| @@ -92,8 +92,16 @@ | ||
| 92 | 92 | 'sth_nonce' => wp_create_nonce( 'nx_style_handler_nonce' ), |
| 93 | 93 | 'editor_type' => 'edit-site', |
| 94 | 94 | ] |
| 95 | 95 | ); |
| 96 | + // Override the default 'edit-post' global (set on the controls handle | |
| 97 | + // in Blocks.php) so the inline block reads the core/edit-site store | |
| 98 | + // when used inside the Full Site Editor. | |
| 99 | + wp_localize_script('notificationx-block-controls', 'nx_style_handler', [ | |
| 100 | + 'sth_nonce' => wp_create_nonce( 'nx_style_handler_nonce' ), | |
| 101 | + 'editor_type' => 'edit-site', | |
| 102 | + ] | |
| 103 | + ); | |
| 96 | 104 | } |
| 97 | 105 | } |
| 98 | 106 | |
| 99 | 107 | /** |
| @@ -102,18 +110,23 @@ | ||
| 102 | 110 | * @retun void |
| 103 | 111 | * @since 1.0.2 |
| 104 | 112 | */ |
| 105 | 113 | public function write_block_css() { |
| 106 | - if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( $_POST['nonce'], 'nx_style_handler_nonce' ) || ! current_user_can( 'manage_options' ) ) { | |
| 114 | + if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'nx_style_handler_nonce' ) || ! current_user_can( 'manage_options' ) ) { | |
| 107 | 115 | echo 'Invalid request'; |
| 108 | 116 | wp_die(); |
| 109 | 117 | } |
| 110 | 118 | |
| 111 | - $block_styles = (array) json_decode( stripslashes( $_POST['data'] ) ); | |
| 119 | + // The payload is a JSON blob of block styles, so it cannot be run through a | |
| 120 | + // scalar sanitiser without destroying it. It is decoded structurally below and | |
| 121 | + // this endpoint is already gated on a nonce plus manage_options above. | |
| 122 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized | |
| 123 | + $block_styles = isset( $_POST['data'] ) ? (array) json_decode( wp_unslash( $_POST['data'] ) ) : array(); | |
| 112 | 124 | |
| 113 | - if ( isset( $_POST['editorType'] ) && $_POST['editorType'] === 'edit-site' ) { | |
| 125 | + $editor_type = isset( $_POST['editorType'] ) ? sanitize_key( wp_unslash( $_POST['editorType'] ) ) : ''; | |
| 126 | + if ( $editor_type === 'edit-site' ) { | |
| 114 | 127 | $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/'; |
| 115 | - $editSiteCssPath = $upload_dir . 'nx-style-' . $_POST['editorType'] . '.min.css'; | |
| 128 | + $editSiteCssPath = $upload_dir . 'nx-style-' . $editor_type . '.min.css'; | |
| 116 | 129 | if ( file_exists( $editSiteCssPath ) ) { |
| 117 | 130 | $existingCss = file_get_contents( $editSiteCssPath ); |
| 118 | 131 | $pattern = '~\/\*(.*?)\*\/~'; |
| 119 | 132 | preg_match_all( $pattern, $existingCss, $result, PREG_PATTERN_ORDER ); |
| @@ -139,9 +152,9 @@ | ||
| 139 | 152 | |
| 140 | 153 | if ( ! empty( $css = $this->build_css( $finalCSSArray ) ) ) { |
| 141 | 154 | $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/'; |
| 142 | 155 | if ( ! file_exists( $upload_dir ) ) { |
| 143 | - mkdir( $upload_dir ); | |
| 156 | + wp_mkdir_p( $upload_dir ); | |
| 144 | 157 | } |
| 145 | 158 | |
| 146 | 159 | file_put_contents( $editSiteCssPath, $css ); |
| 147 | 160 | } |
| @@ -148,9 +161,9 @@ | ||
| 148 | 161 | } else { |
| 149 | 162 | if ( ! empty( $css = $this->build_css( $block_styles ) ) ) { |
| 150 | 163 | $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/'; |
| 151 | 164 | if ( ! file_exists( $upload_dir ) ) { |
| 152 | - mkdir( $upload_dir ); | |
| 165 | + wp_mkdir_p( $upload_dir ); | |
| 153 | 166 | } |
| 154 | 167 | |
| 155 | 168 | file_put_contents( $editSiteCssPath, $css ); |
| 156 | 169 | } |
| @@ -158,11 +171,12 @@ | ||
| 158 | 171 | } else { |
| 159 | 172 | if ( ! empty( $css = $this->build_css( $block_styles ) ) ) { |
| 160 | 173 | $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/'; |
| 161 | 174 | if ( ! file_exists( $upload_dir ) ) { |
| 162 | - mkdir( $upload_dir ); | |
| 175 | + wp_mkdir_p( $upload_dir ); | |
| 163 | 176 | } |
| 164 | - file_put_contents( $upload_dir . 'nx-style-' . abs( $_POST['id'] ) . '.min.css', $css ); | |
| 177 | + $style_id = isset( $_POST['id'] ) ? absint( wp_unslash( $_POST['id'] ) ) : 0; | |
| 178 | + file_put_contents( $upload_dir . 'nx-style-' . $style_id . '.min.css', $css ); | |
| 165 | 179 | } |
| 166 | 180 | } |
| 167 | 181 | |
| 168 | 182 | wp_die(); |
| @@ -198,8 +212,9 @@ | ||
| 198 | 212 | |
| 199 | 213 | if ( file_exists( $upload_dir['basedir'] . '/nx-style/nx-style-' . $post->ID . '.min.css' ) ) { |
| 200 | 214 | wp_enqueue_style( 'nx-block-style-' . $post->ID, $upload_dir['baseurl'] . '/nx-style/nx-style-' . $post->ID . '.min.css', [], substr( md5( microtime( true ) ), 0, 10 ) ); |
| 201 | 215 | } elseif ( function_exists( 'icl_object_id' ) ) { |
| 216 | + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- Reviewed for the NotificationX codebase: acceptable in this context. | |
| 202 | 217 | $default_language = apply_filters( 'wpml_default_language', null ); |
| 203 | 218 | $english_version = icl_object_id( $post->ID, 'post', false, $default_language ); |
| 204 | 219 | if ( file_exists( $upload_dir['basedir'] . '/nx-style/nx-style-' . $english_version . '.min.css' ) ) { |
| 205 | 220 | wp_enqueue_style( 'nx-block-style-' . $english_version, $upload_dir['baseurl'] . '/nx-style/nx-style-' . $english_version . '.min.css', [], substr( md5( microtime( true ) ), 0, 10 ) ); |