Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 12 additions & 1 deletion event/main_listener.php
Original file line number Diff line number Diff line change
Expand Up @@ -355,11 +355,17 @@ public function acp_manage_forums_update_data_after($event)
// MCP
public function mcp_forum_view_before($event)
{
$attr_id = (int) $this->request->variable('attr_id', 0);
add_form_key('qte_mcp_attr_apply', '_QTE');
$attr_id = (int) $this->request->variable('attr_id', 0, false, \phpbb\request\request_interface::POST);
$forum_id = (int) $event['forum_info']['forum_id'];

if ($attr_id)
{
if (!check_form_key('qte_mcp_attr_apply'))
{
trigger_error($this->language->lang('FORM_INVALID'));
}

$this->qte->mcp_attr_apply($attr_id, $forum_id, $event['topic_id_list']);
}

Expand Down Expand Up @@ -635,6 +641,11 @@ public function viewtopic_add_quickmod_option_before($event)

if ($attr_id)
{
if (!check_link_hash($this->request->variable('hash', ''), 'qte_attr_apply'))
{
return;
}

$this->qte->get_users_by_user_id($this->user->data['user_id']);
$this->qte->attr_apply($attr_id, $event['topic_id'], $event['forum_id'], $event['topic_data']['topic_attr_id'], $event['topic_data']['topic_poster'], $event['viewtopic_url']);
}
Expand Down
4 changes: 2 additions & 2 deletions qte.php
Original file line number Diff line number Diff line change
Expand Up @@ -181,7 +181,7 @@ public function attr_select($forum_id, $author_id = 0, $attribute_id = 0, $viewt
'S_SELECTED' => (!empty($attribute_id) && ($attr['attr_id'] == $attribute_id)) ? true : false,
'S_QTE_DESC' => !empty($attr['attr_desc']) ? true : false,

'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => $attr['attr_id']]) : false,
'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => $attr['attr_id'], 'hash' => generate_link_hash('qte_attr_apply')]) : false,
]);
}
}
Expand All @@ -193,7 +193,7 @@ public function attr_select($forum_id, $author_id = 0, $attribute_id = 0, $viewt
'S_QTE_SELECTED' => ($s_delete && ($attribute_id == self::DELETE)) ? true : false,
'S_QTE_KEEP' => !empty($attribute_id) && ($attribute_id == self::KEEP) ? true : false,

'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => self::DELETE]) : false,
'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => self::DELETE, 'hash' => generate_link_hash('qte_attr_apply')]) : false,
]);
}

Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
{% if S_QTE_SELECT %}
{{ S_FORM_TOKEN_QTE }}
<fieldset class="display-actions">
<select name="attr_id" id="attribute">
<option style="padding-left: 0px; font-weight: bold;" value="0">{{ lang('QTE_ATTRIBUTE_SELECT') }}</option>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,4 +19,4 @@
</ul>
</div>
</div>
{% endif %}
{% endif %}
54 changes: 54 additions & 0 deletions tests/unit/event/main_listener_test.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
<?php
/**
*
* Quick Title Edition extension for the phpBB Forum Software package.
*
* @copyright (c) 2023, Kailey Snay, https://www.snayhomelab.com/
* @license GNU General Public License, version 2 (GPL-2.0)
*
*/

namespace kaileymsnay\qte\tests\unit\event;

class main_listener_test extends \phpbb_test_case
{
public function test_viewtopic_get_attribute_without_valid_hash_is_ignored()
{
global $user;
$previous_user = $user ?? null;
$user = new \stdClass();
$user->data = ['user_form_salt' => 'test-salt'];

$request = $this->createMock('\phpbb\request\request');
$request->expects($this->exactly(2))
->method('variable')
->willReturnCallback(function($name, $default) {
return $name === 'attr_id' ? 1 : 'invalid-hash';
});

$qte = $this->createMock('\kaileymsnay\qte\qte');
$qte->expects($this->never())->method('attr_apply');

$listener = new \kaileymsnay\qte\event\main_listener(
$this->createMock('\phpbb\cache\driver\driver_interface'),
$this->createMock('\phpbb\db\driver\driver_interface'),
$this->createMock('\phpbb\language\language'),
$this->createMock('\phpbb\log\log'),
$request,
$this->createMock('\phpbb\template\template'),
$this->createMock('\phpbb\user'),
'phpbb_',
$qte,
$this->createMock('\kaileymsnay\qte\search\fulltext_attribute')
);

try
{
$listener->viewtopic_add_quickmod_option_before(new \phpbb\event\data([]));
}
finally
{
$user = $previous_user;
}
}
}
Loading