← All changes
|
src/conditionals/third-party/elementor-edit-conditional.php
+46
-8
18.3
→
trunk
View file →
| @@ -10,22 +10,60 @@ | ||
| 10 | 10 | */ |
| 11 | 11 | class Elementor_Edit_Conditional implements Conditional { |
| 12 | 12 | |
| 13 | 13 | /** |
| 14 | - * Returns whether or not this conditional is met. | |
| 14 | + * Returns whether this conditional is met. | |
| 15 | 15 | * |
| 16 | - * @return bool Whether or not the conditional is met. | |
| 16 | + * @return bool Whether the conditional is met. | |
| 17 | 17 | */ |
| 18 | 18 | public function is_met() { |
| 19 | 19 | global $pagenow; |
| 20 | 20 | |
| 21 | - // Check if we are on an Elementor edit page. | |
| 22 | - $get_action = \filter_input( \INPUT_GET, 'action', \FILTER_SANITIZE_STRING ); | |
| 23 | - if ( $pagenow === 'post.php' && $get_action === 'elementor' ) { | |
| 21 | + // Editing a post/page in Elementor. | |
| 22 | + if ( $pagenow === 'post.php' && $this->is_elementor_get_action() ) { | |
| 24 | 23 | return true; |
| 25 | 24 | } |
| 26 | 25 | |
| 27 | - // Check if we are in our Elementor ajax request. | |
| 28 | - $post_action = \filter_input( \INPUT_POST, 'action', \FILTER_SANITIZE_STRING ); | |
| 29 | - return \wp_doing_ajax() && $post_action === 'wpseo_elementor_save'; | |
| 26 | + // Request for us saving a post/page in Elementor (submits our form via AJAX). | |
| 27 | + return \wp_doing_ajax() && $this->is_yoast_save_post_action(); | |
| 28 | + } | |
| 29 | + | |
| 30 | + /** | |
| 31 | + * Checks if the current request' GET action is 'elementor'. | |
| 32 | + * | |
| 33 | + * @return bool True when the GET action is 'elementor'. | |
| 34 | + */ | |
| 35 | + private function is_elementor_get_action(): bool { | |
| 36 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Reason: We are not processing form information. | |
| 37 | + if ( ! isset( $_GET['action'] ) ) { | |
| 38 | + return false; | |
| 39 | + } | |
| 40 | + | |
| 41 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Reason: We are not processing form information. | |
| 42 | + if ( ! \is_string( $_GET['action'] ) ) { | |
| 43 | + return false; | |
| 44 | + } | |
| 45 | + | |
| 46 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended,WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Reason: We are not processing form information, we are only strictly comparing. | |
| 47 | + return \wp_unslash( $_GET['action'] ) === 'elementor'; | |
| 48 | + } | |
| 49 | + | |
| 50 | + /** | |
| 51 | + * Checks if the current request' POST action is 'wpseo_elementor_save'. | |
| 52 | + * | |
| 53 | + * @return bool True when the POST action is 'wpseo_elementor_save'. | |
| 54 | + */ | |
| 55 | + private function is_yoast_save_post_action(): bool { | |
| 56 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- Reason: We are not processing form information. | |
| 57 | + if ( ! isset( $_POST['action'] ) ) { | |
| 58 | + return false; | |
| 59 | + } | |
| 60 | + | |
| 61 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- Reason: We are not processing form information. | |
| 62 | + if ( ! \is_string( $_POST['action'] ) ) { | |
| 63 | + return false; | |
| 64 | + } | |
| 65 | + | |
| 66 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing,WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Reason: We are not processing form information, we are only strictly comparing. | |
| 67 | + return \wp_unslash( $_POST['action'] ) === 'wpseo_elementor_save'; | |
| 30 | 68 | } |
| 31 | 69 | } |