2022-11-21 02:58:22 +00:00
< ? php
/* Copyright ( C ) 2010 Laurent Destailleur < eldy @ users . sourceforge . net >
2023-05-07 12:31:35 +00:00
* Copyright ( C ) 2023 Alexandre Janniaux < alexandre . janniaux @ gmail . com >
2024-11-13 23:16:43 +00:00
* Copyright ( C ) 2024 Frédéric France < frederic . france @ free . fr >
2022-11-21 02:58:22 +00:00
*
* This program is free software ; you can redistribute it and / or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation ; either version 3 of the License , or
* ( at your option ) any later version .
*
* This program is distributed in the hope that it will be useful ,
* but WITHOUT ANY WARRANTY ; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
* GNU General Public License for more details .
*
* You should have received a copy of the GNU General Public License
* along with this program . If not , see < https :// www . gnu . org / licenses />.
* or see https :// www . gnu . org /
*/
/**
* \file test / phpunit / WebsiteTest . php
* \ingroup test
* \brief PHPUnit test
* \remarks To run this script as CLI : phpunit filename . php
*/
global $conf , $user , $langs , $db ;
//define('TEST_DB_FORCE_TYPE','mysql'); // This is to force using mysql driver
//require_once 'PHPUnit/Autoload.php';
2024-02-16 22:26:32 +00:00
require_once dirname ( __FILE__ ) . '/CommonClassTest.class.php' ;
2022-11-21 02:58:22 +00:00
if ( ! defined ( 'NOREQUIRESOC' )) {
define ( 'NOREQUIRESOC' , '1' );
}
if ( ! defined ( 'NOCSRFCHECK' )) {
define ( 'NOCSRFCHECK' , '1' );
}
if ( ! defined ( 'NOTOKENRENEWAL' )) {
define ( 'NOTOKENRENEWAL' , '1' );
}
if ( ! defined ( 'NOREQUIREMENU' )) {
define ( 'NOREQUIREMENU' , '1' ); // If there is no menu to show
}
if ( ! defined ( 'NOREQUIREHTML' )) {
define ( 'NOREQUIREHTML' , '1' ); // If we don't need to load the html.form.class.php
}
if ( ! defined ( 'NOREQUIREAJAX' )) {
define ( 'NOREQUIREAJAX' , '1' );
}
if ( ! defined ( " NOLOGIN " )) {
define ( " NOLOGIN " , '1' ); // If this page is public (can be called outside logged session)
}
if ( ! defined ( " NOSESSION " )) {
define ( " NOSESSION " , '1' );
}
require_once dirname ( __FILE__ ) . '/../../htdocs/main.inc.php' ;
require_once dirname ( __FILE__ ) . '/../../htdocs/core/lib/website.lib.php' ;
2023-02-11 14:39:16 +00:00
require_once dirname ( __FILE__ ) . '/../../htdocs/core/lib/website2.lib.php' ;
2023-03-28 18:28:57 +00:00
require_once dirname ( __FILE__ ) . '/../../htdocs/website/class/website.class.php' ;
2022-11-21 02:58:22 +00:00
if ( empty ( $user -> id )) {
print " Load permissions for admin user nb 1 \n " ;
$user -> fetch ( 1 );
2024-11-13 23:16:43 +00:00
$user -> loadRights ();
2022-11-21 02:58:22 +00:00
}
2024-12-18 14:54:48 +00:00
if ( empty ( $user -> rights -> website )) {
$user -> rights -> website = new stdClass ();
}
2024-02-19 14:28:21 +00:00
$conf -> global -> MAIN_DISABLE_ALL_MAILS = 1 ;
2022-11-21 02:58:22 +00:00
/**
* Class for PHPUnit tests
*
* @ backupGlobals disabled
* @ backupStaticAttributes enabled
* @ remarks backupGlobals must be disabled to have db , conf , user and lang not erased .
*/
2024-02-16 22:26:32 +00:00
class WebsiteTest extends CommonClassTest
2022-11-21 02:58:22 +00:00
{
/**
* testGetPagesFromSearchCriterias
*
* @ return void
*/
public function testGetPagesFromSearchCriterias ()
{
2024-02-17 16:38:10 +00:00
global $db , $website ; // We need the $website as global, it is used by the getPagesFromSearchCriterias()
2023-03-28 18:28:57 +00:00
$website = new Website ( $db ); // $website must be defined globally for getPagesFromSearchCriterias()
2022-11-21 02:58:22 +00:00
$s = " 123') OR 1=1-- \ ' xxx " ;
/*
2023-03-28 18:24:40 +00:00
var_dump ( $s );
var_dump ( $db -> escapeforlike ( $s ));
var_dump ( $db -> escape ( $db -> escapeforlike ( $s )));
*/
2022-11-21 02:58:22 +00:00
$res = getPagesFromSearchCriterias ( 'page,blogpost' , 'meta,content' , $s , 2 , 'date_creation' , 'DESC' , 'en' );
//var_dump($res);
print __METHOD__ . " message= " . $res [ 'code' ] . " \n " ;
// We must found no line (so code should be KO). If we found somethiing, it means there is a SQL injection of the 1=1
$this -> assertEquals ( $res [ 'code' ], 'KO' );
}
2023-02-11 14:39:16 +00:00
2023-03-27 15:37:09 +00:00
/**
* testDolStripPhpCode
*
* @ return void
*/
public function testDolStripPhpCode ()
{
global $db ;
$s = " abc \n <?php echo 'def' \n // comment \n ?>ghi " ;
$result = dolStripPhpCode ( $s );
$this -> assertEquals ( " abc \n <span phptag></span>ghi " , $result );
$s = " abc \n <?PHP echo 'def' \n // comment \n ?>ghi " ;
$result = dolStripPhpCode ( $s );
$this -> assertEquals ( " abc \n <span phptag></span>ghi " , $result );
}
2023-02-11 14:39:16 +00:00
/**
* testCheckPHPCode
*
* @ return void
*/
public function testCheckPHPCode ()
{
2024-12-18 18:00:33 +00:00
global $conf , $user ;
2023-02-11 14:39:16 +00:00
2026-02-09 02:18:00 +00:00
// Force allow of PHP in website from main setup
global $dolibarr_website_allow_custom_php ;
2026-06-09 16:22:31 +00:00
$dolibarr_website_allow_custom_php = 2 ; // Value 2 allow PHP code, so we can check the protections. Value 1 will allow PHP code only if exec fautres are disabled in PHP.
2026-02-09 02:18:00 +00:00
2023-02-11 14:39:16 +00:00
// Force permission so this is not the permission that will affect result of checkPHPCode
$user -> rights -> website -> writephp = 1 ;
2024-12-18 18:00:33 +00:00
// Legitimate
$t = '' ;
$s = '<?php execu ?>' ;
$result = checkPHPCode ( $t , $s );
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
$this -> assertEquals ( $result , 0 , 'checkPHPCode detect string as dangerous when it is legitimate' );
2024-12-23 13:07:08 +00:00
$t = '' ;
$s = '<?php echo $_SESSION["eee"] ?>' ;
$result = checkPHPCode ( $t , $s );
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
$this -> assertEquals ( $result , 0 , 'checkPHPCode detect string as dangerous when it is legitimate' );
2024-12-18 18:00:33 +00:00
// Dangerous
2024-04-23 18:26:24 +00:00
$t = '' ;
2023-02-11 14:39:16 +00:00
$s = '<?php exec("eee"); ?>' ;
2024-04-23 18:26:24 +00:00
$result = checkPHPCode ( $t , $s );
2023-02-11 14:39:16 +00:00
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
2024-12-18 14:54:48 +00:00
$this -> assertEquals ( $result , 1 , 'checkPHPCode did not detect the string was dangerous' );
$t = '' ;
$s = '<?php eXec ("eee"); ?>' ;
$result = checkPHPCode ( $t , $s );
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
$this -> assertEquals ( $result , 1 , 'checkPHPCode did not detect the string was dangerous' );
$t = '' ;
$s = '<?php $a="xec"; "e$a" ("ee"); ?>' ;
$result = checkPHPCode ( $t , $s );
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
2023-02-11 14:39:16 +00:00
$this -> assertEquals ( $result , 1 , 'checkPHPCode did not detect the string was dangerous' );
2024-12-18 18:00:33 +00:00
$t = '' ;
$s = '<?php $a=\'exec\'("ee"); ?>' ;
$result = checkPHPCode ( $t , $s );
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
$this -> assertEquals ( $result , 1 , 'checkPHPCode did not detect the string was dangerous' );
2024-04-23 18:26:24 +00:00
$t = '' ;
2023-02-11 14:39:16 +00:00
$s = '<?php $_="{"; $_=($_^"<").($_^">;").($_^"/"); ?><?=${\'_\'.$_}["_"](${\'_\'.$_}["__"]);?>' ;
2024-04-23 18:26:24 +00:00
$result = checkPHPCode ( $t , $s );
2023-02-11 14:39:16 +00:00
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
$this -> assertEquals ( $result , 1 , 'checkPHPCode did not detect the string was dangerous' );
2024-12-18 18:00:33 +00:00
// Dangerous but legitimate due to option WEBSITE_PHP_ALLOW_EXEC
$conf -> global -> WEBSITE_PHP_ALLOW_EXEC = 1 ;
$t = '' ;
$s = '<?php exec("eee"); ?>' ;
$result = checkPHPCode ( $t , $s );
print __METHOD__ . " result checkPHPCode= " . $result . " \n " ;
$this -> assertEquals ( $result , 0 , 'checkPHPCode did not accept the exec. it should when WEBSITE_PHP_ALLOW_EXEC is set.' );
2023-02-11 14:39:16 +00:00
}
2023-09-04 22:49:01 +00:00
/**
* testDolKeepOnlyPhpCode
*
* @ return void
*/
public function testDolKeepOnlyPhpCode ()
{
$s = 'HTML content <?php exec("eee"); ?> and more HTML content' ;
$result = dolKeepOnlyPhpCode ( $s );
print __METHOD__ . " result dolKeepOnlyPhpCode= " . $result . " \n " ;
$this -> assertEquals ( '<?php exec("eee"); ?>' , $result , 'dolKeepOnlyPhpCode did extract the correct string' );
$s = 'HTML content <? exec("eee"); ?> and more HTML content' ;
$result = dolKeepOnlyPhpCode ( $s );
print __METHOD__ . " result dolKeepOnlyPhpCode= " . $result . " \n " ;
$this -> assertEquals ( '<?php exec("eee"); ?>' , $result , 'dolKeepOnlyPhpCode did extract the correct string' );
$s = 'HTML content <?php test() <?php test2(); ?> and more HTML content' ;
$result = dolKeepOnlyPhpCode ( $s );
print __METHOD__ . " result dolKeepOnlyPhpCode= " . $result . " \n " ;
$this -> assertEquals ( '<?php test() ?><?php test2(); ?>' , $result , 'dolKeepOnlyPhpCode did extract the correct string' );
}
2024-09-13 23:36:31 +00:00
/**
* testGetImageFromHtmlContent
*
* @ return void
*/
public function testGetImageFromHtmlContent ()
{
// Example of usage
$htmlContent = '<p>Some text before.</p><img src="image1.jpg"><p>Some text in between.</p><img src="/mydir/image2.jpg"><p>Some text after.</p>' ;
$firstImage = getImageFromHtmlContent ( $htmlContent , 1 );
print __METHOD__ . " result firstImage= " . $firstImage . " \n " ;
$this -> assertEquals ( 'image1.jpg' , $firstImage , ' failed to get firstimage' );
$secondImage = getImageFromHtmlContent ( $htmlContent , 2 );
print __METHOD__ . " result secondImage= " . $secondImage . " \n " ;
$this -> assertEquals ( '/mydir/image2.jpg' , $secondImage , ' failed to get second image' );
}
2022-11-21 02:58:22 +00:00
}