| @@ -2,9 +2,19 @@ | ||
| 2 | 2 | namespace enshrined\svgSanitize; |
| 3 | 3 | |
| 4 | 4 | class Helper |
| 5 | 5 | { |
| 6 | + const XLINK_NAMESPACE_URI = 'http://www.w3.org/1999/xlink'; | |
| 7 | + | |
| 6 | 8 | /** |
| 9 | + * Resolves the `href`/`xlink:href` value of an element. | |
| 10 | + * | |
| 11 | + * The lookup is case insensitive on purpose: `Sanitizer::cleanHrefAttributes()` | |
| 12 | + * normalizes names such as `HrEf`/`xlink:HrEf` back to `href`/`xlink:href`, | |
| 13 | + * so anything consuming this helper has to see those attributes as well - | |
| 14 | + * otherwise a mixed-case name hides the reference from e.g. the `<use>` | |
| 15 | + * reference graph, which is built before that normalization happens. | |
| 16 | + * | |
| 7 | 17 | * @param \DOMElement $element |
| 8 | 18 | * @return string|null |
| 9 | 19 | */ |
| 10 | 20 | public static function getElementHref(\DOMElement $element) |
| @@ -11,10 +21,21 @@ | ||
| 11 | 21 | { |
| 12 | 22 | if ($element->hasAttribute('href')) { |
| 13 | 23 | return $element->getAttribute('href'); |
| 14 | 24 | } |
| 15 | - if ($element->hasAttributeNS('http://www.w3.org/1999/xlink', 'href')) { | |
| 16 | - return $element->getAttributeNS('http://www.w3.org/1999/xlink', 'href'); | |
| 25 | + if ($element->hasAttributeNS(self::XLINK_NAMESPACE_URI, 'href')) { | |
| 26 | + return $element->getAttributeNS(self::XLINK_NAMESPACE_URI, 'href'); | |
| 27 | + } | |
| 28 | + foreach ($element->attributes as $attribute) { | |
| 29 | + if (!$attribute instanceof \DOMAttr | |
| 30 | + || strtolower($attribute->localName) !== 'href' | |
| 31 | + ) { | |
| 32 | + continue; | |
| 33 | + } | |
| 34 | + $prefix = strtolower((string)$attribute->prefix); | |
| 35 | + if ($prefix === '' || $prefix === 'xlink') { | |
| 36 | + return $attribute->value; | |
| 37 | + } | |
| 17 | 38 | } |
| 18 | 39 | return null; |
| 19 | 40 | } |
| 20 | 41 | |