| @@ -3,10 +3,10 @@ | ||
| 3 | 3 | if (!defined('ABSPATH')) { |
| 4 | 4 | exit; |
| 5 | 5 | } |
| 6 | 6 | |
| 7 | -if (!class_exists('RC_Reviews_Collector')) { | |
| 8 | - class RC_Reviews_Collector { | |
| 7 | +if (!class_exists('Ultimate_Post_Kit_Reviews_Collector')) { | |
| 8 | + class Ultimate_Post_Kit_Reviews_Collector { | |
| 9 | 9 | |
| 10 | 10 | public $version = '1.0.0'; |
| 11 | 11 | |
| 12 | 12 | public $rc_name; |
| @@ -41,10 +41,10 @@ | ||
| 41 | 41 | $this->params = $params; |
| 42 | 42 | $this->review_url = isset($params['review_url']) ? $params['review_url'] : false; |
| 43 | 43 | |
| 44 | 44 | // add_action( 'admin_enqueue_scripts', array( $this, 'rc_enqueue_scripts' ) ); |
| 45 | - add_action('wp_ajax_rc_sdk_insights', array($this, 'rc_sdk_insights')); | |
| 46 | - add_action('wp_ajax_rc_sdk_dismiss_notice', array($this, 'rc_sdk_dismiss_notice')); | |
| 45 | + add_action('wp_ajax_ultimate_post_kit_reviews_insights', array($this, 'rc_sdk_insights')); | |
| 46 | + add_action('wp_ajax_ultimate_post_kit_reviews_dismiss_notice', array($this, 'rc_sdk_dismiss_notice')); | |
| 47 | 47 | |
| 48 | 48 | $security_key = md5($params['plugin_name']); |
| 49 | 49 | $this->rc_name = 'rc_' . str_replace('-', '_', sanitize_title($params['plugin_name']) . '_' . $security_key); |
| 50 | 50 | $this->rc_allow_name = 'rc_allow_' . $this->rc_name; |
| @@ -159,13 +159,22 @@ | ||
| 159 | 159 | /** |
| 160 | 160 | * Ajax callback |
| 161 | 161 | */ |
| 162 | 162 | public function rc_sdk_insights() { |
| 163 | - $sanitized_status = isset($_POST['button_val']) ? sanitize_text_field($_POST['button_val']) : ''; | |
| 164 | - $nonce = isset($_POST['nonce']) ? sanitize_text_field($_POST['nonce']) : ''; | |
| 165 | - $allow_name = isset($_POST['allow_name']) ? sanitize_text_field($_POST['allow_name']) : ''; | |
| 166 | - $date_name = isset($_POST['date_name']) ? sanitize_text_field($_POST['date_name']) : ''; | |
| 163 | + $sanitized_status = isset($_POST['button_val']) ? sanitize_text_field(wp_unslash($_POST['button_val'])) : ''; | |
| 164 | + $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : ''; | |
| 165 | + $allow_name = isset($_POST['allow_name']) ? sanitize_text_field(wp_unslash($_POST['allow_name'])) : ''; | |
| 166 | + $date_name = isset($_POST['date_name']) ? sanitize_text_field(wp_unslash($_POST['date_name'])) : ''; | |
| 167 | 167 | |
| 168 | + // Confine the writes to this SDK's own option namespace so a request | |
| 169 | + // cannot use these to overwrite an arbitrary WordPress option. | |
| 170 | + if (0 !== strpos($allow_name, 'rc_allow_')) { | |
| 171 | + $allow_name = ''; | |
| 172 | + } | |
| 173 | + if (0 !== strpos($date_name, 'rc_date_')) { | |
| 174 | + $date_name = ''; | |
| 175 | + } | |
| 176 | + | |
| 168 | 177 | if (!wp_verify_nonce($nonce, 'rc_sdk')) { |
| 169 | 178 | wp_send_json(array( |
| 170 | 179 | 'status' => 'error', |
| 171 | 180 | 'title' => 'Error', |
| @@ -182,19 +191,21 @@ | ||
| 182 | 191 | )); |
| 183 | 192 | wp_die(); |
| 184 | 193 | } |
| 185 | 194 | |
| 186 | - if ('disallow' == $sanitized_status) { | |
| 195 | + if ('disallow' == $sanitized_status && $allow_name) { | |
| 187 | 196 | update_option($allow_name, 'disallow'); |
| 188 | 197 | } |
| 189 | 198 | |
| 190 | - if ($sanitized_status == 'skip') { | |
| 199 | + if ($sanitized_status == 'skip' && $allow_name) { | |
| 191 | 200 | update_option($allow_name, 'skip'); |
| 192 | 201 | /** |
| 193 | 202 | * Next schedule date for attempt |
| 194 | 203 | */ |
| 195 | - update_option($date_name, gmdate('Y-m-d', strtotime("+1 month"))); | |
| 196 | - } elseif ($sanitized_status == 'yes') { | |
| 204 | + if ($date_name) { | |
| 205 | + update_option($date_name, gmdate('Y-m-d', strtotime("+1 month"))); | |
| 206 | + } | |
| 207 | + } elseif ($sanitized_status == 'yes' && $allow_name) { | |
| 197 | 208 | update_option($allow_name, 'yes'); |
| 198 | 209 | } |
| 199 | 210 | |
| 200 | 211 | wp_send_json(array( |
| @@ -268,10 +279,10 @@ | ||
| 268 | 279 | * |
| 269 | 280 | * @return void |
| 270 | 281 | */ |
| 271 | 282 | public function rc_sdk_dismiss_notice() { |
| 272 | - $nonce = isset($_POST['nonce']) ? sanitize_text_field($_POST['nonce']) : ''; | |
| 273 | - $rc_name = isset($_POST['rc_name']) ? sanitize_text_field($_POST['rc_name']) : ''; | |
| 283 | + $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : ''; | |
| 284 | + $rc_name = isset($_POST['rc_name']) ? sanitize_text_field(wp_unslash($_POST['rc_name'])) : ''; | |
| 274 | 285 | |
| 275 | 286 | if (!wp_verify_nonce($nonce, 'rc_sdk')) { |
| 276 | 287 | wp_send_json(array( |
| 277 | 288 | 'status' => 'error', |
| @@ -304,12 +315,7 @@ | ||
| 304 | 315 | |
| 305 | 316 | /** |
| 306 | 317 | * Main Insights Function |
| 307 | 318 | */ |
| 308 | -if (!function_exists('rc_sdk_automate')) { | |
| 309 | - function rc_sdk_automate($params) { | |
| 310 | - if (class_exists('RC_Reviews_Collector')) { | |
| 311 | - // RC_Reviews_Collector::get_instance( $params ); | |
| 312 | - new RC_Reviews_Collector($params); | |
| 313 | - } | |
| 314 | - } | |
| 319 | +function ultimate_post_kit_reviews_automate($params) { | |
| 320 | + new Ultimate_Post_Kit_Reviews_Collector($params); | |
| 315 | 321 | } |