diff --git a/filter/tex/filter.php b/filter/tex/filter.php index e8b0709e0bb..1c6d348a15d 100644 --- a/filter/tex/filter.php +++ b/filter/tex/filter.php @@ -118,6 +118,16 @@ function tex_filter ($courseid, $text) { $text = str_replace($matches[0][$i],$replacement,$text); } + // TeX blacklist. MDL-18552 + $tex_blacklist = array( + 'include','def','command','loop','repeat','open','toks','output', + 'input','catcode','name','^^', + '\every','\errhelp','\errorstopmode','\scrollmode','\nonstopmode', + '\batchmode','\read','\write','csname','\newhelp','\uppercase', + '\lowercase','\relax','\aftergroup', + '\afterassignment','\expandafter','\noexpand','\special' + ); + // TeX expression // or $$ TeX expression $$ // or \[ TeX expression \] // original tag of MathType and TeXaide (dlnsk) @@ -138,6 +148,19 @@ function tex_filter ($courseid, $text) { $align = "text-top"; $texexp = preg_replace('/^align=top /','',$texexp); } + /// Check $texexp against blacklist (whitelisting could be more complete but also harder to maintain). MDL-18552 + $invalidcommands = array(); + foreach($tex_blacklist as $command) { + if (stristr($texexp, $command)) { /// Found invalid command. Annotate. + $invalidcommands[] = $command; + } + } + if (!empty($invalidcommands)) { /// Invalid commands found. Output error and continue with next TeX element + $invalidstr = get_string('invalidtexcommand', 'error', implode(', ', $invalidcommands)); + $text = str_replace( $matches[0][$i], $invalidstr, $text); + continue; + } + /// Everything is ok, let's process the expression $md5 = md5($texexp); if (! $texcache = get_record("cache_filters","filter","tex", "md5key", $md5)) { $texcache->filter = 'tex'; diff --git a/filter/tex/texdebug.php b/filter/tex/texdebug.php index ce54e08b29e..569b0b4d962 100644 --- a/filter/tex/texdebug.php +++ b/filter/tex/texdebug.php @@ -1,10 +1,8 @@ -action = optional_param( 'action','',PARAM_ALPHA ); $param->tex = optional_param( 'tex','' ); + require_login(); + require_capability('moodle/site:config', get_context_instance(CONTEXT_SYSTEM), $USER->id); /// Required cap to run this. MDL-18552 + $query = urldecode($_SERVER['QUERY_STRING']); error_reporting(E_ALL); $output = '';