PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | includes/page-add-booking/add_booking__component.php +67 -18 11.8 → 11.9 View file →
@@ -18,9 +18,9 @@
18 18 * Check if current user can access the Add Booking workflow.
19 19 *
20 20 * @return bool
21 21 */
22 - public static function current_user_can_add_booking() {
22 + public static function current_user_can_add_booking() {
23 23
24 24 $user_role = get_bk_option( 'booking_user_role_addbooking' );
25 25 $cap = 'read';
26 26
@@ -29,10 +29,35 @@
29 29 } elseif ( class_exists( 'WPBC_Admin_Menus' ) && isset( WPBC_Admin_Menus::$capability['subscriber'] ) ) {
30 30 $cap = WPBC_Admin_Menus::$capability['subscriber'];
31 31 }
32 32
33 - return current_user_can( $cap );
34 - }
33 + return current_user_can( $cap );
34 + }
35 +
36 +
37 + /**
38 + * Create the administrator booking nonce for an authorized page context.
39 + *
40 + * The public booking endpoint accepts signed-out requests, so administrator
41 + * behavior must be enabled by a user-bound nonce and the same capability and
42 + * MultiUser checks that the server repeats during booking creation.
43 + *
44 + * @return string Administrator booking nonce, or an empty string when the
45 + * current user cannot use the administrator booking workflow.
46 + */
47 + public static function get_admin_booking_nonce() {
48 +
49 + if (
50 + ! is_user_logged_in()
51 + || ! self::current_user_can_add_booking()
52 + || ! function_exists( 'wpbc_is_mu_user_can_be_here' )
53 + || ! wpbc_is_mu_user_can_be_here( 'activated_user' )
54 + ) {
55 + return '';
56 + }
57 +
58 + return wp_create_nonce( 'wpbc_admin_booking_create' );
59 + }
35 60
36 61 /**
37 62 * Render the component and echo by default.
38 63 *
@@ -194,12 +219,12 @@
194 219 */
195 220 private static function print_context_js( $args ) {
196 221
197 222 $booking_hash = isset( $args['booking_hash'] ) ? (string) $args['booking_hash'] : '';
198 - $admin_booking_nonce = self::current_user_can_add_booking() ? wp_create_nonce( 'wpbc_admin_booking_create' ) : '';
223 + $admin_booking_nonce = self::get_admin_booking_nonce();
199 224 $allow_past_date_arr = self::get_allow_past_min_date_arr( $args );
200 - $context = array(
201 - 'resource_id' => absint( $args['resource_id'] ),
225 + $context = array(
226 + 'resource_id' => absint( $args['resource_id'] ),
202 227 'selected_dates_without_calendar' => (string) $args['selected_dates_without_calendar'],
203 228 'selected_dates' => (string) $args['selected_dates'],
204 229 'selected_date' => (string) $args['selected_date'],
205 230 'selected_time' => (string) $args['selected_time'],
@@ -206,20 +231,44 @@
206 231 'time_override_enabled' => absint( $args['time_override_enabled'] ),
207 232 'time_override_source' => (string) $args['time_override_source'],
208 233 'time_override_start' => (string) $args['time_override_start'],
209 234 'time_override_end' => (string) $args['time_override_end'],
210 - 'allow_past' => ! empty( $args['allow_past'] ) ? 1 : 0,
211 - );
212 - ?>
213 - <script type="text/javascript">
214 - window.wpbc_add_booking_component_context = <?php echo wp_json_encode( $context ); ?>;
215 - if ( 'undefined' !== typeof _wpbc ) {
216 - _wpbc.set_other_param( 'this_page_booking_hash', <?php echo wp_json_encode( $booking_hash ); ?> );
217 - _wpbc.set_other_param( 'this_page_allow_past', <?php echo wp_json_encode( ! empty( $args['allow_past'] ) ? 1 : 0 ); ?> );
218 - _wpbc.set_other_param( 'this_page_allow_past_arr', <?php echo wp_json_encode( $allow_past_date_arr ); ?> );
219 - _wpbc.set_other_param( 'this_page_admin_booking_nonce', <?php echo wp_json_encode( $admin_booking_nonce ); ?> );
220 - }
221 - </script>
235 + 'allow_past' => ! empty( $args['allow_past'] ) ? 1 : 0,
236 + );
237 + $booking_context_js = "_wpbc.set_other_param( 'this_page_booking_hash', " . wp_json_encode( $booking_hash ) . ' );';
238 + $booking_context_js .= "_wpbc.set_other_param( 'this_page_allow_past', " . wp_json_encode( ! empty( $args['allow_past'] ) ? 1 : 0 ) . ' );';
239 + $booking_context_js .= "_wpbc.set_other_param( 'this_page_allow_past_arr', " . wp_json_encode( $allow_past_date_arr ) . ' );';
240 + $booking_context_js .= "_wpbc.set_other_param( 'this_page_admin_booking_nonce', " . wp_json_encode( $admin_booking_nonce ) . ' );';
241 +
242 + $is_context_queued = false;
243 + if ( ! wp_doing_ajax() && class_exists( 'WPBC_FE_Assets' ) ) {
244 + $is_context_queued = WPBC_FE_Assets::add_jq_ready_js_to_wp_script(
245 + 'wpbc_all',
246 + $booking_context_js,
247 + 'wpbc:add-booking-admin-context:' . md5( $booking_context_js )
248 + );
249 + }
250 + ?>
251 + <script type="text/javascript">
252 + window.wpbc_add_booking_component_context = <?php echo wp_json_encode( $context ); ?>;
253 + <?php if ( ! $is_context_queued ) : ?>
254 + ( function () {
255 + function apply_booking_context() {
256 + if ( 'undefined' === typeof _wpbc ) {
257 + return;
258 + }
259 +
260 + <?php echo $booking_context_js; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Values are JSON encoded above. ?>
261 + }
262 +
263 + if ( 'undefined' !== typeof _wpbc ) {
264 + apply_booking_context();
265 + } else {
266 + document.addEventListener( 'DOMContentLoaded', apply_booking_context );
267 + }
268 + }() );
269 + <?php endif; ?>
270 + </script>
222 271 <?php
223 272 }
224 273
225 274