svg.go 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. package svg
  2. import (
  3. "bytes"
  4. "fmt"
  5. "io"
  6. "strings"
  7. nanoid "github.com/matoous/go-nanoid/v2"
  8. "github.com/tdewolff/parse/v2"
  9. "github.com/tdewolff/parse/v2/xml"
  10. "github.com/imgproxy/imgproxy/v3/imagedata"
  11. )
  12. var feDropShadowName = []byte("feDropShadow")
  13. var feDropShadowTemplate = strings.TrimSpace(`
  14. <feMerge result="dsin-%[1]s"><feMergeNode %[3]s /></feMerge>
  15. <feGaussianBlur %[4]s />
  16. <feOffset %[5]s result="dsof-%[2]s" />
  17. <feFlood %[6]s />
  18. <feComposite in2="dsof-%[2]s" operator="in" />
  19. <feMerge %[7]s>
  20. <feMergeNode />
  21. <feMergeNode in="dsin-%[1]s" />
  22. </feMerge>
  23. `)
  24. func cloneHeaders(src map[string]string) map[string]string {
  25. if src == nil {
  26. return nil
  27. }
  28. dst := make(map[string]string, len(src))
  29. for k, v := range src {
  30. dst[k] = v
  31. }
  32. return dst
  33. }
  34. func Sanitize(data *imagedata.ImageData) (*imagedata.ImageData, error) {
  35. r := bytes.NewReader(data.Data)
  36. l := xml.NewLexer(parse.NewInput(r))
  37. buf, cancel := imagedata.BorrowBuffer()
  38. ignoreTag := 0
  39. var curTagName string
  40. for {
  41. tt, tdata := l.Next()
  42. if ignoreTag > 0 {
  43. switch tt {
  44. case xml.ErrorToken:
  45. cancel()
  46. return nil, l.Err()
  47. case xml.EndTagToken, xml.StartTagCloseVoidToken:
  48. ignoreTag--
  49. case xml.StartTagToken:
  50. ignoreTag++
  51. }
  52. continue
  53. }
  54. switch tt {
  55. case xml.ErrorToken:
  56. if l.Err() != io.EOF {
  57. cancel()
  58. return nil, l.Err()
  59. }
  60. newData := imagedata.ImageData{
  61. Data: buf.Bytes(),
  62. Type: data.Type,
  63. Headers: cloneHeaders(data.Headers),
  64. }
  65. newData.SetCancel(cancel)
  66. return &newData, nil
  67. case xml.StartTagToken:
  68. curTagName = strings.ToLower(string(l.Text()))
  69. if curTagName == "script" {
  70. ignoreTag++
  71. continue
  72. }
  73. buf.Write(tdata)
  74. case xml.AttributeToken:
  75. attrName := strings.ToLower(string(l.Text()))
  76. if _, unsafe := unsafeAttrs[attrName]; unsafe {
  77. continue
  78. }
  79. if curTagName == "use" && (attrName == "href" || attrName == "xlink:href") {
  80. val := strings.TrimSpace(strings.Trim(string(l.AttrVal()), `"'`))
  81. if len(val) > 0 && val[0] != '#' {
  82. continue
  83. }
  84. }
  85. buf.Write(tdata)
  86. default:
  87. buf.Write(tdata)
  88. }
  89. }
  90. }
  91. func replaceDropShadowNode(l *xml.Lexer, buf *bytes.Buffer) error {
  92. var (
  93. inAttrs strings.Builder
  94. blurAttrs strings.Builder
  95. offsetAttrs strings.Builder
  96. floodAttrs strings.Builder
  97. finalAttrs strings.Builder
  98. )
  99. inID, _ := nanoid.New(8)
  100. offsetID, _ := nanoid.New(8)
  101. hasStdDeviation := false
  102. hasDx := false
  103. hasDy := false
  104. TOKEN_LOOP:
  105. for {
  106. tt, tdata := l.Next()
  107. switch tt {
  108. case xml.ErrorToken:
  109. if l.Err() != io.EOF {
  110. return l.Err()
  111. }
  112. break TOKEN_LOOP
  113. case xml.EndTagToken, xml.StartTagCloseVoidToken:
  114. break TOKEN_LOOP
  115. case xml.AttributeToken:
  116. switch strings.ToLower(string(l.Text())) {
  117. case "in":
  118. inAttrs.Write(tdata)
  119. case "stddeviation":
  120. blurAttrs.Write(tdata)
  121. hasStdDeviation = true
  122. case "dx":
  123. offsetAttrs.Write(tdata)
  124. hasDx = true
  125. case "dy":
  126. offsetAttrs.Write(tdata)
  127. hasDy = true
  128. case "flood-color", "flood-opacity":
  129. floodAttrs.Write(tdata)
  130. default:
  131. finalAttrs.Write(tdata)
  132. }
  133. }
  134. }
  135. if !hasStdDeviation {
  136. blurAttrs.WriteString(` stdDeviation="2"`)
  137. }
  138. if !hasDx {
  139. offsetAttrs.WriteString(` dx="2"`)
  140. }
  141. if !hasDy {
  142. offsetAttrs.WriteString(` dy="2"`)
  143. }
  144. fmt.Fprintf(
  145. buf, feDropShadowTemplate,
  146. inID, offsetID,
  147. inAttrs.String(),
  148. blurAttrs.String(),
  149. offsetAttrs.String(),
  150. floodAttrs.String(),
  151. finalAttrs.String(),
  152. )
  153. return nil
  154. }
  155. func FixUnsupported(data *imagedata.ImageData) (*imagedata.ImageData, bool, error) {
  156. if !bytes.Contains(data.Data, feDropShadowName) {
  157. return data, false, nil
  158. }
  159. r := bytes.NewReader(data.Data)
  160. l := xml.NewLexer(parse.NewInput(r))
  161. buf, cancel := imagedata.BorrowBuffer()
  162. for {
  163. tt, tdata := l.Next()
  164. switch tt {
  165. case xml.ErrorToken:
  166. if l.Err() != io.EOF {
  167. cancel()
  168. return nil, false, l.Err()
  169. }
  170. newData := imagedata.ImageData{
  171. Data: buf.Bytes(),
  172. Type: data.Type,
  173. Headers: cloneHeaders(data.Headers),
  174. }
  175. newData.SetCancel(cancel)
  176. return &newData, true, nil
  177. case xml.StartTagToken:
  178. if bytes.Equal(l.Text(), feDropShadowName) {
  179. if err := replaceDropShadowNode(l, buf); err != nil {
  180. cancel()
  181. return nil, false, err
  182. }
  183. continue
  184. }
  185. buf.Write(tdata)
  186. default:
  187. buf.Write(tdata)
  188. }
  189. }
  190. }