PluginProbe
WCPOS – Point of Sale (POS) plugin for WooCommerce / 1.10.22
WCPOS – Point of Sale (POS) plugin for WooCommerce v1.10.22
1.10.22 1.10.21 1.10.20 1.10.19 1.10.18 1.10.17 1.10.16 1.10.15 1.10.13 1.10.14 1.10.12 1.10.11 1.10.10 1.10.9 1.10.8 untagged-3d9b7ccddc54df87c672 1.10.7 1.10.6 1.10.5 1.10.3 1.10.4 1.10.2 1.10.1 1.10.0 1.9.17 All 166 releases
woocommerce-pos / includes / Services / Role_Meta_Guard.php

Role_Meta_Guard.php in WCPOS – Point of Sale (POS) plugin for WooCommerce 1.10.22, at includes/Services/Role_Meta_Guard.php

58 lines 1.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Customer role meta protection.
4 *
5 * @package WCPOS\WooCommercePOS
6 */
7
8 namespace WCPOS\WooCommercePOS\Services;
9
10 /**
11 * Roles and levels change only through the WP_User role APIs.
12 */
13 final class Role_Meta_Guard {
14 /**
15 * Register after other customer meta listeners.
16 */
17 public static function register(): void {
18 add_action( 'woocommerce_before_customer_object_save', array( self::class, 'strip_role_meta' ), PHP_INT_MAX );
19 }
20
21 /**
22 * Strip role metadata that WooCommerce copies onto the customer as generic meta.
23 *
24 * @param mixed $customer Object being saved.
25 */
26 public static function strip_role_meta( $customer ): void {
27 if ( ! $customer instanceof \WC_Customer ) {
28 return;
29 }
30
31 foreach ( $customer->get_meta_data() as $meta ) {
32 if ( self::is_role_meta_key( $meta->key ) ) {
33 if ( $meta->id ) {
34 $customer->delete_meta_data_by_mid( $meta->id );
35 } else {
36 $customer->delete_meta_data( $meta->key );
37 }
38 }
39 }
40 }
41
42 /**
43 * Identify role and level metadata for any blog prefix.
44 *
45 * @param mixed $key Meta key.
46 * @return bool Whether the key stores roles or a user level.
47 */
48 public static function is_role_meta_key( $key ): bool {
49 if ( ! \is_string( $key ) ) {
50 return false;
51 }
52
53 global $wpdb;
54
55 return 1 === preg_match( '/^' . preg_quote( $wpdb->base_prefix, '/' ) . '(\d+_)?(capabilities|user_level)$/i', trim( $key ) );
56 }
57 }
58