Harden published curriculum and student flows
This commit is contained in:
@@ -51,31 +51,24 @@ final class PublishedContentService
|
||||
return null;
|
||||
}
|
||||
|
||||
$candidates = [
|
||||
$root . '/' . $storageKey,
|
||||
$root . '/_incoming/' . $storageKey,
|
||||
dirname($root) . '/' . $storageKey,
|
||||
dirname($root, 2) . '/' . $storageKey,
|
||||
];
|
||||
|
||||
if (preg_match('#staged/grade_10/[^/]+/(.+)#', $storageKey, $matches)) {
|
||||
$inner = $matches[1];
|
||||
$candidates[] = $root . '/' . $inner;
|
||||
$candidates[] = $root . '/_incoming/' . $inner;
|
||||
}
|
||||
|
||||
// Published storage keys must resolve to their exact file inside the
|
||||
// curriculum root. Do not fall back to another similarly named file.
|
||||
$real = realpath($root . '/' . $storageKey);
|
||||
$prefix = rtrim($root, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR;
|
||||
$projectRoot = realpath(dirname(__DIR__, 2)) ?: '';
|
||||
return $real !== false && str_starts_with($real, $prefix) && is_file($real) ? $real : null;
|
||||
}
|
||||
|
||||
foreach ($candidates as $candidate) {
|
||||
$real = realpath($candidate);
|
||||
if ($real && is_file($real)) {
|
||||
// Ensure candidate is strictly within the project root to prevent traversal
|
||||
if ($projectRoot !== '' && str_starts_with($real, $projectRoot)) {
|
||||
return $real;
|
||||
}
|
||||
}
|
||||
}
|
||||
return null;
|
||||
public static function studentMayRead(int $studentId, array $asset): bool
|
||||
{
|
||||
if ($studentId <= 0 || empty($asset['grade_key'])) return false;
|
||||
$student = Database::selectOne(
|
||||
"SELECT s.grade_level FROM students s
|
||||
JOIN auth_identities ai ON ai.id=s.identity_id AND ai.status='active'
|
||||
WHERE s.id=? LIMIT 1",
|
||||
[$studentId]
|
||||
);
|
||||
if (!$student || empty($student['grade_level'])) return false;
|
||||
return StudentAccessControlService::normalizeGrade((string)$student['grade_level'])
|
||||
=== StudentAccessControlService::normalizeGrade((string)$asset['grade_key']);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user