a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
350 lines
No EOL
14 KiB
HTML
350 lines
No EOL
14 KiB
HTML
<?xml version="1.0" encoding="iso-8859-1"?>
|
|
<!DOCTYPE html
|
|
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
|
|
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
|
|
|
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
|
|
<head>
|
|
<title>Module: Erubis::PhpGenerator</title>
|
|
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
|
|
<meta http-equiv="Content-Script-Type" content="text/javascript" />
|
|
<link rel="stylesheet" href="../.././rdoc-style.css" type="text/css" media="screen" />
|
|
<script type="text/javascript">
|
|
// <![CDATA[
|
|
|
|
function popupCode( url ) {
|
|
window.open(url, "Code", "resizable=yes,scrollbars=yes,toolbar=no,status=no,height=150,width=400")
|
|
}
|
|
|
|
function toggleCode( id ) {
|
|
if ( document.getElementById )
|
|
elem = document.getElementById( id );
|
|
else if ( document.all )
|
|
elem = eval( "document.all." + id );
|
|
else
|
|
return false;
|
|
|
|
elemStyle = elem.style;
|
|
|
|
if ( elemStyle.display != "block" ) {
|
|
elemStyle.display = "block"
|
|
} else {
|
|
elemStyle.display = "none"
|
|
}
|
|
|
|
return true;
|
|
}
|
|
|
|
// Make codeblocks hidden by default
|
|
document.writeln( "<style type=\"text/css\">div.method-source-code { display: none }</style>" )
|
|
|
|
// ]]>
|
|
</script>
|
|
|
|
</head>
|
|
<body>
|
|
|
|
|
|
|
|
<div id="classHeader">
|
|
<table class="header-table">
|
|
<tr class="top-aligned-row">
|
|
<td><strong>Module</strong></td>
|
|
<td class="class-name-in-header">Erubis::PhpGenerator</td>
|
|
</tr>
|
|
<tr class="top-aligned-row">
|
|
<td><strong>In:</strong></td>
|
|
<td>
|
|
<a href="../../files/erubis/engine/ephp_rb.html">
|
|
erubis/engine/ephp.rb
|
|
</a>
|
|
<br />
|
|
</td>
|
|
</tr>
|
|
|
|
</table>
|
|
</div>
|
|
<!-- banner header -->
|
|
|
|
<div id="bodyContent">
|
|
|
|
|
|
|
|
<div id="contextContent">
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div id="method-list">
|
|
<h3 class="section-bar">Methods</h3>
|
|
|
|
<div class="name-list">
|
|
<a href="#M000125">add_expr_debug</a>
|
|
<a href="#M000124">add_expr_escaped</a>
|
|
<a href="#M000123">add_expr_literal</a>
|
|
<a href="#M000127">add_postamble</a>
|
|
<a href="#M000120">add_preamble</a>
|
|
<a href="#M000126">add_stmt</a>
|
|
<a href="#M000122">add_text</a>
|
|
<a href="#M000121">escape_text</a>
|
|
<a href="#M000119">init_generator</a>
|
|
</div>
|
|
</div>
|
|
|
|
</div>
|
|
|
|
|
|
<!-- if includes -->
|
|
<div id="includes">
|
|
<h3 class="section-bar">Included Modules</h3>
|
|
|
|
<div id="includes-list">
|
|
<span class="include-name"><a href="Generator.html">Generator</a></span>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="section">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<!-- if method_list -->
|
|
<div id="methods">
|
|
<h3 class="section-bar">Public Instance methods</h3>
|
|
|
|
<div id="method-M000125" class="method-detail">
|
|
<a name="M000125"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000125" class="method-signature">
|
|
<span class="method-name">add_expr_debug</span><span class="method-args">(src, code)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000125-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000125-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 46</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_expr_debug</span>(<span class="ruby-identifier">src</span>, <span class="ruby-identifier">code</span>)
|
|
<span class="ruby-identifier">code</span>.<span class="ruby-identifier">strip!</span>
|
|
<span class="ruby-identifier">s</span> = <span class="ruby-identifier">code</span>.<span class="ruby-identifier">gsub</span>(<span class="ruby-regexp re">/\'/</span>, <span class="ruby-value str">"\\'"</span>)
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-node">"<?php error_log('*** debug: #{s}='.(#{code}), 0); ?>"</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000124" class="method-detail">
|
|
<a name="M000124"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000124" class="method-signature">
|
|
<span class="method-name">add_expr_escaped</span><span class="method-args">(src, code)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000124-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000124-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 42</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_expr_escaped</span>(<span class="ruby-identifier">src</span>, <span class="ruby-identifier">code</span>)
|
|
<span class="ruby-identifier">add_expr_literal</span>(<span class="ruby-identifier">src</span>, <span class="ruby-identifier">escaped_expr</span>(<span class="ruby-identifier">code</span>))
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000123" class="method-detail">
|
|
<a name="M000123"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000123" class="method-signature">
|
|
<span class="method-name">add_expr_literal</span><span class="method-args">(src, code)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000123-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000123-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 37</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_expr_literal</span>(<span class="ruby-identifier">src</span>, <span class="ruby-identifier">code</span>)
|
|
<span class="ruby-identifier">code</span>.<span class="ruby-identifier">strip!</span>
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-node">"<?php echo #{code}; ?>"</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000127" class="method-detail">
|
|
<a name="M000127"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000127" class="method-signature">
|
|
<span class="method-name">add_postamble</span><span class="method-args">(src)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000127-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000127-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 63</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_postamble</span>(<span class="ruby-identifier">src</span>)
|
|
<span class="ruby-comment cmt"># empty</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000120" class="method-detail">
|
|
<a name="M000120"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000120" class="method-signature">
|
|
<span class="method-name">add_preamble</span><span class="method-args">(src)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000120-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000120-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 25</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_preamble</span>(<span class="ruby-identifier">src</span>)
|
|
<span class="ruby-comment cmt"># empty</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000126" class="method-detail">
|
|
<a name="M000126"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000126" class="method-signature">
|
|
<span class="method-name">add_stmt</span><span class="method-args">(src, code)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000126-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000126-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 52</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_stmt</span>(<span class="ruby-identifier">src</span>, <span class="ruby-identifier">code</span>)
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-value str">"<?php"</span>
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-value str">" "</span> <span class="ruby-keyword kw">if</span> <span class="ruby-identifier">code</span>[<span class="ruby-value">0</span>] <span class="ruby-operator">!=</span> <span class="ruby-value">?\ </span><span class="ruby-comment cmt">#</span>
|
|
<span class="ruby-keyword kw">if</span> <span class="ruby-identifier">code</span>[<span class="ruby-value">-1</span>] <span class="ruby-operator">==</span> <span class="ruby-value">?\n</span>
|
|
<span class="ruby-identifier">code</span>.<span class="ruby-identifier">chomp!</span>
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-identifier">code</span> <span class="ruby-operator"><<</span> <span class="ruby-value str">"?>\n"</span>
|
|
<span class="ruby-keyword kw">else</span>
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-identifier">code</span> <span class="ruby-operator"><<</span> <span class="ruby-value str">"?>"</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000122" class="method-detail">
|
|
<a name="M000122"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000122" class="method-signature">
|
|
<span class="method-name">add_text</span><span class="method-args">(src, text)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000122-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000122-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 33</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">add_text</span>(<span class="ruby-identifier">src</span>, <span class="ruby-identifier">text</span>)
|
|
<span class="ruby-identifier">src</span> <span class="ruby-operator"><<</span> <span class="ruby-identifier">escape_text</span>(<span class="ruby-identifier">text</span>)
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000121" class="method-detail">
|
|
<a name="M000121"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000121" class="method-signature">
|
|
<span class="method-name">escape_text</span><span class="method-args">(text)</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000121-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000121-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 29</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">escape_text</span>(<span class="ruby-identifier">text</span>)
|
|
<span class="ruby-keyword kw">return</span> <span class="ruby-identifier">text</span>.<span class="ruby-identifier">gsub!</span>(<span class="ruby-regexp re">/<\?xml\b/</span>, <span class="ruby-value str">'<<?php ?>?xml'</span>) <span class="ruby-operator">||</span> <span class="ruby-identifier">text</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="method-M000119" class="method-detail">
|
|
<a name="M000119"></a>
|
|
|
|
<div class="method-heading">
|
|
<a href="#M000119" class="method-signature">
|
|
<span class="method-name">init_generator</span><span class="method-args">(properties={})</span>
|
|
</a>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
<p><a class="source-toggle" href="#"
|
|
onclick="toggleCode('M000119-source');return false;">[Source]</a></p>
|
|
<div class="method-source-code" id="M000119-source">
|
|
<pre>
|
|
<span class="ruby-comment cmt"># File erubis/engine/ephp.rb, line 20</span>
|
|
<span class="ruby-keyword kw">def</span> <span class="ruby-identifier">init_generator</span>(<span class="ruby-identifier">properties</span>={})
|
|
<span class="ruby-keyword kw">super</span>
|
|
<span class="ruby-ivar">@escapefunc</span> <span class="ruby-operator">||=</span> <span class="ruby-value str">'htmlspecialchars'</span>
|
|
<span class="ruby-keyword kw">end</span>
|
|
</pre>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
|
|
</div>
|
|
|
|
|
|
</div>
|
|
|
|
|
|
<div id="validator-badges">
|
|
<p><small><a href="http://validator.w3.org/check/referer">[Validate]</a></small></p>
|
|
</div>
|
|
|
|
</body>
|
|
</html> |