| @@ -1,7 +1,7 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | -if (!defined('WPO_VERSION')) die('No direct access allowed'); | |
| 3 | +if (!defined('ABSPATH')) die('No direct access allowed'); | |
| 4 | 4 | |
| 5 | 5 | /** |
| 6 | 6 | * Parent class for all optimizations. |
| 7 | 7 | */ |
| @@ -94,18 +94,20 @@ | ||
| 94 | 94 | |
| 95 | 95 | protected $wpdb; |
| 96 | 96 | |
| 97 | 97 | /** |
| 98 | - * This is abstracted so as to provide future possibilities, e.g. logging. | |
| 98 | + * This is abstracted so to provide future possibilities, e.g. logging. | |
| 99 | 99 | * |
| 100 | - * @param string $sql The quesry for SQL to be ran. | |
| 101 | - * @return array Return array of results | |
| 100 | + * @param string $sql The prepared SQL query to run | |
| 101 | + * @return mixed Return array of results | |
| 102 | 102 | */ |
| 103 | 103 | protected function query($sql) { |
| 104 | 104 | $this->sql_commands[] = $sql; |
| 105 | 105 | do_action('wp_optimize_optimization_query', $sql, $this); |
| 106 | - $result = $this->wpdb->query($sql); | |
| 107 | - return apply_filters('wp_optimize_optimization_query_result', $result, $sql, $this); | |
| 106 | + $result = $this->wpdb->query($sql); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared -- Already prepared query | |
| 107 | + $filtered_result = apply_filters('wp_optimize_optimization_query_result', $result, $sql, $this); | |
| 108 | + if (!empty($filtered_result) && is_array($filtered_result)) return $filtered_result; | |
| 109 | + return $result; | |
| 108 | 110 | } |
| 109 | 111 | |
| 110 | 112 | /** |
| 111 | 113 | * Display or hide optimization in optimizations list. |
| @@ -125,9 +127,9 @@ | ||
| 125 | 127 | * @return array |
| 126 | 128 | */ |
| 127 | 129 | public function preview($params) { |
| 128 | 130 | return array( |
| 129 | - 'id_key' => 'id', // key used used to identify data. | |
| 131 | + 'id_key' => 'id', // key is used to identify data. | |
| 130 | 132 | 'offset' => $params['offset'], |
| 131 | 133 | 'limit' => $params['limit'], |
| 132 | 134 | 'total' => 0, |
| 133 | 135 | 'data' => array(), // returned data as associative array where keys are column names and values - database cell values. |
| @@ -215,9 +217,9 @@ | ||
| 215 | 217 | * This triggers the do_optimization function |
| 216 | 218 | * within class-wp-optimizer.php to kick off the optimizations. |
| 217 | 219 | * It also passed the data array from the wpadmin.js. |
| 218 | 220 | * |
| 219 | - * @return array array of results that includes sql_commands, output and meta | |
| 221 | + * @return array|object|WP_Error|WP_Optimization array of results that includes sql_commands, output and meta | |
| 220 | 222 | */ |
| 221 | 223 | public function do_optimization() { |
| 222 | 224 | return $this->optimizer->do_optimization($this); |
| 223 | 225 | } |
| @@ -225,9 +227,9 @@ | ||
| 225 | 227 | /** |
| 226 | 228 | * This gathers the optimization information to be displayed |
| 227 | 229 | * before triggering any optimizations |
| 228 | 230 | * |
| 229 | - * @return object Returns an object of optimization information | |
| 231 | + * @return array|object|WP_Error|WP_Optimization Returns an object of optimization information | |
| 230 | 232 | */ |
| 231 | 233 | public function get_optimization_info() { |
| 232 | 234 | return $this->optimizer->get_optimization_info($this); |
| 233 | 235 | } |
| @@ -253,9 +255,9 @@ | ||
| 253 | 255 | |
| 254 | 256 | // check selected sites field. |
| 255 | 257 | if (!empty($optimization_sites)) { |
| 256 | 258 | foreach ($optimization_sites as $site_id) { |
| 257 | - if ('all' == $site_id) { | |
| 259 | + if ('all' === (string) $site_id) { | |
| 258 | 260 | $all_sites = true; |
| 259 | 261 | } else { |
| 260 | 262 | $selected_sites[] = $site_id; |
| 261 | 263 | } |
| @@ -275,9 +277,11 @@ | ||
| 275 | 277 | } else { |
| 276 | 278 | $objects[] = 1; |
| 277 | 279 | } |
| 278 | 280 | |
| 279 | - return apply_filters('get_optimization_blogs', $objects); | |
| 281 | + $filtered_objects = apply_filters('get_optimization_blogs', $objects); | |
| 282 | + if (is_array($filtered_objects)) return $filtered_objects; | |
| 283 | + return $objects; | |
| 280 | 284 | } |
| 281 | 285 | |
| 282 | 286 | /** |
| 283 | 287 | * Returns true if optimization works in multisite mode |
| @@ -297,9 +301,9 @@ | ||
| 297 | 301 | return WP_Optimize()->get_sites(); |
| 298 | 302 | } |
| 299 | 303 | |
| 300 | 304 | /** |
| 301 | - * Wrapper for switch_to_blog Wordpress MU function | |
| 305 | + * Wrapper for switch_to_blog WordPress MU function | |
| 302 | 306 | * |
| 303 | 307 | * @param int $new_blog new blog id. |
| 304 | 308 | * @return bool|void - if on multisite, then always true (see https://codex.wordpress.org/Function_Reference/switch_to_blog) |
| 305 | 309 | */ |
| @@ -309,11 +313,11 @@ | ||
| 309 | 313 | } |
| 310 | 314 | } |
| 311 | 315 | |
| 312 | 316 | /** |
| 313 | - * Wrapper for restore_current_blog Wordpress MU function | |
| 317 | + * Wrapper for restore_current_blog WordPress MU function | |
| 314 | 318 | * |
| 315 | - * @return bool | |
| 319 | + * @return bool|void | |
| 316 | 320 | */ |
| 317 | 321 | public function restore_current_blog() { |
| 318 | 322 | if (function_exists('restore_current_blog') && $this->is_multisite_mode()) { |
| 319 | 323 | return restore_current_blog(); |
| @@ -322,9 +326,9 @@ | ||
| 322 | 326 | |
| 323 | 327 | /** |
| 324 | 328 | * This function adds output to the current registered output |
| 325 | 329 | * |
| 326 | - * @param array $output Array of various outputs. | |
| 330 | + * @param string $output Output message | |
| 327 | 331 | */ |
| 328 | 332 | public function register_output($output) { |
| 329 | 333 | $this->output[] = $output; |
| 330 | 334 | } |
| @@ -332,9 +336,9 @@ | ||
| 332 | 336 | /** |
| 333 | 337 | * This function adds meta-data associated with the result to the registered output |
| 334 | 338 | * |
| 335 | 339 | * @param string $key The key value. |
| 336 | - * @param string $value The value to be passed. | |
| 340 | + * @param mixed $value The value to be passed. | |
| 337 | 341 | */ |
| 338 | 342 | public function register_meta($key, $value) { |
| 339 | 343 | $this->meta[$key] = $value; |
| 340 | 344 | } |
| @@ -367,36 +371,49 @@ | ||
| 367 | 371 | |
| 368 | 372 | |
| 369 | 373 | /** |
| 370 | 374 | * The next three functions reflect the fact that historically, WP-Optimize has not, for all optimizations, used the same ID consistently throughout forms, saved settings, and saved settings for scheduled clean-ups. Mostly, it has; but some flexibility is needed for the exceptions. |
| 375 | + * | |
| 376 | + * @return string | |
| 371 | 377 | */ |
| 372 | 378 | public function get_setting_id() { |
| 373 | 379 | return empty($this->setting_id) ? 'user-'.$this->id : 'user-'.$this->setting_id; |
| 374 | 380 | } |
| 375 | 381 | |
| 382 | + /** | |
| 383 | + * This function, `get_setting_id` and `get_auto_id` functions reflect the fact that historically, WP-Optimize has not, for all optimizations, used the same ID consistently throughout forms, saved settings, and saved settings for scheduled clean-ups. Mostly, it has; but some flexibility is needed for the exceptions. | |
| 384 | + * | |
| 385 | + * @return string | |
| 386 | + */ | |
| 376 | 387 | public function get_dom_id() { |
| 377 | 388 | return empty($this->dom_id) ? 'clean-'.$this->id : $this->dom_id; |
| 378 | 389 | } |
| 379 | 390 | |
| 391 | + /** | |
| 392 | + * This function, `get_setting_id` and `get_dom_id` functions reflect the fact that historically, WP-Optimize has not, for all optimizations, used the same ID consistently throughout forms, saved settings, and saved settings for scheduled clean-ups. Mostly, it has; but some flexibility is needed for the exceptions. | |
| 393 | + * | |
| 394 | + * @return string | |
| 395 | + */ | |
| 380 | 396 | public function get_auto_id() { |
| 381 | 397 | return empty($this->auto_id) ? $this->id : $this->auto_id; |
| 382 | 398 | } |
| 383 | 399 | |
| 400 | + /** | |
| 401 | + * Checks whether this optimization has changes table data | |
| 402 | + * | |
| 403 | + * @return bool | |
| 404 | + */ | |
| 384 | 405 | public function get_changes_table_data() { |
| 385 | 406 | return empty($this->changes_table_data) ? false : true; |
| 386 | 407 | } |
| 387 | 408 | |
| 388 | - public function get_run_sort_order() { | |
| 389 | - return empty($this->run_sort_order) ? 0 : $this->run_sort_order; | |
| 390 | - } | |
| 391 | - | |
| 392 | 409 | /** |
| 393 | - * Only used if $available_for_auto is true, in which case this function should be over-ridden | |
| 410 | + * Returns the run sort order | |
| 394 | 411 | * |
| 395 | - * @return string Error message. | |
| 412 | + * @return int | |
| 396 | 413 | */ |
| 397 | - public function get_auto_option_description() { | |
| 398 | - return 'Error: missing scheduled option description ('.$this->id.')'; | |
| 414 | + public function get_run_sort_order() { | |
| 415 | + return empty($this->run_sort_order) ? 0 : $this->run_sort_order; | |
| 399 | 416 | } |
| 400 | 417 | |
| 401 | 418 | /** |
| 402 | 419 | * What is returned must be at least convertible to an array |
| @@ -411,9 +428,11 @@ | ||
| 411 | 428 | $results->sql_commands = $this->sql_commands; |
| 412 | 429 | $results->output = $this->output; |
| 413 | 430 | $results->meta = $this->meta; |
| 414 | 431 | |
| 415 | - return apply_filters('wp_optimize_optimization_results', $results, $this->id, $this); | |
| 432 | + $filtered_results = apply_filters('wp_optimize_optimization_results', $results, $this->id, $this); | |
| 433 | + if (!empty($filtered_results) && is_object($filtered_results)) return $filtered_results; | |
| 434 | + return $results; | |
| 416 | 435 | } |
| 417 | 436 | |
| 418 | 437 | /** |
| 419 | 438 | * Generate information about optimization required for show it. |
| @@ -428,9 +447,9 @@ | ||
| 428 | 447 | |
| 429 | 448 | // N.B. Some of the optimizations used to have an onclick call to fCheck(). But that function was commented out, so did nothing. |
| 430 | 449 | $settings_label = $this->settings_label(); |
| 431 | 450 | |
| 432 | - $setting_activated = ((empty($wpo_user_selection[$setting_id]) || 'false' == $wpo_user_selection[$setting_id]) ? false : true); | |
| 451 | + $setting_activated = !empty($wpo_user_selection[$setting_id]) && 'false' !== $wpo_user_selection[$setting_id]; | |
| 433 | 452 | |
| 434 | 453 | $info = $this->get_optimization_info()->output; |
| 435 | 454 | |
| 436 | 455 | $settings_html = array( |
| @@ -436,14 +455,14 @@ | ||
| 436 | 455 | $settings_html = array( |
| 437 | 456 | 'dom_id' => $dom_id, |
| 438 | 457 | 'activated' => $setting_activated, |
| 439 | 458 | 'settings_label' => $settings_label, |
| 440 | - 'info' => $info | |
| 459 | + 'info' => wp_kses(join('<br>', $info), $this->allow_checkboxes()), | |
| 441 | 460 | ); |
| 442 | 461 | |
| 443 | 462 | if (empty($settings_label)) { |
| 444 | 463 | // Error_log, as this is a defect. |
| 445 | - error_log("Optimization with setting ID ".$setting_id." lacks a settings label (method: settings_label())"); | |
| 464 | + error_log("Optimization with setting ID ".$setting_id." lacks a settings label (method: settings_label())"); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging only | |
| 446 | 465 | } |
| 447 | 466 | |
| 448 | 467 | return $settings_html; |
| 449 | 468 | } |
| @@ -457,9 +476,9 @@ | ||
| 457 | 476 | * @return string |
| 458 | 477 | */ |
| 459 | 478 | public function get_preview_link($text, $attributes = array()) { |
| 460 | 479 | // if preview is not supported then return just $text. |
| 461 | - if (false == $this->support_preview || false == WP_Optimize::is_premium()) return $text; | |
| 480 | + if (!$this->support_preview || !WP_Optimize::is_premium()) return $text; | |
| 462 | 481 | |
| 463 | 482 | $attributes = array_merge( |
| 464 | 483 | array( |
| 465 | 484 | 'title' => __('Preview found items', 'wp-optimize'), |
| @@ -477,6 +496,38 @@ | ||
| 477 | 496 | |
| 478 | 497 | $link = '<a href="#" class="wpo-optimization-preview"'.$str_attr.'>'.$text.'</a>'; |
| 479 | 498 | |
| 480 | 499 | return $link; |
| 500 | + } | |
| 501 | + | |
| 502 | + /** | |
| 503 | + * Adds input and label tags to allowed HTML tags. | |
| 504 | + * | |
| 505 | + * @return array | |
| 506 | + */ | |
| 507 | + private function allow_checkboxes() { | |
| 508 | + $allowed_html = wp_kses_allowed_html('post'); | |
| 509 | + | |
| 510 | + $allowed_html['input'] = array( | |
| 511 | + 'type' => true, | |
| 512 | + 'name' => true, | |
| 513 | + 'id' => true, | |
| 514 | + 'class' => true, | |
| 515 | + 'value' => true, | |
| 516 | + 'placeholder' => true, | |
| 517 | + 'required' => true, | |
| 518 | + 'checked' => true, | |
| 519 | + 'disabled' => true, | |
| 520 | + 'min' => true, | |
| 521 | + 'max' => true, | |
| 522 | + 'step' => true | |
| 523 | + ); | |
| 524 | + | |
| 525 | + $allowed_html['label'] = array( | |
| 526 | + 'for' => true, | |
| 527 | + 'class' => true, | |
| 528 | + 'id' => true | |
| 529 | + ); | |
| 530 | + | |
| 531 | + return $allowed_html; | |
| 481 | 532 | } |
| 482 | 533 | } |