PluginProbe
Polylang / 3.8.10
Polylang v3.8.10
3.8.10 3.8.9 3.8.8 3.8.7 3.8.6 3.8.5 3.8.4 3.8.3 2.7 2.7.0.1 2.7.1 2.7.2 2.7.3 2.7.4 2.8 2.8.1 2.8.2 2.8.3 2.8.4 2.9 2.9.1 2.9.2 3.0 3.0.1 3.0.2 All 234 releases
← All changes | src/admin/admin-filters-columns.php +108 -31 3.8.5 → 3.8.10 View file →
@@ -335,35 +335,77 @@
335 335 if ( ! isset( $_POST['post_type'], $_POST['post_id'], $_POST['screen'] ) ) {
336 336 wp_die( 0 );
337 337 }
338 338
339 - $post_type = sanitize_key( $_POST['post_type'] );
339 + if ( ! is_numeric( $_POST['post_id'] ) ) {
340 + wp_die( 0 );
341 + }
340 342
341 - if ( ! post_type_exists( $post_type ) || ! $this->model->is_translated_post_type( $post_type ) ) {
343 + $post_type_object = get_post_type_object( sanitize_key( $_POST['post_type'] ) );
344 +
345 + if ( empty( $post_type_object ) || ! $this->model->is_translated_post_type( $post_type_object->name ) ) {
342 346 wp_die( 0 );
343 347 }
344 348
345 - /** @var WP_Posts_List_Table $wp_list_table */
346 349 $wp_list_table = _get_list_table( 'WP_Posts_List_Table', array( 'screen' => sanitize_key( $_POST['screen'] ) ) );
347 350
348 - $x = new WP_Ajax_Response();
351 + if ( empty( $wp_list_table ) ) {
352 + wp_die( 0 );
353 + }
349 354
355 + $response = new WP_Ajax_Response();
356 +
350 357 // Collect old translations.
351 - $translations = empty( $_POST['translations'] ) ? array() : explode( ',', $_POST['translations'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput
352 - $translations = array_map( 'intval', $translations );
353 - $translations = array_merge( $translations, array( (int) $_POST['post_id'] ) ); // Add current post
358 + if ( ! empty( $_POST['translations'] ) && is_string( $_POST['translations'] ) ) {
359 + $translations = explode( ',', $_POST['translations'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput
360 + $translations = array_filter( $translations, 'is_numeric' );
361 + $translations = array_map( 'intval', $translations );
362 + $translations = array_filter( $translations );
363 + } else {
364 + $translations = array();
365 + }
354 366
355 - foreach ( $translations as $post_id ) {
356 - $level = is_post_type_hierarchical( $post_type ) ? count( get_ancestors( $post_id, $post_type ) ) : 0;
357 - if ( $post = get_post( $post_id ) ) {
358 - ob_start();
359 - $wp_list_table->single_row( $post, $level );
360 - $data = (string) ob_get_clean();
361 - $x->add( array( 'what' => 'row', 'data' => $data, 'supplemental' => array( 'post_id' => $post_id ) ) );
367 + $translations = array_merge( $translations, $this->model->post->get_translations( (int) $_POST['post_id'] ) );
368 + $translations = array_unique( $translations );
369 +
370 + if ( empty( $translations ) ) { // May occur if the modified post has no language.
371 + $response->send();
372 + }
373 +
374 + /** @var WP_Post[] */
375 + $posts = ( new WP_Query() )->query(
376 + array(
377 + // Do not add `post_status`, as this allows `WP_Query` to handle user capabilities to read private posts.
378 + 'post__in' => $translations,
379 + 'post_type' => $post_type_object->name,
380 + 'posts_per_page' => count( $translations ),
381 + 'no_found_rows' => true,
382 + 'orderby' => 'ID',
383 + 'lang' => '',
384 + )
385 + );
386 +
387 + foreach ( $posts as $post ) {
388 + if ( $post_type_object->hierarchical ) {
389 + $level = count( get_ancestors( $post->ID, $post->post_type, 'post_type' ) );
390 + } else {
391 + $level = 0;
362 392 }
393 +
394 + ob_start();
395 + $wp_list_table->single_row( $post, $level );
396 + $data = (string) ob_get_clean();
397 +
398 + $response->add(
399 + array(
400 + 'what' => 'row',
401 + 'data' => $data,
402 + 'supplemental' => array( 'post_id' => $post->ID ),
403 + )
404 + );
363 405 }
364 406
365 - $x->send();
407 + $response->send();
366 408 }
367 409
368 410 /**
369 411 * Update rows of translated terms when adding / deleting a translation
@@ -381,38 +423,73 @@
381 423 if ( ! isset( $_POST['taxonomy'], $_POST['term_id'], $_POST['screen'] ) ) {
382 424 wp_die( 0 );
383 425 }
384 426
385 - $taxonomy = sanitize_key( $_POST['taxonomy'] );
427 + if ( ! is_numeric( $_POST['term_id'] ) ) {
428 + wp_die( 0 );
429 + }
386 430
387 - if ( ! taxonomy_exists( $taxonomy ) || ! $this->model->is_translated_taxonomy( $taxonomy ) ) {
431 + $taxonomy_object = get_taxonomy( sanitize_key( $_POST['taxonomy'] ) );
432 +
433 + if ( empty( $taxonomy_object ) || ! $this->model->is_translated_taxonomy( $taxonomy_object->name ) ) {
388 434 wp_die( 0 );
389 435 }
390 436
391 - /** @var WP_Terms_List_Table $wp_list_table */
392 437 $wp_list_table = _get_list_table( 'WP_Terms_List_Table', array( 'screen' => sanitize_key( $_POST['screen'] ) ) );
393 438
394 - $x = new WP_Ajax_Response();
439 + if ( empty( $wp_list_table ) ) {
440 + wp_die( 0 );
441 + }
395 442
443 + $response = new WP_Ajax_Response();
444 +
396 445 // Collect old translations.
397 - $translations = empty( $_POST['translations'] ) ? array() : explode( ',', $_POST['translations'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput
398 - $translations = array_map( 'intval', $translations );
399 - $translations = array_merge( $translations, $this->model->term->get_translations( (int) $_POST['term_id'] ) ); // Add current translations.
400 - $translations = array_unique( $translations ); // Remove duplicates.
446 + if ( ! empty( $_POST['translations'] ) && is_string( $_POST['translations'] ) ) {
447 + $translations = explode( ',', $_POST['translations'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput
448 + $translations = array_filter( $translations, 'is_numeric' );
449 + $translations = array_map( 'intval', $translations );
450 + $translations = array_filter( $translations );
451 + } else {
452 + $translations = array();
453 + }
401 454
402 - foreach ( $translations as $term_id ) {
403 - $level = is_taxonomy_hierarchical( $taxonomy ) ? count( get_ancestors( $term_id, $taxonomy ) ) : 0;
404 - $tag = get_term( $term_id, $taxonomy );
455 + $translations = array_merge( $translations, $this->model->term->get_translations( (int) $_POST['term_id'] ) );
456 + $translations = array_unique( $translations );
405 457
406 - if ( ! $tag instanceof WP_Term ) {
407 - continue;
458 + if ( empty( $translations ) ) { // May occur if the modfied term has no language.
459 + $response->send();
460 + }
461 +
462 + /** @var WP_Term[] */
463 + $terms = ( new WP_Term_Query() )->query(
464 + array(
465 + 'include' => $translations,
466 + 'taxonomy' => $taxonomy_object->name,
467 + 'hide_empty' => false,
468 + 'orderby' => 'term_id',
469 + 'lang' => '',
470 + )
471 + );
472 +
473 + foreach ( $terms as $term ) {
474 + if ( $taxonomy_object->hierarchical ) {
475 + $level = count( get_ancestors( $term->term_id, $taxonomy_object->name, 'taxonomy' ) );
476 + } else {
477 + $level = 0;
408 478 }
409 479
410 480 ob_start();
411 - $wp_list_table->single_row( $tag, $level );
481 + $wp_list_table->single_row( $term, $level );
412 482 $data = (string) ob_get_clean();
413 - $x->add( array( 'what' => 'row', 'data' => $data, 'supplemental' => array( 'term_id' => $term_id ) ) );
483 +
484 + $response->add(
485 + array(
486 + 'what' => 'row',
487 + 'data' => $data,
488 + 'supplemental' => array( 'term_id' => $term->term_id ),
489 + )
490 + );
414 491 }
415 492
416 - $x->send();
493 + $response->send();
417 494 }
418 495 }