Repository navigation
Conversation
snoopdave
left a comment
There was a problem hiding this comment.
PR-Review: 2 inline comments posted.
| // MySQL's TEXT column holds 65,535 bytes. Leave room for the rest of an entry. | ||
| public static final int MAX_FIELD_BYTES = 60000; | ||
|
|
||
| private static final Pattern IMAGE_TAG = Pattern.compile("(?is)<img\\b[^>]*>"); |
There was a problem hiding this comment.
🐞Claude Issue: Blocking: This is the cause of the failing CodeQL check (high: polynomial regex on user data). [^>]* also matches <, so on text with many <img and no > each find() scans to the end of the input, which is O(n²). Measured with "<img ".repeat(n): 0.44 s at 50 KB, 1.8 s at 100 KB, 7.2 s at 200 KB. Any author can make a save take minutes.
Fix: stop at the next tag start. On the same input this ran in 1–3 ms:
private static final Pattern IMAGE_TAG = Pattern.compile("(?is)<img\\b[^<>]*>");Add a regression test with a large adversarial input.
| public static final int MAX_FIELD_BYTES = 60000; | ||
|
|
||
| private static final Pattern IMAGE_TAG = Pattern.compile("(?is)<img\\b[^>]*>"); | ||
| private static final Pattern SOURCE_ATTRIBUTE = Pattern.compile( |
There was a problem hiding this comment.
🐞Claude Issue: Important: SOURCE_ATTRIBUTE can match src= inside another attribute's quoted value. For example, in <img alt='src="data:image/png;base64,..."' src="https://..."> the alt text is treated as the source. That alt text is then rewritten or rejected, and the real src is ignored. Match attributes in sequence instead (name=value pairs from the tag start), or at least skip matches that fall inside an earlier quoted value.
|
🐞Claude Issue: PR-Review: General Issues The following issues were found but cannot be attached to a specific line in the diff:
|
Fixes ROL-2184.
Summary
Desktop images pasted or dragged into the rich text editor remain visible while editing but disappear from published entries because their
data:sources are removed during rendering.This change converts PNG, JPEG, and GIF data images to Roller media files when uploads are available to the author. If uploads are disabled or the author cannot upload, it keeps validated images inline. Saving an older entry applies the same handling to images already in its text or summary.
It also adds
weblog.inlineImages.preferInlinefor operators who want inline storage even when uploads are available, limits inline content to 60,000 UTF-8 bytes per field, permits validated data images through the HTML sanitizer, and updates bundled theme image policies and the user guide.Verification
mvn -q -pl app -am -DskipTests compile— passedgit diff --check— passedNotes
Custom themes with their own Content Security Policy need
data:inimg-srcto display inline images.