PluginProbe
Stream – Activity Log & Audit Trail / 3.7.0
Stream – Activity Log & Audit Trail v3.7.0
4.4.0 4.3.0 4.2.2 4.2.1 trunk 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.1 3.1.1 3.10.0 3.2.0 3.2.1 3.2.2 3.2.3 All 50 releases
← All changes | classes/class-admin.php +299 -170 3.0.53.7.0 View file →
@@ -1,5 +1,11 @@
1 1 <?php
2 +/**
3 + * Centralized manager for WordPress backend functionality.
4 + *
5 + * @package WP_Stream
6 + */
7 +
2 8 namespace WP_Stream;
3 9
4 10 use DateTime;
5 11 use DateTimeZone;
@@ -6,11 +12,15 @@
6 12 use DateInterval;
7 13 use \WP_CLI;
8 14 use \WP_Roles;
9 15
16 +/**
17 + * Class - Admin
18 + */
10 19 class Admin {
20 +
11 21 /**
12 - * Hold Plugin class
22 + * Holds Instance of plugin object
13 23 *
14 24 * @var Plugin
15 25 */
16 26 public $plugin;
@@ -115,9 +125,9 @@
115 125
116 126 /**
117 127 * Class constructor.
118 128 *
119 - * @param Plugin $plugin The main Plugin class.
129 + * @param Plugin $plugin Instance of plugin object.
120 130 */
121 131 public function __construct( $plugin ) {
122 132 $this->plugin = $plugin;
123 133
@@ -124,9 +134,9 @@
124 134 add_action( 'init', array( $this, 'init' ) );
125 135
126 136 // Ensure function used in various methods is pre-loaded.
127 137 if ( ! function_exists( 'is_plugin_active_for_network' ) ) {
128 - require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
138 + require_once ABSPATH . '/wp-admin/includes/plugin.php';
129 139 }
130 140
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
@@ -131,9 +141,9 @@
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
133 143 add_filter( 'role_has_cap', array( $this, 'filter_role_caps' ), 10, 3 );
134 144
135 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) && ! is_network_admin() ) {
145 + if ( is_multisite() && $plugin->is_network_activated() && ! is_network_admin() ) {
136 146 $options = (array) get_site_option( 'wp_stream_network', array() );
137 147 $option = isset( $options['general_site_access'] ) ? absint( $options['general_site_access'] ) : 1;
138 148
139 149 $this->disable_access = ( $option ) ? false : true;
@@ -151,36 +161,62 @@
151 161 // Add admin body class.
152 162 add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
153 163
154 164 // Plugin action links.
155 - add_filter( 'plugin_action_links', array( $this, 'plugin_action_links' ), 10, 2 );
165 + add_filter(
166 + 'plugin_action_links',
167 + array(
168 + $this,
169 + 'plugin_action_links',
170 + ),
171 + 10,
172 + 2
173 + );
156 174
157 175 // Load admin scripts and styles.
158 - add_action( 'admin_enqueue_scripts', array( $this, 'admin_enqueue_scripts' ) );
176 + add_action(
177 + 'admin_enqueue_scripts',
178 + array(
179 + $this,
180 + 'admin_enqueue_scripts',
181 + )
182 + );
159 183 add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
160 184
161 185 // Reset Streams database.
162 - add_action( 'wp_ajax_wp_stream_reset', array( $this, 'wp_ajax_reset' ) );
186 + add_action(
187 + 'wp_ajax_wp_stream_reset',
188 + array(
189 + $this,
190 + 'wp_ajax_reset',
191 + )
192 + );
163 193
164 - // Uninstall Streams and Deactivate plugin.
165 - $uninstall = new Uninstall( $this->plugin );
166 - add_action( 'wp_ajax_wp_stream_uninstall', array( $uninstall, 'uninstall' ) );
194 + /**
195 + * Uninstall Streams and Deactivate plugin.
196 + *
197 + * @todo Confirm if variable assignment is necessary.
198 + */
199 + $uninstall = $this->plugin->db->driver->purge_storage( $this->plugin );
167 200
168 201 // Auto purge setup.
169 202 add_action( 'wp_loaded', array( $this, 'purge_schedule_setup' ) );
170 - add_action( 'wp_stream_auto_purge', array( $this, 'purge_scheduled_action' ) );
203 + add_action(
204 + 'wp_stream_auto_purge',
205 + array(
206 + $this,
207 + 'purge_scheduled_action',
208 + )
209 + );
171 210
172 211 // Ajax users list.
173 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
174 -
175 - // Ajax user's name by ID.
176 - add_action( 'wp_ajax_wp_stream_get_filter_value_by_id', array( $this, 'get_filter_value_by_id' ) );
177 -
178 - // Ajax users list.
179 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
180 -
181 - // Ajax user's name by ID.
182 - add_action( 'wp_ajax_wp_stream_get_filter_value_by_id', array( $this, 'get_filter_value_by_id' ) );
212 + add_action(
213 + 'wp_ajax_wp_stream_filters',
214 + array(
215 + $this,
216 + 'ajax_filters',
217 + )
218 + );
183 219 }
184 220
185 221 /**
186 222 * Load admin classes
@@ -217,9 +253,9 @@
217 253 * @param bool $is_error If the message is error_level (true) or warning (false).
218 254 */
219 255 public function notice( $message, $is_error = true ) {
220 256 if ( defined( 'WP_CLI' ) && WP_CLI ) {
221 - $message = strip_tags( $message );
257 + $message = wp_strip_all_tags( $message );
222 258
223 259 if ( $is_error ) {
224 260 WP_CLI::warning( $message );
225 261 } else {
@@ -308,8 +344,16 @@
308 344 $main_menu_position
309 345 );
310 346
311 347 /**
348 + * Fires before submenu items are added to the Stream menu
349 + * allowing plugins to add menu items before Settings
350 + *
351 + * @return void
352 + */
353 + do_action( 'wp_stream_admin_menu' );
354 +
355 + /**
312 356 * Filter the Settings admin page title
313 357 *
314 358 * @return string
315 359 */
@@ -332,9 +376,15 @@
332 376 */
333 377 do_action( 'wp_stream_admin_menu_screens' );
334 378
335 379 // Register the list table early, so it associates the column headers with 'Screen settings'.
336 - add_action( 'load-' . $this->screen_id['main'], array( $this, 'register_list_table' ) );
380 + add_action(
381 + 'load-' . $this->screen_id['main'],
382 + array(
383 + $this,
384 + 'register_list_table',
385 + )
386 + );
337 387 }
338 388 }
339 389
340 390 /**
@@ -341,15 +391,15 @@
341 391 * Enqueue scripts/styles for admin screen
342 392 *
343 393 * @action admin_enqueue_scripts
344 394 *
345 - * @param string $hook
395 + * @param string $hook Current hook.
346 396 *
347 397 * @return void
348 398 */
349 399 public function admin_enqueue_scripts( $hook ) {
350 - wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/select2.js', array( 'jquery' ), '3.5.2', true );
351 - wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/select2.css', array(), '3.5.2' );
400 + wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/js/select2.full.min.js', array( 'jquery' ), '3.5.2', true );
401 + wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/css/select2.min.css', array(), '3.5.2' );
352 402 wp_register_script( 'wp-stream-timeago', $this->plugin->locations['url'] . 'ui/lib/timeago/jquery.timeago.js', array(), '1.4.1', true );
353 403
354 404 $locale = strtolower( substr( get_locale(), 0, 2 ) );
355 405 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
@@ -354,14 +404,27 @@
354 404 $locale = strtolower( substr( get_locale(), 0, 2 ) );
355 405 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
356 406
357 407 if ( file_exists( $this->plugin->locations['dir'] . sprintf( $file_tmpl, $locale ) ) ) {
358 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ), array( 'wp-stream-timeago' ), '1' );
408 + wp_register_script(
409 + 'wp-stream-timeago-locale',
410 + $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ),
411 + array( 'wp-stream-timeago' ),
412 + '1',
413 + false
414 + );
359 415 } else {
360 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ), array( 'wp-stream-timeago' ), '1' );
416 + wp_register_script(
417 + 'wp-stream-timeago-locale',
418 + $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ),
419 + array( 'wp-stream-timeago' ),
420 + '1',
421 + false
422 + );
361 423 }
362 424
363 - wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.css', array(), $this->plugin->get_version() );
425 + $min = wp_stream_min_suffix();
426 + wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.' . $min . 'css', array(), $this->plugin->get_version() );
364 427
365 428 $script_screens = array( 'plugins.php' );
366 429
367 430 if ( in_array( $hook, $this->screen_id, true ) || in_array( $hook, $script_screens, true ) ) {
@@ -370,10 +433,38 @@
370 433
371 434 wp_enqueue_script( 'wp-stream-timeago' );
372 435 wp_enqueue_script( 'wp-stream-timeago-locale' );
373 436
374 - wp_enqueue_script( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/js/admin.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
375 - wp_enqueue_script( 'wp-stream-live-updates', $this->plugin->locations['url'] . 'ui/js/live-updates.js', array( 'jquery', 'heartbeat' ), $this->plugin->get_version() );
437 + wp_enqueue_script(
438 + 'wp-stream-admin',
439 + $this->plugin->locations['url'] . 'ui/js/admin.' . $min . 'js',
440 + array(
441 + 'jquery',
442 + 'wp-stream-select2',
443 + ),
444 + $this->plugin->get_version(),
445 + false
446 + );
447 + wp_enqueue_script(
448 + 'wp-stream-admin-exclude',
449 + $this->plugin->locations['url'] . 'ui/js/exclude.' . $min . 'js',
450 + array(
451 + 'jquery',
452 + 'wp-stream-select2',
453 + ),
454 + $this->plugin->get_version(),
455 + false
456 + );
457 + wp_enqueue_script(
458 + 'wp-stream-live-updates',
459 + $this->plugin->locations['url'] . 'ui/js/live-updates.' . $min . 'js',
460 + array(
461 + 'jquery',
462 + 'heartbeat',
463 + ),
464 + $this->plugin->get_version(),
465 + false
466 + );
376 467
377 468 wp_localize_script(
378 469 'wp-stream-admin',
379 470 'wp_stream',
@@ -387,17 +478,21 @@
387 478 'gmt_offset' => get_option( 'gmt_offset' ),
388 479 )
389 480 );
390 481
482 + $order_types = array( 'asc', 'desc' );
483 +
391 484 wp_localize_script(
392 485 'wp-stream-live-updates',
393 486 'wp_stream_live_updates',
394 487 array(
395 488 'current_screen' => $hook,
396 - 'current_page' => isset( $_GET['paged'] ) ? esc_js( $_GET['paged'] ) : '1', // input var okay
397 - 'current_order' => isset( $_GET['order'] ) ? esc_js( $_GET['order'] ) : 'desc', // input var okay
398 - 'current_query' => wp_stream_json_encode( $_GET ), // input var okay
399 - 'current_query_count' => count( $_GET ), // input var okay
489 + 'current_page' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : '1', // phpcs:ignore WordPress.Security.NonceVerification.Recommended
490 + 'current_order' => isset( $_GET['order'] ) && in_array( strtolower( $_GET['order'] ), $order_types, true ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
491 + ? esc_js( $_GET['order'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
492 + : 'desc',
493 + 'current_query' => wp_stream_json_encode( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
494 + 'current_query_count' => count( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
400 495 )
401 496 );
402 497 }
403 498
@@ -414,15 +509,23 @@
414 509 * @return int
415 510 */
416 511 $bulk_actions_threshold = apply_filters( 'wp_stream_bulk_actions_threshold', 100 );
417 512
418 - wp_enqueue_script( 'wp-stream-global', $this->plugin->locations['url'] . 'ui/js/global.js', array( 'jquery' ), $this->plugin->get_version() );
513 + wp_enqueue_script(
514 + 'wp-stream-global',
515 + $this->plugin->locations['url'] . 'ui/js/global.' . $min . 'js',
516 + array( 'jquery' ),
517 + $this->plugin->get_version(),
518 + false
519 + );
520 +
419 521 wp_localize_script(
420 522 'wp-stream-global',
421 523 'wp_stream_global',
422 524 array(
423 - 'bulk_actions' => array(
424 - 'i18n' => array(
525 + 'bulk_actions' => array(
526 + 'i18n' => array(
527 + /* translators: %s: a number of items (e.g. "1,742") */
425 528 'confirm_action' => sprintf( esc_html__( 'Are you sure you want to perform bulk actions on over %s items? This process could take a while to complete.', 'stream' ), number_format( absint( $bulk_actions_threshold ) ) ),
426 529 ),
427 530 'threshold' => absint( $bulk_actions_threshold ),
428 531 ),
@@ -440,8 +543,13 @@
440 543 if ( is_admin() && false !== strpos( wp_stream_filter_input( INPUT_GET, 'page' ), $this->records_page_slug ) ) {
441 544 return true;
442 545 }
443 546
547 + $screen = get_current_screen();
548 + if ( is_admin() && Alerts::POST_TYPE === $screen->post_type ) {
549 + return true;
550 + }
551 +
444 552 return false;
445 553 }
446 554
447 555 /**
@@ -446,9 +554,9 @@
446 554
447 555 /**
448 556 * Add a specific body class to all Stream admin screens
449 557 *
450 - * @param string $classes CSS classes to output to body
558 + * @param string $classes CSS classes to output to body.
451 559 *
452 560 * @filter admin_body_class
453 561 *
454 562 * @return string
@@ -458,10 +566,10 @@
458 566
459 567 if ( $this->is_stream_screen() ) {
460 568 $stream_classes[] = $this->admin_body_class;
461 569
462 - if ( isset( $_GET['page'] ) ) {
463 - $stream_classes[] = sanitize_key( $_GET['page'] ); // input var okay
570 + if ( isset( $_GET['page'] ) ) { // // phpcs:ignore WordPress.Security.NonceVerification.Recommended
571 + $stream_classes[] = sanitize_key( $_GET['page'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
464 572 }
465 573 }
466 574
467 575 /**
@@ -482,16 +590,17 @@
482 590 *
483 591 * @action admin_enqueue_scripts
484 592 */
485 593 public function admin_menu_css() {
486 - wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.css', array(), $this->plugin->get_version() );
594 + $min = wp_stream_min_suffix();
595 + wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.' . $min . 'css', array(), $this->plugin->get_version() );
487 596 wp_register_style( 'wp-stream-icons', $this->plugin->locations['url'] . 'ui/stream-icons/style.css', array(), $this->plugin->get_version() );
488 597
489 - // Make sure we're working off a clean version
598 + // Make sure we're working off a clean version.
490 599 if ( ! file_exists( ABSPATH . WPINC . '/version.php' ) ) {
491 600 return;
492 601 }
493 - include( ABSPATH . WPINC . '/version.php' );
602 + include ABSPATH . WPINC . '/version.php';
494 603
495 604 if ( ! isset( $wp_version ) ) {
496 605 return;
497 606 }
@@ -550,10 +659,15 @@
550 659
551 660 \wp_add_inline_style( 'wp-admin', $css );
552 661 }
553 662
663 + /**
664 + * Handle the reset AJAX request to reset logs.
665 + *
666 + * @return bool
667 + */
554 668 public function wp_ajax_reset() {
555 - check_ajax_referer( 'stream_nonce', 'wp_stream_nonce' );
669 + check_ajax_referer( 'stream_nonce_reset', 'wp_stream_nonce_reset' );
556 670
557 671 if ( ! current_user_can( $this->settings_cap ) ) {
558 672 wp_die(
559 673 esc_html__( "You don't have sufficient privileges to do this action.", 'stream' )
@@ -565,9 +679,9 @@
565 679 if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
566 680 return true;
567 681 }
568 682
569 - wp_redirect(
683 + wp_safe_redirect(
570 684 add_query_arg(
571 685 array(
572 686 'page' => is_network_admin() ? $this->network->network_settings_page_slug : $this->settings_page_slug,
573 687 'message' => 'data_erased',
@@ -578,14 +692,19 @@
578 692
579 693 exit;
580 694 }
581 695
696 + /**
697 + * Clears stream records from the database.
698 + *
699 + * @return void
700 + */
582 701 private function erase_stream_records() {
583 702 global $wpdb;
584 703
585 704 $where = '';
586 705
587 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
706 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
588 707 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
589 708 }
590 709
591 710 $wpdb->query(
@@ -596,8 +715,13 @@
596 715 WHERE 1=1 {$where};" // @codingStandardsIgnoreLine $where already prepared
597 716 );
598 717 }
599 718
719 + /**
720 + * Schedules a purge of records.
721 + *
722 + * @return void
723 + */
600 724 public function purge_schedule_setup() {
601 725 if ( ! wp_next_scheduled( 'wp_stream_auto_purge' ) ) {
602 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
603 727 }
@@ -602,41 +726,48 @@
602 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
603 727 }
604 728 }
605 729
730 + /**
731 + * Executes a scheduled purge
732 + *
733 + * @return void
734 + */
606 735 public function purge_scheduled_action() {
607 736 global $wpdb;
608 737
609 - // Don't purge when in Network Admin unless Stream is network activated
738 + // Don't purge when in Network Admin unless Stream is network activated.
610 739 if (
611 740 is_multisite()
612 741 &&
613 742 is_network_admin()
614 743 &&
615 - ! is_plugin_active_for_network( $this->plugin->locations['plugin'] )
744 + ! $this->plugin->is_network_activated()
616 745 ) {
617 746 return;
618 747 }
619 748
620 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
621 - $options = (array) get_site_option( 'wp_stream_network', array() );
749 + $defaults = $this->plugin->settings->get_defaults();
750 + if ( is_multisite() && $this->plugin->is_network_activated() ) {
751 + $options = (array) get_site_option( 'wp_stream_network', $defaults );
622 752 } else {
623 - $options = (array) get_option( 'wp_stream', array() );
753 + $options = (array) get_option( 'wp_stream', $defaults );
624 754 }
625 755
626 - if ( isset( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
756 + if ( ! empty( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
627 757 return;
628 758 }
629 759
630 - $days = $options['general_records_ttl'];
631 - $date = new DateTime( 'now', $timezone = new DateTimeZone( 'UTC' ) );
760 + $days = $options['general_records_ttl'];
761 + $timezone = new DateTimeZone( 'UTC' );
762 + $date = new DateTime( 'now', $timezone );
632 763
633 764 $date->sub( DateInterval::createFromDateString( "$days days" ) );
634 765
635 766 $where = $wpdb->prepare( ' AND `stream`.`created` < %s', $date->format( 'Y-m-d H:i:s' ) );
636 767
637 - // Multisite but NOT network activated, only purge the current blog
638 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
768 + // Multisite but NOT network activated, only purge the current blog.
769 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
639 770 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
640 771 }
641 772
642 773 $wpdb->query(
@@ -648,13 +779,15 @@
648 779 );
649 780 }
650 781
651 782 /**
652 - * @param array $links
653 - * @param string $file
783 + * Returns the admin action links.
654 784 *
655 785 * @filter plugin_action_links
656 786 *
787 + * @param array $links Action links.
788 + * @param string $file Plugin file.
789 + *
657 790 * @return array
658 791 */
659 792 public function plugin_action_links( $links, $file ) {
660 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
@@ -660,30 +793,42 @@
660 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
661 794 return $links;
662 795 }
663 796
664 - // Also don't show links in Network Admin if Stream isn't network enabled
665 - if ( is_network_admin() && is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
797 + // Also don't show links in Network Admin if Stream isn't network enabled.
798 + if ( is_network_admin() && is_multisite() && ! $this->plugin->is_network_activated() ) {
666 799 return $links;
667 800 }
668 801
669 802 if ( is_network_admin() ) {
670 - $admin_page_url = add_query_arg( array( 'page' => $this->network->network_settings_page_slug ), network_admin_url( $this->admin_parent_page ) );
803 + $admin_page_url = add_query_arg(
804 + array(
805 + 'page' => $this->network->network_settings_page_slug,
806 + ),
807 + network_admin_url( $this->admin_parent_page )
808 + );
671 809 } else {
672 - $admin_page_url = add_query_arg( array( 'page' => $this->settings_page_slug ), admin_url( $this->admin_parent_page ) );
810 + $admin_page_url = add_query_arg(
811 + array(
812 + 'page' => $this->settings_page_slug,
813 + ),
814 + admin_url( $this->admin_parent_page )
815 + );
673 816 }
674 817
675 818 $links[] = sprintf( '<a href="%s">%s</a>', esc_url( $admin_page_url ), esc_html__( 'Settings', 'default' ) );
676 819
677 - $url = add_query_arg(
678 - array(
679 - 'action' => 'wp_stream_uninstall',
680 - 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
681 - ),
682 - admin_url( 'admin-ajax.php' )
683 - );
820 + if ( ! defined( 'DISALLOW_FILE_MODS' ) || false === DISALLOW_FILE_MODS ) {
821 + $url = add_query_arg(
822 + array(
823 + 'action' => 'wp_stream_uninstall',
824 + 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
825 + ),
826 + admin_url( 'admin-ajax.php' )
827 + );
684 828
685 - $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
829 + $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
830 + }
686 831
687 832 return $links;
688 833 }
689 834
@@ -693,12 +838,12 @@
693 838 public function render_list_table() {
694 839 $this->list_table->prepare_items();
695 840 ?>
696 841 <div class="wrap">
697 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
698 - <?php $this->list_table->display() ?>
842 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
843 + <?php $this->list_table->display(); ?>
699 844 </div>
700 - <?php
845 + <?php
701 846 }
702 847
703 848 /**
704 849 * Render settings page
@@ -710,28 +855,28 @@
710 855 $page_description = apply_filters( 'wp_stream_settings_form_description', '' );
711 856
712 857 $sections = $this->plugin->settings->get_fields();
713 858 $active_tab = wp_stream_filter_input( INPUT_GET, 'tab' );
714 -
715 - wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.js', array( 'jquery' ), $this->plugin->get_version(), true );
859 + $min = wp_stream_min_suffix();
860 + wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.' . $min . 'js', array( 'jquery' ), $this->plugin->get_version(), true );
716 861 ?>
717 862 <div class="wrap">
718 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
863 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
719 864
720 865 <?php if ( ! empty( $page_description ) ) : ?>
721 - <p><?php echo esc_html( $page_description ) ?></p>
866 + <p><?php echo esc_html( $page_description ); ?></p>
722 867 <?php endif; ?>
723 868
724 - <?php settings_errors() ?>
869 + <?php settings_errors(); ?>
725 870
726 871 <?php if ( count( $sections ) > 1 ) : ?>
727 872 <h2 class="nav-tab-wrapper">
728 - <?php $i = 0 ?>
873 + <?php $i = 0; ?>
729 874 <?php foreach ( $sections as $section => $data ) : ?>
730 - <?php $i ++ ?>
731 - <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ) ?>
732 - <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ) ?>" class="nav-tab<?php if ( $is_active ) { echo esc_attr( ' nav-tab-active' ); } ?>">
733 - <?php echo esc_html( $data['title'] ) ?>
875 + <?php $i++; ?>
876 + <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ); ?>
877 + <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ); ?>" class="nav-tab <?php echo $is_active ? esc_attr( ' nav-tab-active' ) : ''; ?>">
878 + <?php echo esc_html( $data['title'] ); ?>
734 879 </a>
735 880 <?php endforeach; ?>
736 881 </h2>
737 882 <?php endif; ?>
@@ -736,29 +881,29 @@
736 881 </h2>
737 882 <?php endif; ?>
738 883
739 884 <div class="nav-tab-content" id="tab-content-settings">
740 - <form method="post" action="<?php echo esc_attr( $form_action ) ?>" enctype="multipart/form-data">
885 + <form method="post" action="<?php echo esc_attr( $form_action ); ?>" enctype="multipart/form-data">
741 886 <div class="settings-sections">
742 - <?php
743 - $i = 0;
744 - foreach ( $sections as $section => $data ) {
745 - $i++;
887 + <?php
888 + $i = 0;
889 + foreach ( $sections as $section => $data ) {
890 + $i++;
746 891
747 - $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
892 + $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
748 893
749 - if ( $is_active ) {
750 - settings_fields( $option_key );
751 - do_settings_sections( $option_key );
752 - }
753 - }
754 - ?>
894 + if ( $is_active ) {
895 + settings_fields( $option_key );
896 + do_settings_sections( $option_key );
897 + }
898 + }
899 + ?>
755 900 </div>
756 - <?php submit_button() ?>
901 + <?php submit_button(); ?>
757 902 </form>
758 903 </div>
759 904 </div>
760 - <?php
905 + <?php
761 906 }
762 907
763 908 /**
764 909 * Instantiate the list table
@@ -763,15 +908,20 @@
763 908 /**
764 909 * Instantiate the list table
765 910 */
766 911 public function register_list_table() {
767 - $this->list_table = new List_Table( $this->plugin, array( 'screen' => $this->screen_id['main'] ) );
912 + $this->list_table = new List_Table(
913 + $this->plugin,
914 + array(
915 + 'screen' => $this->screen_id['main'],
916 + )
917 + );
768 918 }
769 919
770 920 /**
771 921 * Check if a particular role has access
772 922 *
773 - * @param string $role
923 + * @param string $role User role.
774 924 *
775 925 * @return bool
776 926 */
777 927 private function role_can_view( $role ) {
@@ -784,12 +934,12 @@
784 934
785 935 /**
786 936 * Filter user caps to dynamically grant our view cap based on allowed roles
787 937 *
788 - * @param $allcaps
789 - * @param $caps
790 - * @param $args
791 - * @param $user
938 + * @param array $allcaps All capabilities.
939 + * @param array $caps Required caps.
940 + * @param array $args Unused.
941 + * @param WP_User $user User.
792 942 *
793 943 * @filter user_has_cap
794 944 *
795 945 * @return array
@@ -834,11 +984,11 @@
834 984 * Filter role caps to dynamically grant our view cap based on allowed roles
835 985 *
836 986 * @filter role_has_cap
837 987 *
838 - * @param $allcaps
839 - * @param $cap
840 - * @param $role
988 + * @param array $allcaps All capabilities.
989 + * @param string $cap Require cap.
990 + * @param string $role User role.
841 991 *
842 992 * @return array
843 993 */
844 994 public function filter_role_caps( $allcaps, $cap, $role ) {
@@ -851,15 +1001,27 @@
851 1001 return $allcaps;
852 1002 }
853 1003
854 1004 /**
1005 + * Ajax callback for return a user list.
1006 + *
855 1007 * @action wp_ajax_wp_stream_filters
856 1008 */
857 1009 public function ajax_filters() {
1010 + if ( ! defined( 'DOING_AJAX' ) || ! current_user_can( $this->plugin->admin->settings_cap ) ) {
1011 + wp_die( '-1' );
1012 + }
1013 +
1014 + check_ajax_referer( 'stream_filters_user_search_nonce', 'nonce' );
1015 +
858 1016 switch ( wp_stream_filter_input( INPUT_GET, 'filter' ) ) {
859 1017 case 'user_id':
860 1018 $users = array_merge(
861 - array( 0 => (object) array( 'display_name' => 'WP-CLI' ) ),
1019 + array(
1020 + 0 => (object) array(
1021 + 'display_name' => 'WP-CLI',
1022 + ),
1023 + ),
862 1024 get_users()
863 1025 );
864 1026
865 1027 $search = wp_stream_filter_input( INPUT_GET, 'q' );
@@ -866,9 +1028,9 @@
866 1028 if ( $search ) {
867 1029 // `search` arg for get_users() is not enough
868 1030 $users = array_filter(
869 1031 $users,
870 - function( $user ) use ( $search ) {
1032 + function ( $user ) use ( $search ) {
871 1033 return false !== mb_strpos( mb_strtolower( $user->display_name ), mb_strtolower( $search ) );
872 1034 }
873 1035 );
874 1036 }
@@ -876,9 +1038,9 @@
876 1038 if ( count( $users ) > $this->preload_users_max ) {
877 1039 $users = array_slice( $users, 0, $this->preload_users_max );
878 1040 }
879 1041
880 - // Get gravatar / roles for final result set
1042 + // Get gravatar / roles for final result set.
881 1043 $results = $this->get_users_record_meta( $users );
882 1044
883 1045 break;
884 1046 }
@@ -883,68 +1045,32 @@
883 1045 break;
884 1046 }
885 1047
886 1048 if ( isset( $results ) ) {
887 - echo wp_stream_json_encode( array_values( $results ) ); // xss ok
1049 + echo wp_stream_json_encode( $results ); // xss ok.
888 1050 }
889 1051
890 - if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
891 - return;
892 - }
893 -
894 1052 die();
895 1053 }
896 1054
897 1055 /**
898 - * @action wp_ajax_wp_stream_get_filter_value_by_id
1056 + * Return relevant user meta data.
1057 + *
1058 + * @param array $authors Author data.
1059 + * @return array
899 1060 */
900 - public function get_filter_value_by_id() {
901 - $filter = wp_stream_filter_input( INPUT_POST, 'filter' );
902 -
903 - switch ( $filter ) {
904 - case 'user_id':
905 - $id = wp_stream_filter_input( INPUT_POST, 'id' );
906 -
907 - if ( '0' === $id ) {
908 - $value = 'WP-CLI';
909 -
910 - break;
911 - }
912 -
913 - $user = get_userdata( $id );
914 -
915 - if ( ! $user || is_wp_error( $user ) ) {
916 - $value = '';
917 - } else {
918 - $value = $user->display_name;
919 - }
920 -
921 - break;
922 - default:
923 - $value = '';
924 - }
925 -
926 - echo wp_stream_json_encode( $value ); // xss ok
927 -
928 - if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
929 - return;
930 - }
931 -
932 - die();
933 - }
934 -
935 1061 public function get_users_record_meta( $authors ) {
936 1062 $authors_records = array();
937 1063
938 1064 foreach ( $authors as $user_id => $args ) {
939 - $author = new Author( $user_id );
1065 + $author = new Author( $args->ID );
940 1066
941 1067 $authors_records[ $user_id ] = array(
942 - 'text' => $author->get_display_name(),
943 - 'id' => $user_id,
944 - 'label' => $author->get_display_name(),
945 - 'icon' => $author->get_avatar_src( 32 ),
946 - 'title' => '',
1068 + 'text' => $author->get_display_name(),
1069 + 'id' => $author->id,
1070 + 'label' => $author->get_display_name(),
1071 + 'icon' => $author->get_avatar_src( 32 ),
1072 + 'title' => '',
947 1073 );
948 1074 }
949 1075
950 1076 return $authors_records;
@@ -952,18 +1078,19 @@
952 1078
953 1079 /**
954 1080 * Get user meta in a way that is also safe for VIP
955 1081 *
956 - * @param int $user_id
957 - * @param string $meta_key
958 - * @param bool $single (optional)
1082 + * @param int $user_id User ID.
1083 + * @param string $meta_key Meta key.
1084 + * @param bool $single Return first found meta value connected to the meta key (optional).
959 1085 *
960 1086 * @return mixed
961 1087 */
962 - function get_user_meta( $user_id, $meta_key, $single = true ) {
1088 + public function get_user_meta( $user_id, $meta_key, $single = true ) {
963 1089 if ( wp_stream_is_vip() && function_exists( 'get_user_attribute' ) ) {
964 1090 return get_user_attribute( $user_id, $meta_key );
965 1091 }
1092 +
966 1093 return get_user_meta( $user_id, $meta_key, $single );
967 1094 }
968 1095
969 1096 /**
@@ -968,19 +1095,20 @@
968 1095
969 1096 /**
970 1097 * Update user meta in a way that is also safe for VIP
971 1098 *
972 - * @param int $user_id
973 - * @param string $meta_key
974 - * @param mixed $meta_value
975 - * @param mixed $prev_value (optional)
1099 + * @param int $user_id User ID.
1100 + * @param string $meta_key Meta key.
1101 + * @param mixed $meta_value Meta value.
1102 + * @param mixed $prev_value Previous meta value being overwritten (optional).
976 1103 *
977 1104 * @return int|bool
978 1105 */
979 - function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
1106 + public function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
980 1107 if ( wp_stream_is_vip() && function_exists( 'update_user_attribute' ) ) {
981 1108 return update_user_attribute( $user_id, $meta_key, $meta_value );
982 1109 }
1110 +
983 1111 return update_user_meta( $user_id, $meta_key, $meta_value, $prev_value );
984 1112 }
985 1113
986 1114 /**
@@ -985,17 +1113,18 @@
985 1113
986 1114 /**
987 1115 * Delete user meta in a way that is also safe for VIP
988 1116 *
989 - * @param int $user_id
990 - * @param string $meta_key
991 - * @param mixed $meta_value (optional)
1117 + * @param int $user_id User ID.
1118 + * @param string $meta_key Meta key.
1119 + * @param mixed $meta_value Meta value (optional).
992 1120 *
993 1121 * @return bool
994 1122 */
995 - function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
1123 + public function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
996 1124 if ( wp_stream_is_vip() && function_exists( 'delete_user_attribute' ) ) {
997 1125 return delete_user_attribute( $user_id, $meta_key, $meta_value );
998 1126 }
1127 +
999 1128 return delete_user_meta( $user_id, $meta_key, $meta_value );
1000 1129 }
1001 1130 }