From 84875aaf8256837cf12bcf4c73d8d6d9952d799e Mon Sep 17 00:00:00 2001 From: Julien Neuhart Date: Tue, 8 Feb 2022 19:45:10 +0100 Subject: [PATCH] fix(chromium): remove local files from extra ling tags & extra script tags (closes #418) --- pkg/modules/chromium/routes.go | 170 +----------------- pkg/modules/chromium/routes_test.go | 150 +--------------- .../testdata/chromium/html/sample11/font.woff | Bin 12644 -> 0 bytes .../chromium/html/sample11/index.html | 12 -- .../testdata/chromium/html/sample11/script.js | 2 - .../testdata/chromium/html/sample11/style.css | 14 -- 6 files changed, 6 insertions(+), 342 deletions(-) delete mode 100644 test/testdata/chromium/html/sample11/font.woff delete mode 100644 test/testdata/chromium/html/sample11/index.html delete mode 100644 test/testdata/chromium/html/sample11/script.js delete mode 100644 test/testdata/chromium/html/sample11/style.css diff --git a/pkg/modules/chromium/routes.go b/pkg/modules/chromium/routes.go index 5c87b882..6b1e8b03 100644 --- a/pkg/modules/chromium/routes.go +++ b/pkg/modules/chromium/routes.go @@ -130,10 +130,8 @@ func convertURLRoute(chromium API, engine gotenberg.PDFEngine) api.Route { form, options := FormDataChromiumPDFOptions(ctx) var ( - URL string - PDFformat string - linkPaths []string - scriptPaths []string + URL string + PDFformat string ) err := form. @@ -163,176 +161,12 @@ func convertURLRoute(chromium API, engine gotenberg.PDFEngine) api.Route { return nil }). - Paths([]string{".woff2", ".woff", ".ttf", ".css"}, &linkPaths). - Paths([]string{".js"}, &scriptPaths). Validate() if err != nil { return fmt.Errorf("validate form data: %w", err) } - // Thanks to Options.LinkTags and Options.ScriptTags, one may - // "hijack" the content of a remote HTML document (for instance, a - // website) by loading external assets like scripts or CSS - // stylesheets. - // - // There are two possibilities: - // - // 1. We auto-detect all files sent in the request that match the - // following file extensions: ".woff2", ".woff", ".ttf", ".css", - // ".css", and ".js". - // - // 2. The user has sent both files and a JSON mapping via the - // "extraLinkTags" and/or "extraScriptTags" form fields. In such a - // scenario, the JSON mapping has the priority for ordering, and - // files which are a not mapped are added at the end. The user may - // also have sent remote URLs in the JSON mapping. - - // First, let's handle the HTML elements. - hasExtraLinkTags := len(options.ExtraLinkTags) > 0 - hasLinkPaths := len(linkPaths) > 0 - - if !hasExtraLinkTags && hasLinkPaths { - // First scenario: there is no JSON mapping, we simply add the - // paths. - options.ExtraLinkTags = make([]LinkTag, len(linkPaths)) - - for i, path := range linkPaths { - options.ExtraLinkTags[i] = LinkTag{ - Href: filepath.Base(path), - } - } - } else if hasExtraLinkTags && hasLinkPaths { - // Second scenario: there are both files and a JSON mapping. - - // First, find the filenames of the files. - filenames := make([]string, len(linkPaths)) - for i, path := range linkPaths { - filenames[i] = filepath.Base(path) - } - - var extraLinkTags []LinkTag - - // Then, let's find the filenames that exist in the JSON - // mapping, plus the entries that do only exist in the JSON - // mapping. - for _, linkTagFromMapping := range options.ExtraLinkTags { - found := false - - for _, filename := range filenames { - if linkTagFromMapping.Href == filename { - extraLinkTags = append(extraLinkTags, linkTagFromMapping) - found = true - - break - } - } - - if !found { - // This entry only exist in the JSON mapping. - extraLinkTags = append(extraLinkTags, linkTagFromMapping) - } - } - - // Then, add the remaining filenames. - for _, filename := range filenames { - found := false - - for _, linkTag := range extraLinkTags { - if linkTag.Href == filename { - found = true - - break - } - } - - if !found { - extraLinkTags = append(extraLinkTags, LinkTag{ - Href: filename, - }) - } - } - - // Last but not least, update the options. - options.ExtraLinkTags = extraLinkTags - } - - // Next, let's handle the HTML