Properly escaped NFO file contents

This commit is contained in:
Kieran Eglin 2024-04-06 10:56:13 -07:00
parent 24875eaeac
commit 44535581e2
No known key found for this signature in database
GPG key ID: 193984967FCF432D
5 changed files with 74 additions and 17 deletions

View file

@ -4,6 +4,8 @@ defmodule Pinchflat.Metadata.NfoBuilder do
use by Kodi/Jellyfin and other media center software.
"""
import Pinchflat.Utils.XmlUtils, only: [safe: 1]
alias Pinchflat.Metadata.MetadataFileHelpers
alias Pinchflat.Filesystem.FilesystemHelpers
@ -42,12 +44,12 @@ defmodule Pinchflat.Metadata.NfoBuilder do
"""
<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<episodedetails>
<title>#{metadata["title"]}</title>
<showtitle>#{metadata["uploader"]}</showtitle>
<uniqueid type="youtube" default="true">#{metadata["id"]}</uniqueid>
<plot>#{metadata["description"]}</plot>
<aired>#{upload_date}</aired>
<season>#{upload_date.year}</season>
<title>#{safe(metadata["title"])}</title>
<showtitle>#{safe(metadata["uploader"])}</showtitle>
<uniqueid type="youtube" default="true">#{safe(metadata["id"])}</uniqueid>
<plot>#{safe(metadata["description"])}</plot>
<aired>#{safe(upload_date)}</aired>
<season>#{safe(upload_date.year)}</season>
<episode>#{Calendar.strftime(upload_date, "%m%d")}</episode>
<genre>YouTube</genre>
</episodedetails>
@ -58,9 +60,9 @@ defmodule Pinchflat.Metadata.NfoBuilder do
"""
<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<tvshow>
<title>#{metadata["title"]}</title>
<plot>#{metadata["description"]}</plot>
<uniqueid type="youtube" default="true">#{metadata["id"]}</uniqueid>
<title>#{safe(metadata["title"])}</title>
<plot>#{safe(metadata["description"])}</plot>
<uniqueid type="youtube" default="true">#{safe(metadata["id"])}</uniqueid>
<genre>YouTube</genre>
</tvshow>
"""

View file

@ -5,6 +5,8 @@ defmodule Pinchflat.Podcasts.RssFeedBuilder do
@datetime_format "%a, %d %b %Y %H:%M:%S %z"
import Pinchflat.Utils.XmlUtils, only: [safe: 1]
alias Pinchflat.Utils.DatetimeUtils
alias Pinchflat.Podcasts.PodcastHelpers
alias PinchflatWeb.Router.Helpers, as: Routes
@ -94,14 +96,6 @@ defmodule Pinchflat.Podcasts.RssFeedBuilder do
"""
end
defp safe(nil), do: ""
defp safe(value) do
value
|> Phoenix.HTML.html_escape()
|> Phoenix.HTML.safe_to_string()
end
defp generate_self_link(url_base, source) do
Path.join(url_base, "#{podcast_route(:rss_feed, source.uuid)}.xml")
end

View file

@ -0,0 +1,17 @@
defmodule Pinchflat.Utils.XmlUtils do
@moduledoc """
Utility methods for working with XML documents
"""
@doc """
Escapes invalid XML characters in a string
Returns binary()
"""
def safe(value) do
value
|> to_string()
|> Phoenix.HTML.html_escape()
|> Phoenix.HTML.safe_to_string()
end
end

View file

@ -30,6 +30,21 @@ defmodule Pinchflat.Metadata.NfoBuilderTest do
assert String.contains?(nfo, ~S(<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>))
assert String.contains?(nfo, "<title>#{metadata["title"]}</title>")
end
test "escapes invalid characters", %{filepath: filepath} do
metadata = %{
"title" => "hello' & <world>",
"uploader" => "uploader",
"id" => "id",
"description" => "description",
"upload_date" => "20210101"
}
result = NfoBuilder.build_and_store_for_media_item(filepath, metadata)
nfo = File.read!(result)
assert String.contains?(nfo, "hello&#39; &amp; &lt;world&gt;")
end
end
describe "build_and_store_for_source/2" do
@ -46,5 +61,18 @@ defmodule Pinchflat.Metadata.NfoBuilderTest do
assert String.contains?(nfo, ~S(<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>))
assert String.contains?(nfo, "<title>#{metadata["title"]}</title>")
end
test "escapes invalid characters", %{filepath: filepath} do
metadata = %{
"title" => "hello' & <world>",
"description" => "description",
"id" => "id"
}
result = NfoBuilder.build_and_store_for_source(filepath, metadata)
nfo = File.read!(result)
assert String.contains?(nfo, "hello&#39; &amp; &lt;world&gt;")
end
end
end

View file

@ -0,0 +1,16 @@
defmodule Pinchflat.Utils.XmlUtilsTest do
use ExUnit.Case, async: true
alias Pinchflat.Utils.XmlUtils
describe "safe/1" do
test "escapes invalid characters" do
assert XmlUtils.safe("hello' & <world>") == "hello&#39; &amp; &lt;world&gt;"
end
test "converts input to string" do
assert XmlUtils.safe(42) == "42"
assert XmlUtils.safe(nil) == ""
end
end
end