parse.js 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296
  1. 'use strict';
  2. var utils = require('./utils');
  3. var has = Object.prototype.hasOwnProperty;
  4. var isArray = Array.isArray;
  5. var defaults = {
  6. allowDots: false,
  7. allowEmptyArrays: false,
  8. allowPrototypes: false,
  9. allowSparse: false,
  10. arrayLimit: 20,
  11. charset: 'utf-8',
  12. charsetSentinel: false,
  13. comma: false,
  14. decodeDotInKeys: false,
  15. decoder: utils.decode,
  16. delimiter: '&',
  17. depth: 5,
  18. duplicates: 'combine',
  19. ignoreQueryPrefix: false,
  20. interpretNumericEntities: false,
  21. parameterLimit: 1000,
  22. parseArrays: true,
  23. plainObjects: false,
  24. strictDepth: false,
  25. strictNullHandling: false
  26. };
  27. var interpretNumericEntities = function (str) {
  28. return str.replace(/&#(\d+);/g, function ($0, numberStr) {
  29. return String.fromCharCode(parseInt(numberStr, 10));
  30. });
  31. };
  32. var parseArrayValue = function (val, options) {
  33. if (val && typeof val === 'string' && options.comma && val.indexOf(',') > -1) {
  34. return val.split(',');
  35. }
  36. return val;
  37. };
  38. // This is what browsers will submit when the ✓ character occurs in an
  39. // application/x-www-form-urlencoded body and the encoding of the page containing
  40. // the form is iso-8859-1, or when the submitted form has an accept-charset
  41. // attribute of iso-8859-1. Presumably also with other charsets that do not contain
  42. // the ✓ character, such as us-ascii.
  43. var isoSentinel = 'utf8=%26%2310003%3B'; // encodeURIComponent('✓')
  44. // These are the percent-encoded utf-8 octets representing a checkmark, indicating that the request actually is utf-8 encoded.
  45. var charsetSentinel = 'utf8=%E2%9C%93'; // encodeURIComponent('✓')
  46. var parseValues = function parseQueryStringValues(str, options) {
  47. var obj = { __proto__: null };
  48. var cleanStr = options.ignoreQueryPrefix ? str.replace(/^\?/, '') : str;
  49. cleanStr = cleanStr.replace(/%5B/gi, '[').replace(/%5D/gi, ']');
  50. var limit = options.parameterLimit === Infinity ? undefined : options.parameterLimit;
  51. var parts = cleanStr.split(options.delimiter, limit);
  52. var skipIndex = -1; // Keep track of where the utf8 sentinel was found
  53. var i;
  54. var charset = options.charset;
  55. if (options.charsetSentinel) {
  56. for (i = 0; i < parts.length; ++i) {
  57. if (parts[i].indexOf('utf8=') === 0) {
  58. if (parts[i] === charsetSentinel) {
  59. charset = 'utf-8';
  60. } else if (parts[i] === isoSentinel) {
  61. charset = 'iso-8859-1';
  62. }
  63. skipIndex = i;
  64. i = parts.length; // The eslint settings do not allow break;
  65. }
  66. }
  67. }
  68. for (i = 0; i < parts.length; ++i) {
  69. if (i === skipIndex) {
  70. continue;
  71. }
  72. var part = parts[i];
  73. var bracketEqualsPos = part.indexOf(']=');
  74. var pos = bracketEqualsPos === -1 ? part.indexOf('=') : bracketEqualsPos + 1;
  75. var key, val;
  76. if (pos === -1) {
  77. key = options.decoder(part, defaults.decoder, charset, 'key');
  78. val = options.strictNullHandling ? null : '';
  79. } else {
  80. key = options.decoder(part.slice(0, pos), defaults.decoder, charset, 'key');
  81. val = utils.maybeMap(
  82. parseArrayValue(part.slice(pos + 1), options),
  83. function (encodedVal) {
  84. return options.decoder(encodedVal, defaults.decoder, charset, 'value');
  85. }
  86. );
  87. }
  88. if (val && options.interpretNumericEntities && charset === 'iso-8859-1') {
  89. val = interpretNumericEntities(val);
  90. }
  91. if (part.indexOf('[]=') > -1) {
  92. val = isArray(val) ? [val] : val;
  93. }
  94. var existing = has.call(obj, key);
  95. if (existing && options.duplicates === 'combine') {
  96. obj[key] = utils.combine(obj[key], val);
  97. } else if (!existing || options.duplicates === 'last') {
  98. obj[key] = val;
  99. }
  100. }
  101. return obj;
  102. };
  103. var parseObject = function (chain, val, options, valuesParsed) {
  104. var leaf = valuesParsed ? val : parseArrayValue(val, options);
  105. for (var i = chain.length - 1; i >= 0; --i) {
  106. var obj;
  107. var root = chain[i];
  108. if (root === '[]' && options.parseArrays) {
  109. obj = options.allowEmptyArrays && (leaf === '' || (options.strictNullHandling && leaf === null))
  110. ? []
  111. : [].concat(leaf);
  112. } else {
  113. obj = options.plainObjects ? Object.create(null) : {};
  114. var cleanRoot = root.charAt(0) === '[' && root.charAt(root.length - 1) === ']' ? root.slice(1, -1) : root;
  115. var decodedRoot = options.decodeDotInKeys ? cleanRoot.replace(/%2E/g, '.') : cleanRoot;
  116. var index = parseInt(decodedRoot, 10);
  117. if (!options.parseArrays && decodedRoot === '') {
  118. obj = { 0: leaf };
  119. } else if (
  120. !isNaN(index)
  121. && root !== decodedRoot
  122. && String(index) === decodedRoot
  123. && index >= 0
  124. && (options.parseArrays && index <= options.arrayLimit)
  125. ) {
  126. obj = [];
  127. obj[index] = leaf;
  128. } else if (decodedRoot !== '__proto__') {
  129. obj[decodedRoot] = leaf;
  130. }
  131. }
  132. leaf = obj;
  133. }
  134. return leaf;
  135. };
  136. var parseKeys = function parseQueryStringKeys(givenKey, val, options, valuesParsed) {
  137. if (!givenKey) {
  138. return;
  139. }
  140. // Transform dot notation to bracket notation
  141. var key = options.allowDots ? givenKey.replace(/\.([^.[]+)/g, '[$1]') : givenKey;
  142. // The regex chunks
  143. var brackets = /(\[[^[\]]*])/;
  144. var child = /(\[[^[\]]*])/g;
  145. // Get the parent
  146. var segment = options.depth > 0 && brackets.exec(key);
  147. var parent = segment ? key.slice(0, segment.index) : key;
  148. // Stash the parent if it exists
  149. var keys = [];
  150. if (parent) {
  151. // If we aren't using plain objects, optionally prefix keys that would overwrite object prototype properties
  152. if (!options.plainObjects && has.call(Object.prototype, parent)) {
  153. if (!options.allowPrototypes) {
  154. return;
  155. }
  156. }
  157. keys.push(parent);
  158. }
  159. // Loop through children appending to the array until we hit depth
  160. var i = 0;
  161. while (options.depth > 0 && (segment = child.exec(key)) !== null && i < options.depth) {
  162. i += 1;
  163. if (!options.plainObjects && has.call(Object.prototype, segment[1].slice(1, -1))) {
  164. if (!options.allowPrototypes) {
  165. return;
  166. }
  167. }
  168. keys.push(segment[1]);
  169. }
  170. // If there's a remainder, check strictDepth option for throw, else just add whatever is left
  171. if (segment) {
  172. if (options.strictDepth === true) {
  173. throw new RangeError('Input depth exceeded depth option of ' + options.depth + ' and strictDepth is true');
  174. }
  175. keys.push('[' + key.slice(segment.index) + ']');
  176. }
  177. return parseObject(keys, val, options, valuesParsed);
  178. };
  179. var normalizeParseOptions = function normalizeParseOptions(opts) {
  180. if (!opts) {
  181. return defaults;
  182. }
  183. if (typeof opts.allowEmptyArrays !== 'undefined' && typeof opts.allowEmptyArrays !== 'boolean') {
  184. throw new TypeError('`allowEmptyArrays` option can only be `true` or `false`, when provided');
  185. }
  186. if (typeof opts.decodeDotInKeys !== 'undefined' && typeof opts.decodeDotInKeys !== 'boolean') {
  187. throw new TypeError('`decodeDotInKeys` option can only be `true` or `false`, when provided');
  188. }
  189. if (opts.decoder !== null && typeof opts.decoder !== 'undefined' && typeof opts.decoder !== 'function') {
  190. throw new TypeError('Decoder has to be a function.');
  191. }
  192. if (typeof opts.charset !== 'undefined' && opts.charset !== 'utf-8' && opts.charset !== 'iso-8859-1') {
  193. throw new TypeError('The charset option must be either utf-8, iso-8859-1, or undefined');
  194. }
  195. var charset = typeof opts.charset === 'undefined' ? defaults.charset : opts.charset;
  196. var duplicates = typeof opts.duplicates === 'undefined' ? defaults.duplicates : opts.duplicates;
  197. if (duplicates !== 'combine' && duplicates !== 'first' && duplicates !== 'last') {
  198. throw new TypeError('The duplicates option must be either combine, first, or last');
  199. }
  200. var allowDots = typeof opts.allowDots === 'undefined' ? opts.decodeDotInKeys === true ? true : defaults.allowDots : !!opts.allowDots;
  201. return {
  202. allowDots: allowDots,
  203. allowEmptyArrays: typeof opts.allowEmptyArrays === 'boolean' ? !!opts.allowEmptyArrays : defaults.allowEmptyArrays,
  204. allowPrototypes: typeof opts.allowPrototypes === 'boolean' ? opts.allowPrototypes : defaults.allowPrototypes,
  205. allowSparse: typeof opts.allowSparse === 'boolean' ? opts.allowSparse : defaults.allowSparse,
  206. arrayLimit: typeof opts.arrayLimit === 'number' ? opts.arrayLimit : defaults.arrayLimit,
  207. charset: charset,
  208. charsetSentinel: typeof opts.charsetSentinel === 'boolean' ? opts.charsetSentinel : defaults.charsetSentinel,
  209. comma: typeof opts.comma === 'boolean' ? opts.comma : defaults.comma,
  210. decodeDotInKeys: typeof opts.decodeDotInKeys === 'boolean' ? opts.decodeDotInKeys : defaults.decodeDotInKeys,
  211. decoder: typeof opts.decoder === 'function' ? opts.decoder : defaults.decoder,
  212. delimiter: typeof opts.delimiter === 'string' || utils.isRegExp(opts.delimiter) ? opts.delimiter : defaults.delimiter,
  213. // eslint-disable-next-line no-implicit-coercion, no-extra-parens
  214. depth: (typeof opts.depth === 'number' || opts.depth === false) ? +opts.depth : defaults.depth,
  215. duplicates: duplicates,
  216. ignoreQueryPrefix: opts.ignoreQueryPrefix === true,
  217. interpretNumericEntities: typeof opts.interpretNumericEntities === 'boolean' ? opts.interpretNumericEntities : defaults.interpretNumericEntities,
  218. parameterLimit: typeof opts.parameterLimit === 'number' ? opts.parameterLimit : defaults.parameterLimit,
  219. parseArrays: opts.parseArrays !== false,
  220. plainObjects: typeof opts.plainObjects === 'boolean' ? opts.plainObjects : defaults.plainObjects,
  221. strictDepth: typeof opts.strictDepth === 'boolean' ? !!opts.strictDepth : defaults.strictDepth,
  222. strictNullHandling: typeof opts.strictNullHandling === 'boolean' ? opts.strictNullHandling : defaults.strictNullHandling
  223. };
  224. };
  225. module.exports = function (str, opts) {
  226. var options = normalizeParseOptions(opts);
  227. if (str === '' || str === null || typeof str === 'undefined') {
  228. return options.plainObjects ? Object.create(null) : {};
  229. }
  230. var tempObj = typeof str === 'string' ? parseValues(str, options) : str;
  231. var obj = options.plainObjects ? Object.create(null) : {};
  232. // Iterate over the keys and setup the new object
  233. var keys = Object.keys(tempObj);
  234. for (var i = 0; i < keys.length; ++i) {
  235. var key = keys[i];
  236. var newObj = parseKeys(key, tempObj[key], options, typeof str === 'string');
  237. obj = utils.merge(obj, newObj, options);
  238. }
  239. if (options.allowSparse === true) {
  240. return obj;
  241. }
  242. return utils.compact(obj);
  243. };