PluginProbe
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar / 2.1.21
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar v2.1.21
2.1.22 2.1.21 2.1.20 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 trunk 1.1 2.0 2.0.1 2.0.10.2 2.0.11 2.0.12 2.0.13 2.0.14 2.0.15 2.0.16 2.0.17 2.0.18 2.0.2 2.0.20 2.0.21 All 56 releases
← All changes | core/wpbm-functions.php +395 -551 2.0.11 → 2.1.21 View file →
@@ -71,10 +71,10 @@
71 71 */
72 72 function wpbm_is_this_demo() {
73 73 //return ! true; //TODO: comment it. 2016-09-27 // Replaced!
74 74 if (
75 - ( ( isset( $_SERVER['SCRIPT_FILENAME'] ) ) && ( strpos( $_SERVER['SCRIPT_FILENAME'], 'oplugins.com' ) !== false ) )
76 - || ( ( isset( $_SERVER['HTTP_HOST'] ) ) && ( strpos( $_SERVER['HTTP_HOST'], 'oplugins.com' ) !== false ) )
75 + ( ( isset( $_SERVER['SCRIPT_FILENAME'] ) ) && ( strpos( sanitize_text_field( wp_unslash($_SERVER['SCRIPT_FILENAME']) ), 'oplugins.com' ) !== false ) )
76 + || ( ( isset( $_SERVER['HTTP_HOST'] ) ) && ( strpos( sanitize_text_field( wp_unslash($_SERVER['HTTP_HOST'])), 'oplugins.com' ) !== false ) )
77 77 )
78 78 return true;
79 79 else
80 80 return false;
@@ -89,191 +89,9 @@
89 89 /** Show System Info (status) at item > Settings General page
90 90 * Link: http://server.com/wp-admin/admin.php?page=wpbm-settings&system_info=show#wpbm_general_settings_system_info_metabox
91 91 */
92 92 function wpbm_system_info() {
93 -
94 - if ( wpbm_is_this_demo() ) return;
95 -
96 - if ( current_user_can( 'activate_plugins' ) ) { // Only for Administrator or Super admin. More here: https://codex.wordpress.org/Roles_and_Capabilities
97 -
98 - global $wpdb, $wp_version;
99 -
100 - $all_plugins = get_plugins();
101 - $active_plugins = get_option( 'active_plugins' );
102 -
103 - $mysql_info = $wpdb->get_results( "SHOW VARIABLES LIKE 'sql_mode'" );
104 - if ( is_array( $mysql_info ) ) $sql_mode = $mysql_info[0]->Value;
105 - if ( empty( $sql_mode ) ) $sql_mode = 'Not set';
106 -
107 - $safe_mode = ( ini_get( 'safe_mode' ) ) ? 'On' : 'Off';
108 - $allow_url_fopen = ( ini_get( 'allow_url_fopen' ) ) ? 'On' : 'Off';
109 - $upload_max_filesize = ( ini_get( 'upload_max_filesize' ) ) ? ini_get( 'upload_max_filesize' ) : 'N/A';
110 - $post_max_size = ( ini_get( 'post_max_size' ) ) ? ini_get( 'post_max_size' ) : 'N/A';
111 - $max_execution_time = ( ini_get( 'max_execution_time' ) ) ? ini_get( 'max_execution_time' ) : 'N/A';
112 - $memory_limit = ( ini_get( 'memory_limit' ) ) ? ini_get( 'memory_limit' ) : 'N/A';
113 - $memory_usage = ( function_exists( 'memory_get_usage' ) ) ? round( memory_get_usage() / 1024 / 1024, 2 ) . ' Mb' : 'N/A';
114 - $exif_read_data = ( is_callable( 'exif_read_data' ) ) ? 'Yes' . " ( V" . substr( phpversion( 'exif' ), 0, 4 ) . ")" : 'No';
115 - $iptcparse = ( is_callable( 'iptcparse' ) ) ? 'Yes' : 'No';
116 - $xml_parser_create = ( is_callable( 'xml_parser_create' ) ) ? 'Yes' : 'No';
117 - $theme = ( function_exists( 'wp_get_theme' ) ) ? wp_get_theme() : get_theme( get_current_theme() );
118 -
119 - if ( function_exists( 'is_multisite' ) ) {
120 - if ( is_multisite() ) $multisite = 'Yes';
121 - else $multisite = 'No';
122 - } else { $multisite = 'N/A';
123 - }
124 -
125 - $system_info = array(
126 - 'system_info' => '',
127 - 'php_info' => '',
128 - 'active_plugins' => '',
129 - 'inactive_plugins' => ''
130 - );
131 -
132 - $ver_small_name = get_wpbm_version();
133 - if ( class_exists( 'wpbm_multiuser' ) ) $ver_small_name = 'multiuser';
134 -
135 - $system_info['system_info'] = array(
136 - 'Plugin Update' => ( defined( 'WPBM_VERSION' ) ) ? WPBM_VERSION : 'N/A',
137 - 'Plugin Version' => ucwords( $ver_small_name ),
138 - 'Plugin Update Date' => date( "Y-m-d", filemtime( WPBM_FILE ) ),
139 -
140 - 'WP Version' => $wp_version,
141 - 'WP DEBUG' => ( ( defined('WP_DEBUG') ) && ( WP_DEBUG ) ) ? 'On' : 'Off',
142 - 'WP DB Version' => get_option( 'db_version' ),
143 - 'Operating System' => PHP_OS,
144 - 'Server' => $_SERVER["SERVER_SOFTWARE"],
145 - 'PHP Version' => PHP_VERSION,
146 - 'PHP Safe Mode' => $safe_mode,
147 - 'MYSQL Version' => $wpdb->get_var( "SELECT VERSION() AS version" ),
148 - 'SQL Mode' => $sql_mode,
149 - 'Memory usage' => $memory_usage,
150 - 'Site URL' => get_option( 'siteurl' ),
151 - 'Home URL' => home_url(),
152 - 'SERVER[HTTP_HOST]' => $_SERVER['HTTP_HOST'],
153 - 'SERVER[SERVER_NAME]' => $_SERVER['SERVER_NAME'],
154 - 'Multisite' => $multisite,
155 - 'Active Theme' => $theme['Name'] . ' ' . $theme['Version']
156 - );
157 -
158 - $system_info['php_info'] = array(
159 - 'PHP Version' => PHP_VERSION,
160 - 'PHP Safe Mode' => $safe_mode,
161 - 'PHP Memory Limit' => '<strong>' . $memory_limit . '</strong>',
162 - 'PHP Max Script Execute Time' => '<strong>' . $max_execution_time . '</strong>',
163 -
164 - 'PHP Max Post Size' => '<strong>' . $post_max_size . '</strong>',
165 - 'PHP MAX Input Vars' => '<strong>' . ( ( ini_get( 'max_input_vars' ) ) ? ini_get( 'max_input_vars' ) : 'N/A' ) . '</strong>', //How many input variables may be accepted (limit is applied to $_GET, $_POST and $_COOKIE superglobal separately).
166 -
167 - 'PHP Max Upload Size' => $upload_max_filesize,
168 - 'PHP Allow URL fopen' => $allow_url_fopen,
169 - 'PHP Exif support' => $exif_read_data,
170 - 'PHP IPTC support' => $iptcparse,
171 - 'PHP XML support' => $xml_parser_create
172 - );
173 -
174 - $system_info['php_info']['PHP cURL'] = ( function_exists('curl_init') ) ? 'On' : 'Off';
175 - $system_info['php_info']['Max Nesting Level'] = ( ( ini_get( 'max_input_nesting_level' ) ) ? ini_get( 'max_input_nesting_level' ) : 'N/A' );
176 - $system_info['php_info']['Max Time 4 script'] = ( ( ini_get( 'max_input_time' ) ) ? ini_get( 'max_input_time' ) : 'N/A' ); //Maximum amount of time each script may spend parsing request data
177 - $system_info['php_info']['Log'] = ( ( ini_get( 'error_log' ) ) ? ini_get( 'error_log' ) : 'N/A' );
178 -
179 - if ( ini_get( "suhosin.get.max_value_length" ) ) {
180 -
181 - $system_info['suhosin_info'] = array();
182 - $system_info['suhosin_info']['POST max_array_index_length'] = ( ( ini_get( 'suhosin.post.max_array_index_length' ) ) ? ini_get( 'suhosin.post.max_array_index_length' ) : 'N/A' );
183 - $system_info['suhosin_info']['REQUEST max_array_index_length'] = ( ( ini_get( 'suhosin.request.max_array_index_length' ) ) ? ini_get( 'suhosin.request.max_array_index_length' ) : 'N/A' );
184 -
185 - $system_info['suhosin_info']['POST max_totalname_length'] = ( ( ini_get( 'suhosin.post.max_totalname_length' ) ) ? ini_get( 'suhosin.post.max_totalname_length' ) : 'N/A' );
186 - $system_info['suhosin_info']['REQUEST max_totalname_length'] = ( ( ini_get( 'suhosin.request.max_totalname_length' ) ) ? ini_get( 'suhosin.request.max_totalname_length' ) : 'N/A' );
187 -
188 - $system_info['suhosin_info']['POST max_vars'] = ( ( ini_get( 'suhosin.post.max_vars' ) ) ? ini_get( 'suhosin.post.max_vars' ) : 'N/A' );
189 - $system_info['suhosin_info']['REQUEST max_vars'] = ( ( ini_get( 'suhosin.request.max_vars' ) ) ? ini_get( 'suhosin.request.max_vars' ) : 'N/A' );
190 -
191 - $system_info['suhosin_info']['POST max_value_length'] = ( ( ini_get( 'suhosin.post.max_value_length' ) ) ? ini_get( 'suhosin.post.max_value_length' ) : 'N/A' );
192 - $system_info['suhosin_info']['REQUEST max_value_length'] = ( ( ini_get( 'suhosin.request.max_value_length' ) ) ? ini_get( 'suhosin.request.max_value_length' ) : 'N/A' );
193 -
194 - $system_info['suhosin_info']['POST max_name_length'] = ( ( ini_get( 'suhosin.post.max_name_length' ) ) ? ini_get( 'suhosin.post.max_name_length' ) : 'N/A' );
195 - $system_info['suhosin_info']['REQUEST max_varname_length'] = ( ( ini_get( 'suhosin.request.max_varname_length' ) ) ? ini_get( 'suhosin.request.max_varname_length' ) : 'N/A' );
196 -
197 - $system_info['suhosin_info']['POST max_array_depth'] = ( ( ini_get( 'suhosin.post.max_array_depth' ) ) ? ini_get( 'suhosin.post.max_array_depth' ) : 'N/A' );
198 - $system_info['suhosin_info']['REQUEST max_array_depth'] = ( ( ini_get( 'suhosin.request.max_array_depth' ) ) ? ini_get( 'suhosin.request.max_array_depth' ) : 'N/A' );
199 - }
200 -
201 -
202 - if ( function_exists('gd_info') ) {
203 - $gd_info = gd_info();
204 - if ( isset( $gd_info['GD Version'] ) )
205 - $gd_info = $gd_info['GD Version'];
206 - else
207 - $gd_info = json_encode( $gd_info );
208 - } else {
209 - $gd_info = 'Off';
210 - }
211 - $system_info['php_info']['PHP GD'] = $gd_info;
212 -
213 - // More here https://docs.woocommerce.com/document/problems-with-large-amounts-of-data-not-saving-variations-rates-etc/
214 -
215 -
216 - foreach ( $all_plugins as $path => $plugin ) {
217 - if ( is_plugin_active( $path ) )
218 - $system_info['active_plugins'][$plugin['Name']] = $plugin['Version'];
219 - else
220 - $system_info['inactive_plugins'][$plugin['Name']] = $plugin['Version'];
221 - }
222 -
223 - // Showing
224 - foreach ( $system_info as $section_name => $section_values ) {
225 - ?>
226 - <span class="wpdevelop">
227 - <table class="table table-striped table-bordered">
228 - <thead><tr><th colspan="2" style="border-bottom: 1px solid #eeeeee;padding: 10px;"><?php echo strtoupper( $section_name ); ?></th></tr></thead>
229 - <tbody>
230 - <?php
231 - if ( !empty( $section_values ) ) {
232 - foreach ( $section_values as $key => $value ) {
233 - ?>
234 - <tr>
235 - <td scope="row" style="width:18em;padding:4px 8px;"><?php echo $key; ?></td>
236 - <td scope="row" style="padding:4px 8px;"><?php echo $value; ?></td>
237 - </tr>
238 - <?php
239 - }
240 - }
241 - ?>
242 - </tbody>
243 - </table>
244 - </span>
245 - <div class="clear"></div>
246 - <?php
247 - }
248 -?>
249 -<hr>
250 -<div style="color:#777;">
251 -<h4 style="font-size:1.1em;">Commonly required configuration vars in php.ini file:</h4>
252 -<h4>General section:</h4>
253 -<pre><code>memory_limit = 256M
254 -max_execution_time = 120
255 -post_max_size = 8M
256 -upload_max_filesize = 8M
257 -max_input_vars = 20480
258 -post_max_size = 64M</code></pre>
259 -<h4>Suhosin section (if installed):</h4>
260 -<pre><code>suhosin.post.max_array_index_length = 1024
261 -suhosin.post.max_totalname_length = 65535
262 -suhosin.post.max_vars = 2048
263 -suhosin.post.max_value_length = 1000000
264 -suhosin.post.max_name_length = 256
265 -suhosin.post.max_array_depth = 1000
266 -suhosin.request.max_array_index_length = 1024
267 -suhosin.request.max_totalname_length = 65535
268 -suhosin.request.max_vars = 2048
269 -suhosin.request.max_value_length = 1000000
270 -suhosin.request.max_varname_length = 256
271 -suhosin.request.max_array_depth = 1000</code></pre>
272 -</div>
273 -<?php
274 - // phpinfo();
275 - }
93 + echo '---';
276 94 }
277 95
278 96
279 97
@@ -296,9 +114,9 @@
296 114 function wpbm_is_wpbc_supported() {
297 115
298 116 // 7.2.1 - its start version of Booking Calendar which support integration with Booking Manager 2.0
299 117
300 - if ( version_compare( wpbm_get_wpbc_version(), '7.2.1') >= 0 ) {
118 + if ( version_compare( wpbm_get_wpbc_version(), '9.8') >= 0 ) {
301 119 return true;
302 120 } else {
303 121 return false;
304 122 }
@@ -431,9 +249,9 @@
431 249 '', // Unknown/unhandled entities
432 250 ' ' // Runs of spaces, post-handling
433 251 );
434 252
435 - $newstring = preg_replace( $plain_search_array, $get_plain_replace_array, strip_tags( $string ) );
253 + $newstring = preg_replace( $plain_search_array, $get_plain_replace_array, wp_strip_all_tags( $string ) );
436 254
437 255 return $newstring;
438 256 }
439 257 // </editor-fold>
@@ -462,8 +280,10 @@
462 280 $replace = wp_parse_args( $replace_array, $defaults );
463 281
464 282 foreach ( $replace as $replace_shortcode => $replace_value ) {
465 283
284 + $replace_value = esc_js( $replace_value ); // FixIn:
285 +
466 286 $subject = str_replace( array( '[' . $replace_shortcode . ']'
467 287 , '{' . $replace_shortcode . '}' )
468 288 , $replace_value
469 289 , $subject );
@@ -476,10 +296,50 @@
476 296
477 297 return $subject;
478 298 }
479 299
300 +
301 +/**
302 + * Sanitize the frontend listing template.
303 + *
304 + * The listing template is stored as an option and rendered by the public
305 + * [booking-manager-listing] shortcode, so script-capable markup must never be
306 + * persisted or returned to visitors.
307 + *
308 + * @param string $template Template HTML with Booking Manager placeholders.
309 + * @return string Safe template HTML.
310 + */
311 +function wpbm_sanitize_listing_template( $template ) {
312 +
313 + if ( ! is_string( $template ) ) {
314 + $template = '';
315 + }
316 +
317 + $allowed_html = wp_kses_allowed_html( 'post' );
318 +
319 + // Keep compatibility with templates that embed safe external content.
320 + $allowed_html['iframe'] = array(
321 + 'src' => true
322 + , 'style' => true
323 + , 'id' => true
324 + , 'class' => true
325 + , 'width' => true
326 + , 'height' => true
327 + , 'title' => true
328 + , 'loading' => true
329 + , 'allowfullscreen' => true
330 + );
331 +
332 + if ( isset( $allowed_html['a'] ) ) {
333 + $allowed_html['a']['target'] = true;
334 + $allowed_html['a']['rel'] = true;
335 + }
336 +
337 + return wp_kses( $template, $allowed_html );
338 +}
339 +
480 340 /** Simple hack to make array strings lowercase
481 - *
341 + *
482 342 * @param type $array
483 343 * @return type
484 344 */
485 345 function wpbm_arraytolower( $array ){
@@ -506,22 +366,22 @@
506 366 }
507 367 }
508 368
509 369 /** Check if this valid timestamp
510 - *
370 + *
511 371 * @param string|int $timestamp
512 372 * @return bool
513 373 */
514 374 function wpbm_is_valid_timestamp( $timestamp ) {
515 - return ( ( (string) (int) $timestamp === $timestamp)
375 + return ( ( (string) (int) $timestamp === $timestamp)
516 376 && ($timestamp <= PHP_INT_MAX)
517 - && ($timestamp >= ~PHP_INT_MAX)
377 + && ($timestamp >= ~PHP_INT_MAX)
518 378 );
519 379 }
520 380 // </editor-fold>
521 381
522 -
523 -// <editor-fold defaultstate="collapsed" desc=" F i l e s && U R L s " >
382 +
383 +// <editor-fold defaultstate="collapsed" desc=" F i l e s && U R L s " >
524 384 ////////////////////////////////////////////////////////////////////////////////
525 385 // F i l e s && U R L s
526 386 ////////////////////////////////////////////////////////////////////////////////
527 387
@@ -546,9 +406,9 @@
546 406 return trailingslashit( WPBM_PLUGIN_URL ) . ltrim( $path, '/\\' );
547 407 }
548 408
549 409 /** Check if such file exist or not.
550 - *
410 + *
551 411 * @param string $path - relative path to file (relative to plugin folder).
552 412 * @return boolean true | false
553 413 */
554 414 function wpbm_is_file_exist( $path ) {
@@ -554,14 +414,14 @@
554 414 function wpbm_is_file_exist( $path ) {
555 415
556 416 if ( file_exists( trailingslashit( WPBM_PLUGIN_DIR ) . ltrim( $path, '/\\' ) ) ) // check if this file exist
557 417 return true;
558 - else
418 + else
559 419 return false;
560 420 }
561 -
421 +
562 422 /** Set URL from absolute to relative (starting from /)
563 - *
423 + *
564 424 * @param type $url
565 425 * @return type
566 426 */
567 427 function wpbm_set_relative_url( $url ){
@@ -574,24 +434,24 @@
574 434 $url = trim($url_path, '/');
575 435 return '/' . $url;
576 436 }
577 437
578 -/** Get Correct Relative URL
579 - *
438 +/** Get Correct Relative URL
439 + *
580 440 * @param type $link
581 441 * @return string
582 442 */
583 443 function wpbm_make_link_relative( $link ){
584 444
585 - if ( $link == get_option('siteurl') )
445 + if ( $link == get_option('siteurl') )
586 446 $link = '/';
587 - $link = '/' . trim( wp_make_link_relative( $link ), '/' );
447 + $link = '/' . trim( wp_make_link_relative( $link ), '/' );
588 448
589 - return $link;
449 + return $link;
590 450 }
591 451
592 -/** Get Correct Absolute URL
593 - *
452 +/** Get Correct Absolute URL
453 + *
594 454 * @param string $link
595 455 * @return type
596 456 */
597 457 function wpbm_make_link_absolute( $link ){
@@ -596,17 +456,17 @@
596 456 */
597 457 function wpbm_make_link_absolute( $link ){
598 458
599 459 if ( ( $link != get_option('siteurl') ) && ( strpos($link, 'http') !== 0 ) )
600 - $link = get_option('siteurl') . '/' . trim( wp_make_link_relative( $link ), '/' );
460 + $link = get_option('siteurl') . '/' . trim( wp_make_link_relative( $link ), '/' );
601 461 return esc_js( $link ) ;
602 462 }
603 463
604 464
605 465 if (!function_exists ('get_file_data_wpdev')) {
606 -
466 +
607 467 /** Get header info from this file, just for compatibility with WordPress 2.8 and older versions
608 - *
468 + *
609 469 * @param type $file
610 470 * @param type $default_headers
611 471 * @param type $context
612 472 * @return type
@@ -612,15 +472,15 @@
612 472 * @return type
613 473 */
614 474 function get_file_data_wpdev( $file, $default_headers, $context = '' ) {
615 475 // We don't need to write to the file, so just open for reading.
616 - $fp = fopen( $file, 'r' );
476 + $fp = fopen( $file, 'r' ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fopen
617 477
618 478 // Pull only the first 8kiB of the file in.
619 - $file_data = fread( $fp, 8192 );
479 + $file_data = fread( $fp, 8192 );// phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fread
620 480
621 481 // PHP will close file handle, but we are good citizens.
622 - fclose( $fp );
482 + fclose( $fp );// phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fclose
623 483
624 484 if( $context != '' ) {
625 485 $extra_headers = array(); //apply_filters( "extra_$context".'_headers', array() );
626 486
@@ -648,9 +508,9 @@
648 508 }
649 509
650 510
651 511 /** Get content from specific URL
652 - *
512 + *
653 513 * @param string $url
654 514 * @return string|boolean (false on error)
655 515 */
656 516 function wpbm_get_ssl_page_content( $url ) {
@@ -658,13 +518,15 @@
658 518 $request = new WP_Http();
659 519
660 520 $result = $request->request( $url
661 521 , array( // Default Parameters
522 + 'reject_unsafe_urls' => true, //FixIn: 2.0.29.1
523 + 'user-agent' => 'Mozilla/5.0 (iPad; U; CPU OS 3_2_1 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Mobile/7B405' //FixIn: 2.0.12.1
662 524 // 'method' => 'GET',
663 525 // 'timeout' => 5, // timeout value for an HTTP request.
664 - // 'redirection' => 5, // number of redirects allowed during an HTTP request.
665 - // 'httpversion' => '1.0',
666 - // 'user-agent' => 'WordPress/' . get_bloginfo( 'version' ) . '; ' . get_bloginfo( 'url' ),
526 + // 'redirection' => 5, // number of redirects allowed during an HTTP request.
527 + // 'httpversion' => '1.0',
528 + // 'user-agent' => 'WordPress/' . get_bloginfo( 'version' ) . '; ' . get_bloginfo( 'url' ),
667 529 // 'reject_unsafe_urls' => false,
668 530 // 'blocking' => true,
669 531 // 'headers' => array(),
670 532 // 'cookies' => array(),
@@ -675,14 +537,14 @@
675 537 // 'sslcertificates' => ABSPATH . WPINC . '/certificates/ca-bundle.crt',
676 538 // 'stream' => false,
677 539 // 'filename' => null,
678 540 // 'limit_response_size' => null
679 - )
541 + )
680 542 );
681 543
682 - if (
683 - ( ! is_wp_error( $result ) )
684 - && ( $result[ 'response' ][ 'code' ] == '200' )
544 + if (
545 + ( ! is_wp_error( $result ) )
546 + && ( $result[ 'response' ][ 'code' ] == '200' )
685 547 ) {
686 548
687 549 return $result[ 'body' ];
688 550
@@ -727,9 +589,9 @@
727 589 $d = 0; // string bytes counter
728 590
729 591 // Iterate over every character in the string, escaping with a slash or encoding to UTF-8 where necessary
730 592 for ( $c = 0; $c < $strlen_var; ++ $c ) {
731 - $ord_var_c = ord( $str{$c} );
593 + $ord_var_c = ord( $str[$c] ); //FixIn: 2.0.17.1
732 594 switch ( true ) {
733 595 case(($ord_var_c >= 0x20) && ($ord_var_c <= 0x7F)): // characters U-00000000 - U-0000007F (same as ASCII)
734 596 $d ++;
735 597 break;
@@ -758,15 +620,15 @@
758 620
759 621 // </editor-fold>
760 622
761 623
762 -// <editor-fold defaultstate="collapsed" desc=" A d m i n M e n u L i n k s " >
624 +// <editor-fold defaultstate="collapsed" desc=" A d m i n M e n u L i n k s " >
763 625 ////////////////////////////////////////////////////////////////////////////
764 626 // A d m i n M e n u L i n k s
765 627 ////////////////////////////////////////////////////////////////////////////
766 628
767 629 /** Get URL to specific Admin Menu page
768 - *
630 + *
769 631 * @param string $menu_type - { item | add | resources | settings }
770 632 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
771 633 * @return string - URL to menu
772 634 */
@@ -794,19 +656,19 @@
794 656 }
795 657
796 658 if ( $is_absolute_url ) {
797 659 $link = admin_url( 'admin.php' ) . '?page=' . $link ;
798 - }
660 + }
799 661
800 - return $link;
662 + return $link;
801 663 }
802 664
803 665 // // // // // // // // // // // // // // // // // // // // // // // // // /
804 666
805 667 /** Get URL of item Listing or Calendar Overview page
806 - *
668 + *
807 669 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
808 - * @param boolean $is_old - { default: true }
670 + * @param boolean $is_old - { default: true }
809 671 * @return string - URL to menu
810 672 */
811 673 function wpbm_get_master_url( $is_absolute_url = true ) {
812 674 return wpbm_get_menu_url( 'master', $is_absolute_url );
@@ -811,12 +673,12 @@
811 673 function wpbm_get_master_url( $is_absolute_url = true ) {
812 674 return wpbm_get_menu_url( 'master', $is_absolute_url );
813 675 }
814 676
815 -/** Get URL of item > Add item page
816 - *
677 +/** Get URL of item > Add item page
678 + *
817 679 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
818 - * @param boolean $is_old - { default: true }
680 + * @param boolean $is_old - { default: true }
819 681 * @return string - URL to menu
820 682 */
821 683 function wpbm_get_new_wpbm_url( $is_absolute_url = true ) {
822 684 return wpbm_get_menu_url( 'add', $is_absolute_url );
@@ -821,18 +683,18 @@
821 683 function wpbm_get_new_wpbm_url( $is_absolute_url = true ) {
822 684 return wpbm_get_menu_url( 'add', $is_absolute_url );
823 685 }
824 686
825 -/** Get URL of item > Settings page
826 - *
687 +/** Get URL of item > Settings page
688 + *
827 689 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
828 - * @param boolean $is_old - { default: true }
690 + * @param boolean $is_old - { default: true }
829 691 * @return string - URL to menu
830 692 */
831 693 function wpbm_get_settings_url( $is_absolute_url = true ) {
832 694 return wpbm_get_menu_url( 'settings', $is_absolute_url );
833 695 }
834 -
696 +
835 697 // // // // // // // // // // // // // // // // // // // // // // // // // /
836 698
837 699 /** Check if this item Listing or Calendar Overview page
838 700 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
@@ -837,62 +699,62 @@
837 699 /** Check if this item Listing or Calendar Overview page
838 700 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
839 701 * @return boolean true | false
840 702 */
841 -function wpbm_is_master_page( $server_param = 'REQUEST_URI' ) {
703 +function wpbm_is_master_page( $server_param = 'REQUEST_URI' ) {
842 704
843 - if ( ( is_admin() ) &&
844 - ( strpos($_SERVER[ $server_param ],'page=oplugins') !== false ) &&
845 - ( strpos($_SERVER[ $server_param ],'tab=wpbm-') === false ) && // not the settings
846 - ( ( strpos($_SERVER[ $server_param ],'tab=wpbm') !== false ) // tab specified
847 - || ( strpos($_SERVER[ $server_param ],'tab=') === false ) ) // or tab not specified at all
705 + if ( ( is_admin() ) && isset($_SERVER[ $server_param ]) &&
706 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'page=oplugins') !== false ) && // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
707 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm-') === false ) && // not the settings // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
708 + ( ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm') !== false ) // tab specified // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
709 + || ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=') === false ) ) // or tab not specified at all // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
848 710 ) {
849 711 return true;
850 - }
712 + }
851 713 return false;
852 714 }
853 715
854 -/** Check if this item > Add item page
716 +/** Check if this item > Add item page
855 717 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
856 718 * @return boolean true | false
857 719 */
858 720 function wpbm_is_new_wpbm_page( $server_param = 'REQUEST_URI' ) {
859 721
860 - if ( ( is_admin() ) &&
861 - ( strpos($_SERVER[ $server_param ],'page=oplugins') !== false ) &&
862 - ( strpos($_SERVER[ $server_param ],'tab=wpbm-new') !== false )
722 + if ( ( is_admin() ) && isset($_SERVER[ $server_param ]) &&
723 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'page=oplugins') !== false ) && // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
724 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm-new') !== false ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
863 725 ) {
864 726 return true;
865 - }
727 + }
866 728 return false;
867 729 }
868 730
869 731
870 -/** Check if this item > Settings page
732 +/** Check if this item > Settings page
871 733 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
872 734 * @return boolean true | false
873 - */
735 + */
874 736 function wpbm_is_settings_page( $server_param = 'REQUEST_URI' ) {
875 737
876 - if ( ( is_admin() ) &&
877 - ( strpos($_SERVER[ $server_param ],'page=oplugins') !== false ) &&
878 - ( strpos($_SERVER[ $server_param ],'tab=wpbm-settings') !== false )
738 + if ( ( is_admin() ) && isset($_SERVER[ $server_param ]) &&
739 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'page=oplugins') !== false ) && // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
740 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm-settings') !== false ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
879 741 ) {
880 742 return true;
881 - }
743 + }
882 744 return false;
883 745 }
884 746
885 747 // </editor-fold>
886 -
887 748
888 -// <editor-fold defaultstate="collapsed" desc=" A d m i n U I E l e m e n t s " >
749 +
750 +// <editor-fold defaultstate="collapsed" desc=" A d m i n U I E l e m e n t s " >
889 751 ////////////////////////////////////////////////////////////////////////////
890 752 // A d m i n U I E l e m e n t s
891 753 ////////////////////////////////////////////////////////////////////////////
892 754
893 755 /** Get Number of new items
894 - *
756 + *
895 757 * @return int
896 758 */
897 759 function wpbm_get_number_new_items(){
898 760 return 0;
@@ -899,9 +761,9 @@
899 761 }
900 762
901 763
902 764 /** Show Admin B A R .
903 - *
765 + *
904 766 * @global type $wp_admin_bar
905 767 * @return type
906 768 */
907 769 function wp_admin_bar_items_menu(){
@@ -928,9 +790,9 @@
928 790 $update_title = $title;
929 791
930 792
931 793 if ( $update_count > 0 ) {
932 - $update_count_title = "&nbsp;<span id='ab-updates' class='wpbm-count bk-update-count' >" . number_format_i18n($update_count) . "</span>" ; //id='wpbm-count'
794 + $update_count_title = "&nbsp;<span class='wpbm-count bk-update-count' style='background: #f0f0f1;color: #2c3338;display: inline;padding: 2px 5px;font-weight: 600;border-radius: 10px;'>" . number_format_i18n($update_count) . "</span>" ; //id='wpbm-count'
933 795 $update_title .= $update_count_title;
934 796 }
935 797
936 798 $link_items = wpbm_get_master_url();
@@ -989,33 +851,16 @@
989 851 // add_action( 'admin_bar_menu', 'wp_admin_bar_items_menu', 70 ); // Add Admin Bar
990 852
991 853
992 854 /** Show Rating link at footer */
993 -function wpbm_show_wpbm_footer(){
855 +function wpbm_show_wpbm_footer(){
994 856
995 - if ( ! wpbm_is_this_demo() ) {
857 + // Nothing here.
858 +}
859 +// </editor-fold>
996 860
997 - $message = sprintf( __( 'If you like %s please leave us a %s rating. A huge thank you in advance!', 'booking-manager')
998 - , '<strong>Booking Manager</strong>' . ' ' . WPBM_VERSION_NUM
999 - , '<a href="https://wordpress.org/support/plugin/booking-manager/reviews/#new-post" target="_blank" title="' . esc_attr__( 'Thanks :)', 'booking-manager') . '">'
1000 - . '&#9733;&#9733;&#9733;&#9733;&#9733;'
1001 - . '</a>'
1002 - );
1003 861
1004 - echo '<div id="wpbm-footer" style="position:absolute;bottom:40px;text-align:left;width:95%;font-size:0.9em;text-shadow:0 1px 0 #fff;margin:0;color:#888;">' . $message . '</div>';
1005 - ?>
1006 - <script type="text/javascript">
1007 - jQuery(document).ready(function(){
1008 - jQuery('#wpfooter').append( jQuery('#wpbm-footer') );
1009 - });
1010 - </script>
1011 - <?php
1012 - }
1013 -}
1014 -// </editor-fold>
1015 -
1016 -
1017 -// <editor-fold defaultstate="collapsed" desc=" DB - cheking if table, field or index exists " >
862 +// <editor-fold defaultstate="collapsed" desc=" DB - cheking if table, field or index exists " >
1018 863 ////////////////////////////////////////////////////////////////////////////
1019 864 // DB - cheking if table, field or index exists
1020 865 ////////////////////////////////////////////////////////////////////////////
1021 866
@@ -1020,9 +865,9 @@
1020 865 ////////////////////////////////////////////////////////////////////////////
1021 866
1022 867 /**
1023 868 * Check if table exist
1024 - *
869 + *
1025 870 * @global type $wpdb
1026 871 * @param string $tablename
1027 872 * @return 0|1
1028 873 */
@@ -1029,31 +874,23 @@
1029 874 function wpbm_is_table_exists( $tablename ) {
1030 875
1031 876 global $wpdb;
1032 877
1033 - if ( (! empty($wpdb->prefix) ) && ( strpos($tablename, $wpdb->prefix) === false ) )
1034 - $tablename = $wpdb->prefix . $tablename ;
878 + if ( ( ! empty( $wpdb->prefix ) ) && ( strpos( $tablename, $wpdb->prefix ) === false ) ) {
879 + $tablename = $wpdb->prefix . $tablename;
880 + }
1035 881
1036 - $sql_check_table = $wpdb->prepare("SHOW TABLES LIKE %s" , $tablename ); //FixIn 5.4.3
1037 882
1038 - $res = $wpdb->get_results( $sql_check_table );
1039 883
1040 - return count($res); //FixIn 5.4.3
1041 - /*
1042 - $sql_check_table = $wpdb->prepare("
1043 - SELECT COUNT(*) AS count
1044 - FROM information_schema.tables
1045 - WHERE table_schema = '". DB_NAME ."'
1046 - AND table_name = %s " , $tablename );
884 + $res = $wpdb->get_results( $wpdb->prepare( "SHOW TABLES LIKE %s", $tablename ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1047 885
1048 - $res = $wpdb->get_results( $sql_check_table );
1049 - return $res[0]->count;*/
886 + return count( $res ); //FixIn 5.4.3.
1050 887 }
1051 888
1052 889
1053 890 /**
1054 891 * Check if table exist
1055 - *
892 + *
1056 893 * @global type $wpdb
1057 894 * @param string $tablename
1058 895 * @param type $fieldname
1059 896 * @return 0|1
@@ -1062,9 +899,9 @@
1062 899 global $wpdb;
1063 900 if ( (! empty($wpdb->prefix) ) && ( strpos($tablename, $wpdb->prefix) === false ) ) $tablename = $wpdb->prefix . $tablename ;
1064 901 $sql_check_table = "SHOW COLUMNS FROM {$tablename}" ;
1065 902
1066 - $res = $wpdb->get_results( $sql_check_table );
903 + $res = $wpdb->get_results( $sql_check_table ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1067 904
1068 905 foreach ($res as $fld) {
1069 906 if ($fld->Field == $fieldname) return 1;
1070 907 }
@@ -1074,9 +911,9 @@
1074 911
1075 912
1076 913 /**
1077 914 * Check if index exist
1078 - *
915 + *
1079 916 * @global type $wpdb
1080 917 * @param string $tablename
1081 918 * @param type $fieldindex
1082 919 * @return 0|1
@@ -1083,24 +920,24 @@
1083 920 */
1084 921 function wpbm_is_index_in_table_exists( $tablename , $fieldindex) {
1085 922 global $wpdb;
1086 923 if ( (! empty($wpdb->prefix) ) && ( strpos($tablename, $wpdb->prefix) === false ) ) $tablename = $wpdb->prefix . $tablename ;
1087 - $sql_check_table = $wpdb->prepare("SHOW INDEX FROM {$tablename} WHERE Key_name = %s", $fieldindex );
1088 - $res = $wpdb->get_results( $sql_check_table );
924 +
925 + $res = $wpdb->get_results( $wpdb->prepare("SHOW INDEX FROM {$tablename} WHERE Key_name = %s", $fieldindex ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared
1089 926 if (count($res)>0) return 1;
1090 927 else return 0;
1091 928 }
1092 929
1093 930 // </editor-fold>
1094 -
1095 -
1096 -// <editor-fold defaultstate="collapsed" desc=" E s c a p i n g " >
931 +
932 +
933 +// <editor-fold defaultstate="collapsed" desc=" E s c a p i n g " >
1097 934 ////////////////////////////////////////////////////////////////////////////
1098 935 // E s c a p i n g
1099 936 ////////////////////////////////////////////////////////////////////////////
1100 937
1101 938 /** Transform the REQESTS parameters (GET and POST) into URL
1102 - *
939 + *
1103 940 * @param type $page_param
1104 941 * @param array $exclude_params
1105 942 * @param type $only_these_parameters
1106 943 * @return type
@@ -1108,25 +945,25 @@
1108 945 function wpbm_get_params_in_url( $page_param , $exclude_params = array(), $only_these_parameters = false, $is_escape_url = false, $only_get = false ){
1109 946
1110 947 $exclude_params[] = 'page';
1111 948
1112 - if ( isset( $_GET['page'] ) )
1113 - $page_param = $_GET['page'];
949 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
950 + if ( isset( $_GET['page'] ) ) { $page_param = $_GET['page']; }
1114 951
1115 952 $get_paramaters = array( 'page' => $page_param );
1116 953
1117 954 if ( $only_get )
1118 - $check_params = $_GET;
1119 - else
1120 - $check_params = $_REQUEST;
1121 -//debuge($check_params);
955 + $check_params = $_GET; // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
956 + else
957 + $check_params = $_REQUEST; // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
958 +//debuge($check_params);
1122 959 foreach ( $check_params as $prm_key => $prm_value ) {
1123 960
1124 961 // Skip parameters arrays, like $_GET['rvaluation_to'] = Array ( [0] => 6, [1] => 14, [2] => 14 )
1125 - if (
1126 - ( is_string( $prm_value ) )
1127 - || ( is_numeric( $prm_value ) )
1128 - ) {
962 + if (
963 + ( is_string( $prm_value ) )
964 + || ( is_numeric( $prm_value ) )
965 + ) {
1129 966
1130 967 if ( strlen( $prm_value ) > 1000 ) { // Check about TOOO long parameters, if it exist then reset it.
1131 968 $prm_value = '';
1132 969 }
@@ -1135,9 +972,9 @@
1135 972 if ( ( $only_these_parameters === false ) || ( in_array( $prm_key, $only_these_parameters ) ) )
1136 973 $get_paramaters[ $prm_key ] = $prm_value;
1137 974 }
1138 975 }
1139 -//debuge($check_params, $get_paramaters, $exclude_params );
976 +//debuge($check_params, $get_paramaters, $exclude_params );
1140 977 $url = admin_url( add_query_arg( $get_paramaters , 'admin.php' ) );
1141 978
1142 979 if ( $is_escape_url )
1143 980 $url = esc_url( $url );
@@ -1146,9 +983,9 @@
1146 983
1147 984 /* // Old variant:
1148 985 if ( isset( $_GET['page'] ) ) $page_param = $_GET['page'];
1149 986
1150 - $url_start = 'admin.php?page=' . $page_param . '&';
987 + $url_start = 'admin.php?page=' . $page_param . '&';
1151 988 $exclude_params[] = 'page';
1152 989 foreach ( $_REQUEST as $prm_key => $prm_value ) {
1153 990
1154 991 if ( !in_array( $prm_key, $exclude_params ) )
@@ -1159,18 +996,18 @@
1159 996 }
1160 997 $url_start = substr( $url_start, 0, -1 );
1161 998
1162 999 return $url_start;
1163 - */
1000 + */
1164 1001 }
1165 1002
1166 1003
1167 1004 /** Clean Request Parameters
1168 - *
1005 + *
1169 1006 */
1170 -function wpbm_check_request_paramters() {
1007 +function wpbm_check_request_paramters() {
1171 1008
1172 - $clean_params = array();
1009 + $clean_params = array();
1173 1010
1174 1011 $clean_params[ 'wh_wpbm_id' ] = 'digit_or_csd'; // '0' | '1' | ''
1175 1012 $clean_params[ 'wh_wpbm_date' ] = 'digit_or_date'; // number | date 2016-07-20
1176 1013 $clean_params[ 'wh_wpbm_datenext' ] = 'd'; // '1' | '2' ....
@@ -1181,13 +1018,13 @@
1181 1018
1182 1019 // elements only listed in array::
1183 1020 if ( is_array( $clean_type ) ) { // check only values from the list in this array
1184 1021
1185 - if ( ( isset( $_REQUEST[ $request_key ] ) ) && ( ! in_array( $_REQUEST[ $request_key ], $clean_type ) ) )
1186 - $clean_type = 's';
1187 - else
1022 + if ( ( isset( $_REQUEST[ $request_key ] ) ) && ( ! in_array( $_REQUEST[ $request_key ], $clean_type ) ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1023 + $clean_type = 's';
1024 + else
1188 1025 $clean_type = 'checked_skip_it';
1189 - }
1026 + }
1190 1027
1191 1028 switch ( $clean_type ) {
1192 1029
1193 1030 case 'checked_skip_it':
@@ -1194,36 +1031,34 @@
1194 1031
1195 1032 break;
1196 1033
1197 1034 case 'digit_or_date': // digit or comma separated digit
1198 - if ( isset( $_REQUEST[ $request_key ] ) )
1199 - $_REQUEST[ $request_key ] = wpbm_clean_digit_or_date( $_REQUEST[ $request_key ] ); // nums
1035 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1036 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = wpbm_clean_digit_or_date( $_REQUEST[ $request_key ] ); } // nums
1200 1037
1201 1038 break;
1202 1039
1203 1040 case 'digit_or_csd': // digit or comma separated digit
1204 - if ( isset( $_REQUEST[ $request_key ] ) )
1205 - $_REQUEST[ $request_key ] = wpbm_clean_digit_or_csd( $_REQUEST[ $request_key ] ); // nums
1041 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1042 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = wpbm_clean_digit_or_csd( $_REQUEST[ $request_key ] ); } // nums
1206 1043
1207 1044 break;
1208 1045
1209 1046 case 's': // string
1210 - if ( isset( $_REQUEST[ $request_key ] ) )
1211 - $_REQUEST[ $request_key ] = wpbm_clean_like_string_for_db( $_REQUEST[ $request_key ] );
1047 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1048 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = wpbm_clean_like_string_for_db( $_REQUEST[ $request_key ] ); }
1212 1049
1213 1050 break;
1214 1051
1215 1052 case 'd': // digit
1216 - if ( isset( $_REQUEST[ $request_key ] ) )
1217 - if ( $_REQUEST[ $request_key ] !== '' )
1218 - $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] );
1053 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1054 + if (( isset( $_REQUEST[ $request_key ] ) ) && ( $_REQUEST[ $request_key ] !== '' )) { $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] ); }
1219 1055
1220 1056 break;
1221 1057
1222 1058 default:
1223 - if ( isset( $_REQUEST[ $request_key ] ) ) {
1224 - $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] );
1225 - }
1059 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1060 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] ); }
1226 1061 break;
1227 1062 }
1228 1063
1229 1064
@@ -1230,15 +1065,15 @@
1230 1065 }
1231 1066
1232 1067 }
1233 1068
1234 -
1069 +
1235 1070 /** Check paramter if it number or comma separated list of numbers
1236 - *
1071 + *
1237 1072 * @global type $wpdb
1238 1073 * @param string $value
1239 1074 * @return string
1240 - *
1075 + *
1241 1076 * Exmaple:
1242 1077 wpbm_clean_digit_or_csd( '12,a,45,9' ) => '12,0,45,9'
1243 1078 * or
1244 1079 wpbm_clean_digit_or_csd( '10a' ) => '10
@@ -1244,9 +1079,9 @@
1244 1079 wpbm_clean_digit_or_csd( '10a' ) => '10
1245 1080 * or
1246 1081 wpbm_clean_digit_or_csd( array( '12,a,45,9', '10a' ) ) => array ( '12,0,45,9', '10' )
1247 1082 */
1248 -function wpbm_clean_digit_or_csd( $value ) { //FixIn:6.2.1.4
1083 +function wpbm_clean_digit_or_csd( $value ) { //FixIn:6.2.1.4
1249 1084
1250 1085 if ( $value === '' ) return $value;
1251 1086
1252 1087
@@ -1251,9 +1086,9 @@
1251 1086
1252 1087
1253 1088 if ( is_array( $value ) ) {
1254 1089 foreach ( $value as $key => $check_value ) {
1255 - $value[ $key ] = wpbm_clean_digit_or_csd( $check_value );
1090 + $value[ $key ] = wpbm_clean_digit_or_csd( $check_value );
1256 1091 }
1257 1092 return $value;
1258 1093 }
1259 1094
@@ -1270,12 +1105,12 @@
1270 1105 }
1271 1106 $result = implode(',', $result );
1272 1107 return $result;
1273 1108 }
1274 -
1275 -
1109 +
1110 +
1276 1111 /** Cehck about Valid date, like 2016-07-20 or digit
1277 - *
1112 + *
1278 1113 * @param string $value
1279 1114 * @return string or int
1280 1115 */
1281 1116 function wpbm_clean_digit_or_date( $value ) { //FixIn:6.2.1.4
@@ -1289,12 +1124,12 @@
1289 1124 return intval( $value );
1290 1125 }
1291 1126
1292 1127 }
1293 -
1294 1128
1129 +
1295 1130 /** Check $value for injection here
1296 - *
1131 + *
1297 1132 * @param type $value
1298 1133 * @return type
1299 1134 */
1300 1135 function wpbm_clean_parameter( $value ) {
@@ -1299,16 +1134,16 @@
1299 1134 */
1300 1135 function wpbm_clean_parameter( $value ) {
1301 1136
1302 1137 $value = preg_replace( '/<[^>]*>/', '', $value ); // clean any tags
1303 - $value = str_replace( '<', ' ', $value );
1304 - $value = str_replace( '>', ' ', $value );
1305 - $value = strip_tags( $value );
1138 + $value = str_replace( '<', ' ', $value );
1139 + $value = str_replace( '>', ' ', $value );
1140 + $value = wp_strip_all_tags( $value );
1306 1141
1307 - // Clean SQL injection
1142 + // Clean SQL injection
1308 1143 $value = esc_sql( $value );
1309 1144
1310 - return $value;
1145 + return $value;
1311 1146 }
1312 1147
1313 1148
1314 1149 function wpbm_esc_like( $value_trimmed ) {
@@ -1321,14 +1156,14 @@
1321 1156 }
1322 1157
1323 1158
1324 1159 /** Clean user string for using in SQL LIKE statement - append to LIKE sql
1325 - *
1160 + *
1326 1161 * @param string $value - to clean
1327 1162 * @return string - escaped
1328 - * Exmaple:
1163 + * Exmaple:
1329 1164 * $search_escaped_like_title = wpbm_clean_like_string_for_append_in_sql_for_db( $input_var );
1330 - *
1165 + *
1331 1166 * $where_sql = " WHERE title LIKE ". $search_escaped_like_title ." ";
1332 1167 */
1333 1168 function wpbm_clean_like_string_for_append_in_sql_for_db( $value ) {
1334 1169 global $wpdb;
@@ -1333,13 +1168,13 @@
1333 1168 function wpbm_clean_like_string_for_append_in_sql_for_db( $value ) {
1334 1169 global $wpdb;
1335 1170
1336 1171 $value_trimmed = trim( stripslashes( $value ) );
1337 -$wild = '%';
1338 -$like = $wild . wpbm_esc_like( $value_trimmed ) . $wild;
1339 -$sql = $wpdb->prepare( "'%s'", $like );
1172 + $wild = '%';
1173 + $like = $wild . wpbm_esc_like( $value_trimmed ) . $wild;
1174 + $sql = $wpdb->prepare( "'%s'", $like ); // phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.QuotedSimplePlaceholder
1340 1175
1341 - return $sql;
1176 + return $sql;
1342 1177
1343 1178
1344 1179 /* Help:
1345 1180 * First half of escaping for LIKE special characters % and _ before preparing for MySQL.
@@ -1354,22 +1189,22 @@
1354 1189 *
1355 1190 * Example Escape Chain:
1356 1191 *
1357 1192 * $sql = esc_sql( wpbm_esc_like( $input ) );
1358 - */
1193 + */
1359 1194
1360 1195 }
1361 1196
1362 1197
1363 -/** Clean string for using in SQL LIKE requests inside single quotes: WHERE title LIKE '%". $escaped_search_title ."%'
1198 +/** Clean string for using in SQL LIKE requests inside single quotes: WHERE title LIKE '%". $escaped_search_title ."%'
1364 1199 * Replaced _ to \_ % to \% \ to \\
1365 1200 * @param string $value - to clean
1366 1201 * @return string - escaped
1367 - * Exmaple:
1202 + * Exmaple:
1368 1203 * $search_escaped_like_title = wpbm_clean_like_string_for_db( $input_var );
1369 - *
1204 + *
1370 1205 * $where_sql = " WHERE title LIKE '%". $search_escaped_like_title ."%' ";
1371 - *
1206 + *
1372 1207 * Important! Use SINGLE quotes after in SQL query: LIKE '%".$data."%'
1373 1208 */
1374 1209 function wpbm_clean_like_string_for_db( $value ){
1375 1210
@@ -1378,9 +1213,9 @@
1378 1213 $value_trimmed = trim( stripslashes( $value ) );
1379 1214
1380 1215 $value_trimmed = wpbm_esc_like( $value_trimmed );
1381 1216
1382 - $value = trim( $wpdb->prepare( "'%s'", $value_trimmed ) , "'" );
1217 + $value = trim( $wpdb->prepare( "'%s'", $value_trimmed ) , "'" ); // phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.QuotedSimplePlaceholder
1383 1218
1384 1219 return $value;
1385 1220
1386 1221 /* Help:
@@ -1396,26 +1231,26 @@
1396 1231 *
1397 1232 * Example Escape Chain:
1398 1233 *
1399 1234 * $sql = esc_sql( wpbm_esc_like( $input ) );
1400 - */
1235 + */
1401 1236 }
1402 1237
1403 1238
1404 1239 /** Escape string from SQL for the HTML form field
1405 - *
1240 + *
1406 1241 * @param string $value
1407 1242 * @return string
1408 - *
1243 + *
1409 1244 * Used: esc_sql function.
1410 - *
1411 - * https://codex.wordpress.org/Function_Reference/esc_sql
1412 - * Note: Be careful to use this function correctly. It will only escape values to be used in strings in the query.
1413 - * That is, it only provides escaping for values that will be within quotes in the SQL (as in field = '{$escaped_value}').
1414 - * If your value is not going to be within quotes, your code will still be vulnerable to SQL injection.
1415 - * For example, this is vulnerable, because the escaped value is not surrounded by quotes in the SQL query:
1416 - * ORDER BY {$escaped_value}. As such, this function does not escape unquoted numeric values, field names, or SQL keywords.
1417 - *
1245 + *
1246 + * https://codex.wordpress.org/Function_Reference/esc_sql
1247 + * Note: Be careful to use this function correctly. It will only escape values to be used in strings in the query.
1248 + * That is, it only provides escaping for values that will be within quotes in the SQL (as in field = '{$escaped_value}').
1249 + * If your value is not going to be within quotes, your code will still be vulnerable to SQL injection.
1250 + * For example, this is vulnerable, because the escaped value is not surrounded by quotes in the SQL query:
1251 + * ORDER BY {$escaped_value}. As such, this function does not escape unquoted numeric values, field names, or SQL keywords.
1252 + *
1418 1253 */
1419 1254 function wpbm_clean_string_for_form( $value ){
1420 1255
1421 1256 global $wpdb;
@@ -1432,16 +1267,16 @@
1432 1267
1433 1268 }
1434 1269 // </editor-fold>
1435 1270
1436 -
1437 -// <editor-fold defaultstate="collapsed" desc=" U s e r s " >
1271 +
1272 +// <editor-fold defaultstate="collapsed" desc=" U s e r s " >
1438 1273 ////////////////////////////////////////////////////////////////////////////////
1439 1274 // U s e r s
1440 1275 ////////////////////////////////////////////////////////////////////////////////
1441 1276
1442 1277 /** Get ID of active user
1443 - *
1278 + *
1444 1279 * @return type
1445 1280 */
1446 1281 function get_wpbm_current_user_id() {
1447 1282 $user = wp_get_current_user();
@@ -1448,11 +1283,35 @@
1448 1283 return ( isset( $user->ID ) ? (int) $user->ID : 0 );
1449 1284 }
1450 1285
1451 1286
1287 +/**
1288 + * Resolve a requested per-user settings target to the current user.
1289 + *
1290 + * Booking Manager's established AJAX payloads include a user ID. The value is
1291 + * retained for request compatibility, but it must never authorize a write to
1292 + * another user's preferences.
1293 + *
1294 + * @param mixed $requested_user_id User ID supplied by the request.
1295 + *
1296 + * @return int Current user ID when the request target matches; otherwise 0.
1297 + */
1298 +function wpbm_get_authorized_user_option_target_id( $requested_user_id ) {
1299 + $current_user_id = get_wpbm_current_user_id();
1300 +
1301 + if ( 0 === $current_user_id || ! is_scalar( $requested_user_id ) ) {
1302 + return 0;
1303 + }
1304 +
1305 + $requested_user_id = absint( wp_unslash( (string) $requested_user_id ) );
1306 +
1307 + return ( $current_user_id === $requested_user_id ) ? $current_user_id : 0;
1308 +}
1309 +
1310 +
1452 1311 /** Check if Current User have specific Role
1453 - *
1454 - * @return bool Whether the current user has the given capability.
1312 + *
1313 + * @return bool Whether the current user has the given capability.
1455 1314 */
1456 1315 function wpbm_is_current_user_have_this_role( $user_role ) {
1457 1316
1458 1317 if ( $user_role == 'administrator' ) $user_role = 'activate_plugins';
@@ -1465,64 +1324,44 @@
1465 1324 }
1466 1325
1467 1326
1468 1327 function wpbm_get_user_ip() {
1469 -//return '84.243.195.114' ; // Test //90.36.89.174
1470 - if (isset($_SERVER['HTTP_CLIENT_IP'])) {
1471 - $userIP = $_SERVER['HTTP_CLIENT_IP'] ;
1472 - } elseif (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
1473 - $userIP = $_SERVER['HTTP_X_FORWARDED_FOR'] ;
1474 - } elseif (isset($_SERVER['HTTP_X_FORWARDED'])) {
1475 - $userIP = $_SERVER['HTTP_X_FORWARDED'] ;
1476 - } elseif (isset($_SERVER['HTTP_FORWARDED_FOR'])) {
1477 - $userIP = $_SERVER['HTTP_FORWARDED_FOR'] ;
1478 - } elseif (isset($_SERVER['HTTP_FORWARDED'])) {
1479 - $userIP = $_SERVER['HTTP_FORWARDED'] ;
1480 - } elseif (isset($_SERVER['REMOTE_ADDR'])) {
1481 - $userIP = $_SERVER['REMOTE_ADDR'] ;
1482 - } else {
1483 - $userIP = "" ;
1484 - }
1485 -
1486 - $userIP = explode( ',', $userIP );
1487 - $userIP = array_map( 'trim', $userIP );
1488 -
1489 - return $userIP[0] ;
1328 + return '---';
1490 1329 }
1491 1330 add_wpbm_filter( 'wpbm_get_user_ip', 'wpbm_get_user_ip' );
1492 1331 // </editor-fold>
1493 1332
1494 1333
1495 -// <editor-fold defaultstate="collapsed" desc=" Mesages for Admin panel " >
1496 -////////////////////////////////////////////////////////////////////////////////
1497 -// Mesages for Admin panel
1498 -////////////////////////////////////////////////////////////////////////////////
1334 +// <editor-fold defaultstate="collapsed" desc=" Mesages for Admin panel " >
1335 +////////////////////////////////////////////////////////////////////////////////
1336 +// Mesages for Admin panel
1337 +////////////////////////////////////////////////////////////////////////////////
1499 1338
1500 1339 function wpbm_show_fixed_message( $message, $time_to_show , $message_type = 'updated' , $notice_id = 0, $is_dismissible = false ) {
1501 1340
1502 1341 // Generate unique HTML ID for the message
1503 1342 if ( $notice_id == 0 )
1504 - $notice_id = intval( time() * rand(10, 100) );
1343 + $notice_id = intval( time() * wp_rand(10, 100) );
1505 1344
1506 1345 $notice_id = 'wpbm_system_notice_' . $notice_id;
1507 1346
1508 1347 $is_dismissible = false;
1509 1348
1510 - if (
1349 + if (
1511 1350 ( ( $is_dismissible ) && ( ! wpbm_section_is_dismissed( $notice_id ) ) )
1512 1351 || ( ! $is_dismissible )
1513 - // || true
1352 + // || true
1514 1353 ){
1515 1354
1516 - ?><div id="<?php echo $notice_id; ?>"
1517 - class="wpbm_system_notice wpbm_is_dismissible wpbm_is_hideable <?php echo $message_type; ?>"
1518 - data-nonce="<?php echo wp_create_nonce( $nonce_name = $notice_id . '_wpbmnonce' ); ?>"
1519 - data-user-id="<?php echo get_current_user_id(); ?>"
1520 - ><?php
1355 + ?><div id="<?php echo esc_attr($notice_id); ?>"
1356 + class="wpbm_system_notice wpbm_is_dismissible wpbm_is_hideable <?php echo esc_attr( $message_type ); ?>"
1357 + data-nonce="<?php echo esc_attr(wp_create_nonce( $nonce_name = $notice_id . '_wpbmnonce' )); ?>"
1358 + data-user-id="<?php echo esc_attr(get_current_user_id()); ?>"
1359 + ><?php
1521 1360
1522 1361 wpbm_x_dismiss_button();
1523 1362
1524 - echo $message;
1363 + echo wp_kses_post($message);
1525 1364
1526 1365 ?></div><?php
1527 1366
1528 1367 // Get the time of message showing
@@ -1527,19 +1366,19 @@
1527 1366
1528 1367 // Get the time of message showing
1529 1368 $time_to_show = intval( $time_to_show ) * 1000;
1530 1369
1531 - if ( $time_to_show > 0 ) {
1532 - ?> <script type="text/javascript">
1533 - jQuery('#<?php echo $notice_id; ?>').animate({opacity: 1},<?php echo $time_to_show; ?>).fadeOut( 2000 );
1370 + if ( $time_to_show > 0 ) {
1371 + ?> <script type="text/javascript">
1372 + jQuery('#<?php echo esc_attr($notice_id); ?>').animate({opacity: 1},<?php echo esc_attr( $time_to_show ); ?>).fadeOut( 2000 );
1534 1373 </script> <?php
1535 - }
1536 - }
1374 + }
1375 + }
1537 1376 }
1538 1377
1539 1378
1540 1379 /** Show Ajax message at the top of page
1541 - *
1380 + *
1542 1381 * @param type $message
1543 1382 * @param type $time_to_show
1544 1383 * @param type $is_error
1545 1384 */
@@ -1551,24 +1390,24 @@
1551 1390 // Escape any JavaScript from message
1552 1391 $notice = html_entity_decode( esc_js( $message ) ,ENT_QUOTES) ;
1553 1392
1554 1393 ?><script type="text/javascript">
1555 - var my_message = '<?php echo $notice; ?>';
1556 - wpbm_admin_show_message( my_message, '<?php echo ( $is_error ? 'error' : 'success' ); ?>', <?php echo $time_to_show; ?> );
1394 + var my_message = '<?php echo esc_js( $notice ); ?>';
1395 + wpbm_admin_show_message( my_message, '<?php echo ( $is_error ? 'error' : 'success' ); ?>', <?php echo esc_attr($time_to_show); ?> );
1557 1396 </script><?php
1558 1397 }
1559 1398
1560 1399
1561 1400 /** Show "Saved Changes" message at the top of settings page.
1562 - *
1563 - */
1401 + *
1402 + */
1564 1403 function wpbm_show_changes_saved_message() {
1565 1404 wpbm_show_message ( __('Changes saved.', 'booking-manager'), 5 );
1566 -}
1405 +}
1567 1406
1568 1407
1569 1408 /** Show Message at Top of Admin Pages
1570 - *
1409 + *
1571 1410 * @param type $message - mesage to show
1572 1411 * @param type $time_to_show - number of seconds to show, if 0 or skiped, then unlimited time.
1573 1412 * @param type $message_type - Default: updated { updated | error | notice }
1574 1413 */
@@ -1574,9 +1413,9 @@
1574 1413 */
1575 1414 function wpbm_show_message ( $message, $time_to_show , $message_type = 'updated') {
1576 1415
1577 1416 // Generate unique HTML ID for the message
1578 - $inner_message_id = intval( time() * rand(10, 100) );
1417 + $inner_message_id = intval( time() * wp_rand(10, 100) );
1579 1418
1580 1419 // Get formated HTML message
1581 1420 $notice = wpbm_get_formated_message( $message, $message_type, $inner_message_id );
1582 1421
@@ -1583,13 +1422,16 @@
1583 1422 // Get the time of message showing
1584 1423 $time_to_show = intval( $time_to_show ) * 1000;
1585 1424
1586 1425 // Show this Message
1587 - ?> <script type="text/javascript">
1426 + ?> <script type="text/javascript">
1588 1427 if ( jQuery('.wpbm_admin_message').length ) {
1589 - jQuery('.wpbm_admin_message').append( '<?php echo $notice; ?>' );
1428 + jQuery('.wpbm_admin_message').append( '<?php
1429 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1430 + echo ($notice);
1431 + ?>' );
1590 1432 <?php if ( $time_to_show > 0 ) { ?>
1591 - jQuery('#wpbm_inner_message_<?php echo $inner_message_id; ?>').animate({opacity: 1},<?php echo $time_to_show; ?>).fadeOut( 2000 );
1433 + jQuery('#wpbm_inner_message_<?php echo esc_attr($inner_message_id); ?>').animate({opacity: 1},<?php echo esc_attr($time_to_show); ?>).fadeOut( 2000 );
1592 1434 <?php } ?>
1593 1435 }
1594 1436 </script> <?php
1595 1437 }
@@ -1595,9 +1437,9 @@
1595 1437 }
1596 1438
1597 1439
1598 1440 /** Escape and prepare message to show it
1599 - *
1441 + *
1600 1442 * @param type $message - message
1601 1443 * @param type $message_type - Default: updated { updated | error | notice }
1602 1444 * @param string $inner_message_id - ID of message DIV, can be skipped
1603 1445 * @return string
@@ -1622,13 +1464,13 @@
1622 1464 }
1623 1465
1624 1466
1625 1467 /** Show system info in settings page
1626 - *
1627 - * @param string $message ...
1468 + *
1469 + * @param string $message ...
1628 1470 * @param string $message_type 'info' | 'warning' | 'error'
1629 1471 * @param string $title __('Important!' , 'booking-manager') | __('Note' , 'booking-manager')
1630 - *
1472 + *
1631 1473 * Exmaple: wpbm_show_message_in_settings( __( 'Nothing Found', 'booking-manager'), 'warning', __('Important!' , 'booking-manager') );
1632 1474 */
1633 1475 function wpbm_show_message_in_settings( $message, $message_type = 'info', $title = '' , $is_echo = true ) {
1634 1476
@@ -1647,9 +1489,9 @@
1647 1489
1648 1490 $message_content .= '<div class="clear"></div>';
1649 1491
1650 1492 if ( $is_echo )
1651 - echo $message_content;
1493 + echo wp_kses_post( $message_content );
1652 1494 else
1653 1495 return $message_content;
1654 1496
1655 1497 }
@@ -1655,36 +1497,39 @@
1655 1497 }
1656 1498 // </editor-fold>
1657 1499
1658 1500
1659 -// <editor-fold defaultstate="collapsed" desc=" Settings Meta Boxes " >
1660 -////////////////////////////////////////////////////////////////////////////////
1501 +// <editor-fold defaultstate="collapsed" desc=" Settings Meta Boxes " >
1502 +////////////////////////////////////////////////////////////////////////////////
1661 1503 // Settings Meta Boxes
1662 -////////////////////////////////////////////////////////////////////////////////
1504 +////////////////////////////////////////////////////////////////////////////////
1663 1505 function wpbm_open_meta_box_section( $metabox_id, $title ) {
1664 1506
1665 1507 $my_close_open_win_id = $metabox_id . '_metabox';
1666 - ?>
1667 - <div class='meta-box'>
1668 - <div
1669 - id="<?php echo $my_close_open_win_id; ?>"
1670 - class="postbox <?php if ( '1' == get_user_option( 'wpbm_win_' . $my_close_open_win_id ) ) echo 'closed'; ?>"
1671 - > <div title="<?php _e('Click to toggle', 'booking-manager'); ?>"
1672 - class="handlediv"
1673 - onclick="javascript:wpbm_verify_window_opening(<?php echo get_wpbm_current_user_id(); ?>, '<?php echo $my_close_open_win_id; ?>');"
1674 - ><br/></div>
1675 - <h3 class='hndle'>
1676 - <span><?php echo wp_kses_post( $title ); ?></span>
1677 - </h3>
1678 - <div class="inside">
1679 - <?php
1508 + //FixIn: 2.0.16.1
1509 + ?>
1510 + <div class='meta-box'>
1511 + <div
1512 + id="<?php echo esc_attr($my_close_open_win_id); ?>"
1513 + class="postbox <?php if ( '1' == get_user_option( 'wpbm_win_' . $my_close_open_win_id ) ) echo 'closed'; ?>"
1514 + ><div class="postbox-header" style="display: flex;flex-flow: row nowrap;border-bottom: 1px solid #ccd0d4;"><?php //FixIn: 8.7.8.1 ?>
1515 + <h3 class='hndle' style="flex: 1 1 auto;border: none;">
1516 + <span><?php echo wp_kses_post( $title ); ?></span>
1517 + </h3>
1518 + <div title="<?php echo esc_attr(__('Click to toggle','booking-manager')); ?>"
1519 + class="handlediv"
1520 + onclick="javascript:wpbm_verify_window_opening(<?php echo esc_attr( get_wpbm_current_user_id() ); ?>, '<?php echo esc_attr($my_close_open_win_id); ?>');"
1521 + ><br/></div>
1522 + </div>
1523 + <div class="inside">
1524 + <?php
1680 1525 }
1681 1526
1682 1527 function wpbm_close_meta_box_section() {
1683 1528 ?>
1684 - </div>
1685 - </div>
1686 - </div>
1529 + </div>
1530 + </div>
1531 + </div>
1687 1532 <?php
1688 1533 }
1689 1534 // </editor-fold>
1690 1535
@@ -1689,23 +1534,23 @@
1689 1534 // </editor-fold>
1690 1535
1691 1536
1692 1537 // from Toolbar
1693 -// <editor-fold defaultstate="collapsed" desc=" M o d a l s " >
1694 -////////////////////////////////////////////////////////////////////////////////
1538 +// <editor-fold defaultstate="collapsed" desc=" M o d a l s " >
1539 +////////////////////////////////////////////////////////////////////////////////
1695 1540 // M o d a l s
1696 1541 ////////////////////////////////////////////////////////////////////////////////
1697 1542
1698 -/** Start Loyouts - Modal Window structure */
1543 +/** Start Loyouts - Modal Window structure */
1699 1544 function wpbm_write_content_for_modals_start_here() {
1700 -
1545 +
1701 1546 ?><span id="wpbm_content_for_modals"></span><?php
1702 1547 }
1703 -add_wpbm_action( 'wpbm_write_content_for_modals', 'wpbm_write_content_for_modals_start_here');
1548 +add_wpbm_action( 'wpbm_write_content_for_modals', 'wpbm_write_content_for_modals_start_here');
1704 1549 // </editor-fold>
1705 1550
1706 1551
1707 -// <editor-fold defaultstate="collapsed" desc=" Inline JavaScript " >
1552 +// <editor-fold defaultstate="collapsed" desc=" Inline JavaScript " >
1708 1553 ////////////////////////////////////////////////////////////////////////////////
1709 1554 // Inline J a v a S c r i p t to Footer page
1710 1555 ////////////////////////////////////////////////////////////////////////////////
1711 1556 /**
@@ -1741,9 +1586,9 @@
1741 1586
1742 1587 $wpbm_queued_js = preg_replace( '/&#(x)?0*(?(1)27|39);?/i', "'", $wpbm_queued_js );
1743 1588 $wpbm_queued_js = str_replace( "\r", '', $wpbm_queued_js );
1744 1589
1745 - echo $wpbm_queued_js . "});\n</script>\n<!-- End WPBM JavaScript -->\n";
1590 + echo $wpbm_queued_js . "});\n</script>\n<!-- End WPBM JavaScript -->\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1746 1591
1747 1592 $wpbm_queued_js = '';
1748 1593 unset( $wpbm_queued_js );
1749 1594 }
@@ -1751,9 +1596,9 @@
1751 1596
1752 1597 // </editor-fold>
1753 1598
1754 1599 // from Toolbar
1755 -// <editor-fold defaultstate="collapsed" desc=" JS & CSS - Tooltips & Popover" >
1600 +// <editor-fold defaultstate="collapsed" desc=" JS & CSS - Tooltips & Popover" >
1756 1601 ////////////////////////////////////////////////////////////////////////////////
1757 1602 // JS & CSS
1758 1603 ////////////////////////////////////////////////////////////////////////////////
1759 1604
@@ -1758,15 +1603,15 @@
1758 1603 ////////////////////////////////////////////////////////////////////////////////
1759 1604
1760 1605 /** Load suport JavaScript for "Items" page*/
1761 1606 function wpbm_js_for_items_page() {
1762 -
1607 +
1763 1608 $is_use_hints = get_wpbm_option( 'wpbm_is_use_hints_at_admin_panel' );
1764 1609 if ( $is_use_hints == 'On' )
1765 1610 wpbm_bs_javascript_tooltips(); // JS Tooltips
1766 1611
1767 - wpbm_bs_javascript_popover(); // JS Popover
1768 -
1612 + wpbm_bs_javascript_popover(); // JS Popover
1613 +
1769 1614 //wpbm_datepicker_js(); // JS Datepicker
1770 1615 wpbm_datepicker_css(); // CSS DatePicker
1771 1616 }
1772 1617
@@ -1772,14 +1617,14 @@
1772 1617
1773 1618
1774 1619 /** Datepicker activation JavaScript */
1775 1620 function wpbm_datepicker_js() {
1776 -
1621 +
1777 1622 ?><script type="text/javascript">
1778 1623 jQuery(document).ready( function(){
1779 1624
1780 1625 function applyCSStoDays( date ){
1781 - return [true, 'date_available'];
1626 + return [true, 'date_available'];
1782 1627 }
1783 1628 jQuery('input.wpbm-filters-section-calendar').datepick(
1784 1629 { beforeShowDay: applyCSStoDays,
1785 1630 showOn: 'focus',
@@ -1790,9 +1635,9 @@
1790 1635 nextText: '&raquo;',
1791 1636 dateFormat: 'yy-mm-dd',
1792 1637 changeMonth: false,
1793 1638 changeYear: false,
1794 - minDate: null,
1639 + minDate: null,
1795 1640 maxDate: null, //'1Y',
1796 1641 showStatus: false,
1797 1642 multiSeparator: ', ',
1798 1643 closeAtTop: false,
@@ -1803,9 +1648,9 @@
1803 1648 mandatory: true
1804 1649 }
1805 1650 );
1806 1651 });
1807 - </script><?php
1652 + </script><?php
1808 1653 }
1809 1654
1810 1655
1811 1656 /** Support CSS - datepick, etc... */
@@ -1841,16 +1686,16 @@
1841 1686 height: auto;
1842 1687 }
1843 1688 </style>
1844 1689 <?php
1845 -}
1690 +}
1846 1691
1847 1692
1848 1693 /** Sortable Table JavaScript */
1849 1694 function wpbm_sortable_js() {
1850 1695 ?>
1851 - <script type="text/javascript">
1852 - // Activate Sortable Functionality
1696 + <script type="text/javascript">
1697 + // Activate Sortable Functionality
1853 1698 jQuery( document ).ready(function(){
1854 1699
1855 1700 jQuery('.wpbm_input_table tbody th').css('cursor','move');
1856 1701
@@ -1874,20 +1719,20 @@
1874 1719 });
1875 1720 });
1876 1721 </script>
1877 1722 <?php
1878 -
1723 +
1879 1724 }
1880 1725 // </editor-fold>
1881 1726
1882 1727
1883 -// <editor-fold defaultstate="collapsed" desc=" R e l o a d p a g e " >
1728 +// <editor-fold defaultstate="collapsed" desc=" R e l o a d p a g e " >
1884 1729 ////////////////////////////////////////////////////////////////////////////////
1885 1730 // R e l o a d p a g e
1886 1731 ////////////////////////////////////////////////////////////////////////////////
1887 1732 /**
1888 1733 * Reload page by using JavaScript
1889 - *
1734 + *
1890 1735 * @param string $url - URL of page to load
1891 1736 */
1892 1737 function wpbm_reload_page_by_js( $url ) {
1893 1738
@@ -1894,10 +1739,10 @@
1894 1739 $redir = html_entity_decode( esc_url( $url ) );
1895 1740
1896 1741 if ( ! empty( $redir ) ) {
1897 1742 ?>
1898 - <script type="text/javascript">
1899 - window.location.href = '<?php echo $redir ?>';
1743 + <script type="text/javascript">
1744 + window.location.href = '<?php echo esc_url($redir); ?>';
1900 1745 </script>
1901 1746 <?php
1902 1747 }
1903 1748 }
@@ -1903,9 +1748,9 @@
1903 1748 }
1904 1749
1905 1750
1906 1751 /** Redirect browser to a specific page
1907 - *
1752 + *
1908 1753 * @param string $url - URL of page to redirect
1909 1754 */
1910 1755 function wpbm_redirect( $url ) {
1911 1756
@@ -1913,20 +1758,20 @@
1913 1758
1914 1759 $url = html_entity_decode( esc_url( $url ) );
1915 1760
1916 1761 echo '<script type="text/javascript">';
1917 - echo 'window.location.href="'.$url.'";';
1762 + echo 'window.location.href="'.esc_url($url).'";';
1918 1763 echo '</script>';
1919 1764 echo '<noscript>';
1920 - echo '<meta http-equiv="refresh" content="0;url='.$url.'" />';
1765 + echo '<meta http-equiv="refresh" content="0;url='.esc_url($url).'" />';
1921 1766 echo '</noscript>';
1922 1767 }
1923 1768 // </editor-fold>
1924 1769
1925 1770
1926 -// <editor-fold defaultstate="collapsed" desc=" P a g i n a t i o n o f T a b l e L i s t i n g " >
1771 +// <editor-fold defaultstate="collapsed" desc=" P a g i n a t i o n o f T a b l e L i s t i n g " >
1927 1772 /** Show P a g i n a t i o n
1928 - *
1773 + *
1929 1774 * @param int $summ_number_of_items - total number of items
1930 1775 * @param int $active_page_num - number of activated page
1931 1776 * @param int $num_items_per_page - number of items per page
1932 1777 * @param array $only_these_parameters - array of keys to exclude from links
@@ -1942,11 +1787,10 @@
1942 1787 if ( $pages_number < 2 )
1943 1788 return;
1944 1789
1945 1790 //Fix: 5.1.4 - Just in case we are having tooo much resources, then we need to show all resources - and its empty string
1946 - if ( ( isset($_REQUEST['wh_wpbm_type'] ) ) && ( strlen($_REQUEST['wh_wpbm_type']) > 1000 ) ) {
1947 - $_REQUEST['wh_wpbm_type'] = '';
1948 - }
1791 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1792 + if ( ( isset($_REQUEST['wh_wpbm_type'] ) ) && ( strlen($_REQUEST['wh_wpbm_type']) > 1000 ) ) { $_REQUEST['wh_wpbm_type'] = ''; }
1949 1793
1950 1794 // First parameter will overwriten by $_GET['page'] parameter
1951 1795 $bk_admin_url = wpbm_get_params_in_url( wpbm_get_master_url( false ), array('page_num'), $only_these_parameters );
1952 1796
@@ -1952,9 +1796,9 @@
1952 1796
1953 1797
1954 1798 ?>
1955 1799 <span class="wpdevelop wpbm-pagination">
1956 - <div class="container-fluid">
1800 + <div class="container-fluid">
1957 1801 <div class="row">
1958 1802 <div class="col-sm-12 text-center control-group0">
1959 1803 <nav class="btn-toolbar">
1960 1804 <div class="btn-group wpbm-no-margin" style="float:none;">
@@ -1959,13 +1803,13 @@
1959 1803 <nav class="btn-toolbar">
1960 1804 <div class="btn-group wpbm-no-margin" style="float:none;">
1961 1805
1962 1806 <?php if ( $pages_number > 1 ) { ?>
1963 - <a class="button button-secondary <?php echo ( $active_page_num == 1 ) ? ' disabled' : ''; ?>"
1964 - href="<?php echo $bk_admin_url; ?>&page_num=<?php if ($active_page_num == 1) { echo $active_page_num; } else { echo ($active_page_num-1); } echo $url_sufix; ?>">
1965 - <?php _e('Prev', 'booking-manager'); ?>
1807 + <a class="button button-secondary <?php echo ( $active_page_num == 1 ) ? ' disabled' : ''; ?>"
1808 + href="<?php echo esc_url($bk_admin_url); ?>&page_num=<?php if ($active_page_num == 1) { echo esc_attr( $active_page_num ); } else { echo esc_attr($active_page_num-1); } echo esc_attr( $url_sufix ); ?>">
1809 + <?php esc_html_e('Prev', 'booking-manager'); ?>
1966 1810 </a>
1967 - <?php }
1811 + <?php }
1968 1812
1969 1813 /** Number visible pages (links) that linked to active page, other pages skipped by "..." */
1970 1814 $num_closed_steps = 3;
1971 1815
@@ -1970,23 +1814,23 @@
1970 1814 $num_closed_steps = 3;
1971 1815
1972 1816 for ( $pg_num = 1; $pg_num <= $pages_number; $pg_num++ ) {
1973 1817
1974 - if ( ! (
1975 - ( $pages_number > ( $num_closed_steps * 4) )
1976 - && ( $pg_num > $num_closed_steps )
1977 - && ( ( $pages_number - $pg_num + 1 ) > $num_closed_steps )
1978 - && ( abs( $active_page_num - $pg_num ) > $num_closed_steps )
1818 + if ( ! (
1819 + ( $pages_number > ( $num_closed_steps * 4) )
1820 + && ( $pg_num > $num_closed_steps )
1821 + && ( ( $pages_number - $pg_num + 1 ) > $num_closed_steps )
1822 + && ( abs( $active_page_num - $pg_num ) > $num_closed_steps )
1979 1823 ) ) {
1980 - ?> <a class="button button-secondary <?php if ($pg_num == $active_page_num ) echo ' active'; ?>"
1981 - href="<?php echo $bk_admin_url; ?>&page_num=<?php echo $pg_num; echo $url_sufix; ?>">
1982 - <?php echo $pg_num; ?>
1983 - </a><?php
1824 + ?> <a class="button button-secondary <?php if ($pg_num == $active_page_num ) echo ' active'; ?>"
1825 + href="<?php echo esc_attr( $bk_admin_url ); ?>&page_num=<?php echo esc_attr( $pg_num); echo esc_attr( $url_sufix); ?>">
1826 + <?php echo esc_html($pg_num); ?>
1827 + </a><?php
1984 1828
1985 - if ( ( $pages_number > ( $num_closed_steps * 4) )
1986 - && ( ($pg_num+1) > $num_closed_steps )
1987 - && ( ( $pages_number - ( $pg_num + 1 ) ) > $num_closed_steps )
1988 - && ( abs($active_page_num - ( $pg_num + 1 ) ) > $num_closed_steps )
1829 + if ( ( $pages_number > ( $num_closed_steps * 4) )
1830 + && ( ($pg_num+1) > $num_closed_steps )
1831 + && ( ( $pages_number - ( $pg_num + 1 ) ) > $num_closed_steps )
1832 + && ( abs($active_page_num - ( $pg_num + 1 ) ) > $num_closed_steps )
1989 1833 ) {
1990 1834 echo ' <a class="button button-secondary disabled" href="javascript:void(0);">...</a> ';
1991 1835 }
1992 1836 }
@@ -1992,11 +1836,11 @@
1992 1836 }
1993 1837 }
1994 1838
1995 1839 if ( $pages_number > 1 ) { ?>
1996 - <a class="button button-secondary <?php echo ( $active_page_num == $pages_number ) ? ' disabled' : ''; ?>"
1997 - href="<?php echo $bk_admin_url; ?>&page_num=<?php if ($active_page_num == $pages_number) { echo $active_page_num; } else { echo ($active_page_num+1); } echo $url_sufix; ?>">
1998 - <?php _e('Next', 'booking-manager'); ?>
1840 + <a class="button button-secondary <?php echo ( $active_page_num == $pages_number ) ? ' disabled' : ''; ?>"
1841 + href="<?php echo esc_attr( $bk_admin_url ); ?>&page_num=<?php if ($active_page_num == $pages_number) { echo esc_attr( $active_page_num); } else { echo esc_attr($active_page_num+1); } echo esc_attr( $url_sufix); ?>">
1842 + <?php esc_html_e('Next', 'booking-manager'); ?>
1999 1843 </a>
2000 1844 <?php } ?>
2001 1845
2002 1846 </div>
@@ -2009,9 +1853,9 @@
2009 1853 }
2010 1854 // </editor-fold>
2011 1855
2012 1856
2013 -// <editor-fold defaultstate="collapsed" desc=" D a t e s " >
1857 +// <editor-fold defaultstate="collapsed" desc=" D a t e s " >
2014 1858 ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
2015 1859 // Dates Format
2016 1860 ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
2017 1861
@@ -2016,9 +1860,9 @@
2016 1860 ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
2017 1861
2018 1862
2019 1863 /** Get Formated Date & time
2020 - *
1864 + *
2021 1865 * @param string $date_sql - 2017-07-31 00:00:00 || 2017-07-31
2022 1866 * @param string $date_format - Optional. - "m / d / Y, D H:i:s"
2023 1867 * @param string $seperator - Optional. - " "
2024 1868 * @return string - July 29, 2014 12:00 am
@@ -2023,21 +1867,21 @@
2023 1867 * @param string $seperator - Optional. - " "
2024 1868 * @return string - July 29, 2014 12:00 am
2025 1869 */
2026 1870 function wpbm_get_date_time_formatted( $date_sql, $date_format = false, $seperator = ' ', $skip_midnight_time = false ) {
2027 -
1871 +
2028 1872 $return_date = wpbm_get_date_formatted( $date_sql, $date_format );
2029 -
2030 - $return_time = wpbm_get_time_formatted( $date_sql, $date_format, $skip_midnight_time );
1873 +
1874 + $return_time = wpbm_get_time_formatted( $date_sql, $date_format, $skip_midnight_time );
2031 1875 if ( ! empty( $return_time ) )
2032 1876 $return_date .= $seperator . $return_time;
2033 -
1877 +
2034 1878 return $return_date;
2035 1879 }
2036 1880
2037 1881
2038 1882 /** Get Formated Date
2039 - *
1883 + *
2040 1884 * @param string $date_sql - 2017-07-31 00:00:00 || 2017-07-31
2041 1885 * @param string $date_format - Optional. - "m / d / Y, D"
2042 1886 * @param bool $skip_midnight_time - Default false - if 00:00:00 then return '';
2043 1887 * @return string - July 29, 2014
@@ -2045,17 +1889,17 @@
2045 1889 function wpbm_get_date_formatted( $date_sql, $date_format = false ) {
2046 1890
2047 1891 if ( $date_format === false ) $date_format = get_wpbm_option( 'wpbm_date_format' );
2048 1892 if ( empty( $date_format ) ) $date_format = "m / d / Y, D";
2049 -
1893 +
2050 1894 $formated_date = date_i18n( $date_format, strtotime( $date_sql ) );
2051 -
1895 +
2052 1896 return $formated_date;
2053 1897 }
2054 1898
2055 1899
2056 1900 /** Get Formated Date & time
2057 - *
1901 + *
2058 1902 * @param string $date_sql - 2017-07-31 00:00:00 || 2017-07-31
2059 1903 * @param string $time_format - Optional. - "H:i:s"
2060 1904 * @return string - 12:00 am
2061 1905 */
@@ -2062,20 +1906,20 @@
2062 1906 function wpbm_get_time_formatted( $date_sql, $time_format = false , $skip_midnight_time = false ) {
2063 1907
2064 1908 if ( ( $skip_midnight_time ) && ( '00:00:00' == substr( $date_sql, -8 ) ) )
2065 1909 return '';
2066 -
1910 +
2067 1911 if ( $time_format === false ) $time_format = get_wpbm_option( 'wpbm_time_format' );
2068 1912 if ( empty( $time_format ) ) $time_format = 'h:i a';
2069 -
1913 +
2070 1914 $formated_date = date_i18n( $time_format, strtotime( $date_sql ) );
2071 -
2072 - return $formated_date;
1915 +
1916 + return $formated_date;
2073 1917 }
2074 1918
2075 1919
2076 1920 /** Check if "current_day" is tomorrow from "next_day"
2077 - *
1921 + *
2078 1922 * @param string $current_day_sql_check : 2015-02-29 00:00:00
2079 1923 * @param string $next_day_sql_check : 2015-02-30 00:00:00
2080 1924 * @return boolean : true | false
2081 1925 */
@@ -2082,28 +1926,28 @@
2082 1926 function wpbm_is_next_day( $current_day_sql_check, $next_day_sql_check ) {
2083 1927
2084 1928 // Current day
2085 1929 $current_day_unix = strtotime( $current_day_sql_check );
2086 -
1930 +
2087 1931 $current_day_midnight_sql = date_i18n( 'Y-m-d', $current_day_unix );
2088 1932 $current_day_midnight_unix = strtotime( $current_day_midnight_sql );
2089 -
1933 +
2090 1934 $calc_next_day_unix = strtotime( '+1 day', $current_day_midnight_unix );
2091 -
1935 +
2092 1936 // Next day
2093 - $next_day_unix = strtotime( $next_day_sql_check );
1937 + $next_day_unix = strtotime( $next_day_sql_check );
2094 1938 $next_day_midnight_sql = date_i18n( 'Y-m-d', $next_day_unix );
2095 1939 $next_day_midnight_unix = strtotime( $next_day_midnight_sql );
2096 -
2097 -
2098 - if ( $calc_next_day_unix == $next_day_midnight_unix )
2099 - return true;
2100 - else
2101 - return false;
1940 +
1941 +
1942 + if ( $calc_next_day_unix == $next_day_midnight_unix )
1943 + return true;
1944 + else
1945 + return false;
2102 1946 }
2103 1947
2104 1948 /** Check if "current_day" is same day of "other_day"
2105 - *
1949 + *
2106 1950 * @param string $current_day_sql_check : 2015-02-29 00:00:00
2107 1951 * @param string $other_day_sql_check : 2015-02-30 00:00:00
2108 1952 * @return boolean : true | false
2109 1953 */
@@ -2110,27 +1954,27 @@
2110 1954 function wpbm_is_this_same_day( $current_day_sql_check, $other_day_sql_check ) {
2111 1955
2112 1956 // Current day
2113 1957 $current_day_unix = strtotime( $current_day_sql_check );
2114 -
1958 +
2115 1959 $current_day_midnight_sql = date_i18n( 'Y-m-d', $current_day_unix );
2116 1960 $current_day_midnight_unix = strtotime( $current_day_midnight_sql );
2117 -
1961 +
2118 1962 // Other day
2119 - $other_day_unix = strtotime( $other_day_sql_check );
1963 + $other_day_unix = strtotime( $other_day_sql_check );
2120 1964 $other_day_midnight_sql = date_i18n( 'Y-m-d', $other_day_unix );
2121 1965 $other_day_midnight_unix = strtotime( $other_day_midnight_sql );
2122 -
2123 -
2124 - if ( $current_day_midnight_unix == $other_day_midnight_unix )
2125 - return true;
2126 - else
2127 - return false;
1966 +
1967 +
1968 + if ( $current_day_midnight_unix == $other_day_midnight_unix )
1969 + return true;
1970 + else
1971 + return false;
2128 1972 }
2129 1973
2130 1974
2131 1975 /** Get days in short format view
2132 - *
1976 + *
2133 1977 * @param string $days Dates: 15.05.2015, 16.05.2015, 17.05.2015
2134 1978 * @return string Dates in format: 15.05.2015 - 17.05.2015
2135 1979 */
2136 1980 function wpbm_get_dates_short_format( $dates_sql_csv ) { // $days - string with comma seperated dates
@@ -2144,24 +1988,24 @@
2144 1988 $result_string = '';
2145 1989 $last_show_day = '';
2146 1990
2147 1991 foreach ( $days as $day ) {
2148 -
1992 +
2149 1993 $is_fin_at_end = false;
2150 -
1994 +
2151 1995 if ( $previosday === false ) { // First Day
2152 -
1996 +
2153 1997 $result_string = wpbm_get_date_time_formatted( $day, false, ' ', true ); // echo format for first day
2154 1998 $last_show_day = $day;
2155 1999 $previosday = $day; // Set previos day for next loop
2156 -
2000 +
2157 2001 } else { // Not first day
2158 -
2159 - if (
2160 - wpbm_is_next_day( $previosday, $day )
2161 - || wpbm_is_this_same_day( $previosday, $day )
2002 +
2003 + if (
2004 + wpbm_is_next_day( $previosday, $day )
2005 + || wpbm_is_this_same_day( $previosday, $day )
2162 2006 ) { // Check if $day next day from previous
2163 -
2007 +
2164 2008 $previosday = $day; // Set previos day for next loop
2165 2009 $is_fin_at_end = true;
2166 2010 } else {
2167 2011 if ( $last_show_day !== $previosday ) { // check if previos day was show or no
@@ -2170,10 +2014,10 @@
2170 2014 $result_string .= ', ' . wpbm_get_date_time_formatted( $day, false, ' ', true ); // assign in needed format this day
2171 2015 $previosday = $day; // Set previos day for next loop
2172 2016 $last_show_day = $day;
2173 2017 }
2174 - }
2175 -
2018 + }
2019 +
2176 2020 }
2177 2021
2178 2022 if ( $is_fin_at_end ) {
2179 2023 $result_string .= ' - ' . wpbm_get_date_time_formatted( $day, false, ' ', true );
@@ -2181,5 +2025,5 @@
2181 2025
2182 2026 return $result_string;
2183 2027 }
2184 2028
2185 -// </editor-fold>
2029 +// </editor-fold>