annotate Lib/IMPL/DOM/Transform/QueryToDOM.pm @ 325:34a110d1f06c

added security check for the query transformation
author cin
date Mon, 27 May 2013 02:49:58 +0400
parents b56b1ec33b59
children 4cc6cc370fb2
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
1 package IMPL::DOM::Transform::QueryToDOM;
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
2 use strict;
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
3
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
4 use IMPL::Const qw(:prop);
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
5 use IMPL::declare {
325
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
6 require => {
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
7 OutOfRangeException => '-IMPL::OutOfRangeException'
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
8 },
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
9 base => [
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
10 'IMPL::DOM::Transform::ObjectToDOM' => '@_'
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
11 ],
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
12 props => [
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
13 prefix => PROP_RO,
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
14 delimiter => PROP_RO
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
15 ]
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
16 };
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
17
325
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
18 our $MAX_INDEX = 1024;
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
19
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
20 sub CTOR {
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
21 my ($this) = @_;
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
22
264
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
23 $this->templates->{'CGI'} = 'TransformCGI';
323
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
24 $this->templates->{'IMPL::Web::Application::Action'} = 'TransformAction';
244
a02b110da931 refactoring
sergey
parents: 238
diff changeset
25
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
26 $this->delimiter('[.]');
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
27 $this->prefix('');
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
28 }
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
29
250
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
30 # inflate simple properties
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
31 sub TransformPlain {
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
32 my ($this,$data) = @_;
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
33
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
34 $this->currentNode->nodeProperty( rawValue => $data );
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
35 $this->currentNode->nodeValue( $this->inflateNodeValue($data) );
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
36 return $this->currentNode;
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
37 }
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
38
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
39 # do not store complex data as node values
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
40 sub StoreObject {
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
41 my ($this,$node,$data) = @_;
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
42
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
43 return $node;
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
44 }
129e48bb5afb DOM refactoring
sergey
parents: 244
diff changeset
45
264
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
46 #TODO: support a.b[0][1].c[1]
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
47
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
48 sub TransformCGI {
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
49 my ($this,$query) = @_;
323
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
50
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
51 my $data={};
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
52
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
53 my $prefix = $this->prefix;
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
54 my $delim = $this->delimiter;
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
55
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
56 foreach my $param (grep index($_,$prefix) >= 0 , $query->param()) {
244
a02b110da931 refactoring
sergey
parents: 238
diff changeset
57
a02b110da931 refactoring
sergey
parents: 238
diff changeset
58 my @value = grep length($_), $query->param($param) or next;
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
59
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
60 my @parts = split /$delim/,$param;
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
61
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
62 my $node = $data;
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
63 while ( my $part = shift @parts ) {
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
64 if (my ($name,$index) = ($part =~ m/^(\w+)(?:\[(\d+)\])?$/) ) {
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
65 if (@parts) {
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
66 if(defined $index) {
325
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
67 $this->ValidateIndex($index);
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
68 $node = ($node->{$name}[$index] ||= {});
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
69 } else {
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
70 $node = ($node->{$name} ||= {});
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
71 }
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
72 } else {
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
73 if(defined $index) {
325
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
74 $this->ValidateIndex($index);
244
a02b110da931 refactoring
sergey
parents: 238
diff changeset
75 $node->{$name}[$index] = (@value == 1 ? $value[0] : \@value);
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
76 } else {
244
a02b110da931 refactoring
sergey
parents: 238
diff changeset
77 $node->{$name} = (@value == 1 ? $value[0] : \@value);
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
78 }
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
79 }
237
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
80 }
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
81 }
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
82 }
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
83
61db68166c37 refactoring QueryToDOM
sergey
parents:
diff changeset
84 return $this->Transform($data);
238
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
85 }
b8c724f6de36 DOM model refactoring
sergey
parents: 237
diff changeset
86
325
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
87 sub ValidateIndex {
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
88 my ($this,$index) = @_;
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
89
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
90 die OutOfRangeException->new()
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
91 unless $index >= 0 and $index <= $MAX_INDEX;
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
92 }
34a110d1f06c added security check for the query transformation
cin
parents: 323
diff changeset
93
323
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
94 sub TransformAction {
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
95 my ($this,$action) = @_;
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
96
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
97 return $this->Transform($action->isJson ? $action->jsonData : $action->query);
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
98 }
b56b1ec33b59 minor changes to support JSON in transformation from a query to an object
sergey
parents: 264
diff changeset
99
264
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
100 1;
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
101
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
102 __END__
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
103
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
104 =pod
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
105
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
106 =head1 NAME
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
107
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
108 C<IMPL::DOM::Transform::QueryToDOM> - преобразование CGI запроса в DOM документ.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
109
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
110 =head1 SYNOPSIS
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
111
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
112 =begin code
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
113
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
114 use CGI();
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
115 use IMPL::require {
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
116 Schema => 'IMPL::DOM::Schema',
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
117 Config => 'IMPL::Config',
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
118 QueryToDOM => 'IMPL::DOM::Transform::QueryToDOM'
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
119 }
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
120
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
121 my $q = CGI->new();
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
122
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
123 my $schema = Schema->LoadSchema(Config->AppBase('schemas','person.xml'));
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
124 my $transorm = QueryToDOM->new('edit', $schema);
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
125
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
126 my $form = $transform->Transform($q);
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
127
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
128 my @errors;
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
129
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
130 push @errors, $transform->buildErrors;
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
131 push @errors, $schema->Validate($doc);
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
132
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
133
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
134 =end code
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
135
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
136 =head1 DESCRIPTION
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
137
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
138 Наследует C<IMPL::DOM::Transform::ObjectToDOM>. Добавляет метод
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
139 C<TransformCGI> который применятеся к объектам типа C<CGI> (и производных).
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
140
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
141 Запрос C<CGI> сначала приводится к хешу, затем полученный хеш преобразуется
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
142 в DOM документ при помощи вызова метода C<Transform>.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
143
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
144 Для этого выбираются параметры запроса, затем, имя каждого параметра
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
145 рассматривается в виде пути к свойству, создается структура из хешей и массивов
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
146 в которую по указанному пути кладется значение.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
147
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
148 Если параметр имеет несколько значений, значит свойство является массивом.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
149
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
150 Также изменено поведение некоторых методов преобразования.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
151
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
152 =over
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
153
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
154 =item * C<TransformPlain($value)>
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
155
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
156 Преобразование для простого значения свойства. Посокльку в запросе передаются
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
157 строковые значения, а схема документа может предполпгать другие типы, при
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
158 преобразовании значения параметра из запроса к значению узла используется
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
159 метод C<< $this->inflateNodeValue($value) >>, также помимо значения
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
160 C<< $this->currentNode->nodeValue >> задается атрибут
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
161 C<< $this->currentNode->nodeProperty( rawValue => $value) >>, для того, чтобы
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
162 была возможность получить оригинальное значение параметра запроса (например,
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
163 в случае когда его формат был не верным и C<nodeValue> будет C<undef>).
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
164
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
165 =item * C<StoreObject($node,$object)>
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
166
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
167 Данный метод вызывается если текущий узел (переданный в параметре C<$node>)
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
168 предполагает простое значение, однако в запросе для него было передано сложное
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
169 содержимое. Данная реализация просто игнорирует переданный объект C<$object>
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
170 и возвращает C<$node> без изменений.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
171
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
172 =back
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
173
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
174 =head1 MEMBERS
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
175
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
176 =head2 C<[get]delimiter>
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
177
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
178 REGEX. Разделитель свойств в имени параметра, по-умолчанию C<'[.]'>
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
179
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
180 =head2 C<[get]prefix>
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
181
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
182 Строка, префикс имен параметров, которые участвуют в формировании документа.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
183 По-умолчанию пусто.
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
184
c9c2ec29793f *IMPL::DOM::Transform: updated documentation
sergey
parents: 250
diff changeset
185 =cut