PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | includes/publish/class-wpbc-booking-form-publisher.php +6 -73 11.7 → 11.9 View file →
@@ -9,8 +9,10 @@
9 9 if ( ! defined( 'ABSPATH' ) ) {
10 10 exit;
11 11 }
12 12
13 +require_once dirname( __DIR__ ) . '/_functions/class-wpbc-environment-policy.php';
14 +
13 15 /**
14 16 * Publish one Booking Form shortcode into a new or existing WordPress page.
15 17 *
16 18 * This service owns request-independent validation and delegates the canonical
@@ -21,85 +23,16 @@
21 23
22 24 /**
23 25 * Determine whether page publishing must be blocked on this website.
24 26 *
25 - * The configured WordPress home host is the canonical site identity for both
26 - * normal page loads and AJAX mutations. The request host is used only when a
27 - * canonical home host is unavailable, which keeps the decision stable without
28 - * trusting a client-controlled Host header over WordPress configuration.
29 - * Development hosts such as `beta` require no exception because only the
30 - * official wpbookingcalendar.com domain and its subdomains are restricted.
27 + * This compatibility method delegates to the shared environment policy. The
28 + * policy owns host identity, exact public-demo classification, internal test
29 + * exceptions, and the released publishing filter for every consumer.
31 30 *
32 31 * @return bool True when page discovery and page mutations must be blocked.
33 32 */
34 33 public static function is_demo_restricted() {
35 - $request_host = self::get_request_host();
36 - $site_host = self::normalize_host( wp_parse_url( home_url( '/' ), PHP_URL_HOST ) );
37 - $canonical_host = '' !== $site_host ? $site_host : $request_host;
38 - $official_demo_host = self::is_official_demo_host( $canonical_host );
39 -
40 - /**
41 - * Filter whether neutral Booking Form publishing is restricted as a live demo.
42 - *
43 - * @since 11.6.0
44 - *
45 - * @param bool $official_demo_host Whether the current host is restricted.
46 - * @param string $site_host Normalized WordPress home URL host.
47 - * @param string $request_host Normalized current request host used only as a fallback.
48 - */
49 - return (bool) apply_filters( 'wpbc_publish_booking_form_is_demo_restricted', $official_demo_host, $site_host, $request_host );
50 - }
51 -
52 - /**
53 - * Read the current HTTP request host without trusting proxy-only headers.
54 - *
55 - * This value is a fallback for unusual environments where WordPress cannot
56 - * provide a configured home hostname. It never overrides a valid canonical
57 - * WordPress site host.
58 - *
59 - * @return string Normalized request host, or an empty string outside HTTP.
60 - */
61 - private static function get_request_host() {
62 - if ( empty( $_SERVER['HTTP_HOST'] ) ) {
63 - return '';
64 - }
65 -
66 - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- normalize_host() validates and reduces this value to a hostname.
67 - return self::normalize_host( wp_unslash( $_SERVER['HTTP_HOST'] ) );
68 - }
69 -
70 - /**
71 - * Normalize a URL or HTTP Host value to a lowercase hostname.
72 - *
73 - * @param mixed $host Hostname, optionally including a port.
74 - *
75 - * @return string Normalized hostname, or an empty string when invalid.
76 - */
77 - private static function normalize_host( $host ) {
78 - $host = trim( strtolower( (string) $host ) );
79 - if ( '' === $host ) {
80 - return '';
81 - }
82 -
83 - $normalized_host = wp_parse_url( 'http://' . ltrim( $host, '/' ), PHP_URL_HOST );
84 - if ( ! is_string( $normalized_host ) ) {
85 - return '';
86 - }
87 -
88 - return untrailingslashit( strtolower( rtrim( $normalized_host, '.' ) ) );
89 - }
90 -
91 - /**
92 - * Determine whether a normalized host belongs to the public demo network.
93 - *
94 - * @param string $host Normalized hostname.
95 - *
96 - * @return bool True for wpbookingcalendar.com and its subdomains.
97 - */
98 - private static function is_official_demo_host( $host ) {
99 - return 'wpbookingcalendar.com' === $host
100 - || ( strlen( $host ) > strlen( '.wpbookingcalendar.com' )
101 - && '.wpbookingcalendar.com' === substr( $host, -strlen( '.wpbookingcalendar.com' ) ) );
34 + return WPBC_Environment_Policy::is_page_publishing_restricted();
102 35 }
103 36
104 37 /**
105 38 * Publish a normalized Booking Form request.