PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 3.3.0
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v3.3.0
3.4.6 3.4.5 3.4.4 3.4.3 3.4.2 3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 All 199 releases
← All changes | admin/class-convertkit-admin-setup-wizard.php +144 -43 2.2.0 → 3.3.0 View file →
@@ -50,11 +50,11 @@
50 50 * The current step in the setup process the user is on.
51 51 *
52 52 * @since 1.9.8.4
53 53 *
54 - * @var int
54 + * @var string
55 55 */
56 - public $step = 1;
56 + public $step = 'start';
57 57
58 58 /**
59 59 * The programmatic name of the setup screen.
60 60 *
@@ -64,8 +64,18 @@
64 64 */
65 65 public $page_name = false;
66 66
67 67 /**
68 + * Whether the wizard is being served within a modal or
69 + * new window.
70 + *
71 + * @since 2.2.6
72 + *
73 + * @var bool
74 + */
75 + public $is_modal = false;
76 +
77 + /**
68 78 * The URL to take the user to when they click the Exit link.
69 79 *
70 80 * @since 1.9.8.4
71 81 *
@@ -113,38 +123,27 @@
113 123 }
114 124
115 125 // Define actions to register the setup screen.
116 126 add_action( 'admin_menu', array( $this, 'register_screen' ) );
117 - add_action( 'admin_head', array( $this, 'hide_screen_from_menu' ) );
118 127 add_action( 'admin_init', array( $this, 'maybe_load_setup_screen' ) );
119 128
120 129 }
121 130
122 131 /**
123 - * Register the setup screen in WordPress' Dashboard, so that index.php?page={$this->page_name}
132 + * Register the wizard screen in WordPress' Dashboard, so that options.php?page={$this->page_name}
124 133 * does not 404 when in the WordPress Admin interface.
125 134 *
135 + * Ensures the WordPress user has the given required_capability to access this screen.
136 + *
126 137 * @since 1.9.8.4
127 138 */
128 139 public function register_screen() {
129 140
130 - add_dashboard_page( '', '', 'edit_posts', $this->page_name, '__return_false' );
141 + add_submenu_page( '', '', '', $this->required_capability, $this->page_name, '__return_false' );
131 142
132 143 }
133 144
134 145 /**
135 - * Hides the menu registered when register_screen() above is called, otherwise
136 - * we would have a blank submenu entry below the Dashboard menu.
137 - *
138 - * @since 1.9.8.4
139 - */
140 - public function hide_screen_from_menu() {
141 -
142 - remove_submenu_page( 'index.php', $this->page_name );
143 -
144 - }
145 -
146 - /**
147 146 * Loads the setup screen if the request URL is for this class
148 147 *
149 148 * @since 1.9.8.4
150 149 */
@@ -163,10 +162,26 @@
163 162
164 163 // Define current screen, so that calls to get_current_screen() tell Plugins which screen is loaded.
165 164 set_current_screen( $this->page_name );
166 165
166 + // If the convertkit-modal parameter exists and is 1, set the flag to denote
167 + // this wizard is served in a modal.
168 + if ( filter_has_var( INPUT_GET, 'convertkit-modal' ) && filter_input( INPUT_GET, 'convertkit-modal', FILTER_SANITIZE_NUMBER_INT ) === '1' ) {
169 + $this->is_modal = true;
170 + }
171 +
172 + /**
173 + * Define the steps for the setup wizard.
174 + *
175 + * @since 3.1.8
176 + *
177 + * @param array $steps The steps for the setup wizard.
178 + * @return array The steps for the setup wizard.
179 + */
180 + $this->steps = apply_filters( 'convertkit_admin_setup_wizard_steps_' . $this->page_name, $this->steps );
181 +
167 182 // Define the step the user is on in the setup process.
168 - $this->step = ( isset( $_REQUEST['step'] ) ? absint( $_REQUEST['step'] ) : 1 ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
183 + $this->step = $this->get_current_step();
169 184
170 185 // Process any posted form data.
171 186 $this->process_form();
172 187
@@ -188,8 +203,68 @@
188 203
189 204 }
190 205
191 206 /**
207 + * Returns the current step in the setup process.
208 + *
209 + * @since 3.1.7
210 + *
211 + * @return string Current step.
212 + */
213 + public function get_current_step() {
214 +
215 + $step = ( filter_has_var( INPUT_GET, 'step' ) ? filter_input( INPUT_GET, 'step', FILTER_SANITIZE_FULL_SPECIAL_CHARS ) : 'start' );
216 +
217 + // Fallback to 'start' if the step is a registered step.
218 + if ( ! array_key_exists( $step, $this->steps ) ) {
219 + $step = 'start';
220 + }
221 +
222 + return $step;
223 +
224 + }
225 +
226 + /**
227 + * Get the number of the current step.
228 + *
229 + * @since 3.1.7
230 + *
231 + * @return int Step number.
232 + */
233 + public function get_current_step_number() {
234 +
235 + return array_search( $this->step, array_keys( $this->steps ), true ) + 1;
236 +
237 + }
238 +
239 + /**
240 + * Get the step by number.
241 + *
242 + * @since 3.1.7
243 + *
244 + * @param int $number Step number (1 based index).
245 + * @return string Step name/key.
246 + */
247 + public function get_step_key_by_number( $number ) {
248 +
249 + return array_keys( $this->steps )[ $number - 1 ];
250 +
251 + }
252 +
253 + /**
254 + * Get the total number of steps.
255 + *
256 + * @since 3.1.7
257 + *
258 + * @return int Total steps.
259 + */
260 + public function get_total_steps() {
261 +
262 + return count( $this->steps );
263 +
264 + }
265 +
266 + /**
192 267 * Process submitted form data for the given setup wizard name and current step.
193 268 *
194 269 * @since 1.9.8.4
195 270 */
@@ -194,23 +269,14 @@
194 269 * @since 1.9.8.4
195 270 */
196 271 private function process_form() {
197 272
198 - // Run security checks.
199 - if ( ! isset( $_POST['_wpnonce'] ) ) {
200 - return;
201 - }
202 - if ( ! wp_verify_nonce( sanitize_key( $_POST['_wpnonce'] ), $this->page_name ) ) {
203 - $this->error = __( 'Invalid nonce specified.', 'convertkit' );
204 - return;
205 - }
206 -
207 273 /**
208 274 * Process submitted form data for the given setup wizard name and current step.
209 275 *
210 276 * @since 1.9.8.4
211 277 *
212 - * @param int $step Current step number.
278 + * @param string $step Current step.
213 279 */
214 280 do_action( 'convertkit_admin_setup_wizard_process_form_' . $this->page_name, $this->step );
215 281
216 282 }
@@ -226,33 +292,36 @@
226 292
227 293 // Define the current step URL.
228 294 $this->current_step_url = add_query_arg(
229 295 array(
230 - 'page' => $this->page_name,
231 - 'step' => $this->step,
296 + 'page' => $this->page_name,
297 + 'convertkit-modal' => $this->is_modal(),
298 + 'step' => $this->step,
232 299 ),
233 - admin_url( 'index.php' )
300 + admin_url( 'options.php' )
234 301 );
235 302
236 303 // Define the previous step URL if we're not on the first or last step.
237 - if ( $this->step > 1 && $this->step < count( $this->steps ) ) {
304 + if ( $this->get_current_step_number() > 1 && $this->get_current_step_number() < $this->get_total_steps() ) {
238 305 $this->previous_step_url = add_query_arg(
239 306 array(
240 - 'page' => $this->page_name,
241 - 'step' => ( $this->step - 1 ),
307 + 'page' => $this->page_name,
308 + 'convertkit-modal' => $this->is_modal(),
309 + 'step' => $this->get_step_key_by_number( $this->get_current_step_number() - 1 ),
242 310 ),
243 - admin_url( 'index.php' )
311 + admin_url( 'options.php' )
244 312 );
245 313 }
246 314
247 315 // Define the next step URL if we're not on the last page.
248 - if ( $this->step < count( $this->steps ) ) {
316 + if ( $this->get_current_step_number() < $this->get_total_steps() ) {
249 317 $this->next_step_url = add_query_arg(
250 318 array(
251 - 'page' => $this->page_name,
252 - 'step' => ( $this->step + 1 ),
319 + 'page' => $this->page_name,
320 + 'convertkit-modal' => $this->is_modal(),
321 + 'step' => $this->get_step_key_by_number( $this->get_current_step_number() + 1 ),
253 322 ),
254 - admin_url( 'index.php' )
323 + admin_url( 'options.php' )
255 324 );
256 325 }
257 326
258 327 }
@@ -268,9 +337,9 @@
268 337 * Load any data into class variables for the given setup wizard name and current step.
269 338 *
270 339 * @since 1.9.8.4
271 340 *
272 - * @param int $step Current step number.
341 + * @param string $step Current step.
273 342 */
274 343 do_action( 'convertkit_admin_setup_wizard_load_screen_data_' . $this->page_name, $this->step );
275 344
276 345 }
@@ -286,9 +355,9 @@
286 355 convertkit_select2_enqueue_scripts();
287 356
288 357 // Enqueue JS.
289 358 wp_enqueue_script( 'convertkit-admin-preview-output', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/preview-output.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true );
290 - wp_enqueue_script( 'convertkit-admin-setup-wizard', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/setup-wizard.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true );
359 + wp_enqueue_script( 'convertkit-admin-setup-wizard', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/setup-wizard.js', array(), CONVERTKIT_PLUGIN_VERSION, true );
291 360
292 361 }
293 362
294 363 /**
@@ -357,8 +426,40 @@
357 426
358 427 }
359 428
360 429 /**
430 + * Whether this wizard is served in a modal window.
431 + *
432 + * @since 2.2.6
433 + *
434 + * @return bool
435 + */
436 + public function is_modal() {
437 +
438 + return $this->is_modal;
439 +
440 + }
441 +
442 + /**
443 + * Outputs HTML to close the current window, due to it being opened
444 + * by window.open().
445 + *
446 + * @since 2.2.6
447 + */
448 + public function maybe_close_modal() {
449 +
450 + // Sanity check we requested a modal.
451 + if ( ! $this->is_modal() ) {
452 + return;
453 + }
454 +
455 + // Load HTML to close the modal.
456 + include_once CONVERTKIT_PLUGIN_PATH . '/views/backend/setup-wizard/close-modal.php';
457 + exit;
458 +
459 + }
460 +
461 + /**
361 462 * Determines if the request is for the setup screen
362 463 *
363 464 * @since 1.9.8.4
364 465 *
@@ -371,12 +472,12 @@
371 472 return false;
372 473 }
373 474
374 475 // Bail if we're not on the setup screen.
375 - if ( ! isset( $_GET['page'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
476 + if ( ! filter_has_var( INPUT_GET, 'page' ) ) {
376 477 return false;
377 478 }
378 - if ( sanitize_text_field( $_GET['page'] ) !== $this->page_name ) { // phpcs:ignore WordPress.Security.NonceVerification
479 + if ( filter_input( INPUT_GET, 'page', FILTER_SANITIZE_FULL_SPECIAL_CHARS ) !== $this->page_name ) {
379 480 return false;
380 481 }
381 482
382 483 return true;