← All changes
|
includes/page-add-booking/add_booking__component.php
+71
-20
11.7
→
11.9
View file →
| @@ -18,9 +18,9 @@ | ||
| 18 | 18 | * Check if current user can access the Add Booking workflow. |
| 19 | 19 | * |
| 20 | 20 | * @return bool |
| 21 | 21 | */ |
| 22 | - public static function current_user_can_add_booking() { | |
| 22 | + public static function current_user_can_add_booking() { | |
| 23 | 23 | |
| 24 | 24 | $user_role = get_bk_option( 'booking_user_role_addbooking' ); |
| 25 | 25 | $cap = 'read'; |
| 26 | 26 | |
| @@ -29,10 +29,35 @@ | ||
| 29 | 29 | } elseif ( class_exists( 'WPBC_Admin_Menus' ) && isset( WPBC_Admin_Menus::$capability['subscriber'] ) ) { |
| 30 | 30 | $cap = WPBC_Admin_Menus::$capability['subscriber']; |
| 31 | 31 | } |
| 32 | 32 | |
| 33 | - return current_user_can( $cap ); | |
| 34 | - } | |
| 33 | + return current_user_can( $cap ); | |
| 34 | + } | |
| 35 | + | |
| 36 | + | |
| 37 | + /** | |
| 38 | + * Create the administrator booking nonce for an authorized page context. | |
| 39 | + * | |
| 40 | + * The public booking endpoint accepts signed-out requests, so administrator | |
| 41 | + * behavior must be enabled by a user-bound nonce and the same capability and | |
| 42 | + * MultiUser checks that the server repeats during booking creation. | |
| 43 | + * | |
| 44 | + * @return string Administrator booking nonce, or an empty string when the | |
| 45 | + * current user cannot use the administrator booking workflow. | |
| 46 | + */ | |
| 47 | + public static function get_admin_booking_nonce() { | |
| 48 | + | |
| 49 | + if ( | |
| 50 | + ! is_user_logged_in() | |
| 51 | + || ! self::current_user_can_add_booking() | |
| 52 | + || ! function_exists( 'wpbc_is_mu_user_can_be_here' ) | |
| 53 | + || ! wpbc_is_mu_user_can_be_here( 'activated_user' ) | |
| 54 | + ) { | |
| 55 | + return ''; | |
| 56 | + } | |
| 57 | + | |
| 58 | + return wp_create_nonce( 'wpbc_admin_booking_create' ); | |
| 59 | + } | |
| 35 | 60 | |
| 36 | 61 | /** |
| 37 | 62 | * Render the component and echo by default. |
| 38 | 63 | * |
| @@ -191,14 +216,15 @@ | ||
| 191 | 216 | * @param array $args Component options. |
| 192 | 217 | * |
| 193 | 218 | * @return void |
| 194 | 219 | */ |
| 195 | - private static function print_context_js( $args ) { | |
| 196 | - | |
| 197 | - $booking_hash = isset( $args['booking_hash'] ) ? (string) $args['booking_hash'] : ''; | |
| 198 | - $allow_past_date_arr = self::get_allow_past_min_date_arr( $args ); | |
| 199 | - $context = array( | |
| 200 | - 'resource_id' => absint( $args['resource_id'] ), | |
| 220 | + private static function print_context_js( $args ) { | |
| 221 | + | |
| 222 | + $booking_hash = isset( $args['booking_hash'] ) ? (string) $args['booking_hash'] : ''; | |
| 223 | + $admin_booking_nonce = self::get_admin_booking_nonce(); | |
| 224 | + $allow_past_date_arr = self::get_allow_past_min_date_arr( $args ); | |
| 225 | + $context = array( | |
| 226 | + 'resource_id' => absint( $args['resource_id'] ), | |
| 201 | 227 | 'selected_dates_without_calendar' => (string) $args['selected_dates_without_calendar'], |
| 202 | 228 | 'selected_dates' => (string) $args['selected_dates'], |
| 203 | 229 | 'selected_date' => (string) $args['selected_date'], |
| 204 | 230 | 'selected_time' => (string) $args['selected_time'], |
| @@ -205,19 +231,44 @@ | ||
| 205 | 231 | 'time_override_enabled' => absint( $args['time_override_enabled'] ), |
| 206 | 232 | 'time_override_source' => (string) $args['time_override_source'], |
| 207 | 233 | 'time_override_start' => (string) $args['time_override_start'], |
| 208 | 234 | 'time_override_end' => (string) $args['time_override_end'], |
| 209 | - 'allow_past' => ! empty( $args['allow_past'] ) ? 1 : 0, | |
| 210 | - ); | |
| 211 | - ?> | |
| 212 | - <script type="text/javascript"> | |
| 213 | - window.wpbc_add_booking_component_context = <?php echo wp_json_encode( $context ); ?>; | |
| 214 | - if ( 'undefined' !== typeof _wpbc ) { | |
| 215 | - _wpbc.set_other_param( 'this_page_booking_hash', <?php echo wp_json_encode( $booking_hash ); ?> ); | |
| 216 | - _wpbc.set_other_param( 'this_page_allow_past', <?php echo wp_json_encode( ! empty( $args['allow_past'] ) ? 1 : 0 ); ?> ); | |
| 217 | - _wpbc.set_other_param( 'this_page_allow_past_arr', <?php echo wp_json_encode( $allow_past_date_arr ); ?> ); | |
| 218 | - } | |
| 219 | - </script> | |
| 235 | + 'allow_past' => ! empty( $args['allow_past'] ) ? 1 : 0, | |
| 236 | + ); | |
| 237 | + $booking_context_js = "_wpbc.set_other_param( 'this_page_booking_hash', " . wp_json_encode( $booking_hash ) . ' );'; | |
| 238 | + $booking_context_js .= "_wpbc.set_other_param( 'this_page_allow_past', " . wp_json_encode( ! empty( $args['allow_past'] ) ? 1 : 0 ) . ' );'; | |
| 239 | + $booking_context_js .= "_wpbc.set_other_param( 'this_page_allow_past_arr', " . wp_json_encode( $allow_past_date_arr ) . ' );'; | |
| 240 | + $booking_context_js .= "_wpbc.set_other_param( 'this_page_admin_booking_nonce', " . wp_json_encode( $admin_booking_nonce ) . ' );'; | |
| 241 | + | |
| 242 | + $is_context_queued = false; | |
| 243 | + if ( ! wp_doing_ajax() && class_exists( 'WPBC_FE_Assets' ) ) { | |
| 244 | + $is_context_queued = WPBC_FE_Assets::add_jq_ready_js_to_wp_script( | |
| 245 | + 'wpbc_all', | |
| 246 | + $booking_context_js, | |
| 247 | + 'wpbc:add-booking-admin-context:' . md5( $booking_context_js ) | |
| 248 | + ); | |
| 249 | + } | |
| 250 | + ?> | |
| 251 | + <script type="text/javascript"> | |
| 252 | + window.wpbc_add_booking_component_context = <?php echo wp_json_encode( $context ); ?>; | |
| 253 | + <?php if ( ! $is_context_queued ) : ?> | |
| 254 | + ( function () { | |
| 255 | + function apply_booking_context() { | |
| 256 | + if ( 'undefined' === typeof _wpbc ) { | |
| 257 | + return; | |
| 258 | + } | |
| 259 | + | |
| 260 | + <?php echo $booking_context_js; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Values are JSON encoded above. ?> | |
| 261 | + } | |
| 262 | + | |
| 263 | + if ( 'undefined' !== typeof _wpbc ) { | |
| 264 | + apply_booking_context(); | |
| 265 | + } else { | |
| 266 | + document.addEventListener( 'DOMContentLoaded', apply_booking_context ); | |
| 267 | + } | |
| 268 | + }() ); | |
| 269 | + <?php endif; ?> | |
| 270 | + </script> | |
| 220 | 271 | <?php |
| 221 | 272 | } |
| 222 | 273 | |
| 223 | 274 | |