5 * Embeds the results of a PHP script at render-time.
11 * @author Paul M. Jones <pmjones@php.net>
15 * @version $Id: Embed.php,v 1.3 2005/02/23 17:38:29 pmjones Exp $
21 * Embeds the results of a PHP script at render-time.
23 * This class implements a Text_Wiki_Parse to embed the contents of a URL
24 * inside the page at render-time. Typically used to get script output.
25 * This differs from the 'include' rule, which incorporates results at
26 * parse-time; 'embed' output does not get parsed by Text_Wiki, while
27 * 'include' ouput does.
29 * This rule is inherently not secure; it allows cross-site scripting to
30 * occur if the embedded output has <script> or other similar tags. Be
37 * @author Paul M. Jones <pmjones@php.net>
41 class Text_Wiki_Parse_Embed
extends Text_Wiki_Parse
{
44 'base' => '/path/to/scripts/'
56 * The regular expression used to find source text matching this
65 var $regex = '/(\[\[embed )(.+?)( .+?)?(\]\])/i';
70 * Generates a token entry for the matched text. Token options are:
72 * 'text' => The full matched text, not including the <code></code> tags.
76 * @param array &$matches The array of matches from parse().
78 * @return A delimited token number to be used as a placeholder in
83 function process(&$matches)
85 // save the file location
86 $this->file
= $this->getConf('base', './') . $matches[2];
88 // extract attribs as variables in the local space
89 $this->vars
= $this->getAttrs($matches[3]);
90 unset($this->vars
['this']);
96 $this->output
= ob_get_contents();
99 // done, place the script output directly in the source
100 return $this->wiki
->addToken(
102 array('text' => $this->output
)