Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
@@ -11,9 +11,15 @@
|
||||
namespace IPS\Text;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use HTMLPurifier_URIFilter;
|
||||
use IPS\Settings;
|
||||
use function defined;
|
||||
use const PHP_URL_HOST;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
@@ -21,17 +27,17 @@ if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
* An HTMLPurifier image transformation that only allows HTTPS images
|
||||
* @see https://stackoverflow.com/questions/34876151/htmlpurifier-allow-scheme-for-specific-tags
|
||||
*/
|
||||
class _HtmlPurifierHttpsImages extends \HTMLPurifier_URIFilter
|
||||
class HtmlPurifierHttpsImages extends HTMLPurifier_URIFilter
|
||||
{
|
||||
public $name = 'HttpsEmbedScheme';
|
||||
public $ourHost = '';
|
||||
public string $ourHost = '';
|
||||
|
||||
public function prepare( $config )
|
||||
public function prepare( $config ) : void
|
||||
{
|
||||
$this->ourHost = parse_url( \IPS\Settings::i()->base_url, \PHP_URL_HOST );
|
||||
$this->ourHost = parse_url( Settings::i()->base_url, PHP_URL_HOST );
|
||||
}
|
||||
|
||||
public function filter( &$uri, $config, $context )
|
||||
public function filter( &$uri, $config, $context ): bool
|
||||
{
|
||||
/* We only care about embedded resources for this, skip src attr so our own parser can handle that. */
|
||||
if ( !$context->get( 'EmbeddedURI', true ) OR $context->get( 'CurrentAttr', true ) == 'src' )
|
||||
|
||||
Reference in new issue
Block a user