PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | wp_admin.php +41 -22 5.47trunk View file →
@@ -24,9 +24,9 @@
24 24 }
25 25 }
26 26
27 27 function removeAdminNotices() {
28 - if (array_key_exists('page', $_REQUEST) && $_REQUEST['page'] == $this->bvinfo->plugname) {
28 + if (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname) {
29 29 remove_all_actions('admin_notices');
30 30 remove_all_actions('all_admin_notices');
31 31 }
32 32 }
@@ -33,40 +33,47 @@
33 33
34 34 public function initHandler() {
35 35 if (!current_user_can('activate_plugins'))
36 36 return;
37 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
38 + $blogvaultkey = WPRHelper::getRawParam('REQUEST', 'blogvaultkey');
39 + $blogvaultkey = $blogvaultkey ? WPRAccount::sanitizeKey($blogvaultkey) : "";
37 40
38 - if (array_key_exists('bvnonce', $_REQUEST) &&
39 - wp_verify_nonce($_REQUEST['bvnonce'], "bvnonce") &&
40 - array_key_exists('blogvaultkey', $_REQUEST) &&
41 - (strlen(WPRAccount::sanitizeKey($_REQUEST['blogvaultkey'])) == 64) &&
42 - (array_key_exists('page', $_REQUEST) &&
43 - $_REQUEST['page'] == $this->bvinfo->plugname)) {
44 - $keys = str_split($_REQUEST['blogvaultkey'], 32);
41 + if ($bvnonce && wp_verify_nonce($bvnonce, "bvnonce") &&
42 + $blogvaultkey && strlen($blogvaultkey) == 64 &&
43 + (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname)) {
44 + $keys = str_split($blogvaultkey, 32);
45 45 WPRAccount::addAccount($this->settings, $keys[0], $keys[1]);
46 - if (array_key_exists('redirect', $_REQUEST)) {
47 - $location = $_REQUEST['redirect'];
46 +
47 + $location = WPRHelper::getStringParamSanitized('REQUEST', 'redirect', 'url');
48 + if ($location) {
48 49 wp_redirect($this->bvinfo->appUrl()."/dash/redir?q=".urlencode($location));
49 50 exit();
50 51 }
51 52 }
53 +
52 54 if ($this->bvinfo->isActivateRedirectSet()) {
53 55 $this->settings->updateOption($this->bvinfo->plug_redirect, 'no');
54 56 ##ACTIVATEREDIRECTCODE##
55 - wp_redirect($this->mainUrl());
57 + if (!wp_doing_ajax()) {
58 + wp_redirect($this->mainUrl());
59 + }
56 60 }
57 61 }
58 62
59 63 public function wprsecAdminMenu($hook) {
60 64 if ($hook === 'toplevel_page_wpremote' || WPRHelper::safePregMatch("/wpr_add_account$/", $hook) || WPRHelper::safePregMatch("/wpr_account_details$/", $hook)) {
61 - wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__));
62 - wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__));
65 + wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__), array(), $this->bvinfo->version);
66 + wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__), array(), $this->bvinfo->version);
67 + wp_enqueue_script( 'wpr-connection-key', plugins_url('js/connection-key.js', __FILE__), array(), $this->bvinfo->version, true);
63 68 }
64 69 }
65 70
66 71 public function menu() {
67 72 $brand = $this->bvinfo->getPluginWhitelabelInfo();
68 - if (!array_key_exists('hide', $brand) && !array_key_exists('hide_from_menu', $brand)) {
73 + $can_whitelabel = $this->bvinfo->canWhiteLabel();
74 + $hide_from_menu = array_key_exists('hide', $brand) || array_key_exists('hide_from_menu', $brand);
75 + if (!$can_whitelabel || !$hide_from_menu) {
69 76 $bname = $this->bvinfo->getBrandName();
70 77 $icon = $this->bvinfo->getBrandIcon();
71 78 add_menu_page($bname, $bname, 'manage_options', $this->bvinfo->plugname,
72 79 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
@@ -94,9 +101,10 @@
94 101 }
95 102 $whitelabel_info = $this->bvinfo->getPluginWhitelabelInfo($slug);
96 103 if (array_key_exists('hide_plugin_details', $whitelabel_info)) {
97 104 foreach ($plugin_metas as $pluginKey => $pluginValue) {
98 - if (strpos($pluginValue, sprintf('>%s<', translate('View details')))) {
105 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
106 + if (strpos($pluginValue, sprintf('>%s<', __('View details')))) {
99 107 unset($plugin_metas[$pluginKey]);
100 108 break;
101 109 }
102 110 }
@@ -136,12 +144,13 @@
136 144 }
137 145
138 146 public function settingsLink($links, $file) {
139 147 #XNOTE: Fix this
140 - if ( $file == plugin_basename( dirname(__FILE__).'/blogvault.php' ) ) {
148 + if ( $file == plugin_basename( dirname(__FILE__).'/plugin.php' ) ) {
141 149 $brand = $this->bvinfo->getPluginWhitelabelInfo();
142 150 if (!array_key_exists('hide_plugin_details', $brand)) {
143 - $links[] = '<a href="'.$this->mainUrl().'">'.__( 'Settings' ).'</a>';
151 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
152 + $links[] = '<a href="'.$this->mainUrl().'">'.__('Settings').'</a>';
144 153 }
145 154 }
146 155 return $links;
147 156 }
@@ -166,8 +175,10 @@
166 175 require_once dirname( __FILE__ ) . '/recover.php';
167 176 $bvnonce = wp_create_nonce("bvnonce");
168 177 $public = WPRAccount::getApiPublicKey($this->settings);
169 178 $secret = WPRRecover::defaultSecret($this->settings);
179 + $ctag = WPRRecover::connectionTag($this->settings);
180 + $server_ip = WPRHelper::getStringParamEscaped('SERVER', 'SERVER_ADDR', 'attr');
170 181 $tags = "<input type='hidden' name='url' value='".esc_attr($this->siteinfo->wpurl())."'/>\n".
171 182 "<input type='hidden' name='homeurl' value='".esc_attr($this->siteinfo->homeurl())."'/>\n".
172 183 "<input type='hidden' name='siteurl' value='".esc_attr($this->siteinfo->siteurl())."'/>\n".
173 184 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
@@ -173,11 +184,12 @@
173 184 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
174 185 "<input type='hidden' name='plug' value='".esc_attr($this->bvinfo->plugname)."'/>\n".
175 186 "<input type='hidden' name='adminurl' value='".esc_attr($this->mainUrl())."'/>\n".
176 187 "<input type='hidden' name='bvversion' value='".esc_attr($this->bvinfo->version)."'/>\n".
177 - "<input type='hidden' name='serverip' value='".esc_attr($_SERVER["SERVER_ADDR"])."'/>\n".
188 + "<input type='hidden' name='serverip' value='".$server_ip."'/>\n".
178 189 "<input type='hidden' name='abspath' value='".esc_attr(ABSPATH)."'/>\n".
179 190 "<input type='hidden' name='secret' value='".esc_attr($secret)."'/>\n".
191 + "<input type='hidden' name='bvctag' value='".esc_attr($ctag)."'/>\n".
180 192 "<input type='hidden' name='public' value='".esc_attr($public)."'/>\n".
181 193 "<input type='hidden' name='bvnonce' value='".esc_attr($bvnonce)."'/>\n";
182 194 return $tags;
183 195 }
@@ -202,13 +214,20 @@
202 214 require_once dirname( __FILE__ ) . "/admin/account_details.php";
203 215 }
204 216
205 217 public function adminPage() {
206 - if (isset($_REQUEST['bvnonce']) && wp_verify_nonce( $_REQUEST['bvnonce'], 'bvnonce' )) {
218 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
219 + if ($bvnonce && wp_verify_nonce($bvnonce, 'bvnonce')) {
207 220 $info = array();
208 221 $this->siteinfo->basic($info);
209 - $this->bvapi->pingbv('/bvapi/disconnect', $info, $_REQUEST['pubkey']);
210 - WPRAccount::remove($this->settings, $_REQUEST['pubkey']);
222 +
223 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
224 +
225 + if (!empty($pubkey)) {
226 + $pubkey = WPRAccount::sanitizeKey($pubkey);
227 + $this->bvapi->pingbv('/bvapi/disconnect', $info, $pubkey);
228 + WPRAccount::remove($this->settings, $pubkey);
229 + }
211 230 }
212 231 if (WPRAccount::isConfigured($this->settings)) {
213 232 if (!isset($_REQUEST['add_account'])) {
214 233 $this->showAccountDetailsPage();
@@ -257,5 +276,5 @@
257 276 }
258 277 return $plugins;
259 278 }
260 279 }
261 -endif;
280 +endif;