Version 5.0.6
This commit is contained in:
1 parent
a3a4a9ccbd
commit
b89858b2ff
1214 files changed
+92828
-14859
No files matched your search
+42
-3
@@ -56,6 +56,7 @@ use IPS\Xml\DOMDocument;
|
||||
use OutOfRangeException;
|
||||
use UnderflowException;
|
||||
use UnexpectedValueException;
|
||||
use function array_key_exists;
|
||||
use function chr;
|
||||
use function count;
|
||||
use function defined;
|
||||
@@ -641,6 +642,7 @@ class Parser
|
||||
$def->addAttribute( 'iframe', 'data-ipsembed-timestamp', 'Text' ); // used in embeddableMedia
|
||||
$def->addAttribute( 'iframe', 'data-internalembed', 'Text' ); // used in embeddableMedia
|
||||
$def->addAttribute( 'iframe', 'allowfullscreen', 'Text' ); // Some services will specify this property
|
||||
$def->addAttribute( 'iframe', 'allow', 'Text' ); // Some services will specify this property. We replace it with individual allow* attributes later on in the parsing process
|
||||
|
||||
/* Custom Iframes need these */
|
||||
$def->addAttribute( 'iframe', 'width', 'Number' ); // Some services will specify this property
|
||||
@@ -681,14 +683,14 @@ class Parser
|
||||
$def->addAttribute( 'iframe', 'data-munge-src', 'Text' );
|
||||
|
||||
/* Videos */
|
||||
$def->addElement( 'video', 'Block', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
|
||||
$def->addElement( 'video', 'Inline', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
|
||||
'controls' => 'Bool',
|
||||
'data-controller' => new HTMLPurifier_AttrDef_Enum( array( 'core.global.core.embeddedvideo' ) ),
|
||||
'data-video-embed' => 'Text',
|
||||
'preload' => new HTMLPurifier_AttrDef_Enum( [ 'auto', 'metadata', 'none' ] ),
|
||||
'style' => 'Text'
|
||||
) );
|
||||
$def->addElement( 'source', 'Block', 'Flow', 'Common', array(
|
||||
$def->addElement( 'source', 'Inline', 'Flow', 'Common', array(
|
||||
'src' => new HTMLPurifier_AttrDef_URI( TRUE ),
|
||||
'srcset' => new HtmlPurifierSrcsetDef( TRUE ),
|
||||
'media' => 'Text',
|
||||
@@ -697,7 +699,7 @@ class Parser
|
||||
) );
|
||||
|
||||
/* Audio */
|
||||
$def->addElement('audio', 'Block', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
|
||||
$def->addElement('audio', 'Inline', 'Optional: (source, Flow) | (Flow, source) | Flow', 'Common', array(
|
||||
'controls' => 'Bool',
|
||||
'data-controller' => new HTMLPurifier_AttrDef_Enum( array( 'core.global.core.embeddedaudio' ) ),
|
||||
'src' => new HTMLPurifier_AttrDef_URI( TRUE ),
|
||||
@@ -1777,6 +1779,43 @@ class Parser
|
||||
}
|
||||
}
|
||||
catch ( Url\Exception ) {}
|
||||
|
||||
}
|
||||
|
||||
/* It is possible the iframe has an `allow` property. Let's make sure to split that up into individual attributes */
|
||||
if ( $element->hasAttribute( "allow" ) )
|
||||
{
|
||||
// todo support a system setting for this in v5.x
|
||||
$allowedAttrs = [
|
||||
"fullscreen" => "",
|
||||
"picture-in-picture" => "",
|
||||
'encrypted-media' => '',
|
||||
];
|
||||
|
||||
$foundAttrs = [];
|
||||
foreach ( explode( ";", $element->getAttribute( 'allow' ) ) as $permission )
|
||||
{
|
||||
$fixedPermission = mb_strtolower( trim( $permission ) );
|
||||
if ( array_key_exists( $fixedPermission, $allowedAttrs ) )
|
||||
{
|
||||
$foundAttrs[] = $fixedPermission;
|
||||
}
|
||||
}
|
||||
|
||||
if ( $element->hasAttribute( 'allowfullscreen' ) )
|
||||
{
|
||||
$foundAttrs[] = "fullscreen";
|
||||
$element->removeAttribute( "allowfullscreen" );
|
||||
}
|
||||
|
||||
if ( count( $foundAttrs ) )
|
||||
{
|
||||
$element->setAttribute( "allow", implode( "; ", array_unique( $foundAttrs ) ) );
|
||||
}
|
||||
else
|
||||
{
|
||||
$element->removeAttribute( "allow" );
|
||||
}
|
||||
}
|
||||
|
||||
/* Native Lazyload all iFrames */
|
||||
|
||||
Reference in new issue
Block a user