Compare commits
6
Commits
fae1fd08ba
..
v1.2.1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c611268bdb | ||
|
|
721c4be1d6
|
||
|
|
3aa65bad06 | ||
|
|
f3ba09b195 | ||
|
|
771942be8b | ||
|
|
242150569b
|
@@ -11,6 +11,13 @@ When a `v*` tag is pushed, `.gitea/workflows/release.yml` publishes the matching
|
||||
the plugin to the next patch version and adds a fresh section here for it. Record
|
||||
each change under the current top section as you work.
|
||||
|
||||
## [1.2.1]
|
||||
|
||||
### Fixed
|
||||
- Registration questions, offering titles/notes, and policy names longer than their storage limit are no longer silently discarded. Previously typing a fixed-size field past its maximum length reported success but saved nothing — the database quietly rejected the over-long value. These fields now cap the input in the form, and the API rejects an over-long value with a clear error.
|
||||
- Students can no longer reach the WordPress dashboard. A student who navigates to `wp-admin` is redirected to the site front end and the admin toolbar is hidden for them, so they only ever see the studio's booking pages. Anyone who runs the studio — administrators, studio admins, and instructors — keeps full `wp-admin` access.
|
||||
- The instructor picker on the **Add/Edit Offering** form no longer comes up empty for a solo studio owner. When the person running the studio teaches from a WordPress administrator account (the default single-account setup), they now appear in the instructor dropdown and can be assigned to a class.
|
||||
|
||||
## [1.2.0]
|
||||
|
||||
### Added
|
||||
@@ -21,10 +28,15 @@ each change under the current top section as you work.
|
||||
- The **Add/Edit Offering** form now shows only the fields relevant to the selected kind: the group-class settings (capacity, dates, times, enrolment/withdrawal deadlines, sessions, schedule note, invite-only) appear only for a group class, and the weekly-reservation option only for a private lesson.
|
||||
- Instructors can add students to any group class by hand from its details page (**Add students directly**), which now appears for public classes too, not just invite-only ones. This bypasses the enrolment deadline and capacity, so a student can be enrolled as a **late enrolment** after the class has closed to self-enrolment.
|
||||
- Studio admins and instructors can open a **lesson detail view** from the Scheduler and My Lessons lists, showing the offering booked, the policy versions the student accepted (with acceptance time and IP), and their intake answers. On My Lessons an instructor may only open their own lessons; the studio Scheduler may open any.
|
||||
- The **Student Registration** block's "registration is by invitation only" message is now customisable, under a new **Invitation-only notice** panel (shortcode: `invite_only_message`). Leaving it blank keeps the default wording.
|
||||
|
||||
### Changed
|
||||
- The student **upcoming lessons** panel now shows each booked offering's name and length beside the time, and lists only the soonest five lessons with a "Show all" reveal. The Scheduler and My Lessons week/list views likewise show the booked offering.
|
||||
|
||||
### Fixed
|
||||
- Accepting an invitation now keeps the student signed in. Previously the registration form processed the submission after the page had started rendering, so the sign-in cookie was never sent and the new student was bounced back to the (logged-out) registration page; it is now handled before any output, and the student lands logged in.
|
||||
- Account-registration questions now save. On sites first installed before account-scope questions existed, the `us_questions.offering_id` column was left `NOT NULL` (the schema migration relied on `dbDelta`, which does not reliably relax a column to allow `NULL`), so saving an account question failed with "Column 'offering_id' cannot be null". A one-time, self-healing migration relaxes the column on the next load.
|
||||
|
||||
## [1.1.1]
|
||||
|
||||
### Fixed
|
||||
|
||||
+25
-12
@@ -5,7 +5,7 @@
|
||||
const { registerBlockType } = wp.blocks;
|
||||
const { createElement: el, useState, useEffect } = wp.element;
|
||||
const { useBlockProps, InspectorControls } = wp.blockEditor;
|
||||
const { PanelBody, SelectControl, ToggleControl } = wp.components;
|
||||
const { PanelBody, SelectControl, ToggleControl, TextareaControl } = wp.components;
|
||||
const { useSelect } = wp.data;
|
||||
const apiFetch = wp.apiFetch;
|
||||
const ServerSideRender = wp.serverSideRender;
|
||||
@@ -151,18 +151,31 @@
|
||||
shortcode: 'us_student_register',
|
||||
attributes: {
|
||||
loginPageId: { type: 'number', default: 0 },
|
||||
inviteOnlyMessage: { type: 'string', default: '' },
|
||||
},
|
||||
inspector: (attributes, setAttributes) => el(
|
||||
PanelBody,
|
||||
{ title: __('After email confirmation', 'unsupervised-schedular') },
|
||||
el(PageSelect, {
|
||||
label: __('Sign-in page', 'unsupervised-schedular'),
|
||||
help: __('Where the sign-in link shown after a student confirms their email address sends them.', 'unsupervised-schedular'),
|
||||
defaultLabel: __('WordPress login screen', 'unsupervised-schedular'),
|
||||
value: attributes.loginPageId,
|
||||
onChange: (loginPageId) => setAttributes({ loginPageId }),
|
||||
})
|
||||
),
|
||||
inspector: (attributes, setAttributes) => [
|
||||
el(
|
||||
PanelBody,
|
||||
{ title: __('After email confirmation', 'unsupervised-schedular'), key: 'confirmation' },
|
||||
el(PageSelect, {
|
||||
label: __('Sign-in page', 'unsupervised-schedular'),
|
||||
help: __('Where the sign-in link shown after a student confirms their email address sends them.', 'unsupervised-schedular'),
|
||||
defaultLabel: __('WordPress login screen', 'unsupervised-schedular'),
|
||||
value: attributes.loginPageId,
|
||||
onChange: (loginPageId) => setAttributes({ loginPageId }),
|
||||
})
|
||||
),
|
||||
el(
|
||||
PanelBody,
|
||||
{ title: __('Invitation-only notice', 'unsupervised-schedular'), key: 'invite-only' },
|
||||
el(TextareaControl, {
|
||||
label: __('Message', 'unsupervised-schedular'),
|
||||
help: __('Shown when registration is invite-only and the visitor has no valid invite link. Leave blank to use the default wording.', 'unsupervised-schedular'),
|
||||
value: attributes.inviteOnlyMessage,
|
||||
onChange: (inviteOnlyMessage) => setAttributes({ inviteOnlyMessage }),
|
||||
})
|
||||
),
|
||||
],
|
||||
},
|
||||
{
|
||||
name: 'us-scheduler/group-classes',
|
||||
|
||||
@@ -97,7 +97,7 @@ recorded in `us_policy_acceptances` with `registration_type = account` and
|
||||
1. Studio admin opens **Invites** (`manage_students`) and invites an email; an invite row is created storing the token's SHA-256 hash, and the registration link (with the raw token) is shown **once** in a notice. To re-send a lost link, revoke and re-invite.
|
||||
2. The invitee opens `[us_student_register]` with the token (`?us_invite=<token>`); the lookup hashes the submitted token and matches it against the stored hash.
|
||||
3. The form shows the invited email **pre-filled and read-only** (the server always uses the invite's address on submit, so a tampered value is ignored) and collects a display name and password, and renders the signup-scoped published policies, each with a required acceptance checkbox. A token that is no longer redeemable (expired / accepted / revoked) renders the normal editable email field instead when open registration is on.
|
||||
4. On submit, the token is re-validated (hashed lookup); a `us_student` user is created, the policy acceptances are recorded (`account` type), the invite is marked `accepted`, and the user is logged in. If the invite carries an `offering_id` (a group-class email invite), the new account is linked to the matching access grant so the invite-only class becomes enrollable for them — see `group-classes.md`.
|
||||
4. On submit, the token is re-validated (hashed lookup); a `us_student` user is created, the policy acceptances are recorded (`account` type), the invite is marked `accepted`, and the user is logged in. The submission is processed on `template_redirect` (`RegistrationPage::maybeHandleSubmit()`) **before** any page output so `wp_set_auth_cookie()` actually persists — it then post/redirect/gets back to the page with `?us_registered=invite`, where the now-logged-in student sees the "created and logged in" confirmation. (Processing the form inside `render()`, which runs during `the_content`, sent the cookie after headers and left the student logged out on the next view.) If the invite carries an `offering_id` (a group-class email invite), the new account is linked to the matching access grant so the invite-only class becomes enrollable for them — see `group-classes.md`.
|
||||
|
||||
## Flow (self-approval mode)
|
||||
1. Studio admin enables **Studio Settings → Registration** and selects the registration page (shared with invites, `us_registration_page_id`).
|
||||
@@ -126,6 +126,7 @@ recorded in `us_policy_acceptances` with `registration_type = account` and
|
||||
|
||||
## Frontend Shortcode
|
||||
- `[us_student_register]` — the registration page. In `invite` mode: shows the form for a valid pending invite, else an "by invitation only" message. In `self_approval` mode: shows the form to anyone (editable email), and renders confirmation-result notices from `?us_confirmed=1|expired`.
|
||||
- The invitation-only message is customisable: block attribute `inviteOnlyMessage` (set under the block's **Invitation-only notice** panel) / shortcode attribute `invite_only_message`. Blank falls back to the default wording (`RegistrationPage::inviteOnlyMessage()`).
|
||||
|
||||
## Token Redirect
|
||||
A `template_redirect` handler (`RegistrationPage::maybeRedirectToRegistrationPage()`)
|
||||
|
||||
@@ -80,6 +80,7 @@ through the server-rendered admin page and read directly by `RegistrationPage`.
|
||||
- Signup step two: `Unsupervised\Schedular\Auth\RegistrationPage`, `templates/frontend/register-page.php`, `assets/js/register.js`
|
||||
- Admin review: `Unsupervised\Schedular\Auth\StudentHistory::registrationInfo()`, `templates/admin/student-detail.php`
|
||||
- Schema: `us_questions.scope` + nullable `us_questions.offering_id` (requires a plugin version bump so `dbDelta` runs)
|
||||
- Nullability repair: `dbDelta` does **not** reliably relax a column from `NOT NULL` to `NULL`, so sites created before account-scope questions kept `offering_id NOT NULL` and rejected account inserts. `QuestionRepository::ensureOfferingNullable()` re-applies the nullable definition (idempotent `ALTER … MODIFY`); `Plugin::boot()` runs it once, guarded by the `us_questions_offering_nullable` option rather than the version gate (affected sites may already be on the current version)
|
||||
|
||||
## Tests
|
||||
- `tests/Unit/Registration/QuestionRepositoryTest.php`
|
||||
|
||||
+105
-17
@@ -30,6 +30,13 @@ class RegistrationPage {
|
||||
*/
|
||||
private const RESULT_CONFIRM_GROUP = 'confirm_group';
|
||||
|
||||
/**
|
||||
* Validation error from the most recent submission processed on
|
||||
* `template_redirect`, carried over to {@see render()} so it can be shown
|
||||
* inline with the form. Empty when the last submit succeeded or none ran.
|
||||
*/
|
||||
private string $submitError = '';
|
||||
|
||||
public function __construct(
|
||||
private InviteRepository $invites,
|
||||
private PolicyRepository $policies,
|
||||
@@ -45,15 +52,29 @@ class RegistrationPage {
|
||||
/**
|
||||
* Renders the student registration shortcode output.
|
||||
*
|
||||
* @param array<int|string, mixed> $atts Block attributes (`loginPageId`) or
|
||||
* shortcode attributes (`login_page_id`).
|
||||
* @param array<int|string, mixed> $atts Block attributes (`loginPageId`,
|
||||
* `inviteOnlyMessage`) or shortcode
|
||||
* attributes (`login_page_id`,
|
||||
* `invite_only_message`).
|
||||
*/
|
||||
public function render( array $atts ): string {
|
||||
// A just-completed invite signup is redirected back here already logged
|
||||
// in (see maybeHandleSubmit); its success flag distinguishes that from a
|
||||
// visitor who simply happens to be signed in already.
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only display flag; the submit that set it was nonce-checked.
|
||||
$registered = sanitize_key( Val::string( wp_unslash( $_GET['us_registered'] ?? '' ) ) );
|
||||
|
||||
if ( is_user_logged_in() ) {
|
||||
if ( self::RESULT_INVITE === $registered ) {
|
||||
return '<div class="us-register-form"><p class="us-success">'
|
||||
. esc_html__( 'Your account has been created and you are now logged in.', 'unsupervised-schedular' )
|
||||
. '</p></div>';
|
||||
}
|
||||
|
||||
return '<p>' . esc_html__( 'You already have an account and are logged in.', 'unsupervised-schedular' ) . '</p>';
|
||||
}
|
||||
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- token identifies the invite; the form submit is nonce-checked below.
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- token identifies the invite; the form submit is nonce-checked in maybeHandleSubmit.
|
||||
$token = sanitize_text_field( Val::string( wp_unslash( $_REQUEST['us_invite'] ?? '' ) ) );
|
||||
// Only the token's hash is stored, so hash the submitted token for lookup.
|
||||
$invite = '' !== $token ? $this->invites->findByToken( Invite::hashToken( $token ) ) : null;
|
||||
@@ -65,17 +86,12 @@ class RegistrationPage {
|
||||
// fail to submit — the stale invite's address.
|
||||
$inviteValid = null !== $invite && $invite->isAcceptable( current_time( 'mysql' ) );
|
||||
|
||||
$error = '';
|
||||
$successType = '';
|
||||
|
||||
if ( isset( $_POST['us_register'] ) && check_admin_referer( 'us_student_register' ) ) {
|
||||
$result = $this->handleSubmit( $invite, $open );
|
||||
if ( in_array( $result, [ self::RESULT_INVITE, self::RESULT_CONFIRM, self::RESULT_CONFIRM_GROUP ], true ) ) {
|
||||
$successType = $result;
|
||||
} else {
|
||||
$error = $result;
|
||||
}
|
||||
}
|
||||
// The submission itself is processed in maybeHandleSubmit on
|
||||
// template_redirect (before any output), so the invite auto-login cookie
|
||||
// is actually sent. Its success signal returns here as ?us_registered;
|
||||
// only a validation error is carried on the instance to show inline.
|
||||
$successType = in_array( $registered, [ self::RESULT_CONFIRM, self::RESULT_CONFIRM_GROUP ], true ) ? $registered : '';
|
||||
$error = $this->submitError;
|
||||
|
||||
// Result of an email-confirmation link (set by EmailConfirmationHandler's redirect).
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only display flag, not a state change.
|
||||
@@ -84,9 +100,10 @@ class RegistrationPage {
|
||||
// Where the post-confirmation prompt sends students to sign in.
|
||||
$loginUrl = $this->loginUrl( Val::int( $atts['loginPageId'] ?? $atts['login_page_id'] ?? 0 ) );
|
||||
|
||||
$policyForms = $this->signupPolicies();
|
||||
$accountQuestions = $this->questions->findByScope( Question::SCOPE_ACCOUNT, activeOnly: true );
|
||||
$canRegister = $open || $inviteValid;
|
||||
$policyForms = $this->signupPolicies();
|
||||
$accountQuestions = $this->questions->findByScope( Question::SCOPE_ACCOUNT, activeOnly: true );
|
||||
$canRegister = $open || $inviteValid;
|
||||
$inviteOnlyMessage = $this->inviteOnlyMessage( $atts );
|
||||
|
||||
// The two-step script only matters when there is a second step to reveal.
|
||||
if ( $canRegister && '' === $successType && [] !== $accountQuestions ) {
|
||||
@@ -98,6 +115,77 @@ class RegistrationPage {
|
||||
return (string) ob_get_clean();
|
||||
}
|
||||
|
||||
/**
|
||||
* Process a submitted registration on `template_redirect`, before any page
|
||||
* output. Running here (rather than inside {@see render()}, which fires
|
||||
* during `the_content` after headers are sent) is what lets the invite
|
||||
* branch's `wp_set_auth_cookie()` actually persist — otherwise the student
|
||||
* appears logged in for a single render and is logged out on the next view.
|
||||
*
|
||||
* On success the request is redirected (post/redirect/get) with a
|
||||
* `?us_registered` flag so a refresh cannot resubmit; a validation error is
|
||||
* stashed for {@see render()} to show inline with the form.
|
||||
*/
|
||||
public function maybeHandleSubmit(): void {
|
||||
if ( ! isset( $_POST['us_register'] ) || is_user_logged_in() ) {
|
||||
return;
|
||||
}
|
||||
|
||||
if ( ! check_admin_referer( 'us_student_register' ) ) {
|
||||
return;
|
||||
}
|
||||
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- verified by check_admin_referer above.
|
||||
$token = sanitize_text_field( Val::string( wp_unslash( $_REQUEST['us_invite'] ?? '' ) ) );
|
||||
$invite = '' !== $token ? $this->invites->findByToken( Invite::hashToken( $token ) ) : null;
|
||||
$open = $this->settings->openRegistrationEnabled();
|
||||
|
||||
$result = $this->handleSubmit( $invite, $open );
|
||||
|
||||
if ( in_array( $result, [ self::RESULT_INVITE, self::RESULT_CONFIRM, self::RESULT_CONFIRM_GROUP ], true ) ) {
|
||||
$this->redirect( add_query_arg( 'us_registered', $result, $this->currentUrl() ) );
|
||||
return;
|
||||
}
|
||||
|
||||
$this->submitError = $result;
|
||||
}
|
||||
|
||||
/**
|
||||
* The current page's clean permalink, used as the post/redirect/get target
|
||||
* so the invite token and any stale flags are dropped from the URL.
|
||||
*/
|
||||
private function currentUrl(): string {
|
||||
$url = get_permalink();
|
||||
|
||||
return is_string( $url ) ? $url : home_url( '/' );
|
||||
}
|
||||
|
||||
/**
|
||||
* Issues the post-submit redirect and stops the request. Split out so tests
|
||||
* can observe the target without the process exiting.
|
||||
*/
|
||||
protected function redirect( string $url ): void {
|
||||
wp_safe_redirect( $url );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* The message shown when registration is closed and no valid invite is
|
||||
* present. Studios can override the default via the block
|
||||
* (`inviteOnlyMessage`) or shortcode (`invite_only_message`) attribute.
|
||||
*
|
||||
* @param array<int|string, mixed> $atts
|
||||
*/
|
||||
private function inviteOnlyMessage( array $atts ): string {
|
||||
$custom = trim( Val::string( $atts['inviteOnlyMessage'] ?? $atts['invite_only_message'] ?? '' ) );
|
||||
|
||||
if ( '' !== $custom ) {
|
||||
return $custom;
|
||||
}
|
||||
|
||||
return esc_html__( 'Registration is by invitation only. Please use the link from your invitation email, or contact the studio.', 'unsupervised-schedular' );
|
||||
}
|
||||
|
||||
/**
|
||||
* Redirect to the configured registration page when an invite token lands
|
||||
* elsewhere (e.g. a link generated before the page was selected). Hooked on
|
||||
|
||||
@@ -0,0 +1,103 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Auth;
|
||||
|
||||
/**
|
||||
* Keeps front-end-only users (students) out of wp-admin entirely.
|
||||
*
|
||||
* Students authenticate through the front-end login shortcode and do all of
|
||||
* their work — booking, viewing lessons, paying — on the site's public pages.
|
||||
* They have no reason to see the WordPress dashboard, profile screen, or admin
|
||||
* bar, so this guard redirects them to the front end if they reach wp-admin and
|
||||
* hides the admin bar for them everywhere.
|
||||
*
|
||||
* Access is decided by capability, not role: anyone holding a back-office
|
||||
* capability (a WordPress administrator, studio admin, or instructor) keeps full
|
||||
* wp-admin access, while a user with none of them is treated as front-end only.
|
||||
*/
|
||||
class StudentAdminGuard {
|
||||
|
||||
/**
|
||||
* Capabilities that grant a genuine reason to be in wp-admin. A user holding
|
||||
* none of these is front-end only and is kept out of the dashboard.
|
||||
*
|
||||
* @var list<string>
|
||||
*/
|
||||
private const BACK_OFFICE_CAPS = [
|
||||
'manage_options',
|
||||
RoleManager::CAP_MANAGE_INSTRUCTORS,
|
||||
RoleManager::CAP_MANAGE_STUDENTS,
|
||||
RoleManager::CAP_MANAGE_OFFERINGS,
|
||||
RoleManager::CAP_MANAGE_QUESTIONS,
|
||||
RoleManager::CAP_MANAGE_POLICIES,
|
||||
RoleManager::CAP_MANAGE_BILLING,
|
||||
RoleManager::CAP_MANAGE_AVAILABILITY,
|
||||
RoleManager::CAP_VIEW_ALL_LESSONS,
|
||||
RoleManager::CAP_VIEW_ALL_PAYMENTS,
|
||||
RoleManager::CAP_VIEW_OWN_PAYMENTS,
|
||||
RoleManager::CAP_EXPORT_PAYMENTS,
|
||||
];
|
||||
|
||||
public function register(): void {
|
||||
add_action( 'admin_init', [ $this, 'redirectFromDashboard' ] );
|
||||
add_filter( 'show_admin_bar', [ $this, 'hideAdminBar' ] );
|
||||
}
|
||||
|
||||
/**
|
||||
* Redirect a front-end-only user away from any wp-admin page to the site
|
||||
* home, so the dashboard and profile screens are never reachable.
|
||||
*/
|
||||
public function redirectFromDashboard(): void {
|
||||
if ( ! $this->shouldBlockAdminAccess() ) {
|
||||
return;
|
||||
}
|
||||
|
||||
wp_safe_redirect( home_url( '/' ) );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether the current request into wp-admin should be bounced to the front
|
||||
* end. AJAX requests are always allowed through so front-end features that
|
||||
* call admin-ajax keep working.
|
||||
*/
|
||||
public function shouldBlockAdminAccess(): bool {
|
||||
if ( wp_doing_ajax() ) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if ( ! is_user_logged_in() ) {
|
||||
return false;
|
||||
}
|
||||
|
||||
return ! $this->hasBackOfficeAccess();
|
||||
}
|
||||
|
||||
/**
|
||||
* Hide the admin bar for front-end-only users; leave it untouched for anyone
|
||||
* with back-office access.
|
||||
*
|
||||
* @param bool $show Whether WordPress would otherwise show the admin bar.
|
||||
*/
|
||||
public function hideAdminBar( bool $show ): bool {
|
||||
if ( is_user_logged_in() && ! $this->hasBackOfficeAccess() ) {
|
||||
return false;
|
||||
}
|
||||
|
||||
return $show;
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether the current user holds any capability that warrants wp-admin access.
|
||||
*/
|
||||
private function hasBackOfficeAccess(): bool {
|
||||
foreach ( self::BACK_OFFICE_CAPS as $cap ) {
|
||||
if ( current_user_can( $cap ) ) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -105,10 +105,14 @@ class BlockRegistrar {
|
||||
'us-scheduler/student-register' => [
|
||||
'render' => [ $this, 'renderRegistration' ],
|
||||
'attributes' => [
|
||||
'loginPageId' => [
|
||||
'loginPageId' => [
|
||||
'type' => 'number',
|
||||
'default' => 0,
|
||||
],
|
||||
'inviteOnlyMessage' => [
|
||||
'type' => 'string',
|
||||
'default' => '',
|
||||
],
|
||||
],
|
||||
],
|
||||
'us-scheduler/group-classes' => [
|
||||
|
||||
@@ -54,6 +54,15 @@ class Offering {
|
||||
*/
|
||||
public const VALID_ACCESS_MODES = [ self::ACCESS_PUBLIC, self::ACCESS_INVITE_ONLY ];
|
||||
|
||||
/** Maximum length of the title, matching the `title` VARCHAR(191) column. */
|
||||
public const MAX_TITLE_LENGTH = 191;
|
||||
|
||||
/** Maximum length of the schedule note, matching the `schedule_note` VARCHAR(191) column. */
|
||||
public const MAX_SCHEDULE_NOTE_LENGTH = 191;
|
||||
|
||||
/** Maximum length of the e-transfer email, matching the `etransfer_email` VARCHAR(191) column. */
|
||||
public const MAX_ETRANSFER_EMAIL_LENGTH = 191;
|
||||
|
||||
public function __construct(
|
||||
public readonly int $instructorId,
|
||||
public readonly string $kind,
|
||||
|
||||
@@ -3,6 +3,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Offering;
|
||||
|
||||
use Unsupervised\Schedular\Auth\AccessSettings;
|
||||
use Unsupervised\Schedular\Auth\RoleManager;
|
||||
use Unsupervised\Schedular\Val;
|
||||
|
||||
@@ -11,6 +12,7 @@ class OfferingController {
|
||||
public function __construct(
|
||||
private OfferingRepository $repository,
|
||||
private ClassSlotReconciler $reconciler,
|
||||
private AccessSettings $access = new AccessSettings(),
|
||||
) {}
|
||||
|
||||
public function renderPage(): void {
|
||||
@@ -137,17 +139,28 @@ class OfferingController {
|
||||
}
|
||||
|
||||
/**
|
||||
* Registered instructors offered in the assignment select, by display name.
|
||||
* Instructors offered in the assignment select, by display name.
|
||||
*
|
||||
* Includes everyone holding the `us_instructor` role plus, when the site owner
|
||||
* has left administrators acting as instructors (the default single-account
|
||||
* setup), WordPress administrators — who teach through the dynamic capability
|
||||
* grant rather than the role. Without them a solo studio owner running the
|
||||
* business from an admin account would find no one to assign a class to.
|
||||
*
|
||||
* @return list<array{id: int, name: string}>
|
||||
*/
|
||||
private function instructorOptions(): array {
|
||||
$roles = [ RoleManager::INSTRUCTOR ];
|
||||
if ( $this->access->adminsAreInstructors() ) {
|
||||
$roles[] = 'administrator';
|
||||
}
|
||||
|
||||
$users = array_filter(
|
||||
get_users(
|
||||
[
|
||||
'role' => RoleManager::INSTRUCTOR,
|
||||
'orderby' => 'display_name',
|
||||
'order' => 'ASC',
|
||||
'role__in' => $roles,
|
||||
'orderby' => 'display_name',
|
||||
'order' => 'ASC',
|
||||
]
|
||||
),
|
||||
static fn( mixed $u ): bool => $u instanceof \WP_User
|
||||
@@ -184,6 +197,17 @@ class OfferingController {
|
||||
return null;
|
||||
}
|
||||
|
||||
$scheduleNote = $this->nullableText( sanitize_text_field( Val::string( wp_unslash( $_POST['schedule_note'] ?? '' ) ) ) );
|
||||
$etransferEmail = $this->nullableText( sanitize_email( Val::string( wp_unslash( $_POST['etransfer_email'] ?? '' ) ) ) );
|
||||
|
||||
// Reject over-long fixed-size fields rather than let the DB silently drop them.
|
||||
if ( mb_strlen( $title ) > Offering::MAX_TITLE_LENGTH
|
||||
|| ( null !== $scheduleNote && mb_strlen( $scheduleNote ) > Offering::MAX_SCHEDULE_NOTE_LENGTH )
|
||||
|| ( null !== $etransferEmail && mb_strlen( $etransferEmail ) > Offering::MAX_ETRANSFER_EMAIL_LENGTH )
|
||||
) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$billingMode = sanitize_key( Val::string( wp_unslash( $_POST['billing_mode'] ?? Offering::BILLING_ONE_TIME ) ) );
|
||||
if ( ! in_array( $billingMode, Offering::VALID_BILLING_MODES, true ) ) {
|
||||
$billingMode = Offering::BILLING_ONE_TIME;
|
||||
@@ -234,8 +258,8 @@ class OfferingController {
|
||||
classTime: $classTime,
|
||||
enrollmentDeadline: $enrollmentDeadline,
|
||||
withdrawalDeadline: $withdrawalDeadline,
|
||||
scheduleNote: $this->nullableText( sanitize_text_field( Val::string( wp_unslash( $_POST['schedule_note'] ?? '' ) ) ) ),
|
||||
etransferEmail: $this->nullableText( sanitize_email( Val::string( wp_unslash( $_POST['etransfer_email'] ?? '' ) ) ) ),
|
||||
scheduleNote: $scheduleNote,
|
||||
etransferEmail: $etransferEmail,
|
||||
cancellationCutoffHours: $cutoffHours,
|
||||
accessMode: isset( $_POST['invite_only'] ) ? Offering::ACCESS_INVITE_ONLY : Offering::ACCESS_PUBLIC,
|
||||
isActive: isset( $_POST['is_active'] ),
|
||||
|
||||
@@ -148,6 +148,14 @@ class OfferingEndpoint {
|
||||
return $this->invalid( __( 'Invalid billing mode.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
|
||||
$scheduleNote = $this->nullableText( $request->get_param( 'schedule_note' ) );
|
||||
$etransferEmail = $this->nullableEmail( $request->get_param( 'etransfer_email' ) );
|
||||
|
||||
$lengthError = $this->checkLengths( $title, $scheduleNote, $etransferEmail );
|
||||
if ( $lengthError instanceof \WP_Error ) {
|
||||
return $lengthError;
|
||||
}
|
||||
|
||||
$offering = new Offering(
|
||||
instructorId: get_current_user_id(),
|
||||
kind: $kind,
|
||||
@@ -162,8 +170,8 @@ class OfferingEndpoint {
|
||||
termStart: $this->nullableText( $request->get_param( 'term_start' ) ),
|
||||
termEnd: $this->nullableText( $request->get_param( 'term_end' ) ),
|
||||
enrollmentDeadline: $this->nullableText( $request->get_param( 'enrollment_deadline' ) ),
|
||||
scheduleNote: $this->nullableText( $request->get_param( 'schedule_note' ) ),
|
||||
etransferEmail: $this->nullableEmail( $request->get_param( 'etransfer_email' ) ),
|
||||
scheduleNote: $scheduleNote,
|
||||
etransferEmail: $etransferEmail,
|
||||
cancellationCutoffHours: $this->nullableInt( $request->get_param( 'cancellation_cutoff_hours' ) ),
|
||||
accessMode: $this->accessMode( $request->get_param( 'access_mode' ), Offering::ACCESS_PUBLIC ),
|
||||
isActive: null === $request->get_param( 'is_active' ) ? true : (bool) $request->get_param( 'is_active' ),
|
||||
@@ -196,10 +204,19 @@ class OfferingEndpoint {
|
||||
return $this->invalid( __( 'Invalid billing mode.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
|
||||
$title = $request->has_param( 'title' ) ? sanitize_text_field( Val::string( $request->get_param( 'title' ) ) ) : $existing->title;
|
||||
$scheduleNote = $request->has_param( 'schedule_note' ) ? $this->nullableText( $request->get_param( 'schedule_note' ) ) : $existing->scheduleNote;
|
||||
$etransferEmail = $request->has_param( 'etransfer_email' ) ? $this->nullableEmail( $request->get_param( 'etransfer_email' ) ) : $existing->etransferEmail;
|
||||
|
||||
$lengthError = $this->checkLengths( $title, $scheduleNote, $etransferEmail );
|
||||
if ( $lengthError instanceof \WP_Error ) {
|
||||
return $lengthError;
|
||||
}
|
||||
|
||||
$offering = new Offering(
|
||||
instructorId: $existing->instructorId,
|
||||
kind: $kind,
|
||||
title: $request->has_param( 'title' ) ? sanitize_text_field( Val::string( $request->get_param( 'title' ) ) ) : $existing->title,
|
||||
title: $title,
|
||||
price: $request->has_param( 'price' ) ? $this->price( $request->get_param( 'price' ) ) : $existing->price,
|
||||
currency: $request->has_param( 'currency' ) ? sanitize_text_field( Val::string( $request->get_param( 'currency' ) ) ) : $existing->currency,
|
||||
billingMode: $billingMode,
|
||||
@@ -210,8 +227,8 @@ class OfferingEndpoint {
|
||||
termStart: $request->has_param( 'term_start' ) ? $this->nullableText( $request->get_param( 'term_start' ) ) : $existing->termStart,
|
||||
termEnd: $request->has_param( 'term_end' ) ? $this->nullableText( $request->get_param( 'term_end' ) ) : $existing->termEnd,
|
||||
enrollmentDeadline: $request->has_param( 'enrollment_deadline' ) ? $this->nullableText( $request->get_param( 'enrollment_deadline' ) ) : $existing->enrollmentDeadline,
|
||||
scheduleNote: $request->has_param( 'schedule_note' ) ? $this->nullableText( $request->get_param( 'schedule_note' ) ) : $existing->scheduleNote,
|
||||
etransferEmail: $request->has_param( 'etransfer_email' ) ? $this->nullableEmail( $request->get_param( 'etransfer_email' ) ) : $existing->etransferEmail,
|
||||
scheduleNote: $scheduleNote,
|
||||
etransferEmail: $etransferEmail,
|
||||
cancellationCutoffHours: $request->has_param( 'cancellation_cutoff_hours' ) ? $this->nullableInt( $request->get_param( 'cancellation_cutoff_hours' ) ) : $existing->cancellationCutoffHours,
|
||||
accessMode: $request->has_param( 'access_mode' ) ? $this->accessMode( $request->get_param( 'access_mode' ), $existing->accessMode ) : $existing->accessMode,
|
||||
isActive: $request->has_param( 'is_active' ) ? (bool) $request->get_param( 'is_active' ) : $existing->isActive,
|
||||
@@ -266,6 +283,34 @@ class OfferingEndpoint {
|
||||
return new \WP_Error( 'invalid_offering', $message, [ 'status' => 400 ] );
|
||||
}
|
||||
|
||||
/**
|
||||
* Reject any fixed-size field whose value exceeds its column length, so an
|
||||
* over-long value is refused with a clear 400 rather than silently dropped
|
||||
* by the database.
|
||||
*/
|
||||
private function checkLengths( string $title, ?string $scheduleNote, ?string $etransferEmail ): ?\WP_Error {
|
||||
$fields = [
|
||||
[ __( 'title', 'unsupervised-schedular' ), $title, Offering::MAX_TITLE_LENGTH ],
|
||||
[ __( 'schedule note', 'unsupervised-schedular' ), $scheduleNote, Offering::MAX_SCHEDULE_NOTE_LENGTH ],
|
||||
[ __( 'e-transfer email', 'unsupervised-schedular' ), $etransferEmail, Offering::MAX_ETRANSFER_EMAIL_LENGTH ],
|
||||
];
|
||||
|
||||
foreach ( $fields as [ $name, $value, $max ] ) {
|
||||
if ( null !== $value && mb_strlen( $value ) > $max ) {
|
||||
return $this->invalid(
|
||||
sprintf(
|
||||
/* translators: 1: field name, 2: maximum character count. */
|
||||
__( 'The %1$s must be %2$d characters or fewer.', 'unsupervised-schedular' ),
|
||||
$name,
|
||||
$max
|
||||
)
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
private function price( mixed $value ): float {
|
||||
return max( 0.0, Val::float( $value ) );
|
||||
}
|
||||
|
||||
+16
-4
@@ -10,6 +10,7 @@ use Unsupervised\Schedular\Auth\RegistrationLoginGate;
|
||||
use Unsupervised\Schedular\Auth\RegistrationMailer;
|
||||
use Unsupervised\Schedular\Auth\RegistrationPage;
|
||||
use Unsupervised\Schedular\Auth\RoleManager;
|
||||
use Unsupervised\Schedular\Auth\StudentAdminGuard;
|
||||
use Unsupervised\Schedular\Booking\BookingPage;
|
||||
use Unsupervised\Schedular\Availability\AvailabilityRepository;
|
||||
use Unsupervised\Schedular\Booking\BookingRepository;
|
||||
@@ -51,10 +52,20 @@ class Plugin {
|
||||
( new Installer() )->run();
|
||||
}
|
||||
|
||||
$availability = new AvailabilityRepository( $wpdb );
|
||||
$bookings = new BookingRepository( $wpdb );
|
||||
$offerings = new OfferingRepository( $wpdb );
|
||||
$questions = new QuestionRepository( $wpdb );
|
||||
$availability = new AvailabilityRepository( $wpdb );
|
||||
$bookings = new BookingRepository( $wpdb );
|
||||
$offerings = new OfferingRepository( $wpdb );
|
||||
$questions = new QuestionRepository( $wpdb );
|
||||
|
||||
// One-time repair for sites where dbDelta left us_questions.offering_id
|
||||
// NOT NULL (it does not reliably relax NULL-ability), which breaks
|
||||
// account-scope registration questions. Guarded by its own flag rather
|
||||
// than the version gate, since affected sites may already be on the
|
||||
// current version. The flag is only set once the ALTER succeeds.
|
||||
if ( '1' !== get_option( 'us_questions_offering_nullable', '' ) && $questions->ensureOfferingNullable() ) {
|
||||
update_option( 'us_questions_offering_nullable', '1' );
|
||||
}
|
||||
|
||||
$answers = new AnswerRepository( $wpdb );
|
||||
$policies = new PolicyRepository( $wpdb );
|
||||
$policyVersions = new PolicyVersionRepository( $wpdb );
|
||||
@@ -86,6 +97,7 @@ class Plugin {
|
||||
( new UpdateChecker() )->register();
|
||||
( new RoleManager() )->register();
|
||||
( new RegistrationLoginGate() )->register();
|
||||
( new StudentAdminGuard() )->register();
|
||||
( new EmailConfirmationHandler( $settings, $registrationMailer ) )->register();
|
||||
( new AdminMenu( $availability, $bookings, $offerings, $questions, $answers, $policies, $policyVersions, $policyService, $acceptances, $invites, $enrollments, $groupAccess, $settings, $paymentRepo, $paymentService, $resolver, $registrationMailer, $creditRepo ) )->register();
|
||||
( new RestRegistrar( $availability, $bookings, $offerings, $questions, $policies, $policyVersions, $policyService, $registrationGate, $enrollments, $groupAccess, $paymentService ) )->register();
|
||||
|
||||
@@ -18,6 +18,12 @@ class Policy {
|
||||
*/
|
||||
public const VALID_SCOPES = [ self::SCOPE_SIGNUP, self::SCOPE_BOOKING, self::SCOPE_BOTH ];
|
||||
|
||||
/** Maximum length of the title, matching the `title` VARCHAR(191) column. */
|
||||
public const MAX_TITLE_LENGTH = 191;
|
||||
|
||||
/** Maximum length of the slug, matching the `slug` VARCHAR(191) column. */
|
||||
public const MAX_SLUG_LENGTH = 191;
|
||||
|
||||
public function __construct(
|
||||
public readonly string $title,
|
||||
public readonly string $slug,
|
||||
|
||||
@@ -47,7 +47,9 @@ class PolicyController {
|
||||
$scope = Policy::SCOPE_BOOKING;
|
||||
}
|
||||
|
||||
if ( '' !== $title && '' !== $slug && null === $this->policies->findBySlug( $slug ) ) {
|
||||
$withinLimits = mb_strlen( $title ) <= Policy::MAX_TITLE_LENGTH && mb_strlen( $slug ) <= Policy::MAX_SLUG_LENGTH;
|
||||
|
||||
if ( '' !== $title && '' !== $slug && $withinLimits && null === $this->policies->findBySlug( $slug ) ) {
|
||||
$this->service->createPolicy( $title, $slug, $scope );
|
||||
}
|
||||
|
||||
|
||||
@@ -118,12 +118,30 @@ class PolicyEndpoint {
|
||||
if ( '' === $title ) {
|
||||
return $this->invalid( __( 'A policy title is required.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
if ( mb_strlen( $title ) > Policy::MAX_TITLE_LENGTH ) {
|
||||
return $this->invalid(
|
||||
sprintf(
|
||||
/* translators: %d: maximum character count. */
|
||||
__( 'The policy title must be %d characters or fewer.', 'unsupervised-schedular' ),
|
||||
Policy::MAX_TITLE_LENGTH
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
$slugParam = sanitize_text_field( Val::string( $request->get_param( 'slug' ) ) );
|
||||
$slug = sanitize_title( '' !== $slugParam ? $slugParam : $title );
|
||||
if ( '' === $slug ) {
|
||||
return $this->invalid( __( 'A valid policy slug is required.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
if ( mb_strlen( $slug ) > Policy::MAX_SLUG_LENGTH ) {
|
||||
return $this->invalid(
|
||||
sprintf(
|
||||
/* translators: %d: maximum character count. */
|
||||
__( 'The policy slug must be %d characters or fewer.', 'unsupervised-schedular' ),
|
||||
Policy::MAX_SLUG_LENGTH
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
if ( null !== $this->policies->findBySlug( $slug ) ) {
|
||||
return new \WP_Error( 'duplicate_slug', __( 'A policy with that slug already exists.', 'unsupervised-schedular' ), [ 'status' => 409 ] );
|
||||
|
||||
@@ -12,6 +12,9 @@ class Question {
|
||||
public const FIELD_SELECT = 'select';
|
||||
public const FIELD_CHECKBOX = 'checkbox';
|
||||
|
||||
/** Maximum length of a question label, matching the `label` VARCHAR(255) column. */
|
||||
public const MAX_LABEL_LENGTH = 255;
|
||||
|
||||
/** Question is scoped to a single offering, asked at booking/enrolment time. */
|
||||
public const SCOPE_OFFERING = 'offering';
|
||||
|
||||
|
||||
@@ -85,7 +85,7 @@ class QuestionController {
|
||||
$label = sanitize_text_field( Val::string( wp_unslash( $_POST['label'] ?? '' ) ) );
|
||||
$fieldType = sanitize_key( Val::string( wp_unslash( $_POST['field_type'] ?? Question::FIELD_TEXT ) ) );
|
||||
|
||||
if ( '' === $label || ! in_array( $fieldType, Question::VALID_FIELD_TYPES, true ) ) {
|
||||
if ( '' === $label || mb_strlen( $label ) > Question::MAX_LABEL_LENGTH || ! in_array( $fieldType, Question::VALID_FIELD_TYPES, true ) ) {
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -79,6 +79,9 @@ class QuestionEndpoint {
|
||||
if ( '' === $label ) {
|
||||
return $this->invalid( __( 'A question label is required.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
if ( mb_strlen( $label ) > Question::MAX_LABEL_LENGTH ) {
|
||||
return $this->invalid( $this->tooLongMessage( __( 'question', 'unsupervised-schedular' ), Question::MAX_LABEL_LENGTH ) );
|
||||
}
|
||||
|
||||
$fieldType = Val::string( $request->get_param( 'field_type' ) ?? Question::FIELD_TEXT );
|
||||
if ( ! in_array( $fieldType, Question::VALID_FIELD_TYPES, true ) ) {
|
||||
@@ -118,9 +121,17 @@ class QuestionEndpoint {
|
||||
return $this->invalid( __( 'Invalid field type.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
|
||||
$label = $request->has_param( 'label' ) ? sanitize_text_field( Val::string( $request->get_param( 'label' ) ) ) : $existing->label;
|
||||
if ( '' === $label ) {
|
||||
return $this->invalid( __( 'A question label is required.', 'unsupervised-schedular' ) );
|
||||
}
|
||||
if ( mb_strlen( $label ) > Question::MAX_LABEL_LENGTH ) {
|
||||
return $this->invalid( $this->tooLongMessage( __( 'question', 'unsupervised-schedular' ), Question::MAX_LABEL_LENGTH ) );
|
||||
}
|
||||
|
||||
$question = new Question(
|
||||
offeringId: $existing->offeringId,
|
||||
label: $request->has_param( 'label' ) ? sanitize_text_field( Val::string( $request->get_param( 'label' ) ) ) : $existing->label,
|
||||
label: $label,
|
||||
fieldType: $fieldType,
|
||||
options: $request->has_param( 'options' ) ? $this->sanitizeOptions( $request->get_param( 'options' ) ) : $existing->options,
|
||||
isRequired: $request->has_param( 'is_required' ) ? (bool) $request->get_param( 'is_required' ) : $existing->isRequired,
|
||||
@@ -217,4 +228,16 @@ class QuestionEndpoint {
|
||||
private function invalid( string $message ): \WP_Error {
|
||||
return new \WP_Error( 'invalid_question', $message, [ 'status' => 400 ] );
|
||||
}
|
||||
|
||||
/**
|
||||
* Build a uniform "too long" validation message for a named field.
|
||||
*/
|
||||
private function tooLongMessage( string $field, int $max ): string {
|
||||
return sprintf(
|
||||
/* translators: 1: field name, 2: maximum character count. */
|
||||
__( 'The %1$s must be %2$d characters or fewer.', 'unsupervised-schedular' ),
|
||||
$field,
|
||||
$max
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -106,4 +106,26 @@ class QuestionRepository {
|
||||
[ '%d' ]
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Relax `offering_id` to allow NULL for account-scope questions (which are
|
||||
* not tied to an offering).
|
||||
*
|
||||
* The account-questions feature (v1.1.0) made the column nullable in the
|
||||
* schema, but dbDelta does not reliably change a column from NOT NULL to
|
||||
* NULL, so sites created before then keep the old NOT NULL column and reject
|
||||
* account-scope inserts with "Column 'offering_id' cannot be null". This
|
||||
* MODIFY is idempotent — re-applying the nullable definition is a no-op.
|
||||
*
|
||||
* @return bool True when the statement ran (or was already applied), false
|
||||
* if it could not be prepared or the query failed.
|
||||
*/
|
||||
public function ensureOfferingNullable(): bool {
|
||||
$sql = $this->db->prepare(
|
||||
'ALTER TABLE %i MODIFY offering_id BIGINT UNSIGNED NULL DEFAULT NULL',
|
||||
$this->table
|
||||
);
|
||||
|
||||
return null !== $sql && false !== $this->db->query( $sql );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -23,6 +23,9 @@ class ShortcodeRegistrar {
|
||||
add_shortcode( 'us_student_login', self::shortcode( [ $this->loginPage, 'render' ] ) );
|
||||
add_shortcode( 'us_student_register', self::shortcode( [ $this->registrationPage, 'render' ] ) );
|
||||
add_shortcode( 'us_group_classes', self::shortcode( [ $this->groupClassPage, 'render' ] ) );
|
||||
// Process registration submissions before output so the invite branch's
|
||||
// auth cookie is actually sent (render() runs too late, during the_content).
|
||||
add_action( 'template_redirect', [ $this->registrationPage, 'maybeHandleSubmit' ] );
|
||||
add_action( 'template_redirect', [ $this->registrationPage, 'maybeRedirectToRegistrationPage' ] );
|
||||
add_action( 'wp_enqueue_scripts', [ $this, 'enqueueAssets' ] );
|
||||
}
|
||||
|
||||
@@ -45,7 +45,7 @@ if ($editing && null !== $editing->termStart && null !== $editing->termEnd && $e
|
||||
<table class="form-table">
|
||||
<tr>
|
||||
<th><label for="title"><?php esc_html_e('Title', 'unsupervised-schedular'); ?></label></th>
|
||||
<td><input type="text" name="title" id="title" class="regular-text" required value="<?php echo esc_attr($editing->title ?? ''); ?>"></td>
|
||||
<td><input type="text" name="title" id="title" class="regular-text" maxlength="<?php echo esc_attr((string) Offering::MAX_TITLE_LENGTH); ?>" required value="<?php echo esc_attr($editing->title ?? ''); ?>"></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th><label for="kind"><?php esc_html_e('Kind', 'unsupervised-schedular'); ?></label></th>
|
||||
@@ -140,11 +140,11 @@ if ($editing && null !== $editing->termStart && null !== $editing->termEnd && $e
|
||||
</tr>
|
||||
<tr class="us-group-only">
|
||||
<th><label for="schedule_note"><?php esc_html_e('Schedule note', 'unsupervised-schedular'); ?></label></th>
|
||||
<td><input type="text" name="schedule_note" id="schedule_note" class="regular-text" placeholder="<?php esc_attr_e('e.g. Tuesdays 4:00pm', 'unsupervised-schedular'); ?>" value="<?php echo esc_attr($editing->scheduleNote ?? ''); ?>"></td>
|
||||
<td><input type="text" name="schedule_note" id="schedule_note" class="regular-text" maxlength="<?php echo esc_attr((string) Offering::MAX_SCHEDULE_NOTE_LENGTH); ?>" placeholder="<?php esc_attr_e('e.g. Tuesdays 4:00pm', 'unsupervised-schedular'); ?>" value="<?php echo esc_attr($editing->scheduleNote ?? ''); ?>"></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th><label for="etransfer_email"><?php esc_html_e('E-transfer email', 'unsupervised-schedular'); ?></label></th>
|
||||
<td><input type="email" name="etransfer_email" id="etransfer_email" class="regular-text" placeholder="<?php esc_attr_e('Overrides the studio default', 'unsupervised-schedular'); ?>" value="<?php echo esc_attr($editing->etransferEmail ?? ''); ?>"></td>
|
||||
<td><input type="email" name="etransfer_email" id="etransfer_email" class="regular-text" maxlength="<?php echo esc_attr((string) Offering::MAX_ETRANSFER_EMAIL_LENGTH); ?>" placeholder="<?php esc_attr_e('Overrides the studio default', 'unsupervised-schedular'); ?>" value="<?php echo esc_attr($editing->etransferEmail ?? ''); ?>"></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th><label for="cancellation_cutoff_hours"><?php esc_html_e('Cancellation cutoff (hours)', 'unsupervised-schedular'); ?></label></th>
|
||||
|
||||
@@ -24,12 +24,12 @@ if (! defined('ABSPATH')) {
|
||||
<table class="form-table">
|
||||
<tr>
|
||||
<th><label for="title"><?php esc_html_e('Title', 'unsupervised-schedular'); ?></label></th>
|
||||
<td><input type="text" name="title" id="title" class="regular-text" required></td>
|
||||
<td><input type="text" name="title" id="title" class="regular-text" maxlength="<?php echo esc_attr((string) Policy::MAX_TITLE_LENGTH); ?>" required></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th><label for="slug"><?php esc_html_e('Slug', 'unsupervised-schedular'); ?></label></th>
|
||||
<td>
|
||||
<input type="text" name="slug" id="slug" class="regular-text" placeholder="<?php esc_attr_e('e.g. cancellation (defaults from title)', 'unsupervised-schedular'); ?>">
|
||||
<input type="text" name="slug" id="slug" class="regular-text" maxlength="<?php echo esc_attr((string) Policy::MAX_SLUG_LENGTH); ?>" placeholder="<?php esc_attr_e('e.g. cancellation (defaults from title)', 'unsupervised-schedular'); ?>">
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
|
||||
@@ -53,7 +53,7 @@ if (! defined('ABSPATH')) {
|
||||
<table class="form-table">
|
||||
<tr>
|
||||
<th><label for="label"><?php esc_html_e('Question', 'unsupervised-schedular'); ?></label></th>
|
||||
<td><input type="text" name="label" id="label" class="regular-text" required></td>
|
||||
<td><input type="text" name="label" id="label" class="regular-text" maxlength="<?php echo esc_attr((string) Question::MAX_LABEL_LENGTH); ?>" required></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th><label for="field_type"><?php esc_html_e('Field type', 'unsupervised-schedular'); ?></label></th>
|
||||
|
||||
@@ -12,6 +12,7 @@ if (! defined('ABSPATH')) {
|
||||
* @var bool $inviteValid Whether $invite can still be redeemed — only then is the email fixed.
|
||||
* @var string $token Raw invite token from the request (only its hash is stored).
|
||||
* @var bool $canRegister
|
||||
* @var string $inviteOnlyMessage Text shown when registration is closed and no valid invite is present.
|
||||
* @var bool $open Whether open (self-approval) registration is enabled.
|
||||
* @var string $successType '' | 'invite' (created + logged in) | 'confirm' (check email) | 'confirm_group' (check email; auto-approved on confirm).
|
||||
* @var string $confirmResult '' | '1' (email confirmed, awaiting approval) | 'ready' (confirmed + auto-approved) | 'expired'.
|
||||
@@ -74,7 +75,7 @@ $renderQuestionField = static function (Question $question): void {
|
||||
<?php endif; ?>
|
||||
|
||||
<?php if (! $canRegister) : ?>
|
||||
<p><?php esc_html_e('Registration is by invitation only. Please use the link from your invitation email, or contact the studio.', 'unsupervised-schedular'); ?></p>
|
||||
<p><?php echo esc_html($inviteOnlyMessage); ?></p>
|
||||
<?php else : ?>
|
||||
<?php if ($error !== '') : ?>
|
||||
<p class="us-error" role="alert"><?php echo esc_html($error); ?></p>
|
||||
|
||||
@@ -59,11 +59,14 @@ class RegistrationPageTest extends TestCase
|
||||
'settings' => Mockery::mock(StudioSettings::class),
|
||||
];
|
||||
|
||||
$this->ctx['versions'] = Mockery::mock(PolicyVersionRepository::class);
|
||||
$this->ctx['acceptances'] = Mockery::mock(AcceptanceRepository::class);
|
||||
|
||||
$this->ctx['page'] = new RegistrationPage(
|
||||
$invites,
|
||||
$policies,
|
||||
Mockery::mock(PolicyVersionRepository::class),
|
||||
Mockery::mock(AcceptanceRepository::class),
|
||||
$this->ctx['versions'],
|
||||
$this->ctx['acceptances'],
|
||||
$this->ctx['settings'],
|
||||
$this->ctx['mailer'],
|
||||
$questions,
|
||||
@@ -403,4 +406,98 @@ class RegistrationPageTest extends TestCase
|
||||
|
||||
self::assertSame('invite', $this->submit($invite, false));
|
||||
}
|
||||
|
||||
public function testMaybeHandleSubmitLogsInInviteAndRedirects(): void
|
||||
{
|
||||
$_POST = [ 'us_register' => '1', 'password' => 'password123', 'display_name' => 'Ada' ];
|
||||
$_REQUEST = [ 'us_invite' => 'raw-token' ];
|
||||
|
||||
Functions\when('is_user_logged_in')->justReturn(false);
|
||||
Functions\when('check_admin_referer')->justReturn(true);
|
||||
Functions\when('email_exists')->justReturn(false);
|
||||
Functions\when('wp_insert_user')->justReturn(42);
|
||||
Functions\when('is_wp_error')->justReturn(false);
|
||||
Functions\when('get_permalink')->justReturn('http://home.test/register/');
|
||||
Functions\when('add_query_arg')->alias(static fn (string $k, string $v, string $u): string => $u . '?' . $k . '=' . $v);
|
||||
|
||||
// The cookie must be set here — during template_redirect, before output —
|
||||
// which is the whole point of processing the submit outside render().
|
||||
Functions\expect('wp_set_current_user')->once()->with(42);
|
||||
Functions\expect('wp_set_auth_cookie')->once()->with(42);
|
||||
|
||||
$invite = new Invite(email: '[email protected]', token: 'hash', createdAt: '2024-01-01 00:00:00', id: 9);
|
||||
$this->ctx['invites']->shouldReceive('findByToken')->once()->andReturn($invite);
|
||||
$this->ctx['invites']->shouldReceive('markAccepted')->once();
|
||||
$this->ctx['settings']->shouldReceive('openRegistrationEnabled')->andReturn(false);
|
||||
|
||||
$page = Mockery::mock(
|
||||
RegistrationPage::class,
|
||||
[
|
||||
$this->ctx['invites'],
|
||||
$this->ctx['policies'],
|
||||
$this->ctx['versions'],
|
||||
$this->ctx['acceptances'],
|
||||
$this->ctx['settings'],
|
||||
$this->ctx['mailer'],
|
||||
$this->ctx['questions'],
|
||||
$this->ctx['answers'],
|
||||
$this->ctx['access'],
|
||||
]
|
||||
)->makePartial()->shouldAllowMockingProtectedMethods();
|
||||
|
||||
$captured = '';
|
||||
$page->shouldReceive('redirect')->once()->with(Mockery::on(static function (string $url) use (&$captured): bool {
|
||||
$captured = $url;
|
||||
return true;
|
||||
}));
|
||||
|
||||
$page->maybeHandleSubmit();
|
||||
|
||||
self::assertStringContainsString('us_registered=invite', $captured);
|
||||
}
|
||||
|
||||
public function testMaybeHandleSubmitStoresValidationErrorWithoutRedirecting(): void
|
||||
{
|
||||
// Too-short password: handleSubmit returns an error and no redirect fires.
|
||||
$_POST = [ 'us_register' => '1', 'password' => 'short', 'display_name' => 'Ada' ];
|
||||
|
||||
Functions\when('is_user_logged_in')->justReturn(false);
|
||||
Functions\when('check_admin_referer')->justReturn(true);
|
||||
$this->ctx['settings']->shouldReceive('openRegistrationEnabled')->andReturn(true);
|
||||
|
||||
// A redirect would call exit; reaching the assertion proves none happened.
|
||||
$this->ctx['page']->maybeHandleSubmit();
|
||||
|
||||
$error = (new \ReflectionProperty(RegistrationPage::class, 'submitError'))->getValue($this->ctx['page']);
|
||||
self::assertNotSame('', $error);
|
||||
}
|
||||
|
||||
public function testInviteSuccessRedirectShowsLoggedInWelcome(): void
|
||||
{
|
||||
// After the PRG redirect the student is logged in; the us_registered flag
|
||||
// distinguishes a just-completed signup from an already-logged-in visitor.
|
||||
$_GET = [ 'us_registered' => 'invite' ];
|
||||
Functions\when('is_user_logged_in')->justReturn(true);
|
||||
Functions\when('sanitize_key')->alias(static fn ($v) => strtolower((string) $v));
|
||||
|
||||
$html = $this->ctx['page']->render([]);
|
||||
|
||||
self::assertStringContainsString('us-success', $html);
|
||||
self::assertStringContainsString('now logged in', $html);
|
||||
}
|
||||
|
||||
public function testInviteOnlyMessageCanBeCustomised(): void
|
||||
{
|
||||
// Closed registration and no invite → the invitation-only gate shows.
|
||||
Functions\when('is_user_logged_in')->justReturn(false);
|
||||
Functions\when('sanitize_key')->alias(static fn ($v) => strtolower((string) $v));
|
||||
Functions\when('wp_login_url')->justReturn('http://home.test/wp-login.php');
|
||||
Functions\when('wp_nonce_field')->justReturn('');
|
||||
$this->ctx['settings']->shouldReceive('openRegistrationEnabled')->andReturn(false);
|
||||
|
||||
$html = $this->ctx['page']->render([ 'inviteOnlyMessage' => 'Ask the front desk for a link.' ]);
|
||||
|
||||
self::assertStringContainsString('Ask the front desk for a link.', $html);
|
||||
self::assertStringNotContainsString('by invitation only', $html);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,88 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Tests\Unit\Auth;
|
||||
|
||||
use Brain\Monkey\Functions;
|
||||
use Unsupervised\Schedular\Auth\RoleManager;
|
||||
use Unsupervised\Schedular\Auth\StudentAdminGuard;
|
||||
use Unsupervised\Schedular\Tests\Unit\TestCase;
|
||||
|
||||
class StudentAdminGuardTest extends TestCase
|
||||
{
|
||||
private StudentAdminGuard $guard;
|
||||
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
$this->guard = new StudentAdminGuard();
|
||||
Functions\when('wp_doing_ajax')->justReturn(false);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param list<string> $held Capabilities the user is treated as holding.
|
||||
*/
|
||||
private function stubUser(bool $loggedIn, array $held = []): void
|
||||
{
|
||||
Functions\when('is_user_logged_in')->justReturn($loggedIn);
|
||||
Functions\when('current_user_can')->alias(static fn (string $cap): bool => in_array($cap, $held, true));
|
||||
}
|
||||
|
||||
public function testBlocksStudentWithNoBackOfficeCapabilities(): void
|
||||
{
|
||||
// A student holds only front-end capabilities.
|
||||
$this->stubUser(true, [RoleManager::CAP_BOOK_LESSON, RoleManager::CAP_VIEW_LESSONS]);
|
||||
|
||||
self::assertTrue($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testAllowsInstructor(): void
|
||||
{
|
||||
$this->stubUser(true, [RoleManager::CAP_MANAGE_AVAILABILITY]);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testAllowsAdministrator(): void
|
||||
{
|
||||
$this->stubUser(true, ['manage_options']);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testDoesNotBlockLoggedOutRequests(): void
|
||||
{
|
||||
$this->stubUser(false);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testDoesNotBlockAjaxRequests(): void
|
||||
{
|
||||
Functions\when('wp_doing_ajax')->justReturn(true);
|
||||
$this->stubUser(true, [RoleManager::CAP_BOOK_LESSON]);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testHidesAdminBarForStudent(): void
|
||||
{
|
||||
$this->stubUser(true, [RoleManager::CAP_BOOK_LESSON]);
|
||||
|
||||
self::assertFalse($this->guard->hideAdminBar(true));
|
||||
}
|
||||
|
||||
public function testKeepsAdminBarForInstructor(): void
|
||||
{
|
||||
$this->stubUser(true, [RoleManager::CAP_MANAGE_AVAILABILITY]);
|
||||
|
||||
self::assertTrue($this->guard->hideAdminBar(true));
|
||||
}
|
||||
|
||||
public function testLeavesAdminBarUntouchedForLoggedOutVisitor(): void
|
||||
{
|
||||
$this->stubUser(false);
|
||||
|
||||
self::assertFalse($this->guard->hideAdminBar(false));
|
||||
}
|
||||
}
|
||||
@@ -126,7 +126,7 @@ class BlockRegistrarTest extends TestCase
|
||||
array_keys($registered['us-scheduler/student-login']['attributes'])
|
||||
);
|
||||
self::assertSame(
|
||||
['loginPageId'],
|
||||
['loginPageId', 'inviteOnlyMessage'],
|
||||
array_keys($registered['us-scheduler/student-register']['attributes'])
|
||||
);
|
||||
self::assertSame(
|
||||
|
||||
@@ -32,6 +32,8 @@ class OfferingControllerTest extends TestCase
|
||||
Functions\when('current_user_can')->justReturn(true);
|
||||
Functions\when('get_current_user_id')->justReturn(3);
|
||||
Functions\when('get_users')->justReturn([]);
|
||||
// Default single-account setup: admins act as instructors.
|
||||
Functions\when('get_option')->justReturn('1');
|
||||
Functions\when('check_admin_referer')->justReturn(true);
|
||||
Functions\when('admin_url')->justReturn('admin.php?page=us-offerings');
|
||||
Functions\when('add_query_arg')->alias(
|
||||
@@ -450,6 +452,51 @@ class OfferingControllerTest extends TestCase
|
||||
self::assertStringNotContainsString('Edit Offering', $html);
|
||||
}
|
||||
|
||||
public function testInstructorPickerIncludesAdministratorsWhenTheyActAsInstructors(): void
|
||||
{
|
||||
// The reported bug: a solo studio owner runs the business from a WordPress
|
||||
// administrator account and teaches through the dynamic capability grant,
|
||||
// so they never hold the us_instructor role. The picker must still list
|
||||
// them, otherwise there is no one to assign a class to.
|
||||
Functions\when('get_option')->justReturn('1');
|
||||
|
||||
$admin = Mockery::mock(\WP_User::class);
|
||||
$admin->ID = 3;
|
||||
$admin->display_name = 'Studio Owner';
|
||||
|
||||
$queriedRoles = [];
|
||||
Functions\when('get_users')->alias(static function (array $args) use (&$queriedRoles, $admin): array {
|
||||
$queriedRoles = $args['role__in'];
|
||||
return [$admin];
|
||||
});
|
||||
$this->repository->shouldReceive('findAll')->andReturn([]);
|
||||
|
||||
$html = $this->render();
|
||||
|
||||
self::assertContains('us_instructor', $queriedRoles);
|
||||
self::assertContains('administrator', $queriedRoles);
|
||||
self::assertStringContainsString('Studio Owner', $html);
|
||||
self::assertStringContainsString('<option value="3"', $html);
|
||||
}
|
||||
|
||||
public function testInstructorPickerExcludesAdministratorsWhenGrantDisabled(): void
|
||||
{
|
||||
// With the "admins are instructors" toggle off, an admin is not a teacher,
|
||||
// so only the explicit us_instructor role is queried.
|
||||
Functions\when('get_option')->justReturn('0');
|
||||
|
||||
$queriedRoles = null;
|
||||
Functions\when('get_users')->alias(static function (array $args) use (&$queriedRoles): array {
|
||||
$queriedRoles = $args['role__in'];
|
||||
return [];
|
||||
});
|
||||
$this->repository->shouldReceive('findAll')->andReturn([]);
|
||||
|
||||
$this->render();
|
||||
|
||||
self::assertSame(['us_instructor'], $queriedRoles);
|
||||
}
|
||||
|
||||
private function render(): string
|
||||
{
|
||||
ob_start();
|
||||
|
||||
@@ -118,4 +118,37 @@ class OfferingEndpointTest extends TestCase
|
||||
|
||||
self::assertArrayNotHasKey('etransfer_email', $data[0]);
|
||||
}
|
||||
|
||||
public function testCreateRejectsTitleLongerThanColumnLimit(): void
|
||||
{
|
||||
Functions\when('sanitize_text_field')->returnArg();
|
||||
Functions\when('sanitize_email')->returnArg();
|
||||
$this->repository->shouldNotReceive('insert');
|
||||
|
||||
$request = new \WP_REST_Request([
|
||||
'kind' => Offering::KIND_GROUP_CLASS,
|
||||
'title' => str_repeat('a', Offering::MAX_TITLE_LENGTH + 1),
|
||||
]);
|
||||
$response = $this->endpoint->create($request);
|
||||
|
||||
self::assertInstanceOf(\WP_Error::class, $response);
|
||||
self::assertSame(400, $response->error_data['invalid_offering']['status']);
|
||||
}
|
||||
|
||||
public function testCreateRejectsScheduleNoteLongerThanColumnLimit(): void
|
||||
{
|
||||
Functions\when('sanitize_text_field')->returnArg();
|
||||
Functions\when('sanitize_email')->returnArg();
|
||||
$this->repository->shouldNotReceive('insert');
|
||||
|
||||
$request = new \WP_REST_Request([
|
||||
'kind' => Offering::KIND_GROUP_CLASS,
|
||||
'title' => 'Choir',
|
||||
'schedule_note' => str_repeat('a', Offering::MAX_SCHEDULE_NOTE_LENGTH + 1),
|
||||
]);
|
||||
$response = $this->endpoint->create($request);
|
||||
|
||||
self::assertInstanceOf(\WP_Error::class, $response);
|
||||
self::assertSame(400, $response->error_data['invalid_offering']['status']);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Tests\Unit\Policy;
|
||||
|
||||
use Brain\Monkey\Functions;
|
||||
use Mockery;
|
||||
use Unsupervised\Schedular\Policy\Policy;
|
||||
use Unsupervised\Schedular\Policy\PolicyEndpoint;
|
||||
use Unsupervised\Schedular\Policy\PolicyRepository;
|
||||
use Unsupervised\Schedular\Policy\PolicyService;
|
||||
use Unsupervised\Schedular\Policy\PolicyVersionRepository;
|
||||
use Unsupervised\Schedular\Tests\Unit\TestCase;
|
||||
|
||||
class PolicyEndpointTest extends TestCase
|
||||
{
|
||||
private PolicyRepository&Mockery\MockInterface $policies;
|
||||
private PolicyService&Mockery\MockInterface $service;
|
||||
private PolicyEndpoint $endpoint;
|
||||
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
|
||||
Functions\when('sanitize_text_field')->returnArg();
|
||||
Functions\when('sanitize_title')->returnArg();
|
||||
|
||||
$this->policies = Mockery::mock(PolicyRepository::class);
|
||||
$this->service = Mockery::mock(PolicyService::class);
|
||||
$this->endpoint = new PolicyEndpoint(
|
||||
$this->policies,
|
||||
Mockery::mock(PolicyVersionRepository::class),
|
||||
$this->service,
|
||||
);
|
||||
}
|
||||
|
||||
public function testCreateRejectsTitleLongerThanColumnLimit(): void
|
||||
{
|
||||
$this->service->shouldNotReceive('createPolicy');
|
||||
|
||||
$request = new \WP_REST_Request([
|
||||
'title' => str_repeat('a', Policy::MAX_TITLE_LENGTH + 1),
|
||||
]);
|
||||
$response = $this->endpoint->create($request);
|
||||
|
||||
self::assertInstanceOf(\WP_Error::class, $response);
|
||||
self::assertSame(400, $response->error_data['invalid_policy']['status']);
|
||||
}
|
||||
|
||||
public function testCreateRejectsSlugLongerThanColumnLimit(): void
|
||||
{
|
||||
$this->service->shouldNotReceive('createPolicy');
|
||||
|
||||
$request = new \WP_REST_Request([
|
||||
'title' => 'Cancellation',
|
||||
'slug' => str_repeat('a', Policy::MAX_SLUG_LENGTH + 1),
|
||||
]);
|
||||
$response = $this->endpoint->create($request);
|
||||
|
||||
self::assertInstanceOf(\WP_Error::class, $response);
|
||||
self::assertSame(400, $response->error_data['invalid_policy']['status']);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,70 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Tests\Unit\Registration;
|
||||
|
||||
use Brain\Monkey\Functions;
|
||||
use Mockery;
|
||||
use Unsupervised\Schedular\Offering\Offering;
|
||||
use Unsupervised\Schedular\Offering\OfferingRepository;
|
||||
use Unsupervised\Schedular\Registration\Question;
|
||||
use Unsupervised\Schedular\Registration\QuestionEndpoint;
|
||||
use Unsupervised\Schedular\Registration\QuestionRepository;
|
||||
use Unsupervised\Schedular\Tests\Unit\TestCase;
|
||||
|
||||
class QuestionEndpointTest extends TestCase
|
||||
{
|
||||
private QuestionRepository&Mockery\MockInterface $questions;
|
||||
private OfferingRepository&Mockery\MockInterface $offerings;
|
||||
private QuestionEndpoint $endpoint;
|
||||
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
|
||||
Functions\when('get_current_user_id')->justReturn(5);
|
||||
Functions\when('current_user_can')->justReturn(false);
|
||||
Functions\when('absint')->alias(static fn ($v): int => abs((int) $v));
|
||||
Functions\when('sanitize_text_field')->returnArg();
|
||||
|
||||
$this->questions = Mockery::mock(QuestionRepository::class);
|
||||
$this->offerings = Mockery::mock(OfferingRepository::class);
|
||||
$this->endpoint = new QuestionEndpoint($this->questions, $this->offerings);
|
||||
|
||||
// The caller (instructor 5) owns offering 9, so the ownership gate passes
|
||||
// and validation is reached.
|
||||
$this->offerings->shouldReceive('findById')->with(9)->andReturn(
|
||||
new Offering(instructorId: 5, kind: Offering::KIND_GROUP_CLASS, title: 'Choir', id: 9)
|
||||
);
|
||||
}
|
||||
|
||||
public function testCreateRejectsLabelLongerThanColumnLimit(): void
|
||||
{
|
||||
// The insert must never be attempted for an over-long label — the bug was
|
||||
// that it reached the DB, silently failed, and returned success anyway.
|
||||
$this->questions->shouldNotReceive('insert');
|
||||
|
||||
$request = new \WP_REST_Request([
|
||||
'offering_id' => 9,
|
||||
'label' => str_repeat('a', Question::MAX_LABEL_LENGTH + 1),
|
||||
]);
|
||||
$response = $this->endpoint->create($request);
|
||||
|
||||
self::assertInstanceOf(\WP_Error::class, $response);
|
||||
self::assertSame(400, $response->error_data['invalid_question']['status']);
|
||||
}
|
||||
|
||||
public function testCreateAcceptsLabelAtColumnLimit(): void
|
||||
{
|
||||
$this->questions->shouldReceive('insert')->once()->andReturn(42);
|
||||
|
||||
$request = new \WP_REST_Request([
|
||||
'offering_id' => 9,
|
||||
'label' => str_repeat('a', Question::MAX_LABEL_LENGTH),
|
||||
]);
|
||||
$response = $this->endpoint->create($request);
|
||||
|
||||
self::assertInstanceOf(\WP_REST_Response::class, $response);
|
||||
self::assertSame(201, $response->get_status());
|
||||
}
|
||||
}
|
||||
@@ -212,4 +212,28 @@ class QuestionRepositoryTest extends TestCase
|
||||
|
||||
self::assertTrue($this->repo->delete(4));
|
||||
}
|
||||
|
||||
public function testEnsureOfferingNullableRunsAlterAndReportsSuccess(): void
|
||||
{
|
||||
$this->db->shouldReceive('prepare')
|
||||
->once()
|
||||
->with(Mockery::pattern('/ALTER TABLE %i MODIFY offering_id .*NULL/'), 'wp_us_questions')
|
||||
->andReturn('ALTER TABLE `wp_us_questions` MODIFY offering_id BIGINT UNSIGNED NULL DEFAULT NULL');
|
||||
|
||||
$this->db->shouldReceive('query')
|
||||
->once()
|
||||
->with('ALTER TABLE `wp_us_questions` MODIFY offering_id BIGINT UNSIGNED NULL DEFAULT NULL')
|
||||
->andReturn(0);
|
||||
|
||||
// A successful DDL query returns 0 rows affected (not false).
|
||||
self::assertTrue($this->repo->ensureOfferingNullable());
|
||||
}
|
||||
|
||||
public function testEnsureOfferingNullableReportsFailureWhenQueryFails(): void
|
||||
{
|
||||
$this->db->shouldReceive('prepare')->once()->andReturn('ALTER ...');
|
||||
$this->db->shouldReceive('query')->once()->andReturn(false);
|
||||
|
||||
self::assertFalse($this->repo->ensureOfferingNullable());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
* Plugin Name: Unsupervised Scheduler
|
||||
* Plugin URI: https://git.unsupervised.ca/Unsupervised/unsupervised-scheduler
|
||||
* Description: Instructor/student lesson scheduling for WordPress.
|
||||
* Version: 1.2.0
|
||||
* Version: 1.2.1
|
||||
* Requires at least: 6.2
|
||||
* Requires PHP: 8.1
|
||||
* Author: Unsupervised
|
||||
@@ -21,7 +21,7 @@ if (! defined('ABSPATH')) {
|
||||
exit;
|
||||
}
|
||||
|
||||
define('USC_VERSION', '1.2.0');
|
||||
define('USC_VERSION', '1.2.1');
|
||||
define('USC_PLUGIN_FILE', __FILE__);
|
||||
define('USC_PLUGIN_DIR', plugin_dir_path(__FILE__));
|
||||
define('USC_PLUGIN_URL', plugin_dir_url(__FILE__));
|
||||
|
||||
Reference in New Issue
Block a user