PluginProbe
Hostinger Tools / 2.0.7
Hostinger Tools v2.0.7
3.0.78 3.0.77 3.0.76 3.0.75 3.0.74 3.0.73 3.0.72 3.0.71 3.0.70 3.0.69 3.0.68 3.0.67 3.0.66 1.8.1 1.8.2 1.8.3 1.9.1 1.9.4 1.9.5 1.9.6 1.9.7 1.9.8 1.9.9 2.0.0 2.0.1 All 109 releases
← All changes | includes/admin/class-hostinger-admin-ajax.php +148 -42 1.9.7 → 2.0.7 View file →
@@ -2,29 +2,127 @@
2 2
3 3 defined( 'ABSPATH' ) || exit;
4 4
5 5 class Hostinger_Admin_Ajax {
6 + private const PROMOTIONAL_BANNER_TRANSIENT = 'hts_hide_promotional_banner_transient';
7 + private const TWO_DAYS = 172800;
8 + private Hostinger_Config $config_handler;
9 + private Hostinger_Settings $settings;
10 + private Hostinger_Helper $helper;
11 + private Hostinger_Surveys_Questions $survey_questions;
12 + private Hostinger_Surveys_Rest $surveys_rest;
6 13 public function __construct() {
7 - add_action( 'init', [ $this, 'define_ajax_events' ], 0 );
14 + $this->settings = new Hostinger_Settings();
15 + $this->helper = new Hostinger_Helper();
16 + $this->config_handler = new Hostinger_Config();
17 + if ( ! empty( Hostinger_Helper::get_api_token() ) ) {
18 + $this->survey_questions = new Hostinger_Surveys_Questions();
19 + $client = new Hostinger_Requests_Client(
20 + $this->config_handler->get_config_value( 'base_rest_uri', HOSTINGER_REST_URI ),
21 + array(
22 + Hostinger_Config::TOKEN_HEADER => $this->helper::get_api_token(),
23 + Hostinger_Config::DOMAIN_HEADER => $this->helper->get_host_info(),
24 + )
25 + );
26 +
27 + $this->surveys_rest = new Hostinger_Surveys_Rest( $client );
28 + }
29 +
30 + add_action( 'init', array( $this, 'define_ajax_events' ), 0 );
8 31 }
9 32
10 33 public function define_ajax_events(): void {
11 - $events = [
34 + $events = array(
12 35 'complete_onboarding_step',
13 36 'publish_website',
14 - 'track_click',
15 37 'identify_action',
16 38 'menu_action',
17 - ];
39 + 'woocommerce_setup_store',
40 + 'hide_promotional_banner',
41 + 'get_survey',
42 + 'submit_survey',
43 + );
18 44
19 45 foreach ( $events as $event ) {
20 - add_action( 'wp_ajax_hostinger_' . $event, [ __CLASS__, $event ] );
21 - add_action( 'wp_ajax_nopriv_hostinger_' . $event, [ __CLASS__, $event ] );
46 + add_action( 'wp_ajax_hostinger_' . $event, array( $this, $event ) );
22 47 }
23 48 }
24 49
50 + public function get_survey(): void {
51 + $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( $_POST['nonce'] ) : '';
52 + $type = sanitize_text_field( $_POST['type'] ) ?? 'ai_survey';
53 +
54 + $security_check = self::request_security_check( $nonce );
55 +
56 + if ( ! empty( $security_check ) ) {
57 + wp_send_json_error( $security_check );
58 + }
59 +
60 + $surveys = new Hostinger_Surveys( $this->settings, $this->helper, $this->config_handler, $this->survey_questions, $this->surveys_rest );
61 +
62 + $survey_questions = $surveys->get_wp_survey_questions();
63 + $questions_json = $surveys->get_specified_survey_questions( $survey_questions, $type );
64 +
65 + wp_send_json( $questions_json );
66 + }
67 +
68 + public function submit_survey(): void {
69 + $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( $_POST['nonce'] ) : '';
70 + $survey_type = sanitize_text_field( $_POST['type'] );
71 + $survey_results = sanitize_text_field( $_POST['survey_results'] );
72 + $surveys = new Hostinger_Surveys( $this->settings, $this->helper, $this->config_handler, $this->survey_questions, $this->surveys_rest );
73 +
74 + $security_check = self::request_security_check( $nonce );
75 +
76 + if ( ! empty( $security_check ) ) {
77 + wp_send_json_error( $security_check );
78 + }
79 +
80 + $decoded_json = json_decode( stripslashes( $survey_results ), true );
81 + $surveys->submit_survey_answers( $decoded_json, $survey_type );
82 + }
83 +
84 + public static function hide_promotional_banner(): void {
85 + $nonce = sanitize_text_field( $_POST['nonce'] );
86 + $transient_key = self::PROMOTIONAL_BANNER_TRANSIENT;
87 + $security_check = self::request_security_check( $nonce );
88 +
89 + if ( ! empty( $security_check ) ) {
90 + wp_send_json_error( $security_check );
91 + }
92 +
93 + if ( false === get_transient( $transient_key ) ) {
94 + set_transient( $transient_key, time(), self::TWO_DAYS );
95 + }
96 +
97 + wp_send_json_success( [] );
98 + }
99 +
100 + public static function woocommerce_setup_store(): void {
101 + $nonce = sanitize_text_field( $_POST['nonce'] );
102 + $event_action = sanitize_text_field( $_POST['event_action'] );
103 +
104 + $security_check = self::request_security_check( $nonce );
105 +
106 + if ( ! empty( $security_check ) ) {
107 + wp_send_json_error( $security_check );
108 + }
109 +
110 + $amplitude = new Hostinger_Amplitude();
111 + $amplitude->setup_store( $event_action );
112 +
113 + wp_send_json_success( [] );
114 + }
115 +
25 116 public static function publish_website(): void {
26 - $publish = (bool) $_POST['maintenance'];
117 + $publish = (bool) $_POST['maintenance'];
118 + $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( $_POST['nonce'] ) : '';
119 + $security_check = self::request_security_check( $nonce );
120 +
121 + if ( ! empty( $security_check ) ) {
122 + wp_send_json_error( $security_check );
123 + }
124 +
27 125 Hostinger_Settings::update_setting( 'maintenance_mode', $publish ? 1 : 0 );
28 126
29 127 require_once HOSTINGER_ABSPATH . 'includes/admin/onboarding/class-hostinger-onboarding.php';
30 128 $content = new Hostinger_Onboarding();
@@ -32,52 +130,46 @@
32 130 if ( has_action( 'litespeed_purge_all' ) ) {
33 131 do_action( 'litespeed_purge_all' );
34 132 }
35 133
36 - wp_send_json_success( [
37 - 'published' => $publish,
38 - 'title' => __( 'Website is published', 'hostinger' ),
39 - 'description' => __( 'Congratulations! Your website is online.', 'hostinger' ),
40 - 'content' => $content->get_content(),
41 - 'preview_url' => home_url(),
42 - ] );
134 + wp_send_json_success(
135 + array(
136 + 'published' => $publish,
137 + 'title' => __( 'Website is published', 'hostinger' ),
138 + 'description' => __( 'Congratulations! Your website is online.', 'hostinger' ),
139 + 'content' => $content->get_content(),
140 + 'preview_url' => home_url(),
141 + )
142 + );
43 143 }
44 144
45 145 public static function complete_onboarding_step(): void {
46 - $step = $_POST['step'];
47 - $completed_steps = get_option( 'hostinger_onboarding_steps', [] );
48 - if ( ! in_array( $step, array_column($completed_steps, 'action'), true ) ) {
49 - $completed_steps[] = [
146 + $step = $_POST['step'];
147 + $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( $_POST['nonce'] ) : '';
148 +
149 + $security_check = self::request_security_check( $nonce );
150 +
151 + if ( ! empty( $security_check ) ) {
152 + wp_send_json_error( $security_check );
153 + }
154 +
155 + $completed_steps = get_option( 'hostinger_onboarding_steps', array() );
156 + if ( ! in_array( $step, array_column( $completed_steps, 'action' ), true ) ) {
157 + $completed_steps[] = array(
50 158 'action' => $step,
51 159 'date' => date( 'Y-m-d H:i:s' ),
52 - ];
160 + );
53 161 }
54 162 Hostinger_Settings::update_setting( 'onboarding_steps', $completed_steps );
55 163
56 - wp_send_json_success( [] );
164 + wp_send_json_success( array() );
57 165 }
58 166
59 - public static function track_click(): void {
60 - $valid_options = [
61 - 'hostinger_preview_button_click'
62 - ];
63 -
64 - $click_action = $_POST['click_action'];
65 - if ( ! in_array( $click_action, $valid_options, true ) ) {
66 - wp_send_json_error( __( 'invalid data', 'hostinger' ) );
67 - }
68 -
69 - $click_count = get_option( $click_action, 0 );
70 - Hostinger_Settings::update_setting( $click_action, ++ $click_count, 'no' );
71 -
72 - wp_send_json_success( [] );
73 - }
74 -
75 167 public static function identify_action(): void {
76 168 $action = sanitize_text_field( $_POST['action_name'] ) ?? '';
77 169
78 170 if ( in_array( $action, Hostinger_Admin_Actions::ACTIONS_LIST, true ) ) {
79 - setcookie($action, $action, time() + (86400), '/');
171 + setcookie( $action, $action, time() + ( 86400 ), '/' );
80 172 wp_send_json_success( $action );
81 173 } else {
82 174 wp_send_json_error( 'Invalid action' );
83 175 }
@@ -83,20 +175,34 @@
83 175 }
84 176 }
85 177
86 178 public static function menu_action(): void {
179 + $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( $_POST['nonce'] ) : '';
180 + $location = sanitize_text_field( $_POST['location'] ) ?? '';
181 + $event_action = sanitize_text_field( $_POST['event_action'] ) ?? '';
87 182
88 - $nonce = sanitize_text_field( $_POST['nonce'] );
89 - $location = sanitize_text_field( $_POST['location'] ) ?? '';
90 - $event_action = sanitize_text_field( $_POST['event_action'] ) ?? '';
183 + $security_check = self::request_security_check( $nonce );
91 184
92 - if ( ! wp_verify_nonce( $nonce, 'hts-ajax-nonce' ) ) {
93 - wp_send_json_error( 'Invalid nonce.' );
185 + if ( ! empty( $security_check ) ) {
186 + wp_send_json_error( $security_check );
94 187 }
95 188
96 189 $amplitude = new Hostinger_Amplitude();
97 190 $amplitude->track_menu_action( $event_action, $location );
191 +
192 + wp_send_json_success( array() );
98 193 }
99 194
195 + public static function request_security_check( $nonce ) {
196 + if ( ! wp_verify_nonce( $nonce, 'hts-ajax-nonce' ) ) {
197 + return 'Invalid nonce';
198 + }
199 +
200 + if ( ! current_user_can( 'manage_options' ) ) {
201 + return 'Lack of permissions';
202 + }
203 +
204 + return false;
205 + }
100 206 }
101 207
102 208 new Hostinger_Admin_Ajax();