diff --git a/docs/docset/generate_docset.py b/docs/docset/generate_docset.py index e09e8d6d1..6f6a6e423 100755 --- a/docs/docset/generate_docset.py +++ b/docs/docset/generate_docset.py @@ -337,14 +337,17 @@ def is_remote(url) -> bool: def download(url, docs) -> str: """Download url into assets/external and return the path relative to docs.""" u = urllib.parse.urlparse(url if not url.startswith('//') else 'https:' + url) + if u.scheme.lower() not in ('http', 'https'): + raise ValueError(f'not an http(s) URL: {url}') req = urllib.request.Request(u.geturl(), headers={'User-Agent': USER_AGENT}) - with urllib.request.urlopen(req, timeout=20) as r: + # (the scheme is checked above) + with urllib.request.urlopen(req, timeout=20) as r: # nosec B310 data = r.read() ctype = r.headers.get_content_type() path = urllib.parse.unquote(u.path).lstrip('/') ext = os.path.splitext(path)[1] if u.query or not ext or path.endswith('/'): - digest = hashlib.sha1(url.encode()).hexdigest()[:12] + digest = hashlib.sha1(url.encode(), usedforsecurity=False).hexdigest()[:12] path = os.path.join(os.path.dirname(path), digest + CONTENT_TYPE_EXT.get(ctype, ext or '.bin')) rel = os.path.normpath(os.path.join('assets', 'external', u.hostname, path)) out = os.path.join(docs, rel) @@ -385,7 +388,8 @@ def localize_images(docs) -> None: def load_mkdocs_yml() -> dict: """Load mkdocs.yml, ignoring tags like !ENV and !!python/name.""" with open(MKDOCS_YML, encoding='utf-8') as f: - return yaml.load(f, Loader=Loader) + # (Loader is a yaml.SafeLoader) + return yaml.load(f, Loader=Loader) # nosec B506 def localize_site_urls(docs, site_url) -> None: diff --git a/include/nlohmann/detail/view/errors.hpp b/include/nlohmann/detail/view/errors.hpp index e45956c8c..6e275608b 100644 --- a/include/nlohmann/detail/view/errors.hpp +++ b/include/nlohmann/detail/view/errors.hpp @@ -66,7 +66,7 @@ template { if (f.code == error_code::input_too_large) { - // (the limit is detail::view::max_input_size: 4 GiB minus 16 bytes) + // (the limit is detail::view::max_input_size(): 4 GiB minus 16 bytes) NLOHMANN_VIEW_THROW(out_of_range::create(416, "input of 4294967280 bytes or more is not supported by json_document", nullptr)); } const BasicJsonType accepted = BasicJsonType::parse(src, src + size, nullptr, true, ignore_comments, ignore_trailing_commas); diff --git a/include/nlohmann/detail/view/node.hpp b/include/nlohmann/detail/view/node.hpp index 4f3d1fe2b..cee98cdb7 100644 --- a/include/nlohmann/detail/view/node.hpp +++ b/include/nlohmann/detail/view/node.hpp @@ -32,7 +32,10 @@ static_assert(static_cast(value_t::null) == 0 && static_cast detail::view::max_input_size)) + if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size())) { failure.code = detail::view::error_code::input_too_large; } diff --git a/single_include/nlohmann/json_view.hpp b/single_include/nlohmann/json_view.hpp index 653dbcd66..cdae60903 100644 --- a/single_include/nlohmann/json_view.hpp +++ b/single_include/nlohmann/json_view.hpp @@ -223,7 +223,10 @@ static_assert(static_cast(value_t::null) == 0 && static_cast { if (f.code == error_code::input_too_large) { - // (the limit is detail::view::max_input_size: 4 GiB minus 16 bytes) + // (the limit is detail::view::max_input_size(): 4 GiB minus 16 bytes) NLOHMANN_VIEW_THROW(out_of_range::create(416, "input of 4294967280 bytes or more is not supported by json_document", nullptr)); } const BasicJsonType accepted = BasicJsonType::parse(src, src + size, nullptr, true, ignore_comments, ignore_trailing_commas); @@ -6892,7 +6895,7 @@ class basic_json_document d.discarded = true; detail::view::parse_failure failure; bool ok = false; - if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size)) + if (NLOHMANN_VIEW_UNLIKELY(size > detail::view::max_input_size())) { failure.code = detail::view::error_code::input_too_large; } diff --git a/tests/src/unit-json_view.cpp b/tests/src/unit-json_view.cpp index c291f22f6..1850d6deb 100644 --- a/tests/src/unit-json_view.cpp +++ b/tests/src/unit-json_view.cpp @@ -417,7 +417,7 @@ TEST_CASE("json_view") { // 32-bit offsets: the limit is 4 GiB minus 16 bytes (a margin below 2^32), // which is what the exception message and the documentation say - const std::size_t limit = nlohmann::detail::view::max_input_size; + const std::size_t limit = nlohmann::detail::view::max_input_size(); CHECK(limit == std::size_t{4294967279u}); const oversized_input input{limit + 1};