url; // $revision = $row->revision; // } else { $sql = sprintf('insert into sandbox (javascript, html, created, last_viewed, url, revision) values ("%s", "%s", now(), now(), "%s", "%s")', mysql_real_escape_string($javascript), mysql_real_escape_string($html), mysql_real_escape_string($code_id), mysql_real_escape_string($revision)); mysql_query($sql); // } if ($ajax) { // supports plugins making use of JS Bin via ajax calls and callbacks if (@$_REQUEST['callback']) { echo $_REQUEST['callback'] . '("'; } $url = 'http://jsbin.com/' . $code_id . ($revision == 1 ? '' : '/' . $revision); if (isset($_REQUEST['format']) && strtolower($_REQUEST['format']) == 'plain') { echo $url; } else { echo '{ "url" : "' . $url . '", "edit" : "' . $url . '/edit", "html" : "' . $url . '/edit", "js" : "' . $url . '/edit" }'; } if ($_REQUEST['callback']) { echo '")'; } } else { // code was saved, so lets do a location redirect to the newly saved code $edit_mode = false; if ($revision == 1) { header('Location: /' . $code_id . '/edit'); } else { header('Location: /' . $code_id . '/' . $revision . '/edit'); } } } else if ($action) { // this should be an id $subaction = array_pop($request); if ($action == 'latest') { // find the latest revision and redirect to that. $code_id = $subaction; $latest_revision = getMaxRevision($code_id); header('Location: /' . $code_id . '/' . $latest_revision); $edit_mode = false; } // gist are formed as jsbin.com/gist/1234 - which land on this condition, so we need to jump out, just in case else if ($subaction != 'gist') { if ($subaction) { $code_id = $subaction; $revision = $action; } else { $code_id = $action; $revision = 1; } list($latest_revision, $html, $javascript) = getCode($code_id, $revision); if (stripos($html, '%code%') === false) { $html = preg_replace('@@', '', $html); } // removed the regex completely to try to protect $n variables in JavaScript $htmlParts = explode("%code%", $html); $html = $htmlParts[0] . $javascript . $htmlParts[1]; $html = preg_replace("/%code%/", $javascript, $html); $html = preg_replace('/<\/body>/', googleAnalytics() . '', $html); $html = preg_replace('/<\/body>/', '' . "\n", $html); if (!$ajax) { $html = preg_replace('/\n", $html); } if (false) { if (stripos($html, '')) { $html = preg_replace('/(.*)/', '$1', $html); } else { // if we can't find a head element, brute force the framebusting in to the HTML $html = '' . $html; } } if (!$html && !$ajax) { $javascript = "/*\n Created using http://jsbin.com\n Source can be edit via http://jsbin.com/$code_id/edit\n*/\n\n" . $javascript; } if (!$html) { header("Content-type: text/javascript"); } echo $html ? $html : $javascript; $edit_mode = false; } } if (!$edit_mode || $ajax) { exit; } function connect() { // sniff, and if on my mac... $link = mysql_connect(DB_HOST, DB_USER, DB_PASSWORD); mysql_select_db(DB_NAME, $link); } function encode($s) { static $jsonReplaces = array(array("\\", "/", "\n", "\t", "\r", "\b", "\f", '"'), array('\\\\', '\\/', '\\n', '\\t', '\\r', '\\b', '\\f', '\"')); return '"' . str_replace($jsonReplaces[0], $jsonReplaces[1], $s) . '"'; } // returns the app loaded with json html + js content function edit() { } // saves current state - should I store regardless of content, to start their own // milestones? function save() { } function getCodeIdParams($request) { $revision = array_pop($request); $code_id = array_pop($request); if ($code_id == null) { $code_id = $revision; $revision = 1; } return array($code_id, $revision); } function getMaxRevision($code_id) { $sql = sprintf('select max(revision) as rev from sandbox where url="%s"', mysql_real_escape_string($code_id), mysql_real_escape_string($revision)); $result = mysql_query($sql); $row = mysql_fetch_object($result); return $row->rev ? $row->rev : 0; } function getCode($code_id, $revision, $testonly = false) { $sql = sprintf('select * from sandbox where url="%s" and revision="%s"', mysql_real_escape_string($code_id), mysql_real_escape_string($revision)); $result = mysql_query($sql); if (!mysql_num_rows($result) && $testonly == false) { header("HTTP/1.0 404 Not Found"); return defaultCode(true); } else if (!mysql_num_rows($result)) { return array($revision); } else { $row = mysql_fetch_object($result); // TODO required anymore? used for auto deletion $sql = 'update sandbox set last_viewed=now() where id=' . $row->id; mysql_query($sql); $javascript = preg_replace('/\r/', '', $row->javascript); $html = preg_replace('/\r/', '', $row->html); $revision = $row->revision; // return array(preg_replace('/\r/', '', $html), preg_replace('/\r/', '', $javascript), $row->streaming, $row->active_tab, $row->active_cursor); return array($revision, get_magic_quotes_gpc() ? stripslashes($html) : $html, get_magic_quotes_gpc() ? stripslashes($javascript) : $javascript, $row->streaming, $row->active_tab, $row->active_cursor); } } function defaultCode($not_found = false) { $library = ''; if (@$_GET['html']) { $html = $_GET['html']; } else { $html = << JS Bin

Hello World

HERE_DOC; } $javascript = ''; if (!@$_GET['js']) { if ($not_found) { $javascript = 'document.getElementById("hello").innerHTML = "This URL does not have any code saved to it.";'; } else { $javascript = "if (document.getElementById('hello')) {\n document.getElementById('hello').innerHTML = 'Hello World - this was inserted using JavaScript';\n}\n"; } } else { $javascript = $_GET['js']; } return array(get_magic_quotes_gpc() ? stripslashes($html) : $html, get_magic_quotes_gpc() ? stripslashes($javascript) : $javascript); } // I'd consider using a tinyurl type generator, but I've yet to find one. // this method also produces *pronousable* urls function generateCodeId($tries = 0) { $code_id = generateURL(); if ($tries > 2) { $code_id .= $tries; } // check if it's free $sql = sprintf('select id from sandbox where url="%s"', mysql_real_escape_string($code_id)); $result = mysql_query($sql); if (mysql_num_rows($result)) { $code_id = generateCodeId(++$tries); } else if ($tries > 10) { echo('Too many tries to find a new code_id - please contact using about'); exit; } return $code_id; } function generateURL() { // generates 5 char word $vowels = str_split('aeiou'); $const = str_split('bcdfghjklmnpqrstvwxyz'); $word = ''; for ($i = 0; $i < 5; $i++) { if ($i % 2 == 0) { // even = vowels $word .= $vowels[rand(0, 4)]; } else { $word .= $const[rand(0, 20)]; } } return $word; } function googleAnalytics() { return << var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www."); document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E")); HERE_DOC; } ?>