}
$seek = fseek($fp, 0 - $size, SEEK_END);
if ($seek === 0) {
- $data = escape_tags(fread($fp, $size));
+ $data = Strings::escapeTags(fread($fp, $size));
while (!feof($fp)) {
- $data .= escape_tags(fread($fp, 4096));
+ $data .= Strings::escapeTags(fread($fp, 4096));
}
}
}
(`url` LIKE '%s' OR `name` LIKE '%s' OR `location` LIKE '%s' OR
`addr` LIKE '%s' OR `about` LIKE '%s' OR `keywords` LIKE '%s') $extra_sql",
DBA::escape(Protocol::DFRN), DBA::escape($ostatus), DBA::escape($diaspora),
- DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)),
- DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)));
+ DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)),
+ DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)));
$results = q("SELECT `nurl`
FROM `gcontact`
GROUP BY `nurl`
ORDER BY `updated` DESC LIMIT %d, %d",
DBA::escape(Protocol::DFRN), DBA::escape($ostatus), DBA::escape($diaspora),
- DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)),
- DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)), DBA::escape(escape_tags($search2)),
+ DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)),
+ DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)), DBA::escape(Strings::escapeTags($search2)),
$pager->getStart(), $pager->getItemsPerPage());
$j = new stdClass();
$j->total = $count[0]["total"];
use Friendica\Model\Profile;
use Friendica\Module\Login;
use Friendica\Util\DateTimeFormat;
+use Friendica\Util\Strings;
use Friendica\Util\Temporal;
require_once 'include/items.php';
$cid = !empty($_POST['cid']) ? intval($_POST['cid']) : 0;
$uid = local_user();
- $start_text = escape_tags(defaults($_REQUEST, 'start_text', ''));
- $finish_text = escape_tags(defaults($_REQUEST, 'finish_text', ''));
+ $start_text = Strings::escapeTags(defaults($_REQUEST, 'start_text', ''));
+ $finish_text = Strings::escapeTags(defaults($_REQUEST, 'finish_text', ''));
$adjust = intval(defaults($_POST, 'adjust', 0));
$nofinish = intval(defaults($_POST, 'nofinish', 0));
// and we'll waste a bunch of time responding to it. Time that
// could've been spent doing something else.
- $summary = escape_tags(trim(defaults($_POST, 'summary', '')));
- $desc = escape_tags(trim(defaults($_POST, 'desc', '')));
- $location = escape_tags(trim(defaults($_POST, 'location', '')));
+ $summary = Strings::escapeTags(trim(defaults($_POST, 'summary', '')));
+ $desc = Strings::escapeTags(trim(defaults($_POST, 'desc', '')));
+ $location = Strings::escapeTags(trim(defaults($_POST, 'location', '')));
$type = 'event';
$action = ($event_id == '') ? 'new' : "event/" . $event_id;
$hash = Strings::getRandomHex();
- $note = escape_tags(trim(defaults($_POST, 'note', '')));
+ $note = Strings::escapeTags(trim(defaults($_POST, 'note', '')));
if ($new_contact) {
$r = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d LIMIT 1",
$app = $orig_post['app'];
$categories = $orig_post['file'];
$title = Strings::removeTags(trim($_REQUEST['title']));
- $body = escape_tags(trim($_REQUEST['body']));
+ $body = Strings::escapeTags(trim($_REQUEST['body']));
$private = $orig_post['private'];
$pubmail_enabled = $orig_post['pubmail'];
$network = $orig_post['network'];
$str_contact_deny = perms2str(defaults($_REQUEST, 'contact_deny', ''));
}
- $title = Strings::removeTags(trim(defaults($_REQUEST, 'title' , '')));
- $location = Strings::removeTags(trim(defaults($_REQUEST, 'location', '')));
- $coord = Strings::removeTags(trim(defaults($_REQUEST, 'coord' , '')));
- $verb = Strings::removeTags(trim(defaults($_REQUEST, 'verb' , '')));
- $emailcc = Strings::removeTags(trim(defaults($_REQUEST, 'emailcc' , '')));
- $body = escape_tags(trim(defaults($_REQUEST, 'body' , '')));
- $network = Strings::removeTags(trim(defaults($_REQUEST, 'network' , Protocol::DFRN)));
- $guid = System::createUUID();
+ $title = Strings::removeTags(trim(defaults($_REQUEST, 'title' , '')));
+ $location = Strings::removeTags(trim(defaults($_REQUEST, 'location', '')));
+ $coord = Strings::removeTags(trim(defaults($_REQUEST, 'coord' , '')));
+ $verb = Strings::removeTags(trim(defaults($_REQUEST, 'verb' , '')));
+ $emailcc = Strings::removeTags(trim(defaults($_REQUEST, 'emailcc' , '')));
+ $body = Strings::escapeTags(trim(defaults($_REQUEST, 'body' , '')));
+ $network = Strings::removeTags(trim(defaults($_REQUEST, 'network' , Protocol::DFRN)));
+ $guid = System::createUUID();
$postopts = defaults($_REQUEST, 'postopts', '');
$replyto = x($_REQUEST, 'replyto') ? Strings::removeTags(trim($_REQUEST['replyto'])) : '';
$subject = x($_REQUEST, 'subject') ? Strings::removeTags(trim($_REQUEST['subject'])) : '';
- $body = x($_REQUEST, 'body') ? escape_tags(trim($_REQUEST['body'])) : '';
+ $body = x($_REQUEST, 'body') ? Strings::escapeTags(trim($_REQUEST['body'])) : '';
$recipient = x($_REQUEST, 'messageto') ? intval($_REQUEST['messageto']) : 0;
$ret = Mail::send($recipient, $body, $subject, $replyto);
'$preid' => $preid,
'$subject' => L10n::t('Subject:'),
'$subjtxt' => x($_REQUEST, 'subject') ? strip_tags($_REQUEST['subject']) : '',
- '$text' => x($_REQUEST, 'body') ? escape_tags(htmlspecialchars($_REQUEST['body'])) : '',
+ '$text' => x($_REQUEST, 'body') ? Strings::escapeTags(htmlspecialchars($_REQUEST['body'])) : '',
'$readonly' => '',
'$yourmessage' => L10n::t('Your message:'),
'$select' => $select,
Hook::add('head', __FILE__, 'network_infinite_scroll_head');
- $search = (x($_GET, 'search') ? escape_tags($_GET['search']) : '');
+ $search = (x($_GET, 'search') ? Strings::escapeTags($_GET['search']) : '');
if (($search != '') && !empty($_GET['submit'])) {
$a->internalRedirect('search?search=' . urlencode($search));
for ($x = 1; $x < $a->argc; $x ++) {
if (is_a_date_arg($a->argv[$x])) {
if ($datequery) {
- $datequery2 = escape_tags($a->argv[$x]);
+ $datequery2 = Strings::escapeTags($a->argv[$x]);
} else {
- $datequery = escape_tags($a->argv[$x]);
+ $datequery = Strings::escapeTags($a->argv[$x]);
$_GET['order'] = 'post';
}
} elseif (intval($a->argv[$x])) {
for ($x = 2; $x < $a->argc; $x ++) {
if (is_a_date_arg($a->argv[$x])) {
if ($datequery) {
- $datequery2 = escape_tags($a->argv[$x]);
+ $datequery2 = Strings::escapeTags($a->argv[$x]);
} else {
- $datequery = escape_tags($a->argv[$x]);
+ $datequery = Strings::escapeTags($a->argv[$x]);
}
} else {
$category = $a->argv[$x];
return;
}
- $dob = $_POST['dob'] ? escape_tags(trim($_POST['dob'])) : '0000-00-00';
+ $dob = $_POST['dob'] ? Strings::escapeTags(trim($_POST['dob'])) : '0000-00-00';
$y = substr($dob, 0, 4);
if ((! ctype_digit($y)) || ($y < 1900)) {
$politic = Strings::removeTags(trim($_POST['politic']));
$religion = Strings::removeTags(trim($_POST['religion']));
- $likes = escape_tags(trim($_POST['likes']));
- $dislikes = escape_tags(trim($_POST['dislikes']));
-
- $about = escape_tags(trim($_POST['about']));
- $interest = escape_tags(trim($_POST['interest']));
- $contact = escape_tags(trim($_POST['contact']));
- $music = escape_tags(trim($_POST['music']));
- $book = escape_tags(trim($_POST['book']));
- $tv = escape_tags(trim($_POST['tv']));
- $film = escape_tags(trim($_POST['film']));
- $romance = escape_tags(trim($_POST['romance']));
- $work = escape_tags(trim($_POST['work']));
- $education = escape_tags(trim($_POST['education']));
+ $likes = Strings::escapeTags(trim($_POST['likes']));
+ $dislikes = Strings::escapeTags(trim($_POST['dislikes']));
+
+ $about = Strings::escapeTags(trim($_POST['about']));
+ $interest = Strings::escapeTags(trim($_POST['interest']));
+ $contact = Strings::escapeTags(trim($_POST['contact']));
+ $music = Strings::escapeTags(trim($_POST['music']));
+ $book = Strings::escapeTags(trim($_POST['book']));
+ $tv = Strings::escapeTags(trim($_POST['tv']));
+ $film = Strings::escapeTags(trim($_POST['film']));
+ $romance = Strings::escapeTags(trim($_POST['romance']));
+ $work = Strings::escapeTags(trim($_POST['work']));
+ $education = Strings::escapeTags(trim($_POST['education']));
$hide_friends = (($_POST['hide-friends'] == 1) ? 1: 0);
}
$subject = ((x($_REQUEST,'subject')) ? Strings::removeTags(trim($_REQUEST['subject'])) : '');
- $body = ((x($_REQUEST,'body')) ? escape_tags(trim($_REQUEST['body'])) : '');
+ $body = ((x($_REQUEST,'body')) ? Strings::escapeTags(trim($_REQUEST['body'])) : '');
$recipient = (($a->argc > 1) ? Strings::removeTags($a->argv[1]) : '');
if ((! $recipient) || (! $body)) {
'$recipname' => $user['username'],
'$nickname' => $user['nickname'],
'$subjtxt' => ((x($_REQUEST, 'subject')) ? strip_tags($_REQUEST['subject']) : ''),
- '$text' => ((x($_REQUEST, 'body')) ? escape_tags(htmlspecialchars($_REQUEST['body'])) : ''),
+ '$text' => ((x($_REQUEST, 'body')) ? Strings::escapeTags(htmlspecialchars($_REQUEST['body'])) : ''),
'$readonly' => '',
'$yourmessage' => L10n::t('Your message:'),
'$parent' => '',
$filesubtype = 'unkn';
}
- $title = escape_tags(trim(!empty($mtch[4]) ? $mtch[4] : $mtch[1]));
+ $title = Strings::escapeTags(trim(!empty($mtch[4]) ? $mtch[4] : $mtch[1]));
$title .= ' ' . $mtch[2] . ' ' . L10n::t('bytes');
$icon = '<div class="attachtype icon s22 type-' . $filetype . ' subtype-' . $filesubtype . '"></div>';
$fetch_further_information = intval(defaults($_POST, 'fetch_further_information', 0));
- $ffi_keyword_blacklist = escape_tags(trim(defaults($_POST, 'ffi_keyword_blacklist', '')));
+ $ffi_keyword_blacklist = Strings::escapeTags(trim(defaults($_POST, 'ffi_keyword_blacklist', '')));
$priority = intval(defaults($_POST, 'poll', 0));
if ($priority > 5 || $priority < 0) {
$priority = 0;
}
- $info = escape_tags(trim($_POST['info']));
+ $info = Strings::escapeTags(trim($_POST['info']));
$r = DBA::update('contact', [
'profile-id' => $profile_id,
use Friendica\BaseModule;
use Friendica\Core\System;
use Friendica\Database\DBA;
+use Friendica\Util\Strings;
require_once 'include/dba.php';
require_once 'include/text.php';
{
$result = [];
- $t = escape_tags($_REQUEST['t']);
+ $t = Strings::escapeTags($_REQUEST['t']);
if (empty($t)) {
System::jsonExit($result);
}
*
* @return string
*/
- public static function escapeTags($string) // escape_tags()
+ public static function escapeTags($string)
{
return htmlspecialchars($string, ENT_COMPAT, 'UTF-8', false);
}
Logger::log("Mail: can't fetch msg ".$msg_uid." for ".$mailconf['user']);
continue;
}
- $datarray['body'] = escape_tags($r['body']);
+ $datarray['body'] = Strings::escapeTags($r['body']);
$datarray['body'] = BBCode::limitBodySize($datarray['body']);
Logger::log("Mail: Importing ".$msg_uid." for ".$mailconf['user']);
$invalidstring='<submit type="button" onclick="alert(\'failed!\');" />';
$validstring = Friendica\Util\Strings::removeTags($invalidstring);
- $escapedString=escape_tags($invalidstring);
+ $escapedString = Friendica\Util\Strings::escapeTags($invalidstring);
$this->assertEquals('[submit type="button" onclick="alert(\'failed!\');" /]', $validstring);
$this->assertEquals(