PluginProbe
CSS & JavaScript Toolbox / 12.0.3
CSS & JavaScript Toolbox v12.0.3
trunk 0.3 0.8 10 10.1 11 11.2 11.3 11.4 11.5 11.6 11.7 11.8 11.9 11.9.1 12 12.0 12.0.1 12.0.3 12.0.4 12.0.5 12.0.6 12.0.7 6.0 6.0.11 All 60 releases
css-javascript-toolbox / framework / access-points / access-point.class.php

access-point.class.php in CSS & JavaScript Toolbox 12.0.3, at framework/access-points/access-point.class.php

254 lines 5.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 *
4 */
5
6 // Disallow direct access.
7 defined('ABSPATH') or die("Access denied");
8
9 /**
10 * Access Point interface
11 */
12 interface CJTIAccessPoint {
13
14 /**
15 * put your comment there...
16 *
17 */
18 public function listen();
19
20 }
21
22 /**
23 *
24 */
25 abstract class CJTAccessPoint extends CJTHookableClass implements CJTIAccessPoint {
26
27 /**
28 * put your comment there...
29 *
30 * @var mixed
31 */
32 protected static $connected;
33
34 /**
35 * put your comment there...
36 *
37 * @var mixed
38 */
39 protected $controller;
40
41 /**
42 * put your comment there...
43 *
44 * @var mixed
45 */
46 protected $controllerName;
47
48 /**
49 * put your comment there...
50 *
51 * @var mixed
52 */
53 protected $name;
54
55 /**
56 * put your comment there...
57 *
58 * @var mixed
59 */
60 protected $onconnected = array('parameters' => array('state'));
61
62 /**
63 * put your comment there...
64 *
65 * @var mixed
66 */
67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68
69 /**
70 * put your comment there...
71 *
72 * @var mixed
73 */
74 protected $onlisten = array('hookType' =>CJTWordpressEvents::HOOK_ACTION);
75
76 /**
77 * put your comment there...
78 *
79 * @var mixed
80 */
81 protected $onsetcontroller = array('parameters' => array('controller'));
82
83 /**
84 * put your comment there...
85 *
86 * @var mixed
87 */
88 protected $overrideControllersPath = null;
89
90 /**
91 * put your comment there...
92 *
93 * @var mixed
94 */
95 protected $overrideControllersPrefix = null;
96
97 /**
98 * put your comment there...
99 *
100 * @var mixed
101 */
102 protected $pageId = CJTPlugin::PLUGIN_REQUEST_ID;
103
104 /**
105 * put your comment there...
106 *
107 */
108 public function __construct($defaultController = 'blocks') {
109 // Initialize Hookable.
110 parent::__construct();
111 // Overrides controllers path using current Access Point model class path
112 $accessPointClassLoader =& CJT_Framework_Autoload_Loader::findClassLoader(get_class($this));
113 if ($accessPointClassLoader) {
114 $this->overrideControllersPath = $accessPointClassLoader->getPath() . DIRECTORY_SEPARATOR . 'controllers';
115 $this->overrideControllersPrefix = $accessPointClassLoader->getPrefix();
116 }
117 // Initialize with validation!
118 $requestedController = isset($_REQUEST['controller']) ? esc_html($_REQUEST['controller']) : $defaultController;
119 $this->controllerName = $this->ongetdefaultcontrollername($this->sanitizeControllerName($requestedController, $defaultController));
120 }
121
122 /**
123 * Sanitize controller name to prevent path traversal attacks
124 *
125 * @param string $controllerName The requested controller name
126 * @param string $defaultController The default controller to use if validation fails
127 * @return string Safe controller name
128 */
129 private function sanitizeControllerName($controllerName, $defaultController) {
130 // Check for null or empty string
131 if (empty($controllerName) || !is_string($controllerName)) {
132 return $defaultController;
133 }
134
135 // Check for path traversal attempts
136 if (strpos($controllerName, '..') !== false) {
137 return $defaultController;
138 }
139
140 // Check for directory separators
141 if (strpos($controllerName, '/') !== false || strpos($controllerName, '\\') !== false) {
142 return $defaultController;
143 }
144
145 // Only allow alphanumeric characters, hyphens, and underscores
146 if (!preg_match('/^[a-zA-Z0-9_-]+$/', $controllerName)) {
147 return $defaultController;
148 }
149
150 return $controllerName;
151 }
152
153 /**
154 * put your comment there...
155 *
156 * @return Boolean TRUE if it wasn't connected! FALSE otherwise.
157 */
158 protected function connected() {
159 // Do connect only if not connected yet
160 if ($returns = !self::$connected) {
161 // Fire connected event!
162 $this->onconnected(true);
163 // Set current instance as the connected object!
164 self::$connected = $this;
165 }
166 return $returns;
167 }
168
169 /**
170 * put your comment there...
171 *
172 */
173 protected abstract function doListen();
174
175 /**
176 * put your comment there...
177 *
178 */
179 public function & getController() {
180 return $this->controller;
181 }
182
183 /**
184 * put your comment there...
185 *
186 */
187 public function getControllerName() {
188 return $this->controllerName;
189 }
190
191 /**
192 * put your comment there...
193 *
194 */
195 public function getName() {
196 return $this->name;
197 }
198
199 /**
200 * put your comment there...
201 *
202 */
203 public static function & isConnected() {
204 return self::$connected;
205 }
206
207 /**
208 * put your comment there...
209 *
210 */
211 public function hasAccess() {
212 return current_user_can('administrator');
213 }
214
215 /**
216 * put your comment there...
217 *
218 */
219 public function listen() {
220 // Fire listen event!
221 $this->onlisten();
222 // Allow access points to bind their hooks
223 $this->doListen();
224 return $this;
225 }
226
227 /**
228 * put your comment there...
229 *
230 * @param mixed $request
231 */
232 public function route($loadView = null, $request = null) {
233 // Only loading one controller is allowed.
234 if (!$this->controller) {
235 // Import view class.
236 require_once CJTOOLBOX_MVC_FRAMEWOK . '/view.inc.php';
237 // Instantiate controller!
238 $this->controller = $this->onsetcontroller(
239 CJTController::getInstance(
240 $this->controllerName,
241 $loadView,
242 $request,
243 $this->overrideControllersPath,
244 $this->overrideControllersPrefix
245 ));
246 }
247 return $this->controller;
248 }
249
250 } // End class.
251
252 // Hookable!
253 CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));
254