PluginProbe
bbPress / 2.6.19
bbPress v2.6.19
2.6.19 2.6.18 2.6.17 trunk 2.0 2.0-beta-1 2.0-beta-2b 2.0-beta-3 2.0-beta-3b 2.0-rc-2 2.0-rc-3 2.0-rc-4 2.0-rc-5 2.0.1 2.0.2 2.0.3 2.1 2.1-beta-1 2.1-rc1 2.1-rc2 2.1-rc3 2.1-rc4 2.1.1 2.1.2 2.1.3 All 74 releases
← All changes | includes/admin/classes/class-bbp-converter.php +58 -31 2.6.17 → 2.6.19 View file →
@@ -98,9 +98,9 @@
98 98
99 99 /**
100 100 * The main bbPress Converter loader
101 101 *
102 - * @since 2.1.0 bbPress (r3813)
102 + * @since 2.1.0 bbPress (r3816)
103 103 */
104 104 public function __construct() {
105 105 $this->setup_globals();
106 106 $this->setup_actions();
@@ -108,9 +108,9 @@
108 108
109 109 /**
110 110 * Admin globals
111 111 *
112 - * @since 2.6.0 bbPress (r6598)
112 + * @since 2.6.0 bbPress (r6601)
113 113 */
114 114 public function setup_globals() {
115 115 $this->converters_dir = bbp_setup_admin()->admin_dir . 'converters/';
116 116 }
@@ -117,9 +117,9 @@
117 117
118 118 /**
119 119 * Setup the default actions
120 120 *
121 - * @since 2.1.0 bbPress (r3813)
121 + * @since 2.1.0 bbPress (r3816)
122 122 */
123 123 public function setup_actions() {
124 124
125 125 // Attach to the admin head with our ajax requests cycle and css
@@ -131,11 +131,16 @@
131 131
132 132 /**
133 133 * Admin scripts
134 134 *
135 - * @since 2.1.0 bbPress (r3813)
135 + * @since 2.1.0 bbPress (r3816)
136 + * @since 2.6.19 bbPress (r7739) Stop autoloading the saved source password.
136 137 */
137 138 public function admin_head() {
139 + // WordPress 6.4+ can stop autoloading an existing option without changing it.
140 + if ( function_exists( 'wp_set_option_autoload_values' ) ) {
141 + wp_set_option_autoload_values( array( '_bbp_converter_db_pass' => false ) );
142 + }
138 143
139 144 // Enqueue scripts
140 145 wp_enqueue_script( 'bbp-converter' );
141 146
@@ -190,19 +195,33 @@
190 195
191 196 /**
192 197 * Callback processor
193 198 *
194 - * @since 2.1.0 bbPress (r3813)
199 + * @since 2.1.0 bbPress (r3816)
195 200 */
196 201 public function process_callback() {
197 202
198 203 // Ready the converter
199 204 $this->check_access();
205 +
206 + // Reject unsafe source table names before saving options or importing.
207 + $db_prefix = isset( $_POST['_bbp_converter_db_prefix'] )
208 + ? wp_unslash( $_POST['_bbp_converter_db_prefix'] )
209 + : '';
210 + if ( ! bbp_is_valid_converter_prefix( $db_prefix ) ) {
211 + wp_send_json_error( array( 'message' => esc_html__( 'Invalid source database table prefix.', 'bbpress' ) ) );
212 + }
213 +
200 214 $this->maybe_set_memory();
201 215 $this->maybe_restart();
202 216 $this->setup_options();
203 217 $this->maybe_update_options();
204 218
219 + // A valid submitted prefix may repair an invalid saved prefix.
220 + if ( empty( $this->converter ) ) {
221 + $this->setup_options();
222 + }
223 +
205 224 // Bail if no converter
206 225 if ( ! empty( $this->converter ) ) {
207 226 $this->do_steps();
208 227 }
@@ -210,9 +229,9 @@
210 229
211 230 /**
212 231 * Wrap the converter output in HTML, so styling can be applied
213 232 *
214 - * @since 2.1.0 bbPress (r4052)
233 + * @since 2.6.0 bbPress (r6601)
215 234 *
216 235 * @param string $output
217 236 */
218 237 private function converter_response( $output = '' ) {
@@ -304,9 +323,10 @@
304 323
305 324 /**
306 325 * Maybe update options
307 326 *
308 - * @since 2.6.0 bbPress (r6637)
327 + * @since 2.6.0 bbPress (r6514)
328 + * @since 2.6.19 bbPress (r7739) Keep or explicitly clear a saved source password.
309 329 */
310 330 private function maybe_update_options() {
311 331
312 332 // Default options
@@ -341,13 +361,8 @@
341 361 '_bbp_converter_db_user' => ! empty( $_POST['_bbp_converter_db_user'] )
342 362 ? sanitize_text_field( $_POST['_bbp_converter_db_user'] )
343 363 : '',
344 364
345 - // DB Password
346 - '_bbp_converter_db_pass' => ! empty( $_POST['_bbp_converter_db_pass'] )
347 - ? sanitize_text_field( $_POST['_bbp_converter_db_pass'] )
348 - : '',
349 -
350 365 // DB Name
351 366 '_bbp_converter_db_name' => ! empty( $_POST['_bbp_converter_db_name'] )
352 367 ? sanitize_text_field( $_POST['_bbp_converter_db_name'] )
353 368 : '',
@@ -367,12 +382,24 @@
367 382 ? sanitize_text_field( $_POST['_bbp_converter_db_prefix'] )
368 383 : ''
369 384 );
370 385
386 + // Saving site-level converter settings must not change the account option.
387 + if ( ! current_user_can( 'bbp_tools_import_users' ) ) {
388 + unset( $options['_bbp_converter_convert_users'] );
389 + }
390 +
371 391 // Update/delete options
372 392 foreach ( $options as $key => $value ) {
373 393 update_option( $key, $value );
374 394 }
395 +
396 + // A blank password keeps the saved value; clearing it is explicit.
397 + if ( isset( $_POST['_bbp_converter_db_pass'] ) && is_string( $_POST['_bbp_converter_db_pass'] ) && '' !== $_POST['_bbp_converter_db_pass'] ) {
398 + update_option( '_bbp_converter_db_pass', wp_unslash( $_POST['_bbp_converter_db_pass'] ), false );
399 + } elseif ( ! empty( $_POST['_bbp_converter_db_pass_clear'] ) || false === get_option( '_bbp_converter_db_pass', false ) ) {
400 + update_option( '_bbp_converter_db_pass', '', false );
401 + }
375 402 }
376 403
377 404 /**
378 405 * Setup converter options
@@ -511,9 +538,9 @@
511 538
512 539 /**
513 540 * Maybe clean the sync table
514 541 *
515 - * @since 2.6.0 bbPress (r6513)
542 + * @since 2.6.0 bbPress (r6514)
516 543 */
517 544 private function step_sync_table() {
518 545 if ( true === $this->converter->clean ) {
519 546 if ( $this->converter->clean() ) {
@@ -545,9 +572,9 @@
545 572
546 573 /**
547 574 * Maybe convert users
548 575 *
549 - * @since 2.6.0 bbPress (r6513)
576 + * @since 2.6.0 bbPress (r6514)
550 577 */
551 578 private function step_users() {
552 579 if ( true === $this->converter->convert_users ) {
553 580 if ( $this->converter->convert_users( $this->start ) ) {
@@ -569,9 +596,9 @@
569 596
570 597 /**
571 598 * Maybe clean up passwords
572 599 *
573 - * @since 2.6.0 bbPress (r6513)
600 + * @since 2.6.0 bbPress (r6514)
574 601 */
575 602 private function step_passwords() {
576 603 if ( true === $this->converter->convert_users ) {
577 604 if ( $this->converter->clean_passwords( $this->start ) ) {
@@ -593,9 +620,9 @@
593 620
594 621 /**
595 622 * Maybe convert forums
596 623 *
597 - * @since 2.6.0 bbPress (r6513)
624 + * @since 2.6.0 bbPress (r6514)
598 625 */
599 626 private function step_forums() {
600 627 if ( $this->converter->convert_forums( $this->start ) ) {
601 628 $this->bump_step();
@@ -612,9 +639,9 @@
612 639
613 640 /**
614 641 * Maybe walk the forum hierarchy
615 642 *
616 - * @since 2.6.0 bbPress (r6513)
643 + * @since 2.6.0 bbPress (r6514)
617 644 */
618 645 private function step_forum_hierarchy() {
619 646 if ( $this->converter->convert_forum_parents( $this->start ) ) {
620 647 $this->bump_step();
@@ -631,9 +658,9 @@
631 658
632 659 /**
633 660 * Maybe convert forum subscriptions
634 661 *
635 - * @since 2.6.0 bbPress (r6513)
662 + * @since 2.6.0 bbPress (r6514)
636 663 */
637 664 private function step_forum_subscriptions() {
638 665 if ( $this->converter->convert_forum_subscriptions( $this->start ) ) {
639 666 $this->bump_step();
@@ -650,9 +677,9 @@
650 677
651 678 /**
652 679 * Maybe convert topics
653 680 *
654 - * @since 2.6.0 bbPress (r6513)
681 + * @since 2.6.0 bbPress (r6514)
655 682 */
656 683 private function step_topics() {
657 684 if ( $this->converter->convert_topics( $this->start ) ) {
658 685 $this->bump_step();
@@ -669,9 +696,9 @@
669 696
670 697 /**
671 698 * Maybe convert topic authors (anonymous)
672 699 *
673 - * @since 2.6.0 bbPress (r6513)
700 + * @since 2.6.0 bbPress (r6514)
674 701 */
675 702 private function step_topics_authors() {
676 703 if ( $this->converter->convert_anonymous_topic_authors( $this->start ) ) {
677 704 $this->bump_step();
@@ -688,9 +715,9 @@
688 715
689 716 /**
690 717 * Maybe convert sticky topics (not super stickies)
691 718 *
692 - * @since 2.6.0 bbPress (r6513)
719 + * @since 2.6.0 bbPress (r6514)
693 720 */
694 721 private function step_stickies() {
695 722 if ( $this->converter->convert_topic_stickies( $this->start ) ) {
696 723 $this->bump_step();
@@ -707,9 +734,9 @@
707 734
708 735 /**
709 736 * Maybe convert super-sticky topics (not per-forum)
710 737 *
711 - * @since 2.6.0 bbPress (r6513)
738 + * @since 2.6.0 bbPress (r6514)
712 739 */
713 740 private function step_super_stickies() {
714 741 if ( $this->converter->convert_topic_super_stickies( $this->start ) ) {
715 742 $this->bump_step();
@@ -726,9 +753,9 @@
726 753
727 754 /**
728 755 * Maybe close converted topics
729 756 *
730 - * @since 2.6.0 bbPress (r6513)
757 + * @since 2.6.0 bbPress (r6514)
731 758 */
732 759 private function step_closed_topics() {
733 760 if ( $this->converter->convert_topic_closed_topics( $this->start ) ) {
734 761 $this->bump_step();
@@ -745,9 +772,9 @@
745 772
746 773 /**
747 774 * Maybe convert topic tags
748 775 *
749 - * @since 2.6.0 bbPress (r6513)
776 + * @since 2.6.0 bbPress (r6514)
750 777 */
751 778 private function step_topic_tags() {
752 779 if ( $this->converter->convert_tags( $this->start ) ) {
753 780 $this->bump_step();
@@ -764,9 +791,9 @@
764 791
765 792 /**
766 793 * Maybe convert topic subscriptions
767 794 *
768 - * @since 2.6.0 bbPress (r6513)
795 + * @since 2.6.0 bbPress (r6514)
769 796 */
770 797 private function step_topic_subscriptions() {
771 798 if ( $this->converter->convert_topic_subscriptions( $this->start ) ) {
772 799 $this->bump_step();
@@ -783,9 +810,9 @@
783 810
784 811 /**
785 812 * Maybe convert topic favorites
786 813 *
787 - * @since 2.6.0 bbPress (r6513)
814 + * @since 2.6.0 bbPress (r6514)
788 815 */
789 816 private function step_topic_favorites() {
790 817 if ( $this->converter->convert_favorites( $this->start ) ) {
791 818 $this->bump_step();
@@ -802,9 +829,9 @@
802 829
803 830 /**
804 831 * Maybe convert replies
805 832 *
806 - * @since 2.6.0 bbPress (r6513)
833 + * @since 2.6.0 bbPress (r6514)
807 834 */
808 835 private function step_replies() {
809 836 if ( $this->converter->convert_replies( $this->start ) ) {
810 837 $this->bump_step();
@@ -821,9 +848,9 @@
821 848
822 849 /**
823 850 * Maybe convert reply authors (anonymous)
824 851 *
825 - * @since 2.6.0 bbPress (r6513)
852 + * @since 2.6.0 bbPress (r6514)
826 853 */
827 854 private function step_reply_authors() {
828 855 if ( $this->converter->convert_anonymous_reply_authors( $this->start ) ) {
829 856 $this->bump_step();
@@ -840,9 +867,9 @@
840 867
841 868 /**
842 869 * Maybe convert the threaded reply hierarchy
843 870 *
844 - * @since 2.6.0 bbPress (r6513)
871 + * @since 2.6.0 bbPress (r6514)
845 872 */
846 873 private function step_reply_hierarchy() {
847 874 if ( $this->converter->convert_reply_to_parents( $this->start ) ) {
848 875 $this->bump_step();
@@ -859,9 +886,9 @@
859 886
860 887 /**
861 888 * Done!
862 889 *
863 - * @since 2.6.0 bbPress (r6513)
890 + * @since 2.6.0 bbPress (r6514)
864 891 */
865 892 private function step_done() {
866 893 $this->reset();
867 894 $this->converter_response( esc_html__( 'Import Finished', 'bbpress' ) );
@@ -871,9 +898,9 @@
871 898
872 899 /**
873 900 * Create Tables for fast syncing
874 901 *
875 - * @since 2.1.0 bbPress (r3813)
902 + * @since 2.1.0 bbPress (r3816)
876 903 */
877 904 public static function sync_table( $drop = false ) {
878 905
879 906 // Setup DB