PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | core/wpbc-translation.php +65 -20 11.0 → 11.9 View file →
@@ -223,8 +223,39 @@
223 223 }
224 224
225 225
226 226 /**
227 + * Validate a locale received from a request.
228 + *
229 + * Locale values are used request-wide and can later be rendered inside JavaScript and HTML attributes. Accept only
230 + * ASCII locale identifiers, such as "en", "en_US", "de_DE_formal", or "en-US". Invalid values must be rejected
231 + * instead of sanitized into a different value. // FixIn: 11.4.3.2.
232 + *
233 + * @param mixed $locale Locale value from the request.
234 + *
235 + * @return string|false Valid locale, or false when the value is invalid.
236 + */
237 +function wpbc_validate_request_locale( $locale ) {
238 +
239 + if ( ! is_string( $locale ) ) {
240 + return false;
241 + }
242 +
243 + $locale = wp_unslash( $locale );
244 +
245 + if (
246 + ( '' === $locale )
247 + || ( strlen( $locale ) > 32 )
248 + || ( 1 !== preg_match( '/\A[A-Za-z0-9]+(?:[_-][A-Za-z0-9]+)*\z/D', $locale ) )
249 + ) {
250 + return false;
251 + }
252 +
253 + return $locale;
254 +}
255 +
256 +
257 +/**
227 258 * Get maybe reloaded 'booking' locale ( WPBC_LOCALE_RELOAD ) and if not defined WPBC_LOCALE_RELOAD define it.
228 259 *
229 260 * @return string
230 261 */
@@ -260,15 +291,15 @@
260 291
261 292 $wpbc_ajx_locale = false;
262 293 // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
263 294 if ( isset( $_REQUEST['wpdev_active_locale'] ) ) {
264 - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.NonceVerification.Recommended
265 - $wpbc_ajx_locale = sanitize_text_field( $_REQUEST['wpdev_active_locale'] );
295 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended
296 + $wpbc_ajx_locale = wpbc_validate_request_locale( $_REQUEST['wpdev_active_locale'] );
266 297 }
267 298 // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
268 299 if ( isset( $_REQUEST['wpbc_ajx_locale'] ) ) {
269 - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.NonceVerification.Recommended
270 - $wpbc_ajx_locale = sanitize_text_field( $_REQUEST['wpbc_ajx_locale'] );
300 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended
301 + $wpbc_ajx_locale = wpbc_validate_request_locale( $_REQUEST['wpbc_ajx_locale'] );
271 302 }
272 303
273 304 // Reload locale ONLY in AJAX, and if `isset $_REQUEST['wpdev_active_locale']
274 305 if (
@@ -378,11 +409,11 @@
378 409
379 410 /**
380 411 * Translate content. Check for language sections -- [lang=xx_XX] shortcode. // FixIn: 10.0.0.46.
381 412 *
382 - * @param $content_orig
413 + * @param mixed $content_orig Content containing optional language sections.
383 414 *
384 - * @return string
415 + * @return string Translated content, or an empty string for unsupported values.
385 416 */
386 417 function wpbc_lang( $content_orig ) {
387 418 return wpdev_check_for_active_language( $content_orig );
388 419 }
@@ -390,23 +421,31 @@
390 421
391 422 /**
392 423 * Check plugin text for active language section -- [lang=xx_XX] shortcode
393 424 *
394 - * @param string $content_orig
395 - * @return string
425 + * @param mixed $content_orig Content containing optional language sections.
426 + * @return string Translated content, or an empty string for unsupported values.
396 427 * Usage:
397 428 * $text = wpbc_lang( $text );
398 429 */
399 430 function wpdev_check_for_active_language( $content_orig ) { // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound
400 431
401 - $content = $content_orig;
432 + if ( is_string( $content_orig ) ) {
433 + $content = $content_orig;
434 + } elseif ( is_scalar( $content_orig ) ) {
435 + $content = (string) $content_orig;
436 + } elseif ( is_object( $content_orig ) && method_exists( $content_orig, '__toString' ) ) {
437 + $content = (string) $content_orig;
438 + } else {
439 + return '';
440 + }
402 441
403 - $languages = array();
404 - $content_ex = explode('[lang',$content);
442 + $languages = array();
443 + $content_ex = explode( '[lang', $content );
405 444
406 445 foreach ( $content_ex as $value ) {
407 446
408 - if ( '=' == substr( $value, 0, 1 ) ) {
447 + if ( '=' === substr( $value, 0, 1 ) ) {
409 448
410 449 $pos_s = strpos( $value, '=' );
411 450 $pos_f = strpos( $value, ']' );
412 451 $key = trim( substr( $value, ( $pos_s + 1 ), ( $pos_f - $pos_s - 1 ) ) );
@@ -417,9 +456,9 @@
417 456 $languages['default'] = $value;
418 457 }
419 458 }
420 459
421 - $locale = wpbc_get_maybe_reloaded_booking_locale(); // $locale = 'fr_FR';
460 + $locale = wpbc_get_maybe_reloaded_booking_locale(); // $locale = 'fr_FR'.
422 461
423 462 if ( isset( $languages[ $locale ] ) ) {
424 463 $return_text = $languages[ $locale ];
425 464 } else {
@@ -732,13 +771,15 @@
732 771
733 772 /**
734 773 * Download translations from wpbookingcalendar.com, unpack it to the ../WPBC_PLUGIN_DIR/languages/' folder
735 774 *
775 + * @param WP_Upgrader_Skin|null $skin Optional authorized upgrader skin.
776 + *
736 777 * @return array|bool|string|WP_Error - result
737 778 */
738 - function wpbc_translation_download_from_wpbc(){
779 + function wpbc_translation_download_from_wpbc( $skin = null ){
739 780
740 - $my_upgrader = wpbc_get_translation_upgrader_obj();
781 + $my_upgrader = wpbc_get_translation_upgrader_obj( $skin );
741 782
742 783 $result = $my_upgrader->run( array(
743 784 'package' => 'https://wpbookingcalendar.com/download/languages/languages.zip', // Please always pass this.
744 785 'destination' => WPBC_PLUGIN_DIR . '/languages/', // WPBC_PLUGIN_DIR . '/lang/', // ...and this.
@@ -755,11 +796,13 @@
755 796
756 797 /**
757 798 * Get translation Upgrader object
758 799 *
800 + * @param WP_Upgrader_Skin|null $skin Optional authorized upgrader skin.
801 + *
759 802 * @return WP_Upgrader obj
760 803 */
761 - function wpbc_get_translation_upgrader_obj(){
804 + function wpbc_get_translation_upgrader_obj( $skin = null ){
762 805
763 806 require_once ABSPATH . 'wp-admin/includes/file.php';
764 807 require_once ABSPATH . 'wp-admin/includes/plugin.php';
765 808 require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
@@ -765,11 +808,13 @@
765 808 require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
766 809 require_once ABSPATH . 'wp-admin/includes/plugin-install.php';
767 810
768 811 require_once WPBC_PLUGIN_DIR . '/core/class/wpbc-class-upgrader-translation-skin.php';
769 - $skin = new WPBC_Upgrader_Translation_Skin(
770 - array( 'skip_header_footer' => true )
771 - );
812 + if ( ! ( $skin instanceof WP_Upgrader_Skin ) ) {
813 + $skin = new WPBC_Upgrader_Translation_Skin(
814 + array( 'skip_header_footer' => true )
815 + );
816 + }
772 817
773 818 $my_upgrader = new WP_Upgrader( $skin );
774 819
775 820 $my_upgrader->init(); // it's required for defining skin messages
@@ -1413,9 +1458,9 @@
1413 1458 * Load translation POT file, and generate PHP file with all translations relative to plugin.
1414 1459 * Link: http://server.com/wp-admin/admin.php?page=wpbc-settings&system_info=show&pot=1#wpbc_general_settings_system_info_metabox
1415 1460 */
1416 1461 function wpbc_pot_to_php() {
1417 -
1462 + return;
1418 1463 /*
1419 1464 * $shortcode = 'wpml';
1420 1465
1421 1466 // Find anything between [wpml] and [/wpml] shortcodes. Magic here: [\s\S]*? - fit to any text