====== ProtectedPostService ====== **Layer:** ''Service'' · **Source:** ''lib/service/ProtectedPostService.php:27'' (lines 27–111) ---- class ProtectedPostService Application service resolving the ready-to-print content of a single post. Owns the protected-vs-public render decision and the sanitization pipeline (double html_entity_decode, style-attribute strip, htmLawed whitelist) that previously lived inline in the single.php template. It never queries the database itself: the decrypted content is supplied by an injected decrypt callback (defaulting to the global decrypt_post() helper) so the service stays unit-testable without a live connection. ======= Docblock Metadata ======= ^ Tag ^ Value ^ | ''@category'' | Service | | ''@author'' | Scriptlog Team | | ''@license'' | MIT | | ''@version'' | 1.0 | | ''@since'' | Since Release 1.0 | ======= Inheritance ======= //No parent, interface or trait. This is a root type.// ======= Constants (0) ======= //None.// ======= Properties (1) ======= ^ Visibility ^ Type ^ Name ^ Default ^ Line ^ | ''private'' | ''(untyped)'' | ''$decryptPost'' | | 34 | ======= Methods (3) ======= ^ Visibility ^ Method ^ Summary ^ Line ^ | public | ''__construct()'' | Constructor. | 43 | | public | ''resolve()'' | Resolve the content branch and unlocked state for a post row. | 61 | | public | ''sanitizeContent()'' | Sanitize post content for safe output. | 107 | ======== __construct() ======== public function __construct(?callable $decryptPost = null) //lines 43–47 (5)// Constructor. ^ Parameter ^ Type ^ Default ^ Description ^ | ''$decryptPost'' | ''?callable'' | ''null'' | Callable (int $id, string $password) => array defaulting to the global decrypt_post() helper when available. | ======== resolve() ======== public function resolve(array $post, array $unlockedPosts = []) //lines 61–95 (35)// Resolve the content branch and unlocked state for a post row. Determines whether the post is password-protected, whether the current session has unlocked it, and produces the sanitized, ready-to-print HTML content for the public/unlocked branches. ^ Parameter ^ Type ^ Default ^ Description ^ | ''$post'' | ''array'' | //required// | The raw post row (requires ID, post_visibility, and post_content keys). | | ''$unlockedPosts'' | ''array'' | ''[]'' | Session store mapping post ID => password. | **Returns:** ''(none declared)'' — array{id:int,is_protected:bool,is_unlocked:bool,show_password_form:bool,content:string} ======== sanitizeContent() ======== public function sanitizeContent(string $content): string //lines 107–110 (4)// Sanitize post content for safe output. Applies the double html_entity_decode, strips inline style attributes, then runs the content through htmLawed with an event-handler/style blacklist. Preserves the exact pipeline previously inline in single.php. ^ Parameter ^ Type ^ Default ^ Description ^ | ''$content'' | ''string'' | //required// | Raw, unsanitized post content. | **Returns:** ''string'' — string Sanitized HTML safe to echo into the template. ---- //This page is generated from source by 'tools/gendoc'. Edits will be overwritten.//