Disable whitelist on entity_server scripts.

This commit is contained in:
Kasen IO 2020-01-05 23:32:28 -05:00
parent d872e9f07d
commit fb5dbfc52a

View file

@ -2377,15 +2377,21 @@ void ScriptEngine::entityScriptContentAvailable(const EntityItemID& entityID, co
// END PULL SAFEURLS FROM INTERFACE.JSON Settings // END PULL SAFEURLS FROM INTERFACE.JSON Settings
bool isInWhitelist = false; // assume unsafe bool isInWhitelist = false; // assume unsafe
for (const auto& str : safeURLS) {
qCDebug(scriptengine) << whitelistPrefix << "Script URL: " << scriptOrURL << "TESTING AGAINST" << str << "RESULTS IN" if(ScriptEngine::getContext() == "entity_server") {
<< scriptOrURL.startsWith(str); isInWhitelist = true;
if (!str.isEmpty() && scriptOrURL.startsWith(str)) { } else {
isInWhitelist = true; for (const auto& str : safeURLS) {
qCDebug(scriptengine) << whitelistPrefix << "Script approved."; qCDebug(scriptengine) << whitelistPrefix << "Script URL: " << scriptOrURL << "TESTING AGAINST" << str << "RESULTS IN"
break; // bail early since we found a match << scriptOrURL.startsWith(str);
} if (!str.isEmpty() && scriptOrURL.startsWith(str)) {
} isInWhitelist = true;
qCDebug(scriptengine) << whitelistPrefix << "Script approved.";
break; // bail early since we found a match
}
}
}
if (!isInWhitelist) { if (!isInWhitelist) {
qCDebug(scriptengine) << whitelistPrefix << "(disabled entity script)" << entityID.toString() << scriptOrURL; qCDebug(scriptengine) << whitelistPrefix << "(disabled entity script)" << entityID.toString() << scriptOrURL;
exception = makeError("UNSAFE_ENTITY_SCRIPTS == 0"); exception = makeError("UNSAFE_ENTITY_SCRIPTS == 0");