Permalink
Browse files

Addresses a data bleeding issue with lift-json

  • Loading branch information...
1 parent b1812ab commit 099d9c86cf6d81f4953957add478ab699946e601 @dpp dpp committed Apr 5, 2013
@@ -384,7 +384,11 @@ object JsonParser {
}
}
- def near = new String(segment, (cur-20) max 0, (cur + 1) min Segments.segmentSize)
+ def near = {
+ val start = (cur - 20) max 0
+ val len = ((cur + 1) min Segments.segmentSize) - start
+ new String(segment, start, len)
+ }
def release = segments.foreach(Segments.release)
@@ -27,6 +27,15 @@ import org.scalacheck.Prop._
* System under specification for JSON Parser.
*/
object JsonParserSpec extends Specification with JValueGen with ScalaCheck {
+
+ private def parseBadThing(): String = try {
+ parse("""{"user":"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"<}""")
+ "x" * 1000
+ } catch {
+ case e: Throwable => e.getMessage
+ }
+
+
"JSON Parser Specification".title
"Any valid json can be parsed" in {
@@ -54,6 +63,15 @@ object JsonParserSpec extends Specification with JValueGen with ScalaCheck {
parse("[\"abc\\\"\\\\\\/\\b\\f\\n\\r\\t\\u00a0\"]") must_== JArray(JString("abc\"\\/\b\f\n\r\t\u00a0")::Nil)
}
+
+ "Parser does not bleed prior results" in {
+ parse("""{"a": "now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things. now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things. now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things. now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things. now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things. now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things. now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things.now is the time for all good men to come to the aid of their dog and eat dog food with other dogs and bark and woof and do dog things"}""")
+
+ val msg = parseBadThing()
+
+ msg.length must be_<=(50)
+ }
+
"Unclosed string literal fails parsing" in {
parseOpt("{\"foo\":\"sd") mustEqual None
parseOpt("{\"foo\":\"sd}") mustEqual None

0 comments on commit 099d9c8

Please sign in to comment.