PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 7.8.1
Admin and Site Enhancements (ASE) v7.8.1
9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-svg-upload.php
admin-site-enhancements / classes Last commit date
class-activation.php 1 year ago class-admin-menu-organizer.php 1 year ago class-auto-publish-posts-with-missed-schedule.php 1 year ago class-avif-upload.php 1 year ago class-captcha-protection.php 1 year ago class-change-login-url.php 1 year ago class-cleanup-admin-bar.php 1 year ago class-common-methods.php 1 year ago class-content-duplication.php 1 year ago class-content-order.php 1 year ago class-custom-admin-footer-text.php 1 year ago class-custom-body-class.php 1 year ago class-custom-css.php 1 year ago class-custom-nav-menu-items-in-new-tab.php 1 year ago class-deactivation.php 1 year ago class-disable-comments.php 1 year ago class-disable-dashboard-widgets.php 1 year ago class-disable-feeds.php 1 year ago class-disable-gutenberg.php 1 year ago class-disable-rest-api.php 1 year ago class-disable-smaller-components.php 1 year ago class-disable-updates.php 1 year ago class-disable-xml-rpc.php 1 year ago class-display-system-summary.php 1 year ago class-email-address-obfuscator.php 1 year ago class-email-delivery.php 1 year ago class-enhance-list-tables.php 1 year ago class-external-permalinks.php 1 year ago class-heartbeat-control.php 1 year ago class-hide-admin-bar.php 1 year ago class-hide-admin-notices.php 1 year ago class-image-sizes-panel.php 1 year ago class-image-upload-control.php 1 year ago class-insert-head-body-footer-code.php 1 year ago class-last-login-column.php 1 year ago class-limit-login-attempts.php 1 year ago class-login-id-type.php 1 year ago class-login-logout-menu.php 1 year ago class-maintenance-mode.php 1 year ago class-manage-ads-appads-txt.php 1 year ago class-manage-robots-txt.php 1 year ago class-media-replacement.php 1 year ago class-multiple-user-roles.php 1 year ago class-obfuscate-author-slugs.php 1 year ago class-open-external-links-in-new-tab.php 1 year ago class-password-protection.php 1 year ago class-redirect-after-login.php 1 year ago class-redirect-after-logout.php 1 year ago class-redirect-fourofour.php 1 year ago class-registration-date-column.php 1 year ago class-revisions-control.php 1 year ago class-search-engines-visibility.php 1 year ago class-settings-fields-render.php 1 year ago class-settings-sanitization.php 1 year ago class-settings-sections-fields.php 1 year ago class-show-custom-taxonomy-filters.php 1 year ago class-site-identity-on-login-page.php 1 year ago class-svg-upload.php 1 year ago class-various-admin-ui-enhancements.php 1 year ago class-view-admin-as-role.php 1 year ago class-wider-admin-menu.php 1 year ago class-wp-config-transformer.php 1 year ago
class-svg-upload.php
289 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 /**
6 * Class for SVG Upload module
7 *
8 * @since 6.9.5
9 */
10 class SVG_Upload {
11
12 /**
13 * Add SVG mime type for media library uploads
14 *
15 * @link https://developer.wordpress.org/reference/hooks/upload_mimes/
16 * @since 2.6.0
17 */
18 public function add_svg_mime( $mimes ) {
19
20 global $roles_svg_upload_enabled;
21
22 $current_user = wp_get_current_user();
23 $current_user_roles = (array) $current_user->roles; // single dimensional array of role slugs
24
25 if ( count( $roles_svg_upload_enabled ) > 0 ) {
26
27 // Add mime type for user roles set to enable SVG upload
28 foreach ( $current_user_roles as $role ) {
29 if ( in_array( $role, $roles_svg_upload_enabled ) ) {
30 $mimes['svg'] = 'image/svg+xml';
31 }
32 }
33
34 }
35
36 return $mimes;
37
38 }
39
40 /**
41 * Check and confirm if the real file type is indeed SVG
42 *
43 * @link https://developer.wordpress.org/reference/functions/wp_check_filetype_and_ext/
44 * @since 2.6.0
45 */
46 public function confirm_file_type_is_svg( $filetypes_extensions, $file, $filename, $mimes ) {
47
48 global $roles_svg_upload_enabled;
49
50 $current_user = wp_get_current_user();
51 $current_user_roles = (array) $current_user->roles; // single dimensional array of role slugs
52
53 if ( count( $roles_svg_upload_enabled ) > 0 ) {
54
55 // Check file extension
56 if ( substr( $filename, -4 ) == '.svg' ) {
57
58 // Add mime type for user roles set to enable SVG upload
59 foreach ( $current_user_roles as $role ) {
60 if ( in_array( $role, $roles_svg_upload_enabled ) ) {
61 $filetypes_extensions['type'] = 'image/svg+xml';
62 $filetypes_extensions['ext'] = 'svg';
63 }
64 }
65
66 }
67
68 }
69
70 return $filetypes_extensions;
71
72 }
73
74 /**
75 * Sanitize the SVG file and maybe allow upload based on the result
76 *
77 * @since 2.6.0
78 */
79 public function sanitize_and_maybe_allow_svg_upload( $file ) {
80 if ( ! isset( $file['tmp_name'] ) ) {
81 return $file;
82 }
83
84 $file_tmp_name = $file['tmp_name']; // full path
85 $file_name = isset( $file['name'] ) ? $file['name'] : '';
86 $file_type_ext = wp_check_filetype_and_ext( $file_tmp_name, $file_name );
87 $file_type = ! empty( $file_type_ext['type'] ) ? $file_type_ext['type'] : '';
88
89 if ( 'image/svg+xml' === $file_type ) {
90 $original_svg = file_get_contents( $file_tmp_name );
91
92 $sanitizer = $this->get_svg_sanitizer();
93 $sanitized_svg = $sanitizer->sanitize( $original_svg ); // boolean
94
95 if ( false === $sanitized_svg ) {
96
97 $file['error'] = 'This SVG file could not be sanitized, so, was not uploaded for security reasons.';
98
99 }
100
101 file_put_contents( $file_tmp_name, $sanitized_svg );
102 }
103
104 return $file;
105 }
106
107 /**
108 * Sanitize a file after it is added to the media library, e.g. via REST API POST request
109 *
110 * @since 7.5.2
111 */
112 public function sanitize_after_upload( $attachment, $request, $creating ) {
113 // Let's sanitize SVG upon creation/insertion in the media library.
114 if ( $creating ) {
115 if ( $attachment instanceof WP_Post ) {
116 $file_path = get_attached_file( $attachment->ID );
117 $original_svg = file_get_contents( $file_path );
118
119 $sanitizer = $this->get_svg_sanitizer();
120 $sanitized_svg = $sanitizer->sanitize( $original_svg ); // boolean
121
122 if ( false !== $sanitized_svg ) {
123 // Sanitization was a success, let's write the result back to the file
124 file_put_contents( $file_path, $sanitized_svg );
125 }
126 }
127 }
128 }
129
130 /**
131 * Get sanitizer object
132 *
133 * @since 7.5.2
134 */
135 public function get_svg_sanitizer() {
136 if ( ! class_exists( '\enshrined\svgSanitize\Sanitizer' ) ) {
137 // Load sanitizer library - https://github.com/darylldoyle/svg-sanitizer
138 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AttributeInterface.php';
139 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/TagInterface.php';
140 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AllowedAttributes.php';
141 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/AllowedTags.php';
142 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/data/XPath.php';
143 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Resolver.php';
144 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Subject.php';
145 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/ElementReference/Usage.php';
146 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Exceptions/NestingException.php';
147 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Helper.php';
148 require_once ASENHA_PATH . 'vendor/enshrined/svg-sanitize/src/Sanitizer.php';
149 }
150
151 // $sanitizer = new Sanitizer();
152 $sanitizer = new \enshrined\svgSanitize\Sanitizer();
153
154 return $sanitizer;
155 }
156
157 /**
158 * Generate metadata for the svg attachment
159 *
160 * @link https://developer.wordpress.org/reference/functions/wp_generate_attachment_metadata/
161 * @since 2.6.0
162 */
163 public function generate_svg_metadata( $metadata, $attachment_id, $context ) {
164
165 if ( get_post_mime_type( $attachment_id ) == 'image/svg+xml' ) {
166
167 // Get SVG dimensions
168 $svg_path = get_attached_file( $attachment_id );
169 $svg = simplexml_load_file( $svg_path );
170 $width = 0;
171 $height = 0;
172
173 if ( $svg ) {
174
175 $attributes = $svg->attributes();
176 if ( isset( $attributes->width, $attributes->height ) ) {
177 $width = intval( floatval( $attributes->width ) );
178 $height = intval( floatval( $attributes->height ) );
179 } elseif ( isset( $attributes->viewBox ) ) {
180 $sizes = explode( ' ', $attributes->viewBox );
181 if ( isset( $sizes[2], $sizes[3] ) ) {
182 $width = intval( floatval( $sizes[2] ) );
183 $height = intval( floatval( $sizes[3] ) );
184 }
185 }
186
187 }
188
189 $metadata['width'] = $width;
190 $metadata['height'] = $height;
191
192 // Get SVG filename
193 $svg_url = wp_get_original_image_url( $attachment_id );
194 $svg_url_path = str_replace( wp_upload_dir()['baseurl'] .'/' , '', $svg_url );
195 $metadata['file'] = $svg_url_path;
196
197 }
198
199 return $metadata;
200
201 }
202
203 /**
204 * Remove responsive image attributes, i.e. srcset attributes, from SVG images HTML
205 * This helps ensure SVGs are displayed properly on the frontend
206 *
207 * @link https://plugins.trac.wordpress.org/browser/svg-support/tags/2.5.7/functions/attachment.php#L282
208 * @since 7.3.0
209 */
210 public function disable_svg_srcset( $sources ) {
211 $first_element = reset( $sources );
212
213 if ( isset( $first_element ) && ! empty( $first_element['url'] ) ) {
214 $extension = pathinfo( reset($sources)['url'], PATHINFO_EXTENSION );
215
216 if ( 'svg' === $extension ) {
217 $sources = array(); // return empty array
218 return $sources;
219 } else {
220 return $sources;
221 }
222 } else {
223 return $sources;
224 }
225 }
226
227 /**
228 * Remove responsive image attributes, i.e. srcset attributes, from SVG images HTML
229 * This helps ensure SVGs are displayed properly on the frontend
230 *
231 * @link https://gist.github.com/ericvalois/5b1e161c127632a1ace7d65ce1363e69
232 * @since 7.3.0
233 */
234 public function remove_svg_responsive_image_attr( string $sizes, $size, $image_src = null ) {
235 $explode = explode( '.', $image_src );
236 $extension = end( $explode );
237
238 if( 'svg' === $extension ){
239 $sizes = '';
240 }
241
242 return $sizes;
243 }
244
245 /**
246 * Return svg file URL to show preview in media library
247 *
248 * @link https://developer.wordpress.org/reference/hooks/wp_ajax_action/
249 * @link https://developer.wordpress.org/reference/functions/wp_get_attachment_url/
250 * @since 2.6.0
251 */
252 public function get_svg_attachment_url() {
253
254 $attachment_url = '';
255 $attachment_id = isset( $_REQUEST['attachmentID'] ) ? $_REQUEST['attachmentID'] : '';
256
257 // Check response mime type
258 if ( $attachment_id ) {
259
260 echo esc_url( wp_get_attachment_url( $attachment_id ) );
261
262 die();
263
264 }
265
266 }
267
268 /**
269 * Return svg file URL to show preview in media library
270 *
271 * @link https://developer.wordpress.org/reference/functions/wp_prepare_attachment_for_js/
272 * @since 2.6.0
273 */
274 public function get_svg_url_in_media_library( $response ) {
275
276 // Check response mime type
277 if ( $response['mime'] === 'image/svg+xml' ) {
278
279 $response['image'] = array(
280 'src' => $response['url'],
281 );
282
283 }
284
285 return $response;
286
287 }
288
289 }