fix(youtube): Incomplete URL substring sanitization

This commit is contained in:
tzhangchi
2022-08-17 10:35:12 +08:00
parent a17ec1c5f9
commit fd9ed2862f
2 changed files with 7 additions and 5 deletions

View File

@@ -1,9 +1,9 @@
import { Protocol } from '@toeverything/datasource/db-service';
import { import {
AsyncBlock, AsyncBlock,
BaseView, BaseView,
SelectBlock, SelectBlock,
} from '@toeverything/framework/virgo'; } from '@toeverything/framework/virgo';
import { Protocol } from '@toeverything/datasource/db-service';
import { YoutubeView } from './YoutubeView'; import { YoutubeView } from './YoutubeView';
export class YoutubeBlock extends BaseView { export class YoutubeBlock extends BaseView {
@@ -19,9 +19,10 @@ export class YoutubeBlock extends BaseView {
const tag_name = el.tagName; const tag_name = el.tagName;
if (tag_name === 'A' && el.parentElement?.childElementCount === 1) { if (tag_name === 'A' && el.parentElement?.childElementCount === 1) {
const href = el.getAttribute('href'); const href = el.getAttribute('href');
const allowedHosts = ['.youtube.com']; const allowedHosts = ['www.youtu.be', 'www.youtube.com'];
const host = new URL(href).host;
if (allowedHosts.includes(href)) { if (allowedHosts.includes(host)) {
return [ return [
{ {
type: this.type, type: this.type,

View File

@@ -1,6 +1,7 @@
export const isYoutubeUrl = (url?: string): boolean => { export const isYoutubeUrl = (url?: string): boolean => {
const allowedHosts = ['youtu.be', 'youtube.com']; const allowedHosts = ['www.youtu.be', 'www.youtube.com'];
return allowedHosts.includes(url); const host = new URL(url).host;
return allowedHosts.includes(host);
}; };
const _regexp = /.*(?:youtu.be\/|v\/|u\/\w\/|embed\/|watch\?v=)([^#&?]*).*/; const _regexp = /.*(?:youtu.be\/|v\/|u\/\w\/|embed\/|watch\?v=)([^#&?]*).*/;