PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Providers/AdminAssetsProvider.php +201 -18 3.0.2.9 → 3.0.16 View file →
@@ -27,15 +27,28 @@
27 27 $capabilities = [];
28 28 if ($current_user->ID > 0) {
29 29 $user_caps = $current_user->allcaps;
30 30 foreach ($user_caps as $cap => $has_cap) {
31 - if ($has_cap && strpos((string) $cap, 'yatra_') === 0) {
32 - $capabilities[$cap] = true;
31 + if (!$has_cap) continue;
32 + // Mirror every `yatra_*` cap into the JS-side map (these
33 + // are what React's `can()` checks against). Also
34 + // explicitly include `manage_options` so the React-side
35 + // admin fallback has a server-confirmed signal even on
36 + // exotic installs where `isWpAdmin` or `roles` were
37 + // filtered out by a third-party plugin.
38 + $capStr = (string) $cap;
39 + if (strpos($capStr, 'yatra_') === 0 || $capStr === 'manage_options') {
40 + $capabilities[$capStr] = true;
33 41 }
34 42 }
35 43 }
36 44
37 45 return apply_filters('yatra_admin_localized_data', [
46 + 'timeZoneIdentifiers' => self::buildTimezoneIdentifierList(),
47 + 'wordPressTimezone' => function_exists('wp_timezone_string')
48 + ? (string) wp_timezone_string()
49 + : 'UTC',
50 + 'timezone' => \Yatra\Services\SettingsService::getString('timezone', 'UTC'),
38 51 'apiUrl' => rest_url('yatra/v1'),
39 52 'licenseStatus' => (function () {
40 53 $all = get_option('yatra_license', []);
41 54 $status = $all['yatra-pro']['status'] ?? 'inactive';
@@ -50,20 +63,104 @@
50 63 'currentUserAvatar' => get_avatar($current_user->ID, 96),
51 64 'siteUrl' => home_url(),
52 65 'adminUrl' => admin_url('admin.php'),
53 66 'pluginUrl' => YATRA_PLUGIN_URL,
67 + // Public URL of the Yatra sitemap (handles plain vs pretty
68 + // permalinks), shown in the SEO settings tab.
69 + 'sitemapUrl' => \Yatra\Sitemap\SitemapRouter::sitemapUrl(),
70 + // Brand-name and brand-logo helpers are filter-backed (defaults
71 + // wired in includes/helpers.php). Pro's WhiteLabel module
72 + // overrides the filters when Agency white-label is active.
54 73 'brandLogoUrl' => function_exists('yatra_get_brand_icon_url') ? yatra_get_brand_icon_url() : '',
74 + 'brandName' => function_exists('yatra_get_brand_name') ? yatra_get_brand_name() : 'Yatra',
75 + // White-label-specific window.yatraAdmin keys (brandMenuOverrides,
76 + // brandMenuOrder, brandUiChrome, brandPrimaryColor) are injected
77 + // by Pro via the `yatra_admin_localized_data` filter applied at
78 + // the bottom of this method. They are NOT set here because option
79 + // storage is owned by Pro's WhiteLabel module.
55 80 'permalinkStructure' => (get_option('permalink_structure') ?: '') ?: 'plain',
56 81 'tripBase' => \Yatra\Services\SettingsService::getTripBase(),
57 82 'bookingBase' => \Yatra\Services\SettingsService::getBookingBase(),
58 83 'capabilities' => $capabilities,
59 84 'roles' => $current_user->roles,
85 + // Cap-gating fallback flag. ALWAYS injected (not just by the
86 + // Team module) because the React `usePermissions.can()` helper
87 + // uses it as the last-resort allow for site owners: anyone
88 + // with `manage_options` passes any cap check, mirroring the
89 + // server-side admin fallback in Team's Capabilities filter.
90 + //
91 + // Without this, free-plugin installs (or Pro installs where
92 + // Team is off) silently fail every `can("yatra_*")` check —
93 + // even for site owners — because the cap isn't on the
94 + // administrator role record. The Team module overwrites
95 + // this same key when active; semantics are identical, so
96 + // the overwrite is safe.
97 + 'isWpAdmin' => current_user_can('manage_options'),
60 98 'isPro' => defined('YATRA_PRO_VERSION'),
99 + // Agency-tier flag — drives the sidebar's White Label entry visibility
100 + // and any other Agency-only UI affordances. Pro registers the filter
101 + // unconditionally so the value is always trustworthy.
102 + 'isAgency' => (bool) apply_filters('yatra_is_agency_active', false),
103 + // AI-eligibility flag (Growth + Agency). Drives the AI Assistant
104 + // sidebar entry visibility and the per-field sparkle affordances
105 + // in the trip / SEO editors.
106 + 'isAiEligible' => (bool) apply_filters('yatra_is_ai_eligible', false),
107 + 'whiteLabelEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
108 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('white_label')
109 + : false,
110 + 'aiAssistantEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
111 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('ai_assistant')
112 + : false,
113 + 'whatsappEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
114 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('whatsapp')
115 + : false,
116 + 'channelManagerEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
117 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('channel_manager')
118 + : false,
119 + 'webhooksEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
120 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('webhooks')
121 + : false,
122 + // Settings → Pricing (Discount Stacking) drives off these
123 + // two. Setting them here (free plugin, AdminAssetsProvider)
124 + // matches the pattern used by every other Pro-module flag
125 + // above and decouples the React UI from Pro module boot
126 + // timing — Pro's init.php is conditionally loaded by
127 + // ProModuleManager only when the module is enabled, so any
128 + // filter-based exposure could fail silently if boot order
129 + // shifts. Reading from the canonical ModuleManager here is
130 + // the source of truth.
131 + 'dynamicPricingEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
132 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('dynamic_pricing')
133 + : false,
134 + 'advancedDiscountEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
135 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('advanced_discount')
136 + : false,
137 + // Single source of truth for every country dropdown in the
138 + // React admin. Pulled from the canonical FormatHelper —
139 + // operators that want a curated or reordered list apply
140 + // the `yatra_countries_list` filter once and it propagates
141 + // to every dropdown automatically.
142 + 'countries' => class_exists('\\Yatra\\Helpers\\FormatHelper')
143 + ? \Yatra\Helpers\FormatHelper::getCountries()
144 + : [],
145 + 'customLandingPagesModuleEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
146 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('custom_landing_pages')
147 + : false,
148 + // Per-trip Deposit & Payment Terms is a Pro feature (FlexiblePayments).
149 + // Default false; Pro's FlexiblePaymentsModule::addAdminData() flips this
150 + // to true via the `yatra_admin_localized_data` filter when active, and
151 + // the React TripForm hides/shows the section based on this flag.
152 + 'flexiblePaymentsEnabled' => false,
61 153 'version' => defined('YATRA_VERSION') ? YATRA_VERSION : '1.0.0',
62 154 'proVersion' => defined('YATRA_PRO_VERSION') ? YATRA_PRO_VERSION : null,
63 155
64 156 'locale' => get_locale(),
65 157 'currency' => \Yatra\Services\SettingsService::getCurrency(),
158 + 'currencyPosition' => \Yatra\Services\SettingsService::getString('currency_position', 'left'),
159 + 'currency_position' => \Yatra\Services\SettingsService::getString('currency_position', 'left'),
160 + 'decimalPlaces' => \Yatra\Services\SettingsService::getPriceDecimals(),
161 + 'thousandSeparator' => \Yatra\Services\SettingsService::getString('thousand_separator', ','),
162 + 'decimalSeparator' => \Yatra\Services\SettingsService::getString('decimal_separator', '.'),
66 163 'date_format' => \Yatra\Services\SettingsService::get('date_format', 'Y-m-d'),
67 164 'time_format' => \Yatra\Services\SettingsService::get('time_format', 'H:i'),
68 165 'geocodingNonce' => wp_create_nonce('yatra_geocoding_nonce'),
69 166 'ajaxUrl' => admin_url('admin-ajax.php'),
@@ -70,8 +167,33 @@
70 167 ]);
71 168 }
72 169
73 170 /**
171 + * Sorted IANA identifiers for the admin timezone control (matches PHP {@see DateTimeZone}).
172 + *
173 + * @return list<string>
174 + */
175 + private static function buildTimezoneIdentifierList(): array
176 + {
177 + if (!function_exists('timezone_identifiers_list')) {
178 + return ['UTC'];
179 + }
180 +
181 + $ids = timezone_identifiers_list();
182 + if (!is_array($ids) || $ids === []) {
183 + return ['UTC'];
184 + }
185 +
186 + $ids = array_values(array_filter($ids, static function ($id): bool {
187 + return is_string($id) && $id !== '';
188 + }));
189 +
190 + sort($ids, SORT_STRING);
191 +
192 + return $ids;
193 + }
194 +
195 + /**
74 196 * Enqueue all admin assets
75 197 *
76 198 * @param string $hook Current admin page hook
77 199 * @return void
@@ -206,9 +328,20 @@
206 328 * @return void
207 329 */
208 330 private function enqueueAdminReactCss(): void
209 331 {
332 + $faPath = YATRA_PLUGIN_PATH . 'assets/vendor/fontawesome/css/all.min.css';
333 + if (file_exists($faPath)) {
334 + wp_enqueue_style(
335 + 'yatra-fontawesome-6-admin',
336 + YATRA_PLUGIN_URL . 'assets/vendor/fontawesome/css/all.min.css',
337 + [],
338 + '6.7.2.' . filemtime($faPath)
339 + );
340 + }
341 +
210 342 $basePath = YATRA_PLUGIN_PATH . 'assets/admin/dist/css/';
343 + $faHandle = file_exists($faPath) ? 'yatra-fontawesome-6-admin' : false;
211 344
212 345 // React vendor CSS (contains react-draft-wysiwyg CSS)
213 346 $reactVendorCss = $basePath . 'react-vendor.css';
214 347 if (file_exists($reactVendorCss)) {
@@ -215,9 +348,9 @@
215 348 $cssVersion = YATRA_VERSION . '.' . filemtime($reactVendorCss);
216 349 wp_enqueue_style(
217 350 'yatra-react-vendor',
218 351 YATRA_PLUGIN_URL . 'assets/admin/dist/css/react-vendor.css',
219 - [],
352 + $faHandle ? [$faHandle] : [],
220 353 $cssVersion
221 354 );
222 355 }
223 356
@@ -275,9 +408,17 @@
275 408 // Use built assets in production
276 409 $appJs = YATRA_PLUGIN_PATH . 'assets/admin/dist/js/app.js';
277 410
278 411 if (file_exists($appJs)) {
279 - $jsVersion = YATRA_VERSION . '.' . filemtime($appJs) . '.view-icon-fix.' . time() . '.' . microtime(true);
412 + // Version on the plugin version + the bundle's own mtime. That
413 + // already changes on every update or rebuild, which is exactly
414 + // when the cache must be busted.
415 + //
416 + // This previously appended time() . microtime(true), making the
417 + // URL unique on every single request — so the ~3 MB admin bundle
418 + // was re-downloaded on every admin page view and could never be
419 + // cached by the browser.
420 + $jsVersion = YATRA_VERSION . '.' . filemtime($appJs);
280 421
281 422 $localized_data = $this->buildAdminLocalizedData();
282 423
283 424 // Enqueue our script with media library as dependency
@@ -298,11 +439,31 @@
298 439 $jsVersion,
299 440 true
300 441 );
301 442
443 + // The bundle calls the global wp.i18n.__() (it never ships its
444 + // own copy), and scripts/extract-js-pot.mjs writes every admin
445 + // string's `#:` reference as this bundle's path precisely so
446 + // WordPress's md5(handle src) JSON lookup matches. This call is
447 + // the missing last link: it tells WordPress to load
448 + // i18n/languages/yatra-{locale}-{md5}.json (or the copy under
449 + // WP_LANG_DIR/plugins) for the admin UI. Without it, translated
450 + // admin strings never reach the SPA. Mirrors FrontendAssetsProvider.
451 + if (function_exists('wp_set_script_translations')) {
452 + wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_PATH . 'i18n/languages');
453 + }
454 +
302 455 // Localize script data
303 456 wp_localize_script('yatra-admin', 'yatraAdmin', $localized_data);
304 457
458 + // Phone dataset for admin displays (flag + dial-code detection of
459 + // stored "+<code><number>" values in booking details).
460 + wp_localize_script('yatra-admin', 'yatraPhoneData', [
461 + 'countries' => \Yatra\Helpers\FormatHelper::getPhoneCountries(),
462 + 'priority' => \Yatra\Helpers\FormatHelper::getPhonePriority(),
463 + 'flagBase' => YATRA_PLUGIN_URL . 'assets/img/flags/',
464 + ]);
465 +
305 466 // Start fetching the ES module as early as possible (helps shorten white/splash time before React runs)
306 467 $app_js_url = YATRA_PLUGIN_URL . 'assets/admin/dist/js/app.js';
307 468 add_action('admin_head', static function () use ($app_js_url, $jsVersion): void {
308 469 $href = esc_url(add_query_arg('ver', rawurlencode((string) $jsVersion), $app_js_url));
@@ -319,20 +480,23 @@
319 480 * @return bool
320 481 */
321 482 private function isViteDevServerRunning(string $url): bool
322 483 {
323 - // Check the actual asset URL, not the root
484 + // Check the actual asset URL, not the root. Uses the WP HTTP API
485 + // (not raw cURL) per WP.org guidelines. Only ever called in dev mode
486 + // (WP_DEBUG && YATRA_DEV_MODE), so it never runs on production loads.
324 487 $assetUrl = $url . '/assets/admin/dist/js/app.js';
325 - $ch = curl_init($assetUrl);
326 - curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
327 - curl_setopt($ch, CURLOPT_TIMEOUT, 2); // 2 second timeout
328 - curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 1); // 1 second connection timeout
329 - curl_setopt($ch, CURLOPT_NOBODY, true); // HEAD request only
330 - curl_exec($ch);
331 - $httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
332 - curl_close($ch);
333 -
334 - return $httpCode === 200;
488 +
489 + $response = wp_remote_head($assetUrl, [
490 + 'timeout' => 2,
491 + 'redirection' => 0,
492 + ]);
493 +
494 + if (is_wp_error($response)) {
495 + return false;
496 + }
497 +
498 + return (int) wp_remote_retrieve_response_code($response) === 200;
335 499 }
336 500
337 501 /**
338 502 * Add inline script for media library compatibility
@@ -352,14 +516,33 @@
352 516 * @return void
353 517 */
354 518 private function loadWordPressTranslations(): void
355 519 {
356 - // Use WordPress built-in function to load script translations
357 - // Specify the path where WordPress should look for JSON translation files
520 + // Use WordPress built-in function to load script translations.
521 + // The third argument MUST be an absolute path to the directory
522 + // that contains the per-locale .json translation files.
523 + //
524 + // Previously this passed YATRA_PLUGIN_FILE — i.e. the main
525 + // plugin PHP FILE path, not its directory. Appending
526 + // "/i18n/languages" yielded ".../plugin/yatra.php/i18n/languages",
527 + // a path that doesn't exist, so WordPress silently fell back to
528 + // shipping source-English strings to the React admin regardless
529 + // of the operator's WP locale.
530 + //
531 + // Use YATRA_PLUGIN_PATH (the directory, ending in /) instead,
532 + // matching the block-editor side that has always worked.
533 + //
534 + // The actual JSON file shipped here is generated at BUILD time
535 + // by scripts/build-translation-json.mjs from each locale's .po
536 + // file. That script writes ONE consolidated JSON per locale
537 + // named `yatra-{locale}-{md5(bundle src path)}.json`, so
538 + // WordPress's native script-translation loader finds it on
539 + // first try — no runtime filter / merge needed.
358 540 if (function_exists('wp_set_script_translations')) {
359 - wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_FILE . '/i18n/languages');
541 + wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_PATH . 'i18n/languages');
360 542 }
361 543 }
544 +
362 545
363 546 /**
364 547 * Enqueue setup wizard assets
365 548 *