From 66ad9cb7494044744a50e95a1929ebc67c7d5aa0 Mon Sep 17 00:00:00 2001 From: Nikita Iarychenko Date: Thu, 10 Apr 2025 18:08:02 +0400 Subject: [PATCH] OPENIDE #161 Change approach from whitelists to blacklists (cherry picked from commit e927f851c876f148cb0eea4d0be2487a6ef435e6) (cherry picked from commit c96820d2e22a407d0dceed75eadea620087c28e1) (cherry picked from commit 49e9d4fd10a321fc9c03ac675bfb66212ce906a5) (cherry picked from commit bf03c2b023f8d26ecdfecba40965b46bdfa3918a) (cherry picked from commit 459c361c117d0729dc503a4676e5e2672d68f6fd) --- .../com/intellij/util/io/HttpRequests.java | 4 +- .../src/ru/openide/io/BlackListUrls.kt | 79 +++++++++++++++++++ .../src/ru/openide/io/WhiteListUrls.kt | 38 --------- 3 files changed, 81 insertions(+), 40 deletions(-) create mode 100644 platform/ide-core/src/ru/openide/io/BlackListUrls.kt delete mode 100644 platform/ide-core/src/ru/openide/io/WhiteListUrls.kt diff --git a/platform/ide-core/src/com/intellij/util/io/HttpRequests.java b/platform/ide-core/src/com/intellij/util/io/HttpRequests.java index 5a75edc102b2..05ca608ac8d1 100644 --- a/platform/ide-core/src/com/intellij/util/io/HttpRequests.java +++ b/platform/ide-core/src/com/intellij/util/io/HttpRequests.java @@ -25,7 +25,7 @@ import org.jetbrains.annotations.ApiStatus; import org.jetbrains.annotations.NotNull; import org.jetbrains.annotations.Nullable; import ru.openide.io.StubUrlConnection; -import ru.openide.io.WhiteListUrls; +import ru.openide.io.BlackListUrls; import javax.net.ssl.HostnameVerifier; import javax.net.ssl.HttpsURLConnection; @@ -582,7 +582,7 @@ public final class HttpRequests { request.myUrl = "https:" + request.myUrl.substring(5); } - if (!WhiteListUrls.isAvailableUrl(request.myUrl)) { + if (!BlackListUrls.isAvailableUrl(request.myUrl)) { LOG.info("Not available url: " + request.myUrl); URL url = new URL(request.myUrl); return new StubUrlConnection(url); diff --git a/platform/ide-core/src/ru/openide/io/BlackListUrls.kt b/platform/ide-core/src/ru/openide/io/BlackListUrls.kt new file mode 100644 index 000000000000..450e2aa11562 --- /dev/null +++ b/platform/ide-core/src/ru/openide/io/BlackListUrls.kt @@ -0,0 +1,79 @@ +// OpenIDE Project +// Copyright (C) 2025 “Open Development Platform” Ltd. (https://openide.ru) +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU Affero General Public License version 3 or later as published by the Free Software Foundation. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU Affero General Public License for more details. +// +// You should have received a copy of the GNU Affero General Public License +// along with this program. If not, see http://www.gnu.org/licenses/. +package ru.openide.io + +import com.intellij.notification.Notification +import com.intellij.notification.NotificationAction +import com.intellij.notification.NotificationType +import java.net.URL +import java.net.URLConnection + +object BlackListUrls { + private val urls = listOf( + "resources.jetbrains.com", + "download.jetbrains.com", + "packages.jetbrains.team", + "cache-redirector.jetbrains.com", + "www.jetbrains.com", + "intellij-test-discovery.labs.intellij.net", + "forms-service.jetbrains.com", + "ea-report.jetbrains.com", + "plugins.jetbrains.com", + "resources.jetbrains.com", + "uploads.jetbrains.com", + "analytics.services.jetbrains.com" + ) + + private val WITHOUT_PROTOCOL_REGEX = Regex("https?://") + + @JvmStatic + fun isAvailableUrl(url: String): Boolean { + if (url.startsWith("file")) return true + val urlWithoutProtocol = url.replaceFirst(WITHOUT_PROTOCOL_REGEX, "") + if (urls.startsWith(urlWithoutProtocol)) { + if (OpenIdePersistentUrlStorage.getInstance().getUrls().startsWith(url)) { + return true + } + + val findPluginId = OpenIdePluginUtil.getInstance().findNonBundledPluginId(Throwable()) + if (findPluginId != null) { + return true + } + + showAccessRequestNotification(url) + return false + } + + return true + } + + private fun showAccessRequestNotification(url: String) { + val addUrlAction = NotificationAction.createSimpleExpiring(OpenIdeBundle.message("allow.access")) { + OpenIdePersistentUrlStorage.getInstance().getUrls().add(url) + } + + Notification("Find Problems", OpenIdeBundle.message("access.to.untrusted.source"), url, NotificationType.WARNING) + .addAction(addUrlAction) + .notify(null) + } + + private fun List.startsWith(url: String): Boolean { + return this.any { url.startsWith(it, true) } + } +} + +class StubUrlConnection(url: URL): URLConnection(url) { + override fun connect() { + } +} \ No newline at end of file diff --git a/platform/ide-core/src/ru/openide/io/WhiteListUrls.kt b/platform/ide-core/src/ru/openide/io/WhiteListUrls.kt deleted file mode 100644 index e2910690f0b6..000000000000 --- a/platform/ide-core/src/ru/openide/io/WhiteListUrls.kt +++ /dev/null @@ -1,38 +0,0 @@ -// Copyright (c) Haulmont 2024. All Rights Reserved. -// Use is subject to license terms. -package com.intellij.util.io - -import java.net.URL -import java.net.URLConnection - -object WhiteListUrls { - private val urls = listOf( - "https://github.com", - "https://search.maven.org", - "https://repo.jfrog.org", - "https://oss.sonatype.org", - "https://repository.jboss.org", - "https://repo.maven.apache.org", - "https://plugins.gradle.org/plugin/org.jetbrains.intellij", - "https://api.github.com/repos", - "https://pypi.python.org", - "http://localhost", - "https://services.gradle.org", - "https://plugins.openide.ru/", - "https://downloads.marketplace.openide.ru", - "https://downloads.openide.ru", - "https://repo1.maven.org/maven2/net/sourceforge/plantuml/plantuml/1.2023.10/plantuml-1.2023.10.jar", - "https://amplicode.ru", - "https://download.openide.ru" - ) - - @JvmStatic - fun isAvailableUrl(url: String): Boolean { - return urls.any { url.startsWith(it, true) } - } -} - -class StubUrlConnection(url: URL): URLConnection(url) { - override fun connect() { - } -} \ No newline at end of file