1 | <?php |
||
11 | class Sanitise |
||
12 | { |
||
13 | |||
14 | private $is_valid = null; |
||
15 | private $_sanitised = null; |
||
16 | private $filters; |
||
17 | private $input; |
||
18 | private $output; |
||
19 | private $strings; |
||
20 | private $urlService; |
||
21 | |||
22 | function __construct() |
||
28 | |||
29 | /** |
||
30 | * |
||
31 | * Removes URLs from strings |
||
32 | * |
||
33 | * @param array|string $data |
||
34 | * @return array|string|string[]|null |
||
35 | */ |
||
36 | public function removeUrl($data) |
||
37 | { |
||
38 | $this->_sanitised = null; |
||
39 | |||
40 | if (is_array($data)) { |
||
41 | foreach ($data as $key => $value) { |
||
42 | $data[$key] = $this->removeUrl($value); |
||
43 | } |
||
44 | return $data; |
||
45 | } |
||
46 | |||
47 | $this->input = $data = trim($data); |
||
48 | $data = $this->urlService->remove($data); |
||
49 | $data = trim($data); |
||
50 | |||
51 | if ($this->input != $data) { |
||
52 | $this->_sanitised = true; |
||
53 | } |
||
54 | $this->is_valid = true; |
||
55 | |||
56 | $this->output = $data; |
||
57 | return $data; |
||
58 | |||
59 | } |
||
60 | |||
61 | /** |
||
62 | * @param $data |
||
63 | * @param string $toEncoding |
||
64 | * @param string $fromEncoding |
||
65 | * @return array|false|string|string[]|null |
||
66 | */ |
||
67 | public function cleanse($data, $toEncoding = 'utf-8', $fromEncoding = 'auto') |
||
68 | { |
||
69 | |||
70 | if (is_array($data)) { |
||
71 | foreach ($data as $key => $value) { |
||
72 | $data[$key] = $this->cleanse($value, $toEncoding, $fromEncoding); |
||
73 | } |
||
74 | return $data; |
||
75 | } |
||
76 | |||
77 | $this->input = $data = trim($data); |
||
78 | $data = $this->strings->clean($data); |
||
79 | $data = mb_convert_encoding($data, $toEncoding, $fromEncoding); |
||
80 | $data = htmlspecialchars_decode($data); |
||
81 | $data = $this->strings->clean($data); |
||
82 | if ($this->input != $data) { |
||
83 | $this->_sanitised = true; |
||
84 | } |
||
85 | $this->output = $data; |
||
86 | return $data; |
||
87 | } |
||
88 | |||
89 | /** |
||
90 | * @param $string |
||
91 | * @param string $delimiter |
||
92 | * @return string |
||
93 | */ |
||
94 | public function cleanseCsv($string, $delimiter = "|") |
||
98 | |||
99 | /** |
||
100 | * @param $data |
||
101 | * @param string $type |
||
102 | * @param int $stringLength |
||
103 | * @return mixed|string |
||
104 | */ |
||
105 | 4 | public function disinfect($data, $type = 'special_chars', $stringLength = -1) |
|
106 | { |
||
107 | |||
108 | 4 | $this->_sanitised = null; |
|
109 | |||
110 | 4 | if (is_array($data)) { |
|
111 | foreach ($data as $key => $value) { |
||
112 | $data[$key] = $this->disinfect($value, $type, $stringLength); |
||
113 | } |
||
114 | return $data; |
||
115 | } |
||
116 | |||
117 | 4 | $this->input = $data = trim($data); |
|
118 | |||
119 | 4 | $data = $this->strings->clean($data); |
|
120 | 4 | $data = $this->strings->stringLength($data, $stringLength); |
|
121 | |||
122 | switch ($type) { |
||
123 | 4 | case "email": |
|
124 | $filterResult = $this->filters->filterEmail($data); |
||
125 | break; |
||
126 | |||
127 | 4 | case "encoded": |
|
128 | $filterResult = $this->filters->filterEncoded($data); |
||
129 | break; |
||
130 | |||
131 | 4 | case "number_float": |
|
132 | 4 | case "float": |
|
133 | $filterResult = $this->filters->filterFloat($data); |
||
134 | break; |
||
135 | |||
136 | 4 | case "number_int": |
|
137 | 4 | case "int": |
|
138 | $filterResult = $this->filters->filterInt($data); |
||
139 | break; |
||
140 | |||
141 | 4 | case "full_special_chars": |
|
142 | $filterResult = $this->filters->filterFullSpecialChar($data); |
||
143 | break; |
||
144 | |||
145 | 4 | case "url": |
|
146 | $filterResult = $this->filters->filterUrl($data); |
||
147 | break; |
||
148 | |||
149 | 4 | case "string": |
|
150 | 3 | $filterResult = $this->filters->filterString($data); |
|
151 | 3 | break; |
|
152 | |||
153 | 1 | default: |
|
154 | 1 | case "special_chars": |
|
155 | 1 | $filterResult = $this->filters->filterSpecial($data); |
|
156 | 1 | break; |
|
157 | 1 | } |
|
158 | |||
159 | 4 | if ($this->input != $filterResult->getResult()) { |
|
160 | 3 | $this->_sanitised = true; |
|
161 | 3 | } |
|
162 | |||
163 | 4 | $this->is_valid = $filterResult->isValid(); |
|
164 | 4 | $this->output = $filterResult->getResult(); |
|
165 | 4 | return $this->decodeHtmlEntity($this->output); |
|
166 | } |
||
167 | |||
168 | |||
169 | /** |
||
170 | * @param $str |
||
171 | * @return mixed|string |
||
172 | */ |
||
173 | 4 | public function decodeHtmlEntity($str) |
|
174 | { |
||
175 | 4 | $ret = html_entity_decode($str, ENT_COMPAT, 'UTF-8'); |
|
176 | 4 | $p2 = -1; |
|
177 | 4 | for (; ;) { |
|
178 | 4 | $p = strpos($ret, '&#', $p2 + 1); |
|
179 | 4 | if ($p === false) { |
|
180 | 4 | break; |
|
181 | } |
||
182 | $p2 = strpos($ret, ';', $p); |
||
183 | if ($p2 === false) { |
||
184 | break; |
||
185 | } |
||
186 | |||
187 | if (substr($ret, $p + 2, 1) == 'x') { |
||
188 | $char = hexdec(substr($ret, $p + 3, $p2 - $p - 3)); |
||
189 | } else { |
||
190 | $char = intval(substr($ret, $p + 2, $p2 - $p - 2)); |
||
191 | } |
||
192 | |||
193 | $newchar = iconv( |
||
194 | 'UCS-4', 'UTF-8', |
||
195 | chr(($char >> 24) & 0xFF) . chr(($char >> 16) & 0xFF) . chr(($char >> 8) & 0xFF) . chr($char & 0xFF) |
||
196 | ); |
||
197 | |||
198 | $ret = substr_replace($ret, $newchar, $p, 1 + $p2 - $p); |
||
199 | $p2 = $p + strlen($newchar); |
||
200 | } |
||
201 | 4 | return $ret; |
|
202 | } |
||
203 | |||
204 | |||
205 | /** |
||
206 | * @return null |
||
207 | */ |
||
208 | public function isSanitised() |
||
212 | |||
213 | /** |
||
214 | * Returns true if the data is valid |
||
215 | * @return null |
||
216 | */ |
||
217 | public function isValid() |
||
221 | |||
222 | 4 | function result() |
|
223 | { |
||
230 | |||
231 | } |
Adding explicit visibility (
private
,protected
, orpublic
) is generally recommend to communicate to other developers how, and from where this method is intended to be used.