gitlab-org--gitlab-foss/lib/gitlab/url_sanitizer.rb

91 lines
2.2 KiB
Ruby
Raw Normal View History

2016-03-21 12:15:51 +00:00
module Gitlab
class UrlSanitizer
def self.sanitize(content)
2017-02-22 17:46:57 +00:00
regexp = URI::Parser.new.make_regexp(%w(http https ssh git))
content.gsub(regexp) { |url| new(url).masked_url }
2016-07-11 07:01:09 +00:00
rescue Addressable::URI::InvalidURIError
content.gsub(regexp, '')
end
2016-06-30 12:30:07 +00:00
def self.valid?(url)
return false unless url.present?
2016-06-30 12:30:07 +00:00
Addressable::URI.parse(url.strip)
true
rescue Addressable::URI::InvalidURIError
false
end
2016-03-21 14:11:05 +00:00
def initialize(url, credentials: nil)
%i[user password].each do |symbol|
credentials[symbol] = credentials[symbol].presence if credentials&.key?(symbol)
end
2016-03-21 14:11:05 +00:00
@credentials = credentials
@url = parse_url(url)
2016-03-21 12:15:51 +00:00
end
def sanitized_url
@sanitized_url ||= safe_url.to_s
end
def masked_url
url = @url.dup
url.password = "*****" if url.password.present?
url.user = "*****" if url.user.present?
url.to_s
end
2016-03-21 12:15:51 +00:00
def credentials
@credentials ||= { user: @url.user.presence, password: @url.password.presence }
2016-03-21 12:15:51 +00:00
end
2016-03-21 14:11:05 +00:00
def full_url
@full_url ||= generate_full_url.to_s
end
2016-03-21 12:15:51 +00:00
private
def parse_url(url)
url = url.to_s.strip
match = url.match(%r{\A(?:git|ssh|http(?:s?))\://(?:(.+)(?:@))?(.+)})
raw_credentials = match[1] if match
if raw_credentials.present?
url.sub!("#{raw_credentials}@", '')
user, password = raw_credentials.split(':')
@credentials ||= { user: user.presence, password: password.presence }
end
url = Addressable::URI.parse(url)
url.password = password if password.present?
url.user = user if user.present?
url
end
2016-03-21 14:11:05 +00:00
def generate_full_url
2016-03-29 13:23:32 +00:00
return @url unless valid_credentials?
2016-03-21 14:11:05 +00:00
@full_url = @url.dup
@full_url.password = credentials[:password] if credentials[:password].present?
@full_url.user = credentials[:user] if credentials[:user].present?
2016-03-21 14:11:05 +00:00
@full_url
end
2016-03-21 12:15:51 +00:00
def safe_url
safe_url = @url.dup
safe_url.password = nil
safe_url.user = nil
safe_url
end
2016-03-29 13:23:32 +00:00
def valid_credentials?
credentials && credentials.is_a?(Hash) && credentials.any?
end
2016-03-21 12:15:51 +00:00
end
2016-03-21 16:29:19 +00:00
end