diff --git a/docs/docset/generate_docset.py b/docs/docset/generate_docset.py index e09e8d6d1..6f6a6e423 100755 --- a/docs/docset/generate_docset.py +++ b/docs/docset/generate_docset.py @@ -337,14 +337,17 @@ def is_remote(url) -> bool: def download(url, docs) -> str: """Download url into assets/external and return the path relative to docs.""" u = urllib.parse.urlparse(url if not url.startswith('//') else 'https:' + url) + if u.scheme.lower() not in ('http', 'https'): + raise ValueError(f'not an http(s) URL: {url}') req = urllib.request.Request(u.geturl(), headers={'User-Agent': USER_AGENT}) - with urllib.request.urlopen(req, timeout=20) as r: + # (the scheme is checked above) + with urllib.request.urlopen(req, timeout=20) as r: # nosec B310 data = r.read() ctype = r.headers.get_content_type() path = urllib.parse.unquote(u.path).lstrip('/') ext = os.path.splitext(path)[1] if u.query or not ext or path.endswith('/'): - digest = hashlib.sha1(url.encode()).hexdigest()[:12] + digest = hashlib.sha1(url.encode(), usedforsecurity=False).hexdigest()[:12] path = os.path.join(os.path.dirname(path), digest + CONTENT_TYPE_EXT.get(ctype, ext or '.bin')) rel = os.path.normpath(os.path.join('assets', 'external', u.hostname, path)) out = os.path.join(docs, rel) @@ -385,7 +388,8 @@ def localize_images(docs) -> None: def load_mkdocs_yml() -> dict: """Load mkdocs.yml, ignoring tags like !ENV and !!python/name.""" with open(MKDOCS_YML, encoding='utf-8') as f: - return yaml.load(f, Loader=Loader) + # (Loader is a yaml.SafeLoader) + return yaml.load(f, Loader=Loader) # nosec B506 def localize_site_urls(docs, site_url) -> None: diff --git a/include/nlohmann/detail/view/errors.hpp b/include/nlohmann/detail/view/errors.hpp index e45956c8c..6e275608b 100644 --- a/include/nlohmann/detail/view/errors.hpp +++ b/include/nlohmann/detail/view/errors.hpp @@ -66,7 +66,7 @@ template { if (f.code == error_code::input_too_large) { - // (the limit is detail::view::max_input_size: 4 GiB minus 16 bytes) + // (the limit is detail::view::max_input_size(): 4 GiB minus 16 bytes) NLOHMANN_VIEW_THROW(out_of_range::create(416, "input of 4294967280 bytes or more is not supported by json_document", nullptr)); } const BasicJsonType accepted = BasicJsonType::parse(src, src + size, nullptr, true, ignore_comments, ignore_trailing_commas); diff --git a/include/nlohmann/detail/view/node.hpp b/include/nlohmann/detail/view/node.hpp index 4f3d1fe2b..cee98cdb7 100644 --- a/include/nlohmann/detail/view/node.hpp +++ b/include/nlohmann/detail/view/node.hpp @@ -32,7 +32,10 @@ static_assert(static_cast(value_t::null) == 0 && static_cast // all_of, min -#include // size_t +#include // array +#include // nullptr_t, size_t // IWYU pragma: keep #include // uint8_t, uint32_t #include // memcpy, strlen #include // distance, input_iterator_tag, iterator_traits @@ -45,6 +46,20 @@ #include // IWYU pragma: export +// json.hpp provides the library's types and macros used below (it includes +// the headers that define them); json_view.hpp must not include them again, +// because the amalgamated json_view.hpp only includes json.hpp +// IWYU pragma: no_include +// IWYU pragma: no_include "nlohmann/detail/abi_config.hpp" +// IWYU pragma: no_include "nlohmann/detail/abi_macros.hpp" +// IWYU pragma: no_include "nlohmann/detail/input/input_adapters.hpp" +// IWYU pragma: no_include "nlohmann/detail/json_pointer.hpp" +// IWYU pragma: no_include "nlohmann/detail/meta/cpp_future.hpp" +// IWYU pragma: no_include "nlohmann/detail/string_concat.hpp" +// IWYU pragma: no_include "nlohmann/detail/value_t.hpp" +// IWYU pragma: no_include "nlohmann/json.hpp" +// IWYU pragma: no_include "nlohmann/json_fwd.hpp" + // the view builds on internals of the library: both must be the same version #if NLOHMANN_JSON_VERSION_MAJOR != 3 || NLOHMANN_JSON_VERSION_MINOR != 12 || NLOHMANN_JSON_VERSION_PATCH != 0 #error "json_view.hpp requires json.hpp of the same version (3.12.0)" @@ -54,7 +69,6 @@ #include #include #include -#include #include #include #include @@ -1341,7 +1355,7 @@ class basic_json_document d.discarded = true; detail::view::parse_failure failure; bool ok = false; - if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size)) + if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size())) { failure.code = detail::view::error_code::input_too_large; } diff --git a/single_include/nlohmann/json_view.hpp b/single_include/nlohmann/json_view.hpp index 70b390810..2ee84ab24 100644 --- a/single_include/nlohmann/json_view.hpp +++ b/single_include/nlohmann/json_view.hpp @@ -27,7 +27,8 @@ #define INCLUDE_NLOHMANN_JSON_VIEW_HPP_ #include // all_of, min -#include // size_t +#include // array +#include // nullptr_t, size_t // IWYU pragma: keep #include // uint8_t, uint32_t #include // memcpy, strlen #include // distance, input_iterator_tag, iterator_traits @@ -45,6 +46,20 @@ #include // IWYU pragma: export +// json.hpp provides the library's types and macros used below (it includes +// the headers that define them); json_view.hpp must not include them again, +// because the amalgamated json_view.hpp only includes json.hpp +// IWYU pragma: no_include +// IWYU pragma: no_include "nlohmann/detail/abi_config.hpp" +// IWYU pragma: no_include "nlohmann/detail/abi_macros.hpp" +// IWYU pragma: no_include "nlohmann/detail/input/input_adapters.hpp" +// IWYU pragma: no_include "nlohmann/detail/json_pointer.hpp" +// IWYU pragma: no_include "nlohmann/detail/meta/cpp_future.hpp" +// IWYU pragma: no_include "nlohmann/detail/string_concat.hpp" +// IWYU pragma: no_include "nlohmann/detail/value_t.hpp" +// IWYU pragma: no_include "nlohmann/json.hpp" +// IWYU pragma: no_include "nlohmann/json_fwd.hpp" + // the view builds on internals of the library: both must be the same version #if NLOHMANN_JSON_VERSION_MAJOR != 3 || NLOHMANN_JSON_VERSION_MINOR != 12 || NLOHMANN_JSON_VERSION_PATCH != 0 #error "json_view.hpp requires json.hpp of the same version (3.12.0)" @@ -208,7 +223,10 @@ static_assert(static_cast(value_t::null) == 0 && static_cast { if (f.code == error_code::input_too_large) { - // (the limit is detail::view::max_input_size: 4 GiB minus 16 bytes) + // (the limit is detail::view::max_input_size(): 4 GiB minus 16 bytes) NLOHMANN_VIEW_THROW(out_of_range::create(416, "input of 4294967280 bytes or more is not supported by json_document", nullptr)); } const BasicJsonType accepted = BasicJsonType::parse(src, src + size, nullptr, true, ignore_comments, ignore_trailing_commas); @@ -4122,8 +4140,6 @@ class editor } // namespace detail NLOHMANN_JSON_NAMESPACE_END -// #include - // #include // #include @@ -8276,7 +8292,7 @@ class basic_json_document d.discarded = true; detail::view::parse_failure failure; bool ok = false; - if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size)) + if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size())) { failure.code = detail::view::error_code::input_too_large; } diff --git a/tests/src/unit-json_view.cpp b/tests/src/unit-json_view.cpp index c291f22f6..1850d6deb 100644 --- a/tests/src/unit-json_view.cpp +++ b/tests/src/unit-json_view.cpp @@ -417,7 +417,7 @@ TEST_CASE("json_view") { // 32-bit offsets: the limit is 4 GiB minus 16 bytes (a margin below 2^32), // which is what the exception message and the documentation say - const std::size_t limit = nlohmann::detail::view::max_input_size; + const std::size_t limit = nlohmann::detail::view::max_input_size(); CHECK(limit == std::size_t{4294967279u}); const oversized_input input{limit + 1};