Reports
This commit is contained in:
@@ -34,9 +34,18 @@ class db_statement extends PDOStatement {
|
||||
if (!is_array($args)) {
|
||||
$args = func_get_args();
|
||||
}else{
|
||||
// Cast all values to string before XSS processing.
|
||||
// json_decode requires a string — integers, booleans, and nulls
|
||||
// passed as bound parameters would otherwise cause a TypeError.
|
||||
// null is preserved as-is so PDO can bind NULL columns correctly.
|
||||
$args = array_map(fn($v) => is_null($v) ? null : (string)$v, $args);
|
||||
|
||||
// escaping array
|
||||
// prevent store XSS
|
||||
foreach($args as &$item){
|
||||
|
||||
if (is_null($item)) continue;
|
||||
|
||||
// decode the JSON data
|
||||
// set second parameter boolean TRUE for associative array output.
|
||||
$result = json_decode($item);
|
||||
@@ -45,6 +54,12 @@ class db_statement extends PDOStatement {
|
||||
$tmp = json_decode($item,true);
|
||||
foreach((array)$tmp as &$ii){
|
||||
|
||||
// Inner values may be arrays (nested JSON objects) — cast to string
|
||||
if (!is_string($ii)) {
|
||||
$ii = json_encode($ii);
|
||||
continue;
|
||||
}
|
||||
|
||||
$result = json_decode($ii);
|
||||
if (json_last_error() === JSON_ERROR_NONE) {
|
||||
// json inside json
|
||||
|
||||
Reference in New Issue
Block a user