| @@ -5,10 +5,12 @@ | ||
| 5 | 5 | * @package Timetics |
| 6 | 6 | */ |
| 7 | 7 | namespace Timetics\Core\Staffs; |
| 8 | 8 | |
| 9 | +defined( 'ABSPATH' ) || exit; | |
| 10 | + | |
| 11 | +use Timetics\Core\Staffs\Onboard; | |
| 9 | 12 | use Timetics\Utils\Singleton; |
| 10 | -use Timetics\Core\Staffs\Onboard; | |
| 11 | 13 | |
| 12 | 14 | class Hooks { |
| 13 | 15 | use Singleton; |
| 14 | 16 | |
| @@ -17,21 +19,22 @@ | ||
| 17 | 19 | * |
| 18 | 20 | * @return void |
| 19 | 21 | */ |
| 20 | 22 | public function init() { |
| 21 | - add_filter( 'retrieve_password_notification_email', [ $this, 'reset_email_content' ], 10, 4 ); | |
| 23 | + add_filter( 'retrieve_password_notification_email', [$this, 'reset_email_content'], 10, 4 ); | |
| 22 | 24 | add_filter( 'retrieve_password_title', [$this, 'reset_email_title'] ); |
| 23 | 25 | |
| 24 | - add_action( 'after_password_reset', [ $this, 'update_staff_status' ] ); | |
| 26 | + add_action( 'after_password_reset', [$this, 'update_staff_status'] ); | |
| 25 | 27 | |
| 26 | - add_filter( 'user_row_actions', [ $this, 'user_row_action' ], 10, 2 ); | |
| 28 | + add_filter( 'user_row_actions', [$this, 'user_row_action'], 10, 2 ); | |
| 27 | 29 | |
| 28 | - add_action( 'admin_init', [ $this, 'make_staff' ] ); | |
| 30 | + add_action( 'admin_init', [$this, 'make_staff'] ); | |
| 29 | 31 | |
| 30 | - add_action( 'init', [ $this, 'setup_staff_onboard'] ); | |
| 32 | + add_action( 'init', [$this, 'setup_staff_onboard'] ); | |
| 31 | 33 | |
| 32 | - add_filter( 'login_redirect', [ $this, 'login_redirect' ], 10, 3 ); | |
| 34 | + add_filter( 'login_redirect', [$this, 'login_redirect'], 10, 3 ); | |
| 33 | 35 | |
| 36 | + add_action( 'wp_ajax_timetics_staff_onboard_skip', [$this, 'timetics_staff_onboard_skip'] ); | |
| 34 | 37 | } |
| 35 | 38 | |
| 36 | 39 | /** |
| 37 | 40 | * Reset user activation and reset password link |
| @@ -43,18 +46,20 @@ | ||
| 43 | 46 | * |
| 44 | 47 | * @return [type] [return description] |
| 45 | 48 | */ |
| 46 | 49 | public function reset_email_content( $config, $key, $user_login, $user_data ) { |
| 47 | - $headers = 'MIME-Version: 1.0' . "\r\n"; | |
| 50 | + $headers = 'MIME-Version: 1.0' . "\r\n"; | |
| 48 | 51 | $headers .= 'Content-type: text/html; charset=iso-8859-1' . "\r\n"; |
| 49 | 52 | |
| 50 | - $local = get_locale(); | |
| 51 | - $reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" ); | |
| 53 | + $local = get_locale(); | |
| 54 | + $timetics_reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" ); | |
| 52 | 55 | |
| 56 | + $timetics_reset_url = apply_filters( 'timetics_staff_password_reset_url', $timetics_reset_url, $key, $user_login, $local ); | |
| 57 | + | |
| 53 | 58 | ob_start(); |
| 54 | - include TIMETICS_PLUGIN_DIR . '/templates/emails/email-header.php'; | |
| 55 | - include TIMETICS_PLUGIN_DIR . '/templates/emails/new-staff.php'; | |
| 56 | - include TIMETICS_PLUGIN_DIR . '/templates/emails/email-footer.php'; | |
| 59 | + include TIMETICS_PLUGIN_DIR . '/templates/emails/email-header.php'; | |
| 60 | + include TIMETICS_PLUGIN_DIR . '/templates/emails/new-staff.php'; | |
| 61 | + include TIMETICS_PLUGIN_DIR . '/templates/emails/email-footer.php'; | |
| 57 | 62 | $message = ob_get_clean(); |
| 58 | 63 | |
| 59 | 64 | $config['message'] = $message; |
| 60 | 65 | $config['headers'] = $headers; |
| @@ -92,9 +97,9 @@ | ||
| 92 | 97 | * @return void |
| 93 | 98 | */ |
| 94 | 99 | public function user_row_action( $actions, $user_object ) { |
| 95 | 100 | $is_staff = user_can( $user_object, 'timetics-staff' ); |
| 96 | - $button_text = $is_staff ? __( 'Remove from staff', 'timetics' ) : __( 'Make staff', 'timetics' ); | |
| 101 | + $button_text = $is_staff ? esc_html__( 'Remove from staff', 'timetics' ) : esc_html__( 'Make staff', 'timetics' ); | |
| 97 | 102 | $action = $is_staff ? 'removestaff' : 'makestaff'; |
| 98 | 103 | |
| 99 | 104 | $actions['staff'] = "<a class='staff' href='" . wp_nonce_url( "users.php?action=$action&users=$user_object->ID", 'bulk-users' ) . "'>" . $button_text . '</a>'; |
| 100 | 105 | |
| @@ -103,26 +108,44 @@ | ||
| 103 | 108 | |
| 104 | 109 | /** |
| 105 | 110 | * Make staff |
| 106 | 111 | * |
| 107 | - * @return void | |
| 112 | + * @return mixed | |
| 108 | 113 | */ |
| 109 | 114 | public function make_staff() { |
| 115 | + | |
| 110 | 116 | $action = isset( $_GET['action'] ) ? sanitize_text_field( wp_unslash( $_GET['action'] ) ) : ''; |
| 111 | 117 | $user_id = isset( $_GET['users'] ) ? intval( $_GET['users'] ) : 0; |
| 118 | + $nonce = isset( $_GET['_wpnonce'] ) ? sanitize_text_field( wp_unslash( $_GET['_wpnonce'] ) ) : ''; | |
| 112 | 119 | $user = get_userdata( $user_id ); |
| 120 | + | |
| 121 | + if ( 'makestaff' === $action ) { | |
| 113 | 122 | |
| 114 | - if ( 'makestaff' === $action ) { | |
| 115 | - $user->add_role( 'timetics-staff' ); | |
| 116 | - $staff = new Staff( $user_id ); | |
| 117 | - $staff->update( | |
| 118 | - [ | |
| 119 | - 'status' => 1, | |
| 120 | - ] | |
| 121 | - ); | |
| 123 | + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) { | |
| 124 | + return; | |
| 125 | + } | |
| 126 | + | |
| 127 | + $capability = current_user_can( 'manage_options' ); | |
| 128 | + if( !$capability) return; | |
| 129 | + | |
| 130 | + $user->add_role( 'timetics-staff' ); | |
| 131 | + $staff = new Staff( $user_id ); | |
| 132 | + $staff->update( | |
| 133 | + [ | |
| 134 | + 'status' => 1, | |
| 135 | + ] | |
| 136 | + ); | |
| 122 | 137 | } |
| 123 | 138 | |
| 124 | 139 | if ( 'removestaff' === $action ) { |
| 140 | + | |
| 141 | + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) { | |
| 142 | + return; | |
| 143 | + } | |
| 144 | + | |
| 145 | + $capability = current_user_can( 'manage_options' ); | |
| 146 | + if( !$capability ) return; | |
| 147 | + | |
| 125 | 148 | $user->remove_role( 'timetics-staff' ); |
| 126 | 149 | } |
| 127 | 150 | } |
| 128 | 151 | |
| @@ -131,9 +154,10 @@ | ||
| 131 | 154 | * |
| 132 | 155 | * @return void |
| 133 | 156 | */ |
| 134 | 157 | public function setup_staff_onboard() { |
| 135 | - $page = isset( $_GET['page'] ) ? sanitize_text_field( $_GET['page'] ) : ''; | |
| 158 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only page parameter check, no form processing | |
| 159 | + $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : ''; | |
| 136 | 160 | |
| 137 | 161 | if ( 'staff-onboard' === $page ) { |
| 138 | 162 | Onboard::instance()->init(); |
| 139 | 163 | } |
| @@ -150,14 +174,24 @@ | ||
| 150 | 174 | */ |
| 151 | 175 | public function login_redirect( $reidrect_to, $requeted_redirect, $user ) { |
| 152 | 176 | global $user; |
| 153 | 177 | |
| 154 | - $roles = isset( $user->roles ) ? $user->roles : []; | |
| 178 | + $roles = isset( $user->roles ) ? $user->roles : []; | |
| 155 | 179 | |
| 156 | - if ( ! in_array('timetics-staff', $roles) ) { | |
| 180 | + if ( is_wp_error( $user ) ) { | |
| 157 | 181 | return $reidrect_to; |
| 158 | 182 | } |
| 159 | 183 | |
| 184 | + $onboard_skip = get_user_meta( $user->ID, 'timetics_staff_onboard_skip', true ); | |
| 185 | + | |
| 186 | + if ( $onboard_skip ) { | |
| 187 | + return $reidrect_to; | |
| 188 | + } | |
| 189 | + | |
| 190 | + if ( ! in_array( 'timetics-staff', $roles ) ) { | |
| 191 | + return $reidrect_to; | |
| 192 | + } | |
| 193 | + | |
| 160 | 194 | $integrations = timetics_get_staff_integrations( $user->ID ); |
| 161 | 195 | |
| 162 | 196 | if ( ! $integrations[0]['connected'] ) { |
| 163 | 197 | $reidrect_to = admin_url( 'admin.php?page=staff-onboard' ); |
| @@ -173,9 +207,23 @@ | ||
| 173 | 207 | * |
| 174 | 208 | * @return string |
| 175 | 209 | */ |
| 176 | 210 | public function reset_email_title( $title ) { |
| 177 | - $title = sprintf( __( 'Welcome to %s oboarding !', 'timetics'), get_bloginfo('name') ); | |
| 211 | + /* translators: %s: Site name */ | |
| 212 | + $title = sprintf( esc_html__( 'Welcome to %s onboarding!', 'timetics' ), get_bloginfo( 'name' ) ); | |
| 178 | 213 | |
| 179 | 214 | return $title; |
| 180 | 215 | } |
| 181 | -} | |
| 216 | + | |
| 217 | + /** | |
| 218 | + * Staff onboard skip | |
| 219 | + * | |
| 220 | + * @return void | |
| 221 | + */ | |
| 222 | + public function timetics_staff_onboard_skip() { | |
| 223 | + check_ajax_referer( 'timetics_staff_onboard_skip', 'nonce' ); | |
| 224 | + | |
| 225 | + update_user_meta( get_current_user_id(), 'timetics_staff_onboard_skip', true ); | |
| 226 | + | |
| 227 | + wp_send_json_success( __( 'Staff onboard skipped successfully.', 'timetics' ) ); | |
| 228 | + } | |
| 229 | +} | |