mirror of
https://github.com/gin-gonic/gin.git
synced 2026-09-04 14:49:27 +08:00
AsciiJSON used fmt.Appendf with "\u%04x" to escape all non-ASCII runes. For code points above U+FFFF the format produces a 5+ digit sequence (e.g. ὠ0 for U+1F600), which is syntactically valid JSON but wrong: a JSON \u escape is exactly 4 hex digits, so decoders interpret the 5th digit as literal text and the recovered string is silently corrupted. Per RFC 8259 section 7, code points above U+FFFF must be encoded as a UTF-16 surrogate pair (\uD800-\uDBFF followed by \uDC00-\uDFFF). Use unicode/utf16.EncodeRune to compute the pair and emit two \uXXXX escapes. Add TestRenderAsciiJSONNonBMP to verify that emoji and other non-BMP characters survive an AsciiJSON -> json.Unmarshal round-trip unchanged. Fixes #4688 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
205 lines
5.4 KiB
Go
205 lines
5.4 KiB
Go
// Copyright 2014 Manu Martinez-Almeida. All rights reserved.
|
||
// Use of this source code is governed by a MIT style
|
||
// license that can be found in the LICENSE file.
|
||
|
||
package render
|
||
|
||
import (
|
||
"bytes"
|
||
"fmt"
|
||
"html/template"
|
||
"net/http"
|
||
"unicode"
|
||
"unicode/utf16"
|
||
|
||
"github.com/gin-gonic/gin/codec/json"
|
||
"github.com/gin-gonic/gin/internal/bytesconv"
|
||
)
|
||
|
||
// JSON contains the given interface object.
|
||
type JSON struct {
|
||
Data any
|
||
}
|
||
|
||
// IndentedJSON contains the given interface object.
|
||
type IndentedJSON struct {
|
||
Data any
|
||
}
|
||
|
||
// SecureJSON contains the given interface object and its prefix.
|
||
type SecureJSON struct {
|
||
Prefix string
|
||
Data any
|
||
}
|
||
|
||
// JsonpJSON contains the given interface object its callback.
|
||
type JsonpJSON struct {
|
||
Callback string
|
||
Data any
|
||
}
|
||
|
||
// AsciiJSON contains the given interface object.
|
||
type AsciiJSON struct {
|
||
Data any
|
||
}
|
||
|
||
// PureJSON contains the given interface object.
|
||
type PureJSON struct {
|
||
Data any
|
||
}
|
||
|
||
var (
|
||
jsonContentType = []string{"application/json; charset=utf-8"}
|
||
jsonpContentType = []string{"application/javascript; charset=utf-8"}
|
||
jsonASCIIContentType = []string{"application/json"}
|
||
)
|
||
|
||
// Render (JSON) writes data with custom ContentType.
|
||
func (r JSON) Render(w http.ResponseWriter) error {
|
||
return WriteJSON(w, r.Data)
|
||
}
|
||
|
||
// WriteContentType (JSON) writes JSON ContentType.
|
||
func (r JSON) WriteContentType(w http.ResponseWriter) {
|
||
writeContentType(w, jsonContentType)
|
||
}
|
||
|
||
// WriteJSON marshals the given interface object and writes it with custom ContentType.
|
||
func WriteJSON(w http.ResponseWriter, obj any) error {
|
||
writeContentType(w, jsonContentType)
|
||
jsonBytes, err := json.API.Marshal(obj)
|
||
if err != nil {
|
||
return err
|
||
}
|
||
_, err = w.Write(jsonBytes)
|
||
return err
|
||
}
|
||
|
||
// Render (IndentedJSON) marshals the given interface object and writes it with custom ContentType.
|
||
func (r IndentedJSON) Render(w http.ResponseWriter) error {
|
||
r.WriteContentType(w)
|
||
jsonBytes, err := json.API.MarshalIndent(r.Data, "", " ")
|
||
if err != nil {
|
||
return err
|
||
}
|
||
_, err = w.Write(jsonBytes)
|
||
return err
|
||
}
|
||
|
||
// WriteContentType (IndentedJSON) writes JSON ContentType.
|
||
func (r IndentedJSON) WriteContentType(w http.ResponseWriter) {
|
||
writeContentType(w, jsonContentType)
|
||
}
|
||
|
||
// Render (SecureJSON) marshals the given interface object and writes it with custom ContentType.
|
||
func (r SecureJSON) Render(w http.ResponseWriter) error {
|
||
r.WriteContentType(w)
|
||
jsonBytes, err := json.API.Marshal(r.Data)
|
||
if err != nil {
|
||
return err
|
||
}
|
||
// if the jsonBytes is array values
|
||
if bytes.HasPrefix(jsonBytes, bytesconv.StringToBytes("[")) && bytes.HasSuffix(jsonBytes,
|
||
bytesconv.StringToBytes("]")) {
|
||
if _, err = w.Write(bytesconv.StringToBytes(r.Prefix)); err != nil {
|
||
return err
|
||
}
|
||
}
|
||
_, err = w.Write(jsonBytes)
|
||
return err
|
||
}
|
||
|
||
// WriteContentType (SecureJSON) writes JSON ContentType.
|
||
func (r SecureJSON) WriteContentType(w http.ResponseWriter) {
|
||
writeContentType(w, jsonContentType)
|
||
}
|
||
|
||
// Render (JsonpJSON) marshals the given interface object and writes it and its callback with custom ContentType.
|
||
func (r JsonpJSON) Render(w http.ResponseWriter) (err error) {
|
||
r.WriteContentType(w)
|
||
ret, err := json.API.Marshal(r.Data)
|
||
if err != nil {
|
||
return err
|
||
}
|
||
|
||
if r.Callback == "" {
|
||
_, err = w.Write(ret)
|
||
return err
|
||
}
|
||
|
||
callback := template.JSEscapeString(r.Callback)
|
||
if _, err = w.Write(bytesconv.StringToBytes(callback)); err != nil {
|
||
return err
|
||
}
|
||
|
||
if _, err = w.Write(bytesconv.StringToBytes("(")); err != nil {
|
||
return err
|
||
}
|
||
|
||
if _, err = w.Write(ret); err != nil {
|
||
return err
|
||
}
|
||
|
||
if _, err = w.Write(bytesconv.StringToBytes(");")); err != nil {
|
||
return err
|
||
}
|
||
|
||
return nil
|
||
}
|
||
|
||
// WriteContentType (JsonpJSON) writes Javascript ContentType.
|
||
func (r JsonpJSON) WriteContentType(w http.ResponseWriter) {
|
||
writeContentType(w, jsonpContentType)
|
||
}
|
||
|
||
// Render (AsciiJSON) marshals the given interface object and writes it with custom ContentType.
|
||
func (r AsciiJSON) Render(w http.ResponseWriter) error {
|
||
r.WriteContentType(w)
|
||
ret, err := json.API.Marshal(r.Data)
|
||
if err != nil {
|
||
return err
|
||
}
|
||
|
||
var buffer bytes.Buffer
|
||
escapeBuf := make([]byte, 0, 13) // Preallocate for worst case: two \uXXXX surrogate pair escapes
|
||
|
||
for _, r := range bytesconv.BytesToString(ret) {
|
||
if r > unicode.MaxASCII {
|
||
if r > 0xFFFF {
|
||
// Non-BMP character (above U+FFFF): encode as a UTF-16 surrogate pair.
|
||
// A JSON \u escape is exactly 4 hex digits, so code points requiring more
|
||
// than 4 digits must be split into a high/low surrogate pair per RFC 8259 §7.
|
||
high, low := utf16.EncodeRune(r)
|
||
escapeBuf = fmt.Appendf(escapeBuf[:0], "\\u%04x\\u%04x", high, low)
|
||
} else {
|
||
// BMP character (U+0080–U+FFFF): a single \uXXXX escape suffices.
|
||
escapeBuf = fmt.Appendf(escapeBuf[:0], "\\u%04x", r)
|
||
}
|
||
buffer.Write(escapeBuf)
|
||
} else {
|
||
buffer.WriteByte(byte(r))
|
||
}
|
||
}
|
||
|
||
_, err = w.Write(buffer.Bytes())
|
||
return err
|
||
}
|
||
|
||
// WriteContentType (AsciiJSON) writes JSON ContentType.
|
||
func (r AsciiJSON) WriteContentType(w http.ResponseWriter) {
|
||
writeContentType(w, jsonASCIIContentType)
|
||
}
|
||
|
||
// Render (PureJSON) writes custom ContentType and encodes the given interface object.
|
||
func (r PureJSON) Render(w http.ResponseWriter) error {
|
||
r.WriteContentType(w)
|
||
encoder := json.API.NewEncoder(w)
|
||
encoder.SetEscapeHTML(false)
|
||
return encoder.Encode(r.Data)
|
||
}
|
||
|
||
// WriteContentType (PureJSON) writes custom ContentType.
|
||
func (r PureJSON) WriteContentType(w http.ResponseWriter) {
|
||
writeContentType(w, jsonContentType)
|
||
}
|