mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-10-09 02:52:47 -04:00
* fix(taxes): reject invalid characters in tax code, category, and jurisdiction names Apply the same unicode_alpha_numeric_punct validation already used for item tax names to the three tax save endpoints, so stored-XSS payloads (<, >) are rejected with a validation error instead of being saved. Mirrors the Items fix and adds a TaxesControllerTest regression suite. * fix(taxes): permit slash and CJK in tax names, add regression tests The unicode_alpha_numeric_punct guard rejected '/' (char type Po), which blocks legitimate slash-separated tax names such as 'GST/HST' and 'VAT/GST' from being saved. Add '/' to the allowed punctuation set and document it. Also add regression tests proving acceptance of a slash name (GST/HST) and a CJK name (消費税) across the tax save endpoints. Addresses CodeRabbit review on #4679. * test(4679): adopt test{Method}_{Purpose} naming convention Align test method names with the convention from #4730 (testPostSaveTaxCodes_RejectsMaliciousName, etc.), per review. * fix(taxes): allow parentheses in names, make name optional Address CodeRabbit review on #4733: - Permit parentheses in tax names (e.g. "VAT (20%)"); slash was already allowed, so both "GST/HST" and "VAT (20%)" now pass while < and > are still rejected. - Drop the rule from tax_code_name, jurisdiction_name and tax_category so a code with a blank name can be saved, matching the form (the form does not require the name). - Add regression tests for the parentheses and blank-name cases. --------- Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
272 lines
8.6 KiB
PHP
272 lines
8.6 KiB
PHP
<?php
|
|
|
|
namespace Tests\Controllers;
|
|
|
|
use CodeIgniter\Database\Config;
|
|
use CodeIgniter\Test\CIUnitTestCase;
|
|
use CodeIgniter\Test\DatabaseTestTrait;
|
|
use CodeIgniter\Test\FeatureTestTrait;
|
|
use Tests\Support\EmployeeFixtureTrait;
|
|
|
|
class TaxesControllerTest extends CIUnitTestCase
|
|
{
|
|
use DatabaseTestTrait;
|
|
use FeatureTestTrait;
|
|
use EmployeeFixtureTrait;
|
|
|
|
protected $migrate = true;
|
|
protected $migrateOnce = true;
|
|
protected $seedOnce = true;
|
|
protected $refresh = false;
|
|
protected $namespace = null;
|
|
|
|
private static $doneBootstrap = false;
|
|
|
|
protected function setUp(): void
|
|
{
|
|
if (self::$doneBootstrap === false) {
|
|
Config::seeder($this->DBGroup)->call('App\Database\Seeds\TestDatabaseBootstrapSeeder');
|
|
Config::connect($this->DBGroup)->close();
|
|
|
|
self::$doneBootstrap = true;
|
|
}
|
|
|
|
parent::setUp();
|
|
}
|
|
|
|
protected function tearDown(): void
|
|
{
|
|
parent::tearDown();
|
|
}
|
|
|
|
protected function createTaxesEmployee(): int
|
|
{
|
|
return $this->createEmployee(
|
|
grants: [
|
|
['permission_id' => 'taxes', 'menu_group' => 'office'],
|
|
]
|
|
);
|
|
}
|
|
|
|
protected function loginAsTaxesEmployee(int $personId): void
|
|
{
|
|
$this->withSession([
|
|
'person_id' => $personId,
|
|
'menu_group' => 'office',
|
|
]);
|
|
}
|
|
|
|
/**
|
|
* Regression test: `tax_code_name[]` containing `<`/`>` (the stored-XSS
|
|
* vector) must be rejected by postSave_tax_codes before anything is saved.
|
|
*/
|
|
public function testPostSaveTaxCodes_RejectsMaliciousName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_codes', [
|
|
'tax_code_id' => ['-1'],
|
|
'tax_code' => ['TC' . uniqid()],
|
|
'tax_code_name' => ['<svg onload=alert(1)>'],
|
|
'city' => [''],
|
|
'state' => [''],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertFalse($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Legitimate unicode tax code names must not be rejected by the XSS guard.
|
|
*/
|
|
public function testPostSaveTaxCodes_AcceptsUnicodeName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_codes', [
|
|
'tax_code_id' => ['-1'],
|
|
'tax_code' => ['TC' . uniqid()],
|
|
'tax_code_name' => ["Impôt, incl."],
|
|
'city' => [''],
|
|
'state' => [''],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Slash-separated tax names (e.g. "GST/HST") are legitimate and must not be
|
|
* rejected by the validation guard.
|
|
*/
|
|
public function testPostSaveTaxCodes_AcceptsSlashName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_codes', [
|
|
'tax_code_id' => ['-1'],
|
|
'tax_code' => ['TC' . uniqid()],
|
|
'tax_code_name' => ['GST/HST'],
|
|
'city' => [''],
|
|
'state' => [''],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Parenthesised tax names (e.g. "VAT (20%)") are legitimate and must not be
|
|
* rejected by the validation guard.
|
|
*/
|
|
public function testPostSaveTaxCodes_AcceptsParenthesesName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_codes', [
|
|
'tax_code_id' => ['-1'],
|
|
'tax_code' => ['TC' . uniqid()],
|
|
'tax_code_name' => ['VAT (20%)'],
|
|
'city' => [''],
|
|
'state' => [''],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
|
|
/**
|
|
* A tax code whose name is left blank is legitimate (the form does not
|
|
* require a name) and must not be rejected by the validation guard.
|
|
*/
|
|
public function testPostSaveTaxCodes_AcceptsBlankName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_codes', [
|
|
'tax_code_id' => ['-1'],
|
|
'tax_code' => ['TC' . uniqid()],
|
|
'tax_code_name' => [''],
|
|
'city' => [''],
|
|
'state' => [''],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Regression test: `tax_category[]` containing `<`/`>` must be rejected.
|
|
*/
|
|
public function testPostSaveTaxCategories_RejectsMaliciousName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_categories', [
|
|
'tax_category_id' => ['-1'],
|
|
'tax_category' => ['<svg onload=alert(1)>'],
|
|
'tax_group_sequence' => ['1'],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertFalse($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Legitimate unicode tax category names must not be rejected.
|
|
*/
|
|
public function testPostSaveTaxCategories_AcceptsUnicodeName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_categories', [
|
|
'tax_category_id' => ['-1'],
|
|
'tax_category' => ["Impôt, incl."],
|
|
'tax_group_sequence' => ['1'],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
|
|
/**
|
|
* CJK tax names (e.g. "消費税", the Japanese consumption tax) are legitimate
|
|
* and must not be rejected by the validation guard.
|
|
*/
|
|
public function testPostSaveTaxCategories_AcceptsCjkName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_categories', [
|
|
'tax_category_id' => ['-1'],
|
|
'tax_category' => ['消費税'],
|
|
'tax_group_sequence' => ['1'],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Regression test: `jurisdiction_name[]` containing `<`/`>` must be rejected.
|
|
*/
|
|
public function testPostSaveTaxJurisdictions_RejectsMaliciousName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_jurisdictions', [
|
|
'jurisdiction_id' => ['-1'],
|
|
'jurisdiction_name' => ['<svg onload=alert(1)>'],
|
|
'tax_group' => ['1'],
|
|
'tax_type' => ['0'],
|
|
'reporting_authority' => [''],
|
|
'tax_group_sequence' => ['1'],
|
|
'cascade_sequence' => ['1'],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertFalse($result['success']);
|
|
}
|
|
|
|
/**
|
|
* Legitimate unicode jurisdiction names must not be rejected.
|
|
*/
|
|
public function testPostSaveTaxJurisdictions_AcceptsUnicodeName(): void
|
|
{
|
|
$employeeId = $this->createTaxesEmployee();
|
|
$this->loginAsTaxesEmployee($employeeId);
|
|
|
|
$response = $this->post('/taxes/save_tax_jurisdictions', [
|
|
'jurisdiction_id' => ['-1'],
|
|
'jurisdiction_name' => ["Impôt, incl."],
|
|
'tax_group' => ['1'],
|
|
'tax_type' => ['0'],
|
|
'reporting_authority' => [''],
|
|
'tax_group_sequence' => ['1'],
|
|
'cascade_sequence' => ['1'],
|
|
]);
|
|
|
|
$response->assertStatus(200);
|
|
$result = json_decode($response->getJSON(), true);
|
|
$this->assertTrue($result['success']);
|
|
}
|
|
}
|