PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/addon/api-addon.php +29 -7 1.0.62 → 1.0.64 View file →
@@ -156,8 +156,18 @@
156 156 [ 'status' => 422 ]
157 157 );
158 158 }
159 159
160 + // The Ask AI setup dialog lets the user edit the account email. Reject a bad one before anything is installed.
161 + $email = isset( $params['email'] ) ? sanitize_email( $params['email'] ) : '';
162 +
163 + if ( isset( $params['email'] ) && ! is_email( $email ) ) {
164 + return $this->send_error(
165 + __( 'Enter a valid email address.', 'timetics' ),
166 + [ 'status' => 422 ]
167 + );
168 + }
169 +
160 170 $extension = timetics_extension()->find( $name );
161 171
162 172 if ( ! $extension ) {
163 173 return $this->send_error(
@@ -184,8 +194,18 @@
184 194 // Our-Plugins download_url wins over the wordpress.org slug lookup, so a
185 195 // non-wordpress.org URL (e.g. GitHub release zip) is not shadowed.
186 196 $download_url = ! empty( $extension['download_url'] ) ? $extension['download_url'] : '';
187 197
198 + // PluginManager checks no capabilities, so require what doing this by hand in Plugins needs.
199 + $needs_install = 'install' === $status || ( 'activate' === $status && ! PluginManager::is_installed( $slug ) );
200 +
201 + if ( ! current_user_can( $needs_install ? 'install_plugins' : 'activate_plugins' ) ) {
202 + return $this->send_error(
203 + __( 'Sorry, you are not allowed to manage plugins on this site.', 'timetics' ),
204 + [ 'status' => 403 ]
205 + );
206 + }
207 +
188 208 switch ( $status ) {
189 209 case 'install':
190 210 if ( ! function_exists( 'WP_Filesystem' ) ) {
191 211 require_once ABSPATH . 'wp-admin/includes/file.php';
@@ -241,19 +261,20 @@
241 261 ];
242 262
243 263 /*
244 264 * Registration only runs when the caller sent explicit consent, which
245 - * today means the onboarding checkbox or the dashboard banner button.
246 - * Activating from About Us installs the plugin and stops there, so no
247 - * identity leaves the site without the user opting in.
265 + * today means the onboarding checkbox, the dashboard banner button or
266 + * the Ask AI setup dialog. Activating from About Us installs the plugin
267 + * and stops there, so no identity leaves the site without the user
268 + * opting in. Strict: a "1" or "true" string never counts as agreement.
248 269 */
249 - if ( 'aisentic' === $name && 'activate' === $status && ! empty( $params['consent'] ) && PluginManager::is_activated( $slug ) ) {
270 + if ( 'aisentic' === $name && 'activate' === $status && true === ( $params['consent'] ?? null ) && PluginManager::is_activated( $slug ) ) {
250 271 // Snapshot before the handshake so the caller can tell a fresh
251 272 // registration (tokens just granted) from re-activating a site that
252 273 // was already connected (no new tokens).
253 274 $was_registered = timetics_aisentic_is_registered();
254 275
255 - $this->register_aisentic_site();
276 + $this->register_aisentic_site( $email );
256 277
257 278 $is_registered = timetics_aisentic_is_registered();
258 279
259 280 // The banner needs to know whether the handshake actually landed so
@@ -282,11 +303,12 @@
282 303 * consent UI showed. Aisentic swallows provider errors and skips the call
283 304 * when it already has an api key, so this never affects the activation
284 305 * response.
285 306 *
307 + * @param string $email Email the user typed, empty to use their account email.
286 308 * @return void
287 309 */
288 - private function register_aisentic_site() {
310 + private function register_aisentic_site( $email = '' ) {
289 311 // Older Aisentic builds have no listener for the action below, so the
290 312 // handshake would go nowhere. Skip instead of storing consent for a
291 313 // registration that cannot happen.
292 314 if ( ! class_exists( 'Aisentic\Api\Services\Registration_Service' ) ) {
@@ -292,9 +314,9 @@
292 314 if ( ! class_exists( 'Aisentic\Api\Services\Registration_Service' ) ) {
293 315 return;
294 316 }
295 317
296 - $identity = timetics_aisentic_identity();
318 + $identity = timetics_aisentic_identity( $email );
297 319
298 320 // No email means nothing to register with, and Aisentic would reject
299 321 // the call anyway. Fail closed rather than inventing a value.
300 322 if ( empty( $identity['email'] ) ) {