| @@ -46,11 +46,17 @@ | ||
| 46 | 46 | |
| 47 | 47 | // Get shortcodes. |
| 48 | 48 | $shortcodes = convertkit_get_shortcodes(); |
| 49 | 49 | |
| 50 | + // Bail if no shortcode or editor type is specified. | |
| 51 | + if ( ! isset( $_REQUEST['shortcode'] ) || ! isset( $_REQUEST['editor_type'] ) ) { | |
| 52 | + require_once CONVERTKIT_PLUGIN_PATH . '/views/backend/tinymce/modal-missing.php'; | |
| 53 | + die(); | |
| 54 | + } | |
| 55 | + | |
| 50 | 56 | // Get requested shortcode name. |
| 51 | - $shortcode_name = sanitize_text_field( $_REQUEST['shortcode'] ); | |
| 52 | - $editor_type = sanitize_text_field( $_REQUEST['editor_type'] ); | |
| 57 | + $shortcode_name = sanitize_text_field( wp_unslash( $_REQUEST['shortcode'] ) ); | |
| 58 | + $editor_type = sanitize_text_field( wp_unslash( $_REQUEST['editor_type'] ) ); | |
| 53 | 59 | |
| 54 | 60 | // If the shortcode is not registered, return a view in the modal to tell the user. |
| 55 | 61 | if ( ! isset( $shortcodes[ $shortcode_name ] ) ) { |
| 56 | 62 | require_once CONVERTKIT_PLUGIN_PATH . '/views/backend/tinymce/modal-missing.php'; |
| @@ -59,11 +65,11 @@ | ||
| 59 | 65 | |
| 60 | 66 | // Define shortcode. |
| 61 | 67 | $shortcode = $shortcodes[ $shortcode_name ]; |
| 62 | 68 | |
| 63 | - // Show a message in the modal if no API Key is specified. | |
| 64 | - if ( array_key_exists( 'has_api_key', $shortcode ) && ! $shortcode['has_api_key'] ) { | |
| 65 | - $notice = $shortcode['no_api_key']; | |
| 69 | + // Show a message in the modal if no Access Token is specified. | |
| 70 | + if ( array_key_exists( 'has_access_token', $shortcode ) && ! $shortcode['has_access_token'] ) { | |
| 71 | + $notice = $shortcode['no_access_token']; | |
| 66 | 72 | require_once CONVERTKIT_PLUGIN_PATH . '/views/backend/tinymce/modal-notice.php'; |
| 67 | 73 | die(); |
| 68 | 74 | } |
| 69 | 75 | |
| @@ -96,14 +102,14 @@ | ||
| 96 | 102 | // Get shortcodes. |
| 97 | 103 | $shortcodes = convertkit_get_shortcodes(); |
| 98 | 104 | |
| 99 | 105 | // Bail if no shortcode are available. |
| 100 | - if ( ! is_array( $shortcodes ) || ! count( $shortcodes ) ) { | |
| 106 | + if ( ! count( $shortcodes ) ) { | |
| 101 | 107 | return; |
| 102 | 108 | } |
| 103 | 109 | |
| 104 | 110 | // Enqueue Quicktag JS. |
| 105 | - wp_enqueue_script( 'convertkit-admin-quicktags', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/quicktags.js', array( 'jquery', 'quicktags' ), CONVERTKIT_PLUGIN_VERSION, true ); | |
| 111 | + wp_enqueue_script( 'convertkit-admin-quicktags', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/quicktags.js', array( 'quicktags' ), CONVERTKIT_PLUGIN_VERSION, true ); | |
| 106 | 112 | |
| 107 | 113 | // Make shortcodes available as convertkit_quicktags JS variable. |
| 108 | 114 | wp_localize_script( 'convertkit-admin-quicktags', 'convertkit_quicktags', $shortcodes ); |
| 109 | 115 | |
| @@ -118,12 +124,8 @@ | ||
| 118 | 124 | |
| 119 | 125 | // Enqueue Quicktag CSS. |
| 120 | 126 | wp_enqueue_style( 'convertkit-admin-quicktags', CONVERTKIT_PLUGIN_URL . 'resources/backend/css/quicktags.css', array(), CONVERTKIT_PLUGIN_VERSION ); |
| 121 | 127 | |
| 122 | - // Enqueue WordPress JS and CSS. | |
| 123 | - wp_enqueue_script( 'wp-color-picker' ); | |
| 124 | - wp_enqueue_style( 'wp-color-picker' ); | |
| 125 | - | |
| 126 | 128 | // Output Backbone View Template. |
| 127 | 129 | add_action( 'wp_print_footer_scripts', array( $this, 'output_quicktags_modal' ) ); |
| 128 | 130 | add_action( 'admin_print_footer_scripts', array( $this, 'output_quicktags_modal' ) ); |
| 129 | 131 | |
| @@ -142,16 +144,16 @@ | ||
| 142 | 144 | // Get shortcodes. |
| 143 | 145 | $shortcodes = convertkit_get_shortcodes(); |
| 144 | 146 | |
| 145 | 147 | // Bail if no shortcodes are available. |
| 146 | - if ( ! is_array( $shortcodes ) || ! count( $shortcodes ) ) { | |
| 148 | + if ( ! count( $shortcodes ) ) { | |
| 147 | 149 | return $plugins; |
| 148 | 150 | } |
| 149 | 151 | |
| 150 | 152 | // Enqueue TinyMCE CSS and JS. |
| 151 | 153 | wp_enqueue_script( 'convertkit-admin-tabs', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/tabs.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true ); |
| 152 | - wp_enqueue_script( 'convertkit-admin-tinymce', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/tinymce.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true ); | |
| 153 | - wp_enqueue_script( 'convertkit-admin-modal', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/modal.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true ); | |
| 154 | + wp_enqueue_script( 'convertkit-admin-tinymce', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/tinymce.js', array(), CONVERTKIT_PLUGIN_VERSION, true ); | |
| 155 | + wp_enqueue_script( 'convertkit-admin-modal', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/modal.js', array(), CONVERTKIT_PLUGIN_VERSION, true ); | |
| 154 | 156 | wp_enqueue_style( 'convertkit-admin-tinymce', CONVERTKIT_PLUGIN_URL . 'resources/backend/css/tinymce.css', array(), CONVERTKIT_PLUGIN_VERSION ); |
| 155 | 157 | |
| 156 | 158 | // Register JS variable convertkit_admin_tinymce.nonce for AJAX calls. |
| 157 | 159 | wp_localize_script( |
| @@ -187,9 +189,9 @@ | ||
| 187 | 189 | // Get shortcodes. |
| 188 | 190 | $shortcodes = convertkit_get_shortcodes(); |
| 189 | 191 | |
| 190 | 192 | // Bail if no shortcodes are available. |
| 191 | - if ( ! is_array( $shortcodes ) || ! count( $shortcodes ) ) { | |
| 193 | + if ( ! count( $shortcodes ) ) { | |
| 192 | 194 | return $buttons; |
| 193 | 195 | } |
| 194 | 196 | |
| 195 | 197 | // Register each Shortcode as a TinyMCE Button. |