@@ -47,7 +47,11 @@ function pro_search_encode($array = array(), $url = true)
4747}
4848
4949/**
50- * Decode a query back to the array
50+ * Decode a Pro Search query payload back to an array.
51+ *
52+ * @param string $str Encoded query string.
53+ * @param bool $url Whether the payload is URL-safe base64 encoded.
54+ * @return array
5155 */
5256if (! function_exists ('pro_search_decode ' )) {
5357 function pro_search_decode ($ str = '' , $ url = true )
@@ -71,21 +75,71 @@ function pro_search_decode($str = '', $url = true)
7175 $ str = str_replace (' ' , '+ ' , $ str );
7276
7377 // Decode back
74- $ str = base64_decode ($ str );
78+ $ str = base64_decode ($ str , true );
79+
80+ if ($ str === false ) {
81+ return array ();
82+ }
7583 }
7684
7785 // Decoding method
78- $ array = (substr ($ str , 0 , 2 ) == 'a: ' ) ? @unserialize ($ str ) : @json_decode ($ str , true );
86+ $ array = (substr ($ str , 0 , 2 ) == 'a: ' )
87+ ? @unserialize ($ str , array ('allowed_classes ' => false ))
88+ : @json_decode ($ str , true );
7989
8090 // Force array output
81- if (! is_array ($ array )) {
91+ if (! is_array ($ array ) || contains_non_scalar_or_recursive_values ( $ array ) ) {
8292 $ array = array ();
8393 }
8494
8595 return $ array ;
8696 }
8797}
8898
99+ /**
100+ * Determine if an array contains non-scalar or recursive values.
101+ *
102+ * @param array $array Decoded query array.
103+ * @return bool
104+ */
105+ if (! function_exists ('contains_non_scalar_or_recursive_values ' )) {
106+ function contains_non_scalar_or_recursive_values ($ array )
107+ {
108+ $ nonScalar = false ;
109+ $ recursive = false ;
110+
111+ set_error_handler (function () use (&$ recursive ) {
112+ $ recursive = true ;
113+
114+ return true ;
115+ });
116+
117+ try {
118+ array_walk_recursive ($ array , function ($ value ) use (&$ nonScalar ) {
119+ if (is_object ($ value ) || is_resource ($ value )) {
120+ $ nonScalar = true ;
121+ }
122+ });
123+ } catch (Throwable $ exception ) {
124+ $ recursive = true ;
125+ } finally {
126+ restore_error_handler ();
127+ }
128+
129+ if ($ recursive ) {
130+ return true ;
131+ }
132+
133+ foreach ($ array as $ value ) {
134+ if (is_object ($ value ) || is_resource ($ value )) {
135+ return true ;
136+ }
137+ }
138+
139+ return $ nonScalar ;
140+ }
141+ }
142+
89143// --------------------------------------------------------------------
90144
91145/**
0 commit comments