Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,8 @@ public class EntryBean {
private boolean rightToLeft = false;
private boolean pinnedToMain = false;
private String enclosureURL = null;
private String enclosureType = null;
private String enclosureLength = null;
private String searchDescription = null;
private int commentCount = 0;

Expand Down Expand Up @@ -227,6 +229,22 @@ public String getEnclosureURL() {
public void setEnclosureURL(String enclosureUrl) {
this.enclosureURL = enclosureUrl;
}

public String getEnclosureType() {
return enclosureType;
}

public void setEnclosureType(String enclosureType) {
this.enclosureType = enclosureType;
}

public String getEnclosureLength() {
return enclosureLength;
}

public void setEnclosureLength(String enclosureLength) {
this.enclosureLength = enclosureLength;
}

public String getSearchDescription() {
return searchDescription;
Expand Down Expand Up @@ -390,6 +408,10 @@ public void copyFrom(WeblogEntry entry, Locale locale) {
for (WeblogEntryAttribute attr : attrs) {
if ("att_mediacast_url".equals(attr.getName())) {
setEnclosureURL(attr.getValue());
} else if ("att_mediacast_type".equals(attr.getName())) {
setEnclosureType(attr.getValue());
} else if ("att_mediacast_length".equals(attr.getName())) {
setEnclosureLength(attr.getValue());
}
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,15 +48,13 @@
import org.apache.roller.weblogger.ui.core.plugins.UIPluginManager;
import org.apache.roller.weblogger.ui.core.plugins.WeblogEntryEditor;
import org.apache.roller.weblogger.ui.struts2.util.UIAction;
import org.apache.roller.weblogger.util.cache.CacheManager;
import org.apache.roller.weblogger.util.EnclosureMetadata;
import org.apache.roller.weblogger.util.MailUtil;
import org.apache.roller.weblogger.util.MediacastException;
import org.apache.roller.weblogger.util.MediacastResource;
import org.apache.roller.weblogger.util.MediacastUtil;
import org.apache.roller.weblogger.util.RollerMessages;
import org.apache.roller.weblogger.util.RollerMessages.RollerMessage;
import org.apache.roller.weblogger.util.Trackback;
import org.apache.roller.weblogger.util.TrackbackNotAllowedException;
import org.apache.roller.weblogger.util.cache.CacheManager;
import org.apache.struts2.convention.annotation.AllowedMethods;
import org.apache.struts2.interceptor.validation.SkipValidation;

Expand Down Expand Up @@ -192,6 +190,19 @@ public String publish() {
*/
private String save() {
if (!hasActionErrors()) {
EnclosureMetadata enclosure = null;
if (!StringUtils.isEmpty(getBean().getEnclosureURL())) {
try {
enclosure = EnclosureMetadata.of(
getBean().getEnclosureURL(),
getBean().getEnclosureType(),
getBean().getEnclosureLength());
} catch (IllegalArgumentException e) {
addError("weblogEdit.enclosureMetadataInvalid");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is fatal where the old flow was advisory (addMessage and continue), and existing entries can't pass it: the removed MediacastUtil stored con.getContentType() verbatim, so att_mediacast_type may be audio/mpeg; charset=utf-8 or video/mp4;codecs=avc1, which MEDIA_TYPE rejects. The author then can't save any change to that entry until they notice and hand-edit the type. Either accept parameters in the regex (and strip them), or treat an invalid legacy value as "clear the enclosure and warn" instead of refusing the save. Also, one generic message for three fields: a blank Length (new field, previously auto-filled) produces the same text as a bad URL.

return INPUT;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This returns before the if ("entryAdd".equals(actionName)) getBean().setStatus(null) reset at the end of the method (line 309), which every other failed save on a new entry goes through. publish() has already stamped PUBLISHED on the bean, so the form re-renders with the green "Published (Last updated: )" badge and an empty date for an entry that was never written, and the hidden bean.status carries PUBLISHED into the next submit.

}
}

try {
WeblogEntryManager weblogEntryManager = WebloggerFactory.getWeblogger()
.getWeblogEntryManager();
Expand Down Expand Up @@ -223,24 +234,13 @@ private String save() {
weblogEntry.setPinnedToMain(getBean().getPinnedToMain());
}

if (!StringUtils.isEmpty(getBean().getEnclosureURL())) {
try {
// Fetch MediaCast resource
log.debug("Checking MediaCast attributes");
MediacastResource mediacast = MediacastUtil
.lookupResource(getBean().getEnclosureURL());

// set mediacast attributes
weblogEntry.putEntryAttribute("att_mediacast_url",
mediacast.getUrl());
weblogEntry.putEntryAttribute("att_mediacast_type",
mediacast.getContentType());
weblogEntry.putEntryAttribute("att_mediacast_length", ""
+ mediacast.getLength());

} catch (MediacastException ex) {
addMessage(getText(ex.getErrorKey()));
}
if (enclosure != null) {
weblogEntry.putEntryAttribute("att_mediacast_url",
enclosure.getUrl());
weblogEntry.putEntryAttribute("att_mediacast_type",
enclosure.getContentType());
weblogEntry.putEntryAttribute("att_mediacast_length",
enclosure.getLength());
} else if ("entryEdit".equals(actionName)) {
try {
// if MediaCast string is empty, clean out MediaCast
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
/*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership.
* The ASF licenses this file to You under the Apache License, Version 2.0
* (the "License"); you may not use this file except in compliance with
* the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.apache.roller.weblogger.util;

import java.util.regex.Pattern;
import org.apache.commons.validator.routines.UrlValidator;

/**
* Validated metadata for an RSS or Atom enclosure.
*/
public final class EnclosureMetadata {

private static final UrlValidator URL_VALIDATOR = new UrlValidator(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

UrlValidator rejects any host whose TLD isn't in its IANA list (blog.internal, roller.local, blog.lan, .test), underscores, and IDN hosts; ALLOW_LOCAL_URLS only admits single-label hosts like localhost. Since MediaFileAddSuccess pre-fills the enclosure URL from the site's own absolute URL, an intranet install can never attach uploaded media as an enclosure, and existing entries with such URLs can no longer be re-saved. java.net.URI with a scheme check (http / https, non-empty host) is enough here; the point is no longer fetching it.

new String[] {"http", "https"}, UrlValidator.ALLOW_LOCAL_URLS);

private static final Pattern MEDIA_TYPE = Pattern.compile(

@mraible mraible Aug 31, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This admits & (and ', `, |), but feeds.vm lines 52 and 80 emit type="$mc_type" without escapeXML, so audio/mp&eg passes validation and turns the whole RSS and Atom feed into malformed XML. Either escape it in feeds.vm or drop those characters from the character class (real media types never use them).

"[!#$%&'*+.^_`|~0-9A-Za-z-]+/[!#$%&'*+.^_`|~0-9A-Za-z-]+");

private final String url;
private final String contentType;
private final String length;

private EnclosureMetadata(String url, String contentType, String length) {
this.url = url;
this.contentType = contentType;
this.length = length;
}

public static EnclosureMetadata of(String url, String contentType, String length) {
String normalizedUrl = normalize(url);
String normalizedType = normalize(contentType);
String normalizedLength = normalize(length);

if (!URL_VALIDATOR.isValid(normalizedUrl)) {
throw new IllegalArgumentException("Enclosure URL must be an absolute HTTP or HTTPS URL");
}
if (!MEDIA_TYPE.matcher(normalizedType).matches()) {
throw new IllegalArgumentException("Enclosure type must be a valid media type");
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: no upper bound; Long.MAX_VALUE is accepted and the feed advertises an 8 EiB enclosure. The form caps the field at 20 characters, so a sanity ceiling here would match.


final long byteLength;
try {
byteLength = Long.parseLong(normalizedLength);
} catch (NumberFormatException e) {
throw new IllegalArgumentException("Enclosure length must be a non-negative integer", e);
}
if (byteLength < 0) {
throw new IllegalArgumentException("Enclosure length must be a non-negative integer");
}

return new EnclosureMetadata(
normalizedUrl, normalizedType, Long.toString(byteLength));
}

private static String normalize(String value) {
return value == null ? "" : value.trim();
}

public String getUrl() {
return url;
}

public String getContentType() {
return contentType;
}

public String getLength() {
return length;
}
}

This file was deleted.

This file was deleted.

Loading
Loading