Whitelist PDF context options (#5924)

This commit is contained in:
Kevin Papst
2026-04-26 09:28:28 +02:00
committed by GitHub
parent 3b051e4aa5
commit 7a559a09e6
6 changed files with 126 additions and 16 deletions

View File

@@ -37,4 +37,56 @@ class MPdfConverterTest extends KernelTestCase
preg_match('/\/Creator \((.*)\)/', $result, $matches);
self::assertCount(2, $matches);
}
public function testAssociatedFilesPathIsStripped(): void
{
$kernel = self::bootKernel();
$cacheDir = $kernel->getContainer()->getParameter('kernel.cache_dir');
// Plant a sentinel on disk that an attacker would try to exfiltrate via
// mPDF's `SetAssociatedFiles`. The legitimate ZUGFeRD path uses
// `content` (pre-read bytes); we additionally pass `path` to confirm
// it is stripped before reaching mPDF.
$sentinelPath = tempnam(sys_get_temp_dir(), 'kimai-pdf-leak-');
self::assertNotFalse($sentinelPath);
$sentinelBytes = 'KIMAI_LEAK_SENTINEL_' . bin2hex(random_bytes(8));
file_put_contents($sentinelPath, $sentinelBytes);
$legitimateContent = 'KIMAI_LEGITIMATE_CONTENT_' . bin2hex(random_bytes(8));
try {
$sut = new MPdfConverter((new FileHelperFactory($this))->create(), $cacheDir);
$result = $sut->convertToPdf('<h1>Test</h1>', [
'associated_files' => [
[
'name' => 'attachment.txt',
'mime' => 'text/plain',
'description' => 'mixed entry',
'AFRelationship' => 'Alternative',
'path' => $sentinelPath,
'content' => $legitimateContent,
],
],
]);
} finally {
@unlink($sentinelPath);
}
self::assertNotEmpty($result);
// Decompress every FlateDecode stream in the produced PDF. The
// sentinel must not appear; the explicitly-supplied `content` must.
$allDecompressed = '';
if (preg_match_all('/stream\r?\n(.*?)\r?\nendstream/s', $result, $streams) > 0) {
foreach ($streams[1] as $stream) {
$decoded = @gzuncompress($stream);
if ($decoded !== false) {
$allDecompressed .= $decoded;
}
}
}
self::assertStringNotContainsString($sentinelBytes, $result);
self::assertStringNotContainsString($sentinelBytes, $allDecompressed);
self::assertStringContainsString($legitimateContent, $allDecompressed);
}
}