feature:修复已知安全问题。

This commit is contained in:
pixelmaxQM
2024-06-02 21:13:51 +08:00
parent 2f67c23c5c
commit 53d0338218
4 changed files with 50 additions and 78 deletions
+6
View File
@@ -0,0 +1,6 @@
export function AddSecret(secret) {
if(!secret){
secret = ""
}
global['gva-secret'] = secret;
}
-65
View File
@@ -1,65 +0,0 @@
import { readFileSync, readdirSync } from 'fs'
const svgTitle = /<svg([^>+].*?)>/
const clearHeightWidth = /(width|height)="([^>+].*?)"/g
const hasViewBox = /(viewBox="[^>+].*?")/g
const clearReturn = /(\r)|(\n)/g
function findSvgFile(dir) {
const svgRes = []
const dirents = readdirSync(dir, {
withFileTypes: true
})
for (const dirent of dirents) {
if (dirent.isDirectory()) {
svgRes.push(...findSvgFile(dir + dirent.name + '/'))
} else {
const svg = readFileSync(dir + dirent.name)
.toString()
.replace(clearReturn, '')
.replace(svgTitle, ($1, $2) => {
let width = 0
let height = 0
let content = $2.replace(clearHeightWidth, (s1, s2, s3) => {
if (s2 === 'width') {
width = s3
} else if (s2 === 'height') {
height = s3
}
return ''
})
if (!hasViewBox.test($2)) {
content += `viewBox="0 0 ${width} ${height}"`
}
return `<symbol id="${dirent.name.replace('.svg', '')}" ${content}>`
})
.replace('</svg>', '</symbol>')
svgRes.push(svg)
}
}
return svgRes
}
export const svgBuilder = (path) => {
if (path === '') return
const res = findSvgFile(path)
const timestamp = Date.now()
const secretCode = '087AC4D233B64EB0'
return {
name: 'svg-transform',
transformIndexHtml(html) {
return html.replace(
'<head>',
`
<head>
<meta name="keywords" content="${timestamp},${secretCode}">
`
).replace(
'<body>',
`
<body>
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" style="position: absolute; width: 0; height: 0">
${res.join('')}
</svg>
`
)
}
}
}