Skip to content

fix: Only keep allowed characters in appid, and flag the method as escaping - #50794

Merged
come-nc merged 2 commits into
masterfrom
fix/fix-appmanager-cleanappid
Feb 13, 2025
Merged

fix: Only keep allowed characters in appid, and flag the method as escaping#50794
come-nc merged 2 commits into
masterfrom
fix/fix-appmanager-cleanappid

Conversation

@come-nc

@come-nccome-nc commented Feb 13, 2025

Copy link
Copy Markdown
Contributor
  • Resolves: #

Summary

There are a few more psalm-taint types than what was listed, and I had to add the phpdoc on the implementation as well to get psalm to take it into account.

I also fixed the FIXME in there by only keeping explicitely allowed characters in appid.
Should be fine as the xsd schema is already enforcing this.

Checklist

…caping
Signed-off-by: Côme Chilliet <come.chilliet@nextcloud.com>
@come-nccome-nc added the 3. to review Waiting for reviews label Feb 13, 2025
@come-nc
come-nc requested review from a team and nickvergessenFebruary 13, 2025 13:29
@come-nccome-nc self-assigned this Feb 13, 2025
@come-nc
come-nc requested review from Altahrim, skjnldsv and yemkareems and removed request for a teamFebruary 13, 2025 13:29
@come-nccome-nc added this to the Nextcloud 32 milestone Feb 13, 2025
@come-nc

Copy link
Copy Markdown
ContributorAuthor

/backport to stable31

@come-nc

Copy link
Copy Markdown
ContributorAuthor

/backport to stable30

@come-nc

Copy link
Copy Markdown
ContributorAuthor

/backport to stable29

Comment threadlib/private/App/AppManager.php Outdated
…ppid
Co-authored-by: Ferdinand Thiessen <opensource@fthiessen.de>
Signed-off-by: Côme Chilliet <91878298+come-nc@users.noreply.github.com>
@come-nc
come-nc requested a review from susnuxFebruary 13, 2025 16:00
@come-nc
come-nc enabled auto-merge February 13, 2025 16:22
@come-nc
come-nc merged commit b003af2 into masterFeb 13, 2025
@come-nc
come-nc deleted the fix/fix-appmanager-cleanappid branch February 13, 2025 16:23
@backportbot

Copy link
Copy Markdown

The backport to stable29 failed. Please do this backport manually.

# Switch to the target branch and update it
git checkout stable29
git pull origin stable29
# Create the new backport branch
git checkout -b backport/50794/stable29
# Cherry pick the change from the commit sha1 of the change against the default branch# This might cause conflicts, resolve them
git cherry-pick 8f57a507 6e7c97ea
# Push the cherry pick commit to the remote repository and open a pull request
git push origin backport/50794/stable29

Error: No changes found in backport branch


Learn more about backports at https://docs.nextcloud.com/server/stable/go.php?to=developer-backports.

@backportbot

Copy link
Copy Markdown

The backport to stable30 failed. Please do this backport manually.

# Switch to the target branch and update it
git checkout stable30
git pull origin stable30
# Create the new backport branch
git checkout -b backport/50794/stable30
# Cherry pick the change from the commit sha1 of the change against the default branch# This might cause conflicts, resolve them
git cherry-pick 8f57a507 6e7c97ea
# Push the cherry pick commit to the remote repository and open a pull request
git push origin backport/50794/stable30

Error: No changes found in backport branch


Learn more about backports at https://docs.nextcloud.com/server/stable/go.php?to=developer-backports.

@come-nc

Copy link
Copy Markdown
ContributorAuthor

Not backportable to 30, cleanAppId is still in legacy/OC_App on this version.

@nextcloud-botnextcloud-bot mentioned this pull request Aug 19, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to reviewWaiting for reviews

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@come-nc@nickvergessen@susnux@skjnldsv