PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | utils/notice/notice.php +17 -10 1.0.17 → 1.0.64 View file →
@@ -1,5 +1,6 @@
1 1 <?php
2 +// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedNamespaceFound -- Third-party vendor library, namespace cannot be changed
2 3 namespace Oxaim\Libs;
3 4
4 5 defined( 'ABSPATH' ) || exit;
5 6
@@ -285,11 +286,13 @@
285 286 }else{
286 287 $expired = '';
287 288 }
288 289
290 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- Vendor library global variable
289 291 global $oxaim_lib_notice_list;
290 292
291 293 if(!isset($oxaim_lib_notice_list[$this->notice_id])){
294 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- Vendor library global variable usage
292 295 $oxaim_lib_notice_list[$this->notice_id] = __FILE__;
293 296
294 297 // is transient expired?
295 298 if ( false === $expired || empty( $expired ) ) {
@@ -311,10 +314,10 @@
311 314 <div
312 315 id="<?php echo esc_attr($this->notice_id); ?>"
313 316 class="notice wpmet-notice notice-<?php echo esc_attr($this->notice_id . ' ' .$this->class); ?> <?php echo (false === $this->dismissible ? '' : 'is-dismissible') ;?>"
314 317
315 - expired_time="<?php echo ($this->expired_time); ?>"
316 - dismissible="<?php echo ($this->dismissible); ?>"
318 + expired_time="<?php echo esc_attr( $this->expired_time ); ?>"
319 + dismissible="<?php echo esc_attr( $this->dismissible ); ?>"
317 320 >
318 321 <?php if(!empty($this->logo)):?>
319 322 <img class="notice-logo" style="<?php echo esc_attr($this->logo_style); ?>" src="<?php echo esc_url($this->logo);?>" />
320 323 <?php endif; ?>
@@ -321,18 +324,18 @@
321 324
322 325 <div class="notice-right-container <?php echo (empty($this->logo) ? 'notice-container-full-width' : ''); ?>">
323 326
324 327 <?php if(empty($this->html)): ?>
325 - <?php echo (empty($this->title) ? '' : sprintf('<div class="notice-main-title notice-vert-space">%s</div>', $this->title)); ?>
328 + <?php echo esc_html( empty($this->title ) ? '' : sprintf('<div class="notice-main-title notice-vert-space">%s</div>', esc_html( $this->title ) )); ?>
326 329
327 330 <div class="notice-message notice-vert-space">
328 - <?php echo ( $this->message );?>
331 + <?php echo wp_kses( $this->message, 'post' );?>
329 332 </div>
330 333
331 334 <?php if(!empty($this->buttons)): ?>
332 335 <div class="button-container notice-vert-space">
333 336 <?php foreach($this->buttons as $button): ?>
334 - <a id="<?php echo (!isset($button['id']) ? '' : $button['id']); ?>" href="<?php echo esc_url($button['url']); ?>" class="wpmet-notice-button <?php echo esc_attr($button['class']); ?>">
337 + <a id="<?php echo esc_attr( !isset($button['id']) ? '' : $button['id'] ); ?>" href="<?php echo esc_url($button['url']); ?>" class="wpmet-notice-button <?php echo esc_attr($button['class']); ?>">
335 338 <?php if(!empty($button['icon'])) :?>
336 339 <i class="notice-icon <?php echo esc_attr($button['icon']); ?>"></i>
337 340 <?php endif; ?>
338 341 <?php echo esc_html($button['text']);?>
@@ -342,9 +345,9 @@
342 345 </div>
343 346 <?php endif;?>
344 347
345 348 <?php else:?>
346 - <?php echo $this->html; ?>
349 + <?php echo wp_kses( $this->html, 'post' ); ?>
347 350 <?php endif;?>
348 351
349 352 </div>
350 353
@@ -365,13 +368,15 @@
365 368 add_action( 'admin_head', [ __CLASS__, 'enqueue_scripts' ] );
366 369 }
367 370
368 371 public static function dismiss_ajax_call() {
369 - $post_arr = filter_input_array( INPUT_POST, FILTER_SANITIZE_STRING );
370 - $notice_id = ( isset( $post_arr['notice_id'] ) ) ? $post_arr['notice_id'] : '';
371 - $dismissible = ( isset( $post_arr['dismissible'] ) ) ? $post_arr['dismissible'] : '';
372 - $expired_time = ( isset( $post_arr['expired_time'] ) ) ? $post_arr['expired_time'] : '';
372 + check_ajax_referer( 'wpmet_notice_dismiss', 'nonce' );
373 373
374 + $post_arr = wp_unslash( $_POST );
375 + $notice_id = ( isset( $post_arr['notice_id'] ) ) ? sanitize_key( $post_arr['notice_id'] ) : '';
376 + $dismissible = ( isset( $post_arr['dismissible'] ) ) ? sanitize_text_field( $post_arr['dismissible'] ) : '';
377 + $expired_time = ( isset( $post_arr['expired_time'] ) ) ? absint( $post_arr['expired_time'] ) : 0;
378 +
374 379 if ( ! empty( $notice_id ) ) {
375 380 if ( 'user' === $dismissible ) {
376 381 update_user_meta( get_current_user_id(), $notice_id, true );
377 382 } else {
@@ -384,8 +389,9 @@
384 389 wp_send_json_error();
385 390 }
386 391
387 392 public static function enqueue_scripts() {
393 + $nonce = wp_create_nonce( 'wpmet_notice_dismiss' );
388 394 echo "
389 395 <script>
390 396 jQuery(document).ready(function ($) {
391 397 $( '.wpmet-notice.is-dismissible' ).on( 'click', '.notice-dismiss', function() {
@@ -405,8 +411,9 @@
405 411 action : 'wpmet-notices',
406 412 notice_id : notice_id,
407 413 dismissible : dismissible,
408 414 expired_time : expired_time,
415 + nonce : '" . esc_js( $nonce ) . "',
409 416 },
410 417 });
411 418 });
412 419 });