PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.16.9
GiveWP – Donation Plugin and Fundraising Platform v4.16.9
4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 2.3.2 2.30.0 All 255 releases
← All changes | includes/admin/tools/export/export-functions.php +50 -33 2.3.04.16.9 View file →
@@ -5,9 +5,9 @@
5 5 * These functions are used for exporting data from Give
6 6 *
7 7 * @package Give
8 8 * @subpackage Admin/Export
9 - * @copyright Copyright (c) 2016, WordImpress
9 + * @copyright Copyright (c) 2016, GiveWP
10 10 * @license https://opensource.org/licenses/gpl-license GNU Public License
11 11 */
12 12
13 13 // Exit if accessed directly.
@@ -15,12 +15,12 @@
15 15 exit;
16 16 }
17 17
18 18
19 -
20 19 /**
21 20 * Process batch exports via ajax
22 21 *
22 + * @since 2.21.0 Sanitize file name. Allow plain file name only.
23 23 * @since 1.5
24 24 * @return void
25 25 */
26 26 function give_do_ajax_export() {
@@ -30,9 +30,12 @@
30 30 parse_str( $_POST['form'], $form );
31 31
32 32 $_REQUEST = $form = (array) $form;
33 33
34 - if ( ! wp_verify_nonce( $_REQUEST['give_ajax_export'], 'give_ajax_export' ) ) {
34 + if (
35 + ! wp_verify_nonce( $_REQUEST['give_ajax_export'], 'give_ajax_export' ) ||
36 + ! current_user_can( 'manage_give_settings' )
37 + ) {
35 38 die( '-2' );
36 39 }
37 40
38 41 /**
@@ -43,13 +46,20 @@
43 46 * @param string $class Export class.
44 47 */
45 48 do_action( 'give_batch_export_class_include', $form['give-export-class'] );
46 49
47 - $step = absint( $_POST['step'] );
48 - $class = sanitize_text_field( $form['give-export-class'] );
50 + if( ! is_subclass_of( $form['give-export-class'], \Give_Batch_Export::class ) ) {
51 + die(-2);
52 + }
49 53
54 + $step = absint( $_POST['step'] );
55 + $class = sanitize_text_field( $form['give-export-class'] );
56 + $filename = isset( $_POST['file_name'] ) ?
57 + basename(sanitize_file_name( $_POST['file_name'] ), '.csv') :
58 + null;
59 +
50 60 /* @var Give_Batch_Export $export */
51 - $export = new $class( $step );
61 + $export = new $class( $step, $filename );
52 62
53 63 if ( ! $export->can_export() ) {
54 64 die( '-1' );
55 65 }
@@ -54,13 +64,13 @@
54 64 die( '-1' );
55 65 }
56 66
57 67 if ( ! $export->is_writable ) {
58 - $json_args = array(
68 + $json_args = [
59 69 'error' => true,
60 - 'message' => esc_html__( 'Export location or file not writable.', 'give' )
61 - );
62 - echo json_encode($json_args);
70 + 'message' => esc_html__( 'Export location or file not writable.', 'give' ),
71 + ];
72 + echo json_encode( $json_args );
63 73 exit;
64 74 }
65 75
66 76 $export->set_properties( give_clean( $_REQUEST ) );
@@ -72,20 +82,21 @@
72 82 $percentage = $export->get_percentage_complete();
73 83
74 84 if ( $ret ) {
75 85
76 - $step += 1;
77 - $json_data = array(
78 - 'step' => $step,
79 - 'percentage' => $percentage
80 - );
86 + $step += 1;
87 + $json_data = [
88 + 'step' => $step,
89 + 'percentage' => $percentage,
90 + 'file_name' => $export->filename,
91 + ];
81 92
82 93 } elseif ( true === $export->is_empty ) {
83 94
84 - $json_data = array(
95 + $json_data = [
85 96 'error' => true,
86 - 'message' => esc_html__( 'No data found for export parameters.', 'give' )
87 - );
97 + 'message' => esc_html__( 'No data found for export parameters.', 'give' ),
98 + ];
88 99
89 100 } elseif ( true === $export->done && true === $export->is_void ) {
90 101
91 102 $message = ! empty( $export->message ) ?
@@ -91,26 +102,30 @@
91 102 $message = ! empty( $export->message ) ?
92 103 $export->message :
93 104 esc_html__( 'Batch Processing Complete', 'give' );
94 105
95 - $json_data = array(
106 + $json_data = [
96 107 'success' => true,
97 - 'message' => $message
98 - );
108 + 'message' => $message,
109 + ];
99 110
100 111 } else {
101 112
102 - $args = array_merge( $_REQUEST, array(
103 - 'step' => $step,
104 - 'class' => $class,
105 - 'nonce' => wp_create_nonce( 'give-batch-export' ),
106 - 'give_action' => 'form_batch_export',
107 - ) );
113 + $args = array_merge(
114 + $_REQUEST,
115 + [
116 + 'step' => $step,
117 + 'class' => $class,
118 + 'nonce' => wp_create_nonce( 'give-batch-export' ),
119 + 'give_action' => 'form_batch_export',
120 + 'file_name' => $export->filename,
121 + ]
122 + );
108 123
109 - $json_data = array(
124 + $json_data = [
110 125 'step' => 'done',
111 - 'url' => add_query_arg( $args, admin_url() )
112 - );
126 + 'url' => esc_url_raw(add_query_arg( $args, admin_url() )),
127 + ];
113 128
114 129 }
115 130
116 131 $export->unset_properties( give_clean( $_REQUEST ), $export );
@@ -126,8 +141,9 @@
126 141 *
127 142 * Note: This function is for internal purposes only.
128 143 * Use filter "give_export_donors_get_default_columns" instead.
129 144 *
145 + * @since 3.12.1 add donor_phone_number column.
130 146 * @since 2.2.6
131 147 *
132 148 * @return array
133 149 */
@@ -132,17 +148,18 @@
132 148 * @return array
133 149 */
134 150 function give_export_donors_get_default_columns() {
135 151
136 - $default_columns = array(
152 + $default_columns = [
137 153 'full_name' => __( 'Name', 'give' ),
138 154 'email' => __( 'Email', 'give' ),
139 155 'address' => __( 'Address', 'give' ),
140 156 'userid' => __( 'User ID', 'give' ),
141 157 'donor_created_date' => __( 'Donor Created Date', 'give' ),
142 - 'donations' => __( 'Number of donations', 'give' ),
158 + 'donor_phone_number' => __( 'Donor Phone Number', 'give' ),
159 + 'donations' => __( 'Number of donations', 'give' ),
143 160 'donation_sum' => __( 'Total Donated', 'give' ),
144 - );
161 + ];
145 162
146 163 /**
147 164 * This filter will be used to define default columns for export.
148 165 *