PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Providers/AdminAssetsProvider.php +155 -18 3.0.3 → 3.0.16 View file →
@@ -27,10 +27,18 @@
27 27 $capabilities = [];
28 28 if ($current_user->ID > 0) {
29 29 $user_caps = $current_user->allcaps;
30 30 foreach ($user_caps as $cap => $has_cap) {
31 - if ($has_cap && strpos((string) $cap, 'yatra_') === 0) {
32 - $capabilities[$cap] = true;
31 + if (!$has_cap) continue;
32 + // Mirror every `yatra_*` cap into the JS-side map (these
33 + // are what React's `can()` checks against). Also
34 + // explicitly include `manage_options` so the React-side
35 + // admin fallback has a server-confirmed signal even on
36 + // exotic installs where `isWpAdmin` or `roles` were
37 + // filtered out by a third-party plugin.
38 + $capStr = (string) $cap;
39 + if (strpos($capStr, 'yatra_') === 0 || $capStr === 'manage_options') {
40 + $capabilities[$capStr] = true;
33 41 }
34 42 }
35 43 }
36 44
@@ -55,15 +63,94 @@
55 63 'currentUserAvatar' => get_avatar($current_user->ID, 96),
56 64 'siteUrl' => home_url(),
57 65 'adminUrl' => admin_url('admin.php'),
58 66 'pluginUrl' => YATRA_PLUGIN_URL,
67 + // Public URL of the Yatra sitemap (handles plain vs pretty
68 + // permalinks), shown in the SEO settings tab.
69 + 'sitemapUrl' => \Yatra\Sitemap\SitemapRouter::sitemapUrl(),
70 + // Brand-name and brand-logo helpers are filter-backed (defaults
71 + // wired in includes/helpers.php). Pro's WhiteLabel module
72 + // overrides the filters when Agency white-label is active.
59 73 'brandLogoUrl' => function_exists('yatra_get_brand_icon_url') ? yatra_get_brand_icon_url() : '',
74 + 'brandName' => function_exists('yatra_get_brand_name') ? yatra_get_brand_name() : 'Yatra',
75 + // White-label-specific window.yatraAdmin keys (brandMenuOverrides,
76 + // brandMenuOrder, brandUiChrome, brandPrimaryColor) are injected
77 + // by Pro via the `yatra_admin_localized_data` filter applied at
78 + // the bottom of this method. They are NOT set here because option
79 + // storage is owned by Pro's WhiteLabel module.
60 80 'permalinkStructure' => (get_option('permalink_structure') ?: '') ?: 'plain',
61 81 'tripBase' => \Yatra\Services\SettingsService::getTripBase(),
62 82 'bookingBase' => \Yatra\Services\SettingsService::getBookingBase(),
63 83 'capabilities' => $capabilities,
64 84 'roles' => $current_user->roles,
85 + // Cap-gating fallback flag. ALWAYS injected (not just by the
86 + // Team module) because the React `usePermissions.can()` helper
87 + // uses it as the last-resort allow for site owners: anyone
88 + // with `manage_options` passes any cap check, mirroring the
89 + // server-side admin fallback in Team's Capabilities filter.
90 + //
91 + // Without this, free-plugin installs (or Pro installs where
92 + // Team is off) silently fail every `can("yatra_*")` check —
93 + // even for site owners — because the cap isn't on the
94 + // administrator role record. The Team module overwrites
95 + // this same key when active; semantics are identical, so
96 + // the overwrite is safe.
97 + 'isWpAdmin' => current_user_can('manage_options'),
65 98 'isPro' => defined('YATRA_PRO_VERSION'),
99 + // Agency-tier flag — drives the sidebar's White Label entry visibility
100 + // and any other Agency-only UI affordances. Pro registers the filter
101 + // unconditionally so the value is always trustworthy.
102 + 'isAgency' => (bool) apply_filters('yatra_is_agency_active', false),
103 + // AI-eligibility flag (Growth + Agency). Drives the AI Assistant
104 + // sidebar entry visibility and the per-field sparkle affordances
105 + // in the trip / SEO editors.
106 + 'isAiEligible' => (bool) apply_filters('yatra_is_ai_eligible', false),
107 + 'whiteLabelEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
108 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('white_label')
109 + : false,
110 + 'aiAssistantEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
111 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('ai_assistant')
112 + : false,
113 + 'whatsappEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
114 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('whatsapp')
115 + : false,
116 + 'channelManagerEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
117 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('channel_manager')
118 + : false,
119 + 'webhooksEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
120 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('webhooks')
121 + : false,
122 + // Settings → Pricing (Discount Stacking) drives off these
123 + // two. Setting them here (free plugin, AdminAssetsProvider)
124 + // matches the pattern used by every other Pro-module flag
125 + // above and decouples the React UI from Pro module boot
126 + // timing — Pro's init.php is conditionally loaded by
127 + // ProModuleManager only when the module is enabled, so any
128 + // filter-based exposure could fail silently if boot order
129 + // shifts. Reading from the canonical ModuleManager here is
130 + // the source of truth.
131 + 'dynamicPricingEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
132 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('dynamic_pricing')
133 + : false,
134 + 'advancedDiscountEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
135 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('advanced_discount')
136 + : false,
137 + // Single source of truth for every country dropdown in the
138 + // React admin. Pulled from the canonical FormatHelper —
139 + // operators that want a curated or reordered list apply
140 + // the `yatra_countries_list` filter once and it propagates
141 + // to every dropdown automatically.
142 + 'countries' => class_exists('\\Yatra\\Helpers\\FormatHelper')
143 + ? \Yatra\Helpers\FormatHelper::getCountries()
144 + : [],
145 + 'customLandingPagesModuleEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
146 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('custom_landing_pages')
147 + : false,
148 + // Per-trip Deposit & Payment Terms is a Pro feature (FlexiblePayments).
149 + // Default false; Pro's FlexiblePaymentsModule::addAdminData() flips this
150 + // to true via the `yatra_admin_localized_data` filter when active, and
151 + // the React TripForm hides/shows the section based on this flag.
152 + 'flexiblePaymentsEnabled' => false,
66 153 'version' => defined('YATRA_VERSION') ? YATRA_VERSION : '1.0.0',
67 154 'proVersion' => defined('YATRA_PRO_VERSION') ? YATRA_PRO_VERSION : null,
68 155
69 156 'locale' => get_locale(),
@@ -69,9 +156,9 @@
69 156 'locale' => get_locale(),
70 157 'currency' => \Yatra\Services\SettingsService::getCurrency(),
71 158 'currencyPosition' => \Yatra\Services\SettingsService::getString('currency_position', 'left'),
72 159 'currency_position' => \Yatra\Services\SettingsService::getString('currency_position', 'left'),
73 - 'decimalPlaces' => (int) \Yatra\Services\SettingsService::getString('currency_decimals', '2'),
160 + 'decimalPlaces' => \Yatra\Services\SettingsService::getPriceDecimals(),
74 161 'thousandSeparator' => \Yatra\Services\SettingsService::getString('thousand_separator', ','),
75 162 'decimalSeparator' => \Yatra\Services\SettingsService::getString('decimal_separator', '.'),
76 163 'date_format' => \Yatra\Services\SettingsService::get('date_format', 'Y-m-d'),
77 164 'time_format' => \Yatra\Services\SettingsService::get('time_format', 'H:i'),
@@ -321,9 +408,17 @@
321 408 // Use built assets in production
322 409 $appJs = YATRA_PLUGIN_PATH . 'assets/admin/dist/js/app.js';
323 410
324 411 if (file_exists($appJs)) {
325 - $jsVersion = YATRA_VERSION . '.' . filemtime($appJs) . '.view-icon-fix.' . time() . '.' . microtime(true);
412 + // Version on the plugin version + the bundle's own mtime. That
413 + // already changes on every update or rebuild, which is exactly
414 + // when the cache must be busted.
415 + //
416 + // This previously appended time() . microtime(true), making the
417 + // URL unique on every single request — so the ~3 MB admin bundle
418 + // was re-downloaded on every admin page view and could never be
419 + // cached by the browser.
420 + $jsVersion = YATRA_VERSION . '.' . filemtime($appJs);
326 421
327 422 $localized_data = $this->buildAdminLocalizedData();
328 423
329 424 // Enqueue our script with media library as dependency
@@ -344,11 +439,31 @@
344 439 $jsVersion,
345 440 true
346 441 );
347 442
443 + // The bundle calls the global wp.i18n.__() (it never ships its
444 + // own copy), and scripts/extract-js-pot.mjs writes every admin
445 + // string's `#:` reference as this bundle's path precisely so
446 + // WordPress's md5(handle src) JSON lookup matches. This call is
447 + // the missing last link: it tells WordPress to load
448 + // i18n/languages/yatra-{locale}-{md5}.json (or the copy under
449 + // WP_LANG_DIR/plugins) for the admin UI. Without it, translated
450 + // admin strings never reach the SPA. Mirrors FrontendAssetsProvider.
451 + if (function_exists('wp_set_script_translations')) {
452 + wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_PATH . 'i18n/languages');
453 + }
454 +
348 455 // Localize script data
349 456 wp_localize_script('yatra-admin', 'yatraAdmin', $localized_data);
350 457
458 + // Phone dataset for admin displays (flag + dial-code detection of
459 + // stored "+<code><number>" values in booking details).
460 + wp_localize_script('yatra-admin', 'yatraPhoneData', [
461 + 'countries' => \Yatra\Helpers\FormatHelper::getPhoneCountries(),
462 + 'priority' => \Yatra\Helpers\FormatHelper::getPhonePriority(),
463 + 'flagBase' => YATRA_PLUGIN_URL . 'assets/img/flags/',
464 + ]);
465 +
351 466 // Start fetching the ES module as early as possible (helps shorten white/splash time before React runs)
352 467 $app_js_url = YATRA_PLUGIN_URL . 'assets/admin/dist/js/app.js';
353 468 add_action('admin_head', static function () use ($app_js_url, $jsVersion): void {
354 469 $href = esc_url(add_query_arg('ver', rawurlencode((string) $jsVersion), $app_js_url));
@@ -365,20 +480,23 @@
365 480 * @return bool
366 481 */
367 482 private function isViteDevServerRunning(string $url): bool
368 483 {
369 - // Check the actual asset URL, not the root
484 + // Check the actual asset URL, not the root. Uses the WP HTTP API
485 + // (not raw cURL) per WP.org guidelines. Only ever called in dev mode
486 + // (WP_DEBUG && YATRA_DEV_MODE), so it never runs on production loads.
370 487 $assetUrl = $url . '/assets/admin/dist/js/app.js';
371 - $ch = curl_init($assetUrl);
372 - curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
373 - curl_setopt($ch, CURLOPT_TIMEOUT, 2); // 2 second timeout
374 - curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 1); // 1 second connection timeout
375 - curl_setopt($ch, CURLOPT_NOBODY, true); // HEAD request only
376 - curl_exec($ch);
377 - $httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
378 - curl_close($ch);
379 -
380 - return $httpCode === 200;
488 +
489 + $response = wp_remote_head($assetUrl, [
490 + 'timeout' => 2,
491 + 'redirection' => 0,
492 + ]);
493 +
494 + if (is_wp_error($response)) {
495 + return false;
496 + }
497 +
498 + return (int) wp_remote_retrieve_response_code($response) === 200;
381 499 }
382 500
383 501 /**
384 502 * Add inline script for media library compatibility
@@ -398,14 +516,33 @@
398 516 * @return void
399 517 */
400 518 private function loadWordPressTranslations(): void
401 519 {
402 - // Use WordPress built-in function to load script translations
403 - // Specify the path where WordPress should look for JSON translation files
520 + // Use WordPress built-in function to load script translations.
521 + // The third argument MUST be an absolute path to the directory
522 + // that contains the per-locale .json translation files.
523 + //
524 + // Previously this passed YATRA_PLUGIN_FILE — i.e. the main
525 + // plugin PHP FILE path, not its directory. Appending
526 + // "/i18n/languages" yielded ".../plugin/yatra.php/i18n/languages",
527 + // a path that doesn't exist, so WordPress silently fell back to
528 + // shipping source-English strings to the React admin regardless
529 + // of the operator's WP locale.
530 + //
531 + // Use YATRA_PLUGIN_PATH (the directory, ending in /) instead,
532 + // matching the block-editor side that has always worked.
533 + //
534 + // The actual JSON file shipped here is generated at BUILD time
535 + // by scripts/build-translation-json.mjs from each locale's .po
536 + // file. That script writes ONE consolidated JSON per locale
537 + // named `yatra-{locale}-{md5(bundle src path)}.json`, so
538 + // WordPress's native script-translation loader finds it on
539 + // first try — no runtime filter / merge needed.
404 540 if (function_exists('wp_set_script_translations')) {
405 - wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_FILE . '/i18n/languages');
541 + wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_PATH . 'i18n/languages');
406 542 }
407 543 }
544 +
408 545
409 546 /**
410 547 * Enqueue setup wizard assets
411 548 *