Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork9.7k
[HttpKernel] Forcing string comparison on query parameters sort in UriSigner#17287
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Closed
Uh oh!
There was an error while loading.Please reload this page.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters
Contributor
DemonTPx commentedJan 7, 2016
👍 |
Member
stof commentedJan 7, 2016
👍 (should be merged in 2.3) |
Member
fabpot commentedJan 7, 2016
Thank you@Timvd. |
fabpot added a commit that referenced this pull requestJan 7, 2016
… sort in UriSigner (Tim van Densen)This PR was submitted for the master branch but it was merged into the 2.3 branch instead (closes#17287).Discussion----------[HttpKernel] Forcing string comparison on query parameters sort in UriSigner| Q | A| ------------- | ---| Bug fix? | yes| New feature? | no| BC breaks? | no| Deprecations? | no| Tests pass? | yes| Fixed tickets || License | MIT| Doc PR |The signing of an url fails when using query parameters with integers as keys.The ksort function in the ```UriSigner``` class changes the order of the query params and causes to generate a different hash which results in a failed check.In this PR we force a string comparison for ksort which keeps the correct order of parameters.Commits-------2040139 Added sort order SORT_STRING for params in UriSigner
This was referencedJan 14, 2016
Merged
Merged
Merged
Merged
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The signing of an url fails when using query parameters with integers as keys.
The ksort function in the
UriSignerclass changes the order of the query params and causes to generate a different hash which results in a failed check.In this PR we force a string comparison for ksort which keeps the correct order of parameters.