====== ProtectedPostService ======
**Layer:** ''Service'' · **Source:** ''lib/service/ProtectedPostService.php:27'' (lines 27–111)
----
class ProtectedPostService
Application service resolving the ready-to-print content of a single post.
Owns the protected-vs-public render decision and the sanitization pipeline
(double html_entity_decode, style-attribute strip, htmLawed whitelist) that
previously lived inline in the single.php template. It never queries the
database itself: the decrypted content is supplied by an injected decrypt
callback (defaulting to the global decrypt_post() helper) so the service
stays unit-testable without a live connection.
======= Docblock Metadata =======
^ Tag ^ Value ^
| ''@category'' | Service |
| ''@author'' | Scriptlog Team |
| ''@license'' | MIT |
| ''@version'' | 1.0 |
| ''@since'' | Since Release 1.0 |
======= Inheritance =======
//No parent, interface or trait. This is a root type.//
======= Constants (0) =======
//None.//
======= Properties (1) =======
^ Visibility ^ Type ^ Name ^ Default ^ Line ^
| ''private'' | ''(untyped)'' | ''$decryptPost'' | | 34 |
======= Methods (3) =======
^ Visibility ^ Method ^ Summary ^ Line ^
| public | ''__construct()'' | Constructor. | 43 |
| public | ''resolve()'' | Resolve the content branch and unlocked state for a post row. | 61 |
| public | ''sanitizeContent()'' | Sanitize post content for safe output. | 107 |
======== __construct() ========
public function __construct(?callable $decryptPost = null)
//lines 43–47 (5)//
Constructor.
^ Parameter ^ Type ^ Default ^ Description ^
| ''$decryptPost'' | ''?callable'' | ''null'' | Callable (int $id, string $password) => array defaulting to the global decrypt_post() helper when available. |
======== resolve() ========
public function resolve(array $post, array $unlockedPosts = [])
//lines 61–95 (35)//
Resolve the content branch and unlocked state for a post row.
Determines whether the post is password-protected, whether the current
session has unlocked it, and produces the sanitized, ready-to-print
HTML content for the public/unlocked branches.
^ Parameter ^ Type ^ Default ^ Description ^
| ''$post'' | ''array'' | //required// | The raw post row (requires ID, post_visibility, and post_content keys). |
| ''$unlockedPosts'' | ''array'' | ''[]'' | Session store mapping post ID => password. |
**Returns:** ''(none declared)'' — array{id:int,is_protected:bool,is_unlocked:bool,show_password_form:bool,content:string}
======== sanitizeContent() ========
public function sanitizeContent(string $content): string
//lines 107–110 (4)//
Sanitize post content for safe output.
Applies the double html_entity_decode, strips inline style attributes,
then runs the content through htmLawed with an event-handler/style
blacklist. Preserves the exact pipeline previously inline in single.php.
^ Parameter ^ Type ^ Default ^ Description ^
| ''$content'' | ''string'' | //required// | Raw, unsanitized post content. |
**Returns:** ''string'' — string Sanitized HTML safe to echo into the template.
----
//This page is generated from source by 'tools/gendoc'. Edits will be overwritten.//