node_modules updated, buefy add to lib folder
This commit is contained in:
+4
@@ -0,0 +1,4 @@
|
||||
language: node_js
|
||||
node_js:
|
||||
- "stable"
|
||||
sudo: false
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
# ChangeLog
|
||||
|
||||
## 2.0.0
|
||||
|
||||
* switch API to template literal tag functions
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
Contributing
|
||||
============
|
||||
|
||||
1. Fork it
|
||||
2. Create your feature branch (`git checkout -b my-new-feature`)
|
||||
3. Commit your changes (`git commit -am 'Add some feature'`)
|
||||
4. Push to the branch (`git push origin my-new-feature`)
|
||||
5. Create new Pull Request
|
||||
+13
@@ -0,0 +1,13 @@
|
||||
Copyright (c) 2015, 2016, 2017, 2018, 2019 Thomas Cort <linuxgeek@gmail.com>
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
||||
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
||||
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
||||
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
||||
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
+75
@@ -0,0 +1,75 @@
|
||||
# ldap-escape
|
||||
|
||||
Template literal tag functions for LDAP filters and distinguished names to prevent [LDAP injection](https://www.owasp.org/index.php/LDAP_injection) attacks.
|
||||
Uses the escape codes from [Active Directory: Characters to Escape](http://social.technet.microsoft.com/wiki/contents/articles/5312.active-directory-characters-to-escape.aspx).
|
||||
|
||||
## Installation
|
||||
|
||||
npm install --save ldap-escape
|
||||
|
||||
## Specification
|
||||
|
||||
### escapes for search filter
|
||||
|
||||
| Character | Escape |
|
||||
|-----------|--------|
|
||||
| `*` | `\2A` |
|
||||
| `(` | `\28` |
|
||||
| `)` | `\29` |
|
||||
| `\` | `\5C` |
|
||||
| `NUL` | `\00` |
|
||||
|
||||
### escapes for distinguished names
|
||||
|
||||
| Character | Escape |
|
||||
|-----------------------------|--------|
|
||||
| `,` | `\,` |
|
||||
| `\` | `\\` |
|
||||
| `#` | `\#` |
|
||||
| `+` | `\+` |
|
||||
| `<` | `\<` |
|
||||
| `>` | `\>` |
|
||||
| `;` | `\;` |
|
||||
| `"` | `\"` |
|
||||
| `=` | `\=` |
|
||||
| `SPC` (leading or trailing) | `\ ` |
|
||||
|
||||
## Template Literal Tag Functions
|
||||
|
||||
### ldapEscape.filter
|
||||
|
||||
Escapes input for use as an LDAP filter.
|
||||
|
||||
### ldapEscape.dn
|
||||
|
||||
Escapes input for use as an LDAP distinguished name.
|
||||
|
||||
## Examples
|
||||
|
||||
### Escape a Search Filter
|
||||
|
||||
"use strict";
|
||||
|
||||
const ldapEscape = require('ldap-escape');
|
||||
|
||||
const uid = 1337;
|
||||
|
||||
console.log(ldapEscape.filter`uid=${uid}`); // -> '(uid=1337)'
|
||||
|
||||
### Escape a DN
|
||||
|
||||
"use strict";
|
||||
|
||||
const ldapEscape = require('ldap-escape');
|
||||
|
||||
const cn = 'alice';
|
||||
|
||||
console.log(ldapEscape.dn`cn=${cn},dc=test`); // -> 'cn=alice,dc=test'
|
||||
|
||||
## Testing
|
||||
|
||||
npm test
|
||||
|
||||
## License
|
||||
|
||||
See [LICENSE.md](https://github.com/tcort/ldap-escape/blob/master/LICENSE.md)
|
||||
+66
@@ -0,0 +1,66 @@
|
||||
'use strict';
|
||||
|
||||
const replacements = {
|
||||
|
||||
/* search filter replacements */
|
||||
|
||||
filter: {
|
||||
'\u0000': '\\00', // NUL
|
||||
'\u0028': '\\28', // (
|
||||
'\u0029': '\\29', // )
|
||||
'\u002a': '\\2a', // *
|
||||
'\u005c': '\\5c' // \
|
||||
},
|
||||
|
||||
/* distinguished name replacements */
|
||||
|
||||
dnBegin: {
|
||||
'\u0020': '\\ ', // SPC
|
||||
},
|
||||
dn: {
|
||||
'\u0022': '\\"', // "
|
||||
'\u0023': '\\#', // #
|
||||
'\u002b': '\\+', // +
|
||||
'\u002c': '\\,', // ,
|
||||
'\u003b': '\\;', // ;
|
||||
'\u003c': '\\<', // <
|
||||
'\u003d': '\\=', // =
|
||||
'\u003e': '\\>', // >
|
||||
'\u005c': '\\\\' // \
|
||||
},
|
||||
dnEnd: {
|
||||
'\u0020': '\\ ' // SPC
|
||||
}
|
||||
|
||||
};
|
||||
|
||||
module.exports = {
|
||||
|
||||
filter: function filter(strings, ...values) {
|
||||
let safe = '';
|
||||
strings.forEach((string, i) => {
|
||||
safe += string;
|
||||
if (values.length > i) {
|
||||
safe += `${values[i]}`.replace(/(\u0000|\u0028|\u0029|\u002a|\u005c)/gm, (ch) => replacements.filter[ch]);
|
||||
}
|
||||
});
|
||||
return safe;
|
||||
},
|
||||
|
||||
dn: function dn(strings, ...values) {
|
||||
let safe = '';
|
||||
strings.forEach((string, i) => {
|
||||
safe += string;
|
||||
if (values.length > i) {
|
||||
safe += `${values[i]}`
|
||||
.replace(/(\u0022|\u0023|\u002b|\u002c|\u003b|\u003c|\u003d|\u003e|\u005c)/gm, (ch) => replacements.dn[ch])
|
||||
.replace(/^(\u0020)/gm, (ch) => replacements.dnBegin[ch])
|
||||
.replace(/(\u0020)$/gm, (ch) => replacements.dnEnd[ch]);
|
||||
|
||||
}
|
||||
});
|
||||
return safe;
|
||||
},
|
||||
|
||||
|
||||
};
|
||||
+92
@@ -0,0 +1,92 @@
|
||||
{
|
||||
"_from": "ldap-escape",
|
||||
"_id": "ldap-escape@2.0.1",
|
||||
"_inBundle": false,
|
||||
"_integrity": "sha512-nDOelSFa6Xck/HedYze+xUJl5wJ2WFMVocaOECfL4Nc5HoHV3PPMxO4UsWeXNY29kTKqFuGWcQ5JOcIcBvEJBQ==",
|
||||
"_location": "/ldap-escape",
|
||||
"_phantomChildren": {},
|
||||
"_requested": {
|
||||
"type": "tag",
|
||||
"registry": true,
|
||||
"raw": "ldap-escape",
|
||||
"name": "ldap-escape",
|
||||
"escapedName": "ldap-escape",
|
||||
"rawSpec": "",
|
||||
"saveSpec": null,
|
||||
"fetchSpec": "latest"
|
||||
},
|
||||
"_requiredBy": [
|
||||
"#USER",
|
||||
"/"
|
||||
],
|
||||
"_resolved": "https://registry.npmjs.org/ldap-escape/-/ldap-escape-2.0.1.tgz",
|
||||
"_shasum": "ee2b849dca0698188aa28595ad6898fa0dbeb511",
|
||||
"_spec": "ldap-escape",
|
||||
"_where": "/home/erik/Documents/workspace_brackets/a1_BME_Project_Ohm/om",
|
||||
"author": {
|
||||
"name": "Thomas Cort",
|
||||
"email": "linuxgeek@gmail.com"
|
||||
},
|
||||
"bugs": {
|
||||
"url": "https://github.com/tcort/ldap-escape/issues"
|
||||
},
|
||||
"bundleDependencies": false,
|
||||
"dependencies": {},
|
||||
"deprecated": false,
|
||||
"description": "Escape functions for LDAP filters and distinguished names to prevent LDAP injection attacks.",
|
||||
"devDependencies": {
|
||||
"jest": "^24.1.0",
|
||||
"jshint": "^2.10.1"
|
||||
},
|
||||
"homepage": "https://github.com/tcort/ldap-escape#readme",
|
||||
"jshintConfig": {
|
||||
"esversion": 6,
|
||||
"bitwise": true,
|
||||
"curly": true,
|
||||
"eqeqeq": true,
|
||||
"forin": true,
|
||||
"freeze": true,
|
||||
"globalstrict": true,
|
||||
"immed": true,
|
||||
"indent": 4,
|
||||
"moz": true,
|
||||
"newcap": true,
|
||||
"noarg": true,
|
||||
"node": true,
|
||||
"noempty": true,
|
||||
"nonew": true,
|
||||
"trailing": true,
|
||||
"undef": true,
|
||||
"smarttabs": true,
|
||||
"strict": true,
|
||||
"validthis": true,
|
||||
"globals": {
|
||||
"describe": false,
|
||||
"it": false,
|
||||
"before": false,
|
||||
"beforeEach": false,
|
||||
"after": false,
|
||||
"afterEach": false
|
||||
}
|
||||
},
|
||||
"keywords": [
|
||||
"LDAP",
|
||||
"escape",
|
||||
"security",
|
||||
"injection",
|
||||
"filter",
|
||||
"dn"
|
||||
],
|
||||
"license": "ISC",
|
||||
"main": "index.js",
|
||||
"name": "ldap-escape",
|
||||
"repository": {
|
||||
"type": "git",
|
||||
"url": "git://github.com/tcort/ldap-escape.git"
|
||||
},
|
||||
"scripts": {
|
||||
"pretest": "jshint index.js",
|
||||
"test": "jest"
|
||||
},
|
||||
"version": "2.0.1"
|
||||
}
|
||||
+71
@@ -0,0 +1,71 @@
|
||||
'use strict';
|
||||
|
||||
var ldapEscape = require('../index');
|
||||
|
||||
describe('ldap-escape', function () {
|
||||
describe('.filter', function () {
|
||||
it('should work in the base case (no escaping), returning a string', function () {
|
||||
const uid = 1337;
|
||||
expect(ldapEscape.filter`(uid=${uid})`).toBe('(uid=1337)');
|
||||
});
|
||||
it('should correctly escape the OWASP Christmas Tree Example', function () {
|
||||
const test = 'Hi (This) = is * a \\ test # ç à ô';
|
||||
expect(ldapEscape.filter`(test=${test})`).toBe('(test=Hi \\28This\\29 = is \\2a a \\5c test # ç à ô)');
|
||||
});
|
||||
it('should correctly escape the PHP test case', function () {
|
||||
const test = 'foo=bar(baz)*';
|
||||
expect(ldapEscape.filter`${test}`).toBe('foo=bar\\28baz\\29\\2a');
|
||||
});
|
||||
});
|
||||
describe('.dn', function () {
|
||||
it('should work in the base case (no escaping), returning a string', function () {
|
||||
const cn = 'alice';
|
||||
const dc = 'com';
|
||||
expect(ldapEscape.dn`cn=${cn},dc=${dc}`).toBe('cn=alice,dc=com');
|
||||
});
|
||||
it('should escape a leading space', function () {
|
||||
const cn = ' alice';
|
||||
const dc = 'com';
|
||||
expect(ldapEscape.dn`cn=${cn},dc=${dc}`).toBe('cn=\\ alice,dc=com');
|
||||
});
|
||||
it('should escape a leading hash', function () {
|
||||
const cn = '#alice';
|
||||
const dc = 'com';
|
||||
expect(ldapEscape.dn`cn=${cn},dc=${dc}`).toBe('cn=\\#alice,dc=com');
|
||||
});
|
||||
it('should escape a leading hash and trailing space', function () {
|
||||
const cn = '# ';
|
||||
const dc = 'com';
|
||||
expect(ldapEscape.dn`cn=${cn},dc=${dc}`).toBe('cn=\\#\\ ,dc=com');
|
||||
});
|
||||
it('should escape a trailing space', function () {
|
||||
const cn = 'alice ';
|
||||
const dc = 'com';
|
||||
expect(ldapEscape.dn`cn=${cn},dc=${dc}`).toBe('cn=alice\\ ,dc=com');
|
||||
});
|
||||
it('should escape a dn of just 3 spaces', function () {
|
||||
const cn = ' ';
|
||||
const dc = 'com';
|
||||
expect(ldapEscape.dn`cn=${cn},dc=${dc}`).toBe('cn=\\ \\ ,dc=com');
|
||||
});
|
||||
it('should correctly escape the OWASP Christmas Tree Example', function () {
|
||||
const dn = ' Hello\\ + , "World" ; ';
|
||||
expect(ldapEscape.dn`${dn}`).toBe('\\ Hello\\\\ \\+ \\, \\\"World\\\" \\;\\ ');
|
||||
});
|
||||
it('should correctly escape the Active Directory Examples', function () {
|
||||
let cn, ou;
|
||||
|
||||
cn = 'Smith, James K.';
|
||||
expect(ldapEscape.dn`cn=${cn},ou=West,dc=MyDomain,dc=com`).toBe('cn=Smith\\, James K.,ou=West,dc=MyDomain,dc=com');
|
||||
|
||||
ou = 'Sales\\Engineering';
|
||||
expect(ldapEscape.dn`ou=${ou},dc=MyDomain,dc=com`).toBe('ou=Sales\\\\Engineering,dc=MyDomain,dc=com');
|
||||
|
||||
cn = 'East#Test + Lab';
|
||||
expect(ldapEscape.dn`cn=${cn},ou=West,dc=MyDomain,dc=com`).toBe('cn=East\\#Test \\+ Lab,ou=West,dc=MyDomain,dc=com');
|
||||
|
||||
cn = ' Jim Smith ';
|
||||
expect(ldapEscape.dn`cn=${cn},ou=West,dc=MyDomain,dc=com`).toBe('cn=\\ Jim Smith\\ ,ou=West,dc=MyDomain,dc=com');
|
||||
});
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user