Commit 5c7b0575 authored by Matt Tyson's avatar Matt Tyson Committed by Dylan Hardison

Bug 1250786 - Detainting of params.json

r=dylan,a=dylan
parent 1969f955
...@@ -292,32 +292,23 @@ sub write_params { ...@@ -292,32 +292,23 @@ sub write_params {
} }
sub read_param_file { sub read_param_file {
my %params; my $params;
my $file = bz_locations()->{'datadir'} . '/params.json'; my $file = bz_locations()->{'datadir'} . '/params.json';
if (-e $file) { if (-e $file) {
my $data; my $data;
read_file($file, binmode => ':utf8', buf_ref => \$data); read_file($file, binmode => ':utf8', buf_ref => \$data);
trick_taint($data);
# If params.json has been manually edited and e.g. some quotes are # If params.json has been manually edited and e.g. some quotes are
# missing, we don't want JSON::XS to leak the content of the file # missing, we don't want JSON::XS to leak the content of the file
# to all users in its error message, so we have to eval'uate it. # to all users in its error message, so we have to eval'uate it.
%params = eval { %{JSON::XS->new->decode($data)} }; $params = eval { JSON::XS->new->decode($data) };
if ($@) { if ($@) {
my $error_msg = (basename($0) eq 'checksetup.pl') ? my $error_msg = (basename($0) eq 'checksetup.pl') ?
$@ : 'run checksetup.pl to see the details.'; $@ : 'run checksetup.pl to see the details.';
die "Error parsing $file: $error_msg"; die "Error parsing $file: $error_msg";
} }
# JSON::XS doesn't detaint data for us.
foreach my $key (keys %params) {
if (ref($params{$key}) eq "ARRAY") {
foreach my $item (@{$params{$key}}) {
trick_taint($item);
}
} else {
trick_taint($params{$key}) if defined $params{$key};
}
}
} }
elsif ($ENV{'SERVER_SOFTWARE'}) { elsif ($ENV{'SERVER_SOFTWARE'}) {
# We're in a CGI, but the params file doesn't exist. We can't # We're in a CGI, but the params file doesn't exist. We can't
...@@ -332,7 +323,7 @@ sub read_param_file { ...@@ -332,7 +323,7 @@ sub read_param_file {
die "The $file file does not exist." die "The $file file does not exist."
. ' You probably need to run checksetup.pl.', . ' You probably need to run checksetup.pl.',
} }
return \%params; return $params // {};
} }
1; 1;
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment