Version in base suite: 1.6.18+dfsg-0+deb13u1 Base version: roundcube_1.6.18+dfsg-0+deb13u1 Target version: roundcube_1.6.19+dfsg-0+deb13u1 Base file: /srv/ftp-master.debian.org/ftp/pool/main/r/roundcube/roundcube_1.6.18+dfsg-0+deb13u1.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/r/roundcube/roundcube_1.6.19+dfsg-0+deb13u1.dsc CHANGELOG.md | 16 debian/changelog | 25 debian/patches/Avoid-dependency-on-new-package-mlocati-ip-lib.patch | 21 debian/patches/Fix-FTBFS-with-phpunit-11.patch | 268 ++++++---- debian/patches/Fix-PHP-Warning-Undefined-variable-tmp_command-in-.-plugi.patch | 40 - debian/patches/Tests-Use-mocked-Guzzle-client-in-Modcss-action-test.patch | 4 debian/patches/fix-install-path.patch | 2 debian/patches/series | 1 plugins/markasjunk/drivers/cmd_learn.php | 2 program/actions/mail/compose.php | 5 program/actions/mail/index.php | 2 program/include/rcmail_sendmail.php | 5 program/lib/Roundcube/rcube_contacts.php | 37 - program/lib/Roundcube/rcube_message.php | 10 program/lib/Roundcube/rcube_mime.php | 8 program/lib/Roundcube/rcube_tnef_decoder.php | 9 program/lib/Roundcube/rcube_utils.php | 6 program/lib/Roundcube/rcube_washtml.php | 15 public_html/plugins/markasjunk/drivers/cmd_learn.php | 2 tests/Actions/Contacts/GroupAddmembers.php | 76 ++ tests/Actions/Contacts/GroupDelmembers.php | 39 + tests/Actions/Mail/Compose.php | 27 + tests/Actions/Mail/Index.php | 17 tests/Framework/Message.php | 44 - tests/Framework/TnefDecoder.php | 21 tests/Framework/Utils.php | 5 tests/Framework/Washtml.php | 49 + tests/MessageMock.php | 47 + tests/Rcmail/Sendmail.php | 9 tests/bootstrap.php | 1 30 files changed, 576 insertions(+), 237 deletions(-) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp6do418_1/roundcube_1.6.18+dfsg-0+deb13u1.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp6do418_1/roundcube_1.6.19+dfsg-0+deb13u1.dsc: no acceptable signature found diff -Nru roundcube-1.6.18+dfsg/CHANGELOG.md roundcube-1.6.19+dfsg/CHANGELOG.md --- roundcube-1.6.18+dfsg/CHANGELOG.md 2026-08-09 07:48:13.000000000 +0000 +++ roundcube-1.6.19+dfsg/CHANGELOG.md 2026-09-06 08:27:09.000000000 +0000 @@ -2,6 +2,22 @@ ## Unreleased +- Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294) +- Security: Fix CSS declaration smuggling via un-encoded ampersand emission +- Security: Fix CSS property injection via body `background` attribute +- Security: Fix email header injection via bare CR in the subject field +- Security: Fix email header injection via C-escape \r in the recipient display name +- Security: Fix email header injection via identity's organization field +- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL +- Security: Fix XSS in the HTML editor using text/enriched part content +- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book +- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL +- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes +- Security: Fix remote-content blocker bypass via SVG SMIL src animation +- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses + +## Release 1.6.18 + - Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274) - Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269) - Security: Add basic validation for content proxied by the css proxy diff -Nru roundcube-1.6.18+dfsg/debian/changelog roundcube-1.6.19+dfsg/debian/changelog --- roundcube-1.6.18+dfsg/debian/changelog 2026-08-10 13:45:10.000000000 +0000 +++ roundcube-1.6.19+dfsg/debian/changelog 2026-09-06 11:22:41.000000000 +0000 @@ -1,8 +1,29 @@ +roundcube (1.6.19+dfsg-0+deb13u1) trixie-security; urgency=high + + * New upstream security and bugfix release (closes: #1146838). + + Fix CSS declaration smuggling via un-encoded ampersand emission. + + Fix CSS property injection via body `background` attribute. + + Fix email header injection via bare CR in the subject field. + + Fix email header injection via C-escape `\r` in the recipient display + name. + + Fix email header injection via identity's organization field. + + Fix zero-click stored XSS via TNEF MIME tag injection in the attachment + URL. + + Fix XSS in the HTML editor using text/enriched part content. + + Fix cross-user access in contact group membership (add/remove) in the + SQL address book. + + Fix `is_local_url()` bypass via trailing-dot FQDN in stylesheet URL. + + Fix remote content blocking bypass via CSS escapes in FuncIRI + attributes. + + Fix remote-content blocker bypass via SVG SMIL src animation. + * Refresh d/patches and remove those applied upstream. + + -- Guilhem Moulin Sun, 06 Sep 2026 13:22:41 +0200 + roundcube (1.6.18+dfsg-0+deb13u1) trixie-security; urgency=high * New upstream security and bugfix release (closes: #1144059). - + Fix CVE-2026-74998: Content proxied by the css proxy is not validated - validation. + + Fix CVE-2026-74998: Content proxied by the CSS proxy is not validated. + Fix CVE-2026-75006: SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 subnets. + Fix CVE-2026-75006: SSRF filter bypass via various forms of diff -Nru roundcube-1.6.18+dfsg/debian/patches/Avoid-dependency-on-new-package-mlocati-ip-lib.patch roundcube-1.6.19+dfsg/debian/patches/Avoid-dependency-on-new-package-mlocati-ip-lib.patch --- roundcube-1.6.18+dfsg/debian/patches/Avoid-dependency-on-new-package-mlocati-ip-lib.patch 2026-08-10 13:45:10.000000000 +0000 +++ roundcube-1.6.19+dfsg/debian/patches/Avoid-dependency-on-new-package-mlocati-ip-lib.patch 2026-09-06 11:22:41.000000000 +0000 @@ -11,9 +11,9 @@ Forwarded: not-needed --- composer.json-dist | 3 +- - program/lib/Roundcube/rcube_utils.php | 164 +++++++++++++++++++++++++++++----- + program/lib/Roundcube/rcube_utils.php | 163 +++++++++++++++++++++++++++++----- tests/Framework/Utils.php | 85 ++++++++++++++++++ - 3 files changed, 226 insertions(+), 26 deletions(-) + 3 files changed, 225 insertions(+), 26 deletions(-) diff --git a/composer.json-dist b/composer.json-dist index 1807004..ca3de26 100644 @@ -30,7 +30,7 @@ "require-dev": { "phpunit/phpunit": "^9" diff --git a/program/lib/Roundcube/rcube_utils.php b/program/lib/Roundcube/rcube_utils.php -index 673ce69..0c2e293 100644 +index b10103e..2c1aff8 100644 --- a/program/lib/Roundcube/rcube_utils.php +++ b/program/lib/Roundcube/rcube_utils.php @@ -1,8 +1,5 @@ @@ -159,7 +159,7 @@ /** * Check if an URL point to a local network location. * -@@ -434,14 +541,9 @@ class rcube_utils +@@ -434,11 +541,6 @@ class rcube_utils $host = parse_url($url, \PHP_URL_HOST); if (is_string($host)) { @@ -168,14 +168,10 @@ - | ParseStringFlag::IPV4ADDRESS_MAYBE_NON_QUAD_DOTTED - | ParseStringFlag::MAY_INCLUDE_ZONEID; - - $host = trim($host, '[]'); - -- // IPLib does not seem to work with IPv6 syntax for IPv4 addresses -+ /* IPv4-mapped IPv6 addresses (RFC4291 2.5.5) */ - $host = preg_replace('/^[0:]*:ffff:/i', '', $host); + $host = trim($host, '[].'); if (preg_match('/([0-9a-f.-]+)\.(nip|sslip)\.io$/i', $host, $matches)) { -@@ -455,25 +557,39 @@ class rcube_utils +@@ -452,26 +554,39 @@ class rcube_utils } } @@ -198,6 +194,7 @@ - '::1/128', - 'fc00::/7', - 'fe80::/10', // IPv6 link-local +- '::ffff:0:0/96', // RFC5156 + if (is_string($address = \rcube_utils::inet_pton2($host))) { + $nets = [ + ['0.0.0.0', '0.0.0.0'], @@ -217,7 +214,7 @@ + } + $nets[] = ['::1', '::1']; + $nets[] = ['fc00::', 'fdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff']; -+ $nets[] = ['fe80::', 'febf:ffff:ffff:ffff:ffff:ffff:ffff:ffff']; ++ $nets[] = ['fe80::', 'febf:ffff:ffff:ffff:ffff:ffff:ffff:ffff']; // IPv6 link-local + } - foreach ($nets as $net) { @@ -231,7 +228,7 @@ } } diff --git a/tests/Framework/Utils.php b/tests/Framework/Utils.php -index 4b8e584..8c69f72 100644 +index 98f53d0..757c1c4 100644 --- a/tests/Framework/Utils.php +++ b/tests/Framework/Utils.php @@ -571,6 +571,86 @@ class Framework_Utils extends TestCase diff -Nru roundcube-1.6.18+dfsg/debian/patches/Fix-FTBFS-with-phpunit-11.patch roundcube-1.6.19+dfsg/debian/patches/Fix-FTBFS-with-phpunit-11.patch --- roundcube-1.6.18+dfsg/debian/patches/Fix-FTBFS-with-phpunit-11.patch 2026-08-10 13:45:10.000000000 +0000 +++ roundcube-1.6.19+dfsg/debian/patches/Fix-FTBFS-with-phpunit-11.patch 2026-09-06 11:22:41.000000000 +0000 @@ -61,10 +61,10 @@ tests/Actions/Contacts/Delete.php | 15 +- tests/Actions/Contacts/Edit.php | 23 ++- tests/Actions/Contacts/Export.php | 23 ++- - tests/Actions/Contacts/GroupAddmembers.php | 23 ++- + tests/Actions/Contacts/GroupAddmembers.php | 27 +-- tests/Actions/Contacts/GroupCreate.php | 23 ++- tests/Actions/Contacts/GroupDelete.php | 23 ++- - tests/Actions/Contacts/GroupDelmembers.php | 23 ++- + tests/Actions/Contacts/GroupDelmembers.php | 25 +-- tests/Actions/Contacts/GroupRename.php | 23 ++- tests/Actions/Contacts/Import.php | 13 +- tests/Actions/Contacts/Index.php | 28 +-- @@ -90,7 +90,7 @@ tests/Actions/Mail/Autocomplete.php | 10 +- tests/Actions/Mail/Bounce.php | 10 +- tests/Actions/Mail/CheckRecent.php | 10 +- - tests/Actions/Mail/Compose.php | 12 +- + tests/Actions/Mail/Compose.php | 22 ++- tests/Actions/Mail/Copy.php | 25 +-- tests/Actions/Mail/Delete.php | 10 +- tests/Actions/Mail/FolderExpunge.php | 33 ++-- @@ -177,7 +177,7 @@ tests/Framework/ImapSearch.php | 12 +- tests/Framework/Ldap.php | 17 +- tests/Framework/LdapGeneric.php | 14 +- - tests/Framework/Message.php | 24 +-- + tests/Framework/Message.php | 28 +-- tests/Framework/MessageHeader.php | 12 +- tests/Framework/MessagePart.php | 12 +- tests/Framework/Mime.php | 56 +++--- @@ -199,7 +199,7 @@ tests/Framework/Spoofchecker.php | 14 +- tests/Framework/StringReplacer.php | 20 +- tests/Framework/Text2Html.php | 22 ++- - tests/Framework/TnefDecoder.php | 16 +- + tests/Framework/TnefDecoder.php | 18 +- tests/Framework/User.php | 30 +-- tests/Framework/Utils.php | 209 +++++++++++---------- tests/Framework/VCard.php | 40 ++-- @@ -222,7 +222,7 @@ tests/StderrMock.php | 15 +- tests/StorageMock.php | 4 +- tests/bootstrap.php | 21 ++- - 213 files changed, 2501 insertions(+), 1794 deletions(-) + 213 files changed, 2514 insertions(+), 1803 deletions(-) diff --git a/plugins/acl/tests/Acl.php b/plugins/acl/tests/Acl.php index 94e0bd4..0ad987f 100644 @@ -2444,7 +2444,7 @@ { $this->markTestIncomplete(); diff --git a/tests/Actions/Contacts/GroupAddmembers.php b/tests/Actions/Contacts/GroupAddmembers.php -index cd05399..50b1d1a 100644 +index 3da464e..4c2675f 100644 --- a/tests/Actions/Contacts/GroupAddmembers.php +++ b/tests/Actions/Contacts/GroupAddmembers.php @@ -1,21 +1,24 @@ @@ -2505,6 +2505,22 @@ $query = $db->query('SELECT * FROM `contactgroups` WHERE `user_id` = 1 AND `name` = \'test-group\''); $result = $db->fetch_assoc($query); $gid = $result['contactgroup_id']; +@@ -82,13 +85,13 @@ class Actions_Contacts_Group_Addmembers extends ActionTestCase + */ + public function test_group_addmembers_cross_user() + { +- $action = new rcmail_action_contacts_group_addmembers(); ++ $action = new \rcmail_action_contacts_group_addmembers(); + $output = $this->initOutput(\rcmail_action::MODE_AJAX, 'contacts', 'add-members'); + + self::initDB('contacts'); + + // Create another user and his group/contact +- $db = rcmail::get_instance()->get_dbh(); ++ $db = \rcmail::get_instance()->get_dbh(); + $db->query('DELETE FROM `contactgroupmembers`'); + $db->query("INSERT INTO `users` (`user_id`, `username`, `mail_host`) VALUES (2, 'test2@example.com', 'localhost')"); + $db->query("INSERT INTO `contactgroups` (`user_id`, `name`) VALUES (2, 'test-group')"); diff --git a/tests/Actions/Contacts/GroupCreate.php b/tests/Actions/Contacts/GroupCreate.php index f94a730..cfe434f 100644 --- a/tests/Actions/Contacts/GroupCreate.php @@ -2632,7 +2648,7 @@ $result = $db->fetch_assoc($query); $gid = $result['contactgroup_id']; diff --git a/tests/Actions/Contacts/GroupDelmembers.php b/tests/Actions/Contacts/GroupDelmembers.php -index d8c4a76..db40832 100644 +index 908399a..20312e3 100644 --- a/tests/Actions/Contacts/GroupDelmembers.php +++ b/tests/Actions/Contacts/GroupDelmembers.php @@ -1,21 +1,24 @@ @@ -2693,6 +2709,15 @@ $query = $db->query('SELECT * FROM `contactgroups` WHERE `user_id` = 1 AND `name` = \'test-group\''); $result = $db->fetch_assoc($query); $gid = $result['contactgroup_id']; +@@ -84,7 +87,7 @@ class Actions_Contacts_Group_Delmembers extends ActionTestCase + */ + public function test_group_delmembers_cross_user() + { +- $action = new rcmail_action_contacts_group_addmembers(); ++ $action = new \rcmail_action_contacts_group_addmembers(); + $output = $this->initOutput(\rcmail_action::MODE_AJAX, 'contacts', 'del-members'); + + self::initDB('contacts'); diff --git a/tests/Actions/Contacts/GroupRename.php b/tests/Actions/Contacts/GroupRename.php index 1cdf598..f6234c1 100644 --- a/tests/Actions/Contacts/GroupRename.php @@ -3769,16 +3794,18 @@ } } diff --git a/tests/Actions/Mail/Compose.php b/tests/Actions/Mail/Compose.php -index c66f64d..ca681b7 100644 +index 7da23bb..788c655 100644 --- a/tests/Actions/Mail/Compose.php +++ b/tests/Actions/Mail/Compose.php -@@ -1,9 +1,11 @@ +@@ -1,9 +1,13 @@ assertSame('> ', $action->quote_text('')); +@@ -42,18 +46,18 @@ class Actions_Mail_Compose extends ActionTestCase + */ + public function test_compose_part_body_enriched() + { +- $message = new MessageMock(123); ++ $message = new \MessageMock(123); + $set_part = function ($body) use ($message) { +- $part = new rcube_message_part(); ++ $part = new \rcube_message_part(); + $part->mime_id = '1'; + [$part->ctype_primary, $part->ctype_secondary] = explode('/', $part->mimetype = 'text/enriched'); + $message->set_part_body(1, $body); + return $part; + }; + +- $action = new rcmail_action_mail_compose(); ++ $action = new \rcmail_action_mail_compose(); + setProperty($action, 'MESSAGE', $message); +- setProperty($action, 'COMPOSE', ['mode' => rcmail_sendmail::MODE_NONE]); ++ setProperty($action, 'COMPOSE', ['mode' => \rcmail_sendmail::MODE_NONE]); + + $part = $set_part('the-textTest'); + $result = $action->compose_part_body($part, true); diff --git a/tests/Actions/Mail/Copy.php b/tests/Actions/Mail/Copy.php index 92ca6ee..2709784 100644 --- a/tests/Actions/Mail/Copy.php @@ -4157,7 +4207,7 @@ } } diff --git a/tests/Actions/Mail/Index.php b/tests/Actions/Mail/Index.php -index d3fcca2..e9ceca0 100644 +index 5a5dbe6..be0f3a8 100644 --- a/tests/Actions/Mail/Index.php +++ b/tests/Actions/Mail/Index.php @@ -1,9 +1,14 @@ @@ -4348,7 +4398,7 @@ $this->assertDoesNotMatchRegularExpression('/data:text/', $washed, "Remove data:text/html links"); $this->assertDoesNotMatchRegularExpression('/vbscript:/', $washed, "Remove vbscript: links"); -@@ -458,12 +463,13 @@ class Actions_Mail_Index extends ActionTestCase +@@ -475,12 +480,13 @@ class Actions_Mail_Index extends ActionTestCase * Test washtml class on non-unicode characters (#1487813) * @group mbstring */ @@ -4364,7 +4414,7 @@ $this->assertMatchesRegularExpression('/

(символ|симол)<\/p>/', $washed, "Remove non-unicode characters from HTML message body"); } -@@ -473,7 +479,7 @@ class Actions_Mail_Index extends ActionTestCase +@@ -490,7 +496,7 @@ class Actions_Mail_Index extends ActionTestCase */ function test_meta_insertion() { @@ -4373,7 +4423,7 @@ $meta = ''; $args = [ -@@ -483,27 +489,27 @@ class Actions_Mail_Index extends ActionTestCase +@@ -500,27 +506,27 @@ class Actions_Mail_Index extends ActionTestCase ]; $body = 'Test1
Test2'; @@ -4407,7 +4457,7 @@ $this->assertTrue(strpos($washed, "$meta") === 0, "Meta tag insertion (6)"); $this->assertTrue(strpos($washed, "Test2") > 0, "Meta tag insertion (7)"); } -@@ -513,13 +519,13 @@ class Actions_Mail_Index extends ActionTestCase +@@ -530,13 +536,13 @@ class Actions_Mail_Index extends ActionTestCase */ function test_plaintext() { @@ -4424,7 +4474,7 @@ $this->assertMatchesRegularExpression( '/nobody@roundcube.net<\/a>/', -@@ -543,7 +549,7 @@ class Actions_Mail_Index extends ActionTestCase +@@ -560,7 +566,7 @@ class Actions_Mail_Index extends ActionTestCase */ function test_mailto() { @@ -4433,7 +4483,7 @@ $part = $this->get_html_part('src/mailto.txt'); $params = ['container_id' => 'foo', 'safe' => false]; -@@ -562,10 +568,10 @@ class Actions_Mail_Index extends ActionTestCase +@@ -579,10 +585,10 @@ class Actions_Mail_Index extends ActionTestCase */ function test_html_comments() { @@ -4446,7 +4496,7 @@ // #1487759 $this->assertMatchesRegularExpression('|

test1

|', $washed, "Buggy HTML comments"); -@@ -578,17 +584,17 @@ class Actions_Mail_Index extends ActionTestCase +@@ -595,17 +601,17 @@ class Actions_Mail_Index extends ActionTestCase */ public function test_html_links() { @@ -4467,7 +4517,7 @@ // allow external links, add target and noreferrer $this->assertStringContainsString('fulltext_search_filter('test', ['dn']); diff --git a/tests/Framework/Message.php b/tests/Framework/Message.php -index 3e40e93..50607b7 100644 +index 0d00e45..5ec9e17 100644 --- a/tests/Framework/Message.php +++ b/tests/Framework/Message.php @@ -1,20 +1,22 @@ @@ -8592,16 +8642,27 @@ $this->assertSame('test', $result); } -@@ -25,7 +27,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase +@@ -24,7 +26,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase + */ + public function test_get_part_url() + { +- $message = new MessageMock(10, 'Test'); ++ $message = new \MessageMock(10, 'Test'); + $message->mime_parts[1] = new \rcube_message_part(); + + $url = $message->get_part_url(1, 'test&test=1'); +@@ -38,8 +40,8 @@ class Framework_Message extends PHPUnit\Framework\TestCase + */ public function test_tnef_decode() { - $message = new rcube_message_test(123); +- $message = new MessageMock(123); - $part = new rcube_message_part(); ++ $message = new \MessageMock(123); + $part = new \rcube_message_part(); - $part->mime_id = 1; + $part->mime_id = '1'; $message->set_part_body(1, ''); -@@ -37,7 +39,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase +@@ -51,7 +53,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase $result = $message->tnef_decode($part); $this->assertCount(1, $result); @@ -8610,7 +8671,7 @@ $this->assertSame('winmail.1.html', $result[0]->mime_id); $this->assertSame('text/html', $result[0]->mimetype); $this->assertSame(5360, $result[0]->size); -@@ -48,7 +50,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase +@@ -62,7 +64,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase $result = $message->tnef_decode($part); $this->assertCount(1, $result); @@ -8619,16 +8680,18 @@ $this->assertSame('winmail.1.0', $result[0]->mime_id); $this->assertSame('application/octet-stream', $result[0]->mimetype); $this->assertSame(244, $result[0]->size); -@@ -62,7 +64,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase +@@ -75,8 +77,8 @@ class Framework_Message extends PHPUnit\Framework\TestCase + */ public function test_uu_decode() { - $message = new rcube_message_test(123); +- $message = new MessageMock(123); - $part = new rcube_message_part(); ++ $message = new \MessageMock(123); + $part = new \rcube_message_part(); - $part->mime_id = 1; + $part->mime_id = '1'; $message->set_part_body(1, ''); -@@ -76,7 +78,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase +@@ -90,7 +92,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase $result = $message->uu_decode($part); $this->assertCount(1, $result); @@ -8637,15 +8700,6 @@ $this->assertSame('uu.1.0', $result[0]->mime_id); $this->assertSame('text/plain', $result[0]->mimetype); $this->assertSame(4, $result[0]->size); -@@ -88,7 +90,7 @@ class Framework_Message extends PHPUnit\Framework\TestCase - /** - * rcube_message wrapper for easier testing (without accessing IMAP) - */ --class rcube_message_test extends rcube_message -+class rcube_message_test extends \rcube_message - { - private $part_bodies = []; - diff --git a/tests/Framework/MessageHeader.php b/tests/Framework/MessageHeader.php index 8ba0ab2..f8785a5 100644 --- a/tests/Framework/MessageHeader.php @@ -9829,16 +9883,18 @@ $this->assertEquals($expected, $html); diff --git a/tests/Framework/TnefDecoder.php b/tests/Framework/TnefDecoder.php -index 8fb9632..6fec023 100644 +index ff3bfe9..73d6f40 100644 --- a/tests/Framework/TnefDecoder.php +++ b/tests/Framework/TnefDecoder.php -@@ -1,11 +1,13 @@ +@@ -1,11 +1,15 @@ decompress($body); $this->assertSame('one-file', trim($result['message']['name'])); -@@ -60,7 +62,7 @@ class Framework_TnefDecoder extends PHPUnit\Framework\TestCase +@@ -60,7 +64,7 @@ class Framework_TnefDecoder extends PHPUnit\Framework\TestCase function test_decompress_body() { $body = file_get_contents(TESTS_DIR . 'src/body.tnef'); @@ -9867,7 +9923,7 @@ $result = $tnef->decompress($body); $this->assertSame('Untitled.html', trim($result['message']['name'])); -@@ -70,7 +72,7 @@ class Framework_TnefDecoder extends PHPUnit\Framework\TestCase +@@ -70,7 +74,7 @@ class Framework_TnefDecoder extends PHPUnit\Framework\TestCase $this->assertSame(5360, $result['message']['size']); $this->assertMatchesRegularExpression('/^<\!DOCTYPE HTML/', $result['message']['stream']); @@ -9876,7 +9932,7 @@ $result = $tnef->decompress($body, true); $this->assertCount(0, $result['attachments']); -@@ -120,7 +122,7 @@ class Framework_TnefDecoder extends PHPUnit\Framework\TestCase +@@ -135,7 +139,7 @@ class Framework_TnefDecoder extends PHPUnit\Framework\TestCase function test_rtf2text() { $body = file_get_contents(TESTS_DIR . 'src/sample.rtf'); @@ -9996,7 +10052,7 @@ $idents = $user->list_identities(); diff --git a/tests/Framework/Utils.php b/tests/Framework/Utils.php -index 4cec5ab..4b8e584 100644 +index 26cf452..98f53d0 100644 --- a/tests/Framework/Utils.php +++ b/tests/Framework/Utils.php @@ -1,11 +1,15 @@ @@ -10371,7 +10427,7 @@ $this->assertSame($v[2], $result); } } -@@ -641,7 +651,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -646,7 +656,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $datetime => $ts) { @@ -10380,7 +10436,7 @@ $this->assertSame($ts, $result, "Error parsing date: $datetime"); } } -@@ -668,7 +678,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -673,7 +683,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $datetime => $ts) { @@ -10389,7 +10445,7 @@ $this->assertSame($ts, $result ? $result->format('Y-m-d') : false, "Error parsing date: $datetime"); } -@@ -678,7 +688,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -683,7 +693,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $datetime => $ts) { @@ -10398,7 +10454,7 @@ $this->assertSame($ts, $result ? $result->format('Y-m-d H:i:s') : false, "Error parsing date: $datetime"); } -@@ -687,7 +697,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -692,7 +702,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $datetime => $ts) { @@ -10407,7 +10463,7 @@ $this->assertSame($ts, $result ? $result->format('Y-m-d H:i:s O') : false, "Error parsing date: $datetime"); } } -@@ -697,17 +707,17 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -702,17 +712,17 @@ class Framework_Utils extends PHPUnit\Framework\TestCase */ function test_anytodatetime_timezone() { @@ -10428,7 +10484,7 @@ if ($result) $result->setTimezone($tz); // move to target timezone for comparison $this->assertSame($ts, $result ? $result->format('Y-m-d H:i') : false, "Error parsing date: $datetime"); } -@@ -726,7 +736,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -731,7 +741,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $data) { @@ -10437,7 +10493,7 @@ $this->assertSame($data[2], $result, "Error formatting date: " . $data[0]); } } -@@ -745,7 +755,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -750,7 +760,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $input => $output) { @@ -10446,7 +10502,7 @@ $this->assertSame($output, $result); } } -@@ -770,7 +780,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -775,7 +785,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $input => $output) { @@ -10455,7 +10511,7 @@ $this->assertSame($output, $result, "Error normalizing '$input'"); } } -@@ -793,7 +803,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -798,7 +808,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase ]; foreach ($test as $idx => $params) { @@ -10464,7 +10520,7 @@ $this->assertSame($params[2], $result, "words_match() at index $idx"); } } -@@ -819,7 +829,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -824,7 +834,7 @@ class Framework_Utils extends PHPUnit\Framework\TestCase } foreach ($test as $input => $output) { @@ -10473,7 +10529,7 @@ $this->assertSame($output, $result); } } -@@ -829,17 +839,17 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -834,17 +844,17 @@ class Framework_Utils extends PHPUnit\Framework\TestCase */ function test_random_bytes() { @@ -10497,7 +10553,7 @@ { /* -@@ -876,9 +886,10 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -881,9 +891,10 @@ class Framework_Utils extends PHPUnit\Framework\TestCase * @param string $encoded Encoded email address * @dataProvider data_idn_convert */ @@ -10509,7 +10565,7 @@ } /** -@@ -888,9 +899,10 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -893,9 +904,10 @@ class Framework_Utils extends PHPUnit\Framework\TestCase * @param string $encoded Encoded email address * @dataProvider data_idn_convert */ @@ -10521,7 +10577,7 @@ } /** -@@ -898,14 +910,14 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -903,14 +915,14 @@ class Framework_Utils extends PHPUnit\Framework\TestCase */ function test_idn_to_ascii_special() { @@ -10539,7 +10595,7 @@ { return [ ['%z', 'hostname', 'hostname'], -@@ -920,15 +932,16 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -925,15 +937,16 @@ class Framework_Utils extends PHPUnit\Framework\TestCase * * @dataProvider data_parse_host */ @@ -10558,7 +10614,7 @@ { return [ [['hostname', null, null], ['hostname', null, null]], -@@ -951,15 +964,16 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -956,15 +969,16 @@ class Framework_Utils extends PHPUnit\Framework\TestCase * * @dataProvider data_parse_host_uri */ @@ -10577,7 +10633,7 @@ return [ ['both', 'Fwd: Re: Test subject both', 'Test subject both'], ['both', 'Re: Fwd: Test subject both', 'Test subject both'], -@@ -977,8 +991,9 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -982,8 +996,9 @@ class Framework_Utils extends PHPUnit\Framework\TestCase * * @dataProvider data_remove_subject_prefix */ @@ -10588,7 +10644,7 @@ } /** -@@ -986,13 +1001,13 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -991,13 +1006,13 @@ class Framework_Utils extends PHPUnit\Framework\TestCase */ function test_server_name() { @@ -10605,7 +10661,7 @@ } /** -@@ -1002,31 +1017,31 @@ class Framework_Utils extends PHPUnit\Framework\TestCase +@@ -1007,31 +1022,31 @@ class Framework_Utils extends PHPUnit\Framework\TestCase { $_SERVER['test'] = 'test.com'; @@ -10804,7 +10860,7 @@ $this->assertSame($result, "BEGIN:VCARD\r\nVERSION:3.0\r\nFN:\r\nN:;;;;\r\nEND:VCARD"); diff --git a/tests/Framework/Washtml.php b/tests/Framework/Washtml.php -index 6b2d026..90b680e 100644 +index 03ab2db..a61f7da 100644 --- a/tests/Framework/Washtml.php +++ b/tests/Framework/Washtml.php @@ -1,11 +1,14 @@ @@ -10962,22 +11018,22 @@ $this->assertSame($this->cleanupResult($washed), $expected, 'White-space and new-line characters handling'); @@ -307,7 +310,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase $html = ""; - $exp = ""; + $exp = ''; - $washer = new rcube_washtml; + $washer = new \rcube_washtml(); $washed = $washer->wash($html); - $this->assertTrue(strpos($washed, $exp) !== false, "Style quotes XSS issue (#1490227)"); + $this->assertStringContainsString($exp, $washed, 'Style quotes XSS issue (#1490227)'); @@ -315,7 +318,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase $html = ""; - $exp = ""; + $exp = ''; - $washer = new rcube_washtml; + $washer = new \rcube_washtml(); $washed = $washer->wash($html); - $this->assertTrue(strpos($washed, $exp) !== false, "Style quotes XSS issue (#1490227)"); + $this->assertStringContainsString($exp, $washed, 'Style quotes XSS issue (#1490227)'); @@ -333,7 +336,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase */ function test_title() @@ -11005,7 +11061,7 @@ { $svg1 = ""; -@@ -553,9 +556,10 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -573,9 +576,10 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase * * @dataProvider data_wash_svg_tests */ @@ -11017,7 +11073,7 @@ $washed = $washer->wash($input); $this->assertSame($expected, $this->cleanupResult($washed), "SVG content"); -@@ -564,7 +568,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -584,7 +588,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase /** * Test cases for various XSS issues */ @@ -11026,7 +11082,7 @@ { return [ [ -@@ -619,9 +623,10 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -660,9 +664,10 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase * * @dataProvider data_wash_xss_tests */ @@ -11038,7 +11094,7 @@ $washed = $washer->wash($input); $this->assertSame($expected, $this->cleanupResult($washed), "XSS issues"); -@@ -635,7 +640,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -676,7 +681,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase $html = ""; $exp = ""; @@ -11047,7 +11103,7 @@ $washed = $washer->wash($html); $this->assertTrue(strpos($washed, $exp) !== false, "Position:fixed (#5264)"); -@@ -679,7 +684,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -720,7 +725,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase I_D = \frac{1}{2} k_n \frac{W}{L} (V_{GS}-V_t)^2 '; @@ -11056,7 +11112,7 @@ $washed = $washer->wash($mathml); // remove whitespace between tags -@@ -696,7 +701,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -737,7 +742,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase { $html = ""; @@ -11065,7 +11121,7 @@ $washed = $washer->wash($html); $this->assertTrue($washer->extlinks); -@@ -704,7 +709,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase +@@ -745,7 +750,7 @@ class Framework_Washtml extends PHPUnit\Framework\TestCase $html = "