MDL-56992 core_scss: Don't allow invalid files to be included
We allow only .scss files so allow files to be included only and only if they end in .scss and they exist on server under theme directory.
This commit is contained in:
committed by
Dan Poltawski
parent
6528ec3505
commit
a76b0b8b85
@@ -98,4 +98,58 @@ class core_scss extends \Leafo\ScssPhp\Compiler {
|
||||
return $this->compile($content);
|
||||
}
|
||||
|
||||
/**
|
||||
* Compile child; returns a value to halt execution
|
||||
*
|
||||
* @param array $child
|
||||
* @param \Leafo\ScssPhp\Formatter\OutputBlock $out
|
||||
*
|
||||
* @return array|null
|
||||
*/
|
||||
protected function compileChild($child, \Leafo\ScssPhp\Formatter\OutputBlock $out) {
|
||||
switch($child[0]) {
|
||||
case \Leafo\ScssPhp\Type::T_SCSSPHP_IMPORT_ONCE:
|
||||
case \Leafo\ScssPhp\Type::T_IMPORT:
|
||||
list(, $rawpath) = $child;
|
||||
$rawpath = $this->reduce($rawpath);
|
||||
$path = $this->compileStringContent($rawpath);
|
||||
if ($path = $this->findImport($path)) {
|
||||
if ($this->is_valid_file($path)) {
|
||||
return parent::compileChild($child, $out);
|
||||
} else {
|
||||
// Sneaky stuff, don't let non scss file in.
|
||||
debugging("Can't import scss file - " . $path, DEBUG_DEVELOPER);
|
||||
}
|
||||
}
|
||||
break;
|
||||
default:
|
||||
return parent::compileChild($child, $out);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Is the given file valid for import ?
|
||||
*
|
||||
* @param $path
|
||||
* @return bool
|
||||
*/
|
||||
protected function is_valid_file($path) {
|
||||
global $CFG;
|
||||
|
||||
$realpath = realpath($path);
|
||||
|
||||
// Additional theme directory.
|
||||
$addthemedirectory = core_component::get_plugin_types()['theme'];
|
||||
$addrealroot = realpath($addthemedirectory);
|
||||
|
||||
// Original theme directory.
|
||||
$themedirectory = $CFG->dirroot . "/theme";
|
||||
$realroot = realpath($themedirectory);
|
||||
|
||||
// File should end in .scss and must be in sites theme directory, else ignore it.
|
||||
$pathvalid = $realpath !== false;
|
||||
$pathvalid = $pathvalid && (substr($path, -5) === '.scss');
|
||||
$pathvalid = $pathvalid && (strpos($realpath, $realroot) === 0 || strpos($realpath, $addrealroot) === 0);
|
||||
return $pathvalid;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user