| @@ -9,48 +9,25 @@ | ||
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | 11 | namespace Templately; |
| 12 | 12 | |
| 13 | -use Templately\Admin\API\Settings as APISettings; | |
| 14 | -use Templately\Admin\Settings; | |
| 15 | -use Templately\API\AIContent; | |
| 16 | -use Templately\API\LogoGeneration; | |
| 17 | -use Templately\API\Conditions; | |
| 18 | -use Templately\API\ThemeBuilderApi; | |
| 19 | -use Templately\Builder\ThemeBuilder; | |
| 20 | -use Templately\Core\Importer\FullSiteImport; | |
| 21 | 13 | use Templately\Utils\Base; |
| 22 | -use Templately\Utils\Database; | |
| 23 | 14 | use Templately\Utils\Enqueue; |
| 24 | 15 | |
| 25 | 16 | use Templately\Core\Admin; |
| 26 | -use Templately\Core\Module; | |
| 17 | +use Templately\Core\Platform_Registry; | |
| 18 | +use Templately\Core\Modules_Manager; | |
| 19 | +use Templately\Core\Capability_Seed; | |
| 27 | 20 | |
| 28 | -use Templately\API\Tags; | |
| 29 | -use Templately\API\Items; | |
| 30 | -use Templately\API\Login; | |
| 31 | -use Templately\API\Checkout; | |
| 32 | -use Templately\API\SignUp; | |
| 33 | -use Templately\API\Profile; | |
| 34 | -use Templately\API\Import; | |
| 35 | -use Templately\API\MyClouds; | |
| 36 | -use Templately\API\WorkSpaces; | |
| 37 | -use Templately\API\Categories; | |
| 38 | -use Templately\API\Dependencies; | |
| 39 | -use Templately\API\TemplateTypes; | |
| 40 | -use Templately\API\SavedTemplates; | |
| 41 | 21 | use Templately\API\Sites; |
| 42 | -use Templately\API\Tour; | |
| 43 | 22 | use Templately\Core\Maintenance; |
| 44 | 23 | use Templately\Core\Migrator; |
| 45 | -use Templately\Core\Platform\Gutenberg; | |
| 46 | -use Templately\Core\Platform\Elementor; | |
| 24 | +use Templately\Utils\Response\RestEnvelope; | |
| 47 | 25 | |
| 48 | 26 | final class Plugin extends Base { |
| 49 | - public $version = '3.7.1'; | |
| 27 | + public $version = '3.8.0'; | |
| 50 | 28 | |
| 51 | 29 | public $admin; |
| 52 | - public $settings; | |
| 53 | 30 | /** |
| 54 | 31 | * Enqueue class responsible for assets |
| 55 | 32 | * @var Enqueue |
| 56 | 33 | */ |
| @@ -56,18 +33,21 @@ | ||
| 56 | 33 | */ |
| 57 | 34 | public $assets; |
| 58 | 35 | |
| 59 | 36 | /** |
| 60 | - * @var ThemeBuilder | |
| 37 | + * Set by modules/theme-builder/module.php's init_hooks() (during | |
| 38 | + * Modules_Manager::boot(), inside plugins_loaded()) — NOT here in the | |
| 39 | + * constructor. ThemeBuilder is now a module-namespaced class | |
| 40 | + * (Templately\Modules\ThemeBuilder\ThemeBuilder); eagerly instantiating it | |
| 41 | + * in the constructor (which runs before plugins_loaded even fires) would | |
| 42 | + * fatal on class-not-found, since Modules_Manager hasn't registered that | |
| 43 | + * module's autoloader yet. | |
| 44 | + * | |
| 45 | + * @var \Templately\Modules\ThemeBuilder\ThemeBuilder | |
| 61 | 46 | */ |
| 62 | 47 | public $theme_builder; |
| 63 | 48 | |
| 64 | 49 | /** |
| 65 | - * @var Developer | |
| 66 | - */ | |
| 67 | - public $developer; | |
| 68 | - | |
| 69 | - /** | |
| 70 | 50 | * Plugin constructor. |
| 71 | 51 | * Initializing Templately plugin. |
| 72 | 52 | * |
| 73 | 53 | * @access private |
| @@ -79,19 +59,18 @@ | ||
| 79 | 59 | Maintenance::init(); |
| 80 | 60 | |
| 81 | 61 | $this->assets = Enqueue::get_instance( TEMPLATELY_URL, TEMPLATELY_PATH, $this->version ); |
| 82 | 62 | $this->admin = Admin::get_instance(); |
| 83 | - $this->settings = Settings::get_instance(); | |
| 84 | - $this->theme_builder = ThemeBuilder::get_instance(); | |
| 85 | 63 | |
| 86 | - // Initialize developer functionality if available | |
| 87 | - $this->init_developer_functionality(); | |
| 88 | - | |
| 89 | 64 | add_action( 'plugins_loaded', [ $this, 'plugins_loaded' ] ); |
| 90 | 65 | add_action( 'rest_api_init', [ $this, 'register_routes' ] ); |
| 91 | 66 | |
| 92 | - add_action( 'init', [ $this, 'google_login_handler' ] ); | |
| 67 | + // 043 — the single response envelope, applied on rest_post_dispatch so | |
| 68 | + // every route in the namespace is covered by construction rather than by | |
| 69 | + // each endpoint remembering to opt in. | |
| 70 | + RestEnvelope::init(); | |
| 93 | 71 | |
| 72 | + | |
| 94 | 73 | /** |
| 95 | 74 | * Initialize. |
| 96 | 75 | */ |
| 97 | 76 | do_action( 'templately_init' ); |
| @@ -103,9 +82,9 @@ | ||
| 103 | 82 | * |
| 104 | 83 | * @since 2.0 |
| 105 | 84 | */ |
| 106 | 85 | public function __clone() { |
| 107 | - _doing_it_wrong( __FUNCTION__, __( 'Cloning is forbidden.', 'templately' ), '2.0' ); | |
| 86 | + _doing_it_wrong( __FUNCTION__, esc_html__( 'Cloning is forbidden.', 'templately' ), '2.0' ); | |
| 108 | 87 | } |
| 109 | 88 | |
| 110 | 89 | /** |
| 111 | 90 | * Un-serializing instances of this class is forbidden. |
| @@ -112,9 +91,9 @@ | ||
| 112 | 91 | * |
| 113 | 92 | * @since 2.0 |
| 114 | 93 | */ |
| 115 | 94 | public function __wakeup() { |
| 116 | - _doing_it_wrong( __FUNCTION__, __( 'Un-serializing instances of this class is forbidden.', 'templately' ), '2.0' ); | |
| 95 | + _doing_it_wrong( __FUNCTION__, esc_html__( 'Un-serializing instances of this class is forbidden.', 'templately' ), '2.0' ); | |
| 117 | 96 | } |
| 118 | 97 | |
| 119 | 98 | /** |
| 120 | 99 | * Initializing Things on Plugins Loaded |
| @@ -120,91 +99,54 @@ | ||
| 120 | 99 | * Initializing Things on Plugins Loaded |
| 121 | 100 | * @return void |
| 122 | 101 | */ |
| 123 | 102 | public function plugins_loaded() { |
| 124 | - $this->platforms(); // PLATFORMS LOADED | |
| 125 | 103 | $this->apis(); // APIs LOADED |
| 126 | 104 | |
| 127 | 105 | /** |
| 128 | - * Migrator for Templately | |
| 106 | + * Host capability registry (spec 053): the seed set MUST exist before any | |
| 107 | + * module boots so is_active()/sub-feature gates can consult it. Registration | |
| 108 | + * is metadata-only — no probe runs here. | |
| 129 | 109 | */ |
| 130 | - Migrator::get_instance(); | |
| 110 | + Capability_Seed::register_all(); | |
| 131 | 111 | |
| 132 | 112 | /** |
| 133 | - * Full Site Import | |
| 113 | + * Feature modules (spec 004): auto-discovered from modules/*, booted after the | |
| 114 | + * legacy API registration so a module may depend on it. | |
| 134 | 115 | */ |
| 135 | - FullSiteImport::get_instance(); | |
| 116 | + Modules_Manager::get_instance()->boot(); | |
| 117 | + | |
| 118 | + /** | |
| 119 | + * Migrator for Templately | |
| 120 | + */ | |
| 121 | + Migrator::get_instance(); | |
| 136 | 122 | } |
| 137 | 123 | |
| 138 | 124 | /** |
| 139 | - * Initialize developer functionality if available | |
| 125 | + * All the API instantiated | |
| 140 | 126 | * |
| 141 | - * This method safely loads developer functionality only if the developer | |
| 142 | - * directory and class exist, preventing fatal errors in production builds. | |
| 127 | + * Every other legacy API endpoint (ThemeBuilderApi, Tour, Conditions, ...) | |
| 128 | + * migrated to its own module's register_rest_routes(), booted lazily on | |
| 129 | + * rest_api_init (Phase 2 extraction, specs 013-037 — see | |
| 130 | + * docs/modularization-prd.md). Sites is the one REST endpoint with no | |
| 131 | + * owning feature spec (site-connection migration is cross-cutting | |
| 132 | + * infrastructure, not a bounded feature) — it stays here as core. | |
| 143 | 133 | * |
| 144 | - * @return void | |
| 145 | - */ | |
| 146 | - private function init_developer_functionality() { | |
| 147 | - $developer_file = TEMPLATELY_PATH . 'includes/Core/Developer/Developer.php'; | |
| 148 | - | |
| 149 | - // Check if developer file exists before attempting to load | |
| 150 | - if ( file_exists( $developer_file ) ) { | |
| 151 | - // Include the developer class file | |
| 152 | - require_once $developer_file; | |
| 153 | - | |
| 154 | - // Check if the class exists after including the file | |
| 155 | - if ( class_exists( '\\Templately\\Core\\Developer\\Developer' ) ) { | |
| 156 | - $this->developer = \Templately\Core\Developer\Developer::get_instance(); | |
| 157 | - } | |
| 158 | - } | |
| 159 | - | |
| 160 | - // If developer functionality is not available, set to null | |
| 161 | - if ( ! isset( $this->developer ) ) { | |
| 162 | - $this->developer = null; | |
| 163 | - } | |
| 164 | - } | |
| 165 | - | |
| 166 | - | |
| 167 | - | |
| 168 | - /** | |
| 169 | - * Initialize all platforms | |
| 170 | - * @return void | |
| 171 | - */ | |
| 172 | - public function platforms() { | |
| 173 | - Gutenberg::get_instance(); | |
| 174 | - Elementor::get_instance(); | |
| 175 | - } | |
| 176 | - | |
| 177 | - /** | |
| 178 | - * All the API instantiated | |
| 134 | + * Both Elementor and Gutenberg platform drivers are now self-registered by | |
| 135 | + * their own module's init_hooks() (modules/elementor-integration/module.php, | |
| 136 | + * modules/gutenberg-integration/module.php) — the former platforms() method | |
| 137 | + * that used to run before this one is gone; there is nothing left to boot | |
| 138 | + * before Modules_Manager::boot() runs. | |
| 179 | 139 | * |
| 180 | 140 | * @return void |
| 181 | 141 | */ |
| 182 | 142 | private function apis() { |
| 183 | - Conditions::get_instance(); | |
| 184 | - Categories::get_instance(); | |
| 185 | - TemplateTypes::get_instance(); | |
| 186 | - Dependencies::get_instance(); | |
| 187 | - Tags::get_instance(); | |
| 188 | - ThemeBuilderApi::get_instance(); | |
| 189 | - | |
| 190 | - AIContent::get_instance(); | |
| 191 | - LogoGeneration::get_instance(); | |
| 192 | - Items::get_instance(); | |
| 193 | - SavedTemplates::get_instance(); | |
| 194 | - | |
| 195 | - Login::get_instance(); | |
| 196 | - Checkout::get_instance(); | |
| 197 | - SignUp::get_instance(); | |
| 198 | - Import::get_instance(); | |
| 199 | - Profile::get_instance(); | |
| 200 | - MyClouds::get_instance(); | |
| 201 | - WorkSpaces::get_instance(); | |
| 202 | 143 | Sites::get_instance(); |
| 203 | - Tour::get_instance(); | |
| 204 | 144 | |
| 205 | - APISettings::get_instance(); | |
| 206 | 145 | // Note: DeveloperSettings::get_instance() is called in Developer::init_modules() when developer functionality is available and enabled |
| 146 | + | |
| 147 | + // MCP Abilities (specs/041-mcp-abilities) now boots via modules/mcp-abilities/ | |
| 148 | + // module.php (Modules_Manager auto-discovery, spec 004) — see Plugin::plugins_loaded(). | |
| 207 | 149 | } |
| 208 | 150 | |
| 209 | 151 | /** |
| 210 | 152 | * Register all REST API endpoints |
| @@ -210,10 +152,17 @@ | ||
| 210 | 152 | * Register all REST API endpoints |
| 211 | 153 | * @return void |
| 212 | 154 | */ |
| 213 | 155 | public function register_routes() { |
| 214 | - if ( ! empty( $modules = Module::get_instance()->get( 'API' ) ) ) { | |
| 156 | + if ( ! empty( $modules = Platform_Registry::get_instance()->get( 'API' ) ) ) { | |
| 215 | 157 | foreach ( $modules as $module ) { |
| 158 | + // Module-owned endpoints (Templately\Modules\*) register explicitly via | |
| 159 | + // Modules_Manager::boot_rest_routes (constitution §VIII). They can still | |
| 160 | + // land in this legacy registry through the shared API base constructor if | |
| 161 | + // something instantiates them early — skip them so routes register once. | |
| 162 | + if ( 0 === strpos( get_class( $module->object ), 'Templately\\Modules\\' ) ) { | |
| 163 | + continue; | |
| 164 | + } | |
| 216 | 165 | $module->object->register_routes(); |
| 217 | 166 | } |
| 218 | 167 | } |
| 219 | 168 | } |
| @@ -265,100 +214,5 @@ | ||
| 265 | 214 | public function load_textdomain() { |
| 266 | 215 | load_plugin_textdomain( 'templately', false, dirname( TEMPLATELY_PLUGIN_BASENAME ) . '/languages' ); |
| 267 | 216 | } |
| 268 | 217 | |
| 269 | - public function google_login_handler() { | |
| 270 | - // Stop if not a templately google login request | |
| 271 | - if ( empty( $_GET['templately_google_login'] ) ) { | |
| 272 | - return; | |
| 273 | - } | |
| 274 | - | |
| 275 | - if ( wp_doing_ajax() || wp_doing_cron() || ( defined( 'REST_REQUEST' ) && REST_REQUEST ) ) { | |
| 276 | - return; | |
| 277 | - } | |
| 278 | - | |
| 279 | - // Checked before the token is consumed: the callback can land while the | |
| 280 | - // auth cookie is missing (expired session, cookie not yet set), and WP | |
| 281 | - // will bounce the user through wp-login and back to this same URL. | |
| 282 | - // Burning the token here would fail that legitimate retry. | |
| 283 | - if ( ! is_user_logged_in() ) { | |
| 284 | - return; | |
| 285 | - } | |
| 286 | - | |
| 287 | - $state = ''; | |
| 288 | - if ( ! empty( $_GET['templately_state'] ) ) { | |
| 289 | - $state = sanitize_text_field( wp_unslash( $_GET['templately_state'] ) ); | |
| 290 | - } elseif ( ! empty( $_GET['state'] ) ) { | |
| 291 | - $state = sanitize_text_field( wp_unslash( $_GET['state'] ) ); | |
| 292 | - } | |
| 293 | - | |
| 294 | - $state_user_id = false; | |
| 295 | - if ( ! empty( $state ) ) { | |
| 296 | - $state_user_id = Database::get_transient( 'google_state_' . $state ); | |
| 297 | - Database::delete_transient( 'google_state_' . $state ); | |
| 298 | - } | |
| 299 | - | |
| 300 | - $is_authorized = false !== $state_user_id | |
| 301 | - && intval( $state_user_id ) === get_current_user_id() | |
| 302 | - && current_user_can( 'delete_posts' ); | |
| 303 | - | |
| 304 | - $redirect_url = remove_query_arg( [ 'templately_google_login', 'templately_state', 'api_key', 'error', 'state', 'redirect-to' ] ); | |
| 305 | - | |
| 306 | - if ( ! $is_authorized ) { | |
| 307 | - $error_message = __( 'This sign-in link is no longer valid. Please try signing in again.', 'templately' ); | |
| 308 | - } elseif ( ! empty( $_GET['error'] ) ) { | |
| 309 | - $error_message = sanitize_text_field( $_GET['error'] ); | |
| 310 | - } elseif ( ! empty( $_GET['api_key'] ) ) { | |
| 311 | - $request = new \WP_REST_Request( 'POST', '/templately/v1/login' ); | |
| 312 | - $request->set_param( 'viaAPI', true ); | |
| 313 | - $request->set_param( 'api_key', sanitize_text_field( $_GET['api_key'] ) ); | |
| 314 | - | |
| 315 | - /** | |
| 316 | - * @var Login $login | |
| 317 | - */ | |
| 318 | - $login = Login::get_instance(); | |
| 319 | - $login->permission_check( $request ); | |
| 320 | - | |
| 321 | - // login() pins the write target to the acting user itself — no pin | |
| 322 | - // here, or its finally would release ours mid-request. | |
| 323 | - $response = $login->login(); | |
| 324 | - | |
| 325 | - if ( ! is_wp_error( $response ) && ! empty( $response['user'] ) ) { | |
| 326 | - $redirect_path = ! empty( $_GET['redirect-to'] ) ? sanitize_text_field( wp_unslash( $_GET['redirect-to'] ) ) : ''; | |
| 327 | - if ( ! empty( $redirect_path ) ) { | |
| 328 | - if ( filter_var( $redirect_path, FILTER_VALIDATE_URL ) ) { | |
| 329 | - $redirect_url = $redirect_path; | |
| 330 | - } else { | |
| 331 | - $is_templately = strpos( $redirect_url, 'page=templately' ) !== false; | |
| 332 | - $is_elementor = strpos( $redirect_url, 'action=elementor' ) !== false; | |
| 333 | - // Gutenberg editor usually has action=edit or is a block editor page | |
| 334 | - $is_gutenberg = ( strpos( $redirect_url, 'action=edit' ) !== false || strpos( $redirect_url, 'post_type=' ) !== false ) && ! $is_elementor; | |
| 335 | - | |
| 336 | - if ( $is_templately || $is_elementor || $is_gutenberg ) { | |
| 337 | - $redirect_url = add_query_arg( 'path', ltrim( $redirect_path, '/' ), $redirect_url ); | |
| 338 | - | |
| 339 | - // Always open the modal in editors after google login | |
| 340 | - if ( $is_elementor || $is_gutenberg ) { | |
| 341 | - $redirect_url = add_query_arg( 'templately_open_modal', '1', $redirect_url ); | |
| 342 | - } | |
| 343 | - } | |
| 344 | - } | |
| 345 | - } | |
| 346 | - | |
| 347 | - wp_safe_redirect( $redirect_url ); | |
| 348 | - exit; | |
| 349 | - } else { | |
| 350 | - $error_message = ( is_wp_error( $response ) ) ? $response->get_error_message() : __( 'Login failed.', 'templately' ); | |
| 351 | - } | |
| 352 | - } else { | |
| 353 | - $error_message = __( 'Missing API Key.', 'templately' ); | |
| 354 | - } | |
| 355 | - | |
| 356 | - $redirect_url = add_query_arg( [ | |
| 357 | - 'templately_error' => 'login_failed', | |
| 358 | - 'error_message' => urlencode( $error_message ), | |
| 359 | - ], $redirect_url ); | |
| 360 | - | |
| 361 | - wp_safe_redirect( $redirect_url ); | |
| 362 | - exit; | |
| 363 | - } | |
| 364 | 218 | } |