Add DoS prevention to decodeHtml function in get-logs component
Added maximum iteration limit (maxIterations = 3) to the decodeHtml function to prevent potential DoS attacks from deeply nested HTML entities. This matches the implementation in deployment/show.blade.php and ensures the function cannot be exploited for excessive CPU usage. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
parent
bf8dcac88c
commit
1b4de18323
1 changed files with 6 additions and 2 deletions
|
|
@ -48,13 +48,17 @@
|
||||||
return line.toLowerCase().includes(this.searchQuery.toLowerCase());
|
return line.toLowerCase().includes(this.searchQuery.toLowerCase());
|
||||||
},
|
},
|
||||||
decodeHtml(text) {
|
decodeHtml(text) {
|
||||||
// Decode HTML entities, handling double-encoding
|
// Decode HTML entities, handling double-encoding with max iteration limit to prevent DoS
|
||||||
let decoded = text;
|
let decoded = text;
|
||||||
let prev = '';
|
let prev = '';
|
||||||
while (decoded !== prev) {
|
let iterations = 0;
|
||||||
|
const maxIterations = 3; // Prevent DoS from deeply nested HTML entities
|
||||||
|
|
||||||
|
while (decoded !== prev && iterations < maxIterations) {
|
||||||
prev = decoded;
|
prev = decoded;
|
||||||
const doc = new DOMParser().parseFromString(decoded, 'text/html');
|
const doc = new DOMParser().parseFromString(decoded, 'text/html');
|
||||||
decoded = doc.documentElement.textContent;
|
decoded = doc.documentElement.textContent;
|
||||||
|
iterations++;
|
||||||
}
|
}
|
||||||
return decoded;
|
return decoded;
|
||||||
},
|
},
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue