← All changes
|
src/conditionals/admin/estimated-reading-time-conditional.php
+14
-18
18.3
→
trunk
View file →
| @@ -2,9 +2,8 @@ | ||
| 2 | 2 | |
| 3 | 3 | namespace Yoast\WP\SEO\Conditionals\Admin; |
| 4 | 4 | |
| 5 | 5 | use Yoast\WP\SEO\Conditionals\Conditional; |
| 6 | -use Yoast\WP\SEO\Helpers\Input_Helper; | |
| 7 | 6 | |
| 8 | 7 | /** |
| 9 | 8 | * Conditional that is only when we want the Estimated Reading Time. |
| 10 | 9 | */ |
| @@ -17,34 +16,27 @@ | ||
| 17 | 16 | */ |
| 18 | 17 | protected $post_conditional; |
| 19 | 18 | |
| 20 | 19 | /** |
| 21 | - * The Input Helper. | |
| 22 | - * | |
| 23 | - * @var Input_Helper | |
| 24 | - */ | |
| 25 | - protected $input_helper; | |
| 26 | - | |
| 27 | - /** | |
| 28 | 20 | * Constructs the Estimated Reading Time Conditional. |
| 29 | 21 | * |
| 30 | 22 | * @param Post_Conditional $post_conditional The post conditional. |
| 31 | - * @param Input_Helper $input_helper The input helper. | |
| 32 | 23 | */ |
| 33 | - public function __construct( Post_Conditional $post_conditional, Input_Helper $input_helper ) { | |
| 24 | + public function __construct( Post_Conditional $post_conditional ) { | |
| 34 | 25 | $this->post_conditional = $post_conditional; |
| 35 | - $this->input_helper = $input_helper; | |
| 36 | 26 | } |
| 37 | 27 | |
| 38 | 28 | /** |
| 39 | - * Returns whether or not this conditional is met. | |
| 29 | + * Returns whether this conditional is met. | |
| 40 | 30 | * |
| 41 | - * @return bool Whether or not the conditional is met. | |
| 31 | + * @return bool Whether the conditional is met. | |
| 42 | 32 | */ |
| 43 | 33 | public function is_met() { |
| 34 | + // phpcs:disable WordPress.Security.NonceVerification.Recommended,WordPress.Security.NonceVerification.Missing -- Reason: Nonce verification should not be done in a conditional but rather in the classes using the conditional. | |
| 44 | 35 | // Check if we are in our Elementor ajax request (for saving). |
| 45 | - if ( \wp_doing_ajax() ) { | |
| 46 | - $post_action = $this->input_helper->filter( \INPUT_POST, 'action', \FILTER_SANITIZE_STRING ); | |
| 36 | + if ( \wp_doing_ajax() && isset( $_POST['action'] ) && \is_string( $_POST['action'] ) ) { | |
| 37 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Reason: We are only strictly comparing the variable. | |
| 38 | + $post_action = \wp_unslash( $_POST['action'] ); | |
| 47 | 39 | if ( $post_action === 'wpseo_elementor_save' ) { |
| 48 | 40 | return true; |
| 49 | 41 | } |
| 50 | 42 | } |
| @@ -53,12 +45,16 @@ | ||
| 53 | 45 | return false; |
| 54 | 46 | } |
| 55 | 47 | |
| 56 | 48 | // We don't support Estimated Reading Time on the attachment post type. |
| 57 | - $post_id = (int) $this->input_helper->filter( \INPUT_GET, 'post', \FILTER_SANITIZE_NUMBER_INT ); | |
| 58 | - if ( \get_post_type( $post_id ) === 'attachment' ) { | |
| 59 | - return false; | |
| 49 | + if ( isset( $_GET['post'] ) && \is_string( $_GET['post'] ) ) { | |
| 50 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Reason: We are casting to an integer. | |
| 51 | + $post_id = (int) \wp_unslash( $_GET['post'] ); | |
| 52 | + if ( $post_id !== 0 && \get_post_type( $post_id ) === 'attachment' ) { | |
| 53 | + return false; | |
| 54 | + } | |
| 60 | 55 | } |
| 61 | 56 | |
| 62 | 57 | return true; |
| 58 | + // phpcs:enable WordPress.Security.NonceVerification.Recommended,WordPress.Security.NonceVerification.Missing | |
| 63 | 59 | } |
| 64 | 60 | } |