PluginProbe
Stream – Activity Log & Audit Trail / 3.8.0
Stream – Activity Log & Audit Trail v3.8.0
4.4.0 4.3.0 4.2.2 4.2.1 trunk 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.1 3.1.1 3.10.0 3.2.0 3.2.1 3.2.2 3.2.3 All 50 releases
← All changes | classes/class-admin.php +294 -121 3.0.73.8.0 View file →
@@ -1,5 +1,11 @@
1 1 <?php
2 +/**
3 + * Centralized manager for WordPress backend functionality.
4 + *
5 + * @package WP_Stream
6 + */
7 +
2 8 namespace WP_Stream;
3 9
4 10 use DateTime;
5 11 use DateTimeZone;
@@ -6,11 +12,15 @@
6 12 use DateInterval;
7 13 use \WP_CLI;
8 14 use \WP_Roles;
9 15
16 +/**
17 + * Class - Admin
18 + */
10 19 class Admin {
20 +
11 21 /**
12 - * Hold Plugin class
22 + * Holds Instance of plugin object
13 23 *
14 24 * @var Plugin
15 25 */
16 26 public $plugin;
@@ -115,9 +125,9 @@
115 125
116 126 /**
117 127 * Class constructor.
118 128 *
119 - * @param Plugin $plugin The main Plugin class.
129 + * @param Plugin $plugin Instance of plugin object.
120 130 */
121 131 public function __construct( $plugin ) {
122 132 $this->plugin = $plugin;
123 133
@@ -124,9 +134,9 @@
124 134 add_action( 'init', array( $this, 'init' ) );
125 135
126 136 // Ensure function used in various methods is pre-loaded.
127 137 if ( ! function_exists( 'is_plugin_active_for_network' ) ) {
128 - require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
138 + require_once ABSPATH . '/wp-admin/includes/plugin.php';
129 139 }
130 140
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
@@ -131,9 +141,9 @@
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
133 143 add_filter( 'role_has_cap', array( $this, 'filter_role_caps' ), 10, 3 );
134 144
135 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) && ! is_network_admin() ) {
145 + if ( is_multisite() && $plugin->is_network_activated() && ! is_network_admin() ) {
136 146 $options = (array) get_site_option( 'wp_stream_network', array() );
137 147 $option = isset( $options['general_site_access'] ) ? absint( $options['general_site_access'] ) : 1;
138 148
139 149 $this->disable_access = ( $option ) ? false : true;
@@ -151,27 +161,62 @@
151 161 // Add admin body class.
152 162 add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
153 163
154 164 // Plugin action links.
155 - add_filter( 'plugin_action_links', array( $this, 'plugin_action_links' ), 10, 2 );
165 + add_filter(
166 + 'plugin_action_links',
167 + array(
168 + $this,
169 + 'plugin_action_links',
170 + ),
171 + 10,
172 + 2
173 + );
156 174
157 175 // Load admin scripts and styles.
158 - add_action( 'admin_enqueue_scripts', array( $this, 'admin_enqueue_scripts' ) );
176 + add_action(
177 + 'admin_enqueue_scripts',
178 + array(
179 + $this,
180 + 'admin_enqueue_scripts',
181 + )
182 + );
159 183 add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
160 184
161 185 // Reset Streams database.
162 - add_action( 'wp_ajax_wp_stream_reset', array( $this, 'wp_ajax_reset' ) );
186 + add_action(
187 + 'wp_ajax_wp_stream_reset',
188 + array(
189 + $this,
190 + 'wp_ajax_reset',
191 + )
192 + );
163 193
164 - // Uninstall Streams and Deactivate plugin.
165 - $uninstall = new Uninstall( $this->plugin );
166 - add_action( 'wp_ajax_wp_stream_uninstall', array( $uninstall, 'uninstall' ) );
194 + /**
195 + * Uninstall Streams and Deactivate plugin.
196 + *
197 + * @todo Confirm if variable assignment is necessary.
198 + */
199 + $uninstall = $this->plugin->db->driver->purge_storage( $this->plugin );
167 200
168 201 // Auto purge setup.
169 202 add_action( 'wp_loaded', array( $this, 'purge_schedule_setup' ) );
170 - add_action( 'wp_stream_auto_purge', array( $this, 'purge_scheduled_action' ) );
203 + add_action(
204 + 'wp_stream_auto_purge',
205 + array(
206 + $this,
207 + 'purge_scheduled_action',
208 + )
209 + );
171 210
172 211 // Ajax users list.
173 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
212 + add_action(
213 + 'wp_ajax_wp_stream_filters',
214 + array(
215 + $this,
216 + 'ajax_filters',
217 + )
218 + );
174 219 }
175 220
176 221 /**
177 222 * Load admin classes
@@ -208,9 +253,9 @@
208 253 * @param bool $is_error If the message is error_level (true) or warning (false).
209 254 */
210 255 public function notice( $message, $is_error = true ) {
211 256 if ( defined( 'WP_CLI' ) && WP_CLI ) {
212 - $message = strip_tags( $message );
257 + $message = wp_strip_all_tags( $message );
213 258
214 259 if ( $is_error ) {
215 260 WP_CLI::warning( $message );
216 261 } else {
@@ -299,8 +344,16 @@
299 344 $main_menu_position
300 345 );
301 346
302 347 /**
348 + * Fires before submenu items are added to the Stream menu
349 + * allowing plugins to add menu items before Settings
350 + *
351 + * @return void
352 + */
353 + do_action( 'wp_stream_admin_menu' );
354 +
355 + /**
303 356 * Filter the Settings admin page title
304 357 *
305 358 * @return string
306 359 */
@@ -323,9 +376,15 @@
323 376 */
324 377 do_action( 'wp_stream_admin_menu_screens' );
325 378
326 379 // Register the list table early, so it associates the column headers with 'Screen settings'.
327 - add_action( 'load-' . $this->screen_id['main'], array( $this, 'register_list_table' ) );
380 + add_action(
381 + 'load-' . $this->screen_id['main'],
382 + array(
383 + $this,
384 + 'register_list_table',
385 + )
386 + );
328 387 }
329 388 }
330 389
331 390 /**
@@ -332,15 +391,15 @@
332 391 * Enqueue scripts/styles for admin screen
333 392 *
334 393 * @action admin_enqueue_scripts
335 394 *
336 - * @param string $hook
395 + * @param string $hook Current hook.
337 396 *
338 397 * @return void
339 398 */
340 399 public function admin_enqueue_scripts( $hook ) {
341 - wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/js/select2.js', array( 'jquery' ), '3.5.2', true );
342 - wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/css/select2.css', array(), '3.5.2' );
400 + wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/js/select2.full.min.js', array( 'jquery' ), '3.5.2', true );
401 + wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/css/select2.min.css', array(), '3.5.2' );
343 402 wp_register_script( 'wp-stream-timeago', $this->plugin->locations['url'] . 'ui/lib/timeago/jquery.timeago.js', array(), '1.4.1', true );
344 403
345 404 $locale = strtolower( substr( get_locale(), 0, 2 ) );
346 405 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
@@ -345,14 +404,27 @@
345 404 $locale = strtolower( substr( get_locale(), 0, 2 ) );
346 405 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
347 406
348 407 if ( file_exists( $this->plugin->locations['dir'] . sprintf( $file_tmpl, $locale ) ) ) {
349 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ), array( 'wp-stream-timeago' ), '1' );
408 + wp_register_script(
409 + 'wp-stream-timeago-locale',
410 + $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ),
411 + array( 'wp-stream-timeago' ),
412 + '1',
413 + false
414 + );
350 415 } else {
351 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ), array( 'wp-stream-timeago' ), '1' );
416 + wp_register_script(
417 + 'wp-stream-timeago-locale',
418 + $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ),
419 + array( 'wp-stream-timeago' ),
420 + '1',
421 + false
422 + );
352 423 }
353 424
354 - wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.css', array(), $this->plugin->get_version() );
425 + $min = wp_stream_min_suffix();
426 + wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.' . $min . 'css', array(), $this->plugin->get_version() );
355 427
356 428 $script_screens = array( 'plugins.php' );
357 429
358 430 if ( in_array( $hook, $this->screen_id, true ) || in_array( $hook, $script_screens, true ) ) {
@@ -361,11 +433,38 @@
361 433
362 434 wp_enqueue_script( 'wp-stream-timeago' );
363 435 wp_enqueue_script( 'wp-stream-timeago-locale' );
364 436
365 - wp_enqueue_script( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/js/admin.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
366 - wp_enqueue_script( 'wp-stream-admin-exclude', $this->plugin->locations['url'] . 'ui/js/exclude.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
367 - wp_enqueue_script( 'wp-stream-live-updates', $this->plugin->locations['url'] . 'ui/js/live-updates.js', array( 'jquery', 'heartbeat' ), $this->plugin->get_version() );
437 + wp_enqueue_script(
438 + 'wp-stream-admin',
439 + $this->plugin->locations['url'] . 'ui/js/admin.' . $min . 'js',
440 + array(
441 + 'jquery',
442 + 'wp-stream-select2',
443 + ),
444 + $this->plugin->get_version(),
445 + false
446 + );
447 + wp_enqueue_script(
448 + 'wp-stream-admin-exclude',
449 + $this->plugin->locations['url'] . 'ui/js/exclude.' . $min . 'js',
450 + array(
451 + 'jquery',
452 + 'wp-stream-select2',
453 + ),
454 + $this->plugin->get_version(),
455 + false
456 + );
457 + wp_enqueue_script(
458 + 'wp-stream-live-updates',
459 + $this->plugin->locations['url'] . 'ui/js/live-updates.' . $min . 'js',
460 + array(
461 + 'jquery',
462 + 'heartbeat',
463 + ),
464 + $this->plugin->get_version(),
465 + false
466 + );
368 467
369 468 wp_localize_script(
370 469 'wp-stream-admin',
371 470 'wp_stream',
@@ -379,17 +478,21 @@
379 478 'gmt_offset' => get_option( 'gmt_offset' ),
380 479 )
381 480 );
382 481
482 + $order_types = array( 'asc', 'desc' );
483 +
383 484 wp_localize_script(
384 485 'wp-stream-live-updates',
385 486 'wp_stream_live_updates',
386 487 array(
387 488 'current_screen' => $hook,
388 - 'current_page' => isset( $_GET['paged'] ) ? esc_js( $_GET['paged'] ) : '1', // input var okay
389 - 'current_order' => isset( $_GET['order'] ) ? esc_js( $_GET['order'] ) : 'desc', // input var okay
390 - 'current_query' => wp_stream_json_encode( $_GET ), // input var okay
391 - 'current_query_count' => count( $_GET ), // input var okay
489 + 'current_page' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : '1', // phpcs:ignore WordPress.Security.NonceVerification.Recommended
490 + 'current_order' => isset( $_GET['order'] ) && in_array( strtolower( $_GET['order'] ), $order_types, true ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
491 + ? esc_js( $_GET['order'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
492 + : 'desc',
493 + 'current_query' => wp_stream_json_encode( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
494 + 'current_query_count' => count( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
392 495 )
393 496 );
394 497 }
395 498
@@ -406,15 +509,23 @@
406 509 * @return int
407 510 */
408 511 $bulk_actions_threshold = apply_filters( 'wp_stream_bulk_actions_threshold', 100 );
409 512
410 - wp_enqueue_script( 'wp-stream-global', $this->plugin->locations['url'] . 'ui/js/global.js', array( 'jquery' ), $this->plugin->get_version() );
513 + wp_enqueue_script(
514 + 'wp-stream-global',
515 + $this->plugin->locations['url'] . 'ui/js/global.' . $min . 'js',
516 + array( 'jquery' ),
517 + $this->plugin->get_version(),
518 + false
519 + );
520 +
411 521 wp_localize_script(
412 522 'wp-stream-global',
413 523 'wp_stream_global',
414 524 array(
415 - 'bulk_actions' => array(
416 - 'i18n' => array(
525 + 'bulk_actions' => array(
526 + 'i18n' => array(
527 + /* translators: %s: a number of items (e.g. "1,742") */
417 528 'confirm_action' => sprintf( esc_html__( 'Are you sure you want to perform bulk actions on over %s items? This process could take a while to complete.', 'stream' ), number_format( absint( $bulk_actions_threshold ) ) ),
418 529 ),
419 530 'threshold' => absint( $bulk_actions_threshold ),
420 531 ),
@@ -432,8 +543,13 @@
432 543 if ( is_admin() && false !== strpos( wp_stream_filter_input( INPUT_GET, 'page' ), $this->records_page_slug ) ) {
433 544 return true;
434 545 }
435 546
547 + $screen = get_current_screen();
548 + if ( is_admin() && Alerts::POST_TYPE === $screen->post_type ) {
549 + return true;
550 + }
551 +
436 552 return false;
437 553 }
438 554
439 555 /**
@@ -438,9 +554,9 @@
438 554
439 555 /**
440 556 * Add a specific body class to all Stream admin screens
441 557 *
442 - * @param string $classes CSS classes to output to body
558 + * @param string $classes CSS classes to output to body.
443 559 *
444 560 * @filter admin_body_class
445 561 *
446 562 * @return string
@@ -450,10 +566,10 @@
450 566
451 567 if ( $this->is_stream_screen() ) {
452 568 $stream_classes[] = $this->admin_body_class;
453 569
454 - if ( isset( $_GET['page'] ) ) {
455 - $stream_classes[] = sanitize_key( $_GET['page'] ); // input var okay
570 + if ( isset( $_GET['page'] ) ) { // // phpcs:ignore WordPress.Security.NonceVerification.Recommended
571 + $stream_classes[] = sanitize_key( $_GET['page'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
456 572 }
457 573 }
458 574
459 575 /**
@@ -474,16 +590,17 @@
474 590 *
475 591 * @action admin_enqueue_scripts
476 592 */
477 593 public function admin_menu_css() {
478 - wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.css', array(), $this->plugin->get_version() );
594 + $min = wp_stream_min_suffix();
595 + wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.' . $min . 'css', array(), $this->plugin->get_version() );
479 596 wp_register_style( 'wp-stream-icons', $this->plugin->locations['url'] . 'ui/stream-icons/style.css', array(), $this->plugin->get_version() );
480 597
481 - // Make sure we're working off a clean version
598 + // Make sure we're working off a clean version.
482 599 if ( ! file_exists( ABSPATH . WPINC . '/version.php' ) ) {
483 600 return;
484 601 }
485 - include( ABSPATH . WPINC . '/version.php' );
602 + include ABSPATH . WPINC . '/version.php';
486 603
487 604 if ( ! isset( $wp_version ) ) {
488 605 return;
489 606 }
@@ -542,10 +659,15 @@
542 659
543 660 \wp_add_inline_style( 'wp-admin', $css );
544 661 }
545 662
663 + /**
664 + * Handle the reset AJAX request to reset logs.
665 + *
666 + * @return bool
667 + */
546 668 public function wp_ajax_reset() {
547 - check_ajax_referer( 'stream_nonce', 'wp_stream_nonce' );
669 + check_ajax_referer( 'stream_nonce_reset', 'wp_stream_nonce_reset' );
548 670
549 671 if ( ! current_user_can( $this->settings_cap ) ) {
550 672 wp_die(
551 673 esc_html__( "You don't have sufficient privileges to do this action.", 'stream' )
@@ -557,9 +679,9 @@
557 679 if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
558 680 return true;
559 681 }
560 682
561 - wp_redirect(
683 + wp_safe_redirect(
562 684 add_query_arg(
563 685 array(
564 686 'page' => is_network_admin() ? $this->network->network_settings_page_slug : $this->settings_page_slug,
565 687 'message' => 'data_erased',
@@ -570,14 +692,19 @@
570 692
571 693 exit;
572 694 }
573 695
696 + /**
697 + * Clears stream records from the database.
698 + *
699 + * @return void
700 + */
574 701 private function erase_stream_records() {
575 702 global $wpdb;
576 703
577 704 $where = '';
578 705
579 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
706 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
580 707 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
581 708 }
582 709
583 710 $wpdb->query(
@@ -588,8 +715,13 @@
588 715 WHERE 1=1 {$where};" // @codingStandardsIgnoreLine $where already prepared
589 716 );
590 717 }
591 718
719 + /**
720 + * Schedules a purge of records.
721 + *
722 + * @return void
723 + */
592 724 public function purge_schedule_setup() {
593 725 if ( ! wp_next_scheduled( 'wp_stream_auto_purge' ) ) {
594 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
595 727 }
@@ -594,41 +726,48 @@
594 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
595 727 }
596 728 }
597 729
730 + /**
731 + * Executes a scheduled purge
732 + *
733 + * @return void
734 + */
598 735 public function purge_scheduled_action() {
599 736 global $wpdb;
600 737
601 - // Don't purge when in Network Admin unless Stream is network activated
738 + // Don't purge when in Network Admin unless Stream is network activated.
602 739 if (
603 740 is_multisite()
604 741 &&
605 742 is_network_admin()
606 743 &&
607 - ! is_plugin_active_for_network( $this->plugin->locations['plugin'] )
744 + ! $this->plugin->is_network_activated()
608 745 ) {
609 746 return;
610 747 }
611 748
612 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
613 - $options = (array) get_site_option( 'wp_stream_network', array() );
749 + $defaults = $this->plugin->settings->get_defaults();
750 + if ( is_multisite() && $this->plugin->is_network_activated() ) {
751 + $options = (array) get_site_option( 'wp_stream_network', $defaults );
614 752 } else {
615 - $options = (array) get_option( 'wp_stream', array() );
753 + $options = (array) get_option( 'wp_stream', $defaults );
616 754 }
617 755
618 - if ( isset( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
756 + if ( ! empty( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
619 757 return;
620 758 }
621 759
622 - $days = $options['general_records_ttl'];
623 - $date = new DateTime( 'now', $timezone = new DateTimeZone( 'UTC' ) );
760 + $days = $options['general_records_ttl'];
761 + $timezone = new DateTimeZone( 'UTC' );
762 + $date = new DateTime( 'now', $timezone );
624 763
625 764 $date->sub( DateInterval::createFromDateString( "$days days" ) );
626 765
627 766 $where = $wpdb->prepare( ' AND `stream`.`created` < %s', $date->format( 'Y-m-d H:i:s' ) );
628 767
629 - // Multisite but NOT network activated, only purge the current blog
630 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
768 + // Multisite but NOT network activated, only purge the current blog.
769 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
631 770 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
632 771 }
633 772
634 773 $wpdb->query(
@@ -640,13 +779,15 @@
640 779 );
641 780 }
642 781
643 782 /**
644 - * @param array $links
645 - * @param string $file
783 + * Returns the admin action links.
646 784 *
647 785 * @filter plugin_action_links
648 786 *
787 + * @param array $links Action links.
788 + * @param string $file Plugin file.
789 + *
649 790 * @return array
650 791 */
651 792 public function plugin_action_links( $links, $file ) {
652 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
@@ -652,30 +793,42 @@
652 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
653 794 return $links;
654 795 }
655 796
656 - // Also don't show links in Network Admin if Stream isn't network enabled
657 - if ( is_network_admin() && is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
797 + // Also don't show links in Network Admin if Stream isn't network enabled.
798 + if ( is_network_admin() && is_multisite() && ! $this->plugin->is_network_activated() ) {
658 799 return $links;
659 800 }
660 801
661 802 if ( is_network_admin() ) {
662 - $admin_page_url = add_query_arg( array( 'page' => $this->network->network_settings_page_slug ), network_admin_url( $this->admin_parent_page ) );
803 + $admin_page_url = add_query_arg(
804 + array(
805 + 'page' => $this->network->network_settings_page_slug,
806 + ),
807 + network_admin_url( $this->admin_parent_page )
808 + );
663 809 } else {
664 - $admin_page_url = add_query_arg( array( 'page' => $this->settings_page_slug ), admin_url( $this->admin_parent_page ) );
810 + $admin_page_url = add_query_arg(
811 + array(
812 + 'page' => $this->settings_page_slug,
813 + ),
814 + admin_url( $this->admin_parent_page )
815 + );
665 816 }
666 817
667 818 $links[] = sprintf( '<a href="%s">%s</a>', esc_url( $admin_page_url ), esc_html__( 'Settings', 'default' ) );
668 819
669 - $url = add_query_arg(
670 - array(
671 - 'action' => 'wp_stream_uninstall',
672 - 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
673 - ),
674 - admin_url( 'admin-ajax.php' )
675 - );
820 + if ( ! defined( 'DISALLOW_FILE_MODS' ) || false === DISALLOW_FILE_MODS ) {
821 + $url = add_query_arg(
822 + array(
823 + 'action' => 'wp_stream_uninstall',
824 + 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
825 + ),
826 + admin_url( 'admin-ajax.php' )
827 + );
676 828
677 - $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
829 + $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
830 + }
678 831
679 832 return $links;
680 833 }
681 834
@@ -685,12 +838,12 @@
685 838 public function render_list_table() {
686 839 $this->list_table->prepare_items();
687 840 ?>
688 841 <div class="wrap">
689 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
690 - <?php $this->list_table->display() ?>
842 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
843 + <?php $this->list_table->display(); ?>
691 844 </div>
692 - <?php
845 + <?php
693 846 }
694 847
695 848 /**
696 849 * Render settings page
@@ -702,28 +855,28 @@
702 855 $page_description = apply_filters( 'wp_stream_settings_form_description', '' );
703 856
704 857 $sections = $this->plugin->settings->get_fields();
705 858 $active_tab = wp_stream_filter_input( INPUT_GET, 'tab' );
706 -
707 - wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.js', array( 'jquery' ), $this->plugin->get_version(), true );
859 + $min = wp_stream_min_suffix();
860 + wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.' . $min . 'js', array( 'jquery' ), $this->plugin->get_version(), true );
708 861 ?>
709 862 <div class="wrap">
710 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
863 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
711 864
712 865 <?php if ( ! empty( $page_description ) ) : ?>
713 - <p><?php echo esc_html( $page_description ) ?></p>
866 + <p><?php echo esc_html( $page_description ); ?></p>
714 867 <?php endif; ?>
715 868
716 - <?php settings_errors() ?>
869 + <?php settings_errors(); ?>
717 870
718 871 <?php if ( count( $sections ) > 1 ) : ?>
719 872 <h2 class="nav-tab-wrapper">
720 - <?php $i = 0 ?>
873 + <?php $i = 0; ?>
721 874 <?php foreach ( $sections as $section => $data ) : ?>
722 - <?php $i ++ ?>
723 - <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ) ?>
724 - <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ) ?>" class="nav-tab<?php if ( $is_active ) { echo esc_attr( ' nav-tab-active' ); } ?>">
725 - <?php echo esc_html( $data['title'] ) ?>
875 + <?php $i++; ?>
876 + <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ); ?>
877 + <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ); ?>" class="nav-tab <?php echo $is_active ? esc_attr( ' nav-tab-active' ) : ''; ?>">
878 + <?php echo esc_html( $data['title'] ); ?>
726 879 </a>
727 880 <?php endforeach; ?>
728 881 </h2>
729 882 <?php endif; ?>
@@ -728,29 +881,29 @@
728 881 </h2>
729 882 <?php endif; ?>
730 883
731 884 <div class="nav-tab-content" id="tab-content-settings">
732 - <form method="post" action="<?php echo esc_attr( $form_action ) ?>" enctype="multipart/form-data">
885 + <form method="post" action="<?php echo esc_attr( $form_action ); ?>" enctype="multipart/form-data">
733 886 <div class="settings-sections">
734 - <?php
735 - $i = 0;
736 - foreach ( $sections as $section => $data ) {
737 - $i++;
887 + <?php
888 + $i = 0;
889 + foreach ( $sections as $section => $data ) {
890 + $i++;
738 891
739 - $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
892 + $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
740 893
741 - if ( $is_active ) {
742 - settings_fields( $option_key );
743 - do_settings_sections( $option_key );
744 - }
745 - }
746 - ?>
894 + if ( $is_active ) {
895 + settings_fields( $option_key );
896 + do_settings_sections( $option_key );
897 + }
898 + }
899 + ?>
747 900 </div>
748 - <?php submit_button() ?>
901 + <?php submit_button(); ?>
749 902 </form>
750 903 </div>
751 904 </div>
752 - <?php
905 + <?php
753 906 }
754 907
755 908 /**
756 909 * Instantiate the list table
@@ -755,15 +908,20 @@
755 908 /**
756 909 * Instantiate the list table
757 910 */
758 911 public function register_list_table() {
759 - $this->list_table = new List_Table( $this->plugin, array( 'screen' => $this->screen_id['main'] ) );
912 + $this->list_table = new List_Table(
913 + $this->plugin,
914 + array(
915 + 'screen' => $this->screen_id['main'],
916 + )
917 + );
760 918 }
761 919
762 920 /**
763 921 * Check if a particular role has access
764 922 *
765 - * @param string $role
923 + * @param string $role User role.
766 924 *
767 925 * @return bool
768 926 */
769 927 private function role_can_view( $role ) {
@@ -776,12 +934,12 @@
776 934
777 935 /**
778 936 * Filter user caps to dynamically grant our view cap based on allowed roles
779 937 *
780 - * @param $allcaps
781 - * @param $caps
782 - * @param $args
783 - * @param $user
938 + * @param array $allcaps All capabilities.
939 + * @param array $caps Required caps.
940 + * @param array $args Unused.
941 + * @param WP_User $user User.
784 942 *
785 943 * @filter user_has_cap
786 944 *
787 945 * @return array
@@ -826,11 +984,11 @@
826 984 * Filter role caps to dynamically grant our view cap based on allowed roles
827 985 *
828 986 * @filter role_has_cap
829 987 *
830 - * @param $allcaps
831 - * @param $cap
832 - * @param $role
988 + * @param array $allcaps All capabilities.
989 + * @param string $cap Require cap.
990 + * @param string $role User role.
833 991 *
834 992 * @return array
835 993 */
836 994 public function filter_role_caps( $allcaps, $cap, $role ) {
@@ -843,8 +1001,10 @@
843 1001 return $allcaps;
844 1002 }
845 1003
846 1004 /**
1005 + * Ajax callback for return a user list.
1006 + *
847 1007 * @action wp_ajax_wp_stream_filters
848 1008 */
849 1009 public function ajax_filters() {
850 1010 if ( ! defined( 'DOING_AJAX' ) || ! current_user_can( $this->plugin->admin->settings_cap ) ) {
@@ -855,9 +1015,13 @@
855 1015
856 1016 switch ( wp_stream_filter_input( INPUT_GET, 'filter' ) ) {
857 1017 case 'user_id':
858 1018 $users = array_merge(
859 - array( 0 => (object) array( 'display_name' => 'WP-CLI' ) ),
1019 + array(
1020 + 0 => (object) array(
1021 + 'display_name' => 'WP-CLI',
1022 + ),
1023 + ),
860 1024 get_users()
861 1025 );
862 1026
863 1027 $search = wp_stream_filter_input( INPUT_GET, 'q' );
@@ -864,9 +1028,9 @@
864 1028 if ( $search ) {
865 1029 // `search` arg for get_users() is not enough
866 1030 $users = array_filter(
867 1031 $users,
868 - function( $user ) use ( $search ) {
1032 + function ( $user ) use ( $search ) {
869 1033 return false !== mb_strpos( mb_strtolower( $user->display_name ), mb_strtolower( $search ) );
870 1034 }
871 1035 );
872 1036 }
@@ -874,9 +1038,9 @@
874 1038 if ( count( $users ) > $this->preload_users_max ) {
875 1039 $users = array_slice( $users, 0, $this->preload_users_max );
876 1040 }
877 1041
878 - // Get gravatar / roles for final result set
1042 + // Get gravatar / roles for final result set.
879 1043 $results = $this->get_users_record_meta( $users );
880 1044
881 1045 break;
882 1046 }
@@ -881,14 +1045,20 @@
881 1045 break;
882 1046 }
883 1047
884 1048 if ( isset( $results ) ) {
885 - echo wp_stream_json_encode( $results ); // xss ok
1049 + echo wp_stream_json_encode( $results ); // xss ok.
886 1050 }
887 1051
888 1052 die();
889 1053 }
890 1054
1055 + /**
1056 + * Return relevant user meta data.
1057 + *
1058 + * @param array $authors Author data.
1059 + * @return array
1060 + */
891 1061 public function get_users_record_meta( $authors ) {
892 1062 $authors_records = array();
893 1063
894 1064 foreach ( $authors as $user_id => $args ) {
@@ -894,13 +1064,13 @@
894 1064 foreach ( $authors as $user_id => $args ) {
895 1065 $author = new Author( $args->ID );
896 1066
897 1067 $authors_records[ $user_id ] = array(
898 - 'text' => $author->get_display_name(),
899 - 'id' => $author->id,
900 - 'label' => $author->get_display_name(),
901 - 'icon' => $author->get_avatar_src( 32 ),
902 - 'title' => '',
1068 + 'text' => $author->get_display_name(),
1069 + 'id' => $author->id,
1070 + 'label' => $author->get_display_name(),
1071 + 'icon' => $author->get_avatar_src( 32 ),
1072 + 'title' => '',
903 1073 );
904 1074 }
905 1075
906 1076 return $authors_records;
@@ -908,18 +1078,19 @@
908 1078
909 1079 /**
910 1080 * Get user meta in a way that is also safe for VIP
911 1081 *
912 - * @param int $user_id
913 - * @param string $meta_key
914 - * @param bool $single (optional)
1082 + * @param int $user_id User ID.
1083 + * @param string $meta_key Meta key.
1084 + * @param bool $single Return first found meta value connected to the meta key (optional).
915 1085 *
916 1086 * @return mixed
917 1087 */
918 - function get_user_meta( $user_id, $meta_key, $single = true ) {
1088 + public function get_user_meta( $user_id, $meta_key, $single = true ) {
919 1089 if ( wp_stream_is_vip() && function_exists( 'get_user_attribute' ) ) {
920 1090 return get_user_attribute( $user_id, $meta_key );
921 1091 }
1092 +
922 1093 return get_user_meta( $user_id, $meta_key, $single );
923 1094 }
924 1095
925 1096 /**
@@ -924,19 +1095,20 @@
924 1095
925 1096 /**
926 1097 * Update user meta in a way that is also safe for VIP
927 1098 *
928 - * @param int $user_id
929 - * @param string $meta_key
930 - * @param mixed $meta_value
931 - * @param mixed $prev_value (optional)
1099 + * @param int $user_id User ID.
1100 + * @param string $meta_key Meta key.
1101 + * @param mixed $meta_value Meta value.
1102 + * @param mixed $prev_value Previous meta value being overwritten (optional).
932 1103 *
933 1104 * @return int|bool
934 1105 */
935 - function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
1106 + public function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
936 1107 if ( wp_stream_is_vip() && function_exists( 'update_user_attribute' ) ) {
937 1108 return update_user_attribute( $user_id, $meta_key, $meta_value );
938 1109 }
1110 +
939 1111 return update_user_meta( $user_id, $meta_key, $meta_value, $prev_value );
940 1112 }
941 1113
942 1114 /**
@@ -941,17 +1113,18 @@
941 1113
942 1114 /**
943 1115 * Delete user meta in a way that is also safe for VIP
944 1116 *
945 - * @param int $user_id
946 - * @param string $meta_key
947 - * @param mixed $meta_value (optional)
1117 + * @param int $user_id User ID.
1118 + * @param string $meta_key Meta key.
1119 + * @param mixed $meta_value Meta value (optional).
948 1120 *
949 1121 * @return bool
950 1122 */
951 - function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
1123 + public function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
952 1124 if ( wp_stream_is_vip() && function_exists( 'delete_user_attribute' ) ) {
953 1125 return delete_user_attribute( $user_id, $meta_key, $meta_value );
954 1126 }
1127 +
955 1128 return delete_user_meta( $user_id, $meta_key, $meta_value );
956 1129 }
957 1130 }