PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / trunk
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! vtrunk
3.8.0 3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 All 112 releases
← All changes | includes/Plugin.php +56 -211 3.7.4 → trunk View file →
@@ -9,51 +9,25 @@
9 9 */
10 10
11 11 namespace Templately;
12 12
13 -use Templately\Admin\API\Settings as APISettings;
14 -use Templately\Admin\Settings;
15 -use Templately\API\AIContent;
16 -use Templately\API\LogoGeneration;
17 -use Templately\API\Conditions;
18 -use Templately\API\ThemeBuilderApi;
19 -use Templately\Builder\ThemeBuilder;
20 -use Templately\Core\Importer\FullSiteImport;
21 -use Templately\Utils\AuthErrorCode;
22 13 use Templately\Utils\Base;
23 -use Templately\Utils\Database;
24 14 use Templately\Utils\Enqueue;
25 15
26 16 use Templately\Core\Admin;
27 -use Templately\Core\Module;
17 +use Templately\Core\Platform_Registry;
18 +use Templately\Core\Modules_Manager;
19 +use Templately\Core\Capability_Seed;
28 20
29 -use Templately\API\Tags;
30 -use Templately\API\Items;
31 -use Templately\API\Login;
32 -use Templately\API\Checkout;
33 -use Templately\API\SignUp;
34 -use Templately\API\AiCredit;
35 -use Templately\API\Profile;
36 -use Templately\API\Import;
37 -use Templately\API\MyClouds;
38 -use Templately\API\WorkSpaces;
39 -use Templately\API\Categories;
40 -use Templately\API\Dependencies;
41 -use Templately\API\TemplateTypes;
42 -use Templately\API\SavedTemplates;
43 21 use Templately\API\Sites;
44 -use Templately\API\Tour;
45 -use Templately\Core\DeactivationSurvey;
46 22 use Templately\Core\Maintenance;
47 23 use Templately\Core\Migrator;
48 -use Templately\Core\Platform\Gutenberg;
49 -use Templately\Core\Platform\Elementor;
24 +use Templately\Utils\Response\RestEnvelope;
50 25
51 26 final class Plugin extends Base {
52 - public $version = '3.7.4';
27 + public $version = '3.8.0';
53 28
54 29 public $admin;
55 - public $settings;
56 30 /**
57 31 * Enqueue class responsible for assets
58 32 * @var Enqueue
59 33 */
@@ -59,18 +33,21 @@
59 33 */
60 34 public $assets;
61 35
62 36 /**
63 - * @var ThemeBuilder
37 + * Set by modules/theme-builder/module.php's init_hooks() (during
38 + * Modules_Manager::boot(), inside plugins_loaded()) — NOT here in the
39 + * constructor. ThemeBuilder is now a module-namespaced class
40 + * (Templately\Modules\ThemeBuilder\ThemeBuilder); eagerly instantiating it
41 + * in the constructor (which runs before plugins_loaded even fires) would
42 + * fatal on class-not-found, since Modules_Manager hasn't registered that
43 + * module's autoloader yet.
44 + *
45 + * @var \Templately\Modules\ThemeBuilder\ThemeBuilder
64 46 */
65 47 public $theme_builder;
66 48
67 49 /**
68 - * @var Developer
69 - */
70 - public $developer;
71 -
72 - /**
73 50 * Plugin constructor.
74 51 * Initializing Templately plugin.
75 52 *
76 53 * @access private
@@ -79,23 +56,21 @@
79 56 $this->define_constants();
80 57 $this->set_locale();
81 58
82 59 Maintenance::init();
83 - DeactivationSurvey::init();
84 60
85 61 $this->assets = Enqueue::get_instance( TEMPLATELY_URL, TEMPLATELY_PATH, $this->version );
86 62 $this->admin = Admin::get_instance();
87 - $this->settings = Settings::get_instance();
88 - $this->theme_builder = ThemeBuilder::get_instance();
89 63
90 - // Initialize developer functionality if available
91 - $this->init_developer_functionality();
92 -
93 64 add_action( 'plugins_loaded', [ $this, 'plugins_loaded' ] );
94 65 add_action( 'rest_api_init', [ $this, 'register_routes' ] );
95 66
96 - add_action( 'init', [ $this, 'google_login_handler' ] );
67 + // 043 — the single response envelope, applied on rest_post_dispatch so
68 + // every route in the namespace is covered by construction rather than by
69 + // each endpoint remembering to opt in.
70 + RestEnvelope::init();
97 71
72 +
98 73 /**
99 74 * Initialize.
100 75 */
101 76 do_action( 'templately_init' );
@@ -107,9 +82,9 @@
107 82 *
108 83 * @since 2.0
109 84 */
110 85 public function __clone() {
111 - _doing_it_wrong( __FUNCTION__, __( 'Cloning is forbidden.', 'templately' ), '2.0' );
86 + _doing_it_wrong( __FUNCTION__, esc_html__( 'Cloning is forbidden.', 'templately' ), '2.0' );
112 87 }
113 88
114 89 /**
115 90 * Un-serializing instances of this class is forbidden.
@@ -116,9 +91,9 @@
116 91 *
117 92 * @since 2.0
118 93 */
119 94 public function __wakeup() {
120 - _doing_it_wrong( __FUNCTION__, __( 'Un-serializing instances of this class is forbidden.', 'templately' ), '2.0' );
95 + _doing_it_wrong( __FUNCTION__, esc_html__( 'Un-serializing instances of this class is forbidden.', 'templately' ), '2.0' );
121 96 }
122 97
123 98 /**
124 99 * Initializing Things on Plugins Loaded
@@ -124,92 +99,54 @@
124 99 * Initializing Things on Plugins Loaded
125 100 * @return void
126 101 */
127 102 public function plugins_loaded() {
128 - $this->platforms(); // PLATFORMS LOADED
129 103 $this->apis(); // APIs LOADED
130 104
131 105 /**
132 - * Migrator for Templately
106 + * Host capability registry (spec 053): the seed set MUST exist before any
107 + * module boots so is_active()/sub-feature gates can consult it. Registration
108 + * is metadata-only — no probe runs here.
133 109 */
134 - Migrator::get_instance();
110 + Capability_Seed::register_all();
135 111
136 112 /**
137 - * Full Site Import
113 + * Feature modules (spec 004): auto-discovered from modules/*, booted after the
114 + * legacy API registration so a module may depend on it.
138 115 */
139 - FullSiteImport::get_instance();
116 + Modules_Manager::get_instance()->boot();
117 +
118 + /**
119 + * Migrator for Templately
120 + */
121 + Migrator::get_instance();
140 122 }
141 123
142 124 /**
143 - * Initialize developer functionality if available
125 + * All the API instantiated
144 126 *
145 - * This method safely loads developer functionality only if the developer
146 - * directory and class exist, preventing fatal errors in production builds.
127 + * Every other legacy API endpoint (ThemeBuilderApi, Tour, Conditions, ...)
128 + * migrated to its own module's register_rest_routes(), booted lazily on
129 + * rest_api_init (Phase 2 extraction, specs 013-037 — see
130 + * docs/modularization-prd.md). Sites is the one REST endpoint with no
131 + * owning feature spec (site-connection migration is cross-cutting
132 + * infrastructure, not a bounded feature) — it stays here as core.
147 133 *
148 - * @return void
149 - */
150 - private function init_developer_functionality() {
151 - $developer_file = TEMPLATELY_PATH . 'includes/Core/Developer/Developer.php';
152 -
153 - // Check if developer file exists before attempting to load
154 - if ( file_exists( $developer_file ) ) {
155 - // Include the developer class file
156 - require_once $developer_file;
157 -
158 - // Check if the class exists after including the file
159 - if ( class_exists( '\\Templately\\Core\\Developer\\Developer' ) ) {
160 - $this->developer = \Templately\Core\Developer\Developer::get_instance();
161 - }
162 - }
163 -
164 - // If developer functionality is not available, set to null
165 - if ( ! isset( $this->developer ) ) {
166 - $this->developer = null;
167 - }
168 - }
169 -
170 -
171 -
172 - /**
173 - * Initialize all platforms
174 - * @return void
175 - */
176 - public function platforms() {
177 - Gutenberg::get_instance();
178 - Elementor::get_instance();
179 - }
180 -
181 - /**
182 - * All the API instantiated
134 + * Both Elementor and Gutenberg platform drivers are now self-registered by
135 + * their own module's init_hooks() (modules/elementor-integration/module.php,
136 + * modules/gutenberg-integration/module.php) — the former platforms() method
137 + * that used to run before this one is gone; there is nothing left to boot
138 + * before Modules_Manager::boot() runs.
183 139 *
184 140 * @return void
185 141 */
186 142 private function apis() {
187 - Conditions::get_instance();
188 - Categories::get_instance();
189 - TemplateTypes::get_instance();
190 - Dependencies::get_instance();
191 - Tags::get_instance();
192 - ThemeBuilderApi::get_instance();
193 -
194 - AIContent::get_instance();
195 - LogoGeneration::get_instance();
196 - Items::get_instance();
197 - SavedTemplates::get_instance();
198 -
199 - Login::get_instance();
200 - Checkout::get_instance();
201 - SignUp::get_instance();
202 - Import::get_instance();
203 - Profile::get_instance();
204 - AiCredit::get_instance();
205 - MyClouds::get_instance();
206 - WorkSpaces::get_instance();
207 143 Sites::get_instance();
208 - Tour::get_instance();
209 144
210 - APISettings::get_instance();
211 145 // Note: DeveloperSettings::get_instance() is called in Developer::init_modules() when developer functionality is available and enabled
146 +
147 + // MCP Abilities (specs/041-mcp-abilities) now boots via modules/mcp-abilities/
148 + // module.php (Modules_Manager auto-discovery, spec 004) — see Plugin::plugins_loaded().
212 149 }
213 150
214 151 /**
215 152 * Register all REST API endpoints
@@ -215,10 +152,17 @@
215 152 * Register all REST API endpoints
216 153 * @return void
217 154 */
218 155 public function register_routes() {
219 - if ( ! empty( $modules = Module::get_instance()->get( 'API' ) ) ) {
156 + if ( ! empty( $modules = Platform_Registry::get_instance()->get( 'API' ) ) ) {
220 157 foreach ( $modules as $module ) {
158 + // Module-owned endpoints (Templately\Modules\*) register explicitly via
159 + // Modules_Manager::boot_rest_routes (constitution §VIII). They can still
160 + // land in this legacy registry through the shared API base constructor if
161 + // something instantiates them early — skip them so routes register once.
162 + if ( 0 === strpos( get_class( $module->object ), 'Templately\\Modules\\' ) ) {
163 + continue;
164 + }
221 165 $module->object->register_routes();
222 166 }
223 167 }
224 168 }
@@ -270,104 +214,5 @@
270 214 public function load_textdomain() {
271 215 load_plugin_textdomain( 'templately', false, dirname( TEMPLATELY_PLUGIN_BASENAME ) . '/languages' );
272 216 }
273 217
274 - public function google_login_handler() {
275 - // Stop if not a templately google login request
276 - if ( empty( $_GET['templately_google_login'] ) ) {
277 - return;
278 - }
279 -
280 - if ( wp_doing_ajax() || wp_doing_cron() || ( defined( 'REST_REQUEST' ) && REST_REQUEST ) ) {
281 - return;
282 - }
283 -
284 - // Checked before the token is consumed: the callback can land while the
285 - // auth cookie is missing (expired session, cookie not yet set), and WP
286 - // will bounce the user through wp-login and back to this same URL.
287 - // Burning the token here would fail that legitimate retry.
288 - if ( ! is_user_logged_in() ) {
289 - return;
290 - }
291 -
292 - $state = '';
293 - if ( ! empty( $_GET['templately_state'] ) ) {
294 - $state = sanitize_text_field( wp_unslash( $_GET['templately_state'] ) );
295 - } elseif ( ! empty( $_GET['state'] ) ) {
296 - $state = sanitize_text_field( wp_unslash( $_GET['state'] ) );
297 - }
298 -
299 - $state_user_id = false;
300 - if ( ! empty( $state ) ) {
301 - $state_user_id = Database::get_transient( 'google_state_' . $state );
302 - Database::delete_transient( 'google_state_' . $state );
303 - }
304 -
305 - $is_authorized = false !== $state_user_id
306 - && intval( $state_user_id ) === get_current_user_id()
307 - && current_user_can( 'delete_posts' );
308 -
309 - $redirect_url = remove_query_arg( [ 'templately_google_login', 'templately_state', 'api_key', 'error', 'state', 'redirect-to' ] );
310 -
311 - if ( ! $is_authorized ) {
312 - $error_code = AuthErrorCode::AUTH_STATE_INVALID;
313 - } elseif ( ! empty( $_GET['error'] ) ) {
314 - // Google's own reason is deliberately dropped rather than forwarded:
315 - // everything on this query string is attacker-controlled, and the
316 - // screen that displays it must never be handed prose from the URL.
317 - $error_code = AuthErrorCode::AUTH_PROVIDER_FAILED;
318 - } elseif ( ! empty( $_GET['api_key'] ) ) {
319 - $request = new \WP_REST_Request( 'POST', '/templately/v1/login' );
320 - $request->set_param( 'viaAPI', true );
321 - $request->set_param( 'api_key', sanitize_text_field( $_GET['api_key'] ) );
322 -
323 - /**
324 - * @var Login $login
325 - */
326 - $login = Login::get_instance();
327 - $login->permission_check( $request );
328 -
329 - // login() pins the write target to the acting user itself — no pin
330 - // here, or its finally would release ours mid-request.
331 - $response = $login->login();
332 -
333 - if ( ! is_wp_error( $response ) && ! empty( $response['user'] ) ) {
334 - $redirect_path = ! empty( $_GET['redirect-to'] ) ? sanitize_text_field( wp_unslash( $_GET['redirect-to'] ) ) : '';
335 - if ( ! empty( $redirect_path ) ) {
336 - if ( filter_var( $redirect_path, FILTER_VALIDATE_URL ) ) {
337 - $redirect_url = $redirect_path;
338 - } else {
339 - $is_templately = strpos( $redirect_url, 'page=templately' ) !== false;
340 - $is_elementor = strpos( $redirect_url, 'action=elementor' ) !== false;
341 - // Gutenberg editor usually has action=edit or is a block editor page
342 - $is_gutenberg = ( strpos( $redirect_url, 'action=edit' ) !== false || strpos( $redirect_url, 'post_type=' ) !== false ) && ! $is_elementor;
343 -
344 - if ( $is_templately || $is_elementor || $is_gutenberg ) {
345 - $redirect_url = add_query_arg( 'path', ltrim( $redirect_path, '/' ), $redirect_url );
346 -
347 - // Always open the modal in editors after google login
348 - if ( $is_elementor || $is_gutenberg ) {
349 - $redirect_url = add_query_arg( 'templately_open_modal', '1', $redirect_url );
350 - }
351 - }
352 - }
353 - }
354 -
355 - wp_safe_redirect( $redirect_url );
356 - exit;
357 - } else {
358 - // The cloud's own wording stays server-side; the screen resolves
359 - // its copy from the code.
360 - $error_code = AuthErrorCode::INVALID_API_KEY;
361 - }
362 - } else {
363 - $error_code = AuthErrorCode::AUTH_MISSING_API_KEY;
364 - }
365 -
366 - $redirect_url = add_query_arg( [
367 - 'templately_error' => $error_code,
368 - ], $redirect_url );
369 -
370 - wp_safe_redirect( $redirect_url );
371 - exit;
372 - }
373 218 }