diff options
Diffstat (limited to 'plugins/CustomDimensions/Dimension/Name.php')
m--------- | plugins/CustomDimensions | 0 | ||||
-rw-r--r-- | plugins/CustomDimensions/Dimension/Name.php | 51 |
2 files changed, 51 insertions, 0 deletions
diff --git a/plugins/CustomDimensions b/plugins/CustomDimensions deleted file mode 160000 -Subproject 318661a2fb1ef3b3e5d6d999ae8b9628cb5a113 diff --git a/plugins/CustomDimensions/Dimension/Name.php b/plugins/CustomDimensions/Dimension/Name.php new file mode 100644 index 0000000000..246ba92a71 --- /dev/null +++ b/plugins/CustomDimensions/Dimension/Name.php @@ -0,0 +1,51 @@ +<?php +/** + * Matomo - free/libre analytics platform + * + * @link https://matomo.org + * @license http://www.gnu.org/licenses/gpl-3.0.html GPL v3 or later + * + */ + +namespace Piwik\Plugins\CustomDimensions\Dimension; + +use \Exception; +use Piwik\Piwik; + +class Name +{ + public function __construct($name) + { + $this->name = $name; + } + + public function check() + { + $maxLen = 255; + + if (empty($this->name)) { + throw new Exception(Piwik::translate('CustomDimensions_NameIsRequired')); + } + + if (strlen($this->name) > $maxLen) { + throw new Exception(Piwik::translate('CustomDimensions_NameIsTooLong', $maxLen)); + } + + $blockedCharacters = self::getBlockedCharacters(); + + // we do not really have to do this and it is not very effective for preventing XSS but doesn't hurt to have + if (strip_tags($this->name) !== $this->name || str_replace($blockedCharacters, '', $this->name) !== $this->name) { + throw new Exception(Piwik::translate('CustomDimensions_NameAllowedCharacters')); + } + } + + /** + * @api + */ + public static function getBlockedCharacters() + { + return [ + '/', '\\', '&', '.', '<', '>', + ]; + } +} |