Class FilenameUtils

java.lang.Object
org.apache.tika.io.FilenameUtils

public class FilenameUtils extends Object
  • Field Details

    • RESERVED_FILENAME_CHARACTERS

      public static final char[] RESERVED_FILENAME_CHARACTERS
      Reserved characters
  • Constructor Details

    • FilenameUtils

      public FilenameUtils()
  • Method Details

    • normalize

      public static String normalize(String name)
      Scans the given file name for reserved characters on different OSs and file systems and returns a sanitized version of the name with the reserved chars replaced by their hexadecimal value.

      For example why?.zip will be converted into why%3F.zip

      Parameters:
      name - the file name to be normalized - NOT NULL
      Returns:
      the normalized file name
      Throws:
      IllegalArgumentException - if name is null
    • getName

      public static String getName(String path)
      This is a duplication of the algorithm and functionality available in commons io FilenameUtils. If Java's File were able handle Windows file paths correctly in linux, we wouldn't need this.

      The goal of this is to get a filename from a path. The package parsers and some other embedded doc extractors could put anything into TikaCoreProperties.RESOURCE_NAME_KEY.

      If a careless client used that filename as if it were a filename and not a path when writing embedded files, bad things could happen. Consider: "../../../my_ppt.ppt".

      Consider using this in combination with normalize(String).

      Parameters:
      path - path to strip
      Returns:
      empty string or a filename, never null
    • getSuffixFromPath

      public static String getSuffixFromPath(String path)
      This includes the period, e.g. ".pdf". This requires that an extension contain only ascii alphanumerics and it requires that an extension length be 5 or less.
      Parameters:
      path -
      Returns:
      the suffix or an empty string if one could not be found
    • getSanitizedEmbeddedFileName

      public static String getSanitizedEmbeddedFileName(Metadata metadata, String defaultExtension, int maxLength)
    • getSanitizedEmbeddedFilePath

      public static String getSanitizedEmbeddedFilePath(Metadata metadata, String defaultExtension, int maxLength)
      This tries to sanitize dangerous user generated embedded file paths. If trusting these paths for writing files, users should run checks to make sure that the generated file path does not zipslip out of the target directory.
      Parameters:
      metadata -
      defaultExtension -
      maxLength -
      Returns:
    • resolveWithin

      public static Path resolveWithin(Path dir, String name) throws IOException
      Resolves name against dir and returns the result only if it stays within dir.

      The result is normalized before it is checked. This is the load-bearing step: without it, resolving a name such as ../x yields the literal path dir/../x, whose path elements still begin with dir, so the Path.startsWith(Path) check below would wrongly accept it. Normalizing first collapses the .. so the check sees the real location.

      Containment is tested with Path.startsWith(Path) (element by element) rather than by comparing path strings, so a sibling whose name merely shares a textual prefix with dir (for example /a/bc against /a/b) is correctly treated as being outside dir.

      Parameters:
      dir - the directory the resolved path must stay within
      name - the child name to resolve against dir; may contain relative segments such as ..
      Returns:
      the resolved, normalized path, guaranteed to start with the normalized dir
      Throws:
      IOException - if name resolves to a location outside dir
    • calculateExtension

      public static String calculateExtension(Metadata metadata, String defaultValue)
      Calculate the extension based on the HttpHeaders.CONTENT_TYPE value. On parse exception or null value, return the default value.
      Parameters:
      metadata -
      defaultValue -
      Returns:
      the extension based on the mime type, including the initial "."