MDL-57596 forms: CLEANHTML in persistent forms
Add special handling for text fields with the CLEANHTML type. This should be used when students and teachers can edit the same field (you can't trust those students). Applies cleaning on submitted data, and on data stored in the DB before it is put back in an editing form.
This commit is contained in:
committed by
Dan Poltawski
parent
ca3cbbc233
commit
3cc4e2f725
@@ -99,7 +99,7 @@ class competency extends persistent {
|
||||
// Description.
|
||||
$mform->addElement('editor', 'description',
|
||||
get_string('description', 'tool_lp'), array('rows' => 4));
|
||||
$mform->setType('description', PARAM_RAW);
|
||||
$mform->setType('description', PARAM_CLEANHTML);
|
||||
// ID number.
|
||||
$mform->addElement('text', 'idnumber', get_string('idnumber', 'tool_lp'), 'maxlength="100"');
|
||||
$mform->setType('idnumber', PARAM_RAW);
|
||||
|
||||
@@ -62,7 +62,7 @@ class competency_framework extends persistent {
|
||||
// Description.
|
||||
$mform->addElement('editor', 'description',
|
||||
get_string('description', 'tool_lp'), array('rows' => 4));
|
||||
$mform->setType('description', PARAM_RAW);
|
||||
$mform->setType('description', PARAM_CLEANHTML);
|
||||
// ID number.
|
||||
$mform->addElement('text', 'idnumber', get_string('idnumber', 'tool_lp'), 'maxlength="100"');
|
||||
$mform->setType('idnumber', PARAM_RAW);
|
||||
|
||||
@@ -184,8 +184,14 @@ abstract class persistent extends moodleform {
|
||||
$data = $this->get_persistent()->to_record();
|
||||
$class = static::$persistentclass;
|
||||
$properties = $class::get_formatted_properties();
|
||||
$allproperties = $class::properties_definition();
|
||||
|
||||
foreach ($data as $field => $value) {
|
||||
// Clean data if it is to be displayed in a form.
|
||||
if (isset($allproperties[$field]['type'])) {
|
||||
$data->$field = clean_param($data->$field, $allproperties[$field]['type']);
|
||||
}
|
||||
|
||||
// Convert formatted properties.
|
||||
if (isset($properties[$field])) {
|
||||
$data->$field = array(
|
||||
|
||||
@@ -59,7 +59,7 @@ class plan extends persistent {
|
||||
$mform->addRule('name', get_string('maximumchars', '', 100), 'maxlength', 100, 'client');
|
||||
// Description.
|
||||
$mform->addElement('editor', 'description', get_string('plandescription', 'tool_lp'), array('rows' => 4));
|
||||
$mform->setType('description', PARAM_RAW);
|
||||
$mform->setType('description', PARAM_CLEANHTML);
|
||||
|
||||
$mform->addElement('date_time_selector', 'duedate', get_string('duedate', 'tool_lp'), array('optional' => true));
|
||||
$mform->addHelpButton('duedate', 'duedate', 'tool_lp');
|
||||
|
||||
@@ -58,7 +58,7 @@ class template extends persistent {
|
||||
// Description.
|
||||
$mform->addElement('editor', 'description',
|
||||
get_string('description', 'tool_lp'), array('rows' => 4));
|
||||
$mform->setType('description', PARAM_RAW);
|
||||
$mform->setType('description', PARAM_CLEANHTML);
|
||||
$mform->addElement('selectyesno', 'visible',
|
||||
get_string('visible', 'tool_lp'));
|
||||
$mform->addElement('date_time_selector',
|
||||
|
||||
@@ -54,7 +54,7 @@ class user_evidence extends persistent {
|
||||
$mform->addRule('name', get_string('maximumchars', '', 100), 'maxlength', 100, 'client');
|
||||
// Description.
|
||||
$mform->addElement('editor', 'description', get_string('userevidencedescription', 'tool_lp'), array('rows' => 10));
|
||||
$mform->setType('description', PARAM_RAW);
|
||||
$mform->setType('description', PARAM_CLEANHTML);
|
||||
|
||||
$mform->addElement('url', 'url', get_string('userevidenceurl', 'tool_lp'), array('size' => '60'), array('usefilepicker' => false));
|
||||
$mform->setType('url', PARAM_RAW_TRIMMED); // Can not use PARAM_URL, it silently converts bad URLs to ''.
|
||||
|
||||
@@ -68,7 +68,7 @@ class competency extends persistent {
|
||||
),
|
||||
'description' => array(
|
||||
'default' => '',
|
||||
'type' => PARAM_RAW
|
||||
'type' => PARAM_CLEANHTML
|
||||
),
|
||||
'descriptionformat' => array(
|
||||
'choices' => array(FORMAT_HTML, FORMAT_MOODLE, FORMAT_PLAIN, FORMAT_MARKDOWN),
|
||||
|
||||
@@ -90,7 +90,7 @@ class competency_framework extends persistent {
|
||||
'type' => PARAM_RAW
|
||||
),
|
||||
'description' => array(
|
||||
'type' => PARAM_RAW,
|
||||
'type' => PARAM_CLEANHTML,
|
||||
'default' => ''
|
||||
),
|
||||
'descriptionformat' => array(
|
||||
|
||||
+3
-2
@@ -334,7 +334,8 @@ abstract class exporter {
|
||||
*/
|
||||
final protected static function get_format_field($definitions, $property) {
|
||||
$formatproperty = $property . 'format';
|
||||
if ($definitions[$property]['type'] == PARAM_RAW && isset($definitions[$formatproperty])
|
||||
if (($definitions[$property]['type'] == PARAM_RAW || $definitions[$property]['type'] == PARAM_CLEANHTML)
|
||||
&& isset($definitions[$formatproperty])
|
||||
&& $definitions[$formatproperty]['type'] == PARAM_INT) {
|
||||
return $formatproperty;
|
||||
}
|
||||
@@ -451,7 +452,7 @@ abstract class exporter {
|
||||
// This is a nested array of more properties.
|
||||
$thisvalue = self::get_read_structure_from_properties($type, $proprequired, $propdefault);
|
||||
} else {
|
||||
if ($definition['type'] == PARAM_TEXT) {
|
||||
if ($definition['type'] == PARAM_TEXT || $definition['type'] == PARAM_CLEANHTML) {
|
||||
// PARAM_TEXT always becomes PARAM_RAW because filters may be applied.
|
||||
$type = PARAM_RAW;
|
||||
}
|
||||
|
||||
@@ -248,7 +248,8 @@ abstract class persistent {
|
||||
$formatted = array();
|
||||
foreach ($properties as $property => $definition) {
|
||||
$propertyformat = $property . 'format';
|
||||
if ($definition['type'] == PARAM_RAW && array_key_exists($propertyformat, $properties)
|
||||
if (($definition['type'] == PARAM_RAW || $definition['type'] == PARAM_CLEANHTML)
|
||||
&& array_key_exists($propertyformat, $properties)
|
||||
&& $properties[$propertyformat]['type'] == PARAM_INT) {
|
||||
$formatted[$property] = $propertyformat;
|
||||
}
|
||||
@@ -616,6 +617,10 @@ abstract class persistent {
|
||||
// Validate_param() does not like false with PARAM_BOOL, better to convert it to int.
|
||||
$value = 0;
|
||||
}
|
||||
if ($definition['type'] === PARAM_CLEANHTML) {
|
||||
// We silently clean for this type. It may introduce changes even to valid data.
|
||||
$value = clean_param($value, PARAM_CLEANHTML);
|
||||
}
|
||||
validate_param($value, $definition['type'], $definition['null']);
|
||||
} catch (invalid_parameter_exception $e) {
|
||||
$errors[$property] = static::get_property_error_message($property);
|
||||
|
||||
@@ -71,7 +71,7 @@ class plan extends persistent {
|
||||
'type' => PARAM_TEXT,
|
||||
),
|
||||
'description' => array(
|
||||
'type' => PARAM_RAW,
|
||||
'type' => PARAM_CLEANHTML,
|
||||
'default' => ''
|
||||
),
|
||||
'descriptionformat' => array(
|
||||
|
||||
@@ -53,7 +53,7 @@ class template extends persistent {
|
||||
),
|
||||
'description' => array(
|
||||
'default' => '',
|
||||
'type' => PARAM_RAW,
|
||||
'type' => PARAM_CLEANHTML,
|
||||
),
|
||||
'descriptionformat' => array(
|
||||
'choices' => array(FORMAT_HTML, FORMAT_MOODLE, FORMAT_PLAIN, FORMAT_MARKDOWN),
|
||||
|
||||
@@ -53,7 +53,7 @@ class user_evidence extends persistent {
|
||||
'type' => PARAM_TEXT
|
||||
),
|
||||
'description' => array(
|
||||
'type' => PARAM_RAW,
|
||||
'type' => PARAM_CLEANHTML,
|
||||
'default' => '',
|
||||
),
|
||||
'descriptionformat' => array(
|
||||
|
||||
Reference in New Issue
Block a user