| @@ -9,8 +9,9 @@ | ||
| 9 | 9 | use ABlocks\Classes\AssetsGenerator; |
| 10 | 10 | use ABlocks\Classes\RegisterScripts; |
| 11 | 11 | use ABlocks\Classes\GlobalCssGenerator; |
| 12 | 12 | use ABlocks\Classes\GlobalClasses; |
| 13 | +use ABlocks\Classes\AtomicStyles; | |
| 13 | 14 | use ABlocks\Classes\FontLoadLocally; |
| 14 | 15 | use ABlocks\Admin\Menu; |
| 15 | 16 | use ABlocks\Helper; |
| 16 | 17 | |
| @@ -42,8 +43,14 @@ | ||
| 42 | 43 | add_action( 'enqueue_block_editor_assets', [ $self, 'global_css_variable' ] ); |
| 43 | 44 | add_action( 'enqueue_block_editor_assets', [ $self, 'add_editor_inline_css' ] ); |
| 44 | 45 | add_action( 'enqueue_block_editor_assets', [ $self, 'editor_google_fonts' ] ); |
| 45 | 46 | |
| 47 | + // The localized ablocks_nonce is minted once per page load, so a tab left | |
| 48 | + // open past the nonce lifetime (or across a re-login) 403s on every | |
| 49 | + // aBlocks request. Renew it the way core renews wp_rest. | |
| 50 | + add_filter( 'wp_refresh_nonces', [ $self, 'refresh_heartbeat_nonce' ] ); | |
| 51 | + add_action( 'wp_ajax_ablocks/refresh_nonce', [ $self, 'ajax_refresh_nonce' ] ); | |
| 52 | + | |
| 46 | 53 | // Detect page |
| 47 | 54 | add_action( 'wp', array( $self, 'detect_page' ) ); |
| 48 | 55 | |
| 49 | 56 | if ( ! is_admin() && Helper::is_enabled_assets_generation() ) { |
| @@ -159,8 +166,42 @@ | ||
| 159 | 166 | return $data; |
| 160 | 167 | } |
| 161 | 168 | |
| 162 | 169 | /** |
| 170 | + * Whether the current user is issued ablocks_nonce in the editor or the | |
| 171 | + * dashboard, and so may have it renewed. Mirrors the gates above. | |
| 172 | + */ | |
| 173 | + private function can_renew_nonce() { | |
| 174 | + return is_user_logged_in() && ( current_user_can( 'edit_posts' ) || current_user_can( Permissions::ACCESS ) ); | |
| 175 | + } | |
| 176 | + | |
| 177 | + /** | |
| 178 | + * Heartbeat: hand an open page a fresh ablocks_nonce whenever core refreshes | |
| 179 | + * its own nonces (the page's nonces are ageing, or the session changed). | |
| 180 | + * | |
| 181 | + * @param array $response The Heartbeat response. | |
| 182 | + * @return array | |
| 183 | + */ | |
| 184 | + public function refresh_heartbeat_nonce( $response ) { | |
| 185 | + if ( $this->can_renew_nonce() ) { | |
| 186 | + $response['ablocks_nonce'] = wp_create_nonce( 'ablocks_nonce' ); | |
| 187 | + } | |
| 188 | + return $response; | |
| 189 | + } | |
| 190 | + | |
| 191 | + /** | |
| 192 | + * A fresh ablocks_nonce for a request that was rejected with a stale one — | |
| 193 | + * the aBlocks counterpart of core's `rest-nonce` action. Logged-in only, and | |
| 194 | + * only for users who would be given the nonce on page load anyway. | |
| 195 | + */ | |
| 196 | + public function ajax_refresh_nonce() { | |
| 197 | + if ( ! $this->can_renew_nonce() ) { | |
| 198 | + wp_send_json_error( [ 'message' => 'forbidden' ], 403 ); | |
| 199 | + } | |
| 200 | + wp_send_json_success( [ 'nonce' => wp_create_nonce( 'ablocks_nonce' ) ] ); | |
| 201 | + } | |
| 202 | + | |
| 203 | + /** | |
| 163 | 204 | * Whether the frontend ABlocksGlobal payload has been attached this request. |
| 164 | 205 | * |
| 165 | 206 | * @var bool |
| 166 | 207 | */ |
| @@ -215,8 +256,11 @@ | ||
| 215 | 256 | 'academy_lms' => Helper::is_active_academy(), |
| 216 | 257 | 'storeengine' => Helper::is_active_storeengine(), |
| 217 | 258 | 'wp_map_block' => Helper::is_active_wp_map_block(), |
| 218 | 259 | 'easy_content_manager' => Helper::is_active_easy_content_manager(), |
| 260 | + 'zencommunity' => Helper::is_active_zencommunity(), | |
| 261 | + 'gemboards' => Helper::is_active_gemboards(), | |
| 262 | + 'quizpress' => Helper::is_active_quizpress(), | |
| 219 | 263 | ] |
| 220 | 264 | ); |
| 221 | 265 | return apply_filters( |
| 222 | 266 | 'ablocks/assets/dashboard_scripts_data', |
| @@ -878,12 +922,17 @@ | ||
| 878 | 922 | */ |
| 879 | 923 | public static function build_revision() { |
| 880 | 924 | $stamp = get_option( self::BUILD_OPTION ); |
| 881 | 925 | |
| 926 | + // The compiler's output revision is part of the key, so an emission | |
| 927 | + // change stales every baked page even without a version bump. See | |
| 928 | + // AtomicStyles::OUTPUT_REVISION. | |
| 929 | + $build = ABLOCKS_VERSION . '+' . AtomicStyles::OUTPUT_REVISION; | |
| 930 | + | |
| 882 | 931 | if ( |
| 883 | 932 | is_array( $stamp ) && |
| 884 | 933 | isset( $stamp['version'], $stamp['time'] ) && |
| 885 | - ABLOCKS_VERSION === $stamp['version'] | |
| 934 | + $build === $stamp['version'] | |
| 886 | 935 | ) { |
| 887 | 936 | return (int) $stamp['time']; |
| 888 | 937 | } |
| 889 | 938 | |
| @@ -890,9 +939,9 @@ | ||
| 890 | 939 | $now = time(); |
| 891 | 940 | update_option( |
| 892 | 941 | self::BUILD_OPTION, |
| 893 | 942 | [ |
| 894 | - 'version' => ABLOCKS_VERSION, | |
| 943 | + 'version' => $build, | |
| 895 | 944 | 'time' => $now, |
| 896 | 945 | ], |
| 897 | 946 | true |
| 898 | 947 | ); |
| @@ -902,17 +951,39 @@ | ||
| 902 | 951 | |
| 903 | 952 | public function set_current_page_template_part( $content, $block ) { |
| 904 | 953 | if ( ! isset( $block['blockName'] ) && is_array( $block ) ) { |
| 905 | 954 | foreach ( $block as $block_item ) { |
| 906 | - if ( ! empty( $block_item['blockName'] ) && strpos( $block_item['blockName'], 'ablocks/' ) !== false ) { | |
| 955 | + if ( $this->is_page_asset_block( $block_item ) ) { | |
| 907 | 956 | $this->current_page_blocks[] = $block_item; |
| 908 | 957 | } |
| 909 | 958 | } |
| 910 | 959 | } |
| 911 | - if ( ! empty( $block['blockName'] ) && strpos( $block['blockName'], 'ablocks/' ) !== false ) { | |
| 960 | + if ( $this->is_page_asset_block( $block ) ) { | |
| 912 | 961 | $this->current_page_blocks[] = $block; |
| 913 | 962 | } |
| 914 | 963 | return $content; |
| 964 | + } | |
| 965 | + | |
| 966 | + /** | |
| 967 | + * Whether a top-level block contributes to the page's generated assets. | |
| 968 | + * | |
| 969 | + * A synced pattern counts too: AssetsGenerator::recursive_block_parser() | |
| 970 | + * already expands its reference. Collecting only `ablocks/*` names left a | |
| 971 | + * page whose content is just a pattern with no combined CSS/JS at all — so a | |
| 972 | + * Loop Filter placed from a pattern rendered unstyled and did nothing when | |
| 973 | + * clicked. | |
| 974 | + * | |
| 975 | + * @param mixed $block Parsed block. | |
| 976 | + * @return bool | |
| 977 | + */ | |
| 978 | + private function is_page_asset_block( $block ) { | |
| 979 | + if ( ! is_array( $block ) || empty( $block['blockName'] ) ) { | |
| 980 | + return false; | |
| 981 | + } | |
| 982 | + if ( 'core/block' === $block['blockName'] ) { | |
| 983 | + return ! empty( $block['attrs']['ref'] ); | |
| 984 | + } | |
| 985 | + return strpos( $block['blockName'], 'ablocks/' ) !== false; | |
| 915 | 986 | } |
| 916 | 987 | |
| 917 | 988 | public function set_theme_builder_locations( $args ) { |
| 918 | 989 | $this->theme_builder_locations = $args; |