PluginProbe
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler / 1.7.1
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler v1.7.1
1.7.1 1.7.0 1.6.6 1.6.5 1.6.4 1.6.3 1.6.2 1.6.1 1.6.0 1.5.4 1.5.5 1.5.3 1.5.2 1.5.1 1.5.0 1.4.2 1.4.1 1.4.0 1.3.28 1.3.27 1.3.26 1.3.25 1.3.23 1.3.22 1.3.21 All 51 releases
← All changes | app/Http/Requests/FluentMetaRequest.php +79 -0 1.4.1 → 1.7.1 View file →
@@ -4,8 +4,10 @@
4 4
5 5 use FluentCart\Framework\Foundation\RequestGuard;
6 6 use FluentCart\Framework\Support\Arr;
7 7 use FluentCart\App\Services\Permission\PermissionManager;
8 +use FluentCart\App\Services\Theme\ColorPalette;
9 +use FluentCart\App\Services\Theme\RadiusPalette;
8 10
9 11 class FluentMetaRequest extends RequestGuard
10 12 {
11 13
@@ -25,8 +27,14 @@
25 27 ]
26 28 ];
27 29
28 30 $rules = Arr::get($rulesMap, $this->get('settings_name'), []);
31 +
32 + // The radius fields only show under Customize; a value hidden under
33 + // another source is dropped by the sanitiser rather than blocking the save.
34 + if ($this->get('settings_name') === 'appearance' && $this->get('appearance_source') === ColorPalette::SOURCE_CUSTOM) {
35 + $rules = array_merge($rules, RadiusPalette::validationRules());
36 + }
29 37 // $rules = [
30 38 // 'object_id' => 'integer|min:1',
31 39 // 'object_type' => 'nullable|sanitizeText|max:50',
32 40 // 'meta_key' => 'nullable|sanitizeText|max:50',
@@ -92,13 +100,20 @@
92 100 'show_cart_icon_in_body' => 'sanitize_text_field',
93 101 'additional_address_field' => 'sanitize_text_field',
94 102 'hide_coupon_field' => 'sanitize_text_field',
95 103 'user_account_creation_mode' => 'sanitize_text_field',
104 + 'require_customer_email_verification' => function ($value) {
105 + return $value === 'no' ? 'no' : 'yes';
106 + },
107 + 'auto_login_after_account_creation' => function ($value) {
108 + return $value === 'yes' ? 'yes' : 'no';
109 + },
96 110 'force_ssl' => 'sanitize_text_field',
97 111 'checkout_page_id' => 'intval',
98 112 'custom_payment_page_id' => 'intval',
99 113 'cart_page_id' => 'intval',
100 114 'receipt_page_id' => 'intval',
115 + 'order_review_page_id' => 'intval',
101 116 'shop_page_id' => 'intval',
102 117 'customer_profile_page_id' => 'intval',
103 118 'customer_profile_page_slug' => 'sanitize_text_field',
104 119 'registration_page_id' => 'intval',
@@ -114,10 +129,30 @@
114 129 'store_state' => 'sanitize_text_field',
115 130 'template_settings_checkout_page_mode' => 'sanitize_text_field',
116 131 'show_relevant_product_in_single_page' => 'sanitize_text_field',
117 132 'show_relevant_product_in_modal' => 'sanitize_text_field',
133 + 'show_reviews_in_single_page' => 'sanitize_text_field',
134 + 'show_rating_in_shop' => 'sanitize_text_field',
135 + 'show_rating_in_relevant' => 'sanitize_text_field',
118 136 'enable_early_payment_for_installment' => 'sanitize_text_field',
137 + 'subscription_management_mode' => function ($value) {
138 + $value = sanitize_text_field($value);
139 + $allowed = ['gateway_managed', 'store_managed'];
140 + return in_array($value, $allowed, true) ? $value : 'gateway_managed';
141 + },
142 + 'subscription_system_charge' => function ($value) {
143 + $value = sanitize_text_field($value);
144 + return in_array($value, ['yes', 'no'], true) ? $value : 'no';
145 + },
146 + 'subscription_manual_fallback' => function ($value) {
147 + $value = sanitize_text_field($value);
148 + return in_array($value, ['yes', 'no'], true) ? $value : 'no';
149 + },
119 150 'order_mode' => 'sanitize_text_field',
151 + 'subscription_mode_guard' => function ($value) {
152 + $value = sanitize_text_field($value);
153 + return in_array($value, ['yes', 'no'], true) ? $value : 'yes';
154 + },
120 155 'variation_view' => 'sanitize_text_field',
121 156 'variation_columns' => 'sanitize_text_field',
122 157 'modules_settings' => 'sanitize_text_field',
123 158 'product_slug' => 'sanitize_text_field',
@@ -122,8 +157,16 @@
122 157 'modules_settings' => 'sanitize_text_field',
123 158 'product_slug' => 'sanitize_text_field',
124 159 'min_receipt_number' => 'sanitize_text_field',
125 160 'inv_prefix' => 'sanitize_text_field',
161 + 'date_time_format_source' => function ($value) {
162 + $value = sanitize_text_field($value);
163 + return in_array($value, ['fluent_cart', 'wordpress'], true) ? $value : 'fluent_cart';
164 + },
165 + 'timezone_source' => function ($value) {
166 + $value = sanitize_text_field($value);
167 + return in_array($value, ['fluent_cart', 'wordpress'], true) ? $value : 'fluent_cart';
168 + },
126 169 'weight_unit' => function ($value) {
127 170 if (!PermissionManager::hasPermission(['store/sensitive'])) {
128 171 $stored = get_option('fluent_cart_store_settings', []);
129 172 return $stored['weight_unit'] ?? 'kg';
@@ -142,8 +185,44 @@
142 185 return in_array($value, $allowed, true) ? $value : 'cm';
143 186 },
144 187 'enable_image_zoom_in_single_product' => 'sanitize_text_field',
145 188 'enable_image_zoom_in_modal' => 'sanitize_text_field',
189 + 'appearance_source' => function ($value) {
190 + $value = sanitize_text_field($value);
191 +
192 + return in_array($value, ColorPalette::sources(), true)
193 + ? $value
194 + : ColorPalette::SOURCE_DEFAULT;
195 + },
196 + 'appearance_colors' => function ($value) {
197 + if (!is_array($value)) {
198 + return [];
199 + }
200 +
201 + // Driven off the registry rather than the submitted keys, so an
202 + // unknown property can never reach the storefront stylesheet.
203 + $colors = [];
204 +
205 + foreach (ColorPalette::globals() as $key => $definition) {
206 + $hex = sanitize_hex_color((string)Arr::get($value, $key, ''));
207 +
208 + // sanitize_hex_color() returns null for anything malformed
209 + // and '' for an empty picker; both mean "not set", which is
210 + // how a colour falls back to FluentCart's own default.
211 + if ($hex) {
212 + $colors[$key] = $hex;
213 + }
214 + }
215 +
216 + return $colors;
217 + },
218 + 'appearance_radius' => function ($value) {
219 + // Registry-driven like the colours: only the known roles, each
220 + // one length. A bare number means pixels; px, rem and em are
221 + // kept as typed. An empty field means "not set", so the
222 + // stylesheet's own fallback applies; 0 is a real value.
223 + return RadiusPalette::sanitizeOwnerMap($value);
224 + },
146 225 'theme_setup' => function ($value) {
147 226 if (!is_array($value)) {
148 227 return [];
149 228 }