1/* 2 * OWASP Enterprise Security API (ESAPI) 3 * 4 * This file is part of the Open Web Application Security Project (OWASP) 5 * Enterprise Security API (ESAPI) project. For details, please see 6 * <a href="http://www.owasp.org/index.php/ESAPI">http://www.owasp.org/index.php/ESAPI</a>. 7 * 8 * Copyright (c) 2008 - The OWASP Foundation 9 * 10 * The ESAPI is published by OWASP under the BSD license. You should read and accept the 11 * LICENSE before you use, modify, and/or redistribute this software. 12 */ 13 14 15// Utility and Core API Methods 16var $namespace = function(name, separator, container){ 17 var ns = name.split(separator || '.'), 18 o = container || window, 19 i, 20 len; 21 for(i = 0, len = ns.length; i < len; i++){ 22 o = o[ns[i]] = o[ns[i]] || {}; 23 } 24 return o; 25}; 26 27var $type = function( oVar, oType ) { 28 if ( !oVar instanceof oType ) { 29 throw new SyntaxError(); 30 } 31}; 32 33if (!$) { 34 var $ = function( sElementID ) { 35 return document.getElementById( sElementID ); 36 }; 37} 38 39if (!Array.prototype.each) { 40 Array.prototype.each = function(fIterator) { 41 if (typeof fIterator != 'function') { 42 throw 'Illegal Argument for Array.each'; 43 } 44 45 for (var i = 0; i < this.length; i ++) { 46 fIterator(this[i]); 47 } 48 }; 49} 50 51if (!Array.prototype.contains) { 52 Array.prototype.contains = function(srch) { 53 var found = false; 54 this.each(function(e) { 55 if ( ( srch.equals && srch.equals(e) ) || e == srch) { 56 found = true; 57 return; 58 } 59 }); 60 return found; 61 }; 62} 63 64if (!Array.prototype.containsKey) { 65 Array.prototype.containsKey = function(srch) { 66 for ( var key in this ) { 67 if ( key.toLowerCase() == srch.toLowerCase() ) { 68 return true; 69 } 70 } 71 return false; 72 }; 73} 74 75if (!Array.prototype.getCaseInsensitive) { 76 Array.prototype.getCaseInsensitive = function(key) { 77 for (var k in this) { 78 if (k.toLowerCase() == key.toLowerCase()) { 79 return this[k]; 80 } 81 } 82 return null; 83 }; 84} 85 86if (!String.prototype.charCodeAt) { 87 String.prototype.charCodeAt = function( idx ) { 88 var c = this.charAt(idx); 89 for ( var i=0;i<65536;i++) { 90 var s = String.fromCharCode(i); 91 if ( s == c ) { return i; } 92 } 93 return 0; 94 }; 95} 96 97if (!String.prototype.endsWith) { 98 String.prototype.endsWith = function( test ) { 99 return this.substr( ( this.length - test.length ), test.length ) == test; 100 }; 101} 102 103// Declare Core Exceptions 104if ( !Exception ) { 105 var Exception = function( sMsg, oException ) { 106 this.cause = oException; 107 this.errorMessage = sMsg; 108 }; 109 110 Exception.prototype = Error.prototype; 111 112 Exception.prototype.getCause = function() { return this.cause; }; 113 114 Exception.prototype.getMessage = function() { return this.message; }; 115 116 /** 117 * This method creates the stacktrace for the Exception only when it is called the first time and 118 * caches it for access after that. Since building a stacktrace is a fairly expensive process, we 119 * only want to do it if it is called. 120 */ 121 Exception.prototype.getStackTrace = function() { 122 if ( this.callstack ) { 123 return this.callstack; 124 } 125 126 if ( this.stack ) { // Mozilla 127 var lines = stack.split("\n"); 128 for ( var i=0, len=lines.length; i<len; i ++ ) { 129 if ( lines[i].match( /^\s*[A-Za-z0-9\=+\$]+\(/ ) ) { 130 this.callstack.push(lines[i]); 131 } 132 } 133 this.callstack.shift(); 134 return this.callstack; 135 } 136 else if ( window.opera && this.message ) { // Opera 137 var lines = this.message.split('\n'); 138 for ( var i=0, len=lines.length; i<len; i++ ) { 139 if ( lines[i].match( /^\s*[A-Za-z0-9\=+\$]+\(/ ) ) { 140 var entry = lines[i]; 141 if ( lines[i+1] ) { 142 entry += " at " + lines[i+1]; 143 i++; 144 } 145 this.callstack.push(entry); 146 } 147 } 148 this.callstack.shift(); 149 return this.callstack; 150 } 151 else { // IE and Safari 152 var currentFunction = arguments.callee.caller; 153 while ( currentFunction ) { 154 var fn = currentFunction.toString(); 155 var fname = fn.substring(fn.indexOf("function")+8,fn.indexOf("(")) || "anonymous"; 156 this.callstack.push(fname); 157 currentFunction = currentFunction.caller; 158 } 159 return this.callstack; 160 } 161 }; 162 163 Exception.prototype.printStackTrace = function( writer ) {
164 var out = this.getMessage() + "|||" + this.getStackTrace().join( "|||" ); 165 166 if ( this.cause ) { 167 if ( this.cause.printStackTrace ) { 168 out += "||||||Caused by " + this.cause.printStackTrace().replace( "\n", "|||" ); 169 } 170 } 171 172 if ( !writer ) { 173 return writer.replace( "|||", "\n" ); 174 } else if ( writer.value ) { 175 writer.value = out.replace( "|||", "\n" ); 176 } else if ( writer.writeln ) { 177 writer.writeln( out.replace( "|||", "\n" ) ); 178 } else if ( writer.innerHTML ) { 179 writer.innerHTML = out.replace( "|||", "<br/>" ); 180 } else if ( writer.innerText ) { 181 writer.innerText = out.replace( "|||", "<br/>" ); 182 } else if ( writer.append ) { 183 writer.append( out.replace( "|||", "\n" ) ); 184 } else if ( writer instanceof Function ) { 185 writer(out.replace( "|||", "\n" ) ); 186 } 187 }; 188} 189 190if ( !RuntimeException ) { 191 var RuntimeException = Exception; 192} 193 194if ( !IllegalArgumentException ) { 195 var IllegalArgumentException = Exception; 196} 197 198if ( !DateFormat ) { 199 // Based on http://jacwright.com/projects/javascript/date_format 200 var DateFormat = function( sFmt ) { 201 202 var fmt = sFmt; 203 204 var replaceChars = { 205 longMonths: [ "January", "February", "March", "April", "May", "June", "July", "August", "September", "October", "
205November", "December" ], 206 shortMonths: [ "Jan", "Feb", "Mar", "Apr", "May", "Jun", "Jul", "Aug", "Sep", "Oct", "Nov", "Dec" ], 207 longDays: [ "Sunday", "Monday", "Tuesday", "Wednesday", "Thursday", "Friday", "Saturday" ], 208 shortDays: [ "Sun", "Mon", "Tue", "Wed", "Thu", "Fri", "Sat" ], 209 210 // Day 211 d: function(date) { return (date.getDate() < 10 ? '0' : '') + date.getDate(); }, 212 D: function(date) { return replaceChars.shortDays[date.getDay()]; }, 213 j: function(date) { return date.getDate(); }, 214 l: function(date) { return replaceChars.longDays[date.getDay()]; }, 215 N: function(date) { return date.getDay() + 1; }, 216 S: function(date) { return (date.getDate() % 10 == 1 && date.getDate() != 11 ? 'st' : (date.getDate() % 10 == 2 && date.getDate() != 12 ? 'nd' : (date.getDate() % 10 == 3 && date.getDate() != 13 ? 'rd' : 'th'))); }, 217 w: function(date) { return date.getDay(); }, 218 z: function(date) { return "Not Yet Supported"; }, 219 // Week 220 W: function(date) { return "Not Yet Supported"; }, 221 // Month 222 F: function(date) { return replaceChars.longMonths[date.getMonth()]; }, 223 m: function(date) { return (date.getMonth() < 9 ? '0' : '') + (date.getMonth() + 1); }, 224 M: function(date) { return replaceChars.shortMonths[date.getMonth()]; }, 225 n: function(date) { return date.getMonth() + 1; }, 226 t: function(date) { return "Not Yet Supported"; }, 227 // Year 228 L: function(date) { return (((date.getFullYear()%4==0)&&(date.getFullYear()%100 != 0)) || (date.getFullYear()%400==0)) ? '1' : '0'; }, 229 o: function(date) { return "Not Supported"; }, 230 Y: function(date) { return date.getFullYear(); }, 231 y: function(date) { return ('' + date.getFullYear()).substr(2); }, 232 // Time 233 a: function(date) { return date.getHours() < 12 ? 'am' : 'pm'; }, 234 A: function(date) { return date.getHours() < 12 ? 'AM' : 'PM'; }, 235 B: function(date) { return "Not Yet Supported"; }, 236 g: function(date) { return date.getHours() % 12 || 12; }, 237 G: function(date) { return date.getHours(); }, 238 h: function(date) { return ((date.getHours() % 12 || 12) < 10 ? '0' : '') + (date.getHours() % 12 || 12); }, 239 H: function(date) { return (date.getHours() < 10 ? '0' : '') + date.getHours(); }, 240 i: function(date) { return (date.getMinutes() < 10 ? '0' : '') + date.getMinutes(); }, 241 s: function(date) { return (date.getSeconds() < 10 ? '0' : '') + date.getSeconds(); }, 242 // Timezone 243 e: function(date) { return "Not Yet Supported"; }, 244 I: function(date) { return "Not Supported"; }, 245 O: function(date) { return (-date.getTimezoneOffset() < 0 ? '-' : '+') + (Math.abs(date.getTimezoneOffset() / 60) < 10 ? '0' : '') + (Math.abs(date.getTimezoneOffset() / 60)) + '00'; }, 246 P: function(date) { return (-date.getTimezoneOffset() < 0 ? '-' : '+') + (Math.abs(date.getTimezoneOffset() / 60) < 10 ? '0' : '') + (Math.abs(date.getTimezoneOffset() / 60)) + ':' + (Math.abs(date.getTimezoneOffset() % 60) < 10 ? '0' : '') + (Math.abs(date.getTimezoneOffset() % 60)); }, 247 T: function(date) { var m = date.getMonth(); date.setMonth(0); var result = date.toTimeString().replace(/^.+ \(?([^\)]+)\)?$/, '$1'); date.setMonth(m); return result;}, 248 Z: function(date) { return -date.getTimezoneOffset() * 60; }, 249 // Full Date/Time 250 c: function(date) { return date.format("Y-m-d") + "T" + date.format("H:i:sP"); }, 251 r: function(date) { return date.toString(); }, 252 U: function(date) { return date.getTime() / 1000; } 253 }; 254 255 256 return {
257 format: function(oDate) { 258 var out = ''; 259 for(var i=0;i<fmt.length;i++) { 260 var c = fmt.charAt(i); 261 if ( replaceChars[c] ) { 262 out += replaceChars[c].call(oDate); 263 } else { 264 out += c; 265 } 266 } 267 return out; 268 } 269 }; 270 }; 271 272 DateFormat.getDateInstance = function() { 273 return new DateFormat("M/d/y h:i a"); 274 }; 275} 276 277$namespace('org.owasp.esapi'); 278 279org.owasp.esapi.ESAPI = function( oProperties ) { 280 var _properties = oProperties; 281 282 if ( !_properties ) throw new RuntimeException("Configuration Error - Unable to load $ESAPI_Properties Object"); 283 284 var _encoder = null; 285 var _validator = null; 286 var _logFactory = null; 287 var _resourceBundle = null; 288 var _httputilities = null; 289 290 return { 291 properties: _properties, 292 293 encoder: function() { 294 if (!_encoder) { 295 if (!_properties.encoder.Implementation) throw new RuntimeException('Configuration Error - $ESAPI.properties.encoder.Implementation object not found.'); 296 _encoder = new _properties.encoder.Implementation(); 297 } 298 return _encoder; 299 }, 300 301 logFactory: function() { 302 if ( !_logFactory ) { 303 if (!_properties.logging.Implementation) throw new RuntimeException('Configuration Error - $ESAPI.properties.logging.Implementation object not found.'); 304 _logFactory = new _properties.logging.Implementation(); 305 } 306 return _logFactory; 307 }, 308 309 logger: function(sModuleName) { 310 return this.logFactory().getLogger(sModuleName); 311 }, 312 313 locale: function() { 314 return org.owasp.esapi.i18n.Locale.getLocale( _properties.localization.DefaultLocale ); 315 }, 316 317 resourceBundle: function() { 318 if (!_resourceBundle) { 319 if(!_properties.localization.StandardResourceBundle) throw new RuntimeException("Configuration Error - $ESAPI.properties.localization.StandardResourceBundle not found."); 320 _resourceBundle = new org.owasp.esapi.i18n.ObjectResourceBundle( _properties.localization.StandardResourceBundle ); 321 } 322 return _resourceBundle; 323 }, 324 325 validator: function() { 326 if (!_validator) { 327 if (!_properties.validation.Implementation) throw new RuntimeException('Configuration Error - $ESAPI.properties.validation.Implementation object not found.'); 328 _validator = new _properties.validation.Implementation(); 329 } 330 return _validator; 331 }, 332 333 httpUtilities: function() { 334 if (!_httputilities) _httputilities = new org.owasp.esapi.HTTPUtilities(); 335 return _httputilities; 336 } 337 }; 338};
339 340var $ESAPI = null; 341 342org.owasp.esapi.ESAPI.initialize = function() { 343 $ESAPI = new org.owasp.esapi.ESAPI( Base.esapi.properties ); 344}; 345 346$namespace('org.owasp.esapi'); 347 348org.owasp.esapi.Encoder = function() { 349 350} 351 352$namespace('org.owasp.esapi'); 353 354org.owasp.esapi.EncoderConstants = { 355 CHAR_LOWERS: [ 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z' ], 356 CHAR_UPPERS: [ 'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z' ], 357 CHAR_DIGITS: [ '0', '1', '2', '3', '4', '5', '6', '7', '8', '9' ], 358 CHAR_SPECIALS: [ '!', '$', '*', '+', '-', '.', '=', '?', '@', '^', '_', '|', '~' ], 359 CHAR_LETTERS: [ 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', 'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z' ], 360 CHAR_ALNUM: [ 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', 'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z', '0', '1', '2', '3', '4', '5', '6', '7', '8', '9' ] 361}; 362 363$namespace('org.owasp.esapi'); 364 365org.owasp.esapi.EnterpriseSecurityException = function(sUserMessage, sLogMessage, oException) { 366 var _logMessage = sLogMessage; 367 var _super = new Exception(sUserMessage, oException); 368 369 return { 370 getMessage: _super.getMessage, 371 getUserMessage: _super.getMessage, 372 getLogMessage: function() { 373 return _logMessage; 374 }, 375 getStackTrace: _super.getStackTrace, 376 printStackTrace: _super.printStackTrace 377 }; 378};
379 380$namespace('org.owasp.esapi'); 381 382org.owasp.esapi.HTTPUtilities = function() { 383 var log = $ESAPI.logger("HTTPUtilities"); 384 var resourceBundle = $ESAPI.resourceBundle(); 385 var EventType = org.owasp.esapi.Logger.EventType; 386 387 return { 388 addCookie: function( oCookie ) { 389 $type(oCookie,org.owasp.esapi.net.Cookie); 390 391 if ( window.top.location.protocol != 'http:' || window.top.location.protocol != 'https:' ) 392 throw new RuntimeException(resourceBundle.getString( "HTTPUtilities.Cookie.Protocol", {"protocol":window.top.location.protocol})); 393 394 var name = oCookie.getName(), 395 value = oCookie.getValue(), 396 maxAge = oCookie.getMaxAge(), 397 domain = oCookie.getDomain(), 398 path = oCookie.getPath(), 399 secure = oCookie.getSecure(); 400 401 var validationErrors = new org.owasp.esapi.ValidationErrorList(); 402 var cookieName = $ESAPI.validator().getValidInput("cookie name", name, "HttpCookieName", 50, false, validationErrors ); 403 var cookieValue = $ESAPI.validator().getValidInput("cookie value", value, "HttpCookieValue", 5000, false, validationErrors ); 404 405 if (validationErrors.size() == 0) { 406 var header = name+'='+escape(value); 407 header += maxAge?";expires=" + ( new Date( ( new Date() ).getTime() + ( 1000 * maxAge ) ).toGMTString() ) : ""; 408 header += path?";path="+path:""; 409 header += domain?";domain="+domain:""; 410 header += secure||$ESAPI.properties.httputilities.cookies.ForceSecure?";secure":""; 411 document.cookie=header; 412 } 413 else 414 { 415 log.warning(EventType.SECURITY_FAILURE, resourceBundle.getString("HTTPUtilities.Cookie.UnsafeData", { 'name':name, 'value':value } ) ); 416 } 417 }, 418 419 /** 420 * Returns a {@link org.owasp.esapi.net.Cookie} containing the name and value of the requested cookie. 421 * 422 * IMPORTANT: The value of the cookie is not sanitized at this level. It is the responsibility of the calling 423 * code to sanitize the value for proper output encoding prior to using it. 424 * 425 * @param sName {String} The name of the cookie to retrieve 426 * @return {org.owasp.esapi.net.Cookie} 427 */ 428 getCookie: function(sName) { 429 var cookieJar = document.cookie.split("; "); 430 for(var i=0,len=cookieJar.length;i<len;i++) { 431 var cookie = cookieJar[i].split("="); 432 if (cookie[0] == escape(sName)) { 433 return new org.owasp.esapi.net.Cookie( sName, cookie[1]?unescape(cookie[1]):'' ); 434 } 435 } 436 return null; 437 }, 438 439 /** 440 * Will attempt to kill any cookies associated with the current request (domain,path,secure). If a cookie cannot 441 * be deleted, a RuntimeException will be thrown. 442 * 443 * @throws RuntimeException if one of the cookies cannot be deleted. 444 */ 445 killAllCookies: function() { 446 var cookieJar = document.cookie.split("; "); 447 for(var i=0,len=cookieJar.length;i<len;i++) { 448 var cookie = cookieJar[i].split("="); 449 var name = unescape(cookie[0]); 450 // RuntimeException will bubble through if the cookie cannot be deleted 451 if (!this.killCookie(name)) { 452 // Something is wrong - cookieJar contains a cookie that is inaccesible using getCookie 453 throw new RuntimeException(resourceBundle.getString("HTTPUtilities.Cookie.CantKill", {"name":name})); 454 } 455 } 456 }, 457 458 /** 459 * Will kill a single cookie. If that cookie cannot be deleted a RuntimeException will be thrown 460 * @param sName {String} The name of the cookie 461 */ 462 killCookie: function(sName) { 463 var c = this.getCookie(sName); 464 if ( c ) {
465 c.setMaxAge( -10 ); 466 this.addCookie(c); 467 if (this.getCookie(sName)) { 468 throw new RuntimeException(resourceBundle.getString("HTTPUtilities.Cookie.CantKill", {"name":sName})); 469 } 470 return true; 471 } 472 return false; 473 }, 474 475 /** 476 * This only works for GET parameters and is meerly a convenience method for accessing that information if need be 477 * @param sName {String} The name of the parameter to retrieve 478 */ 479 getRequestParameter: function( sName ) { 480 var url = window.top.location.search.substring(1); 481 var pIndex = url.indexOf(sName); 482 if (pIndex<0) return null; 483 pIndex=pIndex+sName.length; 484 var lastIndex=url.indexOf("&",pIndex); 485 if (lastIndex<0) lastIndex=url.length; 486 return unescape(url.substring(pIndex,lastIndex)); 487 } 488 }; 489}; 490 491$namespace('org.owasp.esapi'); 492 493org.owasp.esapi.IntrusionException = function(sUserMessage, sLogMessage, oCause) { 494 var _super = new org.owasp.esapi.EnterpriseSecurityException(sUserMessage, sLogMessage, oCause); 495 496 return { 497 getMessage: _super.getMessage, 498 getUserMessage: _super.getMessage, 499 getLogMessage: _super.getLogMessage, 500 getStackTrace: _super.getStackTrace, 501 printStackTrace: _super.printStackTrace 502 }; 503};
504 505$namespace('org.owasp.esapi'); 506 507org.owasp.esapi.LogFactory = function() { 508 return { 509 getLogger: false 510 }; 511} 512 513$namespace('org.owasp.esapi'); 514 515org.owasp.esapi.Logger = function() { 516 return { 517 setLevel: false, 518 fatal: false, 519 error: false, 520 isErrorEnabled: false, 521 warning: false, 522 isWarningEnabled: false, 523 info: false, 524 isInfoEnabled: false, 525 debug: false, 526 isDebugEnabled: false, 527 trace: false, 528 isTraceEnabled: false 529 }; 530}; 531 532org.owasp.esapi.Logger.EventType = function( sName, bNewSuccess ) { 533 var type = sName; 534 var success = bNewSuccess; 535 536 return { 537 isSuccess: function() { 538 return success; 539 }, 540 541 toString: function() { 542 return type; 543 } 544 }; 545}; 546 547with(org.owasp.esapi.Logger) { 548 549 EventType.SECURITY_SUCCESS = new EventType( "SECURITY SUCCESS", true ); 550 EventType.SECURITY_FAILURE = new EventType( "SECURITY FAILURE", false ); 551 EventType.EVENT_SUCCESS = new EventType( "EVENT SUCCESS", true ); 552 EventType.EVENT_FAILURE = new EventType( "EVENT FAILURE", false ); 553 554 OFF = Number.MAX_VALUE; 555 FATAL = 1000; 556 ERROR = 800; 557 WARNING = 600; 558 INFO = 400; 559 DEBUG = 200; 560 TRACE = 100; 561 ALL = Number.MIN_VALUE; 562} 563 564$namespace('org.owasp.esapi'); 565 566org.owasp.esapi.PreparedString = function(sTemplate, oCodec, sParameterCharacter) { 567 // Private Scope 568 var parts = []; 569 var parameters = []; 570 571 function split(s) { 572 var idx = 0, pcount = 0; 573 for (var i = 0; i < s.length; i ++) { 574 if (s.charAt(i) == sParameterCharacter) { 575 pcount ++; 576 parts.push(s.substr(idx, i)); 577 idx = i + 1; 578 } 579 } 580 parts.push(s.substr(idx)); 581 parameters = new Array(pcount); 582 } 583 584 ; 585 586 if (!sParameterCharacter) { 587 sParameterCharacter = '?'; 588 } 589 590 split(sTemplate); 591 592 return { 593 set: function(iIndex, sValue, codec) { 594 if (iIndex < 1 || iIndex > parameters.length) { 595 throw new IllegalArgumentException("Attempt to set parameter: " + iIndex + " on a PreparedString with only " + parameters.length + " placeholders"); 596 } 597 if (!codec) { 598 codec = oCodec; 599 } 600 parameters[iIndex - 1] = codec.encode([], sValue); 601 }, 602 603 toString: function() { 604 for (var ix = 0; ix < parameters.length; ix ++) { 605 if (parameters[ix] == null) { 606 throw new RuntimeException("Attempt to render PreparedString without setting parameter " + (ix + 1)); 607 } 608 } 609 var out = '', i = 0; 610 for (var p = 0; p < parts.length; p ++) { 611 out += parts[p]; 612 if (i < parameters.length) { 613 out += parameters[i++]; 614 } 615 } 616 return out; 617 } 618 }; 619};
620 621 622$namespace('org.owasp.esapi'); 623 624org.owasp.esapi.ValidationErrorList = function() { 625 var errorList = Array(); 626 627 return { 628 addError: function( sContext, oValidationException ) { 629 if ( sContext == null ) throw new RuntimeException( "Context cannot be null: " + oValidationException.getLogMessage(), oValidationException ); 630 if ( oValidationException == null ) throw new RuntimeException( "Context (" + sContext + ") - Error cannot be null" ); 631 if ( errorList[sContext] ) throw new RuntimeException( "Context (" + sContext + ") already exists. must be unique." ); 632 errorList[sContext] = oValidationException; 633 }, 634 635 errors: function() { 636 return errorList; 637 }, 638 639 isEmpty: function() { 640 return errorList.length == 0; 641 }, 642 643 size: function() { 644 return errorList.length; 645 } 646 }; 647}; 648 649 650$namespace('org.owasp.esapi'); 651 652org.owasp.esapi.ValidationRule = function() { 653 return { 654 getValid: false, 655 setAllowNull: false, 656 getTypeName: false, 657 setTypeName: false, 658 setEncoder: false, 659 assertValid: false, 660 getSafe: false, 661 isValid: false, 662 whitelist: false 663 }; 664};
665 666 667$namespace('org.owasp.esapi'); 668 669org.owasp.esapi.Validator = function() { 670 return { 671 addRule: false, 672 getRule: false, 673 getValidInput: false, 674 isValidDate: false, 675 getValidDate: false, 676 isValidSafeHTML: false, 677 getValidSafeHTML: false, 678 isValidCreditCard: false, 679 getValidCreditCard: false, 680 isValidFilename: false, 681 getValidFilename: false, 682 isValidNumber: false, 683 getValidNumber: false, 684 isValidPrintable: false, 685 getValidPrintable: false 686 }; 687}; 688 689 690$namespace('org.owasp.esapi.codecs.Base64'); 691 692org.owasp.esapi.codecs.Base64 = { 693 _keyStr : "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=", 694 695 encode: function(sInput) { 696 if (!sInput) { 697 return null; 698 } 699 700 var out = ''; 701 var ch1,ch2,ch3,enc1,enc2,enc3,enc4; 702 var i = 0; 703 704 var input = org.owasp.esapi.codecs.UTF8.encode(sInput); 705 706 while (i < input.length) { 707 ch1 = input.charCodeAt(i++); 708 ch2 = input.charCodeAt(i++); 709 ch3 = input.charCodeAt(i++); 710 711 enc1 = ch1 >> 2; 712 enc2 = ((ch1 & 3) << 4) | (ch2 >> 4); 713 enc3 = ((ch2 & 15) << 2) | (ch3 >> 6); 714 enc4 = ch3 & 63; 715 716 if (isNaN(ch2)) { 717 enc3 = enc4 = 64; 718 } 719 else if (isNaN(ch3)) { 720 enc4 = 64; 721 } 722 723 out += this._keyStr.charAt(enc1) + this._keyStr.charAt(enc2) + this._keyStr.charAt(enc3) + this._keyStr.charAt(enc4); 724 } 725 726 return out; 727 }, 728 729 decode: function(sInput) { 730 if (!sInput) { 731 return null; 732 } 733 734 var out = ''; 735 var ch1, ch2, ch3, enc1, enc2, enc3, enc4; 736 var i = 0; 737 738 var input = sInput.replace(/[^A-Za-z0-9\+\/\=]/g, ""); 739 740 while (i < input.length) { 741 enc1 = this._keyStr.indexOf(input.charAt(i++)); 742 enc2 = this._keyStr.indexOf(input.charAt(i++)); 743 enc3 = this._keyStr.indexOf(input.charAt(i++)); 744 enc4 = this._keyStr.indexOf(input.charAt(i++)); 745 746 ch1 = (enc1 << 2) | (enc2 >> 4); 747 ch2 = ((enc2 & 15) << 4) | (enc3 >> 2); 748 ch3 = ((enc3 & 3) << 6) | enc4; 749 750 out += String.fromCharCode(ch1); 751 if (enc3 != 64) { 752 out += String.fromCharCode(ch2); 753 } 754 if (enc4 != 64) { 755 out += String.fromCharCode(ch3); 756 } 757 } 758 759 out = org.owasp.esapi.codecs.UTF8.decode(out); 760 return out; 761 } 762}; 763 764 765$namespace('org.owasp.esapi.codecs'); 766 767org.owasp.esapi.codecs.CSSCodec = function() { 768 var _super = new org.owasp.esapi.codecs.Codec(); 769 770 return { 771 encode: _super.encode, 772 773 decode: _super.decode, 774 775 encodeCharacter: function(aImmune, c) { 776 if (aImmune.contains(c)) { 777 return c; 778 } 779 780 var hex = org.owasp.esapi.codecs.Codec.getHexForNonAlphanumeric(c); 781 if (hex == null) { 782 return c; 783 } 784 785 return "\\" + hex + " "; 786 }, 787 788 decodeCharacter: function(oPushbackString) { 789 oPushbackString.mark(); 790 var first = oPushbackString.next(); 791 if (first == null) { 792 oPushbackString.reset(); 793 return null; 794 } 795 796 if (first != '\\') { 797 oPushbackString.reset(); 798 return null; 799 } 800 801 var second = oPushbackString.next(); 802 if (second == null) { 803 oPushbackString.reset(); 804 return null; 805 } 806 807 if (oPushbackString.isHexDigit(second)) { 808 var out = second; 809 for (var i = 0; i < 6; i ++) { 810 var c = oPushbackString.next(); 811 if (c == null || c.charCodeAt(0) == 0x20) { 812 break; 813 } 814 if (oPushbackString.isHexDigit(c)) { 815 out += c; 816 } else { 817 input.pushback(c); 818 break; 819 } 820 } 821 822 try { 823 var n = parseInt(out, 16); 824 return String.fromCharCode(n); 825 } catch (e) { 826 oPushbackString.reset(); 827 return null; 828 } 829 } 830 831 return second; 832 } 833 }; 834};
835 836 837$namespace('org.owasp.esapi.codecs'); 838 839org.owasp.esapi.codecs.Codec = function() { 840 return { 841 /** 842 * Encode a String so that it can be safely used in a specific context. 843 * 844 * @param aImmune 845 * array of immune characters 846 * @param sInput 847 * the String to encode 848 * @return the encoded String 849 */ 850 encode: function(aImmune, sInput) { 851 var out = ''; 852 for (var i = 0; i < sInput.length; i ++) { 853 var c = sInput.charAt(i); 854 out += this.encodeCharacter(aImmune, c); 855 } 856 return out; 857 }, 858 859 /** 860 * Default implementation that should be overridden in specific codecs. 861 * 862 * @param aImmune 863 * array of immune characters 864 * @param c 865 * the Character to encode 866 * @return 867 * the encoded Character 868 */ 869 encodeCharacter: function(aImmune, c) { 870 return c; 871 }, 872 873 /** 874 * Decode a String that was encoded using the encode method in this Class 875 * 876 * @param sInput 877 * the String to decode 878 * @return 879 * the decoded String 880 */ 881 decode: function(sInput) { 882 var out = ''; 883 var pbs = new org.owasp.esapi.codecs.PushbackString(sInput); 884 while (pbs.hasNext()) { 885 var c = this.decodeCharacter(pbs); 886 if (c != null) { 887 out += c; 888 } else { 889 out += pbs.next(); 890 } 891 } 892 return out; 893 }, 894 895 /** 896 * Returns the decoded version of the next character from the input string and advances the 897 * current character in the PushbackString. If the current character is not encoded, this 898 * method MUST reset the PushbackString. 899 * 900 * @param oPushbackString the Character to decode 901 * @return the decoded Character 902 */ 903 decodeCharacter: function(oPushbackString) { 904 return oPushbackString.next(); 905 } 906 }; 907};
908 909org.owasp.esapi.codecs.Codec.getHexForNonAlphanumeric = function(c) { 910 if (c.charCodeAt(0) < 256) { 911 return org.owasp.esapi.codecs.Codec.hex[c.charCodeAt(0)]; 912 } 913 return c.charCodeAt(0).toString(16); 914}; 915 916org.owasp.esapi.codecs.Codec.hex = []; 917for ( var c = 0; c < 0xFF; c ++ ) { 918 if ( c >= 0x30 && c <= 0x39 || c>= 0x41 && c <= 0x5A || c >= 0x61 && c <= 0x7A ) { 919 org.owasp.esapi.codecs.Codec.hex[c] = null; 920 } else { 921 org.owasp.esapi.codecs.Codec.hex[c] = c.toString(16); 922 } 923}; 924 925var entityToCharacterMap = []; 926entityToCharacterMap["""] = "34"; /* 34 : quotation mark */ 927entityToCharacterMap["&"] = "38"; /* 38 : ampersand */ 928entityToCharacterMap["<"] = "60"; /* 60 : less-than sign */ 929entityToCharacterMap[">"] = "62"; /* 62 : greater-than sign */ 930entityToCharacterMap[" "] = "160"; /* 160 : no-break space */ 931entityToCharacterMap["¡"] = "161"; /* 161 : inverted exclamation mark */ 932entityToCharacterMap["¢"] = "162"; /* 162 : cent sign */ 933entityToCharacterMap["£"] = "163"; /* 163 : pound sign */ 934entityToCharacterMap["¤"] = "164"; /* 164 : currency sign */ 935entityToCharacterMap["¥"] = "165"; /* 165 : yen sign */ 936entityToCharacterMap["¦"] = "166"; /* 166 : broken bar */ 937entityToCharacterMap["§"] = "167"; /* 167 : section sign */ 938entityToCharacterMap["¨"] = "168"; /* 168 : diaeresis */ 939entityToCharacterMap["©"] = "169"; /* 169 : copyright sign */ 940entityToCharacterMap["ª"] = "170"; /* 170 : feminine ordinal indicator */ 941entityToCharacterMap["«"] = "171"; /* 171 : left-pointing double angle quotation mark */ 942entityToCharacterMap["¬"] = "172"; /* 172 : not sign */ 943entityToCharacterMap["­"] = "173"; /* 173 : soft hyphen */ 944entityToCharacterMap["®"] = "174"; /* 174 : registered sign */ 945entityToCharacterMap["¯"] = "175"; /* 175 : macron */ 946entityToCharacterMap["°"] = "176"; /* 176 : degree sign */ 947entityToCharacterMap["±"] = "177"; /* 177 : plus-minus sign */ 948entityToCharacterMap["²"] = "178"; /* 178 : superscript two */ 949entityToCharacterMap["³"] = "179"; /* 179 : superscript three */ 950entityToCharacterMap["´"] = "180"; /* 180 : acute accent */ 951entityToCharacterMap["µ"] = "181"; /* 181 : micro sign */ 952entityToCharacterMap["¶"] = "182"; /* 182 : pilcrow sign */ 953entityToCharacterMap["·"] = "183"; /* 183 : middle dot */ 954entityToCharacterMap["¸"] = "184"; /* 184 : cedilla */ 955entityToCharacterMap["¹"] = "185"; /* 185 : superscript one */ 956entityToCharacterMap["º"] = "186"; /* 186 : masculine ordinal indicator */ 957entityToCharacterMap["»"] = "187"; /* 187 : right-pointing double angle quotation mark */ 958entityToCharacterMap["¼"] = "188"; /* 188 : vulgar fraction one quarter */ 959entityToCharacterMap["½"] = "189"; /* 189 : vulgar fraction one half */ 960entityToCharacterMap["¾"] = "190"; /* 190 : vulgar fraction three quarters */ 961entityToCharacterMap["¿"] = "191"; /* 191 : inverted question mark */ 962entityToCharacterMap["À"] = "192"; /* 192 : Latin capital letter a with grave */ 963entityToCharacterMap["Á"] = "193"; /* 193 : Latin capital letter a with acute */ 964entityToCharacterMap["Â"] = "194"; /* 194 : Latin capital letter a with circumflex */ 965entityToCharacterMap["Ã"] = "195"; /* 195 : Latin capital letter a with tilde */ 966entityToCharacterMap["Ä"] = "196"; /* 196 : Latin capital letter a with diaeresis */ 967entityToCharacterMap["Å"] = "197"; /* 197 : Latin capital letter a with ring above */ 968entityToCharacterMap["Æ"] = "198"; /* 198 : Latin capital letter ae */ 969entityToCharacterMap["Ç"] = "199"; /* 199 : Latin capital letter c with cedilla */ 970entityToCharacterMap["È"] = "200"; /* 200 : Latin capital letter e with grave */ 971entityToCharacterMap["É"] = "201"; /* 201 : Latin capital letter e with acute */ 972entityToCharacterMap["Ê"] = "202"; /* 202 : Latin capital letter e with circumflex */ 973entityToCharacterMap["Ë"] = "203"; /* 203 : Latin capital letter e with diaeresis */ 974entityToCharacterMap["Ì"] = "204"; /* 204 : Latin capital letter i with grave */ 975entityToCharacterMap["Í"] = "205"; /* 205 : Latin capital letter i with acute */ 976entityToCharacterMap["Î"] = "206"; /* 206 : Latin capital letter i with circumflex */ 977entityToCharacterMap["Ï"] = "207"; /* 207 : Latin capital letter i with diaeresis */ 978entityToCharacterMap["Ð"] = "208"; /* 208 : Latin capital letter eth */ 979entityToCharacterMap["Ñ"] = "209"; /* 209 : Latin capital letter n with tilde */ 980entityToCharacterMap["Ò"] = "210"; /* 210 : Latin capital letter o with grave */ 981entityToCharacterMap["Ó"] = "211"; /* 211 : Latin capital letter o with acute */ 982entityToCharacterMap["Ô"] = "212"; /* 212 : Latin capital letter o with circumflex */ 983entityToCharacterMap["Õ"] = "213"; /* 213 : Latin capital letter o with tilde */ 984entityToCharacterMap["Ö"] = "214"; /* 214 : Latin capital letter o with diaeresis */ 985entityToCharacterMap["×"] = "215"; /* 215 : multiplication sign */ 986entityToCharacterMap["Ø"] = "216"; /* 216 : Latin capital letter o with stroke */ 987entityToCharacterMap["Ù"] = "217"; /* 217 : Latin capital letter u with grave */ 988entityToCharacterMap["Ú"] = "218"; /* 218 : Latin capital letter u with acute */ 989entityToCharacterMap["Û"] = "219"; /* 219 : Latin capital letter u with circumflex */ 990entityToCharacterMap["Ü"] = "220"; /* 220 : Latin capital letter u with diaeresis */ 991entityToCharacterMap["Ý"] = "221"; /* 221 : Latin capital letter y with acute */ 992entityToCharacterMap["Þ"] = "222"; /* 222 : Latin capital letter thorn */ 993entityToCharacterMap["ß"] = "223"; /* 223 : Latin small letter sharp s, German Eszett */ 994entityToCharacterMap["à"] = "224"; /* 224 : Latin small letter a with grave */ 995entityToCharacterMap["á"] = "225"; /* 225 : Latin small letter a with acute */ 996entityToCharacterMap["â"] = "226";
996 /* 226 : Latin small letter a with circumflex */ 997entityToCharacterMap["ã"] = "227"; /* 227 : Latin small letter a with tilde */ 998entityToCharacterMap["ä"] = "228"; /* 228 : Latin small letter a with diaeresis */ 999entityToCharacterMap["å"] = "229"; /* 229 : Latin small letter a with ring above */ 1000entityToCharacterMap["æ"] = "230"; /* 230 : Latin lowercase ligature ae */ 1001entityToCharacterMap["ç"] = "231"; /* 231 : Latin small letter c with cedilla */ 1002entityToCharacterMap["è"] = "232"; /* 232 : Latin small letter e with grave */ 1003entityToCharacterMap["é"] = "233"; /* 233 : Latin small letter e with acute */ 1004entityToCharacterMap["ê"] = "234"; /* 234 : Latin small letter e with circumflex */ 1005entityToCharacterMap["ë"] = "235"; /* 235 : Latin small letter e with diaeresis */ 1006entityToCharacterMap["ì"] = "236"; /* 236 : Latin small letter i with grave */ 1007entityToCharacterMap["í"] = "237"; /* 237 : Latin small letter i with acute */ 1008entityToCharacterMap["î"] = "238"; /* 238 : Latin small letter i with circumflex */ 1009entityToCharacterMap["ï"] = "239"; /* 239 : Latin small letter i with diaeresis */ 1010entityToCharacterMap["ð"] = "240"; /* 240 : Latin small letter eth */ 1011entityToCharacterMap["ñ"] = "241"; /* 241 : Latin small letter n with tilde */ 1012entityToCharacterMap["ò"] = "242"; /* 242 : Latin small letter o with grave */ 1013entityToCharacterMap["ó"] = "243"; /* 243 : Latin small letter o with acute */ 1014entityToCharacterMap["ô"] = "244"; /* 244 : Latin small letter o with circumflex */ 1015entityToCharacterMap["õ"] = "245"; /* 245 : Latin small letter o with tilde */ 1016entityToCharacterMap["ö"] = "246"; /* 246 : Latin small letter o with diaeresis */ 1017entityToCharacterMap["÷"] = "247"; /* 247 : division sign */ 1018entityToCharacterMap["ø"] = "248"; /* 248 : Latin small letter o with stroke */ 1019entityToCharacterMap["ù"] = "249"; /* 249 : Latin small letter u with grave */ 1020entityToCharacterMap["ú"] = "250"; /* 250 : Latin small letter u with acute */ 1021entityToCharacterMap["û"] = "251"; /* 251 : Latin small letter u with circumflex */ 1022entityToCharacterMap["ü"] = "252"; /* 252 : Latin small letter u with diaeresis */ 1023entityToCharacterMap["ý"] = "253"; /* 253 : Latin small letter y with acute */ 1024entityToCharacterMap["þ"] = "254"; /* 254 : Latin small letter thorn */ 1025entityToCharacterMap["ÿ"] = "255"; /* 255 : Latin small letter y with diaeresis */ 1026entityToCharacterMap["&OElig"] = "338"; /* 338 : Latin capital ligature oe */ 1027entityToCharacterMap["&oelig"] = "339"; /* 339 : Latin small ligature oe */ 1028entityToCharacterMap["&Scaron"] = "352"; /* 352 : Latin capital letter s with caron */ 1029entityToCharacterMap["&scaron"] = "353"; /* 353 : Latin small letter s with caron */ 1030entityToCharacterMap["&Yuml"] = "376"; /* 376 : Latin capital letter y with diaeresis */ 1031entityToCharacterMap["&fnof"] = "402"; /* 402 : Latin small letter f with hook */ 1032entityToCharacterMap["&circ"] = "710"; /* 710 : modifier letter circumflex accent */ 1033entityToCharacterMap["&tilde"] = "732"; /* 732 : small tilde */ 1034entityToCharacterMap["&Alpha"] = "913"; /* 913 : Greek capital letter alpha */ 1035entityToCharacterMap["&Beta"] = "914"; /* 914 : Greek capital letter beta */ 1036entityToCharacterMap["&Gamma"] = "915"; /* 915 : Greek capital letter gamma */ 1037entityToCharacterMap["&Delta"] = "916"; /* 916 : Greek capital letter delta */ 1038entityToCharacterMap["&Epsilon"] = "917"; /* 917 : Greek capital letter epsilon */ 1039entityToCharacterMap["&Zeta"] = "918"; /* 918 : Greek capital letter zeta */ 1040entityToCharacterMap["&Eta"] = "919"; /* 919 : Greek capital letter eta */ 1041entityToCharacterMap["&Theta"] = "920"; /* 920 : Greek capital letter theta */ 1042entityToCharacterMap["&Iota"] = "921"; /* 921 : Greek capital letter iota */ 1043entityToCharacterMap["&Kappa"] = "922"; /* 922 : Greek capital letter kappa */ 1044entityToCharacterMap["&Lambda"] = "923"; /* 923 : Greek capital letter lambda */ 1045entityToCharacterMap["&Mu"] = "924"; /* 924 : Greek capital letter mu */ 1046entityToCharacterMap["&Nu"] = "925"; /* 925 : Greek capital letter nu */ 1047entityToCharacterMap["&Xi"] = "926"; /* 926 : Greek capital letter xi */ 1048entityToCharacterMap["&Omicron"] = "927"; /* 927 : Greek capital letter omicron */ 1049entityToCharacterMap["&Pi"] = "928"; /* 928 : Greek capital letter pi */ 1050entityToCharacterMap["&Rho"] = "929"; /* 929 : Greek capital letter rho */ 1051entityToCharacterMap["&Sigma"] = "931"; /* 931 : Greek capital letter sigma */ 1052entityToCharacterMap["&Tau"] = "932"; /* 932 : Greek capital letter tau */ 1053entityToCharacterMap["&Upsilon"] = "933"; /* 933 : Greek capital letter upsilon */ 1054entityToCharacterMap["&Phi"] = "934"; /* 934 : Greek capital letter phi */ 1055entityToCharacterMap["&Chi"] = "935"; /* 935 : Greek capital letter chi */ 1056entityToCharacterMap["&Psi"] = "936"; /* 936 : Greek capital letter psi */ 1057entityToCharacterMap["&Omega"] = "937"; /* 937 : Greek capital letter omega */ 1058entityToCharacterMap["&alpha"] = "945"; /* 945 : Greek small letter alpha */ 1059entityToCharacterMap["&beta"] = "946"; /* 946 : Greek small letter beta */ 1060entityToCharacterMap["&gamma"] = "947"; /* 947 : Greek small letter gamma */ 1061entityToCharacterMap["&delta"] = "948"; /* 948 : Greek small letter delta */ 1062entityToCharacterMap["&epsilon"] = "949"; /* 949 : Greek small letter epsilon */ 1063entityToCharacterMap["&zeta"] = "950"; /* 950 : Greek small letter zeta */ 1064entityToCharacterMap["&eta"] = "951"; /* 951 : Greek small letter eta */ 1065entityToCharacterMap["&theta"] = "952"; /* 952 : Greek small letter theta */ 1066entityToCharacterMap["&iota"] = "953"; /* 953 : Greek small letter iota */ 1067entityToCharacterMap["&kappa"] = "954"; /* 954 : Greek small letter kappa */ 1068entityToCharacterMap["&lambda"] = "955"; /* 955 : Greek small letter lambda */ 1069entityToCharacterMap["&mu"] = "956"; /* 956 : Greek small letter mu */ 1070entityToCharacterMap["&nu"] = "957"; /* 957 : Greek small letter nu */ 1071entityToCharacterMap["&xi"] = "958"; /* 958 : Greek small letter xi */ 1072entityToCharacterMap["&omicron"] = "959"; /* 959 : Greek small letter omicron */ 1073entityToCharacterMap["&pi"] = "960"; /* 960 : Greek small letter pi */ 1074entityToCharacterMap["&rho"] = "961"; /* 961 : Greek small letter rho */ 1075entityToCharacterMap["&sigmaf"] = "962"; /* 962 : Greek small letter final sigma */ 1076entityToCharacterMap["&sigma"] = "963"; /* 963 : Greek small letter sigma */ 1077entityToCharacterMap["&tau"] = "964"; /* 964 : Greek small letter tau */ 1078entityToCharacterMap["&upsilon"] = "965"; /* 965 : Greek small letter upsilon */ 1079entityToCharacterMap["&phi"] = "966"; /* 966 : Greek small letter phi */ 1080entityToCharacterMap["&chi"] = "967"; /* 967 : Greek small letter chi */ 1081entityToCharacterMap["&psi"] = "968"; /* 968 : Greek small letter psi */ 1082entityToCharacterMap["&omega"] = "969"; /* 969 : Greek small letter omega */ 1083entityToCharacterMap["&thetasym"] = "977"; /* 977 : Greek theta symbol */ 1084entityToCharacterMap["&upsih"] = "978"; /* 978 : Greek upsilon with hook symbol */ 1085entityToCharacterMap["&piv"] = "982"; /* 982 : Greek pi symbol */ 1086entityToCharacterMap["&ensp"] = "8194"; /* 8194 : en space */ 1087entityToCharacterMap["&emsp"] = "8195"; /* 8195 : em space */ 1088entityToCharacterMap["&thinsp"] = "8201"; /* 8201 : thin space */ 1089entityToCharacterMap["&zwnj"] = "8204"; /* 8204 : zero width non-joiner */ 1090entityToCharacterMap["&zwj"] = "8205"; /* 8205 : zero width joiner */ 1091entityToCharacterMap["&lrm"] = "8206"; /* 8206 : left-to-right mark */ 1092entityToCharacterMap["&rlm"] = "8207"; /* 8207 : right-to-left mark */ 1093entityToCharacterMap["&ndash"] = "8211"; /* 8211 : en dash */ 1094entityToCharacterMap["&mdash"] = "8212"; /* 8212 : em dash */ 1095entityToCharacterMap["&lsquo"] = "8216"; /* 8216 : left single quotation mark */ 1096entityToCharacterMap["&rsquo"] = "8217"; /* 8217 : right single quotation mark */ 1097entityToCharacterMap["&sbquo"] = "8218"; /* 8218 : single low-9 quotation mark */ 1098entityToCharacterMap["&ldquo"] = "8220"; /* 8220 : left double quotation mark */ 1099entityToCharacterMap["&rdquo"] = "8221"; /* 8221 : right double quotation mark */ 1100entityToCharacterMap["&bdquo"] = "8222"; /* 8222 : double low-9 quotation mark */ 1101entityToCharacterMap["&dagger"] = "8224"; /* 8224 : dagger */ 1102entityToCharacterMap["&Dagger"] = "8225"; /* 8225 : double dagger */ 1103entityToCharacterMap["&bull"] = "8226"; /* 8226 : bullet */
1104entityToCharacterMap["&hellip"] = "8230"; /* 8230 : horizontal ellipsis */ 1105entityToCharacterMap["&permil"] = "8240"; /* 8240 : per mille sign */ 1106entityToCharacterMap["&prime"] = "8242"; /* 8242 : prime */ 1107entityToCharacterMap["&Prime"] = "8243"; /* 8243 : double prime */ 1108entityToCharacterMap["&lsaquo"] = "8249"; /* 8249 : single left-pointing angle quotation mark */ 1109entityToCharacterMap["&rsaquo"] = "8250"; /* 8250 : single right-pointing angle quotation mark */ 1110entityToCharacterMap["&oline"] = "8254"; /* 8254 : overline */ 1111entityToCharacterMap["&frasl"] = "8260"; /* 8260 : fraction slash */ 1112entityToCharacterMap["&euro"] = "8364"; /* 8364 : euro sign */ 1113entityToCharacterMap["&image"] = "8365"; /* 8465 : black-letter capital i */ 1114entityToCharacterMap["&weierp"] = "8472"; /* 8472 : script capital p, Weierstrass p */ 1115entityToCharacterMap["&real"] = "8476"; /* 8476 : black-letter capital r */ 1116entityToCharacterMap["&trade"] = "8482"; /* 8482 : trademark sign */ 1117entityToCharacterMap["&alefsym"] = "8501"; /* 8501 : alef symbol */ 1118entityToCharacterMap["&larr"] = "8592"; /* 8592 : leftwards arrow */ 1119entityToCharacterMap["&uarr"] = "8593"; /* 8593 : upwards arrow */ 1120entityToCharacterMap["&rarr"] = "8594"; /* 8594 : rightwards arrow */ 1121entityToCharacterMap["&darr"] = "8595"; /* 8595 : downwards arrow */ 1122entityToCharacterMap["&harr"] = "8596"; /* 8596 : left right arrow */ 1123entityToCharacterMap["&crarr"] = "8629"; /* 8629 : downwards arrow with corner leftwards */ 1124entityToCharacterMap["&lArr"] = "8656"; /* 8656 : leftwards double arrow */ 1125entityToCharacterMap["&uArr"] = "8657"; /* 8657 : upwards double arrow */ 1126entityToCharacterMap["&rArr"] = "8658"; /* 8658 : rightwards double arrow */ 1127entityToCharacterMap["&dArr"] = "8659"; /* 8659 : downwards double arrow */ 1128entityToCharacterMap["&hArr"] = "8660"; /* 8660 : left right double arrow */ 1129entityToCharacterMap["&forall"] = "8704"; /* 8704 : for all */ 1130entityToCharacterMap["&part"] = "8706"; /* 8706 : partial differential */ 1131entityToCharacterMap["&exist"] = "8707"; /* 8707 : there exists */ 1132entityToCharacterMap["&empty"] = "8709"; /* 8709 : empty set */ 1133entityToCharacterMap["&nabla"] = "8711"; /* 8711 : nabla */ 1134entityToCharacterMap["&isin"] = "8712"; /* 8712 : element of */ 1135entityToCharacterMap["¬in"] = "8713"; /* 8713 : not an element of */ 1136entityToCharacterMap["&ni"] = "8715"; /* 8715 : contains as member */ 1137entityToCharacterMap["&prod"] = "8719"; /* 8719 : n-ary product */ 1138entityToCharacterMap["&sum"] = "8721"; /* 8721 : n-ary summation */ 1139entityToCharacterMap["&minus"] = "8722"; /* 8722 : minus sign */ 1140entityToCharacterMap["&lowast"] = "8727"; /* 8727 : asterisk operator */ 1141entityToCharacterMap["&radic"] = "8730"; /* 8730 : square root */ 1142entityToCharacterMap["&prop"] = "8733"; /* 8733 : proportional to */ 1143entityToCharacterMap["&infin"] = "8734"; /* 8734 : infinity */ 1144entityToCharacterMap["&ang"] = "8736"; /* 8736 : angle */ 1145entityToCharacterMap["&and"] = "8743"; /* 8743 : logical and */ 1146entityToCharacterMap["&or"] = "8744"; /* 8744 : logical or */ 1147entityToCharacterMap["&cap"] = "8745"; /* 8745 : intersection */ 1148entityToCharacterMap["&cup"] = "8746"; /* 8746 : union */ 1149entityToCharacterMap["&int"] = "8747"; /* 8747 : integral */ 1150entityToCharacterMap["&there4"] = "8756"; /* 8756 : therefore */ 1151entityToCharacterMap["&sim"] = "8764"; /* 8764 : tilde operator */ 1152entityToCharacterMap["&cong"] = "8773"; /* 8773 : congruent to */ 1153entityToCharacterMap["&asymp"] = "8776"; /* 8776 : almost equal to */ 1154entityToCharacterMap["&ne"] = "8800"; /* 8800 : not equal to */ 1155entityToCharacterMap["&equiv"] = "8801"; /* 8801 : identical to, equivalent to */ 1156entityToCharacterMap["&le"] = "8804"; /* 8804 : less-than or equal to */ 1157entityToCharacterMap["&ge"] = "8805"; /* 8805 : greater-than or equal to */ 1158entityToCharacterMap["&sub"] = "8834"; /* 8834 : subset of */ 1159entityToCharacterMap["&sup"] = "8835"; /* 8835 : superset of */ 1160entityToCharacterMap["&nsub"] = "8836"; /* 8836 : not a subset of */ 1161entityToCharacterMap["&sube"] = "8838"; /* 8838 : subset of or equal to */ 1162entityToCharacterMap["&supe"] = "8839"; /* 8839 : superset of or equal to */ 1163entityToCharacterMap["&oplus"] = "8853"; /* 8853 : circled plus */ 1164entityToCharacterMap["&otimes"] = "8855"; /* 8855 : circled times */ 1165entityToCharacterMap["&perp"] = "8869"; /* 8869 : up tack */ 1166entityToCharacterMap["&sdot"] = "8901"; /* 8901 : dot operator */ 1167entityToCharacterMap["&lceil"] = "8968"; /* 8968 : left ceiling */ 1168entityToCharacterMap["&rceil"] = "8969"; /* 8969 : right ceiling */ 1169entityToCharacterMap["&lfloor"] = "8970"; /* 8970 : left floor */ 1170entityToCharacterMap["&rfloor"] = "8971"; /* 8971 : right floor */ 1171entityToCharacterMap["&lang"] = "9001"; /* 9001 : left-pointing angle bracket */ 1172entityToCharacterMap["&rang"] = "9002"; /* 9002 : right-pointing angle bracket */ 1173entityToCharacterMap["&loz"] = "9674"; /* 9674 : lozenge */ 1174entityToCharacterMap["&spades"] = "9824"; /* 9824 : black spade suit */ 1175entityToCharacterMap["&clubs"] = "9827"; /* 9827 : black club suit */ 1176entityToCharacterMap["&hearts"] = "9829"; /* 9829 : black heart suit */ 1177entityToCharacterMap["&diams"] = "9830"; /* 9830 : black diamond suit */ 1178 1179var characterToEntityMap = []; 1180 1181for ( var entity in entityToCharacterMap ) { 1182 characterToEntityMap[entityToCharacterMap[entity]] = entity; 1183} 1184 1185$namespace('org.owasp.esapi.codecs'); 1186 1187org.owasp.esapi.codecs.HTMLEntityCodec = function() { 1188 var _super = new org.owasp.esapi.codecs.Codec(); 1189 1190 var getNumericEntity = function(input) { 1191 var first = input.peek(); 1192 if (first == null) { 1193 return null; 1194 } 1195 1196 if (first == 'x' || first == 'X') { 1197 input.next(); 1198 return parseHex(input); 1199 } 1200 return parseNumber(input); 1201 }; 1202 1203 var parseNumber = function(input) { 1204 var out = ''; 1205 while (input.hasNext()) { 1206 var c = input.peek(); 1207 if (c.match(/[0-9]/)) { 1208 out += c; 1209 input.next(); 1210 } else if (c == ';') { 1211 input.next(); 1212 break; 1213 } else { 1214 break; 1215 } 1216 } 1217 1218 try { 1219 return parseInt(out); 1220 } catch (e) { 1221 return null; 1222 } 1223 }; 1224 1225 var parseHex = function(input) { 1226 var out = ''; 1227 while (input.hasNext()) { 1228 var c = input.peek(); 1229 if (c.match(/[0-9A-Fa-f]/)) { 1230 out += c; 1231 input.next(); 1232 } else if (c == ';') { 1233 input.next(); 1234 break; 1235 } else { 1236 break; 1237 } 1238 } 1239 try { 1240 return parseInt(out, 16); 1241 } catch (e) { 1242 return null; 1243 } 1244 }; 1245 1246 var getNamedEntity = function(input) { 1247 var entity = ''; 1248 while (input.hasNext()) { 1249 var c = input.peek(); 1250 if (c.match(/[A-Za-z]/)) { 1251 entity += c;
1252 input.next(); 1253 if (entityToCharacterMap.containsKey('&' + entity)) { 1254 if (input.peek(';')) input.next(); 1255 break; 1256 } 1257 } else if (c == ';') { 1258 input.next(); 1259 } else { 1260 break; 1261 } 1262 } 1263 1264 return String.fromCharCode(entityToCharacterMap.getCaseInsensitive('&' + entity)); 1265 }; 1266 1267 return { 1268 encode: _super.encode, 1269 1270 decode: _super.decode, 1271 1272 encodeCharacter: function(aImmune, c) { 1273 if (aImmune.contains(c)) { 1274 return c; 1275 } 1276 1277 var hex = org.owasp.esapi.codecs.Codec.getHexForNonAlphanumeric(c); 1278 if (hex == null) { 1279 return c; 1280 } 1281 1282 var cc = c.charCodeAt(0); 1283 if (( cc <= 0x1f && c != '\t' && c != '\n' && c != '\r' ) || ( cc >= 0x7f && cc <= 0x9f ) || c == ' ') { 1284 return " "; 1285 } 1286 1287 var entityName = characterToEntityMap[cc]; 1288 if (entityName != null) { 1289 return entityName + ";"; 1290 } 1291 1292 return "&#x" + hex + ";"; 1293 }, 1294 1295 decodeCharacter: function(oPushbackString) { 1296 //noinspection UnnecessaryLocalVariableJS 1297 var input = oPushbackString; 1298 input.mark(); 1299 var first = input.next(); 1300 if (first == null || first != '&') { 1301 input.reset(); 1302 return null; 1303 } 1304 1305 var second = input.next(); 1306 if (second == null) { 1307 input.reset(); 1308 return null; 1309 } 1310 1311 if (second == '#') { 1312 var c = getNumericEntity(input); 1313 if (c != null) { 1314 return c; 1315 } 1316 } else if (second.match(/[A-Za-z]/)) { 1317 input.pushback(second); 1318 c = getNamedEntity(input); 1319 if (c != null) { 1320 return c; 1321 } 1322 } 1323 input.reset(); 1324 return null; 1325 } 1326 }; 1327};
1328 1329 1330$namespace('org.owasp.esapi.codecs'); 1331 1332org.owasp.esapi.codecs.JavascriptCodec = function() { 1333 var _super = new org.owasp.esapi.codecs.Codec(); 1334 1335 return { 1336 encode: function(aImmune, sInput) { 1337 var out = ''; 1338 for (var idx = 0; idx < sInput.length; idx ++) { 1339 var ch = sInput.charAt(idx); 1340 if (aImmune.contains(ch)) { 1341 out += ch; 1342 } 1343 else { 1344 var hex = org.owasp.esapi.codecs.Codec.getHexForNonAlphanumeric(ch); 1345 if (hex == null) { 1346 out += ch; 1347 } 1348 else { 1349 var tmp = ch.charCodeAt(0).toString(16); 1350 if (ch.charCodeAt(0) < 256) { 1351 var pad = "00".substr(tmp.length); 1352 out += "\\x" + pad + tmp.toUpperCase(); 1353 } 1354 else { 1355 pad = "0000".substr(tmp.length); 1356 out += "\\u" + pad + tmp.toUpperCase(); 1357 } 1358 } 1359 } 1360 } 1361 return out; 1362 }, 1363 1364 decode: _super.decode, 1365 1366 decodeCharacter: function(oPushbackString) { 1367 oPushbackString.mark(); 1368 var first = oPushbackString.next(); 1369 if (first == null) { 1370 oPushbackString.reset(); 1371 return null; 1372 } 1373 1374 if (first != '\\') { 1375 oPushbackString.reset(); 1376 return null; 1377 } 1378 1379 var second = oPushbackString.next(); 1380 if (second == null) { 1381 oPushbackString.reset(); 1382 return null; 1383 } 1384 1385 // \0 collides with the octal decoder and is non-standard 1386 // if ( second.charValue() == '0' ) { 1387 // return Character.valueOf( (char)0x00 ); 1388 if (second == 'b') { 1389 return 0x08; 1390 } else if (second == 't') { 1391 return 0x09; 1392 } else if (second == 'n') { 1393 return 0x0a; 1394 } else if (second == 'v') { 1395 return 0x0b; 1396 } else if (second == 'f') { 1397 return 0x0c; 1398 } else if (second == 'r') { 1399 return 0x0d; 1400 } else if (second == '\"') { 1401 return 0x22; 1402 } else if (second == '\'') { 1403 return 0x27; 1404 } else if (second == '\\') { 1405 return 0x5c; 1406 } else if (second.toLowerCase() == 'x') { 1407 out = ''; 1408 for (var i = 0; i < 2; i++) { 1409 var c = oPushbackString.nextHex(); 1410 if (c != null) { 1411 out += c; 1412 } else { 1413 input.reset(); 1414 return null; 1415 } 1416 } 1417 try { 1418 n = parseInt(out, 16); 1419 return String.fromCharCode(n); 1420 } catch (e) { 1421 oPushbackString.reset(); 1422 return null; 1423 } 1424 } else if (second.toLowerCase() == 'u') { 1425 out = ''; 1426 for (i = 0; i < 4; i++) { 1427 c = oPushbackString.nextHex(); 1428 if (c != null) { 1429 out += c; 1430 } else { 1431 input.reset(); 1432 return null; 1433 } 1434 } 1435 try { 1436 var n = parseInt(out, 16); 1437 return String.fromCharCode(n); 1438 } catch (e) { 1439 oPushbackString.reset(); 1440 return null; 1441 } 1442 } else if (oPushbackString.isOctalDigit(second)) { 1443 var out = second; 1444 var c2 = oPushbackString.next(); 1445 if (!oPushbackString.isOctalDigit(c2)) { 1446 oPushbackString.pushback(c2); 1447 } else { 1448 out += c2; 1449 var c3 = oPushbackString.next(); 1450 if (!oPushbackString.isOctalDigit(c3)) { 1451 oPushbackString.pushback(c3); 1452 } else { 1453 out += c3; 1454 } 1455 } 1456 1457 try { 1458 n = parseInt(out, 8); 1459 return String.fromCharCode(n); 1460 } catch (e) { 1461 oPushbackString.reset(); 1462 return null; 1463 } 1464 } 1465 return second; 1466 } 1467 }; 1468};
1469 1470 1471$namespace('org.owasp.esapi.codecs'); 1472 1473org.owasp.esapi.codecs.PercentCodec = function() { 1474 var _super = new org.owasp.esapi.codecs.Codec(); 1475 1476 var ALPHA_NUMERIC_STR = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"; 1477 var RFC_NON_ALPHANUMERIC_UNRESERVED_STR = "-._~"; 1478 var ENCODED_NON_ALPHA_NUMERIC_UNRESERVED = true; 1479 var UNENCODED_STR = ALPHA_NUMERIC_STR + (ENCODED_NON_ALPHA_NUMERIC_UNRESERVED ? "" : RFC_NON_ALPHANUMERIC_UNRESERVED_STR); 1480 1481 var getTwoUpperBytes = function(b) { 1482 var out = ''; 1483 if (b < -128 || b > 127) { 1484 throw new IllegalArgumentException("b is not a byte (was " + b + ")"); 1485 } 1486 b &= 0xFF; 1487 if (b < 0x10) { 1488 out += '0'; 1489 } 1490 return out + b.toString(16).toUpperCase(); 1491 }; 1492 1493 return { 1494 encode: _super.encode, 1495 1496 decode: _super.decode, 1497 1498 encodeCharacter: function(aImmune, c) { 1499 if (UNENCODED_STR.indexOf(c) > -1) { 1500 return c; 1501 } 1502 1503 var bytes = org.owasp.esapi.codecs.UTF8.encode(c); 1504 var out = ''; 1505 for (var b = 0; b < bytes.length; b++) { 1506 out += '%' + getTwoUpperBytes(bytes.charCodeAt(b)); 1507 } 1508 return out; 1509 }, 1510 1511 decodeCharacter: function(oPushbackString) { 1512 oPushbackString.mark(); 1513 var first = oPushbackString.next(); 1514 if (first == null || first != '%') { 1515 oPushbackString.reset(); 1516 return null; 1517 } 1518 1519 var out = ''; 1520 for (var i = 0; i < 2; i++) { 1521 var c = oPushbackString.nextHex(); 1522 if (c != null) { 1523 out += c; 1524 } 1525 } 1526 if (out.length == 2) { 1527 try { 1528 var n = parseInt(out, 16); 1529 return String.fromCharCode(n); 1530 } catch (e) { 1531 } 1532 } 1533 oPushbackString.reset(); 1534 return null; 1535 } 1536 }; 1537};
1538 1539 1540$namespace('org.owasp.esapi.codecs'); 1541 1542org.owasp.esapi.codecs.PushbackString = function(sInput) { 1543 var _input = sInput, 1544 _pushback = '', 1545 _temp = '', 1546 _index = 0, 1547 _mark = 0; 1548 1549 return { 1550 pushback: function(c) { 1551 _pushback = c; 1552 }, 1553 1554 index: function() { 1555 return _index; 1556 }, 1557 1558 hasNext: function() { 1559 if (_pushback != null) return true; 1560 return !(_input == null || _input.length == 0 || _index >= _input.length); 1561 1562 }, 1563 1564 next: function() { 1565 if (_pushback != null) { 1566 var save = _pushback; 1567 _pushback = null; 1568 return save; 1569 } 1570 if (_input == null || _input.length == 0 || _index >= _input.length) { 1571 return null; 1572 } 1573 return _input.charAt(_index++); 1574 }, 1575 1576 nextHex: function() { 1577 var c = this.next(); 1578 if (this.isHexDigit(c)) return c; 1579 return null; 1580 }, 1581 1582 nextOctal: function() { 1583 var c = this.next(); 1584 if (this.isOctalDigit(c)) return c; 1585 return null; 1586 }, 1587 1588 isHexDigit: function(c) { 1589 return c != null && ( ( c >= '0' && c <= '9' ) || ( c >= 'a' && c <= 'f' ) || ( c >= 'A' && c <= 'F' ) ); 1590 }, 1591 1592 isOctalDigit: function(c) { 1593 return c != null && ( c >= '0' && c <= '7' ); 1594 }, 1595 1596 peek: function(c) { 1597 if (!c) { 1598 if (_pushback != null) return _pushback; 1599 if (_input == null || _input.length == 0 || _index >= _input.length) return null; 1600 return _input.charAt(_index); 1601 } else { 1602 if (_pushback != null && _pushback == c) return true; 1603 if (_input == null || _input.length == 0 || _index >= _input.length) return false; 1604 return _input.charAt(_index) == c; 1605 } 1606 }, 1607 1608 mark: function() { 1609 _temp = _pushback; 1610 _mark = _index; 1611 }, 1612 1613 reset: function() { 1614 _pushback = _temp; 1615 _index = _mark; 1616 }, 1617 1618 remainder: function() { 1619 var out = _input.substr(_index); 1620 if (_pushback != null) { 1621 out = _pushback + out; 1622 } 1623 return out; 1624 } 1625 }; 1626};
1627 1628 1629$namespace('org.owasp.esapi.codecs'); 1630 1631org.owasp.esapi.codecs.UTF8 = { 1632 encode: function(sInput) { 1633 var input = sInput.replace(/\r\n/g, "\n"); 1634 var utftext = ''; 1635 1636 for (var n = 0; n < input.length; n ++) { 1637 var c = input.charCodeAt(n); 1638 1639 if (c < 128) { 1640 utftext += String.fromCharCode(c); 1641 } 1642 else if (( c > 127) && (c < 2048)) { 1643 utftext += String.fromCharCode((c >> 6) | 192); 1644 utftext += String.fromCharCode((c & 63) | 128); 1645 } 1646 else { 1647 utftext += String.fromCharCode((c >> 12) | 224); 1648 utftext += String.fromCharCode(((c >> 6) & 63) | 128); 1649 utftext += String.fromCharCode((c & 63) | 128); 1650 } 1651 } 1652 1653 return utftext; 1654 } 1655 , 1656 1657 decode: function(sInput) { 1658 var out = ''; 1659 var i = c = c1 = c2 = 0; 1660 1661 while (i < sInput.length) { 1662 c = sInput.charCodeAt(i); 1663 1664 if (c < 128) { 1665 out += String.fromCharCode(c); 1666 i ++; 1667 } 1668 else if ((c > 191) && (c < 224)) { 1669 c2 = sInput.charCodeAt(i + 1); 1670 out += String.fromCharCode(((c & 31) << 6) | (c2 & 63)); 1671 i += 2; 1672 } 1673 else { 1674 c2 = utftext.charCodeAt(i + 1); 1675 c3 = utftext.charCodeAt(i + 2); 1676 string += String.fromCharCode(((c & 15) << 12) | ((c2 & 63) << 6) | (c3 & 63)); 1677 i += 3; 1678 } 1679 } 1680 1681 return out; 1682 } 1683}; 1684 1685 1686$namespace('org.owasp.esapi.i18n'); 1687 1688org.owasp.esapi.i18n.ArrayResourceBundle = function( sName, oLocale, aMessages, oParent ) { 1689 with(org.owasp.esapi.i18n) var _super = new ResourceBundle( sName, oLocale, oParent ); 1690 1691 var messages = aMessages; 1692 1693 return { 1694 getParent: _super.getParent, 1695 getLocale: _super.getLocale, 1696 getName: _super.getName, 1697 getString: _super.getString, 1698 getMessage: function(sKey) { 1699 return messages[sKey]; 1700 } 1701 }; 1702};
1703 1704 1705$namespace('org.owasp.esapi.i18n'); 1706 1707org.owasp.esapi.i18n.Locale = function( sLanguage, sCountry, sVariant ) { 1708 var language = sLanguage, country = sCountry, variant = sVariant; 1709 1710 return { 1711 getLanguage: function() { return language; }, 1712 getCountry: function() { return country; }, 1713 getVariant: function() { return variant; }, 1714 toString: function() { return language + ( country ? "-" + country + ( variant ? "-" + variant : "" ) : "" ); } 1715 }; 1716}; 1717 1718org.owasp.esapi.i18n.Locale.US = new org.owasp.esapi.i18n.Locale("en","US"); 1719org.owasp.esapi.i18n.Locale.GB = new org.owasp.esapi.i18n.Locale("en","GB"); 1720 1721org.owasp.esapi.i18n.Locale.getLocale = function(sLocale) { 1722 var l = sLocale.split("-"); 1723 return new org.owasp.esapi.i18n.Locale( l[0], (l.length>1?l[1]:""), (l.length>2?l.length[2]:"")); 1724}; 1725 1726org.owasp.esapi.i18n.Locale.getDefault = function() { 1727 var l = (navigator['language']?navigator['language']:(navigator['userLanguage']?navigator['userLanguage']:'en-US')).split("-"); 1728 return new org.owasp.esapi.i18n.Locale( l[0], (l.length>1?l[1]:""), (l.length>2?l.length[2]:"")); 1729}; 1730 1731 1732$namespace('org.owasp.esapi.i18n'); 1733 1734org.owasp.esapi.i18n.ObjectResourceBundle = function( oResource, oParent ) { 1735 var _super = new org.owasp.esapi.i18n.ResourceBundle( oResource.name, org.owasp.esapi.i18n.Locale.getLocale(oResource.locale), oParent ); 1736 1737 var messages = oResource.messages; 1738 1739 return { 1740 getParent: _super.getParent, 1741 getLocale: _super.getLocale, 1742 getName: _super.getName, 1743 getString: _super.getString, 1744 getMessage: function(sKey) { 1745 return messages[sKey]; 1746 } 1747 }; 1748};
1749 1750 1751$namespace('org.owasp.esapi.i18n'); 1752 1753org.owasp.esapi.i18n.ResourceBundle = function( sName, oLocale, oParentResourceBundle ) { 1754 var parent = oParentResourceBundle; 1755 var locale = oLocale; 1756 var name = sName; 1757 1758 if ( !name ) throw new SyntaxError("Name required for implementations of org.owasp.esapi.i18n.ResourceBundle"); 1759 if ( !locale ) throw new SyntaxError("Locale required for implementations of org.owasp.esapi.i18n.ResourceBundle"); 1760 1761 return { 1762 getParent: function() { return parent; }, 1763 getLocale: function() { return locale; }, 1764 getName: function() { return name; }, 1765 getMessage: function(sKey) { return sKey; }, 1766 getString: function( sKey, oContextMap ) { 1767 if ( arguments.length < 1 ) { 1768 throw new IllegalArgumentException("No key passed to getString"); 1769 } 1770 1771 var msg = this.getMessage(sKey); 1772 if ( !msg ) { 1773 if ( parent ) { 1774 return parent.getString( sKey, oContextMap ); 1775 } else { 1776 return sKey; 1777 } 1778 } 1779 1780 if ( !msg.match( /\{([A-Za-z]+)\}/ ) || !oContextMap ) { 1781 return msg; 1782 } 1783 1784 var out = '', lastIndex = 0; 1785 while (true) { 1786 var nextVarIdx = msg.indexOf( "{", lastIndex ); 1787 var endIndex = msg.indexOf( "}", nextVarIdx ); 1788 1789 if ( nextVarIdx < 0 ) { 1790 out += msg.substr( lastIndex, msg.length-lastIndex ); 1791 break; 1792 } 1793 1794 if ( nextVarIdx >= 0 && endIndex < -1 ) { 1795 throw new SyntaxError("Invalid Message - Unclosed Context Reference: " + msg ); 1796 } 1797 1798 out += msg.substring( lastIndex, nextVarIdx ); 1799 var contextKey = msg.substring( nextVarIdx+1, endIndex ); 1800 if ( oContextMap[contextKey] ) { 1801 out += oContextMap[contextKey]; 1802 } else { 1803 out += msg.substring( nextVarIdx, endIndex+1 ); 1804 } 1805 1806 lastIndex = endIndex + 1; 1807 } 1808 1809 return out; 1810 } 1811 }; 1812};
1813 1814org.owasp.esapi.i18n.ResourceBundle.getResourceBundle = function(sResource, oLocale) { 1815 var classname = sResource + "_" + oLocale.toString().replace("-","_"); 1816 1817 with( org.owasp.esapi.i18n ) { 1818 if ( ResourceBundle[classname] instanceof Object ) { 1819 return ResourceBundle[classname]; 1820 } else { 1821 return new ResourceBundle[classname](); 1822 } 1823 } 1824}; 1825 1826$namespace('org.owasp.esapi.net'); 1827 1828/** 1829 * Constructs a cookie with a specified name and value. 1830 * <p/> 1831 * The name must conform to RFC 2109. That means it can contain only ASCII alphanumeric characters and cannot contain 1832 * commas, semicolons, or white space or begin with a $ character. The cookie's name cannot be changed after creation. 1833 * <p/> 1834 * The value can be anything the server chooses to send. Its value is probably of interest only to the server. The 1835 * cookie's value can be changed after creation with the setValue method. 1836 * <p/> 1837 * By default, cookies are created according to the Netscape cookie specification. The version can be changed with the 1838 * {@link #setVersion} method. 1839 * 1840 * @constructor 1841 * @param sName {String} a <code>String</code> specifying the name of the cookie 1842 * @param sValue {String} a <code>String</code> specifying the value of the cookie 1843 * @throws IllegalArgumentException 1844 * if the cookie name contains illegal characters (for example, a comma, space, or semicolon) or it is one of 1845 * the tokens reserved for use by the cookie protocol 1846 */ 1847org.owasp.esapi.net.Cookie = function( sName, sValue ) { 1848 var name; // NAME= ... "$Name" style is reserved 1849 var value; // value of NAME 1850 1851 var comment; // ;Comment=VALUE ... describes the cookies use 1852 var domain; // ;Domain=VALUE ... domain that sees the cookie 1853 var maxAge; // ;Max-Age=VALUE ... cookies auto-expire 1854 var path; // ;Path=VALUE ... URLs that see the cookie 1855 var secure; // ;Secure ... e.g. use SSL 1856 var version; // ;Version=1 ... means RFC-2109++ style 1857 1858 var _resourceBundle = $ESAPI.resourceBundle(); 1859 1860 var tSpecials = ",; "; 1861 1862 var isToken = function(sValue) { 1863 for(var i=0,len=sValue.length;i<len;i++) { 1864 var cc = sValue.charCodeAt(i),c=sValue.charAt(i); 1865 if (cc<0x20||cc>=0x7F||tSpecials.indexOf(c)!=-1) { 1866 return false; 1867 } 1868 } 1869 return true; 1870 }; 1871 1872 if ( !isToken(sName) 1873 || sName.toLowerCase() == 'comment' 1874 || sName.toLowerCase() == 'discard' 1875 || sName.toLowerCase() == 'domain' 1876 || sName.toLowerCase() == 'expires' 1877 || sName.toLowerCase() == 'max-age' 1878 || sName.toLowerCase() == 'path' 1879 || sName.toLowerCase() == 'secure' 1880 || sName.toLowerCase() == 'version' 1881 || sName.charAt(0) == '$' ) { 1882 var errMsg = _resourceBundle.getString( "Cookie.Name", { 'name':sName } ); 1883 throw new IllegalArgumentException(errMsg); 1884 } 1885 1886 name = sName; 1887 value = sValue; 1888 1889 return { 1890 setComment: function(purpose) { comment = purpose; }, 1891 getComment: function() { return comment; }, 1892 setDomain: function(sDomain) { domain = sDomain.toLowerCase(); }, 1893 getDomain: function() { return domain; }, 1894 setMaxAge: function(nExpirey) { maxAge = nExpirey; }, 1895 getMaxAge: function() { return maxAge; }, 1896 setPath: function(sPath) { path = sPath; }, 1897 getPath: function() { return path; }, 1898 setSecure: function(bSecure) { secure = bSecure; }, 1899 getSecure: function() { return secure; }, 1900 getName: function() { return name; }, 1901 setValue: function(sValue) { value = sValue; }, 1902 getValue: function() { return value; }, 1903 setVersion: function(nVersion) { 1904 if(nVersion<0||nVersion>1)throw new IllegalArgumentException(_resourceBundle.getString("Cookie.Version", { 'version':nVersion } ) ); 1905 version = nVersion; 1906 }, 1907 getVersion: function() { return version; } 1908 }; 1909};
1910 1911$namespace('org.owasp.esapi.reference.encoding'); 1912 1913org.owasp.esapi.reference.encoding.DefaultEncoder = function(aCodecs) { 1914 var _codecs = [], 1915 _htmlCodec = new org.owasp.esapi.codecs.HTMLEntityCodec(), 1916 _javascriptCodec = new org.owasp.esapi.codecs.JavascriptCodec(), 1917 _cssCodec = new org.owasp.esapi.codecs.CSSCodec(), 1918 _percentCodec = new org.owasp.esapi.codecs.PercentCodec(); 1919 1920 if (!aCodecs) { 1921 _codecs.push(_htmlCodec); 1922 _codecs.push(_javascriptCodec); 1923 _codecs.push(_cssCodec); 1924 _codecs.push(_percentCodec); 1925 } else { 1926 _codecs = aCodecs; 1927 } 1928 1929 var IMMUNE_HTML = new Array(',', '.', '-', '_', ' '); 1930 var IMMUNE_HTMLATTR = new Array(',', '.', '-', '_'); 1931 var IMMUNE_CSS = new Array(); 1932 var IMMUNE_JAVASCRIPT = new Array(',', '.', '_'); 1933 1934 return { 1935 cananicalize: function(sInput, bStrict) { 1936 if (!sInput) { 1937 return null; 1938 } 1939 var working = sInput, codecFound = null, mixedCount = 1, foundCount = 0, clean = false; 1940 while (!clean) { 1941 clean = true; 1942 1943 _codecs.each(function(codec) { 1944 var old = working; 1945 working = codec.decode(working); 1946 1947 if (old != working) { 1948 if (codecFound != null && codecFound != codec) { 1949 mixedCount ++; 1950 } 1951 codecFound = codec; 1952 if (clean) { 1953 foundCount ++; 1954 } 1955 clean = false; 1956 } 1957 }); 1958 } 1959 1960 if (foundCount >= 2 && mixedCount > 1) { 1961 if (bStrict) { 1962 throw new org.owasp.esapi.IntrusionException("Input validation failure", "Multiple (" + foundCount + "x) and mixed encoding (" + mixedCount + "x) detected in " + sInput); 1963 } 1964 } 1965 else if (foundCount >= 2) { 1966 if (bStrict) { 1967 throw new org.owasp.esapi.IntrusionException("Input validation failure", "Multiple (" + foundCount + "x) encoding detected in " + sInput); 1968 } 1969 } 1970 else if (mixedCount > 1) { 1971 if (bStrict) { 1972 throw new org.owasp.esapi.IntrusionException("Input validation failure", "Mixed (" + mixedCount + "x) encoding detected in " + sInput); 1973 } 1974 } 1975 return working; 1976 }, 1977 1978 normalize: function(sInput) { 1979 return sInput.replace(/[^\x00-\x7F]/g, ''); 1980 }, 1981 1982 encodeForHTML: function(sInput) { 1983 return !sInput ? null : _htmlCodec.encode(IMMUNE_HTML, sInput); 1984 }, 1985 1986 decodeForHTML: function(sInput) { 1987 return !sInput ? null : _htmlCodec.decode(sInput); 1988 }, 1989 1990 encodeForHTMLAttribute: function(sInput) { 1991 return !sInput ? null : _htmlCodec.encode(IMMUNE_HTMLATTR, sInput); 1992 }, 1993 1994 encodeForCSS: function(sInput) { 1995 return !sInput ? null : _cssCodec.encode(IMMUNE_CSS, sInput); 1996 }, 1997 1998 encodeForJavaScript: function(sInput) { 1999 return !sInput ? null : _javascriptCodec.encode(IMMUNE_JAVASCRIPT, sInput); 2000 }, 2001 2002 encodeForJavascript: this.encodeForJavaScript, 2003 2004 encodeForURL: function(sInput) { 2005 return !sInput ? null : escape(sInput); 2006 }, 2007 2008 decodeFromURL: function(sInput) { 2009 return !sInput ? null : unescape(sInput); 2010 }, 2011 2012 encodeForBase64: function(sInput) { 2013 return !sInput ? null : org.owasp.esapi.codecs.Base64.encode(sInput); 2014 }, 2015 2016 decodeFromBase64: function(sInput) { 2017 return !sInput ? null : org.owasp.esapi.codecs.Base64.decode(sInput); 2018 } 2019 }; 2020};
2021 2022 2023$namespace('org.owasp.esapi.reference.logging'); 2024 2025org.owasp.esapi.reference.logging.Log4JSLogFactory = function() { 2026 var loggersMap = Array(); 2027 2028 var Log4JSLogger = function( sModuleName ) { 2029 var jsLogger = null; 2030 var moduleName = sModuleName?sModuleName:null; 2031 var Level = Log4js.Level; 2032 2033 var logUrl = false, logApplicationName = false, encodingRequired = false, encodingFunction = $ESAPI.encoder().encodeForHTML; 2034 2035 jsLogger = Log4js.getLogger( moduleName ); 2036 2037 var convertESAPILevel = function( nLevel ) { 2038 var Logger = org.owasp.esapi.Logger; 2039 switch (nLevel) { 2040 case Logger.OFF: return Log4js.Level.OFF; 2041 case Logger.FATAL: return Log4js.Level.FATAL; 2042 case Logger.ERROR: return Log4js.Level.ERROR; 2043 case Logger.WARNING: return Log4js.Level.WARN; 2044 case Logger.INFO: return Log4js.Level.INFO; 2045 case Logger.DEBUG: return Log4js.Level.DEBUG; 2046 case Logger.TRACE: return Log4js.Level.TRACE; 2047 case Logger.ALL: return Log4js.Level.ALL; 2048 } 2049 }; 2050 2051 return { 2052 setLevel: function( nLevel ) { 2053 try { 2054 jsLogger.setLevel( convertESAPILevel( nLevel ) ); 2055 } catch (e) { 2056 this.error( org.owasp.esapi.Logger.SECURITY_FAILURE, "", e ); 2057 } 2058 }, 2059 2060 trace: function( oEventType, sMessage, oException ) { 2061 this.log( Level.TRACE, oEventType, sMessage, oException ); 2062 }, 2063 2064 debug: function( oEventType, sMessage, oException ) { 2065 this.log( Level.DEBUG, oEventType, sMessage, oException ); 2066 }, 2067 2068 info: function( oEventType, sMessage, oException ) { 2069 this.log( Level.INFO, oEventType, sMessage, oException ); 2070 }, 2071 2072 warning: function( oEventType, sMessage, oException ) { 2073 this.log( Level.WARN, oEventType, sMessage, oException ); 2074 }, 2075 2076 error: function( oEventType, sMessage, oException ) { 2077 this.log( Level.ERROR, oEventType, sMessage, oException ); 2078 }, 2079 2080 fatal: function( oEventType, sMessage, oException ) { 2081 this.log( Level.FATAL, oEventType, sMessage, oException ); 2082 }, 2083 2084 log: function( oLevel, oEventType, sMessage, oException ) { 2085 switch(oLevel) { 2086 case Level.TRACE: if ( !jsLogger.isTraceEnabled() ) { return; } break; 2087 case Level.DEBUG: if ( !jsLogger.isDebugEnabled() ) { return; } break; 2088 case Level.INFO: if ( !jsLogger.isInfoEnabled() ) { return; } break; 2089 case Level.WARNING: if ( !jsLogger.isWarnEnabled() ) { return; } break; 2090 case Level.ERROR: if ( !jsLogger.isErrorEnabled() ) { return; } break; 2091 case Level.FATAL: if ( !jsLogger.isFatalEnabled() ) { return; } break; 2092 } 2093 2094 if ( !sMessage ) { 2095 sMessage = ""; 2096 } 2097 2098 sMessage = '[' + oEventType.toString() + '] - ' + sMessage; 2099 2100 var clean = sMessage.replace("\n","_").replace("\r","_"); 2101 if ( encodingRequired ) { 2102 clean = encodingFunction(clean); 2103 if ( clean != sMessage) { 2104 clean += " [Encoded]"; 2105 } 2106 } 2107 2108 var appInfo = ( logUrl ? window.location.href : "" ) + 2109 ( logApplicationName ? "/" + $ESAPI.properties.application.Name : "" ); 2110 2111 jsLogger.log( oLevel, ( appInfo != "" ? "[" + appInfo + "] " : "" ) + clean, oException ); 2112 }, 2113 2114 addAppender: function( oAppender ) { 2115 jsLogger.addAppender( oAppender ); 2116 }, 2117 2118 isLogUrl: function() { return logUrl; }, 2119 setLogUrl: function(b) { logUrl = b; },
2120 isLogApplicationName: function() { return logApplicationName; }, 2121 setLogApplicationName: function(b) { logApplicationName = b; }, 2122 isEncodingRequired: function() { return encodingRequired; }, 2123 setEncodingRequired: function(b) { encodingRequired = b; }, 2124 setEncodingFunction: function(f) { encodingFunction = f; }, 2125 isDebugEnabled: function() { return jsLogger.isDebugEnabled(); }, 2126 isErrorEnabled: function() { return jsLogger.isErrorEnabled(); }, 2127 isFatalEnabled: function() { return jsLogger.isFatalEnabled(); }, 2128 isInfoEnabled: function() { return jsLogger.isInfoEnabled(); }, 2129 isTraceEnabled: function() { return jsLogger.isTraceEnabled(); }, 2130 isWarningEnabled: function() { return jsLogger.isWarnEnabled(); } 2131 }; 2132 }; 2133 2134 var getLoggerConfig = function( moduleName ) { 2135 var logConfig = $ESAPI.properties.logging; 2136 if ( logConfig[moduleName] ) { 2137 logConfig = logConfig[moduleName]; 2138 } 2139 return logConfig; 2140 }; 2141 2142 return { 2143 getLogger: function ( moduleName ) { 2144 var key = ( typeof moduleName == 'string' ) ? moduleName : moduleName.constructor.toString(); 2145 var logger = loggersMap[key]; 2146 if ( !logger ) { 2147 logger = new Log4JSLogger(key); 2148 2149 var logConfig = getLoggerConfig(moduleName); 2150 2151 logger.setLevel( logConfig.Level ); 2152 logger.setLogUrl( logConfig.LogUrl ); 2153 logger.setLogApplicationName( logConfig.LogApplicationName ); 2154 logger.setEncodingRequired( logConfig.EncodingRequired ); 2155 2156 if ( logConfig.EncodingFunction ) { 2157 logger.setEncodingFunction( logConfig.EncodingFunction ); 2158 } 2159 2160 logConfig.Appenders.each(function(e){ 2161 if ( logConfig.Layout ) { 2162 e.setLayout( logConfig.Layout ); 2163 } 2164 logger.addAppender(e); 2165 }); 2166 2167 loggersMap[key] = logger; 2168 } 2169 return logger; 2170 } 2171 }; 2172};
2173 2174 2175$namespace('org.owasp.esapi.reference.validation'); 2176 2177org.owasp.esapi.reference.validation.BaseValidationRule = function( sTypeName, oEncoder, oLocale ) { 2178 var log = $ESAPI.logger( "Validation" ); 2179 var EventType = org.owasp.esapi.Logger.EventType; 2180 2181 var typename = sTypeName; 2182 var encoder = oEncoder?oEncoder:$ESAPI.encoder(); 2183 var allowNull = false; 2184 2185 var ResourceBundle = org.owasp.esapi.i18n.ResourceBundle; 2186 2187 var locale = oLocale?oLocale:$ESAPI.locale(); 2188 var resourceBundle; 2189 2190 if ( $ESAPI.properties.validation.ResourceBundle ) { 2191 resourceBundle = ResourceBundle.getResourceBundle( $ESAPI.properties.validation.ResourceBundle, locale ); 2192 } 2193 2194 if ( !resourceBundle ) { 2195 resourceBundle = $ESAPI.resourceBundle(); 2196 log.info( EventType.EVENT_FAILURE, "No Validation ResourceBundle - Defaulting to " + resourceBundle.getName() + "(" + resourceBundle.getLocale().toString() + ")" ); 2197 } 2198 2199 log.info( EventType.EVENT_SUCCESS, "Validation Rule Initialized with ResourceBundle: " + resourceBundle.getName() ); 2200 2201 return { 2202 setAllowNull: function(b) { allowNull = b; }, 2203 2204 isAllowNull: function() { return allowNull; }, 2205 2206 getTypeName: function() { return typename; }, 2207 2208 setTypeName: function(s) { typename = s; }, 2209 2210 setEncoder: function(oEncoder) { encoder = oEncoder; }, 2211 2212 getEncoder: function() { return encoder; }, 2213 2214 assertValid: function( sContext, sInput ) { 2215 this.getValid( sContext, sInput ); 2216 }, 2217 2218 getValid: function( sContext, sInput, oValidationErrorList ) { 2219 var valid = null; 2220 try { 2221 valid = this.getValidInput( sContext, sInput ); 2222 } catch (oValidationException) { 2223 return this.sanitize( sContext, sInput ); 2224 } 2225 return valid; 2226 }, 2227 2228 getValidInput: function( sContext, sInput ) { 2229 return sInput; 2230 }, 2231 2232 getSafe: function( sContext, sInput ) { 2233 var valid = null; 2234 try { 2235 valid = this.getValidInput( sContext, sInput ); 2236 } catch (oValidationException) { 2237 return this.sanitize( sContext, sInput ); 2238 } 2239 return valid; 2240 }, 2241 2242 /** 2243 * The method is similar to ValidationRuile.getSafe except that it returns a 2244 * harmless object that <b>may or may not have any similarity to the original 2245 * input (in some cases you may not care)</b>. In most cases this should be the 2246 * same as the getSafe method only instead of throwing an exception, return 2247 * some default value. 2248 * 2249 * @param context 2250 * @param input 2251 * @return a parsed version of the input or a default value. 2252 */ 2253 sanitize: function( sContext, sInput ) { 2254 return sInput; 2255 }, 2256 2257 isValid: function( sContext, sInput ) { 2258 var valid = false; 2259 try { 2260 this.getValidInput( sContext, sInput ); 2261 valid = true; 2262 } catch (oValidationException) { 2263 return false; 2264 } 2265 return valid; 2266 }, 2267 2268 /** 2269 * Removes characters that aren't in the whitelist from the input String. 2270 * O(input.length) whitelist performance 2271 * @param input String to be sanitized 2272 * @param whitelist allowed characters 2273 * @return input stripped of all chars that aren't in the whitelist 2274 */ 2275 whitelist: function( sInput, aWhitelist ) { 2276 var stripped = ''; 2277 for ( var i=0;i<sInput.length;i++ ) { 2278 var c = sInput.charAt(i); 2279 if ( aWhitelist.contains(c) ) { 2280 stripped += c; 2281 } 2282 } 2283 return stripped; 2284 }, 2285 2286 getUserMessage: function( sContext, sDefault, oContextValues ) { 2287 return this.getMessage( sContext+".Usr", sDefault+".Usr", oContextValues ); 2288 }, 2289 2290 getLogMessage: function( sContext, sDefault, oContextValues ) { 2291 return this.getMessage( sContext+".Log", sDefault+".Log", oContextValues ); 2292 }, 2293 2294 getMessage: function( sContext, sDefault, oContextValues ) { 2295 return resourceBundle.getString( sContext, oContextValues ) ? resourceBundle.getString( sContext, oContextValues ) : resourceBundle.getString( sDefault, oContextValues ); 2296 }, 2297 2298 validationException: function( sContext, sDefault, sValidation, oContextValues ) { 2299 throw new org.owasp.esapi.reference.validation.ValidationException( 2300 this.getUserMessage( sContext+"."+sValidation, sDefault+"."+sValidation, oContextValues ), 2301 this.getLogMessage( sContext+"."+sValidation, sDefault+"."+sValidation, oContextValues ), 2302 sContext 2303 ); 2304 } 2305 }; 2306};
2307 2308 2309$namespace('org.owasp.esapi.reference.validation'); 2310 2311org.owasp.esapi.reference.validation.CreditCardValidationRule = function( sTypeName, oEncoder, oLocale ) { 2312 var _super = new org.owasp.esapi.reference.validation.BaseValidationRule( sTypeName, oEncoder, oLocale ); 2313 var _validationType = "CreditCard"; 2314 2315 var maxCardLength = 19; 2316 var ccrule; 2317 2318 var readDefaultCreditCardRule = function() { 2319 var p = new RegExp( $ESAPI.properties.validation.CreditCard ); 2320 var ccr = new org.owasp.esapi.reference.validation.StringValidationRule( "ccrule", _super.getEncoder(), oLocale, p ); 2321 ccr.setMaxLength( maxCardLength ); 2322 ccr.setAllowNull( false ); 2323 return ccr; 2324 }; 2325 2326 ccRule = readDefaultCreditCardRule(); 2327 2328 var validCreditCardFormat = function( ccNum ) { 2329 var digitsonly = ''; 2330 var c; 2331 for (var i=0;o<ccNum.length;i++) { 2332 c = ccNum.charAt(i); 2333 if ( c.match( /[0-9]/ ) ) digitsonly += c; 2334 } 2335 2336 var sum = 0, digit = 0, addend = 0, timesTwo = false; 2337 2338 for (var j=digitsonly.length-1; j>=0; j--) { 2339 digit = parseInt(digitsonly.substring(j,i+1)); 2340 if ( timesTwo ) { 2341 addend = digit * 2; 2342 if ( addend > 9 ) addend -= 9; 2343 } else { 2344 addend = digit; 2345 } 2346 sum += addend; 2347 timesTwo = !timesTwo; 2348 } 2349 return sum % 10 == 0; 2350 }; 2351 2352 return { 2353 getMaxCardLength: function() { return maxCardLength; }, 2354 2355 setMaxCardLength: function(n) { maxCardLength = n; }, 2356 2357 setAllowNull: _super.setAllowNull, 2358 2359 isAllowNull: _super.isAllowNull, 2360 2361 getTypeName: _super.getTypeName, 2362 2363 setTypeName: _super.setTypeName, 2364 2365 setEncoder: _super.setEncoder, 2366 2367 getEncoder: _super.getEncoder, 2368 2369 assertValid: _super.assertValid, 2370 2371 getValid: _super.getValid, 2372 2373 getValidInput: function( sContext, sInput ) { 2374 if ( !sInput || sInput.trim() == '' ) { 2375 if ( this.isAllowNull() ) { 2376 return null; 2377 } 2378 _super.validationException( sContext, _validationType, "Required", { "context":sContext, "input":sInput } ); 2379 } 2380 2381 var canonical = ccrule.getValid( sContext, sInput ); 2382 2383 if ( !validCreditCardFormat(canonical) ) { 2384 _super.validationException( sContext, _validationType, "Invalid", { "context":sContext, "input":sInput } ); 2385 } 2386 2387 return canonical; 2388 }, 2389 2390 getSafe: _super.getSafe, 2391 2392 sanitize: function( sContext, sInput ) { 2393 return this.whitelist( sInput, org.owasp.esapi.EncoderConstants.CHAR_DIGITS ); 2394 }, 2395 2396 isValid: _super.isValid, 2397 2398 whitelist: _super.whitelist 2399 }; 2400};
2401 2402 2403$namespace('org.owasp.esapi.reference.validation'); 2404 2405org.owasp.esapi.reference.validation.DateValidationRule = function( sTypeName, oEncoder, oLocale ) { 2406 var _super = new org.owasp.esapi.reference.validation.BaseValidationRule( sTypeName, oEncoder, oLocale ); 2407 var _validationTarget = "Date"; 2408 2409 var format = DateFormat.getDateInstance(); 2410 2411 var safelyParse = function(sContext,sInput) { 2412 if ( !sContext || sContext.trim() == '' ) { 2413 if ( _super.isAllowNull() ) { 2414 return null; 2415 } 2416 _super.validationException( sContext, _validationTarget, "Required", { "context":sContext, "input":sInput, "format":format } ); 2417 } 2418 2419 var canonical = _super.getEncoder().cananicalize(sInput); 2420 2421 try { 2422 return format.parse(canonical); 2423 } catch (e) { 2424 _super.validationException( sContext, _validationTarget, "Invalid", { "context":sContext, "input":sInput, "format":format } ); 2425 } 2426 }; 2427 2428 return { 2429 setDateFormat: function(fmt) { 2430 if ( !fmt ) { 2431 throw new IllegalArgumentException("DateValidationRule.setDateFormat requires a non-null DateFormat"); 2432 } 2433 format = fmt; 2434 }, 2435 2436 setAllowNull: _super.setAllowNull, 2437 2438 isAllowNull: _super.isAllowNull, 2439 2440 getTypeName: _super.getTypeName, 2441 2442 setTypeName: _super.setTypeName, 2443 2444 setEncoder: _super.setEncoder, 2445 2446 getEncoder: _super.getEncoder, 2447 2448 assertValid: _super.assertValid, 2449 2450 getValid: _super.getValid, 2451 2452 getValidInput: function( sContext, sInput ) { 2453 return safelyParse(sContext,sInput); 2454 }, 2455 2456 getSafe: _super.getSafe, 2457 2458 sanitize: function( sContext, sInput ) { 2459 var date = new Date(0); 2460 try { 2461 date = safelyParse(sContext,sInput); 2462 } catch (e) { } 2463 return date; 2464 }, 2465 2466 isValid: _super.isValid, 2467 2468 whitelist: _super.whitelist 2469 }; 2470};
2471 2472 2473$namespace('org.owasp.esapi.reference.validation'); 2474 2475org.owasp.esapi.reference.validation.DefaultValidator = function( oEncoder, oLocale ) { 2476 var rules = Array(); 2477 var encoder = oEncoder?oEncoder:$ESAPI.encoder(); 2478 var locale = oLocale?oLocale:org.owasp.esapi.i18n.Locale.getDefault(); 2479 2480 var p = org.owasp.esapi.reference.validation; 2481 2482 return { 2483 addRule: function( oValidationRule ) { 2484 rules[oValidationRule.getName()] = oValidationRule; 2485 }, 2486 2487 getRule: function( sName ) { 2488 return rules[sName]; 2489 }, 2490 2491 isValidInput: function( sContext, sInput, sType, nMaxLength, bAllowNull ) { 2492 try { 2493 this.getValidInput( sContext, sInput, sType, nMaxLength, bAllowNull ); 2494 return true; 2495 } catch (e) { 2496 return false; 2497 } 2498 }, 2499 2500 getValidInput: function( sContext, sInput, sType, nMaxLength, bAllowNull, oValidationErrorList ) { 2501 var rvr = new org.owasp.esapi.reference.validation.StringValidationRule( sType, encoder, locale ); 2502 var p = new RegExp($ESAPI.properties.validation[sType]); 2503 if ( p && p instanceof RegExp ) { 2504 rvr.addWhitelistPattern( p ); 2505 } else { 2506 throw new IllegalArgumentException("Invalid Type: " + sType + " not found."); 2507 } 2508 rvr.setMaxLength( nMaxLength ); 2509 rvr.setAllowNull( bAllowNull ); 2510 2511 try { 2512 return rvr.getValid(sContext,sInput); 2513 } catch (e) { 2514 if ( e instanceof p.ValidationErrorList && oValidationErrorList ) { 2515 oValidationErrorList.addError( sContext, e ); 2516 } 2517 throw e; 2518 } 2519 }, 2520 2521 isValidDate: function( sContext, sInput, oDateFormat, bAllowNull ) { 2522 try { 2523 this.getValidDate( sContext, sInput, oDateFormat, bAllowNull ); 2524 return true; 2525 } catch (e) { 2526 return false; 2527 } 2528 }, 2529 2530 getValidDate: function( sContext, sInput, oDateFormat, bAllowNull, oValidationErrorList ) { 2531 var dvr = new p.DateValidationRule( sContext, encoder, locale ); 2532 dvr.setAllowNull( bAllowNull ); 2533 dvr.setDateFormat(oDateFormat); 2534 try { 2535 return dvr.getValid( sContext, sInput ); 2536 } catch (e) { 2537 if ( e instanceof p.ValidationErrorList && oValidationErrorList ) { 2538 oValidationErrorList.addError( sContext, e ); 2539 } 2540 throw e; 2541 } 2542 }, 2543 2544 getValidCreditCard: function( sContext, sInput, bAllowNull, oValidationErrorList ) { 2545 var ccr = new p.CreditCardValidationRule( sContext, encoder, locale ); 2546 ccr.setAllowNull(bAllowNull); 2547 2548 try { 2549 return ccr.getValid(sContext,sInput); 2550 } catch (e) { 2551 if ( e instanceof p.ValidationErrorList && oValidationErrorList ) { 2552 oValidationErrorList.addError( sContext, e ); 2553 } 2554 throw e; 2555 } 2556 }, 2557 2558 isValidCreditCard: function( sContext, sInput, bAllowNull ) { 2559 try { 2560 this.getValidCreditCard( sContext,sInput,bAllowNull ); 2561 return true; 2562 } catch (e) { 2563 return false; 2564 } 2565 }, 2566 2567 getValidNumber: function( sContext, sInput, bAllowNull, nMinValue, nMaxValue, oValidationErrorList ) { 2568 var nvr = new p.NumberValidationRule( sContext, encoder, locale, nMinValue, nMaxValue ); 2569 nvr.setAllowNull(bAllowNull); 2570 2571 try { 2572 return nvr.getValid(sContext, sInput); 2573 } catch(e) { 2574 if ( e instanceof p.ValidationErrorList && oValidationErrorList ) { 2575 oValidationErrorList.addError( sContext, e ); 2576 } 2577 throw e; 2578 } 2579 }, 2580 2581 isValidNumber: function( sContext, sInput, bAllowNull, nMinValue, nMaxValue ) { 2582 try { 2583 this.getValidNumber(sContext,sInput,bAllowNull,nMinValue,nMaxValue); 2584 return true; 2585 } catch (e) { 2586 return false; 2587 } 2588 }, 2589 2590 getValidInteger: function( sContext, sInput, bAllowNull, nMinValue, nMaxValue, oValidationErrorList ) { 2591 var nvr = new p.IntegerValidationRule( sContext, encoder, locale, nMinValue, nMaxValue ); 2592 nvr.setAllowNull(bAllowNull); 2593 2594 try { 2595 return nvr.getValid(sContext, sInput); 2596 } catch(e) { 2597 if ( e instanceof p.ValidationErrorList && oValidationErrorList ) { 2598 oValidationErrorList.addError( sContext, e ); 2599 } 2600 throw e; 2601 } 2602 }, 2603 2604 isValidInteger: function( sContext, sInput, bAllowNull, nMinValue, nMaxValue ) { 2605 try { 2606 this.getValidInteger(sContext,sInput,bAllowNull,nMinValue,nMaxValue); 2607 return true; 2608 } catch (e) { 2609 return false; 2610 } 2611 } 2612 }; 2613};
2614 2615 2616$namespace('org.owasp.esapi.reference.validation'); 2617 2618org.owasp.esapi.reference.validation.IntegerValidationRule = function( sTypeName, oEncoder, oLocale, nMinValue, nMaxValue ) { 2619 var _super = new org.owasp.esapi.reference.validation.BaseValidationRule( sTypeName, oEncoder, oLocale ); 2620 var _validationTarget = "Integer"; 2621 2622 var minValue = nMinValue?nMinValue:Number.MIN_VALUE; 2623 var maxValue = nMaxValue?nMaxValue:Number.MAX_VALUE; 2624 2625 if ( minValue >= maxValue ) { 2626 throw new IllegalArgumentException( "minValue must be less than maxValue" ); 2627 } 2628 2629 var safelyParse = function(sContext,sInput) { 2630 if ( !sInput || sInput.trim() == '' ) { 2631 if ( _super.allowNull() ) { 2632 return null; 2633 } 2634 _super.validationException( sContext, _validationTarget, "Required", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2635 } 2636 2637 var canonical = _super.getEncoder().cananicalize(sInput); 2638 2639 var n = parseInt(canonical); 2640 if ( n == 'NaN' ) { 2641 _super.validationException( sContext, _validationTarget, "NaN", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2642 } 2643 if ( n < minValue ) { 2644 _super.validationException( sContext, _validationTarget, "MinValue", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2645 } 2646 if ( n > maxValue ) { 2647 _super.validationException( sContext, _validationTarget, "MaxValue", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2648 } 2649 return n; 2650 }; 2651 2652 return { 2653 setMinValue: function(n) { minValue = n; }, 2654 2655 getMinValue: function() { return minValue; }, 2656 2657 setMaxValue: function(n) { maxValue = n; }, 2658 2659 getMaxValue: function() { return maxValue; }, 2660 2661 setAllowNull: _super.setAllowNull, 2662 2663 isAllowNull: _super.isAllowNull, 2664 2665 getTypeName: _super.getTypeName, 2666 2667 setTypeName: _super.setTypeName, 2668 2669 setEncoder: _super.setEncoder, 2670 2671 getEncoder: _super.getEncoder, 2672 2673 assertValid: _super.assertValid, 2674 2675 getValid: _super.getValid, 2676 2677 getValidInput: function( sContext, sInput ) { 2678 return safelyParse(sContext,sInput); 2679 }, 2680 2681 getSafe: _super.getSafe, 2682 2683 sanitize: function( sContext, sInput ) { 2684 var n = 0; 2685 try { 2686 n = safelyParse(sContext,sInput); 2687 } catch (e) { } 2688 return n; 2689 }, 2690 2691 isValid: _super.isValid, 2692 2693 whitelist: _super.whitelist 2694 }; 2695};
2696 2697 2698$namespace('org.owasp.esapi.reference.validation'); 2699 2700org.owasp.esapi.reference.validation.NumberValidationRule = function( sTypeName, oEncoder, oLocale, fMinValue, fMaxValue ) { 2701 var _super = new org.owasp.esapi.reference.validation.BaseValidationRule( sTypeName, oEncoder, oLocale ); 2702 var _validationTarget = 'Number'; 2703 2704 var minValue = fMinValue?fMinValue:Number.MIN_VALUE; 2705 var maxValue = fMaxValue?fMaxValue:Number.MAX_VALUE; 2706 2707 if ( minValue >= maxValue ) throw new IllegalArgumentException("MinValue must be less that MaxValue"); 2708 2709 var safelyParse = function( sContext, sInput ) { 2710 if ( !sInput || sInput.trim() == '' ) { 2711 if ( _super.isAllowNull() ) { 2712 return null; 2713 } 2714 _super.validationException( sContext, _validationTarget, "Required", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2715 } 2716 2717 var canonical = _super.getEncoder().cananicalize( sInput ); 2718 2719 var f = 0.0; 2720 try { 2721 f = parseFloat( canonical ); 2722 } catch (e) { 2723 _super.validationException( sContext, _validationTarget, "Invalid", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2724 } 2725 2726 if ( f == 'NaN' ) { 2727 _super.validationException( sContext, _validationTarget, "NaN", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2728 } 2729 if ( f < minValue ) { 2730 _super.validationException( sContext, _validationTarget, "MinValue", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2731 } 2732 if ( f > maxValue ) { 2733 _super.validationException( sContext, _validationTarget, "MaxValue", { "context":sContext, "input":sInput, "minValue":minValue, "maxValue":maxValue } ); 2734 } 2735 return f; 2736 }; 2737 2738 return { 2739 setMinValue: function(n) { minValue = n; }, 2740 2741 getMinValue: function() { return minValue; }, 2742 2743 setMaxValue: function(n) { maxValue = n; }, 2744 2745 getMaxValue: function() { return maxValue; }, 2746 2747 setAllowNull: _super.setAllowNull, 2748 2749 isAllowNull: _super.isAllowNull, 2750 2751 getTypeName: _super.getTypeName, 2752 2753 setTypeName: _super.setTypeName, 2754 2755 setEncoder: _super.setEncoder, 2756 2757 getEncoder: _super.getEncoder, 2758 2759 assertValid: _super.assertValid, 2760 2761 getValid: _super.getValid, 2762 2763 getValidInput: function( sContext, sInput ) { 2764 return safelyParse(sContext,sInput); 2765 }, 2766 2767 getSafe: _super.getSafe, 2768 2769 sanitize: function( sContext, sInput ) { 2770 var n = 0; 2771 try { 2772 n = safelyParse(sContext,sInput); 2773 } catch (e) { } 2774 return n; 2775 }, 2776 2777 isValid: _super.isValid, 2778 2779 whitelist: _super.whitelist 2780 }; 2781};
2782 2783 2784$namespace('org.owasp.esapi.reference.validation'); 2785 2786org.owasp.esapi.reference.validation.StringValidationRule = function( sTypeName, oEncoder, oLocale, sWhiteListPattern ) { 2787 var _super = new org.owasp.esapi.reference.validation.BaseValidationRule( sTypeName, oEncoder, oLocale ); 2788 var _validationTarget = 'String'; 2789 2790 var whitelistPatterns = Array(); 2791 var blacklistPatterns = Array(); 2792 var minLength = 0; 2793 var maxLength = Number.MAX_VALUE; 2794 var validateInputAndCanonical = true; 2795 2796 if ( sWhiteListPattern ) { 2797 if ( sWhiteListPattern instanceof String ) { 2798 whitelistPatterns.push( new RegExp(sWhiteListPattern) ); 2799 } else if ( sWhiteListPattern instanceof RegExp ) { 2800 whitelistPatterns.push( sWhiteListPattern ); 2801 } else { 2802 throw new IllegalArgumentException("sWhiteListPattern must be a string containing RegExp or a RegExp Object"); 2803 } 2804 } 2805 2806 var checkWhitelist = function( sContext, sInput, sOrig ) { 2807 whitelistPatterns.each(function(p){ 2808 if ( sInput.match(p) ) { 2809 _super.validationException( sContext, _validationTarget, "Whitelist", { "context":sContext, "input":sInput, "orig":sOrig, "pattern":p.toString(), "minLength":minLength, "maxLength":maxLength, "validateInputAndCanonical":validateInputAndCanonical } ); 2810 } 2811 }); 2812 }; 2813 2814 var checkBlacklist = function( sContext, sInput, sOrig ) { 2815 blacklistPatterns.each(function(p){ 2816 if ( sInput.match(p) ) { 2817 _super.validationException( sContext, _validationTarget, "Blacklist", { "context":sContext, "input":sInput, "orig":sOrig, "pattern":p.toString(), "minLength":minLength, "maxLength":maxLength, "validateInputAndCanonical":validateInputAndCanonical } ); 2818 } 2819 }); 2820 }; 2821 2822 var checkLength = function( sContext, sInput, sOrig ) { 2823 if ( sInput.length < minLength ) { 2824 _super.validationException( sContext, _validationTarget, "MinLength", { "context":sContext, "input":sInput, "orig":sOrig, "minLength":minLength, "maxLength":maxLength, "validateInputAndCanonical":validateInputAndCanonical } ); 2825 } 2826 if ( sInput.length > maxLength ) { 2827 _super.validationException( sContext, _validationTarget, "MaxLength", { "context":sContext, "input":sInput, "orig":sOrig, "minLength":minLength, "maxLength":maxLength, "validateInputAndCanonical":validateInputAndCanonical } ); 2828 } 2829 return sInput; 2830 }; 2831 2832 var checkEmpty = function( sContext, sInput, sOrig ) { 2833 if ( !sInput || sInput.trim() == '' ) { 2834 if ( _super.isAllowNull() ) { 2835 return null; 2836 } 2837 _super.validationException( sContext, _validationTarget, "Required", { "context":sContext, "input":sInput, "orig":sOrig, "minLength":minLength, "maxLength":maxLength, "validateInputAndCanonical":validateInputAndCanonical } ); 2838 } 2839 }; 2840 2841 return { 2842 addWhitelistPattern: function(p) { 2843 if ( p instanceof String ) { 2844 whitelistPatterns.push( new RegExp(p) ); 2845 } else if ( p instanceof RegExp ) { 2846 whitelistPatterns.push(p); 2847 } else { 2848 throw new IllegalArgumentException("p must be a string containing RegExp or a RegExp Object"); 2849 } 2850 }, 2851 2852 addBlacklistPattern: function(p) { 2853 if ( p instanceof String ) { 2854 blacklistPatterns.push( new RegExp(p) ); 2855 } else if ( p instanceof RegExp ) { 2856 blacklistPatterns.push(p); 2857 } else { 2858 throw new IllegalArgumentException("p must be a string containing RegExp or a RegExp Object"); 2859 } 2860 }, 2861 2862 setMinLength: function(n) { minLength = n; }, 2863 2864 getMinLength: function() { return minLength; }, 2865 2866 setMaxLength: function(n) { maxLength = n; }, 2867 2868 getMaxLength: function() { return maxLength; }, 2869 2870 setValidateInputAndCanonical: function(b) { validateInputAndCanonical = b; }, 2871 2872 isValidateInputAndCanonical: function() { return validateInputAndCanonical; }, 2873 2874 setAllowNull: _super.setAllowNull, 2875 2876 isAllowNull: _super.isAllowNull, 2877 2878 getTypeName: _super.getTypeName, 2879 2880 setTypeName: _super.setTypeName, 2881 2882 setEncoder: _super.setEncoder, 2883 2884 getEncoder: _super.getEncoder, 2885 2886 assertValid: _super.assertValid, 2887 2888 getValid: _super.getValid, 2889 2890 getValidInput: function( sContext, sInput ) { 2891 var canonical = null; 2892 2893 if ( checkEmpty( sContext, sInput ) == null ) { 2894 return null; 2895 } 2896 2897 if ( validateInputAndCanonical ) { 2898 checkLength(sContext, sInput); 2899 checkWhitelist(sContext,sInput); 2900 checkBlacklist(sContext,sInput); 2901 } 2902 2903 canonical = this.getEncoder().cananicalize(sInput); 2904 2905 if ( checkEmpty( sContext, canonical, sInput ) == null ) { 2906 return null; 2907 } 2908 2909 checkLength( sContext, canonical, sInput ); 2910 checkWhitelist( sContext, canonical, sInput ); 2911 checkBlacklist( sContext, canonical, sInput ); 2912 2913 return canonical; 2914 }, 2915 2916 getSafe: _super.getSafe, 2917 2918 sanitize: function( sContext, sInput ) { 2919 return this.whitelist( sInput, org.owasp.esapi.EncoderConstants.CHAR_ALNUM ); 2920 }, 2921 2922 isValid: _super.isValid, 2923 2924 whitelist: _super.whitelist 2925 }; 2926};
2927 2928 2929$namespace('org.owasp.esapi.reference.validation'); 2930 2931org.owasp.esapi.reference.validation.ValidationException = function( sUserMessage, sLogMessage ) { 2932 var oException, sContext; 2933 if ( arguments[2] && arguments[2] instanceof Exception ) { 2934 oException = arguments[2]; 2935 if ( arguments[3] && arguments[3] instanceof String ) { 2936 sContext = arguments[3]; 2937 } 2938 } else if ( arguments[2] && arguments[2] instanceof String ) { 2939 sContext = arguments[2]; 2940 } 2941 2942 var _super = new org.owasp.esapi.EnterpriseSecurityException( sUserMessage, sLogMessage, oException ); 2943 2944 return { 2945 setContext: function(s) { sContext = s; }, 2946 getContext: function() { return sContext; }, 2947 getMessage: _super.getMessage, 2948 getUserMessage: _super.getMessage, 2949 getLogMessage: _super.getLogMessage, 2950 getStackTrace: _super.getStackTrace, 2951 printStackTrace: _super.printStackTrace 2952 }; 2953};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.