Skip to content

[13.x] Prevent loose comparison bypass in in_array validation rule - #61319

Merged
taylorotwell merged 1 commit into
laravel:13.xfrom
KIKOmanasijev:fix/in-array-strict-comparison
Aug 24, 2026
Merged

taylorotwell merged 1 commit into
laravel:13.xfrom
KIKOmanasijev:fix/in-array-strict-comparison

Conversation

@KIKOmanasijev

@KIKOmanasijev KIKOmanasijev commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

The in_array validation rule currently uses non-strict in_array() comparison against values extracted from request data, so numeric-looking values such as "1e0" and "0e123456789" can match "1" and "0".

Use strict comparison for this rule and add regression coverage for loose numeric-string matches while preserving exact matches. This follows the same fix and test shape as #61146 for the in rule.

Since in_array compares against request values rather than string rule parameters, the tests also verify that integer/string mismatches fail while exact integer and string matches continue to pass.

@github-actions

Copy link
Copy Markdown

Thanks for submitting a PR!

Note that draft PRs are not reviewed. If you would like a review, please mark your pull request as ready for review in the GitHub user interface.

Pull requests that are abandoned in draft may be closed due to inactivity.

@KIKOmanasijev
KIKOmanasijev marked this pull request as ready for review August 24, 2026 18:04
@KIKOmanasijev
KIKOmanasijev marked this pull request as draft August 24, 2026 18:06
@KIKOmanasijev
KIKOmanasijev marked this pull request as ready for review August 24, 2026 21:30
@taylorotwell
taylorotwell merged commit e8420db into laravel:13.x Aug 24, 2026
56 checks passed
binaryfire added a commit to hypervel/components-backup that referenced this pull request Oct 1, 2026
Compare in_array and doesnt_contain values strictly and document their type-sensitive behavior. Retain contains behavior from the current upstream target.

Port the remaining scalar in-rule cases, remove its obsolete documented difference, and consolidate contains/doesnt_contain tests under upstream file names. Preserve distinct existing assertions while restoring missing rule-formatting cases and adding strict-membership coverage. The validation suite and analysis pass.

Upstream:
laravel/framework#61146
laravel/framework#61315
laravel/framework#61319
laravel/framework#61318

Source: laravel/framework master 7068848dfe48fc3a433598e09ce798799d442a52.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants