← All changes
|
app/Services/Integrations/GlobalIntegrationService.php
+21
-1
6.2.13
→
6.2.15
View file →
| @@ -2,8 +2,9 @@ | ||
| 2 | 2 | |
| 3 | 3 | namespace FluentForm\App\Services\Integrations; |
| 4 | 4 | |
| 5 | 5 | use Exception; |
| 6 | +use FluentForm\App\Modules\AddOnModule; | |
| 6 | 7 | use FluentForm\Framework\Support\Arr; |
| 7 | 8 | class GlobalIntegrationService |
| 8 | 9 | { |
| 9 | 10 | // Sentinel written over connected credential values on read (FINDING-16) and |
| @@ -126,10 +127,16 @@ | ||
| 126 | 127 | if (!$moduleKey || !in_array($moduleStatus, ['yes', 'no'])) { |
| 127 | 128 | // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Exception message, not output |
| 128 | 129 | throw new Exception(__('Status update failed. Not valid module or status', 'fluentform')); |
| 129 | 130 | } |
| 131 | + $modules = (array)get_option('fluentform_global_modules_status'); | |
| 132 | + | |
| 133 | + if (!$this->isTogglableModuleKey($moduleKey, $modules)) { | |
| 134 | + // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Exception message, not output | |
| 135 | + throw new Exception(__('Status update failed. Not valid module or status', 'fluentform')); | |
| 136 | + } | |
| 137 | + | |
| 130 | 138 | try { |
| 131 | - $modules = (array)get_option('fluentform_global_modules_status'); | |
| 132 | 139 | $modules[$moduleKey] = $moduleStatus; |
| 133 | 140 | update_option('fluentform_global_modules_status', $modules, 'no'); |
| 134 | 141 | } catch (Exception $e) { |
| 135 | 142 | // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Exception message, not output |
| @@ -134,6 +141,19 @@ | ||
| 134 | 141 | } catch (Exception $e) { |
| 135 | 142 | // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Exception message, not output |
| 136 | 143 | throw new Exception($e->getMessage()); |
| 137 | 144 | } |
| 145 | + } | |
| 146 | + | |
| 147 | + /** | |
| 148 | + * Read from the live registry, never a second list here, so a newly registered add-on stays togglable. | |
| 149 | + * Administrators bypass it: this REST request misses add-ons that register only in wp-admin context. | |
| 150 | + */ | |
| 151 | + private function isTogglableModuleKey($moduleKey, array $storedModules) | |
| 152 | + { | |
| 153 | + if (current_user_can('manage_options') || array_key_exists($moduleKey, $storedModules)) { | |
| 154 | + return true; | |
| 155 | + } | |
| 156 | + | |
| 157 | + return array_key_exists($moduleKey, (array) (new AddOnModule())->getRegisteredAddOns()); | |
| 138 | 158 | } |
| 139 | 159 | } |