Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

JavaScript Snippet Injection #7650

Merged
merged 42 commits into from
Apr 26, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
42 commits
Select commit Hold shift + click to select a range
7fdfcdb
JavaScript snippet injection
siyuniu-ms Feb 14, 2023
25c2af1
Avoid dependency on globals for unit tests
trask Feb 14, 2023
8f9813d
Update Servlet3OutputStreamWriteBytesAndOffsetAdvice.java
siyuniu-ms Feb 16, 2023
d2af9ca
update comments
siyuniu-ms Feb 18, 2023
95a6714
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
6a5329a
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
85c43e1
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
6d422bf
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
f597144
Update SnippetInjectingResponseWrapper.java
siyuniu-ms Feb 21, 2023
9fc8899
Update Servlet3Singletons.java
siyuniu-ms Feb 22, 2023
1919eb0
JavaScript snippet injection
siyuniu-ms Feb 14, 2023
26b55c5
Avoid dependency on globals for unit tests
trask Feb 14, 2023
72563d2
Update Servlet3OutputStreamWriteBytesAndOffsetAdvice.java
siyuniu-ms Feb 16, 2023
bd024bc
update comments
siyuniu-ms Feb 18, 2023
3bd615e
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
79b2ed5
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
c1b5da5
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
f0715a1
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 18, 2023
7554774
Update SnippetInjectingResponseWrapper.java
siyuniu-ms Feb 21, 2023
2097d0b
Update Servlet3Singletons.java
siyuniu-ms Feb 22, 2023
e64c3c5
Merge branch 'pr/6381' of https://github.com/siyuniu-ms/opentelemetry…
siyuniu-ms Feb 22, 2023
bf171da
Merge remote-tracking branch 'upstream/main' into pr/6381
siyuniu-ms Feb 22, 2023
1008aef
refactor, rename
siyuniu-ms Feb 24, 2023
ca7eb61
Merge remote-tracking branch 'upstream/main' into pr/6381
trask Feb 24, 2023
b46cbff
Some refactoring of the unit tests
trask Feb 25, 2023
db6dcaa
Update instrumentation/servlet/servlet-3.0/javaagent/src/test/groovy/…
trask Feb 27, 2023
0aa85b0
Update instrumentation/servlet/servlet-3.0/javaagent/src/main/java/io…
siyuniu-ms Feb 27, 2023
175c2f4
change naming and util test
siyuniu-ms Feb 27, 2023
df43675
optimization on PrintWriter
siyuniu-ms Feb 28, 2023
4a35251
change based on comments
siyuniu-ms Apr 5, 2023
6aaf18b
update for atomicity
siyuniu-ms Apr 17, 2023
eff7aba
Update ExperimentalSnippetHolder.java
siyuniu-ms Apr 19, 2023
5f33dca
initial value change to empty string
siyuniu-ms Apr 19, 2023
4d269b8
remove unnecessary print
siyuniu-ms Apr 19, 2023
cdc0cd4
Merge branch 'main' into pr/6381
siyuniu-ms Apr 20, 2023
390bf48
Update ExperimentalSnippetHolder.java
siyuniu-ms Apr 20, 2023
be5d10a
Update ExperimentalSnippetHolder.java
siyuniu-ms Apr 22, 2023
e775627
Merge remote-tracking branch 'upstream/main' into pr/6381
siyuniu-ms Apr 24, 2023
06dcd94
change based on new serverEndpoint
siyuniu-ms Apr 24, 2023
b47fbd1
solve the import error
siyuniu-ms Apr 24, 2023
c184c86
Update ServerEndpoint.java
siyuniu-ms Apr 25, 2023
672e8a7
Update AbstractServlet3Test.groovy
siyuniu-ms Apr 25, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
plugins {
id("otel.java-conventions")
}

dependencies {
testImplementation("javax.servlet:javax.servlet-api:3.0.1")
testImplementation(project(":instrumentation:servlet:servlet-3.0:javaagent"))
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,158 @@
/*
* Copyright The OpenTelemetry Authors
* SPDX-License-Identifier: Apache-2.0
*/

package io.opentelemetry.javaagent.instrumentation.servlet.v3_0.snippet;

import static io.opentelemetry.javaagent.instrumentation.servlet.v3_0.snippet.TestUtil.readFileAsString;
import static org.assertj.core.api.AssertionsForClassTypes.assertThat;
import static org.mockito.Mockito.mock;
import static org.mockito.Mockito.when;

import java.io.IOException;
import java.io.PrintWriter;
import java.io.StringWriter;
import java.nio.charset.Charset;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpServletResponseWrapper;
import org.junit.jupiter.api.Test;

class SnippetPrintWriterTest {

@Test
void testInjectToTextHtml() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String html = readFileAsString("beforeSnippetInjection.html");

InMemoryHttpServletResponse response = createInMemoryHttpServletResponse("text/html");
SnippetInjectingResponseWrapper responseWrapper =
new SnippetInjectingResponseWrapper(response, snippet);

responseWrapper.getWriter().write(html);
responseWrapper.getWriter().flush();

String expectedHtml = readFileAsString("afterSnippetInjection.html");
assertThat(response.getStringContent()).isEqualTo(expectedHtml);
}

@Test
void testInjectToChineseTextHtml() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String html = readFileAsString("beforeSnippetInjectionChinese.html");

InMemoryHttpServletResponse response = createInMemoryHttpServletResponse("text/html");
SnippetInjectingResponseWrapper responseWrapper =
new SnippetInjectingResponseWrapper(response, snippet);

responseWrapper.getWriter().write(html);
responseWrapper.getWriter().flush();

String expectedHtml = readFileAsString("afterSnippetInjectionChinese.html");
assertThat(response.getStringContent()).isEqualTo(expectedHtml);
}

@Test
void shouldNotInjectToTextHtml() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String html = readFileAsString("beforeSnippetInjection.html");

InMemoryHttpServletResponse response = createInMemoryHttpServletResponse("not/text");

SnippetInjectingResponseWrapper responseWrapper =
new SnippetInjectingResponseWrapper(response, snippet);

responseWrapper.getWriter().write(html);
responseWrapper.getWriter().flush();

assertThat(response.getStringContent()).isEqualTo(html);
}

@Test
void testWriteInt() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String html = readFileAsString("beforeSnippetInjection.html");

InMemoryHttpServletResponse response = createInMemoryHttpServletResponse("text/html");
SnippetInjectingResponseWrapper responseWrapper =
new SnippetInjectingResponseWrapper(response, snippet);

byte[] originalBytes = html.getBytes(Charset.defaultCharset());
for (byte originalByte : originalBytes) {
responseWrapper.getWriter().write(originalByte);
}
responseWrapper.getWriter().flush();

String expectedHtml = readFileAsString("afterSnippetInjection.html");
assertThat(response.getStringContent()).isEqualTo(expectedHtml);
}

@Test
void testWriteCharArray() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String html = readFileAsString("beforeSnippetInjectionChinese.html");

InMemoryHttpServletResponse response = createInMemoryHttpServletResponse("text/html");
SnippetInjectingResponseWrapper responseWrapper =
new SnippetInjectingResponseWrapper(response, snippet);

char[] originalChars = html.toCharArray();
responseWrapper.getWriter().write(originalChars, 0, originalChars.length);
responseWrapper.getWriter().flush();

String expectedHtml = readFileAsString("afterSnippetInjectionChinese.html");
assertThat(response.getStringContent()).isEqualTo(expectedHtml);
}

@Test
void testWriteWithOffset() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String html = readFileAsString("beforeSnippetInjectionChinese.html");
String extraBuffer = "this buffer should not be print out";
html = extraBuffer + html;

InMemoryHttpServletResponse response = createInMemoryHttpServletResponse("text/html");
SnippetInjectingResponseWrapper responseWrapper =
new SnippetInjectingResponseWrapper(response, snippet);

responseWrapper
.getWriter()
.write(html, extraBuffer.length(), html.length() - extraBuffer.length());
responseWrapper.getWriter().flush();

String expectedHtml = readFileAsString("afterSnippetInjectionChinese.html");
assertThat(response.getStringContent()).isEqualTo(expectedHtml);
}

private static InMemoryHttpServletResponse createInMemoryHttpServletResponse(String contentType) {
HttpServletResponse response = mock(HttpServletResponse.class);
when(response.getContentType()).thenReturn(contentType);
when(response.getStatus()).thenReturn(200);
when(response.containsHeader("content-type")).thenReturn(true);
return new InMemoryHttpServletResponse(response);
}

private static class InMemoryHttpServletResponse extends HttpServletResponseWrapper {

private PrintWriter printWriter;
private StringWriter stringWriter;

InMemoryHttpServletResponse(HttpServletResponse delegate) {
super(delegate);
}

@Override
public PrintWriter getWriter() {
if (printWriter == null) {
stringWriter = new StringWriter();
printWriter = new PrintWriter(stringWriter);
}
return printWriter;
}

String getStringContent() {
printWriter.flush();
return stringWriter.toString();
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,139 @@
/*
* Copyright The OpenTelemetry Authors
* SPDX-License-Identifier: Apache-2.0
*/

package io.opentelemetry.javaagent.instrumentation.servlet.v3_0.snippet;

import static io.opentelemetry.javaagent.instrumentation.servlet.v3_0.snippet.TestUtil.readFileAsBytes;
import static java.nio.charset.StandardCharsets.UTF_8;
import static org.assertj.core.api.AssertionsForClassTypes.assertThat;
import static org.mockito.Mockito.mock;
import static org.mockito.Mockito.when;

import java.io.ByteArrayOutputStream;
import java.io.IOException;
import java.nio.charset.Charset;
import javax.servlet.ServletOutputStream;
import javax.servlet.http.HttpServletResponse;
import org.junit.jupiter.api.Test;

class SnippetServletOutputStreamTest {

@Test
void testInjectionForStringContainHeadTag() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
byte[] html = readFileAsBytes("beforeSnippetInjection.html");

InjectionState obj = createInjectionStateForTesting(snippet, UTF_8);
InMemoryServletOutputStream out = new InMemoryServletOutputStream();

OutputStreamSnippetInjectionHelper helper = new OutputStreamSnippetInjectionHelper(snippet);
boolean injected = helper.handleWrite(obj, out, html, 0, html.length);
assertThat(obj.getHeadTagBytesSeen()).isEqualTo(-1);
assertThat(injected).isEqualTo(true);

byte[] expectedHtml = readFileAsBytes("afterSnippetInjection.html");
assertThat(out.getBytes()).isEqualTo(expectedHtml);
}

@Test
void testInjectionForChinese() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
byte[] html = readFileAsBytes("beforeSnippetInjectionChinese.html");

InjectionState obj = createInjectionStateForTesting(snippet, UTF_8);
InMemoryServletOutputStream out = new InMemoryServletOutputStream();

OutputStreamSnippetInjectionHelper helper = new OutputStreamSnippetInjectionHelper(snippet);
boolean injected = helper.handleWrite(obj, out, html, 0, html.length);

byte[] expectedHtml = readFileAsBytes("afterSnippetInjectionChinese.html");
assertThat(injected).isTrue();
assertThat(obj.getHeadTagBytesSeen()).isEqualTo(-1);
assertThat(out.getBytes()).isEqualTo(expectedHtml);
}

@Test
void testInjectionForStringWithoutHeadTag() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
byte[] html = readFileAsBytes("htmlWithoutHeadTag.html");

InjectionState obj = createInjectionStateForTesting(snippet, UTF_8);
InMemoryServletOutputStream out = new InMemoryServletOutputStream();

OutputStreamSnippetInjectionHelper helper = new OutputStreamSnippetInjectionHelper(snippet);
boolean injected = helper.handleWrite(obj, out, html, 0, html.length);

assertThat(injected).isFalse();
assertThat(obj.getHeadTagBytesSeen()).isEqualTo(0);
assertThat(out.getBytes()).isEmpty();
}

@Test
void testHeadTagSplitAcrossTwoWrites() throws IOException {
String snippet = "\n <script type=\"text/javascript\"> Test </script>";
String htmlFirstPart = "<!DOCTYPE html>\n<html lang=\"en\">\n<he";
byte[] htmlFirstPartBytes = htmlFirstPart.getBytes(UTF_8);

InjectionState obj = createInjectionStateForTesting(snippet, UTF_8);
InMemoryServletOutputStream out = new InMemoryServletOutputStream();

OutputStreamSnippetInjectionHelper helper = new OutputStreamSnippetInjectionHelper(snippet);
boolean injected =
helper.handleWrite(obj, out, htmlFirstPartBytes, 0, htmlFirstPartBytes.length);

assertThat(injected).isFalse();
assertThat(obj.getHeadTagBytesSeen()).isEqualTo(3);
assertThat(out.getBytes()).isEmpty();

String htmlSecondPart =
"ad>\n"
+ " <meta charset=\"UTF-8\">\n"
+ " <title>Title</title>\n"
+ "</head>\n"
+ "<body>\n"
+ "\n"
+ "</body>\n"
+ "</html>";
byte[] htmlSecondPartBytes = htmlSecondPart.getBytes(UTF_8);
injected = helper.handleWrite(obj, out, htmlSecondPartBytes, 0, htmlSecondPartBytes.length);

assertThat(injected).isTrue();
assertThat(obj.getHeadTagBytesSeen()).isEqualTo(-1);

String expectedSecondPart =
"ad>\n"
+ " <script type=\"text/javascript\"> Test </script>\n"
+ " <meta charset=\"UTF-8\">\n"
+ " <title>Title</title>\n"
+ "</head>\n"
+ "<body>\n"
+ "\n"
+ "</body>\n"
+ "</html>";
assertThat(out.getBytes()).isEqualTo(expectedSecondPart.getBytes(UTF_8));
}

private static InjectionState createInjectionStateForTesting(String snippet, Charset charset) {
HttpServletResponse response = mock(HttpServletResponse.class);
when(response.isCommitted()).thenReturn(false);
when(response.getCharacterEncoding()).thenReturn(charset.name());

return new InjectionState(new SnippetInjectingResponseWrapper(response, snippet));
}

private static class InMemoryServletOutputStream extends ServletOutputStream {

private final ByteArrayOutputStream baos = new ByteArrayOutputStream();

@Override
public void write(int b) {
baos.write(b);
}

public byte[] getBytes() {
return baos.toByteArray();
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
/*
* Copyright The OpenTelemetry Authors
* SPDX-License-Identifier: Apache-2.0
*/

package io.opentelemetry.javaagent.instrumentation.servlet.v3_0.snippet;

import static java.nio.charset.StandardCharsets.UTF_8;

import java.io.ByteArrayOutputStream;
import java.io.IOException;
import java.io.InputStream;

public class TestUtil {

protected static byte[] readFileAsBytes(String resourceName) throws IOException {
InputStream in =
SnippetPrintWriterTest.class.getClassLoader().getResourceAsStream(resourceName);
ByteArrayOutputStream result = new ByteArrayOutputStream();
byte[] buffer = new byte[1024];
int length;
while ((length = in.read(buffer)) != -1) {
result.write(buffer, 0, length);
}
return result.toByteArray();
}

protected static String readFileAsString(String resourceName) throws IOException {
return new String(readFileAsBytes(resourceName), UTF_8);
}

private TestUtil() {}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
<!DOCTYPE html>
<html lang="en">
<head>
<script type="text/javascript"> Test </script>
<meta charset="UTF-8">
<title>Title</title>
</head>
<body>

</body>
</html>
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
<!DOCTYPE html>
<html lang="en">
<head>
<script type="text/javascript"> Test </script>
<meta charset="UTF-8">
<title>Title</title>
</head>
<body>
<p>欢迎光临</p>
</body>
</html>
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Title</title>
</head>
<body>

</body>
</html>
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Title</title>
</head>
<body>
<p>欢迎光临</p>
</body>
</html>
Loading