Skip to content

Commit a12ce50

Browse files
author
Robert He
committed
Merge branch 'MAGETWO-90177-Image-Broken-on-Storefront-with-Secure-Key' into team3-delivery
2 parents e6b689f + ba0143b commit a12ce50

File tree

3 files changed

+137
-43
lines changed

3 files changed

+137
-43
lines changed

app/code/Magento/Tinymce3/view/base/web/tinymce3Adapter.js

Lines changed: 15 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -480,7 +480,9 @@ define([
480480
* @param {String} directive
481481
*/
482482
makeDirectiveUrl: function (directive) {
483-
return this.config['directives_url'].replace(/directive.*/, 'directive/___directive/' + directive);
483+
return this.config['directives_url']
484+
.replace(/directive/, 'directive/___directive/' + directive)
485+
.replace(/\/$/, '');
484486
},
485487

486488
/**
@@ -537,12 +539,18 @@ define([
537539
* @return {*}
538540
*/
539541
decodeDirectives: function (content) {
540-
// escape special chars in directives url to use it in regular expression
541-
var url = this.makeDirectiveUrl('%directive%').replace(/([$^.?*!+:=()\[\]{}|\\])/g, '\\$1'),
542-
reg = new RegExp(url.replace('%directive%', '([a-zA-Z0-9%,_-]+)\/?'));
543-
544-
return content.gsub(reg, function (match) { //eslint-disable-line no-extra-bind
545-
return Base64.mageDecode(decodeURIComponent(match[1])).replace(/"/g, '"');
542+
var directiveUrl = this.makeDirectiveUrl('%directive%').split('?')[0], // remove query string from directive
543+
// escape special chars in directives url to use in regular expression
544+
regexEscapedDirectiveUrl = directiveUrl.replace(/([$^.?*!+:=()\[\]{}|\\])/g, '\\$1'),
545+
regexDirectiveUrl = regexEscapedDirectiveUrl
546+
.replace(
547+
'%directive%',
548+
'([a-zA-Z0-9,_-]+(?:%2[A-Z]|)+\/?)(?:(?!").)*'
549+
) + '/?(\\\\?[^"]*)?', // allow optional query string
550+
reg = new RegExp(regexDirectiveUrl);
551+
552+
return content.gsub(reg, function (match) {
553+
return Base64.mageDecode(decodeURIComponent(match[1]).replace(/\/$/, '')).replace(/"/g, '"');
546554
});
547555
},
548556

dev/tests/js/jasmine/tests/lib/mage/wysiwygAdapter.test.js

Lines changed: 108 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -22,41 +22,119 @@ define([
2222
Constr.prototype = wysiwygAdapter;
2323

2424
obj = new Constr();
25-
obj.initialize('id', {
26-
'directives_url': 'http://example.com/admin/cms/wysiwyg/directive/'
27-
});
2825
});
2926

3027
describe('wysiwygAdapter', function () {
31-
var decodedHtml = '<p>' +
32-
'<img src="{{media url=&quot;wysiwyg/banana.jpg&quot;}}" alt="" width="612" height="459"></p>',
33-
encodedHtml = '<p>' +
34-
'<img src="http://example.com/admin/cms/wysiwyg/directive/' +
35-
'___directive/e3ttZWRpYSB1cmw9Ind5c2l3eWcvYmFuYW5hLmpwZyJ9fQ%2C%2C" alt="" width="612" height="459">' +
36-
'</p>',
37-
encodedHtmlWithForwardSlashInImgSrc = encodedHtml.replace('%2C%2C', '%2C%2C/');
38-
39-
describe('"encodeDirectives" method', function () {
40-
it('converts media directive img src to directive URL', function () {
41-
expect(obj.encodeDirectives(decodedHtml)).toEqual(encodedHtml);
28+
describe('encoding and decoding directives', function () {
29+
function runTests(decodedHtml, encodedHtml) {
30+
var encodedHtmlWithForwardSlashInImgSrc = encodedHtml.replace(/src="((?:(?!"|\\\?).)*)/, 'src="$1/');
31+
32+
describe('"encodeDirectives" method', function () {
33+
it('converts media directive img src to directive URL', function () {
34+
expect(obj.encodeDirectives(decodedHtml)).toEqual(encodedHtml);
35+
});
36+
});
37+
38+
describe('"decodeDirectives" method', function () {
39+
it(
40+
'converts directive URL img src without a trailing forward slash ' +
41+
'to media url without a trailing forward slash',
42+
function () {
43+
expect(obj.decodeDirectives(encodedHtml)).toEqual(decodedHtml);
44+
}
45+
);
46+
47+
it('converts directive URL img src with a trailing forward slash ' +
48+
'to media url without a trailing forward slash',
49+
function () {
50+
expect(encodedHtmlWithForwardSlashInImgSrc).not.toEqual(encodedHtml);
51+
expect(obj.decodeDirectives(encodedHtmlWithForwardSlashInImgSrc)).toEqual(decodedHtml);
52+
}
53+
);
54+
});
55+
}
56+
57+
describe('without SID in directive query string', function () {
58+
describe('without secret key', function () {
59+
var decodedHtml = '<p>' +
60+
'<img src="{{media url=&quot;wysiwyg/banana.jpg&quot;}}" alt="" width="612" height="459"></p>',
61+
encodedHtml = '<p>' +
62+
'<img src="http://example.com/admin/cms/wysiwyg/directive/___directive' +
63+
'/e3ttZWRpYSB1cmw9Ind5c2l3eWcvYmFuYW5hLmpwZyJ9fQ%2C%2C" alt="" width="612" height="459">' +
64+
'</p>';
65+
66+
beforeEach(function () {
67+
obj.initialize('id', {
68+
'directives_url': 'http://example.com/admin/cms/wysiwyg/directive/'
69+
});
70+
});
71+
72+
runTests(decodedHtml, encodedHtml);
73+
});
74+
75+
describe('with secret key', function () {
76+
var decodedHtml = '<p>' +
77+
'<img src="{{media url=&quot;wysiwyg/banana.jpg&quot;}}" alt="" width="612" height="459"></p>',
78+
encodedHtml = '<p>' +
79+
'<img src="http://example.com/admin/cms/wysiwyg/directive/___directive' +
80+
'/e3ttZWRpYSB1cmw9Ind5c2l3eWcvYmFuYW5hLmpwZyJ9fQ%2C%2C/key/' +
81+
'5552655d13a141099d27f5d5b0c58869423fd265687167da12cad2bb39aa9a58" ' +
82+
'alt="" width="612" height="459">' +
83+
'</p>',
84+
directiveUrl = 'http://example.com/admin/cms/wysiwyg/directive/key/' +
85+
'5552655d13a141099d27f5d5b0c58869423fd265687167da12cad2bb39aa9a58/';
86+
87+
beforeEach(function () {
88+
obj.initialize('id', {
89+
'directives_url': directiveUrl
90+
});
91+
});
92+
93+
runTests(decodedHtml, encodedHtml);
94+
});
4295
});
43-
});
4496

45-
describe('"decodeDirectives" method', function () {
46-
it(
47-
'converts directive URL img src without a trailing forward slash ' +
48-
'to media url without a trailing forward slash',
49-
function () {
50-
expect(obj.decodeDirectives(encodedHtml)).toEqual(decodedHtml);
51-
}
52-
);
53-
54-
it('converts directive URL img src with a trailing forward slash ' +
55-
'to media url without a trailing forward slash',
56-
function () {
57-
expect(obj.decodeDirectives(encodedHtmlWithForwardSlashInImgSrc)).toEqual(decodedHtml);
58-
}
59-
);
97+
describe('with SID in directive query string', function () {
98+
describe('without secret key', function () {
99+
var decodedHtml = '<p>' +
100+
'<img src="{{media url=&quot;wysiwyg/banana.jpg&quot;}}" alt="" width="612" height="459"></p>',
101+
encodedHtml = '<p>' +
102+
'<img src="http://example.com/admin/cms/wysiwyg/directive/___directive' +
103+
'/e3ttZWRpYSB1cmw9Ind5c2l3eWcvYmFuYW5hLmpwZyJ9fQ%2C%2C?SID=something" ' +
104+
'alt="" width="612" height="459">' +
105+
'</p>',
106+
directiveUrl = 'http://example.com/admin/cms/wysiwyg/directive?SID=something';
107+
108+
beforeEach(function () {
109+
obj.initialize('id', {
110+
'directives_url': directiveUrl
111+
});
112+
});
113+
114+
runTests(decodedHtml, encodedHtml);
115+
});
116+
117+
describe('with secret key', function () {
118+
var decodedHtml = '<p>' +
119+
'<img src="{{media url=&quot;wysiwyg/banana.jpg&quot;}}" alt="" width="612" height="459"></p>',
120+
encodedHtml = '<p>' +
121+
'<img src="http://example.com/admin/cms/wysiwyg/directive/___directive' +
122+
'/e3ttZWRpYSB1cmw9Ind5c2l3eWcvYmFuYW5hLmpwZyJ9fQ%2C%2C/key/' +
123+
'5552655d13a141099d27f5d5b0c58869423fd265687167da12cad2bb39aa9a58?SID=something" ' +
124+
'alt="" width="612" height="459">' +
125+
'</p>',
126+
directiveUrl = 'http://example.com/admin/cms/wysiwyg/directive/key/' +
127+
'5552655d13a141099d27f5d5b0c58869423fd265687167da12cad2bb39aa9a58?SID=something';
128+
129+
beforeEach(function () {
130+
obj.initialize('id', {
131+
'directives_url': directiveUrl
132+
});
133+
});
134+
135+
runTests(decodedHtml, encodedHtml);
136+
});
137+
});
60138
});
61139
});
62140
});

lib/web/mage/adminhtml/wysiwyg/tiny_mce/tinymce4Adapter.js

Lines changed: 14 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -575,7 +575,9 @@ define([
575575
* @param {String} directive
576576
*/
577577
makeDirectiveUrl: function (directive) {
578-
return this.config['directives_url'].replace(/directive.*/, 'directive/___directive/' + directive);
578+
return this.config['directives_url']
579+
.replace(/directive/, 'directive/___directive/' + directive)
580+
.replace(/\/$/, '');
579581
},
580582

581583
/**
@@ -606,11 +608,17 @@ define([
606608
* @return {*}
607609
*/
608610
decodeDirectives: function (content) {
609-
// escape special chars in directives url to use it in regular expression
610-
var url = this.makeDirectiveUrl('%directive%').replace(/([$^.?*!+:=()\[\]{}|\\])/g, '\\$1'),
611-
reg = new RegExp(url.replace('%directive%', '([a-zA-Z0-9,_-]+(?:%2[A-Z]|)+\/?)'));
612-
613-
return content.gsub(reg, function (match) { //eslint-disable-line no-extra-bind
611+
var directiveUrl = this.makeDirectiveUrl('%directive%').split('?')[0], // remove query string from directive
612+
// escape special chars in directives url to use in regular expression
613+
regexEscapedDirectiveUrl = directiveUrl.replace(/([$^.?*!+:=()\[\]{}|\\])/g, '\\$1'),
614+
regexDirectiveUrl = regexEscapedDirectiveUrl
615+
.replace(
616+
'%directive%',
617+
'([a-zA-Z0-9,_-]+(?:%2[A-Z]|)+\/?)(?:(?!").)*'
618+
) + '/?(\\\\?[^"]*)?', // allow optional query string
619+
reg = new RegExp(regexDirectiveUrl);
620+
621+
return content.gsub(reg, function (match) {
614622
return Base64.mageDecode(decodeURIComponent(match[1]).replace(/\/$/, '')).replace(/"/g, '&quot;');
615623
});
616624
},

0 commit comments

Comments
 (0)