PluginProbe
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder / 2.15.0
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder v2.15.0
2.15.0 2.14.0 2.13.0 2.13.1 2.12.0 2.11.1 2.11.0 2.10.0 2.9.0 2.7.4 2.7.5 2.7.6 2.7.7 2.8.0 2.8.1 2.9.1 trunk 1.0 1.0-beta1 1.0-beta2 1.0-beta3 1.0.1 1.0.2 1.0.3 1.1.0 All 82 releases
ablocks / includes / blocks / logout / block.php

block.php in aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder 2.15.0, at includes/blocks/logout/block.php

300 lines 11.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 namespace ABlocks\Blocks\Logout;
3
4 if ( ! defined( 'ABSPATH' ) ) {
5 exit;
6 }
7
8 use ABlocks\Classes\BlockBaseAbstract;
9 use ABlocks\Classes\CssGeneratorV2;
10 use ABlocks\Controls\Alignment;
11 use ABlocks\Controls\Range;
12 use ABlocks\Controls\Border;
13 use ABlocks\Controls\Typography;
14 use ABlocks\Controls\TextShadow;
15 use ABlocks\Controls\TextStroke;
16 use ABlocks\Controls\Color;
17
18
19 class Block extends BlockBaseAbstract {
20 protected $block_name = 'logout';
21
22 /**
23 * Query arg carrying the signature of a block-issued logout redirect URL.
24 */
25 const REDIRECT_SIGNATURE_ARG = 'ablocks_rs';
26
27 public function __construct( $keep_silent = false ) {
28 parent::__construct( $keep_silent );
29
30 if ( $this->is_enabled_block() && ! $keep_silent ) {
31 add_filter( 'allowed_redirect_hosts', array( $this, 'allow_signed_logout_redirect_host' ) );
32 }
33 }
34
35 /**
36 * wp-login.php ends a logout with wp_safe_redirect(), which swaps any host
37 * outside `allowed_redirect_hosts` for admin_url() — so a custom URL on
38 * another domain never took effect. Allow that host for this one request,
39 * and only when the redirect carries a signature this block produced from
40 * the site's secret salts: a hand-made or edited `redirect_to` stays
41 * rejected, so this is not an open redirect.
42 *
43 * @param string[] $hosts Allowed hosts.
44 * @return string[]
45 */
46 public function allow_signed_logout_redirect_host( $hosts ) {
47 global $pagenow;
48
49 // phpcs:disable WordPress.Security.NonceVerification.Recommended -- wp-login.php verifies the log-out nonce itself; this only reads the redirect target.
50 if (
51 'wp-login.php' !== $pagenow ||
52 ! isset( $_REQUEST['action'], $_REQUEST['redirect_to'], $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) ||
53 'logout' !== $_REQUEST['action'] ||
54 ! is_string( $_REQUEST['redirect_to'] ) ||
55 ! is_string( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] )
56 ) {
57 return $hosts;
58 }
59
60 // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- compared against an HMAC, never output.
61 $redirect = wp_unslash( $_REQUEST['redirect_to'] );
62 $signature = sanitize_text_field( wp_unslash( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) );
63 // phpcs:enable WordPress.Security.NonceVerification.Recommended
64
65 if ( ! hash_equals( self::sign_redirect_url( $redirect ), $signature ) ) {
66 return $hosts;
67 }
68
69 $host = wp_parse_url( $redirect, PHP_URL_HOST );
70 if ( $host ) {
71 $hosts[] = $host;
72 }
73
74 return $hosts;
75 }
76
77 private static function sign_redirect_url( $url ) {
78 return wp_hash( 'ablocks-logout-redirect|' . $url, 'nonce' );
79 }
80
81 /**
82 * Normalize the configured custom URL, falling back to the home URL for an
83 * empty, non-HTTP(S) or malformed value.
84 *
85 * @param string $url Configured URL.
86 * @return string
87 */
88 private static function sanitize_custom_redirect_url( $url ) {
89 $url = esc_url_raw( trim( (string) $url ), array( 'http', 'https' ) );
90 if ( '' === $url ) {
91 return home_url();
92 }
93
94 $parts = wp_parse_url( $url );
95 if ( false === $parts ) {
96 return home_url();
97 }
98
99 // esc_url_raw() turns bare text such as "not a url" into "http://notaurl";
100 // a real destination is either this site's host or a dotted domain name.
101 if ( isset( $parts['host'] ) ) {
102 $home_host = wp_parse_url( home_url(), PHP_URL_HOST );
103 if ( $parts['host'] !== $home_host && false === strpos( $parts['host'], '.' ) ) {
104 return home_url();
105 }
106 }
107
108 return $url;
109 }
110
111 public function build_css( $attributes ) {
112 $css_generator = new CssGeneratorV2( $attributes, $this->block_name );
113
114 $css_generator->add_class_styles(
115 '{{WRAPPER}} .ablocks-block-logout__label',
116 $this->get_log_out_label_color( $attributes )
117 );
118
119 $css_generator->add_class_styles(
120 '{{WRAPPER}} .ablocks-block-logout',
121 $this->get_log_out_css( $attributes ),
122 $this->get_log_out_css( $attributes, 'Tablet' ),
123 $this->get_log_out_css( $attributes, 'Mobile' ),
124 $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_log_out_css( $attributes, $device ); } )
125 );
126 $css_generator->add_class_styles(
127 '{{WRAPPER}} .ablocks-block-logout__name',
128 $this->get_name_css( $attributes )
129 );
130
131 $css_generator->add_class_styles(
132 '{{WRAPPER}} .ablocks-block-logout__avatar',
133 $this->get_avatar_css( $attributes ),
134 $this->get_avatar_css( $attributes, 'Tablet' ),
135 $this->get_avatar_css( $attributes, 'Mobile' ),
136 $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_css( $attributes, $device ); } )
137 );
138 $css_generator->add_class_styles(
139 '{{WRAPPER}} .ablocks-block-logout__avatar:hover',
140 $this->get_avatar_border_hover_css( $attributes ),
141 $this->get_avatar_border_hover_css( $attributes, 'Tablet' ),
142 $this->get_avatar_border_hover_css( $attributes, 'Mobile' ),
143 $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_border_hover_css( $attributes, $device ); } )
144 );
145
146 return $css_generator->generate_css();
147 }
148
149 public function get_log_out_label_color( $attributes, $device = '' ) {
150 $typography = isset( $attributes['labelTypography'] ) ? $attributes['labelTypography'] : '';
151 $text_stroke = isset( $attributes['labelTextStroke'] ) ? $attributes['labelTextStroke'] : '';
152 $text_shadow = isset( $attributes['labelTextShadow'] ) ? $attributes['labelTextShadow'] : '';
153 $typographyglobal = ! empty( $attributes['labelTypographyGlobal'] ) ? $attributes['labelTypographyGlobal'] : array();
154 return array_merge(
155 [ 'color' => Color::get_css( isset( $attributes['logOutLabelColor'] ) ? $attributes['logOutLabelColor'] : '' ) ],
156 [ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ],
157 Typography::get_css( $typography, '', $device, $typographyglobal ),
158 TextStroke::get_css( $text_stroke, '', $device ),
159 TextShadow::get_css( $text_shadow, '', $device ),
160 );
161 }
162
163 public function get_log_out_css( $attributes, $device = '' ) {
164 $log_out_css = [];
165 if ( ! empty( $attributes['direction'][ 'value' . $device ] ) ) {
166 $log_out_css['flex-direction'] = $attributes['direction'][ 'value' . $device ];
167 }
168
169 if ( isset( $attributes['labelAlignment'][ 'value' . $device ] ) ) {
170 $log_out_css['justify-content'] = $attributes['labelAlignment'][ 'value' . $device ];
171 }
172
173 return array_merge(
174 [ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ],
175 $log_out_css
176 );
177 }
178
179
180 public function get_avatar_css( $attributes, $device = '' ) {
181
182 return array_merge(
183 Range::get_css([
184 'attributeValue' => $attributes['avatarWidth'],
185 'attribute_object_key' => 'value',
186 'isResponsive' => true,
187 'defaultValue' => 40,
188 'hasUnit' => true,
189 'unitDefaultValue' => 'px',
190 'property' => 'width',
191 'device' => $device,
192 ]),
193 Range::get_css([
194 'attributeValue' => $attributes['avatarHeight'],
195 'attribute_object_key' => 'value',
196 'isResponsive' => true,
197 'defaultValue' => 40,
198 'hasUnit' => true,
199 'unitDefaultValue' => 'px',
200 'property' => 'height',
201 'device' => $device,
202 ]),
203 isset( $attributes['avatarBorder'] ) ? Border::get_css( $attributes['avatarBorder'], '', $device ) : [],
204 );
205 }
206
207 public function get_avatar_border_hover_css( $attributes, $device = '' ) {
208 return array_merge(
209 isset( $attributes['avatarBorder'] ) ? Border::get_hover_css( $attributes['avatarBorder'], '', $device ) : []
210 );
211 }
212
213 public function get_name_css( $attributes, $device = '' ) {
214 $typography = isset( $attributes['nameTypography'] ) ? $attributes['nameTypography'] : '';
215 $text_stroke = isset( $attributes['nameTextStroke'] ) ? $attributes['nameTextStroke'] : '';
216 $text_shadow = isset( $attributes['nameTextShadow'] ) ? $attributes['nameTextShadow'] : '';
217 $typographyglobal = ! empty( $attributes['nameTypographyGlobal'] ) ? $attributes['nameTypographyGlobal'] : array();
218 return array_merge(
219 [ 'color' => Color::get_css( isset( $attributes['nameColor'] ) ? $attributes['nameColor'] : '' ) ],
220 Typography::get_css( $typography, '', $device, $typographyglobal ),
221 TextStroke::get_css( $text_stroke, '', $device ),
222 TextShadow::get_css( $text_shadow, '', $device )
223 );
224 }
225
226 public function render_block_content( $attributes, $content, $block_instance ) {
227 $logout_redirect_option = isset( $attributes['logoutRedirect'] ) ? $attributes['logoutRedirect'] : 'current-url';
228
229 if ( $logout_redirect_option === 'current-url' ) {
230 // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
231 $logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] );
232 } elseif ( $logout_redirect_option === 'custom-url' ) {
233 $logout_redirect_url = self::sanitize_custom_redirect_url( isset( $attributes['logoutCustomUrl'] ) ? $attributes['logoutCustomUrl'] : '' );
234 }
235
236 $login_redirect_option = isset( $attributes['loginRedirect'] ) ? $attributes['loginRedirect'] : 'current-url';
237
238 if ( $login_redirect_option === 'current-url' ) {
239 // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
240 $login_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] );
241 } elseif ( $login_redirect_option === 'custom-url' ) {
242 $login_redirect_url = isset( $attributes['loginCustomUrl'] ) && ! empty( $attributes['loginCustomUrl'] )
243 ? esc_url( $attributes['loginCustomUrl'] )
244 : home_url();
245 }
246
247 $current_user = wp_get_current_user();
248 $profile_picture = esc_url( get_avatar_url( $current_user->ID ) );
249 $display_name = sanitize_text_field( $current_user->display_name );
250
251 $button_icon_url = isset( $attributes['buttonIconUrl'] ) && ! empty( $attributes['buttonIconUrl'] )
252 ? esc_url( $attributes['buttonIconUrl'] )
253 : '';
254
255 $button_class = isset( $attributes['buttonClass'] ) ? sanitize_html_class( $attributes['buttonClass'] ) : 'ablocks-block-logout__label';
256 $is_logged_in = is_user_logged_in();
257 $is_show_avatar = isset( $attributes['isShowAvatar'] ) && $attributes['isShowAvatar'];
258 $is_show_name = isset( $attributes['isShowName'] ) && $attributes['isShowName'];
259
260 $button_text = $is_logged_in
261 ? ( isset( $attributes['logOutLabel'] ) ? sanitize_text_field( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) )
262 : ( isset( $attributes['logInLabel'] ) ? sanitize_text_field( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) );
263
264 $action_url = $is_logged_in ? wp_logout_url( $logout_redirect_url ) : wp_login_url( $login_redirect_url );
265
266 if ( $is_logged_in && 'custom-url' === $logout_redirect_option ) {
267 // wp_logout_url() returns an HTML-escaped URL; decode it before adding
268 // the arg, the anchor below escapes it again.
269 $action_url = add_query_arg(
270 self::REDIRECT_SIGNATURE_ARG,
271 self::sign_redirect_url( $logout_redirect_url ),
272 html_entity_decode( $action_url, ENT_QUOTES )
273 );
274 }
275
276 ob_start();
277 ?>
278 <div class="ablocks-block-logout">
279 <?php if ( $is_logged_in && $is_show_avatar ) : ?>
280 <img
281 src="<?php echo esc_url( $profile_picture ); ?>"
282 alt="<?php echo esc_attr( $display_name ); ?>"
283 class="ablocks-block-logout__avatar"
284 />
285 <?php endif; ?>
286 <?php if ( $is_logged_in && $is_show_name ) : ?>
287 <span class="ablocks-block-logout__name"><?php echo esc_html( $display_name ); ?></span>
288 <?php endif; ?>
289 <a href="<?php echo esc_url( $action_url ); ?>" class="<?php echo esc_attr( $button_class ); ?>">
290 (<span><?php echo esc_html( $button_text ); ?></span>)
291 </a>
292 </div>
293 <?php
294
295 return ob_get_clean();
296 }
297
298
299 }
300