| 1 |
<?php |
| 2 |
/** |
| 3 |
* Zoom Scheduler block render implementation. |
| 4 |
* |
| 5 |
* Loaded lazily from zoom-scheduler.php only when the block is rendered, to keep |
| 6 |
* the render body out of the eager front-end PHP/opcache footprint. |
| 7 |
* |
| 8 |
* @package automattic/jetpack |
| 9 |
*/ |
| 10 |
|
| 11 |
namespace Automattic\Jetpack\Extensions\Zoom_Scheduler; |
| 12 |
|
| 13 |
use Automattic\Jetpack\Blocks; |
| 14 |
use Jetpack_Gutenberg; |
| 15 |
|
| 16 |
if ( ! defined( 'ABSPATH' ) ) { |
| 17 |
exit( 0 ); |
| 18 |
} |
| 19 |
|
| 20 |
// Keep in sync with the IFRAME_HEIGHT in edit.js and min-block-size in view.scss. |
| 21 |
const IFRAME_HEIGHT = 900; |
| 22 |
const EMBED_WRAPPER_CLASS = 'wp-block-jetpack-zoom-scheduler__embed'; |
| 23 |
|
| 24 |
/** |
| 25 |
* Dynamic rendering of the block. |
| 26 |
* |
| 27 |
* @param array $attr Array containing the Zoom Scheduler block attributes. |
| 28 |
* @return string |
| 29 |
*/ |
| 30 |
function render( $attr ) { |
| 31 |
$url = isset( $attr['url'] ) |
| 32 |
? Jetpack_Gutenberg::validate_block_embed_url( $attr['url'], array( 'scheduler.zoom.us' ) ) |
| 33 |
: ''; |
| 34 |
|
| 35 |
if ( empty( $url ) ) { |
| 36 |
return ''; |
| 37 |
} |
| 38 |
|
| 39 |
Jetpack_Gutenberg::load_assets_as_required( __DIR__ ); |
| 40 |
|
| 41 |
$url = set_url_scheme( $url, 'https' ); |
| 42 |
$classes = Blocks::classes( Blocks::get_block_feature( __DIR__ ), $attr ); |
| 43 |
$embed_url = add_query_arg( 'embed', 'true', $url ); |
| 44 |
|
| 45 |
if ( Blocks::is_amp_request() ) { |
| 46 |
return sprintf( |
| 47 |
'<div class="%1$s"><a href="%2$s" target="_blank" rel="noopener noreferrer">%3$s</a></div>', |
| 48 |
esc_attr( $classes ), |
| 49 |
esc_url( $url ), |
| 50 |
esc_html__( 'Open Zoom Scheduler', 'jetpack' ) |
| 51 |
); |
| 52 |
} |
| 53 |
|
| 54 |
/* |
| 55 |
* The embed is cross-origin to the WordPress page (host is allow-listed |
| 56 |
* above), so the framed Zoom page cannot reach the parent DOM regardless of |
| 57 |
* these tokens. allow-same-origin lets the booking page use its own cookies |
| 58 |
* and storage, allow-scripts runs its booking UI, and allow-popups/allow-forms |
| 59 |
* cover the confirmation flow. |
| 60 |
*/ |
| 61 |
$sandbox = 'allow-scripts allow-same-origin allow-popups allow-forms'; |
| 62 |
|
| 63 |
return sprintf( |
| 64 |
'<div class="%1$s"><div class="%2$s"><iframe src="%3$s" title="%4$s" width="100%%" height="%5$d" frameborder="0" loading="lazy" sandbox="%6$s"></iframe></div></div>', |
| 65 |
esc_attr( $classes ), |
| 66 |
esc_attr( EMBED_WRAPPER_CLASS ), |
| 67 |
esc_url( $embed_url ), |
| 68 |
esc_attr__( 'Zoom Scheduler', 'jetpack' ), |
| 69 |
IFRAME_HEIGHT, |
| 70 |
esc_attr( $sandbox ) |
| 71 |
); |
| 72 |
} |
| 73 |
|