This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | /** |
||
3 | * Implements Special:PagesWithProp |
||
4 | * |
||
5 | * This program is free software; you can redistribute it and/or modify |
||
6 | * it under the terms of the GNU General Public License as published by |
||
7 | * the Free Software Foundation; either version 2 of the License, or |
||
8 | * (at your option) any later version. |
||
9 | * |
||
10 | * This program is distributed in the hope that it will be useful, |
||
11 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
12 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
13 | * GNU General Public License for more details. |
||
14 | * |
||
15 | * You should have received a copy of the GNU General Public License along |
||
16 | * with this program; if not, write to the Free Software Foundation, Inc., |
||
17 | * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. |
||
18 | * http://www.gnu.org/copyleft/gpl.html |
||
19 | * |
||
20 | * @since 1.21 |
||
21 | * @file |
||
22 | * @ingroup SpecialPage |
||
23 | * @author Brad Jorsch |
||
24 | */ |
||
25 | |||
26 | /** |
||
27 | * Special:PagesWithProp to search the page_props table |
||
28 | * @ingroup SpecialPage |
||
29 | * @since 1.21 |
||
30 | */ |
||
31 | class SpecialPagesWithProp extends QueryPage { |
||
32 | private $propName = null; |
||
33 | private $existingPropNames = null; |
||
34 | |||
35 | function __construct( $name = 'PagesWithProp' ) { |
||
36 | parent::__construct( $name ); |
||
37 | } |
||
38 | |||
39 | function isCacheable() { |
||
40 | return false; |
||
41 | } |
||
42 | |||
43 | public function execute( $par ) { |
||
44 | $this->setHeaders(); |
||
45 | $this->outputHeader(); |
||
46 | $this->getOutput()->addModuleStyles( 'mediawiki.special.pagesWithProp' ); |
||
47 | |||
48 | $request = $this->getRequest(); |
||
49 | $propname = $request->getVal( 'propname', $par ); |
||
50 | |||
51 | $propnames = $this->getExistingPropNames(); |
||
52 | |||
53 | $form = HTMLForm::factory( 'ooui', [ |
||
54 | 'propname' => [ |
||
55 | 'type' => 'combobox', |
||
56 | 'name' => 'propname', |
||
57 | 'options' => $propnames, |
||
58 | 'default' => $propname, |
||
59 | 'label-message' => 'pageswithprop-prop', |
||
60 | 'required' => true, |
||
61 | ], |
||
62 | ], $this->getContext() ); |
||
63 | $form->setMethod( 'get' ); |
||
64 | $form->setSubmitCallback( [ $this, 'onSubmit' ] ); |
||
65 | $form->setWrapperLegendMsg( 'pageswithprop-legend' ); |
||
66 | $form->addHeaderText( $this->msg( 'pageswithprop-text' )->parseAsBlock() ); |
||
67 | $form->setSubmitTextMsg( 'pageswithprop-submit' ); |
||
68 | |||
69 | $form->prepareForm(); |
||
70 | $form->displayForm( false ); |
||
71 | if ( $propname !== '' && $propname !== null ) { |
||
72 | $form->trySubmit(); |
||
73 | } |
||
74 | } |
||
75 | |||
76 | public function onSubmit( $data, $form ) { |
||
77 | $this->propName = $data['propname']; |
||
78 | parent::execute( $data['propname'] ); |
||
0 ignored issues
–
show
|
|||
79 | } |
||
80 | |||
81 | /** |
||
82 | * Return an array of subpages beginning with $search that this special page will accept. |
||
83 | * |
||
84 | * @param string $search Prefix to search for |
||
85 | * @param int $limit Maximum number of results to return |
||
86 | * @param int $offset Number of pages to skip |
||
87 | * @return string[] Matching subpages |
||
88 | */ |
||
89 | public function prefixSearchSubpages( $search, $limit, $offset ) { |
||
90 | $subpages = array_keys( $this->queryExistingProps( $limit, $offset ) ); |
||
91 | // We've already limited and offsetted, set to N and 0 respectively. |
||
92 | return self::prefixSearchArray( $search, count( $subpages ), $subpages, 0 ); |
||
93 | } |
||
94 | |||
95 | /** |
||
96 | * Disable RSS/Atom feeds |
||
97 | * @return bool |
||
98 | */ |
||
99 | function isSyndicated() { |
||
100 | return false; |
||
101 | } |
||
102 | |||
103 | public function getQueryInfo() { |
||
104 | return [ |
||
105 | 'tables' => [ 'page_props', 'page' ], |
||
106 | 'fields' => [ |
||
107 | 'page_id' => 'pp_page', |
||
108 | 'page_namespace', |
||
109 | 'page_title', |
||
110 | 'page_len', |
||
111 | 'page_is_redirect', |
||
112 | 'page_latest', |
||
113 | 'pp_value', |
||
114 | ], |
||
115 | 'conds' => [ |
||
116 | 'pp_propname' => $this->propName, |
||
117 | ], |
||
118 | 'join_conds' => [ |
||
119 | 'page' => [ 'INNER JOIN', 'page_id = pp_page' ] |
||
120 | ], |
||
121 | 'options' => [] |
||
122 | ]; |
||
123 | } |
||
124 | |||
125 | function getOrderFields() { |
||
126 | return [ 'page_id' ]; |
||
127 | } |
||
128 | |||
129 | /** |
||
130 | * @param Skin $skin |
||
131 | * @param object $result Result row |
||
132 | * @return string |
||
133 | */ |
||
134 | function formatResult( $skin, $result ) { |
||
135 | $title = Title::newFromRow( $result ); |
||
136 | $ret = Linker::link( $title, null, [], [], [ 'known' ] ); |
||
137 | if ( $result->pp_value !== '' ) { |
||
138 | // Do not show very long or binary values on the special page |
||
139 | $valueLength = strlen( $result->pp_value ); |
||
140 | $isBinary = strpos( $result->pp_value, "\0" ) !== false; |
||
141 | $isTooLong = $valueLength > 1024; |
||
142 | |||
143 | if ( $isBinary || $isTooLong ) { |
||
144 | $message = $this |
||
145 | ->msg( $isBinary ? 'pageswithprop-prophidden-binary' : 'pageswithprop-prophidden-long' ) |
||
146 | ->params( $this->getLanguage()->formatSize( $valueLength ) ); |
||
147 | |||
148 | $propValue = Html::element( 'span', [ 'class' => 'prop-value-hidden' ], $message->text() ); |
||
149 | } else { |
||
150 | $propValue = Html::element( 'span', [ 'class' => 'prop-value' ], $result->pp_value ); |
||
151 | } |
||
152 | |||
153 | $ret .= $this->msg( 'colon-separator' )->escaped() . $propValue; |
||
154 | } |
||
155 | |||
156 | return $ret; |
||
157 | } |
||
158 | |||
159 | public function getExistingPropNames() { |
||
160 | if ( $this->existingPropNames === null ) { |
||
161 | $this->existingPropNames = $this->queryExistingProps(); |
||
162 | } |
||
163 | return $this->existingPropNames; |
||
164 | } |
||
165 | |||
166 | protected function queryExistingProps( $limit = null, $offset = 0 ) { |
||
167 | $opts = [ |
||
168 | 'DISTINCT', 'ORDER BY' => 'pp_propname' |
||
169 | ]; |
||
170 | if ( $limit ) { |
||
171 | $opts['LIMIT'] = $limit; |
||
172 | } |
||
173 | if ( $offset ) { |
||
174 | $opts['OFFSET'] = $offset; |
||
175 | } |
||
176 | |||
177 | $res = wfGetDB( DB_REPLICA )->select( |
||
178 | 'page_props', |
||
179 | 'pp_propname', |
||
180 | '', |
||
181 | __METHOD__, |
||
182 | $opts |
||
183 | ); |
||
184 | |||
185 | $propnames = []; |
||
186 | foreach ( $res as $row ) { |
||
187 | $propnames[$row->pp_propname] = $row->pp_propname; |
||
188 | } |
||
189 | |||
190 | return $propnames; |
||
191 | } |
||
192 | |||
193 | protected function getGroupName() { |
||
194 | return 'pages'; |
||
195 | } |
||
196 | } |
||
197 |
This check looks for a call to a parent method whose name is different than the method from which it is called.
Consider the following code:
The
getFirstName()
method in theSon
calls the wrong method in the parent class.