StyleBookで特殊文字をリテラル形式で許可する
StyleBookの定義では、文字列内の特殊文字をリテラル形式で扱う必要がある場合に、逐語的な文字列を使用できます。これらの文字列には、エスケープ文字、バックスラッシュ、引用符、括弧、空白、角括弧などが含まれます。
StyleBookでは、逐語的な文字列を使用してNetScalerポリシー式をリテラル形式で含めることができます。ポリシー式には通常、特殊文字が含まれています。逐語的な文字列を使用しない場合、文字列を部分文字列に分割して特殊文字をエスケープする必要があります。
逐語的な文字列を作成するには、次のように特殊文字の間に文字列をカプセル化します。
~{string}~
StyleBook式で逐語的な文字列を使用できます。
注
入力文字列で文字シーケンス }~ を使用しないでください。このシーケンスは逐語的な文字列の終わりを示すためです。
例:
---
name: test-deny-url
namespace: citrix.adc.stylebooks
version: "6.2"
display-name: StyleBook for creating an AppFw profile
description: This Stylebook configures an AppFw config.
schema-version: "1.0"
import-stylebooks:
-
namespace: netscaler.nitro.config
prefix: ns
version: "13.0"
parameters:
-
name: name
type: string
required: true
substitutions:
default-deny-urls-regex:
"Command_injection_attack": str("([ /=]|\\t|\\n)(ls|cat)([ ;'" + "\\\"&].*)?$")
"Command_injection_attack2": ~{([ /=]|\t|\n)(ls|rm|cat)([ ;'\"&].*)?$}~
components:
-
name: appfw-profile-comp
type: ns::appfwprofile
properties:
name: $parameters.name
type: ["XML"]
components:
-
name: appfw-profile-denyurl-default-binding-subcomp-all
type: ns::appfwprofile_denyurl_binding
properties:
name: $parent.properties.name
denyurl?: $substitutions.default-deny-urls-regex["Command_injection_attack"]
state?: "ENABLED"
-
name: appfw-profile-denyurl-default-binding-subcomp-all2
type: ns::appfwprofile_denyurl_binding
properties:
name: $parent.properties.name
denyurl?: $substitutions.default-deny-urls-regex["Command_injection_attack2"]
state?: "ENABLED"
この例では、
default-deny-urls-regex の置換は逐語的な式を持っています。
-
"Command_injection_attack": str("([ /=]|\\t|\\n)(ls|cat)([ ;'" + "\\\"&].*)?$"): StyleBookはこれを正規表現として処理します。 -
"Command_injection_attack2": ~{([ /=]|\t|\n)(ls|rm|cat)([ ;'\"&].*)?$}~: StyleBookはこれを逐語的な式として処理します。この文字列内の特殊文字はリテラル形式になります。
複数の逐語的な文字列を連結する
逐語的な文字列を通常の文字列や補間を含む文字列と連結できます。その際、StyleBookは逐語的な文字列のみ解釈をスキップします。文字列間にプラス (+) 演算子を使用して連結します。
例:
value: "~{\"id\": \"}~ + %{$atom.key}% + ~{\", \"value\": \"}~ + %{$atom.value}% + ~{\"}~"
この例では、
%{$atom.key}% と %{$atom.value}% が解釈されます。そして、残りの解釈はスキップされます。