| @@ -6,15 +6,14 @@ | ||
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | 8 | namespace Code_Snippets; |
| 9 | 9 | |
| 10 | -use Code_Snippets\Core\DB; | |
| 11 | -use Code_Snippets\Flat_Files\Snippet_Files; | |
| 12 | 10 | use Exception; |
| 13 | 11 | use Code_Snippets\Model\Snippet; |
| 14 | 12 | use Code_Snippets\Utils\Validator; |
| 15 | 13 | use Throwable; |
| 16 | 14 | use function Code_Snippets\Utils\get_self_option; |
| 15 | +use function Code_Snippets\Utils\validate_network_param; | |
| 17 | 16 | use function Code_Snippets\Utils\update_self_option; |
| 18 | 17 | |
| 19 | 18 | /** |
| 20 | 19 | * Get the locked status for a snippet from wp_options. |
| @@ -24,9 +23,9 @@ | ||
| 24 | 23 | * |
| 25 | 24 | * @return bool Whether the snippet is locked. |
| 26 | 25 | */ |
| 27 | 26 | function is_snippet_locked( int $snippet_id, ?bool $network = null ): bool { |
| 28 | - $network = DB::validate_network_param( $network ); | |
| 27 | + $network = validate_network_param( $network ); | |
| 29 | 28 | $locked_snippets = get_self_option( $network, 'code_snippets_locked', [] ); |
| 30 | 29 | |
| 31 | 30 | return isset( $locked_snippets[ $snippet_id ] ) && $locked_snippets[ $snippet_id ]; |
| 32 | 31 | } |
| @@ -40,9 +39,9 @@ | ||
| 40 | 39 | * |
| 41 | 40 | * @return void |
| 42 | 41 | */ |
| 43 | 42 | function set_snippet_locked( int $snippet_id, bool $locked, ?bool $network = null ): void { |
| 44 | - $network = DB::validate_network_param( $network ); | |
| 43 | + $network = validate_network_param( $network ); | |
| 45 | 44 | $locked_snippets = get_self_option( $network, 'code_snippets_locked', [] ); |
| 46 | 45 | |
| 47 | 46 | if ( $locked ) { |
| 48 | 47 | $locked_snippets[ $snippet_id ] = true; |
| @@ -64,9 +63,12 @@ | ||
| 64 | 63 | function clean_active_snippets_cache( string $table_name, $scopes = false ) { |
| 65 | 64 | $scope_groups = $scopes |
| 66 | 65 | ? [ $scopes ] |
| 67 | 66 | : [ |
| 67 | + // Content snippets. | |
| 68 | 68 | [ 'head-content', 'body-content', 'footer-content' ], |
| 69 | + | |
| 70 | + // Function snippets. | |
| 69 | 71 | [ 'global', 'single-use', 'front-end' ], |
| 70 | 72 | [ 'global', 'single-use', 'admin' ], |
| 71 | 73 | ]; |
| 72 | 74 | |
| @@ -101,8 +103,24 @@ | ||
| 101 | 103 | * |
| 102 | 104 | * @return bool Whether the group was flushed. |
| 103 | 105 | */ |
| 104 | 106 | function flush_cache_group( string $group ): bool { |
| 107 | + /** | |
| 108 | + * Short-circuits flushing a cache group. | |
| 109 | + * | |
| 110 | + * Returning a boolean skips the object cache entirely: false makes the | |
| 111 | + * caller fall back to deleting the known keys one by one, for a cache | |
| 112 | + * that reports group support it does not really have. | |
| 113 | + * | |
| 114 | + * @param bool|null $flushed Whether the group was flushed, or null to let the cache try. | |
| 115 | + * @param string $group Cache group. | |
| 116 | + */ | |
| 117 | + $flushed = apply_filters( 'code_snippets/pre_flush_cache_group', null, $group ); | |
| 118 | + | |
| 119 | + if ( null !== $flushed ) { | |
| 120 | + return (bool) $flushed; | |
| 121 | + } | |
| 122 | + | |
| 105 | 123 | if ( ! function_exists( 'wp_cache_flush_group' ) || |
| 106 | 124 | ! function_exists( 'wp_cache_supports' ) || |
| 107 | 125 | ! wp_cache_supports( 'flush_group' ) ) { |
| 108 | 126 | return false; |
| @@ -107,9 +125,9 @@ | ||
| 107 | 125 | ! wp_cache_supports( 'flush_group' ) ) { |
| 108 | 126 | return false; |
| 109 | 127 | } |
| 110 | 128 | |
| 111 | - return (bool) wp_cache_flush_group( $group ); | |
| 129 | + return wp_cache_flush_group( $group ); | |
| 112 | 130 | } |
| 113 | 131 | |
| 114 | 132 | /** |
| 115 | 133 | * Flush the cache groups belonging to other versions of the plugin. |
| @@ -128,12 +146,34 @@ | ||
| 128 | 146 | // upgrading from 3.10.0 or 3.10.1 sheds the objects that would otherwise |
| 129 | 147 | // still be waiting to break its next rollback. |
| 130 | 148 | flush_cache_group( CACHE_GROUP_BASE ); |
| 131 | 149 | |
| 132 | - flush_cache_group( CACHE_GROUP ); | |
| 150 | + // Where the cache cannot flush a whole group, the keys this plugin writes | |
| 151 | + // are deleted one by one instead, so an uninstall followed by a reinstall | |
| 152 | + // of the same version cannot read snippets that no longer exist. | |
| 153 | + if ( ! flush_cache_group( CACHE_GROUP ) ) { | |
| 154 | + flush_known_cache_keys(); | |
| 155 | + } | |
| 133 | 156 | } |
| 134 | 157 | |
| 135 | 158 | /** |
| 159 | + * Delete every key this plugin is known to write in its current cache group. | |
| 160 | + * | |
| 161 | + * @return void | |
| 162 | + */ | |
| 163 | +function flush_known_cache_keys(): void { | |
| 164 | + // Both tables' keys go, whether this is a network: deleting a key | |
| 165 | + // that was never written does not cost anything, and it keeps one path to test. | |
| 166 | + $tables = [ code_snippets()->db->get_table_name( false ), code_snippets()->db->get_table_name( true ) ]; | |
| 167 | + | |
| 168 | + foreach ( array_unique( $tables ) as $table ) { | |
| 169 | + clean_snippets_cache( $table ); | |
| 170 | + } | |
| 171 | + | |
| 172 | + wp_cache_delete( Settings\CACHE_KEY, CACHE_GROUP ); | |
| 173 | +} | |
| 174 | + | |
| 175 | +/** | |
| 136 | 176 | * Retrieve a list of snippets from the database. |
| 137 | 177 | * Read operation. |
| 138 | 178 | * |
| 139 | 179 | * @param array<string> $ids The IDs of the snippets to fetch. |
| @@ -151,9 +191,9 @@ | ||
| 151 | 191 | if ( 1 === $ids_count ) { |
| 152 | 192 | return [ get_snippet( $ids[0], $network ) ]; |
| 153 | 193 | } |
| 154 | 194 | |
| 155 | - $network = DB::validate_network_param( $network ); | |
| 195 | + $network = validate_network_param( $network ); | |
| 156 | 196 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 157 | 197 | |
| 158 | 198 | $snippets = wp_cache_get( "all_snippets_$table_name", CACHE_GROUP ); |
| 159 | 199 | |
| @@ -273,9 +313,9 @@ | ||
| 273 | 313 | function get_snippet( int $id = 0, ?bool $network = null ): ?Snippet { |
| 274 | 314 | global $wpdb; |
| 275 | 315 | |
| 276 | 316 | $id = absint( $id ); |
| 277 | - $network = DB::validate_network_param( $network ); | |
| 317 | + $network = validate_network_param( $network ); | |
| 278 | 318 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 279 | 319 | |
| 280 | 320 | if ( 0 === $id ) { |
| 281 | 321 | // If an invalid ID is provided, then return an empty snippet object. |
| @@ -384,9 +424,9 @@ | ||
| 384 | 424 | * @since 2.0.0 |
| 385 | 425 | */ |
| 386 | 426 | function activate_snippet( int $id, ?bool $network = null ) { |
| 387 | 427 | global $wpdb; |
| 388 | - $network = DB::validate_network_param( $network ); | |
| 428 | + $network = validate_network_param( $network ); | |
| 389 | 429 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 390 | 430 | |
| 391 | 431 | // Retrieve the snippet code from the database for validation before activating. |
| 392 | 432 | $snippet = get_snippet( $id, $network ); |
| @@ -433,9 +473,9 @@ | ||
| 433 | 473 | * @since 2.0.0 |
| 434 | 474 | */ |
| 435 | 475 | function activate_snippets( array $ids, ?bool $network = null ): ?array { |
| 436 | 476 | global $wpdb; |
| 437 | - $network = DB::validate_network_param( $network ); | |
| 477 | + $network = validate_network_param( $network ); | |
| 438 | 478 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 439 | 479 | |
| 440 | 480 | $snippets = get_snippets( $ids, $network ); |
| 441 | 481 | |
| @@ -505,9 +545,9 @@ | ||
| 505 | 545 | * @since 2.0.0 |
| 506 | 546 | */ |
| 507 | 547 | function deactivate_snippet( int $id, ?bool $network = null ): ?Snippet { |
| 508 | 548 | global $wpdb; |
| 509 | - $network = DB::validate_network_param( $network ); | |
| 549 | + $network = validate_network_param( $network ); | |
| 510 | 550 | $table = code_snippets()->db->get_table_name( $network ); |
| 511 | 551 | |
| 512 | 552 | // Set the snippet to inactive. |
| 513 | 553 | $result = $wpdb->update( |
| @@ -547,9 +587,9 @@ | ||
| 547 | 587 | * @since 2.0.0 |
| 548 | 588 | */ |
| 549 | 589 | function delete_snippet( int $id, ?bool $network = null ): bool { |
| 550 | 590 | global $wpdb; |
| 551 | - $network = DB::validate_network_param( $network ); | |
| 591 | + $network = validate_network_param( $network ); | |
| 552 | 592 | $table = code_snippets()->db->get_table_name( $network ); |
| 553 | 593 | |
| 554 | 594 | $snippet = get_snippet( $id, $network ); |
| 555 | 595 | |
| @@ -591,9 +631,9 @@ | ||
| 591 | 631 | * @since 3.8.0 |
| 592 | 632 | */ |
| 593 | 633 | function trash_snippet( int $id, ?bool $network = null ): bool { |
| 594 | 634 | global $wpdb; |
| 595 | - $network = DB::validate_network_param( $network ); | |
| 635 | + $network = validate_network_param( $network ); | |
| 596 | 636 | $table = code_snippets()->db->get_table_name( $network ); |
| 597 | 637 | |
| 598 | 638 | $snippet = get_snippet( $id, $network ); |
| 599 | 639 | |
| @@ -622,9 +662,9 @@ | ||
| 622 | 662 | * @since 3.8.0 |
| 623 | 663 | */ |
| 624 | 664 | function restore_snippet( int $id, ?bool $network = null ): bool { |
| 625 | 665 | global $wpdb; |
| 626 | - $network = DB::validate_network_param( $network ); | |
| 666 | + $network = validate_network_param( $network ); | |
| 627 | 667 | $table = code_snippets()->db->get_table_name( $network ); |
| 628 | 668 | |
| 629 | 669 | $result = $wpdb->update( $table, [ 'active' => '0' ], [ 'id' => $id ], [ '%d' ] ); |
| 630 | 670 | |
| @@ -702,13 +742,12 @@ | ||
| 702 | 742 | |
| 703 | 743 | // Update the last modification date if necessary. |
| 704 | 744 | $snippet->update_modified(); |
| 705 | 745 | |
| 746 | + // Strip any wrapper markup that came along with the pasted code. | |
| 747 | + $snippet->code = normalize_snippet_code( $snippet->code, $snippet->type ); | |
| 748 | + | |
| 706 | 749 | if ( 'php' === $snippet->type ) { |
| 707 | - // Remove tags from beginning and end of snippet. | |
| 708 | - $snippet->code = preg_replace( '|^\s*<\?(php)?|', '', $snippet->code ); | |
| 709 | - $snippet->code = preg_replace( '|\?>\s*$|', '', $snippet->code ); | |
| 710 | - | |
| 711 | 750 | // Deactivate snippet if code contains errors. |
| 712 | 751 | if ( $snippet->active && 'single-use' !== $snippet->scope ) { |
| 713 | 752 | test_snippet_code( $snippet ); |
| 714 | 753 | |
| @@ -725,8 +764,13 @@ | ||
| 725 | 764 | |
| 726 | 765 | // Shared network snippets are always considered inactive. |
| 727 | 766 | $snippet->active = $snippet->active && ! $snippet->shared_network; |
| 728 | 767 | |
| 768 | + // Snippet authorship: track who created and who last edited each snippet. | |
| 769 | + // `created_by` is fixed at insert time; `updated_by` reflects every save. | |
| 770 | + $current_user_id = get_current_user_id(); | |
| 771 | + $author_id = $current_user_id > 0 ? $current_user_id : null; | |
| 772 | + | |
| 729 | 773 | // Build the list of data to insert (excluding locked, which is stored in wp_options). |
| 730 | 774 | $data = [ |
| 731 | 775 | 'name' => $snippet->name, |
| 732 | 776 | 'description' => $snippet->desc, |
| @@ -738,12 +782,14 @@ | ||
| 738 | 782 | 'active' => intval( $snippet->active ), |
| 739 | 783 | 'modified' => $snippet->modified, |
| 740 | 784 | 'revision' => $snippet->revision, |
| 741 | 785 | 'cloud_id' => $snippet->cloud_id_owner ? $snippet->cloud_id_owner : null, |
| 786 | + 'updated_by' => $author_id, | |
| 742 | 787 | ]; |
| 743 | 788 | |
| 744 | 789 | // Create a new snippet if the ID is not set. |
| 745 | 790 | if ( 0 === $snippet->id ) { |
| 791 | + $data['created_by'] = $author_id; | |
| 746 | 792 | $result = $wpdb->insert( $table, $data, '%s' ); |
| 747 | 793 | if ( false === $result ) { |
| 748 | 794 | return null; |
| 749 | 795 | } |
| @@ -789,8 +835,40 @@ | ||
| 789 | 835 | return $updated; |
| 790 | 836 | } |
| 791 | 837 | |
| 792 | 838 | /** |
| 839 | + * Resolve a user ID to a compact author object for display. | |
| 840 | + * | |
| 841 | + * Returns the user's ID, display name, and avatar URL, or null when the ID is | |
| 842 | + * empty or the user no longer exists. Results are cached per request, so a list | |
| 843 | + * of snippets sharing authors only triggers one lookup per distinct user. | |
| 844 | + * | |
| 845 | + * @param int $user_id User ID to resolve. | |
| 846 | + * | |
| 847 | + * @return array{id: int, display_name: string, avatar_url: string}|null | |
| 848 | + */ | |
| 849 | +function get_snippet_author( int $user_id ): ?array { | |
| 850 | + static $cache = []; | |
| 851 | + | |
| 852 | + if ( $user_id <= 0 ) { | |
| 853 | + return null; | |
| 854 | + } | |
| 855 | + | |
| 856 | + if ( ! array_key_exists( $user_id, $cache ) ) { | |
| 857 | + $user = get_userdata( $user_id ); | |
| 858 | + $cache[ $user_id ] = $user ? | |
| 859 | + [ | |
| 860 | + 'id' => $user_id, | |
| 861 | + 'display_name' => $user->display_name, | |
| 862 | + 'avatar_url' => (string) get_avatar_url( $user_id, [ 'size' => 32 ] ), | |
| 863 | + ] : | |
| 864 | + null; | |
| 865 | + } | |
| 866 | + | |
| 867 | + return $cache[ $user_id ]; | |
| 868 | +} | |
| 869 | + | |
| 870 | +/** | |
| 793 | 871 | * Execute a snippet. |
| 794 | 872 | * Execute operation. |
| 795 | 873 | * |
| 796 | 874 | * Code must NOT be escaped, as it will be executed directly. |
| @@ -844,9 +922,9 @@ | ||
| 844 | 922 | */ |
| 845 | 923 | function get_snippet_by_cloud_id( string $cloud_id, ?bool $multisite = null ): ?Snippet { |
| 846 | 924 | global $wpdb; |
| 847 | 925 | |
| 848 | - $multisite = DB::validate_network_param( $multisite ); | |
| 926 | + $multisite = validate_network_param( $multisite ); | |
| 849 | 927 | $table_name = code_snippets()->db->get_table_name( $multisite ); |
| 850 | 928 | |
| 851 | 929 | $cached_snippets = wp_cache_get( "all_snippets_$table_name", CACHE_GROUP ); |
| 852 | 930 | |
| @@ -872,8 +950,64 @@ | ||
| 872 | 950 | return apply_filters( 'code_snippets/get_snippet_by_cloud_id', $snippet, $cloud_id, $multisite ); |
| 873 | 951 | } |
| 874 | 952 | |
| 875 | 953 | /** |
| 954 | + * Remove the wrapper markup that a snippet's code does not need. | |
| 955 | + * | |
| 956 | + * Snippet code is stored bare: PHP is evaluated already inside PHP, and CSS and | |
| 957 | + * JavaScript are wrapped in their own tags when printed. People increasingly | |
| 958 | + * paste code generated by an AI assistant, which almost always arrives wrapped | |
| 959 | + * in the tags for its language and sometimes in a markdown code fence as well. | |
| 960 | + * | |
| 961 | + * Leaving that markup in place fails differently depending on the type, and all | |
| 962 | + * three ways are unhelpful. PHP raises a syntax error, so the snippet saves and | |
| 963 | + * is then quietly deactivated. CSS and JavaScript have no syntax check at all, | |
| 964 | + * so they save as active and emit doubled tags on the front end with nothing | |
| 965 | + * reported anywhere. | |
| 966 | + * | |
| 967 | + * Only a wrapper around the whole snippet is removed. Tags appearing partway | |
| 968 | + * through the code are left alone, since those are the author's own. | |
| 969 | + * | |
| 970 | + * @param string $code Snippet code as provided. | |
| 971 | + * @param string $type Snippet type: php, css, js or html. | |
| 972 | + * | |
| 973 | + * @return string Code with any surrounding wrapper markup removed. | |
| 974 | + */ | |
| 975 | +function normalize_snippet_code( string $code, string $type ): string { | |
| 976 | + // A markdown fence around the whole snippet, as copied from a chat window. | |
| 977 | + // The closing fence only goes when an opening one was there: on its own it | |
| 978 | + // is the author's content, as in an HTML snippet ending in backticks. | |
| 979 | + $code = preg_replace( '/\A\s*```[a-z]*[ \t]*\R/i', '', $code, 1, $fenced ); | |
| 980 | + | |
| 981 | + if ( $fenced ) { | |
| 982 | + $code = preg_replace( '/\R\s*```\s*\z/', '', $code ); | |
| 983 | + } | |
| 984 | + | |
| 985 | + switch ( $type ) { | |
| 986 | + case 'php': | |
| 987 | + // `php` is matched as a whole word so that `<?phpinfo()` is not | |
| 988 | + // mistaken for an opening tag followed by `info()`. | |
| 989 | + $code = preg_replace( '/\A\s*<\?(?:php\b)?/i', '', $code ); | |
| 990 | + $code = preg_replace( '/\?>\s*\z/', '', $code ); | |
| 991 | + break; | |
| 992 | + | |
| 993 | + case 'css': | |
| 994 | + $code = preg_replace( '/\A\s*<style\b[^>]*>/i', '', $code ); | |
| 995 | + $code = preg_replace( '/<\/style\s*>\s*\z/i', '', $code ); | |
| 996 | + break; | |
| 997 | + | |
| 998 | + case 'js': | |
| 999 | + $code = preg_replace( '/\A\s*<script\b[^>]*>/i', '', $code ); | |
| 1000 | + $code = preg_replace( '/<\/script\s*>\s*\z/i', '', $code ); | |
| 1001 | + break; | |
| 1002 | + } | |
| 1003 | + | |
| 1004 | + // Drop the single line break left behind by an opening tag on its own line, | |
| 1005 | + // so the stored code does not gain a blank first line each time. | |
| 1006 | + return preg_replace( '/\A\R/', '', $code ); | |
| 1007 | +} | |
| 1008 | + | |
| 1009 | +/** | |
| 876 | 1010 | * Update a snippet entry given a list of fields. |
| 877 | 1011 | * Write operation. |
| 878 | 1012 | * |
| 879 | 1013 | * @param int $snippet_id ID of the snippet to update. |
| @@ -882,9 +1016,9 @@ | ||
| 882 | 1016 | */ |
| 883 | 1017 | function update_snippet_fields( int $snippet_id, array $fields, ?bool $network = null ) { |
| 884 | 1018 | global $wpdb; |
| 885 | 1019 | |
| 886 | - $network = DB::validate_network_param( $network ); | |
| 1020 | + $network = validate_network_param( $network ); | |
| 887 | 1021 | $table = code_snippets()->db->get_table_name( $network ); |
| 888 | 1022 | |
| 889 | 1023 | // Build a new snippet object for the validation. |
| 890 | 1024 | $snippet = new Snippet(); |