PluginProbe
ووسلام – همگام سازی ووکامرس و باسلام / 1.10.19
ووسلام – همگام سازی ووکامرس و باسلام v1.10.19
1.10.19 1.10.20 1.10.18 1.10.17 1.10.15 1.10.14 1.10.13 1.10.12 1.10.10 1.10.9 1.10.8 1.10.7 1.10.6 1.10.5 1.10.4 1.10.3 1.10.2 1.10.1 1.10.0 1.9.2 1.9.1 1.9.0 1.8.8 1.8.5 1.8.6 All 53 releases
← All changes | includes/Utilities/TicketExtraInfoFormatter.php +13 -47 1.10.21.10.19 View file →
@@ -5,61 +5,27 @@
5 5 defined('ABSPATH') || exit;
6 6
7 7 class TicketExtraInfoFormatter
8 8 {
9 - public static function appendFromRequest(string $content, array $request): string
9 + public static function sanitizeContent($value): string
10 10 {
11 - $dashboardLines = self::collectDashboardLines($request);
12 - $hostPanelLines = self::collectHostPanelLines($request);
11 + $value = wp_check_invalid_utf8(wp_unslash((string) $value));
13 12
14 - if (empty($dashboardLines) && empty($hostPanelLines)) {
15 - return trim($content);
13 + if (strpos($value, '<') !== false) {
14 + $value = wp_pre_kses_less_than($value);
15 + $value = wp_strip_all_tags($value, false);
16 + $value = str_replace("<\n", "&lt;\n", $value);
16 17 }
17 18
18 - $sections = [trim($content)];
19 + $value = str_replace(["\r\n", "\r"], "\n", $value);
20 + $value = preg_replace('/[\x00-\x08\x0B\x0C\x0E-\x1F\x7F]/', '', $value);
19 21
20 - if (!empty($dashboardLines)) {
21 - $sections[] = "اطلاعات پیشخوان:\n" . implode("\n", $dashboardLines);
22 - }
23 -
24 - if (!empty($hostPanelLines)) {
25 - $sections[] = "کنترل پنل هاست:\n" . implode("\n", $hostPanelLines);
26 - }
27 -
28 - return trim(implode("\n\n", array_filter($sections)));
22 + return trim($value);
29 23 }
30 24
31 - private static function collectDashboardLines(array $request): array
25 + public static function appendFromRequest(string $content, array $request): string
32 26 {
33 - $lines = [];
34 -
35 - $dashboardLoginUrl = self::sanitize($request['dashboard_login_url'] ?? '');
36 - $dashboardUsername = self::sanitize($request['dashboard_username'] ?? '');
37 - $dashboardPassword = self::sanitize($request['dashboard_password'] ?? '');
38 -
39 - if ($dashboardLoginUrl !== '') $lines[] = 'آدرس لاگین پیشخوان: ' . $dashboardLoginUrl;
40 - if ($dashboardUsername !== '') $lines[] = 'نام کاربری پیشخوان: ' . $dashboardUsername;
41 - if ($dashboardPassword !== '') $lines[] = 'رمز عبور پیشخوان: ' . $dashboardPassword;
42 -
43 - return $lines;
44 - }
45 -
46 - private static function collectHostPanelLines(array $request): array
47 - {
48 - $lines = [];
49 -
50 - $hostPanelLoginUrl = self::sanitize($request['host_panel_login_url'] ?? '');
51 - $hostPanelUsername = self::sanitize($request['host_panel_username'] ?? '');
52 - $hostPanelPassword = self::sanitize($request['host_panel_password'] ?? '');
53 -
54 - if ($hostPanelLoginUrl !== '') $lines[] = 'آدرس لاگین کنترل پنل هاست: ' . $hostPanelLoginUrl;
55 - if ($hostPanelUsername !== '') $lines[] = 'نام کاربری کنترل پنل هاست: ' . $hostPanelUsername;
56 - if ($hostPanelPassword !== '') $lines[] = 'رمز عبور کنترل پنل هاست: ' . $hostPanelPassword;
57 -
58 - return $lines;
59 - }
60 -
61 - private static function sanitize($value): string
62 - {
63 - return sanitize_text_field(wp_unslash((string) $value));
27 + // Kept as a compatibility shim for third-party callers. Access data is
28 + // intentionally ignored and must be sent with TicketAccessData instead.
29 + return trim($content);
64 30 }
65 31 }