1.18.2 (#3190)
* improve console version output * fix empty string issue in csv export (DDE protection) - fixes #3189 * fix twig sort deprecation in php 8 * sort user by displayName in users report * fix missing custom translations in edit modal * fix font-family in invoice.css * invoice template "freelancer pdf" - added customer number, moved some fields around * invoice template "default" - relocate customer number and order number in
This commit is contained in:
@@ -49,9 +49,10 @@ class VersionCommandTest extends KernelTestCase
|
||||
{
|
||||
return [
|
||||
[[], 'Kimai ' . Constants::VERSION . ' by Kevin Papst and contributors.'],
|
||||
[['--name' => true], Constants::NAME],
|
||||
[['--short' => true], Constants::VERSION],
|
||||
[['--number' => true], Constants::VERSION_ID],
|
||||
// @deprecated since 1.14.1
|
||||
[['--name' => true], Constants::NAME],
|
||||
[['--candidate' => true], Constants::STATUS],
|
||||
[['--semver' => true], Constants::VERSION . '-' . Constants::STATUS],
|
||||
];
|
||||
|
||||
@@ -25,5 +25,6 @@ class ConsoleApplicationTest extends TestCase
|
||||
$sut = new ConsoleApplication($kernel);
|
||||
self::assertEquals(Constants::SOFTWARE, $sut->getName());
|
||||
self::assertEquals(Constants::VERSION, $sut->getVersion());
|
||||
self::assertEquals(sprintf('%s <info>%s</info> (env: <comment></>, debug: <comment>false</>)', Constants::SOFTWARE, Constants::VERSION), $sut->getLongVersion());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -32,6 +32,7 @@ class StringHelperTest extends TestCase
|
||||
public function getDdeAttackStrings()
|
||||
{
|
||||
yield ['DDE ("cmd";"/C calc";"!A0")A0'];
|
||||
yield [' DDE ("cmd";"/C calc";"!A0")A0'];
|
||||
yield ["@SUM(1+9)*cmd|' /C calc'!A0"];
|
||||
yield ["-10+20+cmd|' /C calc'!A0"];
|
||||
yield ["+10+20+cmd|' /C calc'!A0"];
|
||||
@@ -54,4 +55,18 @@ class StringHelperTest extends TestCase
|
||||
{
|
||||
self::assertEquals("' " . $input, StringHelper::sanitizeDDE($input));
|
||||
}
|
||||
|
||||
public function getNonDdeAttackStrings()
|
||||
{
|
||||
yield [''];
|
||||
yield [' '];
|
||||
}
|
||||
|
||||
/**
|
||||
* @dataProvider getNonDdeAttackStrings
|
||||
*/
|
||||
public function testSanitizeDdeWithCorrectStrings(string $input)
|
||||
{
|
||||
self::assertEquals($input, StringHelper::sanitizeDDE($input));
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user