4
0
Эх сурвалжийг харах

Remove vulnerable and unused code path for displaying errors (#9395)

If we were to remove or rename `errorController`, an HTML injection could potentially be introduced due to the fallback code path, that directly echoes the logs without any escaping.

(but mainly removing it to reduce the amount of code, and since it's unused)
Inverle 7 цаг өмнө
parent
commit
4e5e142cd0
1 өөрчлөгдсөн 5 нэмэгдсэн , 20 устгасан
  1. 5 20
      lib/Minz/Error.php

+ 5 - 20
lib/Minz/Error.php

@@ -23,28 +23,13 @@ class Minz_Error {
 	*/
 	public static function error(int $code = 404, string|array $logs = [], bool $redirect = true): void {
 		$logs = self::processLogs($logs);
-		$error_filename = APP_PATH . '/Controllers/errorController.php';
 
-		if (file_exists($error_filename)) {
-			Minz_Session::_params([
-				'error_code' => $code,
-				'error_logs' => $logs,
-			]);
+		Minz_Session::_params([
+			'error_code' => $code,
+			'error_logs' => $logs,
+		]);
 
-			Minz_Request::forward(['c' => 'error'], $redirect);
-		} else {
-			echo '<h1>An error occurred</h1>' . "\n";
-
-			if (!empty($logs)) {
-				echo '<ul>' . "\n";
-				foreach ($logs as $log) {
-					echo '<li>' . $log . '</li>' . "\n";
-				}
-				echo '</ul>' . "\n";
-			}
-
-			exit();
-		}
+		Minz_Request::forward(['c' => 'error'], $redirect);
 	}
 
 	/**