PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/settings/api-settings.php +114 -1 1.0.13 → 1.0.64 View file →
@@ -5,9 +5,12 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Settings;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Base\Api;
12 +use Timetics\Core\Admin\Hooks;
10 13 use Timetics\Utils\Singleton;
11 14
12 15 class Api_Settings extends Api {
13 16 use Singleton;
@@ -37,8 +40,10 @@
37 40 [
38 41 'methods' => \WP_REST_Server::READABLE,
39 42 'callback' => [$this, 'get_settings'],
40 43 'permission_callback' => function () {
44 + // The public booking app needs a small, explicitly safe
45 + // settings payload. get_settings() filters it by role.
41 46 return true;
42 47 },
43 48 ],
44 49 [
@@ -44,9 +49,9 @@
44 49 [
45 50 'methods' => \WP_REST_Server::EDITABLE,
46 51 'callback' => [$this, 'update_settings'],
47 52 'permission_callback' => function () {
48 - return true;
53 + return current_user_can( 'manage_options' );
49 54 },
50 55 ],
51 56 ]
52 57 );
@@ -83,8 +88,14 @@
83 88 */
84 89 public function get_settings() {
85 90 $settings = apply_filters( 'timetics_settings', timetics_get_settings() );
86 91
92 + // The booking and staff interfaces need non-sensitive display and scheduling
93 + // settings. Never send credentials or webhook URLs to non-administrators.
94 + if ( ! current_user_can( 'manage_options' ) ) {
95 + $settings = $this->get_staff_safe_settings( $settings );
96 + }
97 +
87 98 $data = [
88 99 'status_code' => 200,
89 100 'success' => 1,
90 101 'message' => esc_html__( 'Get all settings', 'timetics' ),
@@ -94,8 +105,47 @@
94 105 return rest_ensure_response( $settings );
95 106 }
96 107
97 108 /**
109 + * Return only settings that staff need to use the admin interface.
110 + *
111 + * This is deliberately an allow-list. New settings remain private until they
112 + * have been reviewed and explicitly added here.
113 + *
114 + * @param array $settings Plugin settings.
115 + *
116 + * @return array
117 + */
118 + private function get_staff_safe_settings( $settings ) {
119 + $safe_keys = [
120 + 'availability',
121 + 'apple_calendar',
122 + 'blocked_days',
123 + 'busyness_category',
124 + 'calendar_locale',
125 + 'currency',
126 + 'custom_fields',
127 + 'default_booking_status',
128 + 'guest_enabled',
129 + 'guest_limit',
130 + 'google_calendar',
131 + 'locale_timezone',
132 + 'paypal_status',
133 + 'primary_color',
134 + 'remainder_time',
135 + 'secondary_color',
136 + 'slot_interval',
137 + 'stripe_status',
138 + 'outlook_calendar',
139 + 'wc_integration',
140 + 'wc_checkout_url',
141 + 'zoom_connection_type',
142 + ];
143 +
144 + return array_intersect_key( (array) $settings, array_flip( $safe_keys ) );
145 + }
146 +
147 + /**
98 148 * Update settings
99 149 *
100 150 * @param WP_Rest_Request $request
101 151 *
@@ -103,9 +153,33 @@
103 153 */
104 154 public function update_settings( $request ) {
105 155 $options = json_decode( $request->get_body(), true );
106 156
157 + if ( ! is_array( $options ) ) {
158 + return new \WP_Error(
159 + 'timetics_invalid_settings',
160 + __( 'Settings must be sent as a JSON object.', 'timetics' ),
161 + [ 'status' => 400 ]
162 + );
163 + }
164 +
107 165 /**
166 + * Filter the settings payload before any of it is checked or saved.
167 + *
168 + * Runs before the checks below, so a listener's result passes through
169 + * them like the raw request does. Add-ons use it to clean their own
170 + * keys. It is an extension point, not the sanitization for core keys.
171 + *
172 + * @since 1.0.63
173 + *
174 + * @param array $options Settings payload from the request body.
175 + */
176 + $filtered = apply_filters( 'timetics_settings_update_params', $options );
177 +
178 + // A listener returning a non-array must not make the save below write nothing.
179 + $options = is_array( $filtered ) ? $filtered : $options;
180 +
181 + /**
108 182 * Added temporary for leagacy sass. It will remove in future.
109 183 */
110 184 $data = [
111 185 'status_code' => 200,
@@ -113,8 +187,18 @@
113 187 'message' => esc_html__( 'Settings successfully updated', 'timetics' ),
114 188 'data' => timetics_get_settings(),
115 189 ];
116 190
191 + // custom domain
192 + if (!empty($options['custom_domain_url']) && isset($options['custom_domain_url'])) {
193 + $custom_domain_data = [
194 + 'custom_domain_url' => $options['custom_domain_url'],
195 + 'network_slug' => $options['network_slug'],
196 + ];
197 + do_action('timetics_custom_domain_data', $custom_domain_data);
198 + }
199 +
200 +
117 201 if ( !empty($options['schedule']) && $options['schedule'] && apply_filters('timetics/staff/member/availability', false)) {
118 202 return rest_ensure_response( apply_filters( 'timetics/admin/staff/error_data', $data, 'availability_update' ) );
119 203 }
120 204
@@ -145,8 +229,12 @@
145 229 if ( ! empty( $options['zapier_webhook'] ) && $options['zapier_webhook'] && apply_filters( 'timetics/admin/settings/zapier_webhook', false ) ) {
146 230 return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'zapier', timetics_get_settings() ) );
147 231 }
148 232
233 + if ( ! empty( $options['flowmattic_webhook'] ) && $options['flowmattic_webhook'] && apply_filters( 'timetics/admin/settings/flowmattic_webhook', false ) ) {
234 + return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'flowmattic', timetics_get_settings() ) );
235 + }
236 +
149 237 if (!empty($options['google_app_client_id']) && $options['google_app_client_id'] && apply_filters('timetics/admin/settings/google_calendar', false)) {
150 238 return rest_ensure_response(apply_filters('timetics/admin/settings/error_data', $data, 'google-calendar', timetics_get_settings()));
151 239 }
152 240
@@ -161,8 +249,12 @@
161 249 if ( ! empty( $options['apple_calendar'] ) && $options['apple_calendar'] && apply_filters( 'timetics/admin/settings/apple_calendar', false ) ) {
162 250 return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'paypal', timetics_get_settings() ) );
163 251 }
164 252
253 + if ( ! empty( $options['uncanny_automator'] ) && $options['uncanny_automator'] && apply_filters( 'timetics/admin/settings/uncanny_automator', false ) ) {
254 + return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'uncanny_automator', timetics_get_settings() ) );
255 + }
256 +
165 257 if (!empty($options['twillo_message']) && $options['twillo_message'] && apply_filters('timetics/admin/settings/twillo_messaging', false)) {
166 258 return rest_ensure_response(apply_filters('timetics/admin/settings/error_data', $data, 'twillo_messaging', timetics_get_settings()));
167 259 }
168 260
@@ -167,8 +259,28 @@
167 259 }
168 260
169 261 if ( $options ) {
170 262 foreach ( $options as $key => $value ) {
263 + // Webhook URLs are pasted from FlowMattic, so keep them a URL.
264 + if ( 'flowmattic_webhook' === $key ) {
265 + $value = esc_url_raw( $value );
266 + }
267 +
268 + // Stored as the strings `yes`/`no`: this
269 + // option defaults to on, and timetics_get_option() treats an
270 + // empty value as "unset" and hands back the default, so a
271 + // boolean false could never switch it off.
272 + if ( 'uncanny_automator' === $key ) {
273 + $value = $value && 'no' !== $value ? 'yes' : 'no';
274 + }
275 +
276 + // Clamp: the cleanup cron only runs every 5 minutes, so a
277 + // lower value would silently do nothing and 0/negative would
278 + // expire bookings instantly.
279 + if ( 'unpaid_booking_expiry_minutes' === $key ) {
280 + $value = max( 5, absint( $value ) );
281 + }
282 +
171 283 timetics_update_option( $key, $value );
172 284 }
173 285 }
174 286
@@ -221,5 +333,6 @@
221 333 ];
222 334
223 335 return rest_ensure_response( $response );
224 336 }
337 +
225 338 }