Software: nginx/1.23.4. PHP/5.6.40-65+ubuntu20.04.1+deb.sury.org+1 uname -a: Linux foro-restaurado-2 5.15.0-1040-oracle #46-Ubuntu SMP Fri Jul 14 21:47:21 UTC 2023 uid=33(www-data) gid=33(www-data) groups=33(www-data) Safe-mode: OFF (not secure) /usr/share/nginx/html/phpbb3/docs/ drwxrwxr-x |
Viewing file: Select action/file-type: These are the phpBB Coding Guidelines for Olympus, all attempts should be made to follow them as closely as possible. Coding Guidelines1. Defaults1.i. Editor SettingsTabs vs Spaces:In order to make this as simple as possible, we will be using tabs, not spaces. We enforce 4 (four) spaces for one tab - therefore you need to set your tab width within your editor to 4 spaces. Make sure that when you save the file, it's saving tabs and not spaces. This way, we can each have the code be displayed the way we like it, without breaking the layout of the actual files. Tabs in front of lines are no problem, but having them within the text can be a problem if you do not set it to the amount of spaces every one of us uses. Here is a short example of how it should look like: {TAB}$mode{TAB}{TAB}= request_var('mode', ''); {TAB}$search_id{TAB}= request_var('search_id', ''); If entered with tabs (replace the {TAB}) both equal signs need to be on the same column. Linefeeds:Ensure that your editor is saving files in the UNIX (LF) line ending format. This means that lines are terminated with a newline, not with Windows Line endings (CR/LF combo) as they are on Win32 or Classic Mac (CR) Line endings. Any decent editor should be able to do this, but it might not always be the default setting. Know your editor. If you want advice for an editor for your Operating System, just ask one of the developers. Some of them do their editing on Win32. 1.ii. File HeaderStandard header for new files:This template of the header must be included at the start of all phpBB files: /** * * @package {PACKAGENAME} * @version $Id: $ * @copyright (c) 2007 phpBB Group * @license http://opensource.org/licenses/gpl-license.php GNU Public License * */ Please see the File Locations section for the correct package name. Files containing inline code:For those files you have to put an empty comment directly after the header to prevent the documentor assigning the header to the first code element found. /** * {HEADER} */ /** */ {CODE} Files containing only functions:Do not forget to comment the functions (especially the first function following the header). Each function should have at least a comment of what this function does. For more complex functions it is recommended to document the parameters too. Files containing only classes:Do not forget to comment the class. Classes need a separate @package definition, it is the same as the header package name. Apart from this special case the above statement for files containing only functions needs to be applied to classes and it's methods too. Code following the header but only functions/classes file:If this case is true, the best method to avoid documentation confusions is adding an ignore command, for example: /** * {HEADER} */ /** * @ignore */ Small code snipped, mostly one or two defines or an if statement /** * {DOCUMENTATION} */ class ... 1.iii. File LocationsFunctions used by more than one page should be placed in functions.php, functions specific to one page should be placed on that page (at the bottom) or within the relevant sections functions file. Some files in The following packages are defined, and related new features/functions should be placed within the mentioned files/locations, as well as specifying the correct package name. The package names are bold within this list:
1.iv. Special ConstantsThere are some special constants application developers are able to utilize to bend some of phpBB's internal functionality to suit their needs. PHPBB_MSG_HANDLER (overwrite message handler) PHPBB_DB_NEW_LINK (overwrite new_link parameter for sql_connect) PHPBB_ROOT_PATH (overwrite $phpbb_root_path) PHPBB_ADMIN_PATH (overwrite $phpbb_admin_path) PHPBB_USE_BOARD_URL_PATH (use generate_board_url() for image paths instead of $phpbb_root_path) PHPBB_DISABLE_ACP_EDITOR (disable ACP style editor for templates) PHPBB_DISABLE_CONFIG_CHECK (disable ACP config.php writeable check) PHPBB_ACM_MEMCACHE_PORT (overwrite memcached port, default is 11211) PHPBB_ACM_MEMCACHE_COMPRESS (overwrite memcached compress setting, default is disabled) PHPBB_ACM_MEMCACHE_HOST (overwrite memcached host name, default is localhost) PHPBB_QA (Set board to QA-Mode, which means the updater also checks for RC-releases) PHPBB_USE_BOARD_URL_PATHIf the
Path locations for the following template variables are affected by this too:
2. Code Layout/GuidelinesPlease note that these Guidelines applies to all php, html, javascript and css files. 2.i. Variable/Function NamingWe will not be using any form of hungarian notation in our naming conventions. Many of us believe that hungarian naming is one of the primary code obfuscation techniques currently in use. Variable Names:Variable names should be in all lowercase, with words separated by an underscore, example:
Names should be descriptive, but concise. We don't want huge sentences as our variable names, but typing an extra couple of characters is always better than wondering what exactly a certain variable is for. Loop Indices:The only situation where a one-character variable name is allowed is when it's the index for some looping construct. In this case, the index of the outer loop should always be $i. If there's a loop inside that loop, its index should be $j, followed by $k, and so on. If the loop is being indexed by some already-existing variable with a meaningful name, this guideline does not apply, example: for ($i = 0; $i < $outer_size; $i++) { for ($j = 0; $j < $inner_size; $j++) { foo($i, $j); } } Function Names:Functions should also be named descriptively. We're not programming in C here, we don't want to write functions called things like "stristr()". Again, all lower-case names with words separated by a single underscore character. Function names should preferably have a verb in them somewhere. Good function names are Function Arguments:Arguments are subject to the same guidelines as variable names. We don't want a bunch of functions like: Summary:The basic philosophy here is to not hurt code clarity for the sake of laziness. This has to be balanced by a little bit of common sense, though; Special Namings:For all emoticons use the term 2.ii. Code LayoutAlways include the braces:This is another case of being too lazy to type 2 extra characters causing problems with code clarity. Even if the body of some construct is only one line long, do not drop the braces. Just don't, examples: // These are all wrong. if (condition) do_stuff(); if (condition) do_stuff(); while (condition) do_stuff(); for ($i = 0; $i < size; $i++) do_stuff($i); // These are all right. if (condition) { do_stuff(); } while (condition) { do_stuff(); } for ($i = 0; $i < size; $i++) { do_stuff(); } Where to put the braces:This one is a bit of a holy war, but we're going to use a style that can be summed up in one sentence: Braces always go on their own line. The closing brace should also always be at the same column as the corresponding opening brace, examples: if (condition) { while (condition2) { ... } } else { ... } for ($i = 0; $i < $size; $i++) { ... } while (condition) { ... } function do_stuff() { ... } Use spaces between tokens:This is another simple, easy step that helps keep code readable without much effort. Whenever you write an assignment, expression, etc.. Always leave one space between the tokens. Basically, write code as if it was English. Put spaces between variable names and operators. Don't put spaces just after an opening bracket or before a closing bracket. Don't put spaces just before a comma or a semicolon. This is best shown with a few examples, examples: // Each pair shows the wrong way followed by the right way. $i=0; $i = 0; if($i<7) ... if ($i < 7) ... if ( ($i < 7)&&($j > 8) ) ... if ($i < 7 && $j > 8) ... do_stuff( $i, 'foo', $b ); do_stuff($i, 'foo', $b); for($i=0; $i<$size; $i++) ... for ($i = 0; $i < $size; $i++) ... $i=($j < $size)?0:1; $i = ($j < $size) ? 0 : 1; Operator precedence:Do you know the exact precedence of all the operators in PHP? Neither do I. Don't guess. Always make it obvious by using brackets to force the precedence of an equation so you know what it does. Remember to not over-use this, as it may harden the readability. Basically, do not enclose single expressions. Examples: // what's the result? who knows. $bool = ($i < 7 && $j > 8 || $k == 4); // now you can be certain what I'm doing here. $bool = (($i < 7) && (($j < 8) || ($k == 4))); // But this one is even better, because it is easier on the eye but the intention is preserved $bool = ($i < 7 && ($j < 8 || $k == 4)); Quoting strings:There are two different ways to quote strings in PHP - either with single quotes or with double quotes. The main difference is that the parser does variable interpolation in double-quoted strings, but not in single quoted strings. Because of this, you should always use single quotes unless you specifically need variable interpolation to be done on that string. This way, we can save the parser the trouble of parsing a bunch of strings where no interpolation needs to be done. Also, if you are using a string variable as part of a function call, you do not need to enclose that variable in quotes. Again, this will just make unnecessary work for the parser. Note, however, that nearly all of the escape sequences that exist for double-quoted strings will not work with single-quoted strings. Be careful, and feel free to break this guideline if it's making your code easier to read, examples: // wrong $str = "This is a really long string with no variables for the parser to find."; do_stuff("$str"); // right $str = 'This is a really long string with no variables for the parser to find.'; do_stuff($str); // Sometimes single quotes are just not right $post_url = $phpbb_root_path . 'posting.' . $phpEx . '?mode=' . $mode . '&start=' . $start; // Double quotes are sometimes needed to not overcroud the line with concentinations $post_url = "{$phpbb_root_path}posting.$phpEx?mode=$mode&start=$start"; In SQL Statements mixing single and double quotes is partly allowed (following the guidelines listed here about SQL Formatting), else it should be tryed to only use one method - mostly single quotes. Associative array keys:In PHP, it's legal to use a literal string as a key to an associative array without quoting that string. We don't want to do this -- the string should always be quoted to avoid confusion. Note that this is only when we're using a literal, not when we're using a variable, examples: // wrong $foo = $assoc_array[blah]; // right $foo = $assoc_array['blah']; // wrong $foo = $assoc_array["$var"]; // right $foo = $assoc_array[$var]; Comments:Each complex function should be preceded by a comment that tells a programmer everything they need to know to use that function. The meaning of every parameter, the expected input, and the output are required as a minimal comment. The function's behaviour in error conditions (and what those error conditions are) should also be present - but mostly included within the comment about the output. Magic numbers:Don't use them. Use named constants for any literal value other than obvious special cases. Basically, it's ok to check if an array has 0 elements by using the literal 0. It's not ok to assign some special meaning to a number and then use it everywhere as a literal. This hurts readability AND maintainability. The constants Shortcut operators:The only shortcut operators that cause readability problems are the shortcut increment // wrong $array[++$i] = $j; $array[$i++] = $k; // right $i++; $array[$i] = $j; $array[$i] = $k; $i++; Inline conditionals:Inline conditionals should only be used to do very simple things. Preferably, they will only be used to do assignments, and not for function calls or anything complex at all. They can be harmful to readability if used incorrectly, so don't fall in love with saving typing by using them, examples: // Bad place to use them ($i < $size && $j > $size) ? do_stuff($foo) : do_stuff($bar); // OK place to use them $min = ($i < $j) ? $i : $j; Don't use uninitialized variables.For phpBB3, we intend to use a higher level of run-time error reporting. This will mean that the use of an uninitialized variable will be reported as a warning. These warnings can be avoided by using the built-in isset() function to check whether a variable has been set - but preferably the variable is always existing. For checking if an array has a key set this can come in handy though, examples: // Wrong if ($forum) ... // Right if (isset($forum)) ... // Also possible if (isset($forum) && $forum == 5) The Switch statements:Switch/case code blocks can get a bit long sometimes. To have some level of notice and being in-line with the opening/closing brace requirement (where they are on the same line for better readability), this also applies to switch/case code blocks and the breaks. An example: // Wrong switch ($mode) { case 'mode1': // I am doing something here break; case 'mode2': // I am doing something completely different here break; } // Good switch ($mode) { case 'mode1': // I am doing something here break; case 'mode2': // I am doing something completely different here break; default: // Always assume that a case was not caught break; } // Also good, if you have more code between the case and the break switch ($mode) { case 'mode1': // I am doing something here break; case 'mode2': // I am doing something completely different here break; default: // Always assume that a case was not caught break; } Even if the break for the default case is not needed, it is sometimes better to include it just for readability and completeness. If no break is intended, please add a comment instead. An example: // Example with no break switch ($mode) { case 'mode1': // I am doing something here // no break here case 'mode2': // I am doing something completely different here break; default: // Always assume that a case was not caught break; } 2.iii. SQL/SQL LayoutCommon SQL Guidelines:All SQL should be cross-DB compatible, if DB specific SQL is used alternatives must be provided which work on all supported DB's (MySQL3/4/5, MSSQL (7.0 and 2000), PostgreSQL (7.0+), Firebird, SQLite, Oracle8, ODBC (generalised if possible)). All SQL commands should utilise the DataBase Abstraction Layer (DBAL) SQL code layout:SQL Statements are often unreadable without some formatting, since they tend to be big at times. Though the formatting of sql statements adds a lot to the readability of code. SQL statements should be formatted in the following way, basically writing keywords: $sql = 'SELECT * <-one tab->FROM ' . SOME_TABLE . ' <-one tab->WHERE a = 1 <-two tabs->AND (b = 2 <-three tabs->OR b = 3) <-one tab->ORDER BY b'; Here the example with the tabs applied: $sql = 'SELECT * FROM ' . SOME_TABLE . ' WHERE a = 1 AND (b = 2 OR b = 3) ORDER BY b'; SQL Quotes:Double quotes where applicable (The variables in these examples are typecasted to integers before) ... examples: // These are wrong. "UPDATE " . SOME_TABLE . " SET something = something_else WHERE a = $b"; 'UPDATE ' . SOME_TABLE . ' SET something = ' . $user_id . ' WHERE a = ' . $something; // These are right. 'UPDATE ' . SOME_TABLE . " SET something = something_else WHERE a = $b"; 'UPDATE ' . SOME_TABLE . " SET something = $user_id WHERE a = $something"; In other words use single quotes where no variable substitution is required or where the variable involved shouldn't appear within double quotes. Otherwise use double quotes. Avoid DB specific SQL:The "not equals operator", as defined by the SQL:2003 standard, is "<>" // This is wrong. $sql = 'SELECT * FROM ' . SOME_TABLE . ' WHERE a != 2'; // This is right. $sql = 'SELECT * FROM ' . SOME_TABLE . ' WHERE a <> 2'; Common DBAL methods:sql_escape():Always use $sql = 'SELECT * FROM ' . SOME_TABLE . " WHERE username = '" . $db->sql_escape($username) . "'"; sql_query_limit():We do not add limit statements to the sql query, but instead use Note: Since Oracle handles limits differently and because of how we implemented this handling you need to take special care if you use Make sure when using something like "SELECT x.*, y.jars" that there is not a column named jars in x; make sure that there is no overlap between an implicit column and the explicit columns. sql_build_array():If you need to UPDATE or INSERT data, make use of the $sql_ary = array( 'somedata' => $my_string, 'otherdata' => $an_int, 'moredata' => $another_int ); $db->sql_query('INSERT INTO ' . SOME_TABLE . ' ' . $db->sql_build_array('INSERT', $sql_ary)); To complete the example, this is how an update statement would look like: $sql_ary = array( 'somedata' => $my_string, 'otherdata' => $an_int, 'moredata' => $another_int ); $sql = 'UPDATE ' . SOME_TABLE . ' SET ' . $db->sql_build_array('UPDATE', $sql_ary) . ' WHERE user_id = ' . (int) $user_id; $db->sql_query($sql); The sql_multi_insert():If you want to insert multiple statements at once, please use the separate $sql_ary = array(); $sql_ary[] = array( 'somedata' => $my_string_1, 'otherdata' => $an_int_1, 'moredata' => $another_int_1, ); $sql_ary[] = array( 'somedata' => $my_string_2, 'otherdata' => $an_int_2, 'moredata' => $another_int_2, ); $db->sql_multi_insert(SOME_TABLE, $sql_ary); sql_in_set():The $sql = 'SELECT * FROM ' . FORUMS_TABLE . ' WHERE ' . $db->sql_in_set('forum_id', $forum_ids); $db->sql_query($sql); Based on the number of values in $forum_ids, the query can look differently. // SQL Statement if $forum_ids = array(1, 2, 3); SELECT FROM phpbb_forums WHERE forum_id IN (1, 2, 3) // SQL Statement if $forum_ids = array(1) or $forum_ids = 1 SELECT FROM phpbb_forums WHERE forum_id = 1 Of course the same is possible for doing a negative match against a number of values: $sql = 'SELECT * FROM ' . FORUMS_TABLE . ' WHERE ' . $db->sql_in_set('forum_id', $forum_ids, true); $db->sql_query($sql); Based on the number of values in $forum_ids, the query can look differently here too. // SQL Statement if $forum_ids = array(1, 2, 3); SELECT FROM phpbb_forums WHERE forum_id NOT IN (1, 2, 3) // SQL Statement if $forum_ids = array(1) or $forum_ids = 1 SELECT FROM phpbb_forums WHERE forum_id <> 1 If the given array is empty, an error will be produced. sql_build_query():The $sql_array = array( 'SELECT' => 'f.*, ft.mark_time', 'FROM' => array( FORUMS_WATCH_TABLE => 'fw', FORUMS_TABLE => 'f' ), 'LEFT_JOIN' => array( array( 'FROM' => array(FORUMS_TRACK_TABLE => 'ft'), 'ON' => 'ft.user_id = ' . $user->data['user_id'] . ' AND ft.forum_id = f.forum_id' ) ), 'WHERE' => 'fw.user_id = ' . $user->data['user_id'] . ' AND f.forum_id = fw.forum_id', 'ORDER_BY' => 'left_id' ); $sql = $db->sql_build_query('SELECT', $sql_array); The possible first parameter for sql_build_query() is SELECT or SELECT_DISTINCT. As you can see, the logic is pretty self-explaining. For the LEFT_JOIN key, just add another array if you want to join on to tables for example. The added benefit of using this construct is that you are able to easily build the query statement based on conditions - for example the above LEFT_JOIN is only necessary if server side topic tracking is enabled; a slight adjustement would be: $sql_array = array( 'SELECT' => 'f.*', 'FROM' => array( FORUMS_WATCH_TABLE => 'fw', FORUMS_TABLE => 'f' ), 'WHERE' => 'fw.user_id = ' . $user->data['user_id'] . ' AND f.forum_id = fw.forum_id', 'ORDER_BY' => 'left_id' ); if ($config['load_db_lastread']) { $sql_array['LEFT_JOIN'] = array( array( 'FROM' => array(FORUMS_TRACK_TABLE => 'ft'), 'ON' => 'ft.user_id = ' . $user->data['user_id'] . ' AND ft.forum_id = f.forum_id' ) ); $sql_array['SELECT'] .= ', ft.mark_time '; } else { // Here we read the cookie data } $sql = $db->sql_build_query('SELECT', $sql_array); 2.iv. OptimizationsOperations in loop definition:Always try to optimize your loops if operations are going on at the comparing part, since this part is executed every time the loop is parsed through. For assignments a descriptive name should be chosen. Example: // On every iteration the sizeof function is called for ($i = 0; $i < sizeof($post_data); $i++) { do_something(); } // You are able to assign the (not changing) result within the loop itself for ($i = 0, $size = sizeof($post_data); $i < $size; $i++) { do_something(); } Use of in_array():Try to avoid using in_array() on huge arrays, and try to not place them into loops if the array to check consist of more than 20 entries. in_array() can be very time consuming and uses a lot of cpu processing time. For little checks it is not noticable, but if checked against a huge array within a loop those checks alone can be a bunch of seconds. If you need this functionality, try using isset() on the arrays keys instead, actually shifting the values into keys and vice versa. A call to 2.v. General GuidelinesGeneral things:Never trust user input (this also applies to server variables as well as cookies). Try to sanitize values returned from a function. Try to sanitize given function variables within your function. The auth class should be used for all authorisation checking. No attempt should be made to remove any copyright information (either contained within the source or displayed interactively when the source is run/compiled), neither should the copyright information be altered in any way (it may be added to). Variables:Make use of the The request_var function determines the type to set from the second parameter (which determines the default value too). If you need to get a scalar variable type, you need to tell this the request_var function explicitly. Examples: // Old method, do not use it $start = (isset($HTTP_GET_VARS['start'])) ? intval($HTTP_GET_VARS['start']) : intval($HTTP_POST_VARS['start']); $submit = (isset($HTTP_POST_VARS['submit'])) ? true : false; // Use request var and define a default variable (use the correct type) $start = request_var('start', 0); $submit = (isset($_POST['submit'])) ? true : false; // $start is an int, the following use of request_var therefore is not allowed $start = request_var('start', '0'); // Getting an array, keys are integers, value defaults to 0 $mark_array = request_var('mark', array(0)); // Getting an array, keys are strings, value defaults to 0 $action_ary = request_var('action', array('' => 0)); Login checks/redirection:To show a forum login box use The Sensitive Operations:For sensitive operations always let the user confirm the action. For the confirmation screens, make use of the Altering Operations:For operations altering the state of the database, for instance posting, always verify the form token, unless you are already using add_form_key('my_form'); if ($submit) { if (!check_form_key('my_form')) { trigger_error('FORM_INVALID'); } } The string passed to Sessions:Sessions should be initiated on each page, as near the top as possible using the following code: $user->session_begin(); $auth->acl($user->data); $user->setup(); The Errors and messages:All messages/errors should be outputed by calling trigger_error('NO_FORUM'); trigger_error($user->lang['NO_FORUM']); trigger_error('NO_MODE', E_USER_ERROR); Url formattingAll urls pointing to internal files need to be prepended by the The append_sid("{$phpbb_root_path}memberlist.$phpEx", 'mode=group&g=' . $row['group_id']) General function usage:Some of these functions are only chosen over others because of personal preference and having no other benefit than to be consistant over the code.
ExitingYour page should either call 3. Styling3.i. Style Config FilesStyle cfg files are simple name-value lists with the information necessary for installing a style. Similar cfg files exist for templates, themes and imagesets. These follow the same principle and will not be introduced individually. Styles can use installed components by using the required_theme/required_template/required_imageset entries. The important part of the style configuration file is assigning an unique name. # General Information about this style name = prosilver_duplicate copyright = © phpBB Group, 2007 version = 3.0.3 required_template = prosilver required_theme = prosilver required_imageset = prosilver 3.2. General Styling RulesTemplates should be produced in a consistent manner. Where appropriate they should be based off an existing copy, e.g. index, viewforum or viewtopic (the combination of which implement a range of conditional and variable forms). Please also note that the intendation and coding guidelines also apply to templates where possible. The outer table class When writing Each block level element should be indented by one tab, same for tabular elements, e.g. Don't use <td><span class="gensmall">TEST</span></td> can just as well become: <td class="gensmall">TEST</td> Try to match text class types with existing useage, e.g. don't use the nav class where viewtopic uses gensmall for example. Row colours/classes are now defined by the template, use an Remember block level ordering is important ... while not all pages validate as XHTML 1.0 Strict compliant it is something we're trying to work too. Use a standard cellpadding of 2 and cellspacing of 0 on outer tables. Inner tables can vary from 0 to 3 or even 4 depending on the need. Use div container/css for styling and table for data representation. The separate catXXXX and thXXX classes are gone. When defining a header cell just use Try to retain consistency of basic layout and class useage, i.e. _EXPLAIN text should generally be placed below the title it explains, e.g. Try to keep template conditional and other statements tabbed in line with the block to which they refer. this is correct <!-- BEGIN test --> <tr> <td>{test.TEXT}</td> </tr> <!-- END test --> this is also correct: <!-- BEGIN test --> <tr> <td>{test.TEXT}</td> </tr> <!-- END test --> it gives immediate feedback on exactly what is looping - decide which way to use based on the readability. 4. Templating4.i. General TemplatingFile namingFirstly templates now take the suffix ".html" rather than ".tpl". This was done simply to make the lifes of some people easier wrt syntax highlighting, etc. VariablesAll template variables should be named appropriately (using underscores for spaces), language entries should be prefixed with L_, system data with S_, urls with U_, javascript urls with UA_, language to be put in javascript statements with LA_, all other variables should be presented 'as is'. L_* template variables are automatically tried to be mapped to the corresponding language entry if the code does not set (and therefore overwrite) this variable specifically. For example Blocks/LoopsThe basic block level loop remains and takes the form: <!-- BEGIN loopname --> markup, {loopname.X_YYYYY}, etc. <!-- END loopname --> A bit later loops will be explained further. To not irritate you we will explain conditionals as well as other statements first. Including filesSomething that existed in 2.0.x which no longer exists in 3.0.x is the ability to assign a template to a variable. This was used (for example) to output the jumpbox. Instead (perhaps better, perhaps not but certainly more flexible) we now have INCLUDE. This takes the simple form:
<!-- INCLUDE filename -->
You will note in the 3.0 templates the major sources start with Added in 3.0.6 is the ability to include a file using a template variable to specify the file, this functionality only works for root variables (i.e. not block variables).
<!-- INCLUDE {FILE_VAR} -->
Template defined variables can also be utilised. <!-- DEFINE $SOME_VAR = 'my_file.html' --> <!-- INCLUDE {$SOME_VAR} --> PHPA contentious decision has seen the ability to include PHP within the template introduced. This is achieved by enclosing the PHP within relevant tags: <!-- PHP --> echo "hello!"; <!-- ENDPHP --> You may also include PHP from an external file using:
<!-- INCLUDEPHP somefile.php -->
it will be included and executed inline. Conditionals/Control structuresThe most significant addition to 3.0.x are conditions or control structures, "if something then do this else do that". The system deployed is very similar to Smarty. This may confuse some people at first but it offers great potential and great flexibility with a little imagination. In their most simple form these constructs take the form: <!-- IF expr --> markup <!-- ENDIF --> expr can take many forms, for example: <!-- IF loop.S_ROW_COUNT is even --> markup <!-- ENDIF --> This will output the markup if the S_ROW_COUNT variable in the current iteration of loop is an even value (i.e. the expr is TRUE). You can use various comparison methods (standard as well as equivalent textual versions noted in square brackets) including ( == [eq] != [neq, ne] <> (same as !=) !== (not equivalent in value and type) === (equivalent in value and type) > [gt] < [lt] >= [gte] <= [lte] && [and] || [or] % [mod] ! [not] + - * / , << (bitwise shift left) >> (bitwise shift right) | (bitwise or) ^ (bitwise xor) & (bitwise and) ~ (bitwise not) is (can be used to join comparison operations) Basic parenthesis can also be used to enforce good old BODMAS rules. Additionally some basic comparison types are defined: even odd div Beyond the simple use of IF you can also do a sequence of comparisons using the following: <!-- IF expr1 --> markup <!-- ELSEIF expr2 --> markup . . . <!-- ELSEIF exprN --> markup <!-- ELSE --> markup <!-- ENDIF --> Each statement will be tested in turn and the relevant output generated when a match (if a match) is found. It is not necessary to always use ELSEIF, ELSE can be used alone to match "everything else". <table> <!-- IF loop.S_ROW_COUNT is even --> <tr class="row1"> <!-- ELSE --> <tr class="row2"> <!-- ENDIF --> <td>HELLO!</td> </tr> </table> This will cause the row cell to be output using class row1 when the row count is even, and class row2 otherwise. The S_ROW_COUNT parameter gets assigned to loops by default. Another example would be the following: <table> <!-- IF loop.S_ROW_COUNT > 10 --> <tr bgcolor="#FF0000"> <!-- ELSEIF loop.S_ROW_COUNT > 5 --> <tr bgcolor="#00FF00"> <!-- ELSEIF loop.S_ROW_COUNT > 2 --> <tr bgcolor="#0000FF"> <!-- ELSE --> <tr bgcolor="#FF00FF"> <!-- ENDIF --> <td>hello!</td> </tr> </table> This will output the row cell in purple for the first two rows, blue for rows 2 to 5, green for rows 5 to 10 and red for remainder. So, you could produce a "nice" gradient effect, for example. <!-- IF S_USER_LOGGED_IN --> markup <!-- ENDIF --> This replaces the existing (fudged) method in 2.0.x using a zero length array and BEGIN/END. Extended syntax for Blocks/LoopsBack to our loops - they had been extended with the following additions. Firstly you can set the start and end points of the loop. For example: <!-- BEGIN loopname(2) --> markup <!-- END loopname --> Will start the loop on the third entry (note that indexes start at zero). Extensions of this are:
A further extension to begin is BEGINELSE: <!-- BEGIN loop --> markup <!-- BEGINELSE --> markup <!-- END loop --> This will cause the markup between Another way of checking if a loop contains values is by prefixing the loops name with a dot: <!-- IF .loop --> <!-- BEGIN loop --> markup <!-- END loop --> <!-- ELSE --> markup <!-- ENDIF --> You are even able to check the number of items within a loop by comparing it with values within the IF condition: <!-- IF .loop > 2 --> <!-- BEGIN loop --> markup <!-- END loop --> <!-- ELSE --> markup <!-- ENDIF --> Nesting loops cause the conditionals needing prefixed with all loops from the outer one to the inner most. An illustration of this: <!-- BEGIN firstloop --> {firstloop.MY_VARIABLE_FROM_FIRSTLOOP} <!-- BEGIN secondloop --> {firstloop.secondloop.MY_VARIABLE_FROM_SECONDLOOP} <!-- END secondloop --> <!-- END firstloop --> Sometimes it is necessary to break out of nested loops to be able to call another loop within the current iteration. This sounds a little bit confusing and it is not used very often. The following (rather complex) example shows this quite good - it also shows how you test for the first and last row in a loop (i will explain the example in detail further down): <!-- BEGIN l_block1 --> <!-- IF l_block1.S_SELECTED --> <strong>{l_block1.L_TITLE}</strong> <!-- IF S_PRIVMSGS --> <!-- the ! at the beginning of the loop name forces the loop to be not a nested one of l_block1 --> <!-- BEGIN !folder --> <!-- IF folder.S_FIRST_ROW --> <ul class="nav"> <!-- ENDIF --> <li><a href="{folder.U_FOLDER}">{folder.FOLDER_NAME}</a></li> <!-- IF folder.S_LAST_ROW --> </ul> <!-- ENDIF --> <!-- END !folder --> <!-- ENDIF --> <ul class="nav"> <!-- BEGIN l_block2 --> <li> <!-- IF l_block1.l_block2.S_SELECTED --> <strong>{l_block1.l_block2.L_TITLE}</strong> <!-- ELSE --> <a href="{l_block1.l_block2.U_TITLE}">{l_block1.l_block2.L_TITLE}</a> <!-- ENDIF --> </li> <!-- END l_block2 --> </ul> <!-- ELSE --> <a class="nav" href="{l_block1.U_TITLE}">{l_block1.L_TITLE}</a> <!-- ENDIF --> <!-- END l_block1 --> Let us first concentrate on this part of the example: <!-- BEGIN l_block1 --> <!-- IF l_block1.S_SELECTED --> markup <!-- ELSE --> <a class="nav" href="{l_block1.U_TITLE}">{l_block1.L_TITLE}</a> <!-- ENDIF --> <!-- END l_block1 --> Here we open the loop l_block1 and doing some things if the value S_SELECTED within the current loop iteration is true, else we write the blocks link and title. Here, you see Let's have a closer look to the markup: <!-- BEGIN l_block1 --> . . <!-- IF S_PRIVMSGS --> <!-- BEGIN !folder --> <!-- IF folder.S_FIRST_ROW --> <ul class="nav"> <!-- ENDIF --> <li><a href="{folder.U_FOLDER}">{folder.FOLDER_NAME}</a></li> <!-- IF folder.S_LAST_ROW --> </ul> <!-- ENDIF --> <!-- END !folder --> <!-- ENDIF --> . . <!-- END l_block1 --> The <!-- BEGIN l_block1 --> . . <ul class="nav"> <!-- BEGIN l_block2 --> <li> <!-- IF l_block1.l_block2.S_SELECTED --> <strong>{l_block1.l_block2.L_TITLE}</strong> <!-- ELSE --> <a href="{l_block1.l_block2.U_TITLE}">{l_block1.l_block2.L_TITLE}</a> <!-- ENDIF --> </li> <!-- END l_block2 --> </ul> . . <!-- END l_block1 --> You see the difference? The loop l_block2 is a member of the loop l_block1 but the loop folder is a main loop. Now back to our folder loop: <!-- IF folder.S_FIRST_ROW --> <ul class="nav"> <!-- ENDIF --> <li><a href="{folder.U_FOLDER}">{folder.FOLDER_NAME}</a></li> <!-- IF folder.S_LAST_ROW --> </ul> <!-- ENDIF --> You may have wondered what the comparison to S_FIRST_ROW and S_LAST_ROW is about. If you haven't guessed already - it is checking for the first iteration of the loop with <ul class="nav"> <!-- written on first iteration --> <li>first element</li> <!-- written on first iteration --> <li>second element</li> <!-- written on second iteration --> <li>third element</li> <!-- written on third iteration --> </ul> <!-- written on third iteration --> As you can see, all three elements are written down as well as the markup for the first iteration and the last one. Sometimes you want to omit writing the general markup - for example: <!-- IF folder.S_FIRST_ROW --> <ul class="nav"> <!-- ELSEIF folder.S_LAST_ROW --> </ul> <!-- ELSE --> <li><a href="{folder.U_FOLDER}">{folder.FOLDER_NAME}</a></li> <!-- ENDIF --> would result in the following markup: <ul class="nav"> <!-- written on first iteration --> <li>second element</li> <!-- written on second iteration --> </ul> <!-- written on third iteration --> Just always remember that processing is taking place from up to down. FormsIf a form is used for a non-trivial operation (i.e. more than a jumpbox), then it should include the <form method="post" id="mcp" action="{U_POST_ACTION}"> <fieldset class="submit-buttons"> <input type="reset" value="{L_RESET}" name="reset" class="button2" /> <input type="submit" name="action[add_warning]" value="{L_SUBMIT}" class="button1" /> {S_FORM_TOKEN} </fieldset> </form> 4.ii. Template InheritanceWhen basing a new template on an existing one, it is not necessary to provide all template files. By declaring the template to be "inheriting" in the template configuration file. The limitation on this is that the base style has to be installed and complete, meaning that it is not itself inheriting. The effect of doing so is that the template engine will use the files in the new template where they exist, but fall back to files in the base template otherwise. Declaring a style to be inheriting also causes it to use some of the configuration settings of the base style, notably database storage. We strongly encourage the use of inheritance for styles based on the bundled styles, as it will ease the update procedure. # General Information about this template name = inherits copyright = © phpBB Group, 2007 version = 3.0.3 # Defining a different template bitfield template_bitfield = lNg= # Are we inheriting? inherit_from = prosilver 5. Character Sets and EncodingsWhat are Unicode, UCS and UTF-8?The Universal Character Set (UCS) described in ISO/IEC 10646 consists of a large amount of characters. Each of them has a unique name and a code point which is an integer number. Unicode - which is an industry standard - complements the Universal Character Set with further information about the characters' properties and alternative character encodings. More information on Unicode can be found on the Unicode Consortium's website. One of the Unicode encodings is the 8-bit Unicode Transformation Format (UTF-8). It encodes characters with up to four bytes aiming for maximum compatibility with the American Standard Code for Information Interchange which is a 7-bit encoding of a relatively small subset of the UCS. phpBB's use of UnicodeUnfortunately PHP does not faciliate the use of Unicode prior to version 6. Most functions simply treat strings as sequences of bytes assuming that each character takes up exactly one byte. This behaviour still allows for storing UTF-8 encoded text in PHP strings but many operations on strings have unexpected results. To circumvent this problem we have created some alternative functions to PHP's native string operations which use code points instead of bytes. These functions can be found in phpBB only uses the ASCII and the UTF-8 character encodings. Still all Strings are UTF-8 encoded because ASCII is a subset of UTF-8. The only exceptions to this rule are code sections which deal with external systems which use other encodings and character sets. Such external data should be converted to UTF-8 using the With // an input string containing a multibyte character $_REQUEST['multibyte_string'] = 'Käse'; // print request variable as a UTF-8 string allowing multibyte characters echo request_var('multibyte_string', '', true); // print request variable as ASCII string echo request_var('multibyte_string', ''); This code snippet will generate the following output: Käse K??se Unicode NormalizationIf you retrieve user input with multibyte characters you should additionally normalize the string using $_REQUEST['multibyte_string'] = 'Käse'; // normalize multibyte strings echo utf8_normalize_nfc(request_var('multibyte_string', '', true)); // ASCII strings do not need to be normalized echo request_var('multibyte_string', ''); Case FoldingCase insensitive comparison of strings is no longer possible with // Bad - The strings might be the same even if strtolower differs if (strtolower($string1) == strtolower($string2)) { echo '$string1 and $string2 are equal or differ in case'; } // Good - Case folding is really case insensitive if (utf8_case_fold_nfc($string1) == utf8_case_fold_nfc($string2)) { echo '$string1 and $string2 are equal or differ in case'; } Confusables DetectionphpBB offers a special method 6. Translation (i18n/L10n) Guidelines6.i. StandardisationReason:phpBB is one of the most translated open-source projects, with the current stable version being available in over 60 localisations. Whilst the ad hoc approach to the naming of language packs has worked, for phpBB3 and beyond we hope to make this process saner which will allow for better interoperation with current and future web browsers. Encoding:With phpBB3, the output encoding for the forum in now UTF-8, a Universal Character Encoding by the Unicode Consortium that is by design a superset to US-ASCII and ISO-8859-1. By using one character set which simultaenously supports all scripts which previously would have required different encodings (eg: ISO-8859-1 to ISO-8859-15 (Latin, Greek, Cyrillic, Thai, Hebrew, Arabic); GB2312 (Simplified Chinese); Big5 (Traditional Chinese), EUC-JP (Japanese), EUC-KR (Korean), VISCII (Vietnamese); et cetera), this removes the need to convert between encodings and improves the accessibility of multilingual forums. The impact is that the language files for phpBB must now also be encoded as UTF-8, with a caveat that the files must not contain a BOM for compatibility reasons with non-Unicode aware versions of PHP. For those with forums using the Latin character set (ie: most European languages), this change is transparent since UTF-8 is superset to US-ASCII and ISO-8859-1. Language Tag:The IETF recently published RFC 4646 for tags used to identify languages, which in combination with RFC 4647 obseletes the older RFC 3006 and older-still RFC 1766. RFC 4646 uses ISO 639-1/ISO 639-2, ISO 3166-1 alpha-2, ISO 15924 and UN M.49 to define a language tag. Each complete tag is composed of subtags which are not case sensitive and can also be empty. Ordering of the subtags in the case that they are all non-empty is: Most language tags consist of a two- or three-letter language subtag (from ISO 639-1/ISO 639-2). Sometimes, this is followed by a two-letter or three-digit region subtag (from ISO 3166-1 alpha-2 or UN M.49). Some examples are:
The ultimate aim of a language tag is to convey the needed useful distingushing information, whilst keeping it as short as possible. So for example, use Next is the ISO 15924 language script code and when one should or shouldn't use it. For example, whilst
Usage of the three-digit UN M.49 code over the two-letter ISO 3166-1 alpha-2 code should hapen if a macro-geographical entity is required and/or the ISO 3166-1 alpha-2 is ambiguous. Examples of English using marco-geographical regions:
Examples of Spanish using marco-geographical regions:
Example of where the ISO 3166-1 alpha-2 is ambiguous and why UN M.49 might be preferred:
Macro-languages & Topolects:RFC 4646 anticipates features which shall be available in (currently draft) ISO 639-3 which aims to provide as complete enumeration of languages as possible, including living, extinct, ancient and constructed languages, whether majour, minor or unwritten. A new feature of ISO 639-3 compared to the previous two revisions is the concept of macrolanguages where Arabic and Chinese are two such examples. In such cases, their respective codes of
6.ii. Other considerationsNormalisation of language tags for phpBB:For phpBB, the language tags are not used in their raw form and instead converted to all lower-case and have the hyphen
How to use
|
Raw language tag | English description within iso.txt |
---|---|
en |
British English |
en-US |
English (United States) |
en-053 |
English (Australia & New Zealand) |
de |
German |
de-CH-1996 |
German (Switzerland, 1996 orthography) |
gws-1996 |
Swiss German (1996 orthography) |
zh-cmn-Hans-CN |
Mandarin Chinese (Simplified, Mainland China) |
zh-yue-Hant-HK |
Cantonese Chinese (Traditional, Hong Kong) |
For the localised language description, just translate the English version though use whatever appropriate punctuation typical for your own locale, assuming the language uses punctuation at all.
Because phpBB is now UTF-8, all translators must take into account that certain strings may be shown when the directionality of the document is either opposite to normal or is ambiguous.
The various Unicode control characters for bi-directional text and their HTML enquivalents where appropriate are as follows:
Unicode character abbreviation |
Unicode code-point |
Unicode character name |
Equivalent HTML markup/entity |
Raw character (enclosed between '') |
---|---|---|---|---|
LRM |
U+200E |
Left-to-Right Mark | ‎ |
'' |
RLM |
U+200F |
Right-to-Left Mark | ‏ |
'' |
LRE |
U+202A |
Left-to-Right Embedding | dir="ltr" |
'' |
RLE |
U+202B |
Right-to-Left Embedding | dir="rtl" |
'' |
PDF |
U+202C |
Pop Directional Formatting | </bdo> |
'' |
LRO |
U+202D |
Left-to-Right Override | <bdo dir="ltr"> |
'' |
RLO |
U+202E |
Right-to-Left Override | <bdo dir="rtl"> |
'' |
For iso.txt
, the directionality of the text can be explicitly set using special Unicode characters via any of the three methods provided by left-to-right/right-to-left markers/embeds/overrides, as without them, the ordering of characters will be incorrect, eg:
Directionality | Raw character view | Display of localised description in iso.txt |
Ordering |
---|---|---|---|
dir="ltr" |
English (Australia & New Zealand) | English (Australia & New Zealand) | Correct |
dir="rtl" |
English (Australia & New Zealand) | English (Australia & New Zealand) | Incorrect |
dir="rtl" with LRM |
English (Australia & New Zealand)U+200E |
English (Australia & New Zealand) | Correct |
dir="rtl" with LRE & PDF |
U+202A English (Australia & New Zealand)U+202C |
English (Australia & New Zealand) | Correct |
dir="rtl" with LRO & PDF |
U+202D English (Australia & New Zealand)U+202C |
English (Australia & New Zealand) | Correct |
In choosing which of the three methods to use, in the majority of cases, the LRM
or RLM
to put a "strong" character to fully enclose an ambiguous punctuation character and thus make it inherit the correct directionality is sufficient.
Within some cases, there may be mixed scripts of a left-to-right and right-to-left direction, so using LRE
& RLE
with PDF
may be more appropriate. Lastly, in very rare instances where directionality must be forced, then use LRO
& RLO
with PDF
.
For further information on authoring techniques of bi-directional text, please see the W3C tutorial on authoring techniques for XHTML pages with bi-directional text.
As phpBB is translated into languages with different ordering rules to that of English, it is possible to show specific values in any order deemed appropriate. Take for example the extremely simple "Page X of Y", whilst in English this could just be coded as:
... 'PAGE_OF' => 'Page %s of %s', /* Just grabbing the replacements as they come and hope they are in the right order */ ...
… a clearer way to show explicit replacement ordering is to do:
... 'PAGE_OF' => 'Page %1$s of %2$s', /* Explicit ordering of the replacements, even if they are the same order as English */ ...
Why bother at all? Because some languages, the string transliterated back to English might read something like:
... 'PAGE_OF' => 'Total of %2$s pages, currently on page %1$s', /* Explicit ordering of the replacements, reversed compared to English as the total comes first */ ...
As the language files are PHP files, where the various strings for phpBB are stored within an array which in turn are used for display within an HTML page, rules of syntax for both must be considered. Potentially problematic characters are: '
(straight quote/apostrophe), "
(straight double quote), <
(less-than sign), >
(greater-than sign) and &
(ampersand).
// Bad - The un-escapsed straight-quote/apostrophe will throw a PHP parse error
... 'CONV_ERROR_NO_AVATAR_PATH' => 'Note to developer: you must specify $convertor['avatar_path'] to use %s.', ...
// Good - Literal straight quotes should be escaped with a backslash, ie: \
... 'CONV_ERROR_NO_AVATAR_PATH' => 'Note to developer: you must specify $convertor[\'avatar_path\'] to use %s.', ...
However, because phpBB3 now uses UTF-8 as its sole encoding, we can actually use this to our advantage and not have to remember to escape a straight quote when we don't have to:
// Bad - The un-escapsed straight-quote/apostrophe will throw a PHP parse error
... 'USE_PERMISSIONS' => 'Test out user's permissions', ...
// Okay - However, non-programmers wouldn't type "user\'s" automatically
... 'USE_PERMISSIONS' => 'Test out user\'s permissions', ...
// Best - Use the Unicode Right-Single-Quotation-Mark character
... 'USE_PERMISSIONS' => 'Test out user’s permissions', ...
The "
(straight double quote), <
(less-than sign) and >
(greater-than sign) characters can all be used as displayed glyphs or as part of HTML markup, for example:
// Bad - Invalid HTML, as segments not part of elements are not entitised
... 'FOO_BAR' => 'PHP version < 4.3.3.<br /> Visit "Downloads" at <a href="http://www.php.net/">www.php.net</a>.', ...
// Okay - No more invalid HTML, but """ is rather clumsy
... 'FOO_BAR' => 'PHP version < 4.3.3.<br /> Visit "Downloads" at <a href="http://www.php.net/">www.php.net</a>.', ...
// Best - No more invalid HTML, and usage of correct typographical quotation marks
... 'FOO_BAR' => 'PHP version < 4.3.3.<br /> Visit “Downloads” at <a href="http://www.php.net/">www.php.net</a>.', ...
Lastly, the &
(ampersand) must always be entitised regardless of where it is used:
// Bad - Invalid HTML, none of the ampersands are entitised
... 'FOO_BAR' => '<a href="http://somedomain.tld/?foo=1&bar=2">Foo & Bar</a>.', ...
// Good - Valid HTML, amperands are correctly entitised in all cases
... 'FOO_BAR' => '<a href="http://somedomain.tld/?foo=1&bar=2">Foo & Bar</a>.', ...
As for how these charcters are entered depends very much on choice of Operating System, current language locale/keyboard configuration and native abilities of the text editor used to edit phpBB language files. Please see http://en.wikipedia.org/wiki/Unicode#Input_methods for more information.
The default language pack bundled with phpBB is British English using Cambridge University Press spelling and is assigned the language code en
. The style and tone of writing tends towards formal and translations should emulate this style, at least for the variant using the most compact language code. Less formal translations or those with colloquialisms must be denoted as such via either an extension
or privateuse
tag within its language code.
The version control system for phpBB3 is subversion. The repository is available at http://code.phpbb.com/svn/phpbb.
/trunk/phpBB
/trunk
at the time of release.
/branches/phpBB-3_0_0/phpBB
/branches/phpBB-2_0_0/phpBB
/tags/release_3_0_BX
/tags/release_3_0_RCX
/tags/release_3_0_X-RCY
/tags/release_3_0_X
/tags/release_2_0_X
The commit message should contain a brief explanation of all changes made within the commit. Often identical to the changelog entry. A bug ticket can be referenced by specifying the ticket ID with a hash, e.g. #12345. A reference to another revision should simply be prefixed with r, e.g. r12345.
Junior Developers need to have their patches approved by a development team member first. The commit message must end in a line with the following format:
Authorised by: developer1[, developer2[, ...]]
This application is opensource software released under the GPL. Please see source code and the docs directory for more details. This package and its contents are Copyright (c) 2000, 2002, 2005, 2007 phpBB Group, All Rights Reserved.
:: Command execute :: | |
--[ c99shell v. 2.0 [PHP 7 Update] [25.02.2019] maintained by HackingTool | HackingTool | Generation time: 0.0031 ]-- |