PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / 3.5.2
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! v3.5.2
3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.10 All 111 releases
← All changes | includes/Utils/Helper.php +8 -150 3.7.23.5.2 View file →
@@ -56,49 +56,24 @@
56 56
57 57 /**
58 58 * Collect IP from request.
59 59 *
60 - * Prefers REMOTE_ADDR since it cannot be spoofed by the client. When it is
61 - * a private/reserved address (reverse proxy, Docker bridge gateway like
62 - * 192.168.65.1, local dev), the forwarded headers are scanned for the first
63 - * public IP. If nothing public is found, the request is local: 127.0.0.1.
64 - *
65 60 * @return string
66 61 */
67 62 public static function get_ip() {
68 - $remote_addr = ! empty($_SERVER['REMOTE_ADDR']) ? sanitize_text_field($_SERVER['REMOTE_ADDR']) : '';
69 -
70 - if (self::is_public_ip($remote_addr)) {
71 - return $remote_addr;
63 + $ip = '127.0.0.1'; // Local IP
64 + if (! empty($_SERVER['HTTP_CLIENT_IP'])) {
65 + $ip = $_SERVER['HTTP_CLIENT_IP'];
66 + } elseif (! empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {
67 + $ip = $_SERVER['HTTP_X_FORWARDED_FOR'];
68 + } else {
69 + $ip = ! empty($_SERVER['REMOTE_ADDR']) ? $_SERVER['REMOTE_ADDR'] : $ip;
72 70 }
73 71
74 - foreach (['HTTP_X_FORWARDED_FOR', 'HTTP_CLIENT_IP'] as $header) {
75 - if (empty($_SERVER[$header])) {
76 - continue;
77 - }
78 - $candidates = explode(',', sanitize_text_field($_SERVER[$header]));
79 - foreach ($candidates as $candidate) {
80 - $candidate = trim($candidate);
81 - if (self::is_public_ip($candidate)) {
82 - return $candidate;
83 - }
84 - }
85 - }
86 -
87 - return '127.0.0.1';
72 + return sanitize_text_field($ip);
88 73 }
89 74
90 75 /**
91 - * Check whether a string is a valid public (non-private, non-reserved) IP.
92 - *
93 - * @param string $ip
94 - * @return bool
95 - */
96 - private static function is_public_ip($ip): bool {
97 - return (bool) filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE);
98 - }
99 -
100 - /**
101 76 * Get views for front-end display
102 77 *
103 78 * @param string $name it will be file name only from the view's folder.
104 79 * @param array $data
@@ -151,13 +126,8 @@
151 126 'Authorization' => 'Bearer ' . $api_key,
152 127 'x-templately-ip' => self::get_ip(),
153 128 'x-templately-url' => home_url('/'),
154 129 'x-templately-version' => defined( 'TEMPLATELY_VERSION' ) ? constant( 'TEMPLATELY_VERSION' ) : '1.0.0',
155 - // Force JSON responses so the cloud returns JSON errors instead of an HTML
156 - // error page (which json_decode() cannot parse). Binary/XML downloads
157 - // (zip pack, attachment WXR) use their own wp_remote_* calls and bypass
158 - // this helper, so they are unaffected. Callers can override via $extra_headers.
159 - 'Accept' => 'application/json',
160 130 ];
161 131
162 132 // Add Content-Type for POST requests
163 133 if (strtoupper($method) === 'POST') {
@@ -163,15 +133,8 @@
163 133 if (strtoupper($method) === 'POST') {
164 134 $headers['Content-Type'] = 'application/json';
165 135 }
166 136
167 - // Resolve requested platform: $_REQUEST wins (frontend-supplied), then caller's extra_headers, then default.
168 - if ( isset( $_REQUEST['requested_platform'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
169 - $extra_headers['x-templately-requested-platform'] = sanitize_text_field( wp_unslash( $_REQUEST['requested_platform'] ) );
170 - } elseif ( ! isset( $extra_headers['x-templately-requested-platform'] ) ) {
171 - $extra_headers['x-templately-requested-platform'] = 'templately';
172 - }
173 -
174 137 // Merge additional headers
175 138 $headers = array_merge($headers, $extra_headers);
176 139
177 140 $args = [
@@ -259,46 +222,8 @@
259 222 return $sanitized_value;
260 223 }
261 224
262 225 /**
263 - * Escape a string for safe embedding inside a GraphQL or JSON string literal.
264 - *
265 - * GraphQL string escaping rules are identical to JSON string escaping (per the
266 - * GraphQL spec), so wp_json_encode() is the authoritative escaper. We strip the
267 - * outer quotes it adds and return only the escaped inner content, ready to be
268 - * wrapped in your own quote pair.
269 - *
270 - * Handles pre-encoded JSON: when the caller has already run json_encode() +
271 - * wp_slash() on a value (e.g. categories, dependencies in Items.php), the
272 - * quotes are already escaped as \" and the string is ready to embed. Calling
273 - * wp_json_encode() again would double-escape those backslashes. We detect this
274 - * case by checking whether wp_unslash() produces valid JSON, and if so, return
275 - * the value directly without further encoding.
276 - *
277 - * @param string $value Raw string or wp_slash(json_encode()) output.
278 - * @return string Escaped string, safe to place between double quotes in GraphQL/JSON.
279 - */
280 - public static function esc_json_string( $value ) {
281 - $value = (string) $value;
282 -
283 - // If wp_slash() was applied to a JSON string upstream, the quotes are
284 - // already escaped (e.g. {\"key\":\"val\"}). Detect this by unslashing and
285 - // checking for valid JSON — if it matches, the value is already suitable
286 - // for embedding in a string literal; return it as-is to avoid doubling backslashes.
287 - $unslashed = wp_unslash( $value );
288 - if ( $unslashed !== $value ) {
289 - $decoded = json_decode( $unslashed, true );
290 - if ( json_last_error() === JSON_ERROR_NONE && null !== $decoded ) {
291 - return $value;
292 - }
293 - }
294 -
295 - $encoded = wp_json_encode( $value );
296 - // wp_json_encode wraps the value in "...", strip those outer quotes.
297 - return substr( $encoded, 1, -1 );
298 - }
299 -
300 - /**
301 226 * Check for X-Templately-Verified header and update user verification status
302 227 *
303 228 * @param array|WP_Error $response The HTTP response array from wp_remote_get/wp_remote_post
304 229 * @return void
@@ -747,74 +672,7 @@
747 672 $r[$key] = $value;
748 673 }
749 674 }
750 675 return $r;
751 - }
752 -
753 - /**
754 - * Creates the plugin's working directory under wp-uploads and blocks direct
755 - * web access to it.
756 - *
757 - * Everything the importer needs on disk lands here: the extracted pack (its
758 - * WXR, its template JSON, its attachments), the AI-generated page JSON, and
759 - * the FSI logs. wp-uploads is web-served, so these paths are not private just
760 - * because their session id is a uuid — the guards are what makes them
761 - * unreadable, not the name.
762 - *
763 - * .htaccess covers Apache and is inherited by everything below this point;
764 - * web.config covers IIS; index.php stops a directory listing on any server.
765 - * nginx honours none of them, so an nginx site still needs a location rule —
766 - * this raises the floor, it does not replace server configuration.
767 - *
768 - * @param string $dir Absolute path to create and protect.
769 - *
770 - * @return bool Whether the directory exists and is usable.
771 - */
772 - public static function protect_directory( $dir ) {
773 - if ( empty( $dir ) ) {
774 - return false;
775 - }
776 -
777 - if ( ! is_dir( $dir ) && ! wp_mkdir_p( $dir ) ) {
778 - return false;
779 - }
780 -
781 - $guards = [
782 - 'index.php' => "<?php\n// Silence is golden.\n",
783 - '.htaccess' => "# Templately working files — not for direct access.\n<IfModule mod_authz_core.c>\n\tRequire all denied\n</IfModule>\n<IfModule !mod_authz_core.c>\n\tOrder allow,deny\n\tDeny from all\n</IfModule>\n",
784 - 'web.config' => "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<configuration>\n\t<system.webServer>\n\t\t<authorization>\n\t\t\t<deny users=\"*\" />\n\t\t</authorization>\n\t</system.webServer>\n</configuration>\n",
785 - ];
786 -
787 - foreach ( $guards as $file => $contents ) {
788 - $path = trailingslashit( $dir ) . $file;
789 - // Never overwrite: a site owner may have relaxed these deliberately.
790 - if ( ! file_exists( $path ) ) {
791 - @file_put_contents( $path, $contents ); // phpcs:ignore
792 - }
793 - }
794 -
795 - return true;
796 - }
797 -
798 - /**
799 - * Absolute path to the plugin's protected working directory in wp-uploads.
800 - *
801 - * @param string $sub Optional subdirectory ('tmp', 'log', 'preview', ...).
802 - *
803 - * @return string Trailing-slashed path, or '' when uploads is unusable.
804 - */
805 - public static function upload_dir( $sub = '' ) {
806 - $upload_dir = wp_upload_dir();
807 -
808 - if ( ! empty( $upload_dir['error'] ) || empty( $upload_dir['basedir'] ) ) {
809 - return '';
810 - }
811 -
812 - $base = trailingslashit( $upload_dir['basedir'] ) . 'templately' . DIRECTORY_SEPARATOR;
813 -
814 - // The guards go on the root so every subdirectory inherits them.
815 - self::protect_directory( $base );
816 -
817 - return '' === $sub ? $base : trailingslashit( $base . $sub );
818 676 }
819 677
820 678 }