@@ -47,7 +47,7 @@ discard block |
||
47 | 47 | if ($height >= $max_size_for_picture) { |
48 | 48 | // scale width |
49 | 49 | $new_width = round($width * ($max_size_for_picture / $height)); |
50 | - $this->image_wrapper->resize($new_width, $max_size_for_picture, 0); |
|
50 | + $this->image_wrapper->resize($new_width, $max_size_for_picture, 0); |
|
51 | 51 | } |
52 | 52 | } |
53 | 53 | } |
@@ -149,7 +149,7 @@ discard block |
||
149 | 149 | |
150 | 150 | public function __construct($path) |
151 | 151 | { |
152 | - parent::__construct($path); |
|
152 | + parent::__construct($path); |
|
153 | 153 | } |
154 | 154 | |
155 | 155 | public function set_image_wrapper() |
@@ -184,19 +184,19 @@ discard block |
||
184 | 184 | } |
185 | 185 | } |
186 | 186 | |
187 | - public function get_image_size() |
|
187 | + public function get_image_size() |
|
188 | 188 | { |
189 | - $imagesize = array('width'=>0,'height'=>0); |
|
190 | - if ($this->image_validated) { |
|
189 | + $imagesize = array('width'=>0,'height'=>0); |
|
190 | + if ($this->image_validated) { |
|
191 | 191 | $imagesize = $this->image->getImageGeometry(); |
192 | - } |
|
193 | - return $imagesize; |
|
194 | - } |
|
192 | + } |
|
193 | + return $imagesize; |
|
194 | + } |
|
195 | 195 | |
196 | - //@todo implement border logic case for Imagick |
|
197 | - public function resize($thumbw, $thumbh, $border, $specific_size = false) |
|
196 | + //@todo implement border logic case for Imagick |
|
197 | + public function resize($thumbw, $thumbh, $border, $specific_size = false) |
|
198 | 198 | { |
199 | - if (!$this->image_validated) return false; |
|
199 | + if (!$this->image_validated) return false; |
|
200 | 200 | |
201 | 201 | if ($specific_size) { |
202 | 202 | $width = $thumbw; |
@@ -206,10 +206,10 @@ discard block |
||
206 | 206 | $width = (int)($this->width * $scale); |
207 | 207 | $height = (int)($this->height * $scale); |
208 | 208 | } |
209 | - $result = $this->image->resizeImage($width, $height, $this->filter, 1); |
|
210 | - $this->width = $thumbw; |
|
211 | - $this->height = $thumbh; |
|
212 | - } |
|
209 | + $result = $this->image->resizeImage($width, $height, $this->filter, 1); |
|
210 | + $this->width = $thumbw; |
|
211 | + $this->height = $thumbh; |
|
212 | + } |
|
213 | 213 | |
214 | 214 | /** |
215 | 215 | * @author José Loguercio <[email protected]> |
@@ -224,8 +224,8 @@ discard block |
||
224 | 224 | public function crop($x, $y, $width, $height, $src_width, $src_height) { |
225 | 225 | if (!$this->image_validated) return false; |
226 | 226 | $this->image->cropimage($width, $height, $x, $y); |
227 | - $this->width = $width; |
|
228 | - $this->height = $height; |
|
227 | + $this->width = $width; |
|
228 | + $this->height = $height; |
|
229 | 229 | } |
230 | 230 | |
231 | 231 | public function send_image($file = '', $compress = -1, $convert_file_to = null) |
@@ -235,35 +235,35 @@ discard block |
||
235 | 235 | if (!empty($convert_file_to) && in_array($convert_file_to, $this->allowed_extensions)) { |
236 | 236 | $type = $convert_file_to; |
237 | 237 | } |
238 | - switch ($type) { |
|
239 | - case 'jpeg': |
|
240 | - case 'jpg': |
|
241 | - if (!$file) header("Content-type: image/jpeg"); |
|
242 | - break; |
|
243 | - case 'png': |
|
244 | - if (!$file) header("Content-type: image/png"); |
|
245 | - break; |
|
246 | - case 'gif': |
|
247 | - if (!$file) header("Content-type: image/gif"); |
|
248 | - break; |
|
249 | - } |
|
250 | - $result = false; |
|
251 | - try { |
|
252 | - $result = $this->image->writeImage($file); |
|
253 | - } catch(ImagickException $e) { |
|
238 | + switch ($type) { |
|
239 | + case 'jpeg': |
|
240 | + case 'jpg': |
|
241 | + if (!$file) header("Content-type: image/jpeg"); |
|
242 | + break; |
|
243 | + case 'png': |
|
244 | + if (!$file) header("Content-type: image/png"); |
|
245 | + break; |
|
246 | + case 'gif': |
|
247 | + if (!$file) header("Content-type: image/gif"); |
|
248 | + break; |
|
249 | + } |
|
250 | + $result = false; |
|
251 | + try { |
|
252 | + $result = $this->image->writeImage($file); |
|
253 | + } catch(ImagickException $e) { |
|
254 | 254 | if ($this->debug) error_log($e->getMessage()); |
255 | 255 | } |
256 | 256 | |
257 | - if (!$file) { |
|
258 | - echo $this->image; |
|
259 | - $this->image->clear(); |
|
257 | + if (!$file) { |
|
258 | + echo $this->image; |
|
259 | + $this->image->clear(); |
|
260 | 260 | $this->image->destroy(); |
261 | - } else { |
|
262 | - $this->image->clear(); |
|
261 | + } else { |
|
262 | + $this->image->clear(); |
|
263 | 263 | $this->image->destroy(); |
264 | - return $result; |
|
265 | - } |
|
266 | - } |
|
264 | + return $result; |
|
265 | + } |
|
266 | + } |
|
267 | 267 | |
268 | 268 | } |
269 | 269 | |
@@ -285,21 +285,21 @@ discard block |
||
285 | 285 | $this->fill_image_info(); |
286 | 286 | |
287 | 287 | switch ($this->type) { |
288 | - case 0: |
|
289 | - $handler = false; |
|
290 | - break; |
|
291 | - case 1 : |
|
288 | + case 0: |
|
289 | + $handler = false; |
|
290 | + break; |
|
291 | + case 1 : |
|
292 | 292 | $handler = @imagecreatefromgif($this->path); |
293 | 293 | $this->type = 'gif'; |
294 | 294 | break; |
295 | - case 2 : |
|
295 | + case 2 : |
|
296 | 296 | $handler = @imagecreatefromjpeg($this->path); |
297 | 297 | $this->type = 'jpg'; |
298 | 298 | break; |
299 | - case 3 : |
|
300 | - $handler = @imagecreatefrompng($this->path); |
|
301 | - $this->type = 'png'; |
|
302 | - break; |
|
299 | + case 3 : |
|
300 | + $handler = @imagecreatefrompng($this->path); |
|
301 | + $this->type = 'png'; |
|
302 | + break; |
|
303 | 303 | } |
304 | 304 | if ($handler) { |
305 | 305 | $this->image_validated = true; |
@@ -313,29 +313,29 @@ discard block |
||
313 | 313 | { |
314 | 314 | $return_array = array('width'=>0,'height'=>0); |
315 | 315 | if ($this->image_validated) { |
316 | - $return_array = array('width'=>$this->width,'height'=>$this->height); |
|
316 | + $return_array = array('width'=>$this->width,'height'=>$this->height); |
|
317 | 317 | } |
318 | 318 | return $return_array; |
319 | - } |
|
319 | + } |
|
320 | 320 | |
321 | 321 | public function fill_image_info() |
322 | 322 | { |
323 | - if (file_exists($this->path)) { |
|
324 | - $image_info = getimagesize($this->path); |
|
325 | - $this->width = $image_info[0]; |
|
326 | - $this->height = $image_info[1]; |
|
327 | - $this->type = $image_info[2]; |
|
328 | - } else { |
|
329 | - $this->width = 0; |
|
330 | - $this->height = 0; |
|
331 | - $this->type = 0; |
|
332 | - } |
|
323 | + if (file_exists($this->path)) { |
|
324 | + $image_info = getimagesize($this->path); |
|
325 | + $this->width = $image_info[0]; |
|
326 | + $this->height = $image_info[1]; |
|
327 | + $this->type = $image_info[2]; |
|
328 | + } else { |
|
329 | + $this->width = 0; |
|
330 | + $this->height = 0; |
|
331 | + $this->type = 0; |
|
332 | + } |
|
333 | 333 | } |
334 | 334 | |
335 | 335 | public function resize($thumbw, $thumbh, $border, $specific_size = false) |
336 | 336 | { |
337 | 337 | if (!$this->image_validated) return false; |
338 | - if ($border == 1) { |
|
338 | + if ($border == 1) { |
|
339 | 339 | if ($specific_size) { |
340 | 340 | $width = $thumbw; |
341 | 341 | $height = $thumbh; |
@@ -344,17 +344,17 @@ discard block |
||
344 | 344 | $width = (int)($this->width * $scale); |
345 | 345 | $height = (int)($this->height * $scale); |
346 | 346 | } |
347 | - $deltaw = (int)(($thumbw - $width) / 2); |
|
348 | - $deltah = (int)(($thumbh - $height) / 2); |
|
349 | - $dst_img = @ImageCreateTrueColor($thumbw, $thumbh); |
|
350 | - @imagealphablending($dst_img, false); |
|
351 | - @imagesavealpha($dst_img, true); |
|
352 | - if (!empty($this->color)) { |
|
353 | - @imagefill($dst_img, 0, 0, $this->color); |
|
354 | - } |
|
355 | - $this->width = $thumbw; |
|
356 | - $this->height = $thumbh; |
|
357 | - } elseif ($border == 0) { |
|
347 | + $deltaw = (int)(($thumbw - $width) / 2); |
|
348 | + $deltah = (int)(($thumbh - $height) / 2); |
|
349 | + $dst_img = @ImageCreateTrueColor($thumbw, $thumbh); |
|
350 | + @imagealphablending($dst_img, false); |
|
351 | + @imagesavealpha($dst_img, true); |
|
352 | + if (!empty($this->color)) { |
|
353 | + @imagefill($dst_img, 0, 0, $this->color); |
|
354 | + } |
|
355 | + $this->width = $thumbw; |
|
356 | + $this->height = $thumbh; |
|
357 | + } elseif ($border == 0) { |
|
358 | 358 | if ($specific_size) { |
359 | 359 | $width = $thumbw; |
360 | 360 | $height = $thumbh; |
@@ -363,19 +363,19 @@ discard block |
||
363 | 363 | $width = (int)($this->width * $scale); |
364 | 364 | $height = (int)($this->height * $scale); |
365 | 365 | } |
366 | - $deltaw = 0; |
|
367 | - $deltah = 0; |
|
368 | - $dst_img = @ImageCreateTrueColor($width, $height); |
|
369 | - @imagealphablending($dst_img, false); |
|
370 | - @imagesavealpha($dst_img, true); |
|
371 | - $this->width = $width; |
|
372 | - $this->height = $height; |
|
373 | - } |
|
374 | - $src_img = $this->bg; |
|
375 | - @ImageCopyResampled($dst_img, $src_img, $deltaw, $deltah, 0, 0, $width, $height, ImageSX($src_img), ImageSY($src_img)); |
|
376 | - $this->bg = $dst_img; |
|
377 | - @imagedestroy($src_img); |
|
378 | - } |
|
366 | + $deltaw = 0; |
|
367 | + $deltah = 0; |
|
368 | + $dst_img = @ImageCreateTrueColor($width, $height); |
|
369 | + @imagealphablending($dst_img, false); |
|
370 | + @imagesavealpha($dst_img, true); |
|
371 | + $this->width = $width; |
|
372 | + $this->height = $height; |
|
373 | + } |
|
374 | + $src_img = $this->bg; |
|
375 | + @ImageCopyResampled($dst_img, $src_img, $deltaw, $deltah, 0, 0, $width, $height, ImageSX($src_img), ImageSY($src_img)); |
|
376 | + $this->bg = $dst_img; |
|
377 | + @imagedestroy($src_img); |
|
378 | + } |
|
379 | 379 | |
380 | 380 | /** |
381 | 381 | * @author José Loguercio <[email protected]> |
@@ -389,7 +389,7 @@ discard block |
||
389 | 389 | public function crop($x, $y, $width, $height, $src_width, $src_height) { |
390 | 390 | if (!$this->image_validated) return false; |
391 | 391 | $this->width = $width; |
392 | - $this->height = $height; |
|
392 | + $this->height = $height; |
|
393 | 393 | $src = null; |
394 | 394 | $dest = @imagecreatetruecolor($width, $height); |
395 | 395 | $type = $this->type; |
@@ -400,56 +400,56 @@ discard block |
||
400 | 400 | @imagecopy($dest, $src, 0, 0, $x, $y, $src_width, $src_height); |
401 | 401 | @imagejpeg($dest, $this->path); |
402 | 402 | break; |
403 | - case 'png' : |
|
403 | + case 'png' : |
|
404 | 404 | $src = @imagecreatefrompng($this->path); |
405 | 405 | @imagecopy($dest, $src, 0, 0, $x, $y, $src_width, $src_height); |
406 | 406 | @imagepng($dest, $this->path); |
407 | 407 | break; |
408 | - case 'gif' : |
|
409 | - $src = @imagecreatefromgif($this->path); |
|
408 | + case 'gif' : |
|
409 | + $src = @imagecreatefromgif($this->path); |
|
410 | 410 | @imagecopy($dest, $src, 0, 0, $x, $y, $src_width, $src_height); |
411 | 411 | @imagegif($dest, $this->path); |
412 | - break; |
|
412 | + break; |
|
413 | 413 | default: return 0; |
414 | 414 | } |
415 | 415 | @imagedestroy($dest); |
416 | 416 | @imagedestroy($src); |
417 | 417 | } |
418 | 418 | |
419 | - public function send_image($file = '', $compress = -1, $convert_file_to = null) |
|
419 | + public function send_image($file = '', $compress = -1, $convert_file_to = null) |
|
420 | 420 | { |
421 | - if (!$this->image_validated) return false; |
|
421 | + if (!$this->image_validated) return false; |
|
422 | 422 | $compress = (int)$compress; |
423 | 423 | $type = $this->type; |
424 | 424 | if (!empty($convert_file_to) && in_array($convert_file_to, $this->allowed_extensions)) { |
425 | 425 | $type = $convert_file_to; |
426 | 426 | } |
427 | - switch ($type) { |
|
428 | - case 'jpeg': |
|
429 | - case 'jpg': |
|
430 | - if (!$file) header("Content-type: image/jpeg"); |
|
431 | - if ($compress == -1) $compress = 100; |
|
432 | - return imagejpeg($this->bg, $file, $compress); |
|
433 | - break; |
|
434 | - case 'png': |
|
435 | - if (!$file) header("Content-type: image/png"); |
|
436 | - if ($compress != -1) { |
|
437 | - @imagetruecolortopalette($this->bg, true, $compress); |
|
438 | - } |
|
439 | - return imagepng($this->bg, $file, $compress); |
|
440 | - break; |
|
441 | - case 'gif': |
|
442 | - if (!$file) header("Content-type: image/gif"); |
|
443 | - if ($compress != -1) { |
|
444 | - @imagetruecolortopalette($this->bg, true, $compress); |
|
445 | - } |
|
446 | - return imagegif($this->bg, $file, $compress); |
|
447 | - break; |
|
448 | - default: return 0; |
|
449 | - } |
|
450 | - // TODO: Occupied memory is not released, because the following fragment of code is actually dead. |
|
451 | - @imagedestroy($this->bg); |
|
452 | - } |
|
427 | + switch ($type) { |
|
428 | + case 'jpeg': |
|
429 | + case 'jpg': |
|
430 | + if (!$file) header("Content-type: image/jpeg"); |
|
431 | + if ($compress == -1) $compress = 100; |
|
432 | + return imagejpeg($this->bg, $file, $compress); |
|
433 | + break; |
|
434 | + case 'png': |
|
435 | + if (!$file) header("Content-type: image/png"); |
|
436 | + if ($compress != -1) { |
|
437 | + @imagetruecolortopalette($this->bg, true, $compress); |
|
438 | + } |
|
439 | + return imagepng($this->bg, $file, $compress); |
|
440 | + break; |
|
441 | + case 'gif': |
|
442 | + if (!$file) header("Content-type: image/gif"); |
|
443 | + if ($compress != -1) { |
|
444 | + @imagetruecolortopalette($this->bg, true, $compress); |
|
445 | + } |
|
446 | + return imagegif($this->bg, $file, $compress); |
|
447 | + break; |
|
448 | + default: return 0; |
|
449 | + } |
|
450 | + // TODO: Occupied memory is not released, because the following fragment of code is actually dead. |
|
451 | + @imagedestroy($this->bg); |
|
452 | + } |
|
453 | 453 | |
454 | 454 | /** |
455 | 455 | * Convert image to black & white |
@@ -25,10 +25,10 @@ discard block |
||
25 | 25 | ); |
26 | 26 | public $is_course_model = true; |
27 | 27 | |
28 | - public function __construct() |
|
28 | + public function __construct() |
|
29 | 29 | { |
30 | 30 | $this->table = Database::get_course_table(TABLE_TIMELINE); |
31 | - } |
|
31 | + } |
|
32 | 32 | |
33 | 33 | /** |
34 | 34 | * Get the count of elements |
@@ -52,16 +52,16 @@ discard block |
||
52 | 52 | /** |
53 | 53 | * Displays the title + grid |
54 | 54 | */ |
55 | - public function listing() |
|
55 | + public function listing() |
|
56 | 56 | { |
57 | - // action links |
|
58 | - $html = '<div class="actions">'; |
|
57 | + // action links |
|
58 | + $html = '<div class="actions">'; |
|
59 | 59 | //$html .= '<a href="career_dashboard.php">'.Display::return_icon('back.png',get_lang('Back'),'','32').'</a>'; |
60 | - $html .= '<a href="'.api_get_self().'?action=add">'.Display::return_icon('add.png', get_lang('Add'),'','32').'</a>'; |
|
61 | - $html .= '</div>'; |
|
60 | + $html .= '<a href="'.api_get_self().'?action=add">'.Display::return_icon('add.png', get_lang('Add'),'','32').'</a>'; |
|
61 | + $html .= '</div>'; |
|
62 | 62 | $html .= Display::grid_html('timelines'); |
63 | 63 | return $html; |
64 | - } |
|
64 | + } |
|
65 | 65 | |
66 | 66 | public function get_status_list() |
67 | 67 | { |
@@ -89,7 +89,7 @@ discard block |
||
89 | 89 | |
90 | 90 | $form->addElement('text', 'headline', get_lang('Name'), array('size' => '70')); |
91 | 91 | //$form->addHtmlEditor('description', get_lang('Description'), false, false, array('ToolbarSet' => 'Careers','Width' => '100%', 'Height' => '250')); |
92 | - $status_list = $this->get_status_list(); |
|
92 | + $status_list = $this->get_status_list(); |
|
93 | 93 | $form->addElement('select', 'status', get_lang('Status'), $status_list); |
94 | 94 | if ($action == 'edit') { |
95 | 95 | //$form->addElement('text', 'created_at', get_lang('CreatedAt')); |
@@ -173,7 +173,7 @@ discard block |
||
173 | 173 | |
174 | 174 | // Setting the rules |
175 | 175 | $form->addRule('headline', get_lang('ThisFieldIsRequired'), 'required'); |
176 | - return $form; |
|
176 | + return $form; |
|
177 | 177 | |
178 | 178 | } |
179 | 179 | |
@@ -184,11 +184,11 @@ discard block |
||
184 | 184 | public function save_item($params) |
185 | 185 | { |
186 | 186 | $params['c_id'] = api_get_course_int_id(); |
187 | - $id = parent::save($params); |
|
188 | - if (!empty($id)) { |
|
189 | - //event_system(LOG_CAREER_CREATE, LOG_CAREER_ID, $id, api_get_utc_datetime(), api_get_user_id()); |
|
190 | - } |
|
191 | - return $id; |
|
187 | + $id = parent::save($params); |
|
188 | + if (!empty($id)) { |
|
189 | + //event_system(LOG_CAREER_CREATE, LOG_CAREER_ID, $id, api_get_utc_datetime(), api_get_user_id()); |
|
190 | + } |
|
191 | + return $id; |
|
192 | 192 | } |
193 | 193 | |
194 | 194 | /** |
@@ -199,16 +199,16 @@ discard block |
||
199 | 199 | $params['c_id'] = api_get_course_int_id(); |
200 | 200 | $params['parent_id'] = '0'; |
201 | 201 | $params['type'] = 'default'; |
202 | - $id = parent::save($params); |
|
203 | - if (!empty($id)) { |
|
204 | - //event_system(LOG_CAREER_CREATE, LOG_CAREER_ID, $id, api_get_utc_datetime(), api_get_user_id()); |
|
205 | - } |
|
206 | - return $id; |
|
202 | + $id = parent::save($params); |
|
203 | + if (!empty($id)) { |
|
204 | + //event_system(LOG_CAREER_CREATE, LOG_CAREER_ID, $id, api_get_utc_datetime(), api_get_user_id()); |
|
205 | + } |
|
206 | + return $id; |
|
207 | 207 | } |
208 | 208 | |
209 | 209 | public function delete($id) { |
210 | - parent::delete($id); |
|
211 | - //event_system(LOG_CAREER_DELETE, LOG_CAREER_ID, $id, api_get_utc_datetime(), api_get_user_id()); |
|
210 | + parent::delete($id); |
|
211 | + //event_system(LOG_CAREER_DELETE, LOG_CAREER_ID, $id, api_get_utc_datetime(), api_get_user_id()); |
|
212 | 212 | } |
213 | 213 | |
214 | 214 | public function get_url($id) { |
@@ -247,7 +247,7 @@ discard block |
||
247 | 247 | $item['asset'] = array( 'media' => $item['media'], |
248 | 248 | 'credit' => $item['media_credit'], |
249 | 249 | 'caption' => $item['media_caption'], |
250 | - ); |
|
250 | + ); |
|
251 | 251 | |
252 | 252 | //Cleaning items |
253 | 253 | unset($item['id']); |
@@ -11,15 +11,15 @@ discard block |
||
11 | 11 | class UrlManager |
12 | 12 | { |
13 | 13 | /** |
14 | - * Creates a new url access |
|
15 | - * |
|
16 | - * @author Julio Montoya <[email protected]>, |
|
17 | - * |
|
18 | - * @param string $url The URL of the site |
|
19 | - * @param string $description The description of the site |
|
20 | - * @param int $active is active or not |
|
21 | - * @return boolean if success |
|
22 | - */ |
|
14 | + * Creates a new url access |
|
15 | + * |
|
16 | + * @author Julio Montoya <[email protected]>, |
|
17 | + * |
|
18 | + * @param string $url The URL of the site |
|
19 | + * @param string $description The description of the site |
|
20 | + * @param int $active is active or not |
|
21 | + * @return boolean if success |
|
22 | + */ |
|
23 | 23 | public static function add($url, $description, $active) |
24 | 24 | { |
25 | 25 | $tms = time(); |
@@ -36,15 +36,15 @@ discard block |
||
36 | 36 | } |
37 | 37 | |
38 | 38 | /** |
39 | - * Updates an URL access |
|
40 | - * @author Julio Montoya <[email protected]>, |
|
41 | - * |
|
42 | - * @param int $url_id The url id |
|
43 | - * @param string $url |
|
44 | - * @param string $description The description of the site |
|
45 | - * @param int $active is active or not |
|
46 | - * @return boolean if success |
|
47 | - */ |
|
39 | + * Updates an URL access |
|
40 | + * @author Julio Montoya <[email protected]>, |
|
41 | + * |
|
42 | + * @param int $url_id The url id |
|
43 | + * @param string $url |
|
44 | + * @param string $description The description of the site |
|
45 | + * @param int $active is active or not |
|
46 | + * @return boolean if success |
|
47 | + */ |
|
48 | 48 | public static function update($url_id, $url, $description, $active) |
49 | 49 | { |
50 | 50 | $url_id = intval($url_id); |
@@ -63,12 +63,12 @@ discard block |
||
63 | 63 | } |
64 | 64 | |
65 | 65 | /** |
66 | - * Deletes an url |
|
67 | - * @author Julio Montoya |
|
68 | - * @param int $id url id |
|
66 | + * Deletes an url |
|
67 | + * @author Julio Montoya |
|
68 | + * @param int $id url id |
|
69 | 69 | * |
70 | - * @return boolean true if success |
|
71 | - * */ |
|
70 | + * @return boolean true if success |
|
71 | + * */ |
|
72 | 72 | public static function delete($id) |
73 | 73 | { |
74 | 74 | $id = intval($id); |
@@ -200,12 +200,12 @@ discard block |
||
200 | 200 | } |
201 | 201 | |
202 | 202 | /** |
203 | - * Gets the inner join of access_url and the course table |
|
204 | - * |
|
205 | - * @author Julio Montoya |
|
206 | - * @param int access url id |
|
207 | - * @return array Database::store_result of the result |
|
208 | - **/ |
|
203 | + * Gets the inner join of access_url and the course table |
|
204 | + * |
|
205 | + * @author Julio Montoya |
|
206 | + * @param int access url id |
|
207 | + * @return array Database::store_result of the result |
|
208 | + **/ |
|
209 | 209 | public static function get_url_rel_course_data($access_url_id = null) |
210 | 210 | { |
211 | 211 | $where = ''; |
@@ -362,12 +362,12 @@ discard block |
||
362 | 362 | } |
363 | 363 | |
364 | 364 | /** |
365 | - * Checks the relationship between an URL and a User (return the num_rows) |
|
366 | - * @author Julio Montoya |
|
367 | - * @param int user id |
|
368 | - * @param int url id |
|
369 | - * @return boolean true if success |
|
370 | - * */ |
|
365 | + * Checks the relationship between an URL and a User (return the num_rows) |
|
366 | + * @author Julio Montoya |
|
367 | + * @param int user id |
|
368 | + * @param int url id |
|
369 | + * @return boolean true if success |
|
370 | + * */ |
|
371 | 371 | public static function relation_url_user_exist($user_id, $url_id) |
372 | 372 | { |
373 | 373 | $table = Database :: get_main_table(TABLE_MAIN_ACCESS_URL_REL_USER); |
@@ -377,15 +377,15 @@ discard block |
||
377 | 377 | $num = Database::num_rows($result); |
378 | 378 | |
379 | 379 | return $num; |
380 | - } |
|
380 | + } |
|
381 | 381 | |
382 | 382 | /** |
383 | - * Checks the relationship between an URL and a Course (return the num_rows) |
|
384 | - * @author Julio Montoya |
|
385 | - * @param int $courseId |
|
386 | - * @param int $urlId |
|
387 | - * @return boolean true if success |
|
388 | - * */ |
|
383 | + * Checks the relationship between an URL and a Course (return the num_rows) |
|
384 | + * @author Julio Montoya |
|
385 | + * @param int $courseId |
|
386 | + * @param int $urlId |
|
387 | + * @return boolean true if success |
|
388 | + * */ |
|
389 | 389 | public static function relation_url_course_exist($courseId, $urlId) |
390 | 390 | { |
391 | 391 | $table_url_rel_course = Database :: get_main_table(TABLE_MAIN_ACCESS_URL_REL_COURSE); |
@@ -420,12 +420,12 @@ discard block |
||
420 | 420 | } |
421 | 421 | |
422 | 422 | /** |
423 | - * Checks the relationship between an URL and a Session (return the num_rows) |
|
424 | - * @author Julio Montoya |
|
425 | - * @param int user id |
|
426 | - * @param int url id |
|
427 | - * @return boolean true if success |
|
428 | - * */ |
|
423 | + * Checks the relationship between an URL and a Session (return the num_rows) |
|
424 | + * @author Julio Montoya |
|
425 | + * @param int user id |
|
426 | + * @param int url id |
|
427 | + * @return boolean true if success |
|
428 | + * */ |
|
429 | 429 | public static function relation_url_session_exist($session_id, $url_id) |
430 | 430 | { |
431 | 431 | $table_url_rel_session= Database::get_main_table(TABLE_MAIN_ACCESS_URL_REL_SESSION); |
@@ -737,13 +737,13 @@ discard block |
||
737 | 737 | } |
738 | 738 | |
739 | 739 | /** |
740 | - * Deletes an url and user relationship |
|
741 | - * @author Julio Montoya |
|
742 | - * @param int user id |
|
743 | - * @param int url id |
|
740 | + * Deletes an url and user relationship |
|
741 | + * @author Julio Montoya |
|
742 | + * @param int user id |
|
743 | + * @param int url id |
|
744 | 744 | * |
745 | - * @return boolean true if success |
|
746 | - * */ |
|
745 | + * @return boolean true if success |
|
746 | + * */ |
|
747 | 747 | public static function delete_url_rel_user($user_id, $url_id) |
748 | 748 | { |
749 | 749 | $table_url_rel_user = Database :: get_main_table(TABLE_MAIN_ACCESS_URL_REL_USER); |
@@ -758,13 +758,13 @@ discard block |
||
758 | 758 | } |
759 | 759 | |
760 | 760 | /** |
761 | - * Deletes an url and course relationship |
|
762 | - * @author Julio Montoya |
|
763 | - * @param int $courseId |
|
764 | - * @param int $urlId |
|
761 | + * Deletes an url and course relationship |
|
762 | + * @author Julio Montoya |
|
763 | + * @param int $courseId |
|
764 | + * @param int $urlId |
|
765 | 765 | * |
766 | - * @return boolean true if success |
|
767 | - * */ |
|
766 | + * @return boolean true if success |
|
767 | + * */ |
|
768 | 768 | public static function delete_url_rel_course($courseId, $urlId) |
769 | 769 | { |
770 | 770 | $table_url_rel_course= Database :: get_main_table(TABLE_MAIN_ACCESS_URL_REL_COURSE); |
@@ -814,13 +814,13 @@ discard block |
||
814 | 814 | } |
815 | 815 | |
816 | 816 | /** |
817 | - * Deletes an url and session relationship |
|
818 | - * @author Julio Montoya |
|
819 | - * @param char course code |
|
820 | - * @param int url id |
|
817 | + * Deletes an url and session relationship |
|
818 | + * @author Julio Montoya |
|
819 | + * @param char course code |
|
820 | + * @param int url id |
|
821 | 821 | * |
822 | - * @return boolean true if success |
|
823 | - * */ |
|
822 | + * @return boolean true if success |
|
823 | + * */ |
|
824 | 824 | public static function delete_url_rel_session($session_id, $url_id) |
825 | 825 | { |
826 | 826 | $table_url_rel_session = Database :: get_main_table(TABLE_MAIN_ACCESS_URL_REL_SESSION); |
@@ -31,8 +31,8 @@ discard block |
||
31 | 31 | |
32 | 32 | |
33 | 33 | function kses($string, $allowed_html, $allowed_protocols = |
34 | - array('http', 'https', 'ftp', 'news', 'nntp', 'telnet', |
|
35 | - 'gopher', 'mailto')) |
|
34 | + array('http', 'https', 'ftp', 'news', 'nntp', 'telnet', |
|
35 | + 'gopher', 'mailto')) |
|
36 | 36 | ############################################################################### |
37 | 37 | # This function makes sure that only the allowed HTML element names, attribute |
38 | 38 | # names and attribute values plus only sane HTML entities will occur in |
@@ -40,12 +40,12 @@ discard block |
||
40 | 40 | # call this function. |
41 | 41 | ############################################################################### |
42 | 42 | { |
43 | - $string = kses_no_null($string); |
|
44 | - $string = kses_js_entities($string); |
|
45 | - $string = kses_normalize_entities($string); |
|
46 | - $string = kses_hook($string); |
|
47 | - $allowed_html_fixed = kses_array_lc($allowed_html); |
|
48 | - return kses_split($string, $allowed_html_fixed, $allowed_protocols); |
|
43 | + $string = kses_no_null($string); |
|
44 | + $string = kses_js_entities($string); |
|
45 | + $string = kses_normalize_entities($string); |
|
46 | + $string = kses_hook($string); |
|
47 | + $allowed_html_fixed = kses_array_lc($allowed_html); |
|
48 | + return kses_split($string, $allowed_html_fixed, $allowed_protocols); |
|
49 | 49 | } # function kses |
50 | 50 | |
51 | 51 | |
@@ -54,7 +54,7 @@ discard block |
||
54 | 54 | # You add any kses hooks here. |
55 | 55 | ############################################################################### |
56 | 56 | { |
57 | - return $string; |
|
57 | + return $string; |
|
58 | 58 | } # function kses_hook |
59 | 59 | |
60 | 60 | |
@@ -63,7 +63,7 @@ discard block |
||
63 | 63 | # This function returns kses' version number. |
64 | 64 | ############################################################################### |
65 | 65 | { |
66 | - return '0.2.2'; |
|
66 | + return '0.2.2'; |
|
67 | 67 | } # function kses_version |
68 | 68 | |
69 | 69 | |
@@ -73,13 +73,13 @@ discard block |
||
73 | 73 | # matches stray ">" characters. |
74 | 74 | ############################################################################### |
75 | 75 | { |
76 | - return preg_replace('%(<'. # EITHER: < |
|
77 | - '[^>]*'. # things that aren't > |
|
78 | - '(>|$)'. # > or end of string |
|
79 | - '|>)%e', # OR: just a > |
|
80 | - "kses_split2('\\1', \$allowed_html, ". |
|
81 | - '$allowed_protocols)', |
|
82 | - $string); |
|
76 | + return preg_replace('%(<'. # EITHER: < |
|
77 | + '[^>]*'. # things that aren't > |
|
78 | + '(>|$)'. # > or end of string |
|
79 | + '|>)%e', # OR: just a > |
|
80 | + "kses_split2('\\1', \$allowed_html, ". |
|
81 | + '$allowed_protocols)', |
|
82 | + $string); |
|
83 | 83 | } # function kses_split |
84 | 84 | |
85 | 85 | |
@@ -91,30 +91,30 @@ discard block |
||
91 | 91 | # attribute list. |
92 | 92 | ############################################################################### |
93 | 93 | { |
94 | - $string = kses_stripslashes($string); |
|
94 | + $string = kses_stripslashes($string); |
|
95 | 95 | |
96 | - if (substr($string, 0, 1) != '<') |
|
96 | + if (substr($string, 0, 1) != '<') |
|
97 | 97 | return '>'; |
98 | 98 | # It matched a ">" character |
99 | 99 | |
100 | - if (!preg_match('%^<\s*(/\s*)?([a-zA-Z0-9]+)([^>]*)>?$%', $string, $matches)) |
|
100 | + if (!preg_match('%^<\s*(/\s*)?([a-zA-Z0-9]+)([^>]*)>?$%', $string, $matches)) |
|
101 | 101 | return ''; |
102 | 102 | # It's seriously malformed |
103 | 103 | |
104 | - $slash = trim($matches[1]); |
|
105 | - $elem = $matches[2]; |
|
106 | - $attrlist = $matches[3]; |
|
104 | + $slash = trim($matches[1]); |
|
105 | + $elem = $matches[2]; |
|
106 | + $attrlist = $matches[3]; |
|
107 | 107 | |
108 | - if (!@isset($allowed_html[strtolower($elem)])) |
|
108 | + if (!@isset($allowed_html[strtolower($elem)])) |
|
109 | 109 | return ''; |
110 | 110 | # They are using a not allowed HTML element |
111 | 111 | |
112 | - if ($slash != '') |
|
112 | + if ($slash != '') |
|
113 | 113 | return "<$slash$elem>"; |
114 | - # No attributes are allowed for closing elements |
|
114 | + # No attributes are allowed for closing elements |
|
115 | 115 | |
116 | - return kses_attr("$slash$elem", $attrlist, $allowed_html, |
|
117 | - $allowed_protocols); |
|
116 | + return kses_attr("$slash$elem", $attrlist, $allowed_html, |
|
117 | + $allowed_protocols); |
|
118 | 118 | } # function kses_split2 |
119 | 119 | |
120 | 120 | |
@@ -130,56 +130,56 @@ discard block |
||
130 | 130 | { |
131 | 131 | # Is there a closing XHTML slash at the end of the attributes? |
132 | 132 | |
133 | - $xhtml_slash = ''; |
|
134 | - if (preg_match('%\s/\s*$%', $attr)) |
|
133 | + $xhtml_slash = ''; |
|
134 | + if (preg_match('%\s/\s*$%', $attr)) |
|
135 | 135 | $xhtml_slash = ' /'; |
136 | 136 | |
137 | 137 | # Are any attributes allowed at all for this element? |
138 | 138 | |
139 | - if (@count($allowed_html[strtolower($element)]) == 0) |
|
139 | + if (@count($allowed_html[strtolower($element)]) == 0) |
|
140 | 140 | return "<$element$xhtml_slash>"; |
141 | 141 | |
142 | 142 | # Split it |
143 | 143 | |
144 | - $attrarr = kses_hair($attr, $allowed_protocols); |
|
144 | + $attrarr = kses_hair($attr, $allowed_protocols); |
|
145 | 145 | |
146 | 146 | # Go through $attrarr, and save the allowed attributes for this element |
147 | 147 | # in $attr2 |
148 | 148 | |
149 | - $attr2 = ''; |
|
149 | + $attr2 = ''; |
|
150 | 150 | |
151 | - foreach ($attrarr as $arreach) |
|
152 | - { |
|
151 | + foreach ($attrarr as $arreach) |
|
152 | + { |
|
153 | 153 | if (!@isset($allowed_html[strtolower($element)] |
154 | 154 | [strtolower($arreach['name'])])) |
155 | - continue; # the attribute is not allowed |
|
155 | + continue; # the attribute is not allowed |
|
156 | 156 | |
157 | 157 | $current = $allowed_html[strtolower($element)] |
158 | 158 | [strtolower($arreach['name'])]; |
159 | 159 | |
160 | 160 | if (!is_array($current)) |
161 | - $attr2 .= ' '.$arreach['whole']; |
|
161 | + $attr2 .= ' '.$arreach['whole']; |
|
162 | 162 | # there are no checks |
163 | 163 | |
164 | 164 | else |
165 | 165 | { |
166 | 166 | # there are some checks |
167 | - $ok = true; |
|
168 | - foreach ($current as $currkey => $currval) |
|
167 | + $ok = true; |
|
168 | + foreach ($current as $currkey => $currval) |
|
169 | 169 | if (!kses_check_attr_val($arreach['value'], $arreach['vless'], |
170 | - $currkey, $currval)) |
|
170 | + $currkey, $currval)) |
|
171 | 171 | { $ok = false; break; } |
172 | 172 | |
173 | - if ($ok) |
|
173 | + if ($ok) |
|
174 | 174 | $attr2 .= ' '.$arreach['whole']; # it passed them |
175 | 175 | } # if !is_array($current) |
176 | - } # foreach |
|
176 | + } # foreach |
|
177 | 177 | |
178 | 178 | # Remove any "<" or ">" characters |
179 | 179 | |
180 | - $attr2 = preg_replace('/[<>]/', '', $attr2); |
|
180 | + $attr2 = preg_replace('/[<>]/', '', $attr2); |
|
181 | 181 | |
182 | - return "<$element$attr2$xhtml_slash>"; |
|
182 | + return "<$element$attr2$xhtml_slash>"; |
|
183 | 183 | } # function kses_attr |
184 | 184 | |
185 | 185 | |
@@ -193,96 +193,96 @@ discard block |
||
193 | 193 | # from attribute values. |
194 | 194 | ############################################################################### |
195 | 195 | { |
196 | - $attrarr = array(); |
|
197 | - $mode = 0; |
|
198 | - $attrname = ''; |
|
196 | + $attrarr = array(); |
|
197 | + $mode = 0; |
|
198 | + $attrname = ''; |
|
199 | 199 | |
200 | 200 | # Loop through the whole attribute list |
201 | 201 | |
202 | - while (strlen($attr) != 0) |
|
203 | - { |
|
202 | + while (strlen($attr) != 0) |
|
203 | + { |
|
204 | 204 | $working = 0; # Was the last operation successful? |
205 | 205 | |
206 | 206 | switch ($mode) |
207 | 207 | { |
208 | - case 0: # attribute name, href for instance |
|
208 | + case 0: # attribute name, href for instance |
|
209 | 209 | |
210 | 210 | if (preg_match('/^([-a-zA-Z]+)/', $attr, $match)) |
211 | 211 | { |
212 | - $attrname = $match[1]; |
|
213 | - $working = $mode = 1; |
|
214 | - $attr = preg_replace('/^[-a-zA-Z]+/', '', $attr); |
|
212 | + $attrname = $match[1]; |
|
213 | + $working = $mode = 1; |
|
214 | + $attr = preg_replace('/^[-a-zA-Z]+/', '', $attr); |
|
215 | 215 | } |
216 | 216 | |
217 | 217 | break; |
218 | 218 | |
219 | - case 1: # equals sign or valueless ("selected") |
|
219 | + case 1: # equals sign or valueless ("selected") |
|
220 | 220 | |
221 | 221 | if (preg_match('/^\s*=\s*/', $attr)) # equals sign |
222 | 222 | { |
223 | - $working = 1; $mode = 2; |
|
224 | - $attr = preg_replace('/^\s*=\s*/', '', $attr); |
|
225 | - break; |
|
223 | + $working = 1; $mode = 2; |
|
224 | + $attr = preg_replace('/^\s*=\s*/', '', $attr); |
|
225 | + break; |
|
226 | 226 | } |
227 | 227 | |
228 | 228 | if (preg_match('/^\s+/', $attr)) # valueless |
229 | 229 | { |
230 | - $working = 1; $mode = 0; |
|
231 | - $attrarr[] = array |
|
230 | + $working = 1; $mode = 0; |
|
231 | + $attrarr[] = array |
|
232 | 232 | ('name' => $attrname, |
233 | - 'value' => '', |
|
234 | - 'whole' => $attrname, |
|
235 | - 'vless' => 'y'); |
|
236 | - $attr = preg_replace('/^\s+/', '', $attr); |
|
233 | + 'value' => '', |
|
234 | + 'whole' => $attrname, |
|
235 | + 'vless' => 'y'); |
|
236 | + $attr = preg_replace('/^\s+/', '', $attr); |
|
237 | 237 | } |
238 | 238 | |
239 | 239 | break; |
240 | 240 | |
241 | - case 2: # attribute value, a URL after href= for instance |
|
241 | + case 2: # attribute value, a URL after href= for instance |
|
242 | 242 | |
243 | 243 | if (preg_match('/^"([^"]*)"(\s+|$)/', $attr, $match)) |
244 | - # "value" |
|
244 | + # "value" |
|
245 | 245 | { |
246 | - $thisval = kses_bad_protocol($match[1], $allowed_protocols); |
|
246 | + $thisval = kses_bad_protocol($match[1], $allowed_protocols); |
|
247 | 247 | |
248 | - $attrarr[] = array |
|
248 | + $attrarr[] = array |
|
249 | 249 | ('name' => $attrname, |
250 | - 'value' => $thisval, |
|
251 | - 'whole' => "$attrname=\"$thisval\"", |
|
252 | - 'vless' => 'n'); |
|
253 | - $working = 1; $mode = 0; |
|
254 | - $attr = preg_replace('/^"[^"]*"(\s+|$)/', '', $attr); |
|
255 | - break; |
|
250 | + 'value' => $thisval, |
|
251 | + 'whole' => "$attrname=\"$thisval\"", |
|
252 | + 'vless' => 'n'); |
|
253 | + $working = 1; $mode = 0; |
|
254 | + $attr = preg_replace('/^"[^"]*"(\s+|$)/', '', $attr); |
|
255 | + break; |
|
256 | 256 | } |
257 | 257 | |
258 | 258 | if (preg_match("/^'([^']*)'(\s+|$)/", $attr, $match)) |
259 | - # 'value' |
|
259 | + # 'value' |
|
260 | 260 | { |
261 | - $thisval = kses_bad_protocol($match[1], $allowed_protocols); |
|
261 | + $thisval = kses_bad_protocol($match[1], $allowed_protocols); |
|
262 | 262 | |
263 | - $attrarr[] = array |
|
263 | + $attrarr[] = array |
|
264 | 264 | ('name' => $attrname, |
265 | - 'value' => $thisval, |
|
266 | - 'whole' => "$attrname='$thisval'", |
|
267 | - 'vless' => 'n'); |
|
268 | - $working = 1; $mode = 0; |
|
269 | - $attr = preg_replace("/^'[^']*'(\s+|$)/", '', $attr); |
|
270 | - break; |
|
265 | + 'value' => $thisval, |
|
266 | + 'whole' => "$attrname='$thisval'", |
|
267 | + 'vless' => 'n'); |
|
268 | + $working = 1; $mode = 0; |
|
269 | + $attr = preg_replace("/^'[^']*'(\s+|$)/", '', $attr); |
|
270 | + break; |
|
271 | 271 | } |
272 | 272 | |
273 | 273 | if (preg_match("%^([^\s\"']+)(\s+|$)%", $attr, $match)) |
274 | - # value |
|
274 | + # value |
|
275 | 275 | { |
276 | - $thisval = kses_bad_protocol($match[1], $allowed_protocols); |
|
276 | + $thisval = kses_bad_protocol($match[1], $allowed_protocols); |
|
277 | 277 | |
278 | - $attrarr[] = array |
|
278 | + $attrarr[] = array |
|
279 | 279 | ('name' => $attrname, |
280 | - 'value' => $thisval, |
|
281 | - 'whole' => "$attrname=\"$thisval\"", |
|
282 | - 'vless' => 'n'); |
|
283 | - # We add quotes to conform to W3C's HTML spec. |
|
284 | - $working = 1; $mode = 0; |
|
285 | - $attr = preg_replace("%^[^\s\"']+(\s+|$)%", '', $attr); |
|
280 | + 'value' => $thisval, |
|
281 | + 'whole' => "$attrname=\"$thisval\"", |
|
282 | + 'vless' => 'n'); |
|
283 | + # We add quotes to conform to W3C's HTML spec. |
|
284 | + $working = 1; $mode = 0; |
|
285 | + $attr = preg_replace("%^[^\s\"']+(\s+|$)%", '', $attr); |
|
286 | 286 | } |
287 | 287 | |
288 | 288 | break; |
@@ -290,21 +290,21 @@ discard block |
||
290 | 290 | |
291 | 291 | if ($working == 0) # not well formed, remove and try again |
292 | 292 | { |
293 | - $attr = kses_html_error($attr); |
|
294 | - $mode = 0; |
|
293 | + $attr = kses_html_error($attr); |
|
294 | + $mode = 0; |
|
295 | 295 | } |
296 | - } # while |
|
296 | + } # while |
|
297 | 297 | |
298 | - if ($mode == 1) |
|
299 | - # special case, for when the attribute list ends with a valueless |
|
300 | - # attribute like "selected" |
|
298 | + if ($mode == 1) |
|
299 | + # special case, for when the attribute list ends with a valueless |
|
300 | + # attribute like "selected" |
|
301 | 301 | $attrarr[] = array |
302 | - ('name' => $attrname, |
|
303 | - 'value' => '', |
|
304 | - 'whole' => $attrname, |
|
305 | - 'vless' => 'y'); |
|
302 | + ('name' => $attrname, |
|
303 | + 'value' => '', |
|
304 | + 'whole' => $attrname, |
|
305 | + 'vless' => 'y'); |
|
306 | 306 | |
307 | - return $attrarr; |
|
307 | + return $attrarr; |
|
308 | 308 | } # function kses_hair |
309 | 309 | |
310 | 310 | |
@@ -315,10 +315,10 @@ discard block |
||
315 | 315 | # with even more checks to come soon. |
316 | 316 | ############################################################################### |
317 | 317 | { |
318 | - $ok = true; |
|
318 | + $ok = true; |
|
319 | 319 | |
320 | - switch (strtolower($checkname)) |
|
321 | - { |
|
320 | + switch (strtolower($checkname)) |
|
321 | + { |
|
322 | 322 | case 'maxlen': |
323 | 323 | # The maxlen check makes sure that the attribute value has a length not |
324 | 324 | # greater than the given value. This can be used to avoid Buffer Overflows |
@@ -326,7 +326,7 @@ discard block |
||
326 | 326 | |
327 | 327 | if (strlen($value) > $checkvalue) |
328 | 328 | $ok = false; |
329 | - break; |
|
329 | + break; |
|
330 | 330 | |
331 | 331 | case 'minlen': |
332 | 332 | # The minlen check makes sure that the attribute value has a length not |
@@ -334,7 +334,7 @@ discard block |
||
334 | 334 | |
335 | 335 | if (strlen($value) < $checkvalue) |
336 | 336 | $ok = false; |
337 | - break; |
|
337 | + break; |
|
338 | 338 | |
339 | 339 | case 'maxval': |
340 | 340 | # The maxval check does two things: it checks that the attribute value is |
@@ -345,9 +345,9 @@ discard block |
||
345 | 345 | |
346 | 346 | if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
347 | 347 | $ok = false; |
348 | - if ($value > $checkvalue) |
|
348 | + if ($value > $checkvalue) |
|
349 | 349 | $ok = false; |
350 | - break; |
|
350 | + break; |
|
351 | 351 | |
352 | 352 | case 'minval': |
353 | 353 | # The minval check checks that the attribute value is a positive integer, |
@@ -355,9 +355,9 @@ discard block |
||
355 | 355 | |
356 | 356 | if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
357 | 357 | $ok = false; |
358 | - if ($value < $checkvalue) |
|
358 | + if ($value < $checkvalue) |
|
359 | 359 | $ok = false; |
360 | - break; |
|
360 | + break; |
|
361 | 361 | |
362 | 362 | case 'valueless': |
363 | 363 | # The valueless check checks if the attribute has a value |
@@ -367,10 +367,10 @@ discard block |
||
367 | 367 | |
368 | 368 | if (strtolower($checkvalue) != $vless) |
369 | 369 | $ok = false; |
370 | - break; |
|
371 | - } # switch |
|
370 | + break; |
|
371 | + } # switch |
|
372 | 372 | |
373 | - return $ok; |
|
373 | + return $ok; |
|
374 | 374 | } # function kses_check_attr_val |
375 | 375 | |
376 | 376 | |
@@ -382,17 +382,17 @@ discard block |
||
382 | 382 | # fooled by a string like "javascript:javascript:alert(57)". |
383 | 383 | ############################################################################### |
384 | 384 | { |
385 | - $string = kses_no_null($string); |
|
386 | - $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
387 | - $string2 = $string.'a'; |
|
385 | + $string = kses_no_null($string); |
|
386 | + $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
387 | + $string2 = $string.'a'; |
|
388 | 388 | |
389 | - while ($string != $string2) |
|
390 | - { |
|
389 | + while ($string != $string2) |
|
390 | + { |
|
391 | 391 | $string2 = $string; |
392 | 392 | $string = kses_bad_protocol_once($string, $allowed_protocols); |
393 | - } # while |
|
393 | + } # while |
|
394 | 394 | |
395 | - return $string; |
|
395 | + return $string; |
|
396 | 396 | } # function kses_bad_protocol |
397 | 397 | |
398 | 398 | |
@@ -401,10 +401,10 @@ discard block |
||
401 | 401 | # This function removes any NULL characters in $string. |
402 | 402 | ############################################################################### |
403 | 403 | { |
404 | - $string = preg_replace('/\0+/', '', $string); |
|
405 | - $string = preg_replace('/(\\\\0)+/', '', $string); |
|
404 | + $string = preg_replace('/\0+/', '', $string); |
|
405 | + $string = preg_replace('/(\\\\0)+/', '', $string); |
|
406 | 406 | |
407 | - return $string; |
|
407 | + return $string; |
|
408 | 408 | } # function kses_no_null |
409 | 409 | |
410 | 410 | |
@@ -415,7 +415,7 @@ discard block |
||
415 | 415 | # preg_replace(//e) seems to require this. |
416 | 416 | ############################################################################### |
417 | 417 | { |
418 | - return preg_replace('%\\\\"%', '"', $string); |
|
418 | + return preg_replace('%\\\\"%', '"', $string); |
|
419 | 419 | } # function kses_stripslashes |
420 | 420 | |
421 | 421 | |
@@ -424,21 +424,21 @@ discard block |
||
424 | 424 | # This function goes through an array, and changes the keys to all lower case. |
425 | 425 | ############################################################################### |
426 | 426 | { |
427 | - $outarray = array(); |
|
427 | + $outarray = array(); |
|
428 | 428 | |
429 | - foreach ($inarray as $inkey => $inval) |
|
430 | - { |
|
429 | + foreach ($inarray as $inkey => $inval) |
|
430 | + { |
|
431 | 431 | $outkey = strtolower($inkey); |
432 | 432 | $outarray[$outkey] = array(); |
433 | 433 | |
434 | 434 | foreach ($inval as $inkey2 => $inval2) |
435 | 435 | { |
436 | - $outkey2 = strtolower($inkey2); |
|
437 | - $outarray[$outkey][$outkey2] = $inval2; |
|
436 | + $outkey2 = strtolower($inkey2); |
|
437 | + $outarray[$outkey][$outkey2] = $inval2; |
|
438 | 438 | } # foreach $inval |
439 | - } # foreach $inarray |
|
439 | + } # foreach $inarray |
|
440 | 440 | |
441 | - return $outarray; |
|
441 | + return $outarray; |
|
442 | 442 | } # function kses_array_lc |
443 | 443 | |
444 | 444 | |
@@ -448,7 +448,7 @@ discard block |
||
448 | 448 | # Netscape 4. |
449 | 449 | ############################################################################### |
450 | 450 | { |
451 | - return preg_replace('%&\s*\{[^}]*(\}\s*;?|$)%', '', $string); |
|
451 | + return preg_replace('%&\s*\{[^}]*(\}\s*;?|$)%', '', $string); |
|
452 | 452 | } # function kses_js_entities |
453 | 453 | |
454 | 454 | |
@@ -459,7 +459,7 @@ discard block |
||
459 | 459 | # quotes and apostrophes as well. |
460 | 460 | ############################################################################### |
461 | 461 | { |
462 | - return preg_replace('/^("[^"]*("|$)|\'[^\']*(\'|$)|\S)*\s*/', '', $string); |
|
462 | + return preg_replace('/^("[^"]*("|$)|\'[^\']*(\'|$)|\S)*\s*/', '', $string); |
|
463 | 463 | } # function kses_html_error |
464 | 464 | |
465 | 465 | |
@@ -469,12 +469,12 @@ discard block |
||
469 | 469 | # handling whitespace and HTML entities. |
470 | 470 | ############################################################################### |
471 | 471 | { |
472 | - $string2 = preg_split('/:|:|:/i', $string, 2); |
|
473 | - if(isset($string2[1]) && !preg_match('%/\?%',$string2[0])) |
|
474 | - { |
|
475 | - $string = kses_bad_protocol_once2($string2[0],$allowed_protocols).trim($string2[1]); |
|
476 | - } |
|
477 | - return $string; |
|
472 | + $string2 = preg_split('/:|:|:/i', $string, 2); |
|
473 | + if(isset($string2[1]) && !preg_match('%/\?%',$string2[0])) |
|
474 | + { |
|
475 | + $string = kses_bad_protocol_once2($string2[0],$allowed_protocols).trim($string2[1]); |
|
476 | + } |
|
477 | + return $string; |
|
478 | 478 | } # function kses_bad_protocol_once |
479 | 479 | |
480 | 480 | |
@@ -484,24 +484,24 @@ discard block |
||
484 | 484 | # list or not, and returns different data depending on the answer. |
485 | 485 | ############################################################################### |
486 | 486 | { |
487 | - $string2 = kses_decode_entities($string); |
|
488 | - $string2 = preg_replace('/\s/', '', $string2); |
|
489 | - $string2 = kses_no_null($string2); |
|
490 | - $string2 = preg_replace('/\xad+/', '', $string2); |
|
491 | - # deals with Opera "feature" |
|
492 | - $string2 = strtolower($string2); |
|
493 | - |
|
494 | - $allowed = false; |
|
495 | - foreach ($allowed_protocols as $one_protocol) |
|
487 | + $string2 = kses_decode_entities($string); |
|
488 | + $string2 = preg_replace('/\s/', '', $string2); |
|
489 | + $string2 = kses_no_null($string2); |
|
490 | + $string2 = preg_replace('/\xad+/', '', $string2); |
|
491 | + # deals with Opera "feature" |
|
492 | + $string2 = strtolower($string2); |
|
493 | + |
|
494 | + $allowed = false; |
|
495 | + foreach ($allowed_protocols as $one_protocol) |
|
496 | 496 | if (strtolower($one_protocol) == $string2) |
497 | 497 | { |
498 | - $allowed = true; |
|
499 | - break; |
|
498 | + $allowed = true; |
|
499 | + break; |
|
500 | 500 | } |
501 | 501 | |
502 | - if ($allowed) |
|
502 | + if ($allowed) |
|
503 | 503 | return "$string2:"; |
504 | - else |
|
504 | + else |
|
505 | 505 | return ''; |
506 | 506 | } # function kses_bad_protocol_once2 |
507 | 507 | |
@@ -514,18 +514,18 @@ discard block |
||
514 | 514 | { |
515 | 515 | # Disarm all entities by converting & to & |
516 | 516 | |
517 | - $string = str_replace('&', '&', $string); |
|
517 | + $string = str_replace('&', '&', $string); |
|
518 | 518 | |
519 | 519 | # Change back the allowed entities in our entity whitelist |
520 | 520 | |
521 | - $string = preg_replace('/&([A-Za-z][A-Za-z0-9]{0,19});/', |
|
522 | - '&\\1;', $string); |
|
523 | - $string = preg_replace('/&#0*([0-9]{1,5});/e', |
|
524 | - 'kses_normalize_entities2("\\1")', $string); |
|
525 | - $string = preg_replace('/&#([Xx])0*(([0-9A-Fa-f]{2}){1,2});/', |
|
526 | - '&#\\1\\2;', $string); |
|
521 | + $string = preg_replace('/&([A-Za-z][A-Za-z0-9]{0,19});/', |
|
522 | + '&\\1;', $string); |
|
523 | + $string = preg_replace('/&#0*([0-9]{1,5});/e', |
|
524 | + 'kses_normalize_entities2("\\1")', $string); |
|
525 | + $string = preg_replace('/&#([Xx])0*(([0-9A-Fa-f]{2}){1,2});/', |
|
526 | + '&#\\1\\2;', $string); |
|
527 | 527 | |
528 | - return $string; |
|
528 | + return $string; |
|
529 | 529 | } # function kses_normalize_entities |
530 | 530 | |
531 | 531 | |
@@ -535,7 +535,7 @@ discard block |
||
535 | 535 | # and nothing more for &#number; entities. |
536 | 536 | ############################################################################### |
537 | 537 | { |
538 | - return (($i > 65535) ? "&#$i;" : "&#$i;"); |
|
538 | + return (($i > 65535) ? "&#$i;" : "&#$i;"); |
|
539 | 539 | } # function kses_normalize_entities2 |
540 | 540 | |
541 | 541 | |
@@ -546,11 +546,11 @@ discard block |
||
546 | 546 | # URL protocol whitelisting system anyway. |
547 | 547 | ############################################################################### |
548 | 548 | { |
549 | - $string = preg_replace('/&#([0-9]+);/e', 'chr("\\1")', $string); |
|
550 | - $string = preg_replace('/&#[Xx]([0-9A-Fa-f]+);/e', 'chr(hexdec("\\1"))', |
|
551 | - $string); |
|
549 | + $string = preg_replace('/&#([0-9]+);/e', 'chr("\\1")', $string); |
|
550 | + $string = preg_replace('/&#[Xx]([0-9A-Fa-f]+);/e', 'chr(hexdec("\\1"))', |
|
551 | + $string); |
|
552 | 552 | |
553 | - return $string; |
|
553 | + return $string; |
|
554 | 554 | } # function kses_decode_entities |
555 | 555 | |
556 | 556 | ?> |
@@ -97,8 +97,8 @@ discard block |
||
97 | 97 | * @return string |
98 | 98 | */ |
99 | 99 | function kses($string, $allowed_html, $allowed_protocols = |
100 | - array('http', 'https', 'ftp', 'news', 'nntp', 'telnet', |
|
101 | - 'gopher', 'mailto')) |
|
100 | + array('http', 'https', 'ftp', 'news', 'nntp', 'telnet', |
|
101 | + 'gopher', 'mailto')) |
|
102 | 102 | { |
103 | 103 | $string = kses_no_null($string); |
104 | 104 | $string = kses_js_entities($string); |
@@ -218,7 +218,7 @@ discard block |
||
218 | 218 | // No attributes are allowed for closing elements |
219 | 219 | |
220 | 220 | return kses_attr("$slash$elem", $attrlist, $allowed_html, |
221 | - $allowed_protocols); |
|
221 | + $allowed_protocols); |
|
222 | 222 | } |
223 | 223 | |
224 | 224 | /** |
@@ -261,11 +261,11 @@ discard block |
||
261 | 261 | foreach ($attrarr as $arreach) |
262 | 262 | { |
263 | 263 | if (!@isset($allowed_html[strtolower($element)] |
264 | - [strtolower($arreach['name'])])) |
|
264 | + [strtolower($arreach['name'])])) |
|
265 | 265 | continue; // the attribute is not allowed |
266 | 266 | |
267 | 267 | $current = $allowed_html[strtolower($element)] |
268 | - [strtolower($arreach['name'])]; |
|
268 | + [strtolower($arreach['name'])]; |
|
269 | 269 | if ($current == '') |
270 | 270 | continue; // the attribute is not allowed |
271 | 271 | |
@@ -279,7 +279,7 @@ discard block |
||
279 | 279 | $ok = true; |
280 | 280 | foreach ($current as $currkey => $currval) |
281 | 281 | if (!kses_check_attr_val($arreach['value'], $arreach['vless'], |
282 | - $currkey, $currval)) |
|
282 | + $currkey, $currval)) |
|
283 | 283 | { $ok = false; break; } |
284 | 284 | |
285 | 285 | if ( strtolower($arreach['name']) == 'style' ) { |
@@ -1,6 +1,6 @@ discard block |
||
1 | 1 | <?php |
2 | 2 | |
3 | - /* |
|
3 | + /* |
|
4 | 4 | * ========================================================================================== |
5 | 5 | * |
6 | 6 | * This program is free software and open source software; you can redistribute |
@@ -21,1146 +21,1146 @@ discard block |
||
21 | 21 | * ========================================================================================== |
22 | 22 | */ |
23 | 23 | |
24 | - /** |
|
25 | - * Class file for PHP5 OOP version of kses |
|
26 | - * |
|
27 | - * This is an updated version of kses to work with PHP5 that works under E_STRICT. |
|
28 | - * |
|
29 | - * This version is a bit of a rewrite to match my own coding style and use some of the |
|
30 | - * capabilities allowed in PHP5. Since this was a significant rewrite, but it still |
|
31 | - * maintains backward compatibility syntax-wise, the version number is now 1.0.0. Any |
|
32 | - * minor changes that do not break compatibility will be indicated in the second or third |
|
33 | - * digits. Anything that breaks compatibility will change the major version number. |
|
34 | - * |
|
35 | - * PHP5 specific changes: |
|
36 | - * + Private methods are now in place |
|
37 | - * + __construct() is now used rather then the standard class name 'kses()' |
|
38 | - * + Kses will not load in any version less that PHP5 |
|
39 | - * Other modifications: |
|
40 | - * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
41 | - * + Method names have been changed to reflect status as verbs |
|
42 | - * + One line methods have been folded into the code |
|
43 | - * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
44 | - * + Kses5 now works in E_STRICT |
|
45 | - * + Version number is 1.0.0 to reflect serious code changes |
|
46 | - * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol(), RemoveProtocols() and SetProtocols() |
|
47 | - * + Deprecated _hook(), Protocols() |
|
48 | - * |
|
49 | - * @package kses |
|
50 | - * @subpackage kses5 |
|
51 | - */ |
|
52 | - |
|
53 | - if(substr(phpversion(), 0, 1) < 5) |
|
54 | - { |
|
55 | - die("Class kses requires PHP 5 or higher."); |
|
56 | - } |
|
57 | - |
|
58 | - /** |
|
59 | - * Only install KSES5 once |
|
60 | - */ |
|
61 | - if(!defined('KSES_CLASS_PHP5')) |
|
62 | - { |
|
63 | - define('KSES_CLASS_PHP5', true); |
|
64 | - |
|
65 | - /** |
|
66 | - * Kses strips evil scripts! |
|
67 | - * |
|
68 | - * This class provides the capability for removing unwanted HTML/XHTML, attributes from |
|
69 | - * tags, and protocols contained in links. The net result is a much more powerful tool |
|
70 | - * than the PHP internal strip_tags() |
|
71 | - * |
|
72 | - * This is a fork of a slick piece of procedural code called 'kses' written by Ulf Harnhammar. |
|
73 | - * |
|
74 | - * The original class for PHP4 was basically a wrapper around all of the functions in |
|
75 | - * the procedural code written by Ulf, and was released 7/25/2003. |
|
76 | - * |
|
77 | - * This version is a bit of a rewrite to match my own coding style and use some of the |
|
78 | - * capabilities allowed in PHP5. Since this was a significant rewrite, but it still |
|
79 | - * maintains backward compatibility syntax-wise, the version number is now 1.0.0. Any |
|
80 | - * minor changes that do not break compatibility will be indicated in the second or third |
|
81 | - * digits. Anything that breaks compatibility will change the major version number. |
|
82 | - * |
|
83 | - * PHP5 specific changes: |
|
84 | - * + Private methods are now in place |
|
85 | - * + __construct() is now used rather then the standard class name 'kses()' |
|
86 | - * + Kses5 will not load in any version less that PHP5 |
|
87 | - * Other modifications: |
|
88 | - * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
89 | - * + Method names have been changed to reflect status as verbs |
|
90 | - * + One line methods have been folded into the code |
|
91 | - * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
92 | - * + Kses now works in E_STRICT |
|
93 | - * + Initial Version number set to 1.0.0 to reflect serious code changes |
|
94 | - * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol(), RemoveProtocols() and SetProtocols() |
|
95 | - * + Deprecated _hook(), Protocols() |
|
96 | - * + Integrated code from kses 0.2.2 into class. |
|
97 | - * + Added methods DumpProtocols(), DumpMethods() |
|
98 | - * |
|
99 | - * @author Richard R. V�squez, Jr. (Original procedural code by Ulf H�rnhammar) |
|
100 | - * @link http://sourceforge.net/projects/kses/ Home Page for Kses |
|
101 | - * @link http://chaos.org/contact/ Contact page with current email address for Richard Vasquez |
|
102 | - * @copyright Richard R. V�squez, Jr. 2005 |
|
103 | - * @version PHP5 OOP 1.0.2 |
|
104 | - * @license http://www.gnu.org/licenses/gpl.html GNU Public License |
|
105 | - * @package kses |
|
106 | - */ |
|
107 | - class kses5 |
|
108 | - { |
|
109 | - /**#@+ |
|
24 | + /** |
|
25 | + * Class file for PHP5 OOP version of kses |
|
26 | + * |
|
27 | + * This is an updated version of kses to work with PHP5 that works under E_STRICT. |
|
28 | + * |
|
29 | + * This version is a bit of a rewrite to match my own coding style and use some of the |
|
30 | + * capabilities allowed in PHP5. Since this was a significant rewrite, but it still |
|
31 | + * maintains backward compatibility syntax-wise, the version number is now 1.0.0. Any |
|
32 | + * minor changes that do not break compatibility will be indicated in the second or third |
|
33 | + * digits. Anything that breaks compatibility will change the major version number. |
|
34 | + * |
|
35 | + * PHP5 specific changes: |
|
36 | + * + Private methods are now in place |
|
37 | + * + __construct() is now used rather then the standard class name 'kses()' |
|
38 | + * + Kses will not load in any version less that PHP5 |
|
39 | + * Other modifications: |
|
40 | + * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
41 | + * + Method names have been changed to reflect status as verbs |
|
42 | + * + One line methods have been folded into the code |
|
43 | + * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
44 | + * + Kses5 now works in E_STRICT |
|
45 | + * + Version number is 1.0.0 to reflect serious code changes |
|
46 | + * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol(), RemoveProtocols() and SetProtocols() |
|
47 | + * + Deprecated _hook(), Protocols() |
|
48 | + * |
|
49 | + * @package kses |
|
50 | + * @subpackage kses5 |
|
51 | + */ |
|
52 | + |
|
53 | + if(substr(phpversion(), 0, 1) < 5) |
|
54 | + { |
|
55 | + die("Class kses requires PHP 5 or higher."); |
|
56 | + } |
|
57 | + |
|
58 | + /** |
|
59 | + * Only install KSES5 once |
|
60 | + */ |
|
61 | + if(!defined('KSES_CLASS_PHP5')) |
|
62 | + { |
|
63 | + define('KSES_CLASS_PHP5', true); |
|
64 | + |
|
65 | + /** |
|
66 | + * Kses strips evil scripts! |
|
67 | + * |
|
68 | + * This class provides the capability for removing unwanted HTML/XHTML, attributes from |
|
69 | + * tags, and protocols contained in links. The net result is a much more powerful tool |
|
70 | + * than the PHP internal strip_tags() |
|
71 | + * |
|
72 | + * This is a fork of a slick piece of procedural code called 'kses' written by Ulf Harnhammar. |
|
73 | + * |
|
74 | + * The original class for PHP4 was basically a wrapper around all of the functions in |
|
75 | + * the procedural code written by Ulf, and was released 7/25/2003. |
|
76 | + * |
|
77 | + * This version is a bit of a rewrite to match my own coding style and use some of the |
|
78 | + * capabilities allowed in PHP5. Since this was a significant rewrite, but it still |
|
79 | + * maintains backward compatibility syntax-wise, the version number is now 1.0.0. Any |
|
80 | + * minor changes that do not break compatibility will be indicated in the second or third |
|
81 | + * digits. Anything that breaks compatibility will change the major version number. |
|
82 | + * |
|
83 | + * PHP5 specific changes: |
|
84 | + * + Private methods are now in place |
|
85 | + * + __construct() is now used rather then the standard class name 'kses()' |
|
86 | + * + Kses5 will not load in any version less that PHP5 |
|
87 | + * Other modifications: |
|
88 | + * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
89 | + * + Method names have been changed to reflect status as verbs |
|
90 | + * + One line methods have been folded into the code |
|
91 | + * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
92 | + * + Kses now works in E_STRICT |
|
93 | + * + Initial Version number set to 1.0.0 to reflect serious code changes |
|
94 | + * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol(), RemoveProtocols() and SetProtocols() |
|
95 | + * + Deprecated _hook(), Protocols() |
|
96 | + * + Integrated code from kses 0.2.2 into class. |
|
97 | + * + Added methods DumpProtocols(), DumpMethods() |
|
98 | + * |
|
99 | + * @author Richard R. V�squez, Jr. (Original procedural code by Ulf H�rnhammar) |
|
100 | + * @link http://sourceforge.net/projects/kses/ Home Page for Kses |
|
101 | + * @link http://chaos.org/contact/ Contact page with current email address for Richard Vasquez |
|
102 | + * @copyright Richard R. V�squez, Jr. 2005 |
|
103 | + * @version PHP5 OOP 1.0.2 |
|
104 | + * @license http://www.gnu.org/licenses/gpl.html GNU Public License |
|
105 | + * @package kses |
|
106 | + */ |
|
107 | + class kses5 |
|
108 | + { |
|
109 | + /**#@+ |
|
110 | 110 | * @access private |
111 | 111 | * @var array |
112 | 112 | */ |
113 | - private $allowed_protocols; |
|
114 | - private $allowed_html; |
|
115 | - /**#@-*/ |
|
116 | - |
|
117 | - /** |
|
118 | - * Constructor for kses. |
|
119 | - * |
|
120 | - * This sets a default collection of protocols allowed in links, and creates an |
|
121 | - * empty set of allowed HTML tags. |
|
122 | - * @since PHP5 OOP 1.0.0 |
|
123 | - */ |
|
124 | - public function __construct() |
|
125 | - { |
|
126 | - /** |
|
127 | - * You could add protocols such as ftp, new, gopher, mailto, irc, etc. |
|
128 | - * |
|
129 | - * The base values the original kses provided were: |
|
130 | - * 'http', 'https', 'ftp', 'news', 'nntp', 'telnet', 'gopher', 'mailto' |
|
131 | - */ |
|
132 | - $this->allowed_protocols = array('http', 'ftp', 'mailto'); |
|
133 | - $this->allowed_html = array(); |
|
134 | - } |
|
135 | - |
|
136 | - /** |
|
137 | - * Basic task of kses - parses $string and strips it as required. |
|
138 | - * |
|
139 | - * This method strips all the disallowed (X)HTML tags, attributes |
|
140 | - * and protocols from the input $string. |
|
141 | - * |
|
142 | - * @access public |
|
143 | - * @param string $string String to be stripped of 'evil scripts' |
|
144 | - * @return string The stripped string |
|
145 | - * @since PHP4 OOP 0.0.1 |
|
146 | - */ |
|
147 | - public function Parse($string = "") |
|
148 | - { |
|
149 | - if (get_magic_quotes_gpc()) |
|
150 | - { |
|
151 | - $string = stripslashes($string); |
|
152 | - } |
|
153 | - $string = $this->removeNulls($string); |
|
154 | - // Remove JavaScript entities from early Netscape 4 versions |
|
155 | - $string = preg_replace('%&\s*\{[^}]*(\}\s*;?|$)%', '', $string); |
|
156 | - $string = $this->normalizeEntities($string); |
|
157 | - $string = $this->filterKsesTextHook($string); |
|
158 | - $string = preg_replace('%(<' . '[^>]*' . '(>|$)' . '|>)%e', "\$this->stripTags('\\1')", $string); |
|
159 | - return $string; |
|
160 | - } |
|
161 | - |
|
162 | - /** |
|
163 | - * Allows for single/batch addition of protocols |
|
164 | - * |
|
165 | - * This method accepts one argument that can be either a string |
|
166 | - * or an array of strings. Invalid data will be ignored. |
|
167 | - * |
|
168 | - * The argument will be processed, and each string will be added |
|
169 | - * via AddProtocol(). |
|
170 | - * |
|
171 | - * @access public |
|
172 | - * @param mixed , A string or array of protocols that will be added to the internal list of allowed protocols. |
|
173 | - * @return bool Status of adding valid protocols. |
|
174 | - * @see AddProtocol() |
|
175 | - * @since PHP5 OOP 1.0.0 |
|
176 | - */ |
|
177 | - public function AddProtocols() |
|
178 | - { |
|
179 | - $c_args = func_num_args(); |
|
180 | - if($c_args != 1) |
|
181 | - { |
|
182 | - trigger_error("kses5::AddProtocols() did not receive an argument.", E_USER_WARNING); |
|
183 | - return false; |
|
184 | - } |
|
185 | - |
|
186 | - $protocol_data = func_get_arg(0); |
|
187 | - |
|
188 | - if(is_array($protocol_data) && count($protocol_data) > 0) |
|
189 | - { |
|
190 | - foreach($protocol_data as $protocol) |
|
191 | - { |
|
192 | - $this->AddProtocol($protocol); |
|
193 | - } |
|
194 | - return true; |
|
195 | - } |
|
196 | - elseif(is_string($protocol_data)) |
|
197 | - { |
|
198 | - $this->AddProtocol($protocol_data); |
|
199 | - return true; |
|
200 | - } |
|
201 | - else |
|
202 | - { |
|
203 | - trigger_error("kses5::AddProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
204 | - return false; |
|
205 | - } |
|
206 | - } |
|
207 | - |
|
208 | - /** |
|
209 | - * Allows for single/batch addition of protocols |
|
210 | - * |
|
211 | - * @deprecated Use AddProtocols() |
|
212 | - * @see AddProtocols() |
|
213 | - * @return bool |
|
214 | - * @since PHP4 OOP 0.0.1 |
|
215 | - */ |
|
216 | - public function Protocols() |
|
217 | - { |
|
218 | - $c_args = func_num_args(); |
|
219 | - if($c_args != 1) |
|
220 | - { |
|
221 | - trigger_error("kses5::Protocols() did not receive an argument.", E_USER_WARNING); |
|
222 | - return false; |
|
223 | - } |
|
224 | - |
|
225 | - return $this->AddProtocols(func_get_arg(0)); |
|
226 | - } |
|
227 | - |
|
228 | - /** |
|
229 | - * Adds a single protocol to $this->allowed_protocols. |
|
230 | - * |
|
231 | - * This method accepts a string argument and adds it to |
|
232 | - * the list of allowed protocols to keep when performing |
|
233 | - * Parse(). |
|
234 | - * |
|
235 | - * @access public |
|
236 | - * @param string $protocol The name of the protocol to be added. |
|
237 | - * @return bool Status of adding valid protocol. |
|
238 | - * @since PHP4 OOP 0.0.1 |
|
239 | - */ |
|
240 | - public function AddProtocol($protocol = "") |
|
241 | - { |
|
242 | - if(!is_string($protocol)) |
|
243 | - { |
|
244 | - trigger_error("kses5::AddProtocol() requires a string.", E_USER_WARNING); |
|
245 | - return false; |
|
246 | - } |
|
247 | - |
|
248 | - // Remove any inadvertent ':' at the end of the protocol. |
|
249 | - if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
250 | - { |
|
251 | - $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
252 | - } |
|
253 | - |
|
254 | - $protocol = strtolower(trim($protocol)); |
|
255 | - if($protocol == "") |
|
256 | - { |
|
257 | - trigger_error("kses5::AddProtocol() tried to add an empty/NULL protocol.", E_USER_WARNING); |
|
258 | - return false; |
|
259 | - } |
|
260 | - |
|
261 | - // prevent duplicate protocols from being added. |
|
262 | - if(!in_array($protocol, $this->allowed_protocols)) |
|
263 | - { |
|
264 | - array_push($this->allowed_protocols, $protocol); |
|
265 | - sort($this->allowed_protocols); |
|
266 | - } |
|
267 | - return true; |
|
268 | - } |
|
269 | - |
|
270 | - /** |
|
271 | - * Removes a single protocol from $this->allowed_protocols. |
|
272 | - * |
|
273 | - * This method accepts a string argument and removes it from |
|
274 | - * the list of allowed protocols to keep when performing |
|
275 | - * Parse(). |
|
276 | - * |
|
277 | - * @access public |
|
278 | - * @param string $protocol The name of the protocol to be removed. |
|
279 | - * @return bool Status of removing valid protocol. |
|
280 | - * @since PHP5 OOP 1.0.0 |
|
281 | - */ |
|
282 | - public function RemoveProtocol($protocol = "") |
|
283 | - { |
|
284 | - if(!is_string($protocol)) |
|
285 | - { |
|
286 | - trigger_error("kses5::RemoveProtocol() requires a string.", E_USER_WARNING); |
|
287 | - return false; |
|
288 | - } |
|
289 | - |
|
290 | - // Remove any inadvertent ':' at the end of the protocol. |
|
291 | - if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
292 | - { |
|
293 | - $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
294 | - } |
|
295 | - |
|
296 | - $protocol = strtolower(trim($protocol)); |
|
297 | - if($protocol == "") |
|
298 | - { |
|
299 | - trigger_error("kses5::RemoveProtocol() tried to remove an empty/NULL protocol.", E_USER_WARNING); |
|
300 | - return false; |
|
301 | - } |
|
302 | - |
|
303 | - // Ensures that the protocol exists before removing it. |
|
304 | - if(in_array($protocol, $this->allowed_protocols)) |
|
305 | - { |
|
306 | - $this->allowed_protocols = array_diff($this->allowed_protocols, array($protocol)); |
|
307 | - sort($this->allowed_protocols); |
|
308 | - } |
|
309 | - |
|
310 | - return true; |
|
311 | - } |
|
312 | - |
|
313 | - /** |
|
314 | - * Allows for single/batch removal of protocols |
|
315 | - * |
|
316 | - * This method accepts one argument that can be either a string |
|
317 | - * or an array of strings. Invalid data will be ignored. |
|
318 | - * |
|
319 | - * The argument will be processed, and each string will be removed |
|
320 | - * via RemoveProtocol(). |
|
321 | - * |
|
322 | - * @access public |
|
323 | - * @param mixed , A string or array of protocols that will be removed from the internal list of allowed protocols. |
|
324 | - * @return bool Status of removing valid protocols. |
|
325 | - * @see RemoveProtocol() |
|
326 | - * @since PHP5 OOP 1.0.0 |
|
327 | - */ |
|
328 | - public function RemoveProtocols() |
|
329 | - { |
|
330 | - $c_args = func_num_args(); |
|
331 | - if($c_args != 1) |
|
332 | - { |
|
333 | - return false; |
|
334 | - } |
|
335 | - |
|
336 | - $protocol_data = func_get_arg(0); |
|
337 | - |
|
338 | - if(is_array($protocol_data) && count($protocol_data) > 0) |
|
339 | - { |
|
340 | - foreach($protocol_data as $protocol) |
|
341 | - { |
|
342 | - $this->RemoveProtocol($protocol); |
|
343 | - } |
|
344 | - } |
|
345 | - elseif(is_string($protocol_data)) |
|
346 | - { |
|
347 | - $this->RemoveProtocol($protocol_data); |
|
348 | - return true; |
|
349 | - } |
|
350 | - else |
|
351 | - { |
|
352 | - trigger_error("kses5::RemoveProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
353 | - return false; |
|
354 | - } |
|
355 | - } |
|
356 | - |
|
357 | - /** |
|
358 | - * Allows for single/batch replacement of protocols |
|
359 | - * |
|
360 | - * This method accepts one argument that can be either a string |
|
361 | - * or an array of strings. Invalid data will be ignored. |
|
362 | - * |
|
363 | - * Existing protocols will be removed, then the argument will be |
|
364 | - * processed, and each string will be added via AddProtocol(). |
|
365 | - * |
|
366 | - * @access public |
|
367 | - * @param mixed , A string or array of protocols that will be the new internal list of allowed protocols. |
|
368 | - * @return bool Status of replacing valid protocols. |
|
369 | - * @since PHP5 OOP 1.0.1 |
|
370 | - * @see AddProtocol() |
|
371 | - */ |
|
372 | - public function SetProtocols() |
|
373 | - { |
|
374 | - $c_args = func_num_args(); |
|
375 | - if($c_args != 1) |
|
376 | - { |
|
377 | - trigger_error("kses5::SetProtocols() did not receive an argument.", E_USER_WARNING); |
|
378 | - return false; |
|
379 | - } |
|
380 | - |
|
381 | - $protocol_data = func_get_arg(0); |
|
382 | - |
|
383 | - if(is_array($protocol_data) && count($protocol_data) > 0) |
|
384 | - { |
|
385 | - $this->allowed_protocols = array(); |
|
386 | - foreach($protocol_data as $protocol) |
|
387 | - { |
|
388 | - $this->AddProtocol($protocol); |
|
389 | - } |
|
390 | - return true; |
|
391 | - } |
|
392 | - elseif(is_string($protocol_data)) |
|
393 | - { |
|
394 | - $this->allowed_protocols = array(); |
|
395 | - $this->AddProtocol($protocol_data); |
|
396 | - return true; |
|
397 | - } |
|
398 | - else |
|
399 | - { |
|
400 | - trigger_error("kses5::SetProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
401 | - return false; |
|
402 | - } |
|
403 | - } |
|
404 | - |
|
405 | - /** |
|
406 | - * Raw dump of allowed protocols |
|
407 | - * |
|
408 | - * This returns an indexed array of allowed protocols for a particular KSES |
|
409 | - * instantiation. |
|
410 | - * |
|
411 | - * @access public |
|
412 | - * @return array The list of allowed protocols. |
|
413 | - * @since PHP5 OOP 1.0.2 |
|
414 | - */ |
|
415 | - public function DumpProtocols() |
|
416 | - { |
|
417 | - return $this->allowed_protocols; |
|
418 | - } |
|
419 | - |
|
420 | - /** |
|
421 | - * Raw dump of allowed (X)HTML elements |
|
422 | - * |
|
423 | - * This returns an indexed array of allowed (X)HTML elements and attributes |
|
424 | - * for a particular KSES instantiation. |
|
425 | - * |
|
426 | - * @access public |
|
427 | - * @return array The list of allowed elements. |
|
428 | - * @since PHP5 OOP 1.0.2 |
|
429 | - */ |
|
430 | - public function DumpElements() |
|
431 | - { |
|
432 | - return $this->allowed_html; |
|
433 | - } |
|
434 | - |
|
435 | - |
|
436 | - /** |
|
437 | - * Adds valid (X)HTML with corresponding attributes that will be kept when stripping 'evil scripts'. |
|
438 | - * |
|
439 | - * This method accepts one argument that can be either a string |
|
440 | - * or an array of strings. Invalid data will be ignored. |
|
441 | - * |
|
442 | - * @access public |
|
443 | - * @param string $tag (X)HTML tag that will be allowed after stripping text. |
|
444 | - * @param array $attribs Associative array of allowed attributes - key => attribute name - value => attribute parameter |
|
445 | - * @return bool Status of Adding (X)HTML and attributes. |
|
446 | - * @since PHP4 OOP 0.0.1 |
|
447 | - */ |
|
448 | - public function AddHTML($tag = "", $attribs = array()) |
|
449 | - { |
|
450 | - if(!is_string($tag)) |
|
451 | - { |
|
452 | - trigger_error("kses5::AddHTML() requires the tag to be a string", E_USER_WARNING); |
|
453 | - return false; |
|
454 | - } |
|
455 | - |
|
456 | - $tag = strtolower(trim($tag)); |
|
457 | - if($tag == "") |
|
458 | - { |
|
459 | - trigger_error("kses5::AddHTML() tried to add an empty/NULL tag", E_USER_WARNING); |
|
460 | - return false; |
|
461 | - } |
|
462 | - |
|
463 | - if(!is_array($attribs)) |
|
464 | - { |
|
465 | - trigger_error("kses5::AddHTML() requires an array (even an empty one) of attributes for '$tag'", E_USER_WARNING); |
|
466 | - return false; |
|
467 | - } |
|
468 | - |
|
469 | - $new_attribs = array(); |
|
470 | - if(is_array($attribs) && count($attribs) > 0) |
|
471 | - { |
|
472 | - foreach($attribs as $idx1 => $val1) |
|
473 | - { |
|
474 | - $new_idx1 = strtolower($idx1); |
|
475 | - $new_val1 = $attribs[$idx1]; |
|
476 | - |
|
477 | - if(is_array($new_val1) && count($attribs) > 0) |
|
478 | - { |
|
479 | - $tmp_val = array(); |
|
480 | - foreach($new_val1 as $idx2 => $val2) |
|
481 | - { |
|
482 | - $new_idx2 = strtolower($idx2); |
|
483 | - $tmp_val[$new_idx2] = $val2; |
|
484 | - } |
|
485 | - $new_val1 = $tmp_val; |
|
486 | - } |
|
487 | - |
|
488 | - $new_attribs[$new_idx1] = $new_val1; |
|
489 | - } |
|
490 | - } |
|
491 | - |
|
492 | - $this->allowed_html[$tag] = $new_attribs; |
|
493 | - return true; |
|
494 | - } |
|
495 | - |
|
496 | - /** |
|
497 | - * This method removes any NULL characters in $string. |
|
498 | - * |
|
499 | - * @access private |
|
500 | - * @param string $string |
|
501 | - * @return string String without any NULL/chr(173) |
|
502 | - * @since PHP4 OOP 0.0.1 |
|
503 | - */ |
|
504 | - private function removeNulls($string) |
|
505 | - { |
|
506 | - $string = preg_replace('/\0+/', '', $string); |
|
507 | - $string = preg_replace('/(\\\\0)+/', '', $string); |
|
508 | - return $string; |
|
509 | - } |
|
510 | - |
|
511 | - /** |
|
512 | - * Normalizes HTML entities |
|
513 | - * |
|
514 | - * This function normalizes HTML entities. It will convert "AT&T" to the correct |
|
515 | - * "AT&T", ":" to ":", "&#XYZZY;" to "&#XYZZY;" and so on. |
|
516 | - * |
|
517 | - * @access private |
|
518 | - * @param string $string |
|
519 | - * @return string String with normalized entities |
|
520 | - * @since PHP4 OOP 0.0.1 |
|
521 | - */ |
|
522 | - private function normalizeEntities($string) |
|
523 | - { |
|
524 | - # Disarm all entities by converting & to & |
|
525 | - $string = str_replace('&', '&', $string); |
|
526 | - |
|
527 | - # TODO: Change back (Keep?) the allowed entities in our entity white list |
|
528 | - |
|
529 | - # Keeps entities that start with [A-Za-z] |
|
530 | - $string = preg_replace( |
|
531 | - '/&([A-Za-z][A-Za-z0-9]{0,19});/', |
|
532 | - '&\\1;', |
|
533 | - $string |
|
534 | - ); |
|
535 | - |
|
536 | - # Change numeric entities to valid 16 bit values |
|
537 | - |
|
538 | - $string = preg_replace( |
|
539 | - '/&#0*([0-9]{1,5});/e', |
|
540 | - '\$this->normalizeEntities16bit("\\1")', |
|
541 | - $string |
|
542 | - ); |
|
543 | - |
|
544 | - # Change &XHHHHHHH (Hex digits) to 16 bit hex values |
|
545 | - $string = preg_replace( |
|
546 | - '/&#([Xx])0*(([0-9A-Fa-f]{2}){1,2});/', |
|
547 | - '&#\\1\\2;', |
|
548 | - $string |
|
549 | - ); |
|
550 | - |
|
551 | - return $string; |
|
552 | - } |
|
553 | - |
|
554 | - /** |
|
555 | - * Helper method used by normalizeEntites() |
|
556 | - * |
|
557 | - * This method helps normalizeEntities() to only accept 16 bit values |
|
558 | - * and nothing more for &#number; entities. |
|
559 | - * |
|
560 | - * This method helps normalize_entities() during a preg_replace() |
|
561 | - * where a &#(0)*XXXXX; occurs. The '(0)*XXXXXX' value is converted to |
|
562 | - * a number and the result is returned as a numeric entity if the number |
|
563 | - * is less than 65536. Otherwise, the value is returned 'as is'. |
|
564 | - * |
|
565 | - * @access private |
|
566 | - * @param string $i |
|
567 | - * @return string Normalized numeric entity |
|
568 | - * @see normalizeEntities() |
|
569 | - * @since PHP4 OOP 0.0.1 |
|
570 | - */ |
|
571 | - private function normalizeEntities16bit($i) |
|
572 | - { |
|
573 | - return (($i > 65535) ? "&#$i;" : "&#$i;"); |
|
574 | - } |
|
575 | - |
|
576 | - /** |
|
577 | - * Allows for additional user defined modifications to text. |
|
578 | - * |
|
579 | - * This method allows for additional modifications to be performed on |
|
580 | - * a string that's being run through Parse(). Currently, it returns the |
|
581 | - * input string 'as is'. |
|
582 | - * |
|
583 | - * This method is provided for users to extend the kses class for their own |
|
584 | - * requirements. |
|
585 | - * |
|
586 | - * @access public |
|
587 | - * @param string $string String to perfrom additional modifications on. |
|
588 | - * @return string User modified string. |
|
589 | - * @see Parse() |
|
590 | - * @since PHP5 OOP 1.0.0 |
|
591 | - */ |
|
592 | - private function filterKsesTextHook($string) |
|
593 | - { |
|
594 | - return $string; |
|
595 | - } |
|
596 | - |
|
597 | - /** |
|
598 | - * Allows for additional user defined modifications to text. |
|
599 | - * |
|
600 | - * @deprecated use filterKsesTextHook() |
|
601 | - * @param string $string |
|
602 | - * @return string |
|
603 | - * @see filterKsesTextHook() |
|
604 | - * @since PHP4 OOP 0.0.1 |
|
605 | - */ |
|
606 | - private function _hook($string) |
|
607 | - { |
|
608 | - return $this->filterKsesTextHook($string); |
|
609 | - } |
|
610 | - |
|
611 | - /** |
|
612 | - * This method goes through an array, and changes the keys to all lower case. |
|
613 | - * |
|
614 | - * @access private |
|
615 | - * @param array $in_array Associative array |
|
616 | - * @return array Modified array |
|
617 | - * @since PHP4 OOP 0.0.1 |
|
618 | - */ |
|
619 | - private function makeArrayKeysLowerCase($in_array) |
|
620 | - { |
|
621 | - $out_array = array(); |
|
622 | - |
|
623 | - if(is_array($in_array) && count($in_array) > 0) |
|
624 | - { |
|
625 | - foreach ($in_array as $in_key => $in_val) |
|
626 | - { |
|
627 | - $out_key = strtolower($in_key); |
|
628 | - $out_array[$out_key] = array(); |
|
629 | - |
|
630 | - if(is_array($in_val) && count($in_val) > 0) |
|
631 | - { |
|
632 | - foreach ($in_val as $in_key2 => $in_val2) |
|
633 | - { |
|
634 | - $out_key2 = strtolower($in_key2); |
|
635 | - $out_array[$out_key][$out_key2] = $in_val2; |
|
636 | - } |
|
637 | - } |
|
638 | - } |
|
639 | - } |
|
640 | - |
|
641 | - return $out_array; |
|
642 | - } |
|
643 | - |
|
644 | - /** |
|
645 | - * This method strips out disallowed and/or mangled (X)HTML tags along with assigned attributes. |
|
646 | - * |
|
647 | - * This method does a lot of work. It rejects some very malformed things |
|
648 | - * like <:::>. It returns an empty string if the element isn't allowed (look |
|
649 | - * ma, no strip_tags()!). Otherwise it splits the tag into an element and an |
|
650 | - * allowed attribute list. |
|
651 | - * |
|
652 | - * @access private |
|
653 | - * @param string $string |
|
654 | - * @return string Modified string minus disallowed/mangled (X)HTML and attributes |
|
655 | - * @since PHP4 OOP 0.0.1 |
|
656 | - */ |
|
657 | - private function stripTags($string) |
|
658 | - { |
|
659 | - $string = preg_replace('%\\\\"%', '"', $string); |
|
660 | - |
|
661 | - if (substr($string, 0, 1) != '<') |
|
662 | - { |
|
663 | - # It matched a ">" character |
|
664 | - return '>'; |
|
665 | - } |
|
666 | - |
|
667 | - if (!preg_match('%^<\s*(/\s*)?([a-zA-Z0-9]+)([^>]*)>?$%', $string, $matches)) |
|
668 | - { |
|
669 | - # It's seriously malformed |
|
670 | - return ''; |
|
671 | - } |
|
672 | - |
|
673 | - $slash = trim($matches[1]); |
|
674 | - $elem = $matches[2]; |
|
675 | - $attrlist = $matches[3]; |
|
676 | - |
|
677 | - if ( |
|
678 | - !isset($this->allowed_html[strtolower($elem)]) || |
|
679 | - !is_array($this->allowed_html[strtolower($elem)])) |
|
680 | - { |
|
681 | - # Found an HTML element not in the white list |
|
682 | - return ''; |
|
683 | - } |
|
684 | - |
|
685 | - if ($slash != '') |
|
686 | - { |
|
687 | - return "<$slash$elem>"; |
|
688 | - } |
|
689 | - # No attributes are allowed for closing elements |
|
690 | - |
|
691 | - return $this->stripAttributes("$slash$elem", $attrlist); |
|
692 | - } |
|
693 | - |
|
694 | - /** |
|
695 | - * This method strips out disallowed attributes for (X)HTML tags. |
|
696 | - * |
|
697 | - * This method removes all attributes if none are allowed for this element. |
|
698 | - * If some are allowed it calls combAttributes() to split them further, and then it |
|
699 | - * builds up new HTML code from the data that combAttributes() returns. It also |
|
700 | - * removes "<" and ">" characters, if there are any left. One more thing it |
|
701 | - * does is to check if the tag has a closing XHTML slash, and if it does, |
|
702 | - * it puts one in the returned code as well. |
|
703 | - * |
|
704 | - * @access private |
|
705 | - * @param string $element (X)HTML tag to check |
|
706 | - * @param string $attr Text containing attributes to check for validity. |
|
707 | - * @return string Resulting valid (X)HTML or '' |
|
708 | - * @see combAttributes() |
|
709 | - * @since PHP4 OOP 0.0.1 |
|
710 | - */ |
|
711 | - private function stripAttributes($element, $attr) |
|
712 | - { |
|
713 | - # Is there a closing XHTML slash at the end of the attributes? |
|
714 | - $xhtml_slash = ''; |
|
715 | - if (preg_match('%\s/\s*$%', $attr)) |
|
716 | - { |
|
717 | - $xhtml_slash = ' /'; |
|
718 | - } |
|
719 | - |
|
720 | - # Are any attributes allowed at all for this element? |
|
721 | - if ( |
|
722 | - !isset($this->allowed_html[strtolower($element)]) || |
|
723 | - count($this->allowed_html[strtolower($element)]) == 0 |
|
724 | - ) |
|
725 | - { |
|
726 | - return "<$element$xhtml_slash>"; |
|
727 | - } |
|
728 | - |
|
729 | - # Split it |
|
730 | - $attrarr = $this->combAttributes($attr); |
|
731 | - |
|
732 | - # Go through $attrarr, and save the allowed attributes for this element |
|
733 | - # in $attr2 |
|
734 | - $attr2 = ''; |
|
735 | - if(is_array($attrarr) && count($attrarr) > 0) |
|
736 | - { |
|
737 | - foreach ($attrarr as $arreach) |
|
738 | - { |
|
739 | - if(!isset($this->allowed_html[strtolower($element)][strtolower($arreach['name'])])) |
|
740 | - { |
|
741 | - continue; |
|
742 | - } |
|
743 | - |
|
744 | - $current = $this->allowed_html[strtolower($element)][strtolower($arreach['name'])]; |
|
745 | - |
|
746 | - if (!is_array($current)) |
|
747 | - { |
|
748 | - # there are no checks |
|
749 | - $attr2 .= ' '.$arreach['whole']; |
|
750 | - } |
|
751 | - else |
|
752 | - { |
|
753 | - # there are some checks |
|
754 | - $ok = true; |
|
755 | - if(is_array($current) && count($current) > 0) |
|
756 | - { |
|
757 | - foreach ($current as $currkey => $currval) |
|
758 | - { |
|
759 | - if (!$this->checkAttributeValue($arreach['value'], $arreach['vless'], $currkey, $currval)) |
|
760 | - { |
|
761 | - $ok = false; |
|
762 | - break; |
|
763 | - } |
|
764 | - } |
|
765 | - } |
|
766 | - |
|
767 | - if ($ok) |
|
768 | - { |
|
769 | - # it passed them |
|
770 | - $attr2 .= ' '.$arreach['whole']; |
|
771 | - } |
|
772 | - } |
|
773 | - } |
|
774 | - } |
|
775 | - |
|
776 | - # Remove any "<" or ">" characters |
|
777 | - $attr2 = preg_replace('/[<>]/', '', $attr2); |
|
778 | - return "<$element$attr2$xhtml_slash>"; |
|
779 | - } |
|
780 | - |
|
781 | - /** |
|
782 | - * This method combs through an attribute list string and returns an associative array of attributes and values. |
|
783 | - * |
|
784 | - * This method does a lot of work. It parses an attribute list into an array |
|
785 | - * with attribute data, and tries to do the right thing even if it gets weird |
|
786 | - * input. It will add quotes around attribute values that don't have any quotes |
|
787 | - * or apostrophes around them, to make it easier to produce HTML code that will |
|
788 | - * conform to W3C's HTML specification. It will also remove bad URL protocols |
|
789 | - * from attribute values. |
|
790 | - * |
|
791 | - * @access private |
|
792 | - * @param string $attr Text containing tag attributes for parsing |
|
793 | - * @return array Associative array containing data on attribute and value |
|
794 | - * @since PHP4 OOP 0.0.1 |
|
795 | - */ |
|
796 | - private function combAttributes($attr) |
|
797 | - { |
|
798 | - $attrarr = array(); |
|
799 | - $mode = 0; |
|
800 | - $attrname = ''; |
|
801 | - |
|
802 | - # Loop through the whole attribute list |
|
803 | - |
|
804 | - while (strlen($attr) != 0) |
|
805 | - { |
|
806 | - # Was the last operation successful? |
|
807 | - $working = 0; |
|
808 | - |
|
809 | - switch ($mode) |
|
810 | - { |
|
811 | - case 0: # attribute name, href for instance |
|
812 | - if (preg_match('/^([-a-zA-Z]+)/', $attr, $match)) |
|
813 | - { |
|
814 | - $attrname = $match[1]; |
|
815 | - $working = $mode = 1; |
|
816 | - $attr = preg_replace('/^[-a-zA-Z]+/', '', $attr); |
|
817 | - } |
|
818 | - break; |
|
819 | - case 1: # equals sign or valueless ("selected") |
|
820 | - if (preg_match('/^\s*=\s*/', $attr)) # equals sign |
|
821 | - { |
|
822 | - $working = 1; |
|
823 | - $mode = 2; |
|
824 | - $attr = preg_replace('/^\s*=\s*/', '', $attr); |
|
825 | - break; |
|
826 | - } |
|
827 | - if (preg_match('/^\s+/', $attr)) # valueless |
|
828 | - { |
|
829 | - $working = 1; |
|
830 | - $mode = 0; |
|
831 | - $attrarr[] = array( |
|
832 | - 'name' => $attrname, |
|
833 | - 'value' => '', |
|
834 | - 'whole' => $attrname, |
|
835 | - 'vless' => 'y' |
|
836 | - ); |
|
837 | - $attr = preg_replace('/^\s+/', '', $attr); |
|
838 | - } |
|
839 | - break; |
|
840 | - case 2: # attribute value, a URL after href= for instance |
|
841 | - if (preg_match('/^"([^"]*)"(\s+|$)/', $attr, $match)) # "value" |
|
842 | - { |
|
843 | - $thisval = $this->removeBadProtocols($match[1]); |
|
844 | - $attrarr[] = array( |
|
845 | - 'name' => $attrname, |
|
846 | - 'value' => $thisval, |
|
847 | - 'whole' => $attrname . '="' . $thisval . '"', |
|
848 | - 'vless' => 'n' |
|
849 | - ); |
|
850 | - $working = 1; |
|
851 | - $mode = 0; |
|
852 | - $attr = preg_replace('/^"[^"]*"(\s+|$)/', '', $attr); |
|
853 | - break; |
|
854 | - } |
|
855 | - if (preg_match("/^'([^']*)'(\s+|$)/", $attr, $match)) # 'value' |
|
856 | - { |
|
857 | - $thisval = $this->removeBadProtocols($match[1]); |
|
858 | - $attrarr[] = array( |
|
859 | - 'name' => $attrname, |
|
860 | - 'value' => $thisval, |
|
861 | - 'whole' => "$attrname='$thisval'", |
|
862 | - 'vless' => 'n' |
|
863 | - ); |
|
864 | - $working = 1; |
|
865 | - $mode = 0; |
|
866 | - $attr = preg_replace("/^'[^']*'(\s+|$)/", '', $attr); |
|
867 | - break; |
|
868 | - } |
|
869 | - if (preg_match("%^([^\s\"']+)(\s+|$)%", $attr, $match)) # value |
|
870 | - { |
|
871 | - $thisval = $this->removeBadProtocols($match[1]); |
|
872 | - $attrarr[] = array( |
|
873 | - 'name' => $attrname, |
|
874 | - 'value' => $thisval, |
|
875 | - 'whole' => $attrname . '="' . $thisval . '"', |
|
876 | - 'vless' => 'n' |
|
877 | - ); |
|
878 | - # We add quotes to conform to W3C's HTML spec. |
|
879 | - $working = 1; |
|
880 | - $mode = 0; |
|
881 | - $attr = preg_replace("%^[^\s\"']+(\s+|$)%", '', $attr); |
|
882 | - } |
|
883 | - break; |
|
884 | - } |
|
885 | - |
|
886 | - if ($working == 0) # not well formed, remove and try again |
|
887 | - { |
|
888 | - $attr = preg_replace('/^("[^"]*("|$)|\'[^\']*(\'|$)|\S)*\s*/', '', $attr); |
|
889 | - $mode = 0; |
|
890 | - } |
|
891 | - } |
|
892 | - |
|
893 | - # special case, for when the attribute list ends with a valueless |
|
894 | - # attribute like "selected" |
|
895 | - if ($mode == 1) |
|
896 | - { |
|
897 | - $attrarr[] = array( |
|
898 | - 'name' => $attrname, |
|
899 | - 'value' => '', |
|
900 | - 'whole' => $attrname, |
|
901 | - 'vless' => 'y' |
|
902 | - ); |
|
903 | - } |
|
904 | - |
|
905 | - return $attrarr; |
|
906 | - } |
|
907 | - |
|
908 | - /** |
|
909 | - * This method removes disallowed protocols. |
|
910 | - * |
|
911 | - * This method removes all non-allowed protocols from the beginning of |
|
912 | - * $string. It ignores whitespace and the case of the letters, and it does |
|
913 | - * understand HTML entities. It does its work in a while loop, so it won't be |
|
914 | - * fooled by a string like "javascript:javascript:alert(57)". |
|
915 | - * |
|
916 | - * @access private |
|
917 | - * @param string $string String to check for protocols |
|
918 | - * @return string String with removed protocols |
|
919 | - * @since PHP4 OOP 0.0.1 |
|
920 | - */ |
|
921 | - private function removeBadProtocols($string) |
|
922 | - { |
|
923 | - $string = $this->RemoveNulls($string); |
|
924 | - $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
925 | - $string2 = $string . 'a'; |
|
926 | - |
|
927 | - $string2 = preg_split('/:|:|:/i', $string, 2); |
|
928 | - if(isset($string2[1]) && !preg_match('%/\?%',$string2[0])) |
|
929 | - { |
|
930 | - $string = $this->filterProtocols($string2[0]).trim($string2[1]); |
|
931 | - } |
|
932 | - return $string; |
|
933 | - } |
|
934 | - |
|
935 | - /** |
|
936 | - * Helper method used by removeBadProtocols() |
|
937 | - * |
|
938 | - * This function processes URL protocols, checks to see if they're in the white- |
|
939 | - * list or not, and returns different data depending on the answer. |
|
940 | - * |
|
941 | - * @access private |
|
942 | - * @param string $string String to check for protocols |
|
943 | - * @return string String with removed protocols |
|
944 | - * @see removeBadProtocols() |
|
945 | - * @since PHP4 OOP 0.0.1 |
|
946 | - */ |
|
947 | - private function filterProtocols($string) |
|
948 | - { |
|
949 | - $string = $this->decodeEntities($string); |
|
950 | - $string = preg_replace('/\s/', '', $string); |
|
951 | - $string = $this->removeNulls($string); |
|
952 | - $string = preg_replace('/\xad+/', '', $string2); # deals with Opera "feature" |
|
953 | - $string = strtolower($string); |
|
954 | - |
|
955 | - if(is_array($this->allowed_protocols) && count($this->allowed_protocols) > 0) |
|
956 | - { |
|
957 | - foreach ($this->allowed_protocols as $one_protocol) |
|
958 | - { |
|
959 | - if (strtolower($one_protocol) == $string) |
|
960 | - { |
|
961 | - return "$string:"; |
|
962 | - } |
|
963 | - } |
|
964 | - } |
|
965 | - |
|
966 | - return ''; |
|
967 | - } |
|
968 | - |
|
969 | - /** |
|
970 | - * Controller method for performing checks on attribute values. |
|
971 | - * |
|
972 | - * This method calls the appropriate method as specified by $checkname with |
|
973 | - * the parameters $value, $vless, and $checkvalue, and returns the result |
|
974 | - * of the call. |
|
975 | - * |
|
976 | - * This method's functionality can be expanded by creating new methods |
|
977 | - * that would match checkAttributeValue[$checkname]. |
|
978 | - * |
|
979 | - * Current checks implemented are: "maxlen", "minlen", "maxval", "minval" and "valueless" |
|
980 | - * |
|
981 | - * @access private |
|
982 | - * @param string $value The value of the attribute to be checked. |
|
983 | - * @param string $vless Indicates whether the the value is supposed to be valueless |
|
984 | - * @param string $checkname The check to be performed |
|
985 | - * @param string $checkvalue The value that is to be checked against |
|
986 | - * @return bool Indicates whether the check passed or not |
|
987 | - * @since PHP5 OOP 1.0.0 |
|
988 | - */ |
|
989 | - private function checkAttributeValue($value, $vless, $checkname, $checkvalue) |
|
990 | - { |
|
991 | - $ok = true; |
|
992 | - $check_attribute_method_name = 'checkAttributeValue' . ucfirst(strtolower($checkname)); |
|
993 | - if(method_exists($this, $check_attribute_method_name)) |
|
994 | - { |
|
995 | - $ok = $this->$check_attribute_method_name($value, $checkvalue, $vless); |
|
996 | - } |
|
997 | - |
|
998 | - return $ok; |
|
999 | - } |
|
1000 | - |
|
1001 | - /** |
|
1002 | - * Helper method invoked by checkAttributeValue(). |
|
1003 | - * |
|
1004 | - * The maxlen check makes sure that the attribute value has a length not |
|
1005 | - * greater than the given value. This can be used to avoid Buffer Overflows |
|
1006 | - * in WWW clients and various Internet servers. |
|
1007 | - * |
|
1008 | - * @access private |
|
1009 | - * @param string $value The value of the attribute to be checked. |
|
1010 | - * @param int $checkvalue The maximum value allowed |
|
1011 | - * @return bool Indicates whether the check passed or not |
|
1012 | - * @see checkAttributeValue() |
|
1013 | - * @since PHP5 OOP 1.0.0 |
|
1014 | - */ |
|
1015 | - private function checkAttributeValueMaxlen($value, $checkvalue) |
|
1016 | - { |
|
1017 | - if (strlen($value) > intval($checkvalue)) |
|
1018 | - { |
|
1019 | - return false; |
|
1020 | - } |
|
1021 | - return true; |
|
1022 | - } |
|
1023 | - |
|
1024 | - /** |
|
1025 | - * Helper method invoked by checkAttributeValue(). |
|
1026 | - * |
|
1027 | - * The minlen check makes sure that the attribute value has a length not |
|
1028 | - * smaller than the given value. |
|
1029 | - * |
|
1030 | - * @access private |
|
1031 | - * @param string $value The value of the attribute to be checked. |
|
1032 | - * @param int $checkvalue The minimum value allowed |
|
1033 | - * @return bool Indicates whether the check passed or not |
|
1034 | - * @see checkAttributeValue() |
|
1035 | - * @since PHP5 OOP 1.0.0 |
|
1036 | - */ |
|
1037 | - private function checkAttributeValueMinlen($value, $checkvalue) |
|
1038 | - { |
|
1039 | - if (strlen($value) < intval($checkvalue)) |
|
1040 | - { |
|
1041 | - return false; |
|
1042 | - } |
|
1043 | - return true; |
|
1044 | - } |
|
1045 | - |
|
1046 | - /** |
|
1047 | - * Helper method invoked by checkAttributeValue(). |
|
1048 | - * |
|
1049 | - * The maxval check does two things: it checks that the attribute value is |
|
1050 | - * an integer from 0 and up, without an excessive amount of zeroes or |
|
1051 | - * whitespace (to avoid Buffer Overflows). It also checks that the attribute |
|
1052 | - * value is not greater than the given value. |
|
1053 | - * |
|
1054 | - * This check can be used to avoid Denial of Service attacks. |
|
1055 | - * |
|
1056 | - * @access private |
|
1057 | - * @param int $value The value of the attribute to be checked. |
|
1058 | - * @param int $checkvalue The maximum numeric value allowed |
|
1059 | - * @return bool Indicates whether the check passed or not |
|
1060 | - * @see checkAttributeValue() |
|
1061 | - * @since PHP5 OOP 1.0.0 |
|
1062 | - */ |
|
1063 | - private function checkAttributeValueMaxval($value, $checkvalue) |
|
1064 | - { |
|
1065 | - if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1066 | - { |
|
1067 | - return false; |
|
1068 | - } |
|
1069 | - if (intval($value) > intval($checkvalue)) |
|
1070 | - { |
|
1071 | - return false; |
|
1072 | - } |
|
1073 | - return true; |
|
1074 | - } |
|
1075 | - |
|
1076 | - /** |
|
1077 | - * Helper method invoked by checkAttributeValue(). |
|
1078 | - * |
|
1079 | - * The minval check checks that the attribute value is a positive integer, |
|
1080 | - * and that it is not smaller than the given value. |
|
1081 | - * |
|
1082 | - * @access private |
|
1083 | - * @param int $value The value of the attribute to be checked. |
|
1084 | - * @param int $checkvalue The minimum numeric value allowed |
|
1085 | - * @return bool Indicates whether the check passed or not |
|
1086 | - * @see checkAttributeValue() |
|
1087 | - * @since PHP5 OOP 1.0.0 |
|
1088 | - */ |
|
1089 | - private function checkAttributeValueMinval($value, $checkvalue) |
|
1090 | - { |
|
1091 | - if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1092 | - { |
|
1093 | - return false; |
|
1094 | - } |
|
1095 | - if (intval($value) < ($checkvalue)) |
|
1096 | - { |
|
1097 | - return false; |
|
1098 | - } |
|
1099 | - return true; |
|
1100 | - } |
|
1101 | - |
|
1102 | - /** |
|
1103 | - * Helper method invoked by checkAttributeValue(). |
|
1104 | - * |
|
1105 | - * The valueless check checks if the attribute has a value |
|
1106 | - * (like <a href="blah">) or not (<option selected>). If the given value |
|
1107 | - * is a "y" or a "Y", the attribute must not have a value. |
|
1108 | - * |
|
1109 | - * If the given value is an "n" or an "N", the attribute must have one. |
|
1110 | - * |
|
1111 | - * @access private |
|
1112 | - * @param int $value The value of the attribute to be checked. |
|
1113 | - * @param mixed $checkvalue This variable is ignored for this test |
|
1114 | - * @param string $vless Flag indicating if this attribute is not supposed to have an attribute |
|
1115 | - * @return bool Indicates whether the check passed or not |
|
1116 | - * @see checkAttributeValue() |
|
1117 | - * @since PHP5 OOP 1.0.0 |
|
1118 | - */ |
|
1119 | - private function checkAttributeValueValueless($value, $checkvalue, $vless) |
|
1120 | - { |
|
1121 | - if (strtolower($checkvalue) != $vless) |
|
1122 | - { |
|
1123 | - return false; |
|
1124 | - } |
|
1125 | - return true; |
|
1126 | - } |
|
1127 | - |
|
1128 | - /** |
|
1129 | - * Decodes numeric HTML entities |
|
1130 | - * |
|
1131 | - * This method decodes numeric HTML entities (A and A). It doesn't |
|
1132 | - * do anything with other entities like ä, but we don't need them in the |
|
1133 | - * URL protocol white listing system anyway. |
|
1134 | - * |
|
1135 | - * @access private |
|
1136 | - * @param string $value The entitiy to be decoded. |
|
1137 | - * @return string Decoded entity |
|
1138 | - * @since PHP4 OOP 0.0.1 |
|
1139 | - */ |
|
1140 | - private function decodeEntities($string) |
|
1141 | - { |
|
1142 | - $string = preg_replace('/&#([0-9]+);/e', 'chr("\\1")', $string); |
|
1143 | - $string = preg_replace('/&#[Xx]([0-9A-Fa-f]+);/e', 'chr(hexdec("\\1"))', $string); |
|
1144 | - return $string; |
|
1145 | - } |
|
1146 | - |
|
1147 | - /** |
|
1148 | - * Returns PHP5 OOP version # of kses. |
|
1149 | - * |
|
1150 | - * Since this class has been refactored and documented and proven to work, |
|
1151 | - * I'm fixing the version number at 1.0.0. |
|
1152 | - * |
|
1153 | - * This version is syntax compatible with the PHP4 OOP version 0.0.2. Future |
|
1154 | - * versions may not be syntax compatible. |
|
1155 | - * |
|
1156 | - * @access public |
|
1157 | - * @return string Version number |
|
1158 | - * @since PHP4 OOP 0.0.1 |
|
1159 | - */ |
|
1160 | - public function Version() |
|
1161 | - { |
|
1162 | - return 'PHP5 OOP 1.0.2'; |
|
1163 | - } |
|
1164 | - } |
|
1165 | - } |
|
113 | + private $allowed_protocols; |
|
114 | + private $allowed_html; |
|
115 | + /**#@-*/ |
|
116 | + |
|
117 | + /** |
|
118 | + * Constructor for kses. |
|
119 | + * |
|
120 | + * This sets a default collection of protocols allowed in links, and creates an |
|
121 | + * empty set of allowed HTML tags. |
|
122 | + * @since PHP5 OOP 1.0.0 |
|
123 | + */ |
|
124 | + public function __construct() |
|
125 | + { |
|
126 | + /** |
|
127 | + * You could add protocols such as ftp, new, gopher, mailto, irc, etc. |
|
128 | + * |
|
129 | + * The base values the original kses provided were: |
|
130 | + * 'http', 'https', 'ftp', 'news', 'nntp', 'telnet', 'gopher', 'mailto' |
|
131 | + */ |
|
132 | + $this->allowed_protocols = array('http', 'ftp', 'mailto'); |
|
133 | + $this->allowed_html = array(); |
|
134 | + } |
|
135 | + |
|
136 | + /** |
|
137 | + * Basic task of kses - parses $string and strips it as required. |
|
138 | + * |
|
139 | + * This method strips all the disallowed (X)HTML tags, attributes |
|
140 | + * and protocols from the input $string. |
|
141 | + * |
|
142 | + * @access public |
|
143 | + * @param string $string String to be stripped of 'evil scripts' |
|
144 | + * @return string The stripped string |
|
145 | + * @since PHP4 OOP 0.0.1 |
|
146 | + */ |
|
147 | + public function Parse($string = "") |
|
148 | + { |
|
149 | + if (get_magic_quotes_gpc()) |
|
150 | + { |
|
151 | + $string = stripslashes($string); |
|
152 | + } |
|
153 | + $string = $this->removeNulls($string); |
|
154 | + // Remove JavaScript entities from early Netscape 4 versions |
|
155 | + $string = preg_replace('%&\s*\{[^}]*(\}\s*;?|$)%', '', $string); |
|
156 | + $string = $this->normalizeEntities($string); |
|
157 | + $string = $this->filterKsesTextHook($string); |
|
158 | + $string = preg_replace('%(<' . '[^>]*' . '(>|$)' . '|>)%e', "\$this->stripTags('\\1')", $string); |
|
159 | + return $string; |
|
160 | + } |
|
161 | + |
|
162 | + /** |
|
163 | + * Allows for single/batch addition of protocols |
|
164 | + * |
|
165 | + * This method accepts one argument that can be either a string |
|
166 | + * or an array of strings. Invalid data will be ignored. |
|
167 | + * |
|
168 | + * The argument will be processed, and each string will be added |
|
169 | + * via AddProtocol(). |
|
170 | + * |
|
171 | + * @access public |
|
172 | + * @param mixed , A string or array of protocols that will be added to the internal list of allowed protocols. |
|
173 | + * @return bool Status of adding valid protocols. |
|
174 | + * @see AddProtocol() |
|
175 | + * @since PHP5 OOP 1.0.0 |
|
176 | + */ |
|
177 | + public function AddProtocols() |
|
178 | + { |
|
179 | + $c_args = func_num_args(); |
|
180 | + if($c_args != 1) |
|
181 | + { |
|
182 | + trigger_error("kses5::AddProtocols() did not receive an argument.", E_USER_WARNING); |
|
183 | + return false; |
|
184 | + } |
|
185 | + |
|
186 | + $protocol_data = func_get_arg(0); |
|
187 | + |
|
188 | + if(is_array($protocol_data) && count($protocol_data) > 0) |
|
189 | + { |
|
190 | + foreach($protocol_data as $protocol) |
|
191 | + { |
|
192 | + $this->AddProtocol($protocol); |
|
193 | + } |
|
194 | + return true; |
|
195 | + } |
|
196 | + elseif(is_string($protocol_data)) |
|
197 | + { |
|
198 | + $this->AddProtocol($protocol_data); |
|
199 | + return true; |
|
200 | + } |
|
201 | + else |
|
202 | + { |
|
203 | + trigger_error("kses5::AddProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
204 | + return false; |
|
205 | + } |
|
206 | + } |
|
207 | + |
|
208 | + /** |
|
209 | + * Allows for single/batch addition of protocols |
|
210 | + * |
|
211 | + * @deprecated Use AddProtocols() |
|
212 | + * @see AddProtocols() |
|
213 | + * @return bool |
|
214 | + * @since PHP4 OOP 0.0.1 |
|
215 | + */ |
|
216 | + public function Protocols() |
|
217 | + { |
|
218 | + $c_args = func_num_args(); |
|
219 | + if($c_args != 1) |
|
220 | + { |
|
221 | + trigger_error("kses5::Protocols() did not receive an argument.", E_USER_WARNING); |
|
222 | + return false; |
|
223 | + } |
|
224 | + |
|
225 | + return $this->AddProtocols(func_get_arg(0)); |
|
226 | + } |
|
227 | + |
|
228 | + /** |
|
229 | + * Adds a single protocol to $this->allowed_protocols. |
|
230 | + * |
|
231 | + * This method accepts a string argument and adds it to |
|
232 | + * the list of allowed protocols to keep when performing |
|
233 | + * Parse(). |
|
234 | + * |
|
235 | + * @access public |
|
236 | + * @param string $protocol The name of the protocol to be added. |
|
237 | + * @return bool Status of adding valid protocol. |
|
238 | + * @since PHP4 OOP 0.0.1 |
|
239 | + */ |
|
240 | + public function AddProtocol($protocol = "") |
|
241 | + { |
|
242 | + if(!is_string($protocol)) |
|
243 | + { |
|
244 | + trigger_error("kses5::AddProtocol() requires a string.", E_USER_WARNING); |
|
245 | + return false; |
|
246 | + } |
|
247 | + |
|
248 | + // Remove any inadvertent ':' at the end of the protocol. |
|
249 | + if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
250 | + { |
|
251 | + $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
252 | + } |
|
253 | + |
|
254 | + $protocol = strtolower(trim($protocol)); |
|
255 | + if($protocol == "") |
|
256 | + { |
|
257 | + trigger_error("kses5::AddProtocol() tried to add an empty/NULL protocol.", E_USER_WARNING); |
|
258 | + return false; |
|
259 | + } |
|
260 | + |
|
261 | + // prevent duplicate protocols from being added. |
|
262 | + if(!in_array($protocol, $this->allowed_protocols)) |
|
263 | + { |
|
264 | + array_push($this->allowed_protocols, $protocol); |
|
265 | + sort($this->allowed_protocols); |
|
266 | + } |
|
267 | + return true; |
|
268 | + } |
|
269 | + |
|
270 | + /** |
|
271 | + * Removes a single protocol from $this->allowed_protocols. |
|
272 | + * |
|
273 | + * This method accepts a string argument and removes it from |
|
274 | + * the list of allowed protocols to keep when performing |
|
275 | + * Parse(). |
|
276 | + * |
|
277 | + * @access public |
|
278 | + * @param string $protocol The name of the protocol to be removed. |
|
279 | + * @return bool Status of removing valid protocol. |
|
280 | + * @since PHP5 OOP 1.0.0 |
|
281 | + */ |
|
282 | + public function RemoveProtocol($protocol = "") |
|
283 | + { |
|
284 | + if(!is_string($protocol)) |
|
285 | + { |
|
286 | + trigger_error("kses5::RemoveProtocol() requires a string.", E_USER_WARNING); |
|
287 | + return false; |
|
288 | + } |
|
289 | + |
|
290 | + // Remove any inadvertent ':' at the end of the protocol. |
|
291 | + if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
292 | + { |
|
293 | + $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
294 | + } |
|
295 | + |
|
296 | + $protocol = strtolower(trim($protocol)); |
|
297 | + if($protocol == "") |
|
298 | + { |
|
299 | + trigger_error("kses5::RemoveProtocol() tried to remove an empty/NULL protocol.", E_USER_WARNING); |
|
300 | + return false; |
|
301 | + } |
|
302 | + |
|
303 | + // Ensures that the protocol exists before removing it. |
|
304 | + if(in_array($protocol, $this->allowed_protocols)) |
|
305 | + { |
|
306 | + $this->allowed_protocols = array_diff($this->allowed_protocols, array($protocol)); |
|
307 | + sort($this->allowed_protocols); |
|
308 | + } |
|
309 | + |
|
310 | + return true; |
|
311 | + } |
|
312 | + |
|
313 | + /** |
|
314 | + * Allows for single/batch removal of protocols |
|
315 | + * |
|
316 | + * This method accepts one argument that can be either a string |
|
317 | + * or an array of strings. Invalid data will be ignored. |
|
318 | + * |
|
319 | + * The argument will be processed, and each string will be removed |
|
320 | + * via RemoveProtocol(). |
|
321 | + * |
|
322 | + * @access public |
|
323 | + * @param mixed , A string or array of protocols that will be removed from the internal list of allowed protocols. |
|
324 | + * @return bool Status of removing valid protocols. |
|
325 | + * @see RemoveProtocol() |
|
326 | + * @since PHP5 OOP 1.0.0 |
|
327 | + */ |
|
328 | + public function RemoveProtocols() |
|
329 | + { |
|
330 | + $c_args = func_num_args(); |
|
331 | + if($c_args != 1) |
|
332 | + { |
|
333 | + return false; |
|
334 | + } |
|
335 | + |
|
336 | + $protocol_data = func_get_arg(0); |
|
337 | + |
|
338 | + if(is_array($protocol_data) && count($protocol_data) > 0) |
|
339 | + { |
|
340 | + foreach($protocol_data as $protocol) |
|
341 | + { |
|
342 | + $this->RemoveProtocol($protocol); |
|
343 | + } |
|
344 | + } |
|
345 | + elseif(is_string($protocol_data)) |
|
346 | + { |
|
347 | + $this->RemoveProtocol($protocol_data); |
|
348 | + return true; |
|
349 | + } |
|
350 | + else |
|
351 | + { |
|
352 | + trigger_error("kses5::RemoveProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
353 | + return false; |
|
354 | + } |
|
355 | + } |
|
356 | + |
|
357 | + /** |
|
358 | + * Allows for single/batch replacement of protocols |
|
359 | + * |
|
360 | + * This method accepts one argument that can be either a string |
|
361 | + * or an array of strings. Invalid data will be ignored. |
|
362 | + * |
|
363 | + * Existing protocols will be removed, then the argument will be |
|
364 | + * processed, and each string will be added via AddProtocol(). |
|
365 | + * |
|
366 | + * @access public |
|
367 | + * @param mixed , A string or array of protocols that will be the new internal list of allowed protocols. |
|
368 | + * @return bool Status of replacing valid protocols. |
|
369 | + * @since PHP5 OOP 1.0.1 |
|
370 | + * @see AddProtocol() |
|
371 | + */ |
|
372 | + public function SetProtocols() |
|
373 | + { |
|
374 | + $c_args = func_num_args(); |
|
375 | + if($c_args != 1) |
|
376 | + { |
|
377 | + trigger_error("kses5::SetProtocols() did not receive an argument.", E_USER_WARNING); |
|
378 | + return false; |
|
379 | + } |
|
380 | + |
|
381 | + $protocol_data = func_get_arg(0); |
|
382 | + |
|
383 | + if(is_array($protocol_data) && count($protocol_data) > 0) |
|
384 | + { |
|
385 | + $this->allowed_protocols = array(); |
|
386 | + foreach($protocol_data as $protocol) |
|
387 | + { |
|
388 | + $this->AddProtocol($protocol); |
|
389 | + } |
|
390 | + return true; |
|
391 | + } |
|
392 | + elseif(is_string($protocol_data)) |
|
393 | + { |
|
394 | + $this->allowed_protocols = array(); |
|
395 | + $this->AddProtocol($protocol_data); |
|
396 | + return true; |
|
397 | + } |
|
398 | + else |
|
399 | + { |
|
400 | + trigger_error("kses5::SetProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
401 | + return false; |
|
402 | + } |
|
403 | + } |
|
404 | + |
|
405 | + /** |
|
406 | + * Raw dump of allowed protocols |
|
407 | + * |
|
408 | + * This returns an indexed array of allowed protocols for a particular KSES |
|
409 | + * instantiation. |
|
410 | + * |
|
411 | + * @access public |
|
412 | + * @return array The list of allowed protocols. |
|
413 | + * @since PHP5 OOP 1.0.2 |
|
414 | + */ |
|
415 | + public function DumpProtocols() |
|
416 | + { |
|
417 | + return $this->allowed_protocols; |
|
418 | + } |
|
419 | + |
|
420 | + /** |
|
421 | + * Raw dump of allowed (X)HTML elements |
|
422 | + * |
|
423 | + * This returns an indexed array of allowed (X)HTML elements and attributes |
|
424 | + * for a particular KSES instantiation. |
|
425 | + * |
|
426 | + * @access public |
|
427 | + * @return array The list of allowed elements. |
|
428 | + * @since PHP5 OOP 1.0.2 |
|
429 | + */ |
|
430 | + public function DumpElements() |
|
431 | + { |
|
432 | + return $this->allowed_html; |
|
433 | + } |
|
434 | + |
|
435 | + |
|
436 | + /** |
|
437 | + * Adds valid (X)HTML with corresponding attributes that will be kept when stripping 'evil scripts'. |
|
438 | + * |
|
439 | + * This method accepts one argument that can be either a string |
|
440 | + * or an array of strings. Invalid data will be ignored. |
|
441 | + * |
|
442 | + * @access public |
|
443 | + * @param string $tag (X)HTML tag that will be allowed after stripping text. |
|
444 | + * @param array $attribs Associative array of allowed attributes - key => attribute name - value => attribute parameter |
|
445 | + * @return bool Status of Adding (X)HTML and attributes. |
|
446 | + * @since PHP4 OOP 0.0.1 |
|
447 | + */ |
|
448 | + public function AddHTML($tag = "", $attribs = array()) |
|
449 | + { |
|
450 | + if(!is_string($tag)) |
|
451 | + { |
|
452 | + trigger_error("kses5::AddHTML() requires the tag to be a string", E_USER_WARNING); |
|
453 | + return false; |
|
454 | + } |
|
455 | + |
|
456 | + $tag = strtolower(trim($tag)); |
|
457 | + if($tag == "") |
|
458 | + { |
|
459 | + trigger_error("kses5::AddHTML() tried to add an empty/NULL tag", E_USER_WARNING); |
|
460 | + return false; |
|
461 | + } |
|
462 | + |
|
463 | + if(!is_array($attribs)) |
|
464 | + { |
|
465 | + trigger_error("kses5::AddHTML() requires an array (even an empty one) of attributes for '$tag'", E_USER_WARNING); |
|
466 | + return false; |
|
467 | + } |
|
468 | + |
|
469 | + $new_attribs = array(); |
|
470 | + if(is_array($attribs) && count($attribs) > 0) |
|
471 | + { |
|
472 | + foreach($attribs as $idx1 => $val1) |
|
473 | + { |
|
474 | + $new_idx1 = strtolower($idx1); |
|
475 | + $new_val1 = $attribs[$idx1]; |
|
476 | + |
|
477 | + if(is_array($new_val1) && count($attribs) > 0) |
|
478 | + { |
|
479 | + $tmp_val = array(); |
|
480 | + foreach($new_val1 as $idx2 => $val2) |
|
481 | + { |
|
482 | + $new_idx2 = strtolower($idx2); |
|
483 | + $tmp_val[$new_idx2] = $val2; |
|
484 | + } |
|
485 | + $new_val1 = $tmp_val; |
|
486 | + } |
|
487 | + |
|
488 | + $new_attribs[$new_idx1] = $new_val1; |
|
489 | + } |
|
490 | + } |
|
491 | + |
|
492 | + $this->allowed_html[$tag] = $new_attribs; |
|
493 | + return true; |
|
494 | + } |
|
495 | + |
|
496 | + /** |
|
497 | + * This method removes any NULL characters in $string. |
|
498 | + * |
|
499 | + * @access private |
|
500 | + * @param string $string |
|
501 | + * @return string String without any NULL/chr(173) |
|
502 | + * @since PHP4 OOP 0.0.1 |
|
503 | + */ |
|
504 | + private function removeNulls($string) |
|
505 | + { |
|
506 | + $string = preg_replace('/\0+/', '', $string); |
|
507 | + $string = preg_replace('/(\\\\0)+/', '', $string); |
|
508 | + return $string; |
|
509 | + } |
|
510 | + |
|
511 | + /** |
|
512 | + * Normalizes HTML entities |
|
513 | + * |
|
514 | + * This function normalizes HTML entities. It will convert "AT&T" to the correct |
|
515 | + * "AT&T", ":" to ":", "&#XYZZY;" to "&#XYZZY;" and so on. |
|
516 | + * |
|
517 | + * @access private |
|
518 | + * @param string $string |
|
519 | + * @return string String with normalized entities |
|
520 | + * @since PHP4 OOP 0.0.1 |
|
521 | + */ |
|
522 | + private function normalizeEntities($string) |
|
523 | + { |
|
524 | + # Disarm all entities by converting & to & |
|
525 | + $string = str_replace('&', '&', $string); |
|
526 | + |
|
527 | + # TODO: Change back (Keep?) the allowed entities in our entity white list |
|
528 | + |
|
529 | + # Keeps entities that start with [A-Za-z] |
|
530 | + $string = preg_replace( |
|
531 | + '/&([A-Za-z][A-Za-z0-9]{0,19});/', |
|
532 | + '&\\1;', |
|
533 | + $string |
|
534 | + ); |
|
535 | + |
|
536 | + # Change numeric entities to valid 16 bit values |
|
537 | + |
|
538 | + $string = preg_replace( |
|
539 | + '/&#0*([0-9]{1,5});/e', |
|
540 | + '\$this->normalizeEntities16bit("\\1")', |
|
541 | + $string |
|
542 | + ); |
|
543 | + |
|
544 | + # Change &XHHHHHHH (Hex digits) to 16 bit hex values |
|
545 | + $string = preg_replace( |
|
546 | + '/&#([Xx])0*(([0-9A-Fa-f]{2}){1,2});/', |
|
547 | + '&#\\1\\2;', |
|
548 | + $string |
|
549 | + ); |
|
550 | + |
|
551 | + return $string; |
|
552 | + } |
|
553 | + |
|
554 | + /** |
|
555 | + * Helper method used by normalizeEntites() |
|
556 | + * |
|
557 | + * This method helps normalizeEntities() to only accept 16 bit values |
|
558 | + * and nothing more for &#number; entities. |
|
559 | + * |
|
560 | + * This method helps normalize_entities() during a preg_replace() |
|
561 | + * where a &#(0)*XXXXX; occurs. The '(0)*XXXXXX' value is converted to |
|
562 | + * a number and the result is returned as a numeric entity if the number |
|
563 | + * is less than 65536. Otherwise, the value is returned 'as is'. |
|
564 | + * |
|
565 | + * @access private |
|
566 | + * @param string $i |
|
567 | + * @return string Normalized numeric entity |
|
568 | + * @see normalizeEntities() |
|
569 | + * @since PHP4 OOP 0.0.1 |
|
570 | + */ |
|
571 | + private function normalizeEntities16bit($i) |
|
572 | + { |
|
573 | + return (($i > 65535) ? "&#$i;" : "&#$i;"); |
|
574 | + } |
|
575 | + |
|
576 | + /** |
|
577 | + * Allows for additional user defined modifications to text. |
|
578 | + * |
|
579 | + * This method allows for additional modifications to be performed on |
|
580 | + * a string that's being run through Parse(). Currently, it returns the |
|
581 | + * input string 'as is'. |
|
582 | + * |
|
583 | + * This method is provided for users to extend the kses class for their own |
|
584 | + * requirements. |
|
585 | + * |
|
586 | + * @access public |
|
587 | + * @param string $string String to perfrom additional modifications on. |
|
588 | + * @return string User modified string. |
|
589 | + * @see Parse() |
|
590 | + * @since PHP5 OOP 1.0.0 |
|
591 | + */ |
|
592 | + private function filterKsesTextHook($string) |
|
593 | + { |
|
594 | + return $string; |
|
595 | + } |
|
596 | + |
|
597 | + /** |
|
598 | + * Allows for additional user defined modifications to text. |
|
599 | + * |
|
600 | + * @deprecated use filterKsesTextHook() |
|
601 | + * @param string $string |
|
602 | + * @return string |
|
603 | + * @see filterKsesTextHook() |
|
604 | + * @since PHP4 OOP 0.0.1 |
|
605 | + */ |
|
606 | + private function _hook($string) |
|
607 | + { |
|
608 | + return $this->filterKsesTextHook($string); |
|
609 | + } |
|
610 | + |
|
611 | + /** |
|
612 | + * This method goes through an array, and changes the keys to all lower case. |
|
613 | + * |
|
614 | + * @access private |
|
615 | + * @param array $in_array Associative array |
|
616 | + * @return array Modified array |
|
617 | + * @since PHP4 OOP 0.0.1 |
|
618 | + */ |
|
619 | + private function makeArrayKeysLowerCase($in_array) |
|
620 | + { |
|
621 | + $out_array = array(); |
|
622 | + |
|
623 | + if(is_array($in_array) && count($in_array) > 0) |
|
624 | + { |
|
625 | + foreach ($in_array as $in_key => $in_val) |
|
626 | + { |
|
627 | + $out_key = strtolower($in_key); |
|
628 | + $out_array[$out_key] = array(); |
|
629 | + |
|
630 | + if(is_array($in_val) && count($in_val) > 0) |
|
631 | + { |
|
632 | + foreach ($in_val as $in_key2 => $in_val2) |
|
633 | + { |
|
634 | + $out_key2 = strtolower($in_key2); |
|
635 | + $out_array[$out_key][$out_key2] = $in_val2; |
|
636 | + } |
|
637 | + } |
|
638 | + } |
|
639 | + } |
|
640 | + |
|
641 | + return $out_array; |
|
642 | + } |
|
643 | + |
|
644 | + /** |
|
645 | + * This method strips out disallowed and/or mangled (X)HTML tags along with assigned attributes. |
|
646 | + * |
|
647 | + * This method does a lot of work. It rejects some very malformed things |
|
648 | + * like <:::>. It returns an empty string if the element isn't allowed (look |
|
649 | + * ma, no strip_tags()!). Otherwise it splits the tag into an element and an |
|
650 | + * allowed attribute list. |
|
651 | + * |
|
652 | + * @access private |
|
653 | + * @param string $string |
|
654 | + * @return string Modified string minus disallowed/mangled (X)HTML and attributes |
|
655 | + * @since PHP4 OOP 0.0.1 |
|
656 | + */ |
|
657 | + private function stripTags($string) |
|
658 | + { |
|
659 | + $string = preg_replace('%\\\\"%', '"', $string); |
|
660 | + |
|
661 | + if (substr($string, 0, 1) != '<') |
|
662 | + { |
|
663 | + # It matched a ">" character |
|
664 | + return '>'; |
|
665 | + } |
|
666 | + |
|
667 | + if (!preg_match('%^<\s*(/\s*)?([a-zA-Z0-9]+)([^>]*)>?$%', $string, $matches)) |
|
668 | + { |
|
669 | + # It's seriously malformed |
|
670 | + return ''; |
|
671 | + } |
|
672 | + |
|
673 | + $slash = trim($matches[1]); |
|
674 | + $elem = $matches[2]; |
|
675 | + $attrlist = $matches[3]; |
|
676 | + |
|
677 | + if ( |
|
678 | + !isset($this->allowed_html[strtolower($elem)]) || |
|
679 | + !is_array($this->allowed_html[strtolower($elem)])) |
|
680 | + { |
|
681 | + # Found an HTML element not in the white list |
|
682 | + return ''; |
|
683 | + } |
|
684 | + |
|
685 | + if ($slash != '') |
|
686 | + { |
|
687 | + return "<$slash$elem>"; |
|
688 | + } |
|
689 | + # No attributes are allowed for closing elements |
|
690 | + |
|
691 | + return $this->stripAttributes("$slash$elem", $attrlist); |
|
692 | + } |
|
693 | + |
|
694 | + /** |
|
695 | + * This method strips out disallowed attributes for (X)HTML tags. |
|
696 | + * |
|
697 | + * This method removes all attributes if none are allowed for this element. |
|
698 | + * If some are allowed it calls combAttributes() to split them further, and then it |
|
699 | + * builds up new HTML code from the data that combAttributes() returns. It also |
|
700 | + * removes "<" and ">" characters, if there are any left. One more thing it |
|
701 | + * does is to check if the tag has a closing XHTML slash, and if it does, |
|
702 | + * it puts one in the returned code as well. |
|
703 | + * |
|
704 | + * @access private |
|
705 | + * @param string $element (X)HTML tag to check |
|
706 | + * @param string $attr Text containing attributes to check for validity. |
|
707 | + * @return string Resulting valid (X)HTML or '' |
|
708 | + * @see combAttributes() |
|
709 | + * @since PHP4 OOP 0.0.1 |
|
710 | + */ |
|
711 | + private function stripAttributes($element, $attr) |
|
712 | + { |
|
713 | + # Is there a closing XHTML slash at the end of the attributes? |
|
714 | + $xhtml_slash = ''; |
|
715 | + if (preg_match('%\s/\s*$%', $attr)) |
|
716 | + { |
|
717 | + $xhtml_slash = ' /'; |
|
718 | + } |
|
719 | + |
|
720 | + # Are any attributes allowed at all for this element? |
|
721 | + if ( |
|
722 | + !isset($this->allowed_html[strtolower($element)]) || |
|
723 | + count($this->allowed_html[strtolower($element)]) == 0 |
|
724 | + ) |
|
725 | + { |
|
726 | + return "<$element$xhtml_slash>"; |
|
727 | + } |
|
728 | + |
|
729 | + # Split it |
|
730 | + $attrarr = $this->combAttributes($attr); |
|
731 | + |
|
732 | + # Go through $attrarr, and save the allowed attributes for this element |
|
733 | + # in $attr2 |
|
734 | + $attr2 = ''; |
|
735 | + if(is_array($attrarr) && count($attrarr) > 0) |
|
736 | + { |
|
737 | + foreach ($attrarr as $arreach) |
|
738 | + { |
|
739 | + if(!isset($this->allowed_html[strtolower($element)][strtolower($arreach['name'])])) |
|
740 | + { |
|
741 | + continue; |
|
742 | + } |
|
743 | + |
|
744 | + $current = $this->allowed_html[strtolower($element)][strtolower($arreach['name'])]; |
|
745 | + |
|
746 | + if (!is_array($current)) |
|
747 | + { |
|
748 | + # there are no checks |
|
749 | + $attr2 .= ' '.$arreach['whole']; |
|
750 | + } |
|
751 | + else |
|
752 | + { |
|
753 | + # there are some checks |
|
754 | + $ok = true; |
|
755 | + if(is_array($current) && count($current) > 0) |
|
756 | + { |
|
757 | + foreach ($current as $currkey => $currval) |
|
758 | + { |
|
759 | + if (!$this->checkAttributeValue($arreach['value'], $arreach['vless'], $currkey, $currval)) |
|
760 | + { |
|
761 | + $ok = false; |
|
762 | + break; |
|
763 | + } |
|
764 | + } |
|
765 | + } |
|
766 | + |
|
767 | + if ($ok) |
|
768 | + { |
|
769 | + # it passed them |
|
770 | + $attr2 .= ' '.$arreach['whole']; |
|
771 | + } |
|
772 | + } |
|
773 | + } |
|
774 | + } |
|
775 | + |
|
776 | + # Remove any "<" or ">" characters |
|
777 | + $attr2 = preg_replace('/[<>]/', '', $attr2); |
|
778 | + return "<$element$attr2$xhtml_slash>"; |
|
779 | + } |
|
780 | + |
|
781 | + /** |
|
782 | + * This method combs through an attribute list string and returns an associative array of attributes and values. |
|
783 | + * |
|
784 | + * This method does a lot of work. It parses an attribute list into an array |
|
785 | + * with attribute data, and tries to do the right thing even if it gets weird |
|
786 | + * input. It will add quotes around attribute values that don't have any quotes |
|
787 | + * or apostrophes around them, to make it easier to produce HTML code that will |
|
788 | + * conform to W3C's HTML specification. It will also remove bad URL protocols |
|
789 | + * from attribute values. |
|
790 | + * |
|
791 | + * @access private |
|
792 | + * @param string $attr Text containing tag attributes for parsing |
|
793 | + * @return array Associative array containing data on attribute and value |
|
794 | + * @since PHP4 OOP 0.0.1 |
|
795 | + */ |
|
796 | + private function combAttributes($attr) |
|
797 | + { |
|
798 | + $attrarr = array(); |
|
799 | + $mode = 0; |
|
800 | + $attrname = ''; |
|
801 | + |
|
802 | + # Loop through the whole attribute list |
|
803 | + |
|
804 | + while (strlen($attr) != 0) |
|
805 | + { |
|
806 | + # Was the last operation successful? |
|
807 | + $working = 0; |
|
808 | + |
|
809 | + switch ($mode) |
|
810 | + { |
|
811 | + case 0: # attribute name, href for instance |
|
812 | + if (preg_match('/^([-a-zA-Z]+)/', $attr, $match)) |
|
813 | + { |
|
814 | + $attrname = $match[1]; |
|
815 | + $working = $mode = 1; |
|
816 | + $attr = preg_replace('/^[-a-zA-Z]+/', '', $attr); |
|
817 | + } |
|
818 | + break; |
|
819 | + case 1: # equals sign or valueless ("selected") |
|
820 | + if (preg_match('/^\s*=\s*/', $attr)) # equals sign |
|
821 | + { |
|
822 | + $working = 1; |
|
823 | + $mode = 2; |
|
824 | + $attr = preg_replace('/^\s*=\s*/', '', $attr); |
|
825 | + break; |
|
826 | + } |
|
827 | + if (preg_match('/^\s+/', $attr)) # valueless |
|
828 | + { |
|
829 | + $working = 1; |
|
830 | + $mode = 0; |
|
831 | + $attrarr[] = array( |
|
832 | + 'name' => $attrname, |
|
833 | + 'value' => '', |
|
834 | + 'whole' => $attrname, |
|
835 | + 'vless' => 'y' |
|
836 | + ); |
|
837 | + $attr = preg_replace('/^\s+/', '', $attr); |
|
838 | + } |
|
839 | + break; |
|
840 | + case 2: # attribute value, a URL after href= for instance |
|
841 | + if (preg_match('/^"([^"]*)"(\s+|$)/', $attr, $match)) # "value" |
|
842 | + { |
|
843 | + $thisval = $this->removeBadProtocols($match[1]); |
|
844 | + $attrarr[] = array( |
|
845 | + 'name' => $attrname, |
|
846 | + 'value' => $thisval, |
|
847 | + 'whole' => $attrname . '="' . $thisval . '"', |
|
848 | + 'vless' => 'n' |
|
849 | + ); |
|
850 | + $working = 1; |
|
851 | + $mode = 0; |
|
852 | + $attr = preg_replace('/^"[^"]*"(\s+|$)/', '', $attr); |
|
853 | + break; |
|
854 | + } |
|
855 | + if (preg_match("/^'([^']*)'(\s+|$)/", $attr, $match)) # 'value' |
|
856 | + { |
|
857 | + $thisval = $this->removeBadProtocols($match[1]); |
|
858 | + $attrarr[] = array( |
|
859 | + 'name' => $attrname, |
|
860 | + 'value' => $thisval, |
|
861 | + 'whole' => "$attrname='$thisval'", |
|
862 | + 'vless' => 'n' |
|
863 | + ); |
|
864 | + $working = 1; |
|
865 | + $mode = 0; |
|
866 | + $attr = preg_replace("/^'[^']*'(\s+|$)/", '', $attr); |
|
867 | + break; |
|
868 | + } |
|
869 | + if (preg_match("%^([^\s\"']+)(\s+|$)%", $attr, $match)) # value |
|
870 | + { |
|
871 | + $thisval = $this->removeBadProtocols($match[1]); |
|
872 | + $attrarr[] = array( |
|
873 | + 'name' => $attrname, |
|
874 | + 'value' => $thisval, |
|
875 | + 'whole' => $attrname . '="' . $thisval . '"', |
|
876 | + 'vless' => 'n' |
|
877 | + ); |
|
878 | + # We add quotes to conform to W3C's HTML spec. |
|
879 | + $working = 1; |
|
880 | + $mode = 0; |
|
881 | + $attr = preg_replace("%^[^\s\"']+(\s+|$)%", '', $attr); |
|
882 | + } |
|
883 | + break; |
|
884 | + } |
|
885 | + |
|
886 | + if ($working == 0) # not well formed, remove and try again |
|
887 | + { |
|
888 | + $attr = preg_replace('/^("[^"]*("|$)|\'[^\']*(\'|$)|\S)*\s*/', '', $attr); |
|
889 | + $mode = 0; |
|
890 | + } |
|
891 | + } |
|
892 | + |
|
893 | + # special case, for when the attribute list ends with a valueless |
|
894 | + # attribute like "selected" |
|
895 | + if ($mode == 1) |
|
896 | + { |
|
897 | + $attrarr[] = array( |
|
898 | + 'name' => $attrname, |
|
899 | + 'value' => '', |
|
900 | + 'whole' => $attrname, |
|
901 | + 'vless' => 'y' |
|
902 | + ); |
|
903 | + } |
|
904 | + |
|
905 | + return $attrarr; |
|
906 | + } |
|
907 | + |
|
908 | + /** |
|
909 | + * This method removes disallowed protocols. |
|
910 | + * |
|
911 | + * This method removes all non-allowed protocols from the beginning of |
|
912 | + * $string. It ignores whitespace and the case of the letters, and it does |
|
913 | + * understand HTML entities. It does its work in a while loop, so it won't be |
|
914 | + * fooled by a string like "javascript:javascript:alert(57)". |
|
915 | + * |
|
916 | + * @access private |
|
917 | + * @param string $string String to check for protocols |
|
918 | + * @return string String with removed protocols |
|
919 | + * @since PHP4 OOP 0.0.1 |
|
920 | + */ |
|
921 | + private function removeBadProtocols($string) |
|
922 | + { |
|
923 | + $string = $this->RemoveNulls($string); |
|
924 | + $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
925 | + $string2 = $string . 'a'; |
|
926 | + |
|
927 | + $string2 = preg_split('/:|:|:/i', $string, 2); |
|
928 | + if(isset($string2[1]) && !preg_match('%/\?%',$string2[0])) |
|
929 | + { |
|
930 | + $string = $this->filterProtocols($string2[0]).trim($string2[1]); |
|
931 | + } |
|
932 | + return $string; |
|
933 | + } |
|
934 | + |
|
935 | + /** |
|
936 | + * Helper method used by removeBadProtocols() |
|
937 | + * |
|
938 | + * This function processes URL protocols, checks to see if they're in the white- |
|
939 | + * list or not, and returns different data depending on the answer. |
|
940 | + * |
|
941 | + * @access private |
|
942 | + * @param string $string String to check for protocols |
|
943 | + * @return string String with removed protocols |
|
944 | + * @see removeBadProtocols() |
|
945 | + * @since PHP4 OOP 0.0.1 |
|
946 | + */ |
|
947 | + private function filterProtocols($string) |
|
948 | + { |
|
949 | + $string = $this->decodeEntities($string); |
|
950 | + $string = preg_replace('/\s/', '', $string); |
|
951 | + $string = $this->removeNulls($string); |
|
952 | + $string = preg_replace('/\xad+/', '', $string2); # deals with Opera "feature" |
|
953 | + $string = strtolower($string); |
|
954 | + |
|
955 | + if(is_array($this->allowed_protocols) && count($this->allowed_protocols) > 0) |
|
956 | + { |
|
957 | + foreach ($this->allowed_protocols as $one_protocol) |
|
958 | + { |
|
959 | + if (strtolower($one_protocol) == $string) |
|
960 | + { |
|
961 | + return "$string:"; |
|
962 | + } |
|
963 | + } |
|
964 | + } |
|
965 | + |
|
966 | + return ''; |
|
967 | + } |
|
968 | + |
|
969 | + /** |
|
970 | + * Controller method for performing checks on attribute values. |
|
971 | + * |
|
972 | + * This method calls the appropriate method as specified by $checkname with |
|
973 | + * the parameters $value, $vless, and $checkvalue, and returns the result |
|
974 | + * of the call. |
|
975 | + * |
|
976 | + * This method's functionality can be expanded by creating new methods |
|
977 | + * that would match checkAttributeValue[$checkname]. |
|
978 | + * |
|
979 | + * Current checks implemented are: "maxlen", "minlen", "maxval", "minval" and "valueless" |
|
980 | + * |
|
981 | + * @access private |
|
982 | + * @param string $value The value of the attribute to be checked. |
|
983 | + * @param string $vless Indicates whether the the value is supposed to be valueless |
|
984 | + * @param string $checkname The check to be performed |
|
985 | + * @param string $checkvalue The value that is to be checked against |
|
986 | + * @return bool Indicates whether the check passed or not |
|
987 | + * @since PHP5 OOP 1.0.0 |
|
988 | + */ |
|
989 | + private function checkAttributeValue($value, $vless, $checkname, $checkvalue) |
|
990 | + { |
|
991 | + $ok = true; |
|
992 | + $check_attribute_method_name = 'checkAttributeValue' . ucfirst(strtolower($checkname)); |
|
993 | + if(method_exists($this, $check_attribute_method_name)) |
|
994 | + { |
|
995 | + $ok = $this->$check_attribute_method_name($value, $checkvalue, $vless); |
|
996 | + } |
|
997 | + |
|
998 | + return $ok; |
|
999 | + } |
|
1000 | + |
|
1001 | + /** |
|
1002 | + * Helper method invoked by checkAttributeValue(). |
|
1003 | + * |
|
1004 | + * The maxlen check makes sure that the attribute value has a length not |
|
1005 | + * greater than the given value. This can be used to avoid Buffer Overflows |
|
1006 | + * in WWW clients and various Internet servers. |
|
1007 | + * |
|
1008 | + * @access private |
|
1009 | + * @param string $value The value of the attribute to be checked. |
|
1010 | + * @param int $checkvalue The maximum value allowed |
|
1011 | + * @return bool Indicates whether the check passed or not |
|
1012 | + * @see checkAttributeValue() |
|
1013 | + * @since PHP5 OOP 1.0.0 |
|
1014 | + */ |
|
1015 | + private function checkAttributeValueMaxlen($value, $checkvalue) |
|
1016 | + { |
|
1017 | + if (strlen($value) > intval($checkvalue)) |
|
1018 | + { |
|
1019 | + return false; |
|
1020 | + } |
|
1021 | + return true; |
|
1022 | + } |
|
1023 | + |
|
1024 | + /** |
|
1025 | + * Helper method invoked by checkAttributeValue(). |
|
1026 | + * |
|
1027 | + * The minlen check makes sure that the attribute value has a length not |
|
1028 | + * smaller than the given value. |
|
1029 | + * |
|
1030 | + * @access private |
|
1031 | + * @param string $value The value of the attribute to be checked. |
|
1032 | + * @param int $checkvalue The minimum value allowed |
|
1033 | + * @return bool Indicates whether the check passed or not |
|
1034 | + * @see checkAttributeValue() |
|
1035 | + * @since PHP5 OOP 1.0.0 |
|
1036 | + */ |
|
1037 | + private function checkAttributeValueMinlen($value, $checkvalue) |
|
1038 | + { |
|
1039 | + if (strlen($value) < intval($checkvalue)) |
|
1040 | + { |
|
1041 | + return false; |
|
1042 | + } |
|
1043 | + return true; |
|
1044 | + } |
|
1045 | + |
|
1046 | + /** |
|
1047 | + * Helper method invoked by checkAttributeValue(). |
|
1048 | + * |
|
1049 | + * The maxval check does two things: it checks that the attribute value is |
|
1050 | + * an integer from 0 and up, without an excessive amount of zeroes or |
|
1051 | + * whitespace (to avoid Buffer Overflows). It also checks that the attribute |
|
1052 | + * value is not greater than the given value. |
|
1053 | + * |
|
1054 | + * This check can be used to avoid Denial of Service attacks. |
|
1055 | + * |
|
1056 | + * @access private |
|
1057 | + * @param int $value The value of the attribute to be checked. |
|
1058 | + * @param int $checkvalue The maximum numeric value allowed |
|
1059 | + * @return bool Indicates whether the check passed or not |
|
1060 | + * @see checkAttributeValue() |
|
1061 | + * @since PHP5 OOP 1.0.0 |
|
1062 | + */ |
|
1063 | + private function checkAttributeValueMaxval($value, $checkvalue) |
|
1064 | + { |
|
1065 | + if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1066 | + { |
|
1067 | + return false; |
|
1068 | + } |
|
1069 | + if (intval($value) > intval($checkvalue)) |
|
1070 | + { |
|
1071 | + return false; |
|
1072 | + } |
|
1073 | + return true; |
|
1074 | + } |
|
1075 | + |
|
1076 | + /** |
|
1077 | + * Helper method invoked by checkAttributeValue(). |
|
1078 | + * |
|
1079 | + * The minval check checks that the attribute value is a positive integer, |
|
1080 | + * and that it is not smaller than the given value. |
|
1081 | + * |
|
1082 | + * @access private |
|
1083 | + * @param int $value The value of the attribute to be checked. |
|
1084 | + * @param int $checkvalue The minimum numeric value allowed |
|
1085 | + * @return bool Indicates whether the check passed or not |
|
1086 | + * @see checkAttributeValue() |
|
1087 | + * @since PHP5 OOP 1.0.0 |
|
1088 | + */ |
|
1089 | + private function checkAttributeValueMinval($value, $checkvalue) |
|
1090 | + { |
|
1091 | + if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1092 | + { |
|
1093 | + return false; |
|
1094 | + } |
|
1095 | + if (intval($value) < ($checkvalue)) |
|
1096 | + { |
|
1097 | + return false; |
|
1098 | + } |
|
1099 | + return true; |
|
1100 | + } |
|
1101 | + |
|
1102 | + /** |
|
1103 | + * Helper method invoked by checkAttributeValue(). |
|
1104 | + * |
|
1105 | + * The valueless check checks if the attribute has a value |
|
1106 | + * (like <a href="blah">) or not (<option selected>). If the given value |
|
1107 | + * is a "y" or a "Y", the attribute must not have a value. |
|
1108 | + * |
|
1109 | + * If the given value is an "n" or an "N", the attribute must have one. |
|
1110 | + * |
|
1111 | + * @access private |
|
1112 | + * @param int $value The value of the attribute to be checked. |
|
1113 | + * @param mixed $checkvalue This variable is ignored for this test |
|
1114 | + * @param string $vless Flag indicating if this attribute is not supposed to have an attribute |
|
1115 | + * @return bool Indicates whether the check passed or not |
|
1116 | + * @see checkAttributeValue() |
|
1117 | + * @since PHP5 OOP 1.0.0 |
|
1118 | + */ |
|
1119 | + private function checkAttributeValueValueless($value, $checkvalue, $vless) |
|
1120 | + { |
|
1121 | + if (strtolower($checkvalue) != $vless) |
|
1122 | + { |
|
1123 | + return false; |
|
1124 | + } |
|
1125 | + return true; |
|
1126 | + } |
|
1127 | + |
|
1128 | + /** |
|
1129 | + * Decodes numeric HTML entities |
|
1130 | + * |
|
1131 | + * This method decodes numeric HTML entities (A and A). It doesn't |
|
1132 | + * do anything with other entities like ä, but we don't need them in the |
|
1133 | + * URL protocol white listing system anyway. |
|
1134 | + * |
|
1135 | + * @access private |
|
1136 | + * @param string $value The entitiy to be decoded. |
|
1137 | + * @return string Decoded entity |
|
1138 | + * @since PHP4 OOP 0.0.1 |
|
1139 | + */ |
|
1140 | + private function decodeEntities($string) |
|
1141 | + { |
|
1142 | + $string = preg_replace('/&#([0-9]+);/e', 'chr("\\1")', $string); |
|
1143 | + $string = preg_replace('/&#[Xx]([0-9A-Fa-f]+);/e', 'chr(hexdec("\\1"))', $string); |
|
1144 | + return $string; |
|
1145 | + } |
|
1146 | + |
|
1147 | + /** |
|
1148 | + * Returns PHP5 OOP version # of kses. |
|
1149 | + * |
|
1150 | + * Since this class has been refactored and documented and proven to work, |
|
1151 | + * I'm fixing the version number at 1.0.0. |
|
1152 | + * |
|
1153 | + * This version is syntax compatible with the PHP4 OOP version 0.0.2. Future |
|
1154 | + * versions may not be syntax compatible. |
|
1155 | + * |
|
1156 | + * @access public |
|
1157 | + * @return string Version number |
|
1158 | + * @since PHP4 OOP 0.0.1 |
|
1159 | + */ |
|
1160 | + public function Version() |
|
1161 | + { |
|
1162 | + return 'PHP5 OOP 1.0.2'; |
|
1163 | + } |
|
1164 | + } |
|
1165 | + } |
|
1166 | 1166 | ?> |
1167 | 1167 | \ No newline at end of file |
@@ -1,507 +1,507 @@ |
||
1 | 1 | <?php |
2 | 2 | |
3 | - // This is a q&d program that shows some of the results of |
|
4 | - // running KSES. If you have further questions, check the |
|
5 | - // current valid email address at http://chaos.org/contact/ |
|
6 | - |
|
7 | - // Make sure we're in a usable PHP environment |
|
8 | - if(substr(phpversion(), 0, 1) < 4) |
|
9 | - { |
|
10 | - define('KSESTEST_VER', 0); |
|
11 | - } |
|
12 | - elseif(substr(phpversion(), 0, 1) >= 5) |
|
13 | - { |
|
14 | - define('KSESTEST_VER', 5); |
|
15 | - } |
|
16 | - else |
|
17 | - { |
|
18 | - define('KSESTEST_VER', 4); |
|
19 | - } |
|
20 | - |
|
21 | - // See if we're in command line or web |
|
22 | - if($_SERVER["DOCUMENT_ROOT"] == "") |
|
23 | - { |
|
24 | - define('KSESTEST_ENV', 'CLI'); |
|
25 | - } |
|
26 | - else |
|
27 | - { |
|
28 | - define('KSESTEST_ENV', 'WEB'); |
|
29 | - } |
|
30 | - |
|
31 | - if(KSESTEST_VER == 0) |
|
32 | - { |
|
33 | - $message = array( |
|
34 | - "Error: Not using a current version of PHP!", |
|
35 | - "You are using PHP version " . phpversion() . ".", |
|
36 | - "KSES Class version requires PHP4 or better.", |
|
37 | - "KSES test program ending." |
|
38 | - ); |
|
39 | - |
|
40 | - displayPage( |
|
41 | - array("title" => "Error running KSES test", "message" => $message) |
|
42 | - ); |
|
43 | - |
|
44 | - exit(); |
|
45 | - } |
|
46 | - |
|
47 | - $include_file = "php" . KSESTEST_VER . ".class.kses.php"; |
|
48 | - if(file_exists($include_file) && is_readable($include_file)) |
|
49 | - { |
|
50 | - include_once($include_file); |
|
51 | - } |
|
52 | - else |
|
53 | - { |
|
54 | - $message = array( |
|
55 | - "Error: Unable to find '" . $include_file . "'.", |
|
56 | - "Please check your include path and make sure the file is available.", |
|
57 | - "Path: " . ini_get('include_path') |
|
58 | - ); |
|
59 | - |
|
60 | - displayPage( |
|
61 | - array('title' => 'Unable to include ' . $include_file, 'message' => $message) |
|
62 | - ); |
|
63 | - |
|
64 | - exit(); |
|
65 | - } |
|
66 | - |
|
67 | - $kses_type = "kses" . KSESTEST_VER; |
|
68 | - $myKses = new $kses_type; |
|
69 | - |
|
70 | - $test_text = array(); |
|
71 | - $test_text = test1_protocols($myKses); |
|
72 | - $test_text = array_merge($test_text, test1_html($myKses)); |
|
73 | - $test_text = array_merge($test_text, test1_kses($myKses)); |
|
74 | - |
|
75 | - displayPage( |
|
76 | - array('title' => 'New Test', 'message' => $test_text) |
|
77 | - ); |
|
78 | - |
|
79 | - function test1_kses(&$myKses) |
|
80 | - { |
|
81 | - $out = array(output_hr(), "Testing current configuration"); |
|
82 | - |
|
83 | - $test_tags = array( |
|
84 | - '<a href="http://www.chaos.org/">www.chaos.org</a>', |
|
85 | - '<a name="X">Short \'a name\' tag</a>', |
|
86 | - '<td colspan="3" rowspan="5">Foo</td>', |
|
87 | - '<td rowspan="2" class="mugwump" style="background-color: rgb(255, 204 204);">Bar</td>', |
|
88 | - '<td nowrap>Very Long String running to 1000 characters...</td>', |
|
89 | - '<td bgcolor="#00ff00" nowrap>Very Long String with a blue background</td>', |
|
90 | - '<a href="proto1://www.foo.com">New protocol test</a>', |
|
91 | - '<img src="proto2://www.foo.com" />', |
|
92 | - '<a href="javascript:javascript:javascript:javascript:javascript:alert(\'Boo!\');">bleep</a>', |
|
93 | - '<a href="proto4://abc.xyz.foo.com">Another new protocol</a>', |
|
94 | - '<a href="proto9://foo.foo.foo.foo.foo.org/">Test of "proto9"</a>', |
|
95 | - '<td width="75">Bar!</td>', |
|
96 | - '<td width="200">Long Cell</td>' |
|
97 | - ); |
|
98 | - |
|
99 | - $out_li = array(); |
|
100 | - // Keep only allowed HTML from the presumed 'form'. |
|
101 | - foreach($test_tags as $tag) |
|
102 | - { |
|
103 | - $temp = $myKses->Parse($tag); |
|
104 | - $check = ($temp == $tag) ? true : false; |
|
105 | - $text = ($temp == $tag) ? 'pass' : 'fail'; |
|
106 | - |
|
107 | - $li_text = output_testresult($check, $text) . output_newline(); |
|
108 | - $li_text .= "Input: " . output_translate($tag) . output_newline(); |
|
109 | - $li_text .= "Output: " . output_translate($temp); |
|
110 | - if(KSESTEST_ENV == 'CLI') |
|
111 | - { |
|
112 | - $li_text .= output_newline(); |
|
113 | - } |
|
114 | - |
|
115 | - array_push($out_li, output_code_wrap($li_text)); |
|
116 | - } |
|
117 | - |
|
118 | - $out = array_merge($out, array(output_ul($out_li))); |
|
119 | - array_push($out, output_hr()); |
|
120 | - array_push($out, "Testing is now finished."); |
|
121 | - return $out; |
|
122 | - } |
|
123 | - |
|
124 | - function output_code_wrap($text) |
|
125 | - { |
|
126 | - if(KSESTEST_ENV == 'CLI') |
|
127 | - { |
|
128 | - return $text; |
|
129 | - } |
|
130 | - else |
|
131 | - { |
|
132 | - return "<code>\n$text<code>\n"; |
|
133 | - } |
|
134 | - } |
|
135 | - |
|
136 | - function output_translate($text) |
|
137 | - { |
|
138 | - if(KSESTEST_ENV == 'CLI') |
|
139 | - { |
|
140 | - return $text; |
|
141 | - } |
|
142 | - else |
|
143 | - { |
|
144 | - return htmlentities($text); |
|
145 | - } |
|
146 | - } |
|
147 | - |
|
148 | - function output_testresult($pass = false, $text = "") |
|
149 | - { |
|
150 | - if(KSESTEST_ENV == 'CLI') |
|
151 | - { |
|
152 | - return '[' . $text . ']'; |
|
153 | - } |
|
154 | - else |
|
155 | - { |
|
156 | - if($pass == true) |
|
157 | - { |
|
158 | - return '<span style="color: green;">[' . $text . ']</span>'; |
|
159 | - } |
|
160 | - else |
|
161 | - { |
|
162 | - return '<span style="color: red;">[' . $text . ']</span>'; |
|
163 | - } |
|
164 | - } |
|
165 | - } |
|
166 | - |
|
167 | - function output_spaces() |
|
168 | - { |
|
169 | - if(KSESTEST_ENV == 'WEB') |
|
170 | - { |
|
171 | - $out = " "; |
|
172 | - } |
|
173 | - else |
|
174 | - { |
|
175 | - $out = " "; |
|
176 | - } |
|
177 | - |
|
178 | - return $out; |
|
179 | - } |
|
180 | - |
|
181 | - function output_newline() |
|
182 | - { |
|
183 | - if(KSESTEST_ENV == 'WEB') |
|
184 | - { |
|
185 | - $out = "<br />\n"; |
|
186 | - } |
|
187 | - else |
|
188 | - { |
|
189 | - $out = "\n"; |
|
190 | - } |
|
191 | - |
|
192 | - return $out; |
|
193 | - } |
|
194 | - |
|
195 | - function displayPage($data = array()) |
|
196 | - { |
|
197 | - $title = ($data['title'] == '') ? 'No title' : $data['title']; |
|
198 | - $message = ($data['message'] == '') ? array('No message') : $data['message']; |
|
199 | - |
|
200 | - $out = ""; |
|
201 | - |
|
202 | - foreach($message as $text) |
|
203 | - { |
|
204 | - if(KSESTEST_ENV == 'WEB') |
|
205 | - { |
|
206 | - $header = "\t\t<h1>$title</h1>\n\t\t<hr />\n"; |
|
207 | - $out .= "\t\t<p>\n"; |
|
208 | - $out .= "\t\t\t$text\n"; |
|
209 | - $out .= "\t\t</p>\n"; |
|
210 | - } |
|
211 | - else |
|
212 | - { |
|
213 | - $header = "$title\n" . str_repeat('-', 60) . "\n\n"; |
|
214 | - $out .= "\t$text\n\n"; |
|
215 | - } |
|
216 | - } |
|
217 | - |
|
218 | - if(KSESTEST_ENV == 'WEB') |
|
219 | - { |
|
220 | - echo "<html>\n"; |
|
221 | - echo "\t<head>\n"; |
|
222 | - echo "\t\t<title>$title</title>\n"; |
|
223 | - echo "\t</head>\n"; |
|
224 | - echo "\t<body>\n"; |
|
225 | - echo $header; |
|
226 | - echo $out; |
|
227 | - echo "\t</body>\n"; |
|
228 | - echo "</html>\n"; |
|
229 | - } |
|
230 | - else |
|
231 | - { |
|
232 | - echo $header; |
|
233 | - echo $out; |
|
234 | - } |
|
235 | - } |
|
236 | - |
|
237 | - function output_hr() |
|
238 | - { |
|
239 | - if(KSESTEST_ENV == 'WEB') |
|
240 | - { |
|
241 | - return "\t\t\t<hr />\n"; |
|
242 | - } |
|
243 | - else |
|
244 | - { |
|
245 | - return str_repeat(60, '-') . "\n"; |
|
246 | - } |
|
247 | - } |
|
248 | - |
|
249 | - function output_ul($data = array(), $padding = "") |
|
250 | - { |
|
251 | - if(!is_array($data) || count($data) < 1) |
|
252 | - { |
|
253 | - return ""; |
|
254 | - } |
|
255 | - |
|
256 | - $text = ""; |
|
257 | - if(KSESTEST_ENV == 'WEB') |
|
258 | - { |
|
259 | - $text = "\t\t\t<ul>\n"; |
|
260 | - foreach($data as $li) |
|
261 | - { |
|
262 | - $text .= "\t\t\t\t<li>$li</li>\n"; |
|
263 | - } |
|
264 | - $text .= "\t\t\t</ul>\n"; |
|
265 | - } |
|
266 | - else |
|
267 | - { |
|
268 | - foreach($data as $li) |
|
269 | - { |
|
270 | - $text .= $padding . " * $li\n"; |
|
271 | - } |
|
272 | - } |
|
273 | - |
|
274 | - return $text; |
|
275 | - } |
|
276 | - |
|
277 | - function test1_protocols(&$myKses) |
|
278 | - { |
|
279 | - $default_prots = $myKses->dumpProtocols(); |
|
280 | - $out_text = array(); |
|
281 | - if(count($default_prots) > 0) |
|
282 | - { |
|
283 | - array_push($out_text, "Initial protocols from KSES" . KSESTEST_VER . ":"); |
|
284 | - array_push($out_text, output_ul($default_prots)); |
|
285 | - array_push($out_text, output_hr()); |
|
286 | - } |
|
287 | - |
|
288 | - $myKses->AddProtocols(array("proto1", "proto2:", "proto3")); // Add a list of protocols |
|
289 | - $myKses->AddProtocols("proto4:"); // Add a single protocol (Note ':' is optional at end) |
|
290 | - $myKses->AddProtocol("proto9", "mystery:", "anarchy"); |
|
291 | - $myKses->AddProtocol("alpha", "beta", "gamma:"); |
|
292 | - |
|
293 | - $add_protocol = "\t\t\t<ol>\n"; |
|
294 | - $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocols(array("proto1", "proto2:", "proto3"));</li>' . "\n"; |
|
295 | - $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocols("proto4:");</li>' . "\n"; |
|
296 | - $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocols("proto4:");</li>' . "\n"; |
|
297 | - $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocol("proto9", "mystery:", "anarchy");</li>' . "\n"; |
|
298 | - $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocol("alpha", "beta", "gamma:");</li>' . "\n"; |
|
299 | - $add_protocol .= "\t\t\t</ol>\n"; |
|
300 | - |
|
301 | - array_push($out_text, $add_protocol); |
|
302 | - |
|
303 | - $new_prots = $myKses->dumpProtocols(); |
|
304 | - if(count($new_prots) > 0) |
|
305 | - { |
|
306 | - array_push($out_text, "New protocols from KSES" . KSESTEST_VER . " after using AddProtocol(s):"); |
|
307 | - array_push($out_text, output_ul($new_prots)); |
|
308 | - array_push($out_text, output_hr()); |
|
309 | - } |
|
310 | - |
|
311 | - $myKses->RemoveProtocols(array("mystery", "anarchy:")); |
|
312 | - $myKses->RemoveProtocols("alpha:"); |
|
313 | - $myKses->RemoveProtocol("beta:"); |
|
314 | - $myKses->RemoveProtocol("gamma"); |
|
315 | - |
|
316 | - $remove_protocol = "\t\t\t<ol>\n"; |
|
317 | - $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocols(array("mystery", "anarchy:"));</li>' . "\n"; |
|
318 | - $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocols("alpha:");</li>' . "\n"; |
|
319 | - $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocol("beta:");</li>' . "\n"; |
|
320 | - $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocol("gamma");</li>' . "\n"; |
|
321 | - $remove_protocol .= "\t\t\t</ol>\n"; |
|
322 | - array_push($out_text, $remove_protocol); |
|
323 | - |
|
324 | - $new_prots = $myKses->dumpProtocols(); |
|
325 | - if(count($new_prots) > 0) |
|
326 | - { |
|
327 | - array_push($out_text, "Resulting protocols from KSES" . KSESTEST_VER . " after using RemoveProtocol(s):"); |
|
328 | - array_push($out_text, output_ul($new_prots)); |
|
329 | - array_push($out_text, output_hr()); |
|
330 | - } |
|
331 | - |
|
332 | - $myKses->SetProtocols(array("https", "gopher", "news")); |
|
333 | - $set_protocol = "\t\t\t<ol>\n"; |
|
334 | - $set_protocol .= "\t\t\t\t" . '<li>$myKses->SetProtocols(array("https", "gopher", "news"));</li>' . "\n"; |
|
335 | - $set_protocol .= "\t\t\t</ol>\n"; |
|
336 | - array_push($out_text, $set_protocol); |
|
337 | - |
|
338 | - $new_prots = $myKses->dumpProtocols(); |
|
339 | - if(count($new_prots) > 0) |
|
340 | - { |
|
341 | - array_push($out_text, "Resulting protocols from KSES" . KSESTEST_VER . " after using SetProtocols:"); |
|
342 | - array_push($out_text, output_ul($new_prots)); |
|
343 | - array_push($out_text, output_hr()); |
|
344 | - } |
|
345 | - |
|
346 | - // Invisible reset |
|
347 | - $myKses->SetProtocols(array("http", "proto1", "proto2", "proto9")); |
|
348 | - |
|
349 | - return $out_text; |
|
350 | - } |
|
351 | - |
|
352 | - function test1_html(&$myKses) |
|
353 | - { |
|
354 | - $out = array(); |
|
355 | - |
|
356 | - // Allows <p>|</p> tag |
|
357 | - $myKses->AddHTML("p"); |
|
358 | - |
|
359 | - // Allows 'a' tag with href|name attributes, |
|
360 | - // href has minlen of 10 chars, and maxlen of 25 chars |
|
361 | - // name has minlen of 2 chars |
|
362 | - $myKses->AddHTML( |
|
363 | - "a", |
|
364 | - array( |
|
365 | - "href" => array('maxlen' => 25, 'minlen' => 10), |
|
366 | - "name" => array('minlen' => 2) |
|
367 | - ) |
|
368 | - ); |
|
369 | - |
|
370 | - // Allows 'td' tag with colspan|rowspan|class|style|width|nowrap attributes, |
|
371 | - // colspan has minval of 2 and maxval of 5 |
|
372 | - // rowspan has minval of 3 and maxval of 6 |
|
373 | - // class has minlen of 1 char and maxlen of 10 chars |
|
374 | - // style has minlen of 10 chars and maxlen of 100 chars |
|
375 | - // width has maxval of 100 |
|
376 | - // nowrap is valueless |
|
377 | - $myKses->AddHTML( |
|
378 | - "td", |
|
379 | - array( |
|
380 | - "colspan" => array('minval' => 2, 'maxval' => 5), |
|
381 | - "rowspan" => array('minval' => 3, 'maxval' => 6), |
|
382 | - "class" => array("minlen" => 1, 'maxlen' => 10), |
|
383 | - "width" => array("maxval" => 100), |
|
384 | - "style" => array('minlen' => 10, 'maxlen' => 100), |
|
385 | - "nowrap" => array('valueless' => 'y') |
|
386 | - ) |
|
387 | - ); |
|
388 | - |
|
389 | - array_push($out, "Modifying HTML Tests:"); |
|
390 | - $code_text = "<pre>\n"; |
|
391 | - $code_text .= " // Allows <p>|</p> tag\n"; |
|
392 | - $code_text .= " \$myKses->AddHTML(\"p\");\n"; |
|
393 | - $code_text .= "\n"; |
|
394 | - $code_text .= " // Allows 'a' tag with href|name attributes,\n"; |
|
395 | - $code_text .= " // href has minlen of 10 chars, and maxlen of 25 chars\n"; |
|
396 | - $code_text .= " // name has minlen of 2 chars\n"; |
|
397 | - $code_text .= " \$myKses->AddHTML(\n"; |
|
398 | - $code_text .= " \"a\",\n"; |
|
399 | - $code_text .= " array(\n"; |
|
400 | - $code_text .= " \"href\" => array('maxlen' => 25, 'minlen' => 10),\n"; |
|
401 | - $code_text .= " \"name\" => array('minlen' => 2)\n"; |
|
402 | - $code_text .= " )\n"; |
|
403 | - $code_text .= " );\n"; |
|
404 | - $code_text .= "\n"; |
|
405 | - $code_text .= " // Allows 'td' tag with colspan|rowspan|class|style|width|nowrap attributes,\n"; |
|
406 | - $code_text .= " // colspan has minval of 2 and maxval of 5\n"; |
|
407 | - $code_text .= " // rowspan has minval of 3 and maxval of 6\n"; |
|
408 | - $code_text .= " // class has minlen of 1 char and maxlen of 10 chars\n"; |
|
409 | - $code_text .= " // style has minlen of 10 chars and maxlen of 100 chars\n"; |
|
410 | - $code_text .= " // width has maxval of 100\n"; |
|
411 | - $code_text .= " // nowrap is valueless\n"; |
|
412 | - $code_text .= " \$myKses->AddHTML(\n"; |
|
413 | - $code_text .= " \"td\",\n"; |
|
414 | - $code_text .= " array(\n"; |
|
415 | - $code_text .= " \"colspan\" => array('minval' => 2, 'maxval' => 5),\n"; |
|
416 | - $code_text .= " \"rowspan\" => array('minval' => 3, 'maxval' => 6),\n"; |
|
417 | - $code_text .= " \"class\" => array(\"minlen\" => 1, 'maxlen' => 10),\n"; |
|
418 | - $code_text .= " \"width\" => array(\"maxval\" => 100),\n"; |
|
419 | - $code_text .= " \"style\" => array('minlen' => 10, 'maxlen' => 100),\n"; |
|
420 | - $code_text .= " \"nowrap\" => array('valueless' => 'y')\n"; |
|
421 | - $code_text .= " )\n"; |
|
422 | - $code_text .= " );\n"; |
|
423 | - $code_text .= "</pre>\n"; |
|
424 | - |
|
425 | - array_push($out, $code_text); |
|
426 | - array_push($out, output_hr()); |
|
427 | - array_push($out, "Net results:"); |
|
428 | - |
|
429 | - $out_elems = $myKses->DumpElements(); |
|
430 | - if(count($out_elems) > 0) |
|
431 | - { |
|
432 | - //array_push($out, "\t\t\t<ul>\n"); |
|
433 | - foreach($out_elems as $tag => $attr_data) |
|
434 | - { |
|
435 | - $out_li_elems = array(); |
|
436 | - $elem_text = "(X)HTML element $tag"; |
|
437 | - $allow = ""; |
|
438 | - if(isset($attr_data) && is_array($attr_data) && count($attr_data) > 0) |
|
439 | - { |
|
440 | - $allow = " allows attribute"; |
|
441 | - if(count($attr_data) > 1) |
|
442 | - { |
|
443 | - $allow .= "s"; |
|
444 | - } |
|
445 | - $allow .= ":\n"; |
|
446 | - } |
|
447 | - |
|
448 | - array_push($out_li_elems, "$elem_text$allow"); |
|
449 | - |
|
450 | - $attr_test_li = array(); |
|
451 | - if(isset($attr_data) && is_array($attr_data) && count($attr_data) > 0) |
|
452 | - { |
|
453 | - foreach($attr_data as $attr_name => $attr_tests) |
|
454 | - { |
|
455 | - $li_text = $attr_name; |
|
456 | - if(isset($attr_tests) && count($attr_tests) > 0) |
|
457 | - { |
|
458 | - foreach($attr_tests as $test_name => $test_val) |
|
459 | - { |
|
460 | - switch($test_name) |
|
461 | - { |
|
462 | - case "maxlen": |
|
463 | - $li_text .= " - maximum length of '" . $test_val . "' characters"; |
|
464 | - break; |
|
465 | - case "minlen": |
|
466 | - $li_text .= " - minimum length of '" . $test_val . "' characters"; |
|
467 | - break; |
|
468 | - case "minval": |
|
469 | - $li_text .= " - minimum value of '" . $test_val . "'"; |
|
470 | - break; |
|
471 | - case "maxval": |
|
472 | - $li_text .= " - maximum value of '" . $test_val . "'"; |
|
473 | - break; |
|
474 | - case "valueless": |
|
475 | - switch(strtolower($test_val)) |
|
476 | - { |
|
477 | - case 'n': |
|
478 | - $li_text .= " - must not be valueless"; |
|
479 | - break; |
|
480 | - case 'y': |
|
481 | - $li_text .= " - must be valueless"; |
|
482 | - break; |
|
483 | - default: |
|
484 | - break; |
|
485 | - } |
|
486 | - break; |
|
487 | - default: |
|
488 | - break; |
|
489 | - } |
|
490 | - } |
|
491 | - } |
|
492 | - array_push($attr_test_li, $li_text); |
|
493 | - } |
|
494 | - if(count($attr_test_li) > 0) |
|
495 | - { |
|
496 | - $attr_test_li = output_ul($attr_test_li, " "); |
|
497 | - $out_li_elems = array("$elem_text$allow$attr_test_li"); |
|
498 | - } |
|
499 | - } |
|
500 | - $out = array_merge($out, $out_li_elems); |
|
501 | - } |
|
502 | - } |
|
503 | - |
|
504 | - return $out; |
|
505 | - } |
|
3 | + // This is a q&d program that shows some of the results of |
|
4 | + // running KSES. If you have further questions, check the |
|
5 | + // current valid email address at http://chaos.org/contact/ |
|
6 | + |
|
7 | + // Make sure we're in a usable PHP environment |
|
8 | + if(substr(phpversion(), 0, 1) < 4) |
|
9 | + { |
|
10 | + define('KSESTEST_VER', 0); |
|
11 | + } |
|
12 | + elseif(substr(phpversion(), 0, 1) >= 5) |
|
13 | + { |
|
14 | + define('KSESTEST_VER', 5); |
|
15 | + } |
|
16 | + else |
|
17 | + { |
|
18 | + define('KSESTEST_VER', 4); |
|
19 | + } |
|
20 | + |
|
21 | + // See if we're in command line or web |
|
22 | + if($_SERVER["DOCUMENT_ROOT"] == "") |
|
23 | + { |
|
24 | + define('KSESTEST_ENV', 'CLI'); |
|
25 | + } |
|
26 | + else |
|
27 | + { |
|
28 | + define('KSESTEST_ENV', 'WEB'); |
|
29 | + } |
|
30 | + |
|
31 | + if(KSESTEST_VER == 0) |
|
32 | + { |
|
33 | + $message = array( |
|
34 | + "Error: Not using a current version of PHP!", |
|
35 | + "You are using PHP version " . phpversion() . ".", |
|
36 | + "KSES Class version requires PHP4 or better.", |
|
37 | + "KSES test program ending." |
|
38 | + ); |
|
39 | + |
|
40 | + displayPage( |
|
41 | + array("title" => "Error running KSES test", "message" => $message) |
|
42 | + ); |
|
43 | + |
|
44 | + exit(); |
|
45 | + } |
|
46 | + |
|
47 | + $include_file = "php" . KSESTEST_VER . ".class.kses.php"; |
|
48 | + if(file_exists($include_file) && is_readable($include_file)) |
|
49 | + { |
|
50 | + include_once($include_file); |
|
51 | + } |
|
52 | + else |
|
53 | + { |
|
54 | + $message = array( |
|
55 | + "Error: Unable to find '" . $include_file . "'.", |
|
56 | + "Please check your include path and make sure the file is available.", |
|
57 | + "Path: " . ini_get('include_path') |
|
58 | + ); |
|
59 | + |
|
60 | + displayPage( |
|
61 | + array('title' => 'Unable to include ' . $include_file, 'message' => $message) |
|
62 | + ); |
|
63 | + |
|
64 | + exit(); |
|
65 | + } |
|
66 | + |
|
67 | + $kses_type = "kses" . KSESTEST_VER; |
|
68 | + $myKses = new $kses_type; |
|
69 | + |
|
70 | + $test_text = array(); |
|
71 | + $test_text = test1_protocols($myKses); |
|
72 | + $test_text = array_merge($test_text, test1_html($myKses)); |
|
73 | + $test_text = array_merge($test_text, test1_kses($myKses)); |
|
74 | + |
|
75 | + displayPage( |
|
76 | + array('title' => 'New Test', 'message' => $test_text) |
|
77 | + ); |
|
78 | + |
|
79 | + function test1_kses(&$myKses) |
|
80 | + { |
|
81 | + $out = array(output_hr(), "Testing current configuration"); |
|
82 | + |
|
83 | + $test_tags = array( |
|
84 | + '<a href="http://www.chaos.org/">www.chaos.org</a>', |
|
85 | + '<a name="X">Short \'a name\' tag</a>', |
|
86 | + '<td colspan="3" rowspan="5">Foo</td>', |
|
87 | + '<td rowspan="2" class="mugwump" style="background-color: rgb(255, 204 204);">Bar</td>', |
|
88 | + '<td nowrap>Very Long String running to 1000 characters...</td>', |
|
89 | + '<td bgcolor="#00ff00" nowrap>Very Long String with a blue background</td>', |
|
90 | + '<a href="proto1://www.foo.com">New protocol test</a>', |
|
91 | + '<img src="proto2://www.foo.com" />', |
|
92 | + '<a href="javascript:javascript:javascript:javascript:javascript:alert(\'Boo!\');">bleep</a>', |
|
93 | + '<a href="proto4://abc.xyz.foo.com">Another new protocol</a>', |
|
94 | + '<a href="proto9://foo.foo.foo.foo.foo.org/">Test of "proto9"</a>', |
|
95 | + '<td width="75">Bar!</td>', |
|
96 | + '<td width="200">Long Cell</td>' |
|
97 | + ); |
|
98 | + |
|
99 | + $out_li = array(); |
|
100 | + // Keep only allowed HTML from the presumed 'form'. |
|
101 | + foreach($test_tags as $tag) |
|
102 | + { |
|
103 | + $temp = $myKses->Parse($tag); |
|
104 | + $check = ($temp == $tag) ? true : false; |
|
105 | + $text = ($temp == $tag) ? 'pass' : 'fail'; |
|
106 | + |
|
107 | + $li_text = output_testresult($check, $text) . output_newline(); |
|
108 | + $li_text .= "Input: " . output_translate($tag) . output_newline(); |
|
109 | + $li_text .= "Output: " . output_translate($temp); |
|
110 | + if(KSESTEST_ENV == 'CLI') |
|
111 | + { |
|
112 | + $li_text .= output_newline(); |
|
113 | + } |
|
114 | + |
|
115 | + array_push($out_li, output_code_wrap($li_text)); |
|
116 | + } |
|
117 | + |
|
118 | + $out = array_merge($out, array(output_ul($out_li))); |
|
119 | + array_push($out, output_hr()); |
|
120 | + array_push($out, "Testing is now finished."); |
|
121 | + return $out; |
|
122 | + } |
|
123 | + |
|
124 | + function output_code_wrap($text) |
|
125 | + { |
|
126 | + if(KSESTEST_ENV == 'CLI') |
|
127 | + { |
|
128 | + return $text; |
|
129 | + } |
|
130 | + else |
|
131 | + { |
|
132 | + return "<code>\n$text<code>\n"; |
|
133 | + } |
|
134 | + } |
|
135 | + |
|
136 | + function output_translate($text) |
|
137 | + { |
|
138 | + if(KSESTEST_ENV == 'CLI') |
|
139 | + { |
|
140 | + return $text; |
|
141 | + } |
|
142 | + else |
|
143 | + { |
|
144 | + return htmlentities($text); |
|
145 | + } |
|
146 | + } |
|
147 | + |
|
148 | + function output_testresult($pass = false, $text = "") |
|
149 | + { |
|
150 | + if(KSESTEST_ENV == 'CLI') |
|
151 | + { |
|
152 | + return '[' . $text . ']'; |
|
153 | + } |
|
154 | + else |
|
155 | + { |
|
156 | + if($pass == true) |
|
157 | + { |
|
158 | + return '<span style="color: green;">[' . $text . ']</span>'; |
|
159 | + } |
|
160 | + else |
|
161 | + { |
|
162 | + return '<span style="color: red;">[' . $text . ']</span>'; |
|
163 | + } |
|
164 | + } |
|
165 | + } |
|
166 | + |
|
167 | + function output_spaces() |
|
168 | + { |
|
169 | + if(KSESTEST_ENV == 'WEB') |
|
170 | + { |
|
171 | + $out = " "; |
|
172 | + } |
|
173 | + else |
|
174 | + { |
|
175 | + $out = " "; |
|
176 | + } |
|
177 | + |
|
178 | + return $out; |
|
179 | + } |
|
180 | + |
|
181 | + function output_newline() |
|
182 | + { |
|
183 | + if(KSESTEST_ENV == 'WEB') |
|
184 | + { |
|
185 | + $out = "<br />\n"; |
|
186 | + } |
|
187 | + else |
|
188 | + { |
|
189 | + $out = "\n"; |
|
190 | + } |
|
191 | + |
|
192 | + return $out; |
|
193 | + } |
|
194 | + |
|
195 | + function displayPage($data = array()) |
|
196 | + { |
|
197 | + $title = ($data['title'] == '') ? 'No title' : $data['title']; |
|
198 | + $message = ($data['message'] == '') ? array('No message') : $data['message']; |
|
199 | + |
|
200 | + $out = ""; |
|
201 | + |
|
202 | + foreach($message as $text) |
|
203 | + { |
|
204 | + if(KSESTEST_ENV == 'WEB') |
|
205 | + { |
|
206 | + $header = "\t\t<h1>$title</h1>\n\t\t<hr />\n"; |
|
207 | + $out .= "\t\t<p>\n"; |
|
208 | + $out .= "\t\t\t$text\n"; |
|
209 | + $out .= "\t\t</p>\n"; |
|
210 | + } |
|
211 | + else |
|
212 | + { |
|
213 | + $header = "$title\n" . str_repeat('-', 60) . "\n\n"; |
|
214 | + $out .= "\t$text\n\n"; |
|
215 | + } |
|
216 | + } |
|
217 | + |
|
218 | + if(KSESTEST_ENV == 'WEB') |
|
219 | + { |
|
220 | + echo "<html>\n"; |
|
221 | + echo "\t<head>\n"; |
|
222 | + echo "\t\t<title>$title</title>\n"; |
|
223 | + echo "\t</head>\n"; |
|
224 | + echo "\t<body>\n"; |
|
225 | + echo $header; |
|
226 | + echo $out; |
|
227 | + echo "\t</body>\n"; |
|
228 | + echo "</html>\n"; |
|
229 | + } |
|
230 | + else |
|
231 | + { |
|
232 | + echo $header; |
|
233 | + echo $out; |
|
234 | + } |
|
235 | + } |
|
236 | + |
|
237 | + function output_hr() |
|
238 | + { |
|
239 | + if(KSESTEST_ENV == 'WEB') |
|
240 | + { |
|
241 | + return "\t\t\t<hr />\n"; |
|
242 | + } |
|
243 | + else |
|
244 | + { |
|
245 | + return str_repeat(60, '-') . "\n"; |
|
246 | + } |
|
247 | + } |
|
248 | + |
|
249 | + function output_ul($data = array(), $padding = "") |
|
250 | + { |
|
251 | + if(!is_array($data) || count($data) < 1) |
|
252 | + { |
|
253 | + return ""; |
|
254 | + } |
|
255 | + |
|
256 | + $text = ""; |
|
257 | + if(KSESTEST_ENV == 'WEB') |
|
258 | + { |
|
259 | + $text = "\t\t\t<ul>\n"; |
|
260 | + foreach($data as $li) |
|
261 | + { |
|
262 | + $text .= "\t\t\t\t<li>$li</li>\n"; |
|
263 | + } |
|
264 | + $text .= "\t\t\t</ul>\n"; |
|
265 | + } |
|
266 | + else |
|
267 | + { |
|
268 | + foreach($data as $li) |
|
269 | + { |
|
270 | + $text .= $padding . " * $li\n"; |
|
271 | + } |
|
272 | + } |
|
273 | + |
|
274 | + return $text; |
|
275 | + } |
|
276 | + |
|
277 | + function test1_protocols(&$myKses) |
|
278 | + { |
|
279 | + $default_prots = $myKses->dumpProtocols(); |
|
280 | + $out_text = array(); |
|
281 | + if(count($default_prots) > 0) |
|
282 | + { |
|
283 | + array_push($out_text, "Initial protocols from KSES" . KSESTEST_VER . ":"); |
|
284 | + array_push($out_text, output_ul($default_prots)); |
|
285 | + array_push($out_text, output_hr()); |
|
286 | + } |
|
287 | + |
|
288 | + $myKses->AddProtocols(array("proto1", "proto2:", "proto3")); // Add a list of protocols |
|
289 | + $myKses->AddProtocols("proto4:"); // Add a single protocol (Note ':' is optional at end) |
|
290 | + $myKses->AddProtocol("proto9", "mystery:", "anarchy"); |
|
291 | + $myKses->AddProtocol("alpha", "beta", "gamma:"); |
|
292 | + |
|
293 | + $add_protocol = "\t\t\t<ol>\n"; |
|
294 | + $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocols(array("proto1", "proto2:", "proto3"));</li>' . "\n"; |
|
295 | + $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocols("proto4:");</li>' . "\n"; |
|
296 | + $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocols("proto4:");</li>' . "\n"; |
|
297 | + $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocol("proto9", "mystery:", "anarchy");</li>' . "\n"; |
|
298 | + $add_protocol .= "\t\t\t\t" . '<li>$myKses->AddProtocol("alpha", "beta", "gamma:");</li>' . "\n"; |
|
299 | + $add_protocol .= "\t\t\t</ol>\n"; |
|
300 | + |
|
301 | + array_push($out_text, $add_protocol); |
|
302 | + |
|
303 | + $new_prots = $myKses->dumpProtocols(); |
|
304 | + if(count($new_prots) > 0) |
|
305 | + { |
|
306 | + array_push($out_text, "New protocols from KSES" . KSESTEST_VER . " after using AddProtocol(s):"); |
|
307 | + array_push($out_text, output_ul($new_prots)); |
|
308 | + array_push($out_text, output_hr()); |
|
309 | + } |
|
310 | + |
|
311 | + $myKses->RemoveProtocols(array("mystery", "anarchy:")); |
|
312 | + $myKses->RemoveProtocols("alpha:"); |
|
313 | + $myKses->RemoveProtocol("beta:"); |
|
314 | + $myKses->RemoveProtocol("gamma"); |
|
315 | + |
|
316 | + $remove_protocol = "\t\t\t<ol>\n"; |
|
317 | + $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocols(array("mystery", "anarchy:"));</li>' . "\n"; |
|
318 | + $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocols("alpha:");</li>' . "\n"; |
|
319 | + $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocol("beta:");</li>' . "\n"; |
|
320 | + $remove_protocol .= "\t\t\t\t" . '<li>$myKses->RemoveProtocol("gamma");</li>' . "\n"; |
|
321 | + $remove_protocol .= "\t\t\t</ol>\n"; |
|
322 | + array_push($out_text, $remove_protocol); |
|
323 | + |
|
324 | + $new_prots = $myKses->dumpProtocols(); |
|
325 | + if(count($new_prots) > 0) |
|
326 | + { |
|
327 | + array_push($out_text, "Resulting protocols from KSES" . KSESTEST_VER . " after using RemoveProtocol(s):"); |
|
328 | + array_push($out_text, output_ul($new_prots)); |
|
329 | + array_push($out_text, output_hr()); |
|
330 | + } |
|
331 | + |
|
332 | + $myKses->SetProtocols(array("https", "gopher", "news")); |
|
333 | + $set_protocol = "\t\t\t<ol>\n"; |
|
334 | + $set_protocol .= "\t\t\t\t" . '<li>$myKses->SetProtocols(array("https", "gopher", "news"));</li>' . "\n"; |
|
335 | + $set_protocol .= "\t\t\t</ol>\n"; |
|
336 | + array_push($out_text, $set_protocol); |
|
337 | + |
|
338 | + $new_prots = $myKses->dumpProtocols(); |
|
339 | + if(count($new_prots) > 0) |
|
340 | + { |
|
341 | + array_push($out_text, "Resulting protocols from KSES" . KSESTEST_VER . " after using SetProtocols:"); |
|
342 | + array_push($out_text, output_ul($new_prots)); |
|
343 | + array_push($out_text, output_hr()); |
|
344 | + } |
|
345 | + |
|
346 | + // Invisible reset |
|
347 | + $myKses->SetProtocols(array("http", "proto1", "proto2", "proto9")); |
|
348 | + |
|
349 | + return $out_text; |
|
350 | + } |
|
351 | + |
|
352 | + function test1_html(&$myKses) |
|
353 | + { |
|
354 | + $out = array(); |
|
355 | + |
|
356 | + // Allows <p>|</p> tag |
|
357 | + $myKses->AddHTML("p"); |
|
358 | + |
|
359 | + // Allows 'a' tag with href|name attributes, |
|
360 | + // href has minlen of 10 chars, and maxlen of 25 chars |
|
361 | + // name has minlen of 2 chars |
|
362 | + $myKses->AddHTML( |
|
363 | + "a", |
|
364 | + array( |
|
365 | + "href" => array('maxlen' => 25, 'minlen' => 10), |
|
366 | + "name" => array('minlen' => 2) |
|
367 | + ) |
|
368 | + ); |
|
369 | + |
|
370 | + // Allows 'td' tag with colspan|rowspan|class|style|width|nowrap attributes, |
|
371 | + // colspan has minval of 2 and maxval of 5 |
|
372 | + // rowspan has minval of 3 and maxval of 6 |
|
373 | + // class has minlen of 1 char and maxlen of 10 chars |
|
374 | + // style has minlen of 10 chars and maxlen of 100 chars |
|
375 | + // width has maxval of 100 |
|
376 | + // nowrap is valueless |
|
377 | + $myKses->AddHTML( |
|
378 | + "td", |
|
379 | + array( |
|
380 | + "colspan" => array('minval' => 2, 'maxval' => 5), |
|
381 | + "rowspan" => array('minval' => 3, 'maxval' => 6), |
|
382 | + "class" => array("minlen" => 1, 'maxlen' => 10), |
|
383 | + "width" => array("maxval" => 100), |
|
384 | + "style" => array('minlen' => 10, 'maxlen' => 100), |
|
385 | + "nowrap" => array('valueless' => 'y') |
|
386 | + ) |
|
387 | + ); |
|
388 | + |
|
389 | + array_push($out, "Modifying HTML Tests:"); |
|
390 | + $code_text = "<pre>\n"; |
|
391 | + $code_text .= " // Allows <p>|</p> tag\n"; |
|
392 | + $code_text .= " \$myKses->AddHTML(\"p\");\n"; |
|
393 | + $code_text .= "\n"; |
|
394 | + $code_text .= " // Allows 'a' tag with href|name attributes,\n"; |
|
395 | + $code_text .= " // href has minlen of 10 chars, and maxlen of 25 chars\n"; |
|
396 | + $code_text .= " // name has minlen of 2 chars\n"; |
|
397 | + $code_text .= " \$myKses->AddHTML(\n"; |
|
398 | + $code_text .= " \"a\",\n"; |
|
399 | + $code_text .= " array(\n"; |
|
400 | + $code_text .= " \"href\" => array('maxlen' => 25, 'minlen' => 10),\n"; |
|
401 | + $code_text .= " \"name\" => array('minlen' => 2)\n"; |
|
402 | + $code_text .= " )\n"; |
|
403 | + $code_text .= " );\n"; |
|
404 | + $code_text .= "\n"; |
|
405 | + $code_text .= " // Allows 'td' tag with colspan|rowspan|class|style|width|nowrap attributes,\n"; |
|
406 | + $code_text .= " // colspan has minval of 2 and maxval of 5\n"; |
|
407 | + $code_text .= " // rowspan has minval of 3 and maxval of 6\n"; |
|
408 | + $code_text .= " // class has minlen of 1 char and maxlen of 10 chars\n"; |
|
409 | + $code_text .= " // style has minlen of 10 chars and maxlen of 100 chars\n"; |
|
410 | + $code_text .= " // width has maxval of 100\n"; |
|
411 | + $code_text .= " // nowrap is valueless\n"; |
|
412 | + $code_text .= " \$myKses->AddHTML(\n"; |
|
413 | + $code_text .= " \"td\",\n"; |
|
414 | + $code_text .= " array(\n"; |
|
415 | + $code_text .= " \"colspan\" => array('minval' => 2, 'maxval' => 5),\n"; |
|
416 | + $code_text .= " \"rowspan\" => array('minval' => 3, 'maxval' => 6),\n"; |
|
417 | + $code_text .= " \"class\" => array(\"minlen\" => 1, 'maxlen' => 10),\n"; |
|
418 | + $code_text .= " \"width\" => array(\"maxval\" => 100),\n"; |
|
419 | + $code_text .= " \"style\" => array('minlen' => 10, 'maxlen' => 100),\n"; |
|
420 | + $code_text .= " \"nowrap\" => array('valueless' => 'y')\n"; |
|
421 | + $code_text .= " )\n"; |
|
422 | + $code_text .= " );\n"; |
|
423 | + $code_text .= "</pre>\n"; |
|
424 | + |
|
425 | + array_push($out, $code_text); |
|
426 | + array_push($out, output_hr()); |
|
427 | + array_push($out, "Net results:"); |
|
428 | + |
|
429 | + $out_elems = $myKses->DumpElements(); |
|
430 | + if(count($out_elems) > 0) |
|
431 | + { |
|
432 | + //array_push($out, "\t\t\t<ul>\n"); |
|
433 | + foreach($out_elems as $tag => $attr_data) |
|
434 | + { |
|
435 | + $out_li_elems = array(); |
|
436 | + $elem_text = "(X)HTML element $tag"; |
|
437 | + $allow = ""; |
|
438 | + if(isset($attr_data) && is_array($attr_data) && count($attr_data) > 0) |
|
439 | + { |
|
440 | + $allow = " allows attribute"; |
|
441 | + if(count($attr_data) > 1) |
|
442 | + { |
|
443 | + $allow .= "s"; |
|
444 | + } |
|
445 | + $allow .= ":\n"; |
|
446 | + } |
|
447 | + |
|
448 | + array_push($out_li_elems, "$elem_text$allow"); |
|
449 | + |
|
450 | + $attr_test_li = array(); |
|
451 | + if(isset($attr_data) && is_array($attr_data) && count($attr_data) > 0) |
|
452 | + { |
|
453 | + foreach($attr_data as $attr_name => $attr_tests) |
|
454 | + { |
|
455 | + $li_text = $attr_name; |
|
456 | + if(isset($attr_tests) && count($attr_tests) > 0) |
|
457 | + { |
|
458 | + foreach($attr_tests as $test_name => $test_val) |
|
459 | + { |
|
460 | + switch($test_name) |
|
461 | + { |
|
462 | + case "maxlen": |
|
463 | + $li_text .= " - maximum length of '" . $test_val . "' characters"; |
|
464 | + break; |
|
465 | + case "minlen": |
|
466 | + $li_text .= " - minimum length of '" . $test_val . "' characters"; |
|
467 | + break; |
|
468 | + case "minval": |
|
469 | + $li_text .= " - minimum value of '" . $test_val . "'"; |
|
470 | + break; |
|
471 | + case "maxval": |
|
472 | + $li_text .= " - maximum value of '" . $test_val . "'"; |
|
473 | + break; |
|
474 | + case "valueless": |
|
475 | + switch(strtolower($test_val)) |
|
476 | + { |
|
477 | + case 'n': |
|
478 | + $li_text .= " - must not be valueless"; |
|
479 | + break; |
|
480 | + case 'y': |
|
481 | + $li_text .= " - must be valueless"; |
|
482 | + break; |
|
483 | + default: |
|
484 | + break; |
|
485 | + } |
|
486 | + break; |
|
487 | + default: |
|
488 | + break; |
|
489 | + } |
|
490 | + } |
|
491 | + } |
|
492 | + array_push($attr_test_li, $li_text); |
|
493 | + } |
|
494 | + if(count($attr_test_li) > 0) |
|
495 | + { |
|
496 | + $attr_test_li = output_ul($attr_test_li, " "); |
|
497 | + $out_li_elems = array("$elem_text$allow$attr_test_li"); |
|
498 | + } |
|
499 | + } |
|
500 | + $out = array_merge($out, $out_li_elems); |
|
501 | + } |
|
502 | + } |
|
503 | + |
|
504 | + return $out; |
|
505 | + } |
|
506 | 506 | |
507 | 507 | ?> |
508 | 508 | \ No newline at end of file |
@@ -1,5 +1,5 @@ discard block |
||
1 | 1 | <?php |
2 | - /* |
|
2 | + /* |
|
3 | 3 | * ========================================================================================== |
4 | 4 | * |
5 | 5 | * This program is free software and open source software; you can redistribute |
@@ -20,1143 +20,1143 @@ discard block |
||
20 | 20 | * ========================================================================================== |
21 | 21 | */ |
22 | 22 | |
23 | - /** |
|
24 | - * Class file for PHP4 OOP version of kses |
|
25 | - * |
|
26 | - * This is an updated version of kses to work with PHP4 that works under E_STRICT. |
|
27 | - * |
|
28 | - * This upgrade provides the following: |
|
29 | - * + Version number synced to procedural version number |
|
30 | - * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
31 | - * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
32 | - * + Kses4 now works in E_STRICT |
|
33 | - * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol() and RemoveProtocols() |
|
34 | - * + Deprecated _hook(), Protocols() |
|
35 | - * + Integrated code from kses 0.2.2 into class. |
|
36 | - * + Added methods DumpProtocols(), DumpMethods() |
|
37 | - * |
|
38 | - * @package kses |
|
39 | - * @subpackage kses4 |
|
40 | - */ |
|
41 | - |
|
42 | - if(substr(phpversion(), 0, 1) < 4) |
|
43 | - { |
|
44 | - die("Class kses requires PHP 4 or higher."); |
|
45 | - } |
|
46 | - |
|
47 | - /** |
|
48 | - * Only install KSES4 once |
|
49 | - */ |
|
50 | - if(!defined('KSES_CLASS_PHP4')) |
|
51 | - { |
|
52 | - define('KSES_CLASS_PHP4', true); |
|
53 | - |
|
54 | - /** |
|
55 | - * Kses strips evil scripts! |
|
56 | - * |
|
57 | - * This class provides the capability for removing unwanted HTML/XHTML, attributes from |
|
58 | - * tags, and protocols contained in links. The net result is a much more powerful tool |
|
59 | - * than the PHP internal strip_tags() |
|
60 | - * |
|
61 | - * This is a fork of a slick piece of procedural code called 'kses' written by Ulf Harnhammar |
|
62 | - * The entire set of functions was wrapped in a PHP object with some internal modifications |
|
63 | - * by Richard Vasquez (http://www.chaos.org/) 7/25/2003 |
|
64 | - * |
|
65 | - * This upgrade provides the following: |
|
66 | - * + Version number synced to procedural version number |
|
67 | - * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
68 | - * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
69 | - * + Kses4 now works in E_STRICT |
|
70 | - * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol(), RemoveProtocols() and SetProtocols() |
|
71 | - * + Deprecated _hook(), Protocols() |
|
72 | - * + Integrated code from kses 0.2.2 into class. |
|
73 | - * |
|
74 | - * @author Richard R. V�squez, Jr. (Original procedural code by Ulf H�rnhammar) |
|
75 | - * @link http://sourceforge.net/projects/kses/ Home Page for Kses |
|
76 | - * @link http://chaos.org/contact/ Contact page with current email address for Richard Vasquez |
|
77 | - * @copyright Richard R. V�squez, Jr. 2003-2005 |
|
78 | - * @version PHP4 OOP 0.2.2 |
|
79 | - * @license http://www.gnu.org/licenses/gpl.html GNU Public License |
|
80 | - * @package kses |
|
81 | - */ |
|
82 | - class kses4 |
|
83 | - { |
|
84 | - /**#@+ |
|
23 | + /** |
|
24 | + * Class file for PHP4 OOP version of kses |
|
25 | + * |
|
26 | + * This is an updated version of kses to work with PHP4 that works under E_STRICT. |
|
27 | + * |
|
28 | + * This upgrade provides the following: |
|
29 | + * + Version number synced to procedural version number |
|
30 | + * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
31 | + * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
32 | + * + Kses4 now works in E_STRICT |
|
33 | + * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol() and RemoveProtocols() |
|
34 | + * + Deprecated _hook(), Protocols() |
|
35 | + * + Integrated code from kses 0.2.2 into class. |
|
36 | + * + Added methods DumpProtocols(), DumpMethods() |
|
37 | + * |
|
38 | + * @package kses |
|
39 | + * @subpackage kses4 |
|
40 | + */ |
|
41 | + |
|
42 | + if(substr(phpversion(), 0, 1) < 4) |
|
43 | + { |
|
44 | + die("Class kses requires PHP 4 or higher."); |
|
45 | + } |
|
46 | + |
|
47 | + /** |
|
48 | + * Only install KSES4 once |
|
49 | + */ |
|
50 | + if(!defined('KSES_CLASS_PHP4')) |
|
51 | + { |
|
52 | + define('KSES_CLASS_PHP4', true); |
|
53 | + |
|
54 | + /** |
|
55 | + * Kses strips evil scripts! |
|
56 | + * |
|
57 | + * This class provides the capability for removing unwanted HTML/XHTML, attributes from |
|
58 | + * tags, and protocols contained in links. The net result is a much more powerful tool |
|
59 | + * than the PHP internal strip_tags() |
|
60 | + * |
|
61 | + * This is a fork of a slick piece of procedural code called 'kses' written by Ulf Harnhammar |
|
62 | + * The entire set of functions was wrapped in a PHP object with some internal modifications |
|
63 | + * by Richard Vasquez (http://www.chaos.org/) 7/25/2003 |
|
64 | + * |
|
65 | + * This upgrade provides the following: |
|
66 | + * + Version number synced to procedural version number |
|
67 | + * + PHPdoc style documentation has been added to the class. See http://www.phpdoc.org/ for more info. |
|
68 | + * + Some methods are now deprecated due to nomenclature style change. See method documentation for specifics. |
|
69 | + * + Kses4 now works in E_STRICT |
|
70 | + * + Addition of methods AddProtocols(), filterKsestextHook(), RemoveProtocol(), RemoveProtocols() and SetProtocols() |
|
71 | + * + Deprecated _hook(), Protocols() |
|
72 | + * + Integrated code from kses 0.2.2 into class. |
|
73 | + * |
|
74 | + * @author Richard R. V�squez, Jr. (Original procedural code by Ulf H�rnhammar) |
|
75 | + * @link http://sourceforge.net/projects/kses/ Home Page for Kses |
|
76 | + * @link http://chaos.org/contact/ Contact page with current email address for Richard Vasquez |
|
77 | + * @copyright Richard R. V�squez, Jr. 2003-2005 |
|
78 | + * @version PHP4 OOP 0.2.2 |
|
79 | + * @license http://www.gnu.org/licenses/gpl.html GNU Public License |
|
80 | + * @package kses |
|
81 | + */ |
|
82 | + class kses4 |
|
83 | + { |
|
84 | + /**#@+ |
|
85 | 85 | * @access private |
86 | 86 | * @var array |
87 | 87 | */ |
88 | - var $allowed_protocols = array(); |
|
89 | - var $allowed_html = array(); |
|
90 | - /**#@-*/ |
|
91 | - |
|
92 | - /** |
|
93 | - * Constructor for kses. |
|
94 | - * |
|
95 | - * This sets a default collection of protocols allowed in links, and creates an |
|
96 | - * empty set of allowed HTML tags. |
|
97 | - * @since PHP4 OOP 0.0.1 |
|
98 | - */ |
|
99 | - function kses4() |
|
100 | - { |
|
101 | - /** |
|
102 | - * You could add protocols such as ftp, new, gopher, mailto, irc, etc. |
|
103 | - * |
|
104 | - * The base values the original kses provided were: |
|
105 | - * 'http', 'https', 'ftp', 'news', 'nntp', 'telnet', 'gopher', 'mailto' |
|
106 | - */ |
|
107 | - $this->allowed_protocols = array('http', 'ftp', 'mailto'); |
|
108 | - $this->allowed_html = array(); |
|
109 | - } |
|
110 | - |
|
111 | - /** |
|
112 | - * Basic task of kses - parses $string and strips it as required. |
|
113 | - * |
|
114 | - * This method strips all the disallowed (X)HTML tags, attributes |
|
115 | - * and protocols from the input $string. |
|
116 | - * |
|
117 | - * @access public |
|
118 | - * @param string $string String to be stripped of 'evil scripts' |
|
119 | - * @return string The stripped string |
|
120 | - * @since PHP4 OOP 0.2.1 |
|
121 | - */ |
|
122 | - function Parse($string = "") |
|
123 | - { |
|
124 | - if (get_magic_quotes_gpc()) |
|
125 | - { |
|
126 | - $string = stripslashes($string); |
|
127 | - } |
|
128 | - $string = $this->_no_null($string); |
|
129 | - $string = $this->_js_entities($string); |
|
130 | - $string = $this->_normalize_entities($string); |
|
131 | - $string = $this->filterKsesTextHook($string); |
|
132 | - return $this->_split($string); |
|
133 | - } |
|
134 | - |
|
135 | - /** |
|
136 | - * Allows for single/batch addition of protocols |
|
137 | - * |
|
138 | - * This method accepts one argument that can be either a string |
|
139 | - * or an array of strings. Invalid data will be ignored. |
|
140 | - * |
|
141 | - * The argument will be processed, and each string will be added |
|
142 | - * via AddProtocol(). |
|
143 | - * |
|
144 | - * @access public |
|
145 | - * @param mixed , A string or array of protocols that will be added to the internal list of allowed protocols. |
|
146 | - * @return bool Status of adding valid protocols. |
|
147 | - * @see AddProtocol() |
|
148 | - * @since PHP4 OOP 0.2.1 |
|
149 | - */ |
|
150 | - function AddProtocols() |
|
151 | - { |
|
152 | - $c_args = func_num_args(); |
|
153 | - if($c_args != 1) |
|
154 | - { |
|
155 | - trigger_error("kses4::AddProtocols() did not receive an argument.", E_USER_WARNING); |
|
156 | - return false; |
|
157 | - } |
|
158 | - |
|
159 | - $protocol_data = func_get_arg(0); |
|
160 | - |
|
161 | - if(is_array($protocol_data) && count($protocol_data) > 0) |
|
162 | - { |
|
163 | - foreach($protocol_data as $protocol) |
|
164 | - { |
|
165 | - $this->AddProtocol($protocol); |
|
166 | - } |
|
167 | - return true; |
|
168 | - } |
|
169 | - elseif(is_string($protocol_data)) |
|
170 | - { |
|
171 | - $this->AddProtocol($protocol_data); |
|
172 | - return true; |
|
173 | - } |
|
174 | - else |
|
175 | - { |
|
176 | - trigger_error("kses4::AddProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
177 | - return false; |
|
178 | - } |
|
179 | - } |
|
180 | - |
|
181 | - /** |
|
182 | - * Allows for single/batch addition of protocols |
|
183 | - * |
|
184 | - * @deprecated Use AddProtocols() |
|
185 | - * @see AddProtocols() |
|
186 | - * @return bool |
|
187 | - * @since PHP4 OOP 0.0.1 |
|
188 | - */ |
|
189 | - function Protocols() |
|
190 | - { |
|
191 | - $c_args = func_num_args(); |
|
192 | - if($c_args != 1) |
|
193 | - { |
|
194 | - trigger_error("kses4::Protocols() did not receive an argument.", E_USER_WARNING); |
|
195 | - return false; |
|
196 | - } |
|
197 | - |
|
198 | - return $this->AddProtocols(func_get_arg(0)); |
|
199 | - } |
|
200 | - |
|
201 | - /** |
|
202 | - * Adds a single protocol to $this->allowed_protocols. |
|
203 | - * |
|
204 | - * This method accepts a string argument and adds it to |
|
205 | - * the list of allowed protocols to keep when performing |
|
206 | - * Parse(). |
|
207 | - * |
|
208 | - * @access public |
|
209 | - * @param string $protocol The name of the protocol to be added. |
|
210 | - * @return bool Status of adding valid protocol. |
|
211 | - * @since PHP4 OOP 0.0.1 |
|
212 | - */ |
|
213 | - function AddProtocol($protocol = "") |
|
214 | - { |
|
215 | - if(!is_string($protocol)) |
|
216 | - { |
|
217 | - trigger_error("kses4::AddProtocol() requires a string.", E_USER_WARNING); |
|
218 | - return false; |
|
219 | - } |
|
220 | - |
|
221 | - $protocol = strtolower(trim($protocol)); |
|
222 | - if($protocol == "") |
|
223 | - { |
|
224 | - trigger_error("kses4::AddProtocol() tried to add an empty/NULL protocol.", E_USER_WARNING); |
|
225 | - return false; |
|
226 | - } |
|
227 | - |
|
228 | - // Remove any inadvertent ':' at the end of the protocol. |
|
229 | - if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
230 | - { |
|
231 | - $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
232 | - } |
|
233 | - |
|
234 | - if(!in_array($protocol, $this->allowed_protocols)) |
|
235 | - { |
|
236 | - array_push($this->allowed_protocols, $protocol); |
|
237 | - sort($this->allowed_protocols); |
|
238 | - } |
|
239 | - return true; |
|
240 | - } |
|
241 | - |
|
242 | - /** |
|
243 | - * Allows for single/batch replacement of protocols |
|
244 | - * |
|
245 | - * This method accepts one argument that can be either a string |
|
246 | - * or an array of strings. Invalid data will be ignored. |
|
247 | - * |
|
248 | - * Existing protocols will be removed, then the argument will be |
|
249 | - * processed, and each string will be added via AddProtocol(). |
|
250 | - * |
|
251 | - * @access public |
|
252 | - * @param mixed , A string or array of protocols that will be the new internal list of allowed protocols. |
|
253 | - * @return bool Status of replacing valid protocols. |
|
254 | - * @since PHP4 OOP 0.2.2 |
|
255 | - * @see AddProtocol() |
|
256 | - */ |
|
257 | - function SetProtocols() |
|
258 | - { |
|
259 | - $c_args = func_num_args(); |
|
260 | - if($c_args != 1) |
|
261 | - { |
|
262 | - trigger_error("kses4::SetProtocols() did not receive an argument.", E_USER_WARNING); |
|
263 | - return false; |
|
264 | - } |
|
265 | - |
|
266 | - $protocol_data = func_get_arg(0); |
|
267 | - |
|
268 | - if(is_array($protocol_data) && count($protocol_data) > 0) |
|
269 | - { |
|
270 | - $this->allowed_protocols = array(); |
|
271 | - foreach($protocol_data as $protocol) |
|
272 | - { |
|
273 | - $this->AddProtocol($protocol); |
|
274 | - } |
|
275 | - return true; |
|
276 | - } |
|
277 | - elseif(is_string($protocol_data)) |
|
278 | - { |
|
279 | - $this->allowed_protocols = array(); |
|
280 | - $this->AddProtocol($protocol_data); |
|
281 | - return true; |
|
282 | - } |
|
283 | - else |
|
284 | - { |
|
285 | - trigger_error("kses4::SetProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
286 | - return false; |
|
287 | - } |
|
288 | - } |
|
289 | - |
|
290 | - /** |
|
291 | - * Raw dump of allowed protocols |
|
292 | - * |
|
293 | - * This returns an indexed array of allowed protocols for a particular KSES |
|
294 | - * instantiation. |
|
295 | - * |
|
296 | - * @access public |
|
297 | - * @return array The list of allowed protocols. |
|
298 | - * @since PHP4 OOP 0.2.2 |
|
299 | - */ |
|
300 | - function DumpProtocols() |
|
301 | - { |
|
302 | - return $this->allowed_protocols; |
|
303 | - } |
|
304 | - |
|
305 | - /** |
|
306 | - * Raw dump of allowed (X)HTML elements |
|
307 | - * |
|
308 | - * This returns an indexed array of allowed (X)HTML elements and attributes |
|
309 | - * for a particular KSES instantiation. |
|
310 | - * |
|
311 | - * @access public |
|
312 | - * @return array The list of allowed elements. |
|
313 | - * @since PHP4 OOP 0.2.2 |
|
314 | - */ |
|
315 | - function DumpElements() |
|
316 | - { |
|
317 | - return $this->allowed_html; |
|
318 | - } |
|
319 | - |
|
320 | - /** |
|
321 | - * Adds valid (X)HTML with corresponding attributes that will be kept when stripping 'evil scripts'. |
|
322 | - * |
|
323 | - * This method accepts one argument that can be either a string |
|
324 | - * or an array of strings. Invalid data will be ignored. |
|
325 | - * |
|
326 | - * @access public |
|
327 | - * @param string $tag (X)HTML tag that will be allowed after stripping text. |
|
328 | - * @param array $attribs Associative array of allowed attributes - key => attribute name - value => attribute parameter |
|
329 | - * @return bool Status of Adding (X)HTML and attributes. |
|
330 | - * @since PHP4 OOP 0.0.1 |
|
331 | - */ |
|
332 | - function AddHTML($tag = "", $attribs = array()) |
|
333 | - { |
|
334 | - if(!is_string($tag)) |
|
335 | - { |
|
336 | - trigger_error("kses4::AddHTML() requires the tag to be a string", E_USER_WARNING); |
|
337 | - return false; |
|
338 | - } |
|
339 | - |
|
340 | - $tag = strtolower(trim($tag)); |
|
341 | - if($tag == "") |
|
342 | - { |
|
343 | - trigger_error("kses4::AddHTML() tried to add an empty/NULL tag", E_USER_WARNING); |
|
344 | - return false; |
|
345 | - } |
|
346 | - |
|
347 | - if(!is_array($attribs)) |
|
348 | - { |
|
349 | - trigger_error("kses4::AddHTML() requires an array (even an empty one) of attributes for '$tag'", E_USER_WARNING); |
|
350 | - return false; |
|
351 | - } |
|
352 | - |
|
353 | - $new_attribs = array(); |
|
354 | - if(is_array($attribs) && count($attribs) > 0) |
|
355 | - { |
|
356 | - foreach($attribs as $idx1 => $val1) |
|
357 | - { |
|
358 | - $new_idx1 = strtolower($idx1); |
|
359 | - $new_val1 = $attribs[$idx1]; |
|
360 | - |
|
361 | - if(is_array($new_val1) && count($new_val1) > 0) |
|
362 | - { |
|
363 | - $tmp_val = array(); |
|
364 | - foreach($new_val1 as $idx2 => $val2) |
|
365 | - { |
|
366 | - $new_idx2 = strtolower($idx2); |
|
367 | - $tmp_val[$new_idx2] = $val2; |
|
368 | - } |
|
369 | - $new_val1 = $tmp_val; |
|
370 | - } |
|
371 | - |
|
372 | - $new_attribs[$new_idx1] = $new_val1; |
|
373 | - } |
|
374 | - } |
|
375 | - |
|
376 | - $this->allowed_html[$tag] = $new_attribs; |
|
377 | - return true; |
|
378 | - } |
|
379 | - |
|
380 | - /** |
|
381 | - * Removes a single protocol from $this->allowed_protocols. |
|
382 | - * |
|
383 | - * This method accepts a string argument and removes it from |
|
384 | - * the list of allowed protocols to keep when performing |
|
385 | - * Parse(). |
|
386 | - * |
|
387 | - * @access public |
|
388 | - * @param string $protocol The name of the protocol to be removed. |
|
389 | - * @return bool Status of removing valid protocol. |
|
390 | - * @since PHP4 OOP 0.2.1 |
|
391 | - */ |
|
392 | - function RemoveProtocol($protocol = "") |
|
393 | - { |
|
394 | - if(!is_string($protocol)) |
|
395 | - { |
|
396 | - trigger_error("kses4::RemoveProtocol() requires a string.", E_USER_WARNING); |
|
397 | - return false; |
|
398 | - } |
|
399 | - |
|
400 | - // Remove any inadvertent ':' at the end of the protocol. |
|
401 | - if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
402 | - { |
|
403 | - $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
404 | - } |
|
405 | - |
|
406 | - $protocol = strtolower(trim($protocol)); |
|
407 | - if($protocol == "") |
|
408 | - { |
|
409 | - trigger_error("kses4::RemoveProtocol() tried to remove an empty/NULL protocol.", E_USER_WARNING); |
|
410 | - return false; |
|
411 | - } |
|
412 | - |
|
413 | - // Ensures that the protocol exists before removing it. |
|
414 | - if(in_array($protocol, $this->allowed_protocols)) |
|
415 | - { |
|
416 | - $this->allowed_protocols = array_diff($this->allowed_protocols, array($protocol)); |
|
417 | - sort($this->allowed_protocols); |
|
418 | - } |
|
419 | - |
|
420 | - return true; |
|
421 | - } |
|
422 | - |
|
423 | - /** |
|
424 | - * Allows for single/batch removal of protocols |
|
425 | - * |
|
426 | - * This method accepts one argument that can be either a string |
|
427 | - * or an array of strings. Invalid data will be ignored. |
|
428 | - * |
|
429 | - * The argument will be processed, and each string will be removed |
|
430 | - * via RemoveProtocol(). |
|
431 | - * |
|
432 | - * @access public |
|
433 | - * @param mixed , A string or array of protocols that will be removed from the internal list of allowed protocols. |
|
434 | - * @return bool Status of removing valid protocols. |
|
435 | - * @see RemoveProtocol() |
|
436 | - * @since PHP5 OOP 0.2.1 |
|
437 | - */ |
|
438 | - function RemoveProtocols() |
|
439 | - { |
|
440 | - $c_args = func_num_args(); |
|
441 | - if($c_args != 1) |
|
442 | - { |
|
443 | - return false; |
|
444 | - } |
|
445 | - |
|
446 | - $protocol_data = func_get_arg(0); |
|
447 | - |
|
448 | - if(is_array($protocol_data) && count($protocol_data) > 0) |
|
449 | - { |
|
450 | - foreach($protocol_data as $protocol) |
|
451 | - { |
|
452 | - $this->RemoveProtocol($protocol); |
|
453 | - } |
|
454 | - } |
|
455 | - elseif(is_string($protocol_data)) |
|
456 | - { |
|
457 | - $this->RemoveProtocol($protocol_data); |
|
458 | - return true; |
|
459 | - } |
|
460 | - else |
|
461 | - { |
|
462 | - trigger_error("kses4::RemoveProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
463 | - return false; |
|
464 | - } |
|
465 | - } |
|
466 | - |
|
467 | - /** |
|
468 | - * This method removes any NULL or characters in $string. |
|
469 | - * |
|
470 | - * @access private |
|
471 | - * @param string $string |
|
472 | - * @return string String without any NULL/chr(173) |
|
473 | - * @since PHP4 OOP 0.0.1 |
|
474 | - */ |
|
475 | - function _no_null($string) |
|
476 | - { |
|
477 | - $string = preg_replace('/\0+/', '', $string); |
|
478 | - $string = preg_replace('/(\\\\0)+/', '', $string); |
|
479 | - return $string; |
|
480 | - } |
|
481 | - |
|
482 | - /** |
|
483 | - * This function removes the HTML JavaScript entities found in early versions of |
|
484 | - * Netscape 4. |
|
485 | - * |
|
486 | - * @access private |
|
487 | - * @param string $string |
|
488 | - * @return string String without any NULL/chr(173) |
|
489 | - * @since PHP4 OOP 0.0.1 |
|
490 | - */ |
|
491 | - function _js_entities($string) |
|
492 | - { |
|
493 | - return preg_replace('%&\s*\{[^}]*(\}\s*;?|$)%', '', $string); |
|
494 | - } |
|
495 | - |
|
496 | - /** |
|
497 | - * Normalizes HTML entities |
|
498 | - * |
|
499 | - * This function normalizes HTML entities. It will convert "AT&T" to the correct |
|
500 | - * "AT&T", ":" to ":", "&#XYZZY;" to "&#XYZZY;" and so on. |
|
501 | - * |
|
502 | - * @access private |
|
503 | - * @param string $string |
|
504 | - * @return string String with normalized entities |
|
505 | - * @since PHP4 OOP 0.0.1 |
|
506 | - */ |
|
507 | - function _normalize_entities($string) |
|
508 | - { |
|
509 | - # Disarm all entities by converting & to & |
|
510 | - $string = str_replace('&', '&', $string); |
|
511 | - |
|
512 | - # Change back the allowed entities in our entity white list |
|
513 | - |
|
514 | - $string = preg_replace('/&([A-Za-z][A-Za-z0-9]{0,19});/', '&\\1;', $string); |
|
515 | - $string = preg_replace('/&#0*([0-9]{1,5});/e', '\$this->_normalize_entities2("\\1")', $string); |
|
516 | - $string = preg_replace('/&#([Xx])0*(([0-9A-Fa-f]{2}){1,2});/', '&#\\1\\2;', $string); |
|
517 | - |
|
518 | - return $string; |
|
519 | - } |
|
520 | - |
|
521 | - /** |
|
522 | - * Helper method used by normalizeEntites() |
|
523 | - * |
|
524 | - * This method helps normalizeEntities() to only accept 16 bit values |
|
525 | - * and nothing more for &#number; entities. |
|
526 | - * |
|
527 | - * This method helps normalize_entities() during a preg_replace() |
|
528 | - * where a &#(0)*XXXXX; occurs. The '(0)*XXXXXX' value is converted to |
|
529 | - * a number and the result is returned as a numeric entity if the number |
|
530 | - * is less than 65536. Otherwise, the value is returned 'as is'. |
|
531 | - * |
|
532 | - * @access private |
|
533 | - * @param string $i |
|
534 | - * @return string Normalized numeric entity |
|
535 | - * @see _normalize_entities() |
|
536 | - * @since PHP4 OOP 0.0.1 |
|
537 | - */ |
|
538 | - function _normalize_entities2($i) |
|
539 | - { |
|
540 | - return (($i > 65535) ? "&#$i;" : "&#$i;"); |
|
541 | - } |
|
542 | - |
|
543 | - /** |
|
544 | - * Allows for additional user defined modifications to text. |
|
545 | - * |
|
546 | - * @deprecated use filterKsesTextHook() |
|
547 | - * @param string $string |
|
548 | - * @see filterKsesTextHook() |
|
549 | - * @return string |
|
550 | - * @since PHP4 OOP 0.0.1 |
|
551 | - */ |
|
552 | - function _hook($string) |
|
553 | - { |
|
554 | - return $this->filterKsesTextHook($string); |
|
555 | - } |
|
556 | - |
|
557 | - /** |
|
558 | - * Allows for additional user defined modifications to text. |
|
559 | - * |
|
560 | - * This method allows for additional modifications to be performed on |
|
561 | - * a string that's being run through Parse(). Currently, it returns the |
|
562 | - * input string 'as is'. |
|
563 | - * |
|
564 | - * This method is provided for users to extend the kses class for their own |
|
565 | - * requirements. |
|
566 | - * |
|
567 | - * @access public |
|
568 | - * @param string $string String to perfrom additional modifications on. |
|
569 | - * @return string User modified string. |
|
570 | - * @see Parse() |
|
571 | - * @since PHP5 OOP 1.0.0 |
|
572 | - */ |
|
573 | - function filterKsesTextHook($string) |
|
574 | - { |
|
575 | - return $string; |
|
576 | - } |
|
577 | - |
|
578 | - /** |
|
579 | - * This method goes through an array, and changes the keys to all lower case. |
|
580 | - * |
|
581 | - * @access private |
|
582 | - * @param array $in_array Associative array |
|
583 | - * @return array Modified array |
|
584 | - * @since PHP4 OOP 0.0.1 |
|
585 | - */ |
|
586 | - function _array_lc($inarray) |
|
587 | - { |
|
588 | - $outarray = array(); |
|
589 | - |
|
590 | - if(is_array($inarray) && count($inarray) > 0) |
|
591 | - { |
|
592 | - foreach ($inarray as $inkey => $inval) |
|
593 | - { |
|
594 | - $outkey = strtolower($inkey); |
|
595 | - $outarray[$outkey] = array(); |
|
596 | - |
|
597 | - if(is_array($inval) && count($inval) > 0) |
|
598 | - { |
|
599 | - foreach ($inval as $inkey2 => $inval2) |
|
600 | - { |
|
601 | - $outkey2 = strtolower($inkey2); |
|
602 | - $outarray[$outkey][$outkey2] = $inval2; |
|
603 | - } |
|
604 | - } |
|
605 | - } |
|
606 | - } |
|
607 | - |
|
608 | - return $outarray; |
|
609 | - } |
|
610 | - |
|
611 | - /** |
|
612 | - * This method searched for HTML tags, no matter how malformed. It also |
|
613 | - * matches stray ">" characters. |
|
614 | - * |
|
615 | - * @access private |
|
616 | - * @param string $string |
|
617 | - * @return string HTML tags |
|
618 | - * @since PHP4 OOP 0.0.1 |
|
619 | - */ |
|
620 | - function _split($string) |
|
621 | - { |
|
622 | - return preg_replace( |
|
623 | - '%(<'. # EITHER: < |
|
624 | - '[^>]*'. # things that aren't > |
|
625 | - '(>|$)'. # > or end of string |
|
626 | - '|>)%e', # OR: just a > |
|
627 | - "\$this->_split2('\\1')", |
|
628 | - $string); |
|
629 | - } |
|
630 | - |
|
631 | - /** |
|
632 | - * This method strips out disallowed and/or mangled (X)HTML tags along with assigned attributes. |
|
633 | - * |
|
634 | - * This method does a lot of work. It rejects some very malformed things |
|
635 | - * like <:::>. It returns an empty string if the element isn't allowed (look |
|
636 | - * ma, no strip_tags()!). Otherwise it splits the tag into an element and an |
|
637 | - * allowed attribute list. |
|
638 | - * |
|
639 | - * @access private |
|
640 | - * @param string $string |
|
641 | - * @return string Modified string minus disallowed/mangled (X)HTML and attributes |
|
642 | - * @since PHP4 OOP 0.0.1 |
|
643 | - */ |
|
644 | - function _split2($string) |
|
645 | - { |
|
646 | - $string = $this->_stripslashes($string); |
|
647 | - |
|
648 | - if (substr($string, 0, 1) != '<') |
|
649 | - { |
|
650 | - # It matched a ">" character |
|
651 | - return '>'; |
|
652 | - } |
|
653 | - |
|
654 | - if (!preg_match('%^<\s*(/\s*)?([a-zA-Z0-9]+)([^>]*)>?$%', $string, $matches)) |
|
655 | - { |
|
656 | - # It's seriously malformed |
|
657 | - return ''; |
|
658 | - } |
|
659 | - |
|
660 | - $slash = trim($matches[1]); |
|
661 | - $elem = $matches[2]; |
|
662 | - $attrlist = $matches[3]; |
|
663 | - |
|
664 | - if ( |
|
665 | - !isset($this->allowed_html[strtolower($elem)]) || |
|
666 | - !is_array($this->allowed_html[strtolower($elem)]) |
|
667 | - ) |
|
668 | - { |
|
669 | - # They are using a not allowed HTML element |
|
670 | - return ''; |
|
671 | - } |
|
672 | - |
|
673 | - if ($slash != '') |
|
674 | - { |
|
675 | - return "<$slash$elem>"; |
|
676 | - } |
|
677 | - # No attributes are allowed for closing elements |
|
678 | - |
|
679 | - return $this->_attr("$slash$elem", $attrlist); |
|
680 | - } |
|
681 | - |
|
682 | - /** |
|
683 | - * This method strips out disallowed attributes for (X)HTML tags. |
|
684 | - * |
|
685 | - * This method removes all attributes if none are allowed for this element. |
|
686 | - * If some are allowed it calls $this->_hair() to split them further, and then it |
|
687 | - * builds up new HTML code from the data that $this->_hair() returns. It also |
|
688 | - * removes "<" and ">" characters, if there are any left. One more thing it |
|
689 | - * does is to check if the tag has a closing XHTML slash, and if it does, |
|
690 | - * it puts one in the returned code as well. |
|
691 | - * |
|
692 | - * @access private |
|
693 | - * @param string $element (X)HTML tag to check |
|
694 | - * @param string $attr Text containing attributes to check for validity. |
|
695 | - * @return string Resulting valid (X)HTML or '' |
|
696 | - * @see _hair() |
|
697 | - * @since PHP4 OOP 0.0.1 |
|
698 | - */ |
|
699 | - function _attr($element, $attr) |
|
700 | - { |
|
701 | - # Is there a closing XHTML slash at the end of the attributes? |
|
702 | - $xhtml_slash = ''; |
|
703 | - if (preg_match('%\s/\s*$%', $attr)) |
|
704 | - { |
|
705 | - $xhtml_slash = ' /'; |
|
706 | - } |
|
707 | - |
|
708 | - # Are any attributes allowed at all for this element? |
|
709 | - if ( |
|
710 | - !isset($this->allowed_html[strtolower($element)]) || |
|
711 | - count($this->allowed_html[strtolower($element)]) == 0 |
|
712 | - ) |
|
713 | - { |
|
714 | - return "<$element$xhtml_slash>"; |
|
715 | - } |
|
716 | - |
|
717 | - # Split it |
|
718 | - $attrarr = $this->_hair($attr); |
|
719 | - |
|
720 | - # Go through $attrarr, and save the allowed attributes for this element |
|
721 | - # in $attr2 |
|
722 | - $attr2 = ''; |
|
723 | - if(is_array($attrarr) && count($attrarr) > 0) |
|
724 | - { |
|
725 | - foreach ($attrarr as $arreach) |
|
726 | - { |
|
727 | - if(!isset($this->allowed_html[strtolower($element)][strtolower($arreach['name'])])) |
|
728 | - { |
|
729 | - continue; |
|
730 | - } |
|
731 | - |
|
732 | - $current = $this->allowed_html[strtolower($element)][strtolower($arreach['name'])]; |
|
733 | - if ($current == '') |
|
734 | - { |
|
735 | - # the attribute is not allowed |
|
736 | - continue; |
|
737 | - } |
|
738 | - |
|
739 | - if (!is_array($current)) |
|
740 | - { |
|
741 | - # there are no checks |
|
742 | - $attr2 .= ' '.$arreach['whole']; |
|
743 | - } |
|
744 | - else |
|
745 | - { |
|
746 | - # there are some checks |
|
747 | - $ok = true; |
|
748 | - if(is_array($current) && count($current) > 0) |
|
749 | - { |
|
750 | - foreach ($current as $currkey => $currval) |
|
751 | - { |
|
752 | - if (!$this->_check_attr_val($arreach['value'], $arreach['vless'], $currkey, $currval)) |
|
753 | - { |
|
754 | - $ok = false; |
|
755 | - break; |
|
756 | - } |
|
757 | - } |
|
758 | - |
|
759 | - if ($ok) |
|
760 | - { |
|
761 | - # it passed them |
|
762 | - $attr2 .= ' '.$arreach['whole']; |
|
763 | - } |
|
764 | - } |
|
765 | - } |
|
766 | - } |
|
767 | - } |
|
768 | - |
|
769 | - # Remove any "<" or ">" characters |
|
770 | - $attr2 = preg_replace('/[<>]/', '', $attr2); |
|
771 | - return "<$element$attr2$xhtml_slash>"; |
|
772 | - } |
|
773 | - |
|
774 | - /** |
|
775 | - * This method combs through an attribute list string and returns an associative array of attributes and values. |
|
776 | - * |
|
777 | - * This method does a lot of work. It parses an attribute list into an array |
|
778 | - * with attribute data, and tries to do the right thing even if it gets weird |
|
779 | - * input. It will add quotes around attribute values that don't have any quotes |
|
780 | - * or apostrophes around them, to make it easier to produce HTML code that will |
|
781 | - * conform to W3C's HTML specification. It will also remove bad URL protocols |
|
782 | - * from attribute values. |
|
783 | - * |
|
784 | - * @access private |
|
785 | - * @param string $attr Text containing tag attributes for parsing |
|
786 | - * @return array Associative array containing data on attribute and value |
|
787 | - * @since PHP4 OOP 0.0.1 |
|
788 | - */ |
|
789 | - function _hair($attr) |
|
790 | - { |
|
791 | - $attrarr = array(); |
|
792 | - $mode = 0; |
|
793 | - $attrname = ''; |
|
794 | - |
|
795 | - # Loop through the whole attribute list |
|
796 | - |
|
797 | - while (strlen($attr) != 0) |
|
798 | - { |
|
799 | - # Was the last operation successful? |
|
800 | - $working = 0; |
|
801 | - |
|
802 | - switch ($mode) |
|
803 | - { |
|
804 | - case 0: # attribute name, href for instance |
|
805 | - if (preg_match('/^([-a-zA-Z]+)/', $attr, $match)) |
|
806 | - { |
|
807 | - $attrname = $match[1]; |
|
808 | - $working = $mode = 1; |
|
809 | - $attr = preg_replace('/^[-a-zA-Z]+/', '', $attr); |
|
810 | - } |
|
811 | - break; |
|
812 | - case 1: # equals sign or valueless ("selected") |
|
813 | - if (preg_match('/^\s*=\s*/', $attr)) # equals sign |
|
814 | - { |
|
815 | - $working = 1; |
|
816 | - $mode = 2; |
|
817 | - $attr = preg_replace('/^\s*=\s*/', '', $attr); |
|
818 | - break; |
|
819 | - } |
|
820 | - if (preg_match('/^\s+/', $attr)) # valueless |
|
821 | - { |
|
822 | - $working = 1; |
|
823 | - $mode = 0; |
|
824 | - $attrarr[] = array( |
|
825 | - 'name' => $attrname, |
|
826 | - 'value' => '', |
|
827 | - 'whole' => $attrname, |
|
828 | - 'vless' => 'y' |
|
829 | - ); |
|
830 | - $attr = preg_replace('/^\s+/', '', $attr); |
|
831 | - } |
|
832 | - break; |
|
833 | - case 2: # attribute value, a URL after href= for instance |
|
834 | - if (preg_match('/^"([^"]*)"(\s+|$)/', $attr, $match)) # "value" |
|
835 | - { |
|
836 | - $thisval = $this->_bad_protocol($match[1]); |
|
837 | - $attrarr[] = array( |
|
838 | - 'name' => $attrname, |
|
839 | - 'value' => $thisval, |
|
840 | - 'whole' => "$attrname=\"$thisval\"", |
|
841 | - 'vless' => 'n' |
|
842 | - ); |
|
843 | - $working = 1; |
|
844 | - $mode = 0; |
|
845 | - $attr = preg_replace('/^"[^"]*"(\s+|$)/', '', $attr); |
|
846 | - break; |
|
847 | - } |
|
848 | - if (preg_match("/^'([^']*)'(\s+|$)/", $attr, $match)) # 'value' |
|
849 | - { |
|
850 | - $thisval = $this->_bad_protocol($match[1]); |
|
851 | - $attrarr[] = array( |
|
852 | - 'name' => $attrname, |
|
853 | - 'value' => $thisval, |
|
854 | - 'whole' => "$attrname='$thisval'", |
|
855 | - 'vless' => 'n' |
|
856 | - ); |
|
857 | - $working = 1; |
|
858 | - $mode = 0; |
|
859 | - $attr = preg_replace("/^'[^']*'(\s+|$)/", '', $attr); |
|
860 | - break; |
|
861 | - } |
|
862 | - if (preg_match("%^([^\s\"']+)(\s+|$)%", $attr, $match)) # value |
|
863 | - { |
|
864 | - $thisval = $this->_bad_protocol($match[1]); |
|
865 | - $attrarr[] = array( |
|
866 | - 'name' => $attrname, |
|
867 | - 'value' => $thisval, |
|
868 | - 'whole' => "$attrname=\"$thisval\"", |
|
869 | - 'vless' => 'n' |
|
870 | - ); |
|
871 | - # We add quotes to conform to W3C's HTML spec. |
|
872 | - $working = 1; |
|
873 | - $mode = 0; |
|
874 | - $attr = preg_replace("%^[^\s\"']+(\s+|$)%", '', $attr); |
|
875 | - } |
|
876 | - break; |
|
877 | - } |
|
878 | - |
|
879 | - if ($working == 0) # not well formed, remove and try again |
|
880 | - { |
|
881 | - $attr = $this->_html_error($attr); |
|
882 | - $mode = 0; |
|
883 | - } |
|
884 | - } |
|
885 | - |
|
886 | - # special case, for when the attribute list ends with a valueless |
|
887 | - # attribute like "selected" |
|
888 | - if ($mode == 1) |
|
889 | - { |
|
890 | - $attrarr[] = array( |
|
891 | - 'name' => $attrname, |
|
892 | - 'value' => '', |
|
893 | - 'whole' => $attrname, |
|
894 | - 'vless' => 'y' |
|
895 | - ); |
|
896 | - } |
|
897 | - |
|
898 | - return $attrarr; |
|
899 | - } |
|
900 | - |
|
901 | - /** |
|
902 | - * This method removes disallowed protocols. |
|
903 | - * |
|
904 | - * This method removes all non-allowed protocols from the beginning of |
|
905 | - * $string. It ignores whitespace and the case of the letters, and it does |
|
906 | - * understand HTML entities. It does its work in a while loop, so it won't be |
|
907 | - * fooled by a string like "javascript:javascript:alert(57)". |
|
908 | - * |
|
909 | - * @access private |
|
910 | - * @param string $string String to check for protocols |
|
911 | - * @return string String with removed protocols |
|
912 | - * @since PHP4 OOP 0.0.1 |
|
913 | - */ |
|
914 | - function _bad_protocol($string) |
|
915 | - { |
|
916 | - $string = $this->_no_null($string); |
|
917 | - $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
918 | - $string2 = $string.'a'; |
|
919 | - |
|
920 | - while ($string != $string2) |
|
921 | - { |
|
922 | - $string2 = $string; |
|
923 | - $string = $this->_bad_protocol_once($string); |
|
924 | - } # while |
|
925 | - |
|
926 | - return $string; |
|
927 | - } |
|
928 | - |
|
929 | - /** |
|
930 | - * Helper method used by _bad_protocol() |
|
931 | - * |
|
932 | - * This function searches for URL protocols at the beginning of $string, while |
|
933 | - * handling whitespace and HTML entities. |
|
934 | - * Function updated to fix security vulnerability (see http://projects.dokeos.com/index.php?do=details&task_id=2312) |
|
935 | - * |
|
936 | - * @access private |
|
937 | - * @param string $string String to check for protocols |
|
938 | - * @return string String with removed protocols |
|
939 | - * @see _bad_protocol() |
|
940 | - * @since PHP4 OOP 0.0.1 |
|
941 | - */ |
|
942 | - function _bad_protocol_once($string) |
|
943 | - { |
|
944 | - $string2 = preg_split('/:|:|:/i', $string, 2); |
|
945 | - if(isset($string2[1]) && !preg_match('%/\?%',$string2[0])) |
|
946 | - { |
|
947 | - $string = $this->_bad_protocol_once2($string2[0]).trim($string2[1]); |
|
948 | - } |
|
949 | - return $string; |
|
950 | - } |
|
951 | - /** |
|
952 | - * Helper method used by _bad_protocol_once() regex |
|
953 | - * |
|
954 | - * This function processes URL protocols, checks to see if they're in the white- |
|
955 | - * list or not, and returns different data depending on the answer. |
|
956 | - * |
|
957 | - * @access private |
|
958 | - * @param string $string String to check for protocols |
|
959 | - * @return string String with removed protocols |
|
960 | - * @see _bad_protocol() |
|
961 | - * @see _bad_protocol_once() |
|
962 | - * @since PHP4 OOP 0.0.1 |
|
963 | - */ |
|
964 | - function _bad_protocol_once2($string) |
|
965 | - { |
|
966 | - $string = $this->_decode_entities($string); |
|
967 | - $string = preg_replace('/\s/', '', $string); |
|
968 | - $string = $this->_no_null($string); |
|
969 | - $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
970 | - $string = strtolower($string); |
|
971 | - |
|
972 | - $allowed = false; |
|
973 | - if(is_array($this->allowed_protocols) && count($this->allowed_protocols) > 0) |
|
974 | - { |
|
975 | - foreach ($this->allowed_protocols as $one_protocol) |
|
976 | - { |
|
977 | - if (strtolower($one_protocol) == $string) |
|
978 | - { |
|
979 | - $allowed = true; |
|
980 | - break; |
|
981 | - } |
|
982 | - } |
|
983 | - } |
|
984 | - |
|
985 | - if ($allowed) |
|
986 | - { |
|
987 | - return "$string:"; |
|
988 | - } |
|
989 | - else |
|
990 | - { |
|
991 | - return ''; |
|
992 | - } |
|
993 | - } |
|
994 | - |
|
995 | - /** |
|
996 | - * This function performs different checks for attribute values. |
|
997 | - * |
|
998 | - * The currently implemented checks are "maxlen", "minlen", "maxval", |
|
999 | - * "minval" and "valueless" with even more checks to come soon. |
|
1000 | - * |
|
1001 | - * @access private |
|
1002 | - * @param string $value The value of the attribute to be checked. |
|
1003 | - * @param string $vless Indicates whether the the value is supposed to be valueless |
|
1004 | - * @param string $checkname The check to be performed |
|
1005 | - * @param string $checkvalue The value that is to be checked against |
|
1006 | - * @return bool Indicates whether the check passed or not |
|
1007 | - * @since PHP4 OOP 0.0.1 |
|
1008 | - */ |
|
1009 | - function _check_attr_val($value, $vless, $checkname, $checkvalue) |
|
1010 | - { |
|
1011 | - $ok = true; |
|
1012 | - |
|
1013 | - switch (strtolower($checkname)) |
|
1014 | - { |
|
1015 | - /** |
|
1016 | - * The maxlen check makes sure that the attribute value has a length not |
|
1017 | - * greater than the given value. This can be used to avoid Buffer Overflows |
|
1018 | - * in WWW clients and various Internet servers. |
|
1019 | - */ |
|
1020 | - case 'maxlen': |
|
1021 | - if (strlen($value) > $checkvalue) |
|
1022 | - { |
|
1023 | - $ok = false; |
|
1024 | - } |
|
1025 | - break; |
|
1026 | - |
|
1027 | - /** |
|
1028 | - * The minlen check makes sure that the attribute value has a length not |
|
1029 | - * smaller than the given value. |
|
1030 | - */ |
|
1031 | - case 'minlen': |
|
1032 | - if (strlen($value) < $checkvalue) |
|
1033 | - { |
|
1034 | - $ok = false; |
|
1035 | - } |
|
1036 | - break; |
|
1037 | - |
|
1038 | - /** |
|
1039 | - * The maxval check does two things: it checks that the attribute value is |
|
1040 | - * an integer from 0 and up, without an excessive amount of zeroes or |
|
1041 | - * whitespace (to avoid Buffer Overflows). It also checks that the attribute |
|
1042 | - * value is not greater than the given value. |
|
1043 | - * This check can be used to avoid Denial of Service attacks. |
|
1044 | - */ |
|
1045 | - case 'maxval': |
|
1046 | - if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1047 | - { |
|
1048 | - $ok = false; |
|
1049 | - } |
|
1050 | - if ($value > $checkvalue) |
|
1051 | - { |
|
1052 | - $ok = false; |
|
1053 | - } |
|
1054 | - break; |
|
1055 | - |
|
1056 | - /** |
|
1057 | - * The minval check checks that the attribute value is a positive integer, |
|
1058 | - * and that it is not smaller than the given value. |
|
1059 | - */ |
|
1060 | - case 'minval': |
|
1061 | - if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1062 | - { |
|
1063 | - $ok = false; |
|
1064 | - } |
|
1065 | - if ($value < $checkvalue) |
|
1066 | - { |
|
1067 | - $ok = false; |
|
1068 | - } |
|
1069 | - break; |
|
1070 | - |
|
1071 | - /** |
|
1072 | - * The valueless check checks if the attribute has a value |
|
1073 | - * (like <a href="blah">) or not (<option selected>). If the given value |
|
1074 | - * is a "y" or a "Y", the attribute must not have a value. |
|
1075 | - * If the given value is an "n" or an "N", the attribute must have one. |
|
1076 | - */ |
|
1077 | - case 'valueless': |
|
1078 | - if (strtolower($checkvalue) != $vless) |
|
1079 | - { |
|
1080 | - $ok = false; |
|
1081 | - } |
|
1082 | - break; |
|
1083 | - |
|
1084 | - } |
|
1085 | - |
|
1086 | - return $ok; |
|
1087 | - } |
|
1088 | - |
|
1089 | - /** |
|
1090 | - * Changes \" to " |
|
1091 | - * |
|
1092 | - * This function changes the character sequence \" to just " |
|
1093 | - * It leaves all other slashes alone. It's really weird, but the quoting from |
|
1094 | - * preg_replace(//e) seems to require this. |
|
1095 | - * |
|
1096 | - * @access private |
|
1097 | - * @param string $string The string to be stripped. |
|
1098 | - * @return string string stripped of \" |
|
1099 | - * @since PHP4 OOP 0.0.1 |
|
1100 | - */ |
|
1101 | - function _stripslashes($string) |
|
1102 | - { |
|
1103 | - return preg_replace('%\\\\"%', '"', $string); |
|
1104 | - } |
|
1105 | - |
|
1106 | - /** |
|
1107 | - * helper method for _hair() |
|
1108 | - * |
|
1109 | - * This function deals with parsing errors in _hair(). The general plan is |
|
1110 | - * to remove everything to and including some whitespace, but it deals with |
|
1111 | - * quotes and apostrophes as well. |
|
1112 | - * |
|
1113 | - * @access private |
|
1114 | - * @param string $string The string to be stripped. |
|
1115 | - * @return string string stripped of whitespace |
|
1116 | - * @see _hair() |
|
1117 | - * @since PHP4 OOP 0.0.1 |
|
1118 | - */ |
|
1119 | - function _html_error($string) |
|
1120 | - { |
|
1121 | - return preg_replace('/^("[^"]*("|$)|\'[^\']*(\'|$)|\S)*\s*/', '', $string); |
|
1122 | - } |
|
1123 | - |
|
1124 | - /** |
|
1125 | - * Decodes numeric HTML entities |
|
1126 | - * |
|
1127 | - * This method decodes numeric HTML entities (A and A). It doesn't |
|
1128 | - * do anything with other entities like ä, but we don't need them in the |
|
1129 | - * URL protocol white listing system anyway. |
|
1130 | - * |
|
1131 | - * @access private |
|
1132 | - * @param string $value The entitiy to be decoded. |
|
1133 | - * @return string Decoded entity |
|
1134 | - * @since PHP4 OOP 0.0.1 |
|
1135 | - */ |
|
1136 | - function _decode_entities($string) |
|
1137 | - { |
|
1138 | - $string = preg_replace('/&#([0-9]+);/e', 'chr("\\1")', $string); |
|
1139 | - $string = preg_replace('/&#[Xx]([0-9A-Fa-f]+);/e', 'chr(hexdec("\\1"))', $string); |
|
1140 | - return $string; |
|
1141 | - } |
|
1142 | - |
|
1143 | - /** |
|
1144 | - * Returns PHP4 OOP version # of kses. |
|
1145 | - * |
|
1146 | - * Since this class has been refactored and documented and proven to work, |
|
1147 | - * I'm syncing the version number to procedural kses. |
|
1148 | - * |
|
1149 | - * @access public |
|
1150 | - * @return string Version number |
|
1151 | - * @since PHP4 OOP 0.0.1 |
|
1152 | - */ |
|
1153 | - function _version() |
|
1154 | - { |
|
1155 | - return 'PHP4 0.2.2 (OOP fork of procedural kses 0.2.2)'; |
|
1156 | - } |
|
1157 | - } |
|
1158 | - |
|
1159 | - |
|
1160 | - |
|
1161 | - } |
|
88 | + var $allowed_protocols = array(); |
|
89 | + var $allowed_html = array(); |
|
90 | + /**#@-*/ |
|
91 | + |
|
92 | + /** |
|
93 | + * Constructor for kses. |
|
94 | + * |
|
95 | + * This sets a default collection of protocols allowed in links, and creates an |
|
96 | + * empty set of allowed HTML tags. |
|
97 | + * @since PHP4 OOP 0.0.1 |
|
98 | + */ |
|
99 | + function kses4() |
|
100 | + { |
|
101 | + /** |
|
102 | + * You could add protocols such as ftp, new, gopher, mailto, irc, etc. |
|
103 | + * |
|
104 | + * The base values the original kses provided were: |
|
105 | + * 'http', 'https', 'ftp', 'news', 'nntp', 'telnet', 'gopher', 'mailto' |
|
106 | + */ |
|
107 | + $this->allowed_protocols = array('http', 'ftp', 'mailto'); |
|
108 | + $this->allowed_html = array(); |
|
109 | + } |
|
110 | + |
|
111 | + /** |
|
112 | + * Basic task of kses - parses $string and strips it as required. |
|
113 | + * |
|
114 | + * This method strips all the disallowed (X)HTML tags, attributes |
|
115 | + * and protocols from the input $string. |
|
116 | + * |
|
117 | + * @access public |
|
118 | + * @param string $string String to be stripped of 'evil scripts' |
|
119 | + * @return string The stripped string |
|
120 | + * @since PHP4 OOP 0.2.1 |
|
121 | + */ |
|
122 | + function Parse($string = "") |
|
123 | + { |
|
124 | + if (get_magic_quotes_gpc()) |
|
125 | + { |
|
126 | + $string = stripslashes($string); |
|
127 | + } |
|
128 | + $string = $this->_no_null($string); |
|
129 | + $string = $this->_js_entities($string); |
|
130 | + $string = $this->_normalize_entities($string); |
|
131 | + $string = $this->filterKsesTextHook($string); |
|
132 | + return $this->_split($string); |
|
133 | + } |
|
134 | + |
|
135 | + /** |
|
136 | + * Allows for single/batch addition of protocols |
|
137 | + * |
|
138 | + * This method accepts one argument that can be either a string |
|
139 | + * or an array of strings. Invalid data will be ignored. |
|
140 | + * |
|
141 | + * The argument will be processed, and each string will be added |
|
142 | + * via AddProtocol(). |
|
143 | + * |
|
144 | + * @access public |
|
145 | + * @param mixed , A string or array of protocols that will be added to the internal list of allowed protocols. |
|
146 | + * @return bool Status of adding valid protocols. |
|
147 | + * @see AddProtocol() |
|
148 | + * @since PHP4 OOP 0.2.1 |
|
149 | + */ |
|
150 | + function AddProtocols() |
|
151 | + { |
|
152 | + $c_args = func_num_args(); |
|
153 | + if($c_args != 1) |
|
154 | + { |
|
155 | + trigger_error("kses4::AddProtocols() did not receive an argument.", E_USER_WARNING); |
|
156 | + return false; |
|
157 | + } |
|
158 | + |
|
159 | + $protocol_data = func_get_arg(0); |
|
160 | + |
|
161 | + if(is_array($protocol_data) && count($protocol_data) > 0) |
|
162 | + { |
|
163 | + foreach($protocol_data as $protocol) |
|
164 | + { |
|
165 | + $this->AddProtocol($protocol); |
|
166 | + } |
|
167 | + return true; |
|
168 | + } |
|
169 | + elseif(is_string($protocol_data)) |
|
170 | + { |
|
171 | + $this->AddProtocol($protocol_data); |
|
172 | + return true; |
|
173 | + } |
|
174 | + else |
|
175 | + { |
|
176 | + trigger_error("kses4::AddProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
177 | + return false; |
|
178 | + } |
|
179 | + } |
|
180 | + |
|
181 | + /** |
|
182 | + * Allows for single/batch addition of protocols |
|
183 | + * |
|
184 | + * @deprecated Use AddProtocols() |
|
185 | + * @see AddProtocols() |
|
186 | + * @return bool |
|
187 | + * @since PHP4 OOP 0.0.1 |
|
188 | + */ |
|
189 | + function Protocols() |
|
190 | + { |
|
191 | + $c_args = func_num_args(); |
|
192 | + if($c_args != 1) |
|
193 | + { |
|
194 | + trigger_error("kses4::Protocols() did not receive an argument.", E_USER_WARNING); |
|
195 | + return false; |
|
196 | + } |
|
197 | + |
|
198 | + return $this->AddProtocols(func_get_arg(0)); |
|
199 | + } |
|
200 | + |
|
201 | + /** |
|
202 | + * Adds a single protocol to $this->allowed_protocols. |
|
203 | + * |
|
204 | + * This method accepts a string argument and adds it to |
|
205 | + * the list of allowed protocols to keep when performing |
|
206 | + * Parse(). |
|
207 | + * |
|
208 | + * @access public |
|
209 | + * @param string $protocol The name of the protocol to be added. |
|
210 | + * @return bool Status of adding valid protocol. |
|
211 | + * @since PHP4 OOP 0.0.1 |
|
212 | + */ |
|
213 | + function AddProtocol($protocol = "") |
|
214 | + { |
|
215 | + if(!is_string($protocol)) |
|
216 | + { |
|
217 | + trigger_error("kses4::AddProtocol() requires a string.", E_USER_WARNING); |
|
218 | + return false; |
|
219 | + } |
|
220 | + |
|
221 | + $protocol = strtolower(trim($protocol)); |
|
222 | + if($protocol == "") |
|
223 | + { |
|
224 | + trigger_error("kses4::AddProtocol() tried to add an empty/NULL protocol.", E_USER_WARNING); |
|
225 | + return false; |
|
226 | + } |
|
227 | + |
|
228 | + // Remove any inadvertent ':' at the end of the protocol. |
|
229 | + if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
230 | + { |
|
231 | + $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
232 | + } |
|
233 | + |
|
234 | + if(!in_array($protocol, $this->allowed_protocols)) |
|
235 | + { |
|
236 | + array_push($this->allowed_protocols, $protocol); |
|
237 | + sort($this->allowed_protocols); |
|
238 | + } |
|
239 | + return true; |
|
240 | + } |
|
241 | + |
|
242 | + /** |
|
243 | + * Allows for single/batch replacement of protocols |
|
244 | + * |
|
245 | + * This method accepts one argument that can be either a string |
|
246 | + * or an array of strings. Invalid data will be ignored. |
|
247 | + * |
|
248 | + * Existing protocols will be removed, then the argument will be |
|
249 | + * processed, and each string will be added via AddProtocol(). |
|
250 | + * |
|
251 | + * @access public |
|
252 | + * @param mixed , A string or array of protocols that will be the new internal list of allowed protocols. |
|
253 | + * @return bool Status of replacing valid protocols. |
|
254 | + * @since PHP4 OOP 0.2.2 |
|
255 | + * @see AddProtocol() |
|
256 | + */ |
|
257 | + function SetProtocols() |
|
258 | + { |
|
259 | + $c_args = func_num_args(); |
|
260 | + if($c_args != 1) |
|
261 | + { |
|
262 | + trigger_error("kses4::SetProtocols() did not receive an argument.", E_USER_WARNING); |
|
263 | + return false; |
|
264 | + } |
|
265 | + |
|
266 | + $protocol_data = func_get_arg(0); |
|
267 | + |
|
268 | + if(is_array($protocol_data) && count($protocol_data) > 0) |
|
269 | + { |
|
270 | + $this->allowed_protocols = array(); |
|
271 | + foreach($protocol_data as $protocol) |
|
272 | + { |
|
273 | + $this->AddProtocol($protocol); |
|
274 | + } |
|
275 | + return true; |
|
276 | + } |
|
277 | + elseif(is_string($protocol_data)) |
|
278 | + { |
|
279 | + $this->allowed_protocols = array(); |
|
280 | + $this->AddProtocol($protocol_data); |
|
281 | + return true; |
|
282 | + } |
|
283 | + else |
|
284 | + { |
|
285 | + trigger_error("kses4::SetProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
286 | + return false; |
|
287 | + } |
|
288 | + } |
|
289 | + |
|
290 | + /** |
|
291 | + * Raw dump of allowed protocols |
|
292 | + * |
|
293 | + * This returns an indexed array of allowed protocols for a particular KSES |
|
294 | + * instantiation. |
|
295 | + * |
|
296 | + * @access public |
|
297 | + * @return array The list of allowed protocols. |
|
298 | + * @since PHP4 OOP 0.2.2 |
|
299 | + */ |
|
300 | + function DumpProtocols() |
|
301 | + { |
|
302 | + return $this->allowed_protocols; |
|
303 | + } |
|
304 | + |
|
305 | + /** |
|
306 | + * Raw dump of allowed (X)HTML elements |
|
307 | + * |
|
308 | + * This returns an indexed array of allowed (X)HTML elements and attributes |
|
309 | + * for a particular KSES instantiation. |
|
310 | + * |
|
311 | + * @access public |
|
312 | + * @return array The list of allowed elements. |
|
313 | + * @since PHP4 OOP 0.2.2 |
|
314 | + */ |
|
315 | + function DumpElements() |
|
316 | + { |
|
317 | + return $this->allowed_html; |
|
318 | + } |
|
319 | + |
|
320 | + /** |
|
321 | + * Adds valid (X)HTML with corresponding attributes that will be kept when stripping 'evil scripts'. |
|
322 | + * |
|
323 | + * This method accepts one argument that can be either a string |
|
324 | + * or an array of strings. Invalid data will be ignored. |
|
325 | + * |
|
326 | + * @access public |
|
327 | + * @param string $tag (X)HTML tag that will be allowed after stripping text. |
|
328 | + * @param array $attribs Associative array of allowed attributes - key => attribute name - value => attribute parameter |
|
329 | + * @return bool Status of Adding (X)HTML and attributes. |
|
330 | + * @since PHP4 OOP 0.0.1 |
|
331 | + */ |
|
332 | + function AddHTML($tag = "", $attribs = array()) |
|
333 | + { |
|
334 | + if(!is_string($tag)) |
|
335 | + { |
|
336 | + trigger_error("kses4::AddHTML() requires the tag to be a string", E_USER_WARNING); |
|
337 | + return false; |
|
338 | + } |
|
339 | + |
|
340 | + $tag = strtolower(trim($tag)); |
|
341 | + if($tag == "") |
|
342 | + { |
|
343 | + trigger_error("kses4::AddHTML() tried to add an empty/NULL tag", E_USER_WARNING); |
|
344 | + return false; |
|
345 | + } |
|
346 | + |
|
347 | + if(!is_array($attribs)) |
|
348 | + { |
|
349 | + trigger_error("kses4::AddHTML() requires an array (even an empty one) of attributes for '$tag'", E_USER_WARNING); |
|
350 | + return false; |
|
351 | + } |
|
352 | + |
|
353 | + $new_attribs = array(); |
|
354 | + if(is_array($attribs) && count($attribs) > 0) |
|
355 | + { |
|
356 | + foreach($attribs as $idx1 => $val1) |
|
357 | + { |
|
358 | + $new_idx1 = strtolower($idx1); |
|
359 | + $new_val1 = $attribs[$idx1]; |
|
360 | + |
|
361 | + if(is_array($new_val1) && count($new_val1) > 0) |
|
362 | + { |
|
363 | + $tmp_val = array(); |
|
364 | + foreach($new_val1 as $idx2 => $val2) |
|
365 | + { |
|
366 | + $new_idx2 = strtolower($idx2); |
|
367 | + $tmp_val[$new_idx2] = $val2; |
|
368 | + } |
|
369 | + $new_val1 = $tmp_val; |
|
370 | + } |
|
371 | + |
|
372 | + $new_attribs[$new_idx1] = $new_val1; |
|
373 | + } |
|
374 | + } |
|
375 | + |
|
376 | + $this->allowed_html[$tag] = $new_attribs; |
|
377 | + return true; |
|
378 | + } |
|
379 | + |
|
380 | + /** |
|
381 | + * Removes a single protocol from $this->allowed_protocols. |
|
382 | + * |
|
383 | + * This method accepts a string argument and removes it from |
|
384 | + * the list of allowed protocols to keep when performing |
|
385 | + * Parse(). |
|
386 | + * |
|
387 | + * @access public |
|
388 | + * @param string $protocol The name of the protocol to be removed. |
|
389 | + * @return bool Status of removing valid protocol. |
|
390 | + * @since PHP4 OOP 0.2.1 |
|
391 | + */ |
|
392 | + function RemoveProtocol($protocol = "") |
|
393 | + { |
|
394 | + if(!is_string($protocol)) |
|
395 | + { |
|
396 | + trigger_error("kses4::RemoveProtocol() requires a string.", E_USER_WARNING); |
|
397 | + return false; |
|
398 | + } |
|
399 | + |
|
400 | + // Remove any inadvertent ':' at the end of the protocol. |
|
401 | + if(substr($protocol, strlen($protocol) - 1, 1) == ":") |
|
402 | + { |
|
403 | + $protocol = substr($protocol, 0, strlen($protocol) - 1); |
|
404 | + } |
|
405 | + |
|
406 | + $protocol = strtolower(trim($protocol)); |
|
407 | + if($protocol == "") |
|
408 | + { |
|
409 | + trigger_error("kses4::RemoveProtocol() tried to remove an empty/NULL protocol.", E_USER_WARNING); |
|
410 | + return false; |
|
411 | + } |
|
412 | + |
|
413 | + // Ensures that the protocol exists before removing it. |
|
414 | + if(in_array($protocol, $this->allowed_protocols)) |
|
415 | + { |
|
416 | + $this->allowed_protocols = array_diff($this->allowed_protocols, array($protocol)); |
|
417 | + sort($this->allowed_protocols); |
|
418 | + } |
|
419 | + |
|
420 | + return true; |
|
421 | + } |
|
422 | + |
|
423 | + /** |
|
424 | + * Allows for single/batch removal of protocols |
|
425 | + * |
|
426 | + * This method accepts one argument that can be either a string |
|
427 | + * or an array of strings. Invalid data will be ignored. |
|
428 | + * |
|
429 | + * The argument will be processed, and each string will be removed |
|
430 | + * via RemoveProtocol(). |
|
431 | + * |
|
432 | + * @access public |
|
433 | + * @param mixed , A string or array of protocols that will be removed from the internal list of allowed protocols. |
|
434 | + * @return bool Status of removing valid protocols. |
|
435 | + * @see RemoveProtocol() |
|
436 | + * @since PHP5 OOP 0.2.1 |
|
437 | + */ |
|
438 | + function RemoveProtocols() |
|
439 | + { |
|
440 | + $c_args = func_num_args(); |
|
441 | + if($c_args != 1) |
|
442 | + { |
|
443 | + return false; |
|
444 | + } |
|
445 | + |
|
446 | + $protocol_data = func_get_arg(0); |
|
447 | + |
|
448 | + if(is_array($protocol_data) && count($protocol_data) > 0) |
|
449 | + { |
|
450 | + foreach($protocol_data as $protocol) |
|
451 | + { |
|
452 | + $this->RemoveProtocol($protocol); |
|
453 | + } |
|
454 | + } |
|
455 | + elseif(is_string($protocol_data)) |
|
456 | + { |
|
457 | + $this->RemoveProtocol($protocol_data); |
|
458 | + return true; |
|
459 | + } |
|
460 | + else |
|
461 | + { |
|
462 | + trigger_error("kses4::RemoveProtocols() did not receive a string or an array.", E_USER_WARNING); |
|
463 | + return false; |
|
464 | + } |
|
465 | + } |
|
466 | + |
|
467 | + /** |
|
468 | + * This method removes any NULL or characters in $string. |
|
469 | + * |
|
470 | + * @access private |
|
471 | + * @param string $string |
|
472 | + * @return string String without any NULL/chr(173) |
|
473 | + * @since PHP4 OOP 0.0.1 |
|
474 | + */ |
|
475 | + function _no_null($string) |
|
476 | + { |
|
477 | + $string = preg_replace('/\0+/', '', $string); |
|
478 | + $string = preg_replace('/(\\\\0)+/', '', $string); |
|
479 | + return $string; |
|
480 | + } |
|
481 | + |
|
482 | + /** |
|
483 | + * This function removes the HTML JavaScript entities found in early versions of |
|
484 | + * Netscape 4. |
|
485 | + * |
|
486 | + * @access private |
|
487 | + * @param string $string |
|
488 | + * @return string String without any NULL/chr(173) |
|
489 | + * @since PHP4 OOP 0.0.1 |
|
490 | + */ |
|
491 | + function _js_entities($string) |
|
492 | + { |
|
493 | + return preg_replace('%&\s*\{[^}]*(\}\s*;?|$)%', '', $string); |
|
494 | + } |
|
495 | + |
|
496 | + /** |
|
497 | + * Normalizes HTML entities |
|
498 | + * |
|
499 | + * This function normalizes HTML entities. It will convert "AT&T" to the correct |
|
500 | + * "AT&T", ":" to ":", "&#XYZZY;" to "&#XYZZY;" and so on. |
|
501 | + * |
|
502 | + * @access private |
|
503 | + * @param string $string |
|
504 | + * @return string String with normalized entities |
|
505 | + * @since PHP4 OOP 0.0.1 |
|
506 | + */ |
|
507 | + function _normalize_entities($string) |
|
508 | + { |
|
509 | + # Disarm all entities by converting & to & |
|
510 | + $string = str_replace('&', '&', $string); |
|
511 | + |
|
512 | + # Change back the allowed entities in our entity white list |
|
513 | + |
|
514 | + $string = preg_replace('/&([A-Za-z][A-Za-z0-9]{0,19});/', '&\\1;', $string); |
|
515 | + $string = preg_replace('/&#0*([0-9]{1,5});/e', '\$this->_normalize_entities2("\\1")', $string); |
|
516 | + $string = preg_replace('/&#([Xx])0*(([0-9A-Fa-f]{2}){1,2});/', '&#\\1\\2;', $string); |
|
517 | + |
|
518 | + return $string; |
|
519 | + } |
|
520 | + |
|
521 | + /** |
|
522 | + * Helper method used by normalizeEntites() |
|
523 | + * |
|
524 | + * This method helps normalizeEntities() to only accept 16 bit values |
|
525 | + * and nothing more for &#number; entities. |
|
526 | + * |
|
527 | + * This method helps normalize_entities() during a preg_replace() |
|
528 | + * where a &#(0)*XXXXX; occurs. The '(0)*XXXXXX' value is converted to |
|
529 | + * a number and the result is returned as a numeric entity if the number |
|
530 | + * is less than 65536. Otherwise, the value is returned 'as is'. |
|
531 | + * |
|
532 | + * @access private |
|
533 | + * @param string $i |
|
534 | + * @return string Normalized numeric entity |
|
535 | + * @see _normalize_entities() |
|
536 | + * @since PHP4 OOP 0.0.1 |
|
537 | + */ |
|
538 | + function _normalize_entities2($i) |
|
539 | + { |
|
540 | + return (($i > 65535) ? "&#$i;" : "&#$i;"); |
|
541 | + } |
|
542 | + |
|
543 | + /** |
|
544 | + * Allows for additional user defined modifications to text. |
|
545 | + * |
|
546 | + * @deprecated use filterKsesTextHook() |
|
547 | + * @param string $string |
|
548 | + * @see filterKsesTextHook() |
|
549 | + * @return string |
|
550 | + * @since PHP4 OOP 0.0.1 |
|
551 | + */ |
|
552 | + function _hook($string) |
|
553 | + { |
|
554 | + return $this->filterKsesTextHook($string); |
|
555 | + } |
|
556 | + |
|
557 | + /** |
|
558 | + * Allows for additional user defined modifications to text. |
|
559 | + * |
|
560 | + * This method allows for additional modifications to be performed on |
|
561 | + * a string that's being run through Parse(). Currently, it returns the |
|
562 | + * input string 'as is'. |
|
563 | + * |
|
564 | + * This method is provided for users to extend the kses class for their own |
|
565 | + * requirements. |
|
566 | + * |
|
567 | + * @access public |
|
568 | + * @param string $string String to perfrom additional modifications on. |
|
569 | + * @return string User modified string. |
|
570 | + * @see Parse() |
|
571 | + * @since PHP5 OOP 1.0.0 |
|
572 | + */ |
|
573 | + function filterKsesTextHook($string) |
|
574 | + { |
|
575 | + return $string; |
|
576 | + } |
|
577 | + |
|
578 | + /** |
|
579 | + * This method goes through an array, and changes the keys to all lower case. |
|
580 | + * |
|
581 | + * @access private |
|
582 | + * @param array $in_array Associative array |
|
583 | + * @return array Modified array |
|
584 | + * @since PHP4 OOP 0.0.1 |
|
585 | + */ |
|
586 | + function _array_lc($inarray) |
|
587 | + { |
|
588 | + $outarray = array(); |
|
589 | + |
|
590 | + if(is_array($inarray) && count($inarray) > 0) |
|
591 | + { |
|
592 | + foreach ($inarray as $inkey => $inval) |
|
593 | + { |
|
594 | + $outkey = strtolower($inkey); |
|
595 | + $outarray[$outkey] = array(); |
|
596 | + |
|
597 | + if(is_array($inval) && count($inval) > 0) |
|
598 | + { |
|
599 | + foreach ($inval as $inkey2 => $inval2) |
|
600 | + { |
|
601 | + $outkey2 = strtolower($inkey2); |
|
602 | + $outarray[$outkey][$outkey2] = $inval2; |
|
603 | + } |
|
604 | + } |
|
605 | + } |
|
606 | + } |
|
607 | + |
|
608 | + return $outarray; |
|
609 | + } |
|
610 | + |
|
611 | + /** |
|
612 | + * This method searched for HTML tags, no matter how malformed. It also |
|
613 | + * matches stray ">" characters. |
|
614 | + * |
|
615 | + * @access private |
|
616 | + * @param string $string |
|
617 | + * @return string HTML tags |
|
618 | + * @since PHP4 OOP 0.0.1 |
|
619 | + */ |
|
620 | + function _split($string) |
|
621 | + { |
|
622 | + return preg_replace( |
|
623 | + '%(<'. # EITHER: < |
|
624 | + '[^>]*'. # things that aren't > |
|
625 | + '(>|$)'. # > or end of string |
|
626 | + '|>)%e', # OR: just a > |
|
627 | + "\$this->_split2('\\1')", |
|
628 | + $string); |
|
629 | + } |
|
630 | + |
|
631 | + /** |
|
632 | + * This method strips out disallowed and/or mangled (X)HTML tags along with assigned attributes. |
|
633 | + * |
|
634 | + * This method does a lot of work. It rejects some very malformed things |
|
635 | + * like <:::>. It returns an empty string if the element isn't allowed (look |
|
636 | + * ma, no strip_tags()!). Otherwise it splits the tag into an element and an |
|
637 | + * allowed attribute list. |
|
638 | + * |
|
639 | + * @access private |
|
640 | + * @param string $string |
|
641 | + * @return string Modified string minus disallowed/mangled (X)HTML and attributes |
|
642 | + * @since PHP4 OOP 0.0.1 |
|
643 | + */ |
|
644 | + function _split2($string) |
|
645 | + { |
|
646 | + $string = $this->_stripslashes($string); |
|
647 | + |
|
648 | + if (substr($string, 0, 1) != '<') |
|
649 | + { |
|
650 | + # It matched a ">" character |
|
651 | + return '>'; |
|
652 | + } |
|
653 | + |
|
654 | + if (!preg_match('%^<\s*(/\s*)?([a-zA-Z0-9]+)([^>]*)>?$%', $string, $matches)) |
|
655 | + { |
|
656 | + # It's seriously malformed |
|
657 | + return ''; |
|
658 | + } |
|
659 | + |
|
660 | + $slash = trim($matches[1]); |
|
661 | + $elem = $matches[2]; |
|
662 | + $attrlist = $matches[3]; |
|
663 | + |
|
664 | + if ( |
|
665 | + !isset($this->allowed_html[strtolower($elem)]) || |
|
666 | + !is_array($this->allowed_html[strtolower($elem)]) |
|
667 | + ) |
|
668 | + { |
|
669 | + # They are using a not allowed HTML element |
|
670 | + return ''; |
|
671 | + } |
|
672 | + |
|
673 | + if ($slash != '') |
|
674 | + { |
|
675 | + return "<$slash$elem>"; |
|
676 | + } |
|
677 | + # No attributes are allowed for closing elements |
|
678 | + |
|
679 | + return $this->_attr("$slash$elem", $attrlist); |
|
680 | + } |
|
681 | + |
|
682 | + /** |
|
683 | + * This method strips out disallowed attributes for (X)HTML tags. |
|
684 | + * |
|
685 | + * This method removes all attributes if none are allowed for this element. |
|
686 | + * If some are allowed it calls $this->_hair() to split them further, and then it |
|
687 | + * builds up new HTML code from the data that $this->_hair() returns. It also |
|
688 | + * removes "<" and ">" characters, if there are any left. One more thing it |
|
689 | + * does is to check if the tag has a closing XHTML slash, and if it does, |
|
690 | + * it puts one in the returned code as well. |
|
691 | + * |
|
692 | + * @access private |
|
693 | + * @param string $element (X)HTML tag to check |
|
694 | + * @param string $attr Text containing attributes to check for validity. |
|
695 | + * @return string Resulting valid (X)HTML or '' |
|
696 | + * @see _hair() |
|
697 | + * @since PHP4 OOP 0.0.1 |
|
698 | + */ |
|
699 | + function _attr($element, $attr) |
|
700 | + { |
|
701 | + # Is there a closing XHTML slash at the end of the attributes? |
|
702 | + $xhtml_slash = ''; |
|
703 | + if (preg_match('%\s/\s*$%', $attr)) |
|
704 | + { |
|
705 | + $xhtml_slash = ' /'; |
|
706 | + } |
|
707 | + |
|
708 | + # Are any attributes allowed at all for this element? |
|
709 | + if ( |
|
710 | + !isset($this->allowed_html[strtolower($element)]) || |
|
711 | + count($this->allowed_html[strtolower($element)]) == 0 |
|
712 | + ) |
|
713 | + { |
|
714 | + return "<$element$xhtml_slash>"; |
|
715 | + } |
|
716 | + |
|
717 | + # Split it |
|
718 | + $attrarr = $this->_hair($attr); |
|
719 | + |
|
720 | + # Go through $attrarr, and save the allowed attributes for this element |
|
721 | + # in $attr2 |
|
722 | + $attr2 = ''; |
|
723 | + if(is_array($attrarr) && count($attrarr) > 0) |
|
724 | + { |
|
725 | + foreach ($attrarr as $arreach) |
|
726 | + { |
|
727 | + if(!isset($this->allowed_html[strtolower($element)][strtolower($arreach['name'])])) |
|
728 | + { |
|
729 | + continue; |
|
730 | + } |
|
731 | + |
|
732 | + $current = $this->allowed_html[strtolower($element)][strtolower($arreach['name'])]; |
|
733 | + if ($current == '') |
|
734 | + { |
|
735 | + # the attribute is not allowed |
|
736 | + continue; |
|
737 | + } |
|
738 | + |
|
739 | + if (!is_array($current)) |
|
740 | + { |
|
741 | + # there are no checks |
|
742 | + $attr2 .= ' '.$arreach['whole']; |
|
743 | + } |
|
744 | + else |
|
745 | + { |
|
746 | + # there are some checks |
|
747 | + $ok = true; |
|
748 | + if(is_array($current) && count($current) > 0) |
|
749 | + { |
|
750 | + foreach ($current as $currkey => $currval) |
|
751 | + { |
|
752 | + if (!$this->_check_attr_val($arreach['value'], $arreach['vless'], $currkey, $currval)) |
|
753 | + { |
|
754 | + $ok = false; |
|
755 | + break; |
|
756 | + } |
|
757 | + } |
|
758 | + |
|
759 | + if ($ok) |
|
760 | + { |
|
761 | + # it passed them |
|
762 | + $attr2 .= ' '.$arreach['whole']; |
|
763 | + } |
|
764 | + } |
|
765 | + } |
|
766 | + } |
|
767 | + } |
|
768 | + |
|
769 | + # Remove any "<" or ">" characters |
|
770 | + $attr2 = preg_replace('/[<>]/', '', $attr2); |
|
771 | + return "<$element$attr2$xhtml_slash>"; |
|
772 | + } |
|
773 | + |
|
774 | + /** |
|
775 | + * This method combs through an attribute list string and returns an associative array of attributes and values. |
|
776 | + * |
|
777 | + * This method does a lot of work. It parses an attribute list into an array |
|
778 | + * with attribute data, and tries to do the right thing even if it gets weird |
|
779 | + * input. It will add quotes around attribute values that don't have any quotes |
|
780 | + * or apostrophes around them, to make it easier to produce HTML code that will |
|
781 | + * conform to W3C's HTML specification. It will also remove bad URL protocols |
|
782 | + * from attribute values. |
|
783 | + * |
|
784 | + * @access private |
|
785 | + * @param string $attr Text containing tag attributes for parsing |
|
786 | + * @return array Associative array containing data on attribute and value |
|
787 | + * @since PHP4 OOP 0.0.1 |
|
788 | + */ |
|
789 | + function _hair($attr) |
|
790 | + { |
|
791 | + $attrarr = array(); |
|
792 | + $mode = 0; |
|
793 | + $attrname = ''; |
|
794 | + |
|
795 | + # Loop through the whole attribute list |
|
796 | + |
|
797 | + while (strlen($attr) != 0) |
|
798 | + { |
|
799 | + # Was the last operation successful? |
|
800 | + $working = 0; |
|
801 | + |
|
802 | + switch ($mode) |
|
803 | + { |
|
804 | + case 0: # attribute name, href for instance |
|
805 | + if (preg_match('/^([-a-zA-Z]+)/', $attr, $match)) |
|
806 | + { |
|
807 | + $attrname = $match[1]; |
|
808 | + $working = $mode = 1; |
|
809 | + $attr = preg_replace('/^[-a-zA-Z]+/', '', $attr); |
|
810 | + } |
|
811 | + break; |
|
812 | + case 1: # equals sign or valueless ("selected") |
|
813 | + if (preg_match('/^\s*=\s*/', $attr)) # equals sign |
|
814 | + { |
|
815 | + $working = 1; |
|
816 | + $mode = 2; |
|
817 | + $attr = preg_replace('/^\s*=\s*/', '', $attr); |
|
818 | + break; |
|
819 | + } |
|
820 | + if (preg_match('/^\s+/', $attr)) # valueless |
|
821 | + { |
|
822 | + $working = 1; |
|
823 | + $mode = 0; |
|
824 | + $attrarr[] = array( |
|
825 | + 'name' => $attrname, |
|
826 | + 'value' => '', |
|
827 | + 'whole' => $attrname, |
|
828 | + 'vless' => 'y' |
|
829 | + ); |
|
830 | + $attr = preg_replace('/^\s+/', '', $attr); |
|
831 | + } |
|
832 | + break; |
|
833 | + case 2: # attribute value, a URL after href= for instance |
|
834 | + if (preg_match('/^"([^"]*)"(\s+|$)/', $attr, $match)) # "value" |
|
835 | + { |
|
836 | + $thisval = $this->_bad_protocol($match[1]); |
|
837 | + $attrarr[] = array( |
|
838 | + 'name' => $attrname, |
|
839 | + 'value' => $thisval, |
|
840 | + 'whole' => "$attrname=\"$thisval\"", |
|
841 | + 'vless' => 'n' |
|
842 | + ); |
|
843 | + $working = 1; |
|
844 | + $mode = 0; |
|
845 | + $attr = preg_replace('/^"[^"]*"(\s+|$)/', '', $attr); |
|
846 | + break; |
|
847 | + } |
|
848 | + if (preg_match("/^'([^']*)'(\s+|$)/", $attr, $match)) # 'value' |
|
849 | + { |
|
850 | + $thisval = $this->_bad_protocol($match[1]); |
|
851 | + $attrarr[] = array( |
|
852 | + 'name' => $attrname, |
|
853 | + 'value' => $thisval, |
|
854 | + 'whole' => "$attrname='$thisval'", |
|
855 | + 'vless' => 'n' |
|
856 | + ); |
|
857 | + $working = 1; |
|
858 | + $mode = 0; |
|
859 | + $attr = preg_replace("/^'[^']*'(\s+|$)/", '', $attr); |
|
860 | + break; |
|
861 | + } |
|
862 | + if (preg_match("%^([^\s\"']+)(\s+|$)%", $attr, $match)) # value |
|
863 | + { |
|
864 | + $thisval = $this->_bad_protocol($match[1]); |
|
865 | + $attrarr[] = array( |
|
866 | + 'name' => $attrname, |
|
867 | + 'value' => $thisval, |
|
868 | + 'whole' => "$attrname=\"$thisval\"", |
|
869 | + 'vless' => 'n' |
|
870 | + ); |
|
871 | + # We add quotes to conform to W3C's HTML spec. |
|
872 | + $working = 1; |
|
873 | + $mode = 0; |
|
874 | + $attr = preg_replace("%^[^\s\"']+(\s+|$)%", '', $attr); |
|
875 | + } |
|
876 | + break; |
|
877 | + } |
|
878 | + |
|
879 | + if ($working == 0) # not well formed, remove and try again |
|
880 | + { |
|
881 | + $attr = $this->_html_error($attr); |
|
882 | + $mode = 0; |
|
883 | + } |
|
884 | + } |
|
885 | + |
|
886 | + # special case, for when the attribute list ends with a valueless |
|
887 | + # attribute like "selected" |
|
888 | + if ($mode == 1) |
|
889 | + { |
|
890 | + $attrarr[] = array( |
|
891 | + 'name' => $attrname, |
|
892 | + 'value' => '', |
|
893 | + 'whole' => $attrname, |
|
894 | + 'vless' => 'y' |
|
895 | + ); |
|
896 | + } |
|
897 | + |
|
898 | + return $attrarr; |
|
899 | + } |
|
900 | + |
|
901 | + /** |
|
902 | + * This method removes disallowed protocols. |
|
903 | + * |
|
904 | + * This method removes all non-allowed protocols from the beginning of |
|
905 | + * $string. It ignores whitespace and the case of the letters, and it does |
|
906 | + * understand HTML entities. It does its work in a while loop, so it won't be |
|
907 | + * fooled by a string like "javascript:javascript:alert(57)". |
|
908 | + * |
|
909 | + * @access private |
|
910 | + * @param string $string String to check for protocols |
|
911 | + * @return string String with removed protocols |
|
912 | + * @since PHP4 OOP 0.0.1 |
|
913 | + */ |
|
914 | + function _bad_protocol($string) |
|
915 | + { |
|
916 | + $string = $this->_no_null($string); |
|
917 | + $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
918 | + $string2 = $string.'a'; |
|
919 | + |
|
920 | + while ($string != $string2) |
|
921 | + { |
|
922 | + $string2 = $string; |
|
923 | + $string = $this->_bad_protocol_once($string); |
|
924 | + } # while |
|
925 | + |
|
926 | + return $string; |
|
927 | + } |
|
928 | + |
|
929 | + /** |
|
930 | + * Helper method used by _bad_protocol() |
|
931 | + * |
|
932 | + * This function searches for URL protocols at the beginning of $string, while |
|
933 | + * handling whitespace and HTML entities. |
|
934 | + * Function updated to fix security vulnerability (see http://projects.dokeos.com/index.php?do=details&task_id=2312) |
|
935 | + * |
|
936 | + * @access private |
|
937 | + * @param string $string String to check for protocols |
|
938 | + * @return string String with removed protocols |
|
939 | + * @see _bad_protocol() |
|
940 | + * @since PHP4 OOP 0.0.1 |
|
941 | + */ |
|
942 | + function _bad_protocol_once($string) |
|
943 | + { |
|
944 | + $string2 = preg_split('/:|:|:/i', $string, 2); |
|
945 | + if(isset($string2[1]) && !preg_match('%/\?%',$string2[0])) |
|
946 | + { |
|
947 | + $string = $this->_bad_protocol_once2($string2[0]).trim($string2[1]); |
|
948 | + } |
|
949 | + return $string; |
|
950 | + } |
|
951 | + /** |
|
952 | + * Helper method used by _bad_protocol_once() regex |
|
953 | + * |
|
954 | + * This function processes URL protocols, checks to see if they're in the white- |
|
955 | + * list or not, and returns different data depending on the answer. |
|
956 | + * |
|
957 | + * @access private |
|
958 | + * @param string $string String to check for protocols |
|
959 | + * @return string String with removed protocols |
|
960 | + * @see _bad_protocol() |
|
961 | + * @see _bad_protocol_once() |
|
962 | + * @since PHP4 OOP 0.0.1 |
|
963 | + */ |
|
964 | + function _bad_protocol_once2($string) |
|
965 | + { |
|
966 | + $string = $this->_decode_entities($string); |
|
967 | + $string = preg_replace('/\s/', '', $string); |
|
968 | + $string = $this->_no_null($string); |
|
969 | + $string = preg_replace('/\xad+/', '', $string); # deals with Opera "feature" |
|
970 | + $string = strtolower($string); |
|
971 | + |
|
972 | + $allowed = false; |
|
973 | + if(is_array($this->allowed_protocols) && count($this->allowed_protocols) > 0) |
|
974 | + { |
|
975 | + foreach ($this->allowed_protocols as $one_protocol) |
|
976 | + { |
|
977 | + if (strtolower($one_protocol) == $string) |
|
978 | + { |
|
979 | + $allowed = true; |
|
980 | + break; |
|
981 | + } |
|
982 | + } |
|
983 | + } |
|
984 | + |
|
985 | + if ($allowed) |
|
986 | + { |
|
987 | + return "$string:"; |
|
988 | + } |
|
989 | + else |
|
990 | + { |
|
991 | + return ''; |
|
992 | + } |
|
993 | + } |
|
994 | + |
|
995 | + /** |
|
996 | + * This function performs different checks for attribute values. |
|
997 | + * |
|
998 | + * The currently implemented checks are "maxlen", "minlen", "maxval", |
|
999 | + * "minval" and "valueless" with even more checks to come soon. |
|
1000 | + * |
|
1001 | + * @access private |
|
1002 | + * @param string $value The value of the attribute to be checked. |
|
1003 | + * @param string $vless Indicates whether the the value is supposed to be valueless |
|
1004 | + * @param string $checkname The check to be performed |
|
1005 | + * @param string $checkvalue The value that is to be checked against |
|
1006 | + * @return bool Indicates whether the check passed or not |
|
1007 | + * @since PHP4 OOP 0.0.1 |
|
1008 | + */ |
|
1009 | + function _check_attr_val($value, $vless, $checkname, $checkvalue) |
|
1010 | + { |
|
1011 | + $ok = true; |
|
1012 | + |
|
1013 | + switch (strtolower($checkname)) |
|
1014 | + { |
|
1015 | + /** |
|
1016 | + * The maxlen check makes sure that the attribute value has a length not |
|
1017 | + * greater than the given value. This can be used to avoid Buffer Overflows |
|
1018 | + * in WWW clients and various Internet servers. |
|
1019 | + */ |
|
1020 | + case 'maxlen': |
|
1021 | + if (strlen($value) > $checkvalue) |
|
1022 | + { |
|
1023 | + $ok = false; |
|
1024 | + } |
|
1025 | + break; |
|
1026 | + |
|
1027 | + /** |
|
1028 | + * The minlen check makes sure that the attribute value has a length not |
|
1029 | + * smaller than the given value. |
|
1030 | + */ |
|
1031 | + case 'minlen': |
|
1032 | + if (strlen($value) < $checkvalue) |
|
1033 | + { |
|
1034 | + $ok = false; |
|
1035 | + } |
|
1036 | + break; |
|
1037 | + |
|
1038 | + /** |
|
1039 | + * The maxval check does two things: it checks that the attribute value is |
|
1040 | + * an integer from 0 and up, without an excessive amount of zeroes or |
|
1041 | + * whitespace (to avoid Buffer Overflows). It also checks that the attribute |
|
1042 | + * value is not greater than the given value. |
|
1043 | + * This check can be used to avoid Denial of Service attacks. |
|
1044 | + */ |
|
1045 | + case 'maxval': |
|
1046 | + if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1047 | + { |
|
1048 | + $ok = false; |
|
1049 | + } |
|
1050 | + if ($value > $checkvalue) |
|
1051 | + { |
|
1052 | + $ok = false; |
|
1053 | + } |
|
1054 | + break; |
|
1055 | + |
|
1056 | + /** |
|
1057 | + * The minval check checks that the attribute value is a positive integer, |
|
1058 | + * and that it is not smaller than the given value. |
|
1059 | + */ |
|
1060 | + case 'minval': |
|
1061 | + if (!preg_match('/^\s{0,6}[0-9]{1,6}\s{0,6}$/', $value)) |
|
1062 | + { |
|
1063 | + $ok = false; |
|
1064 | + } |
|
1065 | + if ($value < $checkvalue) |
|
1066 | + { |
|
1067 | + $ok = false; |
|
1068 | + } |
|
1069 | + break; |
|
1070 | + |
|
1071 | + /** |
|
1072 | + * The valueless check checks if the attribute has a value |
|
1073 | + * (like <a href="blah">) or not (<option selected>). If the given value |
|
1074 | + * is a "y" or a "Y", the attribute must not have a value. |
|
1075 | + * If the given value is an "n" or an "N", the attribute must have one. |
|
1076 | + */ |
|
1077 | + case 'valueless': |
|
1078 | + if (strtolower($checkvalue) != $vless) |
|
1079 | + { |
|
1080 | + $ok = false; |
|
1081 | + } |
|
1082 | + break; |
|
1083 | + |
|
1084 | + } |
|
1085 | + |
|
1086 | + return $ok; |
|
1087 | + } |
|
1088 | + |
|
1089 | + /** |
|
1090 | + * Changes \" to " |
|
1091 | + * |
|
1092 | + * This function changes the character sequence \" to just " |
|
1093 | + * It leaves all other slashes alone. It's really weird, but the quoting from |
|
1094 | + * preg_replace(//e) seems to require this. |
|
1095 | + * |
|
1096 | + * @access private |
|
1097 | + * @param string $string The string to be stripped. |
|
1098 | + * @return string string stripped of \" |
|
1099 | + * @since PHP4 OOP 0.0.1 |
|
1100 | + */ |
|
1101 | + function _stripslashes($string) |
|
1102 | + { |
|
1103 | + return preg_replace('%\\\\"%', '"', $string); |
|
1104 | + } |
|
1105 | + |
|
1106 | + /** |
|
1107 | + * helper method for _hair() |
|
1108 | + * |
|
1109 | + * This function deals with parsing errors in _hair(). The general plan is |
|
1110 | + * to remove everything to and including some whitespace, but it deals with |
|
1111 | + * quotes and apostrophes as well. |
|
1112 | + * |
|
1113 | + * @access private |
|
1114 | + * @param string $string The string to be stripped. |
|
1115 | + * @return string string stripped of whitespace |
|
1116 | + * @see _hair() |
|
1117 | + * @since PHP4 OOP 0.0.1 |
|
1118 | + */ |
|
1119 | + function _html_error($string) |
|
1120 | + { |
|
1121 | + return preg_replace('/^("[^"]*("|$)|\'[^\']*(\'|$)|\S)*\s*/', '', $string); |
|
1122 | + } |
|
1123 | + |
|
1124 | + /** |
|
1125 | + * Decodes numeric HTML entities |
|
1126 | + * |
|
1127 | + * This method decodes numeric HTML entities (A and A). It doesn't |
|
1128 | + * do anything with other entities like ä, but we don't need them in the |
|
1129 | + * URL protocol white listing system anyway. |
|
1130 | + * |
|
1131 | + * @access private |
|
1132 | + * @param string $value The entitiy to be decoded. |
|
1133 | + * @return string Decoded entity |
|
1134 | + * @since PHP4 OOP 0.0.1 |
|
1135 | + */ |
|
1136 | + function _decode_entities($string) |
|
1137 | + { |
|
1138 | + $string = preg_replace('/&#([0-9]+);/e', 'chr("\\1")', $string); |
|
1139 | + $string = preg_replace('/&#[Xx]([0-9A-Fa-f]+);/e', 'chr(hexdec("\\1"))', $string); |
|
1140 | + return $string; |
|
1141 | + } |
|
1142 | + |
|
1143 | + /** |
|
1144 | + * Returns PHP4 OOP version # of kses. |
|
1145 | + * |
|
1146 | + * Since this class has been refactored and documented and proven to work, |
|
1147 | + * I'm syncing the version number to procedural kses. |
|
1148 | + * |
|
1149 | + * @access public |
|
1150 | + * @return string Version number |
|
1151 | + * @since PHP4 OOP 0.0.1 |
|
1152 | + */ |
|
1153 | + function _version() |
|
1154 | + { |
|
1155 | + return 'PHP4 0.2.2 (OOP fork of procedural kses 0.2.2)'; |
|
1156 | + } |
|
1157 | + } |
|
1158 | + |
|
1159 | + |
|
1160 | + |
|
1161 | + } |
|
1162 | 1162 | ?> |
1163 | 1163 | \ No newline at end of file |
@@ -42,141 +42,141 @@ |
||
42 | 42 | */ |
43 | 43 | function xajaxCompressJavascript($sJS) |
44 | 44 | { |
45 | - //remove windows cariage returns |
|
46 | - $sJS = str_replace("\r","",$sJS); |
|
47 | - |
|
48 | - //array to store replaced literal strings |
|
49 | - $literal_strings = array(); |
|
50 | - |
|
51 | - //explode the string into lines |
|
52 | - $lines = explode("\n",$sJS); |
|
53 | - //loop through all the lines, building a new string at the same time as removing literal strings |
|
54 | - $clean = ""; |
|
55 | - $inComment = false; |
|
56 | - $literal = ""; |
|
57 | - $inQuote = false; |
|
58 | - $escaped = false; |
|
59 | - $quoteChar = ""; |
|
60 | - |
|
61 | - for($i=0;$i<count($lines);$i++) |
|
62 | - { |
|
63 | - $line = $lines[$i]; |
|
64 | - $inNormalComment = false; |
|
65 | - |
|
66 | - //loop through line's characters and take out any literal strings, replace them with ___i___ where i is the index of this string |
|
67 | - for($j=0;$j<strlen($line);$j++) |
|
68 | - { |
|
69 | - $c = substr($line,$j,1); |
|
70 | - $d = substr($line,$j,2); |
|
71 | - |
|
72 | - //look for start of quote |
|
73 | - if(!$inQuote && !$inComment) |
|
74 | - { |
|
75 | - //is this character a quote or a comment |
|
76 | - if(($c=="\"" || $c=="'") && !$inComment && !$inNormalComment) |
|
77 | - { |
|
78 | - $inQuote = true; |
|
79 | - $inComment = false; |
|
80 | - $escaped = false; |
|
81 | - $quoteChar = $c; |
|
82 | - $literal = $c; |
|
83 | - } |
|
84 | - else if($d=="/*" && !$inNormalComment) |
|
85 | - { |
|
86 | - $inQuote = false; |
|
87 | - $inComment = true; |
|
88 | - $escaped = false; |
|
89 | - $quoteChar = $d; |
|
90 | - $literal = $d; |
|
91 | - $j++; |
|
92 | - } |
|
93 | - else if($d=="//") //ignore string markers that are found inside comments |
|
94 | - { |
|
95 | - $inNormalComment = true; |
|
96 | - $clean .= $c; |
|
97 | - } |
|
98 | - else |
|
99 | - { |
|
100 | - $clean .= $c; |
|
101 | - } |
|
102 | - } |
|
103 | - else //allready in a string so find end quote |
|
104 | - { |
|
105 | - if($c == $quoteChar && !$escaped && !$inComment) |
|
106 | - { |
|
107 | - $inQuote = false; |
|
108 | - $literal .= $c; |
|
109 | - |
|
110 | - //subsitute in a marker for the string |
|
111 | - $clean .= "___" . count($literal_strings) . "___"; |
|
112 | - |
|
113 | - //push the string onto our array |
|
114 | - array_push($literal_strings,$literal); |
|
115 | - |
|
116 | - } |
|
117 | - else if($inComment && $d=="*/") |
|
118 | - { |
|
119 | - $inComment = false; |
|
120 | - $literal .= $d; |
|
121 | - |
|
122 | - //subsitute in a marker for the string |
|
123 | - $clean .= "___" . count($literal_strings) . "___"; |
|
124 | - |
|
125 | - //push the string onto our array |
|
126 | - array_push($literal_strings,$literal); |
|
127 | - |
|
128 | - $j++; |
|
129 | - } |
|
130 | - else if($c == "\\" && !$escaped) |
|
131 | - $escaped = true; |
|
132 | - else |
|
133 | - $escaped = false; |
|
134 | - |
|
135 | - $literal .= $c; |
|
136 | - } |
|
137 | - } |
|
138 | - if($inComment) $literal .= "\n"; |
|
139 | - $clean .= "\n"; |
|
140 | - } |
|
141 | - //explode the clean string into lines again |
|
142 | - $lines = explode("\n",$clean); |
|
143 | - |
|
144 | - //now process each line at a time |
|
145 | - for($i=0;$i<count($lines);$i++) |
|
146 | - { |
|
147 | - $line = $lines[$i]; |
|
148 | - |
|
149 | - //remove comments |
|
150 | - $line = preg_replace("/\/\/(.*)/","",$line); |
|
151 | - |
|
152 | - //strip leading and trailing whitespace |
|
153 | - $line = trim($line); |
|
154 | - |
|
155 | - //remove all whitespace with a single space |
|
156 | - $line = preg_replace("/\s+/"," ",$line); |
|
157 | - |
|
158 | - //remove any whitespace that occurs after/before an operator |
|
159 | - $line = preg_replace("/\s*([!\}\{;,&=\|\-\+\*\/\)\(:])\s*/","\\1",$line); |
|
160 | - |
|
161 | - $lines[$i] = $line; |
|
162 | - } |
|
163 | - |
|
164 | - //implode the lines |
|
165 | - $sJS = implode("\n",$lines); |
|
166 | - |
|
167 | - //make sure there is a max of 1 \n after each line |
|
168 | - $sJS = preg_replace("/[\n]+/","\n",$sJS); |
|
169 | - |
|
170 | - //strip out line breaks that immediately follow a semi-colon |
|
171 | - $sJS = preg_replace("/;\n/",";",$sJS); |
|
172 | - |
|
173 | - //curly brackets aren't on their own |
|
174 | - $sJS = preg_replace("/[\n]*\{[\n]*/","{",$sJS); |
|
175 | - |
|
176 | - //finally loop through and replace all the literal strings: |
|
177 | - for($i=0;$i<count($literal_strings);$i++) |
|
178 | - $sJS = str_replace("___".$i."___",$literal_strings[$i],$sJS); |
|
179 | - |
|
180 | - return $sJS; |
|
45 | + //remove windows cariage returns |
|
46 | + $sJS = str_replace("\r","",$sJS); |
|
47 | + |
|
48 | + //array to store replaced literal strings |
|
49 | + $literal_strings = array(); |
|
50 | + |
|
51 | + //explode the string into lines |
|
52 | + $lines = explode("\n",$sJS); |
|
53 | + //loop through all the lines, building a new string at the same time as removing literal strings |
|
54 | + $clean = ""; |
|
55 | + $inComment = false; |
|
56 | + $literal = ""; |
|
57 | + $inQuote = false; |
|
58 | + $escaped = false; |
|
59 | + $quoteChar = ""; |
|
60 | + |
|
61 | + for($i=0;$i<count($lines);$i++) |
|
62 | + { |
|
63 | + $line = $lines[$i]; |
|
64 | + $inNormalComment = false; |
|
65 | + |
|
66 | + //loop through line's characters and take out any literal strings, replace them with ___i___ where i is the index of this string |
|
67 | + for($j=0;$j<strlen($line);$j++) |
|
68 | + { |
|
69 | + $c = substr($line,$j,1); |
|
70 | + $d = substr($line,$j,2); |
|
71 | + |
|
72 | + //look for start of quote |
|
73 | + if(!$inQuote && !$inComment) |
|
74 | + { |
|
75 | + //is this character a quote or a comment |
|
76 | + if(($c=="\"" || $c=="'") && !$inComment && !$inNormalComment) |
|
77 | + { |
|
78 | + $inQuote = true; |
|
79 | + $inComment = false; |
|
80 | + $escaped = false; |
|
81 | + $quoteChar = $c; |
|
82 | + $literal = $c; |
|
83 | + } |
|
84 | + else if($d=="/*" && !$inNormalComment) |
|
85 | + { |
|
86 | + $inQuote = false; |
|
87 | + $inComment = true; |
|
88 | + $escaped = false; |
|
89 | + $quoteChar = $d; |
|
90 | + $literal = $d; |
|
91 | + $j++; |
|
92 | + } |
|
93 | + else if($d=="//") //ignore string markers that are found inside comments |
|
94 | + { |
|
95 | + $inNormalComment = true; |
|
96 | + $clean .= $c; |
|
97 | + } |
|
98 | + else |
|
99 | + { |
|
100 | + $clean .= $c; |
|
101 | + } |
|
102 | + } |
|
103 | + else //allready in a string so find end quote |
|
104 | + { |
|
105 | + if($c == $quoteChar && !$escaped && !$inComment) |
|
106 | + { |
|
107 | + $inQuote = false; |
|
108 | + $literal .= $c; |
|
109 | + |
|
110 | + //subsitute in a marker for the string |
|
111 | + $clean .= "___" . count($literal_strings) . "___"; |
|
112 | + |
|
113 | + //push the string onto our array |
|
114 | + array_push($literal_strings,$literal); |
|
115 | + |
|
116 | + } |
|
117 | + else if($inComment && $d=="*/") |
|
118 | + { |
|
119 | + $inComment = false; |
|
120 | + $literal .= $d; |
|
121 | + |
|
122 | + //subsitute in a marker for the string |
|
123 | + $clean .= "___" . count($literal_strings) . "___"; |
|
124 | + |
|
125 | + //push the string onto our array |
|
126 | + array_push($literal_strings,$literal); |
|
127 | + |
|
128 | + $j++; |
|
129 | + } |
|
130 | + else if($c == "\\" && !$escaped) |
|
131 | + $escaped = true; |
|
132 | + else |
|
133 | + $escaped = false; |
|
134 | + |
|
135 | + $literal .= $c; |
|
136 | + } |
|
137 | + } |
|
138 | + if($inComment) $literal .= "\n"; |
|
139 | + $clean .= "\n"; |
|
140 | + } |
|
141 | + //explode the clean string into lines again |
|
142 | + $lines = explode("\n",$clean); |
|
143 | + |
|
144 | + //now process each line at a time |
|
145 | + for($i=0;$i<count($lines);$i++) |
|
146 | + { |
|
147 | + $line = $lines[$i]; |
|
148 | + |
|
149 | + //remove comments |
|
150 | + $line = preg_replace("/\/\/(.*)/","",$line); |
|
151 | + |
|
152 | + //strip leading and trailing whitespace |
|
153 | + $line = trim($line); |
|
154 | + |
|
155 | + //remove all whitespace with a single space |
|
156 | + $line = preg_replace("/\s+/"," ",$line); |
|
157 | + |
|
158 | + //remove any whitespace that occurs after/before an operator |
|
159 | + $line = preg_replace("/\s*([!\}\{;,&=\|\-\+\*\/\)\(:])\s*/","\\1",$line); |
|
160 | + |
|
161 | + $lines[$i] = $line; |
|
162 | + } |
|
163 | + |
|
164 | + //implode the lines |
|
165 | + $sJS = implode("\n",$lines); |
|
166 | + |
|
167 | + //make sure there is a max of 1 \n after each line |
|
168 | + $sJS = preg_replace("/[\n]+/","\n",$sJS); |
|
169 | + |
|
170 | + //strip out line breaks that immediately follow a semi-colon |
|
171 | + $sJS = preg_replace("/;\n/",";",$sJS); |
|
172 | + |
|
173 | + //curly brackets aren't on their own |
|
174 | + $sJS = preg_replace("/[\n]*\{[\n]*/","{",$sJS); |
|
175 | + |
|
176 | + //finally loop through and replace all the literal strings: |
|
177 | + for($i=0;$i<count($literal_strings);$i++) |
|
178 | + $sJS = str_replace("___".$i."___",$literal_strings[$i],$sJS); |
|
179 | + |
|
180 | + return $sJS; |
|
181 | 181 | } |
182 | 182 | ?> |