PluginProbe
VdoCipher: Secure Video Player and Hosting / 1.11
VdoCipher: Secure Video Player and Hosting v1.11
trunk 1.10 1.11 1.12 1.13 1.14 1.15 1.17 1.18 1.19 1.20 1.21 1.22 1.23 1.24 1.25 1.26 1.27 1.28 1.29 1.3 1.30 1.4 1.5 1.6 All 28 releases
← All changes | vdocipher.php +101 -343 1.281.11 View file →
@@ -1,142 +1,85 @@
1 1 <?php
2 2 /**
3 3 * Plugin Name: VdoCipher
4 - * Plugin URI: https://www.vdocipher.com
5 - * Description: Secured video hosting for WordPress
6 - * Version: 1.28
4 + * Plugin URI: http://www.vdocipher.com
5 + * Description: Secured video hosting for wordpress
6 + * Version: 1.10
7 7 * Author: VdoCipher
8 - * Author URI: https://www.vdocipher.com
8 + * Author URI: http://www.vdocipher.com
9 9 * License: GPL2
10 10 */
11 11
12 12 if (__FILE__ == $_SERVER['SCRIPT_FILENAME']) {
13 13 header($_SERVER['SERVER_PROTOCOL'] . ' 404 Not Found');
14 - exit("<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML 2.0//EN\">\r\n<html lang='en'><head>\r\n<title>404 Not Found</title>\r\n".
14 + exit("<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML 2.0//EN\">\r\n<html><head>\r\n<title>404 Not Found</title>\r\n".
15 15 "</head><body>\r\n<h1>Not Found</h1>\r\n<p>The requested URL " . $_SERVER['SCRIPT_NAME'] . " was not found on ".
16 16 "this server.</p>\r\n</body></html>");
17 17 }
18 18
19 -if (!defined('VDOCIPHER_PLUGIN_VERSION')) {
20 - define('VDOCIPHER_PLUGIN_VERSION', '1.28');
21 -}
22 -
23 -if (!defined('VDOCIPHER_PLAYER_VERSION')) {
24 - define('VDOCIPHER_PLAYER_VERSION', 'v2');
25 -}
26 -
27 -if (!defined('VDOCIPHER_DEFAULT_THEME')) {
28 - define('VDOCIPHER_DEFAULT_THEME', '');
29 -}
30 -
31 -function vdo_plugin_check_version()
19 +function vdo_send($action, $params, $posts = array())
32 20 {
33 - // This applies only for installs 1.24 and below
34 - if (!get_option('vdo_plugin_version')) {
35 - if (preg_match('/^1\.[0123456]\.[0-9]{1,2}$/', get_option('vdo_embed_version'))) {
36 - update_option('vdo_embed_version', VDOCIPHER_PLAYER_VERSION);
37 - }
38 - if (preg_match('/^1\.[01234]\.[0-9]{1,2}$/', get_option('vdo_embed_version'))) {
39 - update_option('vdo_default_height', 'auto');
40 - }
41 - update_option('vdo_plugin_version', VDOCIPHER_PLUGIN_VERSION);
42 - return ;
43 - }
44 - // This applies for all new installations after 1.25
45 - if (VDOCIPHER_PLUGIN_VERSION !== get_option('vdo_plugin_version')) {
46 - if (preg_match('/^1\.[0-9]{1,2}\.[0-9]{1,2}$/', get_option('vdo_embed_version'))) {
47 - update_option('vdo_embed_version', VDOCIPHER_PLAYER_VERSION);
48 - }
49 - update_option('vdo_plugin_version', VDOCIPHER_PLUGIN_VERSION);
50 - }
51 -}
52 -
53 -add_action('plugins_loaded', 'vdo_plugin_check_version');
54 -
55 -// Function called to get OTP, starts
56 -function vdo_otp($video, $otp_post_array = array())
57 -{
58 21 $client_key = get_option('vdo_client_key');
59 22 if ($client_key == false || $client_key == "") {
60 - return (object)['message' => 'Plugin not configured. API Key missing.'];
61 - } else if (strlen($client_key) !== 64) {
62 - return (object)["message" => "Invalid API Key."];
23 + return "Plugin not configured. Please set the key to embed videos.";
63 24 }
64 - $url = "https://dev.vdocipher.com/api/videos/$video/otp";
65 - $headers = array(
66 - 'Authorization'=>'Apisecret '.$client_key,
67 - 'Content-Type'=>'application/json',
68 - 'Accept'=>'application/json'
69 - );
70 - $otp_post_json = json_encode($otp_post_array);
71 - $response = wp_remote_post(
72 - $url,
73 - array(
74 - 'method' => 'POST',
75 - 'headers' => $headers,
76 - 'body' => $otp_post_json
77 - )
78 - );
25 +
26 + $getData = http_build_query($params);
27 + $posts["clientSecretKey"] = $client_key;
28 + $url = "http://api.vdocipher.com/v2/$action/?$getData";
29 + $response = wp_safe_remote_post($url, array(
30 + 'method' => 'POST',
31 + 'body' => $posts
32 + ));
79 33 if (is_wp_error($response)) {
80 34 $error_message = $response->get_error_message();
81 - if (false !== stripos($error_message, 'Operation timed out')) {
82 - $error_message = 'Operation timed out. Check your firewall at web host or try after sometime.';
83 - } else if (false !== stripos($error_message, 'Could not resolve host')) {
84 - $error_message = 'Connectivity issue. Check firewall at web host.';
85 - }
86 - return ["message" => $error_message];
35 + echo "VdoCipher: Something went wrong: $error_message";
36 + return "";
87 37 }
88 -
89 - $responseCode = $response['response']['code'];
90 - if ($responseCode === 404) {
91 - return (object)["message" => "Video ID not found"];
92 - }
93 - else if ($responseCode === 403) {
94 - return (object)["message" => "API key does not have OTP creator permission"];
95 - }
96 - else if ($responseCode === 400 || $responseCode === 401) {
97 - return (object)["message" => "Incorrect API key"];
98 - } else {
99 - return json_decode($response['body']);
100 - }
38 + return $response['body'];
101 39 }
102 -// Function called to get OTP, ends
103 -
104 -// VdoCipher Shortcode starts
105 40 function vdo_shortcode($atts)
106 41 {
107 - $vdo_args = shortcode_atts(
42 + extract(shortcode_atts(
108 43 array(
109 - 'width' => get_option('vdo_default_width'),
110 - 'height' => get_option('vdo_default_height'),
111 - 'id' => 'id',
112 - 'no_annotate'=> false,
113 - 'vdo_theme'=> false,
114 - ),
44 + 'title' => 'TITLE_OF_VIDEO',
45 + 'width' => get_option('vdo_default_width') . "px",
46 + 'height' => get_option('vdo_default_height') . "px",
47 + 'id' => 'id',
48 + 'no_annotate'=> false,
49 + 'version'=> 0,
50 + ),
115 51 $atts
116 - );
117 - $width = $vdo_args['width'];
118 - $height = $vdo_args['height'];
119 - $id = $vdo_args['id'];
120 - $no_annotate = $vdo_args['no_annotate'];
121 - $vdo_theme = $vdo_args['vdo_theme'];
122 -
123 - if (!preg_match('/.*px$/', $width)) {
124 - $width = $width."px";
125 - }
126 - if (!preg_match('/.*px$/', $height)) {
127 - if ($height != 'auto') {
128 - $height = $height."px";
52 + ));
53 + if (!$atts['id']) {
54 + if (!$atts['title']) {
55 + return "Required argument id for embedded video not found.";
129 56 }
130 - }
131 - if (!$atts['id']) {
132 - return "Required argument id for embedded video not found.";
57 + $params = array(
58 + 'search'=>array(
59 + 'title'=>$title
60 + ),
61 + 'page'=>1,
62 + 'limit'=>30,
63 + 'type'=>'json'
64 + );
65 + $video = vdo_send("videos", $params);
66 + $video = json_decode($video);
67 + if ($video == null) {
68 + return "404. Video not found.";
69 + }
70 + $video = $video[0]->id;
71 + if ($video == null) {
72 + return "No video with given title found.";
73 + }
133 74 } else {
134 75 $video = $id;
135 76 }
136 77
137 - // Initialize $otp_post_array, to be sent as part of OTP request, as for time-to-live 300
138 - $otp_post_array = array("ttl" => 300);
78 + $params = array(
79 + 'video'=>$video
80 + );
81 + $anno = false;
139 82 if (!function_exists("eval_date")) {
140 83 function eval_date($matches)
141 84 {
142 85 return current_time($matches[1]);
@@ -152,204 +95,84 @@
152 95 $vdo_annotate_code = str_replace('{username}', $current_user->user_login, $vdo_annotate_code);
153 96 $vdo_annotate_code = str_replace('{id}', $current_user->ID, $vdo_annotate_code);
154 97 }
155 98 $vdo_annotate_code = str_replace('{ip}', $_SERVER['REMOTE_ADDR'], $vdo_annotate_code);
156 - $vdo_annotate_code = preg_replace_callback('/{date\.([^}]+)}/', "eval_date", $vdo_annotate_code);
99 + $vdo_annotate_code = preg_replace_callback('/\{date\.([^\}]+)\}/', "eval_date", $vdo_annotate_code);
157 100 $vdo_annotate_code = apply_filters('vdocipher_annotate_postprocess', $vdo_annotate_code);
158 - // Add annotate code to $otp_post_array, which will be
159 - // converted to Json and then sent as POST body to API endpoint
160 101 if (!$no_annotate) {
161 - $otp_post_array["annotate"] = $vdo_annotate_code;
102 + $anno = array("annotate" => $vdo_annotate_code);
162 103 }
163 104 }
164 - // OTP is requested via vdo_otp function
165 - $OTP_Response = vdo_otp($video, $otp_post_array);
166 -
167 - // https://www.php.net/manual/en/function.isset.php#86313
168 - $message = (isset($OTP_Response->message)) ? $OTP_Response->message : null;
169 - $OTP = (isset($OTP_Response->otp)) ? $OTP_Response->otp : null;
170 - $playbackInfo = (isset($OTP_Response->playbackInfo)) ? $OTP_Response->playbackInfo : null;
171 -
105 + $OTP = vdo_send("otp", $params, $anno);
106 + $OTP = json_decode($OTP);
172 107 if (is_null($OTP)) {
173 - return "<div id='vdo$OTP'><strong>VdoCipher Error: $message</strong></div>";
108 + $output = "<span id='vdo$OTP' style='background:#555555;color:#FFFFFF'><h4>Video not found</h4></span>";
109 + return $output;
174 110 }
111 + $OTP = $OTP->otp;
175 112
176 - // Version, legacy, for flash only
177 113 $version = 0;
178 114 if (isset($atts['version'])) {
179 115 $version = $atts['version'];
180 116 }
181 -
182 - // Video Embed version is retrieved from options table or from shortcode attribute
183 - $vdo_embed_version_str = get_option('vdo_embed_version');
184 -
185 - // Video Player theme, update and as shortcode attribute
186 - if (!$vdo_theme) {
187 - $vdo_player_theme = get_option('vdo_player_theme');
188 - } else {
189 - $vdo_player_theme = $vdo_theme;
117 + $output = "<div id='vdo$OTP' style='height:$height;width:$width;max-width:100%' ></div>";
118 + $output .= "<script> (function(v,i,d,e,o){v[o]=v[o]||{}; v[o].add = v[o].add || function V(a){".
119 + " (v[o].d=v[o].d||[]).push(a);};";
120 + $output .= "if(!v[o].l) { v[o].l=1*new Date(); a=i.createElement(d), m=i.getElementsByTagName(d)[0]; a.async=1; ".
121 + "a.src=e; m.parentNode.insertBefore(a,m);}";
122 + $output .= " })(window,document,'script','//de122v0opjemw.cloudfront.net/vdo.js','vdo'); vdo.add({ ";
123 + $output .= "o: '$OTP', ";
124 + if ($version == 32) {
125 + $output .= "version: '$version' ";
190 126 }
191 - if (strpos($vdo_player_theme, 'v1/') === 0 || strlen($vdo_player_theme) === 32) {
192 - $vdo_embed_version_str = '1.6.10';
193 - } else if (strlen($vdo_player_theme) === 16) {
194 - $vdo_embed_version_str = 'v2';
195 - }
196 - $speedOptions = esc_attr(get_option('vdo_player_speed'));
197 - $speedPattern = '/^\d.\d{1,2}(,\d.\d{1,2})+$/';
198 -
199 - // Old Embed Code
200 - if ($vdo_embed_version_str === '1.6.10') {
201 - //Old embed code
202 - $output = <<<END
203 - <div id='vdo$OTP' style='height:$height;width:$width;max-width:100%' ></div>
204 - <script>(function(v,i,d,e,o){v[o]=v[o]||{}; v[o].add = v[o].add || function V(a){
205 - (v[o].d=v[o].d||[]).push(a);};
206 - if(!v[o].l) { v[o].l=1*new Date(); a=i.createElement(d), m=i.getElementsByTagName(d)[0];
207 - a.async=1; a.src=e; m.parentNode.insertBefore(a,m);}
208 - })(window,document,'script','https://d1z78r8i505acl.cloudfront.net/playerAssets/1.6.10/vdo.js','vdo');
209 - vdo.add({
210 - otp: '$OTP',
211 - playbackInfo: '$playbackInfo',
212 - theme: '$vdo_player_theme',
213 - plugins: [{
214 - name: 'keyboard',
215 - options: {
216 - preset: 'default',
217 - bindings: {
218 - 'Left' : (player) => player.seek(player.currentTime - 15),
219 - 'Right' : (player) => player.seek(player.currentTime + 15),
220 - },
221 - }
222 - }],
223 - container: document.querySelector('#vdo$OTP'),
224 - })
225 - </script>
226 -END;
227 -
228 - if ($speedOptions !== false && preg_match($speedPattern, $speedOptions)) {
229 - $output .= <<<END
230 - <script>
231 - (function () {
232 - var originalReadyFunction = window.onVdoCipherAPIReady;
233 - // private API; do not use anywhere else; might change without notice
234 - var index = vdo.d.length - 1;
235 - window.onVdoCipherAPIReady = () => {
236 - if (originalReadyFunction) originalReadyFunction();
237 - var v_ = vdo.getObjects()[index];
238 - v_.addEventListener('load', () => {
239 - v_.availablePlaybackRates = [$speedOptions]
240 - });
241 - }
242 - })()
243 - </script>
244 -END;
245 - }
246 - } else if ($vdo_embed_version_str === 'v2') {
247 - $uniq = 'u' . rand();
248 - $output = <<<END
249 -<script src="https://player.vdocipher.com/v2/api.js"></script>
250 -<iframe
251 - src="https://player.vdocipher.com/v2/?otp=$OTP&playbackInfo=$playbackInfo"
252 - id="$uniq"
253 - style="height:$height;width:$width;max-width:100%;border:0;display: block;"
254 - allow="encrypted-media"
255 - allowfullscreen
256 -></iframe>
257 -<script>
258 -(function() {
259 - const iframe = document.querySelector('#$uniq');
260 - const player = VdoPlayer.getInstance(iframe);
261 - player.video.addEventListener('loadstart', async () => {
262 - const aspectRatio = (await player.api.getMetaData()).aspectRatio;
263 - if (iframe.style.height === 'auto' && iframe.style.width.endsWith('px')) {
264 - iframe.style.maxHeight = '100vh';
265 - if (CSS.supports('aspect-ratio', 1)) {
266 - iframe.style.aspectRatio = aspectRatio;
267 - } else {
268 - const offsetWidth = iframe.offsetWidth;
269 - iframe.style.height = Math.round(offsetWidth / aspectRatio) + 'px';
270 - }
271 - }
272 - });
273 -})();
274 -</script>
275 -END;
276 - if ($speedOptions !== false && preg_match($speedPattern, $speedOptions)) {
277 - $output .= <<<END
278 -<script>
279 -(function() {
280 - const iframe = document.querySelector('#$uniq')
281 - const player = VdoPlayer.getInstance(iframe);
282 - player.video.addEventListener('loadstart', async () => {
283 - player.api.updatePlayerConfig({playbackSpeedOptions: [$speedOptions]});
284 - });
285 -})();
286 -</script>
287 -END;
288 - }
289 -
290 - } else {
291 - $output = 'Invalid player selection: ' . $vdo_embed_version_str;
292 - }
127 + $output .= "}); </script>";
293 128 return $output;
294 129 }
130 +
295 131 add_shortcode('vdo', 'vdo_shortcode');
296 -// VdoCipher Shortcode ends
297 132
298 -// adding the Settings link, starts
133 +
134 +/// adding the settings link
299 135 $plugin = plugin_basename(__FILE__);
300 136 add_filter("plugin_action_links_$plugin", 'vdo_settings_link');
301 137
302 138 function vdo_settings_link($links)
303 139 {
304 - $settings_link = '<a href="options-general.php?page=vdocipher">Settings</a>';
140 + $settings_link = '<a href="options-general.php?page=vdocipher.php">Settings</a>';
305 141 array_unshift($links, $settings_link);
306 142 return $links;
307 143 }
308 -// adding the Settings link, ends
309 144
310 -// add the menu item and register settings (3 functions), starts
145 +
146 +/// add the menu item and register settings
311 147 if (is_admin()) { // admin actions
148 + add_action('admin_menu', 'vdo_menu');
312 149 add_action('admin_init', 'register_vdo_settings');
313 - add_action('admin_menu', 'vdo_menu');
150 +} else {
151 + // non-admin enqueues, actions, and filters
314 152 }
315 153 function vdo_menu()
316 154 {
317 - if (get_option('vdo_show_plugin_in_sidebar') === "") {
318 - add_options_page(
319 - 'VdoCipher Options',
320 - 'VdoCipher',
321 - 'manage_options',
322 - 'vdocipher',
323 - 'vdo_options'
324 - );
325 - } else {
326 - add_menu_page(
327 - 'VdoCipher Options',
328 - 'VdoCipher',
329 - 'manage_options',
330 - 'vdocipher',
331 - 'vdo_options',
332 - plugin_dir_url(__FILE__).'images/logo.png'
333 - );
334 - }
155 + add_options_page('VdoCipher Options', 'VdoCipher', 'manage_options', 'vdocipher', 'vdo_options');
335 156 }
336 -
337 157 function vdo_options()
338 158 {
339 159 if (!get_option('vdo_default_height')) {
340 - update_option('vdo_default_height', 'auto');
160 + update_option('vdo_default_height', '360');
341 161 }
342 162 if (!get_option('vdo_default_width')) {
343 - update_option('vdo_default_width', '1280');
163 + update_option('vdo_default_width', '640');
344 164 }
165 + $vdo_client_key = get_option('vdo_client_key');
166 + if (!$vdo_client_key && strlen($vdo_client_key) != 64) {
167 + vdo_show_form_client_key();
168 + return "";
169 + }
345 170 if (!current_user_can('manage_options')) {
346 - wp_die(__('You do not have sufficient permissions to access this page.'));
171 + wp_die(__('You do not have sufficient permissions to access this page.'));
347 172 }
348 173 include('include/options.php');
349 - return "";
350 174 }
351 -
352 175 function register_vdo_settings()
353 176 {
354 177 // whitelist options
355 178 register_setting('vdo_option-group', 'vdo_client_key');
@@ -355,98 +178,33 @@
355 178 register_setting('vdo_option-group', 'vdo_client_key');
356 179 register_setting('vdo_option-group', 'vdo_default_height');
357 180 register_setting('vdo_option-group', 'vdo_default_width');
358 181 register_setting('vdo_option-group', 'vdo_annotate_code');
359 - register_setting('vdo_option-group', 'vdo_embed_version');
360 - register_setting('vdo_option-group', 'vdo_player_theme');
361 - register_setting('vdo_option-group', 'vdo_plugin_version');
362 - register_setting('vdo_option-group', 'vdo_player_speed');
363 - register_setting('vdo_option-group', 'vdo_show_plugin_in_sidebar');
364 182 }
365 -// add the menu item and register settings (3 functions), ends
366 183
367 -// Activation Hook starts
368 -function vdo_activate()
184 +/// adding a section for asking for the client key
185 +function vdo_show_form_client_key()
369 186 {
370 - add_option('vdo_default_height', 'auto');
371 - add_option('vdo_default_width', 1280);
372 - add_option('vdo_embed_version', VDOCIPHER_PLAYER_VERSION);
373 - add_option('vdo_player_theme', VDOCIPHER_DEFAULT_THEME);
374 - add_option('vdo_show_plugin_in_sidebar', 'true');
187 + include('include/setting_form.php');
375 188 }
376 -register_activation_hook(__FILE__, 'vdo_activate');
377 -
378 -// Registering and specifying Gutenberg block
379 -function vdo_register_block()
189 +register_deactivation_hook(__FILE__, 'vdo_deactivate');
190 +function vdo_deactivate()
380 191 {
381 - if (!function_exists('register_block_type')) {
382 - return ;
383 - }
384 - wp_register_script(
385 - 'vdo-block-script',
386 - plugins_url('/include/block/dist/blocks.build.js', __FILE__),
387 - array('wp-blocks', 'wp-element', 'wp-editor', 'wp-i18n')
388 - );
389 - wp_register_style(
390 - 'vdo-block-base-style',
391 - plugins_url('/include/block/dist/blocks.style.build.css', __FILE__),
392 - array('wp-blocks')
393 - );
394 - wp_register_style(
395 - 'vdo-block-editor-style',
396 - plugins_url('/include/block/dist/blocks.editor.build.css', __FILE__),
397 - array('wp-edit-blocks')
398 - );
399 - register_block_type(
400 - 'vdo/block',
401 - array(
402 - 'editor_script'=>'vdo-block-script',
403 - 'editor_style'=>'vdo-block-editor-style',
404 - 'style'=>'vdo-block-base-style',
405 - 'attributes'=>array(
406 - 'id'=>array(
407 - 'type'=>'string',
408 - ),
409 - 'width'=>array(
410 - 'type'=>'string',
411 - 'default'=>get_option('vdo_default_width')
412 - ),
413 - 'height'=>array(
414 - 'type'=>'string',
415 - 'default'=>get_option('vdo_default_height')
416 - ),
417 - 'vdo_theme'=>array(
418 - 'type'=>'string',
419 - 'default'=>get_option('vdo_player_theme')
420 - ),
421 - 'vdo_version'=>array(
422 - 'type'=>'string',
423 - 'default'=>get_option('vdo_embed_version')
424 - ),
425 - ),
426 - 'render_callback'=>'vdo_shortcode'
427 - )
428 - );
429 -}
430 -
431 -add_action('init', 'vdo_register_block');
432 -
433 -// Deactivation Hook starts
434 -function vdo_uninstall()
435 -{
436 192 delete_option('vdo_client_key');
437 193 delete_option('vdo_default_width');
438 194 delete_option('vdo_default_height');
439 195 delete_option('vdo_annotate_code');
440 - delete_option('vdo_embed_version');
441 - delete_option('vdo_player_theme');
442 - delete_option('vdo_plugin_version');
443 - delete_option('vdo_player_speed');
444 - delete_option('vdo_show_plugin_in_sidebar');
445 196 }
446 -register_uninstall_hook(__FILE__, 'vdo_uninstall');
447 -
448 -// Admin notice to configure plugin for new installs, starts
197 +function vdo_activate()
198 +{
199 + if (!get_option('vdo_default_height')) {
200 + update_option('vdo_default_height', '400');
201 + }
202 + if (!get_option('vdo_default_width')) {
203 + update_option('vdo_default_width', '640');
204 + }
205 +}
206 +register_activation_hook(__FILE__, 'vdo_activate');
449 207 function vdo_admin_notice()
450 208 {
451 209 if ((!get_option('vdo_client_key') || strlen(get_option('vdo_client_key')) != 64)
452 210 && basename($_SERVER['PHP_SELF']) == "plugins.php"