| @@ -9,13 +9,19 @@ | ||
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | 11 | namespace Templately; |
| 12 | 12 | |
| 13 | +use Templately\Admin\API\Settings as APISettings; | |
| 14 | +use Templately\Admin\Settings; | |
| 15 | +use Templately\API\AIContent; | |
| 16 | +use Templately\API\LogoGeneration; | |
| 13 | 17 | use Templately\API\Conditions; |
| 14 | 18 | use Templately\API\ThemeBuilderApi; |
| 15 | 19 | use Templately\Builder\ThemeBuilder; |
| 16 | 20 | use Templately\Core\Importer\FullSiteImport; |
| 21 | +use Templately\Utils\AuthErrorCode; | |
| 17 | 22 | use Templately\Utils\Base; |
| 23 | +use Templately\Utils\Database; | |
| 18 | 24 | use Templately\Utils\Enqueue; |
| 19 | 25 | |
| 20 | 26 | use Templately\Core\Admin; |
| 21 | 27 | use Templately\Core\Module; |
| @@ -22,8 +28,9 @@ | ||
| 22 | 28 | |
| 23 | 29 | use Templately\API\Tags; |
| 24 | 30 | use Templately\API\Items; |
| 25 | 31 | use Templately\API\Login; |
| 32 | +use Templately\API\Checkout; | |
| 26 | 33 | use Templately\API\SignUp; |
| 27 | 34 | use Templately\API\Profile; |
| 28 | 35 | use Templately\API\Import; |
| 29 | 36 | use Templately\API\MyClouds; |
| @@ -31,8 +38,10 @@ | ||
| 31 | 38 | use Templately\API\Categories; |
| 32 | 39 | use Templately\API\Dependencies; |
| 33 | 40 | use Templately\API\TemplateTypes; |
| 34 | 41 | use Templately\API\SavedTemplates; |
| 42 | +use Templately\API\Sites; | |
| 43 | +use Templately\API\Tour; | |
| 35 | 44 | use Templately\Core\Maintenance; |
| 36 | 45 | use Templately\Core\Migrator; |
| 37 | 46 | use Templately\Core\Platform\Gutenberg; |
| 38 | 47 | use Templately\Core\Platform\Elementor; |
| @@ -37,11 +46,12 @@ | ||
| 37 | 46 | use Templately\Core\Platform\Gutenberg; |
| 38 | 47 | use Templately\Core\Platform\Elementor; |
| 39 | 48 | |
| 40 | 49 | final class Plugin extends Base { |
| 41 | - public $version = '3.1.0'; | |
| 50 | + public $version = '3.7.2'; | |
| 42 | 51 | |
| 43 | 52 | public $admin; |
| 53 | + public $settings; | |
| 44 | 54 | /** |
| 45 | 55 | * Enqueue class responsible for assets |
| 46 | 56 | * @var Enqueue |
| 47 | 57 | */ |
| @@ -52,8 +62,13 @@ | ||
| 52 | 62 | */ |
| 53 | 63 | public $theme_builder; |
| 54 | 64 | |
| 55 | 65 | /** |
| 66 | + * @var Developer | |
| 67 | + */ | |
| 68 | + public $developer; | |
| 69 | + | |
| 70 | + /** | |
| 56 | 71 | * Plugin constructor. |
| 57 | 72 | * Initializing Templately plugin. |
| 58 | 73 | * |
| 59 | 74 | * @access private |
| @@ -65,16 +80,24 @@ | ||
| 65 | 80 | Maintenance::init(); |
| 66 | 81 | |
| 67 | 82 | $this->assets = Enqueue::get_instance( TEMPLATELY_URL, TEMPLATELY_PATH, $this->version ); |
| 68 | 83 | $this->admin = Admin::get_instance(); |
| 84 | + $this->settings = Settings::get_instance(); | |
| 69 | 85 | $this->theme_builder = ThemeBuilder::get_instance(); |
| 70 | 86 | |
| 87 | + // Initialize developer functionality if available | |
| 88 | + $this->init_developer_functionality(); | |
| 89 | + | |
| 71 | 90 | add_action( 'plugins_loaded', [ $this, 'plugins_loaded' ] ); |
| 72 | 91 | add_action( 'rest_api_init', [ $this, 'register_routes' ] ); |
| 92 | + | |
| 93 | + add_action( 'init', [ $this, 'google_login_handler' ] ); | |
| 94 | + | |
| 73 | 95 | /** |
| 74 | 96 | * Initialize. |
| 75 | 97 | */ |
| 76 | 98 | do_action( 'templately_init' ); |
| 99 | + | |
| 77 | 100 | } |
| 78 | 101 | |
| 79 | 102 | /** |
| 80 | 103 | * Cloning is forbidden. |
| @@ -113,8 +136,38 @@ | ||
| 113 | 136 | FullSiteImport::get_instance(); |
| 114 | 137 | } |
| 115 | 138 | |
| 116 | 139 | /** |
| 140 | + * Initialize developer functionality if available | |
| 141 | + * | |
| 142 | + * This method safely loads developer functionality only if the developer | |
| 143 | + * directory and class exist, preventing fatal errors in production builds. | |
| 144 | + * | |
| 145 | + * @return void | |
| 146 | + */ | |
| 147 | + private function init_developer_functionality() { | |
| 148 | + $developer_file = TEMPLATELY_PATH . 'includes/Core/Developer/Developer.php'; | |
| 149 | + | |
| 150 | + // Check if developer file exists before attempting to load | |
| 151 | + if ( file_exists( $developer_file ) ) { | |
| 152 | + // Include the developer class file | |
| 153 | + require_once $developer_file; | |
| 154 | + | |
| 155 | + // Check if the class exists after including the file | |
| 156 | + if ( class_exists( '\\Templately\\Core\\Developer\\Developer' ) ) { | |
| 157 | + $this->developer = \Templately\Core\Developer\Developer::get_instance(); | |
| 158 | + } | |
| 159 | + } | |
| 160 | + | |
| 161 | + // If developer functionality is not available, set to null | |
| 162 | + if ( ! isset( $this->developer ) ) { | |
| 163 | + $this->developer = null; | |
| 164 | + } | |
| 165 | + } | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + /** | |
| 117 | 170 | * Initialize all platforms |
| 118 | 171 | * @return void |
| 119 | 172 | */ |
| 120 | 173 | public function platforms() { |
| @@ -134,17 +187,25 @@ | ||
| 134 | 187 | Dependencies::get_instance(); |
| 135 | 188 | Tags::get_instance(); |
| 136 | 189 | ThemeBuilderApi::get_instance(); |
| 137 | 190 | |
| 191 | + AIContent::get_instance(); | |
| 192 | + LogoGeneration::get_instance(); | |
| 138 | 193 | Items::get_instance(); |
| 139 | 194 | SavedTemplates::get_instance(); |
| 140 | 195 | |
| 141 | 196 | Login::get_instance(); |
| 197 | + Checkout::get_instance(); | |
| 142 | 198 | SignUp::get_instance(); |
| 143 | 199 | Import::get_instance(); |
| 144 | 200 | Profile::get_instance(); |
| 145 | 201 | MyClouds::get_instance(); |
| 146 | 202 | WorkSpaces::get_instance(); |
| 203 | + Sites::get_instance(); | |
| 204 | + Tour::get_instance(); | |
| 205 | + | |
| 206 | + APISettings::get_instance(); | |
| 207 | + // Note: DeveloperSettings::get_instance() is called in Developer::init_modules() when developer functionality is available and enabled | |
| 147 | 208 | } |
| 148 | 209 | |
| 149 | 210 | /** |
| 150 | 211 | * Register all REST API endpoints |
| @@ -203,6 +264,106 @@ | ||
| 203 | 264 | * |
| 204 | 265 | */ |
| 205 | 266 | public function load_textdomain() { |
| 206 | 267 | load_plugin_textdomain( 'templately', false, dirname( TEMPLATELY_PLUGIN_BASENAME ) . '/languages' ); |
| 268 | + } | |
| 269 | + | |
| 270 | + public function google_login_handler() { | |
| 271 | + // Stop if not a templately google login request | |
| 272 | + if ( empty( $_GET['templately_google_login'] ) ) { | |
| 273 | + return; | |
| 274 | + } | |
| 275 | + | |
| 276 | + if ( wp_doing_ajax() || wp_doing_cron() || ( defined( 'REST_REQUEST' ) && REST_REQUEST ) ) { | |
| 277 | + return; | |
| 278 | + } | |
| 279 | + | |
| 280 | + // Checked before the token is consumed: the callback can land while the | |
| 281 | + // auth cookie is missing (expired session, cookie not yet set), and WP | |
| 282 | + // will bounce the user through wp-login and back to this same URL. | |
| 283 | + // Burning the token here would fail that legitimate retry. | |
| 284 | + if ( ! is_user_logged_in() ) { | |
| 285 | + return; | |
| 286 | + } | |
| 287 | + | |
| 288 | + $state = ''; | |
| 289 | + if ( ! empty( $_GET['templately_state'] ) ) { | |
| 290 | + $state = sanitize_text_field( wp_unslash( $_GET['templately_state'] ) ); | |
| 291 | + } elseif ( ! empty( $_GET['state'] ) ) { | |
| 292 | + $state = sanitize_text_field( wp_unslash( $_GET['state'] ) ); | |
| 293 | + } | |
| 294 | + | |
| 295 | + $state_user_id = false; | |
| 296 | + if ( ! empty( $state ) ) { | |
| 297 | + $state_user_id = Database::get_transient( 'google_state_' . $state ); | |
| 298 | + Database::delete_transient( 'google_state_' . $state ); | |
| 299 | + } | |
| 300 | + | |
| 301 | + $is_authorized = false !== $state_user_id | |
| 302 | + && intval( $state_user_id ) === get_current_user_id() | |
| 303 | + && current_user_can( 'delete_posts' ); | |
| 304 | + | |
| 305 | + $redirect_url = remove_query_arg( [ 'templately_google_login', 'templately_state', 'api_key', 'error', 'state', 'redirect-to' ] ); | |
| 306 | + | |
| 307 | + if ( ! $is_authorized ) { | |
| 308 | + $error_code = AuthErrorCode::AUTH_STATE_INVALID; | |
| 309 | + } elseif ( ! empty( $_GET['error'] ) ) { | |
| 310 | + // Google's own reason is deliberately dropped rather than forwarded: | |
| 311 | + // everything on this query string is attacker-controlled, and the | |
| 312 | + // screen that displays it must never be handed prose from the URL. | |
| 313 | + $error_code = AuthErrorCode::AUTH_PROVIDER_FAILED; | |
| 314 | + } elseif ( ! empty( $_GET['api_key'] ) ) { | |
| 315 | + $request = new \WP_REST_Request( 'POST', '/templately/v1/login' ); | |
| 316 | + $request->set_param( 'viaAPI', true ); | |
| 317 | + $request->set_param( 'api_key', sanitize_text_field( $_GET['api_key'] ) ); | |
| 318 | + | |
| 319 | + /** | |
| 320 | + * @var Login $login | |
| 321 | + */ | |
| 322 | + $login = Login::get_instance(); | |
| 323 | + $login->permission_check( $request ); | |
| 324 | + | |
| 325 | + // login() pins the write target to the acting user itself — no pin | |
| 326 | + // here, or its finally would release ours mid-request. | |
| 327 | + $response = $login->login(); | |
| 328 | + | |
| 329 | + if ( ! is_wp_error( $response ) && ! empty( $response['user'] ) ) { | |
| 330 | + $redirect_path = ! empty( $_GET['redirect-to'] ) ? sanitize_text_field( wp_unslash( $_GET['redirect-to'] ) ) : ''; | |
| 331 | + if ( ! empty( $redirect_path ) ) { | |
| 332 | + if ( filter_var( $redirect_path, FILTER_VALIDATE_URL ) ) { | |
| 333 | + $redirect_url = $redirect_path; | |
| 334 | + } else { | |
| 335 | + $is_templately = strpos( $redirect_url, 'page=templately' ) !== false; | |
| 336 | + $is_elementor = strpos( $redirect_url, 'action=elementor' ) !== false; | |
| 337 | + // Gutenberg editor usually has action=edit or is a block editor page | |
| 338 | + $is_gutenberg = ( strpos( $redirect_url, 'action=edit' ) !== false || strpos( $redirect_url, 'post_type=' ) !== false ) && ! $is_elementor; | |
| 339 | + | |
| 340 | + if ( $is_templately || $is_elementor || $is_gutenberg ) { | |
| 341 | + $redirect_url = add_query_arg( 'path', ltrim( $redirect_path, '/' ), $redirect_url ); | |
| 342 | + | |
| 343 | + // Always open the modal in editors after google login | |
| 344 | + if ( $is_elementor || $is_gutenberg ) { | |
| 345 | + $redirect_url = add_query_arg( 'templately_open_modal', '1', $redirect_url ); | |
| 346 | + } | |
| 347 | + } | |
| 348 | + } | |
| 349 | + } | |
| 350 | + | |
| 351 | + wp_safe_redirect( $redirect_url ); | |
| 352 | + exit; | |
| 353 | + } else { | |
| 354 | + // The cloud's own wording stays server-side; the screen resolves | |
| 355 | + // its copy from the code. | |
| 356 | + $error_code = AuthErrorCode::INVALID_API_KEY; | |
| 357 | + } | |
| 358 | + } else { | |
| 359 | + $error_code = AuthErrorCode::AUTH_MISSING_API_KEY; | |
| 360 | + } | |
| 361 | + | |
| 362 | + $redirect_url = add_query_arg( [ | |
| 363 | + 'templately_error' => $error_code, | |
| 364 | + ], $redirect_url ); | |
| 365 | + | |
| 366 | + wp_safe_redirect( $redirect_url ); | |
| 367 | + exit; | |
| 207 | 368 | } |
| 208 | 369 | } |