PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | includes/publish/wpbc-publish-shortcode.php +71 -37 10.1.3 → 11.9 View file →
@@ -1,4 +1,4 @@
1 1 <?php
2 2 /**
3 3 * @version 1.0
4 4 * @package Booking Calendar
@@ -9,11 +9,12 @@
9 9 * @link https://wpbookingcalendar.com/
10 10 * @email [email protected]
11 11 *
12 12 * @modified 2023-12-27
13 + * @file: ../includes/publish/wpbc-publish-shortcode.php
13 14 */
14 15
15 -if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly //FixIn: 9.8.15.5
16 +if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly // FixIn: 9.8.15.5.
16 17
17 18
18 19 /**
19 20 * Get prepared (for WP Blocks) shortcode of booking form for inserting into the post or page
@@ -50,17 +51,20 @@
50 51 * @return false|void
51 52 */
52 53 function wpbc_check_for_submit__page_resource_publish( $page_name ) {
53 54
54 - if ( 'resources' !== $page_name ) {
55 + if (
56 + ( 'resources' !== $page_name )
57 + ){
55 58 return false;
56 59 }
57 60
58 61 // Check $_POST
59 62
63 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
60 64 if ( ( isset( $_POST['action'] ) ) && ( 'wpbc_page_resource_publish' === $_POST['action'] ) ) {
61 65
62 - if ( wpbc_is_this_demo() ) {
66 + if ( wpbc_is_booking_form_publishing_restricted() ) {
63 67 wpbc_show_notice__for_page_resource_publish( 'This operation is restricted in the demo version.', 'warning' );
64 68 return;
65 69 }
66 70
@@ -68,18 +72,20 @@
68 72
69 73 $add_shortcode_result_arr = false;
70 74
71 75 // CREATE NEW PAGE
72 - if(
73 - ( 'create' === $_POST['wpbc_page_resource_publish_what'] )
76 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
77 + if ( ( 'create' === $_POST['wpbc_page_resource_publish_what'] )
74 78 && ( ! empty($_POST['create_page_for_resource_publish'] ) )
75 79 && ( ! empty($_POST['wpbc_page_resource_publish_resource_id'] ) )
76 80 ){
77 - $shortcode_resource_id = intval( $_POST['wpbc_page_resource_publish_resource_id'] );
78 - $page_name = $_POST['create_page_for_resource_publish'];
81 + $shortcode_resource_id = intval( $_POST['wpbc_page_resource_publish_resource_id'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
82 + $page_name = sanitize_text_field( wp_unslash( $_POST['create_page_for_resource_publish'] ) ); /* phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing */ /* FixIn: sanitize_unslash */
79 83
84 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
80 85 if ( ! empty( $_POST['wpbc_page_resource_publish_resource_shortcode'] ) ) {
81 86 //$insert_shortcode = WPBC_Settings_API::validate_textarea_post_static( 'wpbc_page_resource_publish_resource_shortcode' );
87 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
82 88 $insert_shortcode = wp_kses( trim( stripslashes( $_POST[ 'wpbc_page_resource_publish_resource_shortcode' ] ) ),
83 89 array_merge( array( // 'iframe' => array( 'src' => true, 'style' => true, 'id' => true, 'class' => true )
84 90 // , 'script' => array( 'type' => true ) // Allow JS
85 91 ),
@@ -104,15 +110,15 @@
104 110 ) );
105 111 }
106 112
107 113 // ADD TO EXIST PAGE
108 - if(
109 - ( 'edit' === $_POST['wpbc_page_resource_publish_what'] )
114 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated
115 + if ( ( 'edit' === $_POST['wpbc_page_resource_publish_what'] )
110 116 && ( ! empty($_POST['select_page_for_resource_publish'] ) )
111 117 && ( ! empty($_POST['wpbc_page_resource_publish_resource_id'] ) )
112 118 ){
113 - $shortcode_resource_id = intval( $_POST['wpbc_page_resource_publish_resource_id'] );
114 - $page_id = intval( $_POST['select_page_for_resource_publish'] );
119 + $shortcode_resource_id = intval( $_POST['wpbc_page_resource_publish_resource_id'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
120 + $page_id = intval( $_POST['select_page_for_resource_publish'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
115 121
116 122 // Add shortcode to specific Page with POST ID
117 123 $check_exist_shortcode_arr = array(
118 124 '[booking resource_id=' . $shortcode_resource_id . ' ',
@@ -124,10 +130,12 @@
124 130 $check_exist_shortcode_arr[] = '[booking]';
125 131 }
126 132
127 133
134 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
128 135 if ( ! empty( $_POST['wpbc_page_resource_publish_resource_shortcode'] ) ) {
129 136 //$insert_shortcode = WPBC_Settings_API::validate_textarea_post_static( 'wpbc_page_resource_publish_resource_shortcode' );
137 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
130 138 $insert_shortcode = wp_kses( trim( stripslashes( $_POST[ 'wpbc_page_resource_publish_resource_shortcode' ] ) ),
131 139 array_merge( array( // 'iframe' => array( 'src' => true, 'style' => true, 'id' => true, 'class' => true )
132 140 // , 'script' => array( 'type' => true ) // Allow JS
133 141 ),
@@ -164,17 +172,19 @@
164 172 // . ' ' . '<a href="' . esc_url( wpbc_make_link_absolute( $relative_post_url ) ) . '">' . $post_title . '</a>'
165 173 );
166 174
167 175 } elseif ( false === $add_shortcode_result_arr ) {
168 - wpbc_show_notice__for_page_resource_publish( 'Error: You may not have chosen the correct page name.', 'warning' );
176 + wpbc_show_notice__for_page_resource_publish( 'Error: You may not have chosen the correct page name.', 'error' );
169 177 wpbc_show_notice__for_page_resource_publish(
170 - sprintf( __('Find more information at the %sFAQ page%s','booking'),
178 + /* translators: 1: ... */
179 + sprintf( __( 'Find more information at the %1$sFAQ page%2$s', 'booking' ),
171 180 '<a href="https://wpbookingcalendar.com/faq/#shortcodes">', '</a>'
172 181 ), 'info');
173 182 }else {
174 - wpbc_show_notice__for_page_resource_publish( $add_shortcode_result_arr['message'], 'warning' );
183 + wpbc_show_notice__for_page_resource_publish( $add_shortcode_result_arr['message'], 'error' );
175 184 wpbc_show_notice__for_page_resource_publish(
176 - sprintf( __('Find more information at the %sFAQ page%s','booking'),
185 + /* translators: 1: ... */
186 + sprintf( __( 'Find more information at the %1$sFAQ page%2$s', 'booking' ),
177 187 '<a href="https://wpbookingcalendar.com/faq/#shortcodes">', '</a>'
178 188 ), 'info');
179 189 }
180 190
@@ -179,16 +189,35 @@
179 189 }
180 190
181 191 }
182 192 }
183 -add_action( 'wpbc_hook_settings_page_before_content_table', 'wpbc_check_for_submit__page_resource_publish' ,10, 1);
184 -
185 -
186 -function wpbc_show_notice__for_page_resource_publish( $message, $message_type='success'){
187 - ?>
188 - <div class="wpbc-settings-notice notice-<?php echo $message_type ?>" style="text-align:left;font-size: 1rem;margin-top:20px;">
189 - <strong><?php echo ( ( 'error' == $message_type ) ? ( __('Error' ,'booking') . '! ' ) : '' ); ?></strong> <?php
190 - echo $message;
193 +add_action( 'wpbc_hook_settings_page_before_content_table', 'wpbc_check_for_submit__page_resource_publish' ,10, 1);
194 +
195 +/**
196 + * Render feedback from the Booking Resource publishing workflow.
197 + *
198 + * The shared publisher is also used outside the Resources catalog, so catalog
199 + * spacing is applied only while the new catalog renderer owns the request.
200 + *
201 + * @param string $message Escaped or deliberately prepared notice markup.
202 + * @param string $message_type Notice type used by the Booking Calendar notice styles.
203 + *
204 + * @return void
205 + */
206 +function wpbc_show_notice__for_page_resource_publish( $message, $message_type = 'success' ) {
207 + $notice_style = 'text-align:left;font-size:1rem;margin-top:20px;';
208 +
209 + if ( function_exists( 'wpbc_catalog_booking_resources_is_page' ) && wpbc_catalog_booking_resources_is_page() ) {
210 + $notice_style = 'text-align:left;font-size:1rem;margin:0 0 40px;';
211 + }
212 + ?>
213 + <div class="wpbc-settings-notice notice-<?php echo esc_attr( $message_type ); ?>" style="<?php echo esc_attr( $notice_style ); ?>">
214 + <strong><?php
215 + if ( ( 'error' == $message_type ) ) {
216 + echo esc_html__( 'Error', 'booking' ) . '! ';
217 + } ?></strong> <?php
218 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
219 + echo $message;
191 220 ?>
192 221 </div>
193 222 <?php
194 223 }
@@ -196,9 +225,15 @@
196 225
197 226 /** Publish Layout - Modal Window structure */
198 227 function wpbc_write_content_for_modal__page_resource_publish( $page_name ) {
199 228
200 - if ( 'resources' !== $page_name ) { return false; }
229 + if (
230 + ( 'resources' !== $page_name ) &&
231 + ( ! wpbc_is_builder_booking_form_page() )
232 + // && ( 'wpbc-ajx_booking' !== $page_name ) // FixIn: 10.6.6.2.
233 + ){
234 + return false;
235 + }
201 236
202 237 ?><span class="wpdevelop"><?php
203 238
204 239 ?><div id="wpbc_modal__resource_publish" class="modal wpbc_popup_modal" tabindex="-1" role="dialog">
@@ -254,14 +289,14 @@
254 289 <div class="modal-dialog modal-lg0">
255 290 <div class="modal-content">
256 291 <div class="modal-header">
257 292 <button type="button" class="close" data-dismiss="modal" aria-label="Close"><span aria-hidden="true">&times;</span></button>
258 - <h4 class="modal-title"><?php _e( 'Insert into page' ); ?></h4>
293 + <h4 class="modal-title"><?php esc_html_e( 'Insert into page', 'booking' ); ?></h4>
259 294 </div>
260 295 <div class="modal-body">
261 296 <div id="wpbc_content_for_js_resource_publish">
262 297 <?php
263 - if ( wpbc_is_this_demo() ) {
298 + if ( wpbc_is_booking_form_publishing_restricted() ) {
264 299 wpbc_show_notice__for_page_resource_publish( 'In the demo versions such operation is not allowed.', 'warning' );
265 300 } else {
266 301 ?>
267 302 <form method="post" action="">
@@ -272,9 +307,9 @@
272 307 <?php
273 308 wp_nonce_field( 'set_resource_publish_check' );
274 309 ?>
275 310 <div class="wpbc_publish_wizard_steps wpbc_publish_wizard_step_1">
276 - <div class="wpbc_publish_wizard_inner_header"><?php _e('Choose whether to embed your booking form in an existing page or create a new one.', 'booking'); ?></div>
311 + <div class="wpbc_publish_wizard_inner_header"><?php esc_html_e('Choose whether to embed your booking form in an existing page or create a new one.', 'booking'); ?></div>
277 312 <div class="wpbc_publish_wizard_steps__buttons">
278 313 <a href="javascript:void(0)" class="button button-secondary"
279 314 onclick="javascript:jQuery( '.wpbc_publish_wizard_steps').hide();
280 315 jQuery( '.wpbc_publish_wizard_step_2').show();
@@ -280,9 +315,9 @@
280 315 jQuery( '.wpbc_publish_wizard_step_2').show();
281 316 jQuery( '#wpbc_modal__resource_publish .modal-footer').show();
282 317 jQuery( '#wpbc_page_resource_publish_resource_shortcode' ).val( jQuery( '#booking_resource_shortcode_' + jQuery( '#wpbc_page_resource_publish_resource_id' ).val() ).val() );
283 318 jQuery( '#wpbc_page_resource_publish_what' ).val( 'edit' );"
284 - ><?php _e('Embed in Existing Page','booking') ?></a>
319 + ><?php esc_html_e('Embed in Existing Page', 'booking' ); ?></a>
285 320 <a href="javascript:void(0)" class="button button-secondary"
286 321 onclick="javascript:jQuery( '.wpbc_publish_wizard_steps').hide();
287 322 jQuery( '.wpbc_publish_wizard_step_3').show();
288 323 jQuery( '#wpbc_modal__resource_publish .modal-footer').show();
@@ -287,36 +322,35 @@
287 322 jQuery( '.wpbc_publish_wizard_step_3').show();
288 323 jQuery( '#wpbc_modal__resource_publish .modal-footer').show();
289 324 jQuery( '#wpbc_page_resource_publish_resource_shortcode' ).val( jQuery( '#booking_resource_shortcode_' + jQuery( '#wpbc_page_resource_publish_resource_id' ).val() ).val() );
290 325 jQuery( '#wpbc_page_resource_publish_what' ).val( 'create' );"
291 - ><?php _e('Create New Page','booking') ?></a>
326 + ><?php esc_html_e('Create New Page','booking'); ?></a>
292 327 </div>
293 328 </div>
294 329 <div class="wpbc_publish_wizard_steps wpbc_publish_wizard_step_2">
295 - <div class="wpbc_publish_wizard_inner_header"><?php _e('Select the page where you want to embed your booking form.', 'booking'); ?></div>
330 + <div class="wpbc_publish_wizard_inner_header"><?php esc_html_e('Select the page where you want to embed your booking form.', 'booking'); ?></div>
296 331 <div class="wpbc_publish_wizard_steps__inputs">
297 332 <?php
298 333 wp_dropdown_pages(
299 334 array(
300 335 'name' => 'select_page_for_resource_publish',
301 - 'show_option_none' => __( '&mdash; Select &mdash;' ),
336 + 'show_option_none' => '&mdash; ' . esc_html__( 'Select', 'booking' ) . ' &mdash;',
302 337 'option_none_value' => '0',
303 338 'selected' => 0,//$privacy_policy_page_id,
304 339 'post_status' => array( 'draft', 'publish' ),
305 340 )
306 341 );
307 - submit_button( __( 'Use This Page' ), 'primary', 'submit', false, array( 'id' => 'set-page' ) );
342 + submit_button( __( 'Use This Page', 'booking' ), 'primary', 'submit', false, array( 'id' => 'set-page' ) );
308 343 ?>
309 344 </div>
310 345 </div>
311 346 <div class="wpbc_publish_wizard_steps wpbc_publish_wizard_step_3">
312 - <div class="wpbc_publish_wizard_inner_header"><?php _e('Provide a name for your new page.', 'booking'); ?></div>
347 + <div class="wpbc_publish_wizard_inner_header"><?php esc_html_e('Provide a name for your new page.', 'booking'); ?></div>
313 348 <div class="wpbc_publish_wizard_steps__inputs">
314 349 <input id="create_page_for_resource_publish" name="create_page_for_resource_publish" type="text" value=""
315 350 placeholder="<?php echo esc_attr( __( 'Enter Page Name', 'booking' ) ); ?>"/>
316 351 <?php
317 -
318 - submit_button( __( 'Create Page' ), 'primary', 'submit', false, array( 'id' => 'set-page' ) );
352 + submit_button( __( 'Create Page', 'booking' ), 'primary', 'submit', false, array( 'id' => 'set-page' ) );
319 353 ?>
320 354 </div>
321 355 </div>
322 356 </form>
@@ -323,15 +357,15 @@
323 357 <?php } ?>
324 358 </div>
325 359 </div>
326 360 <div class="modal-footer">
327 - <!--a href="javascript:void(0)" class="button button-secondary" data-dismiss="modal"><?php _e('Close' ,'booking'); ?></a-->
361 + <!--a href="javascript:void(0)" class="button button-secondary" data-dismiss="modal"><?php esc_html_e('Close' ,'booking'); ?></a-->
328 362 <a id="wpbc_modal__go_back_button" class="button button-secondary"
329 363 href="javascript:void(0);"
330 364 onclick="javascript:jQuery( '.wpbc_publish_wizard_steps').hide();
331 365 jQuery( '.wpbc_publish_wizard_step_1').show();
332 366 jQuery( '#wpbc_modal__resource_publish .modal-footer').hide();"
333 - ><i class="menu_icon icon-1x wpbc_icn_keyboard_arrow_left"></i> <?php _e('Go Back' ,'booking'); ?></a>
367 + ><i class="menu_icon icon-1x wpbc_icn_keyboard_arrow_left"></i> <?php esc_html_e('Go Back' ,'booking'); ?></a>
334 368 </div>
335 369 </div><!-- /.modal-content -->
336 370 </div><!-- /.modal-dialog -->
337 371 </div><!-- /.modal -->