PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 7.0.2
Admin and Site Enhancements (ASE) v7.0.2
9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-svg-upload.php
admin-site-enhancements / classes Last commit date
class-activation.php 2 years ago class-admin-columns-manager.php 2 years ago class-admin-menu-organizer.php 2 years ago class-auto-publish-posts-with-missed-schedule.php 2 years ago class-avif-upload.php 2 years ago class-change-login-url.php 2 years ago class-cleanup-admin-bar.php 2 years ago class-code-snippets-manager.php 2 years ago class-common-methods.php 2 years ago class-content-duplication.php 2 years ago class-content-order.php 2 years ago class-custom-admin-footer-text.php 2 years ago class-custom-body-class.php 2 years ago class-custom-content-types.php 2 years ago class-custom-css.php 2 years ago class-custom-nav-menu-items-in-new-tab.php 2 years ago class-deactivation.php 2 years ago class-disable-comments.php 2 years ago class-disable-dashboard-widgets.php 2 years ago class-disable-feeds.php 2 years ago class-disable-gutenberg.php 2 years ago class-disable-rest-api.php 2 years ago class-disable-smaller-components.php 2 years ago class-disable-updates.php 2 years ago class-disable-xml-rpc.php 2 years ago class-display-system-summary.php 2 years ago class-email-address-obfuscator.php 2 years ago class-email-delivery.php 2 years ago class-enhance-list-tables.php 2 years ago class-external-permalinks.php 2 years ago class-heartbeat-control.php 2 years ago class-hide-admin-bar.php 2 years ago class-hide-admin-notices.php 2 years ago class-image-sizes-panel.php 2 years ago class-image-upload-control.php 2 years ago class-insert-head-body-footer-code.php 2 years ago class-last-login-column.php 2 years ago class-limit-login-attempts.php 2 years ago class-login-id-type.php 2 years ago class-login-logout-menu.php 2 years ago class-maintenance-mode.php 2 years ago class-manage-ads-appads-txt.php 2 years ago class-manage-robots-txt.php 2 years ago class-media-replacement.php 2 years ago class-multiple-user-roles.php 2 years ago class-obfuscate-author-slugs.php 2 years ago class-open-external-links-in-new-tab.php 2 years ago class-password-protection.php 2 years ago class-redirect-after-login.php 2 years ago class-redirect-after-logout.php 2 years ago class-redirect-fourofour.php 2 years ago class-revisions-control.php 2 years ago class-search-engines-visibility.php 2 years ago class-settings-fields-render.php 2 years ago class-settings-sanitization.php 2 years ago class-settings-sections-fields.php 2 years ago class-show-custom-taxonomy-filters.php 2 years ago class-site-identity-on-login-page.php 2 years ago class-svg-upload.php 2 years ago class-various-admin-ui-enhancements.php 2 years ago class-view-admin-as-role.php 2 years ago class-wider-admin-menu.php 2 years ago
class-svg-upload.php
215 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 /**
6 * Class for SVG Upload module
7 *
8 * @since 6.9.5
9 */
10 class SVG_Upload {
11
12 /**
13 * Add SVG mime type for media library uploads
14 *
15 * @link https://developer.wordpress.org/reference/hooks/upload_mimes/
16 * @since 2.6.0
17 */
18 public function add_svg_mime( $mimes ) {
19
20 global $roles_svg_upload_enabled;
21
22 $current_user = wp_get_current_user();
23 $current_user_roles = (array) $current_user->roles; // single dimensional array of role slugs
24
25 if ( count( $roles_svg_upload_enabled ) > 0 ) {
26
27 // Add mime type for user roles set to enable SVG upload
28 foreach ( $current_user_roles as $role ) {
29 if ( in_array( $role, $roles_svg_upload_enabled ) ) {
30 $mimes['svg'] = 'image/svg+xml';
31 }
32 }
33
34 }
35
36 return $mimes;
37
38 }
39
40 /**
41 * Check and confirm if the real file type is indeed SVG
42 *
43 * @link https://developer.wordpress.org/reference/functions/wp_check_filetype_and_ext/
44 * @since 2.6.0
45 */
46 public function confirm_file_type_is_svg( $filetypes_extensions, $file, $filename, $mimes ) {
47
48 global $roles_svg_upload_enabled;
49
50 $current_user = wp_get_current_user();
51 $current_user_roles = (array) $current_user->roles; // single dimensional array of role slugs
52
53 if ( count( $roles_svg_upload_enabled ) > 0 ) {
54
55 // Check file extension
56 if ( substr( $filename, -4 ) == '.svg' ) {
57
58 // Add mime type for user roles set to enable SVG upload
59 foreach ( $current_user_roles as $role ) {
60 if ( in_array( $role, $roles_svg_upload_enabled ) ) {
61 $filetypes_extensions['type'] = 'image/svg+xml';
62 $filetypes_extensions['ext'] = 'svg';
63 }
64 }
65
66 }
67
68 }
69
70 return $filetypes_extensions;
71
72 }
73
74 /**
75 * Sanitize the SVG file and maybe allow upload based on the result
76 *
77 * @since 2.6.0
78 */
79 public function sanitize_and_maybe_allow_svg_upload( $file ) {
80
81 if ( ! isset( $file['tmp_name'] ) ) {
82 return $file;
83 }
84
85 $file_tmp_name = $file['tmp_name']; // full path
86 $file_name = isset( $file['name'] ) ? $file['name'] : '';
87 $file_type_ext = wp_check_filetype_and_ext( $file_tmp_name, $file_name );
88 $file_type = ! empty( $file_type_ext['type'] ) ? $file_type_ext['type'] : '';
89
90 if ( 'image/svg+xml' === $file_type ) {
91
92 // Load sanitizer library - https://github.com/darylldoyle/svg-sanitizer
93 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AttributeInterface.php';
94 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/TagInterface.php';
95 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AllowedAttributes.php';
96 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AllowedTags.php';
97 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/XPath.php';
98 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Resolver.php';
99 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Subject.php';
100 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Usage.php';
101 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Exceptions/NestingException.php';
102 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Helper.php';
103 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Sanitizer.php';
104
105 // $sanitizer = new Sanitizer();
106 $sanitizer = new \enshrined\svgSanitize\Sanitizer();
107
108 $original_svg = file_get_contents( $file_tmp_name );
109 $sanitized_svg = $sanitizer->sanitize( $original_svg ); // boolean
110
111 if ( false === $sanitized_svg ) {
112
113 $file['error'] = 'This SVG file could not be sanitized, so, was not uploaded for security reasons.';
114
115 }
116
117 file_put_contents( $file_tmp_name, $sanitized_svg );
118
119 }
120
121 return $file;
122
123 }
124
125 /**
126 * Generate metadata for the svg attachment
127 *
128 * @link https://developer.wordpress.org/reference/functions/wp_generate_attachment_metadata/
129 * @since 2.6.0
130 */
131 public function generate_svg_metadata( $metadata, $attachment_id, $context ) {
132
133 if ( get_post_mime_type( $attachment_id ) == 'image/svg+xml' ) {
134
135 // Get SVG dimensions
136 $svg_path = get_attached_file( $attachment_id );
137 $svg = simplexml_load_file( $svg_path );
138 $width = 0;
139 $height = 0;
140
141 if ( $svg ) {
142
143 $attributes = $svg->attributes();
144 if ( isset( $attributes->width, $attributes->height ) ) {
145 $width = intval( floatval( $attributes->width ) );
146 $height = intval( floatval( $attributes->height ) );
147 } elseif ( isset( $attributes->viewBox ) ) {
148 $sizes = explode( ' ', $attributes->viewBox );
149 if ( isset( $sizes[2], $sizes[3] ) ) {
150 $width = intval( floatval( $sizes[2] ) );
151 $height = intval( floatval( $sizes[3] ) );
152 }
153 }
154
155 }
156
157 $metadata['width'] = $width;
158 $metadata['height'] = $height;
159
160 // Get SVG filename
161 $svg_url = wp_get_original_image_url( $attachment_id );
162 $svg_url_path = str_replace( wp_upload_dir()['baseurl'] .'/' , '', $svg_url );
163 $metadata['file'] = $svg_url_path;
164
165 }
166
167 return $metadata;
168
169 }
170
171 /**
172 * Return svg file URL to show preview in media library
173 *
174 * @link https://developer.wordpress.org/reference/hooks/wp_ajax_action/
175 * @link https://developer.wordpress.org/reference/functions/wp_get_attachment_url/
176 * @since 2.6.0
177 */
178 public function get_svg_attachment_url() {
179
180 $attachment_url = '';
181 $attachment_id = isset( $_REQUEST['attachmentID'] ) ? $_REQUEST['attachmentID'] : '';
182
183 // Check response mime type
184 if ( $attachment_id ) {
185
186 echo esc_url( wp_get_attachment_url( $attachment_id ) );
187
188 die();
189
190 }
191
192 }
193
194 /**
195 * Return svg file URL to show preview in media library
196 *
197 * @link https://developer.wordpress.org/reference/functions/wp_prepare_attachment_for_js/
198 * @since 2.6.0
199 */
200 public function get_svg_url_in_media_library( $response ) {
201
202 // Check response mime type
203 if ( $response['mime'] === 'image/svg+xml' ) {
204
205 $response['image'] = array(
206 'src' => $response['url'],
207 );
208
209 }
210
211 return $response;
212
213 }
214
215 }