Files
opensourcepos/app/Language/ml/Config.php
T
184918d914 fix(security): handle special characters in .env key values and improve insertion logic (#4656)
* fix(security): handle special characters in `.env` key values and improve insertion logic

- Escape backslashes and dollar signs in `applyEnvKeyReplacement` to prevent unintended value corruption.
- Ensure new keys are inserted after `encryption.key` for better organization and manageability.
- Add explicit cast to int to prevent wrong concatenation operator warning.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): handle null return in `applyEnvKeyReplacement` and ensure proper `.env` updates

- Update `applyEnvKeyReplacement` to return `null` on failure, improving error handling.
- Adjust calls to `atomicWriteFile` with updated content to prevent unintended behavior.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): improve error logging and exception messages in file locking

- Add detailed logging for file open and locking errors in `security_helper`.
- Remove unused `helper` and `checkThrottleEncryption` calls from `Events` for cleanup.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): improve atomic file write and handle encryption key placement

- Throw `RandomException` for better error reporting in `atomicWriteFile`.
- Simplify Windows-specific `rename()` fallback logic.
- Fix `encryption.key` assignment order to ensure consistency in `.env` updates.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): improve `.env` file handling and add unit tests for helper functions

- Suppress warnings in `file_get_contents` to prevent unnecessary error logs.
- Update `applyEnvKeyReplacement` to use `preg_replace_callback` for better safety.
- Add comprehensive unit tests for `security_helper` functions to ensure `.env` updates and key management work as expected.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): enhance `.env` update logic and add robust exception handling

- Add `RandomException` to improve error reporting in encryption key management.
- Introduce environment file locking for safer `.env` updates.
- Ensure `applyEnvKeyReplacement` properly handles and inserts old key comments.
- Replace direct file writes with `atomicWriteFile` for consistency.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): refactor `.env` file initialization and encryption key handling

- Introduce `initializeEnvFile` for reusable `.env` setup logic.
- Add `backupEnvFile` and `writeNewEncryptionKey` for robust key management with backups.
- Simplify and clean up redundant `.env` handling code paths.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): clarify `checkEncryption` docblock return value description

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): escape backslashes and dollar signs in `applyEnvKeyReplacement`

- Ensure `applyEnvKeyReplacement` properly escapes special characters when inserting or appending `.env` keys.
- Add new unit tests to validate correct handling of backslashes and dollar signs.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(i18n): add localized error messages and improve error reporting in `security_helper`

- Add missing translations for error messages across multiple language files.
- Update `security_helper` to use localized exception messages with placeholders.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* Redesign encryption/throttle key provisioning as read-only runtime

- checkEncryption()/checkThrottleEncryption() are now read-only guards that
  throw when no valid key is provisioned, instead of writing .env at
  request time.
- Add rotateEncryptionKey() and provisionThrottleKey() for explicit,
  idempotent provisioning.
- Add php spark env:provision (app/Commands/EnvProvision.php) so Docker can
  provision keys once at container startup before any request.
- Add app/Libraries/CI3SecretConverter.php shared CI3->CI4 secret converter
  (AES-128-CBC decrypt + CI4 re-encrypt/verify/save) used by both the
  interactive migration and the docker startup path.
- Refactor convertToCI4 migration to use the shared converter.
- Persist .env in a named volume and run spark env:provision on boot; stop
  baking .env into the shipped image.
- Add guard/rotation/throttle + converter tests; clean up orphaned
  msg_pwd_required language keys across all locales.

* fix: save CI4 ciphertext in env:provision and bind-mount a .env file

Addresses CodeRabbit review on PR #4656:

- env:provision CI3 branch was persisting *plaintext* secrets (saveAll($plain))
  instead of the CI4 ciphertext, unlike the ConvertToCI4 migration. Now
  encrypts with encryptAll(), verifies the round trip, and saves the ciphertext.
- The ospos_env named volume mounted at /app/.env made .env a directory, so
  atomicWriteFile's rename() failed and spark env:provision could not start apache.
  Switch to a bind mount of a host file (./.env) which persists and stays a file.
- Add a regression test asserting the command persists ciphertext (not plaintext).

* chore: trim redundant docblocks in EnvProvision and provision throttle.key in CI

Follow up on @objecttothis review comments:
- app/Commands/EnvProvision.php: remove the boilerplate docblocks the
  property names already convey (group/name/usage/description, run()),
  the two inline step comments, the anyNonEmpty() param docblock, and the
  legacySecretsPresent() docblock. Keeps the class-level docblock since it
  is the only place that states the read-only runtime design + the
  never-persist-plaintext invariant.
- .github/workflows/phpunit.yml: provision a per-run throttle.key the same
  way the encryption key is already provisioned. The PR makes
  checkThrottleEncryption() a read-only guard that throws when
  env('throttle.key') is unset; CI only started exporting ENCRYPTION_KEY,
  so every test that goes through the Throttle filter (7 ThrottleTest
  cases + 4 LoginTest cases) failed with
  "No throttle key is provisioned. Run `php spark env:provision`".
  Writing `throttle.key=<KEY>` into .env matches what
  `php spark env:provision` does on a real container start.

* fix(ci): write throttle.key into .env instead of exporting an OS env var

The previous attempt exported throttle.key via GITHUB_ENV, but CodeIgniter's
env() helper resolves in the order $_ENV[$key] ?? $_SERVER[$key] ?? getenv($key),
and DotEnv populates $_ENV['throttle.key'] from the .env file first. Because the
.env (copied from .env.example) ships with the empty placeholder throttle.key='',
that $_ENV entry exists as '' and short-circuits the ?? chain before getenv()
is reached — so the OS env var was never consulted and every Throttle/Login test
still threw 'No throttle key is provisioned'.

Write the per-run key into the .env file itself (sed-replacing the empty
placeholder), which is exactly what `php spark env:provision` does in
production and is the single source env() actually reads from.

Verify the replacement happened (grep -Eq '^throttle\.key=.') so a future change
to the placeholder format fails the run loudly instead of silently breaking
the 11 throttle-dependent tests.

* fix(security): restore CI3->CI4 auto-provisioning gated by .env writability

checkEncryption()/checkThrottleEncryption() again provision the keys
inline when .env is writable (empty key -> generate; short key -> decrypt,
rotate, re-encrypt, verify, persist legacy CI3 secrets). When .env is not
writable they assume the key was provisioned externally (e.g. docker
env:provision) and throw. Update helper tests to match and correct the
EnvProvision docblock that claimed the runtime was strictly read-only.

* test(security): make short-key conversion branch injectable and test it

checkEncryption() now accepts an optional CI3SecretConverter so the
CI3->CI4 conversion branch can be exercised in unit tests without a
database. Adds testCheckEncryptionConvertsCi3ShortKeyWhenEnvWritable
which seeds CI3-era ciphertexts via a fake Appconfig model and asserts
the key is rotated and the payload verifies back to the original
plaintext.

* fix(security): abort on backup/read/saveAll failure to avoid data loss

Three related data-integrity fixes:

- backupEnvFile() now returns true/false based on whether the backup
  actually exists and is readable. rotateEncryptionKey() aborts before
  destroying the key when the backup could not be written to disk.

- rotateEncryptionKey() and provisionThrottleKey() throw
  RuntimeException(Error.unable_to_read_env_file) when the .env read
  fails, instead of silently replacing the whole file with an empty
  string. This prevents a permission error from wiping all keys.

- checkEncryption() and EnvProvision::run() now both roll back to the
  backup with abortEncryptionConversion() when the post-rotation
  saveAll() throws, matching the migration path (which already did this).
  A failing fake Appconfig is used to exercise this in the new
  testCheckEncryptionRollsBackWhenSaveAllFails test.

* fix(ci): skip comment job in deploy-pr.yml when prepare was not run

The comment job had if: always(), so it ran even when the prepare job
was skipped (e.g. review was not approved). With PR_NUMBER empty the gh
api call posted to issues//comments, received a 404, and the entire run
showed up as failure. Guard the job with
needs.prepare.result == 'success' so it only runs when PR_NUMBER is valid.

* address coderabbit open items: placeholder guards, message neutrality, ar-EG alignment

- backupEnvFile(): fail when mkdir() or either chmod() fails, so the
  pre-rotation backup is actually persisted before the key is replaced
- email/message config views: only show the 'already set' placeholder when
  the secret is actually present (prevented false positives on fresh installs)
- Error.unable_to_create_env_file / .unable_to_read_env_file (en + en-GB):
  use key-neutral wording since both keys are provisioned with the same keys
- ar-EG/Error.php: align all => arrows on the longest key

Item 7 (filesystem test isolation) is a larger refactor — the tests are
serial on CI and tearDown() restores state per test. Left for follow-up.

* test(security): isolate helper FS tests via Config\SecurityEnv

Introduce Config\SecurityEnv holding envPath/backupPath/lockPath so the
security helper reads its target paths from shared configuration instead of
hardcoded ROOTPATH/WRITEPATH literals. security_helperTest.php now redirects
all three to a unique per-run sandbox under sys_get_temp_dir() and tears it
down in tearDown(), so the suite no longer reads/writes the repository's real
.env and is safe to run in parallel.

No helper signature changes; production callers unaffected.

Addresses CodeRabbit item 7 (issue #4700).

Co-Authored-By: opencode <bot@opencode.ai>

* fix(security): run key-conversion as one locked transaction

Address CodeRabbit Major findings from the 4th re-review of the env
helper and its callers:

1. Hold .env.lock for the entire CI3 -> CI4 conversion transaction
   (backup -> rotate -> re-encrypt -> verify -> persist -> cleanup) so a
   concurrent worker cannot interleave a key write between the rotation
   and the ciphertext save. Split rotateEncryptionKey into a lock-free
   core (rotateEncryptionKeyUnlock) plus the existing lock wrapper and a
   new rotateEncryptionKeyTransaction that owns the lock across the full
   unit and performs both the in-lock rollback (abortEncryptionConversion)
   and the in-lock backup removal on success.

2. Treat the legacy value '0' as non-empty data so key rotation still
   persists the re-encrypted ciphertext when '0' is the only stored
   secret (array_filter would have dropped it and skipped saveAll).

3. Wrap the post-rotation re-encrypt/verify/saveAll sequence in a
   catch (Throwable) across all three call-sites so CI4
   EncryptionException, ReflectionException from batch_save, a failed
   round-trip verify, and any other failure all roll the .env key back
   to the pre-rotation state.

4. In Docker Compose, use long-syntax bind with create_host_path: false
   and document in INSTALL.md that the host .env must be a regular file
   (a missing one is no longer auto-created as a directory, and the
   mount now rejects a missing source on Compose implementations that
   support the flag).

Files touched: app/Helpers/security_helper.php, app/Commands/EnvProvision.php,
app/Database/Migrations/20220127000000_convertToCI4.php, docker-compose.yml,
INSTALL.md. All 4 existing helper tests still pass via CI.

* fix(security): make abortEncryptionConversion fail loudly on restore failure

The rollback path restored the .env backup with a suppressed
file_put_contents() and an unchecked file_get_contents(). If the restore
failed after the key had already been rotated, .env was left holding the new
CI4 key while the DB still held CI3-era ciphertext, so the data became
undecryptable after the next restart.

Now the backup read is checked for false and the restore goes through the
existing atomicWriteFile() helper; either failure throws so the error is
surfaced instead of silently corrupting the config. Adds a regression test
that forces an unreadable backup and asserts the throw plus that .env is
left untouched.

* fix(security): guard abortEncryptionConversion backup read before touching it

Validate the backup is a regular readable file (is_file/is_readable) before
reading it, so a missing/malformed backup fails loudly instead of emitting a
file_get_contents() warning. The unreadable-backup regression test now
exercises this guard rather than relying on a promoted warning.

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: jekkos <jeroen.peelaerts@gmail.com>
Co-authored-by: jekkos <jekkos@users.noreply.github.com>
Co-authored-by: opencode <bot@opencode.ai>
2026-09-21 17:35:45 +02:00

335 lines
19 KiB
PHP

<?php
return [
'address' => '',
'address_required' => '',
'all_set' => 'All file permissions are set correctly!',
'allow_duplicate_barcodes' => '',
'apostrophe' => '',
'backup_button' => '',
'backup_database' => '',
'barcode' => '',
'barcode_company' => '',
'barcode_configuration' => '',
'barcode_content' => '',
'barcode_first_row' => '',
'barcode_font' => '',
'barcode_formats' => '',
'barcode_generate_if_empty' => '',
'barcode_height' => '',
'barcode_id' => '',
'barcode_info' => '',
'barcode_layout' => '',
'barcode_name' => '',
'barcode_number' => '',
'barcode_number_in_row' => '',
'barcode_page_cellspacing' => '',
'barcode_page_width' => '',
'barcode_price' => '',
'barcode_second_row' => '',
'barcode_third_row' => '',
'barcode_tooltip' => '',
'barcode_type' => '',
'barcode_width' => '',
'bottom' => '',
'cash_button' => '',
'cash_button_1' => '',
'cash_button_2' => '',
'cash_button_3' => '',
'cash_button_4' => '',
'cash_button_5' => '',
'cash_button_6' => '',
'cash_decimals' => '',
'cash_decimals_tooltip' => '',
'cash_rounding' => '',
'category_dropdown' => '',
'center' => '',
'change_apperance_tooltip' => '',
'comma' => '',
'company' => '',
'company_avatar' => '',
'company_change_image' => '',
'company_logo' => '',
'company_remove_image' => '',
'company_required' => '',
'company_select_image' => '',
'company_website_url' => '',
'country_codes' => '',
'country_codes_tooltip' => '',
'currency_code' => '',
'currency_decimals' => '',
'currency_symbol' => '',
'current_employee_only' => '',
'customer_reward' => '',
'customer_reward_duplicate' => '',
'customer_reward_enable' => '',
'customer_reward_invalid_chars' => '',
'customer_reward_required' => '',
'customer_sales_tax_support' => '',
'date_or_time_format' => '',
'datetimeformat' => '',
'decimal_point' => '',
'default_barcode_font_size_number' => '',
'default_barcode_font_size_required' => '',
'default_barcode_height_number' => '',
'default_barcode_height_required' => '',
'default_barcode_num_in_row_number' => '',
'default_barcode_num_in_row_required' => '',
'default_barcode_page_cellspacing_number' => '',
'default_barcode_page_cellspacing_required' => '',
'default_barcode_page_width_number' => '',
'default_barcode_page_width_required' => '',
'default_barcode_width_number' => '',
'default_barcode_width_required' => '',
'default_item_columns' => '',
'default_origin_tax_code' => '',
'default_receivings_discount' => '',
'default_receivings_discount_number' => '',
'default_receivings_discount_required' => '',
'default_sales_discount' => '',
'default_sales_discount_number' => '',
'default_sales_discount_required' => '',
'default_tax_category' => '',
'default_tax_code' => '',
'default_tax_jurisdiction' => '',
'default_tax_name_number' => '',
'default_tax_name_required' => '',
'default_tax_rate' => '',
'default_tax_rate_1' => '',
'default_tax_rate_2' => '',
'default_tax_rate_3' => '',
'default_tax_rate_number' => '',
'default_tax_rate_required' => '',
'derive_sale_quantity' => '',
'derive_sale_quantity_tooltip' => '',
'dinner_table' => '',
'dinner_table_duplicate' => '',
'dinner_table_enable' => '',
'dinner_table_invalid_chars' => '',
'dinner_table_required' => '',
'dot' => '',
'email' => '',
'email_configuration' => '',
'email_mailpath' => '',
'email_protocol' => '',
'email_receipt_check_behaviour' => '',
'email_receipt_check_behaviour_always' => '',
'email_receipt_check_behaviour_last' => '',
'email_receipt_check_behaviour_never' => '',
'email_smtp_crypto' => '',
'email_smtp_host' => '',
'email_smtp_pass' => '',
'email_smtp_port' => '',
'email_smtp_timeout' => '',
'email_smtp_user' => '',
'enable_avatar' => '',
'enable_avatar_tooltip' => '',
'enable_dropdown_tooltip' => '',
'enable_new_look' => '',
'enable_right_bar' => '',
'enable_right_bar_tooltip' => '',
'enforce_privacy' => '',
'enforce_privacy_tooltip' => '',
'fax' => '',
'file_perm' => 'There are problems with file permissions please fix and reload this page.',
'financial_year' => '',
'financial_year_apr' => '',
'financial_year_aug' => '',
'financial_year_dec' => '',
'financial_year_feb' => '',
'financial_year_jan' => '',
'financial_year_jul' => '',
'financial_year_jun' => '',
'financial_year_mar' => '',
'financial_year_may' => '',
'financial_year_nov' => '',
'financial_year_oct' => '',
'financial_year_sep' => '',
'floating_labels' => '',
'gcaptcha_enable' => '',
'gcaptcha_secret_key' => '',
'gcaptcha_secret_key_required' => '',
'gcaptcha_site_key' => '',
'gcaptcha_site_key_required' => '',
'gcaptcha_tooltip' => '',
'general' => '',
'general_configuration' => '',
'giftcard_number' => '',
'giftcard_random' => '',
'giftcard_series' => '',
'image_allowed_file_types' => '',
'image_max_height_tooltip' => '',
'image_max_size_tooltip' => '',
'image_max_width_tooltip' => '',
'image_restrictions' => '',
'include_hsn' => '',
'info' => '',
'info_configuration' => '',
'input_groups' => '',
'integrations' => '',
'integrations_configuration' => '',
'invoice' => '',
'invoice_configuration' => '',
'invoice_default_comments' => '',
'invoice_email_message' => '',
'invoice_enable' => '',
'invoice_printer' => '',
'invoice_type' => '',
'is_readable' => '',
'is_writable' => 'is writable, but the permissions are higher than 750.',
'item_markup' => '',
'jsprintsetup_required' => '',
'language' => '',
'last_used_invoice_number' => '',
'last_used_quote_number' => '',
'last_used_work_order_number' => '',
'left' => '',
'license' => '',
'license_configuration' => '',
'line_sequence' => '',
'lines_per_page' => '',
'lines_per_page_number' => '',
'lines_per_page_required' => '',
'locale' => '',
'locale_configuration' => '',
'locale_info' => '',
'location' => '',
'location_configuration' => '',
'location_info' => '',
'login_form' => '',
'logout' => '',
'mailchimp' => '',
'mailchimp_api_key' => '',
'mailchimp_configuration' => '',
'mailchimp_key_successfully' => '',
'mailchimp_key_unsuccessfully' => '',
'mailchimp_lists' => '',
'mailchimp_tooltip' => '',
'message' => '',
'message_configuration' => '',
'msg_msg' => '',
'msg_msg_placeholder' => '',
'msg_pwd' => '',
'msg_src' => '',
'msg_src_required' => '',
'msg_uid' => '',
'msg_uid_required' => '',
'multi_pack_enabled' => '',
'no_risk' => 'No security/vulnerability risks.',
'none' => '',
'notify_alignment' => '',
'number_format' => '',
'number_locale' => '',
'number_locale_invalid' => '',
'number_locale_required' => '',
'number_locale_tooltip' => '',
'os_timezone' => '',
'ospos_info' => '',
'payment_options_order' => '',
'payment_reference_code_length_limits' => 'പേയ്‌മെന്റ് റഫറൻസ് കോഡ്<br>ദൈർഘ്യ പരിധികൾ',
'payment_reference_code_length_max_label' => 'പരമാവധി',
'payment_reference_code_length_min_label' => 'കുറഞ്ഞത്',
'perm_risk' => 'Permissions higher than 750 leaves this software at risk.',
'phone' => '',
'phone_required' => '',
'print_bottom_margin' => '',
'print_bottom_margin_number' => '',
'print_bottom_margin_required' => '',
'print_delay_autoreturn' => '',
'print_delay_autoreturn_number' => '',
'print_delay_autoreturn_required' => '',
'print_footer' => '',
'print_header' => '',
'print_left_margin' => '',
'print_left_margin_number' => '',
'print_left_margin_required' => '',
'print_receipt_check_behaviour' => '',
'print_receipt_check_behaviour_always' => '',
'print_receipt_check_behaviour_last' => '',
'print_receipt_check_behaviour_never' => '',
'print_right_margin' => '',
'print_right_margin_number' => '',
'print_right_margin_required' => '',
'print_silently' => '',
'print_top_margin' => '',
'print_top_margin_number' => '',
'print_top_margin_required' => '',
'quantity_decimals' => '',
'quick_cash_enable' => '',
'quote_default_comments' => '',
'receipt' => '',
'receipt_category' => '',
'receipt_configuration' => '',
'receipt_default' => '',
'receipt_font_size' => '',
'receipt_font_size_number' => '',
'receipt_font_size_required' => '',
'receipt_info' => '',
'receipt_printer' => '',
'receipt_short' => '',
'receipt_show_company_name' => '',
'receipt_show_description' => '',
'receipt_show_serialnumber' => '',
'receipt_show_tax_ind' => '',
'receipt_show_taxes' => '',
'receipt_show_total_discount' => '',
'receipt_template' => '',
'receiving_calculate_average_price' => '',
'recv_invoice_format' => '',
'register_mode_default' => '',
'report_an_issue' => '',
'return_policy_required' => '',
'reward' => '',
'reward_configuration' => '',
'right' => '',
'sales_invoice_format' => '',
'sales_quote_format' => '',
'mailpath_invalid' => 'അസാധുവായ sendmail പാത്ത്. അക്ഷരങ്ങൾ, അക്കങ്ങൾ, ഡാഷുകൾ, അടിവരകൾ, സ്ലാഷുകൾ, ബാക്ക്സ്ലാഷുകൾ, കോളനുകൾ, സ്പേസുകൾ, ഡോട്ടുകൾ എന്നിവ മാത്രമേ അനുവദനീയമായുള്ളൂ.',
'saved_successfully' => '',
'saved_unsuccessfully' => '',
'security_issue' => 'Security Vulnerability Warning',
'server_notice' => 'Please use the below info for issue reporting.',
'service_charge' => '',
'show_due_enable' => '',
'show_office_group' => '',
'statistics' => '',
'statistics_tooltip' => '',
'stock_location' => '',
'stock_location_duplicate' => '',
'stock_location_invalid_chars' => '',
'stock_location_required' => '',
'suggestions_fifth_column' => '',
'suggestions_first_column' => '',
'suggestions_fourth_column' => '',
'suggestions_layout' => '',
'suggestions_second_column' => '',
'suggestions_third_column' => '',
'system_conf' => 'Setup & Conf',
'system_info' => 'System Info',
'table' => '',
'table_configuration' => '',
'takings_printer' => '',
'tax' => '',
'tax_category' => '',
'tax_category_duplicate' => '',
'tax_category_invalid_chars' => '',
'tax_category_required' => '',
'tax_category_used' => '',
'tax_configuration' => '',
'tax_decimals' => '',
'tax_id' => '',
'tax_included' => '',
'theme' => '',
'theme_preview' => '',
'thousands_separator' => '',
'timezone' => '',
'timezone_error' => '',
'top' => '',
'use_destination_based_tax' => '',
'user_timezone' => '',
'website' => '',
'wholesale_markup' => '',
'work_order_enable' => '',
'work_order_format' => '',
];