File: unserialize_allowed_classes_option_invalid_class_names.phpt

package info (click to toggle)
php8.4 8.4.11-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 208,108 kB
  • sloc: ansic: 1,060,628; php: 35,345; sh: 11,866; cpp: 7,201; pascal: 4,913; javascript: 3,091; asm: 2,810; yacc: 2,411; makefile: 689; xml: 446; python: 301; awk: 148
file content (48 lines) | stat: -rw-r--r-- 1,491 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
--TEST--
Test unserialize() with array allowed_classes and nonsensical class names
--FILE--
<?php
class foo {
        public $x = "bar";
}
$z = array(new foo(), 2, "3");
$s = serialize($z);

try {
    unserialize($s, ["allowed_classes" => [""]]);
} catch (Throwable $e) {
    echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
    unserialize($s, ["allowed_classes" => ["245blerg"]]);
} catch (Throwable $e) {
    echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
    unserialize($s, ["allowed_classes" => ["  whitespace  "]]);
} catch (Throwable $e) {
    echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
    unserialize($s, ["allowed_classes" => ["name\nwith whitespace"]]);
} catch (Throwable $e) {
    echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
    unserialize($s, ["allowed_classes" => ['$dollars']]);
} catch (Throwable $e) {
    echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
    unserialize($s, ["allowed_classes" => ["have\0nul_byte"]]);
} catch (Throwable $e) {
    echo $e::class, ': ', $e->getMessage(), "\n";
}

?>
--EXPECT--
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "  whitespace  " given
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "name
with whitespace" given
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "$dollars" given
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "have" given