| @@ -17,30 +17,33 @@ | ||
| 17 | 17 | } |
| 18 | 18 | |
| 19 | 19 | public function html(){ |
| 20 | 20 | |
| 21 | - $urls = stripslashes( trim( $this->options['urls'] ) ); | |
| 22 | - $tab_titles = stripslashes( $this->options['tab_titles'] ); | |
| 21 | + $urls = trim( $this->options['urls'] ); | |
| 22 | + $tab_titles = $this->options['tab_titles']; | |
| 23 | 23 | $count = intval( $this->options['count'] ); |
| 24 | 24 | |
| 25 | 25 | $show_date = intval( $this->options['show_date'] ); |
| 26 | 26 | $show_desc = intval( $this->options['show_desc'] ); |
| 27 | 27 | $show_author = intval( $this->options['show_author'] ); |
| 28 | - $show_thumb = stripslashes( $this->options['show_thumb'] ); | |
| 28 | + $show_thumb = intval( $this->options['show_thumb'] ); | |
| 29 | 29 | $open_newtab = intval( $this->options['open_newtab'] ); |
| 30 | 30 | $add_nofollow = intval( $this->options['add_nofollow'] ); |
| 31 | 31 | $strip_desc = intval( $this->options['strip_desc'] ); |
| 32 | 32 | $strip_title = intval( $this->options['strip_title'] ); |
| 33 | - $date_format = htmlspecialchars( $this->options['date_format'] ); | |
| 34 | - $order_by = htmlspecialchars( $this->options['order_by'] ); | |
| 35 | - $read_more = htmlspecialchars( $this->options['read_more'] ); | |
| 33 | + $date_format = $this->options['date_format']; | |
| 34 | + $date_timezone = $this->options['date_timezone']; | |
| 35 | + $order_by = $this->options['order_by']; | |
| 36 | + $read_more = $this->options['read_more']; | |
| 36 | 37 | $rich_desc = intval( $this->options['rich_desc'] ); |
| 37 | - $thumbnail_position = htmlspecialchars( $this->options['thumbnail_position'] ); | |
| 38 | - $thumbnail_size = htmlspecialchars( $this->options['thumbnail_size'] ); | |
| 39 | - $thumbnail_default = htmlspecialchars( $this->options['thumbnail_default'] ); | |
| 38 | + $desc_type = $this->options['desc_type']; | |
| 39 | + $thumbnail_position = $this->options['thumbnail_position']; | |
| 40 | + $thumbnail_size = $this->options['thumbnail_size']; | |
| 41 | + $thumbnail_default = $this->options['thumbnail_default']; | |
| 42 | + $no_feed_text = $this->options['no_feed_text']; | |
| 40 | 43 | |
| 41 | - $color_theme = stripslashes( $this->options['color_style'] ); | |
| 42 | - $display_type = stripslashes( $this->options['display_type'] ); | |
| 44 | + $color_theme = $this->options['color_style']; | |
| 45 | + $display_type = $this->options['display_type']; | |
| 43 | 46 | $visible_items = intval( $this->options['visible_items'] ); |
| 44 | 47 | $ticker_speed = intval( $this->options['ticker_speed'] ) * 1000; |
| 45 | 48 | |
| 46 | 49 | if( empty( $urls ) ){ |
| @@ -55,8 +58,9 @@ | ||
| 55 | 58 | $url_count = count( $urls ); |
| 56 | 59 | |
| 57 | 60 | $feeds = array(); |
| 58 | 61 | $html = ''; |
| 62 | + $no_feed_html = '<div>' . wp_kses_post( $no_feed_text ) . '</div>'; | |
| 59 | 63 | |
| 60 | 64 | $classes = array( 'srr-wrap', 'srr-style-' . $color_theme ); |
| 61 | 65 | if( $display_type == 'vertical_ticker' ) array_push( $classes, 'srr-vticker' ); |
| 62 | 66 | $class = implode( ' ', $classes ); |
| @@ -63,14 +67,20 @@ | ||
| 63 | 67 | |
| 64 | 68 | // Fetch the feed |
| 65 | 69 | for( $i=0; $i < $url_count; $i++ ){ |
| 66 | 70 | $feed_url = trim( $urls[$i] ); |
| 71 | + | |
| 72 | + // Skip if the RSS feed URL is same as the site URL | |
| 73 | + if ( in_array( untrailingslashit( $feed_url ), array( site_url(), home_url() ), true ) ) { | |
| 74 | + continue; | |
| 75 | + } | |
| 76 | + | |
| 67 | 77 | $feed = fetch_feed( $feed_url ); |
| 68 | 78 | |
| 69 | 79 | if( is_wp_error( $feed ) ){ |
| 70 | - $feed_title = 'Error'; | |
| 80 | + $feed_title = __( 'Error' ); | |
| 71 | 81 | }else{ |
| 72 | - $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : esc_attr( strip_tags( $feed->get_title() ) ); | |
| 82 | + $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : strip_tags( $feed->get_title() ); | |
| 73 | 83 | } |
| 74 | 84 | |
| 75 | 85 | $feeds[ $feed_url ] = array( |
| 76 | 86 | 'id' => rand( 100, 999 ), |
| @@ -80,17 +90,13 @@ | ||
| 80 | 90 | } |
| 81 | 91 | |
| 82 | 92 | // Generate tabs |
| 83 | 93 | if( $url_count > 1 ){ |
| 84 | - $html .= '<ul class="srr-tab-wrap srr-tab-style-' . $color_theme . ' srr-clearfix">'; | |
| 94 | + $html .= '<ul class="srr-tab-wrap srr-tab-style-' . esc_attr( $color_theme ) . ' srr-clearfix">'; | |
| 85 | 95 | foreach( $feeds as $url => $data ){ |
| 86 | 96 | $id = $data[ 'id' ]; |
| 87 | 97 | $feed = $data[ 'feed' ]; |
| 88 | - if( is_wp_error( $feed ) ){ | |
| 89 | - $html .= '<li data-tab="srr-tab-' . $id . '">Error</li>'; | |
| 90 | - }else{ | |
| 91 | - $html .= '<li data-tab="srr-tab-' . $id . '">' . $data[ 'title' ] . '</li>'; | |
| 92 | - } | |
| 98 | + $html .= '<li data-tab="srr-tab-' . esc_attr( $id ) . '">' . wp_kses_post( $data[ 'title' ] ) . '</li>'; | |
| 93 | 99 | } |
| 94 | 100 | $html .= '</ul>'; |
| 95 | 101 | } |
| 96 | 102 | |
| @@ -101,18 +107,22 @@ | ||
| 101 | 107 | $feed = $data[ 'feed' ]; |
| 102 | 108 | |
| 103 | 109 | // Check for feed errors |
| 104 | 110 | if ( is_wp_error( $feed ) ){ |
| 105 | - $html .= '<div class="srr-wrap srr-style-' . $color_theme .'" data-id="srr-tab-' . $id . '"><p>RSS Error: ' . $feed->get_error_message() . '</p></div>'; | |
| 111 | + $html .= '<div class="srr-wrap srr-style-' . esc_attr( $color_theme ) .'" data-id="srr-tab-' . esc_attr( $id ) . '"><p>RSS Error: ' . wp_kses_post( $feed->get_error_message() ) . '</p></div>'; | |
| 106 | 112 | continue; |
| 107 | 113 | } |
| 108 | 114 | |
| 109 | - if( method_exists( $feed, 'enable_order_by_date' ) && in_array( $order_by, array( 'date', 'date_reverse' ) ) ){ | |
| 110 | - $feed->enable_order_by_date( true ); | |
| 115 | + if( method_exists( $feed, 'enable_order_by_date' ) ){ | |
| 116 | + if( in_array( $order_by, array( 'date', 'date_reverse' ) ) ){ | |
| 117 | + $feed->enable_order_by_date( true ); | |
| 118 | + }else{ | |
| 119 | + $feed->enable_order_by_date( false ); | |
| 120 | + } | |
| 111 | 121 | } |
| 112 | 122 | |
| 113 | 123 | // Outer wrap start |
| 114 | - $html .= '<div class="' . $class . '" data-visible="' . $visible_items . '" data-speed="' . $ticker_speed . '" data-id="srr-tab-' . $id . '">'; | |
| 124 | + $html .= '<div class="' . esc_attr( $class ) . '" data-visible="' . esc_attr( $visible_items ) . '" data-speed="' . esc_attr( $ticker_speed ) . '" data-id="srr-tab-' . esc_attr( $id ) . '">'; | |
| 115 | 125 | $html .= '<div>'; |
| 116 | 126 | |
| 117 | 127 | $max_items = $feed->get_item_quantity(); |
| 118 | 128 | |
| @@ -117,9 +127,9 @@ | ||
| 117 | 127 | $max_items = $feed->get_item_quantity(); |
| 118 | 128 | |
| 119 | 129 | // Check feed items |
| 120 | 130 | if ( $max_items == 0 ){ |
| 121 | - $html .= '<div>' . __( 'No items', 'super-rss-reader' ) . '</div>'; | |
| 131 | + $html .= $no_feed_html; | |
| 122 | 132 | }else{ |
| 123 | 133 | |
| 124 | 134 | $feed_items = $feed->get_items(); |
| 125 | 135 | $feed_items = $this->process_items( $feed_items, $count, $order_by ); |
| @@ -130,12 +140,12 @@ | ||
| 130 | 140 | |
| 131 | 141 | // Link |
| 132 | 142 | $link = $item->get_link(); |
| 133 | 143 | while ( stristr( $link, 'http' ) != $link ){ $link = substr( $link, 1 ); } |
| 134 | - $link = esc_url( strip_tags($link) ); | |
| 144 | + $link = strip_tags($link); | |
| 135 | 145 | |
| 136 | 146 | // Title |
| 137 | - $title = esc_attr( strip_tags( $item->get_title() ) ); | |
| 147 | + $title = strip_tags( $item->get_title() ); | |
| 138 | 148 | $title_full = $title; |
| 139 | 149 | |
| 140 | 150 | if ( empty( $title ) ){ |
| 141 | 151 | $title = __( 'No Title', 'super-rss-reader' ); |
| @@ -150,12 +160,28 @@ | ||
| 150 | 160 | |
| 151 | 161 | // Add no follow attribute |
| 152 | 162 | $no_follow = $add_nofollow ? ' rel="nofollow noopener noreferrer"' : ''; |
| 153 | 163 | |
| 164 | + if( empty( $link ) ){ | |
| 165 | + $link = '#'; | |
| 166 | + $new_tab = ''; | |
| 167 | + } | |
| 168 | + | |
| 154 | 169 | // Date |
| 155 | - $date = date_i18n( $date_format, $item->get_date( 'U' ) ); | |
| 156 | - $date_full = esc_attr( $item->get_date() ); | |
| 170 | + $date = ''; | |
| 171 | + $date_full = strip_tags( $item->get_date() ); | |
| 157 | 172 | |
| 173 | + if( strtolower( $date_format ) == 'relative' ){ | |
| 174 | + $item_date = $item->get_date( 'U' ); | |
| 175 | + if( $item_date ){ | |
| 176 | + $date = human_time_diff( $item_date, current_time( 'U' ) ) . ' ' . __( 'ago' ); | |
| 177 | + }else{ | |
| 178 | + $date = __( 'Today' ); | |
| 179 | + } | |
| 180 | + }else{ | |
| 181 | + $date = SRR_Utilities::date_i18n( $date_format, $item->get_date( 'U' ), $date_timezone ); | |
| 182 | + } | |
| 183 | + | |
| 158 | 184 | // Thumbnail |
| 159 | 185 | $thumb = ''; |
| 160 | 186 | if ( $show_thumb == 1 ){ |
| 161 | 187 | $thumb_url = $this->get_thumbnail_url( $item, $thumbnail_default ); |
| @@ -168,9 +194,9 @@ | ||
| 168 | 194 | $thumb_style = ''; |
| 169 | 195 | foreach( $thumb_styles as $prop => $val ){ |
| 170 | 196 | $thumb_style .= "$prop:$val;"; |
| 171 | 197 | } |
| 172 | - $thumb = '<a href="' . $link . '" class="srr-thumb srr-thumb-' . $thumbnail_position . '" style="' . $thumb_style . '" ' . $new_tab . $no_follow . '><img src="' . $thumb_url . '" alt="' . $title_full . '" align="left" /></a>'; | |
| 198 | + $thumb = '<a href="' . esc_url( $link ) . '" class="srr-thumb srr-thumb-' . esc_attr( $thumbnail_position ) . '" style="' . esc_attr( $thumb_style ) . '" ' . $new_tab . $no_follow . '><img src="' . esc_url( $thumb_url ) . '" alt="' . esc_attr( $title_full ) . '" align="left"' . ( wp_lazy_loading_enabled( 'img', 'srr-thumbnail' ) ? ' loading="lazy"' : '' ) . ' /></a>'; | |
| 173 | 199 | } |
| 174 | 200 | } |
| 175 | 201 | |
| 176 | 202 | // Description |
| @@ -175,38 +201,39 @@ | ||
| 175 | 201 | |
| 176 | 202 | // Description |
| 177 | 203 | $desc = ''; |
| 178 | 204 | if( $show_desc ){ |
| 205 | + $desc_content = ( $desc_type == 'summary' ) ? $item->get_description() : $item->get_content(); | |
| 179 | 206 | if( $rich_desc ){ |
| 180 | - $desc = strip_tags( $item->get_description(), '<p><a><img><em><strong><font><strike><s><u><i>' ); | |
| 207 | + $desc = wp_kses_post( strip_tags( $desc_content, '<p><a><img><em><strong><font><strike><s><u><i><br>' ) ); | |
| 181 | 208 | }else{ |
| 209 | + $desc = str_replace( array( "\n", "\r" ), ' ', strip_tags( @html_entity_decode( $desc_content, ENT_QUOTES, get_option('blog_charset') ) ) ); | |
| 182 | 210 | |
| 183 | - $desc = str_replace( array( "\n", "\r" ), ' ', esc_attr( strip_tags( @html_entity_decode( $item->get_description(), ENT_QUOTES, get_option('blog_charset') ) ) ) ); | |
| 184 | - $read_more_link = ''; | |
| 185 | - | |
| 186 | 211 | if( $strip_desc != 0 ){ |
| 187 | 212 | $desc = wp_trim_words( $desc, $strip_desc ); |
| 188 | - $read_more_link = !empty( $read_more ) ? ' <a href="' . $link . '" title="' . __( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . $read_more . '</a>' : ''; | |
| 189 | - | |
| 190 | 213 | if ( '[...]' == substr( $desc, -5 ) ){ |
| 191 | 214 | $desc = substr( $desc, 0, -5 ); |
| 192 | 215 | }elseif ( '[…]' != substr( $desc, -10 ) ){ |
| 193 | 216 | $desc .= ''; |
| 194 | 217 | } |
| 218 | + } | |
| 195 | 219 | |
| 196 | - $desc = esc_html( $desc ); | |
| 220 | + $desc = trim( esc_html( $desc ) ); | |
| 221 | + if( !empty( $desc ) ){ | |
| 222 | + $read_more_link = !empty( $read_more ) ? ' <a href="' . esc_url( $link ) . '" title="' . esc_attr__( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . esc_html( $read_more ) . '</a>' : ''; | |
| 223 | + $desc = $desc . $read_more_link; | |
| 197 | 224 | } |
| 198 | 225 | |
| 199 | - $desc = $desc . $read_more_link; | |
| 200 | - | |
| 201 | 226 | } |
| 202 | 227 | } |
| 203 | 228 | |
| 204 | 229 | // Author |
| 205 | - $author = $item->get_author(); | |
| 206 | - if ( is_object( $author ) ) { | |
| 207 | - $author = $author->get_name(); | |
| 208 | - $author = esc_html( strip_tags( $author ) ); | |
| 230 | + $author = ''; | |
| 231 | + if( $show_author ){ | |
| 232 | + $author = $item->get_author(); | |
| 233 | + if ( is_object( $author ) ) { | |
| 234 | + $author = strip_tags( $author->get_name() ); | |
| 235 | + } | |
| 209 | 236 | } |
| 210 | 237 | |
| 211 | 238 | $t_title = ''; |
| 212 | 239 | $t_meta = ''; |
| @@ -212,19 +239,19 @@ | ||
| 212 | 239 | $t_meta = ''; |
| 213 | 240 | $t_thumb = ''; |
| 214 | 241 | $t_desc = ''; |
| 215 | 242 | |
| 216 | - $t_title .= '<div class="srr-title"><a href="' . $link . '"' . $new_tab . $no_follow . ' title="' . $title_full . '">' . $title . '</a></div>'; | |
| 243 | + $t_title .= '<div class="srr-title"><a href="' . esc_url( $link ) . '"' . $new_tab . $no_follow . ' title="' . esc_attr( $title_full ) . '">' . esc_html( $title ) . '</a></div>'; | |
| 217 | 244 | |
| 218 | 245 | // Metadata |
| 219 | 246 | if( $show_date || $show_author ){ |
| 220 | 247 | $t_meta .= '<div class="srr-meta">'; |
| 221 | 248 | if( $show_date && !empty( $date ) ){ |
| 222 | - $t_meta .= '<time class="srr-date" title="' . $date_full . ' UTC">' . $date . '</time>'; | |
| 249 | + $t_meta .= '<time class="srr-date" title="' . esc_attr( $date_full ) . ' UTC">' . esc_html( $date ) . '</time>'; | |
| 223 | 250 | } |
| 224 | 251 | |
| 225 | 252 | if( $show_author && !empty( $author ) ){ |
| 226 | - $t_meta .= ' - <cite class="srr-author">' . $author . '</cite>'; | |
| 253 | + $t_meta .= ' - <cite class="srr-author">' . esc_html( $author ) . '</cite>'; | |
| 227 | 254 | } |
| 228 | 255 | $t_meta .= '</div>'; // End meta |
| 229 | 256 | } |
| 230 | 257 | |
| @@ -231,9 +258,9 @@ | ||
| 231 | 258 | if ( $show_thumb ){ |
| 232 | 259 | $t_thumb .= $thumb; |
| 233 | 260 | } |
| 234 | 261 | |
| 235 | - if( $show_desc ){ | |
| 262 | + if( $show_desc && !empty( $desc ) ){ | |
| 236 | 263 | $t_desc .= '<div class="srr-summary srr-clearfix">'; |
| 237 | 264 | $t_desc .= $rich_desc ? $desc : ( '<p>' . $desc . '</p>' ); |
| 238 | 265 | $t_desc .= '</div>'; // End summary |
| 239 | 266 | } |
| @@ -264,8 +291,13 @@ | ||
| 264 | 291 | $html .= '</div>'; // End feed item |
| 265 | 292 | |
| 266 | 293 | $j++; |
| 267 | 294 | } |
| 295 | + | |
| 296 | + if( $j == 1 ){ | |
| 297 | + $html .= $no_feed_html; | |
| 298 | + } | |
| 299 | + | |
| 268 | 300 | } |
| 269 | 301 | |
| 270 | 302 | // Outer wrap end |
| 271 | 303 | $html .= '</div></div>' ; |