From 9e5986df1de943618d0b5376a8e52d3834f465ce Mon Sep 17 00:00:00 2001 From: Andre Klapper Date: Fri, 24 Oct 2025 11:00:36 +0200 Subject: [PATCH] Validate icon existence when setting project icon Summary: Do not allow setting an invalid project icon via the `project.edit` Conduit API but validate the value. Same game as in D26430. Closes T16322 Test Plan: * Run `echo '{"transactions":[{"type":"name","value":"projectWithInvalidIcon"},{"type":"icon", "value":"noexxxist"}]}' | /var/www/html/phorge/arcanist/bin/arc call-conduit --conduit-uri http://phorge.localhost --conduit-token "cli-xxx" project.edit --` * Succeed before applying this patch * Fail after applying this patch: ``` { "error": "ERR-CONDUIT-CORE", "errorMessage": "ERR-CONDUIT-CORE: Validation errors:\n - Value for \"project:icon\" is invalid: \"noexxxist\".", "response": null } ``` Reviewers: O1 Blessed Committers, mainframe98 Reviewed By: O1 Blessed Committers, mainframe98 Subscribers: mainframe98, tobiaswiese, valerio.bozzolan, Matthew, Cigaryno Maniphest Tasks: T16322 Differential Revision: https://we.phorge.it/D26459 --- .../PhabricatorProjectIconTransaction.php | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/src/applications/project/xaction/PhabricatorProjectIconTransaction.php b/src/applications/project/xaction/PhabricatorProjectIconTransaction.php index 932ce4bdc4..9c0cfb7634 100644 --- a/src/applications/project/xaction/PhabricatorProjectIconTransaction.php +++ b/src/applications/project/xaction/PhabricatorProjectIconTransaction.php @@ -39,4 +39,28 @@ final class PhabricatorProjectIconTransaction return PhabricatorProjectIconSet::getIconIcon($new); } + public function validateTransactions($object, array $xactions) { + $errors = array(); + + if (!$xactions) { + return $errors; + } + + foreach ($xactions as $xaction) { + $new_icon = $xaction->getNewValue(); + if (!PhabricatorProjectIconSet::getIconName($new_icon)) { + $errors[] = new PhabricatorApplicationTransactionValidationError( + self::TRANSACTIONTYPE, + pht('Invalid'), + pht( + 'Value for "%s" is invalid: "%s".', + self::TRANSACTIONTYPE, + $new_icon)); + break; + } + } + + return $errors; + } + } -- 2.51.2