PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
ultimate-post-kit / includes / ultimate-post-kit-metabox.php

ultimate-post-kit-metabox.php in Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets 4.5.6, at includes/ultimate-post-kit-metabox.php

116 lines 6.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 if (!defined('ABSPATH')) {
4 exit; // Exit if accessed directly.
5 }
6
7 if (!class_exists('Ultimate_Post_Kit_Metabox')) {
8 class Ultimate_Post_Kit_Metabox {
9 public $enabled_video_features;
10 public $enabled_audio_features;
11
12 public function __construct() {
13 $this->enabled_video_features = ultimate_post_kit_option('video_link', 'ultimate_post_kit_other_settings', 'off');
14 $this->enabled_audio_features = ultimate_post_kit_option('audio_link', 'ultimate_post_kit_other_settings', 'off');
15
16 if ($this->enabled_video_features == 'on' || $this->enabled_audio_features == 'on') {
17 add_action('admin_init', [$this, 'upk_additional_features_fields']);
18 add_action('save_post', [$this, 'upk_additional_features_save']);
19 }
20 }
21
22 public function upk_additional_features_fields() {
23 add_meta_box('upk_video_link_metabox', __('Ultimate Post Kit Additional', 'ultimate-post-kit'), [$this, 'upk_video_link_metabox_callback'], 'post', 'side', 'default');
24 }
25 public function upk_video_link_metabox_callback($post) {
26 wp_nonce_field('upk_additional_features_nonce_action', 'upk_additional_features_nonce_field');
27
28 $video_label = esc_html__('Video Link', 'ultimate-post-kit');
29 $video_link = get_post_meta($post->ID, '_upk_video_link_meta_key', true);
30
31 $audio_link_label = esc_html__('Audio Link', 'ultimate-post-kit');
32 $audio_link = get_post_meta($post->ID, '_upk_audio_link_meta_key', true);
33
34 $audio_label = esc_html__('Audio Title', 'ultimate-post-kit');
35 $audio_title = get_post_meta($post->ID, '_upk_audio_title_meta_key', true);
36
37 $artist_label = esc_html__('Artist Name', 'ultimate-post-kit');
38 $artist_name = get_post_meta($post->ID, '_upk_artist_name_meta_key', true);
39
40
41 $display_content = '<div class="upk-video-link-form-group">';
42 if ($this->enabled_video_features == 'on') {
43 $display_content .= '<label for="_upk_video_link_meta_key">' . $video_label . '</label>';
44 $display_content .= '<input type="text" class="widefat" name="_upk_video_link_meta_key" id="_upk_video_link_meta_key" value="' . $video_link . '">';
45 }
46 if ($this->enabled_audio_features == 'on') {
47 $display_content .= '<label for="_upk_audio_link_meta_key">' . $audio_link_label . '</label>';
48 $display_content .= '<input type="text" class="widefat" name="_upk_audio_link_meta_key" id="_upk_audio_link_meta_key" value="' . $audio_link . '">';
49 $display_content .= '<label for="_upk_audio_title_meta_key">' . $audio_label . '</label>';
50 $display_content .= '<input type="text" class="widefat" name="_upk_audio_title_meta_key" id="_upk_audio_title_meta_key" value="' . $audio_title . '">';
51 $display_content .= '<label for="_upk_artist_name_meta_key">' . $artist_label . '</label>';
52 $display_content .= '<input type="text" class="widefat" name="_upk_artist_name_meta_key" id="_upk_artist_name_meta_key" value="' . $artist_name . '">';
53 }
54 $display_content .= '</div>';
55
56
57
58
59 $this->get_control_output($display_content); // Method escapes and echoes internally via wp_kses().
60 }
61 public function get_control_output($output) {
62 $tags = [
63 'div' => ['class' => []],
64 'label' => ['for' => []],
65 'span' => ['scope' => [], 'class' => []],
66 'input' => ['type' => [], 'class' => [], 'id' => [], 'name' => [], 'value' => [], 'placeholder' => [], 'checked' => []],
67 ];
68 if (isset($output)) {
69 echo wp_kses($output, $tags);
70 }
71 }
72
73 public function upk_additional_features_save($post_id) {
74 if (!$this->is_secured_nonce('upk_additional_features_nonce_action', 'upk_additional_features_nonce_field', $post_id)) {
75 return $post_id;
76 }
77
78 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read.
79 $video_link = isset($_POST['_upk_video_link_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_video_link_meta_key'])) : '';
80 update_post_meta($post_id, '_upk_video_link_meta_key', $video_link);
81
82 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read.
83 $audio_link = isset($_POST['_upk_audio_link_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_audio_link_meta_key'])) : '';
84 update_post_meta($post_id, '_upk_audio_link_meta_key', $audio_link);
85
86 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read.
87 $audio_title = isset($_POST['_upk_audio_title_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_audio_title_meta_key'])) : '';
88 update_post_meta($post_id, '_upk_audio_title_meta_key', $audio_title);
89
90 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read.
91 $artist_name = isset($_POST['_upk_artist_name_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_artist_name_meta_key'])) : '';
92 update_post_meta($post_id, '_upk_artist_name_meta_key', $artist_name);
93 }
94
95
96 protected function is_secured_nonce($action, $nonce_field, $post_id) {
97 // phpcs:ignore WordPress.Security.NonceVerification.Missing -- reading the nonce value itself; it is validated with wp_verify_nonce() immediately below.
98 $nonce = isset($_POST[$nonce_field]) ? sanitize_text_field(wp_unslash($_POST[$nonce_field])) : '';
99 if ($nonce == '') {
100 return false;
101 } elseif (!wp_verify_nonce($nonce, $action)) {
102 return false;
103 } elseif (!current_user_can('edit_post', $post_id)) {
104 return false;
105 } elseif (wp_is_post_autosave($post_id)) {
106 return false;
107 } elseif (wp_is_post_revision($post_id)) {
108 return false;
109 } else {
110 return true;
111 }
112 }
113 }
114 new Ultimate_Post_Kit_Metabox();
115 }
116