PluginProbe
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar / 2.1.21
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar v2.1.21
2.1.22 2.1.21 2.1.20 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 trunk 1.1 2.0 2.0.1 2.0.10.2 2.0.11 2.0.12 2.0.13 2.0.14 2.0.15 2.0.16 2.0.17 2.0.18 2.0.2 2.0.20 2.0.21 All 56 releases
← All changes | core/wpbm-functions.php +414 -555 2.0 → 2.1.21 View file →
@@ -5,9 +5,9 @@
5 5 * @subpackage Support Functions
6 6 * @category Functions
7 7 *
8 8 * @author wpdevelop
9 - * @link http://oplugins.com/
9 + * @link https://oplugins.com/
10 10 * @email [email protected]
11 11 *
12 12 * @modified 29.09.2015
13 13 */
@@ -61,9 +61,9 @@
61 61 function wpbm_up_link() {
62 62 if ( ! wpbm_is_this_demo() )
63 63 $v = wpbm_get_ver_sufix();
64 64 else $v = '';
65 - return 'http://oplugins.com/plugins/booking-manager/' . ( ( empty($v) ) ? '' : 'upgrade-' . $v . '/' ) ;
65 + return 'https://oplugins.com/plugins/booking-manager/' . ( ( empty($v) ) ? '' : 'upgrade-' . $v . '/' ) ;
66 66 }
67 67
68 68 /** Check if this demo website
69 69 *
@@ -71,10 +71,10 @@
71 71 */
72 72 function wpbm_is_this_demo() {
73 73 //return ! true; //TODO: comment it. 2016-09-27 // Replaced!
74 74 if (
75 - ( ( isset( $_SERVER['SCRIPT_FILENAME'] ) ) && ( strpos( $_SERVER['SCRIPT_FILENAME'], 'oplugins.com' ) !== false ) )
76 - || ( ( isset( $_SERVER['HTTP_HOST'] ) ) && ( strpos( $_SERVER['HTTP_HOST'], 'oplugins.com' ) !== false ) )
75 + ( ( isset( $_SERVER['SCRIPT_FILENAME'] ) ) && ( strpos( sanitize_text_field( wp_unslash($_SERVER['SCRIPT_FILENAME']) ), 'oplugins.com' ) !== false ) )
76 + || ( ( isset( $_SERVER['HTTP_HOST'] ) ) && ( strpos( sanitize_text_field( wp_unslash($_SERVER['HTTP_HOST'])), 'oplugins.com' ) !== false ) )
77 77 )
78 78 return true;
79 79 else
80 80 return false;
@@ -89,191 +89,9 @@
89 89 /** Show System Info (status) at item > Settings General page
90 90 * Link: http://server.com/wp-admin/admin.php?page=wpbm-settings&system_info=show#wpbm_general_settings_system_info_metabox
91 91 */
92 92 function wpbm_system_info() {
93 -
94 - if ( wpbm_is_this_demo() ) return;
95 -
96 - if ( current_user_can( 'activate_plugins' ) ) { // Only for Administrator or Super admin. More here: https://codex.wordpress.org/Roles_and_Capabilities
97 -
98 - global $wpdb, $wp_version;
99 -
100 - $all_plugins = get_plugins();
101 - $active_plugins = get_option( 'active_plugins' );
102 -
103 - $mysql_info = $wpdb->get_results( "SHOW VARIABLES LIKE 'sql_mode'" );
104 - if ( is_array( $mysql_info ) ) $sql_mode = $mysql_info[0]->Value;
105 - if ( empty( $sql_mode ) ) $sql_mode = 'Not set';
106 -
107 - $safe_mode = ( ini_get( 'safe_mode' ) ) ? 'On' : 'Off';
108 - $allow_url_fopen = ( ini_get( 'allow_url_fopen' ) ) ? 'On' : 'Off';
109 - $upload_max_filesize = ( ini_get( 'upload_max_filesize' ) ) ? ini_get( 'upload_max_filesize' ) : 'N/A';
110 - $post_max_size = ( ini_get( 'post_max_size' ) ) ? ini_get( 'post_max_size' ) : 'N/A';
111 - $max_execution_time = ( ini_get( 'max_execution_time' ) ) ? ini_get( 'max_execution_time' ) : 'N/A';
112 - $memory_limit = ( ini_get( 'memory_limit' ) ) ? ini_get( 'memory_limit' ) : 'N/A';
113 - $memory_usage = ( function_exists( 'memory_get_usage' ) ) ? round( memory_get_usage() / 1024 / 1024, 2 ) . ' Mb' : 'N/A';
114 - $exif_read_data = ( is_callable( 'exif_read_data' ) ) ? 'Yes' . " ( V" . substr( phpversion( 'exif' ), 0, 4 ) . ")" : 'No';
115 - $iptcparse = ( is_callable( 'iptcparse' ) ) ? 'Yes' : 'No';
116 - $xml_parser_create = ( is_callable( 'xml_parser_create' ) ) ? 'Yes' : 'No';
117 - $theme = ( function_exists( 'wp_get_theme' ) ) ? wp_get_theme() : get_theme( get_current_theme() );
118 -
119 - if ( function_exists( 'is_multisite' ) ) {
120 - if ( is_multisite() ) $multisite = 'Yes';
121 - else $multisite = 'No';
122 - } else { $multisite = 'N/A';
123 - }
124 -
125 - $system_info = array(
126 - 'system_info' => '',
127 - 'php_info' => '',
128 - 'active_plugins' => '',
129 - 'inactive_plugins' => ''
130 - );
131 -
132 - $ver_small_name = get_wpbm_version();
133 - if ( class_exists( 'wpbm_multiuser' ) ) $ver_small_name = 'multiuser';
134 -
135 - $system_info['system_info'] = array(
136 - 'Plugin Update' => ( defined( 'WPBM_VERSION' ) ) ? WPBM_VERSION : 'N/A',
137 - 'Plugin Version' => ucwords( $ver_small_name ),
138 - 'Plugin Update Date' => date( "Y-m-d", filemtime( WPBM_FILE ) ),
139 -
140 - 'WP Version' => $wp_version,
141 - 'WP DEBUG' => ( ( defined('WP_DEBUG') ) && ( WP_DEBUG ) ) ? 'On' : 'Off',
142 - 'WP DB Version' => get_option( 'db_version' ),
143 - 'Operating System' => PHP_OS,
144 - 'Server' => $_SERVER["SERVER_SOFTWARE"],
145 - 'PHP Version' => PHP_VERSION,
146 - 'PHP Safe Mode' => $safe_mode,
147 - 'MYSQL Version' => $wpdb->get_var( "SELECT VERSION() AS version" ),
148 - 'SQL Mode' => $sql_mode,
149 - 'Memory usage' => $memory_usage,
150 - 'Site URL' => get_option( 'siteurl' ),
151 - 'Home URL' => home_url(),
152 - 'SERVER[HTTP_HOST]' => $_SERVER['HTTP_HOST'],
153 - 'SERVER[SERVER_NAME]' => $_SERVER['SERVER_NAME'],
154 - 'Multisite' => $multisite,
155 - 'Active Theme' => $theme['Name'] . ' ' . $theme['Version']
156 - );
157 -
158 - $system_info['php_info'] = array(
159 - 'PHP Version' => PHP_VERSION,
160 - 'PHP Safe Mode' => $safe_mode,
161 - 'PHP Memory Limit' => '<strong>' . $memory_limit . '</strong>',
162 - 'PHP Max Script Execute Time' => '<strong>' . $max_execution_time . '</strong>',
163 -
164 - 'PHP Max Post Size' => '<strong>' . $post_max_size . '</strong>',
165 - 'PHP MAX Input Vars' => '<strong>' . ( ( ini_get( 'max_input_vars' ) ) ? ini_get( 'max_input_vars' ) : 'N/A' ) . '</strong>', //How many input variables may be accepted (limit is applied to $_GET, $_POST and $_COOKIE superglobal separately).
166 -
167 - 'PHP Max Upload Size' => $upload_max_filesize,
168 - 'PHP Allow URL fopen' => $allow_url_fopen,
169 - 'PHP Exif support' => $exif_read_data,
170 - 'PHP IPTC support' => $iptcparse,
171 - 'PHP XML support' => $xml_parser_create
172 - );
173 -
174 - $system_info['php_info']['PHP cURL'] = ( function_exists('curl_init') ) ? 'On' : 'Off';
175 - $system_info['php_info']['Max Nesting Level'] = ( ( ini_get( 'max_input_nesting_level' ) ) ? ini_get( 'max_input_nesting_level' ) : 'N/A' );
176 - $system_info['php_info']['Max Time 4 script'] = ( ( ini_get( 'max_input_time' ) ) ? ini_get( 'max_input_time' ) : 'N/A' ); //Maximum amount of time each script may spend parsing request data
177 - $system_info['php_info']['Log'] = ( ( ini_get( 'error_log' ) ) ? ini_get( 'error_log' ) : 'N/A' );
178 -
179 - if ( ini_get( "suhosin.get.max_value_length" ) ) {
180 -
181 - $system_info['suhosin_info'] = array();
182 - $system_info['suhosin_info']['POST max_array_index_length'] = ( ( ini_get( 'suhosin.post.max_array_index_length' ) ) ? ini_get( 'suhosin.post.max_array_index_length' ) : 'N/A' );
183 - $system_info['suhosin_info']['REQUEST max_array_index_length'] = ( ( ini_get( 'suhosin.request.max_array_index_length' ) ) ? ini_get( 'suhosin.request.max_array_index_length' ) : 'N/A' );
184 -
185 - $system_info['suhosin_info']['POST max_totalname_length'] = ( ( ini_get( 'suhosin.post.max_totalname_length' ) ) ? ini_get( 'suhosin.post.max_totalname_length' ) : 'N/A' );
186 - $system_info['suhosin_info']['REQUEST max_totalname_length'] = ( ( ini_get( 'suhosin.request.max_totalname_length' ) ) ? ini_get( 'suhosin.request.max_totalname_length' ) : 'N/A' );
187 -
188 - $system_info['suhosin_info']['POST max_vars'] = ( ( ini_get( 'suhosin.post.max_vars' ) ) ? ini_get( 'suhosin.post.max_vars' ) : 'N/A' );
189 - $system_info['suhosin_info']['REQUEST max_vars'] = ( ( ini_get( 'suhosin.request.max_vars' ) ) ? ini_get( 'suhosin.request.max_vars' ) : 'N/A' );
190 -
191 - $system_info['suhosin_info']['POST max_value_length'] = ( ( ini_get( 'suhosin.post.max_value_length' ) ) ? ini_get( 'suhosin.post.max_value_length' ) : 'N/A' );
192 - $system_info['suhosin_info']['REQUEST max_value_length'] = ( ( ini_get( 'suhosin.request.max_value_length' ) ) ? ini_get( 'suhosin.request.max_value_length' ) : 'N/A' );
193 -
194 - $system_info['suhosin_info']['POST max_name_length'] = ( ( ini_get( 'suhosin.post.max_name_length' ) ) ? ini_get( 'suhosin.post.max_name_length' ) : 'N/A' );
195 - $system_info['suhosin_info']['REQUEST max_varname_length'] = ( ( ini_get( 'suhosin.request.max_varname_length' ) ) ? ini_get( 'suhosin.request.max_varname_length' ) : 'N/A' );
196 -
197 - $system_info['suhosin_info']['POST max_array_depth'] = ( ( ini_get( 'suhosin.post.max_array_depth' ) ) ? ini_get( 'suhosin.post.max_array_depth' ) : 'N/A' );
198 - $system_info['suhosin_info']['REQUEST max_array_depth'] = ( ( ini_get( 'suhosin.request.max_array_depth' ) ) ? ini_get( 'suhosin.request.max_array_depth' ) : 'N/A' );
199 - }
200 -
201 -
202 - if ( function_exists('gd_info') ) {
203 - $gd_info = gd_info();
204 - if ( isset( $gd_info['GD Version'] ) )
205 - $gd_info = $gd_info['GD Version'];
206 - else
207 - $gd_info = json_encode( $gd_info );
208 - } else {
209 - $gd_info = 'Off';
210 - }
211 - $system_info['php_info']['PHP GD'] = $gd_info;
212 -
213 - // More here https://docs.woocommerce.com/document/problems-with-large-amounts-of-data-not-saving-variations-rates-etc/
214 -
215 -
216 - foreach ( $all_plugins as $path => $plugin ) {
217 - if ( is_plugin_active( $path ) )
218 - $system_info['active_plugins'][$plugin['Name']] = $plugin['Version'];
219 - else
220 - $system_info['inactive_plugins'][$plugin['Name']] = $plugin['Version'];
221 - }
222 -
223 - // Showing
224 - foreach ( $system_info as $section_name => $section_values ) {
225 - ?>
226 - <span class="wpdevelop">
227 - <table class="table table-striped table-bordered">
228 - <thead><tr><th colspan="2" style="border-bottom: 1px solid #eeeeee;padding: 10px;"><?php echo strtoupper( $section_name ); ?></th></tr></thead>
229 - <tbody>
230 - <?php
231 - if ( !empty( $section_values ) ) {
232 - foreach ( $section_values as $key => $value ) {
233 - ?>
234 - <tr>
235 - <td scope="row" style="width:18em;padding:4px 8px;"><?php echo $key; ?></td>
236 - <td scope="row" style="padding:4px 8px;"><?php echo $value; ?></td>
237 - </tr>
238 - <?php
239 - }
240 - }
241 - ?>
242 - </tbody>
243 - </table>
244 - </span>
245 - <div class="clear"></div>
246 - <?php
247 - }
248 -?>
249 -<hr>
250 -<div style="color:#777;">
251 -<h4 style="font-size:1.1em;">Commonly required configuration vars in php.ini file:</h4>
252 -<h4>General section:</h4>
253 -<pre><code>memory_limit = 256M
254 -max_execution_time = 120
255 -post_max_size = 8M
256 -upload_max_filesize = 8M
257 -max_input_vars = 20480
258 -post_max_size = 64M</code></pre>
259 -<h4>Suhosin section (if installed):</h4>
260 -<pre><code>suhosin.post.max_array_index_length = 1024
261 -suhosin.post.max_totalname_length = 65535
262 -suhosin.post.max_vars = 2048
263 -suhosin.post.max_value_length = 1000000
264 -suhosin.post.max_name_length = 256
265 -suhosin.post.max_array_depth = 1000
266 -suhosin.request.max_array_index_length = 1024
267 -suhosin.request.max_totalname_length = 65535
268 -suhosin.request.max_vars = 2048
269 -suhosin.request.max_value_length = 1000000
270 -suhosin.request.max_varname_length = 256
271 -suhosin.request.max_array_depth = 1000</code></pre>
272 -</div>
273 -<?php
274 - // phpinfo();
275 - }
93 + echo '---';
276 94 }
277 95
278 96
279 97
@@ -296,9 +114,9 @@
296 114 function wpbm_is_wpbc_supported() {
297 115
298 116 // 7.2.1 - its start version of Booking Calendar which support integration with Booking Manager 2.0
299 117
300 - if ( version_compare( wpbm_get_wpbc_version(), '7.2.1') >= 0 ) {
118 + if ( version_compare( wpbm_get_wpbc_version(), '9.8') >= 0 ) {
301 119 return true;
302 120 } else {
303 121 return false;
304 122 }
@@ -387,10 +205,10 @@
387 205 // List of preg* regular expression patterns to search for replace in plain emails. More: https://raw.github.com/ushahidi/wp-silcc/master/class.html2text.inc
388 206 $plain_search_array = array(
389 207 "/\r/", // Non-legal carriage return
390 208 '/&(nbsp|#160);/i', // Non-breaking space
391 - '/&(quot|rdquo|ldquo|#8220|#8221|#147|#148);/i', // Double quotes
392 - '/&(apos|rsquo|lsquo|#8216|#8217);/i', // Single quotes
209 + '/&(quot|rdquo|ldquo|#8220|#8221|#147|#148|#34|#034);/i', // Double quotes //FixIn: 2.0.1.6
210 + '/&(apos|rsquo|lsquo|#8216|#8217|#39|#039);/i', // Single quotes //FixIn: 2.0.1.6
393 211 '/&gt;/i', // Greater-than
394 212 '/&lt;/i', // Less-than
395 213 '/&#38;/i', // Ampersand
396 214 '/&#038;/i', // Ampersand
@@ -431,9 +249,9 @@
431 249 '', // Unknown/unhandled entities
432 250 ' ' // Runs of spaces, post-handling
433 251 );
434 252
435 - $newstring = preg_replace( $plain_search_array, $get_plain_replace_array, strip_tags( $string ) );
253 + $newstring = preg_replace( $plain_search_array, $get_plain_replace_array, wp_strip_all_tags( $string ) );
436 254
437 255 return $newstring;
438 256 }
439 257 // </editor-fold>
@@ -462,8 +280,10 @@
462 280 $replace = wp_parse_args( $replace_array, $defaults );
463 281
464 282 foreach ( $replace as $replace_shortcode => $replace_value ) {
465 283
284 + $replace_value = esc_js( $replace_value ); // FixIn:
285 +
466 286 $subject = str_replace( array( '[' . $replace_shortcode . ']'
467 287 , '{' . $replace_shortcode . '}' )
468 288 , $replace_value
469 289 , $subject );
@@ -476,10 +296,50 @@
476 296
477 297 return $subject;
478 298 }
479 299
300 +
301 +/**
302 + * Sanitize the frontend listing template.
303 + *
304 + * The listing template is stored as an option and rendered by the public
305 + * [booking-manager-listing] shortcode, so script-capable markup must never be
306 + * persisted or returned to visitors.
307 + *
308 + * @param string $template Template HTML with Booking Manager placeholders.
309 + * @return string Safe template HTML.
310 + */
311 +function wpbm_sanitize_listing_template( $template ) {
312 +
313 + if ( ! is_string( $template ) ) {
314 + $template = '';
315 + }
316 +
317 + $allowed_html = wp_kses_allowed_html( 'post' );
318 +
319 + // Keep compatibility with templates that embed safe external content.
320 + $allowed_html['iframe'] = array(
321 + 'src' => true
322 + , 'style' => true
323 + , 'id' => true
324 + , 'class' => true
325 + , 'width' => true
326 + , 'height' => true
327 + , 'title' => true
328 + , 'loading' => true
329 + , 'allowfullscreen' => true
330 + );
331 +
332 + if ( isset( $allowed_html['a'] ) ) {
333 + $allowed_html['a']['target'] = true;
334 + $allowed_html['a']['rel'] = true;
335 + }
336 +
337 + return wp_kses( $template, $allowed_html );
338 +}
339 +
480 340 /** Simple hack to make array strings lowercase
481 - *
341 + *
482 342 * @param type $array
483 343 * @return type
484 344 */
485 345 function wpbm_arraytolower( $array ){
@@ -506,22 +366,22 @@
506 366 }
507 367 }
508 368
509 369 /** Check if this valid timestamp
510 - *
370 + *
511 371 * @param string|int $timestamp
512 372 * @return bool
513 373 */
514 374 function wpbm_is_valid_timestamp( $timestamp ) {
515 - return ( ( (string) (int) $timestamp === $timestamp)
375 + return ( ( (string) (int) $timestamp === $timestamp)
516 376 && ($timestamp <= PHP_INT_MAX)
517 - && ($timestamp >= ~PHP_INT_MAX)
377 + && ($timestamp >= ~PHP_INT_MAX)
518 378 );
519 379 }
520 380 // </editor-fold>
521 381
522 -
523 -// <editor-fold defaultstate="collapsed" desc=" F i l e s && U R L s " >
382 +
383 +// <editor-fold defaultstate="collapsed" desc=" F i l e s && U R L s " >
524 384 ////////////////////////////////////////////////////////////////////////////////
525 385 // F i l e s && U R L s
526 386 ////////////////////////////////////////////////////////////////////////////////
527 387
@@ -546,9 +406,9 @@
546 406 return trailingslashit( WPBM_PLUGIN_URL ) . ltrim( $path, '/\\' );
547 407 }
548 408
549 409 /** Check if such file exist or not.
550 - *
410 + *
551 411 * @param string $path - relative path to file (relative to plugin folder).
552 412 * @return boolean true | false
553 413 */
554 414 function wpbm_is_file_exist( $path ) {
@@ -554,14 +414,14 @@
554 414 function wpbm_is_file_exist( $path ) {
555 415
556 416 if ( file_exists( trailingslashit( WPBM_PLUGIN_DIR ) . ltrim( $path, '/\\' ) ) ) // check if this file exist
557 417 return true;
558 - else
418 + else
559 419 return false;
560 420 }
561 -
421 +
562 422 /** Set URL from absolute to relative (starting from /)
563 - *
423 + *
564 424 * @param type $url
565 425 * @return type
566 426 */
567 427 function wpbm_set_relative_url( $url ){
@@ -574,24 +434,24 @@
574 434 $url = trim($url_path, '/');
575 435 return '/' . $url;
576 436 }
577 437
578 -/** Get Correct Relative URL
579 - *
438 +/** Get Correct Relative URL
439 + *
580 440 * @param type $link
581 441 * @return string
582 442 */
583 443 function wpbm_make_link_relative( $link ){
584 444
585 - if ( $link == get_option('siteurl') )
445 + if ( $link == get_option('siteurl') )
586 446 $link = '/';
587 - $link = '/' . trim( wp_make_link_relative( $link ), '/' );
447 + $link = '/' . trim( wp_make_link_relative( $link ), '/' );
588 448
589 - return $link;
449 + return $link;
590 450 }
591 451
592 -/** Get Correct Absolute URL
593 - *
452 +/** Get Correct Absolute URL
453 + *
594 454 * @param string $link
595 455 * @return type
596 456 */
597 457 function wpbm_make_link_absolute( $link ){
@@ -596,17 +456,17 @@
596 456 */
597 457 function wpbm_make_link_absolute( $link ){
598 458
599 459 if ( ( $link != get_option('siteurl') ) && ( strpos($link, 'http') !== 0 ) )
600 - $link = get_option('siteurl') . '/' . trim( wp_make_link_relative( $link ), '/' );
460 + $link = get_option('siteurl') . '/' . trim( wp_make_link_relative( $link ), '/' );
601 461 return esc_js( $link ) ;
602 462 }
603 463
604 464
605 465 if (!function_exists ('get_file_data_wpdev')) {
606 -
466 +
607 467 /** Get header info from this file, just for compatibility with WordPress 2.8 and older versions
608 - *
468 + *
609 469 * @param type $file
610 470 * @param type $default_headers
611 471 * @param type $context
612 472 * @return type
@@ -612,15 +472,15 @@
612 472 * @return type
613 473 */
614 474 function get_file_data_wpdev( $file, $default_headers, $context = '' ) {
615 475 // We don't need to write to the file, so just open for reading.
616 - $fp = fopen( $file, 'r' );
476 + $fp = fopen( $file, 'r' ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fopen
617 477
618 478 // Pull only the first 8kiB of the file in.
619 - $file_data = fread( $fp, 8192 );
479 + $file_data = fread( $fp, 8192 );// phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fread
620 480
621 481 // PHP will close file handle, but we are good citizens.
622 - fclose( $fp );
482 + fclose( $fp );// phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fclose
623 483
624 484 if( $context != '' ) {
625 485 $extra_headers = array(); //apply_filters( "extra_$context".'_headers', array() );
626 486
@@ -648,9 +508,9 @@
648 508 }
649 509
650 510
651 511 /** Get content from specific URL
652 - *
512 + *
653 513 * @param string $url
654 514 * @return string|boolean (false on error)
655 515 */
656 516 function wpbm_get_ssl_page_content( $url ) {
@@ -658,13 +518,15 @@
658 518 $request = new WP_Http();
659 519
660 520 $result = $request->request( $url
661 521 , array( // Default Parameters
522 + 'reject_unsafe_urls' => true, //FixIn: 2.0.29.1
523 + 'user-agent' => 'Mozilla/5.0 (iPad; U; CPU OS 3_2_1 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Mobile/7B405' //FixIn: 2.0.12.1
662 524 // 'method' => 'GET',
663 525 // 'timeout' => 5, // timeout value for an HTTP request.
664 - // 'redirection' => 5, // number of redirects allowed during an HTTP request.
665 - // 'httpversion' => '1.0',
666 - // 'user-agent' => 'WordPress/' . get_bloginfo( 'version' ) . '; ' . get_bloginfo( 'url' ),
526 + // 'redirection' => 5, // number of redirects allowed during an HTTP request.
527 + // 'httpversion' => '1.0',
528 + // 'user-agent' => 'WordPress/' . get_bloginfo( 'version' ) . '; ' . get_bloginfo( 'url' ),
667 529 // 'reject_unsafe_urls' => false,
668 530 // 'blocking' => true,
669 531 // 'headers' => array(),
670 532 // 'cookies' => array(),
@@ -675,19 +537,34 @@
675 537 // 'sslcertificates' => ABSPATH . WPINC . '/certificates/ca-bundle.crt',
676 538 // 'stream' => false,
677 539 // 'filename' => null,
678 540 // 'limit_response_size' => null
679 - )
541 + )
680 542 );
681 543
682 - if (
683 - ( ! is_wp_error( $result ) )
684 - && ( $result[ 'response' ][ 'code' ] == '200' )
544 + if (
545 + ( ! is_wp_error( $result ) )
546 + && ( $result[ 'response' ][ 'code' ] == '200' )
685 547 ) {
686 548
687 549 return $result[ 'body' ];
688 550
689 551 } else {
552 +
553 + //FixIn: 2.0.2.2
554 + if ( is_wp_error( $result ) ) {
555 + $error_message = $result->get_error_message();
556 + } else {
557 + $error_message = __( 'Unknown error during downloading feed', 'booking-manager' );
558 +
559 + // Show more detail info of not ability to download .ics feeds. //FixIn: 2.0.10.5
560 + $error_message .= $result[ 'body' ];
561 + //do_action( 'wpbc_admin_show_top_notice', $error_message, 'error', 5000 );
562 + //die;
563 + }
564 + do_action( 'wpbc_admin_show_top_notice', $error_message, 'error', 5000 ); // N_O_T_I_C_E in H_E_A_D_E_R
565 +// debuge($error_message); //FixIn: 2.0.1.3 //FixIn: 2.0.8.2
566 +
690 567 return false;
691 568 }
692 569 }
693 570
@@ -712,9 +589,9 @@
712 589 $d = 0; // string bytes counter
713 590
714 591 // Iterate over every character in the string, escaping with a slash or encoding to UTF-8 where necessary
715 592 for ( $c = 0; $c < $strlen_var; ++ $c ) {
716 - $ord_var_c = ord( $str{$c} );
593 + $ord_var_c = ord( $str[$c] ); //FixIn: 2.0.17.1
717 594 switch ( true ) {
718 595 case(($ord_var_c >= 0x20) && ($ord_var_c <= 0x7F)): // characters U-00000000 - U-0000007F (same as ASCII)
719 596 $d ++;
720 597 break;
@@ -743,15 +620,15 @@
743 620
744 621 // </editor-fold>
745 622
746 623
747 -// <editor-fold defaultstate="collapsed" desc=" A d m i n M e n u L i n k s " >
624 +// <editor-fold defaultstate="collapsed" desc=" A d m i n M e n u L i n k s " >
748 625 ////////////////////////////////////////////////////////////////////////////
749 626 // A d m i n M e n u L i n k s
750 627 ////////////////////////////////////////////////////////////////////////////
751 628
752 629 /** Get URL to specific Admin Menu page
753 - *
630 + *
754 631 * @param string $menu_type - { item | add | resources | settings }
755 632 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
756 633 * @return string - URL to menu
757 634 */
@@ -779,19 +656,19 @@
779 656 }
780 657
781 658 if ( $is_absolute_url ) {
782 659 $link = admin_url( 'admin.php' ) . '?page=' . $link ;
783 - }
660 + }
784 661
785 - return $link;
662 + return $link;
786 663 }
787 664
788 665 // // // // // // // // // // // // // // // // // // // // // // // // // /
789 666
790 667 /** Get URL of item Listing or Calendar Overview page
791 - *
668 + *
792 669 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
793 - * @param boolean $is_old - { default: true }
670 + * @param boolean $is_old - { default: true }
794 671 * @return string - URL to menu
795 672 */
796 673 function wpbm_get_master_url( $is_absolute_url = true ) {
797 674 return wpbm_get_menu_url( 'master', $is_absolute_url );
@@ -796,12 +673,12 @@
796 673 function wpbm_get_master_url( $is_absolute_url = true ) {
797 674 return wpbm_get_menu_url( 'master', $is_absolute_url );
798 675 }
799 676
800 -/** Get URL of item > Add item page
801 - *
677 +/** Get URL of item > Add item page
678 + *
802 679 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
803 - * @param boolean $is_old - { default: true }
680 + * @param boolean $is_old - { default: true }
804 681 * @return string - URL to menu
805 682 */
806 683 function wpbm_get_new_wpbm_url( $is_absolute_url = true ) {
807 684 return wpbm_get_menu_url( 'add', $is_absolute_url );
@@ -806,18 +683,18 @@
806 683 function wpbm_get_new_wpbm_url( $is_absolute_url = true ) {
807 684 return wpbm_get_menu_url( 'add', $is_absolute_url );
808 685 }
809 686
810 -/** Get URL of item > Settings page
811 - *
687 +/** Get URL of item > Settings page
688 + *
812 689 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
813 - * @param boolean $is_old - { default: true }
690 + * @param boolean $is_old - { default: true }
814 691 * @return string - URL to menu
815 692 */
816 693 function wpbm_get_settings_url( $is_absolute_url = true ) {
817 694 return wpbm_get_menu_url( 'settings', $is_absolute_url );
818 695 }
819 -
696 +
820 697 // // // // // // // // // // // // // // // // // // // // // // // // // /
821 698
822 699 /** Check if this item Listing or Calendar Overview page
823 700 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
@@ -822,62 +699,62 @@
822 699 /** Check if this item Listing or Calendar Overview page
823 700 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
824 701 * @return boolean true | false
825 702 */
826 -function wpbm_is_master_page( $server_param = 'REQUEST_URI' ) {
703 +function wpbm_is_master_page( $server_param = 'REQUEST_URI' ) {
827 704
828 - if ( ( is_admin() ) &&
829 - ( strpos($_SERVER[ $server_param ],'page=oplugins') !== false ) &&
830 - ( strpos($_SERVER[ $server_param ],'tab=wpbm-') === false ) && // not the settings
831 - ( ( strpos($_SERVER[ $server_param ],'tab=wpbm') !== false ) // tab specified
832 - || ( strpos($_SERVER[ $server_param ],'tab=') === false ) ) // or tab not specified at all
705 + if ( ( is_admin() ) && isset($_SERVER[ $server_param ]) &&
706 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'page=oplugins') !== false ) && // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
707 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm-') === false ) && // not the settings // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
708 + ( ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm') !== false ) // tab specified // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
709 + || ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=') === false ) ) // or tab not specified at all // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
833 710 ) {
834 711 return true;
835 - }
712 + }
836 713 return false;
837 714 }
838 715
839 -/** Check if this item > Add item page
716 +/** Check if this item > Add item page
840 717 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
841 718 * @return boolean true | false
842 719 */
843 720 function wpbm_is_new_wpbm_page( $server_param = 'REQUEST_URI' ) {
844 721
845 - if ( ( is_admin() ) &&
846 - ( strpos($_SERVER[ $server_param ],'page=oplugins') !== false ) &&
847 - ( strpos($_SERVER[ $server_param ],'tab=wpbm-new') !== false )
722 + if ( ( is_admin() ) && isset($_SERVER[ $server_param ]) &&
723 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'page=oplugins') !== false ) && // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
724 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm-new') !== false ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
848 725 ) {
849 726 return true;
850 - }
727 + }
851 728 return false;
852 729 }
853 730
854 731
855 -/** Check if this item > Settings page
732 +/** Check if this item > Settings page
856 733 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
857 734 * @return boolean true | false
858 - */
735 + */
859 736 function wpbm_is_settings_page( $server_param = 'REQUEST_URI' ) {
860 737
861 - if ( ( is_admin() ) &&
862 - ( strpos($_SERVER[ $server_param ],'page=oplugins') !== false ) &&
863 - ( strpos($_SERVER[ $server_param ],'tab=wpbm-settings') !== false )
738 + if ( ( is_admin() ) && isset($_SERVER[ $server_param ]) &&
739 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'page=oplugins') !== false ) && // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
740 + ( strpos(sanitize_text_field( wp_unslash($_SERVER[ $server_param ])),'tab=wpbm-settings') !== false ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
864 741 ) {
865 742 return true;
866 - }
743 + }
867 744 return false;
868 745 }
869 746
870 747 // </editor-fold>
871 -
872 748
873 -// <editor-fold defaultstate="collapsed" desc=" A d m i n U I E l e m e n t s " >
749 +
750 +// <editor-fold defaultstate="collapsed" desc=" A d m i n U I E l e m e n t s " >
874 751 ////////////////////////////////////////////////////////////////////////////
875 752 // A d m i n U I E l e m e n t s
876 753 ////////////////////////////////////////////////////////////////////////////
877 754
878 755 /** Get Number of new items
879 - *
756 + *
880 757 * @return int
881 758 */
882 759 function wpbm_get_number_new_items(){
883 760 return 0;
@@ -884,9 +761,9 @@
884 761 }
885 762
886 763
887 764 /** Show Admin B A R .
888 - *
765 + *
889 766 * @global type $wp_admin_bar
890 767 * @return type
891 768 */
892 769 function wp_admin_bar_items_menu(){
@@ -913,9 +790,9 @@
913 790 $update_title = $title;
914 791
915 792
916 793 if ( $update_count > 0 ) {
917 - $update_count_title = "&nbsp;<span id='ab-updates' class='wpbm-count bk-update-count' >" . number_format_i18n($update_count) . "</span>" ; //id='wpbm-count'
794 + $update_count_title = "&nbsp;<span class='wpbm-count bk-update-count' style='background: #f0f0f1;color: #2c3338;display: inline;padding: 2px 5px;font-weight: 600;border-radius: 10px;'>" . number_format_i18n($update_count) . "</span>" ; //id='wpbm-count'
918 795 $update_title .= $update_count_title;
919 796 }
920 797
921 798 $link_items = wpbm_get_master_url();
@@ -974,33 +851,16 @@
974 851 // add_action( 'admin_bar_menu', 'wp_admin_bar_items_menu', 70 ); // Add Admin Bar
975 852
976 853
977 854 /** Show Rating link at footer */
978 -function wpbm_show_wpbm_footer(){
855 +function wpbm_show_wpbm_footer(){
979 856
980 - if ( ! wpbm_is_this_demo() ) {
857 + // Nothing here.
858 +}
859 +// </editor-fold>
981 860
982 - $message = sprintf( __( 'If you like %s please leave us a %s rating. A huge thank you in advance!', 'booking-manager')
983 - , '<strong>Booking Manager</strong>' . ' ' . WPBM_VERSION_NUM
984 - , '<a href="https://wordpress.org/support/plugin/booking-manager/reviews/#new-post" target="_blank" title="' . esc_attr__( 'Thanks :)', 'booking-manager') . '">'
985 - . '&#9733;&#9733;&#9733;&#9733;&#9733;'
986 - . '</a>'
987 - );
988 861
989 - echo '<div id="wpbm-footer" style="position:absolute;bottom:40px;text-align:left;width:95%;font-size:0.9em;text-shadow:0 1px 0 #fff;margin:0;color:#888;">' . $message . '</div>';
990 - ?>
991 - <script type="text/javascript">
992 - jQuery(document).ready(function(){
993 - jQuery('#wpfooter').append( jQuery('#wpbm-footer') );
994 - });
995 - </script>
996 - <?php
997 - }
998 -}
999 -// </editor-fold>
1000 -
1001 -
1002 -// <editor-fold defaultstate="collapsed" desc=" DB - cheking if table, field or index exists " >
862 +// <editor-fold defaultstate="collapsed" desc=" DB - cheking if table, field or index exists " >
1003 863 ////////////////////////////////////////////////////////////////////////////
1004 864 // DB - cheking if table, field or index exists
1005 865 ////////////////////////////////////////////////////////////////////////////
1006 866
@@ -1005,9 +865,9 @@
1005 865 ////////////////////////////////////////////////////////////////////////////
1006 866
1007 867 /**
1008 868 * Check if table exist
1009 - *
869 + *
1010 870 * @global type $wpdb
1011 871 * @param string $tablename
1012 872 * @return 0|1
1013 873 */
@@ -1014,31 +874,23 @@
1014 874 function wpbm_is_table_exists( $tablename ) {
1015 875
1016 876 global $wpdb;
1017 877
1018 - if ( (! empty($wpdb->prefix) ) && ( strpos($tablename, $wpdb->prefix) === false ) )
1019 - $tablename = $wpdb->prefix . $tablename ;
878 + if ( ( ! empty( $wpdb->prefix ) ) && ( strpos( $tablename, $wpdb->prefix ) === false ) ) {
879 + $tablename = $wpdb->prefix . $tablename;
880 + }
1020 881
1021 - $sql_check_table = $wpdb->prepare("SHOW TABLES LIKE %s" , $tablename ); //FixIn 5.4.3
1022 882
1023 - $res = $wpdb->get_results( $sql_check_table );
1024 883
1025 - return count($res); //FixIn 5.4.3
1026 - /*
1027 - $sql_check_table = $wpdb->prepare("
1028 - SELECT COUNT(*) AS count
1029 - FROM information_schema.tables
1030 - WHERE table_schema = '". DB_NAME ."'
1031 - AND table_name = %s " , $tablename );
884 + $res = $wpdb->get_results( $wpdb->prepare( "SHOW TABLES LIKE %s", $tablename ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1032 885
1033 - $res = $wpdb->get_results( $sql_check_table );
1034 - return $res[0]->count;*/
886 + return count( $res ); //FixIn 5.4.3.
1035 887 }
1036 888
1037 889
1038 890 /**
1039 891 * Check if table exist
1040 - *
892 + *
1041 893 * @global type $wpdb
1042 894 * @param string $tablename
1043 895 * @param type $fieldname
1044 896 * @return 0|1
@@ -1047,9 +899,9 @@
1047 899 global $wpdb;
1048 900 if ( (! empty($wpdb->prefix) ) && ( strpos($tablename, $wpdb->prefix) === false ) ) $tablename = $wpdb->prefix . $tablename ;
1049 901 $sql_check_table = "SHOW COLUMNS FROM {$tablename}" ;
1050 902
1051 - $res = $wpdb->get_results( $sql_check_table );
903 + $res = $wpdb->get_results( $sql_check_table ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1052 904
1053 905 foreach ($res as $fld) {
1054 906 if ($fld->Field == $fieldname) return 1;
1055 907 }
@@ -1059,9 +911,9 @@
1059 911
1060 912
1061 913 /**
1062 914 * Check if index exist
1063 - *
915 + *
1064 916 * @global type $wpdb
1065 917 * @param string $tablename
1066 918 * @param type $fieldindex
1067 919 * @return 0|1
@@ -1068,24 +920,24 @@
1068 920 */
1069 921 function wpbm_is_index_in_table_exists( $tablename , $fieldindex) {
1070 922 global $wpdb;
1071 923 if ( (! empty($wpdb->prefix) ) && ( strpos($tablename, $wpdb->prefix) === false ) ) $tablename = $wpdb->prefix . $tablename ;
1072 - $sql_check_table = $wpdb->prepare("SHOW INDEX FROM {$tablename} WHERE Key_name = %s", $fieldindex );
1073 - $res = $wpdb->get_results( $sql_check_table );
924 +
925 + $res = $wpdb->get_results( $wpdb->prepare("SHOW INDEX FROM {$tablename} WHERE Key_name = %s", $fieldindex ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared
1074 926 if (count($res)>0) return 1;
1075 927 else return 0;
1076 928 }
1077 929
1078 930 // </editor-fold>
1079 -
1080 -
1081 -// <editor-fold defaultstate="collapsed" desc=" E s c a p i n g " >
931 +
932 +
933 +// <editor-fold defaultstate="collapsed" desc=" E s c a p i n g " >
1082 934 ////////////////////////////////////////////////////////////////////////////
1083 935 // E s c a p i n g
1084 936 ////////////////////////////////////////////////////////////////////////////
1085 937
1086 938 /** Transform the REQESTS parameters (GET and POST) into URL
1087 - *
939 + *
1088 940 * @param type $page_param
1089 941 * @param array $exclude_params
1090 942 * @param type $only_these_parameters
1091 943 * @return type
@@ -1093,25 +945,25 @@
1093 945 function wpbm_get_params_in_url( $page_param , $exclude_params = array(), $only_these_parameters = false, $is_escape_url = false, $only_get = false ){
1094 946
1095 947 $exclude_params[] = 'page';
1096 948
1097 - if ( isset( $_GET['page'] ) )
1098 - $page_param = $_GET['page'];
949 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
950 + if ( isset( $_GET['page'] ) ) { $page_param = $_GET['page']; }
1099 951
1100 952 $get_paramaters = array( 'page' => $page_param );
1101 953
1102 954 if ( $only_get )
1103 - $check_params = $_GET;
1104 - else
1105 - $check_params = $_REQUEST;
1106 -//debuge($check_params);
955 + $check_params = $_GET; // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
956 + else
957 + $check_params = $_REQUEST; // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
958 +//debuge($check_params);
1107 959 foreach ( $check_params as $prm_key => $prm_value ) {
1108 960
1109 961 // Skip parameters arrays, like $_GET['rvaluation_to'] = Array ( [0] => 6, [1] => 14, [2] => 14 )
1110 - if (
1111 - ( is_string( $prm_value ) )
1112 - || ( is_numeric( $prm_value ) )
1113 - ) {
962 + if (
963 + ( is_string( $prm_value ) )
964 + || ( is_numeric( $prm_value ) )
965 + ) {
1114 966
1115 967 if ( strlen( $prm_value ) > 1000 ) { // Check about TOOO long parameters, if it exist then reset it.
1116 968 $prm_value = '';
1117 969 }
@@ -1120,9 +972,9 @@
1120 972 if ( ( $only_these_parameters === false ) || ( in_array( $prm_key, $only_these_parameters ) ) )
1121 973 $get_paramaters[ $prm_key ] = $prm_value;
1122 974 }
1123 975 }
1124 -//debuge($check_params, $get_paramaters, $exclude_params );
976 +//debuge($check_params, $get_paramaters, $exclude_params );
1125 977 $url = admin_url( add_query_arg( $get_paramaters , 'admin.php' ) );
1126 978
1127 979 if ( $is_escape_url )
1128 980 $url = esc_url( $url );
@@ -1131,9 +983,9 @@
1131 983
1132 984 /* // Old variant:
1133 985 if ( isset( $_GET['page'] ) ) $page_param = $_GET['page'];
1134 986
1135 - $url_start = 'admin.php?page=' . $page_param . '&';
987 + $url_start = 'admin.php?page=' . $page_param . '&';
1136 988 $exclude_params[] = 'page';
1137 989 foreach ( $_REQUEST as $prm_key => $prm_value ) {
1138 990
1139 991 if ( !in_array( $prm_key, $exclude_params ) )
@@ -1144,18 +996,18 @@
1144 996 }
1145 997 $url_start = substr( $url_start, 0, -1 );
1146 998
1147 999 return $url_start;
1148 - */
1000 + */
1149 1001 }
1150 1002
1151 1003
1152 1004 /** Clean Request Parameters
1153 - *
1005 + *
1154 1006 */
1155 -function wpbm_check_request_paramters() {
1007 +function wpbm_check_request_paramters() {
1156 1008
1157 - $clean_params = array();
1009 + $clean_params = array();
1158 1010
1159 1011 $clean_params[ 'wh_wpbm_id' ] = 'digit_or_csd'; // '0' | '1' | ''
1160 1012 $clean_params[ 'wh_wpbm_date' ] = 'digit_or_date'; // number | date 2016-07-20
1161 1013 $clean_params[ 'wh_wpbm_datenext' ] = 'd'; // '1' | '2' ....
@@ -1166,13 +1018,13 @@
1166 1018
1167 1019 // elements only listed in array::
1168 1020 if ( is_array( $clean_type ) ) { // check only values from the list in this array
1169 1021
1170 - if ( ( isset( $_REQUEST[ $request_key ] ) ) && ( ! in_array( $_REQUEST[ $request_key ], $clean_type ) ) )
1171 - $clean_type = 's';
1172 - else
1022 + if ( ( isset( $_REQUEST[ $request_key ] ) ) && ( ! in_array( $_REQUEST[ $request_key ], $clean_type ) ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1023 + $clean_type = 's';
1024 + else
1173 1025 $clean_type = 'checked_skip_it';
1174 - }
1026 + }
1175 1027
1176 1028 switch ( $clean_type ) {
1177 1029
1178 1030 case 'checked_skip_it':
@@ -1179,36 +1031,34 @@
1179 1031
1180 1032 break;
1181 1033
1182 1034 case 'digit_or_date': // digit or comma separated digit
1183 - if ( isset( $_REQUEST[ $request_key ] ) )
1184 - $_REQUEST[ $request_key ] = wpbm_clean_digit_or_date( $_REQUEST[ $request_key ] ); // nums
1035 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1036 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = wpbm_clean_digit_or_date( $_REQUEST[ $request_key ] ); } // nums
1185 1037
1186 1038 break;
1187 1039
1188 1040 case 'digit_or_csd': // digit or comma separated digit
1189 - if ( isset( $_REQUEST[ $request_key ] ) )
1190 - $_REQUEST[ $request_key ] = wpbm_clean_digit_or_csd( $_REQUEST[ $request_key ] ); // nums
1041 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1042 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = wpbm_clean_digit_or_csd( $_REQUEST[ $request_key ] ); } // nums
1191 1043
1192 1044 break;
1193 1045
1194 1046 case 's': // string
1195 - if ( isset( $_REQUEST[ $request_key ] ) )
1196 - $_REQUEST[ $request_key ] = wpbm_clean_like_string_for_db( $_REQUEST[ $request_key ] );
1047 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1048 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = wpbm_clean_like_string_for_db( $_REQUEST[ $request_key ] ); }
1197 1049
1198 1050 break;
1199 1051
1200 1052 case 'd': // digit
1201 - if ( isset( $_REQUEST[ $request_key ] ) )
1202 - if ( $_REQUEST[ $request_key ] !== '' )
1203 - $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] );
1053 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1054 + if (( isset( $_REQUEST[ $request_key ] ) ) && ( $_REQUEST[ $request_key ] !== '' )) { $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] ); }
1204 1055
1205 1056 break;
1206 1057
1207 1058 default:
1208 - if ( isset( $_REQUEST[ $request_key ] ) ) {
1209 - $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] );
1210 - }
1059 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1060 + if ( isset( $_REQUEST[ $request_key ] ) ) { $_REQUEST[ $request_key ] = intval( $_REQUEST[ $request_key ] ); }
1211 1061 break;
1212 1062 }
1213 1063
1214 1064
@@ -1215,15 +1065,15 @@
1215 1065 }
1216 1066
1217 1067 }
1218 1068
1219 -
1069 +
1220 1070 /** Check paramter if it number or comma separated list of numbers
1221 - *
1071 + *
1222 1072 * @global type $wpdb
1223 1073 * @param string $value
1224 1074 * @return string
1225 - *
1075 + *
1226 1076 * Exmaple:
1227 1077 wpbm_clean_digit_or_csd( '12,a,45,9' ) => '12,0,45,9'
1228 1078 * or
1229 1079 wpbm_clean_digit_or_csd( '10a' ) => '10
@@ -1229,9 +1079,9 @@
1229 1079 wpbm_clean_digit_or_csd( '10a' ) => '10
1230 1080 * or
1231 1081 wpbm_clean_digit_or_csd( array( '12,a,45,9', '10a' ) ) => array ( '12,0,45,9', '10' )
1232 1082 */
1233 -function wpbm_clean_digit_or_csd( $value ) { //FixIn:6.2.1.4
1083 +function wpbm_clean_digit_or_csd( $value ) { //FixIn:6.2.1.4
1234 1084
1235 1085 if ( $value === '' ) return $value;
1236 1086
1237 1087
@@ -1236,9 +1086,9 @@
1236 1086
1237 1087
1238 1088 if ( is_array( $value ) ) {
1239 1089 foreach ( $value as $key => $check_value ) {
1240 - $value[ $key ] = wpbm_clean_digit_or_csd( $check_value );
1090 + $value[ $key ] = wpbm_clean_digit_or_csd( $check_value );
1241 1091 }
1242 1092 return $value;
1243 1093 }
1244 1094
@@ -1255,12 +1105,12 @@
1255 1105 }
1256 1106 $result = implode(',', $result );
1257 1107 return $result;
1258 1108 }
1259 -
1260 -
1109 +
1110 +
1261 1111 /** Cehck about Valid date, like 2016-07-20 or digit
1262 - *
1112 + *
1263 1113 * @param string $value
1264 1114 * @return string or int
1265 1115 */
1266 1116 function wpbm_clean_digit_or_date( $value ) { //FixIn:6.2.1.4
@@ -1274,12 +1124,12 @@
1274 1124 return intval( $value );
1275 1125 }
1276 1126
1277 1127 }
1278 -
1279 1128
1129 +
1280 1130 /** Check $value for injection here
1281 - *
1131 + *
1282 1132 * @param type $value
1283 1133 * @return type
1284 1134 */
1285 1135 function wpbm_clean_parameter( $value ) {
@@ -1284,16 +1134,16 @@
1284 1134 */
1285 1135 function wpbm_clean_parameter( $value ) {
1286 1136
1287 1137 $value = preg_replace( '/<[^>]*>/', '', $value ); // clean any tags
1288 - $value = str_replace( '<', ' ', $value );
1289 - $value = str_replace( '>', ' ', $value );
1290 - $value = strip_tags( $value );
1138 + $value = str_replace( '<', ' ', $value );
1139 + $value = str_replace( '>', ' ', $value );
1140 + $value = wp_strip_all_tags( $value );
1291 1141
1292 - // Clean SQL injection
1142 + // Clean SQL injection
1293 1143 $value = esc_sql( $value );
1294 1144
1295 - return $value;
1145 + return $value;
1296 1146 }
1297 1147
1298 1148
1299 1149 function wpbm_esc_like( $value_trimmed ) {
@@ -1306,14 +1156,14 @@
1306 1156 }
1307 1157
1308 1158
1309 1159 /** Clean user string for using in SQL LIKE statement - append to LIKE sql
1310 - *
1160 + *
1311 1161 * @param string $value - to clean
1312 1162 * @return string - escaped
1313 - * Exmaple:
1163 + * Exmaple:
1314 1164 * $search_escaped_like_title = wpbm_clean_like_string_for_append_in_sql_for_db( $input_var );
1315 - *
1165 + *
1316 1166 * $where_sql = " WHERE title LIKE ". $search_escaped_like_title ." ";
1317 1167 */
1318 1168 function wpbm_clean_like_string_for_append_in_sql_for_db( $value ) {
1319 1169 global $wpdb;
@@ -1318,13 +1168,13 @@
1318 1168 function wpbm_clean_like_string_for_append_in_sql_for_db( $value ) {
1319 1169 global $wpdb;
1320 1170
1321 1171 $value_trimmed = trim( stripslashes( $value ) );
1322 -$wild = '%';
1323 -$like = $wild . wpbm_esc_like( $value_trimmed ) . $wild;
1324 -$sql = $wpdb->prepare( "'%s'", $like );
1172 + $wild = '%';
1173 + $like = $wild . wpbm_esc_like( $value_trimmed ) . $wild;
1174 + $sql = $wpdb->prepare( "'%s'", $like ); // phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.QuotedSimplePlaceholder
1325 1175
1326 - return $sql;
1176 + return $sql;
1327 1177
1328 1178
1329 1179 /* Help:
1330 1180 * First half of escaping for LIKE special characters % and _ before preparing for MySQL.
@@ -1339,22 +1189,22 @@
1339 1189 *
1340 1190 * Example Escape Chain:
1341 1191 *
1342 1192 * $sql = esc_sql( wpbm_esc_like( $input ) );
1343 - */
1193 + */
1344 1194
1345 1195 }
1346 1196
1347 1197
1348 -/** Clean string for using in SQL LIKE requests inside single quotes: WHERE title LIKE '%". $escaped_search_title ."%'
1198 +/** Clean string for using in SQL LIKE requests inside single quotes: WHERE title LIKE '%". $escaped_search_title ."%'
1349 1199 * Replaced _ to \_ % to \% \ to \\
1350 1200 * @param string $value - to clean
1351 1201 * @return string - escaped
1352 - * Exmaple:
1202 + * Exmaple:
1353 1203 * $search_escaped_like_title = wpbm_clean_like_string_for_db( $input_var );
1354 - *
1204 + *
1355 1205 * $where_sql = " WHERE title LIKE '%". $search_escaped_like_title ."%' ";
1356 - *
1206 + *
1357 1207 * Important! Use SINGLE quotes after in SQL query: LIKE '%".$data."%'
1358 1208 */
1359 1209 function wpbm_clean_like_string_for_db( $value ){
1360 1210
@@ -1363,9 +1213,9 @@
1363 1213 $value_trimmed = trim( stripslashes( $value ) );
1364 1214
1365 1215 $value_trimmed = wpbm_esc_like( $value_trimmed );
1366 1216
1367 - $value = trim( $wpdb->prepare( "'%s'", $value_trimmed ) , "'" );
1217 + $value = trim( $wpdb->prepare( "'%s'", $value_trimmed ) , "'" ); // phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.QuotedSimplePlaceholder
1368 1218
1369 1219 return $value;
1370 1220
1371 1221 /* Help:
@@ -1381,26 +1231,26 @@
1381 1231 *
1382 1232 * Example Escape Chain:
1383 1233 *
1384 1234 * $sql = esc_sql( wpbm_esc_like( $input ) );
1385 - */
1235 + */
1386 1236 }
1387 1237
1388 1238
1389 1239 /** Escape string from SQL for the HTML form field
1390 - *
1240 + *
1391 1241 * @param string $value
1392 1242 * @return string
1393 - *
1243 + *
1394 1244 * Used: esc_sql function.
1395 - *
1396 - * https://codex.wordpress.org/Function_Reference/esc_sql
1397 - * Note: Be careful to use this function correctly. It will only escape values to be used in strings in the query.
1398 - * That is, it only provides escaping for values that will be within quotes in the SQL (as in field = '{$escaped_value}').
1399 - * If your value is not going to be within quotes, your code will still be vulnerable to SQL injection.
1400 - * For example, this is vulnerable, because the escaped value is not surrounded by quotes in the SQL query:
1401 - * ORDER BY {$escaped_value}. As such, this function does not escape unquoted numeric values, field names, or SQL keywords.
1402 - *
1245 + *
1246 + * https://codex.wordpress.org/Function_Reference/esc_sql
1247 + * Note: Be careful to use this function correctly. It will only escape values to be used in strings in the query.
1248 + * That is, it only provides escaping for values that will be within quotes in the SQL (as in field = '{$escaped_value}').
1249 + * If your value is not going to be within quotes, your code will still be vulnerable to SQL injection.
1250 + * For example, this is vulnerable, because the escaped value is not surrounded by quotes in the SQL query:
1251 + * ORDER BY {$escaped_value}. As such, this function does not escape unquoted numeric values, field names, or SQL keywords.
1252 + *
1403 1253 */
1404 1254 function wpbm_clean_string_for_form( $value ){
1405 1255
1406 1256 global $wpdb;
@@ -1417,16 +1267,16 @@
1417 1267
1418 1268 }
1419 1269 // </editor-fold>
1420 1270
1421 -
1422 -// <editor-fold defaultstate="collapsed" desc=" U s e r s " >
1271 +
1272 +// <editor-fold defaultstate="collapsed" desc=" U s e r s " >
1423 1273 ////////////////////////////////////////////////////////////////////////////////
1424 1274 // U s e r s
1425 1275 ////////////////////////////////////////////////////////////////////////////////
1426 1276
1427 1277 /** Get ID of active user
1428 - *
1278 + *
1429 1279 * @return type
1430 1280 */
1431 1281 function get_wpbm_current_user_id() {
1432 1282 $user = wp_get_current_user();
@@ -1433,11 +1283,35 @@
1433 1283 return ( isset( $user->ID ) ? (int) $user->ID : 0 );
1434 1284 }
1435 1285
1436 1286
1287 +/**
1288 + * Resolve a requested per-user settings target to the current user.
1289 + *
1290 + * Booking Manager's established AJAX payloads include a user ID. The value is
1291 + * retained for request compatibility, but it must never authorize a write to
1292 + * another user's preferences.
1293 + *
1294 + * @param mixed $requested_user_id User ID supplied by the request.
1295 + *
1296 + * @return int Current user ID when the request target matches; otherwise 0.
1297 + */
1298 +function wpbm_get_authorized_user_option_target_id( $requested_user_id ) {
1299 + $current_user_id = get_wpbm_current_user_id();
1300 +
1301 + if ( 0 === $current_user_id || ! is_scalar( $requested_user_id ) ) {
1302 + return 0;
1303 + }
1304 +
1305 + $requested_user_id = absint( wp_unslash( (string) $requested_user_id ) );
1306 +
1307 + return ( $current_user_id === $requested_user_id ) ? $current_user_id : 0;
1308 +}
1309 +
1310 +
1437 1311 /** Check if Current User have specific Role
1438 - *
1439 - * @return bool Whether the current user has the given capability.
1312 + *
1313 + * @return bool Whether the current user has the given capability.
1440 1314 */
1441 1315 function wpbm_is_current_user_have_this_role( $user_role ) {
1442 1316
1443 1317 if ( $user_role == 'administrator' ) $user_role = 'activate_plugins';
@@ -1450,64 +1324,44 @@
1450 1324 }
1451 1325
1452 1326
1453 1327 function wpbm_get_user_ip() {
1454 -//return '84.243.195.114' ; // Test //90.36.89.174
1455 - if (isset($_SERVER['HTTP_CLIENT_IP'])) {
1456 - $userIP = $_SERVER['HTTP_CLIENT_IP'] ;
1457 - } elseif (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
1458 - $userIP = $_SERVER['HTTP_X_FORWARDED_FOR'] ;
1459 - } elseif (isset($_SERVER['HTTP_X_FORWARDED'])) {
1460 - $userIP = $_SERVER['HTTP_X_FORWARDED'] ;
1461 - } elseif (isset($_SERVER['HTTP_FORWARDED_FOR'])) {
1462 - $userIP = $_SERVER['HTTP_FORWARDED_FOR'] ;
1463 - } elseif (isset($_SERVER['HTTP_FORWARDED'])) {
1464 - $userIP = $_SERVER['HTTP_FORWARDED'] ;
1465 - } elseif (isset($_SERVER['REMOTE_ADDR'])) {
1466 - $userIP = $_SERVER['REMOTE_ADDR'] ;
1467 - } else {
1468 - $userIP = "" ;
1469 - }
1470 -
1471 - $userIP = explode( ',', $userIP );
1472 - $userIP = array_map( 'trim', $userIP );
1473 -
1474 - return $userIP[0] ;
1328 + return '---';
1475 1329 }
1476 1330 add_wpbm_filter( 'wpbm_get_user_ip', 'wpbm_get_user_ip' );
1477 1331 // </editor-fold>
1478 1332
1479 1333
1480 -// <editor-fold defaultstate="collapsed" desc=" Mesages for Admin panel " >
1481 -////////////////////////////////////////////////////////////////////////////////
1482 -// Mesages for Admin panel
1483 -////////////////////////////////////////////////////////////////////////////////
1334 +// <editor-fold defaultstate="collapsed" desc=" Mesages for Admin panel " >
1335 +////////////////////////////////////////////////////////////////////////////////
1336 +// Mesages for Admin panel
1337 +////////////////////////////////////////////////////////////////////////////////
1484 1338
1485 1339 function wpbm_show_fixed_message( $message, $time_to_show , $message_type = 'updated' , $notice_id = 0, $is_dismissible = false ) {
1486 1340
1487 1341 // Generate unique HTML ID for the message
1488 1342 if ( $notice_id == 0 )
1489 - $notice_id = intval( time() * rand(10, 100) );
1343 + $notice_id = intval( time() * wp_rand(10, 100) );
1490 1344
1491 1345 $notice_id = 'wpbm_system_notice_' . $notice_id;
1492 1346
1493 1347 $is_dismissible = false;
1494 1348
1495 - if (
1349 + if (
1496 1350 ( ( $is_dismissible ) && ( ! wpbm_section_is_dismissed( $notice_id ) ) )
1497 1351 || ( ! $is_dismissible )
1498 - // || true
1352 + // || true
1499 1353 ){
1500 1354
1501 - ?><div id="<?php echo $notice_id; ?>"
1502 - class="wpbm_system_notice wpbm_is_dismissible wpbm_is_hideable <?php echo $message_type; ?>"
1503 - data-nonce="<?php echo wp_create_nonce( $nonce_name = $notice_id . '_wpbmnonce' ); ?>"
1504 - data-user-id="<?php echo get_current_user_id(); ?>"
1505 - ><?php
1355 + ?><div id="<?php echo esc_attr($notice_id); ?>"
1356 + class="wpbm_system_notice wpbm_is_dismissible wpbm_is_hideable <?php echo esc_attr( $message_type ); ?>"
1357 + data-nonce="<?php echo esc_attr(wp_create_nonce( $nonce_name = $notice_id . '_wpbmnonce' )); ?>"
1358 + data-user-id="<?php echo esc_attr(get_current_user_id()); ?>"
1359 + ><?php
1506 1360
1507 1361 wpbm_x_dismiss_button();
1508 1362
1509 - echo $message;
1363 + echo wp_kses_post($message);
1510 1364
1511 1365 ?></div><?php
1512 1366
1513 1367 // Get the time of message showing
@@ -1512,19 +1366,19 @@
1512 1366
1513 1367 // Get the time of message showing
1514 1368 $time_to_show = intval( $time_to_show ) * 1000;
1515 1369
1516 - if ( $time_to_show > 0 ) {
1517 - ?> <script type="text/javascript">
1518 - jQuery('#<?php echo $notice_id; ?>').animate({opacity: 1},<?php echo $time_to_show; ?>).fadeOut( 2000 );
1370 + if ( $time_to_show > 0 ) {
1371 + ?> <script type="text/javascript">
1372 + jQuery('#<?php echo esc_attr($notice_id); ?>').animate({opacity: 1},<?php echo esc_attr( $time_to_show ); ?>).fadeOut( 2000 );
1519 1373 </script> <?php
1520 - }
1521 - }
1374 + }
1375 + }
1522 1376 }
1523 1377
1524 1378
1525 1379 /** Show Ajax message at the top of page
1526 - *
1380 + *
1527 1381 * @param type $message
1528 1382 * @param type $time_to_show
1529 1383 * @param type $is_error
1530 1384 */
@@ -1536,24 +1390,24 @@
1536 1390 // Escape any JavaScript from message
1537 1391 $notice = html_entity_decode( esc_js( $message ) ,ENT_QUOTES) ;
1538 1392
1539 1393 ?><script type="text/javascript">
1540 - var my_message = '<?php echo $notice; ?>';
1541 - wpbm_admin_show_message( my_message, '<?php echo ( $is_error ? 'error' : 'success' ); ?>', <?php echo $time_to_show; ?> );
1394 + var my_message = '<?php echo esc_js( $notice ); ?>';
1395 + wpbm_admin_show_message( my_message, '<?php echo ( $is_error ? 'error' : 'success' ); ?>', <?php echo esc_attr($time_to_show); ?> );
1542 1396 </script><?php
1543 1397 }
1544 1398
1545 1399
1546 1400 /** Show "Saved Changes" message at the top of settings page.
1547 - *
1548 - */
1401 + *
1402 + */
1549 1403 function wpbm_show_changes_saved_message() {
1550 1404 wpbm_show_message ( __('Changes saved.', 'booking-manager'), 5 );
1551 -}
1405 +}
1552 1406
1553 1407
1554 1408 /** Show Message at Top of Admin Pages
1555 - *
1409 + *
1556 1410 * @param type $message - mesage to show
1557 1411 * @param type $time_to_show - number of seconds to show, if 0 or skiped, then unlimited time.
1558 1412 * @param type $message_type - Default: updated { updated | error | notice }
1559 1413 */
@@ -1559,9 +1413,9 @@
1559 1413 */
1560 1414 function wpbm_show_message ( $message, $time_to_show , $message_type = 'updated') {
1561 1415
1562 1416 // Generate unique HTML ID for the message
1563 - $inner_message_id = intval( time() * rand(10, 100) );
1417 + $inner_message_id = intval( time() * wp_rand(10, 100) );
1564 1418
1565 1419 // Get formated HTML message
1566 1420 $notice = wpbm_get_formated_message( $message, $message_type, $inner_message_id );
1567 1421
@@ -1568,13 +1422,16 @@
1568 1422 // Get the time of message showing
1569 1423 $time_to_show = intval( $time_to_show ) * 1000;
1570 1424
1571 1425 // Show this Message
1572 - ?> <script type="text/javascript">
1426 + ?> <script type="text/javascript">
1573 1427 if ( jQuery('.wpbm_admin_message').length ) {
1574 - jQuery('.wpbm_admin_message').append( '<?php echo $notice; ?>' );
1428 + jQuery('.wpbm_admin_message').append( '<?php
1429 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1430 + echo ($notice);
1431 + ?>' );
1575 1432 <?php if ( $time_to_show > 0 ) { ?>
1576 - jQuery('#wpbm_inner_message_<?php echo $inner_message_id; ?>').animate({opacity: 1},<?php echo $time_to_show; ?>).fadeOut( 2000 );
1433 + jQuery('#wpbm_inner_message_<?php echo esc_attr($inner_message_id); ?>').animate({opacity: 1},<?php echo esc_attr($time_to_show); ?>).fadeOut( 2000 );
1577 1434 <?php } ?>
1578 1435 }
1579 1436 </script> <?php
1580 1437 }
@@ -1580,9 +1437,9 @@
1580 1437 }
1581 1438
1582 1439
1583 1440 /** Escape and prepare message to show it
1584 - *
1441 + *
1585 1442 * @param type $message - message
1586 1443 * @param type $message_type - Default: updated { updated | error | notice }
1587 1444 * @param string $inner_message_id - ID of message DIV, can be skipped
1588 1445 * @return string
@@ -1607,13 +1464,13 @@
1607 1464 }
1608 1465
1609 1466
1610 1467 /** Show system info in settings page
1611 - *
1612 - * @param string $message ...
1468 + *
1469 + * @param string $message ...
1613 1470 * @param string $message_type 'info' | 'warning' | 'error'
1614 1471 * @param string $title __('Important!' , 'booking-manager') | __('Note' , 'booking-manager')
1615 - *
1472 + *
1616 1473 * Exmaple: wpbm_show_message_in_settings( __( 'Nothing Found', 'booking-manager'), 'warning', __('Important!' , 'booking-manager') );
1617 1474 */
1618 1475 function wpbm_show_message_in_settings( $message, $message_type = 'info', $title = '' , $is_echo = true ) {
1619 1476
@@ -1632,9 +1489,9 @@
1632 1489
1633 1490 $message_content .= '<div class="clear"></div>';
1634 1491
1635 1492 if ( $is_echo )
1636 - echo $message_content;
1493 + echo wp_kses_post( $message_content );
1637 1494 else
1638 1495 return $message_content;
1639 1496
1640 1497 }
@@ -1640,36 +1497,39 @@
1640 1497 }
1641 1498 // </editor-fold>
1642 1499
1643 1500
1644 -// <editor-fold defaultstate="collapsed" desc=" Settings Meta Boxes " >
1645 -////////////////////////////////////////////////////////////////////////////////
1501 +// <editor-fold defaultstate="collapsed" desc=" Settings Meta Boxes " >
1502 +////////////////////////////////////////////////////////////////////////////////
1646 1503 // Settings Meta Boxes
1647 -////////////////////////////////////////////////////////////////////////////////
1504 +////////////////////////////////////////////////////////////////////////////////
1648 1505 function wpbm_open_meta_box_section( $metabox_id, $title ) {
1649 1506
1650 1507 $my_close_open_win_id = $metabox_id . '_metabox';
1651 - ?>
1652 - <div class='meta-box'>
1653 - <div
1654 - id="<?php echo $my_close_open_win_id; ?>"
1655 - class="postbox <?php if ( '1' == get_user_option( 'wpbm_win_' . $my_close_open_win_id ) ) echo 'closed'; ?>"
1656 - > <div title="<?php _e('Click to toggle', 'booking-manager'); ?>"
1657 - class="handlediv"
1658 - onclick="javascript:wpbm_verify_window_opening(<?php echo get_wpbm_current_user_id(); ?>, '<?php echo $my_close_open_win_id; ?>');"
1659 - ><br/></div>
1660 - <h3 class='hndle'>
1661 - <span><?php echo wp_kses_post( $title ); ?></span>
1662 - </h3>
1663 - <div class="inside">
1664 - <?php
1508 + //FixIn: 2.0.16.1
1509 + ?>
1510 + <div class='meta-box'>
1511 + <div
1512 + id="<?php echo esc_attr($my_close_open_win_id); ?>"
1513 + class="postbox <?php if ( '1' == get_user_option( 'wpbm_win_' . $my_close_open_win_id ) ) echo 'closed'; ?>"
1514 + ><div class="postbox-header" style="display: flex;flex-flow: row nowrap;border-bottom: 1px solid #ccd0d4;"><?php //FixIn: 8.7.8.1 ?>
1515 + <h3 class='hndle' style="flex: 1 1 auto;border: none;">
1516 + <span><?php echo wp_kses_post( $title ); ?></span>
1517 + </h3>
1518 + <div title="<?php echo esc_attr(__('Click to toggle','booking-manager')); ?>"
1519 + class="handlediv"
1520 + onclick="javascript:wpbm_verify_window_opening(<?php echo esc_attr( get_wpbm_current_user_id() ); ?>, '<?php echo esc_attr($my_close_open_win_id); ?>');"
1521 + ><br/></div>
1522 + </div>
1523 + <div class="inside">
1524 + <?php
1665 1525 }
1666 1526
1667 1527 function wpbm_close_meta_box_section() {
1668 1528 ?>
1669 - </div>
1670 - </div>
1671 - </div>
1529 + </div>
1530 + </div>
1531 + </div>
1672 1532 <?php
1673 1533 }
1674 1534 // </editor-fold>
1675 1535
@@ -1674,23 +1534,23 @@
1674 1534 // </editor-fold>
1675 1535
1676 1536
1677 1537 // from Toolbar
1678 -// <editor-fold defaultstate="collapsed" desc=" M o d a l s " >
1679 -////////////////////////////////////////////////////////////////////////////////
1538 +// <editor-fold defaultstate="collapsed" desc=" M o d a l s " >
1539 +////////////////////////////////////////////////////////////////////////////////
1680 1540 // M o d a l s
1681 1541 ////////////////////////////////////////////////////////////////////////////////
1682 1542
1683 -/** Start Loyouts - Modal Window structure */
1543 +/** Start Loyouts - Modal Window structure */
1684 1544 function wpbm_write_content_for_modals_start_here() {
1685 -
1545 +
1686 1546 ?><span id="wpbm_content_for_modals"></span><?php
1687 1547 }
1688 -add_wpbm_action( 'wpbm_write_content_for_modals', 'wpbm_write_content_for_modals_start_here');
1548 +add_wpbm_action( 'wpbm_write_content_for_modals', 'wpbm_write_content_for_modals_start_here');
1689 1549 // </editor-fold>
1690 1550
1691 1551
1692 -// <editor-fold defaultstate="collapsed" desc=" Inline JavaScript " >
1552 +// <editor-fold defaultstate="collapsed" desc=" Inline JavaScript " >
1693 1553 ////////////////////////////////////////////////////////////////////////////////
1694 1554 // Inline J a v a S c r i p t to Footer page
1695 1555 ////////////////////////////////////////////////////////////////////////////////
1696 1556 /**
@@ -1726,9 +1586,9 @@
1726 1586
1727 1587 $wpbm_queued_js = preg_replace( '/&#(x)?0*(?(1)27|39);?/i', "'", $wpbm_queued_js );
1728 1588 $wpbm_queued_js = str_replace( "\r", '', $wpbm_queued_js );
1729 1589
1730 - echo $wpbm_queued_js . "});\n</script>\n<!-- End WPBM JavaScript -->\n";
1590 + echo $wpbm_queued_js . "});\n</script>\n<!-- End WPBM JavaScript -->\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1731 1591
1732 1592 $wpbm_queued_js = '';
1733 1593 unset( $wpbm_queued_js );
1734 1594 }
@@ -1736,9 +1596,9 @@
1736 1596
1737 1597 // </editor-fold>
1738 1598
1739 1599 // from Toolbar
1740 -// <editor-fold defaultstate="collapsed" desc=" JS & CSS - Tooltips & Popover" >
1600 +// <editor-fold defaultstate="collapsed" desc=" JS & CSS - Tooltips & Popover" >
1741 1601 ////////////////////////////////////////////////////////////////////////////////
1742 1602 // JS & CSS
1743 1603 ////////////////////////////////////////////////////////////////////////////////
1744 1604
@@ -1743,15 +1603,15 @@
1743 1603 ////////////////////////////////////////////////////////////////////////////////
1744 1604
1745 1605 /** Load suport JavaScript for "Items" page*/
1746 1606 function wpbm_js_for_items_page() {
1747 -
1607 +
1748 1608 $is_use_hints = get_wpbm_option( 'wpbm_is_use_hints_at_admin_panel' );
1749 1609 if ( $is_use_hints == 'On' )
1750 1610 wpbm_bs_javascript_tooltips(); // JS Tooltips
1751 1611
1752 - wpbm_bs_javascript_popover(); // JS Popover
1753 -
1612 + wpbm_bs_javascript_popover(); // JS Popover
1613 +
1754 1614 //wpbm_datepicker_js(); // JS Datepicker
1755 1615 wpbm_datepicker_css(); // CSS DatePicker
1756 1616 }
1757 1617
@@ -1757,14 +1617,14 @@
1757 1617
1758 1618
1759 1619 /** Datepicker activation JavaScript */
1760 1620 function wpbm_datepicker_js() {
1761 -
1621 +
1762 1622 ?><script type="text/javascript">
1763 1623 jQuery(document).ready( function(){
1764 1624
1765 1625 function applyCSStoDays( date ){
1766 - return [true, 'date_available'];
1626 + return [true, 'date_available'];
1767 1627 }
1768 1628 jQuery('input.wpbm-filters-section-calendar').datepick(
1769 1629 { beforeShowDay: applyCSStoDays,
1770 1630 showOn: 'focus',
@@ -1775,9 +1635,9 @@
1775 1635 nextText: '&raquo;',
1776 1636 dateFormat: 'yy-mm-dd',
1777 1637 changeMonth: false,
1778 1638 changeYear: false,
1779 - minDate: null,
1639 + minDate: null,
1780 1640 maxDate: null, //'1Y',
1781 1641 showStatus: false,
1782 1642 multiSeparator: ', ',
1783 1643 closeAtTop: false,
@@ -1788,9 +1648,9 @@
1788 1648 mandatory: true
1789 1649 }
1790 1650 );
1791 1651 });
1792 - </script><?php
1652 + </script><?php
1793 1653 }
1794 1654
1795 1655
1796 1656 /** Support CSS - datepick, etc... */
@@ -1826,16 +1686,16 @@
1826 1686 height: auto;
1827 1687 }
1828 1688 </style>
1829 1689 <?php
1830 -}
1690 +}
1831 1691
1832 1692
1833 1693 /** Sortable Table JavaScript */
1834 1694 function wpbm_sortable_js() {
1835 1695 ?>
1836 - <script type="text/javascript">
1837 - // Activate Sortable Functionality
1696 + <script type="text/javascript">
1697 + // Activate Sortable Functionality
1838 1698 jQuery( document ).ready(function(){
1839 1699
1840 1700 jQuery('.wpbm_input_table tbody th').css('cursor','move');
1841 1701
@@ -1859,20 +1719,20 @@
1859 1719 });
1860 1720 });
1861 1721 </script>
1862 1722 <?php
1863 -
1723 +
1864 1724 }
1865 1725 // </editor-fold>
1866 1726
1867 1727
1868 -// <editor-fold defaultstate="collapsed" desc=" R e l o a d p a g e " >
1728 +// <editor-fold defaultstate="collapsed" desc=" R e l o a d p a g e " >
1869 1729 ////////////////////////////////////////////////////////////////////////////////
1870 1730 // R e l o a d p a g e
1871 1731 ////////////////////////////////////////////////////////////////////////////////
1872 1732 /**
1873 1733 * Reload page by using JavaScript
1874 - *
1734 + *
1875 1735 * @param string $url - URL of page to load
1876 1736 */
1877 1737 function wpbm_reload_page_by_js( $url ) {
1878 1738
@@ -1879,10 +1739,10 @@
1879 1739 $redir = html_entity_decode( esc_url( $url ) );
1880 1740
1881 1741 if ( ! empty( $redir ) ) {
1882 1742 ?>
1883 - <script type="text/javascript">
1884 - window.location.href = '<?php echo $redir ?>';
1743 + <script type="text/javascript">
1744 + window.location.href = '<?php echo esc_url($redir); ?>';
1885 1745 </script>
1886 1746 <?php
1887 1747 }
1888 1748 }
@@ -1888,9 +1748,9 @@
1888 1748 }
1889 1749
1890 1750
1891 1751 /** Redirect browser to a specific page
1892 - *
1752 + *
1893 1753 * @param string $url - URL of page to redirect
1894 1754 */
1895 1755 function wpbm_redirect( $url ) {
1896 1756
@@ -1898,20 +1758,20 @@
1898 1758
1899 1759 $url = html_entity_decode( esc_url( $url ) );
1900 1760
1901 1761 echo '<script type="text/javascript">';
1902 - echo 'window.location.href="'.$url.'";';
1762 + echo 'window.location.href="'.esc_url($url).'";';
1903 1763 echo '</script>';
1904 1764 echo '<noscript>';
1905 - echo '<meta http-equiv="refresh" content="0;url='.$url.'" />';
1765 + echo '<meta http-equiv="refresh" content="0;url='.esc_url($url).'" />';
1906 1766 echo '</noscript>';
1907 1767 }
1908 1768 // </editor-fold>
1909 1769
1910 1770
1911 -// <editor-fold defaultstate="collapsed" desc=" P a g i n a t i o n o f T a b l e L i s t i n g " >
1771 +// <editor-fold defaultstate="collapsed" desc=" P a g i n a t i o n o f T a b l e L i s t i n g " >
1912 1772 /** Show P a g i n a t i o n
1913 - *
1773 + *
1914 1774 * @param int $summ_number_of_items - total number of items
1915 1775 * @param int $active_page_num - number of activated page
1916 1776 * @param int $num_items_per_page - number of items per page
1917 1777 * @param array $only_these_parameters - array of keys to exclude from links
@@ -1927,11 +1787,10 @@
1927 1787 if ( $pages_number < 2 )
1928 1788 return;
1929 1789
1930 1790 //Fix: 5.1.4 - Just in case we are having tooo much resources, then we need to show all resources - and its empty string
1931 - if ( ( isset($_REQUEST['wh_wpbm_type'] ) ) && ( strlen($_REQUEST['wh_wpbm_type']) > 1000 ) ) {
1932 - $_REQUEST['wh_wpbm_type'] = '';
1933 - }
1791 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1792 + if ( ( isset($_REQUEST['wh_wpbm_type'] ) ) && ( strlen($_REQUEST['wh_wpbm_type']) > 1000 ) ) { $_REQUEST['wh_wpbm_type'] = ''; }
1934 1793
1935 1794 // First parameter will overwriten by $_GET['page'] parameter
1936 1795 $bk_admin_url = wpbm_get_params_in_url( wpbm_get_master_url( false ), array('page_num'), $only_these_parameters );
1937 1796
@@ -1937,9 +1796,9 @@
1937 1796
1938 1797
1939 1798 ?>
1940 1799 <span class="wpdevelop wpbm-pagination">
1941 - <div class="container-fluid">
1800 + <div class="container-fluid">
1942 1801 <div class="row">
1943 1802 <div class="col-sm-12 text-center control-group0">
1944 1803 <nav class="btn-toolbar">
1945 1804 <div class="btn-group wpbm-no-margin" style="float:none;">
@@ -1944,13 +1803,13 @@
1944 1803 <nav class="btn-toolbar">
1945 1804 <div class="btn-group wpbm-no-margin" style="float:none;">
1946 1805
1947 1806 <?php if ( $pages_number > 1 ) { ?>
1948 - <a class="button button-secondary <?php echo ( $active_page_num == 1 ) ? ' disabled' : ''; ?>"
1949 - href="<?php echo $bk_admin_url; ?>&page_num=<?php if ($active_page_num == 1) { echo $active_page_num; } else { echo ($active_page_num-1); } echo $url_sufix; ?>">
1950 - <?php _e('Prev', 'booking-manager'); ?>
1807 + <a class="button button-secondary <?php echo ( $active_page_num == 1 ) ? ' disabled' : ''; ?>"
1808 + href="<?php echo esc_url($bk_admin_url); ?>&page_num=<?php if ($active_page_num == 1) { echo esc_attr( $active_page_num ); } else { echo esc_attr($active_page_num-1); } echo esc_attr( $url_sufix ); ?>">
1809 + <?php esc_html_e('Prev', 'booking-manager'); ?>
1951 1810 </a>
1952 - <?php }
1811 + <?php }
1953 1812
1954 1813 /** Number visible pages (links) that linked to active page, other pages skipped by "..." */
1955 1814 $num_closed_steps = 3;
1956 1815
@@ -1955,23 +1814,23 @@
1955 1814 $num_closed_steps = 3;
1956 1815
1957 1816 for ( $pg_num = 1; $pg_num <= $pages_number; $pg_num++ ) {
1958 1817
1959 - if ( ! (
1960 - ( $pages_number > ( $num_closed_steps * 4) )
1961 - && ( $pg_num > $num_closed_steps )
1962 - && ( ( $pages_number - $pg_num + 1 ) > $num_closed_steps )
1963 - && ( abs( $active_page_num - $pg_num ) > $num_closed_steps )
1818 + if ( ! (
1819 + ( $pages_number > ( $num_closed_steps * 4) )
1820 + && ( $pg_num > $num_closed_steps )
1821 + && ( ( $pages_number - $pg_num + 1 ) > $num_closed_steps )
1822 + && ( abs( $active_page_num - $pg_num ) > $num_closed_steps )
1964 1823 ) ) {
1965 - ?> <a class="button button-secondary <?php if ($pg_num == $active_page_num ) echo ' active'; ?>"
1966 - href="<?php echo $bk_admin_url; ?>&page_num=<?php echo $pg_num; echo $url_sufix; ?>">
1967 - <?php echo $pg_num; ?>
1968 - </a><?php
1824 + ?> <a class="button button-secondary <?php if ($pg_num == $active_page_num ) echo ' active'; ?>"
1825 + href="<?php echo esc_attr( $bk_admin_url ); ?>&page_num=<?php echo esc_attr( $pg_num); echo esc_attr( $url_sufix); ?>">
1826 + <?php echo esc_html($pg_num); ?>
1827 + </a><?php
1969 1828
1970 - if ( ( $pages_number > ( $num_closed_steps * 4) )
1971 - && ( ($pg_num+1) > $num_closed_steps )
1972 - && ( ( $pages_number - ( $pg_num + 1 ) ) > $num_closed_steps )
1973 - && ( abs($active_page_num - ( $pg_num + 1 ) ) > $num_closed_steps )
1829 + if ( ( $pages_number > ( $num_closed_steps * 4) )
1830 + && ( ($pg_num+1) > $num_closed_steps )
1831 + && ( ( $pages_number - ( $pg_num + 1 ) ) > $num_closed_steps )
1832 + && ( abs($active_page_num - ( $pg_num + 1 ) ) > $num_closed_steps )
1974 1833 ) {
1975 1834 echo ' <a class="button button-secondary disabled" href="javascript:void(0);">...</a> ';
1976 1835 }
1977 1836 }
@@ -1977,11 +1836,11 @@
1977 1836 }
1978 1837 }
1979 1838
1980 1839 if ( $pages_number > 1 ) { ?>
1981 - <a class="button button-secondary <?php echo ( $active_page_num == $pages_number ) ? ' disabled' : ''; ?>"
1982 - href="<?php echo $bk_admin_url; ?>&page_num=<?php if ($active_page_num == $pages_number) { echo $active_page_num; } else { echo ($active_page_num+1); } echo $url_sufix; ?>">
1983 - <?php _e('Next', 'booking-manager'); ?>
1840 + <a class="button button-secondary <?php echo ( $active_page_num == $pages_number ) ? ' disabled' : ''; ?>"
1841 + href="<?php echo esc_attr( $bk_admin_url ); ?>&page_num=<?php if ($active_page_num == $pages_number) { echo esc_attr( $active_page_num); } else { echo esc_attr($active_page_num+1); } echo esc_attr( $url_sufix); ?>">
1842 + <?php esc_html_e('Next', 'booking-manager'); ?>
1984 1843 </a>
1985 1844 <?php } ?>
1986 1845
1987 1846 </div>
@@ -1994,9 +1853,9 @@
1994 1853 }
1995 1854 // </editor-fold>
1996 1855
1997 1856
1998 -// <editor-fold defaultstate="collapsed" desc=" D a t e s " >
1857 +// <editor-fold defaultstate="collapsed" desc=" D a t e s " >
1999 1858 ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
2000 1859 // Dates Format
2001 1860 ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
2002 1861
@@ -2001,9 +1860,9 @@
2001 1860 ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
2002 1861
2003 1862
2004 1863 /** Get Formated Date & time
2005 - *
1864 + *
2006 1865 * @param string $date_sql - 2017-07-31 00:00:00 || 2017-07-31
2007 1866 * @param string $date_format - Optional. - "m / d / Y, D H:i:s"
2008 1867 * @param string $seperator - Optional. - " "
2009 1868 * @return string - July 29, 2014 12:00 am
@@ -2008,21 +1867,21 @@
2008 1867 * @param string $seperator - Optional. - " "
2009 1868 * @return string - July 29, 2014 12:00 am
2010 1869 */
2011 1870 function wpbm_get_date_time_formatted( $date_sql, $date_format = false, $seperator = ' ', $skip_midnight_time = false ) {
2012 -
1871 +
2013 1872 $return_date = wpbm_get_date_formatted( $date_sql, $date_format );
2014 -
2015 - $return_time = wpbm_get_time_formatted( $date_sql, $date_format, $skip_midnight_time );
1873 +
1874 + $return_time = wpbm_get_time_formatted( $date_sql, $date_format, $skip_midnight_time );
2016 1875 if ( ! empty( $return_time ) )
2017 1876 $return_date .= $seperator . $return_time;
2018 -
1877 +
2019 1878 return $return_date;
2020 1879 }
2021 1880
2022 1881
2023 1882 /** Get Formated Date
2024 - *
1883 + *
2025 1884 * @param string $date_sql - 2017-07-31 00:00:00 || 2017-07-31
2026 1885 * @param string $date_format - Optional. - "m / d / Y, D"
2027 1886 * @param bool $skip_midnight_time - Default false - if 00:00:00 then return '';
2028 1887 * @return string - July 29, 2014
@@ -2030,17 +1889,17 @@
2030 1889 function wpbm_get_date_formatted( $date_sql, $date_format = false ) {
2031 1890
2032 1891 if ( $date_format === false ) $date_format = get_wpbm_option( 'wpbm_date_format' );
2033 1892 if ( empty( $date_format ) ) $date_format = "m / d / Y, D";
2034 -
1893 +
2035 1894 $formated_date = date_i18n( $date_format, strtotime( $date_sql ) );
2036 -
1895 +
2037 1896 return $formated_date;
2038 1897 }
2039 1898
2040 1899
2041 1900 /** Get Formated Date & time
2042 - *
1901 + *
2043 1902 * @param string $date_sql - 2017-07-31 00:00:00 || 2017-07-31
2044 1903 * @param string $time_format - Optional. - "H:i:s"
2045 1904 * @return string - 12:00 am
2046 1905 */
@@ -2047,20 +1906,20 @@
2047 1906 function wpbm_get_time_formatted( $date_sql, $time_format = false , $skip_midnight_time = false ) {
2048 1907
2049 1908 if ( ( $skip_midnight_time ) && ( '00:00:00' == substr( $date_sql, -8 ) ) )
2050 1909 return '';
2051 -
1910 +
2052 1911 if ( $time_format === false ) $time_format = get_wpbm_option( 'wpbm_time_format' );
2053 1912 if ( empty( $time_format ) ) $time_format = 'h:i a';
2054 -
1913 +
2055 1914 $formated_date = date_i18n( $time_format, strtotime( $date_sql ) );
2056 -
2057 - return $formated_date;
1915 +
1916 + return $formated_date;
2058 1917 }
2059 1918
2060 1919
2061 1920 /** Check if "current_day" is tomorrow from "next_day"
2062 - *
1921 + *
2063 1922 * @param string $current_day_sql_check : 2015-02-29 00:00:00
2064 1923 * @param string $next_day_sql_check : 2015-02-30 00:00:00
2065 1924 * @return boolean : true | false
2066 1925 */
@@ -2067,28 +1926,28 @@
2067 1926 function wpbm_is_next_day( $current_day_sql_check, $next_day_sql_check ) {
2068 1927
2069 1928 // Current day
2070 1929 $current_day_unix = strtotime( $current_day_sql_check );
2071 -
1930 +
2072 1931 $current_day_midnight_sql = date_i18n( 'Y-m-d', $current_day_unix );
2073 1932 $current_day_midnight_unix = strtotime( $current_day_midnight_sql );
2074 -
1933 +
2075 1934 $calc_next_day_unix = strtotime( '+1 day', $current_day_midnight_unix );
2076 -
1935 +
2077 1936 // Next day
2078 - $next_day_unix = strtotime( $next_day_sql_check );
1937 + $next_day_unix = strtotime( $next_day_sql_check );
2079 1938 $next_day_midnight_sql = date_i18n( 'Y-m-d', $next_day_unix );
2080 1939 $next_day_midnight_unix = strtotime( $next_day_midnight_sql );
2081 -
2082 -
2083 - if ( $calc_next_day_unix == $next_day_midnight_unix )
2084 - return true;
2085 - else
2086 - return false;
1940 +
1941 +
1942 + if ( $calc_next_day_unix == $next_day_midnight_unix )
1943 + return true;
1944 + else
1945 + return false;
2087 1946 }
2088 1947
2089 1948 /** Check if "current_day" is same day of "other_day"
2090 - *
1949 + *
2091 1950 * @param string $current_day_sql_check : 2015-02-29 00:00:00
2092 1951 * @param string $other_day_sql_check : 2015-02-30 00:00:00
2093 1952 * @return boolean : true | false
2094 1953 */
@@ -2095,27 +1954,27 @@
2095 1954 function wpbm_is_this_same_day( $current_day_sql_check, $other_day_sql_check ) {
2096 1955
2097 1956 // Current day
2098 1957 $current_day_unix = strtotime( $current_day_sql_check );
2099 -
1958 +
2100 1959 $current_day_midnight_sql = date_i18n( 'Y-m-d', $current_day_unix );
2101 1960 $current_day_midnight_unix = strtotime( $current_day_midnight_sql );
2102 -
1961 +
2103 1962 // Other day
2104 - $other_day_unix = strtotime( $other_day_sql_check );
1963 + $other_day_unix = strtotime( $other_day_sql_check );
2105 1964 $other_day_midnight_sql = date_i18n( 'Y-m-d', $other_day_unix );
2106 1965 $other_day_midnight_unix = strtotime( $other_day_midnight_sql );
2107 -
2108 -
2109 - if ( $current_day_midnight_unix == $other_day_midnight_unix )
2110 - return true;
2111 - else
2112 - return false;
1966 +
1967 +
1968 + if ( $current_day_midnight_unix == $other_day_midnight_unix )
1969 + return true;
1970 + else
1971 + return false;
2113 1972 }
2114 1973
2115 1974
2116 1975 /** Get days in short format view
2117 - *
1976 + *
2118 1977 * @param string $days Dates: 15.05.2015, 16.05.2015, 17.05.2015
2119 1978 * @return string Dates in format: 15.05.2015 - 17.05.2015
2120 1979 */
2121 1980 function wpbm_get_dates_short_format( $dates_sql_csv ) { // $days - string with comma seperated dates
@@ -2129,24 +1988,24 @@
2129 1988 $result_string = '';
2130 1989 $last_show_day = '';
2131 1990
2132 1991 foreach ( $days as $day ) {
2133 -
1992 +
2134 1993 $is_fin_at_end = false;
2135 -
1994 +
2136 1995 if ( $previosday === false ) { // First Day
2137 -
1996 +
2138 1997 $result_string = wpbm_get_date_time_formatted( $day, false, ' ', true ); // echo format for first day
2139 1998 $last_show_day = $day;
2140 1999 $previosday = $day; // Set previos day for next loop
2141 -
2000 +
2142 2001 } else { // Not first day
2143 -
2144 - if (
2145 - wpbm_is_next_day( $previosday, $day )
2146 - || wpbm_is_this_same_day( $previosday, $day )
2002 +
2003 + if (
2004 + wpbm_is_next_day( $previosday, $day )
2005 + || wpbm_is_this_same_day( $previosday, $day )
2147 2006 ) { // Check if $day next day from previous
2148 -
2007 +
2149 2008 $previosday = $day; // Set previos day for next loop
2150 2009 $is_fin_at_end = true;
2151 2010 } else {
2152 2011 if ( $last_show_day !== $previosday ) { // check if previos day was show or no
@@ -2155,10 +2014,10 @@
2155 2014 $result_string .= ', ' . wpbm_get_date_time_formatted( $day, false, ' ', true ); // assign in needed format this day
2156 2015 $previosday = $day; // Set previos day for next loop
2157 2016 $last_show_day = $day;
2158 2017 }
2159 - }
2160 -
2018 + }
2019 +
2161 2020 }
2162 2021
2163 2022 if ( $is_fin_at_end ) {
2164 2023 $result_string .= ' - ' . wpbm_get_date_time_formatted( $day, false, ' ', true );
@@ -2166,5 +2025,5 @@
2166 2025
2167 2026 return $result_string;
2168 2027 }
2169 2028
2170 -// </editor-fold>
2029 +// </editor-fold>