Skip to content

Commit

Permalink
Merge branch '5.4' into 6.0
Browse files Browse the repository at this point in the history
* 5.4:
  [Console] Fixes "Incorrectly nested style tag found" error when using multi-line header content
  Fix LDAP connection options
  fix probably undefined variable $expireAt
  Fix aliases handling in command name completion
  Fix division by zero
  Allow ErrorHandler ^5.0 to be used in HttpKernel
  [Security/Http] Ignore invalid URLs found in failure/success paths
  Fix typo
  • Loading branch information
nicolas-grekas committed May 14, 2022
2 parents fcf01e5 + ac64013 commit 5a48bfb
Show file tree
Hide file tree
Showing 2 changed files with 23 additions and 0 deletions.
3 changes: 3 additions & 0 deletions CsrfTokenManager.php
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,9 @@ private function derandomize(string $value): string
return $value;
}
$key = base64_decode(strtr($parts[1], '-_', '+/'));
if ('' === $key || false === $key) {
return $value;
}
$value = base64_decode(strtr($parts[2], '-_', '+/'));

return $this->xor($value, $key);
Expand Down
20 changes: 20 additions & 0 deletions Tests/CsrfTokenManagerTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -193,6 +193,26 @@ public function testNonExistingTokenIsNotValid($namespace, $manager, $storage)
$this->assertFalse($manager->isTokenValid(new CsrfToken('token_id', 'FOOBAR')));
}

public function testTokenShouldNotTriggerDivisionByZero()
{
[$generator, $storage] = $this->getGeneratorAndStorage();
$manager = new CsrfTokenManager($generator, $storage);

// Scenario: the token that was returned is abc.def.ghi, and gets modified in the browser to abc..ghi

$storage->expects($this->once())
->method('hasToken')
->with('https-token_id')
->willReturn(true);

$storage->expects($this->once())
->method('getToken')
->with('https-token_id')
->willReturn('def');

$this->assertFalse($manager->isTokenValid(new CsrfToken('token_id', 'abc..ghi')));
}

/**
* @dataProvider getManagerGeneratorAndStorage
*/
Expand Down

0 comments on commit 5a48bfb

Please sign in to comment.