# fluent-booking/2.3.0/app/Hooks/Handlers/DataExporter.php

Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution, version 2.3.0. 237 lines.

- Page: https://pluginprobe.com/plugins/fluent-booking/2.3.0/code/app/Hooks/Handlers/DataExporter.php
- Raw: https://pluginprobe.com/plugins/fluent-booking/2.3.0/raw/app/Hooks/Handlers/DataExporter.php
- Modified: 2026-06-08T11:36:48+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/fluent-booking/2.3.0/code/app/Hooks/Handlers/DataExporter.php#L10-L20`.

```php
<?php

namespace FluentBooking\App\Hooks\Handlers;

use FluentBooking\App\Models\Booking;
use FluentBooking\App\Models\Calendar;
use FluentBooking\App\Models\Availability;
use FluentBooking\App\Services\PermissionManager;

class DataExporter
{
    public function exportCalendar()
    {
        if (!$this->verifyNonce()) {
            wp_die(esc_html__('Security check failed. Please refresh and try again.', 'fluent-booking'), 403);
        }

        $calendarId = isset($_REQUEST['calendar_id']) ? (int)$_REQUEST['calendar_id'] : null; // phpcs:ignore WordPress.Security.NonceVerification.Recommended

        if (!$calendarId) {
            die(esc_html__('Please provide Calendar ID', 'fluent-booking'));
        }

        $calendar = Calendar::with(['metas', 'events' => function ($query) {
            $query->with('event_metas');
        }])->find($calendarId);

        if (!$calendar) {
            die(esc_html__('Calendar not found', 'fluent-booking'));
        }

        if (!PermissionManager::hasCalendarAccess($calendar)) {
            die(esc_html__('You do not have permission to export data', 'fluent-booking'));
        }

        $calendarData = $this->prepareCalendarExportData($calendar);

        header('Content-Type: application/json');
        header('Content-Disposition: attachment; filename=CluentBookingHostExport-' . $calendarId . '.json');
        echo json_encode($calendarData, JSON_PRETTY_PRINT); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
        exit();
    }

    public function exportBookingHosts()
    {
        if (!$this->verifyNonce()) {
            wp_die(esc_html__('Security check failed. Please refresh and try again.', 'fluent-booking'), 403);
        }

        $groupId = isset($_REQUEST['group_id']) ? (int)$_REQUEST['group_id'] : null; // phpcs:ignore WordPress.Security.NonceVerification.Recommended

        if (!$groupId) {
            die(esc_html__('Please provide Group ID', 'fluent-booking'));
        }

        $attendees = Booking::where('group_id', $groupId)->get();

        if ($attendees->isEmpty()) {
            die(esc_html__('No bookings found for the provided Group ID', 'fluent-booking'));
        }

        if (!PermissionManager::userCanSeeAllBookings() && !$attendees->first()->hasBookingAccess()) {
            die(esc_html__('You do not have permission to export this group\'s attendees', 'fluent-booking'));
        }

        $csvData[] = [
            'First Name',
            'Last Name',
            'Email',
            'Message',
            'Location Details',
            'Source',
            'Booking Type',
            'Status',
            'Source URL',
            'Duration',
            'Start Time',
            'End Time',
            'Payment Status',
            'Payment Order Status',
            'Payment Method',
            'Currency',
            'Total Amount',
            'Order Created At',
            'Transaction ID',
            'Vendor Charge ID',
            'Transaction Payment Method',
            'Transaction Status',
            'Transaction Total',
            'Transaction Created At',
        ];

        foreach ($attendees as $attendee) {
            $row = [
                $this->sanitizeCsvCell($attendee->first_name),
                $this->sanitizeCsvCell($attendee->last_name),
                $this->sanitizeCsvCell($attendee->email),
                $this->sanitizeCsvCell($attendee->message),
                $this->sanitizeCsvCell($attendee->getLocationAsText()),
                $this->sanitizeCsvCell($attendee->source),
                $this->sanitizeCsvCell($attendee->booking_type),
                $this->sanitizeCsvCell($attendee->status),
                $this->sanitizeCsvCell($attendee->source_url),
                $this->sanitizeCsvCell($attendee->slot_minutes),
                $this->sanitizeCsvCell($attendee->start_time),
                $this->sanitizeCsvCell($attendee->end_time),
                $this->sanitizeCsvCell($attendee->payment_status),
            ];

            $paymentOrder = $attendee->payment_status ? $attendee->payment_order : null;
            $row          = array_merge($row, $this->buildPaymentColumns($paymentOrder));

            $csvData[] = $row;
        }

        $csvData = apply_filters('fluent_booking/exporting_booking_data_csv', $csvData, $attendees);

        $output = fopen('php://output', 'w');
        header('Content-Type: text/csv');
        header('Content-Disposition: attachment; filename=Booking-Event-Guests-' . $groupId . '.csv');

        foreach ($csvData as $index => $row) {
            // Sanitize header row cells for consistency (formula-neutralize and strip control chars)
            if ($index === 0) {
                $row = array_map([$this, 'sanitizeCsvCell'], $row);
            }
            fputcsv($output, $row);
        }

        fclose($output); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fclose
        exit();
    }

    /*
     * Prepare calendar data for export
     * @param Calendar|int $calendar Calendar Model or ID
     * @return array
     */
    public function prepareCalendarExportData($calendar = null)
    {
        if (is_numeric($calendar)) {
            $calendar = Calendar::with(['metas', 'events' => function ($query) {
                $query->with('event_metas');
            }])->find($calendar);
        } else if (is_null($calendar)) {
            $calendar = Calendar::with(['metas', 'events' => function ($query) {
                $query->with('event_metas');
            }])->first();
        }

        if (!$calendar) {
            return [];
        }

        $availabilities = [];

        foreach ($calendar->events as $event) {
            if (isset($availabilities[$event->availability_id])) {
                continue;
            }
            $availability = Availability::find($event->availability_id);
            if ($availability) {
                $availabilities[$event->availability_id] = $availability;
            }
        }

        $calendarData = $calendar->toArray();

        $calendarData['data_type'] = 'host';
        $calendarData['availabilities'] = $availabilities;

        $calendarData = apply_filters('fluent_booking/exporting_calendar_data_json', $calendarData, $calendar);

        return $calendarData;
    }

    private function buildPaymentColumns($order)
    {
        if (!$order) {
            return array_fill(0, 11, '');
        }

        $order->load(['items', 'transaction']);
        $trans = $order->transaction;

        return [
            $this->sanitizeCsvCell($order->status),
            $this->sanitizeCsvCell($order->payment_method),
            $this->sanitizeCsvCell($order->currency),
            $order->total_amount / 100,
            $this->sanitizeCsvCell($order->created_at),
            $this->sanitizeCsvCell($trans ? $trans->id : ''),
            $this->sanitizeCsvCell($trans ? $trans->vendor_charge_id : ''),
            $this->sanitizeCsvCell($trans ? $trans->payment_method : ''),
            $this->sanitizeCsvCell($trans ? $trans->status : ''),
            $trans ? $trans->total / 100 : '',
            $this->sanitizeCsvCell($trans ? $trans->created_at : ''),
        ];
    }

    /**
     * Sanitize a value for safe CSV output: neutralize formula injection and strip control chars.
     * Prefix with single quote when value starts with =, +, -, or @ so spreadsheets treat as text.
     *
     * @param mixed $value Cell value (string, number, or null).
     * @return string Safe string for fputcsv.
     */
    private function sanitizeCsvCell($value)
    {
        if (empty($value)) {
            return '';
        }
        $value = (string) $value;
        // Strip control characters (ASCII 0-31 except tab, LF, CR).
        $value = preg_replace('/[\x00-\x08\x0B\x0C\x0E-\x1F]/', '', $value);
        // Neutralize formula injection: prefix with ' so Excel/LibreOffice treat as text.
        $first = isset($value[0]) ? $value[0] : '';
        if (in_array($first, ['=', '+', '-', '@'], true)) {
            $value = "'" . $value;
        }

        return $value;
    }

    /**
     * Verify the request nonce for AJAX actions.
     *
     * @return bool
     */
    private function verifyNonce()
    {
        $nonce = isset($_REQUEST['nonce']) ? sanitize_text_field(wp_unslash($_REQUEST['nonce'])) : '';

        return !empty($nonce) && wp_verify_nonce($nonce, 'fluent-booking');
    }
}

```
