MDL-70823 core: safer alternative for unserializing objects.

This commit is contained in:
Paul Holden
2021-11-03 16:57:06 +01:00
committed by Sara Arjona
parent bc3890b60d
commit e22fded5fe
2 changed files with 38 additions and 0 deletions
+15
View File
@@ -10404,6 +10404,21 @@ function unserialize_array($expression) {
return $value;
}
/**
* Safe method for unserializing given input that is expected to contain only a serialized instance of an stdClass object
*
* If any class type other than stdClass is included in the input string, it will not be instantiated and will be cast to an
* stdClass object. The initial cast to array, then back to object is to ensure we are always returning the correct type,
* otherwise we would return an instances of {@see __PHP_Incomplete_class} for malformed strings
*
* @param string $input
* @return stdClass
*/
function unserialize_object(string $input): stdClass {
$instance = (array) unserialize($input, ['allowed_classes' => [stdClass::class]]);
return (object) $instance;
}
/**
* The lang_string class
*