comparison vendor/psy/psysh/src/CodeCleaner/InstanceOfPass.php @ 13:5fb285c0d0e3

Update Drupal core to 8.4.7 via Composer. Security update; I *think* we've been lucky to get away with this so far, as we don't support self-registration which seems to be used by the so-called "drupalgeddon 2" attack that 8.4.5 was vulnerable to.
author Chris Cannam
date Mon, 23 Apr 2018 09:33:26 +0100
parents
children
comparison
equal deleted inserted replaced
12:7a779792577d 13:5fb285c0d0e3
1 <?php
2
3 /*
4 * This file is part of Psy Shell.
5 *
6 * (c) 2012-2018 Justin Hileman
7 *
8 * For the full copyright and license information, please view the LICENSE
9 * file that was distributed with this source code.
10 */
11
12 namespace Psy\CodeCleaner;
13
14 use PhpParser\Node;
15 use PhpParser\Node\Expr\ConstFetch;
16 use PhpParser\Node\Expr\Instanceof_;
17 use PhpParser\Node\Scalar;
18 use PhpParser\Node\Scalar\Encapsed;
19 use Psy\Exception\FatalErrorException;
20
21 /**
22 * Validate that the instanceof statement does not receive a scalar value or a non-class constant.
23 *
24 * @author Martin HasoĊˆ <martin.hason@gmail.com>
25 */
26 class InstanceOfPass extends CodeCleanerPass
27 {
28 const EXCEPTION_MSG = 'instanceof expects an object instance, constant given';
29
30 /**
31 * Validate that the instanceof statement does not receive a scalar value or a non-class constant.
32 *
33 * @throws FatalErrorException if a scalar or a non-class constant is given
34 *
35 * @param Node $node
36 */
37 public function enterNode(Node $node)
38 {
39 if (!$node instanceof Instanceof_) {
40 return;
41 }
42
43 if (($node->expr instanceof Scalar && !$node->expr instanceof Encapsed) || $node->expr instanceof ConstFetch) {
44 throw new FatalErrorException(self::EXCEPTION_MSG, 0, E_ERROR, null, $node->getLine());
45 }
46 }
47 }