| @@ -7,14 +7,19 @@ | ||
| 7 | 7 | * Main function to render the rules panel. |
| 8 | 8 | */ |
| 9 | 9 | function ao_ccss_render_rules() { |
| 10 | 10 | // Attach required arrays. |
| 11 | - global $ao_ccss_rules; | |
| 12 | - global $ao_ccss_types; | |
| 13 | -?> | |
| 11 | + $criticalcss = autoptimize()->criticalcss(); | |
| 12 | + $ao_ccss_rules = sanitize_rules( $criticalcss->get_option( 'rules' ) ); | |
| 13 | + $ao_ccss_types = $criticalcss->get_types(); | |
| 14 | + | |
| 15 | + if ( empty( $ao_ccss_types ) || ! is_array( $ao_ccss_types ) ) { | |
| 16 | + $ao_ccss_types = array( 'No conditionals, check CSS optimization settings.' ); | |
| 17 | + } | |
| 18 | + ?> | |
| 14 | 19 | <ul id="rules-panel"> |
| 15 | 20 | <li class="itemDetail"> |
| 16 | - <h2 class="itemTitle"><?php _e( 'Rules', 'autoptimize' ); ?></h2> | |
| 21 | + <h2 class="itemTitle"><?php esc_html_e( 'Rules', 'autoptimize' ); ?></h2> | |
| 17 | 22 | |
| 18 | 23 | <!-- BEGIN Rule dialogs --> |
| 19 | 24 | <!-- Unsaved dialog --> |
| 20 | 25 | <div id="unSavedWarning" class="hidden updated settings-error notice notice-warning is-dismissible"> |
| @@ -25,33 +30,33 @@ | ||
| 25 | 30 | <div id="addEditCritCss" class="hidden"> |
| 26 | 31 | <table class="form-table rules"> |
| 27 | 32 | <tr id="critcss_addedit_type_wrapper"> |
| 28 | 33 | <th scope="row"> |
| 29 | - <?php _e( 'Rule Type', 'autoptimize' ); ?> | |
| 34 | + <?php esc_html_e( 'Rule Type', 'autoptimize' ); ?> | |
| 30 | 35 | </th> |
| 31 | 36 | <td> |
| 32 | 37 | <select id="critcss_addedit_type" style="width:100%;"> |
| 33 | - <option value="paths"><?php _e( 'Path', 'autoptimize' ); ?></option> | |
| 34 | - <option value="types"><?php _e( 'Conditional Tag', 'autoptimize' ); ?></option> | |
| 38 | + <option value="paths"><?php esc_html_e( 'Path', 'autoptimize' ); ?></option> | |
| 39 | + <option value="types"><?php esc_html_e( 'Conditional Tag', 'autoptimize' ); ?></option> | |
| 35 | 40 | </select> |
| 36 | 41 | </td> |
| 37 | 42 | </tr> |
| 38 | 43 | <tr id="critcss_addedit_path_wrapper"> |
| 39 | 44 | <th scope="row"> |
| 40 | - <?php _e( 'String in Path', 'autoptimize' ); ?> | |
| 45 | + <?php esc_html_e( 'String in Path', 'autoptimize' ); ?> | |
| 41 | 46 | </th> |
| 42 | 47 | <td> |
| 43 | - <input type="text" id="critcss_addedit_path" placeholder="<?php _e( "Enter a part of the URL that identifies the page(s) you're targetting.", 'autoptimize' ); ?>" style="width:100%;" value=""> | |
| 48 | + <input type="text" id="critcss_addedit_path" placeholder="<?php esc_html_e( "Enter a part of the URL that identifies the page(s) you're targetting.", 'autoptimize' ); ?>" style="width:100%;" value=""> | |
| 44 | 49 | </td> |
| 45 | 50 | </tr> |
| 46 | 51 | <tr id="critcss_addedit_pagetype_wrapper"> |
| 47 | 52 | <th scope="row"> |
| 48 | - <?php _e( 'Conditional Tag, Custom Post Type or Page Template', 'autoptimize' ); ?> | |
| 53 | + <?php esc_html_e( 'Conditional Tag, Custom Post Type or Page Template', 'autoptimize' ); ?> | |
| 49 | 54 | </th> |
| 50 | 55 | <td> |
| 51 | 56 | <select id="critcss_addedit_pagetype" style="width:100%;"> |
| 52 | - <option value="" disabled selected><?php _e( 'Select from the list below...', 'autoptimize' ); ?></option> | |
| 53 | - <optgroup label="<?php _e( 'Standard Conditional Tags', 'autoptimize' ); ?>"> | |
| 57 | + <option value="" disabled selected><?php esc_html_e( 'Select from the list below...', 'autoptimize' ); ?></option> | |
| 58 | + <optgroup label="<?php esc_html_e( 'Standard Conditional Tags', 'autoptimize' ); ?>"> | |
| 54 | 59 | <?php |
| 55 | 60 | // Render grouped simple conditional tags. |
| 56 | 61 | foreach ( $ao_ccss_types as $ctag ) { |
| 57 | 62 | $optgrp = substr( $ctag, 0, 3 ); |
| @@ -71,29 +76,29 @@ | ||
| 71 | 76 | </optgroup> |
| 72 | 77 | <?php |
| 73 | 78 | if ( substr( $type, 0, 12 ) === 'custom_post_' ) { |
| 74 | 79 | ?> |
| 75 | - <optgroup label="<?php _e( 'Custom Post Types', 'autoptimize' ); ?>"> | |
| 80 | + <optgroup label="<?php esc_html_e( 'Custom Post Types', 'autoptimize' ); ?>"> | |
| 76 | 81 | <?php |
| 77 | 82 | } elseif ( substr( $type, 0, 9 ) === 'template_' ) { |
| 78 | 83 | ?> |
| 79 | - <optgroup label="<?php _e( 'Page Templates', 'autoptimize' ); ?>"> | |
| 84 | + <optgroup label="<?php esc_html_e( 'Page Templates', 'autoptimize' ); ?>"> | |
| 80 | 85 | <?php |
| 81 | 86 | } elseif ( substr( $type, 0, 4 ) === 'bbp_' ) { |
| 82 | 87 | ?> |
| 83 | - <optgroup label="<?php _e( 'BBPress Conditional Tags', 'autoptimize' ); ?>"> | |
| 88 | + <optgroup label="<?php esc_html_e( 'BBPress Conditional Tags', 'autoptimize' ); ?>"> | |
| 84 | 89 | <?php |
| 85 | 90 | } elseif ( substr( $type, 0, 3 ) === 'bp_' ) { |
| 86 | 91 | ?> |
| 87 | - <optgroup label="<?php _e( 'BuddyPress Conditional Tags', 'autoptimize' ); ?>"> | |
| 92 | + <optgroup label="<?php esc_html_e( 'BuddyPress Conditional Tags', 'autoptimize' ); ?>"> | |
| 88 | 93 | <?php |
| 89 | 94 | } elseif ( substr( $type, 0, 4 ) === 'edd_' ) { |
| 90 | 95 | ?> |
| 91 | - <optgroup label="<?php _e( 'Easy Digital Downloads Conditional Tags', 'autoptimize' ); ?>"> | |
| 96 | + <optgroup label="<?php esc_html_e( 'Easy Digital Downloads Conditional Tags', 'autoptimize' ); ?>"> | |
| 92 | 97 | <?php |
| 93 | 98 | } elseif ( substr( $type, 0, 4 ) === 'woo_' ) { |
| 94 | 99 | ?> |
| 95 | - <optgroup label="<?php _e( 'WooCommerce Conditional Tags', 'autoptimize' ); ?>"> | |
| 100 | + <optgroup label="<?php esc_html_e( 'WooCommerce Conditional Tags', 'autoptimize' ); ?>"> | |
| 96 | 101 | <?php |
| 97 | 102 | } |
| 98 | 103 | } |
| 99 | 104 | |
| @@ -103,11 +108,11 @@ | ||
| 103 | 108 | if ( substr( $type, 0, 12 ) === 'custom_post_' ) { |
| 104 | 109 | $_type = str_replace( 'custom_post_', '', $type ); |
| 105 | 110 | } elseif ( substr( $type, 0, 9 ) === 'template_' ) { |
| 106 | 111 | $_type = str_replace( 'template_', '', $type ); |
| 107 | - } elseif ( 'bbp_is_bbpress' == $type ) { | |
| 112 | + } elseif ( 'bbp_is_bbpress' === $type ) { | |
| 108 | 113 | $_type = str_replace( 'bbp_', '', $type ); |
| 109 | - } elseif ( 'bp_is_buddypress' == $type ) { | |
| 114 | + } elseif ( 'bp_is_buddypress' === $type ) { | |
| 110 | 115 | $_type = str_replace( 'bp_', '', $type ); |
| 111 | 116 | } elseif ( substr( $type, 0, 4 ) === 'woo_' ) { |
| 112 | 117 | $_type = str_replace( 'woo_', '', $type ); |
| 113 | 118 | } elseif ( substr( $type, 0, 4 ) === 'edd_' ) { |
| @@ -126,12 +131,12 @@ | ||
| 126 | 131 | </td> |
| 127 | 132 | </tr> |
| 128 | 133 | <tr> |
| 129 | 134 | <th scope="row"> |
| 130 | - <?php _e( 'Custom Critical CSS', 'autoptimize' ); ?> | |
| 135 | + <?php esc_html_e( 'Custom Critical CSS', 'autoptimize' ); ?> | |
| 131 | 136 | </th> |
| 132 | 137 | <td> |
| 133 | - <textarea id="critcss_addedit_css" rows="13" cols="10" style="width:100%;" placeholder="<?php _e( 'Paste your specific critical CSS here and hit submit to save.', 'autoptimize' ); ?>"></textarea> | |
| 138 | + <textarea id="critcss_addedit_css" rows="13" cols="10" style="width:100%;" placeholder="<?php esc_html_e( 'Paste your specific critical CSS here and hit submit to save.', 'autoptimize' ); ?>"></textarea> | |
| 134 | 139 | <input type="hidden" id="critcss_addedit_file"> |
| 135 | 140 | <input type="hidden" id="critcss_addedit_id"> |
| 136 | 141 | </td> |
| 137 | 142 | </tr> |
| @@ -138,36 +143,32 @@ | ||
| 138 | 143 | </table> |
| 139 | 144 | </div> |
| 140 | 145 | |
| 141 | 146 | <!-- Remove dialog --> |
| 142 | - <div id="confirm-rm" title="<?php _e( 'Delete Rule', 'autoptimize' ); ?>" class="hidden"> | |
| 147 | + <div id="confirm-rm" title="<?php esc_html_e( 'Delete Rule', 'autoptimize' ); ?>" class="hidden"> | |
| 143 | 148 | <p><?php _e( 'This Critical CSS rule will be deleted immediately and cannot be recovered.<br /><br /><strong>Are you sure?</strong>', 'autoptimize' ); ?></p> |
| 144 | 149 | </div> |
| 145 | 150 | |
| 146 | 151 | <!-- Remove All dialog --> |
| 147 | - <div id="confirm-rm-all" title="<?php _e( 'Delete all Rules and Jobs', 'autoptimize' ); ?>" class="hidden"> | |
| 152 | + <div id="confirm-rm-all" title="<?php esc_html_e( 'Delete all Rules and Jobs', 'autoptimize' ); ?>" class="hidden"> | |
| 148 | 153 | <p><?php _e( 'All Critical CSS rules will be deleted immediately and cannot be recovered.<br /><br /><strong>Are you sure?</strong>', 'autoptimize' ); ?></p> |
| 149 | 154 | </div> |
| 150 | 155 | |
| 151 | 156 | <!-- Add/edit default critical CSS dialog --> |
| 152 | 157 | <div id="default_critcss_wrapper" class="hidden"> |
| 153 | - <textarea id="dummyDefault" rows="19" cols="10" style="width:100%;" placeholder="<?php _e( 'Paste your MINIFIED default critical CSS here and hit submit to save. This is the critical CSS to be used for every page NOT MATCHING any rule.', 'autoptimize' ); ?>"></textarea> | |
| 158 | + <textarea id="dummyDefault" rows="19" cols="10" style="width:100%;" placeholder="<?php esc_html_e( 'Paste your minified default critical CSS here and hit submit to save. This is the critical CSS to be used for every page not matching any rule.', 'autoptimize' ); ?>"></textarea> | |
| 154 | 159 | </div> |
| 155 | 160 | |
| 156 | 161 | <!-- Add/edit additional critical CSS dialog --> |
| 157 | 162 | <div id="additional_critcss_wrapper" class="hidden"> |
| 158 | - <textarea id="dummyAdditional" rows="19" cols="10" style="width:100%;" placeholder="<?php _e( 'Paste your MINIFIED additional critical CSS here and hit submit to save. This is the CSS to be added AT THE END of every critical CSS provided by a matching rule, or the default one.', 'autoptimize' ); ?>"></textarea> | |
| 163 | + <textarea id="dummyAdditional" rows="19" cols="10" style="width:100%;" placeholder="<?php esc_html_e( 'Paste your minified additional critical CSS here and hit submit to save. This is the CSS to be added AT THE END of every critical CSS provided by a matching rule, or the default one.', 'autoptimize' ); ?>"></textarea> | |
| 159 | 164 | </div> |
| 160 | 165 | |
| 161 | - <!-- Wrapper for in screen notices --> | |
| 162 | - <div id="rules-notices"></div> | |
| 163 | - <!-- END Rule add/edit dialogs --> | |
| 164 | - | |
| 165 | 166 | <!-- BEGIN Rules UI --> |
| 166 | 167 | <div class="howto"> |
| 167 | 168 | <div class="title-wrap"> |
| 168 | - <h4 class="title"><?php _e( 'How To Use Autoptimize CriticalCSS Power-Up Rules', 'autoptimize' ); ?></h4> | |
| 169 | - <p class="subtitle"><?php _e( 'Click the side arrow to toggle instructions', 'autoptimize' ); ?></p> | |
| 169 | + <h4 class="title"><?php esc_html_e( 'How To Use Autoptimize CriticalCSS Rules', 'autoptimize' ); ?></h4> | |
| 170 | + <p class="subtitle"><?php esc_html_e( 'Click the side arrow to toggle instructions', 'autoptimize' ); ?></p> | |
| 170 | 171 | </div> |
| 171 | 172 | <button type="button" class="toggle-btn"> |
| 172 | 173 | <span class="toggle-indicator dashicons dashicons-arrow-up dashicons-arrow-down"></span> |
| 173 | 174 | </button> |
| @@ -173,35 +174,65 @@ | ||
| 173 | 174 | </button> |
| 174 | 175 | <div class="howto-wrap hidden"> |
| 175 | 176 | <p><?php _e( "TL;DR:<br />Critical CSS files from <span class='badge auto'>AUTO</span> <strong>rules are updated automatically</strong> while from <span class='badge manual'>MANUAL</span> <strong>rules are not.</strong>", 'autoptimize' ); ?></p> |
| 176 | 177 | <ol> |
| 177 | - <li><?php _e( 'When a valid <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> API key is in place, Autoptimize CriticalCSS Power-Up starts to operate <strong>automatically</strong>.', 'autoptimize' ); ?></li> | |
| 178 | + <li><?php _e( 'When a valid <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> API key is in place, Autoptimize starts to operate <strong>automatically</strong>.', 'autoptimize' ); ?></li> | |
| 178 | 179 | <li><?php _e( 'Upon a request to any of the frontend pages made by a <strong>not logged in user</strong>, it will <strong>asynchronously</strong> fetch and update the critical CSS from <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> for conditional tags you have on your site (e.g. is_page, is_single, is_archive etc.)', 'autoptimize' ); ?></li> |
| 179 | 180 | <li><?php _e( 'These requests also creates an <span class="badge auto">AUTO</span> rule for you. The critical CSS files from <span class="badge auto">AUTO</span> <strong>rules are updated automatically</strong> when a CSS file in your theme or frontend plugins changes.', 'autoptimize' ); ?></li> |
| 180 | 181 | <li><?php _e( 'If you want to make any fine tunning in the critical CSS file of an <span class="badge auto">AUTO</span> rule, click on "Edit" button of that rule, change what you need, submit and save it. The rule you\'ve just edited becomes a <span class="badge manual">MANUAL</span> rule then.', 'autoptimize' ); ?></li> |
| 181 | 182 | <li><?php _e( 'You can create <span class="badge manual">MANUAL</span> rules for specific page paths (URL). Longer, more specific paths have higher priority over shorter ones, which in turn have higher priority over <span class="badge auto">AUTO</span> rules. Also, critical CSS files from <span class="badge manual">MANUAL</span> <strong>rules are NEVER updated automatically.</strong>', 'autoptimize' ); ?></li> |
| 182 | - <li><?php _e( 'You can also create an <span class="badge auto">AUTO</span> rule for a path by leaving its critical CSS content empty. The critical CSS for that path will be automatically fetched from <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> for you and updated whenever it changes.', 'autoptimize' ); ?></li> | |
| 183 | - <li><?php _e( "If you see an <span class='badge auto'>AUTO</span> rule with a <span class='badge review'>R</span> besides it (R is after REVIEW), it means that the fetched critical CSS for that rule is not 100% garanteed to work according to <a href='https://criticalcss.com/?aff=1' target='_blank'>criticalcss.com</a> analysis. It's advised that you edit and review that rule to make any required adjustments.", 'autoptimize' ); ?></li> | |
| 184 | 183 | <li><?php _e( 'At any time you can delete an <span class="badge auto">AUTO</span> or <span class="badge manual">MANUAL</span> rule by cliking on "Remove" button of the desired rule and saving your changes.', 'autoptimize' ); ?></li> |
| 185 | 184 | </ol> |
| 186 | 185 | </div> |
| 187 | 186 | </div> |
| 188 | - <textarea id="autoptimize_css_defer_inline" name="autoptimize_css_defer_inline" rows="19" cols="10" style="width:100%;"><?php echo get_option( 'autoptimize_css_defer_inline', '' ); ?></textarea> | |
| 189 | - <textarea id="autoptimize_ccss_additional" name="autoptimize_ccss_additional" rows="19" cols="10" style="width:100%;"><?php echo get_option( 'autoptimize_ccss_additional', '' ); ?></textarea> | |
| 187 | + <textarea id="autoptimize_css_defer_inline" name="autoptimize_css_defer_inline" rows="19" cols="10" style="width:100%;"><?php echo autoptimizeStyles::sanitize_css( get_option( 'autoptimize_css_defer_inline', '' ) ); ?></textarea> | |
| 188 | + <textarea id="autoptimize_ccss_additional" name="autoptimize_ccss_additional" rows="19" cols="10" style="width:100%;"><?php echo autoptimizeStyles::sanitize_css( get_option( 'autoptimize_ccss_additional', '' ) ); ?></textarea> | |
| 190 | 189 | <table class="rules-list" cellspacing="0"><tbody id="rules-list"></tbody></table> |
| 191 | - <input class="hidden" type="text" id="critCssOrigin" name="autoptimize_ccss_rules" value='<?php echo ( json_encode( $ao_ccss_rules, JSON_FORCE_OBJECT ) ); ?>'> | |
| 190 | + <input class="hidden" type="text" id="critCssOrigin" name="autoptimize_ccss_rules" value='<?php echo ( esc_attr( json_encode( $ao_ccss_rules, JSON_FORCE_OBJECT ) ) ); ?>'> | |
| 191 | + <!-- Wrapper for in screen notices --> | |
| 192 | + <div id="rules-notices"></div> | |
| 193 | + <!-- END Rule add/edit dialogs --> | |
| 192 | 194 | <div class="submit rules-btn"> |
| 193 | 195 | <div class="alignleft"> |
| 194 | - <span id="addCritCssButton" class="button-secondary"><?php _e( 'Add New Rule', 'autoptimize' ); ?></span> | |
| 195 | - <span id="editDefaultButton" class="button-secondary"><?php _e( 'Edit Default Rule CSS', 'autoptimize' ); ?></span> | |
| 196 | - <span id="editAdditionalButton" class="button-secondary"><?php _e( 'Add CSS To All Rules', 'autoptimize' ); ?></span> | |
| 196 | + <span id="addCritCssButton" class="button-secondary"><?php esc_html_e( 'Add New Rule', 'autoptimize' ); ?></span> | |
| 197 | + <span id="editDefaultButton" class="button-secondary"><?php esc_html_e( 'Edit Default Rule CSS', 'autoptimize' ); ?></span> | |
| 198 | + <span id="editAdditionalButton" class="button-secondary"><?php esc_html_e( 'Add CSS To All Rules', 'autoptimize' ); ?></span> | |
| 197 | 199 | </div> |
| 198 | 200 | <div class="alignright"> |
| 199 | - <span id="removeAllRules" class="button-secondary" style="color:red;"><?php _e( 'Remove all rules', 'autoptimize' ); ?></span> | |
| 201 | + <span id="removeAllRules" class="button-secondary" style="color:red;"><?php esc_html_e( 'Remove all rules', 'autoptimize' ); ?></span> | |
| 200 | 202 | </div> |
| 201 | 203 | </div> |
| 202 | 204 | <!-- END Rules UI --> |
| 203 | 205 | </li> |
| 204 | 206 | </ul> |
| 205 | -<?php | |
| 207 | + <?php | |
| 206 | 208 | } |
| 209 | + | |
| 210 | +/** | |
| 211 | + * Sanitize rules before rendering. | |
| 212 | + * | |
| 213 | + * @param array $rules Array with rules to be sanitized. | |
| 214 | + */ | |
| 215 | +function sanitize_rules( $rules ) { | |
| 216 | + if ( is_array( $rules ) && ! empty( $rules ) && apply_filters( 'autoptimize_filter_ccss_paths_clickable', true ) ) { | |
| 217 | + if ( array_key_exists( 'paths', $rules ) ) { | |
| 218 | + foreach ( $rules['paths'] as $key => $value ) { | |
| 219 | + $newkey = esc_url( $key ); | |
| 220 | + if ( $newkey !== $key ) { | |
| 221 | + if ( 0 === strpos( $newkey, 'http://' ) && 0 !== strpos( $key, 'http://' ) ) { | |
| 222 | + // esc_url adds "http://" to any string that does not start with either a protocol or a | |
| 223 | + // slash, see https://developer.wordpress.org/reference/functions/esc_url/#more-information | |
| 224 | + // this removes that unneeded protocol again. | |
| 225 | + $newkey = substr_replace( $newkey, '', 0, 7 ); | |
| 226 | + } | |
| 227 | + unset( $rules['paths'][ $key ] ); | |
| 228 | + $rules['paths'][ $newkey ] = $value; | |
| 229 | + } | |
| 230 | + } | |
| 231 | + } | |
| 232 | + } | |
| 233 | + | |
| 234 | + $rules = autoptimizeUtils::strip_tags_array( $rules ); | |
| 235 | + return $rules; | |
| 236 | +} | |
| 237 | + | |
| 207 | 238 | ?> |