mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-03 20:02:29 +02:00
InputValidator::confirmIDs() kept an id when intval($id) > 0 but returned the original value, and its callers implode the result into SQL `IN (...)` lists (mass edit and delete of lines, users, streams, series; bouquet contents; global search). '1) OR (1=1' has an intval of 1, so it passed the filter and reached the query unchanged. It now returns the integers. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA
42 lines
1.3 KiB
PHP
42 lines
1.3 KiB
PHP
<?php
|
|
|
|
use XcVm\Core\Validation\InputValidator;
|
|
use PHPUnit\Framework\TestCase;
|
|
|
|
final class InputValidatorTest extends TestCase {
|
|
public function testValidateReturnsFalseWhenRequiredFieldsMissing() {
|
|
$this->assertFalse(InputValidator::validate('processProvider', array()));
|
|
}
|
|
|
|
public function testValidateReturnsTrueForMinimalProviderPayload() {
|
|
$payload = array(
|
|
'ip' => '127.0.0.1',
|
|
'port' => 8080,
|
|
'username' => 'user',
|
|
'password' => 'pass',
|
|
'name' => 'provider',
|
|
);
|
|
|
|
$this->assertTrue(InputValidator::validate('processProvider', $payload));
|
|
}
|
|
|
|
public function testValidateOrFailUsesStatusConstant() {
|
|
if (!defined('STATUS_INVALID_INPUT')) {
|
|
define('STATUS_INVALID_INPUT', 400);
|
|
}
|
|
|
|
$result = InputValidator::validateOrFail('processProvider', array('ip' => '127.0.0.1'));
|
|
$this->assertSame(STATUS_INVALID_INPUT, $result['status']);
|
|
}
|
|
|
|
/**
|
|
* Callers implode the result straight into `IN (...)`, so what comes back
|
|
* must be the integers, not the strings that merely start with one.
|
|
*/
|
|
public function testConfirmIdsReturnsIntegers() {
|
|
$this->assertSame([5, 12], InputValidator::confirmIDs(['5', '0', '-3', 'abc', '12']));
|
|
$this->assertSame([1], InputValidator::confirmIDs(['1) OR (1=1']));
|
|
$this->assertSame([7], InputValidator::confirmIDs([7]));
|
|
}
|
|
}
|