Two fixes to freshports-www, both merged to main and tested on dvl.freshports.org. The three #598 dark-mode commits that were merged with them are included too.
- Deploy:
origin/mainat 36ab59cb - Database and config: no changes
- Tested on: dvl.freshports.org, all tests pass
- Rollback to: ef625c52
Escape request and database values on vuxml.php
1496bb5d, PR #679. File: www/vuxml.php
vid/vulnvalues are nowhtmlspecialchars()‘d when printed, andrawurlencode()‘d in the vuxml.org links.- Removed the unneeded
pg_escape_string()onvid.VuXML::FetchByVID()already usespg_query_params. PHP_SELFin the “List all Vulnerabilities” links is now escaped.- Both
vuxml_name_link()helpers now escape package names, VIDs and dates, and encode them in their hrefs. VuXML descriptions are XHTML and are still printed as-is.
Low risk. The unescaped output was already masked, because FetchByVID() dies (with an escaped message) on any value that isn’t a real VID. This change is defence in depth. Visible change: in ?list, the “port” links now encode + as %2B (41 links on dvl).
Keep + in package names when /?package= redirects
54585dfe, cba6fba0, PR #681, fixes #680. Files: www/index.php, www/filter.php, www/package.php, classes/searches.php, include/freshports.php
- The not-found redirect to
package.phpnowurlencode()s the name, soapache+ipv6no longer becomesapache ipv6. Searches::GetDefaultSearchStringPackage()andGetDefaultMethodStringPackage()nowurlencode()the name themselves. All callers were updated to pass the raw name.- Removed
pg_escape_string()from the package name inindex.php,filter.phpandpackage.php. It doubled any'in a name. freshports_VuXML_Link()now encodes the package name in its href.filter.php“multiple ports” case: changednew Searches($dbh)to$db. The undefined-variable warning was blocking the redirect and leaving a blank page, e.g. foropenssl. That bug was already there before #680.
Also in this deploy: #598 dark mode
- 58733b0c: load the site stylesheet on vuxml.php.
- 2c70be9b: fix duplicate class attributes on vuxml.php tables.
- 95c9faac: show the watch list ? count symbol as text, not
sum.gif.
Smoke tests after deploy
Every result below is what dvl returned. Check also that no page shows a PHP warning. The vuxml.php pages need a logged-in session while LOGIN_TO_VIEW_VUXML is set.
| URL | Expect |
|---|---|
/vuxml.php?vid=a"><b>x|b | “I found 0 entries for a”><b>x…”, shown as text and not as markup |
/vuxml.php?list | Full list; a “port” link like /?package=apache%2Bmod_ssl |
/vuxml.php?package=389-ds-base | That package’s entry |
/?package=apache%2Bipv6 | package.php: “(‘apache+ipv6’) could not be found”; the Search link has query=apache%2Bipv6 |
/?package=libsigc%2B%2B30 | /devel/libsigc++30/ |
/?package=389-ds-base | /net/389-ds-base/ |
/?package=openssl | search.php?query=openssl&…&method=exact, listing security/openssl and security/openssl30 |
/filter.php?package=openssl | Same as above, not a blank page |
/net/389-ds-base/ | VuXML icon links to /vuxml.php?package=389-ds-base |
Rollback
Redeploy ef625c52, the commit before both PRs. That would also undo the #598 changes. To roll back only one fix, revert PR #681 or 1496bb5d on its own.











