| 1 |
<?php |
| 2 |
namespace ABlocks\Blocks\Logout; |
| 3 |
|
| 4 |
if ( ! defined( 'ABSPATH' ) ) { |
| 5 |
exit; |
| 6 |
} |
| 7 |
|
| 8 |
use ABlocks\Classes\BlockBaseAbstract; |
| 9 |
use ABlocks\Classes\CssGeneratorV2; |
| 10 |
use ABlocks\Controls\Alignment; |
| 11 |
use ABlocks\Controls\Range; |
| 12 |
use ABlocks\Controls\Border; |
| 13 |
use ABlocks\Controls\Typography; |
| 14 |
use ABlocks\Controls\TextShadow; |
| 15 |
use ABlocks\Controls\TextStroke; |
| 16 |
use ABlocks\Controls\Color; |
| 17 |
|
| 18 |
|
| 19 |
class Block extends BlockBaseAbstract { |
| 20 |
protected $block_name = 'logout'; |
| 21 |
|
| 22 |
/** |
| 23 |
* Query arg carrying the signature of a block-issued logout redirect URL. |
| 24 |
*/ |
| 25 |
const REDIRECT_SIGNATURE_ARG = 'ablocks_rs'; |
| 26 |
|
| 27 |
public function __construct( $keep_silent = false ) { |
| 28 |
parent::__construct( $keep_silent ); |
| 29 |
|
| 30 |
if ( $this->is_enabled_block() && ! $keep_silent ) { |
| 31 |
add_filter( 'allowed_redirect_hosts', array( $this, 'allow_signed_logout_redirect_host' ) ); |
| 32 |
} |
| 33 |
} |
| 34 |
|
| 35 |
/** |
| 36 |
* wp-login.php ends a logout with wp_safe_redirect(), which swaps any host |
| 37 |
* outside `allowed_redirect_hosts` for admin_url() — so a custom URL on |
| 38 |
* another domain never took effect. Allow that host for this one request, |
| 39 |
* and only when the redirect carries a signature this block produced from |
| 40 |
* the site's secret salts: a hand-made or edited `redirect_to` stays |
| 41 |
* rejected, so this is not an open redirect. |
| 42 |
* |
| 43 |
* @param string[] $hosts Allowed hosts. |
| 44 |
* @return string[] |
| 45 |
*/ |
| 46 |
public function allow_signed_logout_redirect_host( $hosts ) { |
| 47 |
global $pagenow; |
| 48 |
|
| 49 |
// phpcs:disable WordPress.Security.NonceVerification.Recommended -- wp-login.php verifies the log-out nonce itself; this only reads the redirect target. |
| 50 |
if ( |
| 51 |
'wp-login.php' !== $pagenow || |
| 52 |
! isset( $_REQUEST['action'], $_REQUEST['redirect_to'], $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) || |
| 53 |
'logout' !== $_REQUEST['action'] || |
| 54 |
! is_string( $_REQUEST['redirect_to'] ) || |
| 55 |
! is_string( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) |
| 56 |
) { |
| 57 |
return $hosts; |
| 58 |
} |
| 59 |
|
| 60 |
// phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- compared against an HMAC, never output. |
| 61 |
$redirect = wp_unslash( $_REQUEST['redirect_to'] ); |
| 62 |
$signature = sanitize_text_field( wp_unslash( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) ); |
| 63 |
// phpcs:enable WordPress.Security.NonceVerification.Recommended |
| 64 |
|
| 65 |
if ( ! hash_equals( self::sign_redirect_url( $redirect ), $signature ) ) { |
| 66 |
return $hosts; |
| 67 |
} |
| 68 |
|
| 69 |
$host = wp_parse_url( $redirect, PHP_URL_HOST ); |
| 70 |
if ( $host ) { |
| 71 |
$hosts[] = $host; |
| 72 |
} |
| 73 |
|
| 74 |
return $hosts; |
| 75 |
} |
| 76 |
|
| 77 |
private static function sign_redirect_url( $url ) { |
| 78 |
return wp_hash( 'ablocks-logout-redirect|' . $url, 'nonce' ); |
| 79 |
} |
| 80 |
|
| 81 |
/** |
| 82 |
* Normalize the configured custom URL, falling back to the home URL for an |
| 83 |
* empty, non-HTTP(S) or malformed value. |
| 84 |
* |
| 85 |
* @param string $url Configured URL. |
| 86 |
* @return string |
| 87 |
*/ |
| 88 |
private static function sanitize_custom_redirect_url( $url ) { |
| 89 |
$url = esc_url_raw( trim( (string) $url ), array( 'http', 'https' ) ); |
| 90 |
if ( '' === $url ) { |
| 91 |
return home_url(); |
| 92 |
} |
| 93 |
|
| 94 |
$parts = wp_parse_url( $url ); |
| 95 |
if ( false === $parts ) { |
| 96 |
return home_url(); |
| 97 |
} |
| 98 |
|
| 99 |
// esc_url_raw() turns bare text such as "not a url" into "http://notaurl"; |
| 100 |
// a real destination is either this site's host or a dotted domain name. |
| 101 |
if ( isset( $parts['host'] ) ) { |
| 102 |
$home_host = wp_parse_url( home_url(), PHP_URL_HOST ); |
| 103 |
if ( $parts['host'] !== $home_host && false === strpos( $parts['host'], '.' ) ) { |
| 104 |
return home_url(); |
| 105 |
} |
| 106 |
} |
| 107 |
|
| 108 |
return $url; |
| 109 |
} |
| 110 |
|
| 111 |
public function build_css( $attributes ) { |
| 112 |
$css_generator = new CssGeneratorV2( $attributes, $this->block_name ); |
| 113 |
|
| 114 |
$css_generator->add_class_styles( |
| 115 |
'{{WRAPPER}} .ablocks-block-logout__label', |
| 116 |
$this->get_log_out_label_color( $attributes ) |
| 117 |
); |
| 118 |
|
| 119 |
$css_generator->add_class_styles( |
| 120 |
'{{WRAPPER}} .ablocks-block-logout', |
| 121 |
$this->get_log_out_css( $attributes ), |
| 122 |
$this->get_log_out_css( $attributes, 'Tablet' ), |
| 123 |
$this->get_log_out_css( $attributes, 'Mobile' ), |
| 124 |
$css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_log_out_css( $attributes, $device ); } ) |
| 125 |
); |
| 126 |
$css_generator->add_class_styles( |
| 127 |
'{{WRAPPER}} .ablocks-block-logout__name', |
| 128 |
$this->get_name_css( $attributes ) |
| 129 |
); |
| 130 |
|
| 131 |
$css_generator->add_class_styles( |
| 132 |
'{{WRAPPER}} .ablocks-block-logout__avatar', |
| 133 |
$this->get_avatar_css( $attributes ), |
| 134 |
$this->get_avatar_css( $attributes, 'Tablet' ), |
| 135 |
$this->get_avatar_css( $attributes, 'Mobile' ), |
| 136 |
$css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_css( $attributes, $device ); } ) |
| 137 |
); |
| 138 |
$css_generator->add_class_styles( |
| 139 |
'{{WRAPPER}} .ablocks-block-logout__avatar:hover', |
| 140 |
$this->get_avatar_border_hover_css( $attributes ), |
| 141 |
$this->get_avatar_border_hover_css( $attributes, 'Tablet' ), |
| 142 |
$this->get_avatar_border_hover_css( $attributes, 'Mobile' ), |
| 143 |
$css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_border_hover_css( $attributes, $device ); } ) |
| 144 |
); |
| 145 |
|
| 146 |
return $css_generator->generate_css(); |
| 147 |
} |
| 148 |
|
| 149 |
public function get_log_out_label_color( $attributes, $device = '' ) { |
| 150 |
$typography = isset( $attributes['labelTypography'] ) ? $attributes['labelTypography'] : ''; |
| 151 |
$text_stroke = isset( $attributes['labelTextStroke'] ) ? $attributes['labelTextStroke'] : ''; |
| 152 |
$text_shadow = isset( $attributes['labelTextShadow'] ) ? $attributes['labelTextShadow'] : ''; |
| 153 |
$typographyglobal = ! empty( $attributes['labelTypographyGlobal'] ) ? $attributes['labelTypographyGlobal'] : array(); |
| 154 |
return array_merge( |
| 155 |
[ 'color' => Color::get_css( isset( $attributes['logOutLabelColor'] ) ? $attributes['logOutLabelColor'] : '' ) ], |
| 156 |
[ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ], |
| 157 |
Typography::get_css( $typography, '', $device, $typographyglobal ), |
| 158 |
TextStroke::get_css( $text_stroke, '', $device ), |
| 159 |
TextShadow::get_css( $text_shadow, '', $device ), |
| 160 |
); |
| 161 |
} |
| 162 |
|
| 163 |
public function get_log_out_css( $attributes, $device = '' ) { |
| 164 |
$log_out_css = []; |
| 165 |
if ( ! empty( $attributes['direction'][ 'value' . $device ] ) ) { |
| 166 |
$log_out_css['flex-direction'] = $attributes['direction'][ 'value' . $device ]; |
| 167 |
} |
| 168 |
|
| 169 |
if ( isset( $attributes['labelAlignment'][ 'value' . $device ] ) ) { |
| 170 |
$log_out_css['justify-content'] = $attributes['labelAlignment'][ 'value' . $device ]; |
| 171 |
} |
| 172 |
|
| 173 |
return array_merge( |
| 174 |
[ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ], |
| 175 |
$log_out_css |
| 176 |
); |
| 177 |
} |
| 178 |
|
| 179 |
|
| 180 |
public function get_avatar_css( $attributes, $device = '' ) { |
| 181 |
|
| 182 |
return array_merge( |
| 183 |
Range::get_css([ |
| 184 |
'attributeValue' => $attributes['avatarWidth'], |
| 185 |
'attribute_object_key' => 'value', |
| 186 |
'isResponsive' => true, |
| 187 |
'defaultValue' => 40, |
| 188 |
'hasUnit' => true, |
| 189 |
'unitDefaultValue' => 'px', |
| 190 |
'property' => 'width', |
| 191 |
'device' => $device, |
| 192 |
]), |
| 193 |
Range::get_css([ |
| 194 |
'attributeValue' => $attributes['avatarHeight'], |
| 195 |
'attribute_object_key' => 'value', |
| 196 |
'isResponsive' => true, |
| 197 |
'defaultValue' => 40, |
| 198 |
'hasUnit' => true, |
| 199 |
'unitDefaultValue' => 'px', |
| 200 |
'property' => 'height', |
| 201 |
'device' => $device, |
| 202 |
]), |
| 203 |
isset( $attributes['avatarBorder'] ) ? Border::get_css( $attributes['avatarBorder'], '', $device ) : [], |
| 204 |
); |
| 205 |
} |
| 206 |
|
| 207 |
public function get_avatar_border_hover_css( $attributes, $device = '' ) { |
| 208 |
return array_merge( |
| 209 |
isset( $attributes['avatarBorder'] ) ? Border::get_hover_css( $attributes['avatarBorder'], '', $device ) : [] |
| 210 |
); |
| 211 |
} |
| 212 |
|
| 213 |
public function get_name_css( $attributes, $device = '' ) { |
| 214 |
$typography = isset( $attributes['nameTypography'] ) ? $attributes['nameTypography'] : ''; |
| 215 |
$text_stroke = isset( $attributes['nameTextStroke'] ) ? $attributes['nameTextStroke'] : ''; |
| 216 |
$text_shadow = isset( $attributes['nameTextShadow'] ) ? $attributes['nameTextShadow'] : ''; |
| 217 |
$typographyglobal = ! empty( $attributes['nameTypographyGlobal'] ) ? $attributes['nameTypographyGlobal'] : array(); |
| 218 |
return array_merge( |
| 219 |
[ 'color' => Color::get_css( isset( $attributes['nameColor'] ) ? $attributes['nameColor'] : '' ) ], |
| 220 |
Typography::get_css( $typography, '', $device, $typographyglobal ), |
| 221 |
TextStroke::get_css( $text_stroke, '', $device ), |
| 222 |
TextShadow::get_css( $text_shadow, '', $device ) |
| 223 |
); |
| 224 |
} |
| 225 |
|
| 226 |
public function render_block_content( $attributes, $content, $block_instance ) { |
| 227 |
$logout_redirect_option = isset( $attributes['logoutRedirect'] ) ? $attributes['logoutRedirect'] : 'current-url'; |
| 228 |
|
| 229 |
if ( $logout_redirect_option === 'current-url' ) { |
| 230 |
// phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash |
| 231 |
$logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] ); |
| 232 |
} elseif ( $logout_redirect_option === 'custom-url' ) { |
| 233 |
$logout_redirect_url = self::sanitize_custom_redirect_url( isset( $attributes['logoutCustomUrl'] ) ? $attributes['logoutCustomUrl'] : '' ); |
| 234 |
} |
| 235 |
|
| 236 |
$login_redirect_option = isset( $attributes['loginRedirect'] ) ? $attributes['loginRedirect'] : 'current-url'; |
| 237 |
|
| 238 |
if ( $login_redirect_option === 'current-url' ) { |
| 239 |
// phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash |
| 240 |
$login_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] ); |
| 241 |
} elseif ( $login_redirect_option === 'custom-url' ) { |
| 242 |
$login_redirect_url = isset( $attributes['loginCustomUrl'] ) && ! empty( $attributes['loginCustomUrl'] ) |
| 243 |
? esc_url( $attributes['loginCustomUrl'] ) |
| 244 |
: home_url(); |
| 245 |
} |
| 246 |
|
| 247 |
$current_user = wp_get_current_user(); |
| 248 |
$profile_picture = esc_url( get_avatar_url( $current_user->ID ) ); |
| 249 |
$display_name = sanitize_text_field( $current_user->display_name ); |
| 250 |
|
| 251 |
$button_icon_url = isset( $attributes['buttonIconUrl'] ) && ! empty( $attributes['buttonIconUrl'] ) |
| 252 |
? esc_url( $attributes['buttonIconUrl'] ) |
| 253 |
: ''; |
| 254 |
|
| 255 |
$button_class = isset( $attributes['buttonClass'] ) ? sanitize_html_class( $attributes['buttonClass'] ) : 'ablocks-block-logout__label'; |
| 256 |
$is_logged_in = is_user_logged_in(); |
| 257 |
$is_show_avatar = isset( $attributes['isShowAvatar'] ) && $attributes['isShowAvatar']; |
| 258 |
$is_show_name = isset( $attributes['isShowName'] ) && $attributes['isShowName']; |
| 259 |
|
| 260 |
$button_text = $is_logged_in |
| 261 |
? ( isset( $attributes['logOutLabel'] ) ? sanitize_text_field( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) ) |
| 262 |
: ( isset( $attributes['logInLabel'] ) ? sanitize_text_field( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) ); |
| 263 |
|
| 264 |
$action_url = $is_logged_in ? wp_logout_url( $logout_redirect_url ) : wp_login_url( $login_redirect_url ); |
| 265 |
|
| 266 |
if ( $is_logged_in && 'custom-url' === $logout_redirect_option ) { |
| 267 |
// wp_logout_url() returns an HTML-escaped URL; decode it before adding |
| 268 |
// the arg, the anchor below escapes it again. |
| 269 |
$action_url = add_query_arg( |
| 270 |
self::REDIRECT_SIGNATURE_ARG, |
| 271 |
self::sign_redirect_url( $logout_redirect_url ), |
| 272 |
html_entity_decode( $action_url, ENT_QUOTES ) |
| 273 |
); |
| 274 |
} |
| 275 |
|
| 276 |
ob_start(); |
| 277 |
?> |
| 278 |
<div class="ablocks-block-logout"> |
| 279 |
<?php if ( $is_logged_in && $is_show_avatar ) : ?> |
| 280 |
<img |
| 281 |
src="<?php echo esc_url( $profile_picture ); ?>" |
| 282 |
alt="<?php echo esc_attr( $display_name ); ?>" |
| 283 |
class="ablocks-block-logout__avatar" |
| 284 |
/> |
| 285 |
<?php endif; ?> |
| 286 |
<?php if ( $is_logged_in && $is_show_name ) : ?> |
| 287 |
<span class="ablocks-block-logout__name"><?php echo esc_html( $display_name ); ?></span> |
| 288 |
<?php endif; ?> |
| 289 |
<a href="<?php echo esc_url( $action_url ); ?>" class="<?php echo esc_attr( $button_class ); ?>"> |
| 290 |
(<span><?php echo esc_html( $button_text ); ?></span>) |
| 291 |
</a> |
| 292 |
</div> |
| 293 |
<?php |
| 294 |
|
| 295 |
return ob_get_clean(); |
| 296 |
} |
| 297 |
|
| 298 |
|
| 299 |
} |
| 300 |
|