| @@ -5,9 +5,9 @@ | ||
| 5 | 5 | exit; |
| 6 | 6 | } |
| 7 | 7 | |
| 8 | 8 | use ABlocks\Classes\BlockBaseAbstract; |
| 9 | -use ABlocks\Classes\CssGenerator; | |
| 9 | +use ABlocks\Classes\CssGeneratorV2; | |
| 10 | 10 | use ABlocks\Controls\Alignment; |
| 11 | 11 | use ABlocks\Controls\Range; |
| 12 | 12 | use ABlocks\Controls\Border; |
| 13 | 13 | use ABlocks\Controls\Typography; |
| @@ -12,18 +12,106 @@ | ||
| 12 | 12 | use ABlocks\Controls\Border; |
| 13 | 13 | use ABlocks\Controls\Typography; |
| 14 | 14 | use ABlocks\Controls\TextShadow; |
| 15 | 15 | use ABlocks\Controls\TextStroke; |
| 16 | +use ABlocks\Controls\Color; | |
| 16 | 17 | |
| 17 | 18 | |
| 18 | 19 | class Block extends BlockBaseAbstract { |
| 19 | 20 | protected $block_name = 'logout'; |
| 20 | 21 | |
| 22 | + /** | |
| 23 | + * Query arg carrying the signature of a block-issued logout redirect URL. | |
| 24 | + */ | |
| 25 | + const REDIRECT_SIGNATURE_ARG = 'ablocks_rs'; | |
| 26 | + | |
| 27 | + public function __construct( $keep_silent = false ) { | |
| 28 | + parent::__construct( $keep_silent ); | |
| 29 | + | |
| 30 | + if ( $this->is_enabled_block() && ! $keep_silent ) { | |
| 31 | + add_filter( 'allowed_redirect_hosts', array( $this, 'allow_signed_logout_redirect_host' ) ); | |
| 32 | + } | |
| 33 | + } | |
| 34 | + | |
| 35 | + /** | |
| 36 | + * wp-login.php ends a logout with wp_safe_redirect(), which swaps any host | |
| 37 | + * outside `allowed_redirect_hosts` for admin_url() — so a custom URL on | |
| 38 | + * another domain never took effect. Allow that host for this one request, | |
| 39 | + * and only when the redirect carries a signature this block produced from | |
| 40 | + * the site's secret salts: a hand-made or edited `redirect_to` stays | |
| 41 | + * rejected, so this is not an open redirect. | |
| 42 | + * | |
| 43 | + * @param string[] $hosts Allowed hosts. | |
| 44 | + * @return string[] | |
| 45 | + */ | |
| 46 | + public function allow_signed_logout_redirect_host( $hosts ) { | |
| 47 | + global $pagenow; | |
| 48 | + | |
| 49 | + // phpcs:disable WordPress.Security.NonceVerification.Recommended -- wp-login.php verifies the log-out nonce itself; this only reads the redirect target. | |
| 50 | + if ( | |
| 51 | + 'wp-login.php' !== $pagenow || | |
| 52 | + ! isset( $_REQUEST['action'], $_REQUEST['redirect_to'], $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) || | |
| 53 | + 'logout' !== $_REQUEST['action'] || | |
| 54 | + ! is_string( $_REQUEST['redirect_to'] ) || | |
| 55 | + ! is_string( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) | |
| 56 | + ) { | |
| 57 | + return $hosts; | |
| 58 | + } | |
| 59 | + | |
| 60 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- compared against an HMAC, never output. | |
| 61 | + $redirect = wp_unslash( $_REQUEST['redirect_to'] ); | |
| 62 | + $signature = sanitize_text_field( wp_unslash( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) ); | |
| 63 | + // phpcs:enable WordPress.Security.NonceVerification.Recommended | |
| 64 | + | |
| 65 | + if ( ! hash_equals( self::sign_redirect_url( $redirect ), $signature ) ) { | |
| 66 | + return $hosts; | |
| 67 | + } | |
| 68 | + | |
| 69 | + $host = wp_parse_url( $redirect, PHP_URL_HOST ); | |
| 70 | + if ( $host ) { | |
| 71 | + $hosts[] = $host; | |
| 72 | + } | |
| 73 | + | |
| 74 | + return $hosts; | |
| 75 | + } | |
| 76 | + | |
| 77 | + private static function sign_redirect_url( $url ) { | |
| 78 | + return wp_hash( 'ablocks-logout-redirect|' . $url, 'nonce' ); | |
| 79 | + } | |
| 80 | + | |
| 81 | + /** | |
| 82 | + * Normalize the configured custom URL, falling back to the home URL for an | |
| 83 | + * empty, non-HTTP(S) or malformed value. | |
| 84 | + * | |
| 85 | + * @param string $url Configured URL. | |
| 86 | + * @return string | |
| 87 | + */ | |
| 88 | + private static function sanitize_custom_redirect_url( $url ) { | |
| 89 | + $url = esc_url_raw( trim( (string) $url ), array( 'http', 'https' ) ); | |
| 90 | + if ( '' === $url ) { | |
| 91 | + return home_url(); | |
| 92 | + } | |
| 93 | + | |
| 94 | + $parts = wp_parse_url( $url ); | |
| 95 | + if ( false === $parts ) { | |
| 96 | + return home_url(); | |
| 97 | + } | |
| 98 | + | |
| 99 | + // esc_url_raw() turns bare text such as "not a url" into "http://notaurl"; | |
| 100 | + // a real destination is either this site's host or a dotted domain name. | |
| 101 | + if ( isset( $parts['host'] ) ) { | |
| 102 | + $home_host = wp_parse_url( home_url(), PHP_URL_HOST ); | |
| 103 | + if ( $parts['host'] !== $home_host && false === strpos( $parts['host'], '.' ) ) { | |
| 104 | + return home_url(); | |
| 105 | + } | |
| 106 | + } | |
| 107 | + | |
| 108 | + return $url; | |
| 109 | + } | |
| 110 | + | |
| 21 | 111 | public function build_css( $attributes ) { |
| 112 | + $css_generator = new CssGeneratorV2( $attributes, $this->block_name ); | |
| 22 | 113 | |
| 23 | - // Generate CSS start | |
| 24 | - $css_generator = new CssGenerator( $attributes, $this->block_name ); | |
| 25 | - | |
| 26 | 114 | $css_generator->add_class_styles( |
| 27 | 115 | '{{WRAPPER}} .ablocks-block-logout__label', |
| 28 | 116 | $this->get_log_out_label_color( $attributes ) |
| 29 | 117 | ); |
| @@ -31,13 +119,14 @@ | ||
| 31 | 119 | $css_generator->add_class_styles( |
| 32 | 120 | '{{WRAPPER}} .ablocks-block-logout', |
| 33 | 121 | $this->get_log_out_css( $attributes ), |
| 34 | 122 | $this->get_log_out_css( $attributes, 'Tablet' ), |
| 35 | - $this->get_log_out_css( $attributes, 'Mobile' ) | |
| 123 | + $this->get_log_out_css( $attributes, 'Mobile' ), | |
| 124 | + $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_log_out_css( $attributes, $device ); } ) | |
| 36 | 125 | ); |
| 37 | 126 | $css_generator->add_class_styles( |
| 38 | 127 | '{{WRAPPER}} .ablocks-block-logout__name', |
| 39 | - $this->get_name_css( $attributes ), | |
| 128 | + $this->get_name_css( $attributes ) | |
| 40 | 129 | ); |
| 41 | 130 | |
| 42 | 131 | $css_generator->add_class_styles( |
| 43 | 132 | '{{WRAPPER}} .ablocks-block-logout__avatar', |
| @@ -42,48 +131,38 @@ | ||
| 42 | 131 | $css_generator->add_class_styles( |
| 43 | 132 | '{{WRAPPER}} .ablocks-block-logout__avatar', |
| 44 | 133 | $this->get_avatar_css( $attributes ), |
| 45 | 134 | $this->get_avatar_css( $attributes, 'Tablet' ), |
| 46 | - $this->get_avatar_css( $attributes, 'Mobile' ) | |
| 135 | + $this->get_avatar_css( $attributes, 'Mobile' ), | |
| 136 | + $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_css( $attributes, $device ); } ) | |
| 47 | 137 | ); |
| 48 | 138 | $css_generator->add_class_styles( |
| 49 | 139 | '{{WRAPPER}} .ablocks-block-logout__avatar:hover', |
| 50 | 140 | $this->get_avatar_border_hover_css( $attributes ), |
| 51 | 141 | $this->get_avatar_border_hover_css( $attributes, 'Tablet' ), |
| 52 | - $this->get_avatar_border_hover_css( $attributes, 'Mobile' ) | |
| 142 | + $this->get_avatar_border_hover_css( $attributes, 'Mobile' ), | |
| 143 | + $css_generator->custom_device_map( function ( $device ) use ( $attributes ) { return $this->get_avatar_border_hover_css( $attributes, $device ); } ) | |
| 53 | 144 | ); |
| 54 | 145 | |
| 55 | 146 | return $css_generator->generate_css(); |
| 56 | 147 | } |
| 57 | 148 | |
| 58 | - | |
| 59 | 149 | public function get_log_out_label_color( $attributes, $device = '' ) { |
| 60 | - $log_out_label_color_css = []; | |
| 61 | - if ( ! empty( $attributes['logOutLabelColor'] ) ) { | |
| 62 | - $log_out_label_color_css['color'] = $attributes['logOutLabelColor']; | |
| 63 | - } | |
| 64 | - if ( ! empty( $attributes['logOutLabelBgColor'] ) ) { | |
| 65 | - $log_out_label_color_css['background'] = $attributes['logOutLabelBgColor']; | |
| 66 | - } | |
| 67 | - | |
| 68 | 150 | $typography = isset( $attributes['labelTypography'] ) ? $attributes['labelTypography'] : ''; |
| 69 | 151 | $text_stroke = isset( $attributes['labelTextStroke'] ) ? $attributes['labelTextStroke'] : ''; |
| 70 | 152 | $text_shadow = isset( $attributes['labelTextShadow'] ) ? $attributes['labelTextShadow'] : ''; |
| 71 | - | |
| 153 | + $typographyglobal = ! empty( $attributes['labelTypographyGlobal'] ) ? $attributes['labelTypographyGlobal'] : array(); | |
| 72 | 154 | return array_merge( |
| 73 | - Typography::get_css( $typography, '', $device ), | |
| 155 | + [ 'color' => Color::get_css( isset( $attributes['logOutLabelColor'] ) ? $attributes['logOutLabelColor'] : '' ) ], | |
| 156 | + [ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ], | |
| 157 | + Typography::get_css( $typography, '', $device, $typographyglobal ), | |
| 74 | 158 | TextStroke::get_css( $text_stroke, '', $device ), |
| 75 | 159 | TextShadow::get_css( $text_shadow, '', $device ), |
| 76 | - $log_out_label_color_css | |
| 77 | 160 | ); |
| 78 | 161 | } |
| 79 | 162 | |
| 80 | 163 | public function get_log_out_css( $attributes, $device = '' ) { |
| 81 | 164 | $log_out_css = []; |
| 82 | - | |
| 83 | - if ( ! empty( $attributes['logOutLabelBgColor'] ) ) { | |
| 84 | - $log_out_css ['background'] = $attributes['logOutLabelBgColor']; | |
| 85 | - } | |
| 86 | 165 | if ( ! empty( $attributes['direction'][ 'value' . $device ] ) ) { |
| 87 | 166 | $log_out_css['flex-direction'] = $attributes['direction'][ 'value' . $device ]; |
| 88 | 167 | } |
| 89 | 168 | |
| @@ -90,30 +169,17 @@ | ||
| 90 | 169 | if ( isset( $attributes['labelAlignment'][ 'value' . $device ] ) ) { |
| 91 | 170 | $log_out_css['justify-content'] = $attributes['labelAlignment'][ 'value' . $device ]; |
| 92 | 171 | } |
| 93 | 172 | |
| 94 | - return $log_out_css; | |
| 173 | + return array_merge( | |
| 174 | + [ 'background' => Color::get_css( isset( $attributes['logOutLabelBgColor'] ) ? $attributes['logOutLabelBgColor'] : '' ) ], | |
| 175 | + $log_out_css | |
| 176 | + ); | |
| 95 | 177 | } |
| 96 | 178 | |
| 97 | 179 | |
| 98 | 180 | public function get_avatar_css( $attributes, $device = '' ) { |
| 99 | - $avatar_css = []; | |
| 100 | 181 | |
| 101 | - if ( ! empty( $attributes['avatarWidth'][ 'value' . $device ] ) ) { | |
| 102 | - $width_value = $attributes['avatarWidth'][ 'value' . $device ]; | |
| 103 | - $width_unit = $attributes['avatarWidth'][ 'valueUnit' . $device ] ?? 'px'; | |
| 104 | - $avatar_css['width'] = $width_value . $width_unit; | |
| 105 | - } | |
| 106 | - | |
| 107 | - if ( ! empty( $attributes['avatarHeight'][ 'value' . $device ] ) ) { | |
| 108 | - $height_value = $attributes['avatarHeight'][ 'value' . $device ]; | |
| 109 | - $height_unit = ! empty( $attributes['avatarHeight'][ 'valueUnit' . $device ] ) | |
| 110 | - ? $attributes['avatarHeight'][ 'valueUnit' . $device ] | |
| 111 | - : 'px'; | |
| 112 | - | |
| 113 | - $avatar_css['height'] = $height_value . $height_unit; | |
| 114 | - } | |
| 115 | - | |
| 116 | 182 | return array_merge( |
| 117 | 183 | Range::get_css([ |
| 118 | 184 | 'attributeValue' => $attributes['avatarWidth'], |
| 119 | 185 | 'attribute_object_key' => 'value', |
| @@ -134,9 +200,8 @@ | ||
| 134 | 200 | 'property' => 'height', |
| 135 | 201 | 'device' => $device, |
| 136 | 202 | ]), |
| 137 | 203 | isset( $attributes['avatarBorder'] ) ? Border::get_css( $attributes['avatarBorder'], '', $device ) : [], |
| 138 | - $avatar_css, | |
| 139 | 204 | ); |
| 140 | 205 | } |
| 141 | 206 | |
| 142 | 207 | public function get_avatar_border_hover_css( $attributes, $device = '' ) { |
| @@ -145,42 +210,35 @@ | ||
| 145 | 210 | ); |
| 146 | 211 | } |
| 147 | 212 | |
| 148 | 213 | public function get_name_css( $attributes, $device = '' ) { |
| 149 | - $name_css = []; | |
| 150 | - | |
| 151 | - if ( ! empty( $attributes['nameColor'] ) ) { | |
| 152 | - $name_css ['color'] = $attributes['nameColor']; | |
| 153 | - } | |
| 154 | 214 | $typography = isset( $attributes['nameTypography'] ) ? $attributes['nameTypography'] : ''; |
| 155 | 215 | $text_stroke = isset( $attributes['nameTextStroke'] ) ? $attributes['nameTextStroke'] : ''; |
| 156 | 216 | $text_shadow = isset( $attributes['nameTextShadow'] ) ? $attributes['nameTextShadow'] : ''; |
| 157 | - | |
| 217 | + $typographyglobal = ! empty( $attributes['nameTypographyGlobal'] ) ? $attributes['nameTypographyGlobal'] : array(); | |
| 158 | 218 | return array_merge( |
| 159 | - Typography::get_css( $typography, '', $device ), | |
| 219 | + [ 'color' => Color::get_css( isset( $attributes['nameColor'] ) ? $attributes['nameColor'] : '' ) ], | |
| 220 | + Typography::get_css( $typography, '', $device, $typographyglobal ), | |
| 160 | 221 | TextStroke::get_css( $text_stroke, '', $device ), |
| 161 | - TextShadow::get_css( $text_shadow, '', $device ), | |
| 162 | - $name_css | |
| 222 | + TextShadow::get_css( $text_shadow, '', $device ) | |
| 163 | 223 | ); |
| 164 | 224 | } |
| 165 | 225 | |
| 166 | - | |
| 167 | - | |
| 168 | 226 | public function render_block_content( $attributes, $content, $block_instance ) { |
| 169 | 227 | $logout_redirect_option = isset( $attributes['logoutRedirect'] ) ? $attributes['logoutRedirect'] : 'current-url'; |
| 170 | 228 | |
| 171 | 229 | if ( $logout_redirect_option === 'current-url' ) { |
| 172 | - $logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; | |
| 230 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash | |
| 231 | + $logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] ); | |
| 173 | 232 | } elseif ( $logout_redirect_option === 'custom-url' ) { |
| 174 | - $logout_redirect_url = isset( $attributes['logoutCustomUrl'] ) && ! empty( $attributes['logoutCustomUrl'] ) | |
| 175 | - ? esc_url( $attributes['logoutCustomUrl'] ) | |
| 176 | - : home_url(); | |
| 233 | + $logout_redirect_url = self::sanitize_custom_redirect_url( isset( $attributes['logoutCustomUrl'] ) ? $attributes['logoutCustomUrl'] : '' ); | |
| 177 | 234 | } |
| 178 | 235 | |
| 179 | 236 | $login_redirect_option = isset( $attributes['loginRedirect'] ) ? $attributes['loginRedirect'] : 'current-url'; |
| 180 | 237 | |
| 181 | 238 | if ( $login_redirect_option === 'current-url' ) { |
| 182 | - $login_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; | |
| 239 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash | |
| 240 | + $login_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] ); | |
| 183 | 241 | } elseif ( $login_redirect_option === 'custom-url' ) { |
| 184 | 242 | $login_redirect_url = isset( $attributes['loginCustomUrl'] ) && ! empty( $attributes['loginCustomUrl'] ) |
| 185 | 243 | ? esc_url( $attributes['loginCustomUrl'] ) |
| 186 | 244 | : home_url(); |
| @@ -186,45 +244,56 @@ | ||
| 186 | 244 | : home_url(); |
| 187 | 245 | } |
| 188 | 246 | |
| 189 | 247 | $current_user = wp_get_current_user(); |
| 190 | - $profile_picture = get_avatar_url( $current_user->ID ); | |
| 191 | - $display_name = $current_user->display_name; | |
| 248 | + $profile_picture = esc_url( get_avatar_url( $current_user->ID ) ); | |
| 249 | + $display_name = sanitize_text_field( $current_user->display_name ); | |
| 192 | 250 | |
| 193 | 251 | $button_icon_url = isset( $attributes['buttonIconUrl'] ) && ! empty( $attributes['buttonIconUrl'] ) |
| 194 | 252 | ? esc_url( $attributes['buttonIconUrl'] ) |
| 195 | 253 | : ''; |
| 196 | 254 | |
| 197 | - $button_class = isset( $attributes['buttonClass'] ) ? esc_attr( $attributes['buttonClass'] ) : 'ablocks-block-logout__label'; | |
| 255 | + $button_class = isset( $attributes['buttonClass'] ) ? sanitize_html_class( $attributes['buttonClass'] ) : 'ablocks-block-logout__label'; | |
| 198 | 256 | $is_logged_in = is_user_logged_in(); |
| 199 | 257 | $is_show_avatar = isset( $attributes['isShowAvatar'] ) && $attributes['isShowAvatar']; |
| 200 | 258 | $is_show_name = isset( $attributes['isShowName'] ) && $attributes['isShowName']; |
| 201 | 259 | |
| 202 | 260 | $button_text = $is_logged_in |
| 203 | - ? ( isset( $attributes['logOutLabel'] ) ? esc_html( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) ) | |
| 204 | - : ( isset( $attributes['logInLabel'] ) ? esc_html( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) ); | |
| 261 | + ? ( isset( $attributes['logOutLabel'] ) ? sanitize_text_field( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) ) | |
| 262 | + : ( isset( $attributes['logInLabel'] ) ? sanitize_text_field( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) ); | |
| 205 | 263 | |
| 206 | 264 | $action_url = $is_logged_in ? wp_logout_url( $logout_redirect_url ) : wp_login_url( $login_redirect_url ); |
| 207 | 265 | |
| 266 | + if ( $is_logged_in && 'custom-url' === $logout_redirect_option ) { | |
| 267 | + // wp_logout_url() returns an HTML-escaped URL; decode it before adding | |
| 268 | + // the arg, the anchor below escapes it again. | |
| 269 | + $action_url = add_query_arg( | |
| 270 | + self::REDIRECT_SIGNATURE_ARG, | |
| 271 | + self::sign_redirect_url( $logout_redirect_url ), | |
| 272 | + html_entity_decode( $action_url, ENT_QUOTES ) | |
| 273 | + ); | |
| 274 | + } | |
| 275 | + | |
| 208 | 276 | ob_start(); |
| 209 | 277 | ?> |
| 210 | - <div class="ablocks-block-logout"> | |
| 278 | + <div class="ablocks-block-logout"> | |
| 211 | 279 | <?php if ( $is_logged_in && $is_show_avatar ) : ?> |
| 212 | - <img | |
| 213 | - src="<?php echo esc_url( $profile_picture ); ?>" | |
| 214 | - alt="<?php echo esc_attr( $display_name ); ?>" | |
| 215 | - class="ablocks-block-logout__avatar" | |
| 280 | + <img | |
| 281 | + src="<?php echo esc_url( $profile_picture ); ?>" | |
| 282 | + alt="<?php echo esc_attr( $display_name ); ?>" | |
| 283 | + class="ablocks-block-logout__avatar" | |
| 216 | 284 | /> |
| 217 | 285 | <?php endif; ?> |
| 218 | 286 | <?php if ( $is_logged_in && $is_show_name ) : ?> |
| 219 | 287 | <span class="ablocks-block-logout__name"><?php echo esc_html( $display_name ); ?></span> |
| 220 | - <?php endif; ?> | |
| 288 | + <?php endif; ?> | |
| 221 | 289 | <a href="<?php echo esc_url( $action_url ); ?>" class="<?php echo esc_attr( $button_class ); ?>"> |
| 222 | 290 | (<span><?php echo esc_html( $button_text ); ?></span>) |
| 223 | 291 | </a> |
| 224 | - </div> | |
| 292 | + </div> | |
| 225 | 293 | <?php |
| 226 | 294 | |
| 227 | 295 | return ob_get_clean(); |
| 228 | 296 | } |
| 297 | + | |
| 229 | 298 | |
| 230 | 299 | } |