MDL-18552 TeX filter - blacklist unsecure commands + protect texdebug ; backported from HEAD

This commit is contained in:
stronk7
2009-03-26 19:19:46 +00:00
parent 2a04f622fb
commit 899ccfe26f
2 changed files with 27 additions and 3 deletions
+23
View File
@@ -118,6 +118,16 @@ function tex_filter ($courseid, $text) {
$text = str_replace($matches[0][$i],$replacement,$text);
}
// TeX blacklist. MDL-18552
$tex_blacklist = array(
'include','def','command','loop','repeat','open','toks','output',
'input','catcode','name','^^',
'\every','\errhelp','\errorstopmode','\scrollmode','\nonstopmode',
'\batchmode','\read','\write','csname','\newhelp','\uppercase',
'\lowercase','\relax','\aftergroup',
'\afterassignment','\expandafter','\noexpand','\special'
);
// <tex> TeX expression </tex>
// or $$ TeX expression $$
// or \[ TeX expression \] // original tag of MathType and TeXaide (dlnsk)
@@ -138,6 +148,19 @@ function tex_filter ($courseid, $text) {
$align = "text-top";
$texexp = preg_replace('/^align=top /','',$texexp);
}
/// Check $texexp against blacklist (whitelisting could be more complete but also harder to maintain). MDL-18552
$invalidcommands = array();
foreach($tex_blacklist as $command) {
if (stristr($texexp, $command)) { /// Found invalid command. Annotate.
$invalidcommands[] = $command;
}
}
if (!empty($invalidcommands)) { /// Invalid commands found. Output error and continue with next TeX element
$invalidstr = get_string('invalidtexcommand', 'error', implode(', ', $invalidcommands));
$text = str_replace( $matches[0][$i], $invalidstr, $text);
continue;
}
/// Everything is ok, let's process the expression
$md5 = md5($texexp);
if (! $texcache = get_record("cache_filters","filter","tex", "md5key", $md5)) {
$texcache->filter = 'tex';
+4 -3
View File
@@ -1,10 +1,8 @@
<?PHP // $Id$
<?php // $Id$
// This function fetches math. images from the data directory
// If not, it obtains the corresponding TeX expression from the cache_tex db table
// and uses mimeTeX to create the image file
$nomoodlecookie = true; // Because it interferes with caching
require_once("../../config.php");
require( 'latex.php' );
@@ -24,6 +22,9 @@
$param->action = optional_param( 'action','',PARAM_ALPHA );
$param->tex = optional_param( 'tex','' );
require_login();
require_capability('moodle/site:config', get_context_instance(CONTEXT_SYSTEM), $USER->id); /// Required cap to run this. MDL-18552
$query = urldecode($_SERVER['QUERY_STRING']);
error_reporting(E_ALL);
$output = '';