Problem/Motivation

When running a security scanner against my site the module logs TypeError: count(): Argument #1 ($value) must be of type Countable|array, bool given in login_security_validate() (line 202 of /srv/www/html/modules/contrib/login_security/login_security.module) #0 [internal function]: login_security_validate(Array, Object(Drupal\Core\Form\FormState))

The scanner is still going, when it's done I'll have a look and see if I can figure out which form values are triggering this error. Possibly this is the same issue as #3143621: Validation function does not properly escape inputs when using preg_grep.

Steps to reproduce

Run a fuzzer against the login form, check the logs.

Proposed resolution

Check the return value from preg_grep and handle it appropriately.

Remaining tasks

Write the fix.

CommentFileSizeAuthor
#2 countable_error-3311976-1.patch815 bytestrobey
Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

cafuego created an issue. See original summary.

trobey’s picture

StatusFileSize
new815 bytes

preg_grep returns false if there are no matches, not an empty array.

trobey’s picture

Status: Active » Needs review
anybody’s picture

Status: Needs review » Needs work

Thanks @trobey - please use !empty() instead, which is fast and safe!

anybody’s picture

Status: Needs work » Needs review

Here we go, see MR!

grevil’s picture

Status: Needs review » Reviewed & tested by the community

LGTM!

  • Anybody committed d0ef88f9 on 2.x
    Issue #3311976 by trobey: Validate fucntion triggers PHP errors
    
anybody’s picture

Status: Reviewed & tested by the community » Fixed

Will be part of 2.1.0! :)

anybody’s picture

Title: Validate fucntion triggers PHP errors » Validate function triggers PHP errors

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.