PluginProbe
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder / 2.16.0
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder v2.16.0
2.16.0 2.15.0 2.14.0 2.13.0 2.13.1 2.12.0 2.11.1 2.11.0 2.10.0 2.9.0 2.7.4 2.7.5 2.7.6 2.7.7 2.8.0 2.8.1 2.9.1 trunk 1.0 1.0-beta1 1.0-beta2 1.0-beta3 1.0.1 1.0.2 1.0.3 All 83 releases
← All changes | includes/assets.php +48 -2 2.13.1 → 2.16.0 View file →
@@ -9,8 +9,9 @@
9 9 use ABlocks\Classes\AssetsGenerator;
10 10 use ABlocks\Classes\RegisterScripts;
11 11 use ABlocks\Classes\GlobalCssGenerator;
12 12 use ABlocks\Classes\GlobalClasses;
13 +use ABlocks\Classes\AtomicStyles;
13 14 use ABlocks\Classes\FontLoadLocally;
14 15 use ABlocks\Admin\Menu;
15 16 use ABlocks\Helper;
16 17
@@ -42,8 +43,14 @@
42 43 add_action( 'enqueue_block_editor_assets', [ $self, 'global_css_variable' ] );
43 44 add_action( 'enqueue_block_editor_assets', [ $self, 'add_editor_inline_css' ] );
44 45 add_action( 'enqueue_block_editor_assets', [ $self, 'editor_google_fonts' ] );
45 46
47 + // The localized ablocks_nonce is minted once per page load, so a tab left
48 + // open past the nonce lifetime (or across a re-login) 403s on every
49 + // aBlocks request. Renew it the way core renews wp_rest.
50 + add_filter( 'wp_refresh_nonces', [ $self, 'refresh_heartbeat_nonce' ] );
51 + add_action( 'wp_ajax_ablocks/refresh_nonce', [ $self, 'ajax_refresh_nonce' ] );
52 +
46 53 // Detect page
47 54 add_action( 'wp', array( $self, 'detect_page' ) );
48 55
49 56 if ( ! is_admin() && Helper::is_enabled_assets_generation() ) {
@@ -159,8 +166,42 @@
159 166 return $data;
160 167 }
161 168
162 169 /**
170 + * Whether the current user is issued ablocks_nonce in the editor or the
171 + * dashboard, and so may have it renewed. Mirrors the gates above.
172 + */
173 + private function can_renew_nonce() {
174 + return is_user_logged_in() && ( current_user_can( 'edit_posts' ) || current_user_can( Permissions::ACCESS ) );
175 + }
176 +
177 + /**
178 + * Heartbeat: hand an open page a fresh ablocks_nonce whenever core refreshes
179 + * its own nonces (the page's nonces are ageing, or the session changed).
180 + *
181 + * @param array $response The Heartbeat response.
182 + * @return array
183 + */
184 + public function refresh_heartbeat_nonce( $response ) {
185 + if ( $this->can_renew_nonce() ) {
186 + $response['ablocks_nonce'] = wp_create_nonce( 'ablocks_nonce' );
187 + }
188 + return $response;
189 + }
190 +
191 + /**
192 + * A fresh ablocks_nonce for a request that was rejected with a stale one —
193 + * the aBlocks counterpart of core's `rest-nonce` action. Logged-in only, and
194 + * only for users who would be given the nonce on page load anyway.
195 + */
196 + public function ajax_refresh_nonce() {
197 + if ( ! $this->can_renew_nonce() ) {
198 + wp_send_json_error( [ 'message' => 'forbidden' ], 403 );
199 + }
200 + wp_send_json_success( [ 'nonce' => wp_create_nonce( 'ablocks_nonce' ) ] );
201 + }
202 +
203 + /**
163 204 * Whether the frontend ABlocksGlobal payload has been attached this request.
164 205 *
165 206 * @var bool
166 207 */
@@ -881,12 +922,17 @@
881 922 */
882 923 public static function build_revision() {
883 924 $stamp = get_option( self::BUILD_OPTION );
884 925
926 + // The compiler's output revision is part of the key, so an emission
927 + // change stales every baked page even without a version bump. See
928 + // AtomicStyles::OUTPUT_REVISION.
929 + $build = ABLOCKS_VERSION . '+' . AtomicStyles::OUTPUT_REVISION;
930 +
885 931 if (
886 932 is_array( $stamp ) &&
887 933 isset( $stamp['version'], $stamp['time'] ) &&
888 - ABLOCKS_VERSION === $stamp['version']
934 + $build === $stamp['version']
889 935 ) {
890 936 return (int) $stamp['time'];
891 937 }
892 938
@@ -893,9 +939,9 @@
893 939 $now = time();
894 940 update_option(
895 941 self::BUILD_OPTION,
896 942 [
897 - 'version' => ABLOCKS_VERSION,
943 + 'version' => $build,
898 944 'time' => $now,
899 945 ],
900 946 true
901 947 );