PluginProbe ʕ •ᴥ•ʔ
Independent Analytics – WordPress Analytics Plugin / 1.17
Independent Analytics – WordPress Analytics Plugin v1.17
2.15.0 2.14.10 trunk 1.1 1.10 1.10.1 1.11 1.12 1.13 1.14 1.15 1.16 1.17 1.17.1 1.17.2 1.17.3 1.17.4 1.18 1.18.1 1.19.0 1.19.1 1.2 1.20.0 1.21.0 1.22.0 1.22.1 1.23.0 1.23.1 1.24.0 1.24.1 1.25.0 1.25.1 1.26.0 1.27.0 1.28.0 1.28.1 1.28.2 1.28.3 1.29.0 1.3 1.30.0 1.30.1 1.4 1.5 1.6 1.7 1.8 1.9 2.0.0 2.0.1 2.1.4 2.1.5 2.1.6 2.10.0 2.10.1 2.10.2 2.10.3 2.10.4 2.11.0 2.11.1 2.11.10 2.11.2 2.11.3 2.11.4 2.11.5 2.11.6 2.11.7 2.11.8 2.11.9 2.12.0 2.12.1 2.12.2 2.13.1 2.13.2 2.13.5 2.13.6 2.14.0 2.14.1 2.14.2 2.14.4 2.14.6 2.14.7 2.14.8 2.14.9 2.2.0 2.2.1 2.3.1 2.3.2 2.4.2 2.4.3 2.5.0 2.5.1 2.6.0 2.6.1 2.6.2 2.6.3 2.6.4 2.7.0 2.7.1 2.7.2 2.7.3 2.8.2 2.8.3 2.8.4 2.8.5 2.8.6 2.8.7 2.8.8 2.8.9 2.9.2 2.9.3 2.9.4 2.9.5 2.9.6 2.9.7
independent-analytics / IAWP / ajax / ajax.php
independent-analytics / IAWP / ajax Last commit date
ajax.php 3 years ago cleared_cache_ajax.php 3 years ago create_campaign_ajax.php 3 years ago delete_data_ajax.php 3 years ago export_campaigns_ajax.php 3 years ago export_geo_ajax.php 3 years ago export_referrers_ajax.php 3 years ago export_views_ajax.php 3 years ago filters_ajax.php 3 years ago migration_status_ajax.php 3 years ago real_time_ajax.php 3 years ago test_email_ajax.php 3 years ago update_capabilities_ajax.php 3 years ago
ajax.php
107 lines
1 <?php
2
3 namespace IAWP;
4
5 abstract class AJAX
6 {
7 public function __construct()
8 {
9 add_action('wp_ajax_' . $this->action_name(), [$this, 'intercept_ajax']);
10 }
11
12 /**
13 * Classes must define an action name for the ajax request
14 *
15 * The required nonce for the ajax request will be the action name with a "_nonce" postfix
16 * Example: "iawp_delete_data" require a "iawp_delete_data_nonce" nonce field
17 *
18 * @return string
19 */
20 abstract protected function action_name(): string;
21
22 /**
23 * Classes must define an action callback to run when an ajax request is made
24 *
25 * @return void
26 */
27 abstract protected function action_callback(): void;
28
29 /**
30 * Classes can define a set of required fields for an ajax request
31 *
32 * @return array
33 */
34 protected function action_required_fields(): array
35 {
36 return [];
37 }
38
39 /**
40 * This is the direct handler for ajax requests.
41 * Permissions and nonce values are checked before executing the ajax action_callback function.
42 *
43 * @return void
44 */
45 final public function intercept_ajax(): void
46 {
47 // Todo - Should this be can_edit() instead?
48 $is_not_migrating = $this->allowed_during_migrations() || !Migrations\Migration::is_migrating();
49 $valid_fields = !$this->missing_fields();
50 $can_view = Capability_Manager::can_view();
51
52 check_ajax_referer($this->action_name(), $this->action_name() . '_nonce');
53
54 if ($is_not_migrating && $valid_fields && $can_view) {
55 $this->action_callback();
56 } else {
57 wp_send_json_error([
58 'errorMessage' => 'Unable to process IAWP AJAX request',
59 ]);
60 }
61
62 wp_die();
63 }
64
65 /**
66 * Override method to allow the AJAX request to run during migrations
67 *
68 * @return bool false by default
69 */
70 protected function allowed_during_migrations(): bool
71 {
72 return false;
73 }
74
75 /**
76 * Get a field value. This method supports text and arrays. Returns array if no field found.
77 *
78 * @param $field_name
79 * @return array|string|null
80 */
81 final protected function get_field($field_name)
82 {
83 if (!array_key_exists($field_name, $_POST)) {
84 return null;
85 }
86
87 $type = gettype($_POST[$field_name]);
88
89 if ($type == 'array') {
90 return rest_sanitize_array($_POST[$field_name]);
91 } else {
92 return sanitize_text_field($_POST[$field_name]);
93 }
94 }
95
96 private function missing_fields(): bool
97 {
98 foreach ($this->action_required_fields() as $required_field) {
99 if (!array_key_exists($required_field, $_POST)) {
100 return true;
101 }
102 }
103
104 return false;
105 }
106 }
107