MDL-41921 mod_url: less restrictions on URL field
[moodle.git] / mod / url / mod_form.php
CommitLineData
58a27a74 1<?php
2
3// This file is part of Moodle - http://moodle.org/
4//
5// Moodle is free software: you can redistribute it and/or modify
6// it under the terms of the GNU General Public License as published by
7// the Free Software Foundation, either version 3 of the License, or
8// (at your option) any later version.
9//
10// Moodle is distributed in the hope that it will be useful,
11// but WITHOUT ANY WARRANTY; without even the implied warranty of
12// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13// GNU General Public License for more details.
14//
15// You should have received a copy of the GNU General Public License
16// along with Moodle. If not, see <http://www.gnu.org/licenses/>.
17
18/**
19 * URL configuration form
20 *
2b641d15
PS
21 * @package mod
22 * @subpackage url
23 * @copyright 2009 Petr Skoda {@link http://skodak.org}
24 * @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
58a27a74 25 */
26
2b641d15 27defined('MOODLE_INTERNAL') || die;
bfebaf64 28
58a27a74 29require_once ($CFG->dirroot.'/course/moodleform_mod.php');
30require_once($CFG->dirroot.'/mod/url/locallib.php');
31
32class mod_url_mod_form extends moodleform_mod {
33 function definition() {
34 global $CFG, $DB;
35 $mform = $this->_form;
36
37 $config = get_config('url');
38
39 //-------------------------------------------------------
40 $mform->addElement('header', 'general', get_string('general', 'form'));
41 $mform->addElement('text', 'name', get_string('name'), array('size'=>'48'));
42 if (!empty($CFG->formatstringstriptags)) {
43 $mform->setType('name', PARAM_TEXT);
44 } else {
b8ea3041 45 $mform->setType('name', PARAM_CLEANHTML);
58a27a74 46 }
47 $mform->addRule('name', null, 'required', null, 'client');
a74cd331 48 $mform->addRule('name', get_string('maximumchars', '', 255), 'maxlength', 255, 'client');
58a27a74 49 $this->add_intro_editor($config->requiremodintro);
50
51 //-------------------------------------------------------
52 $mform->addElement('header', 'content', get_string('contentheader', 'url'));
e5dd8e3b 53 $mform->addElement('url', 'externalurl', get_string('externalurl', 'url'), array('size'=>'60'), array('usefilepicker'=>true));
47164284 54 $mform->setType('externalurl', PARAM_RAW_TRIMMED);
ec3c9dad 55 $mform->addRule('externalurl', null, 'required', null, 'client');
5c5317ae
FM
56 $mform->setExpanded('content');
57
58a27a74 58 //-------------------------------------------------------
9cf26d08 59 $mform->addElement('header', 'optionssection', get_string('appearance'));
58a27a74 60
61 if ($this->current->instance) {
62 $options = resourcelib_get_displayoptions(explode(',', $config->displayoptions), $this->current->display);
63 } else {
64 $options = resourcelib_get_displayoptions(explode(',', $config->displayoptions));
65 }
66 if (count($options) == 1) {
67 $mform->addElement('hidden', 'display');
d18e0fe6 68 $mform->setType('display', PARAM_INT);
58a27a74 69 reset($options);
70 $mform->setDefault('display', key($options));
71 } else {
72 $mform->addElement('select', 'display', get_string('displayselect', 'url'), $options);
73 $mform->setDefault('display', $config->display);
a4330d14 74 $mform->addHelpButton('display', 'displayselect', 'url');
58a27a74 75 }
76
77 if (array_key_exists(RESOURCELIB_DISPLAY_POPUP, $options)) {
78 $mform->addElement('text', 'popupwidth', get_string('popupwidth', 'url'), array('size'=>3));
79 if (count($options) > 1) {
80 $mform->disabledIf('popupwidth', 'display', 'noteq', RESOURCELIB_DISPLAY_POPUP);
81 }
82 $mform->setType('popupwidth', PARAM_INT);
83 $mform->setDefault('popupwidth', $config->popupwidth);
58a27a74 84
85 $mform->addElement('text', 'popupheight', get_string('popupheight', 'url'), array('size'=>3));
86 if (count($options) > 1) {
87 $mform->disabledIf('popupheight', 'display', 'noteq', RESOURCELIB_DISPLAY_POPUP);
88 }
89 $mform->setType('popupheight', PARAM_INT);
90 $mform->setDefault('popupheight', $config->popupheight);
58a27a74 91 }
92
93 if (array_key_exists(RESOURCELIB_DISPLAY_AUTO, $options) or
94 array_key_exists(RESOURCELIB_DISPLAY_EMBED, $options) or
95 array_key_exists(RESOURCELIB_DISPLAY_FRAME, $options)) {
58a27a74 96 $mform->addElement('checkbox', 'printintro', get_string('printintro', 'url'));
97 $mform->disabledIf('printintro', 'display', 'eq', RESOURCELIB_DISPLAY_POPUP);
98 $mform->disabledIf('printintro', 'display', 'eq', RESOURCELIB_DISPLAY_OPEN);
99 $mform->disabledIf('printintro', 'display', 'eq', RESOURCELIB_DISPLAY_NEW);
100 $mform->setDefault('printintro', $config->printintro);
58a27a74 101 }
102
103 //-------------------------------------------------------
104 $mform->addElement('header', 'parameterssection', get_string('parametersheader', 'url'));
f08e5e98 105 $mform->addElement('static', 'parametersinfo', '', get_string('parametersheader_help', 'url'));
58a27a74 106
107 if (empty($this->current->parameters)) {
108 $parcount = 5;
109 } else {
110 $parcount = 5 + count(unserialize($this->current->parameters));
111 $parcount = ($parcount > 100) ? 100 : $parcount;
112 }
113 $options = url_get_variable_options($config);
114
115 for ($i=0; $i < $parcount; $i++) {
116 $parameter = "parameter_$i";
117 $variable = "variable_$i";
118 $pargroup = "pargoup_$i";
119 $group = array(
120 $mform->createElement('text', $parameter, '', array('size'=>'12')),
121 $mform->createElement('selectgroups', $variable, '', $options),
122 );
123 $mform->addGroup($group, $pargroup, get_string('parameterinfo', 'url'), ' ', false);
914077b4 124 $mform->setType($parameter, PARAM_RAW);
58a27a74 125 }
126
127 //-------------------------------------------------------
128 $this->standard_coursemodule_elements();
129
130 //-------------------------------------------------------
131 $this->add_action_buttons();
132 }
133
134 function data_preprocessing(&$default_values) {
135 if (!empty($default_values['displayoptions'])) {
136 $displayoptions = unserialize($default_values['displayoptions']);
137 if (isset($displayoptions['printintro'])) {
138 $default_values['printintro'] = $displayoptions['printintro'];
139 }
58a27a74 140 if (!empty($displayoptions['popupwidth'])) {
141 $default_values['popupwidth'] = $displayoptions['popupwidth'];
142 }
143 if (!empty($displayoptions['popupheight'])) {
144 $default_values['popupheight'] = $displayoptions['popupheight'];
145 }
146 }
147 if (!empty($default_values['parameters'])) {
148 $parameters = unserialize($default_values['parameters']);
149 $i = 0;
150 foreach ($parameters as $parameter=>$variable) {
151 $default_values['parameter_'.$i] = $parameter;
152 $default_values['variable_'.$i] = $variable;
153 $i++;
154 }
155 }
156 }
157
4373200f
AKA
158 function validation($data, $files) {
159 $errors = parent::validation($data, $files);
48f69e41
PS
160
161 // Validating Entered url, we are looking for obvious problems only,
162 // teachers are responsible for testing if it actually works.
163
164 // This is not a security validation!! Teachers are allowed to enter "javascript:alert(666)" for example.
165
166 // NOTE: do not try to explain the difference between URL and URI, people would be only confused...
167
47164284
MG
168 if (!empty($data['externalurl'])) {
169 $url = $data['externalurl'];
170 if (preg_match('|^/|', $url)) {
48f69e41
PS
171 // links relative to server root are ok - no validation necessary
172
173 } else if (preg_match('|^[a-z]+://|i', $url) or preg_match('|^https?:|i', $url) or preg_match('|^ftp:|i', $url)) {
174 // normal URL
175 if (!url_appears_valid_url($url)) {
176 $errors['externalurl'] = get_string('invalidurl', 'url');
177 }
178
179 } else if (preg_match('|^[a-z]+:|i', $url)) {
180 // general URI such as teamspeak, mailto, etc. - it may or may not work in all browsers,
181 // we do not validate these at all, sorry
182
183 } else {
184 // invalid URI, we try to fix it by adding 'http://' prefix,
185 // relative links are NOT allowed because we display the link on different pages!
186 if (!url_appears_valid_url('http://'.$url)) {
187 $errors['externalurl'] = get_string('invalidurl', 'url');
188 }
189 }
4373200f
AKA
190 }
191 return $errors;
192 }
193
58a27a74 194}