==================== === Coding Standards ==================== Contributing Code _________________ The PKP team is happy to accept patches in the public "OCS Development" forum at . If you would like to have your patch included in the OCS codebase, we suggest discussing it with the OCS team before implementation to ensure that it suits upcoming development plans. For code that is intended for inclusion in the main codebase: * Patches against a current CVS checkout are preferred; alternately, patches against the most recent release version are acceptable. * Unless agreed with the development team, users should be able to toggle contributed features between enabled and disabled with a single setting; the system behavior should not be modified when the feature is disabled. * The feature should be suitable for situations where very distinct conferences are hosted within the same deployment; i.e. settings should generally be conference- level, not system-level. * The design patterns used in OCS 2.x should be understood and adhered to. * Localization standards should be maintained. * Database IDs should be checked as in the current codebase. * XSS (cross-site scripting) attacks should be checked as in the current codebase. * Contributors are responsible for writing code compatible with the primary platforms listed in README. * Contributions should be delivered to the team via the public "OCS Development" forum as a patch. * OCS 2.x management features should be kept in mind, such as upgrade and installation; all database schema information should be maintained in the dbscripts/xml/ocs_schema.xml file; etc. * The development team is happy to review contributed patches, but we have a limited amount of time to spend integrating patches with the codebase or modifying contributed code. If aspects of the code need work, we would rather inform the presenter and have them perform the modifications. For contributions that are distributed separately as patches or plugins: * If contributors haven't met all the conditions above, they are welcome to distribute additional features as patches or plugins. However, the OCS team won't be able to provide support in this case. * If the option is available, coding a feature as a plugin is the preferred method. The OCS team is continuing to refine the plugin infrastructure and welcomes discussion with plugin developers. General Conventions ___________________ Editors ------- * Tabs: Configure your editor to use tabs instead of spaces for indentation. * Linefeeds: Your editor must save files using UNIX linefeed format (not DOS CR/LF or Mac CR format). * Ensure your files end with a linefeed if your editor does not automatically add one. Indentation style ------------- * Always include braces even in cases where they are optional. * Use K&R indentation style. * For example: if (condition) { ... } else { ... } Naming Conventions ------------------ * Use descriptive names. One character names are only acceptable as index variables in for loops. * Variable and function/method names (excluding constructors) should start with a lowercase letter and capitalize all other words. E.g., $myVariableName; function myMethodName() { } * Class names should start with a capital letter and capitalize all words. E.g., MyClassName * Constant names should be capitalized with words separated by an underscore. In general, constant names should also be prefixed with the package/class name to avoid collisions. E.g., ROLE_ID_DIRECTOR Comments -------- * PHPDoc/Javadoc-style commenting is encouraged. See * For example: /** * My method. * @param $foo string * @return boolean */ function myMethod($foo) { ... } PHP Tags -------- * Use the tags to enclose PHP code instead of the abbreviated form. * Ensure that each opening "" tag (i.e., do not omit a trailing "?>" at the end of a file even though the PHP parser does not strictly require it). Quoting Strings --------------- * Use single quotes (') instead of double quotes (") to quote strings unless the string contains variables or escape sequences. Single quotes are slightly more efficient since PHP does not have to perform variable interpolation. Error Level ----------- * Code must not produce any error or warning messages with the error_reporting level set to E_ALL (this is the default level set in includes/driver.inc.php). * This means using $array['key'] rather than $array[key], not using uninitialized variables, etc. * Note that this means that "@" should not be used haphazardly to suppress error messages. Global Variables ---------------- * Code should not rely on register_globals being enabled. * GET/POST/Cookie variables should be accessed through the appropriate helper function. Other PHP Conventions _____________________ * The inline form of if/else is acceptable for small statements (e.g., assignments) only. E.g., $foo = $bar ? 1 : 0; * Use spaces between tokens. E.g., $foo = 1; $i > 0 * Compatibility with PHP >= 4.2 (including PHP 5) is required. Appropriate abstractions should be used around non-backwards compatible code (e.g., using function_exists() to check for an available function and using an alternate implementation if it does not exist). HTML/XML -------- * HTML should be XHTML-compliant as much as possible. E.g., use "
" instead of "
". * Tag names should be lower case. SQL --- * Use spaces between tokens. E.g., "column = ?" instead of "column=?" * Uppercase SQL keywords. E.g., INSERT, UPDATE, etc. * Long SQL statements should be logically broken up into multiple lines. * SQL INSERT statements should always specify the column names. * For example: INSERT INTO mytable (x, y, z) VALUES (?, ?, ?) * All SQL queries should be compatible with at least the versions of MySQL and PostgreSQL supported by the application. Although vendor-specific SQL expressions should be avoided, a record should be kept of any non-portable SQL that does get used (e.g., by filing a bug report). OCS Conventions _______________ CVS --- * A web interface to the CVS repository is located at . * A brief log message describing the changes made must be included with all CVS commits. * Whenever possible, CVS commit log messages should include "#BUG_ID_NUMBER#" to reference a Bugzilla report at (it will be automatically linked when viewing a log in CVSweb). File Header ----------- * PHP files should begin with a header similar to the following. Non-PHP files should begin with a similar header adapted to the appropriate comment style. /** * @file FILENAME.inc.php * * Copyright (c) 2000-2008 John Willinsky * Distributed under the GNU GPL v2. For full terms see the file docs/COPYING. * * @package PACKAGE * @class CLASS * * DESCRIPTION. * * $Id: README-DEV,v 1.6 2008/04/04 17:06:48 asmecher Exp $ */ Database Queries ----------- * SQL queries should use the ADOdb abstraction layer. * SQL should use placeholders for variables. * For example: $dbconn = $DBConnection::getConn(); $result = $dbconn->execute('SELECT x FROM mytable WHERE y = ?', array($y)); $result = $dbconn->execute('INSERT INTO mytable (x, y) VALUES (?, ?)', array($x, $y)); * Only portable, standards compliant SQL should be used - compatibility with MySQL >= 3.23 (including 4.x), and PostgreSQL >= 7.3 is required. If database specific logic cannot be avoided it should be abstracted into DBConnection or ADOdb. Direct Access Objects --------------------- * DAO classes should be used to encapsulate all database calls. * Use DAORegistry to retrieve a reference to a DAO object. * For example: $sessionDao = &DAORegistry::getDAO('SessionDAO'); * DAO classes are expected to handle date/datetime format conversion between the database and PHP, and insertion ID retrieval for sequenced records; abstractions are provided in the base DAO class. Templates --------- * HTML output in PHP code should be kept to a minimum. * HTML output should come from the Smarty template abstraction layer. * The template engine supports basic conditional logic and loops and can access objects and arrays, but the complexity of the business logic used in templates should be minimized. * Basic template skeleton: {** * FILENAME.tpl * * Copyright (c) 2000-2008 John Willinsky * Distributed under the GNU GPL v2. For full terms see the file docs/COPYING. * * DESCRIPTION. * * $Id: README-DEV,v 1.6 2008/04/04 17:06:48 asmecher Exp $ *} {assign var="pageTitle" value="user.userHome"} {include file="common/header.tpl"} ... {include file="common/footer.tpl"} Authorization ------------- * Use methods in Validation class to check user credentials. * For example: Validation::isLoggedIn(); Validation::isAuthorized(ROLE_ID_CONFERENCE_MANAGER, $conferenceId, $schedConfId); Validation::isConferenceManager($conferenceId); [ preferred to isAuthorized() ] Localization ------------ * i18n strings are defined in locale//locale.xml. * Key names should be in the form "sectionname(.subsectionname)*.name". E.g., "manager.setup.conferenceTitle" * Use {translate key="my.key.name"} in templates to translate i18n keys. * Use the String wrapper class in place of the built-in string manipulation/regexp routines when handling data that could potentially be in UTF-8 (e.g., user input, parsed user files, etc.). Input Validation ---------------- * User input should be properly validated/escaped (do not rely on magic_quotes_gpc being on or off). * For example, in template forms: * Retrieving user input: $foo = Request::getUserVar('foo'); * Escaping habits in order of precedence: - Manager's Step 5 text fields: No escaping performed - Abstracts, notes, comments, emails: {$field|strip_unsafe_html|nl2br} - Database IDs safely fetched from DB: no escaping necessary. - Mailing Address fields: {$mailingAddress|escape|nl2br} - Biography fields: {$biography|escape|nl2br} - Custom issue or article IDs in URLs: {$pageUrl}/.../{$customId|escape:"url"} - Date fields: Use date_format. - Comment fields: (to be filled in) - Multi-line fields inside textarea tags: {$field|escape} - Multi-line input fields that are filled in by the Manager or Site Administrator: {$field|nl2br} - All other fields: {$field|escape} Note that these should apply to parameters supplied to {translate key="..."} and {mailto address="..."} calls, e.g {translate key="my.key.takes.parameter" myParam=$myVar|escape} Other Tips ---------- * Use Request::redirectUrl($url), or better yet, Request::redirect(...) for HTTP redirects instead of header('Location: ...'); * For additional coding convention information, see the OCS Design Document at .