Skip to content

Commit b386ea2

Browse files
authored
Merge pull request #5359 from ExpressionEngine/7.dev
Version 7.5.26
2 parents c55c82b + f9da9f6 commit b386ea2

60 files changed

Lines changed: 7148 additions & 98 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/tests-minimal.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -241,7 +241,7 @@ jobs:
241241

242242
- name: Start SMTP Server
243243
run: |
244-
npm install -g maildev
244+
npm install -g maildev@2.x
245245
maildev &
246246
247247
# This will get a Stable Chrome version that is 2 releases back from latest, and install it

‎.github/workflows/tests.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -192,7 +192,7 @@ jobs:
192192

193193
- name: Start SMTP Server
194194
run: |
195-
npm install -g maildev
195+
npm install -g maildev@2.x
196196
maildev &
197197
198198
# This will get a Stable Chrome version that is 2 releases back from latest, and install it

‎README.md‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,6 @@ ExpressionEngine separates your content from your design, enabling you to make s
4646
If you're new to ExpressionEngine, check out:
4747

4848
- [The Big Picture](https://docs.expressionengine.com/latest/getting-started/the-big-picture.html)
49-
- [Building a Simple News Site from Start to Finish](https://docs.expressionengine.com/latest/how_to/building_a_simple_news_site.html)
5049
- [10-minute ExpressionEngine Primer](https://www.youtube.com/watch?v=qKaOirMRz2s) on ExpressionEngineTV
5150

5251
## How to Contribute

‎build-tools/build.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"tag": "7.5.25",
2+
"tag": "7.5.26",
33
"repositories": {
44
"app": "git@github.com:ExpressionEngine/ExpressionEngine",
55
"docs": "git@github.com:ExpressionEngine/ExpressionEngine-User-Guide"

‎system/ee/ExpressionEngine/Addons/channel/libraries/channel_form/Channel_form_lib.php‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1113,10 +1113,12 @@ private function _build_custom_field_variables()
11131113
*/
11141114
private function _swap_custom_field_variables($custom_field_variables_row, $tagdata)
11151115
{
1116+
$integer_variables = array('field_id', 'field_data', 'rows', 'maxlength');
1117+
11161118
foreach ($custom_field_variables_row as $key => $value) {
11171119
if (is_array($value)) {
11181120
$tagdata = $this->swap_var_pair($key, $value, $tagdata);
1119-
} elseif ($key === 'field_id') {
1121+
} elseif (in_array($key, $integer_variables, true)) {
11201122
$tagdata = ee()->TMPL->swap_var_single($key, (string) $value, $tagdata);
11211123
} elseif (! is_int($value)) {
11221124
// don't use our conditionals as vars

‎system/ee/ExpressionEngine/Addons/file/ft.file.php‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -153,9 +153,10 @@ public function save($data)
153153
}
154154

155155
/**
156-
* Show the publish field
156+
* Render the publish field for the current request.
157157
*
158-
* @access public
158+
* @param mixed $data Stored file field data
159+
* @return string Rendered file field
159160
*/
160161
public function display_field($data)
161162
{
@@ -188,7 +189,8 @@ public function display_field($data)
188189
$allowed_file_dirs,
189190
$content_type,
190191
$filebrowser,
191-
($show_existing == 'y') ? $existing_limit : null
192+
($show_existing == 'y') ? $existing_limit : null,
193+
($this->content_type() === 'channel') ? $this->field_name : null
192194
);
193195
}
194196

‎system/ee/ExpressionEngine/Addons/pro_search/helpers/pro_search_helper.php‎

Lines changed: 58 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,11 @@ function pro_search_encode($array = array(), $url = true)
4747
}
4848

4949
/**
50-
* Decode a query back to the array
50+
* Decode a Pro Search query payload back to an array.
51+
*
52+
* @param string $str Encoded query string.
53+
* @param bool $url Whether the payload is URL-safe base64 encoded.
54+
* @return array
5155
*/
5256
if (! function_exists('pro_search_decode')) {
5357
function pro_search_decode($str = '', $url = true)
@@ -71,21 +75,71 @@ function pro_search_decode($str = '', $url = true)
7175
$str = str_replace(' ', '+', $str);
7276

7377
// Decode back
74-
$str = base64_decode($str);
78+
$str = base64_decode($str, true);
79+
80+
if ($str === false) {
81+
return array();
82+
}
7583
}
7684

7785
// Decoding method
78-
$array = (substr($str, 0, 2) == 'a:') ? @unserialize($str) : @json_decode($str, true);
86+
$array = (substr($str, 0, 2) == 'a:')
87+
? @unserialize($str, array('allowed_classes' => false))
88+
: @json_decode($str, true);
7989

8090
// Force array output
81-
if (! is_array($array)) {
91+
if (! is_array($array) || contains_non_scalar_or_recursive_values($array)) {
8292
$array = array();
8393
}
8494

8595
return $array;
8696
}
8797
}
8898

99+
/**
100+
* Determine if an array contains non-scalar or recursive values.
101+
*
102+
* @param array $array Decoded query array.
103+
* @return bool
104+
*/
105+
if (! function_exists('contains_non_scalar_or_recursive_values')) {
106+
function contains_non_scalar_or_recursive_values($array)
107+
{
108+
$nonScalar = false;
109+
$recursive = false;
110+
111+
set_error_handler(function () use (&$recursive) {
112+
$recursive = true;
113+
114+
return true;
115+
});
116+
117+
try {
118+
array_walk_recursive($array, function ($value) use (&$nonScalar) {
119+
if (is_object($value) || is_resource($value)) {
120+
$nonScalar = true;
121+
}
122+
});
123+
} catch (Throwable $exception) {
124+
$recursive = true;
125+
} finally {
126+
restore_error_handler();
127+
}
128+
129+
if ($recursive) {
130+
return true;
131+
}
132+
133+
foreach ($array as $value) {
134+
if (is_object($value) || is_resource($value)) {
135+
return true;
136+
}
137+
}
138+
139+
return $nonScalar;
140+
}
141+
}
142+
89143
// --------------------------------------------------------------------
90144

91145
/**

‎system/ee/ExpressionEngine/Controller/Design/Group.php‎

Lines changed: 22 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -476,17 +476,35 @@ public function edit($group_name, $group_id = null)
476476
ee()->cp->render('settings/form', $vars);
477477
}
478478

479+
/**
480+
* Remove a Template Group.
481+
*
482+
* @return void
483+
*/
479484
public function remove()
480485
{
481-
if (! ee('Permission')->can('delete_template_groups')) {
486+
if (
487+
! ee('Permission')->can('delete_template_groups') ||
488+
ee('Request')->method() !== 'POST'
489+
) {
482490
show_error(lang('unauthorized_access'), 403);
483491
}
484492

493+
$group_id = ee()->input->post('group_id');
494+
$group_name = ee()->input->post('group_name');
495+
496+
if (
497+
! is_numeric($group_id) &&
498+
(! is_string($group_name) || $group_name === '')
499+
) {
500+
show_error(lang('group_not_found'));
501+
}
502+
485503
$groups = ee('Model')->get('TemplateGroup');
486-
if (is_numeric(ee()->input->post('group_id'))) {
487-
$groups = $groups->filter('group_id', ee()->input->post('group_id'));
504+
if (is_numeric($group_id)) {
505+
$groups = $groups->filter('group_id', $group_id);
488506
} else {
489-
$groups = $groups->filter('group_name', ee()->input->post('group_name'));
507+
$groups = $groups->filter('group_name', $group_name);
490508
}
491509
$groups = $groups->filter('site_id', ee()->config->item('site_id'))
492510
->all();

‎system/ee/ExpressionEngine/Controller/Design/Template.php‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -597,6 +597,11 @@ private function validateTemplate(TemplateModel $template)
597597
$_POST['template_engine'] = null;
598598
}
599599

600+
if (! ee('Permission')->isSuperAdmin()) {
601+
$_POST['allow_php'] = $template->isNew() ? 'n' : $template->allow_php;
602+
$_POST['php_parse_location'] = $template->isNew() ? 'o' : $template->php_parse_location;
603+
}
604+
600605
$template->set($_POST);
601606
$template->edit_date = ee()->localize->now;
602607
$template->last_author_id = ee()->session->userdata('member_id');

‎system/ee/ExpressionEngine/Controller/Members/Members.php‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -929,7 +929,7 @@ private function renderMemberTab($errors)
929929
foreach (ee('Model')->make('Member')->getDisplay()->getFields() as $field) {
930930
$sections['custom_fields'][] = [
931931
'title' => $field->getLabel(),
932-
'desc' => $field->getInstructions(),
932+
'desc' => ee('Format')->make('Text', (string) $field->getInstructions())->convertToEntities()->compile(),
933933
'fields' => [
934934
$field->getName() => [
935935
'type' => 'html',

0 commit comments

Comments
 (0)