PluginProbe
Visualizer – Tables & Charts Manager with Built-in AI Generator / 3.3.4
Visualizer – Tables & Charts Manager with Built-in AI Generator v3.3.4
4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.10.1 3.10.10 3.10.11 3.10.12 3.10.13 3.10.14 3.10.15 3.10.2 3.10.3 3.10.4 All 148 releases
← All changes | classes/Visualizer/Module/Chart.php +175 -727 4.0.73.3.4 View file →
@@ -68,38 +68,11 @@
68 68 $this->_addAjaxAction( Visualizer_Plugin::ACTION_JSON_SET_SCHEDULE, 'setJsonSchedule' );
69 69
70 70 $this->_addAjaxAction( Visualizer_Plugin::ACTION_SAVE_FILTER_QUERY, 'saveFilter' );
71 71
72 - $this->_addFilter( 'visualizer_get_sidebar', 'getSidebar', 10, 2 );
73 72 }
74 73
75 74 /**
76 - * Generates the HTML of the sidebar for the chart.
77 - *
78 - * @since ?
79 - *
80 - * @access public
81 - */
82 - public function getSidebar( $sidebar, $chart_id ) {
83 - $chart = get_post( $chart_id );
84 - $data = $this->_getChartArray( $chart );
85 - $sidebar = '';
86 - $sidebar_class = $this->load_chart_class_name( $chart_id );
87 - if ( class_exists( $sidebar_class, true ) ) {
88 - $sidebar = new $sidebar_class( $data['settings'] );
89 - $sidebar->__series = $data['series'];
90 - $sidebar->__data = $data['data'];
91 - } else {
92 - $sidebar = apply_filters( 'visualizer_pro_chart_type_sidebar', '', $data );
93 - if ( $sidebar !== '' ) {
94 - $sidebar->__series = $data['series'];
95 - $sidebar->__data = $data['data'];
96 - }
97 - }
98 - return str_replace( "'", '"', $sidebar->__toString() );
99 - }
100 -
101 - /**
102 75 * Sets the schedule for how JSON-endpoint charts should be updated.
103 76 *
104 77 * @since ?
105 78 *
@@ -107,10 +80,11 @@
107 80 */
108 81 public function setJsonSchedule() {
109 82 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_SET_SCHEDULE . Visualizer_Plugin::VERSION, 'security' );
110 83
111 - $chart_id = isset( $_POST['chart'] ) ? filter_var(
112 - $_POST['chart'],
84 + $chart_id = filter_input(
85 + INPUT_POST,
86 + 'chart',
113 87 FILTER_VALIDATE_INT,
114 88 array(
115 89 'options' => array(
116 90 'min_range' => 1,
@@ -115,18 +89,14 @@
115 89 'options' => array(
116 90 'min_range' => 1,
117 91 ),
118 92 )
119 - ) : false;
93 + );
120 94
121 95 if ( ! $chart_id ) {
122 96 wp_send_json_error();
123 97 }
124 98
125 - if ( ! self::can_edit_chart( $chart_id ) ) {
126 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ), 403 );
127 - }
128 -
129 99 $time = filter_input(
130 100 INPUT_POST,
131 101 'time',
132 102 FILTER_VALIDATE_INT,
@@ -136,30 +106,12 @@
136 106 ),
137 107 )
138 108 );
139 109
140 - if ( Visualizer_Module::is_pro() ) {
141 - $is_woocommerce_report = filter_input(
142 - INPUT_POST,
143 - 'is_woocommerce_report',
144 - FILTER_VALIDATE_BOOLEAN
145 - );
146 -
147 - if ( $is_woocommerce_report ) {
148 - update_post_meta( $chart_id, Visualizer_Plugin::CF_IS_WOOCOMMERCE_SOURCE, true );
149 - } else {
150 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_IS_WOOCOMMERCE_SOURCE );
151 - }
152 - }
153 -
154 110 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE );
155 111
156 112 if ( -1 < $time ) {
157 113 add_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE, $time );
158 - // Update schedules.
159 - $schedules = get_option( Visualizer_Plugin::CF_JSON_SCHEDULE, array() );
160 - $schedules[ $chart_id ] = time() + $time * HOUR_IN_SECONDS;
161 - update_option( Visualizer_Plugin::CF_JSON_SCHEDULE, $schedules );
162 114 }
163 115 wp_send_json_success();
164 116 }
165 117
@@ -172,12 +124,8 @@
172 124 */
173 125 public function getJsonRoots() {
174 126 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_GET_ROOTS . Visualizer_Plugin::VERSION, 'security' );
175 127
176 - if ( ! current_user_can( 'edit_posts' ) ) {
177 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ) );
178 - }
179 -
180 128 $params = wp_parse_args( $_POST['params'] );
181 129
182 130 $source = new Visualizer_Source_Json( $params );
183 131
@@ -198,25 +146,19 @@
198 146 */
199 147 public function getJsonData() {
200 148 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_GET_DATA . Visualizer_Plugin::VERSION, 'security' );
201 149
202 - if ( ! current_user_can( 'edit_posts' ) ) {
203 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ) );
204 - }
205 -
206 150 $params = wp_parse_args( $_POST['params'] );
207 151
208 152 $chart_id = $params['chart'];
209 153
210 - $chart = $chart_id ? get_post( $chart_id ) : null;
211 - if ( ! $chart || Visualizer_Plugin::CPT_VISUALIZER !== $chart->post_type || ! current_user_can( 'edit_post', $chart_id ) ) {
154 + if ( empty( $chart_id ) ) {
212 155 wp_die();
213 156 }
214 157
215 158 $source = new Visualizer_Source_Json( $params );
216 - $source->fetch();
217 - $data = $source->getRawData();
218 159
160 + $data = $source->parse();
219 161 if ( empty( $data ) ) {
220 162 wp_send_json_error( array( 'msg' => esc_html__( 'Unable to fetch data from the endpoint. Please try again.', 'visualizer' ) ) );
221 163 }
222 164
@@ -234,21 +176,20 @@
234 176 public function setJsonData() {
235 177 check_ajax_referer( Visualizer_Plugin::ACTION_JSON_SET_DATA . Visualizer_Plugin::VERSION, 'security' );
236 178
237 179 $params = $_POST;
238 - $chart_id = isset( $_GET['chart'] ) ? absint( $_GET['chart'] ) : 0;
180 + $chart_id = $_GET['chart'];
239 181
240 - if ( ! self::can_edit_chart( $chart_id ) ) {
241 - wp_die( esc_html__( 'You do not have permission to perform this action.', 'visualizer' ), '', array( 'response' => 403 ) );
182 + if ( empty( $chart_id ) ) {
183 + wp_die();
242 184 }
243 185
244 186 $chart = get_post( $chart_id );
245 187
246 188 $source = new Visualizer_Source_Json( $params );
247 - update_post_meta( $chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true );
248 - $source->fetchFromEditableTable();
189 + $source->fetch();
249 190
250 - $content = $source->getData( get_post_meta( $chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) );
191 + $content = $source->getData();
251 192 $chart->post_content = $content;
252 193 wp_update_post( $chart->to_array() );
253 194 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
254 195 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
@@ -254,62 +195,20 @@
254 195 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
255 196 update_post_meta( $chart->ID, Visualizer_Plugin::CF_DEFAULT_DATA, 0 );
256 197 update_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_URL, $params['url'] );
257 198 update_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_ROOT, $params['root'] );
258 -
259 - delete_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_HEADERS );
260 - $headers = array( 'method' => $params['method'] );
261 - if ( ! empty( $params['auth'] ) ) {
262 - $headers['auth'] = $params['auth'];
263 - } elseif ( ! empty( $params['username'] ) && ! empty( $params['password'] ) ) {
264 - $headers['auth'] = array( 'username' => $params['username'], 'password' => $params['password'] );
265 - }
266 -
267 - add_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_HEADERS, $headers );
268 -
269 199 delete_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_PAGING );
270 200 if ( ! empty( $params['paging'] ) ) {
271 201 add_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_PAGING, $params['paging'] );
272 202 }
273 203
274 - if ( Visualizer_Module::is_pro() ) {
275 - if ( ! empty( $params['vz_woo_source'] ) ) {
276 - update_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_WOOCOMMERCE_SOURCE, $params['vz_woo_source'] );
277 - } else {
278 - delete_post_meta( $chart->ID, Visualizer_Plugin::CF_JSON_WOOCOMMERCE_SOURCE );
279 - }
280 - }
281 -
282 - $time = filter_input(
283 - INPUT_POST,
284 - 'time',
285 - FILTER_VALIDATE_INT,
286 - array(
287 - 'options' => array(
288 - 'min_range' => -1,
289 - ),
290 - )
291 - );
292 -
293 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE );
294 -
295 - if ( -1 < $time ) {
296 - add_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_SCHEDULE, $time );
297 - }
298 -
299 - // delete other source specific parameters.
300 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY );
301 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_SCHEDULE );
302 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_URL );
303 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_SCHEDULE );
304 -
305 204 $render = new Visualizer_Render_Page_Update();
306 205 $render->id = $chart->ID;
307 - $render->data = json_encode( $source->getRawData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ) );
206 + $render->data = json_encode( $source->getRawData() );
308 207 $render->series = json_encode( $source->getSeries() );
309 208 $render->render();
310 209
311 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
210 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
312 211 }
313 212
314 213
315 214 /**
@@ -321,14 +220,8 @@
321 220 *
322 221 * @access public
323 222 */
324 223 public function getCharts() {
325 - check_ajax_referer( Visualizer_Plugin::ACTION_GET_CHARTS, 'nonce' );
326 -
327 - if ( ! current_user_can( 'edit_posts' ) ) {
328 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ), 403 );
329 - }
330 -
331 224 $query_args = array(
332 225 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
333 226 'posts_per_page' => 9,
334 227 'paged' => filter_input(
@@ -342,11 +235,8 @@
342 235 ),
343 236 )
344 237 ),
345 238 );
346 - if ( ! current_user_can( 'edit_others_posts' ) ) {
347 - $query_args['author'] = get_current_user_id();
348 - }
349 239 $filter = filter_input( INPUT_GET, 's', FILTER_SANITIZE_STRING );
350 240 if ( empty( $filter ) ) {
351 241 // 'filter' is from the modal from the add media button.
352 242 $filter = filter_input( INPUT_GET, 'filter', FILTER_SANITIZE_STRING );
@@ -394,19 +284,19 @@
394 284 * @since 1.0.0
395 285 *
396 286 * @access private
397 287 *
398 - * @param WP_Post|null $chart The chart object.
288 + * @param WP_Post $chart The chart object.
399 289 *
400 290 * @return array The array of chart data.
401 291 */
402 - private function _getChartArray( $chart = null ) {
292 + private function _getChartArray( WP_Post $chart = null ) {
403 293 if ( is_null( $chart ) ) {
404 294 $chart = $this->_chart;
405 295 }
406 296 $type = get_post_meta( $chart->ID, Visualizer_Plugin::CF_CHART_TYPE, true );
407 297 $series = apply_filters( Visualizer_Plugin::FILTER_GET_CHART_SERIES, get_post_meta( $chart->ID, Visualizer_Plugin::CF_SERIES, true ), $chart->ID, $type );
408 - $data = self::get_chart_data( $chart, $type );
298 + $data = apply_filters( Visualizer_Plugin::FILTER_GET_CHART_DATA, unserialize( $chart->post_content ), $chart->ID, $type );
409 299 $library = $this->load_chart_type( $chart->ID );
410 300
411 301 $settings = get_post_meta( $chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
412 302 $settings = apply_filters( Visualizer_Plugin::FILTER_GET_CHART_SETTINGS, $settings, $chart->ID, $type );
@@ -422,13 +312,8 @@
422 312 }
423 313
424 314 $date_formats = Visualizer_Source::get_date_formats_if_exists( $series, $data );
425 315
426 - $code = '';
427 - if ( 'd3' === $library ) {
428 - $code = get_post_meta( $chart->ID, Visualizer_Module_AIBuilder::CF_D3_CODE, true );
429 - }
430 -
431 316 return array(
432 317 'type' => $type,
433 318 'series' => $series,
434 319 'settings' => $settings,
@@ -433,9 +318,8 @@
433 318 'series' => $series,
434 319 'settings' => $settings,
435 320 'data' => $data,
436 321 'library' => $library,
437 - 'code' => $code,
438 322 'css' => $css,
439 323 'date_formats' => $date_formats,
440 324 );
441 325 }
@@ -452,9 +336,9 @@
452 336 public static function _sendResponse( $results ) {
453 337 header( 'Content-type: application/json' );
454 338 nocache_headers();
455 339 echo json_encode( $results );
456 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
340 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
457 341 }
458 342
459 343 /**
460 344 * Deletes a chart from database.
@@ -465,14 +349,16 @@
465 349 * @access public
466 350 */
467 351 public function deleteChart() {
468 352 $is_post = $_SERVER['REQUEST_METHOD'] === 'POST';
469 - $input = $is_post ? $_POST : $_GET;
353 + $input_method = $is_post ? INPUT_POST : INPUT_GET;
470 354 $chart_id = $success = false;
471 - $nonce = isset( $input['nonce'] ) && wp_verify_nonce( $input['nonce'] );
472 - if ( $nonce ) {
473 - $chart_id = isset( $input['chart'] ) ? filter_var(
474 - $input['chart'],
355 + $nonce = wp_verify_nonce( filter_input( $input_method, 'nonce' ) );
356 + $capable = current_user_can( 'delete_posts' );
357 + if ( $nonce && $capable ) {
358 + $chart_id = filter_input(
359 + $input_method,
360 + 'chart',
475 361 FILTER_VALIDATE_INT,
476 362 array(
477 363 'options' => array(
478 364 'min_range' => 1,
@@ -477,34 +363,16 @@
477 363 'options' => array(
478 364 'min_range' => 1,
479 365 ),
480 366 )
481 - ) : false;
367 + );
482 368 if ( $chart_id ) {
483 369 $chart = get_post( $chart_id );
484 - $success = $chart
485 - && $chart->post_type === Visualizer_Plugin::CPT_VISUALIZER
486 - && (
487 - current_user_can( 'delete_post', $chart_id )
488 - || ( (int) $chart->post_author === get_current_user_id() && current_user_can( 'delete_posts' ) )
489 - );
370 + $success = $chart && $chart->post_type === Visualizer_Plugin::CPT_VISUALIZER;
490 371 }
491 372 }
492 373 if ( $success ) {
493 - global $sitepress;
494 - if ( Visualizer_Module::is_pro() && ( function_exists( 'icl_get_languages' ) && $sitepress instanceof \SitePress ) ) {
495 - $trid = $sitepress->get_element_trid( $chart_id, 'post_' . Visualizer_Plugin::CPT_VISUALIZER );
496 - $translations = $sitepress->get_element_translations( $trid );
497 - if ( ! empty( $translations ) ) {
498 - foreach ( $translations as $translated_post ) {
499 - wp_delete_post( $translated_post->element_id, true );
500 - }
501 - } else {
502 - wp_delete_post( $chart_id, true );
503 - }
504 - } else {
505 - wp_delete_post( $chart_id, true );
506 - }
374 + wp_delete_post( $chart_id, true );
507 375 }
508 376 if ( $is_post ) {
509 377 self::_sendResponse(
510 378 array(
@@ -552,111 +420,44 @@
552 420 *
553 421 * @access public
554 422 */
555 423 public function renderChartPages() {
556 - if ( ! current_user_can( 'edit_posts' ) ) {
557 - wp_die( __( 'You do not have permission to access this page.', 'visualizer' ) );
558 - }
559 -
560 424 defined( 'IFRAME_REQUEST' ) || define( 'IFRAME_REQUEST', 1 );
561 - if ( ! defined( 'ET_BUILDER_PRODUCT_VERSION' ) && function_exists( 'et_get_theme_version' ) ) {
562 - define( 'ET_BUILDER_PRODUCT_VERSION', et_get_theme_version() );
563 - }
564 - // Set current screen for the render chart.
565 - set_current_screen( 'visualizer_render_chart' );
566 425 // check chart, if chart not exists, will create new one and redirects to the same page with proper chart id
567 426 $chart_id = isset( $_GET['chart'] ) ? filter_var( $_GET['chart'], FILTER_VALIDATE_INT ) : '';
568 - if ( ! empty( $_POST ) ) {
569 - $_POST = map_deep( $_POST, 'wp_strip_all_tags' );
570 - }
571 - $chart = $chart_id ? get_post( $chart_id ) : null;
572 - if ( $chart && ! self::can_edit_chart( $chart_id ) ) {
573 - wp_die( esc_html__( 'You do not have permission to access this page.', 'visualizer' ), '', array( 'response' => 403 ) );
574 - }
575 - if ( ! $chart_id || ! $chart || $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ) {
576 - if ( empty( $_GET['lang'] ) || empty( $_GET['parent_chart_id'] ) ) {
577 - $this->deleteOldCharts();
578 - $default_type = isset( $_GET['type'] ) && ! empty( $_GET['type'] ) ? $_GET['type'] : 'line';
579 - $chart_status = Visualizer_Module_Admin::checkChartStatus( $default_type );
580 - if ( ! $chart_status ) {
581 - $default_type = 'line';
582 - }
583 - $source = new Visualizer_Source_Csv( VISUALIZER_ABSPATH . DIRECTORY_SEPARATOR . 'samples' . DIRECTORY_SEPARATOR . $default_type . '.csv' );
584 - $source->fetch();
585 - $chart_id = wp_insert_post(
427 + if ( ! $chart_id || ! ( $chart = get_post( $chart_id ) ) || $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ) {
428 + $this->deleteOldCharts();
429 + $default_type = isset( $_GET['type'] ) && ! empty( $_GET['type'] ) ? $_GET['type'] : 'line';
430 + $source = new Visualizer_Source_Csv( VISUALIZER_ABSPATH . DIRECTORY_SEPARATOR . 'samples' . DIRECTORY_SEPARATOR . $default_type . '.csv' );
431 + $source->fetch();
432 + $chart_id = wp_insert_post(
433 + array(
434 + 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
435 + 'post_title' => 'Visualization',
436 + 'post_author' => get_current_user_id(),
437 + 'post_status' => 'auto-draft',
438 + 'post_content' => $source->getData(),
439 + )
440 + );
441 + if ( $chart_id && ! is_wp_error( $chart_id ) ) {
442 + add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_TYPE, $default_type );
443 + add_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, 1 );
444 + add_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
445 + add_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
446 + add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_LIBRARY, '' );
447 + add_post_meta(
448 + $chart_id,
449 + Visualizer_Plugin::CF_SETTINGS,
586 450 array(
587 - 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
588 - 'post_title' => 'Visualization',
589 - 'post_author' => get_current_user_id(),
590 - 'post_status' => 'auto-draft',
591 - 'post_content' => $source->getData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ),
451 + 'focusTarget' => 'datum',
592 452 )
593 453 );
594 - if ( $chart_id && ! is_wp_error( $chart_id ) ) {
595 - add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_TYPE, $default_type );
596 - add_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, 1 );
597 - add_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
598 - add_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
599 - add_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_LIBRARY, '' );
600 - add_post_meta(
601 - $chart_id,
602 - Visualizer_Plugin::CF_SETTINGS,
603 - array(
604 - 'focusTarget' => 'datum',
605 - )
606 - );
607 -
608 - do_action( 'visualizer_pro_new_chart_defaults', $chart_id );
609 - }
610 - } else {
611 - $parent_chart_id = filter_var( $_GET['parent_chart_id'], FILTER_VALIDATE_INT );
612 - $success = false;
613 - if ( $parent_chart_id && self::can_edit_chart( $parent_chart_id ) ) {
614 - $parent_chart = get_post( $parent_chart_id );
615 - $success = $parent_chart && $parent_chart->post_type === Visualizer_Plugin::CPT_VISUALIZER;
616 - }
617 - if ( $success ) {
618 - $new_chart_id = wp_insert_post(
619 - array(
620 - 'post_type' => Visualizer_Plugin::CPT_VISUALIZER,
621 - 'post_title' => 'Visualization',
622 - 'post_author' => get_current_user_id(),
623 - 'post_status' => $parent_chart->post_status,
624 - 'post_content' => $parent_chart->post_content,
625 - )
626 - );
627 -
628 - if ( is_wp_error( $new_chart_id ) ) {
629 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Error while cloning chart %d = %s', $parent_chart_id, print_r( $new_chart_id, true ) ), 'error', __FILE__, __LINE__ );
630 - } else {
631 - $post_meta = get_post_meta( $parent_chart_id );
632 - $chart_id = $new_chart_id;
633 - foreach ( $post_meta as $key => $value ) {
634 - if ( strpos( $key, 'visualizer-' ) !== false ) {
635 - add_post_meta( $new_chart_id, $key, self::maybe_decode_content( $value[0] ) );
636 - }
637 - }
638 - }
639 - }
640 454 do_action( 'visualizer_pro_new_chart_defaults', $chart_id );
641 455 }
642 - wp_redirect( esc_url_raw( add_query_arg( 'chart', (int) $chart_id ) ) );
643 -
644 - if ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) {
645 - wp_die();
646 - }
647 - exit();
456 + wp_redirect( add_query_arg( 'chart', (int) $chart_id ) );
457 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
648 458 }
649 459
650 - $_POST['save_chart_image'] = isset( $_POST['save_chart_image'] ) && 'yes' === $_POST['save_chart_image'] ? true : false;
651 - $_POST['lazy_load_chart'] = isset( $_POST['lazy_load_chart'] ) && 'yes' === $_POST['lazy_load_chart'] ? true : false;
652 -
653 - if ( isset( $_POST['chart-img'] ) && ! empty( $_POST['chart-img'] ) ) {
654 - $attachment_id = $this->save_chart_image( $_POST['chart-img'], $chart_id, $_POST['save_chart_image'] );
655 - if ( $attachment_id ) {
656 - update_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_IMAGE, $attachment_id );
657 - }
658 - }
659 460 $lib = $this->load_chart_type( $chart_id );
660 461
661 462 // the alpha color picker (RGBA) is not supported by google.
662 463 $color_picker_dep = 'wp-color-picker';
@@ -669,9 +470,9 @@
669 470 wp_register_script( 'visualizer-chosen', VISUALIZER_ABSURL . 'js/lib/chosen.jquery.min.js', array( 'jquery' ), Visualizer_Plugin::VERSION );
670 471 wp_register_style( 'visualizer-chosen', VISUALIZER_ABSURL . 'css/lib/chosen.min.css', array(), Visualizer_Plugin::VERSION );
671 472
672 473 wp_register_style( 'visualizer-frame', VISUALIZER_ABSURL . 'css/frame.css', array( 'visualizer-chosen' ), Visualizer_Plugin::VERSION );
673 - wp_register_script( 'visualizer-frame', VISUALIZER_ABSURL . 'js/frame.js', array( 'visualizer-chosen', 'jquery-ui-accordion', 'jquery-ui-tabs' ), Visualizer_Plugin::VERSION, true );
474 + wp_register_script( 'visualizer-frame', VISUALIZER_ABSURL . 'js/frame.js', array( 'visualizer-chosen', 'jquery-ui-accordion' ), Visualizer_Plugin::VERSION, true );
674 475 wp_register_script( 'visualizer-customization', $this->get_user_customization_js(), array(), null, true );
675 476 wp_register_script(
676 477 'visualizer-render',
677 478 VISUALIZER_ABSURL . 'js/render-facade.js',
@@ -710,9 +511,8 @@
710 511 if ( isset( $_POST['cancel'] ) && 1 === intval( $_POST['cancel'] ) ) {
711 512 // if the cancel button is clicked.
712 513 $this->undoRevisions( $chart_id, true );
713 514 } elseif ( isset( $_POST['save'] ) && 1 === intval( $_POST['save'] ) ) {
714 - $this->handlePermissions();
715 515 // if the save button is clicked.
716 516 $this->undoRevisions( $chart_id, false );
717 517 } else {
718 518 // if the edit button is clicked.
@@ -718,16 +518,8 @@
718 518 // if the edit button is clicked.
719 519 $this->_chart = $this->handleExistingRevisions( $chart_id, $this->_chart );
720 520 }
721 521
722 - // Clear existing chart cache.
723 - if ( isset( $_POST['save'] ) && 1 === intval( $_POST['save'] ) ) {
724 - $cache_key = Visualizer_Plugin::CF_CHART_CACHE . '_' . $chart_id;
725 - if ( get_transient( $cache_key ) ) {
726 - delete_transient( $cache_key );
727 - }
728 - }
729 -
730 522 switch ( $tab ) {
731 523 case 'settings':
732 524 $this->_handleDataAndSettingsPage();
733 525 break;
@@ -735,18 +527,18 @@
735 527 case 'visualizer': // fall through.
736 528 $this->_handleTypesPage();
737 529 break;
738 530 default:
739 - // this should never happen.
531 + do_action( 'visualizer_pro_handle_tab', $tab, $this->_chart );
740 532 break;
741 533 }
742 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
534 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
743 535 }
744 536
745 537 /**
746 538 * Load code editor assets.
747 539 */
748 - private function loadCodeEditorAssets( $chart_id ) {
540 + private function loadCodeEditorAssets() {
749 541 global $wp_version;
750 542
751 543 $wp_scripts = wp_scripts();
752 544
@@ -752,9 +544,9 @@
752 544
753 545 // data tables assets.
754 546 wp_register_script( 'visualizer-datatables', VISUALIZER_ABSURL . 'js/lib/datatables.min.js', array( 'jquery-ui-core' ), Visualizer_Plugin::VERSION );
755 547 wp_register_style( 'visualizer-datatables', VISUALIZER_ABSURL . 'css/lib/datatables.min.css', array(), Visualizer_Plugin::VERSION );
756 - wp_register_style( 'visualizer-jquery-ui', sprintf( '//code.jquery.com/ui/%s/themes/smoothness/jquery-ui.css', $wp_scripts->registered['jquery-ui-core']->ver ), array( 'visualizer-datatables' ), Visualizer_Plugin::VERSION );
548 + wp_register_style( 'visualizer-jquery-ui', sprintf( '//ajax.googleapis.com/ajax/libs/jqueryui/%s/themes/smoothness/jquery-ui.css', $wp_scripts->registered['jquery-ui-core']->ver ), array( 'visualizer-datatables' ), Visualizer_Plugin::VERSION );
757 549 wp_enqueue_script( 'visualizer-datatables' );
758 550 wp_enqueue_style( 'visualizer-jquery-ui' );
759 551
760 552 if ( ! Visualizer_Module::is_pro() ) {
@@ -760,9 +552,9 @@
760 552 if ( ! Visualizer_Module::is_pro() ) {
761 553 return;
762 554 }
763 555
764 - $table_col_mapping = Visualizer_Source_Query_Params::get_all_db_tables_column_mapping( $chart_id );
556 + $table_col_mapping = Visualizer_Source_Query_Params::get_all_db_tables_column_mapping();
765 557
766 558 if ( version_compare( $wp_version, '4.9.0', '<' ) ) {
767 559 // code mirror assets.
768 560 wp_register_script( 'visualizer-codemirror-core', '//codemirror.net/lib/codemirror.js', array( 'jquery' ), Visualizer_Plugin::VERSION );
@@ -770,9 +562,9 @@
770 562 wp_register_script( 'visualizer-codemirror-matchbrackets', '//codemirror.net/addon/edit/matchbrackets.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
771 563 wp_register_script( 'visualizer-codemirror-closebrackets', '//codemirror.net/addon/edit/closebrackets.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
772 564 wp_register_script( 'visualizer-codemirror-sql', '//codemirror.net/mode/sql/sql.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
773 565 wp_register_script( 'visualizer-codemirror-sql-hint', '//codemirror.net/addon/hint/sql-hint.js', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
774 - wp_register_script( 'visualizer-codemirror-hint', '//codemirror.net/addon/hint/show-hint.js', array( 'visualizer-codemirror-sql', 'visualizer-codemirror-sql-hint', 'visualizer-codemirror-placeholder', 'visualizer-codemirror-matchbrackets', 'visualizer-codemirror-closebrackets' ), Visualizer_Plugin::VERSION );
566 + wp_register_script( 'visualizer-codemirror-hint', '//codemirror.net/addon/hint/show-hint.js', array( 'visualizer-codemirror-sql', 'visualizer-codemirror-sql-hint', 'visualizer-codemirror-placeholder', 'visualizer-codemirror-matchbrackets', 'visualizer-codemirror-closebrackets' ), Visualizer_Plugin::VERSION );
775 567 wp_register_style( 'visualizer-codemirror-core', '//codemirror.net/lib/codemirror.css', array(), Visualizer_Plugin::VERSION );
776 568 wp_register_style( 'visualizer-codemirror-hint', '//codemirror.net/addon/hint/show-hint.css', array( 'visualizer-codemirror-core' ), Visualizer_Plugin::VERSION );
777 569
778 570 wp_enqueue_script( 'visualizer-codemirror-hint' );
@@ -786,9 +578,9 @@
786 578 'lineWrapping' => true,
787 579 'dragDrop' => false,
788 580 'matchBrackets' => true,
789 581 'autoCloseBrackets' => true,
790 - 'extraKeys' => array( 'Shift-Space' => 'autocomplete' ),
582 + 'extraKeys' => array( 'Ctrl-Space' => 'autocomplete' ),
791 583 'hintOptions' => array( 'tables' => $table_col_mapping ),
792 584 ),
793 585 )
794 586 );
@@ -797,54 +589,26 @@
797 589 return $table_col_mapping;
798 590 }
799 591
800 592 /**
801 - * Handle permissions from the new conslidated settings sidebar.
802 - */
803 - private function handlePermissions() {
804 - if ( ! Visualizer_Module::is_pro() ) {
805 - return;
806 - }
807 -
808 - // we will not support old free and new pro.
809 - // handling new free and old pro.
810 - if ( has_action( 'visualizer_pro_handle_tab' ) ) {
811 - do_action( 'visualizer_pro_handle_tab', 'permissions', $this->_chart );
812 - } else {
813 - do_action( 'visualizer_handle_permissions', $this->_chart );
814 - }
815 - }
816 -
817 - /**
818 593 * Handle data and settings page
819 594 */
820 595 private function _handleDataAndSettingsPage() {
596 + if ( isset( $_POST['map_api_key'] ) ) {
597 + update_option( 'visualizer-map-api-key', $_POST['map_api_key'] );
598 + }
821 599 if ( $_SERVER['REQUEST_METHOD'] === 'POST' && isset( $_GET['nonce'] ) && wp_verify_nonce( $_GET['nonce'] ) ) {
822 - $is_canceled = isset( $_POST['cancel'] ) && 1 === intval( $_POST['cancel'] );
823 - $is_newly_created = $this->_chart->post_status === 'auto-draft';
824 -
825 - if ( isset( $_POST['map_api_key'] ) && current_user_can( 'manage_options' ) ) {
826 - update_option( 'visualizer-map-api-key', sanitize_text_field( wp_unslash( $_POST['map_api_key'] ) ) );
827 - }
828 -
829 - if ( $is_newly_created && ! $is_canceled ) {
600 + if ( $this->_chart->post_status === 'auto-draft' ) {
830 601 $this->_chart->post_status = 'publish';
831 602
832 603 // ensure that a revision is not created. If a revision is created it will have the proper data and the parent of the revision will have default data.
833 604 // we do not want any difference in data so disable revisions temporarily.
834 - $this->disableRevisionsTemporarily();
835 -
605 + add_filter( 'wp_revisions_to_keep', '__return_false' );
836 606 wp_update_post( $this->_chart->to_array() );
837 607 }
838 608 // save meta data only when it is NOT being canceled.
839 - if ( ! $is_canceled ) {
840 - $post_settings = $_POST;
841 - $existing = get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
842 - if ( isset( $existing['colors'] ) && is_array( $existing['colors'] ) && ! isset( $post_settings['colors'] ) ) {
843 - $post_settings['colors'] = $existing['colors'];
844 - }
845 - $post_settings = $this->sanitizeSettings( $post_settings );
846 - update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, $post_settings );
609 + if ( ! ( isset( $_POST['cancel'] ) && 1 === intval( $_POST['cancel'] ) ) ) {
610 + update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, $_POST );
847 611
848 612 // we will keep a parameter called 'internal_title' that will be set to the given title or, if empty, the chart ID
849 613 // this will help in searching with the chart id.
850 614 $settings = get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
@@ -858,19 +622,14 @@
858 622 if ( empty( $title ) ) {
859 623 $title = $this->_chart->ID;
860 624 }
861 625 $settings['internal_title'] = $title;
862 - $settings_label = isset( $settings['pieResidueSliceLabel'] ) ? $settings['pieResidueSliceLabel'] : '';
863 - if ( empty( $settings_label ) ) {
864 - $settings['pieResidueSliceLabel'] = esc_html__( 'Other', 'visualizer' );
865 - } else {
866 - $settings['pieResidueSliceLabel'] = $settings_label;
867 - }
868 626 update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SETTINGS, $settings );
869 627 }
870 628 $render = new Visualizer_Render_Page_Send();
871 629 $render->text = sprintf( '[visualizer id="%d"]', $this->_chart->ID );
872 630 wp_iframe( array( $render, 'render' ) );
631 +
873 632 return;
874 633 }
875 634 $data = $this->_getChartArray();
876 635 $sidebar = '';
@@ -891,11 +650,10 @@
891 650 wp_enqueue_style( 'visualizer-frame' );
892 651 wp_enqueue_script( 'visualizer-preview' );
893 652 wp_enqueue_script( 'visualizer-chosen' );
894 653 wp_enqueue_script( 'visualizer-render' );
895 - wp_enqueue_code_editor( array( 'type' => 'application/json' ) );
896 654
897 - if ( Visualizer_Module::can_show_feature( 'simple-editor' ) ) {
655 + if ( ! Visualizer_Module::is_pro() ) {
898 656 wp_enqueue_script( 'visualizer-editor-simple' );
899 657 wp_localize_script(
900 658 'visualizer-editor-simple',
901 659 'visualizer1',
@@ -901,16 +659,18 @@
901 659 'visualizer1',
902 660 array(
903 661 'ajax' => array(
904 662 'url' => admin_url( 'admin-ajax.php' ),
905 - 'nonces' => array(),
906 - 'actions' => array(),
663 + 'nonces' => array(
664 + ),
665 + 'actions' => array(
666 + ),
907 667 ),
908 668 )
909 669 );
910 670 }
911 671
912 - $table_col_mapping = $this->loadCodeEditorAssets( $this->_chart->ID );
672 + $table_col_mapping = $this->loadCodeEditorAssets();
913 673
914 674 wp_localize_script(
915 675 'visualizer-render',
916 676 'visualizer',
@@ -915,15 +675,11 @@
915 675 'visualizer-render',
916 676 'visualizer',
917 677 array(
918 678 'l10n' => array(
919 - 'invalid_source' => esc_html__( 'The URL you entered is invalid. Please enter a valid URL.', 'visualizer' ),
920 - 'loading' => esc_html__( 'Loading...', 'visualizer' ),
921 - 'json_error' => esc_html__( 'An error occured in fetching data.', 'visualizer' ),
922 - 'select_columns' => esc_html__( 'Please select a few columns to include in the chart.', 'visualizer' ),
923 - 'save_settings' => __( 'You have modified the chart\'s settings. To modify the source/data again, you must save this chart and reopen it for editing. If you continue without saving the chart, you may lose your changes.', 'visualizer' ),
924 - 'copied' => __( 'The data has been copied to your clipboard. Hit Ctrl-V/Cmd-V in your spreadsheet editor to paste the data.', 'visualizer' ),
925 - 'invalid_format' => esc_html__( 'This format pattern is not supported in the series settings field. Use the Manual Configuration option instead.', 'visualizer' ),
679 + 'invalid_source' => esc_html__( 'You have entered invalid URL. Please, insert proper URL.', 'visualizer' ),
680 + 'loading' => esc_html__( 'Loading...', 'visualizer' ),
681 + 'json_error' => esc_html__( 'An error occured in fetching data.', 'visualizer' ),
926 682 ),
927 683 'charts' => array(
928 684 'canvas' => $data,
929 685 'id' => $this->_chart->ID,
@@ -954,9 +710,8 @@
954 710 'page_type' => 'chart',
955 711 'json_tag_separator' => Visualizer_Source_Json::TAG_SEPARATOR,
956 712 'json_tag_separator_view' => Visualizer_Source_Json::TAG_SEPARATOR_VIEW,
957 713 'is_front' => false,
958 - 'rest_base' => get_rest_url( null, 'wc/v3/reports/' ),
959 714 )
960 715 );
961 716
962 717 $render = new Visualizer_Render_Page_Data();
@@ -967,19 +722,20 @@
967 722 if ( filter_input( INPUT_GET, 'library', FILTER_VALIDATE_BOOLEAN ) ) {
968 723 $render->button = filter_input( INPUT_GET, 'action' ) === Visualizer_Plugin::ACTION_EDIT_CHART
969 724 ? esc_html__( 'Save Chart', 'visualizer' )
970 725 : esc_html__( 'Create Chart', 'visualizer' );
971 -
972 - $render->cancel_button = esc_html__( 'Cancel', 'visualizer' );
726 + if ( filter_input( INPUT_GET, 'action' ) === Visualizer_Plugin::ACTION_EDIT_CHART ) {
727 + $render->cancel_button = esc_html__( 'Cancel', 'visualizer' );
728 + }
973 729 } else {
974 730 $render->button = esc_attr__( 'Insert Chart', 'visualizer' );
975 731 }
976 732
977 - do_action( 'visualizer_enqueue_scripts_and_styles', $data, $this->_chart->ID );
733 + do_action( 'visualizer_enqueue_scripts_and_styles', $data );
978 734
979 735 if ( Visualizer_Module::is_pro() && Visualizer_Module::is_pro_older_than( '1.9.0' ) ) {
980 736 global $Visualizer_Pro;
981 - $Visualizer_Pro->_enqueueScriptsAndStyles( $data, $this->_chart->ID );
737 + $Visualizer_Pro->_enqueueScriptsAndStyles( $data );
982 738 }
983 739
984 740 $this->_addAction( 'admin_head', 'renderFlattrScript' );
985 741 wp_iframe( array( $render, 'render' ) );
@@ -993,12 +749,12 @@
993 749 * @access private
994 750 */
995 751 private function _handleTypesPage() {
996 752 // process post request
997 - if ( $_SERVER['REQUEST_METHOD'] === 'POST' && wp_verify_nonce( filter_input( INPUT_POST, 'nonce' ), 'visualizer-upload-data' ) ) {
753 + if ( $_SERVER['REQUEST_METHOD'] === 'POST' && wp_verify_nonce( filter_input( INPUT_POST, 'nonce' ) ) ) {
998 754 $type = filter_input( INPUT_POST, 'type' );
999 755 $library = filter_input( INPUT_POST, 'chart-library' );
1000 - if ( Visualizer_Module_Admin::checkChartStatus( $type ) ) {
756 + if ( in_array( $type, Visualizer_Plugin::getChartTypes(), true ) ) {
1001 757 if ( empty( $library ) ) {
1002 758 // library cannot be empty.
1003 759 do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, 'Chart library empty while creating the chart! Aborting...', 'error', __FILE__, __LINE__ );
1004 760 return;
@@ -1010,9 +766,9 @@
1010 766 // if the chart has default data, update it with appropriate default data for new type
1011 767 if ( filter_var( get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_DEFAULT_DATA, true ), FILTER_VALIDATE_BOOLEAN ) ) {
1012 768 $source = new Visualizer_Source_Csv( VISUALIZER_ABSPATH . DIRECTORY_SEPARATOR . 'samples' . DIRECTORY_SEPARATOR . $type . '.csv' );
1013 769 $source->fetch();
1014 - $this->_chart->post_content = $source->getData( get_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) );
770 + $this->_chart->post_content = $source->getData();
1015 771 wp_update_post( $this->_chart->to_array() );
1016 772 update_post_meta( $this->_chart->ID, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
1017 773 }
1018 774
@@ -1019,9 +775,9 @@
1019 775 Visualizer_Module_Utility::set_defaults( $this->_chart );
1020 776
1021 777 // redirect to next tab
1022 778 // changed by Ash/Upwork
1023 - wp_redirect( esc_url_raw( add_query_arg( 'tab', 'settings' ) ) );
779 + wp_redirect( add_query_arg( 'tab', 'settings' ) );
1024 780
1025 781 return;
1026 782 }
1027 783 }
@@ -1034,35 +790,8 @@
1034 790 wp_iframe( array( $render, 'render' ) );
1035 791 }
1036 792
1037 793 /**
1038 - * Sanitize settings data from the request.
1039 - *
1040 - * @param array<string, mixed> $post_data The POST data to sanitize.
1041 - * @return array<string, mixed> The sanitized settings data.
1042 - */
1043 - private function sanitizeSettings( $post_data ): array {
1044 - $chart_img = '';
1045 - if ( isset( $post_data['chart-img'] ) ) {
1046 - $chart_img = wp_unslash( $post_data['chart-img'] );
1047 - unset( $post_data['chart-img'] );
1048 - }
1049 -
1050 - $post_data = map_deep(
1051 - $post_data,
1052 - 'sanitize_textarea_field'
1053 - );
1054 -
1055 - // The value is a client-side canvas export; keep it only when it is a
1056 - // base64 image data URI so nothing else is ever stored unsanitized.
1057 - if ( is_string( $chart_img ) && preg_match( '#^data:image/(png|jpeg|webp);base64,[A-Za-z0-9+/ ]+=*$#', $chart_img ) ) {
1058 - $post_data['chart-img'] = $chart_img;
1059 - }
1060 -
1061 - return $post_data;
1062 - }
1063 -
1064 - /**
1065 794 * Renders flattr script in the iframe <head>
1066 795 *
1067 796 * @since 1.4.2
1068 797 * @action admin_head
@@ -1077,124 +806,30 @@
1077 806 * Processes the CSV that is sent in the request as a string.
1078 807 *
1079 808 * @since 3.2.0
1080 809 */
1081 - /**
1082 - * Determines whether a remote URL serves an XLSX file.
1083 - *
1084 - * Used as a fallback when the URL path has no recognisable file extension
1085 - * (e.g. SharePoint, signed S3 URLs, or "download?id=…" endpoints).
1086 - *
1087 - * Uses the shared remote-fetch policy to block non-public destinations,
1088 - * and streams the response to a temp file so no body data is held in memory
1089 - * regardless of whether the server honours the Range header.
1090 - *
1091 - * The check relies on the ZIP magic number (PK\x03\x04) that every XLSX
1092 - * file begins with, making it immune to misleading Content-Type headers
1093 - * such as application/octet-stream. Content-Type is used as a last-resort
1094 - * fallback only when the temp file is empty (e.g. a HEAD-only server).
1095 - *
1096 - * @access private
1097 - * @param string $url The remote URL to probe.
1098 - * @return bool TRUE if the file appears to be XLSX, FALSE otherwise.
1099 - */
1100 - private static function _url_is_xlsx( $url ) {
1101 - $tmpfile = wp_tempnam( 'visualizer_xlsx_probe' );
1102 - if ( ! $tmpfile ) {
1103 - return false;
1104 - }
1105 -
1106 - $response = Visualizer_Remote_Fetch::request(
1107 - $url,
1108 - array(
1109 - 'timeout' => 10,
1110 - 'user-agent' => 'WordPress/' . get_bloginfo( 'version' ),
1111 - 'headers' => array( 'Range' => 'bytes=0-3' ),
1112 - 'stream' => true,
1113 - 'filename' => $tmpfile,
1114 - 'limit_response_size' => 4,
1115 - )
1116 - );
1117 -
1118 - if ( is_wp_error( $response ) ) {
1119 - @unlink( $tmpfile ); // phpcs:ignore WordPress.PHP.NoSilencedErrors
1120 - return false;
1121 - }
1122 -
1123 - $magic = '';
1124 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fopen
1125 - $fh = @fopen( $tmpfile, 'rb' ); // phpcs:ignore WordPress.PHP.NoSilencedErrors
1126 - if ( $fh ) {
1127 - $magic = fread( $fh, 4 ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fread
1128 - fclose( $fh ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fclose
1129 - }
1130 - @unlink( $tmpfile ); // phpcs:ignore WordPress.PHP.NoSilencedErrors
1131 -
1132 - if ( strlen( $magic ) >= 4 ) {
1133 - // XLSX (and all ZIP-based Office formats) start with PK\x03\x04.
1134 - return $magic === "PK\x03\x04";
1135 - }
1136 -
1137 - // Last resort: server returned an empty body (e.g. ignored Range and
1138 - // returned only headers). Check Content-Type from the same response.
1139 - // application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
1140 - return false !== strpos(
1141 - wp_remote_retrieve_header( $response, 'content-type' ),
1142 - 'spreadsheetml'
1143 - );
1144 - }
1145 -
1146 - /**
1147 - * Parses a raw CSV string or editor payload and returns a source object.
1148 - *
1149 - * @access private
1150 - * @param string $data The raw CSV data string.
1151 - * @param string $editor_type The editor type ('text' or 'tabular').
1152 - * @return Visualizer_Source|null The populated source object, or null on failure.
1153 - */
1154 - private function handleCSVasString( $data, $editor_type ) {
810 + private function handleCSVasString( $data ) {
1155 811 $source = null;
1156 812
1157 - switch ( $editor_type ) {
1158 - case 'text':
1159 - // data coming in from the text editor.
1160 - $tmpfile = tempnam( get_temp_dir(), Visualizer_Plugin::NAME );
1161 - $handle = fopen( $tmpfile, 'w' );
1162 - $values = preg_split( '/[\n\r]+/', stripslashes( trim( $data ) ) );
1163 - if ( $values ) {
1164 - foreach ( $values as $row ) {
1165 - if ( empty( $row ) ) {
1166 - continue;
1167 - }
1168 - $row = explode( ',', $row );
1169 - $row = array_map(
1170 - function ( $r ) {
1171 - return '' === $r ? ' ' : $r;
1172 - },
1173 - $row
1174 - );
1175 - $row = implode( ',', $row );
1176 - // don't use fpucsv here because we need to just dump the data
1177 - // minus the empty rows
1178 - // because fputcsv needs to tokenize
1179 - // we can standardize the CSV enclosure here and replace all ' with "
1180 - // we can assume that if there are an even number of ' they should be changed to "
1181 - // but that will screw up words like fo'c'sle
1182 - // so here let's just assume ' will NOT be used for enclosures
1183 - fwrite( $handle, $row );
1184 - fwrite( $handle, PHP_EOL );
813 + // @issue https://github.com/Codeinwp/visualizer/issues/412
814 + if ( has_filter( 'visualizer_pro_handle_chart_data' ) ) {
815 + $source = apply_filters( 'visualizer_pro_handle_chart_data', $data, '' );
816 + } else {
817 + // data coming in from the text editor.
818 + $tmpfile = tempnam( get_temp_dir(), Visualizer_Plugin::NAME );
819 + $handle = fopen( $tmpfile, 'w' );
820 + $values = preg_split( '/[\n\r]+/', stripslashes( trim( $data ) ) );
821 + if ( $values ) {
822 + foreach ( $values as $row ) {
823 + if ( empty( $row ) ) {
824 + continue;
1185 825 }
826 + $columns = explode( ',', $row );
827 + fputcsv( $handle, $columns );
1186 828 }
1187 - $source = new Visualizer_Source_Csv( $tmpfile );
1188 - fclose( $handle );
1189 - break;
1190 - case 'table':
1191 - // Import from Chart
1192 - // fall-through.
1193 - case 'excel':
1194 - // data coming in from the excel editor.
1195 - $source = apply_filters( 'visualizer_pro_handle_chart_data', $data, '' );
1196 - break;
829 + }
830 + $source = new Visualizer_Source_Csv( $tmpfile );
831 + fclose( $handle );
1197 832 }
1198 833 return $source;
1199 834 }
1200 835
@@ -1217,9 +852,9 @@
1217 852 foreach ( $types as $type ) {
1218 853 if ( empty( $type ) ) {
1219 854 $exclude[] = $index;
1220 855 }
1221 - ++$index;
856 + $index++;
1222 857 }
1223 858
1224 859 // when N headers are being renamed, the number of headers increases by N
1225 860 // because of the way datatable duplicates header information
@@ -1243,9 +878,9 @@
1243 878 $csv[] = $types;
1244 879 for ( $j = 0; $j < count( $columns[0] ); $j++ ) {
1245 880 $row = array();
1246 881 for ( $i = 0; $i < count( $headers ); $i++ ) {
1247 - $row[] = sanitize_text_field( $columns[ $i ][ $j ] );
882 + $row[] = $columns[ $i ][ $j ];
1248 883 }
1249 884 $csv[] = $row;
1250 885 }
1251 886
@@ -1277,16 +912,11 @@
1277 912 public function uploadData() {
1278 913 // if this is being called internally from pro and VISUALIZER_DO_NOT_DIE is set.
1279 914 // otherwise, assume this is a normal web request.
1280 915 $can_die = ! ( defined( 'VISUALIZER_DO_NOT_DIE' ) && VISUALIZER_DO_NOT_DIE );
1281 - // $can_die also gates the capability checks below, so VISUALIZER_DO_NOT_DIE must stay internal-only (never set from request input or globally).
1282 916
1283 - // validate nonce; capability check applies to web requests only, not trusted internal calls.
1284 - if (
1285 - ! isset( $_GET['nonce'] ) ||
1286 - ! wp_verify_nonce( $_GET['nonce'], 'visualizer-upload-data' ) ||
1287 - ( $can_die && ! current_user_can( 'edit_posts' ) )
1288 - ) {
917 + // validate nonce
918 + if ( ! isset( $_GET['nonce'] ) || ! wp_verify_nonce( $_GET['nonce'] ) ) {
1289 919 if ( ! $can_die ) {
1290 920 return;
1291 921 }
1292 922 status_header( 403 );
@@ -1295,15 +925,9 @@
1295 925
1296 926 // check chart, if chart exists
1297 927 // do not use filter_input as it does not work for phpunit test cases, use filter_var instead
1298 928 $chart_id = isset( $_GET['chart'] ) ? filter_var( $_GET['chart'], FILTER_VALIDATE_INT ) : '';
1299 - $chart = $chart_id ? get_post( $chart_id ) : null;
1300 - if (
1301 - ! $chart_id ||
1302 - ! $chart ||
1303 - $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ||
1304 - ( $can_die && ! current_user_can( 'edit_post', $chart_id ) )
1305 - ) {
929 + if ( ! $chart_id || ! ( $chart = get_post( $chart_id ) ) || $chart->post_type !== Visualizer_Plugin::CPT_VISUALIZER ) {
1306 930 if ( ! $can_die ) {
1307 931 return;
1308 932 }
1309 933 status_header( 400 );
@@ -1309,10 +933,8 @@
1309 933 status_header( 400 );
1310 934 exit;
1311 935 }
1312 936
1313 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Uploading data for chart %d with POST = %s and GET = %s', $chart_id, print_r( $_POST, true ), print_r( $_GET, true ) ), 'debug', __FILE__, __LINE__ );
1314 -
1315 937 if ( ! isset( $_POST['vz-import-time'] ) ) {
1316 938 apply_filters( 'visualizer_pro_remove_schedule', $chart_id );
1317 939 }
1318 940
@@ -1324,9 +946,8 @@
1324 946
1325 947 // delete "import from db" specific parameters.
1326 948 delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY );
1327 949 delete_post_meta( $chart_id, Visualizer_Plugin::CF_DB_SCHEDULE );
1328 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_REMOTE_DB_PARAMS );
1329 950 }
1330 951
1331 952 // delete json related data.
1332 953 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_URL );
@@ -1331,68 +952,36 @@
1331 952 // delete json related data.
1332 953 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_URL );
1333 954 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_ROOT );
1334 955 delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_PAGING );
1335 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_JSON_HEADERS );
1336 956
1337 - // delete last error
1338 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR );
1339 -
1340 - // delete editor related data.
1341 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_EDITOR );
1342 -
1343 - // delete this so that a JSON import can be later edited manually without a problem.
1344 - delete_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE );
1345 -
1346 957 $source = null;
1347 958 $render = new Visualizer_Render_Page_Update();
1348 -
1349 - $remote_data = false;
1350 - if ( isset( $_POST['remote_data'] ) && function_exists( 'wp_http_validate_url' ) ) {
1351 - $remote_data = wp_http_validate_url( $_POST['remote_data'] );
1352 - }
1353 - if ( false !== $remote_data ) {
1354 - $remote_ext = strtolower( pathinfo( parse_url( $remote_data, PHP_URL_PATH ), PATHINFO_EXTENSION ) );
1355 - if ( 'xlsx' === $remote_ext || ( 'csv' !== $remote_ext && self::_url_is_xlsx( $remote_data ) ) ) {
1356 - $source = new Visualizer_Source_Xlsx_Remote( $remote_data );
1357 - } else {
1358 - $source = new Visualizer_Source_Csv_Remote( $remote_data );
1359 - }
959 + if ( isset( $_POST['remote_data'] ) && filter_var( $_POST['remote_data'], FILTER_VALIDATE_URL ) ) {
960 + $source = new Visualizer_Source_Csv_Remote( $_POST['remote_data'] );
1360 961 if ( isset( $_POST['vz-import-time'] ) ) {
1361 - apply_filters( 'visualizer_pro_chart_schedule', $chart_id, $remote_data, $_POST['vz-import-time'] );
962 + apply_filters( 'visualizer_pro_chart_schedule', $chart_id, $_POST['remote_data'], $_POST['vz-import-time'] );
1362 963 }
1363 - } elseif ( isset( $_FILES['local_data'] ) && $_FILES['local_data']['error'] === 0 ) {
1364 - $local_ext = strtolower( pathinfo( isset( $_FILES['local_data']['name'] ) ? $_FILES['local_data']['name'] : '', PATHINFO_EXTENSION ) );
1365 - if ( 'xlsx' === $local_ext ) {
1366 - $source = new Visualizer_Source_Xlsx( $_FILES['local_data']['tmp_name'] );
1367 - } else {
1368 - $source = new Visualizer_Source_Csv( $_FILES['local_data']['tmp_name'] );
1369 - }
964 + // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison
965 + } elseif ( isset( $_FILES['local_data'] ) && $_FILES['local_data']['error'] == 0 ) {
966 + $source = new Visualizer_Source_Csv( $_FILES['local_data']['tmp_name'] );
1370 967 } elseif ( isset( $_POST['chart_data'] ) && strlen( $_POST['chart_data'] ) > 0 ) {
1371 - $source = $this->handleCSVasString( $_POST['chart_data'], $_POST['editor-type'] );
1372 - update_post_meta( $chart_id, Visualizer_Plugin::CF_EDITOR, $_POST['editor-type'] );
968 + $source = $this->handleCSVasString( $_POST['chart_data'] );
1373 969 } elseif ( isset( $_POST['table_data'] ) && 'yes' === $_POST['table_data'] ) {
1374 970 $source = $this->handleTabularData();
1375 - update_post_meta( $chart_id, Visualizer_Plugin::CF_EDITOR, $_POST['editor-type'] );
1376 971 } else {
1377 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'CSV file with chart data was not uploaded for chart %d.', $chart_id ), 'error', __FILE__, __LINE__ );
1378 - $render->message = esc_html__( 'No CSV file was received. Select a file and try uploading again.', 'visualizer' );
1379 - update_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR, esc_html__( 'No CSV file was received. Select a file and try uploading again.', 'visualizer' ) );
972 + $render->message = esc_html__( 'CSV file with chart data was not uploaded. Please try again.', 'visualizer' );
1380 973 }
1381 -
1382 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Uploaded data for chart %d with source %s', $chart_id, print_r( $source, true ) ), 'debug', __FILE__, __LINE__ );
1383 -
1384 974 if ( $source ) {
1385 975 if ( $source->fetch() ) {
1386 - $content = $source->getData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) );
976 + $content = $source->getData();
1387 977 $populate = true;
1388 - $json = self::decode_content( $content );
1389 - if ( is_array( $json ) ) {
978 + if ( is_string( $content ) && is_array( unserialize( $content ) ) ) {
979 + $json = unserialize( $content );
1390 980 // if source exists, so should data. if source exists but data is blank, do not populate the chart.
1391 981 // if we populate the data even if it is empty, the chart will show "Table has no columns".
1392 982 if ( array_key_exists( 'source', $json ) && ! empty( $json['source'] ) && ( ! array_key_exists( 'data', $json ) || empty( $json['data'] ) ) ) {
1393 983 do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Not populating chart data as source exists (%s) but data is empty!', $json['source'] ), 'warn', __FILE__, __LINE__ );
1394 - update_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR, sprintf( 'Not populating chart data as source exists (%s) but data is empty!', $json['source'] ) );
1395 984 $populate = false;
1396 985 }
1397 986 }
1398 987 if ( $populate ) {
@@ -1398,49 +987,32 @@
1398 987 if ( $populate ) {
1399 988 $chart->post_content = $content;
1400 989 }
1401 990 wp_update_post( $chart->to_array() );
1402 -
1403 991 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
1404 992 update_post_meta( $chart->ID, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
1405 993 update_post_meta( $chart->ID, Visualizer_Plugin::CF_DEFAULT_DATA, 0 );
1406 994
1407 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Updated post for chart %d', $chart_id ), 'debug', __FILE__, __LINE__ );
1408 -
1409 995 Visualizer_Module_Utility::set_defaults( $chart, null );
1410 996
1411 997 $settings = get_post_meta( $chart->ID, Visualizer_Plugin::CF_SETTINGS, true );
1412 - if ( isset( $settings['series'] ) && ! ( count( $settings['series'] ) - count( $source->getSeries() ) > 1 ) ) {
1413 - $diff_total_series = abs( count( $settings['series'] ) - count( $source->getSeries() ) );
1414 - if ( $diff_total_series ) {
1415 - foreach ( range( 1, $diff_total_series ) as $k => $diff_series ) {
1416 - $settings['series'][] = end( $settings['series'] );
1417 - }
1418 - update_post_meta( $chart->ID, Visualizer_Plugin::CF_SETTINGS, $settings );
1419 - }
1420 - }
1421 998
1422 999 $render->id = $chart->ID;
1423 - $render->data = json_encode( $source->getRawData( get_post_meta( $chart->ID, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ) );
1000 + $render->data = json_encode( $source->getRawData() );
1424 1001 $render->series = json_encode( $source->getSeries() );
1425 1002 $render->settings = json_encode( $settings );
1426 1003 } else {
1427 - $error = $source->get_error();
1428 - if ( empty( $error ) ) {
1429 - $error = esc_html__( 'The CSV file couldn\'t be read. Check that it\'s properly formatted and try again.', 'visualizer' );
1004 + $render->message = $source->get_error();
1005 + if ( empty( $render->message ) ) {
1006 + $render->message = esc_html__( 'CSV file is broken or invalid. Please try again.', 'visualizer' );
1430 1007 }
1431 - $render->message = $error;
1432 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( '%s for chart %d.', $error, $chart_id ), 'error', __FILE__, __LINE__ );
1433 - update_post_meta( $chart_id, Visualizer_Plugin::CF_ERROR, $error );
1434 1008 }
1435 - } else {
1436 - do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Unknown internal error for chart %d.', $chart_id ), 'error', __FILE__, __LINE__ );
1437 1009 }
1438 1010 $render->render();
1439 1011 if ( ! $can_die ) {
1440 1012 return;
1441 1013 }
1442 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1014 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1443 1015 }
1444 1016
1445 1017 /**
1446 1018 * Clones the chart.
@@ -1451,11 +1023,12 @@
1451 1023 */
1452 1024 public function cloneChart() {
1453 1025 $chart_id = $success = false;
1454 1026 $nonce = isset( $_GET['nonce'] ) && wp_verify_nonce( $_GET['nonce'], Visualizer_Plugin::ACTION_CLONE_CHART );
1455 - if ( $nonce ) {
1027 + $capable = current_user_can( 'edit_posts' );
1028 + if ( $nonce && $capable ) {
1456 1029 $chart_id = isset( $_GET['chart'] ) ? filter_var( $_GET['chart'], FILTER_VALIDATE_INT ) : '';
1457 - if ( $chart_id && self::can_edit_chart( $chart_id ) ) {
1030 + if ( $chart_id ) {
1458 1031 $chart = get_post( $chart_id );
1459 1032 $success = $chart && $chart->post_type === Visualizer_Plugin::CPT_VISUALIZER;
1460 1033 }
1461 1034 }
@@ -1475,29 +1048,26 @@
1475 1048 } else {
1476 1049 $post_meta = get_post_meta( $chart_id );
1477 1050 foreach ( $post_meta as $key => $value ) {
1478 1051 if ( strpos( $key, 'visualizer-' ) !== false ) {
1479 - add_post_meta( $new_chart_id, $key, self::maybe_decode_content( $value[0] ) );
1052 + add_post_meta( $new_chart_id, $key, maybe_unserialize( $value[0] ) );
1480 1053 }
1481 1054 }
1482 - $redirect = esc_url(
1483 - add_query_arg(
1484 - array(
1485 - 'page' => 'visualizer',
1486 - 'type' => filter_input( INPUT_GET, 'type' ),
1487 - 'vaction' => false,
1488 - ),
1489 - admin_url( 'admin.php' )
1055 + $redirect = add_query_arg(
1056 + array(
1057 + 'page' => 'visualizer',
1058 + 'type' => filter_input( INPUT_GET, 'type' ),
1059 + 'vaction' => false,
1490 1060 ),
1491 - null,
1492 - 'db'
1061 + admin_url( 'admin.php' )
1493 1062 );
1494 1063 }
1495 1064 }
1496 1065
1497 - if ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) {
1066 + if ( defined( 'WP_TESTS_DOMAIN' ) ) {
1498 1067 wp_die();
1499 1068 }
1069 +
1500 1070 wp_redirect( $redirect );
1501 1071 exit;
1502 1072 }
1503 1073
@@ -1509,25 +1079,28 @@
1509 1079 * @access public
1510 1080 */
1511 1081 public function exportData() {
1512 1082 check_ajax_referer( Visualizer_Plugin::ACTION_EXPORT_DATA . Visualizer_Plugin::VERSION, 'security' );
1513 - $chart_id = isset( $_GET['chart'] ) ? filter_var(
1514 - $_GET['chart'],
1515 - FILTER_VALIDATE_INT,
1516 - array(
1517 - 'options' => array(
1518 - 'min_range' => 1,
1519 - ),
1520 - )
1521 - ) : '';
1522 - if ( $chart_id && self::can_edit_chart( $chart_id ) ) {
1523 - $data = $this->_getDataAs( $chart_id, 'csv' );
1524 - if ( $data ) {
1525 - echo wp_send_json_success( $data );
1083 + $capable = current_user_can( 'edit_posts' );
1084 + if ( $capable ) {
1085 + $chart_id = isset( $_GET['chart'] ) ? filter_var(
1086 + $_GET['chart'],
1087 + FILTER_VALIDATE_INT,
1088 + array(
1089 + 'options' => array(
1090 + 'min_range' => 1,
1091 + ),
1092 + )
1093 + ) : '';
1094 + if ( $chart_id ) {
1095 + $data = $this->_getDataAs( $chart_id, 'csv' );
1096 + if ( $data ) {
1097 + echo wp_send_json_success( $data );
1098 + }
1526 1099 }
1527 1100 }
1528 1101
1529 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1102 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1530 1103 }
1531 1104
1532 1105 /**
1533 1106 * Handles chart data page.
@@ -1540,12 +1113,9 @@
1540 1113 $data = $this->_getChartArray();
1541 1114 $render = new Visualizer_Render_Page_Data();
1542 1115 $render->chart = $this->_chart;
1543 1116 $render->type = $data['type'];
1544 -
1545 - if ( $data && $data['settings'] ) {
1546 - unset( $data['settings']['width'], $data['settings']['height'], $data['settings']['chartArea'] );
1547 - }
1117 + unset( $data['settings']['width'], $data['settings']['height'], $data['settings']['chartArea'] );
1548 1118 wp_enqueue_style( 'visualizer-frame' );
1549 1119 wp_enqueue_script( 'visualizer-render' );
1550 1120 wp_localize_script(
1551 1121 'visualizer-render',
@@ -1551,11 +1121,10 @@
1551 1121 'visualizer-render',
1552 1122 'visualizer',
1553 1123 array(
1554 1124 'l10n' => array(
1555 - 'invalid_source' => esc_html__( 'The URL you entered is invalid. Please enter a valid URL.', 'visualizer' ),
1556 - 'loading' => esc_html__( 'Loading...', 'visualizer' ),
1557 - 'invalid_format' => esc_html__( 'This format pattern is not supported in the series settings field. To display percentages, use the Manual Configuration option instead.', 'visualizer' ),
1125 + 'invalid_source' => esc_html__( 'You have entered invalid URL. Please, insert proper URL.', 'visualizer' ),
1126 + 'loading' => esc_html__( 'Loading...', 'visualizer' ),
1558 1127 ),
1559 1128 'charts' => array(
1560 1129 'canvas' => $data,
1561 1130 ),
@@ -1561,13 +1130,13 @@
1561 1130 ),
1562 1131 )
1563 1132 );
1564 1133
1565 - do_action( 'visualizer_enqueue_scripts_and_styles', $data, $this->_chart->ID );
1134 + do_action( 'visualizer_enqueue_scripts_and_styles', $data );
1566 1135
1567 1136 if ( Visualizer_Module::is_pro() && Visualizer_Module::is_pro_older_than( '1.9.0' ) ) {
1568 1137 global $Visualizer_Pro;
1569 - $Visualizer_Pro->_enqueueScriptsAndStyles( $data, $this->_chart->ID );
1138 + $Visualizer_Pro->_enqueueScriptsAndStyles( $data );
1570 1139 }
1571 1140
1572 1141 // Added by Ash/Upwork
1573 1142 $this->_addAction( 'admin_head', 'renderFlattrScript' );
@@ -1581,27 +1150,14 @@
1581 1150 */
1582 1151 public function getQueryData() {
1583 1152 check_ajax_referer( Visualizer_Plugin::ACTION_FETCH_DB_DATA . Visualizer_Plugin::VERSION, 'security' );
1584 1153
1585 - if ( ! current_user_can( 'administrator' ) ) {
1586 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1587 - }
1588 - if ( ! is_super_admin() ) {
1589 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1590 - }
1591 -
1592 - if ( ! Visualizer_Module::is_pro() ) {
1593 - wp_send_json_error( array( 'msg' => __( 'Feature is not available.', 'visualizer' ) ) );
1594 - }
1595 -
1596 1154 $params = wp_parse_args( $_POST['params'] );
1597 - $chart_id = filter_var( $params['chart_id'], FILTER_VALIDATE_INT );
1598 - $query = trim( $params['query'], ';' );
1599 -
1600 - $source = new Visualizer_Source_Query( stripslashes( $query ), $chart_id, $params );
1155 + $source = new Visualizer_Source_Query( stripslashes( $params['query'] ) );
1601 1156 $html = $source->fetch( true );
1602 - $error = $source->get_error();
1603 - if ( ! empty( $error ) ) {
1157 + $error = '';
1158 + if ( empty( $html ) ) {
1159 + $error = $source->get_error();
1604 1160 wp_send_json_error( array( 'msg' => $error ) );
1605 1161 }
1606 1162 wp_send_json_success( array( 'table' => $html ) );
1607 1163 }
@@ -1613,19 +1169,8 @@
1613 1169 */
1614 1170 public function saveQuery() {
1615 1171 check_ajax_referer( Visualizer_Plugin::ACTION_SAVE_DB_QUERY . Visualizer_Plugin::VERSION, 'security' );
1616 1172
1617 - if ( ! current_user_can( 'administrator' ) ) {
1618 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1619 - }
1620 - if ( ! is_super_admin() ) {
1621 - wp_send_json_error( array( 'msg' => __( 'Action not allowed for this user.', 'visualizer' ) ) );
1622 - }
1623 -
1624 - if ( ! Visualizer_Module::is_pro() ) {
1625 - wp_send_json_error( array( 'msg' => __( 'Feature is not available.', 'visualizer' ) ) );
1626 - }
1627 -
1628 1173 $chart_id = filter_input(
1629 1174 INPUT_GET,
1630 1175 'chart',
1631 1176 FILTER_VALIDATE_INT,
@@ -1635,43 +1180,21 @@
1635 1180 ),
1636 1181 )
1637 1182 );
1638 1183
1639 - $hours = filter_input(
1640 - INPUT_POST,
1641 - 'refresh',
1642 - FILTER_VALIDATE_FLOAT,
1643 - array(
1644 - 'options' => array(
1645 - 'min_range' => -1,
1646 - 'max_range' => apply_filters( 'visualizer_is_business', false ) ? PHP_INT_MAX : -1,
1647 - ),
1648 - )
1649 - );
1650 -
1651 - if ( ! is_numeric( $hours ) ) {
1652 - $hours = -1;
1653 - }
1654 -
1655 1184 $render = new Visualizer_Render_Page_Update();
1656 1185 if ( $chart_id ) {
1657 1186 $params = wp_parse_args( $_POST['params'] );
1658 - $query = trim( $params['query'], ';' );
1659 - $source = new Visualizer_Source_Query( stripslashes( $query ), $chart_id, $params );
1187 + $source = new Visualizer_Source_Query( stripslashes( $params['query'] ) );
1660 1188 $source->fetch( false );
1661 1189 $error = $source->get_error();
1662 1190 if ( empty( $error ) ) {
1663 - update_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY, stripslashes( $query ) );
1191 + $hours = $_POST['refresh'];
1192 + update_post_meta( $chart_id, Visualizer_Plugin::CF_DB_QUERY, stripslashes( $params['query'] ) );
1664 1193 update_post_meta( $chart_id, Visualizer_Plugin::CF_SOURCE, $source->getSourceName() );
1665 1194 update_post_meta( $chart_id, Visualizer_Plugin::CF_SERIES, $source->getSeries() );
1666 1195 update_post_meta( $chart_id, Visualizer_Plugin::CF_DB_SCHEDULE, $hours );
1667 1196 update_post_meta( $chart_id, Visualizer_Plugin::CF_DEFAULT_DATA, 0 );
1668 - if ( isset( $params['db_type'] ) && $params['db_type'] !== Visualizer_Plugin::WP_DB_NAME ) {
1669 - $remote_db_params = $params;
1670 - unset( $remote_db_params['query'] );
1671 - unset( $remote_db_params['chart_id'] );
1672 - update_post_meta( $chart_id, Visualizer_Plugin::CF_REMOTE_DB_PARAMS, $remote_db_params );
1673 - }
1674 1197
1675 1198 $schedules = get_option( Visualizer_Plugin::CF_DB_SCHEDULE, array() );
1676 1199 $schedules[ $chart_id ] = time() + $hours * HOUR_IN_SECONDS;
1677 1200 update_option( Visualizer_Plugin::CF_DB_SCHEDULE, $schedules );
@@ -1678,14 +1201,13 @@
1678 1201
1679 1202 wp_update_post(
1680 1203 array(
1681 1204 'ID' => $chart_id,
1682 - 'post_content' => $source->getData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ),
1205 + 'post_content' => $source->getData(),
1683 1206 )
1684 1207 );
1685 - $render->data = json_encode( $source->getRawData( get_post_meta( $chart_id, Visualizer_Plugin::CF_EDITABLE_TABLE, true ) ) );
1208 + $render->data = json_encode( $source->getRawData() );
1686 1209 $render->series = json_encode( $source->getSeries() );
1687 - $render->id = $chart_id;
1688 1210 } else {
1689 1211 $render->message = $error;
1690 1212 }
1691 1213 }
@@ -1690,9 +1212,9 @@
1690 1212 }
1691 1213 }
1692 1214 $render->render();
1693 1215 if ( ! ( defined( 'VISUALIZER_DO_NOT_DIE' ) && VISUALIZER_DO_NOT_DIE ) ) {
1694 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1216 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1695 1217 }
1696 1218 }
1697 1219
1698 1220
@@ -1703,10 +1225,11 @@
1703 1225 */
1704 1226 public function saveFilter() {
1705 1227 check_ajax_referer( Visualizer_Plugin::ACTION_SAVE_FILTER_QUERY . Visualizer_Plugin::VERSION, 'security' );
1706 1228
1707 - $chart_id = isset( $_GET['chart'] ) ? filter_var(
1708 - $_GET['chart'],
1229 + $chart_id = filter_input(
1230 + INPUT_GET,
1231 + 'chart',
1709 1232 FILTER_VALIDATE_INT,
1710 1233 array(
1711 1234 'options' => array(
1712 1235 'min_range' => 1,
@@ -1711,90 +1234,15 @@
1711 1234 'options' => array(
1712 1235 'min_range' => 1,
1713 1236 ),
1714 1237 )
1715 - ) : false;
1716 -
1717 - if ( ! self::can_edit_chart( $chart_id ) ) {
1718 - wp_send_json_error( array( 'msg' => esc_html__( 'You do not have permission to perform this action.', 'visualizer' ) ), 403 );
1719 - }
1720 -
1721 - $hours = filter_input(
1722 - INPUT_POST,
1723 - 'refresh',
1724 - FILTER_VALIDATE_FLOAT,
1725 - array(
1726 - 'options' => array(
1727 - 'min_range' => -1,
1728 - 'max_range' => apply_filters( 'visualizer_is_business', false ) ? PHP_INT_MAX : -1,
1729 - ),
1730 - )
1731 1238 );
1732 1239
1733 - if ( ! is_numeric( $hours ) ) {
1734 - $hours = -1;
1735 - }
1240 + $hours = $_POST['refresh'];
1736 1241
1737 1242 do_action( 'visualizer_save_filter', $chart_id, $hours );
1738 1243
1739 1244 if ( ! ( defined( 'VISUALIZER_DO_NOT_DIE' ) && VISUALIZER_DO_NOT_DIE ) ) {
1740 - ( defined( 'WP_TESTS_DOMAIN' ) && function_exists( 'tests_add_filter' ) ) ? wp_die() : exit();
1245 + defined( 'WP_TESTS_DOMAIN' ) ? wp_die() : exit();
1741 1246 }
1742 - }
1743 -
1744 - /**
1745 - * Save chart image.
1746 - *
1747 - * @param string $base64_img Chart image.
1748 - * @param int $chart_id Chart ID.
1749 - * @param bool $save_attachment Save attachment.
1750 - * @return int Attachment ID, or 0 when no attachment was saved.
1751 - */
1752 - public function save_chart_image( $base64_img, $chart_id, $save_attachment = true ) {
1753 - // Delete old chart image.
1754 - $old_attachment_id = get_post_meta( $chart_id, Visualizer_Plugin::CF_CHART_IMAGE, true );
1755 - if ( $old_attachment_id ) {
1756 - wp_delete_attachment( $old_attachment_id, true );
1757 - }
1758 -
1759 - if ( ! $save_attachment ) {
1760 - return 0;
1761 - }
1762 -
1763 - // Upload dir.
1764 - $upload_dir = wp_upload_dir();
1765 - $upload_path = str_replace( '/', DIRECTORY_SEPARATOR, $upload_dir['path'] ) . DIRECTORY_SEPARATOR;
1766 -
1767 - $img = str_replace( 'data:image/png;base64,', '', (string) $base64_img );
1768 - $img = str_replace( ' ', '+', $img );
1769 - $decoded = base64_decode( $img, true );
1770 - // The value comes from an untrusted request; only write real PNG bytes to uploads.
1771 - if ( false === $decoded || 0 !== strncmp( $decoded, "\x89PNG\r\n\x1a\n", 8 ) ) {
1772 - return 0;
1773 - }
1774 - $filename = 'visualization-' . $chart_id . '.png';
1775 - $file_type = 'image/png';
1776 - $hashed_filename = $filename;
1777 -
1778 - // Save the image in the uploads directory.
1779 - require_once ABSPATH . '/wp-admin/includes/file.php';
1780 - \WP_Filesystem();
1781 - global $wp_filesystem;
1782 - if ( ! is_a( $wp_filesystem, 'WP_Filesystem_Base' ) ) {
1783 - $creds = request_filesystem_credentials( site_url() );
1784 - wp_filesystem( $creds );
1785 - }
1786 - $upload_file = $wp_filesystem->put_contents( $upload_path . $hashed_filename, $decoded );
1787 -
1788 - // Insert new chart image.
1789 - $attachment = array(
1790 - 'post_mime_type' => $file_type,
1791 - 'post_title' => preg_replace( '/\.[^.]+$/', '', basename( $hashed_filename ) ),
1792 - 'post_content' => '',
1793 - 'post_status' => 'inherit',
1794 - 'guid' => $upload_dir['url'] . '/' . basename( $hashed_filename ),
1795 - );
1796 -
1797 - $attach_id = wp_insert_attachment( $attachment, $upload_dir['path'] . '/' . $hashed_filename );
1798 - return $attach_id;
1799 1247 }
1800 1248 }