瀏覽代碼

Add regexp template tag validation

Kailash Nadh 6 年之前
父節點
當前提交
8a952c137b
共有 2 個文件被更改,包括 8 次插入4 次删除
  1. 1 1
      models/models.go
  2. 7 3
      templates.go

+ 1 - 1
models/models.go

@@ -208,7 +208,7 @@ func (s SubscriberAttribs) Scan(src interface{}) error {
 }
 }
 
 
 // CompileTemplate compiles a campaign body template into its base
 // CompileTemplate compiles a campaign body template into its base
-// template and sets the resultant template to Campaign.Tpl
+// template and sets the resultant template to Campaign.Tpl.
 func (c *Campaign) CompileTemplate(f template.FuncMap) error {
 func (c *Campaign) CompileTemplate(f template.FuncMap) error {
 	// Compile the base template.
 	// Compile the base template.
 	t := regexpLinkTag.ReplaceAllString(c.TemplateBody, regexpLinkTagReplace)
 	t := regexpLinkTag.ReplaceAllString(c.TemplateBody, regexpLinkTagReplace)

+ 7 - 3
templates.go

@@ -5,8 +5,8 @@ import (
 	"errors"
 	"errors"
 	"fmt"
 	"fmt"
 	"net/http"
 	"net/http"
+	"regexp"
 	"strconv"
 	"strconv"
-	"strings"
 
 
 	"github.com/asaskevich/govalidator"
 	"github.com/asaskevich/govalidator"
 	"github.com/knadh/listmonk/models"
 	"github.com/knadh/listmonk/models"
@@ -32,6 +32,10 @@ type dummyMessage struct {
 	UnsubscribeURL string
 	UnsubscribeURL string
 }
 }
 
 
+var (
+	regexpTplTag = regexp.MustCompile(`{{(\s+)?template\s+?"content"(\s+)?\.(\s+)?}}`)
+)
+
 // handleGetTemplates handles retrieval of templates.
 // handleGetTemplates handles retrieval of templates.
 func handleGetTemplates(c echo.Context) error {
 func handleGetTemplates(c echo.Context) error {
 	var (
 	var (
@@ -76,7 +80,7 @@ func handlePreviewTemplate(c echo.Context) error {
 	)
 	)
 
 
 	if body != "" {
 	if body != "" {
-		if strings.Count(body, tplTag) != 1 {
+		if !regexpTplTag.MatchString(body) {
 			return echo.NewHTTPError(http.StatusBadRequest,
 			return echo.NewHTTPError(http.StatusBadRequest,
 				fmt.Sprintf("Template body should contain the %s placeholder exactly once", tplTag))
 				fmt.Sprintf("Template body should contain the %s placeholder exactly once", tplTag))
 		}
 		}
@@ -243,7 +247,7 @@ func validateTemplate(o models.Template) error {
 		return errors.New("invalid length for `name`")
 		return errors.New("invalid length for `name`")
 	}
 	}
 
 
-	if strings.Count(o.Body, tplTag) != 1 {
+	if !regexpTplTag.MatchString(o.Body) {
 		return fmt.Errorf("template body should contain the %s placeholder exactly once", tplTag)
 		return fmt.Errorf("template body should contain the %s placeholder exactly once", tplTag)
 	}
 	}