feat: add XSS protection by implementing form data filtering

This commit is contained in:
Björn Fromme
2023-11-13 17:46:56 +01:00
parent 654648e934
commit f04d90af6f
19 changed files with 324 additions and 13 deletions
+3 -2
View File
@@ -64,7 +64,8 @@
"twig/html-extra": "^3.7",
"twig/intl-extra": "^3.7",
"twig/string-extra": "^3.7",
"twig/twig": "^2.12|^3.0"
"twig/twig": "^2.12|^3.0",
"voku/anti-xss": "^4.1"
},
"config": {
"allow-plugins": {
@@ -127,4 +128,4 @@
"symfony/web-profiler-bundle": "6.3.*"
},
"version": "0.1.0"
}
}
Generated
+261 -1
View File
@@ -4,7 +4,7 @@
"Read more about it at https://getcomposer.org/doc/01-basic-usage.md#installing-dependencies",
"This file is @generated automatically"
],
"content-hash": "df338b352545df0665c61f700f265651",
"content-hash": "807c60574ab0d809d424a5782a0f5806",
"packages": [
{
"name": "beberlei/doctrineextensions",
@@ -9019,6 +9019,266 @@
},
"time": "2020-10-02T23:36:20+00:00"
},
{
"name": "voku/anti-xss",
"version": "4.1.42",
"source": {
"type": "git",
"url": "https://github.com/voku/anti-xss.git",
"reference": "bca1f8607e55a3c5077483615cd93bd8f11bd675"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/voku/anti-xss/zipball/bca1f8607e55a3c5077483615cd93bd8f11bd675",
"reference": "bca1f8607e55a3c5077483615cd93bd8f11bd675",
"shasum": ""
},
"require": {
"php": ">=7.0.0",
"voku/portable-utf8": "~6.0.2"
},
"require-dev": {
"phpunit/phpunit": "~6.0 || ~7.0 || ~9.0"
},
"type": "library",
"extra": {
"branch-alias": {
"dev-master": "4.1.x-dev"
}
},
"autoload": {
"psr-4": {
"voku\\helper\\": "src/voku/helper/"
}
},
"notification-url": "https://packagist.org/downloads/",
"license": [
"MIT"
],
"authors": [
{
"name": "EllisLab Dev Team",
"homepage": "http://ellislab.com/"
},
{
"name": "Lars Moelleken",
"email": "[email protected]",
"homepage": "https://www.moelleken.org/"
}
],
"description": "anti xss-library",
"homepage": "https://github.com/voku/anti-xss",
"keywords": [
"anti-xss",
"clean",
"security",
"xss"
],
"support": {
"issues": "https://github.com/voku/anti-xss/issues",
"source": "https://github.com/voku/anti-xss/tree/4.1.42"
},
"funding": [
{
"url": "https://www.paypal.me/moelleken",
"type": "custom"
},
{
"url": "https://github.com/voku",
"type": "github"
},
{
"url": "https://opencollective.com/anti-xss",
"type": "open_collective"
},
{
"url": "https://www.patreon.com/voku",
"type": "patreon"
},
{
"url": "https://tidelift.com/funding/github/packagist/voku/anti-xss",
"type": "tidelift"
}
],
"time": "2023-07-03T14:40:46+00:00"
},
{
"name": "voku/portable-ascii",
"version": "2.0.1",
"source": {
"type": "git",
"url": "https://github.com/voku/portable-ascii.git",
"reference": "b56450eed252f6801410d810c8e1727224ae0743"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/voku/portable-ascii/zipball/b56450eed252f6801410d810c8e1727224ae0743",
"reference": "b56450eed252f6801410d810c8e1727224ae0743",
"shasum": ""
},
"require": {
"php": ">=7.0.0"
},
"require-dev": {
"phpunit/phpunit": "~6.0 || ~7.0 || ~9.0"
},
"suggest": {
"ext-intl": "Use Intl for transliterator_transliterate() support"
},
"type": "library",
"autoload": {
"psr-4": {
"voku\\": "src/voku/"
}
},
"notification-url": "https://packagist.org/downloads/",
"license": [
"MIT"
],
"authors": [
{
"name": "Lars Moelleken",
"homepage": "http://www.moelleken.org/"
}
],
"description": "Portable ASCII library - performance optimized (ascii) string functions for php.",
"homepage": "https://github.com/voku/portable-ascii",
"keywords": [
"ascii",
"clean",
"php"
],
"support": {
"issues": "https://github.com/voku/portable-ascii/issues",
"source": "https://github.com/voku/portable-ascii/tree/2.0.1"
},
"funding": [
{
"url": "https://www.paypal.me/moelleken",
"type": "custom"
},
{
"url": "https://github.com/voku",
"type": "github"
},
{
"url": "https://opencollective.com/portable-ascii",
"type": "open_collective"
},
{
"url": "https://www.patreon.com/voku",
"type": "patreon"
},
{
"url": "https://tidelift.com/funding/github/packagist/voku/portable-ascii",
"type": "tidelift"
}
],
"time": "2022-03-08T17:03:00+00:00"
},
{
"name": "voku/portable-utf8",
"version": "6.0.13",
"source": {
"type": "git",
"url": "https://github.com/voku/portable-utf8.git",
"reference": "b8ce36bf26593e5c2e81b1850ef0ffb299d2043f"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/voku/portable-utf8/zipball/b8ce36bf26593e5c2e81b1850ef0ffb299d2043f",
"reference": "b8ce36bf26593e5c2e81b1850ef0ffb299d2043f",
"shasum": ""
},
"require": {
"php": ">=7.0.0",
"symfony/polyfill-iconv": "~1.0",
"symfony/polyfill-intl-grapheme": "~1.0",
"symfony/polyfill-intl-normalizer": "~1.0",
"symfony/polyfill-mbstring": "~1.0",
"symfony/polyfill-php72": "~1.0",
"voku/portable-ascii": "~2.0.0"
},
"require-dev": {
"phpstan/phpstan": "1.9.*@dev",
"phpstan/phpstan-strict-rules": "1.4.*@dev",
"phpunit/phpunit": "~6.0 || ~7.0 || ~9.0",
"thecodingmachine/phpstan-strict-rules": "1.0.*@dev",
"voku/phpstan-rules": "3.1.*@dev"
},
"suggest": {
"ext-ctype": "Use Ctype for e.g. hexadecimal digit detection",
"ext-fileinfo": "Use Fileinfo for better binary file detection",
"ext-iconv": "Use iconv for best performance",
"ext-intl": "Use Intl for best performance",
"ext-json": "Use JSON for string detection",
"ext-mbstring": "Use Mbstring for best performance"
},
"type": "library",
"autoload": {
"files": [
"bootstrap.php"
],
"psr-4": {
"voku\\": "src/voku/"
}
},
"notification-url": "https://packagist.org/downloads/",
"license": [
"(Apache-2.0 or GPL-2.0)"
],
"authors": [
{
"name": "Nicolas Grekas",
"email": "[email protected]"
},
{
"name": "Hamid Sarfraz",
"homepage": "http://pageconfig.com/"
},
{
"name": "Lars Moelleken",
"homepage": "http://www.moelleken.org/"
}
],
"description": "Portable UTF-8 library - performance optimized (unicode) string functions for php.",
"homepage": "https://github.com/voku/portable-utf8",
"keywords": [
"UTF",
"clean",
"php",
"unicode",
"utf-8",
"utf8"
],
"support": {
"issues": "https://github.com/voku/portable-utf8/issues",
"source": "https://github.com/voku/portable-utf8/tree/6.0.13"
},
"funding": [
{
"url": "https://www.paypal.me/moelleken",
"type": "custom"
},
{
"url": "https://github.com/voku",
"type": "github"
},
{
"url": "https://opencollective.com/portable-utf8",
"type": "open_collective"
},
{
"url": "https://www.patreon.com/voku",
"type": "patreon"
},
{
"url": "https://tidelift.com/funding/github/packagist/voku/portable-utf8",
"type": "tidelift"
}
],
"time": "2023-03-08T08:35:38+00:00"
},
{
"name": "webmozart/assert",
"version": "1.11.0",
+1
View File
@@ -33,6 +33,7 @@ class AddressType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Address::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -41,6 +41,7 @@ class ApplicationStatusType extends AbstractType
{
$resolver->setDefaults([
'data_class' => ApplicationStatusDto::class,
'anti_xss' => true,
]);
}
}
+1 -8
View File
@@ -12,7 +12,6 @@ use Doctrine\ORM\EntityRepository;
use Symfony\Bridge\Doctrine\Form\Type\EntityType;
use Symfony\Component\Form\AbstractType;
use Symfony\Component\Form\Extension\Core\Type\CheckboxType;
use Symfony\Component\Form\Extension\Core\Type\ChoiceType;
use Symfony\Component\Form\Extension\Core\Type\CollectionType;
use Symfony\Component\Form\Extension\Core\Type\IntegerType;
use Symfony\Component\Form\Extension\Core\Type\TextareaType;
@@ -24,13 +23,6 @@ class AssignmentType extends AbstractType
public function buildForm(FormBuilderInterface $builder, array $options): void
{
$builder
->add('status', ChoiceType::class, [
'label' => 'Status',
'choices' => [
'offen' => Assignment::STATUS_OPEN,
'geschlossen' => Assignment::STATUS_CLOSED,
],
])
->add('availableDispositions', IntegerType::class, [
'label' => 'zu vergeben',
'required' => false,
@@ -144,6 +136,7 @@ class AssignmentType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Assignment::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -32,6 +32,7 @@ class AvailabilityType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Availability::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -32,6 +32,7 @@ class BankAccountType extends AbstractType
{
$resolver->setDefaults([
'data_class' => BankAccount::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -30,6 +30,7 @@ class CommunicationType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Communication::class,
'anti_xss' => true,
]);
}
}
+2 -1
View File
@@ -33,7 +33,8 @@ class ContactType extends AbstractType
{
$resolver
->setDefaults([
'data_class' => Contact::class,
'data_class' => Contact::class,
'anti_xss' => true,
])
->setRequired(['upload_session'])
->setAllowedTypes('upload_session', UploadSessionDto::class)
+1
View File
@@ -46,6 +46,7 @@ class DocumentCheckType extends AbstractType
'abgelehnt' => Upload::STATUS_REJECTED,
],
],
'anti_xss' => true,
])
->setRequired(['document_type'])
->setAllowedTypes('document_type', 'string')
+42
View File
@@ -0,0 +1,42 @@
<?php
namespace App\Form\Extension;
use Symfony\Component\Form\AbstractTypeExtension;
use Symfony\Component\Form\Extension\Core\Type\FormType;
use Symfony\Component\Form\FormBuilderInterface;
use Symfony\Component\Form\FormEvent;
use Symfony\Component\Form\FormEvents;
use Symfony\Component\OptionsResolver\OptionsResolver;
use voku\helper\AntiXSS;
class AntiXssExtension extends AbstractTypeExtension
{
public function buildForm(FormBuilderInterface $builder, array $options): void
{
parent::buildForm($builder, $options);
if (true === $options['anti_xss']) {
$builder->addEventListener(FormEvents::PRE_SUBMIT, function (FormEvent $event) {
$data = $event->getData();
$antiXss = new AntiXSS();
foreach ($data as $key => $value) {
$data[$key] = $antiXss->xss_clean($value);
}
$event->setData($data);
});
}
}
public function configureOptions(OptionsResolver $resolver): void
{
$resolver->setDefaults([
'anti_xss' => false,
]);
}
public static function getExtendedTypes(): iterable
{
return [FormType::class];
}
}
+1
View File
@@ -28,6 +28,7 @@ class FaqType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Faq::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -32,6 +32,7 @@ class FeeType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Fee::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -41,6 +41,7 @@ class FeedbackType extends AbstractType
$resolver
->setDefaults([
'data_class' => Feedback::class,
'anti_xss' => true,
])
->setRequired(['feedback_set'])
->setAllowedTypes('feedback_set', FeedbackSet::class)
+2 -1
View File
@@ -50,7 +50,7 @@ class JobProfileType extends AbstractType
'label' => 'Feedback-Vorlage',
'class' => FeedbackSet::class,
'choice_label' => 'name',
'placeholder' => '',
'placeholder' => 'Kein Feedback',
])
;
}
@@ -59,6 +59,7 @@ class JobProfileType extends AbstractType
{
$resolver->setDefaults([
'data_class' => JobProfile::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -61,6 +61,7 @@ class TeamerApplicationType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Application::class,
'anti_xss' => true,
]);
}
}
+1
View File
@@ -80,6 +80,7 @@ class TeamerJobProfileType extends AbstractType
'data_class' => Teamer::class,
'job_profiles' => [],
'selectable_job_profiles' => [],
'anti_xss' => true,
]);
}
}
+1
View File
@@ -113,6 +113,7 @@ class TeamerProfileType extends AbstractType
'validation_groups' => [
'profile',
],
'anti_xss' => true,
])
->setRequired(['upload_session'])
->setAllowedTypes('upload_session', UploadSessionDto::class)
+1
View File
@@ -23,6 +23,7 @@ class TrainingType extends AbstractType
{
$resolver->setDefaults([
'data_class' => Training::class,
'anti_xss' => true,
]);
}
}