summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDaniel Veillard <veillard@redhat.com>2011-02-22 10:14:23 +0800
committerDaniel Veillard <veillard@redhat.com>2011-02-22 10:14:23 +0800
commitecb6bcb8d1b7e44842edde3929f412d46b40c89f (patch)
tree48c42f77a0f28e14f8bf31c7dc05daeaaed697e3
parent0dd2f5377e1d8ff94d9774b69f6ce9fb07466fef (diff)
downloadlibxslt-ecb6bcb8d1b7e44842edde3929f412d46b40c89f.tar.gz
libxslt-ecb6bcb8d1b7e44842edde3929f412d46b40c89f.tar.bz2
libxslt-ecb6bcb8d1b7e44842edde3929f412d46b40c89f.zip
Fix generate-id() to not expose object addresses
As pointed out by Chris Evans <scarybeasts@gmail.com> it's better security wise to not expose object addresses directly, use a diff w.r.t. the document root own address to avoid this * libxslt/functions.c: fix IDs generation code
-rw-r--r--libxslt/functions.c26
1 files changed, 21 insertions, 5 deletions
diff --git a/libxslt/functions.c b/libxslt/functions.c
index 4720c7a3..de962f4e 100644
--- a/libxslt/functions.c
+++ b/libxslt/functions.c
@@ -654,8 +654,9 @@ xsltFormatNumberFunction(xmlXPathParserContextPtr ctxt, int nargs)
void
xsltGenerateIdFunction(xmlXPathParserContextPtr ctxt, int nargs){
xmlNodePtr cur = NULL;
- unsigned long val;
- xmlChar str[20];
+ long val;
+ xmlChar str[30];
+ xmlDocPtr doc;
if (nargs == 0) {
cur = ctxt->context->node;
@@ -694,9 +695,24 @@ xsltGenerateIdFunction(xmlXPathParserContextPtr ctxt, int nargs){
* Okay this is ugly but should work, use the NodePtr address
* to forge the ID
*/
- val = (unsigned long)((char *)cur - (char *)0);
- val /= sizeof(xmlNode);
- sprintf((char *)str, "id%ld", val);
+ if (cur->type != XML_NAMESPACE_DECL)
+ doc = cur->doc;
+ else {
+ xmlNsPtr ns = (xmlNsPtr) cur;
+
+ if (ns->context != NULL)
+ doc = ns->context;
+ else
+ doc = ctxt->context->doc;
+
+ }
+
+ val = (long)((char *)cur - (char *)doc);
+ if (val >= 0) {
+ sprintf((char *)str, "idp%ld", val);
+ } else {
+ sprintf((char *)str, "idm%ld", -val);
+ }
valuePush(ctxt, xmlXPathNewString(str));
}