1.18.2 (#3190)
* improve console version output * fix empty string issue in csv export (DDE protection) - fixes #3189 * fix twig sort deprecation in php 8 * sort user by displayName in users report * fix missing custom translations in edit modal * fix font-family in invoice.css * invoice template "freelancer pdf" - added customer number, moved some fields around * invoice template "default" - relocate customer number and order number in
This commit is contained in:
@@ -32,6 +32,7 @@ class StringHelperTest extends TestCase
|
||||
public function getDdeAttackStrings()
|
||||
{
|
||||
yield ['DDE ("cmd";"/C calc";"!A0")A0'];
|
||||
yield [' DDE ("cmd";"/C calc";"!A0")A0'];
|
||||
yield ["@SUM(1+9)*cmd|' /C calc'!A0"];
|
||||
yield ["-10+20+cmd|' /C calc'!A0"];
|
||||
yield ["+10+20+cmd|' /C calc'!A0"];
|
||||
@@ -54,4 +55,18 @@ class StringHelperTest extends TestCase
|
||||
{
|
||||
self::assertEquals("' " . $input, StringHelper::sanitizeDDE($input));
|
||||
}
|
||||
|
||||
public function getNonDdeAttackStrings()
|
||||
{
|
||||
yield [''];
|
||||
yield [' '];
|
||||
}
|
||||
|
||||
/**
|
||||
* @dataProvider getNonDdeAttackStrings
|
||||
*/
|
||||
public function testSanitizeDdeWithCorrectStrings(string $input)
|
||||
{
|
||||
self::assertEquals($input, StringHelper::sanitizeDDE($input));
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user