Validation.php 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813
  1. <?php
  2. /**
  3. * @package Grav\Common\Data
  4. *
  5. * @copyright Copyright (C) 2015 - 2019 Trilby Media, LLC. All rights reserved.
  6. * @license MIT License; see LICENSE file for details.
  7. */
  8. namespace Grav\Common\Data;
  9. use Grav\Common\Grav;
  10. use Grav\Common\Utils;
  11. use Grav\Common\Yaml;
  12. class Validation
  13. {
  14. /**
  15. * Validate value against a blueprint field definition.
  16. *
  17. * @param mixed $value
  18. * @param array $field
  19. * @return array
  20. */
  21. public static function validate($value, array $field)
  22. {
  23. if (!isset($field['type'])) {
  24. $field['type'] = 'text';
  25. }
  26. $validate = (array)($field['validate'] ?? null);
  27. $type = $validate['type'] ?? $field['type'];
  28. $required = $validate['required'] ?? false;
  29. // If value isn't required, we will stop validation if empty value is given.
  30. if ($required !== true && ($value === null || $value === '' || (($field['type'] === 'checkbox' || $field['type'] === 'switch') && $value == false))
  31. ) {
  32. return [];
  33. }
  34. // Get language class.
  35. $language = Grav::instance()['language'];
  36. $name = ucfirst($field['label'] ?? $field['name']);
  37. $message = (string) isset($field['validate']['message'])
  38. ? $language->translate($field['validate']['message'])
  39. : $language->translate('GRAV.FORM.INVALID_INPUT', null, true) . ' "' . $language->translate($name) . '"';
  40. // Validate type with fallback type text.
  41. $method = 'type' . str_replace('-', '_', $type);
  42. // If this is a YAML field validate/filter as such
  43. if (isset($field['yaml']) && $field['yaml'] === true) {
  44. $method = 'typeYaml';
  45. }
  46. $messages = [];
  47. $success = method_exists(__CLASS__, $method) ? self::$method($value, $validate, $field) : true;
  48. if (!$success) {
  49. $messages[$field['name']][] = $message;
  50. }
  51. // Check individual rules.
  52. foreach ($validate as $rule => $params) {
  53. $method = 'validate' . ucfirst(str_replace('-', '_', $rule));
  54. if (method_exists(__CLASS__, $method)) {
  55. $success = self::$method($value, $params);
  56. if (!$success) {
  57. $messages[$field['name']][] = $message;
  58. }
  59. }
  60. }
  61. return $messages;
  62. }
  63. /**
  64. * Filter value against a blueprint field definition.
  65. *
  66. * @param mixed $value
  67. * @param array $field
  68. * @return mixed Filtered value.
  69. */
  70. public static function filter($value, array $field)
  71. {
  72. $validate = (array)($field['filter'] ?? $field['validate'] ?? null);
  73. // If value isn't required, we will return null if empty value is given.
  74. if (($value === null || $value === '') && empty($validate['required'])) {
  75. return null;
  76. }
  77. if (!isset($field['type'])) {
  78. $field['type'] = 'text';
  79. }
  80. $type = $field['filter']['type'] ?? $field['validate']['type'] ?? $field['type'];
  81. $method = 'filter' . ucfirst(str_replace('-', '_', $type));
  82. // If this is a YAML field validate/filter as such
  83. if (isset($field['yaml']) && $field['yaml'] === true) {
  84. $method = 'filterYaml';
  85. }
  86. if (!method_exists(__CLASS__, $method)) {
  87. $method = isset($field['array']) && $field['array'] === true ? 'filterArray' : 'filterText';
  88. }
  89. return self::$method($value, $validate, $field);
  90. }
  91. /**
  92. * HTML5 input: text
  93. *
  94. * @param mixed $value Value to be validated.
  95. * @param array $params Validation parameters.
  96. * @param array $field Blueprint for the field.
  97. * @return bool True if validation succeeded.
  98. */
  99. public static function typeText($value, array $params, array $field)
  100. {
  101. if (!\is_string($value) && !is_numeric($value)) {
  102. return false;
  103. }
  104. $value = (string)$value;
  105. if (!empty($params['trim'])) {
  106. $value = trim($value);
  107. }
  108. if (isset($params['min']) && \strlen($value) < $params['min']) {
  109. return false;
  110. }
  111. if (isset($params['max']) && \strlen($value) > $params['max']) {
  112. return false;
  113. }
  114. $min = $params['min'] ?? 0;
  115. if (isset($params['step']) && (\strlen($value) - $min) % $params['step'] === 0) {
  116. return false;
  117. }
  118. if ((!isset($params['multiline']) || !$params['multiline']) && preg_match('/\R/um', $value)) {
  119. return false;
  120. }
  121. return true;
  122. }
  123. protected static function filterText($value, array $params, array $field)
  124. {
  125. if (!\is_string($value) && !is_numeric($value)) {
  126. return '';
  127. }
  128. if (!empty($params['trim'])) {
  129. $value = trim($value);
  130. }
  131. return (string) $value;
  132. }
  133. /**
  134. * @param mixed $value
  135. * @param array $params
  136. * @param array $field
  137. * @return string|null
  138. */
  139. protected static function filterCheckbox($value, array $params, array $field)
  140. {
  141. $value = (string)$value;
  142. $field_value = (string)($field['value'] ?? '1');
  143. return $value === $field_value ? $value : null;
  144. }
  145. protected static function filterCommaList($value, array $params, array $field)
  146. {
  147. return \is_array($value) ? $value : preg_split('/\s*,\s*/', $value, -1, PREG_SPLIT_NO_EMPTY);
  148. }
  149. public static function typeCommaList($value, array $params, array $field)
  150. {
  151. return \is_array($value) ? true : self::typeText($value, $params, $field);
  152. }
  153. protected static function filterLower($value, array $params)
  154. {
  155. return strtolower($value);
  156. }
  157. protected static function filterUpper($value, array $params)
  158. {
  159. return strtoupper($value);
  160. }
  161. /**
  162. * HTML5 input: textarea
  163. *
  164. * @param mixed $value Value to be validated.
  165. * @param array $params Validation parameters.
  166. * @param array $field Blueprint for the field.
  167. * @return bool True if validation succeeded.
  168. */
  169. public static function typeTextarea($value, array $params, array $field)
  170. {
  171. if (!isset($params['multiline'])) {
  172. $params['multiline'] = true;
  173. }
  174. return self::typeText($value, $params, $field);
  175. }
  176. /**
  177. * HTML5 input: password
  178. *
  179. * @param mixed $value Value to be validated.
  180. * @param array $params Validation parameters.
  181. * @param array $field Blueprint for the field.
  182. * @return bool True if validation succeeded.
  183. */
  184. public static function typePassword($value, array $params, array $field)
  185. {
  186. return self::typeText($value, $params, $field);
  187. }
  188. /**
  189. * HTML5 input: hidden
  190. *
  191. * @param mixed $value Value to be validated.
  192. * @param array $params Validation parameters.
  193. * @param array $field Blueprint for the field.
  194. * @return bool True if validation succeeded.
  195. */
  196. public static function typeHidden($value, array $params, array $field)
  197. {
  198. return self::typeText($value, $params, $field);
  199. }
  200. /**
  201. * Custom input: checkbox list
  202. *
  203. * @param mixed $value Value to be validated.
  204. * @param array $params Validation parameters.
  205. * @param array $field Blueprint for the field.
  206. * @return bool True if validation succeeded.
  207. */
  208. public static function typeCheckboxes($value, array $params, array $field)
  209. {
  210. // Set multiple: true so checkboxes can easily use min/max counts to control number of options required
  211. $field['multiple'] = true;
  212. return self::typeArray((array) $value, $params, $field);
  213. }
  214. protected static function filterCheckboxes($value, array $params, array $field)
  215. {
  216. return self::filterArray($value, $params, $field);
  217. }
  218. /**
  219. * HTML5 input: checkbox
  220. *
  221. * @param mixed $value Value to be validated.
  222. * @param array $params Validation parameters.
  223. * @param array $field Blueprint for the field.
  224. * @return bool True if validation succeeded.
  225. */
  226. public static function typeCheckbox($value, array $params, array $field)
  227. {
  228. $value = (string)$value;
  229. $field_value = (string)($field['value'] ?? '1');
  230. return $value === $field_value;
  231. }
  232. /**
  233. * HTML5 input: radio
  234. *
  235. * @param mixed $value Value to be validated.
  236. * @param array $params Validation parameters.
  237. * @param array $field Blueprint for the field.
  238. * @return bool True if validation succeeded.
  239. */
  240. public static function typeRadio($value, array $params, array $field)
  241. {
  242. return self::typeArray((array) $value, $params, $field);
  243. }
  244. /**
  245. * Custom input: toggle
  246. *
  247. * @param mixed $value Value to be validated.
  248. * @param array $params Validation parameters.
  249. * @param array $field Blueprint for the field.
  250. * @return bool True if validation succeeded.
  251. */
  252. public static function typeToggle($value, array $params, array $field)
  253. {
  254. if (\is_bool($value)) {
  255. $value = (int)$value;
  256. }
  257. return self::typeArray((array) $value, $params, $field);
  258. }
  259. /**
  260. * Custom input: file
  261. *
  262. * @param mixed $value Value to be validated.
  263. * @param array $params Validation parameters.
  264. * @param array $field Blueprint for the field.
  265. * @return bool True if validation succeeded.
  266. */
  267. public static function typeFile($value, array $params, array $field)
  268. {
  269. return self::typeArray((array)$value, $params, $field);
  270. }
  271. protected static function filterFile($value, array $params, array $field)
  272. {
  273. return (array)$value;
  274. }
  275. /**
  276. * HTML5 input: select
  277. *
  278. * @param mixed $value Value to be validated.
  279. * @param array $params Validation parameters.
  280. * @param array $field Blueprint for the field.
  281. * @return bool True if validation succeeded.
  282. */
  283. public static function typeSelect($value, array $params, array $field)
  284. {
  285. return self::typeArray((array) $value, $params, $field);
  286. }
  287. /**
  288. * HTML5 input: number
  289. *
  290. * @param mixed $value Value to be validated.
  291. * @param array $params Validation parameters.
  292. * @param array $field Blueprint for the field.
  293. * @return bool True if validation succeeded.
  294. */
  295. public static function typeNumber($value, array $params, array $field)
  296. {
  297. if (!is_numeric($value)) {
  298. return false;
  299. }
  300. if (isset($params['min']) && $value < $params['min']) {
  301. return false;
  302. }
  303. if (isset($params['max']) && $value > $params['max']) {
  304. return false;
  305. }
  306. $min = $params['min'] ?? 0;
  307. return !(isset($params['step']) && fmod($value - $min, $params['step']) === 0);
  308. }
  309. protected static function filterNumber($value, array $params, array $field)
  310. {
  311. return (string)(int)$value !== (string)(float)$value ? (float) $value : (int) $value;
  312. }
  313. protected static function filterDateTime($value, array $params, array $field)
  314. {
  315. $format = Grav::instance()['config']->get('system.pages.dateformat.default');
  316. if ($format) {
  317. $converted = new \DateTime($value);
  318. return $converted->format($format);
  319. }
  320. return $value;
  321. }
  322. /**
  323. * HTML5 input: range
  324. *
  325. * @param mixed $value Value to be validated.
  326. * @param array $params Validation parameters.
  327. * @param array $field Blueprint for the field.
  328. * @return bool True if validation succeeded.
  329. */
  330. public static function typeRange($value, array $params, array $field)
  331. {
  332. return self::typeNumber($value, $params, $field);
  333. }
  334. protected static function filterRange($value, array $params, array $field)
  335. {
  336. return self::filterNumber($value, $params, $field);
  337. }
  338. /**
  339. * HTML5 input: color
  340. *
  341. * @param mixed $value Value to be validated.
  342. * @param array $params Validation parameters.
  343. * @param array $field Blueprint for the field.
  344. * @return bool True if validation succeeded.
  345. */
  346. public static function typeColor($value, array $params, array $field)
  347. {
  348. return preg_match('/^\#[0-9a-fA-F]{3}[0-9a-fA-F]{3}?$/u', $value);
  349. }
  350. /**
  351. * HTML5 input: email
  352. *
  353. * @param mixed $value Value to be validated.
  354. * @param array $params Validation parameters.
  355. * @param array $field Blueprint for the field.
  356. * @return bool True if validation succeeded.
  357. */
  358. public static function typeEmail($value, array $params, array $field)
  359. {
  360. $values = !\is_array($value) ? explode(',', preg_replace('/\s+/', '', $value)) : $value;
  361. foreach ($values as $val) {
  362. if (!(self::typeText($val, $params, $field) && filter_var($val, FILTER_VALIDATE_EMAIL))) {
  363. return false;
  364. }
  365. }
  366. return true;
  367. }
  368. /**
  369. * HTML5 input: url
  370. *
  371. * @param mixed $value Value to be validated.
  372. * @param array $params Validation parameters.
  373. * @param array $field Blueprint for the field.
  374. * @return bool True if validation succeeded.
  375. */
  376. public static function typeUrl($value, array $params, array $field)
  377. {
  378. return self::typeText($value, $params, $field) && filter_var($value, FILTER_VALIDATE_URL);
  379. }
  380. /**
  381. * HTML5 input: datetime
  382. *
  383. * @param mixed $value Value to be validated.
  384. * @param array $params Validation parameters.
  385. * @param array $field Blueprint for the field.
  386. * @return bool True if validation succeeded.
  387. */
  388. public static function typeDatetime($value, array $params, array $field)
  389. {
  390. if ($value instanceof \DateTime) {
  391. return true;
  392. }
  393. if (!\is_string($value)) {
  394. return false;
  395. }
  396. if (!isset($params['format'])) {
  397. return false !== strtotime($value);
  398. }
  399. $dateFromFormat = \DateTime::createFromFormat($params['format'], $value);
  400. return $dateFromFormat && $value === date($params['format'], $dateFromFormat->getTimestamp());
  401. }
  402. /**
  403. * HTML5 input: datetime-local
  404. *
  405. * @param mixed $value Value to be validated.
  406. * @param array $params Validation parameters.
  407. * @param array $field Blueprint for the field.
  408. * @return bool True if validation succeeded.
  409. */
  410. public static function typeDatetimeLocal($value, array $params, array $field)
  411. {
  412. return self::typeDatetime($value, $params, $field);
  413. }
  414. /**
  415. * HTML5 input: date
  416. *
  417. * @param mixed $value Value to be validated.
  418. * @param array $params Validation parameters.
  419. * @param array $field Blueprint for the field.
  420. * @return bool True if validation succeeded.
  421. */
  422. public static function typeDate($value, array $params, array $field)
  423. {
  424. if (!isset($params['format'])) {
  425. $params['format'] = 'Y-m-d';
  426. }
  427. return self::typeDatetime($value, $params, $field);
  428. }
  429. /**
  430. * HTML5 input: time
  431. *
  432. * @param mixed $value Value to be validated.
  433. * @param array $params Validation parameters.
  434. * @param array $field Blueprint for the field.
  435. * @return bool True if validation succeeded.
  436. */
  437. public static function typeTime($value, array $params, array $field)
  438. {
  439. if (!isset($params['format'])) {
  440. $params['format'] = 'H:i';
  441. }
  442. return self::typeDatetime($value, $params, $field);
  443. }
  444. /**
  445. * HTML5 input: month
  446. *
  447. * @param mixed $value Value to be validated.
  448. * @param array $params Validation parameters.
  449. * @param array $field Blueprint for the field.
  450. * @return bool True if validation succeeded.
  451. */
  452. public static function typeMonth($value, array $params, array $field)
  453. {
  454. if (!isset($params['format'])) {
  455. $params['format'] = 'Y-m';
  456. }
  457. return self::typeDatetime($value, $params, $field);
  458. }
  459. /**
  460. * HTML5 input: week
  461. *
  462. * @param mixed $value Value to be validated.
  463. * @param array $params Validation parameters.
  464. * @param array $field Blueprint for the field.
  465. * @return bool True if validation succeeded.
  466. */
  467. public static function typeWeek($value, array $params, array $field)
  468. {
  469. if (!isset($params['format']) && !preg_match('/^\d{4}-W\d{2}$/u', $value)) {
  470. return false;
  471. }
  472. return self::typeDatetime($value, $params, $field);
  473. }
  474. /**
  475. * Custom input: array
  476. *
  477. * @param mixed $value Value to be validated.
  478. * @param array $params Validation parameters.
  479. * @param array $field Blueprint for the field.
  480. * @return bool True if validation succeeded.
  481. */
  482. public static function typeArray($value, array $params, array $field)
  483. {
  484. if (!\is_array($value)) {
  485. return false;
  486. }
  487. if (isset($field['multiple'])) {
  488. if (isset($params['min']) && \count($value) < $params['min']) {
  489. return false;
  490. }
  491. if (isset($params['max']) && \count($value) > $params['max']) {
  492. return false;
  493. }
  494. $min = $params['min'] ?? 0;
  495. if (isset($params['step']) && (\count($value) - $min) % $params['step'] === 0) {
  496. return false;
  497. }
  498. }
  499. // If creating new values is allowed, no further checks are needed.
  500. if (!empty($field['selectize']['create'])) {
  501. return true;
  502. }
  503. $options = $field['options'] ?? [];
  504. $use = $field['use'] ?? 'values';
  505. if (empty($field['selectize']) || empty($field['multiple'])) {
  506. $options = array_keys($options);
  507. }
  508. if ($use === 'keys') {
  509. $value = array_keys($value);
  510. }
  511. return !($options && array_diff($value, $options));
  512. }
  513. protected static function filterArray($value, $params, $field)
  514. {
  515. $values = (array) $value;
  516. $options = isset($field['options']) ? array_keys($field['options']) : [];
  517. $multi = $field['multiple'] ?? false;
  518. if (\count($values) === 1 && isset($values[0]) && $values[0] === '') {
  519. return null;
  520. }
  521. if ($options) {
  522. $useKey = isset($field['use']) && $field['use'] === 'keys';
  523. foreach ($values as $key => $val) {
  524. $values[$key] = $useKey ? (bool) $val : $val;
  525. }
  526. }
  527. if ($multi) {
  528. foreach ($values as $key => $val) {
  529. if (\is_array($val)) {
  530. $val = implode(',', $val);
  531. $values[$key] = array_map('trim', explode(',', $val));
  532. } else {
  533. $values[$key] = trim($val);
  534. }
  535. }
  536. }
  537. if (isset($field['ignore_empty']) && Utils::isPositive($field['ignore_empty'])) {
  538. foreach ($values as $key => $val) {
  539. if ($val === '') {
  540. unset($values[$key]);
  541. } elseif (\is_array($val)) {
  542. foreach ($val as $inner_key => $inner_value) {
  543. if ($inner_value === '') {
  544. unset($val[$inner_key]);
  545. }
  546. }
  547. }
  548. $values[$key] = $val;
  549. }
  550. }
  551. return $values;
  552. }
  553. public static function typeList($value, array $params, array $field)
  554. {
  555. if (!\is_array($value)) {
  556. return false;
  557. }
  558. if (isset($field['fields'])) {
  559. foreach ($value as $key => $item) {
  560. foreach ($field['fields'] as $subKey => $subField) {
  561. $subKey = trim($subKey, '.');
  562. $subValue = $item[$subKey] ?? null;
  563. self::validate($subValue, $subField);
  564. }
  565. }
  566. }
  567. return true;
  568. }
  569. protected static function filterList($value, array $params, array $field)
  570. {
  571. return (array) $value;
  572. }
  573. public static function filterYaml($value, $params)
  574. {
  575. if (!\is_string($value)) {
  576. return $value;
  577. }
  578. return (array) Yaml::parse($value);
  579. }
  580. /**
  581. * Custom input: ignore (will not validate)
  582. *
  583. * @param mixed $value Value to be validated.
  584. * @param array $params Validation parameters.
  585. * @param array $field Blueprint for the field.
  586. * @return bool True if validation succeeded.
  587. */
  588. public static function typeIgnore($value, array $params, array $field)
  589. {
  590. return true;
  591. }
  592. public static function filterIgnore($value, array $params, array $field)
  593. {
  594. return $value;
  595. }
  596. /**
  597. * Input value which can be ignored.
  598. *
  599. * @param mixed $value Value to be validated.
  600. * @param array $params Validation parameters.
  601. * @param array $field Blueprint for the field.
  602. * @return bool True if validation succeeded.
  603. */
  604. public static function typeUnset($value, array $params, array $field)
  605. {
  606. return true;
  607. }
  608. public static function filterUnset($value, array $params, array $field)
  609. {
  610. return null;
  611. }
  612. // HTML5 attributes (min, max and range are handled inside the types)
  613. public static function validateRequired($value, $params)
  614. {
  615. if (is_scalar($value)) {
  616. return (bool) $params !== true || $value !== '';
  617. }
  618. return (bool) $params !== true || !empty($value);
  619. }
  620. public static function validatePattern($value, $params)
  621. {
  622. return (bool) preg_match("`^{$params}$`u", $value);
  623. }
  624. // Internal types
  625. public static function validateAlpha($value, $params)
  626. {
  627. return ctype_alpha($value);
  628. }
  629. public static function validateAlnum($value, $params)
  630. {
  631. return ctype_alnum($value);
  632. }
  633. public static function typeBool($value, $params)
  634. {
  635. return \is_bool($value) || $value == 1 || $value == 0;
  636. }
  637. public static function validateBool($value, $params)
  638. {
  639. return \is_bool($value) || $value == 1 || $value == 0;
  640. }
  641. protected static function filterBool($value, $params)
  642. {
  643. return (bool) $value;
  644. }
  645. public static function validateDigit($value, $params)
  646. {
  647. return ctype_digit($value);
  648. }
  649. public static function validateFloat($value, $params)
  650. {
  651. return \is_float(filter_var($value, FILTER_VALIDATE_FLOAT));
  652. }
  653. protected static function filterFloat($value, $params)
  654. {
  655. return (float) $value;
  656. }
  657. public static function validateHex($value, $params)
  658. {
  659. return ctype_xdigit($value);
  660. }
  661. public static function validateInt($value, $params)
  662. {
  663. return is_numeric($value) && (int)$value == $value;
  664. }
  665. protected static function filterInt($value, $params)
  666. {
  667. return (int)$value;
  668. }
  669. public static function validateArray($value, $params)
  670. {
  671. return \is_array($value) || ($value instanceof \ArrayAccess && $value instanceof \Traversable && $value instanceof \Countable);
  672. }
  673. public static function filterItem_List($value, $params)
  674. {
  675. return array_values(array_filter($value, function($v) { return !empty($v); } ));
  676. }
  677. public static function validateJson($value, $params)
  678. {
  679. return (bool) (@json_decode($value));
  680. }
  681. }