PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/settings/api-settings.php +105 -2 1.0.20 → 1.0.64 View file →
@@ -5,9 +5,12 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Settings;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Base\Api;
12 +use Timetics\Core\Admin\Hooks;
10 13 use Timetics\Utils\Singleton;
11 14
12 15 class Api_Settings extends Api {
13 16 use Singleton;
@@ -37,8 +40,10 @@
37 40 [
38 41 'methods' => \WP_REST_Server::READABLE,
39 42 'callback' => [$this, 'get_settings'],
40 43 'permission_callback' => function () {
44 + // The public booking app needs a small, explicitly safe
45 + // settings payload. get_settings() filters it by role.
41 46 return true;
42 47 },
43 48 ],
44 49 [
@@ -44,9 +49,9 @@
44 49 [
45 50 'methods' => \WP_REST_Server::EDITABLE,
46 51 'callback' => [$this, 'update_settings'],
47 52 'permission_callback' => function () {
48 - return true;
53 + return current_user_can( 'manage_options' );
49 54 },
50 55 ],
51 56 ]
52 57 );
@@ -83,8 +88,14 @@
83 88 */
84 89 public function get_settings() {
85 90 $settings = apply_filters( 'timetics_settings', timetics_get_settings() );
86 91
92 + // The booking and staff interfaces need non-sensitive display and scheduling
93 + // settings. Never send credentials or webhook URLs to non-administrators.
94 + if ( ! current_user_can( 'manage_options' ) ) {
95 + $settings = $this->get_staff_safe_settings( $settings );
96 + }
97 +
87 98 $data = [
88 99 'status_code' => 200,
89 100 'success' => 1,
90 101 'message' => esc_html__( 'Get all settings', 'timetics' ),
@@ -94,8 +105,47 @@
94 105 return rest_ensure_response( $settings );
95 106 }
96 107
97 108 /**
109 + * Return only settings that staff need to use the admin interface.
110 + *
111 + * This is deliberately an allow-list. New settings remain private until they
112 + * have been reviewed and explicitly added here.
113 + *
114 + * @param array $settings Plugin settings.
115 + *
116 + * @return array
117 + */
118 + private function get_staff_safe_settings( $settings ) {
119 + $safe_keys = [
120 + 'availability',
121 + 'apple_calendar',
122 + 'blocked_days',
123 + 'busyness_category',
124 + 'calendar_locale',
125 + 'currency',
126 + 'custom_fields',
127 + 'default_booking_status',
128 + 'guest_enabled',
129 + 'guest_limit',
130 + 'google_calendar',
131 + 'locale_timezone',
132 + 'paypal_status',
133 + 'primary_color',
134 + 'remainder_time',
135 + 'secondary_color',
136 + 'slot_interval',
137 + 'stripe_status',
138 + 'outlook_calendar',
139 + 'wc_integration',
140 + 'wc_checkout_url',
141 + 'zoom_connection_type',
142 + ];
143 +
144 + return array_intersect_key( (array) $settings, array_flip( $safe_keys ) );
145 + }
146 +
147 + /**
98 148 * Update settings
99 149 *
100 150 * @param WP_Rest_Request $request
101 151 *
@@ -103,9 +153,33 @@
103 153 */
104 154 public function update_settings( $request ) {
105 155 $options = json_decode( $request->get_body(), true );
106 156
157 + if ( ! is_array( $options ) ) {
158 + return new \WP_Error(
159 + 'timetics_invalid_settings',
160 + __( 'Settings must be sent as a JSON object.', 'timetics' ),
161 + [ 'status' => 400 ]
162 + );
163 + }
164 +
107 165 /**
166 + * Filter the settings payload before any of it is checked or saved.
167 + *
168 + * Runs before the checks below, so a listener's result passes through
169 + * them like the raw request does. Add-ons use it to clean their own
170 + * keys. It is an extension point, not the sanitization for core keys.
171 + *
172 + * @since 1.0.63
173 + *
174 + * @param array $options Settings payload from the request body.
175 + */
176 + $filtered = apply_filters( 'timetics_settings_update_params', $options );
177 +
178 + // A listener returning a non-array must not make the save below write nothing.
179 + $options = is_array( $filtered ) ? $filtered : $options;
180 +
181 + /**
108 182 * Added temporary for leagacy sass. It will remove in future.
109 183 */
110 184 $data = [
111 185 'status_code' => 200,
@@ -119,9 +193,9 @@
119 193 $custom_domain_data = [
120 194 'custom_domain_url' => $options['custom_domain_url'],
121 195 'network_slug' => $options['network_slug'],
122 196 ];
123 - do_action('custom_domain_data', $custom_domain_data);
197 + do_action('timetics_custom_domain_data', $custom_domain_data);
124 198 }
125 199
126 200
127 201 if ( !empty($options['schedule']) && $options['schedule'] && apply_filters('timetics/staff/member/availability', false)) {
@@ -155,8 +229,12 @@
155 229 if ( ! empty( $options['zapier_webhook'] ) && $options['zapier_webhook'] && apply_filters( 'timetics/admin/settings/zapier_webhook', false ) ) {
156 230 return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'zapier', timetics_get_settings() ) );
157 231 }
158 232
233 + if ( ! empty( $options['flowmattic_webhook'] ) && $options['flowmattic_webhook'] && apply_filters( 'timetics/admin/settings/flowmattic_webhook', false ) ) {
234 + return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'flowmattic', timetics_get_settings() ) );
235 + }
236 +
159 237 if (!empty($options['google_app_client_id']) && $options['google_app_client_id'] && apply_filters('timetics/admin/settings/google_calendar', false)) {
160 238 return rest_ensure_response(apply_filters('timetics/admin/settings/error_data', $data, 'google-calendar', timetics_get_settings()));
161 239 }
162 240
@@ -171,8 +249,12 @@
171 249 if ( ! empty( $options['apple_calendar'] ) && $options['apple_calendar'] && apply_filters( 'timetics/admin/settings/apple_calendar', false ) ) {
172 250 return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'paypal', timetics_get_settings() ) );
173 251 }
174 252
253 + if ( ! empty( $options['uncanny_automator'] ) && $options['uncanny_automator'] && apply_filters( 'timetics/admin/settings/uncanny_automator', false ) ) {
254 + return rest_ensure_response( apply_filters( 'timetics/admin/settings/error_data', $data, 'uncanny_automator', timetics_get_settings() ) );
255 + }
256 +
175 257 if (!empty($options['twillo_message']) && $options['twillo_message'] && apply_filters('timetics/admin/settings/twillo_messaging', false)) {
176 258 return rest_ensure_response(apply_filters('timetics/admin/settings/error_data', $data, 'twillo_messaging', timetics_get_settings()));
177 259 }
178 260
@@ -177,8 +259,28 @@
177 259 }
178 260
179 261 if ( $options ) {
180 262 foreach ( $options as $key => $value ) {
263 + // Webhook URLs are pasted from FlowMattic, so keep them a URL.
264 + if ( 'flowmattic_webhook' === $key ) {
265 + $value = esc_url_raw( $value );
266 + }
267 +
268 + // Stored as the strings `yes`/`no`: this
269 + // option defaults to on, and timetics_get_option() treats an
270 + // empty value as "unset" and hands back the default, so a
271 + // boolean false could never switch it off.
272 + if ( 'uncanny_automator' === $key ) {
273 + $value = $value && 'no' !== $value ? 'yes' : 'no';
274 + }
275 +
276 + // Clamp: the cleanup cron only runs every 5 minutes, so a
277 + // lower value would silently do nothing and 0/negative would
278 + // expire bookings instantly.
279 + if ( 'unpaid_booking_expiry_minutes' === $key ) {
280 + $value = max( 5, absint( $value ) );
281 + }
282 +
181 283 timetics_update_option( $key, $value );
182 284 }
183 285 }
184 286
@@ -231,5 +333,6 @@
231 333 ];
232 334
233 335 return rest_ensure_response( $response );
234 336 }
337 +
235 338 }