Tags: dereuromark/cakephp-templating
Tags
Collect icon names from svgPath directories and JSON maps (#20) Without a `path`, AbstractIcon::path() falls back to `svgPath` for name collection. IconCollection::buildMap() calls names() on construction, so the fallback runs on every helper init, not only with checkExistence. - FontAwesome4/5/6 (and so 7), Bootstrap and Material collectors fed an svgPath directory straight to file_get_contents(), raising "Read of N bytes failed with errno=21 Is a directory". They now scan the directory for .svg file names, like Lucide/Feather already did. - A JSON SVG map as svgPath was rejected with "is not a directory", which buildMap() swallowed, silently disabling auto-prefixing (and failing hard with checkExistence). path() now accepts an existing .json map; the map keys are the icon names. FA4/Material read it as JSON, FA6 skips style detection for plain string map entries. - The collector in-memory cache is a single static array shared by all subclasses and was keyed by path only, so two collectors reading the same path got each other's result. The key now includes the class. - IconCollection defaults `separator` to ':' so it works standalone without IconHelper.
Validate icon names + drop dead Serializable from Html (#14) Reject path-traversal payloads in SvgRenderTrait::getSvgPath and HeroiconsIcon::getSvgPath: icon names are now allow-listed against [a-zA-Z0-9][a-zA-Z0-9_-]*, the resolved path is realpath-confined to the configured base directory, and the Heroicons style config key is allow-listed against the directories Heroicons ships. JSON-map mode also runs the icon-name allow-list defensively. Drop the Serializable interface from View\Html. The legacy unserialize(string): void method had an empty body and would have left the typed $html property uninitialized on first access; PHP 8.1 deprecated the interface anyway. __serialize / __unserialize remain and continue to round-trip cleanly. Tests cover ../, slash, backslash and empty icon names plus the Heroicons style allow-list.
Add support for svg inlining (#7) * Add support for svg inlining * Added `Configure('debug')` checking support and auto inline when `false` Added the `inline` argument to all icon classes for improved readability Updated docs * Improve inline regex functionality * phpstan fix
PreviousNext