2006-08-04 02:48:20 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
require_once 'HTMLPurifier/AttrDef.php';
|
|
|
|
require_once 'HTMLPurifier/Config.php';
|
|
|
|
|
2006-08-20 21:47:15 +00:00
|
|
|
/**
|
2007-02-03 20:15:33 +00:00
|
|
|
* Validates contents based on NMTOKENS attribute type.
|
|
|
|
* @note The only current use for this is the class attribute in HTML
|
|
|
|
* @note Could have some functionality factored out into Nmtoken class
|
|
|
|
* @warning We cannot assume this class will be used only for 'class'
|
|
|
|
* attributes. Not sure how to hook in magic behavior, then.
|
2006-08-20 21:47:15 +00:00
|
|
|
*/
|
2007-02-14 20:38:51 +00:00
|
|
|
class HTMLPurifier_AttrDef_HTML_Nmtokens extends HTMLPurifier_AttrDef
|
2006-08-04 02:48:20 +00:00
|
|
|
{
|
|
|
|
|
2008-01-05 00:10:43 +00:00
|
|
|
public function validate($string, $config, $context) {
|
2006-08-04 02:48:20 +00:00
|
|
|
|
2006-08-05 00:30:31 +00:00
|
|
|
$string = trim($string);
|
2006-08-04 02:48:20 +00:00
|
|
|
|
|
|
|
// early abort: '' and '0' (strings that convert to false) are invalid
|
|
|
|
if (!$string) return false;
|
|
|
|
|
|
|
|
// OPTIMIZABLE!
|
|
|
|
// do the preg_match, capture all subpatterns for reformulation
|
|
|
|
|
|
|
|
// we don't support U+00A1 and up codepoints or
|
|
|
|
// escaping because I don't know how to do that with regexps
|
|
|
|
// and plus it would complicate optimization efforts (you never
|
|
|
|
// see that anyway).
|
|
|
|
$matches = array();
|
2006-11-12 19:26:49 +00:00
|
|
|
$pattern = '/(?:(?<=\s)|\A)'. // look behind for space or string start
|
2006-08-05 00:30:31 +00:00
|
|
|
'((?:--|-?[A-Za-z_])[A-Za-z_\-0-9]*)'.
|
2006-11-12 19:26:49 +00:00
|
|
|
'(?:(?=\s)|\z)/'; // look ahead for space or string end
|
2006-08-04 02:48:20 +00:00
|
|
|
preg_match_all($pattern, $string, $matches);
|
|
|
|
|
2006-08-05 00:30:31 +00:00
|
|
|
if (empty($matches[1])) return false;
|
|
|
|
|
2007-02-03 20:15:33 +00:00
|
|
|
// reconstruct string
|
2006-08-04 02:48:20 +00:00
|
|
|
$new_string = '';
|
2007-02-03 20:15:33 +00:00
|
|
|
foreach ($matches[1] as $token) {
|
|
|
|
$new_string .= $token . ' ';
|
2006-08-04 02:48:20 +00:00
|
|
|
}
|
|
|
|
$new_string = rtrim($new_string);
|
|
|
|
|
2006-08-05 00:30:31 +00:00
|
|
|
return $new_string;
|
2006-08-04 02:48:20 +00:00
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|