Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 19 additions & 10 deletions lib/index.js
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
var rawbody = require('raw-body');
const rawbody = require('raw-body');

function hasSql(value) {

Expand All @@ -7,35 +7,43 @@ function hasSql(value) {
}

// sql regex reference: http://www.symantec.com/connect/articles/detection-sql-injection-and-cross-site-scripting-attacks
var sql_meta = new RegExp('(%27)|(\')|(--)|(%23)|(#)', 'i');
var sql_meta = new RegExp(/(%27)|(\')|(--)|(%23)|(#)/, 'i');
if(sql_meta.test(value)){
return true;
}

var sql_meta2 = new RegExp('((%3D)|(=))[^\n]*((%27)|(\')|(--)|(%3B)|(;))', 'i');
var sql_meta2 = new RegExp(/((%3D)|(=))[^\n]*((%27)|(\')|(--)|(%3B)|(;))/, 'i');
if(sql_meta2.test(value)){
return true;
}

var sql_typical = new RegExp('w*((%27)|(\'))((%6F)|o|(%4F))((%72)|r|(%52))', 'i');
var sql_typical = new RegExp(/w*((%27)|(\'))((%6F)|o|(%4F))((%72)|r|(%52))/, 'i');
if(sql_typical.test(value)){
return true;
}

var sql_union = new RegExp('((%27)|(\'))union', 'i');
var sql_union = new RegExp(/((%27)|(\'))union/, 'i');
if(sql_union.test(value)){
return true;
}

return false;
}

function isNullAndUndefined(value) {
if(value === null && value === undefined) {
return true;
}

return false;
}

function middleware(req, res, next) {

var containsSql = false;

if (req.originalUrl !== null && req.originalUrl !== undefined) {
if (hasSql(req.originalUrl) === true) {
if (!isNullAndUndefined(req.originalUrl)) {
if (hasSql(req.originalUrl)) {
containsSql = true;
}
}
Expand All @@ -49,18 +57,18 @@ function middleware(req, res, next) {
return next(err);
}

if (body !== null && body !== undefined) {
if (!isNullAndUndefined(body)) {

if (typeof body !== 'string') {
body = JSON.stringify(body);
}

if (hasSql(body) === true) {
if (hasSql(body)) {
containsSql = true;
}
}

if (containsSql === true) {
if (containsSql) {
res.send(403);
}
else {
Expand All @@ -72,4 +80,5 @@ function middleware(req, res, next) {
}
}


module.exports = middleware;