Compare commits
14
Commits
7.58
...
438237e852
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
438237e852 | ||
|
|
cc3b64a193 | ||
|
|
aa5c4a5a74 | ||
|
|
4e0d4316d6 | ||
|
|
27bffaa4dc | ||
|
|
a8891db014 | ||
|
|
54c778223d | ||
|
|
a40774a820 | ||
|
|
f466459072 | ||
|
|
d5096cf9ad | ||
|
|
a163542966 | ||
|
|
f7ae17e6c4 | ||
|
|
fdd2f67cc6 | ||
|
|
8fb74fdf95 |
@@ -6,3 +6,4 @@ sites/*/files
|
|||||||
sites/*/private
|
sites/*/private
|
||||||
sites/*/tmp
|
sites/*/tmp
|
||||||
|
|
||||||
|
error/
|
||||||
|
|||||||
+61
-1
@@ -1,7 +1,67 @@
|
|||||||
|
Drupal 7.xx, xxxx-xx-xx (development version)
|
||||||
|
-----------------------
|
||||||
|
|
||||||
|
Drupal 7.67, 2019-05-08
|
||||||
|
-----------------------
|
||||||
|
- Fixed security issues:
|
||||||
|
- SA-CORE-2019-007
|
||||||
|
|
||||||
|
Drupal 7.66, 2019-04-17
|
||||||
|
-----------------------
|
||||||
|
- Fixed security issues:
|
||||||
|
- SA-CORE-2019-006
|
||||||
|
|
||||||
|
Drupal 7.65, 2019-03-20
|
||||||
|
-----------------------
|
||||||
|
- Fixed security issues:
|
||||||
|
- SA-CORE-2019-004
|
||||||
|
|
||||||
|
Drupal 7.64, 2019-02-06
|
||||||
|
-----------------------
|
||||||
|
- [regression] Unset the 'host' header in drupal_http_request() during redirect
|
||||||
|
- Fixed: 7.x does not have Phar protection and Phar tests are failing on Drupal 7
|
||||||
|
- Fixed: Notice: Undefined index: display_field in file_field_widget_value() (line 582 of /module/file/file.field.inc)
|
||||||
|
- Performance improvement: Registry rebuild should not parse the same file twice in the same request
|
||||||
|
- Fixed _registry_update() to clear caches after transaction is committed
|
||||||
|
|
||||||
|
Drupal 7.63, 2019-01-16
|
||||||
|
-----------------------
|
||||||
|
- Fixed a fatal error for some Drush users introduced by SA-CORE-2019-002.
|
||||||
|
|
||||||
|
Drupal 7.62, 2019-01-15
|
||||||
|
-----------------------
|
||||||
|
- Fixed security issues:
|
||||||
|
- SA-CORE-2019-001
|
||||||
|
- SA-CORE-2019-002
|
||||||
|
|
||||||
|
Drupal 7.61, 2018-11-07
|
||||||
|
-----------------------
|
||||||
|
- File upload validation functions and hook_file_validate() implementations are
|
||||||
|
now always passed the correct file URI.
|
||||||
|
- The default form cache expiration of 6 hours is now configurable (API
|
||||||
|
addition: https://www.drupal.org/node/2857751).
|
||||||
|
- Allowed callers of drupal_http_request() to optionally specify an explicit
|
||||||
|
Host header.
|
||||||
|
- Allowed the + character to appear in usernames.
|
||||||
|
- PHP 7.2: Fixed Archive_Tar incompatibility.
|
||||||
|
- PHP 7.2: Removed deprecated function each().
|
||||||
|
- PHP 7.2: Avoid count() calls on uncountable variables.
|
||||||
|
- PHP 7.2: Removed deprecated create_function() call.
|
||||||
|
- PHP 7.2: Make sure variables are arrays in theme_links().
|
||||||
|
- Fixed theme-settings.php not being loaded on cached forms
|
||||||
|
- Fixed problem with IE11 & Chrome(PointerEvents enabled) & some Firefox scroll to the top of the page after dragging the bottom item with jquery 1.5 <-> 1.11
|
||||||
|
|
||||||
|
Drupal 7.60, 2018-10-18
|
||||||
|
------------------------
|
||||||
|
- Fixed security issues. See SA-CORE-2018-006.
|
||||||
|
|
||||||
|
Drupal 7.59, 2018-04-25
|
||||||
|
-----------------------
|
||||||
|
- Fixed security issues (remote code execution). See SA-CORE-2018-004.
|
||||||
|
|
||||||
Drupal 7.58, 2018-03-28
|
Drupal 7.58, 2018-03-28
|
||||||
-----------------------
|
-----------------------
|
||||||
- Fixed security issues (multiple vulnerabilities). See SA-CORE-2018-002.
|
- Fixed security issues (remote code execution). See SA-CORE-2018-002.
|
||||||
|
|
||||||
Drupal 7.57, 2018-02-21
|
Drupal 7.57, 2018-02-21
|
||||||
-----------------------
|
-----------------------
|
||||||
|
|||||||
+2
-2
@@ -15,6 +15,7 @@ The branch maintainers for Drupal 7 are:
|
|||||||
- Fabian Franz 'Fabianx' https://www.drupal.org/u/fabianx
|
- Fabian Franz 'Fabianx' https://www.drupal.org/u/fabianx
|
||||||
- David Rothstein 'David_Rothstein' https://www.drupal.org/u/david_rothstein
|
- David Rothstein 'David_Rothstein' https://www.drupal.org/u/david_rothstein
|
||||||
- Stefan Ruijsenaars 'stefan.r' https://www.drupal.org/u/stefanr-0
|
- Stefan Ruijsenaars 'stefan.r' https://www.drupal.org/u/stefanr-0
|
||||||
|
- (provisional) Pol Dellaiera 'Pol' https://www.drupal.org/u/pol
|
||||||
|
|
||||||
|
|
||||||
Component maintainers
|
Component maintainers
|
||||||
@@ -44,10 +45,9 @@ Cron system
|
|||||||
- Derek Wright 'dww' https://www.drupal.org/u/dww
|
- Derek Wright 'dww' https://www.drupal.org/u/dww
|
||||||
|
|
||||||
Database system
|
Database system
|
||||||
- Larry Garfield 'Crell' https://www.drupal.org/u/crell
|
- ?
|
||||||
|
|
||||||
- MySQL driver
|
- MySQL driver
|
||||||
- Larry Garfield 'Crell' https://www.drupal.org/u/crell
|
|
||||||
- David Strauss 'David Strauss' https://www.drupal.org/u/david-strauss
|
- David Strauss 'David Strauss' https://www.drupal.org/u/david-strauss
|
||||||
|
|
||||||
- PostgreSQL driver
|
- PostgreSQL driver
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
google-site-verification: google5c59d2e455c34eaa.html
|
|
||||||
+24
-2
@@ -8,7 +8,7 @@
|
|||||||
/**
|
/**
|
||||||
* The current system version.
|
* The current system version.
|
||||||
*/
|
*/
|
||||||
define('VERSION', '7.58');
|
define('VERSION', '7.67');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Core API compatibility.
|
* Core API compatibility.
|
||||||
@@ -704,6 +704,19 @@ function drupal_environment_initialize() {
|
|||||||
// Set sane locale settings, to ensure consistent string, dates, times and
|
// Set sane locale settings, to ensure consistent string, dates, times and
|
||||||
// numbers handling.
|
// numbers handling.
|
||||||
setlocale(LC_ALL, 'C');
|
setlocale(LC_ALL, 'C');
|
||||||
|
|
||||||
|
// PHP's built-in phar:// stream wrapper is not sufficiently secure. Override
|
||||||
|
// it with a more secure one, which requires PHP 5.3.3. For lower versions,
|
||||||
|
// unregister the built-in one without replacing it. Sites needing phar
|
||||||
|
// support for lower PHP versions must implement hook_stream_wrappers() to
|
||||||
|
// register their desired implementation.
|
||||||
|
if (in_array('phar', stream_get_wrappers(), TRUE)) {
|
||||||
|
stream_wrapper_unregister('phar');
|
||||||
|
if (version_compare(PHP_VERSION, '5.3.3', '>=')) {
|
||||||
|
include_once DRUPAL_ROOT . '/includes/file.phar.inc';
|
||||||
|
file_register_phar_wrapper();
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -2778,6 +2791,11 @@ function _drupal_bootstrap_variables() {
|
|||||||
unset($_GET['destination']);
|
unset($_GET['destination']);
|
||||||
unset($_REQUEST['destination']);
|
unset($_REQUEST['destination']);
|
||||||
}
|
}
|
||||||
|
// Use the DrupalRequestSanitizer to ensure that the destination's query
|
||||||
|
// parameters are not dangerous.
|
||||||
|
if (isset($_GET['destination'])) {
|
||||||
|
DrupalRequestSanitizer::cleanDestination();
|
||||||
|
}
|
||||||
// If there's still something in $_REQUEST['destination'] that didn't come
|
// If there's still something in $_REQUEST['destination'] that didn't come
|
||||||
// from $_GET, check it too.
|
// from $_GET, check it too.
|
||||||
if (isset($_REQUEST['destination']) && (!isset($_GET['destination']) || $_REQUEST['destination'] != $_GET['destination']) && url_is_external($_REQUEST['destination'])) {
|
if (isset($_REQUEST['destination']) && (!isset($_GET['destination']) || $_REQUEST['destination'] != $_GET['destination']) && url_is_external($_REQUEST['destination'])) {
|
||||||
@@ -3780,8 +3798,12 @@ function _drupal_shutdown_function() {
|
|||||||
chdir(DRUPAL_ROOT);
|
chdir(DRUPAL_ROOT);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
while (list($key, $callback) = each($callbacks)) {
|
// Manually iterate over the array instead of using a foreach loop.
|
||||||
|
// A foreach operates on a copy of the array, so any shutdown functions that
|
||||||
|
// were added from other shutdown functions would never be called.
|
||||||
|
while ($callback = current($callbacks)) {
|
||||||
call_user_func_array($callback['callback'], $callback['arguments']);
|
call_user_func_array($callback['callback'], $callback['arguments']);
|
||||||
|
next($callbacks);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
catch (Exception $exception) {
|
catch (Exception $exception) {
|
||||||
|
|||||||
+18
-3
@@ -611,8 +611,9 @@ function drupal_parse_url($url) {
|
|||||||
}
|
}
|
||||||
// The 'q' parameter contains the path of the current page if clean URLs are
|
// The 'q' parameter contains the path of the current page if clean URLs are
|
||||||
// disabled. It overrides the 'path' of the URL when present, even if clean
|
// disabled. It overrides the 'path' of the URL when present, even if clean
|
||||||
// URLs are enabled, due to how Apache rewriting rules work.
|
// URLs are enabled, due to how Apache rewriting rules work. The path
|
||||||
if (isset($options['query']['q'])) {
|
// parameter must be a string.
|
||||||
|
if (isset($options['query']['q']) && is_string($options['query']['q'])) {
|
||||||
$options['path'] = $options['query']['q'];
|
$options['path'] = $options['query']['q'];
|
||||||
unset($options['query']['q']);
|
unset($options['query']['q']);
|
||||||
}
|
}
|
||||||
@@ -866,8 +867,10 @@ function drupal_http_request($url, array $options = array()) {
|
|||||||
// Make the socket connection to a proxy server.
|
// Make the socket connection to a proxy server.
|
||||||
$socket = 'tcp://' . $proxy_server . ':' . variable_get('proxy_port', 8080);
|
$socket = 'tcp://' . $proxy_server . ':' . variable_get('proxy_port', 8080);
|
||||||
// The Host header still needs to match the real request.
|
// The Host header still needs to match the real request.
|
||||||
|
if (!isset($options['headers']['Host'])) {
|
||||||
$options['headers']['Host'] = $uri['host'];
|
$options['headers']['Host'] = $uri['host'];
|
||||||
$options['headers']['Host'] .= isset($uri['port']) && $uri['port'] != 80 ? ':' . $uri['port'] : '';
|
$options['headers']['Host'] .= isset($uri['port']) && $uri['port'] != 80 ? ':' . $uri['port'] : '';
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'http':
|
case 'http':
|
||||||
@@ -877,14 +880,18 @@ function drupal_http_request($url, array $options = array()) {
|
|||||||
// RFC 2616: "non-standard ports MUST, default ports MAY be included".
|
// RFC 2616: "non-standard ports MUST, default ports MAY be included".
|
||||||
// We don't add the standard port to prevent from breaking rewrite rules
|
// We don't add the standard port to prevent from breaking rewrite rules
|
||||||
// checking the host that do not take into account the port number.
|
// checking the host that do not take into account the port number.
|
||||||
|
if (!isset($options['headers']['Host'])) {
|
||||||
$options['headers']['Host'] = $uri['host'] . ($port != 80 ? ':' . $port : '');
|
$options['headers']['Host'] = $uri['host'] . ($port != 80 ? ':' . $port : '');
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'https':
|
case 'https':
|
||||||
// Note: Only works when PHP is compiled with OpenSSL support.
|
// Note: Only works when PHP is compiled with OpenSSL support.
|
||||||
$port = isset($uri['port']) ? $uri['port'] : 443;
|
$port = isset($uri['port']) ? $uri['port'] : 443;
|
||||||
$socket = 'ssl://' . $uri['host'] . ':' . $port;
|
$socket = 'ssl://' . $uri['host'] . ':' . $port;
|
||||||
|
if (!isset($options['headers']['Host'])) {
|
||||||
$options['headers']['Host'] = $uri['host'] . ($port != 443 ? ':' . $port : '');
|
$options['headers']['Host'] = $uri['host'] . ($port != 443 ? ':' . $port : '');
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
default:
|
default:
|
||||||
@@ -1087,6 +1094,11 @@ function drupal_http_request($url, array $options = array()) {
|
|||||||
elseif ($options['max_redirects']) {
|
elseif ($options['max_redirects']) {
|
||||||
// Redirect to the new location.
|
// Redirect to the new location.
|
||||||
$options['max_redirects']--;
|
$options['max_redirects']--;
|
||||||
|
|
||||||
|
// We need to unset the 'Host' header
|
||||||
|
// as we are redirecting to a new location.
|
||||||
|
unset($options['headers']['Host']);
|
||||||
|
|
||||||
$result = drupal_http_request($location, $options);
|
$result = drupal_http_request($location, $options);
|
||||||
$result->redirect_code = $code;
|
$result->redirect_code = $code;
|
||||||
}
|
}
|
||||||
@@ -2310,7 +2322,10 @@ function url($path = NULL, array $options = array()) {
|
|||||||
$language = isset($options['language']) && isset($options['language']->language) ? $options['language']->language : '';
|
$language = isset($options['language']) && isset($options['language']->language) ? $options['language']->language : '';
|
||||||
$alias = drupal_get_path_alias($original_path, $language);
|
$alias = drupal_get_path_alias($original_path, $language);
|
||||||
if ($alias != $original_path) {
|
if ($alias != $original_path) {
|
||||||
$path = $alias;
|
// Strip leading slashes from internal path aliases to prevent them
|
||||||
|
// becoming external URLs without protocol. /example.com should not be
|
||||||
|
// turned into //example.com.
|
||||||
|
$path = ltrim($alias, '/');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+49
-4
@@ -993,8 +993,15 @@ function file_build_uri($path) {
|
|||||||
* @return
|
* @return
|
||||||
* The destination filepath, or FALSE if the file already exists
|
* The destination filepath, or FALSE if the file already exists
|
||||||
* and FILE_EXISTS_ERROR is specified.
|
* and FILE_EXISTS_ERROR is specified.
|
||||||
|
*
|
||||||
|
* @throws RuntimeException
|
||||||
|
* Thrown if the filename contains invalid UTF-8.
|
||||||
*/
|
*/
|
||||||
function file_destination($destination, $replace) {
|
function file_destination($destination, $replace) {
|
||||||
|
$basename = drupal_basename($destination);
|
||||||
|
if (!drupal_validate_utf8($basename)) {
|
||||||
|
throw new RuntimeException(sprintf("Invalid filename '%s'", $basename));
|
||||||
|
}
|
||||||
if (file_exists($destination)) {
|
if (file_exists($destination)) {
|
||||||
switch ($replace) {
|
switch ($replace) {
|
||||||
case FILE_EXISTS_REPLACE:
|
case FILE_EXISTS_REPLACE:
|
||||||
@@ -1002,7 +1009,6 @@ function file_destination($destination, $replace) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case FILE_EXISTS_RENAME:
|
case FILE_EXISTS_RENAME:
|
||||||
$basename = drupal_basename($destination);
|
|
||||||
$directory = drupal_dirname($destination);
|
$directory = drupal_dirname($destination);
|
||||||
$destination = file_create_filename($basename, $directory);
|
$destination = file_create_filename($basename, $directory);
|
||||||
break;
|
break;
|
||||||
@@ -1218,11 +1224,20 @@ function file_unmunge_filename($filename) {
|
|||||||
* @return
|
* @return
|
||||||
* File path consisting of $directory and a unique filename based off
|
* File path consisting of $directory and a unique filename based off
|
||||||
* of $basename.
|
* of $basename.
|
||||||
|
*
|
||||||
|
* @throws RuntimeException
|
||||||
|
* Thrown if the $basename is not valid UTF-8 or another error occurs
|
||||||
|
* stripping control characters.
|
||||||
*/
|
*/
|
||||||
function file_create_filename($basename, $directory) {
|
function file_create_filename($basename, $directory) {
|
||||||
|
$original = $basename;
|
||||||
// Strip control characters (ASCII value < 32). Though these are allowed in
|
// Strip control characters (ASCII value < 32). Though these are allowed in
|
||||||
// some filesystems, not many applications handle them well.
|
// some filesystems, not many applications handle them well.
|
||||||
$basename = preg_replace('/[\x00-\x1F]/u', '_', $basename);
|
$basename = preg_replace('/[\x00-\x1F]/u', '_', $basename);
|
||||||
|
if (preg_last_error() !== PREG_NO_ERROR) {
|
||||||
|
throw new RuntimeException(sprintf("Invalid filename '%s'", $original));
|
||||||
|
}
|
||||||
|
|
||||||
if (substr(PHP_OS, 0, 3) == 'WIN') {
|
if (substr(PHP_OS, 0, 3) == 'WIN') {
|
||||||
// These characters are not allowed in Windows filenames
|
// These characters are not allowed in Windows filenames
|
||||||
$basename = str_replace(array(':', '*', '?', '"', '<', '>', '|'), '_', $basename);
|
$basename = str_replace(array(':', '*', '?', '"', '<', '>', '|'), '_', $basename);
|
||||||
@@ -1534,9 +1549,9 @@ function file_save_upload($form_field_name, $validators = array(), $destination
|
|||||||
// rename filename.php.foo and filename.php to filename.php.foo.txt and
|
// rename filename.php.foo and filename.php to filename.php.foo.txt and
|
||||||
// filename.php.txt, respectively). Don't rename if 'allow_insecure_uploads'
|
// filename.php.txt, respectively). Don't rename if 'allow_insecure_uploads'
|
||||||
// evaluates to TRUE.
|
// evaluates to TRUE.
|
||||||
if (!variable_get('allow_insecure_uploads', 0) && preg_match('/\.(php|pl|py|cgi|asp|js)(\.|$)/i', $file->filename) && (substr($file->filename, -4) != '.txt')) {
|
if (!variable_get('allow_insecure_uploads', 0) && preg_match('/\.(php|phar|pl|py|cgi|asp|js)(\.|$)/i', $file->filename) && (substr($file->filename, -4) != '.txt')) {
|
||||||
$file->filemime = 'text/plain';
|
$file->filemime = 'text/plain';
|
||||||
$file->uri .= '.txt';
|
// The destination filename will also later be used to create the URI.
|
||||||
$file->filename .= '.txt';
|
$file->filename .= '.txt';
|
||||||
// The .txt extension may not be in the allowed list of extensions. We have
|
// The .txt extension may not be in the allowed list of extensions. We have
|
||||||
// to add it here or else the file upload will fail.
|
// to add it here or else the file upload will fail.
|
||||||
@@ -1563,7 +1578,13 @@ function file_save_upload($form_field_name, $validators = array(), $destination
|
|||||||
if (substr($destination, -1) != '/') {
|
if (substr($destination, -1) != '/') {
|
||||||
$destination .= '/';
|
$destination .= '/';
|
||||||
}
|
}
|
||||||
|
try {
|
||||||
$file->destination = file_destination($destination . $file->filename, $replace);
|
$file->destination = file_destination($destination . $file->filename, $replace);
|
||||||
|
}
|
||||||
|
catch (RuntimeException $e) {
|
||||||
|
drupal_set_message(t('The file %source could not be uploaded because the name is invalid.', array('%source' => $form_field_name)), 'error');
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
// If file_destination() returns FALSE then $replace == FILE_EXISTS_ERROR and
|
// If file_destination() returns FALSE then $replace == FILE_EXISTS_ERROR and
|
||||||
// there's an existing file so we need to bail.
|
// there's an existing file so we need to bail.
|
||||||
if ($file->destination === FALSE) {
|
if ($file->destination === FALSE) {
|
||||||
@@ -2130,9 +2151,33 @@ function file_download_access($uri) {
|
|||||||
* 'filename', and 'name' members corresponding to the matching files.
|
* 'filename', and 'name' members corresponding to the matching files.
|
||||||
*/
|
*/
|
||||||
function file_scan_directory($dir, $mask, $options = array(), $depth = 0) {
|
function file_scan_directory($dir, $mask, $options = array(), $depth = 0) {
|
||||||
|
// Default nomask option.
|
||||||
|
$nomask = '/(\.\.?|CVS)$/';
|
||||||
|
|
||||||
|
// Overrides the $nomask variable accordingly if $options['nomask'] is set.
|
||||||
|
//
|
||||||
|
// Allow directories specified in settings.php to be ignored. You can use this
|
||||||
|
// to not check for files in common special-purpose directories. For example,
|
||||||
|
// node_modules and bower_components. Ignoring irrelevant directories is a
|
||||||
|
// performance boost.
|
||||||
|
if (!isset($options['nomask'])) {
|
||||||
|
$ignore_directories = variable_get(
|
||||||
|
'file_scan_ignore_directories',
|
||||||
|
array()
|
||||||
|
);
|
||||||
|
|
||||||
|
foreach ($ignore_directories as $index => $ignore_directory) {
|
||||||
|
$ignore_directories[$index] = preg_quote($ignore_directory, '/');
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!empty($ignore_directories)) {
|
||||||
|
$nomask = '/^(\.\.?)|CVS|' . implode('|', $ignore_directories) . '$/';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Merge in defaults.
|
// Merge in defaults.
|
||||||
$options += array(
|
$options += array(
|
||||||
'nomask' => '/(\.\.?|CVS)$/',
|
'nomask' => $nomask,
|
||||||
'callback' => 0,
|
'callback' => 0,
|
||||||
'recurse' => TRUE,
|
'recurse' => TRUE,
|
||||||
'key' => 'uri',
|
'key' => 'uri',
|
||||||
|
|||||||
@@ -0,0 +1,55 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Drupal\Core\Security\PharExtensionInterceptor;
|
||||||
|
use TYPO3\PharStreamWrapper\Manager as PharStreamWrapperManager;
|
||||||
|
use TYPO3\PharStreamWrapper\Behavior as PharStreamWrapperBehavior;
|
||||||
|
use TYPO3\PharStreamWrapper\PharStreamWrapper;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Registers a phar stream wrapper that is more secure than PHP's built-in one.
|
||||||
|
*
|
||||||
|
* @see file_get_stream_wrappers()
|
||||||
|
*/
|
||||||
|
function file_register_phar_wrapper() {
|
||||||
|
$directory = DRUPAL_ROOT . '/misc/typo3/phar-stream-wrapper/src';
|
||||||
|
include_once $directory . '/Assertable.php';
|
||||||
|
include_once $directory . '/Behavior.php';
|
||||||
|
include_once $directory . '/Exception.php';
|
||||||
|
include_once $directory . '/Helper.php';
|
||||||
|
include_once $directory . '/Manager.php';
|
||||||
|
include_once $directory . '/PharStreamWrapper.php';
|
||||||
|
include_once $directory . '/Collectable.php';
|
||||||
|
include_once $directory . '/Interceptor/ConjunctionInterceptor.php';
|
||||||
|
include_once $directory . '/Interceptor/PharMetaDataInterceptor.php';
|
||||||
|
include_once $directory . '/Phar/Container.php';
|
||||||
|
include_once $directory . '/Phar/DeserializationException.php';
|
||||||
|
include_once $directory . '/Phar/Manifest.php';
|
||||||
|
include_once $directory . '/Phar/Reader.php';
|
||||||
|
include_once $directory . '/Phar/ReaderException.php';
|
||||||
|
include_once $directory . '/Phar/Stub.php';
|
||||||
|
include_once $directory . '/Resolvable.php';
|
||||||
|
include_once $directory . '/Resolver/PharInvocation.php';
|
||||||
|
include_once $directory . '/Resolver/PharInvocationCollection.php';
|
||||||
|
include_once $directory . '/Resolver/PharInvocationResolver.php';
|
||||||
|
include_once DRUPAL_ROOT . '/misc/typo3/drupal-security/PharExtensionInterceptor.php';
|
||||||
|
include_once DRUPAL_ROOT . '/misc/brumann/polyfill-unserialize/src/Unserialize.php';
|
||||||
|
|
||||||
|
// Set up a stream wrapper to handle insecurities due to PHP's built-in
|
||||||
|
// phar stream wrapper.
|
||||||
|
try {
|
||||||
|
$behavior = new PharStreamWrapperBehavior();
|
||||||
|
PharStreamWrapperManager::initialize(
|
||||||
|
$behavior->withAssertion(new PharExtensionInterceptor())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
catch (\LogicException $e) {
|
||||||
|
// Continue if the PharStreamWrapperManager is already initialized.
|
||||||
|
// For example, this occurs following a drupal_static_reset(), such
|
||||||
|
// as during tests.
|
||||||
|
};
|
||||||
|
|
||||||
|
// To prevent file_stream_wrapper_valid_scheme() treating "phar" as a valid
|
||||||
|
// scheme, this is registered with PHP only, not with hook_stream_wrappers()
|
||||||
|
// or the internal storage of file_get_stream_wrappers().
|
||||||
|
stream_wrapper_register('phar', '\\TYPO3\\PharStreamWrapper\\PharStreamWrapper');
|
||||||
|
}
|
||||||
+8
-4
@@ -555,8 +555,10 @@ function form_get_cache($form_build_id, &$form_state) {
|
|||||||
* Stores a form in the cache.
|
* Stores a form in the cache.
|
||||||
*/
|
*/
|
||||||
function form_set_cache($form_build_id, $form, $form_state) {
|
function form_set_cache($form_build_id, $form, $form_state) {
|
||||||
// 6 hours cache life time for forms should be plenty.
|
// The default cache_form expiration is 6 hours. On busy sites, the cache_form
|
||||||
$expire = 21600;
|
// table can become very large. A shorter cache lifetime can help to keep the
|
||||||
|
// table's size under control.
|
||||||
|
$expire = variable_get('form_cache_expiration', 21600);
|
||||||
|
|
||||||
// Ensure that the form build_id embedded in the form structure is the same as
|
// Ensure that the form build_id embedded in the form structure is the same as
|
||||||
// the one passed in as a parameter. This is an additional safety measure to
|
// the one passed in as a parameter. This is an additional safety measure to
|
||||||
@@ -1438,10 +1440,12 @@ function _form_validate(&$elements, &$form_state, $form_id = NULL) {
|
|||||||
// length if it's a string, and the item count if it's an array.
|
// length if it's a string, and the item count if it's an array.
|
||||||
// An unchecked checkbox has a #value of integer 0, different than string
|
// An unchecked checkbox has a #value of integer 0, different than string
|
||||||
// '0', which could be a valid value.
|
// '0', which could be a valid value.
|
||||||
$is_empty_multiple = (!count($elements['#value']));
|
$is_countable = is_array($elements['#value']) || $elements['#value'] instanceof Countable;
|
||||||
|
$is_empty_multiple = $is_countable && count($elements['#value']) == 0;
|
||||||
$is_empty_string = (is_string($elements['#value']) && drupal_strlen(trim($elements['#value'])) == 0);
|
$is_empty_string = (is_string($elements['#value']) && drupal_strlen(trim($elements['#value'])) == 0);
|
||||||
$is_empty_value = ($elements['#value'] === 0);
|
$is_empty_value = ($elements['#value'] === 0);
|
||||||
if ($is_empty_multiple || $is_empty_string || $is_empty_value) {
|
$is_empty_null = is_null($elements['#value']);
|
||||||
|
if ($is_empty_multiple || $is_empty_string || $is_empty_value || $is_empty_null) {
|
||||||
// Although discouraged, a #title is not mandatory for form elements. In
|
// Although discouraged, a #title is not mandatory for form elements. In
|
||||||
// case there is no #title, we cannot set a form error message.
|
// case there is no #title, we cannot set a form error message.
|
||||||
// Instead of setting no #title, form constructors are encouraged to set
|
// Instead of setting no #title, form constructors are encouraged to set
|
||||||
|
|||||||
@@ -779,7 +779,7 @@ function drupal_uninstall_modules($module_list = array(), $uninstall_dependents
|
|||||||
$module_list = array_flip(array_values($module_list));
|
$module_list = array_flip(array_values($module_list));
|
||||||
|
|
||||||
$profile = drupal_get_profile();
|
$profile = drupal_get_profile();
|
||||||
while (list($module) = each($module_list)) {
|
foreach (array_keys($module_list) as $module) {
|
||||||
if (!isset($module_data[$module]) || drupal_get_installed_schema_version($module) == SCHEMA_UNINSTALLED) {
|
if (!isset($module_data[$module]) || drupal_get_installed_schema_version($module) == SCHEMA_UNINSTALLED) {
|
||||||
// This module doesn't exist or is already uninstalled. Skip it.
|
// This module doesn't exist or is already uninstalled. Skip it.
|
||||||
unset($module_list[$module]);
|
unset($module_list[$module]);
|
||||||
|
|||||||
+6
-3
@@ -576,7 +576,8 @@ function _menu_load_objects(&$item, &$map) {
|
|||||||
// 'load arguments' in the hook_menu() entry, but they need
|
// 'load arguments' in the hook_menu() entry, but they need
|
||||||
// some processing. In this case the $function is the key to the
|
// some processing. In this case the $function is the key to the
|
||||||
// load_function array, and the value is the list of arguments.
|
// load_function array, and the value is the list of arguments.
|
||||||
list($function, $args) = each($function);
|
$args = current($function);
|
||||||
|
$function = key($function);
|
||||||
$load_functions[$index] = $function;
|
$load_functions[$index] = $function;
|
||||||
|
|
||||||
// Some arguments are placeholders for dynamic items to process.
|
// Some arguments are placeholders for dynamic items to process.
|
||||||
@@ -2402,7 +2403,8 @@ function menu_set_active_trail($new_trail = NULL) {
|
|||||||
// a stripped down menu tree containing the active trail only, in case
|
// a stripped down menu tree containing the active trail only, in case
|
||||||
// the given menu has not been built in this request yet.
|
// the given menu has not been built in this request yet.
|
||||||
$tree = menu_tree_page_data($preferred_link['menu_name'], NULL, TRUE);
|
$tree = menu_tree_page_data($preferred_link['menu_name'], NULL, TRUE);
|
||||||
list($key, $curr) = each($tree);
|
$curr = current($tree);
|
||||||
|
next($tree);
|
||||||
}
|
}
|
||||||
// There is no link for the current path.
|
// There is no link for the current path.
|
||||||
else {
|
else {
|
||||||
@@ -2432,7 +2434,8 @@ function menu_set_active_trail($new_trail = NULL) {
|
|||||||
}
|
}
|
||||||
$tree = $curr['below'] ? $curr['below'] : array();
|
$tree = $curr['below'] ? $curr['below'] : array();
|
||||||
}
|
}
|
||||||
list($key, $curr) = each($tree);
|
$curr = current($tree);
|
||||||
|
next($tree);
|
||||||
}
|
}
|
||||||
// Make sure the current page is in the trail to build the page title, by
|
// Make sure the current page is in the trail to build the page title, by
|
||||||
// appending either the preferred link or the menu router item for the
|
// appending either the preferred link or the menu router item for the
|
||||||
|
|||||||
+10
-2
@@ -404,7 +404,11 @@ function module_enable($module_list, $enable_dependencies = TRUE) {
|
|||||||
// Create an associative array with weights as values.
|
// Create an associative array with weights as values.
|
||||||
$module_list = array_flip(array_values($module_list));
|
$module_list = array_flip(array_values($module_list));
|
||||||
|
|
||||||
while (list($module) = each($module_list)) {
|
// The array is iterated over manually (instead of using a foreach) because
|
||||||
|
// modules may be added to the list within the loop and we need to process
|
||||||
|
// them.
|
||||||
|
while ($module = key($module_list)) {
|
||||||
|
next($module_list);
|
||||||
if (!isset($module_data[$module])) {
|
if (!isset($module_data[$module])) {
|
||||||
// This module is not found in the filesystem, abort.
|
// This module is not found in the filesystem, abort.
|
||||||
return FALSE;
|
return FALSE;
|
||||||
@@ -540,7 +544,11 @@ function module_disable($module_list, $disable_dependents = TRUE) {
|
|||||||
$module_list = array_flip(array_values($module_list));
|
$module_list = array_flip(array_values($module_list));
|
||||||
|
|
||||||
$profile = drupal_get_profile();
|
$profile = drupal_get_profile();
|
||||||
while (list($module) = each($module_list)) {
|
// The array is iterated over manually (instead of using a foreach) because
|
||||||
|
// modules may be added to the list within the loop and we need to process
|
||||||
|
// them.
|
||||||
|
while ($module = key($module_list)) {
|
||||||
|
next($module_list);
|
||||||
if (!isset($module_data[$module]) || !$module_data[$module]->status) {
|
if (!isset($module_data[$module]) || !$module_data[$module]->status) {
|
||||||
// This module doesn't exist or is already disabled, skip it.
|
// This module doesn't exist or is already disabled, skip it.
|
||||||
unset($module_list[$module]);
|
unset($module_list[$module]);
|
||||||
|
|||||||
+29
-4
@@ -19,7 +19,6 @@
|
|||||||
* Does the work for registry_update().
|
* Does the work for registry_update().
|
||||||
*/
|
*/
|
||||||
function _registry_update() {
|
function _registry_update() {
|
||||||
|
|
||||||
// The registry serves as a central autoloader for all classes, including
|
// The registry serves as a central autoloader for all classes, including
|
||||||
// the database query builders. However, the registry rebuild process
|
// the database query builders. However, the registry rebuild process
|
||||||
// requires write ability to the database, which means having access to the
|
// requires write ability to the database, which means having access to the
|
||||||
@@ -33,6 +32,11 @@ function _registry_update() {
|
|||||||
require_once DRUPAL_ROOT . '/includes/database/select.inc';
|
require_once DRUPAL_ROOT . '/includes/database/select.inc';
|
||||||
require_once DRUPAL_ROOT . '/includes/database/' . $driver . '/query.inc';
|
require_once DRUPAL_ROOT . '/includes/database/' . $driver . '/query.inc';
|
||||||
|
|
||||||
|
// During the first registry rebuild in a request, we check all the files.
|
||||||
|
// During subsequent rebuilds, we only add new files. It makes the rebuilding
|
||||||
|
// process faster during installation of modules.
|
||||||
|
static $check_existing_files = TRUE;
|
||||||
|
|
||||||
// Get current list of modules and their files.
|
// Get current list of modules and their files.
|
||||||
$modules = db_query("SELECT * FROM {system} WHERE type = 'module'")->fetchAll();
|
$modules = db_query("SELECT * FROM {system} WHERE type = 'module'")->fetchAll();
|
||||||
// Get the list of files we are going to parse.
|
// Get the list of files we are going to parse.
|
||||||
@@ -55,6 +59,9 @@ function _registry_update() {
|
|||||||
$files["$filename"] = array('module' => '', 'weight' => 0);
|
$files["$filename"] = array('module' => '', 'weight' => 0);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Initialize an empty array for the unchanged files.
|
||||||
|
$unchanged_files = array();
|
||||||
|
|
||||||
$transaction = db_transaction();
|
$transaction = db_transaction();
|
||||||
try {
|
try {
|
||||||
// Allow modules to manually modify the list of files before the registry
|
// Allow modules to manually modify the list of files before the registry
|
||||||
@@ -63,11 +70,20 @@ function _registry_update() {
|
|||||||
// list can then be added to the list of files that the registry will parse,
|
// list can then be added to the list of files that the registry will parse,
|
||||||
// or modify attributes of a file.
|
// or modify attributes of a file.
|
||||||
drupal_alter('registry_files', $files, $modules);
|
drupal_alter('registry_files', $files, $modules);
|
||||||
|
|
||||||
foreach (registry_get_parsed_files() as $filename => $file) {
|
foreach (registry_get_parsed_files() as $filename => $file) {
|
||||||
// Add the hash for those files we have already parsed.
|
// Add the hash for those files we have already parsed.
|
||||||
if (isset($files[$filename])) {
|
if (isset($files[$filename])) {
|
||||||
|
if ($check_existing_files === TRUE) {
|
||||||
$files[$filename]['hash'] = $file['hash'];
|
$files[$filename]['hash'] = $file['hash'];
|
||||||
}
|
}
|
||||||
|
else {
|
||||||
|
// Ignore that file for this request, it has been parsed previously
|
||||||
|
// and it is unlikely it has changed.
|
||||||
|
unset($files[$filename]);
|
||||||
|
$unchanged_files[$filename] = $file;
|
||||||
|
}
|
||||||
|
}
|
||||||
else {
|
else {
|
||||||
// Flush the registry of resources in files that are no longer on disc
|
// Flush the registry of resources in files that are no longer on disc
|
||||||
// or are in files that no installed modules require to be parsed.
|
// or are in files that no installed modules require to be parsed.
|
||||||
@@ -79,8 +95,12 @@ function _registry_update() {
|
|||||||
->execute();
|
->execute();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
$parsed_files = _registry_parse_files($files);
|
$parsed_files = _registry_parse_files($files);
|
||||||
|
|
||||||
|
// Add unchanged files to the files.
|
||||||
|
$files += $unchanged_files;
|
||||||
|
|
||||||
$unchanged_resources = array();
|
$unchanged_resources = array();
|
||||||
$lookup_cache = array();
|
$lookup_cache = array();
|
||||||
if ($cache = cache_get('lookup_cache', 'cache_bootstrap')) {
|
if ($cache = cache_get('lookup_cache', 'cache_bootstrap')) {
|
||||||
@@ -89,12 +109,10 @@ function _registry_update() {
|
|||||||
foreach ($lookup_cache as $key => $file) {
|
foreach ($lookup_cache as $key => $file) {
|
||||||
// If the file for this cached resource is carried over unchanged from
|
// If the file for this cached resource is carried over unchanged from
|
||||||
// the last registry build, then we can safely re-cache it.
|
// the last registry build, then we can safely re-cache it.
|
||||||
if ($file && in_array($file, array_keys($files)) && !in_array($file, $parsed_files)) {
|
if ($file && isset($files[$file]) && !in_array($file, $parsed_files, TRUE)) {
|
||||||
$unchanged_resources[$key] = $file;
|
$unchanged_resources[$key] = $file;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
module_implements('', FALSE, TRUE);
|
|
||||||
_registry_check_code(REGISTRY_RESET_LOOKUP_CACHE);
|
|
||||||
}
|
}
|
||||||
catch (Exception $e) {
|
catch (Exception $e) {
|
||||||
$transaction->rollback();
|
$transaction->rollback();
|
||||||
@@ -102,6 +120,13 @@ function _registry_update() {
|
|||||||
throw $e;
|
throw $e;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
module_implements('', FALSE, TRUE);
|
||||||
|
_registry_check_code(REGISTRY_RESET_LOOKUP_CACHE);
|
||||||
|
|
||||||
|
// During the next run in this request, don't bother re-checking existing
|
||||||
|
// files.
|
||||||
|
$check_existing_files = FALSE;
|
||||||
|
|
||||||
// We have some unchanged resources, warm up the cache - no need to pay
|
// We have some unchanged resources, warm up the cache - no need to pay
|
||||||
// for looking them up again.
|
// for looking them up again.
|
||||||
if (count($unchanged_resources) > 0) {
|
if (count($unchanged_resources) > 0) {
|
||||||
|
|||||||
@@ -51,6 +51,38 @@ class DrupalRequestSanitizer {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Removes the destination if it is dangerous.
|
||||||
|
*
|
||||||
|
* Note this can only be called after common.inc has been included.
|
||||||
|
*
|
||||||
|
* @return bool
|
||||||
|
* TRUE if the destination has been removed from $_GET, FALSE if not.
|
||||||
|
*/
|
||||||
|
public static function cleanDestination() {
|
||||||
|
$dangerous_keys = array();
|
||||||
|
$log_sanitized_keys = variable_get('sanitize_input_logging', FALSE);
|
||||||
|
|
||||||
|
$parts = drupal_parse_url($_GET['destination']);
|
||||||
|
// If there is a query string, check its query parameters.
|
||||||
|
if (!empty($parts['query'])) {
|
||||||
|
$whitelist = variable_get('sanitize_input_whitelist', array());
|
||||||
|
|
||||||
|
self::stripDangerousValues($parts['query'], $whitelist, $dangerous_keys);
|
||||||
|
if (!empty($dangerous_keys)) {
|
||||||
|
// The destination is removed rather than sanitized to mirror the
|
||||||
|
// handling of external destinations.
|
||||||
|
unset($_GET['destination']);
|
||||||
|
unset($_REQUEST['destination']);
|
||||||
|
if ($log_sanitized_keys) {
|
||||||
|
trigger_error(format_string('Potentially unsafe destination removed from query string parameters (GET) because it contained the following keys: @keys', array('@keys' => implode(', ', $dangerous_keys))));
|
||||||
|
}
|
||||||
|
return TRUE;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Strips dangerous keys from the provided input.
|
* Strips dangerous keys from the provided input.
|
||||||
*
|
*
|
||||||
|
|||||||
+13
-11
@@ -1776,13 +1776,13 @@ function theme_link($variables) {
|
|||||||
* http://www.w3.org/TR/WCAG-TECHS/H42.html for more information.
|
* http://www.w3.org/TR/WCAG-TECHS/H42.html for more information.
|
||||||
*/
|
*/
|
||||||
function theme_links($variables) {
|
function theme_links($variables) {
|
||||||
$links = $variables['links'];
|
$links = (array) $variables['links'];
|
||||||
$attributes = $variables['attributes'];
|
$attributes = (array) $variables['attributes'];
|
||||||
$heading = $variables['heading'];
|
$heading = $variables['heading'];
|
||||||
global $language_url;
|
global $language_url;
|
||||||
$output = '';
|
$output = '';
|
||||||
|
|
||||||
if (count($links) > 0) {
|
if (!empty($links)) {
|
||||||
// Treat the heading first if it is present to prepend it to the
|
// Treat the heading first if it is present to prepend it to the
|
||||||
// list of links.
|
// list of links.
|
||||||
if (!empty($heading)) {
|
if (!empty($heading)) {
|
||||||
@@ -1995,7 +1995,7 @@ function theme_table($variables) {
|
|||||||
$empty = $variables['empty'];
|
$empty = $variables['empty'];
|
||||||
|
|
||||||
// Add sticky headers, if applicable.
|
// Add sticky headers, if applicable.
|
||||||
if (count($header) && $sticky) {
|
if (!empty($header) && $sticky) {
|
||||||
drupal_add_js('misc/tableheader.js');
|
drupal_add_js('misc/tableheader.js');
|
||||||
// Add 'sticky-enabled' class to the table to identify it for JS.
|
// Add 'sticky-enabled' class to the table to identify it for JS.
|
||||||
// This is needed to target tables constructed by this function.
|
// This is needed to target tables constructed by this function.
|
||||||
@@ -2009,7 +2009,7 @@ function theme_table($variables) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Format the table columns:
|
// Format the table columns:
|
||||||
if (count($colgroups)) {
|
if (!empty($colgroups)) {
|
||||||
foreach ($colgroups as $number => $colgroup) {
|
foreach ($colgroups as $number => $colgroup) {
|
||||||
$attributes = array();
|
$attributes = array();
|
||||||
|
|
||||||
@@ -2044,8 +2044,9 @@ function theme_table($variables) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Add the 'empty' row message if available.
|
// Add the 'empty' row message if available.
|
||||||
if (!count($rows) && $empty) {
|
if (empty($rows) && $empty) {
|
||||||
$header_count = 0;
|
$header_count = 0;
|
||||||
|
if (!empty($header)) {
|
||||||
foreach ($header as $header_cell) {
|
foreach ($header as $header_cell) {
|
||||||
if (is_array($header_cell)) {
|
if (is_array($header_cell)) {
|
||||||
$header_count += isset($header_cell['colspan']) ? $header_cell['colspan'] : 1;
|
$header_count += isset($header_cell['colspan']) ? $header_cell['colspan'] : 1;
|
||||||
@@ -2054,28 +2055,29 @@ function theme_table($variables) {
|
|||||||
$header_count++;
|
$header_count++;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
$rows[] = array(array('data' => $empty, 'colspan' => $header_count, 'class' => array('empty', 'message')));
|
$rows[] = array(array('data' => $empty, 'colspan' => $header_count, 'class' => array('empty', 'message')));
|
||||||
}
|
}
|
||||||
|
|
||||||
// Format the table header:
|
// Format the table header:
|
||||||
if (count($header)) {
|
if (!empty($header)) {
|
||||||
$ts = tablesort_init($header);
|
$ts = tablesort_init($header);
|
||||||
// HTML requires that the thead tag has tr tags in it followed by tbody
|
// HTML requires that the thead tag has tr tags in it followed by tbody
|
||||||
// tags. Using ternary operator to check and see if we have any rows.
|
// tags. Using ternary operator to check and see if we have any rows.
|
||||||
$output .= (count($rows) ? ' <thead><tr>' : ' <tr>');
|
$output .= (!empty($rows) ? ' <thead><tr>' : ' <tr>');
|
||||||
foreach ($header as $cell) {
|
foreach ($header as $cell) {
|
||||||
$cell = tablesort_header($cell, $header, $ts);
|
$cell = tablesort_header($cell, $header, $ts);
|
||||||
$output .= _theme_table_cell($cell, TRUE);
|
$output .= _theme_table_cell($cell, TRUE);
|
||||||
}
|
}
|
||||||
// Using ternary operator to close the tags based on whether or not there are rows
|
// Using ternary operator to close the tags based on whether or not there are rows
|
||||||
$output .= (count($rows) ? " </tr></thead>\n" : "</tr>\n");
|
$output .= (!empty($rows) ? " </tr></thead>\n" : "</tr>\n");
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
$ts = array();
|
$ts = array();
|
||||||
}
|
}
|
||||||
|
|
||||||
// Format the table rows:
|
// Format the table rows:
|
||||||
if (count($rows)) {
|
if (!empty($rows)) {
|
||||||
$output .= "<tbody>\n";
|
$output .= "<tbody>\n";
|
||||||
$flip = array('even' => 'odd', 'odd' => 'even');
|
$flip = array('even' => 'odd', 'odd' => 'even');
|
||||||
$class = 'even';
|
$class = 'even';
|
||||||
@@ -2095,7 +2097,7 @@ function theme_table($variables) {
|
|||||||
$attributes = array();
|
$attributes = array();
|
||||||
$no_striping = FALSE;
|
$no_striping = FALSE;
|
||||||
}
|
}
|
||||||
if (count($cells)) {
|
if (!empty($cells)) {
|
||||||
// Add odd/even class
|
// Add odd/even class
|
||||||
if (!$no_striping) {
|
if (!$no_striping) {
|
||||||
$class = $flip[$class];
|
$class = $flip[$class];
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
/vendor/
|
||||||
|
/phpunit.xml
|
||||||
|
/.composer.lock
|
||||||
|
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
language: php
|
||||||
|
|
||||||
|
sudo: false
|
||||||
|
|
||||||
|
php:
|
||||||
|
- '5.3'
|
||||||
|
- '5.4'
|
||||||
|
- '5.5'
|
||||||
|
- '5.6'
|
||||||
|
- '7.0'
|
||||||
|
- '7.1'
|
||||||
|
|
||||||
|
before_install:
|
||||||
|
- phpenv config-rm xdebug.ini
|
||||||
|
- composer self-update
|
||||||
|
|
||||||
|
install:
|
||||||
|
- composer install
|
||||||
|
|
||||||
|
script: phpunit
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
MIT License
|
||||||
|
|
||||||
|
Copyright (c) 2016 Denis Brumann
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
in the Software without restriction, including without limitation the rights
|
||||||
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all
|
||||||
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
|
SOFTWARE.
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
Polyfill unserialize [](https://travis-ci.org/dbrumann/polyfill-unserialize)
|
||||||
|
===
|
||||||
|
|
||||||
|
Backports unserialize options introduced in PHP 7.0 to older PHP versions.
|
||||||
|
This was originally designed as a Proof of Concept for Symfony Issue [#21090](https://github.com/symfony/symfony/pull/21090).
|
||||||
|
|
||||||
|
You can use this package in projects that rely on PHP versions older than PHP 7.0.
|
||||||
|
In case you are using PHP 7.0+ the original `unserialize()` will be used instead.
|
||||||
|
|
||||||
|
From the [documentation](https://secure.php.net/manual/en/function.unserialize.php):
|
||||||
|
|
||||||
|
> Warning: Do not pass untrusted user input to unserialize(). Unserialization can
|
||||||
|
> result in code being loaded and executed due to object instantiation
|
||||||
|
> and autoloading, and a malicious user may be able to exploit this.
|
||||||
|
|
||||||
|
This warning holds true even when `allowed_classes` is used.
|
||||||
|
|
||||||
|
Requirements
|
||||||
|
------------
|
||||||
|
|
||||||
|
- PHP 5.3+
|
||||||
|
|
||||||
|
Installation
|
||||||
|
------------
|
||||||
|
|
||||||
|
You can install this package via composer:
|
||||||
|
|
||||||
|
```
|
||||||
|
composer require brumann/polyfill-unserialize "^1.0"
|
||||||
|
```
|
||||||
|
|
||||||
|
Known Issues
|
||||||
|
------------
|
||||||
|
|
||||||
|
There is a mismatch in behavior when `allowed_classes` in `$options` is not
|
||||||
|
of the correct type (array or boolean). PHP 7.1 will issue a warning, whereas
|
||||||
|
PHP 7.0 will not. I opted to copy the behavior of the former.
|
||||||
|
|
||||||
|
Tests
|
||||||
|
-----
|
||||||
|
|
||||||
|
You can run the test suite using PHPUnit. It is intentionally not bundled as
|
||||||
|
dev dependency to make sure this package has the lowest restrictions on the
|
||||||
|
implementing system as possible.
|
||||||
|
|
||||||
|
Please read the [PHPUnit Manual](https://phpunit.de/manual/current/en/installation.html)
|
||||||
|
for information how to install it on your system.
|
||||||
|
|
||||||
|
You can run the test suite as follows:
|
||||||
|
|
||||||
|
```
|
||||||
|
phpunit -c phpunit.xml.dist tests/
|
||||||
|
```
|
||||||
|
|
||||||
|
Contributing
|
||||||
|
------------
|
||||||
|
|
||||||
|
This package is considered feature complete. As such I will likely not update it
|
||||||
|
unless there are security issues.
|
||||||
|
|
||||||
|
Should you find any bugs or have questions, feel free to submit an Issue or a Pull Request.
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
{
|
||||||
|
"name": "brumann/polyfill-unserialize",
|
||||||
|
"description": "Backports unserialize options introduced in PHP 7.0 to older PHP versions.",
|
||||||
|
"type": "library",
|
||||||
|
"license": "MIT",
|
||||||
|
"authors": [
|
||||||
|
{
|
||||||
|
"name": "Denis Brumann",
|
||||||
|
"email": "denis.brumann@sensiolabs.de"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"autoload": {
|
||||||
|
"psr-4": {
|
||||||
|
"Brumann\\Polyfill\\": "src/"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"autoload-dev": {
|
||||||
|
"psr-4": {
|
||||||
|
"Tests\\Brumann\\Polyfill\\": "tests/"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"minimum-stability": "stable",
|
||||||
|
"require": {
|
||||||
|
"php": "^5.3|^7.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
|
||||||
|
<phpunit
|
||||||
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||||
|
xsi:noNamespaceSchemaLocation="http://schema.phpunit.de/4.1/phpunit.xsd"
|
||||||
|
backupGlobals="false"
|
||||||
|
colors="true"
|
||||||
|
bootstrap="vendor/autoload.php"
|
||||||
|
>
|
||||||
|
<php>
|
||||||
|
<ini name="error_reporting" value="-1" />
|
||||||
|
</php>
|
||||||
|
|
||||||
|
<testsuites>
|
||||||
|
<testsuite name="Brumann\Polyfill Test Suite">
|
||||||
|
<directory>./tests/</directory>
|
||||||
|
</testsuite>
|
||||||
|
</testsuites>
|
||||||
|
|
||||||
|
<filter>
|
||||||
|
<whitelist>
|
||||||
|
<directory>./src/</directory>
|
||||||
|
</whitelist>
|
||||||
|
</filter>
|
||||||
|
</phpunit>
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Brumann\Polyfill;
|
||||||
|
|
||||||
|
final class Unserialize
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @see https://secure.php.net/manual/en/function.unserialize.php
|
||||||
|
*
|
||||||
|
* @param string $serialized Serialized data
|
||||||
|
* @param array $options Associative array containing options
|
||||||
|
*
|
||||||
|
* @return mixed
|
||||||
|
*/
|
||||||
|
public static function unserialize($serialized, array $options = array())
|
||||||
|
{
|
||||||
|
if (PHP_VERSION_ID >= 70000) {
|
||||||
|
return \unserialize($serialized, $options);
|
||||||
|
}
|
||||||
|
if (!array_key_exists('allowed_classes', $options)) {
|
||||||
|
$options['allowed_classes'] = true;
|
||||||
|
}
|
||||||
|
$allowedClasses = $options['allowed_classes'];
|
||||||
|
if (true === $allowedClasses) {
|
||||||
|
return \unserialize($serialized);
|
||||||
|
}
|
||||||
|
if (false === $allowedClasses) {
|
||||||
|
$allowedClasses = array();
|
||||||
|
}
|
||||||
|
if (!is_array($allowedClasses)) {
|
||||||
|
trigger_error(
|
||||||
|
'unserialize(): allowed_classes option should be array or boolean',
|
||||||
|
E_USER_WARNING
|
||||||
|
);
|
||||||
|
$allowedClasses = array();
|
||||||
|
}
|
||||||
|
|
||||||
|
$sanitizedSerialized = preg_replace_callback(
|
||||||
|
'/(^|;)O:\d+:"([^"]*)":(\d+):{/',
|
||||||
|
function ($match) use ($allowedClasses) {
|
||||||
|
list($completeMatch, $leftBorder, $className, $objectSize) = $match;
|
||||||
|
if (in_array($className, $allowedClasses)) {
|
||||||
|
return $completeMatch;
|
||||||
|
} else {
|
||||||
|
return sprintf(
|
||||||
|
'%sO:22:"__PHP_Incomplete_Class":%d:{s:27:"__PHP_Incomplete_Class_Name";%s',
|
||||||
|
$leftBorder,
|
||||||
|
$objectSize + 1, // size of object + 1 for added string
|
||||||
|
\serialize($className)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
},
|
||||||
|
$serialized
|
||||||
|
);
|
||||||
|
|
||||||
|
return \unserialize($sanitizedSerialized);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,112 @@
|
|||||||
|
/**
|
||||||
|
* For jQuery versions less than 3.4.0, this replaces the jQuery.extend
|
||||||
|
* function with the one from jQuery 3.4.0, slightly modified (documented
|
||||||
|
* below) to be compatible with older jQuery versions and browsers.
|
||||||
|
*
|
||||||
|
* This provides the Object.prototype pollution vulnerability fix to Drupal
|
||||||
|
* installations running older jQuery versions, including the versions shipped
|
||||||
|
* with Drupal core and https://www.drupal.org/project/jquery_update.
|
||||||
|
*
|
||||||
|
* @see https://github.com/jquery/jquery/pull/4333
|
||||||
|
*/
|
||||||
|
|
||||||
|
(function (jQuery) {
|
||||||
|
|
||||||
|
// Do not override jQuery.extend() if the jQuery version is already >=3.4.0.
|
||||||
|
var versionParts = jQuery.fn.jquery.split('.');
|
||||||
|
var majorVersion = parseInt(versionParts[0]);
|
||||||
|
var minorVersion = parseInt(versionParts[1]);
|
||||||
|
var patchVersion = parseInt(versionParts[2]);
|
||||||
|
var isPreReleaseVersion = (patchVersion.toString() !== versionParts[2]);
|
||||||
|
if (
|
||||||
|
(majorVersion > 3) ||
|
||||||
|
(majorVersion === 3 && minorVersion > 4) ||
|
||||||
|
(majorVersion === 3 && minorVersion === 4 && patchVersion > 0) ||
|
||||||
|
(majorVersion === 3 && minorVersion === 4 && patchVersion === 0 && !isPreReleaseVersion)
|
||||||
|
) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* This is almost verbatim copied from jQuery 3.4.0.
|
||||||
|
*
|
||||||
|
* Only two minor changes have been made:
|
||||||
|
* - The call to isFunction() is changed to jQuery.isFunction().
|
||||||
|
* - The two calls to Array.isArray() is changed to jQuery.isArray().
|
||||||
|
*
|
||||||
|
* The above two changes ensure compatibility with all older jQuery versions
|
||||||
|
* (1.4.4 - 3.3.1) and older browser versions (e.g., IE8).
|
||||||
|
*/
|
||||||
|
jQuery.extend = jQuery.fn.extend = function() {
|
||||||
|
var options, name, src, copy, copyIsArray, clone,
|
||||||
|
target = arguments[ 0 ] || {},
|
||||||
|
i = 1,
|
||||||
|
length = arguments.length,
|
||||||
|
deep = false;
|
||||||
|
|
||||||
|
// Handle a deep copy situation
|
||||||
|
if ( typeof target === "boolean" ) {
|
||||||
|
deep = target;
|
||||||
|
|
||||||
|
// Skip the boolean and the target
|
||||||
|
target = arguments[ i ] || {};
|
||||||
|
i++;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Handle case when target is a string or something (possible in deep copy)
|
||||||
|
if ( typeof target !== "object" && !jQuery.isFunction( target ) ) {
|
||||||
|
target = {};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Extend jQuery itself if only one argument is passed
|
||||||
|
if ( i === length ) {
|
||||||
|
target = this;
|
||||||
|
i--;
|
||||||
|
}
|
||||||
|
|
||||||
|
for ( ; i < length; i++ ) {
|
||||||
|
|
||||||
|
// Only deal with non-null/undefined values
|
||||||
|
if ( ( options = arguments[ i ] ) != null ) {
|
||||||
|
|
||||||
|
// Extend the base object
|
||||||
|
for ( name in options ) {
|
||||||
|
copy = options[ name ];
|
||||||
|
|
||||||
|
// Prevent Object.prototype pollution
|
||||||
|
// Prevent never-ending loop
|
||||||
|
if ( name === "__proto__" || target === copy ) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Recurse if we're merging plain objects or arrays
|
||||||
|
if ( deep && copy && ( jQuery.isPlainObject( copy ) ||
|
||||||
|
( copyIsArray = jQuery.isArray( copy ) ) ) ) {
|
||||||
|
src = target[ name ];
|
||||||
|
|
||||||
|
// Ensure proper type for the source value
|
||||||
|
if ( copyIsArray && !jQuery.isArray( src ) ) {
|
||||||
|
clone = [];
|
||||||
|
} else if ( !copyIsArray && !jQuery.isPlainObject( src ) ) {
|
||||||
|
clone = {};
|
||||||
|
} else {
|
||||||
|
clone = src;
|
||||||
|
}
|
||||||
|
copyIsArray = false;
|
||||||
|
|
||||||
|
// Never move original objects, clone them
|
||||||
|
target[ name ] = jQuery.extend( deep, clone, copy );
|
||||||
|
|
||||||
|
// Don't bring in undefined values
|
||||||
|
} else if ( copy !== undefined ) {
|
||||||
|
target[ name ] = copy;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Return the modified object
|
||||||
|
return target;
|
||||||
|
};
|
||||||
|
|
||||||
|
})(jQuery);
|
||||||
+33
-11
@@ -580,21 +580,43 @@ Drupal.tableDrag.prototype.dropRow = function (event, self) {
|
|||||||
* Get the mouse coordinates from the event (allowing for browser differences).
|
* Get the mouse coordinates from the event (allowing for browser differences).
|
||||||
*/
|
*/
|
||||||
Drupal.tableDrag.prototype.mouseCoords = function (event) {
|
Drupal.tableDrag.prototype.mouseCoords = function (event) {
|
||||||
// Complete support for pointer events was only introduced to jQuery in
|
|
||||||
// version 1.11.1; between versions 1.7 and 1.11.0 pointer events have the
|
|
||||||
// clientX and clientY properties undefined. In those cases, the properties
|
|
||||||
// must be retrieved from the event.originalEvent object instead.
|
|
||||||
var clientX = event.clientX || event.originalEvent.clientX;
|
|
||||||
var clientY = event.clientY || event.originalEvent.clientY;
|
|
||||||
|
|
||||||
if (event.pageX || event.pageY) {
|
// Match both null and undefined, but not zero, by using != null.
|
||||||
|
// See https://stackoverflow.com/questions/2647867/how-to-determine-if-variable-is-undefined-or-null
|
||||||
|
if (event.pageX != null && event.pageY != null) {
|
||||||
return {x: event.pageX, y: event.pageY};
|
return {x: event.pageX, y: event.pageY};
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
// Complete support for pointer events was only introduced to jQuery in
|
||||||
x: clientX + document.body.scrollLeft - document.body.clientLeft,
|
// version 1.11.1; between versions 1.7 and 1.11.0 pointer events have the
|
||||||
y: clientY + document.body.scrollTop - document.body.clientTop
|
// pageX and pageY properties undefined. In those cases, the properties must
|
||||||
};
|
// be retrieved from the event.originalEvent object instead.
|
||||||
|
if (event.originalEvent && event.originalEvent.pageX != null && event.originalEvent.pageY != null) {
|
||||||
|
return {x: event.originalEvent.pageX, y: event.originalEvent.pageY};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Some old browsers do not support MouseEvent.pageX and *.pageY at all.
|
||||||
|
// See https://developer.mozilla.org/en-US/docs/Web/API/MouseEvent/pageY
|
||||||
|
// For those, we look at event.clientX and event.clientY instead.
|
||||||
|
if (event.clientX == null || event.clientY == null) {
|
||||||
|
// In some jQuery versions, some events created by jQuery do not have
|
||||||
|
// clientX and clientY. But the original event might have.
|
||||||
|
if (!event.originalEvent) {
|
||||||
|
throw new Error("The event has no coordinates, and no event.originalEvent.");
|
||||||
|
}
|
||||||
|
event = event.originalEvent;
|
||||||
|
if (event.clientX == null || event.clientY == null) {
|
||||||
|
throw new Error("The original event has no coordinates.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Copied from jQuery.event.fix() in jQuery 1.4.1.
|
||||||
|
// In newer jQuery versions, this code is in jQuery.event.mouseHooks.filter().
|
||||||
|
var doc = document.documentElement, body = document.body;
|
||||||
|
var pageX = event.clientX + ( doc && doc.scrollLeft || body && body.scrollLeft || 0 ) - ( doc && doc.clientLeft || body && body.clientLeft || 0 );
|
||||||
|
var pageY = event.clientY + ( doc && doc.scrollTop || body && body.scrollTop || 0 ) - ( doc && doc.clientTop || body && body.clientTop || 0 );
|
||||||
|
|
||||||
|
return {x: pageX, y: pageY};
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -0,0 +1,79 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Drupal\Core\Security;
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Assertable;
|
||||||
|
use TYPO3\PharStreamWrapper\Helper;
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* An alternate PharExtensionInterceptor to support phar-based CLI tools.
|
||||||
|
*
|
||||||
|
* @see \TYPO3\PharStreamWrapper\Interceptor\PharExtensionInterceptor
|
||||||
|
*/
|
||||||
|
class PharExtensionInterceptor implements Assertable {
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determines whether phar file is allowed to execute.
|
||||||
|
*
|
||||||
|
* The phar file is allowed to execute if:
|
||||||
|
* - the base file name has a ".phar" suffix.
|
||||||
|
* - it is the CLI tool that has invoked the interceptor.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* The path of the phar file to check.
|
||||||
|
* @param string $command
|
||||||
|
* The command being carried out.
|
||||||
|
*
|
||||||
|
* @return bool
|
||||||
|
* TRUE if the phar file is allowed to execute.
|
||||||
|
*
|
||||||
|
* @throws Exception
|
||||||
|
* Thrown when the file is not allowed to execute.
|
||||||
|
*/
|
||||||
|
public function assert($path, $command) {
|
||||||
|
if ($this->baseFileContainsPharExtension($path)) {
|
||||||
|
return TRUE;
|
||||||
|
}
|
||||||
|
throw new Exception(
|
||||||
|
sprintf(
|
||||||
|
'Unexpected file extension in "%s"',
|
||||||
|
$path
|
||||||
|
),
|
||||||
|
1535198703
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determines if a path has a .phar extension or invoked execution.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* The path of the phar file to check.
|
||||||
|
*
|
||||||
|
* @return bool
|
||||||
|
* TRUE if the file has a .phar extension or if the execution has been
|
||||||
|
* invoked by the phar file.
|
||||||
|
*/
|
||||||
|
private function baseFileContainsPharExtension($path) {
|
||||||
|
$baseFile = Helper::determineBaseFile($path);
|
||||||
|
if ($baseFile === NULL) {
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
// If the stream wrapper is registered by invoking a phar file that does
|
||||||
|
// not not have .phar extension then this should be allowed. For
|
||||||
|
// example, some CLI tools recommend removing the extension.
|
||||||
|
$backtrace = debug_backtrace(DEBUG_BACKTRACE_IGNORE_ARGS);
|
||||||
|
// Find the last entry in the backtrace containing a 'file' key as
|
||||||
|
// sometimes the last caller is executed outside the scope of a file. For
|
||||||
|
// example, this occurs with shutdown functions.
|
||||||
|
do {
|
||||||
|
$caller = array_pop($backtrace);
|
||||||
|
} while (empty($caller['file']) && !empty($backtrace));
|
||||||
|
if (isset($caller['file']) && $baseFile === Helper::determineBaseFile($caller['file'])) {
|
||||||
|
return TRUE;
|
||||||
|
}
|
||||||
|
$fileExtension = pathinfo($baseFile, PATHINFO_EXTENSION);
|
||||||
|
return strtolower($fileExtension) === 'phar';
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
.idea
|
||||||
|
vendor/
|
||||||
|
composer.lock
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
MIT License
|
||||||
|
|
||||||
|
Copyright (c) 2018 TYPO3 project - https://typo3.org/
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
in the Software without restriction, including without limitation the rights
|
||||||
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all
|
||||||
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
|
SOFTWARE.
|
||||||
@@ -0,0 +1,218 @@
|
|||||||
|
[](https://scrutinizer-ci.com/g/TYPO3/phar-stream-wrapper/?branch=v2)
|
||||||
|
[](https://travis-ci.org/TYPO3/phar-stream-wrapper)
|
||||||
|
|
||||||
|
# PHP Phar Stream Wrapper
|
||||||
|
|
||||||
|
## Abstract & History
|
||||||
|
|
||||||
|
Based on Sam Thomas' findings concerning
|
||||||
|
[insecure deserialization in combination with obfuscation strategies](https://blog.secarma.co.uk/labs/near-phar-dangerous-unserialization-wherever-you-are)
|
||||||
|
allowing to hide Phar files inside valid image resources, the TYPO3 project
|
||||||
|
decided back then to introduce a `PharStreamWrapper` to intercept invocations
|
||||||
|
of the `phar://` stream in PHP and only allow usage for defined locations in
|
||||||
|
the file system.
|
||||||
|
|
||||||
|
Since the TYPO3 mission statement is **inspiring people to share**, we thought
|
||||||
|
it would be helpful for others to release our `PharStreamWrapper` as standalone
|
||||||
|
package to the PHP community.
|
||||||
|
|
||||||
|
The mentioned security issue was reported to TYPO3 on 10th June 2018 by Sam Thomas
|
||||||
|
and has been addressed concerning the specific attack vector and for this generic
|
||||||
|
`PharStreamWrapper` in TYPO3 versions 7.6.30 LTS, 8.7.17 LTS and 9.3.1 on 12th
|
||||||
|
July 2018.
|
||||||
|
|
||||||
|
* https://typo3.org/security/advisory/typo3-core-sa-2018-002/
|
||||||
|
* https://blog.secarma.co.uk/labs/near-phar-dangerous-unserialization-wherever-you-are
|
||||||
|
* https://youtu.be/GePBmsNJw6Y
|
||||||
|
|
||||||
|
## License
|
||||||
|
|
||||||
|
In general the TYPO3 core is released under the GNU General Public License version
|
||||||
|
2 or any later version (`GPL-2.0-or-later`). In order to avoid licensing issues and
|
||||||
|
incompatibilities this `PharStreamWrapper` is licenced under the MIT License. In case
|
||||||
|
you duplicate or modify source code, credits are not required but really appreciated.
|
||||||
|
|
||||||
|
## Credits
|
||||||
|
|
||||||
|
Thanks to [Alex Pott](https://github.com/alexpott), Drupal for creating
|
||||||
|
back-ports of all sources in order to provide compatibility with PHP v5.3.
|
||||||
|
|
||||||
|
## Installation
|
||||||
|
|
||||||
|
The `PharStreamWrapper` is provided as composer package `typo3/phar-stream-wrapper`
|
||||||
|
and has minimum requirements of PHP v5.3 ([`v2`](https://github.com/TYPO3/phar-stream-wrapper/tree/v2) branch) and PHP v7.0 ([`master`](https://github.com/TYPO3/phar-stream-wrapper) branch).
|
||||||
|
|
||||||
|
### Installation for PHP v7.0
|
||||||
|
|
||||||
|
```
|
||||||
|
composer require typo3/phar-stream-wrapper ^3.0
|
||||||
|
```
|
||||||
|
|
||||||
|
### Installation for PHP v5.3
|
||||||
|
|
||||||
|
```
|
||||||
|
composer require typo3/phar-stream-wrapper ^2.0
|
||||||
|
```
|
||||||
|
|
||||||
|
## Example
|
||||||
|
|
||||||
|
The following example is bundled within this package, the shown
|
||||||
|
`PharExtensionInterceptor` denies all stream wrapper invocations files
|
||||||
|
not having the `.phar` suffix. Interceptor logic has to be individual and
|
||||||
|
adjusted to according requirements.
|
||||||
|
|
||||||
|
```
|
||||||
|
$behavior = new \TYPO3\PharStreamWrapper\Behavior();
|
||||||
|
\TYPO3\PharStreamWrapper\Manager::initialize(
|
||||||
|
$behavior->withAssertion(new PharExtensionInterceptor())
|
||||||
|
);
|
||||||
|
|
||||||
|
if (in_array('phar', stream_get_wrappers())) {
|
||||||
|
stream_wrapper_unregister('phar');
|
||||||
|
stream_wrapper_register('phar', 'TYPO3\\PharStreamWrapper\\PharStreamWrapper');
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
* `PharStreamWrapper` defined as class reference will be instantiated each time
|
||||||
|
`phar://` streams shall be processed.
|
||||||
|
* `Manager` as singleton pattern being called by `PharStreamWrapper` instances
|
||||||
|
in order to retrieve individual behavior and settings.
|
||||||
|
* `Behavior` holds reference to interceptor(s) that shall assert correct/allowed
|
||||||
|
invocation of a given `$path` for a given `$command`. Interceptors implement
|
||||||
|
the interface `Assertable`. Interceptors can act individually on following
|
||||||
|
commands or handle all of them in case not defined specifically:
|
||||||
|
+ `COMMAND_DIR_OPENDIR`
|
||||||
|
+ `COMMAND_MKDIR`
|
||||||
|
+ `COMMAND_RENAME`
|
||||||
|
+ `COMMAND_RMDIR`
|
||||||
|
+ `COMMAND_STEAM_METADATA`
|
||||||
|
+ `COMMAND_STREAM_OPEN`
|
||||||
|
+ `COMMAND_UNLINK`
|
||||||
|
+ `COMMAND_URL_STAT`
|
||||||
|
|
||||||
|
## Interceptors
|
||||||
|
|
||||||
|
The following interceptor is shipped with the package and ready to use in order
|
||||||
|
to block any Phar invocation of files not having a `.phar` suffix. Besides that
|
||||||
|
individual interceptors are possible of course.
|
||||||
|
|
||||||
|
```
|
||||||
|
class PharExtensionInterceptor implements Assertable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Determines whether the base file name has a ".phar" suffix.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function assert($path, $command)
|
||||||
|
{
|
||||||
|
if ($this->baseFileContainsPharExtension($path)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
throw new Exception(
|
||||||
|
sprintf(
|
||||||
|
'Unexpected file extension in "%s"',
|
||||||
|
$path
|
||||||
|
),
|
||||||
|
1535198703
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private function baseFileContainsPharExtension($path)
|
||||||
|
{
|
||||||
|
$baseFile = Helper::determineBaseFile($path);
|
||||||
|
if ($baseFile === null) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
$fileExtension = pathinfo($baseFile, PATHINFO_EXTENSION);
|
||||||
|
return strtolower($fileExtension) === 'phar';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### ConjunctionInterceptor
|
||||||
|
|
||||||
|
This interceptor combines multiple interceptors implementing `Assertable`.
|
||||||
|
It succeeds when all nested interceptors succeed as well (logical `AND`).
|
||||||
|
|
||||||
|
```
|
||||||
|
$behavior = new \TYPO3\PharStreamWrapper\Behavior();
|
||||||
|
\TYPO3\PharStreamWrapper\Manager::initialize(
|
||||||
|
$behavior->withAssertion(new ConjunctionInterceptor(array(
|
||||||
|
new PharExtensionInterceptor(),
|
||||||
|
new PharMetaDataInterceptor()
|
||||||
|
)))
|
||||||
|
);
|
||||||
|
```
|
||||||
|
|
||||||
|
### PharExtensionInterceptor
|
||||||
|
|
||||||
|
This (basic) interceptor just checks whether the invoked Phar archive has
|
||||||
|
an according `.phar` file extension. Resolving symbolic links as well as
|
||||||
|
Phar internal alias resolving are considered as well.
|
||||||
|
|
||||||
|
```
|
||||||
|
$behavior = new \TYPO3\PharStreamWrapper\Behavior();
|
||||||
|
\TYPO3\PharStreamWrapper\Manager::initialize(
|
||||||
|
$behavior->withAssertion(new PharExtensionInterceptor())
|
||||||
|
);
|
||||||
|
```
|
||||||
|
|
||||||
|
### PharMetaDataInterceptor
|
||||||
|
|
||||||
|
This interceptor is actually checking serialized Phar meta-data against
|
||||||
|
PHP objects and would consider a Phar archive malicious in case not only
|
||||||
|
scalar values are found. A custom low-level `Phar\Reader` is used in order to
|
||||||
|
avoid using PHP's `Phar` object which would trigger the initial vulnerability.
|
||||||
|
|
||||||
|
```
|
||||||
|
$behavior = new \TYPO3\PharStreamWrapper\Behavior();
|
||||||
|
\TYPO3\PharStreamWrapper\Manager::initialize(
|
||||||
|
$behavior->withAssertion(new PharMetaDataInterceptor())
|
||||||
|
);
|
||||||
|
```
|
||||||
|
|
||||||
|
## Reader
|
||||||
|
|
||||||
|
* `Phar\Reader::__construct(string $fileName)`: Creates low-level reader for Phar archive
|
||||||
|
* `Phar\Reader::resolveContainer(): Phar\Container`: Resolves model representing Phar archive
|
||||||
|
* `Phar\Container::getStub(): Phar\Stub`: Resolves (plain PHP) stub section of Phar archive
|
||||||
|
* `Phar\Container::getManifest(): Phar\Manifest`: Resolves parsed Phar archive manifest as
|
||||||
|
documented at http://php.net/manual/en/phar.fileformat.manifestfile.php
|
||||||
|
* `Phar\Stub::getMappedAlias(): string`: Resolves internal Phar archive alias defined in stub
|
||||||
|
using `Phar::mapPhar('alias.phar')` - actually the plain PHP source is analyzed here
|
||||||
|
* `Phar\Manifest::getAlias(): string` - Resolves internal Phar archive alias defined in manifest
|
||||||
|
using `Phar::setAlias('alias.phar')`
|
||||||
|
* `Phar\Manifest::getMetaData(): string`: Resolves serialized Phar archive meta-data
|
||||||
|
* `Phar\Manifest::deserializeMetaData(): mixed`: Resolves deserialized Phar archive meta-data
|
||||||
|
containing only scalar values - in case an object is determined, an according
|
||||||
|
`Phar\DeserializationException` will be thrown
|
||||||
|
|
||||||
|
```
|
||||||
|
$reader = new Phar\Reader('example.phar');
|
||||||
|
var_dump($reader->resolveContainer()->getManifest()->deserializeMetaData());
|
||||||
|
```
|
||||||
|
|
||||||
|
## Helper
|
||||||
|
|
||||||
|
* `Helper::determineBaseFile(string $path): string`: Determines base file that can be
|
||||||
|
accessed using the regular file system. For instance the following path
|
||||||
|
`phar:///home/user/bundle.phar/content.txt` would be resolved to
|
||||||
|
`/home/user/bundle.phar`.
|
||||||
|
* `Helper::resetOpCache()`: Resets PHP's OPcache if enabled as work-around for
|
||||||
|
issues in `include()` or `require()` calls and OPcache delivering wrong
|
||||||
|
results. More details can be found in PHP's bug tracker, for instance like
|
||||||
|
https://bugs.php.net/bug.php?id=66569
|
||||||
|
|
||||||
|
## Security Contact
|
||||||
|
|
||||||
|
In case of finding additional security issues in the TYPO3 project or in this
|
||||||
|
`PharStreamWrapper` package in particular, please get in touch with the
|
||||||
|
[TYPO3 Security Team](mailto:security@typo3.org).
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
{
|
||||||
|
"name": "typo3/phar-stream-wrapper",
|
||||||
|
"description": "Interceptors for PHP's native phar:// stream handling",
|
||||||
|
"type": "library",
|
||||||
|
"license": "MIT",
|
||||||
|
"homepage": "https://typo3.org/",
|
||||||
|
"keywords": ["php", "phar", "stream-wrapper", "security"],
|
||||||
|
"require": {
|
||||||
|
"php": "^5.3.3|^7.0",
|
||||||
|
"ext-fileinfo": "*",
|
||||||
|
"ext-json": "*",
|
||||||
|
"brumann/polyfill-unserialize": "^1.0"
|
||||||
|
},
|
||||||
|
"require-dev": {
|
||||||
|
"ext-xdebug": "*",
|
||||||
|
"phpunit/phpunit": "^4.8.36"
|
||||||
|
},
|
||||||
|
"autoload": {
|
||||||
|
"psr-4": {
|
||||||
|
"TYPO3\\PharStreamWrapper\\": "src/"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"autoload-dev": {
|
||||||
|
"psr-4": {
|
||||||
|
"TYPO3\\PharStreamWrapper\\Tests\\": "tests/"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
interface Assertable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function assert($path, $command);
|
||||||
|
}
|
||||||
@@ -0,0 +1,124 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
class Behavior implements Assertable
|
||||||
|
{
|
||||||
|
const COMMAND_DIR_OPENDIR = 'dir_opendir';
|
||||||
|
const COMMAND_MKDIR = 'mkdir';
|
||||||
|
const COMMAND_RENAME = 'rename';
|
||||||
|
const COMMAND_RMDIR = 'rmdir';
|
||||||
|
const COMMAND_STEAM_METADATA = 'stream_metadata';
|
||||||
|
const COMMAND_STREAM_OPEN = 'stream_open';
|
||||||
|
const COMMAND_UNLINK = 'unlink';
|
||||||
|
const COMMAND_URL_STAT = 'url_stat';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string[]
|
||||||
|
*/
|
||||||
|
private $availableCommands = array(
|
||||||
|
self::COMMAND_DIR_OPENDIR,
|
||||||
|
self::COMMAND_MKDIR,
|
||||||
|
self::COMMAND_RENAME,
|
||||||
|
self::COMMAND_RMDIR,
|
||||||
|
self::COMMAND_STEAM_METADATA,
|
||||||
|
self::COMMAND_STREAM_OPEN,
|
||||||
|
self::COMMAND_UNLINK,
|
||||||
|
self::COMMAND_URL_STAT,
|
||||||
|
);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var Assertable[]
|
||||||
|
*/
|
||||||
|
private $assertions;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param Assertable $assertable
|
||||||
|
* @return static
|
||||||
|
*/
|
||||||
|
public function withAssertion(Assertable $assertable)
|
||||||
|
{
|
||||||
|
$commands = func_get_args();
|
||||||
|
array_shift($commands);
|
||||||
|
$this->assertCommands($commands);
|
||||||
|
$commands = $commands ?: $this->availableCommands;
|
||||||
|
|
||||||
|
$target = clone $this;
|
||||||
|
foreach ($commands as $command) {
|
||||||
|
$target->assertions[$command] = $assertable;
|
||||||
|
}
|
||||||
|
return $target;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function assert($path, $command)
|
||||||
|
{
|
||||||
|
$this->assertCommand($command);
|
||||||
|
$this->assertAssertionCompleteness();
|
||||||
|
|
||||||
|
return $this->assertions[$command]->assert($path, $command);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array $commands
|
||||||
|
*/
|
||||||
|
private function assertCommands(array $commands)
|
||||||
|
{
|
||||||
|
$unknownCommands = array_diff($commands, $this->availableCommands);
|
||||||
|
if (empty($unknownCommands)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
throw new \LogicException(
|
||||||
|
sprintf(
|
||||||
|
'Unknown commands: %s',
|
||||||
|
implode(', ', $unknownCommands)
|
||||||
|
),
|
||||||
|
1535189881
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function assertCommand($command)
|
||||||
|
{
|
||||||
|
if (in_array($command, $this->availableCommands, true)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
throw new \LogicException(
|
||||||
|
sprintf(
|
||||||
|
'Unknown command "%s"',
|
||||||
|
$command
|
||||||
|
),
|
||||||
|
1535189882
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function assertAssertionCompleteness()
|
||||||
|
{
|
||||||
|
$undefinedAssertions = array_diff(
|
||||||
|
$this->availableCommands,
|
||||||
|
array_keys($this->assertions)
|
||||||
|
);
|
||||||
|
if (empty($undefinedAssertions)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
throw new \LogicException(
|
||||||
|
sprintf(
|
||||||
|
'Missing assertions for commands: %s',
|
||||||
|
implode(', ', $undefinedAssertions)
|
||||||
|
),
|
||||||
|
1535189883
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Resolver\PharInvocation;
|
||||||
|
|
||||||
|
interface Collectable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function has(PharInvocation $invocation);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @param null $flags
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function collect(PharInvocation $invocation, $flags = null);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param callable $callback
|
||||||
|
* @param bool $reverse
|
||||||
|
* @return null|PharInvocation
|
||||||
|
*/
|
||||||
|
public function findByCallback($callback, $reverse = false);
|
||||||
|
}
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
class Exception extends \RuntimeException
|
||||||
|
{
|
||||||
|
}
|
||||||
@@ -0,0 +1,199 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Helper provides low-level tools on file name resolving. However it does not
|
||||||
|
* (and should not) maintain any runtime state information. In order to resolve
|
||||||
|
* Phar archive paths according resolvers have to be used.
|
||||||
|
*
|
||||||
|
* @see \TYPO3\PharStreamWrapper\Resolvable::resolve()
|
||||||
|
*/
|
||||||
|
class Helper
|
||||||
|
{
|
||||||
|
/*
|
||||||
|
* Resets PHP's OPcache if enabled as work-around for issues in `include()`
|
||||||
|
* or `require()` calls and OPcache delivering wrong results.
|
||||||
|
*
|
||||||
|
* @see https://bugs.php.net/bug.php?id=66569
|
||||||
|
*/
|
||||||
|
public static function resetOpCache()
|
||||||
|
{
|
||||||
|
if (function_exists('opcache_reset')
|
||||||
|
&& function_exists('opcache_get_status')
|
||||||
|
) {
|
||||||
|
$status = opcache_get_status();
|
||||||
|
if (!empty($status['opcache_enabled'])) {
|
||||||
|
opcache_reset();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determines base file that can be accessed using the regular file system.
|
||||||
|
* For e.g. "phar:///home/user/bundle.phar/content.txt" that would result
|
||||||
|
* into "/home/user/bundle.phar".
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @return string|null
|
||||||
|
*/
|
||||||
|
public static function determineBaseFile($path)
|
||||||
|
{
|
||||||
|
$parts = explode('/', static::normalizePath($path));
|
||||||
|
|
||||||
|
while (count($parts)) {
|
||||||
|
$currentPath = implode('/', $parts);
|
||||||
|
if (@is_file($currentPath)) {
|
||||||
|
return $currentPath;
|
||||||
|
}
|
||||||
|
array_pop($parts);
|
||||||
|
}
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public static function hasPharPrefix($path)
|
||||||
|
{
|
||||||
|
return stripos($path, 'phar://') === 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public static function removePharPrefix($path)
|
||||||
|
{
|
||||||
|
$path = trim($path);
|
||||||
|
if (!static::hasPharPrefix($path)) {
|
||||||
|
return $path;
|
||||||
|
}
|
||||||
|
return substr($path, 7);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Normalizes a path, removes phar:// prefix, fixes Windows directory
|
||||||
|
* separators. Result is without trailing slash.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public static function normalizePath($path)
|
||||||
|
{
|
||||||
|
return rtrim(
|
||||||
|
static::normalizeWindowsPath(
|
||||||
|
static::removePharPrefix($path)
|
||||||
|
),
|
||||||
|
'/'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Fixes a path for windows-backslashes and reduces double-slashes to single slashes
|
||||||
|
*
|
||||||
|
* @param string $path File path to process
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
private static function normalizeWindowsPath($path)
|
||||||
|
{
|
||||||
|
return str_replace('\\', '/', $path);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves all dots, slashes and removes spaces after or before a path...
|
||||||
|
*
|
||||||
|
* @param string $path Input string
|
||||||
|
* @return string Canonical path, always without trailing slash
|
||||||
|
*/
|
||||||
|
private static function getCanonicalPath($path)
|
||||||
|
{
|
||||||
|
$path = static::normalizeWindowsPath($path);
|
||||||
|
|
||||||
|
$absolutePathPrefix = '';
|
||||||
|
if (static::isAbsolutePath($path)) {
|
||||||
|
if (static::isWindows() && strpos($path, ':/') === 1) {
|
||||||
|
$absolutePathPrefix = substr($path, 0, 3);
|
||||||
|
$path = substr($path, 3);
|
||||||
|
} else {
|
||||||
|
$path = ltrim($path, '/');
|
||||||
|
$absolutePathPrefix = '/';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$pathParts = explode('/', $path);
|
||||||
|
$pathPartsLength = count($pathParts);
|
||||||
|
for ($partCount = 0; $partCount < $pathPartsLength; $partCount++) {
|
||||||
|
// double-slashes in path: remove element
|
||||||
|
if ($pathParts[$partCount] === '') {
|
||||||
|
array_splice($pathParts, $partCount, 1);
|
||||||
|
$partCount--;
|
||||||
|
$pathPartsLength--;
|
||||||
|
}
|
||||||
|
// "." in path: remove element
|
||||||
|
if ((isset($pathParts[$partCount]) ? $pathParts[$partCount] : '') === '.') {
|
||||||
|
array_splice($pathParts, $partCount, 1);
|
||||||
|
$partCount--;
|
||||||
|
$pathPartsLength--;
|
||||||
|
}
|
||||||
|
// ".." in path:
|
||||||
|
if ((isset($pathParts[$partCount]) ? $pathParts[$partCount] : '') === '..') {
|
||||||
|
if ($partCount === 0) {
|
||||||
|
array_splice($pathParts, $partCount, 1);
|
||||||
|
$partCount--;
|
||||||
|
$pathPartsLength--;
|
||||||
|
} elseif ($partCount >= 1) {
|
||||||
|
// Rremove this and previous element
|
||||||
|
array_splice($pathParts, $partCount - 1, 2);
|
||||||
|
$partCount -= 2;
|
||||||
|
$pathPartsLength -= 2;
|
||||||
|
} elseif ($absolutePathPrefix) {
|
||||||
|
// can't go higher than root dir
|
||||||
|
// simply remove this part and continue
|
||||||
|
array_splice($pathParts, $partCount, 1);
|
||||||
|
$partCount--;
|
||||||
|
$pathPartsLength--;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $absolutePathPrefix . implode('/', $pathParts);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Checks if the $path is absolute or relative (detecting either '/' or
|
||||||
|
* 'x:/' as first part of string) and returns TRUE if so.
|
||||||
|
*
|
||||||
|
* @param string $path File path to evaluate
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private static function isAbsolutePath($path)
|
||||||
|
{
|
||||||
|
// Path starting with a / is always absolute, on every system
|
||||||
|
// On Windows also a path starting with a drive letter is absolute: X:/
|
||||||
|
return (isset($path[0]) ? $path[0] : null) === '/'
|
||||||
|
|| static::isWindows() && (
|
||||||
|
strpos($path, ':/') === 1
|
||||||
|
|| strpos($path, ':\\') === 1
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private static function isWindows()
|
||||||
|
{
|
||||||
|
return stripos(PHP_OS, 'WIN') === 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,88 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Interceptor;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Assertable;
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
|
||||||
|
class ConjunctionInterceptor implements Assertable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @var Assertable[]
|
||||||
|
*/
|
||||||
|
private $assertions;
|
||||||
|
|
||||||
|
public function __construct(array $assertions)
|
||||||
|
{
|
||||||
|
$this->assertAssertions($assertions);
|
||||||
|
$this->assertions = $assertions;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Executes assertions based on all contained assertions.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function assert($path, $command)
|
||||||
|
{
|
||||||
|
if ($this->invokeAssertions($path, $command)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
throw new Exception(
|
||||||
|
sprintf(
|
||||||
|
'Assertion failed in "%s"',
|
||||||
|
$path
|
||||||
|
),
|
||||||
|
1539625084
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param Assertable[] $assertions
|
||||||
|
*/
|
||||||
|
private function assertAssertions(array $assertions)
|
||||||
|
{
|
||||||
|
foreach ($assertions as $assertion) {
|
||||||
|
if (!$assertion instanceof Assertable) {
|
||||||
|
throw new \InvalidArgumentException(
|
||||||
|
sprintf(
|
||||||
|
'Instance %s must implement Assertable',
|
||||||
|
get_class($assertion)
|
||||||
|
),
|
||||||
|
1539624719
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private function invokeAssertions($path, $command)
|
||||||
|
{
|
||||||
|
try {
|
||||||
|
foreach ($this->assertions as $assertion) {
|
||||||
|
if (!$assertion->assert($path, $command)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (Exception $exception) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Interceptor;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Assertable;
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
use TYPO3\PharStreamWrapper\Manager;
|
||||||
|
|
||||||
|
class PharExtensionInterceptor implements Assertable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Determines whether the base file name has a ".phar" suffix.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function assert($path, $command)
|
||||||
|
{
|
||||||
|
if ($this->baseFileContainsPharExtension($path)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
throw new Exception(
|
||||||
|
sprintf(
|
||||||
|
'Unexpected file extension in "%s"',
|
||||||
|
$path
|
||||||
|
),
|
||||||
|
1535198703
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private function baseFileContainsPharExtension($path)
|
||||||
|
{
|
||||||
|
$invocation = Manager::instance()->resolve($path);
|
||||||
|
if ($invocation === null) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
$fileExtension = pathinfo($invocation->getBaseName(), PATHINFO_EXTENSION);
|
||||||
|
return strtolower($fileExtension) === 'phar';
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,73 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Interceptor;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Assertable;
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
use TYPO3\PharStreamWrapper\Manager;
|
||||||
|
use TYPO3\PharStreamWrapper\Phar\DeserializationException;
|
||||||
|
use TYPO3\PharStreamWrapper\Phar\Reader;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @internal Experimental implementation of checking against serialized objects in Phar meta-data
|
||||||
|
* @internal This functionality has not been 100% pentested...
|
||||||
|
*/
|
||||||
|
class PharMetaDataInterceptor implements Assertable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Determines whether the according Phar archive contains
|
||||||
|
* (potential insecure) serialized objects.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function assert($path, $command)
|
||||||
|
{
|
||||||
|
if ($this->baseFileDoesNotHaveMetaDataIssues($path)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
throw new Exception(
|
||||||
|
sprintf(
|
||||||
|
'Problematic meta-data in "%s"',
|
||||||
|
$path
|
||||||
|
),
|
||||||
|
1539632368
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private function baseFileDoesNotHaveMetaDataIssues($path)
|
||||||
|
{
|
||||||
|
$invocation = Manager::instance()->resolve($path);
|
||||||
|
if ($invocation === null) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
// directly return in case invocation was checked before
|
||||||
|
if ($invocation->getVariable(__CLASS__) === true) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
// otherwise analyze meta-data
|
||||||
|
try {
|
||||||
|
$reader = new Reader($invocation->getBaseName());
|
||||||
|
$reader->resolveContainer()->getManifest()->deserializeMetaData();
|
||||||
|
$invocation->setVariable(__CLASS__, true);
|
||||||
|
} catch (DeserializationException $exception) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,135 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Resolver\PharInvocation;
|
||||||
|
use TYPO3\PharStreamWrapper\Resolver\PharInvocationCollection;
|
||||||
|
use TYPO3\PharStreamWrapper\Resolver\PharInvocationResolver;
|
||||||
|
|
||||||
|
class Manager
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @var self
|
||||||
|
*/
|
||||||
|
private static $instance;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var Behavior
|
||||||
|
*/
|
||||||
|
private $behavior;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var Resolvable
|
||||||
|
*/
|
||||||
|
private $resolver;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var Collectable
|
||||||
|
*/
|
||||||
|
private $collection;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param Behavior $behaviour
|
||||||
|
* @param Resolvable $resolver
|
||||||
|
* @param Collectable $collection
|
||||||
|
* @return self
|
||||||
|
*/
|
||||||
|
public static function initialize(
|
||||||
|
Behavior $behaviour,
|
||||||
|
Resolvable $resolver = null,
|
||||||
|
Collectable $collection = null
|
||||||
|
) {
|
||||||
|
if (self::$instance === null) {
|
||||||
|
self::$instance = new self($behaviour, $resolver, $collection);
|
||||||
|
return self::$instance;
|
||||||
|
}
|
||||||
|
throw new \LogicException(
|
||||||
|
'Manager can only be initialized once',
|
||||||
|
1535189871
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return self
|
||||||
|
*/
|
||||||
|
public static function instance()
|
||||||
|
{
|
||||||
|
if (self::$instance !== null) {
|
||||||
|
return self::$instance;
|
||||||
|
}
|
||||||
|
throw new \LogicException(
|
||||||
|
'Manager needs to be initialized first',
|
||||||
|
1535189872
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public static function destroy()
|
||||||
|
{
|
||||||
|
if (self::$instance === null) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
self::$instance = null;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param Behavior $behaviour
|
||||||
|
* @param Resolvable $resolver
|
||||||
|
* @param Collectable $collection
|
||||||
|
*/
|
||||||
|
private function __construct(
|
||||||
|
Behavior $behaviour,
|
||||||
|
Resolvable $resolver = null,
|
||||||
|
Collectable $collection = null
|
||||||
|
) {
|
||||||
|
if ($collection === null) {
|
||||||
|
$collection = new PharInvocationCollection();
|
||||||
|
}
|
||||||
|
if ($resolver === null) {
|
||||||
|
$resolver = new PharInvocationResolver();
|
||||||
|
}
|
||||||
|
$this->collection = $collection;
|
||||||
|
$this->resolver = $resolver;
|
||||||
|
$this->behavior = $behaviour;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function assert($path, $command)
|
||||||
|
{
|
||||||
|
return $this->behavior->assert($path, $command);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param null|int $flags
|
||||||
|
* @return null|PharInvocation
|
||||||
|
*/
|
||||||
|
public function resolve($path, $flags = null)
|
||||||
|
{
|
||||||
|
return $this->resolver->resolve($path, $flags);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return Collectable
|
||||||
|
*/
|
||||||
|
public function getCollection()
|
||||||
|
{
|
||||||
|
return $this->collection;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,59 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Phar;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
class Container
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @var Stub
|
||||||
|
*/
|
||||||
|
private $stub;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var Manifest
|
||||||
|
*/
|
||||||
|
private $manifest;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param Stub $stub
|
||||||
|
* @param Manifest $manifest
|
||||||
|
*/
|
||||||
|
public function __construct(Stub $stub, Manifest $manifest)
|
||||||
|
{
|
||||||
|
$this->stub = $stub;
|
||||||
|
$this->manifest = $manifest;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return Stub
|
||||||
|
*/
|
||||||
|
public function getStub()
|
||||||
|
{
|
||||||
|
return $this->stub;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return Manifest
|
||||||
|
*/
|
||||||
|
public function getManifest()
|
||||||
|
{
|
||||||
|
return $this->manifest;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getAlias()
|
||||||
|
{
|
||||||
|
return $this->manifest->getAlias() ?: $this->stub->getMappedAlias();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Phar;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
|
||||||
|
class DeserializationException extends Exception
|
||||||
|
{
|
||||||
|
}
|
||||||
@@ -0,0 +1,176 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Phar;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use Brumann\Polyfill\Unserialize;
|
||||||
|
|
||||||
|
class Manifest
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param string $content
|
||||||
|
* @return self
|
||||||
|
* @see http://php.net/manual/en/phar.fileformat.phar.php
|
||||||
|
*/
|
||||||
|
public static function fromContent($content)
|
||||||
|
{
|
||||||
|
$target = new static();
|
||||||
|
$target->manifestLength = Reader::resolveFourByteLittleEndian($content, 0);
|
||||||
|
$target->amountOfFiles = Reader::resolveFourByteLittleEndian($content, 4);
|
||||||
|
$target->flags = Reader::resolveFourByteLittleEndian($content, 10);
|
||||||
|
$target->aliasLength = Reader::resolveFourByteLittleEndian($content, 14);
|
||||||
|
$target->alias = substr($content, 18, $target->aliasLength);
|
||||||
|
$target->metaDataLength = Reader::resolveFourByteLittleEndian($content, 18 + $target->aliasLength);
|
||||||
|
$target->metaData = substr($content, 22 + $target->aliasLength, $target->metaDataLength);
|
||||||
|
|
||||||
|
$apiVersionNibbles = Reader::resolveTwoByteBigEndian($content, 8);
|
||||||
|
$target->apiVersion = implode('.', array(
|
||||||
|
($apiVersionNibbles & 0xf000) >> 12,
|
||||||
|
($apiVersionNibbles & 0x0f00) >> 8,
|
||||||
|
($apiVersionNibbles & 0x00f0) >> 4,
|
||||||
|
));
|
||||||
|
|
||||||
|
return $target;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var int
|
||||||
|
*/
|
||||||
|
private $manifestLength;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var int
|
||||||
|
*/
|
||||||
|
private $amountOfFiles;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $apiVersion;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var int
|
||||||
|
*/
|
||||||
|
private $flags;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var int
|
||||||
|
*/
|
||||||
|
private $aliasLength;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $alias;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var int
|
||||||
|
*/
|
||||||
|
private $metaDataLength;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $metaData;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Avoid direct instantiation.
|
||||||
|
*/
|
||||||
|
private function __construct()
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function getManifestLength()
|
||||||
|
{
|
||||||
|
return $this->manifestLength;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function getAmountOfFiles()
|
||||||
|
{
|
||||||
|
return $this->amountOfFiles;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getApiVersion()
|
||||||
|
{
|
||||||
|
return $this->apiVersion;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function getFlags()
|
||||||
|
{
|
||||||
|
return $this->flags;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function getAliasLength()
|
||||||
|
{
|
||||||
|
return $this->aliasLength;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getAlias()
|
||||||
|
{
|
||||||
|
return $this->alias;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function getMetaDataLength()
|
||||||
|
{
|
||||||
|
return $this->metaDataLength;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getMetaData()
|
||||||
|
{
|
||||||
|
return $this->metaData;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return mixed|null
|
||||||
|
*/
|
||||||
|
public function deserializeMetaData()
|
||||||
|
{
|
||||||
|
if (empty($this->metaData)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$result = Unserialize::unserialize($this->metaData, array('allowed_classes' => false));
|
||||||
|
|
||||||
|
$serialized = json_encode($result);
|
||||||
|
if (strpos($serialized, '__PHP_Incomplete_Class_Name') !== false) {
|
||||||
|
throw new DeserializationException(
|
||||||
|
'Meta-data contains serialized object',
|
||||||
|
1539623382
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $result;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,220 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Phar;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
class Reader
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $fileName;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $fileType;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $fileName
|
||||||
|
*/
|
||||||
|
public function __construct($fileName)
|
||||||
|
{
|
||||||
|
if (strpos($fileName, '://') !== false) {
|
||||||
|
throw new ReaderException(
|
||||||
|
'File name must not contain stream prefix',
|
||||||
|
1539623708
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->fileName = $fileName;
|
||||||
|
$this->fileType = $this->determineFileType();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return Container
|
||||||
|
*/
|
||||||
|
public function resolveContainer()
|
||||||
|
{
|
||||||
|
$data = $this->extractData($this->resolveStream() . $this->fileName);
|
||||||
|
|
||||||
|
if ($data['stubContent'] === null) {
|
||||||
|
throw new ReaderException(
|
||||||
|
'Cannot resolve stub',
|
||||||
|
1547807881
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if ($data['manifestContent'] === null || $data['manifestLength'] === null) {
|
||||||
|
throw new ReaderException(
|
||||||
|
'Cannot resolve manifest',
|
||||||
|
1547807882
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (strlen($data['manifestContent']) < $data['manifestLength']) {
|
||||||
|
throw new ReaderException(
|
||||||
|
sprintf(
|
||||||
|
'Exected manifest length %d, got %d',
|
||||||
|
strlen($data['manifestContent']),
|
||||||
|
$data['manifestLength']
|
||||||
|
),
|
||||||
|
1547807883
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new Container(
|
||||||
|
Stub::fromContent($data['stubContent']),
|
||||||
|
Manifest::fromContent($data['manifestContent'])
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $fileName e.g. '/path/file.phar' or 'compress.zlib:///path/file.phar'
|
||||||
|
* @return array
|
||||||
|
*/
|
||||||
|
private function extractData($fileName)
|
||||||
|
{
|
||||||
|
$stubContent = null;
|
||||||
|
$manifestContent = null;
|
||||||
|
$manifestLength = null;
|
||||||
|
|
||||||
|
$resource = fopen($fileName, 'r');
|
||||||
|
if (!is_resource($resource)) {
|
||||||
|
throw new ReaderException(
|
||||||
|
sprintf('Resource %s could not be opened', $fileName),
|
||||||
|
1547902055
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
while (!feof($resource)) {
|
||||||
|
$line = fgets($resource);
|
||||||
|
// stop reading file when manifest can be extracted
|
||||||
|
if ($manifestLength !== null && $manifestContent !== null && strlen($manifestContent) >= $manifestLength) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
$manifestPosition = strpos($line, '__HALT_COMPILER();');
|
||||||
|
|
||||||
|
// first line contains start of manifest
|
||||||
|
if ($stubContent === null && $manifestContent === null && $manifestPosition !== false) {
|
||||||
|
$stubContent = substr($line, 0, $manifestPosition - 1);
|
||||||
|
$manifestContent = preg_replace('#^.*__HALT_COMPILER\(\);(?>[ \n]\?>(?>\r\n|\n)?)?#', '', $line);
|
||||||
|
$manifestLength = $this->resolveManifestLength($manifestContent);
|
||||||
|
// line contains start of stub
|
||||||
|
} elseif ($stubContent === null) {
|
||||||
|
$stubContent = $line;
|
||||||
|
// line contains start of manifest
|
||||||
|
} elseif ($manifestContent === null && $manifestPosition !== false) {
|
||||||
|
$manifestContent = preg_replace('#^.*__HALT_COMPILER\(\);(?>[ \n]\?>(?>\r\n|\n)?)?#', '', $line);
|
||||||
|
$manifestLength = $this->resolveManifestLength($manifestContent);
|
||||||
|
// manifest has been started (thus is cannot be stub anymore), add content
|
||||||
|
} elseif ($manifestContent !== null) {
|
||||||
|
$manifestContent .= $line;
|
||||||
|
$manifestLength = $this->resolveManifestLength($manifestContent);
|
||||||
|
// stub has been started (thus cannot be manifest here, yet), add content
|
||||||
|
} elseif ($stubContent !== null) {
|
||||||
|
$stubContent .= $line;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fclose($resource);
|
||||||
|
|
||||||
|
return array(
|
||||||
|
'stubContent' => $stubContent,
|
||||||
|
'manifestContent' => $manifestContent,
|
||||||
|
'manifestLength' => $manifestLength,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves stream in order to handle compressed Phar archives.
|
||||||
|
*
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
private function resolveStream()
|
||||||
|
{
|
||||||
|
if ($this->fileType === 'application/x-gzip') {
|
||||||
|
return 'compress.zlib://';
|
||||||
|
} elseif ($this->fileType === 'application/x-bzip2') {
|
||||||
|
return 'compress.bzip2://';
|
||||||
|
}
|
||||||
|
return '';
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
private function determineFileType()
|
||||||
|
{
|
||||||
|
$fileInfo = new \finfo();
|
||||||
|
return $fileInfo->file($this->fileName, FILEINFO_MIME_TYPE);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $content
|
||||||
|
* @return int|null
|
||||||
|
*/
|
||||||
|
private function resolveManifestLength($content)
|
||||||
|
{
|
||||||
|
if (strlen($content) < 4) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
return static::resolveFourByteLittleEndian($content, 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $content
|
||||||
|
* @param int $start
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public static function resolveFourByteLittleEndian($content, $start)
|
||||||
|
{
|
||||||
|
$payload = substr($content, $start, 4);
|
||||||
|
if (!is_string($payload)) {
|
||||||
|
throw new ReaderException(
|
||||||
|
sprintf('Cannot resolve value at offset %d', $start),
|
||||||
|
1539614260
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
$value = unpack('V', $payload);
|
||||||
|
if (!isset($value[1])) {
|
||||||
|
throw new ReaderException(
|
||||||
|
sprintf('Cannot resolve value at offset %d', $start),
|
||||||
|
1539614261
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return $value[1];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $content
|
||||||
|
* @param int $start
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public static function resolveTwoByteBigEndian($content, $start)
|
||||||
|
{
|
||||||
|
$payload = substr($content, $start, 2);
|
||||||
|
if (!is_string($payload)) {
|
||||||
|
throw new ReaderException(
|
||||||
|
sprintf('Cannot resolve value at offset %d', $start),
|
||||||
|
1539614263
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
$value = unpack('n', $payload);
|
||||||
|
if (!isset($value[1])) {
|
||||||
|
throw new ReaderException(
|
||||||
|
sprintf('Cannot resolve value at offset %d', $start),
|
||||||
|
1539614264
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return $value[1];
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Phar;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
|
||||||
|
class ReaderException extends Exception
|
||||||
|
{
|
||||||
|
}
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Phar;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @internal Experimental implementation of Phar archive internals
|
||||||
|
*/
|
||||||
|
class Stub
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param string $content
|
||||||
|
* @return self
|
||||||
|
*/
|
||||||
|
public static function fromContent($content)
|
||||||
|
{
|
||||||
|
$target = new static();
|
||||||
|
$target->content = $content;
|
||||||
|
|
||||||
|
if (
|
||||||
|
stripos($content, 'Phar::mapPhar(') !== false
|
||||||
|
&& preg_match('#Phar\:\:mapPhar\(([^)]+)\)#', $content, $matches)
|
||||||
|
) {
|
||||||
|
// remove spaces, single & double quotes
|
||||||
|
// @todo `'my' . 'alias' . '.phar'` is not evaluated here
|
||||||
|
$target->mappedAlias = trim($matches[1], ' \'"');
|
||||||
|
}
|
||||||
|
|
||||||
|
return $target;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $content;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $mappedAlias = '';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getContent()
|
||||||
|
{
|
||||||
|
return $this->content;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getMappedAlias()
|
||||||
|
{
|
||||||
|
return $this->mappedAlias;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,511 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Resolver\PharInvocation;
|
||||||
|
|
||||||
|
class PharStreamWrapper
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Internal stream constants that are not exposed to PHP, but used...
|
||||||
|
* @see https://github.com/php/php-src/blob/e17fc0d73c611ad0207cac8a4a01ded38251a7dc/main/php_streams.h
|
||||||
|
*/
|
||||||
|
const STREAM_OPEN_FOR_INCLUDE = 128;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var resource
|
||||||
|
*/
|
||||||
|
public $context;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var resource
|
||||||
|
*/
|
||||||
|
protected $internalResource;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var PharInvocation
|
||||||
|
*/
|
||||||
|
protected $invocation;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function dir_closedir()
|
||||||
|
{
|
||||||
|
if (!is_resource($this->internalResource)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->invokeInternalStreamWrapper(
|
||||||
|
'closedir',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
return !is_resource($this->internalResource);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param int $options
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function dir_opendir($path, $options)
|
||||||
|
{
|
||||||
|
$this->assert($path, Behavior::COMMAND_DIR_OPENDIR);
|
||||||
|
$this->internalResource = $this->invokeInternalStreamWrapper(
|
||||||
|
'opendir',
|
||||||
|
$path,
|
||||||
|
$this->context
|
||||||
|
);
|
||||||
|
return is_resource($this->internalResource);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string|false
|
||||||
|
*/
|
||||||
|
public function dir_readdir()
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'readdir',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function dir_rewinddir()
|
||||||
|
{
|
||||||
|
if (!is_resource($this->internalResource)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->invokeInternalStreamWrapper(
|
||||||
|
'rewinddir',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
return is_resource($this->internalResource);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param int $mode
|
||||||
|
* @param int $options
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function mkdir($path, $mode, $options)
|
||||||
|
{
|
||||||
|
$this->assert($path, Behavior::COMMAND_MKDIR);
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'mkdir',
|
||||||
|
$path,
|
||||||
|
$mode,
|
||||||
|
(bool) ($options & STREAM_MKDIR_RECURSIVE),
|
||||||
|
$this->context
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path_from
|
||||||
|
* @param string $path_to
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function rename($path_from, $path_to)
|
||||||
|
{
|
||||||
|
$this->assert($path_from, Behavior::COMMAND_RENAME);
|
||||||
|
$this->assert($path_to, Behavior::COMMAND_RENAME);
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'rename',
|
||||||
|
$path_from,
|
||||||
|
$path_to,
|
||||||
|
$this->context
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param int $options
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function rmdir($path, $options)
|
||||||
|
{
|
||||||
|
$this->assert($path, Behavior::COMMAND_RMDIR);
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'rmdir',
|
||||||
|
$path,
|
||||||
|
$this->context
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param int $cast_as
|
||||||
|
*/
|
||||||
|
public function stream_cast($cast_as)
|
||||||
|
{
|
||||||
|
throw new Exception(
|
||||||
|
'Method stream_select() cannot be used',
|
||||||
|
1530103999
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function stream_close()
|
||||||
|
{
|
||||||
|
$this->invokeInternalStreamWrapper(
|
||||||
|
'fclose',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_eof()
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'feof',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_flush()
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'fflush',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param int $operation
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_lock($operation)
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'flock',
|
||||||
|
$this->internalResource,
|
||||||
|
$operation
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param int $option
|
||||||
|
* @param string|int $value
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_metadata($path, $option, $value)
|
||||||
|
{
|
||||||
|
$this->assert($path, Behavior::COMMAND_STEAM_METADATA);
|
||||||
|
if ($option === STREAM_META_TOUCH) {
|
||||||
|
return call_user_func_array(
|
||||||
|
array($this, 'invokeInternalStreamWrapper'),
|
||||||
|
array_merge(array('touch', $path), (array) $value)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if ($option === STREAM_META_OWNER_NAME || $option === STREAM_META_OWNER) {
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'chown',
|
||||||
|
$path,
|
||||||
|
$value
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if ($option === STREAM_META_GROUP_NAME || $option === STREAM_META_GROUP) {
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'chgrp',
|
||||||
|
$path,
|
||||||
|
$value
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if ($option === STREAM_META_ACCESS) {
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'chmod',
|
||||||
|
$path,
|
||||||
|
$value
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param string $mode
|
||||||
|
* @param int $options
|
||||||
|
* @param string|null $opened_path
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_open(
|
||||||
|
$path,
|
||||||
|
$mode,
|
||||||
|
$options,
|
||||||
|
&$opened_path = null
|
||||||
|
) {
|
||||||
|
$this->assert($path, Behavior::COMMAND_STREAM_OPEN);
|
||||||
|
$arguments = array($path, $mode, (bool) ($options & STREAM_USE_PATH));
|
||||||
|
// only add stream context for non include/require calls
|
||||||
|
if (!($options & static::STREAM_OPEN_FOR_INCLUDE)) {
|
||||||
|
$arguments[] = $this->context;
|
||||||
|
// work around https://bugs.php.net/bug.php?id=66569
|
||||||
|
// for including files from Phar stream with OPcache enabled
|
||||||
|
} else {
|
||||||
|
Helper::resetOpCache();
|
||||||
|
}
|
||||||
|
$this->internalResource = call_user_func_array(
|
||||||
|
array($this, 'invokeInternalStreamWrapper'),
|
||||||
|
array_merge(array('fopen'), $arguments)
|
||||||
|
);
|
||||||
|
if (!is_resource($this->internalResource)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
if ($opened_path !== null) {
|
||||||
|
$metaData = stream_get_meta_data($this->internalResource);
|
||||||
|
$opened_path = $metaData['uri'];
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param int $count
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function stream_read($count)
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'fread',
|
||||||
|
$this->internalResource,
|
||||||
|
$count
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param int $offset
|
||||||
|
* @param int $whence
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_seek($offset, $whence = SEEK_SET)
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'fseek',
|
||||||
|
$this->internalResource,
|
||||||
|
$offset,
|
||||||
|
$whence
|
||||||
|
) !== -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param int $option
|
||||||
|
* @param int $arg1
|
||||||
|
* @param int $arg2
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_set_option($option, $arg1, $arg2)
|
||||||
|
{
|
||||||
|
if ($option === STREAM_OPTION_BLOCKING) {
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'stream_set_blocking',
|
||||||
|
$this->internalResource,
|
||||||
|
$arg1
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if ($option === STREAM_OPTION_READ_TIMEOUT) {
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'stream_set_timeout',
|
||||||
|
$this->internalResource,
|
||||||
|
$arg1,
|
||||||
|
$arg2
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if ($option === STREAM_OPTION_WRITE_BUFFER) {
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'stream_set_write_buffer',
|
||||||
|
$this->internalResource,
|
||||||
|
$arg2
|
||||||
|
) === 0;
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array
|
||||||
|
*/
|
||||||
|
public function stream_stat()
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'fstat',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function stream_tell()
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'ftell',
|
||||||
|
$this->internalResource
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param int $new_size
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function stream_truncate($new_size)
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'ftruncate',
|
||||||
|
$this->internalResource,
|
||||||
|
$new_size
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $data
|
||||||
|
* @return int
|
||||||
|
*/
|
||||||
|
public function stream_write($data)
|
||||||
|
{
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'fwrite',
|
||||||
|
$this->internalResource,
|
||||||
|
$data
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function unlink($path)
|
||||||
|
{
|
||||||
|
$this->assert($path, Behavior::COMMAND_UNLINK);
|
||||||
|
return $this->invokeInternalStreamWrapper(
|
||||||
|
'unlink',
|
||||||
|
$path,
|
||||||
|
$this->context
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param int $flags
|
||||||
|
* @return array|false
|
||||||
|
*/
|
||||||
|
public function url_stat($path, $flags)
|
||||||
|
{
|
||||||
|
$this->assert($path, Behavior::COMMAND_URL_STAT);
|
||||||
|
$functionName = $flags & STREAM_URL_STAT_QUIET ? '@stat' : 'stat';
|
||||||
|
return $this->invokeInternalStreamWrapper($functionName, $path);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param string $command
|
||||||
|
*/
|
||||||
|
protected function assert($path, $command)
|
||||||
|
{
|
||||||
|
if (Manager::instance()->assert($path, $command) === true) {
|
||||||
|
$this->collectInvocation($path);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Exception(
|
||||||
|
sprintf(
|
||||||
|
'Denied invocation of "%s" for command "%s"',
|
||||||
|
$path,
|
||||||
|
$command
|
||||||
|
),
|
||||||
|
1535189880
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
*/
|
||||||
|
protected function collectInvocation($path)
|
||||||
|
{
|
||||||
|
if (isset($this->invocation)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$manager = Manager::instance();
|
||||||
|
$this->invocation = $manager->resolve($path);
|
||||||
|
if ($this->invocation === null) {
|
||||||
|
throw new Exception(
|
||||||
|
'Expected invocation could not be resolved',
|
||||||
|
1556389591
|
||||||
|
);
|
||||||
|
}
|
||||||
|
// confirm, previous interceptor(s) validated invocation
|
||||||
|
$this->invocation->confirm();
|
||||||
|
$collection = $manager->getCollection();
|
||||||
|
if (!$collection->has($this->invocation)) {
|
||||||
|
$collection->collect($this->invocation);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return Manager|Assertable
|
||||||
|
* @deprecated Use Manager::instance() directly
|
||||||
|
*/
|
||||||
|
protected function resolveAssertable()
|
||||||
|
{
|
||||||
|
return Manager::instance();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Invokes commands on the native PHP Phar stream wrapper.
|
||||||
|
*
|
||||||
|
* @param string $functionName
|
||||||
|
* @param mixed ...$arguments
|
||||||
|
* @return mixed
|
||||||
|
*/
|
||||||
|
private function invokeInternalStreamWrapper($functionName)
|
||||||
|
{
|
||||||
|
$arguments = func_get_args();
|
||||||
|
array_shift($arguments);
|
||||||
|
$silentExecution = $functionName{0} === '@';
|
||||||
|
$functionName = ltrim($functionName, '@');
|
||||||
|
$this->restoreInternalSteamWrapper();
|
||||||
|
|
||||||
|
try {
|
||||||
|
if ($silentExecution) {
|
||||||
|
$result = @call_user_func_array($functionName, $arguments);
|
||||||
|
} else {
|
||||||
|
$result = call_user_func_array($functionName, $arguments);
|
||||||
|
}
|
||||||
|
} catch (\Exception $exception) {
|
||||||
|
$this->registerStreamWrapper();
|
||||||
|
throw $exception;
|
||||||
|
} catch (\Throwable $throwable) {
|
||||||
|
$this->registerStreamWrapper();
|
||||||
|
throw $throwable;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->registerStreamWrapper();
|
||||||
|
return $result;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function restoreInternalSteamWrapper()
|
||||||
|
{
|
||||||
|
stream_wrapper_restore('phar');
|
||||||
|
}
|
||||||
|
|
||||||
|
private function registerStreamWrapper()
|
||||||
|
{
|
||||||
|
stream_wrapper_unregister('phar');
|
||||||
|
stream_wrapper_register('phar', get_class($this));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Resolver\PharInvocation;
|
||||||
|
|
||||||
|
interface Resolvable
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param null|int $flags
|
||||||
|
* @return null|PharInvocation
|
||||||
|
*/
|
||||||
|
public function resolve($path, $flags = null);
|
||||||
|
}
|
||||||
@@ -0,0 +1,125 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Resolver;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Exception;
|
||||||
|
|
||||||
|
class PharInvocation
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $baseName;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
private $alias;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var bool
|
||||||
|
* @see \TYPO3\PharStreamWrapper\PharStreamWrapper::collectInvocation()
|
||||||
|
*/
|
||||||
|
private $confirmed = false;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Arbitrary variables to be used by interceptors as registry
|
||||||
|
* (e.g. in order to avoid duplicate processing and assertions)
|
||||||
|
*
|
||||||
|
* @var array
|
||||||
|
*/
|
||||||
|
private $variables;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $baseName
|
||||||
|
* @param string $alias
|
||||||
|
*/
|
||||||
|
public function __construct($baseName, $alias = '')
|
||||||
|
{
|
||||||
|
if ($baseName === '') {
|
||||||
|
throw new Exception(
|
||||||
|
'Base-name cannot be empty',
|
||||||
|
1551283689
|
||||||
|
);
|
||||||
|
}
|
||||||
|
$this->baseName = $baseName;
|
||||||
|
$this->alias = $alias;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function __toString()
|
||||||
|
{
|
||||||
|
return $this->baseName;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return string
|
||||||
|
*/
|
||||||
|
public function getBaseName()
|
||||||
|
{
|
||||||
|
return $this->baseName;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return null|string
|
||||||
|
*/
|
||||||
|
public function getAlias()
|
||||||
|
{
|
||||||
|
return $this->alias;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function isConfirmed()
|
||||||
|
{
|
||||||
|
return $this->confirmed;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function confirm()
|
||||||
|
{
|
||||||
|
$this->confirmed = true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $name
|
||||||
|
* @return mixed|null
|
||||||
|
*/
|
||||||
|
public function getVariable($name)
|
||||||
|
{
|
||||||
|
if (!isset($this->variables[$name])) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
return $this->variables[$name];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $name
|
||||||
|
* @param mixed $value
|
||||||
|
*/
|
||||||
|
public function setVariable($name, $value)
|
||||||
|
{
|
||||||
|
$this->variables[$name] = $value;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param PharInvocation $other
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function equals(PharInvocation $other)
|
||||||
|
{
|
||||||
|
return $other->baseName === $this->baseName
|
||||||
|
&& $other->alias === $this->alias;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,156 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Resolver;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Collectable;
|
||||||
|
|
||||||
|
class PharInvocationCollection implements Collectable
|
||||||
|
{
|
||||||
|
const UNIQUE_INVOCATION = 1;
|
||||||
|
const UNIQUE_BASE_NAME = 2;
|
||||||
|
const DUPLICATE_ALIAS_WARNING = 32;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var PharInvocation[]
|
||||||
|
*/
|
||||||
|
private $invocations = array();
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function has(PharInvocation $invocation)
|
||||||
|
{
|
||||||
|
return in_array($invocation, $this->invocations, true);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @param null|int $flags
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
public function collect(PharInvocation $invocation, $flags = null)
|
||||||
|
{
|
||||||
|
if ($flags === null) {
|
||||||
|
$flags = static::UNIQUE_INVOCATION | static::DUPLICATE_ALIAS_WARNING;
|
||||||
|
}
|
||||||
|
if ($invocation->getBaseName() === ''
|
||||||
|
|| $invocation->getAlias() === ''
|
||||||
|
|| !$this->assertUniqueBaseName($invocation, $flags)
|
||||||
|
|| !$this->assertUniqueInvocation($invocation, $flags)
|
||||||
|
) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
if ($flags & static::DUPLICATE_ALIAS_WARNING) {
|
||||||
|
$this->triggerDuplicateAliasWarning($invocation);
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->invocations[] = $invocation;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param callable $callback
|
||||||
|
* @param bool $reverse
|
||||||
|
* @return null|PharInvocation
|
||||||
|
*/
|
||||||
|
public function findByCallback($callback, $reverse = false)
|
||||||
|
{
|
||||||
|
foreach ($this->getInvocations($reverse) as $invocation) {
|
||||||
|
if (call_user_func($callback, $invocation) === true) {
|
||||||
|
return $invocation;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Asserts that base-name is unique. This disallows having multiple invocations for
|
||||||
|
* same base-name but having different alias names.
|
||||||
|
*
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @param int $flags
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private function assertUniqueBaseName(PharInvocation $invocation, $flags)
|
||||||
|
{
|
||||||
|
if (!($flags & static::UNIQUE_BASE_NAME)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
return $this->findByCallback(
|
||||||
|
function (PharInvocation $candidate) use ($invocation) {
|
||||||
|
return $candidate->getBaseName() === $invocation->getBaseName();
|
||||||
|
}
|
||||||
|
) === null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Asserts that combination of base-name and alias is unique. This allows having multiple
|
||||||
|
* invocations for same base-name but having different alias names (for whatever reason).
|
||||||
|
*
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @param int $flags
|
||||||
|
* @return bool
|
||||||
|
*/
|
||||||
|
private function assertUniqueInvocation(PharInvocation $invocation, $flags)
|
||||||
|
{
|
||||||
|
if (!($flags & static::UNIQUE_INVOCATION)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
return $this->findByCallback(
|
||||||
|
function (PharInvocation $candidate) use ($invocation) {
|
||||||
|
return $candidate->equals($invocation);
|
||||||
|
}
|
||||||
|
) === null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Triggers warning for invocations with same alias and same confirmation state.
|
||||||
|
*
|
||||||
|
* @param PharInvocation $invocation
|
||||||
|
* @see \TYPO3\PharStreamWrapper\PharStreamWrapper::collectInvocation()
|
||||||
|
*/
|
||||||
|
private function triggerDuplicateAliasWarning(PharInvocation $invocation)
|
||||||
|
{
|
||||||
|
$sameAliasInvocation = $this->findByCallback(
|
||||||
|
function (PharInvocation $candidate) use ($invocation) {
|
||||||
|
return $candidate->isConfirmed() === $invocation->isConfirmed()
|
||||||
|
&& $candidate->getAlias() === $invocation->getAlias();
|
||||||
|
},
|
||||||
|
true
|
||||||
|
);
|
||||||
|
if ($sameAliasInvocation === null) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
trigger_error(
|
||||||
|
sprintf(
|
||||||
|
'Alias %s cannot be used by %s, already used by %s',
|
||||||
|
$invocation->getAlias(),
|
||||||
|
$invocation->getBaseName(),
|
||||||
|
$sameAliasInvocation->getBaseName()
|
||||||
|
),
|
||||||
|
E_USER_WARNING
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param bool $reverse
|
||||||
|
* @return PharInvocation[]
|
||||||
|
*/
|
||||||
|
private function getInvocations($reverse = false)
|
||||||
|
{
|
||||||
|
if ($reverse) {
|
||||||
|
return array_reverse($this->invocations);
|
||||||
|
}
|
||||||
|
return $this->invocations;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,241 @@
|
|||||||
|
<?php
|
||||||
|
namespace TYPO3\PharStreamWrapper\Resolver;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This file is part of the TYPO3 project.
|
||||||
|
*
|
||||||
|
* It is free software; you can redistribute it and/or modify it under the terms
|
||||||
|
* of the MIT License (MIT). For the full copyright and license information,
|
||||||
|
* please read the LICENSE file that was distributed with this source code.
|
||||||
|
*
|
||||||
|
* The TYPO3 project - inspiring people to share!
|
||||||
|
*/
|
||||||
|
|
||||||
|
use TYPO3\PharStreamWrapper\Helper;
|
||||||
|
use TYPO3\PharStreamWrapper\Manager;
|
||||||
|
use TYPO3\PharStreamWrapper\Phar\Reader;
|
||||||
|
use TYPO3\PharStreamWrapper\Resolvable;
|
||||||
|
|
||||||
|
class PharInvocationResolver implements Resolvable
|
||||||
|
{
|
||||||
|
const RESOLVE_REALPATH = 1;
|
||||||
|
const RESOLVE_ALIAS = 2;
|
||||||
|
const ASSERT_INTERNAL_INVOCATION = 32;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string[]
|
||||||
|
*/
|
||||||
|
private $invocationFunctionNames = array(
|
||||||
|
'include',
|
||||||
|
'include_once',
|
||||||
|
'require',
|
||||||
|
'require_once'
|
||||||
|
);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Contains resolved base names in order to reduce file IO.
|
||||||
|
*
|
||||||
|
* @var string[]
|
||||||
|
*/
|
||||||
|
private $baseNames = array();
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves PharInvocation value object (baseName and optional alias).
|
||||||
|
*
|
||||||
|
* Phar aliases are intended to be used only inside Phar archives, however
|
||||||
|
* PharStreamWrapper needs this information exposed outside of Phar as well
|
||||||
|
* It is possible that same alias is used for different $baseName values.
|
||||||
|
* That's why PharInvocationCollection behaves like a stack when resolving
|
||||||
|
* base-name for a given alias. On the other hand it is not possible that
|
||||||
|
* one $baseName is referring to multiple aliases.
|
||||||
|
* @see https://secure.php.net/manual/en/phar.setalias.php
|
||||||
|
* @see https://secure.php.net/manual/en/phar.mapphar.php
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @param int|null $flags
|
||||||
|
* @return null|PharInvocation
|
||||||
|
*/
|
||||||
|
public function resolve($path, $flags = null)
|
||||||
|
{
|
||||||
|
$hasPharPrefix = Helper::hasPharPrefix($path);
|
||||||
|
if ($flags === null) {
|
||||||
|
$flags = static::RESOLVE_REALPATH | static::RESOLVE_ALIAS | static::ASSERT_INTERNAL_INVOCATION;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($hasPharPrefix && $flags & static::RESOLVE_ALIAS) {
|
||||||
|
$invocation = $this->findByAlias($path);
|
||||||
|
if ($invocation !== null) {
|
||||||
|
return $invocation;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$baseName = $this->resolveBaseName($path, $flags);
|
||||||
|
if ($baseName === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($flags & static::RESOLVE_REALPATH) {
|
||||||
|
$baseName = $this->baseNames[$baseName];
|
||||||
|
}
|
||||||
|
|
||||||
|
return $this->retrieveInvocation($baseName, $flags);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Retrieves PharInvocation, either existing in collection or created on demand
|
||||||
|
* with resolving a potential alias name used in the according Phar archive.
|
||||||
|
*
|
||||||
|
* @param string $baseName
|
||||||
|
* @param int $flags
|
||||||
|
* @return PharInvocation
|
||||||
|
*/
|
||||||
|
private function retrieveInvocation($baseName, $flags)
|
||||||
|
{
|
||||||
|
$invocation = $this->findByBaseName($baseName);
|
||||||
|
if ($invocation !== null) {
|
||||||
|
return $invocation;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($flags & static::RESOLVE_ALIAS) {
|
||||||
|
$reader = new Reader($baseName);
|
||||||
|
$alias = $reader->resolveContainer()->getAlias();
|
||||||
|
} else {
|
||||||
|
$alias = '';
|
||||||
|
}
|
||||||
|
// add unconfirmed(!) new invocation to collection
|
||||||
|
$invocation = new PharInvocation($baseName, $alias);
|
||||||
|
Manager::instance()->getCollection()->collect($invocation);
|
||||||
|
return $invocation;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @param int $flags
|
||||||
|
* @return null|string
|
||||||
|
*/
|
||||||
|
private function resolveBaseName($path, $flags)
|
||||||
|
{
|
||||||
|
$baseName = $this->findInBaseNames($path);
|
||||||
|
if ($baseName !== null) {
|
||||||
|
return $baseName;
|
||||||
|
}
|
||||||
|
|
||||||
|
$baseName = Helper::determineBaseFile($path);
|
||||||
|
if ($baseName !== null) {
|
||||||
|
$this->addBaseName($baseName);
|
||||||
|
return $baseName;
|
||||||
|
}
|
||||||
|
|
||||||
|
$possibleAlias = $this->resolvePossibleAlias($path);
|
||||||
|
if (!($flags & static::RESOLVE_ALIAS) || $possibleAlias === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$trace = debug_backtrace();
|
||||||
|
foreach ($trace as $item) {
|
||||||
|
if (!isset($item['function']) || !isset($item['args'][0])
|
||||||
|
|| !in_array($item['function'], $this->invocationFunctionNames, true)) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
$currentPath = $item['args'][0];
|
||||||
|
if (Helper::hasPharPrefix($currentPath)) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
$currentBaseName = Helper::determineBaseFile($currentPath);
|
||||||
|
if ($currentBaseName === null) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
// ensure the possible alias name (how we have been called initially) matches
|
||||||
|
// the resolved alias name that was retrieved by the current possible base name
|
||||||
|
$reader = new Reader($currentBaseName);
|
||||||
|
$currentAlias = $reader->resolveContainer()->getAlias();
|
||||||
|
if ($currentAlias !== $possibleAlias) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
$this->addBaseName($currentBaseName);
|
||||||
|
return $currentBaseName;
|
||||||
|
}
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return null|string
|
||||||
|
*/
|
||||||
|
private function resolvePossibleAlias($path)
|
||||||
|
{
|
||||||
|
$normalizedPath = Helper::normalizePath($path);
|
||||||
|
return strstr($normalizedPath, '/', true) ?: null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $baseName
|
||||||
|
* @return null|PharInvocation
|
||||||
|
*/
|
||||||
|
private function findByBaseName($baseName)
|
||||||
|
{
|
||||||
|
return Manager::instance()->getCollection()->findByCallback(
|
||||||
|
function (PharInvocation $candidate) use ($baseName) {
|
||||||
|
return $candidate->getBaseName() === $baseName;
|
||||||
|
},
|
||||||
|
true
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $path
|
||||||
|
* @return null|string
|
||||||
|
*/
|
||||||
|
private function findInBaseNames($path)
|
||||||
|
{
|
||||||
|
// return directly if the resolved base name was submitted
|
||||||
|
if (in_array($path, $this->baseNames, true)) {
|
||||||
|
return $path;
|
||||||
|
}
|
||||||
|
|
||||||
|
$parts = explode('/', Helper::normalizePath($path));
|
||||||
|
|
||||||
|
while (count($parts)) {
|
||||||
|
$currentPath = implode('/', $parts);
|
||||||
|
if (isset($this->baseNames[$currentPath])) {
|
||||||
|
return $currentPath;
|
||||||
|
}
|
||||||
|
array_pop($parts);
|
||||||
|
}
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $baseName
|
||||||
|
*/
|
||||||
|
private function addBaseName($baseName)
|
||||||
|
{
|
||||||
|
if (isset($this->baseNames[$baseName])) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
$this->baseNames[$baseName] = realpath($baseName);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Finds confirmed(!) invocations by alias.
|
||||||
|
*
|
||||||
|
* @param string $path
|
||||||
|
* @return null|PharInvocation
|
||||||
|
* @see \TYPO3\PharStreamWrapper\PharStreamWrapper::collectInvocation()
|
||||||
|
*/
|
||||||
|
private function findByAlias($path)
|
||||||
|
{
|
||||||
|
$possibleAlias = $this->resolvePossibleAlias($path);
|
||||||
|
if ($possibleAlias === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
return Manager::instance()->getCollection()->findByCallback(
|
||||||
|
function (PharInvocation $candidate) use ($possibleAlias) {
|
||||||
|
return $candidate->isConfirmed() && $candidate->getAlias() === $possibleAlias;
|
||||||
|
},
|
||||||
|
true
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -7,8 +7,7 @@ files[] = aggregator.test
|
|||||||
configure = admin/config/services/aggregator/settings
|
configure = admin/config/services/aggregator/settings
|
||||||
stylesheets[all][] = aggregator.css
|
stylesheets[all][] = aggregator.css
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
files[] = block.test
|
files[] = block.test
|
||||||
configure = admin/structure/block
|
configure = admin/structure/block
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -13,8 +13,7 @@ regions[footer] = Footer
|
|||||||
regions[highlighted] = Highlighted
|
regions[highlighted] = Highlighted
|
||||||
regions[help] = Help
|
regions[help] = Help
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
files[] = blog.test
|
files[] = blog.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ files[] = book.test
|
|||||||
configure = admin/content/book/settings
|
configure = admin/content/book/settings
|
||||||
stylesheets[all][] = book.css
|
stylesheets[all][] = book.css
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -768,11 +768,13 @@ function book_prev($book_link) {
|
|||||||
return NULL;
|
return NULL;
|
||||||
}
|
}
|
||||||
$flat = book_get_flat_menu($book_link);
|
$flat = book_get_flat_menu($book_link);
|
||||||
// Assigning the array to $flat resets the array pointer for use with each().
|
reset($flat);
|
||||||
$curr = NULL;
|
$curr = NULL;
|
||||||
do {
|
do {
|
||||||
$prev = $curr;
|
$prev = $curr;
|
||||||
list($key, $curr) = each($flat);
|
$curr = current($flat);
|
||||||
|
$key = key($flat);
|
||||||
|
next($flat);
|
||||||
} while ($key && $key != $book_link['mlid']);
|
} while ($key && $key != $book_link['mlid']);
|
||||||
|
|
||||||
if ($key == $book_link['mlid']) {
|
if ($key == $book_link['mlid']) {
|
||||||
@@ -806,9 +808,10 @@ function book_prev($book_link) {
|
|||||||
*/
|
*/
|
||||||
function book_next($book_link) {
|
function book_next($book_link) {
|
||||||
$flat = book_get_flat_menu($book_link);
|
$flat = book_get_flat_menu($book_link);
|
||||||
// Assigning the array to $flat resets the array pointer for use with each().
|
reset($flat);
|
||||||
do {
|
do {
|
||||||
list($key, $curr) = each($flat);
|
$key = key($flat);
|
||||||
|
next($flat);
|
||||||
}
|
}
|
||||||
while ($key && $key != $book_link['mlid']);
|
while ($key && $key != $book_link['mlid']);
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
files[] = color.test
|
files[] = color.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -9,8 +9,7 @@ files[] = comment.test
|
|||||||
configure = admin/content/comment
|
configure = admin/content/comment
|
||||||
stylesheets[all][] = comment.css
|
stylesheets[all][] = comment.css
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
files[] = contact.test
|
files[] = contact.test
|
||||||
configure = admin/structure/contact
|
configure = admin/structure/contact
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
files[] = contextual.test
|
files[] = contextual.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ files[] = dashboard.test
|
|||||||
dependencies[] = block
|
dependencies[] = block
|
||||||
configure = admin/dashboard/customize
|
configure = admin/dashboard/customize
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
files[] = dblog.test
|
files[] = dblog.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -11,8 +11,7 @@ dependencies[] = field_sql_storage
|
|||||||
required = TRUE
|
required = TRUE
|
||||||
stylesheets[all][] = theme/field.css
|
stylesheets[all][] = theme/field.css
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ dependencies[] = field
|
|||||||
files[] = field_sql_storage.test
|
files[] = field_sql_storage.test
|
||||||
required = TRUE
|
required = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ dependencies[] = field
|
|||||||
dependencies[] = options
|
dependencies[] = options
|
||||||
files[] = tests/list.test
|
files[] = tests/list.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -61,7 +61,7 @@ function list_update_7001() {
|
|||||||
|
|
||||||
// Additionally, float keys need to be disambiguated ('.5' is '0.5').
|
// Additionally, float keys need to be disambiguated ('.5' is '0.5').
|
||||||
if ($field['type'] == 'list_number' && !empty($allowed_values)) {
|
if ($field['type'] == 'list_number' && !empty($allowed_values)) {
|
||||||
$keys = array_map(create_function('$a', 'return (string) (float) $a;'), array_keys($allowed_values));
|
$keys = array_map('_list_update_7001_float_string_cast', array_keys($allowed_values));
|
||||||
$allowed_values = array_combine($keys, array_values($allowed_values));
|
$allowed_values = array_combine($keys, array_values($allowed_values));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -88,6 +88,13 @@ function list_update_7001() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Helper callback function to cast the array element.
|
||||||
|
*/
|
||||||
|
function _list_update_7001_float_string_cast($element) {
|
||||||
|
return (string) (float) $element;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Helper function for list_update_7001: extract allowed values from a string.
|
* Helper function for list_update_7001: extract allowed values from a string.
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ package = Testing
|
|||||||
version = VERSION
|
version = VERSION
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
dependencies[] = field
|
dependencies[] = field
|
||||||
files[] = number.test
|
files[] = number.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -69,7 +69,7 @@ class NumberFieldTestCase extends DrupalWebTestCase {
|
|||||||
preg_match('|test-entity/manage/(\d+)/edit|', $this->url, $match);
|
preg_match('|test-entity/manage/(\d+)/edit|', $this->url, $match);
|
||||||
$id = $match[1];
|
$id = $match[1];
|
||||||
$this->assertRaw(t('test_entity @id has been created.', array('@id' => $id)), 'Entity was created');
|
$this->assertRaw(t('test_entity @id has been created.', array('@id' => $id)), 'Entity was created');
|
||||||
$this->assertRaw(round($value, 2), 'Value is displayed.');
|
$this->assertRaw($value, 'Value is displayed.');
|
||||||
|
|
||||||
// Try to create entries with more than one decimal separator; assert fail.
|
// Try to create entries with more than one decimal separator; assert fail.
|
||||||
$wrong_entries = array(
|
$wrong_entries = array(
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
dependencies[] = field
|
dependencies[] = field
|
||||||
files[] = options.test
|
files[] = options.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ dependencies[] = field
|
|||||||
files[] = text.test
|
files[] = text.test
|
||||||
required = TRUE
|
required = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ files[] = field_test.entity.inc
|
|||||||
version = VERSION
|
version = VERSION
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
dependencies[] = field
|
dependencies[] = field
|
||||||
files[] = field_ui.test
|
files[] = field_ui.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -599,7 +599,7 @@ function file_field_widget_value($element, $input = FALSE, $form_state) {
|
|||||||
// If the display field is present make sure its unchecked value is saved.
|
// If the display field is present make sure its unchecked value is saved.
|
||||||
$field = field_widget_field($element, $form_state);
|
$field = field_widget_field($element, $form_state);
|
||||||
if (empty($input['display'])) {
|
if (empty($input['display'])) {
|
||||||
$input['display'] = $field['settings']['display_field'] ? 0 : 1;
|
$input['display'] = !empty($field['settings']['display_field']) ? 0 : 1;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
dependencies[] = field
|
dependencies[] = field
|
||||||
files[] = tests/file.test
|
files[] = tests/file.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -239,6 +239,9 @@ function file_ajax_upload() {
|
|||||||
$form_parents = func_get_args();
|
$form_parents = func_get_args();
|
||||||
$form_build_id = (string) array_pop($form_parents);
|
$form_build_id = (string) array_pop($form_parents);
|
||||||
|
|
||||||
|
// Sanitize form parents before using them.
|
||||||
|
$form_parents = array_filter($form_parents, 'element_child');
|
||||||
|
|
||||||
if (empty($_POST['form_build_id']) || $form_build_id != $_POST['form_build_id']) {
|
if (empty($_POST['form_build_id']) || $form_build_id != $_POST['form_build_id']) {
|
||||||
// Invalid request.
|
// Invalid request.
|
||||||
drupal_set_message(t('An unrecoverable error occurred. The uploaded file likely exceeded the maximum file size (@size) that this server supports.', array('@size' => format_size(file_upload_max_size()))), 'error');
|
drupal_set_message(t('An unrecoverable error occurred. The uploaded file likely exceeded the maximum file size (@size) that this server supports.', array('@size' => format_size(file_upload_max_size()))), 'error');
|
||||||
|
|||||||
@@ -1875,3 +1875,60 @@ class FileFieldAnonymousSubmission extends FileFieldTestCase {
|
|||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Tests the file_scan_directory() function.
|
||||||
|
*/
|
||||||
|
class FileScanDirectory extends FileFieldTestCase {
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string
|
||||||
|
*/
|
||||||
|
protected $path;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* {@inheritdoc}
|
||||||
|
*/
|
||||||
|
public static function getInfo() {
|
||||||
|
return array(
|
||||||
|
'name' => 'File ScanDirectory',
|
||||||
|
'description' => 'Tests the file_scan_directory() function.',
|
||||||
|
'group' => 'File',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* {@inheritdoc}
|
||||||
|
*/
|
||||||
|
function setUp() {
|
||||||
|
parent::setUp();
|
||||||
|
|
||||||
|
$this->path = 'modules/file/tests/fixtures/file_scan_ignore';
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Tests file_scan_directory() obeys 'file_scan_ignore_directories' setting.
|
||||||
|
* If nomask is not passed as argument, it should use the default settings.
|
||||||
|
* If nomask is passed as argument, it should obey this rule.
|
||||||
|
*/
|
||||||
|
public function testNoMask() {
|
||||||
|
$files = file_scan_directory($this->path, '/\.txt$/');
|
||||||
|
$this->assertEqual(3, count($files), '3 text files found when not ignoring directories.');
|
||||||
|
|
||||||
|
global $conf;
|
||||||
|
$conf['file_scan_ignore_directories'] = array('frontend_framework');
|
||||||
|
|
||||||
|
$files = file_scan_directory($this->path, '/\.txt$/');
|
||||||
|
$this->assertEqual(1, count($files), '1 text files found when ignoring directories called "frontend_framework".');
|
||||||
|
|
||||||
|
// Make that directories specified by default still work when a new nomask is provided.
|
||||||
|
$files = file_scan_directory($this->path, '/\.txt$/', array('nomask' => '/^c.txt/'));
|
||||||
|
$this->assertEqual(2, count($files), '2 text files found when an "nomask" option is passed in.');
|
||||||
|
|
||||||
|
// Ensure that the directories in file_scan_ignore_directories are escaped using preg_quote.
|
||||||
|
$conf['file_scan_ignore_directories'] = array('frontend.*');
|
||||||
|
$files = file_scan_directory($this->path, '/\.txt$/');
|
||||||
|
$this->assertEqual(3, count($files), '2 text files found when ignoring a directory that is not there.');
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ files[] = filter.test
|
|||||||
required = TRUE
|
required = TRUE
|
||||||
configure = admin/config/content/formats
|
configure = admin/config/content/formats
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -9,8 +9,7 @@ files[] = forum.test
|
|||||||
configure = admin/structure/forum
|
configure = admin/structure/forum
|
||||||
stylesheets[all][] = forum.css
|
stylesheets[all][] = forum.css
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
files[] = help.test
|
files[] = help.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -736,7 +736,8 @@ function theme_image_style_effects($variables) {
|
|||||||
if (!isset($form[$key]['#access']) || $form[$key]['#access']) {
|
if (!isset($form[$key]['#access']) || $form[$key]['#access']) {
|
||||||
$rows[] = array(
|
$rows[] = array(
|
||||||
'data' => $row,
|
'data' => $row,
|
||||||
'class' => !empty($form[$key]['weight']['#access']) || $key == 'new' ? array('draggable') : array(),
|
// Use a strict (===) comparison since $key can be 0.
|
||||||
|
'class' => !empty($form[$key]['weight']['#access']) || $key === 'new' ? array('draggable') : array(),
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,8 +7,7 @@ dependencies[] = file
|
|||||||
files[] = image.test
|
files[] = image.test
|
||||||
configure = admin/config/media/image-styles
|
configure = admin/config/media/image-styles
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
files[] = image_module_test.module
|
files[] = image_module_test.module
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
files[] = locale.test
|
files[] = locale.test
|
||||||
configure = admin/config/regional/language
|
configure = admin/config/regional/language
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -3188,11 +3188,7 @@ class LocaleLanguageNegotiationInfoFunctionalTest extends DrupalWebTestCase {
|
|||||||
foreach (language_types_info() as $type => $info) {
|
foreach (language_types_info() as $type => $info) {
|
||||||
if (isset($info['fixed'])) {
|
if (isset($info['fixed'])) {
|
||||||
$negotiation = variable_get("language_negotiation_$type", array());
|
$negotiation = variable_get("language_negotiation_$type", array());
|
||||||
$equal = count($info['fixed']) == count($negotiation);
|
$equal = array_keys($negotiation) === array_values($info['fixed']);
|
||||||
while ($equal && list($id) = each($negotiation)) {
|
|
||||||
list(, $info_id) = each($info['fixed']);
|
|
||||||
$equal = $info_id == $id;
|
|
||||||
}
|
|
||||||
$this->assertTrue($equal, format_string('language negotiation for %type is properly set up', array('%type' => $type)));
|
$this->assertTrue($equal, format_string('language negotiation for %type is properly set up', array('%type' => $type)));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ package = Testing
|
|||||||
version = VERSION
|
version = VERSION
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
files[] = menu.test
|
files[] = menu.test
|
||||||
configure = admin/structure/menu
|
configure = admin/structure/menu
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -9,8 +9,7 @@ required = TRUE
|
|||||||
configure = admin/structure/types
|
configure = admin/structure/types
|
||||||
stylesheets[all][] = node.css
|
stylesheets[all][] = node.css
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ version = VERSION
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -5,8 +5,7 @@ package = Core
|
|||||||
core = 7.x
|
core = 7.x
|
||||||
files[] = openid.test
|
files[] = openid.test
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
dependencies[] = openid
|
dependencies[] = openid
|
||||||
hidden = TRUE
|
hidden = TRUE
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -4,8 +4,7 @@ package = Core
|
|||||||
version = VERSION
|
version = VERSION
|
||||||
core = 7.x
|
core = 7.x
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,7 @@ core = 7.x
|
|||||||
files[] = path.test
|
files[] = path.test
|
||||||
configure = admin/config/search/path
|
configure = admin/config/search/path
|
||||||
|
|
||||||
; Information added by Drupal.org packaging script on 2018-03-28
|
; Information added by Drupal.org packaging script on 2019-05-08
|
||||||
version = "7.58"
|
version = "7.67"
|
||||||
project = "drupal"
|
project = "drupal"
|
||||||
datestamp = "1522264019"
|
datestamp = "1557336079"
|
||||||
|
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user