| 1 |
<?php |
| 2 |
/** |
| 3 |
* Allow-listed template loader for the Setup Wizard module. |
| 4 |
* |
| 5 |
* @package Booking Calendar |
| 6 |
*/ |
| 7 |
|
| 8 |
if ( ! defined( 'ABSPATH' ) ) { |
| 9 |
exit; |
| 10 |
} |
| 11 |
|
| 12 |
/** |
| 13 |
* Resolve only server-defined Setup Wizard templates below the module root. |
| 14 |
*/ |
| 15 |
final class WPBC_Setup_Wizard_Templates { |
| 16 |
|
| 17 |
/** @var WPBC_Setup_Wizard_Step_Module_Registry */ |
| 18 |
private $module_registry; |
| 19 |
|
| 20 |
/** |
| 21 |
* Build the allow-list loader around the reusable module registry. |
| 22 |
* |
| 23 |
* @param WPBC_Setup_Wizard_Step_Module_Registry|null $module_registry Optional shared module registry. |
| 24 |
*/ |
| 25 |
public function __construct( $module_registry = null ) { |
| 26 |
$this->module_registry = $module_registry instanceof WPBC_Setup_Wizard_Step_Module_Registry |
| 27 |
? $module_registry |
| 28 |
: new WPBC_Setup_Wizard_Step_Module_Registry(); |
| 29 |
} |
| 30 |
|
| 31 |
/** |
| 32 |
* Return the complete template allow-list. |
| 33 |
* |
| 34 |
* @return array<string,string> Template paths keyed by stable template ID. |
| 35 |
*/ |
| 36 |
public function get_allow_list() { |
| 37 |
$core_allow_list = array( |
| 38 |
'shell' => __DIR__ . '/templates/shell.php', |
| 39 |
'rail' => __DIR__ . '/templates/rail.php', |
| 40 |
'footer' => __DIR__ . '/templates/footer.php', |
| 41 |
'settings-hint' => __DIR__ . '/templates/settings-hint.php', |
| 42 |
'confirmation-dialog' => __DIR__ . '/templates/confirmation-dialog.php', |
| 43 |
'step-welcome' => __DIR__ . '/templates/step-welcome.php', |
| 44 |
'step-business-details' => __DIR__ . '/templates/step-business-details.php', |
| 45 |
'step-booking-experience' => __DIR__ . '/templates/step-booking-experience.php', |
| 46 |
'step-booking-experience-toolbar' => __DIR__ . '/templates/step-booking-experience-toolbar.php', |
| 47 |
'step-customer-journey' => __DIR__ . '/templates/step-customer-journey.php', |
| 48 |
); |
| 49 |
|
| 50 |
$error_allow_list = array( 'error' => __DIR__ . '/templates/error.php' ); |
| 51 |
$module_allow_list = array_diff_key( $this->module_registry->get_template_allow_list(), $core_allow_list, $error_allow_list ); |
| 52 |
|
| 53 |
return array_merge( |
| 54 |
$core_allow_list, |
| 55 |
$module_allow_list, |
| 56 |
$error_allow_list |
| 57 |
); |
| 58 |
} |
| 59 |
|
| 60 |
/** |
| 61 |
* Resolve one allow-listed template and prove it remains inside the module. |
| 62 |
* |
| 63 |
* @param string $template_id Server-selected template identifier. |
| 64 |
* |
| 65 |
* @return string|WP_Error Canonical template path or validation error. |
| 66 |
*/ |
| 67 |
public function get_template_path( $template_id ) { |
| 68 |
$allow_list = $this->get_allow_list(); |
| 69 |
|
| 70 |
if ( ! isset( $allow_list[ $template_id ] ) ) { |
| 71 |
return new WP_Error( 'wpbc_setup_wizard_unknown_template', __( 'The requested Setup Wizard template is not registered.', 'booking' ) ); |
| 72 |
} |
| 73 |
|
| 74 |
$template_path = realpath( $allow_list[ $template_id ] ); |
| 75 |
$template_root = realpath( __DIR__ ); |
| 76 |
|
| 77 |
if ( false === $template_path || false === $template_root || 0 !== strpos( $template_path, $template_root . DIRECTORY_SEPARATOR ) ) { |
| 78 |
return new WP_Error( 'wpbc_setup_wizard_invalid_template', __( 'The requested Setup Wizard template is unavailable.', 'booking' ) ); |
| 79 |
} |
| 80 |
|
| 81 |
return $template_path; |
| 82 |
} |
| 83 |
|
| 84 |
/** |
| 85 |
* Render one server-selected template with an explicit context record. |
| 86 |
* |
| 87 |
* Templates receive only `$template_context`; arbitrary variable extraction |
| 88 |
* is intentionally avoided so template contracts stay visible and auditable. |
| 89 |
* |
| 90 |
* @param string $template_id Server-selected template identifier. |
| 91 |
* @param array<string,mixed> $template_context Authorized presentation context. |
| 92 |
* |
| 93 |
* @return true|WP_Error True after rendering, or a template validation error. |
| 94 |
*/ |
| 95 |
public function render( $template_id, array $template_context = array() ) { |
| 96 |
$template_path = $this->get_template_path( $template_id ); |
| 97 |
|
| 98 |
if ( is_wp_error( $template_path ) ) { |
| 99 |
return $template_path; |
| 100 |
} |
| 101 |
|
| 102 |
include $template_path; |
| 103 |
|
| 104 |
return true; |
| 105 |
} |
| 106 |
} |
| 107 |
|