Commit eb1357fe authored by Dylan Hardison's avatar Dylan Hardison

Bug 1230932 - Providing a condition as an ID to the webservice results in a taint error

r=dkl,a=dkl
parent 0cd77b4e
...@@ -68,6 +68,8 @@ use constant WS_ERROR_CODE => { ...@@ -68,6 +68,8 @@ use constant WS_ERROR_CODE => {
number_too_large => 54, number_too_large => 54,
number_too_small => 55, number_too_small => 55,
illegal_date => 56, illegal_date => 56,
param_integer_required => 57,
param_integer_array_required => 58,
# Bug errors usually occupy the 100-200 range. # Bug errors usually occupy the 100-200 range.
improper_bug_id_field_value => 100, improper_bug_id_field_value => 100,
bug_id_does_not_exist => 101, bug_id_does_not_exist => 101,
......
...@@ -22,6 +22,7 @@ use MIME::Base64 qw(decode_base64 encode_base64); ...@@ -22,6 +22,7 @@ use MIME::Base64 qw(decode_base64 encode_base64);
use Storable qw(dclone); use Storable qw(dclone);
use Test::Taint (); use Test::Taint ();
use URI::Escape qw(uri_unescape); use URI::Escape qw(uri_unescape);
use Bugzilla::WebService::Util qw(validate);
use parent qw(Exporter); use parent qw(Exporter);
...@@ -241,28 +242,6 @@ sub api_include_exclude { ...@@ -241,28 +242,6 @@ sub api_include_exclude {
return $params; return $params;
} }
sub validate {
my ($self, $params, @keys) = @_;
# If $params is defined but not a reference, then we weren't
# sent any parameters at all, and we're getting @keys where
# $params should be.
return ($self, undef) if (defined $params and !ref $params);
# If @keys is not empty then we convert any named
# parameters that have scalar values to arrayrefs
# that match.
foreach my $key (@keys) {
if (exists $params->{$key}) {
$params->{$key} = ref $params->{$key}
? $params->{$key}
: [ $params->{$key} ];
}
}
return ($self, $params);
}
sub translate { sub translate {
my ($params, $mapped) = @_; my ($params, $mapped) = @_;
my %changes; my %changes;
......
...@@ -1200,6 +1200,10 @@ sub update_comment_tags { ...@@ -1200,6 +1200,10 @@ sub update_comment_tags {
{ function => 'Bug.update_comment_tags', { function => 'Bug.update_comment_tags',
param => 'comment_id' }); param => 'comment_id' });
ThrowCodeError("param_integer_required", { function => 'Bug.update_comment_tags',
param => 'comment_id' })
unless $comment_id =~ /^[0-9]+$/;
my $comment = Bugzilla::Comment->new($comment_id) my $comment = Bugzilla::Comment->new($comment_id)
|| return []; || return [];
$comment->bug->check_is_visible(); $comment->bug->check_is_visible();
......
...@@ -69,6 +69,8 @@ use constant WS_ERROR_CODE => { ...@@ -69,6 +69,8 @@ use constant WS_ERROR_CODE => {
number_too_large => 54, number_too_large => 54,
number_too_small => 55, number_too_small => 55,
illegal_date => 56, illegal_date => 56,
param_integer_required => 57,
param_integer_array_required => 58,
# Bug errors usually occupy the 100-200 range. # Bug errors usually occupy the 100-200 range.
improper_bug_id_field_value => 100, improper_bug_id_field_value => 100,
bug_id_does_not_exist => 101, bug_id_does_not_exist => 101,
......
...@@ -18,6 +18,7 @@ use Bugzilla::WebService::Constants; ...@@ -18,6 +18,7 @@ use Bugzilla::WebService::Constants;
use Storable qw(dclone); use Storable qw(dclone);
use URI::Escape qw(uri_unescape); use URI::Escape qw(uri_unescape);
use List::MoreUtils qw(all any);
use parent qw(Exporter); use parent qw(Exporter);
...@@ -221,7 +222,8 @@ sub validate { ...@@ -221,7 +222,8 @@ sub validate {
# sent any parameters at all, and we're getting @keys where # sent any parameters at all, and we're getting @keys where
# $params should be. # $params should be.
return ($self, undef) if (defined $params and !ref $params); return ($self, undef) if (defined $params and !ref $params);
my @id_params = qw( ids comment_ids );
# If @keys is not empty then we convert any named # If @keys is not empty then we convert any named
# parameters that have scalar values to arrayrefs # parameters that have scalar values to arrayrefs
# that match. # that match.
...@@ -230,6 +232,12 @@ sub validate { ...@@ -230,6 +232,12 @@ sub validate {
$params->{$key} = ref $params->{$key} $params->{$key} = ref $params->{$key}
? $params->{$key} ? $params->{$key}
: [ $params->{$key} ]; : [ $params->{$key} ];
if (any { $key eq $_ } @id_params) {
my $ids = $params->{$key};
ThrowCodeError('param_integer_array_required', { param => $key })
unless ref($ids) eq 'ARRAY' && all { /^[0-9]+$/ } @$ids;
}
} }
} }
......
...@@ -294,6 +294,13 @@ ...@@ -294,6 +294,13 @@
a <code>[% param FILTER html %]</code> argument, and that a <code>[% param FILTER html %]</code> argument, and that
argument was not set. argument was not set.
[% ELSIF error == "param_integer_required" %]
The function <code>[% function FILTER html %]</code> requires
that <code>[% param FILTER html %]</code> be an integer.
[% ELSIF error == "param_integer_array_required" %]
The <code>[% param FILTER html %]</code> parameter must be an array of integers.
[% ELSIF error == "params_required" %] [% ELSIF error == "params_required" %]
[% title = "Missing Parameter" %] [% title = "Missing Parameter" %]
The function <code>[% function FILTER html %]</code> requires The function <code>[% function FILTER html %]</code> requires
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment