PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 3.3.0
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v3.3.0
3.4.6 3.4.5 3.4.4 3.4.3 3.4.2 3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 All 199 releases
← All changes | admin/class-convertkit-admin-setup-wizard.php +90 -40 2.2.6 → 3.3.0 View file →
@@ -50,11 +50,11 @@
50 50 * The current step in the setup process the user is on.
51 51 *
52 52 * @since 1.9.8.4
53 53 *
54 - * @var int
54 + * @var string
55 55 */
56 - public $step = 1;
56 + public $step = 'start';
57 57
58 58 /**
59 59 * The programmatic name of the setup screen.
60 60 *
@@ -123,38 +123,27 @@
123 123 }
124 124
125 125 // Define actions to register the setup screen.
126 126 add_action( 'admin_menu', array( $this, 'register_screen' ) );
127 - add_action( 'admin_head', array( $this, 'hide_screen_from_menu' ) );
128 127 add_action( 'admin_init', array( $this, 'maybe_load_setup_screen' ) );
129 128
130 129 }
131 130
132 131 /**
133 - * Register the setup screen in WordPress' Dashboard, so that index.php?page={$this->page_name}
132 + * Register the wizard screen in WordPress' Dashboard, so that options.php?page={$this->page_name}
134 133 * does not 404 when in the WordPress Admin interface.
135 134 *
135 + * Ensures the WordPress user has the given required_capability to access this screen.
136 + *
136 137 * @since 1.9.8.4
137 138 */
138 139 public function register_screen() {
139 140
140 - add_dashboard_page( '', '', 'edit_posts', $this->page_name, '__return_false' );
141 + add_submenu_page( '', '', '', $this->required_capability, $this->page_name, '__return_false' );
141 142
142 143 }
143 144
144 145 /**
145 - * Hides the menu registered when register_screen() above is called, otherwise
146 - * we would have a blank submenu entry below the Dashboard menu.
147 - *
148 - * @since 1.9.8.4
149 - */
150 - public function hide_screen_from_menu() {
151 -
152 - remove_submenu_page( 'index.php', $this->page_name );
153 -
154 - }
155 -
156 - /**
157 146 * Loads the setup screen if the request URL is for this class
158 147 *
159 148 * @since 1.9.8.4
160 149 */
@@ -175,14 +164,24 @@
175 164 set_current_screen( $this->page_name );
176 165
177 166 // If the convertkit-modal parameter exists and is 1, set the flag to denote
178 167 // this wizard is served in a modal.
179 - if ( array_key_exists( 'convertkit-modal', $_REQUEST ) && $_REQUEST['convertkit-modal'] === '1' ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
168 + if ( filter_has_var( INPUT_GET, 'convertkit-modal' ) && filter_input( INPUT_GET, 'convertkit-modal', FILTER_SANITIZE_NUMBER_INT ) === '1' ) {
180 169 $this->is_modal = true;
181 170 }
182 171
172 + /**
173 + * Define the steps for the setup wizard.
174 + *
175 + * @since 3.1.8
176 + *
177 + * @param array $steps The steps for the setup wizard.
178 + * @return array The steps for the setup wizard.
179 + */
180 + $this->steps = apply_filters( 'convertkit_admin_setup_wizard_steps_' . $this->page_name, $this->steps );
181 +
183 182 // Define the step the user is on in the setup process.
184 - $this->step = ( isset( $_REQUEST['step'] ) ? absint( $_REQUEST['step'] ) : 1 ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
183 + $this->step = $this->get_current_step();
185 184
186 185 // Process any posted form data.
187 186 $this->process_form();
188 187
@@ -204,8 +203,68 @@
204 203
205 204 }
206 205
207 206 /**
207 + * Returns the current step in the setup process.
208 + *
209 + * @since 3.1.7
210 + *
211 + * @return string Current step.
212 + */
213 + public function get_current_step() {
214 +
215 + $step = ( filter_has_var( INPUT_GET, 'step' ) ? filter_input( INPUT_GET, 'step', FILTER_SANITIZE_FULL_SPECIAL_CHARS ) : 'start' );
216 +
217 + // Fallback to 'start' if the step is a registered step.
218 + if ( ! array_key_exists( $step, $this->steps ) ) {
219 + $step = 'start';
220 + }
221 +
222 + return $step;
223 +
224 + }
225 +
226 + /**
227 + * Get the number of the current step.
228 + *
229 + * @since 3.1.7
230 + *
231 + * @return int Step number.
232 + */
233 + public function get_current_step_number() {
234 +
235 + return array_search( $this->step, array_keys( $this->steps ), true ) + 1;
236 +
237 + }
238 +
239 + /**
240 + * Get the step by number.
241 + *
242 + * @since 3.1.7
243 + *
244 + * @param int $number Step number (1 based index).
245 + * @return string Step name/key.
246 + */
247 + public function get_step_key_by_number( $number ) {
248 +
249 + return array_keys( $this->steps )[ $number - 1 ];
250 +
251 + }
252 +
253 + /**
254 + * Get the total number of steps.
255 + *
256 + * @since 3.1.7
257 + *
258 + * @return int Total steps.
259 + */
260 + public function get_total_steps() {
261 +
262 + return count( $this->steps );
263 +
264 + }
265 +
266 + /**
208 267 * Process submitted form data for the given setup wizard name and current step.
209 268 *
210 269 * @since 1.9.8.4
211 270 */
@@ -210,23 +269,14 @@
210 269 * @since 1.9.8.4
211 270 */
212 271 private function process_form() {
213 272
214 - // Run security checks.
215 - if ( ! isset( $_POST['_wpnonce'] ) ) {
216 - return;
217 - }
218 - if ( ! wp_verify_nonce( sanitize_key( $_POST['_wpnonce'] ), $this->page_name ) ) {
219 - $this->error = __( 'Invalid nonce specified.', 'convertkit' );
220 - return;
221 - }
222 -
223 273 /**
224 274 * Process submitted form data for the given setup wizard name and current step.
225 275 *
226 276 * @since 1.9.8.4
227 277 *
228 - * @param int $step Current step number.
278 + * @param string $step Current step.
229 279 */
230 280 do_action( 'convertkit_admin_setup_wizard_process_form_' . $this->page_name, $this->step );
231 281
232 282 }
@@ -246,32 +296,32 @@
246 296 'page' => $this->page_name,
247 297 'convertkit-modal' => $this->is_modal(),
248 298 'step' => $this->step,
249 299 ),
250 - admin_url( 'index.php' )
300 + admin_url( 'options.php' )
251 301 );
252 302
253 303 // Define the previous step URL if we're not on the first or last step.
254 - if ( $this->step > 1 && $this->step < count( $this->steps ) ) {
304 + if ( $this->get_current_step_number() > 1 && $this->get_current_step_number() < $this->get_total_steps() ) {
255 305 $this->previous_step_url = add_query_arg(
256 306 array(
257 307 'page' => $this->page_name,
258 308 'convertkit-modal' => $this->is_modal(),
259 - 'step' => ( $this->step - 1 ),
309 + 'step' => $this->get_step_key_by_number( $this->get_current_step_number() - 1 ),
260 310 ),
261 - admin_url( 'index.php' )
311 + admin_url( 'options.php' )
262 312 );
263 313 }
264 314
265 315 // Define the next step URL if we're not on the last page.
266 - if ( $this->step < count( $this->steps ) ) {
316 + if ( $this->get_current_step_number() < $this->get_total_steps() ) {
267 317 $this->next_step_url = add_query_arg(
268 318 array(
269 319 'page' => $this->page_name,
270 320 'convertkit-modal' => $this->is_modal(),
271 - 'step' => ( $this->step + 1 ),
321 + 'step' => $this->get_step_key_by_number( $this->get_current_step_number() + 1 ),
272 322 ),
273 - admin_url( 'index.php' )
323 + admin_url( 'options.php' )
274 324 );
275 325 }
276 326
277 327 }
@@ -287,9 +337,9 @@
287 337 * Load any data into class variables for the given setup wizard name and current step.
288 338 *
289 339 * @since 1.9.8.4
290 340 *
291 - * @param int $step Current step number.
341 + * @param string $step Current step.
292 342 */
293 343 do_action( 'convertkit_admin_setup_wizard_load_screen_data_' . $this->page_name, $this->step );
294 344
295 345 }
@@ -305,9 +355,9 @@
305 355 convertkit_select2_enqueue_scripts();
306 356
307 357 // Enqueue JS.
308 358 wp_enqueue_script( 'convertkit-admin-preview-output', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/preview-output.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true );
309 - wp_enqueue_script( 'convertkit-admin-setup-wizard', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/setup-wizard.js', array( 'jquery' ), CONVERTKIT_PLUGIN_VERSION, true );
359 + wp_enqueue_script( 'convertkit-admin-setup-wizard', CONVERTKIT_PLUGIN_URL . 'resources/backend/js/setup-wizard.js', array(), CONVERTKIT_PLUGIN_VERSION, true );
310 360
311 361 }
312 362
313 363 /**
@@ -422,12 +472,12 @@
422 472 return false;
423 473 }
424 474
425 475 // Bail if we're not on the setup screen.
426 - if ( ! isset( $_GET['page'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
476 + if ( ! filter_has_var( INPUT_GET, 'page' ) ) {
427 477 return false;
428 478 }
429 - if ( sanitize_text_field( $_GET['page'] ) !== $this->page_name ) { // phpcs:ignore WordPress.Security.NonceVerification
479 + if ( filter_input( INPUT_GET, 'page', FILTER_SANITIZE_FULL_SPECIAL_CHARS ) !== $this->page_name ) {
430 480 return false;
431 481 }
432 482
433 483 return true;