PluginProbe
CSS & JavaScript Toolbox / 12.0.4
CSS & JavaScript Toolbox v12.0.4
trunk 0.3 0.8 10 10.1 11 11.2 11.3 11.4 11.5 11.6 11.7 11.8 11.9 11.9.1 12 12.0 12.0.1 12.0.3 12.0.4 12.0.5 12.0.6 12.0.7 6.0 6.0.11 All 60 releases
← All changes | framework/access-points/access-point.class.php +109 -50 6.012.0.4 View file →
@@ -1,7 +1,7 @@
1 1 <?php
2 2 /**
3 -*
3 +*
4 4 */
5 5
6 6 // Disallow direct access.
7 7 defined('ABSPATH') or die("Access denied");
@@ -9,60 +9,60 @@
9 9 /**
10 10 * Access Point interface
11 11 */
12 12 interface CJTIAccessPoint {
13 -
13 +
14 14 /**
15 15 * put your comment there...
16 - *
16 + *
17 17 */
18 18 public function listen();
19 -
19 +
20 20 }
21 21
22 22 /**
23 -*
23 +*
24 24 */
25 25 abstract class CJTAccessPoint extends CJTHookableClass implements CJTIAccessPoint {
26 -
26 +
27 27 /**
28 28 * put your comment there...
29 - *
29 + *
30 30 * @var mixed
31 31 */
32 32 protected static $connected;
33 -
33 +
34 34 /**
35 35 * put your comment there...
36 - *
36 + *
37 37 * @var mixed
38 38 */
39 39 protected $controller;
40 -
40 +
41 41 /**
42 42 * put your comment there...
43 - *
43 + *
44 44 * @var mixed
45 45 */
46 46 protected $controllerName;
47 -
47 +
48 48 /**
49 49 * put your comment there...
50 - *
50 + *
51 51 * @var mixed
52 52 */
53 53 protected $name;
54 -
54 +
55 55 /**
56 56 * put your comment there...
57 - *
57 + *
58 58 * @var mixed
59 59 */
60 60 protected $onconnected = array('parameters' => array('state'));
61 -
61 +
62 62 /**
63 63 * put your comment there...
64 - *
64 + *
65 65 * @var mixed
66 66 */
67 67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68 68
@@ -67,41 +67,93 @@
67 67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68 68
69 69 /**
70 70 * put your comment there...
71 - *
71 + *
72 72 * @var mixed
73 73 */
74 74 protected $onlisten = array('hookType' =>CJTWordpressEvents::HOOK_ACTION);
75 -
75 +
76 76 /**
77 77 * put your comment there...
78 - *
78 + *
79 79 * @var mixed
80 80 */
81 81 protected $onsetcontroller = array('parameters' => array('controller'));
82 -
82 +
83 83 /**
84 84 * put your comment there...
85 - *
85 + *
86 86 * @var mixed
87 87 */
88 + protected $overrideControllersPath = null;
89 +
90 + /**
91 + * put your comment there...
92 + *
93 + * @var mixed
94 + */
95 + protected $overrideControllersPrefix = null;
96 +
97 + /**
98 + * put your comment there...
99 + *
100 + * @var mixed
101 + */
88 102 protected $pageId = CJTPlugin::PLUGIN_REQUEST_ID;
89 -
103 +
90 104 /**
91 105 * put your comment there...
92 - *
106 + *
93 107 */
94 108 public function __construct($defaultController = 'blocks') {
95 109 // Initialize Hookable.
96 110 parent::__construct();
97 - // Initialize!
98 - $this->controllerName = $this->ongetdefaultcontrollername($_REQUEST['controller'] ? $_REQUEST['controller'] : $defaultController);
111 + // Overrides controllers path using current Access Point model class path
112 + $accessPointClassLoader =& CJT_Framework_Autoload_Loader::findClassLoader(get_class($this));
113 + if ($accessPointClassLoader) {
114 + $this->overrideControllersPath = $accessPointClassLoader->getPath() . DIRECTORY_SEPARATOR . 'controllers';
115 + $this->overrideControllersPrefix = $accessPointClassLoader->getPrefix();
116 + }
117 + // Initialize with validation!
118 + $requestedController = isset($_REQUEST['controller']) ? esc_html($_REQUEST['controller']) : $defaultController;
119 + $this->controllerName = $this->ongetdefaultcontrollername($this->sanitizeControllerName($requestedController, $defaultController));
99 120 }
100 -
121 +
101 122 /**
123 + * Sanitize controller name to prevent path traversal attacks
124 + *
125 + * @param string $controllerName The requested controller name
126 + * @param string $defaultController The default controller to use if validation fails
127 + * @return string Safe controller name
128 + */
129 + private function sanitizeControllerName($controllerName, $defaultController) {
130 + // Check for null or empty string
131 + if (empty($controllerName) || !is_string($controllerName)) {
132 + return $defaultController;
133 + }
134 +
135 + // Check for path traversal attempts
136 + if (strpos($controllerName, '..') !== false) {
137 + return $defaultController;
138 + }
139 +
140 + // Check for directory separators
141 + if (strpos($controllerName, '/') !== false || strpos($controllerName, '\\') !== false) {
142 + return $defaultController;
143 + }
144 +
145 + // Only allow alphanumeric characters, hyphens, and underscores
146 + if (!preg_match('/^[a-zA-Z0-9_-]+$/', $controllerName)) {
147 + return $defaultController;
148 + }
149 +
150 + return $controllerName;
151 + }
152 +
153 + /**
102 154 * put your comment there...
103 - *
155 + *
104 156 * @return Boolean TRUE if it wasn't connected! FALSE otherwise.
105 157 */
106 158 protected function connected() {
107 159 // Do connect only if not connected yet
@@ -112,58 +164,58 @@
112 164 self::$connected = $this;
113 165 }
114 166 return $returns;
115 167 }
116 -
168 +
117 169 /**
118 170 * put your comment there...
119 - *
171 + *
120 172 */
121 173 protected abstract function doListen();
122 -
174 +
123 175 /**
124 176 * put your comment there...
125 - *
177 + *
126 178 */
127 179 public function & getController() {
128 - return $this->controller;
180 + return $this->controller;
129 181 }
130 -
182 +
131 183 /**
132 184 * put your comment there...
133 - *
185 + *
134 186 */
135 187 public function getControllerName() {
136 - return $this->controllerName;
188 + return $this->controllerName;
137 189 }
138 -
190 +
139 191 /**
140 192 * put your comment there...
141 - *
193 + *
142 194 */
143 195 public function getName() {
144 196 return $this->name;
145 197 }
146 -
198 +
147 199 /**
148 200 * put your comment there...
149 - *
201 + *
150 202 */
151 203 public static function & isConnected() {
152 204 return self::$connected;
153 205 }
154 -
206 +
155 207 /**
156 208 * put your comment there...
157 - *
209 + *
158 210 */
159 211 public function hasAccess() {
160 212 return current_user_can('administrator');
161 213 }
162 -
214 +
163 215 /**
164 216 * put your comment there...
165 - *
217 + *
166 218 */
167 219 public function listen() {
168 220 // Fire listen event!
169 221 $this->onlisten();
@@ -170,25 +222,32 @@
170 222 // Allow access points to bind their hooks
171 223 $this->doListen();
172 224 return $this;
173 225 }
174 -
226 +
175 227 /**
176 228 * put your comment there...
177 - *
229 + *
178 230 * @param mixed $request
179 231 */
180 - public function route($request = null) {
232 + public function route($loadView = null, $request = null) {
181 233 // Only loading one controller is allowed.
182 234 if (!$this->controller) {
183 235 // Import view class.
184 236 require_once CJTOOLBOX_MVC_FRAMEWOK . '/view.inc.php';
185 237 // Instantiate controller!
186 - $this->controller = $this->onsetcontroller(CJTController::getInstance($this->controllerName, null, $request));
238 + $this->controller = $this->onsetcontroller(
239 + CJTController::getInstance(
240 + $this->controllerName,
241 + $loadView,
242 + $request,
243 + $this->overrideControllersPath,
244 + $this->overrideControllersPrefix
245 + ));
187 246 }
188 247 return $this->controller;
189 248 }
190 -
249 +
191 250 } // End class.
192 251
193 252 // Hookable!
194 -CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));
253 +CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));