Skip to content

2.2.1

Latest

Choose a tag to compare

@dereuromark dereuromark released this 05 May 01:43
· 3 commits to master since this release
d852c18

Fixes

  • Allow-list the ext token parsed out of the on-disk cache header. extractCacheInfo() previously fed whatever it found in <!--cachetime:.../...;ext:...--> straight into Response::withType() — anything able to write to tmp/cache/views/ (a misconfigured CACHE constant pointing at a public path, a compromised plugin, a bug elsewhere that let user input control a cache filename) could therefore force an arbitrary Content-Type, opening a MIME-confusion / XSS surface. The token is now restricted to a fixed list (html, json, xml, csv, txt, rss, atom, js, css) with the regex tightened to [a-z0-9]{1,8}. Mirrored in both CacheMiddleware and FileCache.
  • Atomic on-disk writes in CacheComponent::_writeFile(). Previously file_put_contents() was used with no lock and no temp-file pattern — under concurrent traffic the middleware could read a half-written file, the regex match failed, cacheTime parsed to 0, and the torn entry never got invalidated by $cacheEnd < time(). Writes now go through tempnam() + LOCK_EX + rename() (atomic on the same filesystem).
  • Reset per-request state at the top of CacheMiddleware::process(). _cacheContent / _cacheInfo were previously not cleared between requests — latent under PHP-FPM (one request per worker), but a correctness landmine on long-lived runtimes (Swoole, RoadRunner, FrankenPHP, ReactPHP) where content from request N could leak into request N+1.

Full Changelog: 2.2.0...2.2.1