mirror of
https://github.com/nlohmann/json.git
synced 2026-10-10 08:27:13 +00:00
Reject integer lengths in json_document::parse
parse(ptr, len) compiled: len converted to allow_exceptions, and ptr was read as a C string, past the end of a buffer without a terminating NUL. Delete the overloads of parse, parse_copy, accept, and read that take an integer other than bool where the flags are expected. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
7 files changed
+88
No files matched your search
@@ -59,6 +59,13 @@ struct classify_input
|
||||
// NOLINTEND(readability-avoid-nested-conditional-operator)
|
||||
};
|
||||
|
||||
/// an integer type other than bool: a length passed where a flag is expected
|
||||
template<typename T>
|
||||
struct is_integer_not_bool : std::is_integral<T> {};
|
||||
|
||||
template<>
|
||||
struct is_integer_not_bool<bool> : std::false_type {};
|
||||
|
||||
/// std::basic_string guarantees a NUL at data()[size()] (the parser's sentinel)
|
||||
template<typename T>
|
||||
struct is_std_string : std::false_type {};
|
||||
|
||||
@@ -291,6 +291,13 @@ class basic_json_document
|
||||
return d;
|
||||
}
|
||||
|
||||
/// parse(ptr, len) does not compile: len would convert to allow_exceptions
|
||||
/// and ptr be read as a C string (as for the overloads of parse_copy,
|
||||
/// accept, and read below)
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
static typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, basic_json_document>::type
|
||||
parse(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
/// parse [first, last)
|
||||
template<typename IteratorType, typename std::enable_if<
|
||||
std::is_base_of<std::input_iterator_tag, typename std::iterator_traits<IteratorType>::iterator_category>::value, int>::type = 0>
|
||||
@@ -318,6 +325,10 @@ class basic_json_document
|
||||
return d;
|
||||
}
|
||||
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
static typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, basic_json_document>::type
|
||||
parse_copy(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
/// check whether the input is valid JSON (the result of basic_json::accept)
|
||||
template<typename InputType>
|
||||
static bool accept(InputType&& input, const bool ignore_comments = false, const bool ignore_trailing_commas = false)
|
||||
@@ -327,6 +338,10 @@ class basic_json_document
|
||||
return !d.is_discarded();
|
||||
}
|
||||
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
static typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, bool>::type
|
||||
accept(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
/// parse into this document, reusing its memory
|
||||
template<typename InputType>
|
||||
// flawfinder: ignore (a member function, not POSIX read())
|
||||
@@ -339,6 +354,11 @@ class basic_json_document
|
||||
std::integral_constant<detail::view::input_kind, detail::view::classify_input<InputType>::value> {});
|
||||
}
|
||||
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
// flawfinder: ignore (a member function, not POSIX read())
|
||||
typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, void>::type
|
||||
read(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
////////////
|
||||
// access //
|
||||
////////////
|
||||
|
||||
Reference in new issue
Block a user