blob: ae88dfc077e1c1073efb97c72bc4d73fe07129fa [file] [log] [blame]
Andrey Andreevc5536aa2012-11-01 17:33:58 +02001<?php
Derek Allard2067d1a2008-11-13 22:59:24 +00002/**
3 * CodeIgniter
4 *
Andrey Andreevfe9309d2015-01-09 17:48:58 +02005 * An open source application development framework for PHP
Derek Allard2067d1a2008-11-13 22:59:24 +00006 *
Andrey Andreevbdb96ca2014-10-28 00:13:31 +02007 * This content is released under the MIT License (MIT)
Andrey Andreeva381d172012-01-06 19:19:37 +02008 *
Andrey Andreev125ef472016-01-11 12:33:00 +02009 * Copyright (c) 2014 - 2016, British Columbia Institute of Technology
Andrey Andreeva381d172012-01-06 19:19:37 +020010 *
Andrey Andreevbdb96ca2014-10-28 00:13:31 +020011 * Permission is hereby granted, free of charge, to any person obtaining a copy
12 * of this software and associated documentation files (the "Software"), to deal
13 * in the Software without restriction, including without limitation the rights
14 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
15 * copies of the Software, and to permit persons to whom the Software is
16 * furnished to do so, subject to the following conditions:
Derek Jonesf4a4bd82011-10-20 12:18:42 -050017 *
Andrey Andreevbdb96ca2014-10-28 00:13:31 +020018 * The above copyright notice and this permission notice shall be included in
19 * all copies or substantial portions of the Software.
20 *
21 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
22 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
23 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
24 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
25 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
26 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
27 * THE SOFTWARE.
28 *
29 * @package CodeIgniter
30 * @author EllisLab Dev Team
darwinel871754a2014-02-11 17:34:57 +010031 * @copyright Copyright (c) 2008 - 2014, EllisLab, Inc. (http://ellislab.com/)
Andrey Andreev125ef472016-01-11 12:33:00 +020032 * @copyright Copyright (c) 2014 - 2016, British Columbia Institute of Technology (http://bcit.ca/)
Andrey Andreevbdb96ca2014-10-28 00:13:31 +020033 * @license http://opensource.org/licenses/MIT MIT License
34 * @link http://codeigniter.com
35 * @since Version 1.0.0
Derek Allard2067d1a2008-11-13 22:59:24 +000036 * @filesource
37 */
Andrey Andreevc5536aa2012-11-01 17:33:58 +020038defined('BASEPATH') OR exit('No direct script access allowed');
Derek Allard2067d1a2008-11-13 22:59:24 +000039
Derek Allard2067d1a2008-11-13 22:59:24 +000040/**
41 * CodeIgniter Security Helpers
42 *
43 * @package CodeIgniter
44 * @subpackage Helpers
45 * @category Helpers
Derek Jonesf4a4bd82011-10-20 12:18:42 -050046 * @author EllisLab Dev Team
Derek Allard2067d1a2008-11-13 22:59:24 +000047 * @link http://codeigniter.com/user_guide/helpers/security_helper.html
48 */
49
50// ------------------------------------------------------------------------
51
Derek Allard2067d1a2008-11-13 22:59:24 +000052if ( ! function_exists('xss_clean'))
53{
Timothy Warrenb75faa12012-04-27 12:03:32 -040054 /**
55 * XSS Filtering
56 *
57 * @param string
58 * @param bool whether or not the content is an image file
59 * @return string
60 */
Derek Jonesf0bcb3c2009-02-10 18:40:21 +000061 function xss_clean($str, $is_image = FALSE)
Derek Allard2067d1a2008-11-13 22:59:24 +000062 {
Andrey Andreev119d8a72014-01-08 15:27:53 +020063 return get_instance()->security->xss_clean($str, $is_image);
Derek Allard2067d1a2008-11-13 22:59:24 +000064 }
65}
66
Derek Allard4433f422010-07-23 08:47:34 -040067// ------------------------------------------------------------------------
68
Derek Allard4433f422010-07-23 08:47:34 -040069if ( ! function_exists('sanitize_filename'))
70{
Timothy Warrenb75faa12012-04-27 12:03:32 -040071 /**
72 * Sanitize Filename
73 *
74 * @param string
75 * @return string
76 */
Derek Allard4433f422010-07-23 08:47:34 -040077 function sanitize_filename($filename)
78 {
Andrey Andreev119d8a72014-01-08 15:27:53 +020079 return get_instance()->security->sanitize_filename($filename);
Derek Allard4433f422010-07-23 08:47:34 -040080 }
81}
82
Derek Allard2067d1a2008-11-13 22:59:24 +000083// --------------------------------------------------------------------
84
Derek Allard8719a5c2009-10-08 16:42:59 +000085if ( ! function_exists('do_hash'))
Barry Mienydd671972010-10-04 16:33:58 +020086{
Timothy Warrenb75faa12012-04-27 12:03:32 -040087 /**
88 * Hash encode a string
89 *
Andrey Andreev29d909d2012-10-27 01:05:09 +030090 * @todo Remove in version 3.1+.
91 * @deprecated 3.0.0 Use PHP's native hash() instead.
92 * @param string $str
93 * @param string $type = 'sha1'
Timothy Warrenb75faa12012-04-27 12:03:32 -040094 * @return string
95 */
Derek Allard8719a5c2009-10-08 16:42:59 +000096 function do_hash($str, $type = 'sha1')
Derek Allard2067d1a2008-11-13 22:59:24 +000097 {
Andrey Andreev7eea3062012-03-19 12:58:45 +020098 if ( ! in_array(strtolower($type), hash_algos()))
Andrey Andreev50bff7c2012-03-19 12:16:38 +020099 {
100 $type = 'md5';
101 }
102
freewil8840c962012-03-18 15:23:09 -0400103 return hash($type, $str);
Derek Allard2067d1a2008-11-13 22:59:24 +0000104 }
105}
Barry Mienydd671972010-10-04 16:33:58 +0200106
Derek Allard2067d1a2008-11-13 22:59:24 +0000107// ------------------------------------------------------------------------
108
Derek Allard2067d1a2008-11-13 22:59:24 +0000109if ( ! function_exists('strip_image_tags'))
110{
Timothy Warrenb75faa12012-04-27 12:03:32 -0400111 /**
112 * Strip Image Tags
113 *
114 * @param string
115 * @return string
116 */
Derek Allard2067d1a2008-11-13 22:59:24 +0000117 function strip_image_tags($str)
118 {
Andrey Andreev119d8a72014-01-08 15:27:53 +0200119 return get_instance()->security->strip_image_tags($str);
Derek Allard2067d1a2008-11-13 22:59:24 +0000120 }
121}
Barry Mienydd671972010-10-04 16:33:58 +0200122
Derek Allard2067d1a2008-11-13 22:59:24 +0000123// ------------------------------------------------------------------------
124
Derek Allard2067d1a2008-11-13 22:59:24 +0000125if ( ! function_exists('encode_php_tags'))
126{
Timothy Warrenb75faa12012-04-27 12:03:32 -0400127 /**
128 * Convert PHP tags to entities
129 *
130 * @param string
131 * @return string
132 */
Derek Allard2067d1a2008-11-13 22:59:24 +0000133 function encode_php_tags($str)
134 {
vkeranov3c298dc2012-07-12 11:04:02 +0300135 return str_replace(array('<?', '?>'), array('&lt;?', '?&gt;'), $str);
Derek Allard2067d1a2008-11-13 22:59:24 +0000136 }
137}