extend.php 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488
  1. <?php
  2. // +----------------------------------------------------------------------
  3. // | ThinkPHP [ WE CAN DO IT JUST THINK IT ]
  4. // +----------------------------------------------------------------------
  5. // | Copyright (c) 2006-2012 http://thinkphp.cn All rights reserved.
  6. // +----------------------------------------------------------------------
  7. // | Licensed ( http://www.apache.org/licenses/LICENSE-2.0 )
  8. // +----------------------------------------------------------------------
  9. // | Author: liu21st <liu21st@gmail.com>
  10. // +----------------------------------------------------------------------
  11. /**
  12. * Think扩展函数库 需要手动加载后调用或者放入项目函数库
  13. * @category Extend
  14. * @package Extend
  15. * @subpackage Function
  16. * @author liu21st <liu21st@gmail.com>
  17. */
  18. /**
  19. * 字符串截取,支持中文和其他编码
  20. * @static
  21. * @access public
  22. * @param string $str 需要转换的字符串
  23. * @param string $start 开始位置
  24. * @param string $length 截取长度
  25. * @param string $charset 编码格式
  26. * @param string $suffix 截断显示字符
  27. * @return string
  28. */
  29. function msubstr($str, $start=0, $length, $charset="utf-8", $suffix=true) {
  30. if(function_exists("mb_substr"))
  31. $slice = mb_substr($str, $start, $length, $charset);
  32. elseif(function_exists('iconv_substr')) {
  33. $slice = iconv_substr($str,$start,$length,$charset);
  34. if(false === $slice) {
  35. $slice = '';
  36. }
  37. }else{
  38. $re['utf-8'] = "/[\x01-\x7f]|[\xc2-\xdf][\x80-\xbf]|[\xe0-\xef][\x80-\xbf]{2}|[\xf0-\xff][\x80-\xbf]{3}/";
  39. $re['gb2312'] = "/[\x01-\x7f]|[\xb0-\xf7][\xa0-\xfe]/";
  40. $re['gbk'] = "/[\x01-\x7f]|[\x81-\xfe][\x40-\xfe]/";
  41. $re['big5'] = "/[\x01-\x7f]|[\x81-\xfe]([\x40-\x7e]|\xa1-\xfe])/";
  42. preg_match_all($re[$charset], $str, $match);
  43. $slice = join("",array_slice($match[0], $start, $length));
  44. }
  45. return $suffix ? $slice.'...' : $slice;
  46. }
  47. /**
  48. * 产生随机字串,可用来自动生成密码 默认长度6位 字母和数字混合
  49. * @param string $len 长度
  50. * @param string $type 字串类型
  51. * 0 字母 1 数字 其它 混合
  52. * @param string $addChars 额外字符
  53. * @return string
  54. */
  55. function rand_string($len=6,$type='',$addChars='') {
  56. $str ='';
  57. switch($type) {
  58. case 0:
  59. $chars='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'.$addChars;
  60. break;
  61. case 1:
  62. $chars= str_repeat('0123456789',3);
  63. break;
  64. case 2:
  65. $chars='ABCDEFGHIJKLMNOPQRSTUVWXYZ'.$addChars;
  66. break;
  67. case 3:
  68. $chars='abcdefghijklmnopqrstuvwxyz'.$addChars;
  69. break;
  70. case 4:
  71. $chars = "们以我到他会作时要动国产的一是工就年阶义发成部民可出能方进在了不和有大这主中人上为来分生对于学下级地个用同行面说种过命度革而多子后自社加小机也经力线本电高量长党得实家定深法表着水理化争现所二起政三好十战无农使性前等反体合斗路图把结第里正新开论之物从当两些还天资事队批点育重其思与间内去因件日利相由压员气业代全组数果期导平各基或月毛然如应形想制心样干都向变关问比展那它最及外没看治提五解系林者米群头意只明四道马认次文通但条较克又公孔领军流入接席位情运器并飞原油放立题质指建区验活众很教决特此常石强极土少已根共直团统式转别造切九你取西持总料连任志观调七么山程百报更见必真保热委手改管处己将修支识病象几先老光专什六型具示复安带每东增则完风回南广劳轮科北打积车计给节做务被整联步类集号列温装即毫知轴研单色坚据速防史拉世设达尔场织历花受求传口断况采精金界品判参层止边清至万确究书术状厂须离再目海交权且儿青才证低越际八试规斯近注办布门铁需走议县兵固除般引齿千胜细影济白格效置推空配刀叶率述今选养德话查差半敌始片施响收华觉备名红续均药标记难存测士身紧液派准斤角降维板许破述技消底床田势端感往神便贺村构照容非搞亚磨族火段算适讲按值美态黄易彪服早班麦削信排台声该击素张密害侯草何树肥继右属市严径螺检左页抗苏显苦英快称坏移约巴材省黑武培著河帝仅针怎植京助升王眼她抓含苗副杂普谈围食射源例致酸旧却充足短划剂宣环落首尺波承粉践府鱼随考刻靠够满夫失包住促枝局菌杆周护岩师举曲春元超负砂封换太模贫减阳扬江析亩木言球朝医校古呢稻宋听唯输滑站另卫字鼓刚写刘微略范供阿块某功套友限项余倒卷创律雨让骨远帮初皮播优占死毒圈伟季训控激找叫云互跟裂粮粒母练塞钢顶策双留误础吸阻故寸盾晚丝女散焊功株亲院冷彻弹错散商视艺灭版烈零室轻血倍缺厘泵察绝富城冲喷壤简否柱李望盘磁雄似困巩益洲脱投送奴侧润盖挥距触星松送获兴独官混纪依未突架宽冬章湿偏纹吃执阀矿寨责熟稳夺硬价努翻奇甲预职评读背协损棉侵灰虽矛厚罗泥辟告卵箱掌氧恩爱停曾溶营终纲孟钱待尽俄缩沙退陈讨奋械载胞幼哪剥迫旋征槽倒握担仍呀鲜吧卡粗介钻逐弱脚怕盐末阴丰雾冠丙街莱贝辐肠付吉渗瑞惊顿挤秒悬姆烂森糖圣凹陶词迟蚕亿矩康遵牧遭幅园腔订香肉弟屋敏恢忘编印蜂急拿扩伤飞露核缘游振操央伍域甚迅辉异序免纸夜乡久隶缸夹念兰映沟乙吗儒杀汽磷艰晶插埃燃欢铁补咱芽永瓦倾阵碳演威附牙芽永瓦斜灌欧献顺猪洋腐请透司危括脉宜笑若尾束壮暴企菜穗楚汉愈绿拖牛份染既秋遍锻玉夏疗尖殖井费州访吹荣铜沿替滚客召旱悟刺脑措贯藏敢令隙炉壳硫煤迎铸粘探临薄旬善福纵择礼愿伏残雷延烟句纯渐耕跑泽慢栽鲁赤繁境潮横掉锥希池败船假亮谓托伙哲怀割摆贡呈劲财仪沉炼麻罪祖息车穿货销齐鼠抽画饲龙库守筑房歌寒喜哥洗蚀废纳腹乎录镜妇恶脂庄擦险赞钟摇典柄辩竹谷卖乱虚桥奥伯赶垂途额壁网截野遗静谋弄挂课镇妄盛耐援扎虑键归符庆聚绕摩忙舞遇索顾胶羊湖钉仁音迹碎伸灯避泛亡答勇频皇柳哈揭甘诺概宪浓岛袭谁洪谢炮浇斑讯懂灵蛋闭孩释乳巨徒私银伊景坦累匀霉杜乐勒隔弯绩招绍胡呼痛峰零柴簧午跳居尚丁秦稍追梁折耗碱殊岗挖氏刃剧堆赫荷胸衡勤膜篇登驻案刊秧缓凸役剪川雪链渔啦脸户洛孢勃盟买杨宗焦赛旗滤硅炭股坐蒸凝竟陷枪黎救冒暗洞犯筒您宋弧爆谬涂味津臂障褐陆啊健尊豆拔莫抵桑坡缝警挑污冰柬嘴啥饭塑寄赵喊垫丹渡耳刨虎笔稀昆浪萨茶滴浅拥穴覆伦娘吨浸袖珠雌妈紫戏塔锤震岁貌洁剖牢锋疑霸闪埔猛诉刷狠忽灾闹乔唐漏闻沈熔氯荒茎男凡抢像浆旁玻亦忠唱蒙予纷捕锁尤乘乌智淡允叛畜俘摸锈扫毕璃宝芯爷鉴秘净蒋钙肩腾枯抛轨堂拌爸循诱祝励肯酒绳穷塘燥泡袋朗喂铝软渠颗惯贸粪综墙趋彼届墨碍启逆卸航衣孙龄岭骗休借".$addChars;
  72. break;
  73. default :
  74. // 默认去掉了容易混淆的字符oOLl和数字01,要添加请使用addChars参数
  75. $chars='ABCDEFGHIJKMNPQRSTUVWXYZabcdefghijkmnpqrstuvwxyz23456789'.$addChars;
  76. break;
  77. }
  78. if($len>10 ) {//位数过长重复字符串一定次数
  79. $chars= $type==1? str_repeat($chars,$len) : str_repeat($chars,5);
  80. }
  81. if($type!=4) {
  82. $chars = str_shuffle($chars);
  83. $str = substr($chars,0,$len);
  84. }else{
  85. // 中文随机字
  86. for($i=0;$i<$len;$i++){
  87. $str.= msubstr($chars, floor(mt_rand(0,mb_strlen($chars,'utf-8')-1)),1);
  88. }
  89. }
  90. return $str;
  91. }
  92. /**
  93. * 获取登录验证码 默认为4位数字
  94. * @param string $fmode 文件名
  95. * @return string
  96. */
  97. function build_verify ($length=4,$mode=1) {
  98. return rand_string($length,$mode);
  99. }
  100. /**
  101. * 字节格式化 把字节数格式为 B K M G T 描述的大小
  102. * @return string
  103. */
  104. function byte_format($size, $dec=2) {
  105. $a = array("B", "KB", "MB", "GB", "TB", "PB");
  106. $pos = 0;
  107. while ($size >= 1024) {
  108. $size /= 1024;
  109. $pos++;
  110. }
  111. return round($size,$dec)." ".$a[$pos];
  112. }
  113. /**
  114. * 检查字符串是否是UTF8编码
  115. * @param string $string 字符串
  116. * @return Boolean
  117. */
  118. function is_utf8($string) {
  119. return preg_match('%^(?:
  120. [\x09\x0A\x0D\x20-\x7E] # ASCII
  121. | [\xC2-\xDF][\x80-\xBF] # non-overlong 2-byte
  122. | \xE0[\xA0-\xBF][\x80-\xBF] # excluding overlongs
  123. | [\xE1-\xEC\xEE\xEF][\x80-\xBF]{2} # straight 3-byte
  124. | \xED[\x80-\x9F][\x80-\xBF] # excluding surrogates
  125. | \xF0[\x90-\xBF][\x80-\xBF]{2} # planes 1-3
  126. | [\xF1-\xF3][\x80-\xBF]{3} # planes 4-15
  127. | \xF4[\x80-\x8F][\x80-\xBF]{2} # plane 16
  128. )*$%xs', $string);
  129. }
  130. /**
  131. * 代码加亮
  132. * @param String $str 要高亮显示的字符串 或者 文件名
  133. * @param Boolean $show 是否输出
  134. * @return String
  135. */
  136. function highlight_code($str,$show=false) {
  137. if(file_exists($str)) {
  138. $str = file_get_contents($str);
  139. }
  140. $str = stripslashes(trim($str));
  141. // The highlight string function encodes and highlights
  142. // brackets so we need them to start raw
  143. $str = str_replace(array('&lt;', '&gt;'), array('<', '>'), $str);
  144. // Replace any existing PHP tags to temporary markers so they don't accidentally
  145. // break the string out of PHP, and thus, thwart the highlighting.
  146. $str = str_replace(array('&lt;?php', '?&gt;', '\\'), array('phptagopen', 'phptagclose', 'backslashtmp'), $str);
  147. // The highlight_string function requires that the text be surrounded
  148. // by PHP tags. Since we don't know if A) the submitted text has PHP tags,
  149. // or B) whether the PHP tags enclose the entire string, we will add our
  150. // own PHP tags around the string along with some markers to make replacement easier later
  151. $str = '<?php //tempstart'."\n".$str.'//tempend ?>'; // <?
  152. // All the magic happens here, baby!
  153. $str = highlight_string($str, TRUE);
  154. // Prior to PHP 5, the highlight function used icky font tags
  155. // so we'll replace them with span tags.
  156. if (abs(phpversion()) < 5) {
  157. $str = str_replace(array('<font ', '</font>'), array('<span ', '</span>'), $str);
  158. $str = preg_replace('#color="(.*?)"#', 'style="color: \\1"', $str);
  159. }
  160. // Remove our artificially added PHP
  161. $str = preg_replace("#\<code\>.+?//tempstart\<br />\</span\>#is", "<code>\n", $str);
  162. $str = preg_replace("#\<code\>.+?//tempstart\<br />#is", "<code>\n", $str);
  163. $str = preg_replace("#//tempend.+#is", "</span>\n</code>", $str);
  164. // Replace our markers back to PHP tags.
  165. $str = str_replace(array('phptagopen', 'phptagclose', 'backslashtmp'), array('&lt;?php', '?&gt;', '\\'), $str); //<?
  166. $line = explode("<br />", rtrim(ltrim($str,'<code>'),'</code>'));
  167. $result = '<div class="code"><ol>';
  168. foreach($line as $key=>$val) {
  169. $result .= '<li>'.$val.'</li>';
  170. }
  171. $result .= '</ol></div>';
  172. $result = str_replace("\n", "", $result);
  173. if( $show!== false) {
  174. echo($result);
  175. }else {
  176. return $result;
  177. }
  178. }
  179. //输出安全的html
  180. function h($text, $tags = null) {
  181. $text = trim($text);
  182. //完全过滤注释
  183. $text = preg_replace('/<!--?.*-->/','',$text);
  184. //完全过滤动态代码
  185. $text = preg_replace('/<\?|\?'.'>/','',$text);
  186. //完全过滤js
  187. $text = preg_replace('/<script?.*\/script>/','',$text);
  188. $text = str_replace('[','&#091;',$text);
  189. $text = str_replace(']','&#093;',$text);
  190. $text = str_replace('|','&#124;',$text);
  191. //过滤换行符
  192. $text = preg_replace('/\r?\n/','',$text);
  193. //br
  194. $text = preg_replace('/<br(\s\/)?'.'>/i','[br]',$text);
  195. $text = preg_replace('/<p(\s\/)?'.'>/i','[br]',$text);
  196. $text = preg_replace('/(\[br\]\s*){10,}/i','[br]',$text);
  197. //过滤危险的属性,如:过滤on事件lang js
  198. while(preg_match('/(<[^><]+)( lang|on|action|background|codebase|dynsrc|lowsrc)[^><]+/i',$text,$mat)){
  199. $text=str_replace($mat[0],$mat[1],$text);
  200. }
  201. while(preg_match('/(<[^><]+)(window\.|javascript:|js:|about:|file:|document\.|vbs:|cookie)([^><]*)/i',$text,$mat)){
  202. $text=str_replace($mat[0],$mat[1].$mat[3],$text);
  203. }
  204. if(empty($tags)) {
  205. $tags = 'table|td|th|tr|i|b|u|strong|img|p|br|div|strong|em|ul|ol|li|dl|dd|dt|a';
  206. }
  207. //允许的HTML标签
  208. $text = preg_replace('/<('.$tags.')( [^><\[\]]*)>/i','[\1\2]',$text);
  209. $text = preg_replace('/<\/('.$tags.')>/Ui','[/\1]',$text);
  210. //过滤多余html
  211. $text = preg_replace('/<\/?(html|head|meta|link|base|basefont|body|bgsound|title|style|script|form|iframe|frame|frameset|applet|id|ilayer|layer|name|script|style|xml)[^><]*>/i','',$text);
  212. //过滤合法的html标签
  213. while(preg_match('/<([a-z]+)[^><\[\]]*>[^><]*<\/\1>/i',$text,$mat)){
  214. $text=str_replace($mat[0],str_replace('>',']',str_replace('<','[',$mat[0])),$text);
  215. }
  216. //转换引号
  217. while(preg_match('/(\[[^\[\]]*=\s*)(\"|\')([^\2=\[\]]+)\2([^\[\]]*\])/i',$text,$mat)){
  218. $text=str_replace($mat[0],$mat[1].'|'.$mat[3].'|'.$mat[4],$text);
  219. }
  220. //过滤错误的单个引号
  221. while(preg_match('/\[[^\[\]]*(\"|\')[^\[\]]*\]/i',$text,$mat)){
  222. $text=str_replace($mat[0],str_replace($mat[1],'',$mat[0]),$text);
  223. }
  224. //转换其它所有不合法的 < >
  225. $text = str_replace('<','&lt;',$text);
  226. $text = str_replace('>','&gt;',$text);
  227. $text = str_replace('"','&quot;',$text);
  228. //反转换
  229. $text = str_replace('[','<',$text);
  230. $text = str_replace(']','>',$text);
  231. $text = str_replace('|','"',$text);
  232. //过滤多余空格
  233. $text = str_replace(' ',' ',$text);
  234. return $text;
  235. }
  236. function ubb($Text) {
  237. $Text=trim($Text);
  238. //$Text=htmlspecialchars($Text);
  239. $Text=preg_replace("/\\t/is"," ",$Text);
  240. $Text=preg_replace("/\[h1\](.+?)\[\/h1\]/is","<h1>\\1</h1>",$Text);
  241. $Text=preg_replace("/\[h2\](.+?)\[\/h2\]/is","<h2>\\1</h2>",$Text);
  242. $Text=preg_replace("/\[h3\](.+?)\[\/h3\]/is","<h3>\\1</h3>",$Text);
  243. $Text=preg_replace("/\[h4\](.+?)\[\/h4\]/is","<h4>\\1</h4>",$Text);
  244. $Text=preg_replace("/\[h5\](.+?)\[\/h5\]/is","<h5>\\1</h5>",$Text);
  245. $Text=preg_replace("/\[h6\](.+?)\[\/h6\]/is","<h6>\\1</h6>",$Text);
  246. $Text=preg_replace("/\[separator\]/is","",$Text);
  247. $Text=preg_replace("/\[center\](.+?)\[\/center\]/is","<center>\\1</center>",$Text);
  248. $Text=preg_replace("/\[url=http:\/\/([^\[]*)\](.+?)\[\/url\]/is","<a href=\"http://\\1\" target=_blank>\\2</a>",$Text);
  249. $Text=preg_replace("/\[url=([^\[]*)\](.+?)\[\/url\]/is","<a href=\"http://\\1\" target=_blank>\\2</a>",$Text);
  250. $Text=preg_replace("/\[url\]http:\/\/([^\[]*)\[\/url\]/is","<a href=\"http://\\1\" target=_blank>\\1</a>",$Text);
  251. $Text=preg_replace("/\[url\]([^\[]*)\[\/url\]/is","<a href=\"\\1\" target=_blank>\\1</a>",$Text);
  252. $Text=preg_replace("/\[img\](.+?)\[\/img\]/is","<img src=\\1>",$Text);
  253. $Text=preg_replace("/\[color=(.+?)\](.+?)\[\/color\]/is","<font color=\\1>\\2</font>",$Text);
  254. $Text=preg_replace("/\[size=(.+?)\](.+?)\[\/size\]/is","<font size=\\1>\\2</font>",$Text);
  255. $Text=preg_replace("/\[sup\](.+?)\[\/sup\]/is","<sup>\\1</sup>",$Text);
  256. $Text=preg_replace("/\[sub\](.+?)\[\/sub\]/is","<sub>\\1</sub>",$Text);
  257. $Text=preg_replace("/\[pre\](.+?)\[\/pre\]/is","<pre>\\1</pre>",$Text);
  258. $Text=preg_replace("/\[email\](.+?)\[\/email\]/is","<a href='mailto:\\1'>\\1</a>",$Text);
  259. $Text=preg_replace("/\[colorTxt\](.+?)\[\/colorTxt\]/eis","color_txt('\\1')",$Text);
  260. $Text=preg_replace("/\[emot\](.+?)\[\/emot\]/eis","emot('\\1')",$Text);
  261. $Text=preg_replace("/\[i\](.+?)\[\/i\]/is","<i>\\1</i>",$Text);
  262. $Text=preg_replace("/\[u\](.+?)\[\/u\]/is","<u>\\1</u>",$Text);
  263. $Text=preg_replace("/\[b\](.+?)\[\/b\]/is","<b>\\1</b>",$Text);
  264. $Text=preg_replace("/\[quote\](.+?)\[\/quote\]/is"," <div class='quote'><h5>引用:</h5><blockquote>\\1</blockquote></div>", $Text);
  265. $Text=preg_replace("/\[code\](.+?)\[\/code\]/eis","highlight_code('\\1')", $Text);
  266. $Text=preg_replace("/\[php\](.+?)\[\/php\]/eis","highlight_code('\\1')", $Text);
  267. $Text=preg_replace("/\[sig\](.+?)\[\/sig\]/is","<div class='sign'>\\1</div>", $Text);
  268. $Text=preg_replace("/\\n/is","<br/>",$Text);
  269. return $Text;
  270. }
  271. // 随机生成一组字符串
  272. function build_count_rand ($number,$length=4,$mode=1) {
  273. if($mode==1 && $length<strlen($number) ) {
  274. //不足以生成一定数量的不重复数字
  275. return false;
  276. }
  277. $rand = array();
  278. for($i=0; $i<$number; $i++) {
  279. $rand[] = rand_string($length,$mode);
  280. }
  281. $unqiue = array_unique($rand);
  282. if(count($unqiue)==count($rand)) {
  283. return $rand;
  284. }
  285. $count = count($rand)-count($unqiue);
  286. for($i=0; $i<$count*3; $i++) {
  287. $rand[] = rand_string($length,$mode);
  288. }
  289. $rand = array_slice(array_unique ($rand),0,$number);
  290. return $rand;
  291. }
  292. function remove_xss($val) {
  293. // remove all non-printable characters. CR(0a) and LF(0b) and TAB(9) are allowed
  294. // this prevents some character re-spacing such as <java\0script>
  295. // note that you have to handle splits with \n, \r, and \t later since they *are* allowed in some inputs
  296. $val = preg_replace('/([\x00-\x08,\x0b-\x0c,\x0e-\x19])/', '', $val);
  297. // straight replacements, the user should never need these since they're normal characters
  298. // this prevents like <IMG SRC=@avascript:alert('XSS')>
  299. $search = 'abcdefghijklmnopqrstuvwxyz';
  300. $search .= 'ABCDEFGHIJKLMNOPQRSTUVWXYZ';
  301. $search .= '1234567890!@#$%^&*()';
  302. $search .= '~`";:?+/={}[]-_|\'\\';
  303. for ($i = 0; $i < strlen($search); $i++) {
  304. // ;? matches the ;, which is optional
  305. // 0{0,7} matches any padded zeros, which are optional and go up to 8 chars
  306. // @ @ search for the hex values
  307. $val = preg_replace('/(&#[xX]0{0,8}'.dechex(ord($search[$i])).';?)/i', $search[$i], $val); // with a ;
  308. // @ @ 0{0,7} matches '0' zero to seven times
  309. $val = preg_replace('/(&#0{0,8}'.ord($search[$i]).';?)/', $search[$i], $val); // with a ;
  310. }
  311. // now the only remaining whitespace attacks are \t, \n, and \r
  312. $ra1 = array('javascript', 'vbscript', 'expression', 'applet', 'meta', 'xml', 'blink', 'link', 'style', 'script', 'embed', 'object', 'iframe', 'frame', 'frameset', 'ilayer', 'layer', 'bgsound', 'title', 'base');
  313. $ra2 = array('onabort', 'onactivate', 'onafterprint', 'onafterupdate', 'onbeforeactivate', 'onbeforecopy', 'onbeforecut', 'onbeforedeactivate', 'onbeforeeditfocus', 'onbeforepaste', 'onbeforeprint', 'onbeforeunload', 'onbeforeupdate', 'onblur', 'onbounce', 'oncellchange', 'onchange', 'onclick', 'oncontextmenu', 'oncontrolselect', 'oncopy', 'oncut', 'ondataavailable', 'ondatasetchanged', 'ondatasetcomplete', 'ondblclick', 'ondeactivate', 'ondrag', 'ondragend', 'ondragenter', 'ondragleave', 'ondragover', 'ondragstart', 'ondrop', 'onerror', 'onerrorupdate', 'onfilterchange', 'onfinish', 'onfocus', 'onfocusin', 'onfocusout', 'onhelp', 'onkeydown', 'onkeypress', 'onkeyup', 'onlayoutcomplete', 'onload', 'onlosecapture', 'onmousedown', 'onmouseenter', 'onmouseleave', 'onmousemove', 'onmouseout', 'onmouseover', 'onmouseup', 'onmousewheel', 'onmove', 'onmoveend', 'onmovestart', 'onpaste', 'onpropertychange', 'onreadystatechange', 'onreset', 'onresize', 'onresizeend', 'onresizestart', 'onrowenter', 'onrowexit', 'onrowsdelete', 'onrowsinserted', 'onscroll', 'onselect', 'onselectionchange', 'onselectstart', 'onstart', 'onstop', 'onsubmit', 'onunload');
  314. $ra = array_merge($ra1, $ra2);
  315. $found = true; // keep replacing as long as the previous round replaced something
  316. while ($found == true) {
  317. $val_before = $val;
  318. for ($i = 0; $i < sizeof($ra); $i++) {
  319. $pattern = '/';
  320. for ($j = 0; $j < strlen($ra[$i]); $j++) {
  321. if ($j > 0) {
  322. $pattern .= '(';
  323. $pattern .= '(&#[xX]0{0,8}([9ab]);)';
  324. $pattern .= '|';
  325. $pattern .= '|(&#0{0,8}([9|10|13]);)';
  326. $pattern .= ')*';
  327. }
  328. $pattern .= $ra[$i][$j];
  329. }
  330. $pattern .= '/i';
  331. $replacement = substr($ra[$i], 0, 2).'<x>'.substr($ra[$i], 2); // add in <> to nerf the tag
  332. $val = preg_replace($pattern, $replacement, $val); // filter out the hex tags
  333. if ($val_before == $val) {
  334. // no replacements were made, so exit the loop
  335. $found = false;
  336. }
  337. }
  338. }
  339. return $val;
  340. }
  341. /**
  342. * 把返回的数据集转换成Tree
  343. * @access public
  344. * @param array $list 要转换的数据集
  345. * @param string $pid parent标记字段
  346. * @param string $level level标记字段
  347. * @return array
  348. */
  349. function list_to_tree($list, $pk='id',$pid = 'pid',$child = '_child',$root=0) {
  350. // 创建Tree
  351. $tree = array();
  352. if(is_array($list)) {
  353. // 创建基于主键的数组引用
  354. $refer = array();
  355. foreach ($list as $key => $data) {
  356. $refer[$data[$pk]] =& $list[$key];
  357. }
  358. foreach ($list as $key => $data) {
  359. // 判断是否存在parent
  360. $parentId = $data[$pid];
  361. if ($root == $parentId) {
  362. $tree[] =& $list[$key];
  363. }else{
  364. if (isset($refer[$parentId])) {
  365. $parent =& $refer[$parentId];
  366. $parent[$child][] =& $list[$key];
  367. }
  368. }
  369. }
  370. }
  371. return $tree;
  372. }
  373. /**
  374. * 对查询结果集进行排序
  375. * @access public
  376. * @param array $list 查询结果
  377. * @param string $field 排序的字段名
  378. * @param array $sortby 排序类型
  379. * asc正向排序 desc逆向排序 nat自然排序
  380. * @return array
  381. */
  382. function list_sort_by($list,$field, $sortby='asc') {
  383. if(is_array($list)){
  384. $refer = $resultSet = array();
  385. foreach ($list as $i => $data)
  386. $refer[$i] = &$data[$field];
  387. switch ($sortby) {
  388. case 'asc': // 正向排序
  389. asort($refer);
  390. break;
  391. case 'desc':// 逆向排序
  392. arsort($refer);
  393. break;
  394. case 'nat': // 自然排序
  395. natcasesort($refer);
  396. break;
  397. }
  398. foreach ( $refer as $key=> $val)
  399. $resultSet[] = &$list[$key];
  400. return $resultSet;
  401. }
  402. return false;
  403. }
  404. /**
  405. * 在数据列表中搜索
  406. * @access public
  407. * @param array $list 数据列表
  408. * @param mixed $condition 查询条件
  409. * 支持 array('name'=>$value) 或者 name=$value
  410. * @return array
  411. */
  412. function list_search($list,$condition) {
  413. if(is_string($condition))
  414. parse_str($condition,$condition);
  415. // 返回的结果集合
  416. $resultSet = array();
  417. foreach ($list as $key=>$data){
  418. $find = false;
  419. foreach ($condition as $field=>$value){
  420. if(isset($data[$field])) {
  421. if(0 === strpos($value,'/')) {
  422. $find = preg_match($value,$data[$field]);
  423. }elseif($data[$field]==$value){
  424. $find = true;
  425. }
  426. }
  427. }
  428. if($find)
  429. $resultSet[] = &$list[$key];
  430. }
  431. return $resultSet;
  432. }
  433. // 自动转换字符集 支持数组转换
  434. function auto_charset($fContents, $from='gbk', $to='utf-8') {
  435. $from = strtoupper($from) == 'UTF8' ? 'utf-8' : $from;
  436. $to = strtoupper($to) == 'UTF8' ? 'utf-8' : $to;
  437. if (strtoupper($from) === strtoupper($to) || empty($fContents) || (is_scalar($fContents) && !is_string($fContents))) {
  438. //如果编码相同或者非字符串标量则不转换
  439. return $fContents;
  440. }
  441. if (is_string($fContents)) {
  442. if (function_exists('mb_convert_encoding')) {
  443. return mb_convert_encoding($fContents, $to, $from);
  444. } elseif (function_exists('iconv')) {
  445. return iconv($from, $to, $fContents);
  446. } else {
  447. return $fContents;
  448. }
  449. } elseif (is_array($fContents)) {
  450. foreach ($fContents as $key => $val) {
  451. $_key = auto_charset($key, $from, $to);
  452. $fContents[$_key] = auto_charset($val, $from, $to);
  453. if ($key != $_key)
  454. unset($fContents[$key]);
  455. }
  456. return $fContents;
  457. }
  458. else {
  459. return $fContents;
  460. }
  461. }