Version 5.0.6

This commit is contained in:
Neo committed 2025-12-19 18:55:49 -08:00
1 parent a3a4a9ccbd
commit b89858b2ff
1214 files changed
+92828 -14859

No files matched your search

+42 -3
View File
@@ -56,6 +56,7 @@ use IPS\Xml\DOMDocument;
use OutOfRangeException;
use UnderflowException;
use UnexpectedValueException;
use function array_key_exists;
use function chr;
use function count;
use function defined;
@@ -641,6 +642,7 @@ class Parser
$def->addAttribute( 'iframe', 'data-ipsembed-timestamp', 'Text' ); // used in embeddableMedia
$def->addAttribute( 'iframe', 'data-internalembed', 'Text' ); // used in embeddableMedia
$def->addAttribute( 'iframe', 'allowfullscreen', 'Text' ); // Some services will specify this property
$def->addAttribute( 'iframe', 'allow', 'Text' ); // Some services will specify this property. We replace it with individual allow* attributes later on in the parsing process
/* Custom Iframes need these */
$def->addAttribute( 'iframe', 'width', 'Number' ); // Some services will specify this property
@@ -681,14 +683,14 @@ class Parser
$def->addAttribute( 'iframe', 'data-munge-src', 'Text' );
/* Videos */
$def->addElement( 'video', 'Block', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
$def->addElement( 'video', 'Inline', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
'controls' => 'Bool',
'data-controller' => new HTMLPurifier_AttrDef_Enum( array( 'core.global.core.embeddedvideo' ) ),
'data-video-embed' => 'Text',
'preload' => new HTMLPurifier_AttrDef_Enum( [ 'auto', 'metadata', 'none' ] ),
'style' => 'Text'
) );
$def->addElement( 'source', 'Block', 'Flow', 'Common', array(
$def->addElement( 'source', 'Inline', 'Flow', 'Common', array(
'src' => new HTMLPurifier_AttrDef_URI( TRUE ),
'srcset' => new HtmlPurifierSrcsetDef( TRUE ),
'media' => 'Text',
@@ -697,7 +699,7 @@ class Parser
) );
/* Audio */
$def->addElement('audio', 'Block', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
$def->addElement('audio', 'Inline', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
'controls' => 'Bool',
'data-controller' => new HTMLPurifier_AttrDef_Enum( array( 'core.global.core.embeddedaudio' ) ),
'src' => new HTMLPurifier_AttrDef_URI( TRUE ),
@@ -1777,6 +1779,43 @@ class Parser
}
}
catch ( Url\Exception ) {}
}
/* It is possible the iframe has an `allow` property. Let's make sure to split that up into individual attributes */
if ( $element->hasAttribute( "allow" ) )
{
// todo support a system setting for this in v5.x
$allowedAttrs = [
"fullscreen" => "",
"picture-in-picture" => "",
'encrypted-media' => '',
];
$foundAttrs = [];
foreach ( explode( ";", $element->getAttribute( 'allow' ) ) as $permission )
{
$fixedPermission = mb_strtolower( trim( $permission ) );
if ( array_key_exists( $fixedPermission, $allowedAttrs ) )
{
$foundAttrs[] = $fixedPermission;
}
}
if ( $element->hasAttribute( 'allowfullscreen' ) )
{
$foundAttrs[] = "fullscreen";
$element->removeAttribute( "allowfullscreen" );
}
if ( count( $foundAttrs ) )
{
$element->setAttribute( "allow", implode( "; ", array_unique( $foundAttrs ) ) );
}
else
{
$element->removeAttribute( "allow" );
}
}
/* Native Lazyload all iFrames */