| @@ -5,59 +5,8 @@ | ||
| 5 | 5 | * @package Automateplug |
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | 8 | /** |
| 9 | - * Safely unserialize a value, blocking PHP object instantiation. | |
| 10 | - * | |
| 11 | - * Drop-in replacement for unserialize() / maybe_unserialize() on any data | |
| 12 | - * that originates from user input or external storage. Uses is_serialized() | |
| 13 | - * to detect serialized strings without calling unserialize(), then deserializes | |
| 14 | - * with allowed_classes => false so no PHP objects are ever instantiated. | |
| 15 | - * | |
| 16 | - * @param mixed $data Value to unserialize. | |
| 17 | - * @return mixed Unserialized value, or original value if not serialized. | |
| 18 | - */ | |
| 19 | -function st_safe_unserialize( $data ) { | |
| 20 | - if ( ! is_string( $data ) || ! is_serialized( $data ) ) { | |
| 21 | - return $data; | |
| 22 | - } | |
| 23 | - // phpcs:ignore PHPCompatibility.FunctionUse.NewFunctionParameters.unserialize_optionsFound -- allowed_classes requires PHP 7.0+; WP minimum is 7.2+ | |
| 24 | - return unserialize( $data, [ 'allowed_classes' => false ] ); | |
| 25 | -} | |
| 26 | - | |
| 27 | -/** | |
| 28 | - * Check whether an automation is allowed to assign the given role to a user. | |
| 29 | - * | |
| 30 | - * Role-assignment actions (WordPress "Change Role"/"Add New Role", Ultimate | |
| 31 | - * Member equivalents, user-creation actions, etc.) take the role as a plain | |
| 32 | - * string from the automation's `selected_options`. That value can originate | |
| 33 | - * from a hard-coded dropdown choice, but it can just as easily come from a | |
| 34 | - * mapped field fed by an incoming webhook, form submission, or raw REST | |
| 35 | - * request body — there is no reliable way at execution time to tell those | |
| 36 | - * apart. `administrator` is therefore blocked by default so no automation | |
| 37 | - * can be used, intentionally or via a spoofed payload, to escalate a user to | |
| 38 | - * Administrator. Site owners who deliberately need an automation to grant | |
| 39 | - * Administrator can restore that via the `suretriggers_blocked_user_roles` | |
| 40 | - * filter. | |
| 41 | - * | |
| 42 | - * @param string $role Role slug requested by the automation. | |
| 43 | - * @return bool True if the role may be assigned, false if it is blocked. | |
| 44 | - */ | |
| 45 | -function st_is_assignable_user_role( $role ) { | |
| 46 | - if ( ! is_string( $role ) || '' === $role ) { | |
| 47 | - return false; | |
| 48 | - } | |
| 49 | - | |
| 50 | - $blocked_roles = apply_filters( 'suretriggers_blocked_user_roles', [ 'administrator' ] ); | |
| 51 | - | |
| 52 | - if ( ! is_array( $blocked_roles ) ) { | |
| 53 | - $blocked_roles = [ 'administrator' ]; | |
| 54 | - } | |
| 55 | - | |
| 56 | - return ! in_array( strtolower( $role ), array_map( 'strtolower', $blocked_roles ), true ); | |
| 57 | -} | |
| 58 | - | |
| 59 | -/** | |
| 60 | 9 | * Get or prepare user id. |
| 61 | 10 | * |
| 62 | 11 | * @return int |
| 63 | 12 | */ |
| @@ -129,114 +78,8 @@ | ||
| 129 | 78 | if ( ! property_exists( $user, 'ID' ) ) { |
| 130 | 79 | return; |
| 131 | 80 | } |
| 132 | 81 | update_user_meta( $user->ID, 'st_last_login', time() ); |
| 133 | -} | |
| 134 | - | |
| 135 | -/** | |
| 136 | - * Add 5-star rating display to plugin row. | |
| 137 | - */ | |
| 138 | -add_filter( 'plugin_row_meta', 'suretriggers_add_plugin_rating', 10, 2 ); | |
| 139 | - | |
| 140 | -/** | |
| 141 | - * Add 5-star rating to plugin meta row. | |
| 142 | - * | |
| 143 | - * @param array $links An array of the plugin's metadata. | |
| 144 | - * @param string $file Path to the plugin file relative to the plugins directory. | |
| 145 | - * @return array Modified array of plugin metadata. | |
| 146 | - */ | |
| 147 | -function suretriggers_add_plugin_rating( $links, $file ) { | |
| 148 | - if ( plugin_basename( SURE_TRIGGERS_FILE ) === $file ) { | |
| 149 | - // Check if user has already clicked the rating (stored in user meta). | |
| 150 | - $user_id = get_current_user_id(); | |
| 151 | - $rating_clicked = get_user_meta( $user_id, 'suretriggers_rating_clicked', true ); | |
| 152 | - | |
| 153 | - // If rating has been clicked, don't show it. | |
| 154 | - if ( $rating_clicked ) { | |
| 155 | - return $links; | |
| 156 | - } | |
| 157 | - | |
| 158 | - $rating_html = '<span class="suretriggers-rating-wrapper" id="suretriggers-rating-wrapper">'; | |
| 159 | - $rating_html .= '<a href="https://wordpress.org/support/plugin/suretriggers/reviews/" target="_blank" class="suretriggers-rating-link" title="Rate this plugin" aria-label="Rate SureTriggers 5 stars on WordPress.org">'; | |
| 160 | - $rating_html .= '<span class="star-rating" role="img" aria-label="5 out of 5 stars">'; | |
| 161 | - for ( $i = 1; $i <= 5; $i++ ) { | |
| 162 | - $rating_html .= '<span class="star star-full" aria-hidden="true"></span>'; | |
| 163 | - } | |
| 164 | - $rating_html .= '</span>'; | |
| 165 | - $rating_html .= '<span class="screen-reader-text">Rate this plugin</span>'; | |
| 166 | - $rating_html .= '</a>'; | |
| 167 | - $rating_html .= '</span>'; | |
| 168 | - $links[] = $rating_html; | |
| 169 | - } | |
| 170 | - return $links; | |
| 171 | -} | |
| 172 | - | |
| 173 | -/** | |
| 174 | - * Enqueue rating styles for plugin meta row. | |
| 175 | - */ | |
| 176 | -add_action( 'admin_enqueue_scripts', 'suretriggers_enqueue_rating_styles' ); | |
| 177 | - | |
| 178 | -/** | |
| 179 | - * Enqueue CSS styles for 5-star rating display. | |
| 180 | - * Following modular CSS organization best practices. | |
| 181 | - * | |
| 182 | - * @return void | |
| 183 | - */ | |
| 184 | -function suretriggers_enqueue_rating_styles() { | |
| 185 | - // Only enqueue on plugins page where rating is displayed. | |
| 186 | - $screen = get_current_screen(); | |
| 187 | - if ( $screen && 'plugins' === $screen->id ) { | |
| 188 | - wp_enqueue_style( | |
| 189 | - 'suretriggers-rating', | |
| 190 | - plugin_dir_url( SURE_TRIGGERS_FILE ) . 'assets/css/st-rating.css', | |
| 191 | - [], | |
| 192 | - defined( 'SURE_TRIGGERS_VER' ) ? SURE_TRIGGERS_VER : '1.0.0' | |
| 193 | - ); | |
| 194 | - | |
| 195 | - wp_enqueue_script( | |
| 196 | - 'suretriggers-rating-js', | |
| 197 | - plugin_dir_url( SURE_TRIGGERS_FILE ) . 'assets/js/st-rating.js', | |
| 198 | - [ 'jquery' ], | |
| 199 | - defined( 'SURE_TRIGGERS_VER' ) ? SURE_TRIGGERS_VER : '1.0.0', | |
| 200 | - true | |
| 201 | - ); | |
| 202 | - | |
| 203 | - // Localize script with AJAX URL and nonce. | |
| 204 | - wp_localize_script( | |
| 205 | - 'suretriggers-rating-js', | |
| 206 | - 'suretriggers_rating_ajax', | |
| 207 | - [ | |
| 208 | - 'ajax_url' => admin_url( 'admin-ajax.php' ), | |
| 209 | - 'nonce' => wp_create_nonce( 'suretriggers_rating_nonce' ), | |
| 210 | - ] | |
| 211 | - ); | |
| 212 | - } | |
| 213 | -} | |
| 214 | - | |
| 215 | -/** | |
| 216 | - * Handle AJAX request to mark rating as clicked. | |
| 217 | - */ | |
| 218 | -add_action( 'wp_ajax_suretriggers_rating_clicked', 'suretriggers_handle_rating_clicked' ); | |
| 219 | - | |
| 220 | -/** | |
| 221 | - * Mark rating as clicked for current user. | |
| 222 | - * | |
| 223 | - * @return void | |
| 224 | - */ | |
| 225 | -function suretriggers_handle_rating_clicked() { | |
| 226 | - // Check if nonce is set and verify it. | |
| 227 | - if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'suretriggers_rating_nonce' ) ) { | |
| 228 | - wp_die( 'Security check failed' ); | |
| 229 | - } | |
| 230 | - | |
| 231 | - // Mark rating as clicked for current user. | |
| 232 | - $user_id = get_current_user_id(); | |
| 233 | - if ( $user_id ) { | |
| 234 | - update_user_meta( $user_id, 'suretriggers_rating_clicked', true ); | |
| 235 | - wp_send_json_success( 'Rating marked as clicked' ); | |
| 236 | - } else { | |
| 237 | - wp_send_json_error( 'User not logged in' ); | |
| 238 | - } | |
| 239 | 82 | } |
| 240 | 83 | |
| 241 | 84 | /** |
| 242 | 85 | * SureTrigger Trigger Button shortcode. |