summaryrefslogtreecommitdiffstats
path: root/library/Icinga/Web/Helper/HtmlPurifier.php
blob: 19fd207787cf31b7b8b1ad1cb0c331a2f3d01c38 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
<?php
/* Icinga Web 2 | (c) 2018 Icinga Development Team | GPLv2+ */

namespace Icinga\Web\Helper;

use Closure;
use Icinga\Web\FileCache;
use InvalidArgumentException;

class HtmlPurifier
{
    /**
     * The actual purifier instance
     *
     * @var \HTMLPurifier
     */
    protected $purifier;

    /**
     * Create a new HtmlPurifier
     *
     * @param   array|Closure   $config     Additional configuration
     */
    public function __construct($config = null)
    {
        $purifierConfig = \HTMLPurifier_Config::createDefault();
        $purifierConfig->set('Core.EscapeNonASCIICharacters', true);
        $purifierConfig->set('Attr.AllowedFrameTargets', array('_blank'));

        if (($cachePath = FileCache::instance()->directory('htmlpurifier.cache')) !== false) {
            $purifierConfig->set('Cache.SerializerPath', $cachePath);
        } else {
            $purifierConfig->set('Cache.DefinitionImpl', null);
        }

        // This avoids permission problems:
        // $purifierConfig->set('Core.DefinitionCache', null);

        // $purifierConfig->set('URI.Base', 'http://www.example.com');
        // $purifierConfig->set('URI.MakeAbsolute', true);

        $this->configure($purifierConfig);

        if ($config instanceof Closure) {
            call_user_func($config, $purifierConfig);
        } elseif (is_array($config)) {
            $purifierConfig->loadArray($config);
        } elseif ($config !== null) {
            throw new InvalidArgumentException('$config must be either a Closure or array');
        }

        $this->purifier = new \HTMLPurifier($purifierConfig);
    }

    /**
     * Apply additional default configuration
     *
     * May be overwritten by more concrete purifier implementations.
     *
     * @param   \HTMLPurifier_Config    $config
     */
    protected function configure($config)
    {
    }

    /**
     * Purify and return the given HTML string
     *
     * @param   string          $html
     * @param   array|Closure   $config     Configuration to use instead of the default
     *
     * @return  string
     */
    public function purify($html, $config = null)
    {
        return $this->purifier->purify($html, $config);
    }

    /**
     * Purify and return the given HTML string
     *
     * Convenience method to bypass object creation.
     *
     * @param   string          $html
     * @param   array|Closure   $config     Additional configuration
     *
     * @return  string
     */
    public static function process($html, $config = null)
    {
        $purifier = new static($config);

        return $purifier->purify($html);
    }
}