Mercurial > zeropaste
annotate app/models/paste.rb @ 418:a69dd2d37950
Prevent adding unrelated classes and funny characters
author | nanaya <me@myconan.net> |
---|---|
date | Thu, 17 Sep 2015 01:13:14 +0900 |
parents | 2ad092e60975 |
children | 9369ad2f2ce8 |
rev | line source |
---|---|
2 | 1 class Paste < ActiveRecord::Base |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
2 attr_accessor :is_private |
379 | 3 after_initialize :set_privacy, :if => :new_record? |
4 | |
70
8f0fb869e770
Limit pastes to 100/hour per IP address.
Edho Arief <edho@myconan.net>
parents:
51
diff
changeset
|
5 before_validation :paste_limit |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
6 before_validation :convert_newlines |
2 | 7 before_validation :set_paste_hash |
176
a9dba6a3008b
Initial work to add paste deletion.
Edho Arief <edho@myconan.net>
parents:
71
diff
changeset
|
8 before_validation :set_paste_key |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
9 before_validation :set_paste_secret |
176
a9dba6a3008b
Initial work to add paste deletion.
Edho Arief <edho@myconan.net>
parents:
71
diff
changeset
|
10 validates :paste, :paste_hash, :key, :ip, :presence => true |
267
0bf1d6f75baa
Accidentally limited pastes to 0 characters.
edogawaconan <me@myconan.net>
parents:
265
diff
changeset
|
11 validates :paste, :length => { :maximum => 1_000_000 } |
2 | 12 |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
13 def to_param |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
14 path |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
15 end |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
16 |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
17 def self.safe_find(raw_id) |
247 | 18 id, secret = raw_id.to_s.split("-") |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
19 return unless id.to_i.to_s == id |
229
388504e43bcf
Properly return 404 when requesting invalid paste.
Edho Arief <edho@myconan.net>
parents:
210
diff
changeset
|
20 begin |
330 | 21 where(:secret => secret).find(id) |
229
388504e43bcf
Properly return 404 when requesting invalid paste.
Edho Arief <edho@myconan.net>
parents:
210
diff
changeset
|
22 rescue ActiveRecord::RecordNotFound |
388504e43bcf
Properly return 404 when requesting invalid paste.
Edho Arief <edho@myconan.net>
parents:
210
diff
changeset
|
23 nil |
388504e43bcf
Properly return 404 when requesting invalid paste.
Edho Arief <edho@myconan.net>
parents:
210
diff
changeset
|
24 end |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
25 end |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
26 |
373
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
27 def self.graceful_create(params) |
376 | 28 paste = new(params) |
373
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
29 fresh = true |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
30 created = true |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
31 |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
32 begin |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
33 created = paste.save |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
34 rescue ActiveRecord::RecordNotUnique |
376 | 35 paste = find_by(:ip => paste.ip, :paste_hash => paste.paste_hash) |
373
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
36 fresh = false |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
37 end |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
38 |
376 | 39 [created, paste, fresh] |
373
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
40 end |
6e3e1e7b0212
Handle unique error in model instead of controller.
nanaya <me@myconan.net>
parents:
330
diff
changeset
|
41 |
316
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
42 def paste_gzip=(paste) |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
43 self.paste = ActiveSupport::Gzip.decompress paste |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
44 end |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
45 |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
46 def paste_gzip_base64=(paste) |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
47 self.paste_gzip = Base64.decode64(paste) |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
48 end |
61f7f258a6fb
Move from-gzip paste parsing to model.
edogawaconan <me@myconan.net>
parents:
290
diff
changeset
|
49 |
265
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
50 def safe_destroy(param_key) |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
51 if key == param_key |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
52 destroy |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
53 else |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
54 errors.add(:key, "is invalid") |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
55 false |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
56 end |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
57 end |
6cca1ab53337
Infinitely better error messages and notice.
edogawaconan <me@myconan.net>
parents:
255
diff
changeset
|
58 |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
59 def path |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
60 [id, secret.presence].compact.join("-") |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
61 end |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
62 |
2 | 63 def set_paste_hash |
51
36d07f047ec2
Or maybe not. Still too long with b62. Backed out changeset ba29d6394863
Edho Arief <edho@myconan.net>
parents:
46
diff
changeset
|
64 self.paste_hash = Digest::SHA512.hexdigest("#{paste}\n") |
2 | 65 end |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
66 |
176
a9dba6a3008b
Initial work to add paste deletion.
Edho Arief <edho@myconan.net>
parents:
71
diff
changeset
|
67 def set_paste_key |
a9dba6a3008b
Initial work to add paste deletion.
Edho Arief <edho@myconan.net>
parents:
71
diff
changeset
|
68 self.key ||= SecureRandom.hex(4) |
a9dba6a3008b
Initial work to add paste deletion.
Edho Arief <edho@myconan.net>
parents:
71
diff
changeset
|
69 end |
a9dba6a3008b
Initial work to add paste deletion.
Edho Arief <edho@myconan.net>
parents:
71
diff
changeset
|
70 |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
71 def set_paste_secret |
330 | 72 self.secret = SecureRandom.hex(4) if is_private? |
230
1c750d3cde1b
Correct way to test is_private flag.
Edho Arief <edho@myconan.net>
parents:
229
diff
changeset
|
73 end |
1c750d3cde1b
Correct way to test is_private flag.
Edho Arief <edho@myconan.net>
parents:
229
diff
changeset
|
74 |
1c750d3cde1b
Correct way to test is_private flag.
Edho Arief <edho@myconan.net>
parents:
229
diff
changeset
|
75 def is_private? |
330 | 76 is_private == "1" |
210
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
77 end |
d59731c3c7bf
Add support for is_private flag
Edho Arief <edho@myconan.net>
parents:
197
diff
changeset
|
78 |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
79 def convert_newlines |
330 | 80 self.paste = paste.to_s.gsub("\r\n", "\n").gsub("\r", "\n") |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
81 end |
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
82 |
70
8f0fb869e770
Limit pastes to 100/hour per IP address.
Edho Arief <edho@myconan.net>
parents:
51
diff
changeset
|
83 def paste_limit |
377
4e6afc8140fb
Use Time.zone as per rubocop recommendation.
nanaya <me@myconan.net>
parents:
376
diff
changeset
|
84 ip_post_recent_count = self.class.where(:ip => ip).where("created_at > ?", Time.zone.now - 1.hour).count |
70
8f0fb869e770
Limit pastes to 100/hour per IP address.
Edho Arief <edho@myconan.net>
parents:
51
diff
changeset
|
85 errors.add :base, :limit if ip_post_recent_count > 100 |
8f0fb869e770
Limit pastes to 100/hour per IP address.
Edho Arief <edho@myconan.net>
parents:
51
diff
changeset
|
86 end |
8f0fb869e770
Limit pastes to 100/hour per IP address.
Edho Arief <edho@myconan.net>
parents:
51
diff
changeset
|
87 |
379 | 88 def set_privacy |
89 self.is_private ||= "0" | |
90 end | |
91 | |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
92 def self.fix_all |
255
a894d7696b7e
More useful return of Paste.fix_all.
edogawaconan <me@myconan.net>
parents:
247
diff
changeset
|
93 stats = Hash.new(0) |
376 | 94 all.find_each do |p| |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
95 p.save |
255
a894d7696b7e
More useful return of Paste.fix_all.
edogawaconan <me@myconan.net>
parents:
247
diff
changeset
|
96 stats[:count] += 1 |
a894d7696b7e
More useful return of Paste.fix_all.
edogawaconan <me@myconan.net>
parents:
247
diff
changeset
|
97 stats[:private] += 1 if p.secret |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
98 end |
330 | 99 stats |
22
032686a0c995
Added newline converter, integrity fixups.
Edho Arief <edho@myconan.net>
parents:
2
diff
changeset
|
100 end |
2 | 101 end |