Initialise the array the write path collects refusals into
An undefined variable reaching a by-reference array parameter is a TypeError under PHP 8, so every save through this endpoint died before writing anything.
This commit is contained in:
@@ -91,6 +91,31 @@ require_once dirname(__DIR__) . '/include/scheduler.php';
|
|||||||
require_once dirname(__DIR__) . '/include/confform.php';
|
require_once dirname(__DIR__) . '/include/confform.php';
|
||||||
|
|
||||||
if ($_SERVER['REQUEST_METHOD'] === 'GET') {
|
if ($_SERVER['REQUEST_METHOD'] === 'GET') {
|
||||||
|
// Section-scoped read. A page that owns a subject rather than a script — the AI tab, and
|
||||||
|
// partnership before it — wants the sections whose header names that subject, across every
|
||||||
|
// conf file it is allowed to see. Same fields, same shape, same write path back; only the
|
||||||
|
// question of "which fields" differs, so it is a mode here rather than a second endpoint
|
||||||
|
// with its own copy of the allowlist and the master push.
|
||||||
|
$match = trim($_GET['sections'] ?? '');
|
||||||
|
if ($match !== '') {
|
||||||
|
// Whole word, case-insensitive. A plain substring is far too loose on these headers —
|
||||||
|
// "ai" alone also selects Maintenance, Containers, Failover and Arr Failed/Stalled
|
||||||
|
// Recovery, which is nine wrong sections out of twenty-one and every one of them looks
|
||||||
|
// deliberate once it is on the page.
|
||||||
|
//
|
||||||
|
// preg_quote first: the needle arrives from a query string, so it is matched as a literal
|
||||||
|
// with boundaries around it rather than as a pattern a caller could widen to everything.
|
||||||
|
$re = '/\b' . preg_quote($match, '/') . '\b/i';
|
||||||
|
$out = [];
|
||||||
|
foreach (vv_get_conf_files() as $f) {
|
||||||
|
foreach (vv_conf_all_groups($f) as $g) {
|
||||||
|
if (preg_match($re, (string) ($g['subsection'] ?? ''))) $out[] = $g;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
echo json_encode(['ok' => true, 'groups' => $out]);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
|
||||||
$id = trim($_GET['id'] ?? '');
|
$id = trim($_GET['id'] ?? '');
|
||||||
if (!$id || str_contains($id, '..')) {
|
if (!$id || str_contains($id, '..')) {
|
||||||
echo json_encode(['ok' => false, 'error' => 'Invalid id']);
|
echo json_encode(['ok' => false, 'error' => 'Invalid id']);
|
||||||
@@ -105,7 +130,10 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
$id = trim($_POST['id'] ?? '');
|
$id = trim($_POST['id'] ?? '');
|
||||||
$rawJson = $_POST['changes'] ?? '[]';
|
$rawJson = $_POST['changes'] ?? '[]';
|
||||||
|
|
||||||
if (!$id) { echo json_encode(['ok' => false, 'error' => 'Missing id']); exit; }
|
// Optional. It labels which script's form was open and is used nowhere in the write — every
|
||||||
|
// change already names its own file and key, and those are what is validated below. A
|
||||||
|
// section-scoped save has no script to name, and inventing one so this check would pass
|
||||||
|
// would be a guard that only ever guarded against itself.
|
||||||
|
|
||||||
$changes = json_decode($rawJson, true);
|
$changes = json_decode($rawJson, true);
|
||||||
if (!is_array($changes)) { echo json_encode(['ok' => false, 'error' => 'Invalid changes']); exit; }
|
if (!is_array($changes)) { echo json_encode(['ok' => false, 'error' => 'Invalid changes']); exit; }
|
||||||
@@ -122,7 +150,13 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
$results = vv_conf_write_changes($changes, $rejected);
|
// Declared before it is passed. It is a by-reference array parameter, and an undefined
|
||||||
|
// variable arrives there as null — which under PHP 8 is a TypeError thrown before a single
|
||||||
|
// byte is written, so every save through this endpoint died with a 500 and the page saw an
|
||||||
|
// unparseable response rather than a refusal it could report. The callers that pass no
|
||||||
|
// second argument were never affected, which is why it survived: this is the only one.
|
||||||
|
$rejected = [];
|
||||||
|
$results = vv_conf_write_changes($changes, $rejected);
|
||||||
|
|
||||||
// Propagate master.conf to partner hosts when the owner edits it (mirrors rawconf.php).
|
// Propagate master.conf to partner hosts when the owner edits it (mirrors rawconf.php).
|
||||||
$push = [];
|
$push = [];
|
||||||
|
|||||||
Reference in New Issue
Block a user