Scriptlog Docs

Scriptlog Documentation

Code reference for the Scriptlog codebase

User Tools

Site Tools


scriptlog:lib:service:protectedpostservice

This is an old revision of the document!


ProtectedPostService

Layer: Service · Source: lib/service/ProtectedPostService.php:27 (lines 27–111)


class ProtectedPostService

Application service resolving the ready-to-print content of a single post.

Owns the protected-vs-public render decision and the sanitization pipeline (double html_entity_decode, style-attribute strip, htmLawed whitelist) that previously lived inline in the single.php template. It never queries the database itself: the decrypted content is supplied by an injected decrypt callback (defaulting to the global decrypt_post() helper) so the service stays unit-testable without a live connection.

Docblock Metadata

^ Tag ^ Value ^
| ''@category'' | Service |
| ''@author'' | Scriptlog Team |
| ''@license'' | MIT |
| ''@version'' | 1.0 |
| ''@since'' | Since Release 1.0 |

Inheritance

No parent, interface or trait. This is a root type.

Constants (0)

None.

Properties (0)

None declared.

Methods (3)

^ Visibility ^ Method ^ Summary ^ Line ^
| public | ''__construct()'' | Constructor. | 43 |
| public | ''resolve()'' | Resolve the content branch and unlocked state for a post row. | 61 |
| public | ''sanitizeContent()'' | Sanitize post content for safe output. | 107 |

__construct()

public function __construct(?callable $decryptPost = null)

lines 43–47 (5)

Constructor.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$decryptPost'' | ''?callable'' | ''null'' | Callable (int $id, string $password) => array defaulting to the global decrypt_post() helper when available. |

resolve()

public function resolve(array $post, array $unlockedPosts = [])

lines 61–95 (35)

Resolve the content branch and unlocked state for a post row.

Determines whether the post is password-protected, whether the current session has unlocked it, and produces the sanitized, ready-to-print HTML content for the public/unlocked branches.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$post'' | ''array'' | //required// | The raw post row (requires ID, post_visibility, and post_content keys). |
| ''$unlockedPosts'' | ''array'' | ''[]'' | Session store mapping post ID => password. |

Returns: (none declared) — array{id:int,is_protected:bool,is_unlocked:bool,show_password_form:bool,content:string}

sanitizeContent()

public function sanitizeContent(string $content): string

lines 107–110 (4)

Sanitize post content for safe output.

Applies the double html_entity_decode, strips inline style attributes, then runs the content through htmLawed with an event-handler/style blacklist. Preserves the exact pipeline previously inline in single.php.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$content'' | ''string'' | //required// | Raw, unsanitized post content. |

Returns: string — string Sanitized HTML safe to echo into the template.


This page is generated from source by 'tools/gendoc'. Edits will be overwritten.

scriptlog/lib/service/protectedpostservice.1790413760.txt.gz · Last modified: by admin