PluginProbe
MxChat – AI Chatbot & Content Generation for WordPress / trunk
MxChat – AI Chatbot & Content Generation for WordPress vtrunk
3.2.21 3.2.20 3.2.19 3.2.18 3.2.17 3.2.16 3.2.15 3.2.14 3.2.12 3.2.13 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 3.2.6 3.2.5 3.2.4 3.2.3 3.2.2 3.2.1 2.0.3 2.0.4 2.0.5 2.0.6 All 152 releases
← All changes | admin/class-ajax-handler.php +336 -14 3.2.13trunk View file →
@@ -27,8 +27,9 @@
27 27 private function mxchat_init_ajax_hooks() {
28 28 // Settings AJAX
29 29 add_action('wp_ajax_mxchat_save_setting', array($this, 'mxchat_save_setting_callback'));
30 30 add_action('wp_ajax_mxchat_save_prompts_setting', array($this, 'mxchat_save_prompts_setting_callback'));
31 + add_action('wp_ajax_mxchat_acf_toggle_group', array($this, 'mxchat_acf_toggle_group_callback'));
31 32 add_action('wp_ajax_migrate_pinecone_settings', array($this, 'ajax_migrate_pinecone_settings'));
32 33
33 34 // License AJAX
34 35 add_action('wp_ajax_mxchat_handle_activate_license', array($this, 'mxchat_handle_activate_license'));
@@ -386,8 +387,113 @@
386 387 }
387 388
388 389 // Handle special cases
389 390 switch ($field_name) {
391 + // Editor Assistant enable toggle (plan-8cb0cb). STANDALONE option — NOT part
392 + // of mxchat_options, so it skips the mxchat_sanitize strip-trap entirely. Save
393 + // it directly and short-circuit (mirrors the mxchat_transcripts_options pattern
394 + // below); never falls through to the generic mxchat_options save. Default OFF.
395 + case 'mxchat_editor_assistant_enabled':
396 + $ea_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
397 + update_option('mxchat_editor_assistant_enabled', $ea_value);
398 + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
399 + return;
400 +
401 + // Smart asset loading toggle (plan-915355). STANDALONE option, same
402 + // reasoning as the Editor Assistant case above — saved directly and
403 + // short-circuited so it never touches mxchat_options / mxchat_sanitize.
404 + // Default OFF (opt-in performance optimization).
405 + case 'mxchat_smart_asset_loading':
406 + $sal_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
407 + update_option('mxchat_smart_asset_loading', $sal_value);
408 + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
409 + return;
410 +
411 + // Hybrid keyword boost toggle (plan-38ffa1). STANDALONE option, same
412 + // pattern. Enabling runs capability detection HERE, at admin-save time —
413 + // building the FULLTEXT index during a visitor's chat request is not
414 + // acceptable, and detection is a one-time cost the admin can wait on.
415 + case 'mxchat_hybrid_keyword_toggle':
416 + $hkb_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
417 + update_option('mxchat_hybrid_keyword_toggle', $hkb_value);
418 + if ($hkb_value === 'on') {
419 + MxChat_Utils::mxchat_hybrid_detect_capability(true);
420 + }
421 + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
422 + return;
423 +
424 + // ACF→PDF import-time extraction (plan 11720c). STANDALONE option, same
425 + // pattern. Moved from a per-import modal checkbox to an install-level
426 + // setting on Knowledge → ACF Fields. Stored '1'/'0' to match the
427 + // knowledge page's sibling toggles. Default OFF.
428 + case 'mxchat_acf_pdf_extraction':
429 + $apx_value = ($value === 'on' || $value === '1') ? '1' : '0';
430 + update_option('mxchat_acf_pdf_extraction', $apx_value);
431 + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
432 + return;
433 +
434 + // In-chat YouTube card: master switch + its own confidence floor
435 + // (plan f52492). STANDALONE options, same pattern as the cases above.
436 + // Default ON — the card already ships, so this is an opt-OUT.
437 + case 'mxchat_video_embed_enabled':
438 + $vce_value = ($value === 'on' || $value === '1') ? 'on' : 'off';
439 + update_option('mxchat_video_embed_enabled', $vce_value);
440 + wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
441 + return;
442 +
443 + // Clamped to the same 20-95 the field advertises. An out-of-range or
444 + // non-numeric POST is corrected rather than refused, and the corrected
445 + // value is echoed back so the field can reconcile — a silently stored
446 + // 0 here would put a video on every answer, which is the bug.
447 + case 'mxchat_video_embed_threshold':
448 + $vct_value = is_numeric($value)
449 + ? (int) $value
450 + : MXCHAT_VIDEO_EMBED_THRESHOLD_DEFAULT;
451 + if ($vct_value < 20) { $vct_value = 20; }
452 + if ($vct_value > 95) { $vct_value = 95; }
453 + update_option('mxchat_video_embed_threshold', $vct_value);
454 + wp_send_json_success([
455 + 'message' => esc_html__('Setting saved', 'mxchat'),
456 + 'value' => $vct_value,
457 + ]);
458 + return;
459 +
460 + // Live-agent availability schedules (plans 8ccaa2 + 99d7a4). STANDALONE
461 + // options, same reasoning as the Editor Assistant case above — nested
462 + // structures that mxchat_sanitize() would strip on the next autosave of any
463 + // other field. Each channel's value arrives as JSON from its own hidden
464 + // input, which that channel's schedule editor keeps in sync; the class owns
465 + // all validation. The bare legacy name is kept as a defense against a
466 + // browser still running pre-split cached admin JS: that UI edited "both
467 + // channels" as one, so its save writes both.
468 + case 'live_agent_schedule_slack':
469 + case 'live_agent_schedule_telegram':
470 + case 'live_agent_schedule_webhook':
471 + case 'live_agent_schedule':
472 + if (!class_exists('MxChat_Live_Agent_Schedule')) {
473 + wp_send_json_error(['message' => esc_html__('Schedule unavailable', 'mxchat')]);
474 + return;
475 + }
476 + $decoded = json_decode($value, true);
477 + if (!is_array($decoded)) {
478 + wp_send_json_error(['message' => esc_html__('Invalid schedule', 'mxchat')]);
479 + return;
480 + }
481 + $channels = ($field_name === 'live_agent_schedule')
482 + ? array('slack', 'telegram')
483 + : array(substr($field_name, strlen('live_agent_schedule_')));
484 + $saved_schedule = null;
485 + foreach ($channels as $schedule_channel) {
486 + $saved_schedule = MxChat_Live_Agent_Schedule::save($schedule_channel, $decoded);
487 + }
488 + // Echo the normalized result so the editor can reconcile if it ever
489 + // disagrees with the server (e.g. a time the class rejected).
490 + wp_send_json_success([
491 + 'message' => esc_html__('Setting saved', 'mxchat'),
492 + 'schedule' => $saved_schedule,
493 + ]);
494 + return;
495 +
390 496 case 'model':
391 497 //error_log('MXChat Save: Processing model selection');
392 498 //error_log('MXChat Save: Model value received: ' . $value);
393 499 //error_log('MXChat Save: Value type: ' . gettype($value));
@@ -474,8 +580,13 @@
474 580 case 'name_field_placeholder':
475 581 //error_log('MXChat Save: Processing name_field_placeholder');
476 582 $options[$field_name] = sanitize_text_field($value);
477 583 break;
584 + case 'consent_checkbox_label':
585 + // b062c4 — same allowlist as the options.php save path and the
586 + // widget render, so the stored label always equals the shown label.
587 + $options[$field_name] = MxChat_Utils::sanitize_consent_label($value);
588 + break;
478 589 case 'similarity_threshold':
479 590 //error_log('MXChat Save: Processing similarity_threshold');
480 591 // Validate and save - enforce min 20, max 85
481 592 $threshold = intval($value);
@@ -502,8 +613,49 @@
502 613 //error_log('MXChat Save: Processing live_agent_status');
503 614 // Set the new value
504 615 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
505 616 break;
617 + // Shared handoff channel (plan 1a2666): re-probe the channel's privacy
618 + // at configuration time so the settings screen can warn about private
619 + // channels (their inbound events arrive as message.groups, which the
620 + // documented app setup never subscribes to). Only id-shaped values can
621 + // be checked before the first handoff resolves a #name — the handoff
622 + // path probes those when it caches the resolved id.
623 + case 'live_agent_shared_channel':
624 + $options[$field_name] = sanitize_text_field($value);
625 + delete_option('mxchat_slack_shared_channel_privacy');
626 + $shared_channel_target = ltrim(trim((string) $options[$field_name]), '#');
627 + if ($shared_channel_target !== '' && preg_match('/^[CG][A-Z0-9]{6,}$/', $shared_channel_target)) {
628 + if (!class_exists('MxChat_Integrator')) {
629 + require_once plugin_dir_path(dirname(__FILE__)) . 'includes/class-mxchat-integrator.php';
630 + }
631 + MxChat_Integrator::mxchat_probe_slack_channel_privacy(
632 + $options['live_agent_bot_token'] ?? '',
633 + $shared_channel_target,
634 + trim((string) $options[$field_name])
635 + );
636 + }
637 + break;
638 + // Webhook handoff destination (plan d88e22). Status normalized like the
639 + // other channel toggles; the URL is refused outright when it isn't
640 + // https so the admin hears about it at save time instead of the
641 + // handoff silently never firing.
642 + case 'webhook_handoff_status':
643 + $options[$field_name] = ($value === 'on') ? 'on' : 'off';
644 + break;
645 + case 'webhook_handoff_url':
646 + $wh_url = trim((string) $value);
647 + if ($wh_url === '') {
648 + $options[$field_name] = '';
649 + break;
650 + }
651 + $wh_clean = esc_url_raw($wh_url, array('https'));
652 + if ($wh_clean === '' || stripos($wh_clean, 'https://') !== 0) {
653 + wp_send_json_error(['message' => esc_html__('Webhook URL must start with https://', 'mxchat')]);
654 + return;
655 + }
656 + $options[$field_name] = $wh_clean;
657 + break;
506 658 case 'enable_web_search':
507 659 //error_log('MXChat Save: Processing enable_web_search');
508 660 $options[$field_name] = ($value === 'on') ? 'on' : 'off';
509 661 break;
@@ -551,9 +703,16 @@
551 703 $transcripts_options = array();
552 704 }
553 705
554 706 // Handle checkbox values (convert 'on'/'off' to 1/0)
555 - if ($value === 'on' || $value === '1') {
707 + if ($field_name === 'mxchat_retention_days') {
708 + // Number field, NOT a checkbox — without this branch a
709 + // value of '1' would hit the 'on'/'1' coercion below
710 + // (harmlessly) but nothing would clamp: this direct-DB
711 + // path bypasses the registered sanitiser and its
712 + // 0-3650 clamp entirely (plan-3c3338).
713 + $transcripts_options[$field_name] = max(0, min(3650, (int) $value));
714 + } else if ($value === 'on' || $value === '1') {
556 715 $transcripts_options[$field_name] = 1;
557 716 } else if ($value === 'off' || $value === '0' || $value === '') {
558 717 $transcripts_options[$field_name] = 0;
559 718 } else {
@@ -558,9 +717,20 @@
558 717 $transcripts_options[$field_name] = 0;
559 718 } else {
560 719 // For text/select fields, sanitize appropriately
561 720 if ($field_name === 'mxchat_notification_email') {
562 - $transcripts_options[$field_name] = sanitize_email($value);
721 + // sanitize_email() alone CANNOT validate this field: given
722 + // "a@x.com, b@y.com" it returns the single concatenated
723 + // address "a@x.comby.com", which is_email() then accepts.
724 + // That is how two addresses used to be stored as one dead
725 + // one, silently. MxChat_Utils validates the raw parts first
726 + // and refuses the whole list if any of them is bad.
727 + $parsed = MxChat_Utils::parse_notification_emails($value);
728 + if ($parsed['error'] !== '') {
729 + // Reject: the previously stored value stays untouched.
730 + wp_send_json_error(array('message' => $parsed['error']));
731 + }
732 + $transcripts_options[$field_name] = implode(', ', $parsed['emails']);
563 733 } else {
564 734 $transcripts_options[$field_name] = sanitize_text_field($value);
565 735 }
566 736 }
@@ -737,8 +907,10 @@
737 907 'contextual_awareness_toggle',
738 908 'citation_links_toggle',
739 909 'enable_email_block',
740 910 'enable_name_field',
911 + 'enable_consent_checkbox',
912 + 'consent_checkbox_required',
741 913 'custom_provider_for_embeddings',
742 914 'custom_provider_for_images',
743 915 'print_button_enabled',
744 916 'reset_chat_enabled'
@@ -885,8 +1057,14 @@
885 1057 if ($field_name === 'mxchat_pinecone_host') {
886 1058 $new_value = str_replace(['https://', 'http://'], '', $new_value);
887 1059 }
888 1060 break;
1061 + case 'mxchat_pinecone_top_k':
1062 + // d0cae1: out-of-range and junk normalize to the default 50 —
1063 + // same clamp the read site applies.
1064 + $top_k = absint($value);
1065 + $new_value = (string) (($top_k >= 1 && $top_k <= 1000) ? $top_k : 50);
1066 + break;
889 1067 default:
890 1068 wp_send_json_error(['message' => esc_html__('Unknown Pinecone field', 'mxchat')]);
891 1069 }
892 1070
@@ -916,14 +1094,16 @@
916 1094 );
917 1095 //error_log('[MXCHAT-PROMPTS] Updated existing option, result: ' . ($save_result !== false ? 'SUCCESS' : 'FAILED'));
918 1096 } else {
919 1097 // Insert new option
1098 + // Credential option — must NOT autoload (holds the Pinecone secret;
1099 + // autoloaded rows are read into memory on every request).
920 1100 $save_result = $wpdb->insert(
921 1101 $wpdb->options,
922 1102 array(
923 1103 'option_name' => 'mxchat_pinecone_addon_options',
924 1104 'option_value' => $serialized_options,
925 - 'autoload' => 'yes'
1105 + 'autoload' => 'off'
926 1106 ),
927 1107 array('%s', '%s', '%s')
928 1108 );
929 1109 //error_log('[MXCHAT-PROMPTS] Inserted new option, result: ' . ($save_result !== false ? 'SUCCESS' : 'FAILED'));
@@ -1041,10 +1221,18 @@
1041 1221 }
1042 1222
1043 1223 // Handle ACF field exclusion toggles
1044 1224 if (strpos($name, 'mxchat_acf_field_') === 0) {
1045 - // Extract field name from the input name (e.g., mxchat_acf_field_private_notes -> private_notes)
1046 - $field_name = str_replace('mxchat_acf_field_', '', $name);
1225 + // The identifier after the prefix is the ACF field KEY (unique per
1226 + // field), not the field name — names are shared across groups and
1227 + // collide (plan 30e81f). Reject anything that isn't key-shaped so a
1228 + // stale pre-3.2.20 page (or its exit beacon) posting a bare name
1229 + // can't write junk into the key-based list.
1230 + $field_key = str_replace('mxchat_acf_field_', '', $name);
1231 + if (!preg_match('/^field_[A-Za-z0-9_\-]+$/', $field_key)) {
1232 + wp_send_json_error(['message' => esc_html__('Invalid ACF field identifier', 'mxchat')]);
1233 + return;
1234 + }
1047 1235 $is_enabled = ($value === 'on' || $value === '1');
1048 1236
1049 1237 // Get current excluded fields
1050 1238 $excluded_fields = get_option('mxchat_acf_excluded_fields', array());
@@ -1053,13 +1241,19 @@
1053 1241 }
1054 1242
1055 1243 if ($is_enabled) {
1056 1244 // Remove from exclusion list (field should be included)
1057 - $excluded_fields = array_values(array_diff($excluded_fields, array($field_name)));
1245 + $excluded_fields = array_values(array_diff($excluded_fields, array($field_key)));
1246 + // Lazy legacy-name conversion: if this field's NAME is still
1247 + // stored (its group was inactive when the 30e81f migration
1248 + // ran), including this one field must not silently include
1249 + // its same-named twins — swap the name entry for the keys of
1250 + // every OTHER field currently wearing that name.
1251 + $excluded_fields = $this->mxchat_expand_legacy_acf_name_entry($excluded_fields, $field_key);
1058 1252 } else {
1059 1253 // Add to exclusion list (field should be excluded)
1060 - if (!in_array($field_name, $excluded_fields)) {
1061 - $excluded_fields[] = $field_name;
1254 + if (!in_array($field_key, $excluded_fields, true)) {
1255 + $excluded_fields[] = $field_key;
1062 1256 }
1063 1257 }
1064 1258
1065 1259 $updated = update_option('mxchat_acf_excluded_fields', $excluded_fields);
@@ -1066,10 +1260,10 @@
1066 1260
1067 1261 if ($updated || true) { // Always report success since the state may already be correct
1068 1262 wp_send_json_success([
1069 1263 'message' => $is_enabled
1070 - ? sprintf(esc_html__('Field "%s" will be included in imports', 'mxchat'), $field_name)
1071 - : sprintf(esc_html__('Field "%s" will be excluded from imports', 'mxchat'), $field_name)
1264 + ? esc_html__('Field will be included in imports', 'mxchat')
1265 + : esc_html__('Field will be excluded from imports', 'mxchat')
1072 1266 ]);
1073 1267 } else {
1074 1268 wp_send_json_error(['message' => esc_html__('Failed to save ACF field setting', 'mxchat')]);
1075 1269 }
@@ -1089,12 +1283,12 @@
1089 1283 }
1090 1284 return;
1091 1285 }
1092 1286
1093 - // Handle other prompts options
1287 + // Handle other prompts options (autoload false — can hold the Pinecone secret)
1094 1288 $options = get_option('mxchat_prompts_options', []);
1095 1289 $options[$name] = $value;
1096 - $updated = update_option('mxchat_prompts_options', $options);
1290 + $updated = update_option('mxchat_prompts_options', $options, false);
1097 1291
1098 1292 if ($updated) {
1099 1293 wp_send_json_success(['message' => esc_html__('Setting saved', 'mxchat')]);
1100 1294 } else {
@@ -1101,10 +1295,130 @@
1101 1295 wp_send_json_error(['message' => esc_html__('No changes detected', 'mxchat')]);
1102 1296 }
1103 1297 }
1104 1298
1299 + /**
1300 + * If the field behind $included_key still has its NAME stored in the
1301 + * exclusion list (a legacy entry the 30e81f migration could not resolve
1302 + * because the group was inactive), replace that name with the keys of
1303 + * every OTHER current field wearing it. Including one field must never
1304 + * silently include its same-named twins — that would be the original
1305 + * collision bug in reverse, in the unsafe (privacy-losing) direction.
1306 + */
1307 + private function mxchat_expand_legacy_acf_name_entry($excluded_fields, $included_key) {
1308 + if (!function_exists('acf_get_field')) {
1309 + return $excluded_fields;
1310 + }
1311 + $field = acf_get_field($included_key);
1312 + if (!$field || empty($field['name'])) {
1313 + return $excluded_fields;
1314 + }
1315 + $field_name = $field['name'];
1316 + if (!in_array($field_name, $excluded_fields, true)) {
1317 + return $excluded_fields;
1318 + }
1319 + $excluded_fields = array_values(array_diff($excluded_fields, array($field_name)));
1320 + foreach ($this->mxchat_acf_keys_for_name($field_name) as $twin_key) {
1321 + if ($twin_key !== $included_key && !in_array($twin_key, $excluded_fields, true)) {
1322 + $excluded_fields[] = $twin_key;
1323 + }
1324 + }
1325 + return $excluded_fields;
1326 + }
1105 1327
1106 1328 /**
1329 + * Keys of every currently-registered top-level ACF field with this name.
1330 + */
1331 + private function mxchat_acf_keys_for_name($field_name) {
1332 + $keys = array();
1333 + if (!function_exists('acf_get_field_groups') || !function_exists('acf_get_fields')) {
1334 + return $keys;
1335 + }
1336 + foreach (acf_get_field_groups() as $group) {
1337 + $group_fields = acf_get_fields($group['key']);
1338 + if (empty($group_fields)) {
1339 + continue;
1340 + }
1341 + foreach ($group_fields as $field) {
1342 + if (isset($field['name'], $field['key']) && $field['name'] === $field_name) {
1343 + $keys[] = $field['key'];
1344 + }
1345 + }
1346 + }
1347 + return $keys;
1348 + }
1349 +
1350 + /**
1351 + * Group-level ACF toggle (plan bf57e0): sets every field in one ACF field
1352 + * group included or excluded in a SINGLE option write. The client must
1353 + * never loop the per-field endpoint for this — get_option → modify →
1354 + * update_option once per field from twenty concurrent requests is a
1355 + * lost-update race that silently drops most of the group.
1356 + */
1357 + public function mxchat_acf_toggle_group_callback() {
1358 + check_ajax_referer('mxchat_prompts_setting_nonce');
1359 +
1360 + if (!current_user_can('manage_options')) {
1361 + wp_send_json_error(['message' => esc_html__('Insufficient permissions', 'mxchat')], 403);
1362 + return;
1363 + }
1364 +
1365 + if (!function_exists('acf_get_fields')) {
1366 + wp_send_json_error(['message' => esc_html__('ACF is not active', 'mxchat')]);
1367 + return;
1368 + }
1369 +
1370 + $group_key = isset($_POST['group_key']) ? sanitize_text_field(wp_unslash($_POST['group_key'])) : '';
1371 + if (!preg_match('/^group_[A-Za-z0-9_\-]+$/', $group_key)) {
1372 + wp_send_json_error(['message' => esc_html__('Invalid ACF group identifier', 'mxchat')]);
1373 + return;
1374 + }
1375 + $state = isset($_POST['state']) ? sanitize_text_field(wp_unslash($_POST['state'])) : '';
1376 + $include = ($state === 'on' || $state === '1');
1377 +
1378 + // Resolve the group's fields SERVER-side — a client-supplied key list
1379 + // is not trusted. This is the same call the settings UI lists from,
1380 + // so the toggle covers exactly the rendered set (top-level fields).
1381 + $group_fields = acf_get_fields($group_key);
1382 + if (empty($group_fields)) {
1383 + wp_send_json_error(['message' => esc_html__('No fields found for this group', 'mxchat')]);
1384 + return;
1385 + }
1386 +
1387 + $excluded_fields = get_option('mxchat_acf_excluded_fields', array());
1388 + if (!is_array($excluded_fields)) {
1389 + $excluded_fields = array();
1390 + }
1391 +
1392 + $touched = array();
1393 + foreach ($group_fields as $field) {
1394 + if (empty($field['key'])) {
1395 + continue;
1396 + }
1397 + if ($include) {
1398 + $excluded_fields = array_values(array_diff($excluded_fields, array($field['key'])));
1399 + $excluded_fields = $this->mxchat_expand_legacy_acf_name_entry($excluded_fields, $field['key']);
1400 + } elseif (!in_array($field['key'], $excluded_fields, true)) {
1401 + $excluded_fields[] = $field['key'];
1402 + }
1403 + $touched[] = array(
1404 + 'name' => 'mxchat_acf_field_' . $field['key'],
1405 + 'value' => $include ? 'on' : 'off',
1406 + );
1407 + }
1408 +
1409 + // The one write — the whole point of this endpoint.
1410 + update_option('mxchat_acf_excluded_fields', array_values($excluded_fields));
1411 +
1412 + wp_send_json_success([
1413 + 'message' => $include
1414 + ? esc_html__('All fields in this group will be included in imports', 'mxchat')
1415 + : esc_html__('All fields in this group will be excluded from imports', 'mxchat'),
1416 + 'fields' => $touched,
1417 + ]);
1418 + }
1419 +
1420 + /**
1107 1421 * Handles AJAX request for Pinecone settings migration
1108 1422 */
1109 1423 public function ajax_migrate_pinecone_settings() {
1110 1424 // Verify nonce
@@ -1140,9 +1454,9 @@
1140 1454 'mxchat_pinecone_index' => sanitize_text_field($old_options['mxchat_pinecone_index'] ?? ''),
1141 1455 'mxchat_pinecone_environment' => sanitize_text_field($old_options['mxchat_pinecone_environment'] ?? '')
1142 1456 );
1143 1457
1144 - update_option('mxchat_pinecone_addon_options', $migrated_options);
1458 + update_option('mxchat_pinecone_addon_options', $migrated_options, false);
1145 1459
1146 1460 wp_send_json_success(array(
1147 1461 'migrated' => true,
1148 1462 'message' => 'Settings migrated successfully from Pinecone add-on'
@@ -1301,9 +1615,17 @@
1301 1615 //error_log('MxChat deactivate: Nonce check failed');
1302 1616 wp_send_json_error('Security check failed.');
1303 1617 return;
1304 1618 }
1305 -
1619 +
1620 + // plan-mxchat-20260731-c63fb6 — nonce is not authorization. Without this,
1621 + // any authenticated user holding the nonce could revoke the site's PRO
1622 + // licence. Every sibling handler in this file already checks.
1623 + if (!current_user_can('manage_options')) {
1624 + wp_send_json_error(esc_html__('Unauthorized', 'mxchat'), 403);
1625 + return;
1626 + }
1627 +
1306 1628 //error_log('MxChat deactivate: Nonce check passed');
1307 1629
1308 1630 $license_key = get_option('mxchat_activation_key');
1309 1631 $email = get_option('mxchat_pro_email');