Merge pull request #56987 from nextcloud/backport/56982/stable28

[stable28] fix(comments): Check comment object
pull/57034/head
Joas Schilling 2025-12-11 09:44:40 +07:00 committed by GitHub
commit c82c2d9668
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
3 changed files with 33 additions and 7 deletions

@ -100,6 +100,10 @@ class EntityCollection extends RootCollection implements IProperties {
public function getChild($name) {
try {
$comment = $this->commentsManager->get($name);
if ($comment->getObjectType() !== $this->name
|| $comment->getObjectId() !== $this->id) {
throw new NotFound();
}
return new CommentNode(
$this->commentsManager,
$comment,
@ -153,8 +157,9 @@ class EntityCollection extends RootCollection implements IProperties {
*/
public function childExists($name) {
try {
$this->commentsManager->get($name);
return true;
$comment = $this->commentsManager->get($name);
return $comment->getObjectType() === $this->name
&& $comment->getObjectId() === $this->id;
} catch (NotFoundException $e) {
return false;
}

@ -76,14 +76,16 @@ class EntityCollectionTest extends \Test\TestCase {
}
public function testGetChild(): void {
$comment = $this->createMock(IComment::class);
$comment->method('getObjectType')
->willReturn('files');
$comment->method('getObjectId')
->willReturn('19');
$this->commentsManager->expects($this->once())
->method('get')
->with('55')
->willReturn(
$this->getMockBuilder(IComment::class)
->disableOriginalConstructor()
->getMock()
);
->willReturn($comment);
$node = $this->collection->getChild('55');
$this->assertTrue($node instanceof \OCA\DAV\Comments\CommentNode);
@ -135,6 +137,17 @@ class EntityCollectionTest extends \Test\TestCase {
}
public function testChildExistsTrue(): void {
$comment = $this->createMock(IComment::class);
$comment->method('getObjectType')
->willReturn('files');
$comment->method('getObjectId')
->willReturn('19');
$this->commentsManager->expects($this->once())
->method('get')
->with('44')
->willReturn($comment);
$this->assertTrue($this->collection->childExists('44'));
}

@ -1103,6 +1103,10 @@ class QueryBuilder implements IQueryBuilder {
* @return $this This QueryBuilder instance.
*/
public function orderBy($sort, $order = null) {
if ($order !== null && !in_array(strtoupper((string) $order), ['ASC', 'DESC'], true)) {
$order = null;
}
$this->queryBuilder->orderBy(
$this->helper->quoteColumnName($sort),
$order
@ -1120,6 +1124,10 @@ class QueryBuilder implements IQueryBuilder {
* @return $this This QueryBuilder instance.
*/
public function addOrderBy($sort, $order = null) {
if ($order !== null && !in_array(strtoupper((string) $order), ['ASC', 'DESC'], true)) {
$order = null;
}
$this->queryBuilder->addOrderBy(
$this->helper->quoteColumnName($sort),
$order