diff --git a/cockatrice/src/interface/widgets/tabs/tab_deck_storage.cpp b/cockatrice/src/interface/widgets/tabs/tab_deck_storage.cpp index 62769d0e3..41ebb17a2 100644 --- a/cockatrice/src/interface/widgets/tabs/tab_deck_storage.cpp +++ b/cockatrice/src/interface/widgets/tabs/tab_deck_storage.cpp @@ -14,6 +14,7 @@ #include #include #include +#include #include #include #include @@ -49,6 +50,12 @@ namespace // How long to wait after the last visibility change before reading back the // Public/Private column, in milliseconds. constexpr int VISIBILITY_REFRESH_DELAY = 500; + +// Whether the file's name matches one of the deck formats Cockatrice can load. +bool isSupportedDeckFile(const QString &filePath) +{ + return QDir::match(DeckLoader::ACCEPTED_FILE_EXTENSIONS, QFileInfo(filePath).fileName()); +} } // namespace TabDeckStorage::TabDeckStorage(TabSupervisor *_tabSupervisor, @@ -58,6 +65,8 @@ TabDeckStorage::TabDeckStorage(TabSupervisor *_tabSupervisor, { localDirModel = new QFileSystemModel(this); localDirModel->setRootPath(SettingsCache::instance().paths().getDeckPath()); + localDirModel->setNameFilters(DeckLoader::ACCEPTED_FILE_EXTENSIONS); + localDirModel->setNameFilterDisables(false); localDirModel->sort(0, Qt::AscendingOrder); localDirView = new QTreeView; @@ -312,6 +321,10 @@ void TabDeckStorage::actOpenLocalDeck() } QString filePath = localDirModel->filePath(curLeft); + if (!isSupportedDeckFile(filePath)) { + continue; + } + std::optional deckOpt = DeckLoader::loadFromFile(filePath, DeckFileFormat::Cockatrice, true); if (!deckOpt) { continue; @@ -376,6 +389,11 @@ void TabDeckStorage::actUpload() void TabDeckStorage::uploadDeck(const QString &filePath, const QString &targetPath) { + if (!isSupportedDeckFile(filePath)) { + QMessageBox::critical(this, tr("Error"), tr("Invalid deck file")); + return; + } + QFile deckFile(filePath); QFileInfo deckFileInfo(deckFile); diff --git a/cockatrice/src/interface/widgets/tabs/tab_replays.cpp b/cockatrice/src/interface/widgets/tabs/tab_replays.cpp index ac4b2cbe9..e26bea2a3 100644 --- a/cockatrice/src/interface/widgets/tabs/tab_replays.cpp +++ b/cockatrice/src/interface/widgets/tabs/tab_replays.cpp @@ -9,6 +9,7 @@ #include #include #include +#include #include #include #include @@ -34,6 +35,12 @@ inline Q_LOGGING_CATEGORY(TabReplaysLog, "replays_tab"); +namespace +{ +// File name filters for the local replay files Cockatrice can load. +const QStringList REPLAY_FILE_NAME_FILTERS = {"*.cor"}; +} // namespace + TabReplays::TabReplays(TabSupervisor *_tabSupervisor, AbstractClient *_client, const ServerInfo_User *currentUserInfo) : Tab(_tabSupervisor), client(_client) { @@ -62,6 +69,8 @@ QGroupBox *TabReplays::createLeftLayout() { localDirModel = new QFileSystemModel(this); localDirModel->setRootPath(SettingsCache::instance().paths().getReplaysPath()); + localDirModel->setNameFilters(REPLAY_FILE_NAME_FILTERS); + localDirModel->setNameFilterDisables(false); localDirModel->sort(0, Qt::AscendingOrder); localDirView = new QTreeView; @@ -263,6 +272,10 @@ void TabReplays::actOpenLocalReplay() } QString filePath = localDirModel->filePath(curLeft); + if (!QDir::match(REPLAY_FILE_NAME_FILTERS, QFileInfo(filePath).fileName())) { + continue; + } + QFile f(filePath); if (!f.open(QIODevice::ReadOnly)) { continue; diff --git a/servatrice/src/serversocketinterface.cpp b/servatrice/src/serversocketinterface.cpp index 9c78c48f3..a8d13675d 100644 --- a/servatrice/src/serversocketinterface.cpp +++ b/servatrice/src/serversocketinterface.cpp @@ -982,6 +982,10 @@ Response::ResponseCode AbstractServerSocketInterface::cmdDeckUpload(const Comman return Response::RespInvalidData; } + if (cmd.deck_list().size() > static_cast(MAX_FILE_LENGTH)) { + return Response::RespInvalidData; + } + sqlInterface->checkSql(); QString deckStr = fileFromStdString(cmd.deck_list());