WordPress.org

Make WordPress Core

Changeset 14670


Ignore:
Timestamp:
05/15/10 19:47:03 (5 years ago)
Author:
nacin
Message:

Validation and nonce improvements to custom background UI. props ocean90, see #12186.

Location:
trunk/wp-admin
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/custom-background.php

    r14628 r14670  
    8686            return; 
    8787 
    88         check_admin_referer('custom-background'); 
    89  
    9088        if ( isset($_POST['reset-background']) ) { 
    91             remove_theme_mod( 'background_image' ); 
     89            check_admin_referer('custom-background-reset', '_wpnonce-custom-background-reset'); 
     90            remove_theme_mod('background_image'); 
     91            remove_theme_mod('background_image_thumb'); 
    9292            return; 
    9393        } 
    9494        if ( isset($_POST['remove-background']) ) { 
    9595            // @TODO: Uploaded files are not removed here. 
     96            check_admin_referer('custom-background-remove', '_wpnonce-custom-background-remove'); 
    9697            set_theme_mod('background_image', ''); 
     98            set_theme_mod('background_image_thumb', ''); 
     99            return; 
    97100        } 
    98101 
    99102        if ( isset($_POST['background-repeat']) ) { 
     103            check_admin_referer('custom-background'); 
    100104            if ( in_array($_POST['background-repeat'], array('repeat', 'no-repeat', 'repeat-x', 'repeat-y')) ) 
    101105                $repeat = $_POST['background-repeat']; 
     
    105109        } 
    106110        if ( isset($_POST['background-position']) ) { 
     111            check_admin_referer('custom-background'); 
    107112            if ( in_array($_POST['background-position'], array('center', 'right', 'left')) ) 
    108113                $position = $_POST['background-position']; 
     
    112117        } 
    113118        if ( isset($_POST['background-attachment']) ) { 
     119            check_admin_referer('custom-background'); 
    114120            if ( in_array($_POST['background-attachment'], array('fixed', 'scroll')) ) 
    115121                $attachment = $_POST['background-attachment']; 
     
    119125        } 
    120126        if ( isset($_POST['background-color']) ) { 
     127            check_admin_referer('custom-background'); 
    121128            $color = preg_replace('/[^0-9a-fA-F]/', '', $_POST['background-color']); 
    122129            if ( strlen($color) == 6 || strlen($color) == 3 ) 
     
    157164<?php 
    158165$background_styles = ''; 
    159 if ( get_background_color() ) { 
    160     $background_styles .= "background-color: #" . get_background_color() . ";"; 
     166if ( $bgcolor = get_background_color() ) { 
     167    $background_styles .= "background-color: #{$bgcolor};"; 
    161168} 
    162169 
     
    164171    $background_styles .= " 
    165172    background-image: url(" . get_theme_mod('background_image_thumb', '') . "); 
    166     background-repeat: ". get_theme_mod('background_repeat', 'no-repeat') . "; 
    167     background-position: top ". get_theme_mod('background_position', 'left') . "; 
    168     background-attachment: " . get_theme_mod('background_position', 'fixed') . "; 
     173    background-repeat: ". get_theme_mod('background_repeat', 'repeat') . "; 
     174    background-position: ". get_theme_mod('background_position', 'left') . " top; 
     175    background-attachment: " . get_theme_mod('background_attachment', 'fixed') . "; 
    169176    "; 
    170177} 
     
    172179<div id="custom-background-image" style="<?php echo $background_styles; ?>"> 
    173180<?php if ( get_background_image() ) { ?> 
    174 <img class="custom-background-image" src="<?php echo get_theme_mod('background_image_thumb', ''); ?>" style="visibility:hidden;" /><br /> 
    175 <img class="custom-background-image" src="<?php echo get_theme_mod('background_image_thumb', ''); ?>" style="visibility:hidden;" /> 
     181<img class="custom-background-image" src="<?php echo get_theme_mod('background_image_thumb', ''); ?>" style="visibility:hidden;" alt="" /><br /> 
     182<img class="custom-background-image" src="<?php echo get_theme_mod('background_image_thumb', ''); ?>" style="visibility:hidden;" alt="" /> 
    176183<?php } ?> 
    177184<br class="clear" /> 
     
    185192<td><p><?php _e('This will remove the background image. You will not be able to restore any customizations.') ?></p> 
    186193<form method="post" action=""> 
    187 <?php wp_nonce_field('custom-background'); ?> 
     194<?php wp_nonce_field('custom-background-remove', '_wpnonce-custom-background-remove'); ?> 
    188195<input type="submit" class="button" name="remove-background" value="<?php esc_attr_e('Remove Background'); ?>" /> 
    189196</form> 
     
    197204<td><p><?php _e('This will restore the original background image. You will not be able to restore any customizations.') ?></p> 
    198205<form method="post" action=""> 
    199 <?php wp_nonce_field('custom-background'); ?> 
     206<?php wp_nonce_field('custom-background-reset', '_wpnonce-custom-background-reset'); ?> 
    200207<input type="submit" class="button" name="reset-background" value="<?php esc_attr_e('Restore Original Image'); ?>" /> 
    201208</form> 
    202209</td> 
    203210</tr> 
    204 </form> 
     211 
    205212<?php endif; ?> 
    206213<tr valign="top"> 
    207214<th scope="row"><?php _e('Upload Image'); ?></th> 
    208 <td><form enctype="multipart/form-data" id="uploadForm" method="post" action=""> 
     215<td><form enctype="multipart/form-data" id="upload-form" method="post" action=""> 
    209216<label for="upload"><?php _e('Choose an image from your computer:'); ?></label><br /><input type="file" id="upload" name="import" /> 
    210217<input type="hidden" name="action" value="save" /> 
    211 <?php wp_nonce_field('custom-background') ?> 
     218<?php wp_nonce_field('custom-background-upload', '_wpnonce-custom-background-upload') ?> 
    212219<p class="submit"> 
    213220<input type="submit" value="<?php esc_attr_e('Upload'); ?>" /> 
     
    300307            return; 
    301308 
    302         check_admin_referer('custom-background'); 
     309        check_admin_referer('custom-background-upload', '_wpnonce-custom-background-upload'); 
    303310        $overrides = array('test_form' => false); 
    304311        $file = wp_handle_upload($_FILES['import'], $overrides); 
     
    330337        $thumbnail = wp_get_attachment_image_src( $id, 'thumbnail' ); 
    331338        set_theme_mod('background_image_thumb', esc_url( $thumbnail[0] ) ); 
    332          
    333         set_theme_mod('background_position', get_theme_mod('background_position', 'left') ); 
    334         set_theme_mod('background_repeat', get_theme_mod('background_repeat', 'tile') ); 
    335         set_theme_mod('background-attachment',  get_theme_mod('background_position', 'fixed') ); 
    336339 
    337340        do_action('wp_create_file_in_uploads', $file, $id); // For replication 
  • trunk/wp-admin/js/custom-background.dev.js

    r14404 r14670  
    1 var buttons = ['#pickcolor'], farbtastic; 
     1var farbtastic; 
    22 
    33function pickColor(color) { 
     4    farbtastic.setColor(color); 
    45    jQuery('#background-color').val(color); 
    5     farbtastic.setColor(color); 
    66    jQuery('#custom-background-image').css('background-color', color); 
    77} 
     
    1111        jQuery('#colorPickerDiv').show(); 
    1212    }); 
     13 
    1314    jQuery('#background-color').keyup(function() { 
    1415        var _hex = jQuery('#background-color').val(); 
     
    2223            pickColor( hex ); 
    2324    }); 
     25 
    2426    jQuery('input[name="background-position"]').change(function() { 
    25         jQuery('#custom-background-image').css('background-position', 'top '+jQuery(this).val()); 
     27        jQuery('#custom-background-image').css('background-position', 'top ' + jQuery(this).val()); 
    2628    }); 
     29 
    2730    jQuery('select[name="background-repeat"]').change(function() { 
    2831        jQuery('#custom-background-image').css('background-repeat', jQuery(this).val()); 
     32    }); 
     33     
     34    jQuery('input[name="background-attachment"]').change(function() { 
     35        jQuery('#custom-background-image').css('background-attachment', jQuery(this).val()); 
    2936    }); 
    3037 
     
    3239        pickColor(color); 
    3340    }); 
    34     pickColor(customBackgroundL10n.backgroundcolor); 
     41    pickColor(jQuery('#background-color').val()); 
     42 
     43    jQuery(document).mousedown(function(){ 
     44        jQuery('#colorPickerDiv').each(function(){ 
     45            var display = jQuery(this).css('display'); 
     46            if ( display == 'block' ) 
     47                jQuery(this).fadeOut(2); 
     48        }); 
     49    }); 
    3550}); 
    36  
    37 jQuery(document).mousedown(function(){ 
    38     hide_picker(); // Make the picker disappear if you click outside its div element 
    39 }); 
    40  
    41 function hide_picker(what) { 
    42     var update = false; 
    43     jQuery('#colorPickerDiv').each(function(){ 
    44         var id = jQuery(this).attr('id'); 
    45         if ( id == what ) 
    46             return; 
    47  
    48         var display = jQuery(this).css('display'); 
    49         if ( display == 'block' ) 
    50             jQuery(this).fadeOut(2); 
    51     }); 
    52 } 
  • trunk/wp-admin/js/custom-background.js

    r13856 r14670  
    1 var buttons=["#pickcolor"],farbtastic;function pickColor(color){jQuery("#background-color").val(color);farbtastic.setColor(color);jQuery("#custom-background-image").css("background-color",color)}jQuery(document).ready(function(){jQuery("#pickcolor").click(function(){jQuery("#colorPickerDiv").show()});jQuery("#background-color").keyup(function(){var _hex=jQuery("#background-color").val();var hex=_hex;if(hex[0]!="#"){hex="#"+hex}hex=hex.replace(/[^#a-fA-F0-9]+/,"");if(hex!=_hex){jQuery("#background-color").val(hex)}if(hex.length==4||hex.length==7){pickColor(hex)}});jQuery('input[name="background-position"]').change(function(){jQuery("#custom-background-image").css("background-position","top "+jQuery(this).val())});jQuery('select[name="background-repeat"]').change(function(){jQuery("#custom-background-image").css("background-repeat",jQuery(this).val())});farbtastic=jQuery.farbtastic("#colorPickerDiv",function(color){pickColor(color)});pickColor(customBackgroundL10n.backgroundcolor)});jQuery(document).mousedown(function(){hide_picker()});function hide_picker(what){var update=false;jQuery("#colorPickerDiv").each(function(){var id=jQuery(this).attr("id");if(id==what){return}var display=jQuery(this).css("display");if(display=="block"){jQuery(this).fadeOut(2)}})}; 
     1var farbtastic;function pickColor(a){farbtastic.setColor(a);jQuery("#background-color").val(a);jQuery("#custom-background-image").css("background-color",a)}jQuery(document).ready(function(){jQuery("#pickcolor").click(function(){jQuery("#colorPickerDiv").show()});jQuery("#background-color").keyup(function(){var b=jQuery("#background-color").val();var a=b;if(a[0]!="#"){a="#"+a}a=a.replace(/[^#a-fA-F0-9]+/,"");if(a!=b){jQuery("#background-color").val(a)}if(a.length==4||a.length==7){pickColor(a)}});jQuery('input[name="background-position"]').change(function(){jQuery("#custom-background-image").css("background-position","top "+jQuery(this).val())});jQuery('select[name="background-repeat"]').change(function(){jQuery("#custom-background-image").css("background-repeat",jQuery(this).val())});jQuery('input[name="background-attachment"]').change(function(){jQuery("#custom-background-image").css("background-attachment",jQuery(this).val())});farbtastic=jQuery.farbtastic("#colorPickerDiv",function(a){pickColor(a)});pickColor(jQuery("#background-color").val());jQuery(document).mousedown(function(){jQuery("#colorPickerDiv").each(function(){var a=jQuery(this).css("display");if(a=="block"){jQuery(this).fadeOut(2)}})})}); 
Note: See TracChangeset for help on using the changeset viewer.