| @@ -51,51 +51,33 @@ | ||
| 51 | 51 | if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) { |
| 52 | 52 | $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' ); |
| 53 | 53 | } |
| 54 | 54 | |
| 55 | - $post_type = $settings['post_source'] ?? 'post'; | |
| 56 | - | |
| 57 | - // Security: Enforce query limits to prevent DoS | |
| 58 | - $per_page = isset( $_POST['per_page'] ) ? absint( $_POST['per_page'] ) : 6; | |
| 59 | - $per_page = min( $per_page, 50 ); // Maximum 50 posts per request | |
| 60 | - $offset = isset( $_POST['offset'] ) ? absint( $_POST['offset'] ) : 0; | |
| 61 | - $offset = min( $offset, 1000 ); // Maximum offset of 1000 | |
| 62 | - | |
| 63 | - // Security: Whitelist allowed post types | |
| 64 | - $allowed_post_types = [ 'post', 'page' ]; | |
| 65 | - // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- established hook name relied on across the plugin family; renaming would break integration. | |
| 66 | - $allowed_post_types = apply_filters( 'upk_alex_grid_allowed_post_types', $allowed_post_types ); | |
| 67 | - $post_type = in_array( $post_type, $allowed_post_types, true ) ? $post_type : 'post'; | |
| 68 | - | |
| 69 | - // Security: Whitelist orderby values | |
| 70 | - $allowed_orderby = [ 'date', 'title', 'modified', 'rand', 'comment_count', 'menu_order' ]; | |
| 71 | - $posts_orderby = isset( $settings['posts_orderby'] ) && in_array( $settings['posts_orderby'], $allowed_orderby, true ) ? $settings['posts_orderby'] : 'date'; | |
| 72 | - | |
| 73 | - // Security: Whitelist order values | |
| 74 | - $posts_order = isset( $settings['posts_order'] ) && in_array( strtoupper( $settings['posts_order'] ), [ 'ASC', 'DESC' ], true ) ? strtoupper( $settings['posts_order'] ) : 'DESC'; | |
| 75 | - | |
| 76 | - $settings = array_merge( | |
| 55 | + // NOTE: the request-derived values below are NOT the ones the query is built from. | |
| 56 | + // query_args() is declared without parameters and re-reads $_POST['settings'] | |
| 57 | + // itself, so anything merged into $settings here is discarded. The query is | |
| 58 | + // constrained inside query_args(): post_status is pinned to 'publish', per_page | |
| 59 | + // is clamped to 1..100, and post_type is restricted to publicly visible post | |
| 60 | + // types by ultimate_post_kit_sanitize_public_post_type(). The defaults are kept | |
| 61 | + // only so the render loop below has the keys it expects. | |
| 62 | + $settings = array_merge( | |
| 77 | 63 | [ |
| 78 | - 'posts_source' => $post_type, | |
| 79 | - 'posts_orderby' => $posts_orderby, | |
| 80 | - 'posts_order' => $posts_order, | |
| 64 | + 'posts_source' => 'post', | |
| 65 | + 'posts_orderby' => 'date', | |
| 66 | + 'posts_order' => 'DESC', | |
| 81 | 67 | 'posts_ignore_sticky_posts' => 'no', |
| 82 | 68 | 'posts_only_with_featured_image' => 'no', |
| 83 | 69 | 'posts_select_date' => '', |
| 84 | 70 | 'posts_exclude_by' => [], |
| 85 | 71 | 'posts_include_by' => [], |
| 86 | - 'posts_per_page' => $per_page, | |
| 87 | - 'posts_offset' => $offset, | |
| 88 | 72 | ], |
| 89 | 73 | $settings |
| 90 | 74 | ); |
| 91 | - | |
| 75 | + | |
| 76 | + // Fill display flags the request may have omitted (see trait) before the render loop reads them. | |
| 77 | + $settings = array_merge( $this->loadmore_display_defaults(), $settings ); | |
| 78 | + | |
| 92 | 79 | $ajaxposts = $this->query_args( $settings ); |
| 93 | - | |
| 94 | - // Security: Override post_status to ensure only published posts are shown | |
| 95 | - if ( ! current_user_can( 'edit_posts' ) ) { | |
| 96 | - $ajaxposts->query_vars['post_status'] = 'publish'; | |
| 97 | - } | |
| 98 | 80 | |
| 99 | 81 | ob_start(); |
| 100 | 82 | $found_posts = false; |
| 101 | 83 | |
| @@ -107,9 +89,9 @@ | ||
| 107 | 89 | $title = get_the_title(); |
| 108 | 90 | $post_link = esc_url(get_permalink()); |
| 109 | 91 | $image_src = wp_get_attachment_image_url(get_post_thumbnail_id(), 'large'); |
| 110 | 92 | $image_src = $image_src ? esc_url($image_src) : esc_url(\Elementor\Utils::get_placeholder_image_src()); |
| 111 | - $category = wp_kses_post(upk_get_category($post_type)); | |
| 93 | + $category = wp_kses_post(upk_get_category($settings['posts_source'] ?? 'post')); | |
| 112 | 94 | $author_url = esc_url(get_author_posts_url(get_the_author_meta('ID'))); |
| 113 | 95 | $author_name = esc_html(get_the_author()); |
| 114 | 96 | $title_tag = Utils::get_valid_html_tag($settings['title_tags'] ); |
| 115 | 97 | |
| @@ -114,13 +96,9 @@ | ||
| 114 | 96 | $title_tag = Utils::get_valid_html_tag($settings['title_tags'] ); |
| 115 | 97 | |
| 116 | 98 | $meta_separator = isset( $settings['meta_separator'] ) ? $settings['meta_separator'] : '|'; |
| 117 | 99 | |
| 118 | - $onclick = ''; | |
| 119 | - if (!empty($settings['global_link']) && $settings['global_link'] === 'yes') { | |
| 120 | - $onclick = ' onclick="window.open(\'' . $post_link . '\', \'_self\')"'; | |
| 121 | - } | |
| 122 | - | |
| 100 | + | |
| 123 | 101 | $date = ''; |
| 124 | 102 | if (!empty($settings['human_diff_time']) && $settings['human_diff_time'] === 'yes') { |
| 125 | 103 | $date = ultimate_post_kit_post_time_diff(($settings['human_diff_time_short'] === 'yes') ? 'short' : ''); |
| 126 | 104 | } else { |