PluginProbe
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts / trunk
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts vtrunk
2.7.7 2.7.6 2.7.5 2.7.4 trunk 1.3 2.0.4 2.0.6 2.1.91 2.2.4 2.2.7 2.2.9 2.3.1 2.3.10 2.4.10 2.4.2 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 2.6.0 2.6.1 2.7.0 All 28 releases
← All changes | includes/shortcodes/shortcode-php.php +97 -55 2.3.1trunk View file →
@@ -1,55 +1,97 @@
1 -<?php
2 -/**
3 - * Php Shortcode
4 - */
5 -
6 -// Exit if accessed directly
7 -if ( ! defined( 'ABSPATH' ) ) {
8 - exit;
9 -}
10 -
11 -class WINP_SnippetShortcodePhp extends WINP_SnippetShortcode {
12 -
13 - public $shortcode_name = 'wbcr_php_snippet';
14 -
15 - /**
16 - * Content render
17 - *
18 - * @param array $attr
19 - * @param string $content
20 - * @param string $tag
21 - */
22 - public function html( $attr, $content, $tag ) {
23 - $id = $this->getSnippetId( $attr, WINP_SNIPPET_TYPE_PHP );
24 -
25 - if ( ! $id ) {
26 - echo '<span style="color:red">' . __( '[' . esc_html( $tag ) . ']: PHP snippets error (not passed the snippet ID)', 'insert-php' ) . '</span>';
27 -
28 - return;
29 - }
30 -
31 - $snippet = get_post( $id );
32 - $snippet_meta = get_post_meta( $id, '' );
33 -
34 - if ( ! $snippet || empty( $snippet_meta ) ) {
35 - return;
36 - }
37 -
38 - $attr = $this->filterAttributes( $attr, $id );
39 -
40 - // Let users pass arbitrary variables, through shortcode attributes.
41 - // @since 2.0.5
42 - extract( $attr, EXTR_SKIP );
43 -
44 - $is_activate = $this->getSnippetActivate( $snippet_meta );
45 - $snippet_scope = $this->getSnippetScope( $snippet_meta );
46 - $snippet_content = $this->getSnippetContent( $snippet, $snippet_meta, $id );
47 -
48 - if ( ! $is_activate || empty( $snippet_content ) || $snippet_scope != 'shortcode' || WINP_Helper::is_safe_mode() ) {
49 - return;
50 - }
51 -
52 - eval( $snippet_content );
53 - }
54 -
55 -}
1 +<?php
2 +/**
3 + * Php Shortcode
4 + */
5 +
6 +// Exit if accessed directly
7 +if ( ! defined( 'ABSPATH' ) ) {
8 + exit;
9 +}
10 +
11 +class WINP_SnippetShortcodePhp extends WINP_SnippetShortcode {
12 +
13 + public $shortcode_name = 'wbcr_php_snippet';
14 +
15 + /**
16 + * Content render
17 + *
18 + * @param array $attr Shortcode attributes.
19 + * @param string $content Enclosed shortcode content.
20 + * @param string $tag Shortcode tag.
21 + * @return mixed Rendered snippet output, if any.
22 + */
23 + public function html( $attr, $content, $tag ) {
24 + $id = $this->get_snippet_id( $attr, WINP_SNIPPET_TYPE_PHP );
25 +
26 + if ( ! $id ) {
27 + if ( current_user_can( 'manage_options' ) || ( defined( 'WP_DEBUG' ) && WP_DEBUG ) ) {
28 + /* translators: %s: Shortcode tag name */
29 + echo '<span style="color:red">' . sprintf( esc_html__( '[%s]: PHP snippets error (not passed the snippet ID)', 'insert-php' ), esc_html( $tag ) ) . '</span>';
30 + }
31 +
32 + return;
33 + }
34 +
35 + $snippet = get_post( $id );
36 + $snippet_meta = get_post_meta( $id, '' );
37 +
38 + if ( ! $snippet || empty( $snippet_meta ) ) {
39 + return;
40 + }
41 +
42 + $attr = $this->filter_attributes( $attr, $id );
43 +
44 + // Let users pass arbitrary variables, through shortcode attributes.
45 + // @since 2.0.5
46 + extract( $attr, EXTR_SKIP );
47 +
48 + $is_activate = $this->get_snippet_activate( $snippet_meta );
49 + $snippet_scope = $this->get_snippet_scope( $snippet_meta );
50 + $snippet_content = $this->get_snippet_content( $snippet, $snippet_meta, $id );
51 +
52 + if ( ! $is_activate || empty( $snippet_content ) || $snippet_scope != 'shortcode' || WINP_Helper::is_safe_mode() ) {
53 + return;
54 + }
55 +
56 + if ( defined( 'DISALLOW_UNFILTERED_HTML' ) && DISALLOW_UNFILTERED_HTML ) {
57 + if ( is_user_logged_in() && WINP_Plugin::app()->current_user_car() ) {
58 + echo esc_html__( 'This Woody snippet cannot run because unfiltered HTML insertion is disabled.', 'insert-php' );
59 + }
60 +
61 + return;
62 + }
63 +
64 + // Track shortcode execution.
65 + WINP_Plugin::app()->get_execute_object()->track_shortcode_snippet( $id );
66 +
67 + // Initialize error handler.
68 + WINP_Error_Handler::init();
69 +
70 + // Set current snippet context for error handler.
71 + WINP_Error_Handler::set_current_snippet( $id, $snippet->post_title, $snippet_content );
72 +
73 + $buffer_level = ob_get_level();
74 + ob_start();
75 +
76 + try {
77 + eval( $snippet_content );
78 +
79 + // Preserve output from buffers opened by the snippet itself.
80 + while ( ob_get_level() > $buffer_level + 1 ) {
81 + ob_end_flush();
82 + }
83 +
84 + $snippet_output = ob_get_clean();
85 + return false !== $snippet_output ? $snippet_output : '';
86 + } catch ( Throwable $exception ) {
87 + while ( ob_get_level() > $buffer_level ) {
88 + ob_end_clean();
89 + }
90 +
91 + return WINP_Error_Handler::handle_exception( $exception );
92 + } finally {
93 + // Clear snippet context after execution.
94 + WINP_Error_Handler::clear_current_snippet();
95 + }
96 + }
97 +}