PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/integrations/auth.php +49 -6 1.0.11 → 1.0.64 View file →
@@ -6,8 +6,10 @@
6 6 */
7 7
8 8 namespace Timetics\Core\Integrations;
9 9
10 +defined( 'ABSPATH' ) || exit;
11 +
10 12 use Timetics\Core\Integrations\Google\Service\Calendar;
11 13 use Timetics\Utils\Singleton;
12 14
13 15 /**
@@ -35,10 +37,22 @@
35 37 public function authenticate() {
36 38 $query_var = get_query_var( 'timetics-integration', false );
37 39 $user_id = get_current_user_id();
38 40
39 - $code = isset( $_GET['code'] ) ? sanitize_text_field( $_GET['code'] ) : '';
41 + $code = isset( $_GET['code'] ) ? sanitize_text_field( wp_unslash( $_GET['code'] ) ) : '';
40 42
43 + // Verify nonce for security.
44 + if ( empty( $code ) ) {
45 + if ( ! isset( $_GET['timetics_auth_nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_GET['timetics_auth_nonce'] ) ), 'timetics_auth_action' ) ) {
46 + return;
47 + }
48 + } else {
49 + $state = isset( $_GET['state'] ) ? sanitize_text_field( wp_unslash( $_GET['state'] ) ) : '';
50 + if ( ! wp_verify_nonce( $state, 'timetics_auth_callback' ) ) {
51 + return;
52 + }
53 + }
54 +
41 55 if ( ! $query_var ) {
42 56 return;
43 57 }
44 58
@@ -49,9 +63,15 @@
49 63 }
50 64
51 65 do_action('timetics_integration_auth', $query_var, $code );
52 66
53 - wp_redirect( admin_url( 'admin.php?page=timetics#/my-profile') );
67 + $redirect_url = admin_url('admin.php?page=timetics#/my-profile');
68 +
69 + if ( current_user_can('manage_options') ) {
70 + $redirect_url = admin_url('admin.php?page=timetics#/settings');
71 + }
72 +
73 + wp_safe_redirect( $redirect_url );
54 74 exit;
55 75 }
56 76
57 77 /**
@@ -63,13 +83,36 @@
63 83 */
64 84 public function google_auth( $code = '' ) {
65 85 $client = timetics_get_google_client();
66 86
67 - $client->add_scope( Calendar::scope() );
68 - $data = $client->fetch_access_token_with_auth_code( $code );
69 - $data['code'] = $code;
87 + // If no code is provided, redirect to Google's authorization page.
88 + if ( empty( $code ) ) {
89 + $state = wp_create_nonce( 'timetics_auth_callback' );
90 + $client->add_scope( Calendar::scope() );
91 + $auth_url = $client->get_auth_url( $state );
92 + // phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect -- Redirecting to external Google OAuth URL.
93 + wp_redirect( $auth_url );
94 + exit;
95 + }
70 96
71 - timetics_update_google_auth( get_current_user_id(), $data );
97 + try {
98 + $client->add_scope( Calendar::scope() );
99 + $data = $client->fetch_access_token_with_auth_code( $code );
100 + $data['code'] = $code;
101 +
102 + timetics_update_google_auth( get_current_user_id(), $data );
103 +
104 + wp_safe_redirect(admin_url('admin.php?page=timetics#/settings'));
105 + exit;
106 + } catch (\Exception $e) {
107 + $error_message = sprintf(
108 + '<p>%s</p><p><a href="%s" class="button button-primary">Go Back</a></p>',
109 + esc_html( $e->getMessage() ),
110 + esc_url( admin_url('admin.php?page=timetics#/settings') )
111 + );
112 +
113 + wp_die( wp_kses_post( $error_message ), esc_html__('Google Auth Error', 'timetics'), array('back_link' => true));
114 + }
72 115 }
73 116
74 117 /**
75 118 * Authentication for zoom