There is no security benefit from encoding &, it's perfectly safe in JavaScript (it likely dates from XML/XHTML requirements). Newly created redirects will use a literal & in these URLs, while continuing to support use of \u0026 for existing pages. Note that this is about use of & for query parameter seperators, the & in a page title will continue to be encoded as %26 in the 'title' value and is unaffected by this change. Bug: T107289 Co-Authored-By: Ammar Abdulhamid <ammarpad@yahoo.com> Change-Id: I1db4483db6bc52a96487fefd2c3693b4825ccbb2
99 lines
2.7 KiB
PHP
99 lines
2.7 KiB
PHP
<?php
|
|
/**
|
|
* Content for JavaScript pages.
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License along
|
|
* with this program; if not, write to the Free Software Foundation, Inc.,
|
|
* 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
* http://www.gnu.org/copyleft/gpl.html
|
|
*
|
|
* @since 1.21
|
|
*
|
|
* @file
|
|
* @ingroup Content
|
|
*
|
|
* @author Daniel Kinzler
|
|
*/
|
|
|
|
use MediaWiki\Title\Title;
|
|
|
|
/**
|
|
* Content for JavaScript pages.
|
|
*
|
|
* @newable
|
|
* @ingroup Content
|
|
*/
|
|
class JavaScriptContent extends TextContent {
|
|
|
|
/**
|
|
* @var Title|null|false
|
|
*/
|
|
private $redirectTarget = false;
|
|
|
|
/**
|
|
* @stable to call
|
|
* @param string $text JavaScript code.
|
|
* @param string $modelId the content model name
|
|
*/
|
|
public function __construct( $text, $modelId = CONTENT_MODEL_JAVASCRIPT ) {
|
|
parent::__construct( $text, $modelId );
|
|
}
|
|
|
|
/**
|
|
* If this page is a redirect, return the content
|
|
* if it should redirect to $target instead
|
|
*
|
|
* @param Title $target
|
|
* @return JavaScriptContent
|
|
*/
|
|
public function updateRedirect( Title $target ) {
|
|
if ( !$this->isRedirect() ) {
|
|
return $this;
|
|
}
|
|
|
|
// @phan-suppress-next-line PhanTypeMismatchReturnSuperType False positive
|
|
return $this->getContentHandler()->makeRedirectContent( $target );
|
|
}
|
|
|
|
/**
|
|
* @return Title|null
|
|
*/
|
|
public function getRedirectTarget() {
|
|
if ( $this->redirectTarget !== false ) {
|
|
return $this->redirectTarget;
|
|
}
|
|
$this->redirectTarget = null;
|
|
$text = $this->getText();
|
|
if ( strpos( $text, '/* #REDIRECT */' ) === 0 ) {
|
|
// Compatiblity with pages created by MW 1.41 and earlier:
|
|
// Older redirects use an over-escaped \u0026 instead of a literal ampersand (T107289)
|
|
$text = str_replace( '\u0026', '&', $text );
|
|
// Extract the title from the url
|
|
if ( preg_match( '/title=(.*?)&action=raw/', $text, $matches ) ) {
|
|
$title = Title::newFromText( urldecode( $matches[1] ) );
|
|
if ( $title ) {
|
|
// Have a title, check that the current content equals what
|
|
// the redirect content should be
|
|
$expected = $this->getContentHandler()->makeRedirectContent( $title );
|
|
'@phan-var JavaScriptContent $expected';
|
|
if ( $expected->getText() === $text ) {
|
|
$this->redirectTarget = $title;
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
return $this->redirectTarget;
|
|
}
|
|
|
|
}
|