| 1 |
<?php |
| 2 |
/** AJAX: list Appointment Services. @package Booking Calendar */ |
| 3 |
if ( ! defined( 'ABSPATH' ) ) { exit; } |
| 4 |
|
| 5 |
/** |
| 6 |
* Return the filtered Service list and Provider presentation directory. |
| 7 |
* |
| 8 |
* Status counts are calculated from the complete provider-filtered result so |
| 9 |
* the management table can switch status without a separate count request. |
| 10 |
* |
| 11 |
* @return void Terminates with a JSON success or error response. |
| 12 |
*/ |
| 13 |
function wpbc_appointment_services_ajax_list() { |
| 14 |
wpbc_appointment_services_ajax_authorize(); |
| 15 |
$service_listing = wpbc_appointment_services_get_catalog_listing(); |
| 16 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; the flag only enables an allow-listed user preference write. |
| 17 |
$save_items_per_page = isset( $_POST['save_items_per_page'] ) |
| 18 |
&& is_scalar( $_POST['save_items_per_page'] ) |
| 19 |
&& '1' === sanitize_text_field( wp_unslash( $_POST['save_items_per_page'] ) ); |
| 20 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above and normalized by WPBC_UI_Listing. |
| 21 |
if ( $save_items_per_page && isset( $_POST['items_per_page'] ) ) { |
| 22 |
$service_listing->save_items_per_page( wp_unslash( $_POST['items_per_page'] ) ); |
| 23 |
} |
| 24 |
$provider = wpbc_appointment_services_get_data_provider(); |
| 25 |
if ( ! is_object( $provider ) || ! method_exists( $provider, 'list_items' ) || ! wpbc_appointment_services_storage_is_ready() ) { |
| 26 |
wp_send_json_success( |
| 27 |
array( |
| 28 |
'storage_ready' => false, |
| 29 |
'services' => array(), |
| 30 |
'listing' => $service_listing->get_client_settings(), |
| 31 |
'message' => wpbc_appointment_services_storage_error()->get_error_message(), |
| 32 |
) |
| 33 |
); |
| 34 |
} |
| 35 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; sanitized before the repository boundary. |
| 36 |
$search = isset( $_POST['search'] ) && is_scalar( $_POST['search'] ) ? sanitize_text_field( wp_unslash( $_POST['search'] ) ) : ''; |
| 37 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; validated against the status allow-list. |
| 38 |
$status = isset( $_POST['status'] ) && is_scalar( $_POST['status'] ) ? sanitize_key( wp_unslash( $_POST['status'] ) ) : 'active'; |
| 39 |
if ( ! in_array( $status, array( 'all', 'active', 'inactive', 'archived' ), true ) ) { $status = 'active'; } |
| 40 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; normalized to a positive integer. |
| 41 |
$resource_id = isset( $_POST['resource_id'] ) && is_scalar( $_POST['resource_id'] ) ? absint( $_POST['resource_id'] ) : 0; |
| 42 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; normalized by the shared listing component. |
| 43 |
$page_number = isset( $_POST['page_number'] ) ? wp_unslash( $_POST['page_number'] ) : 1; |
| 44 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; normalized against the configured allow-list. |
| 45 |
$items_per_page = isset( $_POST['items_per_page'] ) ? wp_unslash( $_POST['items_per_page'] ) : $service_listing->get_items_per_page(); |
| 46 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; normalized against sortable listing columns. |
| 47 |
$sort_by = isset( $_POST['sort_by'] ) ? wp_unslash( $_POST['sort_by'] ) : null; |
| 48 |
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- Authorized above; normalized to asc or desc. |
| 49 |
$sort_order = isset( $_POST['sort_order'] ) ? wp_unslash( $_POST['sort_order'] ) : null; |
| 50 |
$catalog_page = wpbc_appointment_services_get_catalog_page( |
| 51 |
$provider, |
| 52 |
array( |
| 53 |
'search' => $search, |
| 54 |
'status' => $status, |
| 55 |
'resource_id' => $resource_id, |
| 56 |
'page_number' => $page_number, |
| 57 |
'items_per_page' => $items_per_page, |
| 58 |
'sort_by' => $sort_by, |
| 59 |
'sort_order' => $sort_order, |
| 60 |
), |
| 61 |
$service_listing |
| 62 |
); |
| 63 |
if ( is_wp_error( $catalog_page ) ) { |
| 64 |
wpbc_appointment_services_send_provider_error( $catalog_page, __( 'Services could not be loaded.', 'booking' ) ); |
| 65 |
} |
| 66 |
$directory = wpbc_appointment_services_get_provider_directory(); |
| 67 |
wp_send_json_success( |
| 68 |
array( |
| 69 |
'storage_ready' => true, |
| 70 |
'services' => $catalog_page['services'], |
| 71 |
'counts' => $catalog_page['counts'], |
| 72 |
'pagination' => $catalog_page['pagination'], |
| 73 |
'sorting' => $catalog_page['sorting'], |
| 74 |
'providers' => array_values( $directory ), |
| 75 |
'provider_count'=> count( $directory ), |
| 76 |
'listing' => $service_listing->get_client_settings(), |
| 77 |
) |
| 78 |
); |
| 79 |
} |
| 80 |
add_action( 'wp_ajax_WPBC_AJX_APPOINTMENT_SERVICES_LIST', 'wpbc_appointment_services_ajax_list' ); |
| 81 |
|