| 1 |
<?php |
| 2 |
/** |
| 3 |
* Php Shortcode |
| 4 |
*/ |
| 5 |
|
| 6 |
// Exit if accessed directly |
| 7 |
if ( ! defined( 'ABSPATH' ) ) { |
| 8 |
exit; |
| 9 |
} |
| 10 |
|
| 11 |
class WINP_SnippetShortcodePhp extends WINP_SnippetShortcode { |
| 12 |
|
| 13 |
public $shortcode_name = 'wbcr_php_snippet'; |
| 14 |
|
| 15 |
/** |
| 16 |
* Content render |
| 17 |
* |
| 18 |
* @param array $attr Shortcode attributes. |
| 19 |
* @param string $content Enclosed shortcode content. |
| 20 |
* @param string $tag Shortcode tag. |
| 21 |
* @return mixed Rendered snippet output, if any. |
| 22 |
*/ |
| 23 |
public function html( $attr, $content, $tag ) { |
| 24 |
$id = $this->get_snippet_id( $attr, WINP_SNIPPET_TYPE_PHP ); |
| 25 |
|
| 26 |
if ( ! $id ) { |
| 27 |
if ( current_user_can( 'manage_options' ) || ( defined( 'WP_DEBUG' ) && WP_DEBUG ) ) { |
| 28 |
/* translators: %s: Shortcode tag name */ |
| 29 |
echo '<span style="color:red">' . sprintf( esc_html__( '[%s]: PHP snippets error (not passed the snippet ID)', 'insert-php' ), esc_html( $tag ) ) . '</span>'; |
| 30 |
} |
| 31 |
|
| 32 |
return; |
| 33 |
} |
| 34 |
|
| 35 |
$snippet = get_post( $id ); |
| 36 |
$snippet_meta = get_post_meta( $id, '' ); |
| 37 |
|
| 38 |
if ( ! $snippet || empty( $snippet_meta ) ) { |
| 39 |
return; |
| 40 |
} |
| 41 |
|
| 42 |
$attr = $this->filter_attributes( $attr, $id ); |
| 43 |
|
| 44 |
// Let users pass arbitrary variables, through shortcode attributes. |
| 45 |
// @since 2.0.5 |
| 46 |
extract( $attr, EXTR_SKIP ); |
| 47 |
|
| 48 |
$is_activate = $this->get_snippet_activate( $snippet_meta ); |
| 49 |
$snippet_scope = $this->get_snippet_scope( $snippet_meta ); |
| 50 |
$snippet_content = $this->get_snippet_content( $snippet, $snippet_meta, $id ); |
| 51 |
|
| 52 |
if ( ! $is_activate || empty( $snippet_content ) || $snippet_scope != 'shortcode' || WINP_Helper::is_safe_mode() ) { |
| 53 |
return; |
| 54 |
} |
| 55 |
|
| 56 |
if ( defined( 'DISALLOW_UNFILTERED_HTML' ) && DISALLOW_UNFILTERED_HTML ) { |
| 57 |
if ( is_user_logged_in() && WINP_Plugin::app()->current_user_car() ) { |
| 58 |
echo esc_html__( 'This Woody snippet cannot run because unfiltered HTML insertion is disabled.', 'insert-php' ); |
| 59 |
} |
| 60 |
|
| 61 |
return; |
| 62 |
} |
| 63 |
|
| 64 |
// Track shortcode execution. |
| 65 |
WINP_Plugin::app()->get_execute_object()->track_shortcode_snippet( $id ); |
| 66 |
|
| 67 |
// Initialize error handler. |
| 68 |
WINP_Error_Handler::init(); |
| 69 |
|
| 70 |
// Set current snippet context for error handler. |
| 71 |
WINP_Error_Handler::set_current_snippet( $id, $snippet->post_title, $snippet_content ); |
| 72 |
|
| 73 |
$buffer_level = ob_get_level(); |
| 74 |
ob_start(); |
| 75 |
|
| 76 |
try { |
| 77 |
eval( $snippet_content ); |
| 78 |
|
| 79 |
// Preserve output from buffers opened by the snippet itself. |
| 80 |
while ( ob_get_level() > $buffer_level + 1 ) { |
| 81 |
ob_end_flush(); |
| 82 |
} |
| 83 |
|
| 84 |
$snippet_output = ob_get_clean(); |
| 85 |
return false !== $snippet_output ? $snippet_output : ''; |
| 86 |
} catch ( Throwable $exception ) { |
| 87 |
while ( ob_get_level() > $buffer_level ) { |
| 88 |
ob_end_clean(); |
| 89 |
} |
| 90 |
|
| 91 |
return WINP_Error_Handler::handle_exception( $exception ); |
| 92 |
} finally { |
| 93 |
// Clear snippet context after execution. |
| 94 |
WINP_Error_Handler::clear_current_snippet(); |
| 95 |
} |
| 96 |
} |
| 97 |
} |
| 98 |
|