PluginProbe
iframe / 5.1
iframe v5.1
trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7 1.8 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 2.9 3.0 4.0 4.1 4.2 4.3 All 35 releases
← All changes | iframe.php +46 -39 3.05.1 View file →
@@ -1,19 +1,24 @@
1 1 <?php
2 2 /*
3 3 Plugin Name: iframe
4 4 Plugin URI: http://wordpress.org/plugins/iframe/
5 -Description: [iframe src="http://www.youtube.com/embed/4qsGTXLnmKs" width="100%" height="500"] shortcode
6 -Version: 3.0
5 +Description: [iframe src="http://www.youtube.com/embed/dUpTjDqjQoo" width="100%" height="500"] shortcode
6 +Version: 5.1
7 7 Author: webvitaly
8 -Author URI: http://web-profile.com.ua/wordpress/plugins/
8 +Author URI: http://web-profile.net/wordpress/plugins/
9 9 License: GPLv3
10 10 */
11 11
12 +if ( ! defined( 'ABSPATH' ) ) { // Avoid direct calls to this file and prevent full path disclosure
13 + exit;
14 +}
12 15
13 -function iframe_unqprfx_embed_shortcode( $atts, $content = null ) {
16 +define('IFRAME_PLUGIN_VERSION', '5.1');
17 +
18 +function iframe_plugin_add_shortcode_cb( $atts ) {
14 19 $defaults = array(
15 - 'src' => 'http://www.youtube.com/embed/4qsGTXLnmKs',
20 + //'src' => 'http://www.youtube.com/embed/dUpTjDqjQoo',
16 21 'width' => '100%',
17 22 'height' => '500',
18 23 'scrolling' => 'yes',
19 24 'class' => 'iframe-class',
@@ -19,8 +24,12 @@
19 24 'class' => 'iframe-class',
20 25 'frameborder' => '0'
21 26 );
22 27
28 + if ( ! is_array( $atts ) ) {
29 + $atts = array();
30 + }
31 +
23 32 foreach ( $defaults as $default => $value ) { // add defaults
24 33 if ( ! @array_key_exists( $default, $atts ) ) { // mute warning with "@" when no params at all
25 34 $atts[$default] = $value;
26 35 }
@@ -25,35 +34,30 @@
25 34 $atts[$default] = $value;
26 35 }
27 36 }
28 37
29 - // get_params_from_url
30 - if ( isset( $atts["get_params_from_url"] ) && ( $atts["get_params_from_url"] == '1' || $atts["get_params_from_url"] == 1 ) ) {
31 - $encode_string = '';
32 - if ( $_GET != NULL ) {
33 - if ( strpos( $atts["src"], '?' ) ) { // if we already have '?' and GET params
34 - $encode_string = '&';
35 - } else {
36 - $encode_string = '?';
37 - }
38 - foreach( $_GET as $key => $value ) {
39 - $encode_string .= $key.'='.$value.'&';
40 - }
38 + $html = "\n".'<!-- iframe plugin v.'.IFRAME_PLUGIN_VERSION.' wordpress.org/plugins/iframe/ -->'."\n";
39 + $html .= '<iframe';
40 + foreach( $atts as $attr => $value ) {
41 + if ( strtolower($attr) == 'src' ) { // sanitize url
42 + $value = esc_url( $value );
41 43 }
42 - $encode_string = rtrim($encode_string, '&'); // remove last '&'
43 - $atts["src"] .= $encode_string;
44 - }
45 44
46 - $html = "\n".'<!-- iframe plugin v.3.0 wordpress.org/plugins/iframe/ -->'."\n";
47 - $html .= '<iframe';
48 - foreach( $atts as $attr => $value ) {
49 - if ( $attr != 'same_height_as' ) { // remove some attributes
50 - if ( $value != '' ) { // adding all attributes
51 - $html .= ' ' . $attr . '="' . $value . '"';
52 - } else { // adding empty attributes
53 - $html .= ' ' . $attr;
54 - }
45 + // Remove 'srcdoc' attribute
46 + if ( strtolower($attr) == 'srcdoc' ) {
47 + continue;
55 48 }
49 +
50 + // Skip attributes starting with "on". Examples: onload, onmouseover, onfocus, onpageshow, onclick
51 + if ( strpos( strtolower( $attr ), 'on' ) === 0 ) {
52 + continue;
53 + }
54 +
55 + if ($value !== '') { // adding all attributes
56 + $html .= ' ' . esc_attr($attr) . '="' . esc_attr($value) . '"';
57 + } else { // adding empty attributes
58 + $html .= ' ' . esc_attr($attr);
59 + }
56 60 }
57 61 $html .= '></iframe>'."\n";
58 62
59 63 if ( isset( $atts["same_height_as"] ) ) {
@@ -60,10 +64,10 @@
60 64 $html .= '
61 65 <script>
62 66 document.addEventListener("DOMContentLoaded", function(){
63 67 var target_element, iframe_element;
64 - iframe_element = document.querySelector("iframe.' . $atts["class"] . '");
65 - target_element = document.querySelector("' . $atts["same_height_as"] . '");
68 + iframe_element = document.querySelector("iframe.' . esc_attr( $atts["class"] ) . '");
69 + target_element = document.querySelector("' . esc_attr( $atts["same_height_as"] ) . '");
66 70 iframe_element.style.height = target_element.offsetHeight + "px";
67 71 });
68 72 </script>
69 73 ';
@@ -70,16 +74,19 @@
70 74 }
71 75
72 76 return $html;
73 77 }
74 -add_shortcode( 'iframe', 'iframe_unqprfx_embed_shortcode' );
78 +add_shortcode( 'iframe', 'iframe_plugin_add_shortcode_cb' );
75 79
76 80
77 -function iframe_unqprfx_plugin_meta( $links, $file ) { // add 'Plugin page' and 'Donate' links to plugin meta row
78 - if ( strpos( $file, 'iframe.php' ) !== false ) {
79 - $links = array_merge( $links, array( '<a href="http://web-profile.com.ua/wordpress/plugins/iframe/" title="Plugin page">Iframe</a>' ) );
80 - $links = array_merge( $links, array( '<a href="http://web-profile.com.ua/donate/" title="Support the development">Donate</a>' ) );
81 - $links = array_merge( $links, array( '<a href="http://codecanyon.net/item/advanced-iframe-pro/5344999?ref=webvitaly">Advanced iFrame Pro</a>' ) );
81 +function iframe_plugin_row_meta_cb( $links, $file ) {
82 + if ( $file == plugin_basename( __FILE__ ) ) {
83 + $row_meta = array(
84 + 'support' => '<a href="http://web-profile.net/wordpress/plugins/iframe/" target="_blank">' . __( 'Iframe', 'iframe' ) . '</a>',
85 + 'donate' => '<a href="http://web-profile.net/donate/" target="_blank">' . __( 'Donate', 'iframe' ) . '</a>',
86 + 'pro' => '<a href="https://1.envato.market/Ym5aq" target="_blank">' . __( 'Advanced iFrame Pro', 'iframe' ) . '</a>'
87 + );
88 + $links = array_merge( $links, $row_meta );
82 89 }
83 - return $links;
90 + return (array) $links;
84 91 }
85 -add_filter( 'plugin_row_meta', 'iframe_unqprfx_plugin_meta', 10, 2 );
92 +add_filter( 'plugin_row_meta', 'iframe_plugin_row_meta_cb', 10, 2 );