format: reject signed numeric tokens in ipv4 and time - #263
Open
sueun-dev wants to merge 1 commit into
Open
Conversation
The ipv4 and time (and thus date-time and email domain-literal) validators parsed their numeric tokens with strconv.Atoi, which accepts a leading '+' or '-' sign. Values like ipv4 "1.2.3.+4" / "+1.2.3.4" / "1.2.3.-0" and time "+9:30:00Z" / "12:+9:00Z" validated even though the dotted-quad and RFC 3339 grammars are digit-only. Reject tokens containing a non-digit before parsing, matching the digit-only handling already used by validateDuration and validateSemver.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
ipv4andtimeformat validators parse their numeric tokens withstrconv.Atoi, which accepts a leading+/-sign, so signed tokens validate even though the dotted-quad and RFC 3339 grammars are digit-only:validateDurationandvalidateSemverin the same file already reject non-digit characters with an explicit loop. This adds a smallisAllDigitshelper and applies it before the threestrconv.Atoicall sites (ipv4 octet, time hh:mm:ss, offset hh:mm), sodate-timeandemailinherit the fix.Added
TestFormatRejectsSignedNumericTokens. Checked:go test ./...(including the official JSON-Schema-Test-Suite),go vet ./...,gofmt -l.