Validation.php 34 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236
  1. <?php
  2. /**
  3. * @package Grav\Common\Data
  4. *
  5. * @copyright Copyright (c) 2015 - 2024 Trilby Media, LLC. All rights reserved.
  6. * @license MIT License; see LICENSE file for details.
  7. */
  8. namespace Grav\Common\Data;
  9. use ArrayAccess;
  10. use Countable;
  11. use DateTime;
  12. use Grav\Common\Config\Config;
  13. use Grav\Common\Grav;
  14. use Grav\Common\Language\Language;
  15. use Grav\Common\Security;
  16. use Grav\Common\User\Interfaces\UserInterface;
  17. use Grav\Common\Utils;
  18. use Grav\Common\Yaml;
  19. use Grav\Framework\Flex\Interfaces\FlexObjectInterface;
  20. use Traversable;
  21. use function count;
  22. use function is_array;
  23. use function is_bool;
  24. use function is_float;
  25. use function is_int;
  26. use function is_string;
  27. /**
  28. * Class Validation
  29. * @package Grav\Common\Data
  30. */
  31. class Validation
  32. {
  33. /**
  34. * Validate value against a blueprint field definition.
  35. *
  36. * @param mixed $value
  37. * @param array $field
  38. * @return array
  39. */
  40. public static function validate($value, array $field)
  41. {
  42. if (!isset($field['type'])) {
  43. $field['type'] = 'text';
  44. }
  45. $validate = (array)($field['validate'] ?? null);
  46. $type = $validate['type'] ?? $field['type'];
  47. $required = $validate['required'] ?? false;
  48. // If value isn't required, we will stop validation if empty value is given.
  49. if ($required !== true && ($value === null || $value === '' || (($field['type'] === 'checkbox' || $field['type'] === 'switch') && $value == false))
  50. ) {
  51. return [];
  52. }
  53. // Get language class.
  54. $language = Grav::instance()['language'];
  55. $name = ucfirst($field['label'] ?? $field['name']);
  56. $message = (string) isset($field['validate']['message'])
  57. ? $language->translate($field['validate']['message'])
  58. : $language->translate('GRAV.FORM.INVALID_INPUT') . ' "' . $language->translate($name) . '"';
  59. // Validate type with fallback type text.
  60. $method = 'type' . str_replace('-', '_', $type);
  61. // If this is a YAML field validate/filter as such
  62. if (isset($field['yaml']) && $field['yaml'] === true) {
  63. $method = 'typeYaml';
  64. }
  65. $messages = [];
  66. $success = method_exists(__CLASS__, $method) ? self::$method($value, $validate, $field) : true;
  67. if (!$success) {
  68. $messages[$field['name']][] = $message;
  69. }
  70. // Check individual rules.
  71. foreach ($validate as $rule => $params) {
  72. $method = 'validate' . ucfirst(str_replace('-', '_', $rule));
  73. if (method_exists(__CLASS__, $method)) {
  74. $success = self::$method($value, $params);
  75. if (!$success) {
  76. $messages[$field['name']][] = $message;
  77. }
  78. }
  79. }
  80. return $messages;
  81. }
  82. /**
  83. * @param mixed $value
  84. * @param array $field
  85. * @return array
  86. */
  87. public static function checkSafety($value, array $field)
  88. {
  89. $messages = [];
  90. $type = $field['validate']['type'] ?? $field['type'] ?? 'text';
  91. $options = $field['xss_check'] ?? [];
  92. if ($options === false || $type === 'unset') {
  93. return $messages;
  94. }
  95. if (!is_array($options)) {
  96. $options = [];
  97. }
  98. $name = ucfirst($field['label'] ?? $field['name'] ?? 'UNKNOWN');
  99. /** @var UserInterface $user */
  100. $user = Grav::instance()['user'] ?? null;
  101. /** @var Config $config */
  102. $config = Grav::instance()['config'];
  103. $xss_whitelist = $config->get('security.xss_whitelist', 'admin.super');
  104. // Get language class.
  105. /** @var Language $language */
  106. $language = Grav::instance()['language'];
  107. if (!static::authorize($xss_whitelist, $user)) {
  108. $defaults = Security::getXssDefaults();
  109. $options += $defaults;
  110. $options['enabled_rules'] += $defaults['enabled_rules'];
  111. if (!empty($options['safe_protocols'])) {
  112. $options['invalid_protocols'] = array_diff($options['invalid_protocols'], $options['safe_protocols']);
  113. }
  114. if (!empty($options['safe_tags'])) {
  115. $options['dangerous_tags'] = array_diff($options['dangerous_tags'], $options['safe_tags']);
  116. }
  117. if (is_string($value)) {
  118. $violation = Security::detectXss($value, $options);
  119. if ($violation) {
  120. $messages[$name][] = $language->translate(['GRAV.FORM.XSS_ISSUES', $language->translate($name)], null, true);
  121. }
  122. } elseif (is_array($value)) {
  123. $violations = Security::detectXssFromArray($value, "{$name}.", $options);
  124. if ($violations) {
  125. $messages[$name][] = $language->translate(['GRAV.FORM.XSS_ISSUES', $language->translate($name)], null, true);
  126. }
  127. }
  128. }
  129. return $messages;
  130. }
  131. /**
  132. * Checks user authorisation to the action.
  133. *
  134. * @param string|string[] $action
  135. * @param UserInterface|null $user
  136. * @return bool
  137. */
  138. public static function authorize($action, UserInterface $user = null)
  139. {
  140. if (!$user) {
  141. return false;
  142. }
  143. $action = (array)$action;
  144. foreach ($action as $a) {
  145. // Ignore 'admin.super' if it's not the only value to be checked.
  146. if ($a === 'admin.super' && count($action) > 1 && $user instanceof FlexObjectInterface) {
  147. continue;
  148. }
  149. if ($user->authorize($a)) {
  150. return true;
  151. }
  152. }
  153. return false;
  154. }
  155. /**
  156. * Filter value against a blueprint field definition.
  157. *
  158. * @param mixed $value
  159. * @param array $field
  160. * @return mixed Filtered value.
  161. */
  162. public static function filter($value, array $field)
  163. {
  164. $validate = (array)($field['filter'] ?? $field['validate'] ?? null);
  165. // If value isn't required, we will return null if empty value is given.
  166. if (($value === null || $value === '') && empty($validate['required'])) {
  167. return null;
  168. }
  169. if (!isset($field['type'])) {
  170. $field['type'] = 'text';
  171. }
  172. $type = $field['filter']['type'] ?? $field['validate']['type'] ?? $field['type'];
  173. $method = 'filter' . ucfirst(str_replace('-', '_', $type));
  174. // If this is a YAML field validate/filter as such
  175. if (isset($field['yaml']) && $field['yaml'] === true) {
  176. $method = 'filterYaml';
  177. }
  178. if (!method_exists(__CLASS__, $method)) {
  179. $method = isset($field['array']) && $field['array'] === true ? 'filterArray' : 'filterText';
  180. }
  181. return self::$method($value, $validate, $field);
  182. }
  183. /**
  184. * HTML5 input: text
  185. *
  186. * @param mixed $value Value to be validated.
  187. * @param array $params Validation parameters.
  188. * @param array $field Blueprint for the field.
  189. * @return bool True if validation succeeded.
  190. */
  191. public static function typeText($value, array $params, array $field)
  192. {
  193. if (!is_string($value) && !is_numeric($value)) {
  194. return false;
  195. }
  196. $value = (string)$value;
  197. if (!empty($params['trim'])) {
  198. $value = trim($value);
  199. }
  200. $value = preg_replace("/\r\n|\r/um", "\n", $value);
  201. $len = mb_strlen($value);
  202. $min = (int)($params['min'] ?? 0);
  203. if ($min && $len < $min) {
  204. return false;
  205. }
  206. $multiline = isset($params['multiline']) && $params['multiline'];
  207. $max = (int)($params['max'] ?? ($multiline ? 65536 : 2048));
  208. if ($max && $len > $max) {
  209. return false;
  210. }
  211. $step = (int)($params['step'] ?? 0);
  212. if ($step && ($len - $min) % $step === 0) {
  213. return false;
  214. }
  215. if (!$multiline && preg_match('/\R/um', $value)) {
  216. return false;
  217. }
  218. return true;
  219. }
  220. /**
  221. * @param mixed $value
  222. * @param array $params
  223. * @param array $field
  224. * @return string
  225. */
  226. protected static function filterText($value, array $params, array $field)
  227. {
  228. if (!is_string($value) && !is_numeric($value)) {
  229. return '';
  230. }
  231. $value = (string)$value;
  232. if (!empty($params['trim'])) {
  233. $value = trim($value);
  234. }
  235. return preg_replace("/\r\n|\r/um", "\n", $value);
  236. }
  237. /**
  238. * @param mixed $value
  239. * @param array $params
  240. * @param array $field
  241. * @return string|null
  242. */
  243. protected static function filterCheckbox($value, array $params, array $field)
  244. {
  245. $value = (string)$value;
  246. $field_value = (string)($field['value'] ?? '1');
  247. return $value === $field_value ? $value : null;
  248. }
  249. /**
  250. * @param mixed $value
  251. * @param array $params
  252. * @param array $field
  253. * @return array|array[]|false|string[]
  254. */
  255. protected static function filterCommaList($value, array $params, array $field)
  256. {
  257. return is_array($value) ? $value : preg_split('/\s*,\s*/', $value, -1, PREG_SPLIT_NO_EMPTY);
  258. }
  259. /**
  260. * @param mixed $value
  261. * @param array $params
  262. * @param array $field
  263. * @return bool
  264. */
  265. public static function typeCommaList($value, array $params, array $field)
  266. {
  267. if (!isset($params['max'])) {
  268. $params['max'] = 2048;
  269. }
  270. return is_array($value) ? true : self::typeText($value, $params, $field);
  271. }
  272. /**
  273. * @param mixed $value
  274. * @param array $params
  275. * @param array $field
  276. * @return array|array[]|false|string[]
  277. */
  278. protected static function filterLines($value, array $params, array $field)
  279. {
  280. return is_array($value) ? $value : preg_split('/\s*[\r\n]+\s*/', $value, -1, PREG_SPLIT_NO_EMPTY);
  281. }
  282. /**
  283. * @param mixed $value
  284. * @param array $params
  285. * @return string
  286. */
  287. protected static function filterLower($value, array $params)
  288. {
  289. return mb_strtolower($value);
  290. }
  291. /**
  292. * @param mixed $value
  293. * @param array $params
  294. * @return string
  295. */
  296. protected static function filterUpper($value, array $params)
  297. {
  298. return mb_strtoupper($value);
  299. }
  300. /**
  301. * HTML5 input: textarea
  302. *
  303. * @param mixed $value Value to be validated.
  304. * @param array $params Validation parameters.
  305. * @param array $field Blueprint for the field.
  306. * @return bool True if validation succeeded.
  307. */
  308. public static function typeTextarea($value, array $params, array $field)
  309. {
  310. if (!isset($params['multiline'])) {
  311. $params['multiline'] = true;
  312. }
  313. return self::typeText($value, $params, $field);
  314. }
  315. /**
  316. * HTML5 input: password
  317. *
  318. * @param mixed $value Value to be validated.
  319. * @param array $params Validation parameters.
  320. * @param array $field Blueprint for the field.
  321. * @return bool True if validation succeeded.
  322. */
  323. public static function typePassword($value, array $params, array $field)
  324. {
  325. if (!isset($params['max'])) {
  326. $params['max'] = 256;
  327. }
  328. return self::typeText($value, $params, $field);
  329. }
  330. /**
  331. * HTML5 input: hidden
  332. *
  333. * @param mixed $value Value to be validated.
  334. * @param array $params Validation parameters.
  335. * @param array $field Blueprint for the field.
  336. * @return bool True if validation succeeded.
  337. */
  338. public static function typeHidden($value, array $params, array $field)
  339. {
  340. return self::typeText($value, $params, $field);
  341. }
  342. /**
  343. * Custom input: checkbox list
  344. *
  345. * @param mixed $value Value to be validated.
  346. * @param array $params Validation parameters.
  347. * @param array $field Blueprint for the field.
  348. * @return bool True if validation succeeded.
  349. */
  350. public static function typeCheckboxes($value, array $params, array $field)
  351. {
  352. // Set multiple: true so checkboxes can easily use min/max counts to control number of options required
  353. $field['multiple'] = true;
  354. return self::typeArray((array) $value, $params, $field);
  355. }
  356. /**
  357. * @param mixed $value
  358. * @param array $params
  359. * @param array $field
  360. * @return array|null
  361. */
  362. protected static function filterCheckboxes($value, array $params, array $field)
  363. {
  364. return self::filterArray($value, $params, $field);
  365. }
  366. /**
  367. * HTML5 input: checkbox
  368. *
  369. * @param mixed $value Value to be validated.
  370. * @param array $params Validation parameters.
  371. * @param array $field Blueprint for the field.
  372. * @return bool True if validation succeeded.
  373. */
  374. public static function typeCheckbox($value, array $params, array $field)
  375. {
  376. $value = (string)$value;
  377. $field_value = (string)($field['value'] ?? '1');
  378. return $value === $field_value;
  379. }
  380. /**
  381. * HTML5 input: radio
  382. *
  383. * @param mixed $value Value to be validated.
  384. * @param array $params Validation parameters.
  385. * @param array $field Blueprint for the field.
  386. * @return bool True if validation succeeded.
  387. */
  388. public static function typeRadio($value, array $params, array $field)
  389. {
  390. return self::typeArray((array) $value, $params, $field);
  391. }
  392. /**
  393. * Custom input: toggle
  394. *
  395. * @param mixed $value Value to be validated.
  396. * @param array $params Validation parameters.
  397. * @param array $field Blueprint for the field.
  398. * @return bool True if validation succeeded.
  399. */
  400. public static function typeToggle($value, array $params, array $field)
  401. {
  402. if (is_bool($value)) {
  403. $value = (int)$value;
  404. }
  405. return self::typeArray((array) $value, $params, $field);
  406. }
  407. /**
  408. * Custom input: file
  409. *
  410. * @param mixed $value Value to be validated.
  411. * @param array $params Validation parameters.
  412. * @param array $field Blueprint for the field.
  413. * @return bool True if validation succeeded.
  414. */
  415. public static function typeFile($value, array $params, array $field)
  416. {
  417. return self::typeArray((array)$value, $params, $field);
  418. }
  419. /**
  420. * @param mixed $value
  421. * @param array $params
  422. * @param array $field
  423. * @return array
  424. */
  425. protected static function filterFile($value, array $params, array $field)
  426. {
  427. return (array)$value;
  428. }
  429. /**
  430. * HTML5 input: select
  431. *
  432. * @param mixed $value Value to be validated.
  433. * @param array $params Validation parameters.
  434. * @param array $field Blueprint for the field.
  435. * @return bool True if validation succeeded.
  436. */
  437. public static function typeSelect($value, array $params, array $field)
  438. {
  439. return self::typeArray((array) $value, $params, $field);
  440. }
  441. /**
  442. * HTML5 input: number
  443. *
  444. * @param mixed $value Value to be validated.
  445. * @param array $params Validation parameters.
  446. * @param array $field Blueprint for the field.
  447. * @return bool True if validation succeeded.
  448. */
  449. public static function typeNumber($value, array $params, array $field)
  450. {
  451. if (!is_numeric($value)) {
  452. return false;
  453. }
  454. $value = (float)$value;
  455. $min = 0;
  456. if (isset($params['min'])) {
  457. $min = (float)$params['min'];
  458. if ($value < $min) {
  459. return false;
  460. }
  461. }
  462. if (isset($params['max'])) {
  463. $max = (float)$params['max'];
  464. if ($value > $max) {
  465. return false;
  466. }
  467. }
  468. if (isset($params['step'])) {
  469. $step = (float)$params['step'];
  470. // Count of how many steps we are above/below the minimum value.
  471. $pos = ($value - $min) / $step;
  472. $pos = round($pos, 10);
  473. return is_int(static::filterNumber($pos, $params, $field));
  474. }
  475. return true;
  476. }
  477. /**
  478. * @param mixed $value
  479. * @param array $params
  480. * @param array $field
  481. * @return float|int
  482. */
  483. protected static function filterNumber($value, array $params, array $field)
  484. {
  485. return (string)(int)$value !== (string)(float)$value ? (float)$value : (int)$value;
  486. }
  487. /**
  488. * @param mixed $value
  489. * @param array $params
  490. * @param array $field
  491. * @return string
  492. */
  493. protected static function filterDateTime($value, array $params, array $field)
  494. {
  495. $format = Grav::instance()['config']->get('system.pages.dateformat.default');
  496. if ($format) {
  497. $converted = new DateTime($value);
  498. return $converted->format($format);
  499. }
  500. return $value;
  501. }
  502. /**
  503. * HTML5 input: range
  504. *
  505. * @param mixed $value Value to be validated.
  506. * @param array $params Validation parameters.
  507. * @param array $field Blueprint for the field.
  508. * @return bool True if validation succeeded.
  509. */
  510. public static function typeRange($value, array $params, array $field)
  511. {
  512. return self::typeNumber($value, $params, $field);
  513. }
  514. /**
  515. * @param mixed $value
  516. * @param array $params
  517. * @param array $field
  518. * @return float|int
  519. */
  520. protected static function filterRange($value, array $params, array $field)
  521. {
  522. return self::filterNumber($value, $params, $field);
  523. }
  524. /**
  525. * HTML5 input: color
  526. *
  527. * @param mixed $value Value to be validated.
  528. * @param array $params Validation parameters.
  529. * @param array $field Blueprint for the field.
  530. * @return bool True if validation succeeded.
  531. */
  532. public static function typeColor($value, array $params, array $field)
  533. {
  534. return (bool)preg_match('/^\#[0-9a-fA-F]{3}[0-9a-fA-F]{3}?$/u', $value);
  535. }
  536. /**
  537. * HTML5 input: email
  538. *
  539. * @param mixed $value Value to be validated.
  540. * @param array $params Validation parameters.
  541. * @param array $field Blueprint for the field.
  542. * @return bool True if validation succeeded.
  543. */
  544. public static function typeEmail($value, array $params, array $field)
  545. {
  546. if (empty($value)) {
  547. return false;
  548. }
  549. if (!isset($params['max'])) {
  550. $params['max'] = 320;
  551. }
  552. $values = !is_array($value) ? explode(',', preg_replace('/\s+/', '', $value)) : $value;
  553. foreach ($values as $val) {
  554. if (!(self::typeText($val, $params, $field) && strpos($val, '@', 1))) {
  555. return false;
  556. }
  557. }
  558. return true;
  559. }
  560. /**
  561. * HTML5 input: url
  562. *
  563. * @param mixed $value Value to be validated.
  564. * @param array $params Validation parameters.
  565. * @param array $field Blueprint for the field.
  566. * @return bool True if validation succeeded.
  567. */
  568. public static function typeUrl($value, array $params, array $field)
  569. {
  570. if (!isset($params['max'])) {
  571. $params['max'] = 2048;
  572. }
  573. return self::typeText($value, $params, $field) && filter_var($value, FILTER_VALIDATE_URL);
  574. }
  575. /**
  576. * HTML5 input: datetime
  577. *
  578. * @param mixed $value Value to be validated.
  579. * @param array $params Validation parameters.
  580. * @param array $field Blueprint for the field.
  581. * @return bool True if validation succeeded.
  582. */
  583. public static function typeDatetime($value, array $params, array $field)
  584. {
  585. if ($value instanceof DateTime) {
  586. return true;
  587. }
  588. if (!is_string($value)) {
  589. return false;
  590. }
  591. if (!isset($params['format'])) {
  592. return false !== strtotime($value);
  593. }
  594. $dateFromFormat = DateTime::createFromFormat($params['format'], $value);
  595. return $dateFromFormat && $value === date($params['format'], $dateFromFormat->getTimestamp());
  596. }
  597. /**
  598. * HTML5 input: datetime-local
  599. *
  600. * @param mixed $value Value to be validated.
  601. * @param array $params Validation parameters.
  602. * @param array $field Blueprint for the field.
  603. * @return bool True if validation succeeded.
  604. */
  605. public static function typeDatetimeLocal($value, array $params, array $field)
  606. {
  607. return self::typeDatetime($value, $params, $field);
  608. }
  609. /**
  610. * HTML5 input: date
  611. *
  612. * @param mixed $value Value to be validated.
  613. * @param array $params Validation parameters.
  614. * @param array $field Blueprint for the field.
  615. * @return bool True if validation succeeded.
  616. */
  617. public static function typeDate($value, array $params, array $field)
  618. {
  619. if (!isset($params['format'])) {
  620. $params['format'] = 'Y-m-d';
  621. }
  622. return self::typeDatetime($value, $params, $field);
  623. }
  624. /**
  625. * HTML5 input: time
  626. *
  627. * @param mixed $value Value to be validated.
  628. * @param array $params Validation parameters.
  629. * @param array $field Blueprint for the field.
  630. * @return bool True if validation succeeded.
  631. */
  632. public static function typeTime($value, array $params, array $field)
  633. {
  634. if (!isset($params['format'])) {
  635. $params['format'] = 'H:i';
  636. }
  637. return self::typeDatetime($value, $params, $field);
  638. }
  639. /**
  640. * HTML5 input: month
  641. *
  642. * @param mixed $value Value to be validated.
  643. * @param array $params Validation parameters.
  644. * @param array $field Blueprint for the field.
  645. * @return bool True if validation succeeded.
  646. */
  647. public static function typeMonth($value, array $params, array $field)
  648. {
  649. if (!isset($params['format'])) {
  650. $params['format'] = 'Y-m';
  651. }
  652. return self::typeDatetime($value, $params, $field);
  653. }
  654. /**
  655. * HTML5 input: week
  656. *
  657. * @param mixed $value Value to be validated.
  658. * @param array $params Validation parameters.
  659. * @param array $field Blueprint for the field.
  660. * @return bool True if validation succeeded.
  661. */
  662. public static function typeWeek($value, array $params, array $field)
  663. {
  664. if (!isset($params['format']) && !preg_match('/^\d{4}-W\d{2}$/u', $value)) {
  665. return false;
  666. }
  667. return self::typeDatetime($value, $params, $field);
  668. }
  669. /**
  670. * Custom input: array
  671. *
  672. * @param mixed $value Value to be validated.
  673. * @param array $params Validation parameters.
  674. * @param array $field Blueprint for the field.
  675. * @return bool True if validation succeeded.
  676. */
  677. public static function typeArray($value, array $params, array $field)
  678. {
  679. if (!is_array($value)) {
  680. return false;
  681. }
  682. if (isset($field['multiple'])) {
  683. if (isset($params['min']) && count($value) < $params['min']) {
  684. return false;
  685. }
  686. if (isset($params['max']) && count($value) > $params['max']) {
  687. return false;
  688. }
  689. $min = $params['min'] ?? 0;
  690. if (isset($params['step']) && (count($value) - $min) % $params['step'] === 0) {
  691. return false;
  692. }
  693. }
  694. // If creating new values is allowed, no further checks are needed.
  695. $validateOptions = $field['validate']['options'] ?? null;
  696. if (!empty($field['selectize']['create']) || $validateOptions === 'ignore') {
  697. return true;
  698. }
  699. $options = $field['options'] ?? [];
  700. $use = $field['use'] ?? 'values';
  701. if ($validateOptions) {
  702. // Use custom options structure.
  703. foreach ($options as &$option) {
  704. $option = $option[$validateOptions] ?? null;
  705. }
  706. unset($option);
  707. $options = array_values($options);
  708. } elseif (empty($field['selectize']) || empty($field['multiple'])) {
  709. $options = array_keys($options);
  710. }
  711. if ($use === 'keys') {
  712. $value = array_keys($value);
  713. }
  714. return !($options && array_diff($value, $options));
  715. }
  716. /**
  717. * @param mixed $value
  718. * @param array $params
  719. * @param array $field
  720. * @return array|null
  721. */
  722. protected static function filterFlatten_array($value, $params, $field)
  723. {
  724. $value = static::filterArray($value, $params, $field);
  725. return is_array($value) ? Utils::arrayUnflattenDotNotation($value) : null;
  726. }
  727. /**
  728. * @param mixed $value
  729. * @param array $params
  730. * @param array $field
  731. * @return array|null
  732. */
  733. protected static function filterArray($value, $params, $field)
  734. {
  735. $values = (array) $value;
  736. $options = isset($field['options']) ? array_keys($field['options']) : [];
  737. $multi = $field['multiple'] ?? false;
  738. if (count($values) === 1 && isset($values[0]) && $values[0] === '') {
  739. return null;
  740. }
  741. if ($options) {
  742. $useKey = isset($field['use']) && $field['use'] === 'keys';
  743. foreach ($values as $key => $val) {
  744. $values[$key] = $useKey ? (bool) $val : $val;
  745. }
  746. }
  747. if ($multi) {
  748. foreach ($values as $key => $val) {
  749. if (is_array($val)) {
  750. $val = implode(',', $val);
  751. $values[$key] = array_map('trim', explode(',', $val));
  752. } else {
  753. $values[$key] = trim($val);
  754. }
  755. }
  756. }
  757. $ignoreEmpty = isset($field['ignore_empty']) && Utils::isPositive($field['ignore_empty']);
  758. $valueType = $params['value_type'] ?? null;
  759. $keyType = $params['key_type'] ?? null;
  760. if ($ignoreEmpty || $valueType || $keyType) {
  761. $values = static::arrayFilterRecurse($values, ['value_type' => $valueType, 'key_type' => $keyType, 'ignore_empty' => $ignoreEmpty]);
  762. }
  763. return $values;
  764. }
  765. /**
  766. * @param array $values
  767. * @param array $params
  768. * @return array
  769. */
  770. protected static function arrayFilterRecurse(array $values, array $params): array
  771. {
  772. foreach ($values as $key => &$val) {
  773. if ($params['key_type']) {
  774. switch ($params['key_type']) {
  775. case 'int':
  776. $result = is_int($key);
  777. break;
  778. case 'string':
  779. $result = is_string($key);
  780. break;
  781. default:
  782. $result = false;
  783. }
  784. if (!$result) {
  785. unset($values[$key]);
  786. }
  787. }
  788. if (is_array($val)) {
  789. $val = static::arrayFilterRecurse($val, $params);
  790. if ($params['ignore_empty'] && empty($val)) {
  791. unset($values[$key]);
  792. }
  793. } else {
  794. if ($params['value_type'] && $val !== '' && $val !== null) {
  795. switch ($params['value_type']) {
  796. case 'bool':
  797. if (Utils::isPositive($val)) {
  798. $val = true;
  799. } elseif (Utils::isNegative($val)) {
  800. $val = false;
  801. } else {
  802. // Ignore invalid bool values.
  803. $val = null;
  804. }
  805. break;
  806. case 'int':
  807. $val = (int)$val;
  808. break;
  809. case 'float':
  810. $val = (float)$val;
  811. break;
  812. case 'string':
  813. $val = (string)$val;
  814. break;
  815. case 'trim':
  816. $val = trim($val);
  817. break;
  818. }
  819. }
  820. if ($params['ignore_empty'] && ($val === '' || $val === null)) {
  821. unset($values[$key]);
  822. }
  823. }
  824. }
  825. return $values;
  826. }
  827. /**
  828. * @param mixed $value
  829. * @param array $params
  830. * @param array $field
  831. * @return bool
  832. */
  833. public static function typeList($value, array $params, array $field)
  834. {
  835. if (!is_array($value)) {
  836. return false;
  837. }
  838. if (isset($field['fields'])) {
  839. foreach ($value as $key => $item) {
  840. foreach ($field['fields'] as $subKey => $subField) {
  841. $subKey = trim($subKey, '.');
  842. $subValue = $item[$subKey] ?? null;
  843. self::validate($subValue, $subField);
  844. }
  845. }
  846. }
  847. return true;
  848. }
  849. /**
  850. * @param mixed $value
  851. * @param array $params
  852. * @param array $field
  853. * @return array
  854. */
  855. protected static function filterList($value, array $params, array $field)
  856. {
  857. return (array) $value;
  858. }
  859. /**
  860. * @param mixed $value
  861. * @param array $params
  862. * @return array
  863. */
  864. public static function filterYaml($value, $params)
  865. {
  866. if (!is_string($value)) {
  867. return $value;
  868. }
  869. return (array) Yaml::parse($value);
  870. }
  871. /**
  872. * Custom input: ignore (will not validate)
  873. *
  874. * @param mixed $value Value to be validated.
  875. * @param array $params Validation parameters.
  876. * @param array $field Blueprint for the field.
  877. * @return bool True if validation succeeded.
  878. */
  879. public static function typeIgnore($value, array $params, array $field)
  880. {
  881. return true;
  882. }
  883. /**
  884. * @param mixed $value
  885. * @param array $params
  886. * @param array $field
  887. * @return mixed
  888. */
  889. public static function filterIgnore($value, array $params, array $field)
  890. {
  891. return $value;
  892. }
  893. /**
  894. * Input value which can be ignored.
  895. *
  896. * @param mixed $value Value to be validated.
  897. * @param array $params Validation parameters.
  898. * @param array $field Blueprint for the field.
  899. * @return bool True if validation succeeded.
  900. */
  901. public static function typeUnset($value, array $params, array $field)
  902. {
  903. return true;
  904. }
  905. /**
  906. * @param mixed $value
  907. * @param array $params
  908. * @param array $field
  909. * @return null
  910. */
  911. public static function filterUnset($value, array $params, array $field)
  912. {
  913. return null;
  914. }
  915. // HTML5 attributes (min, max and range are handled inside the types)
  916. /**
  917. * @param mixed $value
  918. * @param bool $params
  919. * @return bool
  920. */
  921. public static function validateRequired($value, $params)
  922. {
  923. if (is_scalar($value)) {
  924. return (bool) $params !== true || $value !== '';
  925. }
  926. return (bool) $params !== true || !empty($value);
  927. }
  928. /**
  929. * @param mixed $value
  930. * @param string $params
  931. * @return bool
  932. */
  933. public static function validatePattern($value, $params)
  934. {
  935. return (bool) preg_match("`^{$params}$`u", $value);
  936. }
  937. // Internal types
  938. /**
  939. * @param mixed $value
  940. * @param mixed $params
  941. * @return bool
  942. */
  943. public static function validateAlpha($value, $params)
  944. {
  945. return ctype_alpha($value);
  946. }
  947. /**
  948. * @param mixed $value
  949. * @param mixed $params
  950. * @return bool
  951. */
  952. public static function validateAlnum($value, $params)
  953. {
  954. return ctype_alnum($value);
  955. }
  956. /**
  957. * @param mixed $value
  958. * @param mixed $params
  959. * @return bool
  960. */
  961. public static function typeBool($value, $params)
  962. {
  963. return is_bool($value) || $value == 1 || $value == 0;
  964. }
  965. /**
  966. * @param mixed $value
  967. * @param mixed $params
  968. * @return bool
  969. */
  970. public static function validateBool($value, $params)
  971. {
  972. return is_bool($value) || $value == 1 || $value == 0;
  973. }
  974. /**
  975. * @param mixed $value
  976. * @param mixed $params
  977. * @return bool
  978. */
  979. protected static function filterBool($value, $params)
  980. {
  981. return (bool) $value;
  982. }
  983. /**
  984. * @param mixed $value
  985. * @param mixed $params
  986. * @return bool
  987. */
  988. public static function validateDigit($value, $params)
  989. {
  990. return ctype_digit($value);
  991. }
  992. /**
  993. * @param mixed $value
  994. * @param mixed $params
  995. * @return bool
  996. */
  997. public static function validateFloat($value, $params)
  998. {
  999. return is_float(filter_var($value, FILTER_VALIDATE_FLOAT));
  1000. }
  1001. /**
  1002. * @param mixed $value
  1003. * @param mixed $params
  1004. * @return float
  1005. */
  1006. protected static function filterFloat($value, $params)
  1007. {
  1008. return (float) $value;
  1009. }
  1010. /**
  1011. * @param mixed $value
  1012. * @param mixed $params
  1013. * @return bool
  1014. */
  1015. public static function validateHex($value, $params)
  1016. {
  1017. return ctype_xdigit($value);
  1018. }
  1019. /**
  1020. * Custom input: int
  1021. *
  1022. * @param mixed $value Value to be validated.
  1023. * @param array $params Validation parameters.
  1024. * @param array $field Blueprint for the field.
  1025. * @return bool True if validation succeeded.
  1026. */
  1027. public static function typeInt($value, array $params, array $field)
  1028. {
  1029. $params['step'] = max(1, (int)($params['step'] ?? 0));
  1030. return self::typeNumber($value, $params, $field);
  1031. }
  1032. /**
  1033. * @param mixed $value
  1034. * @param mixed $params
  1035. * @return bool
  1036. */
  1037. public static function validateInt($value, $params)
  1038. {
  1039. return is_numeric($value) && (int)$value == $value;
  1040. }
  1041. /**
  1042. * @param mixed $value
  1043. * @param mixed $params
  1044. * @return int
  1045. */
  1046. protected static function filterInt($value, $params)
  1047. {
  1048. return (int)$value;
  1049. }
  1050. /**
  1051. * @param mixed $value
  1052. * @param mixed $params
  1053. * @return bool
  1054. */
  1055. public static function validateArray($value, $params)
  1056. {
  1057. return is_array($value) || ($value instanceof ArrayAccess && $value instanceof Traversable && $value instanceof Countable);
  1058. }
  1059. /**
  1060. * @param mixed $value
  1061. * @param mixed $params
  1062. * @return array
  1063. */
  1064. public static function filterItem_List($value, $params)
  1065. {
  1066. return array_values(array_filter($value, static function ($v) {
  1067. return !empty($v);
  1068. }));
  1069. }
  1070. /**
  1071. * @param mixed $value
  1072. * @param mixed $params
  1073. * @return bool
  1074. */
  1075. public static function validateJson($value, $params)
  1076. {
  1077. return (bool) (@json_decode($value));
  1078. }
  1079. }