PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | includes/_functions/admin_menu_url.php +177 -61 11.3 → 11.9 View file →
@@ -1,4 +1,4 @@
1 1 <?php
2 2 /**
3 3 * @version 1.0
4 4 * @package Booking Calendar
@@ -59,27 +59,32 @@
59 59
60 60 return $maybe_absolute_link;
61 61 }
62 62
63 -/**
64 - * Get Absolute URL (check for languages)
65 - *
66 - * @param $maybe_relative_link
67 - *
68 - * @return string
69 - */
70 -function wpbc_make_link_absolute( $maybe_relative_link ){
63 +/**
64 + * Convert a relative front-end path to an absolute language-aware URL.
65 + *
66 + * The path is passed through WordPress so multilingual URL filters can apply
67 + * the current language directory or domain without introducing duplicate
68 + * path separators.
69 + *
70 + * @param string $maybe_relative_link Relative or absolute front-end URL.
71 + *
72 + * @return string JavaScript-safe absolute URL.
73 + */
74 +function wpbc_make_link_absolute( $maybe_relative_link ){
75 +
76 + if ( ( $maybe_relative_link != home_url() ) && ( strpos( $maybe_relative_link, 'http' ) !== 0 ) ) {
77 +
78 + $maybe_relative_link = wpbc_lang( $maybe_relative_link ); // FixIn: 8.4.5.1.
79 +
80 + $relative_path = trim( wp_make_link_relative( $maybe_relative_link ), '/' );
81 + $maybe_relative_link = home_url( '/' . $relative_path );
82 + }
83 +
84 + return esc_js( $maybe_relative_link );
85 +}
71 86
72 - if ( ( $maybe_relative_link != home_url() ) && ( strpos( $maybe_relative_link, 'http' ) !== 0 ) ) {
73 -
74 - $maybe_relative_link = wpbc_lang( $maybe_relative_link ); // FixIn: 8.4.5.1.
75 -
76 - $maybe_relative_link = home_url() . '/' . trim( wp_make_link_relative( $maybe_relative_link ), '/' ); // FixIn: 7.0.1.20.
77 - }
78 -
79 - return esc_js( $maybe_relative_link );
80 -}
81 -
82 87 /**
83 88 * Redirect browser to a specific page
84 89 *
85 90 * @param string $url - URL of page to redirect
@@ -269,14 +274,83 @@
269 274 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
270 275 * @param boolean $is_old - { default: true }
271 276 * @return string - URL to menu
272 277 */
273 -function wpbc_get_new_booking_url( $is_absolute_url = true, $is_old = true ) {
274 - return wpbc_get_menu_url( 'add', $is_absolute_url, $is_old );
275 -}
276 -
277 -/**
278 - * Get URL of Booking > Resources page
278 +function wpbc_get_new_booking_url( $is_absolute_url = true, $is_old = true ) {
279 + return wpbc_get_menu_url( 'add', $is_absolute_url, $is_old );
280 +}
281 +
282 +/**
283 + * Get the normalized administrator edit-booking destination.
284 + *
285 + * Existing installations and malformed stored values retain the popup workflow.
286 + * The optional argument keeps normalization independently testable without
287 + * changing a saved WordPress option.
288 + *
289 + * @param null|string $stored_mode Optional stored mode. Null loads the site option.
290 + *
291 + * @return string Either `popup` or `add_booking_page`.
292 + */
293 +function wpbc_get_booking_admin_edit_mode( $stored_mode = null ) {
294 +
295 + if ( null === $stored_mode ) {
296 + $stored_mode = get_bk_option( 'booking_admin_edit_booking_mode' );
297 + }
298 +
299 + $stored_mode = sanitize_key( (string) $stored_mode );
300 +
301 + return in_array( $stored_mode, array( 'popup', 'add_booking_page' ), true ) ? $stored_mode : 'popup';
302 +}
303 +
304 +/**
305 + * Check whether administrator edit links should open the dedicated Add Booking page.
306 + *
307 + * @param null|string $stored_mode Optional stored mode used for independent testing.
308 + *
309 + * @return bool True for the dedicated page; false for the default popup.
310 + */
311 +function wpbc_is_booking_admin_edit_page_enabled( $stored_mode = null ) {
312 + return 'add_booking_page' === wpbc_get_booking_admin_edit_mode( $stored_mode );
313 +}
314 +
315 +/**
316 + * Build the authorized administrator URL for editing one Booking on Add Booking.
317 + *
318 + * The destination page retains its existing capability, MultiUser ownership,
319 + * Booking hash, Resource, and Booking Form checks. This helper only centralizes
320 + * the released URL contract used by Booking Listing and Timeline links.
321 + *
322 + * @param int $resource_id Booking Resource ID.
323 + * @param string $booking_hash Booking edit hash.
324 + * @param string $booking_form Optional custom Booking Form name.
325 + *
326 + * @return string Sanitized Add Booking edit URL, or an empty string when required values are missing.
327 + */
328 +function wpbc_get_booking_admin_edit_url( $resource_id, $booking_hash, $booking_form = '' ) {
329 +
330 + $resource_id = absint( $resource_id );
331 + $booking_hash = sanitize_text_field( (string) $booking_hash );
332 + $booking_form = sanitize_text_field( (string) $booking_form );
333 +
334 + if ( $resource_id < 1 || '' === $booking_hash ) {
335 + return '';
336 + }
337 +
338 + $query_args = array(
339 + 'booking_type' => $resource_id,
340 + 'booking_hash' => $booking_hash,
341 + 'parent_res' => 1,
342 + );
343 +
344 + if ( '' !== $booking_form ) {
345 + $query_args['booking_form'] = $booking_form;
346 + }
347 +
348 + return esc_url_raw( add_query_arg( $query_args, wpbc_get_new_booking_url( true, false ) ) );
349 +}
350 +
351 +/**
352 + * Get URL of Booking > Resources page
279 353 *
280 354 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
281 355 * @param boolean $is_old - { default: true }
282 356 * @return string - URL to menu
@@ -324,20 +398,37 @@
324 398 * @param boolean $is_absolute_url - Absolute or relative url { default: true }
325 399 * @param boolean $is_old - { default: true }
326 400 * @return string - URL to menu
327 401 */
328 -function wpbc_get_settings_themes_url( $is_absolute_url = true, $is_old = true ) {
329 - return wpbc_get_settings_url( $is_absolute_url, $is_old ) . '&tab=themes';
330 -}
402 +function wpbc_get_settings_themes_url( $is_absolute_url = true, $is_old = true ) {
403 + return wpbc_get_settings_url( $is_absolute_url, $is_old ) . '&tab=themes';
404 +}
405 +
406 +/**
407 + * Get URL of Booking > Settings > Form Messages page.
408 + *
409 + * @param boolean $is_absolute_url Absolute or relative URL.
410 + * @param boolean $is_old Legacy menu URL style.
411 + * @return string
412 + */
413 +function wpbc_get_settings_messages_url( $is_absolute_url = true, $is_old = true ) {
414 + return wpbc_get_settings_url( $is_absolute_url, $is_old ) . '&tab=form_messages';
415 +}
331 416
332 417 /**
333 - * Get URL of Booking > Setup page
334 - *
335 - * @param boolean $is_absolute_url - Absolute or relative url { default: true }
336 - * @param boolean $is_old - { default: true }
337 - * @return string - URL to menu
338 - */
339 -function wpbc_get_setup_wizard_page_url( $is_absolute_url = true, $is_old = true ) {
418 + * Get the canonical production Setup Wizard URL.
419 + *
420 + * Opening this URL never restarts or completes a checkpoint. The page resumes
421 + * an active checkpoint, starts Welcome when no checkpoint exists, or renders
422 + * Setup overview when the checkpoint is complete. A new setup is an explicit,
423 + * nonce-protected action from Setup overview.
424 + *
425 + * @param bool $is_absolute_url Whether to return an absolute administration URL.
426 + * @param bool $is_old Retained compatibility argument; ignored by the native menu URL builder.
427 + *
428 + * @return string Canonical Setup Wizard URL.
429 + */
430 +function wpbc_get_setup_wizard_page_url( $is_absolute_url = true, $is_old = true ) {
340 431 return wpbc_get_menu_url( 'setup', $is_absolute_url, $is_old );
341 432 }
342 433
343 434
@@ -429,16 +520,24 @@
429 520 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
430 521 *
431 522 * @return boolean true | false
432 523 */
433 -function wpbc_is_settings_form_page( $server_param = 'REQUEST_URI' ) {
434 - // Regular user overwrite settings.
524 +function wpbc_is_settings_form_page( $server_param = 'REQUEST_URI' ) {
525 + // Regular user overwrite settings.
526 +
527 + // Match the legacy `form` tab exactly. A substring check also matched newer
528 + // tabs whose names start with `form`, such as `form_messages`.
529 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
530 + $request_uri = ! empty( $_SERVER[ $server_param ] ) ? (string) $_SERVER[ $server_param ] : '';
531 + $is_form_tab = (bool) preg_match( '/(?:[?&])tab=form(?:&|$)/', $request_uri );
532 +
533 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
534 + $is_multiuser_form_tab = class_exists( 'wpdev_bk_multiuser' ) && ! empty( $_REQUEST['tab'] ) && 'form' === $_REQUEST['tab'];
535 +
536 + if ( is_admin() && false !== strpos( $request_uri, 'page=wpbc-settings' ) && ( $is_form_tab || $is_multiuser_form_tab ) ) {
537 + return true;
538 + }
435 539
436 - // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
437 - if ( ( is_admin() ) && ( strpos( $_SERVER[ $server_param ], 'page=wpbc-settings' ) !== false ) && ( ( strpos( $_SERVER[ $server_param ], '&tab=form' ) !== false ) || ( ( class_exists( 'wpdev_bk_multiuser' ) ) && ( ! empty( $_REQUEST['tab'] ) ) && ( 'form' === $_REQUEST['tab'] ) ) ) ) {
438 - return true;
439 - }
440 -
441 540 return false;
442 541 }
443 542
444 543
@@ -485,9 +584,9 @@
485 584 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
486 585 *
487 586 * @return boolean true | false
488 587 */
489 -function wpbc_is_settings_calendar_page( $server_param = 'REQUEST_URI' ) {
588 +function wpbc_is_settings_calendar_page( $server_param = 'REQUEST_URI' ) {
490 589 // Regular user overwrite settings.
491 590
492 591 // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
493 592 if ( ( is_admin() ) && ( false !== strpos( $_SERVER[ $server_param ], 'page=wpbc-settings' ) ) && ( false !== strpos( $_SERVER[ $server_param ], '&tab=calendar_settings' ) ) ) {
@@ -494,9 +593,20 @@
494 593 return true;
495 594 }
496 595
497 596 return false;
498 -}
597 +}
598 +
599 +/**
600 + * Check if this is WP Booking Calendar > Settings > Form Messages.
601 + *
602 + * @param string $server_param Server URL parameter.
603 + * @return boolean
604 + */
605 +function wpbc_is_settings_messages_page( $server_param = 'REQUEST_URI' ) {
606 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
607 + return is_admin() && ! empty( $_SERVER[ $server_param ] ) && false !== strpos( $_SERVER[ $server_param ], 'page=wpbc-settings' ) && false !== strpos( $_SERVER[ $server_param ], '&tab=form_messages' );
608 +}
499 609
500 610 /**
501 611 * Check if this admin page renders a real front-end booking form or calendar preview.
502 612 *
@@ -507,14 +617,16 @@
507 617 return (
508 618 wpbc_is_new_booking_page()
509 619 || wpbc_is_settings_form_page()
510 620 || wpbc_is_settings_themes_page()
511 - || wpbc_is_settings_calendar_page()
512 - || wpbc_is_setup_wizard_page()
513 - || wpbc_is_builder_booking_form_page()
514 - || ( function_exists( 'wpbc_is_add_booking_modal_on_booking_listing_page' ) && wpbc_is_add_booking_modal_on_booking_listing_page() )
515 - );
516 -}
621 + || wpbc_is_settings_calendar_page()
622 + || wpbc_is_settings_messages_page()
623 + || wpbc_is_setup_wizard_page()
624 + || wpbc_is_builder_booking_form_page()
625 + || ( function_exists( 'wpbc_add_appointment_page_is_active' ) && wpbc_add_appointment_page_is_active() )
626 + || ( function_exists( 'wpbc_is_add_booking_modal_on_booking_listing_page' ) && wpbc_is_add_booking_modal_on_booking_listing_page() )
627 + );
628 +}
517 629
518 630 /**
519 631 * Check if this Booking > Availability page
520 632 *
@@ -550,16 +662,20 @@
550 662 return false;
551 663 }
552 664
553 665
554 -/**
555 - * Check if this Booking > Setup page
556 - *
557 - * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
558 - *
559 - * @return boolean true | false
560 - */
561 -function wpbc_is_setup_wizard_page( $server_param = 'REQUEST_URI' ) { // FixIn: 9.8.0.1.
666 +/**
667 + * Check whether the current administration URL belongs to a Booking Calendar setup route.
668 + *
669 + * The prefix match is intentional because the canonical route and its hidden
670 + * compatibility alias share the same stable setup prefix.
671 + *
672 + * @param string $server_param Server field to inspect. Expected values are
673 + * `REQUEST_URI` or `HTTP_REFERER`.
674 + *
675 + * @return bool True for any Booking Calendar setup route; otherwise false.
676 + */
677 +function wpbc_is_setup_wizard_page( $server_param = 'REQUEST_URI' ) { // FixIn: 9.8.0.1.
562 678
563 679 // New.
564 680 // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
565 681 if ( ( is_admin() ) && ( strpos( $_SERVER[ $server_param ], 'page=wpbc-setup' ) !== false ) ) {
@@ -565,12 +681,12 @@
565 681 if ( ( is_admin() ) && ( strpos( $_SERVER[ $server_param ], 'page=wpbc-setup' ) !== false ) ) {
566 682 return true;
567 683 }
568 684
569 - return false;
570 -}
571 -
572 -/**
685 + return false;
686 +}
687 +
688 +/**
573 689 * Check if this Booking > Resources page
574 690 *
575 691 * @param string $server_param - 'REQUEST_URI' | 'HTTP_REFERER' Default: 'REQUEST_URI'
576 692 *