Bug 523977: Make Bugzilla::Object->check send the trimmed value to new(), and also be more accurate about what's "empty". This also makes detaint_natural and detaint_signed call int() on their return values.

Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@258774 18797224-902f-48f8-a5cc-f745e15eee43
This commit is contained in:
mkanat%bugzilla.org 2009-10-24 05:26:35 +00:00
parent 3945837e05
commit 17aaca86e7
2 changed files with 13 additions and 9 deletions

View File

@ -117,10 +117,17 @@ sub check {
if (!ref $param) {
$param = { name => $param };
}
# Don't allow empty names or ids.
my $check_param = exists $param->{id} ? $param->{id} : $param->{name};
$check_param = trim($check_param);
$check_param || ThrowUserError('object_not_specified', { class => $class });
my $check_param = exists $param->{id} ? 'id' : 'name';
$param->{$check_param} = trim($param->{$check_param});
# If somebody passes us "0", we want to throw an error like
# "there is no X with the name 0". This is true even for ids. So here,
# we only check if the parameter is undefined or empty.
if (!defined $param->{$check_param} or $param->{$check_param} eq '') {
ThrowUserError('object_not_specified', { class => $class });
}
my $obj = $class->new($param);
if (!$obj) {
# We don't want to override the normal template "user" object if

View File

@ -68,17 +68,14 @@ sub trick_taint {
sub detaint_natural {
my $match = $_[0] =~ /^(\d+)$/;
$_[0] = $match ? $1 : undef;
$_[0] = $match ? int($1) : undef;
return (defined($_[0]));
}
sub detaint_signed {
my $match = $_[0] =~ /^([-+]?\d+)$/;
$_[0] = $match ? $1 : undef;
# Remove any leading plus sign.
if (defined($_[0]) && $_[0] =~ /^\+(\d+)$/) {
$_[0] = $1;
}
# The "int()" call removes any leading plus sign.
$_[0] = $match ? int($1) : undef;
return (defined($_[0]));
}