* (bug 6061) Improper escaping in some html forms
[mediawiki.git] / includes / Export.php
blobd0253eb7ae03f467d862376470a78a0a0a4e3a0c
1 <?php
2 # Copyright (C) 2003, 2005, 2006 Brion Vibber <brion@pobox.com>
3 # http://www.mediawiki.org/
5 # This program is free software; you can redistribute it and/or modify
6 # it under the terms of the GNU General Public License as published by
7 # the Free Software Foundation; either version 2 of the License, or
8 # (at your option) any later version.
10 # This program is distributed in the hope that it will be useful,
11 # but WITHOUT ANY WARRANTY; without even the implied warranty of
12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 # GNU General Public License for more details.
15 # You should have received a copy of the GNU General Public License along
16 # with this program; if not, write to the Free Software Foundation, Inc.,
17 # 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
18 # http://www.gnu.org/copyleft/gpl.html
19 /**
21 * @package MediaWiki
22 * @subpackage SpecialPage
25 /** */
26 require_once( 'Revision.php' );
28 define( 'MW_EXPORT_FULL', 0 );
29 define( 'MW_EXPORT_CURRENT', 1 );
31 define( 'MW_EXPORT_BUFFER', 0 );
32 define( 'MW_EXPORT_STREAM', 1 );
34 define( 'MW_EXPORT_TEXT', 0 );
35 define( 'MW_EXPORT_STUB', 1 );
38 /**
39 * @package MediaWiki
40 * @subpackage SpecialPage
42 class WikiExporter {
44 var $list_authors = false ; # Return distinct author list (when not returning full history)
45 var $author_list = "" ;
47 /**
48 * If using MW_EXPORT_STREAM to stream a large amount of data,
49 * provide a database connection which is not managed by
50 * LoadBalancer to read from: some history blob types will
51 * make additional queries to pull source data while the
52 * main query is still running.
54 * @param Database $db
55 * @param int $history one of MW_EXPORT_FULL or MW_EXPORT_CURRENT
56 * @param int $buffer one of MW_EXPORT_BUFFER or MW_EXPORT_STREAM
58 function WikiExporter( &$db, $history = MW_EXPORT_CURRENT,
59 $buffer = MW_EXPORT_BUFFER, $text = MW_EXPORT_TEXT ) {
60 $this->db =& $db;
61 $this->history = $history;
62 $this->buffer = $buffer;
63 $this->writer = new XmlDumpWriter();
64 $this->sink = new DumpOutput();
65 $this->text = $text;
68 /**
69 * Set the DumpOutput or DumpFilter object which will receive
70 * various row objects and XML output for filtering. Filters
71 * can be chained or used as callbacks.
73 * @param mixed $callback
75 function setOutputSink( &$sink ) {
76 $this->sink =& $sink;
79 function openStream() {
80 $output = $this->writer->openStream();
81 $this->sink->writeOpenStream( $output );
84 function closeStream() {
85 $output = $this->writer->closeStream();
86 $this->sink->writeCloseStream( $output );
89 /**
90 * Dumps a series of page and revision records for all pages
91 * in the database, either including complete history or only
92 * the most recent version.
94 function allPages() {
95 return $this->dumpFrom( '' );
98 /**
99 * Dumps a series of page and revision records for those pages
100 * in the database falling within the page_id range given.
101 * @param int $start Inclusive lower limit (this id is included)
102 * @param int $end Exclusive upper limit (this id is not included)
103 * If 0, no upper limit.
105 function pagesByRange( $start, $end ) {
106 $condition = 'page_id >= ' . intval( $start );
107 if( $end ) {
108 $condition .= ' AND page_id < ' . intval( $end );
110 return $this->dumpFrom( $condition );
114 * @param Title $title
116 function pageByTitle( $title ) {
117 return $this->dumpFrom(
118 'page_namespace=' . $title->getNamespace() .
119 ' AND page_title=' . $this->db->addQuotes( $title->getDbKey() ) );
122 function pageByName( $name ) {
123 $title = Title::newFromText( $name );
124 if( is_null( $title ) ) {
125 return new WikiError( "Can't export invalid title" );
126 } else {
127 return $this->pageByTitle( $title );
131 function pagesByName( $names ) {
132 foreach( $names as $name ) {
133 $this->pageByName( $name );
138 // -------------------- private implementation below --------------------
140 # Generates the distinct list of authors of an article
141 # Not called by default (depends on $this->list_authors)
142 # Can be set by Special:Export when not exporting whole history
143 function do_list_authors ( $page , $revision , $cond ) {
144 $fname = "do_list_authors" ;
145 wfProfileIn( $fname );
146 $this->author_list = "<contributors>";
147 $sql = "SELECT DISTINCT rev_user_text,rev_user FROM {$page},{$revision} WHERE page_id=rev_page AND " . $cond ;
148 $result = $this->db->query( $sql, $fname );
149 $resultset = $this->db->resultObject( $result );
150 while( $row = $resultset->fetchObject() ) {
151 $this->author_list .= "<contributor>" .
152 "<username>" .
153 htmlentities( $row->rev_user_text ) .
154 "</username>" .
155 "<id>" .
156 $row->rev_user .
157 "</id>" .
158 "</contributor>";
160 wfProfileOut( $fname );
161 $this->author_list .= "</contributors>";
164 function dumpFrom( $cond = '' ) {
165 $fname = 'WikiExporter::dumpFrom';
166 wfProfileIn( $fname );
168 $page = $this->db->tableName( 'page' );
169 $revision = $this->db->tableName( 'revision' );
170 $text = $this->db->tableName( 'text' );
172 if( $this->history == MW_EXPORT_FULL ) {
173 $join = 'page_id=rev_page';
174 } elseif( $this->history == MW_EXPORT_CURRENT ) {
175 if ( $this->list_authors && $cond != '' ) { // List authors, if so desired
176 $this->do_list_authors ( $page , $revision , $cond );
178 $join = 'page_id=rev_page AND page_latest=rev_id';
179 } else {
180 wfProfileOut( $fname );
181 return new WikiError( "$fname given invalid history dump type." );
183 $where = ( $cond == '' ) ? '' : "$cond AND";
185 if( $this->buffer == MW_EXPORT_STREAM ) {
186 $prev = $this->db->bufferResults( false );
188 if( $cond == '' ) {
189 // Optimization hack for full-database dump
190 $revindex = $pageindex = $this->db->useIndexClause("PRIMARY");
191 $straight = ' /*! STRAIGHT_JOIN */ ';
192 } else {
193 $pageindex = '';
194 $revindex = '';
195 $straight = '';
197 if( $this->text == MW_EXPORT_STUB ) {
198 $sql = "SELECT $straight * FROM
199 $page $pageindex,
200 $revision $revindex
201 WHERE $where $join
202 ORDER BY page_id";
203 } else {
204 $sql = "SELECT $straight * FROM
205 $page $pageindex,
206 $revision $revindex,
207 $text
208 WHERE $where $join AND rev_text_id=old_id
209 ORDER BY page_id";
211 $result = $this->db->query( $sql, $fname );
212 $wrapper = $this->db->resultObject( $result );
213 $this->outputStream( $wrapper );
215 if ( $this->list_authors ) {
216 $this->outputStream( $wrapper );
219 if( $this->buffer == MW_EXPORT_STREAM ) {
220 $this->db->bufferResults( $prev );
223 wfProfileOut( $fname );
227 * Runs through a query result set dumping page and revision records.
228 * The result set should be sorted/grouped by page to avoid duplicate
229 * page records in the output.
231 * The result set will be freed once complete. Should be safe for
232 * streaming (non-buffered) queries, as long as it was made on a
233 * separate database connection not managed by LoadBalancer; some
234 * blob storage types will make queries to pull source data.
236 * @param ResultWrapper $resultset
237 * @access private
239 function outputStream( $resultset ) {
240 $last = null;
241 while( $row = $resultset->fetchObject() ) {
242 if( is_null( $last ) ||
243 $last->page_namespace != $row->page_namespace ||
244 $last->page_title != $row->page_title ) {
245 if( isset( $last ) ) {
246 $output = $this->writer->closePage();
247 $this->sink->writeClosePage( $output );
249 $output = $this->writer->openPage( $row );
250 $this->sink->writeOpenPage( $row, $output );
251 $last = $row;
253 $output = $this->writer->writeRevision( $row );
254 $this->sink->writeRevision( $row, $output );
256 if( isset( $last ) ) {
257 $output = $this->author_list . $this->writer->closePage();
258 $this->sink->writeClosePage( $output );
260 $resultset->free();
264 class XmlDumpWriter {
267 * Returns the export schema version.
268 * @return string
270 function schemaVersion() {
271 return "0.3"; // FIXME: upgrade to 0.4 when updated XSD is ready, for the revision deletion bits
275 * Opens the XML output stream's root <mediawiki> element.
276 * This does not include an xml directive, so is safe to include
277 * as a subelement in a larger XML stream. Namespace and XML Schema
278 * references are included.
280 * Output will be encoded in UTF-8.
282 * @return string
284 function openStream() {
285 global $wgContLanguageCode;
286 $ver = $this->schemaVersion();
287 return wfElement( 'mediawiki', array(
288 'xmlns' => "http://www.mediawiki.org/xml/export-$ver/",
289 'xmlns:xsi' => "http://www.w3.org/2001/XMLSchema-instance",
290 'xsi:schemaLocation' => "http://www.mediawiki.org/xml/export-$ver/ " .
291 "http://www.mediawiki.org/xml/export-$ver.xsd",
292 'version' => $ver,
293 'xml:lang' => $wgContLanguageCode ),
294 null ) .
295 "\n" .
296 $this->siteInfo();
299 function siteInfo() {
300 $info = array(
301 $this->sitename(),
302 $this->homelink(),
303 $this->generator(),
304 $this->caseSetting(),
305 $this->namespaces() );
306 return " <siteinfo>\n " .
307 implode( "\n ", $info ) .
308 "\n </siteinfo>\n";
311 function sitename() {
312 global $wgSitename;
313 return wfElement( 'sitename', array(), $wgSitename );
316 function generator() {
317 global $wgVersion;
318 return wfElement( 'generator', array(), "MediaWiki $wgVersion" );
321 function homelink() {
322 $page = Title::newFromText( wfMsgForContent( 'mainpage' ) );
323 return wfElement( 'base', array(), $page->getFullUrl() );
326 function caseSetting() {
327 global $wgCapitalLinks;
328 // "case-insensitive" option is reserved for future
329 $sensitivity = $wgCapitalLinks ? 'first-letter' : 'case-sensitive';
330 return wfElement( 'case', array(), $sensitivity );
333 function namespaces() {
334 global $wgContLang;
335 $spaces = " <namespaces>\n";
336 foreach( $wgContLang->getFormattedNamespaces() as $ns => $title ) {
337 $spaces .= ' ' . wfElement( 'namespace', array( 'key' => $ns ), $title ) . "\n";
339 $spaces .= " </namespaces>";
340 return $spaces;
344 * Closes the output stream with the closing root element.
345 * Call when finished dumping things.
347 function closeStream() {
348 return "</mediawiki>\n";
353 * Opens a <page> section on the output stream, with data
354 * from the given database row.
356 * @param object $row
357 * @return string
358 * @access private
360 function openPage( $row ) {
361 $out = " <page>\n";
362 $title = Title::makeTitle( $row->page_namespace, $row->page_title );
363 $out .= ' ' . wfElementClean( 'title', array(), $title->getPrefixedText() ) . "\n";
364 $out .= ' ' . wfElement( 'id', array(), strval( $row->page_id ) ) . "\n";
365 if( '' != $row->page_restrictions ) {
366 $out .= ' ' . wfElement( 'restrictions', array(),
367 strval( $row->page_restrictions ) ) . "\n";
369 return $out;
373 * Closes a <page> section on the output stream.
375 * @access private
377 function closePage() {
378 return " </page>\n";
382 * Dumps a <revision> section on the output stream, with
383 * data filled in from the given database row.
385 * @param object $row
386 * @return string
387 * @access private
389 function writeRevision( $row ) {
390 $fname = 'WikiExporter::dumpRev';
391 wfProfileIn( $fname );
393 $out = " <revision>\n";
394 $out .= " " . wfElement( 'id', null, strval( $row->rev_id ) ) . "\n";
396 $ts = wfTimestamp( TS_ISO_8601, $row->rev_timestamp );
397 $out .= " " . wfElement( 'timestamp', null, $ts ) . "\n";
399 if( $row->rev_deleted & MW_REV_DELETED_USER ) {
400 $out .= " " . wfElement( 'contributor', array( 'deleted' => 'deleted' ) ) . "\n";
401 } else {
402 $out .= " <contributor>\n";
403 if( $row->rev_user ) {
404 $out .= " " . wfElementClean( 'username', null, strval( $row->rev_user_text ) ) . "\n";
405 $out .= " " . wfElement( 'id', null, strval( $row->rev_user ) ) . "\n";
406 } else {
407 $out .= " " . wfElementClean( 'ip', null, strval( $row->rev_user_text ) ) . "\n";
409 $out .= " </contributor>\n";
412 if( $row->rev_minor_edit ) {
413 $out .= " <minor/>\n";
415 if( $row->rev_deleted & MW_REV_DELETED_COMMENT ) {
416 $out .= " " . wfElement( 'comment', array( 'deleted' => 'deleted' ) ) . "\n";
417 } elseif( $row->rev_comment != '' ) {
418 $out .= " " . wfElementClean( 'comment', null, strval( $row->rev_comment ) ) . "\n";
421 if( $row->rev_deleted & MW_REV_DELETED_TEXT ) {
422 $out .= " " . wfElement( 'text', array( 'deleted' => 'deleted' ) ) . "\n";
423 } elseif( isset( $row->old_text ) ) {
424 // Raw text from the database may have invalid chars
425 $text = strval( Revision::getRevisionText( $row ) );
426 $out .= " " . wfElementClean( 'text',
427 array( 'xml:space' => 'preserve' ),
428 strval( $text ) ) . "\n";
429 } else {
430 // Stub output
431 $out .= " " . wfElement( 'text',
432 array( 'id' => $row->rev_text_id ),
433 "" ) . "\n";
436 $out .= " </revision>\n";
438 wfProfileOut( $fname );
439 return $out;
446 * Base class for output stream; prints to stdout or buffer or whereever.
448 class DumpOutput {
449 function writeOpenStream( $string ) {
450 $this->write( $string );
453 function writeCloseStream( $string ) {
454 $this->write( $string );
457 function writeOpenPage( $page, $string ) {
458 $this->write( $string );
461 function writeClosePage( $string ) {
462 $this->write( $string );
465 function writeRevision( $rev, $string ) {
466 $this->write( $string );
470 * Override to write to a different stream type.
471 * @return bool
473 function write( $string ) {
474 print $string;
479 * Stream outputter to send data to a file.
481 class DumpFileOutput extends DumpOutput {
482 var $handle;
484 function DumpFileOutput( $file ) {
485 $this->handle = fopen( $file, "wt" );
488 function write( $string ) {
489 fputs( $this->handle, $string );
494 * Stream outputter to send data to a file via some filter program.
495 * Even if compression is available in a library, using a separate
496 * program can allow us to make use of a multi-processor system.
498 class DumpPipeOutput extends DumpFileOutput {
499 function DumpPipeOutput( $command, $file = null ) {
500 if( !is_null( $file ) ) {
501 $command .= " > " . wfEscapeShellArg( $file );
503 $this->handle = popen( $command, "w" );
508 * Sends dump output via the gzip compressor.
510 class DumpGZipOutput extends DumpPipeOutput {
511 function DumpGZipOutput( $file ) {
512 parent::DumpPipeOutput( "gzip", $file );
517 * Sends dump output via the bgzip2 compressor.
519 class DumpBZip2Output extends DumpPipeOutput {
520 function DumpBZip2Output( $file ) {
521 parent::DumpPipeOutput( "bzip2", $file );
526 * Sends dump output via the p7zip compressor.
528 class Dump7ZipOutput extends DumpPipeOutput {
529 function Dump7ZipOutput( $file ) {
530 $command = "7za a -bd -si " . wfEscapeShellArg( $file );
531 // Suppress annoying useless crap from p7zip
532 // Unfortunately this could suppress real error messages too
533 $command .= " >/dev/null 2>&1";
534 parent::DumpPipeOutput( $command );
541 * Dump output filter class.
542 * This just does output filtering and streaming; XML formatting is done
543 * higher up, so be careful in what you do.
545 class DumpFilter {
546 function DumpFilter( &$sink ) {
547 $this->sink =& $sink;
550 function writeOpenStream( $string ) {
551 $this->sink->writeOpenStream( $string );
554 function writeCloseStream( $string ) {
555 $this->sink->writeCloseStream( $string );
558 function writeOpenPage( $page, $string ) {
559 $this->sendingThisPage = $this->pass( $page, $string );
560 if( $this->sendingThisPage ) {
561 $this->sink->writeOpenPage( $page, $string );
565 function writeClosePage( $string ) {
566 if( $this->sendingThisPage ) {
567 $this->sink->writeClosePage( $string );
568 $this->sendingThisPage = false;
572 function writeRevision( $rev, $string ) {
573 if( $this->sendingThisPage ) {
574 $this->sink->writeRevision( $rev, $string );
579 * Override for page-based filter types.
580 * @return bool
582 function pass( $page, $string ) {
583 return true;
588 * Simple dump output filter to exclude all talk pages.
590 class DumpNotalkFilter extends DumpFilter {
591 function pass( $page ) {
592 return !Namespace::isTalk( $page->page_namespace );
597 * Dump output filter to include or exclude pages in a given set of namespaces.
599 class DumpNamespaceFilter extends DumpFilter {
600 var $invert = false;
601 var $namespaces = array();
603 function DumpNamespaceFilter( &$sink, $param ) {
604 parent::DumpFilter( $sink );
606 $constants = array(
607 "NS_MAIN" => NS_MAIN,
608 "NS_TALK" => NS_TALK,
609 "NS_USER" => NS_USER,
610 "NS_USER_TALK" => NS_USER_TALK,
611 "NS_PROJECT" => NS_PROJECT,
612 "NS_PROJECT_TALK" => NS_PROJECT_TALK,
613 "NS_IMAGE" => NS_IMAGE,
614 "NS_IMAGE_TALK" => NS_IMAGE_TALK,
615 "NS_MEDIAWIKI" => NS_MEDIAWIKI,
616 "NS_MEDIAWIKI_TALK" => NS_MEDIAWIKI_TALK,
617 "NS_TEMPLATE" => NS_TEMPLATE,
618 "NS_TEMPLATE_TALK" => NS_TEMPLATE_TALK,
619 "NS_HELP" => NS_HELP,
620 "NS_HELP_TALK" => NS_HELP_TALK,
621 "NS_CATEGORY" => NS_CATEGORY,
622 "NS_CATEGORY_TALK" => NS_CATEGORY_TALK );
624 if( $param{0} == '!' ) {
625 $this->invert = true;
626 $param = substr( $param, 1 );
629 foreach( explode( ',', $param ) as $key ) {
630 $key = trim( $key );
631 if( isset( $constants[$key] ) ) {
632 $ns = $constants[$key];
633 $this->namespaces[$ns] = true;
634 } elseif( is_numeric( $key ) ) {
635 $ns = intval( $key );
636 $this->namespaces[$ns] = true;
637 } else {
638 wfDie( "Unrecognized namespace key '$key'\n" );
643 function pass( $page ) {
644 $match = isset( $this->namespaces[$page->page_namespace] );
645 return $this->invert xor $match;
651 * Dump output filter to include only the last revision in each page sequence.
653 class DumpLatestFilter extends DumpFilter {
654 var $page, $pageString, $rev, $revString;
656 function writeOpenPage( $page, $string ) {
657 $this->page = $page;
658 $this->pageString = $string;
661 function writeClosePage( $string ) {
662 if( $this->rev ) {
663 $this->sink->writeOpenPage( $this->page, $this->pageString );
664 $this->sink->writeRevision( $this->rev, $this->revString );
665 $this->sink->writeClosePage( $string );
667 $this->rev = null;
668 $this->revString = null;
669 $this->page = null;
670 $this->pageString = null;
673 function writeRevision( $rev, $string ) {
674 if( $rev->rev_id == $this->page->page_latest ) {
675 $this->rev = $rev;
676 $this->revString = $string;
682 * Base class for output stream; prints to stdout or buffer or whereever.
684 class DumpMultiWriter {
685 function DumpMultiWriter( $sinks ) {
686 $this->sinks = $sinks;
687 $this->count = count( $sinks );
690 function writeOpenStream( $string ) {
691 for( $i = 0; $i < $this->count; $i++ ) {
692 $this->sinks[$i]->writeOpenStream( $string );
696 function writeCloseStream( $string ) {
697 for( $i = 0; $i < $this->count; $i++ ) {
698 $this->sinks[$i]->writeCloseStream( $string );
702 function writeOpenPage( $page, $string ) {
703 for( $i = 0; $i < $this->count; $i++ ) {
704 $this->sinks[$i]->writeOpenPage( $page, $string );
708 function writeClosePage( $string ) {
709 for( $i = 0; $i < $this->count; $i++ ) {
710 $this->sinks[$i]->writeClosePage( $string );
714 function writeRevision( $rev, $string ) {
715 for( $i = 0; $i < $this->count; $i++ ) {
716 $this->sinks[$i]->writeRevision( $rev, $string );
721 function xmlsafe( $string ) {
722 $fname = 'xmlsafe';
723 wfProfileIn( $fname );
726 * The page may contain old data which has not been properly normalized.
727 * Invalid UTF-8 sequences or forbidden control characters will make our
728 * XML output invalid, so be sure to strip them out.
730 $string = UtfNormal::cleanUp( $string );
732 $string = htmlspecialchars( $string );
733 wfProfileOut( $fname );
734 return $string;