mirror of
https://gitflic.ru/project/openide/openide.git
synced 2026-09-27 10:03:11 +07:00
OPENIDE #161 Change approach from whitelists to blacklists
(cherry picked from commit e927f851c876f148cb0eea4d0be2487a6ef435e6) (cherry picked from commitc96820d2e2) (cherry picked from commit49e9d4fd10) (cherry picked from commitbf03c2b023) (cherry picked from commit459c361c11)
This commit is contained in:
@@ -25,7 +25,7 @@ import org.jetbrains.annotations.ApiStatus;
|
||||
import org.jetbrains.annotations.NotNull;
|
||||
import org.jetbrains.annotations.Nullable;
|
||||
import ru.openide.io.StubUrlConnection;
|
||||
import ru.openide.io.WhiteListUrls;
|
||||
import ru.openide.io.BlackListUrls;
|
||||
|
||||
import javax.net.ssl.HostnameVerifier;
|
||||
import javax.net.ssl.HttpsURLConnection;
|
||||
@@ -582,7 +582,7 @@ public final class HttpRequests {
|
||||
request.myUrl = "https:" + request.myUrl.substring(5);
|
||||
}
|
||||
|
||||
if (!WhiteListUrls.isAvailableUrl(request.myUrl)) {
|
||||
if (!BlackListUrls.isAvailableUrl(request.myUrl)) {
|
||||
LOG.info("Not available url: " + request.myUrl);
|
||||
URL url = new URL(request.myUrl);
|
||||
return new StubUrlConnection(url);
|
||||
|
||||
@@ -0,0 +1,79 @@
|
||||
// OpenIDE Project
|
||||
// Copyright (C) 2025 “Open Development Platform” Ltd. (https://openide.ru)
|
||||
//
|
||||
// This program is free software: you can redistribute it and/or modify
|
||||
// it under the terms of the GNU Affero General Public License version 3 or later as published by the Free Software Foundation.
|
||||
//
|
||||
// This program is distributed in the hope that it will be useful,
|
||||
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
// GNU Affero General Public License for more details.
|
||||
//
|
||||
// You should have received a copy of the GNU Affero General Public License
|
||||
// along with this program. If not, see http://www.gnu.org/licenses/.
|
||||
package ru.openide.io
|
||||
|
||||
import com.intellij.notification.Notification
|
||||
import com.intellij.notification.NotificationAction
|
||||
import com.intellij.notification.NotificationType
|
||||
import java.net.URL
|
||||
import java.net.URLConnection
|
||||
|
||||
object BlackListUrls {
|
||||
private val urls = listOf(
|
||||
"resources.jetbrains.com",
|
||||
"download.jetbrains.com",
|
||||
"packages.jetbrains.team",
|
||||
"cache-redirector.jetbrains.com",
|
||||
"www.jetbrains.com",
|
||||
"intellij-test-discovery.labs.intellij.net",
|
||||
"forms-service.jetbrains.com",
|
||||
"ea-report.jetbrains.com",
|
||||
"plugins.jetbrains.com",
|
||||
"resources.jetbrains.com",
|
||||
"uploads.jetbrains.com",
|
||||
"analytics.services.jetbrains.com"
|
||||
)
|
||||
|
||||
private val WITHOUT_PROTOCOL_REGEX = Regex("https?://")
|
||||
|
||||
@JvmStatic
|
||||
fun isAvailableUrl(url: String): Boolean {
|
||||
if (url.startsWith("file")) return true
|
||||
val urlWithoutProtocol = url.replaceFirst(WITHOUT_PROTOCOL_REGEX, "")
|
||||
if (urls.startsWith(urlWithoutProtocol)) {
|
||||
if (OpenIdePersistentUrlStorage.getInstance().getUrls().startsWith(url)) {
|
||||
return true
|
||||
}
|
||||
|
||||
val findPluginId = OpenIdePluginUtil.getInstance().findNonBundledPluginId(Throwable())
|
||||
if (findPluginId != null) {
|
||||
return true
|
||||
}
|
||||
|
||||
showAccessRequestNotification(url)
|
||||
return false
|
||||
}
|
||||
|
||||
return true
|
||||
}
|
||||
|
||||
private fun showAccessRequestNotification(url: String) {
|
||||
val addUrlAction = NotificationAction.createSimpleExpiring(OpenIdeBundle.message("allow.access")) {
|
||||
OpenIdePersistentUrlStorage.getInstance().getUrls().add(url)
|
||||
}
|
||||
|
||||
Notification("Find Problems", OpenIdeBundle.message("access.to.untrusted.source"), url, NotificationType.WARNING)
|
||||
.addAction(addUrlAction)
|
||||
.notify(null)
|
||||
}
|
||||
|
||||
private fun List<String>.startsWith(url: String): Boolean {
|
||||
return this.any { url.startsWith(it, true) }
|
||||
}
|
||||
}
|
||||
|
||||
class StubUrlConnection(url: URL): URLConnection(url) {
|
||||
override fun connect() {
|
||||
}
|
||||
}
|
||||
@@ -1,38 +0,0 @@
|
||||
// Copyright (c) Haulmont 2024. All Rights Reserved.
|
||||
// Use is subject to license terms.
|
||||
package com.intellij.util.io
|
||||
|
||||
import java.net.URL
|
||||
import java.net.URLConnection
|
||||
|
||||
object WhiteListUrls {
|
||||
private val urls = listOf(
|
||||
"https://github.com",
|
||||
"https://search.maven.org",
|
||||
"https://repo.jfrog.org",
|
||||
"https://oss.sonatype.org",
|
||||
"https://repository.jboss.org",
|
||||
"https://repo.maven.apache.org",
|
||||
"https://plugins.gradle.org/plugin/org.jetbrains.intellij",
|
||||
"https://api.github.com/repos",
|
||||
"https://pypi.python.org",
|
||||
"http://localhost",
|
||||
"https://services.gradle.org",
|
||||
"https://plugins.openide.ru/",
|
||||
"https://downloads.marketplace.openide.ru",
|
||||
"https://downloads.openide.ru",
|
||||
"https://repo1.maven.org/maven2/net/sourceforge/plantuml/plantuml/1.2023.10/plantuml-1.2023.10.jar",
|
||||
"https://amplicode.ru",
|
||||
"https://download.openide.ru"
|
||||
)
|
||||
|
||||
@JvmStatic
|
||||
fun isAvailableUrl(url: String): Boolean {
|
||||
return urls.any { url.startsWith(it, true) }
|
||||
}
|
||||
}
|
||||
|
||||
class StubUrlConnection(url: URL): URLConnection(url) {
|
||||
override fun connect() {
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user