PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.4.9
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.4.9
4.4.9.1 4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 4.1.7.3.1 All 141 releases
← All changes | inc/admin/class-lp-admin-ajax.php +248 -255 4.1.7.3.2 → 4.4.9 View file →
@@ -10,8 +10,13 @@
10 10
11 11 /**
12 12 * Prevent loading this file directly
13 13 */
14 +
15 +use LearnPress\Helpers\Response;
16 +use LearnPress\Helpers\Template;
17 +use LearnPress\Models\UserModel;
18 +
14 19 defined( 'ABSPATH' ) || exit();
15 20
16 21 if ( ! class_exists( 'LP_Admin_Ajax' ) ) {
17 22
@@ -19,33 +24,11 @@
19 24 * Class LP_Admin_Ajax
20 25 */
21 26 class LP_Admin_Ajax {
22 27 public function __construct() {
23 - add_action(
24 - 'wp_ajax_nopriv_check_wp_remote',
25 - function () {
26 - echo '[TEST_REMOTE]';
27 - exit;
28 - }
29 - );
30 28 }
31 29
32 30 /**
33 - * Tests the background handler's connection.
34 - *
35 - * @since 4.1.7.3.2
36 - *
37 - * @return bool|WP_Error
38 - */
39 - public static function check_wp_remote() {
40 - $test_url = add_query_arg( 'action', 'check_wp_remote', admin_url( 'admin-ajax.php' ) );
41 - $result = wp_safe_remote_get( $test_url );
42 - $body = ! is_wp_error( $result ) ? wp_remote_retrieve_body( $result ) : $result;
43 -
44 - return $body === '[TEST_REMOTE]' ? true : $result;
45 - }
46 -
47 - /**
48 31 * Add action ajax
49 32 */
50 33 public static function init() {
51 34 if ( ! is_user_logged_in() ) {
@@ -53,28 +36,12 @@
53 36 }
54 37
55 38 $ajax_events = array(
56 39 'create_page' => false, // Use create new page on Settings
57 - // 'plugin_action' => false,
58 - // 'modal_search_items' => false,
59 - //'dismiss_notice' => false,
60 - //'search_users' => false,
61 - 'load_chart' => false,
40 + //'load_chart' => false,
62 41 'search_course_category' => false,
63 - 'custom_stats' => false,
64 - //'ignore_setting_up' => false,
42 + //'custom_stats' => false,
65 43 'get_page_permalink' => false,
66 - //'dummy_image' => false,
67 - // 'update_add_on_status' => false,
68 - // 'plugin_install' => false,
69 - //'bundle_activate_add_ons' => false,
70 - //'install_sample_data' => false,
71 -
72 - // Remove Notice
73 - //'remove_notice_popup' => false,
74 - // Update order status
75 - // 'update_order_status' => false,
76 - 'update_order_exports' => false,
77 44 );
78 45
79 46 foreach ( $ajax_events as $ajax_event => $nopriv ) {
80 47 add_action( 'wp_ajax_learnpress_' . $ajax_event, array( __CLASS__, $ajax_event ) );
@@ -88,40 +55,32 @@
88 55 do_action( 'learn-press/ajax/admin-load', __CLASS__ );
89 56
90 57 $ajax_events = array(
91 58 'search_items' => 'modal_search_items',
92 - 'update-payment-order', // Update ordering of payments when user changing.
93 - 'update-payment-status', // Enable type payment
94 - //'toggle_item_preview',
59 + 'update-payment-order',
60 + // Update ordering of payments when user changing.
61 + 'update-payment-status',
62 + // Enable type payment
95 63
96 64 // admin editor
97 65 'admin_course_editor',
98 66 'admin_quiz_editor',
99 67 'admin_question_editor',
100 - // duplicator
101 - 'duplicator', // Duplicate course, lesson, quiz, question.
102 -
103 - //'add_item_to_order',
104 - //'remove_order_item',
105 -
106 - 'modal_search_items', // Used to search courses on LP Order
107 - 'modal_search_users', // Used to search users on LP Order
108 - 'add_items_to_order', // Used to add courses on LP Order
109 - 'remove_items_from_order', // Used to remove items from LP Order
110 - 'update_email_status', // Use for enable email on LP Settings
111 - //'create-pages',
112 - 'search-authors', // Used to search username on input some page (list courses, lp orders, quizzes, questions... on the Backend
113 - 'skip-notice-install',
114 - //'join_newsletter',
115 - //'dashboard-order-status',
116 - //'dashboard-plugin-status',
117 - //'dismiss-notice',
118 - //'sync-user-orders',
119 - //'sync-course-final-quiz',
120 - //'sync-remove-older-data',
121 - //'sync-calculate-course-results',
122 - //'create-question-type',
123 - // 'sync-user-courses',
68 + 'duplicator',
69 + // Duplicate course, lesson, quiz, question.
70 + 'modal_search_items',
71 + // Used to search courses on LP Order
72 + //'modal_search_users',
73 + // Used to search users on LP Order
74 + 'add_items_to_order',
75 + // Used to add courses on LP Order
76 + 'remove_items_from_order',
77 + // Used to remove items from LP Order
78 + 'update_email_status',
79 + // Use for enable email on LP Settings
80 + 'search-authors',
81 + // Used to search username on input some page (list courses, lp orders, quizzes, questions... on the Backend
82 + //'skip-notice-install',
124 83 );
125 84
126 85 foreach ( $ajax_events as $action => $callback ) {
127 86 if ( is_numeric( $action ) ) {
@@ -171,15 +130,8 @@
171 130 die();
172 131 }
173 132
174 133 /**
175 - * Hide notice install
176 - */
177 - public static function skip_notice_install() {
178 - delete_option( 'learn_press_install' );
179 - }
180 -
181 - /**
182 134 * Handle ajax admin course editor.
183 135 *
184 136 * @since 3.0.0
185 137 */
@@ -232,19 +184,32 @@
232 184 *
233 185 * @note tungnx checked has use
234 186 */
235 187 public static function duplicator() {
236 - $post_id = intval( $_GET['id'] ?? 0 );
188 + $nonce = LP_Request::get_param( 'nonce' );
189 + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
190 + learn_press_send_json_error( __( 'Nonce is invalid!', 'learnpress' ) );
191 + }
237 192
238 - // get post type
193 + $post_id = intval( $_GET['id'] ?? 0 );
239 194 $post_type = learn_press_get_post_type( $post_id );
240 195
241 196 if ( ! $post_id ) {
242 197 learn_press_send_json_error( __( 'Oops! ID not found', 'learnpress' ) );
243 198 } else {
199 + $can_duplicate = apply_filters( 'learn-press/can-duplicate-course', true, $post_id, $post_type );
200 + if ( ! current_user_can( ADMIN_ROLE ) ) {
201 + $post_author = get_post_field( 'post_author', $post_id );
202 + if ( get_current_user_id() != $post_author ) {
203 + $can_duplicate = false;
204 + }
205 + }
244 206
245 - $new_item_id = '';
207 + if ( ! $can_duplicate ) {
208 + learn_press_send_json_error( __( 'You cannot duplicate this item.', 'learnpress' ) );
209 + }
246 210
211 + $new_item_id = '';
247 212 $duplicate_args = apply_filters( 'learn-press/duplicate-post-args', array( 'post_status' => 'publish' ) );
248 213
249 214 switch ( $post_type ) {
250 215 case LP_COURSE_CPT:
@@ -292,14 +257,25 @@
292 257 /**
293 258 * Update ordering of payments when user changing.
294 259 *
295 260 * @since 3.0.0
296 - * @use for sorting by type payment gateway
261 + * @version 1.0.1
297 262 * @note tungnx checked has use
298 263 */
299 264 public static function update_payment_order() {
265 + if ( ! current_user_can( ADMIN_ROLE ) ) { // Fix security.
266 + return;
267 + }
268 +
269 + $nonce = LP_Request::get_param( 'nonce' );
270 + if ( ! wp_verify_nonce( $nonce, 'lp-settings' ) ) {
271 + die( 'Nonce is invalid!' );
272 + }
273 +
300 274 $payment_order = learn_press_get_request( 'order' );
301 275 update_option( 'learn_press_payment_order', $payment_order );
276 +
277 + die( 'Order of Payment Gateway is updated success' );
302 278 }
303 279
304 280 /**
305 281 * Enable type payment
@@ -304,14 +280,14 @@
304 280 /**
305 281 * Enable type payment
306 282 *
307 283 * @since 3.0.0
308 - * @use for enable type payment gateway
284 + * @version 1.0.1
309 285 * @note tungnx checked has use
310 286 */
311 287 public static function update_payment_status() {
312 - $payment_id = learn_press_get_request( 'id' );
313 - $status = LP_Request::get_string( 'status' );
288 + $payment_id = LP_Request::get_param( 'id' );
289 + $status = LP_Request::get_param( 'status' );
314 290 $payment = LP_Gateways::instance()->get_gateway( $payment_id );
315 291
316 292 if ( ! $payment ) {
317 293 return;
@@ -316,10 +292,22 @@
316 292 if ( ! $payment ) {
317 293 return;
318 294 }
319 295
296 + if ( ! current_user_can( ADMIN_ROLE ) ) { // Fix security.
297 + return;
298 + }
299 +
300 + $nonce = LP_Request::get_param( 'nonce' );
301 + if ( ! wp_verify_nonce( $nonce, 'lp-settings' ) ) {
302 + die( 'Nonce is invalid!' );
303 + }
304 +
320 305 $response[ $payment->id ] = $payment->enable( $status == 'yes' );
321 306
307 + $lp_settings_cache = new LP_Settings_Cache( true );
308 + $lp_settings_cache->clean_lp_settings();
309 +
322 310 learn_press_send_json( $response );
323 311 }
324 312
325 313 /**
@@ -328,13 +316,21 @@
328 316 * @since 3.0.0
329 317 * @note tungnnx checked has use
330 318 */
331 319 public static function update_email_status() {
332 -
333 320 $email_id = LP_Request::get_string( 'id' );
334 321 $status = LP_Request::get_string( 'status' );
335 322 $response = array();
336 323
324 + if ( ! current_user_can( ADMIN_ROLE ) ) { // Fix security.
325 + return;
326 + }
327 +
328 + $nonce = LP_Request::get_param( 'nonce' );
329 + if ( ! wp_verify_nonce( $nonce, 'lp-settings' ) ) {
330 + die( 'Nonce is invalid!' );
331 + }
332 +
337 333 if ( $email_id ) {
338 334
339 335 $email = LP_Emails::get_email( $email_id );
340 336 if ( ! $email ) {
@@ -347,8 +343,12 @@
347 343 foreach ( $emails as $email ) {
348 344 $response[ $email->id ] = $email->enable( $status == 'yes' );
349 345 }
350 346 }
347 +
348 + $lp_settings_cache = new LP_Settings_Cache( true );
349 + $lp_settings_cache->clean_lp_settings();
350 +
351 351 learn_press_send_json( $response );
352 352 }
353 353
354 354 /**
@@ -354,15 +354,35 @@
354 354 /**
355 355 * Search items by requesting params.
356 356 */
357 357 public static function modal_search_items() {
358 - $term = LP_Helper::sanitize_params_submitted( $_POST['term'] ?? '' );
359 - $type = LP_Helper::sanitize_params_submitted( $_POST['type'] ?? '' );
360 - $context = LP_Helper::sanitize_params_submitted( $_POST['context'] ?? '' );
361 - $context_id = LP_Helper::sanitize_params_submitted( $_POST['context_id'] ?? '' );
362 - $paged = LP_Helper::sanitize_params_submitted( $_POST['paged'] ?? '' );
363 - $exclude = LP_Request::get( 'exclude' );
358 + $term = LP_Request::get_param( 'term' );
359 + $type = LP_Request::get_param( 'type' );
360 + $context = LP_Request::get_param( 'context' );
361 + $context_id = LP_Request::get_param( 'context_id' );
362 + $paged = LP_Request::get_param( 'paged' );
363 + $exclude = LP_Request::get_param( 'exclude' );
364 364
365 + if ( ! current_user_can( ADMIN_ROLE ) ) { // Fix security
366 + $roles_accept = apply_filters( 'lp/backend/roles/can-search-items', [ ADMIN_ROLE ] );
367 +
368 + $flag = false;
369 + foreach ( $roles_accept as $role ) {
370 + if ( current_user_can( $role ) ) {
371 + $flag = true;
372 + }
373 + }
374 +
375 + if ( ! $flag ) {
376 + return;
377 + }
378 + }
379 +
380 + $nonce = LP_Request::get_param( 'nonce' );
381 + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
382 + die( 'Nonce is invalid!' );
383 + }
384 +
365 385 $search = new LP_Modal_Search_Items( compact( 'term', 'type', 'context', 'context_id', 'paged', 'exclude' ) );
366 386
367 387 learn_press_send_json(
368 388 array(
@@ -376,19 +396,40 @@
376 396 /**
377 397 * Search items by requesting params.
378 398 *
379 399 * @note tungnx checked has use
400 + * @deprecated 4.2.6.9.3
380 401 */
381 - public static function modal_search_users() {
382 - $term = LP_Helper::sanitize_params_submitted( $_POST['term'] ?? '' );
383 - $type = LP_Helper::sanitize_params_submitted( $_POST['type'] ?? '' );
384 - $context = LP_Helper::sanitize_params_submitted( $_POST['context'] ?? '' );
385 - $context_id = LP_Helper::sanitize_params_submitted( $_POST['context_id'] ?? '' );
386 - $paged = LP_Helper::sanitize_params_submitted( $_POST['paged'] ?? '' );
387 - $multiple = LP_Helper::sanitize_params_submitted( $_POST['multiple'] ?? '' ) == 'yes';
388 - $text_format = LP_Helper::sanitize_params_submitted( $_POST['text_format'] ?? '' );
389 - $exclude = LP_Request::get( 'exclude' );
402 + /*public static function modal_search_users() {
403 + $term = LP_Request::get_param( 'term' );
404 + $type = LP_Request::get_param( 'type' );
405 + $context = LP_Request::get_param( 'context' );
406 + $context_id = LP_Request::get_param( 'context_id' );
407 + $paged = LP_Request::get_param( 'paged' );
408 + $multiple = LP_Request::get_param( 'multiple' ) == 'yes';
409 + $text_format = LP_Request::get_param( 'text_format' );
410 + $exclude = LP_Request::get_param( 'exclude' );
411 + $roles_accept = apply_filters(
412 + 'lp/backend/roles/can-search-users',
413 + [ ADMIN_ROLE ]
414 + );
390 415
416 + $flag = false;
417 + foreach ( $roles_accept as $role ) {
418 + if ( current_user_can( $role ) ) {
419 + $flag = true;
420 + }
421 + }
422 +
423 + if ( ! $flag ) {
424 + return;
425 + }
426 +
427 + $nonce = LP_Request::get_param( 'nonce' );
428 + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
429 + die( 'Nonce is invalid!' );
430 + }
431 +
391 432 $search = new LP_Modal_Search_Users( compact( 'term', 'type', 'context', 'context_id', 'paged', 'multiple', 'text_format', 'exclude' ) );
392 433
393 434 learn_press_send_json(
394 435 array(
@@ -396,9 +437,9 @@
396 437 'nav' => $search->get_pagination(),
397 438 'users' => $search->get_items(),
398 439 )
399 440 );
400 - }
441 + }*/
401 442
402 443 /**
403 444 * Search course category.
404 445 */
@@ -404,12 +445,12 @@
404 445 */
405 446 public static function search_course_category() {
406 447 global $wpdb;
407 448 $sql = 'SELECT `t`.`term_id` as `id`, '
408 - . ' `t`.`name` `text` '
409 - . " FROM {$wpdb->terms} t "
410 - . " INNER JOIN {$wpdb->term_taxonomy} tt ON t.term_id = tt.term_id AND taxonomy='course_category' "
411 - . ' WHERE `t`.`name` LIKE %s';
449 + . ' `t`.`name` `text` '
450 + . " FROM {$wpdb->terms} t "
451 + . " INNER JOIN {$wpdb->term_taxonomy} tt ON t.term_id = tt.term_id AND taxonomy='course_category' "
452 + . ' WHERE `t`.`name` LIKE %s';
412 453 $s = '%' . filter_input( INPUT_GET, 'q' ) . '%';
413 454 $query = $wpdb->prepare( $sql, $s );
414 455 $items = $wpdb->get_results( $query );
415 456 $data = array( 'items' => $items );
@@ -422,8 +463,10 @@
422 463 *
423 464 * @note tungnx checked has use
424 465 */
425 466 public static function remove_items_from_order() {
467 + $response = new LP_REST_Response();
468 +
426 469 // ensure that user has permission
427 470 if ( ! current_user_can( 'edit_lp_orders' ) ) {
428 471 die( __( 'Access denied', 'learnpress' ) );
429 472 }
@@ -428,27 +471,29 @@
428 471 die( __( 'Access denied', 'learnpress' ) );
429 472 }
430 473
431 474 // verify nonce
432 - $nonce = learn_press_get_request( 'remove_nonce' );
433 - if ( ! wp_verify_nonce( $nonce, 'remove_order_item' ) ) {
475 + $nonce = LP_Request::get_param( 'nonce' );
476 + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
434 477 die( __( 'Nonce check failed', 'learnpress' ) );
435 478 }
436 479
437 480 // validate order
438 - $order_id = learn_press_get_request( 'order_id' );
439 - if ( ! is_numeric( $order_id ) || learn_press_get_post_type( $order_id ) != 'lp_order' ) {
481 + $order_id = LP_Request::get_param( 'order_id', 0, 'int' );
482 + if ( learn_press_get_post_type( $order_id ) != 'lp_order' ) {
440 483 die( __( 'Invalid order', 'learnpress' ) );
441 484 }
442 485
443 486 // validate item
444 - $items = learn_press_get_request( 'items' );
487 + $item_ids_str = LP_Request::get_param( 'items', '' );
488 + if ( empty( $item_ids_str ) ) {
489 + die( __( 'Invalid item', 'learnpress' ) );
490 + }
445 491
446 - $order = learn_press_get_order( $order_id );
492 + $item_ids = array_map( 'absint', explode( ',', $item_ids_str ) );
493 + $order = learn_press_get_order( $order_id );
447 494
448 - global $wpdb;
449 -
450 - foreach ( $items as $item_id ) {
495 + foreach ( $item_ids as $item_id ) {
451 496 $order->remove_item( $item_id );
452 497 }
453 498
454 499 $order_data = learn_press_update_order_items( $order_id );
@@ -455,10 +500,10 @@
455 500 $currency_symbol = learn_press_get_currency_symbol( $order_data['currency'] );
456 501 $order_data['subtotal_html'] = learn_press_format_price( $order_data['subtotal'], $currency_symbol );
457 502 $order_data['total_html'] = learn_press_format_price( $order_data['total'], $currency_symbol );
458 503 $order_items = $order->get_items();
504 + $html = '';
459 505 if ( $order_items ) {
460 - $html = '';
461 506 foreach ( $order_items as $item ) {
462 507 ob_start();
463 508 include learn_press_get_admin_view( 'meta-boxes/order/order-item.php' );
464 509 $html .= ob_get_clean();
@@ -464,15 +509,13 @@
464 509 $html .= ob_get_clean();
465 510 }
466 511 }
467 512
468 - learn_press_send_json(
469 - array(
470 - 'result' => 'success',
471 - 'item_html' => $html,
472 - 'order_data' => $order_data,
473 - )
474 - );
513 + $response->status = 'success';
514 + $response->data->item_html = $html;
515 + $response->data->order_data = $order_data;
516 +
517 + wp_send_json( $response );
475 518 }
476 519
477 520 /**
478 521 * Add courses to order
@@ -479,8 +522,28 @@
479 522 *
480 523 * @note tungnx checked has use
481 524 */
482 525 public static function add_items_to_order() {
526 + $response = new LP_REST_Response();
527 +
528 + $roles_accept = apply_filters( 'lp/backend/roles/can-add-items', [ ADMIN_ROLE ] );
529 +
530 + $flag = false;
531 + foreach ( $roles_accept as $role ) {
532 + if ( current_user_can( $role ) ) {
533 + $flag = true;
534 + }
535 + }
536 +
537 + if ( ! $flag ) {
538 + return;
539 + }
540 +
541 + $nonce = LP_Request::get_param( 'nonce' );
542 + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
543 + die( 'Nonce is invalid!' );
544 + }
545 +
483 546 // ensure that user has permission
484 547 if ( ! current_user_can( 'edit_lp_orders' ) ) {
485 548 die( __( 'Permission denied', 'learnpress' ) );
486 549 }
@@ -485,27 +548,25 @@
485 548 die( __( 'Permission denied', 'learnpress' ) );
486 549 }
487 550
488 551 // validate order
489 - $order_id = learn_press_get_request( 'order_id' );
552 + $order_id = LP_Request::get_param( 'order_id', 0 );
490 553 if ( ! is_numeric( $order_id ) || learn_press_get_post_type( $order_id ) != 'lp_order' ) {
491 554 die( __( 'Invalid order', 'learnpress' ) );
492 555 }
493 556
494 557 // validate item
495 - $item_ids = learn_press_get_request( 'items' );
496 - $order = learn_press_get_order( $order_id );
558 + $item_ids_str = LP_Request::get_param( 'items', '' );
559 + if ( empty( $item_ids_str ) ) {
560 + die( __( 'Invalid item', 'learnpress' ) );
561 + }
497 562
498 - $response = array(
499 - 'result' => 'error',
500 - );
501 -
502 - $order_item_ids = $order->add_items( $item_ids );
503 -
504 - if ( $order_item_ids ) {
505 - $html = '';
506 - $order_items = $order->get_items();
507 -
563 + $item_ids = array_map( 'absint', explode( ',', $item_ids_str ) );
564 + $order = learn_press_get_order( $order_id );
565 + $order_item = $order->add_items( $item_ids );
566 + if ( $order_item ) {
567 + $html = '';
568 + $order_items = $order->get_items();
508 569 $order_data = learn_press_update_order_items( $order_id );
509 570 $currency_symbol = learn_press_get_currency_symbol( $order_data['currency'] );
510 571 $order_data['subtotal_html'] = learn_press_format_price( $order_data['subtotal'], $currency_symbol );
511 572 $order_data['total_html'] = learn_press_format_price( $order_data['total'], $currency_symbol );
@@ -511,79 +572,27 @@
511 572 $order_data['total_html'] = learn_press_format_price( $order_data['total'], $currency_symbol );
512 573
513 574 if ( $order_items ) {
514 575 foreach ( $order_items as $item ) {
515 -
516 - if ( ! in_array( $item['id'], $order_item_ids ) ) {
576 + if ( ! in_array( $item['id'], $order_item ) ) {
517 577 continue;
518 578 }
519 579
520 580 ob_start();
521 - include learn_press_get_admin_view( 'meta-boxes/order/order-item.php' );
581 + Template::instance()->get_admin_template( 'meta-boxes/order/order-item.php', compact( 'item', 'order' ) );
522 582 $html .= ob_get_clean();
523 583 }
524 584 }
525 585
526 - $response = array(
527 - 'result' => 'success',
528 - 'item_html' => $html,
529 - 'order_data' => $order_data,
530 - );
586 + $response->status = 'success';
587 + $response->data->item_html = $html;
588 + $response->data->order_data = $order_data;
531 589 }
532 590
533 - learn_press_send_json( $response );
591 + wp_send_json( $response );
534 592 }
535 593
536 - /**
537 - * Get content send via payload and parse to json.
538 - *
539 - * @param mixed $params (Optional) List of keys want to get from payload.
540 - *
541 - * @return array|bool|mixed|object
542 - * @deprecated 4.1.6.9
543 - */
544 - /*public static function get_php_input( $params = '' ) {
545 - static $data = false;
546 - if ( false === $data ) {
547 - try {
548 - $data = json_decode( file_get_contents( 'php://input' ), true );
549 - } catch ( Exception $exception ) {
550 - }
551 - }
552 -
553 - if ( $data && func_num_args() > 0 ) {
554 - $params = is_array( func_get_arg( 0 ) ) ? func_get_arg( 0 ) : func_get_args();
555 - if ( $params ) {
556 - $request = array();
557 - foreach ( $params as $key ) {
558 - $request[] = array_key_exists( $key, $data ) ? $data[ $key ] : false;
559 - }
560 -
561 - return $request;
562 - }
563 - }
564 -
565 - return $data;
566 - }*/
567 -
568 - /**
569 - * Parse request content into var.
570 - * Normally, parse and assign to $_POST or $_GET.
571 - *
572 - * @param $var
573 - * @deprecated 4.1.6.9
574 - */
575 - /*public static function parsePhpInput( &$var ) {
576 - $data = self::get_php_input();
577 -
578 - if ( $data ) {
579 - foreach ( $data as $k => $v ) {
580 - $var[ $k ] = $v;
581 - }
582 - }
583 - }*/
584 -
585 - public static function load_chart() {
594 + /*public static function load_chart() {
586 595 if ( ! class_exists( 'LP_Submenu_Statistics' ) ) {
587 596 $statistic = include_once LP_PLUGIN_PATH . '/inc/admin/sub-menus/class-lp-submenu-statistics.php';
588 597 } else {
589 598 $statistic = new LP_Submenu_Statistics();
@@ -588,9 +597,9 @@
588 597 } else {
589 598 $statistic = new LP_Submenu_Statistics();
590 599 }
591 600 $statistic->load_chart();
592 - }
601 + }*/
593 602
594 603 public static function json_search_customer_name( $query ) {
595 604 global $wpdb;
596 605
@@ -610,49 +619,55 @@
610 619 *
611 620 * @note tungnnx checked use
612 621 */
613 622 public static function create_page() {
614 - $response = array(
615 - 'code' => 0,
616 - 'message' => '',
617 - );
623 + $response = new Response();
618 624
619 - /**
620 - * Check valid
621 - *
622 - * 1. Capability - user can edit pages (add\edit\delete)
623 - * 2. Check nonce return true
624 - * 3. param post page_name not empty
625 - *
626 - * @since 3.2.6.8
627 - * @author tungnx
628 - */
629 - if ( ! current_user_can( 'edit_pages' ) || empty( $_POST['page_name'] ) ) {
630 - $response['message'] = 'Request invalid';
631 - learn_press_send_json( $response );
632 - }
625 + try {
626 + /**
627 + * Check valid
628 + *
629 + * 1. Capability - user can edit pages (add\edit\delete)
630 + * 2. Check nonce return true
631 + * 3. param post page_name not empty
632 + *
633 + * @since 3.2.6.8
634 + */
635 + if ( ! current_user_can( UserModel::ROLE_ADMINISTRATOR )
636 + || empty( $_POST['page_name'] ) ) {
637 + throw new Exception( 'Request invalid' );
638 + }
633 639
634 - $page_name = LP_Helper::sanitize_params_submitted( $_POST['page_name'] );
640 + // Check nonce
641 + $nonce = LP_Request::get_param( 'nonce' );
642 + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
643 + throw new Exception( 'Request invalid' );
644 + }
635 645
636 - if ( $page_name ) {
637 - $page_id = LP_Helper::create_page( $page_name );
646 + $page_name = LP_Helper::sanitize_params_submitted( $_POST['page_name'] );
647 + $field_name = LP_Request::get_param( 'field_name' );
638 648
639 - if ( $page_id ) {
640 - $response['code'] = 1;
641 - $response['message'] = 'create page success';
642 - $response['page'] = get_post( $page_id );
643 - $html = learn_press_pages_dropdown( '', '', array( 'echo' => false ) );
644 - preg_match_all( '!value=\"([0-9]+)\"!', $html, $matches );
645 - $response['positions'] = $matches[1];
646 - $response['html'] = '<a href="' . get_edit_post_link( $page_id ) . '" target="_blank">' . __( 'Edit Page', 'learnpress' ) . '</a>&nbsp;';
647 - $response['html'] .= '<a href="' . get_permalink( $page_id ) . '" target="_blank">' . __( 'View Page', 'learnpress' ) . '</a>';
648 - } else {
649 - $response['error'] = __( 'Error! Page creation failed. Please try again.', 'learnpress' );
649 + if ( ! $page_name ) {
650 + throw new Exception( __( 'Empty page name!', 'learnpress' ) );
650 651 }
651 - } else {
652 - $response['error'] = __( 'Empty page name!', 'learnpress' );
652 +
653 + $data_create_page = array(
654 + 'post_title' => $page_name,
655 + );
656 +
657 + $page_id = LP_Helper::create_page( $data_create_page, $field_name );
658 +
659 + if ( ! $page_id ) {
660 + throw new Exception( __( 'Error! Page creation failed. Please try again.', 'learnpress' ) );
661 + }
662 +
663 + $response->status = Response::STATUS_SUCCESS;
664 + $response->message = 'create page success';
665 + } catch ( Exception $e ) {
666 + $response->message = $e->getMessage();
653 667 }
654 - learn_press_send_json( $response );
668 +
669 + wp_send_json( $response );
655 670 }
656 671
657 672 /**
658 673 * Get edit|view link of a page
@@ -661,11 +676,11 @@
661 676 $page_id = (int) $_REQUEST['page_id'] ?? 0;
662 677 ?>
663 678
664 679 <a href="<?php echo get_edit_post_link( $page_id ); ?>"
665 - target="_blank"><?php _e( 'Edit Page', 'learnpress' ); ?></a>
680 + target="_blank"><?php _e( 'Edit Page', 'learnpress' ); ?></a>
666 681 <a href="<?php echo get_permalink( $page_id ); ?>"
667 - target="_blank"><?php _e( 'View Page', 'learnpress' ); ?></a>
682 + target="_blank"><?php _e( 'View Page', 'learnpress' ); ?></a>
668 683
669 684 <?php
670 685 die();
671 686 }
@@ -671,10 +686,12 @@
671 686 }
672 687
673 688 /**
674 689 * Get date from, to for static chart
690 + *
691 + * @deprecated 4.2.6.9.3
675 692 */
676 - public static function custom_stats() {
693 + /*public static function custom_stats() {
677 694 $from = LP_Helper::sanitize_params_submitted( $_REQUEST['from'] ?? 0 );
678 695 $to = LP_Helper::sanitize_params_submitted( $_REQUEST['to'] ?? 0 );
679 696 $date_diff = strtotime( $to ) - strtotime( $from );
680 697 if ( $date_diff <= 0 || $from == 0 || $to == 0 ) {
@@ -681,33 +698,9 @@
681 698 die();
682 699 }
683 700 learn_press_process_chart( learn_press_get_chart_students( $to, 'days', floor( $date_diff / ( 60 * 60 * 24 ) ) + 1 ) );
684 701 die();
685 - }
686 -
687 - /**
688 - * Export Order invoice to PDF
689 - *
690 - * @since 3.2.7.8
691 - * @author hungkv
692 - */
693 - public static function update_order_exports() {
694 - $order_id = absint( $_POST['order_id'] );
695 - $order = learn_press_get_order( $order_id );
696 - $currency_symbol = learn_press_get_currency_symbol( $order->get_currency() );
697 -
698 - ob_start();
699 - learn_press_admin_view(
700 - 'meta-boxes/order/content-tab-preview-exports-invoice.php',
701 - array(
702 - 'order' => $order,
703 - 'currency_symbol' => $currency_symbol,
704 - )
705 - );
706 - $html = ob_get_clean();
707 - echo wp_kses_post( $html );
708 - die();
709 - }
702 + }*/
710 703 }
711 704
712 705 add_action( 'init', array( 'LP_Admin_Ajax', 'init' ) );
713 706 }