PluginProbe
Groups – Memberships and Access Control / 4.7.1
Groups – Memberships and Access Control v4.7.1
4.8.0 4.7.1 4.7.0 4.6.0 4.5.0 4.4.0 4.3.0 trunk 1.0.0-beta-1 1.0.0-beta-2 1.0.0-beta-3 1.0.0-beta-3b 1.0.0-beta-3c 1.0.0-beta-3d 1.1.4 1.1.5 1.10.0 1.10.1 1.10.2 1.10.3 1.11.0 1.11.1 1.11.2 1.11.3 1.12.0 All 132 releases
← All changes | lib/access/class-groups-access-shortcodes.php +51 -19 1.11.1 → 4.7.1 View file →
@@ -44,28 +44,36 @@
44 44
45 45 /**
46 46 * Takes one attribute "group" which is a comma-separated list of group
47 47 * names or ids (can be mixed).
48 + *
48 49 * The content is shown if the current user belongs to the group(s).
49 - *
50 + *
50 51 * @param array $atts attributes
51 52 * @param string $content content to render
53 + *
54 + * @return string
52 55 */
53 56 public static function groups_member( $atts, $content = null ) {
54 - $output = "";
55 - $options = shortcode_atts( array( "group" => "" ), $atts );
57 +
58 + if ( !Groups_Shortcodes::validate( 'groups_member', $atts, $content ) ) {
59 + return '';
60 + }
61 +
62 + $output = '';
63 + $options = shortcode_atts( array( 'group' => '' ), $atts );
56 64 $show_content = false;
57 65 if ( $content !== null ) {
58 66 $groups_user = new Groups_User( get_current_user_id() );
59 - $groups = explode( ",", $options['group'] );
67 + $groups = explode( ',', $options['group'] );
60 68 foreach ( $groups as $group ) {
61 - $group = trim( $group );
69 + $group = addslashes( trim( $group ) );
62 70 $current_group = Groups_Group::read( $group );
63 71 if ( !$current_group ) {
64 72 $current_group = Groups_Group::read_by_name( $group );
65 73 }
66 74 if ( $current_group ) {
67 - if ( Groups_User_Group::read( $groups_user->user->ID , $current_group->group_id ) ) {
75 + if ( $groups_user->is_member( $current_group->group_id ) ) {
68 76 $show_content = true;
69 77 break;
70 78 }
71 79 }
@@ -82,28 +90,36 @@
82 90
83 91 /**
84 92 * Takes one attribute "group" which is a comma-separated list of group
85 93 * names or ids (can be mixed).
94 + *
86 95 * The content is shown if the current user does NOT belong to the group(s).
87 96 *
88 97 * @param array $atts attributes
89 98 * @param string $content content to render
99 + *
100 + * @return string
90 101 */
91 102 public static function groups_non_member( $atts, $content = null ) {
92 - $output = "";
93 - $options = shortcode_atts( array( "group" => "" ), $atts );
103 +
104 + if ( !Groups_Shortcodes::validate( 'groups_non_member', $atts, $content ) ) {
105 + return '';
106 + }
107 +
108 + $output = '';
109 + $options = shortcode_atts( array( 'group' => '' ), $atts );
94 110 $show_content = true;
95 111 if ( $content !== null ) {
96 112 $groups_user = new Groups_User( get_current_user_id() );
97 - $groups = explode( ",", $options['group'] );
113 + $groups = explode( ',', $options['group'] );
98 114 foreach ( $groups as $group ) {
99 - $group = trim( $group );
115 + $group = addslashes( trim( $group ) );
100 116 $current_group = Groups_Group::read( $group );
101 117 if ( !$current_group ) {
102 118 $current_group = Groups_Group::read_by_name( $group );
103 119 }
104 120 if ( $current_group ) {
105 - if ( Groups_User_Group::read( $groups_user->user->ID , $current_group->group_id ) ) {
121 + if ( $groups_user->is_member( $current_group->group_id ) ) {
106 122 $show_content = false;
107 123 break;
108 124 }
109 125 }
@@ -120,22 +136,30 @@
120 136
121 137 /**
122 138 * Takes one attribute "capability" that must be a valid capability label
123 139 * or a list of capabilities separated by comma.
140 + *
124 141 * The content is shown if the current user has one of the capabilities.
125 - *
142 + *
126 143 * @param array $atts attributes
127 144 * @param string $content content to render
145 + *
146 + * @return string
128 147 */
129 148 public static function groups_can( $atts, $content = null ) {
130 - $output = "";
131 - $options = shortcode_atts( array( "capability" => "" ), $atts );
149 +
150 + if ( !Groups_Shortcodes::validate( 'groups_can', $atts, $content ) ) {
151 + return '';
152 + }
153 +
154 + $output = '';
155 + $options = shortcode_atts( array( 'capability' => '' ), $atts );
132 156 if ( $content !== null ) {
133 157 $groups_user = new Groups_User( get_current_user_id() );
134 158 $capability = $options['capability'];
135 159 $capabilities = array_map( 'trim', explode( ',', $capability ) );
136 160 $show_content = false;
137 - foreach( $capabilities as $capability ) {
161 + foreach ( $capabilities as $capability ) {
138 162 if ( $groups_user->can( $capability ) ) {
139 163 $show_content = true;
140 164 break;
141 165 }
@@ -151,23 +175,31 @@
151 175 }
152 176
153 177 /**
154 178 * Takes one attribute "capability" that must be a valid capability label,
155 - * or a comma-separaed list of those.
179 + * or a comma-separated list of those.
180 + *
156 181 * The content is shown if the current user has none of the capabilities.
157 182 *
158 183 * @param array $atts attributes
159 184 * @param string $content content to render
185 + *
186 + * @return string
160 187 */
161 188 public static function groups_can_not( $atts, $content = null ) {
162 - $output = "";
163 - $options = shortcode_atts( array( "capability" => "" ), $atts );
189 +
190 + if ( !Groups_Shortcodes::validate( 'groups_can_not', $atts, $content ) ) {
191 + return '';
192 + }
193 +
194 + $output = '';
195 + $options = shortcode_atts( array( 'capability' => '' ), $atts );
164 196 if ( $content !== null ) {
165 197 $groups_user = new Groups_User( get_current_user_id() );
166 198 $capability = $options['capability'];
167 199 $capabilities = array_map( 'trim', explode( ',', $capability ) );
168 200 $show_content = true;
169 - foreach( $capabilities as $capability ) {
201 + foreach ( $capabilities as $capability ) {
170 202 if ( $groups_user->can( $capability ) ) {
171 203 $show_content = false;
172 204 break;
173 205 }