| 1 |
<?php |
| 2 |
|
| 3 |
namespace King_Addons; |
| 4 |
|
| 5 |
use King_Addons\Animations\Animations; |
| 6 |
|
| 7 |
if (!defined('ABSPATH')) { |
| 8 |
exit; |
| 9 |
} |
| 10 |
|
| 11 |
/** |
| 12 |
* Sanitizes untrusted grid settings received through AJAX handlers. |
| 13 |
*/ |
| 14 |
class Grid_Ajax_Security |
| 15 |
{ |
| 16 |
/** |
| 17 |
* Returns allowed animation size values. |
| 18 |
* |
| 19 |
* @return array<int, string> Allowed size slugs. |
| 20 |
*/ |
| 21 |
public static function get_allowed_animation_sizes(): array |
| 22 |
{ |
| 23 |
return ['small', 'medium', 'large']; |
| 24 |
} |
| 25 |
|
| 26 |
/** |
| 27 |
* Returns allowed image effect slugs. |
| 28 |
* |
| 29 |
* @return array<int, string> Allowed effect slugs. |
| 30 |
*/ |
| 31 |
public static function get_allowed_image_effects(): array |
| 32 |
{ |
| 33 |
return ['none', 'pro-zi', 'pro-zo', 'grayscale-in', 'pro-go', 'blur-in', 'pro-bo', 'slide']; |
| 34 |
} |
| 35 |
|
| 36 |
/** |
| 37 |
* Returns allowed image effect direction values. |
| 38 |
* |
| 39 |
* @return array<int, string> Allowed direction slugs. |
| 40 |
*/ |
| 41 |
public static function get_allowed_image_effect_directions(): array |
| 42 |
{ |
| 43 |
return ['top', 'right', 'bottom', 'left']; |
| 44 |
} |
| 45 |
|
| 46 |
/** |
| 47 |
* Sanitizes an animation slug against the widget allowlist. |
| 48 |
* |
| 49 |
* @param mixed $value Raw animation value. |
| 50 |
* @return string Sanitized animation slug. |
| 51 |
*/ |
| 52 |
public static function sanitize_animation($value): string |
| 53 |
{ |
| 54 |
$value = sanitize_key((string) $value); |
| 55 |
|
| 56 |
return in_array($value, Animations::get_animation_slugs(), true) ? $value : 'none'; |
| 57 |
} |
| 58 |
|
| 59 |
/** |
| 60 |
* Sanitizes an animation size slug. |
| 61 |
* |
| 62 |
* @param mixed $value Raw animation size value. |
| 63 |
* @return string Sanitized animation size slug. |
| 64 |
*/ |
| 65 |
public static function sanitize_animation_size($value): string |
| 66 |
{ |
| 67 |
$value = sanitize_key((string) $value); |
| 68 |
|
| 69 |
return in_array($value, self::get_allowed_animation_sizes(), true) ? $value : 'large'; |
| 70 |
} |
| 71 |
|
| 72 |
/** |
| 73 |
* Sanitizes an animation timing slug. |
| 74 |
* |
| 75 |
* @param mixed $value Raw animation timing value. |
| 76 |
* @return string Sanitized animation timing slug. |
| 77 |
*/ |
| 78 |
public static function sanitize_animation_timing($value): string |
| 79 |
{ |
| 80 |
$value = sanitize_key((string) $value); |
| 81 |
$allowed = array_keys(Core::getAnimationTimings()); |
| 82 |
|
| 83 |
return in_array($value, $allowed, true) ? $value : 'ease-default'; |
| 84 |
} |
| 85 |
|
| 86 |
/** |
| 87 |
* Sanitizes an image effect slug. |
| 88 |
* |
| 89 |
* @param mixed $value Raw image effect value. |
| 90 |
* @return string Sanitized image effect slug. |
| 91 |
*/ |
| 92 |
public static function sanitize_image_effect($value): string |
| 93 |
{ |
| 94 |
$value = sanitize_key((string) $value); |
| 95 |
|
| 96 |
if (!in_array($value, self::get_allowed_image_effects(), true)) { |
| 97 |
return 'none'; |
| 98 |
} |
| 99 |
|
| 100 |
if ( |
| 101 |
!king_addons_freemius()->can_use_premium_code__premium_only() |
| 102 |
&& in_array($value, ['pro-zi', 'pro-zo', 'pro-go', 'pro-bo'], true) |
| 103 |
) { |
| 104 |
return 'none'; |
| 105 |
} |
| 106 |
|
| 107 |
return $value; |
| 108 |
} |
| 109 |
|
| 110 |
/** |
| 111 |
* Sanitizes an image effect size slug. |
| 112 |
* |
| 113 |
* @param mixed $value Raw image effect size value. |
| 114 |
* @return string Sanitized image effect size slug. |
| 115 |
*/ |
| 116 |
public static function sanitize_image_effect_size($value): string |
| 117 |
{ |
| 118 |
$value = sanitize_key((string) $value); |
| 119 |
|
| 120 |
return in_array($value, self::get_allowed_animation_sizes(), true) ? $value : 'medium'; |
| 121 |
} |
| 122 |
|
| 123 |
/** |
| 124 |
* Sanitizes an image effect direction slug. |
| 125 |
* |
| 126 |
* @param mixed $value Raw image effect direction value. |
| 127 |
* @return string Sanitized image effect direction slug. |
| 128 |
*/ |
| 129 |
public static function sanitize_image_effect_direction($value): string |
| 130 |
{ |
| 131 |
$value = sanitize_key((string) $value); |
| 132 |
|
| 133 |
return in_array($value, self::get_allowed_image_effect_directions(), true) ? $value : 'bottom'; |
| 134 |
} |
| 135 |
|
| 136 |
/** |
| 137 |
* Sanitizes a yes/no switcher value. |
| 138 |
* |
| 139 |
* @param mixed $value Raw switcher value. |
| 140 |
* @return string Either "yes" or an empty string. |
| 141 |
*/ |
| 142 |
public static function sanitize_yes_no_switcher($value): string |
| 143 |
{ |
| 144 |
return 'yes' === $value ? 'yes' : ''; |
| 145 |
} |
| 146 |
} |
| 147 |
|