Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions NEWS.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@
* Update visibility hidden reason handling ([MODKBEKBJ-823](https://folio-org.atlassian.net/browse/MODKBEKBJ-823))
* Remove HTML validation for package's custom display name field ([MODKBEKBJ-855](https://folio-org.atlassian.net/browse/MODKBEKBJ-855))
* Add access types to eholdings/providers/{id}/packages response ([MODKBEKBJ-839](https://folio-org.atlassian.net/browse/MODKBEKBJ-839))
* Sanitize HTML content for the package description field ([MODKBEKBJ-860](https://folio-org.atlassian.net/browse/MODKBEKBJ-860))

### Bug fixes
* Fix offset handling when retrieving holdings from HoldingsIQ. ([MODKBEKBJ-825](https://folio-org.atlassian.net/browse/MODKBEKBJ-825))
Expand Down
6 changes: 6 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@
<lombok.version>1.18.48</lombok.version>
<opencsv.version>5.12.0</opencsv.version>
<commons-lang3.version>3.20.0</commons-lang3.version>
<jsoup.version>1.23.2</jsoup.version>

<ramlfiles_path>${basedir}/ramls</ramlfiles_path>
<jsonschema_paths>types/**</jsonschema_paths>
Expand Down Expand Up @@ -222,6 +223,11 @@
<artifactId>commons-lang3</artifactId>
<version>${commons-lang3.version}</version>
</dependency>
<dependency>
<groupId>org.jsoup</groupId>
<artifactId>jsoup</artifactId>
<version>${jsoup.version}</version>
</dependency>

<!-- Test dependencies -->
<dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,11 +10,18 @@
import org.folio.holdingsiq.model.Visibility;
import org.folio.rest.jaxrs.model.PackagePutDataAttributes;
import org.folio.rest.jaxrs.model.PackageVisibility;
import org.folio.service.sanitizer.Sanitizer;

public abstract class CommonPackagePutRequestConverter {

static final String HIDDEN_BY_CUSTOMER = "Hidden by Customer";

private final Sanitizer<String> htmlSanitizer;

protected CommonPackagePutRequestConverter(Sanitizer<String> htmlSanitizer) {
this.htmlSanitizer = htmlSanitizer;
}

protected PackagePut.PackagePutBuilder convertCommonAttributes(PackagePutDataAttributes attributes) {
var builder = PackagePut.builder();

Expand Down Expand Up @@ -45,7 +52,7 @@ protected Visibility convertVisibility(PackageVisibility pv) {
private void convertSimpleFields(PackagePutDataAttributes attributes, PackagePut.PackagePutBuilder builder) {
builder.isSelected(attributes.getIsSelected());
builder.isFullPackage(attributes.getIsFullPackage());
builder.customDescription(attributes.getCustomDescription());
builder.customDescription(htmlSanitizer.sanitize(attributes.getCustomDescription()));
builder.customDisplayName(attributes.getCustomDisplayName());
builder.packageFreeAccess(attributes.getIsFreeAccess());
builder.packageUrl(attributes.getUrl());
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,20 +12,27 @@
import org.folio.rest.jaxrs.model.PackageAltName;
import org.folio.rest.jaxrs.model.PackagePostRequest;
import org.folio.rest.jaxrs.model.ProxyDto;
import org.folio.service.sanitizer.Sanitizer;
import org.springframework.core.convert.converter.Converter;
import org.springframework.stereotype.Component;

@Component
public class CustomPackagePostRequestConverter implements Converter<PackagePostRequest, PackagePost> {

private final Sanitizer<String> htmlSanitizer;

public CustomPackagePostRequestConverter(Sanitizer<String> htmlSanitizer) {
this.htmlSanitizer = htmlSanitizer;
}

@Override
public PackagePost convert(PackagePostRequest postPackageBody) {
var data = postPackageBody.getData();
var attributes = data.getAttributes();
return PackagePost.builder()
.customAltNames(mapItemsNullable(attributes.getCustomAltNames(), this::convertAlternateName))
.coverage(convertCoverageDates(attributes.getCustomCoverage()))
.customDescription(attributes.getCustomDescription())
.customDescription(htmlSanitizer.sanitize(attributes.getCustomDescription()))
.customDisplayName(attributes.getCustomDisplayName())
.contentType(CONTENT_TYPE_TO_RMAPI_CODE.getOrDefault(attributes.getContentType(), 6))
.packageName(attributes.getName())
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@

import org.folio.holdingsiq.model.PackagePut;
import org.folio.rest.jaxrs.model.PackagePutRequest;
import org.folio.service.sanitizer.Sanitizer;
import org.springframework.core.convert.converter.Converter;
import org.springframework.stereotype.Component;

Expand All @@ -12,6 +13,10 @@ public class CustomPackagePutRequestConverter
extends CommonPackagePutRequestConverter
implements Converter<PackagePutRequest, PackagePut> {

public CustomPackagePutRequestConverter(Sanitizer<String> htmlSanitizer) {
super(htmlSanitizer);
}

@Override
public PackagePut convert(PackagePutRequest request) {
var attributes = request.getData().getAttributes();
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
import org.folio.holdingsiq.model.PackagePut;
import org.folio.holdingsiq.model.TokenInfo;
import org.folio.rest.jaxrs.model.PackagePutRequest;
import org.folio.service.sanitizer.Sanitizer;
import org.springframework.core.convert.converter.Converter;
import org.springframework.stereotype.Component;

Expand All @@ -11,6 +12,10 @@ public class ManagedPackagePutRequestConverter
extends CommonPackagePutRequestConverter
implements Converter<PackagePutRequest, PackagePut> {

public ManagedPackagePutRequestConverter(Sanitizer<String> htmlSanitizer) {
super(htmlSanitizer);
}

@Override
public PackagePut convert(PackagePutRequest request) {
var attributes = request.getData().getAttributes();
Expand Down
Loading
Loading