wiki.techinc.nl/includes/HTMLForm.php

1576 lines
39 KiB
PHP
Raw Normal View History

<?php
/**
* Object handling generic submission, CSRF protection, layout and
* other logic for UI forms. in a reusable manner.
*
* In order to generate the form, the HTMLForm object takes an array
* structure detailing the form fields available. Each element of the
* array is a basic property-list, including the type of field, the
* label it is to be given in the form, callbacks for validation and
* 'filtering', and other pertinent information.
*
* Field types are implemented as subclasses of the generic HTMLFormField
* object, and typically implement at least getInputHTML, which generates
* the HTML for the input field to be placed in the table.
*
* The constructor input is an associative array of $fieldname => $info,
* where $info is an Associative Array with any of the following:
*
* 'class' -- the subclass of HTMLFormField that will be used
* to create the object. *NOT* the CSS class!
* 'type' -- roughly translates into the <select> type attribute.
* if 'class' is not specified, this is used as a map
* through HTMLForm::$typeMappings to get the class name.
* 'default' -- default value when the form is displayed
* 'id' -- HTML id attribute
* 'cssclass' -- CSS class
* 'options' -- varies according to the specific object.
* 'label-message' -- message key for a message to use as the label.
* can be an array of msg key and then parameters to
* the message.
* 'label' -- alternatively, a raw text message. Overridden by
* label-message
* 'help-message' -- message key for a message to use as a help text.
* can be an array of msg key and then parameters to
* the message.
* 'required' -- passed through to the object, indicating that it
* is a required field.
* 'size' -- the length of text fields
* 'filter-callback -- a function name to give you the chance to
* massage the inputted value before it's processed.
* @see HTMLForm::filter()
* 'validation-callback' -- a function name to give you the chance
* to impose extra validation on the field input.
* @see HTMLForm::validate()
*
* TODO: Document 'section' / 'subsection' stuff
*/
class HTMLForm {
static $jsAdded = false;
# A mapping of 'type' inputs onto standard HTMLFormField subclasses
2009-06-21 18:26:29 +00:00
static $typeMappings = array(
'text' => 'HTMLTextField',
'textarea' => 'HTMLTextAreaField',
2009-06-21 18:26:29 +00:00
'select' => 'HTMLSelectField',
'radio' => 'HTMLRadioField',
'multiselect' => 'HTMLMultiSelectField',
'check' => 'HTMLCheckField',
'toggle' => 'HTMLCheckField',
'int' => 'HTMLIntField',
'float' => 'HTMLFloatField',
2009-06-21 18:26:29 +00:00
'info' => 'HTMLInfoField',
'selectorother' => 'HTMLSelectOrOtherField',
'submit' => 'HTMLSubmitField',
'hidden' => 'HTMLHiddenField',
'edittools' => 'HTMLEditTools',
Start using some HTML 5 form features autofocus attribute added in some places; this looks like it's respected by both recent Opera and recent WebKit. Its function is self-explanatory. :) I used this in a few obvious places like Special:UserLogin and Special:ResetPass to focus the first field in the form. Could be used in other places too: Special:Search, etc. required attribute added in some places. This is only supported in recent Opera at the moment. Also self-explanatory: it won't allow form submission if the field is empty. For stuff using HTMLForm (i.e., Special:Preferences), validation will be done for integers and floats. Browsers that support this (recent Opera) will not allow non-integers to be submitted for integer fields, will not allow non-floating-point values to be submitted for float fields, and will enforce any min/max values specified. Opera also gives little up and down arrows to allow the user to increment/decrement the value in addition to letting them edit the field as text. For HTMLForm and account creation, the email input type is used for e-mails. This enforces a sane set of values for e-mails (alphanumerics plus some ASCII punctuation, with an @ in it). Again, this is supported only by recent Opera (yay Opera!). Note that this is actually more restrictive than what we currently check for on the server side; it might be sane to tighten up our server-side checks to forbid e-mail addresses that HTML 5 forbids. In all cases, the extra features aren't added if $wgHtml5 is false, and will be ignored by non-supporting browsers. The major room for further improvement here is use of the pattern attribute. We can have the client refuse to submit the form unless it matches a regex! The HTML 5 spec says that if a title attribute is provided, it should be a message that explains what the valid values are and browsers should provide it to the user if the regex doesn't match, so it's not a usability problem. I didn't bother adding that anywhere at this point because it would require adding new messages, but it should be easy to do. Note of course that HTMLForm should be updated to verify that pattern matches on the server side as well -- this way we have a clean, unified way of ensuring that our client and server checks are the same.
2009-08-07 03:32:20 +00:00
# HTMLTextField will output the correct type="" attribute automagically.
# There are about four zillion other HTML5 input types, like url, but
Start using some HTML 5 form features autofocus attribute added in some places; this looks like it's respected by both recent Opera and recent WebKit. Its function is self-explanatory. :) I used this in a few obvious places like Special:UserLogin and Special:ResetPass to focus the first field in the form. Could be used in other places too: Special:Search, etc. required attribute added in some places. This is only supported in recent Opera at the moment. Also self-explanatory: it won't allow form submission if the field is empty. For stuff using HTMLForm (i.e., Special:Preferences), validation will be done for integers and floats. Browsers that support this (recent Opera) will not allow non-integers to be submitted for integer fields, will not allow non-floating-point values to be submitted for float fields, and will enforce any min/max values specified. Opera also gives little up and down arrows to allow the user to increment/decrement the value in addition to letting them edit the field as text. For HTMLForm and account creation, the email input type is used for e-mails. This enforces a sane set of values for e-mails (alphanumerics plus some ASCII punctuation, with an @ in it). Again, this is supported only by recent Opera (yay Opera!). Note that this is actually more restrictive than what we currently check for on the server side; it might be sane to tighten up our server-side checks to forbid e-mail addresses that HTML 5 forbids. In all cases, the extra features aren't added if $wgHtml5 is false, and will be ignored by non-supporting browsers. The major room for further improvement here is use of the pattern attribute. We can have the client refuse to submit the form unless it matches a regex! The HTML 5 spec says that if a title attribute is provided, it should be a message that explains what the valid values are and browsers should provide it to the user if the regex doesn't match, so it's not a usability problem. I didn't bother adding that anywhere at this point because it would require adding new messages, but it should be easy to do. Note of course that HTMLForm should be updated to verify that pattern matches on the server side as well -- this way we have a clean, unified way of ensuring that our client and server checks are the same.
2009-08-07 03:32:20 +00:00
# we don't use those at the moment, so no point in adding all of them.
'email' => 'HTMLTextField',
2009-09-06 15:41:24 +00:00
'password' => 'HTMLTextField',
2009-06-21 18:26:29 +00:00
);
protected $mMessagePrefix;
protected $mFlatFields;
protected $mFieldTree;
protected $mShowReset = false;
public $mFieldData;
protected $mSubmitCallback;
protected $mValidationErrorMessage;
protected $mPre = '';
protected $mHeader = '';
protected $mFooter = '';
protected $mPost = '';
protected $mId;
protected $mSubmitID;
protected $mSubmitName;
protected $mSubmitText;
protected $mSubmitTooltip;
protected $mTitle;
protected $mMethod = 'post';
protected $mUseMultipart = false;
protected $mHiddenFields = array();
protected $mButtons = array();
protected $mWrapperLegend = false;
2009-06-21 18:26:29 +00:00
/**
* Build a new HTMLForm from an array of field attributes
* @param $descriptor Array of Field constructs, as described above
* @param $messagePrefix String a prefix to go in front of default messages
*/
public function __construct( $descriptor, $messagePrefix = '' ) {
$this->mMessagePrefix = $messagePrefix;
2009-06-21 18:26:29 +00:00
// Expand out into a tree.
$loadedDescriptor = array();
$this->mFlatFields = array();
2009-06-21 18:26:29 +00:00
foreach ( $descriptor as $fieldname => $info ) {
$section = isset( $info['section'] )
? $info['section']
: '';
2009-06-21 18:26:29 +00:00
$info['name'] = isset( $info['name'] )
? $info['name']
: $fieldname;
2009-06-21 18:26:29 +00:00
if ( isset( $info['type'] ) && $info['type'] == 'file' ) {
$this->mUseMultipart = true;
}
$field = self::loadInputFromParameters( $info );
$field->mParent = $this;
2009-06-21 18:26:29 +00:00
$setSection =& $loadedDescriptor;
if ( $section ) {
$sectionParts = explode( '/', $section );
2009-06-21 18:26:29 +00:00
while ( count( $sectionParts ) ) {
$newName = array_shift( $sectionParts );
2009-06-21 18:26:29 +00:00
if ( !isset( $setSection[$newName] ) ) {
$setSection[$newName] = array();
}
2009-06-21 18:26:29 +00:00
$setSection =& $setSection[$newName];
}
}
2009-06-21 18:26:29 +00:00
$setSection[$fieldname] = $field;
$this->mFlatFields[$fieldname] = $field;
}
2009-06-21 18:26:29 +00:00
$this->mFieldTree = $loadedDescriptor;
}
2009-06-21 18:26:29 +00:00
/**
* Add the HTMLForm-specific JavaScript, if it hasn't been
* done already.
*/
static function addJS() {
if ( self::$jsAdded ) return;
2009-06-21 18:26:29 +00:00
global $wgOut;
2009-06-21 18:26:29 +00:00
$wgOut->addModules( 'mediawiki.legacy.htmlform' );
}
/**
* Initialise a new Object for the field
* @param $descriptor input Descriptor, as described above
* @return HTMLFormField subclass
*/
static function loadInputFromParameters( $descriptor ) {
if ( isset( $descriptor['class'] ) ) {
$class = $descriptor['class'];
} elseif ( isset( $descriptor['type'] ) ) {
$class = self::$typeMappings[$descriptor['type']];
$descriptor['class'] = $class;
}
2009-06-21 18:26:29 +00:00
if ( !$class ) {
2009-06-21 18:26:29 +00:00
throw new MWException( "Descriptor with no class: " . print_r( $descriptor, true ) );
}
2009-06-21 18:26:29 +00:00
$obj = new $class( $descriptor );
2009-06-21 18:26:29 +00:00
return $obj;
}
/**
* Prepare form for submission
*/
function prepareForm() {
# Check if we have the info we need
if ( ! $this->mTitle ) {
throw new MWException( "You must call setTitle() on an HTMLForm" );
}
2009-06-21 18:26:29 +00:00
// FIXME shouldn't this be closer to displayForm() ?
self::addJS();
2009-06-21 18:26:29 +00:00
# Load data from the request.
$this->loadData();
}
2009-06-21 18:26:29 +00:00
/**
* Try submitting, with edit token check first
* @return Status|boolean
*/
function tryAuthorizedSubmit() {
global $wgUser, $wgRequest;
$editToken = $wgRequest->getVal( 'wpEditToken' );
2009-06-21 18:26:29 +00:00
$result = false;
if ( $wgUser->matchEditToken( $editToken ) ) {
$result = $this->trySubmit();
}
return $result;
}
2009-06-21 18:26:29 +00:00
/**
* The here's-one-I-made-earlier option: do the submission if
* posted, or display the form with or without funky valiation
* errors
* @return Bool or Status whether submission was successful.
*/
function show() {
$this->prepareForm();
$result = $this->tryAuthorizedSubmit();
if ( $result === true || ( $result instanceof Status && $result->isGood() ) ){
return $result;
}
2009-06-21 18:26:29 +00:00
$this->displayForm( $result );
return false;
}
2009-06-21 18:26:29 +00:00
/**
* Validate all the fields, and call the submision callback
* function if everything is kosher.
* @return Mixed Bool true == Successful submission, Bool false
* == No submission attempted, anything else == Error to
* display.
*/
function trySubmit() {
# Check for validation
foreach ( $this->mFlatFields as $fieldname => $field ) {
if ( !empty( $field->mParams['nodata'] ) ) {
continue;
}
if ( $field->validate(
$this->mFieldData[$fieldname],
$this->mFieldData )
!== true
) {
return isset( $this->mValidationErrorMessage )
? $this->mValidationErrorMessage
: array( 'htmlform-invalid-input' );
}
}
2009-06-21 18:26:29 +00:00
$callback = $this->mSubmitCallback;
2009-06-21 18:26:29 +00:00
$data = $this->filterDataForSubmit( $this->mFieldData );
2009-06-21 18:26:29 +00:00
$res = call_user_func( $callback, $data );
2009-06-21 18:26:29 +00:00
return $res;
}
2009-06-21 18:26:29 +00:00
/**
* Set a callback to a function to do something with the form
* once it's been successfully validated.
* @param $cb String function name. The function will be passed
* the output from HTMLForm::filterDataForSubmit, and must
* return Bool true on success, Bool false if no submission
* was attempted, or String HTML output to display on error.
*/
function setSubmitCallback( $cb ) {
$this->mSubmitCallback = $cb;
}
2009-06-21 18:26:29 +00:00
/**
* Set a message to display on a validation error.
* @param $msg Mixed String or Array of valid inputs to wfMsgExt()
* (so each entry can be either a String or Array)
*/
function setValidationErrorMessage( $msg ) {
$this->mValidationErrorMessage = $msg;
}
/**
* Set the introductory message, overwriting any existing message.
* @param $msg String complete text of message to display
*/
function setIntro( $msg ) { $this->mPre = $msg; }
2009-06-21 18:26:29 +00:00
/**
* Add introductory text.
* @param $msg String complete text of message to display
*/
function addPreText( $msg ) { $this->mPre .= $msg; }
/**
* Add header text, inside the form.
* @param $msg String complete text of message to display
*/
function addHeaderText( $msg ) { $this->mHeader .= $msg; }
/**
* Add footer text, inside the form.
* @param $msg String complete text of message to display
*/
function addFooterText( $msg ) { $this->mFooter .= $msg; }
/**
* Add text to the end of the display.
* @param $msg String complete text of message to display
*/
function addPostText( $msg ) { $this->mPost .= $msg; }
/**
* Add a hidden field to the output
* @param $name String field name
* @param $value String field value
* @param $attribs Array
*/
public function addHiddenField( $name, $value, $attribs = array() ) {
$attribs += array( 'name' => $name );
$this->mHiddenFields[] = array( $value, $attribs );
}
public function addButton( $name, $value, $id = null, $attribs = null ) {
$this->mButtons[] = compact( 'name', 'value', 'id', 'attribs' );
}
2009-06-21 18:26:29 +00:00
/**
* Display the form (sending to wgOut), with an appropriate error
* message or stack of messages, and any validation errors, etc.
* @param $submitResult Mixed output from HTMLForm::trySubmit()
*/
function displayForm( $submitResult ) {
global $wgOut;
2009-06-21 18:26:29 +00:00
$html = ''
. $this->getErrors( $submitResult )
. $this->mHeader
. $this->getBody()
. $this->getHiddenFields()
. $this->getButtons()
. $this->mFooter
;
2009-06-21 18:26:29 +00:00
$html = $this->wrapForm( $html );
2009-06-21 18:26:29 +00:00
$wgOut->addHTML( ''
. $this->mPre
. $html
. $this->mPost
);
}
2009-06-21 18:26:29 +00:00
/**
* Wrap the form innards in an actual <form> element
* @param $html String HTML contents to wrap.
* @return String wrapped HTML.
*/
function wrapForm( $html ) {
# Include a <fieldset> wrapper for style, if requested.
if ( $this->mWrapperLegend !== false ) {
$html = Xml::fieldset( $this->mWrapperLegend, $html );
}
# Use multipart/form-data
$encType = $this->mUseMultipart
? 'multipart/form-data'
: 'application/x-www-form-urlencoded';
# Attributes
$attribs = array(
'action' => $this->getTitle()->getFullURL(),
'method' => $this->mMethod,
'class' => 'visualClear',
'enctype' => $encType,
2009-06-21 18:26:29 +00:00
);
if ( !empty( $this->mId ) ) {
$attribs['id'] = $this->mId;
}
return Html::rawElement( 'form', $attribs, $html );
}
2009-06-21 18:26:29 +00:00
/**
* Get the hidden fields that should go inside the form.
* @return String HTML.
*/
function getHiddenFields() {
global $wgUser;
2009-06-21 18:26:29 +00:00
$html = '';
$html .= Html::hidden( 'wpEditToken', $wgUser->editToken(), array( 'id' => 'wpEditToken' ) ) . "\n";
2009-11-16 16:21:11 +00:00
$html .= Html::hidden( 'title', $this->getTitle()->getPrefixedText() ) . "\n";
foreach ( $this->mHiddenFields as $data ) {
list( $value, $attribs ) = $data;
$html .= Html::hidden( $attribs['name'], $value, $attribs ) . "\n";
}
2009-06-21 18:26:29 +00:00
return $html;
}
2009-06-21 18:26:29 +00:00
/**
* Get the submit and (potentially) reset buttons.
* @return String HTML.
*/
function getButtons() {
$html = '';
$attribs = array();
2009-06-21 18:26:29 +00:00
if ( isset( $this->mSubmitID ) ) {
$attribs['id'] = $this->mSubmitID;
}
if ( isset( $this->mSubmitName ) ) {
$attribs['name'] = $this->mSubmitName;
}
if ( isset( $this->mSubmitTooltip ) ) {
global $wgUser;
$attribs += $wgUser->getSkin()->tooltipAndAccessKeyAttribs( $this->mSubmitTooltip );
}
2009-06-21 18:26:29 +00:00
$attribs['class'] = 'mw-htmlform-submit';
2009-06-21 18:26:29 +00:00
$html .= Xml::submitButton( $this->getSubmitText(), $attribs ) . "\n";
2009-06-21 18:26:29 +00:00
if ( $this->mShowReset ) {
2009-09-07 01:47:45 +00:00
$html .= Html::element(
2009-06-21 18:26:29 +00:00
'input',
array(
'type' => 'reset',
'value' => wfMsg( 'htmlform-reset' )
)
) . "\n";
}
foreach ( $this->mButtons as $button ) {
$attrs = array(
'type' => 'submit',
'name' => $button['name'],
'value' => $button['value']
);
if ( $button['attribs'] ) {
$attrs += $button['attribs'];
}
if ( isset( $button['id'] ) ) {
$attrs['id'] = $button['id'];
}
$html .= Html::element( 'input', $attrs );
}
return $html;
}
2009-06-21 18:26:29 +00:00
/**
* Get the whole body of the form.
*/
function getBody() {
return $this->displaySection( $this->mFieldTree );
}
2009-06-21 18:26:29 +00:00
/**
* Format and display an error message stack.
* @param $errors Mixed String or Array of message keys
* @return String
*/
function getErrors( $errors ) {
if ( $errors instanceof Status ) {
global $wgOut;
$errorstr = $wgOut->parse( $errors->getWikiText() );
} elseif ( is_array( $errors ) ) {
$errorstr = $this->formatErrors( $errors );
} else {
$errorstr = $errors;
}
return $errorstr
? Html::rawElement( 'div', array( 'class' => 'error' ), $errorstr )
: '';
}
2009-06-21 18:26:29 +00:00
/**
* Format a stack of error messages into a single HTML string
* @param $errors Array of message keys/values
* @return String HTML, a <ul> list of errors
*/
static function formatErrors( $errors ) {
$errorstr = '';
foreach ( $errors as $error ) {
if ( is_array( $error ) ) {
2009-06-21 18:26:29 +00:00
$msg = array_shift( $error );
} else {
$msg = $error;
$error = array();
}
2009-09-07 01:47:45 +00:00
$errorstr .= Html::rawElement(
2009-06-21 18:26:29 +00:00
'li',
null,
wfMsgExt( $msg, array( 'parseinline' ), $error )
);
}
2009-06-21 18:26:29 +00:00
2009-09-07 01:47:45 +00:00
$errorstr = Html::rawElement( 'ul', array(), $errorstr );
2009-06-21 18:26:29 +00:00
return $errorstr;
}
2009-06-21 18:26:29 +00:00
/**
* Set the text for the submit button
* @param $t String plaintext.
*/
function setSubmitText( $t ) {
$this->mSubmitText = $t;
}
2009-06-21 18:26:29 +00:00
/**
* Get the text for the submit button, either customised or a default.
* @return unknown_type
*/
function getSubmitText() {
return $this->mSubmitText
? $this->mSubmitText
: wfMsg( 'htmlform-submit' );
}
public function setSubmitName( $name ) {
$this->mSubmitName = $name;
}
public function setSubmitTooltip( $name ) {
$this->mSubmitTooltip = $name;
}
/**
* Set the id for the submit button.
* @param $t String. FIXME: Integrity is *not* validated
*/
function setSubmitID( $t ) {
$this->mSubmitID = $t;
}
public function setId( $id ) {
$this->mId = $id;
}
/**
* Prompt the whole form to be wrapped in a <fieldset>, with
* this text as its <legend> element.
* @param $legend String HTML to go inside the <legend> element.
* Will be escaped
*/
public function setWrapperLegend( $legend ) { $this->mWrapperLegend = $legend; }
2009-06-21 18:26:29 +00:00
/**
* Set the prefix for various default messages
* TODO: currently only used for the <fieldset> legend on forms
* with multiple sections; should be used elsewhre?
* @param $p String
*/
function setMessagePrefix( $p ) {
$this->mMessagePrefix = $p;
}
2009-06-21 18:26:29 +00:00
/**
* Set the title for form submission
* @param $t Title of page the form is on/should be posted to
*/
function setTitle( $t ) {
$this->mTitle = $t;
}
2009-06-21 18:26:29 +00:00
/**
* Get the title
* @return Title
*/
function getTitle() {
return $this->mTitle;
}
/**
* Set the method used to submit the form
* @param $method String
*/
public function setMethod( $method='post' ){
$this->mMethod = $method;
}
public function getMethod(){
return $this->mMethod;
}
2009-06-21 18:26:29 +00:00
/**
* TODO: Document
* @param $fields
*/
function displaySection( $fields, $sectionName = '' ) {
$tableHtml = '';
$subsectionHtml = '';
$hasLeftColumn = false;
2009-06-21 18:26:29 +00:00
foreach ( $fields as $key => $value ) {
if ( is_object( $value ) ) {
2009-06-21 18:26:29 +00:00
$v = empty( $value->mParams['nodata'] )
? $this->mFieldData[$key]
: $value->getDefault();
$tableHtml .= $value->getTableRow( $v );
2009-06-21 18:26:29 +00:00
Remove most named character references from output Recommit of r66254 to trunk. This was just find extensions phase3 -iname '*.php' \! -iname '*.i18n.php' \! -iname 'Messages*.php' \! -iname '*_Messages.php' -exec sed -i 's/&nbsp;/\&#160;/g;s/&mdash;/―/g;s/&bull;/•/g;s/&aacute;/á/g;s/&acute;/´/g;s/&agrave;/à/g;s/&alpha;/α/g;s/&auml;/ä/g;s/&ccedil;/ç/g;s/&copy;/©/g;s/&darr;/↓/g;s/&deg;/°/g;s/&eacute;/é/g;s/&ecirc;/ê/g;s/&euml;/ë/g;s/&egrave;/è/g;s/&euro;/€/g;s/&harr;//g;s/&hellip;/…/g;s/&iacute;/í/g;s/&igrave;/ì/g;s/&larr;/←/g;s/&ldquo;/“/g;s/&middot;/·/g;s/&minus;/−/g;s/&ndash;/–/g;s/&oacute;/ó/g;s/&ocirc;/ô/g;s/&oelig;/œ/g;s/&ograve;/ò/g;s/&otilde;/õ/g;s/&ouml;/ö/g;s/&pound;/£/g;s/&prime;/′/g;s/&Prime;/″/g;s/&raquo;/»/g;s/&rarr;/→/g;s/&rdquo;/”/g;s/&Sigma;/Σ/g;s/&times;/×/g;s/&uacute;/ú/g;s/&uarr;/↑/g;s/&uuml;/ü/g;s/&yen;/¥/g' {} + followed by reading over every single line of the resulting diff and fixing a whole bunch of false positives. The reason for this change is given in <http://lists.wikimedia.org/pipermail/wikitech-l/2010-April/047617.html>. I cleared it with Tim and Brion on IRC before committing. It might cause a few problems, but I tried to be careful; please report any issues. I skipped all messages files. I plan to make a follow-up commit that alters wfMsgExt() with 'escapenoentities' to sanitize all the entities. That way, the only messages that will be problems will be ones that output raw HTML, and we want to get rid of those anyway. This should get rid of all named entities everywhere except messages. I skipped a few things like &nbsp that I noticed in manual inspection, because they weren't well-formed XML anyway. Also, to everyone who uses non-breaking spaces when they could use a normal space, or nothing at all, or CSS padding: I still hate you. Die.
2010-05-30 17:33:59 +00:00
if ( $value->getLabel() != '&#160;' )
$hasLeftColumn = true;
} elseif ( is_array( $value ) ) {
$section = $this->displaySection( $value, $key );
$legend = wfMsg( "{$this->mMessagePrefix}-$key" );
$subsectionHtml .= Xml::fieldset( $legend, $section ) . "\n";
}
}
2009-06-21 18:26:29 +00:00
$classes = array();
if ( !$hasLeftColumn ) { // Avoid strange spacing when no labels exist
$classes[] = 'mw-htmlform-nolabel';
}
$attribs = array(
'class' => implode( ' ', $classes ),
);
if ( $sectionName ) {
$attribs['id'] = Sanitizer::escapeId( "mw-htmlform-$sectionName" );
}
2009-06-21 18:26:29 +00:00
$tableHtml = Html::rawElement( 'table', $attribs,
2009-09-07 15:25:22 +00:00
Html::rawElement( 'tbody', array(), "\n$tableHtml\n" ) ) . "\n";
2009-06-21 18:26:29 +00:00
return $subsectionHtml . "\n" . $tableHtml;
}
2009-06-21 18:26:29 +00:00
/**
* Construct the form fields from the Descriptor array
*/
function loadData() {
global $wgRequest;
2009-06-21 18:26:29 +00:00
$fieldData = array();
2009-06-21 18:26:29 +00:00
foreach ( $this->mFlatFields as $fieldname => $field ) {
if ( !empty( $field->mParams['nodata'] ) ) {
continue;
} elseif ( !empty( $field->mParams['disabled'] ) ) {
$fieldData[$fieldname] = $field->getDefault();
} else {
$fieldData[$fieldname] = $field->loadDataFromRequest( $wgRequest );
}
}
2009-06-21 18:26:29 +00:00
# Filter data.
foreach ( $fieldData as $name => &$value ) {
$field = $this->mFlatFields[$name];
$value = $field->filter( $value, $this->mFlatFields );
}
$this->mFieldData = $fieldData;
}
2009-06-21 18:26:29 +00:00
/**
* Stop a reset button being shown for this form
* @param $suppressReset Bool set to false to re-enable the
* button again
*/
function suppressReset( $suppressReset = true ) {
$this->mShowReset = !$suppressReset;
}
2009-06-21 18:26:29 +00:00
/**
* Overload this if you want to apply special filtration routines
* to the form as a whole, after it's submitted but before it's
* processed.
* @param $data
* @return unknown_type
*/
function filterDataForSubmit( $data ) {
return $data;
}
}
/**
* The parent class to generate form fields. Any field type should
* be a subclass of this.
*/
abstract class HTMLFormField {
protected $mValidationCallback;
protected $mFilterCallback;
protected $mName;
public $mParams;
protected $mLabel; # String label. Set on construction
protected $mID;
protected $mClass = '';
protected $mDefault;
public $mParent;
/**
* This function must be implemented to return the HTML to generate
* the input object itself. It should not implement the surrounding
* table cells/rows, or labels/help messages.
* @param $value String the value to set the input to; eg a default
* text for a text input.
* @return String valid HTML.
*/
abstract function getInputHTML( $value );
2009-06-21 18:26:29 +00:00
/**
* Override this function to add specific validation checks on the
* field input. Don't forget to call parent::validate() to ensure
* that the user-defined callback mValidationCallback is still run
* @param $value String the value the field was submitted with
* @param $alldata Array the data collected from the form
* @return Mixed Bool true on success, or String error to display.
*/
function validate( $value, $alldata ) {
2009-06-21 18:26:29 +00:00
if ( isset( $this->mValidationCallback ) ) {
return call_user_func( $this->mValidationCallback, $value, $alldata );
}
2009-06-21 18:26:29 +00:00
if ( isset( $this->mParams['required'] ) && $value === '' ) {
return wfMsgExt( 'htmlform-required', 'parseinline' );
}
return true;
}
2009-06-21 18:26:29 +00:00
function filter( $value, $alldata ) {
if ( isset( $this->mFilterCallback ) ) {
$value = call_user_func( $this->mFilterCallback, $value, $alldata );
}
2009-06-21 18:26:29 +00:00
return $value;
}
2009-06-21 18:26:29 +00:00
/**
* Should this field have a label, or is there no input element with the
* appropriate id for the label to point to?
*
* @return bool True to output a label, false to suppress
*/
protected function needsLabel() {
return true;
}
/**
* Get the value that this input has been set to from a posted form,
* or the input's default value if it has not been set.
* @param $request WebRequest
* @return String the value
*/
function loadDataFromRequest( $request ) {
if ( $request->getCheck( $this->mName ) ) {
return $request->getText( $this->mName );
} else {
return $this->getDefault();
}
}
2009-06-21 18:26:29 +00:00
/**
* Initialise the object
* @param $params Associative Array. See HTMLForm doc for syntax.
*/
function __construct( $params ) {
$this->mParams = $params;
2009-06-21 18:26:29 +00:00
# Generate the label from a message, if possible
if ( isset( $params['label-message'] ) ) {
$msgInfo = $params['label-message'];
2009-06-21 18:26:29 +00:00
if ( is_array( $msgInfo ) ) {
$msg = array_shift( $msgInfo );
} else {
$msg = $msgInfo;
$msgInfo = array();
}
2009-06-21 18:26:29 +00:00
$this->mLabel = wfMsgExt( $msg, 'parseinline', $msgInfo );
2009-06-21 18:26:29 +00:00
} elseif ( isset( $params['label'] ) ) {
$this->mLabel = $params['label'];
}
2009-06-21 18:26:29 +00:00
if ( isset( $params['name'] ) ) {
$name = $params['name'];
$validName = Sanitizer::escapeId( $name );
if ( $name != $validName ) {
throw new MWException( "Invalid name '$name' passed to " . __METHOD__ );
}
$this->mName = 'wp' . $name;
$this->mID = 'mw-input-' . $name;
}
2009-06-21 18:26:29 +00:00
if ( isset( $params['default'] ) ) {
$this->mDefault = $params['default'];
}
2009-06-21 18:26:29 +00:00
if ( isset( $params['id'] ) ) {
$id = $params['id'];
$validId = Sanitizer::escapeId( $id );
if ( $id != $validId ) {
throw new MWException( "Invalid id '$id' passed to " . __METHOD__ );
}
$this->mID = $id;
}
2009-06-21 18:26:29 +00:00
if ( isset( $params['cssclass'] ) ) {
$this->mClass = $params['cssclass'];
}
if ( isset( $params['validation-callback'] ) ) {
$this->mValidationCallback = $params['validation-callback'];
}
2009-06-21 18:26:29 +00:00
if ( isset( $params['filter-callback'] ) ) {
$this->mFilterCallback = $params['filter-callback'];
}
}
2009-06-21 18:26:29 +00:00
/**
* Get the complete table row for the input, including help text,
* labels, and whatever.
* @param $value String the value to set the input to.
* @return String complete HTML table row.
*/
function getTableRow( $value ) {
# Check for invalid data.
global $wgRequest;
2009-06-21 18:26:29 +00:00
$errors = $this->validate( $value, $this->mParent->mFieldData );
$cellAttributes = array();
$verticalLabel = false;
if ( !empty($this->mParams['vertical-label']) ) {
$cellAttributes['colspan'] = 2;
$verticalLabel = true;
}
if ( $errors === true || ( !$wgRequest->wasPosted() && ( $this->mParent->getMethod() == 'post' ) ) ) {
$errors = '';
} else {
2009-09-07 01:47:45 +00:00
$errors = Html::rawElement( 'span', array( 'class' => 'error' ), $errors );
}
2009-06-21 18:26:29 +00:00
$label = $this->getLabelHtml( $cellAttributes );
$field = Html::rawElement(
'td',
array( 'class' => 'mw-input' ) + $cellAttributes,
$this->getInputHTML( $value ) . "\n$errors"
);
2009-06-21 18:26:29 +00:00
$fieldType = get_class( $this );
if ($verticalLabel) {
$html = Html::rawElement( 'tr',
array( 'class' => 'mw-htmlform-vertical-label' ), $label );
$html .= Html::rawElement( 'tr',
array( 'class' => "mw-htmlform-field-$fieldType {$this->mClass}" ),
$field );
} else {
$html = Html::rawElement( 'tr',
array( 'class' => "mw-htmlform-field-$fieldType {$this->mClass}" ),
$label . $field );
}
2009-06-21 18:26:29 +00:00
$helptext = null;
2009-06-21 18:26:29 +00:00
if ( isset( $this->mParams['help-message'] ) ) {
$msg = $this->mParams['help-message'];
$helptext = wfMsgExt( $msg, 'parseinline' );
if ( wfEmptyMsg( $msg, $helptext ) ) {
# Never mind
$helptext = null;
}
} elseif ( isset( $this->mParams['help'] ) ) {
$helptext = $this->mParams['help'];
}
if ( !is_null( $helptext ) ) {
2009-09-07 01:47:45 +00:00
$row = Html::rawElement( 'td', array( 'colspan' => 2, 'class' => 'htmlform-tip' ),
$helptext );
2009-09-07 01:47:45 +00:00
$row = Html::rawElement( 'tr', array(), $row );
$html .= "$row\n";
}
2009-06-21 18:26:29 +00:00
return $html;
}
2009-06-21 18:26:29 +00:00
function getLabel() {
return $this->mLabel;
}
function getLabelHtml( $cellAttributes = array() ) {
# Don't output a for= attribute for labels with no associated input.
# Kind of hacky here, possibly we don't want these to be <label>s at all.
$for = array();
if ( $this->needsLabel() ) {
$for['for'] = $this->mID;
}
return Html::rawElement( 'td', array( 'class' => 'mw-label' ) + $cellAttributes,
Html::rawElement( 'label', $for, $this->getLabel() )
);
}
2009-06-21 18:26:29 +00:00
function getDefault() {
if ( isset( $this->mDefault ) ) {
return $this->mDefault;
} else {
return null;
}
}
/**
* Returns the attributes required for the tooltip and accesskey.
*
* @return array Attributes
*/
public function getTooltipAndAccessKey() {
if ( empty( $this->mParams['tooltip'] ) ) {
return array();
}
global $wgUser;
return $wgUser->getSkin()->tooltipAndAccessKeyAttribs( $this->mParams['tooltip'] );
}
2009-06-21 18:26:29 +00:00
/**
* flatten an array of options to a single array, for instance,
* a set of <options> inside <optgroups>.
* @param $options Associative Array with values either Strings
* or Arrays
* @return Array flattened input
*/
public static function flattenOptions( $options ) {
$flatOpts = array();
2009-06-21 18:26:29 +00:00
2010-10-14 20:53:04 +00:00
foreach ( $options as $value ) {
if ( is_array( $value ) ) {
$flatOpts = array_merge( $flatOpts, self::flattenOptions( $value ) );
} else {
$flatOpts[] = $value;
}
}
2009-06-21 18:26:29 +00:00
return $flatOpts;
}
}
class HTMLTextField extends HTMLFormField {
function getSize() {
return isset( $this->mParams['size'] )
? $this->mParams['size']
: 45;
}
function getInputHTML( $value ) {
2009-09-06 15:07:29 +00:00
$attribs = array(
'id' => $this->mID,
'name' => $this->mName,
'size' => $this->getSize(),
'value' => $value,
) + $this->getTooltipAndAccessKey();
2009-06-21 18:26:29 +00:00
if ( isset( $this->mParams['maxlength'] ) ) {
$attribs['maxlength'] = $this->mParams['maxlength'];
}
Start using some HTML 5 form features autofocus attribute added in some places; this looks like it's respected by both recent Opera and recent WebKit. Its function is self-explanatory. :) I used this in a few obvious places like Special:UserLogin and Special:ResetPass to focus the first field in the form. Could be used in other places too: Special:Search, etc. required attribute added in some places. This is only supported in recent Opera at the moment. Also self-explanatory: it won't allow form submission if the field is empty. For stuff using HTMLForm (i.e., Special:Preferences), validation will be done for integers and floats. Browsers that support this (recent Opera) will not allow non-integers to be submitted for integer fields, will not allow non-floating-point values to be submitted for float fields, and will enforce any min/max values specified. Opera also gives little up and down arrows to allow the user to increment/decrement the value in addition to letting them edit the field as text. For HTMLForm and account creation, the email input type is used for e-mails. This enforces a sane set of values for e-mails (alphanumerics plus some ASCII punctuation, with an @ in it). Again, this is supported only by recent Opera (yay Opera!). Note that this is actually more restrictive than what we currently check for on the server side; it might be sane to tighten up our server-side checks to forbid e-mail addresses that HTML 5 forbids. In all cases, the extra features aren't added if $wgHtml5 is false, and will be ignored by non-supporting browsers. The major room for further improvement here is use of the pattern attribute. We can have the client refuse to submit the form unless it matches a regex! The HTML 5 spec says that if a title attribute is provided, it should be a message that explains what the valid values are and browsers should provide it to the user if the regex doesn't match, so it's not a usability problem. I didn't bother adding that anywhere at this point because it would require adding new messages, but it should be easy to do. Note of course that HTMLForm should be updated to verify that pattern matches on the server side as well -- this way we have a clean, unified way of ensuring that our client and server checks are the same.
2009-08-07 03:32:20 +00:00
if ( !empty( $this->mParams['disabled'] ) ) {
$attribs['disabled'] = 'disabled';
}
2009-06-21 18:26:29 +00:00
# TODO: Enforce pattern, step, required, readonly on the server side as
# well
foreach ( array( 'min', 'max', 'pattern', 'title', 'step',
'placeholder' ) as $param ) {
if ( isset( $this->mParams[$param] ) ) {
$attribs[$param] = $this->mParams[$param];
Start using some HTML 5 form features autofocus attribute added in some places; this looks like it's respected by both recent Opera and recent WebKit. Its function is self-explanatory. :) I used this in a few obvious places like Special:UserLogin and Special:ResetPass to focus the first field in the form. Could be used in other places too: Special:Search, etc. required attribute added in some places. This is only supported in recent Opera at the moment. Also self-explanatory: it won't allow form submission if the field is empty. For stuff using HTMLForm (i.e., Special:Preferences), validation will be done for integers and floats. Browsers that support this (recent Opera) will not allow non-integers to be submitted for integer fields, will not allow non-floating-point values to be submitted for float fields, and will enforce any min/max values specified. Opera also gives little up and down arrows to allow the user to increment/decrement the value in addition to letting them edit the field as text. For HTMLForm and account creation, the email input type is used for e-mails. This enforces a sane set of values for e-mails (alphanumerics plus some ASCII punctuation, with an @ in it). Again, this is supported only by recent Opera (yay Opera!). Note that this is actually more restrictive than what we currently check for on the server side; it might be sane to tighten up our server-side checks to forbid e-mail addresses that HTML 5 forbids. In all cases, the extra features aren't added if $wgHtml5 is false, and will be ignored by non-supporting browsers. The major room for further improvement here is use of the pattern attribute. We can have the client refuse to submit the form unless it matches a regex! The HTML 5 spec says that if a title attribute is provided, it should be a message that explains what the valid values are and browsers should provide it to the user if the regex doesn't match, so it's not a usability problem. I didn't bother adding that anywhere at this point because it would require adding new messages, but it should be easy to do. Note of course that HTMLForm should be updated to verify that pattern matches on the server side as well -- this way we have a clean, unified way of ensuring that our client and server checks are the same.
2009-08-07 03:32:20 +00:00
}
}
foreach ( array( 'required', 'autofocus', 'multiple', 'readonly' ) as $param ) {
if ( isset( $this->mParams[$param] ) ) {
$attribs[$param] = '';
Start using some HTML 5 form features autofocus attribute added in some places; this looks like it's respected by both recent Opera and recent WebKit. Its function is self-explanatory. :) I used this in a few obvious places like Special:UserLogin and Special:ResetPass to focus the first field in the form. Could be used in other places too: Special:Search, etc. required attribute added in some places. This is only supported in recent Opera at the moment. Also self-explanatory: it won't allow form submission if the field is empty. For stuff using HTMLForm (i.e., Special:Preferences), validation will be done for integers and floats. Browsers that support this (recent Opera) will not allow non-integers to be submitted for integer fields, will not allow non-floating-point values to be submitted for float fields, and will enforce any min/max values specified. Opera also gives little up and down arrows to allow the user to increment/decrement the value in addition to letting them edit the field as text. For HTMLForm and account creation, the email input type is used for e-mails. This enforces a sane set of values for e-mails (alphanumerics plus some ASCII punctuation, with an @ in it). Again, this is supported only by recent Opera (yay Opera!). Note that this is actually more restrictive than what we currently check for on the server side; it might be sane to tighten up our server-side checks to forbid e-mail addresses that HTML 5 forbids. In all cases, the extra features aren't added if $wgHtml5 is false, and will be ignored by non-supporting browsers. The major room for further improvement here is use of the pattern attribute. We can have the client refuse to submit the form unless it matches a regex! The HTML 5 spec says that if a title attribute is provided, it should be a message that explains what the valid values are and browsers should provide it to the user if the regex doesn't match, so it's not a usability problem. I didn't bother adding that anywhere at this point because it would require adding new messages, but it should be easy to do. Note of course that HTMLForm should be updated to verify that pattern matches on the server side as well -- this way we have a clean, unified way of ensuring that our client and server checks are the same.
2009-08-07 03:32:20 +00:00
}
}
# Implement tiny differences between some field variants
# here, rather than creating a new class for each one which
# is essentially just a clone of this one.
if ( isset( $this->mParams['type'] ) ) {
switch ( $this->mParams['type'] ) {
case 'email':
$attribs['type'] = 'email';
break;
case 'int':
$attribs['type'] = 'number';
break;
case 'float':
$attribs['type'] = 'number';
$attribs['step'] = 'any';
break;
# Pass through
case 'password':
case 'file':
$attribs['type'] = $this->mParams['type'];
break;
}
Start using some HTML 5 form features autofocus attribute added in some places; this looks like it's respected by both recent Opera and recent WebKit. Its function is self-explanatory. :) I used this in a few obvious places like Special:UserLogin and Special:ResetPass to focus the first field in the form. Could be used in other places too: Special:Search, etc. required attribute added in some places. This is only supported in recent Opera at the moment. Also self-explanatory: it won't allow form submission if the field is empty. For stuff using HTMLForm (i.e., Special:Preferences), validation will be done for integers and floats. Browsers that support this (recent Opera) will not allow non-integers to be submitted for integer fields, will not allow non-floating-point values to be submitted for float fields, and will enforce any min/max values specified. Opera also gives little up and down arrows to allow the user to increment/decrement the value in addition to letting them edit the field as text. For HTMLForm and account creation, the email input type is used for e-mails. This enforces a sane set of values for e-mails (alphanumerics plus some ASCII punctuation, with an @ in it). Again, this is supported only by recent Opera (yay Opera!). Note that this is actually more restrictive than what we currently check for on the server side; it might be sane to tighten up our server-side checks to forbid e-mail addresses that HTML 5 forbids. In all cases, the extra features aren't added if $wgHtml5 is false, and will be ignored by non-supporting browsers. The major room for further improvement here is use of the pattern attribute. We can have the client refuse to submit the form unless it matches a regex! The HTML 5 spec says that if a title attribute is provided, it should be a message that explains what the valid values are and browsers should provide it to the user if the regex doesn't match, so it's not a usability problem. I didn't bother adding that anywhere at this point because it would require adding new messages, but it should be easy to do. Note of course that HTMLForm should be updated to verify that pattern matches on the server side as well -- this way we have a clean, unified way of ensuring that our client and server checks are the same.
2009-08-07 03:32:20 +00:00
}
2009-09-06 15:07:29 +00:00
return Html::element( 'input', $attribs );
}
}
class HTMLTextAreaField extends HTMLFormField {
function getCols() {
return isset( $this->mParams['cols'] )
? $this->mParams['cols']
: 80;
}
function getRows() {
return isset( $this->mParams['rows'] )
? $this->mParams['rows']
: 25;
}
function getInputHTML( $value ) {
$attribs = array(
'id' => $this->mID,
'name' => $this->mName,
'cols' => $this->getCols(),
'rows' => $this->getRows(),
) + $this->getTooltipAndAccessKey();
if ( !empty( $this->mParams['disabled'] ) ) {
$attribs['disabled'] = 'disabled';
}
if ( !empty( $this->mParams['readonly'] ) ) {
$attribs['readonly'] = 'readonly';
}
foreach ( array( 'required', 'autofocus' ) as $param ) {
if ( isset( $this->mParams[$param] ) ) {
$attribs[$param] = '';
}
}
return Html::element( 'textarea', $attribs, $value );
}
}
/**
* A field that will contain a numeric value
*/
class HTMLFloatField extends HTMLTextField {
function getSize() {
return isset( $this->mParams['size'] )
? $this->mParams['size']
: 20;
}
2009-06-21 18:26:29 +00:00
function validate( $value, $alldata ) {
2009-06-21 18:26:29 +00:00
$p = parent::validate( $value, $alldata );
if ( $p !== true ) {
return $p;
}
$value = trim( $value );
2009-06-21 18:26:29 +00:00
# http://dev.w3.org/html5/spec/common-microsyntaxes.html#real-numbers
# with the addition that a leading '+' sign is ok.
2010-12-15 13:33:47 +00:00
if ( !preg_match( '/^((\+|\-)?\d+(\.\d+)?(E(\+|\-)?\d+)?)?$/i', $value ) ) {
return wfMsgExt( 'htmlform-float-invalid', 'parse' );
}
2009-06-21 18:26:29 +00:00
# The "int" part of these message names is rather confusing.
# They make equal sense for all numbers.
2009-06-21 18:26:29 +00:00
if ( isset( $this->mParams['min'] ) ) {
$min = $this->mParams['min'];
if ( $min > $value ) {
2009-06-21 18:26:29 +00:00
return wfMsgExt( 'htmlform-int-toolow', 'parse', array( $min ) );
}
}
2009-06-21 18:26:29 +00:00
if ( isset( $this->mParams['max'] ) ) {
$max = $this->mParams['max'];
if ( $max < $value ) {
2009-06-21 18:26:29 +00:00
return wfMsgExt( 'htmlform-int-toohigh', 'parse', array( $max ) );
}
}
2009-06-21 18:26:29 +00:00
return true;
}
}
/**
* A field that must contain a number
*/
class HTMLIntField extends HTMLFloatField {
function validate( $value, $alldata ) {
$p = parent::validate( $value, $alldata );
if ( $p !== true ) {
return $p;
}
# http://dev.w3.org/html5/spec/common-microsyntaxes.html#signed-integers
# with the addition that a leading '+' sign is ok. Note that leading zeros
# are fine, and will be left in the input, which is useful for things like
# phone numbers when you know that they are integers (the HTML5 type=tel
# input does not require its value to be numeric). If you want a tidier
# value to, eg, save in the DB, clean it up with intval().
2010-12-15 13:33:47 +00:00
if ( !preg_match( '/^((\+|\-)?\d+)?$/', trim( $value ) )
) {
return wfMsgExt( 'htmlform-int-invalid', 'parse' );
}
return true;
}
}
/**
* A checkbox field
*/
class HTMLCheckField extends HTMLFormField {
function getInputHTML( $value ) {
if ( !empty( $this->mParams['invert'] ) ) {
$value = !$value;
}
2009-06-21 18:26:29 +00:00
$attr = $this->getTooltipAndAccessKey();
$attr['id'] = $this->mID;
if ( !empty( $this->mParams['disabled'] ) ) {
$attr['disabled'] = 'disabled';
}
2009-06-21 18:26:29 +00:00
Remove most named character references from output Recommit of r66254 to trunk. This was just find extensions phase3 -iname '*.php' \! -iname '*.i18n.php' \! -iname 'Messages*.php' \! -iname '*_Messages.php' -exec sed -i 's/&nbsp;/\&#160;/g;s/&mdash;/―/g;s/&bull;/•/g;s/&aacute;/á/g;s/&acute;/´/g;s/&agrave;/à/g;s/&alpha;/α/g;s/&auml;/ä/g;s/&ccedil;/ç/g;s/&copy;/©/g;s/&darr;/↓/g;s/&deg;/°/g;s/&eacute;/é/g;s/&ecirc;/ê/g;s/&euml;/ë/g;s/&egrave;/è/g;s/&euro;/€/g;s/&harr;//g;s/&hellip;/…/g;s/&iacute;/í/g;s/&igrave;/ì/g;s/&larr;/←/g;s/&ldquo;/“/g;s/&middot;/·/g;s/&minus;/−/g;s/&ndash;/–/g;s/&oacute;/ó/g;s/&ocirc;/ô/g;s/&oelig;/œ/g;s/&ograve;/ò/g;s/&otilde;/õ/g;s/&ouml;/ö/g;s/&pound;/£/g;s/&prime;/′/g;s/&Prime;/″/g;s/&raquo;/»/g;s/&rarr;/→/g;s/&rdquo;/”/g;s/&Sigma;/Σ/g;s/&times;/×/g;s/&uacute;/ú/g;s/&uarr;/↑/g;s/&uuml;/ü/g;s/&yen;/¥/g' {} + followed by reading over every single line of the resulting diff and fixing a whole bunch of false positives. The reason for this change is given in <http://lists.wikimedia.org/pipermail/wikitech-l/2010-April/047617.html>. I cleared it with Tim and Brion on IRC before committing. It might cause a few problems, but I tried to be careful; please report any issues. I skipped all messages files. I plan to make a follow-up commit that alters wfMsgExt() with 'escapenoentities' to sanitize all the entities. That way, the only messages that will be problems will be ones that output raw HTML, and we want to get rid of those anyway. This should get rid of all named entities everywhere except messages. I skipped a few things like &nbsp that I noticed in manual inspection, because they weren't well-formed XML anyway. Also, to everyone who uses non-breaking spaces when they could use a normal space, or nothing at all, or CSS padding: I still hate you. Die.
2010-05-30 17:33:59 +00:00
return Xml::check( $this->mName, $value, $attr ) . '&#160;' .
Html::rawElement( 'label', array( 'for' => $this->mID ), $this->mLabel );
}
2009-06-21 18:26:29 +00:00
/**
* For a checkbox, the label goes on the right hand side, and is
* added in getInputHTML(), rather than HTMLFormField::getRow()
*/
2009-06-21 18:26:29 +00:00
function getLabel() {
Remove most named character references from output Recommit of r66254 to trunk. This was just find extensions phase3 -iname '*.php' \! -iname '*.i18n.php' \! -iname 'Messages*.php' \! -iname '*_Messages.php' -exec sed -i 's/&nbsp;/\&#160;/g;s/&mdash;/―/g;s/&bull;/•/g;s/&aacute;/á/g;s/&acute;/´/g;s/&agrave;/à/g;s/&alpha;/α/g;s/&auml;/ä/g;s/&ccedil;/ç/g;s/&copy;/©/g;s/&darr;/↓/g;s/&deg;/°/g;s/&eacute;/é/g;s/&ecirc;/ê/g;s/&euml;/ë/g;s/&egrave;/è/g;s/&euro;/€/g;s/&harr;//g;s/&hellip;/…/g;s/&iacute;/í/g;s/&igrave;/ì/g;s/&larr;/←/g;s/&ldquo;/“/g;s/&middot;/·/g;s/&minus;/−/g;s/&ndash;/–/g;s/&oacute;/ó/g;s/&ocirc;/ô/g;s/&oelig;/œ/g;s/&ograve;/ò/g;s/&otilde;/õ/g;s/&ouml;/ö/g;s/&pound;/£/g;s/&prime;/′/g;s/&Prime;/″/g;s/&raquo;/»/g;s/&rarr;/→/g;s/&rdquo;/”/g;s/&Sigma;/Σ/g;s/&times;/×/g;s/&uacute;/ú/g;s/&uarr;/↑/g;s/&uuml;/ü/g;s/&yen;/¥/g' {} + followed by reading over every single line of the resulting diff and fixing a whole bunch of false positives. The reason for this change is given in <http://lists.wikimedia.org/pipermail/wikitech-l/2010-April/047617.html>. I cleared it with Tim and Brion on IRC before committing. It might cause a few problems, but I tried to be careful; please report any issues. I skipped all messages files. I plan to make a follow-up commit that alters wfMsgExt() with 'escapenoentities' to sanitize all the entities. That way, the only messages that will be problems will be ones that output raw HTML, and we want to get rid of those anyway. This should get rid of all named entities everywhere except messages. I skipped a few things like &nbsp that I noticed in manual inspection, because they weren't well-formed XML anyway. Also, to everyone who uses non-breaking spaces when they could use a normal space, or nothing at all, or CSS padding: I still hate you. Die.
2010-05-30 17:33:59 +00:00
return '&#160;';
}
2009-06-21 18:26:29 +00:00
function loadDataFromRequest( $request ) {
$invert = false;
if ( isset( $this->mParams['invert'] ) && $this->mParams['invert'] ) {
$invert = true;
}
2009-06-21 18:26:29 +00:00
// GetCheck won't work like we want for checks.
if ( $request->getCheck( 'wpEditToken' ) ) {
// XOR has the following truth table, which is what we want
// INVERT VALUE | OUTPUT
// true true | false
// false true | true
// false false | false
// true false | true
return $request->getBool( $this->mName ) xor $invert;
} else {
return $this->getDefault();
}
}
}
/**
* A select dropdown field. Basically a wrapper for Xmlselect class
*/
class HTMLSelectField extends HTMLFormField {
function validate( $value, $alldata ) {
$p = parent::validate( $value, $alldata );
if ( $p !== true ) {
return $p;
}
2009-06-21 18:26:29 +00:00
$validOptions = HTMLFormField::flattenOptions( $this->mParams['options'] );
if ( in_array( $value, $validOptions ) )
return true;
else
return wfMsgExt( 'htmlform-select-badoption', 'parseinline' );
}
2009-06-21 18:26:29 +00:00
function getInputHTML( $value ) {
$select = new XmlSelect( $this->mName, $this->mID, strval( $value ) );
# If one of the options' 'name' is int(0), it is automatically selected.
# because PHP sucks and things int(0) == 'some string'.
# Working around this by forcing all of them to strings.
$options = array_map( 'strval', $this->mParams['options'] );
2009-06-21 18:26:29 +00:00
if ( !empty( $this->mParams['disabled'] ) ) {
$select->setAttribute( 'disabled', 'disabled' );
}
2009-06-21 18:26:29 +00:00
$select->addOptions( $options );
2009-06-21 18:26:29 +00:00
return $select->getHTML();
}
}
/**
* Select dropdown field, with an additional "other" textbox.
*/
class HTMLSelectOrOtherField extends HTMLTextField {
static $jsAdded = false;
2009-06-21 18:26:29 +00:00
function __construct( $params ) {
if ( !in_array( 'other', $params['options'], true ) ) {
$params['options'][wfMsg( 'htmlform-selectorother-other' )] = 'other';
}
2009-06-21 18:26:29 +00:00
parent::__construct( $params );
}
static function forceToStringRecursive( $array ) {
if ( is_array( $array ) ) {
return array_map( array( __CLASS__, 'forceToStringRecursive' ), $array );
} else {
return strval( $array );
}
}
2009-06-21 18:26:29 +00:00
function getInputHTML( $value ) {
$valInSelect = false;
2009-06-21 18:26:29 +00:00
if ( $value !== false ) {
$valInSelect = in_array(
$value,
HTMLFormField::flattenOptions( $this->mParams['options'] )
);
}
2009-06-21 18:26:29 +00:00
$selected = $valInSelect ? $value : 'other';
$opts = self::forceToStringRecursive( $this->mParams['options'] );
2009-06-21 18:26:29 +00:00
$select = new XmlSelect( $this->mName, $this->mID, $selected );
$select->addOptions( $opts );
2009-06-21 18:26:29 +00:00
$select->setAttribute( 'class', 'mw-htmlform-select-or-other' );
2009-06-21 18:26:29 +00:00
$tbAttribs = array( 'id' => $this->mID . '-other', 'size' => $this->getSize() );
if ( !empty( $this->mParams['disabled'] ) ) {
$select->setAttribute( 'disabled', 'disabled' );
$tbAttribs['disabled'] = 'disabled';
}
2009-06-21 18:26:29 +00:00
$select = $select->getHTML();
2009-06-21 18:26:29 +00:00
if ( isset( $this->mParams['maxlength'] ) ) {
$tbAttribs['maxlength'] = $this->mParams['maxlength'];
}
2009-06-21 18:26:29 +00:00
$textbox = Html::input(
$this->mName . '-other',
$valInSelect ? '' : $value,
'text',
$tbAttribs
);
2009-06-21 18:26:29 +00:00
return "$select<br />\n$textbox";
}
2009-06-21 18:26:29 +00:00
function loadDataFromRequest( $request ) {
if ( $request->getCheck( $this->mName ) ) {
$val = $request->getText( $this->mName );
2009-06-21 18:26:29 +00:00
if ( $val == 'other' ) {
2009-06-21 18:26:29 +00:00
$val = $request->getText( $this->mName . '-other' );
}
2009-06-21 18:26:29 +00:00
return $val;
} else {
return $this->getDefault();
}
}
}
/**
* Multi-select field
*/
class HTMLMultiSelectField extends HTMLFormField {
function validate( $value, $alldata ) {
$p = parent::validate( $value, $alldata );
2009-06-21 18:26:29 +00:00
if ( $p !== true ) {
return $p;
}
if ( !is_array( $value ) ) {
return false;
}
2009-06-21 18:26:29 +00:00
# If all options are valid, array_intersect of the valid options
# and the provided options will return the provided options.
$validOptions = HTMLFormField::flattenOptions( $this->mParams['options'] );
2009-06-21 18:26:29 +00:00
$validValues = array_intersect( $value, $validOptions );
if ( count( $validValues ) == count( $value ) ) {
return true;
} else {
return wfMsgExt( 'htmlform-select-badoption', 'parseinline' );
}
}
2009-06-21 18:26:29 +00:00
function getInputHTML( $value ) {
$html = $this->formatOptions( $this->mParams['options'], $value );
2009-06-21 18:26:29 +00:00
return $html;
}
2009-06-21 18:26:29 +00:00
function formatOptions( $options, $value ) {
$html = '';
2009-06-21 18:26:29 +00:00
$attribs = array();
if ( !empty( $this->mParams['disabled'] ) ) {
$attribs['disabled'] = 'disabled';
}
2009-06-21 18:26:29 +00:00
foreach ( $options as $label => $info ) {
if ( is_array( $info ) ) {
2009-09-07 01:47:45 +00:00
$html .= Html::rawElement( 'h1', array(), $label ) . "\n";
$html .= $this->formatOptions( $info, $value );
} else {
$thisAttribs = array( 'id' => "{$this->mID}-$info", 'value' => $info );
$checkbox = Xml::check(
$this->mName . '[]',
in_array( $info, $value, true ),
$attribs + $thisAttribs );
$checkbox .= '&#160;' . Html::rawElement( 'label', array( 'for' => "{$this->mID}-$info" ), $label );
2009-06-21 18:26:29 +00:00
$html .= $checkbox . '<br />';
}
}
2009-06-21 18:26:29 +00:00
return $html;
}
2009-06-21 18:26:29 +00:00
function loadDataFromRequest( $request ) {
# won't work with getCheck
if ( $request->getCheck( 'wpEditToken' ) ) {
$arr = $request->getArray( $this->mName );
2009-06-21 18:26:29 +00:00
if ( !$arr ) {
$arr = array();
}
2009-06-21 18:26:29 +00:00
return $arr;
} else {
return $this->getDefault();
}
}
2009-06-21 18:26:29 +00:00
function getDefault() {
if ( isset( $this->mDefault ) ) {
return $this->mDefault;
} else {
return array();
}
}
protected function needsLabel() {
return false;
}
}
/**
* Radio checkbox fields.
*/
class HTMLRadioField extends HTMLFormField {
function validate( $value, $alldata ) {
$p = parent::validate( $value, $alldata );
2009-06-21 18:26:29 +00:00
if ( $p !== true ) {
return $p;
}
if ( !is_string( $value ) && !is_int( $value ) ) {
return false;
}
2009-06-21 18:26:29 +00:00
$validOptions = HTMLFormField::flattenOptions( $this->mParams['options'] );
2009-06-21 18:26:29 +00:00
if ( in_array( $value, $validOptions ) ) {
return true;
} else {
return wfMsgExt( 'htmlform-select-badoption', 'parseinline' );
}
}
2009-06-21 18:26:29 +00:00
/**
* This returns a block of all the radio options, in one cell.
* @see includes/HTMLFormField#getInputHTML()
*/
function getInputHTML( $value ) {
$html = $this->formatOptions( $this->mParams['options'], $value );
2009-06-21 18:26:29 +00:00
return $html;
}
function formatOptions( $options, $value ) {
$html = '';
2009-06-21 18:26:29 +00:00
$attribs = array();
if ( !empty( $this->mParams['disabled'] ) ) {
$attribs['disabled'] = 'disabled';
}
2009-06-21 18:26:29 +00:00
# TODO: should this produce an unordered list perhaps?
foreach ( $options as $label => $info ) {
if ( is_array( $info ) ) {
2009-09-07 01:47:45 +00:00
$html .= Html::rawElement( 'h1', array(), $label ) . "\n";
$html .= $this->formatOptions( $info, $value );
} else {
$id = Sanitizer::escapeId( $this->mID . "-$info" );
$html .= Xml::radio(
$this->mName,
$info,
$info == $value,
$attribs + array( 'id' => $id )
);
Remove most named character references from output Recommit of r66254 to trunk. This was just find extensions phase3 -iname '*.php' \! -iname '*.i18n.php' \! -iname 'Messages*.php' \! -iname '*_Messages.php' -exec sed -i 's/&nbsp;/\&#160;/g;s/&mdash;/―/g;s/&bull;/•/g;s/&aacute;/á/g;s/&acute;/´/g;s/&agrave;/à/g;s/&alpha;/α/g;s/&auml;/ä/g;s/&ccedil;/ç/g;s/&copy;/©/g;s/&darr;/↓/g;s/&deg;/°/g;s/&eacute;/é/g;s/&ecirc;/ê/g;s/&euml;/ë/g;s/&egrave;/è/g;s/&euro;/€/g;s/&harr;//g;s/&hellip;/…/g;s/&iacute;/í/g;s/&igrave;/ì/g;s/&larr;/←/g;s/&ldquo;/“/g;s/&middot;/·/g;s/&minus;/−/g;s/&ndash;/–/g;s/&oacute;/ó/g;s/&ocirc;/ô/g;s/&oelig;/œ/g;s/&ograve;/ò/g;s/&otilde;/õ/g;s/&ouml;/ö/g;s/&pound;/£/g;s/&prime;/′/g;s/&Prime;/″/g;s/&raquo;/»/g;s/&rarr;/→/g;s/&rdquo;/”/g;s/&Sigma;/Σ/g;s/&times;/×/g;s/&uacute;/ú/g;s/&uarr;/↑/g;s/&uuml;/ü/g;s/&yen;/¥/g' {} + followed by reading over every single line of the resulting diff and fixing a whole bunch of false positives. The reason for this change is given in <http://lists.wikimedia.org/pipermail/wikitech-l/2010-April/047617.html>. I cleared it with Tim and Brion on IRC before committing. It might cause a few problems, but I tried to be careful; please report any issues. I skipped all messages files. I plan to make a follow-up commit that alters wfMsgExt() with 'escapenoentities' to sanitize all the entities. That way, the only messages that will be problems will be ones that output raw HTML, and we want to get rid of those anyway. This should get rid of all named entities everywhere except messages. I skipped a few things like &nbsp that I noticed in manual inspection, because they weren't well-formed XML anyway. Also, to everyone who uses non-breaking spaces when they could use a normal space, or nothing at all, or CSS padding: I still hate you. Die.
2010-05-30 17:33:59 +00:00
$html .= '&#160;' .
2009-09-07 01:47:45 +00:00
Html::rawElement( 'label', array( 'for' => $id ), $label );
2009-06-21 18:26:29 +00:00
$html .= "<br />\n";
}
}
2009-06-21 18:26:29 +00:00
return $html;
}
protected function needsLabel() {
return false;
}
}
/**
* An information field (text blob), not a proper input.
*/
class HTMLInfoField extends HTMLFormField {
function __construct( $info ) {
$info['nodata'] = true;
2009-06-21 18:26:29 +00:00
parent::__construct( $info );
}
2009-06-21 18:26:29 +00:00
function getInputHTML( $value ) {
2009-06-21 18:26:29 +00:00
return !empty( $this->mParams['raw'] ) ? $value : htmlspecialchars( $value );
}
2009-06-21 18:26:29 +00:00
function getTableRow( $value ) {
2009-06-21 18:26:29 +00:00
if ( !empty( $this->mParams['rawrow'] ) ) {
return $value;
}
2009-06-21 18:26:29 +00:00
return parent::getTableRow( $value );
}
protected function needsLabel() {
return false;
}
}
class HTMLHiddenField extends HTMLFormField {
public function __construct( $params ) {
parent::__construct( $params );
# forcing the 'wp' prefix on hidden field names
# is undesirable
$this->mName = substr( $this->mName, 2 );
# Per HTML5 spec, hidden fields cannot be 'required'
# http://dev.w3.org/html5/spec/states-of-the-type-attribute.html#hidden-state
unset( $this->mParams['required'] );
}
public function getTableRow( $value ) {
$params = array();
if ( $this->mID ) {
$params['id'] = $this->mID;
}
$this->mParent->addHiddenField(
$this->mName,
$this->mDefault,
$params
);
return '';
}
public function getInputHTML( $value ) { return ''; }
}
/**
* Add a submit button inline in the form (as opposed to
* HTMLForm::addButton(), which will add it at the end).
*/
class HTMLSubmitField extends HTMLFormField {
function __construct( $info ) {
$info['nodata'] = true;
parent::__construct( $info );
}
function getInputHTML( $value ) {
return Xml::submitButton(
$value,
array(
'class' => 'mw-htmlform-submit',
'name' => $this->mName,
'id' => $this->mID,
)
);
}
protected function needsLabel() {
return false;
}
/**
* Button cannot be invalid
*/
public function validate( $value, $alldata ){
return true;
}
}
class HTMLEditTools extends HTMLFormField {
public function getInputHTML( $value ) {
return '';
}
public function getTableRow( $value ) {
return "<tr><td></td><td class=\"mw-input\">"
. '<div class="mw-editTools">'
. wfMsgExt( empty( $this->mParams['message'] )
? 'edittools' : $this->mParams['message'],
array( 'parse', 'content' ) )
. "</div></td></tr>\n";
}
2009-11-16 16:21:11 +00:00
}