| @@ -32,9 +32,15 @@ | ||
| 32 | 32 | return $widgets; |
| 33 | 33 | } |
| 34 | 34 | |
| 35 | 35 | public function callback_ajax_loadmore_posts() { |
| 36 | + // Verify the front-end nonce (sent by UltimatePostKitConfig.nonce) before | |
| 37 | + // processing this public load-more request. | |
| 38 | + if ( ! check_ajax_referer( 'upk-site', 'nonce', false ) ) { | |
| 39 | + wp_send_json_error( array( 'message' => esc_html__( 'Security check failed.', 'ultimate-post-kit' ) ), 403 ); | |
| 40 | + } | |
| 36 | 41 | |
| 42 | + | |
| 37 | 43 | $settings = []; |
| 38 | 44 | |
| 39 | 45 | if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) { |
| 40 | 46 | $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' ); |
| @@ -57,8 +63,11 @@ | ||
| 57 | 63 | ], |
| 58 | 64 | $settings |
| 59 | 65 | ); |
| 60 | 66 | |
| 67 | + // Fill display flags the request may have omitted (see trait) before the render loop reads them. | |
| 68 | + $settings = array_merge( $this->loadmore_display_defaults(), $settings ); | |
| 69 | + | |
| 61 | 70 | $ajaxposts = $this->query_args( $settings ); |
| 62 | 71 | |
| 63 | 72 | ob_start(); |
| 64 | 73 | $found_posts = false; |
| @@ -75,15 +84,10 @@ | ||
| 75 | 84 | $author_name = esc_html( get_the_author() ); |
| 76 | 85 | $meta_sep = $settings['meta_separator'] ?? '/'; |
| 77 | 86 | $title_tag = Utils::get_valid_html_tag($settings['title_tags']); |
| 78 | 87 | |
| 79 | - $onclick = ''; | |
| 80 | - if ( ! empty( $settings['global_link'] ) && $settings['global_link'] === 'yes' ) { | |
| 81 | - $onclick = 'onclick="window.open(\'' . esc_url( $post_link ) . '\', \'_self\')"'; | |
| 82 | - } | |
| 83 | - | |
| 84 | 88 | ?> |
| 85 | - <div <?php echo $onclick; ?> class="upk-item"> | |
| 89 | + <div <?php if ( ! empty( $settings['global_link'] ) && $settings['global_link'] === 'yes' ) { printf( 'onclick="window.open(\'%s\', \'_self\')"', esc_url( $post_link ) ); } ?> class="upk-item"> | |
| 86 | 90 | <div class="upk-image-wrap"> |
| 87 | 91 | <?php $this->render_image(get_post_thumbnail_id(), 'large'); ?> |
| 88 | 92 | |
| 89 | 93 | <div class="upk-content"> |
| @@ -180,11 +184,11 @@ | ||
| 180 | 184 | if (has_excerpt()) { |
| 181 | 185 | the_excerpt(); |
| 182 | 186 | } else { |
| 183 | 187 | if (function_exists('ultimate_post_kit_custom_excerpt')) { |
| 184 | - echo wp_kses_post(ultimate_post_kit_custom_excerpt(intval($settings['excerpt_length'] ?? 20), false, '')); | |
| 188 | + echo wp_kses_post(ultimate_post_kit_custom_excerpt(ultimate_post_kit_clamp_excerpt_length($settings['excerpt_length'] ?? 20, 20), false, '')); | |
| 185 | 189 | } else { |
| 186 | - echo esc_html(wp_trim_words(wp_strip_all_tags(get_the_content()), intval($settings['excerpt_length'] ?? 20))); | |
| 190 | + echo esc_html(wp_trim_words(wp_strip_all_tags(get_the_content()), ultimate_post_kit_clamp_excerpt_length($settings['excerpt_length'] ?? 20, 20))); | |
| 187 | 191 | } |
| 188 | 192 | } |
| 189 | 193 | ?> |
| 190 | 194 | </div> |
| @@ -197,11 +201,12 @@ | ||
| 197 | 201 | <?php if ($settings['show_readmore'] === 'yes') : ?> |
| 198 | 202 | <a href="<?php echo esc_url($post_link); ?>" class="upk-readmore" target="<?php echo esc_attr($settings['upk_link_new_tab'] === 'yes' ? '_blank' : '_self'); ?>"> |
| 199 | 203 | <span class="upk-flex upk-flex-middle"> |
| 200 | 204 | <?php echo esc_html($settings['readmore_text'] ?? __('Read More', 'ultimate-post-kit')); ?> |
| 201 | - <?php if ($settings['readmore_icon']['value']) : ?> | |
| 205 | + <?php $upk_readmore_icon = ultimate_post_kit_sanitize_request_icon($settings['readmore_icon'] ?? null); ?> | |
| 206 | + <?php if ($upk_readmore_icon) : ?> | |
| 202 | 207 | <span class="upk-readmore-btn-icon upk-flex-align-<?php echo esc_attr($settings['icon_align']); ?>"> |
| 203 | - <?php Icons_Manager::render_icon($settings['readmore_icon'], ['aria-hidden' => 'true', 'class' => 'fa-fw']); ?> | |
| 208 | + <?php Icons_Manager::render_icon($upk_readmore_icon, ['aria-hidden' => 'true', 'class' => 'fa-fw']); ?> | |
| 204 | 209 | </span> |
| 205 | 210 | <?php endif; ?> |
| 206 | 211 | </span> |
| 207 | 212 | </a> |
| @@ -209,9 +214,9 @@ | ||
| 209 | 214 | </div> |
| 210 | 215 | |
| 211 | 216 | <?php if ($settings['show_comments'] === 'yes') : ?> |
| 212 | 217 | <div class="upk-comments"> |
| 213 | - <?php echo absint(get_comments_number()); ?> <?php echo esc_html_x('Comments', 'Frontend', 'ultimate-post-kit'); ?> | |
| 218 | + <?php echo esc_html( $this->upk_get_formatted_comments_count( get_the_ID() ) ); ?> | |
| 214 | 219 | </div> |
| 215 | 220 | <?php endif; ?> |
| 216 | 221 | </div> |
| 217 | 222 | </div> |