2023-06-12 19:41:07 +10:00
|
|
|
From df74c59a086d20ebf634026fe14ad686e04fb92c Mon Sep 17 00:00:00 2001
|
2014-07-02 23:46:50 +01:00
|
|
|
From: Thinkofdeath <thinkofdeath@spigotmc.org>
|
|
|
|
Date: Wed, 2 Jul 2014 23:35:51 +0100
|
|
|
|
Subject: [PATCH] Better item validation
|
|
|
|
|
|
|
|
|
2021-03-16 09:00:00 +11:00
|
|
|
diff --git a/src/main/java/net/minecraft/network/PacketDataSerializer.java b/src/main/java/net/minecraft/network/PacketDataSerializer.java
|
2023-04-10 08:30:55 +10:00
|
|
|
index 16b3a6a56..e6313cb64 100644
|
2021-03-16 09:00:00 +11:00
|
|
|
--- a/src/main/java/net/minecraft/network/PacketDataSerializer.java
|
|
|
|
+++ b/src/main/java/net/minecraft/network/PacketDataSerializer.java
|
2023-03-15 03:30:00 +11:00
|
|
|
@@ -672,6 +672,10 @@ public class PacketDataSerializer extends ByteBuf {
|
2014-07-19 19:10:12 +01:00
|
|
|
NBTTagCompound nbttagcompound = null;
|
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (item.canBeDepleted() || item.shouldOverrideMultiplayerNbt()) {
|
2014-07-19 19:10:12 +01:00
|
|
|
+ // Spigot start - filter
|
2021-11-22 09:00:00 +11:00
|
|
|
+ itemstack = itemstack.copy();
|
2014-07-19 19:10:12 +01:00
|
|
|
+ CraftItemStack.setItemMeta(itemstack, CraftItemStack.getItemMeta(itemstack));
|
|
|
|
+ // Spigot end
|
2014-11-26 08:27:08 +11:00
|
|
|
nbttagcompound = itemstack.getTag();
|
2014-07-19 19:10:12 +01:00
|
|
|
}
|
|
|
|
|
2014-07-02 23:46:50 +01:00
|
|
|
diff --git a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java
|
2023-06-12 19:41:07 +10:00
|
|
|
index 03b576455..dfde2c619 100644
|
2014-07-02 23:46:50 +01:00
|
|
|
--- a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java
|
|
|
|
+++ b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaBook.java
|
2022-09-11 10:35:31 +10:00
|
|
|
@@ -20,6 +20,10 @@ import org.bukkit.craftbukkit.util.CraftChatMessage;
|
|
|
|
import org.bukkit.craftbukkit.util.CraftMagicNumbers;
|
2019-04-23 15:12:43 +10:00
|
|
|
import org.bukkit.inventory.meta.BookMeta;
|
2014-07-02 23:46:50 +01:00
|
|
|
|
|
|
|
+// Spigot start
|
|
|
|
+import static org.spigotmc.ValidateUtils.*;
|
|
|
|
+// Spigot end
|
|
|
|
+
|
|
|
|
@DelegateDeserialization(SerializableMeta.class)
|
2015-04-16 11:19:45 +01:00
|
|
|
public class CraftMetaBook extends CraftMetaItem implements BookMeta {
|
2014-07-02 23:46:50 +01:00
|
|
|
static final ItemMetaKey BOOK_TITLE = new ItemMetaKey("title");
|
2022-09-11 10:35:31 +10:00
|
|
|
@@ -80,11 +84,11 @@ public class CraftMetaBook extends CraftMetaItem implements BookMeta {
|
2014-07-02 23:46:50 +01:00
|
|
|
super(tag);
|
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (tag.contains(BOOK_TITLE.NBT)) {
|
2014-07-02 23:46:50 +01:00
|
|
|
- this.title = tag.getString(BOOK_TITLE.NBT);
|
2020-07-19 08:47:03 +10:00
|
|
|
+ this.title = limit( tag.getString(BOOK_TITLE.NBT), 8192 ); // Spigot
|
2014-07-02 23:46:50 +01:00
|
|
|
}
|
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (tag.contains(BOOK_AUTHOR.NBT)) {
|
2014-07-02 23:46:50 +01:00
|
|
|
- this.author = tag.getString(BOOK_AUTHOR.NBT);
|
2020-07-19 08:47:03 +10:00
|
|
|
+ this.author = limit( tag.getString(BOOK_AUTHOR.NBT), 8192 ); // Spigot
|
2014-07-02 23:46:50 +01:00
|
|
|
}
|
2014-12-11 20:46:00 +00:00
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (tag.contains(RESOLVED.NBT)) {
|
2022-09-11 10:35:31 +10:00
|
|
|
@@ -112,7 +116,7 @@ public class CraftMetaBook extends CraftMetaItem implements BookMeta {
|
2021-01-01 08:53:21 +11:00
|
|
|
} else {
|
|
|
|
page = validatePage(page);
|
2014-11-26 08:27:08 +11:00
|
|
|
}
|
2021-01-01 08:53:21 +11:00
|
|
|
- this.pages.add(page);
|
|
|
|
+ this.pages.add( limit( page, 16384 ) ); // Spigot
|
2014-07-02 23:46:50 +01:00
|
|
|
}
|
2014-12-26 22:02:31 +00:00
|
|
|
}
|
|
|
|
}
|
2014-07-02 23:46:50 +01:00
|
|
|
diff --git a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java
|
2023-06-12 19:41:07 +10:00
|
|
|
index a584c1a03..a866f5308 100644
|
2014-07-02 23:46:50 +01:00
|
|
|
--- a/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java
|
|
|
|
+++ b/src/main/java/org/bukkit/craftbukkit/inventory/CraftMetaItem.java
|
2023-06-12 19:41:07 +10:00
|
|
|
@@ -77,6 +77,10 @@ import org.bukkit.inventory.meta.Repairable;
|
2019-04-23 15:12:43 +10:00
|
|
|
import org.bukkit.inventory.meta.tags.CustomItemTagContainer;
|
2019-04-25 14:39:43 +10:00
|
|
|
import org.bukkit.persistence.PersistentDataContainer;
|
2014-07-02 23:46:50 +01:00
|
|
|
|
|
|
|
+// Spigot start
|
|
|
|
+import static org.spigotmc.ValidateUtils.*;
|
|
|
|
+// Spigot end
|
|
|
|
+
|
|
|
|
/**
|
|
|
|
* Children must include the following:
|
|
|
|
*
|
2023-06-12 19:41:07 +10:00
|
|
|
@@ -331,18 +335,18 @@ class CraftMetaItem implements ItemMeta, Damageable, Repairable, BlockDataMeta {
|
2021-01-01 08:53:21 +11:00
|
|
|
NBTTagCompound display = tag.getCompound(DISPLAY.NBT);
|
2014-07-02 23:46:50 +01:00
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (display.contains(NAME.NBT)) {
|
2021-01-01 08:53:21 +11:00
|
|
|
- displayName = display.getString(NAME.NBT);
|
|
|
|
+ displayName = limit( display.getString(NAME.NBT), 8192 ); // Spigot
|
|
|
|
}
|
2014-07-02 23:46:50 +01:00
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (display.contains(LOCNAME.NBT)) {
|
2021-01-01 08:53:21 +11:00
|
|
|
- locName = display.getString(LOCNAME.NBT);
|
|
|
|
+ locName = limit( display.getString(LOCNAME.NBT), 8192 ); // Spigot
|
|
|
|
}
|
2014-07-02 23:46:50 +01:00
|
|
|
|
2021-11-22 09:00:00 +11:00
|
|
|
if (display.contains(LORE.NBT)) {
|
2021-01-01 08:53:21 +11:00
|
|
|
NBTTagList list = display.getList(LORE.NBT, CraftMagicNumbers.NBT.TAG_STRING);
|
|
|
|
lore = new ArrayList<String>(list.size());
|
2014-07-02 23:46:50 +01:00
|
|
|
for (int index = 0; index < list.size(); index++) {
|
2014-07-09 10:23:19 +10:00
|
|
|
- String line = list.getString(index);
|
2019-04-24 10:12:26 +10:00
|
|
|
+ String line = limit( list.getString(index), 8192 ); // Spigot
|
2021-01-01 08:53:21 +11:00
|
|
|
lore.add(line);
|
|
|
|
}
|
|
|
|
}
|
2014-07-02 23:46:50 +01:00
|
|
|
diff --git a/src/main/java/org/spigotmc/ValidateUtils.java b/src/main/java/org/spigotmc/ValidateUtils.java
|
|
|
|
new file mode 100644
|
2023-04-10 08:30:55 +10:00
|
|
|
index 000000000..58a953481
|
2014-07-02 23:46:50 +01:00
|
|
|
--- /dev/null
|
|
|
|
+++ b/src/main/java/org/spigotmc/ValidateUtils.java
|
|
|
|
@@ -0,0 +1,14 @@
|
|
|
|
+package org.spigotmc;
|
|
|
|
+
|
|
|
|
+public class ValidateUtils
|
|
|
|
+{
|
|
|
|
+
|
|
|
|
+ public static String limit(String str, int limit)
|
|
|
|
+ {
|
|
|
|
+ if ( str.length() > limit )
|
|
|
|
+ {
|
|
|
|
+ return str.substring( 0, limit );
|
|
|
|
+ }
|
|
|
|
+ return str;
|
|
|
|
+ }
|
|
|
|
+}
|
|
|
|
--
|
2023-06-08 01:30:00 +10:00
|
|
|
2.40.1
|
2014-07-02 23:46:50 +01:00
|
|
|
|