diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..d862e03 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2025 Apps Dev Team + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/composer.json b/composer.json index fac40cf..0207ae4 100644 --- a/composer.json +++ b/composer.json @@ -5,6 +5,7 @@ "src/" ] }, + "license": "MIT", "require": { "nette/utils": "^2.0|^3.0|^4.0" }, diff --git a/src/Filters/Image.php b/src/Filters/Image.php index 7a272aa..556a82d 100644 --- a/src/Filters/Image.php +++ b/src/Filters/Image.php @@ -33,13 +33,15 @@ public function __construct(string $path, string $dir = 'thumbnails', int $multi */ public function format(string $url, int $width, int $height, int $mode = \Nette\Utils\Image::OrSmaller, int $format = IMAGETYPE_WEBP): string { + $originalUrl = $url; + $isRemoteUrl = $this->isRemoteUrl($url); // original file does not exist if ($isRemoteUrl) { $contents = @file_get_contents($url); if (!$contents) { - return $url; + return $originalUrl; } list($urlWithoutExtension,) = $this->splitUrlOnLastDot($this->removeProtocol($url)); @@ -47,12 +49,12 @@ public function format(string $url, int $width, int $height, int $mode = \Nette\ } else { $url = trim($url, '/'); if (!file_exists($this->path . '/' . $url)) { - return $url; + return $originalUrl; } $contents = file_get_contents($this->path . '/' . $url); if ($this->isAnimatedGif($contents)) { - return $url; + return $originalUrl; } list($urlWithoutExtension,) = $this->splitUrlOnLastDot($url); @@ -61,6 +63,10 @@ public function format(string $url, int $width, int $height, int $mode = \Nette\ $width = $width * $this->multiplier; $height = $height * $this->multiplier; $ext = pathinfo(parse_url($url, PHP_URL_PATH), PATHINFO_EXTENSION); + if ($ext === 'svg') { + return $originalUrl; + } + $newFile = $this->dir . '/' . $urlWithoutExtension . '_' . $width . '_' . $height . '_' . $mode . '_' . $ext . '.' . self::FormatToExtensions[$format]; $this->createImage($contents, $width, $height, $mode, $format, $this->path . '/' . $newFile); diff --git a/src/Guzzle.php b/src/Guzzle.php index ada18ab..60ba4a1 100644 --- a/src/Guzzle.php +++ b/src/Guzzle.php @@ -5,11 +5,15 @@ use GuzzleHttp\Exception\ConnectException; use GuzzleHttp\Exception\GuzzleException; use GuzzleHttp\Exception\RequestException; -use GuzzleHttp\Psr7\Message; +use Psr\Http\Message\MessageInterface; +use Psr\Http\Message\RequestInterface; +use Psr\Http\Message\ResponseInterface; use Throwable; class Guzzle { + private const MAX_BODY_LENGTH = 10000; + /** * @throws Throwable */ @@ -18,13 +22,75 @@ public static function handleException(Throwable $e): ?Exception if ($e instanceof GuzzleException) { $message = ''; if ($e instanceof ConnectException || $e instanceof RequestException) { - $message = "--- REQUEST ---\n" . Message::toString($e->getRequest()) . "\n --- RESPONSE ---\n"; + $message = "--- REQUEST ---\n" . self::sanitizeMessage(self::messageToString($e->getRequest())) . "\n --- RESPONSE ---\n"; } - $message .= ($e instanceof RequestException && $e->getResponse() ? Message::toString($e->getResponse()) : $e->getMessage()); + $message .= ($e instanceof RequestException && $e->getResponse() ? self::sanitizeMessage(self::messageToString($e->getResponse())) : $e->getMessage()); throw new Exception($message); } throw $e; } + + /** + * Obdoba GuzzleHttp\Psr7\Message::toString(), ale tělo čte ze streamu jen do MAX_BODY_LENGTH. + * Message::toString() načítá celé tělo do paměti, což u velkých těl (např. upload souboru + * v multipart requestu) shodí proces na memory limitu ještě před ořezáním v sanitizeMessage(). + */ + private static function messageToString(MessageInterface $message): string + { + if ($message instanceof RequestInterface) { + $msg = trim($message->getMethod() . ' ' . $message->getRequestTarget()) . ' HTTP/' . $message->getProtocolVersion(); + if (!$message->hasHeader('host')) { + $msg .= "\r\nHost: " . $message->getUri()->getHost(); + } + } elseif ($message instanceof ResponseInterface) { + $msg = 'HTTP/' . $message->getProtocolVersion() . ' ' . $message->getStatusCode() . ' ' . $message->getReasonPhrase(); + } else { + $msg = ''; + } + + foreach ($message->getHeaders() as $name => $values) { + $msg .= "\r\n" . $name . ': ' . implode(', ', $values); + } + + $body = ''; + $stream = $message->getBody(); + if ($stream->isSeekable() && $stream->isReadable()) { + $size = $stream->getSize(); + $stream->seek(0); + $body = $stream->read(self::MAX_BODY_LENGTH); + if ($size === null || $size > self::MAX_BODY_LENGTH) { + $body .= "\n\n... [truncated" . ($size !== null ? ', total ' . $size . ' bytes' : '') . ']'; + } + } + + return $msg . "\r\n\r\n" . $body; + } + + private static function sanitizeMessage(string $message): string + { + // Odstraneni binarnich dat (null byty apod.) + if (preg_match('/[^\x20-\x7E\x0A\x0D\t]/u', $message)) { + // Najdeme konec hlavicek (prazdny radek) + $headerEnd = strpos($message, "\r\n\r\n"); + if ($headerEnd === false) { + $headerEnd = strpos($message, "\n\n"); + } + + if ($headerEnd !== false) { + $headers = substr($message, 0, $headerEnd); + return $headers . "\n\n[binary data removed]"; + } + + return '[binary data removed]'; + } + + // Oriznuti prilis dlouhych textovych odpovedi + if (strlen($message) > self::MAX_BODY_LENGTH) { + return substr($message, 0, self::MAX_BODY_LENGTH) . "\n\n... [truncated, total " . strlen($message) . " bytes]"; + } + + return $message; + } } diff --git a/src/JsComponents.php b/src/JsComponents.php index 12b9686..2e49c73 100644 --- a/src/JsComponents.php +++ b/src/JsComponents.php @@ -2,17 +2,25 @@ namespace ADT\Utils; +use Nette\Utils\Json; + class JsComponents { protected array $components = []; public function generateConfig(): string { - return json_encode($this->components); + return Json::encode($this->components); } public function setRecaptcha(string $siteKey): string { return $this->components['recaptcha']['siteKey'] = $siteKey; } + + public function setComponents(array $components): self + { + $this->components = array_merge($this->components, $components); + return $this; + } } diff --git a/src/TErrorPresenter.php b/src/TErrorPresenter.php index 42a921c..6f1dcff 100644 --- a/src/TErrorPresenter.php +++ b/src/TErrorPresenter.php @@ -2,6 +2,7 @@ namespace ADT\Utils; +use Nette\Application\Attributes\Persistent; use Nette\Application\BadRequestException; use Nette\Application\Helpers; use Nette\Routing\Router; @@ -15,7 +16,7 @@ trait TErrorPresenter protected bool $log404 = true; protected bool $log500 = true; - /** @persistent */ + #[Persistent] public $url; public function __construct(Router $router)