MediaWiki REL1_27
FormSpecialPage.php
Go to the documentation of this file.
1<?php
31abstract class FormSpecialPage extends SpecialPage {
36 protected $par = null;
37
42 protected $reauthPostData = null;
43
48 abstract protected function getFormFields();
49
54 protected function preText() {
55 return '';
56 }
57
62 protected function postText() {
63 return '';
64 }
65
70 protected function alterForm( HTMLForm $form ) {
71 }
72
79 protected function getMessagePrefix() {
80 return strtolower( $this->getName() );
81 }
82
89 protected function getDisplayFormat() {
90 return 'table';
91 }
92
97 protected function getForm() {
98 $context = $this->getContext();
99 $onSubmit = [ $this, 'onSubmit' ];
100
101 if ( $this->reauthPostData ) {
102 // Restore POST data
104 $oldRequest = $this->getRequest();
105 $context->setRequest( new DerivativeRequest(
106 $oldRequest, $this->reauthPostData + $oldRequest->getQueryValues(), true
107 ) );
108
109 // But don't treat it as a "real" submission just in case of some
110 // crazy kind of CSRF.
111 $onSubmit = function () {
112 return false;
113 };
114 }
115
116 $form = HTMLForm::factory(
117 $this->getDisplayFormat(),
118 $this->getFormFields(),
119 $context,
120 $this->getMessagePrefix()
121 );
122 $form->setSubmitCallback( $onSubmit );
123 if ( $this->getDisplayFormat() !== 'ooui' ) {
124 // No legend and wrapper by default in OOUI forms, but can be set manually
125 // from alterForm()
126 $form->setWrapperLegendMsg( $this->getMessagePrefix() . '-legend' );
127 }
128
129 $headerMsg = $this->msg( $this->getMessagePrefix() . '-text' );
130 if ( !$headerMsg->isDisabled() ) {
131 $form->addHeaderText( $headerMsg->parseAsBlock() );
132 }
133
134 // Retain query parameters (uselang etc)
135 $params = array_diff_key(
136 $this->getRequest()->getQueryValues(), [ 'title' => null ] );
137 $form->addHiddenField( 'redirectparams', wfArrayToCgi( $params ) );
138
139 $form->addPreText( $this->preText() );
140 $form->addPostText( $this->postText() );
141 $this->alterForm( $form );
142
143 // Give hooks a chance to alter the form, adding extra fields or text etc
144 Hooks::run( 'SpecialPageBeforeFormDisplay', [ $this->getName(), &$form ] );
145
146 return $form;
147 }
148
155 abstract public function onSubmit( array $data /* $form = null */ );
156
162 public function onSuccess() {
163 }
164
170 public function execute( $par ) {
171 $this->setParameter( $par );
172 $this->setHeaders();
173
174 // This will throw exceptions if there's a problem
175 $this->checkExecutePermissions( $this->getUser() );
176
177 $securityLevel = $this->getLoginSecurityLevel();
178 if ( $securityLevel !== false && !$this->checkLoginSecurityLevel( $securityLevel ) ) {
179 return;
180 }
181
182 $form = $this->getForm();
183 if ( $form->show() ) {
184 $this->onSuccess();
185 }
186 }
187
192 protected function setParameter( $par ) {
193 $this->par = $par;
194 }
195
202 protected function checkExecutePermissions( User $user ) {
203 $this->checkPermissions();
204
205 if ( $this->requiresUnblock() && $user->isBlocked() ) {
206 $block = $user->getBlock();
207 throw new UserBlockedError( $block );
208 }
209
210 if ( $this->requiresWrite() ) {
211 $this->checkReadOnly();
212 }
213 }
214
219 public function requiresWrite() {
220 return true;
221 }
222
227 public function requiresUnblock() {
228 return true;
229 }
230
237 protected function setReauthPostData( array $data ) {
238 $this->reauthPostData = $data;
239 }
240}
wfArrayToCgi( $array1, $array2=null, $prefix='')
This function takes one or two arrays as input, and returns a CGI-style string, e....
An IContextSource implementation which will inherit context from another source but allow individual ...
Similar to FauxRequest, but only fakes URL parameters and method (POST or GET) and use the base reque...
Special page which uses an HTMLForm to handle processing.
array null $reauthPostData
POST data preserved across re-authentication.
getMessagePrefix()
Get message prefix for HTMLForm.
onSuccess()
Do something exciting on successful processing of the form, most likely to show a confirmation messag...
getForm()
Get the HTMLForm to control behavior.
preText()
Add pre-text to the form.
alterForm(HTMLForm $form)
Play with the HTMLForm if you need to more substantially.
postText()
Add post-text to the form.
getDisplayFormat()
Get display format for the form.
onSubmit(array $data)
Process the form on POST submission.
setReauthPostData(array $data)
Preserve POST data across reauthentication.
checkExecutePermissions(User $user)
Called from execute() to check if the given user can perform this action.
requiresUnblock()
Whether this action cannot be executed by a blocked user.
getFormFields()
Get an HTMLForm descriptor array.
setParameter( $par)
Maybe do something interesting with the subpage parameter.
requiresWrite()
Whether this action requires the wiki not to be locked.
string $par
The sub-page of the special page.
execute( $par)
Basic SpecialPage workflow: get a form, send it to the user; get some data back,.
Object handling generic submission, CSRF protection, layout and other logic for UI forms.
Definition HTMLForm.php:123
static factory( $displayFormat)
Construct a HTMLForm object for given display type.
Definition HTMLForm.php:264
Parent class for all special pages.
getName()
Get the name of this Special Page.
setHeaders()
Sets headers - this should be called from the execute() method of all derived classes!
checkLoginSecurityLevel( $level=null)
Verifies that the user meets the security level, possibly reauthenticating them in the process.
getUser()
Shortcut to get the User executing this instance.
checkPermissions()
Checks if userCanExecute, and if not throws a PermissionsError.
getContext()
Gets the context this SpecialPage is executed in.
getRequest()
Get the WebRequest being used for this instance.
checkReadOnly()
If the wiki is currently in readonly mode, throws a ReadOnlyError.
getLoginSecurityLevel()
Tells if the special page does something security-sensitive and needs extra defense against a stolen ...
msg()
Wrapper around wfMessage that sets the current context.
Show an error when the user tries to do something whilst blocked.
The User object encapsulates all of the user-specific settings (user_id, name, rights,...
Definition User.php:47
isBlocked( $bFromSlave=true)
Check if user is blocked.
Definition User.php:1915
the array() calling protocol came about after MediaWiki 1.4rc1.
please add to it if you re going to add events to the MediaWiki code where normally authentication against an external auth plugin would be creating a local account $user
Definition hooks.txt:249
injection txt This is an overview of how MediaWiki makes use of dependency injection The design described here grew from the discussion of RFC T384 The term dependency this means that anything an object needs to operate should be injected from the the object itself should only know narrow no concrete implementation of the logic it relies on The requirement to inject everything typically results in an architecture that based on two main types of and essentially stateless service objects that use other service objects to operate on the value objects As of the beginning MediaWiki is only starting to use the DI approach Much of the code still relies on global state or direct resulting in a highly cyclical dependency which acts as the top level factory for services in MediaWiki which can be used to gain access to default instances of various services MediaWikiServices however also allows new services to be defined and default services to be redefined Services are defined or redefined by providing a callback the instantiator that will return a new instance of the service When it will create an instance of MediaWikiServices and populate it with the services defined in the files listed by thereby bootstrapping the DI framework Per $wgServiceWiringFiles lists includes ServiceWiring php
Definition injection.txt:37
$context
Definition load.php:44
$params