mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
Saving a user from the web ui took the whole auth path down: PHP Fatal error: Uncaught TypeError: strcasecmp(): Argument #1 ($string1) must be of type string, array given in includes/auth.php:197 #0 auth.php(197): strcasecmp() #1 auth.php(528): getAuthUser() #2 auth.php(687): userFromSession() reached from ?view=user&uid=2. That page's form posts user[Username], user[Password], user[Name] and the rest, so $_REQUEST['user'] is an array on every save from it, and getAuthUser() read that parameter as the username to filter on and handed it to strcasecmp(). Under PHP 8 a string function given an array is a TypeError rather than a warning, so the request died with a 500. The same shape arrives from anyone who cares to send it, and not only on a page that needs a session. userFromSession() reads user, pass, username, password and auth straight out of the request, and the credential branches run before anyone is logged in, so ?username[]=x&password[]=y reaches validateUser() with arrays on an install that has never seen the caller before. requestString() returns a parameter only when it is a string and null otherwise, which is what the callers already do with a parameter that was not sent. An array is not a username, a password or an auth hash. master no longer has the strcasecmp line the report names, so it does not fatal in that exact spot, but it reads the same unvalidated values: $filterUser is bound as a query parameter and the credentials still reach validateUser(). This fixes the class rather than the one line, and backports to 1.38 where the reported line lives. The test lifts requestString() out of auth.php and evaluates it alone, because including auth.php needs a database; test_auth_no_include_side_effects.php sidesteps the same dependency the same way. 8 cases, covering the form's array, the login parameters, a nested array and the strings that must still pass through. 5 of them fail without this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> (cherry picked from commit 1f4aa1a16c1b63fdf34a6f2c6aef6590dbd45acd)
84 lines
3.2 KiB
PHP
84 lines
3.2 KiB
PHP
<?php
|
|
// Tests requestString() in web/includes/auth.php: the request parameters the
|
|
// auth path reads have to be strings before anything does string work on them.
|
|
//
|
|
// The reported failure was a fatal, not a wrong answer:
|
|
//
|
|
// PHP Fatal error: Uncaught TypeError: strcasecmp(): Argument #1 ($string1)
|
|
// must be of type string, array given in includes/auth.php:197
|
|
// #0 auth.php(197): strcasecmp()
|
|
// #1 auth.php(528): getAuthUser()
|
|
// #2 auth.php(687): userFromSession()
|
|
//
|
|
// reached from ?view=user&uid=2. That page's form posts user[Username],
|
|
// user[Password] and the rest, so $_REQUEST['user'] is an array on every save,
|
|
// and getAuthUser() handed it straight to strcasecmp(). The same shape arrives
|
|
// from anyone who asks for it: ?username[]=x&password[]=y reaches the login
|
|
// path with no session at all.
|
|
//
|
|
// Run: php tests/php/test_auth_request_string.php
|
|
//
|
|
// requestString() is pure, but including auth.php requires a database --
|
|
// User.php pulls in database.php, which connects at include time -- so the
|
|
// function is lifted out of the file and evaluated on its own, the same
|
|
// dodge test_auth_no_include_side_effects.php makes for the same reason.
|
|
$auth_src = file_get_contents(__DIR__.'/../../web/includes/auth.php');
|
|
if ($auth_src === false) {
|
|
echo "FAIL could not read auth.php\n";
|
|
exit(1);
|
|
}
|
|
if (!preg_match('/^function requestString\(.*?^}$/ms', $auth_src, $matches)) {
|
|
echo "FAIL requestString() not found in auth.php\n";
|
|
exit(1);
|
|
}
|
|
eval($matches[0]);
|
|
|
|
$failures = 0;
|
|
$passes = 0;
|
|
|
|
function check($name, $got, $expected) {
|
|
global $failures, $passes;
|
|
$got_str = var_export($got, true);
|
|
$expected_str = var_export($expected, true);
|
|
if ($got === $expected) {
|
|
$passes++;
|
|
echo "ok $name\n";
|
|
} else {
|
|
$failures++;
|
|
echo "FAIL $name: expected $expected_str, got $got_str\n";
|
|
}
|
|
}
|
|
|
|
// A parameter the client did send, as a string, comes back unchanged.
|
|
$_REQUEST = array('user' => 'admin');
|
|
check('string passes through', requestString('user'), 'admin');
|
|
|
|
// The empty string is still a string: callers decide what empty means, and the
|
|
// login paths already test for it with empty().
|
|
$_REQUEST = array('user' => '');
|
|
check('empty string is kept', requestString('user'), '');
|
|
|
|
// A parameter that was never sent.
|
|
$_REQUEST = array();
|
|
check('missing parameter is null', requestString('user'), null);
|
|
|
|
// The shape the user edit form posts. This is the reported crash.
|
|
$_REQUEST = array('user' => array('Username' => 'admin', 'Password' => 'secret'));
|
|
check('form array is refused', requestString('user'), null);
|
|
|
|
// The shape an attacker sends, on the paths that need no session.
|
|
$_REQUEST = array('username' => array('admin'), 'password' => array('x'));
|
|
check('username array is refused', requestString('username'), null);
|
|
check('password array is refused', requestString('password'), null);
|
|
|
|
// An auth hash is used to look up a user and compared against the session copy.
|
|
$_REQUEST = array('auth' => array('deadbeef'));
|
|
check('auth array is refused', requestString('auth'), null);
|
|
|
|
// Anything else PHP can put in a request parameter.
|
|
$_REQUEST = array('user' => array(array('nested')));
|
|
check('nested array is refused', requestString('user'), null);
|
|
|
|
echo "\n$passes passed, $failures failed\n";
|
|
exit($failures ? 1 : 0);
|