svg.go 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215
  1. package svg
  2. import (
  3. "bytes"
  4. "fmt"
  5. "io"
  6. "strings"
  7. nanoid "github.com/matoous/go-nanoid/v2"
  8. "github.com/tdewolff/parse/v2"
  9. "github.com/tdewolff/parse/v2/xml"
  10. "github.com/imgproxy/imgproxy/v3/imagedata"
  11. )
  12. var feDropShadowName = []byte("feDropShadow")
  13. const feDropShadowTemplate = `
  14. <feMerge result="dsin-%[1]s"><feMergeNode %[3]s /></feMerge>
  15. <feGaussianBlur %[4]s />
  16. <feOffset %[5]s result="dsof-%[2]s" />
  17. <feFlood %[6]s />
  18. <feComposite in2="dsof-%[2]s" operator="in" />
  19. <feMerge %[7]s>
  20. <feMergeNode />
  21. <feMergeNode in="dsin-%[1]s" />
  22. </feMerge>
  23. `
  24. func Satitize(data *imagedata.ImageData) (*imagedata.ImageData, error) {
  25. r := bytes.NewReader(data.Data)
  26. l := xml.NewLexer(parse.NewInput(r))
  27. buf, cancel := imagedata.BorrowBuffer()
  28. ignoreTag := 0
  29. var curTagName string
  30. for {
  31. tt, tdata := l.Next()
  32. if ignoreTag > 0 {
  33. switch tt {
  34. case xml.ErrorToken:
  35. cancel()
  36. return nil, l.Err()
  37. case xml.EndTagToken, xml.StartTagCloseVoidToken:
  38. ignoreTag--
  39. case xml.StartTagToken:
  40. ignoreTag++
  41. }
  42. continue
  43. }
  44. switch tt {
  45. case xml.ErrorToken:
  46. if l.Err() != io.EOF {
  47. cancel()
  48. return nil, l.Err()
  49. }
  50. newData := imagedata.ImageData{
  51. Data: buf.Bytes(),
  52. Type: data.Type,
  53. }
  54. newData.SetCancel(cancel)
  55. return &newData, nil
  56. case xml.StartTagToken:
  57. curTagName = strings.ToLower(string(l.Text()))
  58. if curTagName == "script" {
  59. ignoreTag++
  60. continue
  61. }
  62. buf.Write(tdata)
  63. case xml.AttributeToken:
  64. attrName := strings.ToLower(string(l.Text()))
  65. if _, unsafe := unsafeAttrs[attrName]; unsafe {
  66. continue
  67. }
  68. if curTagName == "use" && (attrName == "href" || attrName == "xlink:href") {
  69. val := strings.TrimSpace(strings.Trim(string(l.AttrVal()), `"'`))
  70. if len(val) > 0 && val[0] != '#' {
  71. continue
  72. }
  73. }
  74. buf.Write(tdata)
  75. default:
  76. buf.Write(tdata)
  77. }
  78. }
  79. }
  80. func replaceDropShadowNode(l *xml.Lexer, buf *bytes.Buffer) error {
  81. var (
  82. inAttrs strings.Builder
  83. blurAttrs strings.Builder
  84. offsetAttrs strings.Builder
  85. floodAttrs strings.Builder
  86. finalAttrs strings.Builder
  87. )
  88. inID, _ := nanoid.New(8)
  89. offsetID, _ := nanoid.New(8)
  90. hasStdDeviation := false
  91. hasDx := false
  92. hasDy := false
  93. TOKEN_LOOP:
  94. for {
  95. tt, tdata := l.Next()
  96. switch tt {
  97. case xml.ErrorToken:
  98. if l.Err() != io.EOF {
  99. return l.Err()
  100. }
  101. break TOKEN_LOOP
  102. case xml.EndTagToken, xml.StartTagCloseVoidToken:
  103. break TOKEN_LOOP
  104. case xml.AttributeToken:
  105. switch strings.ToLower(string(l.Text())) {
  106. case "in":
  107. inAttrs.Write(tdata)
  108. case "stddeviation":
  109. blurAttrs.Write(tdata)
  110. hasStdDeviation = true
  111. case "dx":
  112. offsetAttrs.Write(tdata)
  113. hasDx = true
  114. case "dy":
  115. offsetAttrs.Write(tdata)
  116. hasDy = true
  117. case "flood-color", "flood-opacity":
  118. floodAttrs.Write(tdata)
  119. default:
  120. finalAttrs.Write(tdata)
  121. }
  122. }
  123. }
  124. if !hasStdDeviation {
  125. blurAttrs.WriteString(` stdDeviation="2"`)
  126. }
  127. if !hasDx {
  128. offsetAttrs.WriteString(` dx="2"`)
  129. }
  130. if !hasDy {
  131. offsetAttrs.WriteString(` dy="2"`)
  132. }
  133. fmt.Fprintf(
  134. buf, feDropShadowTemplate,
  135. inID, offsetID,
  136. inAttrs.String(),
  137. blurAttrs.String(),
  138. offsetAttrs.String(),
  139. floodAttrs.String(),
  140. finalAttrs.String(),
  141. )
  142. return nil
  143. }
  144. func FixUnsupported(data *imagedata.ImageData) (*imagedata.ImageData, bool, error) {
  145. if !bytes.Contains(data.Data, feDropShadowName) {
  146. return data, false, nil
  147. }
  148. r := bytes.NewReader(data.Data)
  149. l := xml.NewLexer(parse.NewInput(r))
  150. buf, cancel := imagedata.BorrowBuffer()
  151. for {
  152. tt, tdata := l.Next()
  153. switch tt {
  154. case xml.ErrorToken:
  155. if l.Err() != io.EOF {
  156. cancel()
  157. return nil, false, l.Err()
  158. }
  159. newData := imagedata.ImageData{
  160. Data: buf.Bytes(),
  161. Type: data.Type,
  162. }
  163. newData.SetCancel(cancel)
  164. return &newData, true, nil
  165. case xml.StartTagToken:
  166. if bytes.Equal(l.Text(), feDropShadowName) {
  167. if err := replaceDropShadowNode(l, buf); err != nil {
  168. cancel()
  169. return nil, false, err
  170. }
  171. continue
  172. }
  173. buf.Write(tdata)
  174. default:
  175. buf.Write(tdata)
  176. }
  177. }
  178. }