| 1 |
<?php |
| 2 |
|
| 3 |
namespace Elementor\Core\Files\Assets; |
| 4 |
|
| 5 |
if ( ! defined( 'ABSPATH' ) ) { |
| 6 |
exit; // Exit if accessed directly. |
| 7 |
} |
| 8 |
|
| 9 |
abstract class Files_Upload_Handler { |
| 10 |
const OPTION_KEY = 'elementor_unfiltered_files_upload'; |
| 11 |
|
| 12 |
public function __construct() { |
| 13 |
add_filter( 'upload_mimes', [ $this, 'support_unfiltered_files_upload' ] ); |
| 14 |
add_filter( 'wp_handle_upload_prefilter', [ $this, 'handle_upload_prefilter' ] ); |
| 15 |
add_filter( 'wp_check_filetype_and_ext', [ $this, 'check_filetype_and_ext' ], 10, 4 ); |
| 16 |
} |
| 17 |
|
| 18 |
abstract public function get_mime_type(); |
| 19 |
|
| 20 |
abstract public function get_file_type(); |
| 21 |
|
| 22 |
/** |
| 23 |
* is_elementor_media_upload |
| 24 |
* @return bool |
| 25 |
*/ |
| 26 |
private function is_elementor_media_upload() { |
| 27 |
return isset( $_POST['uploadTypeCaller'] ) && 'elementor-editor-upload' === $_POST['uploadTypeCaller']; // phpcs:ignore |
| 28 |
} |
| 29 |
|
| 30 |
/** |
| 31 |
* @return bool |
| 32 |
*/ |
| 33 |
final public static function is_enabled() { |
| 34 |
$enabled = ! ! get_option( self::OPTION_KEY ) && self::file_sanitizer_can_run(); |
| 35 |
|
| 36 |
/** |
| 37 |
* @deprecated 3.0.0 Use `elementor/document/urls/edit` filter instead. |
| 38 |
*/ |
| 39 |
$enabled = apply_filters( 'elementor/files/svg/enabled', $enabled ); |
| 40 |
|
| 41 |
/** |
| 42 |
* Allow Unfiltered Files Upload. |
| 43 |
* |
| 44 |
* Determines whether to enable unfiltered file uploads. |
| 45 |
* |
| 46 |
* @since 3.0.0 |
| 47 |
* |
| 48 |
* @param bool $enabled Weather upload is enabled or not. |
| 49 |
*/ |
| 50 |
$enabled = apply_filters( 'elementor/files/allow_unfiltered_upload', $enabled ); |
| 51 |
|
| 52 |
return $enabled; |
| 53 |
} |
| 54 |
|
| 55 |
final public function support_unfiltered_files_upload( $existing_mimes ) { |
| 56 |
$existing_mimes[ $this->get_file_type() ] = $this->get_mime_type(); |
| 57 |
|
| 58 |
return $existing_mimes; |
| 59 |
} |
| 60 |
|
| 61 |
/** |
| 62 |
* handle_upload_prefilter |
| 63 |
* @param $file |
| 64 |
* |
| 65 |
* @return mixed |
| 66 |
*/ |
| 67 |
public function handle_upload_prefilter( $file ) { |
| 68 |
if ( ! $this->is_file_should_handled( $file ) ) { |
| 69 |
return $file; |
| 70 |
} |
| 71 |
|
| 72 |
$ext = pathinfo( $file['name'], PATHINFO_EXTENSION ); |
| 73 |
$file_type = $this->get_file_type(); |
| 74 |
$display_type = strtoupper( $file_type ); |
| 75 |
|
| 76 |
if ( $file_type !== $ext ) { |
| 77 |
$file['error'] = sprintf( __( 'The uploaded %1$s file is not supported. Please upload a valid %2$s file', 'elementor' ), $ext, $display_type ); |
| 78 |
return $file; |
| 79 |
} |
| 80 |
|
| 81 |
if ( ! self::is_enabled() ) { |
| 82 |
$file['error'] = sprintf( __( '%1$s file is not allowed for security reasons', 'elementor' ), $display_type ); |
| 83 |
return $file; |
| 84 |
} |
| 85 |
|
| 86 |
return $file; |
| 87 |
} |
| 88 |
|
| 89 |
protected function is_file_should_handled( $file ) { |
| 90 |
return $this->is_elementor_media_upload() && $this->get_mime_type() === $file['type']; |
| 91 |
} |
| 92 |
|
| 93 |
/** |
| 94 |
* file_sanitizer_can_run |
| 95 |
* @return bool |
| 96 |
*/ |
| 97 |
public static function file_sanitizer_can_run() { |
| 98 |
return class_exists( 'DOMDocument' ) && class_exists( 'SimpleXMLElement' ); |
| 99 |
} |
| 100 |
|
| 101 |
/** |
| 102 |
* Check filetype and ext |
| 103 |
* |
| 104 |
* A workaround for upload validation which relies on a PHP extension (fileinfo) |
| 105 |
* with inconsistent reporting behaviour. |
| 106 |
* ref: https://core.trac.wordpress.org/ticket/39550 |
| 107 |
* ref: https://core.trac.wordpress.org/ticket/40175 |
| 108 |
* |
| 109 |
* @param $data |
| 110 |
* @param $file |
| 111 |
* @param $filename |
| 112 |
* @param $mimes |
| 113 |
* |
| 114 |
* @return mixed |
| 115 |
*/ |
| 116 |
public function check_filetype_and_ext( $data, $file, $filename, $mimes ) { |
| 117 |
if ( ! empty( $data['ext'] ) && ! empty( $data['type'] ) ) { |
| 118 |
return $data; |
| 119 |
} |
| 120 |
|
| 121 |
$wp_file_type = wp_check_filetype( $filename, $mimes ); |
| 122 |
$file_type = strtolower( $this->get_file_type() ); |
| 123 |
|
| 124 |
if ( $file_type === $wp_file_type['ext'] ) { |
| 125 |
$data['ext'] = $file_type; |
| 126 |
$data['type'] = $this->get_mime_type(); |
| 127 |
} |
| 128 |
|
| 129 |
return $data; |
| 130 |
} |
| 131 |
} |
| 132 |
|