diff --git a/lib/moodlelib.php b/lib/moodlelib.php index 0093959dd20..30937c360d1 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -597,7 +597,7 @@ function clean_param($param, $type) { return preg_replace('/[^a-zA-Z0-9\/_-]/i', '', $param); case PARAM_FILE: // Strip all suspicious characters from filename - $param = preg_replace('~[[:cntrl:]]|[&<>"`\|\':\\/]~u', '', $param); + $param = preg_replace('~[[:cntrl:]]|[&<>"`\|\':\\\\/]~u', '', $param); $param = preg_replace('~\.\.+~', '', $param); if ($param === '.') { $param = ''; diff --git a/lib/simpletest/testmoodlelib.php b/lib/simpletest/testmoodlelib.php index 627e86bc63e..80fdddb80c1 100644 --- a/lib/simpletest/testmoodlelib.php +++ b/lib/simpletest/testmoodlelib.php @@ -240,49 +240,37 @@ class moodlelib_test extends UnitTestCase { $this->assertEqual(optional_param('username', 'default_user', PARAM_CLEAN), 'default_user'); } - /** - * Used by {@link optional_param()} and {@link required_param()} to - * clean the variables and/or cast to specific types, based on - * an options field. - * - * $course->format = clean_param($course->format, PARAM_ALPHA); - * $selectedgrade_item = clean_param($selectedgrade_item, PARAM_CLEAN); - * - * - * @uses $CFG - * @uses PARAM_CLEAN - * @uses PARAM_INT - * @uses PARAM_INTEGER - * @uses PARAM_ALPHA - * @uses PARAM_ALPHANUM - * @uses PARAM_NOTAGS - * @uses PARAM_ALPHAEXT - * @uses PARAM_BOOL - * @uses PARAM_SAFEDIR - * @uses PARAM_FILE - * @uses PARAM_PATH - * @uses PARAM_HOST - * @uses PARAM_URL - * @uses PARAM_LOCALURL - * @uses PARAM_CLEANHTML - * @uses PARAM_SEQUENCE - * @uses PARAM_USERNAME - * @uses PARAM_STRINGID - * @param mixed $param the variable we are cleaning - * @param int $type expected format of param after cleaning. - * @return mixed - */ - function test_clean_param() { - global $CFG; - // Test unknown parameter type - - // Test Raw param + function test_clean_param_raw() { $this->assertEqual(clean_param('#()*#,9789\'".,<42897>assertEqual(clean_param('#()*#,9789\'".,<42897>assertEqual(clean_param('#()*#,9789\'".,<42897>assertEqual(clean_param('#()*#,9789\'".,<42897>assertEqual(clean_param('#()*#,9789\'".,<42897>assertEqual(clean_param('#()*#,9789\'".,<42897>assertEqual(clean_param('http://google.com/', PARAM_URL), 'http://google.com/'); $this->assertEqual(clean_param('http://some.very.long.and.silly.domain/with/a/path/', PARAM_URL), 'http://some.very.long.and.silly.domain/with/a/path/'); @@ -290,16 +278,34 @@ class moodlelib_test extends UnitTestCase { $this->assertEqual(clean_param('http://0.255.1.1/numericip.php', PARAM_URL), 'http://0.255.1.1/numericip.php'); $this->assertEqual(clean_param('/just/a/path', PARAM_URL), '/just/a/path'); $this->assertEqual(clean_param('funny:thing', PARAM_URL), ''); + } + function test_clean_param_localurl() { + global $CFG; $this->assertEqual(clean_param('http://google.com/', PARAM_LOCALURL), ''); $this->assertEqual(clean_param('http://some.very.long.and.silly.domain/with/a/path/', PARAM_LOCALURL), ''); $this->assertEqual(clean_param($CFG->wwwroot, PARAM_LOCALURL), $CFG->wwwroot); $this->assertEqual(clean_param('/just/a/path', PARAM_LOCALURL), '/just/a/path'); $this->assertEqual(clean_param('funny:thing', PARAM_LOCALURL), ''); $this->assertEqual(clean_param('course/view.php?id=3', PARAM_LOCALURL), 'course/view.php?id=3'); + } + function test_clean_param_file() { + $this->assertEqual(clean_param('correctfile.txt', PARAM_FILE), 'correctfile.txt'); + $this->assertEqual(clean_param('b\'ae.t"x|t', PARAM_FILE), 'badfile.txt'); + $this->assertEqual(clean_param('../parentdirfile.txt', PARAM_FILE), 'parentdirfile.txt'); + //The following behaviours have been maintained although they seem a little odd + $this->assertEqual(clean_param('funny:thing', PARAM_FILE), 'funnything'); + $this->assertEqual(clean_param('./currentdirfile.txt', PARAM_FILE), '.currentdirfile.txt'); + $this->assertEqual(clean_param('c:\temp\windowsfile.txt', PARAM_FILE), 'ctempwindowsfile.txt'); + $this->assertEqual(clean_param('/home/user/linuxfile.txt', PARAM_FILE), 'homeuserlinuxfile.txt'); + $this->assertEqual(clean_param('~/myfile.txt', PARAM_FILE), '~myfile.txt'); + } + + function test_clean_param_username() { + global $CFG; $currentstatus = $CFG->extendedusernamechars; - + // Run tests with extended character == FALSE; $CFG->extendedusernamechars = FALSE; $this->assertEqual(clean_param('johndoe123', PARAM_USERNAME), 'johndoe123' ); @@ -326,7 +332,9 @@ class moodlelib_test extends UnitTestCase { $this->assertEqual(clean_param('johndóé ', PARAM_USERNAME), 'johndóé'); $CFG->extendedusernamechars = $currentstatus; + } + function test_clean_param_stringid() { // Test string identifiers validation // valid strings: $this->assertEqual(clean_param('validstring', PARAM_STRINGID), 'validstring');