PluginProbe
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance / 4.7.0
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance v4.7.0
4.7.0 4.6.1 4.6.0 4.5.5 4.5.4 4.5.3 4.5.2 3.2.20 3.2.21 3.2.22 3.2.3 3.2.5 3.2.6 3.2.7 3.2.9 3.3.0 3.3.1 3.3.2 3.4.0 3.4.1 3.4.2 3.5.0 3.6.0 3.7.0 3.7.1 All 111 releases
wp-optimize / includes / fragments / input-processing.php

input-processing.php in WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance 4.7.0, at includes/fragments/input-processing.php

82 lines 3.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace TeamUpdraft\WP_Optimize\Includes\Fragments;
4
5 if (!defined('ABSPATH')) die('No direct access allowed');
6
7 /**
8 * Return the value of a member of a superglobal, after slash-stripping and sanitisation.
9 *
10 * When using, it is recommended that if the $type or $sanitisation parameters are not used then a code comment is added to state the reason.
11 *
12 * If the specified key is not found, or the resulting value does not match the expected type, the default value is returned instead.
13 * An error is logged if the type does not match, but no exception is thrown.
14 *
15 * Previously this function could throw a TypeError when the fetched value did not match the expected type.
16 * This behavior has been removed in favor of returning the $default and logging the error, to improve fault tolerance.
17 *
18 * @param String $superglobal - should be one of 'get', 'post', 'request', 'cookie' or 'server'; case insensitive
19 * @param String $key - the key to fetch from the superglobal array
20 * @param String|Null $type - If specified, must match gettype() on the returned value; otherwise, $default is returned and an error is logged.
21 * @param Callable|Null $sanitisation - the sanitisation function to run the result through (any function), with the first parameter being the putative value. Any $default value will not be sanitised, which allows different cases to be distinguished as described above.
22 * @param Mixed $default - value to return if the key is not found or type mismatched
23 *
24 * @return Mixed
25 *
26 * @see https://developer.wordpress.org/apis/security/sanitizing/
27 * @see https://www.php.net/manual/en/function.gettype.php
28 */
29 function fetch_superglobal($superglobal, $key, $type = null, $sanitisation = null, $default = null) {
30
31 $superglobal = '_'.strtoupper($superglobal);
32
33 // N.B. Superglobals can only be dereferenced by variable variables in the global scope; this is why we have to use $GLOBALS
34 if (!is_array($GLOBALS[$superglobal]) || !isset($GLOBALS[$superglobal][$key])) {
35 $putative_return = $default;
36 } else {
37 $putative_return = stripslashes_deep($GLOBALS[$superglobal][$key]);
38 if (null !== $sanitisation) {
39 try {
40 $putative_return = call_user_func($sanitisation, $putative_return);
41 } catch (\Throwable $e) {
42 $backtrace_summary = \WP_Optimize_Utils::get_backtrace_summary();
43 error_log(sprintf('WP-Optimize: fetch_superglobal() failed due to: "%s" [%s]', $e->getMessage(), $backtrace_summary));// phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose
44 return $default;
45 }
46 }
47 }
48
49 if (null !== $type && strtolower(gettype($putative_return)) !== strtolower($type)) {
50 $backtrace_summary = \WP_Optimize_Utils::get_backtrace_summary();
51 error_log(sprintf('WP-Optimize: fetch_superglobal() failed due to type mismatch - expected "%s", received "%s" [%s]', $type, gettype($putative_return), $backtrace_summary)); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose
52 return $default;
53 }
54
55 return $putative_return;
56 }
57
58 /**
59 * Used to verify a nonce
60 *
61 * @param string $name Nonce name
62 * @param string|int $action Nonce action
63 *
64 * @return bool
65 */
66 function verify_nonce($name, $action = -1) {
67 $name = fetch_superglobal('request', $name, null, 'sanitize_key');
68 if (null === $name) {
69 return false;
70 }
71 if (function_exists('wp_verify_nonce')) {
72 if (wp_verify_nonce($name, $action)) {
73 return true;
74 }
75 }
76
77 $backtrace_summary = \WP_Optimize_Utils::get_backtrace_summary();
78 error_log(sprintf('WP-Optimize: verify_nonce() failed for action "%s" [%s]', $action, $backtrace_summary)); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose
79
80 return false;
81 }
82