spigot/CraftBukkit-Patches/0082-Better-item-validation.patch

125 lines
5 KiB
Diff
Raw Normal View History

2019-04-23 09:33:25 +10:00
From 5a4ba8f7895347214faa9c0184e38b91cd84619d Mon Sep 17 00:00:00 2001
2014-07-02 23:46:50 +01:00
From: Thinkofdeath <thinkofdeath@spigotmc.org>
Date: Wed, 2 Jul 2014 23:35:51 +0100
Subject: [PATCH] Better item validation
diff --git a/src/main/java/net/minecraft/server/PacketDataSerializer.java b/src/main/java/net/minecraft/server/PacketDataSerializer.java
2019-04-23 09:33:25 +10:00
index 440a50fe..7582151a 100644
--- a/src/main/java/net/minecraft/server/PacketDataSerializer.java
+++ b/src/main/java/net/minecraft/server/PacketDataSerializer.java
2018-10-23 06:00:00 +11:00
@@ -247,6 +247,10 @@ public class PacketDataSerializer extends ByteBuf {
NBTTagCompound nbttagcompound = null;
2018-07-15 10:00:00 +10:00
if (item.usesDurability() || item.n()) {
+ // Spigot start - filter
+ itemstack = itemstack.cloneItemStack();
+ CraftItemStack.setItemMeta(itemstack, CraftItemStack.getItemMeta(itemstack));
+ // Spigot end
nbttagcompound = itemstack.getTag();
}
2014-07-02 23:46:50 +01:00
diff --git a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java
2019-04-23 09:33:25 +10:00
index adb21dd2..a0dc5524 100644
2014-07-02 23:46:50 +01:00
--- a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java
+++ b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java
2017-04-22 15:54:44 +10:00
@@ -23,6 +23,10 @@ import net.minecraft.server.IChatBaseComponent;
import net.minecraft.server.NBTTagString;
import org.bukkit.craftbukkit.util.CraftChatMessage;
2014-07-02 23:46:50 +01:00
+// Spigot start
+import static org.spigotmc.ValidateUtils.*;
+// Spigot end
+
@DelegateDeserialization(SerializableMeta.class)
2015-04-16 11:19:45 +01:00
public class CraftMetaBook extends CraftMetaItem implements BookMeta {
2014-07-02 23:46:50 +01:00
static final ItemMetaKey BOOK_TITLE = new ItemMetaKey("title");
2018-04-19 10:02:20 +10:00
@@ -59,11 +63,11 @@ public class CraftMetaBook extends CraftMetaItem implements BookMeta {
2014-07-02 23:46:50 +01:00
super(tag);
if (tag.hasKey(BOOK_TITLE.NBT)) {
- this.title = tag.getString(BOOK_TITLE.NBT);
+ this.title = limit( tag.getString(BOOK_TITLE.NBT), 1024 ); // Spigot
}
if (tag.hasKey(BOOK_AUTHOR.NBT)) {
- this.author = tag.getString(BOOK_AUTHOR.NBT);
+ this.author = limit( tag.getString(BOOK_AUTHOR.NBT), 1024 ); // Spigot
}
2014-12-11 20:46:00 +00:00
boolean resolved = false;
2018-04-19 10:02:20 +10:00
@@ -88,7 +92,7 @@ public class CraftMetaBook extends CraftMetaItem implements BookMeta {
2014-12-12 09:47:02 +00:00
// Ignore and treat as an old book
}
}
2014-12-26 22:02:31 +00:00
- addPage(page);
+ addPage( limit( page, 2048 ) ); // Spigot
2014-07-02 23:46:50 +01:00
}
2014-12-26 22:02:31 +00:00
}
}
2014-07-02 23:46:50 +01:00
diff --git a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java
2019-04-23 09:33:25 +10:00
index a463c88a..55d63c04 100644
2014-07-02 23:46:50 +01:00
--- a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java
+++ b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java
2019-04-02 21:23:20 +11:00
@@ -75,6 +75,10 @@ import org.apache.commons.codec.binary.Base64;
2018-09-21 20:57:04 +10:00
import javax.annotation.Nonnull;
import javax.annotation.Nullable;
2014-07-02 23:46:50 +01:00
+// Spigot start
+import static org.spigotmc.ValidateUtils.*;
+// Spigot end
+
/**
* Children must include the following:
*
2019-04-02 21:23:20 +11:00
@@ -306,7 +310,7 @@ class CraftMetaItem implements ItemMeta, Damageable, Repairable {
2014-07-02 23:46:50 +01:00
if (display.hasKey(NAME.NBT)) {
2018-07-21 10:19:54 +10:00
try {
- displayName = IChatBaseComponent.ChatSerializer.a(display.getString(NAME.NBT));
+ displayName = IChatBaseComponent.ChatSerializer.a( limit( display.getString(NAME.NBT), 1024 ) ); // Spigot
} catch (JsonParseException ex) {
// Ignore (stripped like Vanilla)
}
2019-04-02 21:23:20 +11:00
@@ -314,7 +318,7 @@ class CraftMetaItem implements ItemMeta, Damageable, Repairable {
2014-07-02 23:46:50 +01:00
2017-02-16 11:55:41 +11:00
if (display.hasKey(LOCNAME.NBT)) {
2018-07-21 10:19:54 +10:00
try {
- locName = IChatBaseComponent.ChatSerializer.a(display.getString(LOCNAME.NBT));
+ locName = IChatBaseComponent.ChatSerializer.a( limit( display.getString(LOCNAME.NBT), 1024 ) ); // Spigot
} catch (JsonParseException ex) {
// Ignore (stripped like Vanilla)
}
2019-04-02 21:23:20 +11:00
@@ -325,7 +329,7 @@ class CraftMetaItem implements ItemMeta, Damageable, Repairable {
2014-07-02 23:46:50 +01:00
lore = new ArrayList<String>(list.size());
for (int index = 0; index < list.size(); index++) {
2014-07-09 10:23:19 +10:00
- String line = list.getString(index);
+ String line = limit( list.getString(index), 1024 ); // Spigot
2014-07-02 23:46:50 +01:00
lore.add(line);
}
}
diff --git a/src/main/java/org/spigotmc/ValidateUtils.java b/src/main/java/org/spigotmc/ValidateUtils.java
new file mode 100644
2019-04-23 09:33:25 +10:00
index 00000000..58a95348
2014-07-02 23:46:50 +01:00
--- /dev/null
+++ b/src/main/java/org/spigotmc/ValidateUtils.java
@@ -0,0 +1,14 @@
+package org.spigotmc;
+
+public class ValidateUtils
+{
+
+ public static String limit(String str, int limit)
+ {
+ if ( str.length() > limit )
+ {
+ return str.substring( 0, limit );
+ }
+ return str;
+ }
+}
--
2019-04-23 09:33:25 +10:00
2.20.1
2014-07-02 23:46:50 +01:00