Skip to content

Add escapeshell args for matomo domain, #AS-685 - #643

Merged
AltamashShaikh merged 1 commit into
5.x-devfrom
AS-685
Aug 20, 2026
Merged

Add escapeshell args for matomo domain, #AS-685#643
AltamashShaikh merged 1 commit into
5.x-devfrom
AS-685

Conversation

@AltamashShaikh

Copy link
Copy Markdown
Contributor

Description

Add escapeshell args for matomo domain, #AS-685

Issue No

Steps to Replicate the Issue

Checklist

  • [✔] Tested locally or on demo2/demo3?
  • [NA] New test case added/updated?
  • [NA] Are all newly added texts included via translation?
  • [NA] Are text sanitized properly? (Eg use of v-text v/s v-html for vue)
  • [✖] Version bumped?
  • [✔] I have understood, reviewed, and tested all AI outputs before use
  • [✔] All AI instructions respect security, IP, and privacy rules
  • [NA] Documentation updated?

@snake14 snake14 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Do we need to bump the version and release?

AI listed an item, but I don't know if I'd really consider it blocking:

Blocking

  1. No regression test covers the shell-injection fix in Importer.php:291 and ImporterGA4.php:343. Existing importer tests leave custom-variable slots at zero, so importCustomVariableSlots() returns before reaching passthru(). A future regression could therefore reintroduce command injection while CI remains green. This violates the matomo-test-runner regression-coverage requirement.

@AltamashShaikh
AltamashShaikh merged commit 26b3e8b into 5.x-dev Aug 20, 2026
9 of 10 checks passed
@AltamashShaikh
AltamashShaikh deleted the AS-685 branch August 20, 2026 01:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants