| @@ -27,8 +27,9 @@ | ||
| 27 | 27 | private function mxchat_init_ajax_hooks() { |
| 28 | 28 | // Settings AJAX |
| 29 | 29 | add_action('wp_ajax_mxchat_save_setting', array($this, 'mxchat_save_setting_callback')); |
| 30 | 30 | add_action('wp_ajax_mxchat_save_prompts_setting', array($this, 'mxchat_save_prompts_setting_callback')); |
| 31 | + add_action('wp_ajax_mxchat_acf_toggle_group', array($this, 'mxchat_acf_toggle_group_callback')); | |
| 31 | 32 | add_action('wp_ajax_migrate_pinecone_settings', array($this, 'ajax_migrate_pinecone_settings')); |
| 32 | 33 | |
| 33 | 34 | // License AJAX |
| 34 | 35 | add_action('wp_ajax_mxchat_handle_activate_license', array($this, 'mxchat_handle_activate_license')); |
| @@ -56,11 +57,116 @@ | ||
| 56 | 57 | add_action('wp_ajax_mxchat_test_custom_provider', array($this, 'mxchat_test_custom_provider_callback')); |
| 57 | 58 | |
| 58 | 59 | // Built-in provider key validation — cheap per-provider auth check (plan-mxchat-20260623-c41f74) |
| 59 | 60 | add_action('wp_ajax_mxchat_test_provider_key', array($this, 'mxchat_test_provider_key_callback')); |
| 61 | + | |
| 62 | + // Custom Post Meta discovery scan for the KB whitelist picker (plan-mxchat-20260709-fe8e4e) | |
| 63 | + add_action('wp_ajax_mxchat_scan_custom_meta_keys', array($this, 'mxchat_scan_custom_meta_keys_callback')); | |
| 60 | 64 | } |
| 61 | 65 | |
| 62 | 66 | /** |
| 67 | + * Discover non-ACF custom post-meta keys present on published public content, so the | |
| 68 | + * KB → Custom Post Meta section can offer a click-to-add picker instead of a blind | |
| 69 | + * "type the exact key you already know" textarea. plan-mxchat-20260709-fe8e4e. | |
| 70 | + * | |
| 71 | + * Bounded + button-triggered only (never on page load). Returns up to 50 keys by | |
| 72 | + * frequency, each with a short sample value, so the owner can judge relevance before | |
| 73 | + * whitelisting. Underscore-prefixed (protected/internal) keys are hidden unless the | |
| 74 | + * caller opts in; ACF-managed keys are excluded so this picker never double-lists the | |
| 75 | + * sibling ACF discovery picker on the same page. | |
| 76 | + */ | |
| 77 | +public function mxchat_scan_custom_meta_keys_callback() { | |
| 78 | + check_ajax_referer('mxchat_prompts_setting_nonce'); | |
| 79 | + | |
| 80 | + if (!current_user_can('manage_options')) { | |
| 81 | + wp_send_json_error(['message' => esc_html__('Unauthorized', 'mxchat')]); | |
| 82 | + } | |
| 83 | + | |
| 84 | + global $wpdb; | |
| 85 | + | |
| 86 | + $include_internal = isset($_POST['include_internal']) && $_POST['include_internal'] === '1'; | |
| 87 | + | |
| 88 | + // Restrict discovery to public post types (the content the KB actually embeds). | |
| 89 | + $post_types = get_post_types(array('public' => true), 'names'); | |
| 90 | + if (empty($post_types)) { | |
| 91 | + wp_send_json_success(array('keys' => array(), 'scanned' => 0)); | |
| 92 | + } | |
| 93 | + $pt_placeholders = implode(',', array_fill(0, count($post_types), '%s')); | |
| 94 | + | |
| 95 | + // Build the set of ACF-managed meta keys to exclude. ACF stores, alongside each | |
| 96 | + // value key `foo`, a reference key `_foo` whose value is the ACF field key | |
| 97 | + // (`field_xxxxx`). Strip the leading underscore from every such reference key to | |
| 98 | + // get the real meta key, and exclude those — the ACF picker on this page owns them. | |
| 99 | + $acf_managed = array(); | |
| 100 | + $acf_refs = $wpdb->get_col( | |
| 101 | + $wpdb->prepare( | |
| 102 | + "SELECT DISTINCT meta_key FROM {$wpdb->postmeta} WHERE meta_key LIKE %s AND meta_value LIKE %s", | |
| 103 | + $wpdb->esc_like('_') . '%', | |
| 104 | + $wpdb->esc_like('field_') . '%' | |
| 105 | + ) | |
| 106 | + ); | |
| 107 | + foreach ((array) $acf_refs as $ref_key) { | |
| 108 | + if (strlen($ref_key) > 1 && $ref_key[0] === '_') { | |
| 109 | + $acf_managed[substr($ref_key, 1)] = true; | |
| 110 | + } | |
| 111 | + } | |
| 112 | + | |
| 113 | + // Discover keys + counts + a sample value in one bounded aggregate query. | |
| 114 | + // SUBSTRING(MIN(...)) keeps the sample selection ONLY_FULL_GROUP_BY-safe. | |
| 115 | + $params = $post_types; | |
| 116 | + $sql = "SELECT pm.meta_key AS mk, COUNT(*) AS n, SUBSTRING(MIN(pm.meta_value), 1, 200) AS sample | |
| 117 | + FROM {$wpdb->postmeta} pm | |
| 118 | + INNER JOIN {$wpdb->posts} p ON p.ID = pm.post_id | |
| 119 | + WHERE p.post_status = 'publish' | |
| 120 | + AND p.post_type IN ($pt_placeholders) | |
| 121 | + AND pm.meta_key <> ''"; | |
| 122 | + if (!$include_internal) { | |
| 123 | + $sql .= " AND pm.meta_key NOT LIKE %s"; | |
| 124 | + $params[] = $wpdb->esc_like('_') . '%'; | |
| 125 | + } | |
| 126 | + $sql .= " GROUP BY pm.meta_key ORDER BY n DESC, pm.meta_key ASC LIMIT 200"; | |
| 127 | + | |
| 128 | + // phpcs:ignore WordPress.DB.PreparedSQL — placeholders assembled above, values in $params. | |
| 129 | + $rows = $wpdb->get_results($wpdb->prepare($sql, $params)); | |
| 130 | + | |
| 131 | + $keys = array(); | |
| 132 | + foreach ((array) $rows as $row) { | |
| 133 | + $mk = $row->mk; | |
| 134 | + if (isset($acf_managed[$mk])) { | |
| 135 | + continue; // already offered by the ACF picker | |
| 136 | + } | |
| 137 | + | |
| 138 | + $raw = (string) $row->sample; | |
| 139 | + if ($raw !== '' && (is_serialized($raw) || preg_match('/^(a:\d+:\{|O:\d+:"|s:\d+:")/', $raw))) { | |
| 140 | + $sample = esc_html__('[structured value]', 'mxchat'); | |
| 141 | + } else { | |
| 142 | + $sample = trim(preg_replace('/\s+/', ' ', $raw)); | |
| 143 | + if (function_exists('mb_strlen') ? mb_strlen($sample) > 60 : strlen($sample) > 60) { | |
| 144 | + $sample = (function_exists('mb_substr') ? mb_substr($sample, 0, 60) : substr($sample, 0, 60)) . '…'; | |
| 145 | + } | |
| 146 | + if ($sample === '') { | |
| 147 | + $sample = esc_html__('(empty value)', 'mxchat'); | |
| 148 | + } | |
| 149 | + } | |
| 150 | + | |
| 151 | + $keys[] = array( | |
| 152 | + 'key' => $mk, | |
| 153 | + 'count' => (int) $row->n, | |
| 154 | + 'sample' => $sample, | |
| 155 | + ); | |
| 156 | + | |
| 157 | + if (count($keys) >= 50) { | |
| 158 | + break; | |
| 159 | + } | |
| 160 | + } | |
| 161 | + | |
| 162 | + wp_send_json_success(array( | |
| 163 | + 'keys' => $keys, | |
| 164 | + 'scanned' => is_array($rows) ? count($rows) : 0, | |
| 165 | + )); | |
| 166 | +} | |
| 167 | + | |
| 168 | +/** | |
| 63 | 169 | * Test connection to a Custom (OpenAI-compatible) provider by hitting its /models endpoint |
| 64 | 170 | * with whichever auth scheme the user configured. Reports model count or a clean error. |
| 65 | 171 | */ |
| 66 | 172 | public function mxchat_test_custom_provider_callback() { |
| @@ -281,8 +387,113 @@ | ||
| 281 | 387 | } |
| 282 | 388 | |
| 283 | 389 | // Handle special cases |
| 284 | 390 | switch ($field_name) { |
| 391 | + // Editor Assistant enable toggle (plan-8cb0cb). STANDALONE option — NOT part | |
| 392 | + // of mxchat_options, so it skips the mxchat_sanitize strip-trap entirely. Save | |
| 393 | + // it directly and short-circuit (mirrors the mxchat_transcripts_options pattern | |
| 394 | + // below); never falls through to the generic mxchat_options save. Default OFF. | |
| 395 | + case 'mxchat_editor_assistant_enabled': | |
| 396 | + $ea_value = ($value === 'on' || $value === '1') ? 'on' : 'off'; | |
| 397 | + update_option('mxchat_editor_assistant_enabled', $ea_value); | |
| 398 | + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]); | |
| 399 | + return; | |
| 400 | + | |
| 401 | + // Smart asset loading toggle (plan-915355). STANDALONE option, same | |
| 402 | + // reasoning as the Editor Assistant case above — saved directly and | |
| 403 | + // short-circuited so it never touches mxchat_options / mxchat_sanitize. | |
| 404 | + // Default OFF (opt-in performance optimization). | |
| 405 | + case 'mxchat_smart_asset_loading': | |
| 406 | + $sal_value = ($value === 'on' || $value === '1') ? 'on' : 'off'; | |
| 407 | + update_option('mxchat_smart_asset_loading', $sal_value); | |
| 408 | + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]); | |
| 409 | + return; | |
| 410 | + | |
| 411 | + // Hybrid keyword boost toggle (plan-38ffa1). STANDALONE option, same | |
| 412 | + // pattern. Enabling runs capability detection HERE, at admin-save time — | |
| 413 | + // building the FULLTEXT index during a visitor's chat request is not | |
| 414 | + // acceptable, and detection is a one-time cost the admin can wait on. | |
| 415 | + case 'mxchat_hybrid_keyword_toggle': | |
| 416 | + $hkb_value = ($value === 'on' || $value === '1') ? 'on' : 'off'; | |
| 417 | + update_option('mxchat_hybrid_keyword_toggle', $hkb_value); | |
| 418 | + if ($hkb_value === 'on') { | |
| 419 | + MxChat_Utils::mxchat_hybrid_detect_capability(true); | |
| 420 | + } | |
| 421 | + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]); | |
| 422 | + return; | |
| 423 | + | |
| 424 | + // ACF→PDF import-time extraction (plan 11720c). STANDALONE option, same | |
| 425 | + // pattern. Moved from a per-import modal checkbox to an install-level | |
| 426 | + // setting on Knowledge → ACF Fields. Stored '1'/'0' to match the | |
| 427 | + // knowledge page's sibling toggles. Default OFF. | |
| 428 | + case 'mxchat_acf_pdf_extraction': | |
| 429 | + $apx_value = ($value === 'on' || $value === '1') ? '1' : '0'; | |
| 430 | + update_option('mxchat_acf_pdf_extraction', $apx_value); | |
| 431 | + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]); | |
| 432 | + return; | |
| 433 | + | |
| 434 | + // In-chat YouTube card: master switch + its own confidence floor | |
| 435 | + // (plan f52492). STANDALONE options, same pattern as the cases above. | |
| 436 | + // Default ON — the card already ships, so this is an opt-OUT. | |
| 437 | + case 'mxchat_video_embed_enabled': | |
| 438 | + $vce_value = ($value === 'on' || $value === '1') ? 'on' : 'off'; | |
| 439 | + update_option('mxchat_video_embed_enabled', $vce_value); | |
| 440 | + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]); | |
| 441 | + return; | |
| 442 | + | |
| 443 | + // Clamped to the same 20-95 the field advertises. An out-of-range or | |
| 444 | + // non-numeric POST is corrected rather than refused, and the corrected | |
| 445 | + // value is echoed back so the field can reconcile — a silently stored | |
| 446 | + // 0 here would put a video on every answer, which is the bug. | |
| 447 | + case 'mxchat_video_embed_threshold': | |
| 448 | + $vct_value = is_numeric($value) | |
| 449 | + ? (int) $value | |
| 450 | + : MXCHAT_VIDEO_EMBED_THRESHOLD_DEFAULT; | |
| 451 | + if ($vct_value < 20) { $vct_value = 20; } | |
| 452 | + if ($vct_value > 95) { $vct_value = 95; } | |
| 453 | + update_option('mxchat_video_embed_threshold', $vct_value); | |
| 454 | + wp_send_json_success([ | |
| 455 | + 'message' => esc_html__('Setting saved', 'mxchat'), | |
| 456 | + 'value' => $vct_value, | |
| 457 | + ]); | |
| 458 | + return; | |
| 459 | + | |
| 460 | + // Live-agent availability schedules (plans 8ccaa2 + 99d7a4). STANDALONE | |
| 461 | + // options, same reasoning as the Editor Assistant case above — nested | |
| 462 | + // structures that mxchat_sanitize() would strip on the next autosave of any | |
| 463 | + // other field. Each channel's value arrives as JSON from its own hidden | |
| 464 | + // input, which that channel's schedule editor keeps in sync; the class owns | |
| 465 | + // all validation. The bare legacy name is kept as a defense against a | |
| 466 | + // browser still running pre-split cached admin JS: that UI edited "both | |
| 467 | + // channels" as one, so its save writes both. | |
| 468 | + case 'live_agent_schedule_slack': | |
| 469 | + case 'live_agent_schedule_telegram': | |
| 470 | + case 'live_agent_schedule_webhook': | |
| 471 | + case 'live_agent_schedule': | |
| 472 | + if (!class_exists('MxChat_Live_Agent_Schedule')) { | |
| 473 | + wp_send_json_error(['message' => esc_html__('Schedule unavailable', 'mxchat')]); | |
| 474 | + return; | |
| 475 | + } | |
| 476 | + $decoded = json_decode($value, true); | |
| 477 | + if (!is_array($decoded)) { | |
| 478 | + wp_send_json_error(['message' => esc_html__('Invalid schedule', 'mxchat')]); | |
| 479 | + return; | |
| 480 | + } | |
| 481 | + $channels = ($field_name === 'live_agent_schedule') | |
| 482 | + ? array('slack', 'telegram') | |
| 483 | + : array(substr($field_name, strlen('live_agent_schedule_'))); | |
| 484 | + $saved_schedule = null; | |
| 485 | + foreach ($channels as $schedule_channel) { | |
| 486 | + $saved_schedule = MxChat_Live_Agent_Schedule::save($schedule_channel, $decoded); | |
| 487 | + } | |
| 488 | + // Echo the normalized result so the editor can reconcile if it ever | |
| 489 | + // disagrees with the server (e.g. a time the class rejected). | |
| 490 | + wp_send_json_success([ | |
| 491 | + 'message' => esc_html__('Setting saved', 'mxchat'), | |
| 492 | + 'schedule' => $saved_schedule, | |
| 493 | + ]); | |
| 494 | + return; | |
| 495 | + | |
| 285 | 496 | case 'model': |
| 286 | 497 | //error_log('MXChat Save: Processing model selection'); |
| 287 | 498 | //error_log('MXChat Save: Model value received: ' . $value); |
| 288 | 499 | //error_log('MXChat Save: Value type: ' . gettype($value)); |
| @@ -369,8 +580,13 @@ | ||
| 369 | 580 | case 'name_field_placeholder': |
| 370 | 581 | //error_log('MXChat Save: Processing name_field_placeholder'); |
| 371 | 582 | $options[$field_name] = sanitize_text_field($value); |
| 372 | 583 | break; |
| 584 | + case 'consent_checkbox_label': | |
| 585 | + // b062c4 — same allowlist as the options.php save path and the | |
| 586 | + // widget render, so the stored label always equals the shown label. | |
| 587 | + $options[$field_name] = MxChat_Utils::sanitize_consent_label($value); | |
| 588 | + break; | |
| 373 | 589 | case 'similarity_threshold': |
| 374 | 590 | //error_log('MXChat Save: Processing similarity_threshold'); |
| 375 | 591 | // Validate and save - enforce min 20, max 85 |
| 376 | 592 | $threshold = intval($value); |
| @@ -397,8 +613,49 @@ | ||
| 397 | 613 | //error_log('MXChat Save: Processing live_agent_status'); |
| 398 | 614 | // Set the new value |
| 399 | 615 | $options[$field_name] = ($value === 'on') ? 'on' : 'off'; |
| 400 | 616 | break; |
| 617 | + // Shared handoff channel (plan 1a2666): re-probe the channel's privacy | |
| 618 | + // at configuration time so the settings screen can warn about private | |
| 619 | + // channels (their inbound events arrive as message.groups, which the | |
| 620 | + // documented app setup never subscribes to). Only id-shaped values can | |
| 621 | + // be checked before the first handoff resolves a #name — the handoff | |
| 622 | + // path probes those when it caches the resolved id. | |
| 623 | + case 'live_agent_shared_channel': | |
| 624 | + $options[$field_name] = sanitize_text_field($value); | |
| 625 | + delete_option('mxchat_slack_shared_channel_privacy'); | |
| 626 | + $shared_channel_target = ltrim(trim((string) $options[$field_name]), '#'); | |
| 627 | + if ($shared_channel_target !== '' && preg_match('/^[CG][A-Z0-9]{6,}$/', $shared_channel_target)) { | |
| 628 | + if (!class_exists('MxChat_Integrator')) { | |
| 629 | + require_once plugin_dir_path(dirname(__FILE__)) . 'includes/class-mxchat-integrator.php'; | |
| 630 | + } | |
| 631 | + MxChat_Integrator::mxchat_probe_slack_channel_privacy( | |
| 632 | + $options['live_agent_bot_token'] ?? '', | |
| 633 | + $shared_channel_target, | |
| 634 | + trim((string) $options[$field_name]) | |
| 635 | + ); | |
| 636 | + } | |
| 637 | + break; | |
| 638 | + // Webhook handoff destination (plan d88e22). Status normalized like the | |
| 639 | + // other channel toggles; the URL is refused outright when it isn't | |
| 640 | + // https so the admin hears about it at save time instead of the | |
| 641 | + // handoff silently never firing. | |
| 642 | + case 'webhook_handoff_status': | |
| 643 | + $options[$field_name] = ($value === 'on') ? 'on' : 'off'; | |
| 644 | + break; | |
| 645 | + case 'webhook_handoff_url': | |
| 646 | + $wh_url = trim((string) $value); | |
| 647 | + if ($wh_url === '') { | |
| 648 | + $options[$field_name] = ''; | |
| 649 | + break; | |
| 650 | + } | |
| 651 | + $wh_clean = esc_url_raw($wh_url, array('https')); | |
| 652 | + if ($wh_clean === '' || stripos($wh_clean, 'https://') !== 0) { | |
| 653 | + wp_send_json_error(['message' => esc_html__('Webhook URL must start with https://', 'mxchat')]); | |
| 654 | + return; | |
| 655 | + } | |
| 656 | + $options[$field_name] = $wh_clean; | |
| 657 | + break; | |
| 401 | 658 | case 'enable_web_search': |
| 402 | 659 | //error_log('MXChat Save: Processing enable_web_search'); |
| 403 | 660 | $options[$field_name] = ($value === 'on') ? 'on' : 'off'; |
| 404 | 661 | break; |
| @@ -446,9 +703,16 @@ | ||
| 446 | 703 | $transcripts_options = array(); |
| 447 | 704 | } |
| 448 | 705 | |
| 449 | 706 | // Handle checkbox values (convert 'on'/'off' to 1/0) |
| 450 | - if ($value === 'on' || $value === '1') { | |
| 707 | + if ($field_name === 'mxchat_retention_days') { | |
| 708 | + // Number field, NOT a checkbox — without this branch a | |
| 709 | + // value of '1' would hit the 'on'/'1' coercion below | |
| 710 | + // (harmlessly) but nothing would clamp: this direct-DB | |
| 711 | + // path bypasses the registered sanitiser and its | |
| 712 | + // 0-3650 clamp entirely (plan-3c3338). | |
| 713 | + $transcripts_options[$field_name] = max(0, min(3650, (int) $value)); | |
| 714 | + } else if ($value === 'on' || $value === '1') { | |
| 451 | 715 | $transcripts_options[$field_name] = 1; |
| 452 | 716 | } else if ($value === 'off' || $value === '0' || $value === '') { |
| 453 | 717 | $transcripts_options[$field_name] = 0; |
| 454 | 718 | } else { |
| @@ -453,9 +717,20 @@ | ||
| 453 | 717 | $transcripts_options[$field_name] = 0; |
| 454 | 718 | } else { |
| 455 | 719 | // For text/select fields, sanitize appropriately |
| 456 | 720 | if ($field_name === 'mxchat_notification_email') { |
| 457 | - $transcripts_options[$field_name] = sanitize_email($value); | |
| 721 | + // sanitize_email() alone CANNOT validate this field: given | |
| 722 | + // "a@x.com, b@y.com" it returns the single concatenated | |
| 723 | + // address "a@x.comby.com", which is_email() then accepts. | |
| 724 | + // That is how two addresses used to be stored as one dead | |
| 725 | + // one, silently. MxChat_Utils validates the raw parts first | |
| 726 | + // and refuses the whole list if any of them is bad. | |
| 727 | + $parsed = MxChat_Utils::parse_notification_emails($value); | |
| 728 | + if ($parsed['error'] !== '') { | |
| 729 | + // Reject: the previously stored value stays untouched. | |
| 730 | + wp_send_json_error(array('message' => $parsed['error'])); | |
| 731 | + } | |
| 732 | + $transcripts_options[$field_name] = implode(', ', $parsed['emails']); | |
| 458 | 733 | } else { |
| 459 | 734 | $transcripts_options[$field_name] = sanitize_text_field($value); |
| 460 | 735 | } |
| 461 | 736 | } |
| @@ -632,8 +907,10 @@ | ||
| 632 | 907 | 'contextual_awareness_toggle', |
| 633 | 908 | 'citation_links_toggle', |
| 634 | 909 | 'enable_email_block', |
| 635 | 910 | 'enable_name_field', |
| 911 | + 'enable_consent_checkbox', | |
| 912 | + 'consent_checkbox_required', | |
| 636 | 913 | 'custom_provider_for_embeddings', |
| 637 | 914 | 'custom_provider_for_images', |
| 638 | 915 | 'print_button_enabled', |
| 639 | 916 | 'reset_chat_enabled' |
| @@ -780,8 +1057,14 @@ | ||
| 780 | 1057 | if ($field_name === 'mxchat_pinecone_host') { |
| 781 | 1058 | $new_value = str_replace(['https://', 'http://'], '', $new_value); |
| 782 | 1059 | } |
| 783 | 1060 | break; |
| 1061 | + case 'mxchat_pinecone_top_k': | |
| 1062 | + // d0cae1: out-of-range and junk normalize to the default 50 — | |
| 1063 | + // same clamp the read site applies. | |
| 1064 | + $top_k = absint($value); | |
| 1065 | + $new_value = (string) (($top_k >= 1 && $top_k <= 1000) ? $top_k : 50); | |
| 1066 | + break; | |
| 784 | 1067 | default: |
| 785 | 1068 | wp_send_json_error(['message' => esc_html__('Unknown Pinecone field', 'mxchat')]); |
| 786 | 1069 | } |
| 787 | 1070 | |
| @@ -811,14 +1094,16 @@ | ||
| 811 | 1094 | ); |
| 812 | 1095 | //error_log('[MXCHAT-PROMPTS] Updated existing option, result: ' . ($save_result !== false ? 'SUCCESS' : 'FAILED')); |
| 813 | 1096 | } else { |
| 814 | 1097 | // Insert new option |
| 1098 | + // Credential option — must NOT autoload (holds the Pinecone secret; | |
| 1099 | + // autoloaded rows are read into memory on every request). | |
| 815 | 1100 | $save_result = $wpdb->insert( |
| 816 | 1101 | $wpdb->options, |
| 817 | 1102 | array( |
| 818 | 1103 | 'option_name' => 'mxchat_pinecone_addon_options', |
| 819 | 1104 | 'option_value' => $serialized_options, |
| 820 | - 'autoload' => 'yes' | |
| 1105 | + 'autoload' => 'off' | |
| 821 | 1106 | ), |
| 822 | 1107 | array('%s', '%s', '%s') |
| 823 | 1108 | ); |
| 824 | 1109 | //error_log('[MXCHAT-PROMPTS] Inserted new option, result: ' . ($save_result !== false ? 'SUCCESS' : 'FAILED')); |
| @@ -936,10 +1221,18 @@ | ||
| 936 | 1221 | } |
| 937 | 1222 | |
| 938 | 1223 | // Handle ACF field exclusion toggles |
| 939 | 1224 | if (strpos($name, 'mxchat_acf_field_') === 0) { |
| 940 | - // Extract field name from the input name (e.g., mxchat_acf_field_private_notes -> private_notes) | |
| 941 | - $field_name = str_replace('mxchat_acf_field_', '', $name); | |
| 1225 | + // The identifier after the prefix is the ACF field KEY (unique per | |
| 1226 | + // field), not the field name — names are shared across groups and | |
| 1227 | + // collide (plan 30e81f). Reject anything that isn't key-shaped so a | |
| 1228 | + // stale pre-3.2.20 page (or its exit beacon) posting a bare name | |
| 1229 | + // can't write junk into the key-based list. | |
| 1230 | + $field_key = str_replace('mxchat_acf_field_', '', $name); | |
| 1231 | + if (!preg_match('/^field_[A-Za-z0-9_\-]+$/', $field_key)) { | |
| 1232 | + wp_send_json_error(['message' => esc_html__('Invalid ACF field identifier', 'mxchat')]); | |
| 1233 | + return; | |
| 1234 | + } | |
| 942 | 1235 | $is_enabled = ($value === 'on' || $value === '1'); |
| 943 | 1236 | |
| 944 | 1237 | // Get current excluded fields |
| 945 | 1238 | $excluded_fields = get_option('mxchat_acf_excluded_fields', array()); |
| @@ -948,13 +1241,19 @@ | ||
| 948 | 1241 | } |
| 949 | 1242 | |
| 950 | 1243 | if ($is_enabled) { |
| 951 | 1244 | // Remove from exclusion list (field should be included) |
| 952 | - $excluded_fields = array_values(array_diff($excluded_fields, array($field_name))); | |
| 1245 | + $excluded_fields = array_values(array_diff($excluded_fields, array($field_key))); | |
| 1246 | + // Lazy legacy-name conversion: if this field's NAME is still | |
| 1247 | + // stored (its group was inactive when the 30e81f migration | |
| 1248 | + // ran), including this one field must not silently include | |
| 1249 | + // its same-named twins — swap the name entry for the keys of | |
| 1250 | + // every OTHER field currently wearing that name. | |
| 1251 | + $excluded_fields = $this->mxchat_expand_legacy_acf_name_entry($excluded_fields, $field_key); | |
| 953 | 1252 | } else { |
| 954 | 1253 | // Add to exclusion list (field should be excluded) |
| 955 | - if (!in_array($field_name, $excluded_fields)) { | |
| 956 | - $excluded_fields[] = $field_name; | |
| 1254 | + if (!in_array($field_key, $excluded_fields, true)) { | |
| 1255 | + $excluded_fields[] = $field_key; | |
| 957 | 1256 | } |
| 958 | 1257 | } |
| 959 | 1258 | |
| 960 | 1259 | $updated = update_option('mxchat_acf_excluded_fields', $excluded_fields); |
| @@ -961,10 +1260,10 @@ | ||
| 961 | 1260 | |
| 962 | 1261 | if ($updated || true) { // Always report success since the state may already be correct |
| 963 | 1262 | wp_send_json_success([ |
| 964 | 1263 | 'message' => $is_enabled |
| 965 | - ? sprintf(esc_html__('Field "%s" will be included in imports', 'mxchat'), $field_name) | |
| 966 | - : sprintf(esc_html__('Field "%s" will be excluded from imports', 'mxchat'), $field_name) | |
| 1264 | + ? esc_html__('Field will be included in imports', 'mxchat') | |
| 1265 | + : esc_html__('Field will be excluded from imports', 'mxchat') | |
| 967 | 1266 | ]); |
| 968 | 1267 | } else { |
| 969 | 1268 | wp_send_json_error(['message' => esc_html__('Failed to save ACF field setting', 'mxchat')]); |
| 970 | 1269 | } |
| @@ -984,12 +1283,12 @@ | ||
| 984 | 1283 | } |
| 985 | 1284 | return; |
| 986 | 1285 | } |
| 987 | 1286 | |
| 988 | - // Handle other prompts options | |
| 1287 | + // Handle other prompts options (autoload false — can hold the Pinecone secret) | |
| 989 | 1288 | $options = get_option('mxchat_prompts_options', []); |
| 990 | 1289 | $options[$name] = $value; |
| 991 | - $updated = update_option('mxchat_prompts_options', $options); | |
| 1290 | + $updated = update_option('mxchat_prompts_options', $options, false); | |
| 992 | 1291 | |
| 993 | 1292 | if ($updated) { |
| 994 | 1293 | wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]); |
| 995 | 1294 | } else { |
| @@ -996,10 +1295,130 @@ | ||
| 996 | 1295 | wp_send_json_error(['message' => esc_html__('No changes detected', 'mxchat')]); |
| 997 | 1296 | } |
| 998 | 1297 | } |
| 999 | 1298 | |
| 1299 | + /** | |
| 1300 | + * If the field behind $included_key still has its NAME stored in the | |
| 1301 | + * exclusion list (a legacy entry the 30e81f migration could not resolve | |
| 1302 | + * because the group was inactive), replace that name with the keys of | |
| 1303 | + * every OTHER current field wearing it. Including one field must never | |
| 1304 | + * silently include its same-named twins — that would be the original | |
| 1305 | + * collision bug in reverse, in the unsafe (privacy-losing) direction. | |
| 1306 | + */ | |
| 1307 | + private function mxchat_expand_legacy_acf_name_entry($excluded_fields, $included_key) { | |
| 1308 | + if (!function_exists('acf_get_field')) { | |
| 1309 | + return $excluded_fields; | |
| 1310 | + } | |
| 1311 | + $field = acf_get_field($included_key); | |
| 1312 | + if (!$field || empty($field['name'])) { | |
| 1313 | + return $excluded_fields; | |
| 1314 | + } | |
| 1315 | + $field_name = $field['name']; | |
| 1316 | + if (!in_array($field_name, $excluded_fields, true)) { | |
| 1317 | + return $excluded_fields; | |
| 1318 | + } | |
| 1319 | + $excluded_fields = array_values(array_diff($excluded_fields, array($field_name))); | |
| 1320 | + foreach ($this->mxchat_acf_keys_for_name($field_name) as $twin_key) { | |
| 1321 | + if ($twin_key !== $included_key && !in_array($twin_key, $excluded_fields, true)) { | |
| 1322 | + $excluded_fields[] = $twin_key; | |
| 1323 | + } | |
| 1324 | + } | |
| 1325 | + return $excluded_fields; | |
| 1326 | + } | |
| 1000 | 1327 | |
| 1001 | 1328 | /** |
| 1329 | + * Keys of every currently-registered top-level ACF field with this name. | |
| 1330 | + */ | |
| 1331 | + private function mxchat_acf_keys_for_name($field_name) { | |
| 1332 | + $keys = array(); | |
| 1333 | + if (!function_exists('acf_get_field_groups') || !function_exists('acf_get_fields')) { | |
| 1334 | + return $keys; | |
| 1335 | + } | |
| 1336 | + foreach (acf_get_field_groups() as $group) { | |
| 1337 | + $group_fields = acf_get_fields($group['key']); | |
| 1338 | + if (empty($group_fields)) { | |
| 1339 | + continue; | |
| 1340 | + } | |
| 1341 | + foreach ($group_fields as $field) { | |
| 1342 | + if (isset($field['name'], $field['key']) && $field['name'] === $field_name) { | |
| 1343 | + $keys[] = $field['key']; | |
| 1344 | + } | |
| 1345 | + } | |
| 1346 | + } | |
| 1347 | + return $keys; | |
| 1348 | + } | |
| 1349 | + | |
| 1350 | + /** | |
| 1351 | + * Group-level ACF toggle (plan bf57e0): sets every field in one ACF field | |
| 1352 | + * group included or excluded in a SINGLE option write. The client must | |
| 1353 | + * never loop the per-field endpoint for this — get_option → modify → | |
| 1354 | + * update_option once per field from twenty concurrent requests is a | |
| 1355 | + * lost-update race that silently drops most of the group. | |
| 1356 | + */ | |
| 1357 | + public function mxchat_acf_toggle_group_callback() { | |
| 1358 | + check_ajax_referer('mxchat_prompts_setting_nonce'); | |
| 1359 | + | |
| 1360 | + if (!current_user_can('manage_options')) { | |
| 1361 | + wp_send_json_error(['message' => esc_html__('Insufficient permissions', 'mxchat')], 403); | |
| 1362 | + return; | |
| 1363 | + } | |
| 1364 | + | |
| 1365 | + if (!function_exists('acf_get_fields')) { | |
| 1366 | + wp_send_json_error(['message' => esc_html__('ACF is not active', 'mxchat')]); | |
| 1367 | + return; | |
| 1368 | + } | |
| 1369 | + | |
| 1370 | + $group_key = isset($_POST['group_key']) ? sanitize_text_field(wp_unslash($_POST['group_key'])) : ''; | |
| 1371 | + if (!preg_match('/^group_[A-Za-z0-9_\-]+$/', $group_key)) { | |
| 1372 | + wp_send_json_error(['message' => esc_html__('Invalid ACF group identifier', 'mxchat')]); | |
| 1373 | + return; | |
| 1374 | + } | |
| 1375 | + $state = isset($_POST['state']) ? sanitize_text_field(wp_unslash($_POST['state'])) : ''; | |
| 1376 | + $include = ($state === 'on' || $state === '1'); | |
| 1377 | + | |
| 1378 | + // Resolve the group's fields SERVER-side — a client-supplied key list | |
| 1379 | + // is not trusted. This is the same call the settings UI lists from, | |
| 1380 | + // so the toggle covers exactly the rendered set (top-level fields). | |
| 1381 | + $group_fields = acf_get_fields($group_key); | |
| 1382 | + if (empty($group_fields)) { | |
| 1383 | + wp_send_json_error(['message' => esc_html__('No fields found for this group', 'mxchat')]); | |
| 1384 | + return; | |
| 1385 | + } | |
| 1386 | + | |
| 1387 | + $excluded_fields = get_option('mxchat_acf_excluded_fields', array()); | |
| 1388 | + if (!is_array($excluded_fields)) { | |
| 1389 | + $excluded_fields = array(); | |
| 1390 | + } | |
| 1391 | + | |
| 1392 | + $touched = array(); | |
| 1393 | + foreach ($group_fields as $field) { | |
| 1394 | + if (empty($field['key'])) { | |
| 1395 | + continue; | |
| 1396 | + } | |
| 1397 | + if ($include) { | |
| 1398 | + $excluded_fields = array_values(array_diff($excluded_fields, array($field['key']))); | |
| 1399 | + $excluded_fields = $this->mxchat_expand_legacy_acf_name_entry($excluded_fields, $field['key']); | |
| 1400 | + } elseif (!in_array($field['key'], $excluded_fields, true)) { | |
| 1401 | + $excluded_fields[] = $field['key']; | |
| 1402 | + } | |
| 1403 | + $touched[] = array( | |
| 1404 | + 'name' => 'mxchat_acf_field_' . $field['key'], | |
| 1405 | + 'value' => $include ? 'on' : 'off', | |
| 1406 | + ); | |
| 1407 | + } | |
| 1408 | + | |
| 1409 | + // The one write — the whole point of this endpoint. | |
| 1410 | + update_option('mxchat_acf_excluded_fields', array_values($excluded_fields)); | |
| 1411 | + | |
| 1412 | + wp_send_json_success([ | |
| 1413 | + 'message' => $include | |
| 1414 | + ? esc_html__('All fields in this group will be included in imports', 'mxchat') | |
| 1415 | + : esc_html__('All fields in this group will be excluded from imports', 'mxchat'), | |
| 1416 | + 'fields' => $touched, | |
| 1417 | + ]); | |
| 1418 | + } | |
| 1419 | + | |
| 1420 | + /** | |
| 1002 | 1421 | * Handles AJAX request for Pinecone settings migration |
| 1003 | 1422 | */ |
| 1004 | 1423 | public function ajax_migrate_pinecone_settings() { |
| 1005 | 1424 | // Verify nonce |
| @@ -1035,9 +1454,9 @@ | ||
| 1035 | 1454 | 'mxchat_pinecone_index' => sanitize_text_field($old_options['mxchat_pinecone_index'] ?? ''), |
| 1036 | 1455 | 'mxchat_pinecone_environment' => sanitize_text_field($old_options['mxchat_pinecone_environment'] ?? '') |
| 1037 | 1456 | ); |
| 1038 | 1457 | |
| 1039 | - update_option('mxchat_pinecone_addon_options', $migrated_options); | |
| 1458 | + update_option('mxchat_pinecone_addon_options', $migrated_options, false); | |
| 1040 | 1459 | |
| 1041 | 1460 | wp_send_json_success(array( |
| 1042 | 1461 | 'migrated' => true, |
| 1043 | 1462 | 'message' => 'Settings migrated successfully from Pinecone add-on' |
| @@ -1196,9 +1615,17 @@ | ||
| 1196 | 1615 | //error_log('MxChat deactivate: Nonce check failed'); |
| 1197 | 1616 | wp_send_json_error('Security check failed.'); |
| 1198 | 1617 | return; |
| 1199 | 1618 | } |
| 1200 | - | |
| 1619 | + | |
| 1620 | + // plan-mxchat-20260731-c63fb6 — nonce is not authorization. Without this, | |
| 1621 | + // any authenticated user holding the nonce could revoke the site's PRO | |
| 1622 | + // licence. Every sibling handler in this file already checks. | |
| 1623 | + if (!current_user_can('manage_options')) { | |
| 1624 | + wp_send_json_error(esc_html__('Unauthorized', 'mxchat'), 403); | |
| 1625 | + return; | |
| 1626 | + } | |
| 1627 | + | |
| 1201 | 1628 | //error_log('MxChat deactivate: Nonce check passed'); |
| 1202 | 1629 | |
| 1203 | 1630 | $license_key = get_option('mxchat_activation_key'); |
| 1204 | 1631 | $email = get_option('mxchat_pro_email'); |