Forums / General Questions / PHP inside ezpages

PHP inside ezpages

Views: 54,189

Results 81 to 100 of 114
5 Jan 2011, 6:46 PM
#81
finlander avatar

finlander

Zen Follower

Join Date:
Oct 2010
Location:
Idaho
Posts:
293
Plugin Contributions:
0

PHP inside ezpages

hey Glenn, yeah, now I'm a little confused, but things work fine.

I did wonder why that 'new_products = false' code was in there when I first looked at this file to add the not-home-page code, but the new products centerbox was displaying fine everywhere before adding the not-home-page code, and now is displaying fine everywhere except the home page, which is what we wanted.

So, yeah, I have no idea why that 'false' code doesn't interfere .. but the 'true' test below it is maybe reversing it (when Admin >> Config setting does have have New Prods centerbox set to display). This is what you are calling the 'resetting' test? Maybe that 'false' code is there so that this file's code simply makes sure that New Prods centerbox is totally off before running the main part of the code, which then turns the centerbox on.

5 Jan 2011, 6:58 PM
#82
gjh42 avatar

gjh42

Black Belt

Join Date:
Jul 2005
Location:
Upstate NY
Posts:
21,876
Plugin Contributions:
8

Re: PHP inside ezpages

Since it does work correctly, I am sure that there is some testing code in the module file that is "required" after the "false" setting. That code in the other file will decide whether the sidebox should be displayed and return a true or false value accordingly.

8 Aug 2011, 6:05 PM
#83
creamcrackers avatar

creamcrackers

Zen Follower

Join Date:
May 2009
Posts:
228
Plugin Contributions:
1

Re: PHP inside ezpages

TecBrat:

Not a Question, but I didn't know where else to post this.

I posted this in the infopages thread a while back. I have updated it to work with ezpages in 1.3.0

To allow PHP code to run inside a "page".

copy includes/templates/template_default/templates/tpl_page_default.php to
includes/templates/your template/templates/

Then edit the new copy as such
find between "<div></div>"

echo $var_pageDetails->fields['pages_html_text'];

> and replace with:
> 
> ```
$titlecheck=substr($var_pageDetails->fields[pages_title],0,9);
if ($titlecheck=="allowcode"){
eval(stripslashes($var_pageDetails->fields['pages_html_text']));}
else{echo $var_pageDetails->fields['pages_html_text']; }

Change "allocode" to whatever name you want your php code ezpages to have, or add more names or remove the if alltogether if you want. (dont forget to change ,0,9 to ,0,x where x is the length of your "allowcode" replacement string.

I hope this is helpful. (I notice that someone else was looking to use include in infopages or ezpages, That's exactly what I am doing. Apparently That person didn't dig deep enough in the other thread, it was 30+ pages long.)

HI
I cant understand
allowcode is my page title (ie the <h1> of my ezypage?) or is it the url /my_ezy_url ? That would be rewritten though because i use seo url mod

And the 0,9... what is that exactly? Change the 9 to the number of characters in my code? Does that include spaces?

8 Aug 2011, 6:11 PM
#84
creamcrackers avatar

creamcrackers

Zen Follower

Join Date:
May 2009
Posts:
228
Plugin Contributions:
1

Re: PHP inside ezpages

Also - with the second example

<div><?php eval(stripslashes('?>' . $var_pageDetails->fields['pages_html_text'])); ?></div>

Which he said is a security issue - is this just a security issue that someone with access to admin area could put some code into ezy pages or could a "customer" enter php somewhere and steal info from my database etc? Customers are able to enter details into ZC database and the file to edit ncludes/templates/template_default/templates/tpl_page_default.php is not just a ezy pages file its the main template default page for the whole site isnt it? Shouldnt it be changing the ezy page template file somewhere instead?

8 Aug 2011, 9:26 PM
#85
apogeerockets avatar

apogeerockets

Zen Follower

Join Date:
Aug 2011
Posts:
104
Plugin Contributions:
0

Re: PHP inside ezpages

So, at this point, the FCKEditor is apparently retired. While I can still download FCKEditor v2.6.6, the current editor is CKEditor 3.6.1 (3.4 for zencart). The CKEditor is still fracking up my PHP and adding code (!-- and -- to essentially comment it out) to make it not work. does anyone know if the FCKEditor hack mentioned at the beginning of the thread works for CKEditor too?

Ideally, what I'm trying to do in the end is be able to write in php into the EZpages and product page descriptions some php that allows specific products to be added to the cart from those non-standard pages.

16 Nov 2011, 2:36 AM
#86
hermes369 avatar

hermes369

New Zenner

Join Date:
Dec 2006
Location:
Augusta, GA
Posts:
74
Plugin Contributions:
0

Re: PHP inside ezpages

I created a directory under /templates/my_template/php. I can call requires from there so far using the get-template-dir method; I'm trying to put several SmugMug galleries on an ez-page. I'm using phpSmug but haven't made it too far.

I am wondering about security implications and even though my plan is to use OAuth, I remain somewhat concerned about injecting a third party within the template directory. I imagine there is a better, modular, way to enable this integration that's more secure; I just don't know what it is or how to do it. Any thoughts?

19 Nov 2011, 11:37 PM
#87
makenoiz avatar

makenoiz

Zen Follower

Join Date:
Mar 2006
Posts:
284
Plugin Contributions:
0

Re: PHP inside ezpages

This thread was started quite a while ago so I wanted to get the current scoop on adding PHP to EZ-pages in .1.3.9h.
0) Can it still be done

  1. Replace which code? Is the following still valid:

Originally Posted by TecBrat View Post
Not a Question, but I didn't know where else to post this.

I posted this in the infopages thread a while back. I have updated it to work with ezpages in 1.3.0

To allow PHP code to run inside a "page".

copy includes/templates/template_default/templates/tpl_page_default.php to
includes/templates/your template/templates/

Then edit the new copy as such
find between "<div></div>"
Code:

echo $var_pageDetails->fields['pages_html_text'];

and replace with:

Code:

$titlecheck=substr($var_pageDetails->fields[pages_title],0,9);
if ($titlecheck=="allowcode"){
eval(stripslashes($var_pageDetails->fields['pages_html_text']));}
else{echo $var_pageDetails->fields['pages_html_text']; }

Change "allocode" to whatever name you want your php code ezpages to have, or add more names or remove the if alltogether if you want. (dont forget to change ,0,9 to ,0,x where x is the length of your "allowcode" replacement string.

I hope this is helpful. (I notice that someone else was looking to use include in infopages or ezpages, That's exactly what I am doing. Apparently That person didn't dig deep enough in the other thread, it was 30+ pages long.)

  1. FCKEditor?
  2. Security Issues?

Thank you

22 stores and counting! Ive been zenned.

20 Nov 2011, 6:09 AM
#88
makenoiz avatar

makenoiz

Zen Follower

Join Date:
Mar 2006
Posts:
284
Plugin Contributions:
0

Re: PHP inside ezpages

Nevermind, I just did it using the simple method and its working great on 1.3.9h. Did not do anything with FCKeditor.

22 stores and counting! Ive been zenned.

16 Dec 2011, 8:56 AM
#89
david_r_1 avatar

david_r_1

New Zenner

Join Date:
Oct 2011
Posts:
42
Plugin Contributions:
0

Re: PHP inside ezpages

The Eval approach has worked perfectly for me (since I reverted to the standard editor), but I'm having trouble using it to call any file that's not in the root directory. If I try to have the page code access anything in includes, etc., it comes back as an "access denied."

I suppose it may be OK to put files into the root directory, but I'm a little worried about it.

Some of the threads mention changing the .htaccess file, but I wasn't able to get that to produce any result.

What I'm doing is using the ez page to display member account data from an external service we provide them. So they can see their list of transactions when logged in to their Zen Cart account. If they aren't logged in, the page isn't accessible.

The php page to generate the display has to pull data from the MySQL database based on their customer number and use that to query the external system. So there are two systems worth of data access that I'd like to keep as protected as possible.

17 Dec 2011, 3:50 AM
#90
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

Right. All php file access inside the includes folder is off-limits to scripts running from a browser.
I strongly suggest from a security standpoint that EZ-Pages is the WRONG place to be injecting PHP code. Period.

Call a file in the root directory. If it's not written with enough security to be put there, then it ought not to be on your site at all.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

30 Dec 2011, 9:27 PM
#91
fakedecoy avatar

fakedecoy

Zen Follower

Join Date:
Jul 2006
Posts:
309
Plugin Contributions:
0

Re: PHP inside ezpages

brandtim's simple solution on page 1 works for me. But I'm having a problem pulling from the database on an EZ page that serves as a comparison page I have written about some products.

<?php echo 'test' . zen_get_products_display_price((int)$_GET['2206']); ?>

The above code inserted into the EZ page is commented out by zen-cart when the page is displayed. From the live page source:

<!--?php echo '$' . zen_get_products_display_price((int)$_GET['2206']); ?-->

Adamant Barbell - Home & commercial gym equipment - Since 2007
www.adamantbarbell.com

30 Dec 2011, 9:36 PM
#92
fakedecoy avatar

fakedecoy

Zen Follower

Join Date:
Jul 2006
Posts:
309
Plugin Contributions:
0

Re: PHP inside ezpages

I need to amend my previous post to say that the solution does NOT work for me. That's what happens when I try.

Adamant Barbell - Home & commercial gym equipment - Since 2007
www.adamantbarbell.com

4 Jan 2012, 4:19 PM
#93
fakedecoy avatar

fakedecoy

Zen Follower

Join Date:
Jul 2006
Posts:
309
Plugin Contributions:
0

Re: PHP inside ezpages

Bump. Any solutions?

Adamant Barbell - Home & commercial gym equipment - Since 2007
www.adamantbarbell.com

9 Jan 2012, 3:54 AM
#94
fakedecoy avatar

fakedecoy

Zen Follower

Join Date:
Jul 2006
Posts:
309
Plugin Contributions:
0

Re: PHP inside ezpages

Bump again. Am I the only one needing to pull pricing info on EZ pages?

I've studied TechBrat's posts several times, but I can't for the live of me figure out what the "allocode" he's talking about is for.

Adamant Barbell - Home & commercial gym equipment - Since 2007
www.adamantbarbell.com

9 Jan 2012, 4:17 AM
#95
fakedecoy avatar

fakedecoy

Zen Follower

Join Date:
Jul 2006
Posts:
309
Plugin Contributions:
0

Re: PHP inside ezpages

Nevermind! I don't know what I did wrong, but it's working now.

Adamant Barbell - Home & commercial gym equipment - Since 2007
www.adamantbarbell.com

16 Feb 2012, 1:59 AM
#97
fakedecoy avatar

fakedecoy

Zen Follower

Join Date:
Jul 2006
Posts:
309
Plugin Contributions:
0

Re: PHP inside ezpages

Is there a further modification to brandtim's excellent solution that can be done to allow a backslash in javascript code that I'm using in an EZPage? Zencart is removing the backslash in the replace function here and I believe is breaking my code in the process.

return decodeURIComponent(keyvaluepair[1].replace(/+/g, ' '));

brandtim's solution to allow PHP code:

brandtim:

MODERATOR COMMENT: Adding eval() to arbitrarily execute random PHP or other code in the manner suggested here opens your site up to security risks.
USE AT YOUR OWN RISK.

I definately needed this feature. Here's an even simpler version.

Replace this:

<div><?php echo $var_pageDetails->fields['pages_html_text']; ?></div> ``` > > with this: > > ``` <div><?php eval(stripslashes('?>' . $var_pageDetails->fields['pages_html_text'])); ?></div> ``` > > This way you don't have worry about php being 'on' in the ezpage - you can make the code of the page html with php inside it (a lot easier). > > Tim

Adamant Barbell - Home & commercial gym equipment - Since 2007
www.adamantbarbell.com

15 Apr 2012, 4:20 PM
#98
divavocals avatar

divavocals

Totally Zenned

Join Date:
Jan 2007
Location:
Los Angeles, California, United States
Posts:
10,011
Plugin Contributions:
3

Re: PHP inside ezpages

DrByte:

Right. All php file access inside the includes folder is off-limits to scripts running from a browser.
I strongly suggest from a security standpoint that EZ-Pages is the WRONG place to be injecting PHP code. Period.

Call a file in the root directory. If it's not written with enough security to be put there, then it ought not to be on your site at all.
Good morning.. I promise I am not trying to be a hard-head here, but I have a client who won't simply accept this answer. I've explained that EZ Pages are saved to the DB and we can't save executable code to the DB.. Would be able to provide me with something more I can take back to her so she will let this go once and for all..:smile:

My Site - Zen Cart & WordPress integration specialist
I don't answer support questions via PM. Post add-on support questions in the support thread. The question & the answer will benefit others with similar issues.

16 Apr 2012, 4:52 AM
#99
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

While the general principle still applies (don't enter programming code via admin screens), I can't give you one generic answer that could adequately arm you with suitable information to convince your client one way or another. Details of what exactly they want to accomplish (the end result), and why (the business goal they're trying to meet or the problem they're trying to solve), as well as why they're convinced that the solution they've come up with is the "right" one having forsaken all others, are all important pieces of information.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

16 Apr 2012, 5:11 AM
#100
divavocals avatar

divavocals

Totally Zenned

Join Date:
Jan 2007
Location:
Los Angeles, California, United States
Posts:
10,011
Plugin Contributions:
3

Re: PHP inside ezpages

DrByte:

While the general principle still applies (don't enter programming code via admin screens), I can't give you one generic answer that could adequately arm you with suitable information to convince your client one way or another. Details of what exactly they want to accomplish (the end result), and why (the business goal they're trying to meet or the problem they're trying to solve), as well as why they're convinced that the solution they've come up with is the "right" one having forsaken all others, are all important pieces of information.I understand.. I'm just looking to find an explanation of the security risks involved with adding PHP code to EZ Pages since the explanations I've provided thus far (based largely on your prior posts) haven't convinced her yet that this is not a good idea.. sigh

The "business problem" she is trying to solve is that she wants to use a particular slideshow/gallery on her site and she wants to be able to add the slideshow code to ANY EZ Page on the site.. Adding it to the defined pages is not an issue, but she is INSISTING on being able to use EZ pages to add these slideshows to as well.. sigh I can create as many defined pages as she needs to do this, but she somehow seems to feel that she won't have "flexibility" if she can't use EZ Pages too..

My Site - Zen Cart & WordPress integration specialist
I don't answer support questions via PM. Post add-on support questions in the support thread. The question & the answer will benefit others with similar issues.