Repository navigation
Commit 7106979
committed
fix: bypass the presentation cache when the key digest cannot be encoded
The digest parts come raw off the query string, and percent-decoding hands
them over as bytes: expand=%FF arrives as "\xFF", which is not valid UTF-8,
so json_encode() returns false - and hash() coerces that false to "" without
a warning, the file not declaring strict_types. Every request carrying any
malformed byte then collapsed onto one digest per presentation, serializer
class included, undoing every discriminator dea76db added: an admin-shaped
payload cached under the constant digest was served verbatim to a public
caller whose own request also failed to encode.
The trigger needs a privileged caller to emit malformed UTF-8 inside the TTL,
which nothing in the platform does organically, so this is hardening rather
than a live hole - but the guard is one expression: the encode result is
captured, and a request whose parts cannot be keyed unambiguously skips the
cache entirely, read and write both. Serving fresh is preferred over
JSON_INVALID_UTF8_SUBSTITUTE, which would still merge requests differing only
in which invalid byte they carried.
Flagged by CodeRabbit on PR #577 (r3714097910), verified end to end in the
container: Illuminate\Http\Request::create preserves the raw byte through
input(), and hash('sha256', false) raises nothing at E_ALL.1 parent 23a45c2 commit 7106979
2 files changed
Lines changed: 43 additions & 12 deletions
File tree
- app/ModelSerializers/Summit/Presentation
- tests
Lines changed: 15 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
266 | 266 | | |
267 | 267 | | |
268 | 268 | | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
269 | 282 | | |
270 | 283 | | |
271 | 284 | | |
272 | 285 | | |
273 | 286 | | |
274 | 287 | | |
275 | | - | |
276 | | - | |
277 | | - | |
278 | | - | |
279 | | - | |
280 | | - | |
281 | | - | |
282 | | - | |
283 | | - | |
284 | | - | |
285 | | - | |
| 288 | + | |
286 | 289 | | |
287 | 290 | | |
288 | | - | |
| 291 | + | |
289 | 292 | | |
290 | 293 | | |
291 | 294 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
187 | 215 | | |
0 commit comments