| @@ -2,9 +2,8 @@ | ||
| 2 | 2 | |
| 3 | 3 | namespace FluentCommunity\App\Services; |
| 4 | 4 | |
| 5 | 5 | use FluentCommunity\App\Functions\Utility; |
| 6 | -use \FluentCommunity\App\Models\Space; | |
| 7 | 6 | use FluentCommunity\App\Models\BaseSpace; |
| 8 | 7 | use FluentCommunity\App\Models\Feed; |
| 9 | 8 | use FluentCommunity\App\Models\Media; |
| 10 | 9 | use FluentCommunity\App\Models\Reaction; |
| @@ -10,8 +9,9 @@ | ||
| 10 | 9 | use FluentCommunity\App\Models\Reaction; |
| 11 | 10 | use FluentCommunity\App\Models\Term; |
| 12 | 11 | use FluentCommunity\App\Models\User; |
| 13 | 12 | use FluentCommunity\App\Models\XProfile; |
| 13 | +use FluentCommunity\Framework\Foundation\Exceptions\UnprocessableEntityHttpException; | |
| 14 | 14 | use FluentCommunity\Framework\Support\Arr; |
| 15 | 15 | use FluentCommunity\Framework\Validator\Validator; |
| 16 | 16 | |
| 17 | 17 | class FeedsHelper |
| @@ -59,8 +59,71 @@ | ||
| 59 | 59 | |
| 60 | 60 | return $user->spaces()->pluck('slug')->toArray(); |
| 61 | 61 | } |
| 62 | 62 | |
| 63 | + /** | |
| 64 | + * Statuses where a post is fully reachable by its direct link. An unlisted post is | |
| 65 | + * hidden from listings only, so it stays commentable and reactable like a published one. | |
| 66 | + * | |
| 67 | + * @return array | |
| 68 | + */ | |
| 69 | + public static function getViewableByLinkStatuses() | |
| 70 | + { | |
| 71 | + return ['published', 'unlisted']; | |
| 72 | + } | |
| 73 | + | |
| 74 | + /** | |
| 75 | + * Row types that opt IN to comments through meta.enable_comments, mapped to the value | |
| 76 | + * assumed when the key is absent. | |
| 77 | + * | |
| 78 | + * A feed post uses the opposite convention - meta.comments_disabled, absent meaning on - | |
| 79 | + * so it is deliberately not listed here and falls through to the permissive default. | |
| 80 | + * | |
| 81 | + * The fallbacks match each model's getDefaultMeta(): a lesson written before the | |
| 82 | + * setting existed keeps its thread, a page does not. Guessing one value for both | |
| 83 | + * would silently switch off every legacy lesson discussion. | |
| 84 | + * | |
| 85 | + * @return array<string, string> | |
| 86 | + */ | |
| 87 | + public static function getOptInCommentTypes() | |
| 88 | + { | |
| 89 | + return apply_filters('fluent_community/opt_in_comment_types', [ | |
| 90 | + 'course_lesson' => 'yes', | |
| 91 | + 'space_page' => 'no', | |
| 92 | + ]); | |
| 93 | + } | |
| 94 | + | |
| 95 | + /** | |
| 96 | + * Whether a row accepts comments at all, by its own settings. | |
| 97 | + * | |
| 98 | + * This is the setting check only - it says nothing about who the current user is. | |
| 99 | + * Space membership and the course level kill switch are separate, in | |
| 100 | + * CommentsController::verifySpacePermission(). | |
| 101 | + * | |
| 102 | + * Both the read and the write path go through here so they cannot disagree. They used | |
| 103 | + * to: the write path only ever read meta.comments_disabled, which pages and lessons | |
| 104 | + * do not set, so a POST landed a comment on a page whose thread the UI was hiding. | |
| 105 | + * | |
| 106 | + * @param \FluentCommunity\App\Models\Feed $feed | |
| 107 | + * @return bool | |
| 108 | + */ | |
| 109 | + public static function commentsEnabled($feed) | |
| 110 | + { | |
| 111 | + $meta = $feed->meta; | |
| 112 | + | |
| 113 | + if (Arr::get($meta, 'comments_disabled') === 'yes') { | |
| 114 | + return false; | |
| 115 | + } | |
| 116 | + | |
| 117 | + $optIn = self::getOptInCommentTypes(); | |
| 118 | + | |
| 119 | + if (isset($optIn[$feed->type])) { | |
| 120 | + return Arr::get($meta, 'enable_comments', $optIn[$feed->type]) === 'yes'; | |
| 121 | + } | |
| 122 | + | |
| 123 | + return true; | |
| 124 | + } | |
| 125 | + | |
| 63 | 126 | public static function getLastFeedId() |
| 64 | 127 | { |
| 65 | 128 | $lastItem = Feed::where('status', 'published') |
| 66 | 129 | ->byUserAccess(get_current_user_id()) |
| @@ -124,8 +187,25 @@ | ||
| 124 | 187 | 'code' => array(), |
| 125 | 188 | 'pre' => array(), |
| 126 | 189 | 'blockquote' => array(), |
| 127 | 190 | 'del' => array(), |
| 191 | + 'table' => array(), | |
| 192 | + 'thead' => array(), | |
| 193 | + 'tbody' => array(), | |
| 194 | + 'tfoot' => array(), | |
| 195 | + 'tr' => array(), | |
| 196 | + 'th' => array( | |
| 197 | + 'align' => true, | |
| 198 | + 'style' => true, | |
| 199 | + 'colspan' => true, | |
| 200 | + 'rowspan' => true, | |
| 201 | + ), | |
| 202 | + 'td' => array( | |
| 203 | + 'align' => true, | |
| 204 | + 'style' => true, | |
| 205 | + 'colspan' => true, | |
| 206 | + 'rowspan' => true, | |
| 207 | + ), | |
| 128 | 208 | )); |
| 129 | 209 | |
| 130 | 210 | return self::maybeTransformDynamicCodes($html); |
| 131 | 211 | } |
| @@ -240,9 +320,17 @@ | ||
| 240 | 320 | |
| 241 | 321 | $profileUrlPrefix = Helper::baseUrl('u/'); |
| 242 | 322 | |
| 243 | 323 | foreach ($matches[2] as $href) { |
| 244 | - if (strpos($href, $profileUrlPrefix) === 0) { | |
| 324 | + // Rendered HTML encodes "&" as "&". Left encoded, "?a=1&b=2" is read | |
| 325 | + // as a parameter named "amp;b" — which makes YouTube drop the "list" param. | |
| 326 | + // Re-sanitized because decoding also restores quotes and angle brackets, | |
| 327 | + // and this value is fetched remotely and stored on the feed. | |
| 328 | + $href = sanitize_url(html_entity_decode($href, ENT_QUOTES | ENT_HTML5, 'UTF-8')); | |
| 329 | + | |
| 330 | + // sanitize_url() empties a disallowed scheme. Returning that would report | |
| 331 | + // "no links" for the whole post and skip any later, usable link. | |
| 332 | + if (!$href || strpos($href, $profileUrlPrefix) === 0) { | |
| 245 | 333 | continue; |
| 246 | 334 | } |
| 247 | 335 | return $href; |
| 248 | 336 | } |
| @@ -490,8 +578,13 @@ | ||
| 490 | 578 | $feedData['meta']['mentioned_user_ids'] = Arr::get($mentions, 'user_ids', []); |
| 491 | 579 | } |
| 492 | 580 | |
| 493 | 581 | $data = apply_filters('fluent_community/feed/new_feed_data', $feedData, $allData); |
| 582 | + | |
| 583 | + if (is_wp_error($data)) { | |
| 584 | + return $data; | |
| 585 | + } | |
| 586 | + | |
| 494 | 587 | $feed = new Feed(); |
| 495 | 588 | $feed->fill($data); |
| 496 | 589 | $feed->save(); |
| 497 | 590 | |
| @@ -518,9 +611,9 @@ | ||
| 518 | 611 | } |
| 519 | 612 | |
| 520 | 613 | public static function sanitizeAndValidateData($data) |
| 521 | 614 | { |
| 522 | - $message = CustomSanitizer::unslashMarkdown(trim(Arr::get($data, 'message'))); | |
| 615 | + $message = CustomSanitizer::unslashMarkdown(trim((string) Arr::get($data, 'message', ''))); | |
| 523 | 616 | |
| 524 | 617 | // Decode HTML entities and strip all whitespace for validation |
| 525 | 618 | $messageForValidation = html_entity_decode($message, ENT_QUOTES | ENT_HTML5, 'UTF-8'); |
| 526 | 619 | $messageForValidation = preg_replace('/\s+/u', '', $messageForValidation); |
| @@ -525,9 +618,12 @@ | ||
| 525 | 618 | $messageForValidation = html_entity_decode($message, ENT_QUOTES | ENT_HTML5, 'UTF-8'); |
| 526 | 619 | $messageForValidation = preg_replace('/\s+/u', '', $messageForValidation); |
| 527 | 620 | |
| 528 | 621 | if (!$messageForValidation) { |
| 529 | - throw new \Exception(esc_html__('Message is required', 'fluent-community')); | |
| 622 | + throw new UnprocessableEntityHttpException( | |
| 623 | + esc_html__('Message is required', 'fluent-community'), | |
| 624 | + 'feed_message_required' | |
| 625 | + ); | |
| 530 | 626 | } |
| 531 | 627 | |
| 532 | 628 | $processedData = [ |
| 533 | 629 | 'message' => $message, |
| @@ -567,10 +663,13 @@ | ||
| 567 | 663 | } |
| 568 | 664 | |
| 569 | 665 | $maxlen = apply_filters('fluent_community/max_post_length', 15000); |
| 570 | 666 | if (\strlen($message) > $maxlen) { |
| 571 | - /* translators: %s is the maximum allowed character count */ | |
| 572 | - throw new \Exception(esc_html(sprintf(__('The post is too long. Please keep it under %s characters.', 'fluent-community'), number_format($maxlen)))); | |
| 667 | + throw new UnprocessableEntityHttpException( | |
| 668 | + /* translators: %s is the maximum allowed character count */ | |
| 669 | + esc_html(sprintf(__('The post is too long. Please keep it under %s characters.', 'fluent-community'), number_format($maxlen))), | |
| 670 | + 'feed_message_too_long' | |
| 671 | + ); | |
| 573 | 672 | } |
| 574 | 673 | |
| 575 | 674 | $titlePref = Utility::postTitlePref(); |
| 576 | 675 | |
| @@ -576,9 +675,12 @@ | ||
| 576 | 675 | |
| 577 | 676 | if ($titlePref) { |
| 578 | 677 | $processedData['title'] = sanitize_text_field(Arr::get($data, 'title')); |
| 579 | 678 | if ($titlePref == 'required' && empty($processedData['title'])) { |
| 580 | - throw new \Exception(esc_html__('Title is required. Please provide a title', 'fluent-community')); | |
| 679 | + throw new UnprocessableEntityHttpException( | |
| 680 | + esc_html__('Title is required. Please provide a title', 'fluent-community'), | |
| 681 | + 'feed_title_required' | |
| 682 | + ); | |
| 581 | 683 | } |
| 582 | 684 | // trim the title if it's too long to 192 chars (multibyte-safe; column is VARCHAR(192) characters) |
| 583 | 685 | if (mb_strlen($processedData['title']) > 192) { |
| 584 | 686 | $processedData['title'] = mb_substr($processedData['title'], 0, 192, 'UTF-8'); |
| @@ -640,8 +742,9 @@ | ||
| 640 | 742 | ->where('is_active', 1) |
| 641 | 743 | ->get(); |
| 642 | 744 | $mediaIds = []; |
| 643 | 745 | foreach ($documents as $document) { |
| 746 | + /** @var Media $document */ | |
| 644 | 747 | $mediaIds[] = $document->getPrivateFileMeta(); |
| 645 | 748 | } |
| 646 | 749 | $feed->document_ids = $mediaIds; |
| 647 | 750 | $feed->load('space'); |
| @@ -669,11 +772,11 @@ | ||
| 669 | 772 | if ($type == 'oembed' || $type == 'iframe_html') { |
| 670 | 773 | $feed->media = $mediaPreview; |
| 671 | 774 | } |
| 672 | 775 | |
| 673 | - // Only fetch the specific attached media, not all media (which would include inline images) | |
| 776 | + // Only fetch the specific attached media, not all media (which would include inline images). | |
| 674 | 777 | $mediaId = Arr::get($mediaPreview, 'media_id'); |
| 675 | - if ($mediaId) { | |
| 778 | + if ($mediaId && $type != 'oembed' && $type != 'iframe_html') { | |
| 676 | 779 | $media = Media::where('id', $mediaId) |
| 677 | 780 | ->where('feed_id', $feed->id) |
| 678 | 781 | ->where('is_active', 1) |
| 679 | 782 | ->first(); |
| @@ -692,12 +795,68 @@ | ||
| 692 | 795 | $feed->meta = $meta; |
| 693 | 796 | } |
| 694 | 797 | } |
| 695 | 798 | |
| 799 | + // Preserve multi-audio so the edit composer can load, edit/remove, and re-save them | |
| 800 | + // (transformForEdit otherwise drops meta for audio-only posts). | |
| 801 | + $audioMedias = Arr::get($meta, 'audio_medias', []); | |
| 802 | + if ($audioMedias) { | |
| 803 | + $editMeta = (isset($feed->meta) && is_array($feed->meta)) ? $feed->meta : []; | |
| 804 | + $editMeta['audio_medias'] = $audioMedias; | |
| 805 | + $feed->meta = $editMeta; | |
| 806 | + } | |
| 807 | + | |
| 696 | 808 | $feed->load('space'); |
| 697 | 809 | return $feed; |
| 698 | 810 | } |
| 699 | 811 | |
| 812 | + /** | |
| 813 | + * Whether the current request may attach a raw "HTML Code" (iframe_html) embed. | |
| 814 | + * | |
| 815 | + * Mirrors the frontend rule in _VideoEmbeder.vue, which exposes that editor tab only | |
| 816 | + * when is_admin is true — i.e. community_moderator globally or within the target | |
| 817 | + * space. Programmatic creation is judged on the supplied author's permission rather | |
| 818 | + * than the HTTP session, so integrations work without a logged-in user. Defaults to | |
| 819 | + * denying when no user can be established at all. | |
| 820 | + * | |
| 821 | + * @param array $requestData Raw request payload. | |
| 822 | + * @param array $data Feed data being assembled. | |
| 823 | + * @param \FluentCommunity\App\Models\Feed|null $existingFeed Set when editing. | |
| 824 | + * @return bool | |
| 825 | + */ | |
| 826 | + private static function canEmbedRawHtml($requestData, $data, $existingFeed = null) | |
| 827 | + { | |
| 828 | + // FeedsController::store()/update() already resolved this against the target space. | |
| 829 | + $precomputed = Arr::get($requestData, 'is_admin'); | |
| 830 | + if ($precomputed !== null) { | |
| 831 | + return (bool)$precomputed; | |
| 832 | + } | |
| 833 | + | |
| 834 | + // Every other caller resolves it here, against the post's author where one has | |
| 835 | + // been established server-side (createFeed() takes user_id from its caller), and | |
| 836 | + // the current user otherwise. Read from $data and never $requestData: the author | |
| 837 | + // is assigned by the controller, so a request cannot nominate whose permission | |
| 838 | + // gets checked. | |
| 839 | + $userId = (int)Arr::get($data, 'user_id'); | |
| 840 | + if (!$userId) { | |
| 841 | + $userId = get_current_user_id(); | |
| 842 | + } | |
| 843 | + | |
| 844 | + $user = $userId ? User::find($userId) : null; | |
| 845 | + if (!$user) { | |
| 846 | + return false; | |
| 847 | + } | |
| 848 | + | |
| 849 | + $space = null; | |
| 850 | + if ($existingFeed) { | |
| 851 | + $space = $existingFeed->space; | |
| 852 | + } elseif ($spaceId = (Arr::get($data, 'space_id') ?: Arr::get($requestData, 'space_id'))) { | |
| 853 | + $space = BaseSpace::find($spaceId); | |
| 854 | + } | |
| 855 | + | |
| 856 | + return (bool)$user->hasPermissionOrInCurrentSpace('community_moderator', $space); | |
| 857 | + } | |
| 858 | + | |
| 700 | 859 | public static function processFeedMetaData($data, $requestData, $existingFeed = null) |
| 701 | 860 | { |
| 702 | 861 | if (empty($data['meta'])) { |
| 703 | 862 | $data['meta'] = []; |
| @@ -765,10 +924,32 @@ | ||
| 765 | 924 | Arr::get($requestData, 'media.type') == 'iframe_html' |
| 766 | 925 | ) |
| 767 | 926 | ) { |
| 768 | 927 | if (Arr::get($requestData, 'media.type') == 'iframe_html') { |
| 928 | + // The UI only offers the "HTML Code" embed to moderators | |
| 929 | + // (_VideoEmbeder.vue passes has_iframe="is_admin"). That is a hint, not a | |
| 930 | + // control, so the same rule is enforced here. Reaching this branch without | |
| 931 | + // the permission means the field was posted straight to the REST API, so | |
| 932 | + // the embed is dropped rather than stored. | |
| 933 | + if (!self::canEmbedRawHtml($requestData, $data, $existingFeed)) { | |
| 934 | + return [$data, $uplaodedDocs]; | |
| 935 | + } | |
| 936 | + | |
| 769 | 937 | $mediaPreview = array_filter(Arr::get($requestData, 'media', [])); |
| 770 | 938 | |
| 939 | + // Moderators are trusted to embed, not to bypass sanitization: the markup | |
| 940 | + // still goes through the same allowlist the oembed branch below uses. | |
| 941 | + if (!empty($mediaPreview['html'])) { | |
| 942 | + $mediaPreview['html'] = RemoteUrlParser::sanitizeOembedHtml($mediaPreview['html']); | |
| 943 | + | |
| 944 | + // Keep only if a usable <iframe> survived; else it renders as junk. | |
| 945 | + if (stripos($mediaPreview['html'], '<iframe') === false) { | |
| 946 | + unset($mediaPreview['html']); | |
| 947 | + } | |
| 948 | + | |
| 949 | + $mediaPreview = array_filter($mediaPreview); | |
| 950 | + } | |
| 951 | + | |
| 771 | 952 | if (empty($mediaPreview['image']) && !empty($mediaPreview['html'])) { |
| 772 | 953 | $thumb = RemoteUrlParser::extractIframeThumbnail($mediaPreview['html']); |
| 773 | 954 | if ($thumb) { |
| 774 | 955 | $mediaPreview['image'] = $thumb; |
| @@ -774,8 +955,13 @@ | ||
| 774 | 955 | $mediaPreview['image'] = $thumb; |
| 775 | 956 | } |
| 776 | 957 | } |
| 777 | 958 | |
| 959 | + // Nothing usable survived; skip storing a broken preview. | |
| 960 | + if (empty($mediaPreview['html']) && empty($mediaPreview['image'])) { | |
| 961 | + return [$data, $uplaodedDocs]; | |
| 962 | + } | |
| 963 | + | |
| 778 | 964 | $data['meta']['media_preview'] = $mediaPreview; |
| 779 | 965 | return [$data, $uplaodedDocs]; |
| 780 | 966 | } |
| 781 | 967 | |
| @@ -939,11 +1125,27 @@ | ||
| 939 | 1125 | $feedMeta['document_lists'] = $documentLists; |
| 940 | 1126 | $feed->meta = $feedMeta; |
| 941 | 1127 | } |
| 942 | 1128 | |
| 943 | - $spaceSettings = Space::where('id', $feed->space_id)->value('settings'); | |
| 1129 | + $spaceSettings = $feed->space ? $feed->space->settings : []; | |
| 944 | 1130 | $feed->default_comment_sort_by = Arr::get($spaceSettings, 'default_comment_sort_by', ''); |
| 945 | 1131 | |
| 1132 | + // Feed::withPublicRelations() eager-loads the space with its raw settings, and | |
| 1133 | + // those settings carry links scoped to logged-in members or to specific | |
| 1134 | + // memberships. BaseSpace::formatSpaceData() filters them for the space | |
| 1135 | + // endpoints; nothing filtered them here, so every feed response handed all of | |
| 1136 | + // a space's links - titles and URLs - to any caller, anonymous included. | |
| 1137 | + if ($feed->space && Arr::get($spaceSettings, 'links')) { | |
| 1138 | + $currentUser = Helper::getCurrentUser(); | |
| 1139 | + | |
| 1140 | + $spaceSettings['links'] = Helper::filterAccessibleLinks( | |
| 1141 | + Arr::get($spaceSettings, 'links', []), | |
| 1142 | + $currentUser ? $currentUser : null | |
| 1143 | + ); | |
| 1144 | + | |
| 1145 | + $feed->space->settings = $spaceSettings; | |
| 1146 | + } | |
| 1147 | + | |
| 946 | 1148 | self::setCurrentRelatedUserId($feed->user_id); |
| 947 | 1149 | |
| 948 | 1150 | return apply_filters('fluent_community/rendering_feed_model', $feed, $config); |
| 949 | 1151 | } |
| @@ -1042,9 +1244,9 @@ | ||
| 1042 | 1244 | $feedHtml = ''; |
| 1043 | 1245 | |
| 1044 | 1246 | if ($mediaImage) { |
| 1045 | 1247 | $feedHtml .= '<div class="fcom_media" style="margin-top: 20px;">'; |
| 1046 | - $feedHtml .= '<a href="' . $postPermalink . '"><img src="' . $mediaImage . '" style="max-width: 100%; height: auto; display: block; margin: 0 auto 0px;" /></a>'; | |
| 1248 | + $feedHtml .= '<a href="' . $postPermalink . '"><img src="' . $mediaImage . '" alt="" style="max-width: 100%; height: auto; display: block; margin: 0 auto 0px;" /></a>'; | |
| 1047 | 1249 | if ($mediaCount > 1) { |
| 1048 | 1250 | /* translators: %d is the number of additional images not shown in the preview. */ |
| 1049 | 1251 | $feedHtml .= '<p style="text-align: center; font-size: 14px; color: #666; margin-top: 10px;">' . sprintf(_n('+%d more image', '+%d more images', $mediaCount - 1, 'fluent-community'), $mediaCount - 1) . '</p>'; |
| 1050 | 1252 | } |