PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 3.4.6
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v3.4.6
3.4.6 3.4.5 3.4.4 3.4.3 3.4.2 3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 All 199 releases
← All changes | admin/setup-wizard/class-convertkit-admin-setup-wizard-plugin.php +11 -6 3.3.3 → 3.4.6 View file →
@@ -71,9 +71,9 @@
71 71 * @since 2.3.2
72 72 *
73 73 * @var string
74 74 */
75 - public $required_capability = 'edit_posts';
75 + public $required_capability = 'manage_options';
76 76
77 77 /**
78 78 * The programmatic name for this wizard.
79 79 *
@@ -144,9 +144,9 @@
144 144 'start' => array(
145 145 'name' => __( 'Connect', 'convertkit' ),
146 146 'next_button' => array(
147 147 'label' => __( 'Connect', 'convertkit' ),
148 - 'link' => $this->api->get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration' ), get_site_url() ),
148 + 'link' => convertkit_get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration' ) ),
149 149 ),
150 150 ),
151 151 'configuration' => array(
152 152 'name' => __( 'Configuration', 'convertkit' ),
@@ -311,8 +311,16 @@
311 311 $this->error = sanitize_text_field( wp_unslash( $request['error_description'] ) );
312 312 return;
313 313 }
314 314
315 + // Show an error if the nonce is missing or invalid.
316 + if ( ! array_key_exists( 'nonce', $request ) || ! wp_verify_nonce( sanitize_key( $request['nonce'] ), CONVERTKIT_NONCE_ACTION_OAUTH_CONNECT ) ) {
317 + // Decrement the step.
318 + $this->step = 'start';
319 + $this->error = __( 'The Kit authorization request could not be verified. Please click Connect again.', 'convertkit' );
320 + return;
321 + }
322 +
315 323 // Sanitize token.
316 324 $authorization_code = sanitize_text_field( wp_unslash( $request['code'] ) );
317 325
318 326 // Exchange the authorization code and verifier for an access token.
@@ -349,11 +357,8 @@
349 357 // If this wizard is being served in a modal window, change the flow.
350 358 if ( $this->is_modal() ) {
351 359 switch ( $step ) {
352 360 case 'start':
353 - // Setup API.
354 - $api = new ConvertKit_API_V4( CONVERTKIT_OAUTH_CLIENT_ID, CONVERTKIT_OAUTH_CLIENT_REDIRECT_URI );
355 -
356 361 // Permit wp_safe_redirect to redirect to app.kit.com.
357 362 add_filter(
358 363 'allowed_redirect_hosts',
359 364 function ( $hosts ) {
@@ -368,9 +373,9 @@
368 373 }
369 374 );
370 375
371 376 // Redirect to OAuth.
372 - wp_safe_redirect( $api->get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration&convertkit-modal=1' ), get_site_url() ) );
377 + wp_safe_redirect( convertkit_get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration&convertkit-modal=1' ) ) );
373 378 die();
374 379
375 380 case 'configuration':
376 381 // Close modal.