PluginProbe
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder / 2.15.0
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder v2.15.0
2.15.0 2.14.0 2.13.0 2.13.1 2.12.0 2.11.1 2.11.0 2.10.0 2.9.0 2.7.4 2.7.5 2.7.6 2.7.7 2.8.0 2.8.1 2.9.1 trunk 1.0 1.0-beta1 1.0-beta2 1.0-beta3 1.0.1 1.0.2 1.0.3 1.1.0 All 82 releases
← All changes | includes/blocks/logout/block.php +139 -70 2.9.1 → 2.15.0 View file →
@@ -5,9 +5,9 @@
5 5 exit;
6 6 }
7 7
8 8 use ABlocks\Classes\BlockBaseAbstract;
9 -use ABlocks\Classes\CssGenerator;
9 +use ABlocks\Classes\CssGeneratorV2;
10 10 use ABlocks\Controls\Alignment;
11 11 use ABlocks\Controls\Range;
12 12 use ABlocks\Controls\Border;
13 13 use ABlocks\Controls\Typography;
@@ -12,18 +12,106 @@
12 12 use ABlocks\Controls\Border;
13 13 use ABlocks\Controls\Typography;
14 14 use ABlocks\Controls\TextShadow;
15 15 use ABlocks\Controls\TextStroke;
16 +use ABlocks\Controls\Color;
16 17
17 18
18 19 class Block extends BlockBaseAbstract {
19 20 protected $block_name = 'logout';
20 21
22 + /**
23 + * Query arg carrying the signature of a block-issued logout redirect URL.
24 + */
25 + const REDIRECT_SIGNATURE_ARG = 'ablocks_rs';
26 +
27 + public function __construct( $keep_silent = false ) {
28 + parent::__construct( $keep_silent );
29 +
30 + if ( $this->is_enabled_block() && ! $keep_silent ) {
31 + add_filter( 'allowed_redirect_hosts', array( $this, 'allow_signed_logout_redirect_host' ) );
32 + }
33 + }
34 +
35 + /**
36 + * wp-login.php ends a logout with wp_safe_redirect(), which swaps any host
37 + * outside `allowed_redirect_hosts` for admin_url() — so a custom URL on
38 + * another domain never took effect. Allow that host for this one request,
39 + * and only when the redirect carries a signature this block produced from
40 + * the site's secret salts: a hand-made or edited `redirect_to` stays
41 + * rejected, so this is not an open redirect.
42 + *
43 + * @param string[] $hosts Allowed hosts.
44 + * @return string[]
45 + */
46 + public function allow_signed_logout_redirect_host( $hosts ) {
47 + global $pagenow;
48 +
49 + // phpcs:disable WordPress.Security.NonceVerification.Recommended -- wp-login.php verifies the log-out nonce itself; this only reads the redirect target.
50 + if (
51 + 'wp-login.php' !== $pagenow ||
52 + ! isset( $_REQUEST['action'], $_REQUEST['redirect_to'], $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) ||
53 + 'logout' !== $_REQUEST['action'] ||
54 + ! is_string( $_REQUEST['redirect_to'] ) ||
55 + ! is_string( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] )
56 + ) {
57 + return $hosts;
58 + }
59 +
60 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- compared against an HMAC, never output.
61 + $redirect = wp_unslash( $_REQUEST['redirect_to'] );
62 + $signature = sanitize_text_field( wp_unslash( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) );
63 + // phpcs:enable WordPress.Security.NonceVerification.Recommended
64 +
65 + if ( ! hash_equals( self::sign_redirect_url( $redirect ), $signature ) ) {
66 + return $hosts;
67 + }
68 +
69 + $host = wp_parse_url( $redirect, PHP_URL_HOST );
70 + if ( $host ) {
71 + $hosts[] = $host;
72 + }
73 +
74 + return $hosts;
75 + }
76 +
77 + private static function sign_redirect_url( $url ) {
78 + return wp_hash( 'ablocks-logout-redirect|' . $url, 'nonce' );
79 + }
80 +
81 + /**
82 + * Normalize the configured custom URL, falling back to the home URL for an
83 + * empty, non-HTTP(S) or malformed value.
84 + *
85 + * @param string $url Configured URL.
86 + * @return string
87 + */
88 + private static function sanitize_custom_redirect_url( $url ) {
89 + $url = esc_url_raw( trim( (string) $url ), array( 'http', 'https' ) );
90 + if ( '' === $url ) {
91 + return home_url();
92 + }
93 +
94 + $parts = wp_parse_url( $url );
95 + if ( false === $parts ) {
96 + return home_url();
97 + }
98 +
99 + // esc_url_raw() turns bare text such as "not a url" into "http://notaurl";
100 + // a real destination is either this site's host or a dotted domain name.
101 + if ( isset( $parts['host'] ) ) {
102 + $home_host = wp_parse_url( home_url(), PHP_URL_HOST );
103 + if ( $parts['host'] !== $home_host && false === strpos( $parts['host'], '.' ) ) {
104 + return home_url();
105 + }
106 + }
107 +
108 + return $url;
109 + }
110 +
21 111 public function build_css( $attributes ) {
112 + $css_generator = new CssGeneratorV2( $attributes, $this->block_name );
22 113
23 - // Generate CSS start
24 - $css_generator = new CssGenerator( $attributes, $this->block_name );
25 -
26 114 $css_generator->add_class_styles(
27 115 '{{WRAPPER}} .ablocks-block-logout__label',
28 116 $this->get_log_out_label_color( $attributes )
29 117 );
@@ -31,13 +119,14 @@
31 119 $css_generator->add_class_styles(
32 120 '{{WRAPPER}} .ablocks-block-logout',
33 121 $this->get_log_out_css( $attributes ),
34 122 $this->get_log_out_css( $attributes, 'Tablet' ),
35 - $this->get_log_out_css( $attributes, 'Mobile' )
123 + $this->get_log_out_css( $attributes, 'Mobile' ),
124 + $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_log_out_css( $attributes, $device ); } )
36 125 );
37 126 $css_generator->add_class_styles(
38 127 '{{WRAPPER}} .ablocks-block-logout__name',
39 - $this->get_name_css( $attributes ),
128 + $this->get_name_css( $attributes )
40 129 );
41 130
42 131 $css_generator->add_class_styles(
43 132 '{{WRAPPER}} .ablocks-block-logout__avatar',
@@ -42,48 +131,38 @@
42 131 $css_generator->add_class_styles(
43 132 '{{WRAPPER}} .ablocks-block-logout__avatar',
44 133 $this->get_avatar_css( $attributes ),
45 134 $this->get_avatar_css( $attributes, 'Tablet' ),
46 - $this->get_avatar_css( $attributes, 'Mobile' )
135 + $this->get_avatar_css( $attributes, 'Mobile' ),
136 + $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_css( $attributes, $device ); } )
47 137 );
48 138 $css_generator->add_class_styles(
49 139 '{{WRAPPER}} .ablocks-block-logout__avatar:hover',
50 140 $this->get_avatar_border_hover_css( $attributes ),
51 141 $this->get_avatar_border_hover_css( $attributes, 'Tablet' ),
52 - $this->get_avatar_border_hover_css( $attributes, 'Mobile' )
142 + $this->get_avatar_border_hover_css( $attributes, 'Mobile' ),
143 + $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_border_hover_css( $attributes, $device ); } )
53 144 );
54 145
55 146 return $css_generator->generate_css();
56 147 }
57 148
58 -
59 149 public function get_log_out_label_color( $attributes, $device = '' ) {
60 - $log_out_label_color_css = [];
61 - if ( ! empty( $attributes['logOutLabelColor'] ) ) {
62 - $log_out_label_color_css['color'] = $attributes['logOutLabelColor'];
63 - }
64 - if ( ! empty( $attributes['logOutLabelBgColor'] ) ) {
65 - $log_out_label_color_css['background'] = $attributes['logOutLabelBgColor'];
66 - }
67 -
68 150 $typography = isset( $attributes['labelTypography'] ) ? $attributes['labelTypography'] : '';
69 151 $text_stroke = isset( $attributes['labelTextStroke'] ) ? $attributes['labelTextStroke'] : '';
70 152 $text_shadow = isset( $attributes['labelTextShadow'] ) ? $attributes['labelTextShadow'] : '';
71 -
153 + $typographyglobal = ! empty( $attributes['labelTypographyGlobal'] ) ? $attributes['labelTypographyGlobal'] : array();
72 154 return array_merge(
73 - Typography::get_css( $typography, '', $device ),
155 + [ 'color' => Color::get_css( isset( $attributes['logOutLabelColor'] ) ? $attributes['logOutLabelColor'] : '' ) ],
156 + [ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ],
157 + Typography::get_css( $typography, '', $device, $typographyglobal ),
74 158 TextStroke::get_css( $text_stroke, '', $device ),
75 159 TextShadow::get_css( $text_shadow, '', $device ),
76 - $log_out_label_color_css
77 160 );
78 161 }
79 162
80 163 public function get_log_out_css( $attributes, $device = '' ) {
81 164 $log_out_css = [];
82 -
83 - if ( ! empty( $attributes['logOutLabelBgColor'] ) ) {
84 - $log_out_css ['background'] = $attributes['logOutLabelBgColor'];
85 - }
86 165 if ( ! empty( $attributes['direction'][ 'value' . $device ] ) ) {
87 166 $log_out_css['flex-direction'] = $attributes['direction'][ 'value' . $device ];
88 167 }
89 168
@@ -90,30 +169,17 @@
90 169 if ( isset( $attributes['labelAlignment'][ 'value' . $device ] ) ) {
91 170 $log_out_css['justify-content'] = $attributes['labelAlignment'][ 'value' . $device ];
92 171 }
93 172
94 - return $log_out_css;
173 + return array_merge(
174 + [ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ],
175 + $log_out_css
176 + );
95 177 }
96 178
97 179
98 180 public function get_avatar_css( $attributes, $device = '' ) {
99 - $avatar_css = [];
100 181
101 - if ( ! empty( $attributes['avatarWidth'][ 'value' . $device ] ) ) {
102 - $width_value = $attributes['avatarWidth'][ 'value' . $device ];
103 - $width_unit = $attributes['avatarWidth'][ 'valueUnit' . $device ] ?? 'px';
104 - $avatar_css['width'] = $width_value . $width_unit;
105 - }
106 -
107 - if ( ! empty( $attributes['avatarHeight'][ 'value' . $device ] ) ) {
108 - $height_value = $attributes['avatarHeight'][ 'value' . $device ];
109 - $height_unit = ! empty( $attributes['avatarHeight'][ 'valueUnit' . $device ] )
110 - ? $attributes['avatarHeight'][ 'valueUnit' . $device ]
111 - : 'px';
112 -
113 - $avatar_css['height'] = $height_value . $height_unit;
114 - }
115 -
116 182 return array_merge(
117 183 Range::get_css([
118 184 'attributeValue' => $attributes['avatarWidth'],
119 185 'attribute_object_key' => 'value',
@@ -134,9 +200,8 @@
134 200 'property' => 'height',
135 201 'device' => $device,
136 202 ]),
137 203 isset( $attributes['avatarBorder'] ) ? Border::get_css( $attributes['avatarBorder'], '', $device ) : [],
138 - $avatar_css,
139 204 );
140 205 }
141 206
142 207 public function get_avatar_border_hover_css( $attributes, $device = '' ) {
@@ -145,42 +210,35 @@
145 210 );
146 211 }
147 212
148 213 public function get_name_css( $attributes, $device = '' ) {
149 - $name_css = [];
150 -
151 - if ( ! empty( $attributes['nameColor'] ) ) {
152 - $name_css ['color'] = $attributes['nameColor'];
153 - }
154 214 $typography = isset( $attributes['nameTypography'] ) ? $attributes['nameTypography'] : '';
155 215 $text_stroke = isset( $attributes['nameTextStroke'] ) ? $attributes['nameTextStroke'] : '';
156 216 $text_shadow = isset( $attributes['nameTextShadow'] ) ? $attributes['nameTextShadow'] : '';
157 -
217 + $typographyglobal = ! empty( $attributes['nameTypographyGlobal'] ) ? $attributes['nameTypographyGlobal'] : array();
158 218 return array_merge(
159 - Typography::get_css( $typography, '', $device ),
219 + [ 'color' => Color::get_css( isset( $attributes['nameColor'] ) ? $attributes['nameColor'] : '' ) ],
220 + Typography::get_css( $typography, '', $device, $typographyglobal ),
160 221 TextStroke::get_css( $text_stroke, '', $device ),
161 - TextShadow::get_css( $text_shadow, '', $device ),
162 - $name_css
222 + TextShadow::get_css( $text_shadow, '', $device )
163 223 );
164 224 }
165 225
166 -
167 -
168 226 public function render_block_content( $attributes, $content, $block_instance ) {
169 227 $logout_redirect_option = isset( $attributes['logoutRedirect'] ) ? $attributes['logoutRedirect'] : 'current-url';
170 228
171 229 if ( $logout_redirect_option === 'current-url' ) {
172 - $logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
230 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
231 + $logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] );
173 232 } elseif ( $logout_redirect_option === 'custom-url' ) {
174 - $logout_redirect_url = isset( $attributes['logoutCustomUrl'] ) && ! empty( $attributes['logoutCustomUrl'] )
175 - ? esc_url( $attributes['logoutCustomUrl'] )
176 - : home_url();
233 + $logout_redirect_url = self::sanitize_custom_redirect_url( isset( $attributes['logoutCustomUrl'] ) ? $attributes['logoutCustomUrl'] : '' );
177 234 }
178 235
179 236 $login_redirect_option = isset( $attributes['loginRedirect'] ) ? $attributes['loginRedirect'] : 'current-url';
180 237
181 238 if ( $login_redirect_option === 'current-url' ) {
182 - $login_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
239 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
240 + $login_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] );
183 241 } elseif ( $login_redirect_option === 'custom-url' ) {
184 242 $login_redirect_url = isset( $attributes['loginCustomUrl'] ) && ! empty( $attributes['loginCustomUrl'] )
185 243 ? esc_url( $attributes['loginCustomUrl'] )
186 244 : home_url();
@@ -186,45 +244,56 @@
186 244 : home_url();
187 245 }
188 246
189 247 $current_user = wp_get_current_user();
190 - $profile_picture = get_avatar_url( $current_user->ID );
191 - $display_name = $current_user->display_name;
248 + $profile_picture = esc_url( get_avatar_url( $current_user->ID ) );
249 + $display_name = sanitize_text_field( $current_user->display_name );
192 250
193 251 $button_icon_url = isset( $attributes['buttonIconUrl'] ) && ! empty( $attributes['buttonIconUrl'] )
194 252 ? esc_url( $attributes['buttonIconUrl'] )
195 253 : '';
196 254
197 - $button_class = isset( $attributes['buttonClass'] ) ? esc_attr( $attributes['buttonClass'] ) : 'ablocks-block-logout__label';
255 + $button_class = isset( $attributes['buttonClass'] ) ? sanitize_html_class( $attributes['buttonClass'] ) : 'ablocks-block-logout__label';
198 256 $is_logged_in = is_user_logged_in();
199 257 $is_show_avatar = isset( $attributes['isShowAvatar'] ) && $attributes['isShowAvatar'];
200 258 $is_show_name = isset( $attributes['isShowName'] ) && $attributes['isShowName'];
201 259
202 260 $button_text = $is_logged_in
203 - ? ( isset( $attributes['logOutLabel'] ) ? esc_html( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) )
204 - : ( isset( $attributes['logInLabel'] ) ? esc_html( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) );
261 + ? ( isset( $attributes['logOutLabel'] ) ? sanitize_text_field( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) )
262 + : ( isset( $attributes['logInLabel'] ) ? sanitize_text_field( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) );
205 263
206 264 $action_url = $is_logged_in ? wp_logout_url( $logout_redirect_url ) : wp_login_url( $login_redirect_url );
207 265
266 + if ( $is_logged_in && 'custom-url' === $logout_redirect_option ) {
267 + // wp_logout_url() returns an HTML-escaped URL; decode it before adding
268 + // the arg, the anchor below escapes it again.
269 + $action_url = add_query_arg(
270 + self::REDIRECT_SIGNATURE_ARG,
271 + self::sign_redirect_url( $logout_redirect_url ),
272 + html_entity_decode( $action_url, ENT_QUOTES )
273 + );
274 + }
275 +
208 276 ob_start();
209 277 ?>
210 - <div class="ablocks-block-logout">
278 + <div class="ablocks-block-logout">
211 279 <?php if ( $is_logged_in && $is_show_avatar ) : ?>
212 - <img
213 - src="<?php echo esc_url( $profile_picture ); ?>"
214 - alt="<?php echo esc_attr( $display_name ); ?>"
215 - class="ablocks-block-logout__avatar"
280 + <img
281 + src="<?php echo esc_url( $profile_picture ); ?>"
282 + alt="<?php echo esc_attr( $display_name ); ?>"
283 + class="ablocks-block-logout__avatar"
216 284 />
217 285 <?php endif; ?>
218 286 <?php if ( $is_logged_in && $is_show_name ) : ?>
219 287 <span class="ablocks-block-logout__name"><?php echo esc_html( $display_name ); ?></span>
220 - <?php endif; ?>
288 + <?php endif; ?>
221 289 <a href="<?php echo esc_url( $action_url ); ?>" class="<?php echo esc_attr( $button_class ); ?>">
222 290 (<span><?php echo esc_html( $button_text ); ?></span>)
223 291 </a>
224 - </div>
292 + </div>
225 293 <?php
226 294
227 295 return ob_get_clean();
228 296 }
297 +
229 298
230 299 }