diff --git a/libraries/classes/Config/ServerConfigChecks.php b/libraries/classes/Config/ServerConfigChecks.php index 7d49ee7705..86f05d2267 100644 --- a/libraries/classes/Config/ServerConfigChecks.php +++ b/libraries/classes/Config/ServerConfigChecks.php @@ -16,7 +16,6 @@ use function __; use function function_exists; use function htmlspecialchars; use function ini_get; -use function is_string; use function mb_strlen; use function sodium_crypto_secretbox_keygen; use function sprintf; @@ -47,17 +46,10 @@ class ServerConfigChecks */ public function performConfigChecks(): void { - $blowfishSecret = $this->cfg->get('blowfish_secret'); - $blowfishSecretSet = false; - $cookieAuthUsed = false; + /** @var string $blowfishSecret */ + $blowfishSecret = $this->cfg->get('blowfish_secret', ''); - [$cookieAuthUsed, $blowfishSecret, $blowfishSecretSet] = $this->performConfigChecksServers( - $cookieAuthUsed, - $blowfishSecret, - $blowfishSecretSet - ); - - $this->performConfigChecksCookieAuthUsed($cookieAuthUsed, $blowfishSecretSet, $blowfishSecret); + $this->performConfigChecksServers($blowfishSecret); // $cfg['AllowArbitraryServer'] // should be disabled @@ -122,19 +114,14 @@ class ServerConfigChecks /** * Check config of servers * - * @param bool $cookieAuthUsed Cookie auth is used - * @param string $blowfishSecret Blowfish secret - * @param bool $blowfishSecretSet Blowfish secret set - * - * @return array + * @param string $blowfishSecret Blowfish secret */ - protected function performConfigChecksServers( - $cookieAuthUsed, - $blowfishSecret, - $blowfishSecretSet - ) { + protected function performConfigChecksServers(string $blowfishSecret): void + { + $blowfishSecretSet = false; + $serverCnt = $this->cfg->getServerCount(); - $isCookieAuthUsed = (int) $cookieAuthUsed; + $isCookieAuthUsed = 0; for ($i = 1; $i <= $serverCnt; $i++) { $cookieAuthServer = ($this->cfg->getValue('Servers/' . $i . '/auth_type') === 'cookie'); $isCookieAuthUsed |= (int) $cookieAuthServer; @@ -144,11 +131,10 @@ class ServerConfigChecks ); $serverName = htmlspecialchars($serverName); - [$blowfishSecret, $blowfishSecretSet] = $this->performConfigChecksServersSetBlowfishSecret( - $blowfishSecret, - $cookieAuthServer, - $blowfishSecretSet - ); + if ($cookieAuthServer && (mb_strlen($blowfishSecret, '8bit') !== SODIUM_CRYPTO_SECRETBOX_KEYBYTES)) { + $blowfishSecretSet = true; + $this->cfg->set('blowfish_secret', sodium_crypto_secretbox_keygen()); + } // $cfg['Servers'][$i]['ssl'] // should be enabled if possible @@ -226,39 +212,24 @@ class ServerConfigChecks ); } - return [ - (bool) $isCookieAuthUsed, - $blowfishSecret, - $blowfishSecretSet, - ]; - } - - /** - * Set blowfish secret - * - * @param string|null $blowfishSecret Blowfish secret - * @param bool $cookieAuthServer Cookie auth is used - * @param bool $blowfishSecretSet Blowfish secret set - * - * @return array - */ - protected function performConfigChecksServersSetBlowfishSecret( - $blowfishSecret, - $cookieAuthServer, - $blowfishSecretSet - ): array { - if ( - $cookieAuthServer - && (! is_string($blowfishSecret) || mb_strlen($blowfishSecret, '8bit') !== SODIUM_CRYPTO_SECRETBOX_KEYBYTES) - ) { - $blowfishSecretSet = true; - $this->cfg->set('blowfish_secret', sodium_crypto_secretbox_keygen()); + // $cfg['blowfish_secret'] + // it's required for 'cookie' authentication + if ($isCookieAuthUsed === 0 || ! $blowfishSecretSet) { + return; } - return [ - $blowfishSecret, - $blowfishSecretSet, - ]; + // 'cookie' auth used, blowfish_secret was generated + SetupIndex::messagesSet( + 'notice', + 'blowfish_secret_created', + Descriptions::get('blowfish_secret'), + Sanitize::sanitizeMessage(__( + 'You didn\'t have blowfish secret set and have enabled ' + . '[kbd]cookie[/kbd] authentication, so a key was automatically ' + . 'generated for you. It is used to encrypt cookies; you don\'t need to ' + . 'remember it.' + )) + ); } /** @@ -334,38 +305,6 @@ class ServerConfigChecks ); } - /** - * Check config of servers - * - * @param bool $cookieAuthUsed Cookie auth is used - * @param bool $blowfishSecretSet Blowfish secret set - * @param string $blowfishSecret Blowfish secret - */ - protected function performConfigChecksCookieAuthUsed( - $cookieAuthUsed, - $blowfishSecretSet, - $blowfishSecret - ): void { - // $cfg['blowfish_secret'] - // it's required for 'cookie' authentication - if (! $cookieAuthUsed || ! $blowfishSecretSet) { - return; - } - - // 'cookie' auth used, blowfish_secret was generated - SetupIndex::messagesSet( - 'notice', - 'blowfish_secret_created', - Descriptions::get('blowfish_secret'), - Sanitize::sanitizeMessage(__( - 'You didn\'t have blowfish secret set and have enabled ' - . '[kbd]cookie[/kbd] authentication, so a key was automatically ' - . 'generated for you. It is used to encrypt cookies; you don\'t need to ' - . 'remember it.' - )) - ); - } - /** * Check configuration for login cookie */ diff --git a/phpstan-baseline.neon b/phpstan-baseline.neon index aa09784b2a..ad5d1802fa 100644 --- a/phpstan-baseline.neon +++ b/phpstan-baseline.neon @@ -620,26 +620,6 @@ parameters: count: 1 path: libraries/classes/Config/Forms/User/SqlForm.php - - - message: "#^Method PhpMyAdmin\\\\Config\\\\ServerConfigChecks\\:\\:performConfigChecksServers\\(\\) return type has no value type specified in iterable type array\\.$#" - count: 1 - path: libraries/classes/Config/ServerConfigChecks.php - - - - message: "#^Parameter \\#1 \\$blowfishSecret of method PhpMyAdmin\\\\Config\\\\ServerConfigChecks\\:\\:performConfigChecksServersSetBlowfishSecret\\(\\) expects string\\|null, bool\\|string\\|null given\\.$#" - count: 1 - path: libraries/classes/Config/ServerConfigChecks.php - - - - message: "#^Parameter \\#2 \\$blowfishSecret of method PhpMyAdmin\\\\Config\\\\ServerConfigChecks\\:\\:performConfigChecksServers\\(\\) expects string, mixed given\\.$#" - count: 1 - path: libraries/classes/Config/ServerConfigChecks.php - - - - message: "#^Parameter \\#3 \\$blowfishSecretSet of method PhpMyAdmin\\\\Config\\\\ServerConfigChecks\\:\\:performConfigChecksServersSetBlowfishSecret\\(\\) expects bool, bool\\|string\\|null given\\.$#" - count: 1 - path: libraries/classes/Config/ServerConfigChecks.php - - message: "#^Cannot access offset int\\|string on mixed\\.$#" count: 1 diff --git a/psalm-baseline.xml b/psalm-baseline.xml index 73df244425..bf5d3e9718 100644 --- a/psalm-baseline.xml +++ b/psalm-baseline.xml @@ -688,18 +688,7 @@ - - $blowfishSecret - $blowfishSecretSet - - - $blowfishSecret - $blowfishSecret - $blowfishSecretSet - $cookieAuthUsed - - - $blowfishSecret + $loginCookieValidity