Skip to content

Commit c55c82b

Browse files
authored
Merge pull request #5332 from ExpressionEngine/7.dev
Release 7.5.25
2 parents e5a6b9c + a1e5039 commit c55c82b

32 files changed

Lines changed: 1528 additions & 145 deletions

File tree

‎build-tools/build.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"tag": "7.5.24",
2+
"tag": "7.5.25",
33
"repositories": {
44
"app": "git@github.com:ExpressionEngine/ExpressionEngine",
55
"docs": "git@github.com:ExpressionEngine/ExpressionEngine-User-Guide"

‎build-tools/make_version.php‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -605,15 +605,22 @@ private function createUpdateFile()
605605
}
606606
}
607607

608+
/**
609+
* Read a sanitized line of user input from STDIN.
610+
*
611+
* @param string $message
612+
* @return string
613+
* @throws Exception
614+
*/
608615
private function prompt($message)
609616
{
610617
echo $message;
611618
$handle = fopen('php://stdin', 'r');
612619
$input = trim(fgets($handle));
613620
fclose($handle);
614621

615-
// Basic input validation - remove any control characters
616-
$input = filter_var($input, FILTER_SANITIZE_STRING, FILTER_FLAG_NO_ENCODE_QUOTES);
622+
$input = strip_tags($input);
623+
$input = preg_replace('/[\x00-\x1F\x7F]/', '', $input);
617624

618625
// Limit input length to prevent issues
619626
if (strlen($input) > 100) {

‎system/ee/ExpressionEngine/Addons/channel/libraries/channel_form/Channel_form_lib.php‎

Lines changed: 24 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -305,14 +305,7 @@ public function entry_form()
305305
);
306306
}
307307

308-
foreach ($custom_field_variables_row as $key => $value) {
309-
if (is_array($value)) {
310-
$temp = $this->swap_var_pair($key, $value, $temp);
311-
} elseif (! is_int($value)) {
312-
// don't use our conditionals as vars
313-
$temp = ee()->TMPL->swap_var_single($key, $value, $temp);
314-
}
315-
}
308+
$temp = $this->_swap_custom_field_variables($custom_field_variables_row, $temp);
316309

317310
if ($custom_field_variables_row['field_type'] === 'catchall') {
318311
$temp = $this->replace_tag($field_name, $this->entry($field_name), array(), $temp);
@@ -1111,6 +1104,29 @@ private function _build_custom_field_variables()
11111104
return $custom_field_variables;
11121105
}
11131106

1107+
/**
1108+
* Swap variables inside a single {custom_fields} row.
1109+
*
1110+
* @param array $custom_field_variables_row
1111+
* @param string $tagdata
1112+
* @return string
1113+
*/
1114+
private function _swap_custom_field_variables($custom_field_variables_row, $tagdata)
1115+
{
1116+
foreach ($custom_field_variables_row as $key => $value) {
1117+
if (is_array($value)) {
1118+
$tagdata = $this->swap_var_pair($key, $value, $tagdata);
1119+
} elseif ($key === 'field_id') {
1120+
$tagdata = ee()->TMPL->swap_var_single($key, (string) $value, $tagdata);
1121+
} elseif (! is_int($value)) {
1122+
// don't use our conditionals as vars
1123+
$tagdata = ee()->TMPL->swap_var_single($key, $value, $tagdata);
1124+
}
1125+
}
1126+
1127+
return $tagdata;
1128+
}
1129+
11141130
/**
11151131
* Add global and field errors
11161132
*

‎system/ee/ExpressionEngine/Addons/file/ft.file.php‎

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -90,9 +90,21 @@ public function validate($data)
9090
$fluid_field_data_id
9191
);
9292

93-
// If this filed was we need to check permissions.
94-
if (! isset($this->settings['grid_row_id']) || $rows[$this->content_id][$this->settings['grid_row_id']] != $data) {
93+
// If this field changed we need to check permissions.
94+
if (! isset($this->settings['grid_row_id'])) {
9595
$check_permissions = true;
96+
} else {
97+
$row = isset($rows[$this->content_id][$this->settings['grid_row_id']])
98+
? $rows[$this->content_id][$this->settings['grid_row_id']]
99+
: array();
100+
$col_id = isset($this->settings['col_id']) ? 'col_id_' . $this->settings['col_id'] : null;
101+
$existing = (is_array($row) && $col_id && array_key_exists($col_id, $row))
102+
? $row[$col_id]
103+
: null;
104+
105+
if ($existing != $data) {
106+
$check_permissions = true;
107+
}
96108
}
97109
} else {
98110
$entry = ee('Model')->get('ChannelEntry', $this->content_id)->first();

‎system/ee/ExpressionEngine/Addons/member/mod.member.php‎

Lines changed: 48 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -2099,8 +2099,13 @@ public function breadcrumb()
20992099
return $this->_build_crumbs($pm_page, $crumbs, $pm_page);
21002100
}
21012101

2102-
if (is_numeric(ee()->uri->segment(2))) {
2103-
$query = ee()->db->query("SELECT screen_name FROM exp_members WHERE member_id = '" . ee()->uri->segment(2) . "'");
2102+
$member_id = ee()->uri->segment(2);
2103+
2104+
if (ctype_digit((string) $member_id)) {
2105+
$query = ee()->db
2106+
->select('screen_name')
2107+
->where('member_id', (int) $member_id)
2108+
->get('members');
21042109

21052110
$crumbs .= $this->_crumb_trail(
21062111
array(
@@ -2894,7 +2899,14 @@ public function ignore_list()
28942899
$prelen = strlen($pre);
28952900

28962901
if ($member_id = ee()->TMPL->fetch_param('member_id')) {
2897-
$query = ee()->db->query("SELECT ignore_list FROM exp_members WHERE member_id = '{$member_id}'");
2902+
if (! ctype_digit((string) $member_id)) {
2903+
return ee()->TMPL->no_results();
2904+
}
2905+
2906+
$query = ee()->db
2907+
->select('ignore_list')
2908+
->where('member_id', (int) $member_id)
2909+
->get('members');
28982910

28992911
if ($query->num_rows() == 0) {
29002912
return ee()->TMPL->no_results();
@@ -2905,10 +2917,39 @@ public function ignore_list()
29052917
$ignored = ee()->session->userdata('ignore_list');
29062918
}
29072919

2908-
$query = ee()->db->query("SELECT m.member_id, m.role_id, m.role_id AS group_id, m.username, m.screen_name, m.email, m.ip_address, m.total_entries, m.total_comments, m.private_messages, m.total_forum_topics, m.total_forum_posts AS total_forum_replies, m.total_forum_topics + m.total_forum_posts AS total_forum_posts,
2909-
r.name AS group_description FROM exp_members AS m, exp_roles AS r
2910-
WHERE r.role_id = m.role_id
2911-
AND m.member_id IN ('" . implode("', '", $ignored) . "')");
2920+
if (! is_array($ignored)) {
2921+
$ignored = ($ignored == '') ? array() : explode('|', (string) $ignored);
2922+
}
2923+
2924+
$ignored = array_values(array_unique(array_map('intval', array_filter($ignored, function ($member_id) {
2925+
return ctype_digit((string) $member_id) && (int) $member_id > 0;
2926+
}))));
2927+
2928+
if (empty($ignored)) {
2929+
return ee()->TMPL->no_results();
2930+
}
2931+
2932+
$query = ee()->db
2933+
->select(array(
2934+
'm.member_id',
2935+
'm.role_id',
2936+
'm.role_id AS group_id',
2937+
'm.username',
2938+
'm.screen_name',
2939+
'm.email',
2940+
'm.ip_address',
2941+
'm.total_entries',
2942+
'm.total_comments',
2943+
'm.private_messages',
2944+
'm.total_forum_topics',
2945+
'm.total_forum_posts AS total_forum_replies',
2946+
'm.total_forum_topics + m.total_forum_posts AS total_forum_posts',
2947+
'r.name AS group_description',
2948+
), false)
2949+
->from('members AS m')
2950+
->join('roles AS r', 'r.role_id = m.role_id')
2951+
->where_in('m.member_id', $ignored)
2952+
->get();
29122953

29132954
if ($query->num_rows() == 0) {
29142955
return ee()->TMPL->no_results();

‎system/ee/ExpressionEngine/Addons/moblog/mod.moblog.php‎

Lines changed: 42 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -698,20 +698,7 @@ public function check_pop_moblog()
698698
preg_match("/\<field\>(.*)\<\/field\>/s", $this->body, $matches))) {
699699
$matches[1] = trim($matches[1]);
700700

701-
ee()->db->select('field_id');
702-
ee()->db->from('channel_fields');
703-
ee()->db->where('(channel_fields.field_name = "' . $matches[1] . '" OR ' . ee()->db->dbprefix('channel_fields') . '.field_label = "' . $matches[1] . '")', null, false);
704-
705-
/* -------------------------------------
706-
/* Hidden Configuration Variable
707-
/* - moblog_allow_nontextareas => Removes the textarea only restriction
708-
/* for custom fields in the moblog module (y/n)
709-
/* -------------------------------------*/
710-
if (ee()->config->item('moblog_allow_nontextareas') != 'y') {
711-
ee()->db->where('channel_fields.field_type', 'textarea');
712-
}
713-
714-
$results = ee()->db->get();
701+
$results = $this->getFieldByNameOrLabel($matches[1], 'field_id');
715702

716703
if ($results->num_rows() > 0) {
717704
$this->moblog_array['moblog_field_id'] = trim($results->row('field_id'));
@@ -1039,6 +1026,40 @@ public function assign_parameters($str)
10391026
return ee('Variables/Parser')->parseTagParameters($str);
10401027
}
10411028

1029+
/**
1030+
* Look up a Moblog target field by name or label using bound values.
1031+
*/
1032+
private function getFieldByNameOrLabel($field_name, $select = 'field_id', $group_id = null)
1033+
{
1034+
$where = array();
1035+
$binds = array();
1036+
1037+
if ($group_id !== null) {
1038+
$where[] = 'group_id = ?';
1039+
$binds[] = $group_id;
1040+
}
1041+
1042+
$where[] = '(field_name = ? OR field_label = ?)';
1043+
$binds[] = $field_name;
1044+
$binds[] = $field_name;
1045+
1046+
/* -------------------------------------
1047+
/* Hidden Configuration Variable
1048+
/* - moblog_allow_nontextareas => Removes the textarea only restriction
1049+
/* for custom fields in the moblog module (y/n)
1050+
/* -------------------------------------*/
1051+
if (ee()->config->item('moblog_allow_nontextareas') != 'y') {
1052+
$where[] = 'field_type = ?';
1053+
$binds[] = 'textarea';
1054+
}
1055+
1056+
$sql = 'SELECT ' . $select .
1057+
' FROM ' . ee()->db->dbprefix('channel_fields') .
1058+
' WHERE ' . implode(' AND ', $where);
1059+
1060+
return ee()->db->query($sql, $binds);
1061+
}
1062+
10421063
/**
10431064
* parse_field
10441065
*
@@ -1064,17 +1085,7 @@ public function parse_field($params, $field_data)
10641085
$format = ($results->num_rows() > 0) ? $results->row('field_fmt') : 'none';
10651086
} else {
10661087
if ($params['name'] != '' && $params['format'] == '') {
1067-
$xsql = (ee()->config->item('moblog_allow_nontextareas') == 'y') ? "" : " AND exp_channel_fields.field_type = 'textarea' ";
1068-
1069-
ee()->db->select('field_id, field_fmt');
1070-
ee()->db->where('group_id', $field_id);
1071-
ee()->db->where('(field_name = "' . $params['name'] . '" OR field_label = "' . $params['name'] . '")', null, false);
1072-
1073-
if (ee()->config->item('moblog_allow_nontextareas') != 'y') {
1074-
ee()->db->where('field_type', 'textarea');
1075-
}
1076-
1077-
$results = ee()->db->get('channel_fields');
1088+
$results = $this->getFieldByNameOrLabel($params['name'], 'field_id, field_fmt', $field_id);
10781089

10791090
$field_id = ($results->num_rows() > 0) ? $results->row('field_id') : $this->moblog_array['moblog_field_id'];
10801091
$format = ($results->num_rows() > 0) ? $results->row('field_fmt') : 'none';
@@ -1091,16 +1102,7 @@ public function parse_field($params, $field_data)
10911102
$field_id = $this->moblog_array['moblog_field_id'];
10921103
$format = $params['format'];
10931104
} elseif ($params['name'] != '' && $params['format'] != '') {
1094-
$xsql = (ee()->config->item('moblog_allow_nontextareas') == 'y') ? "" : " AND exp_channel_fields.field_type = 'textarea' ";
1095-
1096-
ee()->db->select('field_id');
1097-
ee()->db->where('(field_name = "' . $params['name'] . '" OR field_label = "' . $params['name'] . '")');
1098-
1099-
if (ee()->config->item('moblog_allow_nontextareas') != 'y') {
1100-
ee()->db->where('field_type', 'textarea');
1101-
}
1102-
1103-
$results = ee()->db->get('channel_fields');
1105+
$results = $this->getFieldByNameOrLabel($params['name'], 'field_id');
11041106

11051107
$field_id = ($results->num_rows() > 0) ? $results->row('field_id') : $this->moblog_array['moblog_field_id'];
11061108
$format = $params['format'];
@@ -1595,7 +1597,9 @@ private function _process_attachment($value, $type, $subtype)
15951597
return true;
15961598
}
15971599

1598-
// Clean the file
1600+
// Clean decoded attachment content before raw_upload().
1601+
// EE_Upload is loaded below with explicit config, so its constructor
1602+
// does not enable the default xss_check() behavior for this path.
15991603
ee()->load->helper('xss');
16001604

16011605
if (xss_check()) {
@@ -1652,7 +1656,8 @@ private function _process_attachment($value, $type, $subtype)
16521656
$file_path = ee()->upload->upload_path . $filename;
16531657
}
16541658

1655-
// Disable xss cleaning in the filemanager
1659+
// The decoded attachment contents were cleaned above. Avoid a second
1660+
// File Manager XSS pass while registering the already-uploaded file.
16561661
ee()->filemanager->xss_clean_off();
16571662

16581663
// Send the file

‎system/ee/ExpressionEngine/Addons/structure/tab.structure.php‎

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,13 @@ public function display($channel_id, $entry_id = '')
7575
return $this->publish_tabs($channel_id, $entry_id);
7676
}
7777

78+
/**
79+
* Build the Structure publish tab settings for the current channel.
80+
*
81+
* @param int|string $channel_id
82+
* @param int|string $entry_id
83+
* @return array
84+
*/
7885
public function publish_tabs($channel_id, $entry_id = '')
7986
{
8087
$settings = array();
@@ -106,8 +113,9 @@ public function publish_tabs($channel_id, $entry_id = '')
106113
if (empty($entry_id)) {
107114
ee()->cp->add_js_script('plugin', 'ee_url_title');
108115

109-
if (ee()->input->get('parent_id')) {
110-
ee()->javascript->output('$("section.wrap div.tab-wrap > form").prepend(\'<input type="hidden" name="structure__parent_id" value="' . ee()->input->get('parent_id') . '" />\');');
116+
$parent_id = (int) ee()->input->get('parent_id');
117+
if ($parent_id > 0) {
118+
ee()->javascript->output('$("section.wrap div.tab-wrap > form").prepend(\'<input type="hidden" name="structure__parent_id" value="' . $parent_id . '" />\');');
111119
}
112120

113121
ee()->javascript->output('

‎system/ee/ExpressionEngine/Config/mimes.php‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,9 @@
2020
return array(
2121
'img' => array(
2222
'application/x-photoshop', // .psd
23+
'image/vnd.adobe.photoshop', // .psd
2324
'image/bmp', // .bmp
25+
'image/x-ms-bmp', // .bmp
2426
'image/gif', // .gif
2527
'image/jpeg', // .jpg, .jpe, .jpeg
2628
'image/pjpeg', // .jpg, .jpe, .jpeg
@@ -108,17 +110,23 @@
108110
),
109111
'archive' => array(
110112
'application/x-gtar', // .gtar
113+
'application/gzip', // .gz
111114
'application/x-gzip', // .gz
115+
'application/vnd.rar', // .rar
116+
'application/x-rar', // .rar
112117
'application/x-rar-compressed', // .rar
113118
'application/x-stuffit', // .sit
119+
'application/tar', // .tar, .tgz
114120
'application/x-tar', // .tar, .tgz
115121
'application/x-zip', // .zip
116122
'application/x-zip-compressed', // .zip
117123
'application/zip', // .zip
118124
),
119125
'audio' => array(
120126
'audio/flac', // .flac
127+
'audio/x-flac', // .flac
121128
'audio/m4a', // .m4a
129+
'audio/mp4a-latm', // .m4a, .m4p
122130
'audio/x-m4a', // m4a
123131
'audio/midi', // .mid, .midi
124132
'audio/mp4', // .mp4
@@ -129,11 +137,14 @@
129137
'audio/x-pn-realaudio', // .ram, .rm
130138
'audio/x-pn-realaudio-plugin', // .rpm
131139
'audio/x-realaudio', // .ra
140+
'audio/wav', // .wav
141+
'audio/wave', // .wav
132142
'audio/x-wav', // .wav
133143
),
134144
'video' => array(
135145
'application/ogg', // .ogv
136146
'video/m4v', // .m4v
147+
'video/x-m4v', // .m4v
137148
'video/mp4', // .mp4
138149
'video/mpeg', // .mpe, .mpeg, .mpg
139150
'video/ogg', // .ogv

‎system/ee/ExpressionEngine/Controller/Addons/Addons.php‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -685,14 +685,17 @@ public function install($addons)
685685
}
686686

687687
/**
688-
* Uninstalls an add-on
688+
* Uninstall one or more add-ons.
689689
*
690-
* @param str|array $addons The name(s) of add-ons to uninstall
691-
* @return void
690+
* @param string|array $addons The name(s) of add-ons to uninstall.
691+
* @return void
692692
*/
693693
public function remove($addons)
694694
{
695-
if (! ee('Permission')->can('admin_addons')) {
695+
if (
696+
! ee('Permission')->can('admin_addons') or
697+
ee('Request')->method() !== 'POST'
698+
) {
696699
show_error(lang('unauthorized_access'), 403);
697700
}
698701

0 commit comments

Comments
 (0)