This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | |||
3 | /* |
||
4 | * This file is part of the ONGR package. |
||
5 | * |
||
6 | * (c) NFQ Technologies UAB <[email protected]> |
||
7 | * |
||
8 | * For the full copyright and license information, please view the LICENSE |
||
9 | * file that was distributed with this source code. |
||
10 | */ |
||
11 | |||
12 | namespace ONGR\CurrencyExchangeBundle\Twig; |
||
13 | |||
14 | use ONGR\CurrencyExchangeBundle\Exception\UndefinedCurrencyException; |
||
15 | use ONGR\CurrencyExchangeBundle\Service\CurrencyExchangeService; |
||
16 | use ONGR\CurrencyExchangeBundle\Tests\Unit\DependencyInjection\ONGRCurrencyExchangeExtensionTest; |
||
17 | use Psr\Log\LoggerAwareInterface; |
||
18 | use Psr\Log\LoggerAwareTrait; |
||
19 | use Psr\Log\LoggerInterface; |
||
20 | |||
21 | /** |
||
22 | * Class for displaying changed currencies. |
||
23 | */ |
||
24 | class PriceExtension extends \Twig_Extension implements LoggerAwareInterface |
||
25 | { |
||
26 | use LoggerAwareTrait; |
||
27 | |||
28 | /** |
||
29 | * Extension name |
||
30 | */ |
||
31 | const NAME = 'price_extension'; |
||
32 | |||
33 | /** |
||
34 | * @var string Currency sign. |
||
35 | */ |
||
36 | private $currencySign; |
||
37 | |||
38 | /** |
||
39 | * @var string Decimal point separator. |
||
40 | */ |
||
41 | private $decPointSeparator; |
||
42 | |||
43 | /** |
||
44 | * @var string Thousands separator. |
||
45 | */ |
||
46 | private $thousandsSeparator; |
||
47 | |||
48 | /** |
||
49 | * @var null Currency. |
||
50 | */ |
||
51 | private $currency = null; |
||
52 | |||
53 | /** |
||
54 | * @var CurrencyExchangeService Service which provide currency exchange rates. |
||
55 | */ |
||
56 | private $currencyService = null; |
||
57 | |||
58 | /** |
||
59 | * @var array Contains formats for each currency. |
||
60 | */ |
||
61 | private $formatsMap; |
||
62 | |||
63 | /** |
||
64 | * @var array Array of currencies to be listed in twig while using the "list" functions. |
||
65 | */ |
||
66 | private $toListMap; |
||
67 | |||
68 | /** |
||
69 | * @var string String containing the default currency_list template |
||
70 | */ |
||
71 | private $currency_list; |
||
72 | |||
73 | /** |
||
74 | * @var string String containing the default price_list template |
||
75 | */ |
||
76 | private $price_list; |
||
77 | |||
78 | /** |
||
79 | 27 | * Constructor. |
|
80 | * |
||
81 | * @param string $currencySign |
||
82 | * @param string $decPointSeparator |
||
83 | * @param string $thousandsSeparator |
||
84 | * @param string $currency_list |
||
85 | * @param string $price_list |
||
86 | * @param array $currency |
||
87 | 27 | * @param array $formatsMap |
|
88 | 27 | * @param array $toListMap |
|
89 | 27 | */ |
|
90 | 27 | public function __construct( |
|
91 | 27 | $currencySign, |
|
92 | 27 | $decPointSeparator, |
|
93 | 27 | $thousandsSeparator, |
|
94 | $currency_list, |
||
95 | $price_list, |
||
96 | $currency = null, |
||
97 | $formatsMap = [], |
||
98 | 2 | $toListMap = [] |
|
99 | ) { |
||
100 | 2 | $this->currencySign = $currencySign; |
|
101 | 2 | $this->decPointSeparator = $decPointSeparator; |
|
102 | 2 | $this->thousandsSeparator = $thousandsSeparator; |
|
103 | 2 | $this->currency = $currency; |
|
104 | 2 | $this->formatsMap = $formatsMap; |
|
105 | 2 | $this->toListMap = $toListMap; |
|
106 | 2 | $this->currency_list = $currency_list; |
|
107 | 2 | $this->price_list = $price_list; |
|
108 | 2 | } |
|
109 | |||
110 | 2 | /** |
|
111 | 2 | * @return \Twig_SimpleFilter[] |
|
112 | */ |
||
113 | 2 | public function getFilters() |
|
114 | { |
||
115 | 2 | $functions = []; |
|
116 | $functions[] = new \Twig_SimpleFilter( |
||
117 | 'ongr_price', |
||
118 | [$this, 'getFormattedPrice'], |
||
119 | ['is_safe' => ['html']] |
||
120 | ); |
||
121 | 2 | $functions[] = new \Twig_SimpleFilter( |
|
122 | 'ongr_price_list', |
||
123 | [$this, 'getPriceList'], |
||
124 | 2 | [ |
|
125 | 2 | 'needs_environment' => true, |
|
126 | 2 | 'is_safe' => ['html'], |
|
127 | ] |
||
128 | 2 | ); |
|
129 | |||
130 | 2 | return $functions; |
|
131 | 2 | } |
|
132 | |||
133 | 2 | /** |
|
134 | 2 | * @return \Twig_SimpleFunction[] |
|
135 | */ |
||
136 | public function getFunctions() |
||
137 | { |
||
138 | return [ |
||
139 | new \Twig_SimpleFunction( |
||
140 | 'ongr_currency_list', |
||
141 | [$this, 'getCurrencyList'], |
||
142 | [ |
||
143 | 'needs_environment' => true, |
||
144 | 'is_safe' => [ |
||
145 | 'html', |
||
146 | ], |
||
147 | ] |
||
148 | 21 | ), |
|
149 | ]; |
||
150 | } |
||
151 | |||
152 | /** |
||
153 | * Returns formatted price. |
||
154 | * |
||
155 | 21 | * @param float $price |
|
156 | * @param int $decimals |
||
157 | 21 | * @param string $toCurrency |
|
158 | 21 | * @param string $fromCurrency |
|
159 | * @param string $customFormat |
||
160 | 20 | * @param string $date |
|
161 | 20 | * |
|
162 | 1 | * @return string |
|
163 | 1 | */ |
|
164 | 1 | public function getFormattedPrice( |
|
165 | 1 | $price, |
|
166 | $decimals = 0, |
||
167 | 1 | $toCurrency = null, |
|
168 | $fromCurrency = null, |
||
169 | 19 | $customFormat = null, |
|
170 | 1 | $date = '' |
|
171 | ) { |
||
172 | 1 | $targetCurrency = $toCurrency ? $toCurrency : $this->currency; |
|
173 | |||
174 | 19 | if ($targetCurrency) { |
|
0 ignored issues
–
show
|
|||
175 | if (isset($this->currencyService)) { |
||
176 | 19 | try { |
|
177 | 12 | $price = $this->currencyService->calculateRate($price, $targetCurrency, $fromCurrency, $date); |
|
178 | 12 | } catch (UndefinedCurrencyException $ex) { |
|
179 | $this->logger && $this->logger->error( |
||
180 | 19 | 'Got undefined currency on PriceExtension', |
|
181 | ['message' => $ex->getMessage()] |
||
182 | 19 | ); |
|
183 | 19 | ||
184 | 1 | return ''; |
|
185 | 19 | } |
|
186 | 11 | } else { |
|
187 | 11 | $this->logger && $this->logger->error('Currency service is undefined on PriceExtension'); |
|
188 | |||
189 | 19 | return ''; |
|
190 | 12 | } |
|
191 | } |
||
192 | 8 | ||
193 | if (abs($price) > floor(abs($price))) { |
||
194 | $decimals = 2; |
||
195 | } |
||
196 | |||
197 | $formattedPrice = number_format($price, $decimals, $this->decPointSeparator, $this->thousandsSeparator); |
||
198 | |||
199 | $printFormat = null; |
||
200 | if ($customFormat) { |
||
0 ignored issues
–
show
The expression
$customFormat of type string|null is loosely compared to true ; this is ambiguous if the string can be empty. You might want to explicitly use !== null instead.
In PHP, under loose comparison (like For '' == false // true
'' == null // true
'ab' == false // false
'ab' == null // false
// It is often better to use strict comparison
'' === false // false
'' === null // false
![]() |
|||
201 | $printFormat = $customFormat; |
||
202 | } elseif (isset($this->formatsMap[$targetCurrency])) { |
||
203 | $printFormat = $this->formatsMap[$targetCurrency]; |
||
204 | } |
||
205 | |||
206 | 7 | if ($printFormat) { |
|
207 | return sprintf($printFormat, $formattedPrice); |
||
208 | } else { |
||
209 | return "{$formattedPrice} {$this->currencySign}"; |
||
210 | } |
||
211 | } |
||
212 | 7 | ||
213 | 7 | /** |
|
214 | 7 | * Returns specified prices formatted by a specified template. |
|
215 | 7 | * |
|
216 | 7 | * @param \Twig_Environment $environment |
|
217 | * @param int $price |
||
218 | 7 | * @param string $template |
|
219 | * @param null $fromCurrency |
||
220 | 7 | * @param string $date |
|
221 | 7 | * |
|
222 | 7 | * @return string |
|
223 | 7 | */ |
|
224 | public function getPriceList( |
||
225 | $environment, |
||
226 | $price, |
||
227 | $template = '', |
||
228 | $fromCurrency = null, |
||
229 | $date = '' |
||
230 | ) { |
||
231 | if ($template == '') { |
||
232 | $template = $this->price_list; |
||
233 | } |
||
234 | 1 | $values = []; |
|
235 | foreach ($this->toListMap as $targetCurrency) { |
||
236 | 1 | $values[] = [ |
|
237 | 1 | 'value' => $this->getFormattedPrice($price, 0, $targetCurrency, $fromCurrency, '', $date), |
|
238 | 1 | 'currency' => strtolower($targetCurrency), |
|
239 | 1 | ]; |
|
240 | 1 | } |
|
241 | 1 | ||
242 | return $environment->render( |
||
243 | 1 | $template, |
|
244 | ['prices' => $values] |
||
245 | 1 | ); |
|
246 | 1 | } |
|
247 | 1 | ||
248 | 1 | /** |
|
249 | * Returns all available currencies. |
||
250 | * |
||
251 | * @param \Twig_Environment $environment |
||
252 | * @param string $template |
||
253 | * |
||
254 | * @return string |
||
255 | */ |
||
256 | 2 | public function getCurrencyList($environment, $template = '') |
|
257 | { |
||
258 | 2 | if ($template == '') { |
|
259 | $template = $this->currency_list; |
||
260 | } |
||
261 | $values = []; |
||
262 | foreach ($this->toListMap as $targetCurrency) { |
||
263 | $values[] = [ |
||
264 | 9 | 'value' => $targetCurrency, |
|
265 | 'code' => strtolower($targetCurrency), |
||
266 | 9 | 'default' => (strcasecmp($targetCurrency, $this->currency) == 0) ? true : false, |
|
267 | 9 | ]; |
|
268 | } |
||
269 | |||
270 | return $environment->render( |
||
271 | $template, |
||
272 | 2 | ['currencies' => $values] |
|
273 | ); |
||
274 | 2 | } |
|
275 | |||
276 | /** |
||
277 | * Returns name of the extension. |
||
278 | * |
||
279 | * @return string |
||
280 | 21 | */ |
|
281 | public function getName() |
||
282 | 21 | { |
|
283 | 21 | return self::NAME; |
|
284 | } |
||
285 | |||
286 | /** |
||
287 | * @param null $currency |
||
288 | 2 | */ |
|
289 | public function setCurrency($currency) |
||
290 | 2 | { |
|
291 | 2 | $this->currency = $currency; |
|
292 | } |
||
293 | |||
294 | /** |
||
295 | * @return string |
||
296 | 1 | */ |
|
297 | public function getCurrency() |
||
298 | 1 | { |
|
299 | 1 | return $this->currency; |
|
300 | } |
||
301 | |||
302 | /** |
||
303 | * @param CurrencyExchangeService $currencyService |
||
304 | 1 | */ |
|
305 | public function setCurrencyExchangeService($currencyService) |
||
306 | 1 | { |
|
307 | 1 | $this->currencyService = $currencyService; |
|
308 | } |
||
309 | |||
310 | /** |
||
311 | * @param array $toListMap |
||
312 | */ |
||
313 | public function setToListMap($toListMap) |
||
314 | { |
||
315 | $this->toListMap = $toListMap; |
||
316 | } |
||
317 | |||
318 | /** |
||
319 | * @param array $formatsMap |
||
320 | */ |
||
321 | public function setFormatsMap($formatsMap) |
||
322 | { |
||
323 | $this->formatsMap = $formatsMap; |
||
324 | } |
||
325 | } |
||
326 |
In PHP, under loose comparison (like
==
, or!=
, orswitch
conditions), values of different types might be equal.For
string
values, the empty string''
is a special case, in particular the following results might be unexpected: