common.inc 31.1 KB
Newer Older
Dries Buytaert's avatar
   
Dries Buytaert committed
1
2
3
4
5
6
7
8
9
10
11
<?php
// $Id$

function conf_init() {

  /*
  ** Try finding a matching configuration file by stripping the website's
  ** URI from left to right.  If no configuration file is found, return a
  ** default value 'conf'.
  */

Dries Buytaert's avatar
   
Dries Buytaert committed
12
  $uri = $_SERVER["PHP_SELF"];
Dries Buytaert's avatar
   
Dries Buytaert committed
13

Dries Buytaert's avatar
   
Dries Buytaert committed
14
  $file = strtolower(strtr($_SERVER["HTTP_HOST"] . substr($uri, 0, strrpos($uri, "/")), "/:", ".."));
Dries Buytaert's avatar
   
Dries Buytaert committed
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30

  while (strlen($file) > 4) {
    if (file_exists("includes/$file.php")) {
      return $file;
    }
    else {
      $file = substr($file, strpos($file, ".") + 1);
    }
  }

  return "conf";
}

function error_handler($errno, $message, $filename, $line, $variables) {
  $types = array(1 => "error", 2 => "warning", 4 => "parse error", 8 => "notice", 16 => "core error", 32 => "core warning", 64 => "compile error", 128 => "compile warning", 256 => "user error", 512 => "user warning", 1024 => "user notice");
  $entry = $types[$errno] .": $message in $filename on line $line.";
Dries Buytaert's avatar
   
Dries Buytaert committed
31
32

  if ($errno & E_ALL ^ E_NOTICE) {
Dries Buytaert's avatar
   
Dries Buytaert committed
33
    watchdog("error", $types[$errno] .": $message in $filename on line $line.");
34
    print "<pre>$entry</pre>";
Dries Buytaert's avatar
   
Dries Buytaert committed
35
36
37
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
38
function watchdog($type, $message, $link = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
39
  global $user;
Dries Buytaert's avatar
   
Dries Buytaert committed
40
  db_query("INSERT INTO {watchdog} (uid, type, message, link, location, hostname, timestamp) VALUES (%d, '%s', '%s', '%s', '%s', '%s', %d)", $user->uid, $type, $message, $link, request_uri(), getenv("REMOTE_ADDR"), time());
Dries Buytaert's avatar
   
Dries Buytaert committed
41
42
43
44
}

function throttle($type, $rate) {
  if (!user_access("access administration pages")) {
Dries Buytaert's avatar
   
Dries Buytaert committed
45
    if ($throttle = db_fetch_object(db_query("SELECT * FROM {watchdog} WHERE type = '$type' AND hostname = '". getenv("REMOTE_ADDR") ."' AND ". time() ." - timestamp < $rate"))) {
Dries Buytaert's avatar
   
Dries Buytaert committed
46
47
48
49
50
51
52
53
54
      watchdog("warning", "throttle: '". getenv("REMOTE_ADDR") ."' exceeded submission rate - $throttle->type");
      die(message_throttle());
    }
    else {
      watchdog($type, "throttle");
    }
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
55
56
function check_php_setting($name, $value) {
  if (ini_get($name) != $value) {
Steven Wittens's avatar
Steven Wittens committed
57
    print "<p>Note that the value of PHP's configuration option <code><b>$name</b></code> is incorrect.  It should be set to '$value' for Drupal to work properly.  Either configure your webserver to support <code>.htaccess</code> files so Drupal's <code>.htaccess</code> file can set it to the proper value, or edit your <code>php.ini</code> file directly.  This message will automatically dissapear when the problem has been fixed.</p>";
Dries Buytaert's avatar
   
Dries Buytaert committed
58
59
60
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
61
62
63
64
65
function arg($index) {

  static $arguments;

  if (empty($arguments)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
66
    $arguments = explode("/", $_GET["q"]);
Dries Buytaert's avatar
   
Dries Buytaert committed
67
68
69
70
71
  }

  return $arguments[$index];
}

Dries Buytaert's avatar
   
Dries Buytaert committed
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
function array2object($node) {

  if (is_array($node)) {
    foreach ($node as $key => $value) {
      $object->$key = $value;
    }
  }
  else {
    $object = $node;
  }

  return $object;
}

function object2array($node) {

  if (is_object($node)) {
    foreach ($node as $key => $value) {
      $array[$key] = $value;
    }
  }
  else {
    $array = $node;
  }

  return $array;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
100
101
102
103
104
105
106
107
108
function referer_uri() {

  if (isset($_SERVER["HTTP_REFERER"])) {
    $uri = $_SERVER["HTTP_REFERER"];

    return check_url($uri);
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
109
function request_uri() {
Dries Buytaert's avatar
   
Dries Buytaert committed
110
111
112
113
  /*
  ** Since request_uri() is only available on Apache, we generate
  ** equivalent using other environment vars.
  */
Dries Buytaert's avatar
   
Dries Buytaert committed
114

Dries Buytaert's avatar
   
Dries Buytaert committed
115
  if (isset($_SERVER["REQUEST_URI"])) {
116
    $uri = $_SERVER["REQUEST_URI"];
Dries Buytaert's avatar
   
Dries Buytaert committed
117
118
  }
  else {
119
    $uri = $_SERVER["PHP_SELF"] ."?". $_SERVER["QUERY_STRING"];
Dries Buytaert's avatar
   
Dries Buytaert committed
120
  }
121

Dries Buytaert's avatar
   
Dries Buytaert committed
122
  return check_url($uri);
Dries Buytaert's avatar
   
Dries Buytaert committed
123
124
}

Dries Buytaert's avatar
   
Dries Buytaert committed
125
function message_access() {
Dries Buytaert's avatar
   
Dries Buytaert committed
126
  return t("You are not authorized to access this page.");
Dries Buytaert's avatar
   
Dries Buytaert committed
127
128
129
130
131
132
133
134
135
136
}

function message_na() {
  return t("n/a");
}

function message_throttle() {
  return t("You exceeded the maximum submission rate.  Please wait a few minutes and try again.");
}

Dries Buytaert's avatar
   
Dries Buytaert committed
137
138
function locale_init() {
  global $languages, $user;
Dries Buytaert's avatar
   
Dries Buytaert committed
139
140
141
142
143
144
  if ($user->uid && $languages[$user->language]) {
    return $user->language;
  }
  else {
    return key($languages);
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
145
146
}

Dries Buytaert's avatar
   
Dries Buytaert committed
147
function t($string, $args = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
148
  global $languages;
149

Dries Buytaert's avatar
   
Dries Buytaert committed
150
151
152
153
154
155
156
  /*
  ** About the usage of t().  We try to keep strings whole as much as
  ** possible and are unafraid of HTML markup within translation strings
  ** if necessary.  The suggested syntax for a link embedded within a
  ** translation string is for example:
  **
  ** $msg = t("You must login below or <a href=\"%url\">create a new
Dries Buytaert's avatar
   
Dries Buytaert committed
157
158
  **           account</a> before viewing the next page.", array("%url"
  **           => url("user/register")));
Dries Buytaert's avatar
   
Dries Buytaert committed
159
160
  */

161
  $string = ($languages && module_exist("locale") ? locale($string) : $string);
162

Dries Buytaert's avatar
   
Dries Buytaert committed
163
164
  if (!$args) {
    return $string;
Kjartan Mannes's avatar
Kjartan Mannes committed
165
166
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
167
168
    return strtr($string, $args);
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
169
170
171
}

function variable_init($conf = array()) {
Dries Buytaert's avatar
   
Dries Buytaert committed
172
  $result = db_query("SELECT * FROM {variable} ");
Dries Buytaert's avatar
   
Dries Buytaert committed
173
174
  while ($variable = db_fetch_object($result)) {
    if (!isset($conf[$variable->name])) {
Dries Buytaert's avatar
   
Dries Buytaert committed
175
      $conf[$variable->name] = unserialize($variable->value);
Dries Buytaert's avatar
   
Dries Buytaert committed
176
177
178
179
180
181
    }
  }

  return $conf;
}

182
function variable_get($name, $default) {
Dries Buytaert's avatar
   
Dries Buytaert committed
183
184
185
186
187
188
189
190
  global $conf;

  return isset($conf[$name]) ? $conf[$name] : $default;
}

function variable_set($name, $value) {
  global $conf;

Dries Buytaert's avatar
   
Dries Buytaert committed
191
192
  db_query("DELETE FROM {variable} WHERE name = '%s'", $name);
  db_query("INSERT INTO {variable} (name, value) VALUES ('%s', '%s')", $name, serialize($value));
Dries Buytaert's avatar
   
Dries Buytaert committed
193
194
195
196
197
198
199

  $conf[$name] = $value;
}

function variable_del($name) {
  global $conf;

Dries Buytaert's avatar
   
Dries Buytaert committed
200
  db_query("DELETE FROM {variable} WHERE name = '%s'", $name);
Dries Buytaert's avatar
   
Dries Buytaert committed
201
202
203
204

  unset($conf[$name]);
}

Dries Buytaert's avatar
   
Dries Buytaert committed
205
function drupal_specialchars($input, $quotes = ENT_NOQUOTES) {
Dries Buytaert's avatar
   
Dries Buytaert committed
206
207
208
209
210
211
212
213
214

  /*
  ** Note that we'd like to go 'htmlspecialchars($input, $quotes, "utf-8")'
  ** like the PHP manual tells us to, but we can't because there's a bug in
  ** PHP <4.3 that makes it mess up multibyte charsets if we specify the
  ** charset.  Change this later once we make PHP 4.3 a requirement.
  */

  return htmlspecialchars($input, $quotes);
Dries Buytaert's avatar
   
Dries Buytaert committed
215
216
}

Dries Buytaert's avatar
   
Dries Buytaert committed
217
function table_cell($cell, $header = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
218
  if (is_array($cell)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
219
220
221
222
223
224
225
226
227
228
229
    $data = $cell["data"];
    foreach ($cell as $key => $value) {
      if ($key != "data")  {
        $attributes .= " $key=\"$value\"";
      }
    }
  }
  else {
    $data = $cell;
  }

Dries Buytaert's avatar
   
Dries Buytaert committed
230
  if ($header) {
Dries Buytaert's avatar
   
Dries Buytaert committed
231
232
233
234
235
236
237
238
239
240
241
    $output = "<th$attributes>$data</th>";
  }
  else {
    $output = "<td$attributes>$data</td>";
  }

  return $output;
}

function table($header, $rows) {

242
  $output = "<table>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
243
244
245
246
247

  /*
  ** Emit the table header:
  */

Dries Buytaert's avatar
   
Dries Buytaert committed
248
249
250
251
252
  if (is_array($header)) {
    $output .= " <tr>";
    foreach ($header as $cell) {
      $output .= table_cell($cell, 1);
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
253
    $output .= " </tr>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
254
255
256
257
258
259
  }

  /*
  ** Emit the table rows:
  */

Dries Buytaert's avatar
   
Dries Buytaert committed
260
261
262
263
264
265
266
267
  if (is_array($rows)) {
    foreach ($rows as $number => $row) {
      if ($number % 2 == 1) {
        $output .= " <tr class=\"light\">";
      }
      else {
        $output .= " <tr class=\"dark\">";
      }
Dries Buytaert's avatar
   
Dries Buytaert committed
268

Dries Buytaert's avatar
   
Dries Buytaert committed
269
270
271
      foreach ($row as $cell) {
        $output .= table_cell($cell, 0);
      }
Dries Buytaert's avatar
   
Dries Buytaert committed
272
      $output .= " </tr>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
273
274
275
    }
  }

Dries Buytaert's avatar
   
Dries Buytaert committed
276
  $output .= "</table>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
277
278
279
280

  return $output;
}

281
282
283
284
285
286
/**
 * Verify the syntax of the given e-mail address.  Empty e-mail addresses
 * are allowed.  See RFC 2822 for details.
 *
 * @param $mail  a email address
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
287
function valid_email_address($mail) {
288
289
290
291
292
293
294
295
296
297
298
299
300
  $user = '[a-zA-Z0-9_\-\.\+\^!#\$%&*+\/\=\?\`\|\{\}~\']+';
  $domain = '(?:[a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\-]*[a-zA-Z0-9]\.?)+';
  $ipv4 = '[0-9]{1,3}(\.[0-9]{1,3}){3}';
  $ipv6 = '[0-9a-fA-F]{1,4}(\:[0-9a-fA-F]{1,4}){7}';

  if (preg_match("/^$user@($domain|(\[($ipv4|$ipv6)\]))$/", $mail)) {
    return 1;
  }
  else {
    return 0;
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
/**
 * Verify the syntax of the given URL.
 *
 * @param $url  an URL
 */
function valid_url($url) {

  if (preg_match("/^[a-zA-z0-9\/:_\-_\.]+$/", $url)) {
    return 1;
  }
  else {
    return 0;
  }
}

Kjartan Mannes's avatar
Kjartan Mannes committed
316
317
318
319
/**
 * Format a single result entry of a search query:
 *
 * @param $item  a single search result as returned by <module>_search of type
Dries Buytaert's avatar
   
Dries Buytaert committed
320
 *               array("count" => ..., "link" => ..., "title" => ...,
Kjartan Mannes's avatar
Kjartan Mannes committed
321
322
323
 *               "user" => ..., "date" => ..., "keywords" => ...)
 * @param $type  module type of this item
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
324
function search_item($item, $type) {
Dries Buytaert's avatar
   
Dries Buytaert committed
325
326
327
328
329
330
331
332
333
334

  /*
  ** Modules may implement the "search_item" hook in order to overwrite
  ** the default function to display search results.
  */

  if (module_hook($type, "search_item")) {
    $output = module_invoke($type, "search_item", $item);
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
335
    $output .= " <b><u><a href=\"". $item["link"] ."\">". $item["title"] ."</a></u></b><br />";
Dries Buytaert's avatar
   
Dries Buytaert committed
336
337
338
    $output .= " <small>$type ". ($item["user"] ? " - ". $item["user"] : "") ."". ($item["date"] ? " - ". format_date($item["date"], "small") : "") ."</small>";
    $output .= "<br /><br />";
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
339
340
341
342

  return $output;
}

Kjartan Mannes's avatar
Kjartan Mannes committed
343
344
345
346
/**
 * Render a generic search form.
 *
 * "Generic" means "universal usable" - that is, usable not only from
Dries Buytaert's avatar
   
Dries Buytaert committed
347
 * 'site.com/search', but also as a simple seach box (without
Dries Buytaert's avatar
   
Dries Buytaert committed
348
349
 * "Restrict search to", help text, etc) from theme's header etc.
 * This means: provide options to only conditionally render certain
Kjartan Mannes's avatar
Kjartan Mannes committed
350
351
 * parts of this form.
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
352
 * @param $action  Form action. Defaults to 'site.com/search'.
Dries Buytaert's avatar
   
Dries Buytaert committed
353
 * @param $keys   string containing keywords for the search.
Dries Buytaert's avatar
   
Dries Buytaert committed
354
 * @param $options != 0: Render additional form fields/text
Kjartan Mannes's avatar
Kjartan Mannes committed
355
356
 *                 ("Restrict search to", help text, etc).
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
357
function search_form($action = NULL, $keys = NULL, $options = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
358
359

  if (!$action) {
Dries Buytaert's avatar
   
Dries Buytaert committed
360
    $action = url("search");
Dries Buytaert's avatar
   
Dries Buytaert committed
361
362
  }

Kjartan Mannes's avatar
Kjartan Mannes committed
363
364
  $output .= " <br /><input type=\"text\" size=\"50\" value=\"". check_form($keys) ."\" name=\"keys\" />";
  $output .= " <input type=\"submit\" value=\"". t("Search") ."\" />\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
365
366
367
368
369
370
371

  if ($options != 0) {
    $output .= "<br />";
    $output .= t("Restrict search to") .": ";

    foreach (module_list() as $name) {
      if (module_hook($name, "search")) {
Kjartan Mannes's avatar
Kjartan Mannes committed
372
        $output .= " <input type=\"checkbox\" name=\"edit[type][$name]\" ". ($edit["type"][$name] ? " checked=\"checked\"" : "") ." /> ". t($name);
Dries Buytaert's avatar
   
Dries Buytaert committed
373
374
375
376
      }
    }
  }

Kjartan Mannes's avatar
Kjartan Mannes committed
377
378
  $form .= "<br />";

Dries Buytaert's avatar
   
Dries Buytaert committed
379
380
381
382
  return form($output, "post", $action);
}

/*
Kjartan Mannes's avatar
Kjartan Mannes committed
383
384
 * Collect the search results:
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
385
function search_data($keys = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
386
387

  $edit = $_POST["edit"];
Dries Buytaert's avatar
   
Dries Buytaert committed
388

Dries Buytaert's avatar
   
Dries Buytaert committed
389
  if (isset($keys)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
390
391
    foreach (module_list() as $name) {
      if (module_hook($name, "search") && (!$edit["type"] || $edit["type"][$name]) && ($result = module_invoke($name, "search", check_query($keys)))) {
Kjartan Mannes's avatar
Kjartan Mannes committed
392
        if ($name == "node" || $name == "comment") {
Dries Buytaert's avatar
   
Dries Buytaert committed
393
          $output .= "<p><b>". t("Matching ". $name ."s ranked in order of relevance") .":</b></p>";
Kjartan Mannes's avatar
Kjartan Mannes committed
394
395
        }
        else {
Dries Buytaert's avatar
   
Dries Buytaert committed
396
          $output .= "<p><b>". t("Matching ". $name ."s") .":</b></p>";
Kjartan Mannes's avatar
Kjartan Mannes committed
397
        }
Dries Buytaert's avatar
   
Dries Buytaert committed
398
399
400
401
402
403
404
405
406
407
        foreach ($result as $entry) {
          $output .= search_item($entry, $name);
        }
      }
    }
  }

  return $output;
}

Kjartan Mannes's avatar
Kjartan Mannes committed
408
409
410
/**
 * Display the search form and the resulting data.
 *
Dries Buytaert's avatar
   
Dries Buytaert committed
411
 * @param $type    If set, search only nodes of this type.
Kjartan Mannes's avatar
Kjartan Mannes committed
412
 *                 Otherwise, search all types.
Dries Buytaert's avatar
   
Dries Buytaert committed
413
 * @param $action  Form action. Defaults to 'site.com/search'.
Kjartan Mannes's avatar
Kjartan Mannes committed
414
 * @param $query   Query string. Defaults to global $keys.
Dries Buytaert's avatar
   
Dries Buytaert committed
415
 * @param $options != 0: Render additional form fields/text
Kjartan Mannes's avatar
Kjartan Mannes committed
416
417
 *                 ("Restrict search to", help text, etc).
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
418
function search_type($type, $action = NULL, $keys = NULL, $options = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
419

Dries Buytaert's avatar
   
Dries Buytaert committed
420
  $_POST["edit"]["type"][$type] = "on";
Dries Buytaert's avatar
   
Dries Buytaert committed
421

Dries Buytaert's avatar
   
Dries Buytaert committed
422
  return search_form($action, $keys, $options) . "<br />". search_data($keys);
Dries Buytaert's avatar
   
Dries Buytaert committed
423
424
}

Dries Buytaert's avatar
   
Dries Buytaert committed
425

Dries Buytaert's avatar
   
Dries Buytaert committed
426
427
function drupal_goto($url) {

Dries Buytaert's avatar
   
Dries Buytaert committed
428
429
430
  /*
  ** Translate &amp; to simply &
  */
Dries Buytaert's avatar
   
Dries Buytaert committed
431

Dries Buytaert's avatar
   
Dries Buytaert committed
432
  $url = str_replace("&amp;", "&", $url);
Dries Buytaert's avatar
   
Dries Buytaert committed
433

Dries Buytaert's avatar
   
Dries Buytaert committed
434
435
436
437
438
  /*
  ** It is advised to use "drupal_goto()" instead of PHP's "header()" as
  ** "drupal_goto()" will append the user's session ID to the URI when PHP
  ** is compiled with "--enable-trans-sid".
  */
Dries Buytaert's avatar
   
Dries Buytaert committed
439
  if (!ini_get("session.use_trans_sid") || !session_id() || strstr($url, session_id())) {
Dries Buytaert's avatar
   
Dries Buytaert committed
440
441
442
    header("Location: $url");
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
443
444
445
446
447
448
449
450
    $sid = session_name() . "=" . session_id();

    if (strstr($url, "?") && !strstr($url, $sid)) {
      header("Location: $url&". $sid);
    }
    else {
      header("Location: $url?". $sid);
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
451
452
453
454
  }

  /*
  ** The "Location" header sends a REDIRECT status code to the http
Dries Buytaert's avatar
   
Dries Buytaert committed
455
  ** daemon.  In some cases this can go wrong, so we make sure none
Dries Buytaert's avatar
   
Dries Buytaert committed
456
457
458
459
460
461
462
463
464
465
466
  ** of the code /below/ gets executed when we redirect.
  */

  exit();
}

/*
** Stores the referer in a persistent variable:
*/

function referer_save() {
Dries Buytaert's avatar
   
Dries Buytaert committed
467
468
  if (!strstr(referer_uri(), request_uri())) {
    $_SESSION["referer"] = referer_uri();
Dries Buytaert's avatar
   
Dries Buytaert committed
469
470
471
472
473
474
475
476
  }
}

/*
** Restores the referer from a persistent variable:
*/

function referer_load() {
Dries Buytaert's avatar
   
Dries Buytaert committed
477
478
  if (isset($_SESSION["referer"])) {
    return $_SESSION["referer"];
Dries Buytaert's avatar
   
Dries Buytaert committed
479
480
481
482
483
484
  }
  else {
    return 0;
  }
}

485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
function xss_check_input_data($data) {

  if (is_array($data)) {
    /*
    ** Form data can contain a number of nested arrays.
    */

    foreach ($data as $key => $value) {
      xss_check_input_data($value);
    }
  }
  else {
    /*
    ** Detect evil input data.
    */

Dries Buytaert's avatar
Dries Buytaert committed
501
    // check strings:
Dries Buytaert's avatar
Dries Buytaert committed
502
    $match  = preg_match("/\Wjavascript\s*:/i", $data);
Dries Buytaert's avatar
Dries Buytaert committed
503
504
505
    $match += preg_match("/\Wexpression\s*\(/i", $data);
    $match += preg_match("/\Walert\s*\(/i", $data);

506
    // check attributes:
Dries Buytaert's avatar
Dries Buytaert committed
507
    $match += preg_match("/\W(dynsrc|datasrc|data|lowsrc|on[a-z]+)\s*=[^>]+?>/i", $data);
Dries Buytaert's avatar
   
Dries Buytaert committed
508

509
510

    // check tags:
Dries Buytaert's avatar
   
Dries Buytaert committed
511
    $match += preg_match("/<\s*(applet|script|object|style|embed|form|blink|meta|html|frame|iframe|layer|ilayer|head|frameset|xml)/i", $data);
512
513
514
515
516
517
518

    if ($match) {
      watchdog("warning", "terminated request because of suspicious input data: ". drupal_specialchars($data));
      die("terminated request because of suspicious input data");
    }
  }
}
Dries Buytaert's avatar
   
Dries Buytaert committed
519

520
function check_url($uri) {
Dries Buytaert's avatar
   
Dries Buytaert committed
521
522
523
524
525
526
527
528
529
530
531
532
  $uri = htmlspecialchars($uri, ENT_QUOTES);

  /*
  ** We replace ( and ) with their entity equivalents to prevent XSS
  ** attacks.
  */

  $uri = strtr($uri, array("(" => "&040;", ")" => "&041;"));

  return $uri;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
533
function check_form($text) {
Dries Buytaert's avatar
   
Dries Buytaert committed
534
  return drupal_specialchars($text, ENT_QUOTES);
Dries Buytaert's avatar
   
Dries Buytaert committed
535
536
}

Dries Buytaert's avatar
   
Dries Buytaert committed
537
function check_query($text) {
Dries Buytaert's avatar
   
Dries Buytaert committed
538
  return addslashes($text);
Dries Buytaert's avatar
   
Dries Buytaert committed
539
540
541
}

function filter($text) {
Dries Buytaert's avatar
   
Dries Buytaert committed
542

Dries Buytaert's avatar
   
Dries Buytaert committed
543
544
545
546
547
548
549
550
551
552
553
554
555
  $modules = module_list();

  /*
  ** Make sure the HTML filters that are part of the node module
  ** are run first.
  */

  if (in_array("node", $modules)) {
    $text = module_invoke("node", "filter", $text);
  }

  foreach ($modules as $name) {
    if (module_hook($name, "filter") && $name != "node") {
Dries Buytaert's avatar
   
Dries Buytaert committed
556
557
558
559
560
      $text = module_invoke($name, "filter", $text);
    }
  }

  return $text;
Dries Buytaert's avatar
   
Dries Buytaert committed
561
562
}

Dries Buytaert's avatar
   
Dries Buytaert committed
563
564
function rewrite_old_urls($text) {

Dries Buytaert's avatar
   
Dries Buytaert committed
565
566
567
568
  global $base_url;

  $end = substr($base_url, 12);

Dries Buytaert's avatar
   
Dries Buytaert committed
569
570
571
  /*
  ** This is a *temporary* filter to rewrite old-style URLs to new-style
  ** URLs (clean URLs).  Currently, URLs are being rewritten dynamically
Dries Buytaert's avatar
   
Dries Buytaert committed
572
573
  ** (ie. "on output"), however when these rewrite rules have been tested
  ** enough, we will use them to permanently rewrite the links in node
Dries Buytaert's avatar
   
Dries Buytaert committed
574
575
576
  ** and comment bodies.
  */

Dries Buytaert's avatar
   
Dries Buytaert committed
577
  if (variable_get("clean_url", "0") == "0") {
Dries Buytaert's avatar
   
Dries Buytaert committed
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
    /*
    ** Relative URLs:
    */

    // rewrite 'node.php?id=<number>[&cid=<number>]' style URLs:
    $text = eregi_replace("\"(node)\.php\?id=([[:digit:]]+)(&cid=)?([[:digit:]]*)", "\"?q=\\1/view/\\2/\\4", $text);

    // rewrite 'module.php?mod=<name>{&<op>=<value>}' style URLs:
    $text = ereg_replace("\"module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "\"?q=\\2/\\4/\\6" , $text);
    $text = ereg_replace("\"module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "\"?q=\\2/\\4", $text);
    $text = ereg_replace("\"module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))", "\"?q=\\2", $text);

    /*
    ** Absolute URLs:
    */

Dries Buytaert's avatar
   
Dries Buytaert committed
594
    // rewrite 'node.php?id=<number>[&cid=<number>]' style URLs:
Dries Buytaert's avatar
   
Dries Buytaert committed
595
    $text = eregi_replace("$end/(node)\.php\?id=([[:digit:]]+)(&cid=)?([[:digit:]]*)", "$end/?q=\\1/view/\\2/\\4", $text);
Dries Buytaert's avatar
   
Dries Buytaert committed
596

Dries Buytaert's avatar
   
Dries Buytaert committed
597
    // rewrite 'module.php?mod=<name>{&<op>=<value>}' style URLs:
Dries Buytaert's avatar
   
Dries Buytaert committed
598
599
600
    $text = ereg_replace("$end/module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "$end/?q=\\2/\\4/\\6" , $text);
    $text = ereg_replace("$end/module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "$end/?q=\\2/\\4", $text);
    $text = ereg_replace("$end/module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))", "\"$end/?q=\\2", $text);
Dries Buytaert's avatar
   
Dries Buytaert committed
601
602
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
603
604
605
606
    /*
    ** Relative URLs:
    */

Dries Buytaert's avatar
   
Dries Buytaert committed
607
    // rewrite 'node.php?id=<number>[&cid=<number>]' style URLs:
Dries Buytaert's avatar
   
Dries Buytaert committed
608
    $text = eregi_replace("\"(node)\.php\?id=([[:digit:]]+)(&cid=)?([[:digit:]]*)", "\"\\1/view/\\2/\\4", $text);
Dries Buytaert's avatar
   
Dries Buytaert committed
609
610

    // rewrite 'module.php?mod=<name>{&<op>=<value>}' style URLs:
Dries Buytaert's avatar
   
Dries Buytaert committed
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
    $text = ereg_replace("\"module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "\"\\2/\\4/\\6", $text);
    $text = ereg_replace("\"module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "\"\\2/\\4", $text);
    $text = ereg_replace("\"module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))", "\"\\2", $text);

    /*
    ** Absolute URLs:
    */

    // rewrite 'node.php?id=<number>[&cid=<number>]' style URLs:
    $text = eregi_replace("$end/(node)\.php\?id=([[:digit:]]+)(&cid=)?([[:digit:]]*)", "$end/\\1/view/\\2/\\4", $text);

    // rewrite 'module.php?mod=<name>{&<op>=<value>}' style URLs:
    $text = ereg_replace("$end/module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "$end/\\2/\\4/\\6", $text);
    $text = ereg_replace("$end/module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))(&?[[:alpha:]]+=([[:alnum:]]+))", "$end/\\2/\\4", $text);
    $text = ereg_replace("$end/module\.php\?(&?[[:alpha:]]+=([[:alnum:]]+))", "$end/\\2", $text);
}
Dries Buytaert's avatar
   
Dries Buytaert committed
627

Dries Buytaert's avatar
   
Dries Buytaert committed
628
629
630
  return $text;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
631
function check_output($text) {
Dries Buytaert's avatar
   
Dries Buytaert committed
632
  if (isset($text)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
633
634
635
636
    // filter content on output:
    $text = filter($text);

    // get the line breaks right:
Dries Buytaert's avatar
   
Dries Buytaert committed
637
    if (strip_tags($text, "<a><i><b><u><tt><code><cite><strong><img>") == $text) {
Dries Buytaert's avatar
   
Dries Buytaert committed
638
639
640
641
642
643
644
645
      $text = nl2br($text);
    }
  }
  else {
    $text = message_na();
  }

  return $text;
Dries Buytaert's avatar
   
Dries Buytaert committed
646
647
648
649
650
651
652
653
654
655
656
}

function check_file($filename) {
  if (is_uploaded_file($filename)) {
    return 1;
  }
  else {
    return 0;
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
657
658
659
function format_rss_channel($title, $link, $description, $items, $language = "en", $args = array()) {
  // arbitrary elements may be added using the $args associative array

Dries Buytaert's avatar
   
Dries Buytaert committed
660
  $output .= "<channel>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
661
662
663
664
  $output .= " <title>". drupal_specialchars(strip_tags($title)) ."</title>\n";
  $output .= " <link>". drupal_specialchars(strip_tags($link)) ."</link>\n";
  $output .= " <description>". drupal_specialchars($description) ."</description>\n";
  $output .= " <language>". drupal_specialchars(strip_tags($language)) ."</language>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
665
  foreach ($args as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
666
    $output .= "<$key>". drupal_specialchars(strip_tags($value)) ."</$key>";
Dries Buytaert's avatar
   
Dries Buytaert committed
667
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
668
669
670
671
672
673
  $output .= $items;
  $output .= "</channel>\n";

  return $output;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
674
675
676
function format_rss_item($title, $link, $description, $args = array()) {
  // arbitrary elements may be added using the $args associative array

Dries Buytaert's avatar
   
Dries Buytaert committed
677
  $output .= "<item>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
678
679
680
  $output .= " <title>". drupal_specialchars(strip_tags($title)) ."</title>\n";
  $output .= " <link>". drupal_specialchars(strip_tags($link)) ."</link>\n";
  $output .= " <description>". drupal_specialchars(check_output($description)) ."</description>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
681
  foreach ($args as $key => $value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
682
    $output .= "<$key>". drupal_specialchars(strip_tags($value)) ."</$key>";
Dries Buytaert's avatar
   
Dries Buytaert committed
683
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
684
685
686
687
688
  $output .= "</item>\n";

  return $output;
}

Dries Buytaert's avatar
   
Dries Buytaert committed
689
690
691
692
693
694
695
696
697
698
699
700
701
702
/**
 * Formats a string with a count of items so that the string is pluralized
 * correctly.
 * format_plural calls t() by itself, make sure not to pass already localized
 * strings to it.
 *
 * @param $count    The item count to display.
 * @param $singular The string for the singular case. Please make sure it's clear
 *                  this is singular, to ease translation. ("1 new comment" instead of
 *                  "1 new").
 * @param $plural   The string for the plrual case. Please make sure it's clear
 *                  this is plural, to ease translation. Use %count in places of the
 *                  item count, as in "%count new comments".
 */
Dries Buytaert's avatar
   
Dries Buytaert committed
703
function format_plural($count, $singular, $plural) {
Dries Buytaert's avatar
   
Dries Buytaert committed
704
  return t($count == 1 ? $singular : $plural, array("%count" => $count));
Dries Buytaert's avatar
   
Dries Buytaert committed
705
706
707
}

function format_size($size) {
Dries Buytaert's avatar
   
Dries Buytaert committed
708
  $suffix = t("bytes");
Dries Buytaert's avatar
   
Dries Buytaert committed
709
710
  if ($size > 1024) {
    $size = round($size / 1024, 2);
Dries Buytaert's avatar
   
Dries Buytaert committed
711
    $suffix = t("KB");
Dries Buytaert's avatar
   
Dries Buytaert committed
712
713
714
  }
  if ($size > 1024) {
    $size = round($size / 1024, 2);
Dries Buytaert's avatar
   
Dries Buytaert committed
715
    $suffix = t("MB");
Dries Buytaert's avatar
   
Dries Buytaert committed
716
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
717
  return t("%size %suffix", array("%size" => $size, "%suffix" => $suffix));
Dries Buytaert's avatar
   
Dries Buytaert committed
718
719
}

Dries Buytaert's avatar
   
Dries Buytaert committed
720
function cache_get($key) {
Dries Buytaert's avatar
   
Dries Buytaert committed
721
  $cache = db_fetch_object(db_query("SELECT data, created FROM {cache} WHERE cid = '%s'", $key));
Dries Buytaert's avatar
   
Dries Buytaert committed
722
  return $cache->data ? $cache : 0;
Dries Buytaert's avatar
   
Dries Buytaert committed
723
724
725
}

function cache_set($cid, $data, $expire = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
726
727
  if (db_fetch_object(db_query("SELECT cid FROM {cache} WHERE cid = '%s'", $cid))) {
    db_query("UPDATE {cache} SET data = '%s', created = %d, expire = %d WHERE cid = '%s'", $data, time(), $expire, $cid);
Dries Buytaert's avatar
   
Dries Buytaert committed
728
729
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
730
    db_query("INSERT INTO {cache} (cid, data, created, expire) VALUES('%s', '%s', %d, %d)", $cid, $data, time(), $expire);
Dries Buytaert's avatar
   
Dries Buytaert committed
731
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
732
733
}

Dries Buytaert's avatar
   
Dries Buytaert committed
734
735
function cache_clear_all($cid = NULL) {
  if (empty($cid)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
736
    db_query("DELETE FROM {cache} WHERE expire <> 0");
Dries Buytaert's avatar
   
Dries Buytaert committed
737
738
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
739
    db_query("DELETE FROM {cache} WHERE cid = '%s'", $cid);
Dries Buytaert's avatar
   
Dries Buytaert committed
740
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
741
742
743
}

function page_set_cache() {
Dries Buytaert's avatar
   
Dries Buytaert committed
744
  global $user;
Dries Buytaert's avatar
   
Dries Buytaert committed
745

Dries Buytaert's avatar
   
Dries Buytaert committed
746
  if (!$user->uid && $_SERVER["REQUEST_METHOD"] == "GET") {
Dries Buytaert's avatar
   
Dries Buytaert committed
747
    if ($data = ob_get_contents()) {
Dries Buytaert's avatar
   
Dries Buytaert committed
748
      cache_set(request_uri(), $data, 1);
Dries Buytaert's avatar
   
Dries Buytaert committed
749
750
751
752
    }
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
753
function page_get_cache() {
Dries Buytaert's avatar
   
Dries Buytaert committed
754
  global $user;
Dries Buytaert's avatar
   
Dries Buytaert committed
755

Dries Buytaert's avatar
   
Dries Buytaert committed
756
757
  $cache = NULL;

Dries Buytaert's avatar
   
Dries Buytaert committed
758
  if (!$user->uid && $_SERVER["REQUEST_METHOD"] == "GET") {
Dries Buytaert's avatar
   
Dries Buytaert committed
759
760
761
    $cache = cache_get(request_uri());

    if (empty($cache)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
762
      ob_start();
Dries Buytaert's avatar
   
Dries Buytaert committed
763
764
    }
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
765

Dries Buytaert's avatar
   
Dries Buytaert committed
766
  return $cache;
Dries Buytaert's avatar
   
Dries Buytaert committed
767
768
769
}

function format_interval($timestamp) {
Dries Buytaert's avatar
   
Dries Buytaert committed
770
  $units = array("1 year|%count years" => 31536000, "1 week|%count weeks" => 604800, "1 day|%count days" => 86400, "1 hour|%count hours" => 3600, "1 min|%count min" => 60, "1 sec|%count sec" => 1);
Kjartan Mannes's avatar
Kjartan Mannes committed
771
  foreach ($units as $key=>$value) {
Dries Buytaert's avatar
   
Dries Buytaert committed
772
773
774
775
776
777
    $key = explode("|", $key);
    if ($timestamp >= $value) {
      $output .= ($output ? " " : "") . format_plural(floor($timestamp / $value), $key[0], $key[1]);
      $timestamp %= $value;
    }
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
778
  return ($output) ? $output : t("0 sec");
Dries Buytaert's avatar
   
Dries Buytaert committed
779
780
781
782
783
}

function format_date($timestamp, $type = "medium", $format = "") {
  global $user;

Kjartan Mannes's avatar
Kjartan Mannes committed
784
  $timestamp += ($user->timezone) ? $user->timezone - date("Z") : 0;
Dries Buytaert's avatar
   
Dries Buytaert committed
785
786
787

  switch ($type) {
    case "small":
Dries Buytaert's avatar
   
Dries Buytaert committed
788
      $date = date(variable_get("date_format_short", "m/d/Y - H:i"), $timestamp);
Dries Buytaert's avatar
   
Dries Buytaert committed
789
790
      break;
    case "medium":
791
      $date = date(variable_get("date_format_medium", "D, m/d/Y - H:i"), $timestamp);
Dries Buytaert's avatar
   
Dries Buytaert committed
792
793
      break;
    case "large":
794
      $date = date(variable_get("date_format_long", "l, F j, Y - H:i"), $timestamp);
Dries Buytaert's avatar
   
Dries Buytaert committed
795
796
797
798
      break;
    case "custom":
      for ($i = strlen($format); $i >= 0; $c = $format[--$i]) {
        if (strstr("DFlMSw", $c)) {
799
          $date = t(date($c, $timestamp)) . $date;
Dries Buytaert's avatar
   
Dries Buytaert committed
800
        }
801
        else if (strstr("AaBdgGhHiIjLmnOrstTUWYyZz", $c)) {
802
          $date = date($c, $timestamp) . $date;
Dries Buytaert's avatar
   
Dries Buytaert committed
803
804
        }
        else {
Kjartan Mannes's avatar
Kjartan Mannes committed
805
          $date = $c.$date;
Dries Buytaert's avatar
   
Dries Buytaert committed
806
807
808
809
        }
      }
      break;
    default:
810
      $date = date(variable_get("date_format_medium", "l, m/d/Y - H:i"), $timestamp);
Dries Buytaert's avatar
   
Dries Buytaert committed
811
812
813
814
815
816
817
  }
  return $date;
}

function format_name($object) {

  if ($object->uid && $object->name) {
Dries Buytaert's avatar
   
Dries Buytaert committed
818
    if (arg(0) == "admin") {
Dries Buytaert's avatar
   
Dries Buytaert committed
819
      $output = l($object->name, "admin/user/edit/$object->uid", array("title" => t("Administer user profile.")));
Dries Buytaert's avatar
   
Dries Buytaert committed
820
821
    }
    else {
Dries Buytaert's avatar
   
Dries Buytaert committed
822
      $output = l($object->name, "user/view/$object->uid", array("title" => t("View user profile.")));
Dries Buytaert's avatar
   
Dries Buytaert committed
823
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
824
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
825
826
827
828
829
830
831
832
833
834
  else if ($object->name) {
    /*
    ** Sometimes modules display content composed by people who are
    ** not registers members of the site (i.e. mailing list or news
    ** aggregator modules).  This clause enables modules to display
    ** the true author of the content.
    */

    $output = $object->name;
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
835
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
836
    $output = t(variable_get("anonymous", "Anonymous"));
Dries Buytaert's avatar
   
Dries Buytaert committed
837
838
  }

Dries Buytaert's avatar
   
Dries Buytaert committed
839
  return $output;
Dries Buytaert's avatar
   
Dries Buytaert committed
840
841
842
}

function form($form, $method = "post", $action = 0, $options = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
843
844

  if (!$action) {
845
    $action = request_uri();
Dries Buytaert's avatar
   
Dries Buytaert committed
846
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
847
  return "<form action=\"$action\" method=\"$method\"". ($options ? " $options" : "") .">\n$form\n</form>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
848
849
850
}

function form_item($title, $value, $description = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
851
  return "<div class=\"form-item\">". ($title ? "<div class=\"title\">$title:</div>" : "") . $value . ($description ? "<div class=\"description\">$description</div>" : "") ."</div>\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
852
853
}

Dries Buytaert's avatar
   
Dries Buytaert committed
854
function form_radio($title, $name, $value = 1, $checked = 0, $description = 0) {
855
  return form_item(0, "<input type=\"radio\" class=\"form-radio\" name=\"edit[$name]\" value=\"". $value ."\"". ($checked ? " checked=\"checked\"" : "") ." /> $title", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
856
857
}

858
function form_checkbox($title, $name, $value = 1, $checked = 0, $description = 0) {
859
  return form_hidden($name, 0) . form_item(0, "<input type=\"checkbox\" class=\"form-checkbox\" name=\"edit[$name]\" value=\"". $value ."\"". ($checked ? " checked=\"checked\"" : "") ." /> $title", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
860
861
862
}

function form_textfield($title, $name, $value, $size, $maxlength, $description = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
863
  $size = $size ? " size=\"$size\"" : "";
Dries Buytaert's avatar
   
Dries Buytaert committed
864
  return form_item($title, "<input type=\"text\" maxlength=\"$maxlength\" class=\"form-text\" name=\"edit[$name]\"$size value=\"". check_form($value) ."\" />", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
865
866
867
}

function form_password($title, $name, $value, $size, $maxlength, $description = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
868
869
  $size = $size ? " size=\"$size\"" : "";
  return form_item($title, "<input type=\"password\" class=\"form-password\" maxlength=\"$maxlength\" name=\"edit[$name]\"$size value=\"". check_form($value) ."\" />", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
870
871
872
}

function form_textarea($title, $name, $value, $cols, $rows, $description = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
873
  $cols = $cols ? " cols=\"$cols\"" : "";
Dries Buytaert's avatar
   
Dries Buytaert committed
874
  module_invoke_all("textarea", $name);  // eg. optionally plug in a WYSIWYG editor
Dries Buytaert's avatar
   
Dries Buytaert committed
875
  return form_item($title, "<textarea wrap=\"virtual\"$cols rows=\"$rows\" name=\"edit[$name]\" id=\"edit[$name]\">". check_form($value) ."</textarea>", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
876
877
}

Dries Buytaert's avatar
   
Dries Buytaert committed
878
function form_select($title, $name, $value, $options, $description = 0, $extra = 0, $multiple = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
879
  if (count($options) > 0) {
Kjartan Mannes's avatar
Kjartan Mannes committed
880
    foreach ($options as $key=>$choice) {
881
      $select .= "<option value=\"$key\"". (is_array($value) ? (in_array($key, $value) ? " selected=\"selected\"" : "") : ($value == $key ? " selected=\"selected\"" : "")) .">". check_form($choice) ."</option>";
Dries Buytaert's avatar
   
Dries Buytaert committed
882
    }
Kjartan Mannes's avatar
Kjartan Mannes committed
883
    return form_item($title, "<select name=\"edit[$name]". ($multiple ? "[]" : "") ."\"". ($multiple ? " multiple " : "") . ($extra ? " $extra" : "") .">$select</select>", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
884
885
886
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
887
888
889
890
891
892
893
894
895
function form_radios($title, $name, $value, $options, $description = 0) {
  if (count($options) > 0) {
    foreach ($options as $key=>$choice) {
      $output .= form_radio($choice, $name, $key, ($key == $value));
    }
    return form_item($title, $output, $description);
  }
}

Dries Buytaert's avatar
   
Dries Buytaert committed
896
function form_file($title, $name, $size, $description = 0) {
897
  return form_item($title, "<input type=\"file\" class=\"form-file\" name=\"edit[$name]\" size=\"$size\" />\n", $description);
Dries Buytaert's avatar
   
Dries Buytaert committed
898
899
900
901
902
903
}

function form_hidden($name, $value) {
  return "<input type=\"hidden\" name=\"edit[$name]\" value=\"". check_form($value) ."\" />\n";
}

Dries Buytaert's avatar
   
Dries Buytaert committed
904
905
function form_submit($value, $name = "op") {
  return "<input type=\"submit\" class=\"form-submit\" name=\"$name\" value=\"". check_form($value) ."\" />\n";
Dries Buytaert's avatar
   
Dries Buytaert committed
906
907
}

Dries Buytaert's avatar
   
Dries Buytaert committed
908
function form_weight($title = NULL, $name = "weight", $value = 0, $delta = 10, $description = 0, $extra = 0) {
Dries Buytaert's avatar
   
Dries Buytaert committed
909
  for ($n = (-1 * $delta); $n <= $delta; $n++) {
Dries Buytaert's avatar
   
Dries Buytaert committed
910
911
912
913
914
915
    $weights[$n] = $n;
  }

  return form_select($title, $name, $value, $weights, $description, $extra);
}

Dries Buytaert's avatar
   
Dries Buytaert committed
916
917
918
919
function form_allowed_tags_text() {
  return variable_get("allowed_html", "") ? (t("Allowed HTML tags") .": ". htmlspecialchars(variable_get("allowed_html", ""))) : "";
}

Dries Buytaert's avatar
   
Dries Buytaert committed
920
function url($url = NULL, $query = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
921
  global $base_url;
Dries Buytaert's avatar
   
Dries Buytaert committed
922

Dries Buytaert's avatar
   
Dries Buytaert committed
923
924
925
926
927
928
929
930
931
932
933
  static $script;

  if (empty($script)) {
    /*
    ** On some webservers such as IIS we can't omit "index.php".  As such we
    ** generate "index.php?q=foo" instead of "?q=foo" on anything that is not
    ** Apache.
    */
    $script = (strpos($_SERVER["SERVER_SOFTWARE"], "Apache") === false) ? "index.php" : "";
  }

Dries Buytaert's avatar
   
Dries Buytaert committed
934
  if (variable_get("clean_url", "0") == "0") {
Dries Buytaert's avatar
   
Dries Buytaert committed
935
936
    if (isset($url)) {
      if (isset($query)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
937
        return "$base_url/$script?q=$url&amp;$query";
Dries Buytaert's avatar
   
Dries Buytaert committed
938
939
      }
      else {
Dries Buytaert's avatar
   
Dries Buytaert committed
940
        return "$base_url/$script?q=$url";
Dries Buytaert's avatar
   
Dries Buytaert committed
941
      }
Dries Buytaert's avatar
   
Dries Buytaert committed
942
943
    }
    else {
Dries Buytaert's avatar
   
Dries Buytaert committed
944
      if (isset($query)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
945
        return "$base_url/$script?$query";
Dries Buytaert's avatar
   
Dries Buytaert committed
946
947
      }
      else {
Dries Buytaert's avatar
   
Dries Buytaert committed
948
        return "$base_url/";
Dries Buytaert's avatar
   
Dries Buytaert committed
949
      }
Dries Buytaert's avatar
   
Dries Buytaert committed
950
951
952
    }
  }
  else {
Dries Buytaert's avatar
   
Dries Buytaert committed
953
954
    if (isset($url)) {
      if (isset($query)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
955
        return "$base_url/$url?$query";
Dries Buytaert's avatar
   
Dries Buytaert committed
956
957
      }
      else {
Dries Buytaert's avatar
   
Dries Buytaert committed
958
        return "$base_url/$url";
Dries Buytaert's avatar
   
Dries Buytaert committed
959
      }
Dries Buytaert's avatar
   
Dries Buytaert committed
960
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
961
    else {
Dries Buytaert's avatar
   
Dries Buytaert committed
962
      if (isset($query)) {
Dries Buytaert's avatar
   
Dries Buytaert committed
963
        return "$base_url/$script?$query";
Dries Buytaert's avatar
   
Dries Buytaert committed
964
965
      }
      else {
Dries Buytaert's avatar
   
Dries Buytaert committed
966
        return "$base_url/";
Dries Buytaert's avatar
   
Dries Buytaert committed
967
      }
Dries Buytaert's avatar
   
Dries Buytaert committed
968
    }
Dries Buytaert's avatar
   
Dries Buytaert committed
969
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
970
971
}

Dries Buytaert's avatar
   
Dries Buytaert committed
972
function l($text, $url, $attributes = array(), $query = NULL) {
Dries Buytaert's avatar
   
Dries Buytaert committed
973

Dries Buytaert's avatar
   
Dries Buytaert committed
974
975
976
977
  $t = array();
  foreach ($attributes as $key => $value) {
    $t[] = "$key=\"$value\"";
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
978
979

  return "<a href=\"". url($url, $query) ."\" ". implode($t, " ") .">$text</a>";
Dries Buytaert's avatar
   
Dries Buytaert committed
980
981
}

Dries Buytaert's avatar
   
Dries Buytaert committed
982
function field_get($string, $name) {
983
  ereg(",?$name=([^,]+)", ", $string", $regs);
Dries Buytaert's avatar
   
Dries Buytaert committed
984
985
986
987
988
  return $regs[1];
}

function field_set($string, $name, $value) {
  $rval = ereg_replace(",$name=[^,]+", "", ",$string");
Dries Buytaert's avatar
   
Dries Buytaert committed
989
  if (isset($value)) {
Kjartan Mannes's avatar
Kjartan Mannes committed
990
991
    $rval .= ($rval == "," ? "" : ",") ."$name=$value";
  }
Dries Buytaert's avatar
   
Dries Buytaert committed
992
993
994
995
  return substr($rval, 1);
}

function link_page() {
Dries Buytaert's avatar
   
Dries Buytaert committed
996
  global $custom_links, $base_url;
Dries Buytaert's avatar
   
Dries Buytaert committed
997

998
999
1000
  if (is_array($custom_links)) {
    return $custom_links;
  }
For faster browsing, not all history is shown. View entire blame