PluginProbe
Photonic Gallery & Lightbox for Flickr, SmugMug & Others / 3.37
Photonic Gallery & Lightbox for Flickr, SmugMug & Others v3.37
3.37 3.36 3.35 3.34 3.33 2.19 2.20 2.21 2.22 2.23 2.24 2.25 2.26 2.27 2.28 2.29 2.30 2.31 2.32 2.33 2.34 2.40 2.41 2.42 2.43 All 142 releases
← All changes | Platforms/SmugMug.php +45 -17 3.33 → 3.37 View file →
@@ -206,9 +206,9 @@
206 206 Update, v1.59 - Using _expand and combining both the expansions prevents the usage of the <code>start</code> and <code>count</code>
207 207 attributes from the album node. So, splitting the call anyway, to introduce the album!images node...
208 208 */
209 209 if ($is_album) {
210 - $chained_calls[] = $this->base_url . 'album/' . $album_field . '?_expand=HighlightImage.ImageSizes,HighlightImage.ImageSizeDetails,HighlightImage.LargestImage';
210 + $chained_calls[] = $this->base_url . 'album/' . $album_field . '?_expand=HighlightImage.ImageSizes,HighlightImage.ImageSizeDetails,HighlightImage.LargestImage,Node.FormattedValues';
211 211 // if ('images' === $attr['view']) { // Fix for https://wordpress.org/support/topic/smugmug-filter-on-keywords-not-working-for-me/
212 212 if (!empty($args['Keywords']) || !empty($args['Text'])) { // Fix for https://wordpress.org/support/topic/smugmug-filter-on-keywords-not-working-for-me/
213 213 $args['Scope'] = 'https://api.smugmug.com/api/v2/album/' . $album_field;
214 214 }
@@ -241,9 +241,9 @@
241 241 case 'tree':
242 242 default:
243 243 $this->push_to_stack('Initial user tree');
244 244 $initial_call = $this->base_url . 'user/' . $attr['nick_name'];
245 - $initial_response = Photonic::http($initial_call, 'GET', $args);
245 + $initial_response = Photonic::http($initial_call, 'GET', $args, null, 90, PHOTONIC_SSL_VERIFY);
246 246
247 247 if (!empty($attr['site_password'])) {
248 248 $chained_calls[] = $this->base_url . 'user/' . $attr['nick_name'] . '!unlock';
249 249 $args['Password'] = $attr['site_password'];
@@ -332,12 +332,12 @@
332 332 if (false === stripos($chained_call, '!unlock')) {
333 333 $this->push_to_stack('Making call');
334 334 if ($this->oauth_done && empty($cookies)) {
335 335 $signed_args = $this->sign_call($chained_call, 'GET', $smug_args);
336 - $response = Photonic::http($chained_call, 'GET', $signed_args, null, 90, false, [], $cookies);
336 + $response = Photonic::http($chained_call, 'GET', $signed_args, null, 90, PHOTONIC_SSL_VERIFY, [], $cookies);
337 337 }
338 338 else {
339 - $response = Photonic::http($chained_call, 'GET', $smug_args, null, 90, false, [], $cookies);
339 + $response = Photonic::http($chained_call, 'GET', $smug_args, null, 90, PHOTONIC_SSL_VERIFY, [], $cookies);
340 340 }
341 341
342 342 $this->pop_from_stack();
343 343
@@ -376,10 +376,22 @@
376 376 if (!$header_done) {
377 377 $header = new Header();
378 378 $header->title = wp_kses_post($album->Name);
379 379 $header->page_url = $album->WebUri;
380 - $header->description = wp_kses_post($album->Description ?? '');
381 380
381 + if (isset($album->FormattedValues->Description->html) && !empty($album->FormattedValues->Description->html)) {
382 + // wp_kses_post is OK here, as we want to permit <a> and other tags - this markup is printed directly on a page and not in a lightbox.
383 + $header->description = wp_kses_post($album->FormattedValues->Description->html);
384 + }
385 + elseif (isset($album->Uris->Node->Node->FormattedValues->Description->html) && !empty($album->Uris->Node->Node->FormattedValues->Description->html)) {
386 + // wp_kses_post is OK here, as we want to permit <a> and other tags - this markup is printed directly on a page and not in a lightbox.
387 + $header->description = wp_kses_post($album->Uris->Node->Node->FormattedValues->Description->html);
388 + }
389 + else {
390 + // wp_kses_post is OK here, as we want to permit <a> and other tags - this markup is printed directly on a page and not in a lightbox.
391 + $header->description = wp_kses_post($album->Description ?? '');
392 + }
393 +
382 394 if (isset($album->Uris->HighlightImage->Image)) {
383 395 $header->thumb_url = $album->Uris->HighlightImage->Image->ThumbnailUrl;
384 396 }
385 397 elseif (isset($album->Uris->AlbumImages->AlbumImage) && is_array($album->Uris->AlbumImages->AlbumImage)) {
@@ -481,9 +493,9 @@
481 493 * @param string $indent
482 494 * @param int $level
483 495 * @return Collection
484 496 */
485 - private function get_collection($node, $short_code, $indent = '', $level = 0): Collection {
497 + private function get_collection($node, $short_code, string $indent = '', int $level = 0): Collection {
486 498 $collection = new Collection();
487 499 $collection->indent = $indent;
488 500
489 501 $albums = [];
@@ -565,9 +577,9 @@
565 577 * @param $short_code
566 578 * @param $pages
567 579 * @return Album_List
568 580 */
569 - private function process_albums($albums, $indent, $album_filter, $short_code, $pages): Album_List {
581 + private function process_albums($albums, string $indent, array $album_filter, $short_code, $pages): Album_List {
570 582 global $photonic_smug_albums_album_per_row_constraint, $photonic_smug_albums_album_constrain_by_count, $photonic_smug_albums_album_title_display, $photonic_smug_hide_albums_album_photos_count_display, $photonic_gallery_template_page;
571 583 $objects = $this->build_level_2_objects($albums, $short_code, $album_filter);
572 584
573 585 $pagination = $this->get_pagination($pages);
@@ -595,9 +607,9 @@
595 607 * @param array $short_code
596 608 * @param $header
597 609 * @return array
598 610 */
599 - private function process_images($response, $short_code, $header): array {
611 + private function process_images($response, array $short_code, $header): array {
600 612 global $photonic_smug_photos_per_row_constraint, $photonic_smug_photos_constrain_by_count,
601 613 $photonic_smug_photo_title_display, $photonic_smug_photo_pop_title_display;
602 614 $body = $response['body'];
603 615 $body = json_decode($body);
@@ -623,9 +635,9 @@
623 635 if (is_array($images)) {
624 636 $photo_objects = $this->build_level_1_objects($images, $short_code);
625 637 }
626 638
627 - $pages = isset($images->Pages) ? $images->Pages : (is_array($images) && isset($body->Pages) ? $body->Pages : null);
639 + $pages = $images->Pages ?? (is_array($images) && isset($body->Pages) ? $body->Pages : null);
628 640 $pagination = $this->get_pagination($pages);
629 641
630 642 if (!empty($photo_objects)) {
631 643 if (!empty($header)) {
@@ -702,9 +714,16 @@
702 714 $this->calculate_sizes($image, $photonic_photo, $sizes);
703 715
704 716 $photonic_photo->title = wp_kses_post($image->Title);
705 717 $photonic_photo->alt_title = $photonic_photo->title;
706 - $photonic_photo->description = wp_kses_post($image->Caption);
718 +
719 + if (isset($image->FormattedValues->Caption->html) && !empty($image->FormattedValues->Caption->html)) {
720 + $photonic_photo->description = wp_kses($image->FormattedValues->Caption->html, Photonic::$safe_description_tags);
721 + }
722 + else {
723 + $photonic_photo->description = wp_kses($image->Caption, Photonic::$safe_description_tags);
724 + }
725 +
707 726 if (isset($image->WebUri)) {
708 727 $photonic_photo->main_page = esc_url($image->WebUri);
709 728 $photonic_photo->buy_link = esc_url($image->WebUri . '/buy');
710 729 }
@@ -732,9 +751,9 @@
732 751 }
733 752 return $photo_objects;
734 753 }
735 754
736 - public function build_level_2_objects($objects_or_response, array $short_code, array $filter_list = [], array &$options = [], ?Pagination &$pagination = null): array {
755 + public function build_level_2_objects($objects_or_response, array $short_code, array $filter_list = [], array $options = [], ?Pagination &$pagination = null): array {
737 756 global $photonic_smug_hide_password_protected_thumbnail, $photonic_gallery_template_page;
738 757
739 758 $named_albums = $filter_list;
740 759 foreach ($named_albums as $idx => $album) {
@@ -789,16 +808,26 @@
789 808 $photonic_album->tile_image = $tileURL;
790 809
791 810 $photonic_album->main_page = esc_url($album->WebUri);
792 811
793 - $photonic_album->title = wp_kses_post($album->Name);
794 - $photonic_album->description = !empty($album->Description) ? wp_kses_post($album->Description) : '';
812 + $photonic_album->title = wp_kses_post($album->Name);
795 813
814 + if (isset($album->FormattedValues->Description->html) && !empty($album->FormattedValues->Description->html)) {
815 + $photonic_album->description = wp_kses($album->FormattedValues->Description->html, Photonic::$safe_description_tags);
816 + }
817 + elseif (isset($album->Uris->Node->Node->FormattedValues->Description->html) && !empty($album->Uris->Node->Node->FormattedValues->Description->html)) {
818 + $photonic_album->description = wp_kses($album->Uris->Node->Node->FormattedValues->Description->html, Photonic::$safe_description_tags);
819 + }
820 + else {
821 + $photonic_album->description = !empty($album->Description) ? wp_kses($album->Description, Photonic::$safe_description_tags) : '';
822 + }
823 +
796 824 if ('page' === $short_code['popup'] && !empty($photonic_gallery_template_page) && is_string(get_post_status($photonic_gallery_template_page))) {
797 825 $internal_short_code = $short_code;
798 826 $internal_short_code['view'] = 'album';
799 827 $internal_short_code['album'] = $photonic_album->id;
800 828 $internal_short_code['layout'] = empty($short_code['photo_layout']) ? $short_code['layout'] : $short_code['photo_layout'];
829 + $internal_short_code['count'] = empty($short_code['photo_count']) ? $short_code['count'] : $short_code['photo_count'];
801 830
802 831 $photonic_album->gallery_url = $this->get_gallery_url($internal_short_code, ['title' => $photonic_album->title]);
803 832 }
804 833
@@ -810,10 +839,10 @@
810 839 $photonic_album->classes = ['photonic-smug-passworded'];
811 840 $photonic_album->passworded = 1;
812 841 }
813 842
814 - if (empty($named_albums) || (!empty($named_albums) && in_array($album->AlbumKey, $named_albums, true) && 'exclude' !== strtolower($short_code['filter_type'])) ||
815 - (!empty($named_albums) && !in_array($album->AlbumKey, $named_albums, true) && 'exclude' === strtolower($short_code['filter_type']))) {
843 + if (empty($named_albums) || (in_array($album->AlbumKey, $named_albums, true) && 'exclude' !== strtolower($short_code['filter_type'])) ||
844 + (!in_array($album->AlbumKey, $named_albums, true) && 'exclude' === strtolower($short_code['filter_type']))) {
816 845 $objects[] = $photonic_album;
817 846 }
818 847 }
819 848 }
@@ -882,15 +911,14 @@
882 911 /**
883 912 * Tests to see if the OAuth Access Token that is cached is still valid. This is important because a user might have manually revoked
884 913 * access for your app through the provider's control panel.
885 914 *
886 - * @param $token
887 915 * @return array|WP_Error
888 916 */
889 917 public function check_access_token() {
890 918 $signed_parameters = $this->sign_call($this->base_url . 'user/sayontan', 'GET', []);
891 919 $end_point = $this->base_url . 'user/sayontan?' . self::build_query($signed_parameters);
892 - return Photonic::http($end_point, 'GET', null);
920 + return Photonic::http($end_point, 'GET', null, null, 90, PHOTONIC_SSL_VERIFY);
893 921 }
894 922
895 923 /**
896 924 * Takes the response for the "Check access token", then tries to determine whether the check was successful or not.