PluginProbe
CSS & JavaScript Toolbox / 8.0.3
CSS & JavaScript Toolbox v8.0.3
trunk 0.3 0.8 10 10.1 11 11.2 11.3 11.4 11.5 11.6 11.7 11.8 11.9 11.9.1 12 12.0 12.0.1 12.0.3 12.0.4 12.0.5 12.0.6 12.0.7 6.0 6.0.11 All 60 releases
← All changes | framework/access-points/access-point.class.php +55 -87 trunk8.0.3 View file →
@@ -1,7 +1,7 @@
1 1 <?php
2 2 /**
3 -*
3 +*
4 4 */
5 5
6 6 // Disallow direct access.
7 7 defined('ABSPATH') or die("Access denied");
@@ -9,60 +9,60 @@
9 9 /**
10 10 * Access Point interface
11 11 */
12 12 interface CJTIAccessPoint {
13 -
13 +
14 14 /**
15 15 * put your comment there...
16 - *
16 + *
17 17 */
18 18 public function listen();
19 -
19 +
20 20 }
21 21
22 22 /**
23 -*
23 +*
24 24 */
25 25 abstract class CJTAccessPoint extends CJTHookableClass implements CJTIAccessPoint {
26 -
26 +
27 27 /**
28 28 * put your comment there...
29 - *
29 + *
30 30 * @var mixed
31 31 */
32 32 protected static $connected;
33 -
33 +
34 34 /**
35 35 * put your comment there...
36 - *
36 + *
37 37 * @var mixed
38 38 */
39 39 protected $controller;
40 -
40 +
41 41 /**
42 42 * put your comment there...
43 - *
43 + *
44 44 * @var mixed
45 45 */
46 46 protected $controllerName;
47 -
47 +
48 48 /**
49 49 * put your comment there...
50 - *
50 + *
51 51 * @var mixed
52 52 */
53 53 protected $name;
54 -
54 +
55 55 /**
56 56 * put your comment there...
57 - *
57 + *
58 58 * @var mixed
59 59 */
60 60 protected $onconnected = array('parameters' => array('state'));
61 -
61 +
62 62 /**
63 63 * put your comment there...
64 - *
64 + *
65 65 * @var mixed
66 66 */
67 67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68 68
@@ -67,44 +67,44 @@
67 67 protected $ongetdefaultcontrollername = array('parameters' => array('controller'));
68 68
69 69 /**
70 70 * put your comment there...
71 - *
71 + *
72 72 * @var mixed
73 73 */
74 74 protected $onlisten = array('hookType' =>CJTWordpressEvents::HOOK_ACTION);
75 -
75 +
76 76 /**
77 77 * put your comment there...
78 - *
78 + *
79 79 * @var mixed
80 80 */
81 81 protected $onsetcontroller = array('parameters' => array('controller'));
82 -
82 +
83 83 /**
84 84 * put your comment there...
85 - *
85 + *
86 86 * @var mixed
87 87 */
88 88 protected $overrideControllersPath = null;
89 -
89 +
90 90 /**
91 91 * put your comment there...
92 - *
92 + *
93 93 * @var mixed
94 94 */
95 95 protected $overrideControllersPrefix = null;
96 -
96 +
97 97 /**
98 98 * put your comment there...
99 - *
99 + *
100 100 * @var mixed
101 101 */
102 102 protected $pageId = CJTPlugin::PLUGIN_REQUEST_ID;
103 -
103 +
104 104 /**
105 105 * put your comment there...
106 - *
106 + *
107 107 */
108 108 public function __construct($defaultController = 'blocks') {
109 109 // Initialize Hookable.
110 110 parent::__construct();
@@ -110,50 +110,18 @@
110 110 parent::__construct();
111 111 // Overrides controllers path using current Access Point model class path
112 112 $accessPointClassLoader =& CJT_Framework_Autoload_Loader::findClassLoader(get_class($this));
113 113 if ($accessPointClassLoader) {
114 - $this->overrideControllersPath = $accessPointClassLoader->getPath() . DIRECTORY_SEPARATOR . 'controllers';
114 + $this->overrideControllersPath = $accessPointClassLoader->getPath() . DIRECTORY_SEPARATOR . 'controllers';
115 115 $this->overrideControllersPrefix = $accessPointClassLoader->getPrefix();
116 116 }
117 - // Initialize with validation!
118 - $requestedController = isset($_REQUEST['controller']) ? esc_html($_REQUEST['controller']) : $defaultController;
119 - $this->controllerName = $this->ongetdefaultcontrollername($this->sanitizeControllerName($requestedController, $defaultController));
117 + // Initialize!
118 + $this->controllerName = $this->ongetdefaultcontrollername(isset($_REQUEST['controller']) ? $_REQUEST['controller'] : $defaultController);
120 119 }
121 -
120 +
122 121 /**
123 - * Sanitize controller name to prevent path traversal attacks
124 - *
125 - * @param string $controllerName The requested controller name
126 - * @param string $defaultController The default controller to use if validation fails
127 - * @return string Safe controller name
128 - */
129 - private function sanitizeControllerName($controllerName, $defaultController) {
130 - // Check for null or empty string
131 - if (empty($controllerName) || !is_string($controllerName)) {
132 - return $defaultController;
133 - }
134 -
135 - // Check for path traversal attempts
136 - if (strpos($controllerName, '..') !== false) {
137 - return $defaultController;
138 - }
139 -
140 - // Check for directory separators
141 - if (strpos($controllerName, '/') !== false || strpos($controllerName, '\\') !== false) {
142 - return $defaultController;
143 - }
144 -
145 - // Only allow alphanumeric characters, hyphens, and underscores
146 - if (!preg_match('/^[a-zA-Z0-9_-]+$/', $controllerName)) {
147 - return $defaultController;
148 - }
149 -
150 - return $controllerName;
151 - }
152 -
153 - /**
154 122 * put your comment there...
155 - *
123 + *
156 124 * @return Boolean TRUE if it wasn't connected! FALSE otherwise.
157 125 */
158 126 protected function connected() {
159 127 // Do connect only if not connected yet
@@ -164,58 +132,58 @@
164 132 self::$connected = $this;
165 133 }
166 134 return $returns;
167 135 }
168 -
136 +
169 137 /**
170 138 * put your comment there...
171 - *
139 + *
172 140 */
173 141 protected abstract function doListen();
174 -
142 +
175 143 /**
176 144 * put your comment there...
177 - *
145 + *
178 146 */
179 147 public function & getController() {
180 - return $this->controller;
148 + return $this->controller;
181 149 }
182 -
150 +
183 151 /**
184 152 * put your comment there...
185 - *
153 + *
186 154 */
187 155 public function getControllerName() {
188 - return $this->controllerName;
156 + return $this->controllerName;
189 157 }
190 -
158 +
191 159 /**
192 160 * put your comment there...
193 - *
161 + *
194 162 */
195 163 public function getName() {
196 164 return $this->name;
197 165 }
198 -
166 +
199 167 /**
200 168 * put your comment there...
201 - *
169 + *
202 170 */
203 171 public static function & isConnected() {
204 172 return self::$connected;
205 173 }
206 -
174 +
207 175 /**
208 176 * put your comment there...
209 - *
177 + *
210 178 */
211 179 public function hasAccess() {
212 180 return current_user_can('administrator');
213 181 }
214 -
182 +
215 183 /**
216 184 * put your comment there...
217 - *
185 + *
218 186 */
219 187 public function listen() {
220 188 // Fire listen event!
221 189 $this->onlisten();
@@ -222,12 +190,12 @@
222 190 // Allow access points to bind their hooks
223 191 $this->doListen();
224 192 return $this;
225 193 }
226 -
194 +
227 195 /**
228 196 * put your comment there...
229 - *
197 + *
230 198 * @param mixed $request
231 199 */
232 200 public function route($loadView = null, $request = null) {
233 201 // Only loading one controller is allowed.
@@ -236,10 +204,10 @@
236 204 require_once CJTOOLBOX_MVC_FRAMEWOK . '/view.inc.php';
237 205 // Instantiate controller!
238 206 $this->controller = $this->onsetcontroller(
239 207 CJTController::getInstance(
240 - $this->controllerName,
241 - $loadView,
208 + $this->controllerName,
209 + $loadView,
242 210 $request,
243 211 $this->overrideControllersPath,
244 212 $this->overrideControllersPrefix
245 213 ));
@@ -245,9 +213,9 @@
245 213 ));
246 214 }
247 215 return $this->controller;
248 216 }
249 -
217 +
250 218 } // End class.
251 219
252 220 // Hookable!
253 -CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));
221 +CJTAccessPoint::define('CJTAccessPoint', array('hookType' => CJTWordpressEvents::HOOK_FILTER));