| @@ -6,13 +6,54 @@ | ||
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | 8 | namespace Code_Snippets; |
| 9 | 9 | |
| 10 | -use ParseError; | |
| 11 | -use function Code_Snippets\Settings\get_self_option; | |
| 12 | -use function Code_Snippets\Settings\update_self_option; | |
| 10 | +use Exception; | |
| 11 | +use Code_Snippets\Model\Snippet; | |
| 12 | +use Code_Snippets\Utils\Validator; | |
| 13 | +use Throwable; | |
| 14 | +use function Code_Snippets\Utils\get_self_option; | |
| 15 | +use function Code_Snippets\Utils\validate_network_param; | |
| 16 | +use function Code_Snippets\Utils\update_self_option; | |
| 13 | 17 | |
| 14 | 18 | /** |
| 19 | + * Get the locked status for a snippet from wp_options. | |
| 20 | + * | |
| 21 | + * @param int $snippet_id Snippet ID. | |
| 22 | + * @param bool|null $network Whether the snippet is network-wide (true) or site-wide (false). | |
| 23 | + * | |
| 24 | + * @return bool Whether the snippet is locked. | |
| 25 | + */ | |
| 26 | +function is_snippet_locked( int $snippet_id, ?bool $network = null ): bool { | |
| 27 | + $network = validate_network_param( $network ); | |
| 28 | + $locked_snippets = get_self_option( $network, 'code_snippets_locked', [] ); | |
| 29 | + | |
| 30 | + return isset( $locked_snippets[ $snippet_id ] ) && $locked_snippets[ $snippet_id ]; | |
| 31 | +} | |
| 32 | + | |
| 33 | +/** | |
| 34 | + * Set the locked status for a snippet in wp_options. | |
| 35 | + * | |
| 36 | + * @param int $snippet_id Snippet ID. | |
| 37 | + * @param bool $locked Whether the snippet should be locked. | |
| 38 | + * @param bool|null $network Whether the snippet is network-wide (true) or site-wide (false). | |
| 39 | + * | |
| 40 | + * @return void | |
| 41 | + */ | |
| 42 | +function set_snippet_locked( int $snippet_id, bool $locked, ?bool $network = null ): void { | |
| 43 | + $network = validate_network_param( $network ); | |
| 44 | + $locked_snippets = get_self_option( $network, 'code_snippets_locked', [] ); | |
| 45 | + | |
| 46 | + if ( $locked ) { | |
| 47 | + $locked_snippets[ $snippet_id ] = true; | |
| 48 | + } else { | |
| 49 | + unset( $locked_snippets[ $snippet_id ] ); | |
| 50 | + } | |
| 51 | + | |
| 52 | + update_self_option( $network, 'code_snippets_locked', $locked_snippets ); | |
| 53 | +} | |
| 54 | + | |
| 55 | +/** | |
| 15 | 56 | * Clean the cache where active snippets are stored. |
| 16 | 57 | * |
| 17 | 58 | * @param string $table_name Snippets table name. |
| 18 | 59 | * @param array<string>|false $scopes List of scopes. Optional. If not provided, will flush the cache for all scopes. |
| @@ -19,14 +60,19 @@ | ||
| 19 | 60 | * |
| 20 | 61 | * @return void |
| 21 | 62 | */ |
| 22 | 63 | function clean_active_snippets_cache( string $table_name, $scopes = false ) { |
| 23 | - $scope_groups = $scopes ? [ $scopes ] : [ | |
| 24 | - [ 'head-content', 'footer-content' ], | |
| 25 | - [ 'global', 'single-use', 'front-end' ], | |
| 26 | - [ 'global', 'single-use', 'admin' ], | |
| 27 | - ]; | |
| 64 | + $scope_groups = $scopes | |
| 65 | + ? [ $scopes ] | |
| 66 | + : [ | |
| 67 | + // Content snippets. | |
| 68 | + [ 'head-content', 'body-content', 'footer-content' ], | |
| 28 | 69 | |
| 70 | + // Function snippets. | |
| 71 | + [ 'global', 'single-use', 'front-end' ], | |
| 72 | + [ 'global', 'single-use', 'admin' ], | |
| 73 | + ]; | |
| 74 | + | |
| 29 | 75 | foreach ( $scope_groups as $scopes ) { |
| 30 | 76 | wp_cache_delete( sprintf( 'active_snippets_%s_%s', sanitize_key( join( '_', $scopes ) ), $table_name ), CACHE_GROUP ); |
| 31 | 77 | } |
| 32 | 78 | } |
| @@ -44,8 +90,90 @@ | ||
| 44 | 90 | clean_active_snippets_cache( $table_name ); |
| 45 | 91 | } |
| 46 | 92 | |
| 47 | 93 | /** |
| 94 | + * Flush an entire cache group, where the object cache supports it. | |
| 95 | + * | |
| 96 | + * Not all persistent cache drop-ins implement group flushing, and the function | |
| 97 | + * itself only exists from WordPress 6.1, so both are checked before use. A | |
| 98 | + * failure is not important: cache groups are scoped to the plugin version, so | |
| 99 | + * flushing is housekeeping rather than something correctness depends on, and | |
| 100 | + * anything left behind is evicted by the cache in its own time. | |
| 101 | + * | |
| 102 | + * @param string $group Cache group to flush. | |
| 103 | + * | |
| 104 | + * @return bool Whether the group was flushed. | |
| 105 | + */ | |
| 106 | +function flush_cache_group( string $group ): bool { | |
| 107 | + /** | |
| 108 | + * Short-circuits flushing a cache group. | |
| 109 | + * | |
| 110 | + * Returning a boolean skips the object cache entirely: false makes the | |
| 111 | + * caller fall back to deleting the known keys one by one, for a cache | |
| 112 | + * that reports group support it does not really have. | |
| 113 | + * | |
| 114 | + * @param bool|null $flushed Whether the group was flushed, or null to let the cache try. | |
| 115 | + * @param string $group Cache group. | |
| 116 | + */ | |
| 117 | + $flushed = apply_filters( 'code_snippets/pre_flush_cache_group', null, $group ); | |
| 118 | + | |
| 119 | + if ( null !== $flushed ) { | |
| 120 | + return (bool) $flushed; | |
| 121 | + } | |
| 122 | + | |
| 123 | + if ( ! function_exists( 'wp_cache_flush_group' ) || | |
| 124 | + ! function_exists( 'wp_cache_supports' ) || | |
| 125 | + ! wp_cache_supports( 'flush_group' ) ) { | |
| 126 | + return false; | |
| 127 | + } | |
| 128 | + | |
| 129 | + return wp_cache_flush_group( $group ); | |
| 130 | +} | |
| 131 | + | |
| 132 | +/** | |
| 133 | + * Flush the cache groups belonging to other versions of the plugin. | |
| 134 | + * | |
| 135 | + * @param string $previous_version Version the site was running beforehand. | |
| 136 | + * | |
| 137 | + * @return void | |
| 138 | + */ | |
| 139 | +function flush_versioned_cache_groups( string $previous_version ): void { | |
| 140 | + if ( '' !== $previous_version && PLUGIN_VERSION !== $previous_version ) { | |
| 141 | + flush_cache_group( CACHE_GROUP_BASE . '_' . $previous_version ); | |
| 142 | + } | |
| 143 | + | |
| 144 | + // Versions before the group was scoped wrote to the unscoped group, and no | |
| 145 | + // version that scopes it ever writes there again. Clearing it means a site | |
| 146 | + // upgrading from 3.10.0 or 3.10.1 sheds the objects that would otherwise | |
| 147 | + // still be waiting to break its next rollback. | |
| 148 | + flush_cache_group( CACHE_GROUP_BASE ); | |
| 149 | + | |
| 150 | + // Where the cache cannot flush a whole group, the keys this plugin writes | |
| 151 | + // are deleted one by one instead, so an uninstall followed by a reinstall | |
| 152 | + // of the same version cannot read snippets that no longer exist. | |
| 153 | + if ( ! flush_cache_group( CACHE_GROUP ) ) { | |
| 154 | + flush_known_cache_keys(); | |
| 155 | + } | |
| 156 | +} | |
| 157 | + | |
| 158 | +/** | |
| 159 | + * Delete every key this plugin is known to write in its current cache group. | |
| 160 | + * | |
| 161 | + * @return void | |
| 162 | + */ | |
| 163 | +function flush_known_cache_keys(): void { | |
| 164 | + // Both tables' keys go, whether this is a network: deleting a key | |
| 165 | + // that was never written does not cost anything, and it keeps one path to test. | |
| 166 | + $tables = [ code_snippets()->db->get_table_name( false ), code_snippets()->db->get_table_name( true ) ]; | |
| 167 | + | |
| 168 | + foreach ( array_unique( $tables ) as $table ) { | |
| 169 | + clean_snippets_cache( $table ); | |
| 170 | + } | |
| 171 | + | |
| 172 | + wp_cache_delete( Settings\CACHE_KEY, CACHE_GROUP ); | |
| 173 | +} | |
| 174 | + | |
| 175 | +/** | |
| 48 | 176 | * Retrieve a list of snippets from the database. |
| 49 | 177 | * Read operation. |
| 50 | 178 | * |
| 51 | 179 | * @param array<string> $ids The IDs of the snippets to fetch. |
| @@ -50,22 +178,22 @@ | ||
| 50 | 178 | * |
| 51 | 179 | * @param array<string> $ids The IDs of the snippets to fetch. |
| 52 | 180 | * @param bool|null $network Retrieve multisite-wide snippets (true) or site-wide snippets (false). |
| 53 | 181 | * |
| 54 | - * @return array<Snippet> List of Snippet objects. | |
| 182 | + * @return Snippet[] List of Snippet objects. | |
| 55 | 183 | * |
| 56 | 184 | * @since 2.0 |
| 57 | 185 | */ |
| 58 | -function get_snippets( array $ids = array(), ?bool $network = null ): array { | |
| 186 | +function get_snippets( array $ids = [], ?bool $network = null ): array { | |
| 59 | 187 | global $wpdb; |
| 60 | 188 | |
| 61 | 189 | // If only one ID has been passed in, defer to the get_snippet() function. |
| 62 | 190 | $ids_count = count( $ids ); |
| 63 | 191 | if ( 1 === $ids_count ) { |
| 64 | - return array( get_snippet( $ids[0], $network ) ); | |
| 192 | + return [ get_snippet( $ids[0], $network ) ]; | |
| 65 | 193 | } |
| 66 | 194 | |
| 67 | - $network = DB::validate_network_param( $network ); | |
| 195 | + $network = validate_network_param( $network ); | |
| 68 | 196 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 69 | 197 | |
| 70 | 198 | $snippets = wp_cache_get( "all_snippets_$table_name", CACHE_GROUP ); |
| 71 | 199 | |
| @@ -72,17 +200,22 @@ | ||
| 72 | 200 | // Fetch all snippets from the database if none are cached. |
| 73 | 201 | if ( ! is_array( $snippets ) ) { |
| 74 | 202 | $results = $wpdb->get_results( "SELECT * FROM $table_name", ARRAY_A ); |
| 75 | 203 | |
| 76 | - $snippets = $results ? | |
| 77 | - array_map( | |
| 204 | + $snippets = $results | |
| 205 | + ? array_map( | |
| 78 | 206 | function ( $snippet_data ) use ( $network ) { |
| 79 | 207 | $snippet_data['network'] = $network; |
| 80 | - return new Snippet( $snippet_data ); | |
| 208 | + $snippet = new Snippet( $snippet_data ); | |
| 209 | + // Load locked from wp_options. | |
| 210 | + if ( $snippet->id > 0 ) { | |
| 211 | + $snippet->locked = is_snippet_locked( $snippet->id, $network ); | |
| 212 | + } | |
| 213 | + return $snippet; | |
| 81 | 214 | }, |
| 82 | 215 | $results |
| 83 | - ) : | |
| 84 | - array(); | |
| 216 | + ) | |
| 217 | + : []; | |
| 85 | 218 | |
| 86 | 219 | $snippets = apply_filters( 'code_snippets/get_snippets', $snippets, $network ); |
| 87 | 220 | |
| 88 | 221 | if ( 0 === $ids_count ) { |
| @@ -172,17 +305,17 @@ | ||
| 172 | 305 | * |
| 173 | 306 | * @param int $id The ID of the snippet to retrieve. 0 to build a new snippet. |
| 174 | 307 | * @param bool|null $network Retrieve a multisite-wide snippet (true) or site-wide snippet (false). |
| 175 | 308 | * |
| 176 | - * @return Snippet A single snippet object. | |
| 309 | + * @return ?Snippet A single snippet object. | |
| 177 | 310 | * |
| 178 | 311 | * @since 2.0.0 |
| 179 | 312 | */ |
| 180 | -function get_snippet( int $id = 0, ?bool $network = null ): Snippet { | |
| 313 | +function get_snippet( int $id = 0, ?bool $network = null ): ?Snippet { | |
| 181 | 314 | global $wpdb; |
| 182 | 315 | |
| 183 | 316 | $id = absint( $id ); |
| 184 | - $network = DB::validate_network_param( $network ); | |
| 317 | + $network = validate_network_param( $network ); | |
| 185 | 318 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 186 | 319 | |
| 187 | 320 | if ( 0 === $id ) { |
| 188 | 321 | // If an invalid ID is provided, then return an empty snippet object. |
| @@ -206,14 +339,20 @@ | ||
| 206 | 339 | $snippet = new Snippet( $snippet_data ); |
| 207 | 340 | } |
| 208 | 341 | |
| 209 | 342 | $snippet->network = $network; |
| 343 | + | |
| 344 | + // Load locked from wp_options if snippet has an ID. | |
| 345 | + if ( $snippet->id > 0 ) { | |
| 346 | + $snippet->locked = is_snippet_locked( $snippet->id, $network ); | |
| 347 | + } | |
| 348 | + | |
| 210 | 349 | return apply_filters( 'code_snippets/get_snippet', $snippet, $id, $network ); |
| 211 | 350 | } |
| 212 | 351 | |
| 213 | 352 | |
| 214 | 353 | /** |
| 215 | - * Ensure the list of shared network snippets is correct if one has been recently activated or deactivated. | |
| 354 | + * Ensure the list of shared network snippets is correct if one has been recently active or deactivated. | |
| 216 | 355 | * Write operation. |
| 217 | 356 | * |
| 218 | 357 | * @access private |
| 219 | 358 | * |
| @@ -218,9 +357,9 @@ | ||
| 218 | 357 | * @access private |
| 219 | 358 | * |
| 220 | 359 | * @param Snippet[] $snippets Snippets that was recently updated. |
| 221 | 360 | * |
| 222 | - * @return boolean Whether an update was performed. | |
| 361 | + * @return bool Whether an update was performed. | |
| 223 | 362 | */ |
| 224 | 363 | function update_shared_network_snippets( array $snippets ): bool { |
| 225 | 364 | $shared_ids = []; |
| 226 | 365 | $unshared_ids = []; |
| @@ -285,9 +424,9 @@ | ||
| 285 | 424 | * @since 2.0.0 |
| 286 | 425 | */ |
| 287 | 426 | function activate_snippet( int $id, ?bool $network = null ) { |
| 288 | 427 | global $wpdb; |
| 289 | - $network = DB::validate_network_param( $network ); | |
| 428 | + $network = validate_network_param( $network ); | |
| 290 | 429 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 291 | 430 | |
| 292 | 431 | // Retrieve the snippet code from the database for validation before activating. |
| 293 | 432 | $snippet = get_snippet( $id, $network ); |
| @@ -295,10 +434,10 @@ | ||
| 295 | 434 | if ( 0 === $snippet->id ) { |
| 296 | 435 | // translators: %d: snippet identifier. |
| 297 | 436 | return sprintf( __( 'Could not locate snippet with ID %d.', 'code-snippets' ), $id ); |
| 298 | 437 | } |
| 299 | - | |
| 300 | - if('php' == $snippet->type ){ | |
| 438 | + | |
| 439 | + if ( 'php' === $snippet->type ) { | |
| 301 | 440 | $validator = new Validator( $snippet->code ); |
| 302 | 441 | if ( $validator->validate() ) { |
| 303 | 442 | return __( 'Could not activate snippet: code did not pass validation.', 'code-snippets' ); |
| 304 | 443 | } |
| @@ -325,10 +464,10 @@ | ||
| 325 | 464 | /** |
| 326 | 465 | * Activates multiple snippets. |
| 327 | 466 | * Write operation. |
| 328 | 467 | * |
| 329 | - * @param array<integer> $ids The IDs of the snippets to activate. | |
| 330 | - * @param bool|null $network Whether the snippets are multisite-wide (true) or site-wide (false). | |
| 468 | + * @param array<int> $ids The IDs of the snippets to activate. | |
| 469 | + * @param bool|null $network Whether the snippets are multisite-wide (true) or site-wide (false). | |
| 331 | 470 | * |
| 332 | 471 | * @return Snippet[]|null Snippets which were successfully activated, or null on failure. |
| 333 | 472 | * |
| 334 | 473 | * @since 2.0.0 |
| @@ -334,9 +473,9 @@ | ||
| 334 | 473 | * @since 2.0.0 |
| 335 | 474 | */ |
| 336 | 475 | function activate_snippets( array $ids, ?bool $network = null ): ?array { |
| 337 | 476 | global $wpdb; |
| 338 | - $network = DB::validate_network_param( $network ); | |
| 477 | + $network = validate_network_param( $network ); | |
| 339 | 478 | $table_name = code_snippets()->db->get_table_name( $network ); |
| 340 | 479 | |
| 341 | 480 | $snippets = get_snippets( $ids, $network ); |
| 342 | 481 | |
| @@ -347,13 +486,28 @@ | ||
| 347 | 486 | // Loop through each snippet code and validate individually. |
| 348 | 487 | $valid_ids = []; |
| 349 | 488 | $valid_snippets = []; |
| 350 | 489 | |
| 490 | + // Names claimed by snippets already accepted into this batch. A snippet is | |
| 491 | + // otherwise validated only against what PHP has declared so far, which does | |
| 492 | + // not include the other snippets about to be activated alongside it. | |
| 493 | + $claimed_identifiers = []; | |
| 494 | + | |
| 351 | 495 | foreach ( $snippets as $snippet ) { |
| 352 | - $validator = new Validator( $snippet->code ); | |
| 496 | + // Only PHP is validated. The validator looks for redeclarations of | |
| 497 | + // existing PHP functions and classes, which says nothing meaningful | |
| 498 | + // about CSS or JavaScript. | |
| 499 | + if ( 'php' !== $snippet->type ) { | |
| 500 | + $valid_ids[] = $snippet->id; | |
| 501 | + $valid_snippets[] = $snippet; | |
| 502 | + continue; | |
| 503 | + } | |
| 504 | + | |
| 505 | + $validator = new Validator( $snippet->code, $claimed_identifiers ); | |
| 353 | 506 | $code_error = $validator->validate(); |
| 354 | 507 | |
| 355 | 508 | if ( ! $code_error ) { |
| 509 | + $claimed_identifiers = $validator->get_claimed_identifiers(); | |
| 356 | 510 | $valid_ids[] = $snippet->id; |
| 357 | 511 | $valid_snippets[] = $snippet; |
| 358 | 512 | } |
| 359 | 513 | } |
| @@ -391,9 +545,9 @@ | ||
| 391 | 545 | * @since 2.0.0 |
| 392 | 546 | */ |
| 393 | 547 | function deactivate_snippet( int $id, ?bool $network = null ): ?Snippet { |
| 394 | 548 | global $wpdb; |
| 395 | - $network = DB::validate_network_param( $network ); | |
| 549 | + $network = validate_network_param( $network ); | |
| 396 | 550 | $table = code_snippets()->db->get_table_name( $network ); |
| 397 | 551 | |
| 398 | 552 | // Set the snippet to inactive. |
| 399 | 553 | $result = $wpdb->update( |
| @@ -409,10 +563,11 @@ | ||
| 409 | 563 | } |
| 410 | 564 | |
| 411 | 565 | // Update the recently active list. |
| 412 | 566 | $snippet = get_snippet( $id ); |
| 413 | - $recently_active = [ $id => time() ] + get_self_option( $network, 'recently_activated_snippets', [] ); | |
| 414 | - update_self_option( $network, 'recently_activated_snippets', $recently_active ); | |
| 567 | + $recently_active = get_self_option( $network, 'recently_active_snippets', [] ); | |
| 568 | + $recently_active[ $id ] = time(); | |
| 569 | + update_self_option( $network, 'recently_active_snippets', $recently_active ); | |
| 415 | 570 | |
| 416 | 571 | update_shared_network_snippets( [ $snippet ] ); |
| 417 | 572 | do_action( 'code_snippets/deactivate_snippet', $id, $network ); |
| 418 | 573 | clean_snippets_cache( $table ); |
| @@ -432,13 +587,18 @@ | ||
| 432 | 587 | * @since 2.0.0 |
| 433 | 588 | */ |
| 434 | 589 | function delete_snippet( int $id, ?bool $network = null ): bool { |
| 435 | 590 | global $wpdb; |
| 436 | - $network = DB::validate_network_param( $network ); | |
| 591 | + $network = validate_network_param( $network ); | |
| 437 | 592 | $table = code_snippets()->db->get_table_name( $network ); |
| 438 | 593 | |
| 439 | 594 | $snippet = get_snippet( $id, $network ); |
| 440 | 595 | |
| 596 | + // Prevent deletion of locked snippets. | |
| 597 | + if ( $snippet->locked ) { | |
| 598 | + return false; | |
| 599 | + } | |
| 600 | + | |
| 441 | 601 | $result = $wpdb->delete( |
| 442 | 602 | $table, |
| 443 | 603 | array( 'id' => $id ), |
| 444 | 604 | array( '%d' ) |
| @@ -446,9 +606,15 @@ | ||
| 446 | 606 | |
| 447 | 607 | if ( $result ) { |
| 448 | 608 | do_action( 'code_snippets/delete_snippet', $snippet, $network ); |
| 449 | 609 | clean_snippets_cache( $table ); |
| 450 | - code_snippets()->cloud_api->delete_snippet_from_transient_data( $id ); | |
| 610 | + | |
| 611 | + $recently_active = get_self_option( $network, 'recently_active_snippets', [] ); | |
| 612 | + | |
| 613 | + if ( isset( $recently_active[ $id ] ) ) { | |
| 614 | + unset( $recently_active[ $id ] ); | |
| 615 | + update_self_option( $network, 'recently_active_snippets', $recently_active ); | |
| 616 | + } | |
| 451 | 617 | } |
| 452 | 618 | |
| 453 | 619 | return (bool) $result; |
| 454 | 620 | } |
| @@ -465,27 +631,24 @@ | ||
| 465 | 631 | * @since 3.8.0 |
| 466 | 632 | */ |
| 467 | 633 | function trash_snippet( int $id, ?bool $network = null ): bool { |
| 468 | 634 | global $wpdb; |
| 469 | - $network = DB::validate_network_param( $network ); | |
| 635 | + $network = validate_network_param( $network ); | |
| 470 | 636 | $table = code_snippets()->db->get_table_name( $network ); |
| 471 | 637 | |
| 472 | 638 | $snippet = get_snippet( $id, $network ); |
| 473 | 639 | |
| 474 | - $result = $wpdb->update( | |
| 475 | - $table, | |
| 476 | - array( 'active' => '-1' ), | |
| 477 | - array( 'id' => $id ), | |
| 478 | - array( '%d' ) | |
| 479 | - ); | |
| 640 | + // Prevent trashing of locked snippets. | |
| 641 | + if ( $snippet->locked ) { | |
| 642 | + return false; | |
| 643 | + } | |
| 480 | 644 | |
| 481 | - if ( $result ) { | |
| 482 | - do_action( 'code_snippets/trash_snippet', $snippet, $network ); | |
| 483 | - clean_snippets_cache( $table ); | |
| 484 | - code_snippets()->cloud_api->delete_snippet_from_transient_data( $id ); | |
| 485 | - } | |
| 645 | + $wpdb->update( $table, [ 'active' => '-1' ], [ 'id' => $id ], [ '%d' ] ); | |
| 486 | 646 | |
| 487 | - return (bool) $result; | |
| 647 | + do_action( 'code_snippets/trash_snippet', $snippet, $network ); | |
| 648 | + clean_snippets_cache( $table ); | |
| 649 | + | |
| 650 | + return true; | |
| 488 | 651 | } |
| 489 | 652 | |
| 490 | 653 | /** |
| 491 | 654 | * Restore a trashed snippet by setting its active status back to 0 (inactive). |
| @@ -499,17 +662,12 @@ | ||
| 499 | 662 | * @since 3.8.0 |
| 500 | 663 | */ |
| 501 | 664 | function restore_snippet( int $id, ?bool $network = null ): bool { |
| 502 | 665 | global $wpdb; |
| 503 | - $network = DB::validate_network_param( $network ); | |
| 666 | + $network = validate_network_param( $network ); | |
| 504 | 667 | $table = code_snippets()->db->get_table_name( $network ); |
| 505 | 668 | |
| 506 | - $result = $wpdb->update( | |
| 507 | - $table, | |
| 508 | - array( 'active' => '0' ), | |
| 509 | - array( 'id' => $id ), | |
| 510 | - array( '%d' ) | |
| 511 | - ); | |
| 669 | + $result = $wpdb->update( $table, [ 'active' => '0' ], [ 'id' => $id ], [ '%d' ] ); | |
| 512 | 670 | |
| 513 | 671 | if ( $result ) { |
| 514 | 672 | do_action( 'code_snippets/restore_snippet', $id, $network ); |
| 515 | 673 | clean_snippets_cache( $table ); |
| @@ -524,8 +682,9 @@ | ||
| 524 | 682 | * @param Snippet $snippet Snippet object. |
| 525 | 683 | */ |
| 526 | 684 | function test_snippet_code( Snippet $snippet ) { |
| 527 | 685 | $snippet->code_error = null; |
| 686 | + $snippet->code_error_trace = null; | |
| 528 | 687 | |
| 529 | 688 | if ( 'php' !== $snippet->type ) { |
| 530 | 689 | return; |
| 531 | 690 | } |
| @@ -534,18 +693,20 @@ | ||
| 534 | 693 | $result = $validator->validate(); |
| 535 | 694 | |
| 536 | 695 | if ( $result ) { |
| 537 | 696 | $snippet->code_error = [ $result['message'], $result['line'] ]; |
| 697 | + $snippet->code_error_trace = ( new Exception() )->getTraceAsString(); | |
| 538 | 698 | } |
| 539 | 699 | |
| 540 | 700 | if ( ! $snippet->code_error && 'single-use' !== $snippet->scope ) { |
| 541 | 701 | $result = execute_snippet( $snippet->code, $snippet->id, true ); |
| 542 | 702 | |
| 543 | - if ( $result instanceof ParseError ) { | |
| 703 | + if ( $result instanceof Throwable ) { | |
| 544 | 704 | $snippet->code_error = [ |
| 545 | 705 | ucfirst( rtrim( $result->getMessage(), '.' ) ) . '.', |
| 546 | 706 | $result->getLine(), |
| 547 | 707 | ]; |
| 708 | + $snippet->code_error_trace = $result->getTraceAsString(); | |
| 548 | 709 | } |
| 549 | 710 | } |
| 550 | 711 | } |
| 551 | 712 | |
| @@ -558,9 +719,9 @@ | ||
| 558 | 719 | * @return Snippet|null Updated snippet. |
| 559 | 720 | * |
| 560 | 721 | * @since 2.0.0 |
| 561 | 722 | */ |
| 562 | -function save_snippet( $snippet ) { | |
| 723 | +function save_snippet( $snippet ): ?Snippet { | |
| 563 | 724 | global $wpdb; |
| 564 | 725 | $table = code_snippets()->db->get_table_name( $snippet->network ); |
| 565 | 726 | |
| 566 | 727 | if ( ! $snippet instanceof Snippet ) { |
| @@ -566,16 +727,27 @@ | ||
| 566 | 727 | if ( ! $snippet instanceof Snippet ) { |
| 567 | 728 | $snippet = new Snippet( $snippet ); |
| 568 | 729 | } |
| 569 | 730 | |
| 731 | + // Prevent modification of locked snippets (allow unlocking itself). | |
| 732 | + if ( 0 !== $snippet->id ) { | |
| 733 | + $old_snippet = get_snippet( $snippet->id, $snippet->network ); | |
| 734 | + | |
| 735 | + if ( $old_snippet->locked && $snippet->locked ) { | |
| 736 | + // If it was locked and the new request still wants it locked, | |
| 737 | + // prevent changes to sensitive fields (code and name). | |
| 738 | + $snippet->code = $old_snippet->code; | |
| 739 | + $snippet->name = $old_snippet->name; | |
| 740 | + } | |
| 741 | + } | |
| 742 | + | |
| 570 | 743 | // Update the last modification date if necessary. |
| 571 | 744 | $snippet->update_modified(); |
| 572 | 745 | |
| 746 | + // Strip any wrapper markup that came along with the pasted code. | |
| 747 | + $snippet->code = normalize_snippet_code( $snippet->code, $snippet->type ); | |
| 748 | + | |
| 573 | 749 | if ( 'php' === $snippet->type ) { |
| 574 | - // Remove tags from beginning and end of snippet. | |
| 575 | - $snippet->code = preg_replace( '|^\s*<\?(php)?|', '', $snippet->code ); | |
| 576 | - $snippet->code = preg_replace( '|\?>\s*$|', '', $snippet->code ); | |
| 577 | - | |
| 578 | 750 | // Deactivate snippet if code contains errors. |
| 579 | 751 | if ( $snippet->active && 'single-use' !== $snippet->scope ) { |
| 580 | 752 | test_snippet_code( $snippet ); |
| 581 | 753 | |
| @@ -592,9 +764,14 @@ | ||
| 592 | 764 | |
| 593 | 765 | // Shared network snippets are always considered inactive. |
| 594 | 766 | $snippet->active = $snippet->active && ! $snippet->shared_network; |
| 595 | 767 | |
| 596 | - // Build the list of data to insert. | |
| 768 | + // Snippet authorship: track who created and who last edited each snippet. | |
| 769 | + // `created_by` is fixed at insert time; `updated_by` reflects every save. | |
| 770 | + $current_user_id = get_current_user_id(); | |
| 771 | + $author_id = $current_user_id > 0 ? $current_user_id : null; | |
| 772 | + | |
| 773 | + // Build the list of data to insert (excluding locked, which is stored in wp_options). | |
| 597 | 774 | $data = [ |
| 598 | 775 | 'name' => $snippet->name, |
| 599 | 776 | 'description' => $snippet->desc, |
| 600 | 777 | 'code' => $snippet->code, |
| @@ -604,13 +781,15 @@ | ||
| 604 | 781 | 'priority' => $snippet->priority, |
| 605 | 782 | 'active' => intval( $snippet->active ), |
| 606 | 783 | 'modified' => $snippet->modified, |
| 607 | 784 | 'revision' => $snippet->revision, |
| 608 | - 'cloud_id' => $snippet->cloud_id ? $snippet->cloud_id : null, | |
| 785 | + 'cloud_id' => $snippet->cloud_id_owner ? $snippet->cloud_id_owner : null, | |
| 786 | + 'updated_by' => $author_id, | |
| 609 | 787 | ]; |
| 610 | 788 | |
| 611 | 789 | // Create a new snippet if the ID is not set. |
| 612 | 790 | if ( 0 === $snippet->id ) { |
| 791 | + $data['created_by'] = $author_id; | |
| 613 | 792 | $result = $wpdb->insert( $table, $data, '%s' ); |
| 614 | 793 | if ( false === $result ) { |
| 615 | 794 | return null; |
| 616 | 795 | } |
| @@ -615,23 +794,78 @@ | ||
| 615 | 794 | return null; |
| 616 | 795 | } |
| 617 | 796 | |
| 618 | 797 | $snippet->id = $wpdb->insert_id; |
| 619 | - do_action( 'code_snippets/create_snippet', $snippet, $table ); | |
| 798 | + $updated = get_snippet( $snippet->id, $snippet->network ); | |
| 799 | + $updated->code_error = $snippet->code_error; | |
| 800 | + $updated->code_error_trace = $snippet->code_error_trace; | |
| 801 | + do_action( 'code_snippets/create_snippet', $updated, $table ); | |
| 802 | + | |
| 803 | + if ( $updated->id > 0 ) { | |
| 804 | + set_snippet_locked( $updated->id, $updated->locked, $updated->network ); | |
| 805 | + } | |
| 620 | 806 | } else { |
| 807 | + // Otherwise, update the snippet data. | |
| 808 | + $existing = get_snippet( $snippet->id, $snippet->network ); | |
| 621 | 809 | |
| 622 | - // Otherwise, update the snippet data. | |
| 623 | - $result = $wpdb->update( $table, $data, [ 'id' => $snippet->id ], null, [ '%d' ] ); | |
| 624 | - if ( false === $result ) { | |
| 625 | - return null; | |
| 810 | + set_snippet_locked( $snippet->id, $snippet->locked, $snippet->network ); | |
| 811 | + $wpdb->update( $table, $data, [ 'id' => $snippet->id ], null, [ '%d' ] ); | |
| 812 | + | |
| 813 | + $updated = get_snippet( $snippet->id, $snippet->network ); | |
| 814 | + $updated->code_error = $snippet->code_error; | |
| 815 | + $updated->code_error_trace = $snippet->code_error_trace; | |
| 816 | + | |
| 817 | + do_action( 'code_snippets/update_snippet', $updated, $table, $existing, $snippet ); | |
| 818 | + | |
| 819 | + if ( ! $updated->active && $existing->active ) { | |
| 820 | + $recently_active = get_self_option( $updated->network, 'recently_active_snippets', [] ); | |
| 821 | + $recently_active[ $updated->id ] = time(); | |
| 822 | + update_self_option( $updated->network, 'recently_active_snippets', $recently_active ); | |
| 823 | + } elseif ( ! $updated->active ) { | |
| 824 | + $recently_active = get_self_option( $updated->network, 'recently_active_snippets', [] ); | |
| 825 | + | |
| 826 | + if ( isset( $recently_active[ $updated->id ] ) ) { | |
| 827 | + unset( $recently_active[ $updated->id ] ); | |
| 828 | + update_self_option( $updated->network, 'recently_active_snippets', $recently_active ); | |
| 829 | + } | |
| 626 | 830 | } |
| 831 | + } | |
| 627 | 832 | |
| 628 | - do_action( 'code_snippets/update_snippet', $snippet, $table ); | |
| 833 | + update_shared_network_snippets( [ $updated ] ); | |
| 834 | + clean_snippets_cache( $table ); | |
| 835 | + return $updated; | |
| 836 | +} | |
| 837 | + | |
| 838 | +/** | |
| 839 | + * Resolve a user ID to a compact author object for display. | |
| 840 | + * | |
| 841 | + * Returns the user's ID, display name, and avatar URL, or null when the ID is | |
| 842 | + * empty or the user no longer exists. Results are cached per request, so a list | |
| 843 | + * of snippets sharing authors only triggers one lookup per distinct user. | |
| 844 | + * | |
| 845 | + * @param int $user_id User ID to resolve. | |
| 846 | + * | |
| 847 | + * @return array{id: int, display_name: string, avatar_url: string}|null | |
| 848 | + */ | |
| 849 | +function get_snippet_author( int $user_id ): ?array { | |
| 850 | + static $cache = []; | |
| 851 | + | |
| 852 | + if ( $user_id <= 0 ) { | |
| 853 | + return null; | |
| 629 | 854 | } |
| 630 | 855 | |
| 631 | - update_shared_network_snippets( [ $snippet ] ); | |
| 632 | - clean_snippets_cache( $table ); | |
| 633 | - return $snippet; | |
| 856 | + if ( ! array_key_exists( $user_id, $cache ) ) { | |
| 857 | + $user = get_userdata( $user_id ); | |
| 858 | + $cache[ $user_id ] = $user ? | |
| 859 | + [ | |
| 860 | + 'id' => $user_id, | |
| 861 | + 'display_name' => $user->display_name, | |
| 862 | + 'avatar_url' => (string) get_avatar_url( $user_id, [ 'size' => 32 ] ), | |
| 863 | + ] : | |
| 864 | + null; | |
| 865 | + } | |
| 866 | + | |
| 867 | + return $cache[ $user_id ]; | |
| 634 | 868 | } |
| 635 | 869 | |
| 636 | 870 | /** |
| 637 | 871 | * Execute a snippet. |
| @@ -638,15 +872,18 @@ | ||
| 638 | 872 | * Execute operation. |
| 639 | 873 | * |
| 640 | 874 | * Code must NOT be escaped, as it will be executed directly. |
| 641 | 875 | * |
| 642 | - * @param string $code Snippet code to execute. | |
| 643 | - * @param integer $id Snippet ID. | |
| 644 | - * @param boolean $force Force snippet execution, even if save mode is active. | |
| 876 | + * @param string $code Snippet code to execute. | |
| 877 | + * @param int $id Snippet ID. | |
| 878 | + * @param bool $force Force snippet execution, even if save mode is active. | |
| 645 | 879 | * |
| 646 | - * @return ParseError|mixed Code error if encountered during execution, or result of snippet execution otherwise. | |
| 880 | + * @return Throwable|mixed Code error if encountered during execution, or result of snippet execution otherwise. | |
| 647 | 881 | * |
| 648 | - * @since 2.0.0 | |
| 882 | + * @since 2.0.0 | |
| 883 | + * @noinspection PhpUndefinedConstantInspection | |
| 884 | + * | |
| 885 | + * phpcs:disable Squiz.PHP.Eval.Discouraged | |
| 649 | 886 | */ |
| 650 | 887 | function execute_snippet( string $code, int $id = 0, bool $force = false ) { |
| 651 | 888 | /** |
| 652 | 889 | * Do not continue if safe mode is active. |
| @@ -660,10 +897,10 @@ | ||
| 660 | 897 | ob_start(); |
| 661 | 898 | |
| 662 | 899 | try { |
| 663 | 900 | $result = eval( $code ); |
| 664 | - } catch ( ParseError $parse_error ) { | |
| 665 | - $result = $parse_error; | |
| 901 | + } catch ( Throwable $throwable ) { | |
| 902 | + $result = $throwable; | |
| 666 | 903 | } |
| 667 | 904 | |
| 668 | 905 | ob_end_clean(); |
| 669 | 906 | |
| @@ -675,10 +912,10 @@ | ||
| 675 | 912 | * Retrieve a single snippets from the database using its cloud ID. |
| 676 | 913 | * |
| 677 | 914 | * Read operation. |
| 678 | 915 | * |
| 679 | - * @param string $cloud_id The Cloud ID of the snippet to retrieve. | |
| 680 | - * @param boolean|null $multisite Retrieve a multisite-wide snippet (true) or site-wide snippet (false). | |
| 916 | + * @param string $cloud_id The Cloud ID of the snippet to retrieve. | |
| 917 | + * @param bool|null $multisite Retrieve a multisite-wide snippet (true) or site-wide snippet (false). | |
| 681 | 918 | * |
| 682 | 919 | * @return Snippet|null A single snippet object or null if no snippet was found. |
| 683 | 920 | * |
| 684 | 921 | * @since 3.5.0 |
| @@ -685,9 +922,9 @@ | ||
| 685 | 922 | */ |
| 686 | 923 | function get_snippet_by_cloud_id( string $cloud_id, ?bool $multisite = null ): ?Snippet { |
| 687 | 924 | global $wpdb; |
| 688 | 925 | |
| 689 | - $multisite = DB::validate_network_param( $multisite ); | |
| 926 | + $multisite = validate_network_param( $multisite ); | |
| 690 | 927 | $table_name = code_snippets()->db->get_table_name( $multisite ); |
| 691 | 928 | |
| 692 | 929 | $cached_snippets = wp_cache_get( "all_snippets_$table_name", CACHE_GROUP ); |
| 693 | 930 | |
| @@ -703,12 +940,74 @@ | ||
| 703 | 940 | // Otherwise, search for the snippet from the database. |
| 704 | 941 | $snippet_data = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM $table_name WHERE cloud_id = %s", $cloud_id ) ); // cache pass, db call ok. |
| 705 | 942 | $snippet = $snippet_data ? new Snippet( $snippet_data ) : null; |
| 706 | 943 | |
| 944 | + // Load locked from wp_options if snippet exists. | |
| 945 | + if ( $snippet && $snippet->id > 0 ) { | |
| 946 | + $snippet->network = $multisite; | |
| 947 | + $snippet->locked = is_snippet_locked( $snippet->id, $multisite ); | |
| 948 | + } | |
| 949 | + | |
| 707 | 950 | return apply_filters( 'code_snippets/get_snippet_by_cloud_id', $snippet, $cloud_id, $multisite ); |
| 708 | 951 | } |
| 709 | 952 | |
| 710 | 953 | /** |
| 954 | + * Remove the wrapper markup that a snippet's code does not need. | |
| 955 | + * | |
| 956 | + * Snippet code is stored bare: PHP is evaluated already inside PHP, and CSS and | |
| 957 | + * JavaScript are wrapped in their own tags when printed. People increasingly | |
| 958 | + * paste code generated by an AI assistant, which almost always arrives wrapped | |
| 959 | + * in the tags for its language and sometimes in a markdown code fence as well. | |
| 960 | + * | |
| 961 | + * Leaving that markup in place fails differently depending on the type, and all | |
| 962 | + * three ways are unhelpful. PHP raises a syntax error, so the snippet saves and | |
| 963 | + * is then quietly deactivated. CSS and JavaScript have no syntax check at all, | |
| 964 | + * so they save as active and emit doubled tags on the front end with nothing | |
| 965 | + * reported anywhere. | |
| 966 | + * | |
| 967 | + * Only a wrapper around the whole snippet is removed. Tags appearing partway | |
| 968 | + * through the code are left alone, since those are the author's own. | |
| 969 | + * | |
| 970 | + * @param string $code Snippet code as provided. | |
| 971 | + * @param string $type Snippet type: php, css, js or html. | |
| 972 | + * | |
| 973 | + * @return string Code with any surrounding wrapper markup removed. | |
| 974 | + */ | |
| 975 | +function normalize_snippet_code( string $code, string $type ): string { | |
| 976 | + // A markdown fence around the whole snippet, as copied from a chat window. | |
| 977 | + // The closing fence only goes when an opening one was there: on its own it | |
| 978 | + // is the author's content, as in an HTML snippet ending in backticks. | |
| 979 | + $code = preg_replace( '/\A\s*```[a-z]*[ \t]*\R/i', '', $code, 1, $fenced ); | |
| 980 | + | |
| 981 | + if ( $fenced ) { | |
| 982 | + $code = preg_replace( '/\R\s*```\s*\z/', '', $code ); | |
| 983 | + } | |
| 984 | + | |
| 985 | + switch ( $type ) { | |
| 986 | + case 'php': | |
| 987 | + // `php` is matched as a whole word so that `<?phpinfo()` is not | |
| 988 | + // mistaken for an opening tag followed by `info()`. | |
| 989 | + $code = preg_replace( '/\A\s*<\?(?:php\b)?/i', '', $code ); | |
| 990 | + $code = preg_replace( '/\?>\s*\z/', '', $code ); | |
| 991 | + break; | |
| 992 | + | |
| 993 | + case 'css': | |
| 994 | + $code = preg_replace( '/\A\s*<style\b[^>]*>/i', '', $code ); | |
| 995 | + $code = preg_replace( '/<\/style\s*>\s*\z/i', '', $code ); | |
| 996 | + break; | |
| 997 | + | |
| 998 | + case 'js': | |
| 999 | + $code = preg_replace( '/\A\s*<script\b[^>]*>/i', '', $code ); | |
| 1000 | + $code = preg_replace( '/<\/script\s*>\s*\z/i', '', $code ); | |
| 1001 | + break; | |
| 1002 | + } | |
| 1003 | + | |
| 1004 | + // Drop the single line break left behind by an opening tag on its own line, | |
| 1005 | + // so the stored code does not gain a blank first line each time. | |
| 1006 | + return preg_replace( '/\A\R/', '', $code ); | |
| 1007 | +} | |
| 1008 | + | |
| 1009 | +/** | |
| 711 | 1010 | * Update a snippet entry given a list of fields. |
| 712 | 1011 | * Write operation. |
| 713 | 1012 | * |
| 714 | 1013 | * @param int $snippet_id ID of the snippet to update. |
| @@ -717,8 +1016,9 @@ | ||
| 717 | 1016 | */ |
| 718 | 1017 | function update_snippet_fields( int $snippet_id, array $fields, ?bool $network = null ) { |
| 719 | 1018 | global $wpdb; |
| 720 | 1019 | |
| 1020 | + $network = validate_network_param( $network ); | |
| 721 | 1021 | $table = code_snippets()->db->get_table_name( $network ); |
| 722 | 1022 | |
| 723 | 1023 | // Build a new snippet object for the validation. |
| 724 | 1024 | $snippet = new Snippet(); |
| @@ -725,10 +1025,18 @@ | ||
| 725 | 1025 | $snippet->id = $snippet_id; |
| 726 | 1026 | |
| 727 | 1027 | // Validate fields through the snippet class and copy them into a clean array. |
| 728 | 1028 | $clean_fields = array(); |
| 1029 | + $locked_value = null; | |
| 729 | 1030 | |
| 730 | 1031 | foreach ( $fields as $field => $value ) { |
| 1032 | + // Handle locked separately (stored in wp_options). | |
| 1033 | + if ( 'locked' === $field ) { | |
| 1034 | + if ( $snippet->set_field( $field, $value ) ) { | |
| 1035 | + $locked_value = $snippet->$field; | |
| 1036 | + } | |
| 1037 | + continue; | |
| 1038 | + } | |
| 731 | 1039 | |
| 732 | 1040 | if ( $snippet->set_field( $field, $value ) ) { |
| 733 | 1041 | $clean_fields[ $field ] = $snippet->$field; |
| 734 | 1042 | } |
| @@ -733,20 +1041,42 @@ | ||
| 733 | 1041 | $clean_fields[ $field ] = $snippet->$field; |
| 734 | 1042 | } |
| 735 | 1043 | } |
| 736 | 1044 | |
| 737 | - // Update the snippet in the database. | |
| 738 | - $wpdb->update( $table, $clean_fields, array( 'id' => $snippet->id ), null, array( '%d' ) ); | |
| 1045 | + // Update the snippet in the database (excluding locked). | |
| 1046 | + if ( ! empty( $clean_fields ) ) { | |
| 1047 | + $wpdb->update( $table, $clean_fields, array( 'id' => $snippet->id ), null, array( '%d' ) ); | |
| 1048 | + } | |
| 739 | 1049 | |
| 740 | - do_action( 'code_snippets/update_snippet', $snippet->id, $table ); | |
| 1050 | + // Save locked to wp_options if it was provided. | |
| 1051 | + if ( null !== $locked_value ) { | |
| 1052 | + set_snippet_locked( $snippet->id, $locked_value, $network ); | |
| 1053 | + } | |
| 1054 | + | |
| 741 | 1055 | clean_snippets_cache( $table ); |
| 1056 | + $updated = get_snippet( $snippet->id, $network ); | |
| 1057 | + if ( $updated->id ) { | |
| 1058 | + do_action( 'code_snippets/update_snippet', $updated, $table ); | |
| 1059 | + } | |
| 742 | 1060 | } |
| 743 | 1061 | |
| 744 | -function execute_snippet_from_flat_file( $code, $file, int $id = 0, bool $force = false ) { | |
| 1062 | +/** | |
| 1063 | + * Evaluate a snippet by loading it from the filesystem. | |
| 1064 | + * | |
| 1065 | + * @param string $code Snippet code. | |
| 1066 | + * @param string $file Snippet filename. | |
| 1067 | + * @param int $id Snippet ID. | |
| 1068 | + * @param bool $force Force snippet execution, even if save mode is active. | |
| 1069 | + * | |
| 1070 | + * @return bool|Exception|Throwable|null Code error if encountered during execution, or result of snippet execution otherwise. | |
| 1071 | + */ | |
| 1072 | +function execute_snippet_from_flat_file( string $code, string $file, int $id = 0, bool $force = false ) { | |
| 745 | 1073 | if ( ! is_file( $file ) ) { |
| 746 | - return execute_snippet( $code, $id, $force ); | |
| 1074 | + execute_snippet( $code, $id, $force ); | |
| 1075 | + return true; | |
| 747 | 1076 | } |
| 748 | 1077 | |
| 1078 | + /* @noinspection PhpUndefinedConstantInspection */ | |
| 749 | 1079 | if ( ! $force && defined( 'CODE_SNIPPETS_SAFE_MODE' ) && CODE_SNIPPETS_SAFE_MODE ) { |
| 750 | 1080 | return false; |
| 751 | 1081 | } |
| 752 | 1082 | |
| @@ -754,12 +1084,8 @@ | ||
| 754 | 1084 | |
| 755 | 1085 | try { |
| 756 | 1086 | require_once $file; |
| 757 | 1087 | $result = null; |
| 758 | - } catch ( ParseError $parse_error ) { | |
| 759 | - $result = $parse_error; | |
| 760 | - } catch ( Error $error ) { | |
| 761 | - $result = $error; | |
| 762 | 1088 | } catch ( Throwable $throwable ) { |
| 763 | 1089 | $result = $throwable; |
| 764 | 1090 | } |
| 765 | 1091 | |