AyeCode /
invoicing
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
| 1 | <?php |
||||
| 2 | /** |
||||
| 3 | * REST items controllers. |
||||
| 4 | * |
||||
| 5 | * @version 1.0.19 |
||||
| 6 | */ |
||||
| 7 | |||||
| 8 | defined( 'ABSPATH' ) || exit; |
||||
| 9 | |||||
| 10 | /** |
||||
| 11 | * REST API items controller class. |
||||
| 12 | * |
||||
| 13 | * @package Invoicing |
||||
| 14 | */ |
||||
| 15 | class WPInv_REST_Items_Controller extends GetPaid_REST_Posts_Controller { |
||||
| 16 | |||||
| 17 | /** |
||||
| 18 | * Post type. |
||||
| 19 | * |
||||
| 20 | * @var string |
||||
| 21 | */ |
||||
| 22 | protected $post_type = 'wpi_item'; |
||||
| 23 | |||||
| 24 | /** |
||||
| 25 | * The base of this controller's route. |
||||
| 26 | * |
||||
| 27 | * @since 1.0.13 |
||||
| 28 | * @var string |
||||
| 29 | */ |
||||
| 30 | protected $rest_base = 'items'; |
||||
| 31 | |||||
| 32 | /** Contains this controller's class name. |
||||
| 33 | * |
||||
| 34 | * @var string |
||||
| 35 | */ |
||||
| 36 | public $crud_class = 'WPInv_Item'; |
||||
| 37 | |||||
| 38 | /** |
||||
| 39 | * Registers the routes for the objects of the controller. |
||||
| 40 | * |
||||
| 41 | * @since 1.0.19 |
||||
| 42 | * |
||||
| 43 | * @see register_rest_route() |
||||
| 44 | */ |
||||
| 45 | public function register_namespace_routes( $namespace ) { |
||||
| 46 | |||||
| 47 | parent::register_namespace_routes( $namespace ); |
||||
| 48 | |||||
| 49 | register_rest_route( |
||||
| 50 | $this->namespace, |
||||
| 51 | '/' . $this->rest_base . '/item-types', |
||||
| 52 | array( |
||||
| 53 | array( |
||||
| 54 | 'methods' => WP_REST_Server::READABLE, |
||||
| 55 | 'callback' => array( $this, 'get_item_types' ), |
||||
| 56 | 'permission_callback' => array( $this, 'get_items_permissions_check' ), |
||||
| 57 | ), |
||||
| 58 | ) |
||||
| 59 | ); |
||||
| 60 | |||||
| 61 | } |
||||
| 62 | |||||
| 63 | /** |
||||
| 64 | * Handles rest requests for item types. |
||||
| 65 | * |
||||
| 66 | * @since 1.0.13 |
||||
| 67 | * |
||||
| 68 | * |
||||
| 69 | * @return WP_REST_Response|WP_Error Response object on success, or WP_Error object on failure. |
||||
| 70 | */ |
||||
| 71 | public function get_item_types() { |
||||
| 72 | return rest_ensure_response( wpinv_get_item_types() ); |
||||
| 73 | } |
||||
| 74 | |||||
| 75 | /** |
||||
| 76 | * Retrieves the query params for the items collection. |
||||
| 77 | * |
||||
| 78 | * @since 1.0.13 |
||||
| 79 | * |
||||
| 80 | * @return array Collection parameters. |
||||
| 81 | */ |
||||
| 82 | public function get_collection_params() { |
||||
| 83 | |||||
| 84 | $params = array_merge( |
||||
| 85 | parent::get_collection_params(), |
||||
| 86 | array( |
||||
| 87 | |||||
| 88 | // Item types |
||||
| 89 | 'type' => array( |
||||
| 90 | 'description' => __( 'Type of items to fetch.', 'invoicing' ), |
||||
| 91 | 'type' => array( 'array', 'string' ), |
||||
| 92 | 'default' => 'any', |
||||
| 93 | 'validate_callback' => 'rest_validate_request_arg', |
||||
| 94 | 'sanitize_callback' => 'wpinv_parse_list', |
||||
| 95 | 'items' => array( |
||||
| 96 | 'enum' => array_merge( array( 'any' ), wpinv_item_types() ), |
||||
| 97 | 'type' => 'string', |
||||
| 98 | ), |
||||
| 99 | ), |
||||
| 100 | |||||
| 101 | ) |
||||
| 102 | ); |
||||
| 103 | |||||
| 104 | // Filter collection parameters for the items controller. |
||||
| 105 | return apply_filters( 'getpaid_rest_items_collection_params', $params, $this ); |
||||
| 106 | |||||
| 107 | } |
||||
| 108 | |||||
| 109 | /** |
||||
| 110 | * Determine the allowed query_vars for a get_items() response and |
||||
| 111 | * prepare for WP_Query. |
||||
| 112 | * |
||||
| 113 | * @param array $prepared_args Prepared arguments. |
||||
| 114 | * @param WP_REST_Request $request Request object. |
||||
| 115 | * @return array $query_args |
||||
| 116 | */ |
||||
| 117 | protected function prepare_items_query( $prepared_args = array(), $request = null ) { |
||||
| 118 | |||||
| 119 | $query_args = parent::prepare_items_query( $prepared_args ); |
||||
| 120 | |||||
| 121 | // Retrieve items by type. |
||||
| 122 | if ( ! in_array( 'any', $request['type'] ) ) { |
||||
|
0 ignored issues
–
show
Bug
introduced
by
Loading history...
|
|||||
| 123 | |||||
| 124 | if ( empty( $query_args['meta_query'] ) ) { |
||||
| 125 | $query_args['meta_query'] = array(); |
||||
| 126 | } |
||||
| 127 | |||||
| 128 | $query_args['meta_query'][] = array( |
||||
| 129 | 'key' => '_wpinv_type', |
||||
| 130 | 'value' => implode( ',', $request['type'] ), |
||||
|
0 ignored issues
–
show
It seems like
$request['type'] can also be of type null; however, parameter $pieces of implode() does only seem to accept array, maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
Loading history...
|
|||||
| 131 | 'compare' => 'IN', |
||||
| 132 | ); |
||||
| 133 | |||||
| 134 | } |
||||
| 135 | |||||
| 136 | return apply_filters( 'getpaid_rest_items_prepare_items_query', $query_args, $request, $this ); |
||||
| 137 | |||||
| 138 | } |
||||
| 139 | |||||
| 140 | /** |
||||
| 141 | * Retrieves a valid list of post statuses. |
||||
| 142 | * |
||||
| 143 | * @since 1.0.15 |
||||
| 144 | * |
||||
| 145 | * @return array A list of registered item statuses. |
||||
| 146 | */ |
||||
| 147 | public function get_post_statuses() { |
||||
| 148 | return array( 'draft', 'pending', 'publish' ); |
||||
| 149 | } |
||||
| 150 | |||||
| 151 | /** |
||||
| 152 | * Checks if a key should be included in a response. |
||||
| 153 | * |
||||
| 154 | * @since 1.0.19 |
||||
| 155 | * @param WPInv_Item $item Item object. |
||||
| 156 | * @param string $field_key The key to check for. |
||||
| 157 | * @return bool |
||||
| 158 | */ |
||||
| 159 | public function object_supports_field( $item, $field_key ) { |
||||
| 160 | |||||
| 161 | if ( 'minimum_price' == $field_key && ! $item->user_can_set_their_price() ) { |
||||
| 162 | return false; |
||||
| 163 | } |
||||
| 164 | |||||
| 165 | foreach ( wpinv_parse_list( 'initial_price the_initial_price recurring_price the_recurring_price recurring_period recurring_interval recurring_limit is_free_trial trial_period trial_interval first_renewal_date' ) as $key ) { |
||||
| 166 | |||||
| 167 | if ( $key == $field_key && ! $item->is_recurring() ) { |
||||
| 168 | return false; |
||||
| 169 | } |
||||
| 170 | } |
||||
| 171 | |||||
| 172 | foreach ( wpinv_parse_list( 'trial_period trial_interval' ) as $key ) { |
||||
| 173 | |||||
| 174 | if ( $key == $field_key && ! $item->has_free_trial() ) { |
||||
| 175 | return false; |
||||
| 176 | } |
||||
| 177 | } |
||||
| 178 | |||||
| 179 | return parent::object_supports_field( $item, $field_key ); |
||||
| 180 | } |
||||
| 181 | |||||
| 182 | } |
||||
| 183 |