| @@ -148,9 +148,13 @@ | ||
| 148 | 148 | } |
| 149 | 149 | ?> |
| 150 | 150 | |
| 151 | 151 | <fieldset class="metabox-prefs"> |
| 152 | - <legend><?php esc_html_e( 'Boxes' ); ?></legend> | |
| 152 | + <legend><?php esc_html_e( 'Screen elements' ); ?></legend> | |
| 153 | + <p> | |
| 154 | + <?php esc_html_e( 'Some screen elements can be shown or hidden by using the checkboxes.' ); ?> | |
| 155 | + <?php esc_html_e( 'Expand or collapse the elements by clicking on their headings, and arrange them by dragging their headings or by clicking on the up and down arrows.' ); ?> | |
| 156 | + </p> | |
| 153 | 157 | <?php meta_box_prefs( $ct_table->name ); ?> |
| 154 | 158 | </fieldset> |
| 155 | 159 | |
| 156 | 160 | <?php |
| @@ -182,9 +186,12 @@ | ||
| 182 | 186 | ?> |
| 183 | 187 | <label class="columns-prefs-<?php echo esc_attr ( $i ); ?>"> |
| 184 | 188 | <input type='radio' name='screen_columns' value='<?php echo esc_attr( $i ); ?>' |
| 185 | 189 | <?php checked( $screen_layout_columns, $i ); ?> /> |
| 186 | - <?php printf( _n( '%s column', '%s columns', $i ), number_format_i18n( $i ) ); ?> | |
| 190 | + <?php | |
| 191 | + // translators: %s: Column name | |
| 192 | + echo esc_html( sprintf( _n( '%s column', '%s columns', $i ), number_format_i18n( $i ) ) ); | |
| 193 | + ?> | |
| 187 | 194 | </label> |
| 188 | 195 | <?php |
| 189 | 196 | endfor; ?> |
| 190 | 197 | </fieldset> |
| @@ -296,14 +303,14 @@ | ||
| 296 | 303 | if ( current_user_can( $ct_table->cap->delete_item, $object_id ) ) { |
| 297 | 304 | |
| 298 | 305 | printf( |
| 299 | 306 | '<a href="%s" class="submitdelete deletion" onclick="%s" aria-label="%s">%s</a>', |
| 300 | - ct_get_delete_link( $ct_table->name, $object_id ), | |
| 307 | + esc_attr( ct_get_delete_link( $ct_table->name, $object_id ) ), | |
| 301 | 308 | "return confirm('" . |
| 302 | 309 | esc_attr( ct_get_table_label( $ct_table->name, 'delete_item_confirm' ) ) . |
| 303 | 310 | "');", |
| 304 | 311 | esc_attr( __( 'Delete permanently' ) ), |
| 305 | - __( 'Delete Permanently' ) | |
| 312 | + esc_html__( 'Delete Permanently' ) | |
| 306 | 313 | ); |
| 307 | 314 | |
| 308 | 315 | } ?> |
| 309 | 316 | |
| @@ -353,34 +360,30 @@ | ||
| 353 | 360 | global $ct_registered_tables, $ct_table; |
| 354 | 361 | |
| 355 | 362 | // If not CT object, die |
| 356 | 363 | if ( ! $ct_table ) |
| 357 | - wp_die( esc_html__( 'Invalid item type.' ) ); | |
| 364 | + wp_die( esc_html__( 'Invalid object type.' ) ); | |
| 358 | 365 | |
| 359 | 366 | // If not CT object allow ui, die |
| 360 | 367 | if ( ! $ct_table->show_ui ) { |
| 361 | - wp_die( esc_html__( 'Sorry, you are not allowed to edit items of this type.' ) ); | |
| 368 | + wp_die( esc_html( ct_get_table_label( $ct_table->name, 'edit_items_not_allowed' ) ) ); | |
| 362 | 369 | } |
| 363 | 370 | |
| 364 | 371 | $primary_key = $ct_table->db->primary_key; |
| 365 | 372 | |
| 366 | 373 | if( ! isset( $_POST[$primary_key] ) ) { |
| 367 | - wp_die( esc_html__( 'Invalid item type.' ) ); | |
| 374 | + wp_die( esc_html__( 'Invalid object type.' ) ); | |
| 368 | 375 | } |
| 369 | 376 | |
| 370 | 377 | $object_id = $_POST[$primary_key]; |
| 371 | 378 | |
| 372 | 379 | // Nonce check |
| 373 | - if ( ! isset( $_REQUEST['_wpnonce'] ) ) { | |
| 374 | - wp_die( esc_html__( 'Sorry, you are not allowed to edit this item.' ) ); | |
| 380 | + if ( ! isset( $_REQUEST['_wpnonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash ( $_REQUEST['_wpnonce'] ) ), 'ct_edit_' . $object_id ) ) { | |
| 381 | + wp_die( esc_html( ct_get_table_label( $ct_table->name, 'edit_item_not_allowed' ) ) ); | |
| 375 | 382 | } |
| 376 | 383 | |
| 377 | - if ( ! wp_verify_nonce( sanitize_text_field( wp_unslash ( $_REQUEST['_wpnonce'] ) ), 'ct_edit_' . $object_id ) ) { | |
| 378 | - wp_die( esc_html__( 'Sorry, you are not allowed to edit this item.' ) ); | |
| 379 | - } | |
| 384 | + $object_data = map_deep( $_POST, 'wp_kses_post' ); | |
| 380 | 385 | |
| 381 | - $object_data = map_deep( $_POST, 'wp_kses_post' ); | |
| 382 | - | |
| 383 | 386 | unset( $object_data['ct-save'] ); |
| 384 | 387 | |
| 385 | 388 | $success = ct_update_object( $object_data ); |
| 386 | 389 | |
| @@ -401,10 +404,10 @@ | ||
| 401 | 404 | |
| 402 | 405 | global $ct_registered_tables, $ct_table; |
| 403 | 406 | |
| 404 | 407 | $messages = array( |
| 405 | - 0 => __( '%s could not be updated.' ), | |
| 406 | - 1 => __( '%s updated successfully.' ), | |
| 408 | + 0 => ct_get_table_label( $ct_table->name, 'update_error' ), | |
| 409 | + 1 => ct_get_table_label( $ct_table->name, 'update_success' ), | |
| 407 | 410 | ); |
| 408 | 411 | |
| 409 | 412 | /** |
| 410 | 413 | * Filters the table updated messages (string keys allowed!). |