PluginProbe
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin / 1.1.12
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin v1.1.12
1.1.12 1.1.11 1.1.10 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.1 1.0.0 0.9.8 0.9.7 0.9.6 0.9.4 0.9.5 0.9.3 0.9.2 0.9.1 0.9.0 0.8.9 All 36 releases
← All changes | includes/helpers.php +59 -0 1.0.1 → 1.1.12 View file →
@@ -220,8 +220,67 @@
220 220 return is_string( $filtered ) && '' !== trim( $filtered ) ? $filtered : $title;
221 221 }
222 222
223 223 /**
224 + * Decode a rendered title into the plain text the desktop paints with.
225 + *
226 + * `wptexturize()` encodes the characters titles are full of — `&` as
227 + * `&`, an apostrophe as `’` — and the shell writes titles
228 + * into text nodes, where the entity renders as itself. Same reasoning
229 + * as {@see openstation_site_title()}, one layer down. Stored names need
230 + * it too: a display name, term name or comment author is saved with
231 + * `&` as `&`, and so is a title kses filtered on save.
232 + *
233 + * Decode BEFORE the tag strip, never after: `<script>` decodes
234 + * into a real tag, and stripping second is what removes it.
235 + *
236 + * A `<` opens a tag only before an ASCII letter, `/`, `!` or `?`, the
237 + * HTML tokenizer's rule, whether or not a `>` closes it. Any other `<`
238 + * is text (`I <3 WordPress`), and `strip_tags()` on its own would drop
239 + * it with everything after it.
240 + *
241 + * @param string $rendered A title or name, rendered or as stored.
242 + * @return string Plain text, tag-free.
243 + */
244 +function openstation_plain_text_title( $rendered ) {
245 + $decoded = html_entity_decode(
246 + (string) $rendered,
247 + ENT_QUOTES,
248 + get_bloginfo( 'charset' )
249 + );
250 +
251 + // A `<` that opens no tag sits out the strip as `&lt;`. `&` is
252 + // escaped first and restored last, so an `&lt;` the decode left as
253 + // text (`&amp;lt;` in the source) does not come back as a `<` too.
254 + $tag_start = '[a-zA-Z\/!?]';
255 + $text = str_replace( '&', '&amp;', $decoded );
256 + $text = openstation_strip_all_tags( $text );
257 + $text = str_replace( '&lt;', '<', $text );
258 + $text = str_replace( '&amp;', '&', $text );
259 +
260 + // Removing a tag can leave a kept `<` against the text after it
261 + // (`<<b>script>`): a space stops the pair from reading as a tag.
262 + return trim( preg_replace( "/<(?={$tag_start})/", '< ', $text ) );
263 +}
264 +
265 +/**
266 + * Strip the tags from stored HTML, keeping a `<` that opens no tag.
267 + *
268 + * A `<` opens a tag only before an ASCII letter, `/`, `!` or `?`. Any
269 + * other one comes back as `&lt;`, the form kses saves it in, so the
270 + * result is still HTML text: `wp_trim_words()` and `wp_html_excerpt()`,
271 + * which strip tags themselves, pass it on to whatever decodes last.
272 + *
273 + * @param string $html Stored HTML.
274 + * @return string Tag-free text, entities still encoded.
275 + */
276 +function openstation_strip_all_tags( $html ) {
277 + return wp_strip_all_tags(
278 + preg_replace( '/<(?![a-zA-Z\/!?])/', '&lt;', (string) $html )
279 + );
280 +}
281 +
282 +/**
224 283 * Build a `WP_Error` for a openstation registration failure.
225 284 *
226 285 * Centralises the error-code vocabulary used by every
227 286 * `openstation_register_*()` function so plugin authors see a