From 4a70a448af4f6f8102949198451117ad131f0fe6 Mon Sep 17 00:00:00 2001 From: Camila Belo Date: Mon, 23 May 2022 08:31:27 +0200 Subject: [PATCH] refactor(techdocs): extract iframes sanitizer hook Signed-off-by: Camila Belo --- .../reader/transformers/html/hooks/iframes.ts | 50 +++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 plugins/techdocs/src/reader/transformers/html/hooks/iframes.ts diff --git a/plugins/techdocs/src/reader/transformers/html/hooks/iframes.ts b/plugins/techdocs/src/reader/transformers/html/hooks/iframes.ts new file mode 100644 index 0000000000..25259dbc43 --- /dev/null +++ b/plugins/techdocs/src/reader/transformers/html/hooks/iframes.ts @@ -0,0 +1,50 @@ +/* + * Copyright 2022 The Backstage Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +/** + * Checks whether a node is iframe or not. + * @param node - can be any element. + * @returns true when node is iframe. + */ +const isIframe = (node: Element) => node.nodeName === 'IFRAME'; + +/** + * Checks whether a iframe is safe or not. + * @param node - is an iframe element. + * @param hosts - list of allowed hosts. + * @returns true when iframe is included in hosts. + */ +const isSafe = (node: Element, hosts: string[]) => { + const src = node.getAttribute('src') || ''; + try { + const { host } = new URL(src); + return hosts.includes(host); + } catch { + return false; + } +}; + +/** + * Returns a function that removes unsafe iframe nodes. + * @param node - can be any element. + * @param hosts - list of allowed hosts. + */ +export const removeUnsafeIframes = (hosts: string[]) => (node: Element) => { + if (isIframe(node) && !isSafe(node, hosts)) { + node.remove(); + } + return node; +};