PluginProbe
Lasso Lite – Affiliate Link Manager & Product Displays / 116
Lasso Lite – Affiliate Link Manager & Product Displays v116
158 157 155 156 154 153 152 151 150 149 148 trunk 0.9.9 104 105 106 107 108 109 110 111 112 113 114 115 All 57 releases
← All changes | classes/class-helper.php +58 -796 158116 View file →
@@ -6,18 +6,14 @@
6 6 */
7 7
8 8 namespace LassoLite\Classes;
9 9
10 -use LassoLite\Classes\Helper\Url_Format;
11 -
12 10 use LassoLite\Admin\Constant;
13 11
14 -use LassoLite\Classes\Affiliate_Link;
15 12 use LassoLite\Classes\Amazon_Api;
16 13 use LassoLite\Classes\Cache_Per_Process;
17 14 use LassoLite\Classes\Enum;
18 15 use LassoLite\Classes\Import;
19 -use LassoLite\Classes\License;
20 16 use LassoLite\Classes\Setting;
21 17 use LassoLite\Classes\SURL;
22 18
23 19 use LassoLite\Models\Model;
@@ -29,8 +25,9 @@
29 25 /**
30 26 * Lasso_Helper
31 27 */
32 28 class Helper {
29 +
33 30 /**
34 31 * User agent
35 32 *
36 33 * @var string $user_agent
@@ -216,9 +213,12 @@
216 213 * @param string $url URL.
217 214 * @return bool
218 215 */
219 216 public static function has_protocol( $url ) {
220 - return Url_Format::has_protocol( $url );
217 + if ( strpos( $url, 'http' ) === 0 || strpos( $url, 'https' ) === 0 ) {
218 + return true;
219 + }
220 + return false;
221 221 }
222 222
223 223 /**
224 224 * Check if Classic Editor plugin is active.
@@ -259,9 +259,9 @@
259 259 /**
260 260 * Get license status in DB
261 261 */
262 262 public static function get_license_status() {
263 - $db_status = get_option( 'lasso_lite_license_status', '' );
263 + $db_status = get_option( 'lasso_license_status', '' );
264 264 $active_license = boolval( $db_status );
265 265
266 266 return $active_license;
267 267 }
@@ -304,9 +304,42 @@
304 304 *
305 305 * @param string $url URL.
306 306 */
307 307 public static function add_https( $url ) {
308 - return Url_Format::add_https( $url );
308 + $invalid_url = array(
309 + 'https://%20https:/',
310 + 'https://xhttps://',
311 + 'http:/https://',
312 + 'http://https://',
313 + 'https://https://',
314 + 'https://hhttps://',
315 + 'https://]https://',
316 + 'https://"https://',
317 + '[gift_item link="https://',
318 + ']https://',
319 + );
320 + $url = trim( $url );
321 + $url = str_replace( $invalid_url, 'https://', $url );
322 +
323 + // ? fix mailto in <a> href
324 + if ( strpos( $url, 'mailto:' ) !== false || filter_var( $url, FILTER_VALIDATE_EMAIL ) ) {
325 + $email = explode( 'mailto:', $url )[1] ?? '';
326 + if ( filter_var( $email, FILTER_VALIDATE_EMAIL ) ) {
327 + $url = 'mailto:' . $email;
328 + }
329 +
330 + return $url;
331 + }
332 +
333 + if ( '' === $url || is_null( $url ) || strpos( $url, '[' ) === 0 ) {
334 + return $url;
335 + }
336 +
337 + if ( strpos( $url, 'http://' ) !== 0 && strpos( $url, 'https://' ) !== 0 && strpos( $url, '.' ) !== false && '#' !== $url ) {
338 + $url = 'https://' . $url;
339 + }
340 +
341 + return $url;
309 342 }
310 343
311 344 /**
312 345 * Format URL before sending request
@@ -442,9 +475,9 @@
442 475 $setup_amz_tracking_id = boolval( get_option( Enum::SETUP_AMZ_TRACKING_ID ) ) ? 15 : 0;
443 476 $follow_on_twitter = boolval( get_option( Enum::FOLLOW_ON_TWITTER ) ) ? 10 : 0;
444 477 $share_on_twitter = boolval( get_option( Enum::SHARE_ON_TWITTER ) ) ? 10 : 0;
445 478 $leave_a_review = boolval( get_option( Enum::LEAVE_A_REVIEW ) ) ? 5 : 0;
446 - $is_show_review_note = ! $leave_a_review && $total_links >= 5 && $enable_support && $setup_amz_tracking_id && $follow_on_twitter && $share_on_twitter ? 1 : 0;
479 + $is_show_review_note = ! $leave_a_review && $total_links >= 20 && $enable_support && $setup_amz_tracking_id && $follow_on_twitter && $share_on_twitter ? 1 : 0;
447 480 $progress = $enable_support + $setup_amz_tracking_id + $follow_on_twitter + $share_on_twitter + ( $links * 2 ) + $leave_a_review;
448 481 $progress = $progress ? $progress / 100 : 0;
449 482 $open_modal_add_link = $links < 20 ? 'btn-add-20-links' : '';
450 483
@@ -469,74 +502,8 @@
469 502 return $data;
470 503 }
471 504
472 505 /**
473 - * Whitelist landing-cookie attribution keys for Lite plugin signup (#788).
474 - *
475 - * @param mixed $raw POST attribution object or JSON string.
476 - * @return array|null Sanitized payload or null when no signal.
477 - */
478 - public static function sanitize_signup_attribution( $raw ) {
479 - $allowed_keys = array(
480 - 'url',
481 - 'ref',
482 - 'utm_source',
483 - 'utm_medium',
484 - 'utm_campaign',
485 - 'utm_content',
486 - 'ref_code',
487 - 'dt',
488 - );
489 - $signal_keys = array(
490 - 'utm_source',
491 - 'utm_medium',
492 - 'utm_campaign',
493 - 'utm_content',
494 - 'ref_code',
495 - );
496 -
497 - if ( is_string( $raw ) ) {
498 - $raw = json_decode( $raw, true );
499 - }
500 - if ( ! is_array( $raw ) || empty( $raw ) ) {
501 - return null;
502 - }
503 -
504 - $payload = array();
505 - foreach ( $allowed_keys as $key ) {
506 - if ( ! isset( $raw[ $key ] ) || ! is_scalar( $raw[ $key ] ) ) {
507 - continue;
508 - }
509 - $text = trim( (string) $raw[ $key ] );
510 - if ( '' === $text ) {
511 - continue;
512 - }
513 - if ( in_array( $key, array( 'url', 'ref' ), true ) ) {
514 - $payload[ $key ] = substr( $text, 0, 2048 );
515 - } else {
516 - $payload[ $key ] = substr( $text, 0, 500 );
517 - }
518 - }
519 -
520 - if ( empty( $payload ) ) {
521 - return null;
522 - }
523 -
524 - $has_signal = false;
525 - foreach ( $signal_keys as $key ) {
526 - if ( ! empty( $payload[ $key ] ) ) {
527 - $has_signal = true;
528 - break;
529 - }
530 - }
531 - if ( ! $has_signal && empty( $payload['url'] ) ) {
532 - return null;
533 - }
534 -
535 - return $payload;
536 - }
537 -
538 - /**
539 506 * Send request
540 507 *
541 508 * @param string $method Method (get or post). Default to get.
542 509 * @param string $url URL. Default to empty.
@@ -566,19 +533,11 @@
566 533 $res = wp_remote_request( $url, $request_options );
567 534 }
568 535
569 536 if ( is_wp_error( $res ) ) {
570 - // Return structured info so callers can surface what failed (e.g. cURL error).
571 - $error_payload = array(
572 - 'error' => array(
573 - 'code' => $res->get_error_code(),
574 - 'message' => $res->get_error_message(),
575 - 'data' => $res->get_error_data(),
576 - ),
577 - );
578 537 return array(
579 538 'status_code' => 500,
580 - 'response' => json_decode( wp_json_encode( $error_payload ) ),
539 + 'response' => array(),
581 540 );
582 541 }
583 542
584 543 $body = wp_remote_retrieve_body( $res );
@@ -590,38 +549,8 @@
590 549 );
591 550 }
592 551
593 552 /**
594 - * Plain-text error from send_request() output (WP_Error payload or API JSON body).
595 - *
596 - * @param array $response Return value from send_request().
597 - * @param string $default Default message.
598 - * @return string
599 - */
600 - public static function hub_request_error_message( $response, $default = 'Request failed.' ) {
601 - $default = (string) $default;
602 - if ( empty( $response ) || ! is_array( $response ) ) {
603 - return $default;
604 - }
605 - $r = $response['response'] ?? null;
606 - if ( empty( $r ) || ! is_object( $r ) ) {
607 - return $default;
608 - }
609 - if ( isset( $r->error ) ) {
610 - if ( is_object( $r->error ) && isset( $r->error->message ) ) {
611 - return (string) $r->error->message;
612 - }
613 - if ( is_string( $r->error ) && $r->error !== '' ) {
614 - return $r->error;
615 - }
616 - }
617 - if ( isset( $r->message ) && is_string( $r->message ) && $r->message !== '' ) {
618 - return $r->message;
619 - }
620 - return $default;
621 - }
622 -
623 - /**
624 553 * Get Lasso Lite - WP option
625 554 *
626 555 * @param string $option_name Option name.
627 556 * @param mixed $default Default value.
@@ -648,45 +577,17 @@
648 577 *
649 578 * @param string $url URL.
650 579 */
651 580 public static function validate_url( $url ) {
652 - return Url_Format::validate_url( $url );
653 - }
654 -
655 - /**
656 - * Remove specific parameters from URL
657 - *
658 - * @param string $url URL to clean.
659 - * @param array|string $params Parameter(s) to remove.
660 - * @return string Cleaned URL
661 - */
662 - public static function remove_url_params( $url, $params ) {
663 - $parsed_url = wp_parse_url( $url );
664 -
665 - if ( ! isset( $parsed_url['query'] ) ) {
666 - return $url;
581 + if ( ! is_string( $url ) ) {
582 + return false;
667 583 }
668 584
669 - parse_str( $parsed_url['query'], $query_params );
585 + $url = str_replace( ' ', '%20', $url );
586 + $url = preg_replace( '/[^\00-\255]+/u', '', $url );
670 587
671 - // ? Handle both array and single parameter
672 - $params = (array) $params;
673 - foreach ( $params as $param ) {
674 - unset( $query_params[ $param ] );
675 - }
676 -
677 - // ? Rebuild URL
678 - $clean_url = $parsed_url['scheme'] . '://' . $parsed_url['host'] . $parsed_url['path'];
679 - if ( ! empty( $query_params ) ) {
680 - $clean_url .= '?' . http_build_query( $query_params );
681 - }
682 -
683 - // ? Add fragment if exists
684 - if ( isset( $parsed_url['fragment'] ) ) {
685 - $clean_url .= '#' . $parsed_url['fragment'];
686 - }
687 -
688 - return $clean_url;
588 + return ( ( strpos( $url, 'http://' ) === 0 || strpos( $url, 'https://' ) === 0 ) &&
589 + filter_var( $url, FILTER_VALIDATE_URL ) !== false );
689 590 }
690 591
691 592 /**
692 593 * Get argument from url
@@ -905,19 +806,13 @@
905 806 if ( empty( $p->import_permalink ) ) {
906 807 $p->import_permalink = $lasso_amazon_api->get_amazon_link_by_product_id( $p->id );
907 808 }
908 809 } elseif ( 'Lasso Pro' === $p->import_source ) {
909 - $target_url = Import::get_lasso_pro_target_url( $p->id );
910 - $p->import_permalink = $target_url;
911 - $p->shortcode = '[lasso rel="' . $p->post_name . '" id="' . $p->id . '"]';
810 + $target_url = Import::get_lasso_pro_target_url( $p->id );
811 + $p->import_permalink = $target_url;
812 + $p->shortcode = '[lasso rel="' . $p->post_name . '" id="' . $p->id . '"]';
912 813 }
913 814
914 - $p->post_title_attr = esc_attr( $p->post_title ?? '' );
915 - $p->import_permalink_attr = esc_attr( $p->import_permalink ?? '' );
916 - if ( ! empty( $p->shortcode ) ) {
917 - $p->shortcode_attr = esc_attr( $p->shortcode );
918 - }
919 -
920 815 return $p;
921 816 }
922 817
923 818 /**
@@ -1147,9 +1042,9 @@
1147 1042 */
1148 1043 public static function is_wordpress_post() {
1149 1044 global $pagenow;
1150 1045
1151 - $get = self::GET(); // phpcs:ignore
1046 + $get = wp_unslash( $_GET ); // phpcs:ignore
1152 1047 $action = $get['action'] ?? '';
1153 1048 $add_new_page = 'post-new.php' === $pagenow;
1154 1049 $edit_page = 'post.php' === $pagenow && 'edit' === $action;
1155 1050 $post_type = $get['post_type'] ?? '';
@@ -1322,87 +1217,8 @@
1322 1217 return ! empty( ( new Lasso_DB() )->get_import_plugins( true ) ) ? true : false;
1323 1218 }
1324 1219
1325 1220 /**
1326 - * Ordered onboarding step ids (tab-item data-step values).
1327 - *
1328 - * @return string[]
1329 - */
1330 - public static function get_onboarding_step_ids() {
1331 - return array( 'welcome', 'display', 'amazon', 'connect-lasso', 'import' );
1332 - }
1333 -
1334 - /**
1335 - * @param string $step Step id.
1336 - * @return bool
1337 - */
1338 - public static function is_valid_onboarding_step( $step ) {
1339 - return in_array( $step, self::get_onboarding_step_ids(), true );
1340 - }
1341 -
1342 - /**
1343 - * Last saved onboarding tab for in-progress FTUE.
1344 - *
1345 - * @param bool $include_import Whether the import step is available for this install.
1346 - * @return string
1347 - */
1348 - public static function get_onboarding_current_step( $include_import = true ) {
1349 - $step = (string) self::get_option( Enum::ONBOARDING_CURRENT_STEP, '' );
1350 - if ( ! self::is_valid_onboarding_step( $step ) ) {
1351 - return 'welcome';
1352 - }
1353 - if ( 'import' === $step && ! $include_import ) {
1354 - return 'connect-lasso';
1355 - }
1356 - return $step;
1357 - }
1358 -
1359 - /**
1360 - * @param string $step Step id.
1361 - * @return bool
1362 - */
1363 - public static function save_onboarding_current_step( $step ) {
1364 - if ( ! self::is_valid_onboarding_step( $step ) ) {
1365 - return false;
1366 - }
1367 - return self::update_option( Enum::ONBOARDING_CURRENT_STEP, $step );
1368 - }
1369 -
1370 - /**
1371 - * @return bool
1372 - */
1373 - public static function clear_onboarding_current_step() {
1374 - return self::update_option( Enum::ONBOARDING_CURRENT_STEP, '' );
1375 - }
1376 -
1377 - /**
1378 - * FTUE gate complete: stop redirecting to onboarding and drop saved step.
1379 - *
1380 - * Cleared after first link creation or an explicit Hub Connect skip.
1381 - *
1382 - * @return void
1383 - */
1384 - public static function mark_onboarding_welcome_complete() {
1385 - self::update_option( Enum::IS_VISITED_WELCOME_PAGE, 1 );
1386 - self::clear_onboarding_current_step();
1387 - }
1388 -
1389 - /**
1390 - * Reset FTUE onboarding state for QA (`reset-onboarding=1`).
1391 - *
1392 - * @return void
1393 - */
1394 - public static function reset_onboarding_for_testing() {
1395 - self::update_option( Enum::IS_VISITED_WELCOME_PAGE, 0 );
1396 - self::clear_onboarding_current_step();
1397 - update_option( Enum::LASSO_LITE_ACTIVE, 1 );
1398 - self::update_option( Constant::LASSO_ACCOUNT_EMAIL, '' );
1399 - self::update_option( Constant::LASSO_ACCOUNT_API_KEY, '' );
1400 - self::update_option( Constant::LASSO_ACCOUNT_USER_ID, 0 );
1401 - self::update_option( Constant::LASSO_OPTION_IS_CONNECTED_AFFILIATE, '0' );
1402 - }
1403 -
1404 - /**
1405 1221 * Get brag icon
1406 1222 *
1407 1223 * @param bool $force_to_show Force to show the brag. Default to false.
1408 1224 */
@@ -1415,10 +1231,9 @@
1415 1231 }
1416 1232
1417 1233 $lasso_settings = Setting::get_settings();
1418 1234
1419 - // Brag mode is always enabled in Lite.
1420 - $enable_brag_mode = true;
1235 + $enable_brag_mode = $lasso_settings['enable_brag_mode'] ?? false;
1421 1236 $lasso_url = $lasso_settings['lasso_affiliate_URL'] ?? false;
1422 1237
1423 1238 if ( $lasso_url && ( $force_to_show || $enable_brag_mode ) ) {
1424 1239 $icon_brag = esc_url( SIMPLE_URLS_URL . '/admin/assets/images/lasso-icon-brag.svg' );
@@ -1424,10 +1239,10 @@
1424 1239 $icon_brag = esc_url( SIMPLE_URLS_URL . '/admin/assets/images/lasso-icon-brag.svg' );
1425 1240 $lasso_affiliate_url = self::add_params_to_url( $lasso_url, array( 'utm_source' => 'brag' ) );
1426 1241 $img_attr = self::build_img_lazyload_attributes();
1427 1242 $icon = '
1428 - <a class="lasso-brag" href="' . esc_url( $lasso_affiliate_url ) . '" target="_blank" rel="nofollow noindex">
1429 - <img src="' . esc_url( $icon_brag ) . '" ' . $img_attr . ' alt="Lasso Brag" width="30" height="30">
1243 + <a class="lasso-brag" href="' . $lasso_affiliate_url . '" target="_blank" rel="nofollow noindex">
1244 + <img src="' . $icon_brag . '" ' . $img_attr . ' alt="Lasso Brag" width="30" height="30">
1430 1245 </a>
1431 1246 ';
1432 1247
1433 1248 Cache_Per_Process::get_instance()->set_cache( $cache_key, $icon );
@@ -1453,8 +1268,9 @@
1453 1268 $query = self::get_query_from_array( $query );
1454 1269 $parse['query'] = $query;
1455 1270
1456 1271 return self::get_url_from_parse( $parse );
1272 +
1457 1273 }
1458 1274
1459 1275 /**
1460 1276 * Get final url in the url
@@ -1558,32 +1374,8 @@
1558 1374 return true;
1559 1375 }
1560 1376
1561 1377 /**
1562 - * CSS custom properties for Lasso display colors (shared admin + block editor iframe).
1563 - *
1564 - * @param bool $important Append `!important` to each variable value.
1565 - * @return string
1566 - */
1567 - public static function get_lasso_display_css_variables( $important = false ) {
1568 - $settings = Setting::get_settings();
1569 - $suffix = $important ? ' !important' : '';
1570 -
1571 - // @codingStandardsIgnoreStart
1572 - return ':root{
1573 - --lasso-main: ' . $settings['display_color_main'] . $suffix . ';
1574 - --lasso-title: ' . $settings['display_color_title'] . $suffix . ';
1575 - --lasso-button: ' . $settings['display_color_button'] . $suffix . ';
1576 - --lasso-secondary-button: ' . $settings['display_color_secondary_button'] . $suffix . ';
1577 - --lasso-button-text: ' . $settings['display_color_button_text'] . $suffix . ';
1578 - --lasso-background: ' . $settings['display_color_background'] . $suffix . ';
1579 - --lasso-pros: ' . $settings['display_color_pros'] . $suffix . ';
1580 - --lasso-cons: ' . $settings['display_color_cons'] . $suffix . ';
1581 - }';
1582 - // @codingStandardsIgnoreEnd
1583 - }
1584 -
1585 - /**
1586 1378 * Whether show Request Review at the top of the page
1587 1379 */
1588 1380 public static function show_request_review() {
1589 1381 $link_count = SURL::total();
@@ -1591,11 +1383,10 @@
1591 1383 $lasso_review_allow = self::cast_to_boolean( self::get_option( Constant::LASSO_OPTION_REVIEW_ALLOW, '1' ) );
1592 1384 $lasso_review_snooze = self::cast_to_boolean( self::get_option( Constant::LASSO_OPTION_REVIEW_SNOOZE, '0' ) );
1593 1385 $lasso_review_link_count = intval( self::get_option( Constant::LASSO_OPTION_REVIEW_LINK_COUNT, $link_count ) );
1594 1386
1595 - // Ask after early success (enough links to be real usage), not after a large catalog.
1596 - $show = ! $lasso_review_snooze && $link_count >= 5;
1597 - $snooze_but_show = $lasso_review_snooze && $link_count - $lasso_review_link_count >= 5;
1387 + $show = ! $lasso_review_snooze && $link_count >= 20;
1388 + $snooze_but_show = $lasso_review_snooze && $link_count - $lasso_review_link_count >= 20;
1598 1389
1599 1390 if ( ! $lasso_review_allow ) {
1600 1391 return false;
1601 1392 }
@@ -1607,109 +1398,8 @@
1607 1398 return false;
1608 1399 }
1609 1400
1610 1401 /**
1611 - * Whether to show the Amazon Creators API migration notice (legacy PA-API keys not required).
1612 - *
1613 - * @return bool
1614 - */
1615 - public static function show_amazon_credentials_notice() {
1616 - $dismissed = self::cast_to_boolean( self::get_option( Constant::LASSO_OPTION_AMAZON_CREDENTIALS_NOTICE_DISMISSED, '0' ) );
1617 - $dismissed_final = self::cast_to_boolean( self::get_option( Constant::LASSO_OPTION_AMAZON_CREDENTIALS_NOTICE_DISMISSED_FINAL, '0' ) );
1618 - $updated = self::cast_to_boolean( self::get_option( Constant::LASSO_OPTION_AMAZON_CREDENTIALS_UPDATED, '0' ) );
1619 -
1620 - $settings = Setting::get_settings();
1621 - $creators_credential_id = trim( (string) ( $settings['amazon_creators_credential_id'] ?? '' ) );
1622 - $creators_secret = trim( (string) ( $settings['amazon_creators_secret'] ?? '' ) );
1623 - $creators_version = trim( (string) ( $settings['amazon_creators_version'] ?? '' ) );
1624 - $creators_partner_tag = trim( (string) ( $settings['amazon_creators_partner_tag'] ?? '' ) );
1625 - $has_creators_credentials = '' !== $creators_credential_id
1626 - && '' !== $creators_secret
1627 - && '' !== $creators_version
1628 - && '' !== $creators_partner_tag;
1629 -
1630 - $dismissed_fully = $dismissed && $dismissed_final;
1631 -
1632 - return ! $dismissed_fully && ! $updated && ! $has_creators_credentials;
1633 - }
1634 -
1635 - /**
1636 - * Whether the stored thumbnail is still the default placeholder.
1637 - *
1638 - * @param string $stored_thumbnail Post meta thumbnail.
1639 - * @return bool
1640 - */
1641 - private static function uses_default_thumbnail( $stored_thumbnail ) {
1642 - $stored_thumbnail = (string) $stored_thumbnail;
1643 -
1644 - if ( '' === $stored_thumbnail ) {
1645 - return true;
1646 - }
1647 -
1648 - if ( false !== strpos( $stored_thumbnail, Constant::DEFAULT_THUMBNAIL ) ) {
1649 - return true;
1650 - }
1651 -
1652 - return false !== strpos( $stored_thumbnail, 'lasso-no-thumbnail.jpg' );
1653 - }
1654 -
1655 - /**
1656 - * Whether the footer credentials banner should block the upsell CTA.
1657 - *
1658 - * The upsell may show after the customer dismisses the banner once, even if the
1659 - * banner reappears on a later page load until the second dismiss is recorded.
1660 - *
1661 - * @return bool
1662 - */
1663 - private static function amazon_credentials_banner_blocks_upsell() {
1664 - if ( ! self::show_amazon_credentials_notice() ) {
1665 - return false;
1666 - }
1667 -
1668 - $dismissed_once = self::cast_to_boolean(
1669 - self::get_option( Constant::LASSO_OPTION_AMAZON_CREDENTIALS_NOTICE_DISMISSED, '0' )
1670 - );
1671 -
1672 - return ! $dismissed_once;
1673 - }
1674 -
1675 - /**
1676 - * Whether to show the Get Amazon Images upsell on URL Details.
1677 - *
1678 - * @param bool $is_amazon_link Whether the link is an Amazon URL.
1679 - * @param string $stored_thumbnail Post meta thumbnail (before Amazon DB enrichment).
1680 - * @param bool $is_amazon_configured Whether valid Amazon API credentials exist.
1681 - * @return bool
1682 - */
1683 - public static function should_show_get_amazon_images_upsell( $is_amazon_link, $stored_thumbnail, $is_amazon_configured ) {
1684 - if ( ! $is_amazon_link || $is_amazon_configured ) {
1685 - return false;
1686 - }
1687 -
1688 - if ( ! self::uses_default_thumbnail( $stored_thumbnail ) ) {
1689 - return false;
1690 - }
1691 -
1692 - return ! self::amazon_credentials_banner_blocks_upsell();
1693 - }
1694 -
1695 - /**
1696 - * Whether the URL Details upsell should render hidden until the credentials banner is dismissed.
1697 - *
1698 - * @param bool $is_amazon_link Whether the link is an Amazon URL.
1699 - * @param string $stored_thumbnail Post meta thumbnail (before Amazon DB enrichment).
1700 - * @param bool $is_amazon_configured Whether valid Amazon API credentials exist.
1701 - * @return bool
1702 - */
1703 - public static function should_defer_get_amazon_images_upsell( $is_amazon_link, $stored_thumbnail, $is_amazon_configured ) {
1704 - if ( ! $is_amazon_link || $is_amazon_configured || ! self::uses_default_thumbnail( $stored_thumbnail ) ) {
1705 - return false;
1706 - }
1707 -
1708 - return self::amazon_credentials_banner_blocks_upsell();
1709 - }
1710 -
1711 - /**
1712 1402 * Get Ajax URL
1713 1403 */
1714 1404 public static function get_ajax_url() {
1715 1405 return admin_url( 'admin-ajax.php' );
@@ -1740,64 +1430,8 @@
1740 1430 return isset( $matches[0] ) ? str_replace( ',', '.', $matches[0] ) : '';
1741 1431 }
1742 1432
1743 1433 /**
1744 - * Get status from BLS
1745 - *
1746 - * @param string $url URL.
1747 - * @param bool $get_res Get response or not. Default to false.
1748 - * @param bool $is_lasso_save Is Lasso save data action. Default to false.
1749 - * @param bool $url_version_param Is add version param to request api url to ignore cache. Default to false.
1750 - * @param bool $force_bls Force fetch product from BLS or not. Default to false.
1751 - * @param bool $refresh_image Bypass cache and fetch fresh product image/metadata. Default to false.
1752 - */
1753 - public static function get_url_status_code_by_broken_link_service( $url, $get_res = false, $is_lasso_save = false, $url_version_param = false, $force_bls = false, $refresh_image = false ) {
1754 - $status = 200;
1755 - $url = Amazon_Api::get_amazon_product_url( $url, false );
1756 - $url = self::format_url_before_requesting( $url );
1757 -
1758 - $headers = self::get_headers();
1759 - $query = array(
1760 - 'url' => $url,
1761 - );
1762 -
1763 - if ( $url_version_param ) {
1764 - $query['ver'] = time();
1765 - }
1766 -
1767 - if ( $force_bls ) {
1768 - $query['force_bls'] = 1;
1769 - }
1770 -
1771 - if ( $refresh_image ) {
1772 - $query['refresh_image'] = 1;
1773 - }
1774 -
1775 - $request_url = Constant::LASSO_LINK . '/link/status/?' . http_build_query( $query, '', '&', PHP_QUERY_RFC3986 );
1776 - if ( ! $is_lasso_save && defined( 'DOING_CRON' ) && DOING_CRON && ! Cron::should_send_scheduled_data_request( $url ) ) {
1777 - return $get_res ? array(
1778 - 'status_code' => 200,
1779 - 'response' => array(),
1780 - ) : 200;
1781 - }
1782 - Cron::maybe_pace_background_request( $url, $is_lasso_save );
1783 - $res = self::send_request( 'get', $request_url, array(), $headers );
1784 -
1785 - // phpcs:ignore
1786 - // $res = self::send_request( 'get', LASSO_LINK . '/link/status/?' . $encrypted_base64, array(), $headers );
1787 - if ( $get_res ) {
1788 - return $res;
1789 - }
1790 -
1791 - $bls_response = $res['response'] ?? null;
1792 - if ( ! is_object( $bls_response ) ) {
1793 - return 500;
1794 - }
1795 -
1796 - return intval( $bls_response->status ?? $status );
1797 - }
1798 -
1799 - /**
1800 1434 * Get currency symbol from ISO currency code
1801 1435 *
1802 1436 * @param string $iso Iso currency code.
1803 1437 * @return string
@@ -1855,378 +1489,6 @@
1855 1489 }
1856 1490
1857 1491 $query = str_replace( ' ', '%', $query );
1858 1492 return $query;
1859 - }
1860 -
1861 - /**
1862 - * Sanitize HTML for safe display (formerly regex-based script strip).
1863 - * Now delegates to wp_kses_post so event handlers and javascript: URLs are removed.
1864 - *
1865 - * Falsy input (null, false, empty string) is returned unchanged.
1866 - *
1867 - * @param string|null|false $html HTML code.
1868 - * @return string|null|false Sanitized HTML, or the original falsy value.
1869 - */
1870 - public static function sanitize_script( $html ) {
1871 - if ( ! $html ) {
1872 - return $html;
1873 - }
1874 -
1875 - return wp_kses_post( (string) $html );
1876 - }
1877 -
1878 - /**
1879 - * Verify access and nonce, then return wp_send_json_error if unverified.
1880 - *
1881 - * @param bool $allow_edit_post_access Allow access for editor, author, contributor.
1882 - * @return void
1883 - */
1884 - public static function verify_access_and_nonce( $allow_edit_post_access = false ) {
1885 - try {
1886 - // ? Verify access token.
1887 - if ( ! current_user_can( 'manage_options' ) ) {
1888 - if ( $allow_edit_post_access ) {
1889 - // ? Allow access for editor, author, contributor.
1890 - // ? WP User Roles: https://wordpress.com/support/invite-people/user-roles/#:~:text=Editor%3A%20Has%20access%20to%20all,posts%20until%20they%20are%20published.
1891 - $current_user_role = self::get_current_user_role();
1892 - if ( ! in_array( $current_user_role, array( 'editor', 'author', 'contributor' ), true ) ) {
1893 - wp_send_json_error( 'Access denied.' );
1894 - }
1895 - } else {
1896 - wp_send_json_error( 'Access denied.' );
1897 - }
1898 - }
1899 -
1900 - // ? Verify nonce.
1901 - $data = array();
1902 - $server = wp_unslash( $_SERVER );
1903 - $method = $server['REQUEST_METHOD'] ?? '';
1904 - if ( 'POST' === $method ) {
1905 - $data = self::POST();
1906 - } elseif ( 'GET' === $method ) {
1907 - $data = self::GET();
1908 - }
1909 -
1910 - $nonce = $data['nonce'] ?? '';
1911 - if ( false === wp_verify_nonce( $nonce, Constant::LASSO_LITE_NONCE . wp_salt() ) ) {
1912 - wp_send_json_error( 'Nonce not verified.' );
1913 - }
1914 - } catch ( WPAjaxDieStopException $e ) {
1915 - throw $e;
1916 - } catch ( \Exception $e ) {
1917 - wp_send_json_error( 'Verify access and nonce error.' );
1918 - }
1919 - }
1920 -
1921 - /**
1922 - * Get current user role
1923 - *
1924 - * @return string
1925 - */
1926 - public static function get_current_user_role() {
1927 - if ( is_user_logged_in() ) {
1928 - $user = wp_get_current_user();
1929 - $roles = (array) $user->roles;
1930 -
1931 - return $roles[0];
1932 - } else {
1933 - return 'guest';
1934 - }
1935 - }
1936 -
1937 - /**
1938 - * Build headers for Lasso API
1939 - *
1940 - * @param string $license_id License ID. Default to null.
1941 - * @return array
1942 - */
1943 - public static function get_headers( $license_id = null ) {
1944 - $license = $license_id ? $license_id : License::get_license();
1945 - if ( ! is_string( $license ) && ! is_numeric( $license ) ) {
1946 - $license = '';
1947 - }
1948 - $license = (string) $license;
1949 -
1950 - $site_id = License::get_site_id();
1951 - if ( ! is_string( $site_id ) && ! is_numeric( $site_id ) ) {
1952 - $site_id = '';
1953 - }
1954 - $site_id = (string) $site_id;
1955 -
1956 - $headers = array(
1957 - 'Content-Type' => 'application/json',
1958 - 'license' => $license,
1959 - 'site_id' => $site_id,
1960 - 'site_url' => rawurlencode( site_url() ),
1961 - 'is_lasso_lite' => '1',
1962 - 'email' => (string) get_option( 'admin_email', '' ),
1963 - );
1964 -
1965 - return $headers;
1966 - }
1967 -
1968 - /**
1969 - * Build lsid
1970 - *
1971 - * @return false|string
1972 - */
1973 - public static function build_lsid() {
1974 - $lsid = session_create_id( 'ls-' );
1975 - if ( ! $lsid ) {
1976 - $lsid = 'ls-' . md5( uniqid( wp_rand(), true ) );
1977 - }
1978 -
1979 - return $lsid;
1980 - }
1981 -
1982 - /**
1983 - * Check if WP Elementor plugin is active.
1984 - *
1985 - * @return bool
1986 - */
1987 - public static function is_wp_elementor_plugin_actived() {
1988 - return self::get_is_plugin_active( 'elementor/elementor.php' );
1989 - }
1990 -
1991 - /**
1992 - * FOLLOW ALL REDIRECTS
1993 - * This makes multiple requests, following each redirect until it reaches the final destination.
1994 - *
1995 - * @param string $url URL.
1996 - * @param bool $is_lasso_save Is Lasso save data action. Default to false.
1997 - * @param bool $get_page_title Get page title or not. Default to false.
1998 - */
1999 - public static function get_redirect_final_target( $url, $is_lasso_save = false, $get_page_title = false ) {
2000 - // ? Get final url for amazon shortlink from cache
2001 - $amazon_shortlink_final_url_cached = Amazon_Api::get_shortlink_final_url_cached( $url );
2002 - if ( $amazon_shortlink_final_url_cached ) {
2003 - return $get_page_title ? array( $amazon_shortlink_final_url_cached, get_option( Amazon_Api::build_shortlink_cache_key( $url ) . '_page_title' ) ) : $amazon_shortlink_final_url_cached;
2004 - }
2005 -
2006 - $origin_url = $url;
2007 - $url = Amazon_Api::get_amazon_product_url( $url, $is_lasso_save ? true : false );
2008 - $url = self::format_url_before_requesting( $url );
2009 - $base_domain = self::get_base_domain( $url );
2010 - $browser = self::get_server_param( 'HTTP_USER_AGENT' );
2011 - $browser = '' !== $browser ? $browser : self::$user_agent;
2012 - $use_bls = apply_filters( 'get_final_url_domain_bls', false, $url );
2013 -
2014 - $cache_prefix = 'get_final_url_';
2015 - $page_title = '';
2016 -
2017 - // ? check result in cache first, it may be use before in the same request.
2018 - $final_url_cache = Cache_Per_Process::get_instance()->get_cache( $cache_prefix . md5( $url ) . $get_page_title );
2019 - if ( $final_url_cache ) {
2020 - return $final_url_cache;
2021 - }
2022 - if ( Amazon_Api::is_amazon_url( $url ) && Amazon_Api::get_product_id_by_url( $url ) ) {
2023 - return $get_page_title ? array( $url, $page_title ) : $url;
2024 - }
2025 -
2026 - $res = wp_remote_get(
2027 - $url,
2028 - array(
2029 - 'headers' => array(
2030 - 'user-agent' => $browser,
2031 - ),
2032 - )
2033 - );
2034 -
2035 - $is_amazon_shortened_url = Amazon_Api::is_amazon_shortened_url( $url );
2036 -
2037 - $status_code = is_wp_error( $res ) ? 500 : $res['response']['code'] ?? '';
2038 - if ( 200 === $status_code || 429 === $status_code ) {
2039 - $new_url = $res['http_response']->get_response_object()->url;
2040 - $use_bls = apply_filters( 'get_final_url_domain_bls', false, $new_url );
2041 - }
2042 -
2043 - if ( $is_amazon_shortened_url ) {
2044 - $use_bls = true;
2045 - }
2046 -
2047 - if ( is_wp_error( $res ) || $use_bls || 403 === $status_code ) {
2048 - $allow_bls = $is_lasso_save
2049 - || ! defined( 'DOING_CRON' )
2050 - || ! DOING_CRON
2051 - || Cron::should_send_scheduled_data_request( $url );
2052 - if ( ! $allow_bls ) {
2053 - $result = $get_page_title ? array( $url, $page_title ) : $url;
2054 - Cache_Per_Process::get_instance()->set_cache( $cache_prefix . md5( $url ) . $get_page_title, $result );
2055 - return $result;
2056 - }
2057 - $headers = self::get_headers();
2058 - $data = array(
2059 - 'url' => $url,
2060 - );
2061 - $encrypted_base64 = http_build_query( $data );
2062 - Cron::maybe_pace_background_request( $url, $is_lasso_save );
2063 - $res = self::send_request( 'get', Constant::LASSO_LINK . '/link/final-url/?' . $encrypted_base64, array(), $headers );
2064 -
2065 - $bls_response = ( isset( $res['response'] ) && is_object( $res['response'] ) ) ? $res['response'] : null;
2066 - $final_url = ( null !== $bls_response ) ? ( $bls_response->finalUrl ?? $url ) : $url;
2067 - $page_title = ( null !== $bls_response ) ? ( $bls_response->pageTitle ?? '' ) : '';
2068 -
2069 - $bls_status = ( null !== $bls_response && isset( $bls_response->status ) ) ? intval( $bls_response->status ) : 0;
2070 - if ( $bls_status ) {
2071 - $response_status = $bls_status;
2072 - } elseif ( 200 === intval( $res['status_code'] ?? 0 ) ) {
2073 - $response_status = 500;
2074 - } else {
2075 - $response_status = intval( $res['status_code'] ?? 500 );
2076 - }
2077 -
2078 - // ? Set the response status code for add new link process
2079 - Cache_Per_Process::get_instance()->set_cache( Affiliate_Link::ADD_NEW_LINK_RESPONSE_STATUS . md5( $origin_url ), $response_status );
2080 -
2081 - $tmp_url = self::get_final_url_from_url_param( $final_url );
2082 - if ( $tmp_url ) {
2083 - $page_title = self::get_title_by_url( $tmp_url );
2084 - $final_url = $tmp_url;
2085 - }
2086 -
2087 - // ? cache result
2088 - $result = $get_page_title ? array( $final_url, $page_title ) : $final_url;
2089 - Cache_Per_Process::get_instance()->set_cache( $cache_prefix . md5( $url ) . $get_page_title, $result );
2090 -
2091 - // ? Cache the final url of amazon shortlink
2092 - if ( $is_amazon_shortened_url ) {
2093 - $shortlink_cache_key = Amazon_Api::build_shortlink_cache_key( $url );
2094 - update_option( $shortlink_cache_key, $final_url );
2095 - // ? Cache the page title of amazon shortlink
2096 - update_option( $shortlink_cache_key . '_page_title', $page_title );
2097 - }
2098 -
2099 - return $result;
2100 - }
2101 -
2102 - $http_response = $res['http_response']->get_response_object();
2103 - $status = wp_remote_retrieve_response_code( $res );
2104 -
2105 - // ? Set the response status code for add new link process
2106 - Cache_Per_Process::get_instance()->set_cache( Affiliate_Link::ADD_NEW_LINK_RESPONSE_STATUS . md5( $origin_url ), $status );
2107 -
2108 - $final_url = $http_response->url;
2109 - $page_title = self::get_page_title( $http_response->body );
2110 - if ( strpos( $page_title, 'Please Wait...' ) !== false
2111 - || strpos( $page_title, 'Cloudflare' ) !== false
2112 - || strpos( $page_title, 'Access Denied' ) !== false
2113 - || strpos( $page_title, 'Just a moment...' ) !== false
2114 - ) {
2115 - $page_title = self::get_title_by_url( $final_url );
2116 - }
2117 -
2118 - $tmp_url = self::get_final_url_from_url_param( $final_url );
2119 - if ( $tmp_url ) {
2120 - $page_title = self::get_title_by_url( $tmp_url );
2121 - $final_url = $tmp_url;
2122 - }
2123 -
2124 - // ? Cache the final url of amazon shortlink
2125 - if ( $is_amazon_shortened_url ) {
2126 - $shortlink_cache_key = Amazon_Api::build_shortlink_cache_key( $url );
2127 - update_option( $shortlink_cache_key, $final_url );
2128 - // ? Cache the page title of amazon shortlink
2129 - update_option( $shortlink_cache_key . '_page_title', $page_title );
2130 - }
2131 -
2132 - if ( ! $page_title || Affiliate_Link::DEFAULT_TITLE === $page_title ) {
2133 - $page_title = self::get_title_by_url( $final_url );
2134 - }
2135 -
2136 - // ? cache result
2137 - $result = $get_page_title ? array( $final_url, $page_title ) : $final_url;
2138 - Cache_Per_Process::get_instance()->set_cache( $cache_prefix . md5( $url ) . $get_page_title, $result );
2139 -
2140 - return $result;
2141 - }
2142 -
2143 - /**
2144 - * Get page title from HTML
2145 - *
2146 - * @param string $html HTML string.
2147 - */
2148 - public static function get_page_title( $html ) {
2149 - $temp = explode( '<title', $html )[1] ?? '';
2150 - $html = $temp ? '<title' . $temp : $html;
2151 - $temp = explode( '</title>', $html )[0] ?? '';
2152 - $html = $temp ? $temp . '</title>' : $html;
2153 - $res = preg_match( '/<title\s*(.*?)>(.*?)<\/title>/siU', $html, $title_matches );
2154 - if ( ! $res ) {
2155 - return '';
2156 - }
2157 -
2158 - // ? Clean up title: remove EOL's and excessive whitespace.
2159 - $title = preg_replace( '/\s+/', ' ', $title_matches[2] ?? '' );
2160 - // ? String – to UTF8 is \xe2\x80\x93, replace by -
2161 - $title = str_replace( '–', '-', $title );
2162 - // ? Remove all non-US-ASCII (i.e. outside 0x0-0x7F) characters
2163 - $title = preg_replace( '/[^\x00-\x7F]/', '', $title );
2164 - $title = trim( $title );
2165 - $title = self::format_post_title( $title );
2166 -
2167 - return $title;
2168 - }
2169 -
2170 - /**
2171 - * Build the dynamic query variable name for serving the performance snippet.
2172 - *
2173 - * Derive a domain-specific key to reduce collisions and support per-domain routing.
2174 - *
2175 - * @return string Query var name (md5 hash of the base domain)
2176 - */
2177 - public static function get_snippet_query() {
2178 - $domain = self::get_base_domain( site_url() );
2179 - if ( empty( $domain ) ) {
2180 - return 'lasso_connect_snippet_lite';
2181 - }
2182 - return md5( $domain );
2183 - }
2184 -
2185 - /**
2186 - * Derive Intercom user_id from email with optional JWT override.
2187 - * If a JWT with a non-empty `user_id` claim is present, that value is used;
2188 - * otherwise the md5 hash of the lowercased+trimmed email is returned.
2189 - * Callers may pass raw or pre-normalized email; the function normalizes
2190 - * defensively to keep the derived user_id deterministic.
2191 - *
2192 - * @param string $user_email Email (raw or pre-normalized); trimmed and lowercased internally.
2193 - * @param string $intercom_user_jwt Optional Intercom JWT token used to override
2194 - * the email-based user_id when valid.
2195 - *
2196 - * @return string Intercom user_id derived from JWT or email hash.
2197 - */
2198 - public static function get_intercom_user_id( $user_email, $intercom_user_jwt ) {
2199 - // MD5 is used only for a deterministic Intercom identifier; not for secrets.
2200 - // Normalize email casing to keep intercom user_id deterministic.
2201 - $normalized_email = is_string( $user_email ) ? strtolower( trim( $user_email ) ) : '';
2202 - $intercom_user_id = md5( $normalized_email );
2203 - if ( ! is_string( $intercom_user_jwt ) || '' === trim( $intercom_user_jwt ) ) {
2204 - return $intercom_user_id;
2205 - }
2206 -
2207 - // JWT is expected to be issued by our backend; no signature verification here.
2208 - $jwt_parts = explode( '.', $intercom_user_jwt );
2209 - if ( 3 === count( $jwt_parts ) ) {
2210 - $payload = $jwt_parts[1];
2211 - $payload = strtr( $payload, '-_', '+/' );
2212 - $payload_length = strlen( $payload );
2213 - $payload_padding = $payload_length % 4;
2214 - // Pad base64 payload to the next multiple of 4 so decode succeeds.
2215 - if ( 0 !== $payload_padding ) {
2216 - $payload = str_pad( $payload, $payload_length + 4 - $payload_padding, '=', STR_PAD_RIGHT );
2217 - }
2218 - $payload_decoded = base64_decode( $payload, true );
2219 - if ( false !== $payload_decoded ) {
2220 - $decoded = json_decode( $payload_decoded );
2221 - if ( JSON_ERROR_NONE === json_last_error() && is_object( $decoded ) && isset( $decoded->user_id ) && is_scalar( $decoded->user_id ) ) {
2222 - $user_id_claim = (string) $decoded->user_id;
2223 - if ( '' !== trim( $user_id_claim ) ) {
2224 - $intercom_user_id = $user_id_claim;
2225 - }
2226 - }
2227 - }
2228 - }
2229 -
2230 - return $intercom_user_id;
2231 1493 }
2232 1494 }