| @@ -2,10 +2,13 @@ | ||
| 2 | 2 | /** |
| 3 | 3 | * Template form search author field for custom post type of course. |
| 4 | 4 | * |
| 5 | 5 | * @since 4.2.6.9 |
| 6 | - * @version 1.0.0 | |
| 6 | + * @version 1.0.1 | |
| 7 | 7 | */ |
| 8 | + | |
| 9 | +use LearnPress\Models\CourseModel; | |
| 10 | + | |
| 8 | 11 | $screen = function_exists( 'get_current_screen' ) ? get_current_screen() : null; |
| 9 | 12 | |
| 10 | 13 | // Check condition show field search by author for post. |
| 11 | 14 | $show_search_author_field = 0; |
| @@ -11,9 +14,9 @@ | ||
| 11 | 14 | $show_search_author_field = 0; |
| 12 | 15 | if ( ! $screen instanceof WP_Screen ) { |
| 13 | 16 | return; |
| 14 | 17 | } |
| 15 | -$course_item_types = learn_press_get_course_item_types(); | |
| 18 | +$course_item_types = CourseModel::item_types_support(); | |
| 16 | 19 | $screens_show_search_author_field = [ |
| 17 | 20 | 'edit-' . LP_COURSE_CPT, |
| 18 | 21 | 'edit-' . LP_QUESTION_CPT, |
| 19 | 22 | 'edit-' . LP_ORDER_CPT, |
| @@ -39,18 +42,30 @@ | ||
| 39 | 42 | |
| 40 | 43 | $input_id = 'post-search-input'; |
| 41 | 44 | |
| 42 | 45 | if ( ! empty( $_REQUEST['orderby'] ) ) { |
| 43 | - echo '<input type="hidden" name="orderby" value="' . esc_attr( $_REQUEST['orderby'] ) . '" />'; | |
| 46 | + echo sprintf( | |
| 47 | + '<input type="hidden" name="orderby" value="%s" />', | |
| 48 | + esc_attr( sanitize_key( $_REQUEST['orderby'] ) ) | |
| 49 | + ); | |
| 44 | 50 | } |
| 45 | 51 | if ( ! empty( $_REQUEST['order'] ) ) { |
| 46 | - echo '<input type="hidden" name="order" value="' . esc_attr( $_REQUEST['order'] ) . '" />'; | |
| 52 | + echo sprintf( | |
| 53 | + '<input type="hidden" name="order" value="%s" />', | |
| 54 | + esc_attr( sanitize_key( $_REQUEST['order'] ) ) | |
| 55 | + ); | |
| 47 | 56 | } |
| 48 | 57 | if ( ! empty( $_REQUEST['post_mime_type'] ) ) { |
| 49 | - echo '<input type="hidden" name="post_mime_type" value="' . esc_attr( $_REQUEST['post_mime_type'] ) . '" />'; | |
| 58 | + echo sprintf( | |
| 59 | + '<input type="hidden" name="post_mime_type" value="%s" />', | |
| 60 | + esc_attr( $_REQUEST['post_mime_type'] ) | |
| 61 | + ); | |
| 50 | 62 | } |
| 51 | 63 | if ( ! empty( $_REQUEST['detached'] ) ) { |
| 52 | - echo '<input type="hidden" name="detached" value="' . esc_attr( $_REQUEST['detached'] ) . '" />'; | |
| 64 | + echo sprintf( | |
| 65 | + '<input type="hidden" name="detached" value="%s" />', | |
| 66 | + esc_attr( $_REQUEST['detached'] ) | |
| 67 | + ); | |
| 53 | 68 | } |
| 54 | 69 | |
| 55 | 70 | $value_search = LP_Request::get_param( 's', '' ); |
| 56 | 71 | ?> |
| @@ -58,10 +73,18 @@ | ||
| 58 | 73 | <label class="screen-reader-text" for="<?php echo esc_attr( $input_id ); ?>"> |
| 59 | 74 | <?php echo $post_type_object->labels->search_items; ?>: |
| 60 | 75 | </label> |
| 61 | 76 | <input type="search" |
| 62 | - id="<?php echo esc_attr( $input_id ); ?>" | |
| 63 | - name="s" | |
| 64 | - placeholder="<?php _e( 'Search', 'learnpress' ); ?>" | |
| 65 | - value="<?php echo esc_attr( $value_search ) ?>"/> | |
| 66 | - <?php submit_button( $post_type_object->labels->search_items, '', '', false, array( 'id' => 'search-submit' ) ); ?> | |
| 77 | + id="<?php echo esc_attr( $input_id ); ?>" | |
| 78 | + name="s" | |
| 79 | + placeholder="<?php _e( 'Search', 'learnpress' ); ?>" | |
| 80 | + value="<?php echo esc_attr( $value_search ); ?>"/> | |
| 81 | + <?php | |
| 82 | + submit_button( | |
| 83 | + $post_type_object->labels->search_items, | |
| 84 | + '', | |
| 85 | + '', | |
| 86 | + false, | |
| 87 | + array( 'id' => 'search-submit' ) | |
| 88 | + ); | |
| 89 | + ?> | |
| 67 | 90 | </p> |