You are here

protected static function RequestSanitizer::checkDestination in Drupal 8

Same name and namespace in other branches
  1. 9 core/lib/Drupal/Core/Security/RequestSanitizer.php \Drupal\Core\Security\RequestSanitizer::checkDestination()

Checks a destination string to see if it is dangerous.

Parameters

string $destination: The destination string to check.

array $whitelist: An array of keys to whitelist as safe.

Return value

array The dangerous keys found in the destination parameter.

1 call to RequestSanitizer::checkDestination()
RequestSanitizer::processParameterBag in core/lib/Drupal/Core/Security/RequestSanitizer.php
Processes a request parameter bag.

File

core/lib/Drupal/Core/Security/RequestSanitizer.php, line 130

Class

RequestSanitizer
Sanitizes user input.

Namespace

Drupal\Core\Security

Code

protected static function checkDestination($destination, array $whitelist) {
  $dangerous_keys = [];
  $parts = UrlHelper::parse($destination);

  // If there is a query string, check its query parameters.
  if (!empty($parts['query'])) {
    static::stripDangerousValues($parts['query'], $whitelist, $dangerous_keys);
  }
  return $dangerous_keys;
}