mirror of
https://github.com/ellite/Wallos.git
synced 2026-07-30 09:45:52 -04:00
feat: option for the week to start on sunday feat: redesign login / registration pages feat: more statistics feat: declarative oidc settings feat: grid view for subscriptions feat: subscription details popup feat: translate categories with ai feat: google image search with serpapi feat: selfh.st image search feat: dashboard icons image search fix: improve background removal feature for logos feat: v2.0 api - write endpoints fix: include todays subscriptions on amount due this month fix: calendar occurrences to respect subscription start date fix: honor configured outbound proxy for logo search without reopening httpoxy SSRF bypass fix: remove hardcode string from the admin page fix: ssrf via http proxy env var in payments logo search fix: require cron auth guard on storetotalyearlycost.php fix: validate per-user smtp host against ssrf fix: escape iCal property values to prevent crlf injection
24 lines
829 B
PHP
24 lines
829 B
PHP
<?php
|
|
|
|
/**
|
|
* Escapes a value for safe embedding in an iCalendar (RFC 5545) property value.
|
|
*
|
|
* Backslash must be escaped first, before the other substitutions introduce
|
|
* new backslashes. Raw CRLF/LF are converted to a literal two-character
|
|
* "\n" escape sequence — never leave a real newline in the output, since
|
|
* iCalendar treats CRLF as a property delimiter: an unescaped newline lets
|
|
* user-supplied text (e.g. a subscription name or notes) terminate the
|
|
* current property and inject arbitrary calendar content (CWE-93).
|
|
*/
|
|
function icalEscape($value)
|
|
{
|
|
$value = (string) $value;
|
|
$value = str_replace('\\', '\\\\', $value);
|
|
$value = str_replace(["\r\n", "\r", "\n"], '\\n', $value);
|
|
$value = str_replace(',', '\\,', $value);
|
|
$value = str_replace(';', '\\;', $value);
|
|
return $value;
|
|
}
|
|
|
|
?>
|