Browse Source

limit length of generated URI to 255 chars to prevent a DoS against the QR-Code dialog

0.8
Philip Kaufmann 13 years ago
parent
commit
b1a99c3a1f
  1. 12
      src/qt/qrcodedialog.cpp

12
src/qt/qrcodedialog.cpp

@ -35,6 +35,11 @@ QRCodeDialog::~QRCodeDialog() @@ -35,6 +35,11 @@ QRCodeDialog::~QRCodeDialog()
void QRCodeDialog::genCode()
{
QString uri = getURI();
if (uri != "")
{
ui->lblQRCode->setText("");
QRcode *code = QRcode_encodeString(uri.toUtf8().constData(), 0, QR_ECLEVEL_L, QR_MODE_8, 1);
myImage = QImage(code->width + 8, code->width + 8, QImage::Format_RGB32);
myImage.fill(0xffffff);
@ -49,6 +54,9 @@ void QRCodeDialog::genCode() @@ -49,6 +54,9 @@ void QRCodeDialog::genCode()
}
QRcode_free(code);
ui->lblQRCode->setPixmap(QPixmap::fromImage(myImage).scaled(300, 300));
}
else
ui->lblQRCode->setText(tr("Resulting URI too long, try to reduce the text for label / message."));
}
QString QRCodeDialog::getURI()
@ -81,7 +89,11 @@ QString QRCodeDialog::getURI() @@ -81,7 +89,11 @@ QString QRCodeDialog::getURI()
paramCount++;
}
// limit URI length to 255 chars, to prevent a DoS of the QR-Code dialog
if (ret.length() < 256)
return ret;
else
return QString("");
}
void QRCodeDialog::on_lnReqAmount_textChanged(const QString &arg1)

Loading…
Cancel
Save