vuxml.php escaping and the + in package names (#680)

The following outlines some changes set to be deployed soon. I will modify this paragraph to the past tense after deployment. The following was composed by Claude.

Two fixes to freshports-www, both merged to main and tested on dvl.freshports.org. The three #598 dark-mode commits that were merged with them are included too.

  • Deploy: origin/main at 36ab59cb
  • Database and config: no changes
  • Tested on: dvl.freshports.org, all tests pass
  • Rollback to: ef625c52

Escape request and database values on vuxml.php

1496bb5d, PR #679. File: www/vuxml.php

  • vid/vuln values are now htmlspecialchars()‘d when printed, and rawurlencode()‘d in the vuxml.org links.
  • Removed the unneeded pg_escape_string() on vid. VuXML::FetchByVID() already uses pg_query_params.
  • PHP_SELF in the “List all Vulnerabilities” links is now escaped.
  • Both vuxml_name_link() helpers now escape package names, VIDs and dates, and encode them in their hrefs. VuXML descriptions are XHTML and are still printed as-is.

Low risk. The unescaped output was already masked, because FetchByVID() dies (with an escaped message) on any value that isn’t a real VID. This change is defence in depth. Visible change: in ?list, the “port” links now encode + as %2B (41 links on dvl).

Keep + in package names when /?package= redirects

54585dfe, cba6fba0, PR #681, fixes #680. Files: www/index.php, www/filter.php, www/package.php, classes/searches.php, include/freshports.php

  • The not-found redirect to package.php now urlencode()s the name, so apache+ipv6 no longer becomes apache ipv6.
  • Searches::GetDefaultSearchStringPackage() and GetDefaultMethodStringPackage() now urlencode() the name themselves. All callers were updated to pass the raw name.
  • Removed pg_escape_string() from the package name in index.php, filter.php and package.php. It doubled any ' in a name.
  • freshports_VuXML_Link() now encodes the package name in its href.
  • filter.php “multiple ports” case: changed new Searches($dbh) to $db. The undefined-variable warning was blocking the redirect and leaving a blank page, e.g. for openssl. That bug was already there before #680.

Also in this deploy: #598 dark mode

PR #679

  • 58733b0c: load the site stylesheet on vuxml.php.
  • 2c70be9b: fix duplicate class attributes on vuxml.php tables.
  • 95c9faac: show the watch list ? count symbol as text, not sum.gif.

Smoke tests after deploy

Every result below is what dvl returned. Check also that no page shows a PHP warning. The vuxml.php pages need a logged-in session while LOGIN_TO_VIEW_VUXML is set.

URLExpect
/vuxml.php?vid=a"><b>x|b“I found 0 entries for a”><b>x…”, shown as text and not as markup
/vuxml.php?listFull list; a “port” link like /?package=apache%2Bmod_ssl
/vuxml.php?package=389-ds-baseThat package’s entry
/?package=apache%2Bipv6package.php: “(‘apache+ipv6’) could not be found”; the Search link has query=apache%2Bipv6
/?package=libsigc%2B%2B30/devel/libsigc++30/
/?package=389-ds-base/net/389-ds-base/
/?package=opensslsearch.php?query=openssl&…&method=exact, listing security/openssl and security/openssl30
/filter.php?package=opensslSame as above, not a blank page
/net/389-ds-base/VuXML icon links to /vuxml.php?package=389-ds-base

Rollback

Redeploy ef625c52, the commit before both PRs. That would also undo the #598 changes. To roll back only one fix, revert PR #681 or 1496bb5d on its own.

Website Pin Facebook Twitter Myspace Friendfeed Technorati del.icio.us Digg Google StumbleUpon Premium Responsive

Leave a Comment

Scroll to Top