PluginProbe
Stream – Activity Log & Audit Trail / 3.8.2
Stream – Activity Log & Audit Trail v3.8.2
4.4.0 4.3.0 4.2.2 4.2.1 trunk 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.1 3.1.1 3.10.0 3.2.0 3.2.1 3.2.2 3.2.3 All 50 releases
← All changes | classes/class-admin.php +342 -200 3.0.23.8.2 View file →
@@ -1,5 +1,11 @@
1 1 <?php
2 +/**
3 + * Centralized manager for WordPress backend functionality.
4 + *
5 + * @package WP_Stream
6 + */
7 +
2 8 namespace WP_Stream;
3 9
4 10 use DateTime;
5 11 use DateTimeZone;
@@ -6,26 +12,42 @@
6 12 use DateInterval;
7 13 use \WP_CLI;
8 14 use \WP_Roles;
9 15
16 +/**
17 + * Class - Admin
18 + */
10 19 class Admin {
20 +
11 21 /**
12 - * Hold Plugin class
22 + * Holds Instance of plugin object
23 + *
13 24 * @var Plugin
14 25 */
15 26 public $plugin;
16 27
17 28 /**
29 + * Holds Network class
30 + *
18 31 * @var Network
19 32 */
20 33 public $network;
21 34
22 35 /**
36 + * Holds Live Update class
37 + *
23 38 * @var Live_Update
24 39 */
25 40 public $live_update;
26 41
27 42 /**
43 + * Holds Export class
44 + *
45 + * @var Export
46 + */
47 + public $export;
48 +
49 + /**
28 50 * Menu page screen id
29 51 *
30 52 * @var string
31 53 */
@@ -103,9 +125,9 @@
103 125
104 126 /**
105 127 * Class constructor.
106 128 *
107 - * @param Plugin $plugin The main Plugin class.
129 + * @param Plugin $plugin Instance of plugin object.
108 130 */
109 131 public function __construct( $plugin ) {
110 132 $this->plugin = $plugin;
111 133
@@ -110,18 +132,18 @@
110 132 $this->plugin = $plugin;
111 133
112 134 add_action( 'init', array( $this, 'init' ) );
113 135
114 - // Ensure function used in various methods is pre-loaded
136 + // Ensure function used in various methods is pre-loaded.
115 137 if ( ! function_exists( 'is_plugin_active_for_network' ) ) {
116 - require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
138 + require_once ABSPATH . '/wp-admin/includes/plugin.php';
117 139 }
118 140
119 - // User and role caps
141 + // User and role caps.
120 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
121 143 add_filter( 'role_has_cap', array( $this, 'filter_role_caps' ), 10, 3 );
122 144
123 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) && ! is_network_admin() ) {
145 + if ( is_multisite() && $plugin->is_network_activated() && ! is_network_admin() ) {
124 146 $options = (array) get_site_option( 'wp_stream_network', array() );
125 147 $option = isset( $options['general_site_access'] ) ? absint( $options['general_site_access'] ) : 1;
126 148
127 149 $this->disable_access = ( $option ) ? false : true;
@@ -126,49 +148,75 @@
126 148
127 149 $this->disable_access = ( $option ) ? false : true;
128 150 }
129 151
130 - // Register settings page
152 + // Register settings page.
131 153 if ( ! $this->disable_access ) {
132 154 add_action( 'admin_menu', array( $this, 'register_menu' ) );
133 155 }
134 156
135 - // Admin notices
157 + // Admin notices.
136 158 add_action( 'admin_notices', array( $this, 'prepare_admin_notices' ) );
137 159 add_action( 'shutdown', array( $this, 'admin_notices' ) );
138 160
139 - // Add admin body class
161 + // Add admin body class.
140 162 add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
141 163
142 - // Plugin action links
143 - add_filter( 'plugin_action_links', array( $this, 'plugin_action_links' ), 10, 2 );
164 + // Plugin action links.
165 + add_filter(
166 + 'plugin_action_links',
167 + array(
168 + $this,
169 + 'plugin_action_links',
170 + ),
171 + 10,
172 + 2
173 + );
144 174
145 - // Load admin scripts and styles
146 - add_action( 'admin_enqueue_scripts', array( $this, 'admin_enqueue_scripts' ) );
175 + // Load admin scripts and styles.
176 + add_action(
177 + 'admin_enqueue_scripts',
178 + array(
179 + $this,
180 + 'admin_enqueue_scripts',
181 + )
182 + );
147 183 add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
148 184
149 - // Reset Streams database
150 - add_action( 'wp_ajax_wp_stream_reset', array( $this, 'wp_ajax_reset' ) );
185 + // Reset Streams database.
186 + add_action(
187 + 'wp_ajax_wp_stream_reset',
188 + array(
189 + $this,
190 + 'wp_ajax_reset',
191 + )
192 + );
151 193
152 - // Uninstall Streams and Deactivate plugin
153 - $uninstall = new Uninstall( $this->plugin );
154 - add_action( 'wp_ajax_wp_stream_uninstall', array( $uninstall, 'uninstall' ) );
194 + /**
195 + * Uninstall Streams and Deactivate plugin.
196 + *
197 + * @todo Confirm if variable assignment is necessary.
198 + */
199 + $uninstall = $this->plugin->db->driver->purge_storage( $this->plugin );
155 200
156 - // Auto purge setup
201 + // Auto purge setup.
157 202 add_action( 'wp_loaded', array( $this, 'purge_schedule_setup' ) );
158 - add_action( 'wp_stream_auto_purge', array( $this, 'purge_scheduled_action' ) );
203 + add_action(
204 + 'wp_stream_auto_purge',
205 + array(
206 + $this,
207 + 'purge_scheduled_action',
208 + )
209 + );
159 210
160 - // Ajax users list
161 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
162 -
163 - // Ajax user's name by ID
164 - add_action( 'wp_ajax_wp_stream_get_filter_value_by_id', array( $this, 'get_filter_value_by_id' ) );
165 -
166 - // Ajax users list
167 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
168 -
169 - // Ajax user's name by ID
170 - add_action( 'wp_ajax_wp_stream_get_filter_value_by_id', array( $this, 'get_filter_value_by_id' ) );
211 + // Ajax users list.
212 + add_action(
213 + 'wp_ajax_wp_stream_filters',
214 + array(
215 + $this,
216 + 'ajax_filters',
217 + )
218 + );
171 219 }
172 220
173 221 /**
174 222 * Load admin classes
@@ -177,16 +225,17 @@
177 225 */
178 226 public function init() {
179 227 $this->network = new Network( $this->plugin );
180 228 $this->live_update = new Live_Update( $this->plugin );
229 + $this->export = new Export( $this->plugin );
181 230 }
182 231
183 232 /**
184 - * Output specific updates passed as URL parameters
233 + * Output specific updates passed as URL parameters.
185 234 *
186 235 * @action admin_notices
187 236 *
188 - * @return string
237 + * @return void
189 238 */
190 239 public function prepare_admin_notices() {
191 240 $message = wp_stream_filter_input( INPUT_GET, 'message' );
192 241
@@ -199,14 +248,14 @@
199 248
200 249 /**
201 250 * Handle notice messages according to the appropriate context (WP-CLI or the WP Admin)
202 251 *
203 - * @param string $message
204 - * @param bool $is_error
252 + * @param string $message Message to output.
253 + * @param bool $is_error If the message is error_level (true) or warning (false).
205 254 */
206 255 public function notice( $message, $is_error = true ) {
207 256 if ( defined( 'WP_CLI' ) && WP_CLI ) {
208 - $message = strip_tags( $message );
257 + $message = wp_strip_all_tags( $message );
209 258
210 259 if ( $is_error ) {
211 260 WP_CLI::warning( $message );
212 261 } else {
@@ -212,14 +261,14 @@
212 261 } else {
213 262 WP_CLI::success( $message );
214 263 }
215 264 } else {
216 - // Trigger admin notices late, so that any notices which occur during page load are displayed
265 + // Trigger admin notices late, so that any notices which occur during page load are displayed.
217 266 add_action( 'shutdown', array( $this, 'admin_notices' ) );
218 267
219 268 $notice = compact( 'message', 'is_error' );
220 269
221 - if ( ! in_array( $notice, $this->notices ) ) {
270 + if ( ! in_array( $notice, $this->notices, true ) ) {
222 271 $this->notices[] = $notice;
223 272 }
224 273 }
225 274 }
@@ -258,9 +307,9 @@
258 307 * Register menu page
259 308 *
260 309 * @action admin_menu
261 310 *
262 - * @return bool|void
311 + * @return void
263 312 */
264 313 public function register_menu() {
265 314 /**
266 315 * Filter the main admin menu title
@@ -295,8 +344,16 @@
295 344 $main_menu_position
296 345 );
297 346
298 347 /**
348 + * Fires before submenu items are added to the Stream menu
349 + * allowing plugins to add menu items before Settings
350 + *
351 + * @return void
352 + */
353 + do_action( 'wp_stream_admin_menu' );
354 +
355 + /**
299 356 * Filter the Settings admin page title
300 357 *
301 358 * @return string
302 359 */
@@ -318,10 +375,16 @@
318 375 * @return void
319 376 */
320 377 do_action( 'wp_stream_admin_menu_screens' );
321 378
322 - // Register the list table early, so it associates the column headers with 'Screen settings'
323 - add_action( 'load-' . $this->screen_id['main'], array( $this, 'register_list_table' ) );
379 + // Register the list table early, so it associates the column headers with 'Screen settings'.
380 + add_action(
381 + 'load-' . $this->screen_id['main'],
382 + array(
383 + $this,
384 + 'register_list_table',
385 + )
386 + );
324 387 }
325 388 }
326 389
327 390 /**
@@ -328,39 +391,80 @@
328 391 * Enqueue scripts/styles for admin screen
329 392 *
330 393 * @action admin_enqueue_scripts
331 394 *
332 - * @param string $hook
395 + * @param string $hook Current hook.
333 396 *
334 397 * @return void
335 398 */
336 399 public function admin_enqueue_scripts( $hook ) {
337 - wp_register_script( 'select2', $this->plugin->locations['url'] . 'ui/lib/select2/select2.js', array( 'jquery' ), '3.5.2', true );
338 - wp_register_style( 'select2', $this->plugin->locations['url'] . 'ui/lib/select2/select2.css', array(), '3.5.2' );
339 - wp_register_script( 'timeago', $this->plugin->locations['url'] . 'ui/lib/timeago/jquery.timeago.js', array(), '1.4.1', true );
400 + wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/js/select2.full.min.js', array( 'jquery' ), '3.5.2', true );
401 + wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/css/select2.min.css', array(), '3.5.2' );
402 + wp_register_script( 'wp-stream-timeago', $this->plugin->locations['url'] . 'ui/lib/timeago/jquery.timeago.js', array(), '1.4.1', true );
340 403
341 404 $locale = strtolower( substr( get_locale(), 0, 2 ) );
342 405 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
343 406
344 407 if ( file_exists( $this->plugin->locations['dir'] . sprintf( $file_tmpl, $locale ) ) ) {
345 - wp_register_script( 'timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ), array( 'timeago' ), '1' );
408 + wp_register_script(
409 + 'wp-stream-timeago-locale',
410 + $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ),
411 + array( 'wp-stream-timeago' ),
412 + '1',
413 + false
414 + );
346 415 } else {
347 - wp_register_script( 'timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ), array( 'timeago' ), '1' );
416 + wp_register_script(
417 + 'wp-stream-timeago-locale',
418 + $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ),
419 + array( 'wp-stream-timeago' ),
420 + '1',
421 + false
422 + );
348 423 }
349 424
350 - wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.css', array(), $this->plugin->get_version() );
425 + $min = wp_stream_min_suffix();
426 + wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.' . $min . 'css', array(), $this->plugin->get_version() );
351 427
352 - $script_screens = array( 'plugins.php', 'user-edit.php', 'user-new.php', 'profile.php' );
428 + $script_screens = array( 'plugins.php' );
353 429
354 - if ( in_array( $hook, $this->screen_id ) || in_array( $hook, $script_screens ) ) {
355 - wp_enqueue_script( 'select2' );
356 - wp_enqueue_style( 'select2' );
430 + if ( in_array( $hook, $this->screen_id, true ) || in_array( $hook, $script_screens, true ) ) {
431 + wp_enqueue_script( 'wp-stream-select2' );
432 + wp_enqueue_style( 'wp-stream-select2' );
357 433
358 - wp_enqueue_script( 'timeago' );
359 - wp_enqueue_script( 'timeago-locale' );
434 + wp_enqueue_script( 'wp-stream-timeago' );
435 + wp_enqueue_script( 'wp-stream-timeago-locale' );
360 436
361 - wp_enqueue_script( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/js/admin.js', array( 'jquery', 'select2' ), $this->plugin->get_version() );
362 - wp_enqueue_script( 'wp-stream-live-updates', $this->plugin->locations['url'] . 'ui/js/live-updates.js', array( 'jquery', 'heartbeat' ), $this->plugin->get_version() );
437 + wp_enqueue_script(
438 + 'wp-stream-admin',
439 + $this->plugin->locations['url'] . 'ui/js/admin.' . $min . 'js',
440 + array(
441 + 'jquery',
442 + 'wp-stream-select2',
443 + ),
444 + $this->plugin->get_version(),
445 + false
446 + );
447 + wp_enqueue_script(
448 + 'wp-stream-admin-exclude',
449 + $this->plugin->locations['url'] . 'ui/js/exclude.' . $min . 'js',
450 + array(
451 + 'jquery',
452 + 'wp-stream-select2',
453 + ),
454 + $this->plugin->get_version(),
455 + false
456 + );
457 + wp_enqueue_script(
458 + 'wp-stream-live-updates',
459 + $this->plugin->locations['url'] . 'ui/js/live-updates.' . $min . 'js',
460 + array(
461 + 'jquery',
462 + 'heartbeat',
463 + ),
464 + $this->plugin->get_version(),
465 + false
466 + );
363 467
364 468 wp_localize_script(
365 469 'wp-stream-admin',
366 470 'wp_stream',
@@ -374,17 +478,21 @@
374 478 'gmt_offset' => get_option( 'gmt_offset' ),
375 479 )
376 480 );
377 481
482 + $order_types = array( 'asc', 'desc' );
483 +
378 484 wp_localize_script(
379 485 'wp-stream-live-updates',
380 486 'wp_stream_live_updates',
381 487 array(
382 488 'current_screen' => $hook,
383 - 'current_page' => isset( $_GET['paged'] ) ? esc_js( $_GET['paged'] ) : '1', // input var okay
384 - 'current_order' => isset( $_GET['order'] ) ? esc_js( $_GET['order'] ) : 'desc', // input var okay
385 - 'current_query' => wp_stream_json_encode( $_GET ), // input var okay
386 - 'current_query_count' => count( $_GET ), // input var okay
489 + 'current_page' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : '1', // phpcs:ignore WordPress.Security.NonceVerification.Recommended
490 + 'current_order' => isset( $_GET['order'] ) && in_array( strtolower( $_GET['order'] ), $order_types, true ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
491 + ? esc_js( $_GET['order'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
492 + : 'desc',
493 + 'current_query' => wp_stream_json_encode( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
494 + 'current_query_count' => count( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
387 495 )
388 496 );
389 497 }
390 498
@@ -401,15 +509,23 @@
401 509 * @return int
402 510 */
403 511 $bulk_actions_threshold = apply_filters( 'wp_stream_bulk_actions_threshold', 100 );
404 512
405 - wp_enqueue_script( 'wp-stream-global', $this->plugin->locations['url'] . 'ui/js/global.js', array( 'jquery' ), $this->plugin->get_version() );
513 + wp_enqueue_script(
514 + 'wp-stream-global',
515 + $this->plugin->locations['url'] . 'ui/js/global.' . $min . 'js',
516 + array( 'jquery' ),
517 + $this->plugin->get_version(),
518 + false
519 + );
520 +
406 521 wp_localize_script(
407 522 'wp-stream-global',
408 523 'wp_stream_global',
409 524 array(
410 - 'bulk_actions' => array(
411 - 'i18n' => array(
525 + 'bulk_actions' => array(
526 + 'i18n' => array(
527 + /* translators: %s: a number of items (e.g. "1,742") */
412 528 'confirm_action' => sprintf( esc_html__( 'Are you sure you want to perform bulk actions on over %s items? This process could take a while to complete.', 'stream' ), number_format( absint( $bulk_actions_threshold ) ) ),
413 529 ),
414 530 'threshold' => absint( $bulk_actions_threshold ),
415 531 ),
@@ -427,8 +543,13 @@
427 543 if ( is_admin() && false !== strpos( wp_stream_filter_input( INPUT_GET, 'page' ), $this->records_page_slug ) ) {
428 544 return true;
429 545 }
430 546
547 + $screen = get_current_screen();
548 + if ( is_admin() && Alerts::POST_TYPE === $screen->post_type ) {
549 + return true;
550 + }
551 +
431 552 return false;
432 553 }
433 554
434 555 /**
@@ -433,9 +554,9 @@
433 554
434 555 /**
435 556 * Add a specific body class to all Stream admin screens
436 557 *
437 - * @param string $classes
558 + * @param string $classes CSS classes to output to body.
438 559 *
439 560 * @filter admin_body_class
440 561 *
441 562 * @return string
@@ -445,10 +566,10 @@
445 566
446 567 if ( $this->is_stream_screen() ) {
447 568 $stream_classes[] = $this->admin_body_class;
448 569
449 - if ( isset( $_GET['page'] ) ) {
450 - $stream_classes[] = sanitize_key( $_GET['page'] ); // input var okay
570 + if ( isset( $_GET['page'] ) ) { // // phpcs:ignore WordPress.Security.NonceVerification.Recommended
571 + $stream_classes[] = sanitize_key( $_GET['page'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
451 572 }
452 573 }
453 574
454 575 /**
@@ -469,16 +590,17 @@
469 590 *
470 591 * @action admin_enqueue_scripts
471 592 */
472 593 public function admin_menu_css() {
473 - wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.css', array(), $this->plugin->get_version() );
594 + $min = wp_stream_min_suffix();
595 + wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.' . $min . 'css', array(), $this->plugin->get_version() );
474 596 wp_register_style( 'wp-stream-icons', $this->plugin->locations['url'] . 'ui/stream-icons/style.css', array(), $this->plugin->get_version() );
475 597
476 - // Make sure we're working off a clean version
598 + // Make sure we're working off a clean version.
477 599 if ( ! file_exists( ABSPATH . WPINC . '/version.php' ) ) {
478 600 return;
479 601 }
480 - include( ABSPATH . WPINC . '/version.php' );
602 + include ABSPATH . WPINC . '/version.php';
481 603
482 604 if ( ! isset( $wp_version ) ) {
483 605 return;
484 606 }
@@ -537,10 +659,15 @@
537 659
538 660 \wp_add_inline_style( 'wp-admin', $css );
539 661 }
540 662
663 + /**
664 + * Handle the reset AJAX request to reset logs.
665 + *
666 + * @return bool
667 + */
541 668 public function wp_ajax_reset() {
542 - check_ajax_referer( 'stream_nonce', 'wp_stream_nonce' );
669 + check_ajax_referer( 'stream_nonce_reset', 'wp_stream_nonce_reset' );
543 670
544 671 if ( ! current_user_can( $this->settings_cap ) ) {
545 672 wp_die(
546 673 esc_html__( "You don't have sufficient privileges to do this action.", 'stream' )
@@ -552,9 +679,9 @@
552 679 if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
553 680 return true;
554 681 }
555 682
556 - wp_redirect(
683 + wp_safe_redirect(
557 684 add_query_arg(
558 685 array(
559 686 'page' => is_network_admin() ? $this->network->network_settings_page_slug : $this->settings_page_slug,
560 687 'message' => 'data_erased',
@@ -565,14 +692,19 @@
565 692
566 693 exit;
567 694 }
568 695
696 + /**
697 + * Clears stream records from the database.
698 + *
699 + * @return void
700 + */
569 701 private function erase_stream_records() {
570 702 global $wpdb;
571 703
572 704 $where = '';
573 705
574 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
706 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
575 707 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
576 708 }
577 709
578 710 $wpdb->query(
@@ -579,12 +711,17 @@
579 711 "DELETE `stream`, `meta`
580 712 FROM {$wpdb->stream} AS `stream`
581 713 LEFT JOIN {$wpdb->streammeta} AS `meta`
582 714 ON `meta`.`record_id` = `stream`.`ID`
583 - WHERE 1=1 {$where};"
715 + WHERE 1=1 {$where};" // @codingStandardsIgnoreLine $where already prepared
584 716 );
585 717 }
586 718
719 + /**
720 + * Schedules a purge of records.
721 + *
722 + * @return void
723 + */
587 724 public function purge_schedule_setup() {
588 725 if ( ! wp_next_scheduled( 'wp_stream_auto_purge' ) ) {
589 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
590 727 }
@@ -589,41 +726,48 @@
589 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
590 727 }
591 728 }
592 729
730 + /**
731 + * Executes a scheduled purge
732 + *
733 + * @return void
734 + */
593 735 public function purge_scheduled_action() {
594 736 global $wpdb;
595 737
596 - // Don't purge when in Network Admin unless Stream is network activated
738 + // Don't purge when in Network Admin unless Stream is network activated.
597 739 if (
598 740 is_multisite()
599 741 &&
600 742 is_network_admin()
601 743 &&
602 - ! is_plugin_active_for_network( $this->plugin->locations['plugin'] )
744 + ! $this->plugin->is_network_activated()
603 745 ) {
604 746 return;
605 747 }
606 748
607 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
608 - $options = (array) get_site_option( 'wp_stream_network', array() );
749 + $defaults = $this->plugin->settings->get_defaults();
750 + if ( is_multisite() && $this->plugin->is_network_activated() ) {
751 + $options = (array) get_site_option( 'wp_stream_network', $defaults );
609 752 } else {
610 - $options = (array) get_option( 'wp_stream', array() );
753 + $options = (array) get_option( 'wp_stream', $defaults );
611 754 }
612 755
613 - if ( isset( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
756 + if ( ! empty( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
614 757 return;
615 758 }
616 759
617 - $days = $options['general_records_ttl'];
618 - $date = new DateTime( 'now', $timezone = new DateTimeZone( 'UTC' ) );
760 + $days = $options['general_records_ttl'];
761 + $timezone = new DateTimeZone( 'UTC' );
762 + $date = new DateTime( 'now', $timezone );
619 763
620 764 $date->sub( DateInterval::createFromDateString( "$days days" ) );
621 765
622 766 $where = $wpdb->prepare( ' AND `stream`.`created` < %s', $date->format( 'Y-m-d H:i:s' ) );
623 767
624 - // Multisite but NOT network activated, only purge the current blog
625 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
768 + // Multisite but NOT network activated, only purge the current blog.
769 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
626 770 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
627 771 }
628 772
629 773 $wpdb->query(
@@ -630,18 +774,20 @@
630 774 "DELETE `stream`, `meta`
631 775 FROM {$wpdb->stream} AS `stream`
632 776 LEFT JOIN {$wpdb->streammeta} AS `meta`
633 777 ON `meta`.`record_id` = `stream`.`ID`
634 - WHERE 1=1 {$where};"
778 + WHERE 1=1 {$where};" // @codingStandardsIgnoreLine $where already prepared
635 779 );
636 780 }
637 781
638 782 /**
639 - * @param array $links
640 - * @param string $file
783 + * Returns the admin action links.
641 784 *
642 785 * @filter plugin_action_links
643 786 *
787 + * @param array $links Action links.
788 + * @param string $file Plugin file.
789 + *
644 790 * @return array
645 791 */
646 792 public function plugin_action_links( $links, $file ) {
647 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
@@ -647,30 +793,42 @@
647 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
648 794 return $links;
649 795 }
650 796
651 - // Also don't show links in Network Admin if Stream isn't network enabled
652 - if ( is_network_admin() && is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
797 + // Also don't show links in Network Admin if Stream isn't network enabled.
798 + if ( is_network_admin() && is_multisite() && ! $this->plugin->is_network_activated() ) {
653 799 return $links;
654 800 }
655 801
656 802 if ( is_network_admin() ) {
657 - $admin_page_url = add_query_arg( array( 'page' => $this->network->network_settings_page_slug ), network_admin_url( $this->admin_parent_page ) );
803 + $admin_page_url = add_query_arg(
804 + array(
805 + 'page' => $this->network->network_settings_page_slug,
806 + ),
807 + network_admin_url( $this->admin_parent_page )
808 + );
658 809 } else {
659 - $admin_page_url = add_query_arg( array( 'page' => $this->settings_page_slug ), admin_url( $this->admin_parent_page ) );
810 + $admin_page_url = add_query_arg(
811 + array(
812 + 'page' => $this->settings_page_slug,
813 + ),
814 + admin_url( $this->admin_parent_page )
815 + );
660 816 }
661 817
662 818 $links[] = sprintf( '<a href="%s">%s</a>', esc_url( $admin_page_url ), esc_html__( 'Settings', 'default' ) );
663 819
664 - $url = add_query_arg(
665 - array(
666 - 'action' => 'wp_stream_uninstall',
667 - 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
668 - ),
669 - admin_url( 'admin-ajax.php' )
670 - );
820 + if ( ! defined( 'DISALLOW_FILE_MODS' ) || false === DISALLOW_FILE_MODS ) {
821 + $url = add_query_arg(
822 + array(
823 + 'action' => 'wp_stream_uninstall',
824 + 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
825 + ),
826 + admin_url( 'admin-ajax.php' )
827 + );
671 828
672 - $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
829 + $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
830 + }
673 831
674 832 return $links;
675 833 }
676 834
@@ -680,12 +838,12 @@
680 838 public function render_list_table() {
681 839 $this->list_table->prepare_items();
682 840 ?>
683 841 <div class="wrap">
684 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
685 - <?php $this->list_table->display() ?>
842 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
843 + <?php $this->list_table->display(); ?>
686 844 </div>
687 - <?php
845 + <?php
688 846 }
689 847
690 848 /**
691 849 * Render settings page
@@ -697,28 +855,28 @@
697 855 $page_description = apply_filters( 'wp_stream_settings_form_description', '' );
698 856
699 857 $sections = $this->plugin->settings->get_fields();
700 858 $active_tab = wp_stream_filter_input( INPUT_GET, 'tab' );
701 -
702 - wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.js', array( 'jquery' ), $this->plugin->get_version(), true );
859 + $min = wp_stream_min_suffix();
860 + wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.' . $min . 'js', array( 'jquery' ), $this->plugin->get_version(), true );
703 861 ?>
704 862 <div class="wrap">
705 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
863 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
706 864
707 865 <?php if ( ! empty( $page_description ) ) : ?>
708 - <p><?php echo esc_html( $page_description ) ?></p>
866 + <p><?php echo esc_html( $page_description ); ?></p>
709 867 <?php endif; ?>
710 868
711 - <?php settings_errors() ?>
869 + <?php settings_errors(); ?>
712 870
713 871 <?php if ( count( $sections ) > 1 ) : ?>
714 872 <h2 class="nav-tab-wrapper">
715 - <?php $i = 0 ?>
873 + <?php $i = 0; ?>
716 874 <?php foreach ( $sections as $section => $data ) : ?>
717 - <?php $i ++ ?>
718 - <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ) ?>
719 - <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ) ?>" class="nav-tab<?php if ( $is_active ) { echo esc_attr( ' nav-tab-active' ); } ?>">
720 - <?php echo esc_html( $data['title'] ) ?>
875 + <?php $i++; ?>
876 + <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ); ?>
877 + <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ); ?>" class="nav-tab <?php echo $is_active ? esc_attr( ' nav-tab-active' ) : ''; ?>">
878 + <?php echo esc_html( $data['title'] ); ?>
721 879 </a>
722 880 <?php endforeach; ?>
723 881 </h2>
724 882 <?php endif; ?>
@@ -723,29 +881,29 @@
723 881 </h2>
724 882 <?php endif; ?>
725 883
726 884 <div class="nav-tab-content" id="tab-content-settings">
727 - <form method="post" action="<?php echo esc_attr( $form_action ) ?>" enctype="multipart/form-data">
885 + <form method="post" action="<?php echo esc_attr( $form_action ); ?>" enctype="multipart/form-data">
728 886 <div class="settings-sections">
729 - <?php
730 - $i = 0;
731 - foreach ( $sections as $section => $data ) {
732 - $i++;
887 + <?php
888 + $i = 0;
889 + foreach ( $sections as $section => $data ) {
890 + $i++;
733 891
734 - $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
892 + $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
735 893
736 - if ( $is_active ) {
737 - settings_fields( $option_key );
738 - do_settings_sections( $option_key );
739 - }
740 - }
741 - ?>
894 + if ( $is_active ) {
895 + settings_fields( $option_key );
896 + do_settings_sections( $option_key );
897 + }
898 + }
899 + ?>
742 900 </div>
743 - <?php submit_button() ?>
901 + <?php submit_button(); ?>
744 902 </form>
745 903 </div>
746 904 </div>
747 - <?php
905 + <?php
748 906 }
749 907
750 908 /**
751 909 * Instantiate the list table
@@ -750,20 +908,25 @@
750 908 /**
751 909 * Instantiate the list table
752 910 */
753 911 public function register_list_table() {
754 - $this->list_table = new List_Table( $this->plugin, array( 'screen' => $this->screen_id['main'] ) );
912 + $this->list_table = new List_Table(
913 + $this->plugin,
914 + array(
915 + 'screen' => $this->screen_id['main'],
916 + )
917 + );
755 918 }
756 919
757 920 /**
758 921 * Check if a particular role has access
759 922 *
760 - * @param string $role
923 + * @param string $role User role.
761 924 *
762 925 * @return bool
763 926 */
764 927 private function role_can_view( $role ) {
765 - if ( in_array( $role, $this->plugin->settings->options['general_role_access'] ) ) {
928 + if ( in_array( $role, $this->plugin->settings->options['general_role_access'], true ) ) {
766 929 return true;
767 930 }
768 931
769 932 return false;
@@ -771,12 +934,12 @@
771 934
772 935 /**
773 936 * Filter user caps to dynamically grant our view cap based on allowed roles
774 937 *
775 - * @param $allcaps
776 - * @param $caps
777 - * @param $args
778 - * @param $user
938 + * @param array $allcaps All capabilities.
939 + * @param array $caps Required caps.
940 + * @param array $args Unused.
941 + * @param WP_User $user User.
779 942 *
780 943 * @filter user_has_cap
781 944 *
782 945 * @return array
@@ -802,9 +965,9 @@
802 965
803 966 $stream_view_caps = array( $this->view_cap );
804 967
805 968 foreach ( $caps as $cap ) {
806 - if ( in_array( $cap, $stream_view_caps ) ) {
969 + if ( in_array( $cap, $stream_view_caps, true ) ) {
807 970 foreach ( $roles as $role ) {
808 971 if ( $this->role_can_view( $role ) ) {
809 972 $allcaps[ $cap ] = true;
810 973
@@ -821,11 +984,11 @@
821 984 * Filter role caps to dynamically grant our view cap based on allowed roles
822 985 *
823 986 * @filter role_has_cap
824 987 *
825 - * @param $allcaps
826 - * @param $cap
827 - * @param $role
988 + * @param array $allcaps All capabilities.
989 + * @param string $cap Require cap.
990 + * @param string $role User role.
828 991 *
829 992 * @return array
830 993 */
831 994 public function filter_role_caps( $allcaps, $cap, $role ) {
@@ -830,9 +993,9 @@
830 993 */
831 994 public function filter_role_caps( $allcaps, $cap, $role ) {
832 995 $stream_view_caps = array( $this->view_cap );
833 996
834 - if ( in_array( $cap, $stream_view_caps ) && $this->role_can_view( $role ) ) {
997 + if ( in_array( $cap, $stream_view_caps, true ) && $this->role_can_view( $role ) ) {
835 998 $allcaps[ $cap ] = true;
836 999 }
837 1000
838 1001 return $allcaps;
@@ -838,15 +1001,27 @@
838 1001 return $allcaps;
839 1002 }
840 1003
841 1004 /**
1005 + * Ajax callback for return a user list.
1006 + *
842 1007 * @action wp_ajax_wp_stream_filters
843 1008 */
844 1009 public function ajax_filters() {
1010 + if ( ! defined( 'DOING_AJAX' ) || ! current_user_can( $this->plugin->admin->settings_cap ) ) {
1011 + wp_die( '-1' );
1012 + }
1013 +
1014 + check_ajax_referer( 'stream_filters_user_search_nonce', 'nonce' );
1015 +
845 1016 switch ( wp_stream_filter_input( INPUT_GET, 'filter' ) ) {
846 1017 case 'user_id':
847 1018 $users = array_merge(
848 - array( 0 => (object) array( 'display_name' => 'WP-CLI' ) ),
1019 + array(
1020 + 0 => (object) array(
1021 + 'display_name' => 'WP-CLI',
1022 + ),
1023 + ),
849 1024 get_users()
850 1025 );
851 1026
852 1027 $search = wp_stream_filter_input( INPUT_GET, 'q' );
@@ -853,9 +1028,9 @@
853 1028 if ( $search ) {
854 1029 // `search` arg for get_users() is not enough
855 1030 $users = array_filter(
856 1031 $users,
857 - function( $user ) use ( $search ) {
1032 + function ( $user ) use ( $search ) {
858 1033 return false !== mb_strpos( mb_strtolower( $user->display_name ), mb_strtolower( $search ) );
859 1034 }
860 1035 );
861 1036 }
@@ -863,9 +1038,9 @@
863 1038 if ( count( $users ) > $this->preload_users_max ) {
864 1039 $users = array_slice( $users, 0, $this->preload_users_max );
865 1040 }
866 1041
867 - // Get gravatar / roles for final result set
1042 + // Get gravatar / roles for final result set.
868 1043 $results = $this->get_users_record_meta( $users );
869 1044
870 1045 break;
871 1046 }
@@ -870,68 +1045,32 @@
870 1045 break;
871 1046 }
872 1047
873 1048 if ( isset( $results ) ) {
874 - echo wp_stream_json_encode( array_values( $results ) ); // xss ok
1049 + echo wp_stream_json_encode( $results ); // xss ok.
875 1050 }
876 1051
877 - if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
878 - return;
879 - }
880 -
881 1052 die();
882 1053 }
883 1054
884 1055 /**
885 - * @action wp_ajax_wp_stream_get_filter_value_by_id
1056 + * Return relevant user meta data.
1057 + *
1058 + * @param array $authors Author data.
1059 + * @return array
886 1060 */
887 - public function get_filter_value_by_id() {
888 - $filter = wp_stream_filter_input( INPUT_POST, 'filter' );
889 -
890 - switch ( $filter ) {
891 - case 'user_id':
892 - $id = wp_stream_filter_input( INPUT_POST, 'id' );
893 -
894 - if ( '0' === $id ) {
895 - $value = 'WP-CLI';
896 -
897 - break;
898 - }
899 -
900 - $user = get_userdata( $id );
901 -
902 - if ( ! $user || is_wp_error( $user ) ) {
903 - $value = '';
904 - } else {
905 - $value = $user->display_name;
906 - }
907 -
908 - break;
909 - default:
910 - $value = '';
911 - }
912 -
913 - echo wp_stream_json_encode( $value ); // xss ok
914 -
915 - if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
916 - return;
917 - }
918 -
919 - die();
920 - }
921 -
922 1061 public function get_users_record_meta( $authors ) {
923 1062 $authors_records = array();
924 1063
925 1064 foreach ( $authors as $user_id => $args ) {
926 - $author = new Author( $user_id );
1065 + $author = new Author( $args->ID );
927 1066
928 1067 $authors_records[ $user_id ] = array(
929 - 'text' => $author->get_display_name(),
930 - 'id' => $user_id,
931 - 'label' => $author->get_display_name(),
932 - 'icon' => $author->get_avatar_src( 32 ),
933 - 'title' => '',
1068 + 'text' => $author->get_display_name(),
1069 + 'id' => $author->id,
1070 + 'label' => $author->get_display_name(),
1071 + 'icon' => $author->get_avatar_src( 32 ),
1072 + 'title' => '',
934 1073 );
935 1074 }
936 1075
937 1076 return $authors_records;
@@ -939,18 +1078,19 @@
939 1078
940 1079 /**
941 1080 * Get user meta in a way that is also safe for VIP
942 1081 *
943 - * @param int $user_id
944 - * @param string $meta_key
945 - * @param bool $single (optional)
1082 + * @param int $user_id User ID.
1083 + * @param string $meta_key Meta key.
1084 + * @param bool $single Return first found meta value connected to the meta key (optional).
946 1085 *
947 1086 * @return mixed
948 1087 */
949 - function get_user_meta( $user_id, $meta_key, $single = true ) {
1088 + public function get_user_meta( $user_id, $meta_key, $single = true ) {
950 1089 if ( wp_stream_is_vip() && function_exists( 'get_user_attribute' ) ) {
951 1090 return get_user_attribute( $user_id, $meta_key );
952 1091 }
1092 +
953 1093 return get_user_meta( $user_id, $meta_key, $single );
954 1094 }
955 1095
956 1096 /**
@@ -955,19 +1095,20 @@
955 1095
956 1096 /**
957 1097 * Update user meta in a way that is also safe for VIP
958 1098 *
959 - * @param int $user_id
960 - * @param string $meta_key
961 - * @param mixed $meta_value
962 - * @param mixed $prev_value (optional)
1099 + * @param int $user_id User ID.
1100 + * @param string $meta_key Meta key.
1101 + * @param mixed $meta_value Meta value.
1102 + * @param mixed $prev_value Previous meta value being overwritten (optional).
963 1103 *
964 1104 * @return int|bool
965 1105 */
966 - function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
1106 + public function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
967 1107 if ( wp_stream_is_vip() && function_exists( 'update_user_attribute' ) ) {
968 1108 return update_user_attribute( $user_id, $meta_key, $meta_value );
969 1109 }
1110 +
970 1111 return update_user_meta( $user_id, $meta_key, $meta_value, $prev_value );
971 1112 }
972 1113
973 1114 /**
@@ -972,17 +1113,18 @@
972 1113
973 1114 /**
974 1115 * Delete user meta in a way that is also safe for VIP
975 1116 *
976 - * @param int $user_id
977 - * @param string $meta_key
978 - * @param mixed $meta_value (optional)
1117 + * @param int $user_id User ID.
1118 + * @param string $meta_key Meta key.
1119 + * @param mixed $meta_value Meta value (optional).
979 1120 *
980 1121 * @return bool
981 1122 */
982 - function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
1123 + public function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
983 1124 if ( wp_stream_is_vip() && function_exists( 'delete_user_attribute' ) ) {
984 1125 return delete_user_attribute( $user_id, $meta_key, $meta_value );
985 1126 }
1127 +
986 1128 return delete_user_meta( $user_id, $meta_key, $meta_value );
987 1129 }
988 1130 }