forked from php/php-src
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
DOMXPath::quote(string $str): string
method to quote strings in XPath, similar to PDO::quote() / mysqli::real_escape_string sample usage: $xp->query("//span[contains(text()," . $xp->quote($string) . ")]") the algorithm is derived from Robert Rossney's research into XPath quoting published at https://stackoverflow.com/a/1352556/1067003 (but using an improved implementation I wrote myself, originally for chrome-php/chrome#575 )
- Loading branch information
1 parent
7ed26c0
commit cffeadf
Showing
4 changed files
with
185 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,85 @@ | ||
--TEST-- | ||
Test DOMXPath::quote with various inputs | ||
--SKIPIF-- | ||
<?php if (!class_exists('DOMXPath')) die('skip DOMXPath not available.'); ?> | ||
--FILE-- | ||
<?php | ||
$dom = new DOMDocument(); | ||
$xpath = new DOMXPath($dom); | ||
|
||
// method to quote strings in XPath, similar to PDO::quote() | ||
|
||
/** | ||
* Quote a string for use in an XPath expression. | ||
* | ||
* Example: $xp->query("//span[contains(text()," . $xp->quote($string) . ")]") | ||
* | ||
* @param string $string string to quote. | ||
* @return string quoted string. | ||
*/ | ||
function UserlandDOMXPathQuote(string $string): string | ||
{ | ||
if (false === \strpos($string, '\'')) { | ||
return '\'' . $string . '\''; | ||
} | ||
if (false === \strpos($string, '"')) { | ||
return '"' . $string . '"'; | ||
} | ||
// if the string contains both single and double quotes, construct an | ||
// expression that concatenates all non-double-quote substrings with | ||
// the quotes, e.g.: | ||
// 'foo'"bar => concat("'foo'", '"bar") | ||
$sb = []; | ||
while ($string !== '') { | ||
$bytesUntilSingleQuote = \strcspn($string, '\''); | ||
$bytesUntilDoubleQuote = \strcspn($string, '"'); | ||
$quoteMethod = ($bytesUntilSingleQuote > $bytesUntilDoubleQuote) ? "'" : '"'; | ||
$bytesUntilQuote = \max($bytesUntilSingleQuote, $bytesUntilDoubleQuote); | ||
$sb[] = $quoteMethod . \substr($string, 0, $bytesUntilQuote) . $quoteMethod; | ||
$string = \substr($string, $bytesUntilQuote); | ||
} | ||
$sb = \implode(',', $sb); | ||
return 'concat(' . $sb . ')'; | ||
} | ||
|
||
|
||
|
||
$tests = [ | ||
'foo' => "'foo'", // no quotes | ||
'"foo' => '\'"foo\'', // double quotes only | ||
'\'foo' => '"\'foo"', // single quotes only | ||
'\'foo"bar' => 'concat("\'foo",\'"bar\')', // both; double quotes in mid-string | ||
'\'foo"bar"baz' => 'concat("\'foo",\'"bar"baz\')', // multiple double quotes in mid-string | ||
'\'foo"' => 'concat("\'foo",\'"\')', // string ends with double quotes | ||
'\'foo""' => 'concat("\'foo",\'""\')', // string ends with run of double quotes | ||
'"\'foo' => 'concat(\'"\',"\'foo")', // string begins with double quotes | ||
'""\'foo' => 'concat(\'""\',"\'foo")', // string begins with run of double quotes | ||
'\'foo""bar' => 'concat("\'foo",\'""bar\')', // run of double quotes in mid-string | ||
]; | ||
|
||
foreach ($tests as $input => $expected) { | ||
$result = $xpath->quote($input); | ||
if ($result === $expected) { | ||
echo "Pass: {$input} => {$result}\n"; | ||
} else { | ||
echo 'Fail: '; | ||
var_dump([ | ||
'input' => $input, | ||
'expected' => $expected, | ||
'result' => $result, | ||
'userland_implementation_result' => UserlandDOMXPathQuote($input), | ||
]); | ||
} | ||
} | ||
?> | ||
--EXPECT-- | ||
Pass: foo => 'foo' | ||
Pass: "foo => '"foo' | ||
Pass: 'foo => "'foo" | ||
Pass: 'foo"bar => concat("'foo",'"bar') | ||
Pass: 'foo"bar"baz => concat("'foo",'"bar"baz') | ||
Pass: 'foo" => concat("'foo",'"') | ||
Pass: 'foo"" => concat("'foo",'""') | ||
Pass: "'foo => concat('"',"'foo") | ||
Pass: ""'foo => concat('""',"'foo") | ||
Pass: 'foo""bar => concat("'foo",'""bar') |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters