PluginProbe
Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification / trunk
Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification vtrunk
5.7.0 5.6.2 5.6.3 5.6.1 5.6.0 5.5.0 5.4.0 5.3.2 5.3.1 5.1.6 5.1.5 trunk 2.1.5 2.11 2.12 2.13 2.15 3.0.0 3.0.1 3.0.2 3.0.3 3.0.5 3.0.51 3.0.60 3.0.61 All 39 releases
double-opt-in / src / Setup / SetupRestController.php

SetupRestController.php in Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification trunk, at src/Setup/SetupRestController.php

173 lines 4.3 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * REST routes of the setup wizard.
4 *
5 * `GET f12-doi/v1/setup` prefilled values, forms, detected plugins
6 * `POST f12-doi/v1/setup/step` save one step {step, data}
7 * `POST f12-doi/v1/setup/test-mail` send the configured mail to the current user
8 * `POST f12-doi/v1/setup/finish` write form settings, mark the wizard done
9 * `POST f12-doi/v1/setup/skip` leave the wizard for later
10 * `POST f12-doi/v1/setup/restart` start again with the saved values
11 *
12 * All require `manage_options`. CSRF protection is WordPress' REST cookie
13 * authentication: without a valid `X-WP-Nonce` the request runs as user 0
14 * and fails the capability check.
15 *
16 * @package Forge12\DoubleOptIn\Setup
17 * @since 5.7.0
18 */
19
20 declare( strict_types=1 );
21
22 namespace Forge12\DoubleOptIn\Setup;
23
24 if ( ! defined( 'ABSPATH' ) ) {
25 exit;
26 }
27
28 class SetupRestController {
29
30 public const API_NAMESPACE = 'f12-doi/v1';
31
32 /** @var SetupService */
33 private $service;
34
35 /** @var SetupState */
36 private $state;
37
38 public function __construct( SetupService $service, SetupState $state ) {
39 $this->service = $service;
40 $this->state = $state;
41 }
42
43 public function init(): void {
44 add_action( 'rest_api_init', array( $this, 'registerRoutes' ) );
45 }
46
47 public function checkPermission(): bool {
48 return current_user_can( 'manage_options' );
49 }
50
51 public function registerRoutes(): void {
52 register_rest_route(
53 self::API_NAMESPACE,
54 '/setup',
55 array(
56 'methods' => \WP_REST_Server::READABLE,
57 'callback' => array( $this, 'getOverview' ),
58 'permission_callback' => array( $this, 'checkPermission' ),
59 )
60 );
61 register_rest_route(
62 self::API_NAMESPACE,
63 '/setup/step',
64 array(
65 'methods' => \WP_REST_Server::CREATABLE,
66 'callback' => array( $this, 'saveStep' ),
67 'permission_callback' => array( $this, 'checkPermission' ),
68 'args' => array(
69 'step' => array(
70 'required' => true,
71 'validate_callback' => static function ( $value ) {
72 return is_string( $value ) && array_key_exists( $value, SetupService::STEPS );
73 },
74 ),
75 ),
76 )
77 );
78 foreach ( array(
79 'test-mail' => 'sendTestMail',
80 'finish' => 'finish',
81 'skip' => 'skip',
82 'restart' => 'restart',
83 ) as $route => $method ) {
84 register_rest_route(
85 self::API_NAMESPACE,
86 '/setup/' . $route,
87 array(
88 'methods' => \WP_REST_Server::CREATABLE,
89 'callback' => array( $this, $method ),
90 'permission_callback' => array( $this, 'checkPermission' ),
91 )
92 );
93 }
94 }
95
96 public function getOverview(): \WP_REST_Response {
97 return $this->respond(
98 array(
99 'ok' => true,
100 'errors' => array(),
101 'data' => $this->service->overview(),
102 )
103 );
104 }
105
106 public function saveStep( \WP_REST_Request $request ): \WP_REST_Response {
107 $data = $request->get_param( 'data' );
108 return $this->respond(
109 $this->service->saveStep(
110 (string) $request->get_param( 'step' ),
111 is_array( $data ) ? $data : array()
112 )
113 );
114 }
115
116 public function sendTestMail(): \WP_REST_Response {
117 return $this->respond( $this->service->sendTestMail() );
118 }
119
120 public function finish(): \WP_REST_Response {
121 return $this->respond( $this->service->finish() );
122 }
123
124 public function skip(): \WP_REST_Response {
125 $this->state->skip();
126 return $this->respond(
127 array(
128 'ok' => true,
129 'errors' => array(),
130 'data' => array( 'status' => $this->state->status() ),
131 )
132 );
133 }
134
135 public function restart(): \WP_REST_Response {
136 $this->state->restart();
137 return $this->respond(
138 array(
139 'ok' => true,
140 'errors' => array(),
141 'data' => array( 'status' => $this->state->status() ),
142 )
143 );
144 }
145
146 /**
147 * @param array{ok: bool, errors: array<string, string>, data?: array<string, mixed>} $result
148 */
149 private function respond( array $result ): \WP_REST_Response {
150 if ( ! empty( $result['ok'] ) ) {
151 return new \WP_REST_Response(
152 array(
153 'success' => true,
154 'data' => $result['data'] ?? array(),
155 ),
156 200
157 );
158 }
159
160 $errors = $result['errors'] ?? array();
161 $message = $errors !== array() ? (string) reset( $errors ) : __( 'The setup step could not be saved.', 'double-opt-in' );
162 return new \WP_REST_Response(
163 array(
164 'success' => false,
165 'message' => $message,
166 'code' => 'SETUP_INVALID',
167 'errors' => $errors,
168 ),
169 422
170 );
171 }
172 }
173