| 1 |
<?php |
| 2 |
/** |
| 3 |
* Full-administration landing boundary for Booking Modes V3 switches. |
| 4 |
* |
| 5 |
* @package Booking Calendar |
| 6 |
* @since 11.8.0 |
| 7 |
*/ |
| 8 |
|
| 9 |
if ( ! defined( 'ABSPATH' ) ) { |
| 10 |
exit; |
| 11 |
} |
| 12 |
|
| 13 |
/** |
| 14 |
* Retain the latest contributor-built navigation tree for one landing request. |
| 15 |
* |
| 16 |
* The normal administration menu lifecycle invokes the source filter after |
| 17 |
* each contributor. Keeping only the latest snapshot avoids reconstructing |
| 18 |
* page controllers inside admin-ajax.php and gives the landing resolver the |
| 19 |
* same capability-, owner-, edition-, and module-scoped metadata as the page. |
| 20 |
*/ |
| 21 |
final class WPBC_Booking_Modes_V3_Landing_Source_Capture { |
| 22 |
|
| 23 |
/** @var array<string,array<string,mixed>> */ |
| 24 |
private static $navigation = array(); |
| 25 |
|
| 26 |
/** |
| 27 |
* Capture the current complete source snapshot without changing it. |
| 28 |
* |
| 29 |
* @param array $navigation Contributor-built navigation tree. |
| 30 |
* @param string $page_slug Page whose contributor lifecycle is running. |
| 31 |
* |
| 32 |
* @return array Unmodified contributor navigation. |
| 33 |
*/ |
| 34 |
public static function capture( $navigation, $page_slug ) { |
| 35 |
unset( $page_slug ); |
| 36 |
self::$navigation = is_array( $navigation ) ? $navigation : array(); |
| 37 |
|
| 38 |
return $navigation; |
| 39 |
} |
| 40 |
|
| 41 |
/** |
| 42 |
* Return the latest contributor-built source snapshot. |
| 43 |
* |
| 44 |
* @return array<string,array<string,mixed>> Source navigation tree. |
| 45 |
*/ |
| 46 |
public static function get_navigation() { |
| 47 |
return self::$navigation; |
| 48 |
} |
| 49 |
} |
| 50 |
add_filter( 'wpbc_plugin_menu_structure_arr', array( 'WPBC_Booking_Modes_V3_Landing_Source_Capture', 'capture' ), PHP_INT_MAX, 2 ); |
| 51 |
|
| 52 |
/** |
| 53 |
* Resolve a signed switch intent after the normal administration menu lifecycle. |
| 54 |
* |
| 55 |
* Invalid, expired, replayed-for-another-context, or unavailable destinations |
| 56 |
* fall back to the safe Bookings page. No page callback or mutation handler is |
| 57 |
* invoked while the destination is checked. |
| 58 |
* |
| 59 |
* @return void |
| 60 |
*/ |
| 61 |
function wpbc_booking_modes_v3_handle_switch_landing() { |
| 62 |
$intent_token = isset( $_GET['wpbc_booking_mode_intent'] ) && is_scalar( $_GET['wpbc_booking_mode_intent'] ) |
| 63 |
? sanitize_text_field( wp_unslash( $_GET['wpbc_booking_mode_intent'] ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Signed, read-only landing intent. |
| 64 |
: ''; |
| 65 |
$signature = isset( $_GET['wpbc_booking_mode_signature'] ) && is_scalar( $_GET['wpbc_booking_mode_signature'] ) |
| 66 |
? sanitize_text_field( wp_unslash( $_GET['wpbc_booking_mode_signature'] ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Signed, read-only landing intent. |
| 67 |
: ''; |
| 68 |
$intent = WPBC_Booking_Modes_V3_Switch_Intent::validate( $intent_token, $signature ); |
| 69 |
$fallback_url = admin_url( 'admin.php?page=wpbc' ); |
| 70 |
|
| 71 |
if ( is_wp_error( $intent ) ) { |
| 72 |
wp_safe_redirect( $fallback_url ); |
| 73 |
exit; |
| 74 |
} |
| 75 |
|
| 76 |
$source_navigation = WPBC_Booking_Modes_V3_Landing_Source_Capture::get_navigation(); |
| 77 |
$redirect_url = WPBC_Booking_Modes_V3_Switch_Intent::resolve_destination( $intent, $source_navigation ); |
| 78 |
|
| 79 |
wp_safe_redirect( $redirect_url ? $redirect_url : $fallback_url ); |
| 80 |
exit; |
| 81 |
} |
| 82 |
add_action( 'admin_init', 'wpbc_booking_modes_v3_handle_switch_landing', PHP_INT_MAX ); |
| 83 |
|