Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
88 commits
Select commit Hold shift + click to select a range
06100bd
Merge pull request #1218 from equalizedigital/release/1.31.0
pattonwebz Aug 29, 2025
9cc9739
Use a specifically named ajax request for frontend highlighter
pattonwebz Sep 1, 2025
52316d4
Ensure user can edit the post id before returning readability markup
pattonwebz Sep 1, 2025
bb6da04
No need for a helper for these callbacks
pattonwebz Sep 1, 2025
d6e896b
Add visibility checks for reading issues in the frontend highlighter
pattonwebz Sep 1, 2025
33d2d70
Gate the frontend highlighter restNonce
pattonwebz Sep 1, 2025
59ed54d
Avoid single use variables for error messages
pattonwebz Sep 1, 2025
f9188b4
Add a can edit posts check to summary, details, and simplified_summar…
pattonwebz Sep 2, 2025
ea19421
Merge remote-tracking branch 'origin/william/tweak/some-request-handl…
pattonwebz Sep 2, 2025
cdbd110
Avoid single use variables for error messages
pattonwebz Sep 2, 2025
55204c0
Fix issue with `new` being missing when creating some error objects
pattonwebz Sep 2, 2025
aabf087
Add privacy policy statement link to newsletter forms
pattonwebz Sep 4, 2025
b62691e
Improve a translator comment
pattonwebz Sep 4, 2025
fb0e22f
Update button alignment in email opt-in styles
pattonwebz Sep 4, 2025
ac97853
Merge pull request #1220 from equalizedigital/william/tweak/some-requ…
pattonwebz Sep 4, 2025
3ec6014
Merge pull request #1224 from equalizedigital/william/pro-275-add-pri…
pattonwebz Sep 4, 2025
49b2cd3
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
590399b
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
36fb263
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
d4cdd98
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
fe26603
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
8e97974
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
c6d315b
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
3b60f9b
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
9922d57
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
2fa07fb
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
f4c7b7e
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
8c1735f
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
3be04bc
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
bd71e05
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
0a0ace8
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
e6d8466
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
6672a2e
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
c302707
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
ea2a2ee
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
a67c043
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
865a423
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
198fab8
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
33240f0
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
4424094
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
cd4f698
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
3b9e538
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
1473006
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
9afd3cd
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
99c0b6f
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
d14b787
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
6dcf181
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
2f9a5b5
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
f6f1523
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
893fe65
Update pot file with latest string and line changes
pattonwebz Sep 4, 2025
5dfd26e
Merge pull request #1226 from equalizedigital/ptc_1985_automatic_tran…
pattonwebz Sep 4, 2025
6786f33
Merge pull request #1225 from equalizedigital/ptc_1985_automatic_tran…
pattonwebz Sep 4, 2025
63da35a
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
5905c9f
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
9ec9d57
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
3fb11cd
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
db12627
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
fccaae8
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
6b9ff80
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
039d7f8
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
5bffcf3
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
53001e8
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
d2acf18
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
1889992
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
1ef9b72
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
220d445
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
d5833e9
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
7710c5a
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
c19c629
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
4cad42b
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
cf853bb
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
ea8f03b
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
4222376
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
0422be0
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
7811dcb
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
c339eda
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
47edaee
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
5b54858
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
8d7c182
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
0557a74
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
82d6884
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
2c375db
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
27076c1
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
712f7a2
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
1756417
PTC accessibility-checker (1985): Automatic Translations {{ datetime }}
SteveJonesDev Sep 4, 2025
44e4014
Merge pull request #1227 from equalizedigital/ptc_1985_automatic_tran…
pattonwebz Sep 4, 2025
266643f
Bump version 1.31.1
pattonwebz Sep 4, 2025
22ba636
Add changelog for v1.31.1
pattonwebz Sep 4, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions accessibility-checker.php
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
* Plugin Name: Accessibility Checker
* Plugin URI: https://a11ychecker.com
* Description: Audit and check your website for accessibility before you hit publish. In-post accessibility scanner and guidance.
* Version: 1.31.0
* Version: 1.31.1
Comment thread
pattonwebz marked this conversation as resolved.
* Requires PHP: 7.4
* Author: Equalize Digital
* Author URI: https://equalizedigital.com
Expand All @@ -36,7 +36,7 @@

// Current plugin version.
if ( ! defined( 'EDAC_VERSION' ) ) {
define( 'EDAC_VERSION', '1.31.0' );
define( 'EDAC_VERSION', '1.31.1' );
}

// Current database version.
Expand Down
141 changes: 56 additions & 85 deletions admin/class-ajax.php
Original file line number Diff line number Diff line change
Expand Up @@ -47,28 +47,26 @@ public function init_hooks() {
* - '-1' means that nonce could not be varified
* - '-2' means that the post ID was not specified
* - '-3' means that there isn't any summary data to return
* - '-5' means that the user does not have permission to view this information for this post
*/
public function summary() {

// nonce security.
if ( ! isset( $_REQUEST['nonce'] ) || ! wp_verify_nonce( sanitize_key( wp_unslash( $_REQUEST['nonce'] ) ), 'ajax-nonce' ) ) {

$error = new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

if ( ! isset( $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) ) );
}

$error = new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) );
wp_send_json_error( $error );

if ( ! current_user_can( 'edit_post', (int) $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-5', __( 'You do not have permission to view this information for this post.', 'accessibility-checker' ) ) );
}

$html = [];
$html['content'] = '';


$post_id = (int) $_REQUEST['post_id'];
$summary = ( new Summary_Generator( $post_id ) )->generate_summary();
$simplified_summary_text = '';
Expand Down Expand Up @@ -126,25 +124,25 @@ public function summary() {
'edac-summary-errors',
$summary['errors'],
/* translators: %s: Number of errors */
sprintf( _n( '%s Error', '%s Errors', $summary['errors'], 'accessibility-checker' ), $summary['errors'] )
sprintf( _n( '%s Error', '%s Errors', $summary['errors'], 'accessibility-checker' ), $summary['errors'] )
) . '
' . edac_generate_summary_stat(
'edac-summary-contrast',
$summary['contrast_errors'],
/* translators: %s: Number of contrast errors */
sprintf( _n( '%s Contrast Error', '%s Contrast Errors', $summary['contrast_errors'], 'accessibility-checker' ), $summary['contrast_errors'] )
sprintf( _n( '%s Contrast Error', '%s Contrast Errors', $summary['contrast_errors'], 'accessibility-checker' ), $summary['contrast_errors'] )
) . '
' . edac_generate_summary_stat(
'edac-summary-warnings',
$summary['warnings'],
/* translators: %s: Number of warnings */
sprintf( _n( '%s Warning', '%s Warnings', $summary['warnings'], 'accessibility-checker' ), $summary['warnings'] )
sprintf( _n( '%s Warning', '%s Warnings', $summary['warnings'], 'accessibility-checker' ), $summary['warnings'] )
) . '
' . edac_generate_summary_stat(
'edac-summary-ignored',
$summary['ignored'],
/* translators: %s: Number of ignored items */
sprintf( _n( '%s Ignored Item', '%s Ignored Items', $summary['ignored'], 'accessibility-checker' ), $summary['ignored'] )
sprintf( _n( '%s Ignored Item', '%s Ignored Items', $summary['ignored'], 'accessibility-checker' ), $summary['ignored'] )
) . '

</ul>
Expand Down Expand Up @@ -181,10 +179,7 @@ public function summary() {
$html['content'] .= '</small></div>' . PHP_EOL;

if ( ! $html ) {

$error = new \WP_Error( '-3', __( 'No summary to return', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-3', __( 'No summary to return', 'accessibility-checker' ) ) );
}

wp_send_json_success( wp_json_encode( $html ) );
Expand All @@ -199,22 +194,20 @@ public function summary() {
* - '-2' means that the post ID was not specified
* - '-3' means that the table name is not valid
* - '-4' means that there isn't any details to return
* - '-5' means that the user does not have permission to view this information for this post
*/
public function details() {

// nonce security.
if ( ! isset( $_REQUEST['nonce'] ) || ! wp_verify_nonce( sanitize_key( wp_unslash( $_REQUEST['nonce'] ) ), 'ajax-nonce' ) ) {

$error = new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

if ( ! isset( $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) ) );
}

$error = new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) );
wp_send_json_error( $error );

if ( ! current_user_can( 'edit_post', (int) $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-5', __( 'You do not have permission to view this information for this post.', 'accessibility-checker' ) ) );
}

$html = '';
Expand All @@ -225,10 +218,7 @@ public function details() {

// Send error if table name is not valid.
if ( ! $table_name ) {

$error = new \WP_Error( '-3', __( 'Invalid table name', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-3', __( 'Invalid table name', 'accessibility-checker' ) ) );
}

$rules = edac_register_rules();
Expand Down Expand Up @@ -567,10 +557,7 @@ function ( $a, $b ) {
}

if ( ! $html ) {

$error = new \WP_Error( '-4', __( 'No details to return', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-4', __( 'No details to return', 'accessibility-checker' ) ) );
}

wp_send_json_success( wp_json_encode( $html ) );
Expand All @@ -584,22 +571,20 @@ function ( $a, $b ) {
* - '-1' means that nonce could not be varified
* - '-2' means that the post ID was not specified
* - '-3' means that there isn't any readability data to return
* - '-5' means that the user does not have permission to view this information for this post
*/
public function readability() {

// nonce security.
if ( ! isset( $_REQUEST['nonce'] ) || ! wp_verify_nonce( sanitize_key( wp_unslash( $_REQUEST['nonce'] ) ), 'ajax-nonce' ) ) {

$error = new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

if ( ! isset( $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) ) );
}

$error = new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) );
wp_send_json_error( $error );

if ( ! current_user_can( 'edit_post', (int) $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-5', __( 'You do not have permission to view this information for this post.', 'accessibility-checker' ) ) );
}

$post_id = (int) $_REQUEST['post_id'];
Expand Down Expand Up @@ -706,10 +691,7 @@ public function readability() {
$html .= '<span class="dashicons dashicons-info"></span><a href="' . esc_url( edac_link_wrapper( 'https://a11ychecker.com/help3265', 'wordpress-general', 'content-analysis', false ) ) . '" target="_blank">Learn more about improving readability and simplified summary requirements</a>';

if ( ! $html ) {

$error = new \WP_Error( '-3', __( 'No readability data to return', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-3', __( 'No readability data to return', 'accessibility-checker' ) ) );
}

wp_send_json_success( wp_json_encode( $html ) );
Expand All @@ -727,32 +709,29 @@ public function add_ignore() {

// nonce security.
if ( ! isset( $_REQUEST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_REQUEST['nonce'] ) ), 'ajax-nonce' ) ) {

$error = new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

global $wpdb;
$table_name = $wpdb->prefix . 'accessibility_checker';
$raw_ids = isset( $_REQUEST['ids'] ) ? (array) wp_unslash( $_REQUEST['ids'] ) : []; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Sanitization handled below.
$ids = array_map(
$table_name = $wpdb->prefix . 'accessibility_checker';
$raw_ids = isset( $_REQUEST['ids'] ) ? (array) wp_unslash( $_REQUEST['ids'] ) : []; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Sanitization handled below.
$ids = array_map(
function ( $value ) {
return (int) $value;
},
$raw_ids
); // Sanitizing array elements to integers.
$action = isset( $_REQUEST['ignore_action'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['ignore_action'] ) ) : '';
$type = isset( $_REQUEST['ignore_type'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['ignore_type'] ) ) : '';
$siteid = get_current_blog_id();
$ignre = ( 'enable' === $action ) ? 1 : 0;
$ignre_user = ( 'enable' === $action ) ? get_current_user_id() : null;
$ignre_user_info = ( 'enable' === $action ) ? get_userdata( $ignre_user ) : '';
$ignre_username = ( 'enable' === $action ) ? $ignre_user_info->user_login : '';
$ignre_date = ( 'enable' === $action ) ? gmdate( 'Y-m-d H:i:s' ) : null;
$ignre_date_formatted = ( 'enable' === $action ) ? gmdate( 'F j, Y g:i a', strtotime( $ignre_date ) ) : '';
$ignre_comment = ( 'enable' === $action && isset( $_REQUEST['comment'] ) ) ? sanitize_textarea_field( wp_unslash( $_REQUEST['comment'] ) ) : null;
$ignore_global = ( 'enable' === $action && isset( $_REQUEST['ignore_global'] ) ) ? sanitize_textarea_field( wp_unslash( $_REQUEST['ignore_global'] ) ) : 0;
$action = isset( $_REQUEST['ignore_action'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['ignore_action'] ) ) : '';
$type = isset( $_REQUEST['ignore_type'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['ignore_type'] ) ) : '';
$siteid = get_current_blog_id();
$ignre = ( 'enable' === $action ) ? 1 : 0;
$ignre_user = ( 'enable' === $action ) ? get_current_user_id() : null;
$ignre_user_info = ( 'enable' === $action ) ? get_userdata( $ignre_user ) : '';
$ignre_username = ( 'enable' === $action ) ? $ignre_user_info->user_login : '';
$ignre_date = ( 'enable' === $action ) ? gmdate( 'Y-m-d H:i:s' ) : null;
$ignre_date_formatted = ( 'enable' === $action ) ? gmdate( 'F j, Y g:i a', strtotime( $ignre_date ) ) : '';
$ignre_comment = ( 'enable' === $action && isset( $_REQUEST['comment'] ) ) ? sanitize_textarea_field( wp_unslash( $_REQUEST['comment'] ) ) : null;
$ignore_global = ( 'enable' === $action && isset( $_REQUEST['ignore_global'] ) ) ? sanitize_textarea_field( wp_unslash( $_REQUEST['ignore_global'] ) ) : 0;

// If largeBatch is set and 'true', we need to perform an update using the 'object'
// instead of IDs. It is a much less efficient query than by IDs - but many IDs run
Expand All @@ -764,8 +743,7 @@ function ( $value ) {
$object = $wpdb->get_var( $wpdb->prepare( 'SELECT object FROM %i WHERE id = %d', $table_name, $first_id ) );

if ( ! $object ) {
$error = new \WP_Error( '-2', __( 'No ignore data to return', 'accessibility-checker' ) );
wp_send_json_error( $error );
wp_send_json_error( new \WP_Error( '-2', __( 'No ignore data to return', 'accessibility-checker' ) ) );
}
// phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Safe variable used for table name, caching not required for one time operation.
$wpdb->query( $wpdb->prepare( 'UPDATE %i SET ignre = %d, ignre_user = %d, ignre_date = %s, ignre_comment = %s, ignre_global = %d WHERE siteid = %d and object = %s', $table_name, $ignre, $ignre_user, $ignre_date, $ignre_comment, $ignore_global, $siteid, $object ) );
Expand All @@ -786,10 +764,7 @@ function ( $value ) {
];

if ( ! $data ) {

$error = new \WP_Error( '-2', __( 'No ignore data to return', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-2', __( 'No ignore data to return', 'accessibility-checker' ) ) );
}
wp_send_json_success( wp_json_encode( $data ) );
}
Expand All @@ -802,37 +777,33 @@ function ( $value ) {
* - '-1' means that nonce could not be varified
* - '-2' means that the post ID was not specified
* - '-3' means that the summary was not specified
* - '-5' means that the user does not have permission to view this information for this post
*/
public function simplified_summary() {

// nonce security.
if ( ! isset( $_REQUEST['nonce'] ) || ! wp_verify_nonce( sanitize_key( wp_unslash( $_REQUEST['nonce'] ) ), 'ajax-nonce' ) ) {

$error = new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

if ( ! isset( $_REQUEST['post_id'] ) ) {

$error = new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-2', __( 'The post ID was not set', 'accessibility-checker' ) ) );
}

if ( ! isset( $_REQUEST['summary'] ) ) {
wp_send_json_error( new \WP_Error( '-3', __( 'The summary was not set', 'accessibility-checker' ) ) );
}

$error = new \WP_Error( '-3', __( 'The summary was not set', 'accessibility-checker' ) );
wp_send_json_error( $error );

if ( ! current_user_can( 'edit_post', (int) $_REQUEST['post_id'] ) ) {
wp_send_json_error( new \WP_Error( '-5', __( 'You do not have permission to edit this post.', 'accessibility-checker' ) ) );
}

$post_id = (int) $_REQUEST['post_id'];
update_post_meta(
$post_id,
'_edac_simplified_summary',
sanitize_text_field( wp_unslash( $_REQUEST['summary'] ) )
);
$post_id = (int) $_REQUEST['post_id'];
update_post_meta(
$post_id,
'_edac_simplified_summary',
sanitize_text_field( wp_unslash( $_REQUEST['summary'] ) )
);

$edac_simplified_summary = get_post_meta( $post_id, '_edac_simplified_summary', $single = true );
$simplified_summary = $edac_simplified_summary ? $edac_simplified_summary : '';
Expand Down
34 changes: 25 additions & 9 deletions admin/class-frontend-highlight.php
Original file line number Diff line number Diff line change
Expand Up @@ -74,9 +74,8 @@ public function get_issues( $post_id ) {
*/
public function ajax() {

if ( ! check_ajax_referer( 'ajax-nonce', 'nonce', false ) ) {
$error = new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) );
wp_send_json_error( $error );
if ( ! check_ajax_referer( 'frontend-highlighter', 'nonce', false ) ) {
wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

if ( ! isset( $_REQUEST['post_id'] ) ) {
Expand All @@ -85,11 +84,31 @@ public function ajax() {
}

$post_id = isset( $_REQUEST['post_id'] ) ? (int) $_REQUEST['post_id'] : 0;
$post = get_post( $post_id );
if ( ! $post ) {
wp_send_json_error( new \WP_Error( '-4', __( 'Post not found', 'accessibility-checker' ) ) );
}

// Check if the user has permission to view this post.
if ( is_user_logged_in() ) {
// For authenticated users, use read_post capability.
if ( ! current_user_can( 'read_post', $post_id ) ) {
wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}
} elseif ( apply_filters( 'edac_filter_frontend_highlighter_visibility', false ) ) {
// For unauthenticated users, only allow access to publicly viewable posts.
if ( ! is_post_publicly_viewable( $post ) ) {
wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}
} else {
// Shouldn't ever reach this point but error just in case.
wp_send_json_error( new \WP_Error( '-1', __( 'Permission Denied', 'accessibility-checker' ) ) );
}

$results = $this->get_issues( $post_id );

if ( ! $results ) {
$error = new \WP_Error( '-3', __( 'Issue query returned no results', 'accessibility-checker' ) );
wp_send_json_error( $error );
wp_send_json_error( new \WP_Error( '-3', __( 'Issue query returned no results', 'accessibility-checker' ) ) );
}

$rules = edac_register_rules();
Expand Down Expand Up @@ -133,10 +152,7 @@ public function ajax() {
}

if ( ! $issues ) {

$error = new \WP_Error( '-5', __( 'Object query returned no results', 'accessibility-checker' ) );
wp_send_json_error( $error );

wp_send_json_error( new \WP_Error( '-5', __( 'Object query returned no results', 'accessibility-checker' ) ) );
}

// if we have fixes then create fields for each of the groups.
Expand Down
10 changes: 10 additions & 0 deletions admin/opt-in/class-email-opt-in.php
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,16 @@ public static function render_form(): void {
</div>
</div>
<div class="_button-wrapper _full_width edac-mt-3 edac-mb-3">
<small>
<?php
printf(
/* translators: 1: link to privacy policy page. 2: link close tag. */
esc_html__( 'By subscribing, you consent to receive emails in accordance with our %1$sPrivacy Policy%2$s.', 'accessibility-checker' ),
'<a href="' . esc_url( edac_link_wrapper( 'https://equalizedigital.com/privacy-policy/', 'email_newsletter', 'privacy', false ) ) . '" target="_blank">',
'</a>'
);
?>
</small>
<button id="_form_1_submit" class="_submit button button-primary" type="submit">
Subscribe
</button>
Expand Down
4 changes: 2 additions & 2 deletions includes/classes/class-enqueue-frontend.php
Original file line number Diff line number Diff line change
Expand Up @@ -100,8 +100,8 @@ public static function maybe_enqueue_frontend_highlighter() {
'edacFrontendHighlighterApp',
[
'postID' => $post_id,
'nonce' => wp_create_nonce( 'ajax-nonce' ),
'restNonce' => wp_create_nonce( 'wp_rest' ),
'nonce' => wp_create_nonce( 'frontend-highlighter' ),
'restNonce' => is_user_logged_in() ? wp_create_nonce( 'wp_rest' ) : '',
'userCanFix' => current_user_can( apply_filters( 'edac_filter_settings_capability', 'manage_options' ) ),
'userCanEdit' => current_user_can( 'edit_post', $post_id ),
'edacUrl' => esc_url_raw( get_site_url() ),
Expand Down
Loading
Loading