diff options
author | Tim Almdal <tnalmdal@shaw.ca> | 2009-07-03 21:44:10 -0700 |
---|---|---|
committer | Tim Almdal <tnalmdal@shaw.ca> | 2009-07-03 21:44:10 -0700 |
commit | 54ffea24196e8f5d88cf9d8607455f0f6aab305c (patch) | |
tree | fc0443ec5b8976d154134f667e21adb80cfea06d /modules/gallery | |
parent | a633c134b754305eaa611c5d67af4ca7c79beafe (diff) |
Split the clean method into two clean and purify. clean is a light weight
approach using html::specialchars and purify uses HTMLPurifier to intelligently
cleanse the output fields. Use purifier for text and title fields where it is
likely that a user would enter html to format their data.
Diffstat (limited to 'modules/gallery')
-rw-r--r-- | modules/gallery/controllers/quick.php | 10 | ||||
-rw-r--r-- | modules/gallery/helpers/p.php | 4 | ||||
-rw-r--r-- | modules/gallery/views/permissions_browse.html.php | 2 | ||||
-rw-r--r-- | modules/gallery/views/simple_uploader.html.php | 6 |
4 files changed, 13 insertions, 9 deletions
diff --git a/modules/gallery/controllers/quick.php b/modules/gallery/controllers/quick.php index 5d3d8885..53af2ba6 100644 --- a/modules/gallery/controllers/quick.php +++ b/modules/gallery/controllers/quick.php @@ -89,7 +89,7 @@ class Quick_Controller extends Controller { access::required("view", $item->parent()); access::required("edit", $item->parent()); - $msg = t("Made <b>%title</b> this album's cover", array("title" => p::clean($item->title))); + $msg = t("Made <b>%title</b> this album's cover", array("title" => p::purify($item->title))); item::make_album_cover($item); message::success($msg); @@ -105,10 +105,10 @@ class Quick_Controller extends Controller { if ($item->is_album()) { print t( "Delete the album <b>%title</b>? All photos and movies in the album will also be deleted.", - array("title" => p::clean($item->title))); + array("title" => p::purify($item->title))); } else { print t("Are you sure you want to delete <b>%title</b>?", - array("title" => p::clean($item->title))); + array("title" => p::purify($item->title))); } $form = item::get_delete_form($item); @@ -122,9 +122,9 @@ class Quick_Controller extends Controller { access::required("edit", $item); if ($item->is_album()) { - $msg = t("Deleted album <b>%title</b>", array("title" => p::clean($item->title))); + $msg = t("Deleted album <b>%title</b>", array("title" => p::purify($item->title))); } else { - $msg = t("Deleted photo <b>%title</b>", array("title" => p::clean($item->title))); + $msg = t("Deleted photo <b>%title</b>", array("title" => p::purify($item->title))); } $item->delete(); diff --git a/modules/gallery/helpers/p.php b/modules/gallery/helpers/p.php index fe53102c..862c769b 100644 --- a/modules/gallery/helpers/p.php +++ b/modules/gallery/helpers/p.php @@ -20,6 +20,10 @@ class p_Core { private static $_purifier = null; static function clean($dirty_html) { + return html::specialchars($dirty_html); + } + + static function purify($dirty_html) { if (empty(self::$_purifier)) { require_once(dirname(__file__) . "/../lib/HTMLPurifier/HTMLPurifier.auto.php"); $config = HTMLPurifier_Config::createDefault(); diff --git a/modules/gallery/views/permissions_browse.html.php b/modules/gallery/views/permissions_browse.html.php index 36394877..888a27f7 100644 --- a/modules/gallery/views/permissions_browse.html.php +++ b/modules/gallery/views/permissions_browse.html.php @@ -42,7 +42,7 @@ <? endforeach ?> <li> <a href="javascript:show(<?= $item->id ?>)"> - <?= p::clean($item->title) ?> + <?= p::purify($item->title) ?> </a> <div class="form" id="edit-<?= $item->id ?>"> <?= $form ?> diff --git a/modules/gallery/views/simple_uploader.html.php b/modules/gallery/views/simple_uploader.html.php index eee29679..56b1c656 100644 --- a/modules/gallery/views/simple_uploader.html.php +++ b/modules/gallery/views/simple_uploader.html.php @@ -6,7 +6,7 @@ <!-- hack to set the title for the dialog --> <form id="gAddPhotosForm" action="<?= url::site("simple_uploader/finish?csrf=$csrf") ?>"> <fieldset> - <legend> <?= t("Add photos to %album_title", array("album_title" => p::clean($item->title))) ?> </legend> + <legend> <?= t("Add photos to %album_title", array("album_title" => p::purify($item->title))) ?> </legend> </fieldset> </form> @@ -28,7 +28,7 @@ <? foreach ($item->parents() as $parent): ?> <li> <?= p::clean($parent->title) ?> </li> <? endforeach ?> - <li class="active"> <?= p::clean($item->title) ?> </li> + <li class="active"> <?= p::purify($item->title) ?> </li> </ul> <p> @@ -185,7 +185,7 @@ $("#gUploadQueueInfo").text("(completed " + stats.successful_uploads + " of " + (stats.files_queued + stats.successful_uploads + stats.upload_errors + stats.upload_cancelled + stats.queue_errors) + ")"); } - + // Auto start the upload this.startUpload(); } |