PluginProbe
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts / 2.2.7
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts v2.2.7
2.7.7 2.7.6 2.7.5 2.7.4 trunk 1.3 2.0.4 2.0.6 2.1.91 2.2.4 2.2.7 2.2.9 2.3.1 2.3.10 2.4.10 2.4.2 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 2.6.0 2.6.1 2.7.0 All 28 releases
insert-php / includes / shortcodes / shortcodes.php

shortcodes.php in Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts 2.2.7, at includes/shortcodes/shortcodes.php

136 lines 4.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * A base shortcode for all lockers
4 *
5 * @since 1.0.0
6 */
7
8 // Exit if accessed directly
9 if ( ! defined( 'ABSPATH' ) ) {
10 exit;
11 }
12
13 class WINP_SnippetShortcode extends Wbcr_FactoryShortcodes329_Shortcode {
14
15 public $shortcode_name = 'wbcr_php_snippet';
16
17 /**
18 * Includes assets
19 * @var bool
20 */
21 public $assets_in_header = true;
22
23 /**
24 * Filter attributes
25 *
26 * @param $attr
27 * @param $post_id
28 *
29 * @return mixed
30 */
31 public function filterAttributes( $attr, $post_id ) {
32 if ( ! empty( $attr ) ) {
33 $available_tags = WINP_Helper::getMetaOption( $post_id, 'snippet_tags', null );
34
35 if ( ! empty( $available_tags ) ) {
36 $available_tags = explode( ',', $available_tags );
37 $available_tags = array_map( 'trim', $available_tags );
38 }
39
40 foreach ( $attr as $name => $value ) {
41 $is_allow_attr = in_array( $name, array( 'id', 'title' ) );
42 $validate_name = preg_match( '/^[a-zA-Z_\x7f-\xff][a-zA-Z0-9_\x7f-\xff]*/', $name );
43
44 if ( ! $is_allow_attr && ( ( ! empty( $available_tags ) && ! in_array( $name, $available_tags ) ) || ! $validate_name ) ) {
45 unset( $attr[ $name ] );
46 } else {
47 // issue PCS-1
48 // before sending the value to the shortcode, using encodeURIComponent(val).replace(/\./g, ‘%2E’); fixes the issue. Will the next update stop this from working?
49 $value = urldecode( $value );
50
51 // Remove script tag
52 $value = preg_replace( '#<script(.*?)>(.*?)</script>#is', '', $value );
53
54 // Remove any attribute starting with "on" or xmlns
55 $value = preg_replace( '#(<[^>]+?[\x00-\x20"\'])(?:on|xmlns)[^>]*+>#iu', '$1>', $value );
56
57 // Remove javascript: and vbscript: protocols
58 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=[\x00-\x20]*([`\'"]*)[\x00-\x20]*j[\x00-\x20]*a[\x00-\x20]*v[\x00-\x20]*a[\x00-\x20]*s[\x00-\x20]*c[\x00-\x20]*r[\x00-\x20]*i[\x00-\x20]*p[\x00-\x20]*t[\x00-\x20]*:#iu', '$1=$2nojavascript...', $value );
59 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=([\'"]*)[\x00-\x20]*v[\x00-\x20]*b[\x00-\x20]*s[\x00-\x20]*c[\x00-\x20]*r[\x00-\x20]*i[\x00-\x20]*p[\x00-\x20]*t[\x00-\x20]*:#iu', '$1=$2novbscript...', $value );
60 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=([\'"]*)[\x00-\x20]*-moz-binding[\x00-\x20]*:#u', '$1=$2nomozbinding...', $value );
61
62 // Filter value
63 $value = filter_var( $value, FILTER_SANITIZE_SPECIAL_CHARS );
64 $attr[ $name ] = filter_var( $value, FILTER_SANITIZE_MAGIC_QUOTES );
65 }
66 }
67 }
68
69 return $attr;
70 }
71
72 /**
73 * Get snippet id
74 *
75 * @param $attr
76 * @param $type
77 *
78 * @return int|null
79 */
80 public function getSnippetId( $attr, $type ) {
81 $id = isset( $attr['id'] ) ? (int) $attr['id'] : null;
82 if ( $id && $type != WINP_Helper::get_snippet_type( $id ) ) {
83 $id = 0;
84 }
85
86 return $id;
87 }
88
89 /**
90 * Get snippet activate
91 *
92 * @param $snippet_meta
93 *
94 * @return bool
95 */
96 public function getSnippetActivate( $snippet_meta ) {
97 return isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_activate' ] ) && $snippet_meta[ $this->plugin->getPrefix() . 'snippet_activate' ][0];
98 }
99
100 /**
101 * Get snippet scope
102 *
103 * @param $snippet_meta
104 *
105 * @return null
106 */
107 public function getSnippetScope( $snippet_meta ) {
108 return isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_scope' ] ) ? $snippet_meta[ $this->plugin->getPrefix() . 'snippet_scope' ][0] : null;
109 }
110
111 /**
112 * Get snippet content
113 *
114 * @param WP_Post $snippet
115 * @param array $snippet_meta
116 * @param int $id
117 *
118 * @return null|string
119 */
120 public function getSnippetContent( $snippet, $snippet_meta, $id ) {
121 $snippet_code = WINP_Helper::get_snippet_code($snippet);
122 return WINP_Plugin::app()->getExecuteObject()->prepareCode( $snippet_code, $id );
123 }
124
125 /**
126 * Content render
127 *
128 * @param array $attr
129 * @param string $content
130 * @param string $tag
131 */
132 public function html( $attr, $content, $tag ) {
133
134 }
135
136 }