forked from spip/medias
Browse Source
- on reprend la lib svg-sanitizer https://github.com/darylldoyle/svg-sanitizer utilisee sur le plugin logo-svg https://github.com/cariagency/spip-logo-svg - on sanitize systematiquement, que l'utilisateur soit admin ou non, car il upload une image sans forcement etre conscient que ca peut contenir des scripts (merci Maieul)issue_4494

14 changed files with 4064 additions and 13 deletions
@ -0,0 +1,340 @@
|
||||
GNU GENERAL PUBLIC LICENSE |
||||
Version 2, June 1991 |
||||
|
||||
Copyright (C) 1989, 1991 Free Software Foundation, Inc., <http://fsf.org/> |
||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
||||
Everyone is permitted to copy and distribute verbatim copies |
||||
of this license document, but changing it is not allowed. |
||||
|
||||
Preamble |
||||
|
||||
The licenses for most software are designed to take away your |
||||
freedom to share and change it. By contrast, the GNU General Public |
||||
License is intended to guarantee your freedom to share and change free |
||||
software--to make sure the software is free for all its users. This |
||||
General Public License applies to most of the Free Software |
||||
Foundation's software and to any other program whose authors commit to |
||||
using it. (Some other Free Software Foundation software is covered by |
||||
the GNU Lesser General Public License instead.) You can apply it to |
||||
your programs, too. |
||||
|
||||
When we speak of free software, we are referring to freedom, not |
||||
price. Our General Public Licenses are designed to make sure that you |
||||
have the freedom to distribute copies of free software (and charge for |
||||
this service if you wish), that you receive source code or can get it |
||||
if you want it, that you can change the software or use pieces of it |
||||
in new free programs; and that you know you can do these things. |
||||
|
||||
To protect your rights, we need to make restrictions that forbid |
||||
anyone to deny you these rights or to ask you to surrender the rights. |
||||
These restrictions translate to certain responsibilities for you if you |
||||
distribute copies of the software, or if you modify it. |
||||
|
||||
For example, if you distribute copies of such a program, whether |
||||
gratis or for a fee, you must give the recipients all the rights that |
||||
you have. You must make sure that they, too, receive or can get the |
||||
source code. And you must show them these terms so they know their |
||||
rights. |
||||
|
||||
We protect your rights with two steps: (1) copyright the software, and |
||||
(2) offer you this license which gives you legal permission to copy, |
||||
distribute and/or modify the software. |
||||
|
||||
Also, for each author's protection and ours, we want to make certain |
||||
that everyone understands that there is no warranty for this free |
||||
software. If the software is modified by someone else and passed on, we |
||||
want its recipients to know that what they have is not the original, so |
||||
that any problems introduced by others will not reflect on the original |
||||
authors' reputations. |
||||
|
||||
Finally, any free program is threatened constantly by software |
||||
patents. We wish to avoid the danger that redistributors of a free |
||||
program will individually obtain patent licenses, in effect making the |
||||
program proprietary. To prevent this, we have made it clear that any |
||||
patent must be licensed for everyone's free use or not licensed at all. |
||||
|
||||
The precise terms and conditions for copying, distribution and |
||||
modification follow. |
||||
|
||||
GNU GENERAL PUBLIC LICENSE |
||||
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION |
||||
|
||||
0. This License applies to any program or other work which contains |
||||
a notice placed by the copyright holder saying it may be distributed |
||||
under the terms of this General Public License. The "Program", below, |
||||
refers to any such program or work, and a "work based on the Program" |
||||
means either the Program or any derivative work under copyright law: |
||||
that is to say, a work containing the Program or a portion of it, |
||||
either verbatim or with modifications and/or translated into another |
||||
language. (Hereinafter, translation is included without limitation in |
||||
the term "modification".) Each licensee is addressed as "you". |
||||
|
||||
Activities other than copying, distribution and modification are not |
||||
covered by this License; they are outside its scope. The act of |
||||
running the Program is not restricted, and the output from the Program |
||||
is covered only if its contents constitute a work based on the |
||||
Program (independent of having been made by running the Program). |
||||
Whether that is true depends on what the Program does. |
||||
|
||||
1. You may copy and distribute verbatim copies of the Program's |
||||
source code as you receive it, in any medium, provided that you |
||||
conspicuously and appropriately publish on each copy an appropriate |
||||
copyright notice and disclaimer of warranty; keep intact all the |
||||
notices that refer to this License and to the absence of any warranty; |
||||
and give any other recipients of the Program a copy of this License |
||||
along with the Program. |
||||
|
||||
You may charge a fee for the physical act of transferring a copy, and |
||||
you may at your option offer warranty protection in exchange for a fee. |
||||
|
||||
2. You may modify your copy or copies of the Program or any portion |
||||
of it, thus forming a work based on the Program, and copy and |
||||
distribute such modifications or work under the terms of Section 1 |
||||
above, provided that you also meet all of these conditions: |
||||
|
||||
a) You must cause the modified files to carry prominent notices |
||||
stating that you changed the files and the date of any change. |
||||
|
||||
b) You must cause any work that you distribute or publish, that in |
||||
whole or in part contains or is derived from the Program or any |
||||
part thereof, to be licensed as a whole at no charge to all third |
||||
parties under the terms of this License. |
||||
|
||||
c) If the modified program normally reads commands interactively |
||||
when run, you must cause it, when started running for such |
||||
interactive use in the most ordinary way, to print or display an |
||||
announcement including an appropriate copyright notice and a |
||||
notice that there is no warranty (or else, saying that you provide |
||||
a warranty) and that users may redistribute the program under |
||||
these conditions, and telling the user how to view a copy of this |
||||
License. (Exception: if the Program itself is interactive but |
||||
does not normally print such an announcement, your work based on |
||||
the Program is not required to print an announcement.) |
||||
|
||||
These requirements apply to the modified work as a whole. If |
||||
identifiable sections of that work are not derived from the Program, |
||||
and can be reasonably considered independent and separate works in |
||||
themselves, then this License, and its terms, do not apply to those |
||||
sections when you distribute them as separate works. But when you |
||||
distribute the same sections as part of a whole which is a work based |
||||
on the Program, the distribution of the whole must be on the terms of |
||||
this License, whose permissions for other licensees extend to the |
||||
entire whole, and thus to each and every part regardless of who wrote it. |
||||
|
||||
Thus, it is not the intent of this section to claim rights or contest |
||||
your rights to work written entirely by you; rather, the intent is to |
||||
exercise the right to control the distribution of derivative or |
||||
collective works based on the Program. |
||||
|
||||
In addition, mere aggregation of another work not based on the Program |
||||
with the Program (or with a work based on the Program) on a volume of |
||||
a storage or distribution medium does not bring the other work under |
||||
the scope of this License. |
||||
|
||||
3. You may copy and distribute the Program (or a work based on it, |
||||
under Section 2) in object code or executable form under the terms of |
||||
Sections 1 and 2 above provided that you also do one of the following: |
||||
|
||||
a) Accompany it with the complete corresponding machine-readable |
||||
source code, which must be distributed under the terms of Sections |
||||
1 and 2 above on a medium customarily used for software interchange; or, |
||||
|
||||
b) Accompany it with a written offer, valid for at least three |
||||
years, to give any third party, for a charge no more than your |
||||
cost of physically performing source distribution, a complete |
||||
machine-readable copy of the corresponding source code, to be |
||||
distributed under the terms of Sections 1 and 2 above on a medium |
||||
customarily used for software interchange; or, |
||||
|
||||
c) Accompany it with the information you received as to the offer |
||||
to distribute corresponding source code. (This alternative is |
||||
allowed only for noncommercial distribution and only if you |
||||
received the program in object code or executable form with such |
||||
an offer, in accord with Subsection b above.) |
||||
|
||||
The source code for a work means the preferred form of the work for |
||||
making modifications to it. For an executable work, complete source |
||||
code means all the source code for all modules it contains, plus any |
||||
associated interface definition files, plus the scripts used to |
||||
control compilation and installation of the executable. However, as a |
||||
special exception, the source code distributed need not include |
||||
anything that is normally distributed (in either source or binary |
||||
form) with the major components (compiler, kernel, and so on) of the |
||||
operating system on which the executable runs, unless that component |
||||
itself accompanies the executable. |
||||
|
||||
If distribution of executable or object code is made by offering |
||||
access to copy from a designated place, then offering equivalent |
||||
access to copy the source code from the same place counts as |
||||
distribution of the source code, even though third parties are not |
||||
compelled to copy the source along with the object code. |
||||
|
||||
4. You may not copy, modify, sublicense, or distribute the Program |
||||
except as expressly provided under this License. Any attempt |
||||
otherwise to copy, modify, sublicense or distribute the Program is |
||||
void, and will automatically terminate your rights under this License. |
||||
However, parties who have received copies, or rights, from you under |
||||
this License will not have their licenses terminated so long as such |
||||
parties remain in full compliance. |
||||
|
||||
5. You are not required to accept this License, since you have not |
||||
signed it. However, nothing else grants you permission to modify or |
||||
distribute the Program or its derivative works. These actions are |
||||
prohibited by law if you do not accept this License. Therefore, by |
||||
modifying or distributing the Program (or any work based on the |
||||
Program), you indicate your acceptance of this License to do so, and |
||||
all its terms and conditions for copying, distributing or modifying |
||||
the Program or works based on it. |
||||
|
||||
6. Each time you redistribute the Program (or any work based on the |
||||
Program), the recipient automatically receives a license from the |
||||
original licensor to copy, distribute or modify the Program subject to |
||||
these terms and conditions. You may not impose any further |
||||
restrictions on the recipients' exercise of the rights granted herein. |
||||
You are not responsible for enforcing compliance by third parties to |
||||
this License. |
||||
|
||||
7. If, as a consequence of a court judgment or allegation of patent |
||||
infringement or for any other reason (not limited to patent issues), |
||||
conditions are imposed on you (whether by court order, agreement or |
||||
otherwise) that contradict the conditions of this License, they do not |
||||
excuse you from the conditions of this License. If you cannot |
||||
distribute so as to satisfy simultaneously your obligations under this |
||||
License and any other pertinent obligations, then as a consequence you |
||||
may not distribute the Program at all. For example, if a patent |
||||
license would not permit royalty-free redistribution of the Program by |
||||
all those who receive copies directly or indirectly through you, then |
||||
the only way you could satisfy both it and this License would be to |
||||
refrain entirely from distribution of the Program. |
||||
|
||||
If any portion of this section is held invalid or unenforceable under |
||||
any particular circumstance, the balance of the section is intended to |
||||
apply and the section as a whole is intended to apply in other |
||||
circumstances. |
||||
|
||||
It is not the purpose of this section to induce you to infringe any |
||||
patents or other property right claims or to contest validity of any |
||||
such claims; this section has the sole purpose of protecting the |
||||
integrity of the free software distribution system, which is |
||||
implemented by public license practices. Many people have made |
||||
generous contributions to the wide range of software distributed |
||||
through that system in reliance on consistent application of that |
||||
system; it is up to the author/donor to decide if he or she is willing |
||||
to distribute software through any other system and a licensee cannot |
||||
impose that choice. |
||||
|
||||
This section is intended to make thoroughly clear what is believed to |
||||
be a consequence of the rest of this License. |
||||
|
||||
8. If the distribution and/or use of the Program is restricted in |
||||
certain countries either by patents or by copyrighted interfaces, the |
||||
original copyright holder who places the Program under this License |
||||
may add an explicit geographical distribution limitation excluding |
||||
those countries, so that distribution is permitted only in or among |
||||
countries not thus excluded. In such case, this License incorporates |
||||
the limitation as if written in the body of this License. |
||||
|
||||
9. The Free Software Foundation may publish revised and/or new versions |
||||
of the General Public License from time to time. Such new versions will |
||||
be similar in spirit to the present version, but may differ in detail to |
||||
address new problems or concerns. |
||||
|
||||
Each version is given a distinguishing version number. If the Program |
||||
specifies a version number of this License which applies to it and "any |
||||
later version", you have the option of following the terms and conditions |
||||
either of that version or of any later version published by the Free |
||||
Software Foundation. If the Program does not specify a version number of |
||||
this License, you may choose any version ever published by the Free Software |
||||
Foundation. |
||||
|
||||
10. If you wish to incorporate parts of the Program into other free |
||||
programs whose distribution conditions are different, write to the author |
||||
to ask for permission. For software which is copyrighted by the Free |
||||
Software Foundation, write to the Free Software Foundation; we sometimes |
||||
make exceptions for this. Our decision will be guided by the two goals |
||||
of preserving the free status of all derivatives of our free software and |
||||
of promoting the sharing and reuse of software generally. |
||||
|
||||
NO WARRANTY |
||||
|
||||
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY |
||||
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN |
||||
OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES |
||||
PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED |
||||
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF |
||||
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS |
||||
TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE |
||||
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, |
||||
REPAIR OR CORRECTION. |
||||
|
||||
12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING |
||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR |
||||
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, |
||||
INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING |
||||
OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED |
||||
TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY |
||||
YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER |
||||
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE |
||||
POSSIBILITY OF SUCH DAMAGES. |
||||
|
||||
END OF TERMS AND CONDITIONS |
||||
|
||||
How to Apply These Terms to Your New Programs |
||||
|
||||
If you develop a new program, and you want it to be of the greatest |
||||
possible use to the public, the best way to achieve this is to make it |
||||
free software which everyone can redistribute and change under these terms. |
||||
|
||||
To do so, attach the following notices to the program. It is safest |
||||
to attach them to the start of each source file to most effectively |
||||
convey the exclusion of warranty; and each file should have at least |
||||
the "copyright" line and a pointer to where the full notice is found. |
||||
|
||||
{description} |
||||
Copyright (C) {year} {fullname} |
||||
|
||||
This program is free software; you can redistribute it and/or modify |
||||
it under the terms of the GNU General Public License as published by |
||||
the Free Software Foundation; either version 2 of the License, or |
||||
(at your option) any later version. |
||||
|
||||
This program is distributed in the hope that it will be useful, |
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of |
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||||
GNU General Public License for more details. |
||||
|
||||
You should have received a copy of the GNU General Public License along |
||||
with this program; if not, write to the Free Software Foundation, Inc., |
||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. |
||||
|
||||
Also add information on how to contact you by electronic and paper mail. |
||||
|
||||
If the program is interactive, make it output a short notice like this |
||||
when it starts in an interactive mode: |
||||
|
||||
Gnomovision version 69, Copyright (C) year name of author |
||||
Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'. |
||||
This is free software, and you are welcome to redistribute it |
||||
under certain conditions; type `show c' for details. |
||||
|
||||
The hypothetical commands `show w' and `show c' should show the appropriate |
||||
parts of the General Public License. Of course, the commands you use may |
||||
be called something other than `show w' and `show c'; they could even be |
||||
mouse-clicks or menu items--whatever suits your program. |
||||
|
||||
You should also get your employer (if you work as a programmer) or your |
||||
school, if any, to sign a "copyright disclaimer" for the program, if |
||||
necessary. Here is a sample; alter the names: |
||||
|
||||
Yoyodyne, Inc., hereby disclaims all copyright interest in the program |
||||
`Gnomovision' (which makes passes at compilers) written by James Hacker. |
||||
|
||||
{signature of Ty Coon}, 1 April 1989 |
||||
Ty Coon, President of Vice |
||||
|
||||
This General Public License does not permit incorporating your program into |
||||
proprietary programs. If your program is a subroutine library, you may |
||||
consider it more useful to permit linking proprietary applications with the |
||||
library. If this is what you want to do, use the GNU Lesser General |
||||
Public License instead of this License. |
||||
|
@ -0,0 +1,88 @@
|
||||
# svg-sanitizer |
||||
|
||||
[](https://travis-ci.org/darylldoyle/svg-sanitizer) [](https://codeclimate.com/github/darylldoyle/svg-sanitizer/coverage) |
||||
|
||||
This is my attempt at building a decent SVG sanitizer in PHP. The work is laregely borrowed from [DOMPurify](https://github.com/cure53/DOMPurify). |
||||
|
||||
## Installation |
||||
|
||||
Either require `enshrined/svg-sanitize` through composer or download the repo and include the old way! |
||||
|
||||
## Usage |
||||
|
||||
Using this is fairly easy. Create a new instance of `enshrined\svgSanitize\Sanitizer` and then call the `sanitize` whilst passing in your dirty SVG/XML |
||||
|
||||
**Basic Example** |
||||
|
||||
```php |
||||
use enshrined\svgSanitize\Sanitizer; |
||||
|
||||
// Create a new sanitizer instance |
||||
$sanitizer = new Sanitizer(); |
||||
|
||||
// Load the dirty svg |
||||
$dirtySVG = file_get_contents('filthy.svg'); |
||||
|
||||
// Pass it to the sanitizer and get it back clean |
||||
$cleanSVG = $sanitizer->sanitize($dirtySVG); |
||||
|
||||
// Now do what you want with your clean SVG/XML data |
||||
|
||||
``` |
||||
|
||||
## Output |
||||
|
||||
This will either return a sanitized SVG/XML string or boolean `false` if XML parsing failed (usually due to a badly formatted file). |
||||
|
||||
## Options |
||||
|
||||
You may pass your own whitelist of tags and attributes by using the `Sanitizer::setAllowedTags` and `Sanitizer::setAllowedAttrs` methods respectively. |
||||
|
||||
These methods require that you implement the `enshrined\svgSanitize\data\TagInterface` or `enshrined\svgSanitize\data\AttributeInterface`. |
||||
|
||||
## Remove remote references |
||||
|
||||
You have the option to remove attributes that reference remote files, this will stop HTTP leaks but will add an overhead to the sanitiser. |
||||
|
||||
This defaults to false, set to true to remove references. |
||||
|
||||
`$sanitizer->removeRemoteReferences(true);` |
||||
|
||||
## Viewing Sanitisation Issues |
||||
|
||||
You may use the `getXmlIssues()` method to return an array of issues that occurred during sanitisation. |
||||
|
||||
This may be useful for logging or providing feedback to the user on why an SVG was refused. |
||||
|
||||
`$issues = $sanitizer->getXmlIssues();` |
||||
|
||||
## Minification |
||||
|
||||
You can minify the XML output by calling `$sanitiser->minify(true);`. |
||||
|
||||
## Demo |
||||
There is a demo available at: [http://svg.enshrined.co.uk/](http://svg.enshrined.co.uk/) |
||||
|
||||
## WordPress |
||||
|
||||
I've just released a WordPress plugin containing this code so you can sanitize your WordPress uploads. It's available from the WordPress plugin directory: [https://wordpress.org/plugins/safe-svg/](https://wordpress.org/plugins/safe-svg/) |
||||
|
||||
## Drupal |
||||
|
||||
[Michael Potter](https://github.com/heyMP) has kindly created a Drupal module for this library which is available at: [https://www.drupal.org/project/svg_sanitizer](https://www.drupal.org/project/svg_sanitizer) |
||||
|
||||
## Tests |
||||
|
||||
You can run these by running `phpunit` |
||||
|
||||
## Standalone scanning of files via CLI |
||||
|
||||
Thanks to the work by [gudmdharalds](https://github.com/gudmdharalds) there's now a standalone scanner that can be used via the CLI. |
||||
|
||||
Any errors will be output in JSON format. See [the PR](https://github.com/darylldoyle/svg-sanitizer/pull/25) for an example. |
||||
|
||||
Use it as follows: `php svg-scanner.php ~/svgs/myfile.svg` |
||||
|
||||
## To-Do |
||||
|
||||
More extensive testing for the SVGs/XML would be lovely, I'll try and add these soon. If you feel like doing it for me, please do and make a PR! |
@ -0,0 +1,22 @@
|
||||
{ |
||||
"name": "enshrined/svg-sanitize", |
||||
"description": "An SVG sanitizer for PHP", |
||||
"license": "GPL-2.0+", |
||||
"authors": [ |
||||
{ |
||||
"name": "Daryll Doyle", |
||||
"email": "daryll@enshrined.co.uk" |
||||
} |
||||
], |
||||
"autoload": { |
||||
"psr-4": { |
||||
"enshrined\\svgSanitize\\": "src" |
||||
} |
||||
}, |
||||
"minimum-stability": "stable", |
||||
"require": {}, |
||||
"require-dev": { |
||||
"phpunit/phpunit": "^6", |
||||
"codeclimate/php-test-reporter": "^0.1.2" |
||||
} |
||||
} |
File diff suppressed because it is too large
Load Diff
@ -0,0 +1,23 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?> |
||||
<phpunit bootstrap="vendor/autoload.php" |
||||
colors="true" |
||||
stopOnFailure="false" |
||||
syntaxCheck="false"> |
||||
|
||||
<testsuites> |
||||
<testsuite name="The project's test suite"> |
||||
<directory>./tests</directory> |
||||
</testsuite> |
||||
</testsuites> |
||||
|
||||
<logging> |
||||
<log type="coverage-clover" target="./build/logs/clover.xml"/> |
||||
</logging> |
||||
|
||||
<filter> |
||||
<whitelist processUncoveredFilesFromWhitelist="true"> |
||||
<directory suffix=".php">./src</directory> |
||||
</whitelist> |
||||
</filter> |
||||
|
||||
</phpunit> |
@ -0,0 +1,473 @@
|
||||
<?php |
||||
|
||||
namespace enshrined\svgSanitize; |
||||
|
||||
use DOMDocument; |
||||
use enshrined\svgSanitize\data\AllowedAttributes; |
||||
use enshrined\svgSanitize\data\AllowedTags; |
||||
use enshrined\svgSanitize\data\AttributeInterface; |
||||
use enshrined\svgSanitize\data\TagInterface; |
||||
|
||||
/** |
||||
* Class Sanitizer |
||||
* |
||||
* @package enshrined\svgSanitize |
||||
*/ |
||||
class Sanitizer |
||||
{ |
||||
|
||||
/** |
||||
* Regex to catch script and data values in attributes |
||||
*/ |
||||
const SCRIPT_REGEX = '/(?:\w+script|data):/xi'; |
||||
|
||||
/** |
||||
* @var DOMDocument |
||||
*/ |
||||
protected $xmlDocument; |
||||
|
||||
/** |
||||
* @var array |
||||
*/ |
||||
protected $allowedTags; |
||||
|
||||
/** |
||||
* @var array |
||||
*/ |
||||
protected $allowedAttrs; |
||||
|
||||
/** |
||||
* @var |
||||
*/ |
||||
protected $xmlLoaderValue; |
||||
|
||||
/** |
||||
* @var bool |
||||
*/ |
||||
protected $minifyXML = false; |
||||
|
||||
/** |
||||
* @var bool |
||||
*/ |
||||
protected $removeRemoteReferences = false; |
||||
|
||||
/** |
||||
* @var bool |
||||
*/ |
||||
protected $removeXMLTag = false; |
||||
|
||||
/** |
||||
* @var int |
||||
*/ |
||||
protected $xmlOptions = LIBXML_NOEMPTYTAG; |
||||
|
||||
/** |
||||
* @var array |
||||
*/ |
||||
protected $xmlIssues = array(); |
||||
|
||||
/** |
||||
* |
||||
*/ |
||||
function __construct() |
||||
{ |
||||
// Load default tags/attributes |
||||
$this->allowedAttrs = array_map('strtolower', AllowedAttributes::getAttributes()); |
||||
$this->allowedTags = array_map('strtolower', AllowedTags::getTags()); |
||||
} |
||||
|
||||
/** |
||||
* Set up the DOMDocument |
||||
*/ |
||||
protected function resetInternal() |
||||
{ |
||||
$this->xmlDocument = new DOMDocument(); |
||||
$this->xmlDocument->preserveWhiteSpace = false; |
||||
$this->xmlDocument->strictErrorChecking = false; |
||||
$this->xmlDocument->formatOutput = !$this->minifyXML; |
||||
} |
||||
|
||||
/** |
||||
* Set XML options to use when saving XML |
||||
* See: DOMDocument::saveXML |
||||
* |
||||
* @param int $xmlOptions |
||||
*/ |
||||
public function setXMLOptions($xmlOptions) |
||||
{ |
||||
$this->xmlOptions = $xmlOptions; |
||||
} |
||||
|
||||
/** |
||||
* Get XML options to use when saving XML |
||||
* See: DOMDocument::saveXML |
||||
* |
||||
* @return int |
||||
*/ |
||||
public function getXMLOptions() |
||||
{ |
||||
return $this->xmlOptions; |
||||
} |
||||
|
||||
/** |
||||
* Get the array of allowed tags |
||||
* |
||||
* @return array |
||||
*/ |
||||
public function getAllowedTags() |
||||
{ |
||||
return $this->allowedTags; |
||||
} |
||||
|
||||
/** |
||||
* Set custom allowed tags |
||||
* |
||||
* @param TagInterface $allowedTags |
||||
*/ |
||||
public function setAllowedTags(TagInterface $allowedTags) |
||||
{ |
||||
$this->allowedTags = array_map('strtolower', $allowedTags::getTags()); |
||||
} |
||||
|
||||
/** |
||||
* Get the array of allowed attributes |
||||
* |
||||
* @return array |
||||
*/ |
||||
public function getAllowedAttrs() |
||||
{ |
||||
return $this->allowedAttrs; |
||||
} |
||||
|
||||
/** |
||||
* Set custom allowed attributes |
||||
* |
||||
* @param AttributeInterface $allowedAttrs |
||||
*/ |
||||
public function setAllowedAttrs(AttributeInterface $allowedAttrs) |
||||
{ |
||||
$this->allowedAttrs = array_map('strtolower', $allowedAttrs::getAttributes()); |
||||
} |
||||
|
||||
/** |
||||
* Should we remove references to remote files? |
||||
* |
||||
* @param bool $removeRemoteRefs |
||||
*/ |
||||
public function removeRemoteReferences($removeRemoteRefs = false) |
||||
{ |
||||
$this->removeRemoteReferences = $removeRemoteRefs; |
||||
} |
||||
|
||||
/** |
||||
* Get XML issues. |
||||
* |
||||
* @return array |
||||
*/ |
||||
public function getXmlIssues() { |
||||
return $this->xmlIssues; |
||||
} |
||||
|
||||
|
||||
/** |
||||
* Sanitize the passed string |
||||
* |
||||
* @param string $dirty |
||||
* @return string |
||||
*/ |
||||
public function sanitize($dirty) |
||||
{ |
||||
// Don't run on an empty string |
||||
if (empty($dirty)) { |
||||
return ''; |
||||
} |
||||
|
||||
// Strip php tags |
||||
$dirty = preg_replace('/<\?(=|php)(.+?)\?>/i', '', $dirty); |
||||
|
||||
$this->resetInternal(); |
||||
$this->setUpBefore(); |
||||
|
||||
$loaded = $this->xmlDocument->loadXML($dirty); |
||||
|
||||
// If we couldn't parse the XML then we go no further. Reset and return false |
||||
if (!$loaded) { |
||||
$this->resetAfter(); |
||||
return false; |
||||
} |
||||
|
||||
$this->removeDoctype(); |
||||
|
||||
// Grab all the elements |
||||
$allElements = $this->xmlDocument->getElementsByTagName("*"); |
||||
|
||||
// Start the cleaning proccess |
||||
$this->startClean($allElements); |
||||
|
||||
// Save cleaned XML to a variable |
||||
if ($this->removeXMLTag) { |
||||
$clean = $this->xmlDocument->saveXML($this->xmlDocument->documentElement, $this->xmlOptions); |
||||
} else { |
||||
$clean = $this->xmlDocument->saveXML($this->xmlDocument, $this->xmlOptions); |
||||
} |
||||
|
||||
$this->resetAfter(); |
||||
|
||||
// Remove any extra whitespaces when minifying |
||||
if ($this->minifyXML) { |
||||
$clean = preg_replace('/\s+/', ' ', $clean); |
||||
} |
||||
|
||||
// Return result |
||||
return $clean; |
||||
} |
||||
|
||||
/** |
||||
* Set up libXML before we start |
||||
*/ |
||||
protected function setUpBefore() |
||||
{ |
||||
// Turn off the entity loader |
||||
$this->xmlLoaderValue = libxml_disable_entity_loader(true); |
||||
|
||||
// Suppress the errors because we don't really have to worry about formation before cleansing |
||||
libxml_use_internal_errors(true); |
||||
|
||||
// Reset array of altered XML |
||||
$this->xmlIssues = array(); |
||||
} |
||||
|
||||
/** |
||||
* Reset the class after use |
||||
*/ |
||||
protected function resetAfter() |
||||
{ |
||||
// Reset the entity loader |
||||
libxml_disable_entity_loader($this->xmlLoaderValue); |
||||
} |
||||
|
||||
/** |
||||
* Remove the XML Doctype |
||||
* It may be caught later on output but that seems to be buggy, so we need to make sure it's gone |
||||
*/ |
||||
protected function removeDoctype() |
||||
{ |
||||
foreach ($this->xmlDocument->childNodes as $child) { |
||||
if ($child->nodeType === XML_DOCUMENT_TYPE_NODE) { |
||||
$child->parentNode->removeChild($child); |
||||
} |
||||
} |
||||
} |
||||
|
||||
/** |
||||
* Start the cleaning with tags, then we move onto attributes and hrefs later |
||||
* |
||||
* @param \DOMNodeList $elements |
||||
*/ |
||||
protected function startClean(\DOMNodeList $elements) |
||||
{ |
||||
// loop through all elements |
||||
// we do this backwards so we don't skip anything if we delete a node |
||||
// see comments at: http://php.net/manual/en/class.domnamednodemap.php |
||||
for ($i = $elements->length - 1; $i >= 0; $i--) { |
||||
$currentElement = $elements->item($i); |
||||
|
||||
// If the tag isn't in the whitelist, remove it and continue with next iteration |
||||
if (!in_array(strtolower($currentElement->tagName), $this->allowedTags)) { |
||||
$currentElement->parentNode->removeChild($currentElement); |
||||
$this->xmlIssues[] = array( |
||||
'message' => 'Suspicious tag \'' . $currentElement->tagName . '\'', |
||||
'line' => $currentElement->getLineNo(), |
||||
); |
||||
continue; |
||||
} |
||||
|
||||
$this->cleanAttributesOnWhitelist($currentElement); |
||||
|
||||
$this->cleanXlinkHrefs($currentElement); |
||||
|
||||
$this->cleanHrefs($currentElement); |
||||
|
||||
if (strtolower($currentElement->tagName) === 'use') { |
||||
if ($this->isUseTagDirty($currentElement)) { |
||||
$currentElement->parentNode->removeChild($currentElement); |
||||
$this->xmlIssues[] = array( |
||||
'message' => 'Suspicious \'' . $currentElement->tagName . '\'', |
||||
'line' => $currentElement->getLineNo(), |
||||
); |
||||
continue; |
||||
} |
||||
} |
||||
} |
||||
} |
||||
|
||||
/** |
||||
* Only allow attributes that are on the whitelist |
||||
* |
||||
* @param \DOMElement $element |
||||
*/ |
||||
protected function cleanAttributesOnWhitelist(\DOMElement $element) |
||||
{ |
||||
for ($x = $element->attributes->length - 1; $x >= 0; $x--) { |
||||
// get attribute name |
||||
$attrName = $element->attributes->item($x)->name; |
||||
|
||||
// Remove attribute if not in whitelist |
||||
if (!in_array(strtolower($attrName), $this->allowedAttrs) && !$this->isAriaAttribute(strtolower($attrName)) && !$this->isDataAttribute(strtolower($attrName))) { |
||||
|
||||
$element->removeAttribute($attrName); |
||||
$this->xmlIssues[] = array( |
||||
'message' => 'Suspicious attribute \'' . $attrName . '\'', |
||||
'line' => $element->getLineNo(), |
||||
); |
||||
} |
||||
|
||||
// Do we want to strip remote references? |
||||
if($this->removeRemoteReferences) { |
||||
// Remove attribute if it has a remote reference |
||||
if (isset($element->attributes->item($x)->value) && $this->hasRemoteReference($element->attributes->item($x)->value)) { |
||||
$element->removeAttribute($attrName); |
||||
$this->xmlIssues[] = array( |
||||
'message' => 'Suspicious attribute \'' . $attrName . '\'', |
||||
'line' => $element->getLineNo(), |
||||
); |
||||
} |
||||
} |
||||
} |
||||
} |
||||
|
||||
/** |
||||
* Clean the xlink:hrefs of script and data embeds |
||||
* |
||||
* @param \DOMElement $element |
||||
*/ |
||||
protected function cleanXlinkHrefs(\DOMElement $element) |
||||
{ |
||||
$xlinks = $element->getAttributeNS('http://www.w3.org/1999/xlink', 'href'); |
||||
if (preg_match(self::SCRIPT_REGEX, $xlinks) === 1) { |
||||
if (!in_array(substr($xlinks, 0, 14), array( |
||||
'data:image/png', // PNG |
||||
'data:image/gif', // GIF |
||||
'data:image/jpg', // JPG |
||||
'data:image/jpe', // JPEG |
||||
'data:image/pjp', // PJPEG |
||||
))) { |
||||
$element->removeAttributeNS( 'http://www.w3.org/1999/xlink', 'href' ); |
||||
$this->xmlIssues[] = array( |
||||
'message' => 'Suspicious attribute \'href\'', |
||||
'line' => $element->getLineNo(), |
||||
); |
||||
|
||||
|
||||
} |
||||
} |
||||
} |
||||
|
||||
/** |
||||
* Clean the hrefs of script and data embeds |
||||
* |
||||
* @param \DOMElement $element |
||||
*/ |
||||
protected function cleanHrefs(\DOMElement $element) |
||||
{ |
||||
$href = $element->getAttribute('href'); |
||||
if (preg_match(self::SCRIPT_REGEX, $href) === 1) { |
||||
$element->removeAttribute('href'); |
||||
$this->xmlIssues[] = array( |
||||
'message' => 'Suspicious attribute \'href\'', |
||||
'line' => $element->getLineNo(), |
||||
); |
||||
} |
||||
} |
||||
|
||||
/** |
||||
* Removes non-printable ASCII characters from string & trims it |
||||
* |
||||
* @param string $value |
||||
* @return bool |
||||
*/ |
||||
protected function removeNonPrintableCharacters($value) |
||||
{ |
||||
return trim(preg_replace('/[^ -~]/xu','',$value)); |
||||
} |
||||
|
||||
/** |
||||
* Does this attribute value have a remote reference? |
||||
* |
||||
* @param $value |
||||
* @return bool |
||||
*/ |
||||
protected function hasRemoteReference($value) |
||||
{ |
||||
$value = $this->removeNonPrintableCharacters($value); |
||||
|
||||
$wrapped_in_url = preg_match('~^url\(\s*[\'"]\s*(.*)\s*[\'"]\s*\)$~xi', $value, $match); |
||||
if (!$wrapped_in_url){ |
||||
return false; |
||||
} |
||||
|
||||
$value = trim($match[1], '\'"'); |
||||
|
||||
return preg_match('~^((https?|ftp|file):)?//~xi', $value); |
||||
} |
||||
|
||||
/** |
||||
* Should we minify the output? |
||||
* |
||||
* @param bool $shouldMinify |
||||
*/ |
||||
public function minify($shouldMinify = false) |
||||
{ |
||||
$this->minifyXML = (bool) $shouldMinify; |
||||
} |
||||
|
||||
/** |
||||
* Should we remove the XML tag in the header? |
||||
* |
||||
* @param bool $removeXMLTag |
||||
*/ |
||||
public function removeXMLTag($removeXMLTag = false) |
||||
{ |
||||
$this->removeXMLTag = (bool) $removeXMLTag; |
||||
} |
||||
|
||||
/** |
||||
* Check to see if an attribute is an aria attribute or not |
||||
* |
||||
* @param $attributeName |
||||
* |
||||
* @return bool |
||||
*/ |
||||
protected function isAriaAttribute($attributeName) |
||||
{ |
||||
return strpos($attributeName, 'aria-') === 0; |
||||
} |
||||
|
||||
/** |
||||
* Check to see if an attribute is an data attribute or not |
||||
* |
||||
* @param $attributeName |
||||
* |
||||
* @return bool |
||||
*/ |
||||
protected function isDataAttribute($attributeName) |
||||
{ |
||||
return strpos($attributeName, 'data-') === 0; |
||||
} |
||||
|
||||
/** |
||||
* Make sure our use tag is only referencing internal resources |
||||
* |
||||
* @param \DOMElement $element |
||||
* @return bool |
||||
*/ |
||||
protected function isUseTagDirty(\DOMElement $element) |
||||
{ |
||||
$xlinks = $element->getAttributeNS('http://www.w3.org/1999/xlink', 'href'); |
||||
if ($xlinks && substr($xlinks, 0, 1) !== '#') { |
||||
return true; |
||||
} |
||||
|
||||
return false; |
||||
} |
||||
} |
@ -0,0 +1,354 @@
|
||||
<?php |
||||
|
||||
|
||||
namespace enshrined\svgSanitize\data; |
||||
|
||||
|
||||
/** |
||||
* Class AllowedAttributes |
||||
* |
||||
* @package enshrined\svgSanitize\data |
||||
*/ |
||||
class AllowedAttributes implements AttributeInterface |
||||
{ |
||||
|
||||
/** |
||||
* Returns an array of attributes |
||||
* |
||||
* @return array |
||||
*/ |
||||
public static function getAttributes() |
||||
{ |
||||
return array( |
||||
// HTML |
||||
'accept', |
||||
'action', |
||||
'align', |
||||
'alt', |
||||
'autocomplete', |
||||
'background', |
||||
'bgcolor', |
||||
'border', |
||||
'cellpadding', |
||||
'cellspacing', |
||||
'checked', |
||||
'cite', |
||||
'class', |
||||
'clear', |
||||
'color', |
||||
'cols', |
||||
'colspan', |
||||
'coords', |
||||
'crossorigin', |
||||
'datetime', |
||||
'default', |
||||
'dir', |
||||
'disabled', |
||||
'download', |
||||
'enctype', |
||||
'face', |
||||
'for', |
||||
'headers', |
||||
'height', |
||||
'hidden', |
||||
'high', |
||||
'href', |
||||
'hreflang', |
||||
'id', |
||||
'integrity', |
||||
'ismap', |
||||
'label', |
||||
'lang', |
||||
'list', |
||||
'loop', |
||||
'low', |
||||
'max', |
||||
'maxlength', |
||||
'media', |
||||
'method', |
||||
'min', |
||||
'multiple', |
||||
'name', |
||||
'noshade', |
||||
'novalidate', |
||||
'nowrap', |
||||
'open', |
||||
'optimum', |
||||
'pattern', |
||||
'placeholder', |
||||
'poster', |
||||
'preload', |
||||
'pubdate', |
||||
'radiogroup', |
||||
'readonly', |
||||
'rel', |
||||
'required', |
||||
'rev', |
||||
'reversed', |
||||
'role', |
||||
'rows', |
||||
'rowspan', |
||||
'spellcheck', |
||||
'scope', |
||||
'selected', |
||||
'shape', |
||||
'size', |
||||
'sizes', |
||||
'span', |
||||
'srclang', |
||||
'start', |
||||
'src', |
||||
'srcset', |
||||
'step', |
||||
'style', |
||||
'summary', |
||||
'tabindex', |
||||
'title', |
||||
'type', |
||||
'usemap', |
||||
'valign', |
||||
'value', |
||||
'width', |
||||
'xmlns', |
||||
|
||||
// SVG |
||||
'accent-height', |
||||
'accumulate', |
||||
'additivive', |
||||
'alignment-baseline', |
||||
'ascent', |
||||
'attributename', |
||||
'attributetype', |
||||
'azimuth', |
||||
'basefrequency', |
||||
'baseline-shift', |
||||
'begin', |
||||
'bias', |
||||
'by', |
||||
'class', |
||||
'clip', |
||||
'clip-path', |
||||
'clip-rule', |
||||
'color', |
||||
'color-interpolation', |
||||
'color-interpolation-filters', |
||||
'color-profile', |
||||
'color-rendering', |
||||
'cx', |
||||
'cy', |
||||
'd', |
||||
'dx', |
||||
'dy', |
||||
'diffuseconstant', |
||||
'direction', |
||||
'display', |
||||
'divisor', |
||||
'dur', |
||||
'edgemode', |
||||
'elevation', |
||||
'end', |
||||
'fill', |
||||
'fill-opacity', |
||||
'fill-rule', |
||||
'filter', |
||||
'flood-color', |
||||
'flood-opacity', |
||||
'font-family', |
||||
'font-size', |
||||
'font-size-adjust', |
||||
'font-stretch', |
||||
'font-style', |
||||
'font-variant', |
||||
'font-weight', |
||||
'fx', |
||||
'fy', |
||||
'g1', |
||||
'g2', |
||||
'glyph-name', |
||||
'glyphref', |
||||
'gradientunits', |
||||
'gradienttransform', |
||||
'height', |
||||
'href', |
||||
'id', |
||||
'image-rendering', |
||||
'in', |
||||
'in2', |
||||
'k', |
||||
'k1', |
||||
'k2', |
||||
'k3', |
||||
'k4', |
||||
'kerning', |
||||
'keypoints', |
||||
'keysplines', |
||||
'keytimes', |
||||
'lang', |
||||
'lengthadjust', |
||||
'letter-spacing', |
||||
'kernelmatrix', |
||||
'kernelunitlength', |
||||
'lighting-color', |
||||
'local', |
||||
'marker-end', |
||||
'marker-mid', |
||||
'marker-start', |
||||
'markerheight', |
||||
'markerunits', |
||||
'markerwidth', |
||||
'maskcontentunits', |
||||
'maskunits', |
||||
'max', |
||||
'mask', |
||||
'media', |
||||
'method', |
||||
'mode', |
||||
'min', |
||||
'name', |
||||
'numoctaves', |
||||
'offset', |
||||
'operator', |
||||
'opacity', |
||||
'order', |
||||
'orient', |
||||
'orientation', |
||||
'origin', |
||||
'overflow', |
||||
'paint-order', |
||||
'path', |
||||
'pathlength', |
||||
'patterncontentunits', |
||||
'patterntransform', |
||||
'patternunits', |
||||
'points', |
||||
'preservealpha', |
||||
'preserveaspectratio', |
||||
'r', |
||||
'rx', |
||||
'ry', |
||||
'radius', |
||||
'refx', |
||||
'refy', |
||||
'repeatcount', |
||||
'repeatdur', |
||||
'restart', |
||||
'result', |
||||
'rotate', |
||||
'scale', |
||||
'seed', |
||||
'shape-rendering', |
||||
'specularconstant', |
||||
'specularexponent', |
||||
'spreadmethod', |
||||
'stddeviation', |
||||
'stitchtiles', |
||||
'stop-color', |
||||
'stop-opacity', |
||||
'stroke-dasharray', |
||||
'stroke-dashoffset', |
||||
'stroke-linecap', |
||||
'stroke-linejoin', |
||||
'stroke-miterlimit', |
||||
'stroke-opacity', |
||||
'stroke', |
||||
'stroke-width', |
||||
'style', |
||||
'surfacescale', |
||||
'tabindex', |
||||
'targetx', |
||||
'targety', |
||||
'transform', |
||||
'text-anchor', |
||||
'text-decoration', |
||||
'text-rendering', |
||||
'textlength', |
||||
'type', |
||||
'u1', |
||||
'u2', |
||||
'unicode', |
||||
'values', |
||||
'viewbox', |
||||
'visibility', |
||||
'vert-adv-y', |
||||
'vert-origin-x', |
||||
'vert-origin-y', |
||||
'width', |
||||
'word-spacing', |
||||
'wrap', |
||||
'writing-mode', |
||||
'xchannelselector', |
||||
'ychannelselector', |
||||
'x', |
||||
'x1', |
||||
'x2', |
||||
'xmlns', |
||||
'y', |
||||
'y1', |
||||
'y2', |
||||
'z', |
||||
'zoomandpan', |
||||
|
||||
// MathML |
||||
'accent', |
||||
'accentunder', |
||||
'align', |
||||
'bevelled', |
||||
'close', |
||||
'columnsalign', |
||||
'columnlines', |
||||
'columnspan', |
||||
'denomalign', |
||||
'depth', |
||||
'dir', |
||||
'display', |
||||
'displaystyle', |
||||
'fence', |
||||
'frame', |
||||
'height', |
||||
'href', |
||||
'id', |
||||
'largeop', |
||||
'length', |
||||
'linethickness', |
||||
'lspace', |
||||
'lquote', |
||||
'mathbackground', |
||||
'mathcolor', |
||||
'mathsize', |
||||
'mathvariant', |
||||
'maxsize', |
||||
'minsize', |
||||
'movablelimits', |
||||
'notation', |
||||
'numalign', |
||||
'open', |
||||
'rowalign', |
||||
'rowlines', |
||||
'rowspacing', |
||||
'rowspan', |
||||
'rspace', |
||||
'rquote', |
||||
'scriptlevel', |
||||
'scriptminsize', |
||||
'scriptsizemultiplier', |
||||
'selection', |
||||
'separator', |
||||
'separators', |
||||
'slope', |
||||
'stretchy', |
||||
'subscriptshift', |
||||
'supscriptshift', |
||||
'symmetric', |
||||
'voffset', |
||||
'width', |
||||
'xmlns', |
||||
|
||||
// XML |
||||
'xlink:href', |
||||
'xml:id', |
||||
'xlink:title', |
||||
'xml:space', |
||||
'xmlns:xlink', |
||||
); |
||||
} |
||||
} |
@ -0,0 +1,245 @@
|
||||
<?php |
||||
|
||||
|
||||
namespace enshrined\svgSanitize\data; |
||||
|
||||
|
||||
/** |
||||
* Class AllowedTags |
||||
* |
||||
* @package enshrined\svgSanitize\data |
||||
*/ |
||||
class AllowedTags implements TagInterface |
||||
{ |
||||
|
||||
/** |
||||
* Returns an array of tags |
||||
* |
||||
* @return array |
||||
*/ |
||||
public static function getTags() |
||||
{ |
||||
return array ( |
||||
// HTML |
||||
'a', |
||||
'abbr', |
||||
'acronym', |
||||
'address', |
||||
'area', |
||||
'article', |
||||
'aside', |
||||
'audio', |
||||
'b', |
||||
'bdi', |
||||
'bdo', |
||||
'big', |
||||
'blink', |
||||
'blockquote', |
||||
'body', |
||||
'br', |
||||
'button', |
||||
'canvas', |
||||
'caption', |
||||
'center', |
||||
'cite', |
||||
'code', |
||||
'col', |
||||
'colgroup', |
||||
'content', |
||||
'data', |
||||
'datalist', |
||||
'dd', |
||||
'decorator', |
||||
'del', |
||||
'details', |
||||
'dfn', |
||||
'dir', |
||||
'div', |
||||
'dl', |
||||
'dt', |
||||
'element', |
||||
'em', |
||||
'fieldset', |
||||
'figcaption', |
||||
'figure', |
||||
'font', |
||||
'footer', |
||||
'form', |
||||
'h1', |
||||
'h2', |
||||
'h3', |
||||
'h4', |
||||
'h5', |
||||
'h6', |
||||
'head', |
||||
'header', |
||||
'hgroup', |
||||
'hr', |
||||
'html', |
||||
'i', |
||||
'image', |
||||
'img', |
||||
'input', |
||||
'ins', |
||||
'kbd', |
||||
'label', |
||||
'legend', |
||||
'li', |
||||
'main', |
||||
'map', |
||||
'mark', |
||||
'marquee', |
||||
'menu', |
||||
'menuitem', |
||||
'meter', |
||||
'nav', |
||||
'nobr', |
||||
'ol', |
||||
'optgroup', |
||||
'option', |
||||
'output', |
||||
'p', |
||||
'pre', |
||||
'progress', |
||||
'q', |
||||
'rp', |
||||
'rt', |
||||
'ruby', |
||||
's', |
||||
'samp', |
||||
'section', |
||||
'select', |
||||
'shadow', |
||||
'small', |
||||
'source', |
||||
'spacer', |
||||
'span', |
||||
'strike', |
||||
'strong', |
||||
'style', |
||||
'sub', |
||||
'summary', |
||||
'sup', |
||||
'table', |
||||
'tbody', |
||||
'td', |
||||
'template', |
||||
'textarea', |
||||
'tfoot', |
||||
'th', |
||||
'thead', |
||||
'time', |
||||
'tr', |
||||
'track', |
||||
'tt', |
||||
'u', |
||||
'ul', |
||||
'var', |
||||
'video', |
||||
'wbr', |
||||
|
||||
// SVG |
||||
'svg', |
||||
'altglyph', |
||||
'altglyphdef', |
||||
'altglyphitem', |
||||
'animatecolor', |
||||
'animatemotion', |
||||
'animatetransform', |
||||
'circle', |
||||
'clippath', |
||||
'defs', |
||||
'desc', |
||||
'ellipse', |
||||
'filter', |
||||
'font', |
||||
'g', |
||||
'glyph', |
||||
'glyphref', |
||||
'hkern', |
||||
'image', |
||||
'line', |
||||
'lineargradient', |
||||
'marker', |
||||
'mask', |
||||
'metadata', |
||||
'mpath', |
||||
'path', |
||||
'pattern', |
||||
'polygon', |
||||
'polyline', |
||||
'radialgradient', |
||||
'rect', |
||||
'stop', |
||||
'switch', |
||||
'symbol', |
||||
'text', |
||||
'textpath', |
||||
'title', |
||||
'tref', |
||||
'tspan', |
||||
'use', |
||||
'view', |
||||
'vkern', |
||||
|
||||
// SVG Filters |
||||
'feBlend', |
||||
'feColorMatrix', |
||||
'feComponentTransfer', |
||||
'feComposite', |
||||
'feConvolveMatrix', |
||||
'feDiffuseLighting', |
||||
'feDisplacementMap', |
||||
'feDistantLight', |
||||
'feFlood', |
||||
'feFuncA', |
||||
'feFuncB', |
||||
'feFuncG', |
||||
'feFuncR', |
||||
'feGaussianBlur', |
||||
'feMerge', |
||||
'feMergeNode', |
||||
'feMorphology', |
||||
'feOffset', |
||||
'fePointLight', |
||||
'feSpecularLighting', |
||||
'feSpotLight', |
||||
'feTile', |
||||
'feTurbulence', |
||||
|
||||
//MathML |
||||
'math', |
||||
'menclose', |
||||
'merror', |
||||
'mfenced', |
||||
'mfrac', |
||||
'mglyph', |
||||
'mi', |
||||
'mlabeledtr', |
||||
'mmuliscripts', |
||||
'mn', |
||||
'mo', |
||||
'mover', |
||||
'mpadded', |
||||
'mphantom', |
||||
'mroot', |
||||
'mrow', |
||||
'ms', |
||||
'mpspace', |
||||
'msqrt', |
||||
'mystyle', |
||||
'msub', |
||||
'msup', |
||||
'msubsup', |
||||
'mtable', |
||||
'mtd', |
||||
'mtext', |
||||
'mtr', |
||||
'munder', |
||||
'munderover', |
||||
|
||||
//text |
||||
'#text' |
||||
); |
||||
} |
||||
} |
@ -0,0 +1,21 @@
|
||||
<?php |
||||
|
||||
|
||||
namespace enshrined\svgSanitize\data; |
||||
|
||||
|
||||
/** |
||||
* Class AttributeInterface |
||||
* |
||||
* @package enshrined\svgSanitize\data |
||||
*/ |
||||
interface AttributeInterface |
||||
{ |
||||
|
||||
/** |
||||
* Returns an array of attributes |
||||
* |
||||
* @return array |
||||
*/ |
||||
public static function getAttributes(); |
||||
} |
@ -0,0 +1,22 @@
|
||||
<?php |
||||
|
||||
|
||||
namespace enshrined\svgSanitize\data; |
||||
|
||||
|
||||
/** |
||||
* Interface TagInterface |
||||
* |
||||
* @package enshrined\svgSanitize\tags |
||||
*/ |
||||
interface TagInterface |
||||
{ |
||||
|
||||
/** |
||||
* Returns an array of tags |
||||
* |
||||
* @return array |
||||
*/ |
||||
public static function getTags(); |
||||
|
||||
} |
@ -0,0 +1,187 @@
|
||||
#!/usr/bin/env php |
||||
<?php |
||||
|
||||
/* |
||||
* Simple program that uses svg-sanitizer |
||||
* to find issues in files specified on the |
||||
* command line, and prints a JSON output with |
||||
* the issues found on exit. |
||||
*/ |
||||
|
||||
require_once( __DIR__ . '/data/AttributeInterface.php' ); |
||||
require_once( __DIR__ . '/data/TagInterface.php' ); |
||||
require_once( __DIR__ . '/data/AllowedAttributes.php' ); |
||||
require_once( __DIR__ . '/data/AllowedTags.php' ); |
||||
require_once( __DIR__ . '/Sanitizer.php' ); |
||||
|
||||
|
||||
/* |
||||
* Print array as JSON and then |
||||
* exit program with a particular |
||||
* exit-code. |
||||
*/ |
||||
|
||||
function sysexit( |
||||
$results, |
||||
$status |
||||
) { |
||||
echo json_encode( |
||||
$results, |
||||
JSON_PRETTY_PRINT |
||||
); |
||||
|
||||
exit( $status ); |
||||
} |
||||
|
||||
|
||||
/* |
||||
* Main part begins |
||||
*/ |
||||
|
||||
global $argv; |
||||
|
||||
/* |
||||
* Set up results array, to |
||||
* be printed on exit. |
||||
*/ |
||||
$results = array( |
||||
'totals' => array( |
||||
'errors' => 0, |
||||
), |
||||
|
||||
'files' => array( |
||||
), |
||||
); |
||||
|
||||
|
||||
/* |
||||
* Catch files to scan from $argv. |
||||
*/ |
||||
|
||||