Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
61 changes: 5 additions & 56 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,75 +4,24 @@ All notable changes to this project will be documented in this file. Dates are d

Generated by [`auto-changelog`](https://github.com/CookPete/auto-changelog).

#### [2.10.0](https://github.com/rdkcentral/javascript-templates/compare/2.9.0...2.10.0)

- Merge tag '2.9.0' into develop [`3556799`](https://github.com/rdkcentral/javascript-templates/commit/3556799ffd5f73068b6808fecfcb85bebb3a3e04)

#### [2.9.0](https://github.com/rdkcentral/javascript-templates/compare/2.8.0...2.9.0)

> 21 August 2026
#### 2.10.1

- RDKB-66901 : Updated parsers in GET, POST, and file metadata [`#45`](https://github.com/rdkcentral/javascript-templates/pull/45)
- RDKB-66802 : harden session lifecycle and cookie scope [`#44`](https://github.com/rdkcentral/javascript-templates/pull/44)
- RDKB-65595 : [Risk-Critical] JST (Generic) Security Fuzzing Report [`#34`](https://github.com/rdkcentral/javascript-templates/pull/34)
- RDKB-66532 RDKB-66534 : Validate session ID format before handling [`#36`](https://github.com/rdkcentral/javascript-templates/pull/36)
- RDKB-65597 : [Risk-High] JST (Generic) Security Fuzzing Report [`#35`](https://github.com/rdkcentral/javascript-templates/pull/35)
- RDKB-66116 : use freedesktop dbus-1.14 and gate native-build/CodeQL by source paths [`#31`](https://github.com/rdkcentral/javascript-templates/pull/31)
- Add changelog for release 2.9.0 [`664c13e`](https://github.com/rdkcentral/javascript-templates/commit/664c13e2f971516443bca4f3c0aa9c3c01daddf6)

#### [2.8.0](https://github.com/rdkcentral/javascript-templates/compare/2.3.0...2.8.0)

> 22 July 2026

- Merge tag '2.3.0' into develop [`f0478c8`](https://github.com/rdkcentral/javascript-templates/commit/f0478c8b644c4feb6f322abc556f527d562ebd58)

#### [2.3.0](https://github.com/rdkcentral/javascript-templates/compare/2.2.0...2.3.0)

> 22 July 2026

- RDKB-66032 : Add PR Format Check workflow [`#29`](https://github.com/rdkcentral/javascript-templates/pull/29)
- RDKB-64641 sets post_data = NULL to keep getPost() unset for file-only multipart bodies [`#27`](https://github.com/rdkcentral/javascript-templates/pull/27)
- RDKB-64256 fix OOB access in log_syntax_error for malformed include parsing [`#26`](https://github.com/rdkcentral/javascript-templates/pull/26)
- RDKB-65677 eliminate session_create leaks and strengthen regression coverage [`#24`](https://github.com/rdkcentral/javascript-templates/pull/24)
- Add changelog for release 2.3.0 [`6d3c2ca`](https://github.com/rdkcentral/javascript-templates/commit/6d3c2ca36a06cc878c9b125b4053dd66d4be3f25)
- Merge tag '2.2.0' into develop [`d73972d`](https://github.com/rdkcentral/javascript-templates/commit/d73972dcf3281b29682f4561a32904d0eb9611dc)

#### [2.2.0](https://github.com/rdkcentral/javascript-templates/compare/2.1.0...2.2.0)

> 15 June 2026

- RDKB-65466 : sso validation token [`#19`](https://github.com/rdkcentral/javascript-templates/pull/19)
- Add changelog for release 2.2.0 [`7323c07`](https://github.com/rdkcentral/javascript-templates/commit/7323c0772b5f6c7f573093bbeca0f4b65bb1e1ef)
- Merge tag '2.1.0' into develop [`6246ada`](https://github.com/rdkcentral/javascript-templates/commit/6246adaaa950bded6b962e748c7f4058285f0a6f)

#### [2.1.0](https://github.com/rdkcentral/javascript-templates/compare/2.0.0...2.1.0)

> 7 May 2026

- RDKB-63696 CMXB7-6329 CPU & Load average spike and jst crash during stability test [`#15`](https://github.com/rdkcentral/javascript-templates/pull/15)
- Add changelog for release 2.1.0 [`32e56da`](https://github.com/rdkcentral/javascript-templates/commit/32e56da5db64fa93f399f27867a83cccdcabf1ac)
- Merge tag '2.0.0' into develop [`591bc95`](https://github.com/rdkcentral/javascript-templates/commit/591bc9532ad335d4ed3a3e7b962854f8c63263e8)

### [2.0.0](https://github.com/rdkcentral/javascript-templates/compare/1.0.1...2.0.0)

> 4 March 2026

- RDKB-63154 RDKB-63013 Native Build Integration [`#10`](https://github.com/rdkcentral/javascript-templates/pull/10)
- Deploy fossid_integration_stateless_diffscan_target_repo action [`#9`](https://github.com/rdkcentral/javascript-templates/pull/9)
- Deploy cla action [`#6`](https://github.com/rdkcentral/javascript-templates/pull/6)
- Add changelog for release 2.0.0 [`116a000`](https://github.com/rdkcentral/javascript-templates/commit/116a000a495ed2513bb60b33fb17f6547cf87ab7)
- Merge tag '1.0.1' into develop [`b57e33b`](https://github.com/rdkcentral/javascript-templates/commit/b57e33b30cde9886736a441e3d1be158759a0f5b)

#### [1.0.1](https://github.com/rdkcentral/javascript-templates/compare/1.0.0...1.0.1)

> 25 September 2025

- RDKB-61157: Something has screwed up error in PAM [`#3`](https://github.com/rdkcentral/javascript-templates/pull/3)
- Add changelog for release [`b058882`](https://github.com/rdkcentral/javascript-templates/commit/b058882f7d110e523432045dc1a8269758b54f93)
- Merge tag '1.0.0' into develop [`a26bae7`](https://github.com/rdkcentral/javascript-templates/commit/a26bae70b3b18068706c5ef590e8a19f29be90c8)

#### 1.0.0

> 7 August 2025

- Import of source (stable2) [`9977c8d`](https://github.com/rdkcentral/javascript-templates/commit/9977c8d13ee9d72a94fb592ba189b5b87aabc92e)
- Deploy cla action [`c23bce2`](https://github.com/rdkcentral/javascript-templates/commit/c23bce21ea9e67479a8e55534016ea333d733196)
- Deploy fossid_integration_stateless_diffscan_target_repo action [`bd39e65`](https://github.com/rdkcentral/javascript-templates/commit/bd39e65b785a83725041924be73fda403985ff9b)
- Add changelog for release 2.9.0 [`664c13e`](https://github.com/rdkcentral/javascript-templates/commit/664c13e2f971516443bca4f3c0aa9c3c01daddf6)
- Add changelog for release [`b058882`](https://github.com/rdkcentral/javascript-templates/commit/b058882f7d110e523432045dc1a8269758b54f93)
154 changes: 98 additions & 56 deletions jsts/jst_prefix.js
Original file line number Diff line number Diff line change
Expand Up @@ -89,69 +89,102 @@ var $_SERVER = new Proxy({}, {
var $_SESSION = {};
var $_jst_session = null;
var $_val_input = {};
function session_start()
function _jst_session_cookie()
{
if($_jst_session)
return;
if($_val_input == 1)
{
$_val_input = 0;
return;
}
ccsp_session.start();
var host = getenv('HTTPS');
if (host == false)
var $cookie = "Set-Cookie: DUKSID=" + ccsp_session.getId() + "; httponly";
else
var $cookie = "Set-Cookie: DUKSID=" + ccsp_session.getId() + "; secure" + "; httponly";
header($cookie);
$_jst_session = ccsp_session.getData();
$_SESSION = new Proxy($_jst_session, {
var $cookie = "Set-Cookie: DUKSID=" + ccsp_session.getId() + "; httponly";
if(ccsp_session.isSecure())
$cookie += "; secure";
return $cookie;
}
function _jst_expire_session_cookie()
{
var $cookie = "Set-Cookie: DUKSID=; Max-Age=0; httponly";
if(ccsp_session.isSecure())
$cookie += "; secure";
return $cookie;
}
function _jst_session_is_current($session_id)
{
if(!ccsp_session.getStatus() || ccsp_session.getId() !== $session_id)
return false;

if(ccsp_session.start() && ccsp_session.getId() === $session_id)
return true;

$_jst_session = null;
$_SESSION = {};
return false;
}
function _jst_session_proxy($session)
{
var $session_id = ccsp_session.getId();
return new Proxy($session, {
get: function(obj, prop) {
return obj[prop];
},
set: function(obj, prop, val){
obj[prop] = val;
ccsp_session.setData(obj);
if(_jst_session_is_current($session_id))
ccsp_session.setData(obj);
return true;
},
deleteProperty(obj, prop) {
if(prop in obj)
{
delete obj[prop];
ccsp_session.setData(obj);
if(_jst_session_is_current($session_id))
ccsp_session.setData(obj);
}
return true;
}
});
}
function session_start()
{
if($_jst_session)
{
if(ccsp_session.start())
return true;

$_jst_session = null;
$_SESSION = {};
return false;
}
if($_val_input == 1)
{
$_val_input = 0;
return false;
}
if(!ccsp_session.start())
{
/* A stale cookie must not create a proxy backed by an inactive session. */
$_jst_session = null;
$_SESSION = {};
return false;
}
if(ccsp_session.getStatus())
{
header(_jst_session_cookie());
}
$_jst_session = ccsp_session.getData();
if($_jst_session === null || typeof($_jst_session) !== 'object')
$_jst_session = {};
$_SESSION = _jst_session_proxy($_jst_session);
return true;
}
function session_create(){
ccsp_session.create();
var host = getenv('HTTPS');
if (host == false)
var $cookie = "Set-Cookie: DUKSID=" + ccsp_session.getId() + "; httponly";
else
var $cookie = "Set-Cookie: DUKSID=" + ccsp_session.getId() + "; secure" + "; httponly";
header($cookie);
if(!ccsp_session.create())
{
$_jst_session = null;
$_SESSION = {};
return false;
}
header(_jst_session_cookie());
$_jst_session = ccsp_session.getData();
$_SESSION = new Proxy($_jst_session, {
get: function(obj, prop) {
return obj[prop];
},
set: function(obj, prop, val){
obj[prop] = val;
ccsp_session.setData(obj);
return true;
},
deleteProperty(obj, prop) {
if(prop in obj)
{
delete obj[prop];
ccsp_session.setData(obj);
}
return true;
}
});
if($_jst_session === null || typeof($_jst_session) !== 'object')
$_jst_session = {};
$_SESSION = _jst_session_proxy($_jst_session);
return true;
}
function session_id()
{
Expand All @@ -163,14 +196,23 @@ function session_status()
}
function session_destroy()
{
header(_jst_expire_session_cookie());
delete $_jst_session;
$_jst_session = null;
delete $_SESSION;
$_SESSION = {};
return ccsp_session.destroy();
}
function session_unset()
{//FIXME
{
var $session_id = ccsp_session.getId();
if(!$_jst_session || !_jst_session_is_current($session_id))
return false;

for(var $key in $_jst_session)
delete $_jst_session[$key];

return ccsp_session.setData($_jst_session);
}
function session_print()
{
Expand All @@ -186,11 +228,11 @@ if(postData)
var postValues = postData.split('&');
for(var i = 0; i < postValues.length; ++i)
{
var postValue = postValues[i].split('=');
if(postValue.length == 2)
var eqIdx = postValues[i].indexOf('=');
if(eqIdx != -1)
{
var value = postValue[1].replace(/[+]/g," ");
$_POST[postValue[0]] = decodeURIComponent(value);
var value = postValues[i].substring(eqIdx + 1).replace(/[+]/g," ");
$_POST[postValues[i].substring(0, eqIdx)] = decodeURIComponent(value);
}
else
{
Expand All @@ -212,17 +254,17 @@ if(filesData)
var fileId = null;
for(var j = 0; j < fileData.length; ++j)
{
var fileValue = fileData[j].split('=');
if(fileValue.length == 2)
var eqIdx = fileData[j].indexOf('=');
if(eqIdx != -1)
{
if(!fileId)
{
fileId = decodeURIComponent(fileValue[1]);
fileId = decodeURIComponent(fileData[j].substring(eqIdx + 1));
$_FILES[fileId]={};
}
else
{
$_FILES[fileId][decodeURIComponent(fileValue[0])]=decodeURIComponent(fileValue[1]);
$_FILES[fileId][decodeURIComponent(fileData[j].substring(0, eqIdx))]=decodeURIComponent(fileData[j].substring(eqIdx + 1));
}
}
else
Expand All @@ -241,10 +283,10 @@ $_GET= (function ()
var ar = qs.split('&');
for(var i=0; i<ar.length; ++i)
{
var ar2 = ar[i].split('=');
if(ar2.length != 2)
var eqIdx = ar[i].indexOf('=');
if(eqIdx == -1)
throw Error("$_GET: Invalid QUERY_STRING");
out[ar2[0]] = ar2[1];
out[ar[i].substring(0, eqIdx)] = ar[i].substring(eqIdx + 1);
}
}
return out;
Expand Down
Loading
Loading