+2
-12
@@ -978,18 +978,8 @@ function clean_param($param, $type) {
|
||||
return preg_replace('/[^a-zA-Z0-9_-]/i', '', $param);
|
||||
|
||||
case PARAM_SAFEPATH:
|
||||
// Replace MS \ separators.
|
||||
$param = str_replace('\\', '/', $param);
|
||||
// Remove any number of ../ to prevent path traversal.
|
||||
$param = preg_replace('/\.\.+\//', '', $param);
|
||||
// Remove everything not a-zA-Z0-9/:_- .
|
||||
$param = preg_replace('/[^a-zA-Z0-9\/:_-]/i', '', $param);
|
||||
// Remove leading slash.
|
||||
$param = ltrim($param, '/');
|
||||
if ($param === '.') {
|
||||
$param = '';
|
||||
}
|
||||
return $param;
|
||||
// Remove everything not a-zA-Z0-9/_- .
|
||||
return preg_replace('/[^a-zA-Z0-9\/_-]/i', '', $param);
|
||||
|
||||
case PARAM_FILE:
|
||||
// Strip all suspicious characters from filename.
|
||||
|
||||
@@ -839,40 +839,6 @@ class core_moodlelib_testcase extends advanced_testcase {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Provide some tested base url and expected results.
|
||||
*
|
||||
* @return array Array of tested base url and expected results.
|
||||
*/
|
||||
public function clean_param_safepath_provider(): array {
|
||||
return [
|
||||
// MS separator test.
|
||||
['c:\temp', 'c:/temp'],
|
||||
|
||||
// Leading slash test.
|
||||
['/tmp/', 'tmp/'],
|
||||
|
||||
// Path traversal test.
|
||||
['../../../../../etc/', 'etc/'],
|
||||
['../', ''],
|
||||
['.../...//', ''],
|
||||
['.', '']
|
||||
];
|
||||
}
|
||||
|
||||
/**
|
||||
* Test clean_param() method with PARAM_SAFEPATH type.
|
||||
*
|
||||
* @dataProvider clean_param_safepath_provider
|
||||
* @covers ::clean_param
|
||||
* @param string $path
|
||||
* @param string $expected
|
||||
*/
|
||||
public function test_clean_param_safepath(string $path, string $expected) {
|
||||
$result = clean_param($path, PARAM_SAFEPATH);
|
||||
$this->assertSame($expected, $result);
|
||||
}
|
||||
|
||||
public function test_validate_param() {
|
||||
try {
|
||||
$param = validate_param('11a', PARAM_INT);
|
||||
|
||||
Reference in New Issue
Block a user