PluginProbe
Autoptimize / trunk
Autoptimize vtrunk
3.1.16 2.2.2 2.3.0 2.3.1 2.3.2 2.3.3 2.3.4 2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 2.5.0 2.5.1 2.6.0 2.6.1 2.6.2 2.7.0 2.7.1 2.7.2 2.7.3 2.7.4 2.7.5 2.7.6 2.7.7 All 108 releases
← All changes | classes/critcss-inc/admin_settings_rules.php +74 -43 2.7.6 → trunk View file →
@@ -7,14 +7,19 @@
7 7 * Main function to render the rules panel.
8 8 */
9 9 function ao_ccss_render_rules() {
10 10 // Attach required arrays.
11 - global $ao_ccss_rules;
12 - global $ao_ccss_types;
13 -?>
11 + $criticalcss = autoptimize()->criticalcss();
12 + $ao_ccss_rules = sanitize_rules( $criticalcss->get_option( 'rules' ) );
13 + $ao_ccss_types = $criticalcss->get_types();
14 +
15 + if ( empty( $ao_ccss_types ) || ! is_array( $ao_ccss_types ) ) {
16 + $ao_ccss_types = array( 'No conditionals, check CSS optimization settings.' );
17 + }
18 + ?>
14 19 <ul id="rules-panel">
15 20 <li class="itemDetail">
16 - <h2 class="itemTitle"><?php _e( 'Rules', 'autoptimize' ); ?></h2>
21 + <h2 class="itemTitle"><?php esc_html_e( 'Rules', 'autoptimize' ); ?></h2>
17 22
18 23 <!-- BEGIN Rule dialogs -->
19 24 <!-- Unsaved dialog -->
20 25 <div id="unSavedWarning" class="hidden updated settings-error notice notice-warning is-dismissible">
@@ -25,33 +30,33 @@
25 30 <div id="addEditCritCss" class="hidden">
26 31 <table class="form-table rules">
27 32 <tr id="critcss_addedit_type_wrapper">
28 33 <th scope="row">
29 - <?php _e( 'Rule Type', 'autoptimize' ); ?>
34 + <?php esc_html_e( 'Rule Type', 'autoptimize' ); ?>
30 35 </th>
31 36 <td>
32 37 <select id="critcss_addedit_type" style="width:100%;">
33 - <option value="paths"><?php _e( 'Path', 'autoptimize' ); ?></option>
34 - <option value="types"><?php _e( 'Conditional Tag', 'autoptimize' ); ?></option>
38 + <option value="paths"><?php esc_html_e( 'Path', 'autoptimize' ); ?></option>
39 + <option value="types"><?php esc_html_e( 'Conditional Tag', 'autoptimize' ); ?></option>
35 40 </select>
36 41 </td>
37 42 </tr>
38 43 <tr id="critcss_addedit_path_wrapper">
39 44 <th scope="row">
40 - <?php _e( 'String in Path', 'autoptimize' ); ?>
45 + <?php esc_html_e( 'String in Path', 'autoptimize' ); ?>
41 46 </th>
42 47 <td>
43 - <input type="text" id="critcss_addedit_path" placeholder="<?php _e( "Enter a part of the URL that identifies the page(s) you're targetting.", 'autoptimize' ); ?>" style="width:100%;" value="">
48 + <input type="text" id="critcss_addedit_path" placeholder="<?php esc_html_e( "Enter a part of the URL that identifies the page(s) you're targetting.", 'autoptimize' ); ?>" style="width:100%;" value="">
44 49 </td>
45 50 </tr>
46 51 <tr id="critcss_addedit_pagetype_wrapper">
47 52 <th scope="row">
48 - <?php _e( 'Conditional Tag, Custom Post Type or Page Template', 'autoptimize' ); ?>
53 + <?php esc_html_e( 'Conditional Tag, Custom Post Type or Page Template', 'autoptimize' ); ?>
49 54 </th>
50 55 <td>
51 56 <select id="critcss_addedit_pagetype" style="width:100%;">
52 - <option value="" disabled selected><?php _e( 'Select from the list below...', 'autoptimize' ); ?></option>
53 - <optgroup label="<?php _e( 'Standard Conditional Tags', 'autoptimize' ); ?>">
57 + <option value="" disabled selected><?php esc_html_e( 'Select from the list below...', 'autoptimize' ); ?></option>
58 + <optgroup label="<?php esc_html_e( 'Standard Conditional Tags', 'autoptimize' ); ?>">
54 59 <?php
55 60 // Render grouped simple conditional tags.
56 61 foreach ( $ao_ccss_types as $ctag ) {
57 62 $optgrp = substr( $ctag, 0, 3 );
@@ -71,29 +76,29 @@
71 76 </optgroup>
72 77 <?php
73 78 if ( substr( $type, 0, 12 ) === 'custom_post_' ) {
74 79 ?>
75 - <optgroup label="<?php _e( 'Custom Post Types', 'autoptimize' ); ?>">
80 + <optgroup label="<?php esc_html_e( 'Custom Post Types', 'autoptimize' ); ?>">
76 81 <?php
77 82 } elseif ( substr( $type, 0, 9 ) === 'template_' ) {
78 83 ?>
79 - <optgroup label="<?php _e( 'Page Templates', 'autoptimize' ); ?>">
84 + <optgroup label="<?php esc_html_e( 'Page Templates', 'autoptimize' ); ?>">
80 85 <?php
81 86 } elseif ( substr( $type, 0, 4 ) === 'bbp_' ) {
82 87 ?>
83 - <optgroup label="<?php _e( 'BBPress Conditional Tags', 'autoptimize' ); ?>">
88 + <optgroup label="<?php esc_html_e( 'BBPress Conditional Tags', 'autoptimize' ); ?>">
84 89 <?php
85 90 } elseif ( substr( $type, 0, 3 ) === 'bp_' ) {
86 91 ?>
87 - <optgroup label="<?php _e( 'BuddyPress Conditional Tags', 'autoptimize' ); ?>">
92 + <optgroup label="<?php esc_html_e( 'BuddyPress Conditional Tags', 'autoptimize' ); ?>">
88 93 <?php
89 94 } elseif ( substr( $type, 0, 4 ) === 'edd_' ) {
90 95 ?>
91 - <optgroup label="<?php _e( 'Easy Digital Downloads Conditional Tags', 'autoptimize' ); ?>">
96 + <optgroup label="<?php esc_html_e( 'Easy Digital Downloads Conditional Tags', 'autoptimize' ); ?>">
92 97 <?php
93 98 } elseif ( substr( $type, 0, 4 ) === 'woo_' ) {
94 99 ?>
95 - <optgroup label="<?php _e( 'WooCommerce Conditional Tags', 'autoptimize' ); ?>">
100 + <optgroup label="<?php esc_html_e( 'WooCommerce Conditional Tags', 'autoptimize' ); ?>">
96 101 <?php
97 102 }
98 103 }
99 104
@@ -103,11 +108,11 @@
103 108 if ( substr( $type, 0, 12 ) === 'custom_post_' ) {
104 109 $_type = str_replace( 'custom_post_', '', $type );
105 110 } elseif ( substr( $type, 0, 9 ) === 'template_' ) {
106 111 $_type = str_replace( 'template_', '', $type );
107 - } elseif ( 'bbp_is_bbpress' == $type ) {
112 + } elseif ( 'bbp_is_bbpress' === $type ) {
108 113 $_type = str_replace( 'bbp_', '', $type );
109 - } elseif ( 'bp_is_buddypress' == $type ) {
114 + } elseif ( 'bp_is_buddypress' === $type ) {
110 115 $_type = str_replace( 'bp_', '', $type );
111 116 } elseif ( substr( $type, 0, 4 ) === 'woo_' ) {
112 117 $_type = str_replace( 'woo_', '', $type );
113 118 } elseif ( substr( $type, 0, 4 ) === 'edd_' ) {
@@ -126,12 +131,12 @@
126 131 </td>
127 132 </tr>
128 133 <tr>
129 134 <th scope="row">
130 - <?php _e( 'Custom Critical CSS', 'autoptimize' ); ?>
135 + <?php esc_html_e( 'Custom Critical CSS', 'autoptimize' ); ?>
131 136 </th>
132 137 <td>
133 - <textarea id="critcss_addedit_css" rows="13" cols="10" style="width:100%;" placeholder="<?php _e( 'Paste your specific critical CSS here and hit submit to save.', 'autoptimize' ); ?>"></textarea>
138 + <textarea id="critcss_addedit_css" rows="13" cols="10" style="width:100%;" placeholder="<?php esc_html_e( 'Paste your specific critical CSS here and hit submit to save.', 'autoptimize' ); ?>"></textarea>
134 139 <input type="hidden" id="critcss_addedit_file">
135 140 <input type="hidden" id="critcss_addedit_id">
136 141 </td>
137 142 </tr>
@@ -138,36 +143,32 @@
138 143 </table>
139 144 </div>
140 145
141 146 <!-- Remove dialog -->
142 - <div id="confirm-rm" title="<?php _e( 'Delete Rule', 'autoptimize' ); ?>" class="hidden">
147 + <div id="confirm-rm" title="<?php esc_html_e( 'Delete Rule', 'autoptimize' ); ?>" class="hidden">
143 148 <p><?php _e( 'This Critical CSS rule will be deleted immediately and cannot be recovered.<br /><br /><strong>Are you sure?</strong>', 'autoptimize' ); ?></p>
144 149 </div>
145 150
146 151 <!-- Remove All dialog -->
147 - <div id="confirm-rm-all" title="<?php _e( 'Delete all Rules and Jobs', 'autoptimize' ); ?>" class="hidden">
152 + <div id="confirm-rm-all" title="<?php esc_html_e( 'Delete all Rules and Jobs', 'autoptimize' ); ?>" class="hidden">
148 153 <p><?php _e( 'All Critical CSS rules will be deleted immediately and cannot be recovered.<br /><br /><strong>Are you sure?</strong>', 'autoptimize' ); ?></p>
149 154 </div>
150 155
151 156 <!-- Add/edit default critical CSS dialog -->
152 157 <div id="default_critcss_wrapper" class="hidden">
153 - <textarea id="dummyDefault" rows="19" cols="10" style="width:100%;" placeholder="<?php _e( 'Paste your MINIFIED default critical CSS here and hit submit to save. This is the critical CSS to be used for every page NOT MATCHING any rule.', 'autoptimize' ); ?>"></textarea>
158 + <textarea id="dummyDefault" rows="19" cols="10" style="width:100%;" placeholder="<?php esc_html_e( 'Paste your minified default critical CSS here and hit submit to save. This is the critical CSS to be used for every page not matching any rule.', 'autoptimize' ); ?>"></textarea>
154 159 </div>
155 160
156 161 <!-- Add/edit additional critical CSS dialog -->
157 162 <div id="additional_critcss_wrapper" class="hidden">
158 - <textarea id="dummyAdditional" rows="19" cols="10" style="width:100%;" placeholder="<?php _e( 'Paste your MINIFIED additional critical CSS here and hit submit to save. This is the CSS to be added AT THE END of every critical CSS provided by a matching rule, or the default one.', 'autoptimize' ); ?>"></textarea>
163 + <textarea id="dummyAdditional" rows="19" cols="10" style="width:100%;" placeholder="<?php esc_html_e( 'Paste your minified additional critical CSS here and hit submit to save. This is the CSS to be added AT THE END of every critical CSS provided by a matching rule, or the default one.', 'autoptimize' ); ?>"></textarea>
159 164 </div>
160 165
161 - <!-- Wrapper for in screen notices -->
162 - <div id="rules-notices"></div>
163 - <!-- END Rule add/edit dialogs -->
164 -
165 166 <!-- BEGIN Rules UI -->
166 167 <div class="howto">
167 168 <div class="title-wrap">
168 - <h4 class="title"><?php _e( 'How To Use Autoptimize CriticalCSS Power-Up Rules', 'autoptimize' ); ?></h4>
169 - <p class="subtitle"><?php _e( 'Click the side arrow to toggle instructions', 'autoptimize' ); ?></p>
169 + <h4 class="title"><?php esc_html_e( 'How To Use Autoptimize CriticalCSS Rules', 'autoptimize' ); ?></h4>
170 + <p class="subtitle"><?php esc_html_e( 'Click the side arrow to toggle instructions', 'autoptimize' ); ?></p>
170 171 </div>
171 172 <button type="button" class="toggle-btn">
172 173 <span class="toggle-indicator dashicons dashicons-arrow-up dashicons-arrow-down"></span>
173 174 </button>
@@ -173,35 +174,65 @@
173 174 </button>
174 175 <div class="howto-wrap hidden">
175 176 <p><?php _e( "TL;DR:<br />Critical CSS files from <span class='badge auto'>AUTO</span> <strong>rules are updated automatically</strong> while from <span class='badge manual'>MANUAL</span> <strong>rules are not.</strong>", 'autoptimize' ); ?></p>
176 177 <ol>
177 - <li><?php _e( 'When a valid <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> API key is in place, Autoptimize CriticalCSS Power-Up starts to operate <strong>automatically</strong>.', 'autoptimize' ); ?></li>
178 + <li><?php _e( 'When a valid <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> API key is in place, Autoptimize starts to operate <strong>automatically</strong>.', 'autoptimize' ); ?></li>
178 179 <li><?php _e( 'Upon a request to any of the frontend pages made by a <strong>not logged in user</strong>, it will <strong>asynchronously</strong> fetch and update the critical CSS from <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> for conditional tags you have on your site (e.g. is_page, is_single, is_archive etc.)', 'autoptimize' ); ?></li>
179 180 <li><?php _e( 'These requests also creates an <span class="badge auto">AUTO</span> rule for you. The critical CSS files from <span class="badge auto">AUTO</span> <strong>rules are updated automatically</strong> when a CSS file in your theme or frontend plugins changes.', 'autoptimize' ); ?></li>
180 181 <li><?php _e( 'If you want to make any fine tunning in the critical CSS file of an <span class="badge auto">AUTO</span> rule, click on "Edit" button of that rule, change what you need, submit and save it. The rule you\'ve just edited becomes a <span class="badge manual">MANUAL</span> rule then.', 'autoptimize' ); ?></li>
181 182 <li><?php _e( 'You can create <span class="badge manual">MANUAL</span> rules for specific page paths (URL). Longer, more specific paths have higher priority over shorter ones, which in turn have higher priority over <span class="badge auto">AUTO</span> rules. Also, critical CSS files from <span class="badge manual">MANUAL</span> <strong>rules are NEVER updated automatically.</strong>', 'autoptimize' ); ?></li>
182 - <li><?php _e( 'You can also create an <span class="badge auto">AUTO</span> rule for a path by leaving its critical CSS content empty. The critical CSS for that path will be automatically fetched from <a href="https://criticalcss.com/?aff=1" target="_blank">criticalcss.com</a> for you and updated whenever it changes.', 'autoptimize' ); ?></li>
183 - <li><?php _e( "If you see an <span class='badge auto'>AUTO</span> rule with a <span class='badge review'>R</span> besides it (R is after REVIEW), it means that the fetched critical CSS for that rule is not 100% garanteed to work according to <a href='https://criticalcss.com/?aff=1' target='_blank'>criticalcss.com</a> analysis. It's advised that you edit and review that rule to make any required adjustments.", 'autoptimize' ); ?></li>
184 183 <li><?php _e( 'At any time you can delete an <span class="badge auto">AUTO</span> or <span class="badge manual">MANUAL</span> rule by cliking on "Remove" button of the desired rule and saving your changes.', 'autoptimize' ); ?></li>
185 184 </ol>
186 185 </div>
187 186 </div>
188 - <textarea id="autoptimize_css_defer_inline" name="autoptimize_css_defer_inline" rows="19" cols="10" style="width:100%;"><?php echo get_option( 'autoptimize_css_defer_inline', '' ); ?></textarea>
189 - <textarea id="autoptimize_ccss_additional" name="autoptimize_ccss_additional" rows="19" cols="10" style="width:100%;"><?php echo get_option( 'autoptimize_ccss_additional', '' ); ?></textarea>
187 + <textarea id="autoptimize_css_defer_inline" name="autoptimize_css_defer_inline" rows="19" cols="10" style="width:100%;"><?php echo autoptimizeStyles::sanitize_css( get_option( 'autoptimize_css_defer_inline', '' ) ); ?></textarea>
188 + <textarea id="autoptimize_ccss_additional" name="autoptimize_ccss_additional" rows="19" cols="10" style="width:100%;"><?php echo autoptimizeStyles::sanitize_css( get_option( 'autoptimize_ccss_additional', '' ) ); ?></textarea>
190 189 <table class="rules-list" cellspacing="0"><tbody id="rules-list"></tbody></table>
191 - <input class="hidden" type="text" id="critCssOrigin" name="autoptimize_ccss_rules" value='<?php echo ( json_encode( $ao_ccss_rules, JSON_FORCE_OBJECT ) ); ?>'>
190 + <input class="hidden" type="text" id="critCssOrigin" name="autoptimize_ccss_rules" value='<?php echo ( esc_attr( json_encode( $ao_ccss_rules, JSON_FORCE_OBJECT ) ) ); ?>'>
191 + <!-- Wrapper for in screen notices -->
192 + <div id="rules-notices"></div>
193 + <!-- END Rule add/edit dialogs -->
192 194 <div class="submit rules-btn">
193 195 <div class="alignleft">
194 - <span id="addCritCssButton" class="button-secondary"><?php _e( 'Add New Rule', 'autoptimize' ); ?></span>
195 - <span id="editDefaultButton" class="button-secondary"><?php _e( 'Edit Default Rule CSS', 'autoptimize' ); ?></span>
196 - <span id="editAdditionalButton" class="button-secondary"><?php _e( 'Add CSS To All Rules', 'autoptimize' ); ?></span>
196 + <span id="addCritCssButton" class="button-secondary"><?php esc_html_e( 'Add New Rule', 'autoptimize' ); ?></span>
197 + <span id="editDefaultButton" class="button-secondary"><?php esc_html_e( 'Edit Default Rule CSS', 'autoptimize' ); ?></span>
198 + <span id="editAdditionalButton" class="button-secondary"><?php esc_html_e( 'Add CSS To All Rules', 'autoptimize' ); ?></span>
197 199 </div>
198 200 <div class="alignright">
199 - <span id="removeAllRules" class="button-secondary" style="color:red;"><?php _e( 'Remove all rules', 'autoptimize' ); ?></span>
201 + <span id="removeAllRules" class="button-secondary" style="color:red;"><?php esc_html_e( 'Remove all rules', 'autoptimize' ); ?></span>
200 202 </div>
201 203 </div>
202 204 <!-- END Rules UI -->
203 205 </li>
204 206 </ul>
205 -<?php
207 + <?php
206 208 }
209 +
210 +/**
211 + * Sanitize rules before rendering.
212 + *
213 + * @param array $rules Array with rules to be sanitized.
214 + */
215 +function sanitize_rules( $rules ) {
216 + if ( is_array( $rules ) && ! empty( $rules ) && apply_filters( 'autoptimize_filter_ccss_paths_clickable', true ) ) {
217 + if ( array_key_exists( 'paths', $rules ) ) {
218 + foreach ( $rules['paths'] as $key => $value ) {
219 + $newkey = esc_url( $key );
220 + if ( $newkey !== $key ) {
221 + if ( 0 === strpos( $newkey, 'http://' ) && 0 !== strpos( $key, 'http://' ) ) {
222 + // esc_url adds "http://" to any string that does not start with either a protocol or a
223 + // slash, see https://developer.wordpress.org/reference/functions/esc_url/#more-information
224 + // this removes that unneeded protocol again.
225 + $newkey = substr_replace( $newkey, '', 0, 7 );
226 + }
227 + unset( $rules['paths'][ $key ] );
228 + $rules['paths'][ $newkey ] = $value;
229 + }
230 + }
231 + }
232 + }
233 +
234 + $rules = autoptimizeUtils::strip_tags_array( $rules );
235 + return $rules;
236 +}
237 +
207 238 ?>