#1130: AgaviNumberValidator manipulates user input, following validators have 
the
risk to operate with manipulated data
---------------------------+------------------------------------------------
 Reporter:  Dennis Meckel  |        Owner:  dominik
     Type:  defect         |       Status:  closed 
 Priority:  high           |    Milestone:  1.0.2  
Component:  validation     |      Version:  1.0.1  
 Severity:  normal         |   Resolution:  wontfix
 Keywords:  hardening      |    Has_patch:  0      
---------------------------+------------------------------------------------
Changes (by david):

  * status:  new => closed
  * resolution:  => wontfix


Comment:

 The casting of the input value is by design for this validator.

 A separate ticket, #1136, describes the issue you mentioned where the
 value is inadvertently cast to an integer zero if the translation
 subsystem is enabled and used for parsing the input.

-- 
Ticket URL: <http://trac.agavi.org/ticket/1130#comment:1>
Agavi <http://www.agavi.org/>
An MVC Framework for PHP5



_______________________________________________
Agavi Tickets Mailing List
[email protected]
http://lists.agavi.org/mailman/listinfo/tickets

Reply via email to