修复模板注入问题

This commit is contained in:
dragon
2025-04-15 17:38:45 +08:00
parent 3f63988e2d
commit 2e7e301858
3 changed files with 14 additions and 8 deletions

View File

@@ -2,14 +2,12 @@ package main
import ( import (
_ "embed" _ "embed"
"html/template"
"net/http" "net/http"
"os" "os"
"path/filepath" "path/filepath"
"text/template"
"time" "time"
sprig "github.com/go-task/slim-sprig/v3"
"github.com/alecthomas/units" "github.com/alecthomas/units"
"code.d7z.net/d7z-project/gitea-pages/pkg" "code.d7z.net/d7z-project/gitea-pages/pkg"
@@ -54,13 +52,13 @@ func (c *Config) NewPageServerOptions() (*pkg.ServerOptions, error) {
if c.Page.DefaultBranch == "" { if c.Page.DefaultBranch == "" {
c.Page.DefaultBranch = "gh-pages" c.Page.DefaultBranch = "gh-pages"
} }
defaultErr := template.Must(template.New("err").Funcs(sprig.FuncMap()).Parse(defaultErrPage)) defaultErr := utils.NewTemplate(defaultErrPage)
if c.Page.ErrUnknownPage != "" { if c.Page.ErrUnknownPage != "" {
data, err := os.ReadFile(c.Page.ErrUnknownPage) data, err := os.ReadFile(c.Page.ErrUnknownPage)
if err != nil { if err != nil {
return nil, errors.Wrapf(err, "failed to read file %s", string(data)) return nil, errors.Wrapf(err, "failed to read file %s", string(data))
} }
c.pageErrUnknown = template.Must(template.New("err").Funcs(sprig.FuncMap()).Parse(c.Page.ErrUnknownPage)) c.pageErrUnknown = utils.NewTemplate(c.Page.ErrUnknownPage)
} else { } else {
c.pageErrUnknown = defaultErr c.pageErrUnknown = defaultErr
} }
@@ -69,7 +67,7 @@ func (c *Config) NewPageServerOptions() (*pkg.ServerOptions, error) {
if err != nil { if err != nil {
return nil, errors.Wrapf(err, "failed to read file %s", c.Page.ErrNotFoundPage) return nil, errors.Wrapf(err, "failed to read file %s", c.Page.ErrNotFoundPage)
} }
c.pageErrNotFound = template.Must(template.New("err").Funcs(sprig.FuncMap()).Parse(string(data))) c.pageErrNotFound = utils.NewTemplate(string(data))
} else { } else {
c.pageErrNotFound = defaultErr c.pageErrNotFound = defaultErr
} }
@@ -100,6 +98,7 @@ func (c *Config) ErrorHandler(w http.ResponseWriter, r *http.Request, err error)
w.WriteHeader(http.StatusNotFound) w.WriteHeader(http.StatusNotFound)
if err = c.pageErrNotFound.Execute(w, utils.NewTemplateInject(r, map[string]any{ if err = c.pageErrNotFound.Execute(w, utils.NewTemplateInject(r, map[string]any{
"Error": err, "Error": err,
"Path": r.URL.Path,
"Code": 404, "Code": 404,
})); err != nil { })); err != nil {
zap.L().Error("failed to render error page", zap.Error(err)) zap.L().Error("failed to render error page", zap.Error(err))
@@ -108,6 +107,7 @@ func (c *Config) ErrorHandler(w http.ResponseWriter, r *http.Request, err error)
w.WriteHeader(http.StatusInternalServerError) w.WriteHeader(http.StatusInternalServerError)
if err = c.pageErrUnknown.Execute(w, utils.NewTemplateInject(r, map[string]any{ if err = c.pageErrUnknown.Execute(w, utils.NewTemplateInject(r, map[string]any{
"Error": err, "Error": err,
"Path": r.URL.Path,
"Code": 500, "Code": 500,
})); err != nil { })); err != nil {
zap.L().Error("failed to render error page", zap.Error(err)) zap.L().Error("failed to render error page", zap.Error(err))

View File

@@ -5,11 +5,11 @@
<meta name="viewport" <meta name="viewport"
content="width=device-width, user-scalable=no, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0"> content="width=device-width, user-scalable=no, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge"> <meta http-equiv="X-UA-Compatible" content="ie=edge">
{{ if eq .code 404 }}<title>404 Not Found</title>{{ else }}<title>500 Unknown Error</title>{{ end }} {{ if eq .Code 404 }}<title>404 Not Found</title>{{ else }}<title>500 Unknown Error</title>{{ end }}
</head> </head>
<Body> <Body>
<div style="text-align: center;"> <div style="text-align: center;">
{{ if eq .code 404 }}<h1>404 Not Found</h1>{{ else }}<h1>500 Unknown Error</h1>{{ end }} {{ if eq .Code 404 }}<h1>404 Not Found</h1>{{ else }}<h1>500 Unknown Error</h1>{{ end }}
</div> </div>
<hr> <hr>
<div style="text-align: center;">Gitea Pages</div> <div style="text-align: center;">Gitea Pages</div>

View File

@@ -1,8 +1,10 @@
package utils package utils
import ( import (
sprig "github.com/go-task/slim-sprig/v3"
"net/http" "net/http"
"strings" "strings"
"text/template"
) )
func NewTemplateInject(r *http.Request, def map[string]any) map[string]any { func NewTemplateInject(r *http.Request, def map[string]any) map[string]any {
@@ -23,3 +25,7 @@ func NewTemplateInject(r *http.Request, def map[string]any) map[string]any {
} }
return def return def
} }
func NewTemplate(data string) *template.Template {
return template.Must(template.New("err").Funcs(sprig.FuncMap()).Parse(data))
}