Don't try to convert non-IP to uint.
[platal.git] / classes / platalpage.php
CommitLineData
0337d704 1<?php
2/***************************************************************************
179afa7f 3 * Copyright (C) 2003-2008 Polytechnique.org *
0337d704 4 * http://opensource.polytechnique.org/ *
5 * *
6 * This program is free software; you can redistribute it and/or modify *
7 * it under the terms of the GNU General Public License as published by *
8 * the Free Software Foundation; either version 2 of the License, or *
9 * (at your option) any later version. *
10 * *
11 * This program is distributed in the hope that it will be useful, *
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
14 * GNU General Public License for more details. *
15 * *
16 * You should have received a copy of the GNU General Public License *
17 * along with this program; if not, write to the Free Software *
18 * Foundation, Inc., *
19 * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA *
20 ***************************************************************************/
21
f12af8ad 22require_once 'smarty/libs/Smarty.class.php';
0337d704 23
1490093c 24abstract class PlatalPage extends Smarty
0337d704 25{
2b1ee50b 26 private $_page_type;
27 private $_tpl;
28 private $_errors;
29 private $_failure;
4a8a1e0a 30 private $_jsonVars;
0337d704 31
0337d704 32 // {{{ function PlatalPage()
33
2b1ee50b 34 public function __construct($tpl, $type = SKINNED)
0337d704 35 {
2b1ee50b 36 parent::Smarty();
0337d704 37
2b1ee50b 38 global $globals;
796aea34 39
abe7e055 40 $this->caching = false;
41 $this->config_overwrite = false;
42 $this->use_sub_dirs = false;
0337d704 43 $this->template_dir = $globals->spoolroot."/templates/";
7faf6e6a 44 $this->compile_dir = $globals->spoolroot."/spool/templates_c/";
0337d704 45 array_unshift($this->plugins_dir, $globals->spoolroot."/plugins/");
46 $this->config_dir = $globals->spoolroot."/configs/";
47
48 $this->compile_check = !empty($globals->debug);
49
1490093c 50 $this->changeTpl($tpl, $type);
860fdaec 51 $this->_errors = array();
4a8a1e0a 52 $this->_jsonVars = array();
860fdaec 53 $this->_failure = false;
0337d704 54
fe556813
FB
55 if ($globals->mode != 'rw') {
56 $this->_errors[] = "En raison d'une maintenance, une partie des fonctionnalités du site sont actuellement"
57 . " désactivée, en particuliers aucune donnée ne sera sauvegardée";
58 }
0337d704 59 $this->register_prefilter('at_to_globals');
60979eb7 60 $this->addJsLink('xorg.js');
4b4b4b67 61 $this->addJsLink('jquery.js');
0337d704 62 }
63
64 // }}}
65 // {{{ function changeTpl()
66
2b1ee50b 67 public function changeTpl($tpl, $type = SKINNED)
0337d704 68 {
c1895524
FB
69 $this->_tpl = $tpl;
70 $this->_page_type = $type;
71 $this->assign('xorg_tpl', $tpl);
0337d704 72 }
73
74 // }}}
e654517d 75 // {{{ function raw()
76
77 public function raw()
78 {
79 global $globals;
80 $this->assign('globals', $globals);
81 return $this->fetch($this->_tpl);
82 }
83
84 // }}}
0337d704 85 // {{{ function _run()
86
2b1ee50b 87 protected function _run($skin)
0337d704 88 {
89 global $globals, $TIME_BEGIN;
36f114ef 90
91 session_write_close();
92
e654517d 93 $this->register_prefilter('trimwhitespace');
94 $this->register_prefilter('form_force_encodings');
7a3f546b 95 $this->register_prefilter('wiki_include');
908db125 96 $this->register_prefilter('if_has_perms');
6995a9b9 97 $this->assign('xorg_errors', $this->_errors);
98 $this->assign('xorg_failure', $this->_failure);
d083f500 99 $this->assign('globals', $globals);
a3a049fc 100
4a8a1e0a 101 if (Env::has('json') && count($this->_jsonVars)) {
102 return $this->jsonDisplay();
103 }
eaf30d86 104
8a105df2 105 if (Env::v('display') == 'light') {
106 $this->_page_type = SIMPLE;
107 } elseif (Env::v('display') == 'raw') {
108 $this->_page_type = NO_SKIN;
109 } elseif (Env::v('display') == 'full') {
110 $this->_page_typ = SKINNED;
111 }
112
62a66dfc 113 switch ($this->_page_type) {
114 case NO_SKIN:
81e9c63f 115 if (!($globals->debug & DEBUG_SMARTY)) {
116 error_reporting(0);
117 }
0337d704 118 $this->display($this->_tpl);
119 exit;
62a66dfc 120
121 case SIMPLE:
c6db254a 122 $this->assign('simple', true);
bf2e1ab0 123
62a66dfc 124 case SKINNED:
b4ee37a4
FB
125 $this->register_modifier('escape_html', 'escape_html');
126 $this->default_modifiers = Array('@escape_html');
0337d704 127 }
5aa58639
FB
128 if (S::i('auth') <= AUTH_PUBLIC) {
129 $this->register_outputfilter('hide_emails');
130 }
bf2e1ab0 131 $this->addJsLink('wiki.js');
493b6abe 132 header("Accept-Charset: utf-8");
4a8a1e0a 133 if (Env::v('forceXml')) {
134 header("Content-Type: text/xml; charset=utf-8");
135 }
b4315e15 136
137 if (!$globals->debug) {
6995a9b9 138 error_reporting(0);
b4315e15 139 $this->display($skin);
140 exit;
141 }
a3a049fc 142
7da8ef90 143 $this->assign('validate', true);
81e9c63f 144 if (!($globals->debug & DEBUG_SMARTY)) {
145 error_reporting(0);
146 }
040a594c 147 $START_SMARTY = microtime(true);
b4315e15 148 $result = $this->fetch($skin);
040a594c
FB
149 $ttime = sprintf('Temps total: %.02fs (Smarty %.02fs) - Mémoire totale : %dKo<br />',
150 microtime(true) - $TIME_BEGIN, microtime(true) - $START_SMARTY,
151 memory_get_peak_usage(true) / 1024);
b4ee37a4
FB
152 if ($globals->debug & DEBUG_BT) {
153 PlBacktrace::clean();
154 $this->assign_by_ref('backtraces', PlBacktrace::$bt);
155 $result = str_replace('@@BACKTRACE@@', $this->fetch('skin/common.backtrace.tpl'), $result);
156 } else {
157 $result = str_replace('@@BACKTRACE@@', '', $result);
158 }
0337d704 159
b4ee37a4 160 $replc = "<span class='erreur'>VALIDATION HTML INACTIVE</span><br />";
81e9c63f 161 if ($globals->debug & DEBUG_VALID) {
b4315e15 162 $fd = fopen($this->compile_dir."/valid.html","w");
163 fwrite($fd, $result);
164 fclose($fd);
a3a049fc 165
b4315e15 166 exec($globals->spoolroot."/bin/devel/xhtml.validate.pl ".$this->compile_dir."/valid.html", $val);
167 foreach ($val as $h) {
168 if (preg_match("/^X-W3C-Validator-Errors: (\d+)$/", $h, $m)) {
169 $replc = '<span style="color: #080;">HTML OK</span><br />';
170 if ($m[1]) {
171 $replc = "<span class='erreur'><a href='http://validator.w3.org/check?uri={$globals->baseurl}"
172 ."/valid.html&amp;ss=1#result'>{$m[1]} ERREUR(S) !!!</a></span><br />";
0337d704 173 }
b4315e15 174 break;
0337d704 175 }
176 }
0337d704 177 }
178
b4315e15 179 echo str_replace("@HOOK@", $ttime.$replc, $result);
0337d704 180 exit;
181 }
182
1490093c 183 abstract public function run();
184
0337d704 185 // }}}
0337d704 186 // {{{ function nb_errs()
187
2b1ee50b 188 public function nb_errs()
0337d704 189 {
860fdaec 190 return count($this->_errors);
0337d704 191 }
192
193 // }}}
194 // {{{ function trig()
195
2b1ee50b 196 public function trig($msg)
0337d704 197 {
860fdaec 198 $this->_errors[] = $msg;
0337d704 199 }
200
201 // }}}
0337d704 202 // {{{ function kill()
203
2b1ee50b 204 public function kill($msg)
0337d704 205 {
90eba1aa 206 global $platal;
207
208 $this->assign('platal', $platal);
0fcbe8d0 209 $this->trig($msg);
210 $this->_failure = true;
0337d704 211 $this->run();
212 }
213
214 // }}}
0337d704 215 // {{{ function addJsLink
216
2b1ee50b 217 public function addJsLink($path)
0337d704 218 {
219 $this->append('xorg_js', $path);
220 }
221
222 // }}}
223 // {{{ function addCssLink
224
2b1ee50b 225 public function addCssLink($path)
0337d704 226 {
227 $this->append('xorg_css', $path);
228 }
229
230 // }}}
ea626742 231 // {{{ function addCssInline
232
2b1ee50b 233 public function addCssInline($css)
ea626742 234 {
235 if (!empty($css)) {
236 $this->append('xorg_inline_css', $css);
eaf30d86 237 }
ea626742 238 }
239
240 // }}}
162370e7 241 // {{{ function setRssLink
242
2b1ee50b 243 public function setRssLink($title, $path)
162370e7 244 {
245 $this->assign('xorg_rss', array('title' => $title, 'href' => $path));
246 }
247
248 // }}}
4a8a1e0a 249 // {{{ function jsonDisplay
250 protected function jsonDisplay()
251 {
252 header("Content-type: text/javascript; charset=utf-8");
253 array_walk_recursive($this->_jsonVars, "escape_xorgDB");
254 $jsonbegin = Env::v('jsonBegin');
255 $jsonend = Env::v('jsonEnd');
256 if (Env::has('jsonVar')) {
257 $jsonbegin = Env::v('jsonVar').' = ';
258 $jsonend = ';';
259 } elseif (Env::has('jsonFunc')) {
260 $jsonbegin = Env::v('jsonFunc').'(';
261 $jsonend = ');';
262 }
263 echo $jsonbegin, json_encode($this->_jsonVars), $jsonend;
264 exit;
265 }
266 // }}}
267 // {{{ function jsonAssign
268 public function jsonAssign($var, $value)
269 {
270 $this->_jsonVars[$var] = $value;
271 }
fba760d2 272
273 // }}}
4a8a1e0a 274}
275
276function escape_xorgDB(&$item, $key)
277{
278 if (is_a($item, 'XOrgDBIterator')) {
279 $expanded = array();
280 while ($a = $item->next()) {
281 $expanded[] = $a;
282 }
283 $item = $expanded;
284 }
0337d704 285}
286
b76f0797 287// {{{ function escape_html ()
288
289/**
290 * default smarty plugin, used to auto-escape dangerous html.
eaf30d86 291 *
b76f0797 292 * < --> &lt;
293 * > --> &gt;
294 * " --> &quot;
295 * & not followed by some entity --> &amp;
296 */
297function escape_html($string)
298{
299 if (is_string($string)) {
c1895524 300 return htmlspecialchars($string, ENT_QUOTES, 'UTF-8');
b76f0797 301 } else {
c1895524 302 return $string;
b76f0797 303 }
304}
305
306// }}}
307// {{{ function at_to_globals()
308
309/**
310 * helper
311 */
312
313function _to_globals($s) {
314 global $globals;
315 $t = explode('.',$s);
316 if (count($t) == 1) {
317 return var_export($globals->$t[0],true);
318 } else {
319 return var_export($globals->$t[0]->$t[1],true);
320 }
321}
322
323/**
324 * compilation plugin used to import $globals confing through #globals.foo.bar# directives
325 */
326
327function at_to_globals($tpl_source, &$smarty)
328{
329 return preg_replace('/#globals\.([a-zA-Z0-9_.]+?)#/e', '_to_globals(\'\\1\')', $tpl_source);
330}
331
332// }}}
333// {{{ function trimwhitespace
334
335function trimwhitespace($source, &$smarty)
336{
120bd636 337 $tags = '(script|pre|textarea)';
abe7e055 338 preg_match_all("!<$tags.*?>.*?</(\\1)>!ius", $source, $tagsmatches);
339 $source = preg_replace("!<$tags.*?>.*?</(\\1)>!ius", "&&&tags&&&", $source);
b76f0797 340
341 // remove all leading spaces, tabs and carriage returns NOT
342 // preceeded by a php close tag.
343 $source = preg_replace('/((?<!\?>)\n)[\s]+/m', '\1', $source);
120bd636 344 $source = preg_replace("!&&&tags&&&!e", 'array_shift($tagsmatches[0])', $source);
b76f0797 345
eaf30d86 346 return $source;
b76f0797 347}
348
349// }}}
7a3f546b 350// {{{ function wiki_include
351
352function wiki_include($source, &$smarty)
353{
354 return preg_replace('/\{include( [^}]*)? wiki=([^} ]+)(.*?)\}/ui',
355 '{include\1 file="../spool/wiki.d/cache_\2.tpl"\3 included=1}',
356 $source);
357}
358
359// }}}
908db125
FB
360//{{{ function hasPerm
361
362function if_has_perms($source, &$smarty)
363{
364 $source = preg_replace('/\{if([^}]*) (\!?)hasPerms\(([^)]+)\)([^}]*)\}/',
365 '{if\1 \2$smarty.session.perms->hasFlagCombination(\3)\4}',
366 $source);
367 return preg_replace('/\{if([^}]*) (\!?)hasPerm\(([^)]+)\)([^}]*)\}/',
368 '{if\1 \2($smarty.session.perms && $smarty.session.perms->hasFlag(\3))\4}',
369 $source);
370}
371
372// }}}
edc636b8 373// {{{
374
375function form_force_encodings($source, &$smarty)
376{
377 return preg_replace('/<form[^\w]/',
a7de4ef7 378 '\0 accept-charset="utf-8" ',
edc636b8 379 $source);
380}
381
382// }}}
bf2e1ab0 383// {{{ function hide_emails
384
385function _hide_email($source)
386{
1bd2bc7e 387 $source = str_replace("\n", '', $source);
6b8d257b 388 return '<script type="text/javascript">//<![CDATA[' . "\n" .
389 'Nix.decode("' . addslashes(str_rot13($source)) . '");' . "\n" .
eaf30d86 390 '//]]></script>';
bf2e1ab0 391}
392
393function hide_emails($source, &$smarty)
394{
a18afbdc 395 if (!strpos($source, '@')) {
396 return $source;
397 }
398
bf2e1ab0 399 //prevent email replacement in <script> and <textarea>
120bd636 400 $tags = '(script|textarea|select)';
abe7e055 401 preg_match_all("!<$tags.*?>.*?</(\\1)>!ius", $source, $tagsmatches);
402 $source = preg_replace("!<$tags.*?>.*?</(\\1)>!ius", "&&&tags&&&", $source);
bf2e1ab0 403
404 //catch all emails in <a href="mailto:...">
a14159bf 405 preg_match_all("!<a[^>]+href=[\"'][^\"']*[-a-z0-9+_.]+@[-a-z0-9_.]+[^\"']*[\"'].*?>.*?</a>!ius", $source, $ahref);
406 $source = preg_replace("!<a[^>]+href=[\"'][^\"']*[-a-z0-9+_.]+@[-a-z0-9_.]+[^\"']*[\"'].*?>.*?</a>!ius", '&&&ahref&&&', $source);
bf2e1ab0 407
408 //prevant replacement in tag attributes
abe7e055 409 preg_match_all("!<[^>]+[-a-z0-9_+.]+@[-a-z0-9_.]+.+?>!ius", $source, $misc);
410 $source = preg_replace("!<[^>]+[-a-z0-9_+.]+@[-a-z0-9_.]+.+?>!ius", '&&&misc&&&', $source);
bf2e1ab0 411
412 //catch !
eaf30d86 413 $source = preg_replace('!([-a-z0-9_+.]+@[-a-z0-9_.]+)!iue', '_hide_email("\1")', $source);
bf2e1ab0 414 $source = preg_replace('!&&&ahref&&&!e', '_hide_email(array_shift($ahref[0]))', $source);
bf2e1ab0 415
416 // restore data
2456ea61 417 $source = preg_replace('!&&&misc&&&!e', 'array_shift($misc[0])', $source);
120bd636 418 $source = preg_replace("!&&&tags&&&!e", 'array_shift($tagsmatches[0])', $source);
bf2e1ab0 419
420 return $source;
421}
422
423// }}}
b76f0797 424
a7de4ef7 425// vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8:
0337d704 426?>