From 0c34164c8bf9a0e34dddd34736c6f3c7eeb663e0 Mon Sep 17 00:00:00 2001 From: Andre Klapper Date: Thu, 29 May 2025 12:07:29 +0200 Subject: [PATCH] Fix PHP 8.1 "strlen(null)" exception in Client ID handling of PhabricatorOAuthServerTokenController Summary: `strlen()` was used in Phabricator to check if a generic value is a non-empty string. This behavior is deprecated since PHP 8.1. Phorge adopts `phutil_nonempty_string()` as a replacement. Note: this may highlight other absurd input values that might be worth correcting instead of just ignoring. If phutil_nonempty_string() throws an exception in your instance, report it to Phorge to evaluate and fix that specific corner case. ``` strlen(): Passing null to parameter #1 ($string) of type string is deprecated #0 PhabricatorOAuthServerTokenController::handleRequest(AphrontRequest) called at [/src/aphront/configuration/AphrontApplicationConfiguration.php:284] ``` See Q182 Test Plan: Read the code. `strlen` is used to get the length of an existing string and not to check for emptiness of a string. There is no string length comparison in the existing code. Reviewers: O1 Blessed Committers, valerio.bozzolan Reviewed By: O1 Blessed Committers, valerio.bozzolan Subscribers: tobiaswiese, valerio.bozzolan, Matthew, Cigaryno Differential Revision: https://we.phorge.it/D26034 --- .../controller/PhabricatorOAuthServerTokenController.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/applications/oauthserver/controller/PhabricatorOAuthServerTokenController.php b/src/applications/oauthserver/controller/PhabricatorOAuthServerTokenController.php index 6fb2bfc334..119d8c95a4 100644 --- a/src/applications/oauthserver/controller/PhabricatorOAuthServerTokenController.php +++ b/src/applications/oauthserver/controller/PhabricatorOAuthServerTokenController.php @@ -23,7 +23,8 @@ final class PhabricatorOAuthServerTokenController $client_id_parameter = $request->getStr('client_id'); $client_id_header = idx($_SERVER, 'PHP_AUTH_USER'); - if (strlen($client_id_parameter) && strlen($client_id_header)) { + if (phutil_nonempty_string($client_id_parameter) && + phutil_nonempty_string($client_id_header)) { if ($client_id_parameter !== $client_id_header) { throw new Exception( pht( -- 2.51.2