Fix SST-715: urlencode returside i udskriv-redirect fra formfunk.php - #451
Fix SST-715: urlencode returside i udskriv-redirect fra formfunk.php#451momocoder14 wants to merge 3 commits into
Conversation
returside blev indsat raa i redirect-URL til udskriv.php. Naar brugeren soeger paa kundenavn i ordrelisten indeholder returside-URL search- parametre som f.eks. &valg=faktura, der laekker ud som selvstaendige GET-parametre i udskriv.php. Dette medforer at $valg saettes til 'faktura' i stedet for 'pdf', PDF-fremviseren springes over, og brugeren ender paa en forkert 'Udskriftsvalg'-side. Urlencode() paa $returside sikrer at & og ? i vaerdien er korrekt kodet og ikke fortolkes som URL-separatorer.
|
Warning Review limit reached
Next review available in: 43 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe change validates ChangesReturn page security
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
The urlencode fixes the reported
Retest with a return URL containing nested |
- Valider returside ved input: accepter kun relative stier (../...) og den kendte legacy-vaerdi 'ordreliste.php' — afviser protokol-URL'er (javascript:, http://) og absolutte stier saa open-redirect er umulig - JS-kontekst (window.location.href): json_encode() i stedet for raa interpolering - URL-param i href (kreditor/debitor ordre-link): urlencode() - Direkte href-vaerdi (luk-knap): htmlspecialchars(ENT_QUOTES) - URL-param i meta-refresh (localprint): urlencode() - formfunk.php: cast returside til string foer urlencode() — undgaar PHP 8.1 null-deprecation naar nomailantal > 0 og returside er NULL
There was a problem hiding this comment.
🔇 Additional comments (6)
includes/formfunk.php (1)
2265-2265: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win
⚠️ Unverified finding
Sandbox verification was unavailable.Normalize non-string
retursidevalues before encoding.When a caller sends
returside[]=...,$retursideis an array. The explicit cast emits anArray to string conversionwarning. An error handler that converts warnings to exceptions can stop the redirect beforeudskriv.phpvalidates the value.Accept only string values and use an empty fallback for other types.
Proposed fix
- urlencode((string)($returside ?? '')) + urlencode(is_string($returside ?? null) ? $returside : '')Verify this behavior under the supported PHP version:
includes/udskriv.php (5)
7-7: LGTM!Also applies to: 44-44
75-82: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win
⚠️ Unverified finding
Sandbox verification was unavailable.Reject malformed UTF-8 before context encoding.
The validator accepts byte sequences that are not valid UTF-8. For example,
../%FFcan reachjson_encode($returside), which can returnfalseand renderwindow.location.href = ;. The HTML output can also become an empty attribute value.Reject invalid UTF-8 in the validator. Keep
ENT_SUBSTITUTEas defense in depth for HTML output.Suggested fix
$returside = (function($s) { $s = trim((string)$s); + if (preg_match('//u', $s) !== 1) return ''; if ($s === '' || $s === 'ordreliste.php') return $s; ... - if ($returside) $href="\"" . htmlspecialchars($returside, ENT_QUOTES, 'UTF-8') . "\" accesskey=\"L\""; + if ($returside) $href="\"" . htmlspecialchars($returside, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8') . "\" accesskey=\"L\"";Also applies to: 96-96, 465-465
75-82: 🗄️ Data Integrity & Integration
⚠️ Unverified finding
Sandbox verification was unavailable.Verify the
nav_back_url()output contract.
nav_back_url()returns a history entry directly and falls back toNAV_DEFAULT_URLinincludes/stdFunc/navStack.php, Lines [72-83]. The new validator discards every value that does not start with../. Confirm that all history entries andNAV_DEFAULT_URLuse this form. Otherwise valid return navigation becomes empty.
408-408: LGTM!
434-434: LGTM!Also applies to: 440-440, 446-446
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 8a8cc41e-aeb1-40b0-8c9d-56eb407cc812
📒 Files selected for processing (2)
includes/formfunk.phpincludes/udskriv.php
…litet - Afvis ugyldig UTF-8 i validatoren (json_encode returnerer ellers false) - Godkend rod-relative stier (/debitor/...) fra nav_back_url()/_SERVER[REQUEST_URI] saa historik-baseret tilbagenavigation ikke tabes - ENT_SUBSTITUTE tilfoejt til htmlspecialchars som forsvar i dybden - formfunk.php: is_string()-guard erstatter (string)-cast saa returside[]=... ikke giver PHP Array-to-string-advarsel
What are the changes about?
returside blev indsat raa i redirect-URL til udskriv.php. Naar brugeren soeger paa kundenavn i ordrelisten indeholder returside-URL search- parametre som f.eks. &valg=faktura, der laekker ud som selvstaendige GET-parametre i udskriv.php. Dette medforer at $valg saettes til 'faktura' i stedet for 'pdf', PDF-fremviseren springes over, og brugeren ender paa en forkert 'Udskriftsvalg'-side.
Urlencode() paa $returside sikrer at & og ? i vaerdien er korrekt kodet og ikke fortolkes som URL-separatorer.
Have you checked the following?
https://docs.google.com/document/d/1GOmomtvKf21OV2VWNOIPweDi4gJHpMCK5qXzrPrypUc/edit?usp=sharing
Summary by CodeRabbit