| 1 |
<?php |
| 2 |
/** |
| 3 |
* Plugin settings form. |
| 4 |
* |
| 5 |
* @package Siteimprove |
| 6 |
* @subpackage Siteimprove/admin/partials |
| 7 |
*/ |
| 8 |
|
| 9 |
/** |
| 10 |
* Plugin settings form. |
| 11 |
* |
| 12 |
* Defines the plugin settings form methods. |
| 13 |
* |
| 14 |
* @package Siteimprove |
| 15 |
* @subpackage Siteimprove/admin/partials |
| 16 |
*/ |
| 17 |
class Siteimprove_Admin_Settings { |
| 18 |
|
| 19 |
/** |
| 20 |
* Admin page nonce |
| 21 |
* |
| 22 |
* @var string Nonce |
| 23 |
*/ |
| 24 |
private $siteimprove_nonce; |
| 25 |
|
| 26 |
const SITEIMPROVE_API_URL = 'https://api.siteimprove.com/v2'; |
| 27 |
|
| 28 |
/** |
| 29 |
* Returns the current nonce |
| 30 |
* |
| 31 |
* @return string WP Nonce |
| 32 |
*/ |
| 33 |
public function request_siteimprove_nonce() { |
| 34 |
return $this->siteimprove_nonce; |
| 35 |
} |
| 36 |
|
| 37 |
/** |
| 38 |
* Register section. |
| 39 |
*/ |
| 40 |
public function register_section() { |
| 41 |
$this->siteimprove_nonce = wp_create_nonce( 'siteimprove-options' ); |
| 42 |
// Register settings for siteimprove plugin settings page. |
| 43 |
register_setting( 'siteimprove', 'siteimprove_token' ); |
| 44 |
register_setting( 'siteimprove', 'siteimprove_disable_new_version', 'Siteimprove_Admin_Settings::validate_siteimprove_disable_new_version' ); |
| 45 |
register_setting( 'siteimprove', 'siteimprove_public_url', 'Siteimprove_Admin_Settings::validate_public_url' ); |
| 46 |
register_setting( 'siteimprove', 'siteimprove_ignore_path_segments', 'Siteimprove_Admin_Settings::validate_ignore_path_segments' ); |
| 47 |
register_setting( 'siteimprove', 'siteimprove_api_username', 'Siteimprove_Admin_Settings::validate_api_username' ); |
| 48 |
register_setting( 'siteimprove', 'siteimprove_api_key', 'Siteimprove_Admin_Settings::validate_api_key' ); |
| 49 |
register_setting( 'siteimprove', 'siteimprove_dev_mode', 'Siteimprove_Admin_Settings::validate_siteimprove_dev_mode' ); |
| 50 |
register_setting( 'siteimprove', 'siteimprove_overlayjs_file', 'Siteimprove_Admin_Settings::validate_siteimprove_overlayjs_file' ); |
| 51 |
|
| 52 |
// Register a new section in the siteimprove page. |
| 53 |
add_settings_section( |
| 54 |
'siteimprove_token', |
| 55 |
__( 'Token', 'siteimprove' ), |
| 56 |
'Siteimprove_Admin_Settings::siteimprove_settings_section_title', |
| 57 |
'siteimprove' |
| 58 |
); |
| 59 |
|
| 60 |
// register a new field siteimprove_token_field, inside the siteimprove_token section of the settings page. |
| 61 |
add_settings_field( |
| 62 |
'siteimprove_token', |
| 63 |
__( 'Token', 'siteimprove' ), |
| 64 |
'Siteimprove_Admin_Settings::siteimprove_token_field', |
| 65 |
'siteimprove', |
| 66 |
'siteimprove_token' |
| 67 |
); |
| 68 |
|
| 69 |
// Register a new section in the siteimprove page. |
| 70 |
add_settings_section( |
| 71 |
'siteimprove_public_url', |
| 72 |
__( 'Public URL', 'siteimprove' ), |
| 73 |
'Siteimprove_Admin_Settings::siteimprove_settings_section_title', |
| 74 |
'siteimprove' |
| 75 |
); |
| 76 |
|
| 77 |
// register a new field siteimprove_public_url_field, inside the siteimprove_token section of the settings page. |
| 78 |
add_settings_field( |
| 79 |
'siteimprove_public_url', |
| 80 |
__( 'Public URL', 'siteimprove' ), |
| 81 |
'Siteimprove_Admin_Settings::siteimprove_public_url_field', |
| 82 |
'siteimprove', |
| 83 |
'siteimprove_public_url' |
| 84 |
); |
| 85 |
|
| 86 |
// register a new field siteimprove_ignore_path_segments_field, inside the siteimprove_public_url section of the settings page. |
| 87 |
add_settings_field( |
| 88 |
'siteimprove_ignore_path_segments', |
| 89 |
__( 'Ignore Path Segments', 'siteimprove' ), |
| 90 |
'Siteimprove_Admin_Settings::siteimprove_ignore_path_segments_field', |
| 91 |
'siteimprove', |
| 92 |
'siteimprove_public_url' |
| 93 |
); |
| 94 |
|
| 95 |
// Register a new section in the siteimprove page. |
| 96 |
add_settings_section( |
| 97 |
'siteimprove_version_section', |
| 98 |
__( 'Plugin Experience', 'siteimprove' ), |
| 99 |
'Siteimprove_Admin_Settings::siteimprove_settings_section_title', |
| 100 |
'siteimprove' |
| 101 |
); |
| 102 |
|
| 103 |
// register a new field siteimprove_disable_new_version_field, inside the siteimprove_version_section section of the settings page. |
| 104 |
add_settings_field( |
| 105 |
'siteimprove_disable_new_version', |
| 106 |
__( 'Use latest experience', 'siteimprove' ), |
| 107 |
'Siteimprove_Admin_Settings::siteimprove_disable_new_version_field', |
| 108 |
'siteimprove', |
| 109 |
'siteimprove_version_section' |
| 110 |
); |
| 111 |
|
| 112 |
// register a new field siteimprove_token_field, inside the siteimprove_token section of the settings page. |
| 113 |
add_settings_field( |
| 114 |
'siteimprove_public_url', |
| 115 |
__( 'Public URL', 'siteimprove' ), |
| 116 |
'Siteimprove_Admin_Settings::siteimprove_public_url_field', |
| 117 |
'siteimprove', |
| 118 |
'siteimprove_public_url' |
| 119 |
); |
| 120 |
|
| 121 |
// Register a new section in the siteimprove page. |
| 122 |
add_settings_section( |
| 123 |
'siteimprove_api_credentials', |
| 124 |
__( 'API Credentials', 'siteimprove' ), |
| 125 |
'Siteimprove_Admin_Settings::siteimprove_settings_section_title', |
| 126 |
'siteimprove' |
| 127 |
); |
| 128 |
|
| 129 |
// Register a new section in the siteimprove page. |
| 130 |
if ( isset( $_GET['devmode'] ) ) { |
| 131 |
add_settings_section( |
| 132 |
'siteimprove_dev_mode_section', |
| 133 |
__( 'Dev Mode', 'siteimprove' ), |
| 134 |
'Siteimprove_Admin_Settings::siteimprove_settings_section_title', |
| 135 |
'siteimprove' |
| 136 |
); |
| 137 |
|
| 138 |
// register a new field Overlayjs_file, inside the siteimprove_api_credentials section of the settings page. |
| 139 |
add_settings_field( |
| 140 |
'siteimprove_overlayjs_file', |
| 141 |
__( 'Overlay JS File', 'siteimprove' ), |
| 142 |
'Siteimprove_Admin_Settings::siteimprove_overlayjs_file_field', |
| 143 |
'siteimprove', |
| 144 |
'siteimprove_dev_mode_section' |
| 145 |
); |
| 146 |
} |
| 147 |
|
| 148 |
// register a new field siteimprove_api_username_field, inside the siteimprove_api_credentials section of the settings page. |
| 149 |
add_settings_field( |
| 150 |
'siteimprove_api_username', |
| 151 |
__( 'API Username (Email)', 'siteimprove' ), |
| 152 |
'Siteimprove_Admin_Settings::siteimprove_api_username_field', |
| 153 |
'siteimprove', |
| 154 |
'siteimprove_api_credentials' |
| 155 |
); |
| 156 |
|
| 157 |
// register a new field siteimprove_api_key_field, inside the siteimprove_api_credentials section of the settings page. |
| 158 |
add_settings_field( |
| 159 |
'siteimprove_api_key', |
| 160 |
__( 'API Key', 'siteimprove' ), |
| 161 |
'Siteimprove_Admin_Settings::siteimprove_api_key_field', |
| 162 |
'siteimprove', |
| 163 |
'siteimprove_api_credentials' |
| 164 |
); |
| 165 |
|
| 166 |
// Register a new section in the siteimprove page. |
| 167 |
add_settings_section( |
| 168 |
'siteimprove_prepublish', |
| 169 |
__( 'Prepublish', 'siteimprove' ), |
| 170 |
'Siteimprove_Admin_Settings::siteimprove_settings_section_title', |
| 171 |
'siteimprove' |
| 172 |
); |
| 173 |
} |
| 174 |
|
| 175 |
/** |
| 176 |
* Register menu for settings form page. |
| 177 |
*/ |
| 178 |
public function register_menu() { |
| 179 |
// Add top level menu page. |
| 180 |
add_menu_page( |
| 181 |
__( 'Siteimprove Plugin' ), |
| 182 |
__( 'Siteimprove' ), |
| 183 |
'manage_options', |
| 184 |
'siteimprove', |
| 185 |
'Siteimprove_Admin_Settings::siteimprove_settings_form', |
| 186 |
plugins_url( 'siteimprove/admin/img/si-icon.svg' ), |
| 187 |
); |
| 188 |
} |
| 189 |
|
| 190 |
/** |
| 191 |
* Section title. |
| 192 |
* |
| 193 |
* @param mixed $args Section title arguments. |
| 194 |
* @return void |
| 195 |
*/ |
| 196 |
public static function siteimprove_settings_section_title( $args ) { |
| 197 |
if ( 'siteimprove_prepublish' === $args['id'] ) { |
| 198 |
$siteimprove_api_key = get_option( 'siteimprove_api_key', '' ); |
| 199 |
$prepublish_allowed = intval( get_option( 'siteimprove_prepublish_allowed', 0 ) ); |
| 200 |
$prepublish_enabled = intval( get_option( 'siteimprove_prepublish_enabled', 0 ) ); |
| 201 |
if ( ! empty( $siteimprove_api_key ) ) { |
| 202 |
if ( 1 === $prepublish_allowed ) { |
| 203 |
?> |
| 204 |
<p>You can use Prepublish on your account.</p> |
| 205 |
<?php |
| 206 |
if ( 0 === $prepublish_enabled ) : |
| 207 |
?> |
| 208 |
<p class="siteimprove_prepublish_activation_messages"> |
| 209 |
<?php |
| 210 |
echo wp_kses( |
| 211 |
__( 'To enable prepublish for this website click <a href="#" id="siteimprove_enable_prepublish" class="button button-primary">here</a>', 'siteimprove' ), |
| 212 |
array( |
| 213 |
'a' => array( |
| 214 |
'href' => array(), |
| 215 |
'id' => array(), |
| 216 |
'class' => array(), |
| 217 |
), |
| 218 |
) |
| 219 |
); |
| 220 |
?> |
| 221 |
</p> |
| 222 |
<?php |
| 223 |
else : |
| 224 |
?> |
| 225 |
<p> |
| 226 |
<?php |
| 227 |
echo wp_kses( |
| 228 |
__( 'Prepublish feature is already enabled for the current website. To use it please go to the preview of any page/post or content that you want to check and click the button <strong>Siteimprove Prepublish Check</strong> located on the top bar of the admin panel', 'siteimprove' ), |
| 229 |
array( |
| 230 |
'strong' => array(), |
| 231 |
) |
| 232 |
); |
| 233 |
?> |
| 234 |
</p> |
| 235 |
<?php |
| 236 |
endif; |
| 237 |
} else { |
| 238 |
?> |
| 239 |
<p> |
| 240 |
<?php |
| 241 |
esc_html_e( 'You can\'t use Prepublish on your account. Please contact sales team to enable this feature for the current website', 'siteimprove' ); |
| 242 |
?> |
| 243 |
</p> |
| 244 |
<?php |
| 245 |
} |
| 246 |
} else { |
| 247 |
?> |
| 248 |
<p> |
| 249 |
<?php |
| 250 |
esc_html_e( 'Please provide a valid API Username and API Key before using this feature.', 'siteimprove' ); |
| 251 |
?> |
| 252 |
</p> |
| 253 |
<?php |
| 254 |
} |
| 255 |
} |
| 256 |
|
| 257 |
if ( 'siteimprove_public_url' === $args['id'] ) { |
| 258 |
?> |
| 259 |
<p> |
| 260 |
<?php |
| 261 |
esc_html_e( 'Configure URL transformation settings. Public URL changes the domain/host of the URL. Ignore Path Segments removes specific path segments from the URL. These settings can be used independently or together.', 'siteimprove' ); |
| 262 |
?> |
| 263 |
</p> |
| 264 |
<?php |
| 265 |
} |
| 266 |
|
| 267 |
if ( 'siteimprove_version_section' === $args['id'] ) { |
| 268 |
?> |
| 269 |
<p> |
| 270 |
<?php |
| 271 |
esc_html_e( 'A new version of the plugin is now available. Please note it is a work in progress and may update over time.' ); |
| 272 |
?> |
| 273 |
</p> |
| 274 |
<?php |
| 275 |
} |
| 276 |
} |
| 277 |
|
| 278 |
/** |
| 279 |
* Form fields |
| 280 |
* |
| 281 |
* @param mixed $args Field Arguments. |
| 282 |
* @return void |
| 283 |
*/ |
| 284 |
public static function siteimprove_disable_new_version_field( $args ) { |
| 285 |
$is_checked = ''; |
| 286 |
// If the option still not exists, the checkbox will start as marked by default. |
| 287 |
if ( false === get_option( 'siteimprove_disable_new_version' ) || 1 === intval( get_option( 'siteimprove_disable_new_version' ) ) ) { |
| 288 |
$is_checked = 'checked'; |
| 289 |
} else { |
| 290 |
$is_checked = ''; |
| 291 |
} |
| 292 |
?> |
| 293 |
<input type="checkbox" id="siteimprove_disable_new_version_field" name="siteimprove_disable_new_version" value='1' <?php echo esc_attr( $is_checked ); ?> /> |
| 294 |
<?php |
| 295 |
} |
| 296 |
|
| 297 |
/** |
| 298 |
* Form fields |
| 299 |
* |
| 300 |
* @param mixed $args Field Arguments. |
| 301 |
* @return void |
| 302 |
*/ |
| 303 |
public static function siteimprove_token_field( $args ) { |
| 304 |
?> |
| 305 |
|
| 306 |
<input type="text" id="siteimprove_token_field" name="siteimprove_token" value="<?php echo esc_attr( get_option( 'siteimprove_token' ) ); ?>" maxlength="50" size="50" /> |
| 307 |
<input class="button" id="siteimprove_token_request" type="button" value="<?php echo esc_attr( __( 'Request new token', 'siteimprove' ) ); ?>" /> |
| 308 |
<?php |
| 309 |
} |
| 310 |
|
| 311 |
/** |
| 312 |
* Form fields |
| 313 |
* |
| 314 |
* @param mixed $args Field Arguments. |
| 315 |
* @return void |
| 316 |
*/ |
| 317 |
public static function siteimprove_public_url_field( $args ) { |
| 318 |
?> |
| 319 |
<input type="text" id="siteimprove_public_url_field" name="siteimprove_public_url" value="<?php echo esc_attr( get_option( 'siteimprove_public_url' ) ); ?>" size="50" /> |
| 320 |
<p> |
| 321 |
<?php |
| 322 |
esc_html_e( '(Optional) Please provide the Public URL for the current site if for any reasons it\'s not the same as the Admin Panel URL. This changes the domain/host of the URL and works independently of the Ignore Path Segments setting.', 'siteimprove' ); |
| 323 |
?> |
| 324 |
</p> |
| 325 |
<p> |
| 326 |
<?php |
| 327 |
esc_html_e( 'Example: Website Admin Panel is hosted at: http://stg-thewebsite.com but the final Public URL will be http://thewebsite.com', 'siteimprove' ); |
| 328 |
?> |
| 329 |
</p> |
| 330 |
<?php |
| 331 |
} |
| 332 |
|
| 333 |
/** |
| 334 |
* Form fields |
| 335 |
* |
| 336 |
* @param mixed $args Field Arguments. |
| 337 |
* @return void |
| 338 |
*/ |
| 339 |
public static function siteimprove_ignore_path_segments_field( $args ) { |
| 340 |
?> |
| 341 |
<input type="text" id="siteimprove_ignore_path_segments_field" name="siteimprove_ignore_path_segments" value="<?php echo esc_attr( get_option( 'siteimprove_ignore_path_segments' ) ); ?>" size="50" /> |
| 342 |
<p> |
| 343 |
<?php |
| 344 |
esc_html_e( '(Optional) Specify path segments to remove from the URL path. Use comma-separated values (e.g. "cms,staging"). This doe not remove anything from the Public URL set. This can be used to clean up path segments from the CMS URLs to better match the end published URLs scanned in the Siteimprove platform in the plugin requests.', 'siteimprove' ); |
| 345 |
?> |
| 346 |
</p> |
| 347 |
<p> |
| 348 |
<?php |
| 349 |
esc_html_e( 'Example: If your URL is https://staging.mysite.com/cms/blog/staging/mypost and you set the Ignore Path Segments to "cms,staging", the result will be https://staging.mysite.com/blog/mypost.', 'siteimprove' ); |
| 350 |
?> |
| 351 |
</p> |
| 352 |
<?php |
| 353 |
} |
| 354 |
|
| 355 |
/** |
| 356 |
* Form fields |
| 357 |
* |
| 358 |
* @param mixed $args Field Arguments. |
| 359 |
* @return void |
| 360 |
*/ |
| 361 |
public static function siteimprove_api_username_field( $args ) { |
| 362 |
?> |
| 363 |
|
| 364 |
<input type="text" id="siteimprove_api_username_field" name="siteimprove_api_username" value="<?php echo esc_attr( get_option( 'siteimprove_api_username' ) ); ?>" maxlength="50" size="50" /> |
| 365 |
<?php |
| 366 |
} |
| 367 |
|
| 368 |
/** |
| 369 |
* Form fields |
| 370 |
* |
| 371 |
* @param mixed $args Field Arguments. |
| 372 |
* @return void |
| 373 |
*/ |
| 374 |
public static function siteimprove_api_key_field( $args ) { |
| 375 |
?> |
| 376 |
|
| 377 |
<input type="text" id="siteimprove_api_key_field" name="siteimprove_api_key" value="<?php echo esc_attr( get_option( 'siteimprove_api_key' ) ); ?>" maxlength="50" size="50" /> |
| 378 |
<?php |
| 379 |
} |
| 380 |
|
| 381 |
/** |
| 382 |
* Form fields |
| 383 |
* |
| 384 |
* @param mixed $args Field Arguments. |
| 385 |
* @return void |
| 386 |
*/ |
| 387 |
public static function siteimprove_overlayjs_file_field( $args ) { |
| 388 |
?> |
| 389 |
|
| 390 |
<input type="text" id="siteimprove_overlayjs_file_field" name="siteimprove_overlayjs_file" value="<?php echo esc_attr( get_option( 'siteimprove_overlayjs_file' ) ); ?>" size="50" /> |
| 391 |
<?php |
| 392 |
} |
| 393 |
|
| 394 |
/** |
| 395 |
* Create settings form. |
| 396 |
*/ |
| 397 |
public static function siteimprove_settings_form() { |
| 398 |
// Check access. |
| 399 |
if ( ! current_user_can( 'manage_options' ) ) { |
| 400 |
return; |
| 401 |
} |
| 402 |
|
| 403 |
settings_errors( 'siteimprove_messages' ); |
| 404 |
?> |
| 405 |
<div class="wrap"> |
| 406 |
<h1><?php echo esc_html( get_admin_page_title() ); ?></h1> |
| 407 |
<form action="options.php" method="post"> |
| 408 |
<?php |
| 409 |
// Display settings fields. |
| 410 |
settings_fields( 'siteimprove' ); |
| 411 |
do_settings_sections( 'siteimprove' ); |
| 412 |
// Submit button. |
| 413 |
submit_button( __( 'Save Settings', 'siteimprove' ) ); |
| 414 |
?> |
| 415 |
</form> |
| 416 |
</div> |
| 417 |
<?php |
| 418 |
} |
| 419 |
|
| 420 |
/** |
| 421 |
* Field Update |
| 422 |
* |
| 423 |
* @param string $value Original value posted in settings page. |
| 424 |
* @return bool |
| 425 |
*/ |
| 426 |
public static function validate_siteimprove_disable_new_version( $value ) { |
| 427 |
if ( ! empty( $value ) ) { |
| 428 |
return $value; |
| 429 |
} |
| 430 |
if ( isset( $_POST['siteimprove_disable_new_version'], $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'siteimprove-options' ) ) { |
| 431 |
$checkbox_value = sanitize_text_field( wp_unslash( $_POST['siteimprove_disable_new_version'] ) ); |
| 432 |
if ( '' !== trim( $checkbox_value ) ) { |
| 433 |
return 1; |
| 434 |
} |
| 435 |
} |
| 436 |
return 0; |
| 437 |
} |
| 438 |
|
| 439 |
/** |
| 440 |
* Field Validation |
| 441 |
* |
| 442 |
* @param string $value Original value posted in settings page. |
| 443 |
* @return string |
| 444 |
*/ |
| 445 |
public static function validate_api_username( $value ) { |
| 446 |
if ( ! empty( $value ) ) { |
| 447 |
$old_value = get_option( 'siteimprove_api_username' ); |
| 448 |
// new username was inputted, check if it's a valid email. |
| 449 |
if ( ! filter_var( $value, FILTER_VALIDATE_EMAIL ) ) { |
| 450 |
add_settings_error( 'siteimprove_messages', 'siteimprove_api_username_error', __( 'API Username must be a valid email', 'siteimprove' ) ); |
| 451 |
if ( ! empty( $old_value ) ) { |
| 452 |
return $old_value; |
| 453 |
} |
| 454 |
} |
| 455 |
|
| 456 |
if ( |
| 457 |
isset( $_POST['siteimprove_api_username'], $_POST['siteimprove_api_key'], $_REQUEST['_wpnonce'] ) |
| 458 |
&& wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'siteimprove-options' ) |
| 459 |
) { |
| 460 |
$username = sanitize_text_field( wp_unslash( $_POST['siteimprove_api_username'] ) ); |
| 461 |
$key = sanitize_text_field( wp_unslash( $_POST['siteimprove_api_key'] ) ); |
| 462 |
$result = self::check_credentials( $username, $key ); |
| 463 |
if ( 'false' === $result['status'] ) { |
| 464 |
// return previous username when error is returned from checking both fields. |
| 465 |
return $old_value; |
| 466 |
} |
| 467 |
} |
| 468 |
} |
| 469 |
return $value; |
| 470 |
} |
| 471 |
|
| 472 |
/** |
| 473 |
* Field Update |
| 474 |
* |
| 475 |
* @param string $value Original value posted in settings page. |
| 476 |
* @return bool |
| 477 |
*/ |
| 478 |
public static function validate_siteimprove_overlayjs_file( $value ) { |
| 479 |
if ( ! empty( $value ) ) { |
| 480 |
$old_value = get_option( 'siteimprove_overlayjs_file' ); |
| 481 |
if ( ! preg_match( '/.+\..{2,}/', $value ) ) { |
| 482 |
add_settings_error( 'siteimprove_messages', 'siteimprove_api_key_error', __( 'Overlay file not saved - Invalid format (please verify if name and extention are correct).', 'siteimprove' ) ); |
| 483 |
if ( ! empty( $old_value ) ) { |
| 484 |
return $old_value; |
| 485 |
} |
| 486 |
} else { |
| 487 |
if ( |
| 488 |
isset( $_POST['siteimprove_overlayjs_file'], $_REQUEST['_wpnonce'] ) |
| 489 |
&& wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'siteimprove-options' ) |
| 490 |
) { |
| 491 |
return $value; |
| 492 |
} |
| 493 |
} |
| 494 |
} |
| 495 |
return $value; |
| 496 |
} |
| 497 |
|
| 498 |
/** |
| 499 |
* Field Validation |
| 500 |
* |
| 501 |
* @param string $value Original value posted in settings page. |
| 502 |
* @return string |
| 503 |
*/ |
| 504 |
public static function validate_api_key( $value ) { |
| 505 |
$old_value = get_option( 'siteimprove_api_key' ); |
| 506 |
|
| 507 |
if ( ! empty( $value ) ) { |
| 508 |
// new API key inserted, let's check if it's a valid one. |
| 509 |
if ( ! preg_match( '/^[a-zA-Z0-9]{32}$/', $value ) ) { |
| 510 |
add_settings_error( 'siteimprove_messages', 'siteimprove_api_key_error', __( 'Invalid format for API Key field', 'siteimprove' ) ); |
| 511 |
if ( ! empty( $old_value ) ) { |
| 512 |
return $old_value; |
| 513 |
} |
| 514 |
} else { |
| 515 |
/* |
| 516 |
Now if API username and key are set, it's time to test both |
| 517 |
against the API endpoint to check if it's a valid user/key set |
| 518 |
and also if the keys correspond to the current website |
| 519 |
*/ |
| 520 |
if ( |
| 521 |
isset( $_POST['siteimprove_api_username'], $_POST['siteimprove_api_key'], $_REQUEST['_wpnonce'] ) |
| 522 |
&& wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'siteimprove-options' ) |
| 523 |
) { |
| 524 |
$username = sanitize_text_field( wp_unslash( $_POST['siteimprove_api_username'] ) ); |
| 525 |
$key = sanitize_text_field( wp_unslash( $_POST['siteimprove_api_key'] ) ); |
| 526 |
$result = self::check_credentials( $username, $key ); |
| 527 |
if ( 'false' === $result['status'] ) { |
| 528 |
add_settings_error( 'siteimprove_messages', 'siteimprove_api_credentials_error', $result['error'] ); |
| 529 |
if ( ! empty( $old_value ) ) { |
| 530 |
return $old_value; |
| 531 |
} |
| 532 |
} else { |
| 533 |
add_settings_error( 'siteimprove_messages', 'siteimprove_message', __( 'Settings Saved', 'siteimprove' ), 'updated' ); |
| 534 |
// check if user has the prepublish feature (AKA contentcheck) enabled. |
| 535 |
self::verify_contentcheck( $username, $key ); |
| 536 |
} |
| 537 |
} |
| 538 |
} |
| 539 |
} |
| 540 |
return $value; |
| 541 |
} |
| 542 |
|
| 543 |
/** |
| 544 |
* Field Validation |
| 545 |
* |
| 546 |
* @param string $value Original value posted in settings page. |
| 547 |
* @return string |
| 548 |
*/ |
| 549 |
public static function validate_public_url( $value ) { |
| 550 |
if ( ! empty( $value ) ) { |
| 551 |
$old_value = get_option( 'siteimprove_public_url' ); |
| 552 |
if ( filter_var( $value, FILTER_VALIDATE_URL ) === false ) { |
| 553 |
add_settings_error( 'siteimprove_messages', 'siteimprove_public_url_error', __( 'Invalid format for Public URL field', 'siteimprove' ) ); |
| 554 |
return $old_value; |
| 555 |
} |
| 556 |
} |
| 557 |
|
| 558 |
return $value; |
| 559 |
} |
| 560 |
|
| 561 |
/** |
| 562 |
* Field Validation for Ignore Path Segments |
| 563 |
* |
| 564 |
* @param string $value Original value posted in settings page. |
| 565 |
* @return string |
| 566 |
*/ |
| 567 |
public static function validate_ignore_path_segments( $value ) { |
| 568 |
if ( ! empty( $value ) ) { |
| 569 |
$old_value = get_option( 'siteimprove_ignore_path_segments' ); |
| 570 |
// Validate that the value contains only alphanumeric characters, hyphens, underscores, and commas. |
| 571 |
if ( ! preg_match( '/^[a-zA-Z0-9\-\_,\s]+$/', $value ) ) { |
| 572 |
add_settings_error( 'siteimprove_messages', 'siteimprove_ignore_path_segments_error', __( 'Invalid format for Ignore Path Segments field. Only alphanumeric characters, hyphens, underscores, and commas are allowed.', 'siteimprove' ) ); |
| 573 |
return $old_value; |
| 574 |
} |
| 575 |
} |
| 576 |
|
| 577 |
return sanitize_text_field( $value ); |
| 578 |
} |
| 579 |
|
| 580 |
/** |
| 581 |
* Abstractor for any API requests made on the admin page |
| 582 |
* |
| 583 |
* @param string $username API Username. |
| 584 |
* @param string $key API Key. |
| 585 |
* @param string $path endpoint on the API. |
| 586 |
* @param array $args optional arguments to be sent on the request. |
| 587 |
* @param string $alternate_url Optional url to use on API requests to the Siteimprove platform. |
| 588 |
* @param string $method Optional, defaults to get. Accepted methods are 'post' and 'get'. |
| 589 |
* |
| 590 |
* @return object Results of the API call. |
| 591 |
*/ |
| 592 |
public static function make_api_request( $username, $key, $path, $args = array(), $alternate_url = '', $method = 'get' ) { |
| 593 |
$params = array( |
| 594 |
'httpversion' => '1.1', |
| 595 |
'blocking' => true, |
| 596 |
'headers' => array( |
| 597 |
'Authorization' => 'Basic ' . base64_encode( $username . ':' . $key ), |
| 598 |
'sslverify' => false, |
| 599 |
), |
| 600 |
); |
| 601 |
array_merge( $params, $args ); |
| 602 |
|
| 603 |
$url = ( ! empty( $alternate_url ) ) ? $alternate_url : self::SITEIMPROVE_API_URL; |
| 604 |
|
| 605 |
if ( 'get' === $method ) { |
| 606 |
$request = wp_remote_get( |
| 607 |
$url . $path, |
| 608 |
$params |
| 609 |
); |
| 610 |
} else { |
| 611 |
$request = wp_remote_post( |
| 612 |
$url . $path, |
| 613 |
$params |
| 614 |
); |
| 615 |
} |
| 616 |
return $request; |
| 617 |
} |
| 618 |
/** |
| 619 |
* Check if the credentials are valid for the current domain |
| 620 |
* |
| 621 |
* @param string $username API Username. |
| 622 |
* @param string $key API Key. |
| 623 |
* @return array |
| 624 |
*/ |
| 625 |
public static function check_credentials( $username, $key ) { |
| 626 |
$return = array( |
| 627 |
'status' => 'false', |
| 628 |
'error' => __( 'Unable to check API Credentials, please try again', 'siteimprove' ), |
| 629 |
); |
| 630 |
|
| 631 |
$request = self::make_api_request( $username, $key, '/ping/account' ); |
| 632 |
|
| 633 |
if ( isset( $request['response'] ) && 401 === $request['response']['code'] ) { |
| 634 |
// Wrong credentials, trow error and exit. |
| 635 |
$return['error'] = __( 'Wrong API Credentials, API access denied. Please fix the credentials and try again', 'siteimprove' ); |
| 636 |
return $return; |
| 637 |
} |
| 638 |
|
| 639 |
$request = self::make_api_request( $username, $key, '/sites?page_size=1000' ); |
| 640 |
|
| 641 |
if ( isset( $request['response'] ) && 200 === $request['response']['code'] ) { |
| 642 |
$results = json_decode( $request['body'] ); |
| 643 |
$account_sites = $results->items; |
| 644 |
|
| 645 |
$public_url = get_option( 'siteimprove_public_url' ); |
| 646 |
|
| 647 |
if ( ! empty( $public_url ) ) { |
| 648 |
$site_url = $public_url; |
| 649 |
} else { |
| 650 |
$site_url = get_site_url(); |
| 651 |
} |
| 652 |
|
| 653 |
$domain = wp_parse_url( $site_url, PHP_URL_HOST ); |
| 654 |
$site_found = false; |
| 655 |
|
| 656 |
foreach ( $account_sites as $site_key => $site_data ) { |
| 657 |
if ( false !== strpos( $site_data->url, $domain ) ) { |
| 658 |
$site_found = true; |
| 659 |
} |
| 660 |
} |
| 661 |
|
| 662 |
if ( true === $site_found ) { |
| 663 |
$return = array( |
| 664 |
'status' => 'true', |
| 665 |
); |
| 666 |
} else { |
| 667 |
$return['error'] = __( 'Current domain/website not found for the provided credentials', 'siteimprove' ); |
| 668 |
} |
| 669 |
} else { |
| 670 |
$return['error'] = __( 'Unable to check website domain. Please try again later', 'siteimprove' ); |
| 671 |
} |
| 672 |
|
| 673 |
return $return; |
| 674 |
} |
| 675 |
|
| 676 |
/** |
| 677 |
* Check against the API endpoint if the user has the prepublish (AKA contentcheck) enabled |
| 678 |
* |
| 679 |
* @param string $username API Username. |
| 680 |
* @param string $key API Key. |
| 681 |
* @return void |
| 682 |
*/ |
| 683 |
public static function verify_contentcheck( $username, $key ) { |
| 684 |
$request = self::make_api_request( $username, $key, '/settings/content_checking' ); |
| 685 |
|
| 686 |
if ( isset( $request['response'] ) && 400 === $request['response']['code'] ) { |
| 687 |
$results = json_decode( $request['body'] ); |
| 688 |
if ( preg_match( '/Requires|feature/i', $results->message ) ) { |
| 689 |
update_option( 'siteimprove_prepublish_allowed', 0 ); |
| 690 |
} |
| 691 |
} else { |
| 692 |
/* |
| 693 |
TODO: Figure out how to find if the feature is allowed but not enabled yet. For now we |
| 694 |
are considering that if there are no errors, then we can keep going and suppose it's |
| 695 |
then possibly allowed to be enabled by the user whenever he wishes to do so. |
| 696 |
*/ |
| 697 |
update_option( 'siteimprove_prepublish_allowed', 1 ); |
| 698 |
|
| 699 |
/* |
| 700 |
Now we'll try to see if the prepublish feature is already enabled. |
| 701 |
If not, then we can show the user a button so he can enable it himself. |
| 702 |
*/ |
| 703 |
$results = json_decode( $request['body'] ); |
| 704 |
if ( isset( $results->is_ready ) && true === $results->is_ready ) { |
| 705 |
update_option( 'siteimprove_prepublish_enabled', 1 ); |
| 706 |
} else { |
| 707 |
update_option( 'siteimprove_prepublish_enabled', 0 ); |
| 708 |
} |
| 709 |
} |
| 710 |
} |
| 711 |
|
| 712 |
/** |
| 713 |
* Check against the API endpoint if the user has the prepublish (AKA contentcheck) available but not enabled yet. |
| 714 |
* |
| 715 |
* @return void |
| 716 |
*/ |
| 717 |
public function prepublish_manual_activation() { |
| 718 |
$siteimprove_api_username = get_option( 'siteimprove_api_username', '' ); |
| 719 |
$siteimprove_api_key = get_option( 'siteimprove_api_key', '' ); |
| 720 |
|
| 721 |
$return = array( |
| 722 |
'message' => 'activation_triggered', |
| 723 |
'result' => true, |
| 724 |
); |
| 725 |
|
| 726 |
$request = self::make_api_request( $siteimprove_api_username, $siteimprove_api_key, '/settings/content_checking', array(), '', 'post' ); |
| 727 |
$results = json_decode( $request['body'] ); |
| 728 |
if ( 400 === $request['response']['code'] ) { |
| 729 |
$return['result'] = false; |
| 730 |
} elseif ( '' !== $results ) { |
| 731 |
$return['result'] = false; |
| 732 |
} |
| 733 |
wp_send_json( $return ); |
| 734 |
wp_die(); |
| 735 |
} |
| 736 |
|
| 737 |
/** |
| 738 |
* Check against the API endpoint if the user has the prepublish (AKA contentcheck) available but not enabled yet. |
| 739 |
* |
| 740 |
* @return void |
| 741 |
*/ |
| 742 |
public function check_prepublish_activation() { |
| 743 |
$siteimprove_api_username = get_option( 'siteimprove_api_username', '' ); |
| 744 |
$siteimprove_api_key = get_option( 'siteimprove_api_key', '' ); |
| 745 |
|
| 746 |
$return = array( |
| 747 |
'message' => 'enabled', |
| 748 |
'result' => false, |
| 749 |
); |
| 750 |
|
| 751 |
$request = self::make_api_request( $siteimprove_api_username, $siteimprove_api_key, '/settings/content_checking', array() ); |
| 752 |
$results = json_decode( $request['body'] ); |
| 753 |
if ( isset( $results->is_ready ) && true === $results->is_ready ) { |
| 754 |
update_option( 'siteimprove_prepublish_enabled', 1 ); |
| 755 |
$return['result'] = true; |
| 756 |
} |
| 757 |
wp_send_json( $return ); |
| 758 |
wp_die(); |
| 759 |
} |
| 760 |
|
| 761 |
/** |
| 762 |
* Return new token for ajax requests. |
| 763 |
*/ |
| 764 |
public function request_token() { |
| 765 |
// Check access. |
| 766 |
if ( ! current_user_can( 'manage_options' ) ) { |
| 767 |
return; |
| 768 |
} |
| 769 |
|
| 770 |
// Check if the nonce is set and is valid. |
| 771 |
if ( isset( $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'siteimprove-options' ) ) { |
| 772 |
// The nonce is valid, output the token. |
| 773 |
echo esc_html( SiteimproveUtils::request_token() ); |
| 774 |
} else { |
| 775 |
wp_die(); |
| 776 |
} |
| 777 |
|
| 778 |
wp_die(); |
| 779 |
} |
| 780 |
} |
| 781 |
|