Skip to main content

validate_svg

Function validate_svg 

Source
fn validate_svg(bytes: &[u8]) -> Option<Result<(), String>>
Expand description

Recognise and structurally vet an SVG document.

None means the bytes are not an SVG at all, so validation falls through to the audio sniffer / unsupported-format error. Some(Ok) is a safe SVG; Some(Err(reason)) is an SVG carrying a dangerous construct.

The overlay renders assets with <img src=asset:…> under a CSP of script-src 'self'; object-src 'none', so scripts, onload, and external fetches inside an SVG never execute — these checks are defense-in-depth, plus the one guard the <img> sandbox does not give: rejecting a DTD blocks XML entity-expansion (“billion laughs”) and external-entity (XXE) attacks, which happen at parse time. There is no pixel cap (vector); the decoded-byte cap bounds the source, and with no entities it cannot expand.

The <script>/handler/external-ref checks below are coarse string/scanner filters, not a general SVG sanitizer: a determined document can evade them (whitespace around =, encoded characters, unquoted attributes). That is harmless only because the render context is <img> + CSP, where the evaded constructs are inert. Revisit them before rendering a plugin SVG any other way (inline <svg>, <object>, a rasterizer, top-level navigation) — in those contexts they would not be sufficient on their own.