MDL-11048 + MDL-11297 improved tag normalisation, more security

This commit is contained in:
skodak
2007-09-16 18:41:57 +00:00
parent 111e12615b
commit 4eb718d801
2 changed files with 14 additions and 34 deletions
+9 -1
View File
@@ -256,6 +256,11 @@ define ('BLOG_COURSE_LEVEL', 3);
define ('BLOG_SITE_LEVEL', 4);
define ('BLOG_GLOBAL_LEVEL', 5);
/**
* Tag constanst
*/
define('TAG_MAX_LENGTH', 50);
/// PARAMETER HANDLING ////////////////////////////////////////////////////
@@ -555,7 +560,10 @@ function clean_param($param, $type) {
$param = preg_replace("/[\\x{80}-\\x{bf}\\x{d7}\\x{f7}]/u", '', $param);
//cleanup the spaces
$param = preg_replace('/ +/', ' ', $param);
return trim($param);
$param = trim($param);
$textlib = new textlib();
return $textlib->substr($param, 0, TAG_MAX_LENGTH);
case PARAM_TAGLIST:
$tags = explode(',', $param);
+5 -33
View File
@@ -1,7 +1,6 @@
<?php
define('DEFAULT_TAG_TABLE_FIELDS', 'id, tagtype, name, rawname, flag');
define('MAX_TAG_LENGTH',50);
/**
* Creates tags
@@ -956,7 +955,7 @@ function tag_instance_table_cleanup() {
/**
* Function that normalizes a tag name
* Function that normalizes a list of tag names
*
* Ex: tag_normalize('bANAana') -> returns 'banana'
* tag_normalize('lots of spaces') -> returns 'lots of spaces'
@@ -969,40 +968,13 @@ function tag_instance_table_cleanup() {
*/
function tag_normalize($tag_names_csv, $lowercase=true) {
$tag_names_csv = clean_param($tag_names_csv, PARAM_TAGLIST);
$textlib = textlib_get_instance();
$tags = explode(',', $tag_names_csv);
if (sizeof($tags) > 1) {
foreach ($tags as $key => $tag) {
$tags[$key] = tag_normalize($tag);
}
return implode(',' , $tags);
}
// only one tag was passed
else {
if ($lowercase){
$value = moodle_strtolower($tag_names_csv);
}
else {
$value = $tag_names_csv;
}
//$value = preg_replace('|[^\w ]|i', '', strtolower(trim($tag_names_csv)));
$value = preg_replace('|[\,\!\@\#\$\%\^\&\*\(\)\-\+\=\~\`\\"\'\_.\[\]\{\}\:\;\?\´\^\\\/\<\>\|]|i', '', trim($value));
//removes excess white spaces
$value = preg_replace('/\s\s+/', ' ', $value);
return $textlib->substr($value,0,MAX_TAG_LENGTH);
if ($lowercase){
$tag_names_csv = moodle_strtolower($tag_names_csv);
}
return $tag_names_csv;
}
function tag_flag_inappropriate($tag_names_or_ids_csv){