| 1 |
<?php |
| 2 |
|
| 3 |
namespace Templately\Modules\Settings; |
| 4 |
|
| 5 |
use Templately\Utils\Base; |
| 6 |
use Templately\Utils\Helper; |
| 7 |
|
| 8 |
class Settings extends Base { |
| 9 |
|
| 10 |
public function __construct() { |
| 11 |
add_action('admin_menu', [$this, 'admin_menu']); |
| 12 |
add_action('wp_head', [$this, 'add_custom_css']); |
| 13 |
} |
| 14 |
|
| 15 |
public function admin_menu() { |
| 16 |
// No $position — see the note in Core/Admin.php::admin_menu(). The old |
| 17 |
// '58.7' was a copied top-level slot, past the end of this submenu, so |
| 18 |
// it always appended; below WP 6.0 it also warned on every admin load. |
| 19 |
add_submenu_page( 'templately', 'Settings', 'Settings', 'delete_posts', 'templately_settings', [$this, 'display_settings'] ); |
| 20 |
} |
| 21 |
|
| 22 |
|
| 23 |
public function display_settings() { |
| 24 |
Helper::views( 'settings' ); |
| 25 |
} |
| 26 |
|
| 27 |
public function add_custom_css() { |
| 28 |
$custom_css = get_option('templately_custom_css'); |
| 29 |
if($custom_css){ |
| 30 |
// Strip tags before echoing INSIDE the <style> element: a stored value |
| 31 |
// containing `</style><script>…` would otherwise break out of it. |
| 32 |
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- the wrapper is a literal; the value is tag-stripped above. |
| 33 |
echo "\n<style id='templately-custom-css'>\n" . wp_strip_all_tags( $custom_css ) . "\n</style>\n"; |
| 34 |
} |
| 35 |
} |
| 36 |
} |
| 37 |
|