sanitize html only for swing panel

PY-30466 reST preview: support "code" and "code-block"
PY-30472 reST preview: support literal blocks
PY-30473 reST preview: support doctest blocks
PY-30475 reST preview: improve table rendering
This commit is contained in:
Ekaterina Tuzova
2018-06-18 16:41:13 +03:00
parent ecef301d86
commit ec97693208
2 changed files with 42 additions and 36 deletions
@@ -12,16 +12,12 @@ import com.intellij.openapi.fileEditor.FileEditorLocation;
import com.intellij.openapi.fileEditor.FileEditorState;
import com.intellij.openapi.project.Project;
import com.intellij.openapi.util.Disposer;
import com.intellij.openapi.util.NotNullLazyValue;
import com.intellij.openapi.util.UserDataHolderBase;
import com.intellij.openapi.vfs.VirtualFile;
import com.intellij.util.Alarm;
import kotlin.Pair;
import org.jetbrains.annotations.NotNull;
import org.jetbrains.annotations.Nullable;
import org.owasp.html.HtmlPolicyBuilder;
import org.owasp.html.PolicyFactory;
import org.owasp.html.Sanitizers;
import javax.swing.*;
import java.beans.PropertyChangeListener;
@@ -32,35 +28,6 @@ public class RestPreviewFileEditor extends UserDataHolderBase implements FileEdi
private final static long RENDERING_DELAY_MS = 20L;
final static NotNullLazyValue<PolicyFactory> SANITIZER_VALUE = new NotNullLazyValue<PolicyFactory>() {
@NotNull
@Override
protected PolicyFactory compute() {
return Sanitizers.BLOCKS
.and(Sanitizers.FORMATTING)
.and(new HtmlPolicyBuilder()
.allowUrlProtocols("file", "http", "https").allowElements("img")
.allowAttributes("alt", "src", "title").onElements("img")
.allowAttributes("border", "height", "width").onElements("img")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowUrlProtocols("file", "http", "https", "mailto").allowElements("a")
.allowAttributes("href", "title").onElements("a")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowStandardUrlProtocols()
.allowElements("table", "tr", "td", "th", "caption", "thead", "tbody", "tfoot")
.allowAttributes("summary").onElements("table")
.allowAttributes("align", "valign")
.onElements("table", "tr", "td", "th", "thead", "tbody", "tfoot")
.allowTextIn("table")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowElements("code", "tr")
.allowAttributes("class").onElements("code", "tr")
.toFactory());
}
};
@NotNull
private final RestPreviewPanel myPanel;
@NotNull
@@ -169,9 +136,8 @@ public class RestPreviewFileEditor extends UserDataHolderBase implements FileEdi
}
String finalHtml = html;
myLastRequest = () -> {
final String currentHtml = "<html>" + SANITIZER_VALUE.getValue().sanitize(finalHtml) + "</html>";
if (!currentHtml.equals(myLastRenderedHtml)) {
myLastRenderedHtml = currentHtml;
if (!finalHtml.equals(myLastRenderedHtml)) {
myLastRenderedHtml = finalHtml;
myPanel.setHtml(myLastRenderedHtml);
}
@@ -1,13 +1,52 @@
// Copyright 2000-2018 JetBrains s.r.o. Use of this source code is governed by the Apache 2.0 license that can be found in the LICENSE file.
package com.jetbrains.rest.editor;
import com.intellij.openapi.util.NotNullLazyValue;
import com.intellij.ui.components.JBScrollPane;
import org.jetbrains.annotations.NotNull;
import org.owasp.html.HtmlPolicyBuilder;
import org.owasp.html.PolicyFactory;
import org.owasp.html.Sanitizers;
import javax.swing.*;
import javax.swing.text.html.HTMLEditorKit;
public class RestSwingHtmlPanel implements RestPreviewPanel {
final static NotNullLazyValue<PolicyFactory> SANITIZER_VALUE = new NotNullLazyValue<PolicyFactory>() {
@NotNull
@Override
protected PolicyFactory compute() {
return Sanitizers.BLOCKS
.and(Sanitizers.FORMATTING)
.and(new HtmlPolicyBuilder()
.allowUrlProtocols("file", "http", "https").allowElements("img")
.allowAttributes("alt", "src", "title").onElements("img")
.allowAttributes("border", "height", "width").onElements("img")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowUrlProtocols("file", "http", "https", "mailto").allowElements("a")
.allowAttributes("href", "title").onElements("a")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowStandardUrlProtocols()
.allowElements("table", "tr", "td", "th", "caption", "thead", "tbody", "tfoot")
.allowAttributes("summary").onElements("table")
.allowAttributes("align", "valign")
.onElements("table", "tr", "td", "th", "thead", "tbody", "tfoot")
.allowTextIn("table")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowStandardUrlProtocols()
.allowElements("pre", "span")
.toFactory())
.and(new HtmlPolicyBuilder()
.allowElements("code", "tr")
.allowAttributes("class").onElements("code", "tr")
.toFactory());
}
};
private final JTextPane myPane;
private final JScrollPane myScrollPane;
@@ -19,6 +58,7 @@ public class RestSwingHtmlPanel implements RestPreviewPanel {
@Override
public void setHtml(@NotNull String html) {
html = "<html>" + SANITIZER_VALUE.getValue().sanitize(html) + "</html>";
myPane.setText(html);
}