Escaping and Inspection
The repository bundles two distinct utility surfaces: Laminas\Escaper\Escaper provides context-specific string transformations, while CodeIgniter initializes Kint support for source inspection and diagnostic rendering. Initialization is source-proven; application-level Escaper use and successful Kint diagnostics are not.
[!IMPORTANT] In
imspr/system/CodeIgniter.php, CodeIgniter::initialize directly calls initializeKint after environment bootstrapping. initializeKint loadsSYSTEMPATH . 'ThirdParty/Kint/init.php'only whenKINT_DIRis not already defined, then appliesConfig\Kintvalues to Kint and its renderers. WhenCI_DEBUGis false, the initialization branch setsKint::$enabled_modeto false.Retrieved evidence contains no Kint dump, trace, diagnostic-render invocation, or successful diagnostic execution record. It also contains no application-level Escaper construction or call site. Treat these as bundled and framework-configured capabilities, not proof of active application use.
Escaper contexts
The bundled Laminas\Escaper\Escaper implementation is in imspr/system/ThirdParty/Escaper/Escaper.php. Its constructor accepts an optional encoding, rejects non-string, blank, and unsupported values with Laminas\Escaper\Exception\InvalidArgumentException, and initializes ENT_QUOTES | ENT_SUBSTITUTE plus the HTML-attribute, JavaScript, and CSS matcher callbacks.
| Method | Source-defined transformation |
|---|---|
| escapeHtml | Returns htmlspecialchars($string, $this->htmlSpecialCharsFlags, $this->encoding). |
| escapeHtmlAttr | Converts input to UTF-8, returns empty or numeric strings unchanged, applies the HTML-attribute matcher to characters outside /[^a-z0-9,\.\-_]/iSu, then converts the result back from UTF-8. |
| escapeJs | Converts input to UTF-8, returns empty or numeric strings unchanged, applies the JavaScript matcher to characters outside /[^a-z0-9,\._]/iSu, then converts the result back from UTF-8. |
| escapeUrl | Returns rawurlencode($string). |
| escapeCss | Converts input to UTF-8, returns empty or numeric strings unchanged, applies the CSS matcher to characters outside /[^a-z0-9]/iSu, then converts the result back from UTF-8. |
For non-UTF-8 escaping, the conversion helper prefers iconv and falls back to mb_convert_encoding. If neither conversion extension is available, the implementation raises Laminas\Escaper\Exception\RuntimeException. A failed conversion returns a blank string; output that remains invalid UTF-8 is rejected through the same runtime exception path.
Kint inspection flow
The source-defined initialization and utility relationship is:
flowchart TD
n1["CodeIgniter::initialize"] -->|direct call| n2["CodeIgniter::initializeKint"]
n2 -->|KINT_DIR guard| n3["Bundled Kint loader"]
n2 -->|applies Config\Kint| n4["Kint and renderer settings"]
n5["Kint\Parser::parse"] -->|BasicObject shape| n6["Kint\Renderer\TextRenderer::render"]
The first two edges describe the framework lifecycle and its guarded loader. The parser-to-renderer edge represents the source-defined object shape: Parser::parse returns parsed object data, while TextRenderer::render accepts a BasicObject. It does not establish that application code dispatches either operation at runtime.
Selective implementation details
[
{
"title": "**CallFinder::getFunctionCalls** — inspect source calls",
"body": "In `imspr/system/ThirdParty/Kint/CallFinder.php`, the method tokenizes source with `token_get_all($source)`, scans only through the requested line, and ignores comments and whitespace while scanning. It verifies the requested function and call signature, parses balanced arguments, and returns normalized parameter data together with modifiers."
},
{
"title": "**Parser::parse** — dispatch by PHP type",
"body": "In `imspr/system/ThirdParty/Kint/Parser/Parser.php`, **Parser::parse** records the lowercased PHP type first. A begin-trigger plugin can stop further parsing. Otherwise, arrays, booleans, doubles, integers, nulls, objects, resources, strings, and unknown values are sent to their type-specific parsers."
},
{
"title": "Array recursion and depth limits",
"body": "The array parser uses a private marker to detect recursion and returns a recursion representation for that branch. Empty arrays return early. When the configured depth limit is reached, the parser records a `depth_limit` hint and stops descending."
},
{
"title": "Object inspection and reflection",
"body": "The object parser uses `spl_object_hash` and `ReflectionObject`, records class and object metadata, and marks repeated object hashes as recursion. For user-defined objects it records the source filename and starting line. A configured depth limit also stops object descent."
},
{
"title": "**TextRenderer::render** — assemble diagnostic text",
"body": "In `imspr/system/ThirdParty/Kint/Renderer/TextRenderer.php`, a matching hint plugin is consulted first: when its **render** result is non-empty, that result replaces the default output and is returned. When the result is empty—or no matching plugin is found—the default path continues with a root title for depth-zero objects, the rendered header and children, and an appended line ending."
},
{
"title": "**TextRenderer::renderHeader** and **TextRenderer::escape**",
"body": "**TextRenderer::renderHeader** formats modifiers, names, operators, types, sizes, and shortened values. Names, operators, types, sizes, and values pass through the renderer escape method before colorization or assembly. **TextRenderer::escape** returns its input unchanged, including when an encoding argument is supplied; this method does not provide content escaping."
}
]
Updated