MDL-41846 repository_url: Convert spaces to %20 in input url

This commit is contained in:
John Okely
2014-12-05 11:23:59 +08:00
parent d5f17c854b
commit 0ce7dfb2d4
2 changed files with 82 additions and 1 deletions
+17 -1
View File
@@ -46,7 +46,9 @@ class repository_url extends repository {
public function __construct($repositoryid, $context = SYSCONTEXTID, $options = array()){
global $CFG;
parent::__construct($repositoryid, $context, $options);
$this->file_url = optional_param('file', '', PARAM_URL);
$this->file_url = optional_param('file', '', PARAM_TEXT);
$this->file_url = $this->escape_url($this->file_url);
$this->file_url = clean_param($this->file_url, PARAM_URL);
}
public function check_login() {
@@ -217,6 +219,20 @@ EOD;
}
}
/**
* Escapes a url by replacing spaces with %20.
*
* Note: In general moodle does not automatically escape urls, but for the purposes of
* making this plugin more user friendly urls will automatically be escaped.
*
* @param string $url An unescaped url.
* @return string The escaped url
*/
protected function escape_url($url) {
$url = str_replace(' ', '%20', $url);
return $url;
}
public function supported_returntypes() {
return (FILE_INTERNAL | FILE_EXTERNAL);
}
+65
View File
@@ -0,0 +1,65 @@
<?php
// This file is part of Moodle - http://moodle.org/
//
// Moodle is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// Moodle is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License
// along with Moodle. If not, see <http://www.gnu.org/licenses/>.
/**
* Unit tests for the URL repository.
*
* @package repository_url
* @copyright 2014 John Okely
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
*/
defined('MOODLE_INTERNAL') || die;
global $CFG;
require_once($CFG->dirroot . '/repository/url/lib.php');
/**
* URL repository test case.
*
* @copyright 2014 John Okely
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
*/
class repository_url_lib_testcase extends advanced_testcase {
/**
* Check that the url escaper performs as expected
*/
public function test_escape_url() {
$this->resetAfterTest();
$repoid = $this->getDataGenerator()->create_repository('url')->id;
$testdata = array(
'http://example.com/test_file.png' => 'http://example.com/test_file.png',
'http://example.com/test%20file.png' => 'http://example.com/test%20file.png',
'http://example.com/test file.png' => 'http://example.com/test%20file.png',
'http://example.com/test file.png?query=string+test&more=string+tests' =>
'http://example.com/test%20file.png?query=string+test&more=string+tests'
);
foreach ($testdata as $input => $expected) {
// The constructor uses a optional_param, so we need to hack $_GET.
$_GET['file'] = $input;
$repository = new repository_url($repoid);
$this->assertSame($expected, $repository->file_url);
}
unset($_GET['file']);
}
}