diff --git a/python/rest/src/com/jetbrains/rest/editor/RestPreviewFileEditor.java b/python/rest/src/com/jetbrains/rest/editor/RestPreviewFileEditor.java index d2dcd4e76da6..b7150f95213f 100644 --- a/python/rest/src/com/jetbrains/rest/editor/RestPreviewFileEditor.java +++ b/python/rest/src/com/jetbrains/rest/editor/RestPreviewFileEditor.java @@ -12,16 +12,12 @@ import com.intellij.openapi.fileEditor.FileEditorLocation; import com.intellij.openapi.fileEditor.FileEditorState; import com.intellij.openapi.project.Project; import com.intellij.openapi.util.Disposer; -import com.intellij.openapi.util.NotNullLazyValue; import com.intellij.openapi.util.UserDataHolderBase; import com.intellij.openapi.vfs.VirtualFile; import com.intellij.util.Alarm; import kotlin.Pair; import org.jetbrains.annotations.NotNull; import org.jetbrains.annotations.Nullable; -import org.owasp.html.HtmlPolicyBuilder; -import org.owasp.html.PolicyFactory; -import org.owasp.html.Sanitizers; import javax.swing.*; import java.beans.PropertyChangeListener; @@ -32,35 +28,6 @@ public class RestPreviewFileEditor extends UserDataHolderBase implements FileEdi private final static long RENDERING_DELAY_MS = 20L; - final static NotNullLazyValue SANITIZER_VALUE = new NotNullLazyValue() { - @NotNull - @Override - protected PolicyFactory compute() { - return Sanitizers.BLOCKS - .and(Sanitizers.FORMATTING) - .and(new HtmlPolicyBuilder() - .allowUrlProtocols("file", "http", "https").allowElements("img") - .allowAttributes("alt", "src", "title").onElements("img") - .allowAttributes("border", "height", "width").onElements("img") - .toFactory()) - .and(new HtmlPolicyBuilder() - .allowUrlProtocols("file", "http", "https", "mailto").allowElements("a") - .allowAttributes("href", "title").onElements("a") - .toFactory()) - .and(new HtmlPolicyBuilder() - .allowStandardUrlProtocols() - .allowElements("table", "tr", "td", "th", "caption", "thead", "tbody", "tfoot") - .allowAttributes("summary").onElements("table") - .allowAttributes("align", "valign") - .onElements("table", "tr", "td", "th", "thead", "tbody", "tfoot") - .allowTextIn("table") - .toFactory()) - .and(new HtmlPolicyBuilder() - .allowElements("code", "tr") - .allowAttributes("class").onElements("code", "tr") - .toFactory()); - } - }; @NotNull private final RestPreviewPanel myPanel; @NotNull @@ -169,9 +136,8 @@ public class RestPreviewFileEditor extends UserDataHolderBase implements FileEdi } String finalHtml = html; myLastRequest = () -> { - final String currentHtml = "" + SANITIZER_VALUE.getValue().sanitize(finalHtml) + ""; - if (!currentHtml.equals(myLastRenderedHtml)) { - myLastRenderedHtml = currentHtml; + if (!finalHtml.equals(myLastRenderedHtml)) { + myLastRenderedHtml = finalHtml; myPanel.setHtml(myLastRenderedHtml); } diff --git a/python/rest/src/com/jetbrains/rest/editor/RestSwingHtmlPanel.java b/python/rest/src/com/jetbrains/rest/editor/RestSwingHtmlPanel.java index 60058b40a9ea..d11d8d77241c 100644 --- a/python/rest/src/com/jetbrains/rest/editor/RestSwingHtmlPanel.java +++ b/python/rest/src/com/jetbrains/rest/editor/RestSwingHtmlPanel.java @@ -1,13 +1,52 @@ // Copyright 2000-2018 JetBrains s.r.o. Use of this source code is governed by the Apache 2.0 license that can be found in the LICENSE file. package com.jetbrains.rest.editor; +import com.intellij.openapi.util.NotNullLazyValue; import com.intellij.ui.components.JBScrollPane; import org.jetbrains.annotations.NotNull; +import org.owasp.html.HtmlPolicyBuilder; +import org.owasp.html.PolicyFactory; +import org.owasp.html.Sanitizers; import javax.swing.*; import javax.swing.text.html.HTMLEditorKit; public class RestSwingHtmlPanel implements RestPreviewPanel { + + final static NotNullLazyValue SANITIZER_VALUE = new NotNullLazyValue() { + @NotNull + @Override + protected PolicyFactory compute() { + return Sanitizers.BLOCKS + .and(Sanitizers.FORMATTING) + .and(new HtmlPolicyBuilder() + .allowUrlProtocols("file", "http", "https").allowElements("img") + .allowAttributes("alt", "src", "title").onElements("img") + .allowAttributes("border", "height", "width").onElements("img") + .toFactory()) + .and(new HtmlPolicyBuilder() + .allowUrlProtocols("file", "http", "https", "mailto").allowElements("a") + .allowAttributes("href", "title").onElements("a") + .toFactory()) + .and(new HtmlPolicyBuilder() + .allowStandardUrlProtocols() + .allowElements("table", "tr", "td", "th", "caption", "thead", "tbody", "tfoot") + .allowAttributes("summary").onElements("table") + .allowAttributes("align", "valign") + .onElements("table", "tr", "td", "th", "thead", "tbody", "tfoot") + .allowTextIn("table") + .toFactory()) + .and(new HtmlPolicyBuilder() + .allowStandardUrlProtocols() + .allowElements("pre", "span") + .toFactory()) + .and(new HtmlPolicyBuilder() + .allowElements("code", "tr") + .allowAttributes("class").onElements("code", "tr") + .toFactory()); + } + }; + private final JTextPane myPane; private final JScrollPane myScrollPane; @@ -19,6 +58,7 @@ public class RestSwingHtmlPanel implements RestPreviewPanel { @Override public void setHtml(@NotNull String html) { + html = "" + SANITIZER_VALUE.getValue().sanitize(html) + ""; myPane.setText(html); }