PluginProbe
Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits / 3.1.9
Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits v3.1.9
3.2.2 3.2.3 3.2.1 3.2.0 3.1.9 3.1.8 3.1.7 3.1.6 3.1.5 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 3.0.9 trunk 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.1.1 1.1.3 1.1.4 1.1.5 All 174 releases
master-addons / inc / classes / ajax-queries.php

ajax-queries.php in Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits 3.1.9, at inc/classes/ajax-queries.php

389 lines 16.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace MasterAddons\Inc\Classes;
4
5 if (!defined('ABSPATH')) {
6 exit; // Exit if accessed directly
7 }
8
9 use \Elementor\Plugin;
10 use \Elementor\Core\Common\Modules\Ajax\Module as Ajax;
11
12 use MasterAddons\Master_Elementor_Addons;
13 use MasterAddons\Inc\Classes\Helper;
14
15 /**
16 * Author Name: Liton Arefin
17 * Author URL: https://jeweltheme.com
18 * Date: 1/7/20
19 */
20
21 class Ajax_Queries
22 {
23
24 public $loaded_templates = [];
25
26 private static $instance = null;
27
28 public static function get_instance()
29 {
30 if (!self::$instance) {
31 self::$instance = new self;
32 }
33 return self::$instance;
34 }
35
36
37 public function __construct()
38 {
39
40 // $this->loaded_templates[] = $this->loaded_templates;
41
42 // Restrict Content
43 add_action('wp_ajax_jltma_restrict_content', array($this, 'jltma_restrict_content'));
44 add_action('wp_ajax_nopriv_jltma_restrict_content', array($this, 'jltma_restrict_content'));
45
46 // Domain Checker
47 add_action('wp_ajax_jltma_domain_checker', array($this, 'jltma_domain_checker'));
48 add_action('wp_ajax_nopriv_jltma_domain_checker', array($this, 'jltma_domain_checker'));
49
50 // Elementor Ajax Requests
51 add_action('elementor/ajax/register_actions', [$this, 'jltma_register_ajax_actions']);
52 }
53
54 public function jltma_register_ajax_actions($ajax_manager)
55 {
56 $ajax_manager->register_ajax_action('jltma_query_control_value_titles', [$this, 'jltma_ajax_call_control_value_titles']);
57 $ajax_manager->register_ajax_action('jltma_query_control_filter_autocomplete', [$this, 'jltma_ajax_call_filter_autocomplete']);
58 }
59
60
61 public function jltma_ajax_call_control_value_titles($request)
62 {
63 $results = call_user_func([$this, 'get_value_titles_for_' . $request['query_type']], $request);
64
65 return $results;
66 }
67
68 // Calls function depending on ajax query data
69 public function jltma_ajax_call_filter_autocomplete(array $data)
70 {
71
72 if (empty($data['query_type']) || empty($data['q'])) {
73 throw new \Exception('Bad Request');
74 }
75
76 $results = call_user_func([$this, 'get_autocomplete_for_' . $data['query_type']], $data);
77
78 return [
79 'results' => $results,
80 ];
81 }
82
83 // Gets autocomplete values for 'posts' query type
84 protected function get_autocomplete_for_posts($data)
85 {
86 $results = [];
87
88 $query_params = [
89 'post_type' => sanitize_text_field($data['object_type']),
90 's' => sanitize_text_field($data['q']),
91 'posts_per_page' => -1,
92 ];
93
94 if ('attachment' === $query_params['post_type']) {
95 $query_params['post_status'] = 'inherit';
96 }
97
98 $query = new \WP_Query($query_params);
99
100 foreach ($query->posts as $post) {
101 $results[] = [
102 'id' => $post->ID,
103 'text' => $post->post_title,
104 ];
105 }
106
107 return $results;
108 }
109
110 // Gets autocomplete values for taxonomy 'terms' query type
111 protected function get_autocomplete_for_terms($data)
112 {
113 $results = [];
114
115 $taxonomies = get_object_taxonomies('');
116
117 $query_params = [
118 'taxonomy' => $taxonomies,
119 'search' => sanitize_text_field($data['q']),
120 'hide_empty' => false,
121 ];
122
123 $terms = get_terms($query_params);
124
125 foreach ($terms as $term) {
126 $taxonomy = get_taxonomy($term->taxonomy);
127
128 $results[] = [
129 'id' => $term->term_id,
130 'text' => $taxonomy->labels->singular_name . ': ' . $term->name,
131 ];
132 }
133
134 return $results;
135 }
136
137
138 // Gets autocomplete values for 'authors' query type
139 protected function get_autocomplete_for_authors($data)
140 {
141 $results = [];
142
143 $query_params = [
144 'who' => 'authors',
145 'has_published_posts' => true,
146 'fields' => [
147 'ID',
148 'display_name',
149 ],
150 'search' => '*' . sanitize_text_field($data['q']) . '*',
151 'search_columns' => [
152 'user_login',
153 'user_nicename',
154 ],
155 ];
156
157 $user_query = new \WP_User_Query($query_params);
158
159 foreach ($user_query->get_results() as $author) {
160 $results[] = [
161 'id' => $author->ID,
162 'text' => $author->display_name,
163 ];
164 }
165
166 return $results;
167 }
168
169 // Gets value titles for 'terms' query type - for saved values
170 protected function get_value_titles_for_terms($data)
171 {
172 $results = [];
173
174 if (empty($data['id'])) {
175 return $results;
176 }
177
178 $term_ids = is_array($data['id']) ? $data['id'] : array($data['id']);
179
180 foreach ($term_ids as $term_id) {
181 $term = get_term($term_id);
182
183 if ($term && !is_wp_error($term)) {
184 $taxonomy = get_taxonomy($term->taxonomy);
185 $results[ $term_id ] = $taxonomy->labels->singular_name . ': ' . $term->name;
186 }
187 }
188
189 return $results;
190 }
191
192 // Gets value titles for 'posts' query type - for saved values
193 protected function get_value_titles_for_posts($data)
194 {
195 $results = [];
196
197 if (empty($data['id'])) {
198 return $results;
199 }
200
201 $post_ids = is_array($data['id']) ? $data['id'] : array($data['id']);
202
203 foreach ($post_ids as $post_id) {
204 $post = get_post($post_id);
205
206 if ($post) {
207 $results[ $post_id ] = $post->post_title;
208 }
209 }
210
211 return $results;
212 }
213
214 // Gets value titles for 'authors' query type - for saved values
215 protected function get_value_titles_for_authors($data)
216 {
217 $results = [];
218
219 if (empty($data['id'])) {
220 return $results;
221 }
222
223 $author_ids = is_array($data['id']) ? $data['id'] : array($data['id']);
224
225 foreach ($author_ids as $author_id) {
226 $author = get_user_by('id', $author_id);
227
228 if ($author) {
229 $results[ $author_id ] = $author->display_name;
230 }
231 }
232
233 return $results;
234 }
235
236
237 // Restrict Content
238 public function jltma_restrict_content()
239 {
240 // Verify nonce first (localized to the frontend script as JLTMA_SCRIPTS.nonce).
241 if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'master-addons-elementor' ) ) {
242 wp_send_json_error( __( 'Security check failed.', 'master-addons' ) );
243 }
244
245 parse_str( isset( $_POST['fields'] ) ? sanitize_text_field( wp_unslash( $_POST['fields'] ) ) : '', $output ); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
246
247 if (!empty($_POST['fields'])) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
248
249 // Math Captcha
250 if ( isset( $_POST['restrict_type'] ) && $_POST['restrict_type'] == 'math_captcha' ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
251 // Field names match the rendered form inputs (jltma_rc_answer / _hd).
252 $rc_answer = isset( $output['jltma_rc_answer'] ) ? trim( $output['jltma_rc_answer'] ) : '';
253 $rc_answer_hd = isset( $output['jltma_rc_answer_hd'] ) ? trim( $output['jltma_rc_answer_hd'] ) : '';
254 if ( $rc_answer === '' || $rc_answer !== $rc_answer_hd ) {
255 die(json_encode(array(
256 "result" => "validate",
257 "output" => /* translators: %s: Error message */ sprintf(__('%1$s &nbsp;', 'master-addons' ), wp_kses_post( wp_unslash( isset( $_POST['error_message'] ) ? $_POST['error_message'] : '' ) )) // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
258 )));
259 }
260 }
261
262 // Password Protection
263 if ( isset( $_POST['restrict_type'] ) && $_POST['restrict_type'] == 'password' ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
264 if ( ( isset( $_POST['content_pass'] ) ? sanitize_text_field( wp_unslash( $_POST['content_pass'] ) ) : '' ) !== $output['ma_el_restrict_content_pass'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
265 $error_msg = isset($_POST['error_message']) ? stripslashes(sanitize_text_field( wp_unslash( $_POST['error_message'] ) )) : __('Incorrect password.', 'master-addons'); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
266 die(json_encode(array(
267 "result" => "validate",
268 "output" => $error_msg
269 )));
270 }
271 }
272
273
274 // Age Restrict
275 if ( isset( $_POST['restrict_type'] ) && $_POST['restrict_type'] == 'age_restrict' ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
276
277 $min_age = isset( $_POST['restrict_age']['min_age'] ) ? (float) sanitize_text_field( wp_unslash( $_POST['restrict_age']['min_age'] ) ) : 0; // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
278
279 // Enter Age
280 if ( isset( $_POST['restrict_age']['age_type'] ) && sanitize_key( wp_unslash( $_POST['restrict_age']['age_type'] ) ) === "enter_age" ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
281
282 if (($output['ma_el_ra_year'] == "") || ($output['ma_el_ra_year'] < $min_age)) {
283 die(json_encode(array(
284 "result" => "validate",
285 "output" => /* translators: %s: Error message */ sprintf(__('%1$s &nbsp;', 'master-addons' ), wp_kses_post( wp_unslash( isset( $_POST['error_message'] ) ? $_POST['error_message'] : '' ) )) // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
286 )));
287 }
288 }
289
290 if ( isset( $_POST['restrict_age']['age_type'] ) && sanitize_key( wp_unslash( $_POST['restrict_age']['age_type'] ) ) === "age_checkbox" ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
291 // Checkbox Age Restriction
292 if ($output['ma_el_rc_check'] != "on") {
293 die(json_encode(array(
294 "result" => "validate",
295 "output" => /* translators: %s: Error message */ sprintf(__('%1$s &nbsp;', 'master-addons' ), wp_kses_post( wp_unslash( isset( $_POST['error_message'] ) ? $_POST['error_message'] : '' ) )) // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
296 )));
297 }
298 }
299
300 if ( isset( $_POST['restrict_age']['age_type'] ) && sanitize_key( wp_unslash( $_POST['restrict_age']['age_type'] ) ) === "input_age" ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
301
302 if ($output['ma_el_ra_day'] == "" || $output['ma_el_ra_month'] == "" || $output['ma_el_ra_year'] == "") {
303 die(json_encode(array(
304 "result" => "validate",
305 "output" => /* translators: %s: Restrict Age */ sprintf(__('%1$s &nbsp;&nbsp;', 'master-addons' ), sanitize_text_field( wp_unslash( isset( $_POST['restrict_age']['empty_bday'] ) ? $_POST['restrict_age']['empty_bday'] : '' ) )) // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
306 )));
307 } else if (!checkdate($output['ma_el_ra_month'], $output['ma_el_ra_day'], $output['ma_el_ra_year'])) {
308 die(json_encode(array(
309 "result" => "validate",
310 "output" => /* translators: %s: Restrict Age */ sprintf(__('%1$s &nbsp;&nbsp;', 'master-addons' ), sanitize_text_field( wp_unslash( isset( $_POST['restrict_age']['non_exist_bday'] ) ? $_POST['restrict_age']['non_exist_bday'] : '' ) )) // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
311 )));
312 } else {
313 $birthday = sprintf("%04d-%02d-%02d", $output['ma_el_ra_year'], $output['ma_el_ra_month'], $output['ma_el_ra_day']);
314 $today = new \DateTime();
315 $min = $today->modify("-{$min_age} year")->format("Y-m-d");
316
317 // Check if after the minimum age date
318 if ($birthday > $min) {
319 die(json_encode(array(
320 "result" => "validate",
321 "output" => /* translators: %s: Error message */ sprintf(__('%1$s , minimum age %2$s', 'master-addons' ), sanitize_text_field($min_age), wp_kses_post( wp_unslash( isset( $_POST['error_message'] ) ? $_POST['error_message'] : '' ) )) // phpcs:ignore WordPress.Security.NonceVerification.Missing -- no nonce available for this AJAX handler
322 )));
323 }
324 }
325 }
326 }
327
328 die(json_encode(array(
329 "result" => "success",
330 "output" => ""
331 )));
332 } // end if fields
333
334 }
335
336
337 // Domain Checker Content
338 public function jltma_domain_checker()
339 {
340 // Check security field first
341 if (empty($_POST['nonce']) || !wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'jltma-domain-checker')) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
342 wp_send_json_error(__('Security Error.', 'master-addons'));
343 }
344
345 $succes_msg = isset($_POST['succes_msg']) ? urldecode(html_entity_decode(wp_kses_post( wp_unslash( $_POST['succes_msg'] ) ))) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
346 $error_msg = isset($_POST['error_msg']) ? urldecode(html_entity_decode(wp_kses_post( wp_unslash( $_POST['error_msg'] ) ))) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
347 $not_found = isset($_POST['not_found']) ? urldecode(html_entity_decode(wp_kses_post( wp_unslash( $_POST['not_found'] ) ))) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
348 $not_entered_domain = isset($_POST['not_entered_domain']) ? sanitize_text_field( wp_unslash( $_POST['not_entered_domain'] ) ) : __('Please enter a domain name.', 'master-addons'); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
349
350 if (empty($_POST['domain'])) {
351 wp_send_json_error($not_entered_domain);
352 }
353
354 $domain = str_replace(array('www.', 'http://'), '', sanitize_text_field( wp_unslash( $_POST['domain'] ) )); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified above
355 $split = explode('.', $domain);
356 if (count($split) == 1) {
357 $domain = $domain . ".com";
358 }
359 $domain = preg_replace("/[^-a-zA-Z0-9.]+/", "", $domain);
360
361 if (strlen($domain) > 0) {
362 // Class responsible for checking if a domain is registered
363 $domain_check = new Domain_Checker();
364 $available = $domain_check->is_available($domain);
365
366 $domain_html = '<strong>' . esc_html($domain) . '</strong>';
367 // Replace both %s and HTML entity variants
368 $search = ['%s', '&percnt;s', '%25s'];
369
370 switch ($available) {
371 case '1':
372 wp_send_json_success(str_replace($search, $domain_html, $succes_msg));
373 break;
374
375 case '0':
376 wp_send_json_error(str_replace($search, $domain_html, $error_msg));
377 break;
378
379 default:
380 wp_send_json_error($not_found);
381 }
382 }
383
384 wp_send_json_error(__('Please enter a valid Domain name.', 'master-addons' ));
385 }
386 }
387
388 // Ajax_Queries::get_instance();
389