PluginProbe
OttoKit: All-in-One Automation Platform / 1.1.6
OttoKit: All-in-One Automation Platform v1.1.6
1.1.38 1.1.37 1.1.36 1.1.35 1.1.34 1.1.33 1.1.32 1.1.31 1.1.30 1.1.29 1.1.28 1.1.27 1.1.9 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 All 124 releases
← All changes | functions.php +0 -157 trunk1.1.6 View file →
@@ -5,59 +5,8 @@
5 5 * @package Automateplug
6 6 */
7 7
8 8 /**
9 - * Safely unserialize a value, blocking PHP object instantiation.
10 - *
11 - * Drop-in replacement for unserialize() / maybe_unserialize() on any data
12 - * that originates from user input or external storage. Uses is_serialized()
13 - * to detect serialized strings without calling unserialize(), then deserializes
14 - * with allowed_classes => false so no PHP objects are ever instantiated.
15 - *
16 - * @param mixed $data Value to unserialize.
17 - * @return mixed Unserialized value, or original value if not serialized.
18 - */
19 -function st_safe_unserialize( $data ) {
20 - if ( ! is_string( $data ) || ! is_serialized( $data ) ) {
21 - return $data;
22 - }
23 - // phpcs:ignore PHPCompatibility.FunctionUse.NewFunctionParameters.unserialize_optionsFound -- allowed_classes requires PHP 7.0+; WP minimum is 7.2+
24 - return unserialize( $data, [ 'allowed_classes' => false ] );
25 -}
26 -
27 -/**
28 - * Check whether an automation is allowed to assign the given role to a user.
29 - *
30 - * Role-assignment actions (WordPress "Change Role"/"Add New Role", Ultimate
31 - * Member equivalents, user-creation actions, etc.) take the role as a plain
32 - * string from the automation's `selected_options`. That value can originate
33 - * from a hard-coded dropdown choice, but it can just as easily come from a
34 - * mapped field fed by an incoming webhook, form submission, or raw REST
35 - * request body — there is no reliable way at execution time to tell those
36 - * apart. `administrator` is therefore blocked by default so no automation
37 - * can be used, intentionally or via a spoofed payload, to escalate a user to
38 - * Administrator. Site owners who deliberately need an automation to grant
39 - * Administrator can restore that via the `suretriggers_blocked_user_roles`
40 - * filter.
41 - *
42 - * @param string $role Role slug requested by the automation.
43 - * @return bool True if the role may be assigned, false if it is blocked.
44 - */
45 -function st_is_assignable_user_role( $role ) {
46 - if ( ! is_string( $role ) || '' === $role ) {
47 - return false;
48 - }
49 -
50 - $blocked_roles = apply_filters( 'suretriggers_blocked_user_roles', [ 'administrator' ] );
51 -
52 - if ( ! is_array( $blocked_roles ) ) {
53 - $blocked_roles = [ 'administrator' ];
54 - }
55 -
56 - return ! in_array( strtolower( $role ), array_map( 'strtolower', $blocked_roles ), true );
57 -}
58 -
59 -/**
60 9 * Get or prepare user id.
61 10 *
62 11 * @return int
63 12 */
@@ -129,114 +78,8 @@
129 78 if ( ! property_exists( $user, 'ID' ) ) {
130 79 return;
131 80 }
132 81 update_user_meta( $user->ID, 'st_last_login', time() );
133 -}
134 -
135 -/**
136 - * Add 5-star rating display to plugin row.
137 - */
138 -add_filter( 'plugin_row_meta', 'suretriggers_add_plugin_rating', 10, 2 );
139 -
140 -/**
141 - * Add 5-star rating to plugin meta row.
142 - *
143 - * @param array $links An array of the plugin's metadata.
144 - * @param string $file Path to the plugin file relative to the plugins directory.
145 - * @return array Modified array of plugin metadata.
146 - */
147 -function suretriggers_add_plugin_rating( $links, $file ) {
148 - if ( plugin_basename( SURE_TRIGGERS_FILE ) === $file ) {
149 - // Check if user has already clicked the rating (stored in user meta).
150 - $user_id = get_current_user_id();
151 - $rating_clicked = get_user_meta( $user_id, 'suretriggers_rating_clicked', true );
152 -
153 - // If rating has been clicked, don't show it.
154 - if ( $rating_clicked ) {
155 - return $links;
156 - }
157 -
158 - $rating_html = '<span class="suretriggers-rating-wrapper" id="suretriggers-rating-wrapper">';
159 - $rating_html .= '<a href="https://wordpress.org/support/plugin/suretriggers/reviews/" target="_blank" class="suretriggers-rating-link" title="Rate this plugin" aria-label="Rate SureTriggers 5 stars on WordPress.org">';
160 - $rating_html .= '<span class="star-rating" role="img" aria-label="5 out of 5 stars">';
161 - for ( $i = 1; $i <= 5; $i++ ) {
162 - $rating_html .= '<span class="star star-full" aria-hidden="true"></span>';
163 - }
164 - $rating_html .= '</span>';
165 - $rating_html .= '<span class="screen-reader-text">Rate this plugin</span>';
166 - $rating_html .= '</a>';
167 - $rating_html .= '</span>';
168 - $links[] = $rating_html;
169 - }
170 - return $links;
171 -}
172 -
173 -/**
174 - * Enqueue rating styles for plugin meta row.
175 - */
176 -add_action( 'admin_enqueue_scripts', 'suretriggers_enqueue_rating_styles' );
177 -
178 -/**
179 - * Enqueue CSS styles for 5-star rating display.
180 - * Following modular CSS organization best practices.
181 - *
182 - * @return void
183 - */
184 -function suretriggers_enqueue_rating_styles() {
185 - // Only enqueue on plugins page where rating is displayed.
186 - $screen = get_current_screen();
187 - if ( $screen && 'plugins' === $screen->id ) {
188 - wp_enqueue_style(
189 - 'suretriggers-rating',
190 - plugin_dir_url( SURE_TRIGGERS_FILE ) . 'assets/css/st-rating.css',
191 - [],
192 - defined( 'SURE_TRIGGERS_VER' ) ? SURE_TRIGGERS_VER : '1.0.0'
193 - );
194 -
195 - wp_enqueue_script(
196 - 'suretriggers-rating-js',
197 - plugin_dir_url( SURE_TRIGGERS_FILE ) . 'assets/js/st-rating.js',
198 - [ 'jquery' ],
199 - defined( 'SURE_TRIGGERS_VER' ) ? SURE_TRIGGERS_VER : '1.0.0',
200 - true
201 - );
202 -
203 - // Localize script with AJAX URL and nonce.
204 - wp_localize_script(
205 - 'suretriggers-rating-js',
206 - 'suretriggers_rating_ajax',
207 - [
208 - 'ajax_url' => admin_url( 'admin-ajax.php' ),
209 - 'nonce' => wp_create_nonce( 'suretriggers_rating_nonce' ),
210 - ]
211 - );
212 - }
213 -}
214 -
215 -/**
216 - * Handle AJAX request to mark rating as clicked.
217 - */
218 -add_action( 'wp_ajax_suretriggers_rating_clicked', 'suretriggers_handle_rating_clicked' );
219 -
220 -/**
221 - * Mark rating as clicked for current user.
222 - *
223 - * @return void
224 - */
225 -function suretriggers_handle_rating_clicked() {
226 - // Check if nonce is set and verify it.
227 - if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'suretriggers_rating_nonce' ) ) {
228 - wp_die( 'Security check failed' );
229 - }
230 -
231 - // Mark rating as clicked for current user.
232 - $user_id = get_current_user_id();
233 - if ( $user_id ) {
234 - update_user_meta( $user_id, 'suretriggers_rating_clicked', true );
235 - wp_send_json_success( 'Rating marked as clicked' );
236 - } else {
237 - wp_send_json_error( 'User not logged in' );
238 - }
239 82 }
240 83
241 84 /**
242 85 * SureTrigger Trigger Button shortcode.