Compare commits

...

3 commits

Author SHA1 Message Date
Chris Stayte
3bdfcf0789
Merge ec9672ec68 into 11007771f0 2026-03-06 20:19:43 -05:00
Chris Stayte
ec9672ec68
Updated from $path to $value 2025-10-21 20:07:03 -04:00
Chris Stayte
7b6bc41d5b
remove % from forbidden characters in git URLs 2025-10-21 20:02:40 -04:00

View file

@ -31,7 +31,7 @@ class ValidGitRepositoryUrl implements ValidationRule
$dangerousChars = [
';', '|', '&', '$', '`', '(', ')', '{', '}',
'[', ']', '<', '>', '\n', '\r', '\0', '"', "'",
'\\', '!', '?', '*', '^', '%', '=', '+',
'\\', '!', '?', '*', '^', '=', '+',
'#', // Comment character that could hide commands
];
@ -85,11 +85,17 @@ class ValidGitRepositoryUrl implements ValidationRule
}
// Validate SSH URL format (git@host:user/repo.git)
if (! preg_match('/^git@[a-zA-Z0-9\.\-]+:[a-zA-Z0-9\-_\/\.~]+$/', $value)) {
if (! preg_match('/^git@[a-zA-Z0-9\.\-]+:[a-zA-Z0-9\-_\/\.~%]+$/', $value)) {
$fail('The :attribute is not a valid SSH repository URL.');
return;
}
// Ensure any percent signs are valid percent-encodings like %20
if (! empty($value) && preg_match('/%(?![0-9A-Fa-f]{2})/', $value)) {
$fail('The :attribute path contains invalid percent encoding.');
return;
}
} elseif (str_starts_with($value, 'http://') || str_starts_with($value, 'https://')) {
// Validate HTTP(S) URL
if (! filter_var($value, FILTER_VALIDATE_URL)) {