PluginProbe
CryptX / 4.2.1
CryptX v4.2.1
4.2.1 4.2.0 4.1.1 trunk 1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.9 2.0 2.1 2.2 2.3 2.3.1 2.3.2 2.3.3 2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 All 93 releases
← All changes | cryptx.php +350 -537 2.4.44.2.1 View file →
@@ -1,588 +1,401 @@
1 1 <?php
2 -/*
3 -Plugin Name: CryptX
4 -Plugin URI: http://weber-nrw.de/wordpress/cryptx/
5 -Description: No more SPAM by spiders scanning you site for email adresses. With CryptX you can hide all your email adresses, with and without a mailto-link, by converting them using javascript or UNICODE. Although you can choose to add a mailto-link to all unlinked email adresses with only one klick at the settings. That's great, isn't it?
6 -Version: 2.4.4
7 -Author: Ralf Weber
8 -Author URI: http://weber-nrw.de/
9 -*/
2 +/**
3 + * Plugin Name: CryptX
4 + * Plugin URI: https://wordpress.org/plugins/cryptx/
5 + * Description: CryptX encrypts email addresses in your posts, pages, comments, and text widgets to protect them from spam bots while keeping them readable for your visitors.
6 + * Version: 4.2.1
7 + * Requires at least: 6.7
8 + * Tested up to: 7.1
9 + * Requires PHP: 8.1
10 + * Author: Ralf Weber
11 + * Author URI: https://weber-nrw.de/
12 + * License: GPL v2 or later
13 + * License URI: https://www.gnu.org/licenses/gpl-2.0.html
14 + * Text Domain: cryptx
15 + *
16 + * CryptX is free software: you can redistribute it and/or modify
17 + * it under the terms of the GNU General Public License as published by
18 + * the Free Software Foundation, either version 2 of the License, or
19 + * any later version.
20 + *
21 + * CryptX is distributed in the hope that it will be useful,
22 + * but WITHOUT ANY WARRANTY; without even the implied warranty of
23 + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
24 + * GNU General Public License for more details.
25 + *
26 + * You should have received a copy of the GNU General Public License
27 + * along with CryptX. If not, see https://www.gnu.org/licenses/gpl-2.0.html.
28 + *
29 + * @package CryptX
30 + * @since 1.0.0
31 + */
10 32
11 -/////////////////////////////////////////////////////////////////////////////
12 -
13 -/**
14 -* @internal prevent from direct calls
15 -*/
33 +// Prevent direct access
16 34 if (!defined('ABSPATH')) {
17 - return ;
18 - }
35 + exit;
36 +}
19 37
20 -/**
21 -* @internal prevent from second inclusion
22 -*/
23 -if (!class_exists('cryptX')) {
38 +// Plugin constants
39 +define('CRYPTX_VERSION', '4.2.1');
40 +define('CRYPTX_PLUGIN_FILE', __FILE__);
41 +define('CRYPTX_PLUGIN_BASENAME', plugin_basename(__FILE__));
42 +define('CRYPTX_BASENAME', plugin_basename(__FILE__)); // Add this missing constant
43 +define('CRYPTX_DIR_PATH', plugin_dir_path(__FILE__));
44 +define('CRYPTX_DIR_URL', plugin_dir_url(__FILE__));
45 +define('CRYPTX_BASEFOLDER', dirname(CRYPTX_PLUGIN_BASENAME));
24 46
25 -/////////////////////////////////////////////////////////////////////////////
47 +// Minimum requirements. Keep these in sync with the plugin header above and
48 +// with "Requires at least" / "Requires PHP" in readme.txt. They are defined
49 +// once and used both for the check and for the notice, so the number shown to
50 +// the user cannot drift away from the number actually enforced.
51 +define('CRYPTX_MIN_PHP', '8.1');
52 +define('CRYPTX_MIN_WP', '6.7');
26 53
27 -load_plugin_textdomain('cryptx', PLUGINDIR . '/' . dirname(plugin_basename (__FILE__)) . '/languages');
28 -
29 -$cryptX_var = (array) get_option('cryptX');
30 -
31 54 /**
32 -* "CryptX" WordPress Plugin
33 -*
34 -* @author Ralf Weber <ralf@weber-nrw.de>
35 -* @license http://opensource.org/licenses/gpl-license.php GNU Public License
36 -*/
37 -Class cryptX {
55 + * Shows an admin notice to whoever is in a position to act on it.
56 + *
57 + * Registered on both admin_notices and network_admin_notices. Without the
58 + * second, a network administrator working in the network backend -- the only
59 + * person who can deactivate a network-activated plugin -- never saw that the
60 + * server runs too old a PHP, or that a class file is missing. The capability
61 + * differs per screen: on a site it is activate_plugins, in the network backend
62 + * manage_network_plugins, which a mere site administrator does not hold.
63 + *
64 + * @param string $message The message, already translated and unescaped.
65 + *
66 + * @return void
67 + */
68 +function cryptx_admin_notice(string $message): void
69 +{
70 + $render = static function () use ($message): void {
71 + $capability = is_network_admin() ? 'manage_network_plugins' : 'activate_plugins';
38 72
39 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
73 + if (!current_user_can($capability)) {
74 + return;
75 + }
40 76
41 - /**
42 - * Constructor
43 - *
44 - * This constructor attaches the needer plugin hook callbacks
45 - */
46 - function cryptX() {
77 + printf('<div class="notice notice-error"><p>%s</p></div>', esc_html($message));
78 + };
47 79
48 - global $cryptX_var;
80 + add_action('admin_notices', $render);
81 + add_action('network_admin_notices', $render);
82 +}
49 83
50 - // attach the converstion handlers
51 - //
52 - if (@$cryptX_var[theContent]) {
53 - $this->filter('the_content');
54 - }
55 - if (@$cryptX_var[theExcerpt]) {
56 - $this->filter('the_excerpt');
57 - }
58 - if (@$cryptX_var[commentText]) {
59 - $this->filter('comment_text');
60 - }
61 - if (@$cryptX_var[widgetText]) {
62 - $this->filter('widget_text');
63 - }
84 +if (version_compare(PHP_VERSION, CRYPTX_MIN_PHP, '<')) {
85 + cryptx_admin_notice(sprintf(
86 + /* translators: %1$s: Required PHP version, %2$s: Current PHP version */
87 + __('CryptX requires PHP version %1$s or higher. You are running version %2$s. Please update PHP.', 'cryptx'),
88 + CRYPTX_MIN_PHP,
89 + PHP_VERSION
90 + ));
91 + return;
92 +}
64 93
65 - // attach to admin menu
66 - //
67 - if (is_admin()) {
68 - add_action('admin_menu',
69 - array(&$this, 'menu')
70 - );
71 - }
94 +// WordPress version check
95 +global $wp_version;
96 +if (version_compare($wp_version, CRYPTX_MIN_WP, '<')) {
97 + cryptx_admin_notice(sprintf(
98 + /* translators: %1$s: Required WordPress version, %2$s: Current WordPress version */
99 + __('CryptX requires WordPress version %1$s or higher. You are running version %2$s. Please update WordPress.', 'cryptx'),
100 + CRYPTX_MIN_WP,
101 + $GLOBALS['wp_version']
102 + ));
103 + return;
104 +}
72 105
73 - // attach to plugin installation
74 - //
75 - add_action(
76 - 'activate_' . str_replace(
77 - DIRECTORY_SEPARATOR, '/',
78 - str_replace(
79 - realpath(ABSPATH . PLUGINDIR) . DIRECTORY_SEPARATOR,
80 - '', __FILE__
81 - )
82 - ),
83 - array(&$this, 'install')
84 - );
106 +// Autoloader for plugin classes
107 +spl_autoload_register(function ($class) {
108 + // Check if the class belongs to our namespace
109 + if (strpos($class, 'CryptX\\') !== 0) {
110 + return;
111 + }
85 112
86 - // attach javascript to Header
87 - //
88 - if (@$cryptX_var[java]) {
89 - add_action(
90 - 'wp_head',
91 - array(&$this, 'header')
92 - );
93 - }
113 + // Remove namespace prefix
114 + $class = substr($class, 7);
94 115
95 - add_action('admin_menu',
96 - array(&$this, 'cryptx_meta_box')
97 - );
116 + // Convert namespace separators to directory separators
117 + $class = str_replace('\\', DIRECTORY_SEPARATOR, $class);
98 118
99 - add_action('wp_insert_post',
100 - array(&$this, 'cryptx_insert_post')
101 - );
102 - add_action('wp_update_post',
103 - array(&$this, 'cryptx_insert_post')
104 - );
119 + // Build the full path
120 + $file = CRYPTX_DIR_PATH . 'classes' . DIRECTORY_SEPARATOR . $class . '.php';
105 121
106 - } // End function
122 + // Include the file if it exists
123 + if (file_exists($file)) {
124 + require_once $file;
125 + }
126 +});
107 127
108 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
128 +// The settings screen posts nothing: it talks to the REST routes in
129 +// CryptX\Admin\RestController, which carry their own capability check and are
130 +// covered by WordPress' REST nonce. The global cryptx_nonce_check() that used
131 +// to sit here guarded $_POST['cryptX_var'], a key nothing has sent since the
132 +// old settings form was removed in 4.1.0 -- a dead guard next to a live one is
133 +// a trap for whoever wires up the next form.
109 134
110 - function filter($apply)
111 - {
112 - global $cryptX_var, $shortcode_tags;
135 +// Initialize the plugin
136 +add_action('plugins_loaded', function() {
137 + // Check if all required classes can be loaded
138 + $requiredClasses = [
139 + 'CryptX\\CryptX',
140 + 'CryptX\\Config',
141 + 'CryptX\\SecureEncryption',
142 + 'CryptX\\Exposure',
143 + 'CryptX\\Block',
144 + 'CryptX\\ImageToken',
145 + 'CryptX\\Admin\\NetworkDefaults',
146 + 'CryptX\\Admin\\SettingsPage',
147 + 'CryptX\\Admin\\SettingsSchema',
148 + 'CryptX\\Admin\\RestController',
149 + 'CryptX\\Admin\\SiteHealth',
150 + ];
113 151
114 - if (@$cryptX_var[autolink]) {
115 - add_filter($apply, array(&$this, 'autolink'), 5);
116 - }
152 + $missingClasses = [];
153 + foreach ($requiredClasses as $class) {
154 + if (!class_exists($class)) {
155 + $missingClasses[] = $class;
156 + }
157 + }
117 158
118 - if (!empty($shortcode_tags) || is_array($shortcode_tags)) {
119 - add_filter($apply, array(&$this, 'autolink'), 11);
120 - }
159 + if (!empty($missingClasses)) {
160 + cryptx_admin_notice(
161 + __('CryptX: Missing required classes: ', 'cryptx') . implode(', ', $missingClasses)
162 + );
163 + return;
164 + }
121 165
122 - add_filter($apply, array($this, 'encryptx'), 12);
123 - add_filter($apply, array($this, 'linktext'), 13);
124 - }
166 + // Initialize the main plugin class
167 + try {
168 + $cryptx_instance = CryptX\CryptX::get_instance();
169 + $cryptx_instance->startCryptX();
170 + cryptx_register_action_links();
125 171
126 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
172 + // Guarded here as well as inside register(), and deliberately not
173 + // listed in $requiredClasses above. Both of those would load the file
174 + // on every single front-end and admin request -- class_exists() runs
175 + // the autoloader, and so does a static call -- to register commands
176 + // that only exist under WP-CLI.
177 + //
178 + // class_exists() is still asked so that a package missing the file
179 + // cannot raise a fatal Error, which catch (Exception) below would not
180 + // have caught. It buys no notice: the commands are then simply absent.
181 + // That is the right silence -- nothing a visitor or an administrator
182 + // sees depends on them.
183 + if (defined('WP_CLI') && WP_CLI && class_exists('CryptX\Cli')) {
184 + CryptX\Cli::register();
185 + }
186 + } catch (Exception $e) {
187 + cryptx_admin_notice(
188 + __('CryptX initialization failed: ', 'cryptx') . $e->getMessage()
189 + );
190 + }
191 +});
127 192
193 +/**
194 + * Runs a callback once for every site of the network, in batches.
195 + *
196 + * get_sites() without a limit pulls the whole network into memory, and a
197 + * network can have thousands of sites. Same construction as uninstall.php,
198 + * deliberately: the two do the same job at opposite ends of the plugin's life,
199 + * and one of them being cleverer than the other only makes both harder to
200 + * trust.
201 + *
202 + * On a single site the callback simply runs once.
203 + *
204 + * @param callable $callback Receives nothing; runs with the site switched in.
205 + *
206 + * @return void
207 + */
208 +function cryptx_for_each_site(callable $callback): void
209 +{
210 + if (!is_multisite()) {
211 + $callback();
128 212
129 - function linktext($content)
130 - {
131 - global $post;
132 - $cryptxoff = false;
133 - $cryptxoffmeta = get_post_meta($post->ID,'cryptxoff',true);
134 - if ($cryptxoffmeta == "true") {
135 - $cryptxoff = true;
136 - }
137 - if ($cryptxoff == false) {
138 - $content = preg_replace_callback("/([_a-zA-Z0-9-]+(\.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(\.[a-zA-Z0-9-]+)*(\.[a-zA-Z]{2,}))/i", array(get_class($this), '_Linktext'), $content );
139 - }
140 - return $content;
141 - }
213 + return;
214 + }
142 215
143 - function _linktext($Match)
144 - {
145 - global $cryptX_var;
146 - switch ($cryptX_var[opt_linktext]) {
216 + $batch_size = 100;
217 + $offset = 0;
147 218
148 - case 1: // alternative text for mail link
149 - $linktext = $cryptX_var[alt_linktext];
150 - break;
219 + do {
220 + $site_ids = get_sites([
221 + 'fields' => 'ids',
222 + 'number' => $batch_size,
223 + 'offset' => $offset,
224 + 'orderby' => 'id',
225 + 'update_site_meta_cache' => false,
226 + ]);
151 227
152 - case 2: // alternative image for mail link
153 - $linktext = "<img src=\"" . $cryptX_var[alt_linkimage] . "\" class=\"cryptxImage\" alt=\"" . $cryptX_var[alt_linkimage_title] . "\" title=\"" . $cryptX_var[alt_linkimage_title] . "\">";
154 - break;
228 + foreach ($site_ids as $site_id) {
229 + switch_to_blog($site_id);
155 230
156 - case 3: // uploaded image for mail link
157 - $imgurl = "/" . PLUGINDIR . "/" . dirname(plugin_basename (__FILE__)) . "/images/" . $cryptX_var[alt_uploadedimage];
158 - $linktext = "<img src=\"" . $imgurl . "\" class=\"cryptxImage\" alt=\"" . $cryptX_var[http_linkimage_title] . "\" title=\"" . $cryptX_var[http_linkimage_title] . "\">";
159 - break;
231 + // finally, so a failing callback does not leave the blog stack
232 + // switched for whatever runs next. It does not keep the loop
233 + // going: an exception still travels upwards and the remaining
234 + // sites are skipped. Catching it here would hide a broken site
235 + // instead, and that is a trade to make deliberately, not in
236 + // passing.
237 + try {
238 + $callback();
239 + } finally {
240 + restore_current_blog();
241 + }
242 + }
160 243
161 - case 4: // text scrambled by antispambot
162 - $linktext = antispambot($Match[1]);
163 - break;
244 + $offset += $batch_size;
245 + } while (count($site_ids) === $batch_size);
246 +}
164 247
165 - default:
166 - $linktext = str_replace( "@", $cryptX_var[at], $Match[1]);
167 - $linktext = str_replace( ".", $cryptX_var[dot], $linktext);
248 +/**
249 + * Removes the plugin's transients from the site that is currently switched in.
250 + *
251 + * @return void
252 + */
253 +function cryptx_delete_transients(): void
254 +{
255 + global $wpdb;
168 256
169 - }
170 - return $linktext;
171 - }
257 + // The LIKE patterns run through $wpdb->esc_like() and $wpdb->prepare().
258 + // No user input is involved here, so this is not a hole, but "_" is a
259 + // single-character wildcard in LIKE: unescaped, '_transient_cryptx_%' also
260 + // matches names like 'Xtransient1cryptxZ...' belonging to other plugins.
261 + // esc_like() turns those underscores into literal ones. The table name is
262 + // an identifier, not a value, and therefore must stay outside prepare().
263 + $transientLike = $wpdb->esc_like('_transient_cryptx_') . '%';
264 + $transientTimeoutLike = $wpdb->esc_like('_transient_timeout_cryptx_') . '%';
172 265
173 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
266 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
267 + $wpdb->query($wpdb->prepare("DELETE FROM {$wpdb->options} WHERE option_name LIKE %s", $transientLike));
268 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
269 + $wpdb->query($wpdb->prepare("DELETE FROM {$wpdb->options} WHERE option_name LIKE %s", $transientTimeoutLike));
270 +}
174 271
175 - function _dirImages()
176 - {
177 - $dir = $_SERVER["DOCUMENT_ROOT"].'/'.PLUGINDIR.'/'.dirname(plugin_basename (__FILE__)).'/images';
178 - $fh = opendir($dir); //Verzeichnis
179 - $verzeichnisinhalt = array();
180 - while (true == ($file = readdir($fh)))
181 - {
182 - if ((substr(strtolower($file), -3)=="jpg") or (substr(strtolower($file), -3)=="gif"))
183 - {
184 - $verzeichnisinhalt[] = $file;
185 - }
186 - }
187 - return $verzeichnisinhalt;
188 - }
272 +/**
273 + * Sets up the plugin's options for the site that is currently switched in.
274 + *
275 + * @return void
276 + */
277 +function cryptx_install_site(): void
278 +{
279 + if (!class_exists('CryptX\\CryptX')) {
280 + return;
281 + }
189 282
190 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
283 + CryptX\CryptX::get_instance()->installCryptX();
284 +}
191 285
192 - function encryptx($content)
193 - {
194 - global $post;
195 - $cryptxoff = false;
196 - $cryptxoffmeta = get_post_meta($post->ID,'cryptxoff',true);
197 - if ($cryptxoffmeta == "true") {
198 - $cryptxoff = true;
199 - }
200 - if ($cryptxoff == false) {
201 - $content = preg_replace_callback('/<a (.*?)(href=("|\')mailto:(.*?)("|\')(.*?)|)>(.*?)<\/a>/i', array(get_class($this), 'mailtocrypt'), $content );
202 - }
203 - return $content;
204 - }
286 +// Activation.
287 +//
288 +// $network_wide is true when someone ticks "Network Activate". WordPress then
289 +// fires this hook exactly once, not once per site -- so without the loop, every
290 +// site but the current one is left without its stored options and, more to the
291 +// point, without the one-time migration of the pre-4.0 "cryptxoff" post meta.
292 +// The plugin still works there, because the defaults fill in, but a site that
293 +// carried excluded posts from an old version would silently lose them.
294 +register_activation_hook(__FILE__, function ($network_wide = false) {
295 + if ($network_wide) {
296 + cryptx_for_each_site('cryptx_install_site');
297 + } else {
298 + cryptx_install_site();
299 + }
205 300
206 - function mailtocrypt($Match)
207 - {
208 - global $cryptX_var;
209 - $return = $Match[0];
210 - $mailto = "mailto:" . $Match[4];
211 - if (@$cryptX_var[java]) {
212 - $crypt = '';
213 - $ascii = 0;
214 - for ($i = 0; $i < strlen( $Match[4] ); $i++) {
215 - $ascii = ord ( substr ( $Match[4], $i ) );
216 - if (8364 <= $char) {
217 - $ascii = 128;
218 - }
219 - $crypt .= chr($ascii + 1);
220 - }
221 - $javascript="javascript:DeCryptX('" . $crypt . "')";
222 - $return = str_replace( "mailto:".$Match[4], $javascript, $return);
223 - } else {
224 - $return = str_replace( $mailto, antispambot($mailto), $return);
225 - }
226 - return $return;
227 - }
301 + flush_rewrite_rules();
302 +});
228 303
304 +// Deactivation. Same reason, other direction: the transients of every site but
305 +// the current one used to survive a network deactivation.
306 +register_deactivation_hook(__FILE__, function ($network_wide = false) {
307 + if ($network_wide) {
308 + cryptx_for_each_site('cryptx_delete_transients');
309 + } else {
310 + cryptx_delete_transients();
311 + }
312 +});
229 313
230 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
314 +// A site created while the plugin is network-active gets the same treatment as
315 +// one that existed at activation time. Without this the new site works -- the
316 +// defaults see to that -- but nothing is ever written until someone saves, and
317 +// the behaviour differs from every other site in the network for no reason
318 +// anybody could see.
319 +add_action('wp_initialize_site', function ($site) {
320 + // The network option directly, not is_plugin_active_for_network(): that
321 + // lives in wp-admin/includes/plugin.php, which is not loaded when a site is
322 + // created over the REST API or WP-CLI -- exactly the paths that create sites
323 + // in bulk.
324 + $network_active = get_site_option('active_sitewide_plugins', []);
231 325
232 - function autolink($content) {
326 + if (!isset($network_active[CRYPTX_PLUGIN_BASENAME])) {
327 + return;
328 + }
233 329
234 - $src[]="/([\s])([_a-zA-Z0-9-]+(\.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(\.[a-zA-Z0-9-]+)*(\.[a-zA-Z]{2,}))/si";
235 - $src[]="/(>)([_a-zA-Z0-9-]+(\.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(\.[a-zA-Z0-9-]+)*(\.[a-zA-Z]{2,}))(<)/si";
236 - $src[]="/(>)([_a-zA-Z0-9-]+(\.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(\.[a-zA-Z0-9-]+)*(\.[a-zA-Z]{2,}))([\s])/si";
237 - $src[]="/([\s])([_a-zA-Z0-9-]+(\.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(\.[a-zA-Z0-9-]+)*(\.[a-zA-Z]{2,}))(<)/si";
238 - $src[]="/^([_a-zA-Z0-9-]+(\.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(\.[a-zA-Z0-9-]+)*(\.[a-zA-Z]{2,}))/si";
239 - $src[]="/(<a[^>]*>)<a[^>]*>/";
240 - $src[]="/(<\/A>)<\/A>/i";
330 + $site_id = is_object($site) ? (int) $site->blog_id : (int) $site;
241 331
242 - $tar[]="\\1<a href=\"mailto:\\2\">\\2</a>";
243 - $tar[]="\\1<a href=\"mailto:\\2\">\\2</a>\\6";
244 - $tar[]="\\1<a href=\"mailto:\\2\">\\2</a>\\6";
245 - $tar[]="\\1<a href=\"mailto:\\2\">\\2</a>\\6";
246 - $tar[]="<a href=\"mailto:\\0\">\\0</a>";
247 - $tar[]="\\1";
248 - $tar[]="\\1";
332 + switch_to_blog($site_id);
333 + cryptx_install_site();
334 + restore_current_blog();
335 +}, 20);
249 336
250 - $content = preg_replace($src,$tar,$content);
337 +// Add plugin action links.
338 +//
339 +// Registered inside the successful-initialisation path on purpose, not at the
340 +// top level of this file. It refers to a class constant, and the plugins screen
341 +// is exactly where someone goes to switch off a plugin whose class files are
342 +// missing -- a fatal error there would take away the only lever they have.
343 +// A plugin that did not initialise has no settings page to link to anyway.
344 +function cryptx_register_action_links(): void
345 +{
346 + add_filter('plugin_action_links_' . CRYPTX_PLUGIN_BASENAME, function ($links) {
347 + $settings_link = '<a href="' .
348 + esc_url(admin_url('options-general.php?page=' . CryptX\Admin\SettingsPage::MENU_SLUG)) .
349 + '">' . esc_html__('Settings', 'cryptx') . '</a>';
350 + array_unshift($links, $settings_link);
251 351
252 - return $content;
253 - }
352 + return $links;
353 + });
354 +}
254 355
255 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
356 +/**
357 + * Encrypts the given content using the CryptX library and wraps it with a shortcode.
358 + *
359 + * @param string $content The content to be encrypted.
360 + * @param array|null $args Optional arguments to customize the encryption process.
361 + *
362 + * @return string The encrypted content wrapped in the appropriate shortcode.
363 + */
364 +if (!function_exists('cryptx_encrypt')) {
365 + function cryptx_encrypt(string $content, ?array $args = []): string
366 + {
367 + $cryptXInstance = Cryptx\CryptX::get_instance();
368 + // $attributesString contains the escaped (esc_attr()) shortcode attributes from $args
369 + // The signature allows null, convertArrayToArgumentString() does not.
370 + $attributesString = $cryptXInstance->convertArrayToArgumentString($args ?? []);
256 371
372 + // wp_kses_post() and not esc_html(): the caller passes content, and
373 + // content in WordPress may carry markup. esc_html() turned a "<br>" in
374 + // a theme field into a visible "&lt;br&gt;" -- reported in the support
375 + // forum, and worked around there with html_entity_decode(), which
376 + // undoes the plugin's own protection in the Unicode and entity modes.
377 + // wp_kses_post keeps what a post may contain and drops the rest.
378 + $shortcode = '[cryptx' . $attributesString . ']' . wp_kses_post($content) . '[/cryptx]';
257 379
258 - function install() {
259 - add_option(
260 - 'cryptX',
261 - array(
262 - 'at' => ' [at] ',
263 - 'dot' => ' [dot] ',
264 - 'theContent' => 1,
265 - 'theExcerpt' => 0,
266 - 'commentText' => 1,
267 - 'widgetText' => 0,
268 - 'java' => 1,
269 - 'opt_linktext' => 0,
270 - )
271 - );
272 - }
273 -
274 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
275 -
276 - /**
277 - * Attach the menu page to the `Options` tab
278 - */
279 - function header()
280 - {
281 - $cryptX_script.= "<script type=\"text/javascript\" src=\"" . get_option('siteurl') . '/' . PLUGINDIR . '/' . dirname(plugin_basename (__FILE__)) . "/js/cryptx.js\"></script>\n";
282 - print($cryptX_script);
283 - }
284 -
285 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
286 -
287 -
288 - function cryptx_meta() {
289 - global $post;
290 - $cryptxoff = false;
291 - $cryptxoffmeta = get_post_meta($post->ID,'cryptxoff',true);
292 - if ($cryptxoffmeta == "true") {
293 - $cryptxoff = true;
294 - }
295 - ?>
296 - <input type="checkbox" name="cryptxoff" <?php if ($cryptxoff) { echo 'checked="checked"'; } ?>/> Disable CryptX
297 - <?php
298 - }
299 -
300 - function cryptx_option() {
301 - global $post;
302 - $cryptxoff = false;
303 - $cryptxoffmeta = get_post_meta($post->ID,'cryptxoff',true);
304 - if ($cryptxoffmeta == "true") {
305 - $cryptxoff = true;
306 - }
307 - if ( current_user_can('edit_posts') ) { ?>
308 - <fieldset id="cryptxoption" class="dbx-box">
309 - <h3 class="dbx-handle">CryptX</h3>
310 - <div class="dbx-content">
311 - <input type="checkbox" name="cryptxon" <?php if ($cryptxoff) { echo 'checked="checked"'; } ?>/> CryptX disabled?
312 - </div>
313 - </fieldset>
314 - <?php
315 - }
316 - }
317 -
318 - function cryptx_meta_box() {
319 - // Check whether the 2.5 function add_meta_box exists, and if it doesn't use 2.3 functions.
320 - if ( function_exists('add_meta_box') ) {
321 - add_meta_box('cryptx','CryptX', array(&$this, 'cryptx_meta'),'post');
322 - add_meta_box('cryptx','CryptX', array(&$this, 'cryptx_meta'),'page');
323 - } else {
324 - add_action('dbx_post_sidebar', array(&$this, 'cryptx_option'));
325 - add_action('dbx_page_sidebar', array(&$this, 'cryptx_option'));
326 - }
327 - }
328 -
329 - //add_action('admin_menu', 'cryptx_meta_box');
330 -
331 - function cryptx_insert_post($pID) {
332 - if (isset($_POST['cryptxoff'])) {
333 - add_post_meta($pID,'cryptxoff',"true", true) or update_post_meta($pID, 'cryptxoff', "true");
334 - } else {
335 - add_post_meta($pID,'cryptxoff',"false", true) or update_post_meta($pID, 'cryptxoff', "false");
336 - }
337 - }
338 - //add_action('wp_insert_post', array(&$this, 'cryptx_insert_post'));
339 -
340 -
341 -
342 -
343 - /**
344 - * Attach the menu page to the `Options` tab
345 - */
346 - function menu() {
347 - add_options_page(
348 - 'CryptX',
349 - (version_compare($GLOBALS['wp_version'], '2.6.999', '>') ? '<img src="' .@plugins_url('cryptx/icon.png'). '" width="10" height="10" alt="CryptX Icon" />' : ''). 'CryptX',
350 - 9,
351 - __FILE__,
352 - array(
353 - $this,
354 - '_submenu'
355 - )
356 - );
357 - }
358 -
359 - /**
360 - * Handles and renders the menu page
361 - */
362 - function _submenu() {
363 - global $cryptX_var;
364 -
365 - if (isset($_POST) && !empty($_POST)) {
366 - if (function_exists('current_user_can') === true && (current_user_can('manage_options') === false || current_user_can('edit_plugins') === false)) {
367 - wp_die("You don't have permission to access!");
368 - }
369 - check_admin_referer('cryptX');
370 - update_option( 'cryptX', $_POST['cryptX_var']);
371 - $cryptX_var = (array) get_option('cryptX'); // reread Options
372 - ?>
373 - <div id="message" class="updated fade">
374 - <p><strong><?php _e('Settings saved.') ?></strong></p>
375 - </div>
376 - <?php } ?>
377 -
378 - <div class="wrap">
379 - <?php if (version_compare($GLOBALS['wp_version'], '2.6.999', '>')) { ?>
380 - <div class="icon32" style="background: url(<?php echo @plugins_url('cryptx/icon32.png') ?>) no-repeat"><br /></div>
381 - <?php } ?>
382 - <h2>CryptX</h2>
383 -
384 - <form method="post" action="">
385 -
386 - <?php wp_nonce_field('cryptX') ?>
387 -
388 - <div id="poststuff" class="ui-sortable">
389 - <div class="postbox">
390 -
391 - <h3><?php _e("Presentation",'cryptx'); ?></h3>
392 -
393 - <div class="inside">
394 - <table class="form-table">
395 - <tr valign="top">
396 - <td><input name="cryptX_var[opt_linktext]" type="radio" id="opt_linktext" value="0" <?php echo ($cryptX_var[opt_linktext] == 0) ? 'checked="checked"' : ''; ?> /></td>
397 - <th scope="row"><label for="cryptX_var[at]"><?php _e("Replacement for '@'",'cryptx'); ?></label></th>
398 - <td><input name="cryptX_var[at]" value="<?php echo $cryptX_var[at]; ?>" type="text" class="regular-text" /></td>
399 - </tr>
400 - <tr valign="top">
401 - <td>&nbsp;</td>
402 - <th scope="row"><label for="cryptX_var[dot]"><?php _e("Replacement for '.'",'cryptx'); ?></label></th>
403 - <td><input name="cryptX_var[dot]" value="<?php echo $cryptX_var[dot]; ?>" type="text" class="regular-text" /></td>
404 - </tr>
405 - <tr valign="top">
406 - <td scope="row"><input type="radio" name="cryptX_var[opt_linktext]" id="opt_linktext2" value="1" <?php echo ($cryptX_var[opt_linktext] == 1) ? 'checked="checked"' : ''; ?>/></td>
407 - <th><label for="cryptX_var[alt_linktext]"><?php _e("Text for link",'cryptx'); ?></label></th>
408 - <td><input name="cryptX_var[alt_linktext]" value="<?php echo $cryptX_var[alt_linktext]; ?>" type="text" class="regular-text" /></td>
409 - </tr>
410 - <tr valign="top">
411 - <td scope="row"><input type="radio" name="cryptX_var[opt_linktext]" id="opt_linktext3" value="2" <?php echo ($cryptX_var[opt_linktext] == 2) ? 'checked="checked"' : ''; ?>/></td>
412 - <th><label for="cryptX_var[alt_linkimage]"><?php _e("Image-URL",'cryptx'); ?></label></th>
413 - <td><input name="cryptX_var[alt_linkimage]" value="<?php echo $cryptX_var[alt_linkimage]; ?>" type="text" class="regular-text" /></td>
414 - </tr>
415 - <tr valign="top">
416 - <td scope="row">&nbsp;</td>
417 - <th><label for="cryptX_var[http_linkimage_title]"><?php _e("Title-Tag for the Image",'cryptx'); ?></label></th>
418 - <td><input name="cryptX_var[http_linkimage_title]" value="<?php echo $cryptX_var[http_linkimage_title]; ?>" type="text" class="regular-text" /></td>
419 - </tr>
420 - <tr valign="top">
421 - <td scope="row"><input type="radio" name="cryptX_var[opt_linktext]" id="opt_linktext4" value="3" <?php echo ($cryptX_var[opt_linktext] == 3) ? 'checked="checked"' : ''; ?>/></td>
422 - <th><label for="cryptX_var[alt_uploadedimage]"><?php _e("Select image from folder",'cryptx'); ?></label></th>
423 - <td><select name="cryptX_var[alt_uploadedimage]" onchange="cryptX_bild_wechsel(this)">
424 - <?php foreach($this->_dirImages() as $image) {
425 - $FirstIMG = (!isset($FirstIMG))? plugins_url('cryptx/images/').$image : ($cryptX_var[alt_uploadedimage] == plugins_url('cryptx/images/').$image) ? plugins_url('cryptx/images/').$image : $FirstIMG;
426 - ?>
427 - <option value="<?php echo plugins_url('cryptx/images/').$image; ?>" <?php echo ($cryptX_var[alt_uploadedimage] == plugins_url('cryptx/images/').$image) ? 'selected' : ''; ?> ><?php echo $image; ?></option>
428 - <?php } ?>
429 - </select>&nbsp;&nbsp;<img src="<?php echo $FirstIMG; ?>" id="cryptXmailTo"></td>
430 - </tr>
431 - <tr valign="top">
432 - <td>&nbsp;</td>
433 - <th><label for="cryptX_var[alt_linkimage_title]"><?php _e("Title-Tag for the Image",'cryptx'); ?></label></th>
434 - <td><input name="cryptX_var[alt_linkimage_title]" value="<?php echo $cryptX_var[alt_linkimage_title]; ?>" type="text" class="regular-text" />
435 - <span class="setting-description"><?php _e("Upload your favorite email-image to ../plugins/cryptx/images. Only .jpg and .gif Supported!",'cryptx'); ?></span></td>
436 - </tr>
437 - <tr valign="top">
438 - <td scope="row"><input type="radio" name="cryptX_var[opt_linktext]" id="opt_linktext" value="4" <?php echo ($cryptX_var[opt_linktext] == 4) ? 'checked="checked"' : ''; ?>/></td>
439 - <th colspan="2"><?php _e("Text scrambled by AntiSpamBot (<small>Try it and look at your site and check the html source!</small>)",'cryptx'); ?></th>
440 - </tr>
441 - </table>
442 - </div>
443 - </div>
444 - <p><input type="submit" name="cryptX" class="button-primary" value="<?php _e('Save Changes') ?>" /></p>
445 -
446 - <div class="postbox">
447 -
448 - <h3><?php _e("General",'cryptx'); ?></h3>
449 -
450 - <div class="inside">
451 - <table class="form-table">
452 - <tr valign="top">
453 - <th scope="row"><?php _e("Apply CryptX to...",'cryptx'); ?></th>
454 - <td><input name="cryptX_var[theContent]" <?php echo ($cryptX_var[theContent]) ? 'checked="checked"' : ''; ?> type="checkbox" />&nbsp;&nbsp;<?php _e("Content",'cryptx'); ?> <?php _e("(<i>this can be disabled per Post by an Option</i>)",'cryptx'); ?><br/>
455 - <input name="cryptX_var[theExcerpt]" <?php echo ($cryptX_var[theExcerpt]) ? 'checked="checked"' : ''; ?> type="checkbox" />&nbsp;&nbsp;<?php _e("Excerpt",'cryptx'); ?><br/>
456 - <input name="cryptX_var[commentText]" <?php echo ($cryptX_var[commentText]) ? 'checked="checked"' : ''; ?> type="checkbox" />&nbsp;&nbsp;<?php _e("Comments",'cryptx'); ?><br/>
457 - <input name="cryptX_var[widgetText]" <?php echo ($cryptX_var[widgetText]) ? 'checked="checked"' : ''; ?> type="checkbox" />&nbsp;&nbsp;<?php _e("Widgets",'cryptx'); ?> <?php _e("(<i>works only on all widgets, not on a single widget</i>!)",'cryptx'); ?></td>
458 - </tr>
459 - <tr valign="top">
460 - <th scope="row"><?php _e("Type of decryption",'cryptx'); ?></th>
461 - <td><input name="cryptX_var[java]" <?php echo ($cryptX_var[java]) ? 'checked="checked"' : ''; ?> type="radio" value="1" />&nbsp;&nbsp;<?php _e("Use javascript to hide the Email-Link.",'cryptx'); ?><br/>
462 - <input name="cryptX_var[java]" <?php echo (!$cryptX_var[java]) ? 'checked="checked"' : ''; ?> type="radio" value="0" />&nbsp;&nbsp;<?php _e("Use Unicode to hide the Email-Link.",'cryptx'); ?></td>
463 - </tr>
464 - <tr valign="top">
465 - <th scope="row" colspan="2"><input name="cryptX_var[autolink]" <?php echo ($cryptX_var[autolink]) ? 'checked="checked"' : ''; ?> type="checkbox" />&nbsp;&nbsp;<?php _e("Add mailto to all unlinked email addresses",'cryptx'); ?></th>
466 - </tr>
467 - </table>
468 -
469 - </div>
470 - </div>
471 - <p><input type="submit" name="cryptX" class="button-primary" value="<?php _e('Save Changes') ?>" /></p>
472 -
473 - <div class="postbox">
474 -
475 - <h3><?php _e("How to use CryptX in your Template",'cryptx'); ?></h3>
476 -
477 - <div class="inside">
478 - <table class="form-table">
479 - <tr>
480 - <td>In your Template you can use the following function to encrypt a email address:
481 - <p style="border:1px solid #000; background-color: #e9e9e9;padding: 10px;">
482 - <i>
483 - &lt;?php <br/>
484 - &nbsp;&nbsp;&nbsp;&nbsp; $mail="name@example.com"; <br/>
485 - &nbsp;&nbsp;&nbsp;&nbsp; $text="Contact"; <br/>
486 - &nbsp;&nbsp;&nbsp;&nbsp; $css ="email"; <br/>
487 - &nbsp;&nbsp;&nbsp;&nbsp; if (function_exists('cryptx')) { <br/>
488 - &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; cryptx($mail, $text, $css, 1); <br/>
489 - &nbsp;&nbsp;&nbsp;&nbsp; } else { <br/>
490 - &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; echo sprintf('&lt;a href="mailto:%s" class="%s"&gt;%s&lt;/a&gt;', $mail, $css, ($text != "" ? $text : $mail)); <br/>
491 - &nbsp;&nbsp;&nbsp;&nbsp; } <br/>
492 - ?&gt;
493 - </i></p>
494 - <ol><li>parameter is the email address.</li>
495 - <li>parameter is the linktext. If none given the email address is used.</li>
496 - <li>parameter is a css class added to the link.</li>
497 - <li>parameter is 1 for echo the encrypted email address or 0 to return the redult to a variable.</li></ol></td>
498 - </tr>
499 - </table>
500 -
501 - </div>
502 - </div>
503 -
504 - <div class="postbox">
505 -
506 - <h3><?php _e("Information",'cryptx'); ?></h3>
507 -
508 - <div class="inside">
509 - <table class="form-table">
510 - <tr>
511 - <td><?php
512 - $data = get_plugin_data(__FILE__);
513 - echo sprintf(
514 - '%1$s: %2$s | %3$s: %4$s | %5$s: <a href="http://weber-nrw.de" target="_blank">Ralf Weber</a> | <a href="http://twitter.com/Weber_NRW" target="_blank">%6$s</a><br />',
515 - __('Plugin'),
516 - 'CryptX',
517 - __('Version'),
518 - $data['Version'],
519 - __('Author'),
520 - __('Follow on Twitter', 'cryptx'));
521 - ?>
522 - </td>
523 - </tr>
524 - </table>
525 -
526 - </div>
527 - </div>
528 -
529 - </div>
530 -
531 - </form>
532 -
533 - <script type="text/javascript">
534 - <!--
535 - function cryptX_bild_wechsel(select){
536 - document.getElementById("cryptXmailTo").src = select.options[select.options.selectedIndex].value;
537 - return true;
538 - } //-->
539 - </script>
540 -
541 - </div>
542 -<?php
543 - }
544 -
545 - // -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
546 -
547 -
548 - //--end-of-class
549 - }
550 -
380 + return do_shortcode($shortcode);
381 + }
551 382 }
552 383
553 -/////////////////////////////////////////////////////////////////////////////
554 -
555 384 /**
556 -* Initiating the plugin...
557 -* @see cryptX
558 -*/
559 -new cryptX;
385 + * Encrypts the given content using the CryptX library and wraps it with a shortcode.
386 + *
387 + * @deprecated 4.0.5 Use cryptx_encrypt() instead.
388 + * @see cryptx_encrypt()
389 + */
390 +if (!function_exists('encryptx')) {
391 + function encryptx(string $content, ?array $args = []): string
392 + {
393 + _doing_it_wrong(
394 + 'encryptx',
395 + esc_html__('This function is deprecated. Use cryptx_encrypt() instead.', 'cryptx'),
396 + '4.0.5'
397 + );
560 398
561 -/**
562 -* Create Template functions...
563 -* $content = string to convert
564 -* $text = string to replace linktext
565 -* $css = assign a css class to the link
566 -* $echo = 0: keep result in a variable, 1: show result
567 -*/
568 -function cryptx( $content, $text="", $css="", $echo=1 )
569 -{
570 - global $cryptX_var;
571 -
572 - $cryptX = new cryptX;
573 -
574 - $content = $cryptX->autolink( $content );
575 -
576 - $content = $cryptX->encryptx( $content );
577 -
578 - if("" != $text) {
579 - $content = preg_replace( "/(<a[^>]*>)(.*)(<\/a>)/i", '$1'.$text.'$3', $content );
580 - }
581 - if("" != $css) {
582 - $content = preg_replace( "/(<a[^>]*)(>)/i", '$1 class="'.$css.'"$2', $content );
583 - }
584 - if(1 == $echo) echo $content;
585 -
586 - return $content;
587 -}
588 -?>
399 + return cryptx_encrypt($content, $args);
400 + }
401 +}