Skip to content

Commit

Permalink
MDL-18552 different TeX trouble fix
Browse files Browse the repository at this point in the history
  • Loading branch information
skodak committed Mar 31, 2009
1 parent f7631e7 commit c94985e
Show file tree
Hide file tree
Showing 6 changed files with 27 additions and 28 deletions.
23 changes: 0 additions & 23 deletions filter/tex/filter.php
Expand Up @@ -137,16 +137,6 @@ function filter ($text) {
$text = str_replace($matches[0][$i],$replacement,$text);
}

// TeX blacklist. MDL-18552
$tex_blacklist = array(
'include','def','command','loop','repeat','open','toks','output',
'input','catcode','name','^^',
'\every','\errhelp','\errorstopmode','\scrollmode','\nonstopmode',
'\batchmode','\read','\write','csname','\newhelp','\uppercase',
'\lowercase','\relax','\aftergroup',
'\afterassignment','\expandafter','\noexpand','\special'
);

// <tex> TeX expression </tex>
// or <tex alt="My alternative text to be used instead of the TeX form"> TeX expression </tex>
// or $$ TeX expression $$
Expand All @@ -169,19 +159,6 @@ function filter ($text) {
$align = "text-top";
$texexp = preg_replace('/^align=top /','',$texexp);
}
/// Check $texexp against blacklist (whitelisting could be more complete but also harder to maintain). MDL-18552
$invalidcommands = array();
foreach($tex_blacklist as $command) {
if (stristr($texexp, $command)) { /// Found invalid command. Annotate.
$invalidcommands[] = $command;
}
}
if (!empty($invalidcommands)) { /// Invalid commands found. Output error and continue with next TeX element
$invalidstr = get_string('invalidtexcommand', 'error', implode(', ', $invalidcommands));
$text = str_replace( $matches[0][$i], $invalidstr, $text);
continue;
}
/// Everything is ok, let's process the expression
$md5 = md5($texexp);
if (! $texcache = $DB->get_record("cache_filters", array("filter"=>"tex", "md5key"=>$md5))) {
$texcache->filter = 'tex';
Expand Down
6 changes: 4 additions & 2 deletions filter/tex/latex.php
Expand Up @@ -44,9 +44,11 @@ function supported() {
* @return string the latex document
*/
function construct_latex_document( $formula, $fontsize=12 ) {
// $fontsize don't affects to formula's size. $density can change size

global $CFG;

$formula = tex_sanitize_formula($formula);

// $fontsize don't affects to formula's size. $density can change size
$doc = "\\documentclass[{$fontsize}pt]{article}\n";
$doc .= $CFG->filter_tex_latexpreamble;
$doc .= "\\pagestyle{empty}\n";
Expand Down
14 changes: 14 additions & 0 deletions filter/tex/lib.php
Expand Up @@ -34,8 +34,22 @@ function tex_filter_get_executable($debug=false) {
print_error('mimetexisnotexist', 'error');
}

function tex_sanitize_formula($texexp) {
/// Check $texexp against blacklist (whitelisting could be more complete but also harder to maintain)
$tex_blacklist = array(
'include','def','command','loop','repeat','open','toks','output',
'input','catcode','name','^^',
'\every','\errhelp','\errorstopmode','\scrollmode','\nonstopmode',
'\batchmode','\read','\write','csname','\newhelp','\uppercase',
'\lowercase','\relax','\aftergroup',
'\afterassignment','\expandafter','\noexpand','\special'
);

return str_ireplace($tex_blacklist, 'forbiddenkeyword', $texexp);
}

function tex_filter_get_cmd($pathname, $texexp) {
$texexp = tex_sanitize_formula($texexp);
$texexp = escapeshellarg($texexp);
$executable = tex_filter_get_executable(false);

Expand Down
1 change: 0 additions & 1 deletion lang/en_utf8/error.php
Expand Up @@ -294,7 +294,6 @@
$string['invalidsesskey'] = 'Incorrect sesskey submitted, form not accepted!';
$string['invalidsection'] = 'Course module record contains invalid section';
$string['invalidshortname'] = 'That\'s an invalid short course name';
$string['invalidtexcommand'] = 'Forbidden TeX command ($a)';
$string['invalidurl'] = 'Invalid URL';
$string['invaliduser'] = 'Invalid user';
$string['invaliduserid'] = 'Invalid user id';
Expand Down
9 changes: 8 additions & 1 deletion lib/db/upgrade.php
Expand Up @@ -1534,7 +1534,14 @@ function xmldb_main_upgrade($oldversion) {
/// Main savepoint reached
upgrade_main_savepoint($result, 2009032001);
}


if ($result && $oldversion < 2009033100) {
require_once("$CFG->dirroot/filter/tex/lib.php");
filter_tex_updatedcallback(null);
/// Main savepoint reached
upgrade_main_savepoint($result, 2009033100);
}

return $result;
}

Expand Down
2 changes: 1 addition & 1 deletion version.php
Expand Up @@ -6,7 +6,7 @@
// This is compared against the values stored in the database to determine
// whether upgrades should be performed (see lib/db/*.php)

$version = 2009033002; // YYYYMMDD = date of the last version bump
$version = 2009033100; // YYYYMMDD = date of the last version bump
// XX = daily increments

$release = '2.0 dev (Build: 20090331)'; // Human-friendly version name
Expand Down

0 comments on commit c94985e

Please sign in to comment.