From 9e74b6fabf172397be50b06586571ac985568ab0 Mon Sep 17 00:00:00 2001 From: Andre Klapper Date: Mon, 1 Dec 2025 15:04:46 +0100 Subject: [PATCH] Fix PHP 8.1 "strlen(null)" exception in Auth for Missing Client ID Cookie Summary: `strlen()` was used in Phabricator to check if a generic value is a non-empty string. This behavior is deprecated since PHP 8.1. Phorge adopts `phutil_nonempty_string()` as a replacement. Note: this may highlight other absurd input values that might be worth correcting instead of just ignoring. If phutil_nonempty_string() throws an exception in your instance, report it to Phorge to evaluate and fix that specific corner case. ``` ERROR 8192: strlen(): Passing null to parameter #1 ($string) of type string is deprecated at [/var/www/html/phorge/phorge/src/applications/auth/provider/PhabricatorAuthProvider.php:570] ``` Also fix a similar issue a few lines below. Closes T16371 Test Plan: I was playing around with the OAuth Server prototype application; I think I had not copied the token and secret of the consumer back to the config yet while still trying to visit the Redirect URI. Don't remember details; sorry. Reviewers: O1 Blessed Committers, mainframe98 Reviewed By: O1 Blessed Committers, mainframe98 Subscribers: tobiaswiese, valerio.bozzolan, Matthew, Cigaryno Maniphest Tasks: T16371 Differential Revision: https://we.phorge.it/D26540 --- src/applications/auth/provider/PhabricatorAuthProvider.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/applications/auth/provider/PhabricatorAuthProvider.php b/src/applications/auth/provider/PhabricatorAuthProvider.php index be103f030e..f78a28bbe6 100644 --- a/src/applications/auth/provider/PhabricatorAuthProvider.php +++ b/src/applications/auth/provider/PhabricatorAuthProvider.php @@ -567,7 +567,7 @@ abstract class PhabricatorAuthProvider extends Phobject { public function getAuthCSRFCode(AphrontRequest $request) { $phcid = $request->getCookie(PhabricatorCookies::COOKIE_CLIENTID); - if (!strlen($phcid)) { + if (!phutil_nonempty_string($phcid)) { throw new AphrontMalformedRequestException( pht('Missing Client ID Cookie'), pht( @@ -584,7 +584,7 @@ abstract class PhabricatorAuthProvider extends Phobject { protected function verifyAuthCSRFCode(AphrontRequest $request, $actual) { $expect = $this->getAuthCSRFCode($request); - if (!strlen($actual)) { + if (!phutil_nonempty_string($actual)) { throw new Exception( pht( 'The authentication provider did not return a client state '. -- 2.51.2