This commit is contained in:
Chris Stayte 2026-03-06 20:19:43 -05:00 committed by GitHub
commit 3bdfcf0789
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -31,7 +31,7 @@ class ValidGitRepositoryUrl implements ValidationRule
$dangerousChars = [ $dangerousChars = [
';', '|', '&', '$', '`', '(', ')', '{', '}', ';', '|', '&', '$', '`', '(', ')', '{', '}',
'[', ']', '<', '>', '\n', '\r', '\0', '"', "'", '[', ']', '<', '>', '\n', '\r', '\0', '"', "'",
'\\', '!', '?', '*', '^', '%', '=', '+', '\\', '!', '?', '*', '^', '=', '+',
'#', // Comment character that could hide commands '#', // Comment character that could hide commands
]; ];
@ -85,11 +85,17 @@ class ValidGitRepositoryUrl implements ValidationRule
} }
// Validate SSH URL format (git@host:user/repo.git) // Validate SSH URL format (git@host:user/repo.git)
if (! preg_match('/^git@[a-zA-Z0-9\.\-]+:[a-zA-Z0-9\-_\/\.~]+$/', $value)) { if (! preg_match('/^git@[a-zA-Z0-9\.\-]+:[a-zA-Z0-9\-_\/\.~%]+$/', $value)) {
$fail('The :attribute is not a valid SSH repository URL.'); $fail('The :attribute is not a valid SSH repository URL.');
return; return;
} }
// Ensure any percent signs are valid percent-encodings like %20
if (! empty($value) && preg_match('/%(?![0-9A-Fa-f]{2})/', $value)) {
$fail('The :attribute path contains invalid percent encoding.');
return;
}
} elseif (str_starts_with($value, 'http://') || str_starts_with($value, 'https://')) { } elseif (str_starts_with($value, 'http://') || str_starts_with($value, 'https://')) {
// Validate HTTP(S) URL // Validate HTTP(S) URL
if (! filter_var($value, FILTER_VALIDATE_URL)) { if (! filter_var($value, FILTER_VALIDATE_URL)) {