| @@ -3,10 +3,12 @@ | ||
| 3 | 3 | namespace BitCode\BitForm\Core\Capability; |
| 4 | 4 | |
| 5 | 5 | use BitCode\BitForm\Core\Util\FileDownloadProvider; |
| 6 | 6 | |
| 7 | -final class Request { | |
| 8 | - public static function Check($type) { | |
| 7 | +final class Request | |
| 8 | +{ | |
| 9 | + public static function Check($type) | |
| 10 | + { | |
| 9 | 11 | switch ($type) { |
| 10 | 12 | case 'admin': |
| 11 | 13 | return is_admin(); |
| 12 | 14 | |
| @@ -23,22 +25,38 @@ | ||
| 23 | 25 | return (!is_admin() || defined('DOING_AJAX')) && !defined('DOING_CRON'); |
| 24 | 26 | } |
| 25 | 27 | } |
| 26 | 28 | |
| 27 | - public static function isPluginPage() { | |
| 28 | - $queryToRemove = ['formID', 'entryID', 'fileID', 'download']; | |
| 29 | - $parsed_url = parse_url(home_url()); | |
| 30 | - $site_url = $parsed_url['scheme'] . '://' . $parsed_url['host']; | |
| 29 | + public static function isPluginPage() | |
| 30 | + { | |
| 31 | + // Plain permalinks put the file route in the query string (?post_type=bitforms&p=ID), | |
| 32 | + // pretty permalinks put it in the path (/bitforms/bitforms-file/). Match both, otherwise | |
| 33 | + // the download handler/shortcode never registers on plain-permalink sites. | |
| 34 | + $routes = get_option('bitforms_routes'); | |
| 35 | + $fileRouteId = isset($routes['file']) ? (int) $routes['file'] : 0; | |
| 31 | 36 | |
| 32 | - $reqUrl = $site_url . remove_query_arg($queryToRemove, $_SERVER['REQUEST_URI']); | |
| 33 | - $downloadUrl = FileDownloadProvider::getBaseDownloadURL(); | |
| 34 | - $reqUrl = '/' !== \substr($reqUrl, -1) ? $reqUrl . '/' : $reqUrl; | |
| 35 | - $downloadUrl = '/' !== \substr($downloadUrl, -1) ? $downloadUrl . '/' : $downloadUrl; | |
| 36 | - switch ($reqUrl) { | |
| 37 | - case $downloadUrl:{ | |
| 37 | + // Plain permalink: ?p=ID (post) or ?page_id=ID, with post_type=bitforms. | |
| 38 | + // Read-only: query vars inspected to detect plugin-managed URL. No state change. | |
| 39 | + if (!empty($fileRouteId)) { | |
| 40 | + $reqPostId = 0; | |
| 41 | + if (isset($_GET['p']) && !is_array($_GET['p'])) { | |
| 42 | + $reqPostId = (int) $_GET['p']; | |
| 43 | + } elseif (isset($_GET['page_id']) && !is_array($_GET['page_id'])) { | |
| 44 | + $reqPostId = (int) $_GET['page_id']; | |
| 45 | + } | |
| 46 | + if ($reqPostId === $fileRouteId) { | |
| 38 | 47 | return true; |
| 39 | 48 | } |
| 40 | - default: | |
| 41 | - return false; | |
| 42 | 49 | } |
| 50 | + | |
| 51 | + // Pretty permalink: compare request path against the download URL path. | |
| 52 | + $downloadUrl = FileDownloadProvider::getBaseDownloadURL(); | |
| 53 | + $downloadPath = wp_parse_url($downloadUrl, PHP_URL_PATH); | |
| 54 | + // Read-only: REQUEST_URI parsed to check if current request targets a plugin-managed URL. No state change. | |
| 55 | + $reqPath = isset($_SERVER['REQUEST_URI']) ? wp_parse_url(wp_unslash($_SERVER['REQUEST_URI']), PHP_URL_PATH) : ''; | |
| 56 | + if (empty($downloadPath) || empty($reqPath)) { | |
| 57 | + return false; | |
| 58 | + } | |
| 59 | + | |
| 60 | + return untrailingslashit($downloadPath) === untrailingslashit($reqPath); | |
| 43 | 61 | } |
| 44 | 62 | } |