diff options
author | Johannes Koenig <mail@jokoenig.de> | 2019-10-06 20:43:55 +0200 |
---|---|---|
committer | Johannes Koenig <mail@jokoenig.de> | 2019-10-06 20:43:55 +0200 |
commit | 2df8d646c1c1375a1758ea3a16551643e4b1e92f (patch) | |
tree | 28909ecd8c401e75d24e61c50080ac797579e646 | |
parent | 1843ff60fd65b3ea8496ad991d8e905d76222cdf (diff) | |
download | nextcloud-server-2df8d646c1c1375a1758ea3a16551643e4b1e92f.tar.gz nextcloud-server-2df8d646c1c1375a1758ea3a16551643e4b1e92f.zip |
make TrustedDomainHelper case insensitive
Signed-off-by: Johannes Koenig <mail@jokoenig.de>
-rw-r--r-- | lib/private/Security/TrustedDomainHelper.php | 2 | ||||
-rw-r--r-- | tests/lib/Security/TrustedDomainHelperTest.php | 5 |
2 files changed, 6 insertions, 1 deletions
diff --git a/lib/private/Security/TrustedDomainHelper.php b/lib/private/Security/TrustedDomainHelper.php index 5237767d8ea..22a75158294 100644 --- a/lib/private/Security/TrustedDomainHelper.php +++ b/lib/private/Security/TrustedDomainHelper.php @@ -90,7 +90,7 @@ class TrustedDomainHelper { if (gettype($trusted) !== 'string') { break; } - $regex = '/^' . implode('[-\.a-zA-Z0-9]*', array_map(function($v) { return preg_quote($v, '/'); }, explode('*', $trusted))) . '$/'; + $regex = '/^' . implode('[-\.a-zA-Z0-9]*', array_map(function($v) { return preg_quote($v, '/'); }, explode('*', $trusted))) . '$/i'; if (preg_match($regex, $domain) || preg_match($regex, $domainWithPort)) { return true; } diff --git a/tests/lib/Security/TrustedDomainHelperTest.php b/tests/lib/Security/TrustedDomainHelperTest.php index 25586a1bc27..86420e22c21 100644 --- a/tests/lib/Security/TrustedDomainHelperTest.php +++ b/tests/lib/Security/TrustedDomainHelperTest.php @@ -54,6 +54,8 @@ class TrustedDomainHelperTest extends \Test\TestCase { 'cen*ter', '*.leadingwith.port:123', 'trailingwith.port*:456', + 'UPPERCASE.DOMAIN', + 'lowercase.domain', ]; return [ // empty defaults to false with 8.1 @@ -106,6 +108,9 @@ class TrustedDomainHelperTest extends \Test\TestCase { [$trustedHostTestList, '-bad', false], [$trustedHostTestList, '-bad.leading.host', false], [$trustedHostTestList, 'bad..der.leading.host', false], + // case sensitivity + [$trustedHostTestList, 'uppercase.domain', true], + [$trustedHostTestList, 'LOWERCASE.DOMAIN', true], ]; } } |