We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 36552
    • 32 Posts
    I built a plugin for TinyMCE for a client to handle citations within the resource content field editor in Manager. I'll explain the set up as briefly as I can before I get to the problem and the solution I'm using at the moment.

    The Editor uses a custom module ('Citations') to enter all of the cited sources used on the site. All data sent to the database uses
    $modx->db->escape($_REQUEST['param'])
    before INSERT or UPDATE.

    My TinyMCE plugin uses that data to populate a select field which the Editor uses to select the citation source. The citation is inserted into the #content at the cursor location and the source is added to <div#sources />. The plugin will then renumber the citations and reorder and renumber the sources so that everything matches up.

    A php script called tinymce.citations.php outputs the TinyMCECitationList js variable that the plugin relies on. (This was all based on the tinymce.linklist.php script that is included with Evo installation of TinyMCE).

    The php script pulls the data from the table the array of JSON strings (via json_encode).

    Today I entered in a couple of new citations. One of them had a title with "Authors' Financial...". This broke it.

    I would get and 'Unexpected Identifier' error in console and viewing tinymce.citations.php showed the single-quote as the culprit. It wasn't escaped. All of my double-quotes were properly escaped (there is an entry with a title that has a quoted phrase).

    After trying every method I could find, I settled on simply running foreach() through the array and replacing any single-quotes with
    &# 039;
    in the value (the space is in there to prevent it from becoming a '). I also perform the $modx->db->escape function on the data being json_encod(ed) as the double-quotes were also breaking it early on.

    $output = json_encode($modx->db->escape($data));


    Everything works now, but this feels pretty hacky to me and wanted to know how others have solved this problem.
      • 13428 ☆ A M B ☆
      • 1,031 Posts
      It is a bit difficult to understand what you are doing without the code or a flow diagram.

      Where do you enter/save the citations? In the current resource in an extra TV? And the problem occurs if you have saved the resouce and try to edit it again? If that is the case: this TV has to be a textarea to avoid any single/double quote issues.
        • 36552
        • 32 Posts
        Quote from: Jako at Apr 01, 2014, 02:22 AM
        It is a bit difficult to understand what you are doing without the code or a flow diagram.

        Where do you enter/save the citations? In the current resource in an extra TV? And the problem occurs if you have saved the resouce and try to edit it again? If that is the case: this TV has to be a textarea to avoid any single/double quote issues.

        I'm afraid I explained too much and over-complicated the problem. Forget everything I said before --

        I have data in my database with single-quotes. When I use json_encode the single-quotes in my data are not being escaped. Double-quotes are.

        The solution I found is to run through the array before json_encode to do a str_replace on all single-quotes, like this :

        foreach($all_of_my_data AS $k=>$v){
            $all_of_my_data [$k] = str_replace("'", "'",  $v);
        }
        
        $function_output = json_encode($modx->db->escape($all_of_my_data));
        


        I use $modx->db->escape() in order to make sure my double-quotes are escaped. Without it, the json fails at the first double-quote in the field values.

        I have no problem with the data in any other transaction. It is only when I use json_encode to send it to javascript that I have the single-quote escape issue. This may be the correct solution, but it seems like my str_replace routine is a little hacky and was looking for alternatives.

        To address your specific questions, Jako:

        1. The citations are entered via a custom module in the Manager and are stored as rows in a table called `modx_citations`. No tvs. Not tied to any resources. They are managed by the module.

        2. The title field is a text filed and I have no problem with any CRUD functions, only the non-escaping single-quote in json_encode

        I appreciate the response and hope this helps to clarify.