← All changes
|
admin/section/class-convertkit-admin-section-oauth.php
+20
-3
3.3.3
→
3.4.6
View file →
| @@ -57,13 +57,31 @@ | ||
| 57 | 57 | if ( ! $this->on_settings_screen( 'general' ) ) { |
| 58 | 58 | return; |
| 59 | 59 | } |
| 60 | 60 | |
| 61 | - // Bail if no authorization code is included in the request. | |
| 61 | + // Bail if no authorization code is included in the request, as this isn't an OAuth callback. | |
| 62 | 62 | if ( ! filter_has_var( INPUT_GET, 'code' ) ) { |
| 63 | 63 | return; |
| 64 | 64 | } |
| 65 | 65 | |
| 66 | + // Bail if the user is not permitted to connect the Plugin to a Kit account. | |
| 67 | + if ( ! current_user_can( 'manage_options' ) ) { | |
| 68 | + return; | |
| 69 | + } | |
| 70 | + | |
| 71 | + // Redirect with an error if the nonce is missing or invalid. | |
| 72 | + $nonce = filter_input( INPUT_GET, 'nonce', FILTER_SANITIZE_FULL_SPECIAL_CHARS ); | |
| 73 | + if ( ! $nonce || ! wp_verify_nonce( sanitize_key( $nonce ), CONVERTKIT_NONCE_ACTION_OAUTH_CONNECT ) ) { | |
| 74 | + wp_safe_redirect( | |
| 75 | + convertkit_get_settings_link( | |
| 76 | + array( | |
| 77 | + 'error_description' => __( 'The Kit authorization request could not be verified. Please click Connect again.', 'convertkit' ), | |
| 78 | + ) | |
| 79 | + ) | |
| 80 | + ); | |
| 81 | + exit(); | |
| 82 | + } | |
| 83 | + | |
| 66 | 84 | // Sanitize token. |
| 67 | 85 | $authorization_code = filter_input( INPUT_GET, 'code', FILTER_SANITIZE_FULL_SPECIAL_CHARS ); |
| 68 | 86 | |
| 69 | 87 | // Exchange the authorization code and verifier for an access token. |
| @@ -115,10 +133,9 @@ | ||
| 115 | 133 | */ |
| 116 | 134 | public function render() { |
| 117 | 135 | |
| 118 | 136 | // Determine the OAuth URL to begin the authorization process. |
| 119 | - $api = new ConvertKit_API_V4( CONVERTKIT_OAUTH_CLIENT_ID, CONVERTKIT_OAUTH_CLIENT_REDIRECT_URI ); | |
| 120 | - $oauth_url = $api->get_oauth_url( admin_url( 'options-general.php?page=_wp_convertkit_settings' ), get_site_url() ); | |
| 137 | + $oauth_url = convertkit_get_oauth_url(); | |
| 121 | 138 | |
| 122 | 139 | /** |
| 123 | 140 | * Performs actions prior to rendering the settings form. |
| 124 | 141 | * |