Exception
2 years ago
File
2 years ago
Session
2 years ago
Tests
2 years ago
AcceptHeader.php
2 years ago
AcceptHeaderItem.php
2 years ago
ApacheRequest.php
2 years ago
BinaryFileResponse.php
2 years ago
Cookie.php
2 years ago
ExpressionRequestMatcher.php
2 years ago
FileBag.php
2 years ago
HeaderBag.php
2 years ago
IpUtils.php
2 years ago
JsonResponse.php
2 years ago
LICENSE
2 years ago
ParameterBag.php
2 years ago
RedirectResponse.php
2 years ago
Request.php
2 years ago
RequestMatcher.php
2 years ago
RequestMatcherInterface.php
2 years ago
RequestStack.php
2 years ago
Response.php
2 years ago
ResponseHeaderBag.php
2 years ago
ServerBag.php
2 years ago
StreamedResponse.php
2 years ago
JsonResponse.php
239 lines
| 1 | <?php |
| 2 | |
| 3 | /* |
| 4 | * This file is part of the Symfony package. |
| 5 | * |
| 6 | * (c) Fabien Potencier <fabien@symfony.com> |
| 7 | * |
| 8 | * For the full copyright and license information, please view the LICENSE |
| 9 | * file that was distributed with this source code. |
| 10 | * |
| 11 | * Modified by impress-org on 23-January-2024 using Strauss. |
| 12 | * @see https://github.com/BrianHenryIE/strauss |
| 13 | */ |
| 14 | |
| 15 | namespace Give\Vendors\Symfony\Component\HttpFoundation; |
| 16 | |
| 17 | /** |
| 18 | * Response represents an HTTP response in JSON format. |
| 19 | * |
| 20 | * Note that this class does not force the returned JSON content to be an |
| 21 | * object. It is however recommended that you do return an object as it |
| 22 | * protects yourself against XSSI and JSON-JavaScript Hijacking. |
| 23 | * |
| 24 | * @see https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/AJAX_Security_Cheat_Sheet.md#always-return-json-with-an-object-on-the-outside |
| 25 | * |
| 26 | * @author Igor Wiedler <igor@wiedler.ch> |
| 27 | */ |
| 28 | class JsonResponse extends Response |
| 29 | { |
| 30 | protected $data; |
| 31 | protected $callback; |
| 32 | |
| 33 | // Encode <, >, ', &, and " characters in the JSON, making it also safe to be embedded into HTML. |
| 34 | // 15 === JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_AMP | JSON_HEX_QUOT |
| 35 | const DEFAULT_ENCODING_OPTIONS = 15; |
| 36 | |
| 37 | protected $encodingOptions = self::DEFAULT_ENCODING_OPTIONS; |
| 38 | |
| 39 | /** |
| 40 | * @param mixed $data The response data |
| 41 | * @param int $status The response status code |
| 42 | * @param array $headers An array of response headers |
| 43 | * @param bool $json If the data is already a JSON string |
| 44 | */ |
| 45 | public function __construct($data = null, $status = 200, $headers = [], $json = false) |
| 46 | { |
| 47 | parent::__construct('', $status, $headers); |
| 48 | |
| 49 | if (null === $data) { |
| 50 | $data = new \ArrayObject(); |
| 51 | } |
| 52 | |
| 53 | $json ? $this->setJson($data) : $this->setData($data); |
| 54 | } |
| 55 | |
| 56 | /** |
| 57 | * Factory method for chainability. |
| 58 | * |
| 59 | * Example: |
| 60 | * |
| 61 | * return JsonResponse::create(['key' => 'value']) |
| 62 | * ->setSharedMaxAge(300); |
| 63 | * |
| 64 | * @param mixed $data The JSON response data |
| 65 | * @param int $status The response status code |
| 66 | * @param array $headers An array of response headers |
| 67 | * |
| 68 | * @return static |
| 69 | */ |
| 70 | public static function create($data = null, $status = 200, $headers = []) |
| 71 | { |
| 72 | return new static($data, $status, $headers); |
| 73 | } |
| 74 | |
| 75 | /** |
| 76 | * Factory method for chainability. |
| 77 | * |
| 78 | * Example: |
| 79 | * |
| 80 | * return JsonResponse::fromJsonString('{"key": "value"}') |
| 81 | * ->setSharedMaxAge(300); |
| 82 | * |
| 83 | * @param string|null $data The JSON response string |
| 84 | * @param int $status The response status code |
| 85 | * @param array $headers An array of response headers |
| 86 | * |
| 87 | * @return static |
| 88 | */ |
| 89 | public static function fromJsonString($data = null, $status = 200, $headers = []) |
| 90 | { |
| 91 | return new static($data, $status, $headers, true); |
| 92 | } |
| 93 | |
| 94 | /** |
| 95 | * Sets the JSONP callback. |
| 96 | * |
| 97 | * @param string|null $callback The JSONP callback or null to use none |
| 98 | * |
| 99 | * @return $this |
| 100 | * |
| 101 | * @throws \InvalidArgumentException When the callback name is not valid |
| 102 | */ |
| 103 | public function setCallback($callback = null) |
| 104 | { |
| 105 | if (null !== $callback) { |
| 106 | // partially taken from https://geekality.net/2011/08/03/valid-javascript-identifier/ |
| 107 | // partially taken from https://github.com/willdurand/JsonpCallbackValidator |
| 108 | // JsonpCallbackValidator is released under the MIT License. See https://github.com/willdurand/JsonpCallbackValidator/blob/v1.1.0/LICENSE for details. |
| 109 | // (c) William Durand <william.durand1@gmail.com> |
| 110 | $pattern = '/^[$_\p{L}][$_\p{L}\p{Mn}\p{Mc}\p{Nd}\p{Pc}\x{200C}\x{200D}]*(?:\[(?:"(?:\\\.|[^"\\\])*"|\'(?:\\\.|[^\'\\\])*\'|\d+)\])*?$/u'; |
| 111 | $reserved = [ |
| 112 | 'break', 'do', 'instanceof', 'typeof', 'case', 'else', 'new', 'var', 'catch', 'finally', 'return', 'void', 'continue', 'for', 'switch', 'while', |
| 113 | 'debugger', 'function', 'this', 'with', 'default', 'if', 'throw', 'delete', 'in', 'try', 'class', 'enum', 'extends', 'super', 'const', 'export', |
| 114 | 'import', 'implements', 'let', 'private', 'public', 'yield', 'interface', 'package', 'protected', 'static', 'null', 'true', 'false', |
| 115 | ]; |
| 116 | $parts = explode('.', $callback); |
| 117 | foreach ($parts as $part) { |
| 118 | if (!preg_match($pattern, $part) || \in_array($part, $reserved, true)) { |
| 119 | throw new \InvalidArgumentException('The callback name is not valid.'); |
| 120 | } |
| 121 | } |
| 122 | } |
| 123 | |
| 124 | $this->callback = $callback; |
| 125 | |
| 126 | return $this->update(); |
| 127 | } |
| 128 | |
| 129 | /** |
| 130 | * Sets a raw string containing a JSON document to be sent. |
| 131 | * |
| 132 | * @param string $json |
| 133 | * |
| 134 | * @return $this |
| 135 | * |
| 136 | * @throws \InvalidArgumentException |
| 137 | */ |
| 138 | public function setJson($json) |
| 139 | { |
| 140 | $this->data = $json; |
| 141 | |
| 142 | return $this->update(); |
| 143 | } |
| 144 | |
| 145 | /** |
| 146 | * Sets the data to be sent as JSON. |
| 147 | * |
| 148 | * @param mixed $data |
| 149 | * |
| 150 | * @return $this |
| 151 | * |
| 152 | * @throws \InvalidArgumentException |
| 153 | */ |
| 154 | public function setData($data = []) |
| 155 | { |
| 156 | if (\defined('HHVM_VERSION')) { |
| 157 | // HHVM does not trigger any warnings and let exceptions |
| 158 | // thrown from a JsonSerializable object pass through. |
| 159 | // If only PHP did the same... |
| 160 | $data = json_encode($data, $this->encodingOptions); |
| 161 | } else { |
| 162 | if (!interface_exists('JsonSerializable', false)) { |
| 163 | set_error_handler(function () { return false; }); |
| 164 | try { |
| 165 | $data = @json_encode($data, $this->encodingOptions); |
| 166 | } finally { |
| 167 | restore_error_handler(); |
| 168 | } |
| 169 | } else { |
| 170 | try { |
| 171 | $data = json_encode($data, $this->encodingOptions); |
| 172 | } catch (\Exception $e) { |
| 173 | if ('Exception' === \get_class($e) && 0 === strpos($e->getMessage(), 'Failed calling ')) { |
| 174 | throw $e->getPrevious() ?: $e; |
| 175 | } |
| 176 | throw $e; |
| 177 | } |
| 178 | |
| 179 | if (\PHP_VERSION_ID >= 70300 && (\JSON_THROW_ON_ERROR & $this->encodingOptions)) { |
| 180 | return $this->setJson($data); |
| 181 | } |
| 182 | } |
| 183 | } |
| 184 | |
| 185 | if (\JSON_ERROR_NONE !== json_last_error()) { |
| 186 | throw new \InvalidArgumentException(json_last_error_msg()); |
| 187 | } |
| 188 | |
| 189 | return $this->setJson($data); |
| 190 | } |
| 191 | |
| 192 | /** |
| 193 | * Returns options used while encoding data to JSON. |
| 194 | * |
| 195 | * @return int |
| 196 | */ |
| 197 | public function getEncodingOptions() |
| 198 | { |
| 199 | return $this->encodingOptions; |
| 200 | } |
| 201 | |
| 202 | /** |
| 203 | * Sets options used while encoding data to JSON. |
| 204 | * |
| 205 | * @param int $encodingOptions |
| 206 | * |
| 207 | * @return $this |
| 208 | */ |
| 209 | public function setEncodingOptions($encodingOptions) |
| 210 | { |
| 211 | $this->encodingOptions = (int) $encodingOptions; |
| 212 | |
| 213 | return $this->setData(json_decode($this->data)); |
| 214 | } |
| 215 | |
| 216 | /** |
| 217 | * Updates the content and headers according to the JSON data and callback. |
| 218 | * |
| 219 | * @return $this |
| 220 | */ |
| 221 | protected function update() |
| 222 | { |
| 223 | if (null !== $this->callback) { |
| 224 | // Not using application/javascript for compatibility reasons with older browsers. |
| 225 | $this->headers->set('Content-Type', 'text/javascript'); |
| 226 | |
| 227 | return $this->setContent(sprintf('/**/%s(%s);', $this->callback, $this->data)); |
| 228 | } |
| 229 | |
| 230 | // Only set the header when there is none or when it equals 'text/javascript' (from a previous update with callback) |
| 231 | // in order to not overwrite a custom definition. |
| 232 | if (!$this->headers->has('Content-Type') || 'text/javascript' === $this->headers->get('Content-Type')) { |
| 233 | $this->headers->set('Content-Type', 'application/json'); |
| 234 | } |
| 235 | |
| 236 | return $this->setContent($this->data); |
| 237 | } |
| 238 | } |
| 239 |