瀏覽代碼

Remove vulnerable and unused code path for displaying errors (#9395)

If we were to remove or rename `errorController`, an HTML injection could potentially be introduced due to the fallback code path, that directly echoes the logs without any escaping.

(but mainly removing it to reduce the amount of code, and since it's unused)
Inverle 10 小時之前
父節點
當前提交
4e5e142cd0
共有 1 個文件被更改,包括 5 次插入 和 20 次删除
  1. 5 20
      lib/Minz/Error.php

+ 5 - 20
lib/Minz/Error.php

@@ -23,28 +23,13 @@ class Minz_Error {
 	*/
 	public static function error(int $code = 404, string|array $logs = [], bool $redirect = true): void {
 		$logs = self::processLogs($logs);
-		$error_filename = APP_PATH . '/Controllers/errorController.php';
 
-		if (file_exists($error_filename)) {
-			Minz_Session::_params([
-				'error_code' => $code,
-				'error_logs' => $logs,
-			]);
+		Minz_Session::_params([
+			'error_code' => $code,
+			'error_logs' => $logs,
+		]);
 
-			Minz_Request::forward(['c' => 'error'], $redirect);
-		} else {
-			echo '<h1>An error occurred</h1>' . "\n";
-
-			if (!empty($logs)) {
-				echo '<ul>' . "\n";
-				foreach ($logs as $log) {
-					echo '<li>' . $log . '</li>' . "\n";
-				}
-				echo '</ul>' . "\n";
-			}
-
-			exit();
-		}
+		Minz_Request::forward(['c' => 'error'], $redirect);
 	}
 
 	/**