| @@ -109,8 +109,9 @@ | ||
| 109 | 109 | 'allow_svg', |
| 110 | 110 | ] |
| 111 | 111 | ); // phpcs:ignore WordPressVIPMinimum.Hooks.RestrictedHooks.upload_mimes |
| 112 | 112 | add_filter( 'wp_handle_upload_prefilter', [ $this, 'check_svg_and_sanitize' ] ); |
| 113 | + add_filter( 'wp_handle_sideload_prefilter', [ $this, 'sanitize_sideloaded_svg' ] ); | |
| 113 | 114 | } |
| 114 | 115 | |
| 115 | 116 | add_filter( 'themeisle-sdk/survey/' . OPTML_PRODUCT_SLUG, [ $this, 'get_survey_metadata' ], 10, 2 ); |
| 116 | 117 | add_action( 'admin_init', [ $this, 'mark_user_with_offload' ] ); |
| @@ -191,26 +192,67 @@ | ||
| 191 | 192 | * |
| 192 | 193 | * @return mixed |
| 193 | 194 | */ |
| 194 | 195 | public function check_svg_and_sanitize( $file ) { |
| 196 | + if ( ! is_array( $file ) || ! $this->is_svg_file( $file ) ) { | |
| 197 | + return $file; | |
| 198 | + } | |
| 199 | + | |
| 200 | + if ( ! current_user_can( 'upload_files' ) ) { | |
| 201 | + $file['error'] = 'Invalid'; | |
| 202 | + return $file; | |
| 203 | + } | |
| 204 | + | |
| 205 | + return $this->sanitize_svg_file( $file ); | |
| 206 | + } | |
| 207 | + | |
| 208 | + /** | |
| 209 | + * Sanitize an SVG stored through wp_handle_sideload(). | |
| 210 | + * | |
| 211 | + * Sideload callers authorize themselves (the REST media endpoint checks upload_files) and | |
| 212 | + * background restores run without a user, so only sanitization is applied here. | |
| 213 | + * | |
| 214 | + * @param array<string, mixed> $file An array of data for a single file. | |
| 215 | + * | |
| 216 | + * @return array<string, mixed> | |
| 217 | + */ | |
| 218 | + public function sanitize_sideloaded_svg( array $file ): array { | |
| 219 | + if ( ! $this->is_svg_file( $file ) ) { | |
| 220 | + return $file; | |
| 221 | + } | |
| 222 | + | |
| 223 | + return $this->sanitize_svg_file( $file ); | |
| 224 | + } | |
| 225 | + | |
| 226 | + /** | |
| 227 | + * Check whether an upload/sideload file array is an SVG. | |
| 228 | + * | |
| 229 | + * @param array<string, mixed> $file An array of data for a single file. | |
| 230 | + * | |
| 231 | + * @return bool | |
| 232 | + */ | |
| 233 | + private function is_svg_file( array $file ): bool { | |
| 195 | 234 | // Ensure we have a proper file path before processing. |
| 196 | 235 | if ( ! isset( $file['tmp_name'] ) ) { |
| 197 | - return $file; | |
| 236 | + return false; | |
| 198 | 237 | } |
| 199 | 238 | |
| 200 | 239 | $file_name = isset( $file['name'] ) ? $file['name'] : ''; |
| 201 | 240 | $wp_filetype = wp_check_filetype_and_ext( $file['tmp_name'], $file_name ); |
| 202 | - $type = ! empty( $wp_filetype['type'] ) ? $wp_filetype['type'] : ''; | |
| 203 | 241 | |
| 204 | - if ( 'image/svg+xml' === $type ) { | |
| 205 | - if ( ! current_user_can( 'upload_files' ) ) { | |
| 206 | - $file['error'] = 'Invalid'; | |
| 207 | - return $file; | |
| 208 | - } | |
| 242 | + return ! empty( $wp_filetype['type'] ) && 'image/svg+xml' === $wp_filetype['type']; | |
| 243 | + } | |
| 209 | 244 | |
| 210 | - if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) { | |
| 211 | - $file['error'] = 'Invalid'; | |
| 212 | - } | |
| 245 | + /** | |
| 246 | + * Sanitize the SVG temp file in place, flagging the upload when it cannot be sanitized. | |
| 247 | + * | |
| 248 | + * @param array<string, mixed> $file An array of data for a single file. | |
| 249 | + * | |
| 250 | + * @return array<string, mixed> | |
| 251 | + */ | |
| 252 | + private function sanitize_svg_file( array $file ): array { | |
| 253 | + if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) { | |
| 254 | + $file['error'] = 'Invalid'; | |
| 213 | 255 | } |
| 214 | 256 | |
| 215 | 257 | return $file; |
| 216 | 258 | } |
| @@ -221,9 +263,9 @@ | ||
| 221 | 263 | * @param string $file Temp file path. |
| 222 | 264 | * |
| 223 | 265 | * @return bool|int |
| 224 | 266 | */ |
| 225 | - protected function sanitize_svg( $file ) { | |
| 267 | + public function sanitize_svg( $file ) { | |
| 226 | 268 | // We can ignore the phpcs warning here as we're reading and writing to the Temp file. |
| 227 | 269 | $dirty = file_get_contents( $file ); // phpcs:ignore |
| 228 | 270 | |
| 229 | 271 | // Is the SVG gzipped? If so we try and decode the string. |
| @@ -252,12 +294,13 @@ | ||
| 252 | 294 | if ( $is_zipped ) { |
| 253 | 295 | $clean = gzencode( $clean ); |
| 254 | 296 | } |
| 255 | 297 | |
| 256 | - // We can ignore the phpcs warning here as we're reading and writing to the Temp file. | |
| 257 | - file_put_contents( $file, $clean ); // phpcs:ignore | |
| 298 | + // We handle the write result below; silence the warning on I/O failure. Reading/writing the temp file is intended. | |
| 299 | + $written = @file_put_contents( $file, $clean ); // phpcs:ignore WordPress.WP.AlternativeFunctions, WordPress.PHP.NoSilencedErrors | |
| 258 | 300 | |
| 259 | - return true; | |
| 301 | + // A failed write leaves the dirty upload in place, so report it as unsanitized. | |
| 302 | + return is_string( $clean ) && strlen( $clean ) === $written; | |
| 260 | 303 | } |
| 261 | 304 | |
| 262 | 305 | /** |
| 263 | 306 | * Check if the contents are gzipped |
| @@ -1414,8 +1457,11 @@ | ||
| 1414 | 1457 | $is_offload_media_available = 'yes'; |
| 1415 | 1458 | } |
| 1416 | 1459 | $api_key = $this->settings->get( 'api_key' ); |
| 1417 | 1460 | $service_data = $this->settings->get( 'service_data' ); |
| 1461 | + if ( ! is_array( $service_data ) ) { | |
| 1462 | + $service_data = []; | |
| 1463 | + } | |
| 1418 | 1464 | $user = get_userdata( get_current_user_id() ); |
| 1419 | 1465 | $user_status = 'inactive'; |
| 1420 | 1466 | $auto_connect = get_option( Optml_Settings::OPTML_USER_EMAIL, 'no' ); |
| 1421 | 1467 | $available_apps = isset( $service_data['available_apps'] ) ? $service_data['available_apps'] : null; |