Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
551ff35344 | ||
|
|
4e1a5c59b5 | ||
|
|
780a55fb00 | ||
|
|
7cbdba45da | ||
|
|
aebcee71b1 | ||
|
|
28b23dcfbc | ||
|
|
50f0d72e62 | ||
|
|
956d8fb1ec | ||
|
|
781d3d5230 | ||
|
|
b7229d0c02 | ||
|
|
6a09dbd486 | ||
|
|
fff698433f | ||
|
|
2004adee70 | ||
|
|
761659ddf0 | ||
|
|
6f7463ad93 | ||
|
|
3e43f73411 | ||
|
|
cfaa928600 | ||
|
|
b98a63475e | ||
|
|
799c739999 | ||
|
|
a4cdf3cfd2 | ||
|
|
1e52fb821c | ||
|
|
41717783ac | ||
|
|
bf0dade005 | ||
|
|
e4b3ca6c94 | ||
|
|
0150486358 | ||
|
|
878e9adeb6 | ||
|
|
afac7f57b0 | ||
|
|
cd374d7de8 | ||
|
|
56a2f0c21f | ||
|
|
f7e402320e | ||
|
|
79071bf0cc | ||
|
|
6d40f860e4 | ||
|
|
fcb7677cfc | ||
|
|
86dcf68f62 | ||
|
|
eddb96cb2e | ||
|
|
2df8d15d91 | ||
|
|
f515e7682a | ||
|
|
6e56bf1799 | ||
|
|
613ea5fc02 | ||
|
|
a9cd74b3fb | ||
|
|
bcd129a961 | ||
|
|
35eadafe3e | ||
|
|
74f4c09eb1 | ||
|
|
67ce55c047 | ||
|
|
ab9c1dcd4d | ||
|
|
f7225cdd01 | ||
|
|
65d95036c0 | ||
|
|
1904ab1352 | ||
|
|
77065246fc | ||
|
|
b6168089a7 | ||
|
|
249bc608b3 | ||
|
|
9c61825a17 | ||
|
|
f7c8728f20 | ||
|
|
7356c6cec6 | ||
|
|
7d11684731 | ||
|
|
86573ebbe9 | ||
|
|
e31f0c34a7 | ||
|
|
452f41108b | ||
|
|
d62d02201b | ||
|
|
cfe15cebd8 | ||
|
|
8133aa66f0 | ||
|
|
94175c1df1 | ||
|
|
82d5409957 | ||
|
|
07728aa425 | ||
|
|
29ad08648f | ||
|
|
a3a4e3922c | ||
|
|
76ff40f8bb | ||
|
|
c0fbcb7706 | ||
|
|
7e073fdfa0 | ||
|
|
1d0a95f022 | ||
|
|
9570ee1823 | ||
|
|
c5ae3d6b00 | ||
|
|
4967111a0e | ||
|
|
e27d1f1e5a | ||
|
|
df54d07169 | ||
|
|
efca592b17 | ||
|
|
95cd2c15cf | ||
|
|
00166e7917 | ||
|
|
ea435b7517 | ||
|
|
6d88ca7c8d | ||
|
|
d4087b2924 | ||
|
|
a01d52e62c | ||
|
|
252149bfdc | ||
|
|
cb2ae7ee35 | ||
|
|
10f68b951d | ||
|
|
0d555a596e | ||
|
|
d485286289 | ||
|
|
97dd8cdf97 | ||
|
|
97ec3584d8 | ||
|
|
e9a00903a9 | ||
|
|
9c6fe22012 | ||
|
|
741849397e | ||
|
|
679e1f09ad | ||
|
|
162ab2b949 | ||
|
|
c0b6dc6b75 | ||
|
|
848f03f4a4 | ||
|
|
ac821854ce | ||
|
|
1ae73c1c12 | ||
|
|
07a138cfe6 | ||
|
|
1d3a3dd6fd | ||
|
|
b33159e3d0 | ||
|
|
12bfc68272 | ||
|
|
c2e4eb9d38 | ||
|
|
5b8efe29f2 | ||
|
|
6811f6e586 | ||
|
|
14d55b289d | ||
|
|
4cd308e721 | ||
|
|
cf1ea6aea7 | ||
|
|
52f5a24742 | ||
|
|
4529db50a8 | ||
|
|
ca50cab7d7 | ||
|
|
dc315a0e24 | ||
|
|
7b11b8b1f0 | ||
|
|
639df7c950 | ||
|
|
b5812b2198 | ||
|
|
6263b674b8 | ||
|
|
c8f54cb9f1 | ||
|
|
1a6f571e15 | ||
|
|
cf1885a46b | ||
|
|
8865845e10 | ||
|
|
284346c499 | ||
|
|
6aa244cf17 | ||
|
|
71eec82126 | ||
|
|
94501a2aad | ||
|
|
f741a01bbe | ||
|
|
c794046eca | ||
|
|
3c72614b3f | ||
|
|
6ce6ded0f8 | ||
|
|
99b14adf07 | ||
|
|
ca2c673cce | ||
|
|
4e01b68f5b | ||
|
|
f3fc776b71 | ||
|
|
4b93f24f26 | ||
|
|
51b6f477dd | ||
|
|
4921e8189b | ||
|
|
33a04c55b1 | ||
|
|
2969c2544d | ||
|
|
69b64b7881 | ||
|
|
9b45cbb77c | ||
|
|
f4ad71e57a | ||
|
|
4b986903cb | ||
|
|
0bf219cf35 | ||
|
|
0477bee1d5 | ||
|
|
541f14ac6d |
@@ -44,3 +44,6 @@ dbbackups
|
||||
*.mysql
|
||||
*.tar.gz
|
||||
*.zip
|
||||
|
||||
# this is not working as missing config a simply delete on import
|
||||
# sites/default/config/sync/system.performance.yml
|
||||
|
||||
@@ -6,11 +6,11 @@
|
||||
"require": {
|
||||
"composer/installers": "^1.0.24",
|
||||
"wikimedia/composer-merge-plugin": "^1.4",
|
||||
"drupal/core": "^8.5",
|
||||
"drupal/console": "^1.7",
|
||||
"drush/drush": "^9"
|
||||
},
|
||||
"replace": {
|
||||
"drupal/core": "^8.5"
|
||||
},
|
||||
"minimum-stability": "dev",
|
||||
"prefer-stable": true,
|
||||
|
||||
|
Before Width: | Height: | Size: 5.2 KiB After Width: | Height: | Size: 3.1 KiB |
|
Before Width: | Height: | Size: 16 KiB After Width: | Height: | Size: 11 KiB |
|
Before Width: | Height: | Size: 5.2 KiB After Width: | Height: | Size: 3.1 KiB |
|
Before Width: | Height: | Size: 16 KiB After Width: | Height: | Size: 11 KiB |
@@ -24,7 +24,7 @@ classList:
|
||||
|
||||
ckeditor:
|
||||
remote: https://github.com/ckeditor/ckeditor-dev
|
||||
version: "4.8.0"
|
||||
version: "4.8.0+2018-04-18-security-patch"
|
||||
license:
|
||||
name: GNU-GPL-2.0-or-later
|
||||
url: https://github.com/ckeditor/ckeditor-dev/blob/4.8.0/LICENSE.md
|
||||
|
||||
@@ -82,7 +82,7 @@ class Drupal {
|
||||
/**
|
||||
* The current system version.
|
||||
*/
|
||||
const VERSION = '8.5.0';
|
||||
const VERSION = '8.5.3';
|
||||
|
||||
/**
|
||||
* Core API compatibility.
|
||||
|
||||
@@ -20,6 +20,7 @@ use Drupal\Core\File\MimeType\MimeTypeGuesser;
|
||||
use Drupal\Core\Http\TrustedHostsRequestFactory;
|
||||
use Drupal\Core\Installer\InstallerRedirectTrait;
|
||||
use Drupal\Core\Language\Language;
|
||||
use Drupal\Core\Security\RequestSanitizer;
|
||||
use Drupal\Core\Site\Settings;
|
||||
use Drupal\Core\Test\TestDatabase;
|
||||
use Symfony\Cmf\Component\Routing\RouteObjectInterface;
|
||||
@@ -542,6 +543,12 @@ class DrupalKernel implements DrupalKernelInterface, TerminableInterface {
|
||||
* {@inheritdoc}
|
||||
*/
|
||||
public function preHandle(Request $request) {
|
||||
// Sanitize the request.
|
||||
$request = RequestSanitizer::sanitize(
|
||||
$request,
|
||||
(array) Settings::get(RequestSanitizer::SANITIZE_WHITELIST, []),
|
||||
(bool) Settings::get(RequestSanitizer::SANITIZE_LOG, FALSE)
|
||||
);
|
||||
|
||||
$this->loadLegacyIncludes();
|
||||
|
||||
|
||||
@@ -0,0 +1,157 @@
|
||||
<?php
|
||||
|
||||
namespace Drupal\Core\Security;
|
||||
|
||||
use Drupal\Component\Utility\UrlHelper;
|
||||
use Symfony\Component\HttpFoundation\ParameterBag;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
|
||||
/**
|
||||
* Sanitizes user input.
|
||||
*/
|
||||
class RequestSanitizer {
|
||||
|
||||
/**
|
||||
* Request attribute to mark the request as sanitized.
|
||||
*/
|
||||
const SANITIZED = '_drupal_request_sanitized';
|
||||
|
||||
/**
|
||||
* The name of the setting that configures the whitelist.
|
||||
*/
|
||||
const SANITIZE_WHITELIST = 'sanitize_input_whitelist';
|
||||
|
||||
/**
|
||||
* The name of the setting that determines if sanitized keys are logged.
|
||||
*/
|
||||
const SANITIZE_LOG = 'sanitize_input_logging';
|
||||
|
||||
/**
|
||||
* Strips dangerous keys from user input.
|
||||
*
|
||||
* @param \Symfony\Component\HttpFoundation\Request $request
|
||||
* The incoming request to sanitize.
|
||||
* @param string[] $whitelist
|
||||
* An array of keys to whitelist as safe. See default.settings.php.
|
||||
* @param bool $log_sanitized_keys
|
||||
* (optional) Set to TRUE to log an keys that are sanitized.
|
||||
*
|
||||
* @return \Symfony\Component\HttpFoundation\Request
|
||||
* The sanitized request.
|
||||
*/
|
||||
public static function sanitize(Request $request, $whitelist, $log_sanitized_keys = FALSE) {
|
||||
if (!$request->attributes->get(self::SANITIZED, FALSE)) {
|
||||
$update_globals = FALSE;
|
||||
$bags = [
|
||||
'query' => 'Potentially unsafe keys removed from query string parameters (GET): %s',
|
||||
'request' => 'Potentially unsafe keys removed from request body parameters (POST): %s',
|
||||
'cookies' => 'Potentially unsafe keys removed from cookie parameters: %s',
|
||||
];
|
||||
foreach ($bags as $bag => $message) {
|
||||
if (static::processParameterBag($request->$bag, $whitelist, $log_sanitized_keys, $bag, $message)) {
|
||||
$update_globals = TRUE;
|
||||
}
|
||||
}
|
||||
if ($update_globals) {
|
||||
$request->overrideGlobals();
|
||||
}
|
||||
$request->attributes->set(self::SANITIZED, TRUE);
|
||||
}
|
||||
return $request;
|
||||
}
|
||||
|
||||
/**
|
||||
* Processes a request parameter bag.
|
||||
*
|
||||
* @param \Symfony\Component\HttpFoundation\ParameterBag $bag
|
||||
* The parameter bag to process.
|
||||
* @param string[] $whitelist
|
||||
* An array of keys to whitelist as safe.
|
||||
* @param bool $log_sanitized_keys
|
||||
* Set to TRUE to log keys that are sanitized.
|
||||
* @param string $bag_name
|
||||
* The request parameter bag name. Either 'query', 'request' or 'cookies'.
|
||||
* @param string $message
|
||||
* The message to log if the parameter bag contains keys that are removed.
|
||||
* If the message contains %s that is replaced by a list of removed keys.
|
||||
*
|
||||
* @return bool
|
||||
* TRUE if the parameter bag has been sanitized, FALSE if not.
|
||||
*/
|
||||
protected static function processParameterBag(ParameterBag $bag, $whitelist, $log_sanitized_keys, $bag_name, $message) {
|
||||
$sanitized = FALSE;
|
||||
$sanitized_keys = [];
|
||||
$bag->replace(static::stripDangerousValues($bag->all(), $whitelist, $sanitized_keys));
|
||||
if (!empty($sanitized_keys)) {
|
||||
$sanitized = TRUE;
|
||||
if ($log_sanitized_keys) {
|
||||
trigger_error(sprintf($message, implode(', ', $sanitized_keys)));
|
||||
}
|
||||
}
|
||||
|
||||
if ($bag->has('destination')) {
|
||||
$destination_dangerous_keys = static::checkDestination($bag->get('destination'), $whitelist);
|
||||
if (!empty($destination_dangerous_keys)) {
|
||||
// The destination is removed rather than sanitized because the URL
|
||||
// generator service is not available and this method is called very
|
||||
// early in the bootstrap.
|
||||
$bag->remove('destination');
|
||||
$sanitized = TRUE;
|
||||
if ($log_sanitized_keys) {
|
||||
trigger_error(sprintf('Potentially unsafe destination removed from %s parameter bag because it contained the following keys: %s', $bag_name, implode(', ', $destination_dangerous_keys)));
|
||||
}
|
||||
}
|
||||
}
|
||||
return $sanitized;
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks a destination string to see if it is dangerous.
|
||||
*
|
||||
* @param string $destination
|
||||
* The destination string to check.
|
||||
* @param array $whitelist
|
||||
* An array of keys to whitelist as safe.
|
||||
*
|
||||
* @return array
|
||||
* The dangerous keys found in the destination parameter.
|
||||
*/
|
||||
protected static function checkDestination($destination, array $whitelist) {
|
||||
$dangerous_keys = [];
|
||||
$parts = UrlHelper::parse($destination);
|
||||
// If there is a query string, check its query parameters.
|
||||
if (!empty($parts['query'])) {
|
||||
static::stripDangerousValues($parts['query'], $whitelist, $dangerous_keys);
|
||||
}
|
||||
return $dangerous_keys;
|
||||
}
|
||||
|
||||
/**
|
||||
* Strips dangerous keys from $input.
|
||||
*
|
||||
* @param mixed $input
|
||||
* The input to sanitize.
|
||||
* @param string[] $whitelist
|
||||
* An array of keys to whitelist as safe.
|
||||
* @param string[] $sanitized_keys
|
||||
* An array of keys that have been removed.
|
||||
*
|
||||
* @return mixed
|
||||
* The sanitized input.
|
||||
*/
|
||||
protected static function stripDangerousValues($input, array $whitelist, array &$sanitized_keys) {
|
||||
if (is_array($input)) {
|
||||
foreach ($input as $key => $value) {
|
||||
if ($key !== '' && $key[0] === '#' && !in_array($key, $whitelist, TRUE)) {
|
||||
unset($input[$key]);
|
||||
$sanitized_keys[] = $key;
|
||||
}
|
||||
else {
|
||||
$input[$key] = static::stripDangerousValues($input[$key], $whitelist, $sanitized_keys);
|
||||
}
|
||||
}
|
||||
}
|
||||
return $input;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -2,12 +2,6 @@ name: Actions
|
||||
type: module
|
||||
description: 'Perform tasks on specific events triggered within the system.'
|
||||
package: Core
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
configure: entity.action.collection
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,15 +2,9 @@ name: 'Action bulk form test'
|
||||
type: module
|
||||
description: 'Support module for action bulk form testing.'
|
||||
package: Testing
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
dependencies:
|
||||
- action
|
||||
- views
|
||||
- node
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,12 +2,6 @@ name: action_form_ajax_test
|
||||
type: module
|
||||
description: 'module used for testing ajax in action config entity forms.'
|
||||
package: Core
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
hidden: true
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,15 +2,9 @@ name: Aggregator
|
||||
type: module
|
||||
description: 'Aggregates syndicated content (RSS, RDF, and Atom feeds) from external sources.'
|
||||
package: Core
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
configure: aggregator.admin_settings
|
||||
dependencies:
|
||||
- file
|
||||
- options
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,11 +2,5 @@ name: 'Aggregator module tests'
|
||||
type: module
|
||||
description: 'Support module for aggregator related testing.'
|
||||
package: Testing
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
|
||||
@@ -2,14 +2,8 @@ name: 'Aggregator test views'
|
||||
type: module
|
||||
description: 'Provides default views for views aggregator tests.'
|
||||
package: Testing
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
dependencies:
|
||||
- aggregator
|
||||
- views
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,12 +2,6 @@ name: 'Automated Cron'
|
||||
type: module
|
||||
description: 'Provides an automated way to run cron jobs, by executing them at the end of a server response.'
|
||||
package: Core
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
configure: system.cron_settings
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,12 +2,6 @@ name: Ban
|
||||
type: module
|
||||
description: 'Enables banning of IP addresses.'
|
||||
package: Core
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
configure: ban.admin_page
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,13 +2,7 @@ name: 'HTTP Basic Authentication'
|
||||
type: module
|
||||
description: 'Provides the HTTP Basic authentication provider'
|
||||
package: Web services
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
dependencies:
|
||||
- user
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
|
||||
@@ -2,11 +2,5 @@ name: 'HTTP Basic Authentication test'
|
||||
type: module
|
||||
description: 'Support module for HTTP Basic Authentication testing.'
|
||||
package: Testing
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
|
||||
@@ -2,11 +2,5 @@ name: BigPipe
|
||||
type: module
|
||||
description: 'Sends pages using the BigPipe technique that allows browsers to show them much faster.'
|
||||
package: Core
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
|
||||
@@ -2,11 +2,5 @@ name: 'BigPipe regression test'
|
||||
type: module
|
||||
description: 'Support module for BigPipe regression testing.'
|
||||
package: Testing
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
|
||||
@@ -2,11 +2,5 @@ name: 'BigPipe test'
|
||||
type: module
|
||||
description: 'Support module for BigPipe testing.'
|
||||
package: Testing
|
||||
# version: VERSION
|
||||
# core: 8.x
|
||||
|
||||
# Information added by Drupal.org packaging script on 2018-03-07
|
||||
version: '8.5.0'
|
||||
core: '8.x'
|
||||
project: 'drupal'
|
||||
datestamp: 1520457826
|
||||
version: VERSION
|
||||
core: 8.x
|
||||
|
||||