PluginProbe
CookieAdmin – Cookie Consent Banner / 1.2.0
CookieAdmin – Cookie Consent Banner v1.2.0
1.2.3 1.2.2 1.2.1 1.2.0 1.1.9 trunk 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8
cookieadmin / includes / enduser.php

enduser.php in CookieAdmin – Cookie Consent Banner 1.2.0, at includes/enduser.php

231 lines 6.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace CookieAdmin;
4
5 if(!defined('COOKIEADMIN_VERSION') || !defined('ABSPATH')){
6 die('Hacking Attempt');
7 }
8
9 class Enduser{
10
11 static $http_cookies = array();
12 static $categorized_cookies = array();
13
14 static function enqueue_scripts(){
15 global $wpdb;
16
17 $view = get_option('cookieadmin_law', 'cookieadmin_gdpr');
18 $policy = cookieadmin_load_policy();
19 $table_name = esc_sql($wpdb->prefix . 'cookieadmin_cookies');
20 //cookieadmin_r_print($view);
21 //cookieadmin_r_print($policy);
22
23 if(!empty($policy) && !empty($view) && !cookieadmin_is_editor_mode()){
24
25 wp_enqueue_style('cookieadmin-style', COOKIEADMIN_PLUGIN_URL . 'assets/css/consent.css', [], COOKIEADMIN_VERSION);
26
27 $js_deps = [];
28 // Free consent.js is the base script from where the functionality gets triggered
29 // So we need to make sure the dependencies of free script gets loaded first
30 // Like the pro/consent.js is a dependency of the free one.
31 if(defined('COOKIEADMIN_PREMIUM')){
32 $js_deps[] = 'cookieadmin_pro_js';
33 }
34
35 wp_enqueue_script('cookieadmin_js', COOKIEADMIN_PLUGIN_URL . 'assets/js/consent.js', $js_deps, COOKIEADMIN_VERSION);
36
37 $policy[$view]['ajax_url'] = admin_url('admin-ajax.php');
38 $policy[$view]['nonce'] = wp_create_nonce('cookieadmin_js_nonce');
39 $policy[$view]['http_cookies'] = self::$http_cookies;
40 $policy[$view]['home_url'] = home_url();
41 $policy[$view]['plugin_url'] = COOKIEADMIN_URL;
42 $policy[$view]['is_pro'] = (defined('COOKIEADMIN_PREMIUM') ? COOKIEADMIN_PREMIUM : 0);
43 $policy[$view]['ssl'] = is_ssl();
44
45 $base_path = parse_url(home_url(), PHP_URL_PATH) ?: '/';
46 $base_path = ($base_path !== '/') ? rtrim($base_path, '/') . '/' : '/';
47
48 // Used for setting cookie
49 $policy[$view]['base_path'] = $base_path;
50
51 $policy[$view]['lang']['show_less'] = __('Show less', 'cookieadmin');
52 $policy[$view]['lang']['duration'] = __('Duration', 'cookieadmin');
53 $policy[$view]['lang']['session'] = __('Session', 'cookieadmin');
54 $policy[$view]['lang']['days'] = __('Days', 'cookieadmin');
55
56 // cookieadmin_r_print($policy);die();
57
58 $rows = $wpdb->get_results("SELECT cookie_name, category, expires, description, patterns FROM {$table_name}");
59 $cookie_data = array();
60
61 foreach ($rows as $row) {
62 $cookie_data[$row->cookie_name] = $row;
63 }
64
65 $policy[$view]['categorized_cookies'] = self::$categorized_cookies = $cookie_data;
66
67 wp_localize_script('cookieadmin_js', 'cookieadmin_policy', $policy[$view]);
68
69 }
70 }
71
72 /* static function cookieadmin_block_cookie_init_php(){
73
74 //New - To catch, remove and send cookies in WP enqueue
75 $http_cookies = array();
76 $headers = headers_list();
77
78 foreach($headers as $header) {
79
80 if (stripos(trim($header), 'Set-Cookie:') === 0) {
81 $header = trim(substr($header, strlen('Set-Cookie:')));
82 $name = trim(explode('=', $header)[0]);
83 $http_cookies[$name]['string'] = trim($header);
84 setcookie($name, '', time() - 999999, '/');
85 }
86 }
87
88 $http_cookies['cookieadmin_consent'] = ["string" => "cookieadmin_consent=CookieAdmin Cookie Initialization"];
89
90 self::$http_cookies = $http_cookies;
91 } */
92
93 static function block_scripts(){
94
95 if(wp_doing_ajax() || is_admin() || defined('REST_REQUEST') || defined('COOKIEADMIN_SCANNER') || cookieadmin_is_editor_mode()){
96 return;
97 }
98
99 $settings = get_option('cookieadmin_settings');
100
101 // If block scripts is disabled, we don't need to make any changes
102 if(empty($settings) || empty($settings['block_scripts'])){
103 return;
104 }
105
106 $view = get_option('cookieadmin_law', 'cookieadmin_gdpr');
107 $policy = cookieadmin_load_policy();
108 if(empty($policy) || empty($view)){
109 return;
110 }
111
112 ob_start([__CLASS__, 'update_tracking_scripts']);
113 }
114
115 static function update_tracking_scripts($html){
116
117 if(stripos($html, '<script') === false){
118 return $html;
119 }
120
121 if(empty(self::$categorized_cookies)){
122 return $html;
123 }
124
125 $cookieadmin_consent = isset($_COOKIE['cookieadmin_consent'])
126 ? json_decode(wp_unslash($_COOKIE['cookieadmin_consent']), true)
127 : [];
128
129 // Sanitizing cookies
130 array_walk( $cookieadmin_consent, function( $value, $key ) use ( &$cookieadmin_consent ) {
131 $sanitized_key = sanitize_key( $key );
132 $cookieadmin_consent[ $sanitized_key ] = sanitize_text_field($value);
133 } );
134
135 $html = preg_replace_callback(
136 '/<script\b([^>]*)>([\s\S]*?)<\/script>/i',
137 function($match) use ($cookieadmin_consent){
138 $attrs = $match[1];
139 $content = $match[2];
140 $full_tag = $match[0];
141
142 if(preg_match('/\btype\s*=\s*["\']text\/plain["\']/i', $attrs)){
143 return $full_tag;
144 }
145
146 if(preg_match('/\b(id|src)\s*=\s*["\'][^"\']*cookieadmin[^"\']*["\']/i', $attrs)){
147 return $full_tag;
148 }
149
150 if(preg_match('/\btype\s*=\s*["\']([^"\']+)["\']/i', $attrs, $type_match)){
151 $type = strtolower(trim($type_match[1]));
152 if($type !== 'text/javascript' && $type !== 'module'){
153 return $full_tag;
154 }
155 }
156
157 $src = '';
158 if(preg_match('/\bsrc\s*=\s*["\']([^"\']*)["\']/i', $attrs, $src_match)){
159 $src = $src_match[1];
160 }
161
162 $match_against = !empty($src) ? $src : trim($attrs . ' ' . $content);
163
164 if(empty($match_against)){
165 return $full_tag;
166 }
167
168 foreach (self::$categorized_cookies as $item) {
169 $category = !empty($item->category) ? strtolower($item->category) : '';
170 $patterns = !empty($item->patterns) ? json_decode($item->patterns, true) : '';
171
172 if(empty($patterns) || empty($category)){
173 continue;
174 }
175
176 foreach ($patterns as $pattern) {
177 if(strpos($match_against, $pattern) !== false){
178 if($category !== 'necessary' &&
179 (empty($cookieadmin_consent) ||
180 (!empty($cookieadmin_consent[$category]) && $cookieadmin_consent[$category] == 'false') ||
181 (!empty($cookieadmin_consent['reject']) && $cookieadmin_consent['reject'] == 'true')
182 )
183 ){
184 if($attrs === ''){
185 return '<script type="text/plain" data-cookieadmin-category="' . esc_attr($category) . '">' . $content . '</script>';
186 }
187 return '<script type="text/plain" data-cookieadmin-category="' . esc_attr($category) . '"' . $attrs . '>' . $content . '</script>';
188 }
189 }
190 }
191 }
192
193 return $full_tag;
194 },
195 $html
196 );
197
198 return $html;
199 }
200
201 static function cookieadmin_show_banner(){
202
203 $view = get_option('cookieadmin_law', 'cookieadmin_gdpr');
204 $policy = cookieadmin_load_policy();
205
206 $raw_template = cookieadmin_load_consent_template($policy[$view], $view);
207
208 if(!is_array($raw_template) || empty($raw_template)){
209 return false;
210 }
211
212 $templates = implode('', $raw_template);
213
214 $allowed_tags = cookieadmin_kses_allowed_html();
215
216 $templates = apply_filters('cookieadmin_after_banner', $templates);
217
218 // var_dump($policy[$view]);
219 echo wp_kses($templates, $allowed_tags);
220 }
221
222 static function cookieadmin_table_exists($table_name) {
223 global $wpdb;
224
225 $query = $wpdb->prepare("SHOW TABLES LIKE %s", $table_name);
226
227 return $wpdb->get_var($query) === $table_name;
228 }
229 }
230
231