PluginProbe
Adminify – White Label, Admin Menu Editor, Login Customizer / 4.0.3.7
Adminify – White Label, Admin Menu Editor, Login Customizer v4.0.3.7
4.3.1 4.3.0 4.2.26 4.2.25 4.2.24 4.2.23 4.2.22 4.2.21 4.2.20 4.2.19 4.2.18 4.2.17 4.2.16 4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 4.1.17 All 164 releases
← All changes | Libs/Addons.php +203 -349 4.2.204.0.3.7 View file →
@@ -1,7 +1,7 @@
1 1 <?php
2 2
3 -namespace PXLBSAdminify\Libs;
3 +namespace WPAdminify\Libs;
4 4
5 5 // No, Direct access Sir !!!
6 6 if (!defined('ABSPATH')) {
7 7 exit;
@@ -24,9 +24,11 @@
24 24 public $plugins_list = [];
25 25 public $sub_menu;
26 26 public $menu_order;
27 27
28 + public $server_url = 'https://coupon.wpadminify.com/';
28 29
30 +
29 31 /**
30 32 * Constructor method
31 33 *
32 34 * @param integer $menu_order .
@@ -39,220 +41,62 @@
39 41 $this->plugins_list = $this->plugins_list();
40 42
41 43 $this->includes();
42 44
43 - // Show Addons menu only on network admin for multisite, or on regular admin for single site
44 - if ( is_multisite() ) {
45 - add_action('network_admin_menu', array($this, 'admin_menu'), 1000);
46 - } else {
47 - add_action('admin_menu', array($this, 'admin_menu'), 1000);
48 - }
49 - add_action('wp_ajax_pxlbsadminify_addons_upgrade_plugin', array($this, 'pxlbsadminify_addons_upgrade_plugin'));
50 - add_action('wp_ajax_pxlbsadminify_addons_activate_plugin', array($this, 'pxlbsadminify_addons_activate_plugin'));
51 - // Notify the site admin when a renamed legacy addon is detected
52 - // alongside its replacement. Per WordPress.org plugin guidelines,
53 - // we must not deactivate or activate plugins automatically; the
54 - // user has to perform the swap themselves from the Plugins screen.
55 - add_action('admin_notices', array($this, 'maybe_renamed_addon_notice'));
56 - add_action( 'rest_api_init', array( $this , 'addons_rest_routes') );
45 + add_action('admin_menu', array($this, 'admin_menu'), 1000);
46 + // add_action('network_admin_menu', array($this, 'admin_menu'), $this->menu_order);
47 + add_action('wp_ajax_jltwp_adminify_addons_upgrade_plugin', array($this, 'jltwp_adminify_addons_upgrade_plugin'));
48 + add_action('wp_ajax_jltwp_adminify_addons_activate_plugin', array($this, 'jltwp_adminify_addons_activate_plugin'));
49 + add_action('plugins_loaded', array($this, 'maybe_replace_addons_path'), 1000); // 1000 is important
57 50 }
58 51
59 - public function addons_rest_routes() {
60 - register_rest_route('adminify/v1', '/get-addons-list', array(
61 - 'methods' => 'GET',
62 - 'callback' => [$this, 'get_addons_plugins_list'],
63 - 'permission_callback' => [$this, 'check_is_admin_user'],
64 - ));
52 + public function maybe_replace_addons_path() {
65 53
66 - register_rest_route('adminify/v1', '/install-addons', array(
67 - 'methods' => 'POST',
68 - 'callback' => [$this, 'install_addons'],
69 - 'permission_callback' => [$this, 'check_verify_nonce_and_permissions'],
70 - ));
71 - }
54 + $addons = [
55 + 'sidebar-generator/adminify-sidebar-generator.php' => 'adminify-sidebar-generator/adminify-sidebar-generator.php'
56 + ];
72 57
73 - public function check_is_admin_user() {
74 - if ( is_multisite() && ! is_super_admin() ) {
75 - return new \WP_Error('rest_forbidden', __('You are not allowed to access this resource.', 'adminify'), array('status' => 403));
76 - }
77 - if ( ! current_user_can('manage_options') ) {
78 - return new \WP_Error('rest_forbidden', __('You are not allowed to access this resource.', 'adminify'), array('status' => 403));
79 - }
80 - return true;
81 - }
58 + foreach ($addons as $old_plugin => $new_plugin) {
82 59
83 - public function check_verify_nonce_and_permissions() {
84 - // The install-addons endpoint may both install AND activate
85 - // addons depending on each addon's current status, so the
86 - // caller must hold BOTH capabilities. On multisite this also
87 - // requires super admin.
88 - if ( is_multisite() && ! is_super_admin() ) {
89 - return new \WP_Error('rest_forbidden', __('Super admin required.', 'adminify'), array('status' => 403));
90 - }
91 - if ( ! current_user_can('install_plugins') ) {
92 - return new \WP_Error('rest_forbidden', __('You are not allowed to install plugins.', 'adminify'), array('status' => 403));
93 - }
94 - if ( ! current_user_can('activate_plugins') ) {
95 - return new \WP_Error('rest_forbidden', __('You are not allowed to activate plugins.', 'adminify'), array('status' => 403));
96 - }
60 + $old_plugin_path = WP_PLUGIN_DIR . '/' . $old_plugin;
61 + $new_plugin_path = WP_PLUGIN_DIR . '/' . $new_plugin;
97 62
98 - // Nonce check from header. Sanitize and unslash before verifying.
99 - $nonce = isset($_SERVER['HTTP_X_WP_NONCE'])
100 - ? sanitize_text_field( wp_unslash( $_SERVER['HTTP_X_WP_NONCE'] ) )
101 - : '';
102 - if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
103 - return new \WP_Error('rest_cookie_invalid_nonce', __('Invalid nonce.', 'adminify'), array('status' => 403));
104 - }
105 -
106 - return true;
107 - }
108 -
109 -
110 - public function get_addons_plugins_list() {
111 - // Fetch the catalogue on demand. This callback only runs on the
112 - // Add-ons page (a user action), so the remote request is not made on
113 - // routine admin page loads.
114 - $plugins = ( method_exists( $this, 'get_adminify_plugins_lists' ) )
115 - ? (array) $this->get_adminify_plugins_lists()
116 - : (array) $this->plugins_list;
117 - unset($plugins['master-addons']);
118 - $all_plugins = get_plugins();
119 - $active_plugins = get_option('active_plugins');
120 - foreach( $plugins as $slug => $plugin){
121 - foreach ($all_plugins as $plugin_file => $plugin_data) {
122 - if (strpos($plugin_file, $slug) !== false) {
123 - $plugins[$slug]["status"] = 'installed';
124 -
125 - if (in_array($plugin_file, $active_plugins)) {
126 - $plugins[$slug]["status"] = 'activated';
127 - }
128 - break;
129 - }
130 - }
131 - if( !isset($plugins[$slug]["status"])) $plugins[$slug]["status"] = 'not-installed';
132 -
133 - }
134 -
135 - return rest_ensure_response($plugins);
136 -
137 - }
138 -
139 -
140 - public function install_addons( $request ) {
141 - $addons = $request->get_param('addons');
142 - if ( empty($addons) || ! is_array($addons) ) {
143 - return new \WP_Error('no_addons', __('No addons were selected.', 'adminify'), array('status' => 400));
144 - }
145 -
146 - $plugins_list = $this->get_addons_plugins_list()->data;
147 - foreach( $addons as $key => $plugin ) {
148 - $plugin = sanitize_key( $plugin );
149 - if ( ! isset( $plugins_list[ $plugin ] ) ) {
63 + // Both files exist, delete the old one
64 + if ( file_exists($old_plugin_path) && file_exists($new_plugin_path) ) {
65 + unlink(dirname($old_plugin_path));
150 66 continue;
151 67 }
152 - if ( $plugins_list[ $plugin ]['status'] === 'activated' ) {
153 - continue;
154 - }
155 - if ( $plugins_list[ $plugin ]['status'] === 'installed' ) {
156 - $this->activate_plugin_by_slug( $plugin );
157 - continue;
158 - }
159 - $params = [
160 - 'request_type' => 'rest',
161 - 'plugin' => $plugins_list[ $plugin ]['download_link'],
162 - ];
163 68
164 - $this->pxlbsadminify_addons_upgrade_plugin( $params );
165 - }
69 + // If the old file exists and the new file doesn't exist, rename the old file to the new file
70 + if ( file_exists($old_plugin_path) && !file_exists($new_plugin_path) ) {
166 71
167 - return rest_ensure_response(['message' => __('Addons processed.', 'adminify'), 'addons' => $addons]);
168 - }
72 + // check if the old plugin is active
73 + include_once( ABSPATH . 'wp-admin/includes/plugin.php' );
169 74
170 - function activate_plugin_by_slug($slug) {
171 - // Activation requires the activate_plugins capability in
172 - // addition to whatever capability gated the calling endpoint.
173 - // On multisite, activation must be performed by a super admin.
174 - if ( is_multisite() && ! is_super_admin() ) {
175 - return new \WP_Error( 'rest_forbidden', __( 'Super admin required to activate plugins.', 'adminify' ), array( 'status' => 403 ) );
176 - }
177 - if ( ! current_user_can( 'activate_plugins' ) ) {
178 - return new \WP_Error( 'rest_forbidden', __( 'You are not allowed to activate plugins.', 'adminify' ), array( 'status' => 403 ) );
179 - }
75 + $is_active = is_plugin_active( $old_plugin );
180 76
181 - // Reject any slug containing path separators / traversal so
182 - // $slug cannot escape WP_PLUGIN_DIR.
183 - if ( ! is_string( $slug ) || $slug === '' || strpbrk( $slug, "/\\" ) !== false || strpos( $slug, '..' ) !== false ) {
184 - return new \WP_Error( 'invalid_slug', __( 'Invalid plugin slug.', 'adminify' ), array( 'status' => 400 ) );
185 - }
77 + if ( $is_active ) {
78 + // Deactivate the old plugin
79 + deactivate_plugins( $old_plugin );
80 + // Rename the old plugin to the new plugin
81 + rename( dirname($old_plugin_path), dirname($new_plugin_path) );
186 82
187 - // Slug must be present in the trusted addons list.
188 - if ( ! array_key_exists( $slug, (array) $this->plugins_list ) ) {
189 - return new \WP_Error( 'invalid_slug', __( 'Invalid plugin slug.', 'adminify' ), array( 'status' => 400 ) );
190 - }
83 + if ( file_exists($new_plugin_path) ) {
84 + // Clear the plugin cache
85 + wp_cache_delete( 'plugins', 'plugins' );
191 86
192 - $plugin_path = WP_PLUGIN_DIR . '/' . $slug;
87 + // Activate the new plugin
88 + activate_plugin( $new_plugin );
89 + }
193 90
194 - if ( ! is_dir( $plugin_path ) ) {
195 - return;
196 - }
197 -
198 - $installed_plugins = get_plugins( '/' . $slug );
199 - if ( empty( $installed_plugins ) ) {
200 - return;
201 - }
202 -
203 - $plugin_relative_path = $slug . '/' . key( $installed_plugins );
204 -
205 - if ( is_plugin_active( $plugin_relative_path ) ) {
206 - return;
207 - }
208 -
209 - activate_plugin( $plugin_relative_path );
210 - }
211 -
212 - /**
213 - * Map of legacy addon slugs that have been renamed to a new slug.
214 - *
215 - * @return array<string,string>
216 - */
217 - protected function renamed_addons_map() {
218 - return [
219 - 'sidebar-generator/adminify-sidebar-generator.php' => 'adminify-sidebar-generator/adminify-sidebar-generator.php',
220 - ];
221 - }
222 -
223 - /**
224 - * Show a non-blocking admin notice if a legacy (renamed) addon is
225 - * still installed. We never deactivate or activate plugins on the
226 - * user's behalf; the notice points them to the Plugins screen so
227 - * they can perform the swap themselves.
228 - */
229 - public function maybe_renamed_addon_notice() {
230 - if ( ! current_user_can('activate_plugins') ) {
231 - return;
232 - }
233 -
234 - $messages = [];
235 -
236 - foreach ($this->renamed_addons_map() as $old_plugin => $new_plugin) {
237 - $old_exists = file_exists(WP_PLUGIN_DIR . '/' . $old_plugin);
238 - if ( ! $old_exists ) {
239 - continue;
91 + } else {
92 + // Rename the old plugin to the new plugin
93 + rename( dirname($old_plugin_path), dirname($new_plugin_path) );
94 + }
240 95 }
241 96
242 - $messages[] = sprintf(
243 - /* translators: 1: old plugin slug, 2: new plugin slug */
244 - esc_html__('"%1$s" has been renamed to "%2$s". Please deactivate and remove the old version, then install the new one from the Adminify Addons screen.', 'adminify'),
245 - esc_html(dirname($old_plugin)),
246 - esc_html(dirname($new_plugin))
247 - );
248 97 }
249 98
250 - if ( empty($messages) ) {
251 - return;
252 - }
253 -
254 - echo '<div class="notice notice-warning"><p><strong>' . esc_html__('Adminify', 'adminify') . ':</strong> ' . esc_html(implode('<br>', $messages)) . '</p></div>';
255 99 }
256 100
257 101 /**
258 102 * Includes
@@ -260,18 +104,17 @@
260 104 * @author Jewel Theme <support@jeweltheme.com>
261 105 */
262 106 public function includes()
263 107 {
264 - // wp-load.php must never be required from within a plugin: the
265 - // plugin already runs inside WordPress. The wp-admin includes
266 - // below are required for plugin install/upgrade APIs used by
267 - // this class and are loaded with require_once immediately
268 - // before the functions from each file are called.
269 - require_once ABSPATH . 'wp-admin/includes/plugin-install.php';
270 - require_once ABSPATH . 'wp-admin/includes/file.php';
271 - require_once ABSPATH . 'wp-admin/includes/misc.php';
272 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
273 - require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
108 + // if (!function_exists('install_plugin_install_status')) {
109 + // require_once ABSPATH . 'wp-admin/includes/plugin-install.php';
110 + require_once(ABSPATH . '/wp-load.php');
111 + require_once(ABSPATH . 'wp-admin/includes/plugin-install.php');
112 + require_once(ABSPATH . 'wp-admin/includes/file.php');
113 + require_once(ABSPATH . 'wp-admin/includes/misc.php');
114 + require_once(ABSPATH . 'wp-admin/includes/plugin.php');
115 + require_once(ABSPATH . 'wp-admin/includes/class-wp-upgrader.php');
116 + // }
274 117 }
275 118
276 119 /**
277 120 * Menu Items
@@ -319,10 +162,26 @@
319 162 *
320 163 * @return void
321 164 */
322 165
323 - public function addons_check()
166 + public function jltwp_adminify_addons_check()
324 167 {
168 +
169 + $license = jltwp_adminify()->_get_license();
170 +
171 + if (!is_object($license) || !$license->is_valid() || !$license->is_active()) return;
172 +
173 + if ( $this->is_eligible_for_coupon() ) {
174 + // Get the coupon
175 + $coupon = $this->maybe_create_and_get_coupon();
176 + if (!empty($coupon) && !empty($coupon['code'])) {
177 + echo sprintf(
178 + __('<h3>Coupon Code: <strong style="color: red">%s</strong> Redeem this coupon code to get free access to all our premium addons (Except Admin Bar Editor, RoleMaster Suite and Master Addons). Learn how to <a href="https://wpadminify.com/redeem-addons-using-coupon-code/" target="_blank">redeem coupon code?</a></h3> ', 'adminify'),
179 + esc_attr($coupon['code'])
180 + );
181 + }
182 + }
183 +
325 184 echo '<style>
326 185 #fs_addons .fs-cards-list{ display: flex; }
327 186 #fs_addons .fs-cards-list .fs-card .fs-inner .fs-cta .button{
328 187 top: 112px;
@@ -331,10 +190,73 @@
331 190 border-radius: 3px !important;
332 191 }</style>';
333 192 }
334 193
194 + public function is_eligible_for_coupon() {
335 195
196 + $is_eligible = get_option('wp_adminify_addon__is_eligible_for_coupon', null);
336 197
198 + if ( $is_eligible !== null ) return wp_validate_boolean($is_eligible);
199 + $args = [
200 + 'license' => base64_encode(json_encode(jltwp_adminify()->_get_license())),
201 + 'action' => 'check_eligibility'
202 + ];
203 +
204 + $request_uri = add_query_arg($args, $this->server_url);
205 +
206 + $response = wp_remote_get($request_uri);
207 +
208 + if (!is_wp_error($response) && $response['response']['code'] === 200) {
209 + $file_contents = wp_remote_retrieve_body($response);
210 + $is_eligible = json_decode($file_contents, true);
211 + update_option('wp_adminify_addon__is_eligible_for_coupon', wp_validate_boolean($is_eligible));
212 + return $is_eligible;
213 + }
214 +
215 + return false;
216 + }
217 +
218 + public function maybe_delete_corrupted_coupon(){
219 + $coupon_delete_check = get_option('wp_adminify_addon__coupon_is_deleted', false);
220 + if($coupon_delete_check != true){
221 + delete_option('wp_adminify_addon__coupon');
222 + update_option('wp_adminify_addon__coupon_is_deleted', true);
223 + }
224 + }
225 +
226 + public function maybe_create_and_get_coupon()
227 + {
228 + $this->maybe_delete_corrupted_coupon();
229 + $coupon = get_option('wp_adminify_addon__coupon');
230 +
231 + if (!empty($coupon)) return $coupon;
232 +
233 + // communicate hit hserver get coupon
234 + $args = [
235 + 'license' => base64_encode(json_encode(jltwp_adminify()->_get_license())),
236 + 'action' => 'get_coupon'
237 + ];
238 +
239 + $response = wp_remote_get(add_query_arg($args, $this->server_url));
240 +
241 + if (!is_wp_error($response) && $response['response']['code'] === 200) {
242 +
243 + $file_contents = wp_remote_retrieve_body($response);
244 + $response_data = json_decode($file_contents, true);
245 +
246 + if (!empty($response_data) && is_array($response_data) && !empty($response_data['id']) && !empty($response_data['code']) ) {
247 + $coupon = [
248 + 'id' => $response_data['id'],
249 + 'code' => $response_data['code']
250 + ];
251 + update_option('wp_adminify_addon__coupon', $coupon);
252 + }
253 + }
254 +
255 + return $coupon;
256 + }
257 +
258 +
337 259 /**
338 260 * Header
339 261 */
340 262 public function header()
@@ -342,11 +264,11 @@
342 264 ?>
343 265 <div class='wp-adminify-addons-header'>
344 266 <div class='wp-adminify-addons-title'>
345 267 <h2>
346 - <?php echo esc_html__('Add Ons for Adminify', 'adminify'); ?>
268 + <?php echo esc_html__('Add Ons for WP Adminify', 'adminify'); ?>
347 269 </h2>
348 - <?php $this->addons_check(); ?>
270 + <?php $this->jltwp_adminify_addons_check(); ?>
349 271 </div>
350 272 <div class='wp-adminify-addons-menu'>
351 273 <div class="wp-filter">
352 274 <ul class="filter-links">
@@ -399,19 +321,10 @@
399 321 * Body
400 322 */
401 323 public function plugins()
402 324 {
403 - // $this->plugins_list is populated at construction only from the
404 - // cached catalogue, which is empty until a live fetch runs. The
405 - // Add-ons page render is itself an explicit user action, so fall
406 - // back to the bundled catalogue here so the cards always show.
407 - $plugins_list = $this->plugins_list;
408 325
409 - if ( empty( $plugins_list ) && method_exists( $this, 'get_adminify_plugins_lists' ) ) {
410 - $plugins_list = (array) $this->get_adminify_plugins_lists();
411 - }
412 -
413 - foreach ($plugins_list as $key => $plugin) {
326 + foreach ($this->plugins_list as $key => $plugin) {
414 327 $install_status = \install_plugin_install_status($plugin);
415 328 $classes = implode(' ', $plugin['type']);
416 329
417 330 $more_details = self_admin_url(
@@ -551,9 +464,9 @@
551 464 * Activate Plugins
552 465 *
553 466 * @author Jewel Theme <support@jeweltheme.com>
554 467 */
555 - public function pxlbsadminify_addons_activate_plugin()
468 + public function jltwp_adminify_addons_activate_plugin()
556 469 {
557 470 if (empty($_POST['plugin'])) {
558 471 return;
559 472 }
@@ -559,35 +472,23 @@
559 472 }
560 473 try {
561 474 $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '';
562 475
563 - if (!wp_verify_nonce($nonce, 'pxlbsadminify_addons_nonce')) {
476 + if (!wp_verify_nonce($nonce, 'jltwp_adminify_addons_nonce')) {
564 477 wp_send_json_error(array('mess' => __('Nonce is invalid', 'adminify')));
565 478 }
566 479
567 - // Security check - only administrators can activate plugins
568 - if (!current_user_can('activate_plugins')) {
569 - wp_send_json_error(array('mess' => __('You do not have permission to perform this action.', 'adminify')));
570 - }
480 + // if ((is_multisite() && !is_network_admin()) || !current_user_can('install_plugins')) {
481 + // wp_send_json_error(array('mess' => __('Invalid access', 'adminify')));
482 + // }
571 483
572 484 $plugin = sanitize_text_field(wp_unslash($_POST['plugin']));
573 485 $plugin_links = array_values(wp_list_pluck($this->plugins_list, 'slug'));
574 486
575 - if (!in_array(dirname($plugin), $plugin_links, true)) {
487 + if (!in_array(dirname($plugin), $plugin_links)) {
576 488 wp_send_json_error(array('mess' => __('Invalid plugin', 'adminify')));
577 489 }
578 490
579 - // Resolve against the list of actually installed plugins so that
580 - // only a known plugin file is ever passed to activate_plugin().
581 - if (!function_exists('get_plugins')) {
582 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
583 - }
584 - $installed_plugins = array_keys(get_plugins());
585 -
586 - if (!in_array($plugin, $installed_plugins, true)) {
587 - wp_send_json_error(array('mess' => __('Invalid plugin', 'adminify')));
588 - }
589 -
590 491 $result = activate_plugin($plugin);
591 492
592 493 if (is_wp_error($result)) {
593 494 wp_send_json_error(
@@ -645,11 +546,11 @@
645 546 * Upgrade Plugins required Libraries
646 547 *
647 548 * @author Jewel Theme <support@jeweltheme.com>
648 549 */
649 - public function pxlbsadminify_addons_upgrade_plugin( $params = null )
550 + public function jltwp_adminify_addons_upgrade_plugin()
650 551 {
651 - if ($params == null && empty($_POST['plugin'])) {
552 + if (empty($_POST['plugin'])) {
652 553 return;
653 554 }
654 555
655 556 try {
@@ -657,73 +558,48 @@
657 558 require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
658 559 require_once ABSPATH . 'wp-admin/includes/class-wp-ajax-upgrader-skin.php';
659 560 require_once ABSPATH . 'wp-admin/includes/class-plugin-upgrader.php';
660 561
661 - if($params == null){
662 - $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '';
562 + $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '';
663 563
664 - if (!wp_verify_nonce($nonce, 'pxlbsadminify_addons_nonce')) {
665 - wp_send_json_error(array('mess' => __('Nonce is invalid', 'adminify')));
666 - }
667 - $plugin = sanitize_text_field(wp_unslash($_POST['plugin']));
668 - }else{
669 - $plugin = $params['plugin'];
564 + if (!wp_verify_nonce($nonce, 'jltwp_adminify_addons_nonce')) {
565 + wp_send_json_error(array('mess' => __('Nonce is invalid', 'adminify')));
670 566 }
671 567
672 - // Security check - only administrators can install plugins
673 - if (!current_user_can('install_plugins')) {
674 - wp_send_json_error(array('mess' => __('You do not have permission to perform this action.', 'adminify')));
675 - }
568 + // if ((is_multisite() && !is_network_admin()) || !current_user_can('install_plugins')) {
569 + // wp_send_json_error(array('mess' => __('Invalid access', 'adminify')));
570 + // }
676 571
572 + $plugin = sanitize_text_field(wp_unslash($_POST['plugin']));
573 +
677 574 $plugin_slug = $this->get_the_plugin_slug( $plugin );
678 575
679 - if ( ! array_key_exists( $plugin_slug, $this->plugins_list ) ) {
576 + if ( ! array_key_exists( $plugin_slug, $this->plugins_list) ) {
680 577 wp_send_json_error(array('mess' => __('Invalid plugin', 'adminify')));
681 578 }
682 579
683 - // Replace the user-supplied $plugin value with values derived
684 - // from our trusted internal addons list, so that arbitrary
685 - // input never reaches Plugin_Upgrader::install()/upgrade() or
686 - // activate_plugin().
687 - $trusted_install_source = isset($this->plugins_list[$plugin_slug]['download_link'])
688 - ? $this->plugins_list[$plugin_slug]['download_link']
689 - : '';
690 -
691 - if($params == null){
692 - $type = isset($_POST['type']) ? sanitize_text_field(wp_unslash($_POST['type'])) : 'install';
693 - }else{
694 - $type = 'install';
695 - }
580 + $type = isset($_POST['type']) ? sanitize_text_field(wp_unslash($_POST['type'])) : 'install';
696 581 $skin = new \WP_Ajax_Upgrader_Skin();
697 582 $upgrader = new \Plugin_Upgrader($skin);
698 583
699 584 if ('install' === $type) {
700 585
701 - if ( empty( $trusted_install_source ) ) {
702 - wp_send_json_error(array('mess' => __('Invalid plugin', 'adminify')));
586 + $result = $upgrader->install($plugin);
587 +
588 + if (empty($result) || empty($upgrader->result)) {
589 + wp_send_json_error(
590 + array(
591 + 'mess' => 'Something is wrong',
592 + )
593 + );
703 594 }
704 595
705 - $result = $upgrader->install( $trusted_install_source );
706 - if ($params == null){
707 - if (empty($result) || empty($upgrader->result)) {
708 - wp_send_json_error(
709 - array(
710 - 'mess' => 'Something is wrong',
711 - )
712 - );
713 - }
714 -
715 - if (is_wp_error($result)) {
716 - wp_send_json_error(
717 - array(
718 - 'mess' => $result->get_error_message(),
719 - )
720 - );
721 - }
722 - }else{
723 - if(empty($result) || empty($upgrader->result)){
724 - return;
725 - }
596 + if (is_wp_error($result)) {
597 + wp_send_json_error(
598 + array(
599 + 'mess' => $result->get_error_message(),
600 + )
601 + );
726 602 }
727 603
728 604 $plugins = get_plugins('/' . $upgrader->result['destination_name']);
729 605 $plugin_data = end($plugins);
@@ -734,91 +610,69 @@
734 610
735 611 $install_status = \install_plugin_install_status($plugin_data);
736 612
737 613 $active_plugin = activate_plugin($install_status['file']);
738 -
739 - if ($params == null){
740 - if (is_wp_error($active_plugin)) {
741 - wp_send_json_error(
742 - array(
743 - 'mess' => $active_plugin->get_error_message(),
744 - )
745 - );
746 - } else {
747 - wp_send_json_success(
748 - array(
749 - 'mess' => __('Install success', 'adminify'),
750 - )
751 - );
752 - }
753 - }
754 - } else {
755 - if ($params == null){
614 +
615 + if (is_wp_error($active_plugin)) {
756 616 wp_send_json_error(
757 617 array(
758 - 'mess' => 'Error',
618 + 'mess' => $active_plugin->get_error_message(),
759 619 )
760 620 );
621 + } else {
622 + wp_send_json_success(
623 + array(
624 + 'mess' => __('Install success', 'adminify'),
625 + )
626 + );
627 + }
628 + } else {
761 629
762 - }
630 + wp_send_json_error(
631 + array(
632 + 'mess' => 'Error',
633 + )
634 + );
763 635 }
764 636 } else {
765 637
766 - // Resolve the trusted plugin file path from the validated
767 - // slug instead of trusting the raw $_POST value, so that
768 - // is_plugin_active(), Plugin_Upgrader::upgrade() and
769 - // activate_plugin() never receive attacker-supplied paths.
770 - $installed_plugins = get_plugins( '/' . $plugin_slug );
771 - if ( empty( $installed_plugins ) ) {
772 - wp_send_json_error(array('mess' => __('Plugin not installed.', 'adminify')));
773 - }
774 - $trusted_plugin_file = $plugin_slug . '/' . key( $installed_plugins );
638 + $is_active = is_plugin_active($plugin);
639 + $result = $upgrader->upgrade($plugin);
775 640
776 - $is_active = is_plugin_active( $trusted_plugin_file );
777 - $result = $upgrader->upgrade( $trusted_plugin_file );
778 -
779 - if ($params == null){
780 - if ( empty($result) || is_wp_error($result) ) {
781 - wp_send_json_error(
782 - array(
783 - 'mess' => is_wp_error($result) ? $result->get_error_message() : __('Couldn\'t upgrade', 'adminify')
784 - )
785 - );
786 - }
641 + if ( empty($result) || is_wp_error($result) ) {
642 + wp_send_json_error(
643 + array(
644 + 'mess' => is_wp_error($result) ? $result->get_error_message() : __('Couldn\'t upgrade', 'adminify')
645 + )
646 + );
787 647 }
788 648
789 - $active_status = activate_plugin( $trusted_plugin_file );
649 + $active_status = activate_plugin($plugin);
790 650
791 - if ($params == null){
792 - if ( empty($active_status) || is_wp_error($active_status) ) {
793 - wp_send_json_error(
794 - array(
795 - 'mess' => is_wp_error($result) ? $result->get_error_message() : __('Activation Failed', 'adminify')
796 - )
797 - );
798 - }
799 -
800 - wp_send_json_success(
651 + if ( empty($active_status) || is_wp_error($active_status) ) {
652 + wp_send_json_error(
801 653 array(
802 - 'mess' => __('Update success', 'adminify'),
803 - 'active' => true,
654 + 'mess' => is_wp_error($result) ? $result->get_error_message() : __('Activation Failed', 'adminify')
804 655 )
805 656 );
806 657 }
807 - }
808 -
809 - } catch (\Exception $ex) {
810 - if ($params == null){
811 - wp_send_json_error(
658 +
659 + wp_send_json_success(
812 660 array(
813 - 'mess' => __('Error exception.', 'adminify'),
814 - array(
815 - 'error' => $ex,
816 - ),
661 + 'mess' => __('Update success', 'adminify'),
662 + 'active' => true,
817 663 )
818 664 );
819 665 }
666 + } catch (\Exception $ex) {
667 + wp_send_json_error(
668 + array(
669 + 'mess' => __('Error exception.', 'adminify'),
670 + array(
671 + 'error' => $ex,
672 + ),
673 + )
674 + );
820 675 }
821 676 }
822 -
823 677 }
824 678 }