PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 7.2.0
Admin and Site Enhancements (ASE) v7.2.0
9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-svg-upload.php
admin-site-enhancements / classes Last commit date
class-activation.php 2 years ago class-admin-columns-manager.php 2 years ago class-admin-menu-organizer.php 2 years ago class-auto-publish-posts-with-missed-schedule.php 2 years ago class-avif-upload.php 2 years ago class-change-login-url.php 2 years ago class-cleanup-admin-bar.php 2 years ago class-code-snippets-manager.php 2 years ago class-common-methods.php 2 years ago class-content-duplication.php 2 years ago class-content-order.php 2 years ago class-custom-admin-footer-text.php 2 years ago class-custom-body-class.php 2 years ago class-custom-content-types.php 2 years ago class-custom-css.php 2 years ago class-custom-nav-menu-items-in-new-tab.php 2 years ago class-deactivation.php 2 years ago class-disable-comments.php 2 years ago class-disable-dashboard-widgets.php 2 years ago class-disable-feeds.php 2 years ago class-disable-gutenberg.php 2 years ago class-disable-rest-api.php 2 years ago class-disable-smaller-components.php 2 years ago class-disable-updates.php 2 years ago class-disable-xml-rpc.php 2 years ago class-display-system-summary.php 2 years ago class-email-address-obfuscator.php 2 years ago class-email-delivery.php 2 years ago class-enhance-list-tables.php 2 years ago class-external-permalinks.php 2 years ago class-heartbeat-control.php 2 years ago class-hide-admin-bar.php 2 years ago class-hide-admin-notices.php 2 years ago class-image-sizes-panel.php 2 years ago class-image-upload-control.php 2 years ago class-insert-head-body-footer-code.php 2 years ago class-last-login-column.php 2 years ago class-limit-login-attempts.php 2 years ago class-login-id-type.php 2 years ago class-login-logout-menu.php 2 years ago class-maintenance-mode.php 2 years ago class-manage-ads-appads-txt.php 2 years ago class-manage-robots-txt.php 2 years ago class-media-replacement.php 2 years ago class-multiple-user-roles.php 2 years ago class-obfuscate-author-slugs.php 2 years ago class-open-external-links-in-new-tab.php 2 years ago class-password-protection.php 2 years ago class-redirect-after-login.php 2 years ago class-redirect-after-logout.php 2 years ago class-redirect-fourofour.php 2 years ago class-revisions-control.php 2 years ago class-search-engines-visibility.php 2 years ago class-settings-fields-render.php 2 years ago class-settings-sanitization.php 2 years ago class-settings-sections-fields.php 2 years ago class-show-custom-taxonomy-filters.php 2 years ago class-site-identity-on-login-page.php 2 years ago class-svg-upload.php 2 years ago class-various-admin-ui-enhancements.php 2 years ago class-view-admin-as-role.php 2 years ago class-wider-admin-menu.php 2 years ago
class-svg-upload.php
217 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 /**
6 * Class for SVG Upload module
7 *
8 * @since 6.9.5
9 */
10 class SVG_Upload {
11
12 /**
13 * Add SVG mime type for media library uploads
14 *
15 * @link https://developer.wordpress.org/reference/hooks/upload_mimes/
16 * @since 2.6.0
17 */
18 public function add_svg_mime( $mimes ) {
19
20 global $roles_svg_upload_enabled;
21
22 $current_user = wp_get_current_user();
23 $current_user_roles = (array) $current_user->roles; // single dimensional array of role slugs
24
25 if ( count( $roles_svg_upload_enabled ) > 0 ) {
26
27 // Add mime type for user roles set to enable SVG upload
28 foreach ( $current_user_roles as $role ) {
29 if ( in_array( $role, $roles_svg_upload_enabled ) ) {
30 $mimes['svg'] = 'image/svg+xml';
31 }
32 }
33
34 }
35
36 return $mimes;
37
38 }
39
40 /**
41 * Check and confirm if the real file type is indeed SVG
42 *
43 * @link https://developer.wordpress.org/reference/functions/wp_check_filetype_and_ext/
44 * @since 2.6.0
45 */
46 public function confirm_file_type_is_svg( $filetypes_extensions, $file, $filename, $mimes ) {
47
48 global $roles_svg_upload_enabled;
49
50 $current_user = wp_get_current_user();
51 $current_user_roles = (array) $current_user->roles; // single dimensional array of role slugs
52
53 if ( count( $roles_svg_upload_enabled ) > 0 ) {
54
55 // Check file extension
56 if ( substr( $filename, -4 ) == '.svg' ) {
57
58 // Add mime type for user roles set to enable SVG upload
59 foreach ( $current_user_roles as $role ) {
60 if ( in_array( $role, $roles_svg_upload_enabled ) ) {
61 $filetypes_extensions['type'] = 'image/svg+xml';
62 $filetypes_extensions['ext'] = 'svg';
63 }
64 }
65
66 }
67
68 }
69
70 return $filetypes_extensions;
71
72 }
73
74 /**
75 * Sanitize the SVG file and maybe allow upload based on the result
76 *
77 * @since 2.6.0
78 */
79 public function sanitize_and_maybe_allow_svg_upload( $file ) {
80
81 if ( ! isset( $file['tmp_name'] ) ) {
82 return $file;
83 }
84
85 $file_tmp_name = $file['tmp_name']; // full path
86 $file_name = isset( $file['name'] ) ? $file['name'] : '';
87 $file_type_ext = wp_check_filetype_and_ext( $file_tmp_name, $file_name );
88 $file_type = ! empty( $file_type_ext['type'] ) ? $file_type_ext['type'] : '';
89
90 if ( 'image/svg+xml' === $file_type ) {
91
92 if ( ! class_exists( '\enshrined\svgSanitize\Sanitizer' ) ) {
93 // Load sanitizer library - https://github.com/darylldoyle/svg-sanitizer
94 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AttributeInterface.php';
95 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/TagInterface.php';
96 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AllowedAttributes.php';
97 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AllowedTags.php';
98 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/XPath.php';
99 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Resolver.php';
100 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Subject.php';
101 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Usage.php';
102 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Exceptions/NestingException.php';
103 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Helper.php';
104 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Sanitizer.php';
105 }
106
107 // $sanitizer = new Sanitizer();
108 $sanitizer = new \enshrined\svgSanitize\Sanitizer();
109
110 $original_svg = file_get_contents( $file_tmp_name );
111 $sanitized_svg = $sanitizer->sanitize( $original_svg ); // boolean
112
113 if ( false === $sanitized_svg ) {
114
115 $file['error'] = 'This SVG file could not be sanitized, so, was not uploaded for security reasons.';
116
117 }
118
119 file_put_contents( $file_tmp_name, $sanitized_svg );
120
121 }
122
123 return $file;
124
125 }
126
127 /**
128 * Generate metadata for the svg attachment
129 *
130 * @link https://developer.wordpress.org/reference/functions/wp_generate_attachment_metadata/
131 * @since 2.6.0
132 */
133 public function generate_svg_metadata( $metadata, $attachment_id, $context ) {
134
135 if ( get_post_mime_type( $attachment_id ) == 'image/svg+xml' ) {
136
137 // Get SVG dimensions
138 $svg_path = get_attached_file( $attachment_id );
139 $svg = simplexml_load_file( $svg_path );
140 $width = 0;
141 $height = 0;
142
143 if ( $svg ) {
144
145 $attributes = $svg->attributes();
146 if ( isset( $attributes->width, $attributes->height ) ) {
147 $width = intval( floatval( $attributes->width ) );
148 $height = intval( floatval( $attributes->height ) );
149 } elseif ( isset( $attributes->viewBox ) ) {
150 $sizes = explode( ' ', $attributes->viewBox );
151 if ( isset( $sizes[2], $sizes[3] ) ) {
152 $width = intval( floatval( $sizes[2] ) );
153 $height = intval( floatval( $sizes[3] ) );
154 }
155 }
156
157 }
158
159 $metadata['width'] = $width;
160 $metadata['height'] = $height;
161
162 // Get SVG filename
163 $svg_url = wp_get_original_image_url( $attachment_id );
164 $svg_url_path = str_replace( wp_upload_dir()['baseurl'] .'/' , '', $svg_url );
165 $metadata['file'] = $svg_url_path;
166
167 }
168
169 return $metadata;
170
171 }
172
173 /**
174 * Return svg file URL to show preview in media library
175 *
176 * @link https://developer.wordpress.org/reference/hooks/wp_ajax_action/
177 * @link https://developer.wordpress.org/reference/functions/wp_get_attachment_url/
178 * @since 2.6.0
179 */
180 public function get_svg_attachment_url() {
181
182 $attachment_url = '';
183 $attachment_id = isset( $_REQUEST['attachmentID'] ) ? $_REQUEST['attachmentID'] : '';
184
185 // Check response mime type
186 if ( $attachment_id ) {
187
188 echo esc_url( wp_get_attachment_url( $attachment_id ) );
189
190 die();
191
192 }
193
194 }
195
196 /**
197 * Return svg file URL to show preview in media library
198 *
199 * @link https://developer.wordpress.org/reference/functions/wp_prepare_attachment_for_js/
200 * @since 2.6.0
201 */
202 public function get_svg_url_in_media_library( $response ) {
203
204 // Check response mime type
205 if ( $response['mime'] === 'image/svg+xml' ) {
206
207 $response['image'] = array(
208 'src' => $response['url'],
209 );
210
211 }
212
213 return $response;
214
215 }
216
217 }