fix(security): convert Pandoc invocation to execFile argument arrays (SEC-1)

This commit is contained in:
2026-08-23 19:31:33 +05:30
parent 25dcaaa816
commit c43caf3902
4 changed files with 620 additions and 333 deletions
-69
View File
@@ -4,75 +4,6 @@
*/
describe('Utility Functions', () => {
describe('parseCommand', () => {
// This function parses command strings into command and args
function parseCommand(cmdString) {
const parts = [];
let current = '';
let inQuotes = false;
let quoteChar = '';
for (let i = 0; i < cmdString.length; i++) {
const char = cmdString[i];
if ((char === '"' || char === "'") && !inQuotes) {
inQuotes = true;
quoteChar = char;
} else if (char === quoteChar && inQuotes) {
inQuotes = false;
quoteChar = '';
} else if (char === ' ' && !inQuotes) {
if (current) {
parts.push(current);
current = '';
}
} else {
current += char;
}
}
if (current) {
parts.push(current);
}
return {
command: parts[0],
args: parts.slice(1),
};
}
test('should parse simple command', () => {
const result = parseCommand('pandoc input.md -o output.pdf');
expect(result.command).toBe('pandoc');
expect(result.args).toEqual(['input.md', '-o', 'output.pdf']);
});
test('should handle double-quoted paths', () => {
const result = parseCommand('pandoc "C:/path with spaces/file.md" -o output.pdf');
expect(result.command).toBe('pandoc');
expect(result.args).toEqual(['C:/path with spaces/file.md', '-o', 'output.pdf']);
});
test('should handle single-quoted paths', () => {
const result = parseCommand("pandoc 'file name.md' -o output.pdf");
expect(result.command).toBe('pandoc');
expect(result.args).toEqual(['file name.md', '-o', 'output.pdf']);
});
test('should handle multiple options', () => {
const result = parseCommand(
'pandoc input.md --pdf-engine=xelatex -V geometry:margin=1in -o output.pdf'
);
expect(result.command).toBe('pandoc');
expect(result.args).toContain('--pdf-engine=xelatex');
expect(result.args).toContain('-V');
});
test('should handle empty command', () => {
const result = parseCommand('');
expect(result.command).toBeUndefined();
expect(result.args).toEqual([]);
});
});
describe('hexToRgb', () => {
// This function converts hex colors to RGB
function hexToRgb(hex) {