| @@ -59,16 +59,21 @@ | ||
| 59 | 59 | 'showSecondaryDomainRecommendationAgent' => false, |
| 60 | 60 | 'domainTLDs' => ['com', 'net'], |
| 61 | 61 | 'priorityDomainTLDs' => [], |
| 62 | 62 | 'stagingSites' => ['wordpress'], |
| 63 | + 'trialDomains' => [], | |
| 63 | 64 | 'domainSearchURL' => '', |
| 64 | 65 | 'showDraft' => false, |
| 65 | 66 | 'showChat' => false, |
| 66 | 67 | 'showAIPageCreation' => false, |
| 68 | + 'mcpConfig' => [], | |
| 69 | + 'mcpWriteList' => [], | |
| 70 | + 'mcpReadList' => [], | |
| 67 | 71 | 'enableImageImports-1-14-6' => false, |
| 68 | 72 | 'disableLibraryAutoOpen' => false, |
| 69 | 73 | 'enableApexDomain' => false, |
| 70 | 74 | 'showLaunch' => false, |
| 75 | + 'showLaunchTitle' => false, | |
| 71 | 76 | 'deactivated' => true, |
| 72 | 77 | 'launchRedirectWebsite' => false, |
| 73 | 78 | 'showAILogo' => false, |
| 74 | 79 | 'showProductRecommendations' => false, |
| @@ -93,10 +98,13 @@ | ||
| 93 | 98 | 'useAgentOnboarding' => false, |
| 94 | 99 | 'hidePluginNotifications' => false, |
| 95 | 100 | 'hideLaunchExitLink' => false, |
| 96 | 101 | 'useAutoUpdate' => false, |
| 102 | + 'showLaunchUpdate' => false, | |
| 97 | 103 | 'activeTests' => [], |
| 98 | 104 | 'showExtendifyCode' => false, |
| 105 | + 'useComingSoon' => false, | |
| 106 | + 'useSearchEngineBlock' => false, | |
| 99 | 107 | 'extendifyCodeData' => [ |
| 100 | 108 | 'link' => '', |
| 101 | 109 | 'title' => '', |
| 102 | 110 | 'message' => '', |
| @@ -101,8 +109,10 @@ | ||
| 101 | 109 | 'title' => '', |
| 102 | 110 | 'message' => '', |
| 103 | 111 | 'cta-primary' => '', |
| 104 | 112 | ], |
| 113 | + 'customDesign' => null, | |
| 114 | + 'strings' => [], | |
| 105 | 115 | ]; |
| 106 | 116 | |
| 107 | 117 | // phpcs:disable Generic.Metrics.CyclomaticComplexity.MaxExceeded |
| 108 | 118 | /** |
| @@ -111,8 +121,16 @@ | ||
| 111 | 121 | * @return void |
| 112 | 122 | */ |
| 113 | 123 | public function __construct() |
| 114 | 124 | { |
| 125 | + self::load(); | |
| 126 | + } | |
| 127 | + | |
| 128 | + /** | |
| 129 | + * @return void | |
| 130 | + */ | |
| 131 | + public static function load() | |
| 132 | + { | |
| 115 | 133 | self::$id = defined('EXTENDIFY_PARTNER_ID') ? constant('EXTENDIFY_PARTNER_ID') : null; |
| 116 | 134 | $data = self::getPartnerData(); |
| 117 | 135 | self::$config['showDomainBanner'] = ($data['showDomainBanner'] ?? self::$config['showDomainBanner']); |
| 118 | 136 | self::$config['showDomainTask'] = ($data['showDomainTask'] ?? self::$config['showDomainTask']); |
| @@ -127,8 +145,9 @@ | ||
| 127 | 145 | self::$config['domainTLDs'] = ($data['domainTLDs'] ?? self::$config['domainTLDs']); |
| 128 | 146 | self::$config['priorityDomainTLDs'] = ($data['priorityDomainTLDs'] |
| 129 | 147 | ?? self::$config['priorityDomainTLDs']); |
| 130 | 148 | self::$config['stagingSites'] = array_map('trim', ($data['stagingSites'] ?? self::$config['stagingSites'])); |
| 149 | + self::$config['trialDomains'] = array_map('trim', ($data['trialDomains'] ?? self::$config['trialDomains'])); | |
| 131 | 150 | self::$config['domainSearchURL'] = ($data['domainSearchURL'] ?? self::$config['domainSearchURL']); |
| 132 | 151 | self::$logo = isset($data['logo'][0]['thumbnails']['large']['url']) |
| 133 | 152 | ? $data['logo'][0]['thumbnails']['large']['url'] |
| 134 | 153 | : self::$logo; |
| @@ -146,9 +165,13 @@ | ||
| 146 | 165 | 'secondaryColor' => ($data['secondaryColor'] ?? ($data['backgroundColor'] ?? null)), |
| 147 | 166 | 'secondaryColorText' => '#ffffff', |
| 148 | 167 | ]; |
| 149 | 168 | self::$config['showAIPageCreation'] = ($data['showAIPageCreation'] ?? self::$config['showAIPageCreation']); |
| 169 | + self::$config['mcpConfig'] = ($data['mcpConfig'] ?? self::$config['mcpConfig']); | |
| 170 | + self::$config['mcpWriteList'] = ($data['mcpWriteList'] ?? self::$config['mcpWriteList']); | |
| 171 | + self::$config['mcpReadList'] = ($data['mcpReadList'] ?? self::$config['mcpReadList']); | |
| 150 | 172 | self::$config['showLaunch'] = ($data['showLaunch'] ?? self::$config['showLaunch']); |
| 173 | + self::$config['showLaunchTitle'] = ($data['showLaunchTitle'] ?? self::$config['showLaunchTitle']); | |
| 151 | 174 | self::$config['deactivated'] = ($data['deactivated'] ?? self::$config['deactivated']); |
| 152 | 175 | self::$config['launchRedirectWebsite'] = ($data['launchRedirectWebsite'] |
| 153 | 176 | ?? self::$config['launchRedirectWebsite']); |
| 154 | 177 | self::$config['showAILogo'] = ($data['showAILogo'] ?? self::$config['showAILogo']); |
| @@ -179,11 +202,17 @@ | ||
| 179 | 202 | self::$config['hidePluginNotifications'] = ($data['hidePluginNotifications'] |
| 180 | 203 | ?? self::$config['hidePluginNotifications']); |
| 181 | 204 | self::$config['hideLaunchExitLink'] = ($data['hideLaunchExitLink'] ?? self::$config['hideLaunchExitLink']); |
| 182 | 205 | self::$config['useAutoUpdate'] = ($data['useAutoUpdate'] ?? self::$config['useAutoUpdate']); |
| 206 | + self::$config['showLaunchUpdate'] = ($data['showLaunchUpdate'] ?? self::$config['showLaunchUpdate']); | |
| 183 | 207 | self::$config['activeTests'] = ($data['activeTests'] ?? self::$config['activeTests']); |
| 184 | 208 | self::$config['showExtendifyCode'] = ($data['showExtendifyCode'] ?? self::$config['showExtendifyCode']); |
| 209 | + self::$config['useComingSoon'] = ($data['useComingSoon'] ?? self::$config['useComingSoon']); | |
| 210 | + self::$config['useSearchEngineBlock'] = ($data['useSearchEngineBlock'] | |
| 211 | + ?? self::$config['useSearchEngineBlock']); | |
| 185 | 212 | self::$config['extendifyCodeData'] = ($data['extendifyCodeData'] ?? self::$config['extendifyCodeData']); |
| 213 | + self::$config['customDesign'] = ($data['customDesign'] ?? self::$config['customDesign']); | |
| 214 | + self::$config['strings'] = ($data['strings'] ?? self::$config['strings']); | |
| 186 | 215 | |
| 187 | 216 | // Add the job hook to fetch the partner data. |
| 188 | 217 | \add_action('extendify_fetch_partner_data', [self::class, 'fetchPartnerData']); |
| 189 | 218 | } |
| @@ -203,15 +232,12 @@ | ||
| 203 | 232 | $partnerData = \get_option('extendify_partner_data_v2', 'empty'); |
| 204 | 233 | if ($partnerData !== 'empty') { |
| 205 | 234 | // We have data, but if it's been 10 minutes, check for new data. |
| 206 | 235 | $partnerRefresh = \get_transient('extendify_partner_data_cache_check'); |
| 207 | - if (!$partnerRefresh && \is_admin()) { | |
| 208 | - \add_action('init', function () { | |
| 209 | - if (!\wp_next_scheduled('extendify_fetch_partner_data')) { | |
| 210 | - \wp_schedule_single_event(time(), 'extendify_fetch_partner_data'); | |
| 211 | - \spawn_cron(); | |
| 212 | - } | |
| 213 | - }); | |
| 236 | + if (!$partnerRefresh && \is_user_logged_in()) { | |
| 237 | + \did_action('init') | |
| 238 | + ? self::scheduleRefresh() | |
| 239 | + : \add_action('init', [self::class, 'scheduleRefresh']); | |
| 214 | 240 | } |
| 215 | 241 | |
| 216 | 242 | return array_merge(self::$config, $partnerData); |
| 217 | 243 | } |
| @@ -223,8 +249,49 @@ | ||
| 223 | 249 | return $mergedData; |
| 224 | 250 | } |
| 225 | 251 | |
| 226 | 252 | /** |
| 253 | + * A token request may be the only visitor a site gets, so it fetches a stale config itself. | |
| 254 | + * | |
| 255 | + * @return void | |
| 256 | + */ | |
| 257 | + public static function refreshIfStale() | |
| 258 | + { | |
| 259 | + if (\get_transient('extendify_partner_data_cache_check')) { | |
| 260 | + return; | |
| 261 | + } | |
| 262 | + | |
| 263 | + // The 45s timeout the plugin gives its hosts is longer than a waiting MCP client allows. | |
| 264 | + $brief = function ($args) { | |
| 265 | + $args['timeout'] = 5; | |
| 266 | + return $args; | |
| 267 | + }; | |
| 268 | + \add_filter('http_request_args', $brief, 101); | |
| 269 | + try { | |
| 270 | + $fetched = self::fetchPartnerData(); | |
| 271 | + } finally { | |
| 272 | + \remove_filter('http_request_args', $brief, 101); | |
| 273 | + } | |
| 274 | + | |
| 275 | + if ($fetched) { | |
| 276 | + self::load(); | |
| 277 | + } | |
| 278 | + } | |
| 279 | + | |
| 280 | + /** | |
| 281 | + * @return void | |
| 282 | + */ | |
| 283 | + public static function scheduleRefresh() | |
| 284 | + { | |
| 285 | + if (\wp_next_scheduled('extendify_fetch_partner_data')) { | |
| 286 | + return; | |
| 287 | + } | |
| 288 | + | |
| 289 | + \wp_schedule_single_event(time(), 'extendify_fetch_partner_data'); | |
| 290 | + \spawn_cron(); | |
| 291 | + } | |
| 292 | + | |
| 293 | + /** | |
| 227 | 294 | * Fetch or refresh the partner data |
| 228 | 295 | * |
| 229 | 296 | * @return array |
| 230 | 297 | */ |
| @@ -267,9 +334,16 @@ | ||
| 267 | 334 | } |
| 268 | 335 | |
| 269 | 336 | $sanitizedData = array_merge( |
| 270 | 337 | Sanitizer::sanitizeUnknown($result['data']), |
| 271 | - ['consentTermsCustom' => \sanitize_text_field(htmlentities(($result['data']['consentTermsCustom'] ?? '')))] | |
| 338 | + [ | |
| 339 | + 'consentTermsCustom' => \sanitize_text_field(htmlentities( | |
| 340 | + ($result['data']['consentTermsCustom'] ?? ''), | |
| 341 | + ENT_QUOTES | ENT_SUBSTITUTE | ENT_HTML401 | |
| 342 | + )), | |
| 343 | + 'customDesign' => self::sanitizeDesign($result['data']['customDesign'] ?? null), | |
| 344 | + 'strings' => self::sanitizeStrings($result['data']['strings'] ?? null), | |
| 345 | + ] | |
| 272 | 346 | ); |
| 273 | 347 | |
| 274 | 348 | // Merge before persisting as this data is accessed directly elsewhere. |
| 275 | 349 | $mergedData = array_merge(self::$config, $sanitizedData); |
| @@ -275,8 +349,76 @@ | ||
| 275 | 349 | $mergedData = array_merge(self::$config, $sanitizedData); |
| 276 | 350 | \update_option('extendify_partner_data_v2', $mergedData); |
| 277 | 351 | |
| 278 | 352 | return $mergedData; |
| 353 | + } | |
| 354 | + | |
| 355 | + /** | |
| 356 | + * Partner copy overriding the shipped strings. | |
| 357 | + * | |
| 358 | + * Which keys exist is the flow's to know, so only shape and text are checked here. | |
| 359 | + * | |
| 360 | + * @param mixed $strings The map as the partner-data response carried it. | |
| 361 | + * @return array | |
| 362 | + */ | |
| 363 | + public static function sanitizeStrings($strings) | |
| 364 | + { | |
| 365 | + return array_map( | |
| 366 | + 'sanitize_text_field', | |
| 367 | + self::designEntries($strings, '/^[a-zA-Z][a-zA-Z0-9]*$/', 'is_string') | |
| 368 | + ); | |
| 369 | + } | |
| 370 | + | |
| 371 | + /** | |
| 372 | + * A design carries GLSL, which the text sanitizers break, so only its shape is checked. | |
| 373 | + * | |
| 374 | + * Empty members are left out rather than kept: json_encode writes an empty | |
| 375 | + * PHP array as [], and the page reads the design as an object. | |
| 376 | + * | |
| 377 | + * @param mixed $design The design as the partner-data response carried it. | |
| 378 | + * @return array|null | |
| 379 | + */ | |
| 380 | + private static function sanitizeDesign($design) | |
| 381 | + { | |
| 382 | + if (!is_array($design)) { | |
| 383 | + return null; | |
| 384 | + } | |
| 385 | + | |
| 386 | + $shader = ($design['shader'] ?? null); | |
| 387 | + $logo = ($design['logo'] ?? null); | |
| 388 | + $kept = array_filter([ | |
| 389 | + 'vars' => self::designEntries( | |
| 390 | + ($design['vars'] ?? null), | |
| 391 | + '/^--ext-(ui|tpl)-[a-z0-9-]+$/', | |
| 392 | + function ($value) { | |
| 393 | + // A CSS value is a string, but 0.88 is a natural way to write one. | |
| 394 | + return is_string($value) || is_int($value) || is_float($value); | |
| 395 | + } | |
| 396 | + ), | |
| 397 | + 'templates' => self::designEntries(($design['templates'] ?? null), '/^[A-Za-z0-9_-]+$/', 'is_string'), | |
| 398 | + 'shader' => is_string($shader) ? \wp_check_invalid_utf8($shader) : '', | |
| 399 | + 'logo' => is_string($logo) ? \esc_url_raw($logo) : '', | |
| 400 | + ]); | |
| 401 | + | |
| 402 | + return $kept ?: null; | |
| 403 | + } | |
| 404 | + | |
| 405 | + private static function designEntries($entries, $keyPattern, callable $accepts) | |
| 406 | + { | |
| 407 | + if (!is_array($entries)) { | |
| 408 | + return []; | |
| 409 | + } | |
| 410 | + | |
| 411 | + $kept = []; | |
| 412 | + foreach ($entries as $key => $value) { | |
| 413 | + if (!is_string($key) || !preg_match($keyPattern, $key) || !$accepts($value)) { | |
| 414 | + continue; | |
| 415 | + } | |
| 416 | + | |
| 417 | + $kept[$key] = is_string($value) ? \wp_check_invalid_utf8($value) : $value; | |
| 418 | + } | |
| 419 | + | |
| 420 | + return $kept; | |
| 279 | 421 | } |
| 280 | 422 | |
| 281 | 423 | /** |
| 282 | 424 | * Return colors mapped as css variables |