PluginProbe
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts / 2.4.10
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts v2.4.10
2.7.6 2.7.5 2.7.4 trunk 1.3 2.0.4 2.0.6 2.1.91 2.2.4 2.2.7 2.2.9 2.3.1 2.3.10 2.4.10 2.4.2 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 2.6.0 2.6.1 2.7.0 2.7.1 All 27 releases
insert-php / includes / shortcodes / shortcodes.php

shortcodes.php in Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts 2.4.10, at includes/shortcodes/shortcodes.php

156 lines 4.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * A base shortcode for all lockers
4 *
5 * @since 1.0.0
6 */
7
8 // Exit if accessed directly
9 if ( ! defined( 'ABSPATH' ) ) {
10 exit;
11 }
12
13 class WINP_SnippetShortcode extends Wbcr_FactoryShortcodes333_Shortcode {
14
15 public $shortcode_name = 'wbcr_php_snippet';
16
17 /**
18 * Includes assets
19 * @var bool
20 */
21 public $assets_in_header = true;
22
23 /**
24 * Filter attributes
25 *
26 * @param $attr
27 * @param $post_id
28 *
29 * @return mixed
30 */
31 public function filterAttributes( $attr, $post_id ) {
32 if ( ! empty( $attr ) ) {
33 $available_tags = WINP_Helper::getMetaOption( $post_id, 'snippet_tags', null );
34
35 if ( ! empty( $available_tags ) ) {
36 $available_tags = explode( ',', $available_tags );
37 $available_tags = array_map( 'trim', $available_tags );
38 }
39
40 foreach ( $attr as $name => $value ) {
41 $is_allow_attr = in_array( $name, array( 'id', 'title' ) );
42 $validate_name = preg_match( '/^[a-zA-Z_\x7f-\xff][a-zA-Z0-9_\x7f-\xff]*/', $name );
43
44 if ( ! $is_allow_attr && ( ( ! empty( $available_tags ) && ! in_array( $name, $available_tags ) ) || ! $validate_name ) ) {
45 unset( $attr[ $name ] );
46 } else {
47 // issue PCS-1
48 // before sending the value to the shortcode, using encodeURIComponent(val).replace(/\./g, ‘%2E’); fixes the issue. Will the next update stop this from working?
49 $value = urldecode( $value );
50
51 // Remove script tag
52 $value = preg_replace( '#<script(.*?)>(.*?)</script>#is', '', $value );
53
54 // Remove any attribute starting with "on" or xmlns
55 $value = preg_replace( '#(<[^>]+?[\x00-\x20"\'])(?:on|xmlns)[^>]*+>#iu', '$1>', $value );
56
57 // Remove javascript: and vbscript: protocols
58 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=[\x00-\x20]*([`\'"]*)[\x00-\x20]*j[\x00-\x20]*a[\x00-\x20]*v[\x00-\x20]*a[\x00-\x20]*s[\x00-\x20]*c[\x00-\x20]*r[\x00-\x20]*i[\x00-\x20]*p[\x00-\x20]*t[\x00-\x20]*:#iu', '$1=$2nojavascript...', $value );
59 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=([\'"]*)[\x00-\x20]*v[\x00-\x20]*b[\x00-\x20]*s[\x00-\x20]*c[\x00-\x20]*r[\x00-\x20]*i[\x00-\x20]*p[\x00-\x20]*t[\x00-\x20]*:#iu', '$1=$2novbscript...', $value );
60 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=([\'"]*)[\x00-\x20]*-moz-binding[\x00-\x20]*:#u', '$1=$2nomozbinding...', $value );
61
62 // Filter value
63 if ( version_compare( phpversion(), '7.3.0', '>=' ) ) {
64 $filter = FILTER_SANITIZE_ADD_SLASHES;
65 } else {
66 $filter = FILTER_SANITIZE_MAGIC_QUOTES;
67 }
68 $value = filter_var( $value, FILTER_SANITIZE_SPECIAL_CHARS );
69 $attr[ $name ] = filter_var( $value, $filter );
70 }
71 }
72 }
73
74 return $attr;
75 }
76
77 /**
78 * Get snippet id
79 *
80 * @param $attr
81 * @param $type
82 *
83 * @return int|null
84 */
85 public function getSnippetId( $attr, $type ) {
86 $id = isset( $attr['id'] ) ? (int) $attr['id'] : null;
87 if ( $id && $type != WINP_Helper::get_snippet_type( $id ) ) {
88 $id = 0;
89 }
90
91 return $id;
92 }
93
94 /**
95 * Get snippet activate
96 *
97 * @param $snippet_meta
98 *
99 * @return bool
100 */
101 public function getSnippetActivate( $snippet_meta ) {
102 // WPML Compatibility
103 if ( defined( 'WPML_PLUGIN_FILE' ) ) {
104 $wpml_langs = isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_wpml_lang' ][0] ) ? $snippet_meta[ $this->plugin->getPrefix() . 'snippet_wpml_lang' ][0] : '';
105 if ( $wpml_langs !== '' && defined( 'ICL_LANGUAGE_CODE' ) ) {
106 if ( ! in_array( ICL_LANGUAGE_CODE, explode( ',', $wpml_langs ) ) ) {
107 return false;
108 }
109 }
110 }
111
112 return isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_activate' ] ) && $snippet_meta[ $this->plugin->getPrefix() . 'snippet_activate' ][0];
113 }
114
115 /**
116 * Get snippet scope
117 *
118 * @param $snippet_meta
119 *
120 * @return null
121 */
122 public function getSnippetScope( $snippet_meta ) {
123 return isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_scope' ] ) ? $snippet_meta[ $this->plugin->getPrefix() . 'snippet_scope' ][0] : null;
124 }
125
126 /**
127 * Get snippet content
128 *
129 * @param WP_Post $snippet
130 * @param array $snippet_meta
131 * @param int $id
132 *
133 * @return null|string
134 */
135 public function getSnippetContent( $snippet, $snippet_meta, $id ) {
136 $snippet_code = WINP_Helper::get_snippet_code( $snippet );
137
138 if ( WINP_Plugin::app()->getOption( 'execute_shortcode' ) ) {
139 $snippet_code = do_shortcode( $snippet_code );
140 }
141
142 return WINP_Plugin::app()->getExecuteObject()->prepareCode( $snippet_code, $id );
143 }
144
145 /**
146 * Content render
147 *
148 * @param array $attr
149 * @param string $content
150 * @param string $tag
151 */
152 public function html( $attr, $content, $tag ) {
153
154 }
155
156 }