This commit is contained in:
Thanakorn S
2026-04-29 17:04:11 +07:00
parent f6dc9a3278
commit db5c47b6ca
15 changed files with 679 additions and 43 deletions
+15
View File
@@ -34,9 +34,18 @@ class db_statement extends PDOStatement {
if (!is_array($args)) {
$args = func_get_args();
}else{
// Cast all values to string before XSS processing.
// json_decode requires a string — integers, booleans, and nulls
// passed as bound parameters would otherwise cause a TypeError.
// null is preserved as-is so PDO can bind NULL columns correctly.
$args = array_map(fn($v) => is_null($v) ? null : (string)$v, $args);
// escaping array
// prevent store XSS
foreach($args as &$item){
if (is_null($item)) continue;
// decode the JSON data
// set second parameter boolean TRUE for associative array output.
$result = json_decode($item);
@@ -45,6 +54,12 @@ class db_statement extends PDOStatement {
$tmp = json_decode($item,true);
foreach((array)$tmp as &$ii){
// Inner values may be arrays (nested JSON objects) — cast to string
if (!is_string($ii)) {
$ii = json_encode($ii);
continue;
}
$result = json_decode($ii);
if (json_last_error() === JSON_ERROR_NONE) {
// json inside json