镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Buffer.from('base64') decodes some white space as data #11987

Description

@jorangreef

I am writing a native addon to decode a buffer containing base64 directly into another buffer, without requiring the allocation of an interim string (see #11866 for why Node cannot decode base64 buffers directly).

I wrote a fuzz test to test my own decoder, and then decided to try it out on Node's base64 decoder.

There are a few cases where Node's decoder treats whitespace as actual data, rather than ignoring it. This happens when the "=" is left out:

// Fails:
> Buffer.from("3v6YpUFyK0/hitA2tCDIfdYKw0 g ", 'base64').toString('binary')
'Þþ�¥Ar+Oá�Ð6´ È}Ö\nÃH>'
> Buffer.from("3v6YpUFyK0/hitA2tCDIfdYKw0g ", 'base64').toString('binary')
'Þþ�¥Ar+Oá�Ð6´ È}Ö\nÃH>'
> Buffer.from("3v6YpUFyK0/hitA2tCDIfdYKw0g\n", 'base64').toString('binary')
'Þþ�¥Ar+Oá�Ð6´ È}Ö\nÃH>'

// Passes:
> Buffer.from("3v6YpUFyK0/hitA2tCDIfdYKw0g=", 'base64').toString('binary')
'Þþ�¥Ar+Oá�Ð6´ È}Ö\nÃH'
> Buffer.from("3v6YpUFyK0/hitA2tCDIfdYKw0g", 'base64').toString('binary')
'Þþ�¥Ar+Oá�Ð6´ È}Ö\nÃH'

In the failing cases, Node's decoder has interpolated a ">".

Activity

  1. added
    bufferIssues and PRs related to the buffer subsystem.
    on Mar 22, 2017
  2. changed the title [-]Buffer.from('base64') decodes white space inconsistently[/-] [+]Buffer.from('base64') decodes some white space as data[/+] on Mar 22, 2017
  3. seishun commented on Mar 22, 2017

    @seishun
    Contributor

    I'm assuming Node.js doesn't throw on invalid base64 input for performance reasons. So it's basically "garbage in - garbage out".

  4. jorangreef commented on Mar 22, 2017

    @jorangreef
    ContributorAuthor

    I'm assuming Node.js doesn't throw on invalid base64 input for performance reasons.

    This is another issue, but there's technically no performance reason why Node's decoder could not throw on non-whitespace, non-alphabet characters. The current decoder can be upgraded without introducing any additional branching cost.

    So it's basically "garbage in - garbage out".

    You're saying the lack of "=" padding plus extra trailing space is illegal? Node's decoder is supposed to ignore white space. It's also supposed to handle the lack of "=" padding. None of that is illegal.

    atob() is generally pretty good at throwing on garbage or illegal data, and it has no problem on the same set.

    There's nothing too unusual about this kind of input either. Imagine a MIME message scenario where the sender never added base64 padding, and an intermediary mail transport added trailing white space.

  5. added a commit that references this issue on Apr 10, 2017
  6. added a commit that references this issue on Jul 19, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bufferIssues and PRs related to the buffer subsystem.confirmed-bugIssues and PRs for confirmed bugs.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions