PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / 2.2.7
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! v2.2.7
3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.10 All 111 releases
← All changes | includes/API/Login.php +21 -129 3.7.42.2.7 View file →
@@ -17,12 +17,8 @@
17 17 if ( '/templately/v1/pricing' === $_route ) {
18 18 return true;
19 19 }
20 20
21 - if ( '/templately/v1/google-auth-url' === $_route ) {
22 - return true;
23 - }
24 -
25 21 return parent::permission_check( $request );
26 22 }
27 23
28 24 public function register_routes() {
@@ -29,41 +25,24 @@
29 25 $this->post( 'login', [$this, 'login'] );
30 26 $this->post( 'logout', [$this, 'logout'] );
31 27 $this->get( 'is-signed', [$this, 'is_signed'] );
32 28 $this->get( 'pricing', [$this, 'pricing'] );
33 - $this->get( 'google-auth-url', [$this, 'google_auth_url'] );
34 29 }
35 30
36 - public function google_auth_url() {
37 - // Get redirect_to parameter from request if provided
38 - $redirect_to = $this->get_param( 'redirect-to', '' );
39 -
40 - // Use client-provided current_url instead of HTTP_REFERER for reliability
41 - $current_url = $this->get_param( 'current_url', '' );
42 -
43 - $url = $this->http()->google_auth_url( $redirect_to, $current_url );
44 - return [
45 - 'status' => 'success',
46 - 'url' => $url
47 - ];
48 - }
49 -
50 31 public function pricing(){
51 - $data = get_transient( "templately_subscriptions_v2" );
32 + $data = get_transient( "templately_subscriptions" );
52 33
53 34 if( is_array( $data ) && ! empty( $data ) ) {
54 35 return $data;
55 36 }
56 37
57 - // Field set drives the Subscription screen's plan comparison grid, so it
58 - // carries the per-plan limits too, not just price/sites.
59 - $query = 'id, price, name, slug, discounted_price, type, sites, coupon, my_cloud_items, pro_items, workspace, fsi_limit, ai_credit, description';
38 + $query = 'id, price, name, discounted_price, type, sites';
60 39 $response = $this->http()->query(
61 40 'subscriptionPlans',
62 41 $query
63 42 )->post();
64 43
65 - set_transient( "templately_subscriptions_v2", $response, WEEK_IN_SECONDS );
44 + set_transient( "templately_subscriptions", $response, WEEK_IN_SECONDS );
66 45
67 46 return $response;
68 47 }
69 48
@@ -81,10 +60,8 @@
81 60 'ip' => $_ip,
82 61 'site_url' => $_site_url
83 62 ];
84 63
85 - $postArgs = [];
86 -
87 64 if ( $viaAPI ) {
88 65 $api_key = $this->get_param( 'api_key' );
89 66 $funcArgs['api_key'] = $api_key;
90 67
@@ -107,50 +84,20 @@
107 84 if ( ! empty( $errors ) ) {
108 85 return $this->error( 'login_error', $errors, 'login', 400 );
109 86 }
110 87
111 - // `ends_at`, `plan_type` and `cancel_at_period_end` drive the Subscription
112 - // screen's renewal line. They are asked for instead of leaning on
113 - // `plan_expire_at`, which the API resolves with `empty($subscription->ends_at)
114 - // ?? …` — a boolean that never falls through, so it never carries a date.
115 - $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, is_company_user, is_restricted_company_user, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice, reviews{ type, type_id, rating }, subscription { id, name, sites, subscription_plan_id, ends_at, plan_type, cancel_at_period_end } }';
88 + $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice }';
116 89
117 90 $response = $this->http()->mutation(
118 91 $viaAPI ? 'connectWithApiKey' : 'connect',
119 92 $query,
120 93 $funcArgs
121 - )->post($postArgs);
94 + )->post();
122 95
123 96 if ( is_wp_error( $response ) ) {
124 97 return $response;
125 98 }
126 99
127 - if ( empty( $response['user']['api_key'] ) ) {
128 - return $this->error( 'login_error', $response['message'] ?? __('Invalid API key.', 'templately'), 'login', 400 );
129 - }
130 -
131 - $options = $this->utils( 'options' );
132 - $options->use_current_user( true );
133 -
134 - try {
135 - return $this->store_connection( $response, $global_signin, $_ip, $_site_url );
136 - } finally {
137 - $options->use_current_user( false );
138 - }
139 - }
140 -
141 - /**
142 - * Persist an authenticated connection against the acting user.
143 - *
144 - * @param array $response Cloud response, already validated.
145 - * @param bool $global_signin Whether the user asked to sign in globally.
146 - * @param string $_ip Request IP, echoed back into the profile.
147 - * @param string $_site_url Site URL, echoed back into the profile.
148 - *
149 - * @return array
150 - */
151 - private function store_connection( $response, $global_signin, $_ip, $_site_url ) {
152 -
153 100 if ( $global_signin && ! Login::is_globally_signed() ) {
154 101 Options::set_global_login();
155 102 }
156 103
@@ -178,25 +125,8 @@
178 125 unset( $response['user']['favourites'] );
179 126 $meta['favourites'] = $_favourites;
180 127 }
181 128
182 - if ( ! empty( $response['user']['reviews'] ) ) {
183 - $_reviews = $this->utils( 'helper' )->normalizeReviews( $response['user']['reviews'] );
184 - $this->utils( 'options' )->set( 'reviews', $_reviews );
185 -
186 - unset( $response['user']['reviews'] );
187 - $meta['reviews'] = $_reviews;
188 - }
189 -
190 - if(Helper::is_dev_api()){
191 - $response['user']['is_dev_api'] = true;
192 - }
193 -
194 - if(! empty( $response['user'] ) && is_array($response['user'])){
195 - $response['user']['ip'] = $_ip;
196 - $response['user']['site_url'] = base64_encode( $_site_url );
197 - }
198 -
199 129 $this->utils( 'options' )->set( 'user', $response['user'] );
200 130 $response['user']['meta'] = $this->user_meta( $meta );
201 131
202 132 return $response;
@@ -202,28 +132,13 @@
202 132 return $response;
203 133 }
204 134
205 135 public function logout() {
206 - // Read the key off the acting user's own record. Options::get() falls back to
207 - // the global-login administrator when no target is given, so $this->api_key
208 - // resolves to the administrator's key for any linked user — disconnecting the
209 - // administrator's account on the cloud as well as locally.
210 - $api_key = $this->utils( 'options' )->get( 'api_key', '', get_current_user_id() );
211 -
212 - if ( empty( $api_key ) ) {
213 - return $this->error(
214 - 'logout_error',
215 - __( 'You are not connected to Templately.', 'templately' ),
216 - 'logout',
217 - 403
218 - );
219 - }
220 -
221 136 $response = $this->http()->mutation(
222 137 'disconnect',
223 138 'status, message, data',
224 139 [
225 - 'api_key' => $api_key,
140 + 'api_key' => $this->api_key,
226 141 "site_url" => home_url( '/' )
227 142 ]
228 143 )->post();
229 144
@@ -250,33 +165,20 @@
250 165 return $response;
251 166 }
252 167
253 168 public function delete(){
254 - $options = $this->utils( 'options' );
169 + $this->utils( 'options' )
170 + ->remove( 'user' )
171 + ->remove( 'favourites' )
172 + ->remove( 'cloud_activity' )
173 + ->remove( 'api_key' )
174 + ->remove( 'global_login' )
175 + ->remove( 'templates_in_clouds' );
255 176
256 - // Pin the removals to the acting user. Without the pin, Options::user_id()
257 - // resolves a linked user to the global-login administrator and the delete
258 - // path wipes the administrator's connection instead of the caller's.
259 - $options->use_current_user( true );
177 + if ( $this->utils( 'options' )->whoami() === 'global' ) {
178 + $this->utils( 'options' )->remove_global_login();
179 + }
260 180
261 - try {
262 - $options
263 - ->remove( 'user' )
264 - ->remove( 'favourites' )
265 - ->remove( 'reviews' )
266 - ->remove( 'cloud_activity' )
267 - ->remove( 'api_key' )
268 - ->remove( 'global_login' )
269 - ->remove( 'total_download_counts' )
270 - ->remove( 'templates_in_clouds' );
271 -
272 - if ( $options->who_am_i() === 'global' ) {
273 - $options->remove_global_login();
274 - }
275 - } finally {
276 - $options->use_current_user( false );
277 - }
278 -
279 181 $global_user_id = $this->utils( 'options' )->is_global();
280 182 $global_user = null;
281 183
282 184 if ( $global_user_id !== $this->utils( 'options' )->current_user_id() ) {
@@ -282,12 +184,8 @@
282 184 if ( $global_user_id !== $this->utils( 'options' )->current_user_id() ) {
283 185 $global_user = $this->utils( 'options' )->get( 'user', false, $global_user_id );
284 186
285 187 if ( ! empty( $global_user ) ) {
286 - if ( is_array( $global_user ) ) {
287 - unset( $global_user['api_key'] );
288 - }
289 -
290 188 $global_user['meta'] = $this->user_meta();
291 189 }
292 190 }
293 191
@@ -293,9 +191,9 @@
293 191
294 192 return $global_user;
295 193 }
296 194
297 - public static function is_signed(): array {
195 + public static function is_signed() {
298 196 $_response = [
299 197 'status' => 'success'
300 198 ];
301 199
@@ -301,13 +199,8 @@
301 199
302 200 $_user = ( new static )->utils( 'options' )->get( 'user', null );
303 201
304 202 if ( ! is_null( $_user ) ) {
305 - // Profiles stored before 3.7.1 may still carry the cloud API key.
306 - if ( is_array( $_user ) ) {
307 - unset( $_user['api_key'] );
308 - }
309 -
310 203 $_user['meta'] = self::get_instance()->user_meta();
311 204 }
312 205
313 206 if ( empty( $_user ) ) {
@@ -318,9 +211,9 @@
318 211
319 212 return $_response;
320 213 }
321 214
322 - public function user_meta( $meta = [] ): array {
215 + public function user_meta( $meta = [] ) {
323 216 $_meta = [
324 217 'link_account' => self::utils( 'options' )->link_account(),
325 218 'unlink_account' => self::utils( 'options' )->unlink_account(),
326 219 'is_globally_signed' => Login::is_globally_signed(),
@@ -325,9 +218,8 @@
325 218 'unlink_account' => self::utils( 'options' )->unlink_account(),
326 219 'is_globally_signed' => Login::is_globally_signed(),
327 220 'signed_as_global' => Login::signed_as_global(),
328 221 'starred' => self::utils( 'options' )->get( 'favourites' ),
329 - 'reviews' => self::utils( 'options' )->get( 'reviews' ),
330 222 'cloud_activity' => self::utils( 'options' )->get( 'cloud_activity' ),
331 223 'has_api' => rest_sanitize_boolean( self::utils( 'options' )->get( 'api_key' ) )
332 224 ];
333 225
@@ -333,12 +225,12 @@
333 225
334 226 return array_merge( $_meta, $meta );
335 227 }
336 228
337 - public static function is_globally_signed(): bool {
229 + public static function is_globally_signed() {
338 230 return rest_sanitize_boolean( ( new static )->utils( 'options' )->is_globally_signed() );
339 231 }
340 232
341 - public static function signed_as_global(): bool {
233 + public static function signed_as_global() {
342 234 return rest_sanitize_boolean( ( new static )->utils( 'options' )->signed_as_global() );
343 235 }
344 -}
236 +}