PluginProbe
Adminify – White Label, Admin Menu Editor, Login Customizer / 4.3.0
Adminify – White Label, Admin Menu Editor, Login Customizer v4.3.0
4.3.1 4.3.0 4.2.26 4.2.25 4.2.24 4.2.23 4.2.22 4.2.21 4.2.20 4.2.19 4.2.18 4.2.17 4.2.16 4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 4.1.17 All 164 releases
adminify / Libs / adminify-framework / classes / comment-options.class.php

comment-options.class.php in Adminify – White Label, Admin Menu Editor, Login Customizer 4.3.0, at Libs/adminify-framework/classes/comment-options.class.php

345 lines 11.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php if ( ! defined( 'ABSPATH' ) ) { die; } // Cannot access directly.
2 /**
3 *
4 * Comment Metabox Class
5 *
6 * @since 1.0.0
7 * @version 1.0.0
8 *
9 */
10 if ( ! class_exists( 'ADMINIFY_Comment_Metabox' ) ) {
11 class ADMINIFY_Comment_Metabox extends ADMINIFY_Abstract{
12
13 // constans
14 public $unique = '';
15 public $abstract = 'comment_metabox';
16 public $sections = array();
17 public $pre_fields = array();
18 public $args = array(
19 'title' => '',
20 'data_type' => 'serialize',
21 'priority' => 'default',
22 'show_reset' => false,
23 'show_restore' => false,
24 'nav' => 'normal',
25 'theme' => 'dark',
26 'class' => '',
27 'defaults' => array(),
28 );
29
30 // run comment metabox construct
31 public function __construct( $key, $params = array() ) {
32
33 $this->unique = $key;
34 $this->args = apply_filters( "adminify_{$this->unique}_args", wp_parse_args( $params['args'], $this->args ), $this );
35 $this->sections = apply_filters( "adminify_{$this->unique}_sections", $params['sections'], $this );
36 $this->pre_fields = $this->pre_fields( $this->sections );
37
38 add_action( 'add_meta_boxes_comment', array( $this, 'add_comment_meta_box' ) );
39 add_action( 'edit_comment', array( $this, 'save_comment_meta_box' ) );
40
41 if ( ! empty( $this->args['class'] ) ) {
42 add_filter( 'postbox_classes_comment_'. $this->unique, array( $this, 'add_comment_metabox_classes' ) );
43 }
44
45 }
46
47 // instance
48 public static function instance( $key, $params = array() ) {
49 return new self( $key, $params );
50 }
51
52 public function add_comment_metabox_classes( $classes ) {
53
54 if ( ! empty( $this->args['class'] ) ) {
55 $classes[] = $this->args['class'];
56 }
57
58 return $classes;
59
60 }
61
62 // add comment metabox
63 public function add_comment_meta_box( $post_type ) {
64
65 add_meta_box( $this->unique, $this->args['title'], array( $this, 'add_comment_meta_box_content' ), 'comment', 'normal', $this->args['priority'], $this->args );
66
67 }
68
69 // get default value
70 public function get_default( $field ) {
71
72 $default = ( isset( $field['default'] ) ) ? $field['default'] : '';
73 $default = ( isset( $this->args['defaults'][$field['id']] ) ) ? $this->args['defaults'][$field['id']] : $default;
74
75 return $default;
76
77 }
78
79 // get meta value
80 public function get_meta_value( $comment_id, $field ) {
81
82 $value = null;
83
84 if ( ! empty( $comment_id ) && ! empty( $field['id'] ) ) {
85
86 if ( $this->args['data_type'] !== 'serialize' ) {
87 $meta = get_comment_meta( $comment_id, $field['id'] );
88 $value = ( isset( $meta[0] ) ) ? $meta[0] : null;
89 } else {
90 $meta = get_comment_meta( $comment_id, $this->unique, true );
91 $value = ( isset( $meta[$field['id']] ) ) ? $meta[$field['id']] : null;
92 }
93
94 }
95
96 $default = ( isset( $field['id'] ) ) ? $this->get_default( $field ) : '';
97 $value = ( isset( $value ) ) ? $value : $default;
98
99 return $value;
100
101 }
102
103 // add comment metabox content
104 public function add_comment_meta_box_content( $comment, $callback ) {
105
106 $has_nav = ( count( $this->sections ) > 1 ) ? true : false;
107 $show_all = ( ! $has_nav ) ? ' adminify-show-all' : '';
108 $errors = ( is_object ( $comment ) ) ? get_comment_meta( $comment->comment_ID, '_adminify_errors_'. $this->unique, true ) : array();
109 $errors = ( ! empty( $errors ) ) ? $errors : array();
110 $theme = ( $this->args['theme'] ) ? ' adminify-theme-'. $this->args['theme'] : '';
111 $nav_type = ( $this->args['nav'] === 'inline' ) ? 'inline' : 'normal';
112
113 if ( is_object( $comment ) && ! empty( $errors ) ) {
114 delete_comment_meta( $comment->comment_ID, '_adminify_errors_'. $this->unique );
115 }
116
117 wp_nonce_field( 'adminify_comment_metabox_nonce', 'adminify_comment_metabox_nonce'. $this->unique );
118
119 echo '<div class="adminify adminify-comment-metabox'. esc_attr( $theme ) .'">';
120
121 echo '<div class="adminify-wrapper'. esc_attr( $show_all ) .'">';
122
123 if ( $has_nav ) {
124
125 echo '<div class="adminify-nav adminify-nav-'. esc_attr( $nav_type ) .' adminify-nav-metabox">';
126
127 echo '<ul>';
128
129 $tab_key = 1;
130
131 foreach ( $this->sections as $section ) {
132
133 $tab_icon = ( ! empty( $section['icon'] ) ) ? '<i class="adminify-tab-icon '. esc_attr( $section['icon'] ) .'"></i>' : '';
134 $tab_error = ( ! empty( $errors['sections'][$tab_key] ) ) ? '<i class="adminify-label-error adminify-error">!</i>' : '';
135
136 echo '<li><a href="#">'. wp_kses_post( $tab_icon ) . esc_html( $section['title'] ) . wp_kses_post( $tab_error ) .'</a></li>';
137
138 $tab_key++;
139
140 }
141
142 echo '</ul>';
143
144 echo '</div>';
145
146 }
147
148 echo '<div class="adminify-content">';
149
150 echo '<div class="adminify-sections">';
151
152 $section_key = 1;
153
154 foreach ( $this->sections as $section ) {
155
156 $section_onload = ( ! $has_nav ) ? ' adminify-onload' : '';
157 $section_class = ( ! empty( $section['class'] ) ) ? ' '. $section['class'] : '';
158 $section_title = ( ! empty( $section['title'] ) ) ? $section['title'] : '';
159 $section_icon = ( ! empty( $section['icon'] ) ) ? '<i class="adminify-section-icon '. esc_attr( $section['icon'] ) .'"></i>' : '';
160
161 echo '<div class="adminify-section hidden'. esc_attr( $section_onload . $section_class ) .'">';
162
163 echo ( $section_title || $section_icon ) ? '<div class="adminify-section-title"><h3>'. wp_kses_post( $section_icon ) . esc_html( $section_title ) .'</h3></div>' : '';
164 echo ( ! empty( $section['description'] ) ) ? '<div class="adminify-field adminify-section-description">'. wp_kses_post( $section['description'] ) .'</div>' : '';
165
166 if ( ! empty( $section['fields'] ) ) {
167
168 foreach ( $section['fields'] as $field ) {
169
170 if ( ! empty( $field['id'] ) && ! empty( $errors['fields'][$field['id']] ) ) {
171 $field['_error'] = $errors['fields'][$field['id']];
172 }
173
174 if ( ! empty( $field['id'] ) ) {
175 $field['default'] = $this->get_default( $field );
176 }
177
178 ADMINIFY::field( $field, $this->get_meta_value( $comment->comment_ID, $field ), $this->unique, 'comment_metabox' );
179
180 }
181
182 } else {
183
184 echo '<div class="adminify-no-option">'. esc_html__( 'No data available.', 'adminify' ) .'</div>';
185
186 }
187
188 echo '</div>';
189
190 $section_key++;
191
192 }
193
194 echo '</div>';
195
196 if ( ! empty( $this->args['show_restore'] ) || ! empty( $this->args['show_reset'] ) ) {
197
198 echo '<div class="adminify-sections-reset">';
199 echo '<label>';
200 echo '<input type="checkbox" name="'. esc_attr( $this->unique ) .'[_reset]" />';
201 echo '<span class="button adminify-button-reset">'. esc_html__( 'Reset', 'adminify' ) .'</span>';
202 echo '<span class="button adminify-button-cancel">'. sprintf( '<small>( %s )</small> %s', esc_html__( 'update post', 'adminify' ), esc_html__( 'Cancel', 'adminify' ) ) .'</span>';
203 echo '</label>';
204 echo '</div>';
205
206 }
207
208 echo '</div>';
209
210 echo ( $has_nav && $nav_type === 'normal' ) ? '<div class="adminify-nav-background"></div>' : '';
211
212 echo '<div class="clear"></div>';
213
214 echo '</div>';
215
216 echo '</div>';
217
218 }
219
220 // save comment metabox
221 public function save_comment_meta_box( $comment_id ) {
222
223 $count = 1;
224 $data = array();
225 $errors = array();
226 $noncekey = 'adminify_comment_metabox_nonce'. $this->unique;
227 $nonce = ( ! empty( $_POST[ $noncekey ] ) ) ? sanitize_text_field( wp_unslash( $_POST[ $noncekey ] ) ) : '';
228
229 if ( ( defined( 'DOING_AUTOSAVE' ) && DOING_AUTOSAVE ) || ! wp_verify_nonce( $nonce, 'adminify_comment_metabox_nonce' ) ) {
230 return $comment_id;
231 }
232
233 // Authorization: a valid nonce proves intent, not permission.
234 if ( ! current_user_can( 'edit_comment', $comment_id ) ) {
235 return $comment_id;
236 }
237
238 // XSS ok.
239 // No worries, This "POST" requests is sanitizing in the below foreach.
240 $request = ( ! empty( $_POST[ $this->unique ] ) ) ? wp_unslash( $_POST[ $this->unique ] ) : array(); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- each field is sanitized individually by the framework's per-field sanitize handlers.
241
242 if ( ! empty( $request ) ) {
243
244 foreach ( $this->sections as $section ) {
245
246 if ( ! empty( $section['fields'] ) ) {
247
248 foreach ( $section['fields'] as $field ) {
249
250 if ( ! empty( $field['id'] ) ) {
251
252 $field_id = $field['id'];
253 $field_value = isset( $request[$field_id] ) ? $request[$field_id] : '';
254
255 // Sanitize "post" request of field.
256 if ( ! isset( $field['sanitize'] ) ) {
257
258 if( is_array( $field_value ) ) {
259 $data[$field_id] = wp_kses_post_deep( $field_value );
260 } else {
261 $data[$field_id] = wp_kses_post( $field_value );
262 }
263
264 } else if( isset( $field['sanitize'] ) && is_callable( $field['sanitize'] ) ) {
265
266 $data[$field_id] = call_user_func( $field['sanitize'], $field_value );
267
268 } else {
269
270 // A sanitize callback was declared but is not callable; never store raw input.
271 if ( is_array( $field_value ) ) {
272 $data[$field_id] = wp_kses_post_deep( $field_value );
273 } else {
274 $data[$field_id] = wp_kses_post( $field_value );
275 }
276
277 }
278
279 // Validate "post" request of field.
280 if ( isset( $field['validate'] ) && is_callable( $field['validate'] ) ) {
281
282 $has_validated = call_user_func( $field['validate'], $field_value );
283
284 if ( ! empty( $has_validated ) ) {
285
286 $errors['sections'][$count] = true;
287 $errors['fields'][$field_id] = $has_validated;
288 $data[$field_id] = $this->get_meta_value( $comment_id, $field );
289
290 }
291
292 }
293
294 }
295
296 }
297
298 }
299
300 $count++;
301
302 }
303
304 }
305
306 $data = apply_filters( "adminify_{$this->unique}_save", $data, $comment_id, $this );
307
308 do_action( "adminify_{$this->unique}_save_before", $data, $comment_id, $this );
309
310 if ( empty( $data ) || ! empty( $request['_reset'] ) ) {
311
312 if ( $this->args['data_type'] !== 'serialize' ) {
313 foreach ( $this->pre_fields as $field ) {
314 if ( ! empty( $field['id'] ) ) {
315 delete_comment_meta( $comment_id, $field['id'] );
316 }
317 }
318 } else {
319 delete_comment_meta( $comment_id, $this->unique );
320 }
321
322 } else {
323
324 if ( $this->args['data_type'] !== 'serialize' ) {
325 foreach ( $data as $key => $value ) {
326 update_comment_meta( $comment_id, $key, $value );
327 }
328 } else {
329 update_comment_meta( $comment_id, $this->unique, $data );
330 }
331
332 if ( ! empty( $errors ) ) {
333 update_comment_meta( $comment_id, '_adminify_errors_'. $this->unique, $errors );
334 }
335
336 }
337
338 do_action( "adminify_{$this->unique}_saved", $data, $comment_id, $this );
339
340 do_action( "adminify_{$this->unique}_save_after", $data, $comment_id, $this );
341
342 }
343 }
344 }
345