mirror of
https://git.jabber.space/devs/cproof.git
synced 2026-07-24 21:56:21 +00:00
feat: Sanitize illegal XML characters from outgoing messages
Filter out control characters (U+0000 to U+001F) from outgoing messages, as they are illegal in XML 1.0 (except for \t, \n, and \r). This prevents XMPP servers from closing the connection when such characters are accidentally or intentionally included in a message. Fixes: https://github.com/profanity-im/profanity/issues/1437
This commit is contained in:
@@ -1281,3 +1281,35 @@ string_matches_one_of__tests__edge_cases(void** state)
|
||||
// is is an empty string, one of the options is an empty string
|
||||
assert_true(string_matches_one_of("Test", "", FALSE, "option1", "", "option2", NULL));
|
||||
}
|
||||
|
||||
void
|
||||
str_xml_sanitize__strips_illegal_characters(void** state)
|
||||
{
|
||||
// Test NULL input
|
||||
assert_null(str_xml_sanitize(NULL));
|
||||
|
||||
// Test empty string
|
||||
gchar* res1 = str_xml_sanitize("");
|
||||
assert_string_equal("", res1);
|
||||
g_free(res1);
|
||||
|
||||
// Test string with no illegal characters
|
||||
gchar* res2 = str_xml_sanitize("Hello World! \t\n\r");
|
||||
assert_string_equal("Hello World! \t\n\r", res2);
|
||||
g_free(res2);
|
||||
|
||||
// Test string with illegal characters (0x16 is ^V, 0x01 is ^A)
|
||||
gchar* res3 = str_xml_sanitize("Hello\x16World\x01!");
|
||||
assert_string_equal("HelloWorld!", res3);
|
||||
g_free(res3);
|
||||
|
||||
// Test string with mixed legal and illegal control characters
|
||||
gchar* res4 = str_xml_sanitize("\x09Legal\x0BIllegal\x0ALegal\x1FIllegal\x0DLegal");
|
||||
assert_string_equal("\tLegalIllegal\nLegalIllegal\rLegal", res4);
|
||||
g_free(res4);
|
||||
|
||||
// Test UTF-8 characters
|
||||
gchar* res5 = str_xml_sanitize("UTF-8: üñîçøðé \x16 and more");
|
||||
assert_string_equal("UTF-8: üñîçøðé and more", res5);
|
||||
g_free(res5);
|
||||
}
|
||||
|
||||
@@ -60,5 +60,6 @@ void string_matches_one_of__tests__edge_cases(void** state);
|
||||
void valid_tls_policy_option__is__correct_for_various_inputs(void** state);
|
||||
void get_mentions__tests__various(void** state);
|
||||
void release_is_new__tests__various(void** state);
|
||||
void str_xml_sanitize__strips_illegal_characters(void** state);
|
||||
|
||||
#endif
|
||||
|
||||
@@ -661,6 +661,7 @@ main(int argc, char* argv[])
|
||||
cmocka_unit_test(prof_occurrences__tests__large_message),
|
||||
cmocka_unit_test(get_mentions__tests__various),
|
||||
cmocka_unit_test(release_is_new__tests__various),
|
||||
cmocka_unit_test(str_xml_sanitize__strips_illegal_characters),
|
||||
|
||||
cmocka_unit_test_setup_teardown(plugins_get_command_names__returns__no_commands,
|
||||
load_preferences,
|
||||
|
||||
Reference in New Issue
Block a user