PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Shortcodes/LoginShortcode.php +34 -11 3.0.2.7 → 3.0.16 View file →
@@ -3,8 +3,10 @@
3 3 declare(strict_types=1);
4 4
5 5 namespace Yatra\Shortcodes;
6 6
7 +use Yatra\Services\SettingsService;
8 +
7 9 /**
8 10 * Login Shortcode
9 11 *
10 12 * Displays customer login form
@@ -48,17 +50,26 @@
48 50 // Enqueue JavaScript
49 51 wp_enqueue_script(
50 52 'yatra-login-shortcode',
51 53 YATRA_PLUGIN_URL . 'assets/js/login-shortcode.js',
52 - ['jquery'],
54 + ['jquery', 'wp-i18n'],
53 55 YATRA_VERSION,
54 56 true
55 57 );
58 + if (function_exists('wp_set_script_translations')) {
59 + wp_set_script_translations(
60 + 'yatra-login-shortcode',
61 + 'yatra',
62 + YATRA_PLUGIN_PATH . 'i18n/languages'
63 + );
64 + }
56 65
57 66 // Localize script for AJAX with security and debugging
58 67 wp_localize_script('yatra-login-shortcode', 'yatra_ajax', [
59 68 'ajax_url' => admin_url('admin-ajax.php'),
60 69 'nonce' => wp_create_nonce('yatra_login_nonce'),
70 + 'rest_url' => esc_url_raw(rest_url('yatra/v1')),
71 + 'rest_nonce' => wp_create_nonce('wp_rest'),
61 72 'debug' => defined('WP_DEBUG') && WP_DEBUG,
62 73 'strings' => [
63 74 'login_error' => __('Login failed. Please try again.', 'yatra'),
64 75 'network_error' => __('Network error. Please check your connection.', 'yatra'),
@@ -72,12 +83,24 @@
72 83 */
73 84 protected function renderContent(array $atts): string
74 85 {
75 86 $atts = shortcode_atts($this->default_attributes, $atts, $this->tag);
76 -
87 +
77 88 // Sanitize and validate attributes
78 89 $atts = $this->sanitizeAttributes($atts);
79 -
90 +
91 + // Translate the built-in default title/subtitle at render time. The
92 + // defaults are stored as raw English in the constructor because __()
93 + // must not run that early (before init) — doing so triggers WordPress's
94 + // just-in-time textdomain notice. A custom title/subtitle set by the
95 + // operator on the shortcode passes through unchanged.
96 + if ($atts['title'] === 'Customer Login') {
97 + $atts['title'] = __('Customer Login', 'yatra');
98 + }
99 + if ($atts['subtitle'] === 'Login to access your bookings and account') {
100 + $atts['subtitle'] = __('Login to access your bookings and account', 'yatra');
101 + }
102 +
80 103 // Check if user is already logged in
81 104 if (is_user_logged_in()) {
82 105 return $this->renderLoggedInMessage($atts);
83 106 }
@@ -99,13 +122,11 @@
99 122 ob_start();
100 123 try {
101 124 include $template_path;
102 125 $content = ob_get_clean();
103 - } catch (Exception $e) {
126 + } catch (\Exception $e) {
104 127 ob_end_clean();
105 - if (defined('WP_DEBUG') && WP_DEBUG) {
106 - error_log('Yatra Login Shortcode Error: ' . $e->getMessage());
107 - }
128 +
108 129 $content = $this->renderFallbackError();
109 130 }
110 131
111 132 // Clean up query vars
@@ -120,9 +141,9 @@
120 141 */
121 142 private function renderLoggedInMessage(array $atts): string
122 143 {
123 144 $user = wp_get_current_user();
124 - $account_url = home_url('/my-account');
145 + $account_url = home_url('/' . SettingsService::getAccountBase());
125 146
126 147 ob_start();
127 148 ?>
128 149 <div class="yatra-login-logged-in">
@@ -131,10 +152,11 @@
131 152 <?php echo yatra_svg_icon('user', 'yatra-logged-in-icon-svg'); ?>
132 153 </div>
133 154 <h3><?php esc_html_e('Already Logged In', 'yatra'); ?></h3>
134 155 <p>
135 - <?php
156 + <?php
136 157 printf(
158 + /* translators: %s: logged-in user's display name. */
137 159 esc_html__('You are logged in as %s.', 'yatra'),
138 160 '<strong>' . esc_html($user->display_name) . '</strong>'
139 161 );
140 162 ?>
@@ -185,10 +207,11 @@
185 207 }
186 208 }
187 209 }
188 210
189 - // Fallback to safe defaults
190 - return wp_get_referer() ?: home_url('/my-account');
211 + // Default: always send users to the account area after login.
212 + // Avoid wp_get_referer() here to prevent redirect loops back to the login form.
213 + return home_url('/' . SettingsService::getAccountBase());
191 214 }
192 215
193 216 /**
194 217 * Render fallback error message