Completed
Push — master ( 9458ed...7d322b )
by Henry
10:04
created

includes/Admin/Controller/Article.php (1 issue)

Labels
Severity

Upgrade to new PHP Analysis Engine

These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more

1
<?php
2
namespace Redaxscript\Admin\Controller;
3
4
use Redaxscript\Admin;
5
use Redaxscript\Filter;
6
use Redaxscript\Validator;
7
use function json_encode;
8
use function strtotime;
9
10
/**
11
 * children class to process the admin article request
12
 *
13
 * @since 4.0.0
14
 *
15
 * @package Redaxscript
16
 * @category Controller
17
 * @author Henry Ruhs
18
 */
19
20
class Article extends ControllerAbstract
21
{
22
	/**
23
	 * process the class
24
	 *
25
	 * @since 4.0.0
26
	 *
27
	 * @param string $action action to process
28
	 *
29
	 * @return string
30
	 */
31
32 11
	public function process(string $action = null) : string
33
	{
34 11
		$postArray = $this->_normalizePost($this->_sanitizePost());
35 11
		$validateArray = $this->_validatePost($postArray);
36 11
		$myUser = $this->_registry->get('myUser');
37 11
		$now = $this->_registry->get('now');
38
39
		/* validate post */
40
41 11
		if ($validateArray)
42
		{
43 7
			return $this->_error(
44
			[
45 7
				'route' => $this->_getErrorRoute($postArray),
46 7
				'message' => $validateArray
47
			]);
48
		}
49
50
		/* handle create */
51
52 4
		if ($action === 'create')
53
		{
54
			$createArray =
55
			[
56 1
				'title' => $postArray['title'],
57 1
				'alias' => $postArray['alias'],
58 1
				'author' => $myUser,
59 1
				'description' => $postArray['description'],
60 1
				'keywords' => $postArray['keywords'],
61 1
				'robots' => $postArray['robots'],
62 1
				'text' => $postArray['text'],
63 1
				'language' => $postArray['language'],
64 1
				'template' => $postArray['template'],
65 1
				'sibling' => $postArray['sibling'],
66 1
				'category' => $postArray['category'],
67 1
				'headline' => $postArray['headline'],
68 1
				'byline' => $postArray['byline'],
69 1
				'comments' => $postArray['comments'],
70 1
				'status' => $postArray['date'] > $now ? 2 : $postArray['status'],
71 1
				'rank' => $postArray['rank'],
72 1
				'access' => $postArray['access'],
73 1
				'date' => $postArray['date'] ? : $now
74
			];
75 1
			if ($this->_create($createArray))
76
			{
77 1
				return $this->_success(
78
				[
79 1
					'route' => $this->_getSuccessRoute($postArray),
80 1
					'timeout' => 2
81
				]);
82
			}
83
		}
84
85
		/* handle update */
86
87 3
		if ($action === 'update')
88
		{
89
			$updateArray =
90
			[
91 2
				'title' => $postArray['title'],
92 2
				'alias' => $postArray['alias'],
93 2
				'author' => $myUser,
94 2
				'description' => $postArray['description'],
95 2
				'keywords' => $postArray['keywords'],
96 2
				'robots' => $postArray['robots'],
97 2
				'text' => $postArray['text'],
98 2
				'language' => $postArray['language'],
99 2
				'template' => $postArray['template'],
100 2
				'sibling' => $postArray['sibling'],
101 2
				'category' => $postArray['category'],
102 2
				'headline' => $postArray['headline'],
103 2
				'byline' => $postArray['byline'],
104 2
				'comments' => $postArray['comments'],
105 2
				'status' => $postArray['date'] > $now ? 2 : $postArray['status'],
106 2
				'rank' => $postArray['rank'],
107 2
				'access' => $postArray['access'],
108 2
				'date' => $postArray['date'] ? : $now
109
			];
110 2
			if ($this->_update($postArray['id'], $updateArray))
111
			{
112 2
				return $this->_success(
113
				[
114 2
					'route' => $this->_getSuccessRoute($postArray),
115 2
					'timeout' => 2
116
				]);
117
			}
118
		}
119
120
		/* handle error */
121
122 1
		return $this->_error(
123
		[
124 1
			'route' => $this->_getErrorRoute($postArray)
125
		]);
126
	}
127
128
	/**
129
	 * sanitize the post
130
	 *
131
	 * @since 4.0.0
132
	 *
133
	 * @return array
134
	 */
135
136 11
	protected function _sanitizePost() : array
137
	{
138 11
		$aliasFilter = new Filter\Alias();
139 11
		$htmlFilter = new Filter\Html();
140 11
		$nameFilter= new Filter\Name();
141 11
		$numberFilter = new Filter\Number();
142 11
		$specialFilter = new Filter\Special();
143
		$toggleFilter = new Filter\Toggle();
144
145
		/* sanitize post */
146
147
		return
148 11
		[
149 11
			'id' => $numberFilter->sanitize($this->_request->getPost('id')),
150 11
			'title' => $nameFilter->sanitize($this->_request->getPost('title')),
0 ignored issues
show
It seems like $this->_request->getPost('title') targeting Redaxscript\Request::getPost() can also be of type array; however, Redaxscript\Filter\Name::sanitize() does only seem to accept null|string, maybe add an additional type check?

This check looks at variables that are passed out again to other methods.

If the outgoing method call has stricter type requirements than the method itself, an issue is raised.

An additional type check may prevent trouble.

Loading history...
151 11
			'alias' => $aliasFilter->sanitize($this->_request->getPost('alias')),
152 11
			'description' => $this->_request->getPost('description'),
153 11
			'keywords' => $this->_request->getPost('keywords'),
154 11
			'robots' => $this->_request->getPost('robots'),
155 11
			'text' => $htmlFilter->sanitize($this->_request->getPost('text'), $this->_registry->get('filter')),
156 11
			'language' => $specialFilter->sanitize($this->_request->getPost('language')),
157 11
			'template' => $specialFilter->sanitize($this->_request->getPost('template')),
158 11
			'sibling' => $this->_request->getPost('sibling'),
159 11
			'category' => $this->_request->getPost('category'),
160 11
			'headline' => $toggleFilter->sanitize($this->_request->getPost('headline')),
161 11
			'byline' => $toggleFilter->sanitize($this->_request->getPost('byline')),
162 11
			'comments' => $toggleFilter->sanitize($this->_request->getPost('comments')),
163 11
			'status' => $toggleFilter->sanitize($this->_request->getPost('status')),
164 11
			'rank' => $numberFilter->sanitize($this->_request->getPost('rank')),
165 11
			'access' => json_encode($this->_request->getPost('access')),
166
			'date' => strtotime($this->_request->getPost('date'))
167
		];
168
	}
169
170
	/**
171
	 * validate the post
172
	 *
173
	 * @since 4.0.0
174
	 *
175
	 * @param array $postArray array of the post
176
	 *
177
	 * @return array
178
	 */
179 11
180
	protected function _validatePost(array $postArray = []) : array
181 11
	{
182 11
		$nameValidator = new Validator\Name();
183 11
		$aliasValidator = new Validator\Alias();
184
		$articleModel = new Admin\Model\Article();
185
		$validateArray = [];
186
187 11
		/* validate post */
188
189 7
		if (!$postArray['title'])
190
		{
191 11
			$validateArray[] = $this->_language->get('title_empty');
192
		}
193 4
		else if (!$nameValidator->validate($postArray['title']))
194
		{
195 7
			$validateArray[] = $this->_language->get('title_incorrect');
196
		}
197 2
		if (!$postArray['alias'])
198
		{
199 5
			$validateArray[] = $this->_language->get('alias_empty');
200
		}
201 1
		else if (!$aliasValidator->validate($postArray['alias']) || $aliasValidator->matchSystem($postArray['alias']))
202
		{
203 11
			$validateArray[] = $this->_language->get('alias_incorrect');
204
		}
205 7
		else if (!$articleModel->isUniqueByIdAndAlias($postArray['id'], $postArray['alias']))
206
		{
207 11
			$validateArray[] = $this->_language->get('alias_exists');
208
		}
209
		if (!$postArray['text'])
210
		{
211
			$validateArray[] = $this->_language->get('article_empty');
212
		}
213
		return $validateArray;
214
	}
215
216
	/**
217
	 * create the article
218
	 *
219
	 * @since 4.0.0
220 1
	 *
221
	 * @param array $createArray array of the create
222 1
	 *
223 1
	 * @return bool
224
	 */
225
226
	protected function _create(array $createArray = []) : bool
227
	{
228
		$articleModel = new Admin\Model\Article();
229
		return $articleModel->createByArray($createArray);
230
	}
231
232
	/**
233
	 * update the article
234
	 *
235
	 * @since 4.0.0
236
	 *
237 2
	 * @param int $articleId identifier of the article
238
	 * @param array $updateArray array of the update
239 2
	 *
240 2
	 * @return bool
241
	 */
242
243
	protected function _update(int $articleId = null, array $updateArray = []) : bool
244
	{
245
		$articleModel = new Admin\Model\Article();
246
		return $articleModel->updateByIdAndArray($articleId, $updateArray);
247
	}
248
249
	/**
250
	 * get success route
251
	 *
252
	 * @since 4.0.0
253 3
	 *
254
	 * @param array $postArray array of the post
255 3
	 *
256
	 * @return string
257 1
	 */
258
259 2
	protected function _getSuccessRoute(array $postArray = []) : string
260
	{
261 1
		if ($this->_registry->get('articlesEdit') && $postArray['id'])
262 1
		{
263
			return 'admin/view/articles#row-' . $postArray['id'];
264 1
		}
265
		if ($this->_registry->get('articlesEdit') && $postArray['alias'])
266
		{
267
			$articleModel = new Admin\Model\Article();
268
			return 'admin/view/articles#row-' . $articleModel->getByAlias($postArray['alias'])->id;
269
		}
270
		return 'admin';
271
	}
272
273
	/**
274
	 * get error route
275
	 *
276
	 * @since 4.0.0
277 8
	 *
278
	 * @param array $postArray array of the post
279 8
	 *
280
	 * @return string
281 2
	 */
282
283 6
	protected function _getErrorRoute(array $postArray = []) : string
284
	{
285 5
		if ($this->_registry->get('articlesEdit') && $postArray['id'])
286
		{
287 1
			return 'admin/edit/articles/' . $postArray['id'];
288
		}
289
		if ($this->_registry->get('articlesNew'))
290
		{
291
			return 'admin/new/articles';
292
		}
293
		return 'admin';
294
	}
295
}
296