From c7d7bc457a88ccfb2c11684e8a6382ed3615196a Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Thu, 24 Sep 2026 07:51:35 +0000 Subject: [PATCH 1/2] fix(site): drop blank alias domains on php site create `ee site create --type=php --alias-domains='a.com,,b.com,'` stored empty alias domains, which ended up in VIRTUAL_HOST and the nginx server_name. The list is now split with site-command's `split_alias_domains()`, which trims the names and drops blank entries. A flag passed without a value no longer becomes the alias domain `1`. --- src/PHP.php | 16 ++++------------ 1 file changed, 4 insertions(+), 12 deletions(-) diff --git a/src/PHP.php b/src/PHP.php index 1e4746e..8933dd0 100644 --- a/src/PHP.php +++ b/src/PHP.php @@ -11,6 +11,7 @@ use function EE\Site\Utils\get_public_dir; use function EE\Site\Utils\get_webroot; use function EE\Site\Utils\check_alias_in_db; +use function EE\Site\Utils\split_alias_domains; use function EE\Utils\get_flag_value; use function EE\Utils\get_value_if_flag_isset; @@ -189,9 +190,9 @@ public function create( $args, $assoc_args ) { \EE::error( sprintf( "Site %1\$s already exists. If you want to re-create it please delete the older one using:\n`ee site delete %1\$s`", $this->site_data['site_url'] ) ); } - $alias_domains = \EE\Utils\get_flag_value( $assoc_args, 'alias-domains', '' ); + $alias_domains = split_alias_domains( \EE\Utils\get_flag_value( $assoc_args, 'alias-domains', '' ) ); - $alias_domain_to_check = explode( ',', $alias_domains ); + $alias_domain_to_check = $alias_domains; $alias_domain_to_check[] = $this->site_data['site_url']; check_alias_in_db( $alias_domain_to_check ); @@ -219,16 +220,7 @@ public function create( $args, $assoc_args ) { } } - $this->site_data['alias_domains'] = $this->site_data['site_url']; - $this->site_data['alias_domains'] .= ','; - if ( ! empty( $alias_domains ) ) { - $comma_seprated_domains = explode( ',', $alias_domains ); - foreach ( $comma_seprated_domains as $domain ) { - $trimmed_domain = trim( $domain ); - $this->site_data['alias_domains'] .= $trimmed_domain . ','; - } - } - $this->site_data['alias_domains'] = substr( $this->site_data['alias_domains'], 0, - 1 ); + $this->site_data['alias_domains'] = implode( ',', array_merge( [ $this->site_data['site_url'] ], $alias_domains ) ); $supported_php_versions = [ 5.6, 7.0, 7.2, 7.3, 7.4, 8.0, 8.1, 8.2, 8.3, 8.4, 8.5, 'latest' ]; if ( ! in_array( $this->site_data['php_version'], $supported_php_versions ) ) { From 268532a6edf3bc119f5754e5e5e4ff15d8e86c9a Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Thu, 24 Sep 2026 07:51:35 +0000 Subject: [PATCH 2/2] fix(site): reject invalid alias domain names on php site create `ee site create --type=php --alias-domains` accepted names like `../evil`, `a..b`, `a.com.` or `default`, which reach VIRTUAL_HOST and the per-domain proxy files. The alias domains are now checked with site-command's `validate_alias_domains()`, and the command exits with an error listing the invalid names before anything is created. --- src/PHP.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/PHP.php b/src/PHP.php index 8933dd0..3e71c95 100644 --- a/src/PHP.php +++ b/src/PHP.php @@ -12,6 +12,7 @@ use function EE\Site\Utils\get_webroot; use function EE\Site\Utils\check_alias_in_db; use function EE\Site\Utils\split_alias_domains; +use function EE\Site\Utils\validate_alias_domains; use function EE\Utils\get_flag_value; use function EE\Utils\get_value_if_flag_isset; @@ -191,6 +192,7 @@ public function create( $args, $assoc_args ) { } $alias_domains = split_alias_domains( \EE\Utils\get_flag_value( $assoc_args, 'alias-domains', '' ) ); + validate_alias_domains( $alias_domains ); $alias_domain_to_check = $alias_domains; $alias_domain_to_check[] = $this->site_data['site_url'];