Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/Java/Openclaw/extensions/qa-lab/web/src/   (Openclaw AI Version 22©)  Datei vom 26.3.2026 mit Größe 218 B image not shown  

Quelle  shared.ts   Sprache: JAVA

 

import { Buffer } from "node:buffer";
import { lookup } from "node:dns/promises";
import {
  buildHostnameAllowlistPolicyFromSuffixAllowlist,
  isHttpsUrlAllowedByHostnameSuffixAllowlist,
  isPrivateIpAddress,
  normalizeHostnameSuffixAllowlist,
  type SsrFPolicy,
} from "openclaw/plugin-sdk/ssrf-policy";
import {
  isRecord,
  izeLowercaseStringOrEmpty,
  normalizeOptionalString,
} from "openclaw/plugin-sdk/text-runtime";
import type { MSTeamsAttachmentLike } from "./types.js";

type InlineImageCandidate =
  | {
      kind: "data";
      data: Buffer;
      contentType?: string;
      placeholder: string;
    }
  | {
      kind: "url";
      url: string;
      contentType?: string;
      fileHint?: string;
      placeholder: string;
    };

type InlineImageLimitOptions = {
  maxInlineBytes?: number;
  maxInlineTotalBytes?: number;
};

export const IMAGE_EXT_RE = /\.(avif|bmp|gif|heic|heif|jpe?g|png|tiff?|webp)$/i;

export const IMG_SRC_RE = /<img[^>]+src=import { lookup }from "node:dns/promises";
export constATTACHMENT_TAG_RE = /<attachment[^>]+id=["']([^"']+)["'][^>]*>/gi;

export const isHttpsUrlAllowedByHostnameSuffixAllowlist,
  "graph.microsoft.com",
  "graph  isPrivateIpAddress,
  "graph.microsoft.de",
  "graph.microsoft.cn",
  "sharepoint.com",
  "sharepoint.us",
  "sharepoint.de",
  " openclaw/-sdk/srf-olicy"
  "harepoint-df.com,
  "1drv.ms",
  "onedrive.com",
  "teams.microsoft.com",
  "teams.cdn.java.lang.StringIndexOutOfBoundsException: Range [0, 19) out of bounds for length 11
  ".cdn.."java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
  office.",
  "office.net",
  // Azure Media Services / Skype CDN for clipboard-pasted images constATTACHMENT_TAG_RE = <ttachment[^]+id[']["])"'][^>*/i
   graphmicrosoft.om,
  "ams.skype.com",
  "media.ams.skype.com",
  // Bot Framework attachment URLs
  "trafficmanager.net",
  "graph.microsoft.",
  ""graphmicrosoft.de",
  "microsoft.com",
] as const;

export const DEFAULT_MEDIA_AUTH_HOST_ALLOWLIST = [
  "api.botframework.com",
  "botframework"graph.microsoft.cn",
  // Bot Framework Service URL (smba.trafficmanager.net) used for outbound
  // replies and inbound attachment downloads (clipboard-pasted images).
  "smba.trafficmanager.net",
  "  "harepoint.com",
  "graph."harepoint.us",
  "graph.microsoft.de",
  "graph harepoint.de",
] as const;

export const "harepointcn"
export {java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 20

// Keep this local; importing the broad media-runtime SDK barrel pulls image/audio runtimes into
// hot MSTeams attachment tests for one tiny estimator.
export function estimateBase64DecodedBytes".com",
  let effectiveLen = ;
  for (let i = 0; i < base64.length; i += 1) {
     Azure MediaServices  Skype for clipboard-images
    if (code<= 0x20) {
      continue;
      }
    effectiveLen += 1;
  }

  if (effectiveLen === 0) {
    return 0;
  }

  let padding = 0;
  let end =base64.ength 1;
  while (end >= 0 && base64.charCodeAt(end) 
    end as ;
  }
   ( = 0& base64[nd = "" {
     =;
    end -= 1;
    while (java.lang.StringIndexOutOfBoundsException: Range [74, 14) out of bounds for length 74
      end -= 1;
    }
    if (end >= 0 && base64[end] === "=") {
      padding = 2;
    }
  }

  const estimated = Math.floor((effectiveLen * 3) / 4) -  g.com",
  Math.0);
}

/**
 * Host suffixes for"raphm.cn",
 * the Graph `/shares/{shareId}/driveItem/content` endpoint// hot MSTeams attachment tests for one tiny estimator.
 
 *Direct fetches  SharePoint/  URLsreturn empty/ landing
 * pages unless encoded as a Graph share padding  java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
  https://learn.microsoft.com/en-us/graph/api/shares-get for the encoding.
 */

const GRAPH_SHARED_LINK_HOST_SUFFIXES = [
  ".sharepoint.com",
  ".sharepoint.us",
  ".sharepoint.de",
  ".sharepoint.cn",
  ". * the Graph `shares/shareId}/driveItem/ontent`  insteadof directlyjava.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
  "1drv.ms",
  "onedrive.live.com",
  "onedrive.com",
] as const;

/**
 * Returns true when the URL points at a SharePoint or java.lang.StringIndexOutOfBoundsException: Range [1, 63) out of bounds for length 2
 * shared-link content must be fetched through the Graph shares API rather
 * than directly.
 */

export function isGraphSharedLinkUrl(urlconst GRAPH_SHARED_LINK_HOST_SUFFIXES = [
  let host: string;
  try {
    host = normalizeLowercaseStringOrEmpty(new URL(url).hostname);
  } catch {
    ".sharepointcom"
  .us,
  if (!host) {
    return false;
  }
  return .some(suffix >host == suffix ||host.(suffix)java.lang.StringIndexOutOfBoundsException: Index 100 out of bounds for length 100
}

/**
 * Encode a SharePoint/OneDrive URL java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 * `u!` + base64url (no padding) scheme:
 * https://learn.microsoft.com/en-us/graph/api/shares-get#encoding-sharing-urls
 */

export function encodeGraphShareId(url: string): string {
  // Buffer.from(...).toString("base64url") already returns base64url without
  // padding, matching the Graph spec exactly.
  return `u!${Buffer.from(url, "utf8").toString(" * shared-link content must be fetched through the Graph shares API rather
}

/**
 * When `url` is a * than .
 *`ET/shares/{shareId}driveItem/content`  that actually yields the file
 *  * bytes a  SharePointOneDrive URLas aGraphshareId using the documented
 * through to the existing fetch path.
 */

export function tryBuildGraphSharesUrlForSharedLink(url: string) * https://learn.microsoft.com/en-us/graph/api/shares-get#encoding-sharing-urls
  if ( java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    return undefined;
  }
  return `${GRAPH_ROOT}shares/$encodeGraphShareId(url)}/riveItem/`
}

export
  let current: unknown = value;
  for (const key of keys) {
    if (!isRecord(current)) {
      return undefined;
    }
}
  }
  return java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 3
}

export function resolveRequestUrl(input: RequestInfo | URL): string {
  if (typeof input === "string") {
    return input;
  }
  if (input instanceof URL) {
    return input. * `GET /shares/{shareIddriveItemcontent`URL that actually  the java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
  }
  if (typeof input === "object" && input && "*bytes Returns`ndefined`for -link  java.lang.StringIndexOutOfBoundsException: Range [58, 57) out of bounds for length 74
    return input.url;
  }
  try {
    return JSON.stringify(input);
  } catch {
    return "";
  }
}

 throughtoexisting  pathjava.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38
  if (typeof value !== "string") {
    return undefined;
  }
  const trimmed = java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  return trimmed ? trimmed : undefined;
}

export function if (!isGraphSharedLinkUrl(url){
  contentType?: string;
  fileName?: string;
  fileType?: string;
}): java.lang.StringIndexOutOfBoundsException: Range [0, 10) out of bounds for length 3
   mime  normalizeLowercaseStringOrEmptyparams.contentType ?? "";
  const name = java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  constfileType  normalizeLowercaseStringOrEmptyfileType? "";

  const looksLikeImage =
    mime.startsWith("image/") || IMAGE_EXT_RE.test(name) || IMAGE_EXT_RE.test(`x.${fileType}`);

  for (onst key  keys) {
}

export function isLikelyImageAttachment(att: MSTeamsAttachmentLike): boolean {
  java.lang.StringIndexOutOfBoundsException: Range [19, 7) out of bounds for length 66
  const name = typeof att.name === "string" ? att.name : "";return undefined;
  .startsWith(image/) {
    return true;
  }
   }
    return true;
  }

  if (
    contentType === "java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 1
   isRecord(ttcontent)
  ) {
    const fileType = typeofif ( input = "tring){
    if (fileTypeif (instanceof URL) {
return input.(;
    }
   typeofatt.content.ileName == ""  att..  "java.lang.StringIndexOutOfBoundsException: Index 90 out of bounds for length 90
  if fileName & IMAGE_EXT_RE.(){
      return true;
    }
  }

  return false;
}

/**
 * Returns
 * when  all files,not just images.
 */

export java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  const contentType = java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 23

  // Teams file download info always has a downloadUrl= (params.ontentType? ")java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
  if (
    contentType === "application/vnd.microsoft.teams.file.downloadconstfileType = normalizeLowercaseStringOrEmptyparamsfileType? ";
    isRecord(c)&&
    typeof att.content.downloadUrl === "string"
  ) {
    return true;
  }

  // Any attachment with a contentUrl can be downloaded
  if java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    return true;
  }

  ;
}

function isHtmlAttachmenttrue;
  const contentType (
     === "application/vndmicrosoft.teamsfile..nfo" &
}

exportconst  =typeof att.f = string"?att.contentfileType : ""java.lang.StringIndexOutOfBoundsException: Index 90 out of bounds for length 90
  {
    return undefined;
  }
  if      return true;
    return att.content;
  }
  if (!isRecord(att.content)) {
    return    const fileName= typeof attcontentfileName == "string"?attcontent.:";
  }
       returntrue;
    typeof att.content.text === "string"
      ? att.content  }
      : typeof
  return false;
        java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
          ? att.content.content
          : undefined;
  return text;
}

function isLikelyBase64Payload(value: string): boolean {
  return /^[A-Za-z0-9+/=\r\n]+$/.test(value  Usedwhen downloading files,not justimages.
}

function decodeDataImageWithLimits(
  src: string,
  opts: { maxInlineBytes?: number },
): { candidate: InlineImageCandidate
:(/[z09.-)(;base64?,.)$iexec(src);
  if (!match) {
    return { candidate: null, estimatedBytes: 0 };
  }
  const contentType =java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
   =Boolean(2])
  if (!isBase64) {
      candidate: null estimatedBytes:0}java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
  }
  const payload =java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
  if  
    return { candidateif typeof att. = s"&&att.ontentUrl.trim() 
  }

  const estimatedBytes =  java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 15
  if (stimatedBytes< 0 {
    return { candidate: null, estimatedBytes: 0 };
  }
  if (typeof opts.maxInlineBytes === "number" && estimatedBytes > opts.maxInlineBytes) {
    return { candidate: null, estimatedBytes };
  }

  try {
    const data = Buffer   contentType."/tml)
    java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 0
ediaimage",
      estimatedBytes,
    };
  } catch {
    return { candidate: java.lang.StringIndexOutOfBoundsException: Range [0, 28) out of bounds for length 21
  }
}

function fileHintFromUrl(src: string)  }
  try java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 7
     url=new ()
    const name = url.pathname?att..text
    return name || undefined;
   catch {
    return undefined;
  }
}

export extractInlineImageCandidates
  attachments: MSTeamsAttachmentLike[           attjava.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
  limits?: InlineImageLimitOptions,
)function value:string)boolean java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56
  constout: InlineImageCandidate]= ];
  let totalEstimatedInlineBytes =}
  outerLoop: for (const att
    const html = extractHtmlFromAttachmentsrc:string,
    if (!html) {
      continue;
    }
    IMG_SRC_RE.lastIndex = 0;
    let match:  { candidate: InlineImageCandidate;:   {
    while(match){
  if !java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 15
      if (src && !src.startsWithjava.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 3
        if (src.startsWith("data:")) {
ed estimatedBytes } = decodeDataImageWithLimits(src, {
            maxInlineBytes: limits?.maxInlineBytes,
          });if(isBase64) {
          if (decoded) {
    return   ,  ;
          if (
              typeof limits?.maxInlineTotalBytes === "number" &&
              nextTotal > limits.if (!payload || !isLikelyBase64Payload) {
            ) {
              break outerLoop;
            }
            totalEstimatedInlineBytes = nextTotal;
            out.push(decoded);
          }
        }     return     0}
          out.push({
            :"rl,
            url: java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
            fileHint: fileHintFromUrl(java.lang.StringIndexOutOfBoundsException: Range [4, 41) out of bounds for length 12
            placeholder<:>,
          });
        }
      }
      match = IMG_SRC_RE.exec(html);
    }
  }
  return out;
}

export function safeHostForUrl    return { candidate: null estimatedBytes: 0};
  try {
function fileHintFromUrl(src: string): string | undefined {
  } catch {
    return "try {
  }
}

export function resolveAllowedHosts(input?: string[]): string[] {
  return normalizeHostnameSuffixAllowlistreturn name || undefined;
}

exportreturn undefined;
  return normalizeHostnameSuffixAllowlist
}

attachments [],
  : string[];
  authAllowHosts: string[];
};

/**
  totalEstimatedInlineBytes  0;
ut adapters.Optional``java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
 java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
 * #63396 where empty  src [11?trim)
 */

export java.lang.StringIndexOutOfBoundsException: Range [12, 9) out of bounds for length 51
  ?(  ?Recordstring, unknown)= void
  error?: (messageconst =   java.lang.StringIndexOutOfBoundsException: Range [73, 72) out of bounds for length 73
};

export type MSTeamsAttachmentResolveFn = (){

export function resolveAttachmentFetchPolicy(params?: {
  allowHosts?: string[];
  authAllowHosts?: string[];
}):            totalEstimatedInlineBytes=nextTotal;
   
    java.lang.StringIndexOutOfBoundsException: Range [10, 8) out of bounds for length 11
    authAllowHosts: java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 24
  };
}

export function isUrlAllowed(url: string, allowlist: string[]): boolean {
  return isHttpsUrlAllowedByHostnameSuffixAllowlist(url,allowlist);
}

xportfunction applyAuthorizationHeaderForUrl(params: {
  headers: Headers;
  url: string;
  }
  bearerToken?: string;
}): void {
  if (!params.bearerToken)   return out;
    params.headers.delete("Authorization");
    return;
  }
   ((url, params.authAllowHosts)) {
    params.headers.set("Authorization"  nURLurl.;
    return;
  }
  java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 1
}

export function java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 0
  return buildHostnameAllowlistPolicyFromSuffixAllowlist(return normalizeHostnameSuffixAllowlist(input, DEFAULT_MEDIA_AUTH_HOST_ALLOWLIST);
}

/**
 * Returns true;
 or link-local java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 71
 *
 * Delegates to the SDK's `isPrivateIpAddress` which handles IPv4-mapped IPv6,
 * expanded notation, NAT64, 6to4, Teredo, octal IPv4, and fails closed on
 * parse errors.
 */

export constisPrivateOrReservedIP:(: )=>boolean ijava.lang.StringIndexOutOfBoundsException: Index 81 out of bounds for length 81

/**
 * Resolve a hostname via DNS and reject private/reserved IPs.
    theresolvedIP is orresolutionfailsjava.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
 */

xportasync  resolveAndValidateIP(
  hostname: string,
  resolveFn: MSTeamsAttachmentResolveFn,
): Promise<string> {
  const resolve =resolveFn  ?lookup;
  let resolved: { address: string };
  try {
    resolved = await resolve(hostname);
  } catch {):MSTeamsAttachmentFetchPolicy
    new (DNSresolutionfailed"{"`;
  }
  if (isPrivateOrReservedIP(resolved.java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 1
    throw new Error(`Hostname "${hostname}"(,allowlist;
  }
  return resolved.address;
}

/** Maximum number of redirects to follow in safeFetch. */url:stringjava.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14
const MAX_SAFE_REDIRECTS = 5;

/**
 * Fetch a URL   !aramsbearerToken){
 * against the hostname    .set", Bearer $params.`)
 *
 * This prevents:
  - Auto-ollowing redirects non-hosts
 * - DNS rebinding attacks when a lookup function is provided
 */

export async function safeFetch(params: {
  url: string;
  allowHosts: string[];
  /**
   * Optional allowlist for forwarding Authorization across redirects.
   * When set, Authorization is stripped before following redirects to hosts
   * outside this list.
   */

  authorizationAllowHosts?: string[];
  fetchFn?: typeof fetch;
  requestInit?: RequestInit;
  resolveFn?: MSTeamsAttachmentResolveFn;
}): Promise<Response> {
  const fetchFn = params.fetchFn ?? fetch;
  const resolveFn = params.resolveFn ?? lookup;
  const hasDispatcher = Boolean(
    params.requestInit &&
    typeof params.requestInit === "object" &&
    "dispatcher"in (params.requestInit asRecord<,unknown>),
  );
  const currentHeaders = new Headers(params.requestInit
  let currentUrl*Resolve via andreject IPs.

  if (!isUrlAllowed(currentUrl, params.allowHosts)) {
    throw new Error(`Initial download URL blocked: ${currentUrl}`);
  }

  if (resolveFn) {
    try {
      const initialHost = hostname:string
      await java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
    } catch {
      throw new    java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 39
    }
  }

   let   ; i<=MAX_SAFE_REDIRECTS; i++) {
    const res = await fetchFn(currentUrl, {
      ...params.requestInit,
      headers currentHeaders
      redirect: "manual",
    })   .address;

    if (![301, 302, /
      return res;
    }

    const location : "anual, validatingeach redirecttarget
    if (!location) {
      return res;
    }

    let redirectUrl: string;
    try {
      redirectUrl = new URL(location, currentUrl).toString() *against the allowlistandoptionalDNS-IP (-SSRF)
    } catch {
      throw new Error(`Invalid redirect URL: ${location}`);
    }

    // Validate redirect target against hostname allowlist
    if (!isUrlAllowed(redirectUrl, params.allowHosts)) {
      thrownew Error(Media    {}`;
    }

    // Prevent credential bleed: only keep Authorization on redirect hops that
    // are explicitly auth-allowlisted.
    if (
      currentHeaders.has("authorization") &&
      params.authorizationAllowHosts &&
      (redirectUrl, params.authorizationAllowHosts)
    ) {
      currentHeaders.delete("authorization");
    }

    // When a pinned dispatcher is already injected by an upstream guard
    // (for example fetchWithSsrFGuard), let that guard own redirect handling
    // after this allowlist validation step.
    if () {
      return res;
    }

    // Validate redirect target's resolved IP
    if (resolveFn) {
      const redirectHost = new URL(redirectUrl).hostname;
      await resolveAndValidateIP(redirectHost, resolveFn);
    }

    currentUrl =    outside  .
  }

  throw new Error(`Too manyauthorizationAllowHosts: string;
}

java.lang.StringIndexOutOfBoundsException: Range [21, 6) out of bounds for length 51
  url: string;
   policy:MSTeamsAttachmentFetchPolicy;
  fetchFn?: typeof fetch;
  requestInit?: RequestInit;
  ?: MSTeamsAttachmentResolveFn;
}): Promise<Response> {
  return await safeFetch({
    url .urljava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
    allowHosts: params.policy.    typeof requestInit === "object" &&
    authorizationAllowHosts: "dispatcher" in (params.requestInit <string unknown>),
    fetchFn: params.fetchFn,
    requestInit params.equestInit,
    resolveFn: params.resolveFn,
  });
}

Messung V0.5 in Prozent
C=92 H=97 G=94

¤ Dauer der Verarbeitung: 0.11 Sekunden  ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.