[SECURITY] Filter disallowed properties in form editor
[Packages/TYPO3.CMS.git] / typo3 / sysext / form / Classes / Domain / Configuration / FrameworkConfiguration / Extractors / FormElement / MultiValuePropertiesExtractor.php
1 <?php
2 declare(strict_types = 1);
3 namespace TYPO3\CMS\Form\Domain\Configuration\FrameworkConfiguration\Extractors\FormElement;
4
5 /*
6 * This file is part of the TYPO3 CMS project.
7 *
8 * It is free software; you can redistribute it and/or modify it under
9 * the terms of the GNU General Public License, either version 2
10 * of the License, or any later version.
11 *
12 * For the full copyright and license information, please read the
13 * LICENSE.txt file that was distributed with this source code.
14 *
15 * The TYPO3 project - inspiring people to share!
16 */
17
18 use TYPO3\CMS\Core\Utility\ArrayUtility;
19 use TYPO3\CMS\Form\Domain\Configuration\FrameworkConfiguration\Extractors\AbstractExtractor;
20
21 /**
22 * @internal
23 */
24 class MultiValuePropertiesExtractor extends AbstractExtractor
25 {
26
27 /**
28 * @param string $_
29 * @param mixed $value
30 * @param array $matches
31 */
32 public function __invoke(string $_, $value, array $matches)
33 {
34 [, $formElementType, $formEditorIndex] = $matches;
35
36 if (
37 $value !== 'Inspector-PropertyGridEditor'
38 && $value !== 'Inspector-MultiSelectEditor'
39 && $value !== 'Inspector-ValidationErrorMessageEditor'
40 ) {
41 return;
42 }
43
44 $propertyPath = implode(
45 '.',
46 [
47 'formElementsDefinition',
48 $formElementType,
49 'formEditor',
50 'editors',
51 $formEditorIndex,
52 'propertyPath',
53 ]
54 );
55
56 $result = $this->extractorDto->getResult();
57 $result['formElements'][$formElementType]['multiValueProperties'][] = ArrayUtility::getValueByPath(
58 $this->extractorDto->getPrototypeConfiguration(),
59 $propertyPath,
60 '.'
61 );
62 $this->extractorDto->setResult($result);
63 }
64 }