| @@ -223,8 +223,39 @@ | ||
| 223 | 223 | } |
| 224 | 224 | |
| 225 | 225 | |
| 226 | 226 | /** |
| 227 | + * Validate a locale received from a request. | |
| 228 | + * | |
| 229 | + * Locale values are used request-wide and can later be rendered inside JavaScript and HTML attributes. Accept only | |
| 230 | + * ASCII locale identifiers, such as "en", "en_US", "de_DE_formal", or "en-US". Invalid values must be rejected | |
| 231 | + * instead of sanitized into a different value. // FixIn: 11.4.3.2. | |
| 232 | + * | |
| 233 | + * @param mixed $locale Locale value from the request. | |
| 234 | + * | |
| 235 | + * @return string|false Valid locale, or false when the value is invalid. | |
| 236 | + */ | |
| 237 | +function wpbc_validate_request_locale( $locale ) { | |
| 238 | + | |
| 239 | + if ( ! is_string( $locale ) ) { | |
| 240 | + return false; | |
| 241 | + } | |
| 242 | + | |
| 243 | + $locale = wp_unslash( $locale ); | |
| 244 | + | |
| 245 | + if ( | |
| 246 | + ( '' === $locale ) | |
| 247 | + || ( strlen( $locale ) > 32 ) | |
| 248 | + || ( 1 !== preg_match( '/\A[A-Za-z0-9]+(?:[_-][A-Za-z0-9]+)*\z/D', $locale ) ) | |
| 249 | + ) { | |
| 250 | + return false; | |
| 251 | + } | |
| 252 | + | |
| 253 | + return $locale; | |
| 254 | +} | |
| 255 | + | |
| 256 | + | |
| 257 | +/** | |
| 227 | 258 | * Get maybe reloaded 'booking' locale ( WPBC_LOCALE_RELOAD ) and if not defined WPBC_LOCALE_RELOAD define it. |
| 228 | 259 | * |
| 229 | 260 | * @return string |
| 230 | 261 | */ |
| @@ -260,15 +291,15 @@ | ||
| 260 | 291 | |
| 261 | 292 | $wpbc_ajx_locale = false; |
| 262 | 293 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing |
| 263 | 294 | if ( isset( $_REQUEST['wpdev_active_locale'] ) ) { |
| 264 | - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.NonceVerification.Recommended | |
| 265 | - $wpbc_ajx_locale = sanitize_text_field( $_REQUEST['wpdev_active_locale'] ); | |
| 295 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended | |
| 296 | + $wpbc_ajx_locale = wpbc_validate_request_locale( $_REQUEST['wpdev_active_locale'] ); | |
| 266 | 297 | } |
| 267 | 298 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing |
| 268 | 299 | if ( isset( $_REQUEST['wpbc_ajx_locale'] ) ) { |
| 269 | - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.NonceVerification.Recommended | |
| 270 | - $wpbc_ajx_locale = sanitize_text_field( $_REQUEST['wpbc_ajx_locale'] ); | |
| 300 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended | |
| 301 | + $wpbc_ajx_locale = wpbc_validate_request_locale( $_REQUEST['wpbc_ajx_locale'] ); | |
| 271 | 302 | } |
| 272 | 303 | |
| 273 | 304 | // Reload locale ONLY in AJAX, and if `isset $_REQUEST['wpdev_active_locale'] |
| 274 | 305 | if ( |
| @@ -378,11 +409,11 @@ | ||
| 378 | 409 | |
| 379 | 410 | /** |
| 380 | 411 | * Translate content. Check for language sections -- [lang=xx_XX] shortcode. // FixIn: 10.0.0.46. |
| 381 | 412 | * |
| 382 | - * @param $content_orig | |
| 413 | + * @param mixed $content_orig Content containing optional language sections. | |
| 383 | 414 | * |
| 384 | - * @return string | |
| 415 | + * @return string Translated content, or an empty string for unsupported values. | |
| 385 | 416 | */ |
| 386 | 417 | function wpbc_lang( $content_orig ) { |
| 387 | 418 | return wpdev_check_for_active_language( $content_orig ); |
| 388 | 419 | } |
| @@ -390,23 +421,31 @@ | ||
| 390 | 421 | |
| 391 | 422 | /** |
| 392 | 423 | * Check plugin text for active language section -- [lang=xx_XX] shortcode |
| 393 | 424 | * |
| 394 | - * @param string $content_orig | |
| 395 | - * @return string | |
| 425 | + * @param mixed $content_orig Content containing optional language sections. | |
| 426 | + * @return string Translated content, or an empty string for unsupported values. | |
| 396 | 427 | * Usage: |
| 397 | 428 | * $text = wpbc_lang( $text ); |
| 398 | 429 | */ |
| 399 | 430 | function wpdev_check_for_active_language( $content_orig ) { // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound |
| 400 | 431 | |
| 401 | - $content = $content_orig; | |
| 432 | + if ( is_string( $content_orig ) ) { | |
| 433 | + $content = $content_orig; | |
| 434 | + } elseif ( is_scalar( $content_orig ) ) { | |
| 435 | + $content = (string) $content_orig; | |
| 436 | + } elseif ( is_object( $content_orig ) && method_exists( $content_orig, '__toString' ) ) { | |
| 437 | + $content = (string) $content_orig; | |
| 438 | + } else { | |
| 439 | + return ''; | |
| 440 | + } | |
| 402 | 441 | |
| 403 | - $languages = array(); | |
| 404 | - $content_ex = explode('[lang',$content); | |
| 442 | + $languages = array(); | |
| 443 | + $content_ex = explode( '[lang', $content ); | |
| 405 | 444 | |
| 406 | 445 | foreach ( $content_ex as $value ) { |
| 407 | 446 | |
| 408 | - if ( '=' == substr( $value, 0, 1 ) ) { | |
| 447 | + if ( '=' === substr( $value, 0, 1 ) ) { | |
| 409 | 448 | |
| 410 | 449 | $pos_s = strpos( $value, '=' ); |
| 411 | 450 | $pos_f = strpos( $value, ']' ); |
| 412 | 451 | $key = trim( substr( $value, ( $pos_s + 1 ), ( $pos_f - $pos_s - 1 ) ) ); |
| @@ -417,9 +456,9 @@ | ||
| 417 | 456 | $languages['default'] = $value; |
| 418 | 457 | } |
| 419 | 458 | } |
| 420 | 459 | |
| 421 | - $locale = wpbc_get_maybe_reloaded_booking_locale(); // $locale = 'fr_FR'; | |
| 460 | + $locale = wpbc_get_maybe_reloaded_booking_locale(); // $locale = 'fr_FR'. | |
| 422 | 461 | |
| 423 | 462 | if ( isset( $languages[ $locale ] ) ) { |
| 424 | 463 | $return_text = $languages[ $locale ]; |
| 425 | 464 | } else { |
| @@ -732,13 +771,15 @@ | ||
| 732 | 771 | |
| 733 | 772 | /** |
| 734 | 773 | * Download translations from wpbookingcalendar.com, unpack it to the ../WPBC_PLUGIN_DIR/languages/' folder |
| 735 | 774 | * |
| 775 | + * @param WP_Upgrader_Skin|null $skin Optional authorized upgrader skin. | |
| 776 | + * | |
| 736 | 777 | * @return array|bool|string|WP_Error - result |
| 737 | 778 | */ |
| 738 | - function wpbc_translation_download_from_wpbc(){ | |
| 779 | + function wpbc_translation_download_from_wpbc( $skin = null ){ | |
| 739 | 780 | |
| 740 | - $my_upgrader = wpbc_get_translation_upgrader_obj(); | |
| 781 | + $my_upgrader = wpbc_get_translation_upgrader_obj( $skin ); | |
| 741 | 782 | |
| 742 | 783 | $result = $my_upgrader->run( array( |
| 743 | 784 | 'package' => 'https://wpbookingcalendar.com/download/languages/languages.zip', // Please always pass this. |
| 744 | 785 | 'destination' => WPBC_PLUGIN_DIR . '/languages/', // WPBC_PLUGIN_DIR . '/lang/', // ...and this. |
| @@ -755,11 +796,13 @@ | ||
| 755 | 796 | |
| 756 | 797 | /** |
| 757 | 798 | * Get translation Upgrader object |
| 758 | 799 | * |
| 800 | + * @param WP_Upgrader_Skin|null $skin Optional authorized upgrader skin. | |
| 801 | + * | |
| 759 | 802 | * @return WP_Upgrader obj |
| 760 | 803 | */ |
| 761 | - function wpbc_get_translation_upgrader_obj(){ | |
| 804 | + function wpbc_get_translation_upgrader_obj( $skin = null ){ | |
| 762 | 805 | |
| 763 | 806 | require_once ABSPATH . 'wp-admin/includes/file.php'; |
| 764 | 807 | require_once ABSPATH . 'wp-admin/includes/plugin.php'; |
| 765 | 808 | require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php'; |
| @@ -765,11 +808,13 @@ | ||
| 765 | 808 | require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php'; |
| 766 | 809 | require_once ABSPATH . 'wp-admin/includes/plugin-install.php'; |
| 767 | 810 | |
| 768 | 811 | require_once WPBC_PLUGIN_DIR . '/core/class/wpbc-class-upgrader-translation-skin.php'; |
| 769 | - $skin = new WPBC_Upgrader_Translation_Skin( | |
| 770 | - array( 'skip_header_footer' => true ) | |
| 771 | - ); | |
| 812 | + if ( ! ( $skin instanceof WP_Upgrader_Skin ) ) { | |
| 813 | + $skin = new WPBC_Upgrader_Translation_Skin( | |
| 814 | + array( 'skip_header_footer' => true ) | |
| 815 | + ); | |
| 816 | + } | |
| 772 | 817 | |
| 773 | 818 | $my_upgrader = new WP_Upgrader( $skin ); |
| 774 | 819 | |
| 775 | 820 | $my_upgrader->init(); // it's required for defining skin messages |
| @@ -1413,9 +1458,9 @@ | ||
| 1413 | 1458 | * Load translation POT file, and generate PHP file with all translations relative to plugin. |
| 1414 | 1459 | * Link: http://server.com/wp-admin/admin.php?page=wpbc-settings&system_info=show&pot=1#wpbc_general_settings_system_info_metabox |
| 1415 | 1460 | */ |
| 1416 | 1461 | function wpbc_pot_to_php() { |
| 1417 | - | |
| 1462 | + return; | |
| 1418 | 1463 | /* |
| 1419 | 1464 | * $shortcode = 'wpml'; |
| 1420 | 1465 | |
| 1421 | 1466 | // Find anything between [wpml] and [/wpml] shortcodes. Magic here: [\s\S]*? - fit to any text |