Zen Cart Logo
Forums / Bug Reports / [Done v155a and v155b] AdminRequestSanitizer Problem

[Done v155a and v155b] AdminRequestSanitizer Problem

Views: 19,680

Results 1 to 16 of 16
31 May 2016, 2:22 AM
#1
jrgoold avatar

jrgoold

New Zenner

Join Date:
May 2016
Location:
St. John's NL Canada
Posts:
32
Plugin Contributions:
0

[Done v155a and v155b] AdminRequestSanitizer Problem

Problem is occurring with ZC 1.5.4 and 1.5.5a (skipped 1.5.5).
The base Zen Cart is heavily modified; however, this problem is only showing up for one aspect: Reviews. Specifically, my version of .../admin/includes/backend/reviews.php (NB my admin directory is called backend).

The error log shows:

[30-May-2016 21:33:39 America/Detroit] Request URI: /backend/reviews.php?page=16&rID=498&action=preview, IP address: 47.55.233.182
#1  AdminRequestSanitizer->filterProductNameDeepRegex()
#2  call_user_func() called at [/home/amistad/public_html/backend/includes/classes/AdminRequestSanitizer.php:290]
#3  AdminRequestSanitizer->processBuiltIn() called at [/home/amistad/public_html/backend/includes/classes/AdminRequestSanitizer.php:201]
#4  AdminRequestSanitizer->runSpecificSanitizer() called at [/home/amistad/public_html/backend/includes/classes/AdminRequestSanitizer.php:180]
#5  AdminRequestSanitizer->runSanitizers() called at [/home/amistad/public_html/backend/includes/init_includes/init_sanitize.php:232]
#6  require(/home/amistad/public_html/backend/includes/init_includes/init_sanitize.php) called at [/home/amistad/public_html/includes/autoload_func.php:48]
#7  require(/home/amistad/public_html/includes/autoload_func.php) called at [/home/amistad/public_html/backend/includes/application_top.php:171]
#8  require_once(/home/amistad/public_html/backend/includes/application_top.php) called at [/home/amistad/public_html/backend/reviews.php:37]

[30-May-2016 21:33:39 America/Detroit] PHP Warning:  Invalid argument supplied for foreach() in /home/amistad/public_html/backend/includes/classes/AdminRequestSanitizer.php on line 565

Server information (screen-shot) is attached. Oh, this is the test site (1.5.5a) the live site is on 1.5.4.

Despite this, the code does do what it is supposed to do. It supports creating reviews and editing reviews. An additional "status" (numeric) is supported and an additional column for reviews (review_type).

I am not sure how to determine which field is causing the problem. Suggestions as to how to track this down would be appreciated. Currently I'm going to continue with other testing (and perhaps turn of sanitizing while doing that testing, to avoid sifting through the logs for other problems).

JRG

31 May 2016, 8:06 AM
#3
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,097
Plugin Contributions:
56

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Does your reviews.php, by chance, make use of an array of $_POST variables? What are the names of the $_POST variables that the plugin uses?

31 May 2016, 2:53 PM
#4
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,883
Plugin Contributions:
3

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Hi all

This is in fact a problem with core code, and not really related to any plugins.

The reviews code passes a 'products_name' hidden field which in this context is a string.
However in general 'products_name' is expected to be an array (e.g. to account for language translations)
Hence the sanitizer complaining it's not an array.

Will push a fix up shortly

31 May 2016, 2:57 PM
#5
jrgoold avatar

jrgoold

New Zenner

Join Date:
May 2016
Location:
St. John's NL Canada
Posts:
32
Plugin Contributions:
0

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

kobra:

Maybe this would assist??

https://www.zen-cart.com/showthread.php?219732-Trustwave-Security-report-Patch-Included-TWSL2016-006

I found your referenced thread after I had posted. The documentation link it has (http://docs.zen-cart.com/Developer_Documentation/v1.5.5/code_docs/admin_sanitization) is particularly helpful as it is the only real documentation I've been able to find on “admin sanitizing”.

Thanks for trying to help — appreciated. More in my reply to the next response.

31 May 2016, 3:24 PM
#6
jrgoold avatar

jrgoold

New Zenner

Join Date:
May 2016
Location:
St. John's NL Canada
Posts:
32
Plugin Contributions:
0

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Hello Wilt,

I discovered the Admin Sanitizer documentation http://docs.zen-cart.com/Developer_Documentation/v1.5.5/code_docs/admin_sanitization. That allowed me to turn on sanitizer debugging messages. I matched the date-time stamp of one of the error logs to one for a debug message.

You undoubtedly have found the real problem. I did notice, however, that in the debug message, the admin sanitizer has changed the value of the "type_name" variable (stripping out spaces and a slash — but leaving a dash). This can be seen in the posted sanitizer debug message.

This is only a problem because I display the type_name. I created additional product types as the subject site deals exclusively in downloadable products: e-books and software (which can be thought of as “interactive e-books”). I am going to resolve this problem by making sure the type_name is a single word (I'll manually change the database to accomplish this).

I am looking forward to a fix.

Oh, turning off "strict sanitizing" doesn’t stop the sanitize error messages, which I am sure you know.

A question, if I may: It seems to me, on reflection, that the Admin Sanitizer documentation implies I should set up data files in /admin/includes/extra_datafiles/ (for me, /backend/…) to define how the Admin Sanitizer should handle any additional GET or POST fields I have added to the Admin core. It doesn’t indicate how the file names should be formed. Could you tell me please? And whether they are necessary (i.e. advised for good security)?

31 May 2016, 4:41 PM
#7
jrgoold avatar

jrgoold

New Zenner

Join Date:
May 2016
Location:
St. John's NL Canada
Posts:
32
Plugin Contributions:
0

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

It wasn’t necessary to manual change the database. Instead, in Admin, Catalog—>Product Types :smile:

Wilt: Sorry, I didn’t realize I hadn't posted the sanitizer log. If you want it, I can reproduce it.

3 Jun 2016, 10:57 PM
#8
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

wilt:

Hi all

This is in fact a problem with core code, and not really related to any plugins.

The reviews code passes a 'products_name' hidden field which in this context is a string.
However in general 'products_name' is expected to be an array (e.g. to account for language translations)
Hence the sanitizer complaining it's not an array.

Will push a fix up shortly
Wilt's fix is the 3 files mentioned here: https://www.zen-cart.com/showthread.php?219760-Known-Bugs-%28and-fixes%29-with-v1-5-5&p=1312333#post1312333

4 Jun 2016, 6:31 PM
#9
jrgoold avatar

jrgoold

New Zenner

Join Date:
May 2016
Location:
St. John's NL Canada
Posts:
32
Plugin Contributions:
0

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Thank you for the link. I shall apply the fixes to both the live and test sites.

10 Dec 2016, 11:55 PM
#10
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

I need to enclose some text in html tags, in the Option Names Comments field, but when I put the tags in, it is not sanitizing and converts the < to < , and the > to > . I have to then go into the database and change them back to < and > so that they do not render as < and > in-screen.

eg: <hr /> becomes <hr />

How do I fix this?

11 Dec 2016, 5:17 AM
#11
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

schoolboy:

but when I put the tags in, it is not sanitizing and converts the < to < , and the > to > .
Actually, it is sanitizing; actually appears to be sanitizing something you wish it didn't.

The process to change this is to identify the name of the input field, and change which sanitization rule is being applied to it for the specified page.

11 Dec 2016, 1:39 PM
#12
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,097
Plugin Contributions:
56

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

@schoolboy, towards the bottom of the (Zen Cart 1.5.5b) file /YOUR_ADMIN/includes/init_includes/init_sanitize.php, find:

$group = array('customers_email_address' => array('sanitizerType' => 'SANITIZE_EMAIL_AUDIENCE', 'method' => 'post', 'pages' => array('mail')));
$sanitizer->addComplexSanitization($group);

$group = array('customers_email_address');
$sanitizer->addSimpleSanitization('SANITIZE_EMAIL', $group);

$group = array('products_description', 'coupon_desc', 'file_contents', 'categories_description', 'message_html', 'banners_html_text', 'pages_html_text', 'comments');
$sanitizer->addSimpleSanitization('PRODUCT_DESC_REGEX', $group);

$group = array('products_url');
$sanitizer->addSimpleSanitization('PRODUCT_URL_REGEX', $group);

$group = array('coupon_min_order');
$sanitizer->addSimpleSanitization('CURRENCY_VALUE_REGEX', $group);

and add the highlighted variable name to enable HTML tags in the products' options' comments:

$group = array('customers_email_address' => array('sanitizerType' => 'SANITIZE_EMAIL_AUDIENCE', 'method' => 'post', 'pages' => array('mail')));
$sanitizer->addComplexSanitization($group);

$group = array('customers_email_address');
$sanitizer->addSimpleSanitization('SANITIZE_EMAIL', $group);

$group = array('products_description', 'coupon_desc', 'file_contents', 'categories_description', 'message_html', 'banners_html_text', 'pages_html_text', 'comments'[B], 'products_options_comment'[/B]);
$sanitizer->addSimpleSanitization('PRODUCT_DESC_REGEX', $group);

$group = array('products_url');
$sanitizer->addSimpleSanitization('PRODUCT_URL_REGEX', $group);

$group = array('coupon_min_order');
$sanitizer->addSimpleSanitization('CURRENCY_VALUE_REGEX', $group);
11 Dec 2016, 6:08 PM
#13
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,883
Plugin Contributions:
3

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Hi

There is some documentation about customizing the sanitizers here

However, to make your life easier, here is what to do.

Create a new file in [admin]/includes/extra_datafiles/

I named it sanitize_products_options_comment.php

contents of the file should be

<?php
$sanitizer = AdminRequestSanitizer::getInstance();
$group = array(
    'products_options_comment' => array('sanitizerType' => 'PRODUCT_DESC_REGEX', 'method' => 'post'),
);
$sanitizer->addComplexSanitization($group);

schoolboy:

I need to enclose some text in html tags, in the Option Names Comments field, but when I put the tags in, it is not sanitizing and converts the < to < , and the > to > . I have to then go into the database and change them back to < and > so that they do not render as < and > in-screen.

eg: <hr /> becomes <hr />

How do I fix this?

11 Dec 2016, 6:16 PM
#14
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,883
Plugin Contributions:
3

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Note.

Have also opened a github issue.
https://github.com/zencart/zencart/issues/1348

12 Dec 2016, 3:22 AM
#15
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

wilt:

Hi

There is some documentation about customizing the sanitizers here

However, to make your life easier, here is what to do.

Create a new file in [admin]/includes/extra_datafiles/

I named it sanitize_products_options_comment.php

contents of the file should be

<?php $sanitizer = AdminRequestSanitizer::getInstance(); $group = array( 'products_options_comment' => array('sanitizerType' => 'PRODUCT_DESC_REGEX', 'method' => 'post'), ); $sanitizer->addComplexSanitization($group); ``` Thanks wilt - that works. @lat9... I tried your suggestion a few days ago and it wouldn't work for me, but thanks for the suggestion. ```php $group = array('products_description', 'coupon_desc', 'file_contents', 'categories_description', 'message_html', 'banners_html_text', 'pages_html_text', 'comments', 'products_options_comment'); $sanitizer->addSimpleSanitization('PRODUCT_DESC_REGEX', $group); ```
12 Dec 2016, 12:16 PM
#16
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,097
Plugin Contributions:
56

Re: [Done v155a and v155b] AdminRequestSanitizer Problem

Hmm, I wonder why that didn't work for you; it's working just fine for me.