PluginProbe
Code Engine – PHP Snippets, AI Functions & Automation for WordPress / trunk
Code Engine – PHP Snippets, AI Functions & Automation for WordPress vtrunk
0.5.6 0.5.5 0.5.4 0.5.3 0.5.2 0.5.1 0.5.0 0.4.9 0.4.8 0.4.7 0.4.6 trunk 0.0.1 0.0.2 0.2.8 0.2.9 0.3.0 0.3.1 0.3.2 0.3.3 0.3.4 0.3.5 0.3.6 0.3.7 0.3.8 All 32 releases
← All changes | classes/core.php +278 -104 0.3.3trunk View file →
@@ -12,9 +12,14 @@
12 12 public $is_rest = false;
13 13 public $is_cli = false;
14 14 public $site_url = null;
15 15 public $mwcode = null;
16 + public $licenser = null;
16 17
18 + // IDs of global snippets already executed this request (by the plugins_loaded pass
19 + // or by load_global_snippets), so a global never runs twice and never re-declares.
20 + public $loaded_global_ids = [];
21 +
17 22 private $option_name = 'mwcode_options';
18 23
19 24 public function __construct() {
20 25 global $mwcode;
@@ -19,9 +24,9 @@
19 24 public function __construct() {
20 25 global $mwcode;
21 26
22 27 $this->site_url = get_site_url();
23 - $this->is_rest = MeowCommon_Helpers::is_rest();
28 + $this->is_rest = MeowKit_MWCODE_Helpers::is_rest();
24 29 $this->is_cli = defined( 'WP_CLI' ) && WP_CLI;
25 30
26 31 // Snippets
27 32 $snippet = new Meow_MWCODE_Modules_Snippet( $this );
@@ -37,8 +42,13 @@
37 42 add_action( 'plugins_loaded', array( $this, 'init' ) );
38 43 }
39 44
40 45 function init() {
46 + // Initialize the licenser for Pro version
47 + if ( class_exists( 'MeowKitPro_MWCODE_Licenser' ) ) {
48 + $this->licenser = new MeowKitPro_MWCODE_Licenser( MWCODE_PREFIX, MWCODE_ENTRY, MWCODE_DOMAIN, MWCODE_ITEM_ID, MWCODE_VERSION );
49 + }
50 +
41 51 // Part of the core, settings and stuff
42 52 $this->admin = new Meow_MWCODE_Admin( $this );
43 53
44 54 // Only for REST
@@ -83,8 +93,11 @@
83 93 return [
84 94 //Safemode
85 95 "safe_mode_status" => "on", // on, off, whitelist
86 96 "safe_mode_whitelist" => [],
97 + //"disallow_block_php" => true, // Do not allow PHP code to be execute through Blocks "code" parameter
98 + "code_blocks" => false,
99 + "code_blocks_whitelist" => [], // Whitelist for code blocks, if empty, all code blocks are allowed
87 100
88 101 //LOGS
89 102 "server_debug_mode" => false,
90 103
@@ -93,8 +106,9 @@
93 106
94 107 //AI
95 108 "ai_suggestions" => false,
96 109 "ai_engine_status"=> false,
110 + "mwai_active" => false,
97 111 "ai_engine_message" => "",
98 112
99 113 //API
100 114 "api_endpoint" => false,
@@ -101,8 +115,12 @@
101 115 "api_token" => md5( time() . rand() ),
102 116
103 117 //MCP
104 118 "mcp_support" => false,
119 + "mcp_functions" => false,
120 +
121 + //MAINTENANCE
122 + "clean_uninstall" => false,
105 123 ];
106 124 }
107 125
108 126 function get_all_options( ) {
@@ -116,19 +134,15 @@
116 134 return $options;
117 135 }
118 136
119 137 function update_options( $options ) {
120 - $current_options = get_option($this->option_name);
121 138
122 - if ($current_options === $options) {
123 - // $this->log('💾 The options are already the expected value.');
124 - } else {
125 - if ( !update_option( $this->option_name, $options, false ) ) {
126 - $this->log( '💾 There was an issue updating the options.' );
127 - }
139 + $options = $this->sanitize_options( $options );
140 +
141 + if ( !update_option( $this->option_name, $options, false ) ) {
142 + //$this->log( '💾 There was an issue updating the options.' );
128 143 }
129 -
130 - $options = $this->sanitize_options( $options );
144 +
131 145 return $options;
132 146 }
133 147
134 148 function update_option( $option, $value ) {
@@ -159,9 +173,9 @@
159 173 $options_modified = true;
160 174 }
161 175
162 176 // Update AI Engine status
163 - $options_modified = $this->updateAIEngineStatus( $options ) || $options_modified;
177 + $options = $this->updateAIEngineStatus( $options );
164 178
165 179 // Disable AI related features if AI Engine is not available
166 180 if ( ! $options['ai_engine_status'] ) {
167 181 if ( $options['ai_suggestions'] !== false ) {
@@ -171,12 +185,8 @@
171 185 // Note: We don't disable MCP support here anymore
172 186 // It will be checked at runtime in the MCP class
173 187 }
174 188
175 - if ( $options_modified ) {
176 - update_option( $this->option_name, $options, false );
177 - }
178 -
179 189 return $options;
180 190 }
181 191
182 192 private function updateAIEngineStatus( &$options ) {
@@ -181,31 +191,17 @@
181 191
182 192 private function updateAIEngineStatus( &$options ) {
183 193 global $mwai;
184 194
185 - if ( is_null( $mwai ) || ! isset( $mwai ) ) {
186 - $options['ai_engine_status'] = false;
187 - $options['ai_engine_message'] = 'AI Engine is not available.';
188 - return true;
189 - }
195 + // AI Engine is active (regardless of whether an API key is configured).
196 + // MCP exposure only needs AI Engine present, not a key, so the MCP toggles
197 + // gate on this rather than on mwai_has_ai.
198 + $options['mwai_active'] = !empty( $mwai );
199 + $options['mwai_has_ai'] = !empty( $mwai ) && method_exists( $mwai, 'hasAI' ) && $mwai->hasAI();
200 + // Legacy
201 + $options['ai_engine_status'] = $options['mwai_has_ai'];
190 202
191 - try {
192 - $status = $mwai->checkStatus();
193 -
194 - if ( $options['ai_engine_status'] != true || $options['ai_engine_message'] != $status ) {
195 - $options['ai_engine_status'] = true;
196 - $options['ai_engine_message'] = $status;
197 - return true;
198 - }
199 - } catch ( Exception $e ) {
200 - if ( $options['ai_engine_status'] != false || $options['ai_engine_message'] != $e->getMessage() ) {
201 - $options['ai_engine_status'] = false;
202 - $options['ai_engine_message'] = $e->getMessage();
203 - return true;
204 - }
205 - }
206 -
207 - return false;
203 + return $options;
208 204 }
209 205
210 206 #endregion
211 207
@@ -234,9 +230,24 @@
234 230
235 231 $this->snippet->validate( $params );
236 232
237 233 $params = $this->snippet->formatParamsForDatabase( $params );
238 - $result = $this->snippet->insert( $params );
234 +
235 + // Route to UPDATE when an existing snippet id is provided (updateSnippet / the
236 + // MCP mwcode_update_snippet tool). This previously always insert()ed, so an
237 + // update tried to INSERT a row with an already-used primary key: that fails on
238 + // the SQLite backend (Studio/Playground) with "Could not insert the snippet",
239 + // and duplicates or errors elsewhere. The admin UI was unaffected because it
240 + // calls snippet->update() directly.
241 + $existing = !empty( $params['id'] ) ? $this->snippet->select_one( $params['id'] ) : null;
242 + if ( $existing ) {
243 + $this->snippet->update( $params );
244 + $result = $params['id'];
245 + }
246 + else {
247 + unset( $params['id'] );
248 + $result = $this->snippet->insert( $params );
249 + }
239 250 $snippet = $this->snippet->select_one( $result );
240 251
241 252 if( $result ) {
242 253 $params['id'] = (string)$result;
@@ -276,16 +287,16 @@
276 287 $value = array_map( 'trim', $value );
277 288 }
278 289
279 290 if ( $type === 'array' ) {
280 - $value = json_encode( $value );
281 - $value = str_replace( '\\', '', $value );
291 + // Convert to PHP array format instead of JSON
292 + $value = var_export( $value, true );
282 293 }
283 294
284 295 return [ $name, $value ];
285 296 }
286 297
287 - function run_non_fn_snippet( $id, $code = null, $test = false ) {
298 + function run_non_fn_snippet( $id, $code = null, $test = false, $prefix = '' ) {
288 299 // Retrieve the snippet code from the provided code or via the snippet ID.
289 300 if ( $code ) {
290 301 $snippet = [ 'code' => $code ];
291 302 } else {
@@ -292,13 +303,17 @@
292 303 $snippet = $this->get_snippet( $id );
293 304 }
294 305
295 306 // Remove any PHP opening tag.
296 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
307 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
297 308
298 309 if ( $test ) {
299 310 $snippet['code'] = preg_replace( '/echo\s+(.+?);/s', 'echo $1 . "\n";', $snippet['code'] );
300 311 }
312 +
313 + if( $prefix ) {
314 + $snippet['code'] = $prefix . "\n" . $snippet['code'];
315 + }
301 316
302 317 $error = null;
303 318 $output = null;
304 319
@@ -347,35 +362,17 @@
347 362 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
348 363 ];
349 364 }
350 365
351 - // Sanitize all the arguments if the option is enabled
352 - if ( $this->get_option( 'sanitize_arguments', true ) ) {
366 + // Arguments used to be sanitized into PHP-literal strings here (quoting,
367 + // esc_sql, var_export) so they could be concatenated into a string of PHP and
368 + // eval-ed. That is gone: the function is now called with call_user_func_array
369 + // (see below), so values are passed as data and need no literal-formatting.
370 + // The old formatting also prefixed argument keys with "$" via sanitize_arg,
371 + // which stored the provided value under "$name" while the call read "name", so
372 + // provided arguments never reached the function. Passing the raw values through
373 + // fixes both issues at once.
353 374
354 - if ( $args ) {
355 - foreach ( $args as $name => $value ) {
356 - list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value );
357 - unset( $args[$name] );
358 -
359 - $args[$sanitizedName] = $sanitizedValue;
360 - }
361 - }
362 -
363 - foreach ( $params['values'] as $name => $value ) {
364 -
365 - if( array_key_exists( 'input', $value) ) {
366 - list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'], $value['type'] );
367 - $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
368 - }
369 -
370 - if( array_key_exists( 'default', $value) ) {
371 - list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'], $value['type'] );
372 - $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
373 - }
374 - }
375 -
376 - }
377 -
378 375 // Make sure the function is existing and is the one in the snippet
379 376 if ( empty( $params['code'] ) ) {
380 377 throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
381 378 }
@@ -383,17 +380,32 @@
383 380 if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
384 381 throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
385 382 }
386 383
387 - // Overwrite the default values with the provided ones
384 + // Collect the provided values, keyed by their normalized (dollar-less) name.
385 + // Incoming keys come from the AI/MCP schema, where register_function_tools()
386 + // strips a leading "$" from the declared name. The stored arg names can still
387 + // carry the "$", so we normalize both sides before matching below. Without this
388 + // a value provided as "style" never binds to an argument declared "$style".
389 + $provided = [];
388 390 if ( $args ) {
389 391 foreach ( $args as $name => $value ) {
390 - $params['values'][$name]['input'] = $value;
392 + $provided[ ltrim( $name, '$' ) ] = $value;
391 393 }
392 394
393 395 $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
394 396 }
395 397
398 + // Global snippets are meant to be always accessible. On non-whitelisted REST routes
399 + // (Workflow Engine, MCP, AI function-calling) the plugins_loaded pass blocks them, so
400 + // make sure their helper library is loaded before we run a function that may call it.
401 + $this->load_global_snippets();
402 +
403 + // Make every *other* active PHP function snippet available so this function can
404 + // call its siblings. We pass the current name as the exception so the target is
405 + // still defined below (with the edited/test code when testing), not pre-defined here.
406 + $this->define_all_functions( $params['name'] );
407 +
396 408 // Check if the function has already been defined
397 409 if ( !in_array( $params['name'], $defined_functions ) ) {
398 410
399 411 // If not, proceed with modification and definition
@@ -411,30 +423,32 @@
411 423 // If already defined, just prepare to call the function without redefining it
412 424 $params['code'] = '';
413 425 }
414 426
415 - // Prepare the code to be executed
416 - $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
417 - foreach ( $params['args'] as $index => $arg ) {
418 - $value = 'null'; // In case the argument is not provided it will be null
419 -
420 - if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
421 -
422 - // If the argument is provided, use it, if not use the default value
423 - if ( !empty( $params['values'][$arg]['input'] ) ) {
424 - $value = $params['values'][$arg]['input'];
425 -
426 - } else if ( !empty( $params['values'][$arg]['default'] ) ) {
427 - $value = $params['values'][$arg]['default'];
428 - }
427 + // Resolve the arguments as REAL PHP values, in the function's declared order.
428 + // The previous version concatenated each value into a string of PHP and eval-ed
429 + // the call, which broke on any string or edge-case value with a parse error
430 + // ("syntax error, unexpected token ')'"). call_user_func_array passes them as
431 + // data, so no value can ever corrupt the call syntax.
432 + $callArgs = [];
433 + foreach ( $params['args'] as $arg ) {
434 + $key = ltrim( $arg, '$' ); // Match the normalized name the caller sent.
435 + $value = null; // Not provided and no default -> null.
436 + // array_key_exists, not !empty: a legitimately provided 0, "0", "" or false
437 + // must reach the function instead of silently falling back to the default.
438 + if ( array_key_exists( $key, $provided ) ) {
439 + $value = $provided[ $key ];
440 + } else if ( isset( $params['values'][$arg]['default'] ) && $params['values'][$arg]['default'] !== '' ) {
441 + $value = $params['values'][$arg]['default'];
429 442 }
430 -
431 - $params['code'] .= "{$value}";
432 - if ( $index < count( $params['args'] ) - 1 ) {
433 - $params['code'] .= ', ';
443 + // An array-typed argument can arrive as a string like "[1, 2, 3]"; turn it
444 + // into a real array so the function receives what its signature expects.
445 + if ( ( $params['values'][$arg]['type'] ?? null ) === 'array' && is_string( $value ) ) {
446 + $decoded = json_decode( $value, true );
447 + $value = is_array( $decoded ) ? $decoded : array_map( 'trim', explode( ',', trim( $value, "[] \t\n\r" ) ) );
434 448 }
449 + $callArgs[] = $value;
435 450 }
436 - $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
437 451
438 452 $error = null;
439 453 $output = null;
440 454
@@ -439,20 +453,28 @@
439 453 $output = null;
440 454
441 455 try {
442 456 ob_start();
443 - eval( $params['code'] );
457 + // $params['code'] holds the function definition (empty if it was already
458 + // defined earlier this request). Declare it, then invoke it as data.
459 + if ( $params['code'] !== '' ) {
460 + eval( $params['code'] );
461 + }
462 + $mwcode_result = call_user_func_array( $params['name'], $callArgs );
463 + echo print_r( $mwcode_result, true );
444 464 $output = ob_get_clean();
445 -
446 - if ( $params['test'] ){
465 +
466 + if ( $params['test'] ) {
447 467 $output = explode( "\n", $output );
448 468 }
449 -
469 +
450 470 } catch ( Throwable $e ) {
451 471 //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
452 472 $error = new Exception(' Error executing the function, ' . $e->getMessage());
453 473
454 - ob_clean();
474 + if ( ob_get_level() > 0 ) {
475 + ob_end_clean();
476 + }
455 477 } finally {
456 478 restore_error_handler();
457 479 }
458 480
@@ -506,8 +528,132 @@
506 528
507 529 return null;
508 530 }
509 531
532 + /**
533 + * Load the active global snippets (persistent + backend/frontend for this context)
534 + * that haven't already run this request, so on-demand function execution has the same
535 + * always-available helper library a normal page load would. Callable functions are
536 + * typically small wrappers around these globals.
537 + *
538 + * On non-whitelisted REST routes (Workflow Engine, MCP, AI function-calling) the
539 + * plugins_loaded pass blocks global snippets for safety; this restores them for the
540 + * deliberate, authorized act of executing a snippet. The loaded-id registry guarantees
541 + * each global runs at most once per request, so nothing is ever re-declared.
542 + */
543 + function load_global_snippets() {
544 + global $current_mwcode_snippet;
545 + static $done = false;
546 + if ( $done ) {
547 + return;
548 + }
549 + $done = true;
550 +
551 + if ( empty( $this->snippet ) ) {
552 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
553 + }
554 +
555 + $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
556 +
557 + $snippets = $this->snippet->select(
558 + null, // offset
559 + -1, // limit (all)
560 + [
561 + [ 'accessor' => 'active', 'value' => 1 ],
562 + [ 'accessor' => 'scope', 'value' => $scope ],
563 + ],
564 + [ 'accessor' => 'priority', 'by' => 'DESC' ]
565 + )['data'] ?? [];
566 +
567 + foreach ( $snippets as $snippet ) {
568 + // Skip globals already executed this request (e.g. by the plugins_loaded pass).
569 + if ( in_array( $snippet['id'], $this->loaded_global_ids ) ) {
570 + continue;
571 + }
572 + $this->loaded_global_ids[] = $snippet['id'];
573 +
574 + $code = $this->snippet->sanitize_code( $snippet['code'] );
575 + $current_mwcode_snippet = $snippet;
576 + try {
577 + ob_start();
578 + eval( $code );
579 + ob_end_clean();
580 + } catch ( Throwable $e ) {
581 + ob_end_clean();
582 + $this->log( "⚠️ Code Engine: Failed to load global snippet \"{$snippet['name']}\": " . $e->getMessage() );
583 + }
584 + }
585 + $current_mwcode_snippet = null;
586 + }
587 +
588 + /**
589 + * Declare every active PHP function snippet in the current request, without
590 + * invoking any of them, so function snippets can call one another.
591 + *
592 + * Function snippets are not auto-loaded on every request (unlike global/backend/
593 + * frontend scopes) — they are meant to run on demand. This is the PHP counterpart
594 + * to get_js_functions_to_push(): it makes the whole library of functions callable
595 + * before a function is executed (via REST, MCP, AI function-calling, Workflow Engine).
596 + *
597 + * Idempotent: a static guard runs the full pass only once per request, and each
598 + * definition is wrapped in function_exists() so nothing is ever redefined.
599 + *
600 + * @param string|null $except Function name to skip (the one run_snippet is about to
601 + * define itself, so edited/test code keeps priority).
602 + */
603 + function define_all_functions( $except = null ) {
604 + static $loaded = false;
605 + if ( $loaded ) {
606 + return;
607 + }
608 + $loaded = true;
609 +
610 + if ( empty( $this->snippet ) ) {
611 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
612 + }
613 +
614 + // One query for every active function snippet (code included), then enrich with
615 + // the function metadata (name + target) the same way run_snippet does.
616 + $snippets = $this->snippet->select(
617 + null, // offset
618 + -1, // limit (all)
619 + [
620 + [ 'accessor' => 'active', 'value' => 1 ],
621 + [ 'accessor' => 'scope', 'value' => 'function' ],
622 + ],
623 + [] // sort
624 + )['data'] ?? [];
625 +
626 + if ( empty( $snippets ) ) {
627 + return;
628 + }
629 +
630 + $this->snippet->get_function_snippets_data( $snippets );
631 +
632 + foreach ( $snippets as $snippet ) {
633 + $name = $snippet['functionName'] ?? '';
634 + $target = strtolower( $snippet['functionTarget'] ?? 'php' );
635 +
636 + // Skip JS functions (pushed to the front-end separately), the function the
637 + // caller will define itself, and anything already declared in this request.
638 + if ( $name === '' || $target === 'js' || $name === $except || function_exists( $name ) ) {
639 + continue;
640 + }
641 +
642 + // Mirror run_snippet()'s non-test handling: drop echo statements, then declare
643 + // (never call) the function, guarded so a later run_snippet() call is a no-op.
644 + $code = $this->snippet->sanitize_code( $snippet['code'] );
645 + $code = preg_replace( '/echo\s+(.+?);/s', '', $code );
646 + $code = "if (!function_exists('{$name}')) {\n{$code}\n}\n";
647 +
648 + try {
649 + eval( $code );
650 + } catch ( Throwable $e ) {
651 + $this->log( "⚠️ Code Engine: Failed to pre-define function \"{$name}\": " . $e->getMessage() );
652 + }
653 + }
654 + }
655 +
510 656 public function get_js_functions_to_push() {
511 657 $functions = $this->snippet->get_functions();
512 658 $js_functions = [];
513 659 foreach ( $functions as &$function ) {
@@ -580,14 +726,17 @@
580 726
581 727 $blocked = false;
582 728 $page = isset( $_GET["page"] ) ? sanitize_text_field( $_GET["page"] ) : null;
583 729
584 - // Block on settings page for safety
730 +
585 731 if ( $page === 'mwcode_settings' ) {
586 - $blocked = true;
732 + // If we blocks global snippets like nonce_life filter, we would block the settings page so let's remove the block for this page
733 +
734 + $blocked = false;
735 + //$blocked = true;
587 736 }
588 737 // Block REST requests that aren't whitelisted
589 - elseif ( MeowCommon_Helpers::is_rest() && !Meow_MWCODE_Core::is_white_listed_rest() ) {
738 + elseif ( MeowKit_MWCODE_Helpers::is_rest() && !Meow_MWCODE_Core::is_white_listed_rest() ) {
590 739 $blocked = true;
591 740 }
592 741
593 742 if ( empty( $this->snippet ) ) {
@@ -618,9 +767,9 @@
618 767 return;
619 768 }
620 769
621 770 $snippets = array_map( function ( $snippet ) use ( $blocked ) {
622 - $snippet['code'] = preg_replace( '/<\?php/', '', $snippet['code'], 1 );
771 + $snippet['code'] = $this->snippet->sanitize_code( $snippet['code'] );
623 772 $snippet['blocked'] = $blocked;
624 773
625 774 // If the snippet must be executed only in the frontend, we bypass the block
626 775 if ( !is_admin() && $snippet['scope'] === 'frontend' ) {
@@ -636,22 +785,35 @@
636 785
637 786 #endregion
638 787
639 788 #region Shortcodes
789 + function separate_mwcode_atts( $atts ) {
640 790
791 + if( array_key_exists( 'id', $atts ) ) unset( $atts['id'] );
792 + if( array_key_exists( 'target', $atts ) ) unset( $atts['target'] );
793 + if( array_key_exists( 'code', $atts ) ) unset( $atts['code'] );
794 +
795 + return $atts;
796 + }
797 +
641 798 function content_shortcode( $atts ) {
642 799
800 + $user_atts = $this->separate_mwcode_atts( $atts );
801 +
643 802 $atts = shortcode_atts( array(
644 - 'id' => null,
645 - 'target' => null,
646 - 'code' => null,
647 - ), $atts );
803 + 'id' => null,
804 + 'target' => null, // js or php
805 + 'code' => null, // For Guttenberg block usage
806 + ), $atts, 'code-engine' );
648 807
649 808 $id = $atts['id'];
650 809 $target = $atts['target'];
651 810 $code = $atts['code'];
811 + $current_post = get_post();
652 812
653 - $no_js = defined( 'DISALLOW_UNFILTERED_HTML' ) && DISALLOW_UNFILTERED_HTML;
813 + $no_js = defined( 'DISALLOW_UNFILTERED_HTML' ) && DISALLOW_UNFILTERED_HTML;
814 + $allow_php = $this->get_option( 'code_blocks', false );
815 + $allow_php_whitelist = $this->get_option( 'code_blocks_whitelist', [] );
654 816
655 817 // If the ID is null, it means it comes from a Guttenberg block
656 818 $is_block = empty( $id ) && !empty( $code );
657 819
@@ -664,8 +826,19 @@
664 826 if ( $no_js && $target === 'js' ) {
665 827 return '<b>Code Engine:</b> Code Block JS are disabled because unfiltered HTML is not allowed on your server.';
666 828 }
667 829
830 + if ( $target === 'php' ) {
831 +
832 + if ( !$allow_php ) {
833 + return '<b>Code Engine:</b> Code Block PHP are disabled. If you are an administrator, you can enable it in the settings, this is not recommended. Please use a Content Snippet ( PHP ) instead.';
834 + }
835 +
836 + if ( !empty( $allow_php_whitelist ) && !in_array( $current_post->ID, $allow_php_whitelist ) ) {
837 + return '<b>Code Engine:</b> Code Block PHP are disabled for this post. If you are an administrator, you can enable it in the settings, this is not recommended. Please use a Content Snippet ( PHP ) instead.';
838 + }
839 + }
840 +
668 841 // Because the code from Blocks are sanitized, we need to replace the &quot; with "
669 842 $code = str_replace( '&quot;', '"', $code );
670 843
671 844 if ( $target === 'js' ) {
@@ -714,9 +887,10 @@
714 887 $output = '<script>' . $snippet['code'] . '</script>';
715 888 }
716 889
717 890 if ( $is_content_php ) {
718 - $output = $this->run_non_fn_snippet( $id );
891 + $prefix = "\$mwcode_atts = unserialize( '" . serialize( $user_atts ) . "' );";
892 + $output = $this->run_non_fn_snippet( $id, null, false, $prefix );
719 893 }
720 894
721 895 return $output;
722 896 }