PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | includes/page-add-booking/add_booking__component.php +71 -20 11.5 → 11.9 View file →
@@ -18,9 +18,9 @@
18 18 * Check if current user can access the Add Booking workflow.
19 19 *
20 20 * @return bool
21 21 */
22 - public static function current_user_can_add_booking() {
22 + public static function current_user_can_add_booking() {
23 23
24 24 $user_role = get_bk_option( 'booking_user_role_addbooking' );
25 25 $cap = 'read';
26 26
@@ -29,10 +29,35 @@
29 29 } elseif ( class_exists( 'WPBC_Admin_Menus' ) && isset( WPBC_Admin_Menus::$capability['subscriber'] ) ) {
30 30 $cap = WPBC_Admin_Menus::$capability['subscriber'];
31 31 }
32 32
33 - return current_user_can( $cap );
34 - }
33 + return current_user_can( $cap );
34 + }
35 +
36 +
37 + /**
38 + * Create the administrator booking nonce for an authorized page context.
39 + *
40 + * The public booking endpoint accepts signed-out requests, so administrator
41 + * behavior must be enabled by a user-bound nonce and the same capability and
42 + * MultiUser checks that the server repeats during booking creation.
43 + *
44 + * @return string Administrator booking nonce, or an empty string when the
45 + * current user cannot use the administrator booking workflow.
46 + */
47 + public static function get_admin_booking_nonce() {
48 +
49 + if (
50 + ! is_user_logged_in()
51 + || ! self::current_user_can_add_booking()
52 + || ! function_exists( 'wpbc_is_mu_user_can_be_here' )
53 + || ! wpbc_is_mu_user_can_be_here( 'activated_user' )
54 + ) {
55 + return '';
56 + }
57 +
58 + return wp_create_nonce( 'wpbc_admin_booking_create' );
59 + }
35 60
36 61 /**
37 62 * Render the component and echo by default.
38 63 *
@@ -191,14 +216,15 @@
191 216 * @param array $args Component options.
192 217 *
193 218 * @return void
194 219 */
195 - private static function print_context_js( $args ) {
196 -
197 - $booking_hash = isset( $args['booking_hash'] ) ? (string) $args['booking_hash'] : '';
198 - $allow_past_date_arr = self::get_allow_past_min_date_arr( $args );
199 - $context = array(
200 - 'resource_id' => absint( $args['resource_id'] ),
220 + private static function print_context_js( $args ) {
221 +
222 + $booking_hash = isset( $args['booking_hash'] ) ? (string) $args['booking_hash'] : '';
223 + $admin_booking_nonce = self::get_admin_booking_nonce();
224 + $allow_past_date_arr = self::get_allow_past_min_date_arr( $args );
225 + $context = array(
226 + 'resource_id' => absint( $args['resource_id'] ),
201 227 'selected_dates_without_calendar' => (string) $args['selected_dates_without_calendar'],
202 228 'selected_dates' => (string) $args['selected_dates'],
203 229 'selected_date' => (string) $args['selected_date'],
204 230 'selected_time' => (string) $args['selected_time'],
@@ -205,19 +231,44 @@
205 231 'time_override_enabled' => absint( $args['time_override_enabled'] ),
206 232 'time_override_source' => (string) $args['time_override_source'],
207 233 'time_override_start' => (string) $args['time_override_start'],
208 234 'time_override_end' => (string) $args['time_override_end'],
209 - 'allow_past' => ! empty( $args['allow_past'] ) ? 1 : 0,
210 - );
211 - ?>
212 - <script type="text/javascript">
213 - window.wpbc_add_booking_component_context = <?php echo wp_json_encode( $context ); ?>;
214 - if ( 'undefined' !== typeof _wpbc ) {
215 - _wpbc.set_other_param( 'this_page_booking_hash', <?php echo wp_json_encode( $booking_hash ); ?> );
216 - _wpbc.set_other_param( 'this_page_allow_past', <?php echo wp_json_encode( ! empty( $args['allow_past'] ) ? 1 : 0 ); ?> );
217 - _wpbc.set_other_param( 'this_page_allow_past_arr', <?php echo wp_json_encode( $allow_past_date_arr ); ?> );
218 - }
219 - </script>
235 + 'allow_past' => ! empty( $args['allow_past'] ) ? 1 : 0,
236 + );
237 + $booking_context_js = "_wpbc.set_other_param( 'this_page_booking_hash', " . wp_json_encode( $booking_hash ) . ' );';
238 + $booking_context_js .= "_wpbc.set_other_param( 'this_page_allow_past', " . wp_json_encode( ! empty( $args['allow_past'] ) ? 1 : 0 ) . ' );';
239 + $booking_context_js .= "_wpbc.set_other_param( 'this_page_allow_past_arr', " . wp_json_encode( $allow_past_date_arr ) . ' );';
240 + $booking_context_js .= "_wpbc.set_other_param( 'this_page_admin_booking_nonce', " . wp_json_encode( $admin_booking_nonce ) . ' );';
241 +
242 + $is_context_queued = false;
243 + if ( ! wp_doing_ajax() && class_exists( 'WPBC_FE_Assets' ) ) {
244 + $is_context_queued = WPBC_FE_Assets::add_jq_ready_js_to_wp_script(
245 + 'wpbc_all',
246 + $booking_context_js,
247 + 'wpbc:add-booking-admin-context:' . md5( $booking_context_js )
248 + );
249 + }
250 + ?>
251 + <script type="text/javascript">
252 + window.wpbc_add_booking_component_context = <?php echo wp_json_encode( $context ); ?>;
253 + <?php if ( ! $is_context_queued ) : ?>
254 + ( function () {
255 + function apply_booking_context() {
256 + if ( 'undefined' === typeof _wpbc ) {
257 + return;
258 + }
259 +
260 + <?php echo $booking_context_js; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Values are JSON encoded above. ?>
261 + }
262 +
263 + if ( 'undefined' !== typeof _wpbc ) {
264 + apply_booking_context();
265 + } else {
266 + document.addEventListener( 'DOMContentLoaded', apply_booking_context );
267 + }
268 + }() );
269 + <?php endif; ?>
270 + </script>
220 271 <?php
221 272 }
222 273
223 274