ソースを参照

Remove vulnerable and unused code path for displaying errors (#9395)

If we were to remove or rename `errorController`, an HTML injection could potentially be introduced due to the fallback code path, that directly echoes the logs without any escaping.

(but mainly removing it to reduce the amount of code, and since it's unused)
Inverle 14 時間 前
親
コミット
4e5e142cd0
1 ファイル変更、5 行追加、20 行削除
  1. 5 20
      lib/Minz/Error.php

+ 5 - 20
lib/Minz/Error.php

@@ -23,28 +23,13 @@ class Minz_Error {
 	*/
 	public static function error(int $code = 404, string|array $logs = [], bool $redirect = true): void {
 		$logs = self::processLogs($logs);
-		$error_filename = APP_PATH . '/Controllers/errorController.php';
 
-		if (file_exists($error_filename)) {
-			Minz_Session::_params([
-				'error_code' => $code,
-				'error_logs' => $logs,
-			]);
+		Minz_Session::_params([
+			'error_code' => $code,
+			'error_logs' => $logs,
+		]);
 
-			Minz_Request::forward(['c' => 'error'], $redirect);
-		} else {
-			echo '<h1>An error occurred</h1>' . "\n";
-
-			if (!empty($logs)) {
-				echo '<ul>' . "\n";
-				foreach ($logs as $log) {
-					echo '<li>' . $log . '</li>' . "\n";
-				}
-				echo '</ul>' . "\n";
-			}
-
-			exit();
-		}
+		Minz_Request::forward(['c' => 'error'], $redirect);
 	}
 
 	/**