1/** 2 * @file 3 * Colorbox module init js. 4 */ 5 6(function ($) { 7 8Drupal.behaviors.initColorbox = { 9 attach: function (context, settings) { 10 if (!$.isFunction($('a, area, input', context).colorbox) || typeof settings.colorbox === 'undefined') { 11 return; 12 } 13 14 if (settings.colorbox.mobiledetect && window.matchMedia) { 15 // Disable Colorbox for small screens. 16 var mq = window.matchMedia("(max-device-width: " + settings.colorbox.mobiledevicewidth + ")"); 17 if (mq.matches) { 18 return; 19 } 20 } 21 22 // Use "data-colorbox-gallery" if set otherwise use "rel". 23 settings.colorbox.rel = function () { 24 if ($(this).data('colorbox-gallery')) { 25 return $(this).data('colorbox-gallery'); 26 } 27 else { 28 return $(this).attr('rel'); 29 } 30 }; 31 32 $('.colorbox', context) 33 .once('init-colorbox').each(function(){ 34 // Only images are supported for the "colorbox" class. 35 // The "photo" setting forces the href attribute to be treated as an image. 36 var extendParams = { 37 photo: true 38 }; 39 // If a title attribute is supplied, sanitize it. 40 var title = $(this).attr('title'); 41 if (typeof title === 'undefined') { 42 title = this.dataset.cboxTitle; 43 } 44 if (title) { 45 extendParams.title = Drupal.colorbox.sanitizeMarkup(title); 46 } 47 $(this).colorbox($.extend({}, settings.colorbox, extendParams)); 48 49 // Only allow http or https protocol in hrefs. 50 var href = $(this).attr('href'); 51 var protocolRegex = /^https?$/i; 52 if (href) { 53 var protocol = href.split(':')[0]; 54 // Use a regex to match http or https protocol. 55 if (!protocolRegex.test(protocol)) { 56 $(this).removeAttr('href'); 57 } 58 } 59 var dataHref = this.dataset.cboxHref; 60 if (dataHref) { 61 var dataProtocol = dataHref.split(':')[0]; 62 if (!protocolRegex.test(dataProtocol)) { 63 delete this.dataset.cboxHref; 64 } 65 } 66 67 // Since the sanitized title has been passed to colorbox settings, 68 // delete the unsanitized data-cbox-title attribute. 69 delete this.dataset.cboxTitle; 70 71 // Disallow dangerous data attributes. 72 delete this.dataset.cboxIframeAttrs; 73 74 // Sanitize other data attributes. 75 var sanitizeDataList = ['cboxNext', 'cboxPrevious', 'cboxCurrent', 76 'cboxClose', 'cboxSlideshowstop', 'cboxSlideshowstart', 77 'cboxXhrError', 'cboxImgerror', 'cboxHtml' 78 ]; 79 for (var a of sanitizeDataList) { 80 if (this.dataset.hasOwnProperty(a)) { 81 this.dataset[a] = Drupal.colorbox.sanitizeMarkup(this.dataset[a]); 82 } 83 } 84 }); 85 86 $(context).bind('cbox_complete', function () { 87 Drupal.attachBehaviors($('#cboxLoadedContent')); 88 }); 89 } 90}; 91 92// Create colorbox namespace if it doesn't exist. 93if (!Drupal.hasOwnProperty('colorbox')) { 94 Drupal.colorbox = {}; 95} 96 97/** 98 * Global function to allow sanitizing captions and control strings. 99 * 100 * @param markup 101 * String containing potential markup. 102 * @return @string 103 * Sanitized string with potentially dangerous markup removed. 104 */ 105Drupal.colorbox.sanitizeMarkup = function(markup) { 106 // If DOMPurify installed, allow some HTML. Otherwise, treat as plain text. 107 if (typeof DOMPurify !== 'undefined') { 108 var purifyConfig = { 109 ALLOWED_TAGS: [ 110 'a', 111 'b', 112 'strong', 113 'i', 114 'em', 115 'u', 116 'cite', 117 'code', 118 'br' 119 ], 120 ALLOWED_ATTR: [ 121 'href', 122 'hreflang', 123 'title', 124 'target' 125 ] 126 } 127 if (Drupal.settings.hasOwnProperty('dompurify_custom_config')) { 128 purifyConfig = Drupal.settings.dompurify_custom_config; 129 } 130 return DOMPurify.sanitize(markup, purifyConfig); 131 } 132 else { 133 return Drupal.checkPlain(markup); 134 } 135} 136 137})(jQuery);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.