fix(api): 服务器显示名称限 64 个可见字符,拒绝换行、控制符和不可见格式符

This commit is contained in:
Lemon-miaow committed 2026-09-27 13:30:28 +08:00
1 parent b8da4e2318
commit 67a7e27f8d
19 files changed
+197 -20

No files matched your search

+29
View File
@@ -9,6 +9,8 @@ import (
"fmt"
"regexp"
"strings"
"unicode"
"unicode/utf8"
)
var (
@@ -145,6 +147,33 @@ func ValidateSystemServerName(name string) error {
return nil
}
// zeroWidthJoiner (U+200D) glues emoji such as the rainbow flag into one picture.
const zeroWidthJoiner = 0x200D
// MaxDisplayName is the most characters a server's display name may have. The
// panel shows it on one line in the fleet grid and the server header.
const MaxDisplayName = 64
// CleanDisplayName trims a server's display name and checks what is left: at most
// MaxDisplayName characters, every one a visible character or a space. Control
// characters, line breaks and the invisible format characters (bidi overrides,
// zero-width spaces) are refused, since they would break the line the panel puts
// the name on or make it read as something else; the zero-width joiner stays,
// because emoji such as the rainbow flag are built with it. An empty result is
// valid: the server then goes by its name.
func CleanDisplayName(s string) (string, error) {
s = strings.TrimSpace(s)
if n := utf8.RuneCountInString(s); n > MaxDisplayName {
return "", fmt.Errorf("naming: display name has %d characters, at most %d are allowed", n, MaxDisplayName)
}
for _, r := range s {
if r == utf8.RuneError || !unicode.IsGraphic(r) && r != zeroWidthJoiner {
return "", fmt.Errorf("naming: display name contains %U, which is not a visible character", r)
}
}
return s, nil
}
// worldVolumeName mirrors operator.dataVolumeName: the per-server StatefulSet's
// volumeClaimTemplate is named "world", so a single-replica server's world PVC
// is "world-<name>-0". This is the one naming convention shared by the operator
+38
View File
@@ -149,3 +149,41 @@ func TestValidateHostname(t *testing.T) {
t.Error("ValidateHostname should reject an empty root domain")
}
}
func TestCleanDisplayName(t *testing.T) {
str := func(rs ...rune) string { return string(rs) }
rainbow := str(0x1F3F3, 0xFE0F, 0x200D, 0x1F308)
cjk := func(n int) string {
s := ""
for range n {
s += "生"
}
return s
}
for _, c := range []struct {
name, in, want string
ok bool
}{
{"trimmed", " Survival World ", "Survival World", true},
{"empty", "", "", true},
{"only spaces", " ", "", true},
{"cjk and punctuation", "生存服 · 第二季!", "生存服 · 第二季!", true},
{"emoji joined by zwj", "Pride " + rainbow, "Pride " + rainbow, true},
{"ideographic space inside", "生存" + str(0x3000) + "服", "生存" + str(0x3000) + "服", true},
{"64 characters of 3 bytes each", cjk(64), cjk(64), true},
{"65 characters", cjk(65), "", false},
{"tab", "a" + str(0x09) + "b", "", false},
{"newline", "a" + str(0x0A) + "b", "", false},
{"nul", "a" + str(0x00), "", false},
{"right-to-left override", "abc" + str(0x202E) + "exe.txt", "", false},
{"zero-width space", "ad" + str(0x200B) + "min", "", false},
{"line separator", "a" + str(0x2028) + "b", "", false},
{"private use", "a" + str(0xE000), "", false},
{"invalid utf-8", string([]byte{'a', 0xff}), "", false},
} {
got, err := naming.CleanDisplayName(c.in)
if (err == nil) != c.ok || got != c.want {
t.Errorf("%s: CleanDisplayName(%q) = %q, %v; want %q, ok=%v", c.name, c.in, got, err, c.want, c.ok)
}
}
}
+6 -1
View File
@@ -1,6 +1,7 @@
package naming
import (
"fmt"
"os"
"regexp"
"slices"
@@ -11,7 +12,8 @@ import (
// The panel's create form checks names as they are typed with its own copy of
// this rule (panel/src/lib/naming.ts). A name reserved or a length changed here
// without the panel would let the form send what the API refuses, or refuse what
// it takes, so the copy is compared to the source.
// it takes, so the copy is compared to the source. The copy also holds the display-name
// length the create and edit forms stop at.
func TestPanelMirrorsServerNameRule(t *testing.T) {
raw, err := os.ReadFile("../../panel/src/lib/naming.ts")
if err != nil {
@@ -40,4 +42,7 @@ func TestPanelMirrorsServerNameRule(t *testing.T) {
if want := "const SERVER_NAME_RE = /" + serverNameRE.String() + "/;"; !strings.Contains(src, want) {
t.Errorf("panel/src/lib/naming.ts lacks %q", want)
}
if want := fmt.Sprintf("export const DISPLAY_NAME_MAX = %d;", MaxDisplayName); !strings.Contains(src, want) {
t.Errorf("panel/src/lib/naming.ts lacks %q", want)
}
}