PluginProbe
Elementor Website Builder – more than just a page builder / 3.25.4
Elementor Website Builder – more than just a page builder v3.25.4
4.3.0-beta3 4.3.0-beta2 4.3.0-beta1 4.2.4 4.2.3 4.2.2 4.2.1 4.2.0 4.1.5 4.2.0-beta2 4.2.0-dev2 4.2.0-beta1 4.1.4 4.1.3 4.1.2 4.1.1 4.1.0 4.1.0-beta3 4.1.0-dev3 4.0.9 4.1.0-beta2 4.1.0-dev2 4.0.8 4.1.0-beta1 4.1.0-dev1 All 452 releases
← All changes | includes/template-library/manager.php +82 -524 4.2.13.25.4 View file →
@@ -2,12 +2,15 @@
2 2 namespace Elementor\TemplateLibrary;
3 3
4 4 use Elementor\Api;
5 5 use Elementor\Core\Common\Modules\Ajax\Module as Ajax;
6 +use Elementor\Core\Isolation\Wordpress_Adapter;
7 +use Elementor\Core\Isolation\Wordpress_Adapter_Interface;
8 +use Elementor\Core\Isolation\Elementor_Adapter;
9 +use Elementor\Core\Isolation\Elementor_Adapter_Interface;
6 10 use Elementor\Core\Settings\Manager as SettingsManager;
7 11 use Elementor\Includes\TemplateLibrary\Data\Controller;
8 12 use Elementor\TemplateLibrary\Classes\Import_Images;
9 -use Elementor\Core\Utils\Template_Library_Import_Export_Utils;
10 13 use Elementor\Plugin;
11 14 use Elementor\User;
12 15 use Elementor\Utils;
13 16
@@ -24,12 +27,8 @@
24 27 * @since 1.0.0
25 28 */
26 29 class Manager {
27 30
28 - const ERROR_TEMPLATE_SOURCE_NOT_FOUND = 'Template source not found.';
29 - const ERROR_TEMPLATE_IDS_MISSING = 'Template IDs are missing.';
30 - const ERROR_JSON_UPLOAD_NOT_ALLOWED = 'Uploading JSON files is not allowed for this user.';
31 -
32 31 /**
33 32 * Registered template sources.
34 33 *
35 34 * Holds a list of all the supported sources with their instances.
@@ -51,8 +50,18 @@
51 50 */
52 51 private $_import_images = null; // phpcs:ignore PSR2.Classes.PropertyDeclaration.Underscore
53 52
54 53 /**
54 + * @var Wordpress_Adapter_Interface
55 + */
56 + protected $wordpress_adapter = null;
57 +
58 + /**
59 + * @var Elementor_Adapter_Interface
60 + */
61 + protected $elementor_adapter = null;
62 +
63 + /**
55 64 * Template library manager constructor.
56 65 *
57 66 * Initializing the template library manager by registering default template
58 67 * sources and initializing ajax calls.
@@ -94,8 +103,15 @@
94 103
95 104 return $this->_import_images;
96 105 }
97 106
107 + public function set_wordpress_adapter( Wordpress_Adapter_Interface $wordpress_adapter ) {
108 + $this->wordpress_adapter = $wordpress_adapter;
109 + }
110 +
111 + public function set_elementor_adapter( Elementor_Adapter_Interface $elementor_adapter ): void {
112 + $this->elementor_adapter = $elementor_adapter;
113 + }
98 114 /**
99 115 * Register template source.
100 116 *
101 117 * Used to register new template sources displayed in the template library.
@@ -191,9 +207,9 @@
191 207 *
192 208 * Retrieve all the templates from all the registered sources.
193 209 *
194 210 * @param array $filter_sources
195 - * @param bool $force_update
211 + * @param bool $force_update
196 212 * @return array
197 213 */
198 214 public function get_templates( array $filter_sources = [], bool $force_update = false ): array {
199 215 $templates = [];
@@ -221,12 +237,10 @@
221 237 *
222 238 * @return array Library data.
223 239 */
224 240 public function get_library_data( array $args ) {
225 - $force_update = ! empty( $args['sync'] );
241 + $library_data = Api::get_library_data( ! empty( $args['sync'] ) );
226 242
227 - $library_data = Api::get_library_data( $force_update );
228 -
229 243 if ( empty( $library_data ) ) {
230 244 return $library_data;
231 245 }
232 246
@@ -233,21 +247,14 @@
233 247 // Ensure all document are registered.
234 248 Plugin::$instance->documents->get_document_types();
235 249
236 250 $filter_sources = ! empty( $args['filter_sources'] ) ? $args['filter_sources'] : [];
251 + $force_update = ! empty( $args['sync'] );
237 252
238 - $full_library_data = [
253 + return [
239 254 'templates' => $this->get_templates( $filter_sources, $force_update ),
240 255 'config' => $library_data['types_data'],
241 256 ];
242 -
243 - /**
244 - * Filter the full library data.
245 - *
246 - * @since 3.32.2
247 - * @param-out $full_library_data - 'templates' and 'config' data ('config' holds the list of categories).
248 - */
249 - return apply_filters( 'elementor/library/full-data', $full_library_data );
250 257 }
251 258
252 259 /**
253 260 * Save template.
@@ -267,25 +274,12 @@
267 274 if ( is_wp_error( $validate_args ) ) {
268 275 return $validate_args;
269 276 }
270 277
271 - $sources = (array) $args['source']; // BC
272 - $results = [];
273 -
274 - foreach ( $sources as $source ) {
275 - $args_copy = $args;
276 - $args_copy['source'] = $source;
277 - $results[] = $this->save_template_item( $args_copy );
278 - }
279 -
280 - return 1 === count( $results ) ? $results[0] : $results;
281 - }
282 -
283 - private function save_template_item( array $args ) {
284 278 $source = $this->get_source( $args['source'] );
285 279
286 280 if ( ! $source ) {
287 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
281 + return new \WP_Error( 'template_error', 'Template source not found.' );
288 282 }
289 283
290 284 $args['content'] = json_decode( $args['content'], true );
291 285
@@ -301,97 +295,8 @@
301 295
302 296 return $source->get_item( $template_id );
303 297 }
304 298
305 - public function move_template( array $args ) {
306 - $validate_args = $this->ensure_args( [ 'source', 'from_source', 'from_template_id' ], $args );
307 -
308 - if ( is_wp_error( $validate_args ) ) {
309 - return $validate_args;
310 - }
311 -
312 - $args['source'] = $args['source'][0];
313 -
314 - $result = $this->move_template_item( $args );
315 -
316 - if ( ! $this->is_action_to_same_source( $args ) ) {
317 - $this->delete_template( [
318 - 'source' => $args['from_source'],
319 - 'template_id' => $args['from_template_id'],
320 - ] );
321 - }
322 -
323 - return $result;
324 - }
325 -
326 - private function move_template_item( array $args ) {
327 - $validate_args = $this->ensure_args( [ 'source', 'from_source', 'from_template_id' ], $args );
328 -
329 - if ( is_wp_error( $validate_args ) ) {
330 - return $validate_args;
331 - }
332 -
333 - $source = $this->get_source( $args['source'] );
334 -
335 - if ( ! $source ) {
336 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
337 - }
338 -
339 - if ( $this->is_action_to_same_source( $args ) ) {
340 - return $source->move_template_to_folder( $args );
341 - }
342 -
343 - $from_source = $this->get_source( $args['from_source'] );
344 -
345 - if ( ! $from_source ) {
346 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
347 - }
348 -
349 - $args = $from_source->format_args_for_single_action( $args );
350 -
351 - $template_id = $source->save_item( $args );
352 -
353 - if ( is_wp_error( $template_id ) ) {
354 - return $template_id;
355 - }
356 -
357 - return $source->get_item( $template_id );
358 - }
359 -
360 - public function copy_template( array $args ) {
361 - $validate_args = $this->ensure_args( [ 'source', 'from_source', 'from_template_id' ], $args );
362 -
363 - if ( is_wp_error( $validate_args ) ) {
364 - return $validate_args;
365 - }
366 -
367 - $source = $this->get_source( $args['source'][0] );
368 -
369 - if ( ! $source ) {
370 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
371 - }
372 -
373 - $from_source = $this->get_source( $args['from_source'] );
374 -
375 - if ( ! $from_source ) {
376 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
377 - }
378 -
379 - $args = $from_source->format_args_for_single_action( $args );
380 -
381 - $template_id = $source->save_item( $args );
382 -
383 - if ( is_wp_error( $template_id ) ) {
384 - return $template_id;
385 - }
386 -
387 - return $source->get_item( $template_id );
388 - }
389 -
390 - private function is_action_to_same_source( $args ) {
391 - return $args['source'] === $args['from_source'];
392 - }
393 -
394 299 /**
395 300 * Update template.
396 301 *
397 302 * Update template on the database.
@@ -413,9 +318,9 @@
413 318
414 319 $source = $this->get_source( $template_data['source'] );
415 320
416 321 if ( ! $source ) {
417 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
322 + return new \WP_Error( 'template_error', 'Template source not found.' );
418 323 }
419 324
420 325 $template_data['content'] = json_decode( $template_data['content'], true );
421 326
@@ -427,30 +332,8 @@
427 332
428 333 return $source->get_item( $template_data['id'] );
429 334 }
430 335
431 - public function rename_template( array $template_data ) {
432 - $validate_args = $this->ensure_args( [ 'source', 'title', 'id' ], $template_data );
433 -
434 - if ( is_wp_error( $validate_args ) ) {
435 - return $validate_args;
436 - }
437 -
438 - $source = $this->get_source( $template_data['source'] );
439 -
440 - if ( ! $source ) {
441 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
442 - }
443 -
444 - $update = $source->update_item( $template_data );
445 -
446 - if ( is_wp_error( $update ) ) {
447 - return $update;
448 - }
449 -
450 - return $source->get_item( $template_data['id'] );
451 - }
452 -
453 336 /**
454 337 * Update templates.
455 338 *
456 339 * Update template on the database.
@@ -492,15 +375,9 @@
492 375 if ( is_wp_error( $validate_args ) ) {
493 376 return $validate_args;
494 377 }
495 378
496 - $source = $this->get_source( $args['source'] );
497 -
498 - if ( ! $source ) {
499 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
500 - }
501 -
502 - if ( method_exists( $source, 'is_allowed_to_read_template' ) && ! $source->is_allowed_to_read_template( $args ) ) {
379 + if ( ! $this->is_allowed_to_read_template( $args ) ) {
503 380 return new \WP_Error(
504 381 'template_error',
505 382 esc_html__( 'You do not have permission to access this template.', 'elementor' )
506 383 );
@@ -509,8 +386,14 @@
509 386 if ( isset( $args['edit_mode'] ) ) {
510 387 Plugin::$instance->editor->set_edit_mode( $args['edit_mode'] );
511 388 }
512 389
390 + $source = $this->get_source( $args['source'] );
391 +
392 + if ( ! $source ) {
393 + return new \WP_Error( 'template_error', 'Template source not found.' );
394 + }
395 +
513 396 do_action( 'elementor/template-library/before_get_source_data', $args, $source );
514 397
515 398 $data = $source->get_data( $args );
516 399
@@ -541,9 +424,9 @@
541 424
542 425 $source = $this->get_source( $args['source'] );
543 426
544 427 if ( ! $source ) {
545 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
428 + return new \WP_Error( 'template_error', 'Template source not found.' );
546 429 }
547 430
548 431 return $source->delete_template( $args['template_id'] );
549 432 }
@@ -567,12 +450,27 @@
567 450 if ( is_wp_error( $validate_args ) ) {
568 451 return $validate_args;
569 452 }
570 453
454 + $post_id = intval( $args['template_id'] );
455 + $post_status = get_post_status( $post_id );
456 +
457 + if ( get_post_type( $post_id ) !== Source_Local::CPT ) {
458 + return new \WP_Error( 'template_error', esc_html__( 'Invalid template type or template does not exist.', 'elementor' ) );
459 + }
460 +
461 + if ( 'private' === $post_status && ! current_user_can( 'read_private_posts', $post_id ) ) {
462 + return new \WP_Error( 'template_error', esc_html__( 'You do not have permission to access this template.', 'elementor' ) );
463 + }
464 +
465 + if ( 'publish' !== $post_status && ! current_user_can( 'edit_post', $post_id ) ) {
466 + return new \WP_Error( 'template_error', esc_html__( 'You do not have permission to export this template.', 'elementor' ) );
467 + }
468 +
571 469 $source = $this->get_source( $args['source'] );
572 470
573 471 if ( ! $source ) {
574 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
472 + return new \WP_Error( 'template_error', 'Template source not found' );
575 473 }
576 474
577 475 return $source->export_template( $args['template_id'] );
578 476 }
@@ -583,9 +481,9 @@
583 481 */
584 482 public function direct_import_template() {
585 483 /** @var Source_Local $source */
586 484 $source = $this->get_source( 'local' );
587 - $file = Utils::get_super_global_value( $_FILES, 'file' ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
485 + $file = Utils::get_super_global_value( $_FILES, 'file' );
588 486 return $source->import_template( $file['name'], $file['tmp_name'] );
589 487 }
590 488
591 489 /**
@@ -600,12 +498,8 @@
600 498 *
601 499 * @return mixed Whether the export succeeded or failed.
602 500 */
603 501 public function import_template( array $data ) {
604 - if ( ! User::is_current_user_can_upload_json() ) {
605 - return new \WP_Error( 'template_error', self::ERROR_JSON_UPLOAD_NOT_ALLOWED );
606 - }
607 -
608 502 // If the template is a JSON file, allow uploading it.
609 503 add_filter( 'elementor/files/allow-file-type/json', [ $this, 'enable_json_template_upload' ] );
610 504 add_filter( 'elementor/files/allow_unfiltered_upload', [ $this, 'enable_json_template_upload' ] );
611 505
@@ -615,15 +509,17 @@
615 509 remove_filter( 'elementor/files/allow-file-type/json', [ $this, 'enable_json_template_upload' ] );
616 510 remove_filter( 'elementor/files/allow_unfiltered_upload', [ $this, 'enable_json_template_upload' ] );
617 511
618 512 if ( is_wp_error( $upload_result ) ) {
513 + Plugin::$instance->uploads_manager->remove_file_or_dir( dirname( $upload_result['tmp_name'] ) );
514 +
619 515 return $upload_result;
620 516 }
621 517
622 - $source = $this->get_source( $data['source'] ?? 'local' );
518 + /** @var Source_Local $source_local */
519 + $source_local = $this->get_source( 'local' );
623 520
624 - $import_mode = $data['import_mode'] ?? 'match_site';
625 - $import_result = $source->import_template( $upload_result['name'], $upload_result['tmp_name'], $import_mode );
521 + $import_result = $source_local->import_template( $upload_result['name'], $upload_result['tmp_name'] );
626 522
627 523 // Remove the temporary directory generated for the stream-uploaded file.
628 524 Plugin::$instance->uploads_manager->remove_file_or_dir( dirname( $upload_result['tmp_name'] ) );
629 525
@@ -683,185 +579,11 @@
683 579 }
684 580
685 581 $import_data = $document->get_import_data( [ 'content' => $elements ] );
686 582
687 - $content = $document::on_import_update_dynamic_content(
688 - $import_data['content'],
689 - [ 'post_ids' => [] ]
690 - );
691 -
692 - return Plugin::$instance->db->iterate_data( $content, function( $element_data ) {
693 - unset( $element_data['htmlCache'] );
694 - return $element_data;
695 - } );
583 + return $import_data['content'];
696 584 }
697 585
698 - public function process_global_styles( array $args ) {
699 - $validate_args = $this->ensure_args( [ 'content', 'import_mode' ], $args );
700 -
701 - if ( is_wp_error( $validate_args ) ) {
702 - return $validate_args;
703 - }
704 -
705 - $import_mode = Template_Library_Import_Export_Utils::sanitize_import_mode( $args['import_mode'] );
706 -
707 - $content = $this->get_validated_json_arg( $args, 'content' );
708 - if ( is_wp_error( $content ) ) {
709 - return $content;
710 - }
711 -
712 - $global_classes = $this->get_validated_json_arg( $args, 'global_classes', true );
713 - if ( is_wp_error( $global_classes ) ) {
714 - return $global_classes;
715 - }
716 -
717 - $global_variables = $this->get_validated_json_arg( $args, 'global_variables', true );
718 - if ( is_wp_error( $global_variables ) ) {
719 - return $global_variables;
720 - }
721 -
722 - $data = [
723 - 'global_classes' => $global_classes,
724 - 'global_variables' => $global_variables,
725 - ];
726 -
727 - $result = apply_filters(
728 - 'elementor/template_library/import/process_content',
729 - [ 'content' => $content ],
730 - $import_mode,
731 - $data,
732 - null
733 - );
734 -
735 - $response = [
736 - 'content' => $result['content'],
737 - ];
738 -
739 - if ( ! empty( $result['updated_global_classes'] ) ) {
740 - $response['updated_global_classes'] = $result['updated_global_classes'];
741 - }
742 -
743 - if ( ! empty( $result['updated_global_variables'] ) ) {
744 - $response['updated_global_variables'] = $result['updated_global_variables'];
745 - }
746 -
747 - $classes_to_flatten = $result['classes_to_flatten'] ?? [];
748 - $variables_to_flatten = $result['variables_to_flatten'] ?? [];
749 -
750 - if ( ! empty( $classes_to_flatten ) ) {
751 - $response['flattened_classes_count'] = count( $classes_to_flatten );
752 - }
753 -
754 - if ( ! empty( $variables_to_flatten ) ) {
755 - $response['flattened_variables_count'] = count( $variables_to_flatten );
756 - }
757 -
758 - return $response;
759 - }
760 -
761 - private function get_validated_json_arg( array $args, string $key, bool $is_optional = false ) {
762 - if ( ! array_key_exists( $key, $args ) || null === $args[ $key ] || '' === $args[ $key ] ) {
763 - return $is_optional ? null : new \WP_Error( "invalid_$key", "Invalid $key." );
764 - }
765 -
766 - $value = $args[ $key ];
767 - if ( is_string( $value ) ) {
768 - $decoded = json_decode( $value, true );
769 - if ( JSON_ERROR_NONE !== json_last_error() ) {
770 - return new \WP_Error( "invalid_$key", "Invalid JSON $key." );
771 - }
772 - return $decoded;
773 - }
774 -
775 - if ( ! is_array( $value ) ) {
776 - return new \WP_Error( "invalid_$key", "Invalid $key format." );
777 - }
778 -
779 - return $value;
780 - }
781 -
782 - public function get_item_children( array $args ) {
783 - $validate_args = $this->ensure_args( [ 'source', 'template_id' ], $args );
784 -
785 - if ( is_wp_error( $validate_args ) ) {
786 - return $validate_args;
787 - }
788 -
789 - $source = $this->get_source( $args['source'] );
790 -
791 - if ( ! $source ) {
792 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
793 - }
794 -
795 - return $source->get_item_children( $args );
796 - }
797 -
798 - public function search_templates( array $args ) {
799 - $validate_args = $this->ensure_args( [ 'source', 'search' ], $args );
800 -
801 - if ( is_wp_error( $validate_args ) ) {
802 - return $validate_args;
803 - }
804 -
805 - $source = $this->get_source( $args['source'] );
806 -
807 - if ( ! $source ) {
808 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
809 - }
810 -
811 - return $source->search_templates( $args );
812 - }
813 -
814 - public function load_more_templates( array $args ) {
815 - $validate_args = $this->ensure_args( [ 'source', 'offset' ], $args );
816 -
817 - if ( is_wp_error( $validate_args ) ) {
818 - return $validate_args;
819 - }
820 -
821 - $source = $this->get_source( $args['source'] );
822 -
823 - if ( ! $source ) {
824 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
825 - }
826 -
827 - return $source->get_items( $args );
828 - }
829 -
830 - public function create_folder( array $args ) {
831 - $validate_args = $this->ensure_args( [ 'source', 'title' ], $args );
832 -
833 - if ( is_wp_error( $validate_args ) ) {
834 - return $validate_args;
835 - }
836 -
837 - $source = $this->get_source( $args['source'] );
838 -
839 - if ( ! $source ) {
840 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
841 - }
842 -
843 - return $source->save_folder( $args );
844 - }
845 -
846 - public function get_folders( array $args ) {
847 - $validate_args = $this->ensure_args( [ 'source', 'offset' ], $args );
848 -
849 - if ( is_wp_error( $validate_args ) ) {
850 - return $validate_args;
851 - }
852 -
853 - $source = $this->get_source( $args['source'] );
854 -
855 - if ( ! $source ) {
856 - return new \WP_Error( 'template_error', 'Folder source not found.' );
857 - }
858 -
859 - $args['templateType'] = 'folder';
860 -
861 - return $source->get_items( $args );
862 - }
863 -
864 586 /**
865 587 * Register default template sources.
866 588 *
867 589 * Register the 'local' and 'remote' template sources that Elementor use by
@@ -873,9 +595,8 @@
873 595 private function register_default_sources() {
874 596 $sources = [
875 597 'local',
876 598 'remote',
877 - 'cloud',
878 599 ];
879 600
880 601 foreach ( $sources as $source_filename ) {
881 602 $class_name = ucwords( $source_filename );
@@ -894,12 +615,12 @@
894 615 * @access private
895 616 *
896 617 * @param string $ajax_request Ajax request.
897 618 *
898 - * @param array $data
619 + * @param array $data
899 620 *
900 621 * @return mixed
901 - * @throws \Exception If current user has no permission or the post is not found.
622 + * @throws \Exception
902 623 */
903 624 private function handle_ajax_request( $ajax_request, array $data ) {
904 625 if ( ! User::is_current_user_can_edit_post_type( Source_Local::CPT ) ) {
905 626 throw new \Exception( 'Access denied.' );
@@ -904,12 +625,8 @@
904 625 if ( ! User::is_current_user_can_edit_post_type( Source_Local::CPT ) ) {
905 626 throw new \Exception( 'Access denied.' );
906 627 }
907 628
908 - if ( 'import_template' === $ajax_request && ! User::is_current_user_can_upload_json() ) {
909 - throw new \Exception( 'Access denied.' );
910 - }
911 -
912 629 if ( ! empty( $data['editor_post_id'] ) ) {
913 630 $editor_post_id = absint( $data['editor_post_id'] );
914 631
915 632 if ( ! get_post( $editor_post_id ) ) {
@@ -921,9 +638,9 @@
921 638
922 639 $result = call_user_func( [ $this, $ajax_request ], $data );
923 640
924 641 if ( is_wp_error( $result ) ) {
925 - throw new \Exception( esc_html( $result->get_error_message() ) );
642 + throw new \Exception( $result->get_error_message() );
926 643 }
927 644
928 645 return $result;
929 646 }
@@ -928,76 +645,8 @@
928 645 return $result;
929 646 }
930 647
931 648 /**
932 - * @throws \Exception If template import fails, file validation errors occur, or processing encounters issues.
933 - */
934 - public function save_template_screenshot( $data ): string {
935 - $validate_args = $this->ensure_args( [ 'template_id', 'screenshot' ], $data );
936 -
937 - if ( is_wp_error( $validate_args ) ) {
938 - return $validate_args;
939 - }
940 -
941 - $raw_binary = base64_decode( substr( $data['screenshot'], strlen( 'data:image/png;base64,' ) ) );
942 -
943 - return $this->get_source( 'cloud' )->save_item_preview( $data['template_id'], $raw_binary );
944 - }
945 -
946 - /**
947 - * @throws \Exception If template processing fails or data validation errors occur.
948 - */
949 - public function template_screenshot_failed( $data ): string {
950 - $validate_args = $this->ensure_args( [ 'template_id' ], $data );
951 -
952 - if ( is_wp_error( $validate_args ) ) {
953 - return $validate_args;
954 - }
955 -
956 - return $this->get_source( 'cloud' )->mark_preview_as_failed( $data['template_id'], $data['error'] );
957 - }
958 -
959 - public function bulk_delete_templates( $data ) {
960 - $validate_args = $this->ensure_args( [ 'template_ids', 'source' ], $data );
961 -
962 - if ( is_wp_error( $validate_args ) ) {
963 - return $validate_args;
964 - }
965 -
966 - $source = $this->get_source( $data['source'] );
967 -
968 - if ( ! $source ) {
969 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
970 - }
971 -
972 - if ( empty( $data['template_ids'] ) || ! is_array( $data['template_ids'] ) ) {
973 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_IDS_MISSING );
974 - }
975 -
976 - return $source->bulk_delete_items( $data['template_ids'] );
977 - }
978 -
979 - public function bulk_undo_delete_items( $data ) {
980 - $validate_args = $this->ensure_args( [ 'template_ids', 'source' ], $data );
981 -
982 - if ( is_wp_error( $validate_args ) ) {
983 - return $validate_args;
984 - }
985 -
986 - $source = $this->get_source( $data['source'] );
987 -
988 - if ( ! $source ) {
989 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
990 - }
991 -
992 - if ( empty( $data['template_ids'] ) || ! is_array( $data['template_ids'] ) ) {
993 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_IDS_MISSING );
994 - }
995 -
996 - return $source->bulk_undo_delete_items( $data['template_ids'] );
997 - }
998 -
999 - /**
1000 649 * Init ajax calls.
1001 650 *
1002 651 * Initialize template library ajax calls for allowed ajax requests.
1003 652 *
@@ -1015,24 +664,8 @@
1015 664 'delete_template',
1016 665 'import_template',
1017 666 'mark_template_as_favorite',
1018 667 'import_from_json',
1019 - 'get_item_children',
1020 - 'search_templates',
1021 - 'rename_template',
1022 - 'load_more_templates',
1023 - 'create_folder',
1024 - 'get_folders',
1025 - 'save_template_screenshot',
1026 - 'move_template',
1027 - 'copy_template',
1028 - 'bulk_move_templates',
1029 - 'bulk_delete_templates',
1030 - 'bulk_copy_templates',
1031 - 'bulk_undo_delete_items',
1032 - 'get_templates_quota',
1033 - 'template_screenshot_failed',
1034 - 'process_global_styles',
1035 668 ];
1036 669
1037 670 foreach ( $library_ajax_requests as $ajax_request ) {
1038 671 $ajax->register_ajax_action( $ajax_request, function( $data ) use ( $ajax_request ) {
@@ -1133,117 +766,42 @@
1133 766
1134 767 return true;
1135 768 }
1136 769
1137 - public function bulk_move_templates( array $args ) {
1138 - $validate_args = $this->ensure_args( [ 'source', 'from_source', 'from_template_id' ], $args );
1139 -
1140 - if ( is_wp_error( $validate_args ) ) {
1141 - return $validate_args;
770 + private function is_allowed_to_read_template( array $args ): bool {
771 + if ( 'remote' === $args['source'] ) {
772 + return true;
1142 773 }
1143 774
1144 - $args['source'] = $args['source'][0];
1145 -
1146 - return $this->bulk_move_template_items( $args );
1147 - }
1148 -
1149 - private function bulk_move_template_items( array $args ) {
1150 - $source = $this->get_source( $args['source'] );
1151 -
1152 - if ( ! $source ) {
1153 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
775 + if ( null === $this->wordpress_adapter ) {
776 + $this->set_wordpress_adapter( new WordPress_Adapter() );
1154 777 }
1155 778
1156 - if ( $this->is_action_to_same_source( $args ) ) {
1157 - return $source->move_bulk_templates_to_folder( $args );
779 + if ( ! $this->should_check_permissions( $args ) ) {
780 + return true;
1158 781 }
1159 782
1160 - $from_source = $this->get_source( $args['from_source'] );
783 + $post_id = intval( $args['template_id'] );
784 + $post_status = $this->wordpress_adapter->get_post_status( $post_id );
785 + $is_private_or_non_published = ( 'private' === $post_status && ! $this->wordpress_adapter->current_user_can( 'read_private_posts', $post_id ) ) || ( 'publish' !== $post_status );
1161 786
1162 - if ( ! $from_source ) {
1163 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
1164 - }
787 + $can_read_template = $is_private_or_non_published || $this->wordpress_adapter->current_user_can( 'edit_post', $post_id );
1165 788
1166 - $bulk_args = $from_source->format_args_for_bulk_action( $args );
1167 -
1168 - if ( $source->supports_quota() && ! $this->is_action_to_same_source( $args ) ) {
1169 - $quota_validation = $source->validate_quota( $bulk_args );
1170 -
1171 - if ( is_wp_error( $quota_validation ) ) {
1172 - return $quota_validation;
1173 - }
1174 -
1175 - if ( false === $quota_validation ) {
1176 - return new \WP_Error( 'quota_error', 'The moving failed because it will pass the maximum templates you can save.' );
1177 - }
1178 - }
1179 -
1180 - $bulk_save = $source->save_bulk_items( $bulk_args );
1181 -
1182 - if ( ! empty( $bulk_save ) ) {
1183 - $this->bulk_delete_templates( [
1184 - 'template_ids' => $args['from_template_id'],
1185 - 'source' => $args['from_source'],
1186 - ] );
1187 - }
1188 -
1189 - return $bulk_save;
789 + return apply_filters( 'elementor/template-library/is_allowed_to_read_template', $can_read_template, $args );
1190 790 }
1191 791
1192 - public function bulk_copy_templates( array $args ) {
1193 - $validate_args = $this->ensure_args( [ 'source', 'from_source', 'from_template_id' ], $args );
1194 -
1195 - if ( is_wp_error( $validate_args ) ) {
1196 - return $validate_args;
792 + private function should_check_permissions( array $args ): bool {
793 + if ( null === $this->elementor_adapter ) {
794 + $this->set_elementor_adapter( new Elementor_Adapter() );
1197 795 }
1198 796
1199 - $args['source'] = $args['source'][0];
797 + // TODO: Remove $isWidgetTemplate in 3.28.0 as there is a Pro dependency
798 + $check_permissions = isset( $args['check_permissions'] ) && false === $args['check_permissions'];
799 + $is_widget_template = 'widget' === $this->elementor_adapter->get_template_type( $args['template_id'] );
1200 800
1201 - return $this->bulk_copy_template_items( $args );
1202 - }
1203 -
1204 - private function bulk_copy_template_items( array $args ) {
1205 - $source = $this->get_source( $args['source'] );
1206 -
1207 - if ( ! $source ) {
1208 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
801 + if ( $check_permissions || $is_widget_template ) {
802 + return false;
1209 803 }
1210 804
1211 - $from_source = $this->get_source( $args['from_source'] );
1212 -
1213 - if ( ! $from_source ) {
1214 - return new \WP_Error( 'template_error', self::ERROR_TEMPLATE_SOURCE_NOT_FOUND );
1215 - }
1216 -
1217 - $bulk_args = $from_source->format_args_for_bulk_action( $args );
1218 -
1219 - if ( $source->supports_quota() && ! $this->is_action_to_same_source( $args ) ) {
1220 - $quota_validation = $source->validate_quota( $bulk_args );
1221 -
1222 - if ( is_wp_error( $quota_validation ) ) {
1223 - return $quota_validation;
1224 - }
1225 -
1226 - if ( false === $quota_validation ) {
1227 - return new \WP_Error( 'quota_error', 'The copying failed because it will pass the maximum templates you can save.' );
1228 - }
1229 - }
1230 -
1231 - return $source->save_bulk_items( $bulk_args );
1232 - }
1233 -
1234 - public function get_templates_quota( array $args ) {
1235 - $validate_args = $this->ensure_args( [ 'source' ], $args );
1236 -
1237 - if ( is_wp_error( $validate_args ) ) {
1238 - return $validate_args;
1239 - }
1240 -
1241 - $source = $this->get_source( $args['source'] );
1242 -
1243 - if ( ! $source ) {
1244 - return new \WP_Error( 'template_error', 'Source not found.' );
1245 - }
1246 -
1247 - return $source->get_quota();
805 + return true;
1248 806 }
1249 807 }