Table of Contents

ProtectedPostService

Layer: Service · Source: lib/service/ProtectedPostService.php:27 (lines 27–111)


class ProtectedPostService

Application service resolving the ready-to-print content of a single post.

Owns the protected-vs-public render decision and the sanitization pipeline (double html_entity_decode, style-attribute strip, htmLawed whitelist) that previously lived inline in the single.php template. It never queries the database itself: the decrypted content is supplied by an injected decrypt callback (defaulting to the global decrypt_post() helper) so the service stays unit-testable without a live connection.

Docblock Metadata

Tag Value
@category Service
@author Scriptlog Team
@license MIT
@version 1.0
@since Since Release 1.0

Inheritance

No parent, interface or trait. This is a root type.

Constants (0)

None.

Properties (1)

Visibility Type Name Default Line
private (untyped) $decryptPost 34

Methods (3)

Visibility Method Summary Line
public __construct() Constructor. 43
public resolve() Resolve the content branch and unlocked state for a post row. 61
public sanitizeContent() Sanitize post content for safe output. 107

__construct()

public function __construct(?callable $decryptPost = null)

lines 43–47 (5)

Constructor.

Parameter Type Default Description
$decryptPost ?callable null Callable (int $id, string $password) ⇒ array defaulting to the global decrypt_post() helper when available.

resolve()

public function resolve(array $post, array $unlockedPosts = [])

lines 61–95 (35)

Resolve the content branch and unlocked state for a post row.

Determines whether the post is password-protected, whether the current session has unlocked it, and produces the sanitized, ready-to-print HTML content for the public/unlocked branches.

Parameter Type Default Description
$post array required The raw post row (requires ID, post_visibility, and post_content keys).
$unlockedPosts array [] Session store mapping post ID ⇒ password.

Returns: (none declared) — array{id:int,is_protected:bool,is_unlocked:bool,show_password_form:bool,content:string}

sanitizeContent()

public function sanitizeContent(string $content): string

lines 107–110 (4)

Sanitize post content for safe output.

Applies the double html_entity_decode, strips inline style attributes, then runs the content through htmLawed with an event-handler/style blacklist. Preserves the exact pipeline previously inline in single.php.

Parameter Type Default Description
$content string required Raw, unsanitized post content.

Returns: string — string Sanitized HTML safe to echo into the template.


This page is generated from source by 'tools/gendoc'. Edits will be overwritten.