| 1 |
<?php |
| 2 |
|
| 3 |
namespace TeamUpdraft\WP_Optimize\Includes\Fragments; |
| 4 |
|
| 5 |
if (!defined('ABSPATH')) die('No direct access allowed'); |
| 6 |
|
| 7 |
/** |
| 8 |
* Return the value of a member of a superglobal, after slash-stripping and sanitisation. |
| 9 |
* |
| 10 |
* When using, it is recommended that if the $type or $sanitisation parameters are not used then a code comment is added to state the reason. |
| 11 |
* |
| 12 |
* If the specified key is not found, or the resulting value does not match the expected type, the default value is returned instead. |
| 13 |
* An error is logged if the type does not match, but no exception is thrown. |
| 14 |
* |
| 15 |
* Previously this function could throw a TypeError when the fetched value did not match the expected type. |
| 16 |
* This behavior has been removed in favor of returning the $default and logging the error, to improve fault tolerance. |
| 17 |
* |
| 18 |
* @param String $superglobal - should be one of 'get', 'post', 'request', 'cookie' or 'server'; case insensitive |
| 19 |
* @param String $key - the key to fetch from the superglobal array |
| 20 |
* @param String|Null $type - If specified, must match gettype() on the returned value; otherwise, $default is returned and an error is logged. |
| 21 |
* @param Callable|Null $sanitisation - the sanitisation function to run the result through (any function), with the first parameter being the putative value. Any $default value will not be sanitised, which allows different cases to be distinguished as described above. |
| 22 |
* @param Mixed $default - value to return if the key is not found or type mismatched |
| 23 |
* |
| 24 |
* @return Mixed |
| 25 |
* |
| 26 |
* @see https://developer.wordpress.org/apis/security/sanitizing/ |
| 27 |
* @see https://www.php.net/manual/en/function.gettype.php |
| 28 |
*/ |
| 29 |
function fetch_superglobal($superglobal, $key, $type = null, $sanitisation = null, $default = null) { |
| 30 |
|
| 31 |
$superglobal = '_'.strtoupper($superglobal); |
| 32 |
|
| 33 |
// N.B. Superglobals can only be dereferenced by variable variables in the global scope; this is why we have to use $GLOBALS |
| 34 |
if (!is_array($GLOBALS[$superglobal]) || !isset($GLOBALS[$superglobal][$key])) { |
| 35 |
$putative_return = $default; |
| 36 |
} else { |
| 37 |
$putative_return = stripslashes_deep($GLOBALS[$superglobal][$key]); |
| 38 |
if (null !== $sanitisation) { |
| 39 |
try { |
| 40 |
$putative_return = call_user_func($sanitisation, $putative_return); |
| 41 |
} catch (\Throwable $e) { |
| 42 |
$backtrace_summary = \WP_Optimize_Utils::get_backtrace_summary(); |
| 43 |
error_log(sprintf('WP-Optimize: fetch_superglobal() failed due to: "%s" [%s]', $e->getMessage(), $backtrace_summary));// phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose |
| 44 |
return $default; |
| 45 |
} |
| 46 |
} |
| 47 |
} |
| 48 |
|
| 49 |
if (null !== $type && strtolower(gettype($putative_return)) !== strtolower($type)) { |
| 50 |
$backtrace_summary = \WP_Optimize_Utils::get_backtrace_summary(); |
| 51 |
error_log(sprintf('WP-Optimize: fetch_superglobal() failed due to type mismatch - expected "%s", received "%s" [%s]', $type, gettype($putative_return), $backtrace_summary)); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose |
| 52 |
return $default; |
| 53 |
} |
| 54 |
|
| 55 |
return $putative_return; |
| 56 |
} |
| 57 |
|
| 58 |
/** |
| 59 |
* Used to verify a nonce |
| 60 |
* |
| 61 |
* @param string $name Nonce name |
| 62 |
* @param string|int $action Nonce action |
| 63 |
* |
| 64 |
* @return bool |
| 65 |
*/ |
| 66 |
function verify_nonce($name, $action = -1) { |
| 67 |
$name = fetch_superglobal('request', $name, null, 'sanitize_key'); |
| 68 |
if (null === $name) { |
| 69 |
return false; |
| 70 |
} |
| 71 |
if (function_exists('wp_verify_nonce')) { |
| 72 |
if (wp_verify_nonce($name, $action)) { |
| 73 |
return true; |
| 74 |
} |
| 75 |
} |
| 76 |
|
| 77 |
$backtrace_summary = \WP_Optimize_Utils::get_backtrace_summary(); |
| 78 |
error_log(sprintf('WP-Optimize: verify_nonce() failed for action "%s" [%s]', $action, $backtrace_summary)); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose |
| 79 |
|
| 80 |
return false; |
| 81 |
} |
| 82 |
|