PluginProbe
QuadMenu – Mega Menu / 3.3.8
QuadMenu – Mega Menu v3.3.8
3.3.8 3.3.7 3.3.6 trunk 1.8.4 1.8.5 1.8.7 1.8.8 1.8.9 1.9.0 1.9.2 1.9.3 1.9.4 1.9.5 1.9.6 1.9.7 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 All 88 releases
quadmenu / redux / ReduxCore / inc / class.p.php

class.p.php in QuadMenu – Mega Menu 3.3.8, at redux/ReduxCore/inc/class.p.php

295 lines 9.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 class ReduxLegacy_P {
4
5 public function __construct() {
6
7 add_action( 'wp_ajax_nopriv_redux_p', array( $this, 'proxy' ) );
8 add_action( 'wp_ajax_redux_p', array( $this, 'proxy' ) );
9 }
10
11 public function proxy() {
12
13 if ( ! isset( $_GET['nonce'] ) || ( isset( $_GET['nonce'] ) && ! wp_verify_nonce( $_GET['nonce'], 'redux-ads-nonce' ) ) ) {
14 die();
15 }
16
17 // Script: Simple PHP Proxy: Get external HTML, JSON and more!
18 //
19 // *Version: 1.6, Last updated: 1/24/2009*
20 //
21 // Project Home - http://benalman.com/projects/php-simple-proxy/
22 // GitHub - http://github.com/cowboy/php-simple-proxy/
23 // Source - http://github.com/cowboy/php-simple-proxy/raw/master/ba-simple-proxy.php
24 //
25 // About: License
26 //
27 // Copyright (c) 2010 "Cowboy" Ben Alman,
28 // Dual licensed under the MIT and GPL licenses.
29 // http://benalman.com/about/license/
30 //
31 // About: Examples
32 //
33 // This working example, complete with fully commented code, illustrates one way
34 // in which this PHP script can be used.
35 //
36 // Simple - http://benalman.com/code/projects/php-simple-proxy/examples/simple/
37 //
38 // About: Release History
39 //
40 // 1.6 - (1/24/2009) Now defaults to JSON mode, which can now be changed to
41 // native mode by specifying ?mode=native. Native and JSONP modes are
42 // disabled by default because of possible XSS vulnerability issues, but
43 // are configurable in the PHP script along with a url validation regex.
44 // 1.5 - (12/27/2009) Initial release
45 //
46 // Topic: GET Parameters
47 //
48 // Certain GET (query string) parameters may be passed into ba-simple-proxy.php
49 // to control its behavior, this is a list of these parameters.
50 //
51 // url - The remote URL resource to fetch. Any GET parameters to be passed
52 // through to the remote URL resource must be urlencoded in this parameter.
53 // mode - If mode=native, the response will be sent using the same content
54 // type and headers that the remote URL resource returned. If omitted, the
55 // response will be JSON (or JSONP). <Native requests> and <JSONP requests>
56 // are disabled by default, see <Configuration Options> for more information.
57 // callback - If specified, the response JSON will be wrapped in this named
58 // function call. This parameter and <JSONP requests> are disabled by
59 // default, see <Configuration Options> for more information.
60 // user_agent - This value will be sent to the remote URL request as the
61 // `User-Agent:` HTTP request header. If omitted, the browser user agent
62 // will be passed through.
63 // send_cookies - If send_cookies=1, all cookies will be forwarded through to
64 // the remote URL request.
65 // send_session - If send_session=1 and send_cookies=1, the SID cookie will be
66 // forwarded through to the remote URL request.
67 // full_headers - If a JSON request and full_headers=1, the JSON response will
68 // contain detailed header information.
69 // full_status - If a JSON request and full_status=1, the JSON response will
70 // contain detailed cURL status information, otherwise it will just contain
71 // the `http_code` property.
72 //
73 // Topic: POST Parameters
74 //
75 // All POST parameters are automatically passed through to the remote URL
76 // request.
77 //
78 // Topic: JSON requests
79 //
80 // This request will return the contents of the specified url in JSON format.
81 //
82 // Request:
83 //
84 // > ba-simple-proxy.php?url=http://example.com/
85 //
86 // Response:
87 //
88 // > { "contents": "<html>...</html>", "headers": {...}, "status": {...} }
89 //
90 // JSON object properties:
91 //
92 // contents - (String) The contents of the remote URL resource.
93 // headers - (Object) A hash of HTTP headers returned by the remote URL
94 // resource.
95 // status - (Object) A hash of status codes returned by cURL.
96 //
97 // Topic: JSONP requests
98 //
99 // This request will return the contents of the specified url in JSONP format
100 // (but only if $enable_jsonp is enabled in the PHP script).
101 //
102 // Request:
103 //
104 // > ba-simple-proxy.php?url=http://example.com/&callback=foo
105 //
106 // Response:
107 //
108 // > foo({ "contents": "<html>...</html>", "headers": {...}, "status": {...} })
109 //
110 // JSON object properties:
111 //
112 // contents - (String) The contents of the remote URL resource.
113 // headers - (Object) A hash of HTTP headers returned by the remote URL
114 // resource.
115 // status - (Object) A hash of status codes returned by cURL.
116 //
117 // Topic: Native requests
118 //
119 // This request will return the contents of the specified url in the format it
120 // was received in, including the same content-type and other headers (but only
121 // if $enable_native is enabled in the PHP script).
122 //
123 // Request:
124 //
125 // > ba-simple-proxy.php?url=http://example.com/&mode=native
126 //
127 // Response:
128 //
129 // > <html>...</html>
130 //
131 // Topic: Notes
132 //
133 // * Assumes magic_quotes_gpc = Off in php.ini
134 //
135 // Topic: Configuration Options
136 //
137 // These variables can be manually edited in the PHP file if necessary.
138 //
139 // $enable_jsonp - Only enable <JSONP requests> if you really need to. If you
140 // install this script on the same server as the page you're calling it
141 // from, plain JSON will work. Defaults to false.
142 // $enable_native - You can enable <Native requests>, but you should only do
143 // this if you also whitelist specific URLs using $valid_url_regex, to avoid
144 // possible XSS vulnerabilities. Defaults to false.
145 // $valid_url_regex - This regex is matched against the url parameter to
146 // ensure that it is valid. This setting only needs to be used if either
147 // $enable_jsonp or $enable_native are enabled. Defaults to '/.*/' which
148 // validates all URLs.
149 //
150 // ############################################################################
151
152
153 $_GET['mode'] = 'native';
154 $_GET['full_headers'] = 1;
155 $_GET['full_status'] = 1;
156 $_GET['send_cookies'] = 1;
157
158 // Change these configuration options if needed, see above descriptions for info.
159 $enable_jsonp = false;
160 $enable_native = true;
161 $valid_url_regex = '/.*/';
162
163 // ############################################################################
164 $url = $_GET['url'];
165
166 if ( isset( $_GET['nonce'] ) ) {
167 $url = str_replace( 'nonce=' . $_GET['nonce'] . '&', '', $url );
168 }
169
170 if ( ! $url ) {
171
172 // Passed url not specified.
173 $contents = 'ERROR: url not specified';
174 $status = array( 'http_code' => 'ERROR' );
175
176 } elseif ( ! preg_match( $valid_url_regex, $url ) ) {
177
178 // Passed url doesn't match $valid_url_regex.
179 $contents = 'ERROR: invalid url';
180 $status = array( 'http_code' => 'ERROR' );
181
182 } else {
183 $url = urldecode( $url );
184 if ( isset( $_GET['proxy'] ) ) {
185 $url .= '&proxy=' . $_GET['proxy'];
186 }
187
188 // Ad URL rewrite
189 if ( strpos( $url, 'http' ) === false ) {
190 $url = 'http:' . $url;
191 }
192
193 if ( isset( $_GET['callback'] ) ) {
194 foreach ( $_GET as $key => $value ) {
195 if ( in_array( $key, array( 'url', 'mode', 'full_headers', 'full_status', 'send_cookies' ) ) ) {
196 continue;
197 }
198 $url .= '&' . $key . '=' . $value;
199 }
200 }
201
202 $args = array(
203 'user-agent' => isset( $_GET['user_agent'] ) ? $_GET['user_agent'] : $_SERVER['HTTP_USER_AGENT'],
204 'method' => 'GET',
205 );
206
207 if ( isset( $_GET['send_cookies'] ) && $_GET['send_cookies'] ) {
208 $cookie = array();
209 foreach ( $_COOKIE as $key => $value ) {
210 $cookie[] = $key . '=' . $value;
211 }
212 if ( isset( $_GET['send_session'] ) && $_GET['send_session'] ) {
213 $cookie[] = SID;
214 }
215 $args['cookies'] = $cookie;
216
217 }
218 if ( strtolower( $_SERVER['REQUEST_METHOD'] ) == 'post' ) {
219 $args['body'] = $_POST;
220 $args['method'] = 'POST';
221
222 }
223
224 $response = wp_remote_request(
225 $url,
226 $args
227 );
228
229 if ( ! is_wp_error( $response ) ) {
230 $status = $response['response']['code'];
231 $contents = $response['body'];
232 }
233 }
234
235 if ( isset( $_GET['mode'] ) && $_GET['mode'] == 'native' ) {
236 if ( ! $enable_native ) {
237 $contents = 'ERROR: invalid mode';
238 $status = array( 'http_code' => 'ERROR' );
239 }
240
241 if ( ! is_wp_error( $response ) && isset( $response['headers']['content-type'] ) ) {
242 header( 'Content-Type: ' . $response['headers']['content-type'] );
243 }
244 if ( ! is_wp_error( $response ) && isset( $response['headers']['content-language'] ) ) {
245 header( 'Content-Language: ' . $response['headers']['content-language'] );
246 }
247 if ( ! is_wp_error( $response ) && isset( $response['headers']['set-cookie'] ) ) {
248 header( 'Set-Cookie: ' . $response['headers']['set-cookie'] );
249 }
250
251 if ( isset( $contents ) ) {
252 print str_replace( 'ads.redux.io', 'look.redux.io', $contents );
253 }
254 } else {
255
256 // $data will be serialized into JSON data.
257 $data = array();
258
259 // Propagate all HTTP headers into the JSON data object.
260 if ( isset( $_GET['full_headers'] ) && $_GET['full_headers'] ) {
261 $data['headers'] = array();
262
263 }
264
265 // Propagate all cURL request / response info to the JSON data object.
266 if ( isset( $_GET['full_status'] ) && $_GET['full_status'] ) {
267 $data['status'] = $status;
268 } else {
269 $data['status'] = array();
270 $data['status']['http_code'] = $status['http_code'];
271 }
272
273 // Set the JSON data object contents, decoding it from JSON if possible.
274 $decoded_json = json_decode( $contents );
275 $data['contents'] = str_replace( 'e(window).width()', 'window.innerWidth||e(window).width()', $decoded_json ? $decoded_json : $contents );
276
277 // Generate appropriate content-type header.
278
279 $is_xhr = isset( $_SERVER['HTTP_X_REQUESTED_WITH'] ) ? strtolower( $_SERVER['HTTP_X_REQUESTED_WITH'] ) : 'xmlhttprequest';
280 header( 'Content-type: application/' . ( $is_xhr ? 'json' : 'x-javascript' ) );
281
282 // Get JSONP callback.
283 $jsonp_callback = $enable_jsonp && isset( $_GET['callback'] ) ? $_GET['callback'] : null;
284
285 // Generate JSON/JSONP string
286 $json = json_encode( $data );
287
288 print $jsonp_callback ? "$jsonp_callback($json)" : $json;
289
290 }
291 }
292 }
293
294 new ReduxLegacy_P();
295