Page MenuHomePhabricator

Wikibase doesn’t validate formatter options, can crash with different TypeErrors
Open, Needs TriagePublic


The wbformatvalue API has an options parameter that allows users to specify the FormatterOptions that will be used to format the value, as JSON. Several of Wikibase’s value formatters don’t really validate these options, so if an API user puts garbage in them, they can provoke various TypeErrors, For example, LatLongFormatter has options to customize the strings used for N/E/S/W, °/'/", set the format to float/dms/dm/dd and determine the floating point precision, where to put spacing, whether to use -1° or 1° S, and what the separator between latitude and longitude is. (Don’t ask me why this class is so amazingly configurable.) By setting the “north” option to an int instead, we get a type error.


  "value": {
    "latitude": 27.988055555556,
    "longitude": 86.925277777778,
    "altitude": null,
    "precision": 0.00027777777777778,
    "globe": ""
  "type": "globecoordinate"

options={"north": 1}

Exception caught: DataValues\\Geo\\Formatters\\LatLongFormatter::makeDirectionalIfNeeded(): Argument #2 ($positiveSymbol) must be of type string, int given