Skip to content

Commit f493902

Browse files
committed
Fix get() helper
1 parent a265c3f commit f493902

8 files changed

Lines changed: 26 additions & 13 deletions

File tree

‎src/Dashboards/APCu/APCuKeyView.php‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ private function getKeySize(string $key): int {
2424
}
2525

2626
private function viewKey(): string {
27-
$key = Http::get('key', '');
27+
$key = Http::get('key', '', true);
2828

2929
if (apcu_exists($key) === false) {
3030
Http::redirect();
@@ -89,7 +89,7 @@ public function saveKey(): void {
8989
* Add/edit form.
9090
*/
9191
private function form(): string {
92-
$key = Http::get('key', '');
92+
$key = Http::get('key', '', true);
9393
$expire = 0;
9494

9595
$encoder = Http::get('encoder', 'none');

‎src/Dashboards/Memcached/MemcachedKeyView.php‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ trait MemcachedKeyView {
2020
* @throws MemcachedException
2121
*/
2222
private function viewKey(): string {
23-
$key = Http::get('key', '');
23+
$key = Http::get('key', '', true);
2424

2525
if (!$this->memcached->exists($key)) {
2626
Http::redirect();
@@ -92,7 +92,7 @@ public function saveKey(): void {
9292
* @throws MemcachedException
9393
*/
9494
private function form(): string {
95-
$key = Http::get('key', '');
95+
$key = Http::get('key', '', true);
9696
$expire = Http::get('ttl', 0);
9797
$expire = $expire === -1 ? 0 : $expire;
9898

‎src/Dashboards/Redis/RedisKeyView.php‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ trait RedisKeyView {
2424
* @throws Exception
2525
*/
2626
private function viewKey(): string {
27-
$key = Http::get('key', '');
27+
$key = Http::get('key', '', true);
2828

2929
if (!$this->redis->exists($key)) {
3030
Http::redirect();
@@ -223,7 +223,7 @@ public function saveKey(): void {
223223
* @throws Exception
224224
*/
225225
private function form(): string {
226-
$key = (string) Http::get('key', Http::post('key', ''));
226+
$key = (string) Http::get('key', Http::post('key', ''), true);
227227
$type = Http::post('rtype', 'string');
228228
$index = $_POST['index'] ?? '';
229229
$score = Http::post('score', 0);

‎src/Helpers.php‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,7 +179,8 @@ public static function export(array $keys, string $filename, callable $value, bo
179179
return $output;
180180
}
181181

182-
header('Content-disposition: attachment; filename='.$filename.'.json');
182+
$safe_filename = preg_replace('/[\x00-\x1f"\\\\]+/', '', $filename);
183+
header('Content-disposition: attachment; filename="'.$safe_filename.'.json"');
183184
header('Content-Type: application/json');
184185
echo $output;
185186
exit;

‎src/Http.php‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,22 +49,24 @@ public static function queryString(array $preserve = [], array $additional = [])
4949

5050
/**
5151
* Get query parameter.
52+
* Set $raw to true for values that are data rather than markup (e.g. cache keys, which may legitimately contain <, >..)
5253
*
5354
* @template Type
5455
*
5556
* @param Type $default
5657
*
5758
* @return Type
5859
*/
59-
public static function get(string $key, $default = null) {
60+
public static function get(string $key, $default = null, bool $raw = false) {
6061
if (!isset($_GET[$key])) {
6162
return $default;
6263
}
6364

64-
$filter = is_int($default) ? FILTER_SANITIZE_NUMBER_INT : FILTER_SANITIZE_FULL_SPECIAL_CHARS;
65-
$value = filter_var($_GET[$key], $filter);
65+
if (is_int($default)) {
66+
return (int) filter_var($_GET[$key], FILTER_SANITIZE_NUMBER_INT);
67+
}
6668

67-
return is_int($default) ? (int) $value : $value;
69+
return filter_var($_GET[$key], $raw ? FILTER_UNSAFE_RAW : FILTER_SANITIZE_FULL_SPECIAL_CHARS);
6870
}
6971

7072
/**

‎templates/partials/table_view.twig‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
{% set td_class = is_title ? ' max-w-xs md:max-w-md truncate hover:text-clip hover:break-all hover:whitespace-normal' : '' %}
3939
<td class="px-3 py-2 border-b border-gray-200 text-sm{{ td_class }}{{ classes[loop.index]|space }} dark:border-gray-700 dark:text-gray-300">
4040
{% if item_key == 'link_title' and view_key %}
41-
{% set link = view_key|replace({__key__: key.key}) %}
41+
{% set link = view_key|replace({__key__: key.key|url_encode}) %}
4242
<a class="font-semibold text-primary-500 dark:text-primary-400 dark:hover:text-primary-300 hover:text-primary-700" href="{{ link }}"{{ config('keymodal', false) ? ' data-view-key' : '' }}>
4343
{{ item }}
4444
{% if key.items %}

‎templates/partials/tree_view.twig‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@
2828
{% endif %}
2929

3030
<span class="font-semibold text-primary-500 dark:text-primary-400 dark:hover:text-primary-300 hover:text-primary-700">
31-
{% set link = view_key|replace({__key__: item.key}) %}
31+
{% set link = view_key|replace({__key__: item.key|url_encode}) %}
3232
<a class="font-semibold text-primary-500 dark:text-primary-400 dark:hover:text-primary-300 hover:text-primary-700" href="{{ link }}"{{ config('keymodal', false) ? ' data-view-key' : '' }}>
3333
{{ item.name }}
3434
{% if item.items %}

‎tests/HttpTest.php‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,16 @@ public function testGetString(): void {
4141
$this->assertSame('', Http::get('test-string-empty', ''));
4242
}
4343

44+
public function testGetSanitizesSpecialChars(): void {
45+
$_GET['test-special'] = 'a<b>&"c';
46+
$this->assertSame('a&lt;b&gt;&amp;&quot;c', Http::get('test-special', ''));
47+
}
48+
49+
public function testGetRawKeepsSpecialChars(): void {
50+
$_GET['test-raw'] = 'a<b>&"c';
51+
$this->assertSame('a<b>&"c', Http::get('test-raw', '', true));
52+
}
53+
4454
public function testGetInt(): void {
4555
$_GET['test-int'] = 4646;
4656
$this->assertSame(4646, Http::get('test-int', 0));

0 commit comments

Comments
 (0)