| Server IP : 172.67.159.97 / Your IP : 216.73.217.154 Web Server : nginx/1.24.0 System : Linux wordpress-sites 6.8.0-134-generic #134-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 26 18:43:11 UTC 2026 x86_64 User : www-data ( 33) PHP Version : 8.1.34 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /var/www/rebeccaone.com/wp-content/plugins/envira-gallery/src/Admin/ |
Upload File : |
<?php
/**
* Envira Gallery Onboarding Wizard
*
* @package Envira_Gallery
*/
namespace Envira\Admin;
// Exit if accessed directly.
use Braintree\Http;
use Envira\Admin\Addons;
use Envira_Gallery_Skin;
use Plugin_Upgrader;
if ( ! defined( 'ABSPATH' ) ) {
exit;
}
/**
* Class that holds our setup wizard.
*
* @since 1.9.14
*/
class Onboarding_Wizard {
/**
* Holds base singleton.
*
* @since 1.9.14
*
* @var object
*/
public $base = null;
/**
* Class constructor.
*
* @since 1.9.14
*/
public function __construct() {
if ( ! is_admin() || wp_doing_cron() || wp_doing_ajax() ) {
return;
}
// Load the base class object.
$this->base = \Envira_Gallery::get_instance();
}
/**
* Setup our hooks.
*/
public function hooks() {
add_action( 'admin_menu', [ $this, 'add_dashboard_page' ] );
add_action( 'admin_head', [ $this, 'hide_dashboard_page_from_menu' ] );
add_action( 'admin_init', [ $this, 'maybeload_onboarding_wizard' ] );
// Ajax actions.
add_action( 'wp_ajax_save_onboarding_data', [ $this, 'save_onboarding_data' ], 10, 1 );
add_action( 'wp_ajax_install_recommended_plugins', [ $this, 'install_recommended_plugins' ], 10, 1 );
add_action( 'wp_ajax_save_selected_addons', [ $this, 'save_selected_addons' ], 10, 1 );
add_action( 'wp_ajax_install_selected_addons', [ $this, 'install_selected_addons' ], 10, 1 );
add_action( 'wp_ajax_envira_verify_license_key', [ $this, 'envira_verify_license_key' ], 10, 1 );
}
/**
* Adds a dashboard page for our setup wizard.
*
* @since 1.9.14
*
* @return void
*/
public function add_dashboard_page() {
add_dashboard_page( '', '', 'manage_options', 'envira-setup-wizard', '' );
}
/**
* Hide the dashboard page from the menu.
*
* @since 1.9.14
*
* @return void
*/
public function hide_dashboard_page_from_menu() {
remove_submenu_page( 'index.php', 'envira-setup-wizard' );
}
/**
* Checks to see if we should load the setup wizard.
*
* @since 1.9.14
*
* @return void
*/
public function maybeload_onboarding_wizard() {
// Don't load the interface if doing an ajax call.
if ( wp_doing_ajax() || wp_doing_cron() ) {
return;
}
// Check for wizard-specific parameter
// Allow plugins to disable the setup wizard
// Check if current user is allowed to save settings.
if (
! isset( $_GET['page'] ) || // phpcs:ignore WordPress.Security.NonceVerification.Recommended
'envira-setup-wizard' !== sanitize_text_field( wp_unslash( $_GET['page'] ) ) || // phpcs:ignore WordPress.Security.NonceVerification.Recommended
! current_user_can( 'manage_options' )
) {
return;
}
set_current_screen();
// Remove an action in the Gutenberg plugin ( not core Gutenberg ) which throws an error.
remove_action( 'admin_print_styles', 'gutenberg_block_editor_admin_print_styles' );
// If we are redirecting, clear the transient so it only happens once.
$this->load_onboarding_wizard();
}
/**
* Load the Onboarding Wizard template.
*
* @since 1.9.14
*
* @return void
*/
private function load_onboarding_wizard() {
$this->enqueue_scripts();
$this->onboarding_wizard_header();
$this->onboarding_wizard_content();
$this->onboarding_wizard_footer();
exit;
}
/**
* Enqueue scripts for the setup wizard.
*
* @since 1.9.14
*
* @return void
*/
private function enqueue_scripts() {
// We don't want any plugin adding notices to our screens. Let's clear them out here.
remove_all_actions( 'admin_notices' );
remove_all_actions( 'all_admin_notices' );
wp_register_script( 'envira-onboarding-wizard', ENVIRA_URL . 'assets/js/min/onboarding-wizard-min.js', [ 'jquery' ], ENVIRA_VERSION, true );
wp_localize_script(
'envira-onboarding-wizard',
'enviraOnboardingWizard',
[
'ajaxUrl' => admin_url( 'admin-ajax.php' ),
'nonce' => wp_create_nonce( 'enviraOnboardingCheck' ),
'connect_nonce' => wp_create_nonce( 'envira-gallery-key-nonce' ),
'plugins_list' => $this->get_installed_plugins(),
]
);
wp_register_style( 'envira-onboarding-wizard', ENVIRA_URL . 'assets/css/onboarding-wizard.css', [], ENVIRA_VERSION );
wp_enqueue_style( 'envira-onboarding-wizard' );
wp_enqueue_style( 'common' );
wp_enqueue_media();
}
/**
* Setup the wizard header.
*
* @since 1.9.14
*
* @return void
*/
private function onboarding_wizard_header() {
?>
<!DOCTYPE html>
<html <?php language_attributes(); ?> dir="ltr">
<head>
<meta charset="<?php bloginfo( 'charset' ); ?>">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>
<?php
// translators: %s is the plugin name.
printf( esc_html__( '%1$s › Onboarding Wizard', 'envira-gallery' ), esc_html( 'Envira Gallery' ) );
?>
</title>
</head>
<body class="" style="visibility: hidden;">
<div class="envira-onboarding-wizard">
<?php
}
/**
* Outputs the content of the current step.
*
* @since 1.9.14
*
* @return void
*/
public function onboarding_wizard_content() {
?>
<div class="envira-onboarding-wizard-wrapper ">
<div class="envira-onboarding-wizard-intro " id="welcome">
<?php envira_load_admin_partial( 'onboarding-wizard/welcome' ); ?>
</div>
<div class="envira-onboarding-wizard-pages" style="display: none">
<!-- logo -->
<img width="339" src="<?php echo esc_attr( ENVIRA_URL . 'assets/images/envira-logo-color.svg' ); ?>" alt="Envira Gallery" class="envira-onboarding-wizard-logo" style="width:339px;">
<!-- Progress Bar -->
<div class="envira-onboarding-progressbar">
<div class="envira-onboarding-progress" id="envira-onboarding-progress"></div>
<div class="envira-onboarding-progress-step envira-onboarding-progress-step-active"></div>
<div class="envira-onboarding-spacer"></div>
<div class="envira-onboarding-progress-step" ></div>
<div class="envira-onboarding-spacer"></div>
<div class="envira-onboarding-progress-step" ></div>
<div class="envira-onboarding-spacer"></div>
<div class="envira-onboarding-progress-step" ></div>
<div class="envira-onboarding-spacer"></div>
<div class="envira-onboarding-progress-step" ></div>
</div>
<?php
// Load template partials for each step based on URL hash.
for ( $i = 1; $i <= 5; $i++ ) {
$step = 'step-' . $i;
envira_load_admin_partial( 'onboarding-wizard/' . $step );
}
?>
<div class="envira-onboarding-close-and-exit">
<a href="<?php echo esc_url( admin_url( '/edit.php?post_type=envira&page=envira-gallery-settings' ) ); ?>"><?php esc_html_e( 'Close and Exit Wizard Without Saving', 'envira-gallery' ); ?></a>
</div>
</div>
</div>
<?php
}
/**
* Outputs the simplified footer used for the Onboarding Wizard.
*
* @since 1.9.14
*
* @return void
*/
public function onboarding_wizard_footer() {
?>
<?php
wp_print_scripts( 'envira-onboarding-wizard' );
do_action( 'admin_footer', '' );
do_action( 'admin_print_footer_scripts' );
?>
</div>
</body>
</html>
<?php
}
/**
* Get a list of installed recommended plugins and addons.
*
* @return array
*/
public function get_installed_plugins(): array {
$addons = [
'envira-albums' => 'envira-albums/envira-albums.php',
'envira-tags' => 'envira-tags/envira-tags.php',
'envira-proofing' => 'envira-proofing/envira-proofing.php',
'envira-videos' => 'envira-videos/envira-videos.php',
'envira-slideshow' => 'envira-slideshow/envira-slideshow.php',
];
$recommended_plugins = $this->get_recommended_plugins();
$plugins = array_merge( $recommended_plugins, $addons );
// Check if these plugins are installed already or not.
$all_plugins = get_plugins();
$installed = [];
foreach ( $plugins as $plugin ) {
if ( in_array( $plugin, array_keys( $all_plugins ), true ) ) {
// Get array key of $plugins.
$installed[] = array_search( $plugin, $plugins, true );
}
}
return $installed;
}
/**
* Get a list of recommended plugins on step 3.
*
* @return array
*/
public function get_recommended_plugins(): array {
$plugins = [
'all-in-one-seo-pack' => 'all-in-one-seo-pack/all_in_one_seo_pack.php',
'wpforms-lite' => 'wpforms-lite/wpforms.php',
'google-analytics-for-wordpress' => 'google-analytics-for-wordpress/googleanalytics.php',
'duplicator' => 'duplicator/duplicator.php',
'wp-mail-smtp' => 'wp-mail-smtp/wp_mail_smtp.php',
];
return $plugins;
}
/**
* Check if a recommended plugin is installed.
*
* @param string $recommended The plugin slug.
*
* @return string
*/
public function is_recommended_plugin_installed( string $recommended ): string {
// Check if these plugins are installed already or not.
$all_plugins = get_plugins();
$plugins = $this->get_recommended_plugins();
if ( strpos( $recommended, 'envira-' ) !== false ) {
$plugin = $recommended . '/' . $recommended . '.php';
} elseif ( array_key_exists( $recommended, $plugins ) ) {
// check if key exists in the array.
$plugin = $plugins[ $recommended ];
}
if ( in_array( $plugin, array_keys( $all_plugins ), true ) ) {
return 'no-clicks disabled';
}
return '';
}
/**
* Get saved onboarding data.
*
* @param string $key The key to get the data.
*
* @return mixed
*/
public function get_onboarding_data( string $key ) {
if ( ! empty( $key ) ) {
$onboarding_data = get_option( 'envira_onboarding_data' );
if ( ! empty( $onboarding_data ) && isset( $onboarding_data[ $key ] ) ) {
return $onboarding_data[ $key ];
}
}
return '';
}
/**
* Save the onboarding data.
*
* @return void
*/
public function save_onboarding_data() {
// check for nonce enviraOnboardingCheck.
if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'enviraOnboardingCheck' ) ) {
wp_send_json_error( 'Invalid nonce' );
wp_die();
}
// check if the current user can manage options.
if ( ! current_user_can( 'manage_options' ) ) {
wp_send_json_error( 'You do not have permission to save data' );
wp_die();
}
if ( ! empty( $_POST['eow'] ) ) {
// Sanitize data and merge to existing data.
$onboarding_data = get_option( 'envira_onboarding_data', [] );
// Capture the previous user type before it is overwritten.
$previous_user_type = isset( $onboarding_data['_user_type'] ) ? $onboarding_data['_user_type'] : '';
$onboarding_data = $this->sanitize_and_assign( '_usage_tracking', 'sanitize_text_field', $onboarding_data );
$onboarding_data = $this->sanitize_and_assign( '_email_address', 'sanitize_email', $onboarding_data );
$onboarding_data = $this->sanitize_and_assign( '_email_opt_in', 'sanitize_text_field', $onboarding_data );
$onboarding_data = $this->sanitize_and_assign( '_user_type', 'sanitize_text_field', $onboarding_data );
$updated = update_option( 'envira_onboarding_data', $onboarding_data );
if ( $updated ) {
// Send data to Drip.
$this->save_to_drip( $onboarding_data, $previous_user_type );
}
wp_send_json_success( 'Data saved successfully' );
wp_die();
}
wp_send_json_error( 'Something went wrong. Please try again.' );
wp_die();
}
/**
* Sanitize and assign the data.
*
* @param string $key The key to get the data.
* @param string $sanitize_function The sanitize function.
* @param array $onboarding_data The onboarding data.
*
* @return array
*/
public function sanitize_and_assign( string $key, string $sanitize_function, array $onboarding_data ): array {
// phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
if ( isset( $_POST['eow'][ $key ] ) ) { // Nonce is verified in the parent function.
// phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
$onboarding_data[ $key ] = $sanitize_function( wp_unslash( $_POST['eow'][ $key ] ) );
} else {
unset( $onboarding_data[ $key ] );
}
return $onboarding_data;
}
/**
* Save the onboarding data to Drip.
*
* @param array $onboarding_data The onboarding data.
*
* @return void
*/
public function save_to_drip( array $onboarding_data, string $previous_user_type = '' ) {
$url = 'https://enviragallery.com/wp-json/envira/v1/get_opt_in_data';
$email = sanitize_email( $onboarding_data['_email_address'] );
if ( empty( $email ) ) {
return;
}
$tags = envira_get_license_level() ? [ 'envira-' . envira_get_license_level() ] : [ 'envira-pro' ];
$current_user_type = isset( $onboarding_data['_user_type'] ) ? $onboarding_data['_user_type'] : '';
if ( $current_user_type ) {
$tags[] = $current_user_type;
}
$body_data = [
'envira-drip-email' => base64_encode( $email ), // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode
'envira-drip-tags' => $tags,
];
// If the user type changed, ask the endpoint to remove the old tag.
if ( $previous_user_type && $previous_user_type !== $current_user_type ) {
$body_data['envira-drip-remove-tags'] = [ $previous_user_type ];
}
$body = wp_json_encode( $body_data );
$args = [
'method' => 'POST',
'headers' => [
'Content-Type' => 'application/json',
'user-agent' => 'ENVIRA/LITE/' . ENVIRA_VERSION . '; ' . get_bloginfo( 'url' ),
],
'body' => $body,
'timeout' => '5', // Timeout in seconds.
'redirection' => '5',
'httpversion' => '1.0',
'blocking' => false,
'data_format' => 'body',
];
$response = wp_remote_request( $url, $args );
}
/**
* Save selected addons to database.
*/
public function save_selected_addons() {
// check for nonce enviraOnboardingCheck.
if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'enviraOnboardingCheck' ) ) {
wp_send_json_error( 'Invalid nonce' );
wp_die();
}
// check if the current user can manage options.
if ( ! current_user_can( 'manage_options' ) ) {
wp_send_json_error( 'You do not have permission to save data' );
wp_die();
}
if ( ! empty( $_POST['addons'] ) ) {
$addons = explode( ',', sanitize_text_field( wp_unslash( $_POST['addons'] ) ) );
// Sanitize data and merge to existing data.
$onboarding_data = get_option( 'envira_onboarding_data' );
if ( empty( $onboarding_data ) ) {
$onboarding_data = [];
}
// Check if $addons has albums addon, then add tags addon too.
if ( in_array( 'envira-albums', $addons, true ) ) {
$addons[] = 'envira-tags';
}
// Save addons as _addons key.
$onboarding_data['_addons'] = $addons;
$updated = update_option( 'envira_onboarding_data', $onboarding_data );
wp_send_json_success( 'Addons saved successfully' );
wp_die();
}
wp_send_json_error( 'Something went wrong. Please try again.' );
wp_die();
}
/**
* Install the selected addons.
*/
public function install_selected_addons() {
// check for nonce enviraOnboardingCheck.
if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'enviraOnboardingCheck' ) ) {
wp_send_json_error( 'Invalid nonce' );
wp_die();
}
// check if the current user can manage options.
if ( ! current_user_can( 'manage_options' ) ) {
wp_send_json_error( 'You do not have permission to install plugins' );
wp_die();
}
// if the user doesn't have a license key, then skip the installation.
if ( empty( envira_get_license_key() ) ) {
wp_send_json_error( 'You do not have valid license to install addons' );
wp_die();
}
// Get addons data from onboarding_data.
$onboarding_data = get_option( 'envira_onboarding_data' );
if ( ! empty( $onboarding_data['_addons'] ) ) {
$plugins = $onboarding_data['_addons'];
// Install the addons.
// Check if the user has valid license key.
$addons = new Addons();
$license = envira_get_license_key();
$addons_list = $addons->get_addons_data( $license );
// Get the addons slugs from addons list.
$addons_slug = wp_list_pluck( $addons_list, 'slug', 'slug' );
$addons_url = wp_list_pluck( $addons_list, 'url', 'slug' );
// Install the plugins.
foreach ( $plugins as $plugin ) {
if ( '' !== $this->is_recommended_plugin_installed( $plugin ) ) {
continue; // Skip the plugin if it is already installed.
}
// Check if the addon is available for this license key.
if ( ! empty( $license ) && ! empty( $addons_list ) && ! in_array( $plugin, $addons_slug, true ) ) {
continue;
}
// Get addon url by slug.
if ( isset( $addons_url[ $plugin ] ) ) {
$this->install_helper( $addons_url[ $plugin ] );
}
}
wp_send_json_success( 'Installed the selected addons successfully.' );
wp_die();
}
}
/**
* Install the recommended plugins and add-ons.
*
* @return void
*/
public function install_recommended_plugins() {
// check for nonce enviraOnboardingCheck.
if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'enviraOnboardingCheck' ) ) {
wp_send_json_error( 'Invalid nonce' );
wp_die();
}
// check if the current user can manage options.
if ( ! current_user_can( 'manage_options' ) ) {
wp_send_json_error( 'You do not have permission to install plugins' );
wp_die();
}
if ( ! empty( $_POST['plugins'] ) ) {
// Sanitize data, plugins is a string delimited by comma.
$plugins = explode( ',', sanitize_text_field( wp_unslash( $_POST['plugins'] ) ) );
// Install the plugins.
foreach ( $plugins as $plugin ) {
if ( '' !== $this->is_recommended_plugin_installed( $plugin ) ) {
continue; // Skip the plugin if it is already installed.
}
// Generate the plugin URL by slug.
$url = 'https://downloads.wordpress.org/plugin/' . $plugin . '.zip';
$this->install_helper( $url );
}
wp_send_json_success( 'Installed the recommended plugins successfully.' );
wp_die();
}
wp_send_json_error( 'Something went wrong. Please try again.' );
wp_die();
}
/**
* Helper function to install the free plugins.
*
* @param string $download_url The download URL.
*
* @return void
*/
public function install_helper( string $download_url ) {
if ( empty( $download_url ) ) {
return;
}
global $hook_suffix;
// Set the current screen to avoid undefined notices.
set_current_screen();
$method = '';
$url = esc_url( admin_url( 'index.php?page=envira-setup-wizard' ) );
// Start output buffering to catch the filesystem form if credentials are needed.
ob_start();
$creds = request_filesystem_credentials( $url, $method, false, false, null );
if ( false === $creds ) {
$form = ob_get_clean();
echo wp_json_encode( [ 'form' => $form ] );
die;
}
// If we are not authenticated, make it happen now.
if ( ! WP_Filesystem( $creds ) ) {
ob_start();
request_filesystem_credentials( $url, $method, true, false, null );
$form = ob_get_clean();
echo wp_json_encode( [ 'form' => $form ] );
die;
}
// We do not need any extra credentials if we have gotten this far, so let's install the plugin.
require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
require_once plugin_dir_path( ENVIRA_FILE ) . 'src/Utils/Skin.php';
// Create the plugin upgrader with our custom skin.
$skin = new Envira_Gallery_Skin();
$installer = new Plugin_Upgrader( $skin );
$installer->install( $download_url );
// Flush the cache and return.
wp_cache_flush();
}
/**
* Verify the license key.
*
* @since 1.9.14
*
* @return void
*
* Copy of maybe_verify_key in License class.
* Modified to return wp_send_json_success and wp_send_json_error.
*/
public function envira_verify_license_key() {
if (
! isset( $_POST['envira-license-key'], $_POST['nonce'] )
|| ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'enviraOnboardingCheck' )
) {
wp_send_json_error( 'Invalid Request', \WP_Http::FORBIDDEN );
wp_die();
}
// Sanitize this option before attempting to save it. This option can also be set on Lite version.
$option = get_option( 'envira_gallery', \Envira_Gallery::default_options() );
if ( ! empty( $option['type'] ) && empty( $option['key'] ) ) {
// Option is invalid reset to defaults.
$option = \Envira_Gallery::default_options();
update_option( 'envira_gallery', $option );
}
$license = new License();
// Perform a request to verify the key.
$verify = $license->perform_remote_request( 'verify-key', [ 'tgm-updater-key' => sanitize_text_field( wp_unslash( $_POST['envira-license-key'] ) ) ] ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
// If it returns false, send back a generic error message and return.
if ( ! $verify ) {
wp_send_json_error(
__( 'There was an error connecting to the remote key API. Please try again later.', 'envira-gallery' ),
\WP_Http::INTERNAL_SERVER_ERROR
);
wp_die();
}
if ( ! empty( $verify->error ) ) {
// If the request returns an error, send back the error message.
wp_send_json_error( $verify->error, \WP_Http::BAD_REQUEST );
wp_die();
}
// Otherwise, our request has been done successfully. Update the option and set the success message.
$option['key'] = sanitize_text_field( wp_unslash( $_POST['envira-license-key'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
$option['type'] = $verify->type ?? $option['type'];
$option['is_expired'] = false;
$option['is_disabled'] = false;
$option['is_invalid'] = false;
update_option( 'envira_can_beta', $verify->beta ?? false );
update_option( 'envira_gallery', $option );
wp_clean_plugins_cache();
wp_send_json_success(
__( 'Congratulations! This site is now receiving automatic updates.', 'envira-gallery' ),
\WP_Http::CREATED
);
wp_die();
}
}