PluginProbe
MxChat – AI Chatbot & Content Generation for WordPress / 3.1.8
MxChat – AI Chatbot & Content Generation for WordPress v3.1.8
3.2.21 3.2.20 3.2.19 3.2.18 3.2.17 3.2.16 3.2.15 3.2.14 3.2.12 3.2.13 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 3.2.6 3.2.5 3.2.4 3.2.3 3.2.2 3.2.1 2.0.3 2.0.4 2.0.5 2.0.6 All 152 releases
← All changes | admin/class-ajax-handler.php +18 -454 3.2.133.1.8 View file →
@@ -47,308 +47,10 @@
47 47 add_action('wp_ajax_mxchat_get_debug_log', array($this, 'mxchat_get_debug_log_callback'));
48 48 add_action('wp_ajax_mxchat_clear_debug_log', array($this, 'mxchat_clear_debug_log_callback'));
49 49 add_action('wp_ajax_mxchat_export_settings', array($this, 'mxchat_export_settings_callback'));
50 50 add_action('wp_ajax_mxchat_reset_all_settings', array($this, 'mxchat_reset_all_settings_callback'));
51 -
52 - // Global rate-limit usage counter reset (admin-only, nonce-guarded)
53 - add_action('wp_ajax_mxchat_reset_global_rate_limit', array($this, 'mxchat_reset_global_rate_limit_callback'));
54 -
55 - // Custom (OpenAI-compatible) Provider connection test
56 - add_action('wp_ajax_mxchat_test_custom_provider', array($this, 'mxchat_test_custom_provider_callback'));
57 -
58 - // Built-in provider key validation — cheap per-provider auth check (plan-mxchat-20260623-c41f74)
59 - add_action('wp_ajax_mxchat_test_provider_key', array($this, 'mxchat_test_provider_key_callback'));
60 -
61 - // Custom Post Meta discovery scan for the KB whitelist picker (plan-mxchat-20260709-fe8e4e)
62 - add_action('wp_ajax_mxchat_scan_custom_meta_keys', array($this, 'mxchat_scan_custom_meta_keys_callback'));
63 51 }
64 52
65 -/**
66 - * Discover non-ACF custom post-meta keys present on published public content, so the
67 - * KB → Custom Post Meta section can offer a click-to-add picker instead of a blind
68 - * "type the exact key you already know" textarea. plan-mxchat-20260709-fe8e4e.
69 - *
70 - * Bounded + button-triggered only (never on page load). Returns up to 50 keys by
71 - * frequency, each with a short sample value, so the owner can judge relevance before
72 - * whitelisting. Underscore-prefixed (protected/internal) keys are hidden unless the
73 - * caller opts in; ACF-managed keys are excluded so this picker never double-lists the
74 - * sibling ACF discovery picker on the same page.
75 - */
76 -public function mxchat_scan_custom_meta_keys_callback() {
77 - check_ajax_referer('mxchat_prompts_setting_nonce');
78 -
79 - if (!current_user_can('manage_options')) {
80 - wp_send_json_error(['message' => esc_html__('Unauthorized', 'mxchat')]);
81 - }
82 -
83 - global $wpdb;
84 -
85 - $include_internal = isset($_POST['include_internal']) && $_POST['include_internal'] === '1';
86 -
87 - // Restrict discovery to public post types (the content the KB actually embeds).
88 - $post_types = get_post_types(array('public' => true), 'names');
89 - if (empty($post_types)) {
90 - wp_send_json_success(array('keys' => array(), 'scanned' => 0));
91 - }
92 - $pt_placeholders = implode(',', array_fill(0, count($post_types), '%s'));
93 -
94 - // Build the set of ACF-managed meta keys to exclude. ACF stores, alongside each
95 - // value key `foo`, a reference key `_foo` whose value is the ACF field key
96 - // (`field_xxxxx`). Strip the leading underscore from every such reference key to
97 - // get the real meta key, and exclude those — the ACF picker on this page owns them.
98 - $acf_managed = array();
99 - $acf_refs = $wpdb->get_col(
100 - $wpdb->prepare(
101 - "SELECT DISTINCT meta_key FROM {$wpdb->postmeta} WHERE meta_key LIKE %s AND meta_value LIKE %s",
102 - $wpdb->esc_like('_') . '%',
103 - $wpdb->esc_like('field_') . '%'
104 - )
105 - );
106 - foreach ((array) $acf_refs as $ref_key) {
107 - if (strlen($ref_key) > 1 && $ref_key[0] === '_') {
108 - $acf_managed[substr($ref_key, 1)] = true;
109 - }
110 - }
111 -
112 - // Discover keys + counts + a sample value in one bounded aggregate query.
113 - // SUBSTRING(MIN(...)) keeps the sample selection ONLY_FULL_GROUP_BY-safe.
114 - $params = $post_types;
115 - $sql = "SELECT pm.meta_key AS mk, COUNT(*) AS n, SUBSTRING(MIN(pm.meta_value), 1, 200) AS sample
116 - FROM {$wpdb->postmeta} pm
117 - INNER JOIN {$wpdb->posts} p ON p.ID = pm.post_id
118 - WHERE p.post_status = 'publish'
119 - AND p.post_type IN ($pt_placeholders)
120 - AND pm.meta_key <> ''";
121 - if (!$include_internal) {
122 - $sql .= " AND pm.meta_key NOT LIKE %s";
123 - $params[] = $wpdb->esc_like('_') . '%';
124 - }
125 - $sql .= " GROUP BY pm.meta_key ORDER BY n DESC, pm.meta_key ASC LIMIT 200";
126 -
127 - // phpcs:ignore WordPress.DB.PreparedSQL — placeholders assembled above, values in $params.
128 - $rows = $wpdb->get_results($wpdb->prepare($sql, $params));
129 -
130 - $keys = array();
131 - foreach ((array) $rows as $row) {
132 - $mk = $row->mk;
133 - if (isset($acf_managed[$mk])) {
134 - continue; // already offered by the ACF picker
135 - }
136 -
137 - $raw = (string) $row->sample;
138 - if ($raw !== '' && (is_serialized($raw) || preg_match('/^(a:\d+:\{|O:\d+:"|s:\d+:")/', $raw))) {
139 - $sample = esc_html__('[structured value]', 'mxchat');
140 - } else {
141 - $sample = trim(preg_replace('/\s+/', ' ', $raw));
142 - if (function_exists('mb_strlen') ? mb_strlen($sample) > 60 : strlen($sample) > 60) {
143 - $sample = (function_exists('mb_substr') ? mb_substr($sample, 0, 60) : substr($sample, 0, 60)) . '…';
144 - }
145 - if ($sample === '') {
146 - $sample = esc_html__('(empty value)', 'mxchat');
147 - }
148 - }
149 -
150 - $keys[] = array(
151 - 'key' => $mk,
152 - 'count' => (int) $row->n,
153 - 'sample' => $sample,
154 - );
155 -
156 - if (count($keys) >= 50) {
157 - break;
158 - }
159 - }
160 -
161 - wp_send_json_success(array(
162 - 'keys' => $keys,
163 - 'scanned' => is_array($rows) ? count($rows) : 0,
164 - ));
165 -}
166 -
167 -/**
168 - * Test connection to a Custom (OpenAI-compatible) provider by hitting its /models endpoint
169 - * with whichever auth scheme the user configured. Reports model count or a clean error.
170 - */
171 -public function mxchat_test_custom_provider_callback() {
172 - check_ajax_referer('mxchat_test_custom_provider');
173 - if (!current_user_can('manage_options')) {
174 - wp_send_json_error(array('message' => esc_html__('Unauthorized', 'mxchat')));
175 - }
176 -
177 - $options = get_option('mxchat_options', array());
178 - $base_url = isset($options['custom_provider_base_url']) ? trim((string) $options['custom_provider_base_url']) : '';
179 - $api_key = isset($options['custom_provider_api_key']) ? trim((string) $options['custom_provider_api_key']) : '';
180 - $auth = isset($options['custom_provider_auth_scheme']) ? $options['custom_provider_auth_scheme'] : 'bearer';
181 - $api_version = isset($options['custom_provider_api_version']) ? trim((string) $options['custom_provider_api_version']) : '';
182 -
183 - if (empty($base_url)) {
184 - wp_send_json_error(array('message' => esc_html__('Base URL is empty. Save it first.', 'mxchat')));
185 - }
186 -
187 - $url = rtrim($base_url, '/') . '/models';
188 - if (!empty($api_version)) {
189 - $url = add_query_arg('api-version', $api_version, $url);
190 - }
191 -
192 - $headers = array('Content-Type' => 'application/json');
193 - if (!empty($api_key)) {
194 - if ($auth === 'api-key') {
195 - $headers['api-key'] = $api_key;
196 - } else {
197 - $headers['Authorization'] = 'Bearer ' . $api_key;
198 - }
199 - }
200 -
201 - $response = wp_remote_get($url, array(
202 - 'headers' => $headers,
203 - 'timeout' => 10,
204 - ));
205 -
206 - if (is_wp_error($response)) {
207 - wp_send_json_error(array('message' => sprintf(esc_html__('Network error: %s', 'mxchat'), esc_html($response->get_error_message()))));
208 - }
209 -
210 - $code = (int) wp_remote_retrieve_response_code($response);
211 - if ($code === 401 || $code === 403) {
212 - wp_send_json_error(array('message' => sprintf(esc_html__('Auth rejected (HTTP %d). Check API key and auth scheme.', 'mxchat'), $code)));
213 - }
214 - if ($code === 404) {
215 - wp_send_json_error(array('message' => esc_html__('Endpoint not found (HTTP 404). Check the Base URL.', 'mxchat')));
216 - }
217 - if ($code < 200 || $code >= 300) {
218 - wp_send_json_error(array('message' => sprintf(esc_html__('Upstream returned HTTP %d.', 'mxchat'), $code)));
219 - }
220 -
221 - $body = json_decode(wp_remote_retrieve_body($response), true);
222 - $count = 0;
223 - if (is_array($body)) {
224 - if (isset($body['data']) && is_array($body['data'])) {
225 - $count = count($body['data']);
226 - } elseif (isset($body['models']) && is_array($body['models'])) {
227 - $count = count($body['models']);
228 - }
229 - }
230 -
231 - wp_send_json_success(array(
232 - 'message' => sprintf(esc_html__('Connection OK — %d model(s) reported.', 'mxchat'), $count),
233 - 'count' => $count,
234 - ));
235 -}
236 -
237 -/**
238 - * Validate a BUILT-IN provider key with the lightest authenticated call per
239 - * provider (a /models or key-info GET — never a generation). Reads the posted
240 - * key value so the owner can test BEFORE saving; falls back to the saved option
241 - * when the field is empty. Mirrors mxchat_test_custom_provider_callback and the
242 - * add-on test buttons (cf5bd5 veo / 8d16f1 perplexity). The key is never logged.
243 - * plan-mxchat-20260623-c41f74.
244 - */
245 -public function mxchat_test_provider_key_callback() {
246 - check_ajax_referer('mxchat_test_provider_key');
247 - if (!current_user_can('manage_options')) {
248 - wp_send_json_error(array('message' => esc_html__('Unauthorized', 'mxchat')));
249 - }
250 -
251 - $provider = isset($_POST['provider']) ? sanitize_key(wp_unslash($_POST['provider'])) : '';
252 - $posted_key = isset($_POST['key']) ? trim((string) wp_unslash($_POST['key'])) : '';
253 -
254 - $option_map = array(
255 - 'openai' => 'api_key',
256 - 'xai' => 'xai_api_key',
257 - 'claude' => 'claude_api_key',
258 - 'deepseek' => 'deepseek_api_key',
259 - 'gemini' => 'gemini_api_key',
260 - 'openrouter' => 'openrouter_api_key',
261 - );
262 - if (!isset($option_map[$provider])) {
263 - wp_send_json_error(array('message' => esc_html__('Unknown provider.', 'mxchat')));
264 - }
265 -
266 - // Prefer the just-typed value (test-before-save); fall back to the saved key.
267 - $key = $posted_key;
268 - if ($key === '') {
269 - $options = get_option('mxchat_options', array());
270 - $key = isset($options[$option_map[$provider]]) ? trim((string) $options[$option_map[$provider]]) : '';
271 - }
272 - if ($key === '') {
273 - wp_send_json_error(array('message' => esc_html__('No API key entered or saved for this provider.', 'mxchat')));
274 - }
275 -
276 - // Lightest authenticated metadata call per provider — model-agnostic, no generation.
277 - $headers = array();
278 - switch ($provider) {
279 - case 'openai':
280 - $url = 'https://api.openai.com/v1/models';
281 - $headers = array('Authorization' => 'Bearer ' . $key);
282 - break;
283 - case 'xai':
284 - $url = 'https://api.x.ai/v1/models';
285 - $headers = array('Authorization' => 'Bearer ' . $key);
286 - break;
287 - case 'deepseek':
288 - $url = 'https://api.deepseek.com/models';
289 - $headers = array('Authorization' => 'Bearer ' . $key);
290 - break;
291 - case 'openrouter':
292 - // /auth/key validates the key itself (the public /models list does not).
293 - $url = 'https://openrouter.ai/api/v1/auth/key';
294 - $headers = array('Authorization' => 'Bearer ' . $key);
295 - break;
296 - case 'gemini':
297 - $url = add_query_arg(array('pageSize' => 1, 'key' => $key), 'https://generativelanguage.googleapis.com/v1beta/models');
298 - break;
299 - case 'claude':
300 - $url = 'https://api.anthropic.com/v1/models';
301 - $headers = array('x-api-key' => $key, 'anthropic-version' => '2023-06-01');
302 - break;
303 - default:
304 - wp_send_json_error(array('message' => esc_html__('Unknown provider.', 'mxchat')));
305 - }
306 -
307 - $response = wp_remote_get($url, array(
308 - 'headers' => $headers,
309 - 'timeout' => 10,
310 - ));
311 -
312 - if (is_wp_error($response)) {
313 - wp_send_json_error(array('message' => sprintf(esc_html__('Network error: %s', 'mxchat'), esc_html($response->get_error_message()))));
314 - }
315 -
316 - $code = (int) wp_remote_retrieve_response_code($response);
317 - if ($code >= 200 && $code < 300) {
318 - wp_send_json_success(array('message' => esc_html__('Key is valid.', 'mxchat')));
319 - }
320 -
321 - // Surface the provider's own error text when present (trimmed; key never echoed).
322 - $detail = '';
323 - $body = json_decode(wp_remote_retrieve_body($response), true);
324 - if (is_array($body)) {
325 - if (isset($body['error']['message'])) {
326 - $detail = $body['error']['message'];
327 - } elseif (isset($body['error']) && is_string($body['error'])) {
328 - $detail = $body['error'];
329 - } elseif (isset($body['message'])) {
330 - $detail = $body['message'];
331 - }
332 - }
333 - $detail = trim((string) $detail);
334 - if (strlen($detail) > 200) {
335 - $detail = substr($detail, 0, 200) . '…';
336 - }
337 -
338 - if ($code === 401 || $code === 403) {
339 - $msg = ($detail !== '')
340 - ? sprintf(esc_html__('Key rejected (HTTP %1$d): %2$s', 'mxchat'), $code, esc_html($detail))
341 - : sprintf(esc_html__('Key rejected (HTTP %d). Check the API key.', 'mxchat'), $code);
342 - wp_send_json_error(array('message' => $msg));
343 - }
344 -
345 - $msg = ($detail !== '')
346 - ? sprintf(esc_html__('Provider returned HTTP %1$d: %2$s', 'mxchat'), $code, esc_html($detail))
347 - : sprintf(esc_html__('Provider returned HTTP %d.', 'mxchat'), $code);
348 - wp_send_json_error(array('message' => $msg));
349 -}
350 -
351 53 // ========================================
352 54 // SETTINGS AJAX HANDLERS
353 55 // ========================================
354 56
@@ -362,10 +64,10 @@
362 64 wp_send_json_error(['message' => esc_html__('Unauthorized', 'mxchat')]);
363 65 }
364 66
365 67 $name = isset($_POST['name']) ? $_POST['name'] : '';
366 - // Remove WP's added slashes before saving (wp_unslash is the canonical form; plan-3f8158).
367 - $value = isset($_POST['value']) ? wp_unslash($_POST['value']) : '';
68 + // Strip slashes from the value before saving
69 + $value = isset($_POST['value']) ? stripslashes($_POST['value']) : '';
368 70
369 71 //error_log('MXChat Save: Processing field name: ' . $name);
370 72 //error_log('MXChat Save: Field value: ' . $value);
371 73
@@ -399,15 +101,20 @@
399 101 //error_log('MXChat Save: Setting model to openrouter');
400 102 $options['model'] = 'openrouter';
401 103 } else {
402 104 //error_log('MXChat Save: Checking against whitelist');
403 - // Catalog refactor (plan-d14e89): canonical allowlist lives in
404 - // includes/class-mxchat-model-catalog.php. A new chat model
405 - // added there is automatically accepted by autosave.
406 - if (!class_exists('MxChat_Model_Catalog')) {
407 - require_once plugin_dir_path(dirname(__FILE__)) . 'includes/class-mxchat-model-catalog.php';
408 - }
409 - $allowed_models = MxChat_Model_Catalog::chat_model_ids();
105 + $allowed_models = array(
106 + 'gemini-3-pro-preview', 'gemini-3-flash-preview', 'gemini-2.5-pro', 'gemini-2.5-flash', 'gemini-2.5-flash-lite',
107 + 'gemini-2.0-flash', 'gemini-2.0-flash-lite', 'gemini-1.5-pro', 'gemini-1.5-flash',
108 + 'grok-4-0709', 'grok-4-1-fast-reasoning', 'grok-4-1-fast-non-reasoning', 'grok-3-beta', 'grok-3-fast-beta', 'grok-3-mini-beta',
109 + 'grok-3-mini-fast-beta', 'grok-2',
110 + 'deepseek-chat',
111 + 'claude-opus-4-6', 'claude-opus-4-5', 'claude-sonnet-4-6',
112 + 'claude-sonnet-4-5-20250929', 'claude-opus-4-1-20250805', 'claude-haiku-4-5-20251001',
113 + 'claude-opus-4-20250514', 'claude-sonnet-4-20250514',
114 + 'gpt-5.4', 'gpt-5.4-mini', 'gpt-5.4-nano', 'gpt-5.3-chat-latest',
115 + 'gpt-5.2', 'gpt-5.1-chat-latest', 'gpt-5.1-2025-11-13', 'gpt-5', 'gpt-5-mini', 'gpt-5-nano',
116 + );
410 117
411 118 //error_log('MXChat Save: in_array result: ' . (in_array($value, $allowed_models) ? 'YES' : 'NO'));
412 119
413 120 if (in_array($value, $allowed_models)) {
@@ -459,15 +166,8 @@
459 166 //error_log('MXChat Save: Processing email_blocker_header_content');
460 167 // Allow HTML content but sanitize it safely
461 168 $options[$field_name] = wp_kses_post($value);
462 169 break;
463 - case 'intro_message':
464 - // Stored-XSS hardening (Wordfence CWE-79, plan-3f8158): sanitize on save as
465 - // defense in depth. wp_kses_post mirrors mxchat_sanitize() (the options.php
466 - // save path) so both save routes treat intro_message identically and strip
467 - // <script>/</textarea> breakout while keeping basic formatting + {visitor_name}.
468 - $options[$field_name] = wp_kses_post($value);
469 - break;
470 170 case 'email_blocker_button_text':
471 171 //error_log('MXChat Save: Processing email_blocker_button_text');
472 172 $options[$field_name] = sanitize_text_field($value);
473 173 break;
@@ -531,12 +231,8 @@
531 231 // Validate script loading strategy value
532 232 $allowed_strategies = array('default', 'defer', 'delay_1s', 'delay_3s', 'delay_5s', 'on_interaction');
533 233 $options[$field_name] = in_array($value, $allowed_strategies) ? $value : 'default';
534 234 break;
535 - case 'auto_retry_on_transient_error':
536 - // Boolean toggle — accept 1/0/on/off, default to '1' if any truthy value.
537 - $options[$field_name] = ($value === '1' || $value === 'on' || $value === 1 || $value === true) ? '1' : '0';
538 - break;
539 235 default:
540 236 // Handle transcripts options
541 237 if (strpos($name, 'mxchat_transcripts_options') !== false) {
542 238 // Extract field name from mxchat_transcripts_options[field_name]
@@ -604,48 +300,8 @@
604 300 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
605 301 return;
606 302 }
607 303 }
608 - // Whole-chatbot global cap (sits in mxchat_options['rate_limits_global']).
609 - // Field names: mxchat_options[rate_limits_global][limit|timeframe|limit_custom]
610 - else if (strpos($name, 'mxchat_options[rate_limits_global]') !== false) {
611 - preg_match('/\[rate_limits_global\]\[(.*?)\]/', $name, $matches);
612 - if (isset($matches[1])) {
613 - $setting_key = $matches[1];
614 - if (!isset($options['rate_limits_global']) || !is_array($options['rate_limits_global'])) {
615 - $options['rate_limits_global'] = array('limit' => 'unlimited', 'timeframe' => 'daily');
616 - }
617 - if ($setting_key === 'limit') {
618 - // Selection from the preset dropdown. If __custom__, resolve from limit_custom; otherwise store directly.
619 - if ($value === '__custom__') {
620 - $custom = isset($options['rate_limits_global']['limit_custom']) ? (string) $options['rate_limits_global']['limit_custom'] : '';
621 - if ($custom !== '' && ctype_digit($custom) && (int) $custom >= 1) {
622 - $options['rate_limits_global']['limit'] = $custom;
623 - }
624 - // else leave existing limit untouched until the custom value arrives
625 - } else {
626 - $options['rate_limits_global']['limit'] = $value;
627 - }
628 - } elseif ($setting_key === 'limit_custom') {
629 - $clean = preg_replace('/[^0-9]/', '', (string) $value);
630 - $options['rate_limits_global']['limit_custom'] = $clean;
631 - // Mirror a valid custom value into limit UNCONDITIONALLY (plan-74eb86).
632 - // The custom number input is only editable when the dropdown is on
633 - // "Custom…" (the toggle JS hides it for presets/unlimited) and autosave
634 - // sends one field per change event, so a limit_custom change only fires
635 - // in custom mode — there is no preset to clobber. The old guard required
636 - // limit to already be non-preset, which it isn't on a first-time custom
637 - // entry (the limit=__custom__ event arrives before limit_custom is set),
638 - // so the value never landed in limit on the first save and reverted on refresh.
639 - if ($clean !== '' && (int) $clean >= 1) {
640 - $options['rate_limits_global']['limit'] = $clean;
641 - }
642 - } elseif ($setting_key === 'timeframe') {
643 - $allowed_tf = array('hourly','daily','weekly','monthly');
644 - $options['rate_limits_global']['timeframe'] = in_array($value, $allowed_tf, true) ? $value : 'daily';
645 - }
646 - }
647 - }
648 304 // First check for rate limits settings
649 305 else if (strpos($name, 'mxchat_options[rate_limits]') !== false) {
650 306 //error_log('MXChat Save: Detected rate_limits field: ' . $name);
651 307
@@ -654,9 +310,9 @@
654 310 //error_log('MXChat Save: Regex matches: ' . print_r($matches, true));
655 311
656 312 if (isset($matches[1]) && isset($matches[2])) {
657 313 $role_id = $matches[1];
658 - $setting_key = $matches[2]; // limit, timeframe, message, or limit_custom
314 + $setting_key = $matches[2]; // limit, timeframe, or message
659 315
660 316 //error_log('MXChat Save: Role ID = ' . $role_id . ', Setting Key = ' . $setting_key);
661 317
662 318 // Initialize rate_limits if it doesn't exist
@@ -674,32 +330,10 @@
674 330 'message' => 'Rate limit exceeded. Please try again later.'
675 331 ];
676 332 }
677 333
678 - if ($setting_key === 'limit') {
679 - if ($value === '__custom__') {
680 - // Pull the integer from limit_custom that may have arrived (or will arrive).
681 - $custom = isset($options['rate_limits'][$role_id]['limit_custom']) ? (string) $options['rate_limits'][$role_id]['limit_custom'] : '';
682 - if ($custom !== '' && ctype_digit($custom) && (int) $custom >= 1) {
683 - $options['rate_limits'][$role_id]['limit'] = $custom;
684 - }
685 - } else {
686 - $options['rate_limits'][$role_id]['limit'] = $value;
687 - }
688 - } elseif ($setting_key === 'limit_custom') {
689 - $clean = preg_replace('/[^0-9]/', '', (string) $value);
690 - $options['rate_limits'][$role_id]['limit_custom'] = $clean;
691 - // Mirror a valid custom value into limit UNCONDITIONALLY — same reasoning
692 - // as the global branch above (plan-74eb86). The per-role custom input is
693 - // only editable in custom mode and autosave is one-field-per-change, so
694 - // this never clobbers a preset; it fixes the first-time-save revert.
695 - if ($clean !== '' && (int) $clean >= 1) {
696 - $options['rate_limits'][$role_id]['limit'] = $clean;
697 - }
698 - } else {
699 - // Update the specific setting (timeframe, message)
700 - $options['rate_limits'][$role_id][$setting_key] = $value;
701 - }
334 + // Update the specific setting
335 + $options['rate_limits'][$role_id][$setting_key] = $value;
702 336 //error_log('MXChat Save: Updated rate_limits[' . $role_id . '][' . $setting_key . '] = ' . $value);
703 337 } else {
704 338 //error_log('MXChat Save: Failed to parse rate_limits pattern: ' . $name);
705 339 }
@@ -736,13 +370,9 @@
736 370 'enable_streaming_toggle',
737 371 'contextual_awareness_toggle',
738 372 'citation_links_toggle',
739 373 'enable_email_block',
740 - 'enable_name_field',
741 - 'custom_provider_for_embeddings',
742 - 'custom_provider_for_images',
743 - 'print_button_enabled',
744 - 'reset_chat_enabled'
374 + 'enable_name_field'
745 375 ])) {
746 376 //error_log('MXChat Save: Processing toggle: ' . $field_name);
747 377 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
748 378 } else {
@@ -1639,74 +1269,8 @@
1639 1269 // Perform the reset
1640 1270 MxChat_Admin::mxchat_reset_all_settings();
1641 1271
1642 1272 wp_send_json_success( array( 'message' => esc_html__( 'All settings have been reset to defaults. The page will reload.', 'mxchat' ) ) );
1643 - }
1644 -
1645 - /**
1646 - * Reset the global rate-limit usage counter to zero on demand.
1647 - *
1648 - * Zeroes the WP option mxchat_chat_limit_<bot>_global that the integrator
1649 - * increments per message, then returns a freshly-formatted readout string
1650 - * so the settings page can update without a reload. Does NOT change any
1651 - * enforcement config — purely clears the running counter.
1652 - */
1653 - public function mxchat_reset_global_rate_limit_callback() {
1654 - // Verify nonce
1655 - if ( ! check_ajax_referer( 'mxchat_reset_global_usage', '_ajax_nonce', false ) ) {
1656 - wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1657 - }
1658 -
1659 - // Check permissions
1660 - if ( ! current_user_can( 'manage_options' ) ) {
1661 - wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1662 - }
1663 -
1664 - // Resolve the per-bot counter key the same way the integrator does.
1665 - $bot_id = isset( $_POST['bot_id'] ) ? sanitize_key( wp_unslash( $_POST['bot_id'] ) ) : 'default';
1666 - $safe_bot = preg_replace( '/[^a-zA-Z0-9_]/', '_', $bot_id );
1667 - if ( $safe_bot === '' ) {
1668 - $safe_bot = 'default';
1669 - }
1670 - $option_key = 'mxchat_chat_limit_' . $safe_bot . '_global';
1671 -
1672 - $now = time();
1673 - update_option( $option_key, array( 'count' => 0, 'timestamp' => $now ) );
1674 -
1675 - // Recompute the display string so the front-end can update in place.
1676 - $all_options = get_option( 'mxchat_options', array() );
1677 - $global_cfg = isset( $all_options['rate_limits_global'] ) && is_array( $all_options['rate_limits_global'] )
1678 - ? $all_options['rate_limits_global']
1679 - : array();
1680 - $limit_raw = isset( $global_cfg['limit'] ) ? (string) $global_cfg['limit'] : 'unlimited';
1681 - // Defensive: if a raw __custom__ ever slips through, fall back to the custom value.
1682 - if ( ! ctype_digit( $limit_raw ) && isset( $global_cfg['limit_custom'] ) && ctype_digit( (string) $global_cfg['limit_custom'] ) ) {
1683 - $limit_raw = (string) $global_cfg['limit_custom'];
1684 - }
1685 - $timeframe = isset( $global_cfg['timeframe'] ) ? (string) $global_cfg['timeframe'] : 'daily';
1686 - $windows = array( 'hourly' => 3600, 'daily' => 86400, 'weekly' => 604800, 'monthly' => 2592000 );
1687 - $window = isset( $windows[ $timeframe ] ) ? $windows[ $timeframe ] : 86400;
1688 - $reset_at = $now + $window;
1689 - $limit_int = ctype_digit( $limit_raw ) ? (int) $limit_raw : 0;
1690 -
1691 - $text = sprintf(
1692 - /* translators: 1: used count, 2: limit, 3: remaining, 4: human-readable time until reset */
1693 - esc_html__( '%1$s of %2$s used · %3$s left · resets in %4$s', 'mxchat' ),
1694 - number_format_i18n( 0 ),
1695 - number_format_i18n( $limit_int ),
1696 - number_format_i18n( $limit_int ),
1697 - human_time_diff( $now, $reset_at )
1698 - );
1699 -
1700 - wp_send_json_success( array(
1701 - 'count' => 0,
1702 - 'limit' => $limit_int,
1703 - 'left' => $limit_int,
1704 - 'reset_at' => $reset_at,
1705 - 'pct' => 0,
1706 - 'text' => $text,
1707 - 'message' => esc_html__( 'Usage counter reset.', 'mxchat' ),
1708 - ) );
1709 1273 }
1710 1274
1711 1275 }
1712 1276