PluginProbe
Adminify – White Label, Admin Menu Editor, Login Customizer / 4.0.2.5
Adminify – White Label, Admin Menu Editor, Login Customizer v4.0.2.5
4.3.2 4.3.1 4.3.0 4.2.26 4.2.25 4.2.24 4.2.23 4.2.22 4.2.21 4.2.20 4.2.19 4.2.18 4.2.17 4.2.16 4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 All 165 releases
← All changes | Inc/Admin/Frames/Init.php +19 -117 4.1.17 → 4.0.2.5 View file →
@@ -32,10 +32,9 @@
32 32 {
33 33
34 34 if ( ! $this->is_allowed() ) {
35 35 if ( is_iframe() ) {
36 - $actual_link = (empty($_SERVER['HTTPS']) ? 'http' : 'https') . "://$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]";
37 - Frames::custom_plugin_change_reload($actual_link);
36 + Frames::custom_plugin_change_reload();
38 37 }
39 38 return;
40 39 }
41 40
@@ -46,135 +45,36 @@
46 45 }
47 46
48 47 }
49 48
50 - /**
51 - * Get the relative admin path without subdirectory prefix
52 - * Handles root, subdirectory, subdomain, and multisite installations
53 - *
54 - * @return string Normalized path (e.g., /wp-admin/edit.php)
55 - */
56 - private function get_normalized_admin_path() {
57 - $php_self = $_SERVER['PHP_SELF'] ?? '';
58 -
59 - // Method 1: Use WordPress native function to get subdirectory path
60 - // site_url() returns full URL including subdirectory
61 - // e.g., https://example.com/blog or https://example.com
62 - $site_url_path = wp_parse_url( site_url(), PHP_URL_PATH );
63 -
64 - // Remove subdirectory prefix if exists
65 - if ( ! empty( $site_url_path ) && $site_url_path !== '/' ) {
66 - // Ensure path starts with subdirectory
67 - if ( strpos( $php_self, $site_url_path ) === 0 ) {
68 - $php_self = substr( $php_self, strlen( $site_url_path ) );
69 - }
70 - }
71 -
72 - // Ensure path starts with /
73 - if ( empty( $php_self ) || $php_self[0] !== '/' ) {
74 - $php_self = '/' . $php_self;
75 - }
76 -
77 - return $php_self;
78 - }
79 -
80 - /**
81 - * Check if current path matches the blocked URL pattern
82 - * Supports exact match and ends-with matching for subdirectory compatibility
83 - *
84 - * @param string $blocked_url The URL pattern to check against
85 - * @return bool True if current path matches the blocked URL
86 - */
87 - private function matches_blocked_url( $blocked_url ) {
88 - $current_path = $this->get_normalized_admin_path();
89 -
90 - // Exact match (normalized)
91 - if ( $current_path === $blocked_url ) {
92 - return true;
93 - }
94 -
95 - // Fallback: ends-with check for edge cases
96 - // e.g., /wp-admin/customize.php should match even if normalization fails
97 - if ( $this->url_ends_with( $_SERVER['PHP_SELF'] ?? '', $blocked_url ) ) {
98 - return true;
99 - }
100 -
101 - return false;
102 - }
103 -
104 - /**
105 - * Check if a URL ends with a specific path
106 - * Useful for subdirectory WordPress installs
107 - *
108 - * @param string $url Full URL or path to check
109 - * @param string $ending The ending pattern to match
110 - * @return bool
111 - */
112 - private function url_ends_with( $url, $ending ) {
113 - $ending_length = strlen( $ending );
114 - if ( $ending_length === 0 ) {
115 - return true;
116 - }
117 - return substr( $url, -$ending_length ) === $ending;
118 - }
119 -
120 - /**
121 - * Get WordPress installation context for debugging
122 - *
123 - * @return array Installation details
124 - */
125 - public function get_install_context() {
126 - return [
127 - 'is_multisite' => is_multisite(),
128 - 'is_subdomain' => defined( 'SUBDOMAIN_INSTALL' ) && SUBDOMAIN_INSTALL,
129 - 'site_url' => site_url(),
130 - 'home_url' => home_url(),
131 - 'admin_url' => admin_url(),
132 - 'subdirectory' => wp_parse_url( site_url(), PHP_URL_PATH ) ?: '/',
133 - 'php_self' => $_SERVER['PHP_SELF'] ?? '',
134 - 'normalized_path' => $this->get_normalized_admin_path(),
135 - ];
136 - }
137 -
138 49 public function is_allowed() {
139 50
140 51 $not_allowed_urls = Admin::get_not_allowed_urls();
141 52
142 53 foreach ( $not_allowed_urls as $url_object ) {
54 +
143 55 if ( is_string( $url_object ) ) {
144 56
145 57 $is_allowed = true; // Scoped Default allowed
146 - // Use normalized path matching for subdirectory compatibility
147 - if ( $this->matches_blocked_url( $url_object ) ) {
148 - $is_allowed = false; // not allowed
149 - }
58 + if ( $url_object === $_SERVER['PHP_SELF'] ) $is_allowed = false; // not allowed
150 59
151 60 } else {
152 61
153 62 $is_allowed = false; // Scoped Default not allowed
154 63
155 - // Use normalized path matching for subdirectory compatibility
156 - if ( $url_object['url'] !== '*' && ! $this->matches_blocked_url( $url_object['url'] ) ) {
157 - $is_allowed = true; // allowed
158 - }
64 + if ( $url_object['url'] !== '*' && $url_object['url'] !== $_SERVER['PHP_SELF'] ) $is_allowed = true; // allowed
159 65
160 66 if ( ! $is_allowed && array_key_exists( 'query_params', $url_object ) ) {
161 - if ( ! $this->check_query_params( $url_object['query_params'] ) ) {
162 - $is_allowed = true; // allowed
163 - }
67 + if ( ! $this->check_query_params( $url_object['query_params'] ) ) $is_allowed = true; // allowed
164 68 }
165 69
166 70 if ( ! $is_allowed && array_key_exists( 'post_type', $url_object ) ) {
167 - if ( ! $this->check_post_type( $url_object['post_type'] ) ) {
168 - $is_allowed = true; // allowed
169 - }
71 + if ( ! $this->check_post_type( $url_object['post_type'] ) ) $is_allowed = true; // allowed
170 72 }
171 73
172 74 }
173 75
174 - if ( ! $is_allowed ) {
175 - return $is_allowed;
176 - }
76 + if ( ! $is_allowed ) return $is_allowed;
177 77
178 78 }
179 79
180 80 return true;
@@ -181,21 +81,13 @@
181 81
182 82 }
183 83
184 84 function check_query_params($query_params) {
185 - // Pattern 1: Both keys and their values should check in $_GET
186 - if (array_keys($query_params) === $query_params) {
187 - foreach ($query_params as $key => $value) {
188 - if (!isset($_GET[$key]) || $_GET[$key] != $value) {
189 - return false; // Key doesn't exist or the value doesn't match
190 - }
191 - }
192 - return true; // All keys and values match
193 - }
194 85
195 - // Pattern 2: Check for only keys in $_GET, no need to check their values
86 + // Pattern 1: Check for only keys in $_GET, no need to check their values
196 87 if (array_values($query_params) === $query_params) {
197 88 foreach ($query_params as $param) {
89 +
198 90 if ( substr($param, -1) === '!' ) {
199 91 $param = substr($param, 0, -1);
200 92 if ( isset($_GET[$param]) ) return false; // The key exists in $_GET
201 93 } else {
@@ -203,8 +95,18 @@
203 95 }
204 96
205 97 }
206 98 return true; // All keys exist
99 + }
100 +
101 + // Pattern 2: Both keys and their values should check in $_GET
102 + if (array_keys($query_params) === $query_params) {
103 + foreach ($query_params as $key => $value) {
104 + if (!isset($_GET[$key]) || $_GET[$key] != $value) {
105 + return false; // Key doesn't exist or the value doesn't match
106 + }
107 + }
108 + return true; // All keys and values match
207 109 }
208 110
209 111 // Pattern 3: A mix of key existence and key-value matching
210 112 foreach ($query_params as $key => $value) {