[BUGFIX] Untrusted GP data is unserialized in wizard_colorpicker.php and view_help.php
[Packages/TYPO3.CMS.git] / t3lib / class.t3lib_extobjbase.php
1 <?php
2 /***************************************************************
3 * Copyright notice
4 *
5 * (c) 1999-2011 Kasper Skårhøj (kasperYYYY@typo3.com)
6 * All rights reserved
7 *
8 * This script is part of the TYPO3 project. The TYPO3 project is
9 * free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License as published by
11 * the Free Software Foundation; either version 2 of the License, or
12 * (at your option) any later version.
13 *
14 * The GNU General Public License can be found at
15 * http://www.gnu.org/copyleft/gpl.html.
16 * A copy is found in the textfile GPL.txt and important notices to the license
17 * from the author is found in LICENSE.txt distributed with these scripts.
18 *
19 *
20 * This script is distributed in the hope that it will be useful,
21 * but WITHOUT ANY WARRANTY; without even the implied warranty of
22 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
23 * GNU General Public License for more details.
24 *
25 * This copyright notice MUST APPEAR in all copies of the script!
26 ***************************************************************/
27 /**
28 * Contains the base class for 'Extension Objects' in backend modules.
29 *
30 * Revised for TYPO3 3.6 July/2003 by Kasper Skårhøj
31 *
32 * @author Kasper Skårhøj <kasperYYYY@typo3.com>
33 */
34
35
36 /**
37 * EXAMPLE: One level.
38 *
39 * This can be seen in the extension 'cms' where the info module have a function added. In 'ext_tables.php' this is done by this function call:
40 *
41 * t3lib_extMgm::insertModuleFunction(
42 * 'web_info',
43 * 'tx_cms_webinfo_page',
44 * t3lib_extMgm::extPath($_EXTKEY).'web_info/class.tx_cms_webinfo.php',
45 * 'LLL:EXT:cms/locallang_tca.php:mod_tx_cms_webinfo_page'
46 * );
47 *
48 *
49 *
50 * EXAMPLE: Two levels.
51 * This is the advanced example. You can see it with the extension 'func_wizards' which is the first layer but then providing another layer for extensions to connect by.
52 * The key used in TBE_MODULES_EXT is normally 'function' (for the 'function menu') but the 'func_wizards' extension uses an alternative key for its configuration: 'wiz'.
53 * In the 'ext_tables.php' file of an extension ('wizard_crpages') which uses the framework provided by 'func_wizards' this looks like this:
54 *
55 * t3lib_extMgm::insertModuleFunction(
56 * 'web_func',
57 * 'tx_wizardcrpages_webfunc_2',
58 * t3lib_extMgm::extPath($_EXTKEY).'class.tx_wizardcrpages_webfunc_2.php',
59 * 'LLL:EXT:wizard_crpages/locallang.php:wiz_crMany',
60 * 'wiz'
61 * );
62 *
63 * But for this two-level thing to work it also requires that the parent module (the real backend module) supports it.
64 * This is the case for the modules web_func and web_info since they have two times inclusion sections in their index.php scripts. For example (from web_func):
65 *
66 * // Make instance:
67 * $SOBE = t3lib_div::makeInstance("SC_mod_web_func_index");
68 * $SOBE->init();
69 *
70 * // Include files?
71 * foreach($SOBE->include_once as $INC_FILE) include_once($INC_FILE);
72 * $SOBE->checkExtObj(); // Checking for first level external objects
73 *
74 * // Repeat Include files! - if any files has been added by second-level extensions
75 * foreach($SOBE->include_once as $INC_FILE) include_once($INC_FILE);
76 * $SOBE->checkSubExtObj(); // Checking second level external objects
77 *
78 * $SOBE->main();
79 * $SOBE->printContent();
80 *
81 * Notice that the first part is as usual: Include classes and call $SOBE->checkExtObj() to initialize any level-1 sub-modules
82 * But then again ->include_once is traversed IF the initialization of the level-1 modules might have added more files!!
83 * And after that $SOBE->checkSubExtObj() is called to initialize the second level.
84 * In this way even a third level could be supported - but most likely that is a too layered model to be practical.
85 *
86 * Anyways, the final interesting thing is to see what the framework "func_wizard" actually does:
87 *
88 * class tx_funcwizards_webfunc extends t3lib_extobjbase {
89 * var $localLangFile = "locallang.php";
90 * var $function_key = "wiz";
91 * function init(&$pObj,$conf) {
92 * // OK, handles ordinary init. This includes setting up the menu array with ->modMenu
93 * parent::init($pObj,$conf);
94 * // Making sure that any further external classes are added to the include_once array. Notice that inclusion happens twice in the main script because of this!!!
95 * $this->handleExternalFunctionValue();
96 * }
97 * ....
98 *
99 * Notice that the handleExternalFunctionValue of this class (t3lib_extobjbase) is called and that the ->function_key internal var is set!
100 *
101 * The two level-2 sub-module "wizard_crpages" and "wizard_sortpages" are totally normal "submodules".
102 */
103
104 /**
105 * Parent class for 'Extension Objects' in backend modules.
106 * Used for 'submodules' to other modules. Also called 'Function menu modules' in t3lib_extMgm. And now its even called 'Extension Objects'. Or 'Module functions'. Wish we had just one name. Or a name at all...(?) Thank God its not so advanced when it works...
107 * In other words this class is used for backend modules which is not true backend modules appearing in the menu but rather adds themselves as a new entry in the function menu which typically exists for a backend module (like Web>Functions, Web>Info or Tools etc...)
108 * The magic that binds this together is stored in the global variable $TBE_MODULES_EXT where extensions wanting to connect a module based on this class to an existing backend module store configuration which consists of the classname, script-path and a label (title/name)
109 * For more information about this, please see the large example comment for the class t3lib_SCbase. This will show the principle of a 'level-1' connection.
110 * The more advanced example - having two layers as it is done by the 'func_wizards' extension with the 'web_info' module - can be seen in the comment above.
111 *
112 * @author Kasper Skårhøj <kasperYYYY@typo3.com>
113 * @package TYPO3
114 * @subpackage t3lib
115 * @see t3lib_SCbase,tx_funcwizards_webfunc::init(), tx_funcwizards_webfunc, tx_wizardsortpages_webfunc_2
116 */
117 class t3lib_extobjbase {
118
119 /**
120 * Contains a reference to the parent (calling) object (which is probably an instance of an extension class to t3lib_SCbase)
121 *
122 * @var t3lib_SCbase
123 * @see init()
124 */
125 var $pObj; // parent SC object
126
127 /**
128 * Set to the directory name of this class file.
129 * @see init()
130 */
131 var $thisPath = '';
132
133 /**
134 * Can be hardcoded to the name of a locallang.php file (from the same directory as the class file) to use/load
135 * @see incLocalLang()
136 */
137 var $localLangFile = 'locallang.php';
138
139 /**
140 * Contains module configuration parts from TBE_MODULES_EXT if found
141 *
142 * @see handleExternalFunctionValue()
143 */
144 var $extClassConf;
145
146 /**
147 * If this value is set it points to a key in the TBE_MODULES_EXT array (not on the top level..) where another classname/filepath/title can be defined for sub-subfunctions.
148 * This is a little hard to explain, so see it in action; it used in the extension 'func_wizards' in order to provide yet a layer of interfacing with the backend module.
149 * The extension 'func_wizards' has this description: 'Adds the 'Wizards' item to the function menu in Web>Func. This is just a framework for wizard extensions.' - so as you can see it is designed to allow further connectivity - 'level 2'
150 *
151 * @see handleExternalFunctionValue(), tx_funcwizards_webfunc
152 */
153 var $function_key = '';
154
155
156 /**
157 * Initialize the object
158 *
159 * @param object A reference to the parent (calling) object (which is probably an instance of an extension class to t3lib_SCbase)
160 * @param array The configuration set for this module - from global array TBE_MODULES_EXT
161 * @return void
162 * @see t3lib_SCbase::checkExtObj()
163 */
164 function init(&$pObj, $conf) {
165 $this->pObj = $pObj;
166
167 // Path of this script:
168 $this->thisPath = dirname($conf['path']);
169 if (!@is_dir($this->thisPath)) {
170 throw new RuntimeException(
171 'TYPO3 Fatal Error: Extension "' . $this->thisPath . ' was not a directory as expected...',
172 1270853912
173 );
174 }
175
176 // Local lang:
177 $this->incLocalLang();
178
179 // Setting MOD_MENU items as we need them for logging:
180 $this->pObj->MOD_MENU = array_merge($this->pObj->MOD_MENU, $this->modMenu()); // Candidate for t3lib_div::array_merge() if integer-keys will some day make trouble...
181 }
182
183 /**
184 * If $this->function_key is set (which means there are two levels of object connectivity) then $this->extClassConf is loaded with the TBE_MODULES_EXT configuration for that sub-sub-module
185 *
186 * @return void
187 * @see $function_key, tx_funcwizards_webfunc::init()
188 */
189 function handleExternalFunctionValue() {
190 // Must clean first to make sure the correct key is set...
191 $this->pObj->MOD_SETTINGS = t3lib_BEfunc::getModuleData($this->pObj->MOD_MENU, t3lib_div::_GP('SET'), $this->pObj->MCONF['name']);
192 if ($this->function_key) {
193 $this->extClassConf = $this->pObj->getExternalItemConfig($this->pObj->MCONF['name'], $this->function_key, $this->pObj->MOD_SETTINGS[$this->function_key]);
194 if (is_array($this->extClassConf) && $this->extClassConf['path']) {
195 $this->pObj->include_once[] = $this->extClassConf['path'];
196 }
197 }
198 }
199
200 /**
201 * Including any locallang file configured and merging its content over the current global LOCAL_LANG array (which is EXPECTED to exist!!!)
202 *
203 * @return void
204 */
205 function incLocalLang() {
206 #if ($this->localLangFile && @is_file($this->thisPath.'/'.$this->localLangFile)) {
207 # include($this->thisPath.'/'.$this->localLangFile);
208 if ($this->localLangFile && (@is_file($this->thisPath . '/' . $this->localLangFile) || @is_file($this->thisPath . '/' . substr($this->localLangFile, 0, -4) . '.xml'))) {
209 $LOCAL_LANG = $GLOBALS['LANG']->includeLLFile($this->thisPath . '/' . $this->localLangFile, FALSE);
210 if (is_array($LOCAL_LANG)) {
211 $GLOBALS['LOCAL_LANG'] = t3lib_div::array_merge_recursive_overrule((array) $GLOBALS['LOCAL_LANG'], $LOCAL_LANG);
212 }
213 }
214 }
215
216 /**
217 * Same as t3lib_SCbase::checkExtObj()
218 *
219 * @return void
220 * @see t3lib_SCbase::checkExtObj()
221 */
222 function checkExtObj() {
223 if (is_array($this->extClassConf) && $this->extClassConf['name']) {
224 $this->extObj = t3lib_div::makeInstance($this->extClassConf['name']);
225 $this->extObj->init($this->pObj, $this->extClassConf);
226
227 // Re-write:
228 $this->pObj->MOD_SETTINGS = t3lib_BEfunc::getModuleData($this->pObj->MOD_MENU, t3lib_div::_GP('SET'), $this->pObj->MCONF['name']);
229 }
230 }
231
232 /**
233 * Calls the main function inside ANOTHER sub-submodule which might exist.
234 *
235 * @return void
236 */
237 function extObjContent() {
238 if (is_object($this->extObj)) {
239 return $this->extObj->main();
240 }
241 }
242
243 /**
244 * Dummy function - but is used to set up additional menu items for this submodule.
245 * For an example see the extension 'cms' where the 'web_info' submodule is defined in cms/web_info/class.tx_cms_webinfo.php, tx_cms_webinfo_page::modMenu()
246 *
247 * @return array A MOD_MENU array which will be merged together with the one from the parent object
248 * @see init(), tx_cms_webinfo_page::modMenu()
249 */
250 function modMenu() {
251 return array();
252 }
253 }
254
255 ?>