PluginProbe
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts / 2.6.0
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts v2.6.0
2.7.7 2.7.6 2.7.5 2.7.4 trunk 1.3 2.0.4 2.0.6 2.1.91 2.2.4 2.2.7 2.2.9 2.3.1 2.3.10 2.4.10 2.4.2 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 2.6.0 2.6.1 2.7.0 All 28 releases
insert-php / includes / shortcodes / shortcodes.php

shortcodes.php in Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts 2.6.0, at includes/shortcodes/shortcodes.php

162 lines 4.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * A base shortcode for all lockers
4 *
5 * @since 1.0.0
6 */
7
8 // Exit if accessed directly
9 if ( ! defined( 'ABSPATH' ) ) {
10 exit;
11 }
12
13 class WINP_SnippetShortcode extends Wbcr_FactoryShortcodes335_Shortcode {
14
15 public $manager;
16
17 public $shortcode_name = 'wbcr_php_snippet';
18
19 /**
20 * Includes assets
21 * @var bool
22 */
23 public $assets_in_header = true;
24
25 public function __construct( $plugin ) {
26 parent::__construct( $plugin );
27 }
28
29 /**
30 * Filter attributes
31 *
32 * @param $attr
33 * @param $post_id
34 *
35 * @return mixed
36 */
37 public function filterAttributes( $attr, $post_id ) {
38 if ( ! empty( $attr ) ) {
39 $available_tags = WINP_Helper::getMetaOption( $post_id, 'snippet_tags', null );
40
41 if ( ! empty( $available_tags ) ) {
42 $available_tags = explode( ',', $available_tags );
43 $available_tags = array_map( 'trim', $available_tags );
44 }
45
46 foreach ( $attr as $name => $value ) {
47 $is_allow_attr = in_array( $name, array( 'id', 'title' ) );
48 $validate_name = preg_match( '/^[a-zA-Z_\x7f-\xff][a-zA-Z0-9_\x7f-\xff]*/', $name );
49
50 if ( ! $is_allow_attr && ( ( ! empty( $available_tags ) && ! in_array( $name, $available_tags ) ) || ! $validate_name ) ) {
51 unset( $attr[ $name ] );
52 } else {
53 // issue PCS-1
54 // before sending the value to the shortcode, using encodeURIComponent(val).replace(/\./g, ‘%2E’); fixes the issue. Will the next update stop this from working?
55 $value = urldecode( $value );
56
57 // Remove script tag
58 $value = preg_replace( '#<script(.*?)>(.*?)</script>#is', '', $value );
59
60 // Remove any attribute starting with "on" or xmlns
61 $value = preg_replace( '#(<[^>]+?[\x00-\x20"\'])(?:on|xmlns)[^>]*+>#iu', '$1>', $value );
62
63 // Remove javascript: and vbscript: protocols
64 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=[\x00-\x20]*([`\'"]*)[\x00-\x20]*j[\x00-\x20]*a[\x00-\x20]*v[\x00-\x20]*a[\x00-\x20]*s[\x00-\x20]*c[\x00-\x20]*r[\x00-\x20]*i[\x00-\x20]*p[\x00-\x20]*t[\x00-\x20]*:#iu', '$1=$2nojavascript...', $value );
65 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=([\'"]*)[\x00-\x20]*v[\x00-\x20]*b[\x00-\x20]*s[\x00-\x20]*c[\x00-\x20]*r[\x00-\x20]*i[\x00-\x20]*p[\x00-\x20]*t[\x00-\x20]*:#iu', '$1=$2novbscript...', $value );
66 $value = preg_replace( '#([a-z]*)[\x00-\x20]*=([\'"]*)[\x00-\x20]*-moz-binding[\x00-\x20]*:#u', '$1=$2nomozbinding...', $value );
67
68 // Filter value
69 if ( version_compare( phpversion(), '7.3.0', '>=' ) ) {
70 $filter = FILTER_SANITIZE_ADD_SLASHES;
71 } else {
72 $filter = FILTER_SANITIZE_MAGIC_QUOTES;
73 }
74 $value = filter_var( $value, FILTER_SANITIZE_SPECIAL_CHARS );
75 $attr[ $name ] = filter_var( $value, $filter );
76 }
77 }
78 }
79
80 return $attr;
81 }
82
83 /**
84 * Get snippet id
85 *
86 * @param $attr
87 * @param $type
88 *
89 * @return int|null
90 */
91 public function getSnippetId( $attr, $type ) {
92 $id = isset( $attr['id'] ) ? (int) $attr['id'] : null;
93
94 if ( $id && $type != WINP_Helper::get_snippet_type( $id ) ) {
95 $id = 0;
96 }
97
98 return $id;
99 }
100
101 /**
102 * Get snippet activate
103 *
104 * @param $snippet_meta
105 *
106 * @return bool
107 */
108 public function getSnippetActivate( $snippet_meta ) {
109 // WPML Compatibility
110 if ( defined( 'WPML_PLUGIN_FILE' ) ) {
111 $wpml_langs = isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_wpml_lang' ][0] ) ? $snippet_meta[ $this->plugin->getPrefix() . 'snippet_wpml_lang' ][0] : '';
112 if ( $wpml_langs !== '' && defined( 'ICL_LANGUAGE_CODE' ) ) {
113 if ( ! in_array( ICL_LANGUAGE_CODE, explode( ',', $wpml_langs ) ) ) {
114 return false;
115 }
116 }
117 }
118
119 return isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_activate' ] ) && $snippet_meta[ $this->plugin->getPrefix() . 'snippet_activate' ][0];
120 }
121
122 /**
123 * Get snippet scope
124 *
125 * @param $snippet_meta
126 *
127 * @return null
128 */
129 public function getSnippetScope( $snippet_meta ) {
130 return isset( $snippet_meta[ $this->plugin->getPrefix() . 'snippet_scope' ] ) ? $snippet_meta[ $this->plugin->getPrefix() . 'snippet_scope' ][0] : null;
131 }
132
133 /**
134 * Get snippet content
135 *
136 * @param WP_Post $snippet
137 * @param array $snippet_meta
138 * @param int $id
139 *
140 * @return null|string
141 */
142 public function getSnippetContent( $snippet, $snippet_meta, $id ) {
143 $snippet_code = WINP_Helper::get_snippet_code( $snippet );
144
145 if ( WINP_Plugin::app()->getOption( 'execute_shortcode' ) ) {
146 $snippet_code = do_shortcode( $snippet_code );
147 }
148
149 return WINP_Plugin::app()->getExecuteObject()->prepareCode( $snippet_code, $id );
150 }
151
152 /**
153 * Content render
154 *
155 * @param array $attr
156 * @param string $content
157 * @param string $tag
158 */
159 public function html( $attr, $content, $tag ) {
160
161 }
162 }