| @@ -5,61 +5,27 @@ | ||
| 5 | 5 | defined('ABSPATH') || exit; |
| 6 | 6 | |
| 7 | 7 | class TicketExtraInfoFormatter |
| 8 | 8 | { |
| 9 | - public static function appendFromRequest(string $content, array $request): string | |
| 9 | + public static function sanitizeContent($value): string | |
| 10 | 10 | { |
| 11 | - $dashboardLines = self::collectDashboardLines($request); | |
| 12 | - $hostPanelLines = self::collectHostPanelLines($request); | |
| 11 | + $value = wp_check_invalid_utf8(wp_unslash((string) $value)); | |
| 13 | 12 | |
| 14 | - if (empty($dashboardLines) && empty($hostPanelLines)) { | |
| 15 | - return trim($content); | |
| 13 | + if (strpos($value, '<') !== false) { | |
| 14 | + $value = wp_pre_kses_less_than($value); | |
| 15 | + $value = wp_strip_all_tags($value, false); | |
| 16 | + $value = str_replace("<\n", "<\n", $value); | |
| 16 | 17 | } |
| 17 | 18 | |
| 18 | - $sections = [trim($content)]; | |
| 19 | + $value = str_replace(["\r\n", "\r"], "\n", $value); | |
| 20 | + $value = preg_replace('/[\x00-\x08\x0B\x0C\x0E-\x1F\x7F]/', '', $value); | |
| 19 | 21 | |
| 20 | - if (!empty($dashboardLines)) { | |
| 21 | - $sections[] = "اطلاعات پیشخوان:\n" . implode("\n", $dashboardLines); | |
| 22 | - } | |
| 23 | - | |
| 24 | - if (!empty($hostPanelLines)) { | |
| 25 | - $sections[] = "کنترل پنل هاست:\n" . implode("\n", $hostPanelLines); | |
| 26 | - } | |
| 27 | - | |
| 28 | - return trim(implode("\n\n", array_filter($sections))); | |
| 22 | + return trim($value); | |
| 29 | 23 | } |
| 30 | 24 | |
| 31 | - private static function collectDashboardLines(array $request): array | |
| 25 | + public static function appendFromRequest(string $content, array $request): string | |
| 32 | 26 | { |
| 33 | - $lines = []; | |
| 34 | - | |
| 35 | - $dashboardLoginUrl = self::sanitize($request['dashboard_login_url'] ?? ''); | |
| 36 | - $dashboardUsername = self::sanitize($request['dashboard_username'] ?? ''); | |
| 37 | - $dashboardPassword = self::sanitize($request['dashboard_password'] ?? ''); | |
| 38 | - | |
| 39 | - if ($dashboardLoginUrl !== '') $lines[] = 'آدرس لاگین پیشخوان: ' . $dashboardLoginUrl; | |
| 40 | - if ($dashboardUsername !== '') $lines[] = 'نام کاربری پیشخوان: ' . $dashboardUsername; | |
| 41 | - if ($dashboardPassword !== '') $lines[] = 'رمز عبور پیشخوان: ' . $dashboardPassword; | |
| 42 | - | |
| 43 | - return $lines; | |
| 44 | - } | |
| 45 | - | |
| 46 | - private static function collectHostPanelLines(array $request): array | |
| 47 | - { | |
| 48 | - $lines = []; | |
| 49 | - | |
| 50 | - $hostPanelLoginUrl = self::sanitize($request['host_panel_login_url'] ?? ''); | |
| 51 | - $hostPanelUsername = self::sanitize($request['host_panel_username'] ?? ''); | |
| 52 | - $hostPanelPassword = self::sanitize($request['host_panel_password'] ?? ''); | |
| 53 | - | |
| 54 | - if ($hostPanelLoginUrl !== '') $lines[] = 'آدرس لاگین کنترل پنل هاست: ' . $hostPanelLoginUrl; | |
| 55 | - if ($hostPanelUsername !== '') $lines[] = 'نام کاربری کنترل پنل هاست: ' . $hostPanelUsername; | |
| 56 | - if ($hostPanelPassword !== '') $lines[] = 'رمز عبور کنترل پنل هاست: ' . $hostPanelPassword; | |
| 57 | - | |
| 58 | - return $lines; | |
| 59 | - } | |
| 60 | - | |
| 61 | - private static function sanitize($value): string | |
| 62 | - { | |
| 63 | - return sanitize_text_field(wp_unslash((string) $value)); | |
| 27 | + // Kept as a compatibility shim for third-party callers. Access data is | |
| 28 | + // intentionally ignored and must be sent with TicketAccessData instead. | |
| 29 | + return trim($content); | |
| 64 | 30 | } |
| 65 | 31 | } |