PluginProbe
Stream – Activity Log & Audit Trail / 3.9.0
Stream – Activity Log & Audit Trail v3.9.0
4.4.0 4.3.0 4.2.2 4.2.1 trunk 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.1 3.1.1 3.10.0 3.2.0 3.2.1 3.2.2 3.2.3 All 50 releases
← All changes | classes/class-admin.php +277 -116 3.2.13.9.0 View file →
@@ -1,5 +1,11 @@
1 1 <?php
2 +/**
3 + * Centralized manager for WordPress backend functionality.
4 + *
5 + * @package WP_Stream
6 + */
7 +
2 8 namespace WP_Stream;
3 9
4 10 use DateTime;
5 11 use DateTimeZone;
@@ -6,11 +12,15 @@
6 12 use DateInterval;
7 13 use \WP_CLI;
8 14 use \WP_Roles;
9 15
16 +/**
17 + * Class - Admin
18 + */
10 19 class Admin {
20 +
11 21 /**
12 - * Hold Plugin class
22 + * Holds Instance of plugin object
13 23 *
14 24 * @var Plugin
15 25 */
16 26 public $plugin;
@@ -115,9 +125,9 @@
115 125
116 126 /**
117 127 * Class constructor.
118 128 *
119 - * @param Plugin $plugin The main Plugin class.
129 + * @param Plugin $plugin Instance of plugin object.
120 130 */
121 131 public function __construct( $plugin ) {
122 132 $this->plugin = $plugin;
123 133
@@ -124,9 +134,9 @@
124 134 add_action( 'init', array( $this, 'init' ) );
125 135
126 136 // Ensure function used in various methods is pre-loaded.
127 137 if ( ! function_exists( 'is_plugin_active_for_network' ) ) {
128 - require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
138 + require_once ABSPATH . '/wp-admin/includes/plugin.php';
129 139 }
130 140
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
@@ -131,9 +141,9 @@
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
133 143 add_filter( 'role_has_cap', array( $this, 'filter_role_caps' ), 10, 3 );
134 144
135 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) && ! is_network_admin() ) {
145 + if ( is_multisite() && $plugin->is_network_activated() && ! is_network_admin() ) {
136 146 $options = (array) get_site_option( 'wp_stream_network', array() );
137 147 $option = isset( $options['general_site_access'] ) ? absint( $options['general_site_access'] ) : 1;
138 148
139 149 $this->disable_access = ( $option ) ? false : true;
@@ -151,26 +161,62 @@
151 161 // Add admin body class.
152 162 add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
153 163
154 164 // Plugin action links.
155 - add_filter( 'plugin_action_links', array( $this, 'plugin_action_links' ), 10, 2 );
165 + add_filter(
166 + 'plugin_action_links',
167 + array(
168 + $this,
169 + 'plugin_action_links',
170 + ),
171 + 10,
172 + 2
173 + );
156 174
157 175 // Load admin scripts and styles.
158 - add_action( 'admin_enqueue_scripts', array( $this, 'admin_enqueue_scripts' ) );
176 + add_action(
177 + 'admin_enqueue_scripts',
178 + array(
179 + $this,
180 + 'admin_enqueue_scripts',
181 + )
182 + );
159 183 add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
160 184
161 185 // Reset Streams database.
162 - add_action( 'wp_ajax_wp_stream_reset', array( $this, 'wp_ajax_reset' ) );
186 + add_action(
187 + 'wp_ajax_wp_stream_reset',
188 + array(
189 + $this,
190 + 'wp_ajax_reset',
191 + )
192 + );
163 193
164 - // Uninstall Streams and Deactivate plugin.
194 + /**
195 + * Uninstall Streams and Deactivate plugin.
196 + *
197 + * @todo Confirm if variable assignment is necessary.
198 + */
165 199 $uninstall = $this->plugin->db->driver->purge_storage( $this->plugin );
166 200
167 201 // Auto purge setup.
168 202 add_action( 'wp_loaded', array( $this, 'purge_schedule_setup' ) );
169 - add_action( 'wp_stream_auto_purge', array( $this, 'purge_scheduled_action' ) );
203 + add_action(
204 + 'wp_stream_auto_purge',
205 + array(
206 + $this,
207 + 'purge_scheduled_action',
208 + )
209 + );
170 210
171 211 // Ajax users list.
172 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
212 + add_action(
213 + 'wp_ajax_wp_stream_filters',
214 + array(
215 + $this,
216 + 'ajax_filters',
217 + )
218 + );
173 219 }
174 220
175 221 /**
176 222 * Load admin classes
@@ -207,9 +253,9 @@
207 253 * @param bool $is_error If the message is error_level (true) or warning (false).
208 254 */
209 255 public function notice( $message, $is_error = true ) {
210 256 if ( defined( 'WP_CLI' ) && WP_CLI ) {
211 - $message = strip_tags( $message );
257 + $message = wp_strip_all_tags( $message );
212 258
213 259 if ( $is_error ) {
214 260 WP_CLI::warning( $message );
215 261 } else {
@@ -330,9 +376,15 @@
330 376 */
331 377 do_action( 'wp_stream_admin_menu_screens' );
332 378
333 379 // Register the list table early, so it associates the column headers with 'Screen settings'.
334 - add_action( 'load-' . $this->screen_id['main'], array( $this, 'register_list_table' ) );
380 + add_action(
381 + 'load-' . $this->screen_id['main'],
382 + array(
383 + $this,
384 + 'register_list_table',
385 + )
386 + );
335 387 }
336 388 }
337 389
338 390 /**
@@ -339,9 +391,9 @@
339 391 * Enqueue scripts/styles for admin screen
340 392 *
341 393 * @action admin_enqueue_scripts
342 394 *
343 - * @param string $hook
395 + * @param string $hook Current hook.
344 396 *
345 397 * @return void
346 398 */
347 399 public function admin_enqueue_scripts( $hook ) {
@@ -352,14 +404,27 @@
352 404 $locale = strtolower( substr( get_locale(), 0, 2 ) );
353 405 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
354 406
355 407 if ( file_exists( $this->plugin->locations['dir'] . sprintf( $file_tmpl, $locale ) ) ) {
356 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ), array( 'wp-stream-timeago' ), '1' );
408 + wp_register_script(
409 + 'wp-stream-timeago-locale',
410 + $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ),
411 + array( 'wp-stream-timeago' ),
412 + '1',
413 + false
414 + );
357 415 } else {
358 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ), array( 'wp-stream-timeago' ), '1' );
416 + wp_register_script(
417 + 'wp-stream-timeago-locale',
418 + $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ),
419 + array( 'wp-stream-timeago' ),
420 + '1',
421 + false
422 + );
359 423 }
360 424
361 - wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.css', array(), $this->plugin->get_version() );
425 + $min = wp_stream_min_suffix();
426 + wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.' . $min . 'css', array(), $this->plugin->get_version() );
362 427
363 428 $script_screens = array( 'plugins.php' );
364 429
365 430 if ( in_array( $hook, $this->screen_id, true ) || in_array( $hook, $script_screens, true ) ) {
@@ -368,11 +433,38 @@
368 433
369 434 wp_enqueue_script( 'wp-stream-timeago' );
370 435 wp_enqueue_script( 'wp-stream-timeago-locale' );
371 436
372 - wp_enqueue_script( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/js/admin.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
373 - wp_enqueue_script( 'wp-stream-admin-exclude', $this->plugin->locations['url'] . 'ui/js/exclude.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
374 - wp_enqueue_script( 'wp-stream-live-updates', $this->plugin->locations['url'] . 'ui/js/live-updates.js', array( 'jquery', 'heartbeat' ), $this->plugin->get_version() );
437 + wp_enqueue_script(
438 + 'wp-stream-admin',
439 + $this->plugin->locations['url'] . 'ui/js/admin.' . $min . 'js',
440 + array(
441 + 'jquery',
442 + 'wp-stream-select2',
443 + ),
444 + $this->plugin->get_version(),
445 + false
446 + );
447 + wp_enqueue_script(
448 + 'wp-stream-admin-exclude',
449 + $this->plugin->locations['url'] . 'ui/js/exclude.' . $min . 'js',
450 + array(
451 + 'jquery',
452 + 'wp-stream-select2',
453 + ),
454 + $this->plugin->get_version(),
455 + false
456 + );
457 + wp_enqueue_script(
458 + 'wp-stream-live-updates',
459 + $this->plugin->locations['url'] . 'ui/js/live-updates.' . $min . 'js',
460 + array(
461 + 'jquery',
462 + 'heartbeat',
463 + ),
464 + $this->plugin->get_version(),
465 + false
466 + );
375 467
376 468 wp_localize_script(
377 469 'wp-stream-admin',
378 470 'wp_stream',
@@ -386,17 +478,21 @@
386 478 'gmt_offset' => get_option( 'gmt_offset' ),
387 479 )
388 480 );
389 481
482 + $order_types = array( 'asc', 'desc' );
483 +
390 484 wp_localize_script(
391 485 'wp-stream-live-updates',
392 486 'wp_stream_live_updates',
393 487 array(
394 488 'current_screen' => $hook,
395 - 'current_page' => isset( $_GET['paged'] ) ? esc_js( $_GET['paged'] ) : '1', // input var okay
396 - 'current_order' => isset( $_GET['order'] ) ? esc_js( $_GET['order'] ) : 'desc', // input var okay
397 - 'current_query' => wp_stream_json_encode( $_GET ), // input var okay
398 - 'current_query_count' => count( $_GET ), // input var okay
489 + 'current_page' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : '1', // phpcs:ignore WordPress.Security.NonceVerification.Recommended
490 + 'current_order' => isset( $_GET['order'] ) && in_array( strtolower( $_GET['order'] ), $order_types, true ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
491 + ? esc_js( $_GET['order'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
492 + : 'desc',
493 + 'current_query' => wp_stream_json_encode( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
494 + 'current_query_count' => count( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
399 495 )
400 496 );
401 497 }
402 498
@@ -413,15 +509,23 @@
413 509 * @return int
414 510 */
415 511 $bulk_actions_threshold = apply_filters( 'wp_stream_bulk_actions_threshold', 100 );
416 512
417 - wp_enqueue_script( 'wp-stream-global', $this->plugin->locations['url'] . 'ui/js/global.js', array( 'jquery' ), $this->plugin->get_version() );
513 + wp_enqueue_script(
514 + 'wp-stream-global',
515 + $this->plugin->locations['url'] . 'ui/js/global.' . $min . 'js',
516 + array( 'jquery' ),
517 + $this->plugin->get_version(),
518 + false
519 + );
520 +
418 521 wp_localize_script(
419 522 'wp-stream-global',
420 523 'wp_stream_global',
421 524 array(
422 - 'bulk_actions' => array(
423 - 'i18n' => array(
525 + 'bulk_actions' => array(
526 + 'i18n' => array(
527 + /* translators: %s: a number of items (e.g. "1,742") */
424 528 'confirm_action' => sprintf( esc_html__( 'Are you sure you want to perform bulk actions on over %s items? This process could take a while to complete.', 'stream' ), number_format( absint( $bulk_actions_threshold ) ) ),
425 529 ),
426 530 'threshold' => absint( $bulk_actions_threshold ),
427 531 ),
@@ -450,9 +554,9 @@
450 554
451 555 /**
452 556 * Add a specific body class to all Stream admin screens
453 557 *
454 - * @param string $classes CSS classes to output to body
558 + * @param string $classes CSS classes to output to body.
455 559 *
456 560 * @filter admin_body_class
457 561 *
458 562 * @return string
@@ -462,10 +566,10 @@
462 566
463 567 if ( $this->is_stream_screen() ) {
464 568 $stream_classes[] = $this->admin_body_class;
465 569
466 - if ( isset( $_GET['page'] ) ) {
467 - $stream_classes[] = sanitize_key( $_GET['page'] ); // input var okay
570 + if ( isset( $_GET['page'] ) ) { // // phpcs:ignore WordPress.Security.NonceVerification.Recommended
571 + $stream_classes[] = sanitize_key( $_GET['page'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
468 572 }
469 573 }
470 574
471 575 /**
@@ -486,16 +590,17 @@
486 590 *
487 591 * @action admin_enqueue_scripts
488 592 */
489 593 public function admin_menu_css() {
490 - wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.css', array(), $this->plugin->get_version() );
594 + $min = wp_stream_min_suffix();
595 + wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.' . $min . 'css', array(), $this->plugin->get_version() );
491 596 wp_register_style( 'wp-stream-icons', $this->plugin->locations['url'] . 'ui/stream-icons/style.css', array(), $this->plugin->get_version() );
492 597
493 - // Make sure we're working off a clean version
598 + // Make sure we're working off a clean version.
494 599 if ( ! file_exists( ABSPATH . WPINC . '/version.php' ) ) {
495 600 return;
496 601 }
497 - include( ABSPATH . WPINC . '/version.php' );
602 + include ABSPATH . WPINC . '/version.php';
498 603
499 604 if ( ! isset( $wp_version ) ) {
500 605 return;
501 606 }
@@ -554,10 +659,15 @@
554 659
555 660 \wp_add_inline_style( 'wp-admin', $css );
556 661 }
557 662
663 + /**
664 + * Handle the reset AJAX request to reset logs.
665 + *
666 + * @return bool
667 + */
558 668 public function wp_ajax_reset() {
559 - check_ajax_referer( 'stream_nonce', 'wp_stream_nonce' );
669 + check_ajax_referer( 'stream_nonce_reset', 'wp_stream_nonce_reset' );
560 670
561 671 if ( ! current_user_can( $this->settings_cap ) ) {
562 672 wp_die(
563 673 esc_html__( "You don't have sufficient privileges to do this action.", 'stream' )
@@ -569,9 +679,9 @@
569 679 if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
570 680 return true;
571 681 }
572 682
573 - wp_redirect(
683 + wp_safe_redirect(
574 684 add_query_arg(
575 685 array(
576 686 'page' => is_network_admin() ? $this->network->network_settings_page_slug : $this->settings_page_slug,
577 687 'message' => 'data_erased',
@@ -582,14 +692,19 @@
582 692
583 693 exit;
584 694 }
585 695
696 + /**
697 + * Clears stream records from the database.
698 + *
699 + * @return void
700 + */
586 701 private function erase_stream_records() {
587 702 global $wpdb;
588 703
589 704 $where = '';
590 705
591 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
706 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
592 707 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
593 708 }
594 709
595 710 $wpdb->query(
@@ -600,8 +715,13 @@
600 715 WHERE 1=1 {$where};" // @codingStandardsIgnoreLine $where already prepared
601 716 );
602 717 }
603 718
719 + /**
720 + * Schedules a purge of records.
721 + *
722 + * @return void
723 + */
604 724 public function purge_schedule_setup() {
605 725 if ( ! wp_next_scheduled( 'wp_stream_auto_purge' ) ) {
606 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
607 727 }
@@ -606,26 +726,32 @@
606 726 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
607 727 }
608 728 }
609 729
730 + /**
731 + * Executes a scheduled purge
732 + *
733 + * @return void
734 + */
610 735 public function purge_scheduled_action() {
611 736 global $wpdb;
612 737
613 - // Don't purge when in Network Admin unless Stream is network activated
738 + // Don't purge when in Network Admin unless Stream is network activated.
614 739 if (
615 740 is_multisite()
616 741 &&
617 742 is_network_admin()
618 743 &&
619 - ! is_plugin_active_for_network( $this->plugin->locations['plugin'] )
744 + ! $this->plugin->is_network_activated()
620 745 ) {
621 746 return;
622 747 }
623 748
624 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
625 - $options = (array) get_site_option( 'wp_stream_network', array() );
749 + $defaults = $this->plugin->settings->get_defaults();
750 + if ( is_multisite() && $this->plugin->is_network_activated() ) {
751 + $options = (array) get_site_option( 'wp_stream_network', $defaults );
626 752 } else {
627 - $options = (array) get_option( 'wp_stream', array() );
753 + $options = (array) get_option( 'wp_stream', $defaults );
628 754 }
629 755
630 756 if ( ! empty( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
631 757 return;
@@ -630,17 +756,18 @@
630 756 if ( ! empty( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
631 757 return;
632 758 }
633 759
634 - $days = $options['general_records_ttl'];
635 - $date = new DateTime( 'now', $timezone = new DateTimeZone( 'UTC' ) );
760 + $days = $options['general_records_ttl'];
761 + $timezone = new DateTimeZone( 'UTC' );
762 + $date = new DateTime( 'now', $timezone );
636 763
637 764 $date->sub( DateInterval::createFromDateString( "$days days" ) );
638 765
639 766 $where = $wpdb->prepare( ' AND `stream`.`created` < %s', $date->format( 'Y-m-d H:i:s' ) );
640 767
641 - // Multisite but NOT network activated, only purge the current blog
642 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
768 + // Multisite but NOT network activated, only purge the current blog.
769 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
643 770 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
644 771 }
645 772
646 773 $wpdb->query(
@@ -652,13 +779,15 @@
652 779 );
653 780 }
654 781
655 782 /**
656 - * @param array $links
657 - * @param string $file
783 + * Returns the admin action links.
658 784 *
659 785 * @filter plugin_action_links
660 786 *
787 + * @param array $links Action links.
788 + * @param string $file Plugin file.
789 + *
661 790 * @return array
662 791 */
663 792 public function plugin_action_links( $links, $file ) {
664 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
@@ -664,30 +793,42 @@
664 793 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
665 794 return $links;
666 795 }
667 796
668 - // Also don't show links in Network Admin if Stream isn't network enabled
669 - if ( is_network_admin() && is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
797 + // Also don't show links in Network Admin if Stream isn't network enabled.
798 + if ( is_network_admin() && is_multisite() && ! $this->plugin->is_network_activated() ) {
670 799 return $links;
671 800 }
672 801
673 802 if ( is_network_admin() ) {
674 - $admin_page_url = add_query_arg( array( 'page' => $this->network->network_settings_page_slug ), network_admin_url( $this->admin_parent_page ) );
803 + $admin_page_url = add_query_arg(
804 + array(
805 + 'page' => $this->network->network_settings_page_slug,
806 + ),
807 + network_admin_url( $this->admin_parent_page )
808 + );
675 809 } else {
676 - $admin_page_url = add_query_arg( array( 'page' => $this->settings_page_slug ), admin_url( $this->admin_parent_page ) );
810 + $admin_page_url = add_query_arg(
811 + array(
812 + 'page' => $this->settings_page_slug,
813 + ),
814 + admin_url( $this->admin_parent_page )
815 + );
677 816 }
678 817
679 818 $links[] = sprintf( '<a href="%s">%s</a>', esc_url( $admin_page_url ), esc_html__( 'Settings', 'default' ) );
680 819
681 - $url = add_query_arg(
682 - array(
683 - 'action' => 'wp_stream_uninstall',
684 - 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
685 - ),
686 - admin_url( 'admin-ajax.php' )
687 - );
820 + if ( ! defined( 'DISALLOW_FILE_MODS' ) || false === DISALLOW_FILE_MODS ) {
821 + $url = add_query_arg(
822 + array(
823 + 'action' => 'wp_stream_uninstall',
824 + 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
825 + ),
826 + admin_url( 'admin-ajax.php' )
827 + );
688 828
689 - $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
829 + $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
830 + }
690 831
691 832 return $links;
692 833 }
693 834
@@ -697,12 +838,12 @@
697 838 public function render_list_table() {
698 839 $this->list_table->prepare_items();
699 840 ?>
700 841 <div class="wrap">
701 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
702 - <?php $this->list_table->display() ?>
842 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
843 + <?php $this->list_table->display(); ?>
703 844 </div>
704 - <?php
845 + <?php
705 846 }
706 847
707 848 /**
708 849 * Render settings page
@@ -714,28 +855,28 @@
714 855 $page_description = apply_filters( 'wp_stream_settings_form_description', '' );
715 856
716 857 $sections = $this->plugin->settings->get_fields();
717 858 $active_tab = wp_stream_filter_input( INPUT_GET, 'tab' );
718 -
719 - wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.js', array( 'jquery' ), $this->plugin->get_version(), true );
859 + $min = wp_stream_min_suffix();
860 + wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.' . $min . 'js', array( 'jquery' ), $this->plugin->get_version(), true );
720 861 ?>
721 862 <div class="wrap">
722 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
863 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
723 864
724 865 <?php if ( ! empty( $page_description ) ) : ?>
725 - <p><?php echo esc_html( $page_description ) ?></p>
866 + <p><?php echo esc_html( $page_description ); ?></p>
726 867 <?php endif; ?>
727 868
728 - <?php settings_errors() ?>
869 + <?php settings_errors(); ?>
729 870
730 871 <?php if ( count( $sections ) > 1 ) : ?>
731 872 <h2 class="nav-tab-wrapper">
732 - <?php $i = 0 ?>
873 + <?php $i = 0; ?>
733 874 <?php foreach ( $sections as $section => $data ) : ?>
734 - <?php $i ++ ?>
735 - <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ) ?>
736 - <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ) ?>" class="nav-tab<?php if ( $is_active ) { echo esc_attr( ' nav-tab-active' ); } ?>">
737 - <?php echo esc_html( $data['title'] ) ?>
875 + <?php $i++; ?>
876 + <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ); ?>
877 + <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ); ?>" class="nav-tab <?php echo $is_active ? esc_attr( ' nav-tab-active' ) : ''; ?>">
878 + <?php echo esc_html( $data['title'] ); ?>
738 879 </a>
739 880 <?php endforeach; ?>
740 881 </h2>
741 882 <?php endif; ?>
@@ -740,29 +881,29 @@
740 881 </h2>
741 882 <?php endif; ?>
742 883
743 884 <div class="nav-tab-content" id="tab-content-settings">
744 - <form method="post" action="<?php echo esc_attr( $form_action ) ?>" enctype="multipart/form-data">
885 + <form method="post" action="<?php echo esc_attr( $form_action ); ?>" enctype="multipart/form-data">
745 886 <div class="settings-sections">
746 - <?php
747 - $i = 0;
748 - foreach ( $sections as $section => $data ) {
749 - $i++;
887 + <?php
888 + $i = 0;
889 + foreach ( $sections as $section => $data ) {
890 + $i++;
750 891
751 - $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
892 + $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
752 893
753 - if ( $is_active ) {
754 - settings_fields( $option_key );
755 - do_settings_sections( $option_key );
756 - }
757 - }
758 - ?>
894 + if ( $is_active ) {
895 + settings_fields( $option_key );
896 + do_settings_sections( $option_key );
897 + }
898 + }
899 + ?>
759 900 </div>
760 - <?php submit_button() ?>
901 + <?php submit_button(); ?>
761 902 </form>
762 903 </div>
763 904 </div>
764 - <?php
905 + <?php
765 906 }
766 907
767 908 /**
768 909 * Instantiate the list table
@@ -767,15 +908,20 @@
767 908 /**
768 909 * Instantiate the list table
769 910 */
770 911 public function register_list_table() {
771 - $this->list_table = new List_Table( $this->plugin, array( 'screen' => $this->screen_id['main'] ) );
912 + $this->list_table = new List_Table(
913 + $this->plugin,
914 + array(
915 + 'screen' => $this->screen_id['main'],
916 + )
917 + );
772 918 }
773 919
774 920 /**
775 921 * Check if a particular role has access
776 922 *
777 - * @param string $role
923 + * @param string $role User role.
778 924 *
779 925 * @return bool
780 926 */
781 927 private function role_can_view( $role ) {
@@ -788,12 +934,12 @@
788 934
789 935 /**
790 936 * Filter user caps to dynamically grant our view cap based on allowed roles
791 937 *
792 - * @param $allcaps
793 - * @param $caps
794 - * @param $args
795 - * @param $user
938 + * @param array $allcaps All capabilities.
939 + * @param array $caps Required caps.
940 + * @param array $args Unused.
941 + * @param WP_User $user User.
796 942 *
797 943 * @filter user_has_cap
798 944 *
799 945 * @return array
@@ -838,11 +984,11 @@
838 984 * Filter role caps to dynamically grant our view cap based on allowed roles
839 985 *
840 986 * @filter role_has_cap
841 987 *
842 - * @param $allcaps
843 - * @param $cap
844 - * @param $role
988 + * @param array $allcaps All capabilities.
989 + * @param string $cap Require cap.
990 + * @param string $role User role.
845 991 *
846 992 * @return array
847 993 */
848 994 public function filter_role_caps( $allcaps, $cap, $role ) {
@@ -855,8 +1001,10 @@
855 1001 return $allcaps;
856 1002 }
857 1003
858 1004 /**
1005 + * Ajax callback for return a user list.
1006 + *
859 1007 * @action wp_ajax_wp_stream_filters
860 1008 */
861 1009 public function ajax_filters() {
862 1010 if ( ! defined( 'DOING_AJAX' ) || ! current_user_can( $this->plugin->admin->settings_cap ) ) {
@@ -867,9 +1015,13 @@
867 1015
868 1016 switch ( wp_stream_filter_input( INPUT_GET, 'filter' ) ) {
869 1017 case 'user_id':
870 1018 $users = array_merge(
871 - array( 0 => (object) array( 'display_name' => 'WP-CLI' ) ),
1019 + array(
1020 + 0 => (object) array(
1021 + 'display_name' => 'WP-CLI',
1022 + ),
1023 + ),
872 1024 get_users()
873 1025 );
874 1026
875 1027 $search = wp_stream_filter_input( INPUT_GET, 'q' );
@@ -876,9 +1028,9 @@
876 1028 if ( $search ) {
877 1029 // `search` arg for get_users() is not enough
878 1030 $users = array_filter(
879 1031 $users,
880 - function( $user ) use ( $search ) {
1032 + function ( $user ) use ( $search ) {
881 1033 return false !== mb_strpos( mb_strtolower( $user->display_name ), mb_strtolower( $search ) );
882 1034 }
883 1035 );
884 1036 }
@@ -886,9 +1038,9 @@
886 1038 if ( count( $users ) > $this->preload_users_max ) {
887 1039 $users = array_slice( $users, 0, $this->preload_users_max );
888 1040 }
889 1041
890 - // Get gravatar / roles for final result set
1042 + // Get gravatar / roles for final result set.
891 1043 $results = $this->get_users_record_meta( $users );
892 1044
893 1045 break;
894 1046 }
@@ -893,14 +1045,20 @@
893 1045 break;
894 1046 }
895 1047
896 1048 if ( isset( $results ) ) {
897 - echo wp_stream_json_encode( $results ); // xss ok
1049 + echo wp_stream_json_encode( $results ); // xss ok.
898 1050 }
899 1051
900 1052 die();
901 1053 }
902 1054
1055 + /**
1056 + * Return relevant user meta data.
1057 + *
1058 + * @param array $authors Author data.
1059 + * @return array
1060 + */
903 1061 public function get_users_record_meta( $authors ) {
904 1062 $authors_records = array();
905 1063
906 1064 foreach ( $authors as $user_id => $args ) {
@@ -906,13 +1064,13 @@
906 1064 foreach ( $authors as $user_id => $args ) {
907 1065 $author = new Author( $args->ID );
908 1066
909 1067 $authors_records[ $user_id ] = array(
910 - 'text' => $author->get_display_name(),
911 - 'id' => $author->id,
912 - 'label' => $author->get_display_name(),
913 - 'icon' => $author->get_avatar_src( 32 ),
914 - 'title' => '',
1068 + 'text' => $author->get_display_name(),
1069 + 'id' => $author->id,
1070 + 'label' => $author->get_display_name(),
1071 + 'icon' => $author->get_avatar_src( 32 ),
1072 + 'title' => '',
915 1073 );
916 1074 }
917 1075
918 1076 return $authors_records;
@@ -920,18 +1078,19 @@
920 1078
921 1079 /**
922 1080 * Get user meta in a way that is also safe for VIP
923 1081 *
924 - * @param int $user_id
925 - * @param string $meta_key
926 - * @param bool $single (optional)
1082 + * @param int $user_id User ID.
1083 + * @param string $meta_key Meta key.
1084 + * @param bool $single Return first found meta value connected to the meta key (optional).
927 1085 *
928 1086 * @return mixed
929 1087 */
930 - function get_user_meta( $user_id, $meta_key, $single = true ) {
1088 + public function get_user_meta( $user_id, $meta_key, $single = true ) {
931 1089 if ( wp_stream_is_vip() && function_exists( 'get_user_attribute' ) ) {
932 1090 return get_user_attribute( $user_id, $meta_key );
933 1091 }
1092 +
934 1093 return get_user_meta( $user_id, $meta_key, $single );
935 1094 }
936 1095
937 1096 /**
@@ -936,19 +1095,20 @@
936 1095
937 1096 /**
938 1097 * Update user meta in a way that is also safe for VIP
939 1098 *
940 - * @param int $user_id
941 - * @param string $meta_key
942 - * @param mixed $meta_value
943 - * @param mixed $prev_value (optional)
1099 + * @param int $user_id User ID.
1100 + * @param string $meta_key Meta key.
1101 + * @param mixed $meta_value Meta value.
1102 + * @param mixed $prev_value Previous meta value being overwritten (optional).
944 1103 *
945 1104 * @return int|bool
946 1105 */
947 - function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
1106 + public function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
948 1107 if ( wp_stream_is_vip() && function_exists( 'update_user_attribute' ) ) {
949 1108 return update_user_attribute( $user_id, $meta_key, $meta_value );
950 1109 }
1110 +
951 1111 return update_user_meta( $user_id, $meta_key, $meta_value, $prev_value );
952 1112 }
953 1113
954 1114 /**
@@ -953,17 +1113,18 @@
953 1113
954 1114 /**
955 1115 * Delete user meta in a way that is also safe for VIP
956 1116 *
957 - * @param int $user_id
958 - * @param string $meta_key
959 - * @param mixed $meta_value (optional)
1117 + * @param int $user_id User ID.
1118 + * @param string $meta_key Meta key.
1119 + * @param mixed $meta_value Meta value (optional).
960 1120 *
961 1121 * @return bool
962 1122 */
963 - function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
1123 + public function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
964 1124 if ( wp_stream_is_vip() && function_exists( 'delete_user_attribute' ) ) {
965 1125 return delete_user_attribute( $user_id, $meta_key, $meta_value );
966 1126 }
1127 +
967 1128 return delete_user_meta( $user_id, $meta_key, $meta_value );
968 1129 }
969 1130 }