Mercurial > hg > isophonics-drupal-site
comparison vendor/psy/psysh/src/CodeCleaner/ValidFunctionNamePass.php @ 13:5fb285c0d0e3
Update Drupal core to 8.4.7 via Composer. Security update; I *think* we've
been lucky to get away with this so far, as we don't support self-registration
which seems to be used by the so-called "drupalgeddon 2" attack that 8.4.5
was vulnerable to.
author | Chris Cannam |
---|---|
date | Mon, 23 Apr 2018 09:33:26 +0100 |
parents | |
children | 129ea1e6d783 |
comparison
equal
deleted
inserted
replaced
12:7a779792577d | 13:5fb285c0d0e3 |
---|---|
1 <?php | |
2 | |
3 /* | |
4 * This file is part of Psy Shell. | |
5 * | |
6 * (c) 2012-2018 Justin Hileman | |
7 * | |
8 * For the full copyright and license information, please view the LICENSE | |
9 * file that was distributed with this source code. | |
10 */ | |
11 | |
12 namespace Psy\CodeCleaner; | |
13 | |
14 use PhpParser\Node; | |
15 use PhpParser\Node\Expr; | |
16 use PhpParser\Node\Expr\FuncCall; | |
17 use PhpParser\Node\Expr\Variable; | |
18 use PhpParser\Node\Stmt\Do_; | |
19 use PhpParser\Node\Stmt\Function_; | |
20 use PhpParser\Node\Stmt\If_; | |
21 use PhpParser\Node\Stmt\Switch_; | |
22 use PhpParser\Node\Stmt\While_; | |
23 use Psy\Exception\FatalErrorException; | |
24 | |
25 /** | |
26 * Validate that function calls will succeed. | |
27 * | |
28 * This pass throws a FatalErrorException rather than letting PHP run | |
29 * headfirst into a real fatal error and die. | |
30 */ | |
31 class ValidFunctionNamePass extends NamespaceAwarePass | |
32 { | |
33 private $conditionalScopes = 0; | |
34 | |
35 /** | |
36 * Store newly defined function names on the way in, to allow recursion. | |
37 * | |
38 * @param Node $node | |
39 */ | |
40 public function enterNode(Node $node) | |
41 { | |
42 parent::enterNode($node); | |
43 | |
44 if (self::isConditional($node)) { | |
45 $this->conditionalScopes++; | |
46 } elseif ($node instanceof Function_) { | |
47 $name = $this->getFullyQualifiedName($node->name); | |
48 | |
49 // @todo add an "else" here which adds a runtime check for instances where we can't tell | |
50 // whether a function is being redefined by static analysis alone. | |
51 if ($this->conditionalScopes === 0) { | |
52 if (function_exists($name) || | |
53 isset($this->currentScope[strtolower($name)])) { | |
54 $msg = sprintf('Cannot redeclare %s()', $name); | |
55 throw new FatalErrorException($msg, 0, E_ERROR, null, $node->getLine()); | |
56 } | |
57 } | |
58 | |
59 $this->currentScope[strtolower($name)] = true; | |
60 } | |
61 } | |
62 | |
63 /** | |
64 * Validate that function calls will succeed. | |
65 * | |
66 * @throws FatalErrorException if a function is redefined | |
67 * @throws FatalErrorException if the function name is a string (not an expression) and is not defined | |
68 * | |
69 * @param Node $node | |
70 */ | |
71 public function leaveNode(Node $node) | |
72 { | |
73 if (self::isConditional($node)) { | |
74 $this->conditionalScopes--; | |
75 } elseif ($node instanceof FuncCall) { | |
76 // if function name is an expression or a variable, give it a pass for now. | |
77 $name = $node->name; | |
78 if (!$name instanceof Expr && !$name instanceof Variable) { | |
79 $shortName = implode('\\', $name->parts); | |
80 $fullName = $this->getFullyQualifiedName($name); | |
81 $inScope = isset($this->currentScope[strtolower($fullName)]); | |
82 if (!$inScope && !function_exists($shortName) && !function_exists($fullName)) { | |
83 $message = sprintf('Call to undefined function %s()', $name); | |
84 throw new FatalErrorException($message, 0, E_ERROR, null, $node->getLine()); | |
85 } | |
86 } | |
87 } | |
88 } | |
89 | |
90 private static function isConditional(Node $node) | |
91 { | |
92 return $node instanceof If_ || | |
93 $node instanceof While_ || | |
94 $node instanceof Do_ || | |
95 $node instanceof Switch_; | |
96 } | |
97 } |