PluginProbe
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder / 2.21.4
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder v2.21.4
V-3.3.0 3.2.2 3.2.1 3.2.0 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 V3.0.3 V3.0.2 -3.0.1 V_3.0.0 1.1.1 1.1.8 1.2 1.3 1.4 1.4.18 1.5.2 1.9 2.0 2.10.0 2.10.1 2.10.2 All 137 releases
← All changes | includes/API/Controller/EntryController.php +33 -26 2.02.21.4 View file →
@@ -6,46 +6,53 @@
6 6 use WP_Error;
7 7 use WP_REST_Controller;
8 8 use WP_REST_Request;
9 9
10 -class EntryController extends WP_REST_Controller {
10 +class EntryController extends WP_REST_Controller
11 +{
11 12 protected static $form;
12 13 protected $formModel;
13 14 protected $form_id;
14 15
15 - public function __construct() {
16 + public function __construct()
17 + {
16 18 $this->formModel = new FormModel();
17 19 }
18 20
19 - public function googleAuth() {
20 - $state = $_GET['state'];
21 - $code = urlencode($_GET['code']);
22 - // echo $code;
23 - if (wp_redirect($state . '&code=' . $code, 302)) {
24 - exit;
25 - }
26 - }
21 + // public function oneDriveAuth()
22 + // {
23 + // $state = $_GET['state'];
24 + // $code = urlencode($_GET['code']);
25 + // // echo $code;
26 + // if (wp_redirect($state . '&code=' . $code, 302)) {
27 + // exit;
28 + // }
29 + // }
27 30
28 - public function oneDriveAuth() {
29 - $state = $_GET['state'];
30 - $code = urlencode($_GET['code']);
31 - // echo $code;
32 - if (wp_redirect($state . '&code=' . $code, 302)) {
33 - exit;
31 + public function authRedirect(WP_REST_Request $request)
32 + {
33 + $state = $request->get_param('state');
34 + $site_url = $this->getDomain(get_site_url());
35 + $state_domain = $this->getDomain($state);
36 +
37 + if ($site_url !== $state_domain) {
38 + return new WP_Error('404', 'Invalid redirect URL: ' . $state_domain);
34 39 }
35 - }
36 40
37 - public function authRedirect(WP_REST_Request $request) {
38 - $state = $request->get_param('state');
39 - $parsed_url = parse_url(get_site_url());
40 - $site_url = $parsed_url['scheme'] . '://' . $parsed_url['host'];
41 - $site_url .= empty($parsed_url['port']) ? null : ':' . $parsed_url['port'];
42 - if (false === strpos($state, $site_url)) {
43 - return new WP_Error('404');
44 - }
45 41 $params = $request->get_params();
46 42 unset($params['rest_route'], $params['state']);
47 - if (wp_redirect($state . '&' . http_build_query($params), 302)) {
43 +
44 + $redirect_url = $state . '&' . http_build_query($params);
45 +
46 + if (wp_redirect($redirect_url, 302)) {
48 47 exit;
49 48 }
49 + }
50 +
51 + private function getDomain($url)
52 + {
53 + $parsed_url = wp_parse_url($url);
54 + $domain = $parsed_url['scheme'] . '://' . $parsed_url['host'];
55 + $domain .= empty($parsed_url['port']) ? null : ':' . $parsed_url['port'];
56 + return $domain;
50 57 }
51 58 }