mirror of
https://github.com/nextcloud/server.git
synced 2026-02-20 00:12:30 -05:00
fix(dav): Allow arrays (of scalars) in property values
Signed-off-by: Côme Chilliet <come.chilliet@nextcloud.com>
This commit is contained in:
parent
266c1fcb2d
commit
8d216a7fdf
1 changed files with 14 additions and 1 deletions
|
|
@ -550,7 +550,16 @@ class CustomPropertiesBackend implements BackendInterface {
|
|||
$valueType = self::PROPERTY_TYPE_HREF;
|
||||
$value = $value->getHref();
|
||||
} else {
|
||||
if (!is_object($value)) {
|
||||
if (is_array($value)) {
|
||||
// For array only allow scalar values
|
||||
foreach ($value as $item) {
|
||||
if (!is_scalar($item)) {
|
||||
throw new DavException(
|
||||
"Property \"$name\" has an invalid value of array containing " . gettype($value),
|
||||
);
|
||||
}
|
||||
}
|
||||
} elseif (!is_object($value)) {
|
||||
throw new DavException(
|
||||
"Property \"$name\" has an invalid value of type " . gettype($value),
|
||||
);
|
||||
|
|
@ -581,6 +590,10 @@ class CustomPropertiesBackend implements BackendInterface {
|
|||
case self::PROPERTY_TYPE_HREF:
|
||||
return new Href($value);
|
||||
case self::PROPERTY_TYPE_OBJECT:
|
||||
if (preg_match('/^a:/', $value)) {
|
||||
// Array, unserialize only scalar values
|
||||
return unserialize(str_replace('\x00', chr(0), $value), ['allowed_classes' => false]);
|
||||
}
|
||||
if (!preg_match('/^O\:\d+\:\"(OCA\\\\DAV\\\\|Sabre\\\\(Cal|Card)?DAV\\\\Xml\\\\Property\\\\)/', $value)) {
|
||||
throw new \LogicException('Found an object class serialized in DB that is not allowed');
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue