diff --git a/filter/tex/latex.php b/filter/tex/latex.php index d626a9f0bbf..a1966da6212 100644 --- a/filter/tex/latex.php +++ b/filter/tex/latex.php @@ -94,6 +94,7 @@ if (empty($pathlatex)) { return false; } + $pathlatex = escapeshellarg(trim($pathlatex, " '\"")); $doc = $this->construct_latex_document( $formula, $fontsize ); @@ -114,15 +115,15 @@ fclose( $fh ); // run latex on document - $command = "{$pathlatex} --interaction=nonstopmode --halt-on-error $tex"; + $command = "$pathlatex --interaction=nonstopmode --halt-on-error $tex"; chdir( $this->temp_dir ); if ($this->execute($command, $log)) { // It allways False on Windows // return false; } // run dvips (.dvi to .ps) - $pathdvips = get_config('filter_tex', 'pathdvips'); - $command = "{$pathdvips} -E $dvi -o $ps"; + $pathdvips = escapeshellarg(trim(get_config('filter_tex', 'pathdvips'), " '\"")); + $command = "$pathdvips -E $dvi -o $ps"; if ($this->execute($command, $log )) { return false; } @@ -134,11 +135,11 @@ $bg_opt = ""; } if ($convertformat == 'svg') { - $pathdvisvgm = get_config('filter_tex', 'pathdvisvgm'); - $command = "{$pathdvisvgm} -E $ps -o $img"; + $pathdvisvgm = escapeshellarg(trim(get_config('filter_tex', 'pathdvisvgm'), " '\"")); + $command = "$pathdvisvgm -E $ps -o $img"; } else { - $pathconvert = get_config('filter_tex', 'pathconvert'); - $command = "{$pathconvert} -density $density -trim $bg_opt $ps $img"; + $pathconvert = escapeshellarg(trim(get_config('filter_tex', 'pathconvert'), " '\"")); + $command = "$pathconvert -density $density -trim $bg_opt $ps $img"; } if ($this->execute($command, $log )) { return false; diff --git a/filter/tex/lib.php b/filter/tex/lib.php index f48bca8aa31..4aad3ec543f 100644 --- a/filter/tex/lib.php +++ b/filter/tex/lib.php @@ -125,9 +125,10 @@ function filter_tex_updatedcallback($name) { return; } - $pathdvips = get_config('filter_tex', 'pathdvips'); - $pathconvert = get_config('filter_tex', 'pathconvert'); - $pathdvisvgm = get_config('filter_tex', 'pathdvisvgm'); + $pathlatex = trim($pathlatex, " '\""); + $pathdvips = trim(get_config('filter_tex', 'pathdvips'), " '\""); + $pathconvert = trim(get_config('filter_tex', 'pathconvert'), " '\""); + $pathdvisvgm = trim(get_config('filter_tex', 'pathdvisvgm'), " '\""); $supportedformats = array('gif'); if ((is_file($pathlatex) && is_executable($pathlatex)) && diff --git a/filter/tex/settings.php b/filter/tex/settings.php index fb0fcdfff4a..e0d5ddce68f 100644 --- a/filter/tex/settings.php +++ b/filter/tex/settings.php @@ -55,9 +55,22 @@ if ($ADMIN->fulltree) { } else if (PHP_OS=='WINNT' or PHP_OS=='WIN32' or PHP_OS=='Windows') { // note: you need Ghostscript installed (standard), miktex (standard) // and ImageMagick (install at c:\ImageMagick) - $default_filter_tex_pathlatex = "\"c:\\texmf\\miktex\\bin\\latex.exe\" "; - $default_filter_tex_pathdvips = "\"c:\\texmf\\miktex\\bin\\dvips.exe\" "; - $default_filter_tex_pathconvert = "\"c:\\imagemagick\\convert.exe\" "; + $default_filter_tex_pathlatex = "c:\\texmf\\miktex\\bin\\latex.exe"; + $default_filter_tex_pathdvips = "c:\\texmf\\miktex\\bin\\dvips.exe"; + $default_filter_tex_pathdvisvgm = "c:\\texmf\\miktex\\bin\\dvisvgm.exe"; + $default_filter_tex_pathconvert = "c:\\imagemagick\\convert.exe"; + } + + $pathlatex = get_config('filter_tex', 'pathlatex'); + $pathdvips = get_config('filter_tex', 'pathdvips'); + $pathconvert = get_config('filter_tex', 'pathconvert'); + $pathdvisvgm = get_config('filter_tex', 'pathdvisvgm'); + if (strrpos($pathlatex . $pathdvips . $pathconvert . $pathdvisvgm, '"') or + strrpos($pathlatex . $pathdvips . $pathconvert . $pathdvisvgm, "'")) { + set_config('pathlatex', trim($pathlatex, " '\""), 'filter_tex'); + set_config('pathdvips', trim($pathdvips, " '\""), 'filter_tex'); + set_config('pathconvert', trim($pathconvert, " '\""), 'filter_tex'); + set_config('pathdvisvgm', trim($pathdvisvgm, " '\""), 'filter_tex'); } $items[] = new admin_setting_configexecutable('filter_tex/pathlatex', get_string('pathlatex', 'filter_tex'), '', $default_filter_tex_pathlatex); diff --git a/filter/tex/texdebug.php b/filter/tex/texdebug.php index b82e97c1817..ad28cbc24f7 100644 --- a/filter/tex/texdebug.php +++ b/filter/tex/texdebug.php @@ -200,28 +200,28 @@ // first check if it is likely to work at all $output .= "

Checking executables

\n"; $executablesexist = true; - $pathlatex = get_config('filter_tex', 'pathlatex'); + $pathlatex = trim(get_config('filter_tex', 'pathlatex'), " '\""); if (is_file($pathlatex)) { $output .= "latex executable ($pathlatex) is readable
\n"; } else { $executablesexist = false; $output .= "Error: latex executable ($pathlatex) is not readable
\n"; } - $pathdvips = get_config('filter_tex', 'pathdvips'); + $pathdvips = trim(get_config('filter_tex', 'pathdvips'), " '\""); if (is_file($pathdvips)) { $output .= "dvips executable ($pathdvips) is readable
\n"; } else { $executablesexist = false; $output .= "Error: dvips executable ($pathdvips) is not readable
\n"; } - $pathconvert = get_config('filter_tex', 'pathconvert'); + $pathconvert = trim(get_config('filter_tex', 'pathconvert'), " '\""); if (is_file($pathconvert)) { $output .= "convert executable ($pathconvert) is readable
\n"; } else { $executablesexist = false; $output .= "Error: convert executable ($pathconvert) is not readable
\n"; } - $pathdvisvgm = get_config('filter_tex', 'pathdvisvgm'); + $pathdvisvgm = trim(get_config('filter_tex', 'pathdvisvgm'), " '\""); if (is_file($pathdvisvgm)) { $output .= "dvisvgm executable ($pathdvisvgm) is readable
\n"; } else { @@ -252,17 +252,21 @@ chdir($latex->temp_dir); // step 1: latex command + $pathlatex = escapeshellarg($pathlatex); $cmd = "$pathlatex --interaction=nonstopmode --halt-on-error $tex"; $output .= execute($cmd); // step 2: dvips command + $pathdvips = escapeshellarg($pathdvips); $cmd = "$pathdvips -E $dvi -o $ps"; $output .= execute($cmd); // Step 3: Set convert or dvisvgm command. if ($convertformat == 'svg') { + $pathdvisvgm = escapeshellarg($pathdvisvgm); $cmd = "$pathdvisvgm -E $ps -o $img"; } else { + $pathconvert = escapeshellarg($pathconvert); $cmd = "$pathconvert -density 240 -trim $ps $img "; } $output .= execute($cmd);