Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Custom test to demonstrate everything breaks - #15

Open
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master
Open

Custom test to demonstrate everything breaks#15
wilsonge wants to merge 3 commits into
joomla-framework:1.x-devfrom
wilsonge:master

Conversation

@wilsonge

Copy link
Copy Markdown
Contributor

So if you run a string containing a symbol < through the filter class then you find that it gets stripped.

It's something inside the tag cleaning - but obviously we don't want all < tags to be stripped

@wilsongewilsonge changed the title Custom test to demonstrate somethingCustom test to demonstrate everything breaksNov 11, 2015
@C-Lodder

C-Lodder commented Nov 11, 2015

Copy link
Copy Markdown

It all starts here: https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L335

Just a possible solution off the top of my head:

  1. Check for <
  2. Match the next string against the $tagBlacklist array values
  3. If there's a match, continue to filter as it's currently doing
  4. Else convert < to its html entity and skip the filtering.

If this workaround it acceptable, let me know and I'll be more than happy to do it.

@C-LodderC-Lodder mentioned this pull request Nov 11, 2015
@photodude

Copy link
Copy Markdown
Contributor

@wilsonge
It's probably the overly broad assumption that there is a tag if there is a < in the tag cleaning method
https://github.com/joomla-framework/filter/blob/master/src/InputFilter.php#L553-L554

@mbabker

Copy link
Copy Markdown
Contributor

@wilsonge You doing anything with this?

@wilsonge

Copy link
Copy Markdown
ContributorAuthor

I can't find a way to "make this work" :( But there's definitely an issue that needs solving as the unit test demonstrates

@photodude

Copy link
Copy Markdown
Contributor

Could we utilize HTML parsing with the PHP DOM module, for this part of the Filter to bypass the overly broad assumption that there is a tag if there is a < in the tag cleaning method?

@mbabker

Copy link
Copy Markdown
Contributor

Possibly? Still should account for what'll probably be rare cases where PHP is configured with --disable-dom though.

@csthomas

Copy link
Copy Markdown
Contributor

I can add such improvement direct to joomla after joomla/joomla-cms#16201 will be merged.
I did a test on my joomla and I got a lots of errors in other tests.
Are all changes accepted? (see below)

There were 30 failures:
1) JFilterInputTest::testCleanByCallingMember with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
2) JFilterInputTest::testCleanByCallingMember with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
3) JFilterInputTest::testCleanByCallingMember with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:803
4) JFilterInputTest::testCleanWithImgWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
5) JFilterInputTest::testCleanWithImgWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
6) JFilterInputTest::testCleanWithImgWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
7) JFilterInputTest::testCleanWithImgWhitelisted with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:951
8) JFilterInputTest::testCleanWithClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
9) JFilterInputTest::testCleanWithClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
10) JFilterInputTest::testCleanWithClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1065
11) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
12) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', 'strongFred', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'strongFred'
+'&lt;strongFred'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
13) JFilterInputTest::testCleanWithImgAndClassWhitelisted with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1186
14) JFilterInputTest::testCleanWithDefaultBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
15) JFilterInputTest::testCleanWithDefaultBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
16) JFilterInputTest::testCleanWithDefaultBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
17) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_b" ('', '<img src="<img src=x"/onerror...)"//>"', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
18) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_c" ('', '<img src="<img src=x"/onerror...1)"//>', 'img src="&lt;img src=x&quot;/.../&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
+'&lt;img src="&lt;img src=x&quot;/onerror=alert(1)&quot;//&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
19) JFilterInputTest::testCleanWithDefaultBlackList with data set "security_tracker_24802_e" ('', '<img src=<img src=x"/onerror=...1)//">', 'img src=<img src="x/onerror=a...//" />', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src=<img src="x/onerror=alert(1)//" />'
+'&lt;img src=<img src="x/onerror=alert(1)//" />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
20) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote2" ('string', '<img src slkdjls " this is "m... stuff', 'img src slkdjls " this is "mo... stuff', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src slkdjls " this is "more " stuff'
+'&lt;img src slkdjls " this is "more " stuff'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
21) JFilterInputTest::testCleanWithDefaultBlackList with data set "hanging_quote3" ('string', '<img src="\' />', 'img src="\' /&gt;"', 'From specific cases')
From specific cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img src="\' /&gt;"'
+'&lt;img src="\' /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
22) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558a" ('string', '<SCRIPT SRC=http://jeffchanne...#<B />', 'SCRIPT SRC=http://jeffchannel...#<B />', 'Test mal-formed element from 25558a')
Test mal-formed element from 25558a
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
+'&lt;SCRIPT SRC=http://jeffchannell.com/evil.js#<B />'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
23) JFilterInputTest::testCleanWithDefaultBlackList with data set "tracker25558e" ('string', '<b><script<b></b><alert(1)</s...t </b>', '<b>script<b></b>alert(1)/script </b>', 'Test mal-formed element from 25558e')
Test mal-formed element from 25558e
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<b>script<b></b>alert(1)/script </b>'
+'<b>&lt;script<b></b>&lt;alert(1)&lt;/script </b>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1422
24) JFilterInputTest::testCleanWithImgBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
25) JFilterInputTest::testCleanWithImgBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
26) JFilterInputTest::testCleanWithImgBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1523
27) JFilterInputTest::testCleanWithClassBlackList with data set "tag_01" ('', '<em', 'em', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'em'
+'&lt;em'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
28) JFilterInputTest::testCleanWithClassBlackList with data set "Malformed Nested tags" ('', '<em><strongFred</strong></em>', '<em>strongFred</strong></em>', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'<em>strongFred</strong></em>'
+'<em>&lt;strongFred</strong></em>'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
29) JFilterInputTest::testCleanWithClassBlackList with data set "missing_quote" ('string', '<img height="123 />', 'img height="123 /&gt;"', 'From generic cases')
From generic cases
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'img height="123 /&gt;"'
+'&lt;img height="123 /&gt;"'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/filter/JFilterInputTest.php:1744
30) JFormTest::testFilterField
Line:474 <>" are always illegal in host names.
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://onmouseover=alert(2);'
+'http://onmouseover=alert(2);&lt;&gt;'
/home/tomash/public_html/a4/tests/unit/suites/libraries/joomla/form/JFormTest.php:474

@nibra

nibra commented Jan 19, 2021

Copy link
Copy Markdown
Contributor

I'd expect from the string filter that
a) I get a string (an array of strings) as a result, whatever I feed into the filter
b) HTML entities are decoded
c) nothing else is changed
Dealing with tags should solely be up to the HTML filter.

Would problems arise, if that behaviour gets implemented into 1.x? I'd like to add it to 2.0 in any case.
@wilsonge ? @Hackwar ? @HLeithner ?

@Hackwar

Copy link
Copy Markdown
Contributor

This is still a current issue.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wilsonge@C-Lodder@photodude@mbabker@csthomas@nibra@Hackwar