cvs: bugtracker /htdocs/index index.php /includes functions.php sanitize.php /template/generic header.html /template/generic/bug index.php

From: Date: Thu, 31 Jul 2008 02:38:33 +0000
Subject: cvs: bugtracker /htdocs/index index.php /includes functions.php sanitize.php /template/generic header.html /template/generic/bug index.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-2251@lists.php.net to get a copy of this message
bcarlyon Thu Jul 31 02:38:33 2008 UTC Added files: /bugtracker/includes sanitize.php Modified files: /bugtracker/htdocs/index index.php /bugtracker/includes functions.php /bugtracker/template/generic header.html /bugtracker/template/generic/bug index.php Log: macking backup commit, as computer just 'panic' over a disk error... http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/index/index.php?r1=1.11&r2=1.12&diff_format=u Index: bugtracker/htdocs/index/index.php diff -u bugtracker/htdocs/index/index.php:1.11 bugtracker/htdocs/index/index.php:1.12 --- bugtracker/htdocs/index/index.php:1.11 Sat Jul 26 02:41:21 2008 +++ bugtracker/htdocs/index/index.php Thu Jul 31 02:38:33 2008 @@ -70,6 +70,7 @@ $php_version[0] = 'Irrelevant'; $form_data = array();//array for holding the data in forms +$display_data = array();// array for holding all the display data that users could of entered $template_data = array_merge($template_data, array( 'page_title' => 'PHP Bugs', 'content_title' => '', @@ -204,6 +205,15 @@ print_r($_COOKIE); echo ' +display +'; +//print_r($template_data); +foreach ($display_data as $ref => $data) +{ +echo $ref . ' - ' . htmlentities($data) . "\n"; +} + +echo ' tpl '; //print_r($template_data); http://cvs.php.net/viewvc.cgi/bugtracker/includes/functions.php?r1=1.11&r2=1.12&diff_format=u Index: bugtracker/includes/functions.php diff -u bugtracker/includes/functions.php:1.11 bugtracker/includes/functions.php:1.12 --- bugtracker/includes/functions.php:1.11 Sat Jul 26 02:41:21 2008 +++ bugtracker/includes/functions.php Thu Jul 31 02:38:33 2008 @@ -31,12 +31,14 @@ } //function tpl_process($file, $text, $jsscripts = FALSE, $meta_refresh = FALSE) { +include($_SERVER['DOCUMENT_ROOT'] . '../includes/sanitize.php'); function tpl_process($file, $jsscripts = FALSE, $meta_refresh = FALSE) { $ext = explode(".",$file); //base it on the file extension trace('I am tpl_processing '); - global $template_data,$form_data; + global $template_data,$form_data,$display_data; + // if ($text) $ext = isset($ext[1]) ? $ext[1] : ''; if ($ext == 'html') @@ -60,6 +62,15 @@ if (!empty($template_data['form_error'])) trace('form error where there should be nonw'); + //sanitize +// $file = $_SERVER['DOCUMENT_ROOT'] . '../template/' . $file; +// $html = api_helpers_html::renderTemplate($file,$display_data,'html'); + + foreach ($display_data as $ref => $replace) { + $display_data[$ref] = htmlentities($display_data[$ref], ENT_QUOTES, 'UTF-8'); + $html = str_replace('{' . strtoupper($ref) . '}',$replace,$html); + } + foreach ($template_data as $ref => $replace) { trace('tpl ' . $ref); http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/header.html?r1=1.4&r2=1.5&diff_format=u Index: bugtracker/template/generic/header.html diff -u bugtracker/template/generic/header.html:1.4 bugtracker/template/generic/header.html:1.5 --- bugtracker/template/generic/header.html:1.4 Sat Jul 26 02:33:43 2008 +++ bugtracker/template/generic/header.html Thu Jul 31 02:38:33 2008 @@ -65,5 +65,4 @@ <a name="content"></a><h2>{CONTENT_TITLE}</h2> {SYSTEM_ERROR} -{FORM_ERROR} http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/bug/index.php?r1=1.13&r2=1.14&diff_format=u Index: bugtracker/template/generic/bug/index.php diff -u bugtracker/template/generic/bug/index.php:1.13 bugtracker/template/generic/bug/index.php:1.14 --- bugtracker/template/generic/bug/index.php:1.13 Sat Jul 26 02:33:43 2008 +++ bugtracker/template/generic/bug/index.php Thu Jul 31 02:38:33 2008 @@ -56,7 +56,11 @@ $row['password'] = ''; $template_data['page_title'] .= ' - #' . $bug->bug_id . ' ' . $bug_row['summary']; - + +//shunt to dispplay +$display_data['dsp_summary'] = $bug_row['summary']; +$display_data['dsp_description'] = $bug_row['description']; + $content .= '<h2>Bug Display</h2>'; //ie fix???? $content .= ' @@ -69,7 +73,7 @@ <table id="bug"> <tr> <td style="width: 100px;">&nbsp;</td> <td style="width: 80px;">&nbsp;</td> <td style="width: 180px;">&nbsp;</td> <td style="width: 150px;">&nbsp;</td></tr> -<tr> <td>Bug: #' . $bug_row['bug_id'] . '</td> <td colspan="2" style="width: 220px;">' . $bug_row['summary'] . '</td> <td>Reported By:<br /><strong>' . $bug_row['reported_by'] . '</strong></td> </tr> +<tr> <td>Bug: #' . $bug_row['bug_id'] . '</td> <td colspan="2" style="width: 220px;">{DSP_SUMMARY}</td> <td>Reported By:<br /><strong>' . $bug_row['reported_by'] . '</strong></td> </tr> <tr> <td><h4>' . $status[$bug_row['status']] . '</h4></td> <td>Opened:</td> <td colspan="2">' . date('d/m/Y H:i O',$bug_row['UNIX_TIMESTAMP(reported_on)']) . '</td> </tr> '; if ($bug_row['UNIX_TIMESTAMP(updated)'] != $bug_row['UNIX_TIMESTAMP(reported_on)']) @@ -85,8 +89,9 @@ <tr> <td></td> <td colspan="2" style="text-align: right;">Version:</td> <td>' . $php_version[$row['php_version']] .'</td> </tr> <tr> <td></td> <td colspan="2" style="text-align: right;">Type:</td> <td>' . $bug_type[$row['bug_type']] . '</td> </tr> <tr> <td></td> <td colspan="2" style="text-align: right;">OS:</td> <td>' . $os_version[$row['os_version']] . '</td> </tr> -<tr> <td></td> <td colspan="3" id="description">' . $bug_row['description'] . '</td> </tr> +<tr> <td></td> <td colspan="3" id="description">{dsp_description}</td> </tr> '; + //extra basic comments if (isset($bug_row['reproduce'])) { http://cvs.php.net/viewvc.cgi/bugtracker/includes/sanitize.php?view=markup&rev=1.1 Index: bugtracker/includes/sanitize.php +++ bugtracker/includes/sanitize.php <?php class api_helpers_html { /** * Template parameters set during the execution of template rendering */ static private $raw; /** * Default escaping */ static private $escaping = 'html'; /** * Escaping for the current execution */ static private $escapingTmp = 'html'; /** * 2 Letter code of the language set during the execution of template rendering */ static public $lang; /** * Template translation strings set during the execution of template rendering */ static public $trans; /** * set default escaping * * @param string escaping (html, json, javascript ..) * * @return void */ public static function setEscaping($escaping) { self::$escaping = $escaping; } /** * set default escaping * * @param mixed raw value to be escaped * @param string escaping (html, json, javascript ..) * * @return void */ public static function escapeVariable($raw, $escaping) { // TODO: add support for objects if (is_array($raw)) { foreach ($raw as $key => $var) { $raw[$key] = self::escapeVariable($var, $escaping); } } else { switch ($escaping) { case 'html': $raw = htmlentities($raw, ENT_QUOTES, 'UTF-8'); break; case 'json': default: break; } } return $raw; } /** * render a template * * @param string the template file to be compiled. * @param array this is the array of variables to pass to the template * @param string escaping (html, json, javascript ..) * * @return string the rendered content */ public static function renderTemplate() { self::$escapingTmp = func_get_arg(2); if (func_num_args() > 1 && is_array(func_get_arg(1))) { self::$raw = func_get_arg(1); if (func_get_arg(2) !== null) { extract(self::escapeVariable(self::$raw, self::$escapingTmp)); } else { extract(self::escapeVariable(self::$raw, self::$escaping)); } } $lang = self::$lang; if (func_get_arg(2) !== null) { $trans = self::escapeVariable(self::$trans, self::$escapingTmp); } else { $trans = self::escapeVariable(self::$trans, self::$escaping); } ob_start(); include func_get_arg(0); $content = ob_get_contents(); ob_end_clean(); return $content; } } ?>

« previous php.webmaster (#2251) next »