From 35cb6c66bddf54c497148af0e13457b30bbca132 Mon Sep 17 00:00:00 2001 From: Richard Steinmetz Date: Fri, 18 Jun 2021 14:21:10 +0200 Subject: [PATCH] Properly decode escaped principal urls Signed-off-by: Richard Steinmetz --- .../CalendarListItemSharingSearch.vue | 18 +++++---- src/utils/url.js | 32 ++++++++++++++++ tests/javascript/unit/utils/url.test.js | 38 +++++++++++++++++++ 3 files changed, 81 insertions(+), 7 deletions(-) create mode 100644 src/utils/url.js create mode 100644 tests/javascript/unit/utils/url.test.js diff --git a/src/components/AppNavigation/CalendarList/CalendarListItemSharingSearch.vue b/src/components/AppNavigation/CalendarList/CalendarListItemSharingSearch.vue index 797b07b25..fcc690eb2 100644 --- a/src/components/AppNavigation/CalendarList/CalendarListItemSharingSearch.vue +++ b/src/components/AppNavigation/CalendarList/CalendarListItemSharingSearch.vue @@ -35,7 +35,7 @@ :user-select="true" open-direction="bottom" track-by="user" - label="user" + label="displayName" @search-change="findSharee" @change="shareCalendar"> {{ $t('calendar', 'No users or groups') }} @@ -49,6 +49,7 @@ import { principalPropertySearchByDisplaynameOrEmail } from '../../../services/c import HttpClient from '@nextcloud/axios' import debounce from 'debounce' import { generateOcsUrl } from '@nextcloud/router' +import { urldecode } from '../../../utils/url' export default { name: 'CalendarListItemSharingSearch', @@ -80,8 +81,6 @@ export default { * @param {Boolean} data.isCircle is this a circle-group ? */ shareCalendar({ user, displayName, uri, isGroup, isCircle }) { - uri = decodeURI(uri) - user = decodeURI(user) this.$store.dispatch('shareCalendar', { calendar: this.calendar, user, @@ -146,7 +145,13 @@ export default { } return results.reduce((list, result) => { - if (hiddenPrincipals.includes(decodeURI(result.principalScheme))) { + const isGroup = result.calendarUserType === 'GROUP' + + // TODO: Why do we have to decode those two values? + const user = urldecode(result[isGroup ? 'groupId' : 'userId']) + const decodedPrincipalScheme = urldecode(result.principalScheme) + + if (hiddenPrincipals.includes(decodedPrincipalScheme)) { return list } if (hiddenUrls.includes(result.url)) { @@ -158,12 +163,11 @@ export default { return list } - const isGroup = result.calendarUserType === 'GROUP' list.push({ - user: result[isGroup ? 'groupId' : 'userId'], + user, displayName: result.displayname, icon: isGroup ? 'icon-group' : 'icon-user', - uri: result.principalScheme, + uri: decodedPrincipalScheme, isGroup, isCircle: false, isNoUser: isGroup, diff --git a/src/utils/url.js b/src/utils/url.js new file mode 100644 index 000000000..1040d03b4 --- /dev/null +++ b/src/utils/url.js @@ -0,0 +1,32 @@ +/** + * @copyright Copyright (c) 2021 Richard Steinmetz + * + * @author Richard Steinmetz + * + * @license GNU AGPL version 3 or any later version + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as + * published by the Free Software Foundation, either version 3 of the + * License, or (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see . + * + */ + +/** + * Works like urldecode() from php + * + * @see https://www.php.net/manual/en/function.urldecode.php + * @param {string} url The url to be decoded + * @returns {string} The decoded url + */ +export function urldecode(url) { + return decodeURIComponent(url.replace(/\+/g, ' ')) +} diff --git a/tests/javascript/unit/utils/url.test.js b/tests/javascript/unit/utils/url.test.js new file mode 100644 index 000000000..c168e435b --- /dev/null +++ b/tests/javascript/unit/utils/url.test.js @@ -0,0 +1,38 @@ +/** + * @copyright Copyright (c) 2021 Richard Steinmetz + * + * @author Richard Steinmetz + * + * @license GNU AGPL version 3 or any later version + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as + * published by the Free Software Foundation, either version 3 of the + * License, or (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see . + * + */ + +import { urldecode } from '../../../../src/utils/url' + +describe('utils/url test suite', () => { + it('should decode urls encoded by php', () => { + const testData = [ + ['my+group+%2B%26%3F%25', 'my group +&?%'], + ['my%2520+group', 'my%20 group'], + ['group%20with%20spaces', 'group with spaces'], + ] + + for (const [encoded, expected] of testData) { + const decoded = urldecode(encoded) + expect(decoded).toEqual(expected) + } + }) +})