PluginProbe
TablePress – Tables in WordPress made easy / 2.2.2
TablePress – Tables in WordPress made easy v2.2.2
3.3.4 3.3.3 3.3.2 3.3.1 trunk 1.12 1.14 1.9.2 2.0.4 2.1.7 2.1.8 2.2 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.3 2.3.1 2.3.2 2.4 2.4.1 2.4.2 2.4.3 2.4.4 All 44 releases
tablepress / controllers / controller-frontend.php

controller-frontend.php in TablePress – Tables in WordPress made easy 2.2.2, at controllers/controller-frontend.php

1,007 lines 40.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Frontend Controller for TablePress with functionality for the frontend
4 *
5 * @package TablePress
6 * @subpackage Controllers
7 * @author Tobias Bäthge
8 * @since 1.0.0
9 */
10
11 // Prohibit direct script loading.
12 defined( 'ABSPATH' ) || die( 'No direct script access allowed!' );
13
14 /**
15 * Frontend Controller class, extends Base Controller Class
16 *
17 * @package TablePress
18 * @subpackage Controllers
19 * @author Tobias Bäthge
20 * @since 1.0.0
21 */
22 class TablePress_Frontend_Controller extends TablePress_Controller {
23
24 /**
25 * List of tables that are shown for the current request.
26 *
27 * @since 1.0.0
28 * @var array<string, array{count: int, instances: array<string, array<string, mixed>>}>
29 */
30 protected $shown_tables = array();
31
32 /**
33 * Initiate Frontend functionality.
34 *
35 * @since 1.0.0
36 */
37 public function __construct() {
38 parent::__construct();
39
40 /**
41 * Filters whether the TablePress Default CSS code shall be loaded.
42 *
43 * @since 1.0.0
44 *
45 * @param bool $use Whether the Default CSS shall be loaded. Default true.
46 */
47 if ( apply_filters( 'tablepress_use_default_css', true ) || TablePress::$model_options->get( 'use_custom_css' ) ) {
48 add_action( 'wp_enqueue_scripts', array( $this, 'enqueue_css' ) );
49 }
50
51 // Add DataTables invocation calls.
52 add_action( 'wp_print_footer_scripts', array( $this, 'add_datatables_calls' ), 11 ); // After inclusion of files.
53
54 // Register TablePress Shortcodes. Priority 20 is kept for backwards-compatibility purposes.
55 add_action( 'init', array( $this, 'init_shortcodes' ), 20 );
56
57 /**
58 * Filters whether the WordPress search shall also search TablePress tables.
59 *
60 * @since 1.0.0
61 *
62 * @param bool $search Whether the TablePress tables shall be searched. Default true.
63 */
64 if ( apply_filters( 'tablepress_wp_search_integration', true ) ) {
65 // Extend WordPress Search to also find posts/pages that have a table with the one of the search terms in title (if shown), description (if shown), or content.
66 add_filter( 'posts_search', array( $this, 'posts_search_filter' ) );
67 }
68
69 /**
70 * Load TablePress Template Tag functions.
71 */
72 TablePress::load_file( 'template-tag-functions.php', 'controllers' );
73
74 /**
75 * Register the tablepress/table block and its dependencies.
76 */
77 register_block_type(
78 TABLEPRESS_ABSPATH . 'blocks/table/',
79 array(
80 'render_callback' => array( $this, 'table_block_render_callback' ),
81 )
82 );
83 }
84
85 /**
86 * Register TablePress Shortcodes.
87 *
88 * @since 1.0.0
89 */
90 public function init_shortcodes(): void {
91 add_shortcode( TablePress::$shortcode, array( $this, 'shortcode_table' ) );
92 add_shortcode( TablePress::$shortcode_info, array( $this, 'shortcode_table_info' ) );
93 }
94
95 /**
96 * Enqueue CSS files for default CSS and "Custom CSS" (if desired).
97 *
98 * @since 1.0.0
99 */
100 public function enqueue_css(): void {
101 /** This filter is documented in controllers/controller-frontend.php */
102 $use_default_css = apply_filters( 'tablepress_use_default_css', true );
103 $custom_css = TablePress::$model_options->get( 'custom_css' );
104 $use_custom_css = ( TablePress::$model_options->get( 'use_custom_css' ) && '' !== $custom_css );
105 $use_custom_css_file = ( $use_custom_css && TablePress::$model_options->get( 'use_custom_css_file' ) );
106 /**
107 * Filters the "Custom CSS" version number that is appended to the enqueued CSS files
108 *
109 * @since 1.0.0
110 *
111 * @param int $version The "Custom CSS" version.
112 */
113 $custom_css_version = (string) apply_filters( 'tablepress_custom_css_version', TablePress::$model_options->get( 'custom_css_version' ) );
114
115 $tablepress_css = TablePress::load_class( 'TablePress_CSS', 'class-css.php', 'classes' );
116
117 // Determine Default CSS URL.
118 $rtl = ( is_rtl() ) ? '-rtl' : '';
119 $unfiltered_default_css_url = plugins_url( "css/build/default{$rtl}.css", TABLEPRESS__FILE__ );
120 /**
121 * Filters the URL from which the TablePress Default CSS file is loaded.
122 *
123 * @since 1.0.0
124 *
125 * @param string $unfiltered_default_css_url URL of the TablePress Default CSS file.
126 */
127 $default_css_url = apply_filters( 'tablepress_default_css_url', $unfiltered_default_css_url );
128
129 $use_custom_css_combined_file = ( $use_default_css && $use_custom_css_file && ! SCRIPT_DEBUG && ! is_rtl() && $unfiltered_default_css_url === $default_css_url && $tablepress_css->load_custom_css_from_file( 'combined' ) );
130
131 if ( $use_custom_css_combined_file ) {
132 $custom_css_combined_url = $tablepress_css->get_custom_css_location( 'combined', 'url' );
133 // Need to use 'tablepress-default' instead of 'tablepress-combined' to not break existing TablePress Extensions.
134 wp_enqueue_style( 'tablepress-default', $custom_css_combined_url, array(), $custom_css_version );
135 } else {
136 $custom_css_dependencies = array();
137 if ( $use_default_css ) {
138 wp_enqueue_style( 'tablepress-default', $default_css_url, array(), TablePress::version );
139 // Add dependency to make sure that Custom CSS is printed after Default CSS.
140 $custom_css_dependencies[] = 'tablepress-default';
141 }
142
143 $use_custom_css_minified_file = ( $use_custom_css_file && ! SCRIPT_DEBUG && $tablepress_css->load_custom_css_from_file( 'minified' ) );
144 if ( $use_custom_css_minified_file ) {
145 $custom_css_minified_url = $tablepress_css->get_custom_css_location( 'minified', 'url' );
146 wp_enqueue_style( 'tablepress-custom', $custom_css_minified_url, $custom_css_dependencies, $custom_css_version );
147 return;
148 }
149
150 $use_custom_css_normal_file = ( $use_custom_css_file && $tablepress_css->load_custom_css_from_file( 'normal' ) );
151 if ( $use_custom_css_normal_file ) {
152 $custom_css_normal_url = $tablepress_css->get_custom_css_location( 'normal', 'url' );
153 wp_enqueue_style( 'tablepress-custom', $custom_css_normal_url, $custom_css_dependencies, $custom_css_version );
154 return;
155 }
156
157 if ( $use_custom_css ) {
158 // Get "Custom CSS" from options, try minified Custom CSS first.
159 $custom_css_minified = TablePress::$model_options->get( 'custom_css_minified' );
160 if ( ! empty( $custom_css_minified ) ) {
161 $custom_css = $custom_css_minified;
162 }
163 /**
164 * Filters the "Custom CSS" code that is to be loaded as inline CSS.
165 *
166 * @since 1.0.0
167 *
168 * @param string $custom_css The "Custom CSS" code.
169 */
170 $custom_css = apply_filters( 'tablepress_custom_css', $custom_css );
171 if ( ! empty( $custom_css ) ) {
172 // wp_add_inline_style() requires a loaded CSS file, so we have to work around that if "Default CSS" is disabled.
173 if ( $use_default_css ) {
174 // Handle of the file to which the <style> shall be appended.
175 wp_add_inline_style( 'tablepress-default', $custom_css );
176 } else {
177 add_action( 'wp_head', array( $this, '_print_custom_css' ), 8 ); // Priority 8 to hook in right after WP_Styles has been processed.
178 }
179 }
180 }
181 }
182 }
183
184 /**
185 * Print "Custom CSS" to "wp_head" inline.
186 *
187 * This is necessary if "Default CSS" is off, and saving "Custom CSS" to a file is not possible.
188 *
189 * @since 1.0.0
190 */
191 public function _print_custom_css(): void {
192 // Get "Custom CSS" from options, try minified Custom CSS first.
193 $custom_css = TablePress::$model_options->get( 'custom_css_minified' );
194 if ( empty( $custom_css ) ) {
195 $custom_css = TablePress::$model_options->get( 'custom_css' );
196 }
197 /** This filter is documented in controllers/controller-frontend.php */
198 $custom_css = apply_filters( 'tablepress_custom_css', $custom_css );
199 echo "<style>\n{$custom_css}\n</style>\n";
200 }
201
202 /**
203 * Enqueue the DataTables JavaScript library and its dependencies.
204 *
205 * @since 1.0.0
206 */
207 protected function _enqueue_datatables(): void {
208 $js_file = 'js/jquery.datatables.min.js';
209 $js_url = plugins_url( $js_file, TABLEPRESS__FILE__ );
210 /**
211 * Filters the URL from which the DataTables JavaScript library file is loaded.
212 *
213 * @since 1.0.0
214 *
215 * @param string $js_url URL of the DataTables JS library file.
216 * @param string $js_file Path and file name of the DataTables JS library file.
217 */
218 $js_url = apply_filters( 'tablepress_datatables_js_url', $js_url, $js_file );
219 wp_enqueue_script( 'tablepress-datatables', $js_url, array( 'jquery-core' ), TablePress::version, true );
220 }
221
222 /**
223 * Add JS code for invocation of DataTables JS library.
224 *
225 * @since 1.0.0
226 */
227 public function add_datatables_calls(): void {
228 // Prevent repeated execution (which would lead to DataTables error messages) via a static variable.
229 static $datatables_calls_printed = false;
230 if ( $datatables_calls_printed ) {
231 return;
232 }
233
234 if ( empty( $this->shown_tables ) ) {
235 // There are no tables with activated DataTables on the page that is currently rendered.
236 return;
237 }
238
239 /*
240 * Don't add the DataTables function calls in the scope of the block editor.
241 * Otherwise, this causes a script error in the block editor iframe.
242 */
243 if ( function_exists( 'get_current_screen' ) ) {
244 $current_screen = get_current_screen();
245 if ( ( $current_screen instanceof WP_Screen ) && $current_screen->is_block_editor() ) {
246 return;
247 }
248 }
249
250 // Storage for the DataTables language strings.
251 $datatables_language = array();
252 // Generate the specific JS commands, depending on chosen features on the "Edit" screen and the Shortcode parameters.
253 $commands = array();
254
255 foreach ( $this->shown_tables as $table_id => $table_store ) {
256 if ( empty( $table_store['instances'] ) ) {
257 continue;
258 }
259
260 foreach ( $table_store['instances'] as $html_id => $js_options ) {
261 $parameters = array();
262
263 // Settle dependencies/conflicts between certain features.
264 if ( false !== $js_options['datatables_scrolly'] ) { // datatables_scrolly can be a string, so that the explicit `false` check is needed.
265 // Vertical scrolling and pagination don't work together.
266 $js_options['datatables_paginate'] = false;
267 }
268 // Sanitize, as it may come from a Shortcode attribute.
269 $js_options['datatables_paginate_entries'] = (int) $js_options['datatables_paginate_entries'];
270
271 /*
272 * DataTables language/translation handling.
273 */
274
275 /**
276 * Filters the locale/language for the DataTables JavaScript library.
277 *
278 * @since 1.0.0
279 *
280 * @param string $locale The DataTables JS library locale.
281 * @param string $table_id The current table ID.
282 */
283 $datatables_locale = apply_filters( 'tablepress_datatables_locale', $js_options['datatables_locale'], $table_id );
284
285 // Only load each locale's language file once.
286 if ( ! isset( $datatables_language[ $datatables_locale ] ) ) {
287 $orig_language_file = TABLEPRESS_ABSPATH . "i18n/datatables/lang-{$datatables_locale}.php";
288
289 /**
290 * Filters the language file path for the DataTables JavaScript library.
291 *
292 * PHP files that return an array and JSON files are supported.
293 * The JSON file method is deprecated and should no longer be used.
294 *
295 * @since 1.0.0
296 *
297 * @param string $orig_language_file Language file path for the DataTables JS library.
298 * @param string $datatables_locale Current locale/language for the DataTables JS library.
299 * @param string $tablepress_abspath Base path of the TablePress plugin.
300 */
301 $language_file = apply_filters( 'tablepress_datatables_language_file', $orig_language_file, $datatables_locale, TABLEPRESS_ABSPATH );
302
303 /*
304 * Load translation file if it's not "en_US" (included as the default in DataTables)
305 * or if the filter was used to change the language file, and the language file exists.
306 * Otherwise, use an empty en_US placeholder, so that the strings are filterable later.
307 */
308 if ( ( 'en_US' !== $datatables_locale || $orig_language_file !== $language_file ) && file_exists( $language_file ) ) {
309 if ( str_ends_with( $language_file, '.php' ) ) {
310 $datatables_strings = require $language_file;
311 if ( ! is_array( $datatables_strings ) ) {
312 $datatables_strings = array();
313 }
314 } elseif ( str_ends_with( $language_file, '.json' ) ) {
315 $datatables_strings = file_get_contents( $language_file );
316 $datatables_strings = json_decode( $datatables_strings, true ); // @phpstan-ignore-line
317 // Check if JSON could be decoded.
318 if ( is_null( $datatables_strings ) ) {
319 $datatables_strings = array();
320 }
321 $datatables_strings = (array) $datatables_strings;
322 } else {
323 // The filtered language file exists, but is not a .php or .json file, so don't use it.
324 $datatables_strings = array();
325 }
326 } else {
327 // If no translation file for the defined locale exists or is needed, use "en_US", as that's built-in.
328 $datatables_locale = 'en_US';
329 $datatables_strings = array();
330 }
331
332 /**
333 * Filters the language strings for the DataTables JavaScript library's features.
334 *
335 * @since 2.0.0
336 *
337 * @param array<string, mixed> $datatables_strings The language strings for DataTables.
338 * @param string $datatables_locale Current locale/language for the DataTables JS library.
339 */
340 $datatables_language[ $datatables_locale ] = apply_filters( 'tablepress_datatables_language_strings', $datatables_strings, $datatables_locale );
341 }
342 $parameters['language'] = '"language":DT_language["' . $datatables_locale . '"]';
343
344 // These parameters need to be added for performance gain or to overwrite unwanted default behavior.
345 if ( $js_options['datatables_sort'] ) {
346 // No initial sort.
347 $parameters['order'] = '"order":[]';
348 // Don't add additional classes, to speed up sorting.
349 $parameters['orderClasses'] = '"orderClasses":false';
350 }
351
352 // Alternating row colors is default, so remove them if not wanted with [].
353 $parameters['stripeClasses'] = '"stripeClasses":' . ( ( $js_options['alternating_row_colors'] ) ? '["even","odd"]' : '[]' );
354
355 // The following options are activated by default, so we only need to "false" them if we don't want them, but don't need to "true" them if we do.
356 if ( ! $js_options['datatables_sort'] ) {
357 $parameters['ordering'] = '"ordering":false';
358 }
359 if ( $js_options['datatables_paginate'] ) {
360 $parameters['pagingType'] = '"pagingType":"simple"';
361 if ( $js_options['datatables_lengthchange'] ) {
362 $length_menu = array( 10, 25, 50, 100 );
363 if ( ! in_array( $js_options['datatables_paginate_entries'], $length_menu, true ) ) {
364 $length_menu[] = $js_options['datatables_paginate_entries'];
365 sort( $length_menu, SORT_NUMERIC );
366 $parameters['lengthMenu'] = '"lengthMenu":[' . implode( ',', $length_menu ) . ']';
367 }
368 } else {
369 $parameters['lengthChange'] = '"lengthChange":false';
370 }
371 if ( 10 !== $js_options['datatables_paginate_entries'] ) {
372 $parameters['pageLength'] = '"pageLength":' . $js_options['datatables_paginate_entries'];
373 }
374 } else {
375 $parameters['paging'] = '"paging":false';
376 }
377 if ( ! $js_options['datatables_filter'] ) {
378 $parameters['searching'] = '"searching":false';
379 }
380 if ( ! $js_options['datatables_info'] ) {
381 $parameters['info'] = '"info":false';
382 }
383 if ( $js_options['datatables_scrollx'] ) {
384 $parameters['scrollX'] = '"scrollX":true';
385 }
386 if ( false !== $js_options['datatables_scrolly'] ) {
387 $parameters['scrollY'] = '"scrollY":"' . preg_replace( '#[^0-9a-z.%]#', '', $js_options['datatables_scrolly'] ) . '"';
388 $parameters['scrollCollapse'] = '"scrollCollapse":true';
389 }
390 if ( ! empty( $js_options['datatables_custom_commands'] ) ) {
391 $parameters['custom_commands'] = $js_options['datatables_custom_commands'];
392 }
393
394 /**
395 * Filters the parameters that are passed to the DataTables JavaScript library.
396 *
397 * @since 1.0.0
398 *
399 * @param array<string, mixed> $parameters The parameters for the DataTables JS library.
400 * @param string $table_id The current table ID.
401 * @param string $html_id The ID of the table HTML element.
402 * @param array<string, mixed> $js_options The options for the JS library.
403 */
404 $parameters = apply_filters( 'tablepress_datatables_parameters', $parameters, $table_id, $html_id, $js_options );
405
406 // If an existing parameter (in the from `"parameter":`) is set in the "Custom Commands", remove its default value.
407 if ( isset( $parameters['custom_commands'] ) ) {
408 foreach ( array_keys( $parameters ) as $maybe_overwritten_parameter ) {
409 if ( str_contains( $parameters['custom_commands'], "\"{$maybe_overwritten_parameter}\":" ) ) {
410 unset( $parameters[ $maybe_overwritten_parameter ] );
411 }
412 }
413 }
414
415 $parameters = implode( ',', $parameters );
416 $parameters = ( ! empty( $parameters ) ) ? '{' . $parameters . '}' : '';
417
418 $command = "$('#{$html_id}').DataTable({$parameters});";
419 /**
420 * Filters the JavaScript command that invokes the DataTables JavaScript library on one table.
421 *
422 * @since 1.0.0
423 *
424 * @param string $command The JS command for the DataTables JS library.
425 * @param string $html_id The ID of the table HTML element.
426 * @param string $parameters The parameters for the DataTables JS library.
427 * @param string $table_id The current table ID.
428 * @param array<string, mixed> $js_options The options for the JS library.
429 */
430 $command = apply_filters( 'tablepress_datatables_command', $command, $html_id, $parameters, $table_id, $js_options );
431 if ( ! empty( $command ) ) {
432 $commands[] = $command;
433 }
434 } // foreach table instance
435 } // foreach table ID
436
437 // DataTables language/translation handling.
438 if ( ! empty( $datatables_language ) ) {
439 $datatables_language = wp_json_encode( $datatables_language, JSON_UNESCAPED_UNICODE | JSON_FORCE_OBJECT );
440 $datatables_language = "var DT_language={$datatables_language};\n";
441 } else {
442 $datatables_language = '';
443 }
444
445 $commands = implode( "\n", $commands );
446 /**
447 * Filters the JavaScript commands that invoke the DataTables JavaScript library on all tables on the page.
448 *
449 * @since 1.0.0
450 *
451 * @param string $commands The JS commands for the DataTables JS library.
452 */
453 $commands = apply_filters( 'tablepress_all_datatables_commands', $commands );
454 if ( '' === $commands ) {
455 return;
456 }
457
458 $script_type_attr = current_theme_supports( 'html5', 'script' ) ? '' : ' type="text/javascript"';
459
460 $js_wrapper = <<<'JS'
461 <script%3$s>
462 jQuery(function($){
463 %1$s%2$s
464 });
465 </script>
466 JS;
467 /**
468 * Filters the script/jQuery wrapper code for the DataTables commands calls.
469 *
470 * @since 1.14.0
471 *
472 * @param string $js_wrapper Default script/jQuery wrapper code for the DataTables commands calls.
473 */
474 $js_wrapper = apply_filters( 'tablepress_all_datatables_commands_wrapper', $js_wrapper );
475 printf( $js_wrapper, $datatables_language, $commands, $script_type_attr );
476
477 // Prevent repeated execution (which would lead to DataTables error messages) via a static variable.
478 $datatables_calls_printed = true;
479 }
480
481 /**
482 * Handle Shortcode [table id=<ID> /].
483 *
484 * @since 1.0.0
485 *
486 * @param array<string, mixed>|string $shortcode_atts List of attributes that where included in the Shortcode. An empty string for empty Shortcodes like [table] or [table /].
487 * @return string Resulting HTML code for the table with the ID <ID>.
488 */
489 public function shortcode_table( /* array|string */ $shortcode_atts ): string {
490 $shortcode_atts = (array) $shortcode_atts;
491
492 $_render = TablePress::load_class( 'TablePress_Render', 'class-render.php', 'classes' );
493
494 $default_shortcode_atts = $_render->get_default_render_options();
495 /**
496 * Filters the available/default attributes for the [table] Shortcode.
497 *
498 * @since 1.0.0
499 *
500 * @param array<string, mixed> $default_shortcode_atts The [table] Shortcode default attributes.
501 */
502 $default_shortcode_atts = apply_filters( 'tablepress_shortcode_table_default_shortcode_atts', $default_shortcode_atts );
503 // Parse Shortcode attributes, only allow those that are specified.
504 $shortcode_atts = shortcode_atts( $default_shortcode_atts, $shortcode_atts ); // Optional third argument left out on purpose. Use filter in the next line instead.
505 /**
506 * Filters the attributes that were passed to the [table] Shortcode.
507 *
508 * @since 1.0.0
509 *
510 * @param array<string, mixed> $shortcode_atts The attributes passed to the [table] Shortcode.
511 */
512 $shortcode_atts = apply_filters( 'tablepress_shortcode_table_shortcode_atts', $shortcode_atts );
513
514 // Check, if a table with the given ID exists.
515 $table_id = (string) preg_replace( '/[^a-zA-Z0-9_-]/', '', $shortcode_atts['id'] );
516 if ( ! TablePress::$model_table->table_exists( $table_id ) ) {
517 $message = "[table &#8220;{$table_id}&#8221; not found /]<br />\n";
518 /**
519 * Filters the "Table not found" message.
520 *
521 * @since 1.0.0
522 *
523 * @param string $message The "Table not found" message.
524 * @param string $table_id The current table ID.
525 */
526 $message = apply_filters( 'tablepress_table_not_found_message', $message, $table_id );
527 return $message;
528 }
529
530 // Load table, with table data, options, and visibility settings.
531 $table = TablePress::$model_table->load( $table_id, true, true );
532 if ( is_wp_error( $table ) ) {
533 $message = "[table &#8220;{$table_id}&#8221; could not be loaded /]<br />\n";
534 /**
535 * Filters the "Table could not be loaded" message.
536 *
537 * @since 1.0.0
538 *
539 * @param string $message The "Table could not be loaded" message.
540 * @param string $table_id The current table ID.
541 * @param WP_Error $table The error object for the table.
542 */
543 $message = apply_filters( 'tablepress_table_load_error_message', $message, $table_id, $table );
544 return $message;
545 }
546 if ( isset( $table['is_corrupted'] ) && $table['is_corrupted'] ) {
547 $message = "<div>Attention: The internal data of table &#8220;{$table_id}&#8221; is corrupted!</div>";
548 /**
549 * Filters the "Table data is corrupted" message.
550 *
551 * @since 1.0.0
552 *
553 * @param string $message The "Table data is corrupted" message.
554 * @param string $table_id The current table ID.
555 * @param string $json_error The JSON error with information about the corrupted table.
556 */
557 $message = apply_filters( 'tablepress_table_corrupted_message', $message, $table_id, $table['json_error'] );
558 return $message;
559 }
560
561 /**
562 * Filters whether the "datatables_custom_commands" Shortcode parameter is disabled.
563 *
564 * By default, the "datatables_custom_commands" Shortcode parameter is disabled for security reasons.
565 *
566 * @since 1.0.0
567 *
568 * @param bool $disable Whether to disable the "datatables_custom_commands" Shortcode parameter. Default true.
569 */
570 if ( ! is_null( $shortcode_atts['datatables_custom_commands'] ) && apply_filters( 'tablepress_disable_custom_commands_shortcode_parameter', true ) ) {
571 $shortcode_atts['datatables_custom_commands'] = null;
572 }
573
574 // Determine options to use (if set in Shortcode, use those, otherwise use stored options, from the "Edit" screen).
575 $render_options = array();
576 foreach ( $shortcode_atts as $key => $value ) {
577 if ( is_null( $value ) && isset( $table['options'][ $key ] ) ) {
578 // Use the table's stored option value, if the Shortcode parameter was not set.
579 $render_options[ $key ] = $table['options'][ $key ];
580 } elseif ( is_string( $value ) ) {
581 // Convert strings 'true' or 'false' to boolean, keep others.
582 $value_lowercase = strtolower( $value );
583 if ( 'true' === $value_lowercase ) {
584 $render_options[ $key ] = true;
585 } elseif ( 'false' === $value_lowercase ) {
586 $render_options[ $key ] = false;
587 } else {
588 $render_options[ $key ] = $value;
589 }
590 } else {
591 // Keep all other values.
592 $render_options[ $key ] = $value;
593 }
594 }
595
596 // Generate unique HTML ID, depending on how often this table has already been shown on this page.
597 if ( ! isset( $this->shown_tables[ $table_id ] ) ) {
598 $this->shown_tables[ $table_id ] = array(
599 'count' => 0,
600 'instances' => array(),
601 );
602 }
603 ++$this->shown_tables[ $table_id ]['count'];
604 $count = $this->shown_tables[ $table_id ]['count'];
605 $render_options['html_id'] = "tablepress-{$table_id}";
606 if ( $count > 1 ) {
607 $render_options['html_id'] .= "-no-{$count}";
608 }
609 /**
610 * Filters the ID of the table HTML element.
611 *
612 * @since 1.0.0
613 *
614 * @param string $html_id The ID of the table HTML element.
615 * @param string $table_id The current table ID.
616 * @param int $count Number of copies of the table with this table ID on the page.
617 */
618 $render_options['html_id'] = apply_filters( 'tablepress_html_id', $render_options['html_id'], $table_id, $count );
619
620 // Generate the "Edit Table" link.
621 $render_options['edit_table_url'] = '';
622 /**
623 * Filters whether the "Edit" link below the table shall be shown.
624 *
625 * The "Edit" link is only shown to logged-in users who possess the necessary capability to edit the table.
626 *
627 * @since 1.0.0
628 *
629 * @param bool $show Whether to show the "Edit" link below the table. Default true.
630 * @param string $table_id The current table ID.
631 */
632 if ( is_user_logged_in() && apply_filters( 'tablepress_edit_link_below_table', true, $table['id'] ) && current_user_can( 'tablepress_edit_table', $table['id'] ) ) {
633 $render_options['edit_table_url'] = TablePress::url( array( 'action' => 'edit', 'table_id' => $table['id'] ) );
634 }
635
636 /**
637 * Filters the render options for the table.
638 *
639 * The render options are determined from the settings on a table's "Edit" screen and the Shortcode parameters.
640 *
641 * @since 1.0.0
642 *
643 * @param array<string, mixed> $render_options The render options for the table.
644 * @param array<string, mixed> $table The current table.
645 */
646 $render_options = apply_filters( 'tablepress_table_render_options', $render_options, $table );
647
648 // Check if table output shall and can be loaded from the transient cache, otherwise generate the output.
649 if ( $render_options['cache_table_output'] && ! is_user_logged_in() ) {
650 // Hash the Render Options array to get a unique cache identifier.
651 $table_hash = md5( wp_json_encode( $render_options, TABLEPRESS_JSON_OPTIONS ) ); // @phpstan-ignore-line
652 $transient_name = 'tablepress_' . $table_hash; // Attention: This string must not be longer than 45 characters!
653 $output = get_transient( $transient_name );
654 if ( false === $output || '' === $output ) {
655 // Render/generate the table HTML, as it was not found in the cache.
656 $_render->set_input( $table, $render_options );
657 $output = $_render->get_output();
658 // Save render output in a transient, set cache timeout to 24 hours.
659 set_transient( $transient_name, $output, DAY_IN_SECONDS );
660 // Update output caches list transient (necessary for cache invalidation upon table saving).
661 $caches_list_transient_name = 'tablepress_c_' . md5( $table_id );
662 $caches_list = get_transient( $caches_list_transient_name );
663 if ( false === $caches_list ) {
664 $caches_list = array();
665 } else {
666 $caches_list = (array) json_decode( $caches_list, true );
667 }
668 if ( ! in_array( $transient_name, $caches_list, true ) ) {
669 $caches_list[] = $transient_name;
670 }
671 set_transient( $caches_list_transient_name, wp_json_encode( $caches_list, TABLEPRESS_JSON_OPTIONS ), 2 * DAY_IN_SECONDS );
672 } else {
673 /**
674 * Filters the cache hit comment message.
675 *
676 * @since 1.0.0
677 *
678 * @param string $comment The cache hit comment message.
679 */
680 $output .= apply_filters( 'tablepress_cache_hit_comment', "<!-- #{$render_options['html_id']} from cache -->" );
681 }
682 } else {
683 // Render/generate the table HTML, as no cache is to be used.
684 $_render->set_input( $table, $render_options );
685 $output = $_render->get_output();
686 }
687
688 // If DataTables is to be and can be used with this instance of a table, process its parameters and register the call for inclusion in the footer.
689 if ( $render_options['use_datatables']
690 && $render_options['table_head']
691 && str_contains( $output, '<thead' ) // A `<thead>` tag is required.
692 && ! str_contains( $output, ' colspan="' ) // `colspan` attributes are forbidden.
693 && ! str_contains( $output, ' rowspan="' ) // `rowspan` attributes are forbidden.
694 ) {
695 // Get options for the DataTables JavaScript library from the table's render options.
696 $js_options = array();
697 foreach ( array(
698 'alternating_row_colors',
699 'datatables_sort',
700 'datatables_paginate',
701 'datatables_paginate',
702 'datatables_paginate_entries',
703 'datatables_lengthchange',
704 'datatables_filter',
705 'datatables_info',
706 'datatables_scrollx',
707 'datatables_scrolly',
708 'datatables_locale',
709 'datatables_custom_commands',
710 ) as $option ) {
711 $js_options[ $option ] = $render_options[ $option ];
712 }
713 /**
714 * Filters the JavaScript options for the table.
715 *
716 * The JavaScript options are determined from the settings on a table's "Edit" screen and the Shortcode parameters.
717 * They are part of the render options and can be overwritten with Shortcode parameters.
718 *
719 * @since 1.0.0
720 *
721 * @param array<string, mixed> $js_options The JavaScript options for the table.
722 * @param string $table_id The current table ID.
723 * @param array<string, mixed> $render_options The render options for the table.
724 */
725 $js_options = apply_filters( 'tablepress_table_js_options', $js_options, $table_id, $render_options );
726 $this->shown_tables[ $table_id ]['instances'][ (string) $render_options['html_id'] ] = $js_options;
727 $this->_enqueue_datatables();
728 }
729
730 // Maybe print a list of used render options.
731 if ( $render_options['shortcode_debug'] && is_user_logged_in() ) {
732 $output .= '<pre>' . var_export( $render_options, true ) . '</pre>'; // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_var_export
733 }
734
735 return $output;
736 }
737
738 /**
739 * Handle Shortcode [table-info id=<ID> field=<name> /].
740 *
741 * @since 1.0.0
742 *
743 * @param array<string, mixed>|string $shortcode_atts List of attributes that where included in the Shortcode. An empty string for empty Shortcodes like [table] or [table /].
744 * @return string Text that replaces the Shortcode (error message or asked-for information).
745 */
746 public function shortcode_table_info( /* array|string */ $shortcode_atts ): string {
747 $shortcode_atts = (array) $shortcode_atts;
748
749 // Parse Shortcode attributes, only allow those that are specified.
750 $default_shortcode_atts = array(
751 'id' => '',
752 'field' => '',
753 'format' => '',
754 );
755 /**
756 * Filters the available/default attributes for the [table-info] Shortcode.
757 *
758 * @since 1.0.0
759 *
760 * @param array<string, mixed> $default_shortcode_atts The [table-info] Shortcode default attributes.
761 */
762 $default_shortcode_atts = apply_filters( 'tablepress_shortcode_table_info_default_shortcode_atts', $default_shortcode_atts );
763 $shortcode_atts = shortcode_atts( $default_shortcode_atts, $shortcode_atts ); // Optional third argument left out on purpose. Use filter in the next line instead.
764 /**
765 * Filters the attributes that were passed to the [table-info] Shortcode.
766 *
767 * @since 1.0.0
768 *
769 * @param array<string, mixed> $shortcode_atts The attributes passed to the [table-info] Shortcode.
770 */
771 $shortcode_atts = apply_filters( 'tablepress_shortcode_table_info_shortcode_atts', $shortcode_atts );
772
773 /**
774 * Filters whether the output of the [table-info] Shortcode is overwritten/short-circuited.
775 *
776 * @since 1.0.0
777 *
778 * @param false|string $overwrite Whether the [table-info] output is overwritten. Return false for the regular content, and a string to overwrite the output.
779 * @param array<string, mixed> $shortcode_atts The attributes passed to the [table-info] Shortcode.
780 */
781 $overwrite = apply_filters( 'tablepress_shortcode_table_info_overwrite', false, $shortcode_atts );
782 if ( is_string( $overwrite ) ) {
783 return $overwrite;
784 }
785
786 // Check, if a table with the given ID exists.
787 $table_id = preg_replace( '/[^a-zA-Z0-9_-]/', '', $shortcode_atts['id'] );
788 if ( ! TablePress::$model_table->table_exists( $table_id ) ) {
789 $message = "[table &#8220;{$table_id}&#8221; not found /]<br />\n";
790 /** This filter is documented in controllers/controller-frontend.php */
791 $message = apply_filters( 'tablepress_table_not_found_message', $message, $table_id );
792 return $message;
793 }
794
795 // Load table, with table data, options, and visibility settings.
796 $table = TablePress::$model_table->load( $table_id, true, true );
797 if ( is_wp_error( $table ) ) {
798 $message = "[table &#8220;{$table_id}&#8221; could not be loaded /]<br />\n";
799 /** This filter is documented in controllers/controller-frontend.php */
800 $message = apply_filters( 'tablepress_table_load_error_message', $message, $table_id, $table );
801 return $message;
802 }
803
804 $field = (string) preg_replace( '/[^a-z_]/', '', strtolower( $shortcode_atts['field'] ) );
805 $format = (string) preg_replace( '/[^a-z]/', '', strtolower( $shortcode_atts['format'] ) );
806
807 // Generate output, depending on what information (field) was asked for.
808 switch ( $field ) {
809 case 'name':
810 case 'description':
811 $output = $table[ $field ];
812 break;
813 case 'last_modified':
814 switch ( $format ) {
815 case 'raw':
816 case 'mysql':
817 $output = $table['last_modified'];
818 break;
819 case 'human':
820 $modified_timestamp = date_create( $table['last_modified'], wp_timezone() );
821 $modified_timestamp = $modified_timestamp->getTimestamp(); // @phpstan-ignore-line
822 $current_timestamp = time();
823 $time_diff = $current_timestamp - $modified_timestamp;
824 // Time difference is only shown up to one week.
825 if ( $time_diff >= 0 && $time_diff < WEEK_IN_SECONDS ) {
826 $output = sprintf( __( '%s ago', 'default' ), human_time_diff( $modified_timestamp, $current_timestamp ) );
827 } else {
828 $output = TablePress::format_datetime( $table['last_modified'], '<br />' );
829 }
830 break;
831 case 'date':
832 $output = TablePress::format_datetime( $table['last_modified'], get_option( 'date_format' ) );
833 break;
834 case 'time':
835 $output = TablePress::format_datetime( $table['last_modified'], get_option( 'time_format' ) );
836 break;
837 default:
838 $output = TablePress::format_datetime( $table['last_modified'] );
839 break;
840 }
841 break;
842 case 'last_editor':
843 $output = TablePress::get_user_display_name( $table['options']['last_editor'] );
844 break;
845 case 'author':
846 $output = TablePress::get_user_display_name( $table['author'] );
847 break;
848 case 'number_rows':
849 $output = count( $table['data'] );
850 if ( 'raw' !== $format ) {
851 if ( $table['options']['table_head'] ) {
852 --$output;
853 }
854 if ( $table['options']['table_foot'] ) {
855 --$output;
856 }
857 }
858 break;
859 case 'number_columns':
860 $output = count( $table['data'][0] );
861 break;
862 default:
863 $output = "[table-info field &#8220;{$field}&#8221; not found in table &#8220;{$table_id}&#8221; /]<br />\n";
864 /**
865 * Filters the "table info field not found" message.
866 *
867 * @since 1.0.0
868 *
869 * @param string $output The "table info field not found" message.
870 * @param array<string, mixed> $table The current table.
871 * @param string $field The field that was not found.
872 * @param string $format The return format for the field.
873 */
874 $output = apply_filters( 'tablepress_table_info_not_found_message', $output, $table, $field, $format );
875 }
876
877 /**
878 * Filters the output of the [table-info] Shortcode.
879 *
880 * @since 1.0.0
881 *
882 * @param string $output The output of the [table-info] Shortcode.
883 * @param array<string, mixed> $table The current table.
884 * @param array<string, mixed> $shortcode_atts The attributes passed to the [table-info] Shortcode.
885 */
886 $output = apply_filters( 'tablepress_shortcode_table_info_output', $output, $table, $shortcode_atts );
887 return $output;
888 }
889
890 /**
891 * Expand WP Search to also find posts and pages that have a search term in a table that is shown in them.
892 *
893 * This is done by looping through all search terms and TablePress tables and searching there for the search term,
894 * saving all tables's IDs that have a search term and then expanding the WP query to search for posts or pages that have the
895 * Shortcode for one of these tables in their content.
896 *
897 * @since 1.0.0
898 *
899 * @global wpdb $wpdb WordPress database abstraction object.
900 *
901 * @param string $search_sql Current part of the "WHERE" clause of the SQL statement used to get posts/pages from the WP database that is related to searching.
902 * @return string Eventually extended SQL "WHERE" clause, to also find posts/pages with Shortcodes in them.
903 */
904 public function posts_search_filter( string $search_sql ): string {
905 global $wpdb;
906
907 if ( ! is_search() || ! is_main_query() ) {
908 return $search_sql;
909 }
910
911 // Get variable that contains all search terms, parsed from $_GET['s'] by WP.
912 $search_terms = get_query_var( 'search_terms' );
913 if ( empty( $search_terms ) || ! is_array( $search_terms ) ) {
914 return $search_sql;
915 }
916
917 // Load all table IDs and prime post meta cache for cached access to options and visibility settings of the tables, don't run filter hook.
918 $table_ids = TablePress::$model_table->load_all( true, false );
919 // Array of all search words that were found, and the table IDs where they were found.
920 $query_result = array();
921
922 foreach ( $table_ids as $table_id ) {
923 // Load table, with table data, options, and visibility settings.
924 $table = TablePress::$model_table->load( $table_id, true, true );
925
926 if ( isset( $table['is_corrupted'] ) && $table['is_corrupted'] ) {
927 // Do not search in corrupted tables.
928 continue;
929 }
930
931 foreach ( $search_terms as $search_term ) {
932 if ( ( $table['options']['print_name'] && false !== stripos( $table['name'], $search_term ) ) // @phpstan-ignore-line
933 || ( $table['options']['print_description'] && false !== stripos( $table['description'], $search_term ) ) ) { // @phpstan-ignore-line
934 // Found the search term in the name or description (and they are shown).
935 $query_result[ $search_term ][] = $table_id; // Add table ID to result list.
936 // No need to continue searching this search term in this table.
937 continue;
938 }
939
940 // Search search term in visible table cells (without taking Shortcode parameters into account!).
941 foreach ( $table['data'] as $row_idx => $table_row ) { // @phpstan-ignore-line
942 if ( 0 === $table['visibility']['rows'][ $row_idx ] ) {
943 // Row is hidden, so don't search in it.
944 continue;
945 }
946 foreach ( $table_row as $col_idx => $table_cell ) {
947 if ( 0 === $table['visibility']['columns'][ $col_idx ] ) {
948 // Column is hidden, so don't search in it.
949 continue;
950 }
951 // @TODO: Cells are not evaluated here, so math formulas are searched.
952 if ( false !== stripos( $table_cell, $search_term ) ) {
953 // Found the search term in the cell content.
954 $query_result[ $search_term ][] = $table_id; // Add table ID to result list
955 // No need to continue searching this search term in this table.
956 continue 3;
957 }
958 }
959 }
960 }
961 }
962
963 // For all found table IDs for each search term, add additional OR statement to the SQL "WHERE" clause.
964
965 // If $_GET['exact'] is set, WordPress doesn't use % in SQL LIKE clauses.
966 $exact = get_query_var( 'exact' );
967 $n = ( empty( $exact ) ) ? '%' : '';
968 $search_sql = $wpdb->remove_placeholder_escape( $search_sql );
969 foreach ( $query_result as $search_term => $table_ids ) {
970 $search_term = esc_sql( $wpdb->esc_like( $search_term ) );
971 $old_or = "OR ({$wpdb->posts}.post_content LIKE '{$n}{$search_term}{$n}')"; // @phpstan-ignore-line
972 $table_ids = implode( '|', $table_ids );
973 $regexp = '\\\\[' . TablePress::$shortcode . ' id=(["\\\']?)(' . $table_ids . ')([\]"\\\' /])'; // ' needs to be single escaped, [ double escaped (with \\) in mySQL
974 $new_or = $old_or . " OR ({$wpdb->posts}.post_content REGEXP '{$regexp}')";
975 $search_sql = str_replace( $old_or, $new_or, $search_sql );
976 }
977 $search_sql = $wpdb->add_placeholder_escape( $search_sql );
978
979 return $search_sql;
980 }
981
982 /**
983 * Callback function for rendering the tablepress/table block.
984 *
985 * @since 2.0.0
986 *
987 * @param array<string, string> $block_attributes List of attributes that where included in the block settings.
988 * @return string Resulting HTML code for the table.
989 */
990 public function table_block_render_callback( array $block_attributes ): string {
991 // Don't return anything if no table was selected.
992 if ( '' === $block_attributes['id'] ) {
993 return '';
994 }
995
996 if ( '' !== trim( $block_attributes['parameters'] ) ) {
997 $render_attributes = shortcode_parse_atts( $block_attributes['parameters'] );
998 } else {
999 $render_attributes = array();
1000 }
1001 $render_attributes['id'] = $block_attributes['id']; // @phpstan-ignore-line
1002
1003 return $this->shortcode_table( $render_attributes );
1004 }
1005
1006 } // class TablePress_Frontend_Controller
1007