autoescape_config_exists = str_contains($content, '$this->config->autoescape = '); $this->source_type = preg_match('!^((?:m\.)?[a-z]+)/!', $template->relative_dirname, $matches) ? $matches[1] : null; $this->template = $template; // replace comments $content = preg_replace('@@s', '', $content); // replace value of src in img/input/script tag $content = preg_replace_callback('/<(?:img|input|script)(?:[^<>]*?)(?(?=cond=")(?:cond="[^"]+"[^<>]*)+|)[^<>]* src="(?!(?:https?|file|data):|[\/\{])([^"]+)"/is', array($this, '_replacePath'), $content); // replace value of srcset in img/source/link tag $content = preg_replace_callback('/<(?:img|source|link)(?:[^<>]*?)(?(?=cond=")(?:cond="[^"]+"[^<>]*)+|)[^<>]* srcset="([^"]+)"/is', array($this, '_replaceSrcsetPath'), $content); // replace loop and cond template syntax $content = $this->_parseInline($content); // include, unload/load, import $content = preg_replace_callback('/{(@[\s\S]+?|(?=[\$\\\\]\w+|_{1,2}[A-Z]+|[!\(+-]|\w+(?:\(|::)|\d+|[\'"].*?[\'"]).+?)}|<(!--[#%])?(include|import|(un)?load(?(4)|(?:_js_plugin)?)|config)(?(2)\(["\']([^"\']+)["\'])(.*?)(?(2)\)--|\/)>|(\s*)/', array($this, '_parseResource'), $content); // remove block which is a virtual tag $content = preg_replace('@@is', '', $content); // form auto generation $temp = preg_replace_callback('/(|[^<>]+)*?>)(.*?)(<\/form>)/is', array($this, '_compileFormAuthGeneration'), $content); if($temp) { $content = $temp; } // prevent from calling directly before writing into file $content = '' . $content; // restore curly braces from temporary entities $content = self::_replaceTempEntities($content); // remove php script reopening $content = preg_replace_callback('/([;{])?( )*\?\>\<\?php\s/', function($match) { return $match[1] === '{' ? '{ ' : '; '; }, $content); // remove empty lines $content = preg_replace([ '/>\<\?php } \?\>\n[\t\x20]*?(?=\n.*?|{[^}]*}|\"(?>'.*?'|.)*?\"|.)*?>)@s"; $nodes = preg_split($split_regex, $content, -1, PREG_SPLIT_DELIM_CAPTURE) ?: []; for($idx = 1, $node_len = count($nodes); $idx < $node_len; $idx+=2) { if(!($node = $nodes[$idx])) { continue; } if(preg_match_all('@\s(loop|cond)="([^"]+)"@', $node, $matches)) { // this tag $tag = substr($node, 1, strpos($node, ' ') - 1); // if the vale of $closing is 0, it means 'skipping' $closing = 0; // process opening tag foreach($matches[1] as $n => $stmt) { $expr = $matches[2][$n]; $expr = self::_replaceVar($expr); $closing++; switch($stmt) { case 'cond': if (preg_match('/^\$[\\\\\w\[\]\'":>-]+$/i', $expr)) { $expr = "$expr ?? false"; } $nodes[$idx - 1] .= ""; break; case 'loop': if(!preg_match('@^(?:(.+?)=>(.+?)(?:,(.+?))?|(.*?;.*?;.*?)|(.+?)\s*=\s*(.+?))$@', $expr, $expr_m)) { break; } if($expr_m[1]) { $expr_m[1] = trim($expr_m[1]); $expr_m[2] = trim($expr_m[2]); if(isset($expr_m[3]) && $expr_m[3]) { $expr_m[2] .= '=>' . trim($expr_m[3]); } $nodes[$idx - 1] .= sprintf('', $expr_m[1], $expr_m[2]); } elseif(isset($expr_m[4]) && $expr_m[4]) { $nodes[$idx - 1] .= ""; } elseif(isset($expr_m[5]) && $expr_m[5]) { $nodes[$idx - 1] .= ""; } break; } } $node = preg_replace('@\s(loop|cond)="([^"]+)"@', '', $node); // find closing tag $close_php = ''; // self closing tag if($node[1] == '!' || substr($node, -2, 1) == '/' || isset($self_closing[$tag])) { $nodes[$idx + 1] = $close_php . $nodes[$idx + 1]; } else { $depth = 1; for($i = $idx + 2; $i < $node_len; $i+=2) { $nd = $nodes[$i]; if(strpos($nd, $tag) === 1) { $depth++; } elseif(strpos($nd, '/' . $tag) === 1) { $depth--; if(!$depth) { $nodes[$i - 1] .= $nodes[$i] . $close_php; $nodes[$i] = ''; break; } } } } } if(strpos($node, '|cond="') !== false) { $node = preg_replace('@(\s[-\w:]+(?:="[^"]+?")?)\|cond="(.+?)"@s', '$1', $node); $node = self::_replaceVar($node); } if($nodes[$idx] != $node) { $nodes[$idx] = $node; } } $content = implode('', $nodes); return $content; } /** * preg_replace_callback handler * replace php code. * @param array $m * @return string changed result */ private function _parseResource($m) { // {@ ... } or {$var} or {func(...)} if($m[1]) { if(preg_match('@^(\w+)\(@', $m[1], $mm) && (!function_exists($mm[1]) && !in_array($mm[1], ['isset', 'unset', 'empty']))) { return $m[0]; } if($m[1][0] == '@') { $m[1] = self::_replaceVar(substr($m[1], 1)); return ""; } else { // Get escape options. if($m[1] === '$content' && preg_match('@^layouts/.+/layout\.html$@', $this->template->relative_path)) { $escape_option = 'noescape'; } elseif(preg_match('/^\$(?:user_)?lang->[a-zA-Z0-9\_]+$/', $m[1])) { $escape_option = 'noescape'; } elseif(preg_match('/^lang\(.+\)$/', $m[1])) { $escape_option = 'noescape'; } else { $escape_option = $this->autoescape_config_exists ? 'auto' : 'noescape'; } // Separate filters from variable. if (preg_match('@^(.+?)(?_applyEscapeOption($var, $escape_option); $var = "nl2br({$var})"; $escape_option = 'noescape'; break; case 'join': $var = $filter_option ? "implode({$filter_option}, {$var})" : "implode(', ', {$var})"; break; case 'date': $var = $filter_option ? "getDisplayDateTime(ztime({$var}), {$filter_option})" : "getDisplayDateTime(ztime({$var}), 'Y-m-d H:i:s')"; break; case 'format': case 'number_format': $var = $filter_option ? "number_format({$var}, {$filter_option})" : "number_format({$var})"; break; case 'shorten': case 'number_shorten': $var = $filter_option ? "number_shorten({$var}, {$filter_option})" : "number_shorten({$var})"; break; case 'link': $var = $this->_applyEscapeOption($var, $escape_option); if ($filter_option) { $filter_option = $this->_applyEscapeOption($filter_option, $escape_option); $var = "'' . ($var) . ''"; } else { $var = "'' . ($var) . ''"; } $escape_option = 'noescape'; break; default: $filter = escape_sqstr($filter); $var = "'INVALID FILTER ({$filter})'"; } } // Apply the escape option and return. return '_applyEscapeOption($var, $escape_option) . ' ?>'; } } if($m[3]) { $attr = array(); if($m[5]) { if(preg_match_all('@,(\w+)="([^"]+)"@', $m[6], $mm)) { foreach($mm[1] as $idx => $name) { $attr[$name] = $mm[2][$idx]; } } $attr['target'] = $m[5]; } else { if(!preg_match_all('@ (\w+)="([^"]+)"@', $m[6], $mm)) { return $m[0]; } foreach($mm[1] as $idx => $name) { $attr[$name] = $mm[2][$idx]; } } switch($m[3]) { // or case 'include': if(!$this->template->relative_dirname || !$attr['target']) { return ''; } if (preg_match('!^\\^/(.+)!', $attr['target'], $tmatches)) { $pathinfo = pathinfo(\RX_BASEDIR . $tmatches[1]); $fileDir = $pathinfo['dirname']; } else { $pathinfo = pathinfo($attr['target']); $fileDir = $this->_getRelativeDir($pathinfo['dirname']); } if(!$fileDir) { return ''; } return "compile('{$fileDir}','{$pathinfo['basename']}') ?>"; // case 'load_js_plugin': $plugin = self::_replaceVar($m[5]); $s = ""; if(strpos($plugin, '$__Context') === false) { $plugin = "'{$plugin}'"; } $s .= ""; return $s; // or or or case 'import': case 'load': case 'unload': $metafile = ''; $metavars = ''; $replacements = HTMLDisplayHandler::$replacements; $attr['target'] = preg_replace(array_keys($replacements), array_values($replacements), $attr['target']); $pathinfo = pathinfo($attr['target']); $doUnload = ($m[3] === 'unload'); $isRemote = !!preg_match('@^(https?:)?//@i', $attr['target']); if($isRemote) { if (empty($pathinfo['extension'])) { $pathinfo['extension'] = preg_match('/[\.\/](css|js)[0-9]?\b/', $attr['target'], $mx) ? $mx[1] : null; } } else { if (preg_match('!^\\^/(.+)!', $attr['target'], $tmatches)) { $pathinfo = pathinfo($tmatches[1]); $relativeDir = $pathinfo['dirname']; $attr['target'] = $relativeDir . '/' . $pathinfo['basename']; } else { if(!preg_match('@^\.?/@', $attr['target'])) { $attr['target'] = './' . $attr['target']; } $relativeDir = $this->_getRelativeDir($pathinfo['dirname']); $attr['target'] = $relativeDir . '/' . $pathinfo['basename']; } } switch($pathinfo['extension']) { case 'xml': if($isRemote || $doUnload) { return ''; } // language file? if($pathinfo['basename'] == 'lang.xml' || substr($pathinfo['dirname'], -5) == '/lang') { $result = "Context::loadLang('{$relativeDir}');"; } else { $result = "require_once('./classes/xml/XmlJsFilter.class.php');\$__xmlFilter=new XmlJsFilter('{$relativeDir}','{$pathinfo['basename']}');\$__xmlFilter->compile();"; } break; case 'js': if($doUnload) { $result = vsprintf("Context::unloadFile('%s', '');", [$attr['target'] ?? '']); } else { $metafile = isset($attr['target']) ? $attr['target'] : ''; $result = vsprintf("Context::loadFile(['%s', '%s', '%s', '%s']);", [ $attr['target'] ?? '', $attr['type'] ?? '', $isRemote ? $this->source_type : '', $attr['index'] ?? '', ]); } break; case 'css': case 'less': case 'scss': if($doUnload) { $result = vsprintf("Context::unloadFile('%s', '', '%s');", [ $attr['target'] ?? '', $attr['media'] ?? '', ]); } else { $metafile = isset($attr['target']) ? $attr['target'] : ''; $metavars = isset($attr['vars']) ? ($attr['vars'] ? self::_replaceVar($attr['vars']) : '') : ''; $result = vsprintf("Context::loadFile(['%s', '%s', '%s', '%s', %s]);", [ $attr['target'] ?? '', $attr['media'] ?? '', $isRemote ? $this->source_type : '', $attr['index'] ?? '', isset($attr['vars']) ? ($attr['vars'] ? self::_replaceVar($attr['vars']) : '[]') : '[]', ]); } break; } $result = ""; if($metafile) { if(!$metavars) { $result = "" . $result; } else { // LESS or SCSS needs the variables to be substituted. $result = "" . $result; } } return $result; // case 'config': $result = ''; if(preg_match_all('@ (\w+)="([^"]+)"@', $m[6], $config_matches, PREG_SET_ORDER)) { foreach($config_matches as $config_match) { $config_value = toBool(trim(strtolower($config_match[2]))) ? 'true' : 'false'; $result .= "\$this->config->{$config_match[1]} = $config_value;"; } } return ""; } } // such as , , if($m[7]) { $m[7] = substr($m[7], 1); if(!$m[7]) { return '' . $m[9]; } if(!preg_match('/^(?:((?:end)?(?:if|switch|for(?:each)?|while)|end)|(else(?:if)?)|(break@)?(case|default)|(break))$/', $m[7], $mm)) { return ''; } if($mm[1]) { if($mm[1][0] == 'e') { return '' . $m[9]; } $precheck = ''; if($mm[1] == 'switch') { $m[9] = ''; } elseif($mm[1] == 'foreach') { $var = preg_replace('/^\s*\(\s*(.+?) .*$/', '$1', $m[8]); $precheck = "if({$var})"; } return '' . $m[9]; } if($mm[2]) { return "" . $m[9]; } if($mm[4]) { return "" . $m[9]; } if($mm[5]) { return ""; } return ''; } return $m[0]; } /** * Apply escape option to an expression. */ private function _applyEscapeOption($str, $escape_option) { if (preg_match('/^\$[\\\\\w\[\]\'":>-]+$/i', $str)) { $str = preg_match('/^\$(__Context->)?lang->/', $str) ? $str : "$str ?? ''"; } switch($escape_option) { case 'escape': return "htmlspecialchars({$str}, ENT_QUOTES, 'UTF-8', true)"; case 'noescape': return "{$str}"; case 'autoescape': return "htmlspecialchars({$str}, ENT_QUOTES, 'UTF-8', false)"; case 'autolang': return "(preg_match('/^\\$(?:user_)?lang->[a-zA-Z0-9\_]+$/', {$str}) ? ({$str}) : htmlspecialchars({$str}, ENT_QUOTES, 'UTF-8', false))"; case 'auto': default: return "(\$this->config->autoescape ? htmlspecialchars({$str}, ENT_QUOTES, 'UTF-8', false) : ({$str}))"; } } /** * change relative path * @param string $path * @return string */ private function _getRelativeDir($path) { $_path = $path; $fileDir = $this->template->absolute_dirname; if($path[0] != '/') { $path = strtr(realpath($fileDir . '/' . $path), '\\', '/'); } // for backward compatibility if(!$path) { $dirs = explode('/', $fileDir); $paths = explode('/', $_path); $idx = array_search($paths[0], $dirs); if($idx !== false) { while($dirs[$idx] && $dirs[$idx] === $paths[0]) { array_splice($dirs, $idx, 1); array_shift($paths); } $path = strtr(realpath($fileDir . '/' . implode('/', $paths)), '\\', '/'); } } $path = preg_replace('/^' . preg_quote(\RX_BASEDIR, '/') . '/', '', $path); return $path; } /** * Check if a string seems to contain a variable. * * @param string $str * @return bool */ private static function _isVar($str) { return preg_match('@(?\$([a-z_][a-z0-9_]*)@i', function($matches) { return '->' . self::_getTempEntityForChar('{') . '$__Context->' . $matches[1] . self::_getTempEntityForChar('}'); }, $php); // Replace all other variables with Context attributes. $php = preg_replace_callback('@(?|(?' . $matches[1]; } }, $php); return $php; } /** * Replace temporary entities to curly braces. * * @param string $str * @return string */ private static function _replaceTempEntities($str) { return strtr($str, [ '{' => '{', '}' => '}', ]); } /** * Get the temporary entity for a character. * * @param string $char * @return string */ private static function _getTempEntityForChar($char) { return '&#x' . strtoupper(bin2hex($char)) . ';'; } }