PluginProbe
Code Engine – PHP Snippets, AI Functions & Automation for WordPress / 0.4.2
Code Engine – PHP Snippets, AI Functions & Automation for WordPress v0.4.2
0.5.6 0.5.5 0.5.4 0.5.3 0.5.2 0.5.1 0.5.0 0.4.9 0.4.8 0.4.7 0.4.6 trunk 0.0.1 0.0.2 0.2.8 0.2.9 0.3.0 0.3.1 0.3.2 0.3.3 0.3.4 0.3.5 0.3.6 0.3.7 0.3.8 All 32 releases
← All changes | classes/core.php +791 -667 0.3.00.4.2 View file →
@@ -6,828 +6,952 @@
6 6 use PhpParser\Error;
7 7
8 8 class Meow_MWCODE_Core
9 9 {
10 - public $admin = null;
11 - public $snippet = null;
12 - public $is_rest = false;
13 - public $is_cli = false;
14 - public $site_url = null;
15 - public $mwcode = null;
10 + public $admin = null;
11 + public $snippet = null;
12 + public $is_rest = false;
13 + public $is_cli = false;
14 + public $site_url = null;
15 + public $mwcode = null;
16 + public $licenser = null;
16 17
17 - private $option_name = 'mwcode_options';
18 + private $option_name = 'mwcode_options';
18 19
19 - public function __construct() {
20 - global $mwcode;
21 -
22 - $this->site_url = get_site_url();
23 - $this->is_rest = MeowCommon_Helpers::is_rest();
24 - $this->is_cli = defined( 'WP_CLI' ) && WP_CLI;
25 -
26 - // Snippets
27 - $snippet = new Meow_MWCODE_Modules_Snippet( $this );
28 - $this->snippet = $snippet;
20 + public function __construct() {
21 + global $mwcode;
29 22
30 - // Create API before plugins_loaded
31 - $this->mwcode = new Meow_MWCODE_API( $this, $snippet );
32 - $mwcode = $this->mwcode;
23 + $this->site_url = get_site_url();
24 + $this->is_rest = MeowKit_MWCODE_Helpers::is_rest();
25 + $this->is_cli = defined( 'WP_CLI' ) && WP_CLI;
33 26
34 - // Add the shortcode for the "content" snippets
35 - add_shortcode( 'code-engine', [ $this, 'content_shortcode' ] );
36 -
37 - add_action( 'plugins_loaded', array( $this, 'init' ) );
38 - }
27 + // Snippets
28 + $snippet = new Meow_MWCODE_Modules_Snippet( $this );
29 + $this->snippet = $snippet;
39 30
40 - function init() {
41 - // Part of the core, settings and stuff
42 - $this->admin = new Meow_MWCODE_Admin( $this );
31 + // Create API before plugins_loaded
32 + $this->mwcode = new Meow_MWCODE_API( $this, $snippet );
33 + $mwcode = $this->mwcode;
43 34
44 - // Only for REST
45 - if ( $this->is_rest ) {
46 - new Meow_MWCODE_Rest( $this, $this->admin, $this->snippet );
47 - }
48 - }
35 + // Add the shortcode for the "content" snippets
36 + add_shortcode( 'code-engine', [ $this, 'content_shortcode' ] );
49 37
38 + add_action( 'plugins_loaded', array( $this, 'init' ) );
39 + }
50 40
51 - /**
52 - *
53 - * Roles & Access Rights
54 - *
55 - */
56 - #region Roles & Access Rights
57 - public function can_access_settings() {
58 - return apply_filters( 'mwcode_allow_setup', current_user_can( 'manage_options' ) );
59 - }
41 + function init() {
42 + // Initialize the licenser for Pro version
43 + if ( class_exists( 'MeowKitPro_MWCODE_Licenser' ) ) {
44 + $this->licenser = new MeowKitPro_MWCODE_Licenser( MWCODE_PREFIX, MWCODE_ENTRY, MWCODE_DOMAIN, MWCODE_ITEM_ID, MWCODE_VERSION );
45 + }
60 46
61 - public function can_access_features() {
62 - return apply_filters( 'mwcode_allow_usage', current_user_can( 'administrator' ) );
63 - }
47 + // Part of the core, settings and stuff
48 + $this->admin = new Meow_MWCODE_Admin( $this );
64 49
65 - public function check_rest_nonce( $request ) {
66 - $nonce = $request->get_header( 'X-WP-Nonce' );
67 - return wp_verify_nonce( $nonce, 'wp_rest' );
68 - }
69 - #endregion
50 + // Only for REST
51 + if ( $this->is_rest ) {
52 + new Meow_MWCODE_Rest( $this, $this->admin, $this->snippet );
53 + }
54 +
55 + // MCP integration - check both class and global variable
56 + if ( class_exists( 'Meow_MWAI_Core' ) || isset( $GLOBALS['mwai'] ) ) {
57 + new Meow_MWCODE_MCP( $this );
58 + }
59 + }
70 60
71 - #region Options
61 + /**
62 + *
63 + * Roles & Access Rights
64 + *
65 + */
66 + #region Roles & Access Rights
67 + public function can_access_settings() {
68 + return apply_filters( 'mwcode_allow_setup', current_user_can( 'manage_options' ) );
69 + }
72 70
73 - function get_option( $option, $default = null ) {
74 - $options = $this->get_all_options();
75 - return $options[$option] ?? $default;
76 - }
71 + public function can_access_features() {
72 + return apply_filters( 'mwcode_allow_usage', current_user_can( 'administrator' ) );
73 + }
77 74
78 - function list_options() {
79 - return [
80 - //Safemode
81 - "safe_mode_status" => "on", // on, off, whitelist
82 - "safe_mode_whitelist" => [],
83 -
84 - //LOGS
85 - "server_debug_mode" => false,
75 + public function check_rest_nonce( $request ) {
76 + $nonce = $request->get_header( 'X-WP-Nonce' );
77 + return wp_verify_nonce( $nonce, 'wp_rest' );
78 + }
79 + #endregion
86 80
87 - //UI
88 - "ui_show_preview" => true,
81 + #region Options
89 82
90 - //AI
91 - "ai_suggestions" => false,
92 - "ai_engine_status"=> false,
93 - "ai_engine_message" => "",
83 + function get_option( $option, $default = null ) {
84 + $options = $this->get_all_options();
85 + return $options[$option] ?? $default;
86 + }
94 87
95 - //API
96 - "api_endpoint" => false,
97 - "api_token" => md5( time() . rand() ),
98 - ];
99 - }
88 + function list_options() {
89 + return [
90 + //Safemode
91 + "safe_mode_status" => "on", // on, off, whitelist
92 + "safe_mode_whitelist" => [],
93 + //"disallow_block_php" => true, // Do not allow PHP code to be execute through Blocks "code" parameter
94 + "code_blocks" => false,
95 + "code_blocks_whitelist" => [], // Whitelist for code blocks, if empty, all code blocks are allowed
96 +
97 + //LOGS
98 + "server_debug_mode" => false,
100 99
101 - function get_all_options( ) {
102 - $options = get_option( $this->option_name, $this->list_options( ) );
103 - $options = $this->sanitize_options( $options );
104 -
105 - return $options;
106 - }
100 + //UI
101 + "ui_show_preview" => false,
107 102
108 - function update_options( $options ) {
109 - $current_options = get_option($this->option_name);
110 -
111 - if ($current_options === $options) {
112 - // $this->log('💾 The options are already the expected value.');
113 - } else {
114 - if ( !update_option( $this->option_name, $options, false ) ) {
115 - $this->log( '💾 There was an issue updating the options.' );
116 - }
117 - }
118 -
119 - $options = $this->sanitize_options( $options );
120 - return $options;
121 - }
103 + //AI
104 + "ai_suggestions" => false,
105 + "ai_engine_status"=> false,
106 + "ai_engine_message" => "",
122 107
123 - function update_option( $option, $value ) {
124 - $options = $this->get_all_options();
125 - $options[$option] = $value;
126 - return $this->update_options( $options );
127 - }
108 + //API
109 + "api_endpoint" => false,
110 + "api_token" => md5( time() . rand() ),
111 +
112 + //MCP
113 + "mcp_support" => false,
128 114
129 - function reset_options() {
130 - if ( $this->get_all_options() === $this->list_options() ) {
131 - return true;
132 - }
133 - return $this->update_options( $this->list_options() );
134 - }
115 + //MAINTENANCE
116 + "clean_uninstall" => false,
117 + ];
118 + }
135 119
136 - // Validate and keep the options clean and logical.
137 - function sanitize_options( $options ) {
138 - $options_modified = false;
120 + function get_all_options( ) {
121 + $options = get_option( $this->option_name, [] );
122 + $defaults = $this->list_options();
123 +
124 + // Merge with defaults to ensure all options exist
125 + $options = array_merge( $defaults, $options );
126 +
127 + $options = $this->sanitize_options( $options );
128 + return $options;
129 + }
139 130
140 - // Make sure safe mode whitelist is an array
141 - if ( ! is_array( $options['safe_mode_whitelist'] ) ) {
142 - $options['safe_mode_whitelist'] = explode( ",", $options['safe_mode_whitelist'] );
143 - $options_modified = true;
144 - }
131 + function update_options( $options ) {
145 132
146 - // Update AI Engine status
147 - $options_modified = $this->updateAIEngineStatus( $options ) || $options_modified;
133 + $options = $this->sanitize_options( $options );
148 134
149 - // Disable AI related features if AI Engine is not available
150 - if ( ! $options['ai_engine_status'] && $options['ai_suggestions'] !== false ) {
151 - $options['ai_suggestions'] = false;
152 - $options_modified = true;
153 - }
135 + if ( !update_option( $this->option_name, $options, false ) ) {
136 + $this->log( '💾 There was an issue updating the options.' );
137 + }
138 +
139 + return $options;
140 + }
154 141
155 - if ( $options_modified ) {
156 - update_option( $this->option_name, $options, false );
157 - }
142 + function update_option( $option, $value ) {
143 + $options = $this->get_all_options();
144 + $options[$option] = $value;
145 + return $this->update_options( $options );
146 + }
158 147
159 - return $options;
160 - }
148 + function reset_options() {
149 + if ( $this->get_all_options() === $this->list_options() ) {
150 + return true;
151 + }
152 + return $this->update_options( $this->list_options() );
153 + }
161 154
162 - private function updateAIEngineStatus( &$options ) {
163 - global $mwai;
155 + // Validate and keep the options clean and logical.
156 + function sanitize_options( $options ) {
157 + $options_modified = false;
158 +
159 + // Ensure mcp_support exists in options
160 + if ( !isset( $options['mcp_support'] ) ) {
161 + $options['mcp_support'] = false;
162 + }
164 163
165 - if ( is_null( $mwai ) || ! isset( $mwai ) ) {
166 - $options['ai_engine_status'] = false;
167 - $options['ai_engine_message'] = 'AI Engine is not available.';
168 - return true;
169 - }
164 + // Make sure safe mode whitelist is an array
165 + if ( ! is_array( $options['safe_mode_whitelist'] ) ) {
166 + $options['safe_mode_whitelist'] = explode( ",", $options['safe_mode_whitelist'] );
167 + $options_modified = true;
168 + }
170 169
171 - try {
172 - $status = $mwai->checkStatus();
170 + // Update AI Engine status
171 + $options_modified = $this->updateAIEngineStatus( $options ) || $options_modified;
173 172
174 - if ( $options['ai_engine_status'] != true || $options['ai_engine_message'] != $status ) {
175 - $options['ai_engine_status'] = true;
176 - $options['ai_engine_message'] = $status;
177 - return true;
178 - }
179 - } catch ( Exception $e ) {
180 - if ( $options['ai_engine_status'] != false || $options['ai_engine_message'] != $e->getMessage() ) {
181 - $options['ai_engine_status'] = false;
182 - $options['ai_engine_message'] = $e->getMessage();
183 - return true;
184 - }
185 - }
173 + // Disable AI related features if AI Engine is not available
174 + if ( ! $options['ai_engine_status'] ) {
175 + if ( $options['ai_suggestions'] !== false ) {
176 + $options['ai_suggestions'] = false;
177 + $options_modified = true;
178 + }
179 + // Note: We don't disable MCP support here anymore
180 + // It will be checked at runtime in the MCP class
181 + }
186 182
187 - return false;
188 - }
183 + return $options;
184 + }
189 185
190 - // #endregion
186 + private function updateAIEngineStatus( &$options ) {
187 + global $mwai;
191 188
192 - #region Snippets
189 + if ( is_null( $mwai ) || ! isset( $mwai ) ) {
190 + $options['ai_engine_status'] = false;
191 + $options['ai_engine_message'] = 'AI Engine is not available.';
192 + return true;
193 + }
193 194
194 - /**
195 - * Get snippet.
196 - *
197 - * @param $id
198 - * @return mixed
199 - */
200 - protected function get_snippet( $id ) {
201 - if ( $this->snippet === null ) {
202 - $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
203 - }
195 + try {
196 + $status = $mwai->checkStatus();
204 197
205 - return $this->snippet->select_one( $id );
198 + if ( $options['ai_engine_status'] != true || $options['ai_engine_message'] != $status ) {
199 + $options['ai_engine_status'] = true;
200 + $options['ai_engine_message'] = $status;
201 + return true;
202 + }
203 + } catch ( Exception $e ) {
204 + if ( $options['ai_engine_status'] != false || $options['ai_engine_message'] != $e->getMessage() ) {
205 + $options['ai_engine_status'] = false;
206 + $options['ai_engine_message'] = $e->getMessage();
207 + return true;
208 + }
206 209 }
207 210
208 - function add_snippet( $params ) {
211 + return false;
212 + }
209 213
210 - $response = [
211 - "snippet" => null,
212 - "result" => false,
213 - ];
214 + #endregion
214 215
215 - $this->snippet->validate( $params );
216 + #region Snippets
216 217
217 - $params = $this->snippet->formatParamsForDatabase( $params );
218 - $result = $this->snippet->insert( $params );
219 - $snippet = $this->snippet->select_one( $result );
218 + /**
219 + * Get snippet.
220 + *
221 + * @param $id
222 + * @return mixed
223 + */
224 + protected function get_snippet( $id ) {
225 + if ( $this->snippet === null ) {
226 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
227 + }
220 228
221 - if( $result ) {
222 - $params['id'] = (string)$result;
229 + return $this->snippet->select_one( $id );
230 + }
223 231
224 - $this->snippet->create_or_update_function_snippet( $params );
225 - $this->snippet->create_or_update_interval_snippet( $params );
232 + function add_snippet( $params ) {
226 233
227 - $this->snippet->get_function_snippets_data( $snippet );
228 - }
234 + $response = [
235 + "snippet" => null,
236 + "result" => false,
237 + ];
229 238
230 - $response['snippet'] = $snippet;
231 - $response['result'] = $result;
239 + $this->snippet->validate( $params );
232 240
233 - return $response;
234 - }
241 + $params = $this->snippet->formatParamsForDatabase( $params );
242 + $result = $this->snippet->insert( $params );
243 + $snippet = $this->snippet->select_one( $result );
235 244
236 - private function sanitize_arg( $name, $value, $type = null) {
237 - $real_type = gettype( $value );
245 + if( $result ) {
246 + $params['id'] = (string)$result;
238 247
239 - if ( $name[0] !== '$' ) { $name = '$' . $name; }
248 + $this->snippet->create_or_update_function_snippet( $params );
249 + $this->snippet->create_or_update_interval_snippet( $params );
240 250
241 - if ( $type == null ) {
242 - $type = $real_type;
243 - }
244 -
245 - if ( $type != 'array' && !empty( $value ) && !is_numeric( $value ) && $value[0] !== '"' && $value[strlen( $value ) - 1] !== '"' ) {
246 - $value = '"' . esc_sql( $value ) . '"';
247 - }
251 + $this->snippet->get_function_snippets_data( $snippet );
252 + }
248 253
249 - if ( $type === 'array' && $real_type === 'string' ) {
250 - // We got a string like this: "["a", "b", "c"]" or "[ 1, 2, 3 ]"
251 - // We need to convert it to an array
252 - $value = str_replace( '"', '', $value );
253 - $value = str_replace( '[', '', $value );
254 - $value = str_replace( ']', '', $value );
255 - $value = explode( ',', $value );
256 - $value = array_map( 'trim', $value );
257 - }
254 + $response['snippet'] = $snippet;
255 + $response['result'] = $result;
258 256
259 - if ( $type === 'array' ) {
260 - $value = json_encode( $value );
261 - $value = str_replace( '\\', '', $value );
262 - }
257 + return $response;
258 + }
263 259
264 - return [ $name, $value ];
265 - }
260 + private function sanitize_arg( $name, $value, $type = null) {
261 + $real_type = gettype( $value );
266 262
267 - function run_non_fn_snippet( $id, $code = null, $test = false ) {
268 - // Retrieve the snippet code from the provided code or via the snippet ID.
269 - if ( $code ) {
270 - $snippet = [ 'code' => $code ];
271 - } else {
272 - $snippet = $this->get_snippet( $id );
273 - }
274 -
275 - // Remove any PHP opening tag.
276 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
277 -
263 + if ( $name[0] !== '$' ) { $name = '$' . $name; }
278 264
279 - if ( $test ) {
280 - $snippet['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $snippet['code'] );
281 - }
282 -
283 - $error = null;
284 - $output = null;
285 -
286 - try {
287 - ob_start();
288 - eval( $snippet['code'] );
289 - $output = ob_get_clean();
290 - } catch ( Throwable $e ) {
291 - $snippet_id = $id ? " ( ID: $id )" : '(Content Gutenberg Block)';
292 - $this->log( '🔴 Error executing the snippet ' . $snippet_id . ' : ' . $e->getMessage() );
293 - ob_clean();
294 - } finally {
295 - restore_error_handler();
296 - }
297 -
298 - // If in test mode, return output as an array of lines with an 'error' key if needed.
299 - if ( $test ) {
300 - $output = explode( "\n", trim( $output ) );
301 - if ( $error !== null ) {
302 - $output['error'] = $error->getMessage();
303 - }
304 - } else {
305 - if ( $error !== null ) {
306 - throw $error;
307 - }
308 - }
309 -
310 - return $output;
311 - }
265 + if ( $type == null ) {
266 + $type = $real_type;
267 + }
312 268
313 - function run_snippet( $id, $args = [], $params = [] )
314 - {
315 - // Static array to track defined functions
316 - static $defined_functions = array();
269 + if ( $type != 'array' && !empty( $value ) && !is_numeric( $value ) && $value[0] !== '"' && $value[strlen( $value ) - 1] !== '"' ) {
270 + $value = '"' . esc_sql( $value ) . '"';
271 + }
317 272
318 - if ( $id ) { // If there is an ID, we get the snippet, if not we get the data from the params
319 - $snippet = $this->get_snippet( $id );
320 - $this->snippet->get_function_snippets_data( $snippet ); // adds the function data to the snippet
273 + if ( $type === 'array' && $real_type === 'string' ) {
274 + // We got a string like this: "["a", "b", "c"]" or "[ 1, 2, 3 ]"
275 + // We need to convert it to an array
276 + $value = str_replace( '"', '', $value );
277 + $value = str_replace( '[', '', $value );
278 + $value = str_replace( ']', '', $value );
279 + $value = explode( ',', $value );
280 + $value = array_map( 'trim', $value );
281 + }
321 282
322 - $params = [ // We set the params according to the snippet we fetched
323 - 'test' => false, // If we pass an ID to the function, we are not testing the snippet
324 - // 'test' => $params['test'] ?? false if needed we can still use ID and test at the same time (should not happen)
325 - 'code' => $snippet['code'],
326 - 'name' => $snippet['functionName'],
327 - 'args' => $snippet['functionArgs'],
328 - 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
329 - ];
330 - }
283 + if ( $type === 'array' ) {
284 + // Convert to PHP array format instead of JSON
285 + $value = var_export( $value, true );
286 + }
331 287
332 - // Sanitize all the arguments if the option is enabled
333 - if ( $this->get_option( 'sanitize_arguments', true ) ) {
288 + return [ $name, $value ];
289 + }
334 290
335 - if ( $args ) {
336 - foreach ( $args as $name => $value ) {
337 - list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value, $value['type'] );
338 - unset( $args[$name] );
291 + function run_non_fn_snippet( $id, $code = null, $test = false, $prefix = '' ) {
292 + // Retrieve the snippet code from the provided code or via the snippet ID.
293 + if ( $code ) {
294 + $snippet = [ 'code' => $code ];
295 + } else {
296 + $snippet = $this->get_snippet( $id );
297 + }
339 298
340 - $args[$sanitizedName] = $sanitizedValue;
341 - }
342 - }
299 + // Remove any PHP opening tag.
300 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
343 301
344 - foreach ( $params['values'] as $name => $value ) {
302 + if ( $test ) {
303 + $snippet['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $snippet['code'] );
304 + }
345 305
346 - if( array_key_exists( 'input', $value) ) {
347 - list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'], $value['type'] );
348 - $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
349 - }
350 -
351 - if( array_key_exists( 'default', $value) ) {
352 - list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'], $value['type'] );
353 - $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
354 - }
355 - }
306 + if( $prefix ) {
307 + $snippet['code'] = $prefix . "\n" . $snippet['code'];
308 + }
309 +
310 + $error = null;
311 + $output = null;
312 +
313 + try {
314 + ob_start();
315 + eval( $snippet['code'] );
316 + $output = ob_get_clean();
317 + } catch ( Throwable $e ) {
318 + $snippet_id = $id ? " ( ID: $id )" : '(Content Gutenberg Block)';
319 + $this->log( '🔴 Error executing the snippet ' . $snippet_id . ' : ' . $e->getMessage() );
320 + ob_clean();
321 + } finally {
322 + restore_error_handler();
323 + }
324 +
325 + // If in test mode, return output as an array of lines with an 'error' key if needed.
326 + if ( $test ) {
327 + $output = explode( "\n", trim( $output ) );
328 + if ( $error !== null ) {
329 + $output['error'] = $error->getMessage();
330 + }
331 + } else {
332 + if ( $error !== null ) {
333 + throw $error;
334 + }
335 + }
336 +
337 + return $output;
338 + }
356 339
357 - }
340 + function run_snippet( $id, $args = [], $params = [] )
341 + {
342 + // Static array to track defined functions
343 + static $defined_functions = array();
358 344
359 - // Make sure the function is existing and is the one in the snippet
360 - if ( empty( $params['code'] ) ) {
361 - throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
362 - }
363 -
364 - if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
365 - throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
366 - }
345 + if ( $id ) { // If there is an ID, we get the snippet, if not we get the data from the params
346 + $snippet = $this->get_snippet( $id );
347 + $this->snippet->get_function_snippets_data( $snippet ); // adds the function data to the snippet
367 348
368 - // Overwrite the default values with the provided ones
369 - if ( $args ) {
370 - foreach ( $args as $name => $value ) {
371 - $params['values'][$name]['input'] = $value;
372 - }
349 + $params = [ // We set the params according to the snippet we fetched
350 + 'test' => false, // If we pass an ID to the function, we are not testing the snippet
351 + // 'test' => $params['test'] ?? false if needed we can still use ID and test at the same time (should not happen)
352 + 'code' => $snippet['code'],
353 + 'name' => $snippet['functionName'],
354 + 'args' => $snippet['functionArgs'],
355 + 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
356 + ];
357 + }
373 358
374 - $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
375 - }
359 + // Sanitize all the arguments if the option is enabled
360 + if ( $this->get_option( 'sanitize_arguments', true ) ) {
376 361
377 - // Check if the function has already been defined
378 - if ( !in_array( $params['name'], $defined_functions ) ) {
362 + if ( $args ) {
363 + foreach ( $args as $name => $value ) {
364 + list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value );
365 + unset( $args[$name] );
379 366
380 - // If not, proceed with modification and definition
381 - if ( $params['test'] ) { // Make sure the echo statement uses a line break
382 - $params['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $params['code'] );
383 - } else { // Remove all echo statements
384 - $params['code'] = preg_replace( '/echo\s+(.+?);/s', '', $params['code'] );
385 - }
367 + $args[$sanitizedName] = $sanitizedValue;
368 + }
369 + }
386 370
387 - $params['code'] = "if (!function_exists('{$params['name']}')) {\n" . $params['code'] . "\n}\n";
371 + foreach ( $params['values'] as $name => $value ) {
388 372
389 - // Add the function name to the array to avoid redefinition
390 - $defined_functions[] = $params['name'];
391 - } else {
392 - // If already defined, just prepare to call the function without redefining it
393 - $params['code'] = '';
394 - }
373 + if( array_key_exists( 'input', $value) ) {
374 + list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'], $value['type'] );
375 + $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
376 + }
395 377
396 - // Prepare the code to be executed
397 - $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
398 - foreach ( $params['args'] as $index => $arg ) {
399 - $value = 'null'; // In case the argument is not provided it will be null
378 + if( array_key_exists( 'default', $value) ) {
379 + list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'], $value['type'] );
380 + $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
381 + }
382 + }
400 383
401 - if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
384 + }
402 385
403 - // If the argument is provided, use it, if not use the default value
404 - if ( !empty( $params['values'][$arg]['input'] ) ) {
405 - $value = $params['values'][$arg]['input'];
386 + // Make sure the function is existing and is the one in the snippet
387 + if ( empty( $params['code'] ) ) {
388 + throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
389 + }
406 390
407 - } else if ( !empty( $params['values'][$arg]['default'] ) ) {
408 - $value = $params['values'][$arg]['default'];
409 - }
410 - }
391 + if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
392 + throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
393 + }
411 394
412 - $params['code'] .= "{$value}";
413 - if ( $index < count( $params['args'] ) - 1 ) {
414 - $params['code'] .= ', ';
415 - }
416 - }
417 - $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
395 + // Overwrite the default values with the provided ones
396 + if ( $args ) {
397 + foreach ( $args as $name => $value ) {
398 + $params['values'][$name]['input'] = $value;
399 + }
418 400
419 - $error = null;
420 - $output = null;
401 + $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
402 + }
421 403
422 - try {
423 - ob_start();
424 - eval( $params['code'] );
425 - $output = ob_get_clean();
426 -
427 - if ( $params['test'] ){
428 - $output = explode( "\n", $output );
429 - }
430 -
431 - } catch ( Throwable $e ) {
432 - //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
433 - $error = new Exception(' Error executing the function, ' . $e->getMessage());
404 + // Check if the function has already been defined
405 + if ( !in_array( $params['name'], $defined_functions ) ) {
434 406
435 - ob_clean();
436 - } finally {
437 - restore_error_handler();
438 - }
407 + // If not, proceed with modification and definition
408 + if ( $params['test'] ) { // Make sure the echo statement uses a line break
409 + $params['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $params['code'] );
410 + } else { // Remove all echo statements
411 + $params['code'] = preg_replace( '/echo\s+(.+?);/s', '', $params['code'] );
412 + }
439 413
440 - if ( $error !== null ) {
441 - if( $params['test'] ){
442 - $output['error'] = $error->getMessage();
443 - } else {
444 - throw $error;
445 - }
446 - }
414 + $params['code'] = "if (!function_exists('{$params['name']}')) {\n" . $params['code'] . "\n}\n";
447 415
448 - return $output;
449 - }
416 + // Add the function name to the array to avoid redefinition
417 + $defined_functions[] = $params['name'];
418 + } else {
419 + // If already defined, just prepare to call the function without redefining it
420 + $params['code'] = '';
421 + }
450 422
423 + // Prepare the code to be executed
424 + $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
425 + foreach ( $params['args'] as $index => $arg ) {
426 + $value = 'null'; // In case the argument is not provided it will be null
451 427
452 - function parse_snippet( $code, $new_snippet = false ){
453 - $parser = ( new ParserFactory( ) )->createForNewestSupportedVersion( );
428 + if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
454 429
455 - if( !$this->snippet ){
456 - $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
457 - }
430 + // If the argument is provided, use it, if not use the default value
431 + if ( !empty( $params['values'][$arg]['input'] ) ) {
432 + $value = $params['values'][$arg]['input'];
458 433
459 - // First we check the function names are unique
460 - $fn = $this->snippet->sanitize_and_check_functions( $code, $new_snippet );
461 - if ( ! $fn['is_valid'] ) {
434 + } else if ( !empty( $params['values'][$arg]['default'] ) ) {
435 + $value = $params['values'][$arg]['default'];
436 + }
437 + }
462 438
463 - $lint = [
464 - 'line' => 1,
465 - 'attributes' => $fn['attributes'][0],
466 - 'raw_message' => implode(', ', $fn['errors'][0]),
467 - 'message' => implode(', ', $fn['errors'][0]),
468 - ];
439 + $params['code'] .= "{$value}";
440 + if ( $index < count( $params['args'] ) - 1 ) {
441 + $params['code'] .= ', ';
442 + }
443 + }
469 444
470 - return $lint;
471 - }
445 + $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
472 446
473 - try {
474 - $stmts = $parser->parse( $code );
475 - $result = $stmts;
476 - } catch ( PhpParser\Error $e ) {
447 + $error = null;
448 + $output = null;
449 +
450 + try {
451 + ob_start();
452 + eval( $params['code'] );
453 + $output = ob_get_clean();
454 +
455 + if ( $params['test'] ){
456 + $output = explode( "\n", $output );
457 + }
458 +
459 + } catch ( Throwable $e ) {
460 + //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
461 + $error = new Exception(' Error executing the function, ' . $e->getMessage());
477 462
478 - $lint = [
479 - 'line' => $e->getStartLine(),
480 - 'attributes' => $e->getAttributes(),
481 - 'raw_message' => $e->getRawMessage(),
482 - 'message' => $e->getMessage(),
483 - ];
463 + ob_clean();
464 + } finally {
465 + restore_error_handler();
466 + }
484 467
485 - return $lint;
486 - }
468 + if ( $error !== null ) {
469 + if( $params['test'] ){
470 + $output['error'] = $error->getMessage();
471 + } else {
472 + throw $error;
473 + }
474 + }
487 475
488 - return null;
489 - }
476 + return $output;
477 + }
490 478
491 - public function get_js_functions_to_push() {
492 - $functions = $this->snippet->get_functions();
493 - $js_functions = [];
494 - foreach ( $functions as &$function ) {
495 - if ( !isset( $function['target'] ) ) {
496 - $function['target'] = 'php';
497 - }
498 - if ( $function['target'] == 'js' ) {
499 - $js_functions[] = $function;
500 - }
501 - }
502 - $snippets = [];
503 - foreach ( $js_functions as $function ) {
504 - $snippet = $this->snippet->select_one( $function['snippetId'] );
505 - $snippet['function_info'] = $function; // Add function info to snippet
506 - $snippets[] = $snippet;
507 - }
508 -
509 - return $this->generate_js_functions_code( $snippets );
510 - }
511 -
512 - function generate_js_functions_code ($snippets ) {
513 - $code = "";
514 - foreach ( $snippets as $snippet ) {
515 - $function_code = $snippet['code'];
516 - $function_info = $snippet['function_info'];
517 -
518 - // Extract function name and arguments
519 - preg_match( '/(?:const|let|var)?\s*(\w+)\s*=\s*\((.*?)\)\s*=>/', $function_code, $matches );
520 - $function_name = $matches[1] ?? $function_info['name'];
521 - $function_args = $matches[2] ?? '';
522 -
523 - // Prepare default values
524 - $default_args = [];
525 - foreach ( $function_info['args'] as $arg ) {
526 - if ( isset( $arg['default'] ) && $arg['default'] !== '' ) {
527 - $default_args[$arg['name']] = $arg['default'];
528 - }
529 - }
530 -
531 - // Modify function to use default values
532 - if ( !empty( $default_args ) ) {
533 - $new_args = explode( ',', $function_args );
534 - foreach ( $new_args as &$arg ) {
535 - $arg = trim( $arg );
536 - if ( isset( $default_args[$arg] ) ) {
537 - $arg .= " = " . json_encode( $default_args[$arg] );
538 - }
539 - }
540 - $new_args_string = implode( ', ', $new_args );
541 - $function_code = preg_replace(
542 - '/(\w+)\s*=\s*\((.*?)\)\s*=>/',
543 - "$1 = ($new_args_string) =>",
544 - $function_code
545 - );
546 - }
547 -
548 - $code .= $function_code . "\n\n";
549 - }
550 479
551 - return $code;
552 - }
480 + function parse_snippet( $code, $new_snippet = false ){
481 + $parser = ( new ParserFactory( ) )->createForNewestSupportedVersion( );
553 482
483 + if( !$this->snippet ){
484 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
485 + }
554 486
555 - /**
556 - * [STATIC] Execute active snippets.
557 - *
558 - * @return array
559 - */
560 - public function execute_active_snippets() {
487 + // First we check the function names are unique
488 + $fn = $this->snippet->sanitize_and_check_functions( $code, $new_snippet );
489 + if ( ! $fn['is_valid'] ) {
561 490
562 - $blocked = false;
563 - $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : null;
564 - if ( $page === 'mwcode_settings' || !Meow_MWCODE_Core::is_white_listed_rest() ) {
565 - $blocked = true;
566 - }
491 + $lint = [
492 + 'line' => 1,
493 + 'attributes' => $fn['attributes'][0],
494 + 'raw_message' => implode(', ', $fn['errors'][0]),
495 + 'message' => implode(', ', $fn['errors'][0]),
496 + ];
567 497
568 - if ( empty( $this->snippet ) ) {
569 - $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
570 - }
498 + return $lint;
499 + }
571 500
572 - $ts = $this->get_option( 'thrown_snippet', null );
573 - if ( !empty( $ts ) ) {
574 - $this->log( "⚠️ Your snippet \"{$ts['name']}\" has thrown a fatal error last time, so we disabled it. Please check the logs for more information." );
575 - $this->snippet->force_disable( $ts['id'] );
576 - $this->update_option( 'thrown_snippet', null );
577 - }
501 + try {
502 + $stmts = $parser->parse( $code );
503 + $result = $stmts;
504 + } catch ( PhpParser\Error $e ) {
578 505
579 - $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
580 - // Get all active snippets
506 + $lint = [
507 + 'line' => $e->getStartLine(),
508 + 'attributes' => $e->getAttributes(),
509 + 'raw_message' => $e->getRawMessage(),
510 + 'message' => $e->getMessage(),
511 + ];
581 512
582 -
513 + return $lint;
514 + }
583 515
584 - $snippets = $this->snippet->select(
585 - null, // offset
586 - -1, // limit
587 - [
588 - [ 'accessor' => 'active', 'value' => 1 ],
589 - [ 'accessor' => 'scope', 'value' => $scope ],
590 - ], // filter
591 - [ 'accessor' => 'priority', 'by' => 'DESC' ] // sort
592 - )['data'];
516 + return null;
517 + }
593 518
519 + public function get_js_functions_to_push() {
520 + $functions = $this->snippet->get_functions();
521 + $js_functions = [];
522 + foreach ( $functions as &$function ) {
523 + if ( !isset( $function['target'] ) ) {
524 + $function['target'] = 'php';
525 + }
526 + if ( $function['target'] == 'js' ) {
527 + $js_functions[] = $function;
528 + }
529 + }
530 + $snippets = [];
531 + foreach ( $js_functions as $function ) {
532 + $snippet = $this->snippet->select_one( $function['snippetId'] );
533 + $snippet['function_info'] = $function; // Add function info to snippet
534 + $snippets[] = $snippet;
535 + }
594 536
595 - if ( empty( $snippets ) ) {
596 - return;
537 + return $this->generate_js_functions_code( $snippets );
538 + }
539 +
540 + function generate_js_functions_code ($snippets ) {
541 + $code = "";
542 + foreach ( $snippets as $snippet ) {
543 + $function_code = $snippet['code'];
544 + $function_info = $snippet['function_info'];
545 +
546 + // Extract function name and arguments
547 + preg_match( '/(?:const|let|var)?\s*(\w+)\s*=\s*\((.*?)\)\s*=>/', $function_code, $matches );
548 + $function_name = $matches[1] ?? $function_info['name'];
549 + $function_args = $matches[2] ?? '';
550 +
551 + // Prepare default values
552 + $default_args = [];
553 + foreach ( $function_info['args'] as $arg ) {
554 + if ( isset( $arg['default'] ) && $arg['default'] !== '' ) {
555 + $default_args[$arg['name']] = $arg['default'];
597 556 }
557 + }
598 558
599 - $snippets = array_map( function ( $snippet ) use ( $blocked ) {
600 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
601 - $snippet['blocked'] = $blocked;
559 + // Modify function to use default values
560 + if ( !empty( $default_args ) ) {
561 + $new_args = explode( ',', $function_args );
562 + foreach ( $new_args as &$arg ) {
563 + $arg = trim( $arg );
564 + if ( isset( $default_args[$arg] ) ) {
565 + $arg .= " = " . json_encode( $default_args[$arg] );
566 + }
567 + }
568 + $new_args_string = implode( ', ', $new_args );
569 + $function_code = preg_replace(
570 + '/(\w+)\s*=\s*\((.*?)\)\s*=>/',
571 + "$1 = ($new_args_string) =>",
572 + $function_code
573 + );
574 + }
602 575
603 - // If the snippet must be executed only in the frontend, we bypass the block
604 - if ( !is_admin() && $snippet['scope'] === 'frontend' ) {
605 - $snippet['blocked'] = false;
606 - }
576 + $code .= $function_code . "\n\n";
577 + }
607 578
608 - return $snippet;
609 - }, $snippets );
579 + return $code;
580 + }
610 581
611 -
612 582
613 - return $snippets;
583 + /**
584 + * [STATIC] Execute active snippets.
585 + *
586 + * @return array
587 + */
588 + public function execute_active_snippets() {
589 +
590 + $blocked = false;
591 + $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : null;
592 +
593 +
594 + if ( $page === 'mwcode_settings' ) {
595 + // If we blocks global snippets like nonce_life filter, we would block the settings page so let's remove the block for this page
596 +
597 + $blocked = false;
598 + //$blocked = true;
614 599 }
600 + // Block REST requests that aren't whitelisted
601 + elseif ( MeowKit_MWCODE_Helpers::is_rest() && !Meow_MWCODE_Core::is_white_listed_rest() ) {
602 + $blocked = true;
603 + }
615 604
605 + if ( empty( $this->snippet ) ) {
606 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
607 + }
616 608
617 - #endregion
609 + $ts = $this->get_option( 'thrown_snippet', null );
610 + if ( !empty( $ts ) ) {
611 + $this->log( "⚠️ Your snippet \"{$ts['name']}\" has thrown a fatal error last time, so we disabled it. Please check the logs for more information." );
612 + $this->snippet->force_disable( $ts['id'] );
613 + $this->update_option( 'thrown_snippet', null );
614 + }
618 615
619 - #reion Shortcodes
616 + $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
617 + // Get all active snippets
620 618
621 - function content_shortcode( $atts ) {
619 + $snippets = $this->snippet->select(
620 + null, // offset
621 + -1, // limit
622 + [
623 + [ 'accessor' => 'active', 'value' => 1 ],
624 + [ 'accessor' => 'scope', 'value' => $scope ],
625 + ], // filter
626 + [ 'accessor' => 'priority', 'by' => 'DESC' ] // sort
627 + )['data'];
622 628
623 - $atts = shortcode_atts( array(
624 - 'id' => null,
625 - 'target' => null,
626 - 'code' => null,
627 - ), $atts );
629 + if ( empty( $snippets ) ) {
630 + return;
631 + }
628 632
629 - $id = $atts['id'];
630 - $target = $atts['target'];
631 - $code = $atts['code'];
633 + $snippets = array_map( function ( $snippet ) use ( $blocked ) {
634 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
635 + $snippet['blocked'] = $blocked;
632 636
633 - // If the ID is null, it means it comes from a Guttenberg block
634 - $is_block = empty( $id ) && !empty( $code );
635 - if( $is_block ){
637 + // If the snippet must be executed only in the frontend, we bypass the block
638 + if ( !is_admin() && $snippet['scope'] === 'frontend' ) {
639 + $snippet['blocked'] = false;
640 + }
636 641
637 - // Because the code from Blocks are sanitized, we need to replace the &quot; with "
638 - $code = str_replace( '&quot;', '"', $code );
642 + return $snippet;
643 + }, $snippets );
639 644
640 - if ( $target === 'js' ) {
641 - $output = '<script>' . $code . '</script>';
642 - }
643 -
644 - if ( $target === 'php' ) {
645 - $output = $this->run_non_fn_snippet( null, $code );
646 - }
647 -
648 - return $output;
649 - }
645 + return $snippets;
646 + }
650 647
651 - // If the ID is not null, it means it comes from a shortcode
652 - if ( empty( $id ) && empty( $code ) ) {
653 - return '<b>Code Engine:</b> Please provide a snippet ID.';
654 - }
655 648
656 - $snippet = $this->get_snippet( $id );
649 + #endregion
657 650
658 - if ( empty( $snippet ) ) {
659 - return '<b>Code Engine:</b> The snippet does not exist.';
660 - }
651 + #region Shortcodes
652 + function separate_mwcode_atts( $atts ) {
661 653
662 - //Check if the snippet scope is either content_php or content_js
663 - $is_content_php = $snippet['scope'] === 'content_php';
664 - $is_content_js = $snippet['scope'] === 'content_js';
654 + if( array_key_exists( 'id', $atts ) ) unset( $atts['id'] );
655 + if( array_key_exists( 'target', $atts ) ) unset( $atts['target'] );
656 + if( array_key_exists( 'code', $atts ) ) unset( $atts['code'] );
665 657
666 - if ( !$is_content_php && !$is_content_js ) {
667 - return '<b>Code Engine:</b> The snippet is not a content snippet.';
668 - }
658 + return $atts;
659 + }
669 660
670 - //Check if the snippet is active
671 - if ( !$snippet['active'] ) {
672 - return '<b>Code Engine:</b> The snippet is not active.';
673 - }
661 + function content_shortcode( $atts ) {
674 662
675 - $output = '<b>Code Engine:</b> No output.';
663 + $user_atts = $this->separate_mwcode_atts( $atts );
676 664
677 - if ( $is_content_js ) {
678 - $output = '<script>' . $snippet['code'] . '</script>';
679 - }
665 + $atts = shortcode_atts( array(
666 + 'id' => null,
667 + 'target' => null, // js or php
668 + 'code' => null, // For Guttenberg block usage
669 + ), $atts, 'code-engine' );
680 670
681 - if ( $is_content_php ) {
682 - $output = $this->run_non_fn_snippet( $id );
683 - }
671 + $id = $atts['id'];
672 + $target = $atts['target'];
673 + $code = $atts['code'];
674 + $current_post = get_post();
675 +
676 + $no_js = defined( 'DISALLOW_UNFILTERED_HTML' ) && DISALLOW_UNFILTERED_HTML;
677 + $allow_php = $this->get_option( 'code_blocks', false );
678 + $allow_php_whitelist = $this->get_option( 'code_blocks_whitelist', [] );
679 +
680 + // If the ID is null, it means it comes from a Guttenberg block
681 + $is_block = empty( $id ) && !empty( $code );
684 682
685 - return $output;
686 - }
683 + if( $is_block ) {
687 684
688 - #endregion
685 + if( $target !== 'js' && $target !== 'php' ) {
686 + return '<b>Code Engine:</b> Please provide a valid target (js or php).';
687 + }
689 688
690 - #region Logs
689 + if ( $no_js && $target === 'js' ) {
690 + return '<b>Code Engine:</b> Code Block JS are disabled because unfiltered HTML is not allowed on your server.';
691 + }
691 692
692 - function get_logs() {
693 - $log_file_path = $this->get_logs_path();
693 + if ( $target === 'php' ) {
694 694
695 - if ( !file_exists( $log_file_path ) ) {
696 - return "Empty log file.";
697 - }
695 + if ( !$allow_php ) {
696 + return '<b>Code Engine:</b> Code Block PHP are disabled. If you are an administrator, you can enable it in the settings, this is not recommended. Please use a Content Snippet ( PHP ) instead.';
697 + }
698 698
699 - $content = file_get_contents( $log_file_path );
700 - $lines = explode( "\n", $content );
701 - $lines = array_filter( $lines );
702 - $lines = array_reverse( $lines );
703 - $content = implode( "\n", $lines );
704 - return $content;
705 - }
699 + if ( !empty( $allow_php_whitelist ) && !in_array( $current_post->ID, $allow_php_whitelist ) ) {
700 + return '<b>Code Engine:</b> Code Block PHP are disabled for this post. If you are an administrator, you can enable it in the settings, this is not recommended. Please use a Content Snippet ( PHP ) instead.';
701 + }
702 + }
706 703
707 - function clear_logs() {
708 - $logPath = $this->get_logs_path();
709 - if ( file_exists( $logPath ) ) {
710 - unlink( $logPath );
711 - }
704 + // Because the code from Blocks are sanitized, we need to replace the &quot; with "
705 + $code = str_replace( '&quot;', '"', $code );
712 706
713 - $options = $this->get_all_options();
714 - $options['logs_path'] = null;
715 - $this->update_options( $options );
716 - }
707 + if ( $target === 'js' ) {
708 + $output = '<script>' . $code . '</script>';
709 + }
717 710
718 - function get_logs_path() {
719 - $uploads_dir = wp_upload_dir();
720 - $uploads_dir_path = trailingslashit( $uploads_dir['basedir'] );
711 + if ( $target === 'php' ) {
712 + $output = $this->run_non_fn_snippet( null, $code );
713 + }
721 714
722 - $path = $this->get_option( 'logs_path' );
715 + return $output;
716 + }
723 717
724 - if ( $path && file_exists( $path ) ) {
725 - // make sure the path is legal (within the uploads directory with the MWCODE_PREFIX and log extension)
726 - if ( strpos( $path, $uploads_dir_path ) !== 0 || strpos( $path, MWCODE_PREFIX ) === false || substr( $path, -4 ) !== '.log' ) {
727 - $path = null;
728 - } else {
729 - return $path;
730 - }
731 - }
718 + // If not a block, we get the snippet by ID
719 + // If the ID is not null, it means it comes from a shortcode
720 + if ( empty( $id ) && empty( $code ) ) {
721 + return '<b>Code Engine:</b> Please provide a snippet ID.';
722 + }
732 723
733 - if ( !$path ) {
734 - $path = $uploads_dir_path . MWCODE_PREFIX . "_" . $this->random_ascii_chars() . ".log";
735 - if ( !file_exists( $path ) ) {
736 - touch( $path );
737 - }
738 - $options = $this->get_all_options();
739 - $options['logs_path'] = $path;
740 - $this->update_options( $options );
741 - }
724 + $snippet = $this->get_snippet( $id );
742 725
743 - return $path;
744 - }
726 + if ( empty( $snippet ) ) {
727 + return '<b>Code Engine:</b> The snippet does not exist.';
728 + }
745 729
746 - function log( $data = null ) {
747 - if ( !$this->get_option( 'server_debug_mode', false ) ) { return false; }
748 - $log_file_path = $this->get_logs_path();
749 - $fh = @fopen( $log_file_path, 'a' );
750 - if ( !$fh ) { return false; }
751 - $date = date( "Y-m-d H:i:s" );
752 - if ( is_null( $data ) ) {
753 - fwrite( $fh, "\n" );
754 - }
755 - else {
756 - fwrite( $fh, "$date: {$data}\n" );
757 - //$this->log( "[MWCODE] $data" );
758 - }
759 - fclose( $fh );
760 - return true;
761 - }
730 + //Check if the snippet scope is either content_php or content_js
731 + $is_content_php = $snippet['scope'] === 'content_php';
732 + $is_content_js = $snippet['scope'] === 'content_js';
762 733
763 - private function random_ascii_chars( $length = 8 ) {
764 - $characters = array_merge( range( 'A', 'Z' ), range( 'a', 'z' ), range( '0', '9' ) );
765 - $characters_length = count( $characters );
766 - $random_string = '';
734 + if ( !$is_content_php && !$is_content_js ) {
735 + return '<b>Code Engine:</b> The snippet is not a content snippet.';
736 + }
767 737
768 - for ( $i = 0; $i < $length; $i++ ) {
769 - $random_string .= $characters[rand(0, $characters_length - 1)];
770 - }
738 + if( $no_js && $is_content_js ) {
739 + return '<b>Code Engine:</b> Code Engine JS snippets are disabled because unfiltered HTML is not allowed on your server.';
740 + }
771 741
772 - return $random_string;
773 - }
742 + //Check if the snippet is active
743 + if ( !$snippet['active'] ) {
744 + return '<b>Code Engine:</b> The snippet is not active.';
745 + }
774 746
775 - #endregion
747 + $output = '<b>Code Engine:</b> No output.';
776 748
777 - #region Helpers
749 + if ( $is_content_js ) {
750 + $output = '<script>' . $snippet['code'] . '</script>';
751 + }
778 752
779 - /**
780 - * Check if the request is from a white-listed REST route.
781 - *
782 - * @return bool
783 - */
784 - public static function is_white_listed_rest() {
785 - $authorized = false;
786 - $white_listed = array(
787 - 'mwai/v1',
788 - 'mwai-ui/v1',
789 - 'media-file-renamer/v1',
790 - 'media-cleaner/v1',
791 - 'wplr/v1',
792 - 'code-engine/v1',
793 - 'wp/v2',
794 - 'meow-gallery/v1',
795 - );
753 + if ( $is_content_php ) {
754 + $prefix = "\$mwcode_atts = unserialize( '" . serialize( $user_atts ) . "' );";
755 + $output = $this->run_non_fn_snippet( $id, null, false, $prefix );
756 + }
796 757
797 - $white_listed = apply_filters( 'meow_mwcode_white_listed_rest', $white_listed );
758 + return $output;
759 + }
798 760
799 - $route = isset( $_SERVER['REQUEST_URI'] ) ? $_SERVER['REQUEST_URI'] : null;
800 - $requested_route = null;
801 -
802 - if ( $route ) {
803 - $route_parts = explode( '/wp-json/', $route );
804 -
805 - if ( isset( $route_parts[1] ) ) {
806 - $requested_route = trim( $route_parts[1], '/' );
807 - foreach ( $white_listed as $white_listed_route ) {
808 - if ( strpos( $requested_route, $white_listed_route ) === 0 ) {
809 - $authorized = true;
810 - $authorized = apply_filters( 'meow_mwcode_white_listed_rest_authorized', $authorized, $requested_route );
811 - return $authorized;
812 - }
813 - }
814 - }
815 -
816 - if ( is_admin() ) {
817 - $authorized = true;
761 + #endregion
818 762
819 - $authorized = apply_filters( 'meow_mwcode_white_listed_rest_authorized', $authorized, $requested_route );
820 - return $authorized;
821 - }
763 + #region Logs
822 764
765 + function get_logs() {
766 + $log_file_path = $this->get_logs_path();
823 767
824 - }
768 + if ( !file_exists( $log_file_path ) ) {
769 + return "Empty log file.";
770 + }
825 771
826 - $authorized = apply_filters( 'meow_mwcode_white_listed_rest_authorized', $authorized, $requested_route );
827 - return $authorized;
772 + $content = file_get_contents( $log_file_path );
773 + $lines = explode( "\n", $content );
774 + $lines = array_filter( $lines );
775 + $lines = array_reverse( $lines );
776 + $content = implode( "\n", $lines );
777 + return $content;
778 + }
779 +
780 + function clear_logs() {
781 + $logPath = $this->get_logs_path();
782 + if ( file_exists( $logPath ) ) {
783 + unlink( $logPath );
828 784 }
829 785
830 - #endregion
786 + $options = $this->get_all_options();
787 + $options['logs_path'] = null;
788 + $this->update_options( $options );
789 + }
790 +
791 + function get_logs_path() {
792 + $uploads_dir = wp_upload_dir();
793 + $uploads_dir_path = trailingslashit( $uploads_dir['basedir'] );
794 +
795 + $path = $this->get_option( 'logs_path' );
796 +
797 + if ( $path && file_exists( $path ) ) {
798 + // make sure the path is legal (within the uploads directory with the MWCODE_PREFIX and log extension)
799 + if ( strpos( $path, $uploads_dir_path ) !== 0 || strpos( $path, MWCODE_PREFIX ) === false || substr( $path, -4 ) !== '.log' ) {
800 + $path = null;
801 + } else {
802 + return $path;
803 + }
804 + }
805 +
806 + if ( !$path ) {
807 + $path = $uploads_dir_path . MWCODE_PREFIX . "_" . $this->random_ascii_chars() . ".log";
808 + if ( !file_exists( $path ) ) {
809 + touch( $path );
810 + }
811 + $options = $this->get_all_options();
812 + $options['logs_path'] = $path;
813 + $this->update_options( $options );
814 + }
815 +
816 + return $path;
817 + }
818 +
819 + function log( $data = null ) {
820 + if ( !$this->get_option( 'server_debug_mode', false ) ) { return false; }
821 + $log_file_path = $this->get_logs_path();
822 + $fh = @fopen( $log_file_path, 'a' );
823 + if ( !$fh ) { return false; }
824 + $date = date( "Y-m-d H:i:s" );
825 + if ( is_null( $data ) ) {
826 + fwrite( $fh, "\n" );
827 + }
828 + else {
829 + fwrite( $fh, "$date: {$data}\n" );
830 + //$this->log( "[MWCODE] $data" );
831 + }
832 + fclose( $fh );
833 + return true;
834 + }
835 +
836 + private function random_ascii_chars( $length = 8 ) {
837 + $characters = array_merge( range( 'A', 'Z' ), range( 'a', 'z' ), range( '0', '9' ) );
838 + $characters_length = count( $characters );
839 + $random_string = '';
840 +
841 + for ( $i = 0; $i < $length; $i++ ) {
842 + $random_string .= $characters[rand(0, $characters_length - 1)];
843 + }
844 +
845 + return $random_string;
846 + }
847 +
848 + #endregion
849 +
850 + #region Helpers
851 +
852 + /**
853 + * Check if the request is from a white-listed REST route.
854 + *
855 + * @return bool
856 + */
857 + public static function is_white_listed_rest() {
858 + $options = get_option( 'mwcode_snippet_vault_options', array() );
859 +
860 + // Early return if bypass is enabled
861 + if ( !empty( $options['bypass_rest_security'] ) ) {
862 + return true;
863 + }
864 +
865 + // Early return for admin requests
866 + if ( is_admin() ) {
867 + return apply_filters( 'mwcode_rest_authorized', true, null );
868 + }
869 +
870 + // Get the requested route
871 + $requested_route = self::get_requested_rest_route();
872 + if ( !$requested_route ) {
873 + return apply_filters( 'mwcode_rest_authorized', false, null );
874 + }
875 +
876 + // Check against whitelist
877 + $white_listed = apply_filters( 'mwcode_rest_whitelist', array(
878 + 'mwai/v1',
879 + 'mwai-ui/v1',
880 + 'media-file-renamer/v1',
881 + 'media-cleaner/v1',
882 + 'wplr/v1',
883 + 'code-engine/v1',
884 + 'wp/v2',
885 + 'meow-gallery/v1',
886 + 'mcp/v1',
887 + ));
888 +
889 + $authorized = self::is_route_whitelisted( $requested_route, $white_listed );
890 +
891 + // Log if debug mode is enabled
892 + if ( !empty( $options['server_debug_mode'] ) ) {
893 + self::log_route_status( $requested_route, $authorized );
894 + }
895 +
896 + return apply_filters( 'mwcode_rest_authorized', $authorized, $requested_route );
897 + }
898 +
899 + /**
900 + * Extract the REST route from the request URI.
901 + *
902 + * @return string|null
903 + */
904 + public static function get_requested_rest_route() {
905 + if ( !isset( $_SERVER['REQUEST_URI'] ) ) {
906 + return null;
907 + }
908 +
909 + $route_parts = explode( '/wp-json/', $_SERVER['REQUEST_URI'] );
910 +
911 + if ( isset( $route_parts[1] ) ) {
912 + return trim( $route_parts[1], '/' );
913 + }
914 +
915 + return null;
916 + }
917 +
918 + /**
919 + * Check if a route is in the whitelist.
920 + *
921 + * @param string $route The route to check
922 + * @param array $white_listed The whitelist array
923 + * @return bool
924 + */
925 + private static function is_route_whitelisted( $route, $white_listed ) {
926 + foreach ( $white_listed as $white_listed_route ) {
927 + if ( strpos( $route, $white_listed_route ) === 0 ) {
928 + return true;
929 + }
930 + }
931 + return false;
932 + }
933 +
934 + /**
935 + * Log the route authorization status.
936 + *
937 + * @param string $route The route being checked
938 + * @param bool $authorized Whether the route is authorized
939 + */
940 + private static function log_route_status( $route, $authorized ) {
941 + global $mwcode_core;
942 +
943 + $message = $authorized
944 + ? "✅ REST route authorized: " . $route
945 + : "❌ REST route rejected (not whitelisted): " . $route;
946 +
947 + if ( isset( $mwcode_core ) ) {
948 + $mwcode_core->log( $message );
949 + } else {
950 + error_log( "[Code Engine] " . $message );
951 + }
952 + }
953 +
954 + #endregion
831 955 }
832 956
833 957 ?>