Validate field_type against the allowed enum in custom field definitions (#50)
Lint / PHP (phpcs PSR-12) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 13s
Lint / PHP requirements (version + extensions) (push) Successful in 39s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 2m1s
Lint / Deploy (push) Successful in 6s
Lint / PHP (phpcs PSR-12) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 13s
Lint / PHP requirements (version + extensions) (push) Successful in 39s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 2m1s
Lint / Deploy (push) Successful in 6s
The setValue()/is_required/select-options half of this issue was already fixed incidentally by #47's new api/ticket_custom_fields.php endpoint. The remaining gap: createDefinition()/updateDefinition() never validated field_type against the six values the schema's enum() actually allows (text/textarea/select/checkbox/date/number), so a malformed type could be stored via the admin API and break whatever UI renders it later. Added an ALLOWED_FIELD_TYPES allowlist check at the top of both methods, returning the same ['success' => false, 'error' => ...] shape they already use for a DB failure — api/custom_fields.php already propagates that shape correctly with no changes needed there. Verified against real MariaDB: an invalid field_type is rejected on both create and update, while a valid one still succeeds. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Lhz7pGMaoTfL5sdYS5XiKv
This commit is contained in:
@@ -8,6 +8,9 @@ class CustomFieldModel
|
|||||||
{
|
{
|
||||||
private $conn;
|
private $conn;
|
||||||
|
|
||||||
|
// Must match custom_field_definitions.field_type's enum() in the schema.
|
||||||
|
private const ALLOWED_FIELD_TYPES = ['text', 'textarea', 'select', 'checkbox', 'date', 'number'];
|
||||||
|
|
||||||
public function __construct($conn)
|
public function __construct($conn)
|
||||||
{
|
{
|
||||||
$this->conn = $conn;
|
$this->conn = $conn;
|
||||||
@@ -87,6 +90,10 @@ class CustomFieldModel
|
|||||||
*/
|
*/
|
||||||
public function createDefinition($data)
|
public function createDefinition($data)
|
||||||
{
|
{
|
||||||
|
if (!in_array($data['field_type'] ?? '', self::ALLOWED_FIELD_TYPES, true)) {
|
||||||
|
return ['success' => false, 'error' => 'Invalid field_type'];
|
||||||
|
}
|
||||||
|
|
||||||
$options = null;
|
$options = null;
|
||||||
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
||||||
$options = json_encode($data['field_options']);
|
$options = json_encode($data['field_options']);
|
||||||
@@ -129,6 +136,10 @@ class CustomFieldModel
|
|||||||
*/
|
*/
|
||||||
public function updateDefinition($fieldId, $data)
|
public function updateDefinition($fieldId, $data)
|
||||||
{
|
{
|
||||||
|
if (!in_array($data['field_type'] ?? '', self::ALLOWED_FIELD_TYPES, true)) {
|
||||||
|
return ['success' => false, 'error' => 'Invalid field_type'];
|
||||||
|
}
|
||||||
|
|
||||||
$options = null;
|
$options = null;
|
||||||
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
||||||
$options = json_encode($data['field_options']);
|
$options = json_encode($data['field_options']);
|
||||||
|
|||||||
Reference in New Issue
Block a user