diff --git a/lib/tests/weblib_test.php b/lib/tests/weblib_test.php index c5a75c80939..4ac75def743 100644 --- a/lib/tests/weblib_test.php +++ b/lib/tests/weblib_test.php @@ -179,8 +179,23 @@ class web_testcase extends advanced_testcase { } function test_out_as_local_url() { + global $CFG; + // Test http url. $url1 = new moodle_url('/lib/tests/weblib_test.php'); $this->assertEquals('/lib/tests/weblib_test.php', $url1->out_as_local_url()); + + // Test https url. + $httpswwwroot = str_replace("http://", "https://", $CFG->wwwroot); + $url2 = new moodle_url($httpswwwroot.'/login/profile.php'); + $this->assertEquals('/login/profile.php', $url2->out_as_local_url()); + + // Test http url matching wwwroot. + $url3 = new moodle_url($CFG->wwwroot); + $this->assertEquals('', $url3->out_as_local_url()); + + // Test http url matching wwwroot ending with slash (/). + $url3 = new moodle_url($CFG->wwwroot.'/'); + $this->assertEquals('/', $url3->out_as_local_url()); } /** @@ -192,6 +207,31 @@ class web_testcase extends advanced_testcase { $url2->out_as_local_url(); } + /** + * You should get error with modified url + * + * @expectedException coding_exception + * @return void + */ + public function test_modified_url_out_as_local_url_error() { + global $CFG; + + $modifiedurl = $CFG->wwwroot.'1'; + $url3 = new moodle_url($modifiedurl.'/login/profile.php'); + $url3->out_as_local_url(); + } + + /** + * Try get local url from external https url and you should get error + * + * @expectedException coding_exception + * @return void + */ + public function test_https_out_as_local_url_error() { + $url4 = new moodle_url('https://www.google.com/lib/tests/weblib_test.php'); + $url4->out_as_local_url(); + } + public function test_clean_text() { $text = "lala xx"; $this->assertEquals($text, clean_text($text, FORMAT_PLAIN)); diff --git a/lib/weblib.php b/lib/weblib.php index 500467bef06..6c8ebab4d45 100644 --- a/lib/weblib.php +++ b/lib/weblib.php @@ -747,12 +747,18 @@ class moodle_url { global $CFG; $url = $this->out($escaped, $overrideparams); + $httpswwwroot = str_replace("http://", "https://", $CFG->wwwroot); - if (strpos($url, $CFG->wwwroot) !== 0) { + // $url should be equal to wwwroot or httpswwwroot. If not then throw exception. + if (($url === $CFG->wwwroot) || (strpos($url, $CFG->wwwroot.'/') === 0)) { + $localurl = substr($url, strlen($CFG->wwwroot)); + return !empty($localurl) ? $localurl : ''; + } else if (($url === $httpswwwroot) || (strpos($url, $httpswwwroot.'/') === 0)) { + $localurl = substr($url, strlen($httpswwwroot)); + return !empty($localurl) ? $localurl : ''; + } else { throw new coding_exception('out_as_local_url called on a non-local URL'); } - - return str_replace($CFG->wwwroot, '', $url); } /**