| @@ -1,8 +1,10 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace EmailKit\Admin\Api; |
| 4 | 4 | |
| 5 | +use EmailKit\Admin\Emails\Helpers\Utils; | |
| 6 | + | |
| 5 | 7 | defined('ABSPATH') || exit; |
| 6 | 8 | class TemplateData |
| 7 | 9 | { |
| 8 | 10 | |
| @@ -26,9 +28,9 @@ | ||
| 26 | 28 | |
| 27 | 29 | if (!wp_verify_nonce($request->get_header( 'X-WP-Nonce' ), 'wp_rest')) { |
| 28 | 30 | return [ |
| 29 | 31 | 'status' => 'fail', |
| 30 | - 'message' => ['Nonce mismatch.'] | |
| 32 | + 'message' => [esc_html__( 'Nonce mismatch.', 'emailkit' )] | |
| 31 | 33 | ]; |
| 32 | 34 | } |
| 33 | 35 | |
| 34 | 36 | if (!is_user_logged_in() || !current_user_can( 'manage_options' )) { |
| @@ -33,9 +35,9 @@ | ||
| 33 | 35 | |
| 34 | 36 | if (!is_user_logged_in() || !current_user_can( 'manage_options' )) { |
| 35 | 37 | return [ |
| 36 | 38 | 'status' => 'fail', |
| 37 | - 'message' => ['Access denied.'] | |
| 39 | + 'message' => [esc_html__( 'Access denied.', 'emailkit' )] | |
| 38 | 40 | ]; |
| 39 | 41 | } |
| 40 | 42 | $template = ''; |
| 41 | 43 | $html = ''; |
| @@ -44,11 +46,30 @@ | ||
| 44 | 46 | $message = ''; |
| 45 | 47 | |
| 46 | 48 | |
| 47 | 49 | |
| 48 | - if(!empty($request->get_param( 'emailkit-editor-template' ) && trim($request->get_param( 'emailkit-editor-template' )) !== '')){ | |
| 49 | - $template = file_get_contents($request->get_param( 'emailkit-editor-template' ))??''; | |
| 50 | - $html = file_get_contents(str_replace( "content.json", "content.html", $request->get_param( 'emailkit-editor-template' )))??''; | |
| 50 | + if (!empty($request->get_param('emailkit-editor-template')) && trim($request->get_param('emailkit-editor-template')) !== '') { | |
| 51 | + $template_path = $request->get_param('emailkit-editor-template'); | |
| 52 | + $allowed_base_path = wp_upload_dir()['basedir'] . '/emailkit/templates/'; | |
| 53 | + $real_path = realpath($template_path); | |
| 54 | + if ($real_path === false || strpos($real_path, realpath($allowed_base_path)) !== 0) { | |
| 55 | + return [ | |
| 56 | + 'status' => 'fail', | |
| 57 | + 'message' => [__('Invalid template path', 'emailkit')] | |
| 58 | + ]; | |
| 59 | + } | |
| 60 | + | |
| 61 | + $template = file_exists($real_path) ? file_get_contents($real_path) : ''; | |
| 62 | + $template = Utils::normalize_template_asset_urls($template); | |
| 63 | + $html_path = str_replace("content.json", "content.html", $real_path); | |
| 64 | + | |
| 65 | + // Validate HTML path as well | |
| 66 | + $real_html_path = realpath($html_path); | |
| 67 | + if ($real_html_path !== false && strpos($real_html_path, realpath($allowed_base_path)) === 0) { | |
| 68 | + | |
| 69 | + $html = file_exists($real_html_path) ? file_get_contents($real_html_path) : ''; | |
| 70 | + $html = Utils::normalize_template_asset_urls($html); | |
| 71 | + } | |
| 51 | 72 | } |
| 52 | 73 | |
| 53 | 74 | $subject = !empty($request->get_param( 'emailkit_template_title' ))? trim($request->get_param( 'emailkit_template_title' )) : null; |
| 54 | 75 | |
| @@ -60,9 +81,9 @@ | ||
| 60 | 81 | $data = array( |
| 61 | 82 | 'post_type' => 'emailkit', |
| 62 | 83 | 'post_status' => 'publish', |
| 63 | 84 | 'post_author' => get_current_user_id(), |
| 64 | - 'post_title' => $subject !== '' ? $subject : "New Template ".uniqid(), | |
| 85 | + 'post_title' => $subject !== '' ? $subject : esc_html__( 'New Template', 'emailkit' ) . ' ' . uniqid(), | |
| 65 | 86 | 'meta_input' => array( |
| 66 | 87 | 'emailkit_template_content_html' => $html, |
| 67 | 88 | 'emailkit_template_content_object' => $template, |
| 68 | 89 | 'emailkit_email_type' => $request->get_param('emailkit_email_type'), |
| @@ -123,5 +144,6 @@ | ||
| 123 | 144 | update_post_meta($id, 'emailkit_template_status', 'inactive'); |
| 124 | 145 | } |
| 125 | 146 | } |
| 126 | 147 | } |
| 148 | + | |
| 127 | 149 | } |