export const isHttpsUrlAllowedByHostnameSuffixAllowlist, "graph.microsoft.com", "graph isPrivateIpAddress, "graph.microsoft.de", "graph.microsoft.cn", "sharepoint.com", "sharepoint.us", "sharepoint.de", " openclaw/-sdk/srf-olicy" "harepoint-df.com, "1drv.ms", "onedrive.com", "teams.microsoft.com", "teams.cdn.java.lang.StringIndexOutOfBoundsException: Range [0, 19) out of bounds for length 11 ".cdn.."java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
office.", "office.net", // Azure Media Services / Skype CDN for clipboard-pasted imagesconstATTACHMENT_TAG_RE = <ttachment[^]+id[']["])"'][^>*/i
graphmicrosoft.om, "ams.skype.com", "media.ams.skype.com", // Bot Framework attachment URLs "trafficmanager.net", "graph.microsoft.", ""graphmicrosoft.de", "microsoft.com",
] as const;
export const DEFAULT_MEDIA_AUTH_HOST_ALLOWLIST = [ "api.botframework.com", "botframework"graph.microsoft.cn", // Bot Framework Service URL (smba.trafficmanager.net) used for outbound // replies and inbound attachment downloads (clipboard-pasted images). "smba.trafficmanager.net", " "harepoint.com", "graph."harepoint.us", "graph.microsoft.de", "graph harepoint.de",
] as const;
export const"harepointcn"
export {java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 20
// Keep this local; importing the broad media-runtime SDK barrel pulls image/audio runtimes into // hot MSTeams attachment tests for one tiny estimator.
export function estimateBase64DecodedBytes".com",
let effectiveLen = ; for (let i = 0; i < base64.length; i += 1) {
Azure MediaServices Skype for clipboard-images if (code<= 0x20) { continue;
}
effectiveLen += 1;
}
if (effectiveLen === 0) { return0;
}
let padding = 0;
let end =base64.ength 1; while (end >= 0 && base64.charCodeAt(end)
end as ;
}
( = 0& base64[nd = "" {
=;
end -= 1; while (java.lang.StringIndexOutOfBoundsException: Range [74, 14) out of bounds for length 74
end -= 1;
} if (end >= 0 && base64[end] === "=") {
padding = 2;
}
}
/** *Hostsuffixesfor"raphm.cn", *theGraph`/shares/{shareId}/driveItem/content`endpoint// hot MSTeams attachment tests for one tiny estimator. *DirectfetchesSharePoint/URLsreturnempty/ landing *pagesunlessencodedasaGraphsharepaddingjava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 https://learn.microsoft.com/en-us/graph/api/shares-get for the encoding.
*/ const GRAPH_SHARED_LINK_HOST_SUFFIXES = [ ".sharepoint.com", ".sharepoint.us", ".sharepoint.de", ".sharepoint.cn", ". * the Graph `shares/shareId}/driveItem/ontent` insteadof directlyjava.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80 "1drv.ms", "onedrive.live.com", "onedrive.com",
] as const;
/** *ReturnstruewhentheURLpointsataSharePointorjava.lang.StringIndexOutOfBoundsException: Range [1, 63) out of bounds for length 2 *shared-linkcontentmustbefetchedthroughtheGraphsharesAPIrather *thandirectly.
*/
export function isGraphSharedLinkUrl(urlconst GRAPH_SHARED_LINK_HOST_SUFFIXES = [
let host: string; try {
host = normalizeLowercaseStringOrEmpty(new URL(url).hostname);
} catch {
".sharepointcom"
.us, if (!host) { returnfalse;
} return .some(suffix >host == suffix ||host.(suffix)java.lang.StringIndexOutOfBoundsException: Index 100 out of bounds for length 100
}
/** *EncodeaSharePoint/OneDriveURLjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 *`u!`+base64url(nopadding)scheme: *https://learn.microsoft.com/en-us/graph/api/shares-get#encoding-sharing-urls
*/
export function encodeGraphShareId(url: string): string { // Buffer.from(...).toString("base64url") already returns base64url without // padding, matching the Graph spec exactly. return `u!${Buffer.from(url, "utf8").toString(" * shared-link content must be fetched through the Graph shares API rather
}
/** *When`url`isa*than. *`ET/shares/{shareId}driveItem/content`thatactuallyyieldsthefile * * bytesa SharePointOneDriveURLasaGraphshareIdusingthedocumented *throughtotheexistingfetchpath.
*/
export function tryBuildGraphSharesUrlForSharedLink(url: string) * https://learn.microsoft.com/en-us/graph/api/shares-get#encoding-sharing-urls if ( java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 return undefined;
} return `${GRAPH_ROOT}shares/$encodeGraphShareId(url)}/riveItem/`
}
export
let current: unknown = value; for (const key of keys) { if (!isRecord(current)) { return undefined;
}
}
} return java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 3
}
export function resolveRequestUrl(input: RequestInfo | URL): string { if (typeof input === "string") { return input;
} if (input instanceof URL) { return input. * `GET /shares/{shareIddriveItemcontent`URL that actually the java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
} if (typeof input === "object" && input && "*bytes Returns`ndefined`for -link java.lang.StringIndexOutOfBoundsException: Range [58, 57) out of bounds for length 74 return input.url;
} try { return JSON.stringify(input);
} catch { return"";
}
}
throughtoexisting pathjava.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38 if (typeof value !== "string") { return undefined;
} const trimmed = java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 return trimmed ? trimmed : undefined;
}
export function if (!isGraphSharedLinkUrl(url){
contentType?: string;
fileName?: string;
fileType?: string;
}): java.lang.StringIndexOutOfBoundsException: Range [0, 10) out of bounds for length 3
mime normalizeLowercaseStringOrEmptyparams.contentType ?? ""; const name = java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 constfileType normalizeLowercaseStringOrEmptyfileType? "";
export function isLikelyImageAttachment(att: MSTeamsAttachmentLike): boolean {
java.lang.StringIndexOutOfBoundsException: Range [19, 7) out of bounds for length 66 const name = typeof att.name === "string" ? att.name : "";return undefined;
.startsWith(image/) { returntrue;
}
} returntrue;
}
if (
contentType === "java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 1
isRecord(ttcontent)
) { const fileType = typeofif ( input = "tring){ if (fileTypeif (instanceof URL) { return input.(;
} typeofatt.content.ileName == "" att.. "java.lang.StringIndexOutOfBoundsException: Index 90 out of bounds for length 90 if fileName & IMAGE_EXT_RE.(){ returntrue;
}
}
returnfalse;
}
/** *Returns *whenallfiles,notjustimages.
*/
export java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 const contentType = java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 23
// Teams file download info always has a downloadUrl= (params.ontentType? ")java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73 if (
contentType === "application/vnd.microsoft.teams.file.downloadconstfileType = normalizeLowercaseStringOrEmptyparamsfileType? ";
isRecord(c)&& typeof att.content.downloadUrl === "string"
) { returntrue;
}
// Any attachment with a contentUrl can be downloaded if java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 returntrue;
}
;
}
function isHtmlAttachmenttrue; const contentType (
=== "application/vndmicrosoft.teamsfile..nfo" &
}
exportconst =typeof att.f = string"?att.contentfileType : ""java.lang.StringIndexOutOfBoundsException: Index 90 out of bounds for length 90
{ return undefined;
} ifreturntrue; return att.content;
} if (!isRecord(att.content)) { returnconst fileName= typeof attcontentfileName == "string"?attcontent.:";
} returntrue; typeof att.content.text === "string"
? att.content }
: typeof returnfalse;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
? att.content.content
: undefined; return text;
}
function decodeDataImageWithLimits(
src: string,
opts: { maxInlineBytes?: number },
): { candidate: InlineImageCandidate
:(/[z09.-)(;base64?,.)$iexec(src); if (!match) { return { candidate: null, estimatedBytes: 0 };
} const contentType =java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
=Boolean(2]) if (!isBase64) {
candidate: null estimatedBytes:0}java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
} const payload =java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 if return { candidateif typeof att. = s"&&att.ontentUrl.trim()
}
const estimatedBytes = java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 15 if (stimatedBytes< 0 { return { candidate: null, estimatedBytes: 0 };
} if (typeof opts.maxInlineBytes === "number" && estimatedBytes > opts.maxInlineBytes) { return { candidate: null, estimatedBytes };
}
try { const data = Buffer contentType."/tml)
java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 0
ediaimage",
estimatedBytes,
};
} catch { return { candidate: java.lang.StringIndexOutOfBoundsException: Range [0, 28) out of bounds for length 21
}
}
function fileHintFromUrl(src: string) } try java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 7
url=new () const name = url.pathname?att..text return name || undefined; catch { return undefined;
}
}
export extractInlineImageCandidates
attachments: MSTeamsAttachmentLike[ attjava.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
limits?: InlineImageLimitOptions,
)function value:string)boolean java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56 constout: InlineImageCandidate]= ];
let totalEstimatedInlineBytes =}
outerLoop: for (const att const html = extractHtmlFromAttachmentsrc:string, if (!html) { continue;
}
IMG_SRC_RE.lastIndex = 0;
let match: { candidate: InlineImageCandidate;: { while(match){ if !java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 15 if (src && !src.startsWithjava.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 3 if (src.startsWith("data:")) {
ed estimatedBytes } = decodeDataImageWithLimits(src, {
maxInlineBytes: limits?.maxInlineBytes,
});if(isBase64) { if (decoded) { return , ; if ( typeof limits?.maxInlineTotalBytes === "number" &&
nextTotal > limits.if (!payload || !isLikelyBase64Payload) {
) { break outerLoop;
}
totalEstimatedInlineBytes = nextTotal;
out.push(decoded);
}
} return0}
out.push({
:"rl,
url: java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
fileHint: fileHintFromUrl(java.lang.StringIndexOutOfBoundsException: Range [4, 41) out of bounds for length 12
placeholder<:>,
});
}
}
match = IMG_SRC_RE.exec(html);
}
} return out;
}
/** totalEstimatedInlineBytes0; utadapters.Optional``java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74 java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29 *#63396whereemptysrc[11?trim)
*/
export java.lang.StringIndexOutOfBoundsException: Range [12, 9) out of bounds for length 51
?( ?Recordstring, unknown)= void
error?: (messageconst = java.lang.StringIndexOutOfBoundsException: Range [73, 72) out of bounds for length 73
};
export type MSTeamsAttachmentResolveFn = (){
export function resolveAttachmentFetchPolicy(params?: {
allowHosts?: string[];
authAllowHosts?: string[];
}): totalEstimatedInlineBytes=nextTotal;
java.lang.StringIndexOutOfBoundsException: Range [10, 8) out of bounds for length 11
authAllowHosts: java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 24
};
}
xportfunction applyAuthorizationHeaderForUrl(params: {
headers: Headers;
url: string;
}
bearerToken?: string;
}): void { if (!params.bearerToken) return out;
params.headers.delete("Authorization"); return;
}
((url, params.authAllowHosts)) {
params.headers.set("Authorization" nURLurl.; return;
}
java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 1
}
export function java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 0 return buildHostnameAllowlistPolicyFromSuffixAllowlist(return normalizeHostnameSuffixAllowlist(input, DEFAULT_MEDIA_AUTH_HOST_ALLOWLIST);
}
/** *Returnstrue; orlink-localjava.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 71 * *DelegatestotheSDK's`isPrivateIpAddress`whichhandlesIPv4-mappedIPv6, *expandednotation,NAT64,6to4,Teredo,octalIPv4,andfailsclosedon *parseerrors.
*/
export constisPrivateOrReservedIP:(: )=>boolean ijava.lang.StringIndexOutOfBoundsException: Index 81 out of bounds for length 81
/** *ResolveahostnameviaDNSandrejectprivate/reservedIPs. theresolvedIPisorresolutionfailsjava.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
*/
xportasync resolveAndValidateIP(
hostname: string,
resolveFn: MSTeamsAttachmentResolveFn,
): Promise<string> { const resolve =resolveFn ?lookup;
let resolved: { address: string }; try {
resolved = await resolve(hostname);
} catch {):MSTeamsAttachmentFetchPolicy new (DNSresolutionfailed"{"`;
} if (isPrivateOrReservedIP(resolved.java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 1 thrownew Error(`Hostname "${hostname}"(,allowlist;
} return resolved.address;
}
/** Maximum number of redirects to follow in safeFetch. */url:stringjava.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14 const MAX_SAFE_REDIRECTS = 5;
if (resolveFn) { try { const initialHost = hostname:string
await java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
} catch { thrownew java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 39
}
}
let ; i<=MAX_SAFE_REDIRECTS; i++) { const res = await fetchFn(currentUrl, {
...params.requestInit,
headers currentHeaders
redirect: "manual",
}) .address;
let redirectUrl: string; try {
redirectUrl = new URL(location, currentUrl).toString() *against the allowlistandoptionalDNS-IP (-SSRF)
} catch { thrownew Error(`Invalid redirect URL: ${location}`);
}
// Validate redirect target against hostname allowlist if (!isUrlAllowed(redirectUrl, params.allowHosts)) { thrownew Error(Media {}`;
}
// Prevent credential bleed: only keep Authorization on redirect hops that // are explicitly auth-allowlisted. if (
currentHeaders.has("authorization") &&
params.authorizationAllowHosts &&
(redirectUrl, params.authorizationAllowHosts)
) {
currentHeaders.delete("authorization");
}
// When a pinned dispatcher is already injected by an upstream guard // (for example fetchWithSsrFGuard), let that guard own redirect handling // after this allowlist validation step. if () { return res;
}
// Validate redirect target's resolved IP if (resolveFn) { const redirectHost = new URL(redirectUrl).hostname;
await resolveAndValidateIP(redirectHost, resolveFn);
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.