PluginProbe
MxChat – AI Chatbot & Content Generation for WordPress / 3.2.20
MxChat – AI Chatbot & Content Generation for WordPress v3.2.20
3.2.21 3.2.20 3.2.19 3.2.18 3.2.17 3.2.16 3.2.15 3.2.14 3.2.12 3.2.13 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 3.2.6 3.2.5 3.2.4 3.2.3 3.2.2 3.2.1 2.0.3 2.0.4 2.0.5 2.0.6 All 152 releases
mxchat-basic / admin / class-ajax-handler.php

class-ajax-handler.php in MxChat – AI Chatbot & Content Generation for WordPress 3.2.20, at admin/class-ajax-handler.php

2,016 lines 90.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * File: admin/class-ajax-handler.php
4 *
5 * Handles all AJAX requests for MxChat admin functionality
6 */
7
8 if (!defined('ABSPATH')) {
9 exit; // Exit if accessed directly
10 }
11
12 class MxChat_Ajax_Handler {
13
14 private $pinecone_manager = null;
15
16 /**
17 * Constructor - Register all AJAX hooks
18 */
19 public function __construct() {
20 $this->mxchat_init_ajax_hooks();
21 }
22
23
24 /**
25 * Register all AJAX action hooks
26 */
27 private function mxchat_init_ajax_hooks() {
28 // Settings AJAX
29 add_action('wp_ajax_mxchat_save_setting', array($this, 'mxchat_save_setting_callback'));
30 add_action('wp_ajax_mxchat_save_prompts_setting', array($this, 'mxchat_save_prompts_setting_callback'));
31 add_action('wp_ajax_mxchat_acf_toggle_group', array($this, 'mxchat_acf_toggle_group_callback'));
32 add_action('wp_ajax_migrate_pinecone_settings', array($this, 'ajax_migrate_pinecone_settings'));
33
34 // License AJAX
35 add_action('wp_ajax_mxchat_handle_activate_license', array($this, 'mxchat_handle_activate_license'));
36 add_action('wp_ajax_mxchat_check_license_status', array($this, 'mxchat_check_license_status'));
37 add_action('wp_ajax_mxchat_deactivate_license', array($this, 'mxchat_deactivate_license'));
38
39 // Actions & Intents AJAX
40 add_action('wp_ajax_mxchat_toggle_action', array($this, 'mxchat_toggle_action'));
41 add_action('wp_ajax_mxchat_update_intent_threshold', array($this, 'mxchat_update_intent_threshold'));
42
43 add_action('wp_ajax_mxchat_save_selected_bot', array($this, 'mxchat_save_selected_bot'));
44 add_action('wp_ajax_mxchat_check_api_keys', array($this, 'mxchat_check_api_keys'));
45
46 // Debug & Optimization AJAX
47 add_action('wp_ajax_mxchat_toggle_debug_mode', array($this, 'mxchat_toggle_debug_mode_callback'));
48 add_action('wp_ajax_mxchat_get_debug_log', array($this, 'mxchat_get_debug_log_callback'));
49 add_action('wp_ajax_mxchat_clear_debug_log', array($this, 'mxchat_clear_debug_log_callback'));
50 add_action('wp_ajax_mxchat_export_settings', array($this, 'mxchat_export_settings_callback'));
51 add_action('wp_ajax_mxchat_reset_all_settings', array($this, 'mxchat_reset_all_settings_callback'));
52
53 // Global rate-limit usage counter reset (admin-only, nonce-guarded)
54 add_action('wp_ajax_mxchat_reset_global_rate_limit', array($this, 'mxchat_reset_global_rate_limit_callback'));
55
56 // Custom (OpenAI-compatible) Provider connection test
57 add_action('wp_ajax_mxchat_test_custom_provider', array($this, 'mxchat_test_custom_provider_callback'));
58
59 // Built-in provider key validation — cheap per-provider auth check (plan-mxchat-20260623-c41f74)
60 add_action('wp_ajax_mxchat_test_provider_key', array($this, 'mxchat_test_provider_key_callback'));
61
62 // Custom Post Meta discovery scan for the KB whitelist picker (plan-mxchat-20260709-fe8e4e)
63 add_action('wp_ajax_mxchat_scan_custom_meta_keys', array($this, 'mxchat_scan_custom_meta_keys_callback'));
64 }
65
66 /**
67 * Discover non-ACF custom post-meta keys present on published public content, so the
68 * KB → Custom Post Meta section can offer a click-to-add picker instead of a blind
69 * "type the exact key you already know" textarea. plan-mxchat-20260709-fe8e4e.
70 *
71 * Bounded + button-triggered only (never on page load). Returns up to 50 keys by
72 * frequency, each with a short sample value, so the owner can judge relevance before
73 * whitelisting. Underscore-prefixed (protected/internal) keys are hidden unless the
74 * caller opts in; ACF-managed keys are excluded so this picker never double-lists the
75 * sibling ACF discovery picker on the same page.
76 */
77 public function mxchat_scan_custom_meta_keys_callback() {
78 check_ajax_referer('mxchat_prompts_setting_nonce');
79
80 if (!current_user_can('manage_options')) {
81 wp_send_json_error(['message' => esc_html__('Unauthorized', 'mxchat')]);
82 }
83
84 global $wpdb;
85
86 $include_internal = isset($_POST['include_internal']) && $_POST['include_internal'] === '1';
87
88 // Restrict discovery to public post types (the content the KB actually embeds).
89 $post_types = get_post_types(array('public' => true), 'names');
90 if (empty($post_types)) {
91 wp_send_json_success(array('keys' => array(), 'scanned' => 0));
92 }
93 $pt_placeholders = implode(',', array_fill(0, count($post_types), '%s'));
94
95 // Build the set of ACF-managed meta keys to exclude. ACF stores, alongside each
96 // value key `foo`, a reference key `_foo` whose value is the ACF field key
97 // (`field_xxxxx`). Strip the leading underscore from every such reference key to
98 // get the real meta key, and exclude those — the ACF picker on this page owns them.
99 $acf_managed = array();
100 $acf_refs = $wpdb->get_col(
101 $wpdb->prepare(
102 "SELECT DISTINCT meta_key FROM {$wpdb->postmeta} WHERE meta_key LIKE %s AND meta_value LIKE %s",
103 $wpdb->esc_like('_') . '%',
104 $wpdb->esc_like('field_') . '%'
105 )
106 );
107 foreach ((array) $acf_refs as $ref_key) {
108 if (strlen($ref_key) > 1 && $ref_key[0] === '_') {
109 $acf_managed[substr($ref_key, 1)] = true;
110 }
111 }
112
113 // Discover keys + counts + a sample value in one bounded aggregate query.
114 // SUBSTRING(MIN(...)) keeps the sample selection ONLY_FULL_GROUP_BY-safe.
115 $params = $post_types;
116 $sql = "SELECT pm.meta_key AS mk, COUNT(*) AS n, SUBSTRING(MIN(pm.meta_value), 1, 200) AS sample
117 FROM {$wpdb->postmeta} pm
118 INNER JOIN {$wpdb->posts} p ON p.ID = pm.post_id
119 WHERE p.post_status = 'publish'
120 AND p.post_type IN ($pt_placeholders)
121 AND pm.meta_key <> ''";
122 if (!$include_internal) {
123 $sql .= " AND pm.meta_key NOT LIKE %s";
124 $params[] = $wpdb->esc_like('_') . '%';
125 }
126 $sql .= " GROUP BY pm.meta_key ORDER BY n DESC, pm.meta_key ASC LIMIT 200";
127
128 // phpcs:ignore WordPress.DB.PreparedSQL — placeholders assembled above, values in $params.
129 $rows = $wpdb->get_results($wpdb->prepare($sql, $params));
130
131 $keys = array();
132 foreach ((array) $rows as $row) {
133 $mk = $row->mk;
134 if (isset($acf_managed[$mk])) {
135 continue; // already offered by the ACF picker
136 }
137
138 $raw = (string) $row->sample;
139 if ($raw !== '' && (is_serialized($raw) || preg_match('/^(a:\d+:\{|O:\d+:"|s:\d+:")/', $raw))) {
140 $sample = esc_html__('[structured value]', 'mxchat');
141 } else {
142 $sample = trim(preg_replace('/\s+/', ' ', $raw));
143 if (function_exists('mb_strlen') ? mb_strlen($sample) > 60 : strlen($sample) > 60) {
144 $sample = (function_exists('mb_substr') ? mb_substr($sample, 0, 60) : substr($sample, 0, 60)) . '';
145 }
146 if ($sample === '') {
147 $sample = esc_html__('(empty value)', 'mxchat');
148 }
149 }
150
151 $keys[] = array(
152 'key' => $mk,
153 'count' => (int) $row->n,
154 'sample' => $sample,
155 );
156
157 if (count($keys) >= 50) {
158 break;
159 }
160 }
161
162 wp_send_json_success(array(
163 'keys' => $keys,
164 'scanned' => is_array($rows) ? count($rows) : 0,
165 ));
166 }
167
168 /**
169 * Test connection to a Custom (OpenAI-compatible) provider by hitting its /models endpoint
170 * with whichever auth scheme the user configured. Reports model count or a clean error.
171 */
172 public function mxchat_test_custom_provider_callback() {
173 check_ajax_referer('mxchat_test_custom_provider');
174 if (!current_user_can('manage_options')) {
175 wp_send_json_error(array('message' => esc_html__('Unauthorized', 'mxchat')));
176 }
177
178 $options = get_option('mxchat_options', array());
179 $base_url = isset($options['custom_provider_base_url']) ? trim((string) $options['custom_provider_base_url']) : '';
180 $api_key = isset($options['custom_provider_api_key']) ? trim((string) $options['custom_provider_api_key']) : '';
181 $auth = isset($options['custom_provider_auth_scheme']) ? $options['custom_provider_auth_scheme'] : 'bearer';
182 $api_version = isset($options['custom_provider_api_version']) ? trim((string) $options['custom_provider_api_version']) : '';
183
184 if (empty($base_url)) {
185 wp_send_json_error(array('message' => esc_html__('Base URL is empty. Save it first.', 'mxchat')));
186 }
187
188 $url = rtrim($base_url, '/') . '/models';
189 if (!empty($api_version)) {
190 $url = add_query_arg('api-version', $api_version, $url);
191 }
192
193 $headers = array('Content-Type' => 'application/json');
194 if (!empty($api_key)) {
195 if ($auth === 'api-key') {
196 $headers['api-key'] = $api_key;
197 } else {
198 $headers['Authorization'] = 'Bearer ' . $api_key;
199 }
200 }
201
202 $response = wp_remote_get($url, array(
203 'headers' => $headers,
204 'timeout' => 10,
205 ));
206
207 if (is_wp_error($response)) {
208 wp_send_json_error(array('message' => sprintf(esc_html__('Network error: %s', 'mxchat'), esc_html($response->get_error_message()))));
209 }
210
211 $code = (int) wp_remote_retrieve_response_code($response);
212 if ($code === 401 || $code === 403) {
213 wp_send_json_error(array('message' => sprintf(esc_html__('Auth rejected (HTTP %d). Check API key and auth scheme.', 'mxchat'), $code)));
214 }
215 if ($code === 404) {
216 wp_send_json_error(array('message' => esc_html__('Endpoint not found (HTTP 404). Check the Base URL.', 'mxchat')));
217 }
218 if ($code < 200 || $code >= 300) {
219 wp_send_json_error(array('message' => sprintf(esc_html__('Upstream returned HTTP %d.', 'mxchat'), $code)));
220 }
221
222 $body = json_decode(wp_remote_retrieve_body($response), true);
223 $count = 0;
224 if (is_array($body)) {
225 if (isset($body['data']) && is_array($body['data'])) {
226 $count = count($body['data']);
227 } elseif (isset($body['models']) && is_array($body['models'])) {
228 $count = count($body['models']);
229 }
230 }
231
232 wp_send_json_success(array(
233 'message' => sprintf(esc_html__('Connection OK — %d model(s) reported.', 'mxchat'), $count),
234 'count' => $count,
235 ));
236 }
237
238 /**
239 * Validate a BUILT-IN provider key with the lightest authenticated call per
240 * provider (a /models or key-info GET — never a generation). Reads the posted
241 * key value so the owner can test BEFORE saving; falls back to the saved option
242 * when the field is empty. Mirrors mxchat_test_custom_provider_callback and the
243 * add-on test buttons (cf5bd5 veo / 8d16f1 perplexity). The key is never logged.
244 * plan-mxchat-20260623-c41f74.
245 */
246 public function mxchat_test_provider_key_callback() {
247 check_ajax_referer('mxchat_test_provider_key');
248 if (!current_user_can('manage_options')) {
249 wp_send_json_error(array('message' => esc_html__('Unauthorized', 'mxchat')));
250 }
251
252 $provider = isset($_POST['provider']) ? sanitize_key(wp_unslash($_POST['provider'])) : '';
253 $posted_key = isset($_POST['key']) ? trim((string) wp_unslash($_POST['key'])) : '';
254
255 $option_map = array(
256 'openai' => 'api_key',
257 'xai' => 'xai_api_key',
258 'claude' => 'claude_api_key',
259 'deepseek' => 'deepseek_api_key',
260 'gemini' => 'gemini_api_key',
261 'openrouter' => 'openrouter_api_key',
262 );
263 if (!isset($option_map[$provider])) {
264 wp_send_json_error(array('message' => esc_html__('Unknown provider.', 'mxchat')));
265 }
266
267 // Prefer the just-typed value (test-before-save); fall back to the saved key.
268 $key = $posted_key;
269 if ($key === '') {
270 $options = get_option('mxchat_options', array());
271 $key = isset($options[$option_map[$provider]]) ? trim((string) $options[$option_map[$provider]]) : '';
272 }
273 if ($key === '') {
274 wp_send_json_error(array('message' => esc_html__('No API key entered or saved for this provider.', 'mxchat')));
275 }
276
277 // Lightest authenticated metadata call per provider — model-agnostic, no generation.
278 $headers = array();
279 switch ($provider) {
280 case 'openai':
281 $url = 'https://api.openai.com/v1/models';
282 $headers = array('Authorization' => 'Bearer ' . $key);
283 break;
284 case 'xai':
285 $url = 'https://api.x.ai/v1/models';
286 $headers = array('Authorization' => 'Bearer ' . $key);
287 break;
288 case 'deepseek':
289 $url = 'https://api.deepseek.com/models';
290 $headers = array('Authorization' => 'Bearer ' . $key);
291 break;
292 case 'openrouter':
293 // /auth/key validates the key itself (the public /models list does not).
294 $url = 'https://openrouter.ai/api/v1/auth/key';
295 $headers = array('Authorization' => 'Bearer ' . $key);
296 break;
297 case 'gemini':
298 $url = add_query_arg(array('pageSize' => 1, 'key' => $key), 'https://generativelanguage.googleapis.com/v1beta/models');
299 break;
300 case 'claude':
301 $url = 'https://api.anthropic.com/v1/models';
302 $headers = array('x-api-key' => $key, 'anthropic-version' => '2023-06-01');
303 break;
304 default:
305 wp_send_json_error(array('message' => esc_html__('Unknown provider.', 'mxchat')));
306 }
307
308 $response = wp_remote_get($url, array(
309 'headers' => $headers,
310 'timeout' => 10,
311 ));
312
313 if (is_wp_error($response)) {
314 wp_send_json_error(array('message' => sprintf(esc_html__('Network error: %s', 'mxchat'), esc_html($response->get_error_message()))));
315 }
316
317 $code = (int) wp_remote_retrieve_response_code($response);
318 if ($code >= 200 && $code < 300) {
319 wp_send_json_success(array('message' => esc_html__('Key is valid.', 'mxchat')));
320 }
321
322 // Surface the provider's own error text when present (trimmed; key never echoed).
323 $detail = '';
324 $body = json_decode(wp_remote_retrieve_body($response), true);
325 if (is_array($body)) {
326 if (isset($body['error']['message'])) {
327 $detail = $body['error']['message'];
328 } elseif (isset($body['error']) && is_string($body['error'])) {
329 $detail = $body['error'];
330 } elseif (isset($body['message'])) {
331 $detail = $body['message'];
332 }
333 }
334 $detail = trim((string) $detail);
335 if (strlen($detail) > 200) {
336 $detail = substr($detail, 0, 200) . '';
337 }
338
339 if ($code === 401 || $code === 403) {
340 $msg = ($detail !== '')
341 ? sprintf(esc_html__('Key rejected (HTTP %1$d): %2$s', 'mxchat'), $code, esc_html($detail))
342 : sprintf(esc_html__('Key rejected (HTTP %d). Check the API key.', 'mxchat'), $code);
343 wp_send_json_error(array('message' => $msg));
344 }
345
346 $msg = ($detail !== '')
347 ? sprintf(esc_html__('Provider returned HTTP %1$d: %2$s', 'mxchat'), $code, esc_html($detail))
348 : sprintf(esc_html__('Provider returned HTTP %d.', 'mxchat'), $code);
349 wp_send_json_error(array('message' => $msg));
350 }
351
352 // ========================================
353 // SETTINGS AJAX HANDLERS
354 // ========================================
355
356 /**
357 * Validates and saves chat settings via AJAX request
358 */
359 public function mxchat_save_setting_callback() {
360 check_ajax_referer('mxchat_save_setting_nonce');
361 if (!current_user_can('manage_options')) {
362 ('MXChat Save: Unauthorized access attempt');
363 wp_send_json_error(['message' => esc_html__('Unauthorized', 'mxchat')]);
364 }
365
366 $name = isset($_POST['name']) ? $_POST['name'] : '';
367 // Remove WP's added slashes before saving (wp_unslash is the canonical form; plan-3f8158).
368 $value = isset($_POST['value']) ? wp_unslash($_POST['value']) : '';
369
370 //error_log('MXChat Save: Processing field name: ' . $name);
371 //error_log('MXChat Save: Field value: ' . $value);
372
373 if (empty($name)) {
374 //error_log('MXChat Save: Empty field name detected');
375 wp_send_json_error(['message' => esc_html__('Invalid field name', 'mxchat')]);
376 }
377
378 // Load the full options array
379 $options = get_option('mxchat_options', []);
380 //error_log('MXChat Save: Current options array: ' . print_r($options, true));
381
382 // Extract field name from mxchat_options[field_name] format if present
383 // But preserve the full name for special cases like rate_limits that need the full path
384 $field_name = $name;
385 if (preg_match('/^mxchat_options\[([^\[\]]+)\]$/', $name, $matches)) {
386 $field_name = $matches[1];
387 }
388
389 // Handle special cases
390 switch ($field_name) {
391 // Editor Assistant enable toggle (plan-8cb0cb). STANDALONE option — NOT part
392 // of mxchat_options, so it skips the mxchat_sanitize strip-trap entirely. Save
393 // it directly and short-circuit (mirrors the mxchat_transcripts_options pattern
394 // below); never falls through to the generic mxchat_options save. Default OFF.
395 case 'mxchat_editor_assistant_enabled':
396 $ea_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
397 update_option('mxchat_editor_assistant_enabled', $ea_value);
398 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
399 return;
400
401 // Smart asset loading toggle (plan-915355). STANDALONE option, same
402 // reasoning as the Editor Assistant case above — saved directly and
403 // short-circuited so it never touches mxchat_options / mxchat_sanitize.
404 // Default OFF (opt-in performance optimization).
405 case 'mxchat_smart_asset_loading':
406 $sal_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
407 update_option('mxchat_smart_asset_loading', $sal_value);
408 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
409 return;
410
411 // Hybrid keyword boost toggle (plan-38ffa1). STANDALONE option, same
412 // pattern. Enabling runs capability detection HERE, at admin-save time —
413 // building the FULLTEXT index during a visitor's chat request is not
414 // acceptable, and detection is a one-time cost the admin can wait on.
415 case 'mxchat_hybrid_keyword_toggle':
416 $hkb_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
417 update_option('mxchat_hybrid_keyword_toggle', $hkb_value);
418 if ($hkb_value === 'on') {
419 MxChat_Utils::mxchat_hybrid_detect_capability(true);
420 }
421 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
422 return;
423
424 // ACF→PDF import-time extraction (plan 11720c). STANDALONE option, same
425 // pattern. Moved from a per-import modal checkbox to an install-level
426 // setting on Knowledge → ACF Fields. Stored '1'/'0' to match the
427 // knowledge page's sibling toggles. Default OFF.
428 case 'mxchat_acf_pdf_extraction':
429 $apx_value = ($value === 'on' || $value === '1') ? '1' : '0';
430 update_option('mxchat_acf_pdf_extraction', $apx_value);
431 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
432 return;
433
434 // In-chat YouTube card: master switch + its own confidence floor
435 // (plan f52492). STANDALONE options, same pattern as the cases above.
436 // Default ON — the card already ships, so this is an opt-OUT.
437 case 'mxchat_video_embed_enabled':
438 $vce_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
439 update_option('mxchat_video_embed_enabled', $vce_value);
440 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
441 return;
442
443 // Clamped to the same 20-95 the field advertises. An out-of-range or
444 // non-numeric POST is corrected rather than refused, and the corrected
445 // value is echoed back so the field can reconcile — a silently stored
446 // 0 here would put a video on every answer, which is the bug.
447 case 'mxchat_video_embed_threshold':
448 $vct_value = is_numeric($value)
449 ? (int) $value
450 : MXCHAT_VIDEO_EMBED_THRESHOLD_DEFAULT;
451 if ($vct_value < 20) { $vct_value = 20; }
452 if ($vct_value > 95) { $vct_value = 95; }
453 update_option('mxchat_video_embed_threshold', $vct_value);
454 wp_send_json_success([
455 'message' => esc_html__('Setting saved', 'mxchat'),
456 'value' => $vct_value,
457 ]);
458 return;
459
460 // Live-agent availability schedules (plans 8ccaa2 + 99d7a4). STANDALONE
461 // options, same reasoning as the Editor Assistant case above — nested
462 // structures that mxchat_sanitize() would strip on the next autosave of any
463 // other field. Each channel's value arrives as JSON from its own hidden
464 // input, which that channel's schedule editor keeps in sync; the class owns
465 // all validation. The bare legacy name is kept as a defense against a
466 // browser still running pre-split cached admin JS: that UI edited "both
467 // channels" as one, so its save writes both.
468 case 'live_agent_schedule_slack':
469 case 'live_agent_schedule_telegram':
470 case 'live_agent_schedule_webhook':
471 case 'live_agent_schedule':
472 if (!class_exists('MxChat_Live_Agent_Schedule')) {
473 wp_send_json_error(['message' => esc_html__('Schedule unavailable', 'mxchat')]);
474 return;
475 }
476 $decoded = json_decode($value, true);
477 if (!is_array($decoded)) {
478 wp_send_json_error(['message' => esc_html__('Invalid schedule', 'mxchat')]);
479 return;
480 }
481 $channels = ($field_name === 'live_agent_schedule')
482 ? array('slack', 'telegram')
483 : array(substr($field_name, strlen('live_agent_schedule_')));
484 $saved_schedule = null;
485 foreach ($channels as $schedule_channel) {
486 $saved_schedule = MxChat_Live_Agent_Schedule::save($schedule_channel, $decoded);
487 }
488 // Echo the normalized result so the editor can reconcile if it ever
489 // disagrees with the server (e.g. a time the class rejected).
490 wp_send_json_success([
491 'message' => esc_html__('Setting saved', 'mxchat'),
492 'schedule' => $saved_schedule,
493 ]);
494 return;
495
496 case 'model':
497 //error_log('MXChat Save: Processing model selection');
498 //error_log('MXChat Save: Model value received: ' . $value);
499 //error_log('MXChat Save: Value type: ' . gettype($value));
500 //error_log('MXChat Save: Value length: ' . strlen($value));
501 //error_log('MXChat Save: Value === "openrouter": ' . ($value === 'openrouter' ? 'YES' : 'NO'));
502
503 // Allow 'openrouter' or validate against whitelist
504 if ($value === 'openrouter') {
505 //error_log('MXChat Save: Setting model to openrouter');
506 $options['model'] = 'openrouter';
507 } else {
508 //error_log('MXChat Save: Checking against whitelist');
509 // Catalog refactor (plan-d14e89): canonical allowlist lives in
510 // includes/class-mxchat-model-catalog.php. A new chat model
511 // added there is automatically accepted by autosave.
512 if (!class_exists('MxChat_Model_Catalog')) {
513 require_once plugin_dir_path(dirname(__FILE__)) . 'includes/class-mxchat-model-catalog.php';
514 }
515 $allowed_models = MxChat_Model_Catalog::chat_model_ids();
516
517 //error_log('MXChat Save: in_array result: ' . (in_array($value, $allowed_models) ? 'YES' : 'NO'));
518
519 if (in_array($value, $allowed_models)) {
520 //error_log('MXChat Save: Model is in whitelist, saving');
521 $options['model'] = sanitize_text_field($value);
522 } else {
523 //error_log('MXChat Save: Invalid model rejected: ' . $value);
524 //error_log('MXChat Save: Allowed models: ' . print_r($allowed_models, true));
525 wp_send_json_error(['message' => esc_html__('Invalid model selected', 'mxchat')]);
526 return;
527 }
528 }
529 break;
530
531 case 'openrouter_selected_model':
532 //error_log('MXChat Save: Processing OpenRouter model: ' . $value);
533 $options['openrouter_selected_model'] = sanitize_text_field($value);
534 // Force immediate save for new keys
535 //error_log('MXChat Save: OpenRouter model saved immediately');
536 break;
537
538 case 'openrouter_selected_model_name':
539 //error_log('MXChat Save: Processing OpenRouter model name: ' . $value);
540 $options['openrouter_selected_model_name'] = sanitize_text_field($value);
541 // Force immediate save for new keys
542 //error_log('MXChat Save: OpenRouter model name saved immediately');
543 break;
544
545 case 'openrouter_api_key':
546 //error_log('MXChat Save: Processing OpenRouter API key');
547 $options['openrouter_api_key'] = sanitize_text_field($value);
548 break;
549
550 // REMOVED DUPLICATE case 'openrouter_selected_model_name' HERE!
551
552 case 'additional_popular_questions':
553 //error_log('MXChat Save: Processing additional_popular_questions');
554 $questions = json_decode($value, true); // No need for stripslashes here
555 if (is_array($questions)) {
556 $options[$field_name] = $questions;
557 // Also update old option for backwards compatibility
558 update_option('additional_popular_questions', $questions);
559 //error_log('MXChat Save: Saved ' . count($questions) . ' additional questions');
560 } else {
561 //error_log('MXChat Save: Failed to decode questions JSON');
562 }
563 break;
564 case 'email_blocker_header_content':
565 //error_log('MXChat Save: Processing email_blocker_header_content');
566 // Allow HTML content but sanitize it safely
567 $options[$field_name] = wp_kses_post($value);
568 break;
569 case 'intro_message':
570 // Stored-XSS hardening (Wordfence CWE-79, plan-3f8158): sanitize on save as
571 // defense in depth. wp_kses_post mirrors mxchat_sanitize() (the options.php
572 // save path) so both save routes treat intro_message identically and strip
573 // <script>/</textarea> breakout while keeping basic formatting + {visitor_name}.
574 $options[$field_name] = wp_kses_post($value);
575 break;
576 case 'email_blocker_button_text':
577 //error_log('MXChat Save: Processing email_blocker_button_text');
578 $options[$field_name] = sanitize_text_field($value);
579 break;
580 case 'name_field_placeholder':
581 //error_log('MXChat Save: Processing name_field_placeholder');
582 $options[$field_name] = sanitize_text_field($value);
583 break;
584 case 'consent_checkbox_label':
585 // b062c4 — same allowlist as the options.php save path and the
586 // widget render, so the stored label always equals the shown label.
587 $options[$field_name] = MxChat_Utils::sanitize_consent_label($value);
588 break;
589 case 'similarity_threshold':
590 //error_log('MXChat Save: Processing similarity_threshold');
591 // Validate and save - enforce min 20, max 85
592 $threshold = intval($value);
593 if ($threshold < 20) $threshold = 20;
594 if ($threshold > 85) $threshold = 85;
595 $options[$field_name] = $threshold;
596 break;
597 case 'rag_sources_limit':
598 //error_log('MXChat Save: Processing rag_sources_limit');
599 // Validate and save - enforce min 3, max 10, default 6
600 $rag_limit = intval($value);
601 if ($rag_limit < 3) $rag_limit = 3;
602 if ($rag_limit > 10) $rag_limit = 10;
603 $options[$field_name] = $rag_limit;
604 break;
605 case 'rag_chunks_limit':
606 // Validate and save - enforce min 8, max 20, default 15
607 $chunks_limit = intval($value);
608 if ($chunks_limit < 8) $chunks_limit = 8;
609 if ($chunks_limit > 20) $chunks_limit = 20;
610 $options[$field_name] = $chunks_limit;
611 break;
612 case 'live_agent_status':
613 //error_log('MXChat Save: Processing live_agent_status');
614 // Set the new value
615 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
616 break;
617 // Webhook handoff destination (plan d88e22). Status normalized like the
618 // other channel toggles; the URL is refused outright when it isn't
619 // https so the admin hears about it at save time instead of the
620 // handoff silently never firing.
621 case 'webhook_handoff_status':
622 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
623 break;
624 case 'webhook_handoff_url':
625 $wh_url = trim((string) $value);
626 if ($wh_url === '') {
627 $options[$field_name] = '';
628 break;
629 }
630 $wh_clean = esc_url_raw($wh_url, array('https'));
631 if ($wh_clean === '' || stripos($wh_clean, 'https://') !== 0) {
632 wp_send_json_error(['message' => esc_html__('Webhook URL must start with https://', 'mxchat')]);
633 return;
634 }
635 $options[$field_name] = $wh_clean;
636 break;
637 case 'enable_web_search':
638 //error_log('MXChat Save: Processing enable_web_search');
639 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
640 break;
641 case 'enable_woocommerce_integration':
642 //error_log('MXChat Save: Processing enable_woocommerce_integration');
643 // Handle values that used to be 1/0
644 $options[$field_name] = ($value === 'on' || $value === '1') ? 'on' : 'off';
645 break;
646 case 'post_type_visibility_mode':
647 // Validate mode value
648 $allowed_modes = array('all', 'include', 'exclude');
649 $options[$field_name] = in_array($value, $allowed_modes) ? $value : 'all';
650 break;
651 case 'post_type_visibility_list':
652 // Handle JSON array of post types
653 $post_types = json_decode($value, true);
654 if (is_array($post_types)) {
655 // Sanitize each post type slug
656 $options[$field_name] = array_map('sanitize_key', $post_types);
657 } else {
658 $options[$field_name] = array();
659 }
660 break;
661 case 'script_loading_strategy':
662 // Validate script loading strategy value
663 $allowed_strategies = array('default', 'defer', 'delay_1s', 'delay_3s', 'delay_5s', 'on_interaction');
664 $options[$field_name] = in_array($value, $allowed_strategies) ? $value : 'default';
665 break;
666 case 'auto_retry_on_transient_error':
667 // Boolean toggle — accept 1/0/on/off, default to '1' if any truthy value.
668 $options[$field_name] = ($value === '1' || $value === 'on' || $value === 1 || $value === true) ? '1' : '0';
669 break;
670 default:
671 // Handle transcripts options
672 if (strpos($name, 'mxchat_transcripts_options') !== false) {
673 // Extract field name from mxchat_transcripts_options[field_name]
674 if (preg_match('/mxchat_transcripts_options\[([^\]]+)\]/', $name, $matches)) {
675 $field_name = $matches[1];
676
677 // Get current transcripts options
678 $transcripts_options = get_option('mxchat_transcripts_options', array());
679
680 // Ensure it's an array
681 if (!is_array($transcripts_options)) {
682 $transcripts_options = array();
683 }
684
685 // Handle checkbox values (convert 'on'/'off' to 1/0)
686 if ($field_name === 'mxchat_retention_days') {
687 // Number field, NOT a checkbox — without this branch a
688 // value of '1' would hit the 'on'/'1' coercion below
689 // (harmlessly) but nothing would clamp: this direct-DB
690 // path bypasses the registered sanitiser and its
691 // 0-3650 clamp entirely (plan-3c3338).
692 $transcripts_options[$field_name] = max(0, min(3650, (int) $value));
693 } else if ($value === 'on' || $value === '1') {
694 $transcripts_options[$field_name] = 1;
695 } else if ($value === 'off' || $value === '0' || $value === '') {
696 $transcripts_options[$field_name] = 0;
697 } else {
698 // For text/select fields, sanitize appropriately
699 if ($field_name === 'mxchat_notification_email') {
700 // sanitize_email() alone CANNOT validate this field: given
701 // "a@x.com, b@y.com" it returns the single concatenated
702 // address "a@x.comby.com", which is_email() then accepts.
703 // That is how two addresses used to be stored as one dead
704 // one, silently. MxChat_Utils validates the raw parts first
705 // and refuses the whole list if any of them is bad.
706 $parsed = MxChat_Utils::parse_notification_emails($value);
707 if ($parsed['error'] !== '') {
708 // Reject: the previously stored value stays untouched.
709 wp_send_json_error(array('message' => $parsed['error']));
710 }
711 $transcripts_options[$field_name] = implode(', ', $parsed['emails']);
712 } else {
713 $transcripts_options[$field_name] = sanitize_text_field($value);
714 }
715 }
716
717 // Use direct database update to bypass any filters
718 global $wpdb;
719
720 // Serialize the options array
721 $serialized = maybe_serialize($transcripts_options);
722
723 // Check if the option already exists in the database
724 $existing = $wpdb->get_var("SELECT option_id FROM {$wpdb->options} WHERE option_name = 'mxchat_transcripts_options'");
725
726 if ($existing) {
727 // Option exists, do an update
728 $result = $wpdb->update(
729 $wpdb->options,
730 array('option_value' => $serialized),
731 array('option_name' => 'mxchat_transcripts_options'),
732 array('%s'),
733 array('%s')
734 );
735 } else {
736 // Option doesn't exist (new install), do an insert
737 $result = $wpdb->insert(
738 $wpdb->options,
739 array(
740 'option_name' => 'mxchat_transcripts_options',
741 'option_value' => $serialized,
742 'autoload' => 'yes'
743 ),
744 array('%s', '%s', '%s')
745 );
746 }
747
748 // Clear all caches after direct DB update
749 wp_cache_delete('mxchat_transcripts_options', 'options');
750 wp_cache_delete('alloptions', 'options');
751 wp_cache_flush();
752
753 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
754 return;
755 }
756 }
757 // Whole-chatbot global cap (sits in mxchat_options['rate_limits_global']).
758 // Field names: mxchat_options[rate_limits_global][limit|timeframe|limit_custom]
759 else if (strpos($name, 'mxchat_options[rate_limits_global]') !== false) {
760 preg_match('/\[rate_limits_global\]\[(.*?)\]/', $name, $matches);
761 if (isset($matches[1])) {
762 $setting_key = $matches[1];
763 if (!isset($options['rate_limits_global']) || !is_array($options['rate_limits_global'])) {
764 $options['rate_limits_global'] = array('limit' => 'unlimited', 'timeframe' => 'daily');
765 }
766 if ($setting_key === 'limit') {
767 // Selection from the preset dropdown. If __custom__, resolve from limit_custom; otherwise store directly.
768 if ($value === '__custom__') {
769 $custom = isset($options['rate_limits_global']['limit_custom']) ? (string) $options['rate_limits_global']['limit_custom'] : '';
770 if ($custom !== '' && ctype_digit($custom) && (int) $custom >= 1) {
771 $options['rate_limits_global']['limit'] = $custom;
772 }
773 // else leave existing limit untouched until the custom value arrives
774 } else {
775 $options['rate_limits_global']['limit'] = $value;
776 }
777 } elseif ($setting_key === 'limit_custom') {
778 $clean = preg_replace('/[^0-9]/', '', (string) $value);
779 $options['rate_limits_global']['limit_custom'] = $clean;
780 // Mirror a valid custom value into limit UNCONDITIONALLY (plan-74eb86).
781 // The custom number input is only editable when the dropdown is on
782 // "Custom…" (the toggle JS hides it for presets/unlimited) and autosave
783 // sends one field per change event, so a limit_custom change only fires
784 // in custom mode — there is no preset to clobber. The old guard required
785 // limit to already be non-preset, which it isn't on a first-time custom
786 // entry (the limit=__custom__ event arrives before limit_custom is set),
787 // so the value never landed in limit on the first save and reverted on refresh.
788 if ($clean !== '' && (int) $clean >= 1) {
789 $options['rate_limits_global']['limit'] = $clean;
790 }
791 } elseif ($setting_key === 'timeframe') {
792 $allowed_tf = array('hourly','daily','weekly','monthly');
793 $options['rate_limits_global']['timeframe'] = in_array($value, $allowed_tf, true) ? $value : 'daily';
794 }
795 }
796 }
797 // First check for rate limits settings
798 else if (strpos($name, 'mxchat_options[rate_limits]') !== false) {
799 //error_log('MXChat Save: Detected rate_limits field: ' . $name);
800
801 // Extract role ID and setting from the name
802 preg_match('/\[rate_limits\]\[(.*?)\]\[(.*?)\]/', $name, $matches);
803 //error_log('MXChat Save: Regex matches: ' . print_r($matches, true));
804
805 if (isset($matches[1]) && isset($matches[2])) {
806 $role_id = $matches[1];
807 $setting_key = $matches[2]; // limit, timeframe, message, or limit_custom
808
809 //error_log('MXChat Save: Role ID = ' . $role_id . ', Setting Key = ' . $setting_key);
810
811 // Initialize rate_limits if it doesn't exist
812 if (!isset($options['rate_limits'])) {
813 // //error_log('MXChat Save: Initializing rate_limits array');
814 $options['rate_limits'] = [];
815 }
816
817 // Initialize role settings if it doesn't exist
818 if (!isset($options['rate_limits'][$role_id])) {
819 //error_log('MXChat Save: Initializing rate_limits for role: ' . $role_id);
820 $options['rate_limits'][$role_id] = [
821 'limit' => ($role_id === 'logged_out') ? '10' : '100',
822 'timeframe' => 'daily',
823 'message' => 'Rate limit exceeded. Please try again later.'
824 ];
825 }
826
827 if ($setting_key === 'limit') {
828 if ($value === '__custom__') {
829 // Pull the integer from limit_custom that may have arrived (or will arrive).
830 $custom = isset($options['rate_limits'][$role_id]['limit_custom']) ? (string) $options['rate_limits'][$role_id]['limit_custom'] : '';
831 if ($custom !== '' && ctype_digit($custom) && (int) $custom >= 1) {
832 $options['rate_limits'][$role_id]['limit'] = $custom;
833 }
834 } else {
835 $options['rate_limits'][$role_id]['limit'] = $value;
836 }
837 } elseif ($setting_key === 'limit_custom') {
838 $clean = preg_replace('/[^0-9]/', '', (string) $value);
839 $options['rate_limits'][$role_id]['limit_custom'] = $clean;
840 // Mirror a valid custom value into limit UNCONDITIONALLY — same reasoning
841 // as the global branch above (plan-74eb86). The per-role custom input is
842 // only editable in custom mode and autosave is one-field-per-change, so
843 // this never clobbers a preset; it fixes the first-time-save revert.
844 if ($clean !== '' && (int) $clean >= 1) {
845 $options['rate_limits'][$role_id]['limit'] = $clean;
846 }
847 } else {
848 // Update the specific setting (timeframe, message)
849 $options['rate_limits'][$role_id][$setting_key] = $value;
850 }
851 //error_log('MXChat Save: Updated rate_limits[' . $role_id . '][' . $setting_key . '] = ' . $value);
852 } else {
853 //error_log('MXChat Save: Failed to parse rate_limits pattern: ' . $name);
854 }
855 }
856 // Then check for role rate limits (old format)
857 else if (strpos($name, 'mxchat_options[role_rate_limits]') !== false) {
858 //error_log('MXChat Save: Processing role_rate_limits field: ' . $name);
859 // Extract role ID from the name
860 preg_match('/\[role_rate_limits\]\[(.*?)\]/', $name, $matches);
861 //error_log('MXChat Save: Regex matches: ' . print_r($matches, true));
862
863 if (isset($matches[1])) {
864 $role_id = $matches[1];
865 // Initialize role_rate_limits if it doesn't exist
866 if (!isset($options['role_rate_limits'])) {
867 //error_log('MXChat Save: Initializing role_rate_limits array');
868 $options['role_rate_limits'] = [];
869 }
870 // Update the specific role's rate limit
871 $options['role_rate_limits'][$role_id] = sanitize_text_field($value);
872 //error_log('MXChat Save: Updated role_rate_limits[' . $role_id . '] = ' . $value);
873 } else {
874 //error_log('MXChat Save: Failed to parse role_rate_limits pattern: ' . $name);
875 }
876 }
877 // Handle toggles - check both extracted field_name and original name for toggle detection
878 else if (strpos($field_name, 'toggle') !== false || in_array($field_name, [
879 'chat_persistence_toggle',
880 'privacy_toggle',
881 'complianz_toggle',
882 'chat_toolbar_toggle',
883 'show_pdf_upload_button',
884 'show_word_upload_button',
885 'enable_streaming_toggle',
886 'contextual_awareness_toggle',
887 'citation_links_toggle',
888 'enable_email_block',
889 'enable_name_field',
890 'enable_consent_checkbox',
891 'consent_checkbox_required',
892 'custom_provider_for_embeddings',
893 'custom_provider_for_images',
894 'print_button_enabled',
895 'reset_chat_enabled'
896 ])) {
897 //error_log('MXChat Save: Processing toggle: ' . $field_name);
898 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
899 } else {
900 //error_log('MXChat Save: Processing standard field: ' . $field_name);
901 // Store all other values directly using the extracted field name
902 $options[$field_name] = $value;
903 }
904 break;
905 }
906
907 // Save all updates to the options array
908 $updated = update_option('mxchat_options', $options);
909 //error_log('MXChat Save: Update result: ' . ($updated ? 'success' : 'unchanged') . ' for field: ' . $name);
910 //error_log('MXChat Save: Updated options array: ' . print_r($options, true));
911
912 // Log the save action if debug mode is enabled
913 if ( class_exists( 'MxChat_Admin' ) ) {
914 MxChat_Admin::mxchat_log_debug(
915 'settings_save',
916 sprintf( 'Field saved: %s', $field_name ),
917 array(
918 'field' => $field_name,
919 'updated' => $updated,
920 )
921 );
922 }
923
924 // Always return success even if WordPress says nothing changed
925 // (which happens when the value is the same as before)
926 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
927 }
928
929 /**
930 * Save the selected bot for knowledge base operations
931 */
932 public function mxchat_save_selected_bot() {
933 // Check nonce
934 if (!wp_verify_nonce($_POST['nonce'] ?? '', 'mxchat_save_setting_nonce')) {
935 wp_send_json_error('Invalid nonce');
936 }
937
938 // Check permissions
939 if (!current_user_can('manage_options')) {
940 wp_send_json_error('Unauthorized');
941 }
942
943 $bot_id = isset($_POST['bot_id']) ? sanitize_key($_POST['bot_id']) : 'default';
944
945 // Save as user meta for the current user
946 $user_id = get_current_user_id();
947 update_user_meta($user_id, 'mxchat_selected_knowledge_bot', $bot_id);
948
949 // Also save as an option for site-wide default
950 update_option('mxchat_current_knowledge_bot', $bot_id);
951
952 // No cache clearing needed since we removed caching
953
954 wp_send_json_success(array(
955 'message' => 'Bot selection saved',
956 'bot_id' => $bot_id
957 ));
958 }
959
960 /**
961 * Handles AJAX request for saving chat settings
962 */
963 public function mxchat_save_prompts_setting_callback() {
964 check_ajax_referer('mxchat_prompts_setting_nonce');
965
966 if (!current_user_can('manage_options')) {
967 wp_send_json_error(['message' => esc_html__('Unauthorized', 'mxchat')]);
968 }
969
970 $name = isset($_POST['name']) ? $_POST['name'] : '';
971 $value = isset($_POST['value']) ? stripslashes($_POST['value']) : '';
972
973 //error_log('[MXCHAT-PROMPTS] Saving setting: ' . $name . ' = ' . $value);
974
975 if (empty($name)) {
976 wp_send_json_error(['message' => esc_html__('Invalid field name', 'mxchat')]);
977 }
978
979 // Handle Pinecone settings - BYPASS WORDPRESS SANITIZATION
980 if (strpos($name, 'mxchat_pinecone_addon_options') !== false) {
981 //error_log('[MXCHAT-PROMPTS] Processing Pinecone setting: ' . $name);
982
983 // Extract the field name
984 if (preg_match('/mxchat_pinecone_addon_options\[([^\]]+)\]/', $name, $matches)) {
985 $field_name = $matches[1];
986 //error_log('[MXCHAT-PROMPTS] Extracted field name: ' . $field_name);
987
988 // Get current options directly from database - NO WordPress filters
989 global $wpdb;
990 $current_options_raw = $wpdb->get_var(
991 $wpdb->prepare(
992 "SELECT option_value FROM {$wpdb->options} WHERE option_name = %s",
993 'mxchat_pinecone_addon_options'
994 )
995 );
996
997 // FIX: Handle the case where the option doesn't exist yet
998 if ($current_options_raw === null) {
999 // Option doesn't exist, create it with default values
1000 $current_options = array(
1001 'mxchat_use_pinecone' => '0',
1002 'mxchat_pinecone_api_key' => '',
1003 'mxchat_pinecone_host' => '',
1004 'mxchat_pinecone_index' => '',
1005 'mxchat_pinecone_environment' => ''
1006 );
1007 //error_log('[MXCHAT-PROMPTS] Option does not exist, creating with defaults');
1008 } else {
1009 // Unserialize the raw data
1010 $current_options = maybe_unserialize($current_options_raw);
1011 if (!is_array($current_options)) {
1012 // Fallback to defaults if unserialization fails
1013 $current_options = array(
1014 'mxchat_use_pinecone' => '0',
1015 'mxchat_pinecone_api_key' => '',
1016 'mxchat_pinecone_host' => '',
1017 'mxchat_pinecone_index' => '',
1018 'mxchat_pinecone_environment' => ''
1019 );
1020 //error_log('[MXCHAT-PROMPTS] Failed to unserialize, using defaults');
1021 }
1022 }
1023
1024 //error_log('[MXCHAT-PROMPTS] Current options from DB: ' . print_r($current_options, true));
1025
1026 // Update the specific field with proper sanitization
1027 switch ($field_name) {
1028 case 'mxchat_use_pinecone':
1029 $new_value = ($value === '1') ? '1' : '0';
1030 break;
1031 case 'mxchat_pinecone_api_key':
1032 case 'mxchat_pinecone_host':
1033 case 'mxchat_pinecone_index':
1034 case 'mxchat_pinecone_environment':
1035 $new_value = sanitize_text_field($value);
1036 if ($field_name === 'mxchat_pinecone_host') {
1037 $new_value = str_replace(['https://', 'http://'], '', $new_value);
1038 }
1039 break;
1040 case 'mxchat_pinecone_top_k':
1041 // d0cae1: out-of-range and junk normalize to the default 50 —
1042 // same clamp the read site applies.
1043 $top_k = absint($value);
1044 $new_value = (string) (($top_k >= 1 && $top_k <= 1000) ? $top_k : 50);
1045 break;
1046 default:
1047 wp_send_json_error(['message' => esc_html__('Unknown Pinecone field', 'mxchat')]);
1048 }
1049
1050 $current_options[$field_name] = $new_value;
1051 //error_log('[MXCHAT-PROMPTS] New value for ' . $field_name . ': "' . $new_value . '"');
1052 //error_log('[MXCHAT-PROMPTS] Updated options: ' . print_r($current_options, true));
1053
1054 // Save directly to database to bypass WordPress sanitization
1055 $serialized_options = maybe_serialize($current_options);
1056
1057 // FIX: Use INSERT ... ON DUPLICATE KEY UPDATE or separate INSERT/UPDATE logic
1058 $option_exists = $wpdb->get_var(
1059 $wpdb->prepare(
1060 "SELECT COUNT(*) FROM {$wpdb->options} WHERE option_name = %s",
1061 'mxchat_pinecone_addon_options'
1062 )
1063 );
1064
1065 if ($option_exists > 0) {
1066 // Update existing option
1067 $save_result = $wpdb->update(
1068 $wpdb->options,
1069 array('option_value' => $serialized_options),
1070 array('option_name' => 'mxchat_pinecone_addon_options'),
1071 array('%s'),
1072 array('%s')
1073 );
1074 //error_log('[MXCHAT-PROMPTS] Updated existing option, result: ' . ($save_result !== false ? 'SUCCESS' : 'FAILED'));
1075 } else {
1076 // Insert new option
1077 // Credential option — must NOT autoload (holds the Pinecone secret;
1078 // autoloaded rows are read into memory on every request).
1079 $save_result = $wpdb->insert(
1080 $wpdb->options,
1081 array(
1082 'option_name' => 'mxchat_pinecone_addon_options',
1083 'option_value' => $serialized_options,
1084 'autoload' => 'off'
1085 ),
1086 array('%s', '%s', '%s')
1087 );
1088 //error_log('[MXCHAT-PROMPTS] Inserted new option, result: ' . ($save_result !== false ? 'SUCCESS' : 'FAILED'));
1089 }
1090
1091 // Clear any WordPress option cache to ensure get_option() returns fresh data
1092 wp_cache_delete('mxchat_pinecone_addon_options', 'options');
1093
1094 // IMPROVED VERIFICATION - Check if the database operation succeeded
1095 if ($save_result !== false) {
1096 // Double-check by reading fresh from database
1097 $verification_raw = $wpdb->get_var(
1098 $wpdb->prepare(
1099 "SELECT option_value FROM {$wpdb->options} WHERE option_name = %s",
1100 'mxchat_pinecone_addon_options'
1101 )
1102 );
1103 $verification_options = maybe_unserialize($verification_raw);
1104 $verified_value = isset($verification_options[$field_name]) ? $verification_options[$field_name] : 'NOT_FOUND';
1105
1106 //error_log('[MXCHAT-PROMPTS] Final verification - Expected: "' . $new_value . '", Got: "' . $verified_value . '"');
1107
1108 // Use loose comparison (==) instead of strict (===) to avoid type issues
1109 if ($verified_value == $new_value || $save_result > 0) {
1110 wp_send_json_success(['message' => esc_html__('Pinecone setting saved', 'mxchat')]);
1111 } else {
1112 // Still return success if the DB operation worked, even if verification is quirky
1113 //error_log('[MXCHAT-PROMPTS] Verification mismatch but DB operation succeeded');
1114 wp_send_json_success(['message' => esc_html__('Pinecone setting saved (DB success)', 'mxchat')]);
1115 }
1116 } else {
1117 wp_send_json_error(['message' => esc_html__('Database save failed', 'mxchat')]);
1118 }
1119 } else {
1120 wp_send_json_error(['message' => esc_html__('Invalid field name format', 'mxchat')]);
1121 }
1122
1123 return; // Exit here for Pinecone settings
1124 }
1125 // Handle auto-sync settings (existing functionality)
1126 if (strpos($name, 'mxchat_auto_sync_') === 0) {
1127 $value = ($value === 'on' || $value === '1') ? '1' : '0';
1128 $updated = update_option($name, $value);
1129
1130 if ($updated || get_option($name) === $value) {
1131 wp_send_json_success(['message' => esc_html__('Auto-sync setting saved', 'mxchat')]);
1132 } else {
1133 wp_send_json_error(['message' => esc_html__('No changes detected', 'mxchat')]);
1134 }
1135 }
1136
1137 // Handle chunking settings - use direct DB access to bypass WordPress filters
1138 if (strpos($name, 'mxchat_chunk') === 0 || $name === 'mxchat_chunking_enabled') {
1139 global $wpdb;
1140
1141 // Get current options directly from database
1142 $current_options_raw = $wpdb->get_var(
1143 $wpdb->prepare(
1144 "SELECT option_value FROM {$wpdb->options} WHERE option_name = %s",
1145 'mxchat_options'
1146 )
1147 );
1148
1149 $options = $current_options_raw !== null ? maybe_unserialize($current_options_raw) : array();
1150 if (!is_array($options)) {
1151 $options = array();
1152 }
1153
1154 // Update the specific chunking field
1155 if ($name === 'mxchat_chunking_enabled') {
1156 $options['chunking_enabled'] = in_array($value, array('on', '1', 'true', true), true);
1157 } elseif ($name === 'mxchat_chunk_size') {
1158 $options['chunk_size'] = max(1000, min(10000, intval($value)));
1159 }
1160
1161 // Save directly to database
1162 $serialized_options = maybe_serialize($options);
1163
1164 $option_exists = $wpdb->get_var(
1165 $wpdb->prepare(
1166 "SELECT COUNT(*) FROM {$wpdb->options} WHERE option_name = %s",
1167 'mxchat_options'
1168 )
1169 );
1170
1171 if ($option_exists > 0) {
1172 $save_result = $wpdb->update(
1173 $wpdb->options,
1174 array('option_value' => $serialized_options),
1175 array('option_name' => 'mxchat_options'),
1176 array('%s'),
1177 array('%s')
1178 );
1179 } else {
1180 $save_result = $wpdb->insert(
1181 $wpdb->options,
1182 array(
1183 'option_name' => 'mxchat_options',
1184 'option_value' => $serialized_options,
1185 'autoload' => 'yes'
1186 ),
1187 array('%s', '%s', '%s')
1188 );
1189 }
1190
1191 // Clear object cache for this option
1192 wp_cache_delete('mxchat_options', 'options');
1193
1194 if ($save_result !== false) {
1195 wp_send_json_success(['message' => esc_html__('Chunking setting saved', 'mxchat')]);
1196 } else {
1197 wp_send_json_error(['message' => esc_html__('Failed to save chunking setting', 'mxchat')]);
1198 }
1199 return;
1200 }
1201
1202 // Handle ACF field exclusion toggles
1203 if (strpos($name, 'mxchat_acf_field_') === 0) {
1204 // The identifier after the prefix is the ACF field KEY (unique per
1205 // field), not the field name — names are shared across groups and
1206 // collide (plan 30e81f). Reject anything that isn't key-shaped so a
1207 // stale pre-3.2.20 page (or its exit beacon) posting a bare name
1208 // can't write junk into the key-based list.
1209 $field_key = str_replace('mxchat_acf_field_', '', $name);
1210 if (!preg_match('/^field_[A-Za-z0-9_\-]+$/', $field_key)) {
1211 wp_send_json_error(['message' => esc_html__('Invalid ACF field identifier', 'mxchat')]);
1212 return;
1213 }
1214 $is_enabled = ($value === 'on' || $value === '1');
1215
1216 // Get current excluded fields
1217 $excluded_fields = get_option('mxchat_acf_excluded_fields', array());
1218 if (!is_array($excluded_fields)) {
1219 $excluded_fields = array();
1220 }
1221
1222 if ($is_enabled) {
1223 // Remove from exclusion list (field should be included)
1224 $excluded_fields = array_values(array_diff($excluded_fields, array($field_key)));
1225 // Lazy legacy-name conversion: if this field's NAME is still
1226 // stored (its group was inactive when the 30e81f migration
1227 // ran), including this one field must not silently include
1228 // its same-named twins — swap the name entry for the keys of
1229 // every OTHER field currently wearing that name.
1230 $excluded_fields = $this->mxchat_expand_legacy_acf_name_entry($excluded_fields, $field_key);
1231 } else {
1232 // Add to exclusion list (field should be excluded)
1233 if (!in_array($field_key, $excluded_fields, true)) {
1234 $excluded_fields[] = $field_key;
1235 }
1236 }
1237
1238 $updated = update_option('mxchat_acf_excluded_fields', $excluded_fields);
1239
1240 if ($updated || true) { // Always report success since the state may already be correct
1241 wp_send_json_success([
1242 'message' => $is_enabled
1243 ? esc_html__('Field will be included in imports', 'mxchat')
1244 : esc_html__('Field will be excluded from imports', 'mxchat')
1245 ]);
1246 } else {
1247 wp_send_json_error(['message' => esc_html__('Failed to save ACF field setting', 'mxchat')]);
1248 }
1249 return;
1250 }
1251
1252 // Handle custom post meta whitelist
1253 if ($name === 'mxchat_custom_meta_whitelist') {
1254 $updated = update_option('mxchat_custom_meta_whitelist', sanitize_textarea_field($value));
1255
1256 if ($updated || true) { // Always report success since the state may already be correct
1257 wp_send_json_success([
1258 'message' => esc_html__('Custom meta whitelist saved', 'mxchat')
1259 ]);
1260 } else {
1261 wp_send_json_error(['message' => esc_html__('Failed to save custom meta whitelist', 'mxchat')]);
1262 }
1263 return;
1264 }
1265
1266 // Handle other prompts options (autoload false — can hold the Pinecone secret)
1267 $options = get_option('mxchat_prompts_options', []);
1268 $options[$name] = $value;
1269 $updated = update_option('mxchat_prompts_options', $options, false);
1270
1271 if ($updated) {
1272 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
1273 } else {
1274 wp_send_json_error(['message' => esc_html__('No changes detected', 'mxchat')]);
1275 }
1276 }
1277
1278 /**
1279 * If the field behind $included_key still has its NAME stored in the
1280 * exclusion list (a legacy entry the 30e81f migration could not resolve
1281 * because the group was inactive), replace that name with the keys of
1282 * every OTHER current field wearing it. Including one field must never
1283 * silently include its same-named twins — that would be the original
1284 * collision bug in reverse, in the unsafe (privacy-losing) direction.
1285 */
1286 private function mxchat_expand_legacy_acf_name_entry($excluded_fields, $included_key) {
1287 if (!function_exists('acf_get_field')) {
1288 return $excluded_fields;
1289 }
1290 $field = acf_get_field($included_key);
1291 if (!$field || empty($field['name'])) {
1292 return $excluded_fields;
1293 }
1294 $field_name = $field['name'];
1295 if (!in_array($field_name, $excluded_fields, true)) {
1296 return $excluded_fields;
1297 }
1298 $excluded_fields = array_values(array_diff($excluded_fields, array($field_name)));
1299 foreach ($this->mxchat_acf_keys_for_name($field_name) as $twin_key) {
1300 if ($twin_key !== $included_key && !in_array($twin_key, $excluded_fields, true)) {
1301 $excluded_fields[] = $twin_key;
1302 }
1303 }
1304 return $excluded_fields;
1305 }
1306
1307 /**
1308 * Keys of every currently-registered top-level ACF field with this name.
1309 */
1310 private function mxchat_acf_keys_for_name($field_name) {
1311 $keys = array();
1312 if (!function_exists('acf_get_field_groups') || !function_exists('acf_get_fields')) {
1313 return $keys;
1314 }
1315 foreach (acf_get_field_groups() as $group) {
1316 $group_fields = acf_get_fields($group['key']);
1317 if (empty($group_fields)) {
1318 continue;
1319 }
1320 foreach ($group_fields as $field) {
1321 if (isset($field['name'], $field['key']) && $field['name'] === $field_name) {
1322 $keys[] = $field['key'];
1323 }
1324 }
1325 }
1326 return $keys;
1327 }
1328
1329 /**
1330 * Group-level ACF toggle (plan bf57e0): sets every field in one ACF field
1331 * group included or excluded in a SINGLE option write. The client must
1332 * never loop the per-field endpoint for this — get_option → modify →
1333 * update_option once per field from twenty concurrent requests is a
1334 * lost-update race that silently drops most of the group.
1335 */
1336 public function mxchat_acf_toggle_group_callback() {
1337 check_ajax_referer('mxchat_prompts_setting_nonce');
1338
1339 if (!current_user_can('manage_options')) {
1340 wp_send_json_error(['message' => esc_html__('Insufficient permissions', 'mxchat')], 403);
1341 return;
1342 }
1343
1344 if (!function_exists('acf_get_fields')) {
1345 wp_send_json_error(['message' => esc_html__('ACF is not active', 'mxchat')]);
1346 return;
1347 }
1348
1349 $group_key = isset($_POST['group_key']) ? sanitize_text_field(wp_unslash($_POST['group_key'])) : '';
1350 if (!preg_match('/^group_[A-Za-z0-9_\-]+$/', $group_key)) {
1351 wp_send_json_error(['message' => esc_html__('Invalid ACF group identifier', 'mxchat')]);
1352 return;
1353 }
1354 $state = isset($_POST['state']) ? sanitize_text_field(wp_unslash($_POST['state'])) : '';
1355 $include = ($state === 'on' || $state === '1');
1356
1357 // Resolve the group's fields SERVER-side — a client-supplied key list
1358 // is not trusted. This is the same call the settings UI lists from,
1359 // so the toggle covers exactly the rendered set (top-level fields).
1360 $group_fields = acf_get_fields($group_key);
1361 if (empty($group_fields)) {
1362 wp_send_json_error(['message' => esc_html__('No fields found for this group', 'mxchat')]);
1363 return;
1364 }
1365
1366 $excluded_fields = get_option('mxchat_acf_excluded_fields', array());
1367 if (!is_array($excluded_fields)) {
1368 $excluded_fields = array();
1369 }
1370
1371 $touched = array();
1372 foreach ($group_fields as $field) {
1373 if (empty($field['key'])) {
1374 continue;
1375 }
1376 if ($include) {
1377 $excluded_fields = array_values(array_diff($excluded_fields, array($field['key'])));
1378 $excluded_fields = $this->mxchat_expand_legacy_acf_name_entry($excluded_fields, $field['key']);
1379 } elseif (!in_array($field['key'], $excluded_fields, true)) {
1380 $excluded_fields[] = $field['key'];
1381 }
1382 $touched[] = array(
1383 'name' => 'mxchat_acf_field_' . $field['key'],
1384 'value' => $include ? 'on' : 'off',
1385 );
1386 }
1387
1388 // The one write — the whole point of this endpoint.
1389 update_option('mxchat_acf_excluded_fields', array_values($excluded_fields));
1390
1391 wp_send_json_success([
1392 'message' => $include
1393 ? esc_html__('All fields in this group will be included in imports', 'mxchat')
1394 : esc_html__('All fields in this group will be excluded from imports', 'mxchat'),
1395 'fields' => $touched,
1396 ]);
1397 }
1398
1399 /**
1400 * Handles AJAX request for Pinecone settings migration
1401 */
1402 public function ajax_migrate_pinecone_settings() {
1403 // Verify nonce
1404 if (!wp_verify_nonce($_POST['_ajax_nonce'] ?? '', 'mxchat_save_setting_nonce')) {
1405 wp_send_json_error('Invalid nonce');
1406 }
1407
1408 // Check permissions
1409 if (!current_user_can('manage_options')) {
1410 wp_send_json_error('Unauthorized access');
1411 }
1412
1413 // Check if old Pinecone addon options exist
1414 $old_options = get_option('mxchat_pinecone_addon_options', array());
1415
1416 if (empty($old_options)) {
1417 wp_send_json_success(array('migrated' => false, 'message' => 'No old settings found'));
1418 }
1419
1420 // Get current core plugin options
1421 $current_options = get_option('mxchat_pinecone_addon_options', array());
1422
1423 // Only migrate if core options are empty or if explicitly requested
1424 $should_migrate = empty($current_options) ||
1425 (empty($current_options['mxchat_pinecone_api_key']) && !empty($old_options['mxchat_pinecone_api_key']));
1426
1427 if ($should_migrate) {
1428 // Migrate settings with proper sanitization
1429 $migrated_options = array(
1430 'mxchat_use_pinecone' => $old_options['mxchat_use_pinecone'] ?? '0',
1431 'mxchat_pinecone_api_key' => sanitize_text_field($old_options['mxchat_pinecone_api_key'] ?? ''),
1432 'mxchat_pinecone_host' => sanitize_text_field($old_options['mxchat_pinecone_host'] ?? ''),
1433 'mxchat_pinecone_index' => sanitize_text_field($old_options['mxchat_pinecone_index'] ?? ''),
1434 'mxchat_pinecone_environment' => sanitize_text_field($old_options['mxchat_pinecone_environment'] ?? '')
1435 );
1436
1437 update_option('mxchat_pinecone_addon_options', $migrated_options, false);
1438
1439 wp_send_json_success(array(
1440 'migrated' => true,
1441 'message' => 'Settings migrated successfully from Pinecone add-on'
1442 ));
1443 } else {
1444 wp_send_json_success(array(
1445 'migrated' => false,
1446 'message' => 'Settings already exist in core plugin'
1447 ));
1448 }
1449 }
1450
1451
1452 // ========================================
1453 // LICENSE AJAX HANDLERS
1454 // ========================================
1455
1456 /**
1457 * Validates and activates chat license via AJAX
1458 */
1459 public function mxchat_handle_activate_license() {
1460 // Check nonce
1461 if (!check_ajax_referer('mxchat_activate_license_nonce', 'security', false)) {
1462 wp_send_json_error(esc_html__('Invalid security token', 'mxchat'));
1463 return;
1464 }
1465
1466 // Verify user capabilities
1467 if (!current_user_can('manage_options')) {
1468 wp_send_json_error(esc_html__('Unauthorized access', 'mxchat'));
1469 return;
1470 }
1471
1472 $license_key = isset($_POST['mxchat_activation_key']) ? sanitize_text_field($_POST['mxchat_activation_key']) : '';
1473 $customer_email = isset($_POST['mxchat_pro_email']) ? sanitize_email($_POST['mxchat_pro_email']) : '';
1474
1475 if (empty($license_key) || empty($customer_email)) {
1476 wp_send_json_error(esc_html__('Email or License Key is missing', 'mxchat'));
1477 return;
1478 }
1479
1480 $product_id = 'MxChatPRO';
1481 $domain = parse_url(home_url(), PHP_URL_HOST); // Get the current domain
1482
1483 // Call WooCommerce Software API for activation (not just validation)
1484 $response = wp_remote_get(
1485 add_query_arg(
1486 array(
1487 'wc-api' => 'software-api',
1488 'request' => 'activation',
1489 'email' => $customer_email,
1490 'license_key' => $license_key,
1491 'product_id' => $product_id,
1492 'instance' => $domain, // THIS IS KEY - include the domain as instance
1493 'platform' => 'wordpress' // Optional but good to include
1494 ),
1495 'https://mxchat.ai/'
1496 ),
1497 array(
1498 'timeout' => 60,
1499 'sslverify' => true
1500 )
1501 );
1502
1503 if (is_wp_error($response)) {
1504 $error_message = $response->get_error_message();
1505 //error_log('MxChat License Activation Error: ' . $error_message);
1506 wp_send_json_error(esc_html__('Activation failed due to a server error: ', 'mxchat') . $error_message);
1507 return;
1508 }
1509
1510 $response_code = wp_remote_retrieve_response_code($response);
1511 $body = wp_remote_retrieve_body($response);
1512
1513 // Log response for debugging
1514 //error_log('MxChat License Response Code: ' . $response_code);
1515 //error_log('MxChat License Response Body: ' . $body);
1516
1517 if ($response_code !== 200) {
1518 wp_send_json_error(esc_html__('Server returned error code: ', 'mxchat') . $response_code);
1519 return;
1520 }
1521
1522 $data = json_decode($body);
1523
1524 if ($data && isset($data->activated) && $data->activated) {
1525 // Success - save local options
1526 update_option('mxchat_license_status', 'active');
1527 update_option('mxchat_pro_email', $customer_email);
1528 update_option('mxchat_activation_key', $license_key);
1529 delete_option('mxchat_license_error');
1530
1531 // Also track on your website (this is your existing domain tracking)
1532 $this->track_domain_on_website($license_key, $customer_email, $domain);
1533
1534 wp_send_json_success(array('message' => esc_html__('License activated successfully', 'mxchat')));
1535 } else {
1536 $error_message = isset($data->error) ? $data->error : esc_html__('Activation failed', 'mxchat');
1537 update_option('mxchat_license_status', 'inactive');
1538 update_option('mxchat_license_error', $error_message);
1539
1540 //error_log('MxChat Activation failed: ' . $error_message);
1541 wp_send_json_error($error_message);
1542 }
1543 }
1544
1545 /**
1546 * Track domain on your website (separate from WooCommerce activation)
1547 */
1548 private function track_domain_on_website($license_key, $email, $domain) {
1549 // This calls your website's tracking API
1550 wp_remote_post('https://mxchat.ai/mxchat-api/activate-license', array(
1551 'body' => array(
1552 'mxchat_pro_email' => $email,
1553 'mxchat_activation_key' => $license_key,
1554 'domain' => $domain
1555 ),
1556 'timeout' => 10,
1557 'sslverify' => true
1558 ));
1559 }
1560
1561 /**
1562 * Validates license via AJAX with email and key
1563 */
1564 public function mxchat_check_license_status() {
1565 // Verify nonce
1566 if (!check_ajax_referer('mxchat_activate_license_nonce', 'security', false)) {
1567 wp_send_json_error('Security check failed');
1568 return;
1569 }
1570
1571 // Add isset checks for safety
1572 $email = isset($_POST['email']) ? sanitize_email($_POST['email']) : '';
1573 $key = isset($_POST['key']) ? sanitize_text_field($_POST['key']) : '';
1574
1575 // Check if this license is actually active in your system
1576 $is_active = (get_option('mxchat_license_status') === 'active' &&
1577 get_option('mxchat_pro_email') === $email &&
1578 get_option('mxchat_activation_key') === $key);
1579
1580 wp_send_json(array(
1581 'is_active' => $is_active
1582 ));
1583 }
1584
1585 /**
1586 * Handle license deactivation - Complete version for plugin
1587 */
1588 function mxchat_deactivate_license() {
1589 // Add debugging
1590 //error_log('MxChat deactivate function called');
1591
1592 // Check nonce
1593 if (!check_ajax_referer('mxchat_activate_license_nonce', 'security', false)) {
1594 //error_log('MxChat deactivate: Nonce check failed');
1595 wp_send_json_error('Security check failed.');
1596 return;
1597 }
1598
1599 // plan-mxchat-20260731-c63fb6 — nonce is not authorization. Without this,
1600 // any authenticated user holding the nonce could revoke the site's PRO
1601 // licence. Every sibling handler in this file already checks.
1602 if (!current_user_can('manage_options')) {
1603 wp_send_json_error(esc_html__('Unauthorized', 'mxchat'), 403);
1604 return;
1605 }
1606
1607 //error_log('MxChat deactivate: Nonce check passed');
1608
1609 $license_key = get_option('mxchat_activation_key');
1610 $email = get_option('mxchat_pro_email');
1611 $domain = parse_url(home_url(), PHP_URL_HOST);
1612
1613 //error_log('MxChat deactivate: License: ' . $license_key . ', Email: ' . $email . ', Domain: ' . $domain);
1614
1615 if (empty($license_key) || empty($email)) {
1616 //error_log('MxChat deactivate: No active license found');
1617 wp_send_json_error('No active license found.');
1618 return;
1619 }
1620
1621 // Clear local license data first
1622 delete_option('mxchat_license_status');
1623 delete_option('mxchat_pro_email');
1624 delete_option('mxchat_activation_key');
1625 delete_option('mxchat_license_error');
1626
1627 //error_log('MxChat deactivate: Local data cleared');
1628
1629 // Notify your website's API to properly deactivate
1630 $response = wp_remote_post('https://mxchat.ai/mxchat-api/deactivate-license', array(
1631 'body' => array(
1632 'license_key' => $license_key,
1633 'email' => $email,
1634 'domain' => $domain
1635 ),
1636 'timeout' => 15,
1637 'sslverify' => true
1638 ));
1639
1640 if (is_wp_error($response)) {
1641 //error_log('MxChat deactivate: Server error - ' . $response->get_error_message());
1642 wp_send_json_success(array(
1643 'message' => 'License deactivated locally. Server could not be contacted to free activation slot.',
1644 'server_notified' => false
1645 ));
1646 return;
1647 }
1648
1649 $response_body = wp_remote_retrieve_body($response);
1650 $response_data = json_decode($response_body, true);
1651
1652 //error_log('MxChat deactivate: Server response - ' . $response_body);
1653
1654 if (isset($response_data['success']) && $response_data['success']) {
1655 //error_log('MxChat deactivate: Success with server notification');
1656 wp_send_json_success(array(
1657 'message' => 'License deactivated successfully. Activation slot has been freed up.',
1658 'server_notified' => true
1659 ));
1660 } else {
1661 //error_log('MxChat deactivate: Server responded but deactivation may have failed');
1662 wp_send_json_success(array(
1663 'message' => 'License deactivated locally. Please check your account dashboard to verify the activation was freed.',
1664 'server_notified' => false
1665 ));
1666 }
1667 }
1668
1669
1670 // ========================================
1671 // ACTIONS & INTENTS AJAX HANDLERS
1672 // ========================================
1673
1674 /**
1675 * Validates nonce and returns JSON error on failure
1676 */
1677 public function mxchat_toggle_action() {
1678 // Check nonce
1679 if (!isset($_POST['nonce']) || !wp_verify_nonce($_POST['nonce'], 'mxchat_actions_nonce')) {
1680 wp_send_json_error(array('message' => 'Security check failed'));
1681 return;
1682 }
1683
1684 // Check permissions
1685 if (!current_user_can('manage_options')) {
1686 wp_send_json_error(array('message' => 'Permission denied'));
1687 return;
1688 }
1689
1690 // Validate params
1691 $intent_id = isset($_POST['intent_id']) ? intval($_POST['intent_id']) : 0;
1692 $enabled = isset($_POST['enabled']) ? (bool)$_POST['enabled'] : false;
1693
1694 if (!$intent_id) {
1695 wp_send_json_error(array('message' => 'Invalid action ID'));
1696 return;
1697 }
1698
1699 // Update the intent/action status in the database
1700 global $wpdb;
1701 $table_name = $wpdb->prefix . 'mxchat_intents';
1702
1703 // Using the 'enabled' field - add this field if it doesn't exist
1704 $result = $wpdb->update(
1705 $table_name,
1706 array('enabled' => $enabled ? 1 : 0),
1707 array('id' => $intent_id),
1708 array('%d'),
1709 array('%d')
1710 );
1711
1712 if ($result === false) {
1713 wp_send_json_error(array('message' => 'Database error'));
1714 return;
1715 }
1716
1717 wp_send_json_success();
1718 }
1719
1720
1721 /**
1722 * Validates permissions for AJAX request handling
1723 */
1724 public function mxchat_update_intent_threshold() {
1725 // Check permissions
1726 if (!current_user_can('manage_options')) {
1727 if (wp_doing_ajax()) {
1728 wp_send_json_error(array('message' => 'Unauthorized user'));
1729 return;
1730 }
1731 wp_die(esc_html__('Unauthorized user', 'mxchat'));
1732 }
1733
1734 // Verify nonce
1735 check_admin_referer('mxchat_update_intent_threshold_nonce');
1736
1737 // Process the update if we have valid data
1738 if (isset($_POST['intent_id'], $_POST['intent_threshold'])) {
1739 global $wpdb;
1740 $table_name = $wpdb->prefix . 'mxchat_intents';
1741 $intent_id = intval($_POST['intent_id']);
1742 $threshold_percentage = max(70, min(95, intval($_POST['intent_threshold'])));
1743 $similarity_threshold = $threshold_percentage / 100;
1744
1745 $result = $wpdb->update(
1746 $table_name,
1747 ['similarity_threshold' => $similarity_threshold],
1748 ['id' => $intent_id],
1749 ['%f'],
1750 ['%d']
1751 );
1752
1753 // Handle AJAX requests
1754 if (wp_doing_ajax()) {
1755 if ($result === false) {
1756 wp_send_json_error(array('message' => 'Failed to update threshold'));
1757 } else {
1758 wp_send_json_success(array('threshold' => $threshold_percentage));
1759 }
1760 return;
1761 }
1762 }
1763
1764 // Redirect for regular form submissions
1765 wp_safe_redirect(admin_url('admin.php?page=mxchat-actions&updated=true'));
1766 exit;
1767 }
1768
1769 // ========================================
1770 // HELPER METHODS
1771 // ========================================
1772
1773 /**
1774 * Returns a specific nonce action string
1775 */
1776 private function mxchat_get_nonce_action() {
1777 return 'mxchat_license_nonce';
1778 }
1779
1780 /**
1781 * Check API key status for all providers
1782 */
1783 public function mxchat_check_api_keys() {
1784 // Check nonce
1785 if (!wp_verify_nonce($_POST['nonce'] ?? '', 'mxchat_save_setting_nonce')) {
1786 wp_send_json_error('Invalid nonce');
1787 }
1788
1789 // Check permissions
1790 if (!current_user_can('manage_options')) {
1791 wp_send_json_error('Unauthorized');
1792 }
1793
1794 // Get current options
1795 $options = get_option('mxchat_options', array());
1796
1797 // Check which API keys are present
1798 $api_key_status = array(
1799 'openai' => !empty($options['api_key']),
1800 'claude' => !empty($options['claude_api_key']),
1801 'xai' => !empty($options['xai_api_key']),
1802 'deepseek' => !empty($options['deepseek_api_key']),
1803 'gemini' => !empty($options['gemini_api_key']),
1804 'openrouter' => !empty($options['openrouter_api_key']),
1805 'voyage' => !empty($options['voyage_api_key'])
1806 );
1807
1808 wp_send_json_success($api_key_status);
1809 }
1810
1811 // ========================================
1812 // DEBUG & OPTIMIZATION AJAX HANDLERS
1813 // ========================================
1814
1815 /**
1816 * Toggle debug mode on/off
1817 */
1818 public function mxchat_toggle_debug_mode_callback() {
1819 // Verify nonce
1820 if ( ! check_ajax_referer( 'mxchat_save_setting_nonce', '_ajax_nonce', false ) ) {
1821 wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1822 }
1823
1824 // Check permissions
1825 if ( ! current_user_can( 'manage_options' ) ) {
1826 wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1827 }
1828
1829 $enabled = isset( $_POST['enabled'] ) && $_POST['enabled'] === 'on';
1830
1831 $options = get_option( 'mxchat_options', array() );
1832
1833 if ( $enabled ) {
1834 $options['debug_mode'] = 'on';
1835 update_option( 'mxchat_options', $options );
1836 MxChat_Admin::mxchat_log_debug( 'debug_mode', 'Debug mode enabled' );
1837 } else {
1838 // Log before disabling
1839 MxChat_Admin::mxchat_log_debug( 'debug_mode', 'Debug mode disabled' );
1840 $options['debug_mode'] = 'off';
1841 update_option( 'mxchat_options', $options );
1842 }
1843
1844 wp_send_json_success( array(
1845 'message' => $enabled ? esc_html__( 'Debug mode enabled', 'mxchat' ) : esc_html__( 'Debug mode disabled', 'mxchat' ),
1846 'enabled' => $enabled,
1847 ) );
1848 }
1849
1850 /**
1851 * Get the debug log entries
1852 */
1853 public function mxchat_get_debug_log_callback() {
1854 // Verify nonce
1855 if ( ! check_ajax_referer( 'mxchat_save_setting_nonce', '_ajax_nonce', false ) ) {
1856 wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1857 }
1858
1859 // Check permissions
1860 if ( ! current_user_can( 'manage_options' ) ) {
1861 wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1862 }
1863
1864 $log = MxChat_Admin::mxchat_get_debug_log();
1865
1866 wp_send_json_success( array(
1867 'log' => $log,
1868 'count' => count( $log ),
1869 ) );
1870 }
1871
1872 /**
1873 * Clear the debug log
1874 */
1875 public function mxchat_clear_debug_log_callback() {
1876 // Verify nonce
1877 if ( ! check_ajax_referer( 'mxchat_save_setting_nonce', '_ajax_nonce', false ) ) {
1878 wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1879 }
1880
1881 // Check permissions
1882 if ( ! current_user_can( 'manage_options' ) ) {
1883 wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1884 }
1885
1886 MxChat_Admin::mxchat_clear_debug_log();
1887
1888 // Log that the log was cleared (this will be the first entry in the new log)
1889 MxChat_Admin::mxchat_log_debug( 'debug_log', 'Debug log cleared by user' );
1890
1891 wp_send_json_success( array( 'message' => esc_html__( 'Debug log cleared', 'mxchat' ) ) );
1892 }
1893
1894 /**
1895 * Export settings as JSON
1896 */
1897 public function mxchat_export_settings_callback() {
1898 // Verify nonce
1899 if ( ! check_ajax_referer( 'mxchat_save_setting_nonce', '_ajax_nonce', false ) ) {
1900 wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1901 }
1902
1903 // Check permissions
1904 if ( ! current_user_can( 'manage_options' ) ) {
1905 wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1906 }
1907
1908 $export = MxChat_Admin::mxchat_export_settings();
1909
1910 // Log the export
1911 MxChat_Admin::mxchat_log_debug( 'settings_export', 'Settings exported by user' );
1912
1913 wp_send_json_success( array(
1914 'settings' => $export,
1915 'filename' => 'mxchat-settings-' . gmdate( 'Y-m-d-His' ) . '.json',
1916 ) );
1917 }
1918
1919 /**
1920 * Reset all settings to defaults
1921 */
1922 public function mxchat_reset_all_settings_callback() {
1923 // Verify nonce
1924 if ( ! check_ajax_referer( 'mxchat_save_setting_nonce', '_ajax_nonce', false ) ) {
1925 wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1926 }
1927
1928 // Check permissions
1929 if ( ! current_user_can( 'manage_options' ) ) {
1930 wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1931 }
1932
1933 // Require confirmation code
1934 $confirmation = isset( $_POST['confirmation'] ) ? sanitize_text_field( wp_unslash( $_POST['confirmation'] ) ) : '';
1935
1936 if ( strtoupper( $confirmation ) !== 'RESET' ) {
1937 wp_send_json_error( array( 'message' => esc_html__( 'Invalid confirmation code. Please type RESET to confirm.', 'mxchat' ) ) );
1938 }
1939
1940 // Perform the reset
1941 MxChat_Admin::mxchat_reset_all_settings();
1942
1943 wp_send_json_success( array( 'message' => esc_html__( 'All settings have been reset to defaults. The page will reload.', 'mxchat' ) ) );
1944 }
1945
1946 /**
1947 * Reset the global rate-limit usage counter to zero on demand.
1948 *
1949 * Zeroes the WP option mxchat_chat_limit_<bot>_global that the integrator
1950 * increments per message, then returns a freshly-formatted readout string
1951 * so the settings page can update without a reload. Does NOT change any
1952 * enforcement config — purely clears the running counter.
1953 */
1954 public function mxchat_reset_global_rate_limit_callback() {
1955 // Verify nonce
1956 if ( ! check_ajax_referer( 'mxchat_reset_global_usage', '_ajax_nonce', false ) ) {
1957 wp_send_json_error( array( 'message' => esc_html__( 'Security check failed', 'mxchat' ) ) );
1958 }
1959
1960 // Check permissions
1961 if ( ! current_user_can( 'manage_options' ) ) {
1962 wp_send_json_error( array( 'message' => esc_html__( 'Unauthorized', 'mxchat' ) ) );
1963 }
1964
1965 // Resolve the per-bot counter key the same way the integrator does.
1966 $bot_id = isset( $_POST['bot_id'] ) ? sanitize_key( wp_unslash( $_POST['bot_id'] ) ) : 'default';
1967 $safe_bot = preg_replace( '/[^a-zA-Z0-9_]/', '_', $bot_id );
1968 if ( $safe_bot === '' ) {
1969 $safe_bot = 'default';
1970 }
1971 $option_key = 'mxchat_chat_limit_' . $safe_bot . '_global';
1972
1973 $now = time();
1974 update_option( $option_key, array( 'count' => 0, 'timestamp' => $now ) );
1975
1976 // Recompute the display string so the front-end can update in place.
1977 $all_options = get_option( 'mxchat_options', array() );
1978 $global_cfg = isset( $all_options['rate_limits_global'] ) && is_array( $all_options['rate_limits_global'] )
1979 ? $all_options['rate_limits_global']
1980 : array();
1981 $limit_raw = isset( $global_cfg['limit'] ) ? (string) $global_cfg['limit'] : 'unlimited';
1982 // Defensive: if a raw __custom__ ever slips through, fall back to the custom value.
1983 if ( ! ctype_digit( $limit_raw ) && isset( $global_cfg['limit_custom'] ) && ctype_digit( (string) $global_cfg['limit_custom'] ) ) {
1984 $limit_raw = (string) $global_cfg['limit_custom'];
1985 }
1986 $timeframe = isset( $global_cfg['timeframe'] ) ? (string) $global_cfg['timeframe'] : 'daily';
1987 $windows = array( 'hourly' => 3600, 'daily' => 86400, 'weekly' => 604800, 'monthly' => 2592000 );
1988 $window = isset( $windows[ $timeframe ] ) ? $windows[ $timeframe ] : 86400;
1989 $reset_at = $now + $window;
1990 $limit_int = ctype_digit( $limit_raw ) ? (int) $limit_raw : 0;
1991
1992 $text = sprintf(
1993 /* translators: 1: used count, 2: limit, 3: remaining, 4: human-readable time until reset */
1994 esc_html__( '%1$s of %2$s used · %3$s left · resets in %4$s', 'mxchat' ),
1995 number_format_i18n( 0 ),
1996 number_format_i18n( $limit_int ),
1997 number_format_i18n( $limit_int ),
1998 human_time_diff( $now, $reset_at )
1999 );
2000
2001 wp_send_json_success( array(
2002 'count' => 0,
2003 'limit' => $limit_int,
2004 'left' => $limit_int,
2005 'reset_at' => $reset_at,
2006 'pct' => 0,
2007 'text' => $text,
2008 'message' => esc_html__( 'Usage counter reset.', 'mxchat' ),
2009 ) );
2010 }
2011
2012 }
2013
2014 // Initialize the AJAX handler
2015 new MxChat_Ajax_Handler();
2016