aboutsummaryrefslogtreecommitdiffstats
path: root/lib/private/AppFramework/Http
diff options
context:
space:
mode:
authorArthur Schiwon <blizzz@arthur-schiwon.de>2023-11-17 14:04:09 +0100
committerArthur Schiwon <blizzz@arthur-schiwon.de>2023-11-24 12:46:38 +0100
commit3fa43a529bbef075364666c5122e7ad18d34de62 (patch)
treea74e60d3da87fb32222dcb1176747a35eff9f368 /lib/private/AppFramework/Http
parent7646f68cd7e4dcba44a1c54258a3fe2a0cf18a36 (diff)
downloadnextcloud-server-3fa43a529bbef075364666c5122e7ad18d34de62.tar.gz
nextcloud-server-3fa43a529bbef075364666c5122e7ad18d34de62.zip
enh(dispatcher): enforce psalm ranges in the http dispatcher
- allows devs to provide int ranges for API arguments Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
Diffstat (limited to 'lib/private/AppFramework/Http')
-rw-r--r--lib/private/AppFramework/Http/Dispatcher.php22
1 files changed, 21 insertions, 1 deletions
diff --git a/lib/private/AppFramework/Http/Dispatcher.php b/lib/private/AppFramework/Http/Dispatcher.php
index 7ff7f7a9cc0..5649060ba76 100644
--- a/lib/private/AppFramework/Http/Dispatcher.php
+++ b/lib/private/AppFramework/Http/Dispatcher.php
@@ -42,6 +42,7 @@ use OCP\AppFramework\Http\Response;
use OCP\Diagnostics\IEventLogger;
use OCP\IConfig;
use OCP\IRequest;
+use OutOfRangeException;
use Psr\Container\ContainerInterface;
use Psr\Log\LoggerInterface;
@@ -197,7 +198,7 @@ class Dispatcher {
private function executeController(Controller $controller, string $methodName): Response {
$arguments = [];
- // valid types that will be casted
+ // valid types that will be cast
$types = ['int', 'integer', 'bool', 'boolean', 'float', 'double'];
foreach ($this->reflector->getParameters() as $param => $default) {
@@ -219,6 +220,7 @@ class Dispatcher {
$value = false;
} elseif ($value !== null && \in_array($type, $types, true)) {
settype($value, $type);
+ $this->ensureParameterValueSatisfiesRange($param, $value);
} elseif ($value === null && $type !== null && $this->appContainer->has($type)) {
$value = $this->appContainer->get($type);
}
@@ -250,4 +252,22 @@ class Dispatcher {
return $response;
}
+
+ /**
+ * @psalm-param mixed $value
+ * @throws OutOfRangeException
+ */
+ private function ensureParameterValueSatisfiesRange(string $param, $value): void {
+ $rangeInfo = $this->reflector->getRange($param);
+ if ($rangeInfo) {
+ if ($value < $rangeInfo['min'] || $value > $rangeInfo['max']) {
+ throw new OutOfRangeException(sprintf(
+ 'Parameter %s must be between %d and %d',
+ $param,
+ $rangeInfo['min'],
+ $rangeInfo['max'],
+ ));
+ }
+ }
+ }
}