This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
1 | <?php declare(strict_types=1); |
||||
2 | |||||
3 | namespace XoopsModules\Xoopspoll; |
||||
4 | |||||
5 | /* |
||||
6 | XOOPS - PHP Content Management System |
||||
7 | Copyright (c) 2000-2020 XOOPS.org |
||||
8 | <https://xoops.org> |
||||
9 | This program is free software; you can redistribute it and/or modify |
||||
10 | it under the terms of the GNU General Public License as published by |
||||
11 | the Free Software Foundation; either version 2 of the License, or |
||||
12 | (at your option) any later version. |
||||
13 | |||||
14 | You may not change or alter any portion of this comment or credits |
||||
15 | of supporting developers from this source code or any supporting |
||||
16 | source code which is considered copyrighted (c) material of the |
||||
17 | original comment or credit authors. |
||||
18 | |||||
19 | This program is distributed in the hope that it will be useful, |
||||
20 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
||||
21 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||||
22 | GNU General Public License for more details. |
||||
23 | |||||
24 | You should have received a copy of the GNU General Public License |
||||
25 | along with this program; if not, write to the Free Software |
||||
26 | Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA |
||||
27 | */ |
||||
28 | |||||
29 | /** |
||||
30 | * Poll Renderer class for the XoopsPoll Module |
||||
31 | * |
||||
32 | * @copyright :: {@link https://xoops.org/ XOOPS Project} |
||||
33 | * @license :: {@link https://www.gnu.org/licenses/gpl-2.0.html GNU GPL 2.0 or later} |
||||
34 | * @subpackage:: admin |
||||
35 | * @since :: 1.0 |
||||
36 | * @author :: {@link https://www.myweb.ne.jp/ Kazumi Ono (AKA onokazu)} |
||||
37 | */ |
||||
38 | |||||
39 | use Xmf\Request; |
||||
40 | use XoopsModules\Xoopspoll\{ |
||||
41 | Poll |
||||
0 ignored issues
–
show
|
|||||
42 | }; |
||||
43 | |||||
44 | Helper::getInstance()->loadLanguage('main'); |
||||
45 | |||||
46 | /** |
||||
47 | * Class Renderer |
||||
48 | */ |
||||
49 | class Renderer |
||||
50 | { |
||||
51 | // Poll class object |
||||
52 | protected Poll $pollObj; |
||||
53 | protected PollHandler $pollHandler; |
||||
54 | protected OptionHandler $optionHandler; |
||||
55 | protected LogHandler $logHandler; |
||||
56 | protected Helper $helper; |
||||
57 | // constructor(s) |
||||
58 | |||||
59 | /** |
||||
60 | * @param Poll|null $poll |
||||
61 | * @param Helper|null $helper |
||||
62 | */ |
||||
63 | public function __construct(Poll $poll = null, Helper $helper = null) |
||||
64 | { |
||||
65 | $this->helper = $helper ?? Helper::getInstance(); |
||||
66 | // setup handlers |
||||
67 | $this->pollHandler = $this->helper->getHandler('Poll'); |
||||
68 | $this->optionHandler = $this->helper->getHandler('Option'); |
||||
69 | $this->logHandler = $this->helper->getHandler('Log'); |
||||
70 | |||||
71 | if ($poll instanceof Poll) { |
||||
72 | $this->pollObj = $poll; |
||||
73 | } elseif (!empty($poll) && ((int)$poll > 0)) { |
||||
74 | $this->pollObj = $this->pollHandler->get((int)$poll); |
||||
75 | } else { |
||||
76 | $this->pollObj = $this->pollHandler->create(); |
||||
77 | } |
||||
78 | } |
||||
79 | |||||
80 | /** |
||||
81 | * create html form to display poll |
||||
82 | * @return string html form for display |
||||
83 | */ |
||||
84 | public function renderForm(): string |
||||
85 | { |
||||
86 | $myTpl = new \XoopsTpl(); |
||||
87 | $this->assignForm($myTpl); // get the poll information |
||||
88 | |||||
89 | // return $myTpl->fetch($GLOBALS['xoops']->path('modules/xoopspoll/templates/xoopspoll_view.tpl')); |
||||
90 | return $myTpl->fetch($this->helper->path('templates/xoopspoll_view.tpl')); |
||||
91 | } |
||||
92 | |||||
93 | /** |
||||
94 | * assigns form values to template for display |
||||
95 | * @var \XoopsTpl |
||||
96 | */ |
||||
97 | public function assignForm(\XoopsTpl $tpl): void |
||||
98 | { |
||||
99 | $myts = \MyTextSanitizer::getInstance(); |
||||
100 | $optionObjs = $this->optionHandler->getAllByPollId($this->pollObj->getVar('poll_id')); |
||||
101 | |||||
102 | if (empty($optionObjs)) { |
||||
103 | /* there was a problem with missing Options */ |
||||
104 | // redirect_header(Request::getString('HTTP_REFERER', '', 'SERVER'), Constants::REDIRECT_DELAY_MEDIUM, _MD_XOOPSPOLL_ERROR_OPTIONS_MISSING); |
||||
105 | } |
||||
106 | |||||
107 | if (Constants::MULTIPLE_SELECT_POLL === $this->pollObj->getVar('multiple')) { |
||||
108 | $optionType = 'checkbox'; |
||||
109 | $optionName = 'option_id[]'; |
||||
110 | } else { |
||||
111 | $optionType = 'radio'; |
||||
112 | $optionName = 'option_id'; |
||||
113 | } |
||||
114 | foreach ($optionObjs as $optionObj) { |
||||
115 | $options[] = [ |
||||
116 | 'input' => "<input type='{$optionType}' " . "name='{$optionName}' " . "value='" . $optionObj->getVar('option_id') . "'>", |
||||
117 | 'text' => $optionObj->getVar('option_text'), |
||||
118 | ]; |
||||
119 | } |
||||
120 | $uid = (isset($GLOBALS['xoopsUser']) |
||||
121 | && \is_object($GLOBALS['xoopsUser'])) ? $GLOBALS['xoopsUser']->getVar('uid') : 0; |
||||
122 | $can_vote = false; |
||||
123 | if ($this->pollObj->isAllowedToVote() |
||||
124 | && (!$this->logHandler->hasVoted($this->pollObj->getVar('poll_id'), \xoops_getenv('REMOTE_ADDR'), $uid))) { |
||||
125 | $can_vote = true; |
||||
126 | } |
||||
127 | /* |
||||
128 | $tpl->assign('poll', array( |
||||
129 | 'question' => htmlspecialchars($this->pollObj->getVar('question')), |
||||
130 | 'pollId' => $this->pollObj->getVar('poll_id'), |
||||
131 | 'viewresults' => $GLOBALS['xoops']->url("modules/xoopspoll/pollresults.php") . "?poll_id=" . $this->pollObj->getVar('poll_id'), |
||||
132 | 'options' => $options, |
||||
133 | 'description' => $myts->displayTarea($myts->undoHtmlSpecialChars($this->pollObj->getVar('description')), 1)) |
||||
134 | ); |
||||
135 | */ |
||||
136 | $tpl->assign([ |
||||
137 | 'poll' => [ |
||||
138 | 'question' => \htmlspecialchars($this->pollObj->getVar('question'), \ENT_QUOTES | \ENT_HTML5), |
||||
139 | 'pollId' => $this->pollObj->getVar('poll_id'), |
||||
140 | 'viewresults' => $GLOBALS['xoops']->url('modules/xoopspoll/pollresults.php') . '?poll_id=' . $this->pollObj->getVar('poll_id'), |
||||
141 | 'options' => $options ?? [], |
||||
142 | 'description' => $myts->displayTarea($myts->undoHtmlSpecialChars($this->pollObj->getVar('description')), 1), |
||||
0 ignored issues
–
show
It seems like
$this->pollObj->getVar('description') can also be of type array and array ; however, parameter $text of MyTextSanitizer::undoHtmlSpecialChars() does only seem to accept string , maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
![]() |
|||||
143 | ], |
||||
144 | 'can_vote' => $can_vote, |
||||
145 | 'action' => $GLOBALS['xoops']->url('modules/xoopspoll/index.php'), |
||||
146 | 'lang_vote' => \_MD_XOOPSPOLL_VOTE, |
||||
147 | 'lang_results' => \_MD_XOOPSPOLL_RESULTS, |
||||
148 | ]); |
||||
149 | } |
||||
150 | |||||
151 | /** |
||||
152 | * display html results to screen (echo) |
||||
153 | */ |
||||
154 | public function renderResults() |
||||
155 | { |
||||
156 | $myTpl = new \XoopsTpl(); |
||||
157 | $this->assignResults($myTpl); // get the poll information |
||||
158 | |||||
159 | // return $myTpl->fetch($GLOBALS['xoops']->path('modules/xoopspoll/templates/xoopspoll_results_renderer.tpl')); |
||||
160 | return $myTpl->fetch($this->helper->path('templates/xoopspoll_results_renderer.tpl')); |
||||
161 | } |
||||
162 | |||||
163 | /** |
||||
164 | * assigns form results to template |
||||
165 | * @var \XoopsTpl tpl |
||||
166 | */ |
||||
167 | public function assignResults(\XoopsTpl $tpl): void |
||||
168 | { |
||||
169 | $myts = \MyTextSanitizer::getInstance(); |
||||
0 ignored issues
–
show
|
|||||
170 | $xuEndTimestamp = \xoops_getUserTimestamp($this->pollObj->getVar('end_time')); |
||||
171 | $xuEndFormatted = \ucfirst(\date(_MEDIUMDATESTRING, (int)$xuEndTimestamp)); |
||||
172 | $xuStartTimestamp = \xoops_getUserTimestamp($this->pollObj->getVar('start_time')); |
||||
173 | $xuStartFormatted = \ucfirst(\date(_MEDIUMDATESTRING, (int)$xuStartTimestamp)); |
||||
174 | $options = []; |
||||
175 | |||||
176 | // $logHandler = $this->helper->getHandler('Log'); |
||||
177 | $criteria = new \CriteriaCompo(); |
||||
178 | $criteria->add(new \Criteria('poll_id', $this->pollObj->getVar('poll_id'), '=')); |
||||
0 ignored issues
–
show
It seems like
$this->pollObj->getVar('poll_id') can also be of type array and array ; however, parameter $value of Criteria::__construct() does only seem to accept string , maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
![]() |
|||||
179 | $criteria->setSort('option_id'); |
||||
180 | $optObjsArray = $this->optionHandler->getAll($criteria); |
||||
181 | $total = $this->pollObj->getVar('votes'); |
||||
182 | $i = 0; |
||||
183 | foreach ($optObjsArray as $optObj) { |
||||
184 | $optionVars = $optObj->getValues(); |
||||
185 | $percent = ($total > 0) ? (100 * $optionVars['option_count'] / $total) : 0; |
||||
186 | if ($percent > 0) { |
||||
187 | $width = (int)($percent * 2); |
||||
188 | $options[$i]['image'] = "<img src='" . $GLOBALS['xoops']->url("modules/xoopspoll/assets/images/colorbars/{$optionVars['option_color']}'") . " style='height: 14px; width: {$width}px; vertical-align: middle;' alt='" . (int)$percent . "%'>"; |
||||
189 | } else { |
||||
190 | $options[$i]['image'] = ''; |
||||
191 | } |
||||
192 | |||||
193 | /* setup module config handler - required since this is called by newbb too */ |
||||
194 | /** @var \XoopsModuleHandler $moduleHandler */ |
||||
195 | $moduleHandler = \xoops_getHandler('module'); |
||||
196 | /** @var \XoopsConfigHandler $configHandler */ |
||||
197 | $configHandler = \xoops_getHandler('config'); |
||||
198 | $xp_module = $moduleHandler->getByDirname('xoopspoll'); |
||||
199 | $module_id = $xp_module->getVar('mid'); |
||||
200 | $xp_config = $configHandler->getConfigsByCat(0, $module_id); |
||||
201 | |||||
202 | if ($xp_config['disp_vote_nums']) { |
||||
203 | $options[$i]['percent'] = \sprintf(' %01.1f%% (%d)', $percent, $optionVars['option_count']); |
||||
204 | } else { |
||||
205 | $options[$i]['percent'] = \sprintf(' %01.1f%%', $percent); |
||||
206 | } |
||||
207 | $options[$i]['text'] = $optionVars['option_text']; |
||||
208 | $options[$i]['total'] = $optionVars['option_count']; |
||||
209 | $options[$i]['value'] = (int)$percent; |
||||
210 | ++$i; |
||||
211 | unset($optionVars); |
||||
212 | } |
||||
213 | $uid = (isset($GLOBALS['xoopsUser']) |
||||
214 | && \is_object($GLOBALS['xoopsUser'])) ? $GLOBALS['xoopsUser']->getVar('uid') : 0; |
||||
215 | $vote = null; |
||||
216 | if (!$this->pollObj->hasExpired() && $this->pollObj->isAllowedToVote() |
||||
217 | && !$this->logHandler->hasVoted($this->pollObj->getVar('poll_id'), \xoops_getenv('REMOTE_ADDR'), $uid)) { |
||||
218 | $vote = "<a href='" . $GLOBALS['xoops']->url('modules/xoopspoll/index.php') . '?poll_id=' . $this->pollObj->getVar('poll_id') . "'>" . \_MD_XOOPSPOLL_VOTE_NOW . '</a>'; |
||||
219 | } |
||||
220 | if ($xp_config['disp_vote_nums']) { |
||||
0 ignored issues
–
show
Comprehensibility
Best Practice
introduced
by
|
|||||
221 | $totalVotes = \sprintf(\_MD_XOOPSPOLL_TOTALVOTES, $total); |
||||
0 ignored issues
–
show
It seems like
$total can also be of type array and array ; however, parameter $values of sprintf() does only seem to accept double|integer|string , maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
![]() |
|||||
222 | $totalVoters = \sprintf(\_MD_XOOPSPOLL_TOTALVOTERS, $this->pollObj->getVar('voters')); |
||||
223 | } else { |
||||
224 | $totalVotes = $totalVoters = ''; |
||||
225 | } |
||||
226 | |||||
227 | $tpl->assign('poll', [ |
||||
228 | 'question' => \htmlspecialchars($this->pollObj->getVar('question'), \ENT_QUOTES | \ENT_HTML5), |
||||
229 | 'end_text' => $xuEndFormatted, |
||||
230 | 'start_text' => $xuStartFormatted, |
||||
231 | 'totalVotes' => $totalVotes, |
||||
232 | 'totalVoters' => $totalVoters, |
||||
233 | 'vote' => $vote, |
||||
234 | 'options' => $options, |
||||
235 | 'description' => $this->pollObj->getVar('description'), //allow html |
||||
236 | ]); |
||||
237 | } |
||||
238 | } |
||||
239 |
Let?s assume that you have a directory layout like this:
and let?s assume the following content of
Bar.php
:If both files
OtherDir/Foo.php
andSomeDir/Foo.php
are loaded in the same runtime, you will see a PHP error such as the following:PHP Fatal error: Cannot use SomeDir\Foo as Foo because the name is already in use in OtherDir/Foo.php
However, as
OtherDir/Foo.php
does not necessarily have to be loaded and the error is only triggered if it is loaded beforeOtherDir/Bar.php
, this problem might go unnoticed for a while. In order to prevent this error from surfacing, you must import the namespace with a different alias: