Skip to content

fix: reject non-digit characters in valid_cc_number() - #10580

Merged
michalsn merged 3 commits into
codeigniter4:developfrom
gr8man:fix/credit-card-ctype-digit
Sep 27, 2026
Merged

michalsn merged 3 commits into
codeigniter4:developfrom
gr8man:fix/credit-card-ctype-digit

Conversation

@gr8man

@gr8man gr8man commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Description
Explain what you have changed, and why.
valid_cc_number() used is_numeric() to reject non-numeric values before the Luhn check. is_numeric() accepts strings that ctype_digit() rejects — e.g. decimal points (5351367.37861108), scientific notation, and sign characters — so such input:

  • bypassed digit-only validation and could pass the Luhn check (parity shifted by the skipped non-digit character), and
  • reached $sumTable[...][$number[$i]] with a non-digit index, triggering an Undefined array key warning/ErrorException.

This PR switches to ctype_digit() (already used elsewhere in system/, e.g. FormatRules::valid_numeric).

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value (without duplication)
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

Use ctype_digit() instead of is_numeric() so values such as decimal
points, which is_numeric() accepts, can no longer reach the Luhn check.
Previously a string like '5351367.37861108' passed validation and the
Luhn indexer triggered an 'Undefined array key' warning on non-digit
characters.
@carson-codeigniter4 carson-codeigniter4 Bot added the bug Verified issues on the current code behavior or pull requests that will fix them label Sep 21, 2026
Comment thread system/Validation/CreditCardRules.php Outdated
@paulbalandan paulbalandan changed the title fix: reject non-digit characters in valid_cc_number() fix: reject non-digit characters in valid_cc_number() Sep 25, 2026
@carson-codeigniter4 carson-codeigniter4 Bot added the needs template Opened issues not following the bug form template label Sep 25, 2026
@carson-codeigniter4

Copy link
Copy Markdown

Hi there, @gr8man! 👋

It looks like this pull request does not follow our template:

Please update the description to follow the template. The needs template label will be removed automatically once it does.

@michalsn
michalsn merged commit d734e61 into codeigniter4:develop Sep 27, 2026
63 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Verified issues on the current code behavior or pull requests that will fix them needs template Opened issues not following the bug form template

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants