Question: how to deal with Regexp::Timeout in _decode_uri_component?
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Bắt đầu trong lib/uri/common.rb tại đường dẫn _decode_uri_component được đề cập và tái hiện Regexp::TimeoutError với một payload được mã hóa phần trăm có kích thước lớn. Thảo luận và xác định hành vi URI mong muốn với các maintainers, sau đó bổ sung coverage cho trường hợp timeout và xác minh rằng cách tiếp cận được chọn xử lý đầu vào đã được báo cáo.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Hi folks, thanks for maintaining the URI gem!
I faced the following issue with a 65MB mime-body payload and over 13 million percent-encoded characters:
Regexp::TimeoutError POST /rails/action_mailbox/mailgun/inbound_emails/mime
vendor/bundle/ruby/3.3.0/gems/uri-0.13.3/lib/uri/common.rb:400:in `match?': regexp match timeout (Regexp::TimeoutError)
from vendor/bundle/ruby/3.3.0/gems/uri-0.13.3/lib/uri/common.rb:400:in `_decode_uri_component'
Ref:
- https://github.com/ruby/uri/blob/v0.13.3/lib/uri/common.rb#L400
- https://github.com/ruby/uri/blob/v1.1.1/lib/uri/common.rb#L464
My workaround was to monkey patch the decode_www_form_component to avoid the Regexp code path if it times out:
module URIFormComponentLinearDecode
ORIGINAL_DECODE_WWW_FORM_COMPONENT = URI.method(:decode_www_form_component)
DECODE_TABLE = URI.const_get(:TBLDECWWWCOMP_)
def decode_www_form_component(str, enc = Encoding::UTF_8)
ORIGINAL_DECODE_WWW_FORM_COMPONENT.call(str, enc)
rescue Regexp::TimeoutError
raise unless str.is_a?(String)
Rails.logger.info("[URIFormComponentLinearDecode] bytesize=#{str.bytesize}")
linear_decode_www_form_component(str, enc)
end
private
def linear_decode_www_form_component(str, enc)
source = str.b
output = String.new(capacity: source.bytesize).b
index = 0
while index < source.bytesize
byte = source.getbyte(index)
case byte
when 37 # "%"
raise ArgumentError, "invalid %-encoding (#{str})" unless index + 2 < source.bytesize
encoded = source.byteslice(index, 3)
decoded = DECODE_TABLE[encoded]
raise ArgumentError, "invalid %-encoding (#{str})" unless decoded
output << decoded
index += 3
when 43 # "+"
output << DECODE_TABLE["+"]
index += 1
else
output << byte
index += 1
end
end
output.force_encoding(enc)
end
end
URI.singleton_class.prepend(URIFormComponentLinearDecode)
I was wondering:
- Did you guys face this problem before?
- Do you have a better approach to it?
- Do you think a solution to this issue belongs in the URI codebase?
- Do you think it would make sense to use a native function in this case?
I'm happy to contribute with a PR if you would like me to. Please let me know if you have any thoughts.
Thanks.
- Ngôn ngữ chính
- Ruby
- Star
- 125
- Fork
- 65
- Merge trung bình
- 6 giờ 4 phút
- Pull request đã merge (30 ngày)
- 2
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ruby/uri
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100
-
upstream contact for Debian Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 25/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 52/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
simp/pupmod-simp-simp#395 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
simp/pupmod-simp-rsyslog#219 ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
simp/pupmod-simp-pupmod#256 ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
simp/pupmod-simp-sudo#150 ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100