Skip to content

[13.x] Prevent loose comparison bypass in contains validation rule - #61320

Merged
taylorotwell merged 1 commit into
laravel:13.xfrom
KIKOmanasijev:fix/contains-strict-comparison
Aug 24, 2026
Merged

taylorotwell merged 1 commit into
laravel:13.xfrom
KIKOmanasijev:fix/contains-strict-comparison

Conversation

@KIKOmanasijev

@KIKOmanasijev KIKOmanasijev commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

The contains validation rule currently uses non-strict in_array() comparison, so numeric-looking values such as "1e0" and "0e123" can satisfy contains:1 and contains:0.

Use strict comparison for this rule and add regression coverage for loose numeric-string matches while preserving exact matches. This follows the same fix and test shape as #61146 for the in rule.

@github-actions

Copy link
Copy Markdown

Thanks for submitting a PR!

Note that draft PRs are not reviewed. If you would like a review, please mark your pull request as ready for review in the GitHub user interface.

Pull requests that are abandoned in draft may be closed due to inactivity.

@KIKOmanasijev
KIKOmanasijev marked this pull request as ready for review August 24, 2026 18:04
@KIKOmanasijev
KIKOmanasijev marked this pull request as draft August 24, 2026 18:06
@KIKOmanasijev
KIKOmanasijev marked this pull request as ready for review August 24, 2026 21:30
@taylorotwell
taylorotwell merged commit 87a21fb into laravel:13.x Aug 24, 2026
111 checks passed
@crynobone

Copy link
Copy Markdown
Member

This may cause a breaking change due to the fact $value isn't converted to string for in_array unlike the previous PR made for in validation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants