Skip to main content

SafeMode

Enum SafeMode 

Source
pub enum SafeMode {
    Unsafe = 0,
    Safe = 1,
    Server = 10,
    Secure = 20,
}
Expand description

Describes the safe mode under which a document is parsed and rendered.

Safe modes provide a security model that controls how much a document is allowed to reach outside of itself. They mirror the safe modes defined by Ruby Asciidoctor, and the discriminant values are chosen so that the modes compare in order of increasing safety (Unsafe < Safe < Server < Secure). Features that could expose the host environment (for example, embedding the contents of a file directly in the output) are only enabled when the safe mode is below a threshold.

The default safe mode is SafeMode::Secure, matching the most conservative setting. A client may relax it via Parser::with_safe_mode.

§This crate performs no path-jail enforcement

Unlike Ruby Asciidoctor, this crate performs no filesystem I/O of its own. Reading include:: targets, images, and SVGs is delegated to the client via IncludeFileHandler, ImageFileHandler, and SvgFileHandler. As a consequence, the path-traversal jail that Ruby Asciidoctor applies through PathResolver#system_path – rejecting or clamping ../, absolute paths, file:// URIs, and symlinks that escape a jail root – is deliberately not ported (see PathResolver). Below Secure, the raw include/image/SVG target is handed to the client handler verbatim, with no traversal check and without communicating any jail boundary.

Enforcing a jail is therefore the client handler’s responsibility. A handler that resolves untrusted targets against the filesystem must itself reject ../, absolute paths, and file:// targets and resolve symlinks against its own jail root; the safe mode alone will not do this for it.

Variants§

§

Unsafe = 0

A safe mode level that disables any of the security features enforced by Asciidoctor (Ruby or otherwise). This mode is intended for use when the document is entirely trusted.

§

Safe = 1

In Ruby Asciidoctor, this level parallels Unsafe except that it prevents access to files which reside outside of the parent directory of the source file.

This crate does not enforce that jail. Because path resolution is delegated to the client handlers (see the type-level docs), Safe currently imposes no restriction beyond Unsafe: the include/image/SVG handlers are consulted and their contents embedded exactly as under Unsafe, and no ..//absolute/file:// traversal check is applied. Keeping untrusted targets inside a directory is the handler’s responsibility.

§

Server = 10

A safe mode level intended for server deployments (hence the name).

In this crate, Server masks host-revealing intrinsic attributes so they cannot leak into rendered output: docdir reads as empty, docfile is relativized against docdir, and user-home reads as . rather than the real home directory.

Server does not by itself disable include or asset embedding. Unlike what its name might suggest, at Server (and every level below Secure) the include/image/SVG handlers are consulted and file contents are embedded: include:: directives pull in file contents, data-uri images are base64-embedded, and inline/interactive SVGs are embedded. Disabling that embedding – and applying any path jail – happens only at Secure (for embedding) or in the client handler (for the jail). A server-side integrator that must not embed arbitrary file contents should use Secure, not Server.

§

Secure = 20

A safe mode level that disables the embedding of file contents into the output.

At Secure (and above), include:: directives are converted to links to their targets rather than embedding file contents, data-uri image embedding is disabled, inline and interactive SVGs render as ordinary <img> elements, and docinfo files are ignored. This is the level at which the include/image/SVG handlers stop being consulted for embedding.

This mode allows the AsciiDoc document to be processed in a shared, server-side environment, such as a wiki, where the document should not be able to embed the contents of arbitrary files. Note that Secure still enforces no path-traversal jail of its own (there is nothing left for a jail to guard, since embedding is off); a client that resolves targets against the filesystem at a lower safe mode must jail them itself (see the type-level docs).

This is the default safe mode.

Trait Implementations§

Source§

impl Clone for SafeMode

Source§

fn clone(&self) -> SafeMode

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for SafeMode

Source§

impl Debug for SafeMode

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for SafeMode

Source§

fn default() -> SafeMode

Returns the “default value” for a type. Read more
Source§

impl Eq for SafeMode

Source§

impl Hash for SafeMode

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for SafeMode

Source§

fn cmp(&self, other: &SafeMode) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

impl PartialEq for SafeMode

Source§

fn eq(&self, other: &SafeMode) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for SafeMode

Source§

fn partial_cmp(&self, other: &SafeMode) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for SafeMode

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.