| @@ -7,8 +7,10 @@ | ||
| 7 | 7 | * @author Tobias Bäthge |
| 8 | 8 | * @since 2.0.0 |
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | +declare(strict_types=1); | |
| 12 | + | |
| 11 | 13 | // Prohibit direct script loading. |
| 12 | 14 | defined( 'ABSPATH' ) || die( 'No direct script access allowed!' ); |
| 13 | 15 | |
| 14 | 16 | /** |
| @@ -26,10 +28,10 @@ | ||
| 26 | 28 | * |
| 27 | 29 | * @since 2.0.0 |
| 28 | 30 | */ |
| 29 | 31 | public function __construct() { |
| 30 | - // Load PHPSpreadsheet via the Composer autoloading mechanism. | |
| 31 | - TablePress::load_file( 'autoload.php', 'libraries' ); | |
| 32 | + // Load PHPSpreadsheet via its autoloading mechanism. | |
| 33 | + TablePress::load_file( 'autoload.php', 'libraries/vendor' ); | |
| 32 | 34 | } |
| 33 | 35 | |
| 34 | 36 | /** |
| 35 | 37 | * Evaluates formulas in the passed table. |
| @@ -51,13 +53,13 @@ | ||
| 51 | 53 | } |
| 52 | 54 | |
| 53 | 55 | $table_has_formulas = true; |
| 54 | 56 | |
| 55 | - // Convert legacy "formulas in text" notation to standard Excel notation (`=Text {A3+B3} Text` => `="Text "&A3+B3&" Text"`). | |
| 56 | - $count = 0; | |
| 57 | - $cell_content = (string) preg_replace( '#{(.+?)}#', '"&$1&"', $cell_content, -1, $count ); | |
| 58 | - if ( $count > 0 ) { | |
| 59 | - $cell_content = '="' . substr( $cell_content, 1 ) . '"'; | |
| 57 | + // Convert legacy "formulas in text" notation (`=Text {A3+B3} Text`) to standard Excel notation (`="Text "&A3+B3&" Text"`). | |
| 58 | + if ( 1 === preg_match( '#{(.+?)}#', $cell_content ) ) { | |
| 59 | + $cell_content = str_replace( '"', '""', $cell_content ); // Preserve existing quotation marks in text around formulas. | |
| 60 | + $cell_content = '="' . substr( $cell_content, 1 ) . '"'; // Wrap the whole cell content in quotation marks, as there will be text around formulas. | |
| 61 | + $cell_content = (string) preg_replace( '#{(.+?)}#', '"&$1&"', $cell_content, -1, $count ); // Convert all wrapped formulas to standard Excel notation. | |
| 60 | 62 | } |
| 61 | 63 | } |
| 62 | 64 | } |
| 63 | 65 | unset( $row, $cell_content ); // Unset use-by-reference parameters of foreach loops. |
| @@ -72,9 +74,9 @@ | ||
| 72 | 74 | $worksheet = $spreadsheet->setActiveSheetIndex( 0 ); |
| 73 | 75 | $worksheet->fromArray( /* $source */ $table_data, /* $nullValue */ '' ); |
| 74 | 76 | |
| 75 | 77 | // Don't allow cyclic references. |
| 76 | - TablePress\PhpOffice\PhpSpreadsheet\Calculation\Calculation::getInstance( $spreadsheet )->cyclicFormulaCount = 0; | |
| 78 | + \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Calculation::getInstance( $spreadsheet )->cyclicFormulaCount = 0; | |
| 77 | 79 | |
| 78 | 80 | /* |
| 79 | 81 | * Register variables as Named Formulas. |
| 80 | 82 | * The variables `ROW`, `COLUMN`, `CELL`, `PI`, and `E` should be considered deprecated and only their formulas should be used. |
| @@ -110,9 +112,12 @@ | ||
| 110 | 112 | $url = esc_url( $url ); |
| 111 | 113 | $cell_content = "<a href=\"{$url}\">{$cell_content}</a>"; |
| 112 | 114 | } |
| 113 | 115 | } |
| 114 | - } catch ( \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Exception $exception ) { | |
| 116 | + | |
| 117 | + // Sanitize the output of the evaluated formula. | |
| 118 | + $cell_content = wp_kses_post( $cell_content ); // Equals wp_filter_post_kses(), but without the unnecessary slashes handling. | |
| 119 | + } catch ( \Throwable $exception ) { | |
| 115 | 120 | $message = str_replace( 'Worksheet!', '', $exception->getMessage() ); |
| 116 | 121 | $cell_content = "!ERROR! {$message}"; |
| 117 | 122 | } |
| 118 | 123 | } |
| @@ -123,9 +128,9 @@ | ||
| 123 | 128 | |
| 124 | 129 | // Save PHP memory. |
| 125 | 130 | $spreadsheet->disconnectWorksheets(); |
| 126 | 131 | unset( $cell_collection, $worksheet, $spreadsheet ); |
| 127 | - } catch ( \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Exception $exception ) { | |
| 132 | + } catch ( \Throwable $exception ) { | |
| 128 | 133 | $message = str_replace( 'Worksheet!', '', $exception->getMessage() ); |
| 129 | 134 | $table_data = array( array( "!ERROR! {$message}" ) ); |
| 130 | 135 | } |
| 131 | 136 | |