Files
XC_VM/tests/Unit/InputValidatorTest.php
T
rootandClaude Opus 5 0d06fff983 fix(security): confirmIDs returns the integers it checked
InputValidator::confirmIDs() kept an id when intval($id) > 0 but returned
the original value, and its callers implode the result into SQL `IN (...)`
lists (mass edit and delete of lines, users, streams, series; bouquet
contents; global search). '1) OR (1=1' has an intval of 1, so it passed the
filter and reached the query unchanged. It now returns the integers.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA
2026-09-17 07:45:48 +00:00

42 lines
1.3 KiB
PHP

<?php
use XcVm\Core\Validation\InputValidator;
use PHPUnit\Framework\TestCase;
final class InputValidatorTest extends TestCase {
public function testValidateReturnsFalseWhenRequiredFieldsMissing() {
$this->assertFalse(InputValidator::validate('processProvider', array()));
}
public function testValidateReturnsTrueForMinimalProviderPayload() {
$payload = array(
'ip' => '127.0.0.1',
'port' => 8080,
'username' => 'user',
'password' => 'pass',
'name' => 'provider',
);
$this->assertTrue(InputValidator::validate('processProvider', $payload));
}
public function testValidateOrFailUsesStatusConstant() {
if (!defined('STATUS_INVALID_INPUT')) {
define('STATUS_INVALID_INPUT', 400);
}
$result = InputValidator::validateOrFail('processProvider', array('ip' => '127.0.0.1'));
$this->assertSame(STATUS_INVALID_INPUT, $result['status']);
}
/**
* Callers implode the result straight into `IN (...)`, so what comes back
* must be the integers, not the strings that merely start with one.
*/
public function testConfirmIdsReturnsIntegers() {
$this->assertSame([5, 12], InputValidator::confirmIDs(['5', '0', '-3', 'abc', '12']));
$this->assertSame([1], InputValidator::confirmIDs(['1) OR (1=1']));
$this->assertSame([7], InputValidator::confirmIDs([7]));
}
}