Browse Source

Tightening security in processing module.

Former-commit-id: ec9c732224e2d631e3eb38c10302ee8f4974dd65
af/merge-core
James South 12 years ago
parent
commit
cda70144e5
  1. 2
      src/ImageProcessor.Web/Helpers/ImageHelpers.cs
  2. 31
      src/ImageProcessor.Web/HttpModules/ImageProcessingModule.cs
  3. 0
      src/ImageProcessorConsole/Program.cs
  4. 2
      src/Images/Penguins-8.png.REMOVED.git-id

2
src/ImageProcessor.Web/Helpers/ImageHelpers.cs

@ -43,7 +43,7 @@ namespace ImageProcessor.Web.Helpers
/// <returns>True the value contains a valid image extension, otherwise false.</returns> /// <returns>True the value contains a valid image extension, otherwise false.</returns>
public static bool IsValidImageExtension(string fileName) public static bool IsValidImageExtension(string fileName)
{ {
return EndFormatRegex.IsMatch(fileName) || string.IsNullOrWhiteSpace(Path.GetExtension(fileName)); return EndFormatRegex.IsMatch(fileName);
} }
/// <summary> /// <summary>

31
src/ImageProcessor.Web/HttpModules/ImageProcessingModule.cs

@ -270,11 +270,8 @@ namespace ImageProcessor.Web.HttpModules
HttpRequest request = context.Request; HttpRequest request = context.Request;
IImageService currentService = this.GetImageServiceForRequest(request); IImageService currentService = this.GetImageServiceForRequest(request);
if (currentService == null) if (currentService != null)
{ {
throw new HttpException(500, "No ImageService found for current request.");
}
bool isFileLocal = currentService.IsFileLocalService; bool isFileLocal = currentService.IsFileLocalService;
string requestPath = string.Empty; string requestPath = string.Empty;
string queryString = string.Empty; string queryString = string.Empty;
@ -316,7 +313,7 @@ namespace ImageProcessor.Web.HttpModules
} }
// Only process requests that pass our sanitizing filter. // Only process requests that pass our sanitizing filter.
if (ImageHelpers.IsValidImageExtension(requestPath) && !string.IsNullOrWhiteSpace(queryString)) if (!string.IsNullOrWhiteSpace(queryString))
{ {
// Replace any presets in the querystring with the actual value. // Replace any presets in the querystring with the actual value.
queryString = this.ReplacePresetsInQueryString(queryString); queryString = this.ReplacePresetsInQueryString(queryString);
@ -360,7 +357,9 @@ namespace ImageProcessor.Web.HttpModules
if (isNewOrUpdated) if (isNewOrUpdated)
{ {
// Process the image. // Process the image.
using (ImageFactory imageFactory = new ImageFactory(preserveExifMetaData != null && preserveExifMetaData.Value)) using (
ImageFactory imageFactory =
new ImageFactory(preserveExifMetaData != null && preserveExifMetaData.Value))
{ {
using (await Locker.LockAsync(cachedPath)) using (await Locker.LockAsync(cachedPath))
{ {
@ -382,9 +381,7 @@ namespace ImageProcessor.Web.HttpModules
memoryStream.Position = 0; memoryStream.Position = 0;
// Process the Image // Process the Image
imageFactory.Load(memoryStream) imageFactory.Load(memoryStream).AutoProcess(queryString).Save(cachedPath);
.AutoProcess(queryString)
.Save(cachedPath);
// Add to the cache. // Add to the cache.
cache.AddImageToCache(cachedPath); cache.AddImageToCache(cachedPath);
@ -424,7 +421,7 @@ namespace ImageProcessor.Web.HttpModules
context.Response.StatusCode = (int)HttpStatusCode.NotModified; context.Response.StatusCode = (int)HttpStatusCode.NotModified;
context.Response.SuppressContent = true; context.Response.SuppressContent = true;
if (!isFileLocal) if (isFileLocal)
{ {
// Set the headers and quit. // Set the headers and quit.
this.SetHeaders(context, (string)context.Items[CachedResponseTypeKey], new List<string> { requestPath, cachedPath }); this.SetHeaders(context, (string)context.Items[CachedResponseTypeKey], new List<string> { requestPath, cachedPath });
@ -448,6 +445,7 @@ namespace ImageProcessor.Web.HttpModules
HttpContext.Current.Response.Redirect(requestPath); HttpContext.Current.Response.Redirect(requestPath);
} }
} }
}
/// <summary> /// <summary>
/// This will make the browser and server keep the output /// This will make the browser and server keep the output
@ -539,7 +537,18 @@ namespace ImageProcessor.Web.HttpModules
} }
} }
return imageService ?? services.FirstOrDefault(s => string.IsNullOrWhiteSpace(s.Key)); if (imageService != null)
{
return imageService;
}
// Return the file based service
if (ImageHelpers.IsValidImageExtension(path))
{
return services.FirstOrDefault(s => string.IsNullOrWhiteSpace(s.Key));
}
return null;
} }
#endregion #endregion
} }

0
src/ImageProcessorConsole/Program.cs

2
src/Images/Penguins-8.png.REMOVED.git-id

@ -1 +1 @@
c433c806c6aba9b23e24ce55b26382e117c7a5d9 1672192a14349a4c93fe9ae885d57a3f34e6cc7c
Loading…
Cancel
Save