Merge pull request #138 from creative-commoners/pulls/1.0/scalars

FIX StringTagField now works with SS-2018-021/CVE-2019-5715 by serialising arrays before write
This commit is contained in:
Guy Marriott 2019-02-19 17:29:18 +13:00 committed by GitHub
commit e739275305
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -205,9 +205,19 @@ class StringTagField extends DropdownField {
$name = $this->getName();
$record->$name = join(',', $this->Value());
$record->write();
}
$record->$name = $this->dataValue();
$record->write();
}
/**
* Ensure that arrays are imploded before being saved
*
* @return mixed|string
*/
public function dataValue()
{
return implode(',', $this->value);
}
/**
* Returns a JSON string of tags, for lazy loading.