Skip to content

Commit bd82d89

Browse files
authored
Add support for different Maven POM encoding (#25873)
Fixes #25853 - Maven POM files aren't always UTF-8 encoded. - Reject the upload of unparsable POM files
1 parent dc679fc commit bd82d89

File tree

3 files changed

+30
-2
lines changed

3 files changed

+30
-2
lines changed

modules/packages/maven/metadata.go

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ import (
88
"io"
99

1010
"code.gitea.io/gitea/modules/validation"
11+
12+
"golang.org/x/net/html/charset"
1113
)
1214

1315
// Metadata represents the metadata of a Maven package
@@ -52,7 +54,10 @@ type pomStruct struct {
5254
// ParsePackageMetaData parses the metadata of a pom file
5355
func ParsePackageMetaData(r io.Reader) (*Metadata, error) {
5456
var pom pomStruct
55-
if err := xml.NewDecoder(r).Decode(&pom); err != nil {
57+
58+
dec := xml.NewDecoder(r)
59+
dec.CharsetReader = charset.NewReaderLabel
60+
if err := dec.Decode(&pom); err != nil {
5661
return nil, err
5762
}
5863

modules/packages/maven/metadata_test.go

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ import (
88
"testing"
99

1010
"github.com/stretchr/testify/assert"
11+
"golang.org/x/text/encoding/charmap"
1112
)
1213

1314
const (
@@ -69,4 +70,20 @@ func TestParsePackageMetaData(t *testing.T) {
6970
assert.Equal(t, dependencyArtifactID, m.Dependencies[0].ArtifactID)
7071
assert.Equal(t, dependencyVersion, m.Dependencies[0].Version)
7172
})
73+
74+
t.Run("Encoding", func(t *testing.T) {
75+
// UTF-8 is default but the metadata could be encoded differently
76+
pomContent8859_1, err := charmap.ISO8859_1.NewEncoder().String(
77+
strings.ReplaceAll(
78+
pomContent,
79+
`<?xml version="1.0"?>`,
80+
`<?xml version="1.0" encoding="ISO-8859-1"?>`,
81+
),
82+
)
83+
assert.NoError(t, err)
84+
85+
m, err := ParsePackageMetaData(strings.NewReader(pomContent8859_1))
86+
assert.NoError(t, err)
87+
assert.NotNil(t, m)
88+
})
7289
}

routers/api/packages/maven/maven.go

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,11 @@ var (
4949

5050
func apiError(ctx *context.Context, status int, obj any) {
5151
helper.LogAndProcessError(ctx, status, obj, func(message string) {
52+
// The maven client does not present the error message to the user. Log it for users with access to server logs.
53+
if status == http.StatusBadRequest || status == http.StatusInternalServerError {
54+
log.Error(message)
55+
}
56+
5257
ctx.PlainText(status, message)
5358
})
5459
}
@@ -320,7 +325,8 @@ func UploadPackageFile(ctx *context.Context) {
320325
var err error
321326
pvci.Metadata, err = maven_module.ParsePackageMetaData(buf)
322327
if err != nil {
323-
log.Error("Error parsing package metadata: %v", err)
328+
apiError(ctx, http.StatusBadRequest, err)
329+
return
324330
}
325331

326332
if pvci.Metadata != nil {

0 commit comments

Comments
 (0)