Validate the UCP location and number preferences - #209
Merged
Merged
Conversation
ucp_prefs_get_data() copied rt_location, rt_viewforum_location and rt_number from the request unchecked, and ucp_prefs_set_data() saved them. Any string up to the column length and any integer could be stored; an unknown location just hid the user's own block. Keep each location within the options the UCP offers (RT_TOP, RT_BOTTOM, RT_SIDE; no side column in the forum view), falling back to the user's stored value and then the board default. Clamp the number to 1-999, and set the form's min to 1 to match. Closes #198 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #198.
Problem
ucp_prefs_get_data()copiedrt_location,rt_viewforum_locationandrt_numberfrom the request unchecked, anducp_prefs_set_data()saved them. Any string up to the column length and any integer could be stored. An unknown location just hid the user's own Recent Topics block.Fix (
event/ucp_listener.php)RT_TOP/RT_BOTTOM/RT_SIDEfor the index,RT_TOP/RT_BOTTOMfor the forum view (no side column there). Anything else falls back to the user's stored value, then the board default. This is done in a smallvalid_location()helper, with the option sets as class constants.rt_numberis clamped to 1–999.mingoes from 0 to 1, matching the server-side bound. 0 only produced an empty block.The values are checked where they're read, so both the form display and the save get clean values.
Tests
tests/event/ucp_listener_test.php, documented intests/tests.md:RT_SIDEas a forum-view location; numbers 100000, 0 and -5. All five invalid cases failed before the fix.Checked on the local board (values posted through phpBB's real request object, admin user; this only computes the would-be
sql_ary, nothing was saved):develop33savesRT_SIDE,RT_BOTTOM,20RT_SIDE,RT_BOTTOM,20RT_SIDE,RT_BOTTOM,20<script>,RT_SIDE,100000<script>,RT_SIDE,100000RT_SIDE,RT_TOP,999RT_EVIL,x,-5RT_EVIL,x,-5RT_SIDE,RT_TOP,1Not in this PR: the ACP settings for the same three values (
acp/recenttopics_module.php) are saved unvalidated too. That's admin-only input and a separate change.No changelog entry or version bump, per this repo's convention.
🤖 Generated with Claude Code