PluginProbe
Code Engine – PHP Snippets, AI Functions & Automation for WordPress / 0.5.7
Code Engine – PHP Snippets, AI Functions & Automation for WordPress v0.5.7
0.5.7 0.5.6 0.5.5 0.5.4 0.5.3 0.5.2 0.5.1 0.5.0 0.4.9 0.4.8 0.4.7 0.4.6 trunk 0.0.1 0.0.2 0.2.8 0.2.9 0.3.0 0.3.1 0.3.2 0.3.3 0.3.4 0.3.5 0.3.6 0.3.7 All 33 releases
← All changes | classes/core.php +256 -102 0.3.60.5.7 View file →
@@ -12,9 +12,14 @@
12 12 public $is_rest = false;
13 13 public $is_cli = false;
14 14 public $site_url = null;
15 15 public $mwcode = null;
16 + public $licenser = null;
16 17
18 + // IDs of global snippets already executed this request (by the plugins_loaded pass
19 + // or by load_global_snippets), so a global never runs twice and never re-declares.
20 + public $loaded_global_ids = [];
21 +
17 22 private $option_name = 'mwcode_options';
18 23
19 24 public function __construct() {
20 25 global $mwcode;
@@ -19,9 +24,9 @@
19 24 public function __construct() {
20 25 global $mwcode;
21 26
22 27 $this->site_url = get_site_url();
23 - $this->is_rest = MeowCommon_Helpers::is_rest();
28 + $this->is_rest = MeowKit_MWCODE_Helpers::is_rest();
24 29 $this->is_cli = defined( 'WP_CLI' ) && WP_CLI;
25 30
26 31 // Snippets
27 32 $snippet = new Meow_MWCODE_Modules_Snippet( $this );
@@ -37,8 +42,13 @@
37 42 add_action( 'plugins_loaded', array( $this, 'init' ) );
38 43 }
39 44
40 45 function init() {
46 + // Initialize the licenser for Pro version
47 + if ( class_exists( 'MeowKitPro_MWCODE_Licenser' ) ) {
48 + $this->licenser = new MeowKitPro_MWCODE_Licenser( MWCODE_PREFIX, MWCODE_ENTRY, MWCODE_DOMAIN, MWCODE_ITEM_ID, MWCODE_VERSION );
49 + }
50 +
41 51 // Part of the core, settings and stuff
42 52 $this->admin = new Meow_MWCODE_Admin( $this );
43 53
44 54 // Only for REST
@@ -96,8 +106,9 @@
96 106
97 107 //AI
98 108 "ai_suggestions" => false,
99 109 "ai_engine_status"=> false,
110 + "mwai_active" => false,
100 111 "ai_engine_message" => "",
101 112
102 113 //API
103 114 "api_endpoint" => false,
@@ -104,8 +115,12 @@
104 115 "api_token" => md5( time() . rand() ),
105 116
106 117 //MCP
107 118 "mcp_support" => false,
119 + "mcp_functions" => false,
120 +
121 + //MAINTENANCE
122 + "clean_uninstall" => false,
108 123 ];
109 124 }
110 125
111 126 function get_all_options( ) {
@@ -119,19 +134,15 @@
119 134 return $options;
120 135 }
121 136
122 137 function update_options( $options ) {
123 - $current_options = get_option($this->option_name);
124 138
125 - if ($current_options === $options) {
126 - // $this->log('💾 The options are already the expected value.');
127 - } else {
128 - if ( !update_option( $this->option_name, $options, false ) ) {
129 - $this->log( '💾 There was an issue updating the options.' );
130 - }
139 + $options = $this->sanitize_options( $options );
140 +
141 + if ( !update_option( $this->option_name, $options, false ) ) {
142 + //$this->log( '💾 There was an issue updating the options.' );
131 143 }
132 -
133 - $options = $this->sanitize_options( $options );
144 +
134 145 return $options;
135 146 }
136 147
137 148 function update_option( $option, $value ) {
@@ -162,9 +173,9 @@
162 173 $options_modified = true;
163 174 }
164 175
165 176 // Update AI Engine status
166 - $options_modified = $this->updateAIEngineStatus( $options ) || $options_modified;
177 + $options = $this->updateAIEngineStatus( $options );
167 178
168 179 // Disable AI related features if AI Engine is not available
169 180 if ( ! $options['ai_engine_status'] ) {
170 181 if ( $options['ai_suggestions'] !== false ) {
@@ -174,12 +185,8 @@
174 185 // Note: We don't disable MCP support here anymore
175 186 // It will be checked at runtime in the MCP class
176 187 }
177 188
178 - if ( $options_modified ) {
179 - update_option( $this->option_name, $options, false );
180 - }
181 -
182 189 return $options;
183 190 }
184 191
185 192 private function updateAIEngineStatus( &$options ) {
@@ -184,31 +191,17 @@
184 191
185 192 private function updateAIEngineStatus( &$options ) {
186 193 global $mwai;
187 194
188 - if ( is_null( $mwai ) || ! isset( $mwai ) ) {
189 - $options['ai_engine_status'] = false;
190 - $options['ai_engine_message'] = 'AI Engine is not available.';
191 - return true;
192 - }
195 + // AI Engine is active (regardless of whether an API key is configured).
196 + // MCP exposure only needs AI Engine present, not a key, so the MCP toggles
197 + // gate on this rather than on mwai_has_ai.
198 + $options['mwai_active'] = !empty( $mwai );
199 + $options['mwai_has_ai'] = !empty( $mwai ) && method_exists( $mwai, 'hasAI' ) && $mwai->hasAI();
200 + // Legacy
201 + $options['ai_engine_status'] = $options['mwai_has_ai'];
193 202
194 - try {
195 - $status = $mwai->checkStatus();
196 -
197 - if ( $options['ai_engine_status'] != true || $options['ai_engine_message'] != $status ) {
198 - $options['ai_engine_status'] = true;
199 - $options['ai_engine_message'] = $status;
200 - return true;
201 - }
202 - } catch ( Exception $e ) {
203 - if ( $options['ai_engine_status'] != false || $options['ai_engine_message'] != $e->getMessage() ) {
204 - $options['ai_engine_status'] = false;
205 - $options['ai_engine_message'] = $e->getMessage();
206 - return true;
207 - }
208 - }
209 -
210 - return false;
203 + return $options;
211 204 }
212 205
213 206 #endregion
214 207
@@ -237,9 +230,24 @@
237 230
238 231 $this->snippet->validate( $params );
239 232
240 233 $params = $this->snippet->formatParamsForDatabase( $params );
241 - $result = $this->snippet->insert( $params );
234 +
235 + // Route to UPDATE when an existing snippet id is provided (updateSnippet / the
236 + // MCP mwcode_update_snippet tool). This previously always insert()ed, so an
237 + // update tried to INSERT a row with an already-used primary key: that fails on
238 + // the SQLite backend (Studio/Playground) with "Could not insert the snippet",
239 + // and duplicates or errors elsewhere. The admin UI was unaffected because it
240 + // calls snippet->update() directly.
241 + $existing = !empty( $params['id'] ) ? $this->snippet->select_one( $params['id'] ) : null;
242 + if ( $existing ) {
243 + $this->snippet->update( $params );
244 + $result = $params['id'];
245 + }
246 + else {
247 + unset( $params['id'] );
248 + $result = $this->snippet->insert( $params );
249 + }
242 250 $snippet = $this->snippet->select_one( $result );
243 251
244 252 if( $result ) {
245 253 $params['id'] = (string)$result;
@@ -279,16 +287,16 @@
279 287 $value = array_map( 'trim', $value );
280 288 }
281 289
282 290 if ( $type === 'array' ) {
283 - $value = json_encode( $value );
284 - $value = str_replace( '\\', '', $value );
291 + // Convert to PHP array format instead of JSON
292 + $value = var_export( $value, true );
285 293 }
286 294
287 295 return [ $name, $value ];
288 296 }
289 297
290 - function run_non_fn_snippet( $id, $code = null, $test = false ) {
298 + function run_non_fn_snippet( $id, $code = null, $test = false, $prefix = '' ) {
291 299 // Retrieve the snippet code from the provided code or via the snippet ID.
292 300 if ( $code ) {
293 301 $snippet = [ 'code' => $code ];
294 302 } else {
@@ -295,13 +303,17 @@
295 303 $snippet = $this->get_snippet( $id );
296 304 }
297 305
298 306 // Remove any PHP opening tag.
299 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
307 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
300 308
301 309 if ( $test ) {
302 310 $snippet['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $snippet['code'] );
303 311 }
312 +
313 + if( $prefix ) {
314 + $snippet['code'] = $prefix . "\n" . $snippet['code'];
315 + }
304 316
305 317 $error = null;
306 318 $output = null;
307 319
@@ -350,35 +362,17 @@
350 362 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
351 363 ];
352 364 }
353 365
354 - // Sanitize all the arguments if the option is enabled
355 - if ( $this->get_option( 'sanitize_arguments', true ) ) {
366 + // Arguments used to be sanitized into PHP-literal strings here (quoting,
367 + // esc_sql, var_export) so they could be concatenated into a string of PHP and
368 + // eval-ed. That is gone: the function is now called with call_user_func_array
369 + // (see below), so values are passed as data and need no literal-formatting.
370 + // The old formatting also prefixed argument keys with "$" via sanitize_arg,
371 + // which stored the provided value under "$name" while the call read "name", so
372 + // provided arguments never reached the function. Passing the raw values through
373 + // fixes both issues at once.
356 374
357 - if ( $args ) {
358 - foreach ( $args as $name => $value ) {
359 - list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value );
360 - unset( $args[$name] );
361 -
362 - $args[$sanitizedName] = $sanitizedValue;
363 - }
364 - }
365 -
366 - foreach ( $params['values'] as $name => $value ) {
367 -
368 - if( array_key_exists( 'input', $value) ) {
369 - list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'], $value['type'] );
370 - $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
371 - }
372 -
373 - if( array_key_exists( 'default', $value) ) {
374 - list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'], $value['type'] );
375 - $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
376 - }
377 - }
378 -
379 - }
380 -
381 375 // Make sure the function is existing and is the one in the snippet
382 376 if ( empty( $params['code'] ) ) {
383 377 throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
384 378 }
@@ -386,17 +380,32 @@
386 380 if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
387 381 throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
388 382 }
389 383
390 - // Overwrite the default values with the provided ones
384 + // Collect the provided values, keyed by their normalized (dollar-less) name.
385 + // Incoming keys come from the AI/MCP schema, where register_function_tools()
386 + // strips a leading "$" from the declared name. The stored arg names can still
387 + // carry the "$", so we normalize both sides before matching below. Without this
388 + // a value provided as "style" never binds to an argument declared "$style".
389 + $provided = [];
391 390 if ( $args ) {
392 391 foreach ( $args as $name => $value ) {
393 - $params['values'][$name]['input'] = $value;
392 + $provided[ ltrim( $name, '$' ) ] = $value;
394 393 }
395 394
396 395 $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
397 396 }
398 397
398 + // Global snippets are meant to be always accessible. On non-whitelisted REST routes
399 + // (Workflow Engine, MCP, AI function-calling) the plugins_loaded pass blocks them, so
400 + // make sure their helper library is loaded before we run a function that may call it.
401 + $this->load_global_snippets();
402 +
403 + // Make every *other* active PHP function snippet available so this function can
404 + // call its siblings. We pass the current name as the exception so the target is
405 + // still defined below (with the edited/test code when testing), not pre-defined here.
406 + $this->define_all_functions( $params['name'] );
407 +
399 408 // Check if the function has already been defined
400 409 if ( !in_array( $params['name'], $defined_functions ) ) {
401 410
402 411 // If not, proceed with modification and definition
@@ -414,30 +423,32 @@
414 423 // If already defined, just prepare to call the function without redefining it
415 424 $params['code'] = '';
416 425 }
417 426
418 - // Prepare the code to be executed
419 - $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
420 - foreach ( $params['args'] as $index => $arg ) {
421 - $value = 'null'; // In case the argument is not provided it will be null
422 -
423 - if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
424 -
425 - // If the argument is provided, use it, if not use the default value
426 - if ( !empty( $params['values'][$arg]['input'] ) ) {
427 - $value = $params['values'][$arg]['input'];
428 -
429 - } else if ( !empty( $params['values'][$arg]['default'] ) ) {
430 - $value = $params['values'][$arg]['default'];
431 - }
427 + // Resolve the arguments as REAL PHP values, in the function's declared order.
428 + // The previous version concatenated each value into a string of PHP and eval-ed
429 + // the call, which broke on any string or edge-case value with a parse error
430 + // ("syntax error, unexpected token ')'"). call_user_func_array passes them as
431 + // data, so no value can ever corrupt the call syntax.
432 + $callArgs = [];
433 + foreach ( $params['args'] as $arg ) {
434 + $key = ltrim( $arg, '$' ); // Match the normalized name the caller sent.
435 + $value = null; // Not provided and no default -> null.
436 + // array_key_exists, not !empty: a legitimately provided 0, "0", "" or false
437 + // must reach the function instead of silently falling back to the default.
438 + if ( array_key_exists( $key, $provided ) ) {
439 + $value = $provided[ $key ];
440 + } else if ( isset( $params['values'][$arg]['default'] ) && $params['values'][$arg]['default'] !== '' ) {
441 + $value = $params['values'][$arg]['default'];
432 442 }
433 -
434 - $params['code'] .= "{$value}";
435 - if ( $index < count( $params['args'] ) - 1 ) {
436 - $params['code'] .= ', ';
443 + // An array-typed argument can arrive as a string like "[1, 2, 3]"; turn it
444 + // into a real array so the function receives what its signature expects.
445 + if ( ( $params['values'][$arg]['type'] ?? null ) === 'array' && is_string( $value ) ) {
446 + $decoded = json_decode( $value, true );
447 + $value = is_array( $decoded ) ? $decoded : array_map( 'trim', explode( ',', trim( $value, "[] \t\n\r" ) ) );
437 448 }
449 + $callArgs[] = $value;
438 450 }
439 - $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
440 451
441 452 $error = null;
442 453 $output = null;
443 454
@@ -442,20 +453,28 @@
442 453 $output = null;
443 454
444 455 try {
445 456 ob_start();
446 - eval( $params['code'] );
457 + // $params['code'] holds the function definition (empty if it was already
458 + // defined earlier this request). Declare it, then invoke it as data.
459 + if ( $params['code'] !== '' ) {
460 + eval( $params['code'] );
461 + }
462 + $mwcode_result = call_user_func_array( $params['name'], $callArgs );
463 + echo print_r( $mwcode_result, true );
447 464 $output = ob_get_clean();
448 -
449 - if ( $params['test'] ){
465 +
466 + if ( $params['test'] ) {
450 467 $output = explode( "\n", $output );
451 468 }
452 -
469 +
453 470 } catch ( Throwable $e ) {
454 471 //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
455 472 $error = new Exception(' Error executing the function, ' . $e->getMessage());
456 473
457 - ob_clean();
474 + if ( ob_get_level() > 0 ) {
475 + ob_end_clean();
476 + }
458 477 } finally {
459 478 restore_error_handler();
460 479 }
461 480
@@ -509,8 +528,132 @@
509 528
510 529 return null;
511 530 }
512 531
532 + /**
533 + * Load the active global snippets (persistent + backend/frontend for this context)
534 + * that haven't already run this request, so on-demand function execution has the same
535 + * always-available helper library a normal page load would. Callable functions are
536 + * typically small wrappers around these globals.
537 + *
538 + * On non-whitelisted REST routes (Workflow Engine, MCP, AI function-calling) the
539 + * plugins_loaded pass blocks global snippets for safety; this restores them for the
540 + * deliberate, authorized act of executing a snippet. The loaded-id registry guarantees
541 + * each global runs at most once per request, so nothing is ever re-declared.
542 + */
543 + function load_global_snippets() {
544 + global $current_mwcode_snippet;
545 + static $done = false;
546 + if ( $done ) {
547 + return;
548 + }
549 + $done = true;
550 +
551 + if ( empty( $this->snippet ) ) {
552 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
553 + }
554 +
555 + $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
556 +
557 + $snippets = $this->snippet->select(
558 + null, // offset
559 + -1, // limit (all)
560 + [
561 + [ 'accessor' => 'active', 'value' => 1 ],
562 + [ 'accessor' => 'scope', 'value' => $scope ],
563 + ],
564 + [ 'accessor' => 'priority', 'by' => 'DESC' ]
565 + )['data'] ?? [];
566 +
567 + foreach ( $snippets as $snippet ) {
568 + // Skip globals already executed this request (e.g. by the plugins_loaded pass).
569 + if ( in_array( $snippet['id'], $this->loaded_global_ids ) ) {
570 + continue;
571 + }
572 + $this->loaded_global_ids[] = $snippet['id'];
573 +
574 + $code = $this->snippet->sanitize_code( $snippet['code'] );
575 + $current_mwcode_snippet = $snippet;
576 + try {
577 + ob_start();
578 + eval( $code );
579 + ob_end_clean();
580 + } catch ( Throwable $e ) {
581 + ob_end_clean();
582 + $this->log( "⚠️ Code Engine: Failed to load global snippet \"{$snippet['name']}\": " . $e->getMessage() );
583 + }
584 + }
585 + $current_mwcode_snippet = null;
586 + }
587 +
588 + /**
589 + * Declare every active PHP function snippet in the current request, without
590 + * invoking any of them, so function snippets can call one another.
591 + *
592 + * Function snippets are not auto-loaded on every request (unlike global/backend/
593 + * frontend scopes) — they are meant to run on demand. This is the PHP counterpart
594 + * to get_js_functions_to_push(): it makes the whole library of functions callable
595 + * before a function is executed (via REST, MCP, AI function-calling, Workflow Engine).
596 + *
597 + * Idempotent: a static guard runs the full pass only once per request, and each
598 + * definition is wrapped in function_exists() so nothing is ever redefined.
599 + *
600 + * @param string|null $except Function name to skip (the one run_snippet is about to
601 + * define itself, so edited/test code keeps priority).
602 + */
603 + function define_all_functions( $except = null ) {
604 + static $loaded = false;
605 + if ( $loaded ) {
606 + return;
607 + }
608 + $loaded = true;
609 +
610 + if ( empty( $this->snippet ) ) {
611 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
612 + }
613 +
614 + // One query for every active function snippet (code included), then enrich with
615 + // the function metadata (name + target) the same way run_snippet does.
616 + $snippets = $this->snippet->select(
617 + null, // offset
618 + -1, // limit (all)
619 + [
620 + [ 'accessor' => 'active', 'value' => 1 ],
621 + [ 'accessor' => 'scope', 'value' => 'function' ],
622 + ],
623 + [] // sort
624 + )['data'] ?? [];
625 +
626 + if ( empty( $snippets ) ) {
627 + return;
628 + }
629 +
630 + $this->snippet->get_function_snippets_data( $snippets );
631 +
632 + foreach ( $snippets as $snippet ) {
633 + $name = $snippet['functionName'] ?? '';
634 + $target = strtolower( $snippet['functionTarget'] ?? 'php' );
635 +
636 + // Skip JS functions (pushed to the front-end separately), the function the
637 + // caller will define itself, and anything already declared in this request.
638 + if ( $name === '' || $target === 'js' || $name === $except || function_exists( $name ) ) {
639 + continue;
640 + }
641 +
642 + // Mirror run_snippet()'s non-test handling: drop echo statements, then declare
643 + // (never call) the function, guarded so a later run_snippet() call is a no-op.
644 + $code = $this->snippet->sanitize_code( $snippet['code'] );
645 + $code = preg_replace( '/echo\s+(.+?);/s', '', $code );
646 + $code = "if (!function_exists('{$name}')) {\n{$code}\n}\n";
647 +
648 + try {
649 + eval( $code );
650 + } catch ( Throwable $e ) {
651 + $this->log( "⚠️ Code Engine: Failed to pre-define function \"{$name}\": " . $e->getMessage() );
652 + }
653 + }
654 + }
655 +
513 656 public function get_js_functions_to_push() {
514 657 $functions = $this->snippet->get_functions();
515 658 $js_functions = [];
516 659 foreach ( $functions as &$function ) {
@@ -581,9 +724,9 @@
581 724 */
582 725 public function execute_active_snippets() {
583 726
584 727 $blocked = false;
585 - $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : null;
728 + $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : '';
586 729
587 730
588 731 if ( $page === 'mwcode_settings' ) {
589 732 // If we blocks global snippets like nonce_life filter, we would block the settings page so let's remove the block for this page
@@ -591,9 +734,9 @@
591 734 $blocked = false;
592 735 //$blocked = true;
593 736 }
594 737 // Block REST requests that aren't whitelisted
595 - elseif ( MeowCommon_Helpers::is_rest() && !Meow_MWCODE_Core::is_white_listed_rest() ) {
738 + elseif ( MeowKit_MWCODE_Helpers::is_rest() && !Meow_MWCODE_Core::is_white_listed_rest() ) {
596 739 $blocked = true;
597 740 }
598 741
599 742 if ( empty( $this->snippet ) ) {
@@ -624,9 +767,9 @@
624 767 return;
625 768 }
626 769
627 770 $snippets = array_map( function ( $snippet ) use ( $blocked ) {
628 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
771 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
629 772 $snippet['blocked'] = $blocked;
630 773
631 774 // If the snippet must be executed only in the frontend, we bypass the block
632 775 if ( !is_admin() && $snippet['scope'] === 'frontend' ) {
@@ -642,16 +785,26 @@
642 785
643 786 #endregion
644 787
645 788 #region Shortcodes
789 + function separate_mwcode_atts( $atts ) {
646 790
791 + if( array_key_exists( 'id', $atts ) ) unset( $atts['id'] );
792 + if( array_key_exists( 'target', $atts ) ) unset( $atts['target'] );
793 + if( array_key_exists( 'code', $atts ) ) unset( $atts['code'] );
794 +
795 + return $atts;
796 + }
797 +
647 798 function content_shortcode( $atts ) {
648 799
800 + $user_atts = $this->separate_mwcode_atts( $atts );
801 +
649 802 $atts = shortcode_atts( array(
650 - 'id' => null,
651 - 'target' => null,
652 - 'code' => null,
653 - ), $atts );
803 + 'id' => null,
804 + 'target' => null, // js or php
805 + 'code' => null, // For Guttenberg block usage
806 + ), $atts, 'code-engine' );
654 807
655 808 $id = $atts['id'];
656 809 $target = $atts['target'];
657 810 $code = $atts['code'];
@@ -734,9 +887,10 @@
734 887 $output = '<script>' . $snippet['code'] . '</script>';
735 888 }
736 889
737 890 if ( $is_content_php ) {
738 - $output = $this->run_non_fn_snippet( $id );
891 + $prefix = "\$mwcode_atts = unserialize( '" . serialize( $user_atts ) . "' );";
892 + $output = $this->run_non_fn_snippet( $id, null, false, $prefix );
739 893 }
740 894
741 895 return $output;
742 896 }