PluginProbe
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance / 3.2.21
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance v3.2.21
4.7.0 4.6.1 4.6.0 4.5.5 4.5.4 4.5.3 4.5.2 3.2.20 3.2.21 3.2.22 3.2.3 3.2.5 3.2.6 3.2.7 3.2.9 3.3.0 3.3.1 3.3.2 3.4.0 3.4.1 3.4.2 3.5.0 3.6.0 3.7.0 3.7.1 All 111 releases
wp-optimize / vendor / rosell-dk / webp-convert / src / Helpers / SanityCheck.txt

SanityCheck.txt in WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance 3.2.21, at vendor/rosell-dk/webp-convert/src/Helpers/SanityCheck.txt

256 lines 7.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace WebPConvert\Helpers;
4
5 use WebPConvert\Helpers\Sanitize;
6 use WebPConvert\Exceptions\SanityException;
7
8 class SanityCheck
9 {
10
11 /**
12 *
13 * @param string $input string to test for NUL char
14 */
15 public static function mustBeString($input, $errorMsg = 'String expected')
16 {
17 if (gettype($input) !== 'string') {
18 throw new SanityException($errorMsg);
19 }
20 return $input;
21 }
22
23 /**
24 * The NUL character is a demon, because it can be used to bypass other tests
25 * See https://st-g.de/2011/04/doing-filename-checks-securely-in-PHP.
26 *
27 * @param string $input string to test for NUL char
28 */
29 public static function noNUL($input, $errorMsg = 'NUL character is not allowed')
30 {
31 self::mustBeString($input);
32 if (strpos($input, chr(0)) !== false) {
33 throw new SanityException($errorMsg);
34 }
35 return $input;
36 }
37
38 /**
39 * Prevent control chararters (#00 - #20).
40 *
41 * This prevents line feed, new line, tab, charater return, tab, ets.
42 * https://www.rapidtables.com/code/text/ascii-table.html
43 *
44 * @param string $input string to test for control characters
45 */
46 public static function noControlChars($input)
47 {
48 self::mustBeString($input);
49 self::noNUL($input);
50 if (preg_match('#[\x{0}-\x{1f}]#', $input)) {
51 throw new SanityException('Control characters are not allowed');
52 }
53 return $input;
54 }
55
56
57 /**
58 *
59 * @param mixed $input something that may not be empty
60 */
61 public static function notEmpty($input, $errorMsg = 'Must be non-empty')
62 {
63 if (empty($input)) {
64 throw new SanityException($input);
65 }
66 return $input;
67 }
68
69
70
71 public static function noDirectoryTraversal($input, $errorMsg = 'Directory traversal is not allowed')
72 {
73 self::mustBeString($input);
74 self::noControlChars($input);
75 if (preg_match('#\.\.\/#', $input)) {
76 throw new SanityException($errorMsg);
77 }
78 return $input;
79 }
80
81 public static function noStreamWrappers($input, $errorMsg = 'Stream wrappers are not allowed')
82 {
83 self::mustBeString($input);
84 self::noControlChars($input);
85
86 // Prevent stream wrappers ("phar://", "php://" and the like)
87 // https://www.php.net/manual/en/wrappers.phar.php
88 if (preg_match('#^\\w+://#', Sanitize::removeNUL($input))) {
89 throw new SanityException($errorMsg);
90 }
91 return $input;
92 }
93
94 public static function path($input)
95 {
96 self::notEmpty($input);
97 self::mustBeString($input);
98 self::noControlChars($input);
99 self::noDirectoryTraversal($input);
100 self::noStreamWrappers($input);
101 return $input;
102 }
103
104 public static function pathWithoutDirectoryTraversal($input)
105 {
106 return self::path($input);
107 }
108
109 public static function absPathMicrosoftStyle($input, $errorMsg = 'Not an fully qualified Windows path')
110 {
111 // On microsoft we allow [drive letter]:\
112 if (!preg_match("#^[A-Z]:\\\\|/#", $input)) {
113 throw new SanityException($errorMsg . ':' . $input);
114 }
115 return $input;
116 }
117
118 public static function absPath($input, $errorMsg = 'Not an absolute path')
119 {
120 if ((strpos($input, '/') !== 0)) {
121
122 // Check if we are on Microsoft
123 $onMicrosoft = false;
124 if (isset($_SERVER['SERVER_SOFTWARE'])) {
125 if (strpos(strtolower($_SERVER['SERVER_SOFTWARE']), 'microsoft') !== false) {
126 $onMicrosoft = true;
127 }
128 }
129 switch (PHP_OS) {
130 case "WINNT":
131 case "WIN32":
132 case "INTERIX":
133 case "UWIN":
134 case "UWIN-W7":
135 $onMicrosoft = true;
136 break;
137 }
138
139 if (!$onMicrosoft) {
140 throw new SanityException($errorMsg . ':' . $input);
141 }
142 self::absPathMicrosoftStyle($input);
143
144 }
145 return self::path($input);
146 }
147
148 public static function pathBeginsWith($input, $beginsWith, $errorMsg = 'Path is outside allowed path')
149 {
150 self::path($input);
151 if (!(strpos($input, $beginsWith) === 0)) {
152 throw new SanityException($errorMsg);
153 }
154 return $input;
155 }
156
157 public static function findClosestExistingFolderSymLinksExpanded($input) {
158 $levelsUp = 1;
159 //echo 'input:' . $input;
160 while (true) {
161 $dir = dirname($input, $levelsUp);
162 //echo 'dir:' . $dir . '<br>';
163 $realPathResult = realpath($dir);
164 if ($realPathResult !== false) {
165 return $realPathResult;
166 }
167 if (($dir == '/') || (strlen($dir) < 4)) {
168 return $dir;
169 }
170 $levelsUp++;
171 }
172 return '/';
173 }
174
175 public static function pathBeginsWithSymLinksExpanded($input, $beginsWith, $errorMsg = 'Path is outside allowed path') {
176 $closestExistingFolder = self::findClosestExistingFolderSymLinksExpanded($input);
177 //throw new SanityException('hm.' . $input . ' : <br>' . $closestExistingFolder);
178 self::pathBeginsWith($closestExistingFolder, $beginsWith, $errorMsg);
179 }
180
181
182
183 public static function absPathExists($input, $errorMsg = 'Path does not exist')
184 {
185 self::absPath($input);
186 if (@!file_exists($input)) {
187 throw new SanityException($errorMsg);
188 }
189 return $input;
190 }
191
192 public static function absPathExistsAndIsDir(
193 $input,
194 $errorMsg = 'Path points to a file (it should point to a directory)'
195 ) {
196 self::absPathExists($input);
197 if (!is_dir($input)) {
198 throw new SanityException($errorMsg);
199 }
200 return $input;
201 }
202
203 public static function absPathExistsAndIsFile(
204 $input,
205 $errorMsg = 'Path points to a directory (it should not do that)'
206 ) {
207 self::absPathExists($input, 'File does not exist');
208 if (@is_dir($input)) {
209 throw new SanityException($errorMsg);
210 }
211 return $input;
212 }
213
214 public static function absPathExistsAndIsNotDir(
215 $input,
216 $errorMsg = 'Path points to a directory (it should point to a file)'
217 ) {
218 self::absPathExistsAndIsFile($input, $errorMsg);
219 return $input;
220 }
221
222
223 public static function pregMatch($pattern, $input, $errorMsg = 'Does not match expected pattern')
224 {
225 self::noNUL($input);
226 self::mustBeString($input);
227 if (!preg_match($pattern, $input)) {
228 throw new SanityException($errorMsg);
229 }
230 return $input;
231 }
232
233 public static function isJSONArray($input, $errorMsg = 'Not a JSON array')
234 {
235 self::noNUL($input);
236 self::mustBeString($input);
237 self::notEmpty($input);
238 if ((strpos($input, '[') !== 0) || (!is_array(json_decode($input)))) {
239 throw new SanityException($errorMsg);
240 }
241 return $input;
242 }
243
244 public static function isJSONObject($input, $errorMsg = 'Not a JSON object')
245 {
246 self::noNUL($input);
247 self::mustBeString($input);
248 self::notEmpty($input);
249 if ((strpos($input, '{') !== 0) || (!is_object(json_decode($input)))) {
250 throw new SanityException($errorMsg);
251 }
252 return $input;
253 }
254
255 }
256