Version 5.0.0 beta 5
This commit is contained in:
1 parent
2f24f9de48
commit
57d9db6ce2
218 files changed
+5331
-7416
No files matched your search
@@ -0,0 +1,45 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief A HTMLPurifier Attribute Definition used for attributes which must be internal URLs or Integers (such as data-fileid for attachments)
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 21 October 2024
|
||||
*/
|
||||
|
||||
namespace IPS\Text;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* A HTMLPurifier Attribute Definition used for attributes which must be internal URLs or Integers (such as data-fileid for attachments)
|
||||
*/
|
||||
class HtmlPurifierIntOrInternalLink extends HtmlPurifierInternalLinkDef
|
||||
{
|
||||
/**
|
||||
* Validate
|
||||
*
|
||||
* @param string $value
|
||||
* @param \HTMLPurifier_Config $config
|
||||
* @param \HTMLPurifier_Context $context
|
||||
* @return bool|string
|
||||
*/
|
||||
public function validate( $value, $config, $context ): bool|string
|
||||
{
|
||||
$parentCheck = parent::validate( $value, $config, $context );
|
||||
|
||||
if( $parentCheck !== FALSE )
|
||||
{
|
||||
return $parentCheck;
|
||||
}
|
||||
|
||||
$integer = new \HTMLPurifier_AttrDef_Integer( false );
|
||||
return $integer->validate( $value, $config, $context );
|
||||
}
|
||||
}
|
||||
@@ -17,6 +17,7 @@ use HTMLPurifier_Config;
|
||||
use HTMLPurifier_Context;
|
||||
use IPS\File;
|
||||
use IPS\Http\Url;
|
||||
use IPS\Http\Url\Exception as UrlException;
|
||||
use IPS\Http\Url\Friendly;
|
||||
use IPS\Http\Url\Internal;
|
||||
use IPS\Settings;
|
||||
@@ -61,8 +62,15 @@ class HtmlPurifierInternalLinkDef extends HTMLPurifier_AttrDef_URI
|
||||
public function validate($uri, $config, $context): bool|string
|
||||
{
|
||||
/* Create the URL */
|
||||
$url = Url::createFromString( str_replace( array( '%7B___base_url___%7D/', '{___base_url___}/' ), Settings::i()->base_url, $uri ) );
|
||||
|
||||
try
|
||||
{
|
||||
$url = Url::createFromString( str_replace( array( '%7B___base_url___%7D/', '{___base_url___}/' ), Settings::i()->base_url, $uri ) );
|
||||
}
|
||||
catch( UrlException $e )
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* If it's not internal, we can stop now */
|
||||
if ( !( $url instanceof Internal ) )
|
||||
{
|
||||
|
||||
@@ -608,8 +608,8 @@ class Parser
|
||||
$def->addAttribute( 'img', 'data-emoticon', 'Bool' ); // Identifies emoticons and stops lightbox running on them
|
||||
|
||||
/* Attachments (set by _parseAElement, _parseImgElement and "insert existing attachment") - Gallery/Downloads use the full URL rather than an ID, hence Text */
|
||||
$def->addAttribute( 'a', 'data-fileid', 'Text' );
|
||||
$def->addAttribute( 'img', 'data-fileid', 'Text' );
|
||||
$def->addAttribute( 'a', 'data-fileid', new HtmlPurifierIntOrInternalLink() );
|
||||
$def->addAttribute( 'img', 'data-fileid', new HtmlPurifierIntOrInternalLink() );
|
||||
$def->addAttribute( 'a', 'data-fileext', 'Text' );
|
||||
|
||||
/* Existing media (inserted with data-extension by the JS so that _getFile is able to locate) */
|
||||
@@ -632,7 +632,7 @@ class Parser
|
||||
/* iFrames (used by embeddableMedia) */
|
||||
$def->addAttribute( 'iframe', 'data-controller', new HTMLPurifier_AttrDef_Enum( array( 'core.front.core.autosizeiframe' ) ) ); // used in core/global/embed/iframe.phtml
|
||||
$def->addAttribute( 'iframe', 'data-embedid', 'Text' ); // used in core/global/embed/iframe.phtml
|
||||
$def->addAttribute( 'iframe', 'data-embedauthorid', 'Text' ); // used for embed notifications
|
||||
$def->addAttribute( 'iframe', 'data-embedauthorid', 'Number' ); // used for embed notifications
|
||||
$def->addAttribute( 'iframe', 'data-embedcontent', 'Text' ); // used in embeddableMedia
|
||||
$def->addAttribute( 'iframe', 'data-ipsembed-contentapp', 'Text' ); // used in embeddableMedia
|
||||
$def->addAttribute( 'iframe', 'data-ipsembed-contentid', 'Text' ); // used in embeddableMedia
|
||||
|
||||
Reference in new issue
Block a user