I hate eol w/s
[lhc/web/wiklou.git] / includes / Html.php
index 9573269..fb3f167 100644 (file)
@@ -1,26 +1,32 @@
 <?php
-# Copyright (C) 2009 Aryeh Gregor
-# http://www.mediawiki.org/
-#
-# This program is free software; you can redistribute it and/or modify
-# it under the terms of the GNU General Public License as published by
-# the Free Software Foundation; either version 2 of the License, or
-# (at your option) any later version.
-#
-# This program is distributed in the hope that it will be useful,
-# but WITHOUT ANY WARRANTY; without even the implied warranty of
-# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
-# GNU General Public License for more details.
-#
-# You should have received a copy of the GNU General Public License along
-# with this program; if not, write to the Free Software Foundation, Inc.,
-# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
-# http://www.gnu.org/copyleft/gpl.html
+/**
+ * Collection of methods to generate HTML content
+ *
+ * Copyright © 2009 Aryeh Gregor
+ * http://www.mediawiki.org/
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
+ * http://www.gnu.org/copyleft/gpl.html
+ *
+ * @file
+ */
 
 /**
  * This class is a collection of static functions that serve two purposes:
  *
- * 1) Implement any algorithms specified by HTML 5, or other HTML
+ * 1) Implement any algorithms specified by HTML5, or other HTML
  * specifications, in a convenient and self-contained way.
  *
  * 2) Allow HTML elements to be conveniently and safely generated, like the
  * This class is meant to be confined to utility functions that are called from
  * trusted code paths.  It does not do enforcement of policy like not allowing
  * <a> elements.
+ *
+ * @since 1.16
  */
 class Html {
-       # List of void elements from HTML 5, section 9.1.2 as of 2009-08-10
+       # List of void elements from HTML5, section 8.1.2 as of 2011-08-12
        private static $voidElements = array(
                'area',
                'base',
@@ -56,119 +64,99 @@ class Html {
                'meta',
                'param',
                'source',
+               'track',
+               'wbr',
        );
 
        # Boolean attributes, which may have the value omitted entirely.  Manually
-       # collected from the HTML 5 spec as of 2009-08-10.
+       # collected from the HTML5 spec as of 2011-08-12.
        private static $boolAttribs = array(
                'async',
-               'autobuffer',
                'autofocus',
                'autoplay',
                'checked',
                'controls',
+               'default',
                'defer',
                'disabled',
                'formnovalidate',
                'hidden',
                'ismap',
+               'itemscope',
                'loop',
                'multiple',
+               'muted',
                'novalidate',
                'open',
+               'pubdate',
                'readonly',
                'required',
                'reversed',
                'scoped',
                'seamless',
+               'selected',
+               'truespeed',
+               'typemustmatch',
+               # HTML5 Microdata
+               'itemscope',
+       );
+
+       private static $HTMLFiveOnlyAttribs = array(
+               'autocomplete',
+               'autofocus',
+               'max',
+               'min',
+               'multiple',
+               'pattern',
+               'placeholder',
+               'required',
+               'step',
+               'spellcheck',
        );
 
        /**
         * Returns an HTML element in a string.  The major advantage here over
         * manually typing out the HTML is that it will escape all attribute
         * values.  If you're hardcoding all the attributes, or there are none, you
-        * should probably type out the string yourself.
+        * should probably just type out the html element yourself.
         *
         * This is quite similar to Xml::tags(), but it implements some useful
         * HTML-specific logic.  For instance, there is no $allowShortTag
         * parameter: the closing tag is magically omitted if $element has an empty
         * content model.  If $wgWellFormedXml is false, then a few bytes will be
-        * shaved off the HTML output as well.  In the future, other HTML-specific
-        * features might be added, like allowing arrays for the values of
-        * attributes like class= and media=.
+        * shaved off the HTML output as well.
         *
-        * @param $element  string The element's name, e.g., 'a'
-        * @param $attribs  array  Associative array of attributes, e.g., array(
-        *   'href' => 'http://www.mediawiki.org/' ).  See expandAttributes() for
+        * @param $element string The element's name, e.g., 'a'
+        * @param $attribs array  Associative array of attributes, e.g., array(
+        *   'href' => 'http://www.mediawiki.org/' ). See expandAttributes() for
         *   further documentation.
         * @param $contents string The raw HTML contents of the element: *not*
         *   escaped!
         * @return string Raw HTML
         */
        public static function rawElement( $element, $attribs = array(), $contents = '' ) {
-               global $wgHtml5, $wgWellFormedXml;
-               $attribs = (array)$attribs;
-               # This is not required in HTML 5, but let's do it anyway, for
-               # consistency and better compression.
-               $element = strtolower( $element );
-
-               # Element-specific hacks to slim down output and ensure validity
-               if ( $element == 'input' ) {
-                       if ( !$wgHtml5 ) {
-                               # With $wgHtml5 off we want to validate as XHTML 1, so we
-                               # strip out any fancy HTML 5-only input types for now.
-                               #
-                               # Whitelist of valid types:
-                               $validTypes = array(
-                                       'hidden',
-                                       'text',
-                                       'password',
-                                       'checkbox',
-                                       'radio',
-                                       'file',
-                                       'submit',
-                                       'image',
-                                       'reset',
-                                       'button',
-                               );
-                               if ( isset( $attribs['type'] )
-                               && !in_array( $attribs['type'], $validTypes ) ) {
-                                       # Fall back to type=text, the default
-                                       unset( $attribs['type'] );
-                               }
-                               # Here we're blacklisting some HTML5-only attributes...
-                               $html5attribs = array(
-                                       'autocomplete',
-                                       'autofocus',
-                                       'max',
-                                       'min',
-                                       'multiple',
-                                       'pattern',
-                                       'placeholder',
-                                       'required',
-                                       'step',
-                               );
-                               foreach ( $html5attribs as $badAttr ) {
-                                       unset( $attribs[$badAttr] );
-                               }
-                       }
-               }
-
-               $start = "<$element" . self::expandAttributes(
-                       self::dropDefaults( $element, $attribs ) );
+               global $wgWellFormedXml;
+               $start = self::openElement( $element, $attribs );
                if ( in_array( $element, self::$voidElements ) ) {
                        if ( $wgWellFormedXml ) {
-                               return "$start />";
+                               # Silly XML.
+                               return substr( $start, 0, -1 ) . ' />';
                        }
-                       return "$start>";
+                       return $start;
                } else {
-                       return "$start>$contents</$element>";
+                       return "$start$contents" . self::closeElement( $element );
                }
        }
 
        /**
         * Identical to rawElement(), but HTML-escapes $contents (like
         * Xml::element()).
+        *
+        * @param $element string
+        * @param $attribs array
+        * @param $contents string
+        *
+        * @return string
         */
        public static function element( $element, $attribs = array(), $contents = '' ) {
                return self::rawElement( $element, $attribs, strtr( $contents, array(
@@ -179,6 +167,100 @@ class Html {
                ) ) );
        }
 
+       /**
+        * Identical to rawElement(), but has no third parameter and omits the end
+        * tag (and the self-closing '/' in XML mode for empty elements).
+        *
+        * @param $element string
+        * @param $attribs array
+        *
+        * @return string
+        */
+       public static function openElement( $element, $attribs = array() ) {
+               global $wgHtml5, $wgWellFormedXml;
+               $attribs = (array)$attribs;
+               # This is not required in HTML5, but let's do it anyway, for
+               # consistency and better compression.
+               $element = strtolower( $element );
+
+               # In text/html, initial <html> and <head> tags can be omitted under
+               # pretty much any sane circumstances, if they have no attributes.  See:
+               # <http://www.whatwg.org/specs/web-apps/current-work/multipage/syntax.html#optional-tags>
+               if ( !$wgWellFormedXml && !$attribs
+               && in_array( $element, array( 'html', 'head' ) ) ) {
+                       return '';
+               }
+
+               # Remove HTML5-only attributes if we aren't doing HTML5, and disable
+               # form validation regardless (see bug 23769 and the more detailed
+               # comment in expandAttributes())
+               if ( $element == 'input' ) {
+                       # Whitelist of types that don't cause validation.  All except
+                       # 'search' are valid in XHTML1.
+                       $validTypes = array(
+                               'hidden',
+                               'text',
+                               'password',
+                               'checkbox',
+                               'radio',
+                               'file',
+                               'submit',
+                               'image',
+                               'reset',
+                               'button',
+                               'search',
+                       );
+
+                       if ( isset( $attribs['type'] )
+                       && !in_array( $attribs['type'], $validTypes ) ) {
+                               unset( $attribs['type'] );
+                       }
+
+                       if ( isset( $attribs['type'] ) && $attribs['type'] == 'search'
+                       && !$wgHtml5 ) {
+                               unset( $attribs['type'] );
+                       }
+               }
+
+               if ( !$wgHtml5 && $element == 'textarea' && isset( $attribs['maxlength'] ) ) {
+                       unset( $attribs['maxlength'] );
+               }
+
+               return "<$element" . self::expandAttributes(
+                       self::dropDefaults( $element, $attribs ) ) . '>';
+       }
+
+       /**
+        * Returns "</$element>", except if $wgWellFormedXml is off, in which case
+        * it returns the empty string when that's guaranteed to be safe.
+        *
+        * @since 1.17
+        * @param $element string Name of the element, e.g., 'a'
+        * @return string A closing tag, if required
+        */
+       public static function closeElement( $element ) {
+               global $wgWellFormedXml;
+
+               $element = strtolower( $element );
+
+               # Reference:
+               # http://www.whatwg.org/specs/web-apps/current-work/multipage/syntax.html#optional-tags
+               if ( !$wgWellFormedXml && in_array( $element, array(
+                       'html',
+                       'head',
+                       'body',
+                       'li',
+                       'dt',
+                       'dd',
+                       'tr',
+                       'td',
+                       'th',
+               ) ) ) {
+                       return '';
+               }
+               return "</$element>";
+       }
+
        /**
         * Given an element name and an associative array of element attributes,
         * return an array that is functionally identical to the input array, but
@@ -230,7 +312,7 @@ class Html {
                        'link' => array( 'media' => 'all' ),
                        'menu' => array( 'type' => 'list' ),
                        # Note: the use of text/javascript here instead of other JavaScript
-                       # MIME types follows the HTML 5 spec.
+                       # MIME types follows the HTML5 spec.
                        'script' => array( 'type' => 'text/javascript' ),
                        'style' => array(
                                'media' => 'all',
@@ -289,6 +371,26 @@ class Html {
         * For instance, it will omit quotation marks if $wgWellFormedXml is false,
         * and will treat boolean attributes specially.
         *
+        * Attributes that should contain space-separated lists (such as 'class') array
+        * values are allowed as well, which will automagically be normalized
+        * and converted to a space-separated string. In addition to a numerical
+        * array, the attribute value may also be an associative array. See the
+        * example below for how that works.
+        * @example Numerical array
+        * <code>
+        *     Html::element( 'em', array(
+        *         'class' => array( 'foo', 'bar' )
+        *     ) );
+        *     // gives '<em class="foo bar"></em>'
+        * </code>
+        * @example Associative array
+        * <code>
+        *     Html::element( 'em', array(
+        *         'class' => array( 'foo', 'bar', 'foo' => false, 'quux' => true )
+        *     ) );
+        *     // gives '<em class="bar quux"></em>'
+        * </code>
+        *
         * @param $attribs array Associative array of attributes, e.g., array(
         *   'href' => 'http://www.mediawiki.org/' ).  Values will be HTML-escaped.
         *   A value of false means to omit the attribute.  For boolean attributes,
@@ -303,7 +405,7 @@ class Html {
                $ret = '';
                $attribs = (array)$attribs;
                foreach ( $attribs as $key => $value ) {
-                       if ( $value === false ) {
+                       if ( $value === false || is_null( $value ) ) {
                                continue;
                        }
 
@@ -314,11 +416,76 @@ class Html {
                                $key = $value;
                        }
 
-                       # Not technically required in HTML 5, but required in XHTML 1.0,
+                       # Not technically required in HTML5, but required in XHTML 1.0,
                        # and we'd like consistency and better compression anyway.
                        $key = strtolower( $key );
 
-                       # See the "Attributes" section in the HTML syntax part of HTML 5,
+                       # Here we're blacklisting some HTML5-only attributes...
+                       if ( !$wgHtml5 && in_array( $key, self::$HTMLFiveOnlyAttribs )
+                        ) {
+                               continue;
+                       }
+
+                       # Bug 23769: Blacklist all form validation attributes for now.  Current
+                       # (June 2010) WebKit has no UI, so the form just refuses to submit
+                       # without telling the user why, which is much worse than failing
+                       # server-side validation.  Opera is the only other implementation at
+                       # this time, and has ugly UI, so just kill the feature entirely until
+                       # we have at least one good implementation.
+                       if ( in_array( $key, array( 'max', 'min', 'pattern', 'required', 'step' ) ) ) {
+                               continue;
+                       }
+
+                       // http://www.w3.org/TR/html401/index/attributes.html ("space-separated")
+                       // http://www.w3.org/TR/html5/index.html#attributes-1 ("space-separated")
+                       $spaceSeparatedListAttributes = array(
+                               'class', // html4, html5
+                               'accesskey', // as of html5, multiple space-separated values allowed
+                               // html4-spec doesn't document rel= as space-separated
+                               // but has been used like that and is now documented as such 
+                               // in the html5-spec.
+                               'rel',
+                       );
+
+                       # Specific features for attributes that allow a list of space-separated values
+                       if ( in_array( $key, $spaceSeparatedListAttributes ) ) {
+                               // Apply some normalization and remove duplicates
+
+                               // Convert into correct array. Array can contain space-seperated
+                               // values. Implode/explode to get those into the main array as well.
+                               if ( is_array( $value ) ) {
+                                       // If input wasn't an array, we can skip this step
+                                       
+                                       $newValue = array();
+                                       foreach ( $value as $k => $v ) {
+                                               if ( is_string( $v ) ) {
+                                                       // String values should be normal `array( 'foo' )`
+                                                       // Just append them
+                                                       if ( !isset( $value[$v] ) ) {
+                                                               // As a special case don't set 'foo' if a
+                                                               // separate 'foo' => true/false exists in the array
+                                                               // keys should be authoritive
+                                                               $newValue[] = $v;
+                                                       }
+                                               } elseif ( $v ) {
+                                                       // If the value is truthy but not a string this is likely
+                                                       // an array( 'foo' => true ), falsy values don't add strings
+                                                       $newValue[] = $k;
+                                               }
+                                       }
+                                       $value = implode( ' ', $newValue );
+                               }
+                               $value = explode( ' ', $value );
+
+                               // Normalize spacing by fixing up cases where people used
+                               // more than 1 space and/or a trailing/leading space
+                               $value = array_diff( $value, array( '', ' ' ) );
+
+                               // Remove duplicates and create the string
+                               $value = implode( ' ', array_unique( $value ) );
+                       }
+
+                       # See the "Attributes" section in the HTML syntax part of HTML5,
                        # 9.1.2.3 as of 2009-08-10.  Most attributes can have quotation
                        # marks omitted, but not all.  (Although a literal " is not
                        # permitted, we don't check for that, since it will be escaped
@@ -338,7 +505,7 @@ class Html {
 
                        if ( in_array( $key, self::$boolAttribs ) ) {
                                # In XHTML 1.0 Transitional, the value needs to be equal to the
-                               # key.  In HTML 5, we can leave the value empty instead.  If we
+                               # key.  In HTML5, we can leave the value empty instead.  If we
                                # don't need well-formed XML, we can omit the = entirely.
                                if ( !$wgWellFormedXml ) {
                                        $ret .= " $key";
@@ -351,7 +518,8 @@ class Html {
                                # Apparently we need to entity-encode \n, \r, \t, although the
                                # spec doesn't mention that.  Since we're doing strtr() anyway,
                                # and we don't need <> escaped here, we may as well not call
-                               # htmlspecialchars().  FIXME: verify that we actually need to
+                               # htmlspecialchars().
+                               # @todo FIXME: Verify that we actually need to
                                # escape \n\r\t here, and explain why, exactly.
                                #
                                # We could call Sanitizer::encodeAttribute() for this, but we
@@ -365,10 +533,12 @@ class Html {
                                        "\t" => '&#9;'
                                );
                                if ( $wgWellFormedXml ) {
-                                       # '<' must be escaped in attributes for XML for some
-                                       # reason, per spec: http://www.w3.org/TR/xml/#NT-AttValue
+                                       # This is allowed per spec: <http://www.w3.org/TR/xml/#NT-AttValue>
+                                       # But reportedly it breaks some XML tools?
+                                       # @todo FIXME: Is this really true?
                                        $map['<'] = '&lt;';
                                }
+                               
                                $ret .= " $key=$quote" . strtr( $value, $map ) . $quote;
                        }
                }
@@ -387,12 +557,15 @@ class Html {
                global $wgHtml5, $wgJsMimeType, $wgWellFormedXml;
 
                $attrs = array();
+
                if ( !$wgHtml5 ) {
                        $attrs['type'] = $wgJsMimeType;
                }
+
                if ( $wgWellFormedXml && preg_match( '/[<&]/', $contents ) ) {
                        $contents = "/*<![CDATA[*/$contents/*]]>*/";
                }
+
                return self::rawElement( 'script', $attrs, $contents );
        }
 
@@ -407,9 +580,11 @@ class Html {
                global $wgHtml5, $wgJsMimeType;
 
                $attrs = array( 'src' => $url );
+
                if ( !$wgHtml5 ) {
                        $attrs['type'] = $wgJsMimeType;
                }
+
                return self::element( 'script', $attrs );
        }
 
@@ -428,6 +603,7 @@ class Html {
                if ( $wgWellFormedXml && preg_match( '/[<&]/', $contents ) ) {
                        $contents = "/*<![CDATA[*/$contents/*]]>*/";
                }
+
                return self::rawElement( 'style', array(
                        'type' => 'text/css',
                        'media' => $media,
@@ -453,7 +629,7 @@ class Html {
 
        /**
         * Convenience function to produce an <input> element.  This supports the
-        * new HTML 5 input types and attributes, and will silently strip them if
+        * new HTML5 input types and attributes, and will silently strip them if
         * $wgHtml5 is false.
         *
         * @param $name    string name attribute
@@ -472,8 +648,7 @@ class Html {
        }
 
        /**
-        * Convenience function to produce an input element with type=hidden, like
-        * Xml::hidden.
+        * Convenience function to produce an input element with type=hidden
         *
         * @param $name    string name attribute
         * @param $value   string value attribute
@@ -484,4 +659,148 @@ class Html {
        public static function hidden( $name, $value, $attribs = array() ) {
                return self::input( $name, $value, 'hidden', $attribs );
        }
+
+       /**
+        * Convenience function to produce an <input> element.  This supports leaving
+        * out the cols= and rows= which Xml requires and are required by HTML4/XHTML
+        * but not required by HTML5 and will silently set cols="" and rows="" if
+        * $wgHtml5 is false and cols and rows are omitted (HTML4 validates present
+        * but empty cols="" and rows="" as valid).
+        *
+        * @param $name    string name attribute
+        * @param $value   string value attribute
+        * @param $attribs array  Associative array of miscellaneous extra
+        *   attributes, passed to Html::element()
+        * @return string Raw HTML
+        */
+       public static function textarea( $name, $value = '', $attribs = array() ) {
+               global $wgHtml5;
+
+               $attribs['name'] = $name;
+
+               if ( !$wgHtml5 ) {
+                       if ( !isset( $attribs['cols'] ) ) {
+                               $attribs['cols'] = "";
+                       }
+
+                       if ( !isset( $attribs['rows'] ) ) {
+                               $attribs['rows'] = "";
+                       }
+               }
+
+               if (substr($value, 0, 1) == "\n") {
+                       // Workaround for bug 12130: browsers eat the initial newline
+                       // assuming that it's just for show, but they do keep the later
+                       // newlines, which we may want to preserve during editing.
+                       // Prepending a single newline
+                       $spacedValue = "\n" . $value;
+               } else {
+                       $spacedValue = $value;
+               }
+               return self::element( 'textarea', $attribs, $spacedValue );
+       }
+
+       /**
+        * Constructs the opening html-tag with necessary doctypes depending on
+        * global variables.
+        *
+        * @param $attribs array  Associative array of miscellaneous extra
+        *   attributes, passed to Html::element() of html tag.
+        * @return string  Raw HTML
+        */
+       public static function htmlHeader( $attribs = array() ) {
+               $ret = '';
+
+               global $wgMimeType;
+
+               if ( self::isXmlMimeType( $wgMimeType ) ) {
+                       $ret .= "<?xml version=\"1.0\" encoding=\"UTF-8\" ?" . ">\n";
+               }
+
+               global $wgHtml5, $wgHtml5Version, $wgDocType, $wgDTD;
+               global $wgXhtmlNamespaces, $wgXhtmlDefaultNamespace;
+
+               if ( $wgHtml5 ) {
+                       $ret .= "<!DOCTYPE html>\n";
+
+                       if ( $wgHtml5Version ) {
+                               $attribs['version'] = $wgHtml5Version;
+                       }
+               } else {
+                       $ret .= "<!DOCTYPE html PUBLIC \"$wgDocType\" \"$wgDTD\">\n";
+                       $attribs['xmlns'] = $wgXhtmlDefaultNamespace;
+
+                       foreach ( $wgXhtmlNamespaces as $tag => $ns ) {
+                               $attribs["xmlns:$tag"] = $ns;
+                       }
+               }
+
+               $html = Html::openElement( 'html', $attribs );
+
+               if ( $html ) {
+                       $html .= "\n";
+               }
+
+               $ret .= $html;
+
+               return $ret;
+       }
+
+       /**
+        * Determines if the given mime type is xml.
+        *
+        * @param $mimetype    string MimeType
+        * @return Boolean
+        */
+       public static function isXmlMimeType( $mimetype ) {
+               switch ( $mimetype ) {
+                       case 'text/xml':
+                       case 'application/xhtml+xml':
+                       case 'application/xml':
+                               return true;
+                       default:
+                               return false;
+               }
+       }
+
+       /**
+        * Get HTML for an info box with an icon.
+        *
+        * @param $text String: wikitext, get this with wfMsgNoTrans()
+        * @param $icon String: icon name, file in skins/common/images
+        * @param $alt String: alternate text for the icon
+        * @param $class String: additional class name to add to the wrapper div
+        * @param $useStylePath
+        *
+        * @return string
+        */
+       static function infoBox( $text, $icon, $alt, $class = false, $useStylePath = true ) {
+               global $wgStylePath;
+
+               if ( $useStylePath ) {
+                       $icon = $wgStylePath.'/common/images/'.$icon;
+               }
+
+               $s  = Html::openElement( 'div', array( 'class' => "mw-infobox $class") );
+
+               $s .= Html::openElement( 'div', array( 'class' => 'mw-infobox-left' ) ).
+                               Html::element( 'img',
+                                       array(
+                                               'src' => $icon,
+                                               'alt' => $alt,
+                                       )
+                               ).
+                               Html::closeElement( 'div' );
+
+               $s .= Html::openElement( 'div', array( 'class' => 'mw-infobox-right' ) ).
+                               $text.
+                               Html::closeElement( 'div' );
+               $s .= Html::element( 'div', array( 'style' => 'clear: left;' ), ' ' );
+
+               $s .= Html::closeElement( 'div' );
+
+               $s .= Html::element( 'div', array( 'style' => 'clear: left;' ), ' ' );
+
+               return $s;
+       }
 }