This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | |||
3 | namespace zacksleo\yii2\post\models; |
||
4 | |||
5 | use common\helpers\files\File; |
||
6 | use Yii; |
||
7 | use yii\helpers\Url; |
||
8 | use yii\web\UploadedFile; |
||
9 | use yii\behaviors\TimestampBehavior; |
||
10 | use zacksleo\yii2\post\Module; |
||
11 | use zacksleo\yii2\post\behaviors\UploadBehavior; |
||
12 | |||
13 | /** |
||
14 | * This is the model class for table "{{%post}}". |
||
15 | * |
||
16 | * @property integer $id |
||
17 | * @property string $title |
||
18 | * @property string $img |
||
19 | * @property integer $views |
||
20 | * @property string $content |
||
21 | * @property string $create |
||
22 | * @property string $updated_at |
||
23 | */ |
||
24 | class Post extends \yii\db\ActiveRecord |
||
25 | { |
||
26 | public $imgFile; |
||
27 | |||
28 | const STATUS_ACTIVE = 1; //上线 |
||
29 | const STATUS_INACTIVE = 0; //下线 |
||
30 | |||
31 | /** |
||
32 | * @inheritdoc |
||
33 | */ |
||
34 | 6 | public static function tableName() |
|
35 | { |
||
36 | 6 | return '{{%post}}'; |
|
37 | } |
||
38 | |||
39 | /** |
||
40 | * @inheritdoc |
||
41 | */ |
||
42 | 5 | public function rules() |
|
43 | { |
||
44 | return [ |
||
45 | 5 | [['title', 'content'], 'required'], |
|
46 | [['views', 'order', 'status'], 'integer'], |
||
47 | 5 | ['status', 'in', 'range' => [self::STATUS_ACTIVE, self::STATUS_INACTIVE]], |
|
48 | [['img'], 'file', |
||
49 | 'skipOnEmpty' => true, |
||
50 | 'extensions' => 'png, jpg, gif, jpeg, bmp, svg, webp', |
||
51 | 'maxFiles' => 1, |
||
52 | 'maxSize' => 300000, |
||
53 | 'on' => ['insert', 'update'] |
||
54 | ], |
||
55 | ]; |
||
56 | } |
||
57 | |||
58 | |||
59 | /** |
||
60 | * @inheritdoc |
||
61 | */ |
||
62 | 2 | public function attributeLabels() |
|
63 | { |
||
64 | return [ |
||
65 | 2 | 'id' => 'ID', |
|
66 | 2 | 'title' => Module::t('post', 'title'), |
|
67 | 2 | 'img' => Module::t('post', 'img'), |
|
68 | 2 | 'views' => Module::t('post', 'views'), |
|
69 | 2 | 'content' => Module::t('post', 'content'), |
|
70 | 2 | 'created_at' => Module::t('post', 'created at'), |
|
71 | 2 | 'updated_at' => Module::t('post', 'updated at'), |
|
72 | 2 | 'order' => Module::t('post', 'order'), |
|
73 | 2 | 'status' => Module::t('post', 'status'), |
|
74 | ]; |
||
75 | } |
||
76 | |||
77 | /** |
||
78 | * @inheritdoc |
||
79 | */ |
||
80 | 6 | public function behaviors() |
|
81 | { |
||
82 | return [ |
||
83 | 6 | 'timestamp' => [ |
|
84 | 6 | 'class' => TimestampBehavior::className() |
|
85 | ], |
||
86 | [ |
||
87 | 6 | 'class' => UploadBehavior::className(), |
|
88 | 6 | 'attribute' => 'img', |
|
89 | 'scenarios' => ['insert', 'update'], |
||
90 | 6 | 'path' => '@frontend/web/uploads/galleries/posts', |
|
91 | 6 | 'url' => '@web/uploads/galleries/posts', |
|
92 | ], |
||
93 | ]; |
||
94 | } |
||
95 | |||
96 | public function fields() |
||
0 ignored issues
–
show
|
|||
97 | { |
||
98 | $fields = parent::fields(); |
||
99 | $fields['img'] = function ($fields) { |
||
0 ignored issues
–
show
|
|||
100 | $path = str_replace('api/uploads/', '', $this->getUploadUrl('img')); |
||
0 ignored issues
–
show
The method
getUploadUrl does not exist on object<zacksleo\yii2\post\models\Post> ? Since you implemented __call , maybe consider adding a @method annotation.
If you implement This is often the case, when class ParentClass {
private $data = array();
public function __call($method, array $args) {
if (0 === strpos($method, 'get')) {
return $this->data[strtolower(substr($method, 3))];
}
throw new \LogicException(sprintf('Unsupported method: %s', $method));
}
}
/**
* If this class knows which fields exist, you can specify the methods here:
*
* @method string getName()
*/
class SomeClass extends ParentClass { }
![]() |
|||
101 | if (isset($_ENV['API_HOST'])) { |
||
102 | $url = $_ENV['API_HOST'] . 'files/' . $path; |
||
103 | } else { |
||
104 | $url = Url::to(['file/view', 'path' => $path], true); |
||
105 | } |
||
106 | return $url; |
||
107 | }; |
||
108 | $fields['url'] = function ($fields) { |
||
109 | $url = $_ENV['APP_HOST'] . 'post/view' . "?id=" . $fields['id']; |
||
110 | return $url; |
||
111 | }; |
||
112 | unset($fields['id'], $fields['created_at'], $fields['updated_at'], $fields['content'], $fields['order'], $fields['status']); |
||
113 | return $fields; |
||
114 | } |
||
115 | |||
116 | public function getUrl() |
||
0 ignored issues
–
show
getUrl uses the super-global variable $_ENV which is generally not recommended.
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: // Bad
class Router
{
public function generate($path)
{
return $_SERVER['HOST'].$path;
}
}
// Better
class Router
{
private $host;
public function __construct($host)
{
$this->host = $host;
}
public function generate($path)
{
return $this->host.$path;
}
}
class Controller
{
public function myAction(Request $request)
{
// Instead of
$page = isset($_GET['page']) ? intval($_GET['page']) : 1;
// Better (assuming you use the Symfony2 request)
$page = $request->query->get('page', 1);
}
}
![]() |
|||
117 | { |
||
118 | return $_ENV['APP_HOST'] . '/post/view?id=' . $this->id; |
||
119 | } |
||
120 | |||
121 | public static function getStatusList() |
||
122 | { |
||
123 | return [ |
||
124 | self::STATUS_INACTIVE => Module::t('post', 'offline'), |
||
125 | self::STATUS_ACTIVE => Module::t('post', 'online'), |
||
126 | ]; |
||
127 | } |
||
128 | |||
129 | public function getImgUrl() |
||
0 ignored issues
–
show
getImgUrl uses the super-global variable $_ENV which is generally not recommended.
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: // Bad
class Router
{
public function generate($path)
{
return $_SERVER['HOST'].$path;
}
}
// Better
class Router
{
private $host;
public function __construct($host)
{
$this->host = $host;
}
public function generate($path)
{
return $this->host.$path;
}
}
class Controller
{
public function myAction(Request $request)
{
// Instead of
$page = isset($_GET['page']) ? intval($_GET['page']) : 1;
// Better (assuming you use the Symfony2 request)
$page = $request->query->get('page', 1);
}
}
![]() |
|||
130 | { |
||
131 | return $_ENV['APP_HOST'] . 'uploads/galleries/posts/' . $this->img; |
||
132 | } |
||
133 | } |
||
134 |
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: