Table of Contents
ProtectedPostService
Layer: Service · Source: lib/service/ProtectedPostService.php:27 (lines 27–111)
class ProtectedPostService
Application service resolving the ready-to-print content of a single post.
Owns the protected-vs-public render decision and the sanitization pipeline (double html_entity_decode, style-attribute strip, htmLawed whitelist) that previously lived inline in the single.php template. It never queries the database itself: the decrypted content is supplied by an injected decrypt callback (defaulting to the global decrypt_post() helper) so the service stays unit-testable without a live connection.
Docblock Metadata
| Tag | Value |
|---|---|
@category | Service |
@author | Scriptlog Team |
@license | MIT |
@version | 1.0 |
@since | Since Release 1.0 |
Inheritance
No parent, interface or trait. This is a root type.
Constants (0)
None.
Properties (1)
| Visibility | Type | Name | Default | Line |
|---|---|---|---|---|
private | (untyped) | $decryptPost | 34 |
Methods (3)
| Visibility | Method | Summary | Line |
|---|---|---|---|
| public | __construct() | Constructor. | 43 |
| public | resolve() | Resolve the content branch and unlocked state for a post row. | 61 |
| public | sanitizeContent() | Sanitize post content for safe output. | 107 |
__construct()
public function __construct(?callable $decryptPost = null)
lines 43–47 (5)
Constructor.
| Parameter | Type | Default | Description |
|---|---|---|---|
$decryptPost | ?callable | null | Callable (int $id, string $password) ⇒ array defaulting to the global decrypt_post() helper when available. |
resolve()
public function resolve(array $post, array $unlockedPosts = [])
lines 61–95 (35)
Resolve the content branch and unlocked state for a post row.
Determines whether the post is password-protected, whether the current session has unlocked it, and produces the sanitized, ready-to-print HTML content for the public/unlocked branches.
| Parameter | Type | Default | Description |
|---|---|---|---|
$post | array | required | The raw post row (requires ID, post_visibility, and post_content keys). |
$unlockedPosts | array | [] | Session store mapping post ID ⇒ password. |
Returns: (none declared) — array{id:int,is_protected:bool,is_unlocked:bool,show_password_form:bool,content:string}
sanitizeContent()
public function sanitizeContent(string $content): string
lines 107–110 (4)
Sanitize post content for safe output.
Applies the double html_entity_decode, strips inline style attributes, then runs the content through htmLawed with an event-handler/style blacklist. Preserves the exact pipeline previously inline in single.php.
| Parameter | Type | Default | Description |
|---|---|---|---|
$content | string | required | Raw, unsanitized post content. |
Returns: string — string Sanitized HTML safe to echo into the template.
This page is generated from source by 'tools/gendoc'. Edits will be overwritten.
