PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/hooks.php +41 -15 1.0.11 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Staffs;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Core\Staffs\Onboard;
10 12 use Timetics\Utils\Singleton;
11 13
12 14 class Hooks {
@@ -48,10 +50,12 @@
48 50 $headers = 'MIME-Version: 1.0' . "\r\n";
49 51 $headers .= 'Content-type: text/html; charset=iso-8859-1' . "\r\n";
50 52
51 53 $local = get_locale();
52 - $reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" );
54 + $timetics_reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" );
53 55
56 + $timetics_reset_url = apply_filters( 'timetics_staff_password_reset_url', $timetics_reset_url, $key, $user_login, $local );
57 +
54 58 ob_start();
55 59 include TIMETICS_PLUGIN_DIR . '/templates/emails/email-header.php';
56 60 include TIMETICS_PLUGIN_DIR . '/templates/emails/new-staff.php';
57 61 include TIMETICS_PLUGIN_DIR . '/templates/emails/email-footer.php';
@@ -104,26 +108,44 @@
104 108
105 109 /**
106 110 * Make staff
107 111 *
108 - * @return void
112 + * @return mixed
109 113 */
110 114 public function make_staff() {
115 +
111 116 $action = isset( $_GET['action'] ) ? sanitize_text_field( wp_unslash( $_GET['action'] ) ) : '';
112 117 $user_id = isset( $_GET['users'] ) ? intval( $_GET['users'] ) : 0;
118 + $nonce = isset( $_GET['_wpnonce'] ) ? sanitize_text_field( wp_unslash( $_GET['_wpnonce'] ) ) : '';
113 119 $user = get_userdata( $user_id );
120 +
121 + if ( 'makestaff' === $action ) {
114 122
115 - if ( 'makestaff' === $action ) {
116 - $user->add_role( 'timetics-staff' );
117 - $staff = new Staff( $user_id );
118 - $staff->update(
119 - [
120 - 'status' => 1,
121 - ]
122 - );
123 + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) {
124 + return;
125 + }
126 +
127 + $capability = current_user_can( 'manage_options' );
128 + if( !$capability) return;
129 +
130 + $user->add_role( 'timetics-staff' );
131 + $staff = new Staff( $user_id );
132 + $staff->update(
133 + [
134 + 'status' => 1,
135 + ]
136 + );
123 137 }
124 138
125 139 if ( 'removestaff' === $action ) {
140 +
141 + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) {
142 + return;
143 + }
144 +
145 + $capability = current_user_can( 'manage_options' );
146 + if( !$capability ) return;
147 +
126 148 $user->remove_role( 'timetics-staff' );
127 149 }
128 150 }
129 151
@@ -132,9 +154,10 @@
132 154 *
133 155 * @return void
134 156 */
135 157 public function setup_staff_onboard() {
136 - $page = isset( $_GET['page'] ) ? sanitize_text_field( $_GET['page'] ) : '';
158 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only page parameter check, no form processing
159 + $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : '';
137 160
138 161 if ( 'staff-onboard' === $page ) {
139 162 Onboard::instance()->init();
140 163 }
@@ -158,9 +181,9 @@
158 181 return $reidrect_to;
159 182 }
160 183
161 184 $onboard_skip = get_user_meta( $user->ID, 'timetics_staff_onboard_skip', true );
162 -
185 +
163 186 if ( $onboard_skip ) {
164 187 return $reidrect_to;
165 188 }
166 189
@@ -184,9 +207,10 @@
184 207 *
185 208 * @return string
186 209 */
187 210 public function reset_email_title( $title ) {
188 - $title = sprintf( esc_html__( 'Welcome to %s oboarding !', 'timetics' ), get_bloginfo( 'name' ) );
211 + /* translators: %s: Site name */
212 + $title = sprintf( esc_html__( 'Welcome to %s onboarding!', 'timetics' ), get_bloginfo( 'name' ) );
189 213
190 214 return $title;
191 215 }
192 216
@@ -195,9 +219,11 @@
195 219 *
196 220 * @return void
197 221 */
198 222 public function timetics_staff_onboard_skip() {
223 + check_ajax_referer( 'timetics_staff_onboard_skip', 'nonce' );
224 +
199 225 update_user_meta( get_current_user_id(), 'timetics_staff_onboard_skip', true );
200 226
201 - wp_send_json_success( __( 'Staff onboard skip successfully.', 'timetics' ) );
227 + wp_send_json_success( __( 'Staff onboard skipped successfully.', 'timetics' ) );
202 228 }
203 -}
229 +}