PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / 3.7.2
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! v3.7.2
3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.10 All 111 releases
← All changes | includes/Plugin.php +162 -1 3.0.93.7.2 View file →
@@ -9,13 +9,19 @@
9 9 */
10 10
11 11 namespace Templately;
12 12
13 +use Templately\Admin\API\Settings as APISettings;
14 +use Templately\Admin\Settings;
15 +use Templately\API\AIContent;
16 +use Templately\API\LogoGeneration;
13 17 use Templately\API\Conditions;
14 18 use Templately\API\ThemeBuilderApi;
15 19 use Templately\Builder\ThemeBuilder;
16 20 use Templately\Core\Importer\FullSiteImport;
21 +use Templately\Utils\AuthErrorCode;
17 22 use Templately\Utils\Base;
23 +use Templately\Utils\Database;
18 24 use Templately\Utils\Enqueue;
19 25
20 26 use Templately\Core\Admin;
21 27 use Templately\Core\Module;
@@ -22,8 +28,9 @@
22 28
23 29 use Templately\API\Tags;
24 30 use Templately\API\Items;
25 31 use Templately\API\Login;
32 +use Templately\API\Checkout;
26 33 use Templately\API\SignUp;
27 34 use Templately\API\Profile;
28 35 use Templately\API\Import;
29 36 use Templately\API\MyClouds;
@@ -31,8 +38,10 @@
31 38 use Templately\API\Categories;
32 39 use Templately\API\Dependencies;
33 40 use Templately\API\TemplateTypes;
34 41 use Templately\API\SavedTemplates;
42 +use Templately\API\Sites;
43 +use Templately\API\Tour;
35 44 use Templately\Core\Maintenance;
36 45 use Templately\Core\Migrator;
37 46 use Templately\Core\Platform\Gutenberg;
38 47 use Templately\Core\Platform\Elementor;
@@ -37,11 +46,12 @@
37 46 use Templately\Core\Platform\Gutenberg;
38 47 use Templately\Core\Platform\Elementor;
39 48
40 49 final class Plugin extends Base {
41 - public $version = '3.0.9';
50 + public $version = '3.7.2';
42 51
43 52 public $admin;
53 + public $settings;
44 54 /**
45 55 * Enqueue class responsible for assets
46 56 * @var Enqueue
47 57 */
@@ -52,8 +62,13 @@
52 62 */
53 63 public $theme_builder;
54 64
55 65 /**
66 + * @var Developer
67 + */
68 + public $developer;
69 +
70 + /**
56 71 * Plugin constructor.
57 72 * Initializing Templately plugin.
58 73 *
59 74 * @access private
@@ -65,16 +80,24 @@
65 80 Maintenance::init();
66 81
67 82 $this->assets = Enqueue::get_instance( TEMPLATELY_URL, TEMPLATELY_PATH, $this->version );
68 83 $this->admin = Admin::get_instance();
84 + $this->settings = Settings::get_instance();
69 85 $this->theme_builder = ThemeBuilder::get_instance();
70 86
87 + // Initialize developer functionality if available
88 + $this->init_developer_functionality();
89 +
71 90 add_action( 'plugins_loaded', [ $this, 'plugins_loaded' ] );
72 91 add_action( 'rest_api_init', [ $this, 'register_routes' ] );
92 +
93 + add_action( 'init', [ $this, 'google_login_handler' ] );
94 +
73 95 /**
74 96 * Initialize.
75 97 */
76 98 do_action( 'templately_init' );
99 +
77 100 }
78 101
79 102 /**
80 103 * Cloning is forbidden.
@@ -113,8 +136,38 @@
113 136 FullSiteImport::get_instance();
114 137 }
115 138
116 139 /**
140 + * Initialize developer functionality if available
141 + *
142 + * This method safely loads developer functionality only if the developer
143 + * directory and class exist, preventing fatal errors in production builds.
144 + *
145 + * @return void
146 + */
147 + private function init_developer_functionality() {
148 + $developer_file = TEMPLATELY_PATH . 'includes/Core/Developer/Developer.php';
149 +
150 + // Check if developer file exists before attempting to load
151 + if ( file_exists( $developer_file ) ) {
152 + // Include the developer class file
153 + require_once $developer_file;
154 +
155 + // Check if the class exists after including the file
156 + if ( class_exists( '\\Templately\\Core\\Developer\\Developer' ) ) {
157 + $this->developer = \Templately\Core\Developer\Developer::get_instance();
158 + }
159 + }
160 +
161 + // If developer functionality is not available, set to null
162 + if ( ! isset( $this->developer ) ) {
163 + $this->developer = null;
164 + }
165 + }
166 +
167 +
168 +
169 + /**
117 170 * Initialize all platforms
118 171 * @return void
119 172 */
120 173 public function platforms() {
@@ -134,17 +187,25 @@
134 187 Dependencies::get_instance();
135 188 Tags::get_instance();
136 189 ThemeBuilderApi::get_instance();
137 190
191 + AIContent::get_instance();
192 + LogoGeneration::get_instance();
138 193 Items::get_instance();
139 194 SavedTemplates::get_instance();
140 195
141 196 Login::get_instance();
197 + Checkout::get_instance();
142 198 SignUp::get_instance();
143 199 Import::get_instance();
144 200 Profile::get_instance();
145 201 MyClouds::get_instance();
146 202 WorkSpaces::get_instance();
203 + Sites::get_instance();
204 + Tour::get_instance();
205 +
206 + APISettings::get_instance();
207 + // Note: DeveloperSettings::get_instance() is called in Developer::init_modules() when developer functionality is available and enabled
147 208 }
148 209
149 210 /**
150 211 * Register all REST API endpoints
@@ -203,6 +264,106 @@
203 264 *
204 265 */
205 266 public function load_textdomain() {
206 267 load_plugin_textdomain( 'templately', false, dirname( TEMPLATELY_PLUGIN_BASENAME ) . '/languages' );
268 + }
269 +
270 + public function google_login_handler() {
271 + // Stop if not a templately google login request
272 + if ( empty( $_GET['templately_google_login'] ) ) {
273 + return;
274 + }
275 +
276 + if ( wp_doing_ajax() || wp_doing_cron() || ( defined( 'REST_REQUEST' ) && REST_REQUEST ) ) {
277 + return;
278 + }
279 +
280 + // Checked before the token is consumed: the callback can land while the
281 + // auth cookie is missing (expired session, cookie not yet set), and WP
282 + // will bounce the user through wp-login and back to this same URL.
283 + // Burning the token here would fail that legitimate retry.
284 + if ( ! is_user_logged_in() ) {
285 + return;
286 + }
287 +
288 + $state = '';
289 + if ( ! empty( $_GET['templately_state'] ) ) {
290 + $state = sanitize_text_field( wp_unslash( $_GET['templately_state'] ) );
291 + } elseif ( ! empty( $_GET['state'] ) ) {
292 + $state = sanitize_text_field( wp_unslash( $_GET['state'] ) );
293 + }
294 +
295 + $state_user_id = false;
296 + if ( ! empty( $state ) ) {
297 + $state_user_id = Database::get_transient( 'google_state_' . $state );
298 + Database::delete_transient( 'google_state_' . $state );
299 + }
300 +
301 + $is_authorized = false !== $state_user_id
302 + && intval( $state_user_id ) === get_current_user_id()
303 + && current_user_can( 'delete_posts' );
304 +
305 + $redirect_url = remove_query_arg( [ 'templately_google_login', 'templately_state', 'api_key', 'error', 'state', 'redirect-to' ] );
306 +
307 + if ( ! $is_authorized ) {
308 + $error_code = AuthErrorCode::AUTH_STATE_INVALID;
309 + } elseif ( ! empty( $_GET['error'] ) ) {
310 + // Google's own reason is deliberately dropped rather than forwarded:
311 + // everything on this query string is attacker-controlled, and the
312 + // screen that displays it must never be handed prose from the URL.
313 + $error_code = AuthErrorCode::AUTH_PROVIDER_FAILED;
314 + } elseif ( ! empty( $_GET['api_key'] ) ) {
315 + $request = new \WP_REST_Request( 'POST', '/templately/v1/login' );
316 + $request->set_param( 'viaAPI', true );
317 + $request->set_param( 'api_key', sanitize_text_field( $_GET['api_key'] ) );
318 +
319 + /**
320 + * @var Login $login
321 + */
322 + $login = Login::get_instance();
323 + $login->permission_check( $request );
324 +
325 + // login() pins the write target to the acting user itself — no pin
326 + // here, or its finally would release ours mid-request.
327 + $response = $login->login();
328 +
329 + if ( ! is_wp_error( $response ) && ! empty( $response['user'] ) ) {
330 + $redirect_path = ! empty( $_GET['redirect-to'] ) ? sanitize_text_field( wp_unslash( $_GET['redirect-to'] ) ) : '';
331 + if ( ! empty( $redirect_path ) ) {
332 + if ( filter_var( $redirect_path, FILTER_VALIDATE_URL ) ) {
333 + $redirect_url = $redirect_path;
334 + } else {
335 + $is_templately = strpos( $redirect_url, 'page=templately' ) !== false;
336 + $is_elementor = strpos( $redirect_url, 'action=elementor' ) !== false;
337 + // Gutenberg editor usually has action=edit or is a block editor page
338 + $is_gutenberg = ( strpos( $redirect_url, 'action=edit' ) !== false || strpos( $redirect_url, 'post_type=' ) !== false ) && ! $is_elementor;
339 +
340 + if ( $is_templately || $is_elementor || $is_gutenberg ) {
341 + $redirect_url = add_query_arg( 'path', ltrim( $redirect_path, '/' ), $redirect_url );
342 +
343 + // Always open the modal in editors after google login
344 + if ( $is_elementor || $is_gutenberg ) {
345 + $redirect_url = add_query_arg( 'templately_open_modal', '1', $redirect_url );
346 + }
347 + }
348 + }
349 + }
350 +
351 + wp_safe_redirect( $redirect_url );
352 + exit;
353 + } else {
354 + // The cloud's own wording stays server-side; the screen resolves
355 + // its copy from the code.
356 + $error_code = AuthErrorCode::INVALID_API_KEY;
357 + }
358 + } else {
359 + $error_code = AuthErrorCode::AUTH_MISSING_API_KEY;
360 + }
361 +
362 + $redirect_url = add_query_arg( [
363 + 'templately_error' => $error_code,
364 + ], $redirect_url );
365 +
366 + wp_safe_redirect( $redirect_url );
367 + exit;
207 368 }
208 369 }