| @@ -98,9 +98,9 @@ | ||
| 98 | 98 | |
| 99 | 99 | /** |
| 100 | 100 | * The main bbPress Converter loader |
| 101 | 101 | * |
| 102 | - * @since 2.1.0 bbPress (r3813) | |
| 102 | + * @since 2.1.0 bbPress (r3816) | |
| 103 | 103 | */ |
| 104 | 104 | public function __construct() { |
| 105 | 105 | $this->setup_globals(); |
| 106 | 106 | $this->setup_actions(); |
| @@ -108,9 +108,9 @@ | ||
| 108 | 108 | |
| 109 | 109 | /** |
| 110 | 110 | * Admin globals |
| 111 | 111 | * |
| 112 | - * @since 2.6.0 bbPress (r6598) | |
| 112 | + * @since 2.6.0 bbPress (r6601) | |
| 113 | 113 | */ |
| 114 | 114 | public function setup_globals() { |
| 115 | 115 | $this->converters_dir = bbp_setup_admin()->admin_dir . 'converters/'; |
| 116 | 116 | } |
| @@ -117,9 +117,9 @@ | ||
| 117 | 117 | |
| 118 | 118 | /** |
| 119 | 119 | * Setup the default actions |
| 120 | 120 | * |
| 121 | - * @since 2.1.0 bbPress (r3813) | |
| 121 | + * @since 2.1.0 bbPress (r3816) | |
| 122 | 122 | */ |
| 123 | 123 | public function setup_actions() { |
| 124 | 124 | |
| 125 | 125 | // Attach to the admin head with our ajax requests cycle and css |
| @@ -131,11 +131,16 @@ | ||
| 131 | 131 | |
| 132 | 132 | /** |
| 133 | 133 | * Admin scripts |
| 134 | 134 | * |
| 135 | - * @since 2.1.0 bbPress (r3813) | |
| 135 | + * @since 2.1.0 bbPress (r3816) | |
| 136 | + * @since 2.6.19 bbPress (r7739) Stop autoloading the saved source password. | |
| 136 | 137 | */ |
| 137 | 138 | public function admin_head() { |
| 139 | + // WordPress 6.4+ can stop autoloading an existing option without changing it. | |
| 140 | + if ( function_exists( 'wp_set_option_autoload_values' ) ) { | |
| 141 | + wp_set_option_autoload_values( array( '_bbp_converter_db_pass' => false ) ); | |
| 142 | + } | |
| 138 | 143 | |
| 139 | 144 | // Enqueue scripts |
| 140 | 145 | wp_enqueue_script( 'bbp-converter' ); |
| 141 | 146 | |
| @@ -190,19 +195,33 @@ | ||
| 190 | 195 | |
| 191 | 196 | /** |
| 192 | 197 | * Callback processor |
| 193 | 198 | * |
| 194 | - * @since 2.1.0 bbPress (r3813) | |
| 199 | + * @since 2.1.0 bbPress (r3816) | |
| 195 | 200 | */ |
| 196 | 201 | public function process_callback() { |
| 197 | 202 | |
| 198 | 203 | // Ready the converter |
| 199 | 204 | $this->check_access(); |
| 205 | + | |
| 206 | + // Reject unsafe source table names before saving options or importing. | |
| 207 | + $db_prefix = isset( $_POST['_bbp_converter_db_prefix'] ) | |
| 208 | + ? wp_unslash( $_POST['_bbp_converter_db_prefix'] ) | |
| 209 | + : ''; | |
| 210 | + if ( ! bbp_is_valid_converter_prefix( $db_prefix ) ) { | |
| 211 | + wp_send_json_error( array( 'message' => esc_html__( 'Invalid source database table prefix.', 'bbpress' ) ) ); | |
| 212 | + } | |
| 213 | + | |
| 200 | 214 | $this->maybe_set_memory(); |
| 201 | 215 | $this->maybe_restart(); |
| 202 | 216 | $this->setup_options(); |
| 203 | 217 | $this->maybe_update_options(); |
| 204 | 218 | |
| 219 | + // A valid submitted prefix may repair an invalid saved prefix. | |
| 220 | + if ( empty( $this->converter ) ) { | |
| 221 | + $this->setup_options(); | |
| 222 | + } | |
| 223 | + | |
| 205 | 224 | // Bail if no converter |
| 206 | 225 | if ( ! empty( $this->converter ) ) { |
| 207 | 226 | $this->do_steps(); |
| 208 | 227 | } |
| @@ -210,9 +229,9 @@ | ||
| 210 | 229 | |
| 211 | 230 | /** |
| 212 | 231 | * Wrap the converter output in HTML, so styling can be applied |
| 213 | 232 | * |
| 214 | - * @since 2.1.0 bbPress (r4052) | |
| 233 | + * @since 2.6.0 bbPress (r6601) | |
| 215 | 234 | * |
| 216 | 235 | * @param string $output |
| 217 | 236 | */ |
| 218 | 237 | private function converter_response( $output = '' ) { |
| @@ -304,9 +323,10 @@ | ||
| 304 | 323 | |
| 305 | 324 | /** |
| 306 | 325 | * Maybe update options |
| 307 | 326 | * |
| 308 | - * @since 2.6.0 bbPress (r6637) | |
| 327 | + * @since 2.6.0 bbPress (r6514) | |
| 328 | + * @since 2.6.19 bbPress (r7739) Keep or explicitly clear a saved source password. | |
| 309 | 329 | */ |
| 310 | 330 | private function maybe_update_options() { |
| 311 | 331 | |
| 312 | 332 | // Default options |
| @@ -341,13 +361,8 @@ | ||
| 341 | 361 | '_bbp_converter_db_user' => ! empty( $_POST['_bbp_converter_db_user'] ) |
| 342 | 362 | ? sanitize_text_field( $_POST['_bbp_converter_db_user'] ) |
| 343 | 363 | : '', |
| 344 | 364 | |
| 345 | - // DB Password | |
| 346 | - '_bbp_converter_db_pass' => ! empty( $_POST['_bbp_converter_db_pass'] ) | |
| 347 | - ? sanitize_text_field( $_POST['_bbp_converter_db_pass'] ) | |
| 348 | - : '', | |
| 349 | - | |
| 350 | 365 | // DB Name |
| 351 | 366 | '_bbp_converter_db_name' => ! empty( $_POST['_bbp_converter_db_name'] ) |
| 352 | 367 | ? sanitize_text_field( $_POST['_bbp_converter_db_name'] ) |
| 353 | 368 | : '', |
| @@ -367,12 +382,24 @@ | ||
| 367 | 382 | ? sanitize_text_field( $_POST['_bbp_converter_db_prefix'] ) |
| 368 | 383 | : '' |
| 369 | 384 | ); |
| 370 | 385 | |
| 386 | + // Saving site-level converter settings must not change the account option. | |
| 387 | + if ( ! current_user_can( 'bbp_tools_import_users' ) ) { | |
| 388 | + unset( $options['_bbp_converter_convert_users'] ); | |
| 389 | + } | |
| 390 | + | |
| 371 | 391 | // Update/delete options |
| 372 | 392 | foreach ( $options as $key => $value ) { |
| 373 | 393 | update_option( $key, $value ); |
| 374 | 394 | } |
| 395 | + | |
| 396 | + // A blank password keeps the saved value; clearing it is explicit. | |
| 397 | + if ( isset( $_POST['_bbp_converter_db_pass'] ) && is_string( $_POST['_bbp_converter_db_pass'] ) && '' !== $_POST['_bbp_converter_db_pass'] ) { | |
| 398 | + update_option( '_bbp_converter_db_pass', wp_unslash( $_POST['_bbp_converter_db_pass'] ), false ); | |
| 399 | + } elseif ( ! empty( $_POST['_bbp_converter_db_pass_clear'] ) || false === get_option( '_bbp_converter_db_pass', false ) ) { | |
| 400 | + update_option( '_bbp_converter_db_pass', '', false ); | |
| 401 | + } | |
| 375 | 402 | } |
| 376 | 403 | |
| 377 | 404 | /** |
| 378 | 405 | * Setup converter options |
| @@ -511,9 +538,9 @@ | ||
| 511 | 538 | |
| 512 | 539 | /** |
| 513 | 540 | * Maybe clean the sync table |
| 514 | 541 | * |
| 515 | - * @since 2.6.0 bbPress (r6513) | |
| 542 | + * @since 2.6.0 bbPress (r6514) | |
| 516 | 543 | */ |
| 517 | 544 | private function step_sync_table() { |
| 518 | 545 | if ( true === $this->converter->clean ) { |
| 519 | 546 | if ( $this->converter->clean() ) { |
| @@ -545,9 +572,9 @@ | ||
| 545 | 572 | |
| 546 | 573 | /** |
| 547 | 574 | * Maybe convert users |
| 548 | 575 | * |
| 549 | - * @since 2.6.0 bbPress (r6513) | |
| 576 | + * @since 2.6.0 bbPress (r6514) | |
| 550 | 577 | */ |
| 551 | 578 | private function step_users() { |
| 552 | 579 | if ( true === $this->converter->convert_users ) { |
| 553 | 580 | if ( $this->converter->convert_users( $this->start ) ) { |
| @@ -569,9 +596,9 @@ | ||
| 569 | 596 | |
| 570 | 597 | /** |
| 571 | 598 | * Maybe clean up passwords |
| 572 | 599 | * |
| 573 | - * @since 2.6.0 bbPress (r6513) | |
| 600 | + * @since 2.6.0 bbPress (r6514) | |
| 574 | 601 | */ |
| 575 | 602 | private function step_passwords() { |
| 576 | 603 | if ( true === $this->converter->convert_users ) { |
| 577 | 604 | if ( $this->converter->clean_passwords( $this->start ) ) { |
| @@ -593,9 +620,9 @@ | ||
| 593 | 620 | |
| 594 | 621 | /** |
| 595 | 622 | * Maybe convert forums |
| 596 | 623 | * |
| 597 | - * @since 2.6.0 bbPress (r6513) | |
| 624 | + * @since 2.6.0 bbPress (r6514) | |
| 598 | 625 | */ |
| 599 | 626 | private function step_forums() { |
| 600 | 627 | if ( $this->converter->convert_forums( $this->start ) ) { |
| 601 | 628 | $this->bump_step(); |
| @@ -612,9 +639,9 @@ | ||
| 612 | 639 | |
| 613 | 640 | /** |
| 614 | 641 | * Maybe walk the forum hierarchy |
| 615 | 642 | * |
| 616 | - * @since 2.6.0 bbPress (r6513) | |
| 643 | + * @since 2.6.0 bbPress (r6514) | |
| 617 | 644 | */ |
| 618 | 645 | private function step_forum_hierarchy() { |
| 619 | 646 | if ( $this->converter->convert_forum_parents( $this->start ) ) { |
| 620 | 647 | $this->bump_step(); |
| @@ -631,9 +658,9 @@ | ||
| 631 | 658 | |
| 632 | 659 | /** |
| 633 | 660 | * Maybe convert forum subscriptions |
| 634 | 661 | * |
| 635 | - * @since 2.6.0 bbPress (r6513) | |
| 662 | + * @since 2.6.0 bbPress (r6514) | |
| 636 | 663 | */ |
| 637 | 664 | private function step_forum_subscriptions() { |
| 638 | 665 | if ( $this->converter->convert_forum_subscriptions( $this->start ) ) { |
| 639 | 666 | $this->bump_step(); |
| @@ -650,9 +677,9 @@ | ||
| 650 | 677 | |
| 651 | 678 | /** |
| 652 | 679 | * Maybe convert topics |
| 653 | 680 | * |
| 654 | - * @since 2.6.0 bbPress (r6513) | |
| 681 | + * @since 2.6.0 bbPress (r6514) | |
| 655 | 682 | */ |
| 656 | 683 | private function step_topics() { |
| 657 | 684 | if ( $this->converter->convert_topics( $this->start ) ) { |
| 658 | 685 | $this->bump_step(); |
| @@ -669,9 +696,9 @@ | ||
| 669 | 696 | |
| 670 | 697 | /** |
| 671 | 698 | * Maybe convert topic authors (anonymous) |
| 672 | 699 | * |
| 673 | - * @since 2.6.0 bbPress (r6513) | |
| 700 | + * @since 2.6.0 bbPress (r6514) | |
| 674 | 701 | */ |
| 675 | 702 | private function step_topics_authors() { |
| 676 | 703 | if ( $this->converter->convert_anonymous_topic_authors( $this->start ) ) { |
| 677 | 704 | $this->bump_step(); |
| @@ -688,9 +715,9 @@ | ||
| 688 | 715 | |
| 689 | 716 | /** |
| 690 | 717 | * Maybe convert sticky topics (not super stickies) |
| 691 | 718 | * |
| 692 | - * @since 2.6.0 bbPress (r6513) | |
| 719 | + * @since 2.6.0 bbPress (r6514) | |
| 693 | 720 | */ |
| 694 | 721 | private function step_stickies() { |
| 695 | 722 | if ( $this->converter->convert_topic_stickies( $this->start ) ) { |
| 696 | 723 | $this->bump_step(); |
| @@ -707,9 +734,9 @@ | ||
| 707 | 734 | |
| 708 | 735 | /** |
| 709 | 736 | * Maybe convert super-sticky topics (not per-forum) |
| 710 | 737 | * |
| 711 | - * @since 2.6.0 bbPress (r6513) | |
| 738 | + * @since 2.6.0 bbPress (r6514) | |
| 712 | 739 | */ |
| 713 | 740 | private function step_super_stickies() { |
| 714 | 741 | if ( $this->converter->convert_topic_super_stickies( $this->start ) ) { |
| 715 | 742 | $this->bump_step(); |
| @@ -726,9 +753,9 @@ | ||
| 726 | 753 | |
| 727 | 754 | /** |
| 728 | 755 | * Maybe close converted topics |
| 729 | 756 | * |
| 730 | - * @since 2.6.0 bbPress (r6513) | |
| 757 | + * @since 2.6.0 bbPress (r6514) | |
| 731 | 758 | */ |
| 732 | 759 | private function step_closed_topics() { |
| 733 | 760 | if ( $this->converter->convert_topic_closed_topics( $this->start ) ) { |
| 734 | 761 | $this->bump_step(); |
| @@ -745,9 +772,9 @@ | ||
| 745 | 772 | |
| 746 | 773 | /** |
| 747 | 774 | * Maybe convert topic tags |
| 748 | 775 | * |
| 749 | - * @since 2.6.0 bbPress (r6513) | |
| 776 | + * @since 2.6.0 bbPress (r6514) | |
| 750 | 777 | */ |
| 751 | 778 | private function step_topic_tags() { |
| 752 | 779 | if ( $this->converter->convert_tags( $this->start ) ) { |
| 753 | 780 | $this->bump_step(); |
| @@ -764,9 +791,9 @@ | ||
| 764 | 791 | |
| 765 | 792 | /** |
| 766 | 793 | * Maybe convert topic subscriptions |
| 767 | 794 | * |
| 768 | - * @since 2.6.0 bbPress (r6513) | |
| 795 | + * @since 2.6.0 bbPress (r6514) | |
| 769 | 796 | */ |
| 770 | 797 | private function step_topic_subscriptions() { |
| 771 | 798 | if ( $this->converter->convert_topic_subscriptions( $this->start ) ) { |
| 772 | 799 | $this->bump_step(); |
| @@ -783,9 +810,9 @@ | ||
| 783 | 810 | |
| 784 | 811 | /** |
| 785 | 812 | * Maybe convert topic favorites |
| 786 | 813 | * |
| 787 | - * @since 2.6.0 bbPress (r6513) | |
| 814 | + * @since 2.6.0 bbPress (r6514) | |
| 788 | 815 | */ |
| 789 | 816 | private function step_topic_favorites() { |
| 790 | 817 | if ( $this->converter->convert_favorites( $this->start ) ) { |
| 791 | 818 | $this->bump_step(); |
| @@ -802,9 +829,9 @@ | ||
| 802 | 829 | |
| 803 | 830 | /** |
| 804 | 831 | * Maybe convert replies |
| 805 | 832 | * |
| 806 | - * @since 2.6.0 bbPress (r6513) | |
| 833 | + * @since 2.6.0 bbPress (r6514) | |
| 807 | 834 | */ |
| 808 | 835 | private function step_replies() { |
| 809 | 836 | if ( $this->converter->convert_replies( $this->start ) ) { |
| 810 | 837 | $this->bump_step(); |
| @@ -821,9 +848,9 @@ | ||
| 821 | 848 | |
| 822 | 849 | /** |
| 823 | 850 | * Maybe convert reply authors (anonymous) |
| 824 | 851 | * |
| 825 | - * @since 2.6.0 bbPress (r6513) | |
| 852 | + * @since 2.6.0 bbPress (r6514) | |
| 826 | 853 | */ |
| 827 | 854 | private function step_reply_authors() { |
| 828 | 855 | if ( $this->converter->convert_anonymous_reply_authors( $this->start ) ) { |
| 829 | 856 | $this->bump_step(); |
| @@ -840,9 +867,9 @@ | ||
| 840 | 867 | |
| 841 | 868 | /** |
| 842 | 869 | * Maybe convert the threaded reply hierarchy |
| 843 | 870 | * |
| 844 | - * @since 2.6.0 bbPress (r6513) | |
| 871 | + * @since 2.6.0 bbPress (r6514) | |
| 845 | 872 | */ |
| 846 | 873 | private function step_reply_hierarchy() { |
| 847 | 874 | if ( $this->converter->convert_reply_to_parents( $this->start ) ) { |
| 848 | 875 | $this->bump_step(); |
| @@ -859,9 +886,9 @@ | ||
| 859 | 886 | |
| 860 | 887 | /** |
| 861 | 888 | * Done! |
| 862 | 889 | * |
| 863 | - * @since 2.6.0 bbPress (r6513) | |
| 890 | + * @since 2.6.0 bbPress (r6514) | |
| 864 | 891 | */ |
| 865 | 892 | private function step_done() { |
| 866 | 893 | $this->reset(); |
| 867 | 894 | $this->converter_response( esc_html__( 'Import Finished', 'bbpress' ) ); |
| @@ -871,9 +898,9 @@ | ||
| 871 | 898 | |
| 872 | 899 | /** |
| 873 | 900 | * Create Tables for fast syncing |
| 874 | 901 | * |
| 875 | - * @since 2.1.0 bbPress (r3813) | |
| 902 | + * @since 2.1.0 bbPress (r3816) | |
| 876 | 903 | */ |
| 877 | 904 | public static function sync_table( $drop = false ) { |
| 878 | 905 | |
| 879 | 906 | // Setup DB |