Rewrite of the wp_jdt_shortcode() function to put security measuremnts in place, better fallback and loading the JS script in the footer

This commit is contained in:
2026-07-21 21:29:03 +02:00
parent d42ff6fc14
commit 507fe4412c
2 changed files with 71 additions and 72 deletions
+1
View File
@@ -87,6 +87,7 @@ Is this plugin prepared for multisites? Yes.
* Added a check for the options page to only load if the user has sufficient rights.
* Changed the radio buttons on the options page to use the WordPress checked() function.
* Changed get_option() for the options page to make use a $default_value.
* Rewrite of the wp_jdt_shortcode() function to put security measuremnts in place, better fallback and loading the JS script in the footer.
= 4.1.0 =
* Compatibility with WordPress version 6.7.1
+70 -72
View File
@@ -180,7 +180,7 @@ function wp_jdt_settings_page()
<?php submit_button(); ?>
</form>
</div>
<?php
<?php
}
add_action('wp_enqueue_scripts', 'wp_jdt_style_and_script'); // add custom style and script
@@ -199,87 +199,85 @@ function wp_jdt_load_textdomain()
load_plugin_textdomain('wp-jquery-datatable', false, dirname(plugin_basename(__FILE__)) . '/languages');
}
add_shortcode('wp_jdt', 'wp_jdt_shortcode'); // add shortcode [wp_jdt id="test" info="true" paging="true" page_length="7" paging_type="full_numbers" b_length_change="true" ordering="true" order_row_number="3" order_row_number_sort="desc" searching="true"]
function wp_jdt_shortcode($atts, $content = "")
add_shortcode('wp_jdt', 'wp_jdt_shortcode');
function wp_jdt_shortcode($atts)
{
// Get defaults from options for when not set in shortcode
$defaults = array(
'id' => 'example',
'info' => get_option('wp_jdt_info', 'true'),
'paging' => get_option('wp_jdt_paging', 'true'),
'page_length' => get_option('wp_jdt_page_length', '10'),
'paging_type' => get_option('wp_jdt_paging_type', 'simple'),
'b_length_change' => get_option('wp_jdt_b_length_change', 'true'),
'ordering' => get_option('wp_jdt_ordering', 'true'),
'order_row_number' => get_option('wp_jdt_order_row', '0'),
'order_row_number_sort' => get_option('wp_jdt_order_row_sort', 'desc'),
'searching' => get_option('wp_jdt_searching', 'true'),
);
$wp_jdt_info = get_option('wp_jdt_info');
$wp_jdt_paging = get_option('wp_jdt_paging');
/*if(get_option('wp_jdt_paging')){
$wp_jdt_paging = 'true';
}else{
$wp_jdt_paging = '';
}*/
$wp_jdt_page_length = get_option('wp_jdt_page_length');
$wp_jdt_paging_type = get_option('wp_jdt_paging_type');
$wp_jdt_b_length_change = get_option('wp_jdt_b_length_change');
$wp_jdt_ordering = get_option('wp_jdt_ordering');
$wp_jdt_order_row = get_option('wp_jdt_order_row');
$wp_jdt_order_row_sort = get_option('wp_jdt_order_row_sort');
$wp_jdt_searching = get_option('wp_jdt_searching');
// Combines user attributes with known attributes and fill in defaults when needed
$atts = shortcode_atts($defaults, $atts, 'wp_jdt');
$atts = shortcode_atts(array(
'id' => "example",
'info' => "$wp_jdt_info",
'paging' => "$wp_jdt_paging",
'page_length' => "$wp_jdt_page_length",
'paging_type' => "$wp_jdt_paging_type",
'b_length_change' => "$wp_jdt_b_length_change",
'ordering' => "$wp_jdt_ordering",
'order_row_number' => "$wp_jdt_order_row",
'order_row_number_sort' => "$wp_jdt_order_row_sort",
'searching' => "$wp_jdt_searching",
), $atts, 'wp_jdt');
// Sanitize and fall back to defaults when setting from shortcode is unknown
$table_id = preg_replace('/[^a-zA-Z0-9_\-]/', '', $atts['id']);
$table_info = ($atts['info'] === 'true') ? 'true' : 'false';
$table_paging = ($atts['paging'] === 'true') ? 'true' : 'false';
$table_page_length = absint($atts['page_length']);
$table_id = esc_js($atts['id']);
$table_info = esc_js($atts['info']);
$table_paging = esc_js($atts['paging']);
$table_page_length = esc_js($atts['page_length']);
$table_paging_type = esc_js($atts['paging_type']);
$table_b_length_change = esc_js($atts['b_length_change']);
$table_ordering = esc_js($atts['ordering']);
$table_order_row_number = esc_js($atts['order_row_number']);
$table_order_row_number_sort = esc_js($atts['order_row_number_sort']);
$table_searching = esc_js($atts['searching']);
$allowed_table_paging_types = array('simple', 'simple_numbers', 'full', 'full_numbers');
$table_paging_type = in_array($atts['paging_type'], $allowed_table_paging_types, true) ? $atts['paging_type'] : 'simple';
$wp_jdt_script = "";
$wp_jdt_script .= "<script type='text/javascript' language='javascript' class='init'> \n";
$wp_jdt_script .= "jQuery(document).ready(function() { \n";
$wp_jdt_script .= "jQuery('#$table_id').DataTable({ \n";
$wp_jdt_script .= "'info': $table_info, \n";
$wp_jdt_script .= "'paging': $table_paging, \n";
if ($table_page_length > 0) {
$wp_jdt_script .= "'pageLength': $table_page_length, \n";
} else {
$wp_jdt_script .= "'pageLength': $wp_jdt_page_length, \n";
}
$wp_jdt_script .= "'pagingType': '$table_paging_type', \n";
$wp_jdt_script .= "'bLengthChange': $table_b_length_change, \n";
$wp_jdt_script .= "'ordering': $table_ordering, \n";
if ($table_order_row_number != '') { // if 'Specific Column Order' is not null than add this attribute
$table_order_row_number_sort = ($table_order_row_number_sort != "") ? $table_order_row_number_sort : 'desc';
$wp_jdt_script .= "'order': [$table_order_row_number,'$table_order_row_number_sort'], \n";
}
$wp_jdt_script .= "'searching': $table_searching, \n";
$wp_jdt_script .= "language: {\n";
$wp_jdt_script .= "'search': '" . __('Searching', 'wp-jquery-datatable') . ":', \n";
$wp_jdt_script .= "}, \n";
$wp_jdt_script .= "} ); \n";
$table_wrapper_id = $table_id . "_wrapper";
$wp_jdt_script .= "jQuery('#$table_wrapper_id select').prepend('<option value=$table_page_length>" . __('Select') . "</option>').val('');";
$wp_jdt_script .= "} ); \n";
$wp_jdt_script .= "</script>";
$table_b_length_change = ($atts['b_length_change'] === 'true') ? 'true' : 'false';
$table_ordering = ($atts['ordering'] === 'true') ? 'true' : 'false';
$table_order_row_number = absint($atts['order_row_number']);
$table_order_sort = (strtolower($atts['order_row_number_sort']) === 'asc') ? 'asc' : 'desc';
$table_searching = ($atts['searching'] === 'true') ? 'true' : 'false';
// css and js
wp_enqueue_style('jdt-style-data-tables');
wp_enqueue_script('jdt-js-datatables');
return $wp_jdt_script;
// Load JS script via wp_footer anonymous function
add_action('wp_footer', function () use (
$table_id,
$table_info,
$table_paging,
$table_page_length,
$table_paging_type,
$table_b_length_change,
$table_ordering,
$table_order_row_number,
$table_order_sort,
$table_searching
) {
?>
<script type="text/javascript">
jQuery(document).ready(function($) {
$('#<?php echo esc_js($table_id); ?>').DataTable({
'info': <?php echo $table_info; ?>,
'paging': <?php echo $table_paging; ?>,
'pageLength': <?php echo $table_page_length; ?>,
'pagingType': '<?php echo esc_js($table_paging_type); ?>',
'bLengthChange': <?php echo $table_b_length_change; ?>,
'ordering': <?php echo $table_ordering; ?>,
'order': [<?php echo $table_order_row_number; ?>, '<?php echo esc_js($table_order_sort); ?>'],
'searching': <?php echo $table_searching; ?>,
'language': {
'search': '<?php echo esc_js(esc_html__('Searching', 'wp-jquery-datatable')); ?>:'
}
});
$('#<?php echo esc_js($table_id); ?>_wrapper select')
.prepend('<option value="<?php echo $table_page_length; ?>"><?php echo esc_js(esc_html__('Select')); ?></option>')
.val('');
});
</script>
<?php
});
// return empty string
return '';
}
register_uninstall_hook(__FILE__, 'wp_jdt_uninstall'); // uninstall plug-in