PluginProbe
Stream – Activity Log & Audit Trail / 4.0.2
Stream – Activity Log & Audit Trail v4.0.2
4.4.0 4.3.0 4.2.2 4.2.1 trunk 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.1 3.1.1 3.10.0 3.2.0 3.2.1 3.2.2 3.2.3 All 50 releases
← All changes | classes/class-admin.php +292 -139 3.0.74.0.2 View file →
@@ -1,16 +1,26 @@
1 1 <?php
2 +/**
3 + * Centralized manager for WordPress backend functionality.
4 + *
5 + * @package WP_Stream
6 + */
7 +
2 8 namespace WP_Stream;
3 9
4 10 use DateTime;
5 11 use DateTimeZone;
6 12 use DateInterval;
7 -use \WP_CLI;
8 -use \WP_Roles;
13 +use WP_CLI;
14 +use WP_Roles;
9 15
16 +/**
17 + * Class - Admin
18 + */
10 19 class Admin {
20 +
11 21 /**
12 - * Hold Plugin class
22 + * Holds Instance of plugin object
13 23 *
14 24 * @var Plugin
15 25 */
16 26 public $plugin;
@@ -115,9 +125,9 @@
115 125
116 126 /**
117 127 * Class constructor.
118 128 *
119 - * @param Plugin $plugin The main Plugin class.
129 + * @param Plugin $plugin Instance of plugin object.
120 130 */
121 131 public function __construct( $plugin ) {
122 132 $this->plugin = $plugin;
123 133
@@ -124,9 +134,9 @@
124 134 add_action( 'init', array( $this, 'init' ) );
125 135
126 136 // Ensure function used in various methods is pre-loaded.
127 137 if ( ! function_exists( 'is_plugin_active_for_network' ) ) {
128 - require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
138 + require_once ABSPATH . '/wp-admin/includes/plugin.php';
129 139 }
130 140
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
@@ -131,9 +141,9 @@
131 141 // User and role caps.
132 142 add_filter( 'user_has_cap', array( $this, 'filter_user_caps' ), 10, 4 );
133 143 add_filter( 'role_has_cap', array( $this, 'filter_role_caps' ), 10, 3 );
134 144
135 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) && ! is_network_admin() ) {
145 + if ( is_multisite() && $plugin->is_network_activated() && ! is_network_admin() ) {
136 146 $options = (array) get_site_option( 'wp_stream_network', array() );
137 147 $option = isset( $options['general_site_access'] ) ? absint( $options['general_site_access'] ) : 1;
138 148
139 149 $this->disable_access = ( $option ) ? false : true;
@@ -151,27 +161,55 @@
151 161 // Add admin body class.
152 162 add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
153 163
154 164 // Plugin action links.
155 - add_filter( 'plugin_action_links', array( $this, 'plugin_action_links' ), 10, 2 );
165 + add_filter(
166 + 'plugin_action_links',
167 + array(
168 + $this,
169 + 'plugin_action_links',
170 + ),
171 + 10,
172 + 2
173 + );
156 174
157 175 // Load admin scripts and styles.
158 - add_action( 'admin_enqueue_scripts', array( $this, 'admin_enqueue_scripts' ) );
176 + add_action(
177 + 'admin_enqueue_scripts',
178 + array(
179 + $this,
180 + 'admin_enqueue_scripts',
181 + )
182 + );
159 183 add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
160 184
161 185 // Reset Streams database.
162 - add_action( 'wp_ajax_wp_stream_reset', array( $this, 'wp_ajax_reset' ) );
186 + add_action(
187 + 'wp_ajax_wp_stream_reset',
188 + array(
189 + $this,
190 + 'wp_ajax_reset',
191 + )
192 + );
163 193
164 - // Uninstall Streams and Deactivate plugin.
165 - $uninstall = new Uninstall( $this->plugin );
166 - add_action( 'wp_ajax_wp_stream_uninstall', array( $uninstall, 'uninstall' ) );
167 -
168 194 // Auto purge setup.
169 195 add_action( 'wp_loaded', array( $this, 'purge_schedule_setup' ) );
170 - add_action( 'wp_stream_auto_purge', array( $this, 'purge_scheduled_action' ) );
196 + add_action(
197 + 'wp_stream_auto_purge',
198 + array(
199 + $this,
200 + 'purge_scheduled_action',
201 + )
202 + );
171 203
172 204 // Ajax users list.
173 - add_action( 'wp_ajax_wp_stream_filters', array( $this, 'ajax_filters' ) );
205 + add_action(
206 + 'wp_ajax_wp_stream_filters',
207 + array(
208 + $this,
209 + 'ajax_filters',
210 + )
211 + );
174 212 }
175 213
176 214 /**
177 215 * Load admin classes
@@ -181,8 +219,14 @@
181 219 public function init() {
182 220 $this->network = new Network( $this->plugin );
183 221 $this->live_update = new Live_Update( $this->plugin );
184 222 $this->export = new Export( $this->plugin );
223 +
224 + // Check if the host has configured the `REMOTE_ADDR` correctly.
225 + $client_ip = $this->plugin->get_client_ip_address();
226 + if ( empty( $client_ip ) && $this->is_stream_screen() ) {
227 + $this->notice( __( 'Stream plugin can\'t determine a reliable client IP address! Please update the hosting environment to set the $_SERVER[\'REMOTE_ADDR\'] variable or use the wp_stream_client_ip_address filter to specify the verified client IP address!', 'stream' ) );
228 + }
185 229 }
186 230
187 231 /**
188 232 * Output specific updates passed as URL parameters.
@@ -208,9 +252,9 @@
208 252 * @param bool $is_error If the message is error_level (true) or warning (false).
209 253 */
210 254 public function notice( $message, $is_error = true ) {
211 255 if ( defined( 'WP_CLI' ) && WP_CLI ) {
212 - $message = strip_tags( $message );
256 + $message = wp_strip_all_tags( $message );
213 257
214 258 if ( $is_error ) {
215 259 WP_CLI::warning( $message );
216 260 } else {
@@ -299,8 +343,16 @@
299 343 $main_menu_position
300 344 );
301 345
302 346 /**
347 + * Fires before submenu items are added to the Stream menu
348 + * allowing plugins to add menu items before Settings
349 + *
350 + * @return void
351 + */
352 + do_action( 'wp_stream_admin_menu' );
353 +
354 + /**
303 355 * Filter the Settings admin page title
304 356 *
305 357 * @return string
306 358 */
@@ -323,9 +375,15 @@
323 375 */
324 376 do_action( 'wp_stream_admin_menu_screens' );
325 377
326 378 // Register the list table early, so it associates the column headers with 'Screen settings'.
327 - add_action( 'load-' . $this->screen_id['main'], array( $this, 'register_list_table' ) );
379 + add_action(
380 + 'load-' . $this->screen_id['main'],
381 + array(
382 + $this,
383 + 'register_list_table',
384 + )
385 + );
328 386 }
329 387 }
330 388
331 389 /**
@@ -332,15 +390,15 @@
332 390 * Enqueue scripts/styles for admin screen
333 391 *
334 392 * @action admin_enqueue_scripts
335 393 *
336 - * @param string $hook
394 + * @param string $hook Current hook.
337 395 *
338 396 * @return void
339 397 */
340 398 public function admin_enqueue_scripts( $hook ) {
341 - wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/js/select2.js', array( 'jquery' ), '3.5.2', true );
342 - wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/css/select2.css', array(), '3.5.2' );
399 + wp_register_script( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/js/select2.full.min.js', array( 'jquery' ), '4.0.13', true );
400 + wp_register_style( 'wp-stream-select2', $this->plugin->locations['url'] . 'ui/lib/select2/css/select2.min.css', array(), '4.0.13' );
343 401 wp_register_script( 'wp-stream-timeago', $this->plugin->locations['url'] . 'ui/lib/timeago/jquery.timeago.js', array(), '1.4.1', true );
344 402
345 403 $locale = strtolower( substr( get_locale(), 0, 2 ) );
346 404 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
@@ -345,14 +403,27 @@
345 403 $locale = strtolower( substr( get_locale(), 0, 2 ) );
346 404 $file_tmpl = 'ui/lib/timeago/locales/jquery.timeago.%s.js';
347 405
348 406 if ( file_exists( $this->plugin->locations['dir'] . sprintf( $file_tmpl, $locale ) ) ) {
349 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ), array( 'wp-stream-timeago' ), '1' );
407 + wp_register_script(
408 + 'wp-stream-timeago-locale',
409 + $this->plugin->locations['url'] . sprintf( $file_tmpl, $locale ),
410 + array( 'wp-stream-timeago' ),
411 + '1',
412 + false
413 + );
350 414 } else {
351 - wp_register_script( 'wp-stream-timeago-locale', $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ), array( 'wp-stream-timeago' ), '1' );
415 + wp_register_script(
416 + 'wp-stream-timeago-locale',
417 + $this->plugin->locations['url'] . sprintf( $file_tmpl, 'en' ),
418 + array( 'wp-stream-timeago' ),
419 + '1',
420 + false
421 + );
352 422 }
353 423
354 - wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.css', array(), $this->plugin->get_version() );
424 + $min = wp_stream_min_suffix();
425 + wp_enqueue_style( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/css/admin.' . $min . 'css', array(), $this->plugin->get_version() );
355 426
356 427 $script_screens = array( 'plugins.php' );
357 428
358 429 if ( in_array( $hook, $this->screen_id, true ) || in_array( $hook, $script_screens, true ) ) {
@@ -361,11 +432,38 @@
361 432
362 433 wp_enqueue_script( 'wp-stream-timeago' );
363 434 wp_enqueue_script( 'wp-stream-timeago-locale' );
364 435
365 - wp_enqueue_script( 'wp-stream-admin', $this->plugin->locations['url'] . 'ui/js/admin.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
366 - wp_enqueue_script( 'wp-stream-admin-exclude', $this->plugin->locations['url'] . 'ui/js/exclude.js', array( 'jquery', 'wp-stream-select2' ), $this->plugin->get_version() );
367 - wp_enqueue_script( 'wp-stream-live-updates', $this->plugin->locations['url'] . 'ui/js/live-updates.js', array( 'jquery', 'heartbeat' ), $this->plugin->get_version() );
436 + wp_enqueue_script(
437 + 'wp-stream-admin',
438 + $this->plugin->locations['url'] . 'ui/js/admin.' . $min . 'js',
439 + array(
440 + 'jquery',
441 + 'wp-stream-select2',
442 + ),
443 + $this->plugin->get_version(),
444 + false
445 + );
446 + wp_enqueue_script(
447 + 'wp-stream-admin-exclude',
448 + $this->plugin->locations['url'] . 'ui/js/exclude.' . $min . 'js',
449 + array(
450 + 'jquery',
451 + 'wp-stream-select2',
452 + ),
453 + $this->plugin->get_version(),
454 + false
455 + );
456 + wp_enqueue_script(
457 + 'wp-stream-live-updates',
458 + $this->plugin->locations['url'] . 'ui/js/live-updates.' . $min . 'js',
459 + array(
460 + 'jquery',
461 + 'heartbeat',
462 + ),
463 + $this->plugin->get_version(),
464 + false
465 + );
368 466
369 467 wp_localize_script(
370 468 'wp-stream-admin',
371 469 'wp_stream',
@@ -370,11 +468,10 @@
370 468 'wp-stream-admin',
371 469 'wp_stream',
372 470 array(
373 471 'i18n' => array(
374 - 'confirm_purge' => esc_html__( 'Are you sure you want to delete all Stream activity records from the database? This cannot be undone.', 'stream' ),
375 - 'confirm_defaults' => esc_html__( 'Are you sure you want to reset all site settings to default? This cannot be undone.', 'stream' ),
376 - 'confirm_uninstall' => esc_html__( 'Are you sure you want to uninstall and deactivate Stream? This will delete all Stream tables from the database and cannot be undone.', 'stream' ),
472 + 'confirm_purge' => esc_html__( 'Are you sure you want to delete all Stream activity records from the database? This cannot be undone.', 'stream' ),
473 + 'confirm_defaults' => esc_html__( 'Are you sure you want to reset all site settings to default? This cannot be undone.', 'stream' ),
377 474 ),
378 475 'locale' => esc_js( $locale ),
379 476 'gmt_offset' => get_option( 'gmt_offset' ),
380 477 )
@@ -379,17 +476,21 @@
379 476 'gmt_offset' => get_option( 'gmt_offset' ),
380 477 )
381 478 );
382 479
480 + $order_types = array( 'asc', 'desc' );
481 +
383 482 wp_localize_script(
384 483 'wp-stream-live-updates',
385 484 'wp_stream_live_updates',
386 485 array(
387 486 'current_screen' => $hook,
388 - 'current_page' => isset( $_GET['paged'] ) ? esc_js( $_GET['paged'] ) : '1', // input var okay
389 - 'current_order' => isset( $_GET['order'] ) ? esc_js( $_GET['order'] ) : 'desc', // input var okay
390 - 'current_query' => wp_stream_json_encode( $_GET ), // input var okay
391 - 'current_query_count' => count( $_GET ), // input var okay
487 + 'current_page' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : '1', // phpcs:ignore WordPress.Security.NonceVerification.Recommended
488 + 'current_order' => isset( $_GET['order'] ) && in_array( strtolower( $_GET['order'] ), $order_types, true ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
489 + ? esc_js( $_GET['order'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
490 + : 'desc',
491 + 'current_query' => wp_json_encode( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
492 + 'current_query_count' => count( $_GET ), // phpcs:ignore WordPress.Security.NonceVerification.Recommended
392 493 )
393 494 );
394 495 }
395 496
@@ -406,15 +507,23 @@
406 507 * @return int
407 508 */
408 509 $bulk_actions_threshold = apply_filters( 'wp_stream_bulk_actions_threshold', 100 );
409 510
410 - wp_enqueue_script( 'wp-stream-global', $this->plugin->locations['url'] . 'ui/js/global.js', array( 'jquery' ), $this->plugin->get_version() );
511 + wp_enqueue_script(
512 + 'wp-stream-global',
513 + $this->plugin->locations['url'] . 'ui/js/global.' . $min . 'js',
514 + array( 'jquery' ),
515 + $this->plugin->get_version(),
516 + false
517 + );
518 +
411 519 wp_localize_script(
412 520 'wp-stream-global',
413 521 'wp_stream_global',
414 522 array(
415 - 'bulk_actions' => array(
416 - 'i18n' => array(
523 + 'bulk_actions' => array(
524 + 'i18n' => array(
525 + /* translators: %s: a number of items (e.g. "1,742") */
417 526 'confirm_action' => sprintf( esc_html__( 'Are you sure you want to perform bulk actions on over %s items? This process could take a while to complete.', 'stream' ), number_format( absint( $bulk_actions_threshold ) ) ),
418 527 ),
419 528 'threshold' => absint( $bulk_actions_threshold ),
420 529 ),
@@ -428,12 +537,23 @@
428 537 *
429 538 * @return bool
430 539 */
431 540 public function is_stream_screen() {
432 - if ( is_admin() && false !== strpos( wp_stream_filter_input( INPUT_GET, 'page' ), $this->records_page_slug ) ) {
541 + if ( ! is_admin() ) {
542 + return false;
543 + }
544 +
545 + $page = wp_stream_filter_input( INPUT_GET, 'page' );
546 + if ( is_string( $page ) && false !== strpos( $page, $this->records_page_slug ) ) {
433 547 return true;
434 548 }
435 549
550 + if ( is_admin() && function_exists( 'get_current_screen' ) ) {
551 + $screen = get_current_screen();
552 +
553 + return ( Alerts::POST_TYPE === $screen->post_type );
554 + }
555 +
436 556 return false;
437 557 }
438 558
439 559 /**
@@ -438,9 +558,9 @@
438 558
439 559 /**
440 560 * Add a specific body class to all Stream admin screens
441 561 *
442 - * @param string $classes CSS classes to output to body
562 + * @param string $classes CSS classes to output to body.
443 563 *
444 564 * @filter admin_body_class
445 565 *
446 566 * @return string
@@ -450,10 +570,10 @@
450 570
451 571 if ( $this->is_stream_screen() ) {
452 572 $stream_classes[] = $this->admin_body_class;
453 573
454 - if ( isset( $_GET['page'] ) ) {
455 - $stream_classes[] = sanitize_key( $_GET['page'] ); // input var okay
574 + if ( isset( $_GET['page'] ) ) { // // phpcs:ignore WordPress.Security.NonceVerification.Recommended
575 + $stream_classes[] = sanitize_key( $_GET['page'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
456 576 }
457 577 }
458 578
459 579 /**
@@ -474,16 +594,17 @@
474 594 *
475 595 * @action admin_enqueue_scripts
476 596 */
477 597 public function admin_menu_css() {
478 - wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.css', array(), $this->plugin->get_version() );
598 + $min = wp_stream_min_suffix();
599 + wp_register_style( 'wp-stream-datepicker', $this->plugin->locations['url'] . 'ui/css/datepicker.' . $min . 'css', array(), $this->plugin->get_version() );
479 600 wp_register_style( 'wp-stream-icons', $this->plugin->locations['url'] . 'ui/stream-icons/style.css', array(), $this->plugin->get_version() );
480 601
481 - // Make sure we're working off a clean version
602 + // Make sure we're working off a clean version.
482 603 if ( ! file_exists( ABSPATH . WPINC . '/version.php' ) ) {
483 604 return;
484 605 }
485 - include( ABSPATH . WPINC . '/version.php' );
606 + include ABSPATH . WPINC . '/version.php';
486 607
487 608 if ( ! isset( $wp_version ) ) {
488 609 return;
489 610 }
@@ -542,10 +663,15 @@
542 663
543 664 \wp_add_inline_style( 'wp-admin', $css );
544 665 }
545 666
667 + /**
668 + * Handle the reset AJAX request to reset logs.
669 + *
670 + * @return bool
671 + */
546 672 public function wp_ajax_reset() {
547 - check_ajax_referer( 'stream_nonce', 'wp_stream_nonce' );
673 + check_ajax_referer( 'stream_nonce_reset', 'wp_stream_nonce_reset' );
548 674
549 675 if ( ! current_user_can( $this->settings_cap ) ) {
550 676 wp_die(
551 677 esc_html__( "You don't have sufficient privileges to do this action.", 'stream' )
@@ -557,9 +683,9 @@
557 683 if ( defined( 'WP_STREAM_TESTS' ) && WP_STREAM_TESTS ) {
558 684 return true;
559 685 }
560 686
561 - wp_redirect(
687 + wp_safe_redirect(
562 688 add_query_arg(
563 689 array(
564 690 'page' => is_network_admin() ? $this->network->network_settings_page_slug : $this->settings_page_slug,
565 691 'message' => 'data_erased',
@@ -570,14 +696,19 @@
570 696
571 697 exit;
572 698 }
573 699
700 + /**
701 + * Clears stream records from the database.
702 + *
703 + * @return void
704 + */
574 705 private function erase_stream_records() {
575 706 global $wpdb;
576 707
577 708 $where = '';
578 709
579 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
710 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
580 711 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
581 712 }
582 713
583 714 $wpdb->query(
@@ -588,8 +719,13 @@
588 719 WHERE 1=1 {$where};" // @codingStandardsIgnoreLine $where already prepared
589 720 );
590 721 }
591 722
723 + /**
724 + * Schedules a purge of records.
725 + *
726 + * @return void
727 + */
592 728 public function purge_schedule_setup() {
593 729 if ( ! wp_next_scheduled( 'wp_stream_auto_purge' ) ) {
594 730 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
595 731 }
@@ -594,41 +730,48 @@
594 730 wp_schedule_event( time(), 'twicedaily', 'wp_stream_auto_purge' );
595 731 }
596 732 }
597 733
734 + /**
735 + * Executes a scheduled purge
736 + *
737 + * @return void
738 + */
598 739 public function purge_scheduled_action() {
599 740 global $wpdb;
600 741
601 - // Don't purge when in Network Admin unless Stream is network activated
742 + // Don't purge when in Network Admin unless Stream is network activated.
602 743 if (
603 744 is_multisite()
604 745 &&
605 746 is_network_admin()
606 747 &&
607 - ! is_plugin_active_for_network( $this->plugin->locations['plugin'] )
748 + ! $this->plugin->is_network_activated()
608 749 ) {
609 750 return;
610 751 }
611 752
612 - if ( is_multisite() && is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
613 - $options = (array) get_site_option( 'wp_stream_network', array() );
753 + $defaults = $this->plugin->settings->get_defaults();
754 + if ( is_multisite() && $this->plugin->is_network_activated() ) {
755 + $options = (array) get_site_option( 'wp_stream_network', $defaults );
614 756 } else {
615 - $options = (array) get_option( 'wp_stream', array() );
757 + $options = (array) get_option( 'wp_stream', $defaults );
616 758 }
617 759
618 - if ( isset( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
760 + if ( ! empty( $options['general_keep_records_indefinitely'] ) || ! isset( $options['general_records_ttl'] ) ) {
619 761 return;
620 762 }
621 763
622 - $days = $options['general_records_ttl'];
623 - $date = new DateTime( 'now', $timezone = new DateTimeZone( 'UTC' ) );
764 + $days = $options['general_records_ttl'];
765 + $timezone = new DateTimeZone( 'UTC' );
766 + $date = new DateTime( 'now', $timezone );
624 767
625 768 $date->sub( DateInterval::createFromDateString( "$days days" ) );
626 769
627 770 $where = $wpdb->prepare( ' AND `stream`.`created` < %s', $date->format( 'Y-m-d H:i:s' ) );
628 771
629 - // Multisite but NOT network activated, only purge the current blog
630 - if ( is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
772 + // Multisite but NOT network activated, only purge the current blog.
773 + if ( is_multisite() && ! $this->plugin->is_network_activated() ) {
631 774 $where .= $wpdb->prepare( ' AND `blog_id` = %d', get_current_blog_id() );
632 775 }
633 776
634 777 $wpdb->query(
@@ -640,13 +783,15 @@
640 783 );
641 784 }
642 785
643 786 /**
644 - * @param array $links
645 - * @param string $file
787 + * Returns the admin action links.
646 788 *
647 789 * @filter plugin_action_links
648 790 *
791 + * @param array $links Action links.
792 + * @param string $file Plugin file.
793 + *
649 794 * @return array
650 795 */
651 796 public function plugin_action_links( $links, $file ) {
652 797 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
@@ -652,31 +797,31 @@
652 797 if ( plugin_basename( $this->plugin->locations['dir'] . 'stream.php' ) !== $file ) {
653 798 return $links;
654 799 }
655 800
656 - // Also don't show links in Network Admin if Stream isn't network enabled
657 - if ( is_network_admin() && is_multisite() && ! is_plugin_active_for_network( $this->plugin->locations['plugin'] ) ) {
801 + // Also don't show links in Network Admin if Stream isn't network enabled.
802 + if ( is_network_admin() && is_multisite() && ! $this->plugin->is_network_activated() ) {
658 803 return $links;
659 804 }
660 805
661 806 if ( is_network_admin() ) {
662 - $admin_page_url = add_query_arg( array( 'page' => $this->network->network_settings_page_slug ), network_admin_url( $this->admin_parent_page ) );
807 + $admin_page_url = add_query_arg(
808 + array(
809 + 'page' => $this->network->network_settings_page_slug,
810 + ),
811 + network_admin_url( $this->admin_parent_page )
812 + );
663 813 } else {
664 - $admin_page_url = add_query_arg( array( 'page' => $this->settings_page_slug ), admin_url( $this->admin_parent_page ) );
814 + $admin_page_url = add_query_arg(
815 + array(
816 + 'page' => $this->settings_page_slug,
817 + ),
818 + admin_url( $this->admin_parent_page )
819 + );
665 820 }
666 821
667 822 $links[] = sprintf( '<a href="%s">%s</a>', esc_url( $admin_page_url ), esc_html__( 'Settings', 'default' ) );
668 823
669 - $url = add_query_arg(
670 - array(
671 - 'action' => 'wp_stream_uninstall',
672 - 'wp_stream_nonce' => wp_create_nonce( 'stream_nonce' ),
673 - ),
674 - admin_url( 'admin-ajax.php' )
675 - );
676 -
677 - $links[] = sprintf( '<span id="wp_stream_uninstall" class="delete"><a href="%s">%s</a></span>', esc_url( $url ), esc_html__( 'Uninstall', 'stream' ) );
678 -
679 824 return $links;
680 825 }
681 826
682 827 /**
@@ -685,12 +830,12 @@
685 830 public function render_list_table() {
686 831 $this->list_table->prepare_items();
687 832 ?>
688 833 <div class="wrap">
689 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
690 - <?php $this->list_table->display() ?>
834 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
835 + <?php $this->list_table->display(); ?>
691 836 </div>
692 - <?php
837 + <?php
693 838 }
694 839
695 840 /**
696 841 * Render settings page
@@ -702,28 +847,28 @@
702 847 $page_description = apply_filters( 'wp_stream_settings_form_description', '' );
703 848
704 849 $sections = $this->plugin->settings->get_fields();
705 850 $active_tab = wp_stream_filter_input( INPUT_GET, 'tab' );
706 -
707 - wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.js', array( 'jquery' ), $this->plugin->get_version(), true );
851 + $min = wp_stream_min_suffix();
852 + wp_enqueue_script( 'wp-stream-settings', $this->plugin->locations['url'] . 'ui/js/settings.' . $min . 'js', array( 'jquery' ), $this->plugin->get_version(), true );
708 853 ?>
709 854 <div class="wrap">
710 - <h1><?php echo esc_html( get_admin_page_title() ) ?></h1>
855 + <h1><?php echo esc_html( get_admin_page_title() ); ?></h1>
711 856
712 857 <?php if ( ! empty( $page_description ) ) : ?>
713 - <p><?php echo esc_html( $page_description ) ?></p>
858 + <p><?php echo esc_html( $page_description ); ?></p>
714 859 <?php endif; ?>
715 860
716 - <?php settings_errors() ?>
861 + <?php settings_errors(); ?>
717 862
718 863 <?php if ( count( $sections ) > 1 ) : ?>
719 864 <h2 class="nav-tab-wrapper">
720 - <?php $i = 0 ?>
865 + <?php $i = 0; ?>
721 866 <?php foreach ( $sections as $section => $data ) : ?>
722 - <?php $i ++ ?>
723 - <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ) ?>
724 - <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ) ?>" class="nav-tab<?php if ( $is_active ) { echo esc_attr( ' nav-tab-active' ); } ?>">
725 - <?php echo esc_html( $data['title'] ) ?>
867 + <?php ++$i; ?>
868 + <?php $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section ); ?>
869 + <a href="<?php echo esc_url( add_query_arg( 'tab', $section ) ); ?>" class="nav-tab <?php echo $is_active ? esc_attr( ' nav-tab-active' ) : ''; ?>">
870 + <?php echo esc_html( $data['title'] ); ?>
726 871 </a>
727 872 <?php endforeach; ?>
728 873 </h2>
729 874 <?php endif; ?>
@@ -728,29 +873,29 @@
728 873 </h2>
729 874 <?php endif; ?>
730 875
731 876 <div class="nav-tab-content" id="tab-content-settings">
732 - <form method="post" action="<?php echo esc_attr( $form_action ) ?>" enctype="multipart/form-data">
877 + <form method="post" action="<?php echo esc_attr( $form_action ); ?>" enctype="multipart/form-data">
733 878 <div class="settings-sections">
734 - <?php
735 - $i = 0;
736 - foreach ( $sections as $section => $data ) {
737 - $i++;
879 + <?php
880 + $i = 0;
881 + foreach ( $sections as $section => $data ) {
882 + ++$i;
738 883
739 - $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
884 + $is_active = ( ( 1 === $i && ! $active_tab ) || $active_tab === $section );
740 885
741 - if ( $is_active ) {
742 - settings_fields( $option_key );
743 - do_settings_sections( $option_key );
744 - }
745 - }
746 - ?>
886 + if ( $is_active ) {
887 + settings_fields( $option_key );
888 + do_settings_sections( $option_key );
889 + }
890 + }
891 + ?>
747 892 </div>
748 - <?php submit_button() ?>
893 + <?php submit_button(); ?>
749 894 </form>
750 895 </div>
751 896 </div>
752 - <?php
897 + <?php
753 898 }
754 899
755 900 /**
756 901 * Instantiate the list table
@@ -755,15 +900,20 @@
755 900 /**
756 901 * Instantiate the list table
757 902 */
758 903 public function register_list_table() {
759 - $this->list_table = new List_Table( $this->plugin, array( 'screen' => $this->screen_id['main'] ) );
904 + $this->list_table = new List_Table(
905 + $this->plugin,
906 + array(
907 + 'screen' => $this->screen_id['main'],
908 + )
909 + );
760 910 }
761 911
762 912 /**
763 913 * Check if a particular role has access
764 914 *
765 - * @param string $role
915 + * @param string $role User role.
766 916 *
767 917 * @return bool
768 918 */
769 919 private function role_can_view( $role ) {
@@ -776,12 +926,12 @@
776 926
777 927 /**
778 928 * Filter user caps to dynamically grant our view cap based on allowed roles
779 929 *
780 - * @param $allcaps
781 - * @param $caps
782 - * @param $args
783 - * @param $user
930 + * @param array $allcaps All capabilities.
931 + * @param array $caps Required caps.
932 + * @param array $args Unused.
933 + * @param WP_User $user User.
784 934 *
785 935 * @filter user_has_cap
786 936 *
787 937 * @return array
@@ -826,11 +976,11 @@
826 976 * Filter role caps to dynamically grant our view cap based on allowed roles
827 977 *
828 978 * @filter role_has_cap
829 979 *
830 - * @param $allcaps
831 - * @param $cap
832 - * @param $role
980 + * @param array $allcaps All capabilities.
981 + * @param string $cap Require cap.
982 + * @param string $role User role.
833 983 *
834 984 * @return array
835 985 */
836 986 public function filter_role_caps( $allcaps, $cap, $role ) {
@@ -843,8 +993,10 @@
843 993 return $allcaps;
844 994 }
845 995
846 996 /**
997 + * Ajax callback for return a user list.
998 + *
847 999 * @action wp_ajax_wp_stream_filters
848 1000 */
849 1001 public function ajax_filters() {
850 1002 if ( ! defined( 'DOING_AJAX' ) || ! current_user_can( $this->plugin->admin->settings_cap ) ) {
@@ -855,9 +1007,13 @@
855 1007
856 1008 switch ( wp_stream_filter_input( INPUT_GET, 'filter' ) ) {
857 1009 case 'user_id':
858 1010 $users = array_merge(
859 - array( 0 => (object) array( 'display_name' => 'WP-CLI' ) ),
1011 + array(
1012 + 0 => (object) array(
1013 + 'display_name' => 'WP-CLI',
1014 + ),
1015 + ),
860 1016 get_users()
861 1017 );
862 1018
863 1019 $search = wp_stream_filter_input( INPUT_GET, 'q' );
@@ -864,9 +1020,9 @@
864 1020 if ( $search ) {
865 1021 // `search` arg for get_users() is not enough
866 1022 $users = array_filter(
867 1023 $users,
868 - function( $user ) use ( $search ) {
1024 + function ( $user ) use ( $search ) {
869 1025 return false !== mb_strpos( mb_strtolower( $user->display_name ), mb_strtolower( $search ) );
870 1026 }
871 1027 );
872 1028 }
@@ -874,9 +1030,9 @@
874 1030 if ( count( $users ) > $this->preload_users_max ) {
875 1031 $users = array_slice( $users, 0, $this->preload_users_max );
876 1032 }
877 1033
878 - // Get gravatar / roles for final result set
1034 + // Get gravatar / roles for final result set.
879 1035 $results = $this->get_users_record_meta( $users );
880 1036
881 1037 break;
882 1038 }
@@ -881,14 +1037,20 @@
881 1037 break;
882 1038 }
883 1039
884 1040 if ( isset( $results ) ) {
885 - echo wp_stream_json_encode( $results ); // xss ok
1041 + echo wp_json_encode( $results );
886 1042 }
887 1043
888 1044 die();
889 1045 }
890 1046
1047 + /**
1048 + * Return relevant user meta data.
1049 + *
1050 + * @param array $authors Author data.
1051 + * @return array
1052 + */
891 1053 public function get_users_record_meta( $authors ) {
892 1054 $authors_records = array();
893 1055
894 1056 foreach ( $authors as $user_id => $args ) {
@@ -894,13 +1056,13 @@
894 1056 foreach ( $authors as $user_id => $args ) {
895 1057 $author = new Author( $args->ID );
896 1058
897 1059 $authors_records[ $user_id ] = array(
898 - 'text' => $author->get_display_name(),
899 - 'id' => $author->id,
900 - 'label' => $author->get_display_name(),
901 - 'icon' => $author->get_avatar_src( 32 ),
902 - 'title' => '',
1060 + 'text' => $author->get_display_name(),
1061 + 'id' => $author->id,
1062 + 'label' => $author->get_display_name(),
1063 + 'icon' => $author->get_avatar_src( 32 ),
1064 + 'title' => '',
903 1065 );
904 1066 }
905 1067
906 1068 return $authors_records;
@@ -908,18 +1070,15 @@
908 1070
909 1071 /**
910 1072 * Get user meta in a way that is also safe for VIP
911 1073 *
912 - * @param int $user_id
913 - * @param string $meta_key
914 - * @param bool $single (optional)
1074 + * @param int $user_id User ID.
1075 + * @param string $meta_key Meta key.
1076 + * @param bool $single Return first found meta value connected to the meta key (optional).
915 1077 *
916 1078 * @return mixed
917 1079 */
918 - function get_user_meta( $user_id, $meta_key, $single = true ) {
919 - if ( wp_stream_is_vip() && function_exists( 'get_user_attribute' ) ) {
920 - return get_user_attribute( $user_id, $meta_key );
921 - }
1080 + public function get_user_meta( $user_id, $meta_key, $single = true ) {
922 1081 return get_user_meta( $user_id, $meta_key, $single );
923 1082 }
924 1083
925 1084 /**
@@ -924,19 +1083,16 @@
924 1083
925 1084 /**
926 1085 * Update user meta in a way that is also safe for VIP
927 1086 *
928 - * @param int $user_id
929 - * @param string $meta_key
930 - * @param mixed $meta_value
931 - * @param mixed $prev_value (optional)
1087 + * @param int $user_id User ID.
1088 + * @param string $meta_key Meta key.
1089 + * @param mixed $meta_value Meta value.
1090 + * @param mixed $prev_value Previous meta value being overwritten (optional).
932 1091 *
933 1092 * @return int|bool
934 1093 */
935 - function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
936 - if ( wp_stream_is_vip() && function_exists( 'update_user_attribute' ) ) {
937 - return update_user_attribute( $user_id, $meta_key, $meta_value );
938 - }
1094 + public function update_user_meta( $user_id, $meta_key, $meta_value, $prev_value = '' ) {
939 1095 return update_user_meta( $user_id, $meta_key, $meta_value, $prev_value );
940 1096 }
941 1097
942 1098 /**
@@ -941,17 +1097,14 @@
941 1097
942 1098 /**
943 1099 * Delete user meta in a way that is also safe for VIP
944 1100 *
945 - * @param int $user_id
946 - * @param string $meta_key
947 - * @param mixed $meta_value (optional)
1101 + * @param int $user_id User ID.
1102 + * @param string $meta_key Meta key.
1103 + * @param mixed $meta_value Meta value (optional).
948 1104 *
949 1105 * @return bool
950 1106 */
951 - function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
952 - if ( wp_stream_is_vip() && function_exists( 'delete_user_attribute' ) ) {
953 - return delete_user_attribute( $user_id, $meta_key, $meta_value );
954 - }
1107 + public function delete_user_meta( $user_id, $meta_key, $meta_value = '' ) {
955 1108 return delete_user_meta( $user_id, $meta_key, $meta_value );
956 1109 }
957 1110 }