MDL-56992 core_scss: Don't allow invalid files to be included

We allow only .scss files so allow files to be included only and only if they end in .scss and they exist on server under theme directory.
This commit is contained in:
Ankit Agarwal
2017-01-04 11:33:57 +00:00
committed by Dan Poltawski
parent 6528ec3505
commit a76b0b8b85
2 changed files with 135 additions and 0 deletions
+54
View File
@@ -98,4 +98,58 @@ class core_scss extends \Leafo\ScssPhp\Compiler {
return $this->compile($content);
}
/**
* Compile child; returns a value to halt execution
*
* @param array $child
* @param \Leafo\ScssPhp\Formatter\OutputBlock $out
*
* @return array|null
*/
protected function compileChild($child, \Leafo\ScssPhp\Formatter\OutputBlock $out) {
switch($child[0]) {
case \Leafo\ScssPhp\Type::T_SCSSPHP_IMPORT_ONCE:
case \Leafo\ScssPhp\Type::T_IMPORT:
list(, $rawpath) = $child;
$rawpath = $this->reduce($rawpath);
$path = $this->compileStringContent($rawpath);
if ($path = $this->findImport($path)) {
if ($this->is_valid_file($path)) {
return parent::compileChild($child, $out);
} else {
// Sneaky stuff, don't let non scss file in.
debugging("Can't import scss file - " . $path, DEBUG_DEVELOPER);
}
}
break;
default:
return parent::compileChild($child, $out);
}
}
/**
* Is the given file valid for import ?
*
* @param $path
* @return bool
*/
protected function is_valid_file($path) {
global $CFG;
$realpath = realpath($path);
// Additional theme directory.
$addthemedirectory = core_component::get_plugin_types()['theme'];
$addrealroot = realpath($addthemedirectory);
// Original theme directory.
$themedirectory = $CFG->dirroot . "/theme";
$realroot = realpath($themedirectory);
// File should end in .scss and must be in sites theme directory, else ignore it.
$pathvalid = $realpath !== false;
$pathvalid = $pathvalid && (substr($path, -5) === '.scss');
$pathvalid = $pathvalid && (strpos($realpath, $realroot) === 0 || strpos($realpath, $addrealroot) === 0);
return $pathvalid;
}
}