From 70ef42c3116ab84108e92bad1201e7e7de78678d Mon Sep 17 00:00:00 2001
From: Jared Vititoe
Date: Tue, 8 Sep 2026 11:58:58 -0400
Subject: [PATCH] Delete dead helpers/OutputHelper.php (#54)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Zero callers anywhere in the app — confirmed via grep for
"OutputHelper::" across the whole codebase. Every view actually calls
htmlspecialchars() directly instead, which a prior audit confirmed is
done consistently, so escaping was never actually at risk. This was
just a misleading, unused class that README.md's file reference
implied was part of the app's active XSS-prevention story. Removed the
file and its README Project Structure entry.
Co-Authored-By: Claude Sonnet 5
Claude-Session: https://claude.ai/code/session_01MGDKHiU5RJdo3dqQUDow3X
---
README.md | 1 -
helpers/OutputHelper.php | 212 ---------------------------------------
2 files changed, 213 deletions(-)
delete mode 100644 helpers/OutputHelper.php
diff --git a/README.md b/README.md
index 3f0ce79..c86480c 100644
--- a/README.md
+++ b/README.md
@@ -362,7 +362,6 @@ tinker_tickets/
│ ├── Database.php # Centralized mysqli connection
│ ├── ErrorHandler.php # Global error/exception handler
│ ├── NotificationHelper.php # Matrix hookshot webhook events
-│ ├── OutputHelper.php # Safe HTML output helpers
│ ├── ResponseHelper.php # JSON API response helpers
│ ├── SynapseHelper.php # Resolves usernames → Matrix IDs via Synapse admin API
│ └── UrlHelper.php # Canonical ticket URLs using APP_DOMAIN
diff --git a/helpers/OutputHelper.php b/helpers/OutputHelper.php
deleted file mode 100644
index 54f7201..0000000
--- a/helpers/OutputHelper.php
+++ /dev/null
@@ -1,212 +0,0 @@
-= OutputHelper::h($userInput) ?>
- *
- * @param string|null $string The string to escape
- * @param int $flags htmlspecialchars flags (default: ENT_QUOTES | ENT_HTML5)
- * @return string Escaped string
- */
- public static function h(?string $string, int $flags = ENT_QUOTES | ENT_HTML5): string
- {
- if ($string === null) {
- return '';
- }
- return htmlspecialchars($string, $flags, 'UTF-8');
- }
-
- /**
- * Escape string for HTML attribute context
- *
- * Use for values inside HTML attributes.
- * Example:
- *
- * @param string|null $string The string to encode
- * @return string URL encoded string
- */
- public static function url(?string $string): string
- {
- if ($string === null) {
- return '';
- }
- return rawurlencode($string);
- }
-
- /**
- * Escape for CSS context
- *
- * Use for values in inline CSS.
- * Example:
- *
- * @param string|null $string The string to escape
- * @return string Escaped string (only allows safe characters)
- */
- public static function css(?string $string): string
- {
- if ($string === null) {
- return '';
- }
- // Only allow alphanumeric, hyphens, underscores, spaces, and common CSS values
- if (!preg_match('/^[a-zA-Z0-9_\-\s#.,()%]+$/', $string)) {
- return '';
- }
- return $string;
- }
-
- /**
- * Format a number safely
- *
- * Ensures output is always a valid number.
- *
- * @param mixed $number The number to format
- * @param int $decimals Number of decimal places
- * @return string Formatted number
- */
- public static function number($number, int $decimals = 0): string
- {
- return number_format((float)$number, $decimals, '.', ',');
- }
-
- /**
- * Format an integer safely
- *
- * @param mixed $value The value to format
- * @return int Integer value
- */
- public static function int($value): int
- {
- return (int)$value;
- }
-
- /**
- * Truncate string with ellipsis
- *
- * @param string|null $string The string to truncate
- * @param int $length Maximum length
- * @param string $suffix Suffix to add if truncated
- * @return string Truncated and escaped string
- */
- public static function truncate(?string $string, int $length = 100, string $suffix = '...'): string
- {
- if ($string === null) {
- return '';
- }
-
- if (mb_strlen($string, 'UTF-8') <= $length) {
- return self::h($string);
- }
-
- return self::h(mb_substr($string, 0, $length, 'UTF-8')) . self::h($suffix);
- }
-
- /**
- * Format a date safely
- *
- * @param string|int|null $date Date string, timestamp, or null
- * @param string $format PHP date format
- * @return string Formatted date
- */
- public static function date($date, string $format = 'Y-m-d H:i:s'): string
- {
- if ($date === null || $date === '') {
- return '';
- }
-
- if (is_numeric($date)) {
- return date($format, (int)$date);
- }
-
- $timestamp = strtotime($date);
- if ($timestamp === false) {
- return '';
- }
-
- return date($format, $timestamp);
- }
-
- /**
- * Check if a string is safe for use as a CSS class name
- *
- * @param string $class The class name to validate
- * @return bool True if safe
- */
- public static function isValidCssClass(string $class): bool
- {
- return preg_match('/^[a-zA-Z_][a-zA-Z0-9_-]*$/', $class) === 1;
- }
-
- /**
- * Sanitize CSS class name(s)
- *
- * @param string|null $classes Space-separated class names
- * @return string Sanitized class names
- */
- public static function cssClass(?string $classes): string
- {
- if ($classes === null || $classes === '') {
- return '';
- }
-
- $classList = explode(' ', $classes);
- $validClasses = array_filter($classList, [self::class, 'isValidCssClass']);
-
- return implode(' ', $validClasses);
- }
-}
-
-/**
- * Shorthand function for HTML escaping
- *
- * @param string|null $string The string to escape
- * @return string Escaped string
- */
-function h(?string $string): string
-{
- return OutputHelper::h($string);
-}