summaryrefslogtreecommitdiffstats
path: root/src/cidschemehandler.h
diff options
context:
space:
mode:
Diffstat (limited to 'src/cidschemehandler.h')
-rw-r--r--src/cidschemehandler.h21
1 files changed, 20 insertions, 1 deletions
diff --git a/src/cidschemehandler.h b/src/cidschemehandler.h
index 56e6ea1..1231fc6 100644
--- a/src/cidschemehandler.h
+++ b/src/cidschemehandler.h
@@ -20,8 +20,27 @@ public:
void setParts(const QHash<QString, InlinePart> &parts) { m_parts = parts; }
/// Builds the namespaced key HtmlBuilder's rewritten URLs will request.
+ ///
+ /// The '!' separator disambiguates a hostile Content-ID from the prefix
+ /// only because prefix is guaranteed '!'-free: the FIRST '!' in the
+ /// result is always the separator, so an attacker-controlled contentId
+ /// containing '!' (even several) cannot make one message's key collide
+ /// with another's, it only extends the id half after that first '!'.
+ /// This is asserted here rather than merely documented, since two call
+ /// sites (this one and HtmlBuilder::namespaceCids) perform the same
+ /// concatenation independently and neither should trust the other to
+ /// have checked it. Q_ASSERT is compiled out in release builds; the
+ /// property that matters there (distinct pairs never collide, and the
+ /// key always splits at its first '!' back to the original prefix) is
+ /// pinned by a test instead, since it holds unconditionally regardless
+ /// of whether this assertion fires.
static QString namespacedKey(const QString &prefix, const QString &contentId)
- { return prefix + QLatin1Char('!') + contentId; }
+ {
+ Q_ASSERT_X(!prefix.contains(QLatin1Char('!')), "CidSchemeHandler::namespacedKey",
+ "cidPrefix must never contain '!': it is the separator, and a "
+ "prefix containing one would make the split ambiguous");
+ return prefix + QLatin1Char('!') + contentId;
+ }
void requestStarted(QWebEngineUrlRequestJob *job) override;