class Bullet::Rack
Constants
- NONCE_MATCHER
Public Class Methods
Public Instance Methods
Source
# File lib/bullet/rack.rb, line 62 def append_to_html_body(response_body, content) body = response_body.dup content = content.html_safe if content.respond_to?(:html_safe) if body.include?('</body>') position = body.rindex('</body>') body.insert(position, content) else body << content end end
Source
# File lib/bullet/rack.rb, line 17 def call(env) return @app.call(env) unless Bullet.enable? Bullet.start_request status, headers, response = @app.call(env) response_body = nil if Bullet.notification? || Bullet.always_append_html_body request = ::Rack::Request.new(env) if Bullet.inject_into_page? && !skip_html_injection?(request) && !file?(headers) && !sse?(headers) && !empty?(response) && status == 200 if html_request?(headers, response) response_body = response_body(response) with_security_policy_nonce(headers) do |nonce| response_body = append_to_html_body(response_body, footer_note(nonce)) if Bullet.add_footer response_body = append_to_html_body(response_body, Bullet.gather_inline_notifications) if Bullet.add_footer && !Bullet.skip_http_headers response_body = append_to_html_body(response_body, xhr_script(nonce)) end end headers['Content-Length'] = response_body.bytesize.to_s elsif !Bullet.skip_http_headers set_header(headers, 'X-bullet-footer-text', Bullet.footer_info.uniq) if Bullet.add_footer set_header(headers, 'X-bullet-console-text', Bullet.text_notifications) if Bullet.console_enabled? end end Bullet.perform_out_of_channel_notifications(env) end [status, headers, response_body ? [response_body] : response] ensure Bullet.end_request end
Source
# File lib/bullet/rack.rb, line 53 def empty?(response) # response may be ["Not Found"], ["Move Permanently"], etc, but # those should not happen if the status is 200 return true if !response.respond_to?(:body) && !response.respond_to?(:first) body = response_body(response) body.nil? || body.empty? end
fix issue if response’s body is a Proc
Source
# File lib/bullet/rack.rb, line 117 def file?(headers) headers['Content-Transfer-Encoding'] == 'binary' || headers['Content-Disposition'] end
Source
# File lib/bullet/rack.rb, line 125 def html_request?(headers, response) headers['Content-Type']&.include?('text/html') end
Source
# File lib/bullet/rack.rb, line 129 def response_body(response) if response.respond_to?(:body) Array === response.body ? response.body.first : response.body elsif response.respond_to?(:first) response.first end end
Source
# File lib/bullet/rack.rb, line 91 def set_header(headers, header_name, header_array) # Many proxy applications such as Nginx and AWS ELB limit # the size a header to 8KB, so truncate the list of reports to # be under that limit header_array.pop while JSON.generate(header_array).length > 8 * 1024 headers[header_name] = JSON.generate(header_array) end
Source
# File lib/bullet/rack.rb, line 108 def simple_parse_query_string(query_string) params = {} query_string.split('&').each do |pair| key, value = pair.split('=', 2).map { |s| CGI.unescape(s) } params[key] = value if key && !key.empty? end params end
Simple query string parser
Source
# File lib/bullet/rack.rb, line 99 def skip_html_injection?(request) query_string = request.env['QUERY_STRING'] return false if query_string.nil? || query_string.empty? params = simple_parse_query_string(query_string) params['skip_html_injection'] == 'true' end
Source
# File lib/bullet/rack.rb, line 121 def sse?(headers) headers['Content-Type'] == 'text/event-stream' end
Private Instance Methods
Source
# File lib/bullet/rack.rb, line 165 def with_security_policy_nonce(headers) csp = headers['Content-Security-Policy'] || headers['Content-Security-Policy-Report-Only'] || '' matched = csp.match(NONCE_MATCHER) nonce = matched[:nonce] if matched if nonce console_enabled = UniformNotifier.console alert_enabled = UniformNotifier.alert UniformNotifier.console = { attributes: { nonce: nonce } } if console_enabled UniformNotifier.alert = { attributes: { nonce: nonce } } if alert_enabled yield nonce UniformNotifier.console = console_enabled UniformNotifier.alert = alert_enabled else yield end end
Source
# File lib/bullet/rack.rb, line 155 def xhr_script(nonce = nil) script = File.read("#{__dir__}/bullet_xhr.js") if nonce "<script type='text/javascript' nonce='#{nonce}'>#{script}</script>" else "<script type='text/javascript'>#{script}</script>" end end
Make footer work for XHR requests by appending data to the footer