Commit Graph

4820 Commits

Author SHA1 Message Date
oleibman 83f2d8692c Validate Mime Type of Image Files 2024-09-11 07:49:46 -07:00
oleibman 3e7751e363 Restrict Protocols for Html Hyperlinks
Render hyperlink as text if it begins with a string of word characters followed by colon, unless the string is one of http, https, file, ftp, or s3.
2024-08-28 12:27:47 -07:00
oleibman 219b0b4651 Scrutinizer Suggestion 2024-08-18 20:18:37 -07:00
oleibman bdc468063e More Tests 2024-08-18 19:32:27 -07:00
oleibman 5cd6b8870c Fix Minor Scrutinizer Complaint 2024-08-17 19:48:58 -07:00
oleibman e312656e3d Restrict Internet Protocols for Linked Images
Do not allow use of Php propietary protocols to retrieve linked images. Restrict to http, https, ftp, file, and s3.
2024-08-17 19:25:18 -07:00
oleibman a9171767f7 Try to Appease Scrutinizer
I usually ignore complexity warnings, but let's see if I can fix this one.
2024-08-15 19:54:59 -07:00
oleibman 197dd4d881 Image Transparency/Opacity Including Html Reader Changes
See discussion #4117. This PR implements image transparency, for Xlsx Reader and Writer, Html Reader, and Html/Dompdf/Mpdf Writer. (Mpdf treats 100% opacity as if it were zero, but it's otherwise okay and that would be an unusual choice anyhow.) A new property `opacity` with getter/setter is added to BaseDrawing (and therefore Drawing and MemoryDrawing). Although the Excel UI lets you set the image *transparency*, the value stored in the Xml is actually its *opacity* (expressed as an integer between 0 and 100,000). Likewise Html/Css lets you set opacity (as a float between 0 and 1). PhpSpreadsheet lets you set it as it is stored in Xml - so a value of 40,000 would indicate 40% opacity = 60% transparency.

In the course of testing, some problems with Html Reader presented themselves. They are corrected as part of this ticket:
- Web page title will no longer be "Untitled Spreadsheet" if a title tag is present in the header section of the html.
- If a class attribute is used with the table tag representing a worksheet, showGridlines and printGridlines will be set according to whether gridlines and/or gridlinesp are among the class names.
- Reader has been performing urldecode on the src attribute of the img tag. This breaks data url's by converting plus signs to spaces. It will now perform urldecode only for non-data url's.
- If height and width are not used as attributes on the img tag, they will be extracted from the style attribute if they are present there.
2024-08-15 18:34:15 -07:00
oleibman f7c183b8ed Merge pull request #4137 from oleibman/fixertest
Php-cs-fixer Increase Timeout, Replace Deprecated Properties
2024-08-12 15:28:44 +00:00
oleibman b843d4e313 Merge branch 'master' into fixertest 2024-08-12 08:25:48 -07:00
oleibman b1d43ee3a3 Remove Some Commented Out Lines 2024-08-12 08:09:37 -07:00
oleibman 9bc51a18c1 Forgot One Change 2024-08-12 08:06:06 -07:00
oleibman 3e56c2da9a Php-cs-fixer Increase Timeout, Replace Deprecated Properties
I am becoming concerned with the increasing run-time of php-cs-fixer, especially since it can time out. Some relief may come from PR #4118, but that won't be merged for some time, if ever. So, bump up the timeout period now. Also replace properties which php-cs-fixer has deprecated with their non-deprecated equivalents. No change to any source code.
2024-08-12 08:01:34 -07:00
oleibman 6a8eda9f9e Merge pull request #3962 from oleibman/atsign
Excel Dynamic Arrays (Avoid Adding At-Signs to Formulas)
2024-08-12 12:48:08 +00:00
oleibman fdbf3334fd Update CHANGELOG.md 2024-08-10 00:46:13 -07:00
oleibman 823cb2d4d5 Merge branch 'master' into atsign 2024-08-09 22:34:54 -07:00
oleibman ffbcee6806 Merge pull request #4132 from oleibman/issue4128
Worksheet applyStylesFromArray Retain Active Cell
2.2.2
2024-08-08 02:31:26 +00:00
oleibman 905d93f60d Update CHANGELOG.md 2024-08-07 19:23:00 -07:00
oleibman 9450bc1acb Merge branch 'master' into issue4128 2024-08-07 11:31:01 -07:00
oleibman 4500f5a87d Worksheet applyStylesFromArray Retain Active Cell
Fix #4128. PR #4073 introduced applyStylesFromArray method, which allowed setting styles without affecting selectedCells or activeSheet. The first use of this method was in Cell setValueExplicit to set quotePrefix appropriately. The new method did not preserve activeCell. I'm not sure why that should matter, but this seems to have caused a problem for Excel 2016. This seems to be a bug in Excel, one which is fixed in newer releases. However, PhpSpreadsheet can avoid the problem by preserving activeCell as well as selectedCells and activeSheet. This PR makes that change.
2024-08-07 08:12:47 -07:00
oleibman e5e6bde299 Update Changelog and Docs Prior to Merge Next Week
This will, I hope, be my last change prior to merge on August 7. PR is fully synced with master (except for this change), and, except for an emergency, I do not intend to merge anything else before this.
2024-08-02 10:48:13 -07:00
oleibman f3ae0bd944 Merge branch 'master' into atsign 2024-08-02 09:01:06 -07:00
oleibman 1c77e00499 Merge pull request #4115 from oleibman/issue4113
New Algorithm for TRUNC, ROUNDUP, and ROUNDDOWN
2024-08-02 15:45:44 +00:00
oleibman b1e5e326ac Merge branch 'master' into issue4113 2024-08-02 08:42:52 -07:00
oleibman 2734dfd8d2 Update CHANGELOG.md 2024-08-02 08:41:48 -07:00
oleibman 4da01c3084 Merge pull request #4111 from oleibman/issue4108
Parameter Name Change Xlsx Writer Workbook
2024-08-01 21:10:16 +00:00
oleibman 3e5f1fec40 Merge branch 'master' into issue4108 2024-08-01 14:07:12 -07:00
oleibman a157e3fe7f Update CHANGELOG.md 2024-08-01 14:04:20 -07:00
oleibman 0ddaff3a21 Update Workbook.php 2024-08-01 11:59:28 -07:00
oleibman fcca8ac3cf Merge pull request #4123 from oleibman/csfixer20240801
Php-cs-fixer Enforcing New Rules
2024-08-01 18:18:33 +00:00
oleibman bbf9d15cb2 Php-cs-fixer Enforcing New Rules
The latest release seems to not want you to give a class element both a Php type and a doc-block type. I used the "fix" operand to delete the redundant doc-block declarations, with no other changes. So there should be no change to executable code.
2024-08-01 10:54:54 -07:00
oleibman 85629b77a0 More Extreme Cases 2024-07-31 12:47:19 -07:00
oleibman 768dd75ba1 Merge branch 'master' into atsign 2024-07-30 22:51:13 -07:00
oleibman 3b150557ad Merge pull request #4120 from oleibman/changelog300again
Prepare Changelog for 3.0
2024-07-31 05:39:02 +00:00
oleibman 7556b12b1b Prepare Changelog for 3.0
Also upgrade vendor modules a day ahead of Dependabot.
2024-07-30 22:22:22 -07:00
oleibman 7b478adaeb Too Many Digits
We can't handle more digits than Php allows. Neither can Excel. Just do our best without throwing an Error.
2024-07-30 21:17:50 -07:00
oleibman 523afe57f0 Merge pull request #4107 from oleibman/pr848
RATE Function Permits Floating Point NPER
2024-07-30 22:05:12 +00:00
oleibman ae2c3ea5e4 Merge pull request #4106 from oleibman/issue1284
Html Reader Preserve Unicode Whitespace Characters
2024-07-30 22:04:10 +00:00
oleibman e39dfe341f Use sprintf in Non-Locale-Aware Manner 2024-07-30 08:44:20 -07:00
oleibman 6de86f5d77 Deal With Scientific Notation 2024-07-30 07:37:57 -07:00
oleibman 58ff1491ba Additional Examples Which Were Failing 2024-07-29 08:24:56 -07:00
Adrien Crivelli a3c5c9e7ce 2.2.1 2.2.1 2024-07-29 16:56:06 +09:00
Adrien Crivelli ea97c17bca Merge pull request #4119 from PHPOffice/powerkiki
Security: prevent XXE (XML External Entity) when loading files
2024-07-29 07:50:39 +00:00
Adrien Crivelli bea2d4b30f Security: prevent XXE (XML External Entity) when loading files
Prevent XEE by hiding custom entities by using single quote to
declare a non-UTF-8 encoding.

XML standard, https://www.w3.org/TR/xml/#NT-EncodingDecl, allows single
quote to declare encoding, but we did not support it. Instead, we
incorrectly fell back on the default of UTF-8. That incorrectly kept the
XML as non-UTF-8, and thus prevented our regexp-based custom entity
detection mechanism to work.
2024-07-29 16:22:43 +09:00
oleibman b43947f4c9 Merge pull request #4101 from oleibman/issue4099
Ods Reader Allow Omission of Some Page Settings Tags
2024-07-27 14:51:24 +00:00
oleibman debb1776ef Update CHANGELOG.md 2024-07-27 07:48:40 -07:00
oleibman ab5965affb Merge branch 'master' into issue4099 2024-07-27 07:36:13 -07:00
oleibman 8225096c6f Merge pull request #4098 from oleibman/issue912
Xlsx Reader and Print/Show Gridlines
2024-07-27 14:27:18 +00:00
oleibman bf0281be34 Merge pull request #4096 from oleibman/issue296
Reference to Defined Name Specifying Worksheet Name
2024-07-27 14:25:50 +00:00
oleibman 64b02b0bc1 Merge pull request #4114 from oleibman/issue4112
Addsheet May Leave Active Sheet Uninitialized
2024-07-27 06:27:53 +00:00