diff --git a/framework/base/router.class.php b/framework/base/router.class.php index 570e004f23..bc154790f7 100644 --- a/framework/base/router.class.php +++ b/framework/base/router.class.php @@ -2792,7 +2792,7 @@ class EndResponseException extends \Exception /** * @param string $content - * + * * @return sellf */ public static function create($content = '') diff --git a/module/gitlab/control.php b/module/gitlab/control.php index 1adc2cbffd..c202c7483c 100644 --- a/module/gitlab/control.php +++ b/module/gitlab/control.php @@ -845,7 +845,7 @@ class gitlab extends control */ public function createBranchPriv($gitlabID, $projectID, $branch = '') { - if($branch) $branch = base64_decode($branch); + if($branch) $branch = helper::safe64Decode($branch); if($_POST) { $this->gitlab->createBranchPriv($gitlabID, $projectID, $branch); @@ -915,9 +915,13 @@ class gitlab extends control */ public function deleteBranchPriv($gitlabID, $projectID, $branch, $confirm = 'no') { - if($confirm != 'yes') die(js::confirm($this->lang->gitlab->branch->confirmDelete , inlink('deleteBranchPriv', "gitlabID=$gitlabID&projectID=$projectID&branch=$branch&confirm=yes"))); + if($confirm != 'yes') + { + $branch = urlencode($branch); + die(js::confirm($this->lang->gitlab->branch->confirmDelete , inlink('deleteBranchPriv', "gitlabID=$gitlabID&projectID=$projectID&branch=$branch&confirm=yes"))); + } - $branch = base64_decode($branch); + $branch = helper::safe64Decode($branch); $reponse = $this->gitlab->apiDeleteBranchPriv($gitlabID, $projectID, $branch); /* If the status code beginning with 20 is returned or empty is returned, it is successful. */ @@ -1092,7 +1096,7 @@ class gitlab extends control */ public function editTagPriv($gitlabID, $projectID, $tag = '') { - $tag = base64_decode($tag); + $tag = helper::safe64Decode($tag); if($_POST) { @@ -1124,7 +1128,7 @@ class gitlab extends control */ public function deleteTagPriv($gitlabID, $projectID, $tag) { - $tag = base64_decode($tag); + $tag = helper::safe64Decode($tag); $reponse = $this->gitlab->apiDeleteTagPriv($gitlabID, $projectID, $tag); /* If the status code beginning with 20 is returned or empty is returned, it is successful. */ @@ -1533,9 +1537,13 @@ class gitlab extends control */ public function deleteTag($gitlabID, $projectID, $tagName = '', $confirm = 'no') { - if($confirm != 'yes') die(js::confirm($this->lang->gitlab->tag->confirmDelete , inlink('deleteTag', "gitlabID=$gitlabID&projectID=$projectID&tagName=$tagName&confirm=yes"))); + if($confirm != 'yes') + { + $tagName = urlencode($tagName); + die(js::confirm($this->lang->gitlab->tag->confirmDelete , inlink('deleteTag', "gitlabID=$gitlabID&projectID=$projectID&tagName=$tagName&confirm=yes"))); + } - $tagName = base64_decode($tagName); + $tagName = helper::safe64Decode($tagName); $reponse = $this->gitlab->apiDeleteTag($gitlabID, $projectID, $tagName); /* If the status code beginning with 20 is returned or empty is returned, it is successful. */ diff --git a/module/gitlab/model.php b/module/gitlab/model.php index e5098ae215..511b8ca025 100644 --- a/module/gitlab/model.php +++ b/module/gitlab/model.php @@ -1525,6 +1525,7 @@ class gitlabModel extends model if(!(int)$gitlabID or !(int)$projectID or empty($tagName)) return false; $apiRoot = $this->getApiRoot($gitlabID); + $tagName = urlencode($tagName); $url = sprintf($apiRoot, "/projects/{$projectID}/repository/tags/{$tagName}"); return json_decode(commonModel::http($url, array(), $options = array(CURLOPT_CUSTOMREQUEST => 'DELETE'))); } @@ -1566,6 +1567,7 @@ class gitlabModel extends model { if(empty($gitlabID)) return false; $apiRoot = $this->getApiRoot($gitlabID); + $tag = urlencode($tag); $url = sprintf($apiRoot, "/projects/{$projectID}/protected_tags/{$tag}"); return json_decode(commonModel::http($url, array(), $options = array(CURLOPT_CUSTOMREQUEST => 'DELETE'))); } @@ -2482,7 +2484,8 @@ class gitlabModel extends model public function apiGetSingleBranchPriv($gitlabID, $projectID, $branch) { if(empty($gitlabID)) return false; - $url = sprintf($this->getApiRoot($gitlabID), "/projects/$projectID/protected_branches/$branch"); + $branch = urlencode($branch); + $url = sprintf($this->getApiRoot($gitlabID), "/projects/$projectID/protected_branches/$branch"); return json_decode(commonModel::http($url)); } @@ -2592,6 +2595,7 @@ class gitlabModel extends model public function apiGetSingleTagPriv($gitlabID, $projectID, $tag) { if(empty($gitlabID)) return false; + $tag = urlencode($tag); $url = sprintf($this->getApiRoot($gitlabID), "/projects/$projectID/protected_tags/$tag"); return json_decode(commonModel::http($url)); } diff --git a/module/gitlab/view/browsetag.html.php b/module/gitlab/view/browsetag.html.php index 233089a065..c9b2378715 100644 --- a/module/gitlab/view/browsetag.html.php +++ b/module/gitlab/view/browsetag.html.php @@ -68,7 +68,7 @@