summaryrefslogtreecommitdiffstats
path: root/lib
diff options
context:
space:
mode:
authorJohn Molakvoæ <skjnldsv@users.noreply.github.com>2023-01-06 09:00:36 +0100
committerGitHub <noreply@github.com>2023-01-06 09:00:36 +0100
commit8392f8b9e75a605711e8ded972e900c102be3923 (patch)
tree8cb9c7f4ca4665ee6d73818a3b457a3883a57e19 /lib
parent0e23fbf16e32621b70a0e8bd4a2aeca46e40b658 (diff)
parent80b05e111c8c02da78e332d77a5ce65d2a71967b (diff)
downloadnextcloud-server-8392f8b9e75a605711e8ded972e900c102be3923.tar.gz
nextcloud-server-8392f8b9e75a605711e8ded972e900c102be3923.zip
Merge pull request #36022 from nextcloud/backport/36016/stable25
[stable25] Add restrictions when downloading to resolve with opengraph link provider
Diffstat (limited to 'lib')
-rw-r--r--lib/private/Collaboration/Reference/LinkReferenceProvider.php16
1 files changed, 16 insertions, 0 deletions
diff --git a/lib/private/Collaboration/Reference/LinkReferenceProvider.php b/lib/private/Collaboration/Reference/LinkReferenceProvider.php
index 5597df1ca97..583cbdcfe99 100644
--- a/lib/private/Collaboration/Reference/LinkReferenceProvider.php
+++ b/lib/private/Collaboration/Reference/LinkReferenceProvider.php
@@ -105,6 +105,22 @@ class LinkReferenceProvider implements IReferenceProvider {
$client = $this->clientService->newClient();
try {
+ $headResponse = $client->head($reference->getId(), [ 'timeout' => 10 ]);
+ } catch (\Exception $e) {
+ $this->logger->debug('Failed to perform HEAD request to get target metadata', ['exception' => $e]);
+ return;
+ }
+ $linkContentLength = $headResponse->getHeader('Content-Length');
+ if (is_numeric($linkContentLength) && (int) $linkContentLength > 5 * 1024 * 1024) {
+ $this->logger->debug('Skip resolving links pointing to content length > 5 MB');
+ return;
+ }
+ $linkContentType = $headResponse->getHeader('Content-Type');
+ if ($linkContentType !== 'text/html') {
+ $this->logger->debug('Skip resolving links pointing to content type that is not "text/html"');
+ return;
+ }
+ try {
$response = $client->get($reference->getId(), [ 'timeout' => 10 ]);
} catch (\Exception $e) {
$this->logger->debug('Failed to fetch link for obtaining open graph data', ['exception' => $e]);