cvs: bugtracker /htdocs/index index.php /includes functions.php sanitize.php /template/generic header.html /template/generic/bug index.php
| From: | Barry Carlyon | Date: | Thu, 31 Jul 2008 02:38:33 +0000 |
| Subject: | cvs: bugtracker /htdocs/index index.php /includes functions.php sanitize.php /template/generic header.html /template/generic/bug index.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-2251@lists.php.net to get a copy of this message | ||
bcarlyon Thu Jul 31 02:38:33 2008 UTC
Added files:
/bugtracker/includes sanitize.php
Modified files:
/bugtracker/htdocs/index index.php
/bugtracker/includes functions.php
/bugtracker/template/generic header.html
/bugtracker/template/generic/bug index.php
Log:
macking backup commit, as computer just 'panic' over a disk error...
http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/index/index.php?r1=1.11&r2=1.12&diff_format=u
Index: bugtracker/htdocs/index/index.php
diff -u bugtracker/htdocs/index/index.php:1.11 bugtracker/htdocs/index/index.php:1.12
--- bugtracker/htdocs/index/index.php:1.11 Sat Jul 26 02:41:21 2008
+++ bugtracker/htdocs/index/index.php Thu Jul 31 02:38:33 2008
@@ -70,6 +70,7 @@
$php_version[0] = 'Irrelevant';
$form_data = array();//array for holding the data in forms
+$display_data = array();// array for holding all the display data that users could of entered
$template_data = array_merge($template_data, array(
'page_title' => 'PHP Bugs',
'content_title' => '',
@@ -204,6 +205,15 @@
print_r($_COOKIE);
echo '
+display
+';
+//print_r($template_data);
+foreach ($display_data as $ref => $data)
+{
+echo $ref . ' - ' . htmlentities($data) . "\n";
+}
+
+echo '
tpl
';
//print_r($template_data);
http://cvs.php.net/viewvc.cgi/bugtracker/includes/functions.php?r1=1.11&r2=1.12&diff_format=u
Index: bugtracker/includes/functions.php
diff -u bugtracker/includes/functions.php:1.11 bugtracker/includes/functions.php:1.12
--- bugtracker/includes/functions.php:1.11 Sat Jul 26 02:41:21 2008
+++ bugtracker/includes/functions.php Thu Jul 31 02:38:33 2008
@@ -31,12 +31,14 @@
}
//function tpl_process($file, $text, $jsscripts = FALSE, $meta_refresh = FALSE) {
+include($_SERVER['DOCUMENT_ROOT'] . '../includes/sanitize.php');
function tpl_process($file, $jsscripts = FALSE, $meta_refresh = FALSE) {
$ext = explode(".",$file);
//base it on the file extension
trace('I am tpl_processing ');
- global $template_data,$form_data;
+ global $template_data,$form_data,$display_data;
+
// if ($text)
$ext = isset($ext[1]) ? $ext[1] : '';
if ($ext == 'html')
@@ -60,6 +62,15 @@
if (!empty($template_data['form_error']))
trace('form error where there should be nonw');
+ //sanitize
+// $file = $_SERVER['DOCUMENT_ROOT'] . '../template/' . $file;
+// $html = api_helpers_html::renderTemplate($file,$display_data,'html');
+
+ foreach ($display_data as $ref => $replace) {
+ $display_data[$ref] = htmlentities($display_data[$ref], ENT_QUOTES, 'UTF-8');
+ $html = str_replace('{' . strtoupper($ref) . '}',$replace,$html);
+ }
+
foreach ($template_data as $ref => $replace)
{
trace('tpl ' . $ref);
http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/header.html?r1=1.4&r2=1.5&diff_format=u
Index: bugtracker/template/generic/header.html
diff -u bugtracker/template/generic/header.html:1.4 bugtracker/template/generic/header.html:1.5
--- bugtracker/template/generic/header.html:1.4 Sat Jul 26 02:33:43 2008
+++ bugtracker/template/generic/header.html Thu Jul 31 02:38:33 2008
@@ -65,5 +65,4 @@
<a name="content"></a><h2>{CONTENT_TITLE}</h2>
{SYSTEM_ERROR}
-{FORM_ERROR}
http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/bug/index.php?r1=1.13&r2=1.14&diff_format=u
Index: bugtracker/template/generic/bug/index.php
diff -u bugtracker/template/generic/bug/index.php:1.13
bugtracker/template/generic/bug/index.php:1.14
--- bugtracker/template/generic/bug/index.php:1.13 Sat Jul 26 02:33:43 2008
+++ bugtracker/template/generic/bug/index.php Thu Jul 31 02:38:33 2008
@@ -56,7 +56,11 @@
$row['password'] = '';
$template_data['page_title'] .= ' - #' . $bug->bug_id . ' ' .
$bug_row['summary'];
-
+
+//shunt to dispplay
+$display_data['dsp_summary'] = $bug_row['summary'];
+$display_data['dsp_description'] = $bug_row['description'];
+
$content .= '<h2>Bug Display</h2>';
//ie fix????
$content .= '
@@ -69,7 +73,7 @@
<table id="bug">
<tr> <td style="width: 100px;"> </td> <td
style="width: 80px;"> </td> <td style="width:
180px;"> </td> <td style="width:
150px;"> </td></tr>
-<tr> <td>Bug: #' . $bug_row['bug_id'] . '</td> <td
colspan="2" style="width: 220px;">' . $bug_row['summary'] .
'</td> <td>Reported By:<br /><strong>' .
$bug_row['reported_by'] . '</strong></td> </tr>
+<tr> <td>Bug: #' . $bug_row['bug_id'] . '</td> <td
colspan="2" style="width: 220px;">{DSP_SUMMARY}</td> <td>Reported
By:<br /><strong>' . $bug_row['reported_by'] .
'</strong></td> </tr>
<tr> <td><h4>' . $status[$bug_row['status']] .
'</h4></td> <td>Opened:</td> <td colspan="2">' .
date('d/m/Y H:i O',$bug_row['UNIX_TIMESTAMP(reported_on)']) . '</td>
</tr>
';
if ($bug_row['UNIX_TIMESTAMP(updated)'] !=
$bug_row['UNIX_TIMESTAMP(reported_on)'])
@@ -85,8 +89,9 @@
<tr> <td></td> <td colspan="2" style="text-align:
right;">Version:</td> <td>' . $php_version[$row['php_version']]
.'</td> </tr>
<tr> <td></td> <td colspan="2" style="text-align:
right;">Type:</td> <td>' . $bug_type[$row['bug_type']] .
'</td> </tr>
<tr> <td></td> <td colspan="2" style="text-align:
right;">OS:</td> <td>' . $os_version[$row['os_version']] .
'</td> </tr>
-<tr> <td></td> <td colspan="3" id="description">'
. $bug_row['description'] . '</td> </tr>
+<tr> <td></td> <td colspan="3"
id="description">{dsp_description}</td> </tr>
';
+
//extra basic comments
if (isset($bug_row['reproduce']))
{
http://cvs.php.net/viewvc.cgi/bugtracker/includes/sanitize.php?view=markup&rev=1.1
Index: bugtracker/includes/sanitize.php
+++ bugtracker/includes/sanitize.php
<?php
class api_helpers_html {
/**
* Template parameters set during the execution of template rendering
*/
static private $raw;
/**
* Default escaping
*/
static private $escaping = 'html';
/**
* Escaping for the current execution
*/
static private $escapingTmp = 'html';
/**
* 2 Letter code of the language set during the execution of template rendering
*/
static public $lang;
/**
* Template translation strings set during the execution of template rendering
*/
static public $trans;
/**
* set default escaping
*
* @param string escaping (html, json, javascript ..)
*
* @return void
*/
public static function setEscaping($escaping) {
self::$escaping = $escaping;
}
/**
* set default escaping
*
* @param mixed raw value to be escaped
* @param string escaping (html, json, javascript ..)
*
* @return void
*/
public static function escapeVariable($raw, $escaping) {
// TODO: add support for objects
if (is_array($raw)) {
foreach ($raw as $key => $var) {
$raw[$key] = self::escapeVariable($var, $escaping);
}
} else {
switch ($escaping) {
case 'html':
$raw = htmlentities($raw, ENT_QUOTES, 'UTF-8');
break;
case 'json':
default:
break;
}
}
return $raw;
}
/**
* render a template
*
* @param string the template file to be compiled.
* @param array this is the array of variables to pass to the template
* @param string escaping (html, json, javascript ..)
*
* @return string the rendered content
*/
public static function renderTemplate() {
self::$escapingTmp = func_get_arg(2);
if (func_num_args() > 1 && is_array(func_get_arg(1))) {
self::$raw = func_get_arg(1);
if (func_get_arg(2) !== null) {
extract(self::escapeVariable(self::$raw, self::$escapingTmp));
} else {
extract(self::escapeVariable(self::$raw, self::$escaping));
}
}
$lang = self::$lang;
if (func_get_arg(2) !== null) {
$trans = self::escapeVariable(self::$trans, self::$escapingTmp);
} else {
$trans = self::escapeVariable(self::$trans, self::$escaping);
}
ob_start();
include func_get_arg(0);
$content = ob_get_contents();
ob_end_clean();
return $content;
}
}
?>