PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | wp_admin.php +37 -20 5.72trunk View file →
@@ -24,9 +24,9 @@
24 24 }
25 25 }
26 26
27 27 function removeAdminNotices() {
28 - if (array_key_exists('page', $_REQUEST) && $_REQUEST['page'] == $this->bvinfo->plugname) {
28 + if (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname) {
29 29 remove_all_actions('admin_notices');
30 30 remove_all_actions('all_admin_notices');
31 31 }
32 32 }
@@ -33,23 +33,25 @@
33 33
34 34 public function initHandler() {
35 35 if (!current_user_can('activate_plugins'))
36 36 return;
37 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
38 + $blogvaultkey = WPRHelper::getRawParam('REQUEST', 'blogvaultkey');
39 + $blogvaultkey = $blogvaultkey ? WPRAccount::sanitizeKey($blogvaultkey) : "";
37 40
38 - if (array_key_exists('bvnonce', $_REQUEST) &&
39 - wp_verify_nonce($_REQUEST['bvnonce'], "bvnonce") &&
40 - array_key_exists('blogvaultkey', $_REQUEST) &&
41 - (strlen(WPRAccount::sanitizeKey($_REQUEST['blogvaultkey'])) == 64) &&
42 - (array_key_exists('page', $_REQUEST) &&
43 - $_REQUEST['page'] == $this->bvinfo->plugname)) {
44 - $keys = str_split($_REQUEST['blogvaultkey'], 32);
41 + if ($bvnonce && wp_verify_nonce($bvnonce, "bvnonce") &&
42 + $blogvaultkey && strlen($blogvaultkey) == 64 &&
43 + (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname)) {
44 + $keys = str_split($blogvaultkey, 32);
45 45 WPRAccount::addAccount($this->settings, $keys[0], $keys[1]);
46 - if (array_key_exists('redirect', $_REQUEST)) {
47 - $location = $_REQUEST['redirect'];
46 +
47 + $location = WPRHelper::getStringParamSanitized('REQUEST', 'redirect', 'url');
48 + if ($location) {
48 49 wp_redirect($this->bvinfo->appUrl()."/dash/redir?q=".urlencode($location));
49 50 exit();
50 51 }
51 52 }
53 +
52 54 if ($this->bvinfo->isActivateRedirectSet()) {
53 55 $this->settings->updateOption($this->bvinfo->plug_redirect, 'no');
54 56 ##ACTIVATEREDIRECTCODE##
55 57 if (!wp_doing_ajax()) {
@@ -59,16 +61,19 @@
59 61 }
60 62
61 63 public function wprsecAdminMenu($hook) {
62 64 if ($hook === 'toplevel_page_wpremote' || WPRHelper::safePregMatch("/wpr_add_account$/", $hook) || WPRHelper::safePregMatch("/wpr_account_details$/", $hook)) {
63 - wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__));
64 - wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__));
65 + wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__), array(), $this->bvinfo->version);
66 + wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__), array(), $this->bvinfo->version);
67 + wp_enqueue_script( 'wpr-connection-key', plugins_url('js/connection-key.js', __FILE__), array(), $this->bvinfo->version, true);
65 68 }
66 69 }
67 70
68 71 public function menu() {
69 72 $brand = $this->bvinfo->getPluginWhitelabelInfo();
70 - if (!array_key_exists('hide', $brand) && !array_key_exists('hide_from_menu', $brand)) {
73 + $can_whitelabel = $this->bvinfo->canWhiteLabel();
74 + $hide_from_menu = array_key_exists('hide', $brand) || array_key_exists('hide_from_menu', $brand);
75 + if (!$can_whitelabel || !$hide_from_menu) {
71 76 $bname = $this->bvinfo->getBrandName();
72 77 $icon = $this->bvinfo->getBrandIcon();
73 78 add_menu_page($bname, $bname, 'manage_options', $this->bvinfo->plugname,
74 79 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
@@ -96,9 +101,10 @@
96 101 }
97 102 $whitelabel_info = $this->bvinfo->getPluginWhitelabelInfo($slug);
98 103 if (array_key_exists('hide_plugin_details', $whitelabel_info)) {
99 104 foreach ($plugin_metas as $pluginKey => $pluginValue) {
100 - if (strpos($pluginValue, sprintf('>%s<', translate('View details')))) {
105 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
106 + if (strpos($pluginValue, sprintf('>%s<', __('View details')))) {
101 107 unset($plugin_metas[$pluginKey]);
102 108 break;
103 109 }
104 110 }
@@ -141,9 +147,10 @@
141 147 #XNOTE: Fix this
142 148 if ( $file == plugin_basename( dirname(__FILE__).'/plugin.php' ) ) {
143 149 $brand = $this->bvinfo->getPluginWhitelabelInfo();
144 150 if (!array_key_exists('hide_plugin_details', $brand)) {
145 - $links[] = '<a href="'.$this->mainUrl().'">'.__( 'Settings' ).'</a>';
151 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
152 + $links[] = '<a href="'.$this->mainUrl().'">'.__('Settings').'</a>';
146 153 }
147 154 }
148 155 return $links;
149 156 }
@@ -168,8 +175,10 @@
168 175 require_once dirname( __FILE__ ) . '/recover.php';
169 176 $bvnonce = wp_create_nonce("bvnonce");
170 177 $public = WPRAccount::getApiPublicKey($this->settings);
171 178 $secret = WPRRecover::defaultSecret($this->settings);
179 + $ctag = WPRRecover::connectionTag($this->settings);
180 + $server_ip = WPRHelper::getStringParamEscaped('SERVER', 'SERVER_ADDR', 'attr');
172 181 $tags = "<input type='hidden' name='url' value='".esc_attr($this->siteinfo->wpurl())."'/>\n".
173 182 "<input type='hidden' name='homeurl' value='".esc_attr($this->siteinfo->homeurl())."'/>\n".
174 183 "<input type='hidden' name='siteurl' value='".esc_attr($this->siteinfo->siteurl())."'/>\n".
175 184 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
@@ -175,11 +184,12 @@
175 184 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
176 185 "<input type='hidden' name='plug' value='".esc_attr($this->bvinfo->plugname)."'/>\n".
177 186 "<input type='hidden' name='adminurl' value='".esc_attr($this->mainUrl())."'/>\n".
178 187 "<input type='hidden' name='bvversion' value='".esc_attr($this->bvinfo->version)."'/>\n".
179 - "<input type='hidden' name='serverip' value='".esc_attr($_SERVER["SERVER_ADDR"])."'/>\n".
188 + "<input type='hidden' name='serverip' value='".$server_ip."'/>\n".
180 189 "<input type='hidden' name='abspath' value='".esc_attr(ABSPATH)."'/>\n".
181 190 "<input type='hidden' name='secret' value='".esc_attr($secret)."'/>\n".
191 + "<input type='hidden' name='bvctag' value='".esc_attr($ctag)."'/>\n".
182 192 "<input type='hidden' name='public' value='".esc_attr($public)."'/>\n".
183 193 "<input type='hidden' name='bvnonce' value='".esc_attr($bvnonce)."'/>\n";
184 194 return $tags;
185 195 }
@@ -204,13 +214,20 @@
204 214 require_once dirname( __FILE__ ) . "/admin/account_details.php";
205 215 }
206 216
207 217 public function adminPage() {
208 - if (isset($_REQUEST['bvnonce']) && wp_verify_nonce( $_REQUEST['bvnonce'], 'bvnonce' )) {
218 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
219 + if ($bvnonce && wp_verify_nonce($bvnonce, 'bvnonce')) {
209 220 $info = array();
210 221 $this->siteinfo->basic($info);
211 - $this->bvapi->pingbv('/bvapi/disconnect', $info, $_REQUEST['pubkey']);
212 - WPRAccount::remove($this->settings, $_REQUEST['pubkey']);
222 +
223 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
224 +
225 + if (!empty($pubkey)) {
226 + $pubkey = WPRAccount::sanitizeKey($pubkey);
227 + $this->bvapi->pingbv('/bvapi/disconnect', $info, $pubkey);
228 + WPRAccount::remove($this->settings, $pubkey);
229 + }
213 230 }
214 231 if (WPRAccount::isConfigured($this->settings)) {
215 232 if (!isset($_REQUEST['add_account'])) {
216 233 $this->showAccountDetailsPage();
@@ -259,5 +276,5 @@
259 276 }
260 277 return $plugins;
261 278 }
262 279 }
263 -endif;
280 +endif;