diff --git a/lib/classes/persistent.php b/lib/classes/persistent.php index 25ac0a8060a..2ee9dd8fd0b 100644 --- a/lib/classes/persistent.php +++ b/lib/classes/persistent.php @@ -393,7 +393,8 @@ abstract class persistent { * @return static */ final public function from_record(stdClass $record) { - $record = (array) $record; + $properties = static::properties_definition(); + $record = array_intersect_key((array) $record, $properties); foreach ($record as $property => $value) { $this->raw_set($property, $value); } diff --git a/lib/tests/persistent_test.php b/lib/tests/persistent_test.php index dbddd3d03c4..23226e2d8cb 100644 --- a/lib/tests/persistent_test.php +++ b/lib/tests/persistent_test.php @@ -177,11 +177,26 @@ class core_persistent_testcase extends advanced_testcase { public function test_from_record_invalid_param() { $p = new core_testable_persistent(); $data = (object) array( + 'shortname' => 'ddd', + 'idnumber' => 'abc', + 'description' => 'xyz', + 'descriptionformat' => FORMAT_PLAIN, + 'parentid' => 999, + 'path' => '/a/b/c', + 'sortorder' => 12, + 'id' => 1, + 'timecreated' => 2, + 'timemodified' => 3, + 'usermodified' => 4, + 'scaleid' => null, 'invalidparam' => 'abc' ); - $this->expectException(coding_exception::class); $p->from_record($data); + + // Previous call should succeed, assert we get back all data except invalid param. + unset($data->invalidparam); + $this->assertEquals($data, $p->to_record()); } public function test_validate() { diff --git a/lib/upgrade.txt b/lib/upgrade.txt index 42e7fefcf94..eefe2d57570 100644 --- a/lib/upgrade.txt +++ b/lib/upgrade.txt @@ -1,6 +1,9 @@ This files describes API changes in core libraries and APIs, information provided here is intended especially for developers. +=== 3.11.6 === +* The persistent method from_record() now only attempts to load record properties defined in the persistent class. + === 3.11.5 === * Two new helper functions have been added to lib/datalib.php, for safely preparing SQL ORDER BY statements where user interactions define sort parameters (see the respective docblocks for full details and examples):