MediaWiki REL1_28
SVGMetadataExtractor.php
Go to the documentation of this file.
1<?php
32 static function getMetadata( $filename ) {
33 $svg = new SVGReader( $filename );
34
35 return $svg->getMetadata();
36 }
37}
38
42class SVGReader {
43 const DEFAULT_WIDTH = 512;
44 const DEFAULT_HEIGHT = 512;
45 const NS_SVG = 'http://www.w3.org/2000/svg';
47 const LANG_FULL_MATCH = 2;
48
50 private $reader = null;
51
53 private $mDebug = false;
54
56 private $metadata = [];
57 private $languages = [];
58 private $languagePrefixes = [];
59
67 function __construct( $source ) {
69 $this->reader = new XMLReader();
70
71 // Don't use $file->getSize() since file object passed to SVGHandler::getMetadata is bogus.
72 $size = filesize( $source );
73 if ( $size === false ) {
74 throw new MWException( "Error getting filesize of SVG." );
75 }
76
77 if ( $size > $wgSVGMetadataCutoff ) {
78 $this->debug( "SVG is $size bytes, which is bigger than $wgSVGMetadataCutoff. Truncating." );
79 $contents = file_get_contents( $source, false, null, -1, $wgSVGMetadataCutoff );
80 if ( $contents === false ) {
81 throw new MWException( 'Error reading SVG file.' );
82 }
83 $this->reader->XML( $contents, null, LIBXML_NOERROR | LIBXML_NOWARNING );
84 } else {
85 $this->reader->open( $source, null, LIBXML_NOERROR | LIBXML_NOWARNING );
86 }
87
88 // Expand entities, since Adobe Illustrator uses them for xmlns
89 // attributes (bug 31719). Note that libxml2 has some protection
90 // against large recursive entity expansions so this is not as
91 // insecure as it might appear to be. However, it is still extremely
92 // insecure. It's necessary to wrap any read() calls with
93 // libxml_disable_entity_loader() to avoid arbitrary local file
94 // inclusion, or even arbitrary code execution if the expect
95 // extension is installed (bug 46859).
96 $oldDisable = libxml_disable_entity_loader( true );
97 $this->reader->setParserProperty( XMLReader::SUBST_ENTITIES, true );
98
99 $this->metadata['width'] = self::DEFAULT_WIDTH;
100 $this->metadata['height'] = self::DEFAULT_HEIGHT;
101
102 // The size in the units specified by the SVG file
103 // (for the metadata box)
104 // Per the SVG spec, if unspecified, default to '100%'
105 $this->metadata['originalWidth'] = '100%';
106 $this->metadata['originalHeight'] = '100%';
107
108 // Because we cut off the end of the svg making an invalid one. Complicated
109 // try catch thing to make sure warnings get restored. Seems like there should
110 // be a better way.
111 MediaWiki\suppressWarnings();
112 try {
113 $this->read();
114 } catch ( Exception $e ) {
115 // Note, if this happens, the width/height will be taken to be 0x0.
116 // Should we consider it the default 512x512 instead?
117 MediaWiki\restoreWarnings();
118 libxml_disable_entity_loader( $oldDisable );
119 throw $e;
120 }
121 MediaWiki\restoreWarnings();
122 libxml_disable_entity_loader( $oldDisable );
123 }
124
128 public function getMetadata() {
129 return $this->metadata;
130 }
131
137 protected function read() {
138 $keepReading = $this->reader->read();
139
140 /* Skip until first element */
141 while ( $keepReading && $this->reader->nodeType != XMLReader::ELEMENT ) {
142 $keepReading = $this->reader->read();
143 }
144
145 if ( $this->reader->localName != 'svg' || $this->reader->namespaceURI != self::NS_SVG ) {
146 throw new MWException( "Expected <svg> tag, got " .
147 $this->reader->localName . " in NS " . $this->reader->namespaceURI );
148 }
149 $this->debug( "<svg> tag is correct." );
150 $this->handleSVGAttribs();
151
152 $exitDepth = $this->reader->depth;
153 $keepReading = $this->reader->read();
154 while ( $keepReading ) {
155 $tag = $this->reader->localName;
156 $type = $this->reader->nodeType;
157 $isSVG = ( $this->reader->namespaceURI == self::NS_SVG );
158
159 $this->debug( "$tag" );
160
161 if ( $isSVG && $tag == 'svg' && $type == XMLReader::END_ELEMENT
162 && $this->reader->depth <= $exitDepth
163 ) {
164 break;
165 } elseif ( $isSVG && $tag == 'title' ) {
166 $this->readField( $tag, 'title' );
167 } elseif ( $isSVG && $tag == 'desc' ) {
168 $this->readField( $tag, 'description' );
169 } elseif ( $isSVG && $tag == 'metadata' && $type == XMLReader::ELEMENT ) {
170 $this->readXml( $tag, 'metadata' );
171 } elseif ( $isSVG && $tag == 'script' ) {
172 // We normally do not allow scripted svgs.
173 // However its possible to configure MW to let them
174 // in, and such files should be considered animated.
175 $this->metadata['animated'] = true;
176 } elseif ( $tag !== '#text' ) {
177 $this->debug( "Unhandled top-level XML tag $tag" );
178
179 // Recurse into children of current tag, looking for animation and languages.
180 $this->animateFilterAndLang( $tag );
181 }
182
183 // Goto next element, which is sibling of current (Skip children).
184 $keepReading = $this->reader->next();
185 }
186
187 $this->reader->close();
188
189 $this->metadata['translations'] = $this->languages + $this->languagePrefixes;
190
191 return true;
192 }
193
200 private function readField( $name, $metafield = null ) {
201 $this->debug( "Read field $metafield" );
202 if ( !$metafield || $this->reader->nodeType != XMLReader::ELEMENT ) {
203 return;
204 }
205 $keepReading = $this->reader->read();
206 while ( $keepReading ) {
207 if ( $this->reader->localName == $name
208 && $this->reader->namespaceURI == self::NS_SVG
209 && $this->reader->nodeType == XMLReader::END_ELEMENT
210 ) {
211 break;
212 } elseif ( $this->reader->nodeType == XMLReader::TEXT ) {
213 $this->metadata[$metafield] = trim( $this->reader->value );
214 }
215 $keepReading = $this->reader->read();
216 }
217 }
218
225 private function readXml( $metafield = null ) {
226 $this->debug( "Read top level metadata" );
227 if ( !$metafield || $this->reader->nodeType != XMLReader::ELEMENT ) {
228 return;
229 }
230 // @todo Find and store type of xml snippet. metadata['metadataType'] = "rdf"
231 if ( method_exists( $this->reader, 'readInnerXML' ) ) {
232 $this->metadata[$metafield] = trim( $this->reader->readInnerXml() );
233 } else {
234 throw new MWException( "The PHP XMLReader extension does not come " .
235 "with readInnerXML() method. Your libxml is probably out of " .
236 "date (need 2.6.20 or later)." );
237 }
238 $this->reader->next();
239 }
240
247 private function animateFilterAndLang( $name ) {
248 $this->debug( "animate filter for tag $name" );
249 if ( $this->reader->nodeType != XMLReader::ELEMENT ) {
250 return;
251 }
252 if ( $this->reader->isEmptyElement ) {
253 return;
254 }
255 $exitDepth = $this->reader->depth;
256 $keepReading = $this->reader->read();
257 while ( $keepReading ) {
258 if ( $this->reader->localName == $name && $this->reader->depth <= $exitDepth
259 && $this->reader->nodeType == XMLReader::END_ELEMENT
260 ) {
261 break;
262 } elseif ( $this->reader->namespaceURI == self::NS_SVG
263 && $this->reader->nodeType == XMLReader::ELEMENT
264 ) {
265 $sysLang = $this->reader->getAttribute( 'systemLanguage' );
266 if ( !is_null( $sysLang ) && $sysLang !== '' ) {
267 // See http://www.w3.org/TR/SVG/struct.html#SystemLanguageAttribute
268 $langList = explode( ',', $sysLang );
269 foreach ( $langList as $langItem ) {
270 $langItem = trim( $langItem );
271 if ( Language::isWellFormedLanguageTag( $langItem ) ) {
272 $this->languages[$langItem] = self::LANG_FULL_MATCH;
273 }
274 // Note, the standard says that any prefix should work,
275 // here we do only the initial prefix, since that will catch
276 // 99% of cases, and we are going to compare against fallbacks.
277 // This differs mildly from how the spec says languages should be
278 // handled, however it matches better how the MediaWiki language
279 // preference is generally handled.
280 $dash = strpos( $langItem, '-' );
281 // Intentionally checking both !false and > 0 at the same time.
282 if ( $dash ) {
283 $itemPrefix = substr( $langItem, 0, $dash );
284 if ( Language::isWellFormedLanguageTag( $itemPrefix ) ) {
285 $this->languagePrefixes[$itemPrefix] = self::LANG_PREFIX_MATCH;
286 }
287 }
288 }
289 }
290 switch ( $this->reader->localName ) {
291 case 'script':
292 // Normally we disallow files with
293 // <script>, but its possible
294 // to configure MW to disable
295 // such checks.
296 case 'animate':
297 case 'set':
298 case 'animateMotion':
299 case 'animateColor':
300 case 'animateTransform':
301 $this->debug( "HOUSTON WE HAVE ANIMATION" );
302 $this->metadata['animated'] = true;
303 break;
304 }
305 }
306 $keepReading = $this->reader->read();
307 }
308 }
309
310 // @todo FIXME: Unused, remove?
311 private function throwXmlError( $err ) {
312 $this->debug( "FAILURE: $err" );
313 wfDebug( "SVGReader XML error: $err\n" );
314 }
315
316 private function debug( $data ) {
317 if ( $this->mDebug ) {
318 wfDebug( "SVGReader: $data\n" );
319 }
320 }
321
327 private function handleSVGAttribs() {
328 $defaultWidth = self::DEFAULT_WIDTH;
329 $defaultHeight = self::DEFAULT_HEIGHT;
330 $aspect = 1.0;
331 $width = null;
332 $height = null;
333
334 if ( $this->reader->getAttribute( 'viewBox' ) ) {
335 // min-x min-y width height
336 $viewBox = preg_split( '/\s+/', trim( $this->reader->getAttribute( 'viewBox' ) ) );
337 if ( count( $viewBox ) == 4 ) {
338 $viewWidth = $this->scaleSVGUnit( $viewBox[2] );
339 $viewHeight = $this->scaleSVGUnit( $viewBox[3] );
340 if ( $viewWidth > 0 && $viewHeight > 0 ) {
341 $aspect = $viewWidth / $viewHeight;
342 $defaultHeight = $defaultWidth / $aspect;
343 }
344 }
345 }
346 if ( $this->reader->getAttribute( 'width' ) ) {
347 $width = $this->scaleSVGUnit( $this->reader->getAttribute( 'width' ), $defaultWidth );
348 $this->metadata['originalWidth'] = $this->reader->getAttribute( 'width' );
349 }
350 if ( $this->reader->getAttribute( 'height' ) ) {
351 $height = $this->scaleSVGUnit( $this->reader->getAttribute( 'height' ), $defaultHeight );
352 $this->metadata['originalHeight'] = $this->reader->getAttribute( 'height' );
353 }
354
355 if ( !isset( $width ) && !isset( $height ) ) {
356 $width = $defaultWidth;
357 $height = $width / $aspect;
358 } elseif ( isset( $width ) && !isset( $height ) ) {
359 $height = $width / $aspect;
360 } elseif ( isset( $height ) && !isset( $width ) ) {
361 $width = $height * $aspect;
362 }
363
364 if ( $width > 0 && $height > 0 ) {
365 $this->metadata['width'] = intval( round( $width ) );
366 $this->metadata['height'] = intval( round( $height ) );
367 }
368 }
369
378 static function scaleSVGUnit( $length, $viewportSize = 512 ) {
379 static $unitLength = [
380 'px' => 1.0,
381 'pt' => 1.25,
382 'pc' => 15.0,
383 'mm' => 3.543307,
384 'cm' => 35.43307,
385 'in' => 90.0,
386 'em' => 16.0, // fake it?
387 'ex' => 12.0, // fake it?
388 '' => 1.0, // "User units" pixels by default
389 ];
390 $matches = [];
391 if ( preg_match( '/^\s*(\d+(?:\.\d+)?)(em|ex|px|pt|pc|cm|mm|in|%|)\s*$/', $length, $matches ) ) {
392 $length = floatval( $matches[1] );
393 $unit = $matches[2];
394 if ( $unit == '%' ) {
395 return $length * 0.01 * $viewportSize;
396 } else {
397 return $length * $unitLength[$unit];
398 }
399 } else {
400 // Assume pixels
401 return floatval( $length );
402 }
403 }
404}
$wgSVGMetadataCutoff
Don't read SVG metadata beyond this point.
wfDebug( $text, $dest='all', array $context=[])
Sends a line to the debug log if enabled or, optionally, to a comment in output.
MediaWiki exception.
static getMetadata( $filename)
static scaleSVGUnit( $length, $viewportSize=512)
Return a rounded pixel equivalent for a labeled CSS/SVG length.
handleSVGAttribs()
Parse the attributes of an SVG element.
read()
Read the SVG.
readXml( $metafield=null)
Read an XML snippet from an element.
animateFilterAndLang( $name)
Filter all children, looking for animated elements.
readField( $name, $metafield=null)
Read a textelement from an element.
__construct( $source)
Constructor.
null XMLReader $reader
when a variable name is used in a it is silently declared as a new local masking the global
Definition design.txt:95
This document is intended to provide useful advice for parties seeking to redistribute MediaWiki to end users It s targeted particularly at maintainers for Linux since it s been observed that distribution packages of MediaWiki often break We ve consistently had to recommend that users seeking support use official tarballs instead of their distribution s and this often solves whatever problem the user is having It would be nice if this could such as
the array() calling protocol came about after MediaWiki 1.4rc1.
namespace are movable Hooks may change this value to override the return value of MWNamespace::isMovable(). 'NewDifferenceEngine' do that in ParserLimitReportFormat instead use this to modify the parameters of the image and a DIV can begin in one section and end in another Make sure your code can handle that case gracefully See the EditSectionClearerLink extension for an example zero but section is usually empty its values are the globals values before the output is cached one of or reset my talk my contributions etc etc otherwise the built in rate limiting checks are if enabled allows for interception of redirect as a string mapping parameter names to values & $type
Definition hooks.txt:2568
this hook is for auditing only RecentChangesLinked and Watchlist RecentChangesLinked and Watchlist e g Watchlist removed from all revisions and log entries to which it was applied This gives extensions a chance to take it off their books $tag
Definition hooks.txt:1033
Allows to change the fields on the form that will be generated $name
Definition hooks.txt:304
returning false will NOT prevent logging $e
Definition hooks.txt:2110
injection txt This is an overview of how MediaWiki makes use of dependency injection The design described here grew from the discussion of RFC T384 The term dependency this means that anything an object needs to operate should be injected from the the object itself should only know narrow no concrete implementation of the logic it relies on The requirement to inject everything typically results in an architecture that based on two main types of and essentially stateless service objects that use other service objects to operate on the value objects As of the beginning MediaWiki is only starting to use the DI approach Much of the code still relies on global state or direct resulting in a highly cyclical dependency which acts as the top level factory for services in MediaWiki which can be used to gain access to default instances of various services MediaWikiServices however also allows new services to be defined and default services to be redefined Services are defined or redefined by providing a callback the instantiator that will return a new instance of the service When it will create an instance of MediaWikiServices and populate it with the services defined in the files listed by thereby bootstrapping the DI framework Per $wgServiceWiringFiles lists includes ServiceWiring php
Definition injection.txt:37
$source