X-Git-Url: http://git.heureux-cyclage.org/?a=blobdiff_plain;f=includes%2FHtml.php;h=3986a7b100c05bca66f0d697e695bb8dc6e46eba;hb=0abb52ae76adfadefdc5e37ee754eb6fc4c4c2fc;hp=76abf38c159d9e14147ddd944fb974e4ed05b374;hpb=76a543ea30f99b5ea83cc98533e31a9c681f347c;p=lhc%2Fweb%2Fwiklou.git diff --git a/includes/Html.php b/includes/Html.php index 76abf38c15..3986a7b100 100644 --- a/includes/Html.php +++ b/includes/Html.php @@ -1,21 +1,27 @@ 'http://www.mediawiki.org/' ). See expandAttributes() for + * @param $element string The element's name, e.g., 'a' + * @param $attribs array Associative array of attributes, e.g., array( + * 'href' => 'http://www.mediawiki.org/' ). See expandAttributes() for * further documentation. * @param $contents string The raw HTML contents of the element: *not* * escaped! @@ -126,6 +151,12 @@ class Html { /** * Identical to rawElement(), but HTML-escapes $contents (like * Xml::element()). + * + * @param $element string + * @param $attribs array + * @param $contents string + * + * @return string */ public static function element( $element, $attribs = array(), $contents = '' ) { return self::rawElement( $element, $attribs, strtr( $contents, array( @@ -139,6 +170,11 @@ class Html { /** * Identical to rawElement(), but has no third parameter and omits the end * tag (and the self-closing '/' in XML mode for empty elements). + * + * @param $element string + * @param $attribs array + * + * @return string */ public static function openElement( $element, $attribs = array() ) { global $wgHtml5, $wgWellFormedXml; @@ -174,15 +210,18 @@ class Html { 'button', 'search', ); + if ( isset( $attribs['type'] ) && !in_array( $attribs['type'], $validTypes ) ) { unset( $attribs['type'] ); } + if ( isset( $attribs['type'] ) && $attribs['type'] == 'search' && !$wgHtml5 ) { unset( $attribs['type'] ); } } + if ( !$wgHtml5 && $element == 'textarea' && isset( $attribs['maxlength'] ) ) { unset( $attribs['maxlength'] ); } @@ -195,6 +234,7 @@ class Html { * Returns "", except if $wgWellFormedXml is off, in which case * it returns the empty string when that's guaranteed to be safe. * + * @since 1.17 * @param $element string Name of the element, e.g., 'a' * @return string A closing tag, if required */ @@ -331,6 +371,28 @@ class Html { * For instance, it will omit quotation marks if $wgWellFormedXml is false, * and will treat boolean attributes specially. * + * Attributes that should contain space-separated lists (such as 'class') array + * values are allowed as well, which will automagically be normalized + * and converted to a space-separated string. In addition to a numerical + * array, the attribute value may also be an associative array. See the + * example below for how that works. + * + * @par Numerical array + * @code + * Html::element( 'em', array( + * 'class' => array( 'foo', 'bar' ) + * ) ); + * // gives '' + * @endcode + * + * @par Associative array + * @code + * Html::element( 'em', array( + * 'class' => array( 'foo', 'bar', 'foo' => false, 'quux' => true ) + * ) ); + * // gives '' + * @endcode + * * @param $attribs array Associative array of attributes, e.g., array( * 'href' => 'http://www.mediawiki.org/' ). Values will be HTML-escaped. * A value of false means to omit the attribute. For boolean attributes, @@ -345,7 +407,7 @@ class Html { $ret = ''; $attribs = (array)$attribs; foreach ( $attribs as $key => $value ) { - if ( $value === false ) { + if ( $value === false || is_null( $value ) ) { continue; } @@ -360,6 +422,12 @@ class Html { # and we'd like consistency and better compression anyway. $key = strtolower( $key ); + # Here we're blacklisting some HTML5-only attributes... + if ( !$wgHtml5 && in_array( $key, self::$HTMLFiveOnlyAttribs ) + ) { + continue; + } + # Bug 23769: Blacklist all form validation attributes for now. Current # (June 2010) WebKit has no UI, so the form just refuses to submit # without telling the user why, which is much worse than failing @@ -370,20 +438,53 @@ class Html { continue; } - # Here we're blacklisting some HTML5-only attributes... - if ( !$wgHtml5 && in_array( $key, array( - 'autocomplete', - 'autofocus', - 'max', - 'min', - 'multiple', - 'pattern', - 'placeholder', - 'required', - 'step', - 'spellcheck', - ) ) ) { - continue; + // http://www.w3.org/TR/html401/index/attributes.html ("space-separated") + // http://www.w3.org/TR/html5/index.html#attributes-1 ("space-separated") + $spaceSeparatedListAttributes = array( + 'class', // html4, html5 + 'accesskey', // as of html5, multiple space-separated values allowed + // html4-spec doesn't document rel= as space-separated + // but has been used like that and is now documented as such + // in the html5-spec. + 'rel', + ); + + # Specific features for attributes that allow a list of space-separated values + if ( in_array( $key, $spaceSeparatedListAttributes ) ) { + // Apply some normalization and remove duplicates + + // Convert into correct array. Array can contain space-seperated + // values. Implode/explode to get those into the main array as well. + if ( is_array( $value ) ) { + // If input wasn't an array, we can skip this step + + $newValue = array(); + foreach ( $value as $k => $v ) { + if ( is_string( $v ) ) { + // String values should be normal `array( 'foo' )` + // Just append them + if ( !isset( $value[$v] ) ) { + // As a special case don't set 'foo' if a + // separate 'foo' => true/false exists in the array + // keys should be authoritive + $newValue[] = $v; + } + } elseif ( $v ) { + // If the value is truthy but not a string this is likely + // an array( 'foo' => true ), falsy values don't add strings + $newValue[] = $k; + } + } + $value = implode( ' ', $newValue ); + } + $value = explode( ' ', $value ); + + // Normalize spacing by fixing up cases where people used + // more than 1 space and/or a trailing/leading space + $value = array_diff( $value, array( '', ' ' ) ); + + // Remove duplicates and create the string + $value = implode( ' ', array_unique( $value ) ); } # See the "Attributes" section in the HTML syntax part of HTML5, @@ -419,7 +520,8 @@ class Html { # Apparently we need to entity-encode \n, \r, \t, although the # spec doesn't mention that. Since we're doing strtr() anyway, # and we don't need <> escaped here, we may as well not call - # htmlspecialchars(). FIXME: verify that we actually need to + # htmlspecialchars(). + # @todo FIXME: Verify that we actually need to # escape \n\r\t here, and explain why, exactly. # # We could call Sanitizer::encodeAttribute() for this, but we @@ -434,10 +536,11 @@ class Html { ); if ( $wgWellFormedXml ) { # This is allowed per spec: - # But reportedly it breaks some XML tools? FIXME: is this - # really true? + # But reportedly it breaks some XML tools? + # @todo FIXME: Is this really true? $map['<'] = '<'; } + $ret .= " $key=$quote" . strtr( $value, $map ) . $quote; } } @@ -456,12 +559,15 @@ class Html { global $wgHtml5, $wgJsMimeType, $wgWellFormedXml; $attrs = array(); + if ( !$wgHtml5 ) { $attrs['type'] = $wgJsMimeType; } + if ( $wgWellFormedXml && preg_match( '/[<&]/', $contents ) ) { $contents = "/**/"; } + return self::rawElement( 'script', $attrs, $contents ); } @@ -476,9 +582,11 @@ class Html { global $wgHtml5, $wgJsMimeType; $attrs = array( 'src' => $url ); + if ( !$wgHtml5 ) { $attrs['type'] = $wgJsMimeType; } + return self::element( 'script', $attrs ); } @@ -497,6 +605,7 @@ class Html { if ( $wgWellFormedXml && preg_match( '/[<&]/', $contents ) ) { $contents = "/**/"; } + return self::rawElement( 'style', array( 'type' => 'text/css', 'media' => $media, @@ -541,8 +650,7 @@ class Html { } /** - * Convenience function to produce an input element with type=hidden, like - * Xml::hidden. + * Convenience function to produce an input element with type=hidden * * @param $name string name attribute * @param $value string value attribute @@ -569,14 +677,118 @@ class Html { */ public static function textarea( $name, $value = '', $attribs = array() ) { global $wgHtml5; + $attribs['name'] = $name; + if ( !$wgHtml5 ) { - if ( !isset( $attribs['cols'] ) ) + if ( !isset( $attribs['cols'] ) ) { $attribs['cols'] = ""; - if ( !isset( $attribs['rows'] ) ) + } + + if ( !isset( $attribs['rows'] ) ) { $attribs['rows'] = ""; + } + } + + if (substr($value, 0, 1) == "\n") { + // Workaround for bug 12130: browsers eat the initial newline + // assuming that it's just for show, but they do keep the later + // newlines, which we may want to preserve during editing. + // Prepending a single newline + $spacedValue = "\n" . $value; + } else { + $spacedValue = $value; + } + return self::element( 'textarea', $attribs, $spacedValue ); + } + /** + * Build a drop-down box for selecting a namespace + * + * @param $params array: + * - selected: [optional] Id of namespace which should be pre-selected + * - all: [optional] Value of item for "all namespaces". If null or unset, no