Guard against null permission_ids in getModulesByPermissionSlug()
modules.permission_ids is NULL for module 8 ("Szerviz kategoriak") on every
environment, and PHP 8.1 deprecates passing null to explode(). The notice was
only visible on prod because its index.php still has the stock
error_reporting(-1), whereas dev was previously changed to
E_ALL & ~E_DEPRECATED & ~E_WARNING & ~E_NOTICE.
- Skip rows whose permission_ids is null or empty. Behaviour-preserving:
explode(',', null) returned array(''), which matched no permission id, so
such modules were already excluded. Verified by simulating old vs new
against the real module rows across six permission-id values including 0,
'1' and 'admin' - identical results.
- Return early when the slug matches no permission, rather than dereferencing
null on the next line.
Does not address the wider issue that prod runs ENVIRONMENT='development'
with display_errors=1, so any notice is rendered to real visitors.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -164,10 +164,25 @@ public function getModulesByPermissionSlug($permissionSlug){
|
|||||||
$this->load->model('Module_model');
|
$this->load->model('Module_model');
|
||||||
$selectedPermission = $this->Module_model->getPermissionBySlug($permissionSlug);
|
$selectedPermission = $this->Module_model->getPermissionBySlug($permissionSlug);
|
||||||
|
|
||||||
|
// An unknown slug yields no permission at all; without this the line below
|
||||||
|
// dereferences null. No permission means no modules.
|
||||||
|
if(!$selectedPermission){
|
||||||
|
return array();
|
||||||
|
}
|
||||||
|
|
||||||
$query = $this->db->query('SELECT * FROM modules;');
|
$query = $this->db->query('SELECT * FROM modules;');
|
||||||
$results = $query->result();
|
$results = $query->result();
|
||||||
$resultArray = array();
|
$resultArray = array();
|
||||||
foreach($results as $resultItem){
|
foreach($results as $resultItem){
|
||||||
|
// modules.permission_ids is NULL for at least one row (module 8,
|
||||||
|
// 'Szerviz kategoriak') on every environment. Passing null to explode()
|
||||||
|
// is deprecated in PHP 8.1 and emits a notice. A module with no
|
||||||
|
// permissions is visible to nobody, so skipping it keeps the previous
|
||||||
|
// behaviour - explode(',', null) returned array('') which matched nothing.
|
||||||
|
if($resultItem->permission_ids === null || $resultItem->permission_ids === ''){
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
$permissionIdsArray = explode(',', $resultItem->permission_ids);
|
$permissionIdsArray = explode(',', $resultItem->permission_ids);
|
||||||
if(in_array($selectedPermission->permission_id, $permissionIdsArray)){
|
if(in_array($selectedPermission->permission_id, $permissionIdsArray)){
|
||||||
$resultArray[] = $resultItem;
|
$resultArray[] = $resultItem;
|
||||||
|
|||||||
Reference in New Issue
Block a user