| @@ -249,8 +249,14 @@ | ||
| 249 | 249 | $opts = $this->get_settings(); |
| 250 | 250 | if ( empty( $opts['enabled'] ) ) { |
| 251 | 251 | return; |
| 252 | 252 | } |
| 253 | + // Something else on the site is already the Cloudflare layer in front | |
| 254 | + // of it. The switch stays as the owner left it, and this zone is not | |
| 255 | + // purged while the block lasts. See Module::blocked_by(). | |
| 256 | + if ( null !== $this->blocked_by() ) { | |
| 257 | + return; | |
| 258 | + } | |
| 253 | 259 | if ( ! empty( $opts['auto_purge_on_update'] ) ) { |
| 254 | 260 | // xSpeed fires this action whenever it purges its own |
| 255 | 261 | // cache (see Cache::purge_all). Listening here keeps |
| 256 | 262 | // CF in sync without any new wiring elsewhere. |
| @@ -285,11 +291,12 @@ | ||
| 285 | 291 | |
| 286 | 292 | /** |
| 287 | 293 | * Mirror a single-URL purge at the edge. |
| 288 | 294 | * |
| 289 | - * NOT about post edits — `on_save_post()` calls `purge_all()`, so those | |
| 290 | - * have always reached Cloudflare through the full-purge listener above. | |
| 291 | - * What reaches `purge_url()` is the narrower set: the two admin purge | |
| 295 | + * Post edits arrive here too when they clear only their affected pages | |
| 296 | + * (`Cache::purge_urls()` publishes one event with every URL); an edit | |
| 297 | + * that clears the whole site comes through the full-purge listener | |
| 298 | + * above. What else reaches `purge_url()` is the narrower set: the two admin purge | |
| 292 | 299 | * buttons, an approved comment, a user change, a WooCommerce product or |
| 293 | 300 | * stock change, `--url` on the CLI and REST, and MCP. Every one of those |
| 294 | 301 | * cleared xSpeed's copy and left Cloudflare's, so the page stayed stale |
| 295 | 302 | * at the edge until its lifetime ran out or somebody pressed Purge All — |
| @@ -321,11 +328,11 @@ | ||
| 321 | 328 | if ( true !== $this->can_purge_edge() ) { |
| 322 | 329 | return; |
| 323 | 330 | } |
| 324 | 331 | |
| 325 | - // Collected and sent once, not one API call per URL. `Purge_Ui`'s | |
| 326 | - // post purge and the WooCommerce product path both fire a handful of | |
| 327 | - // these in a loop, and a round trip each would be a wait each. | |
| 332 | + // Collected and sent once, not one API call per URL. A request can | |
| 333 | + // raise several of these (a bulk edit, a stock change on each item | |
| 334 | + // of an order), and a round trip each would be a wait each. | |
| 328 | 335 | if ( array() === $this->pending_edge_urls ) { |
| 329 | 336 | add_action( 'shutdown', array( $this, 'flush_edge_url_purges' ), 20 ); |
| 330 | 337 | } |
| 331 | 338 | $blog = function_exists( 'get_current_blog_id' ) ? (int) get_current_blog_id() : 0; |
| @@ -331,8 +338,9 @@ | ||
| 331 | 338 | $blog = function_exists( 'get_current_blog_id' ) ? (int) get_current_blog_id() : 0; |
| 332 | 339 | foreach ( $urls as $url ) { |
| 333 | 340 | $this->pending_edge_urls[ $blog ][ $url ] = true; |
| 334 | 341 | } |
| 342 | + \XSpeed\Cache::note_purge_forwarded( 'Cloudflare' ); | |
| 335 | 343 | } |
| 336 | 344 | |
| 337 | 345 | /** |
| 338 | 346 | * Hand whatever `on_xspeed_purge_url()` collected to cron. |
| @@ -605,8 +613,12 @@ | ||
| 605 | 613 | $opts = $this->get_settings(); |
| 606 | 614 | if ( empty( $opts['enabled'] ) ) { |
| 607 | 615 | return __( 'the Cloudflare integration is switched off', 'xspeed' ); |
| 608 | 616 | } |
| 617 | + $blocked = $this->blocked_by(); | |
| 618 | + if ( null !== $blocked ) { | |
| 619 | + return $blocked; | |
| 620 | + } | |
| 609 | 621 | if ( ! $this->has_credentials( $opts ) ) { |
| 610 | 622 | return __( 'no zone ID or API credentials are configured', 'xspeed' ); |
| 611 | 623 | } |
| 612 | 624 | |
| @@ -674,17 +686,19 @@ | ||
| 674 | 686 | * Persist any settings sent with the save, then verify the credentials |
| 675 | 687 | * immediately so an invalid or newly-changed token surfaces on the panel |
| 676 | 688 | * instead of failing silently the next time xSpeed purges. Response shape |
| 677 | 689 | * is unchanged (flat settings) so the autosave client is unaffected. (#119) |
| 690 | + * | |
| 691 | + * The parent writes the settings, so its licence, blocked-by and | |
| 692 | + * wp-config refusals apply here too; a refused write is not verified. | |
| 678 | 693 | */ |
| 679 | 694 | public function rest_update_settings( \WP_REST_Request $request ) { |
| 680 | - $params = $request->get_json_params(); | |
| 681 | - if ( ! is_array( $params ) ) { | |
| 682 | - $params = $request->get_params(); | |
| 695 | + $response = parent::rest_update_settings( $request ); | |
| 696 | + if ( is_wp_error( $response ) ) { | |
| 697 | + return $response; | |
| 683 | 698 | } |
| 684 | - $settings = $this->update_settings( is_array( $params ) ? $params : array() ); | |
| 685 | 699 | $this->verify_and_record(); |
| 686 | - return rest_ensure_response( $settings ); | |
| 700 | + return $response; | |
| 687 | 701 | } |
| 688 | 702 | |
| 689 | 703 | public function rest_verify( \WP_REST_Request $request ) { |
| 690 | 704 | $res = Cloudflare::verify( $this->get_settings() ); |