Compare commits

..
Author SHA1 Message Date
Vlad Kidanov 5bf7dc0c9c Merge pull request #419 from catalyst/general-fixes
Bug fixes and improvements
2026-08-05 10:05:23 +01:00
vlad.kidanov c95a35aae5 Bug fixes and improvements
WR492688: Issue #32

Fix: the 'static' flag can no longer be set from a raw client value. It
is now only true if the request presents a 'statickey' matching an
HMAC-SHA256 of the outage id keyed with a per-site secret
(infopage::statickey(), lazily generated via set_config()/get_config()).
maintenance_static_page::create_from_outage() now sends that computed
statickey instead of static=1 when it internally fetches info.php, so
the legitimate static-generation path keeps working while external
forgery of the flag is no longer possible.

WR492688: Issue #33

WR492688: Version bump
2026-07-20 11:56:43 +01:00
cameron1729 a55678d2cb Merge pull request #412 from sarahjcotton/WR489688-security-fix-39
WR489688: Security fix #30
2026-07-13 21:12:31 +08:00
Sarah Cotton be740fd139 WR489688: Security fix #30 2026-06-25 15:15:22 +01:00
Tomo Tsuyuki 9bab491666 Revert "Fix URL is blocked message when not behind a proxy/load balancer"
This reverts commit 51db933862.
2026-06-18 12:00:26 +10:00
Tomo Tsuyuki 20fef09b03 issue #405: fix unit test failure 2026-06-18 10:01:42 +10:00
7 changed files with 45 additions and 40 deletions
+23 -2
View File
@@ -53,10 +53,14 @@ class infopage {
$CFG->svgicons = true;
if (is_null($params)) {
$id = optional_param('id', null, PARAM_INT);
$params = [
'id' => optional_param('id', null, PARAM_INT),
'id' => $id,
'outage' => null,
'static' => optional_param('static', false, PARAM_BOOL),
'static' => !is_null($id) && hash_equals(
self::statickey($id),
optional_param('statickey', '', PARAM_ALPHANUM)
),
];
} else {
$defaults = [
@@ -152,4 +156,21 @@ class infopage {
$this->outage = $params['outage'];
$this->static = $params['static'];
}
/**
* Computes the secret token that proves a request to view an outage's static
* rendering came from this plugin's own static-page generator, not an external
* client forging the request. Used to gate the 'static' flag (see constructor).
*
* @param int $outageid
* @return string
*/
public static function statickey($outageid) {
$secret = get_config('auth_outage', 'staticsecret');
if (empty($secret)) {
$secret = random_string(64);
set_config('staticsecret', $secret, 'auth_outage');
}
return hash_hmac('sha256', (string)$outageid, $secret);
}
}
@@ -56,7 +56,8 @@ class maintenance_static_page {
header('X-Outage-EndTime: ' . $outage->stoptime);
}
$data = maintenance_static_page_io::file_get_data(
$CFG->wwwroot . '/auth/outage/info.php?auth_outage_hide_warning=1&static=1&id=' . $outage->id
$CFG->wwwroot . '/auth/outage/info.php?auth_outage_hide_warning=1&id=' . $outage->id
. '&statickey=' . infopage::statickey($outage->id)
);
$html = $data['contents'];
}
+5 -1
View File
@@ -56,7 +56,7 @@ class outagelib {
global $CFG;
require_once($CFG->libdir . '/filelib.php');
$curl = new curl(['ignoresecurity' => true]);
$curl = new curl();
$contents = $curl->get($file);
$info = $curl->get_info();
if (!empty($info['content_type'])) {
@@ -267,6 +267,10 @@ class outagelib {
// single-quotes (and double for the sake of it) are present otherwise it would break the code.
$allowedips = addslashes($allowedips);
// Escape the access key before substitution into the PHP literal to prevent
// code injection via a maliciously crafted access key value.
$accesskey = addslashes((string)$accesskey);
$cookiesecure = is_moodle_cookie_secure();
// Since Moodle 4.3 cookiehttponly is default to true and this CFG is not set.
+4
View File
@@ -30,7 +30,11 @@ use auth_outage\local\controllers\maintenance_static_page;
// @codingStandardsIgnoreStart
require_once(__DIR__.'/../../config.php');
require_once($CFG->libdir . '/adminlib.php');
// @codingStandardsIgnoreEnd
admin_externalpage_setup('auth_outage_manage');
$id = optional_param('id', null, PARAM_INT);
$outage = is_null($id) ? outagedb::get_next_starting() : outagedb::get_by_id($id);
if (is_null($outage)) {
@@ -431,39 +431,6 @@ final class maintenance_static_page_test extends \auth_outage\base_testcase {
maintenance_static_page_io::file_get_data(200);
}
/**
* Test file_get_data with curlsecurityblockedhosts.
* We will use an external URL to test passing ignoresecurity inside of file_get_data works,
* ideally in real code we should only be calling file_get_data with internal URLs.
*/
public function test_file_get_data_curlsecurityblockedhosts(): void {
global $CFG, $USER;
$testhtml = $this->getExternalTestFileUrl('/test.html');
$url = new \moodle_url($testhtml);
$host = $url->get_host();
set_config('curlsecurityblockedhosts', $host); // Blocks $host.
// Test a regular curl with the default security enabled does in fact get blocked.
$curl = new \curl();
$contents = $curl->get($testhtml);
$expected = $curl->get_security()->get_blocked_url_string();
self::assertSame($expected, $contents);
self::assertSame(0, $curl->get_errno());
if ($CFG->branch >= 403) {
self::assertDebuggingCalled(
"Blocked $testhtml: The URL is blocked. [user {$USER->id}]",
DEBUG_NONE
);
}
// Test file_get_data does return the page and isn't blocked by security.
$found = maintenance_static_page_io::file_get_data($url->out());
$expected = '47250a973d1b88d9445f94db4ef2c97a';
self::assertSame($expected, md5($found['contents']));
self::assertSame('text/html', $found['mime']);
}
/**
* Test remove css selector.
*/
+2 -2
View File
@@ -28,8 +28,8 @@
defined('MOODLE_INTERNAL') || die();
$plugin->component = "auth_outage";
$plugin->version = 2024081903; // The current plugin version (Date: YYYYMMDDXX).
$plugin->release = 2024081903; // Human-readable release information.
$plugin->version = 2024081907; // The current plugin version (Date: YYYYMMDDXX).
$plugin->release = 2024081907; // Human-readable release information.
$plugin->requires = 2017111309; // 2017111309 = T13, but this really requires 3.9 and higher.
$plugin->maturity = MATURITY_STABLE; // Suitable for PRODUCTION environments!
$plugin->supported = [39, 405]; // A range of branch numbers of supported moodle versions.
+9 -1
View File
@@ -39,7 +39,15 @@ defined('MOODLE_INTERNAL') || die();
<b><?php echo get_string('infountil', 'auth_outage'); ?></b>
<?php echo userdate($viewbag['outage']->stoptime, get_string('datetimeformat', 'auth_outage')); ?>
</div>
<div class="auth_outage_info_description"><?php echo $viewbag['outage']->get_description(); ?></div>
<div class="auth_outage_info_description">
<?php
echo format_text(
$viewbag['outage']->get_description(),
FORMAT_HTML,
['context' => context_system::instance()]
);
?>
</div>
<?php if ($viewbag['admin']) : ?>
<?php