PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
booking / includes / page-setup-wizard / step-days-off / class-wpbc-setup-wizard-days-off-ajax.php

class-wpbc-setup-wizard-days-off-ajax.php in Booking Calendar 11.9, at includes/page-setup-wizard/step-days-off/class-wpbc-setup-wizard-days-off-ajax.php

139 lines 3.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * AJAX read and mutation boundary for the reusable Days Off editor.
4 *
5 * @package Booking Calendar
6 */
7
8 if ( ! defined( 'ABSPATH' ) ) {
9 exit;
10 }
11
12 /**
13 * Authorize, validate, and normalize scoped reads and canonical writes.
14 */
15 final class WPBC_Setup_Wizard_Days_Off_Ajax {
16
17 const ACTION_MUTATE = 'WPBC_AJX_SETUP_WIZARD_DAYS_OFF_MUTATE';
18 const ACTION_LOAD = 'WPBC_AJX_SETUP_WIZARD_DAYS_OFF_LOAD';
19
20 /**
21 * Register the authenticated scoped-read endpoint.
22 *
23 * @return void
24 */
25 public static function register() {
26 add_action( 'wp_ajax_' . self::ACTION_LOAD, array( __CLASS__, 'load' ) );
27 }
28
29 /**
30 * Load canonical unavailable dates for one authorized Resource scope.
31 *
32 * @return void Sends a JSON response and terminates.
33 */
34 public static function load() {
35 $days_off = self::authorize_request();
36 $scope = self::get_request_string( 'scope' );
37 $request_id = substr( sanitize_key( self::get_request_string( 'request_id' ) ), 0, 80 );
38 $result = $days_off->get_state( $scope );
39
40 if ( is_wp_error( $result ) ) {
41 wp_send_json_error(
42 array(
43 'code' => $result->get_error_code(),
44 'message' => $result->get_error_message(),
45 'request_id' => $request_id,
46 ),
47 400
48 );
49 }
50
51 wp_send_json_success(
52 array(
53 'state' => $result,
54 'request_id' => $request_id,
55 )
56 );
57 }
58
59 /**
60 * Apply one explicit Add/Delete range request.
61 *
62 * @return void Sends a JSON response and terminates.
63 */
64 public static function mutate() {
65 $days_off = self::authorize_request();
66 $view_scope = self::get_request_string( 'view_scope' );
67 if ( '' === $view_scope ) {
68 $view_scope = 'all';
69 }
70
71 $result = $days_off->mutate_range(
72 self::get_request_string( 'operation' ),
73 self::get_request_string( 'scope' ),
74 self::get_request_string( 'first_date' ),
75 self::get_request_string( 'last_date' ),
76 self::get_request_string( 'revision' ),
77 $view_scope
78 );
79 $request_id = substr( sanitize_key( self::get_request_string( 'request_id' ) ), 0, 80 );
80
81 if ( is_wp_error( $result ) ) {
82 $error_data = $result->get_error_data();
83 $response = array(
84 'code' => $result->get_error_code(),
85 'message' => $result->get_error_message(),
86 'request_id' => $request_id,
87 );
88 if ( is_array( $error_data ) && isset( $error_data['state'] ) && is_array( $error_data['state'] ) ) {
89 $response['state'] = $error_data['state'];
90 }
91 $status = 'wpbc_setup_wizard_days_off_stale_state' === $result->get_error_code() ? 409 : 400;
92 wp_send_json_error( $response, $status );
93 }
94
95 wp_send_json_success(
96 array(
97 'state' => $result,
98 'operation' => self::get_request_string( 'operation' ),
99 'request_id' => $request_id,
100 )
101 );
102 }
103
104 /**
105 * Verify the shared wizard nonce, page access, and Availability policy.
106 *
107 * @return WPBC_Setup_Wizard_Days_Off Authorized domain service.
108 */
109 private static function authorize_request() {
110 if ( ! WPBC_Setup_Wizard_Ajax::verify_request_nonce() ) {
111 wp_send_json_error( array( 'message' => __( 'Your Setup Wizard session expired. Reload the page and try again.', 'booking' ) ), 403 );
112 }
113 if ( ! WPBC_Setup_Wizard_Access::current_user_can_access() ) {
114 wp_send_json_error( array( 'message' => __( 'You are not allowed to use this Setup Wizard.', 'booking' ) ), 403 );
115 }
116 $days_off = new WPBC_Setup_Wizard_Days_Off();
117 if ( ! $days_off->current_user_can_manage() ) {
118 wp_send_json_error( array( 'message' => __( 'You are not allowed to change date availability.', 'booking' ) ), 403 );
119 }
120
121 return $days_off;
122 }
123
124 /**
125 * Read one scalar request value without accepting arrays or objects.
126 *
127 * @param string $key Request field.
128 *
129 * @return string Sanitized value.
130 */
131 private static function get_request_string( $key ) {
132 if ( ! isset( $_POST[ $key ] ) || ! is_scalar( $_POST[ $key ] ) ) {
133 return '';
134 }
135
136 return sanitize_text_field( wp_unslash( $_POST[ $key ] ) );
137 }
138 }
139