| @@ -52,17 +52,17 @@ | ||
| 52 | 52 | |
| 53 | 53 | if ( ! empty( $_REQUEST['orderby'] ) ) { |
| 54 | 54 | if ( is_array( $_REQUEST['orderby'] ) ) { |
| 55 | 55 | foreach ( $_REQUEST['orderby'] as $key => $value ) { |
| 56 | - echo '<input type="hidden" name="orderby[' . esc_attr( $key ) . ']" value="' . esc_attr( $value ) . '" />'; | |
| 56 | + echo '<input type="hidden" name="orderby[' . esc_attr( sanitize_text_field( wp_unslash( $key ) ) ) . ']" value="' . esc_attr( sanitize_text_field( wp_unslash( $value ) ) ) . '" />'; | |
| 57 | 57 | } |
| 58 | 58 | } else { |
| 59 | - echo '<input type="hidden" name="orderby" value="' . esc_attr( $_REQUEST['orderby'] ) . '" />'; | |
| 59 | + echo '<input type="hidden" name="orderby" value="' . esc_attr( sanitize_text_field( wp_unslash( $_REQUEST['orderby'] ) ) ) . '" />'; | |
| 60 | 60 | } |
| 61 | 61 | } |
| 62 | 62 | |
| 63 | 63 | if ( ! empty( $_REQUEST['order'] ) ) { |
| 64 | - echo '<input type="hidden" name="order" value="' . esc_attr( sanitize_text_field( $_REQUEST['order'] ) ) . '" />'; | |
| 64 | + echo '<input type="hidden" name="order" value="' . esc_attr( sanitize_text_field( wp_unslash( $_REQUEST['order'] ) ) ) . '" />'; | |
| 65 | 65 | } |
| 66 | 66 | ?> |
| 67 | 67 | <p class="search-box"> |
| 68 | 68 | <label class="screen-reader-text" for="<?php echo esc_attr( $input_id ); ?>"><?php echo $text; ?>:</label> |
| @@ -125,9 +125,9 @@ | ||
| 125 | 125 | $list_link = add_query_arg( '_ctviewnonce', wp_create_nonce( 'ct_views_filter' ), $list_link ); |
| 126 | 126 | $current = ''; |
| 127 | 127 | |
| 128 | 128 | if( isset( $_GET['_ctviewnonce'] ) && wp_verify_nonce( sanitize_text_field( wp_unslash ( $_GET['_ctviewnonce'] ) ), 'ct_views_filter' ) ) { |
| 129 | - $current = isset( $_GET[$field_id] ) ? sanitize_text_field( $_GET[$field_id] ) : ''; | |
| 129 | + $current = isset( $_GET[$field_id] ) ? sanitize_text_field( wp_unslash( $_GET[$field_id] ) ) : ''; | |
| 130 | 130 | } |
| 131 | 131 | |
| 132 | 132 | // Setup the 'All' view |
| 133 | 133 | $all_count = absint( $wpdb->get_var( "SELECT COUNT( * ) FROM {$ct_table->db->table_name}" ) ); |
| @@ -198,8 +198,10 @@ | ||
| 198 | 198 | * @since 1.0.0 |
| 199 | 199 | * |
| 200 | 200 | * @param string $which The location of the extra table nav markup: 'top' or 'bottom'. |
| 201 | 201 | */ |
| 202 | + do_action( "ct_manage_{$ct_table->name}_extra_tablenav", $which ); | |
| 203 | + // Backward compatibility | |
| 202 | 204 | do_action( "manage_{$ct_table->name}_extra_tablenav", $which ); |
| 203 | 205 | |
| 204 | 206 | } |
| 205 | 207 | |
| @@ -237,9 +239,11 @@ | ||
| 237 | 239 | * |
| 238 | 240 | * @param array $posts_columns An array of column names. |
| 239 | 241 | * @param CT_Table $ct_table The table object. |
| 240 | 242 | */ |
| 241 | - return apply_filters( "manage_{$ct_table->name}_columns", $columns, $ct_table ); | |
| 243 | + // Backward Compatibility | |
| 244 | + $columns = apply_filters( "manage_{$ct_table->name}_columns", $columns, $ct_table ); | |
| 245 | + return apply_filters( "ct_manage_{$ct_table->name}_columns", $columns, $ct_table ); | |
| 242 | 246 | } |
| 243 | 247 | |
| 244 | 248 | /** |
| 245 | 249 | * Retrieve the table's sortable columns |
| @@ -266,9 +270,11 @@ | ||
| 266 | 270 | * |
| 267 | 271 | * @param array $sortable_columns An array of column names. |
| 268 | 272 | * @param CT_Table $ct_table The table object. |
| 269 | 273 | */ |
| 270 | - return apply_filters( "manage_{$ct_table->name}_sortable_columns", $sortable_columns, $ct_table ); | |
| 274 | + // Backward Compatibility | |
| 275 | + $sortable_columns = apply_filters( "manage_{$ct_table->name}_sortable_columns", $sortable_columns, $ct_table ); | |
| 276 | + return apply_filters( "ct_manage_{$ct_table->name}_sortable_columns", $sortable_columns, $ct_table ); | |
| 271 | 277 | } |
| 272 | 278 | |
| 273 | 279 | /** |
| 274 | 280 | * This function renders most of the columns in the list table. |
| @@ -299,8 +305,10 @@ | ||
| 299 | 305 | * @param int $object_id The current object ID. |
| 300 | 306 | * @param stdClass $object The current object. |
| 301 | 307 | * @param CT_Table $ct_table The CT table object. |
| 302 | 308 | */ |
| 309 | + do_action( "ct_manage_{$ct_table->name}_custom_column", $column_name, $item->$primary_key, $item, $ct_table ); | |
| 310 | + // Backward Compatibility | |
| 303 | 311 | do_action( "manage_{$ct_table->name}_custom_column", $column_name, $item->$primary_key, $item, $ct_table ); |
| 304 | 312 | $custom_output = ob_get_clean(); |
| 305 | 313 | |
| 306 | 314 | if( ! empty( $custom_output ) ) { |
| @@ -319,8 +327,9 @@ | ||
| 319 | 327 | |
| 320 | 328 | // Turns first column into a text link with url to edit the item |
| 321 | 329 | $value = sprintf( '<strong><a href="%s" aria-label="%s">%s</a></strong>', |
| 322 | 330 | esc_attr( ct_get_edit_link( $ct_table->name, $item->$primary_key ) ), |
| 331 | + // translators: %s: value | |
| 323 | 332 | esc_attr( sprintf( __( 'Edit “%s”' ), $value ) ), |
| 324 | 333 | $value |
| 325 | 334 | ); |
| 326 | 335 | |
| @@ -405,19 +414,17 @@ | ||
| 405 | 414 | $primary_key = $ct_table->db->primary_key; |
| 406 | 415 | |
| 407 | 416 | if ( current_user_can( $ct_table->cap->edit_items ) ): ?> |
| 408 | 417 | <label class="screen-reader-text" for="cb-select-<?php echo esc_attr( $item->$primary_key ); ?>"><?php |
| 409 | - echo sprintf( __( 'Select Item #%d' ), $item->$primary_key ); | |
| 418 | + // translators: %d: item ID | |
| 419 | + echo esc_html( sprintf( ct_get_table_label( $ct_table->name, 'select_item' ), $item->$primary_key ) ); | |
| 410 | 420 | ?></label> |
| 411 | 421 | <input id="cb-select-<?php echo esc_attr( $item->$primary_key ); ?>" type="checkbox" name="item[]" value="<?php echo esc_attr( $item->$primary_key ); ?>" /> |
| 412 | 422 | <div class="locked-indicator"> |
| 413 | 423 | <span class="locked-indicator-icon" aria-hidden="true"></span> |
| 414 | 424 | <span class="screen-reader-text"><?php |
| 415 | - echo esc_html( sprintf( | |
| 416 | 425 | /* translators: %d: item ID */ |
| 417 | - __( '“Item #%d” is locked' ), | |
| 418 | - $item->$primary_key | |
| 419 | - ) ); | |
| 426 | + echo esc_html( sprintf( ct_get_table_label( $ct_table->name, 'item_locked' ), $item->$primary_key ) ); | |
| 420 | 427 | ?></span> |
| 421 | 428 | </div> |
| 422 | 429 | <?php endif; |
| 423 | 430 | } |