Commit graph

35 commits

Author SHA1 Message Date
Niklas Laxström
e1065a1d57 Little docs to help developers keep track of versions... 2010-02-24 16:06:55 +00:00
Aryeh Gregor
23bc48ea35 Fix comment, remove unused global 2010-02-21 01:44:25 +00:00
Chad Horohoe
02a59dce9f Use isset() instead of array_key_exists() 2010-01-27 19:14:18 +00:00
Aryeh Gregor
010c456825 Merge all skins' output of opening <body> tag
This fixes a few minor discrepancies, like Vector outputting dir=""
(redundant to the one on <html>), and non-Monobook-based skins omitting
the capitalize-all-nouns class (!).  This adds Html::openElement() and
refactors Html::rawElement() accordingly, so I checked that all parser
tests still pass.

I wasn't able to figure out if I broke some feature of right-floating
quickbars in the Standard skin, because I wasn't able to figure out what
the feature was in the first place.  Hopefully either it works, or
nobody cares, or someone else will figure out what it was supposed to
do.  (This is the stuff in getBodyOptions() in Standard.php I deleted;
I'm not sure the addition to sticky.js does what I want.)
2010-01-15 01:16:52 +00:00
Raimond Spekking
18ed54d077 Tweak 'HMTL 5' -> 'HTML5' per suggestion on translatewiki: http://translatewiki.net/wiki/Thread:Support/HTML5
See http://en.wikipedia.org/wiki/HTML5 too.
2009-12-30 07:08:52 +00:00
Aryeh Gregor
e71ffbd5ba maxlength=200 for page move summary in HTML5
Bug 16921.  maxlength is not allowed on textareas in HTML4, so this only
works in HTML5.  Note that Firefox 3.5 and Opera 9.22 ignore the
attribute (didn't test IE), so this isn't a complete fix.  Recent WebKit
does respect the attribute (tested in Chrome 4).

Of course, the length limit of 200 is a hack, just like for edit
summaries, and we really need to move to a non-varchar(255) backend for
all these fields.

Relevant to r45517, r45571.
2009-12-15 00:11:47 +00:00
Aryeh Gregor
5d768de96e Fix bugs in r59360, r59361, r59363
* spellcheck is not a boolean attribute; it is an enumerated attribute
  whose possible values are "true" and "false".  If it were boolean, the
  permitted constructs would be <input spellcheck>, <input
  spellcheck="spellcheck">, and <input spellcheck="">, which would all
  set it true, and it would only be set to false if omitted entirely.
  (It would be boolean if HTML5 had invented it, but can't be for
  historical reasons.)
* spellcheck is valid on any HTML element, not just input, and so should
  be stripped on any element.

For reference, a table of all HTML5 attributes can be found at:

<http://www.whatwg.org/specs/web-apps/current-work/multipage/section-index.html#attributes-0>
2009-12-11 19:01:16 +00:00
Daniel Friesen
fa3aa9653e EditPage refactor and improvements.
- EditPage::showEditForm broken up into task specific methods
- Subclasses can indicate they can't support section mode
- Standard inputs should all be now in methods they can be grabbed from by subclasses that want to re-arange things
- Many more places to override and hook into to change behavior
- showTextbox1 parameters changed from $classes to $customAttribs and $textoverride
- showContentForm and importContentFormData added; New workflow to override the wpTextbox1 behavior to use an alternate edit form ui or handle wpTextbox1 content in an alternate way.
- getActionURL added for EditPage subclasses used in places where $this->action isn't enough (ie: EditPage on special pages)
Html::textarea added
2009-12-02 07:22:29 +00:00
Sam Reed
258009f383 Further followup to r59360
Add spellcheck to html5attribs for blacklisting

Switch from xml to html input
2009-11-23 19:16:43 +00:00
Aryeh Gregor
0120d492b0 Escape '<' in attribute values for well-formed XML
This fixes r56407, which fixed bug 20655.  Now $wgWellFormedXml is used,
not $wgHtml5.  The previous code was outputting malformed XML if
$wgHtml5 and $wgWellFormedXml were both true.

I wish we had unit tests for this.  :(
2009-10-01 01:30:58 +00:00
Aryeh Gregor
5db865d453 Improve $attribs documentation in Html
As suggested by Nikerabbit on code review for r56778, noted how boolean
attributes are handled in a function-level comment.  Also adjusted
comments to reduce duplication by referring to other functions'
comments.
2009-09-23 15:16:05 +00:00
Aryeh Gregor
a3cdf1ab2f Fix "Invalid argument for foreach()" in Html
Reported by Nikerabbit on IRC to happen on Preferences, although I
couldn't reproduce immediately.  The change should be helpful for this
kind of thing anyway.
2009-09-22 17:41:34 +00:00
Aryeh Gregor
5c1205314c Tighten up unquoted attribute output
Only affects wikis with $wgWellFormedXml = false.  In principle, the old
behavior might have permitted XSS in IE if that setting is false (which
is not the default), but I haven't checked.  See
<http://code.google.com/p/html5lib/issues/detail?id=92>.
2009-09-18 15:28:46 +00:00
Aaron Schulz
6c182ab889 typecast $attribs to an array to avoid on-site notices 2009-09-18 14:55:42 +00:00
Aryeh Gregor
4a02cca0a3 Don't drop default attrib values in non-HTML5
Some attributes that have defaults in HTML5 don't have defaults in
XHTML1, particularly type="" on scripts and styles (bug 20713).  There's
not much point in trying to maintain two separate sets of defaults,
so I've just kept the HTML5 ones and haven't tried to strip any defaults
in XHTML1 mode.
2009-09-18 14:19:34 +00:00
Aaron Schulz
539dbc2d31 Default $attribs to an array in expandAttributes() 2009-09-16 22:52:15 +00:00
Alex Z
e886186e41 (bug 20655) If $wgHtml5 is false, run attribute values through Sanitizer::encodeAttribute() 2009-09-16 05:29:44 +00:00
Aryeh Gregor
f03c53b8a7 Fix silly <table class=''> 2009-09-07 15:25:22 +00:00
Aryeh Gregor
a039be051b Refactor redundant attrib dropping into new method
This saves code in a few places on the caller's side, and will reduce
the size of output HTML more consistently.
2009-09-07 00:21:55 +00:00
Aryeh Gregor
1cdedb1d44 Fix YET ANOTHER PHP WEAK TYPING BUG
Literal "0" was getting quoted.  Because, of course, 0 is equal to the
empty string.
2009-09-06 15:08:10 +00:00
Aryeh Gregor
e476e97314 Move more <input> logic from input() to element() 2009-09-06 15:07:52 +00:00
Aryeh Gregor
49e2599368 Use type=search for Monobook sidebar
Didn't bother to do this for other skins at the moment.  This should
allow more native-looking styling on some platforms (e.g., Safari on
Mac).
2009-08-26 14:59:59 +00:00
Aryeh Gregor
5e72d3501e Emit CDATA more intelligently
This fixes some possible XML invalidity from r54767: CDATA stuff was
being added only if $wgHtml5 was false, instead of whenever
$wgWellFormedXml is true.  Also, it uses CDATA for script as well as
style, but in both cases only uses it if there's a & or < somewhere.
2009-08-23 21:06:54 +00:00
Aryeh Gregor
daa8ed1a6e Typo in comment 2009-08-21 22:30:51 +00:00
Aryeh Gregor
faedd9d09f Autofocus Special:Search box
Also generally clean up the code around there: add some line breaks, use
Html instead of Xml (using new Html::hidden()).
2009-08-21 21:57:26 +00:00
Aryeh Gregor
f61d9e089d Omit useless value="" in Html::input() 2009-08-21 21:34:52 +00:00
Aryeh Gregor
3d3aa7c369 Only require necessary fields in Special:ResetPass
This fixes r54567.  That made the password fields on Special:ResetPass
always required, but in fact the current password should never be
required (existing users always might have empty passwords), and the new
password is only required if $wgMinimalPasswordLength > 0.

This commit also permits passing array( 'required' ) to
Html::(rawE|e)lement() instead of array( 'required' => 'meaningless' ),
for boolean attribs only.  This syntax is used in SpecialResetpass.
2009-08-21 21:06:06 +00:00
Aryeh Gregor
f103c057d0 Move validation logic from input() to rawElement()
This way callers of rawElement() or element() will also get correct
behavior.
2009-08-21 20:50:35 +00:00
Aryeh Gregor
defb1eeaf0 Correct outdated comments 2009-08-21 20:39:16 +00:00
Aryeh Gregor
ef664913d1 Don't escape >" in tag contents, no point 2009-08-21 20:38:53 +00:00
Aryeh Gregor
643dad9da3 Remove somewhat braindead comments
On second thought, if you're outputting user-supplied JS without careful
validation, it doesn't really matter if it's HTML-escaped or not.  :D
CSS has expr() and such too.
2009-08-20 21:30:47 +00:00
Brion Vibber
9bcb7bc8b0 Cleanup from r54770 "Add Html::input() convenience function"
Split the giant arrays of attributes/values to one item per line, which makes them easier to look at, easier to grep, and easier to see what's happening when they're changed in diffs.
We're not printing; vertical space isn't at a premium. ;)
2009-08-19 01:39:05 +00:00
Aryeh Gregor
8494a6cdb8 Make element() escape input like in Xml
Added rawElement() to allow unescaped input (like Xml::tags() but
better-named :) ).  This makes sure the easier case is the safer one as
well, and trades a risk of XSS for a risk of double-escaping.  After
discussion in #mediawiki a few days ago.
2009-08-18 01:01:47 +00:00
Aryeh Gregor
e9e6223e71 Add Html::input() convenience function
Currently only used in SpecialResetpass.  Also added some whitespace to
the HTML output of SpecialResetpass, so that it's somewhat readable.
2009-08-11 01:00:44 +00:00
Aryeh Gregor
7aa4a8f90c For HTML 5, drop type="" attributes for CSS/JS
This time done in a nice, centralized fashion, reducing LOC for callers
even if HTML 5 is disabled.  The implementation is a new Html class,
similar to Xml but intended to be HTML-specific from the beginning
instead of half-heartedly attempting to provide generic XML services but
actually with lots of HTML-specific stuff tacked on.

As part of the new Html class, a global config option $wgWellFormedXml
is added.  It's set to true by default, but if set to false, the Html
class will drop some things that HTML 5 doesn't require, like
self-closing " />" syntax and attribute quotation marks (sometimes).
2009-08-11 00:09:24 +00:00