Version 5.0.0 beta 5

This commit is contained in:
Neo committed 2025-12-19 17:04:22 -08:00
1 parent 2f24f9de48
commit 57d9db6ce2
218 files changed
+5331 -7416

No files matched your search

@@ -0,0 +1,45 @@
<?php
/**
* @brief A HTMLPurifier Attribute Definition used for attributes which must be internal URLs or Integers (such as data-fileid for attachments)
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 21 October 2024
*/
namespace IPS\Text;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* A HTMLPurifier Attribute Definition used for attributes which must be internal URLs or Integers (such as data-fileid for attachments)
*/
class HtmlPurifierIntOrInternalLink extends HtmlPurifierInternalLinkDef
{
/**
* Validate
*
* @param string $value
* @param \HTMLPurifier_Config $config
* @param \HTMLPurifier_Context $context
* @return bool|string
*/
public function validate( $value, $config, $context ): bool|string
{
$parentCheck = parent::validate( $value, $config, $context );
if( $parentCheck !== FALSE )
{
return $parentCheck;
}
$integer = new \HTMLPurifier_AttrDef_Integer( false );
return $integer->validate( $value, $config, $context );
}
}
+10 -2
View File
@@ -17,6 +17,7 @@ use HTMLPurifier_Config;
use HTMLPurifier_Context;
use IPS\File;
use IPS\Http\Url;
use IPS\Http\Url\Exception as UrlException;
use IPS\Http\Url\Friendly;
use IPS\Http\Url\Internal;
use IPS\Settings;
@@ -61,8 +62,15 @@ class HtmlPurifierInternalLinkDef extends HTMLPurifier_AttrDef_URI
public function validate($uri, $config, $context): bool|string
{
/* Create the URL */
$url = Url::createFromString( str_replace( array( '%7B___base_url___%7D/', '{___base_url___}/' ), Settings::i()->base_url, $uri ) );
try
{
$url = Url::createFromString( str_replace( array( '%7B___base_url___%7D/', '{___base_url___}/' ), Settings::i()->base_url, $uri ) );
}
catch( UrlException $e )
{
return FALSE;
}
/* If it's not internal, we can stop now */
if ( !( $url instanceof Internal ) )
{
+3 -3
View File
@@ -608,8 +608,8 @@ class Parser
$def->addAttribute( 'img', 'data-emoticon', 'Bool' ); // Identifies emoticons and stops lightbox running on them
/* Attachments (set by _parseAElement, _parseImgElement and "insert existing attachment") - Gallery/Downloads use the full URL rather than an ID, hence Text */
$def->addAttribute( 'a', 'data-fileid', 'Text' );
$def->addAttribute( 'img', 'data-fileid', 'Text' );
$def->addAttribute( 'a', 'data-fileid', new HtmlPurifierIntOrInternalLink() );
$def->addAttribute( 'img', 'data-fileid', new HtmlPurifierIntOrInternalLink() );
$def->addAttribute( 'a', 'data-fileext', 'Text' );
/* Existing media (inserted with data-extension by the JS so that _getFile is able to locate) */
@@ -632,7 +632,7 @@ class Parser
/* iFrames (used by embeddableMedia) */
$def->addAttribute( 'iframe', 'data-controller', new HTMLPurifier_AttrDef_Enum( array( 'core.front.core.autosizeiframe' ) ) ); // used in core/global/embed/iframe.phtml
$def->addAttribute( 'iframe', 'data-embedid', 'Text' ); // used in core/global/embed/iframe.phtml
$def->addAttribute( 'iframe', 'data-embedauthorid', 'Text' ); // used for embed notifications
$def->addAttribute( 'iframe', 'data-embedauthorid', 'Number' ); // used for embed notifications
$def->addAttribute( 'iframe', 'data-embedcontent', 'Text' ); // used in embeddableMedia
$def->addAttribute( 'iframe', 'data-ipsembed-contentapp', 'Text' ); // used in embeddableMedia
$def->addAttribute( 'iframe', 'data-ipsembed-contentid', 'Text' ); // used in embeddableMedia