This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | |||
3 | namespace ogheo\comments\widget; |
||
4 | |||
5 | use Yii; |
||
6 | use yii\base\Model; |
||
7 | use yii\helpers\Url; |
||
8 | use yii\helpers\Json; |
||
9 | use yii\caching\TagDependency; |
||
10 | use yii\data\ActiveDataProvider; |
||
11 | use ogheo\comments\assets\CommentsAsset; |
||
12 | use ogheo\comments\helpers\CommentsHelper; |
||
13 | use ogheo\comments\Module as CommentsModule; |
||
14 | |||
15 | /** |
||
16 | * Class Comments |
||
17 | * @package ogheo\comments\widget |
||
18 | */ |
||
19 | class Comments extends \yii\base\Widget |
||
20 | { |
||
21 | /** |
||
22 | * Page url |
||
23 | * @var string |
||
24 | */ |
||
25 | public $url; |
||
26 | |||
27 | /** |
||
28 | * Model |
||
29 | * @var object |
||
30 | */ |
||
31 | public $model; |
||
32 | |||
33 | /** |
||
34 | * Model key |
||
35 | * @var string |
||
36 | */ |
||
37 | public $model_key; |
||
38 | |||
39 | /** |
||
40 | * Display comments form for unregistered users. |
||
41 | * @var bool |
||
42 | */ |
||
43 | public $guestComments = true; |
||
44 | |||
45 | /** |
||
46 | * Comments block display type. |
||
47 | * By default comments block is displayed as a button. |
||
48 | * To display comments block in full size, change that value to whatever you want. |
||
49 | * Ex: extended |
||
50 | * @var string |
||
51 | */ |
||
52 | public $defaultCommentsView = 'restricted'; |
||
53 | |||
54 | /** |
||
55 | * Position where comments form will be displayed. |
||
56 | * By default form is displayed above the comments. |
||
57 | * To display it after, change it to 'bottom'. |
||
58 | * @var string |
||
59 | */ |
||
60 | public $formPosition = 'top'; |
||
61 | |||
62 | /** |
||
63 | * Maximum allowed level for comments replies. |
||
64 | * @var int |
||
65 | */ |
||
66 | public $maxNestedLevel = 5; |
||
67 | |||
68 | /** |
||
69 | * Number of displayed comments by default. |
||
70 | * @var int |
||
71 | */ |
||
72 | public $commentsPerPage = 10; |
||
73 | |||
74 | /** |
||
75 | * Order direction. |
||
76 | * @var int |
||
77 | */ |
||
78 | public $order = SORT_DESC; |
||
79 | |||
80 | /** |
||
81 | * Nested order direction. |
||
82 | * @var int |
||
83 | */ |
||
84 | public $nestedOrder = SORT_ASC; |
||
85 | |||
86 | /** |
||
87 | * Comment form id |
||
88 | * @var string |
||
89 | */ |
||
90 | public $formId = 'comment-form'; |
||
91 | |||
92 | /** |
||
93 | * Comments wrapper id |
||
94 | * @var string |
||
95 | */ |
||
96 | public $wrapperId = 'comments'; |
||
97 | |||
98 | /** |
||
99 | * Comments show id |
||
100 | * @var string |
||
101 | */ |
||
102 | public $showCommentsId = 'show-comments'; |
||
103 | |||
104 | /** |
||
105 | * Comments full id |
||
106 | * @var string |
||
107 | */ |
||
108 | public $fullCommentsId = 'comments-full'; |
||
109 | |||
110 | /** |
||
111 | * Comments pjax container id |
||
112 | * @var string |
||
113 | */ |
||
114 | public $pjaxContainerId = 'comments-container'; |
||
115 | |||
116 | /** |
||
117 | * Comment form id |
||
118 | * @var string |
||
119 | */ |
||
120 | public $formContainerId = 'comments-container-form'; |
||
121 | |||
122 | /** |
||
123 | * Comment form id |
||
124 | * @var string |
||
125 | */ |
||
126 | public $submitButtonId = 'submitButton'; |
||
127 | |||
128 | /** |
||
129 | * @var array DataProvider config |
||
130 | */ |
||
131 | public $dataProviderConfig = null; |
||
132 | /** |
||
133 | * @var array ListView config |
||
134 | */ |
||
135 | public $listViewConfig = null; |
||
136 | |||
137 | /** |
||
138 | * @var array comment widget client options |
||
139 | */ |
||
140 | public $clientOptions = []; |
||
141 | |||
142 | /** |
||
143 | * @var string |
||
144 | */ |
||
145 | public $commentsView = '@vendor/ogheo/yii2-comments/src/widget/views/comments'; |
||
146 | |||
147 | /** |
||
148 | * @var string |
||
149 | */ |
||
150 | public $commentView = '@vendor/ogheo/yii2-comments/src/widget/views/_comment'; |
||
151 | |||
152 | /** |
||
153 | * @var string |
||
154 | */ |
||
155 | public $formView = '@vendor/ogheo/yii2-comments/src/widget/views/_form'; |
||
156 | |||
157 | /** |
||
158 | * @inheritdoc |
||
159 | */ |
||
160 | public function init() |
||
161 | { |
||
162 | parent::init(); |
||
163 | |||
164 | Yii::$app->getModule('comments'); |
||
165 | |||
166 | $this->formId = $this->getId() . '-' . $this->formId; |
||
167 | $this->wrapperId = $this->getId() . '-' . $this->wrapperId; |
||
168 | $this->showCommentsId = $this->getId() . '-' . $this->showCommentsId; |
||
169 | $this->fullCommentsId = $this->getId() . '-' . $this->fullCommentsId; |
||
170 | $this->pjaxContainerId = $this->getId() . '-' . $this->pjaxContainerId; |
||
171 | $this->formContainerId = $this->getId() . '-' . $this->formContainerId; |
||
172 | $this->submitButtonId = $this->getId() . '-' . $this->submitButtonId; |
||
173 | |||
174 | if ($this->url === null) { |
||
175 | $this->url = Url::canonical(); |
||
176 | Url::remember($this->url, CommentsModule::getInstance()->urlCacheSessionKey); |
||
177 | } else { |
||
178 | Url::remember($this->url, CommentsModule::getInstance()->urlCacheSessionKey); |
||
179 | } |
||
180 | |||
181 | if ($this->model instanceof Model) { |
||
182 | $this->model = $this->model->tableName(); |
||
183 | } |
||
184 | |||
185 | $this->registerAssets(); |
||
186 | } |
||
187 | |||
188 | /** |
||
189 | * @inheritdoc |
||
190 | * @return string |
||
191 | */ |
||
192 | public function run() |
||
193 | { |
||
194 | $commentClass = CommentsModule::getInstance()->commentModelClass; |
||
195 | $commentsCounter = $commentClass::getCommentsCounter([ |
||
196 | 'url' => $this->url, |
||
197 | 'model' => $this->model, |
||
198 | 'model_key' => $this->model_key |
||
199 | ]); |
||
200 | |||
201 | $dataProvider = new ActiveDataProvider( |
||
202 | array_merge( |
||
203 | [ |
||
204 | 'query' => $commentClass::getComments([ |
||
205 | 'url' => $this->url, |
||
206 | 'model' => $this->model, |
||
207 | 'model_key' => $this->model_key, |
||
208 | 'nestedOrder' => $this->nestedOrder, |
||
209 | 'loadComments' => true |
||
210 | ]) |
||
211 | ], $this->getDataProviderConfig() |
||
212 | ) |
||
213 | ); |
||
214 | |||
215 | return $this->render($this->commentsView, [ |
||
216 | 'dataProvider' => $dataProvider, |
||
217 | 'commentsCounter' => $commentsCounter, |
||
218 | 'commentModel' => Yii::createObject($commentClass, [[ |
||
219 | 'url' => $this->url, |
||
220 | 'model' => $this->model, |
||
221 | 'model_key' => $this->model_key, |
||
222 | 'email' => Yii::$app->user->isGuest ? CommentsHelper::getEmail() : null, |
||
223 | 'username' => Yii::$app->user->isGuest ? CommentsHelper::getUsername() : null, |
||
224 | 'scenario' => Yii::$app->user->isGuest ? $commentClass::SCENARIO_GUEST : $commentClass::SCENARIO_USER, |
||
225 | 'created_by' => Yii::$app->user->isGuest ? null : Yii::$app->user->getId() |
||
226 | ]]), |
||
227 | 'widget' => $this |
||
228 | ]); |
||
229 | } |
||
230 | |||
231 | /** |
||
232 | * @return array |
||
233 | */ |
||
234 | public function getDataProviderConfig() |
||
235 | { |
||
236 | if ($this->dataProviderConfig === null) { |
||
237 | $this->dataProviderConfig = [ |
||
238 | 'key' => function ($model) { |
||
239 | return CommentsHelper::encodeId($model->id); |
||
240 | }, |
||
241 | 'pagination' => [ |
||
242 | 'defaultPageSize' => $this->commentsPerPage |
||
243 | ], |
||
244 | 'sort' => [ |
||
245 | 'attributes' => ['created_at'], |
||
246 | 'defaultOrder' => [ |
||
247 | 'created_at' => $this->order |
||
248 | ] |
||
249 | ] |
||
250 | ]; |
||
251 | } |
||
252 | |||
253 | return $this->dataProviderConfig; |
||
254 | } |
||
255 | |||
256 | /** |
||
257 | * @return array |
||
258 | */ |
||
259 | public function getListViewConfig() |
||
260 | { |
||
261 | if ($this->listViewConfig === null) { |
||
262 | $this->listViewConfig = [ |
||
263 | 'layout' => '{items}<div class="text-center">{pager}</div>', |
||
264 | 'options' => ['class' => 'comments-list'], |
||
265 | 'itemOptions' => ['class' => 'media'], |
||
266 | 'itemView' => function ($model, $key, $index, $widget) { |
||
0 ignored issues
–
show
|
|||
267 | return $this->render($this->commentView, [ |
||
268 | 'maxNestedLevel' => $this->maxNestedLevel, |
||
269 | 'nestedLevel' => 1, |
||
270 | 'widget' => $this, |
||
271 | 'model' => $model, |
||
272 | ]); |
||
273 | }, |
||
274 | 'emptyText' => '', |
||
275 | 'pager' => [ |
||
276 | 'class' => \yii\widgets\LinkPager::className(), |
||
277 | 'options' => ['class' => 'pagination pagination-sm'], |
||
278 | 'maxButtonCount' => 5 |
||
279 | ] |
||
280 | ]; |
||
281 | } |
||
282 | |||
283 | return $this->listViewConfig; |
||
284 | } |
||
285 | |||
286 | /** |
||
287 | * @return string |
||
288 | */ |
||
289 | public function getClientOptions() |
||
290 | { |
||
291 | $this->clientOptions['wrapperId'] = '#' . $this->wrapperId; |
||
292 | $this->clientOptions['formSelector'] = '#' . $this->formId; |
||
293 | $this->clientOptions['showCommentsId'] = '#' . $this->showCommentsId; |
||
294 | $this->clientOptions['fullCommentsId'] = '#' . $this->fullCommentsId; |
||
295 | $this->clientOptions['pjaxContainerId'] = '#' . $this->pjaxContainerId; |
||
296 | $this->clientOptions['formContainerId'] = '#' . $this->formContainerId; |
||
297 | $this->clientOptions['submitButtonId'] = '#' . $this->submitButtonId; |
||
298 | $this->clientOptions['postButtonName'] = Yii::t('comments', 'Post'); |
||
299 | $this->clientOptions['replyButtonName'] = Yii::t('comments', 'Reply'); |
||
300 | $this->clientOptions['ratingUrl'] = Url::to(['comments/default/rate']); |
||
301 | |||
302 | return Json::encode($this->clientOptions); |
||
303 | } |
||
304 | |||
305 | /** |
||
306 | * Register assets. |
||
307 | */ |
||
308 | public function registerAssets() |
||
309 | { |
||
310 | $view = $this->getView(); |
||
311 | CommentsAsset::register($view); |
||
312 | $view->registerJs("jQuery('#{$this->wrapperId}').comment({$this->getClientOptions()});"); |
||
313 | } |
||
314 | } |
||
315 |
This check looks from parameters that have been defined for a function or method, but which are not used in the method body.