diff --git a/lib/moodlelib.php b/lib/moodlelib.php index d4ee49ec996..f31795fbf7c 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -1069,25 +1069,8 @@ function clean_param($param, $type) { case PARAM_HOST: // Allow FQDN or IPv4 dotted quad. - $param = preg_replace('/[^\.\d\w-]/', '', (string)$param ); - // Match ipv4 dotted quad. - if (preg_match('/(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})/', $param, $match)) { - // Confirm values are ok. - if ( $match[0] > 255 - || $match[1] > 255 - || $match[3] > 255 - || $match[4] > 255 ) { - // Hmmm, what kind of dotted quad is this? - $param = ''; - } - } else if ( preg_match('/^[\w\d\.-]+$/', $param) // Dots, hyphens, numbers. - && !preg_match('/^[\.-]/', $param) // No leading dots/hyphens. - && !preg_match('/[\.-]$/', $param) // No trailing dots/hyphens. - ) { - // All is ok - $param is respected. - } else { - // All is not ok... - $param=''; + if (!\core\ip_utils::is_domain_name($param) && !\core\ip_utils::is_ipv4_address($param)) { + $param = ''; } return $param; diff --git a/lib/tests/moodlelib_test.php b/lib/tests/moodlelib_test.php index 21c4e56b1c9..88adffbe898 100644 --- a/lib/tests/moodlelib_test.php +++ b/lib/tests/moodlelib_test.php @@ -646,6 +646,38 @@ class moodlelib_test extends \advanced_testcase { $this->assertSame('', clean_param(null, PARAM_TEXT)); } + /** + * Data provider for {@see test_clean_param_host} + * + * @return array + */ + public static function clean_param_host_provider(): array { + return [ + 'Valid (low octets)' => ['0.0.0.0', '0.0.0.0'], + 'Valid (high octets)' => ['255.255.255.255', '255.255.255.255'], + 'Invalid first octet' => ['256.1.1.1', ''], + 'Invalid second octet' => ['1.256.1.1', ''], + 'Invalid third octet' => ['1.1.256.1', ''], + 'Invalid fourth octet' => ['1.1.1.256', ''], + 'Valid host' => ['moodle.org', 'moodle.org'], + 'Invalid host' => ['.example.com', ''], + ]; + } + + /** + * Testing cleaning parameters with PARAM_HOST + * + * @param string $param + * @param string $expected + * + * @dataProvider clean_param_host_provider + * + * @covers \clean_param + */ + public function test_clean_param_host(string $param, string $expected): void { + $this->assertEquals($expected, clean_param($param, PARAM_HOST)); + } + public function test_clean_param_url() { // Test PARAM_URL and PARAM_LOCALURL a bit. // Valid URLs.