PluginProbe
Booking Calendar / 11.6
Booking Calendar v11.6
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
booking / includes / page-appointment-services / ajax / appointment_services__catalog_edit.php

appointment_services__catalog_edit.php in Booking Calendar 11.6, at includes/page-appointment-services/ajax/appointment_services__catalog_edit.php

140 lines 5.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * AJAX endpoints for reviewed Appointment Service catalog edits.
4 *
5 * The endpoints expose only the Service-domain preview and apply contracts.
6 * Selection and inspector presentation remain in the shared catalog client.
7 *
8 * @package Booking Calendar
9 * @since 11.6.0
10 */
11 if ( ! defined( 'ABSPATH' ) ) { exit; }
12
13 /**
14 * Decode one JSON request field into an associative array.
15 *
16 * @param string $field_name POST field name.
17 *
18 * @return array<string,mixed>|WP_Error Decoded values or a malformed-request error.
19 */
20 function wpbc_appointment_services_catalog_decode_json_field( $field_name ) {
21 // phpcs:ignore WordPress.Security.NonceVerification.Missing
22 $raw_value = isset( $_POST[ $field_name ] ) && is_scalar( $_POST[ $field_name ] ) ? wp_unslash( $_POST[ $field_name ] ) : '';
23 $decoded = json_decode( (string) $raw_value, true );
24
25 if ( JSON_ERROR_NONE !== json_last_error() || ! is_array( $decoded ) ) {
26 return new WP_Error( 'wpbc_service_malformed_request', __( 'The Service editing request is malformed.', 'booking' ) );
27 }
28
29 return $decoded;
30 }
31
32 /**
33 * Send one Service catalog editing error with a safe HTTP status.
34 *
35 * @param WP_Error $error Domain validation, conflict, or storage error.
36 * @return void Terminates with a normalized JSON error.
37 */
38 function wpbc_appointment_services_send_catalog_edit_error( $error ) {
39 $error_code = $error->get_error_code();
40 $status = 400;
41
42 if ( in_array( $error_code, array( 'wpbc_service_stale_review', 'wpbc_service_stale_delete_review', 'wpbc_service_stale_delete_apply' ), true ) ) {
43 $status = 409;
44 } elseif ( in_array( $error_code, array( 'service_not_found', 'invalid_service' ), true ) ) {
45 $status = 404;
46 } elseif ( in_array( $error_code, array( 'appointment_services_storage_unavailable', 'wpbc_service_delete_unsupported_storage' ), true ) ) {
47 $status = 503;
48 } elseif ( in_array( $error_code, array( 'wpbc_service_apply_failed', 'wpbc_service_delete_failed', 'wpbc_service_delete_compensation_failed' ), true ) ) {
49 $status = 500;
50 }
51
52 wp_send_json_error(
53 array(
54 'code' => sanitize_key( $error_code ),
55 'message' => $error->get_error_message(),
56 ),
57 $status
58 );
59 }
60
61 /**
62 * Return current row-specific inline field schemas for visible Services.
63 *
64 * @return void Terminates with a JSON response.
65 */
66 function wpbc_appointment_services_ajax_catalog_inline_schema() {
67 wpbc_appointment_services_ajax_authorize();
68 $service_ids = wpbc_appointment_services_catalog_decode_json_field( 'ids' );
69 if ( is_wp_error( $service_ids ) ) {
70 wpbc_appointment_services_send_catalog_edit_error( $service_ids );
71 }
72 $result = ( new WPBC_Appointment_Services_Catalog_Editor() )->get_inline_schema( $service_ids );
73 if ( is_wp_error( $result ) ) {
74 wpbc_appointment_services_send_catalog_edit_error( $result );
75 }
76 wp_send_json_success( array( 'schema' => $result ) );
77 }
78 add_action( 'wp_ajax_WPBC_AJX_APPOINTMENT_SERVICES_INLINE_SCHEMA', 'wpbc_appointment_services_ajax_catalog_inline_schema' );
79
80 /**
81 * Return the safe bulk-field intersection for selected Services.
82 *
83 * @return void Terminates with a JSON response.
84 */
85 function wpbc_appointment_services_ajax_catalog_bulk_contract() {
86 wpbc_appointment_services_ajax_authorize();
87 $service_ids = wpbc_appointment_services_catalog_decode_json_field( 'ids' );
88 if ( is_wp_error( $service_ids ) ) {
89 wpbc_appointment_services_send_catalog_edit_error( $service_ids );
90 }
91 $result = ( new WPBC_Appointment_Services_Catalog_Editor() )->get_bulk_contract( $service_ids );
92 if ( is_wp_error( $result ) ) {
93 wpbc_appointment_services_send_catalog_edit_error( $result );
94 }
95 wp_send_json_success( array( 'contract' => $result ) );
96 }
97 add_action( 'wp_ajax_WPBC_AJX_APPOINTMENT_SERVICES_BULK_CONTRACT', 'wpbc_appointment_services_ajax_catalog_bulk_contract' );
98
99 /**
100 * Return a signed, non-mutating Service edit review.
101 *
102 * @return void Terminates with a JSON response.
103 */
104 function wpbc_appointment_services_ajax_catalog_preview() {
105 wpbc_appointment_services_ajax_authorize();
106 $editor = new WPBC_Appointment_Services_Catalog_Editor();
107 // phpcs:ignore WordPress.Security.NonceVerification.Missing
108 $mode = isset( $_POST['mode'] ) ? sanitize_key( wp_unslash( $_POST['mode'] ) ) : '';
109 $ids = wpbc_appointment_services_catalog_decode_json_field( 'ids' );
110 $changes = wpbc_appointment_services_catalog_decode_json_field( 'changes' );
111 if ( is_wp_error( $ids ) || is_wp_error( $changes ) ) {
112 wpbc_appointment_services_send_catalog_edit_error( is_wp_error( $ids ) ? $ids : $changes );
113 }
114 $result = $editor->preview( $mode, $ids, $changes );
115 if ( is_wp_error( $result ) ) { wpbc_appointment_services_send_catalog_edit_error( $result ); }
116 wp_send_json_success( $result );
117 }
118 add_action( 'wp_ajax_WPBC_AJX_APPOINTMENT_SERVICES_CATALOG_PREVIEW', 'wpbc_appointment_services_ajax_catalog_preview' );
119
120 /**
121 * Apply one signed Service edit plan after revalidation.
122 *
123 * @return void Terminates with a JSON response.
124 */
125 function wpbc_appointment_services_ajax_catalog_apply() {
126 wpbc_appointment_services_ajax_authorize();
127 $editor = new WPBC_Appointment_Services_Catalog_Editor();
128 $plan = wpbc_appointment_services_catalog_decode_json_field( 'plan' );
129 if ( is_wp_error( $plan ) ) {
130 wpbc_appointment_services_send_catalog_edit_error( $plan );
131 }
132 // phpcs:ignore WordPress.Security.NonceVerification.Missing
133 $token = isset( $_POST['token'] ) && is_scalar( $_POST['token'] ) ? sanitize_text_field( wp_unslash( $_POST['token'] ) ) : '';
134 $result = $editor->apply( $plan, $token );
135 if ( is_wp_error( $result ) ) { wpbc_appointment_services_send_catalog_edit_error( $result ); }
136 $result['message'] = __( 'Service changes applied.', 'booking' );
137 wp_send_json_success( $result );
138 }
139 add_action( 'wp_ajax_WPBC_AJX_APPOINTMENT_SERVICES_CATALOG_APPLY', 'wpbc_appointment_services_ajax_catalog_apply' );
140