← All changes
|
admin/setup-wizard/class-convertkit-admin-setup-wizard-plugin.php
+10
-5
3.4.2
→
3.4.6
View file →
| @@ -144,9 +144,9 @@ | ||
| 144 | 144 | 'start' => array( |
| 145 | 145 | 'name' => __( 'Connect', 'convertkit' ), |
| 146 | 146 | 'next_button' => array( |
| 147 | 147 | 'label' => __( 'Connect', 'convertkit' ), |
| 148 | - 'link' => $this->api->get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration' ), get_site_url() ), | |
| 148 | + 'link' => convertkit_get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration' ) ), | |
| 149 | 149 | ), |
| 150 | 150 | ), |
| 151 | 151 | 'configuration' => array( |
| 152 | 152 | 'name' => __( 'Configuration', 'convertkit' ), |
| @@ -311,8 +311,16 @@ | ||
| 311 | 311 | $this->error = sanitize_text_field( wp_unslash( $request['error_description'] ) ); |
| 312 | 312 | return; |
| 313 | 313 | } |
| 314 | 314 | |
| 315 | + // Show an error if the nonce is missing or invalid. | |
| 316 | + if ( ! array_key_exists( 'nonce', $request ) || ! wp_verify_nonce( sanitize_key( $request['nonce'] ), CONVERTKIT_NONCE_ACTION_OAUTH_CONNECT ) ) { | |
| 317 | + // Decrement the step. | |
| 318 | + $this->step = 'start'; | |
| 319 | + $this->error = __( 'The Kit authorization request could not be verified. Please click Connect again.', 'convertkit' ); | |
| 320 | + return; | |
| 321 | + } | |
| 322 | + | |
| 315 | 323 | // Sanitize token. |
| 316 | 324 | $authorization_code = sanitize_text_field( wp_unslash( $request['code'] ) ); |
| 317 | 325 | |
| 318 | 326 | // Exchange the authorization code and verifier for an access token. |
| @@ -349,11 +357,8 @@ | ||
| 349 | 357 | // If this wizard is being served in a modal window, change the flow. |
| 350 | 358 | if ( $this->is_modal() ) { |
| 351 | 359 | switch ( $step ) { |
| 352 | 360 | case 'start': |
| 353 | - // Setup API. | |
| 354 | - $api = new ConvertKit_API_V4( CONVERTKIT_OAUTH_CLIENT_ID, CONVERTKIT_OAUTH_CLIENT_REDIRECT_URI ); | |
| 355 | - | |
| 356 | 361 | // Permit wp_safe_redirect to redirect to app.kit.com. |
| 357 | 362 | add_filter( |
| 358 | 363 | 'allowed_redirect_hosts', |
| 359 | 364 | function ( $hosts ) { |
| @@ -368,9 +373,9 @@ | ||
| 368 | 373 | } |
| 369 | 374 | ); |
| 370 | 375 | |
| 371 | 376 | // Redirect to OAuth. |
| 372 | - wp_safe_redirect( $api->get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration&convertkit-modal=1' ), get_site_url() ) ); | |
| 377 | + wp_safe_redirect( convertkit_get_oauth_url( admin_url( 'options.php?page=convertkit-setup&step=configuration&convertkit-modal=1' ) ) ); | |
| 373 | 378 | die(); |
| 374 | 379 | |
| 375 | 380 | case 'configuration': |
| 376 | 381 | // Close modal. |