PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
booking / includes / page-catalog-booking-resources / ajax / booking-resources-inline.php

booking-resources-inline.php in Booking Calendar 11.9, at includes/page-catalog-booking-resources/ajax/booking-resources-inline.php

110 lines 4.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Independent AJAX transport for reviewed inline Resource operations.
4 *
5 * @package Booking Calendar
6 * @since 11.6.0
7 */
8
9 if ( ! defined( 'ABSPATH' ) ) {
10 exit;
11 }
12
13 /**
14 * Decode one bounded JSON payload for the inline endpoint family.
15 *
16 * @param string $request_key POST key containing JSON.
17 * @param string $error_message Safe translated validation message.
18 * @return array<int|string,mixed>|WP_Error Decoded array or validation error.
19 */
20 function wpbc_catalog_booking_resources_inline_decode_json( $request_key, $error_message ) {
21 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- The endpoint verifies the shared nonce before calling this helper.
22 $raw_value = isset( $_POST[ $request_key ] ) && is_scalar( $_POST[ $request_key ] ) ? wp_unslash( (string) $_POST[ $request_key ] ) : '';
23 if ( '' === $raw_value || strlen( $raw_value ) > 250000 ) {
24 return new WP_Error( 'wpbc_catalog_inline_json_invalid', $error_message );
25 }
26 $decoded_value = json_decode( $raw_value, true );
27
28 return is_array( $decoded_value ) ? $decoded_value : new WP_Error( 'wpbc_catalog_inline_json_invalid', $error_message );
29 }
30
31 /**
32 * Return current row-specific inline field schemas.
33 *
34 * @return void Terminates with a JSON response.
35 */
36 function wpbc_catalog_booking_resources_ajax_inline_schema() {
37 $authorized = wpbc_catalog_booking_resource_inspector_authorize();
38 if ( is_wp_error( $authorized ) ) {
39 wpbc_catalog_booking_resource_inspector_send_error( $authorized, 403 );
40 }
41 $resource_ids = wpbc_catalog_booking_resources_inline_decode_json( 'resource_ids', __( 'The inline Booking Resource selection is invalid.', 'booking' ) );
42 if ( is_wp_error( $resource_ids ) ) {
43 wpbc_catalog_booking_resource_inspector_send_error( $resource_ids );
44 }
45 $schema = ( new WPBC_Catalog_Booking_Resources_Inline_Editor() )->get_schema( $resource_ids );
46 if ( is_wp_error( $schema ) ) {
47 wpbc_catalog_booking_resource_inspector_send_error( $schema );
48 }
49
50 wp_send_json_success( array( 'schema' => $schema ) );
51 }
52 add_action( 'wp_ajax_WPBC_AJX_CATALOG_BOOKING_RESOURCES_INLINE_SCHEMA', 'wpbc_catalog_booking_resources_ajax_inline_schema' );
53
54 /**
55 * Return a signed preview without mutating any Resource.
56 *
57 * @return void Terminates with a JSON response.
58 */
59 function wpbc_catalog_booking_resources_ajax_inline_preview() {
60 $authorized = wpbc_catalog_booking_resource_inspector_authorize();
61 if ( is_wp_error( $authorized ) ) {
62 wpbc_catalog_booking_resource_inspector_send_error( $authorized, 403 );
63 }
64 $rows = wpbc_catalog_booking_resources_inline_decode_json( 'rows', __( 'The inline Booking Resource changes are invalid.', 'booking' ) );
65 if ( is_wp_error( $rows ) ) {
66 wpbc_catalog_booking_resource_inspector_send_error( $rows );
67 }
68 $preview = ( new WPBC_Catalog_Booking_Resources_Inline_Editor() )->preview( $rows );
69 if ( is_wp_error( $preview ) ) {
70 wpbc_catalog_booking_resource_inspector_send_error( $preview );
71 }
72
73 wp_send_json_success( array( 'preview' => $preview ) );
74 }
75 add_action( 'wp_ajax_WPBC_AJX_CATALOG_BOOKING_RESOURCES_INLINE_PREVIEW', 'wpbc_catalog_booking_resources_ajax_inline_preview' );
76
77 /**
78 * Apply a signed inline review after current-value revalidation.
79 *
80 * @return void Terminates with a JSON response.
81 */
82 function wpbc_catalog_booking_resources_ajax_inline_apply() {
83 $authorized = wpbc_catalog_booking_resource_inspector_authorize( 'inline_update' );
84 if ( is_wp_error( $authorized ) ) {
85 wpbc_catalog_booking_resource_inspector_send_error( $authorized, 403 );
86 }
87 $rows = wpbc_catalog_booking_resources_inline_decode_json( 'rows', __( 'The inline Booking Resource changes are invalid.', 'booking' ) );
88 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- Verified above.
89 $review_token = isset( $_POST['review_token'] ) && is_scalar( $_POST['review_token'] ) ? sanitize_text_field( wp_unslash( (string) $_POST['review_token'] ) ) : '';
90 if ( is_wp_error( $rows ) ) {
91 wpbc_catalog_booking_resource_inspector_send_error( $rows );
92 }
93 $result = ( new WPBC_Catalog_Booking_Resources_Inline_Editor() )->apply( $rows, $review_token );
94 if ( is_wp_error( $result ) ) {
95 wpbc_catalog_booking_resource_inspector_send_error( $result, 'wpbc_catalog_inline_review_stale' === $result->get_error_code() ? 409 : 400 );
96 }
97
98 wp_send_json_success(
99 array(
100 'updated_ids' => array_map( 'absint', $result['updated_ids'] ),
101 'message' => sprintf(
102 /* translators: %s: Number of updated Booking Resources. */
103 _n( '%s Booking Resource updated.', '%s Booking Resources updated.', $result['updated_count'], 'booking' ),
104 number_format_i18n( $result['updated_count'] )
105 ),
106 )
107 );
108 }
109 add_action( 'wp_ajax_WPBC_AJX_CATALOG_BOOKING_RESOURCES_INLINE_APPLY', 'wpbc_catalog_booking_resources_ajax_inline_apply' );
110