Skip to content
GitLab
Projects
Groups
Snippets
Help
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in
Toggle navigation
D
drupal
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Locked Files
Custom Issue Tracker
Custom Issue Tracker
Labels
Merge Requests
225
Merge Requests
225
Requirements
Requirements
List
Security & Compliance
Security & Compliance
Dependency List
License Compliance
Analytics
Analytics
Code Review
Insights
Issue
Repository
Value Stream
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Commits
Open sidebar
project
drupal
Commits
99b763a1
Unverified
Commit
99b763a1
authored
Nov 17, 2020
by
alexpott
1
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Issue
#3175884
by gabesullice, mglaman, juagarc4, catch: JSON:API link keys can collide
parent
e82556c3
Changes
2
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
101 additions
and
3 deletions
+101
-3
core/modules/jsonapi/src/Normalizer/LinkCollectionNormalizer.php
...dules/jsonapi/src/Normalizer/LinkCollectionNormalizer.php
+25
-3
core/modules/jsonapi/tests/src/Kernel/Normalizer/LinkCollectionNormalizerTest.php
...ts/src/Kernel/Normalizer/LinkCollectionNormalizerTest.php
+76
-0
No files found.
core/modules/jsonapi/src/Normalizer/LinkCollectionNormalizer.php
View file @
99b763a1
...
...
@@ -17,7 +17,8 @@
*
* When normalizing more than one link in a LinkCollection with the same key, a
* unique and random string is appended to the link's key after a double dash
* (--) to differentiate the links.
* (--) to differentiate the links. See this class's hashByHref() method for
* details.
*
* This may change with a later version of the JSON:API specification.
*
...
...
@@ -82,7 +83,15 @@ public function normalize($object, $format = NULL, array $context = []) {
}
/**
* Hashes a link by its href.
* Hashes a link using its href and its target attributes, if any.
*
* This method generates an unpredictable, but deterministic, 7 character
* alphanumeric hash for a given link.
*
* The hash is unpredictable because a random hash salt will be used for every
* request. The hash is deterministic because, within a single request, links
* with the same href and target attributes (i.o.w. duplicates) will generate
* equivalent hash values.
*
* @param \Drupal\jsonapi\JsonApiResource\Link $link
* A link to be hashed.
...
...
@@ -91,10 +100,23 @@ public function normalize($object, $format = NULL, array $context = []) {
* A 7 character alphanumeric hash.
*/
protected
function
hashByHref
(
Link
$link
)
{
// Generate a salt unique to each instance of this class.
if
(
!
$this
->
hashSalt
)
{
$this
->
hashSalt
=
Crypt
::
randomBytesBase64
();
}
return
substr
(
str_replace
([
'-'
,
'_'
],
''
,
Crypt
::
hashBase64
(
$this
->
hashSalt
.
$link
->
getHref
())),
0
,
7
);
// Create a dictionary of link parameters.
$link_parameters
=
[
'href'
=>
$link
->
getHref
(),
]
+
$link
->
getTargetAttributes
();
// Serialize the dictionary into a string.
foreach
(
$link_parameters
as
$name
=>
$value
)
{
$serialized_parameters
[]
=
sprintf
(
'%s="%s"'
,
$name
,
implode
(
' '
,
(
array
)
$value
));
}
// Hash the string.
$b64_hash
=
Crypt
::
hashBase64
(
$this
->
hashSalt
.
implode
(
'; '
,
$serialized_parameters
));
// Remove any dashes and underscores from the base64 hash and then return
// the first 7 characters.
return
substr
(
str_replace
([
'-'
,
'_'
],
''
,
$b64_hash
),
0
,
7
);
}
}
core/modules/jsonapi/tests/src/Kernel/Normalizer/LinkCollectionNormalizerTest.php
0 → 100644
View file @
99b763a1
<?php
namespace
Drupal\Tests\jsonapi\Kernel\Normalizer
;
use
Drupal\Core\Cache\CacheableMetadata
;
use
Drupal\Core\Url
;
use
Drupal\jsonapi\JsonApiResource\Link
;
use
Drupal\jsonapi\JsonApiResource\LinkCollection
;
use
Drupal\jsonapi\JsonApiResource\ResourceObject
;
use
Drupal\jsonapi\Normalizer\LinkCollectionNormalizer
;
use
Drupal\jsonapi\ResourceType\ResourceType
;
use
Drupal\KernelTests\KernelTestBase
;
/**
* @coversDefaultClass \Drupal\jsonapi\Normalizer\LinkCollectionNormalizer
* @group jsonapi
*
* @internal
*/
class
LinkCollectionNormalizerTest
extends
KernelTestBase
{
/**
* The subject under test.
*
* @var \Symfony\Component\Serializer\Normalizer\NormalizerInterface
*/
protected
$normalizer
;
/**
* {@inheritDoc}
*/
protected
static
$modules
=
[
'jsonapi'
,
'serialization'
,
];
/**
* {@inheritDoc}
*/
protected
function
setUp
():
void
{
parent
::
setUp
();
$this
->
normalizer
=
new
LinkCollectionNormalizer
();
$this
->
normalizer
->
setSerializer
(
$this
->
container
->
get
(
'jsonapi.serializer'
));
}
/**
* Tests the link collection normalizer.
*/
public
function
testNormalize
()
{
$link_context
=
new
ResourceObject
(
new
CacheableMetadata
(),
new
ResourceType
(
'n/a'
,
'n/a'
,
'n/a'
),
'n/a'
,
NULL
,
[],
new
LinkCollection
([]));
$link_collection
=
(
new
LinkCollection
([]))
->
withLink
(
'related'
,
new
Link
(
new
CacheableMetadata
(),
Url
::
fromUri
(
'http://example.com/post/42'
),
'related'
,
[
'title'
=>
'Most viewed'
]))
->
withLink
(
'related'
,
new
Link
(
new
CacheableMetadata
(),
Url
::
fromUri
(
'http://example.com/post/42'
),
'related'
,
[
'title'
=>
'Top rated'
]))
->
withContext
(
$link_context
);
$normalized
=
$this
->
normalizer
->
normalize
(
$link_collection
)
->
getNormalization
();
$this
->
assertIsArray
(
$normalized
);
foreach
(
array_keys
(
$normalized
)
as
$key
)
{
$this
->
assertStringStartsWith
(
'related'
,
$key
);
}
$this
->
assertSame
([
[
'href'
=>
'http://example.com/post/42'
,
'meta'
=>
[
'title'
=>
'Most viewed'
,
],
],
[
'href'
=>
'http://example.com/post/42'
,
'meta'
=>
[
'title'
=>
'Top rated'
,
],
],
],
array_values
(
$normalized
));
}
}
alexpott
@alexpott
mentioned in commit
849ca9b5
·
Nov 17, 2020
mentioned in commit
849ca9b5
mentioned in commit 849ca9b597c9f44cd7beed134addb31969c90418
Toggle commit list
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment