Merge branch '6.1.x'

This commit is contained in:
Sébastien Deleuze
2024-06-10 22:46:03 +02:00
2 changed files with 14 additions and 2 deletions

View File

@@ -59,6 +59,7 @@ import org.springframework.lang.Nullable;
* @author Arjen Poutsma * @author Arjen Poutsma
* @author Sam Brannen * @author Sam Brannen
* @author Brian Clozel * @author Brian Clozel
* @author Sebastien Deleuze
* @since 16 April 2001 * @since 16 April 2001
*/ */
public abstract class StringUtils { public abstract class StringUtils {
@@ -71,6 +72,8 @@ public abstract class StringUtils {
private static final String WINDOWS_FOLDER_SEPARATOR = "\\"; private static final String WINDOWS_FOLDER_SEPARATOR = "\\";
private static final String DOUBLE_BACKLASHES = "\\\\";
private static final String TOP_PATH = ".."; private static final String TOP_PATH = "..";
private static final String CURRENT_PATH = "."; private static final String CURRENT_PATH = ".";
@@ -695,7 +698,7 @@ public abstract class StringUtils {
* Normalize the path by suppressing sequences like "path/.." and * Normalize the path by suppressing sequences like "path/.." and
* inner simple dots. * inner simple dots.
* <p>The result is convenient for path comparison. For other uses, * <p>The result is convenient for path comparison. For other uses,
* notice that Windows separators ("\") are replaced by simple slashes. * notice that Windows separators ("\" and "\\") are replaced by simple slashes.
* <p><strong>NOTE</strong> that {@code cleanPath} should not be depended * <p><strong>NOTE</strong> that {@code cleanPath} should not be depended
* upon in a security context. Other mechanisms should be used to prevent * upon in a security context. Other mechanisms should be used to prevent
* path-traversal issues. * path-traversal issues.
@@ -707,7 +710,15 @@ public abstract class StringUtils {
return path; return path;
} }
String normalizedPath = replace(path, WINDOWS_FOLDER_SEPARATOR, FOLDER_SEPARATOR); String normalizedPath;
// Optimize when there is no backslash
if (path.indexOf('\\') != -1) {
normalizedPath = replace(path, DOUBLE_BACKLASHES, FOLDER_SEPARATOR);
normalizedPath = replace(normalizedPath, WINDOWS_FOLDER_SEPARATOR, FOLDER_SEPARATOR);
}
else {
normalizedPath = path;
}
String pathToUse = normalizedPath; String pathToUse = normalizedPath;
// Shortcut if there is no work to do // Shortcut if there is no work to do

View File

@@ -419,6 +419,7 @@ class StringUtilsTests {
assertThat(StringUtils.cleanPath("file:///c:/some/../path/the%20file.txt")).isEqualTo("file:///c:/path/the%20file.txt"); assertThat(StringUtils.cleanPath("file:///c:/some/../path/the%20file.txt")).isEqualTo("file:///c:/path/the%20file.txt");
assertThat(StringUtils.cleanPath("jar:file:///c:\\some\\..\\path\\.\\the%20file.txt")).isEqualTo("jar:file:///c:/path/the%20file.txt"); assertThat(StringUtils.cleanPath("jar:file:///c:\\some\\..\\path\\.\\the%20file.txt")).isEqualTo("jar:file:///c:/path/the%20file.txt");
assertThat(StringUtils.cleanPath("jar:file:///c:/some/../path/./the%20file.txt")).isEqualTo("jar:file:///c:/path/the%20file.txt"); assertThat(StringUtils.cleanPath("jar:file:///c:/some/../path/./the%20file.txt")).isEqualTo("jar:file:///c:/path/the%20file.txt");
assertThat(StringUtils.cleanPath("jar:file:///c:\\\\some\\\\..\\\\path\\\\.\\\\the%20file.txt")).isEqualTo("jar:file:///c:/path/the%20file.txt");
} }
@Test @Test