common.inc 39.7 KB
Newer Older
Dries Buytaert's avatar
   
Dries Buytaert committed
1
<?php
Dries Buytaert's avatar
Dries Buytaert committed
2
/* $Id$ */
Dries Buytaert's avatar
   
Dries Buytaert committed
3

Dries Buytaert's avatar
   
Dries Buytaert committed
4
/**
5
6
7
8
9
10
 * @defgroup common Core functions
 */

/**
 * @name Page title
 * @ingroup common
Dries Buytaert's avatar
   
Dries Buytaert committed
11
12
13
14
 *
 * Functions to get and set the title of the current page.
 * @{
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
15
16
17
18
function drupal_set_title($title = NULL) {
  static $stored_title;

  if (isset($title)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
19
    $stored_title = ucfirst($title);
Dries Buytaert's avatar
   
Dries Buytaert committed
20
21
22
23
24
25
26
27
28
29
30
31
32
  }
  return $stored_title;
}

function drupal_get_title() {
  $title = drupal_set_title();

  if (!isset($title)) {
    $title = menu_get_active_title();
  }

  return $title;
}
33
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
34

Dries Buytaert's avatar
   
Dries Buytaert committed
35
/**
36
37
 * @name Page messages
 * @ingroup common
Dries Buytaert's avatar
   
Dries Buytaert committed
38
39
40
41
 *
 * Functions to get and set the message of the current page.
 * @{
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
42
function drupal_set_message($message = NULL, $type = "status") {
Dries Buytaert's avatar
   
Dries Buytaert committed
43
  static $stored_message = array();
Dries Buytaert's avatar
   
Dries Buytaert committed
44
45

  if (isset($message)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
46
    $stored_message[] = array($message, $type);
Dries Buytaert's avatar
   
Dries Buytaert committed
47
48
49
50
51
  }

  return $stored_message;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
52
function drupal_get_messages() {
Dries Buytaert's avatar
   
Dries Buytaert committed
53
54
  return drupal_set_message();
}
55
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
56

Dries Buytaert's avatar
   
Dries Buytaert committed
57
/**
58
59
 * @name Page breadcrumbs
 * @ingroup common
Dries Buytaert's avatar
   
Dries Buytaert committed
60
61
62
63
 *
 * Functions to get and set the breadcrumb trail of the current page.
 * @{
 */
64
65
66
67
68

/**
 * @param $breadcrumb Array of links, starting with "home" and proceeding up
 *   to but not including the current page.
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
function drupal_set_breadcrumb($breadcrumb = NULL) {
  static $stored_breadcrumb;

  if (isset($breadcrumb)) {
    $stored_breadcrumb = $breadcrumb;
  }
  return $stored_breadcrumb;
}

function drupal_get_breadcrumb() {
  $breadcrumb = drupal_set_breadcrumb();

  if (!isset($breadcrumb)) {
    $breadcrumb = menu_get_active_breadcrumb();
  }

  return $breadcrumb;
}
87
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
88

89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
/**
 * @name Page tabs
 * @ingroup common
 *
 * Functions to get and set the tabs of the current page.
 * @{
 */

/**
 * @param $tab Array of links to use for tabs
 */
function drupal_set_tab($tab = NULL) {
  static $stored_tab = array();

  if (!is_null($tab)) {
    $stored_tab[] =  $tab;
  }
  return $stored_tab;
}

function drupal_get_tab() {
  return drupal_set_tab();
}
/* @} */

Dries Buytaert's avatar
Dries Buytaert committed
114
115
116
117
118
119
120
121
122
/**
 * @name HTML head contents
 * @ingroup common
 *
 * Set and get output that should be in the \<head\> tag.
 * @{
 */

function drupal_set_html_head($data = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
123
  static $stored_head = '';
Dries Buytaert's avatar
Dries Buytaert committed
124
125
126
127
128
129
130
131
132
133

  if (!is_null($data)) {
    $stored_head .= "$data\n";
  }
  return $stored_head;
}

function drupal_get_html_head() {
  global $base_url;

Dries Buytaert's avatar
   
Dries Buytaert committed
134
  $output = "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\" />\n";
Dries Buytaert's avatar
Dries Buytaert committed
135
  $output .= "<base href=\"$base_url/\" />\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
136
  $output .= "<style type=\"text/css\" media=\"all\">\n";
Dries Buytaert's avatar
Dries Buytaert committed
137
138
139
140
141
142
143
  $output .= "@import url(misc/drupal.css);\n";
  $output .= "</style>\n";

  return $output . drupal_set_html_head();
}
/* @} */

Dries Buytaert's avatar
   
Dries Buytaert committed
144
/**
Dries Buytaert's avatar
   
Dries Buytaert committed
145
 * @name URL path alias
146
147
 * @ingroup common
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
148
 * Functions to handle path aliases.
Dries Buytaert's avatar
   
Dries Buytaert committed
149
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
150
function drupal_get_path_map($action = "") {
Dries Buytaert's avatar
Dries Buytaert committed
151
  static $map = NULL;
Dries Buytaert's avatar
   
Dries Buytaert committed
152

Dries Buytaert's avatar
   
Dries Buytaert committed
153
154
155
156
  if ($action == "rebuild") {
    $map = NULL;
  }

Dries Buytaert's avatar
Dries Buytaert committed
157
  if (is_null($map)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
158
    $map = array();  // make $map non-null in case no aliases are defined
Dries Buytaert's avatar
   
Dries Buytaert committed
159
    $result = db_query("SELECT * FROM {url_alias}");
Dries Buytaert's avatar
   
Dries Buytaert committed
160
    while ($data = db_fetch_object($result)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
161
      $map[$data->dst] = $data->src;
Dries Buytaert's avatar
   
Dries Buytaert committed
162
163
164
165
166
167
    }
  }

  return $map;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
168
169
170
function drupal_rebuild_path_map() {
  drupal_get_path_map("rebuild");
}
171
172

/**
Dries Buytaert's avatar
   
Dries Buytaert committed
173
 * Given an old url, return the alias.
174
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
function drupal_get_path_alias($path) {
  if (($map = drupal_get_path_map()) && ($newpath = array_search($path, $map))) {
    return $newpath;
  }
  elseif (function_exists("conf_url_rewrite")) {
    return conf_url_rewrite($path, 'outgoing');
  }
}

/**
 * Given an alias, return the default url.
 */
function drupal_get_normal_path($path) {
  if (($map = drupal_get_path_map()) && isset($map[$path])) {
    return $map[$path];
  }
  elseif (function_exists("conf_url_rewrite")) {
    return conf_url_rewrite($path, 'incoming');
  }
  else {
    return $path;
  }
}
/* @} */
199

Dries Buytaert's avatar
Dries Buytaert committed
200
201
202
203
204
205
206
207
/**
 * @name HTTP headers
 * @ingroup common
 *
 * Functions to get and set the HTTP headers of the current page.
 * @{
 */
function drupal_set_header($header = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
208
  static $stored_headers = '';
Dries Buytaert's avatar
Dries Buytaert committed
209
210
211
212
213
214
215
216
217
218
219
220
221

  if (!is_null($header)) {
    header($header);
    $stored_headers .= "$header\n";
  }
  return $stored_headers;
}

function drupal_get_headers() {
  return drupal_set_header();
}
/* @} */

Dries Buytaert's avatar
   
Dries Buytaert committed
222
223
224
225
226
227
228
229
/**
 * @name HTTP handling
 * @ingroup common
 *
 * Functions to properly handle HTTP responses.
 * @{
 */

230
231
232
233
234
235
/**
 * HTTP redirects. Makes sure the redirected url is formatted correctly and
 * includes the session ID.
 *
 * @note This function ends the request.
 *
Dries Buytaert's avatar
Dries Buytaert committed
236
237
238
 * @param $url A Drupal URL
 * @param $query Query string component
 * @param $fragment Fragment identifier
239
 */
Dries Buytaert's avatar
Dries Buytaert committed
240
function drupal_goto($url = NULL, $query = NULL, $fragment = NULL) {
241
242

  /*
Dries Buytaert's avatar
Dries Buytaert committed
243
  ** Translate &amp; to simply & in the absolute URL
244
  */
Dries Buytaert's avatar
   
Dries Buytaert committed
245

Dries Buytaert's avatar
Dries Buytaert committed
246
  $url = str_replace("&amp;", "&", url($url, $query, $fragment, TRUE));
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278

  /*
  ** It is advised to use "drupal_goto()" instead of PHP's "header()" as
  ** "drupal_goto()" will append the user's session ID to the URI when PHP
  ** is compiled with "--enable-trans-sid".
  */
  if (!ini_get("session.use_trans_sid") || !session_id() || strstr($url, session_id())) {
    header("Location: $url");
  }
  else {
    $sid = session_name() . "=" . session_id();

    if (strstr($url, "?") && !strstr($url, $sid)) {
      header("Location: $url&". $sid);
    }
    else {
      header("Location: $url?". $sid);
    }
  }

  /*
  ** The "Location" header sends a REDIRECT status code to the http
  ** daemon.  In some cases this can go wrong, so we make sure none
  ** of the code /below/ gets executed when we redirect.
  */

  exit();
}

/**
 * Generates a 404 error if the request can not be handled.
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
279
function drupal_not_found() {
Dries Buytaert's avatar
   
Dries Buytaert committed
280
281
  header('HTTP/1.0 404 Not Found');
  watchdog('httpd', '404 error: "'. check_query($_GET['q']) .'" not found');
Dries Buytaert's avatar
   
Dries Buytaert committed
282
283

  $path = drupal_get_normal_path(variable_get('site_404', ''));
Dries Buytaert's avatar
   
Dries Buytaert committed
284
  $status = MENU_FALLTHROUGH;
Dries Buytaert's avatar
   
Dries Buytaert committed
285
286
  if ($path) {
    menu_set_active_item($path);
Dries Buytaert's avatar
   
Dries Buytaert committed
287
    $status = menu_execute_active_handler();
Dries Buytaert's avatar
   
Dries Buytaert committed
288
289
  }

Dries Buytaert's avatar
   
Dries Buytaert committed
290
  if ($status != MENU_FOUND) {
Dries Buytaert's avatar
Dries Buytaert committed
291
    print theme('page', '', t('Page not found'));
Dries Buytaert's avatar
   
Dries Buytaert committed
292
293
  }
}
Dries Buytaert's avatar
   
Dries Buytaert committed
294

Dries Buytaert's avatar
   
Dries Buytaert committed
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
/**
 * Generates a 403 error if the request is not allowed.
 */
function drupal_access_denied() {
  header('HTTP/1.0 403 Forbidden');

  $path = drupal_get_normal_path(variable_get('site_403', ''));
  $status = MENU_FALLTHROUGH;
  if ($path) {
    menu_set_active_item($path);
    $status = menu_execute_active_handler();
  }

  if ($status != MENU_FOUND) {
    print theme('page', message_access(), t('Access denied'));
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
/**
 * Flexible and powerful HTTP client implementation. Allows to GET, POST, PUT
 * or any other HTTP requests. Handles redirects.
 *
 * @param $url A string containing a fully qualified URI.
 * @param $headers An array containing a HTTP header => value pair.
 * @param $method A string defining the HTTP request to use.
 * @param $data A string containing data to include in the request.
 * @param $retry An integer representing how many times to retry the request
 *   in case of a redirect.
 * @return An object containing the HTTP request headers, response code,
 *   headers, data, and redirect status.
 */
function drupal_http_request($url, $headers = array(), $method = 'GET', $data = NULL, $retry = 3) {
  // Parse the URL, and make sure we can handle the schema
  $uri = parse_url($url);
  switch ($uri['scheme']) {
    case 'http':
      $fp = @fsockopen($uri['host'], ($uri['port'] ? $uri['port'] : 80), $errno, $errstr, 15);
      break;
    case 'https':
      // Note: only works for PHP 4.3 compiled with openssl
      $fp = @fsockopen("ssl://$uri[host]", ($uri['port'] ? $uri['port'] : 443), $errno, $errstr, 20);
      break;
    default:
      $result->error = "invalid schema $uri[scheme]";
      return $result;
  }

  // Make sure the socket opened properly
  if (!$fp) {
    $result->error = trim("$errno $errstr");
    return $result;
  }

  // Construct the path to act on
  $path = $uri['path'] ? $uri['path'] : '/';
  if ($uri['query']) {
    $path .= "?$uri[query]";
  }

  // Create http request
  $defaults = array(
356
357
358
    'Host' => "Host: $uri[host]",
    'User-Agent' => 'User-Agent: Drupal (+http://www.drupal.org/)',
    'Content-Length' => 'Content-Length: '. strlen($data)
Dries Buytaert's avatar
   
Dries Buytaert committed
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
  );

  foreach ($headers as $header => $value) {
    $defaults[$header] = "$header: $value";
  }

  $request = "$method $path HTTP/1.0\r\n";
  $request .= implode("\r\n", $defaults);
  $request .= "\r\n\r\n";
  if ($data) {
    $request .= "$data\r\n";
  }
  $result->request = $request;

  fwrite($fp, $request);

  // Fetch response.
376
  $response = '';
377
  while (!feof($fp) && $data = fread($fp, 1024)) {
378
    $response .= $data;
Dries Buytaert's avatar
   
Dries Buytaert committed
379
380
381
382
  }
  fclose($fp);

  // Parse response.
383
  $response = preg_split("/\r\n|\n|\r/", $response);
Dries Buytaert's avatar
   
Dries Buytaert committed
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
  list($protocol, $code, $text) = explode(' ', trim(array_shift($response)), 3);
  $result->headers = array();
  $result->data = '';

  // Parse headers.
  while ($line = trim(array_shift($response))) {
    if ($line == '') {
      break;
    }
    list($header, $value) = explode(':', $line, 2);
    $result->headers[$header] = trim($value);
  }

  $result->data = implode('', $response);

  $responses = array(
    100 => 'Continue', 101 => 'Switching Protocols',
    200 => 'OK', 201 => 'Created', 202 => 'Accepted', 203 => 'Non-Authoritative Information', 204 => 'No Content', 205 => 'Reset Content', 206 => 'Partial Content',
    300 => 'Multiple Choices', 301 => 'Moved Permanently', 302 => 'Found', 303 => 'See Other', 304 => 'Not Modified', 305 => 'Use Proxy', 307 => 'Temporary Redirect',
    400 => 'Bad Request', 401 => 'Unauthorized', 402 => 'Payment Required', 403 => 'Forbidden', 404 => 'Not Found', 405 => 'Method Not Allowed', 406 => 'Not Acceptable', 407 => 'Proxy Authentication Required', 408 => 'Request Time-out', 409 => 'Conflict', 410 => 'Gone', 411 => 'Length Required', 412 => 'Precondition Failed', 413 => 'Request Entity Too Large', 414 => 'Request-URI Too Large', 415 => 'Unsupported Media Type', 416 => 'Requested range not satisfiable', 417 => 'Expectation Failed',
    500 => 'Internal Server Error', 501 => 'Not Implemented', 502 => 'Bad Gateway', 503 => 'Service Unavailable', 504 => 'Gateway Time-out', 505 => 'HTTP Version not supported'
  );
  // RFC 2616 states that all unknown HTTP codes must be treated the same as
  // the base code in their class:
  if (!isset($responses[$code])) {
    $code = floor($code / 100) * 100;
  }

  switch ($code) {
    case 200: // OK
    case 304: // Not modified
      break;
    case 301: // Moved permanently
    case 302: // Moved temporarily
    case 307: // Moved temporarily
      $location = $result->headers['Location'];

      if ($retry) {
        $result = drupal_http_request($result->headers['Location'], $headers, $method, $data, --$retry);
        $result->redirect_code = $result->code;
      }
      $result->redirect_url = $location;

      break;
    default:
      $result->error = $text;
  }

  $result->code = $code;
  return $result;
}
435
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
436

Dries Buytaert's avatar
   
Dries Buytaert committed
437
438
439
function error_handler($errno, $message, $filename, $line, $variables) {
  $types = array(1 => "error", 2 => "warning", 4 => "parse error", 8 => "notice", 16 => "core error", 32 => "core warning", 64 => "compile error", 128 => "compile warning", 256 => "user error", 512 => "user warning", 1024 => "user notice");
  $entry = $types[$errno] .": $message in $filename on line $line.";
Dries Buytaert's avatar
   
Dries Buytaert committed
440
441

  if ($errno & E_ALL ^ E_NOTICE) {
Dries Buytaert's avatar
   
Dries Buytaert committed
442
    watchdog("error", $types[$errno] .": $message in $filename on line $line.");
Dries Buytaert's avatar
Dries Buytaert committed
443
444
445
    if (error_reporting()) {
      print "<pre>$entry</pre>";
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
446
447
448
  }
}

Dries Buytaert's avatar
Dries Buytaert committed
449
450
function _fix_gpc_magic(&$item, $key) {
  if (is_array($item)) {
Kjartan Mannes's avatar
Kjartan Mannes committed
451
452
453
    array_walk($item, '_fix_gpc_magic');
  }
  else {
Kjartan Mannes's avatar
Kjartan Mannes committed
454
    $item = stripslashes($item);
Dries Buytaert's avatar
   
Dries Buytaert committed
455
456
457
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
458
459
function fix_gpc_magic() {
  static $fixed = false;
Kjartan Mannes's avatar
Kjartan Mannes committed
460
  if (!$fixed && ini_get("magic_quotes_gpc")) {
Dries Buytaert's avatar
Dries Buytaert committed
461
462
463
464
465
466
    array_walk($_GET, '_fix_gpc_magic');
    array_walk($_POST, '_fix_gpc_magic');
    array_walk($_COOKIE, '_fix_gpc_magic');
    array_walk($_REQUEST, '_fix_gpc_magic');
    $fixed = true;
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
467
468
}

469
470
471
472
473
474
475
/**
 * @name Conversion
 * @ingroup common
 *
 * Converts data structures to a different type.
 * @{
 */
Dries Buytaert's avatar
Dries Buytaert committed
476
477
478
function array2object($array) {
  if (is_array($array)) {
    foreach ($array as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
479
480
481
482
      $object->$key = $value;
    }
  }
  else {
Dries Buytaert's avatar
Dries Buytaert committed
483
    $object = $array;
Dries Buytaert's avatar
   
Dries Buytaert committed
484
485
486
487
488
  }

  return $object;
}

Dries Buytaert's avatar
Dries Buytaert committed
489
490
491
function object2array($object) {
  if (is_object($object)) {
    foreach ($object as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
492
493
494
495
      $array[$key] = $value;
    }
  }
  else {
Dries Buytaert's avatar
Dries Buytaert committed
496
    $array = $object;
Dries Buytaert's avatar
   
Dries Buytaert committed
497
498
499
500
  }

  return $array;
}
501
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
502

503
504
505
506
507
508
509
/**
 * @name Messages
 * @ingroup common
 *
 * Frequently used messages.
 * @{
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
510
function message_access() {
Dries Buytaert's avatar
   
Dries Buytaert committed
511
  return t("You are not authorized to access this page.");
Dries Buytaert's avatar
   
Dries Buytaert committed
512
513
514
515
516
517
}

function message_na() {
  return t("n/a");
}

518
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
519

Dries Buytaert's avatar
   
Dries Buytaert committed
520
521
function locale_init() {
  global $languages, $user;
Dries Buytaert's avatar
   
Dries Buytaert committed
522
523
524
525
526
527
  if ($user->uid && $languages[$user->language]) {
    return $user->language;
  }
  else {
    return key($languages);
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
528
529
}

530
531
532
533
534
/**
 * @ingroup common
 *
 * Translates strings to the current locale.
 *
535
536
537
538
 * When using t(), try to put entire sentences and strings in one t() call.
 * This makes it easier for translators. We are unafraid of HTML markup within
 * translation strings if necessary. The suggested syntax for a link embedded
 * within a translation string is for example:
539
540
541
542
543
 * @code
 *   $msg = t("You must login below or \<a href=\"%url\"\>create a new
 *             account\</a\> before viewing the next page.", array("%url"
 *             => url("user/register")));
 * @endcode
544
545
546
 * We suggest the same syntax for links to other sites. This makes it easy to
 * change link URLs if needed (which happens often) without requiring updates
 * to translations.
547
548
549
550
551
 *
 * @param $string A string containing the english string to translate.
 * @param $args Array of values to replace in the string.
 * @return Translated string.
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
552
function t($string, $args = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
553
  global $languages;
554

555
  $string = ($languages && module_exist("locale") ? locale($string) : $string);
556

Dries Buytaert's avatar
   
Dries Buytaert committed
557
558
  if (!$args) {
    return $string;
Kjartan Mannes's avatar
Kjartan Mannes committed
559
560
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
561
562
    return strtr($string, $args);
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
563
564
}

Dries Buytaert's avatar
   
Dries Buytaert committed
565
function drupal_specialchars($input, $quotes = ENT_NOQUOTES) {
Dries Buytaert's avatar
   
Dries Buytaert committed
566
567
568
569
570
571
572
573
574

  /*
  ** Note that we'd like to go 'htmlspecialchars($input, $quotes, "utf-8")'
  ** like the PHP manual tells us to, but we can't because there's a bug in
  ** PHP <4.3 that makes it mess up multibyte charsets if we specify the
  ** charset.  Change this later once we make PHP 4.3 a requirement.
  */

  return htmlspecialchars($input, $quotes);
Dries Buytaert's avatar
   
Dries Buytaert committed
575
576
}

577
578
579
580
581
/**
 * @name Validation
 * @ingroup common
 *
 * Functions to validate user input.
Dries Buytaert's avatar
   
Dries Buytaert committed
582
 * @{
583
584
 */

585
/**
Dries Buytaert's avatar
   
Dries Buytaert committed
586
587
 * Verify the syntax of the given e-mail address. Empty e-mail addresses are
 * allowed. See RFC 2822 for details.
588
 *
589
 * @param $mail A string containing an email address.
Dries Buytaert's avatar
   
Dries Buytaert committed
590
 * @return
591
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
592
function valid_email_address($mail) {
593
594
595
596
597
  $user = '[a-zA-Z0-9_\-\.\+\^!#\$%&*+\/\=\?\`\|\{\}~\']+';
  $domain = '(?:[a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\-]*[a-zA-Z0-9]\.?)+';
  $ipv4 = '[0-9]{1,3}(\.[0-9]{1,3}){3}';
  $ipv6 = '[0-9a-fA-F]{1,4}(\:[0-9a-fA-F]{1,4}){7}';

Dries Buytaert's avatar
Dries Buytaert committed
598
  return preg_match("/^$user@($domain|(\[($ipv4|$ipv6)\]))$/", $mail);
599
600
}

Dries Buytaert's avatar
   
Dries Buytaert committed
601
602
603
/**
 * Verify the syntax of the given URL.
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
604
605
606
607
608
609
 * @param $url
 *   an URL
 * @param $absolute
 *   is the URL to be verified absolute, ie. of the form \<scheme\>://\<hostname\>/...?
 * @return
 *   valid syntax: TRUE; FALSE otherwise
Dries Buytaert's avatar
   
Dries Buytaert committed
610
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
611
function valid_url($url, $absolute = FALSE) {
612
  if ($absolute) {
613
    return preg_match("/^(http|https|ftp):\/\/[a-z0-9\/:_\-_\.\?,~=#&]+$/i", $url);
614
615
  }
  else {
616
    return preg_match("/^[a-z0-9\/:_\-_\.,]+$/i", $url);
617
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
618
619
}

620
621
622
623
624
625
626
function valid_input_data($data) {
  if (is_array($data) || is_object($data)) {
    /*
    ** Form data can contain a number of nested arrays.
    */

    foreach ($data as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
627
      if (!valid_input_data($key) || !valid_input_data($value)) {
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
        return 0;
      }
    }
  }
  else {
    /*
    ** Detect evil input data.
    */

    // check strings:
    $match  = preg_match("/\Wjavascript\s*:/i", $data);
    $match += preg_match("/\Wexpression\s*\(/i", $data);
    $match += preg_match("/\Walert\s*\(/i", $data);

    // check attributes:
    $match += preg_match("/\W(dynsrc|datasrc|data|lowsrc|on[a-z]+)\s*=[^>]+?>/i", $data);

    // check tags:
    $match += preg_match("/<\s*(applet|script|object|style|embed|form|blink|meta|html|frame|iframe|layer|ilayer|head|frameset|xml)/i", $data);

    if ($match) {
      watchdog("warning", "terminated request because of suspicious input data: ". drupal_specialchars($data));
      return 0;
    }
  }

  return 1;
}
/* @} */

/**
 * @defgroup search Search interface
 * @{
 */
Kjartan Mannes's avatar
Kjartan Mannes committed
662
663
664
/**
 * Format a single result entry of a search query:
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
665
 * @param $item a single search result as returned by <i>module</i>_search of
666
 *   type array("count" => ..., "link" => ..., "title" => ..., "user" => ...,
Dries Buytaert's avatar
   
Dries Buytaert committed
667
668
 *   "date" => ..., "keywords" => ...)
 * @param $type module type of this item
Kjartan Mannes's avatar
Kjartan Mannes committed
669
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
670
function search_item($item, $type) {
Dries Buytaert's avatar
   
Dries Buytaert committed
671
672
673
674
675
676
677
678
679
680

  /*
  ** Modules may implement the "search_item" hook in order to overwrite
  ** the default function to display search results.
  */

  if (module_hook($type, "search_item")) {
    $output = module_invoke($type, "search_item", $item);
  }
  else {
681
682
    $output = " <dt class=\"title\"><a href=\"". $item["link"] ."\">". $item["title"] ."</a></dt>";
    $output .= " <dd class=\"small\">" . t($type) . ($item["user"] ? " - ". $item["user"] : "") ."". ($item["date"] ? " - ". format_date($item["date"], "small") : "") ."</dd>";
Dries Buytaert's avatar
   
Dries Buytaert committed
683
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
684
685
686
687

  return $output;
}

Kjartan Mannes's avatar
Kjartan Mannes committed
688
689
690
691
/**
 * Render a generic search form.
 *
 * "Generic" means "universal usable" - that is, usable not only from
Dries Buytaert's avatar
   
Dries Buytaert committed
692
693
694
 * 'site.com/search', but also as a simple seach box (without "Restrict search
 * to", help text, etc) from theme's header etc. This means: provide options to
 * only conditionally render certain parts of this form.
Kjartan Mannes's avatar
Kjartan Mannes committed
695
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
696
697
698
699
 * @param $action Form action. Defaults to 'site.com/search'.
 * @param $keys string containing keywords for the search.
 * @param $options != 0: Render additional form fields/text ("Restrict search
 *   to", help text, etc).
Kjartan Mannes's avatar
Kjartan Mannes committed
700
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
701
function search_form($action = NULL, $keys = NULL, $options = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
702
703
  $edit = $_POST['edit'];

Dries Buytaert's avatar
   
Dries Buytaert committed
704
  if (!$action) {
Dries Buytaert's avatar
   
Dries Buytaert committed
705
    $action = url("search");
Dries Buytaert's avatar
   
Dries Buytaert committed
706
707
  }

708
  $output = " <div class=\"search-form\"><br /><input type=\"text\" class=\"form-text\" size=\"50\" value=\"". check_form($keys) ."\" name=\"keys\" />";
Dries Buytaert's avatar
   
Dries Buytaert committed
709
  $output .= " <input type=\"submit\" class=\"form-submit\" value=\"". t("Search") ."\" />\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
710

Dries Buytaert's avatar
Dries Buytaert committed
711
  if ($options) {
Dries Buytaert's avatar
   
Dries Buytaert committed
712
713
714
715
716
    $output .= "<br />";
    $output .= t("Restrict search to") .": ";

    foreach (module_list() as $name) {
      if (module_hook($name, "search")) {
Kjartan Mannes's avatar
Kjartan Mannes committed
717
        $output .= " <input type=\"checkbox\" name=\"edit[type][$name]\" ". ($edit["type"][$name] ? " checked=\"checked\"" : "") ." /> ". t($name);
Dries Buytaert's avatar
   
Dries Buytaert committed
718
719
      }
    }
720
    $output .= "</div>";
Dries Buytaert's avatar
   
Dries Buytaert committed
721
722
723
724
725
726
  }

  return form($output, "post", $action);
}

/*
Kjartan Mannes's avatar
Kjartan Mannes committed
727
728
 * Collect the search results:
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
729
function search_data($keys = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
730
  $edit = $_POST["edit"];
Dries Buytaert's avatar
   
Dries Buytaert committed
731
  $output = '';
Dries Buytaert's avatar
   
Dries Buytaert committed
732

Dries Buytaert's avatar
   
Dries Buytaert committed
733
  if (isset($keys)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
734
    foreach (module_list() as $name) {
Dries Buytaert's avatar
   
Dries Buytaert committed
735
736
737
738
      if (module_hook($name, "search") && (!$edit["type"] || $edit["type"][$name])) {
        list($title, $results) = module_invoke($name, "search", $keys);
        if ($results) {
          $output .= "<h2>$title</h2>";
739
          $output .= "<dl class=\"search-results\">";
Dries Buytaert's avatar
   
Dries Buytaert committed
740
741
742
          foreach ($results as $entry) {
            $output .= search_item($entry, $name);
          }
743
          $output .= "</dl>";
Dries Buytaert's avatar
   
Dries Buytaert committed
744
745
746
747
748
749
750
751
        }
      }
    }
  }

  return $output;
}

Kjartan Mannes's avatar
Kjartan Mannes committed
752
753
754
/**
 * Display the search form and the resulting data.
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
755
756
757
758
759
760
 * @param $type If set, search only nodes of this type. Otherwise, search all
 *   types.
 * @param $action Form action. Defaults to 'site.com/search'.
 * @param $keys Query string. Defaults to global $keys.
 * @param $options != 0: Render additional form fields/text ("Restrict search
 *   to", help text, etc).
Kjartan Mannes's avatar
Kjartan Mannes committed
761
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
762
763
function search_type($type, $action = NULL, $keys = NULL, $options = NULL) {
  $_POST["edit"]["type"][$type] = "on";
Dries Buytaert's avatar
   
Dries Buytaert committed
764

Dries Buytaert's avatar
   
Dries Buytaert committed
765
  return search_form($action, $keys, $options) . "<br />". search_data($keys);
Dries Buytaert's avatar
   
Dries Buytaert committed
766
}
767
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
768

Dries Buytaert's avatar
   
Dries Buytaert committed
769
function check_form($text) {
Dries Buytaert's avatar
   
Dries Buytaert committed
770
  return drupal_specialchars($text, ENT_QUOTES);
Dries Buytaert's avatar
   
Dries Buytaert committed
771
772
}

773
774
function check_file($filename) {
  return is_uploaded_file($filename);
Dries Buytaert's avatar
   
Dries Buytaert committed
775
776
}

Dries Buytaert's avatar
   
Dries Buytaert committed
777
778
779
780
781
782
783
784
/**
 * @name Formatting
 * @ingroup common
 *
 * Functions to format numbers, strings, dates, etc.
 * @{
 */

Dries Buytaert's avatar
   
Dries Buytaert committed
785
786
787
function format_rss_channel($title, $link, $description, $items, $language = "en", $args = array()) {
  // arbitrary elements may be added using the $args associative array

Dries Buytaert's avatar
Dries Buytaert committed
788
  $output = "<channel>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
789
790
  $output .= " <title>". drupal_specialchars(strip_tags($title)) ."</title>\n";
  $output .= " <link>". drupal_specialchars(strip_tags($link)) ."</link>\n";
791
  $output .= " <description>". drupal_specialchars(strip_tags($description)) ."</description>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
792
  $output .= " <language>". drupal_specialchars(strip_tags($language)) ."</language>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
793
  foreach ($args as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
794
    $output .= " <$key>". drupal_specialchars(strip_tags($value)) ."</$key>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
795
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
796
797
798
799
800
801
  $output .= $items;
  $output .= "</channel>\n";

  return $output;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
802
803
804
function format_rss_item($title, $link, $description, $args = array()) {
  // arbitrary elements may be added using the $args associative array

Dries Buytaert's avatar
Dries Buytaert committed
805
  $output = "<item>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
806
807
808
  $output .= " <title>". drupal_specialchars(strip_tags($title)) ."</title>\n";
  $output .= " <link>". drupal_specialchars(strip_tags($link)) ."</link>\n";
  $output .= " <description>". drupal_specialchars(check_output($description)) ."</description>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
809
  foreach ($args as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
810
    $output .= "<$key>". drupal_specialchars(strip_tags($value)) ."</$key>";
Dries Buytaert's avatar
   
Dries Buytaert committed
811
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
812
813
814
815
816
  $output .= "</item>\n";

  return $output;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
817
818
/**
 * Formats a string with a count of items so that the string is pluralized
Dries Buytaert's avatar
   
Dries Buytaert committed
819
820
 * correctly. format_plural calls t() by itself, make sure not to pass already
 * localized strings to it.
Dries Buytaert's avatar
   
Dries Buytaert committed
821
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
822
823
824
825
 * @param $count The item count to display.
 * @param $singular The string for the singular case. Please make sure it's
 *   clear this is singular, to ease translation. ("1 new comment" instead of "1
 *   new").
826
 * @param $plural The string for the plural case. Please make sure it's clear
Dries Buytaert's avatar
   
Dries Buytaert committed
827
828
 *   this is plural, to ease translation. Use %count in places of the item
 *   count, as in "%count new comments".
Dries Buytaert's avatar
   
Dries Buytaert committed
829
 * @return Translated string
Dries Buytaert's avatar
   
Dries Buytaert committed
830
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
831
function format_plural($count, $singular, $plural) {
Dries Buytaert's avatar
   
Dries Buytaert committed
832
  return t($count == 1 ? $singular : $plural, array("%count" => $count));
Dries Buytaert's avatar
   
Dries Buytaert committed
833
834
}

Dries Buytaert's avatar
   
Dries Buytaert committed
835
836
837
838
839
840
/**
 * Generates a string representation for the given byte count.
 *
 * @param $size The size in bytes
 * @return Translated string representation of the size
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
841
function format_size($size) {
Dries Buytaert's avatar
   
Dries Buytaert committed
842
  $suffix = t("bytes");
Dries Buytaert's avatar
   
Dries Buytaert committed
843
844
  if ($size > 1024) {
    $size = round($size / 1024, 2);
Dries Buytaert's avatar
   
Dries Buytaert committed
845
    $suffix = t("KB");
Dries Buytaert's avatar
   
Dries Buytaert committed
846
847
848
  }
  if ($size > 1024) {
    $size = round($size / 1024, 2);
Dries Buytaert's avatar
   
Dries Buytaert committed
849
    $suffix = t("MB");
Dries Buytaert's avatar
   
Dries Buytaert committed
850
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
851
  return t("%size %suffix", array("%size" => $size, "%suffix" => $suffix));
Dries Buytaert's avatar
   
Dries Buytaert committed
852
853
}

Dries Buytaert's avatar
   
Dries Buytaert committed
854
855
856
857
858
859
860
/**
 * Formats a time interval with the requested granularity.
 *
 * @param $timestamp The length of the interval in seconds
 * @param $granularity How much units to consider when generating the string
 * @return Translated string representation of the interval
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
861
function format_interval($timestamp, $granularity = 2) {
Dries Buytaert's avatar
   
Dries Buytaert committed
862
  $units = array("1 year|%count years" => 31536000, "1 week|%count weeks" => 604800, "1 day|%count days" => 86400, "1 hour|%count hours" => 3600, "1 min|%count min" => 60, "1 sec|%count sec" => 1);
Dries Buytaert's avatar
   
Dries Buytaert committed
863
  $output = '';
Dries Buytaert's avatar
   
Dries Buytaert committed
864
  foreach ($units as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
865
866
867
868
    $key = explode("|", $key);
    if ($timestamp >= $value) {
      $output .= ($output ? " " : "") . format_plural(floor($timestamp / $value), $key[0], $key[1]);
      $timestamp %= $value;
Dries Buytaert's avatar
   
Dries Buytaert committed
869
870
871
872
873
      $granularity--;
    }

    if ($granularity == 0) {
      break;
Dries Buytaert's avatar
   
Dries Buytaert committed
874
875
    }
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
876
  return $output ? $output : t("0 sec");
Dries Buytaert's avatar
   
Dries Buytaert committed
877
878
}

Dries Buytaert's avatar
   
Dries Buytaert committed
879
880
881
882
883
884
885
886
887
888
889
890
/**
 * Formats a date with the given configured format or a custom format string.
 * Drupal allows administrators to select formatting strings for 'small',
 * 'medium' and 'large' date formats. This function can handle these formats,
 * as well as any custom format.
 *
 * @param $timestamp The exact date to format
 * @param $type Could be 'small', 'medium' or 'large' for the preconfigured
 *              date formats. If 'custom' is specified, the next parameter
 *              should contain the format string
 * @param $format Format string (as required by the PHP date() function).
 *                Only required if 'custom' date format is requested.
891
892
 * @param $timezone Timezone offset in seconds in case the user timezone
 *   should not be used.
Dries Buytaert's avatar
   
Dries Buytaert committed
893
894
 * @return Translated date string in the requested format
 */
895
896
897
898
899
function format_date($timestamp, $type = 'medium', $format = '', $timezone = NULL) {
  if ($timezone === NULL) {
    global $user;
    $timezone = $user->uid ? $user->timezone : variable_get('date_default_timezone', 0);
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
900

901
  $timestamp += $timezone;
Dries Buytaert's avatar
   
Dries Buytaert committed
902
903

  switch ($type) {
904
905
    case 'small':
      $format = variable_get('date_format_short', 'm/d/Y - H:i');
Dries Buytaert's avatar
   
Dries Buytaert committed
906
      break;
907
908
    case 'large':
      $format = variable_get('date_format_long', 'l, F j, Y - H:i');
Dries Buytaert's avatar
   
Dries Buytaert committed
909
      break;
910
    case 'custom':
Dries Buytaert's avatar
   
Dries Buytaert committed
911
      // No change to format
Dries Buytaert's avatar
   
Dries Buytaert committed
912
      break;
913
    case 'medium':
Dries Buytaert's avatar
   
Dries Buytaert committed
914
    default:
915
      $format = variable_get('date_format_medium', 'D, m/d/Y - H:i');
Dries Buytaert's avatar
   
Dries Buytaert committed
916
917
  }

918
  $max = strlen($format);
Dries Buytaert's avatar
   
Dries Buytaert committed
919
  $date = '';
920
921
  for ($i = 0; $i <= $max; $c = $format{$i++}) {
    if (strpos('AaDFlM', $c)) {
922
      $date .= t(gmdate($c, $timestamp));
923
924
925
926
927
928
    }
    else if (strpos('BdgGhHiIjLmnsStTUwWYyz', $c)) {
      $date .= gmdate($c, $timestamp);
    }
    else if ($c == 'r') {
      $date .= format_date($timestamp - $timezone, 'custom', 'D, d M Y H:i:s O', $timezone);
Dries Buytaert's avatar
   
Dries Buytaert committed
929
    }
930
931
932
933
934
    else if ($c == 'O') {
      $date .= sprintf('%s%02d%02d', ($timezone < 0 ? '-' : '+'), abs($timezone / 3600), abs($timezone % 3600) / 60);
    }
    else if ($c == 'Z') {
      $date .= $timezone;
Dries Buytaert's avatar
   
Dries Buytaert committed
935
936
    }
    else {
937
      $date .= $c;
Dries Buytaert's avatar
   
Dries Buytaert committed
938
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
939
  }
940

Dries Buytaert's avatar
   
Dries Buytaert committed
941
942
943
  return $date;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
944
945
946
947
948
949
950
951
/**
 * Formats a username.
 *
 * @param $object User object
 * @return String containing a HTML link to the user's page if the
 *         passed object suggests that this is a site user. Otherwise
 *         only the user name is returned.
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
952
953
954
function format_name($object) {

  if ($object->uid && $object->name) {
955
956
957
958
959
960
    /*
    ** Shorten the name when it is too long or it will break many
    ** tables.
    */

    if (strlen($object->name) > 20) {
961
      $name = truncate_utf8($object->name, 15) ."...";
962
963
964
965
966
    }
    else {
      $name = $object->name;
    }

Dries Buytaert's avatar
   
Dries Buytaert committed
967
    if (arg(0) == "admin" and user_access("administer users")) {
968
      $output = l($name, "admin/user/edit/$object->uid", array("title" => t("Administer user profile.")));
Dries Buytaert's avatar
   
Dries Buytaert committed
969
970
    }
    else {
971
      $output = l($name, "user/view/$object->uid", array("title" => t("View user profile.")));
Dries Buytaert's avatar
   
Dries Buytaert committed
972
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
973
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
974
975
976
977
978
979
980
981
982
983
  else if ($object->name) {
    /*
    ** Sometimes modules display content composed by people who are
    ** not registers members of the site (i.e. mailing list or news
    ** aggregator modules).  This clause enables modules to display
    ** the true author of the content.
    */

    $output = $object->name;
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
984
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
985
    $output = t(variable_get("anonymous", "Anonymous"));
Dries Buytaert's avatar
   
Dries Buytaert committed
986
987
  }

Dries Buytaert's avatar
   
Dries Buytaert committed
988
  return $output;
Dries Buytaert's avatar
   
Dries Buytaert committed
989
}
Dries Buytaert's avatar
   
Dries Buytaert committed
990
/* @} */
Dries Buytaert's avatar
   
Dries Buytaert committed
991

992
993
994
995
/**
 * @defgroup from Form generation
 * @{
 */
996
function form($form, $method = "post", $action = NULL, $attributes = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
997
  if (!$action) {
998
    $action = request_uri();
Dries Buytaert's avatar
   
Dries Buytaert committed
999
  }
1000
  return "<form action=\"$action\" method=\"$method\"". drupal_attributes($attributes) .">\n$form\n</form>\n";
For faster browsing, not all history is shown. View entire blame