PluginProbe
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce / 3.3.0
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce v3.3.0
3.3.0 3.2.1 3.2.0 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 3.0.1 trunk 1.0.4 1.1.0 1.1.0.1 1.1.1 1.1.10 1.1.11 1.1.12 1.1.13 1.1.14 1.1.15 1.1.16 1.1.17 1.1.18 1.1.19 1.1.2 All 162 releases
← All changes | admin-core/ajax/common-settings.php +28 -0 3.2.0 → 3.3.0 View file →
@@ -41,8 +41,15 @@
41 41 */
42 42 private $pending_redirect = '';
43 43
44 44 /**
45 + * Fields the save skipped because the user lacks `unfiltered_html`.
46 + *
47 + * @var array<int, string>
48 + */
49 + private $skipped_fields = array();
50 +
51 + /**
45 52 * Initiator
46 53 *
47 54 * @since 1.0.0
48 55 * @return object initialized object of class.
@@ -168,8 +175,19 @@
168 175 $response_data = array(
169 176 'messsage' => __( 'Successfully saved data!', 'cartflows' ),
170 177 );
171 178
179 + // Name the fields that were dropped so the UI can say so rather than
180 + // reporting a clean save the user did not get.
181 + if ( ! empty( $this->skipped_fields ) ) {
182 + $response_data['skipped_fields'] = $this->skipped_fields;
183 + $response_data['messsage'] = sprintf(
184 + /* translators: %s: comma separated list of setting names. */
185 + __( 'Saved, but these were not updated because your account cannot edit scripts: %s', 'cartflows' ),
186 + implode( ', ', $this->skipped_fields )
187 + );
188 + }
189 +
172 190 // If a tab handler queued a redirect (e.g. legacy-admin toggle was just
173 191 // enabled), pass it through so the client hard-navigates after save.
174 192 if ( ! empty( $this->pending_redirect ) ) {
175 193 $response_data['redirect_to'] = $this->pending_redirect;
@@ -249,9 +267,19 @@
249 267 }
250 268
251 269 // Global CSS/JS are output raw on every CartFlows page. Restrict authoring to users
252 270 // with `unfiltered_html` so per-plugin caps cannot grant script write access to lower roles.
271 + // Record what was dropped — returning silently here let save_global_settings() go on
272 + // to report a success the user did not get.
253 273 if ( ! current_user_can( 'unfiltered_html' ) ) {
274 + if ( isset( $_POST['_cartflows_global_scripts']['global_css'] ) ) { //phpcs:ignore WordPress.Security.NonceVerification.Missing
275 + $this->skipped_fields[] = __( 'Global CSS', 'cartflows' );
276 + }
277 +
278 + if ( isset( $_POST['_cartflows_global_scripts']['global_js'] ) ) { //phpcs:ignore WordPress.Security.NonceVerification.Missing
279 + $this->skipped_fields[] = __( 'Global JS', 'cartflows' );
280 + }
281 +
254 282 return;
255 283 }
256 284
257 285 if ( isset( $_POST['_cartflows_global_scripts'] ) ) { //phpcs:ignore WordPress.Security.NonceVerification.Missing