MediaWiki
REL1_22
|
The WebRequest class encapsulates getting at data passed in the URL or via a POSTed form, handling remove of "magic quotes" slashes, stripping illegal input characters and normalizing Unicode sequences. More...
Public Member Functions | |
__construct () | |
appendQuery ($query) | |
Take an arbitrary query and rewrite the present URL to include it. | |
appendQueryArray ($array, $onlyquery=false) | |
Appends or replaces value of query variables. | |
appendQueryValue ($key, $value, $onlyquery=false) | |
checkSessionCookie () | |
Returns true if there is a session cookie set. | |
checkUrlExtension ($extWhitelist=array()) | |
Check if Internet Explorer will detect an incorrect cache extension in PATH_INFO or QUERY_STRING. | |
escapeAppendQuery ($query) | |
HTML-safe version of appendQuery(). | |
getAllHeaders () | |
Get an array containing all request headers. | |
getArray ($name, $default=null) | |
Fetch an array from the input or return $default if it's not set. | |
getBool ($name, $default=false) | |
Fetch a boolean value from the input or return $default if not set. | |
getCheck ($name) | |
Return true if the named value is set in the input, whatever that value is (even "0"). | |
getCookie ($key, $prefix=null, $default=null) | |
Get a cookie from the $_COOKIE jar. | |
getError () | |
Return the upload error. | |
getFileName ($key) | |
Return the original filename of the uploaded file, as reported by the submitting user agent. | |
getFileSize ($key) | |
Return the size of the upload, or 0. | |
getFileTempname ($key) | |
Return the path to the temporary file where PHP has stored the upload. | |
getFullRequestURL () | |
Return the request URI with the canonical service and hostname, path, and query string. | |
getFuzzyBool ($name, $default=false) | |
Fetch a boolean value from the input or return $default if not set. | |
getHeader ($name) | |
Get a request header, or false if it isn't set. | |
getInt ($name, $default=0) | |
Fetch an integer value from the input or return $default if not set. | |
getIntArray ($name, $default=null) | |
Fetch an array of integers, or return $default if it's not set. | |
getIntOrNull ($name) | |
Fetch an integer value from the input or return null if empty. | |
getLimitOffset ($deflimit=50, $optionname= 'rclimit') | |
Check for limit and offset parameters on the input, and return sensible defaults if not given. | |
getMethod () | |
Get the HTTP method used for this request. | |
getQueryValues () | |
Get the values passed in the query string. | |
getRawInput () | |
Return the raw request body, with no processing. | |
getRawPostString () | |
Return the contents of the POST with no decoding. | |
getRawQueryString () | |
Return the contents of the Query with no decoding. | |
getRequestURL () | |
Return the path and query string portion of the request URI. | |
getSessionData ($key) | |
Get data from $_SESSION. | |
getSize () | |
Return the file size of the uploaded file. | |
getTempName () | |
Return the path to the temporary file. | |
getText ($name, $default= '') | |
Fetch a text string from the given array or return $default if it's not set. | |
getUpload ($key) | |
Return a WebRequestUpload object corresponding to the key. | |
getUploadError ($key) | |
Return the upload error or 0. | |
getVal ($name, $default=null) | |
Fetch a scalar from the input or return $default if it's not set. | |
getValueNames ($exclude=array()) | |
Returns the names of all input values excluding those in $exclude. | |
getValues () | |
Extracts the given named values into an array. | |
interpolateTitle () | |
Check for title, action, and/or variant data in the URL and interpolate it into the GET variables. | |
isIniSizeOverflow () | |
Returns whether this upload failed because of overflow of a maximum set in php.ini. | |
normalizeUnicode ($data) | |
Recursively normalizes UTF-8 strings in the given array. | |
response () | |
Return a handle to WebResponse style object, for setting cookies, headers and other stuff, for Request being worked on. | |
setSessionData ($key, $data) | |
Set session data. | |
setVal ($key, $value) | |
Set an arbitrary value into our get/post data. | |
unsetVal ($key) | |
Unset an arbitrary value from our get/post data. | |
wasPosted () | |
Returns true if the present request was reached by a POST operation, false otherwise (GET, HEAD, or command-line). | |
Static Public Member Functions | |
static | detectProtocol () |
static | detectProtocolAndStdPort () |
static | detectServer () |
Work out an appropriate URL prefix containing scheme and host, based on information detected from $_SERVER. | |
static | extractTitle ($path, $bases, $key=false) |
URL rewriting function; tries to extract page title and, optionally, one other fixed parameter value from a URL path. | |
static | getPathInfo ($want= 'all') |
Extract relevant query arguments from the http request uri's path to be merged with the normal php provided query arguments. | |
Public Attributes | |
$headers = array() | |
Protected Member Functions | |
doSecurityRedirect ($url) | |
Attempt to redirect to a URL with a QUERY_STRING that's not dangerous in IE 6. | |
Protected Attributes | |
$data | |
Private Member Functions | |
checkMagicQuotes () | |
If magic_quotes_gpc option is on, run the global arrays through fix_magic_quotes to strip out the stupid slashes. | |
& | fix_magic_quotes (&$arr, $topLevel=true) |
Recursively strips slashes from the given array; used for undoing the evil that is magic_quotes_gpc. | |
getGPCVal ($arr, $name, $default) | |
Fetch a value from the given array or return $default if it's not set. | |
initHeaders () | |
Initialise the header list. | |
Private Attributes | |
String | $ip |
Cached client IP address. | |
WebResponse | $response |
Lazy-init response object. |
The WebRequest class encapsulates getting at data passed in the URL or via a POSTed form, handling remove of "magic quotes" slashes, stripping illegal input characters and normalizing Unicode sequences.
Usually this is used via a global singleton, $wgRequest. You should not create a second WebRequest object; make a FauxRequest object if you want to pass arbitrary data to some function in place of the web input.
Definition at line 38 of file WebRequest.php.
Definition at line 51 of file WebRequest.php.
References checkMagicQuotes(), and data.
Referenced by DerivativeRequest\__construct().
WebRequest::appendQuery | ( | $ | query | ) |
Take an arbitrary query and rewrite the present URL to include it.
string | $query | query string fragment; do not include initial '?' |
Definition at line 722 of file WebRequest.php.
WebRequest::appendQueryArray | ( | $ | array, |
$ | onlyquery = false |
||
) |
Appends or replaces value of query variables.
array | $array | of values to replace/add to query |
bool | $onlyquery | whether to only return the query string and not the complete URL |
Definition at line 755 of file WebRequest.php.
WebRequest::appendQueryValue | ( | $ | key, |
$ | value, | ||
$ | onlyquery = false |
||
) |
$key | |
$value | |
$onlyquery | bool |
Definition at line 743 of file WebRequest.php.
WebRequest::checkMagicQuotes | ( | ) | [private] |
If magic_quotes_gpc option is on, run the global arrays through fix_magic_quotes to strip out the stupid slashes.
WARNING: This should only be done once! Running a second time could damage the values.
Definition at line 291 of file WebRequest.php.
Referenced by __construct().
Returns true if there is a session cookie set.
This does not necessarily mean that the user is logged in!
If you want to check for an open session, use session_id() instead; that will also tell you if the session was opened during the current request (in which case the cookie will be sent back to the client at the end of the script run).
Reimplemented in DerivativeRequest, and FauxRequest.
Definition at line 640 of file WebRequest.php.
WebRequest::checkUrlExtension | ( | $ | extWhitelist = array() | ) |
Check if Internet Explorer will detect an incorrect cache extension in PATH_INFO or QUERY_STRING.
If the request can't be allowed, show an error message or redirect to a safer URL. Returns true if the URL is OK, and false if an error message has been shown and the request should be aborted.
$extWhitelist | array |
HttpError |
Reimplemented in FauxRequest.
Definition at line 958 of file WebRequest.php.
static WebRequest::detectProtocol | ( | ) | [static] |
Definition at line 206 of file WebRequest.php.
Referenced by LoginForm\execute(), and wfExpandUrl().
static WebRequest::detectProtocolAndStdPort | ( | ) | [static] |
Definition at line 192 of file WebRequest.php.
static WebRequest::detectServer | ( | ) | [static] |
Work out an appropriate URL prefix containing scheme and host, based on information detected from $_SERVER.
Definition at line 160 of file WebRequest.php.
Referenced by WebRequestTest\testDetectServer().
WebRequest::doSecurityRedirect | ( | $ | url | ) | [protected] |
Attempt to redirect to a URL with a QUERY_STRING that's not dangerous in IE 6.
Returns true if it was successful, false otherwise.
$url | string |
Definition at line 983 of file WebRequest.php.
WebRequest::escapeAppendQuery | ( | $ | query | ) |
HTML-safe version of appendQuery().
string | $query | query string fragment; do not include initial '?' |
Definition at line 733 of file WebRequest.php.
static WebRequest::extractTitle | ( | $ | path, |
$ | bases, | ||
$ | key = false |
||
) | [static] |
URL rewriting function; tries to extract page title and, optionally, one other fixed parameter value from a URL path.
string | $path | the URL path given from the client |
array | $bases | one or more URLs, optionally with $1 at the end |
string | $key | if provided, the matching key in $bases will be passed on as the value of this URL parameter |
Definition at line 240 of file WebRequest.php.
& WebRequest::fix_magic_quotes | ( | &$ | arr, |
$ | topLevel = true |
||
) | [private] |
Recursively strips slashes from the given array; used for undoing the evil that is magic_quotes_gpc.
array | $arr | will be modified |
bool | $topLevel | Specifies if the array passed is from the top level of the source. In PHP5 magic_quotes only escapes the first level of keys that belong to an array. |
Definition at line 270 of file WebRequest.php.
Get an array containing all request headers.
Reimplemented in DerivativeRequest.
Definition at line 904 of file WebRequest.php.
WebRequest::getArray | ( | $ | name, |
$ | default = null |
||
) |
Fetch an array from the input or return $default if it's not set.
If source was scalar, will return an array with a single element. If no source and no default, returns NULL.
$name | String | |
array | $default | optional default (or NULL) |
Definition at line 412 of file WebRequest.php.
WebRequest::getBool | ( | $ | name, |
$ | default = false |
||
) |
Fetch a boolean value from the input or return $default if not set.
Guaranteed to return true or false, with normal PHP semantics for boolean interpretation of strings.
$name | String |
$default | Boolean |
Definition at line 476 of file WebRequest.php.
Referenced by FormOptions\fetchValuesFromRequest().
WebRequest::getCheck | ( | $ | name | ) |
Return true if the named value is set in the input, whatever that value is (even "0").
Return false if the named value is not set. Example use is checking for the presence of check boxes in forms.
$name | String |
Definition at line 501 of file WebRequest.php.
WebRequest::getCookie | ( | $ | key, |
$ | prefix = null , |
||
$ | default = null |
||
) |
Get a cookie from the $_COOKIE jar.
string | $key | the name of the cookie |
string | $prefix | a prefix to use for the cookie name, if not $wgCookiePrefix |
$default | Mixed: what to return if the value isn't found |
Reimplemented in DerivativeRequest, and FauxRequest.
Definition at line 652 of file WebRequest.php.
Return the upload error.
See link for explanation http://www.php.net/manual/en/features.file-upload.errors.php
Definition at line 1269 of file WebRequest.php.
WebRequest::getFileName | ( | $ | key | ) |
Return the original filename of the uploaded file, as reported by the submitting user agent.
HTML-style character entities are interpreted and normalized to Unicode normalization form C, in part to deal with weird input from Safari with non-ASCII filenames.
Other than this the name is not verified for being a safe filename.
$key | String: |
Definition at line 844 of file WebRequest.php.
WebRequest::getFileSize | ( | $ | key | ) |
Return the size of the upload, or 0.
$key | String: |
Definition at line 816 of file WebRequest.php.
WebRequest::getFileTempname | ( | $ | key | ) |
Return the path to the temporary file where PHP has stored the upload.
$key | String: |
Definition at line 804 of file WebRequest.php.
Return the request URI with the canonical service and hostname, path, and query string.
This will be suitable for use as an absolute link in HTML or other output.
If $wgServer is protocol-relative, this will return a fully qualified URL with the protocol that was used for this request.
Definition at line 712 of file WebRequest.php.
WebRequest::getFuzzyBool | ( | $ | name, |
$ | default = false |
||
) |
Fetch a boolean value from the input or return $default if not set.
Unlike getBool, the string "false" will result in boolean false, which is useful when interpreting information sent from JavaScript.
$name | String |
$default | Boolean |
Definition at line 489 of file WebRequest.php.
Referenced by ResourceLoaderContext\__construct().
WebRequest::getGPCVal | ( | $ | arr, |
$ | name, | ||
$ | default | ||
) | [private] |
Fetch a value from the given array or return $default if it's not set.
$arr | Array |
$name | String |
$default | Mixed |
Definition at line 331 of file WebRequest.php.
WebRequest::getHeader | ( | $ | name | ) |
Get a request header, or false if it isn't set.
string | $name | case-insensitive header name |
Reimplemented in DerivativeRequest, and FauxRequest.
Definition at line 915 of file WebRequest.php.
WebRequest::getInt | ( | $ | name, |
$ | default = 0 |
||
) |
Fetch an integer value from the input or return $default if not set.
Guaranteed to return an integer; non-numeric input will typically return 0.
$name | String |
$default | Integer |
Definition at line 448 of file WebRequest.php.
Referenced by FormOptions\fetchValuesFromRequest().
WebRequest::getIntArray | ( | $ | name, |
$ | default = null |
||
) |
Fetch an array of integers, or return $default if it's not set.
If source was scalar, will return an array with a single element. If no source and no default, returns NULL. If an array is returned, contents are guaranteed to be integers.
$name | String | |
array | $default | option default (or NULL) |
Definition at line 431 of file WebRequest.php.
WebRequest::getIntOrNull | ( | $ | name | ) |
Fetch an integer value from the input or return null if empty.
Guaranteed to return an integer or null; non-numeric input will typically return null.
$name | String |
Definition at line 460 of file WebRequest.php.
Referenced by FormOptions\fetchValuesFromRequest().
WebRequest::getLimitOffset | ( | $ | deflimit = 50 , |
$ | optionname = 'rclimit' |
||
) |
Check for limit and offset parameters on the input, and return sensible defaults if not given.
The limit must be positive and is capped at 5000. Offset must be positive but is not capped.
$deflimit | Integer: limit to use if no input and the user hasn't set the option. | |
string | $optionname | to specify an option other than rclimit to pull from. |
Definition at line 773 of file WebRequest.php.
Get the HTTP method used for this request.
Reimplemented in FauxRequest.
Definition at line 612 of file WebRequest.php.
static WebRequest::getPathInfo | ( | $ | want = 'all' | ) | [static] |
Extract relevant query arguments from the http request uri's path to be merged with the normal php provided query arguments.
Tries to use the REQUEST_URI data if available and parses it according to the wiki's configuration looking for any known pattern.
If the REQUEST_URI is not provided we'll fall back on the PATH_INFO provided by the server if any and use that to set a 'title' parameter.
string | $want | If this is not 'all', then the function will return an empty array if it determines that the URL is inside a rewrite path. |
Definition at line 77 of file WebRequest.php.
Referenced by wfThumbHandle404().
Get the values passed in the query string.
No transformation is performed on the values.
Reimplemented in FauxRequest.
Definition at line 565 of file WebRequest.php.
Return the raw request body, with no processing.
Cached since some methods disallow reading the stream more than once. As stated in the php docs, this does not work with enctype="multipart/form-data".
Reimplemented in FauxRequest.
Definition at line 599 of file WebRequest.php.
Return the contents of the POST with no decoding.
Use when you need to know exactly what was sent, e.g. for an OAuth signature over the elements.
Reimplemented in FauxRequest.
Definition at line 585 of file WebRequest.php.
Return the contents of the Query with no decoding.
Use when you need to know exactly what was sent, e.g. for an OAuth signature over the elements.
Reimplemented in FauxRequest.
Definition at line 575 of file WebRequest.php.
Return the path and query string portion of the request URI.
This will be suitable for use as a relative link in HTML output.
MWException |
Reimplemented in FauxRequest.
Definition at line 667 of file WebRequest.php.
WebRequest::getSessionData | ( | $ | key | ) |
Get data from $_SESSION.
string | $key | name of key in $_SESSION |
Reimplemented in DerivativeRequest, and FauxRequest.
Definition at line 931 of file WebRequest.php.
Return the file size of the uploaded file.
Definition at line 1242 of file WebRequest.php.
Return the path to the temporary file.
Definition at line 1255 of file WebRequest.php.
WebRequest::getText | ( | $ | name, |
$ | default = '' |
||
) |
Fetch a text string from the given array or return $default if it's not set.
Carriage returns are stripped from the text, and with some language modules there is an input transliteration applied. This should generally be used for form "<textarea>" and "<input>" fields. Used for user-supplied freeform text input (for which input transformations may be required - e.g. Esperanto x-coding).
$name | String | |
string | $default | optional |
Reimplemented in FauxRequest.
Definition at line 519 of file WebRequest.php.
Referenced by FormOptions\fetchValuesFromRequest().
WebRequest::getUpload | ( | $ | key | ) |
Return a WebRequestUpload object corresponding to the key.
$key | string |
Definition at line 855 of file WebRequest.php.
WebRequest::getUploadError | ( | $ | key | ) |
Return the upload error or 0.
$key | String: |
Definition at line 828 of file WebRequest.php.
WebRequest::getVal | ( | $ | name, |
$ | default = null |
||
) |
Fetch a scalar from the input or return $default if it's not set.
Returns a string. Arrays are discarded. Useful for non-freeform text inputs (e.g. predefined internal text keys selected by a drop-down menu). For freeform input, see getText().
$name | String | |
string | $default | optional default (or NULL) |
Definition at line 362 of file WebRequest.php.
Referenced by ResourceLoaderContext\__construct().
WebRequest::getValueNames | ( | $ | exclude = array() | ) |
Returns the names of all input values excluding those in $exclude.
$exclude | Array |
Definition at line 555 of file WebRequest.php.
Extracts the given named values into an array.
If no arguments are given, returns all input values. No transformation is performed on the values.
Reimplemented in FauxRequest.
Definition at line 533 of file WebRequest.php.
WebRequest::initHeaders | ( | ) | [private] |
Initialise the header list.
Definition at line 877 of file WebRequest.php.
Check for title, action, and/or variant data in the URL and interpolate it into the GET variables.
This should only be run after $wgContLang is available, as we may need the list of language variants to determine available variant URLs.
Definition at line 218 of file WebRequest.php.
Returns whether this upload failed because of overflow of a maximum set in php.ini.
Definition at line 1283 of file WebRequest.php.
WebRequest::normalizeUnicode | ( | $ | data | ) |
Recursively normalizes UTF-8 strings in the given array.
$data | string|array |
Definition at line 311 of file WebRequest.php.
Return a handle to WebResponse style object, for setting cookies, headers and other stuff, for Request being worked on.
Definition at line 865 of file WebRequest.php.
WebRequest::setSessionData | ( | $ | key, |
$ | data | ||
) |
Set session data.
string | $key | name of key in $_SESSION |
$data | Mixed |
Reimplemented in DerivativeRequest, and FauxRequest.
Definition at line 944 of file WebRequest.php.
WebRequest::setVal | ( | $ | key, |
$ | value | ||
) |
Set an arbitrary value into our get/post data.
string | $key | key name to use |
$value | Mixed: value to set |
Definition at line 381 of file WebRequest.php.
WebRequest::unsetVal | ( | $ | key | ) |
Unset an arbitrary value from our get/post data.
string | $key | key name to use |
Definition at line 393 of file WebRequest.php.
Returns true if the present request was reached by a POST operation, false otherwise (GET, HEAD, or command-line).
Note that values retrieved by the object may come from the GET URL etc even on a POST request.
Reimplemented in FauxRequest.
Definition at line 625 of file WebRequest.php.
WebRequest::$data [protected] |
Definition at line 39 of file WebRequest.php.
Referenced by DerivativeRequest\__construct().
Definition at line 39 of file WebRequest.php.
String WebRequest::$ip [private] |
Cached client IP address.
Definition at line 49 of file WebRequest.php.
WebResponse WebRequest::$response [private] |
Lazy-init response object.
Definition at line 44 of file WebRequest.php.