| @@ -5,8 +5,10 @@ | ||
| 5 | 5 | * @package Timetics |
| 6 | 6 | */ |
| 7 | 7 | namespace Timetics\Core\Staffs; |
| 8 | 8 | |
| 9 | +defined( 'ABSPATH' ) || exit; | |
| 10 | + | |
| 9 | 11 | use Timetics\Core\Staffs\Onboard; |
| 10 | 12 | use Timetics\Utils\Singleton; |
| 11 | 13 | |
| 12 | 14 | class Hooks { |
| @@ -48,11 +50,11 @@ | ||
| 48 | 50 | $headers = 'MIME-Version: 1.0' . "\r\n"; |
| 49 | 51 | $headers .= 'Content-type: text/html; charset=iso-8859-1' . "\r\n"; |
| 50 | 52 | |
| 51 | 53 | $local = get_locale(); |
| 52 | - $reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" ); | |
| 54 | + $timetics_reset_url = site_url( "wp-login.php?action=rp&key={$key}&login={$user_login}&wp_lang={$local}" ); | |
| 53 | 55 | |
| 54 | - $reset_url = apply_filters( 'timetics_staff_password_reset_url', $reset_url, $key, $user_login, $local ); | |
| 56 | + $timetics_reset_url = apply_filters( 'timetics_staff_password_reset_url', $timetics_reset_url, $key, $user_login, $local ); | |
| 55 | 57 | |
| 56 | 58 | ob_start(); |
| 57 | 59 | include TIMETICS_PLUGIN_DIR . '/templates/emails/email-header.php'; |
| 58 | 60 | include TIMETICS_PLUGIN_DIR . '/templates/emails/new-staff.php'; |
| @@ -106,26 +108,44 @@ | ||
| 106 | 108 | |
| 107 | 109 | /** |
| 108 | 110 | * Make staff |
| 109 | 111 | * |
| 110 | - * @return void | |
| 112 | + * @return mixed | |
| 111 | 113 | */ |
| 112 | 114 | public function make_staff() { |
| 115 | + | |
| 113 | 116 | $action = isset( $_GET['action'] ) ? sanitize_text_field( wp_unslash( $_GET['action'] ) ) : ''; |
| 114 | 117 | $user_id = isset( $_GET['users'] ) ? intval( $_GET['users'] ) : 0; |
| 118 | + $nonce = isset( $_GET['_wpnonce'] ) ? sanitize_text_field( wp_unslash( $_GET['_wpnonce'] ) ) : ''; | |
| 115 | 119 | $user = get_userdata( $user_id ); |
| 120 | + | |
| 121 | + if ( 'makestaff' === $action ) { | |
| 116 | 122 | |
| 117 | - if ( 'makestaff' === $action ) { | |
| 118 | - $user->add_role( 'timetics-staff' ); | |
| 119 | - $staff = new Staff( $user_id ); | |
| 120 | - $staff->update( | |
| 121 | - [ | |
| 122 | - 'status' => 1, | |
| 123 | - ] | |
| 124 | - ); | |
| 123 | + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) { | |
| 124 | + return; | |
| 125 | + } | |
| 126 | + | |
| 127 | + $capability = current_user_can( 'manage_options' ); | |
| 128 | + if( !$capability) return; | |
| 129 | + | |
| 130 | + $user->add_role( 'timetics-staff' ); | |
| 131 | + $staff = new Staff( $user_id ); | |
| 132 | + $staff->update( | |
| 133 | + [ | |
| 134 | + 'status' => 1, | |
| 135 | + ] | |
| 136 | + ); | |
| 125 | 137 | } |
| 126 | 138 | |
| 127 | 139 | if ( 'removestaff' === $action ) { |
| 140 | + | |
| 141 | + if ( !wp_verify_nonce( $nonce, 'bulk-users' ) ) { | |
| 142 | + return; | |
| 143 | + } | |
| 144 | + | |
| 145 | + $capability = current_user_can( 'manage_options' ); | |
| 146 | + if( !$capability ) return; | |
| 147 | + | |
| 128 | 148 | $user->remove_role( 'timetics-staff' ); |
| 129 | 149 | } |
| 130 | 150 | } |
| 131 | 151 | |
| @@ -134,9 +154,10 @@ | ||
| 134 | 154 | * |
| 135 | 155 | * @return void |
| 136 | 156 | */ |
| 137 | 157 | public function setup_staff_onboard() { |
| 138 | - $page = isset( $_GET['page'] ) ? sanitize_text_field( $_GET['page'] ) : ''; | |
| 158 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only page parameter check, no form processing | |
| 159 | + $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : ''; | |
| 139 | 160 | |
| 140 | 161 | if ( 'staff-onboard' === $page ) { |
| 141 | 162 | Onboard::instance()->init(); |
| 142 | 163 | } |
| @@ -186,8 +207,9 @@ | ||
| 186 | 207 | * |
| 187 | 208 | * @return string |
| 188 | 209 | */ |
| 189 | 210 | public function reset_email_title( $title ) { |
| 211 | + /* translators: %s: Site name */ | |
| 190 | 212 | $title = sprintf( esc_html__( 'Welcome to %s onboarding!', 'timetics' ), get_bloginfo( 'name' ) ); |
| 191 | 213 | |
| 192 | 214 | return $title; |
| 193 | 215 | } |
| @@ -197,9 +219,11 @@ | ||
| 197 | 219 | * |
| 198 | 220 | * @return void |
| 199 | 221 | */ |
| 200 | 222 | public function timetics_staff_onboard_skip() { |
| 223 | + check_ajax_referer( 'timetics_staff_onboard_skip', 'nonce' ); | |
| 224 | + | |
| 201 | 225 | update_user_meta( get_current_user_id(), 'timetics_staff_onboard_skip', true ); |
| 202 | 226 | |
| 203 | 227 | wp_send_json_success( __( 'Staff onboard skipped successfully.', 'timetics' ) ); |
| 204 | 228 | } |
| 205 | 229 | } |