PluginProbe
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance / 4.7.0
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance v4.7.0
4.7.0 4.6.1 4.6.0 4.5.5 4.5.4 4.5.3 4.5.2 3.2.20 3.2.21 3.2.22 3.2.3 3.2.5 3.2.6 3.2.7 3.2.9 3.3.0 3.3.1 3.3.2 3.4.0 3.4.1 3.4.2 3.5.0 3.6.0 3.7.0 3.7.1 All 111 releases
← All changes | includes/class-wpo-ajax.php +21 -30 3.4.0 → 4.7.0 View file →
@@ -22,10 +22,10 @@
22 22 * Constructor
23 23 */
24 24 private function __construct() {
25 25 add_action('wp_ajax_wp_optimize_ajax', array($this, 'handle_ajax_requests'));
26 - add_filter('wp_optimize_heartbeat_ajax', array($this, 'handle_heartbeat_requests'), 10, 1);
27 - add_filter('wp_optimize_is_heartbeat_valid_ajax_command', array($this, 'is_heartbeat_command_valid'), 10, 1);
26 + add_filter('wp_optimize_heartbeat_ajax', array($this, 'handle_heartbeat_requests'));
27 + add_filter('wp_optimize_is_heartbeat_valid_ajax_command', array($this, 'is_heartbeat_command_valid'));
28 28 }
29 29
30 30 /**
31 31 * Check if a command is valid for this class
@@ -60,15 +60,15 @@
60 60 */
61 61 public function handle_heartbeat_requests($action) {
62 62 $this->set_heartbeat_subaction($action);
63 63
64 - if (!$this->is_user_capable()) {
65 - return json_encode($this->send_user_capability_error_response(false));
64 + if (!WP_Optimize()->current_user_can()) {
65 + return wp_json_encode($this->send_user_capability_error_response(false));
66 66 }
67 67
68 - if (is_multisite() && !current_user_can('manage_network_options')) {
68 + if (is_multisite() && !WP_Optimize()->current_user_can('manage_network_options')) {
69 69 if (!$this->is_valid_multisite_command()) {
70 - return json_encode($this->send_invalid_multisite_command_error_response(false));
70 + return wp_json_encode($this->send_invalid_multisite_command_error_response(false));
71 71 }
72 72 }
73 73
74 74 $this->set_commands();
@@ -105,13 +105,13 @@
105 105 if (!$this->is_valid_request()) {
106 106 $this->send_security_check_failed_error_response();
107 107 }
108 108
109 - if (!$this->is_user_capable()) {
109 + if (!WP_Optimize()->current_user_can()) {
110 110 $this->send_user_capability_error_response();
111 111 }
112 112
113 - if (is_multisite() && !current_user_can('manage_network_options')) {
113 + if (is_multisite() && !WP_Optimize()->current_user_can('manage_network_options')) {
114 114 if (!$this->is_valid_multisite_command()) {
115 115 $this->send_invalid_multisite_command_error_response();
116 116 }
117 117 }
@@ -137,9 +137,9 @@
137 137 if ($json_last_error) {
138 138 $this->set_error_response_on_json_encode_error($json_last_error);
139 139 }
140 140
141 - echo $this->results;
141 + echo $this->results; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output already escaped
142 142 die;
143 143 }
144 144
145 145 /**
@@ -145,9 +145,9 @@
145 145 /**
146 146 * Sets nonce property value
147 147 */
148 148 private function set_nonce() {
149 - $this->nonce = empty($_POST['nonce']) ? '' : $_POST['nonce'];
149 + $this->nonce = empty($_POST['nonce']) ? '' : sanitize_key(wp_unslash($_POST['nonce'])); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- is_valid_request() checks nonce
150 150 }
151 151
152 152 /**
153 153 * Sets subaction property value
@@ -152,9 +152,9 @@
152 152 /**
153 153 * Sets subaction property value
154 154 */
155 155 private function set_subaction() {
156 - $this->subaction = empty($_POST['subaction']) ? '' : stripcslashes($_POST['subaction']);
156 + $this->subaction = empty($_POST['subaction']) ? '' : sanitize_key(wp_unslash($_POST['subaction'])); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- is_valid_request() checks nonce
157 157 }
158 158
159 159 /**
160 160 * Sets heartbeat subaction property value
@@ -168,9 +168,9 @@
168 168 /**
169 169 * Sets data property value
170 170 */
171 171 private function set_data() {
172 - $this->data = isset($_POST['data']) ? stripslashes_deep($_POST['data']) : null;
172 + $this->data = isset($_POST['data']) ? stripslashes_deep($_POST['data']) : null; // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- is_valid_request() checks nonce, sanitization takes place later
173 173 }
174 174
175 175 /**
176 176 * Checks whether the request is valid or not
@@ -191,22 +191,12 @@
191 191 'error_message' => __('The security check failed; try refreshing the page.', 'wp-optimize')
192 192 ));
193 193 }
194 194
195 -
196 195 /**
197 - * Checks whether current user capable of doing this action or not
198 - *
199 - * @return bool
200 - */
201 - private function is_user_capable() {
202 - return current_user_can(WP_Optimize()->capability_required());
203 - }
204 -
205 - /**
206 196 * Send user capability check failed error response to browser and possibly die
207 197 *
208 - * @param Boolean $send - if true, then the response is output; otherwise, it is returned
198 + * @param boolean $send - if true, then the response is output; otherwise, it is returned
209 199 */
210 200 private function send_user_capability_error_response($send = true) {
211 201 $error = array(
212 202 'result' => false,
@@ -213,9 +203,9 @@
213 203 'error_code' => 'security_check',
214 204 'error_message' => __('You are not allowed to run this command.', 'wp-optimize')
215 205 );
216 206
217 - if (true == $send) {
207 + if ($send) {
218 208 wp_send_json($error);
219 209 } else {
220 210 return $error;
221 211 }
@@ -243,9 +233,9 @@
243 233 'error_code' => 'update_failed',
244 234 'error_message' => __('Options can only be saved by network admin', 'wp-optimize')
245 235 );
246 236
247 - if (true == $send) {
237 + if ($send) {
248 238 wp_send_json($error);
249 239 } else {
250 240 return $error;
251 241 }
@@ -285,9 +275,9 @@
285 275 if (in_array($this->subaction, array('dismiss_dash_notice_until', 'dismiss_season'))) {
286 276 $options->update_option($this->subaction, (time() + 366 * 86400));
287 277 } elseif (in_array($this->subaction, array('dismiss_page_notice_until', 'dismiss_notice'))) {
288 278 $options->update_option($this->subaction, (time() + 84 * 86400));
289 - } elseif ('dismiss_review_notice' == $this->subaction) {
279 + } elseif ('dismiss_review_notice' === $this->subaction) {
290 280 if (empty($this->data['dismiss_forever'])) {
291 281 $options->update_option($this->subaction, time() + 84 * 86400);
292 282 } else {
293 283 $options->update_option($this->subaction, 100 * (365.25 * 86400));
@@ -298,9 +288,9 @@
298 288 /**
299 289 * Sets commands property value
300 290 */
301 291 private function set_commands() {
302 - $this->commands = new WP_Optimize_Commands();
292 + $this->commands = apply_filters('wpo_premium_ajax_commands', new WP_Optimize_Commands());
303 293
304 294 $minify_commands = $this->get_minify_commands();
305 295 if ($this->is_subaction_a_minify_command($minify_commands)) {
306 296 $this->commands = $minify_commands;
@@ -369,9 +359,9 @@
369 359 /**
370 360 * Log an error message for invalid ajax command
371 361 */
372 362 private function add_invalid_command_error_log_entry() {
373 - error_log("WP-Optimize: ajax_handler: no such command (" . $this->subaction . ")");
363 + error_log("WP-Optimize: ajax_handler: no such command (" . $this->subaction . ")"); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Edge case, used for debugging
374 364 }
375 365
376 366 /**
377 367 * Set `results` property with error response array for invalid ajax command
@@ -381,8 +371,9 @@
381 371 private function set_invalid_command_error_response() {
382 372 $this->results = array(
383 373 'result' => false,
384 374 'error_code' => 'command_not_found',
375 + // translators: %s is an ajax command name
385 376 'error_message' => sprintf(__('The command "%s" was not found', 'wp-optimize'), $this->subaction)
386 377 );
387 378 }
388 379
@@ -444,9 +435,9 @@
444 435 'error_message' => 'json_encode error : ' . $json_last_error,
445 436 'error_data' => '',
446 437 );
447 438
448 - $this->results = json_encode($this->results);
439 + $this->results = wp_json_encode($this->results);
449 440 }
450 441
451 442 /**
452 443 * Json encode the `results` property value
@@ -451,9 +442,9 @@
451 442 /**
452 443 * Json encode the `results` property value
453 444 */
454 445 private function json_encode_results() {
455 - $this->results = json_encode($this->results);
446 + $this->results = wp_json_encode($this->results);
456 447 }
457 448 }
458 449
459 450 endif;