| @@ -44,8 +44,15 @@ | ||
| 44 | 44 | |
| 45 | 45 | $list_id = (!empty($options['mailchimp_list_id'])) ? $options['mailchimp_list_id'] : ''; // Your list is here |
| 46 | 46 | $api_key = (!empty($options['mailchimp_api_key'])) ? $options['mailchimp_api_key'] : ''; // Your mailchimp api key here |
| 47 | 47 | |
| 48 | + // This endpoint is registered on wp_ajax_nopriv_, so it is reachable before the | |
| 49 | + // site owner has configured Mailchimp at all. Without credentials the request | |
| 50 | + // below would be built against an unresolvable host and fail. | |
| 51 | + if (empty($api_key) || empty($list_id) || false === strpos($api_key, '-')) { | |
| 52 | + return null; | |
| 53 | + } | |
| 54 | + | |
| 48 | 55 | $args = array( |
| 49 | 56 | 'method' => 'PUT', |
| 50 | 57 | 'headers' => array( |
| 51 | 58 | 'Authorization' => 'Basic ' . base64_encode('user:' . $api_key) |
| @@ -57,9 +64,15 @@ | ||
| 57 | 64 | )) |
| 58 | 65 | ); |
| 59 | 66 | $response = wp_remote_post('https://' . substr($api_key, strpos($api_key, '-') + 1) . '.api.mailchimp.com/3.0/lists/' . $list_id . '/members/' . md5(strtolower($email)), $args); |
| 60 | 67 | |
| 61 | - $body = json_decode($response['body']); | |
| 68 | + // A transport failure returns WP_Error, which is an object: indexing it as an | |
| 69 | + // array is a fatal. The caller already handles a null/!is_object result. | |
| 70 | + if (is_wp_error($response)) { | |
| 71 | + return null; | |
| 72 | + } | |
| 73 | + | |
| 74 | + $body = json_decode(wp_remote_retrieve_body($response)); | |
| 62 | 75 | |
| 63 | 76 | return $body; |
| 64 | 77 | } |
| 65 | 78 | |