2019-11-27 06:25:33 +01:00
|
|
|
<?php
|
|
|
|
|
2020-01-17 18:19:25 +01:00
|
|
|
/*
|
|
|
|
* This file is part of RaspiSMS.
|
|
|
|
*
|
|
|
|
* (c) Pierre-Lin Bonnemaison <plebwebsas@gmail.com>
|
|
|
|
*
|
|
|
|
* This source file is subject to the GPL-3.0 license that is bundled
|
|
|
|
* with this source code in the file LICENSE.
|
|
|
|
*/
|
|
|
|
|
2019-11-27 06:25:33 +01:00
|
|
|
namespace controllers\internals;
|
|
|
|
|
|
|
|
use Symfony\Component\ExpressionLanguage\ExpressionFunction;
|
|
|
|
use Symfony\Component\ExpressionLanguage\ExpressionFunctionProviderInterface;
|
|
|
|
|
|
|
|
class ExpressionProvider implements ExpressionFunctionProviderInterface
|
|
|
|
{
|
|
|
|
public function getFunctions()
|
|
|
|
{
|
2020-04-03 21:22:13 +02:00
|
|
|
//Override default constant() function to make it return null
|
|
|
|
//This will prevent the use of constant() func to read constants with security impact (such as session, db credentials, etc.)
|
|
|
|
$neutralized_constant = new ExpressionFunction('constant', function ($str) {
|
|
|
|
return null;
|
|
|
|
}, function ($arguments, $str) {
|
|
|
|
return null;
|
|
|
|
});
|
|
|
|
|
|
|
|
|
2019-11-27 06:25:33 +01:00
|
|
|
return [
|
2020-04-03 21:22:13 +02:00
|
|
|
$neutralized_constant,
|
2019-11-27 06:25:33 +01:00
|
|
|
ExpressionFunction::fromPhp('is_null', 'exists'),
|
|
|
|
ExpressionFunction::fromPhp('mb_strtolower', 'lower'),
|
|
|
|
ExpressionFunction::fromPhp('mb_strtoupper', 'upper'),
|
|
|
|
ExpressionFunction::fromPhp('mb_substr', 'substr'),
|
2020-06-10 01:30:14 +02:00
|
|
|
ExpressionFunction::fromPhp('mb_strlen', 'strlen'),
|
2019-11-27 06:25:33 +01:00
|
|
|
ExpressionFunction::fromPhp('abs', 'abs'),
|
|
|
|
ExpressionFunction::fromPhp('strtotime', 'date'),
|
|
|
|
];
|
|
|
|
}
|
|
|
|
}
|