PhpSpreadsheet/tests/PhpSpreadsheetTests/Reader/Security/XmlScannerTest.php

141 lines
4.4 KiB
PHP
Raw Normal View History

2018-11-19 21:47:34 +00:00
<?php
namespace PhpOffice\PhpSpreadsheetTests\Reader\Security;
2018-11-19 22:22:59 +00:00
use PhpOffice\PhpSpreadsheet\Reader\Security\XmlScanner;
use PhpOffice\PhpSpreadsheet\Reader\Xls;
2018-11-25 13:33:01 +00:00
use PhpOffice\PhpSpreadsheet\Reader\Xlsx;
use PhpOffice\PhpSpreadsheet\Reader\Xml;
2018-11-20 07:18:35 +00:00
use PHPUnit\Framework\TestCase;
2018-11-19 21:47:34 +00:00
class XmlScannerTest extends TestCase
{
/**
* @dataProvider providerValidXML
*
* @param mixed $filename
* @param mixed $expectedResult
* @param $libxmlDisableEntityLoader
2018-11-19 21:47:34 +00:00
*/
public function testValidXML($filename, $expectedResult, $libxmlDisableEntityLoader)
2018-11-19 21:47:34 +00:00
{
libxml_disable_entity_loader($libxmlDisableEntityLoader);
2018-11-23 22:05:17 +00:00
$reader = XmlScanner::getInstance(new \PhpOffice\PhpSpreadsheet\Reader\Xml());
2018-11-19 21:47:34 +00:00
$result = $reader->scanFile($filename);
self::assertEquals($expectedResult, $result);
self::assertEquals($libxmlDisableEntityLoader, libxml_disable_entity_loader());
2018-11-19 21:47:34 +00:00
}
public function providerValidXML()
{
$tests = [];
2018-11-19 22:22:59 +00:00
foreach (glob(__DIR__ . '/../../../data/Reader/Xml/XEETestValid*.xml') as $file) {
$filename = realpath($file);
$expectedResult = file_get_contents($file);
$tests[basename($file) . '_libxml_entity_loader_disabled'] = [$filename, $expectedResult, true];
$tests[basename($file) . '_libxml_entity_loader_enabled'] = [$filename, $expectedResult, false];
2018-11-19 21:47:34 +00:00
}
return $tests;
}
/**
* @dataProvider providerInvalidXML
*
* @param mixed $filename
* @param $libxmlDisableEntityLoader
2018-11-19 21:47:34 +00:00
*/
public function testInvalidXML($filename, $libxmlDisableEntityLoader)
2018-11-19 21:47:34 +00:00
{
$this->expectException(\PhpOffice\PhpSpreadsheet\Reader\Exception::class);
libxml_disable_entity_loader($libxmlDisableEntityLoader);
2018-11-23 22:05:17 +00:00
$reader = XmlScanner::getInstance(new \PhpOffice\PhpSpreadsheet\Reader\Xml());
2018-11-19 21:47:34 +00:00
$expectedResult = 'FAILURE: Should throw an Exception rather than return a value';
$result = $reader->scanFile($filename);
self::assertEquals($expectedResult, $result);
self::assertEquals($libxmlDisableEntityLoader, libxml_disable_entity_loader());
2018-11-19 21:47:34 +00:00
}
public function providerInvalidXML()
{
$tests = [];
2018-11-19 22:22:59 +00:00
foreach (glob(__DIR__ . '/../../../data/Reader/Xml/XEETestInvalidUTF*.xml') as $file) {
$filename = realpath($file);
$tests[basename($file) . '_libxml_entity_loader_disabled'] = [$filename, true];
$tests[basename($file) . '_libxml_entity_loader_enabled'] = [$filename, false];
2018-11-19 21:47:34 +00:00
}
return $tests;
}
public function testGetSecurityScannerForXmlBasedReader()
{
$fileReader = new Xlsx();
$scanner = $fileReader->getSecuritySCanner();
// Must return an object...
$this->assertInternalType('object', $scanner);
// ... of the correct type
$this->assertInstanceOf(XmlScanner::class, $scanner);
}
public function testGetSecurityScannerForNonXmlBasedReader()
{
$fileReader = new Xls();
$scanner = $fileReader->getSecuritySCanner();
// Must return a null...
$this->assertNull($scanner);
}
/**
* @dataProvider providerValidXMLForCallback
*
* @param mixed $filename
2018-11-25 13:33:01 +00:00
* @param mixed $expectedResult
*/
public function testSecurityScanWithCallback($filename, $expectedResult)
{
$fileReader = new Xlsx();
$scanner = $fileReader->getSecuritySCanner();
$scanner->setAdditionalCallback('strrev');
$xml = $scanner->scanFile($filename);
$this->assertEquals(strrev($expectedResult), $xml);
}
public function providerValidXMLForCallback()
{
$tests = [];
foreach (glob(__DIR__ . '/../../../data/Reader/Xml/SecurityScannerWithCallback*.xml') as $file) {
$tests[basename($file)] = [realpath($file), file_get_contents($file)];
}
return $tests;
}
/**
* @dataProvider providerLibxmlSettings
*
2019-01-02 04:38:13 +00:00
* @param $libxmlDisableLoader
*/
2019-01-02 04:38:13 +00:00
public function testNewInstanceCreationDoesntChangeLibxmlSettings($libxmlDisableLoader)
{
2019-01-02 04:38:13 +00:00
libxml_disable_entity_loader($libxmlDisableLoader);
$reader = new Xml();
2019-01-02 04:38:13 +00:00
self::assertEquals($libxmlDisableLoader, libxml_disable_entity_loader($libxmlDisableLoader));
unset($reader);
}
public function providerLibxmlSettings()
{
return [
[true],
[false],
];
}
2018-11-20 07:18:35 +00:00
}