class Token implements Viewable

ViewModel for displaying token errors.

Token checks are used to validate that a form submission was a deliberate action from the user, and not a forgery that was sent while the user was logged in.

Traits

Provides methods for validating UTF-8 character encoding and string composition.
Provides standard implementation for the Viewable interface.

Methods

string
encodeEscapeUrl(string $url)

URL-encode and escape a query string for use in a URL.

bool
isAlnum(string $alnum)

Check that a string is comprised solely of alphanumeric characters.

bool
isAlnumUnderscore(string $alnumUnderscore)

Check that a string is comprised solely of alphanumeric characters and underscores.

bool
isAlpha(string $alpha)

Check that a string is comprised solely of alphabetical characters.

bool
isUtf8(string $text)

Check if the character encoding of text is UTF-8.

string
trimString(mixed $text)

Cast to string, check UTF-8 encoding and strip trailing whitespace and control characters.

string
pageTitle()

Return title of this page.

from Viewable
setPageTitle(string $pageTitle)

Set the title of this page.

from Viewable
template()

Return the template object required by this page.

from Viewable
setTemplate(string $template)

Set the template used by this page.

from Viewable
string
theme()

Return the theme used by this page.

from Viewable
setTheme(string $theme)

Set (change) the theme.

from Viewable
array
metadata()

Return page-specific metadata overrides.

from Viewable
setMetadata(array $metadata)

Set page-specific overrides of the site metadata.

from Viewable
__construct($model)

Constructor

displayError()

Display error message.

Details

in ValidateString at line 41
string encodeEscapeUrl(string $url)

URL-encode and escape a query string for use in a URL.

Trims, checks for UTF-8 compliance, rawurlencodes and then escapes with htmlspecialchars(). If you wish to use the data on a landing page you must decode it with htmlspecialchars_decode() followed by rawurldecode() in that order. But really, if you are using any characters that need to be encoded in the first place you should probably just stop.

Parameters

string $url Unescaped input URL.

Return Value

string Encoded and escaped URL.

in ValidateString at line 59
bool isAlnum(string $alnum)

Check that a string is comprised solely of alphanumeric characters.

Accented regional characters are rejected. This method is designed to be used to check database identifiers or object property names.

Parameters

string $alnum Input to be tested.

Return Value

bool True if valid alphanumerical string, false otherwise.

in ValidateString at line 77
bool isAlnumUnderscore(string $alnumUnderscore)

Check that a string is comprised solely of alphanumeric characters and underscores.

Accented regional characters are rejected. This method is designed to be used to check database identifiers or object property names.

Parameters

string $alnumUnderscore Input to be tested.

Return Value

bool True if valid alphanumerical or underscore string, false otherwise.

in ValidateString at line 95
bool isAlpha(string $alpha)

Check that a string is comprised solely of alphabetical characters.

Tolerates vanilla ASCII only. Accented regional characters are rejected. This method is designed to be used to check database identifiers or object property names.

Parameters

string $alpha Input to be tested.

Return Value

bool True if valid alphabetical string, false otherwise.

in ValidateString at line 113
bool isUtf8(string $text)

Check if the character encoding of text is UTF-8.

All strings received from external sources must be passed through this function, particularly prior to storage in the database.

Parameters

string $text Input string to check.

Return Value

bool True if string is UTF-8 encoded otherwise false.

in ValidateString at line 131
string trimString(mixed $text)

Cast to string, check UTF-8 encoding and strip trailing whitespace and control characters.

Removes trailing whitespace and control characters (ASCII <= 32 / UTF-8 points 0-32 inclusive), checks for UTF-8 character set and casts input to a string. Note that the data returned by this function still requires escaping at the point of use; it is not database or XSS safe.

As the input is cast to a string do NOT apply this function to non-string types (int, float, bool, object, resource, null, array, etc).

Parameters

mixed $text Input to be trimmed.

Return Value

string Trimmed and UTF-8 validated string.

in Viewable at line 39
string pageTitle()

Return title of this page.

Return Value

string

in Viewable at line 49
setPageTitle(string $pageTitle)

Set the title of this page.

Parameters

string $pageTitle Title of this page.

in Viewable at line 59
Template template()

Return the template object required by this page.

Return Value

Template

in Viewable at line 69
setTemplate(string $template)

Set the template used by this page.

Parameters

string $template Name of template (alphanumeric and underscore characters only).

in Viewable at line 86
string theme()

Return the theme used by this page.

Return Value

string

in Viewable at line 98
setTheme(string $theme)

Set (change) the theme.

You must ensure that the new theme directory contains the HTML template files that you need.

Parameters

string $theme Name of theme directory (alphanumeric and underscores only).

in Viewable at line 115
array metadata()

Return page-specific metadata overrides.

Return Value

array

in Viewable at line 125
setMetadata(array $metadata)

Set page-specific overrides of the site metadata.

Parameters

array $metadata Array of metadata as key => value pairs.

at line 50
__construct($model)

Constructor

Parameters

$model

at line 64
displayError()

Display error message.