PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/hooks.php +39 -15 1.0.14 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Staffs;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Core\Staffs\Onboard;
10 12 use Timetics\Utils\Singleton;
11 13
12 14 class Hooks {
@@ -48,11 +50,11 @@
48 50 $headers = 'MIME-Version: 1.0' . "\r\n";
49 51 $headers .= 'Content-type: text/html; charset=iso-8859-1' . "\r\n";
50 52
51 53 $local = get_locale();
52 - $reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" );
54 + $timetics_reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" );
53 55
54 - $reset_url = apply_filters( 'timetics_staff_password_reset_url', $reset_url, $key, $user_login, $local );
56 + $timetics_reset_url = apply_filters( 'timetics_staff_password_reset_url', $timetics_reset_url, $key, $user_login, $local );
55 57
56 58 ob_start();
57 59 include TIMETICS_PLUGIN_DIR . '/templates/emails/email-header.php';
58 60 include TIMETICS_PLUGIN_DIR . '/templates/emails/new-staff.php';
@@ -106,26 +108,44 @@
106 108
107 109 /**
108 110 * Make staff
109 111 *
110 - * @return void
112 + * @return mixed
111 113 */
112 114 public function make_staff() {
115 +
113 116 $action = isset( $_GET['action'] ) ? sanitize_text_field( wp_unslash( $_GET['action'] ) ) : '';
114 117 $user_id = isset( $_GET['users'] ) ? intval( $_GET['users'] ) : 0;
118 + $nonce = isset( $_GET['_wpnonce'] ) ? sanitize_text_field( wp_unslash( $_GET['_wpnonce'] ) ) : '';
115 119 $user = get_userdata( $user_id );
120 +
121 + if ( 'makestaff' === $action ) {
116 122
117 - if ( 'makestaff' === $action ) {
118 - $user->add_role( 'timetics-staff' );
119 - $staff = new Staff( $user_id );
120 - $staff->update(
121 - [
122 - 'status' => 1,
123 - ]
124 - );
123 + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) {
124 + return;
125 + }
126 +
127 + $capability = current_user_can( 'manage_options' );
128 + if( !$capability) return;
129 +
130 + $user->add_role( 'timetics-staff' );
131 + $staff = new Staff( $user_id );
132 + $staff->update(
133 + [
134 + 'status' => 1,
135 + ]
136 + );
125 137 }
126 138
127 139 if ( 'removestaff' === $action ) {
140 +
141 + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) {
142 + return;
143 + }
144 +
145 + $capability = current_user_can( 'manage_options' );
146 + if( !$capability ) return;
147 +
128 148 $user->remove_role( 'timetics-staff' );
129 149 }
130 150 }
131 151
@@ -134,9 +154,10 @@
134 154 *
135 155 * @return void
136 156 */
137 157 public function setup_staff_onboard() {
138 - $page = isset( $_GET['page'] ) ? sanitize_text_field( $_GET['page'] ) : '';
158 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only page parameter check, no form processing
159 + $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : '';
139 160
140 161 if ( 'staff-onboard' === $page ) {
141 162 Onboard::instance()->init();
142 163 }
@@ -186,9 +207,10 @@
186 207 *
187 208 * @return string
188 209 */
189 210 public function reset_email_title( $title ) {
190 - $title = sprintf( esc_html__( 'Welcome to %s oboarding !', 'timetics' ), get_bloginfo( 'name' ) );
211 + /* translators: %s: Site name */
212 + $title = sprintf( esc_html__( 'Welcome to %s onboarding!', 'timetics' ), get_bloginfo( 'name' ) );
191 213
192 214 return $title;
193 215 }
194 216
@@ -197,9 +219,11 @@
197 219 *
198 220 * @return void
199 221 */
200 222 public function timetics_staff_onboard_skip() {
223 + check_ajax_referer( 'timetics_staff_onboard_skip', 'nonce' );
224 +
201 225 update_user_meta( get_current_user_id(), 'timetics_staff_onboard_skip', true );
202 226
203 - wp_send_json_success( __( 'Staff onboard skip successfully.', 'timetics' ) );
227 + wp_send_json_success( __( 'Staff onboard skipped successfully.', 'timetics' ) );
204 228 }
205 -}
229 +}