Skip to content

Commit

Permalink
fix(dcellar-web-ui): browser cache getObjectMeta API and upgrade next…
Browse files Browse the repository at this point in the history
…js to prevent CVE-2024-34351
  • Loading branch information
devinxl committed May 11, 2024
1 parent 5e2c017 commit e257911
Show file tree
Hide file tree
Showing 2 changed files with 26 additions and 18 deletions.
4 changes: 2 additions & 2 deletions apps/dcellar-web-ui/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@
"dayjs": "^1.11.7",
"ethers": "^5.7.2",
"lodash-es": "^4.17.21",
"next": "~14.1.0",
"next": "~14.1.1",
"query-string": "^8.1.0",
"react": "~18.2.0",
"react-dom": "~18.2.0",
Expand Down Expand Up @@ -80,7 +80,7 @@
"eslint-config-prettier": "~9.1.0",
"@typescript-eslint/eslint-plugin": "~7.0.2",
"@typescript-eslint/parser": "~7.0.2",
"eslint-config-next": "~14.1.0",
"eslint-config-next": "~14.1.1",
"eslint-plugin-react": "~7.33.2"
},
"lint-staged": {
Expand Down
40 changes: 24 additions & 16 deletions apps/dcellar-web-ui/src/facade/object.ts
Original file line number Diff line number Diff line change
Expand Up @@ -621,22 +621,30 @@ export const getObjectMeta = async (
objectName,
)}?object-meta`;

return axios.get(url).then(
(e) => {
const data = xmlParser.parse(e.data)?.GfSpGetObjectMetaResponse.Object as ObjectMeta;
return [data, null];
},
(e) => {
const { response } = e;
if (!response) return [null, { code: 500, message: 'Oops, something went wrong' }];

const error =
response?.status === 429
? { code: response.status, message: 'SP not available. Try later.' }
: { message: xmlParser.parse(response.data)?.Error?.Message, code: response.status };
return [null, error];
},
);
return axios
.get(url, {
headers: {
'Cache-Control': 'no-cache',
Pragma: 'no-cache',
Expires: '0',
},
})
.then(
(e) => {
const data = xmlParser.parse(e.data)?.GfSpGetObjectMetaResponse.Object as ObjectMeta;
return [data, null];
},
(e) => {
const { response } = e;
if (!response) return [null, { code: 500, message: 'Oops, something went wrong' }];

const error =
response?.status === 429
? { code: response.status, message: 'SP not available. Try later.' }
: { message: xmlParser.parse(response.data)?.Error?.Message, code: response.status };
return [null, error];
},
);
};

export const getObjectVersions = async (id: string): Promise<ObjectVersion[]> => {
Expand Down

0 comments on commit e257911

Please sign in to comment.