1
0

svg.go 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200
  1. package svg
  2. import (
  3. "bytes"
  4. "fmt"
  5. "io"
  6. "strings"
  7. nanoid "github.com/matoous/go-nanoid/v2"
  8. "github.com/tdewolff/parse/v2"
  9. "github.com/tdewolff/parse/v2/xml"
  10. "github.com/imgproxy/imgproxy/v3/imagedata"
  11. )
  12. var feDropShadowName = []byte("feDropShadow")
  13. const feDropShadowTemplate = `
  14. <feMerge result="dsin-%[1]s"><feMergeNode %[3]s /></feMerge>
  15. <feGaussianBlur %[4]s />
  16. <feOffset %[5]s result="dsof-%[2]s" />
  17. <feFlood %[6]s />
  18. <feComposite in2="dsof-%[2]s" operator="in" />
  19. <feMerge %[7]s>
  20. <feMergeNode />
  21. <feMergeNode in="dsin-%[1]s" />
  22. </feMerge>
  23. `
  24. func Satitize(data *imagedata.ImageData) (*imagedata.ImageData, error) {
  25. r := bytes.NewReader(data.Data)
  26. l := xml.NewLexer(parse.NewInput(r))
  27. buf, cancel := imagedata.BorrowBuffer()
  28. ignoreTag := 0
  29. for {
  30. tt, tdata := l.Next()
  31. if ignoreTag > 0 {
  32. switch tt {
  33. case xml.ErrorToken:
  34. cancel()
  35. return nil, l.Err()
  36. case xml.EndTagToken, xml.StartTagCloseVoidToken:
  37. ignoreTag--
  38. case xml.StartTagToken:
  39. ignoreTag++
  40. }
  41. continue
  42. }
  43. switch tt {
  44. case xml.ErrorToken:
  45. if l.Err() != io.EOF {
  46. cancel()
  47. return nil, l.Err()
  48. }
  49. newData := imagedata.ImageData{
  50. Data: buf.Bytes(),
  51. Type: data.Type,
  52. }
  53. newData.SetCancel(cancel)
  54. return &newData, nil
  55. case xml.StartTagToken:
  56. if strings.ToLower(string(l.Text())) == "script" {
  57. ignoreTag++
  58. continue
  59. }
  60. buf.Write(tdata)
  61. case xml.AttributeToken:
  62. if _, unsafe := unsafeAttrs[strings.ToLower(string(l.Text()))]; unsafe {
  63. continue
  64. }
  65. buf.Write(tdata)
  66. default:
  67. buf.Write(tdata)
  68. }
  69. }
  70. }
  71. func replaceDropShadowNode(l *xml.Lexer, buf *bytes.Buffer) error {
  72. var (
  73. inAttrs strings.Builder
  74. blurAttrs strings.Builder
  75. offsetAttrs strings.Builder
  76. floodAttrs strings.Builder
  77. finalAttrs strings.Builder
  78. )
  79. inID, _ := nanoid.New(8)
  80. offsetID, _ := nanoid.New(8)
  81. hasStdDeviation := false
  82. hasDx := false
  83. hasDy := false
  84. TOKEN_LOOP:
  85. for {
  86. tt, tdata := l.Next()
  87. switch tt {
  88. case xml.ErrorToken:
  89. if l.Err() != io.EOF {
  90. return l.Err()
  91. }
  92. break TOKEN_LOOP
  93. case xml.EndTagToken, xml.StartTagCloseVoidToken:
  94. break TOKEN_LOOP
  95. case xml.AttributeToken:
  96. switch strings.ToLower(string(l.Text())) {
  97. case "in":
  98. inAttrs.Write(tdata)
  99. case "stddeviation":
  100. blurAttrs.Write(tdata)
  101. hasStdDeviation = true
  102. case "dx":
  103. offsetAttrs.Write(tdata)
  104. hasDx = true
  105. case "dy":
  106. offsetAttrs.Write(tdata)
  107. hasDy = true
  108. case "flood-color", "flood-opacity":
  109. floodAttrs.Write(tdata)
  110. default:
  111. finalAttrs.Write(tdata)
  112. }
  113. }
  114. }
  115. if !hasStdDeviation {
  116. blurAttrs.WriteString(` stdDeviation="2"`)
  117. }
  118. if !hasDx {
  119. offsetAttrs.WriteString(` dx="2"`)
  120. }
  121. if !hasDy {
  122. offsetAttrs.WriteString(` dy="2"`)
  123. }
  124. fmt.Fprintf(
  125. buf, feDropShadowTemplate,
  126. inID, offsetID,
  127. inAttrs.String(),
  128. blurAttrs.String(),
  129. offsetAttrs.String(),
  130. floodAttrs.String(),
  131. finalAttrs.String(),
  132. )
  133. return nil
  134. }
  135. func FixUnsupported(data *imagedata.ImageData) (*imagedata.ImageData, bool, error) {
  136. if !bytes.Contains(data.Data, feDropShadowName) {
  137. return data, false, nil
  138. }
  139. r := bytes.NewReader(data.Data)
  140. l := xml.NewLexer(parse.NewInput(r))
  141. buf, cancel := imagedata.BorrowBuffer()
  142. for {
  143. tt, tdata := l.Next()
  144. switch tt {
  145. case xml.ErrorToken:
  146. if l.Err() != io.EOF {
  147. cancel()
  148. return nil, false, l.Err()
  149. }
  150. newData := imagedata.ImageData{
  151. Data: buf.Bytes(),
  152. Type: data.Type,
  153. }
  154. newData.SetCancel(cancel)
  155. return &newData, true, nil
  156. case xml.StartTagToken:
  157. if bytes.Equal(l.Text(), feDropShadowName) {
  158. if err := replaceDropShadowNode(l, buf); err != nil {
  159. cancel()
  160. return nil, false, err
  161. }
  162. continue
  163. }
  164. buf.Write(tdata)
  165. default:
  166. buf.Write(tdata)
  167. }
  168. }
  169. }