HEX
Server: LiteSpeed
System: Linux cde4.duelhost.dk 4.18.0-553.34.1.lve.el8.x86_64 #1 SMP Thu Jan 9 16:30:32 UTC 2025 x86_64
User: dmhkjfau (1027)
PHP: 7.4.33
Disabled: exec,system,passthru,shell_exec,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Upload Files
File: /home/dmhkjfau/public_html/wp-content/plugins/wp-seopress/src/Actions/Api/PagePreview.php
<?php // phpcs:ignore

namespace SEOPress\Actions\Api;

if ( ! defined( 'ABSPATH' ) ) {
	exit;
}

use SEOPress\Core\Hooks\ExecuteHooks;
use SEOPress\ManualHooks\ApiHeader;

/**
 * Page Preview
 */
class PagePreview implements ExecuteHooks {

	/**
	 * The Page Preview hooks.
	 *
	 * @since 5.0.0
	 */
	public function hooks() {
		add_action( 'rest_api_init', array( $this, 'register' ) );
	}

	/**
	 * The Page Preview register.
	 *
	 * @since 5.0.0
	 *
	 * @return void
	 */
	public function register() {
		register_rest_route(
			'seopress/v1',
			'/posts/(?P<id>\d+)/page-preview',
			array(
				'methods'             => 'GET',
				'callback'            => array( $this, 'preview' ),
				'args'                => array(
					'id' => array(
						'validate_callback' => function ( $param, $request, $key ) { // phpcs:ignore
							return is_numeric( $param );
						},
					),
				),
				'permission_callback' => function ( $request ) {
					return current_user_can( 'edit_post', (int) $request['id'] );
				},
			)
		);

		// Same handler over POST so the browser can hand us the rendered HTML
		// it captured (crawler view, WAF-proof) instead of us looping back.
		register_rest_route(
			'seopress/v1',
			'/posts/(?P<id>\d+)/page-preview/analyze',
			array(
				'methods'             => 'POST',
				'callback'            => array( $this, 'preview' ),
				'args'                => array(
					'id' => array(
						'validate_callback' => function ( $param, $request, $key ) { // phpcs:ignore
							return is_numeric( $param );
						},
					),
				),
				'permission_callback' => function ( $request ) {
					return current_user_can( 'edit_post', (int) $request['id'] );
				},
			)
		);
	}

	/**
	 * The Page Preview process preview.
	 *
	 * @param \WP_REST_Request $request The request.
	 *
	 * @since 5.0.0
	 */
	public function preview( \WP_REST_Request $request ) {
		$api_header = new ApiHeader();
		$api_header->hooks();

		$id = (int) $request->get_param( 'id' );

		// Prefer the browser-captured HTML; fall back to the server loop-back.
		$html = $request->get_param( 'html' ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput -- parsed read-only by DOMDocument, never echoed.

		if ( ! empty( $html ) ) {
			$str = (string) $html;
		} else {
			$dom_result = seopress_get_service( 'RequestPreview' )->getDomById( $id );

			if ( ! $dom_result['success'] ) {
				$message = '';

				switch ( $dom_result['code'] ) {
					case 404:
						$message = __( 'To get your Google snippet preview, publish your post!', 'wp-seopress' );
						break;
					case 401:
						$message = __( 'Your site is protected by an authentication.', 'wp-seopress' );
						break;
				}

				// Match the nested { value } shape returned on success
				// (DomFilterContent) so consumers reading `title.value` /
				// `description.value` (GooglePreview, field placeholders)
				// surface the message instead of a blank preview.
				return new \WP_REST_Response(
					array(
						'title'       => array( 'value' => $message ),
						'description' => array( 'value' => '' ),
					)
				);
			}

			$str = $dom_result['body'];
		}

		$data = seopress_get_service( 'DomFilterContent' )->getData( $str, $id );

		if ( defined( 'WP_DEBUG' ) && WP_DEBUG ) {
			$data['analyzed_content_id'] = $id;
		}

		$data['analysis_target_kw'] = array(
			'value' => array_filter( explode( ',', strtolower( (string) get_post_meta( $id, '_seopress_analysis_target_kw', true ) ) ) ),
		);

		return new \WP_REST_Response( $data );
	}
}