【发布时间】:2015-11-02 14:10:06
【问题描述】:
我正在使用Symfony's console component 编写一些命令行工具,其中一个使用WP-CLI 来建立一个WordPress 站点。特别是使用 wp option update 我遇到了 JSON 和引号的问题。
例如,运行类似:
shell_exec("wp option update blogdescription ''");
在数据库中生成文字 ''。事实上,每当我使用该命令时,如果它成功,我尝试在数据库中设置的任何内容都会被包含在单引号中。
然后是这样的:
$github_updater_args = [
'github_access_token'=>'',
'bitbucket_username'=>'username',
'bitbucket_password'=>'password',
'all-in-one-seo-populate-keywords'=>'1'
];
$github_updater_args = json_encode($github_updater_args);
var_dump($github_updater_args);
shell_exec("wp option update github_updater '$github_updater_args' --format=json");
转储结果:
string(200) "{"github_access_token":"","bitbucket_username":"devs@webspecdesign.com","bitbucket_password":"xxxxxxxxx","webspec-design-wordpress-core":"1","all-in-one-seo-populate-keywords":"1","webspec-smtp":"1"}"
这是有效的 JSON,但 wp 命令导致以下结果:
Error: Invalid JSON: '{github_access_token:,bitbucket_username:username,bitbucket_password:password,all-in-one-seo-populate-keywords:1}'
您会注意到引号已被删除,我认为这就是它所抱怨的?或者这就是它转储错误的方式?
不管怎样,然后我决定硬编码 JSON,所以:
shell_exec('wp option update github_updater \'{"github_access_token": "", "bitbucket_username": "username", "bitbucket_password": "password"}\' --format=json');
这给了我以下错误:
错误:位置参数太多:,bitbucket_username:用户名,bitbucket_password:密码}'
我打赌这两个问题是相关的。我想这可能是一个 WP-CLI 问题,所以我在那里打开了一个问题,但它是closed without reaching an answer。然而,我越是盯着它看,我就越觉得它可能是 Symfony 的东西。也许我肯定需要使用Process Component 而不是shell_exec?这就是它的设计目的吗?
更新:尝试了 Symfony 进程组件:
$process = new Process("wp option update blogdescription ''");
$process->run();
仍然得到我的两个报价。所以那里什么也没做。
【问题讨论】:
-
您基本上遭受了相当于 sql 注入攻击的 shell 的痛苦。你需要使用escapeshellcmd()
-
@MarcB 我认为这是以前建议的。我试过
shell_exec(escapeshellcmd("wp option update blogdescription 'gal'"));,博客的标语最终变成了'gal',引号和所有 -
不要转义整个 shell 命令行,只转义 json。记住。您至少要经过两个解析器:shell 和 wp。您需要转义 json 以便它通过 shell 解析器
-
shell_exec( "wp option update github_updater '" . escapeshellcmd($github_updater_args) . "' --format=json" );继续导致 Invalid JSON 错误
标签: json symfony symfony-process wp-cli symfony-console