File
Blob: src/shared/web/validation.ts
| 1 | /** |
| 2 | * Request/route validation helpers used across UI routes. |
| 3 | */ |
| 4 | export const MAX_REF_LEN = 256; |
| 5 | export const MAX_PATH_LEN = 4096; |
| 6 | export const OWNER_REPO_RE = /^[A-Za-z0-9._-]{1,100}$/; |
| 7 | export const REF_RE = /^[A-Za-z0-9._\/-]{1,256}$/; // allow refs/heads/main, tags, simple branch names |
| 8 | export const OID_RE = /^[0-9a-fA-F]{40}$/; |
| 9 | |
| 10 | export function isValidOwnerRepo(s: string): boolean { |
| 11 | return OWNER_REPO_RE.test(s); |
| 12 | } |
| 13 | |
| 14 | export function isValidRef(ref: string): boolean { |
| 15 | if (!ref || ref.length > MAX_REF_LEN) return false; |
| 16 | if (ref === "HEAD") return true; |
| 17 | if (OID_RE.test(ref)) return true; |
| 18 | return REF_RE.test(ref); |
| 19 | } |
| 20 | |
| 21 | export function isValidPath(p: string): boolean { |
| 22 | if (p.length > MAX_PATH_LEN) return false; |
| 23 | // disallow control chars and NUL |
| 24 | return !/[\0\u0000-\u001F]/.test(p); |
| 25 | } |