Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enforce 65k character limit when attempting to update setting values. #3162

Merged
merged 14 commits into from
Nov 12, 2021
9 changes: 7 additions & 2 deletions src/Forum/ForumServiceProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -31,8 +31,10 @@
use Flarum\Settings\Event\Saved;
use Flarum\Settings\Event\Saving;
use Flarum\Settings\SettingsRepositoryInterface;
use Flarum\Settings\SettingsValidator;
use Illuminate\Contracts\Container\Container;
use Illuminate\Contracts\Events\Dispatcher;
use Illuminate\Contracts\Validation\Factory as ValidatorFactory;
use Illuminate\Contracts\View\Factory;
use Laminas\Stratigility\MiddlewarePipe;
use Symfony\Contracts\Translation\TranslatorInterface;
Expand Down Expand Up @@ -131,7 +133,7 @@ public function register()
});
}

public function boot(Container $container, Dispatcher $events, Factory $view)
public function boot(Container $container, Dispatcher $events, Factory $view, ValidatorFactory $validatorFactory)
{
$this->loadViewsFrom(__DIR__.'/../../views', 'flarum.forum');

Expand Down Expand Up @@ -172,7 +174,10 @@ function (Saved $event) use ($container) {

$events->listen(
Saving::class,
function (Saving $event) use ($container) {
function (Saving $event) use ($container, $validatorFactory) {
$settingsValidator = new SettingsValidator($validatorFactory, $event->settings);
$settingsValidator->validate();

$validator = new ValidateCustomLess(
$container->make('flarum.assets.forum'),
$container->make('flarum.locales'),
Expand Down
46 changes: 46 additions & 0 deletions src/Settings/SettingsValidator.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
<?php

/*
* This file is part of Flarum.
*
* For detailed copyright and license information, please view the
* LICENSE file that was distributed with this source code.
*/

namespace Flarum\Settings;

use Illuminate\Contracts\Validation\Factory;
use Illuminate\Validation\ValidationException;

class SettingsValidator
{
/**
* @var Factory
*/
protected $validatorFactory;

/**
* @var array
*/
protected $settings;

public function __construct(Factory $validatorFactory, array $settings)
{
$this->validatorFactory = $validatorFactory;
$this->settings = $settings;
}

public function validate()
{
$validator = $this->validatorFactory->make(
$this->settings,
array_map(function ($value) {
return 'max:65000';
}, $this->settings),
);

if ($validator->fails()) {
throw new ValidationException($validator);
}
}
}