PluginProbe
CSS & JavaScript Toolbox / 6.0.6
CSS & JavaScript Toolbox v6.0.6
trunk 0.3 0.8 10 10.1 11 11.2 11.3 11.4 11.5 11.6 11.7 11.8 11.9 11.9.1 12 12.0 12.0.1 12.0.3 12.0.4 12.0.5 12.0.6 12.0.7 6.0 6.0.11 All 60 releases
← All changes | framework/access-points/access-point.class.php +49 -108 trunk6.0.6 View file →
@@ -1,7 +1,7 @@
1 1 <?php
2 2 /**
3 -*
3 +*
4 4 */
5 5
6 6 // Disallow direct access.
7 7 defined('ABSPATH') or die("Access denied");
@@ -9,60 +9,60 @@
9 9 /**
10 10 * Access Point interface
11 11 */
12 12 interface CJTIAccessPoint {
13 -
13 +
14 14 /**
15 15 * put your comment there...
16 - *
16 + *
17 17 */
18 18 public function listen();
19 -
19 +
20 20 }
21 21
22 22 /**
23 -*
23 +*
24 24 */
25 25 abstract class CJTAccessPoint extends CJTHookableClass implements CJTIAccessPoint {
26 -
26 +
27 27 /**
28 28 * put your comment there...
29 - *
29 + *
30 30 * @var mixed
31 31 */
32 32 protected static $connected;
33 -
33 +
34 34 /**
35 35 * put your comment there...
36 - *
36 + *
37 37 * @var mixed
38 38 */
39 39 protected $controller;
40 -
40 +
41 41 /**
42 42 * put your comment there...
43 - *
43 + *
44 44 * @var mixed
45 45 */
46 46 protected $controllerName;
47 -
47 +
48 48 /**
49 49 * put your comment there...
50 - *
50 + *
51 51 * @var mixed
52 52 */
53 53 protected $name;
54 -
54 +
55 55 /**
56 56 * put your comment there...
57 - *
57 + *
58 58 * @var mixed
59 59 */
60 60 protected $onconnected = array('parameters' => array('state'));
61 -
61 +
62 62 /**
63 63 * put your comment there...
64 - *
64 + *
65 65 * @var mixed
66 66 */
67 67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68 68
@@ -67,93 +67,41 @@
67 67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68 68
69 69 /**
70 70 * put your comment there...
71 - *
71 + *
72 72 * @var mixed
73 73 */
74 74 protected $onlisten = array('hookType' =>CJTWordpressEvents::HOOK_ACTION);
75 -
75 +
76 76 /**
77 77 * put your comment there...
78 - *
78 + *
79 79 * @var mixed
80 80 */
81 81 protected $onsetcontroller = array('parameters' => array('controller'));
82 -
82 +
83 83 /**
84 84 * put your comment there...
85 - *
85 + *
86 86 * @var mixed
87 87 */
88 - protected $overrideControllersPath = null;
89 -
90 - /**
91 - * put your comment there...
92 - *
93 - * @var mixed
94 - */
95 - protected $overrideControllersPrefix = null;
96 -
97 - /**
98 - * put your comment there...
99 - *
100 - * @var mixed
101 - */
102 88 protected $pageId = CJTPlugin::PLUGIN_REQUEST_ID;
103 -
89 +
104 90 /**
105 91 * put your comment there...
106 - *
92 + *
107 93 */
108 94 public function __construct($defaultController = 'blocks') {
109 95 // Initialize Hookable.
110 96 parent::__construct();
111 - // Overrides controllers path using current Access Point model class path
112 - $accessPointClassLoader =& CJT_Framework_Autoload_Loader::findClassLoader(get_class($this));
113 - if ($accessPointClassLoader) {
114 - $this->overrideControllersPath = $accessPointClassLoader->getPath() . DIRECTORY_SEPARATOR . 'controllers';
115 - $this->overrideControllersPrefix = $accessPointClassLoader->getPrefix();
116 - }
117 - // Initialize with validation!
118 - $requestedController = isset($_REQUEST['controller']) ? esc_html($_REQUEST['controller']) : $defaultController;
119 - $this->controllerName = $this->ongetdefaultcontrollername($this->sanitizeControllerName($requestedController, $defaultController));
97 + // Initialize!
98 + $this->controllerName = $this->ongetdefaultcontrollername(isset($_REQUEST['controller']) ? $_REQUEST['controller'] : $defaultController);
120 99 }
121 -
100 +
122 101 /**
123 - * Sanitize controller name to prevent path traversal attacks
124 - *
125 - * @param string $controllerName The requested controller name
126 - * @param string $defaultController The default controller to use if validation fails
127 - * @return string Safe controller name
128 - */
129 - private function sanitizeControllerName($controllerName, $defaultController) {
130 - // Check for null or empty string
131 - if (empty($controllerName) || !is_string($controllerName)) {
132 - return $defaultController;
133 - }
134 -
135 - // Check for path traversal attempts
136 - if (strpos($controllerName, '..') !== false) {
137 - return $defaultController;
138 - }
139 -
140 - // Check for directory separators
141 - if (strpos($controllerName, '/') !== false || strpos($controllerName, '\\') !== false) {
142 - return $defaultController;
143 - }
144 -
145 - // Only allow alphanumeric characters, hyphens, and underscores
146 - if (!preg_match('/^[a-zA-Z0-9_-]+$/', $controllerName)) {
147 - return $defaultController;
148 - }
149 -
150 - return $controllerName;
151 - }
152 -
153 - /**
154 102 * put your comment there...
155 - *
103 + *
156 104 * @return Boolean TRUE if it wasn't connected! FALSE otherwise.
157 105 */
158 106 protected function connected() {
159 107 // Do connect only if not connected yet
@@ -164,58 +112,58 @@
164 112 self::$connected = $this;
165 113 }
166 114 return $returns;
167 115 }
168 -
116 +
169 117 /**
170 118 * put your comment there...
171 - *
119 + *
172 120 */
173 121 protected abstract function doListen();
174 -
122 +
175 123 /**
176 124 * put your comment there...
177 - *
125 + *
178 126 */
179 127 public function & getController() {
180 - return $this->controller;
128 + return $this->controller;
181 129 }
182 -
130 +
183 131 /**
184 132 * put your comment there...
185 - *
133 + *
186 134 */
187 135 public function getControllerName() {
188 - return $this->controllerName;
136 + return $this->controllerName;
189 137 }
190 -
138 +
191 139 /**
192 140 * put your comment there...
193 - *
141 + *
194 142 */
195 143 public function getName() {
196 144 return $this->name;
197 145 }
198 -
146 +
199 147 /**
200 148 * put your comment there...
201 - *
149 + *
202 150 */
203 151 public static function & isConnected() {
204 152 return self::$connected;
205 153 }
206 -
154 +
207 155 /**
208 156 * put your comment there...
209 - *
157 + *
210 158 */
211 159 public function hasAccess() {
212 160 return current_user_can('administrator');
213 161 }
214 -
162 +
215 163 /**
216 164 * put your comment there...
217 - *
165 + *
218 166 */
219 167 public function listen() {
220 168 // Fire listen event!
221 169 $this->onlisten();
@@ -222,12 +170,12 @@
222 170 // Allow access points to bind their hooks
223 171 $this->doListen();
224 172 return $this;
225 173 }
226 -
174 +
227 175 /**
228 176 * put your comment there...
229 - *
177 + *
230 178 * @param mixed $request
231 179 */
232 180 public function route($loadView = null, $request = null) {
233 181 // Only loading one controller is allowed.
@@ -234,20 +182,13 @@
234 182 if (!$this->controller) {
235 183 // Import view class.
236 184 require_once CJTOOLBOX_MVC_FRAMEWOK . '/view.inc.php';
237 185 // Instantiate controller!
238 - $this->controller = $this->onsetcontroller(
239 - CJTController::getInstance(
240 - $this->controllerName,
241 - $loadView,
242 - $request,
243 - $this->overrideControllersPath,
244 - $this->overrideControllersPrefix
245 - ));
186 + $this->controller = $this->onsetcontroller(CJTController::getInstance($this->controllerName, $loadView, $request));
246 187 }
247 188 return $this->controller;
248 189 }
249 -
190 +
250 191 } // End class.
251 192
252 193 // Hookable!
253 -CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));
194 +CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));