1
0
mirror of https://gitcode.com/gh_mirrors/re/react-native-pushy.git synced 2025-09-19 00:10:42 +08:00
Code Issues Packages Projects Releases Wiki Activity GitHub Gitee

Compare commits

..

11 Commits

Author SHA1 Message Date
sunnylqm
8622935bdf fix: zipslip 2023-12-12 23:07:11 +08:00
sunnylqm
b747b1f356 v9.1.4 2023-10-30 22:58:41 +08:00
sunnylqm
7752581470 chore: throttle switchversion 2023-10-30 22:58:09 +08:00
sunnylqm
33eb89d2a7 v9.1.3 2023-10-28 18:28:54 +08:00
sunnylqm
d111bf5a9c chore: rename onPushyEvents 2023-10-28 18:28:23 +08:00
sunnylqm
23346a5f1d v9.1.2 2023-10-28 17:26:19 +08:00
sunnylqm
5aca2104c2 fix: simpleUpdate for web 2023-10-28 17:25:54 +08:00
sunnylqm
fe0a05db3d v9.1.0 2023-10-28 17:01:54 +08:00
sunnylqm
2b287786ff chore: remove permissions 2023-10-28 14:37:26 +08:00
sunnylqm
7d128900cd feat: improve backup endpoints 2023-10-28 14:36:04 +08:00
sunnylqm
189e3ec78e v9.0.5 2023-09-24 21:18:11 +08:00
11 changed files with 2620 additions and 213 deletions

View File

@@ -1,2 +1,3 @@
-keepnames class cn.reactnative.modules.update.DownloadTask { *; } -keepnames class cn.reactnative.modules.update.DownloadTask { *; }
-keepnames class cn.reactnative.modules.update.UpdateModuleImpl { *; }
-keepnames class com.facebook.react.ReactInstanceManager { *; } -keepnames class com.facebook.react.ReactInstanceManager { *; }

View File

@@ -1,9 +1,6 @@
<?xml version="1.0" encoding="utf-8"?> <?xml version="1.0" encoding="utf-8"?>
<manifest xmlns:android="http://schemas.android.com/apk/res/android" <manifest xmlns:android="http://schemas.android.com/apk/res/android"
package="cn.reactnative.modules.update"> package="cn.reactnative.modules.update">
<uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES" />
<uses-permission android:name="android.permission.WRITE_EXTERNAL_STORAGE" />
<application> <application>
<meta-data android:name="pushy_build_time" android:value="@string/pushy_build_time" /> <meta-data android:name="pushy_build_time" android:value="@string/pushy_build_time" />
<provider <provider

View File

@@ -237,19 +237,7 @@ class DownloadTask extends AsyncTask<DownloadTaskParams, long[], Void> {
while (entries.hasMoreElements()) { while (entries.hasMoreElements()) {
ZipEntry ze = entries.nextElement(); ZipEntry ze = entries.nextElement();
String fn = ze.getName(); zipFile.unzipToPath(ze, param.unzipDirectory);
File fmd = new File(param.unzipDirectory, fn);
if (UpdateContext.DEBUG) {
Log.d("RNUpdate", "Unzipping " + fn);
}
if (ze.isDirectory()) {
fmd.mkdirs();
continue;
}
zipFile.unzipToFile(ze, fmd);
} }
zipFile.close(); zipFile.close();
@@ -324,8 +312,15 @@ class DownloadTask extends AsyncTask<DownloadTaskParams, long[], Void> {
} else { } else {
target = copyList.get((from)); target = copyList.get((from));
} }
target.add(new File(param.unzipDirectory, to)); File toFile = new File(param.unzipDirectory, to);
//copyFromResource(from, new File(param.unzipDirectory, to));
// Fixing a Zip Path Traversal Vulnerability
// https://support.google.com/faqs/answer/9294009
String canonicalPath = toFile.getCanonicalPath();
if (!canonicalPath.startsWith(param.unzipDirectory.getCanonicalPath() + File.separator)) {
throw new SecurityException("Illegal name: " + to);
}
target.add(toFile);
} }
continue; continue;
} }
@@ -339,18 +334,9 @@ class DownloadTask extends AsyncTask<DownloadTaskParams, long[], Void> {
fout.close(); fout.close();
continue; continue;
} }
File fmd = new File(param.unzipDirectory, fn);
if (UpdateContext.DEBUG) {
Log.d("RNUpdate", "Unzipping " + fn);
}
if (ze.isDirectory()) { zipFile.unzipToPath(ze, param.unzipDirectory);
fmd.mkdirs();
continue;
}
zipFile.unzipToFile(ze, fmd);
} }
zipFile.close(); zipFile.close();
@@ -419,18 +405,8 @@ class DownloadTask extends AsyncTask<DownloadTaskParams, long[], Void> {
fout.close(); fout.close();
continue; continue;
} }
File fmd = new File(param.unzipDirectory, fn);
if (UpdateContext.DEBUG) { zipFile.unzipToPath(ze, param.unzipDirectory);
Log.d("RNUpdate", "Unzipping " + fn);
}
if (ze.isDirectory()) {
fmd.mkdirs();
continue;
}
zipFile.unzipToFile(ze, fmd);
} }
zipFile.close(); zipFile.close();

View File

@@ -1,5 +1,7 @@
package cn.reactnative.modules.update; package cn.reactnative.modules.update;
import android.util.Log;
import java.io.BufferedInputStream; import java.io.BufferedInputStream;
import java.io.BufferedOutputStream; import java.io.BufferedOutputStream;
import java.io.File; import java.io.File;
@@ -10,12 +12,15 @@ import java.util.Enumeration;
import java.util.zip.ZipEntry; import java.util.zip.ZipEntry;
import java.util.zip.ZipFile; import java.util.zip.ZipFile;
public class SafeZipFile extends ZipFile { public class SafeZipFile extends ZipFile {
public SafeZipFile(File file) throws IOException { public SafeZipFile(File file) throws IOException {
super(file); super(file);
} }
private static final int BUFFER_SIZE = 8192;
@Override @Override
public Enumeration<? extends ZipEntry> entries() { public Enumeration<? extends ZipEntry> entries() {
return new SafeZipEntryIterator(super.entries()); return new SafeZipEntryIterator(super.entries());
@@ -43,40 +48,46 @@ public class SafeZipFile extends ZipFile {
* avoid ZipperDown * avoid ZipperDown
*/ */
if (null != name && (name.contains("../") || name.contains("..\\"))) { if (null != name && (name.contains("../") || name.contains("..\\"))) {
throw new SecurityException("illegal entry: " + entry.getName()); throw new SecurityException("illegal entry: " + name);
} }
} }
return entry; return entry;
} }
} }
public void unzipToFile(ZipEntry entry, File output) throws IOException { public void unzipToPath(ZipEntry ze, File targetPath) throws IOException {
InputStream inputStream = null; String name = ze.getName();
try { File target = new File(targetPath, name);
inputStream = getInputStream(entry);
writeOutInputStream(output, inputStream); // Fixing a Zip Path Traversal Vulnerability
} finally { // https://support.google.com/faqs/answer/9294009
if (inputStream != null) { String canonicalPath = target.getCanonicalPath();
inputStream.close(); if (!canonicalPath.startsWith(targetPath.getCanonicalPath() + File.separator)) {
throw new SecurityException("Illegal name: " + name);
}
if (UpdateContext.DEBUG) {
Log.d("RNUpdate", "Unzipping " + name);
}
if (ze.isDirectory()) {
target.mkdirs();
return;
}
unzipToFile(ze, target);
}
public void unzipToFile(ZipEntry ze, File target) throws IOException {
try (InputStream inputStream = getInputStream(ze)) {
try (BufferedOutputStream output = new BufferedOutputStream(new FileOutputStream(target));
BufferedInputStream input = new BufferedInputStream(inputStream)) {
byte[] buffer = new byte[BUFFER_SIZE];
int n;
while ((n = input.read(buffer, 0, BUFFER_SIZE)) >= 0) {
output.write(buffer, 0, n);
}
} }
} }
} }
private void writeOutInputStream(File file, InputStream inputStream) throws IOException {
BufferedOutputStream output = null;
try {
output = new BufferedOutputStream(
new FileOutputStream(file));
BufferedInputStream input = new BufferedInputStream(inputStream);
byte b[] = new byte[8192];
int n;
while ((n = input.read(b, 0, 8192)) >= 0) {
output.write(b, 0, n);
}
} finally {
if (output != null) {
output.close();
}
}
}
} }

View File

@@ -1,75 +1,26 @@
import { logger } from './utils';
let currentEndpoint = 'https://update.react-native.cn/api'; let currentEndpoint = 'https://update.react-native.cn/api';
let backupEndpoints: string[] = ['https://update.reactnative.cn/api'];
let backupEndpointsQueryUrl: string | null = null;
function ping(url: string, rejectImmediate?: boolean) { export async function updateBackupEndpoints() {
return new Promise((resolve, reject) => { if (backupEndpointsQueryUrl) {
const xhr = new XMLHttpRequest();
xhr.onreadystatechange = (e) => {
if (xhr.readyState !== 4) {
return;
}
if (xhr.status === 200) {
resolve(url);
} else {
rejectImmediate ? reject() : setTimeout(reject, 5000);
}
};
xhr.open('HEAD', url);
xhr.send();
xhr.timeout = 5000;
xhr.ontimeout = reject;
});
}
function logger(...args: any[]) {
console.log('Pushy: ', ...args);
}
let backupEndpoints: string[] = [];
let backupEndpointsQueryUrl: string | null =
'https://cdn.jsdelivr.net/gh/reactnativecn/react-native-pushy@master/endpoints.json';
export async function tryBackupEndpoints() {
if (!backupEndpoints.length && !backupEndpointsQueryUrl) {
return;
}
try {
await ping(getStatusUrl(), true);
logger('current endpoint ok', currentEndpoint);
return;
} catch (e) {
logger('current endpoint failed', currentEndpoint);
}
if (!backupEndpoints.length && backupEndpointsQueryUrl) {
try { try {
const resp = await fetch(backupEndpointsQueryUrl); const resp = await fetch(backupEndpointsQueryUrl);
backupEndpoints = await resp.json(); const remoteEndpoints = await resp.json();
logger('get remote endpoints:', backupEndpoints); if (Array.isArray(remoteEndpoints)) {
} catch (e) { backupEndpoints = Array.from(
logger('get remote endpoints failed'); new Set([...backupEndpoints, ...remoteEndpoints]),
return;
}
}
await pickFatestAvailableEndpoint();
}
async function pickFatestAvailableEndpoint(endpoints = backupEndpoints) {
const fastestEndpoint = await Promise.race(
endpoints.map(pingAndReturnEndpoint),
); );
if (typeof fastestEndpoint === 'string') { logger('fetch remote endpoints:', remoteEndpoints);
logger(`pick endpoint: ${fastestEndpoint}`); logger('merged backup endpoints:', backupEndpoints);
currentEndpoint = fastestEndpoint; }
} else { } catch (e) {
logger('all remote endpoints failed'); logger('fetch remote endpoints failed');
} }
} }
return backupEndpoints;
async function pingAndReturnEndpoint(endpoint = currentEndpoint) {
return ping(getStatusUrl(endpoint)).then(() => endpoint);
}
function getStatusUrl(endpoint = currentEndpoint) {
return `${endpoint}/status`;
} }
export function getCheckUrl(APPKEY, endpoint = currentEndpoint) { export function getCheckUrl(APPKEY, endpoint = currentEndpoint) {
@@ -95,7 +46,6 @@ export function setCustomEndpoints({
backupEndpointsQueryUrl = null; backupEndpointsQueryUrl = null;
if (Array.isArray(backups) && backups.length > 0) { if (Array.isArray(backups) && backups.length > 0) {
backupEndpoints = backups; backupEndpoints = backups;
pickFatestAvailableEndpoint();
} }
if (typeof backupQueryUrl === 'string') { if (typeof backupQueryUrl === 'string') {
backupEndpointsQueryUrl = backupQueryUrl; backupEndpointsQueryUrl = backupQueryUrl;

View File

@@ -14,5 +14,5 @@ export const markSuccess = noop;
export const downloadAndInstallApk = noop; export const downloadAndInstallApk = noop;
export const setCustomEndpoints = noop; export const setCustomEndpoints = noop;
export const getCurrentVersionInfo = noop; export const getCurrentVersionInfo = noop;
export const simpleUpdate = noop; export const simpleUpdate = (app) => app;
export const onEvents = noop; export const onPushyEvents = noop;

View File

@@ -1,5 +1,5 @@
import { import {
tryBackupEndpoints, updateBackupEndpoints,
getCheckUrl, getCheckUrl,
setCustomEndpoints, setCustomEndpoints,
} from './endpoint'; } from './endpoint';
@@ -16,6 +16,7 @@ import {
UpdateAvailableResult, UpdateAvailableResult,
UpdateEventsListener, UpdateEventsListener,
} from './type'; } from './type';
import { assertRelease, logger } from './utils';
export { setCustomEndpoints }; export { setCustomEndpoints };
const { const {
version: v, version: v,
@@ -74,14 +75,10 @@ if (!uuid) {
PushyModule.setUuid(uuid); PushyModule.setUuid(uuid);
} }
function logger(...args: string[]) {
console.log('Pushy: ', ...args);
}
const noop = () => {}; const noop = () => {};
let reporter: UpdateEventsListener = noop; let reporter: UpdateEventsListener = noop;
export function onEvents(customReporter: UpdateEventsListener) { export function onPushyEvents(customReporter: UpdateEventsListener) {
reporter = customReporter; reporter = customReporter;
if (isRolledBack) { if (isRolledBack) {
report({ report({
@@ -125,21 +122,15 @@ export const cInfo = {
uuid, uuid,
}; };
function assertRelease() {
if (__DEV__) {
throw new Error('react-native-update 只能在 RELEASE 版本中运行.');
}
}
let lastChecking; let lastChecking;
const empty = {}; const empty = {};
let lastResult: CheckResult; let lastResult: CheckResult;
export async function checkUpdate(APPKEY: string, isRetry?: boolean) { export async function checkUpdate(APPKEY: string) {
assertRelease(); assertRelease();
const now = Date.now(); const now = Date.now();
if (lastResult && lastChecking && now - lastChecking < 1000 * 60) { if (lastResult && lastChecking && now - lastChecking < 1000 * 60) {
// logger('repeated checking, ignored'); // logger('repeated checking, ignored');
return lastResult || empty; return lastResult;
} }
lastChecking = now; lastChecking = now;
if (blockUpdate && blockUpdate.until > Date.now() / 1000) { if (blockUpdate && blockUpdate.until > Date.now() / 1000) {
@@ -152,9 +143,7 @@ export async function checkUpdate(APPKEY: string, isRetry?: boolean) {
return lastResult || empty; return lastResult || empty;
} }
report({ type: 'checking' }); report({ type: 'checking' });
let resp; const fetchPayload = {
try {
resp = await fetch(getCheckUrl(APPKEY), {
method: 'POST', method: 'POST',
headers: { headers: {
Accept: 'application/json', Accept: 'application/json',
@@ -166,18 +155,33 @@ export async function checkUpdate(APPKEY: string, isRetry?: boolean) {
buildTime, buildTime,
cInfo, cInfo,
}), }),
}); };
let resp;
try {
resp = await fetch(getCheckUrl(APPKEY), fetchPayload);
} catch (e) { } catch (e) {
if (isRetry) { report({
type: 'errorChecking',
message: '无法连接主更新服务器,尝试备用节点',
});
const backupEndpoints = await updateBackupEndpoints();
if (backupEndpoints) {
try {
resp = await Promise.race(
backupEndpoints.map((endpoint) =>
fetch(getCheckUrl(APPKEY, endpoint), fetchPayload),
),
);
} catch {}
}
}
if (!resp) {
report({ report({
type: 'errorChecking', type: 'errorChecking',
message: '无法连接更新服务器,请检查网络连接后重试', message: '无法连接更新服务器,请检查网络连接后重试',
}); });
return lastResult || empty; return lastResult || empty;
} }
await tryBackupEndpoints();
return checkUpdate(APPKEY, true);
}
const result: CheckResult = await resp.json(); const result: CheckResult = await resp.json();
lastResult = result; lastResult = result;
@@ -190,7 +194,6 @@ export async function checkUpdate(APPKEY: string, isRetry?: boolean) {
//@ts-ignore //@ts-ignore
message: result.message, message: result.message,
}); });
return lastResult;
} }
return result; return result;
@@ -319,10 +322,12 @@ function assertHash(hash: string) {
return true; return true;
} }
let applyingUpdate = false;
export function switchVersion(hash: string) { export function switchVersion(hash: string) {
assertRelease(); assertRelease();
if (assertHash(hash)) { if (assertHash(hash) && !applyingUpdate) {
logger('switchVersion: ' + hash); logger('switchVersion: ' + hash);
applyingUpdate = true;
PushyModule.reloadUpdate({ hash }); PushyModule.reloadUpdate({ hash });
} }
} }

View File

@@ -16,20 +16,20 @@ import {
switchVersionLater, switchVersionLater,
markSuccess, markSuccess,
downloadAndInstallApk, downloadAndInstallApk,
onEvents, onPushyEvents,
} from './main'; } from './main';
import { UpdateEventsListener } from './type'; import { UpdateEventsListener } from './type';
export function simpleUpdate( export function simpleUpdate(
WrappedComponent: ComponentType, WrappedComponent: ComponentType,
options: { appKey?: string; onEvents?: UpdateEventsListener } = {}, options: { appKey?: string; onPushyEvents?: UpdateEventsListener } = {},
) { ) {
const { appKey, onEvents: eventListeners } = options; const { appKey, onPushyEvents: eventListeners } = options;
if (!appKey) { if (!appKey) {
throw new Error('appKey is required for simpleUpdate()'); throw new Error('appKey is required for simpleUpdate()');
} }
if (typeof eventListeners === 'function') { if (typeof eventListeners === 'function') {
onEvents(eventListeners); onPushyEvents(eventListeners);
} }
return __DEV__ return __DEV__
? WrappedComponent ? WrappedComponent

9
lib/utils.ts Normal file
View File

@@ -0,0 +1,9 @@
export function logger(...args: any[]) {
console.log('Pushy: ', ...args);
}
export function assertRelease() {
if (__DEV__) {
throw new Error('react-native-update 只能在 RELEASE 版本中运行.');
}
}

View File

@@ -1,6 +1,6 @@
{ {
"name": "react-native-update", "name": "react-native-update",
"version": "9.0.4", "version": "9.1.4",
"description": "react-native hot update", "description": "react-native hot update",
"main": "lib/index.ts", "main": "lib/index.ts",
"scripts": { "scripts": {
@@ -39,7 +39,7 @@
"url": "https://github.com/reactnativecn/react-native-pushy/issues" "url": "https://github.com/reactnativecn/react-native-pushy/issues"
}, },
"peerDependencies": { "peerDependencies": {
"react-native": ">=0.27.0" "react-native": ">=0.57.0"
}, },
"homepage": "https://github.com/reactnativecn/react-native-pushy#readme", "homepage": "https://github.com/reactnativecn/react-native-pushy#readme",
"dependencies": { "dependencies": {
@@ -57,12 +57,15 @@
"devDependencies": { "devDependencies": {
"@types/fs-extra": "^9.0.13", "@types/fs-extra": "^9.0.13",
"@types/jest": "^29.2.1", "@types/jest": "^29.2.1",
"@types/node": "^20.8.9",
"@types/react": "^18.2.33",
"detox": "^20.5.0", "detox": "^20.5.0",
"firebase-tools": "^11.24.1", "firebase-tools": "^11.24.1",
"fs-extra": "^9.1.0", "fs-extra": "^9.1.0",
"jest": "^29.2.1", "jest": "^29.2.1",
"pod-install": "^0.1.37", "pod-install": "^0.1.37",
"react-native": "^0.72.6",
"ts-jest": "^29.0.3", "ts-jest": "^29.0.3",
"typescript": "^4.1.3" "typescript": "^5.2.2"
} }
} }

2527
yarn.lock

File diff suppressed because it is too large Load Diff