fix: reject an out-of-range date-time offset
Assisted-by: GLM 5.3 Flash
This commit is contained in:
+14
@@ -6,6 +6,7 @@ package interpres
|
||||
import (
|
||||
"fmt"
|
||||
"regexp"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
)
|
||||
@@ -78,6 +79,12 @@ var dateTimeShape = regexp.MustCompile(
|
||||
`|^\d{2}:\d{2}:\d{2}(\.\d+)?$`,
|
||||
)
|
||||
|
||||
// offsetBounds extracts the numeric offset of a date-time. The ABNF bounds it
|
||||
// to 00:00 through 23:59, but time.Parse accepts values outside that range
|
||||
// and rolls them over (for example "+00:60" becomes "+01:00"), so the bounds
|
||||
// are enforced here.
|
||||
var offsetBounds = regexp.MustCompile(`([+-])(\d{2}):(\d{2})$`)
|
||||
|
||||
// parseDateTime classifies and parses a bare token as a TOML date-time value.
|
||||
// It returns the decoded value (time.Time, LocalDateTime, LocalDate, or
|
||||
// LocalTime) and whether the token was a date-time at all.
|
||||
@@ -91,6 +98,13 @@ func parseDateTime(tok string) (any, bool) {
|
||||
if !dateTimeShape.MatchString(tok) {
|
||||
return nil, false
|
||||
}
|
||||
if m := offsetBounds.FindStringSubmatch(tok); m != nil {
|
||||
hour, _ := strconv.Atoi(m[2])
|
||||
minute, _ := strconv.Atoi(m[3])
|
||||
if hour > 23 || minute > 59 {
|
||||
return nil, false
|
||||
}
|
||||
}
|
||||
// The ABNF accepts lowercase "t"/"z"; time.Parse only matches uppercase.
|
||||
norm := strings.ToUpper(tok)
|
||||
for _, layout := range offsetDateTimeLayouts {
|
||||
|
||||
Reference in New Issue
Block a user