Fixes variable use.
[platal.git] / classes / plpage.php
CommitLineData
0337d704 1<?php
2/***************************************************************************
e92ecb8c 3 * Copyright (C) 2003-2011 Polytechnique.org *
0337d704 4 * http://opensource.polytechnique.org/ *
5 * *
6 * This program is free software; you can redistribute it and/or modify *
7 * it under the terms of the GNU General Public License as published by *
8 * the Free Software Foundation; either version 2 of the License, or *
9 * (at your option) any later version. *
10 * *
11 * This program is distributed in the hope that it will be useful, *
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
14 * GNU General Public License for more details. *
15 * *
16 * You should have received a copy of the GNU General Public License *
17 * along with this program; if not, write to the Free Software *
18 * Foundation, Inc., *
19 * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA *
20 ***************************************************************************/
21
5640f093
FB
22if (!@include_once 'smarty/libs/Smarty.class.php') {
23 require_once 'smarty/Smarty.class.php';
24}
0337d704 25
04334c61 26abstract class PlPage extends Smarty
0337d704 27{
2b1ee50b 28 private $_page_type;
29 private $_tpl;
30 private $_errors;
31 private $_failure;
4a8a1e0a 32 private $_jsonVars;
0337d704 33
04334c61 34 // {{{ function PlPage()
0337d704 35
abde67b1 36 public function __construct()
0337d704 37 {
2b1ee50b 38 parent::Smarty();
0337d704 39
2b1ee50b 40 global $globals;
796aea34 41
abe7e055 42 $this->caching = false;
43 $this->config_overwrite = false;
44 $this->use_sub_dirs = false;
a33955e4
FB
45 $this->template_dir = $globals->spoolroot . '/templates/';
46 $this->compile_dir = $globals->spoolroot . '/spool/templates_c/';
47 array_unshift($this->plugins_dir,
48 $globals->spoolroot . '/core/plugins/',
49 $globals->spoolroot . '/plugins/');
50 $this->config_dir = $globals->spoolroot . '/configs/';
0337d704 51
b5e56a71 52 $this->compile_check = !empty($globals->debug) || $globals->smarty_autocompile;
0337d704 53
71a753d3 54 $this->_errors = array('errors' => array());
4a8a1e0a 55 $this->_jsonVars = array();
860fdaec 56 $this->_failure = false;
0337d704 57
fe556813 58 if ($globals->mode != 'rw') {
d27380cd
AA
59 $this->trigError("En raison d'une maintenance, une partie des fonctionnalités du site est"
60 . " actuellement désactivée, en particulier aucune donnée ne sera sauvegardée");
fe556813 61 }
0337d704 62 $this->register_prefilter('at_to_globals');
0337d704 63 }
64
65 // }}}
66 // {{{ function changeTpl()
67
2b1ee50b 68 public function changeTpl($tpl, $type = SKINNED)
0337d704 69 {
91ebb7ff
FB
70 $this->_tpl = $tpl;
71 $this->_page_type = $type;
72 $this->assign('pl_tpl', $tpl);
0337d704 73 }
74
75 // }}}
7cb40d85
FB
76 // {{{ function getCoreTpl()
77
78 public static function getCoreTpl($tpl)
79 {
80 global $globals;
81 return $globals->spoolroot . '/core/templates/' . $tpl;
82 }
83
84 // }}}
85 // {{{ function coreTpl()
86
87 /** Use a template from the core.
88 */
89 public function coreTpl($tpl, $type = SKINNED)
90 {
91 global $globals;
92 $this->changeTpl(self::getCoreTpl($tpl), $type);
93 }
94
95 // }}}
e654517d 96 // {{{ function raw()
97
98 public function raw()
99 {
100 global $globals;
101 $this->assign('globals', $globals);
102 return $this->fetch($this->_tpl);
103 }
104
105 // }}}
0337d704 106 // {{{ function _run()
107
2b1ee50b 108 protected function _run($skin)
0337d704 109 {
80d0423e 110 global $globals, $platal, $TIME_BEGIN;
36f114ef 111
732e5855 112 Platal::session()->close();
36f114ef 113
e654517d 114 $this->register_prefilter('trimwhitespace');
115 $this->register_prefilter('form_force_encodings');
7a3f546b 116 $this->register_prefilter('wiki_include');
7cb40d85 117 $this->register_prefilter('core_include');
b6ec30c5 118 $this->register_prefilter('if_rewrites');
91ebb7ff
FB
119 $this->assign('pl_triggers', $this->_errors);
120 $this->assign('pl_errors', $this->nb_errs());
121 $this->assign('pl_failure', $this->_failure);
80d0423e 122 $this->assign_by_ref('platal', $platal);
08d7cc45 123 $this->assign_by_ref('globals', $globals);
a3a049fc 124
4a8a1e0a 125 if (Env::has('json') && count($this->_jsonVars)) {
126 return $this->jsonDisplay();
127 }
eaf30d86 128
7299bfce
FB
129 $display = Env::s('display');
130 if ($display == 'light' && $this->_page_type == SKINNED) {
8a105df2 131 $this->_page_type = SIMPLE;
7299bfce 132 } elseif ($display == 'raw') {
8a105df2 133 $this->_page_type = NO_SKIN;
7299bfce 134 } elseif ($display == 'full') {
e90c2e8d 135 $this->_page_type = SKINNED;
8a105df2 136 }
137
d58e3be0
SJ
138 if ($this->_page_type == SIMPLE) {
139 $this->assign('simple', true);
140 } else {
141 $this->assign('simple', false);
142 }
143
62a66dfc 144 switch ($this->_page_type) {
145 case NO_SKIN:
81e9c63f 146 if (!($globals->debug & DEBUG_SMARTY)) {
147 error_reporting(0);
148 }
0337d704 149 $this->display($this->_tpl);
150 exit;
62a66dfc 151
152 case SIMPLE:
62a66dfc 153 case SKINNED:
b4ee37a4
FB
154 $this->register_modifier('escape_html', 'escape_html');
155 $this->default_modifiers = Array('@escape_html');
0337d704 156 }
5aa58639
FB
157 if (S::i('auth') <= AUTH_PUBLIC) {
158 $this->register_outputfilter('hide_emails');
159 }
493b6abe 160 header("Accept-Charset: utf-8");
4a8a1e0a 161 if (Env::v('forceXml')) {
a286fc7a 162 pl_content_headers("text/xml");
4a8a1e0a 163 }
b4315e15 164
165 if (!$globals->debug) {
6995a9b9 166 error_reporting(0);
b4315e15 167 $this->display($skin);
c67e49ea 168 pl_print_errors(true);
b4315e15 169 exit;
170 }
a3a049fc 171
7da8ef90 172 $this->assign('validate', true);
81e9c63f 173 if (!($globals->debug & DEBUG_SMARTY)) {
174 error_reporting(0);
175 }
040a594c 176 $START_SMARTY = microtime(true);
b4315e15 177 $result = $this->fetch($skin);
040a594c
FB
178 $ttime = sprintf('Temps total: %.02fs (Smarty %.02fs) - Mémoire totale : %dKo<br />',
179 microtime(true) - $TIME_BEGIN, microtime(true) - $START_SMARTY,
180 memory_get_peak_usage(true) / 1024);
b4ee37a4
FB
181 if ($globals->debug & DEBUG_BT) {
182 PlBacktrace::clean();
183 $this->assign_by_ref('backtraces', PlBacktrace::$bt);
7cb40d85
FB
184 $result = str_replace('@@BACKTRACE@@',
185 $this->fetch(self::getCoreTpl('backtrace.tpl')),
186 $result);
b4ee37a4
FB
187 } else {
188 $result = str_replace('@@BACKTRACE@@', '', $result);
189 }
0337d704 190
b4ee37a4 191 $replc = "<span class='erreur'>VALIDATION HTML INACTIVE</span><br />";
81e9c63f 192 if ($globals->debug & DEBUG_VALID) {
d1bdef74 193 global $platal;
b4315e15 194 $fd = fopen($this->compile_dir."/valid.html","w");
195 fwrite($fd, $result);
196 fclose($fd);
a3a049fc 197
d1bdef74
FB
198 $replc = '<span id="html_valid"><span style="color: #860">VALIDATION HTML EN COURS</span></span>'
199 . '<script type="text/javascript">$("#html_valid").updateHtml("validator");</script>'
200 . '<br />';
0337d704 201 }
202
b4315e15 203 echo str_replace("@HOOK@", $ttime.$replc, $result);
0337d704 204 exit;
205 }
206
1490093c 207 abstract public function run();
208
0337d704 209 // }}}
0337d704 210 // {{{ function nb_errs()
211
2b1ee50b 212 public function nb_errs()
0337d704 213 {
71a753d3 214 return count($this->_errors['errors']);
0337d704 215 }
216
217 // }}}
218 // {{{ function trig()
219
a7d35093 220 private function trig($msg, $type = 'errors')
0337d704 221 {
71a753d3
FB
222 if (!isset($this->_errors[$type])) {
223 $this->_errors[$type] = array();
224 }
225 $this->_errors[$type][] = $msg;
226 }
227
228 public function trigError($msg)
229 {
230 $this->trig($msg, 'errors');
231 }
232
e00bc67e
FB
233 public function trigWarning($msg)
234 {
235 $this->trig($msg, 'warnings');
236 }
237
71a753d3
FB
238 public function trigSuccess($msg)
239 {
240 $this->trig($msg, 'success');
0337d704 241 }
242
243 // }}}
8adfe956
RB
244 // {{{ function trigRedirect
245
246 // Acts as trig(), but replaces the template with a simple one displaying
247 // the error messages and a "continue" link.
248 private function trigRedirect($msg, $continue, $type = 'errors')
249 {
250 $this->trig($msg, $type);
251 $this->coreTpl('msgredirect.tpl');
252 $this->assign('continue', $continue);
253 $this->run();
254 }
255
256 public function trigErrorRedirect($msg, $continue)
257 {
258 $this->trigRedirect($msg, $continue, 'errors');
259 }
260
261 public function trigWarningRedirect($msg, $continue)
262 {
263 $this->trigRedirect($msg, $continue, 'warnings');
264 }
265
266 public function trigSuccessRedirect($msg, $continue)
267 {
268 $this->trigRedirect($msg, $continue, 'success');
269 }
270
271 // }}}
0337d704 272 // {{{ function kill()
273
ca476935 274 public function kill($msg, $type = 'errors')
0337d704 275 {
36f472dc
FB
276 // PHP is used on command line... do not run the whole page stuff.
277 if (php_sapi_name() == 'cli') {
278 echo $msg . "\n";
fc2cfa65 279 exit(-1);
36f472dc
FB
280 }
281
90eba1aa 282 global $platal;
283
ca476935 284 $this->trig($msg, $type);
0fcbe8d0 285 $this->_failure = true;
0337d704 286 $this->run();
287 }
288
ca476935
SJ
289 public function killError($msg)
290 {
291 $this->kill($msg, 'errors');
292 }
293
294 public function killWarning($msg)
295 {
296 $this->kill($msg, 'warnings');
297 }
298
299 public function killSuccess($msg)
300 {
301 $this->kill($msg, 'success');
302 }
303
0337d704 304 // }}}
9902e47b
FB
305 // {{{ function setTitle
306
307 public function setTitle($title)
308 {
380e2a5a
FB
309 global $globals;
310 if (isset($globals->core->sitename)) {
311 $title = $globals->core->sitename . ' :: ' . $title;
312 }
9902e47b
FB
313 $this->assign('pl_title', $title);
314 }
315
316 // }}}
0337d704 317 // {{{ function addJsLink
318
47a44ed0 319 public function addJsLink($filename, $static_content = true)
0337d704 320 {
47a44ed0
VZ
321 if ($static_content) {
322 $this->append('pl_js', pl_static_content_path("javascript/", $filename));
323 } else {
324 $this->append('pl_js', "javascript/$filename");
325 }
0337d704 326 }
327
328 // }}}
329 // {{{ function addCssLink
330
2b1ee50b 331 public function addCssLink($path)
0337d704 332 {
91ebb7ff 333 $this->append('pl_css', $path);
0337d704 334 }
335
336 // }}}
1e9a1d99
AA
337 // {{{ function addLink
338
339 public function addLink($rel, $path)
340 {
341 $this->append('pl_link', array('rel' => $rel, 'href' => $path));
342 }
343
344
345 // }}}
ea626742 346 // {{{ function addCssInline
347
2b1ee50b 348 public function addCssInline($css)
ea626742 349 {
350 if (!empty($css)) {
91ebb7ff 351 $this->append('pl_inline_css', $css);
eaf30d86 352 }
ea626742 353 }
354
355 // }}}
162370e7 356 // {{{ function setRssLink
357
2b1ee50b 358 public function setRssLink($title, $path)
162370e7 359 {
91ebb7ff 360 $this->assign('pl_rss', array('title' => $title, 'href' => $path));
162370e7 361 }
362
363 // }}}
4a8a1e0a 364 // {{{ function jsonDisplay
365 protected function jsonDisplay()
366 {
a286fc7a 367 pl_content_headers("text/javascript");
c67e49ea
FB
368 if (!empty(PlBacktrace::$bt)) {
369 $this->jsonAssign('pl_backtraces', PlBacktrace::$bt);
641802fe 370 }
b00a702a 371 array_walk_recursive($this->_jsonVars, "escape_XDB");
4a8a1e0a 372 $jsonbegin = Env::v('jsonBegin');
373 $jsonend = Env::v('jsonEnd');
374 if (Env::has('jsonVar')) {
375 $jsonbegin = Env::v('jsonVar').' = ';
376 $jsonend = ';';
377 } elseif (Env::has('jsonFunc')) {
378 $jsonbegin = Env::v('jsonFunc').'(';
379 $jsonend = ');';
380 }
381 echo $jsonbegin, json_encode($this->_jsonVars), $jsonend;
382 exit;
383 }
384 // }}}
c67e49ea
FB
385
386 public function runJSon()
387 {
388 pl_content_headers("text/javascript");
389 if (!empty(PlBacktrace::$bt)) {
390 $this->jsonAssign('pl_backtraces', PlBacktrace::$bt);
391 }
392 echo json_encode($this->_jsonVars);
393 exit;
394 }
395
4a8a1e0a 396 // {{{ function jsonAssign
397 public function jsonAssign($var, $value)
398 {
399 $this->_jsonVars[$var] = $value;
400 }
fba760d2 401
402 // }}}
4a8a1e0a 403}
404
b00a702a 405function escape_XDB(&$item, $key)
4a8a1e0a 406{
b00a702a 407 if ($item instanceof XDBIterator) {
4a8a1e0a 408 $expanded = array();
409 while ($a = $item->next()) {
410 $expanded[] = $a;
411 }
412 $item = $expanded;
413 }
0337d704 414}
415
b76f0797 416// {{{ function escape_html ()
417
418/**
419 * default smarty plugin, used to auto-escape dangerous html.
eaf30d86 420 *
b76f0797 421 * < --> &lt;
422 * > --> &gt;
423 * " --> &quot;
424 * & not followed by some entity --> &amp;
425 */
426function escape_html($string)
427{
428 if (is_string($string)) {
c1895524 429 return htmlspecialchars($string, ENT_QUOTES, 'UTF-8');
b76f0797 430 } else {
c1895524 431 return $string;
b76f0797 432 }
433}
434
435// }}}
436// {{{ function at_to_globals()
437
438/**
439 * helper
440 */
441
442function _to_globals($s) {
443 global $globals;
444 $t = explode('.',$s);
445 if (count($t) == 1) {
446 return var_export($globals->$t[0],true);
447 } else {
448 return var_export($globals->$t[0]->$t[1],true);
449 }
450}
451
452/**
453 * compilation plugin used to import $globals confing through #globals.foo.bar# directives
454 */
455
ed4f7de0 456function at_to_globals($tpl_source, $smarty)
b76f0797 457{
458 return preg_replace('/#globals\.([a-zA-Z0-9_.]+?)#/e', '_to_globals(\'\\1\')', $tpl_source);
7cb40d85 459}
b76f0797 460
7cb40d85
FB
461// }}}
462// {{{ function trimwhitespace
b76f0797 463
ed4f7de0 464function trimwhitespace($source, $smarty)
7cb40d85
FB
465{
466 $tags = '(script|pre|textarea)';
467 preg_match_all("!<$tags.*?>.*?</(\\1)>!ius", $source, $tagsmatches);
468 $source = preg_replace("!<$tags.*?>.*?</(\\1)>!ius", "&&&tags&&&", $source);
b76f0797 469
7cb40d85
FB
470 // remove all leading spaces, tabs and carriage returns NOT
471 // preceeded by a php close tag.
472 $source = preg_replace('/((?<!\?>)\n)[\s]+/m', '\1', $source);
473 $source = preg_replace("!&&&tags&&&!e", 'array_shift($tagsmatches[0])', $source);
b76f0797 474
7cb40d85
FB
475 return $source;
476}
b76f0797 477
7cb40d85
FB
478// }}}
479// {{{ function wiki_include
7a3f546b 480
ed4f7de0 481function wiki_include($source, $smarty)
7a3f546b 482{
7cb40d85 483 global $globals;
7a3f546b 484 return preg_replace('/\{include( [^}]*)? wiki=([^} ]+)(.*?)\}/ui',
7cb40d85
FB
485 '{include\1 file="' . $globals->spoolroot . '/spool/wiki.d/cache_\2.tpl"\3 included=1}',
486 $source);
487}
488
ed4f7de0 489function core_include($source, $smarty)
7cb40d85
FB
490{
491 global $globals;
492 return preg_replace('/\{include( [^}]*)? core=([^} ]+)(.*?)\}/ui',
493 '{include\1 file="' . $globals->spoolroot . '/core/templates/\2"\3}',
7a3f546b 494 $source);
495}
496
497// }}}
908db125
FB
498//{{{ function hasPerm
499
ed4f7de0 500function if_rewrites($source, $smarty)
908db125 501{
a2efe30f
FB
502 $perms = 'isset($smarty.session.user|smarty:nodefaults) && $smarty.session.user';
503 return preg_replace(array('/\{(else)?if([^}]*) (\!?)hasPerms?\(([^)]+)\)([^}]*)\}/',
504 '/\{(else)?if([^}]*) (\!?)t\(([^)]+)\)([^}]*)\}/'),
505 array('{\1if\2 \3(' . $perms . '->checkPerms(\4))\5}',
506 '{\1if\2 \3(isset(\4|smarty:nodefaults) && (\4|smarty:nodefaults))\5}'),
7cb40d85 507 $source);
908db125
FB
508}
509
510// }}}
edc636b8 511// {{{
512
ed4f7de0 513function form_force_encodings($source, $smarty)
edc636b8 514{
515 return preg_replace('/<form[^\w]/',
a7de4ef7 516 '\0 accept-charset="utf-8" ',
edc636b8 517 $source);
518}
519
520// }}}
bf2e1ab0 521// {{{ function hide_emails
522
523function _hide_email($source)
524{
1bd2bc7e 525 $source = str_replace("\n", '', $source);
6b8d257b 526 return '<script type="text/javascript">//<![CDATA[' . "\n" .
91ebb7ff
FB
527 'Nix.decode("' . addslashes(str_rot13($source)) . '");' . "\n" .
528 '//]]></script>';
bf2e1ab0 529}
530
ed4f7de0 531function hide_emails($source, $smarty)
bf2e1ab0 532{
a18afbdc 533 if (!strpos($source, '@')) {
534 return $source;
535 }
536
bf2e1ab0 537 //prevent email replacement in <script> and <textarea>
120bd636 538 $tags = '(script|textarea|select)';
abe7e055 539 preg_match_all("!<$tags.*?>.*?</(\\1)>!ius", $source, $tagsmatches);
540 $source = preg_replace("!<$tags.*?>.*?</(\\1)>!ius", "&&&tags&&&", $source);
bf2e1ab0 541
542 //catch all emails in <a href="mailto:...">
a14159bf 543 preg_match_all("!<a[^>]+href=[\"'][^\"']*[-a-z0-9+_.]+@[-a-z0-9_.]+[^\"']*[\"'].*?>.*?</a>!ius", $source, $ahref);
544 $source = preg_replace("!<a[^>]+href=[\"'][^\"']*[-a-z0-9+_.]+@[-a-z0-9_.]+[^\"']*[\"'].*?>.*?</a>!ius", '&&&ahref&&&', $source);
bf2e1ab0 545
546 //prevant replacement in tag attributes
abe7e055 547 preg_match_all("!<[^>]+[-a-z0-9_+.]+@[-a-z0-9_.]+.+?>!ius", $source, $misc);
548 $source = preg_replace("!<[^>]+[-a-z0-9_+.]+@[-a-z0-9_.]+.+?>!ius", '&&&misc&&&', $source);
bf2e1ab0 549
550 //catch !
eaf30d86 551 $source = preg_replace('!([-a-z0-9_+.]+@[-a-z0-9_.]+)!iue', '_hide_email("\1")', $source);
bf2e1ab0 552 $source = preg_replace('!&&&ahref&&&!e', '_hide_email(array_shift($ahref[0]))', $source);
bf2e1ab0 553
554 // restore data
2456ea61 555 $source = preg_replace('!&&&misc&&&!e', 'array_shift($misc[0])', $source);
120bd636 556 $source = preg_replace("!&&&tags&&&!e", 'array_shift($tagsmatches[0])', $source);
bf2e1ab0 557
558 return $source;
559}
560
561// }}}
b76f0797 562
a7de4ef7 563// vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8:
0337d704 564?>