PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 2.8.6
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v2.8.6
3.4.4 3.4.3 3.4.2 3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 2.2.9 2.3.0 All 197 releases
← All changes | includes/class-convertkit-subscriber.php +42 -19 2.2.6 → 2.8.6 View file →
@@ -33,16 +33,16 @@
33 33 */
34 34 public function get_subscriber_id() {
35 35
36 36 // If the subscriber ID is in the request URI, use it.
37 - if ( isset( $_REQUEST[ $this->key ] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
38 - return $this->validate_and_store_subscriber_id( sanitize_text_field( $_REQUEST[ $this->key ] ) ); // phpcs:ignore WordPress.Security.NonceVerification
37 + if ( filter_has_var( INPUT_GET, $this->key ) ) {
38 + return $this->validate_and_store_subscriber_id( filter_input( INPUT_GET, $this->key, FILTER_SANITIZE_FULL_SPECIAL_CHARS ) );
39 39 }
40 40
41 41 // If the subscriber ID is in a cookie, return it.
42 42 // For performance, we don't check that the subscriber ID exists every time, otherwise this would
43 43 // call the API on every page load.
44 - if ( isset( $_COOKIE[ $this->key ] ) ) {
44 + if ( isset( $_COOKIE[ $this->key ] ) && ! empty( $_COOKIE[ $this->key ] ) ) {
45 45 return $this->get_subscriber_id_from_cookie();
46 46 }
47 47
48 48 // If here, no subscriber ID exists.
@@ -62,20 +62,27 @@
62 62 public function validate_and_store_subscriber_id( $subscriber_id ) {
63 63
64 64 // Bail if the API hasn't been configured.
65 65 $settings = new ConvertKit_Settings();
66 - if ( ! $settings->has_api_key_and_secret() ) {
66 + if ( ! $settings->has_access_and_refresh_token() ) {
67 67 return new WP_Error(
68 68 'convertkit_subscriber_get_subscriber_id_from_request_error',
69 - __( 'API Key and Secret not configured in Plugin Settings.', 'convertkit' )
69 + __( 'Access Token not configured in Plugin Settings.', 'convertkit' )
70 70 );
71 71 }
72 72
73 73 // Initialize the API.
74 - $api = new ConvertKit_API( $settings->get_api_key(), $settings->get_api_secret(), $settings->debug_enabled() );
74 + $api = new ConvertKit_API_V4(
75 + CONVERTKIT_OAUTH_CLIENT_ID,
76 + CONVERTKIT_OAUTH_CLIENT_REDIRECT_URI,
77 + $settings->get_access_token(),
78 + $settings->get_refresh_token(),
79 + $settings->debug_enabled(),
80 + 'subscriber'
81 + );
75 82
76 83 // Get subscriber by ID, to ensure they exist.
77 - $subscriber = $api->get_subscriber_by_id( $subscriber_id );
84 + $subscriber = $api->get_subscriber( absint( $subscriber_id ) );
78 85
79 86 // Bail if no subscriber exists with the given subscriber ID, or an error occured.
80 87 if ( is_wp_error( $subscriber ) ) {
81 88 // Delete the cookie.
@@ -85,12 +92,12 @@
85 92 return $subscriber;
86 93 }
87 94
88 95 // Store the subscriber ID as a cookie.
89 - $this->set( $subscriber['id'] );
96 + $this->set( $subscriber['subscriber']['id'] );
90 97
91 98 // Return subscriber ID.
92 - return $subscriber['id'];
99 + return $subscriber['subscriber']['id'];
93 100
94 101 }
95 102
96 103 /**
@@ -105,35 +112,42 @@
105 112 public function validate_and_store_subscriber_email( $subscriber_email ) {
106 113
107 114 // Bail if the API hasn't been configured.
108 115 $settings = new ConvertKit_Settings();
109 - if ( ! $settings->has_api_key_and_secret() ) {
116 + if ( ! $settings->has_access_and_refresh_token() ) {
110 117 return new WP_Error(
111 118 'convertkit_subscriber_get_subscriber_id_from_request_error',
112 - __( 'API Key and Secret not configured in Plugin Settings.', 'convertkit' )
119 + __( 'Access Token not configured in Plugin Settings.', 'convertkit' )
113 120 );
114 121 }
115 122
116 123 // Initialize the API.
117 - $api = new ConvertKit_API( $settings->get_api_key(), $settings->get_api_secret(), $settings->debug_enabled() );
124 + $api = new ConvertKit_API_V4(
125 + CONVERTKIT_OAUTH_CLIENT_ID,
126 + CONVERTKIT_OAUTH_CLIENT_REDIRECT_URI,
127 + $settings->get_access_token(),
128 + $settings->get_refresh_token(),
129 + $settings->debug_enabled(),
130 + 'subscriber'
131 + );
118 132
119 133 // Get subscriber by email, to ensure they exist.
120 - $subscriber = $api->get_subscriber_by_email( $subscriber_email );
134 + $subscriber_id = $api->get_subscriber_id( $subscriber_email );
121 135
122 136 // Bail if no subscriber exists with the given subscriber ID, or an error occured.
123 - if ( is_wp_error( $subscriber ) ) {
137 + if ( is_wp_error( $subscriber_id ) ) {
124 138 // Delete the cookie.
125 139 $this->forget();
126 140
127 141 // Return error.
128 - return $subscriber;
142 + return $subscriber_id;
129 143 }
130 144
131 145 // Store the subscriber ID as a cookie.
132 - $this->set( $subscriber['id'] );
146 + $this->set( $subscriber_id );
133 147
134 148 // Return subscriber ID.
135 - return $subscriber['id'];
149 + return $subscriber_id;
136 150
137 151 }
138 152
139 153 /**
@@ -139,17 +153,24 @@
139 153 /**
140 154 * Gets the subscriber ID from the `ck_subscriber_id` cookie.
141 155 *
142 156 * @since 2.0.0
157 + *
158 + * @return string
143 159 */
144 160 private function get_subscriber_id_from_cookie() {
145 161
146 - return $_COOKIE[ $this->key ];
162 + if ( ! isset( $_COOKIE[ $this->key ] ) ) {
163 + return '';
164 + }
147 165
166 + return sanitize_text_field( wp_unslash( $_COOKIE[ $this->key ] ) );
167 +
148 168 }
149 169
150 170 /**
151 - * Stores the given subscriber ID in the `ck_subscriber_id` cookie.
171 + * Stores the given subscriber ID in the `ck_subscriber_id` cookie
172 + * and a prefixed `wordpress_ck_subscriber_id` cookie.
152 173 *
153 174 * @since 2.0.0
154 175 *
155 176 * @param int|string $subscriber_id Subscriber ID.
@@ -156,8 +177,9 @@
156 177 */
157 178 public function set( $subscriber_id ) {
158 179
159 180 setcookie( $this->key, (string) $subscriber_id, time() + ( 365 * DAY_IN_SECONDS ), '/' );
181 + setcookie( 'wordpress_' . $this->key, (string) $subscriber_id, time() + ( 365 * DAY_IN_SECONDS ), '/' );
160 182
161 183 }
162 184
163 185 /**
@@ -167,8 +189,9 @@
167 189 */
168 190 public function forget() {
169 191
170 192 setcookie( $this->key, '', time() - ( 365 * DAY_IN_SECONDS ), '/' );
193 + setcookie( 'wordpress_' . $this->key, '', time() - ( 365 * DAY_IN_SECONDS ), '/' );
171 194
172 195 }
173 196
174 197 }