PluginProbe
Code Engine – PHP Snippets, AI Functions & Automation for WordPress / 0.4.3
Code Engine – PHP Snippets, AI Functions & Automation for WordPress v0.4.3
0.5.7 0.5.6 0.5.5 0.5.4 0.5.3 0.5.2 0.5.1 0.5.0 0.4.9 0.4.8 0.4.7 0.4.6 trunk 0.0.1 0.0.2 0.2.8 0.2.9 0.3.0 0.3.1 0.3.2 0.3.3 0.3.4 0.3.5 0.3.6 0.3.7 All 33 releases
← All changes | classes/core.php +804 -611 0.2.90.4.3 View file →
@@ -6,756 +6,949 @@
6 6 use PhpParser\Error;
7 7
8 8 class Meow_MWCODE_Core
9 9 {
10 - public $admin = null;
11 - public $snippet = null;
12 - public $is_rest = false;
13 - public $is_cli = false;
14 - public $site_url = null;
15 - public $mwcode = null;
10 + public $admin = null;
11 + public $snippet = null;
12 + public $is_rest = false;
13 + public $is_cli = false;
14 + public $site_url = null;
15 + public $mwcode = null;
16 + public $licenser = null;
16 17
17 - private $option_name = 'mwcode_options';
18 + private $option_name = 'mwcode_options';
18 19
19 - public function __construct() {
20 - global $mwcode;
21 -
22 - $this->site_url = get_site_url();
23 - $this->is_rest = MeowCommon_Helpers::is_rest();
24 - $this->is_cli = defined( 'WP_CLI' ) && WP_CLI;
25 -
26 - // Snippets
27 - $snippet = new Meow_MWCODE_Modules_Snippet( $this );
28 - $this->snippet = $snippet;
20 + public function __construct() {
21 + global $mwcode;
29 22
30 - // Create API before plugins_loaded
31 - $this->mwcode = new Meow_MWCODE_API( $this, $snippet );
32 - $mwcode = $this->mwcode;
23 + $this->site_url = get_site_url();
24 + $this->is_rest = MeowKit_MWCODE_Helpers::is_rest();
25 + $this->is_cli = defined( 'WP_CLI' ) && WP_CLI;
33 26
34 - // Add the shortcode for the "content" snippets
35 - add_shortcode( 'code-engine', [ $this, 'content_shortcode' ] );
36 -
37 - add_action( 'plugins_loaded', array( $this, 'init' ) );
38 - }
27 + // Snippets
28 + $snippet = new Meow_MWCODE_Modules_Snippet( $this );
29 + $this->snippet = $snippet;
39 30
40 - function init() {
41 - // Part of the core, settings and stuff
42 - $this->admin = new Meow_MWCODE_Admin( $this );
31 + // Create API before plugins_loaded
32 + $this->mwcode = new Meow_MWCODE_API( $this, $snippet );
33 + $mwcode = $this->mwcode;
43 34
44 - // Only for REST
45 - if ( $this->is_rest ) {
46 - new Meow_MWCODE_Rest( $this, $this->admin, $this->snippet );
47 - }
48 - }
35 + // Add the shortcode for the "content" snippets
36 + add_shortcode( 'code-engine', [ $this, 'content_shortcode' ] );
49 37
38 + add_action( 'plugins_loaded', array( $this, 'init' ) );
39 + }
50 40
51 - /**
52 - *
53 - * Roles & Access Rights
54 - *
55 - */
56 - #region Roles & Access Rights
57 - public function can_access_settings() {
58 - return apply_filters( 'mwcode_allow_setup', current_user_can( 'manage_options' ) );
59 - }
41 + function init() {
42 + // Initialize the licenser for Pro version
43 + if ( class_exists( 'MeowKitPro_MWCODE_Licenser' ) ) {
44 + $this->licenser = new MeowKitPro_MWCODE_Licenser( MWCODE_PREFIX, MWCODE_ENTRY, MWCODE_DOMAIN, MWCODE_ITEM_ID, MWCODE_VERSION );
45 + }
60 46
61 - public function can_access_features() {
62 - return apply_filters( 'mwcode_allow_usage', current_user_can( 'administrator' ) );
63 - }
47 + // Part of the core, settings and stuff
48 + $this->admin = new Meow_MWCODE_Admin( $this );
64 49
65 - public function check_rest_nonce( $request ) {
66 - $nonce = $request->get_header( 'X-WP-Nonce' );
67 - return wp_verify_nonce( $nonce, 'wp_rest' );
68 - }
69 - #endregion
50 + // Only for REST
51 + if ( $this->is_rest ) {
52 + new Meow_MWCODE_Rest( $this, $this->admin, $this->snippet );
53 + }
54 +
55 + // MCP integration - check both class and global variable
56 + if ( class_exists( 'Meow_MWAI_Core' ) || isset( $GLOBALS['mwai'] ) ) {
57 + new Meow_MWCODE_MCP( $this );
58 + }
59 + }
70 60
71 - #region Options
61 + /**
62 + *
63 + * Roles & Access Rights
64 + *
65 + */
66 + #region Roles & Access Rights
67 + public function can_access_settings() {
68 + return apply_filters( 'mwcode_allow_setup', current_user_can( 'manage_options' ) );
69 + }
72 70
73 - function get_option( $option, $default = null ) {
74 - $options = $this->get_all_options();
75 - return $options[$option] ?? $default;
76 - }
71 + public function can_access_features() {
72 + return apply_filters( 'mwcode_allow_usage', current_user_can( 'administrator' ) );
73 + }
77 74
78 - function list_options() {
79 - return [
80 - //Safemode
81 - "safe_mode_status" => "on", // on, off, whitelist
82 - "safe_mode_whitelist" => [],
83 -
84 - //LOGS
85 - "server_debug_mode" => false,
75 + public function check_rest_nonce( $request ) {
76 + $nonce = $request->get_header( 'X-WP-Nonce' );
77 + return wp_verify_nonce( $nonce, 'wp_rest' );
78 + }
79 + #endregion
86 80
87 - //UI
88 - "ui_show_preview" => true,
81 + #region Options
89 82
90 - //AI
91 - "ai_suggestions" => false,
92 - "ai_engine_status"=> false,
93 - "ai_engine_message" => "",
83 + function get_option( $option, $default = null ) {
84 + $options = $this->get_all_options();
85 + return $options[$option] ?? $default;
86 + }
94 87
95 - //API
96 - "api_endpoint" => false,
97 - "api_token" => md5( time() . rand() ),
98 - ];
99 - }
88 + function list_options() {
89 + return [
90 + //Safemode
91 + "safe_mode_status" => "on", // on, off, whitelist
92 + "safe_mode_whitelist" => [],
93 + //"disallow_block_php" => true, // Do not allow PHP code to be execute through Blocks "code" parameter
94 + "code_blocks" => false,
95 + "code_blocks_whitelist" => [], // Whitelist for code blocks, if empty, all code blocks are allowed
96 +
97 + //LOGS
98 + "server_debug_mode" => false,
100 99
101 - function get_all_options( ) {
102 - $options = get_option( $this->option_name, $this->list_options( ) );
103 - $options = $this->sanitize_options( $options );
104 -
105 - return $options;
106 - }
100 + //UI
101 + "ui_show_preview" => false,
107 102
108 - function update_options( $options ) {
109 - $current_options = get_option($this->option_name);
110 -
111 - if ($current_options === $options) {
112 - // $this->log('💾 The options are already the expected value.');
113 - } else {
114 - if ( !update_option( $this->option_name, $options, false ) ) {
115 - $this->log( '💾 There was an issue updating the options.' );
116 - }
117 - }
118 -
119 - $options = $this->sanitize_options( $options );
120 - return $options;
121 - }
103 + //AI
104 + "ai_suggestions" => false,
105 + "ai_engine_status"=> false,
106 + "ai_engine_message" => "",
122 107
123 - function update_option( $option, $value ) {
124 - $options = $this->get_all_options();
125 - $options[$option] = $value;
126 - return $this->update_options( $options );
127 - }
108 + //API
109 + "api_endpoint" => false,
110 + "api_token" => md5( time() . rand() ),
111 +
112 + //MCP
113 + "mcp_support" => false,
128 114
129 - function reset_options() {
130 - if ( $this->get_all_options() === $this->list_options() ) {
131 - return true;
132 - }
133 - return $this->update_options( $this->list_options() );
134 - }
115 + //MAINTENANCE
116 + "clean_uninstall" => false,
117 + ];
118 + }
135 119
136 - // Validate and keep the options clean and logical.
137 - function sanitize_options( $options ) {
138 - $options_modified = false;
120 + function get_all_options( ) {
121 + $options = get_option( $this->option_name, [] );
122 + $defaults = $this->list_options();
123 +
124 + // Merge with defaults to ensure all options exist
125 + $options = array_merge( $defaults, $options );
126 +
127 + $options = $this->sanitize_options( $options );
128 + return $options;
129 + }
139 130
140 - // Make sure safe mode whitelist is an array
141 - if ( ! is_array( $options['safe_mode_whitelist'] ) ) {
142 - $options['safe_mode_whitelist'] = explode( ",", $options['safe_mode_whitelist'] );
143 - $options_modified = true;
144 - }
131 + function update_options( $options ) {
145 132
146 - // Update AI Engine status
147 - $options_modified = $this->updateAIEngineStatus( $options ) || $options_modified;
133 + $options = $this->sanitize_options( $options );
148 134
149 - // Disable AI related features if AI Engine is not available
150 - if ( ! $options['ai_engine_status'] && $options['ai_suggestions'] !== false ) {
151 - $options['ai_suggestions'] = false;
152 - $options_modified = true;
153 - }
135 + if ( !update_option( $this->option_name, $options, false ) ) {
136 + $this->log( '💾 There was an issue updating the options.' );
137 + }
138 +
139 + return $options;
140 + }
154 141
155 - if ( $options_modified ) {
156 - update_option( $this->option_name, $options, false );
157 - }
142 + function update_option( $option, $value ) {
143 + $options = $this->get_all_options();
144 + $options[$option] = $value;
145 + return $this->update_options( $options );
146 + }
158 147
159 - return $options;
160 - }
148 + function reset_options() {
149 + if ( $this->get_all_options() === $this->list_options() ) {
150 + return true;
151 + }
152 + return $this->update_options( $this->list_options() );
153 + }
161 154
162 - private function updateAIEngineStatus( &$options ) {
163 - global $mwai;
155 + // Validate and keep the options clean and logical.
156 + function sanitize_options( $options ) {
157 + $options_modified = false;
158 +
159 + // Ensure mcp_support exists in options
160 + if ( !isset( $options['mcp_support'] ) ) {
161 + $options['mcp_support'] = false;
162 + }
164 163
165 - if ( is_null( $mwai ) || ! isset( $mwai ) ) {
166 - $options['ai_engine_status'] = false;
167 - $options['ai_engine_message'] = 'AI Engine is not available.';
168 - return true;
169 - }
164 + // Make sure safe mode whitelist is an array
165 + if ( ! is_array( $options['safe_mode_whitelist'] ) ) {
166 + $options['safe_mode_whitelist'] = explode( ",", $options['safe_mode_whitelist'] );
167 + $options_modified = true;
168 + }
170 169
171 - try {
172 - $status = $mwai->checkStatus();
170 + // Update AI Engine status
171 + $options = $this->updateAIEngineStatus( $options );
173 172
174 - if ( $options['ai_engine_status'] != true || $options['ai_engine_message'] != $status ) {
175 - $options['ai_engine_status'] = true;
176 - $options['ai_engine_message'] = $status;
177 - return true;
178 - }
179 - } catch ( Exception $e ) {
180 - if ( $options['ai_engine_status'] != false || $options['ai_engine_message'] != $e->getMessage() ) {
181 - $options['ai_engine_status'] = false;
182 - $options['ai_engine_message'] = $e->getMessage();
183 - return true;
184 - }
185 - }
173 + // Disable AI related features if AI Engine is not available
174 + if ( ! $options['ai_engine_status'] ) {
175 + if ( $options['ai_suggestions'] !== false ) {
176 + $options['ai_suggestions'] = false;
177 + $options_modified = true;
178 + }
179 + // Note: We don't disable MCP support here anymore
180 + // It will be checked at runtime in the MCP class
181 + }
186 182
187 - return false;
188 - }
183 + return $options;
184 + }
189 185
190 - // #endregion
186 + private function updateAIEngineStatus( &$options ) {
187 + global $mwai;
191 188
192 - #region Snippets
189 + if ( is_null( $mwai ) || ! isset( $mwai ) ) {
190 + $options['ai_engine_status'] = false;
191 + $options['ai_engine_message'] = 'AI Engine is not available.';
193 192
194 - /**
195 - * Get snippet.
196 - *
197 - * @param $id
198 - * @return mixed
199 - */
200 - protected function get_snippet( $id ) {
201 - if ( $this->snippet === null ) {
202 - $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
203 - }
193 + return $options;
194 + }
204 195
205 - return $this->snippet->select_one( $id );
196 + try {
197 + $status = $mwai->checkStatus();
198 +
199 + $options['ai_engine_status'] = true;
200 + $options['ai_engine_message'] = is_array( $status ) ? "Environments: " . implode( ', ', $status ) : $status;
201 +
202 + } catch ( Exception $e ) {
203 +
204 + $options['ai_engine_status'] = false;
205 + $options['ai_engine_message'] = $e->getMessage();
206 206 }
207 207
208 - private function sanitize_arg( $name, $value ) {
209 - if ( $name[0] !== '$' ) { $name = '$' . $name; }
210 -
211 - if ( !empty( $value ) && !is_numeric( $value ) && $value[0] !== '"' && $value[strlen( $value ) - 1] !== '"' ) {
212 - $value = '"' . esc_sql( $value ) . '"';
213 - }
208 + return $options;
209 + }
214 210
215 - return [ $name, $value ];
216 - }
211 + #endregion
217 212
218 - function run_non_fn_snippet( $id, $code = null, $test = false ) {
219 - // Retrieve the snippet code from the provided code or via the snippet ID.
220 - if ( $code ) {
221 - $snippet = [ 'code' => $code ];
222 - } else {
223 - $snippet = $this->get_snippet( $id );
224 - }
225 -
226 - // Remove any PHP opening tag.
227 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
228 -
213 + #region Snippets
229 214
230 - if ( $test ) {
231 - $snippet['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $snippet['code'] );
232 - }
233 -
234 - $error = null;
235 - $output = null;
236 -
237 - try {
238 - ob_start();
239 - eval( $snippet['code'] );
240 - $output = ob_get_clean();
241 - } catch ( Throwable $e ) {
242 - $error = new Exception( 'Error executing the snippet, ' . $e->getMessage() );
243 - ob_clean();
244 - } finally {
245 - restore_error_handler();
246 - }
247 -
248 - // If in test mode, return output as an array of lines with an 'error' key if needed.
249 - if ( $test ) {
250 - $output = explode( "\n", trim( $output ) );
251 - if ( $error !== null ) {
252 - $output['error'] = $error->getMessage();
253 - }
254 - } else {
255 - if ( $error !== null ) {
256 - throw $error;
257 - }
258 - }
259 -
260 - return $output;
261 - }
215 + /**
216 + * Get snippet.
217 + *
218 + * @param $id
219 + * @return mixed
220 + */
221 + protected function get_snippet( $id ) {
222 + if ( $this->snippet === null ) {
223 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
224 + }
262 225
263 - function run_snippet( $id, $args = [], $params = [] )
264 - {
265 - // Static array to track defined functions
266 - static $defined_functions = array();
226 + return $this->snippet->select_one( $id );
227 + }
267 228
268 - if ( $id ) { // If there is an ID, we get the snippet, if not we get the data from the params
269 - $snippet = $this->get_snippet( $id );
270 - $this->snippet->get_function_snippets_data( $snippet ); // adds the function data to the snippet
229 + function add_snippet( $params ) {
271 230
272 - $params = [ // We set the params according to the snippet we fetched
273 - 'test' => false, // If we pass an ID to the function, we are not testing the snippet
274 - // 'test' => $params['test'] ?? false if needed we can still use ID and test at the same time (should not happen)
275 - 'code' => $snippet['code'],
276 - 'name' => $snippet['functionName'],
277 - 'args' => $snippet['functionArgs'],
278 - 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
279 - ];
280 - }
231 + $response = [
232 + "snippet" => null,
233 + "result" => false,
234 + ];
281 235
282 - // Sanitize all the arguments if the option is enabled
283 - if ( $this->get_option( 'sanitize_arguments', true ) ) {
236 + $this->snippet->validate( $params );
284 237
285 - if ( $args ) {
286 - foreach ( $args as $name => $value ) {
287 - list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value );
288 - unset( $args[$name] );
238 + $params = $this->snippet->formatParamsForDatabase( $params );
239 + $result = $this->snippet->insert( $params );
240 + $snippet = $this->snippet->select_one( $result );
289 241
290 - $args[$sanitizedName] = $sanitizedValue;
291 - }
292 - }
242 + if( $result ) {
243 + $params['id'] = (string)$result;
293 244
294 - foreach ( $params['values'] as $name => $value ) {
245 + $this->snippet->create_or_update_function_snippet( $params );
246 + $this->snippet->create_or_update_interval_snippet( $params );
295 247
296 - if( array_key_exists( 'input', $value) ) {
297 - list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'] );
298 - $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
299 - }
300 -
301 - if( array_key_exists( 'default', $value) ) {
302 - list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'] );
303 - $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
304 - }
305 - }
248 + $this->snippet->get_function_snippets_data( $snippet );
249 + }
306 250
307 - }
251 + $response['snippet'] = $snippet;
252 + $response['result'] = $result;
308 253
309 -
254 + return $response;
255 + }
310 256
311 - // Make sure the function is existing and is the one in the snippet
312 - if ( empty( $params['code'] ) ) {
313 - throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
314 - }
315 -
316 - if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
317 - throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
318 - }
257 + private function sanitize_arg( $name, $value, $type = null) {
258 + $real_type = gettype( $value );
319 259
320 - // Overwrite the default values with the provided ones
321 - if ( $args ) {
322 - foreach ( $args as $name => $value ) {
323 - $params['values'][$name]['input'] = $value;
324 - }
260 + if ( $name[0] !== '$' ) { $name = '$' . $name; }
325 261
326 - $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
327 - }
262 + if ( $type == null ) {
263 + $type = $real_type;
264 + }
328 265
329 - // Check if the function has already been defined
330 - if ( !in_array( $params['name'], $defined_functions ) ) {
266 + if ( $type != 'array' && !empty( $value ) && !is_numeric( $value ) && $value[0] !== '"' && $value[strlen( $value ) - 1] !== '"' ) {
267 + $value = '"' . esc_sql( $value ) . '"';
268 + }
331 269
332 - // If not, proceed with modification and definition
333 - if ( $params['test'] ) { // Make sure the echo statement uses a line break
334 - $params['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $params['code'] );
335 - } else { // Remove all echo statements
336 - $params['code'] = preg_replace( '/echo\s+(.+?);/s', '', $params['code'] );
337 - }
270 + if ( $type === 'array' && $real_type === 'string' ) {
271 + // We got a string like this: "["a", "b", "c"]" or "[ 1, 2, 3 ]"
272 + // We need to convert it to an array
273 + $value = str_replace( '"', '', $value );
274 + $value = str_replace( '[', '', $value );
275 + $value = str_replace( ']', '', $value );
276 + $value = explode( ',', $value );
277 + $value = array_map( 'trim', $value );
278 + }
338 279
339 - $params['code'] = "if (!function_exists('{$params['name']}')) {\n" . $params['code'] . "\n}\n";
280 + if ( $type === 'array' ) {
281 + // Convert to PHP array format instead of JSON
282 + $value = var_export( $value, true );
283 + }
340 284
341 - // Add the function name to the array to avoid redefinition
342 - $defined_functions[] = $params['name'];
343 - } else {
344 - // If already defined, just prepare to call the function without redefining it
345 - $params['code'] = '';
346 - }
285 + return [ $name, $value ];
286 + }
347 287
348 - // Prepare the code to be executed
349 - $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
350 - foreach ( $params['args'] as $index => $arg ) {
351 - $value = 'null'; // In case the argument is not provided it will be null
288 + function run_non_fn_snippet( $id, $code = null, $test = false, $prefix = '' ) {
289 + // Retrieve the snippet code from the provided code or via the snippet ID.
290 + if ( $code ) {
291 + $snippet = [ 'code' => $code ];
292 + } else {
293 + $snippet = $this->get_snippet( $id );
294 + }
352 295
353 - if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
296 + // Remove any PHP opening tag.
297 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
354 298
355 - // If the argument is provided, use it, if not use the default value
356 - if ( !empty( $params['values'][$arg]['input'] ) ) {
357 - $value = $params['values'][$arg]['input'];
299 + if ( $test ) {
300 + $snippet['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $snippet['code'] );
301 + }
358 302
359 - } else if ( !empty( $params['values'][$arg]['default'] ) ) {
360 - $value = $params['values'][$arg]['default'];
361 - }
362 - }
303 + if( $prefix ) {
304 + $snippet['code'] = $prefix . "\n" . $snippet['code'];
305 + }
306 +
307 + $error = null;
308 + $output = null;
309 +
310 + try {
311 + ob_start();
312 + eval( $snippet['code'] );
313 + $output = ob_get_clean();
314 + } catch ( Throwable $e ) {
315 + $snippet_id = $id ? " ( ID: $id )" : '(Content Gutenberg Block)';
316 + $this->log( '🔴 Error executing the snippet ' . $snippet_id . ' : ' . $e->getMessage() );
317 + ob_clean();
318 + } finally {
319 + restore_error_handler();
320 + }
321 +
322 + // If in test mode, return output as an array of lines with an 'error' key if needed.
323 + if ( $test ) {
324 + $output = explode( "\n", trim( $output ) );
325 + if ( $error !== null ) {
326 + $output['error'] = $error->getMessage();
327 + }
328 + } else {
329 + if ( $error !== null ) {
330 + throw $error;
331 + }
332 + }
333 +
334 + return $output;
335 + }
363 336
364 - $params['code'] .= "{$value}";
365 - if ( $index < count( $params['args'] ) - 1 ) {
366 - $params['code'] .= ', ';
367 - }
368 - }
369 - $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
337 + function run_snippet( $id, $args = [], $params = [] )
338 + {
339 + // Static array to track defined functions
340 + static $defined_functions = array();
370 341
371 - $error = null;
372 - $output = null;
342 + if ( $id ) { // If there is an ID, we get the snippet, if not we get the data from the params
343 + $snippet = $this->get_snippet( $id );
344 + $this->snippet->get_function_snippets_data( $snippet ); // adds the function data to the snippet
373 345
374 - try {
375 - ob_start();
376 - eval( $params['code'] );
377 - $output = ob_get_clean();
378 -
379 - if ( $params['test'] ){
380 - $output = explode( "\n", $output );
381 - }
382 -
383 - } catch ( Throwable $e ) {
384 - //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
385 - $error = new Exception(' Error executing the function, ' . $e->getMessage());
346 + $params = [ // We set the params according to the snippet we fetched
347 + 'test' => false, // If we pass an ID to the function, we are not testing the snippet
348 + // 'test' => $params['test'] ?? false if needed we can still use ID and test at the same time (should not happen)
349 + 'code' => $snippet['code'],
350 + 'name' => $snippet['functionName'],
351 + 'args' => $snippet['functionArgs'],
352 + 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
353 + ];
354 + }
386 355
387 - ob_clean();
388 - } finally {
389 - restore_error_handler();
390 - }
356 + // Sanitize all the arguments if the option is enabled
357 + if ( $this->get_option( 'sanitize_arguments', true ) ) {
391 358
392 - if ( $error !== null ) {
393 - if( $params['test'] ){
394 - $output['error'] = $error->getMessage();
395 - } else {
396 - throw $error;
397 - }
398 - }
359 + if ( $args ) {
360 + foreach ( $args as $name => $value ) {
361 + list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value );
362 + unset( $args[$name] );
399 363
400 - return $output;
401 - }
364 + $args[$sanitizedName] = $sanitizedValue;
365 + }
366 + }
402 367
368 + foreach ( $params['values'] as $name => $value ) {
403 369
404 - function parse_snippet( $code, $new_snippet = false ){
405 - $parser = ( new ParserFactory( ) )->createForNewestSupportedVersion( );
370 + if( array_key_exists( 'input', $value) ) {
371 + list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'], $value['type'] );
372 + $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
373 + }
406 374
407 - if( !$this->snippet ){
408 - $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
409 - }
375 + if( array_key_exists( 'default', $value) ) {
376 + list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'], $value['type'] );
377 + $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
378 + }
379 + }
410 380
411 - // First we check the function names are unique
412 - $fn = $this->snippet->sanitize_and_check_functions( $code, $new_snippet );
413 - if ( ! $fn['is_valid'] ) {
381 + }
414 382
415 - $lint = [
416 - 'line' => 1,
417 - 'attributes' => $fn['attributes'][0],
418 - 'raw_message' => implode(', ', $fn['errors'][0]),
419 - 'message' => implode(', ', $fn['errors'][0]),
420 - ];
383 + // Make sure the function is existing and is the one in the snippet
384 + if ( empty( $params['code'] ) ) {
385 + throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
386 + }
421 387
422 - return $lint;
423 - }
388 + if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
389 + throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
390 + }
424 391
425 - try {
426 - $stmts = $parser->parse( $code );
427 - $result = $stmts;
428 - } catch ( PhpParser\Error $e ) {
392 + // Overwrite the default values with the provided ones
393 + if ( $args ) {
394 + foreach ( $args as $name => $value ) {
395 + $params['values'][$name]['input'] = $value;
396 + }
429 397
430 - $lint = [
431 - 'line' => $e->getStartLine(),
432 - 'attributes' => $e->getAttributes(),
433 - 'raw_message' => $e->getRawMessage(),
434 - 'message' => $e->getMessage(),
435 - ];
398 + $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
399 + }
436 400
437 - return $lint;
438 - }
401 + // Check if the function has already been defined
402 + if ( !in_array( $params['name'], $defined_functions ) ) {
439 403
440 - return null;
441 - }
404 + // If not, proceed with modification and definition
405 + if ( $params['test'] ) { // Make sure the echo statement uses a line break
406 + $params['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $params['code'] );
407 + } else { // Remove all echo statements
408 + $params['code'] = preg_replace( '/echo\s+(.+?);/s', '', $params['code'] );
409 + }
442 410
443 - public function get_js_functions_to_push() {
444 - $functions = $this->snippet->get_functions();
445 - $js_functions = [];
446 - foreach ( $functions as &$function ) {
447 - if ( !isset( $function['target'] ) ) {
448 - $function['target'] = 'php';
449 - }
450 - if ( $function['target'] == 'js' ) {
451 - $js_functions[] = $function;
452 - }
453 - }
454 - $snippets = [];
455 - foreach ( $js_functions as $function ) {
456 - $snippet = $this->snippet->select_one( $function['snippetId'] );
457 - $snippet['function_info'] = $function; // Add function info to snippet
458 - $snippets[] = $snippet;
459 - }
460 -
461 - return $this->generate_js_functions_code( $snippets );
462 - }
463 -
464 - function generate_js_functions_code ($snippets ) {
465 - $code = "";
466 - foreach ( $snippets as $snippet ) {
467 - $function_code = $snippet['code'];
468 - $function_info = $snippet['function_info'];
469 -
470 - // Extract function name and arguments
471 - preg_match( '/(?:const|let|var)?\s*(\w+)\s*=\s*\((.*?)\)\s*=>/', $function_code, $matches );
472 - $function_name = $matches[1] ?? $function_info['name'];
473 - $function_args = $matches[2] ?? '';
474 -
475 - // Prepare default values
476 - $default_args = [];
477 - foreach ( $function_info['args'] as $arg ) {
478 - if ( isset( $arg['default'] ) && $arg['default'] !== '' ) {
479 - $default_args[$arg['name']] = $arg['default'];
480 - }
481 - }
482 -
483 - // Modify function to use default values
484 - if ( !empty( $default_args ) ) {
485 - $new_args = explode( ',', $function_args );
486 - foreach ( $new_args as &$arg ) {
487 - $arg = trim( $arg );
488 - if ( isset( $default_args[$arg] ) ) {
489 - $arg .= " = " . json_encode( $default_args[$arg] );
490 - }
491 - }
492 - $new_args_string = implode( ', ', $new_args );
493 - $function_code = preg_replace(
494 - '/(\w+)\s*=\s*\((.*?)\)\s*=>/',
495 - "$1 = ($new_args_string) =>",
496 - $function_code
497 - );
498 - }
499 -
500 - $code .= $function_code . "\n\n";
501 - }
411 + $params['code'] = "if (!function_exists('{$params['name']}')) {\n" . $params['code'] . "\n}\n";
502 412
503 - return $code;
504 - }
413 + // Add the function name to the array to avoid redefinition
414 + $defined_functions[] = $params['name'];
415 + } else {
416 + // If already defined, just prepare to call the function without redefining it
417 + $params['code'] = '';
418 + }
505 419
420 + // Prepare the code to be executed
421 + $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
422 + foreach ( $params['args'] as $index => $arg ) {
423 + $value = 'null'; // In case the argument is not provided it will be null
506 424
507 - /**
508 - * [STATIC] Execute active snippets.
509 - *
510 - * @return array
511 - */
512 - public function execute_active_snippets() {
425 + if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
513 426
514 - $blocked = false;
515 - $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : null;
516 - if ( $page === 'mwcode_settings' || !Meow_MWCODE_Core::is_white_listed_rest() ) {
517 - $blocked = true;
518 - }
427 + // If the argument is provided, use it, if not use the default value
428 + if ( !empty( $params['values'][$arg]['input'] ) ) {
429 + $value = $params['values'][$arg]['input'];
519 430
520 - if ( empty( $this->snippet ) ) {
521 - $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
522 - }
431 + } else if ( !empty( $params['values'][$arg]['default'] ) ) {
432 + $value = $params['values'][$arg]['default'];
433 + }
434 + }
523 435
524 - $ts = $this->get_option( 'thrown_snippet', null );
525 - if ( !empty( $ts ) ) {
526 - $this->log( "⚠️ Your snippet \"{$ts['name']}\" has thrown a fatal error last time, so we disabled it. Please check the logs for more information." );
527 - $this->snippet->force_disable( $ts['id'] );
528 - $this->update_option( 'thrown_snippet', null );
529 - }
436 + $params['code'] .= "{$value}";
437 + if ( $index < count( $params['args'] ) - 1 ) {
438 + $params['code'] .= ', ';
439 + }
440 + }
530 441
531 - $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
532 - // Get all active snippets
442 + $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
533 443
534 -
444 + $error = null;
445 + $output = null;
446 +
447 + try {
448 + ob_start();
449 + eval( $params['code'] );
450 + $output = ob_get_clean();
451 +
452 + if ( $params['test'] ){
453 + $output = explode( "\n", $output );
454 + }
455 +
456 + } catch ( Throwable $e ) {
457 + //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
458 + $error = new Exception(' Error executing the function, ' . $e->getMessage());
535 459
536 - $snippets = $this->snippet->select(
537 - null, // offset
538 - -1, // limit
539 - [
540 - [ 'accessor' => 'active', 'value' => 1 ],
541 - [ 'accessor' => 'scope', 'value' => $scope ],
542 - ], // filter
543 - [ 'accessor' => 'priority', 'by' => 'DESC' ] // sort
544 - )['data'];
460 + ob_clean();
461 + } finally {
462 + restore_error_handler();
463 + }
545 464
465 + if ( $error !== null ) {
466 + if( $params['test'] ){
467 + $output['error'] = $error->getMessage();
468 + } else {
469 + throw $error;
470 + }
471 + }
546 472
547 - if ( empty( $snippets ) ) {
548 - return;
473 + return $output;
474 + }
475 +
476 +
477 + function parse_snippet( $code, $new_snippet = false ){
478 + $parser = ( new ParserFactory( ) )->createForNewestSupportedVersion( );
479 +
480 + if( !$this->snippet ){
481 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
482 + }
483 +
484 + // First we check the function names are unique
485 + $fn = $this->snippet->sanitize_and_check_functions( $code, $new_snippet );
486 + if ( ! $fn['is_valid'] ) {
487 +
488 + $lint = [
489 + 'line' => 1,
490 + 'attributes' => $fn['attributes'][0],
491 + 'raw_message' => implode(', ', $fn['errors'][0]),
492 + 'message' => implode(', ', $fn['errors'][0]),
493 + ];
494 +
495 + return $lint;
496 + }
497 +
498 + try {
499 + $stmts = $parser->parse( $code );
500 + $result = $stmts;
501 + } catch ( PhpParser\Error $e ) {
502 +
503 + $lint = [
504 + 'line' => $e->getStartLine(),
505 + 'attributes' => $e->getAttributes(),
506 + 'raw_message' => $e->getRawMessage(),
507 + 'message' => $e->getMessage(),
508 + ];
509 +
510 + return $lint;
511 + }
512 +
513 + return null;
514 + }
515 +
516 + public function get_js_functions_to_push() {
517 + $functions = $this->snippet->get_functions();
518 + $js_functions = [];
519 + foreach ( $functions as &$function ) {
520 + if ( !isset( $function['target'] ) ) {
521 + $function['target'] = 'php';
522 + }
523 + if ( $function['target'] == 'js' ) {
524 + $js_functions[] = $function;
525 + }
526 + }
527 + $snippets = [];
528 + foreach ( $js_functions as $function ) {
529 + $snippet = $this->snippet->select_one( $function['snippetId'] );
530 + $snippet['function_info'] = $function; // Add function info to snippet
531 + $snippets[] = $snippet;
532 + }
533 +
534 + return $this->generate_js_functions_code( $snippets );
535 + }
536 +
537 + function generate_js_functions_code ($snippets ) {
538 + $code = "";
539 + foreach ( $snippets as $snippet ) {
540 + $function_code = $snippet['code'];
541 + $function_info = $snippet['function_info'];
542 +
543 + // Extract function name and arguments
544 + preg_match( '/(?:const|let|var)?\s*(\w+)\s*=\s*\((.*?)\)\s*=>/', $function_code, $matches );
545 + $function_name = $matches[1] ?? $function_info['name'];
546 + $function_args = $matches[2] ?? '';
547 +
548 + // Prepare default values
549 + $default_args = [];
550 + foreach ( $function_info['args'] as $arg ) {
551 + if ( isset( $arg['default'] ) && $arg['default'] !== '' ) {
552 + $default_args[$arg['name']] = $arg['default'];
549 553 }
554 + }
550 555
551 - $snippets = array_map( function ( $snippet ) use ( $blocked ) {
552 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
553 - $snippet['blocked'] = $blocked;
556 + // Modify function to use default values
557 + if ( !empty( $default_args ) ) {
558 + $new_args = explode( ',', $function_args );
559 + foreach ( $new_args as &$arg ) {
560 + $arg = trim( $arg );
561 + if ( isset( $default_args[$arg] ) ) {
562 + $arg .= " = " . json_encode( $default_args[$arg] );
563 + }
564 + }
565 + $new_args_string = implode( ', ', $new_args );
566 + $function_code = preg_replace(
567 + '/(\w+)\s*=\s*\((.*?)\)\s*=>/',
568 + "$1 = ($new_args_string) =>",
569 + $function_code
570 + );
571 + }
554 572
555 - // If the snippet must be executed only in the frontend, we bypass the block
556 - if ( !is_admin() && $snippet['scope'] === 'frontend' ) {
557 - $snippet['blocked'] = false;
558 - }
573 + $code .= $function_code . "\n\n";
574 + }
559 575
560 - return $snippet;
561 - }, $snippets );
576 + return $code;
577 + }
562 578
563 -
564 579
565 - return $snippets;
580 + /**
581 + * [STATIC] Execute active snippets.
582 + *
583 + * @return array
584 + */
585 + public function execute_active_snippets() {
586 +
587 + $blocked = false;
588 + $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : null;
589 +
590 +
591 + if ( $page === 'mwcode_settings' ) {
592 + // If we blocks global snippets like nonce_life filter, we would block the settings page so let's remove the block for this page
593 +
594 + $blocked = false;
595 + //$blocked = true;
566 596 }
597 + // Block REST requests that aren't whitelisted
598 + elseif ( MeowKit_MWCODE_Helpers::is_rest() && !Meow_MWCODE_Core::is_white_listed_rest() ) {
599 + $blocked = true;
600 + }
567 601
602 + if ( empty( $this->snippet ) ) {
603 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
604 + }
568 605
569 - #endregion
606 + $ts = $this->get_option( 'thrown_snippet', null );
607 + if ( !empty( $ts ) ) {
608 + $this->log( "⚠️ Your snippet \"{$ts['name']}\" has thrown a fatal error last time, so we disabled it. Please check the logs for more information." );
609 + $this->snippet->force_disable( $ts['id'] );
610 + $this->update_option( 'thrown_snippet', null );
611 + }
570 612
571 - #reion Shortcodes
613 + $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
614 + // Get all active snippets
572 615
573 - function content_shortcode( $atts ) {
616 + $snippets = $this->snippet->select(
617 + null, // offset
618 + -1, // limit
619 + [
620 + [ 'accessor' => 'active', 'value' => 1 ],
621 + [ 'accessor' => 'scope', 'value' => $scope ],
622 + ], // filter
623 + [ 'accessor' => 'priority', 'by' => 'DESC' ] // sort
624 + )['data'];
574 625
575 - $atts = shortcode_atts( array(
576 - 'id' => null,
577 - ), $atts );
626 + if ( empty( $snippets ) ) {
627 + return;
628 + }
578 629
579 - $id = $atts['id'];
580 - if ( empty( $id ) ) {
581 - return '<b>Code Engine:</b> Please provide a snippet ID.';
582 - }
630 + $snippets = array_map( function ( $snippet ) use ( $blocked ) {
631 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
632 + $snippet['blocked'] = $blocked;
583 633
584 - $snippet = $this->get_snippet( $id );
634 + // If the snippet must be executed only in the frontend, we bypass the block
635 + if ( !is_admin() && $snippet['scope'] === 'frontend' ) {
636 + $snippet['blocked'] = false;
637 + }
585 638
586 - if ( empty( $snippet ) ) {
587 - return '<b>Code Engine:</b> The snippet does not exist.';
588 - }
639 + return $snippet;
640 + }, $snippets );
589 641
590 - //Check if the snippet scope is either content_php or content_js
591 - $is_content_php = $snippet['scope'] === 'content_php';
592 - $is_content_js = $snippet['scope'] === 'content_js';
642 + return $snippets;
643 + }
593 644
594 - if ( !$is_content_php && !$is_content_js ) {
595 - return '<b>Code Engine:</b> The snippet is not a content snippet.';
596 - }
597 645
598 - //Check if the snippet is active
599 - if ( !$snippet['active'] ) {
600 - return '<b>Code Engine:</b> The snippet is not active.';
601 - }
646 + #endregion
602 647
603 - $output = '<b>Code Engine:</b> No output.';
648 + #region Shortcodes
649 + function separate_mwcode_atts( $atts ) {
604 650
605 - if ( $is_content_js ) {
606 - $output = '<script>' . $snippet['code'] . '</script>';
607 - }
651 + if( array_key_exists( 'id', $atts ) ) unset( $atts['id'] );
652 + if( array_key_exists( 'target', $atts ) ) unset( $atts['target'] );
653 + if( array_key_exists( 'code', $atts ) ) unset( $atts['code'] );
608 654
609 - if ( $is_content_php ) {
610 - $output = $this->run_non_fn_snippet( $id );
611 - }
655 + return $atts;
656 + }
612 657
613 - return $output;
614 - }
658 + function content_shortcode( $atts ) {
615 659
616 - #endregion
660 + $user_atts = $this->separate_mwcode_atts( $atts );
617 661
618 - #region Logs
662 + $atts = shortcode_atts( array(
663 + 'id' => null,
664 + 'target' => null, // js or php
665 + 'code' => null, // For Guttenberg block usage
666 + ), $atts, 'code-engine' );
619 667
620 - function get_logs() {
621 - $log_file_path = $this->get_logs_path();
668 + $id = $atts['id'];
669 + $target = $atts['target'];
670 + $code = $atts['code'];
671 + $current_post = get_post();
672 +
673 + $no_js = defined( 'DISALLOW_UNFILTERED_HTML' ) && DISALLOW_UNFILTERED_HTML;
674 + $allow_php = $this->get_option( 'code_blocks', false );
675 + $allow_php_whitelist = $this->get_option( 'code_blocks_whitelist', [] );
676 +
677 + // If the ID is null, it means it comes from a Guttenberg block
678 + $is_block = empty( $id ) && !empty( $code );
622 679
623 - if ( !file_exists( $log_file_path ) ) {
624 - return "Empty log file.";
625 - }
680 + if( $is_block ) {
626 681
627 - $content = file_get_contents( $log_file_path );
628 - $lines = explode( "\n", $content );
629 - $lines = array_filter( $lines );
630 - $lines = array_reverse( $lines );
631 - $content = implode( "\n", $lines );
632 - return $content;
633 - }
682 + if( $target !== 'js' && $target !== 'php' ) {
683 + return '<b>Code Engine:</b> Please provide a valid target (js or php).';
684 + }
634 685
635 - function clear_logs() {
636 - $logPath = $this->get_logs_path();
637 - if ( file_exists( $logPath ) ) {
638 - unlink( $logPath );
639 - }
686 + if ( $no_js && $target === 'js' ) {
687 + return '<b>Code Engine:</b> Code Block JS are disabled because unfiltered HTML is not allowed on your server.';
688 + }
640 689
641 - $options = $this->get_all_options();
642 - $options['logs_path'] = null;
643 - $this->update_options( $options );
644 - }
690 + if ( $target === 'php' ) {
645 691
646 - function get_logs_path() {
647 - $uploads_dir = wp_upload_dir();
648 - $uploads_dir_path = trailingslashit( $uploads_dir['basedir'] );
692 + if ( !$allow_php ) {
693 + return '<b>Code Engine:</b> Code Block PHP are disabled. If you are an administrator, you can enable it in the settings, this is not recommended. Please use a Content Snippet ( PHP ) instead.';
694 + }
649 695
650 - $path = $this->get_option( 'logs_path' );
696 + if ( !empty( $allow_php_whitelist ) && !in_array( $current_post->ID, $allow_php_whitelist ) ) {
697 + return '<b>Code Engine:</b> Code Block PHP are disabled for this post. If you are an administrator, you can enable it in the settings, this is not recommended. Please use a Content Snippet ( PHP ) instead.';
698 + }
699 + }
651 700
652 - if ( $path && file_exists( $path ) ) {
653 - // make sure the path is legal (within the uploads directory with the MWCODE_PREFIX and log extension)
654 - if ( strpos( $path, $uploads_dir_path ) !== 0 || strpos( $path, MWCODE_PREFIX ) === false || substr( $path, -4 ) !== '.log' ) {
655 - $path = null;
656 - } else {
657 - return $path;
658 - }
659 - }
701 + // Because the code from Blocks are sanitized, we need to replace the &quot; with "
702 + $code = str_replace( '&quot;', '"', $code );
660 703
661 - if ( !$path ) {
662 - $path = $uploads_dir_path . MWCODE_PREFIX . "_" . $this->random_ascii_chars() . ".log";
663 - if ( !file_exists( $path ) ) {
664 - touch( $path );
665 - }
666 - $options = $this->get_all_options();
667 - $options['logs_path'] = $path;
668 - $this->update_options( $options );
669 - }
704 + if ( $target === 'js' ) {
705 + $output = '<script>' . $code . '</script>';
706 + }
670 707
671 - return $path;
672 - }
708 + if ( $target === 'php' ) {
709 + $output = $this->run_non_fn_snippet( null, $code );
710 + }
673 711
674 - function log( $data = null ) {
675 - if ( !$this->get_option( 'server_debug_mode', false ) ) { return false; }
676 - $log_file_path = $this->get_logs_path();
677 - $fh = @fopen( $log_file_path, 'a' );
678 - if ( !$fh ) { return false; }
679 - $date = date( "Y-m-d H:i:s" );
680 - if ( is_null( $data ) ) {
681 - fwrite( $fh, "\n" );
682 - }
683 - else {
684 - fwrite( $fh, "$date: {$data}\n" );
685 - //$this->log( "[MWCODE] $data" );
686 - }
687 - fclose( $fh );
688 - return true;
689 - }
712 + return $output;
713 + }
690 714
691 - private function random_ascii_chars( $length = 8 ) {
692 - $characters = array_merge( range( 'A', 'Z' ), range( 'a', 'z' ), range( '0', '9' ) );
693 - $characters_length = count( $characters );
694 - $random_string = '';
715 + // If not a block, we get the snippet by ID
716 + // If the ID is not null, it means it comes from a shortcode
717 + if ( empty( $id ) && empty( $code ) ) {
718 + return '<b>Code Engine:</b> Please provide a snippet ID.';
719 + }
695 720
696 - for ( $i = 0; $i < $length; $i++ ) {
697 - $random_string .= $characters[rand(0, $characters_length - 1)];
698 - }
721 + $snippet = $this->get_snippet( $id );
699 722
700 - return $random_string;
701 - }
723 + if ( empty( $snippet ) ) {
724 + return '<b>Code Engine:</b> The snippet does not exist.';
725 + }
702 726
703 - #endregion
727 + //Check if the snippet scope is either content_php or content_js
728 + $is_content_php = $snippet['scope'] === 'content_php';
729 + $is_content_js = $snippet['scope'] === 'content_js';
704 730
705 - #region Helpers
731 + if ( !$is_content_php && !$is_content_js ) {
732 + return '<b>Code Engine:</b> The snippet is not a content snippet.';
733 + }
706 734
707 - /**
708 - * Check if the request is from a white-listed REST route.
709 - *
710 - * @return bool
711 - */
712 - public static function is_white_listed_rest() {
713 - $authorized = false;
714 - $white_listed = array(
715 - 'mwai/v1',
716 - 'mwai-ui/v1',
717 - 'media-file-renamer/v1',
718 - 'media-cleaner/v1',
719 - 'wplr/v1',
720 - 'code-engine/v1',
721 - 'wp/v2',
722 - 'meow-gallery/v1',
723 - );
735 + if( $no_js && $is_content_js ) {
736 + return '<b>Code Engine:</b> Code Engine JS snippets are disabled because unfiltered HTML is not allowed on your server.';
737 + }
724 738
725 - $white_listed = apply_filters( 'meow_mwcode_white_listed_rest', $white_listed );
739 + //Check if the snippet is active
740 + if ( !$snippet['active'] ) {
741 + return '<b>Code Engine:</b> The snippet is not active.';
742 + }
726 743
727 - $route = isset( $_SERVER['REQUEST_URI'] ) ? $_SERVER['REQUEST_URI'] : null;
728 - $requested_route = null;
729 -
730 - if ( $route ) {
731 - $route_parts = explode( '/wp-json/', $route );
732 -
733 - if ( isset( $route_parts[1] ) ) {
734 - $requested_route = trim( $route_parts[1], '/' );
735 - foreach ( $white_listed as $white_listed_route ) {
736 - if ( strpos( $requested_route, $white_listed_route ) === 0 ) {
737 - $authorized = true;
738 - $authorized = apply_filters( 'meow_mwcode_white_listed_rest_authorized', $authorized, $requested_route );
739 - return $authorized;
740 - }
741 - }
742 - }
743 -
744 - if ( is_admin() ) {
745 - $authorized = true;
744 + $output = '<b>Code Engine:</b> No output.';
746 745
747 - $authorized = apply_filters( 'meow_mwcode_white_listed_rest_authorized', $authorized, $requested_route );
748 - return $authorized;
749 - }
746 + if ( $is_content_js ) {
747 + $output = '<script>' . $snippet['code'] . '</script>';
748 + }
750 749
750 + if ( $is_content_php ) {
751 + $prefix = "\$mwcode_atts = unserialize( '" . serialize( $user_atts ) . "' );";
752 + $output = $this->run_non_fn_snippet( $id, null, false, $prefix );
753 + }
751 754
752 - }
755 + return $output;
756 + }
753 757
754 - $authorized = apply_filters( 'meow_mwcode_white_listed_rest_authorized', $authorized, $requested_route );
755 - return $authorized;
758 + #endregion
759 +
760 + #region Logs
761 +
762 + function get_logs() {
763 + $log_file_path = $this->get_logs_path();
764 +
765 + if ( !file_exists( $log_file_path ) ) {
766 + return "Empty log file.";
756 767 }
757 768
758 - #endregion
769 + $content = file_get_contents( $log_file_path );
770 + $lines = explode( "\n", $content );
771 + $lines = array_filter( $lines );
772 + $lines = array_reverse( $lines );
773 + $content = implode( "\n", $lines );
774 + return $content;
775 + }
776 +
777 + function clear_logs() {
778 + $logPath = $this->get_logs_path();
779 + if ( file_exists( $logPath ) ) {
780 + unlink( $logPath );
781 + }
782 +
783 + $options = $this->get_all_options();
784 + $options['logs_path'] = null;
785 + $this->update_options( $options );
786 + }
787 +
788 + function get_logs_path() {
789 + $uploads_dir = wp_upload_dir();
790 + $uploads_dir_path = trailingslashit( $uploads_dir['basedir'] );
791 +
792 + $path = $this->get_option( 'logs_path' );
793 +
794 + if ( $path && file_exists( $path ) ) {
795 + // make sure the path is legal (within the uploads directory with the MWCODE_PREFIX and log extension)
796 + if ( strpos( $path, $uploads_dir_path ) !== 0 || strpos( $path, MWCODE_PREFIX ) === false || substr( $path, -4 ) !== '.log' ) {
797 + $path = null;
798 + } else {
799 + return $path;
800 + }
801 + }
802 +
803 + if ( !$path ) {
804 + $path = $uploads_dir_path . MWCODE_PREFIX . "_" . $this->random_ascii_chars() . ".log";
805 + if ( !file_exists( $path ) ) {
806 + touch( $path );
807 + }
808 + $options = $this->get_all_options();
809 + $options['logs_path'] = $path;
810 + $this->update_options( $options );
811 + }
812 +
813 + return $path;
814 + }
815 +
816 + function log( $data = null ) {
817 + if ( !$this->get_option( 'server_debug_mode', false ) ) { return false; }
818 + $log_file_path = $this->get_logs_path();
819 + $fh = @fopen( $log_file_path, 'a' );
820 + if ( !$fh ) { return false; }
821 + $date = date( "Y-m-d H:i:s" );
822 + if ( is_null( $data ) ) {
823 + fwrite( $fh, "\n" );
824 + }
825 + else {
826 + fwrite( $fh, "$date: {$data}\n" );
827 + //$this->log( "[MWCODE] $data" );
828 + }
829 + fclose( $fh );
830 + return true;
831 + }
832 +
833 + private function random_ascii_chars( $length = 8 ) {
834 + $characters = array_merge( range( 'A', 'Z' ), range( 'a', 'z' ), range( '0', '9' ) );
835 + $characters_length = count( $characters );
836 + $random_string = '';
837 +
838 + for ( $i = 0; $i < $length; $i++ ) {
839 + $random_string .= $characters[rand(0, $characters_length - 1)];
840 + }
841 +
842 + return $random_string;
843 + }
844 +
845 + #endregion
846 +
847 + #region Helpers
848 +
849 + /**
850 + * Check if the request is from a white-listed REST route.
851 + *
852 + * @return bool
853 + */
854 + public static function is_white_listed_rest() {
855 + $options = get_option( 'mwcode_snippet_vault_options', array() );
856 +
857 + // Early return if bypass is enabled
858 + if ( !empty( $options['bypass_rest_security'] ) ) {
859 + return true;
860 + }
861 +
862 + // Early return for admin requests
863 + if ( is_admin() ) {
864 + return apply_filters( 'mwcode_rest_authorized', true, null );
865 + }
866 +
867 + // Get the requested route
868 + $requested_route = self::get_requested_rest_route();
869 + if ( !$requested_route ) {
870 + return apply_filters( 'mwcode_rest_authorized', false, null );
871 + }
872 +
873 + // Check against whitelist
874 + $white_listed = apply_filters( 'mwcode_rest_whitelist', array(
875 + 'mwai/v1',
876 + 'mwai-ui/v1',
877 + 'media-file-renamer/v1',
878 + 'media-cleaner/v1',
879 + 'wplr/v1',
880 + 'code-engine/v1',
881 + 'wp/v2',
882 + 'meow-gallery/v1',
883 + 'mcp/v1',
884 + ));
885 +
886 + $authorized = self::is_route_whitelisted( $requested_route, $white_listed );
887 +
888 + // Log if debug mode is enabled
889 + if ( !empty( $options['server_debug_mode'] ) ) {
890 + self::log_route_status( $requested_route, $authorized );
891 + }
892 +
893 + return apply_filters( 'mwcode_rest_authorized', $authorized, $requested_route );
894 + }
895 +
896 + /**
897 + * Extract the REST route from the request URI.
898 + *
899 + * @return string|null
900 + */
901 + public static function get_requested_rest_route() {
902 + if ( !isset( $_SERVER['REQUEST_URI'] ) ) {
903 + return null;
904 + }
905 +
906 + $route_parts = explode( '/wp-json/', $_SERVER['REQUEST_URI'] );
907 +
908 + if ( isset( $route_parts[1] ) ) {
909 + return trim( $route_parts[1], '/' );
910 + }
911 +
912 + return null;
913 + }
914 +
915 + /**
916 + * Check if a route is in the whitelist.
917 + *
918 + * @param string $route The route to check
919 + * @param array $white_listed The whitelist array
920 + * @return bool
921 + */
922 + private static function is_route_whitelisted( $route, $white_listed ) {
923 + foreach ( $white_listed as $white_listed_route ) {
924 + if ( strpos( $route, $white_listed_route ) === 0 ) {
925 + return true;
926 + }
927 + }
928 + return false;
929 + }
930 +
931 + /**
932 + * Log the route authorization status.
933 + *
934 + * @param string $route The route being checked
935 + * @param bool $authorized Whether the route is authorized
936 + */
937 + private static function log_route_status( $route, $authorized ) {
938 + global $mwcode_core;
939 +
940 + $message = $authorized
941 + ? "✅ REST route authorized: " . $route
942 + : "❌ REST route rejected (not whitelisted): " . $route;
943 +
944 + if ( isset( $mwcode_core ) ) {
945 + $mwcode_core->log( $message );
946 + } else {
947 + error_log( "[Code Engine] " . $message );
948 + }
949 + }
950 +
951 + #endregion
759 952 }
760 953
761 954 ?>