PluginProbe
Visualizer – Tables & Charts Manager with Built-in AI Generator / 3.2.0
Visualizer – Tables & Charts Manager with Built-in AI Generator v3.2.0
4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.10.1 3.10.10 3.10.11 3.10.12 3.10.13 3.10.14 3.10.15 3.10.2 3.10.3 3.10.4 All 148 releases
← All changes | classes/Visualizer/Module/Chart.php +200 -806 4.0.63.2.0 View file →
@@ -68,38 +68,11 @@
68 68 $this->_addAjaxAction( Visualizer_Plugin::ACTION_JSON_SET_SCHEDULE, 'setJsonSchedule' );
69 69
70 70 $this->_addAjaxAction( Visualizer_Plugin::ACTION_SAVE_FILTER_QUERY, 'saveFilter' );
71 71
72 - $this->_addFilter( 'visualizer_get_sidebar', 'getSidebar', 10, 2 );
73 72 }
74 73
75 74 /**
76 - * Generates the HTML of the sidebar for the chart.
77 - *
78 - * @since ?
79 - *
80 - * @access public
81 - */
82 - public function getSidebar( $sidebar, $chart_id ) {
83 - $chart = get_post( $chart_id );
84 - $data = $this->_getChartArray( $chart );
85 - $sidebar = '';
86 - $sidebar_class = $this->load_chart_class_name( $chart_id );
87 - if ( class_exists( $sidebar_class, true ) ) {
88 - $sidebar = new $sidebar_class( $data['settings'] );
89 - $sidebar->__series = $data['series'];
90 - $sidebar->__data = $data['data'];
91 - } else {
92 - $sidebar = apply_filters( 'visualizer_pro_chart_type_sidebar', '', $data );
93 - if ( $sidebar !== '' ) {
94 - $sidebar->__series = $data['series'];
95 - $sidebar->__data = $data['data'];
96 - }
97 - }
98 - return str_replace( "'", '"', $sidebar->__toString() );
99 - }
100 -
101 - /**
102 75 * Sets the schedule for how JSON-endpoint charts should be updated.
103 76 *
104 77 * @since ?
105 78 *
@@ -107,10 +80,11 @@
107 80 */
108 81 public function setJsonSchedule() {
109 82 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_SET_SCHEDULE . Visualizer_Plugin::VERSION, 'security' );
110 83
111 - $chart_id = isset( $_POST['chart'] ) ? filter_var(
112 - $_POST['chart'],
84 + $chart_id = filter_input(
85 + INPUT_POST,
86 + 'chart',
113 87 FILTER_VALIDATE_INT,
114 88 array(
115 89 'options' => array(
116 90 'min_range' => 1,
@@ -115,18 +89,14 @@
115 89 'options' => array(
116 90 'min_range' => 1,
117 91 ),
118 92 )
119 - ) : false;
93 + );
120 94
121 95 if ( ! $chart_id ) {
122 96 wp_send_json_error();
123 97 }
124 98
125 - if ( ! self::can_edit_chart( $chart_id ) ) {
126 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ), 403 );
127 - }
128 -
129 99 $time = filter_input(
130 100 INPUT_POST,
131 101 'time',
132 102 FILTER_VALIDATE_INT,
@@ -136,30 +106,12 @@
136 106 ),
137 107 )
138 108 );
139 109
140 - if ( Visualizer_Module::is_pro() ) {
141 - $is_woocommerce_report = filter_input(
142 - INPUT_POST,
143 - 'is_woocommerce_report',
144 - FILTER_VALIDATE_BOOLEAN
145 - );
146 -
147 - if ( $is_woocommerce_report ) {
148 - update_post_meta( $chart_id, Visualizer_Plugin::CF_IS_WOOCOMMERCE_SOURCE, true );
149 - } else {
150 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_IS_WOOCOMMERCE_SOURCE );
151 - }
152 - }
153 -
154 110 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE );
155 111
156 112 if ( -1 < $time ) {
157 113 add_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE, $time );
158 - // Update schedules.
159 - $schedules = get_option( Visualizer_Plugin::CF_JSON_SCHEDULE, array() );
160 - $schedules[ $chart_id ] = time() + $time * HOUR_IN_SECONDS;
161 - update_option( Visualizer_Plugin::CF_JSON_SCHEDULE, $schedules );
162 114 }
163 115 wp_send_json_success();
164 116 }
165 117
@@ -172,12 +124,8 @@
172 124 */
173 125 public function getJsonRoots() {
174 126 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_GET_ROOTS . Visualizer_Plugin::VERSION, 'security' );
175 127
176 - if ( ! current_user_can( 'edit_posts' ) ) {
177 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ) );
178 - }
179 -
180 128 $params = wp_parse_args( $_POST['params'] );
181 129
182 130 $source = new Visualizer_Source_Json( $params );
183 131
@@ -182,9 +130,9 @@
182 130 $source = new Visualizer_Source_Json( $params );
183 131
184 132 $roots = $source->fetchRoots();
185 133 if ( empty( $roots ) ) {
186 - wp_send_json_error( array( 'msg' => $source->get_error() ) );
134 + wp_send_json_error();
187 135 }
188 136
189 137 wp_send_json_success( array( 'url' => $params['url'], 'roots' => $roots ) );
190 138 }
@@ -198,27 +146,21 @@
198 146 */
199 147 public function getJsonData() {
200 148 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_GET_DATA . Visualizer_Plugin::VERSION, 'security' );
201 149
202 - if ( ! current_user_can( 'edit_posts' ) ) {
203 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ) );
204 - }
205 -
206 150 $params = wp_parse_args( $_POST['params'] );
207 151
208 152 $chart_id = $params['chart'];
209 153
210 - $chart = $chart_id ? get_post( $chart_id ) : null;
211 - if ( ! $chart || Visualizer_Plugin::CPT_VISUALIZER !== $chart->post_type || ! current_user_can( 'edit_post', $chart_id ) ) {
154 + if ( empty( $chart_id ) ) {
212 155 wp_die();
213 156 }
214 157
215 158 $source = new Visualizer_Source_Json( $params );
216 - $source->fetch();
217 - $data = $source->getRawData();
218 159
160 + $data = $source->parse();
219 161 if ( empty( $data ) ) {
220 - wp_send_json_error( array( 'msg' => esc_html__( 'Unable to fetch data from the endpoint. Please try again.', 'visualizer' ) ) );
162 + wp_send_json_error();
221 163 }
222 164
223 165 $data = Visualizer_Render_Layout::show( 'editor-table', $data, $chart_id, 'viz-json-table', false, false );
224 166 wp_send_json_success( array( 'table' => $data, 'root' => $params['root'], 'url' => $params['url'], 'paging' => $source->getPaginationElements() ) );
@@ -234,21 +176,20 @@
234 176 public function setJsonData() {
235 177 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_SET_DATA . Visualizer_Plugin::VERSION, 'security' );
236 178
237 179 $params = $_POST;
238 - $chart_id = isset( $_GET['chart'] ) ? absint( $_GET['chart'] ) : 0;
180 + $chart_id = $_GET['chart'];
239 181
240 - if ( ! self::can_edit_chart( $chart_id ) ) {
241 - wp_die( esc_html__( 'You do not have permission to perform this action.', 'visualizer' ), '', array( 'response' => 403 ) );
182 + if ( empty( $chart_id ) ) {
183 + wp_die();
242 184 }
243 185
244 186 $chart = get_post( $chart_id );
245 187
246 188 $source = new Visualizer_Source_Json( $params );
247 - update_post_meta( $chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true );
248 - $source->fetchFromEditableTable();
189 + $source->fetch();
249 190
250 - $content = $source->getData( get_post_meta( $chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) );
191 + $content = $source->getData();
251 192 $chart->post_content = $content;
252 193 wp_update_post( $chart->to_array() );
253 194 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
254 195 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
@@ -254,62 +195,20 @@
254 195 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
255 196 update_post_meta( $chart->ID, Visualizer_Plugin::CF_DEFAULT_DATA, 0 );
256 197 update_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_URL, $params['url'] );
257 198 update_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_ROOT, $params['root'] );
258 -
259 - delete_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_HEADERS );
260 - $headers = array( 'method' => $params['method'] );
261 - if ( ! empty( $params['auth'] ) ) {
262 - $headers['auth'] = $params['auth'];
263 - } elseif ( ! empty( $params['username'] ) && ! empty( $params['password'] ) ) {
264 - $headers['auth'] = array( 'username' => $params['username'], 'password' => $params['password'] );
265 - }
266 -
267 - add_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_HEADERS, $headers );
268 -
269 199 delete_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_PAGING );
270 200 if ( ! empty( $params['paging'] ) ) {
271 201 add_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_PAGING, $params['paging'] );
272 202 }
273 203
274 - if ( Visualizer_Module::is_pro() ) {
275 - if ( ! empty( $params['vz_woo_source'] ) ) {
276 - update_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_WOOCOMMERCE_SOURCE, $params['vz_woo_source'] );
277 - } else {
278 - delete_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_WOOCOMMERCE_SOURCE );
279 - }
280 - }
281 -
282 - $time = filter_input(
283 - INPUT_POST,
284 - 'time',
285 - FILTER_VALIDATE_INT,
286 - array(
287 - 'options' => array(
288 - 'min_range' => -1,
289 - ),
290 - )
291 - );
292 -
293 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE );
294 -
295 - if ( -1 < $time ) {
296 - add_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE, $time );
297 - }
298 -
299 - // delete other source specific parameters.
300 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY );
301 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_SCHEDULE );
302 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_URL );
303 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_SCHEDULE );
304 -
305 204 $render = new Visualizer_Render_Page_Update();
306 205 $render->id = $chart->ID;
307 - $render->data = json_encode( $source->getRawData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ) );
206 + $render->data = json_encode( $source->getRawData() );
308 207 $render->series = json_encode( $source->getSeries() );
309 208 $render->render();
310 209
311 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
210 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
312 211 }
313 212
314 213
315 214 /**
@@ -321,14 +220,8 @@
321 220 *
322 221 * @access public
323 222 */
324 223 public function getCharts() {
325 - check_ajax_referer( Visualizer_Plugin::ACTION_GET_CHARTS, 'nonce' );
326 -
327 - if ( ! current_user_can( 'edit_posts' ) ) {
328 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ), 403 );
329 - }
330 -
331 224 $query_args = array(
332 225 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
333 226 'posts_per_page' => 9,
334 227 'paged' => filter_input(
@@ -342,11 +235,8 @@
342 235 ),
343 236 )
344 237 ),
345 238 );
346 - if ( ! current_user_can( 'edit_others_posts' ) ) {
347 - $query_args['author'] = get_current_user_id();
348 - }
349 239 $filter = filter_input( INPUT_GET, 's', FILTER_SANITIZE_STRING );
350 240 if ( empty( $filter ) ) {
351 241 // 'filter' is from the modal from the add media button.
352 242 $filter = filter_input( INPUT_GET, 'filter', FILTER_SANITIZE_STRING );
@@ -394,19 +284,19 @@
394 284 * @since 1.0.0
395 285 *
396 286 * @access private
397 287 *
398 - * @param WP_Post|null $chart The chart object.
288 + * @param WP_Post $chart The chart object.
399 289 *
400 290 * @return array The array of chart data.
401 291 */
402 - private function _getChartArray( $chart = null ) {
292 + private function _getChartArray( WP_Post $chart = null ) {
403 293 if ( is_null( $chart ) ) {
404 294 $chart = $this->_chart;
405 295 }
406 296 $type = get_post_meta( $chart->ID, Visualizer_Plugin::CF_CHART_TYPE, true );
407 297 $series = apply_filters( Visualizer_Plugin::FILTER_GET_CHART_SERIES, get_post_meta( $chart->ID, Visualizer_Plugin::CF_SERIES, true ), $chart->ID, $type );
408 - $data = self::get_chart_data( $chart, $type );
298 + $data = apply_filters( Visualizer_Plugin::FILTER_GET_CHART_DATA, unserialize( $chart->post_content ), $chart->ID, $type );
409 299 $library = $this->load_chart_type( $chart->ID );
410 300
411 301 $settings = get_post_meta( $chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
412 302 $settings = apply_filters( Visualizer_Plugin::FILTER_GET_CHART_SETTINGS, $settings, $chart->ID, $type );
@@ -422,13 +312,8 @@
422 312 }
423 313
424 314 $date_formats = Visualizer_Source::get_date_formats_if_exists( $series, $data );
425 315
426 - $code = '';
427 - if ( 'd3' === $library ) {
428 - $code = get_post_meta( $chart->ID, Visualizer_Module_AIBuilder::CF_D3_CODE, true );
429 - }
430 -
431 316 return array(
432 317 'type' => $type,
433 318 'series' => $series,
434 319 'settings' => $settings,
@@ -433,9 +318,8 @@
433 318 'series' => $series,
434 319 'settings' => $settings,
435 320 'data' => $data,
436 321 'library' => $library,
437 - 'code' => $code,
438 322 'css' => $css,
439 323 'date_formats' => $date_formats,
440 324 );
441 325 }
@@ -452,9 +336,9 @@
452 336 public static function _sendResponse( $results ) {
453 337 header( 'Content-type: application/json' );
454 338 nocache_headers();
455 339 echo json_encode( $results );
456 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
340 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
457 341 }
458 342
459 343 /**
460 344 * Deletes a chart from database.
@@ -465,14 +349,16 @@
465 349 * @access public
466 350 */
467 351 public function deleteChart() {
468 352 $is_post = $_SERVER['REQUEST_METHOD'] === 'POST';
469 - $input = $is_post ? $_POST : $_GET;
353 + $input_method = $is_post ? INPUT_POST : INPUT_GET;
470 354 $chart_id = $success = false;
471 - $nonce = isset( $input['nonce'] ) && wp_verify_nonce( $input['nonce'] );
472 - if ( $nonce ) {
473 - $chart_id = isset( $input['chart'] ) ? filter_var(
474 - $input['chart'],
355 + $nonce = wp_verify_nonce( filter_input( $input_method, 'nonce' ) );
356 + $capable = current_user_can( 'delete_posts' );
357 + if ( $nonce && $capable ) {
358 + $chart_id = filter_input(
359 + $input_method,
360 + 'chart',
475 361 FILTER_VALIDATE_INT,
476 362 array(
477 363 'options' => array(
478 364 'min_range' => 1,
@@ -477,34 +363,16 @@
477 363 'options' => array(
478 364 'min_range' => 1,
479 365 ),
480 366 )
481 - ) : false;
367 + );
482 368 if ( $chart_id ) {
483 369 $chart = get_post( $chart_id );
484 - $success = $chart
485 - && $chart->post_type === Visualizer_Plugin::CPT_VISUALIZER
486 - && (
487 - current_user_can( 'delete_post', $chart_id )
488 - || ( (int) $chart->post_author === get_current_user_id() && current_user_can( 'delete_posts' ) )
489 - );
370 + $success = $chart && $chart->post_type === Visualizer_Plugin::CPT_VISUALIZER;
490 371 }
491 372 }
492 373 if ( $success ) {
493 - global $sitepress;
494 - if ( Visualizer_Module::is_pro() && ( function_exists( 'icl_get_languages' ) && $sitepress instanceof \SitePress ) ) {
495 - $trid = $sitepress->get_element_trid( $chart_id, 'post_' . Visualizer_Plugin::CPT_VISUALIZER );
496 - $translations = $sitepress->get_element_translations( $trid );
497 - if ( ! empty( $translations ) ) {
498 - foreach ( $translations as $translated_post ) {
499 - wp_delete_post( $translated_post->element_id, true );
500 - }
501 - } else {
502 - wp_delete_post( $chart_id, true );
503 - }
504 - } else {
505 - wp_delete_post( $chart_id, true );
506 - }
374 + wp_delete_post( $chart_id, true );
507 375 }
508 376 if ( $is_post ) {
509 377 self::_sendResponse(
510 378 array(
@@ -511,9 +379,9 @@
511 379 'success' => $success,
512 380 )
513 381 );
514 382 }
515 - wp_redirect( remove_query_arg( 'vaction', wp_get_referer() ) );
383 + wp_redirect( wp_get_referer() );
516 384 exit;
517 385 }
518 386
519 387 /**
@@ -552,126 +420,51 @@
552 420 *
553 421 * @access public
554 422 */
555 423 public function renderChartPages() {
556 - if ( ! current_user_can( 'edit_posts' ) ) {
557 - wp_die( __( 'You do not have permission to access this page.', 'visualizer' ) );
558 - }
559 -
560 424 defined( 'IFRAME_REQUEST' ) || define( 'IFRAME_REQUEST', 1 );
561 - if ( ! defined( 'ET_BUILDER_PRODUCT_VERSION' ) && function_exists( 'et_get_theme_version' ) ) {
562 - define( 'ET_BUILDER_PRODUCT_VERSION', et_get_theme_version() );
563 - }
564 - // Set current screen for the render chart.
565 - set_current_screen( 'visualizer_render_chart' );
566 425 // check chart, if chart not exists, will create new one and redirects to the same page with proper chart id
567 426 $chart_id = isset( $_GET['chart'] ) ? filter_var( $_GET['chart'], FILTER_VALIDATE_INT ) : '';
568 - if ( ! empty( $_POST ) ) {
569 - $_POST = map_deep( $_POST, 'wp_strip_all_tags' );
570 - }
571 - $chart = $chart_id ? get_post( $chart_id ) : null;
572 - if ( $chart && ! self::can_edit_chart( $chart_id ) ) {
573 - wp_die( esc_html__( 'You do not have permission to access this page.', 'visualizer' ), '', array( 'response' => 403 ) );
574 - }
575 - if ( ! $chart_id || ! $chart || $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ) {
576 - if ( empty( $_GET['lang'] ) || empty( $_GET['parent_chart_id'] ) ) {
577 - $this->deleteOldCharts();
578 - $default_type = isset( $_GET['type'] ) && ! empty( $_GET['type'] ) ? $_GET['type'] : 'line';
579 - $chart_status = Visualizer_Module_Admin::checkChartStatus( $default_type );
580 - if ( ! $chart_status ) {
581 - $default_type = 'line';
582 - }
583 - $source = new Visualizer_Source_Csv( VISUALIZER_ABSPATH . DIRECTORY_SEPARATOR . 'samples' . DIRECTORY_SEPARATOR . $default_type . '.csv' );
584 - $source->fetch();
585 - $chart_id = wp_insert_post(
427 + if ( ! $chart_id || ! ( $chart = get_post( $chart_id ) ) || $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ) {
428 + $this->deleteOldCharts();
429 + $default_type = isset( $_GET['type'] ) && ! empty( $_GET['type'] ) ? $_GET['type'] : 'line';
430 + $source = new Visualizer_Source_Csv( VISUALIZER_ABSPATH . DIRECTORY_SEPARATOR . 'samples' . DIRECTORY_SEPARATOR . $default_type . '.csv' );
431 + $source->fetch();
432 + $chart_id = wp_insert_post(
433 + array(
434 + 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
435 + 'post_title' => 'Visualization',
436 + 'post_author' => get_current_user_id(),
437 + 'post_status' => 'auto-draft',
438 + 'post_content' => $source->getData(),
439 + )
440 + );
441 + if ( $chart_id && ! is_wp_error( $chart_id ) ) {
442 + add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_TYPE, $default_type );
443 + add_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, 1 );
444 + add_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
445 + add_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
446 + add_post_meta(
447 + $chart_id,
448 + Visualizer_Plugin::CF_SETTINGS,
586 449 array(
587 - 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
588 - 'post_title' => 'Visualization',
589 - 'post_author' => get_current_user_id(),
590 - 'post_status' => 'auto-draft',
591 - 'post_content' => $source->getData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ),
450 + 'focusTarget' => 'datum',
592 451 )
593 452 );
594 - if ( $chart_id && ! is_wp_error( $chart_id ) ) {
595 - add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_TYPE, $default_type );
596 - add_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, 1 );
597 - add_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
598 - add_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
599 - add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_LIBRARY, '' );
600 - add_post_meta(
601 - $chart_id,
602 - Visualizer_Plugin::CF_SETTINGS,
603 - array(
604 - 'focusTarget' => 'datum',
605 - )
606 - );
607 -
608 - do_action( 'visualizer_pro_new_chart_defaults', $chart_id );
609 - }
610 - } else {
611 - $parent_chart_id = filter_var( $_GET['parent_chart_id'], FILTER_VALIDATE_INT );
612 - $success = false;
613 - if ( $parent_chart_id && self::can_edit_chart( $parent_chart_id ) ) {
614 - $parent_chart = get_post( $parent_chart_id );
615 - $success = $parent_chart && $parent_chart->post_type === Visualizer_Plugin::CPT_VISUALIZER;
616 - }
617 - if ( $success ) {
618 - $new_chart_id = wp_insert_post(
619 - array(
620 - 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
621 - 'post_title' => 'Visualization',
622 - 'post_author' => get_current_user_id(),
623 - 'post_status' => $parent_chart->post_status,
624 - 'post_content' => $parent_chart->post_content,
625 - )
626 - );
627 -
628 - if ( is_wp_error( $new_chart_id ) ) {
629 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Error while cloning chart %d = %s', $parent_chart_id, print_r( $new_chart_id, true ) ), 'error', __FILE__, __LINE__ );
630 - } else {
631 - $post_meta = get_post_meta( $parent_chart_id );
632 - $chart_id = $new_chart_id;
633 - foreach ( $post_meta as $key => $value ) {
634 - if ( strpos( $key, 'visualizer-' ) !== false ) {
635 - add_post_meta( $new_chart_id, $key, self::maybe_decode_content( $value[0] ) );
636 - }
637 - }
638 - }
639 - }
640 453 do_action( 'visualizer_pro_new_chart_defaults', $chart_id );
641 454 }
642 - wp_redirect( esc_url_raw( add_query_arg( 'chart', (int) $chart_id ) ) );
643 -
644 - if ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) {
645 - wp_die();
646 - }
647 - exit();
455 + wp_redirect( add_query_arg( 'chart', (int) $chart_id ) );
456 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
648 457 }
649 458
650 - $_POST['save_chart_image'] = isset( $_POST['save_chart_image'] ) && 'yes' === $_POST['save_chart_image'] ? true : false;
651 - $_POST['lazy_load_chart'] = isset( $_POST['lazy_load_chart'] ) && 'yes' === $_POST['lazy_load_chart'] ? true : false;
459 + $this->load_chart_type( $chart_id );
652 460
653 - if ( isset( $_POST['chart-img'] ) && ! empty( $_POST['chart-img'] ) ) {
654 - $attachment_id = $this->save_chart_image( $_POST['chart-img'], $chart_id, $_POST['save_chart_image'] );
655 - if ( $attachment_id ) {
656 - update_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_IMAGE, $attachment_id );
657 - }
658 - }
659 - $lib = $this->load_chart_type( $chart_id );
660 -
661 - // the alpha color picker (RGBA) is not supported by google.
662 - $color_picker_dep = 'wp-color-picker';
663 - if ( in_array( $lib, array( 'chartjs', 'datatables' ), true ) && ! wp_script_is( 'wp-color-picker-alpha', 'registered' ) ) {
664 - wp_register_script( 'wp-color-picker-alpha', VISUALIZER_ABSURL . 'js/lib/wp-color-picker-alpha.min.js', array( 'wp-color-picker' ), Visualizer_Plugin::VERSION );
665 - $color_picker_dep = 'wp-color-picker-alpha';
666 - }
667 -
668 461 // enqueue and register scripts and styles
669 462 wp_register_script( 'visualizer-chosen', VISUALIZER_ABSURL . 'js/lib/chosen.jquery.min.js', array( 'jquery' ), Visualizer_Plugin::VERSION );
670 463 wp_register_style( 'visualizer-chosen', VISUALIZER_ABSURL . 'css/lib/chosen.min.css', array(), Visualizer_Plugin::VERSION );
671 464
672 465 wp_register_style( 'visualizer-frame', VISUALIZER_ABSURL . 'css/frame.css', array( 'visualizer-chosen' ), Visualizer_Plugin::VERSION );
673 - wp_register_script( 'visualizer-frame', VISUALIZER_ABSURL . 'js/frame.js', array( 'visualizer-chosen', 'jquery-ui-accordion', 'jquery-ui-tabs' ), Visualizer_Plugin::VERSION, true );
466 + wp_register_script( 'visualizer-frame', VISUALIZER_ABSURL . 'js/frame.js', array( 'visualizer-chosen', 'jquery-ui-accordion' ), Visualizer_Plugin::VERSION, true );
674 467 wp_register_script( 'visualizer-customization', $this->get_user_customization_js(), array(), null, true );
675 468 wp_register_script(
676 469 'visualizer-render',
677 470 VISUALIZER_ABSURL . 'js/render-facade.js',
@@ -682,9 +475,9 @@
682 475 wp_register_script(
683 476 'visualizer-preview',
684 477 VISUALIZER_ABSURL . 'js/preview.js',
685 478 array(
686 - $color_picker_dep,
479 + 'wp-color-picker',
687 480 'visualizer-render',
688 481 ),
689 482 Visualizer_Plugin::VERSION,
690 483 true
@@ -690,11 +483,10 @@
690 483 true
691 484 );
692 485 wp_register_script( 'visualizer-editor-simple', VISUALIZER_ABSURL . 'js/simple-editor.js', array( 'jquery' ), Visualizer_Plugin::VERSION, true );
693 486
694 - do_action( 'visualizer_add_scripts' );
695 -
696 - if ( Visualizer_Module::is_pro() && Visualizer_Module::is_pro_older_than( '1.9.0' ) ) {
487 + // added by Ash/Upwork
488 + if ( VISUALIZER_PRO ) {
697 489 global $Visualizer_Pro;
698 490 $Visualizer_Pro->_addScriptsAndStyles();
699 491 }
700 492
@@ -710,9 +502,8 @@
710 502 if ( isset( $_POST['cancel'] ) && 1 === intval( $_POST['cancel'] ) ) {
711 503 // if the cancel button is clicked.
712 504 $this->undoRevisions( $chart_id, true );
713 505 } elseif ( isset( $_POST['save'] ) && 1 === intval( $_POST['save'] ) ) {
714 - $this->handlePermissions();
715 506 // if the save button is clicked.
716 507 $this->undoRevisions( $chart_id, false );
717 508 } else {
718 509 // if the edit button is clicked.
@@ -718,16 +509,8 @@
718 509 // if the edit button is clicked.
719 510 $this->_chart = $this->handleExistingRevisions( $chart_id, $this->_chart );
720 511 }
721 512
722 - // Clear existing chart cache.
723 - if ( isset( $_POST['save'] ) && 1 === intval( $_POST['save'] ) ) {
724 - $cache_key = Visualizer_Plugin::CF_CHART_CACHE . '_' . $chart_id;
725 - if ( get_transient( $cache_key ) ) {
726 - delete_transient( $cache_key );
727 - }
728 - }
729 -
730 513 switch ( $tab ) {
731 514 case 'settings':
732 515 $this->_handleDataAndSettingsPage();
733 516 break;
@@ -735,34 +518,34 @@
735 518 case 'visualizer': // fall through.
736 519 $this->_handleTypesPage();
737 520 break;
738 521 default:
739 - // this should never happen.
522 + do_action( 'visualizer_pro_handle_tab', $tab, $this->_chart );
740 523 break;
741 524 }
742 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
525 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
743 526 }
744 527
745 528 /**
746 529 * Load code editor assets.
747 530 */
748 - private function loadCodeEditorAssets( $chart_id ) {
531 + private function loadCodeEditorAssets() {
749 532 global $wp_version;
750 533
751 534 $wp_scripts = wp_scripts();
752 535
753 536 // data tables assets.
754 - wp_register_script( 'visualizer-datatables', VISUALIZER_ABSURL . 'js/lib/datatables.min.js', array( 'jquery-ui-core' ), Visualizer_Plugin::VERSION );
755 - wp_register_style( 'visualizer-datatables', VISUALIZER_ABSURL . 'css/lib/datatables.min.css', array(), Visualizer_Plugin::VERSION );
756 - wp_register_style( 'visualizer-jquery-ui', sprintf( '//code.jquery.com/ui/%s/themes/smoothness/jquery-ui.css', $wp_scripts->registered['jquery-ui-core']->ver ), array( 'visualizer-datatables' ), Visualizer_Plugin::VERSION );
537 + wp_register_script( 'visualizer-datatables', '//cdn.datatables.net/v/dt/dt-1.10.18/b-1.5.6/b-colvis-1.5.6/cr-1.5.0/fc-3.2.5/fh-3.1.4/r-2.2.2/sc-2.0.0/sl-1.3.0/datatables.min.js', array( 'jquery-ui-core' ), Visualizer_Plugin::VERSION );
538 + wp_register_style( 'visualizer-datatables', '//cdn.datatables.net/v/dt/dt-1.10.18/b-1.5.6/b-colvis-1.5.6/cr-1.5.0/fc-3.2.5/fh-3.1.4/r-2.2.2/sc-2.0.0/sl-1.3.0/datatables.min.css', array(), Visualizer_Plugin::VERSION );
539 + wp_register_style( 'visualizer-jquery-ui', sprintf( '//ajax.googleapis.com/ajax/libs/jqueryui/%s/themes/smoothness/jquery-ui.css', $wp_scripts->registered['jquery-ui-core']->ver ), array( 'visualizer-datatables' ), Visualizer_Plugin::VERSION );
757 540 wp_enqueue_script( 'visualizer-datatables' );
758 541 wp_enqueue_style( 'visualizer-jquery-ui' );
759 542
760 - if ( ! Visualizer_Module::is_pro() ) {
543 + if ( ! VISUALIZER_PRO ) {
761 544 return;
762 545 }
763 546
764 - $table_col_mapping = Visualizer_Source_Query_Params::get_all_db_tables_column_mapping( $chart_id );
547 + $table_col_mapping = Visualizer_Source_Query_Params::get_all_db_tables_column_mapping();
765 548
766 549 if ( version_compare( $wp_version, '4.9.0', '<' ) ) {
767 550 // code mirror assets.
768 551 wp_register_script( 'visualizer-codemirror-core', '//codemirror.net/lib/codemirror.js', array( 'jquery' ), Visualizer_Plugin::VERSION );
@@ -770,9 +553,9 @@
770 553 wp_register_script( 'visualizer-codemirror-matchbrackets', '//codemirror.net/addon/edit/matchbrackets.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
771 554 wp_register_script( 'visualizer-codemirror-closebrackets', '//codemirror.net/addon/edit/closebrackets.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
772 555 wp_register_script( 'visualizer-codemirror-sql', '//codemirror.net/mode/sql/sql.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
773 556 wp_register_script( 'visualizer-codemirror-sql-hint', '//codemirror.net/addon/hint/sql-hint.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
774 - wp_register_script( 'visualizer-codemirror-hint', '//codemirror.net/addon/hint/show-hint.js', array( 'visualizer-codemirror-sql', 'visualizer-codemirror-sql-hint', 'visualizer-codemirror-placeholder', 'visualizer-codemirror-matchbrackets', 'visualizer-codemirror-closebrackets' ), Visualizer_Plugin::VERSION );
557 + wp_register_script( 'visualizer-codemirror-hint', '//codemirror.net/addon/hint/show-hint.js', array( 'visualizer-codemirror-sql', 'visualizer-codemirror-sql-hint', 'visualizer-codemirror-placeholder', 'visualizer-codemirror-matchbrackets', 'visualizer-codemirror-closebrackets' ), Visualizer_Plugin::VERSION );
775 558 wp_register_style( 'visualizer-codemirror-core', '//codemirror.net/lib/codemirror.css', array(), Visualizer_Plugin::VERSION );
776 559 wp_register_style( 'visualizer-codemirror-hint', '//codemirror.net/addon/hint/show-hint.css', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
777 560
778 561 wp_enqueue_script( 'visualizer-codemirror-hint' );
@@ -786,9 +569,9 @@
786 569 'lineWrapping' => true,
787 570 'dragDrop' => false,
788 571 'matchBrackets' => true,
789 572 'autoCloseBrackets' => true,
790 - 'extraKeys' => array( 'Shift-Space' => 'autocomplete' ),
573 + 'extraKeys' => array( 'Ctrl-Space' => 'autocomplete' ),
791 574 'hintOptions' => array( 'tables' => $table_col_mapping ),
792 575 ),
793 576 )
794 577 );
@@ -797,85 +580,36 @@
797 580 return $table_col_mapping;
798 581 }
799 582
800 583 /**
801 - * Handle permissions from the new conslidated settings sidebar.
802 - */
803 - private function handlePermissions() {
804 - if ( ! Visualizer_Module::is_pro() ) {
805 - return;
806 - }
807 -
808 - // we will not support old free and new pro.
809 - // handling new free and old pro.
810 - if ( has_action( 'visualizer_pro_handle_tab' ) ) {
811 - do_action( 'visualizer_pro_handle_tab', 'permissions', $this->_chart );
812 - } else {
813 - do_action( 'visualizer_handle_permissions', $this->_chart );
814 - }
815 - }
816 -
817 - /**
818 584 * Handle data and settings page
819 585 */
820 586 private function _handleDataAndSettingsPage() {
587 + if ( isset( $_POST['map_api_key'] ) ) {
588 + update_option( 'visualizer-map-api-key', $_POST['map_api_key'] );
589 + }
821 590 if ( $_SERVER['REQUEST_METHOD'] === 'POST' && isset( $_GET['nonce'] ) && wp_verify_nonce( $_GET['nonce'] ) ) {
822 - $is_canceled = isset( $_POST['cancel'] ) && 1 === intval( $_POST['cancel'] );
823 - $is_newly_created = $this->_chart->post_status === 'auto-draft';
824 -
825 - if ( isset( $_POST['map_api_key'] ) && current_user_can( 'manage_options' ) ) {
826 - update_option( 'visualizer-map-api-key', sanitize_text_field( wp_unslash( $_POST['map_api_key'] ) ) );
827 - }
828 -
829 - if ( $is_newly_created && ! $is_canceled ) {
591 + if ( $this->_chart->post_status === 'auto-draft' ) {
830 592 $this->_chart->post_status = 'publish';
831 593
832 594 // ensure that a revision is not created. If a revision is created it will have the proper data and the parent of the revision will have default data.
833 595 // we do not want any difference in data so disable revisions temporarily.
834 - $this->disableRevisionsTemporarily();
835 -
596 + add_filter( 'wp_revisions_to_keep', '__return_false' );
836 597 wp_update_post( $this->_chart->to_array() );
837 598 }
838 599 // save meta data only when it is NOT being canceled.
839 - if ( ! $is_canceled ) {
840 - $post_settings = $_POST;
841 - $existing = get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
842 - if ( isset( $existing['colors'] ) && is_array( $existing['colors'] ) && ! isset( $post_settings['colors'] ) ) {
843 - $post_settings['colors'] = $existing['colors'];
844 - }
845 - $post_settings = $this->sanitizeSettings( $post_settings );
846 - update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, $post_settings );
847 -
848 - // we will keep a parameter called 'internal_title' that will be set to the given title or, if empty, the chart ID
849 - // this will help in searching with the chart id.
850 - $settings = get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
851 - $title = null;
852 - if ( isset( $settings['title'] ) && ! empty( $settings['title'] ) ) {
853 - $title = $settings['title'];
854 - if ( is_array( $title ) ) {
855 - $title = $settings['title']['text'];
856 - }
857 - }
858 - if ( empty( $title ) ) {
859 - $title = $this->_chart->ID;
860 - }
861 - $settings['internal_title'] = $title;
862 - $settings_label = isset( $settings['pieResidueSliceLabel'] ) ? $settings['pieResidueSliceLabel'] : '';
863 - if ( empty( $settings_label ) ) {
864 - $settings['pieResidueSliceLabel'] = esc_html__( 'Other', 'visualizer' );
865 - } else {
866 - $settings['pieResidueSliceLabel'] = $settings_label;
867 - }
868 - update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, $settings );
600 + if ( ! ( isset( $_POST['cancel'] ) && 1 === intval( $_POST['cancel'] ) ) ) {
601 + update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, $_POST );
869 602 }
870 603 $render = new Visualizer_Render_Page_Send();
871 604 $render->text = sprintf( '[visualizer id="%d"]', $this->_chart->ID );
872 605 wp_iframe( array( $render, 'render' ) );
606 +
873 607 return;
874 608 }
875 609 $data = $this->_getChartArray();
876 610 $sidebar = '';
877 - $sidebar_class = $this->load_chart_class_name( $this->_chart->ID );
611 + $sidebar_class = 'Visualizer_Render_Sidebar_Type_' . ucfirst( $data['type'] );
878 612 if ( class_exists( $sidebar_class, true ) ) {
879 613 $sidebar = new $sidebar_class( $data['settings'] );
880 614 $sidebar->__series = $data['series'];
881 615 $sidebar->__data = $data['data'];
@@ -885,17 +619,16 @@
885 619 $sidebar->__series = $data['series'];
886 620 $sidebar->__data = $data['data'];
887 621 }
888 622 }
889 - unset( $data['settings']['width'], $data['settings']['height'], $data['settings']['chartArea'] );
623 + unset( $data['settings']['width'], $data['settings']['height'] );
890 624 wp_enqueue_style( 'wp-color-picker' );
891 625 wp_enqueue_style( 'visualizer-frame' );
892 626 wp_enqueue_script( 'visualizer-preview' );
893 627 wp_enqueue_script( 'visualizer-chosen' );
894 628 wp_enqueue_script( 'visualizer-render' );
895 - wp_enqueue_code_editor( array( 'type' => 'application/json' ) );
896 629
897 - if ( Visualizer_Module::can_show_feature( 'simple-editor' ) ) {
630 + if ( ! VISUALIZER_PRO ) {
898 631 wp_enqueue_script( 'visualizer-editor-simple' );
899 632 wp_localize_script(
900 633 'visualizer-editor-simple',
901 634 'visualizer1',
@@ -901,16 +634,18 @@
901 634 'visualizer1',
902 635 array(
903 636 'ajax' => array(
904 637 'url' => admin_url( 'admin-ajax.php' ),
905 - 'nonces' => array(),
906 - 'actions' => array(),
638 + 'nonces' => array(
639 + ),
640 + 'actions' => array(
641 + ),
907 642 ),
908 643 )
909 644 );
910 645 }
911 646
912 - $table_col_mapping = $this->loadCodeEditorAssets( $this->_chart->ID );
647 + $table_col_mapping = $this->loadCodeEditorAssets();
913 648
914 649 wp_localize_script(
915 650 'visualizer-render',
916 651 'visualizer',
@@ -915,15 +650,11 @@
915 650 'visualizer-render',
916 651 'visualizer',
917 652 array(
918 653 'l10n' => array(
919 - 'invalid_source' => esc_html__( 'The URL you entered is invalid. Please enter a valid URL.', 'visualizer' ),
920 - 'loading' => esc_html__( 'Loading...', 'visualizer' ),
921 - 'json_error' => esc_html__( 'An error occured in fetching data.', 'visualizer' ),
922 - 'select_columns' => esc_html__( 'Please select a few columns to include in the chart.', 'visualizer' ),
923 - 'save_settings' => __( 'You have modified the chart\'s settings. To modify the source/data again, you must save this chart and reopen it for editing. If you continue without saving the chart, you may lose your changes.', 'visualizer' ),
924 - 'copied' => __( 'The data has been copied to your clipboard. Hit Ctrl-V/Cmd-V in your spreadsheet editor to paste the data.', 'visualizer' ),
925 - 'invalid_format' => esc_html__( 'This format pattern is not supported in the series settings field. Use the Manual Configuration option instead.', 'visualizer' ),
654 + 'invalid_source' => esc_html__( 'You have entered invalid URL. Please, insert proper URL.', 'visualizer' ),
655 + 'loading' => esc_html__( 'Loading...', 'visualizer' ),
656 + 'json_error' => esc_html__( 'An error occured in fetching data.', 'visualizer' ),
926 657 ),
927 658 'charts' => array(
928 659 'canvas' => $data,
929 660 'id' => $this->_chart->ID,
@@ -949,14 +680,13 @@
949 680 ),
950 681 'db_query' => array(
951 682 'tables' => $table_col_mapping,
952 683 ),
953 - 'is_pro' => Visualizer_Module::is_pro(),
684 + 'is_pro' => VISUALIZER_PRO,
954 685 'page_type' => 'chart',
955 686 'json_tag_separator' => Visualizer_Source_Json::TAG_SEPARATOR,
956 687 'json_tag_separator_view' => Visualizer_Source_Json::TAG_SEPARATOR_VIEW,
957 688 'is_front' => false,
958 - 'rest_base' => get_rest_url( null, 'wc/v3/reports/' ),
959 689 )
960 690 );
961 691
962 692 $render = new Visualizer_Render_Page_Data();
@@ -967,21 +697,18 @@
967 697 if ( filter_input( INPUT_GET, 'library', FILTER_VALIDATE_BOOLEAN ) ) {
968 698 $render->button = filter_input( INPUT_GET, 'action' ) === Visualizer_Plugin::ACTION_EDIT_CHART
969 699 ? esc_html__( 'Save Chart', 'visualizer' )
970 700 : esc_html__( 'Create Chart', 'visualizer' );
971 -
972 - $render->cancel_button = esc_html__( 'Cancel', 'visualizer' );
701 + if ( filter_input( INPUT_GET, 'action' ) === Visualizer_Plugin::ACTION_EDIT_CHART ) {
702 + $render->cancel_button = esc_html__( 'Cancel', 'visualizer' );
703 + }
973 704 } else {
974 705 $render->button = esc_attr__( 'Insert Chart', 'visualizer' );
975 706 }
976 -
977 - do_action( 'visualizer_enqueue_scripts_and_styles', $data, $this->_chart->ID );
978 -
979 - if ( Visualizer_Module::is_pro() && Visualizer_Module::is_pro_older_than( '1.9.0' ) ) {
707 + if ( VISUALIZER_PRO ) {
980 708 global $Visualizer_Pro;
981 - $Visualizer_Pro->_enqueueScriptsAndStyles( $data, $this->_chart->ID );
709 + $Visualizer_Pro->_enqueueScriptsAndStyles( $data );
982 710 }
983 -
984 711 $this->_addAction( 'admin_head', 'renderFlattrScript' );
985 712 wp_iframe( array( $render, 'render' ) );
986 713 }
987 714
@@ -993,35 +720,24 @@
993 720 * @access private
994 721 */
995 722 private function _handleTypesPage() {
996 723 // process post request
997 - if ( $_SERVER['REQUEST_METHOD'] === 'POST' && wp_verify_nonce( filter_input( INPUT_POST, 'nonce' ), 'visualizer-upload-data' ) ) {
724 + if ( $_SERVER['REQUEST_METHOD'] === 'POST' && wp_verify_nonce( filter_input( INPUT_POST, 'nonce' ) ) ) {
998 725 $type = filter_input( INPUT_POST, 'type' );
999 - $library = filter_input( INPUT_POST, 'chart-library' );
1000 - if ( Visualizer_Module_Admin::checkChartStatus( $type ) ) {
1001 - if ( empty( $library ) ) {
1002 - // library cannot be empty.
1003 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, 'Chart library empty while creating the chart! Aborting...', 'error', __FILE__, __LINE__ );
1004 - return;
1005 - }
1006 -
726 + if ( in_array( $type, Visualizer_Plugin::getChartTypes(), true ) ) {
1007 727 // save new chart type
1008 728 update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_CHART_TYPE, $type );
1009 - update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_CHART_LIBRARY, $library );
1010 729 // if the chart has default data, update it with appropriate default data for new type
1011 730 if ( filter_var( get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_DEFAULT_DATA, true ), FILTER_VALIDATE_BOOLEAN ) ) {
1012 731 $source = new Visualizer_Source_Csv( VISUALIZER_ABSPATH . DIRECTORY_SEPARATOR . 'samples' . DIRECTORY_SEPARATOR . $type . '.csv' );
1013 732 $source->fetch();
1014 - $this->_chart->post_content = $source->getData( get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) );
733 + $this->_chart->post_content = $source->getData();
1015 734 wp_update_post( $this->_chart->to_array() );
1016 735 update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
1017 736 }
1018 -
1019 - Visualizer_Module_Utility::set_defaults( $this->_chart );
1020 -
1021 737 // redirect to next tab
1022 738 // changed by Ash/Upwork
1023 - wp_redirect( esc_url_raw( add_query_arg( 'tab', 'settings' ) ) );
739 + wp_redirect( add_query_arg( 'tab', 'settings' ) );
1024 740
1025 741 return;
1026 742 }
1027 743 }
@@ -1026,9 +742,9 @@
1026 742 }
1027 743 }
1028 744 $render = new Visualizer_Render_Page_Types();
1029 745 $render->type = get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_CHART_TYPE, true );
1030 - $render->types = Visualizer_Module_Admin::_getChartTypesLocalized( false, false, false, 'types' );
746 + $render->types = Visualizer_Module_Admin::_getChartTypesLocalized();
1031 747 $render->chart = $this->_chart;
1032 748 wp_enqueue_style( 'visualizer-frame' );
1033 749 wp_enqueue_script( 'visualizer-frame' );
1034 750 wp_iframe( array( $render, 'render' ) );
@@ -1034,35 +750,8 @@
1034 750 wp_iframe( array( $render, 'render' ) );
1035 751 }
1036 752
1037 753 /**
1038 - * Sanitize settings data from the request.
1039 - *
1040 - * @param array<string, mixed> $post_data The POST data to sanitize.
1041 - * @return array<string, mixed> The sanitized settings data.
1042 - */
1043 - private function sanitizeSettings( $post_data ): array {
1044 - $chart_img = '';
1045 - if ( isset( $post_data['chart-img'] ) ) {
1046 - $chart_img = wp_unslash( $post_data['chart-img'] );
1047 - unset( $post_data['chart-img'] );
1048 - }
1049 -
1050 - $post_data = map_deep(
1051 - $post_data,
1052 - 'sanitize_textarea_field'
1053 - );
1054 -
1055 - // The value is a client-side canvas export; keep it only when it is a
1056 - // base64 image data URI so nothing else is ever stored unsanitized.
1057 - if ( is_string( $chart_img ) && preg_match( '#^data:image/(png|jpeg|webp);base64,[A-Za-z0-9+/ ]+=*$#', $chart_img ) ) {
1058 - $post_data['chart-img'] = $chart_img;
1059 - }
1060 -
1061 - return $post_data;
1062 - }
1063 -
1064 - /**
1065 754 * Renders flattr script in the iframe <head>
1066 755 *
1067 756 * @since 1.4.2
1068 757 * @action admin_head
@@ -1077,124 +766,28 @@
1077 766 * Processes the CSV that is sent in the request as a string.
1078 767 *
1079 768 * @since 3.2.0
1080 769 */
1081 - /**
1082 - * Determines whether a remote URL serves an XLSX file.
1083 - *
1084 - * Used as a fallback when the URL path has no recognisable file extension
1085 - * (e.g. SharePoint, signed S3 URLs, or "download?id=…" endpoints).
1086 - *
1087 - * Uses the shared remote-fetch policy to block non-public destinations,
1088 - * and streams the response to a temp file so no body data is held in memory
1089 - * regardless of whether the server honours the Range header.
1090 - *
1091 - * The check relies on the ZIP magic number (PK\x03\x04) that every XLSX
1092 - * file begins with, making it immune to misleading Content-Type headers
1093 - * such as application/octet-stream. Content-Type is used as a last-resort
1094 - * fallback only when the temp file is empty (e.g. a HEAD-only server).
1095 - *
1096 - * @access private
1097 - * @param string $url The remote URL to probe.
1098 - * @return bool TRUE if the file appears to be XLSX, FALSE otherwise.
1099 - */
1100 - private static function _url_is_xlsx( $url ) {
1101 - $tmpfile = wp_tempnam( 'visualizer_xlsx_probe' );
1102 - if ( ! $tmpfile ) {
1103 - return false;
1104 - }
1105 -
1106 - $response = Visualizer_Remote_Fetch::request(
1107 - $url,
1108 - array(
1109 - 'timeout' => 10,
1110 - 'user-agent' => 'WordPress/' . get_bloginfo( 'version' ),
1111 - 'headers' => array( 'Range' => 'bytes=0-3' ),
1112 - 'stream' => true,
1113 - 'filename' => $tmpfile,
1114 - 'limit_response_size' => 4,
1115 - )
1116 - );
1117 -
1118 - if ( is_wp_error( $response ) ) {
1119 - @unlink( $tmpfile ); // phpcs:ignore WordPress.PHP.NoSilencedErrors
1120 - return false;
1121 - }
1122 -
1123 - $magic = '';
1124 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fopen
1125 - $fh = @fopen( $tmpfile, 'rb' ); // phpcs:ignore WordPress.PHP.NoSilencedErrors
1126 - if ( $fh ) {
1127 - $magic = fread( $fh, 4 ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fread
1128 - fclose( $fh ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fclose
1129 - }
1130 - @unlink( $tmpfile ); // phpcs:ignore WordPress.PHP.NoSilencedErrors
1131 -
1132 - if ( strlen( $magic ) >= 4 ) {
1133 - // XLSX (and all ZIP-based Office formats) start with PK\x03\x04.
1134 - return $magic === "PK\x03\x04";
1135 - }
1136 -
1137 - // Last resort: server returned an empty body (e.g. ignored Range and
1138 - // returned only headers). Check Content-Type from the same response.
1139 - // application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
1140 - return false !== strpos(
1141 - wp_remote_retrieve_header( $response, 'content-type' ),
1142 - 'spreadsheetml'
1143 - );
1144 - }
1145 -
1146 - /**
1147 - * Parses a raw CSV string or editor payload and returns a source object.
1148 - *
1149 - * @access private
1150 - * @param string $data The raw CSV data string.
1151 - * @param string $editor_type The editor type ('text' or 'tabular').
1152 - * @return Visualizer_Source|null The populated source object, or null on failure.
1153 - */
1154 - private function handleCSVasString( $data, $editor_type ) {
770 + private function handleCSVasString( $data ) {
1155 771 $source = null;
1156 -
1157 - switch ( $editor_type ) {
1158 - case 'text':
1159 - // data coming in from the text editor.
1160 - $tmpfile = tempnam( get_temp_dir(), Visualizer_Plugin::NAME );
1161 - $handle = fopen( $tmpfile, 'w' );
1162 - $values = preg_split( '/[\n\r]+/', stripslashes( trim( $data ) ) );
1163 - if ( $values ) {
1164 - foreach ( $values as $row ) {
1165 - if ( empty( $row ) ) {
1166 - continue;
1167 - }
1168 - $row = explode( ',', $row );
1169 - $row = array_map(
1170 - function ( $r ) {
1171 - return '' === $r ? ' ' : $r;
1172 - },
1173 - $row
1174 - );
1175 - $row = implode( ',', $row );
1176 - // don't use fpucsv here because we need to just dump the data
1177 - // minus the empty rows
1178 - // because fputcsv needs to tokenize
1179 - // we can standardize the CSV enclosure here and replace all ' with "
1180 - // we can assume that if there are an even number of ' they should be changed to "
1181 - // but that will screw up words like fo'c'sle
1182 - // so here let's just assume ' will NOT be used for enclosures
1183 - fwrite( $handle, $row );
1184 - fwrite( $handle, PHP_EOL );
772 + if ( VISUALIZER_PRO ) {
773 + $source = apply_filters( 'visualizer_pro_handle_chart_data', $data, '' );
774 + } else {
775 + // data coming in from the text editor.
776 + $tmpfile = tempnam( get_temp_dir(), Visualizer_Plugin::NAME );
777 + $handle = fopen( $tmpfile, 'w' );
778 + $values = preg_split( '/[\n\r]+/', stripslashes( trim( $data ) ) );
779 + if ( $values ) {
780 + foreach ( $values as $row ) {
781 + if ( empty( $row ) ) {
782 + continue;
1185 783 }
784 + $columns = explode( ',', $row );
785 + fputcsv( $handle, $columns );
1186 786 }
1187 - $source = new Visualizer_Source_Csv( $tmpfile );
1188 - fclose( $handle );
1189 - break;
1190 - case 'table':
1191 - // Import from Chart
1192 - // fall-through.
1193 - case 'excel':
1194 - // data coming in from the excel editor.
1195 - $source = apply_filters( 'visualizer_pro_handle_chart_data', $data, '' );
1196 - break;
787 + }
788 + $source = new Visualizer_Source_Csv( $tmpfile );
789 + fclose( $handle );
1197 790 }
1198 791 return $source;
1199 792 }
1200 793
@@ -1217,9 +810,9 @@
1217 810 foreach ( $types as $type ) {
1218 811 if ( empty( $type ) ) {
1219 812 $exclude[] = $index;
1220 813 }
1221 - ++$index;
814 + $index++;
1222 815 }
1223 816
1224 817 // when N headers are being renamed, the number of headers increases by N
1225 818 // because of the way datatable duplicates header information
@@ -1243,9 +836,9 @@
1243 836 $csv[] = $types;
1244 837 for ( $j = 0; $j < count( $columns[0] ); $j++ ) {
1245 838 $row = array();
1246 839 for ( $i = 0; $i < count( $headers ); $i++ ) {
1247 - $row[] = sanitize_text_field( $columns[ $i ][ $j ] );
840 + $row[] = $columns[ $i ][ $j ];
1248 841 }
1249 842 $csv[] = $row;
1250 843 }
1251 844
@@ -1277,16 +870,11 @@
1277 870 public function uploadData() {
1278 871 // if this is being called internally from pro and VISUALIZER_DO_NOT_DIE is set.
1279 872 // otherwise, assume this is a normal web request.
1280 873 $can_die = ! ( defined( 'VISUALIZER_DO_NOT_DIE' ) && VISUALIZER_DO_NOT_DIE );
1281 - // $can_die also gates the capability checks below, so VISUALIZER_DO_NOT_DIE must stay internal-only (never set from request input or globally).
1282 874
1283 - // validate nonce; capability check applies to web requests only, not trusted internal calls.
1284 - if (
1285 - ! isset( $_GET['nonce'] ) ||
1286 - ! wp_verify_nonce( $_GET['nonce'], 'visualizer-upload-data' ) ||
1287 - ( $can_die && ! current_user_can( 'edit_posts' ) )
1288 - ) {
875 + // validate nonce
876 + if ( ! isset( $_GET['nonce'] ) || ! wp_verify_nonce( $_GET['nonce'] ) ) {
1289 877 if ( ! $can_die ) {
1290 878 return;
1291 879 }
1292 880 status_header( 403 );
@@ -1295,15 +883,9 @@
1295 883
1296 884 // check chart, if chart exists
1297 885 // do not use filter_input as it does not work for phpunit test cases, use filter_var instead
1298 886 $chart_id = isset( $_GET['chart'] ) ? filter_var( $_GET['chart'], FILTER_VALIDATE_INT ) : '';
1299 - $chart = $chart_id ? get_post( $chart_id ) : null;
1300 - if (
1301 - ! $chart_id ||
1302 - ! $chart ||
1303 - $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ||
1304 - ( $can_die && ! current_user_can( 'edit_post', $chart_id ) )
1305 - ) {
887 + if ( ! $chart_id || ! ( $chart = get_post( $chart_id ) ) || $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ) {
1306 888 if ( ! $can_die ) {
1307 889 return;
1308 890 }
1309 891 status_header( 400 );
@@ -1309,10 +891,8 @@
1309 891 status_header( 400 );
1310 892 exit;
1311 893 }
1312 894
1313 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Uploading data for chart %d with POST = %s and GET = %s', $chart_id, print_r( $_POST, true ), print_r( $_GET, true ) ), 'debug', __FILE__, __LINE__ );
1314 -
1315 895 if ( ! isset( $_POST['vz-import-time'] ) ) {
1316 896 apply_filters( 'visualizer_pro_remove_schedule', $chart_id );
1317 897 }
1318 898
@@ -1324,9 +904,8 @@
1324 904
1325 905 // delete "import from db" specific parameters.
1326 906 delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY );
1327 907 delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_SCHEDULE );
1328 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_REMOTE_DB_PARAMS );
1329 908 }
1330 909
1331 910 // delete json related data.
1332 911 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_URL );
@@ -1331,68 +910,36 @@
1331 910 // delete json related data.
1332 911 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_URL );
1333 912 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_ROOT );
1334 913 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_PAGING );
1335 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_HEADERS );
1336 914
1337 - // delete last error
1338 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR );
1339 -
1340 - // delete editor related data.
1341 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_EDITOR );
1342 -
1343 - // delete this so that a JSON import can be later edited manually without a problem.
1344 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE );
1345 -
1346 915 $source = null;
1347 916 $render = new Visualizer_Render_Page_Update();
1348 -
1349 - $remote_data = false;
1350 - if ( isset( $_POST['remote_data'] ) && function_exists( 'wp_http_validate_url' ) ) {
1351 - $remote_data = wp_http_validate_url( $_POST['remote_data'] );
1352 - }
1353 - if ( false !== $remote_data ) {
1354 - $remote_ext = strtolower( pathinfo( parse_url( $remote_data, PHP_URL_PATH ), PATHINFO_EXTENSION ) );
1355 - if ( 'xlsx' === $remote_ext || ( 'csv' !== $remote_ext && self::_url_is_xlsx( $remote_data ) ) ) {
1356 - $source = new Visualizer_Source_Xlsx_Remote( $remote_data );
1357 - } else {
1358 - $source = new Visualizer_Source_Csv_Remote( $remote_data );
1359 - }
917 + if ( isset( $_POST['remote_data'] ) && filter_var( $_POST['remote_data'], FILTER_VALIDATE_URL ) ) {
918 + $source = new Visualizer_Source_Csv_Remote( $_POST['remote_data'] );
1360 919 if ( isset( $_POST['vz-import-time'] ) ) {
1361 - apply_filters( 'visualizer_pro_chart_schedule', $chart_id, $remote_data, $_POST['vz-import-time'] );
920 + apply_filters( 'visualizer_pro_chart_schedule', $chart_id, $_POST['remote_data'], $_POST['vz-import-time'] );
1362 921 }
1363 - } elseif ( isset( $_FILES['local_data'] ) && $_FILES['local_data']['error'] === 0 ) {
1364 - $local_ext = strtolower( pathinfo( isset( $_FILES['local_data']['name'] ) ? $_FILES['local_data']['name'] : '', PATHINFO_EXTENSION ) );
1365 - if ( 'xlsx' === $local_ext ) {
1366 - $source = new Visualizer_Source_Xlsx( $_FILES['local_data']['tmp_name'] );
1367 - } else {
1368 - $source = new Visualizer_Source_Csv( $_FILES['local_data']['tmp_name'] );
1369 - }
922 + // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison
923 + } elseif ( isset( $_FILES['local_data'] ) && $_FILES['local_data']['error'] == 0 ) {
924 + $source = new Visualizer_Source_Csv( $_FILES['local_data']['tmp_name'] );
1370 925 } elseif ( isset( $_POST['chart_data'] ) && strlen( $_POST['chart_data'] ) > 0 ) {
1371 - $source = $this->handleCSVasString( $_POST['chart_data'], $_POST['editor-type'] );
1372 - update_post_meta( $chart_id, Visualizer_Plugin::CF_EDITOR, $_POST['editor-type'] );
926 + $source = $this->handleCSVasString( $_POST['chart_data'] );
1373 927 } elseif ( isset( $_POST['table_data'] ) && 'yes' === $_POST['table_data'] ) {
1374 928 $source = $this->handleTabularData();
1375 - update_post_meta( $chart_id, Visualizer_Plugin::CF_EDITOR, $_POST['editor-type'] );
1376 929 } else {
1377 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'CSV file with chart data was not uploaded for chart %d.', $chart_id ), 'error', __FILE__, __LINE__ );
1378 - $render->message = esc_html__( 'No CSV file was received. Select a file and try uploading again.', 'visualizer' );
1379 - update_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR, esc_html__( 'No CSV file was received. Select a file and try uploading again.', 'visualizer' ) );
930 + $render->message = esc_html__( 'CSV file with chart data was not uploaded. Please, try again.', 'visualizer' );
1380 931 }
1381 -
1382 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Uploaded data for chart %d with source %s', $chart_id, print_r( $source, true ) ), 'debug', __FILE__, __LINE__ );
1383 -
1384 932 if ( $source ) {
1385 933 if ( $source->fetch() ) {
1386 - $content = $source->getData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) );
934 + $content = $source->getData();
1387 935 $populate = true;
1388 - $json = self::decode_content( $content );
1389 - if ( is_array( $json ) ) {
936 + if ( is_string( $content ) && is_array( unserialize( $content ) ) ) {
937 + $json = unserialize( $content );
1390 938 // if source exists, so should data. if source exists but data is blank, do not populate the chart.
1391 939 // if we populate the data even if it is empty, the chart will show "Table has no columns".
1392 940 if ( array_key_exists( 'source', $json ) && ! empty( $json['source'] ) && ( ! array_key_exists( 'data', $json ) || empty( $json['data'] ) ) ) {
1393 941 do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Not populating chart data as source exists (%s) but data is empty!', $json['source'] ), 'warn', __FILE__, __LINE__ );
1394 - update_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR, sprintf( 'Not populating chart data as source exists (%s) but data is empty!', $json['source'] ) );
1395 942 $populate = false;
1396 943 }
1397 944 }
1398 945 if ( $populate ) {
@@ -1398,49 +945,23 @@
1398 945 if ( $populate ) {
1399 946 $chart->post_content = $content;
1400 947 }
1401 948 wp_update_post( $chart->to_array() );
1402 -
1403 949 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
1404 950 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
1405 951 update_post_meta( $chart->ID, Visualizer_Plugin::CF_DEFAULT_DATA, 0 );
1406 -
1407 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Updated post for chart %d', $chart_id ), 'debug', __FILE__, __LINE__ );
1408 -
1409 - Visualizer_Module_Utility::set_defaults( $chart, null );
1410 -
1411 - $settings = get_post_meta( $chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
1412 - if ( isset( $settings['series'] ) && ! ( count( $settings['series'] ) - count( $source->getSeries() ) > 1 ) ) {
1413 - $diff_total_series = abs( count( $settings['series'] ) - count( $source->getSeries() ) );
1414 - if ( $diff_total_series ) {
1415 - foreach ( range( 1, $diff_total_series ) as $k => $diff_series ) {
1416 - $settings['series'][] = end( $settings['series'] );
1417 - }
1418 - update_post_meta( $chart->ID, Visualizer_Plugin::CF_SETTINGS, $settings );
1419 - }
1420 - }
1421 -
1422 952 $render->id = $chart->ID;
1423 - $render->data = json_encode( $source->getRawData( get_post_meta( $chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ) );
953 + $render->data = json_encode( $source->getRawData() );
1424 954 $render->series = json_encode( $source->getSeries() );
1425 - $render->settings = json_encode( $settings );
1426 955 } else {
1427 - $error = $source->get_error();
1428 - if ( empty( $error ) ) {
1429 - $error = esc_html__( 'The CSV file couldn\'t be read. Check that it\'s properly formatted and try again.', 'visualizer' );
1430 - }
1431 - $render->message = $error;
1432 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( '%s for chart %d.', $error, $chart_id ), 'error', __FILE__, __LINE__ );
1433 - update_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR, $error );
956 + $render->message = esc_html__( 'CSV file is broken or invalid. Please, try again.', 'visualizer' );
1434 957 }
1435 - } else {
1436 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Unknown internal error for chart %d.', $chart_id ), 'error', __FILE__, __LINE__ );
1437 958 }
1438 959 $render->render();
1439 960 if ( ! $can_die ) {
1440 961 return;
1441 962 }
1442 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
963 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1443 964 }
1444 965
1445 966 /**
1446 967 * Clones the chart.
@@ -1450,17 +971,27 @@
1450 971 * @access public
1451 972 */
1452 973 public function cloneChart() {
1453 974 $chart_id = $success = false;
1454 - $nonce = isset( $_GET['nonce'] ) && wp_verify_nonce( $_GET['nonce'], Visualizer_Plugin::ACTION_CLONE_CHART );
1455 - if ( $nonce ) {
1456 - $chart_id = isset( $_GET['chart'] ) ? filter_var( $_GET['chart'], FILTER_VALIDATE_INT ) : '';
1457 - if ( $chart_id && self::can_edit_chart( $chart_id ) ) {
975 + $nonce = wp_verify_nonce( filter_input( INPUT_GET, 'nonce' ), Visualizer_Plugin::ACTION_CLONE_CHART );
976 + $capable = current_user_can( 'edit_posts' );
977 + if ( $nonce && $capable ) {
978 + $chart_id = filter_input(
979 + INPUT_GET,
980 + 'chart',
981 + FILTER_VALIDATE_INT,
982 + array(
983 + 'options' => array(
984 + 'min_range' => 1,
985 + ),
986 + )
987 + );
988 + if ( $chart_id ) {
1458 989 $chart = get_post( $chart_id );
1459 990 $success = $chart && $chart->post_type === Visualizer_Plugin::CPT_VISUALIZER;
1460 991 }
1461 992 }
1462 - $redirect = remove_query_arg( 'vaction', wp_get_referer() );
993 + $redirect = wp_get_referer();
1463 994 if ( $success ) {
1464 995 $new_chart_id = wp_insert_post(
1465 996 array(
1466 997 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
@@ -1469,35 +1000,23 @@
1469 1000 'post_status' => $chart->post_status,
1470 1001 'post_content' => $chart->post_content,
1471 1002 )
1472 1003 );
1473 - if ( is_wp_error( $new_chart_id ) ) {
1474 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Error while cloning chart %d = %s', $chart_id, print_r( $new_chart_id, true ) ), 'error', __FILE__, __LINE__ );
1475 - } else {
1476 - $post_meta = get_post_meta( $chart_id );
1477 - foreach ( $post_meta as $key => $value ) {
1478 - if ( strpos( $key, 'visualizer-' ) !== false ) {
1479 - add_post_meta( $new_chart_id, $key, self::maybe_decode_content( $value[0] ) );
1480 - }
1481 - }
1482 - $redirect = esc_url(
1483 - add_query_arg(
1484 - array(
1485 - 'page' => 'visualizer',
1486 - 'type' => filter_input( INPUT_GET, 'type' ),
1487 - 'vaction' => false,
1488 - ),
1489 - admin_url( 'admin.php' )
1004 + if ( $new_chart_id && ! is_wp_error( $new_chart_id ) ) {
1005 + add_post_meta( $new_chart_id, Visualizer_Plugin::CF_CHART_TYPE, get_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_TYPE, true ) );
1006 + add_post_meta( $new_chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, get_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, true ) );
1007 + add_post_meta( $new_chart_id, Visualizer_Plugin::CF_SOURCE, get_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, true ) );
1008 + add_post_meta( $new_chart_id, Visualizer_Plugin::CF_SERIES, get_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, true ) );
1009 + add_post_meta( $new_chart_id, Visualizer_Plugin::CF_SETTINGS, get_post_meta( $chart_id, Visualizer_Plugin::CF_SETTINGS, true ) );
1010 + $redirect = add_query_arg(
1011 + array(
1012 + 'page' => 'visualizer',
1013 + 'type' => filter_input( INPUT_GET, 'type' ),
1490 1014 ),
1491 - null,
1492 - 'db'
1015 + admin_url( 'upload.php' )
1493 1016 );
1494 1017 }
1495 1018 }
1496 -
1497 - if ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) {
1498 - wp_die();
1499 - }
1500 1019 wp_redirect( $redirect );
1501 1020 exit;
1502 1021 }
1503 1022
@@ -1509,25 +1028,28 @@
1509 1028 * @access public
1510 1029 */
1511 1030 public function exportData() {
1512 1031 check_ajax_referer( Visualizer_Plugin::ACTION_EXPORT_DATA . Visualizer_Plugin::VERSION, 'security' );
1513 - $chart_id = isset( $_GET['chart'] ) ? filter_var(
1514 - $_GET['chart'],
1515 - FILTER_VALIDATE_INT,
1516 - array(
1517 - 'options' => array(
1518 - 'min_range' => 1,
1519 - ),
1520 - )
1521 - ) : '';
1522 - if ( $chart_id && self::can_edit_chart( $chart_id ) ) {
1523 - $data = $this->_getDataAs( $chart_id, 'csv' );
1524 - if ( $data ) {
1525 - echo wp_send_json_success( $data );
1032 + $capable = current_user_can( 'edit_posts' );
1033 + if ( $capable ) {
1034 + $chart_id = isset( $_GET['chart'] ) ? filter_var(
1035 + $_GET['chart'],
1036 + FILTER_VALIDATE_INT,
1037 + array(
1038 + 'options' => array(
1039 + 'min_range' => 1,
1040 + ),
1041 + )
1042 + ) : '';
1043 + if ( $chart_id ) {
1044 + $data = $this->_getDataAs( $chart_id, 'csv' );
1045 + if ( $data ) {
1046 + echo wp_send_json_success( $data );
1047 + }
1526 1048 }
1527 1049 }
1528 1050
1529 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1051 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1530 1052 }
1531 1053
1532 1054 /**
1533 1055 * Handles chart data page.
@@ -1540,12 +1062,9 @@
1540 1062 $data = $this->_getChartArray();
1541 1063 $render = new Visualizer_Render_Page_Data();
1542 1064 $render->chart = $this->_chart;
1543 1065 $render->type = $data['type'];
1544 -
1545 - if ( $data && $data['settings'] ) {
1546 - unset( $data['settings']['width'], $data['settings']['height'], $data['settings']['chartArea'] );
1547 - }
1066 + unset( $data['settings']['width'], $data['settings']['height'] );
1548 1067 wp_enqueue_style( 'visualizer-frame' );
1549 1068 wp_enqueue_script( 'visualizer-render' );
1550 1069 wp_localize_script(
1551 1070 'visualizer-render',
@@ -1551,11 +1070,10 @@
1551 1070 'visualizer-render',
1552 1071 'visualizer',
1553 1072 array(
1554 1073 'l10n' => array(
1555 - 'invalid_source' => esc_html__( 'The URL you entered is invalid. Please enter a valid URL.', 'visualizer' ),
1556 - 'loading' => esc_html__( 'Loading...', 'visualizer' ),
1557 - 'invalid_format' => esc_html__( 'This format pattern is not supported in the series settings field. To display percentages, use the Manual Configuration option instead.', 'visualizer' ),
1074 + 'invalid_source' => esc_html__( 'You have entered invalid URL. Please, insert proper URL.', 'visualizer' ),
1075 + 'loading' => esc_html__( 'Loading...', 'visualizer' ),
1558 1076 ),
1559 1077 'charts' => array(
1560 1078 'canvas' => $data,
1561 1079 ),
@@ -1560,16 +1078,13 @@
1560 1078 'canvas' => $data,
1561 1079 ),
1562 1080 )
1563 1081 );
1564 -
1565 - do_action( 'visualizer_enqueue_scripts_and_styles', $data, $this->_chart->ID );
1566 -
1567 - if ( Visualizer_Module::is_pro() && Visualizer_Module::is_pro_older_than( '1.9.0' ) ) {
1082 + // Added by Ash/Upwork
1083 + if ( VISUALIZER_PRO ) {
1568 1084 global $Visualizer_Pro;
1569 - $Visualizer_Pro->_enqueueScriptsAndStyles( $data, $this->_chart->ID );
1085 + $Visualizer_Pro->_enqueueScriptsAndStyles( $data );
1570 1086 }
1571 -
1572 1087 // Added by Ash/Upwork
1573 1088 $this->_addAction( 'admin_head', 'renderFlattrScript' );
1574 1089 wp_iframe( array( $render, 'render' ) );
1575 1090 }
@@ -1581,27 +1096,14 @@
1581 1096 */
1582 1097 public function getQueryData() {
1583 1098 check_ajax_referer( Visualizer_Plugin::ACTION_FETCH_DB_DATA . Visualizer_Plugin::VERSION, 'security' );
1584 1099
1585 - if ( ! current_user_can( 'administrator' ) ) {
1586 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1587 - }
1588 - if ( ! is_super_admin() ) {
1589 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1590 - }
1591 -
1592 - if ( ! Visualizer_Module::is_pro() ) {
1593 - wp_send_json_error( array( 'msg' => __( 'Feature is not available.', 'visualizer' ) ) );
1594 - }
1595 -
1596 1100 $params = wp_parse_args( $_POST['params'] );
1597 - $chart_id = filter_var( $params['chart_id'], FILTER_VALIDATE_INT );
1598 - $query = trim( $params['query'], ';' );
1599 -
1600 - $source = new Visualizer_Source_Query( stripslashes( $query ), $chart_id, $params );
1101 + $source = new Visualizer_Source_Query( stripslashes( $params['query'] ) );
1601 1102 $html = $source->fetch( true );
1602 - $error = $source->get_error();
1603 - if ( ! empty( $error ) ) {
1103 + $error = '';
1104 + if ( empty( $html ) ) {
1105 + $error = $source->get_error();
1604 1106 wp_send_json_error( array( 'msg' => $error ) );
1605 1107 }
1606 1108 wp_send_json_success( array( 'table' => $html ) );
1607 1109 }
@@ -1613,19 +1115,8 @@
1613 1115 */
1614 1116 public function saveQuery() {
1615 1117 check_ajax_referer( Visualizer_Plugin::ACTION_SAVE_DB_QUERY . Visualizer_Plugin::VERSION, 'security' );
1616 1118
1617 - if ( ! current_user_can( 'administrator' ) ) {
1618 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1619 - }
1620 - if ( ! is_super_admin() ) {
1621 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1622 - }
1623 -
1624 - if ( ! Visualizer_Module::is_pro() ) {
1625 - wp_send_json_error( array( 'msg' => __( 'Feature is not available.', 'visualizer' ) ) );
1626 - }
1627 -
1628 1119 $chart_id = filter_input(
1629 1120 INPUT_GET,
1630 1121 'chart',
1631 1122 FILTER_VALIDATE_INT,
@@ -1635,43 +1126,21 @@
1635 1126 ),
1636 1127 )
1637 1128 );
1638 1129
1639 - $hours = filter_input(
1640 - INPUT_POST,
1641 - 'refresh',
1642 - FILTER_VALIDATE_FLOAT,
1643 - array(
1644 - 'options' => array(
1645 - 'min_range' => -1,
1646 - 'max_range' => apply_filters( 'visualizer_is_business', false ) ? PHP_INT_MAX : -1,
1647 - ),
1648 - )
1649 - );
1650 -
1651 - if ( ! is_numeric( $hours ) ) {
1652 - $hours = -1;
1653 - }
1654 -
1655 1130 $render = new Visualizer_Render_Page_Update();
1656 1131 if ( $chart_id ) {
1657 1132 $params = wp_parse_args( $_POST['params'] );
1658 - $query = trim( $params['query'], ';' );
1659 - $source = new Visualizer_Source_Query( stripslashes( $query ), $chart_id, $params );
1133 + $source = new Visualizer_Source_Query( stripslashes( $params['query'] ) );
1660 1134 $source->fetch( false );
1661 1135 $error = $source->get_error();
1662 1136 if ( empty( $error ) ) {
1663 - update_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY, stripslashes( $query ) );
1137 + $hours = $_POST['refresh'];
1138 + update_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY, stripslashes( $params['query'] ) );
1664 1139 update_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
1665 1140 update_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
1666 1141 update_post_meta( $chart_id, Visualizer_Plugin::CF_DB_SCHEDULE, $hours );
1667 1142 update_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, 0 );
1668 - if ( isset( $params['db_type'] ) && $params['db_type'] !== Visualizer_Plugin::WP_DB_NAME ) {
1669 - $remote_db_params = $params;
1670 - unset( $remote_db_params['query'] );
1671 - unset( $remote_db_params['chart_id'] );
1672 - update_post_meta( $chart_id, Visualizer_Plugin::CF_REMOTE_DB_PARAMS, $remote_db_params );
1673 - }
1674 1143
1675 1144 $schedules = get_option( Visualizer_Plugin::CF_DB_SCHEDULE, array() );
1676 1145 $schedules[ $chart_id ] = time() + $hours * HOUR_IN_SECONDS;
1677 1146 update_option( Visualizer_Plugin::CF_DB_SCHEDULE, $schedules );
@@ -1678,14 +1147,13 @@
1678 1147
1679 1148 wp_update_post(
1680 1149 array(
1681 1150 'ID' => $chart_id,
1682 - 'post_content' => $source->getData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ),
1151 + 'post_content' => $source->getData(),
1683 1152 )
1684 1153 );
1685 - $render->data = json_encode( $source->getRawData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ) );
1154 + $render->data = json_encode( $source->getRawData() );
1686 1155 $render->series = json_encode( $source->getSeries() );
1687 - $render->id = $chart_id;
1688 1156 } else {
1689 1157 $render->message = $error;
1690 1158 }
1691 1159 }
@@ -1690,9 +1158,9 @@
1690 1158 }
1691 1159 }
1692 1160 $render->render();
1693 1161 if ( ! ( defined( 'VISUALIZER_DO_NOT_DIE' ) && VISUALIZER_DO_NOT_DIE ) ) {
1694 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1162 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1695 1163 }
1696 1164 }
1697 1165
1698 1166
@@ -1703,10 +1171,11 @@
1703 1171 */
1704 1172 public function saveFilter() {
1705 1173 check_ajax_referer( Visualizer_Plugin::ACTION_SAVE_FILTER_QUERY . Visualizer_Plugin::VERSION, 'security' );
1706 1174
1707 - $chart_id = isset( $_GET['chart'] ) ? filter_var(
1708 - $_GET['chart'],
1175 + $chart_id = filter_input(
1176 + INPUT_GET,
1177 + 'chart',
1709 1178 FILTER_VALIDATE_INT,
1710 1179 array(
1711 1180 'options' => array(
1712 1181 'min_range' => 1,
@@ -1711,90 +1180,15 @@
1711 1180 'options' => array(
1712 1181 'min_range' => 1,
1713 1182 ),
1714 1183 )
1715 - ) : false;
1716 -
1717 - if ( ! self::can_edit_chart( $chart_id ) ) {
1718 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ), 403 );
1719 - }
1720 -
1721 - $hours = filter_input(
1722 - INPUT_POST,
1723 - 'refresh',
1724 - FILTER_VALIDATE_FLOAT,
1725 - array(
1726 - 'options' => array(
1727 - 'min_range' => -1,
1728 - 'max_range' => apply_filters( 'visualizer_is_business', false ) ? PHP_INT_MAX : -1,
1729 - ),
1730 - )
1731 1184 );
1732 1185
1733 - if ( ! is_numeric( $hours ) ) {
1734 - $hours = -1;
1735 - }
1186 + $hours = $_POST['refresh'];
1736 1187
1737 1188 do_action( 'visualizer_save_filter', $chart_id, $hours );
1738 1189
1739 1190 if ( ! ( defined( 'VISUALIZER_DO_NOT_DIE' ) && VISUALIZER_DO_NOT_DIE ) ) {
1740 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1191 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1741 1192 }
1742 - }
1743 -
1744 - /**
1745 - * Save chart image.
1746 - *
1747 - * @param string $base64_img Chart image.
1748 - * @param int $chart_id Chart ID.
1749 - * @param bool $save_attachment Save attachment.
1750 - * @return int Attachment ID, or 0 when no attachment was saved.
1751 - */
1752 - public function save_chart_image( $base64_img, $chart_id, $save_attachment = true ) {
1753 - // Delete old chart image.
1754 - $old_attachment_id = get_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_IMAGE, true );
1755 - if ( $old_attachment_id ) {
1756 - wp_delete_attachment( $old_attachment_id, true );
1757 - }
1758 -
1759 - if ( ! $save_attachment ) {
1760 - return 0;
1761 - }
1762 -
1763 - // Upload dir.
1764 - $upload_dir = wp_upload_dir();
1765 - $upload_path = str_replace( '/', DIRECTORY_SEPARATOR, $upload_dir['path'] ) . DIRECTORY_SEPARATOR;
1766 -
1767 - $img = str_replace( 'data:image/png;base64,', '', (string) $base64_img );
1768 - $img = str_replace( ' ', '+', $img );
1769 - $decoded = base64_decode( $img, true );
1770 - // The value comes from an untrusted request; only write real PNG bytes to uploads.
1771 - if ( false === $decoded || 0 !== strncmp( $decoded, "\x89PNG\r\n\x1a\n", 8 ) ) {
1772 - return 0;
1773 - }
1774 - $filename = 'visualization-' . $chart_id . '.png';
1775 - $file_type = 'image/png';
1776 - $hashed_filename = $filename;
1777 -
1778 - // Save the image in the uploads directory.
1779 - require_once ABSPATH . '/wp-admin/includes/file.php';
1780 - \WP_Filesystem();
1781 - global $wp_filesystem;
1782 - if ( ! is_a( $wp_filesystem, 'WP_Filesystem_Base' ) ) {
1783 - $creds = request_filesystem_credentials( site_url() );
1784 - wp_filesystem( $creds );
1785 - }
1786 - $upload_file = $wp_filesystem->put_contents( $upload_path . $hashed_filename, $decoded );
1787 -
1788 - // Insert new chart image.
1789 - $attachment = array(
1790 - 'post_mime_type' => $file_type,
1791 - 'post_title' => preg_replace( '/\.[^.]+$/', '', basename( $hashed_filename ) ),
1792 - 'post_content' => '',
1793 - 'post_status' => 'inherit',
1794 - 'guid' => $upload_dir['url'] . '/' . basename( $hashed_filename ),
1795 - );
1796 -
1797 - $attach_id = wp_insert_attachment( $attachment, $upload_dir['path'] . '/' . $hashed_filename );
1798 - return $attach_id;
1799 1193 }
1800 1194 }