XssForm.jsx 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175
  1. import React from 'react';
  2. import PropTypes from 'prop-types';
  3. import { withTranslation } from 'react-i18next';
  4. import loggerFactory from '@alias/logger';
  5. import { createSubscribedElement } from '../../UnstatedUtils';
  6. import { toastSuccess, toastError } from '../../../util/apiNotification';
  7. import { tags, attrs } from '../../../../../lib/service/xss/recommended-whitelist';
  8. import AppContainer from '../../../services/AppContainer';
  9. import AdminMarkDownContainer from '../../../services/AdminMarkDownContainer';
  10. import AdminUpdateButtonRow from '../Common/AdminUpdateButtonRow';
  11. import WhiteListInput from './WhiteListInput';
  12. const logger = loggerFactory('growi:importer');
  13. class XssForm extends React.Component {
  14. constructor(props) {
  15. super(props);
  16. this.onClickSubmit = this.onClickSubmit.bind(this);
  17. }
  18. async onClickSubmit() {
  19. const { t } = this.props;
  20. try {
  21. await this.props.adminMarkDownContainer.updateXssSetting();
  22. toastSuccess(t('toaster.update_successed', { target: t('admin:markdown_setting.xss_header') }));
  23. }
  24. catch (err) {
  25. toastError(err);
  26. logger.error(err);
  27. }
  28. }
  29. xssOptions() {
  30. const { t, adminMarkDownContainer } = this.props;
  31. const { xssOption } = adminMarkDownContainer.state;
  32. return (
  33. <div className="form-group col-12 my-3">
  34. <div className="row">
  35. <div className="col-md-4 col-sm-12 align-self-start mb-4">
  36. <div className="custom-control custom-radio ">
  37. <input
  38. type="radio"
  39. className="custom-control-input"
  40. id="xssOption1"
  41. name="XssOption"
  42. checked={xssOption === 1}
  43. onChange={() => { adminMarkDownContainer.setState({ xssOption: 1 }) }}
  44. />
  45. <label className="custom-control-label w-100" htmlFor="xssOption1">
  46. <p className="font-weight-bold">{t('admin:markdown_setting.xss_options.remove_all_tags')}</p>
  47. <div className="mt-4">
  48. {t('admin:markdown_setting.xss_options.remove_all_tags_desc')}
  49. </div>
  50. </label>
  51. </div>
  52. </div>
  53. <div className="col-md-4 col-sm-12 align-self-start mb-4">
  54. <div className="custom-control custom-radio">
  55. <input
  56. type="radio"
  57. className="custom-control-input"
  58. id="xssOption2"
  59. name="XssOption"
  60. checked={xssOption === 2}
  61. onChange={() => { adminMarkDownContainer.setState({ xssOption: 2 }) }}
  62. />
  63. <label className="custom-control-label w-100" htmlFor="xssOption2">
  64. <p className="font-weight-bold">{t('admin:markdown_setting.xss_options.recommended_setting')}</p>
  65. <div className="m-t-15">
  66. <div className="d-flex justify-content-between">
  67. {t('admin:markdown_setting.xss_options.tag_names')}
  68. </div>
  69. <textarea
  70. className="form-control xss-list"
  71. name="recommendedTags"
  72. rows="6"
  73. cols="40"
  74. readOnly
  75. defaultValue={tags}
  76. />
  77. </div>
  78. <div className="m-t-15">
  79. <div className="d-flex justify-content-between">
  80. {t('admin:markdown_setting.xss_options.tag_attributes')}
  81. </div>
  82. <textarea
  83. className="form-control xss-list"
  84. name="recommendedAttrs"
  85. rows="6"
  86. cols="40"
  87. readOnly
  88. defaultValue={attrs}
  89. />
  90. </div>
  91. </label>
  92. </div>
  93. </div>
  94. <div className="col-md-4 col-sm-12 align-self-start mb-4">
  95. <div className="custom-control custom-radio">
  96. <input
  97. type="radio"
  98. className="custom-control-input"
  99. id="xssOption3"
  100. name="XssOption"
  101. checked={xssOption === 3}
  102. onChange={() => { adminMarkDownContainer.setState({ xssOption: 3 }) }}
  103. />
  104. <label className="custom-control-label w-100" htmlFor="xssOption3">
  105. <p className="font-weight-bold">{t('admin:markdown_setting.xss_options.custom_whitelist')}</p>
  106. <WhiteListInput customizable />
  107. </label>
  108. </div>
  109. </div>
  110. </div>
  111. </div>
  112. );
  113. }
  114. render() {
  115. const { t, adminMarkDownContainer } = this.props;
  116. const { isEnabledXss } = adminMarkDownContainer.state;
  117. return (
  118. <React.Fragment>
  119. <fieldset className="col-12">
  120. <div className="form-group">
  121. <div className="col-8 offset-4 my-3">
  122. <div className="custom-control custom-switch custom-checkbox-success">
  123. <input
  124. type="checkbox"
  125. className="custom-control-input"
  126. id="XssEnable"
  127. name="isEnabledXss"
  128. checked={isEnabledXss}
  129. onChange={adminMarkDownContainer.switchEnableXss}
  130. />
  131. <label className="custom-control-label w-100" htmlFor="XssEnable">
  132. {t('admin:markdown_setting.xss_options.enable_xss_prevention')}
  133. </label>
  134. </div>
  135. </div>
  136. </div>
  137. <div className="col-12">
  138. {isEnabledXss && this.xssOptions()}
  139. </div>
  140. </fieldset>
  141. <AdminUpdateButtonRow onClick={this.onClickSubmit} disabled={adminMarkDownContainer.state.retrieveError != null} />
  142. </React.Fragment>
  143. );
  144. }
  145. }
  146. const XssFormWrapper = (props) => {
  147. return createSubscribedElement(XssForm, props, [AppContainer, AdminMarkDownContainer]);
  148. };
  149. XssForm.propTypes = {
  150. t: PropTypes.func.isRequired, // i18next
  151. appContainer: PropTypes.instanceOf(AppContainer).isRequired,
  152. adminMarkDownContainer: PropTypes.instanceOf(AdminMarkDownContainer).isRequired,
  153. };
  154. export default withTranslation()(XssFormWrapper);