Commit 595bd840f4ebd4ff849223a0f0865870da63d5cf

Authored by totoro
1 parent 160d0690

add encode_HTML_entities function which get an HTML text and encode it into esca…

…ped HTML. This allows to transmit HTML to HTML element i.e. input text area with text in HTML format must be encoded to avoid error.
Showing 1 changed file with 76 additions and 20 deletions   Show diff stats
web/CXM_making_a_web_site.anubis
... ... @@ -67,6 +67,63 @@ transmit CXM_web_action.anubis
67 67  
68 68 transmit calexium_lib/web/types/web_action_name.anubis
69 69  
  70 +//TODO move anywhere
  71 +
  72 +
  73 +define List(Word8)
  74 +/** Test for HTML entity which must be encoded
  75 + * and return the encoded entity if needed
  76 + */
  77 + get_entity
  78 + (
  79 + Word8 _char,
  80 + List(Word8) tail
  81 + )=
  82 + //test for the ampersand
  83 + if _char = '&' then
  84 + //test if it's already an encoded string like & < etc. In that case we do nothing
  85 + if insensitive_equal(['&','a','m','p',';'], tail, 0) then [_char]
  86 + else if insensitive_equal(['&','l','t',';'], tail, 0) then [_char]
  87 + else if insensitive_equal(['&','g','t',';'], tail, 0) then [_char]
  88 + else if insensitive_equal(['&','q','u','o','t',';'], tail, 0) then [_char]
  89 + else
  90 + [';','p','m','a','&']
  91 + //test for '<' etc.
  92 + else if _char = '<' then [';','t','l','&']
  93 + else if _char = '>' then [';','t','g','&']
  94 + else if _char = '\"' then [';','t','o','u','q','&']
  95 + else [_char]
  96 +.
  97 +
  98 +define String
  99 + _HTML_encode_entities
  100 + (
  101 + List(Word8) source,
  102 + List(Word8) current
  103 + )=
  104 + if source is
  105 + {
  106 + [] then implode(reverse(current)),
  107 + [c . t] then
  108 + _HTML_encode_entities(t, get_entity(c, t) + current)
  109 + }
  110 +.
  111 +
  112 +public define String
  113 + encode_HTML_entities
  114 + (
  115 + String source
  116 + )=
  117 + _HTML_encode_entities(explode(source), [])
  118 +.
  119 +
  120 +//public define String
  121 +// encode_HTML_entities
  122 +// (
  123 +// String source
  124 +// )=
  125 +//.
  126 +
70 127 //read CXM_html_tooltip.anubis
71 128  
72 129 * (1) Structure of a web site.
... ... @@ -4293,7 +4350,7 @@ public define Printable_tree
4293 4350 [ ] then [ ],
4294 4351 [h . t] then
4295 4352 if h is (attrs,val,item)
4296   - then ["<option value=\""+val.value+"\" "+format_attrs(attrs)+">", item, "</option>\n" . format_choices(t)]
  4353 + then ["<option value=\""+encode_HTML_entities(val.value)+"\" "+format_attrs(attrs)+">", item, "</option>\n" . format_choices(t)]
4297 4354 }.
4298 4355  
4299 4356 public define Printable_tree
... ... @@ -4308,8 +4365,8 @@ public define Printable_tree
4308 4365 [h . t] then
4309 4366 if h is (attrs,val,item) then
4310 4367 if val.value = selected.value
4311   - then ["<option value=\""+val.value+"\" "+format_attrs(attrs)+" selected=\"selected\">", item, "</option>\n" . format_choices(t)]
4312   - else ["<option value=\""+val.value+"\" "+format_attrs(attrs)+" >", item, "</option>\n" . format_choices(t,selected)]
  4368 + then ["<option value=\""+encode_HTML_entities(val.value)+"\" "+format_attrs(attrs)+" selected=\"selected\">", item, "</option>\n" . format_choices(t)]
  4369 + else ["<option value=\""+encode_HTML_entities(val.value)+"\" "+format_attrs(attrs)+" >", item, "</option>\n" . format_choices(t,selected)]
4313 4370 }.
4314 4371  
4315 4372  
... ... @@ -4938,9 +4995,9 @@ define Printable_tree
4938 4995 url(_) then ""
4939 4996 },
4940 4997 if action_name = "" then
4941   - ["<input type=\"button\" value=\"",text,"\"", format_attrs(options), " />"]
  4998 + ["<input type=\"button\" value=\"",encode_HTML_entities(text),"\"", format_attrs(options), " />"]
4942 4999 else
4943   - [s,"<input type=\"button\" value=\"",text,"\"", format_attrs(options), " onclick=\"",h,"\" />"]
  5000 + [s,"<input type=\"button\" value=\"",encode_HTML_entities(text),"\"", format_attrs(options), " onclick=\"",h,"\" />"]
4944 5001 }
4945 5002 ],
4946 5003 button(url_off,url_on) then
... ... @@ -5779,18 +5836,17 @@ define Printable_tree
5779 5836 format(cinfo,ic_v,any_foreign_link(options,url,name),format_element,is_https, action_count, head_tags),
5780 5837 private_download(url,name,extra,action) then
5781 5838 format(cinfo,ic_v,any_private_download(url,name,extra,action),format_element,is_https, action_count, head_tags),
5782   - text_input(options, label_text, id, name, i, w) then
5783   -
  5839 + text_input(options, label_text, id, name, init, w) then
5784 5840 [ format_label(label_text, id),
5785   - "<input type=\"text\" name=\"",name,"\" id=\"",id,"\" size=\"",w,"\" value=\"",i,"\"",format_attrs([class("in") . options])," />"],
5786   - text_input_ro(options, label_text, id, name,i,w) then
  5841 + "<input type=\"text\" name=\"",name,"\" id=\"",id,"\" size=\"",w,"\" value=\"",encode_HTML_entities(init.value),"\"",format_attrs([class("in") . options])," />"],
  5842 + text_input_ro(options, label_text, id, name, init, w) then
5787 5843 [ format_label(label_text, id),
5788   - "<input readonly=\"readonly\" type=\"text\" name=\"",name,"\" id=\"",id,"\" size=\"",w,"\" value=\"",i,"\"",format_attrs([class("in") . options])," />"],
5789   - password_input(options, label_text, id, name,i,w) then
  5844 + "<input readonly=\"readonly\" type=\"text\" name=\"",name,"\" id=\"",id,"\" size=\"",w,"\" value=\"",encode_HTML_entities(init.value),"\"",format_attrs([class("in") . options])," />"],
  5845 + password_input(options, label_text, id, name, init, w) then
5790 5846 [ format_label(label_text, id),
5791   - "<input type=\"password\" name=\"",name,"\" id=\"",id,"\" size=\"",w,"\" value=\"",i,"\"",format_attrs([class("in") . options])," />"],
5792   - text_area(options,label_text, id, n,i,w,h) then
5793   - [ format_label(label_text, id), "<textarea ",format(options)," id=\"",id,"\" name=\"",n,"\" cols=\"",w,"\" rows=\"",h,"\">",i,"</textarea>"],
  5847 + "<input type=\"password\" name=\"",name,"\" id=\"",id,"\" size=\"",w,"\" value=\"",encode_HTML_entities(init.value),"\"",format_attrs([class("in") . options])," />"],
  5848 + text_area(options,label_text, id, n, init, w, h) then
  5849 + [ format_label(label_text, id), "<textarea ",format(options)," id=\"",id,"\" name=\"",n,"\" cols=\"",w,"\" rows=\"",h,"\">",encode_HTML_entities(init.value),"</textarea>"],
5794 5850 file_upload(options, label, id, n, w) then
5795 5851 [ format_label(label, id),
5796 5852 "<input type=\"file\" id=\"",id,"\" size=\"",w,"\" name=\"",n,"\"",format_attrs([class("in") . options])," />"],
... ... @@ -5807,11 +5863,11 @@ define Printable_tree
5807 5863 [ format_label(label, id),
5808 5864 "<select id=\"",id,"\" name=\"",n,"\" size=\"",s,"\" ",format_attrs([class("in") . options]),">",format_choices(cs,sd),"</select>"],
5809 5865  
5810   - radio_button(options, label, id, n, v, c) then
  5866 + radio_button(options, label, id, n, value, c) then
5811 5867 [ format_label(label, id),
5812   - "<input type=\"radio\" name=\"",n,"\" id=\"",id,"\" value=\"",v,"\"",(if c then " checked=\"checked\"" else ""),format_attrs([class("in") . options])," />"],
5813   - radio_button_r(options, label, id, n, v, c) then
5814   - [ "<input type=\"radio\" name=\"",n,"\" id=\"",id,"\" value=\"",v,"\"",(if c then " checked=\"checked\"" else ""),format_attrs([class("in") . options])," />",
  5868 + "<input type=\"radio\" name=\"",n,"\" id=\"",id,"\" value=\"",value,"\"",(if c then " checked=\"checked\"" else ""),format_attrs([class("in") . options])," />"],
  5869 + radio_button_r(options, label, id, n, value, c) then
  5870 + [ "<input type=\"radio\" name=\"",n,"\" id=\"",id,"\" value=\"",value,"\"",(if c then " checked=\"checked\"" else ""),format_attrs([class("in") . options])," />",
5815 5871 format_label(label, id)],
5816 5872 check_box(options, label, id, n, c) then
5817 5873 [ format_label(label, id),
... ... @@ -5823,9 +5879,9 @@ define Printable_tree
5823 5879 format(cinfo,ic_v,any_div(options, e),format_element,is_https, action_count, head_tags),
5824 5880 div_empty(options) then
5825 5881 format(cinfo,ic_v,any_div_empty(options),format_element,is_https, action_count, head_tags),
5826   - hidden(_id, name, value) then
  5882 + hidden(_id, name, init) then
5827 5883 since _id is html_Id(id),
5828   - ["<input type=\"hidden\"",(if id = "" then "" else " id=\""+id+"\"")," name=\"",name,"\" value=\"",value,"\" />"],
  5884 + ["<input type=\"hidden\"",(if id = "" then "" else " id=\""+id+"\"")," name=\"",name,"\" value=\"",encode_HTML_entities(init.value),"\" />"],
5829 5885 partial(p_content) then
5830 5886 if p_content is partial_content(tags, html_elements) then
5831 5887 head_tags <- *head_tags + tags;
... ...