| @@ -1,7 +1,7 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | -if (!defined('WPO_VERSION')) die('No direct access allowed'); | |
| 3 | +if (!defined('ABSPATH')) die('No direct access allowed'); | |
| 4 | 4 | |
| 5 | 5 | if (!class_exists('WP_Optimize_Heartbeat')) : |
| 6 | 6 | |
| 7 | 7 | class WP_Optimize_Heartbeat { |
| @@ -17,13 +17,9 @@ | ||
| 17 | 17 | $pages_enabled = array('WP-Optimize', 'wpo_images', 'wpo_cache', 'wpo_minify', 'wpo_settings', 'wpo_support', 'wpo_mayalso', 'upload.php'); |
| 18 | 18 | |
| 19 | 19 | // Change heartbeat API frequency to 15 seconds to improve UI experience |
| 20 | 20 | // only for the pages that we enable in `$pages_enabled` |
| 21 | - if (isset($_GET['page'])) { | |
| 22 | - $query_page = sanitize_text_field(wp_unslash($_GET['page'])); // phpcs:ignore WordPress.Security.NonceVerification -- not processing form data | |
| 23 | - } else { | |
| 24 | - $query_page = $pagenow; | |
| 25 | - } | |
| 21 | + $query_page = isset($_GET['page']) ? sanitize_text_field(wp_unslash($_GET['page'])) : $pagenow; // phpcs:ignore WordPress.Security.NonceVerification -- not processing form data | |
| 26 | 22 | |
| 27 | 23 | if (in_array($query_page, $pages_enabled)) { |
| 28 | 24 | add_filter('heartbeat_settings', array($this, 'set_heartbeat_time_interval'), PHP_INT_MAX); |
| 29 | 25 | } |
| @@ -64,11 +60,13 @@ | ||
| 64 | 60 | * |
| 65 | 61 | * @param array $response Heartbeat response data to pass back to front end. |
| 66 | 62 | * @param array $data Data received from the front end (unslashed). |
| 67 | 63 | * |
| 68 | - * @return array | |
| 64 | + * @return array|void | |
| 69 | 65 | */ |
| 70 | 66 | public function receive_heartbeat($response, $data) { |
| 67 | + $allowed_smush_commands = Updraft_Smush_Manager_Commands::get_allowed_ajax_commands(); | |
| 68 | + $user_can = WP_Optimize()->current_user_can(); | |
| 71 | 69 | $commands = new Updraft_Smush_Manager_Commands(Updraft_Smush_Manager::instance()); |
| 72 | 70 | $commands->heartbeat_command = true; |
| 73 | 71 | |
| 74 | 72 | foreach ($data as $uid => $command) { |
| @@ -81,10 +79,23 @@ | ||
| 81 | 79 | $response['callbacks'][$uid] = apply_filters('wp_optimize_heartbeat_ajax', $command); |
| 82 | 80 | } |
| 83 | 81 | } else { |
| 84 | 82 | $command_name = key($command); |
| 85 | - if ('updraft_smush_ajax' == $command_name) { | |
| 83 | + if ('updraft_smush_ajax' === $command_name) { | |
| 84 | + | |
| 85 | + if (!$user_can) { | |
| 86 | + continue; | |
| 87 | + } | |
| 88 | + | |
| 86 | 89 | $command_data = current($command); |
| 90 | + | |
| 91 | + if (empty($command_data['subaction'])) { | |
| 92 | + continue; | |
| 93 | + } | |
| 94 | + | |
| 95 | + if (!in_array($command_data['subaction'], $allowed_smush_commands, true)) { | |
| 96 | + continue; | |
| 97 | + } | |
| 87 | 98 | |
| 88 | 99 | $command_data_param = null; |
| 89 | 100 | if (isset($command_data['data'])) { |
| 90 | 101 | $command_data_param = $command_data['data']; |
| @@ -91,18 +102,22 @@ | ||
| 91 | 102 | } |
| 92 | 103 | |
| 93 | 104 | $_REQUEST['subaction'] = $command_data['subaction']; |
| 94 | 105 | $_REQUEST['data'] = $command_data_param; |
| 95 | - | |
| 96 | - ob_start(); | |
| 97 | - | |
| 106 | + | |
| 98 | 107 | if (!is_callable(array($commands, $command_data['subaction']))) { |
| 99 | 108 | continue; |
| 100 | 109 | } |
| 101 | 110 | |
| 111 | + ob_start(); | |
| 112 | + | |
| 102 | 113 | $method = new ReflectionMethod($commands, $command_data['subaction']); |
| 103 | 114 | |
| 104 | - $command_response = $method->invokeArgs($commands, array($command_data_param)); | |
| 115 | + try { | |
| 116 | + $command_response = $method->invokeArgs($commands, array($command_data_param)); | |
| 117 | + } catch (Exception $e) { | |
| 118 | + $command_response = new WP_Error($e->getCode() ? $e->getCode() : 1, $e->getMessage()); | |
| 119 | + } | |
| 105 | 120 | |
| 106 | 121 | if (is_array($command_response)) { |
| 107 | 122 | $response['callbacks'][$uid] = $command_response; |
| 108 | 123 | ob_end_clean(); |