PluginProbe
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls / 6.5.1
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls v6.5.1
6.5.1 6.5.0 6.4.9 6.4.8 6.4.7 6.4.6 6.4.5 6.4.4 6.4.3 6.4.2 6.4.1 6.4.0 6.3.9 6.3.8 6.3.7 6.3.6 6.3.5 6.3.4 6.3.3 5.6.0 5.6.1 5.6.2 5.6.3 5.6.4 5.6.5 All 154 releases
← All changes | includes/lists/class-poll-maker-results-list-table.php +71 -38 5.6.2 → 6.5.1 View file →
@@ -10,10 +10,10 @@
10 10 public function __construct( $plugin_name ) {
11 11 $this->plugin_name = $plugin_name;
12 12 $this->title_length = Poll_Maker_Ays_Admin::get_listtables_title_length('results');
13 13 parent::__construct(array(
14 - 'singular' => __('Result', "poll-maker"), //singular name of the listed records
15 - 'plural' => __('Results', "poll-maker"), //plural name of the listed records
14 + 'singular' =>esc_html__('Result', "poll-maker"), //singular name of the listed records
15 + 'plural' =>esc_html__('Results', "poll-maker"), //plural name of the listed records
16 16 'ajax' => false, //does this table support ajax?
17 17 ));
18 18 add_action('admin_notices', array($this, 'results_notices'));
19 19
@@ -30,18 +30,27 @@
30 30 public static function get_reports( $per_page = 50, $page_number = 1 ) {
31 31
32 32 global $wpdb;
33 33
34 - $sql = "SELECT
35 - {$wpdb->prefix}ayspoll_polls.id,
36 - SUM({$wpdb->prefix}ayspoll_answers.votes) AS voted,
37 - {$wpdb->prefix}ayspoll_answers.poll_id,
38 - {$wpdb->prefix}ayspoll_polls.categories
39 - FROM
40 - {$wpdb->prefix}ayspoll_answers
41 - INNER JOIN
42 - {$wpdb->prefix}ayspoll_polls
43 - ON {$wpdb->prefix}ayspoll_answers.poll_id = {$wpdb->prefix}ayspoll_polls.id ";
34 + if (isset($_SERVER['HTTP_HOST']) && sanitize_text_field($_SERVER['HTTP_HOST']) == "playground.wordpress.net") {
35 + $sql = "SELECT
36 + {$wpdb->prefix}ayspoll_polls.id,
37 + SUM(CAST({$wpdb->prefix}ayspoll_answers.votes AS INTEGER)) AS voted,
38 + {$wpdb->prefix}ayspoll_answers.poll_id,
39 + {$wpdb->prefix}ayspoll_polls.categories
40 + FROM {$wpdb->prefix}ayspoll_answers
41 + INNER JOIN {$wpdb->prefix}ayspoll_polls
42 + ON {$wpdb->prefix}ayspoll_answers.poll_id = {$wpdb->prefix}ayspoll_polls.id ";
43 + } else {
44 + $sql = "SELECT
45 + {$wpdb->prefix}ayspoll_polls.id,
46 + SUM({$wpdb->prefix}ayspoll_answers.votes) AS voted,
47 + {$wpdb->prefix}ayspoll_answers.poll_id,
48 + {$wpdb->prefix}ayspoll_polls.categories
49 + FROM {$wpdb->prefix}ayspoll_answers
50 + INNER JOIN {$wpdb->prefix}ayspoll_polls
51 + ON {$wpdb->prefix}ayspoll_answers.poll_id = {$wpdb->prefix}ayspoll_polls.id ";
52 + }
44 53
45 54 if (isset($_REQUEST['orderbypoll']) && $_REQUEST['orderbypoll'] > 0) {
46 55 $poll_id = absint(sanitize_text_field( $_REQUEST['orderbypoll'] ));
47 56
@@ -55,8 +64,9 @@
55 64
56 65 $sql .= "GROUP BY {$wpdb->prefix}ayspoll_answers.poll_id";
57 66 if (!empty($_REQUEST['orderby'])) {
58 67 $order_by = ( isset( $_REQUEST['orderby'] ) && sanitize_text_field( $_REQUEST['orderby'] ) != '' ) ? sanitize_text_field( $_REQUEST['orderby'] ) : 'id';
68 + $order_by = str_replace('id', $wpdb->prefix . 'ayspoll_polls.id', $order_by);
59 69 $order_by .= ( ! empty( $_REQUEST['order'] ) && strtolower( $_REQUEST['order'] ) == 'asc' ) ? ' ASC' : ' DESC';
60 70
61 71 $sql_orderby = sanitize_sql_orderby($order_by);
62 72
@@ -62,12 +72,12 @@
62 72
63 73 if ( $sql_orderby ) {
64 74 $sql .= ' ORDER BY ' . $sql_orderby;
65 75 } else {
66 - $sql .= ' ORDER BY id DESC';
76 + $sql .= ' ORDER BY ' . $wpdb->prefix . 'ayspoll_polls.id DESC';
67 77 }
68 78 } else {
69 - $sql .= ' ORDER BY id DESC';
79 + $sql .= ' ORDER BY ' . $wpdb->prefix . 'ayspoll_polls.id DESC';
70 80 }
71 81
72 82 $sql .= " LIMIT %d";
73 83 $args[] = $per_page;
@@ -161,11 +171,20 @@
161 171 'poll_id' => $id
162 172 )
163 173 );
164 174
165 - $sql = "DELETE r FROM {$wpdb->prefix}ayspoll_reports as r
166 - JOIN {$wpdb->prefix}ayspoll_answers ON {$wpdb->prefix}ayspoll_answers.id = r.answer_id
167 - WHERE {$wpdb->prefix}ayspoll_answers.poll_id = $id";
175 + if (isset($_SERVER['HTTP_HOST']) && sanitize_text_field($_SERVER['HTTP_HOST']) == "playground.wordpress.net") {
176 + $sql = "DELETE FROM {$wpdb->prefix}ayspoll_reports
177 + WHERE answer_id IN (
178 + SELECT id FROM {$wpdb->prefix}ayspoll_answers
179 + WHERE poll_id = $id
180 + )";
181 + } else {
182 + $sql = "DELETE r FROM {$wpdb->prefix}ayspoll_reports as r
183 + JOIN {$wpdb->prefix}ayspoll_answers ON {$wpdb->prefix}ayspoll_answers.id = r.answer_id
184 + WHERE {$wpdb->prefix}ayspoll_answers.poll_id = $id";
185 + }
186 +
168 187 $res = $wpdb->query($sql);
169 188
170 189 return $res > 0;
171 190 }
@@ -227,11 +246,19 @@
227 246
228 247 $res = $wpdb->get_row("SELECT * FROM {$wpdb->prefix}ayspoll_polls WHERE id={$item['id']}", "ARRAY_A");
229 248
230 249 $restitle = Poll_Maker_Ays_Admin::ays_restriction_string("word",stripcslashes($res['title']), $this->title_length);
231 - $title = sprintf('<a href="?page=%s-each&poll=%d&title=%s">' . $restitle . '</a>', esc_attr($_REQUEST['page']), absint($item['id']), stripslashes($res['title']));
250 + $title = sprintf('<a href="?page=%s-each&poll=%d&title=%s">' . $restitle . '</a>', esc_attr($_REQUEST['page']), absint($item['id']), stripslashes($res['title']));
251 +
232 252 $actions = [
233 - 'delete' => sprintf('<a href="?page=%s&action=%s&result=%s&_wpnonce=%s">Delete</a>', esc_attr($_REQUEST['page']), 'delete', absint($item['id']), $delete_nonce),
253 + 'delete' => sprintf(
254 + '<a href="?page=%s&action=%s&result=%s&_wpnonce=%s">%s</a>',
255 + esc_attr( $_REQUEST['page'] ),
256 + 'delete',
257 + absint( $item['id'] ),
258 + $delete_nonce,
259 + __( 'Delete', 'poll-maker' )
260 + ),
234 261 ];
235 262
236 263 return $title . $this->row_actions($actions);
237 264 }
@@ -298,12 +325,12 @@
298 325 */
299 326 function get_columns() {
300 327 $columns = array(
301 328 'cb' => '<input type="checkbox" />',
302 - 'id' => __('ID',"poll-maker"),
303 - 'poll_title' => __('Poll',"poll-maker"),
304 - 'voted' => __('Voters count',"poll-maker"),
305 - 'unread' => __('New results count',"poll-maker")
329 + 'poll_title' =>esc_html__('Poll',"poll-maker"),
330 + 'voted' =>esc_html__('Voters count',"poll-maker"),
331 + 'unread' =>esc_html__('New results count',"poll-maker"),
332 + 'id' =>esc_html__('ID',"poll-maker")
306 333 );
307 334
308 335 return $columns;
309 336 }
@@ -328,10 +355,10 @@
328 355 * @return array
329 356 */
330 357 public function get_bulk_actions() {
331 358 $actions = array(
332 - 'bulk-read' => __('Mark as read', "poll-maker"),
333 - 'bulk-delete' => __('Delete', "poll-maker"),
359 + 'bulk-read' =>esc_html__('Mark as read', "poll-maker"),
360 + 'bulk-delete' =>esc_html__('Delete', "poll-maker"),
334 361 );
335 362
336 363 return $actions;
337 364 }
@@ -383,18 +410,20 @@
383 410 wp_redirect($url);
384 411 }
385 412
386 413 }
387 -
388 - // If the delete bulk action is triggered
389 - if ((isset($_POST['action']) && 'bulk-delete' == $_POST['action'])
390 - || (isset($_POST['action2']) && 'bulk-delete' == $_POST['action2'])
414 +
415 + // Process bulk-delete action
416 + if ((isset($_POST['action']) && $_POST['action'] == 'bulk-delete')
417 + || (isset($_POST['action2']) && $_POST['action2'] == 'bulk-delete')
391 418 ) {
392 - $delete_ids = esc_sql($_POST['bulk-action']);
393 419
394 - // loop over the array of record IDs and delete them
395 - foreach ( $delete_ids as $id ) {
396 - self::delete_reports($id);
420 + if (!empty($_POST['bulk-action']) && is_array($_POST['bulk-action'])) {
421 + $delete_ids = array_map('intval', $_POST['bulk-action']);
422 +
423 + foreach ($delete_ids as $id) {
424 + self::delete_reports($id);
425 + }
397 426 }
398 427
399 428 // esc_url_raw() is used to prevent converting ampersand in url to "#038;"
400 429 // add_query_arg() return the current url
@@ -405,10 +434,14 @@
405 434 } elseif ((isset($_POST['action']) && 'bulk-read' == $_POST['action'])
406 435 || (isset($_POST['action2']) && 'bulk-read' == $_POST['action2'])
407 436 ) {
408 437
409 - $read_ids = esc_sql($_POST['bulk-action']);
438 + if (empty($_POST['bulk-action']) || !is_array($_POST['bulk-action'])) {
439 + return;
440 + }
410 441
442 + $read_ids = array_map('intval', $_POST['bulk-action']);
443 +
411 444 // loop over the array of record IDs and mark as readed them
412 445 foreach ( $read_ids as $id ) {
413 446 echo $id . "<br>";
414 447 self::mark_as_read_reports($id);
@@ -446,9 +479,9 @@
446 479 return;
447 480 }
448 481
449 482 if ('deleted' == $status) {
450 - $updated_message = esc_html(__('Result deleted.', "poll-maker"));
483 + $updated_message = esc_html( esc_html__('Result deleted.', "poll-maker"));
451 484 }
452 485
453 486 if (empty($updated_message)) {
454 487 return;
@@ -454,9 +487,9 @@
454 487 return;
455 488 }
456 489
457 490 ?>
458 - <div class="notice notice-success is-dismissible">
491 + <div class="ays-poll-admin-notice notice notice-success is-dismissible">
459 492 <p> <?php echo $updated_message; ?> </p>
460 493 </div>
461 494 <?php
462 495 }
@@ -482,9 +515,9 @@
482 515 $content = "";
483 516 if(isset($poll_cats)){
484 517 $content = '<label for="bulk-action-selector-top-cat" class="screen-reader-text">Select Filter Type</label>
485 518 <select name="orderbycat" id="bulk-action-selector-top-cat">
486 - <option value="0" selected>' .__("Select Category", "poll-maker"). '</option>';
519 + <option value="0" selected>' . esc_html__("Select Category", "poll-maker"). '</option>';
487 520 $selected = "";
488 521 $this_cat_id = 0;
489 522 foreach ($poll_cats as $cat_key => $cat_value) {
490 523 $selected = (isset($_REQUEST['orderbycat']) && $_REQUEST['orderbycat'] == $cat_value['id'] ) ? 'selected' : '';
@@ -493,9 +526,9 @@
493 526 $cat_value = isset($cat_value['title']) && $cat_value['title'] != "" ? esc_attr($cat_value['title']) : "";
494 527 $content .= '<option value="'.$cat_id.'" '.$selected.'>'.$cat_value.'</option>';
495 528 }
496 529 $content .= '</select>';
497 - $content .= '<input type="submit" id="doactioncat" name="filter_by_cat" class="button action" value="'.__("Filter", "poll-maker").'" style="width: 3.7rem;margin-left: 5px;">';
530 + $content .= '<input type="submit" id="doactioncat" name="filter_by_cat" class="button action" value="'. esc_html__("Filter", "poll-maker").'" style="width: 3.7rem;margin-left: 5px;">';
498 531 if(isset($_REQUEST['filter_by_cat'])){
499 532 $new_url = remove_query_arg("orderbycat")."&orderbycat=".$this_cat_id;
500 533 wp_redirect($new_url);
501 534 }