PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Providers/AdminAssetsProvider.php +147 -18 3.0.4 → 3.0.16 View file →
@@ -27,10 +27,18 @@
27 27 $capabilities = [];
28 28 if ($current_user->ID > 0) {
29 29 $user_caps = $current_user->allcaps;
30 30 foreach ($user_caps as $cap => $has_cap) {
31 - if ($has_cap && strpos((string) $cap, 'yatra_') === 0) {
32 - $capabilities[$cap] = true;
31 + if (!$has_cap) continue;
32 + // Mirror every `yatra_*` cap into the JS-side map (these
33 + // are what React's `can()` checks against). Also
34 + // explicitly include `manage_options` so the React-side
35 + // admin fallback has a server-confirmed signal even on
36 + // exotic installs where `isWpAdmin` or `roles` were
37 + // filtered out by a third-party plugin.
38 + $capStr = (string) $cap;
39 + if (strpos($capStr, 'yatra_') === 0 || $capStr === 'manage_options') {
40 + $capabilities[$capStr] = true;
33 41 }
34 42 }
35 43 }
36 44
@@ -55,15 +63,86 @@
55 63 'currentUserAvatar' => get_avatar($current_user->ID, 96),
56 64 'siteUrl' => home_url(),
57 65 'adminUrl' => admin_url('admin.php'),
58 66 'pluginUrl' => YATRA_PLUGIN_URL,
67 + // Public URL of the Yatra sitemap (handles plain vs pretty
68 + // permalinks), shown in the SEO settings tab.
69 + 'sitemapUrl' => \Yatra\Sitemap\SitemapRouter::sitemapUrl(),
70 + // Brand-name and brand-logo helpers are filter-backed (defaults
71 + // wired in includes/helpers.php). Pro's WhiteLabel module
72 + // overrides the filters when Agency white-label is active.
59 73 'brandLogoUrl' => function_exists('yatra_get_brand_icon_url') ? yatra_get_brand_icon_url() : '',
74 + 'brandName' => function_exists('yatra_get_brand_name') ? yatra_get_brand_name() : 'Yatra',
75 + // White-label-specific window.yatraAdmin keys (brandMenuOverrides,
76 + // brandMenuOrder, brandUiChrome, brandPrimaryColor) are injected
77 + // by Pro via the `yatra_admin_localized_data` filter applied at
78 + // the bottom of this method. They are NOT set here because option
79 + // storage is owned by Pro's WhiteLabel module.
60 80 'permalinkStructure' => (get_option('permalink_structure') ?: '') ?: 'plain',
61 81 'tripBase' => \Yatra\Services\SettingsService::getTripBase(),
62 82 'bookingBase' => \Yatra\Services\SettingsService::getBookingBase(),
63 83 'capabilities' => $capabilities,
64 84 'roles' => $current_user->roles,
85 + // Cap-gating fallback flag. ALWAYS injected (not just by the
86 + // Team module) because the React `usePermissions.can()` helper
87 + // uses it as the last-resort allow for site owners: anyone
88 + // with `manage_options` passes any cap check, mirroring the
89 + // server-side admin fallback in Team's Capabilities filter.
90 + //
91 + // Without this, free-plugin installs (or Pro installs where
92 + // Team is off) silently fail every `can("yatra_*")` check —
93 + // even for site owners — because the cap isn't on the
94 + // administrator role record. The Team module overwrites
95 + // this same key when active; semantics are identical, so
96 + // the overwrite is safe.
97 + 'isWpAdmin' => current_user_can('manage_options'),
65 98 'isPro' => defined('YATRA_PRO_VERSION'),
99 + // Agency-tier flag — drives the sidebar's White Label entry visibility
100 + // and any other Agency-only UI affordances. Pro registers the filter
101 + // unconditionally so the value is always trustworthy.
102 + 'isAgency' => (bool) apply_filters('yatra_is_agency_active', false),
103 + // AI-eligibility flag (Growth + Agency). Drives the AI Assistant
104 + // sidebar entry visibility and the per-field sparkle affordances
105 + // in the trip / SEO editors.
106 + 'isAiEligible' => (bool) apply_filters('yatra_is_ai_eligible', false),
107 + 'whiteLabelEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
108 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('white_label')
109 + : false,
110 + 'aiAssistantEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
111 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('ai_assistant')
112 + : false,
113 + 'whatsappEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
114 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('whatsapp')
115 + : false,
116 + 'channelManagerEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
117 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('channel_manager')
118 + : false,
119 + 'webhooksEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
120 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('webhooks')
121 + : false,
122 + // Settings → Pricing (Discount Stacking) drives off these
123 + // two. Setting them here (free plugin, AdminAssetsProvider)
124 + // matches the pattern used by every other Pro-module flag
125 + // above and decouples the React UI from Pro module boot
126 + // timing — Pro's init.php is conditionally loaded by
127 + // ProModuleManager only when the module is enabled, so any
128 + // filter-based exposure could fail silently if boot order
129 + // shifts. Reading from the canonical ModuleManager here is
130 + // the source of truth.
131 + 'dynamicPricingEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
132 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('dynamic_pricing')
133 + : false,
134 + 'advancedDiscountEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
135 + ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('advanced_discount')
136 + : false,
137 + // Single source of truth for every country dropdown in the
138 + // React admin. Pulled from the canonical FormatHelper —
139 + // operators that want a curated or reordered list apply
140 + // the `yatra_countries_list` filter once and it propagates
141 + // to every dropdown automatically.
142 + 'countries' => class_exists('\\Yatra\\Helpers\\FormatHelper')
143 + ? \Yatra\Helpers\FormatHelper::getCountries()
144 + : [],
66 145 'customLandingPagesModuleEnabled' => class_exists('\\Yatra\\Core\\Modules\\ModuleManager')
67 146 ? \Yatra\Core\Modules\ModuleManager::isModuleEnabled('custom_landing_pages')
68 147 : false,
69 148 // Per-trip Deposit & Payment Terms is a Pro feature (FlexiblePayments).
@@ -77,9 +156,9 @@
77 156 'locale' => get_locale(),
78 157 'currency' => \Yatra\Services\SettingsService::getCurrency(),
79 158 'currencyPosition' => \Yatra\Services\SettingsService::getString('currency_position', 'left'),
80 159 'currency_position' => \Yatra\Services\SettingsService::getString('currency_position', 'left'),
81 - 'decimalPlaces' => (int) \Yatra\Services\SettingsService::getString('currency_decimals', '2'),
160 + 'decimalPlaces' => \Yatra\Services\SettingsService::getPriceDecimals(),
82 161 'thousandSeparator' => \Yatra\Services\SettingsService::getString('thousand_separator', ','),
83 162 'decimalSeparator' => \Yatra\Services\SettingsService::getString('decimal_separator', '.'),
84 163 'date_format' => \Yatra\Services\SettingsService::get('date_format', 'Y-m-d'),
85 164 'time_format' => \Yatra\Services\SettingsService::get('time_format', 'H:i'),
@@ -329,9 +408,17 @@
329 408 // Use built assets in production
330 409 $appJs = YATRA_PLUGIN_PATH . 'assets/admin/dist/js/app.js';
331 410
332 411 if (file_exists($appJs)) {
333 - $jsVersion = YATRA_VERSION . '.' . filemtime($appJs) . '.view-icon-fix.' . time() . '.' . microtime(true);
412 + // Version on the plugin version + the bundle's own mtime. That
413 + // already changes on every update or rebuild, which is exactly
414 + // when the cache must be busted.
415 + //
416 + // This previously appended time() . microtime(true), making the
417 + // URL unique on every single request — so the ~3 MB admin bundle
418 + // was re-downloaded on every admin page view and could never be
419 + // cached by the browser.
420 + $jsVersion = YATRA_VERSION . '.' . filemtime($appJs);
334 421
335 422 $localized_data = $this->buildAdminLocalizedData();
336 423
337 424 // Enqueue our script with media library as dependency
@@ -352,11 +439,31 @@
352 439 $jsVersion,
353 440 true
354 441 );
355 442
443 + // The bundle calls the global wp.i18n.__() (it never ships its
444 + // own copy), and scripts/extract-js-pot.mjs writes every admin
445 + // string's `#:` reference as this bundle's path precisely so
446 + // WordPress's md5(handle src) JSON lookup matches. This call is
447 + // the missing last link: it tells WordPress to load
448 + // i18n/languages/yatra-{locale}-{md5}.json (or the copy under
449 + // WP_LANG_DIR/plugins) for the admin UI. Without it, translated
450 + // admin strings never reach the SPA. Mirrors FrontendAssetsProvider.
451 + if (function_exists('wp_set_script_translations')) {
452 + wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_PATH . 'i18n/languages');
453 + }
454 +
356 455 // Localize script data
357 456 wp_localize_script('yatra-admin', 'yatraAdmin', $localized_data);
358 457
458 + // Phone dataset for admin displays (flag + dial-code detection of
459 + // stored "+<code><number>" values in booking details).
460 + wp_localize_script('yatra-admin', 'yatraPhoneData', [
461 + 'countries' => \Yatra\Helpers\FormatHelper::getPhoneCountries(),
462 + 'priority' => \Yatra\Helpers\FormatHelper::getPhonePriority(),
463 + 'flagBase' => YATRA_PLUGIN_URL . 'assets/img/flags/',
464 + ]);
465 +
359 466 // Start fetching the ES module as early as possible (helps shorten white/splash time before React runs)
360 467 $app_js_url = YATRA_PLUGIN_URL . 'assets/admin/dist/js/app.js';
361 468 add_action('admin_head', static function () use ($app_js_url, $jsVersion): void {
362 469 $href = esc_url(add_query_arg('ver', rawurlencode((string) $jsVersion), $app_js_url));
@@ -373,20 +480,23 @@
373 480 * @return bool
374 481 */
375 482 private function isViteDevServerRunning(string $url): bool
376 483 {
377 - // Check the actual asset URL, not the root
484 + // Check the actual asset URL, not the root. Uses the WP HTTP API
485 + // (not raw cURL) per WP.org guidelines. Only ever called in dev mode
486 + // (WP_DEBUG && YATRA_DEV_MODE), so it never runs on production loads.
378 487 $assetUrl = $url . '/assets/admin/dist/js/app.js';
379 - $ch = curl_init($assetUrl);
380 - curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
381 - curl_setopt($ch, CURLOPT_TIMEOUT, 2); // 2 second timeout
382 - curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 1); // 1 second connection timeout
383 - curl_setopt($ch, CURLOPT_NOBODY, true); // HEAD request only
384 - curl_exec($ch);
385 - $httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
386 - curl_close($ch);
387 -
388 - return $httpCode === 200;
488 +
489 + $response = wp_remote_head($assetUrl, [
490 + 'timeout' => 2,
491 + 'redirection' => 0,
492 + ]);
493 +
494 + if (is_wp_error($response)) {
495 + return false;
496 + }
497 +
498 + return (int) wp_remote_retrieve_response_code($response) === 200;
389 499 }
390 500
391 501 /**
392 502 * Add inline script for media library compatibility
@@ -406,14 +516,33 @@
406 516 * @return void
407 517 */
408 518 private function loadWordPressTranslations(): void
409 519 {
410 - // Use WordPress built-in function to load script translations
411 - // Specify the path where WordPress should look for JSON translation files
520 + // Use WordPress built-in function to load script translations.
521 + // The third argument MUST be an absolute path to the directory
522 + // that contains the per-locale .json translation files.
523 + //
524 + // Previously this passed YATRA_PLUGIN_FILE — i.e. the main
525 + // plugin PHP FILE path, not its directory. Appending
526 + // "/i18n/languages" yielded ".../plugin/yatra.php/i18n/languages",
527 + // a path that doesn't exist, so WordPress silently fell back to
528 + // shipping source-English strings to the React admin regardless
529 + // of the operator's WP locale.
530 + //
531 + // Use YATRA_PLUGIN_PATH (the directory, ending in /) instead,
532 + // matching the block-editor side that has always worked.
533 + //
534 + // The actual JSON file shipped here is generated at BUILD time
535 + // by scripts/build-translation-json.mjs from each locale's .po
536 + // file. That script writes ONE consolidated JSON per locale
537 + // named `yatra-{locale}-{md5(bundle src path)}.json`, so
538 + // WordPress's native script-translation loader finds it on
539 + // first try — no runtime filter / merge needed.
412 540 if (function_exists('wp_set_script_translations')) {
413 - wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_FILE . '/i18n/languages');
541 + wp_set_script_translations('yatra-admin', 'yatra', YATRA_PLUGIN_PATH . 'i18n/languages');
414 542 }
415 543 }
544 +
416 545
417 546 /**
418 547 * Enqueue setup wizard assets
419 548 *