| @@ -10,13 +10,20 @@ | ||
| 10 | 10 | defined('ABSPATH') || exit; |
| 11 | 11 | |
| 12 | 12 | class SettingsPageHandler |
| 13 | 13 | { |
| 14 | + private const VALIDATION_ERROR_TRANSIENT_PREFIX = 'sync_basalam_settings_validation_error_'; | |
| 15 | + | |
| 14 | 16 | public static function saveSettings() |
| 15 | 17 | { |
| 16 | 18 | $data = isset($_POST['sync_basalam_settings']) ? array_map('sanitize_text_field', wp_unslash($_POST['sync_basalam_settings'])) : []; |
| 17 | 19 | |
| 18 | 20 | if ($data) { |
| 21 | + if (!SettingsManager::isProductUpdateSelectionValid($data)) { | |
| 22 | + self::pushValidationError(SettingsConfig::CUSTOM_PRODUCT_UPDATE_REQUIRED_MESSAGE); | |
| 23 | + return false; | |
| 24 | + } | |
| 25 | + | |
| 19 | 26 | SettingsManager::updateSettings($data); |
| 20 | 27 | |
| 21 | 28 | if (!empty($data[SettingsConfig::DEVELOPER_MODE]) && $data[SettingsConfig::DEVELOPER_MODE] === 'true') { |
| 22 | 29 | $debugTask = new Debug(); |
| @@ -28,16 +35,47 @@ | ||
| 28 | 35 | |
| 29 | 36 | if (isset($_POST['get_token']) && $_POST['get_token'] == 1) { |
| 30 | 37 | self::redirectToOAuth(); |
| 31 | 38 | } |
| 39 | + | |
| 40 | + return true; | |
| 32 | 41 | } |
| 33 | 42 | |
| 43 | + public static function pullValidationError(): string | |
| 44 | + { | |
| 45 | + $userId = get_current_user_id(); | |
| 46 | + if ($userId <= 0) return ''; | |
| 47 | + | |
| 48 | + $key = self::VALIDATION_ERROR_TRANSIENT_PREFIX . $userId; | |
| 49 | + $message = get_transient($key); | |
| 50 | + delete_transient($key); | |
| 51 | + | |
| 52 | + return is_string($message) ? $message : ''; | |
| 53 | + } | |
| 54 | + | |
| 55 | + private static function pushValidationError(string $message): void | |
| 56 | + { | |
| 57 | + $userId = get_current_user_id(); | |
| 58 | + if ($userId <= 0) return; | |
| 59 | + | |
| 60 | + set_transient( | |
| 61 | + self::VALIDATION_ERROR_TRANSIENT_PREFIX . $userId, | |
| 62 | + wp_strip_all_tags($message), | |
| 63 | + 2 * MINUTE_IN_SECONDS | |
| 64 | + ); | |
| 65 | + } | |
| 66 | + | |
| 34 | 67 | private static function redirectToOAuth() |
| 35 | 68 | { |
| 36 | 69 | $OAuthManger = new OAuthManager(); |
| 37 | 70 | $oauthUrls = $OAuthManger->getOAuthUrls(); |
| 38 | 71 | |
| 39 | - wp_redirect($oauthUrls['url_req_token']); | |
| 72 | + // Mark this authorization as started by the current (authenticated) admin | |
| 73 | + // so the OAuth callback can reject forged requests. This runs only after | |
| 74 | + // the nonce-protected settings POST, so it cannot be triggered cross-site. | |
| 75 | + OAuthManager::issueOauthState(); | |
| 76 | + | |
| 77 | + wp_redirect($oauthUrls['url_req_token']); // phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect -- Intentional external/user-provided redirect. | |
| 40 | 78 | exit(); |
| 41 | 79 | } |
| 42 | 80 | |
| 43 | 81 | public static function handleOauthCallback() |
| @@ -53,11 +91,11 @@ | ||
| 53 | 91 | |
| 54 | 92 | $onboardingCompleted = get_option('sync_basalam_onboarding_completed'); |
| 55 | 93 | |
| 56 | 94 | if (!$onboardingCompleted) { |
| 57 | - wp_redirect(admin_url('admin.php?page=basalam-onboarding&step=3')); | |
| 95 | + wp_safe_redirect(admin_url('admin.php?page=basalam-onboarding&step=3')); | |
| 58 | 96 | } else { |
| 59 | - wp_redirect(admin_url('admin.php?page=sync_basalam')); | |
| 97 | + wp_safe_redirect(admin_url('admin.php?page=sync_basalam')); | |
| 60 | 98 | } |
| 61 | 99 | exit(); |
| 62 | 100 | } |
| 63 | 101 | } |