summaryrefslogtreecommitdiff
path: root/modules/gallery
diff options
context:
space:
mode:
authorTim Almdal <tnalmdal@shaw.ca>2009-07-03 21:44:10 -0700
committerTim Almdal <tnalmdal@shaw.ca>2009-07-03 21:44:10 -0700
commit54ffea24196e8f5d88cf9d8607455f0f6aab305c (patch)
treefc0443ec5b8976d154134f667e21adb80cfea06d /modules/gallery
parenta633c134b754305eaa611c5d67af4ca7c79beafe (diff)
Split the clean method into two clean and purify. clean is a light weight
approach using html::specialchars and purify uses HTMLPurifier to intelligently cleanse the output fields. Use purifier for text and title fields where it is likely that a user would enter html to format their data.
Diffstat (limited to 'modules/gallery')
-rw-r--r--modules/gallery/controllers/quick.php10
-rw-r--r--modules/gallery/helpers/p.php4
-rw-r--r--modules/gallery/views/permissions_browse.html.php2
-rw-r--r--modules/gallery/views/simple_uploader.html.php6
4 files changed, 13 insertions, 9 deletions
diff --git a/modules/gallery/controllers/quick.php b/modules/gallery/controllers/quick.php
index 5d3d8885..53af2ba6 100644
--- a/modules/gallery/controllers/quick.php
+++ b/modules/gallery/controllers/quick.php
@@ -89,7 +89,7 @@ class Quick_Controller extends Controller {
access::required("view", $item->parent());
access::required("edit", $item->parent());
- $msg = t("Made <b>%title</b> this album's cover", array("title" => p::clean($item->title)));
+ $msg = t("Made <b>%title</b> this album's cover", array("title" => p::purify($item->title)));
item::make_album_cover($item);
message::success($msg);
@@ -105,10 +105,10 @@ class Quick_Controller extends Controller {
if ($item->is_album()) {
print t(
"Delete the album <b>%title</b>? All photos and movies in the album will also be deleted.",
- array("title" => p::clean($item->title)));
+ array("title" => p::purify($item->title)));
} else {
print t("Are you sure you want to delete <b>%title</b>?",
- array("title" => p::clean($item->title)));
+ array("title" => p::purify($item->title)));
}
$form = item::get_delete_form($item);
@@ -122,9 +122,9 @@ class Quick_Controller extends Controller {
access::required("edit", $item);
if ($item->is_album()) {
- $msg = t("Deleted album <b>%title</b>", array("title" => p::clean($item->title)));
+ $msg = t("Deleted album <b>%title</b>", array("title" => p::purify($item->title)));
} else {
- $msg = t("Deleted photo <b>%title</b>", array("title" => p::clean($item->title)));
+ $msg = t("Deleted photo <b>%title</b>", array("title" => p::purify($item->title)));
}
$item->delete();
diff --git a/modules/gallery/helpers/p.php b/modules/gallery/helpers/p.php
index fe53102c..862c769b 100644
--- a/modules/gallery/helpers/p.php
+++ b/modules/gallery/helpers/p.php
@@ -20,6 +20,10 @@
class p_Core {
private static $_purifier = null;
static function clean($dirty_html) {
+ return html::specialchars($dirty_html);
+ }
+
+ static function purify($dirty_html) {
if (empty(self::$_purifier)) {
require_once(dirname(__file__) . "/../lib/HTMLPurifier/HTMLPurifier.auto.php");
$config = HTMLPurifier_Config::createDefault();
diff --git a/modules/gallery/views/permissions_browse.html.php b/modules/gallery/views/permissions_browse.html.php
index 36394877..888a27f7 100644
--- a/modules/gallery/views/permissions_browse.html.php
+++ b/modules/gallery/views/permissions_browse.html.php
@@ -42,7 +42,7 @@
<? endforeach ?>
<li>
<a href="javascript:show(<?= $item->id ?>)">
- <?= p::clean($item->title) ?>
+ <?= p::purify($item->title) ?>
</a>
<div class="form" id="edit-<?= $item->id ?>">
<?= $form ?>
diff --git a/modules/gallery/views/simple_uploader.html.php b/modules/gallery/views/simple_uploader.html.php
index eee29679..56b1c656 100644
--- a/modules/gallery/views/simple_uploader.html.php
+++ b/modules/gallery/views/simple_uploader.html.php
@@ -6,7 +6,7 @@
<!-- hack to set the title for the dialog -->
<form id="gAddPhotosForm" action="<?= url::site("simple_uploader/finish?csrf=$csrf") ?>">
<fieldset>
- <legend> <?= t("Add photos to %album_title", array("album_title" => p::clean($item->title))) ?> </legend>
+ <legend> <?= t("Add photos to %album_title", array("album_title" => p::purify($item->title))) ?> </legend>
</fieldset>
</form>
@@ -28,7 +28,7 @@
<? foreach ($item->parents() as $parent): ?>
<li> <?= p::clean($parent->title) ?> </li>
<? endforeach ?>
- <li class="active"> <?= p::clean($item->title) ?> </li>
+ <li class="active"> <?= p::purify($item->title) ?> </li>
</ul>
<p>
@@ -185,7 +185,7 @@
$("#gUploadQueueInfo").text("(completed " + stats.successful_uploads +
" of " + (stats.files_queued + stats.successful_uploads + stats.upload_errors + stats.upload_cancelled + stats.queue_errors) + ")");
}
-
+
// Auto start the upload
this.startUpload();
}