WordPress 4.0
[autoinstalls/wordpress.git] / wp-admin / customize.php
index 7f26586ab8f30c28c02fa9e1b196448e89de3b1f..3cfa0c787bbdaecf3c7c5fca75644e12c2e7ef47 100644 (file)
@@ -1,6 +1,6 @@
 <?php
 /**
- * Customize Controls
+ * Theme Customize Screen.
  *
  * @package WordPress
  * @subpackage Customize
@@ -9,17 +9,29 @@
 
 define( 'IFRAME_REQUEST', true );
 
+/** Load WordPress Administration Bootstrap */
 require_once( dirname( __FILE__ ) . '/admin.php' );
-if ( ! current_user_can( 'edit_theme_options' ) )
+
+if ( ! current_user_can( 'customize' ) ) {
        wp_die( __( 'Cheatin&#8217; uh?' ) );
+}
 
 wp_reset_vars( array( 'url', 'return' ) );
-$url = urldecode( $url );
+$url = wp_unslash( $url );
 $url = wp_validate_redirect( $url, home_url( '/' ) );
-if ( $return )
-       $return = wp_validate_redirect( urldecode( $return ) );
-if ( ! $return )
-       $return = $url;
+if ( $return ) {
+       $return = wp_unslash( $return );
+       $return = wp_validate_redirect( $return );
+}
+if ( ! $return ) {
+       if ( $url ) {
+               $return = $url;
+       } elseif ( current_user_can( 'edit_theme_options' ) || current_user_can( 'switch_themes' ) ) {
+               $return = admin_url( 'themes.php' );
+       } else {
+               $return = admin_url();
+       }
+}
 
 global $wp_scripts, $wp_customize;
 
@@ -56,12 +68,12 @@ do_action( 'customize_controls_enqueue_scripts' );
 wp_user_settings();
 _wp_admin_html_begin();
 
-$body_class = 'wp-core-ui js';
+$body_class = 'wp-core-ui wp-customizer js';
 
 if ( wp_is_mobile() ) :
        $body_class .= ' mobile';
 
-       ?><meta name="viewport" id="viewport-meta" content="width=device-width, initial-scale=0.8, minimum-scale=0.5, maximum-scale=1.2"><?php
+       ?><meta name="viewport" id="viewport-meta" content="width=device-width, initial-scale=0.8, minimum-scale=0.5, maximum-scale=1.2" /><?php
 endif;
 
 $is_ios = wp_is_mobile() && preg_match( '/iPad|iPod|iPhone/', $_SERVER['HTTP_USER_AGENT'] );
@@ -74,17 +86,22 @@ if ( is_rtl() )
 $body_class .= ' locale-' . sanitize_html_class( strtolower( str_replace( '_', '-', get_locale() ) ) );
 
 $admin_title = sprintf( __( '%1$s &#8212; WordPress' ), strip_tags( sprintf( __( 'Customize %s' ), $wp_customize->theme()->display('Name') ) ) );
-?><title><?php echo $admin_title; ?></title><?php
+?><title><?php echo $admin_title; ?></title>
 
+<script type="text/javascript">
+var ajaxurl = '<?php echo admin_url( 'admin-ajax.php', 'relative' ); ?>';
+</script>
+
+<?php
 /**
- * Print Customizer control styles.
+ * Fires when Customizer control styles are printed.
  *
  * @since 3.4.0
  */
 do_action( 'customize_controls_print_styles' );
 
 /**
- * Print Customizer control scripts.
+ * Fires when Customizer control scripts are printed.
  *
  * @since 3.4.0
  */
@@ -101,44 +118,57 @@ do_action( 'customize_controls_print_scripts' );
                                submit_button( $save_text, 'primary save', 'save', false );
                        ?>
                        <span class="spinner"></span>
-                       <a class="back button" href="<?php echo esc_url( $return ? $return : admin_url( 'themes.php' ) ); ?>">
-                               <?php _e( 'Cancel' ); ?>
+                       <a class="customize-controls-close" href="<?php echo esc_url( $return ); ?>">
+                               <span class="screen-reader-text"><?php _e( 'Cancel' ); ?></span>
                        </a>
+                       <span class="control-panel-back" tabindex="-1"><span class="screen-reader-text"><?php _e( 'Back' ); ?></span></span>
                </div>
 
                <?php
                        $screenshot = $wp_customize->theme()->get_screenshot();
-                       $cannot_expand = ! ( $screenshot || $wp_customize->theme()->get('Description') );
+                       $cannot_expand = ! ( $wp_customize->is_theme_active() || $screenshot || $wp_customize->theme()->get('Description') );
                ?>
 
+               <div id="widgets-right"><!-- For Widget Customizer, many widgets try to look for instances under div#widgets-right, so we have to add that ID to a container div in the customizer for compat -->
                <div class="wp-full-overlay-sidebar-content accordion-container" tabindex="-1">
                        <div id="customize-info" class="accordion-section <?php if ( $cannot_expand ) echo ' cannot-expand'; ?>">
                                <div class="accordion-section-title" aria-label="<?php esc_attr_e( 'Theme Customizer Options' ); ?>" tabindex="0">
                                        <span class="preview-notice"><?php
-                                               /* translators: %s is the theme name in the Customize/Live Preview pane */
-                                               echo sprintf( __( 'You are previewing %s' ), '<strong class="theme-name">' . $wp_customize->theme()->display('Name') . '</strong>' );
+                                               if ( ! $wp_customize->is_theme_active() ) {
+                                                       /* translators: %s is the theme name in the Customize/Live Preview pane */
+                                                       echo sprintf( __( 'You are previewing %s' ), '<strong class="theme-name">' . $wp_customize->theme()->display('Name') . '</strong>' );
+                                               } else {
+                                                       /* translators: %s is the site/panel title in the Customize pane */
+                                                       echo sprintf( __( 'You are customizing %s' ), '<strong class="theme-name site-title">' . get_bloginfo( 'name' ) . '</strong>' );
+                                               }
                                        ?></span>
                                </div>
                                <?php if ( ! $cannot_expand ) : ?>
                                <div class="accordion-section-content">
-                                       <?php if ( $screenshot ) : ?>
-                                               <img class="theme-screenshot" src="<?php echo esc_url( $screenshot ); ?>" />
-                                       <?php endif; ?>
-
-                                       <?php if ( $wp_customize->theme()->get('Description') ): ?>
-                                               <div class="theme-description"><?php echo $wp_customize->theme()->display('Description'); ?></div>
-                                       <?php endif; ?>
+                                       <?php if ( ! $wp_customize->is_theme_active() ) :
+                                               if ( $screenshot ) : ?>
+                                                       <img class="theme-screenshot" src="<?php echo esc_url( $screenshot ); ?>" />
+                                               <?php endif; ?>
+
+                                               <?php if ( $wp_customize->theme()->get('Description') ): ?>
+                                                       <div class="theme-description"><?php echo $wp_customize->theme()->display('Description'); ?></div>
+                                               <?php endif;
+                                       else:
+                                               echo __( 'The Customizer allows you to preview changes to your site before publishing them. You can also navigate to different pages on your site to preview them.' );
+                                       endif; ?>
                                </div>
                                <?php endif; ?>
                        </div>
 
                        <div id="customize-theme-controls"><ul>
                                <?php
-                               foreach ( $wp_customize->sections() as $section )
-                                       $section->maybe_render();
+                               foreach ( $wp_customize->containers() as $container ) {
+                                       $container->maybe_render();
+                               }
                                ?>
                        </ul></div>
                </div>
+               </div>
 
                <div id="customize-footer-actions" class="wp-full-overlay-footer">
                        <a href="#" class="collapse-sidebar button-secondary" title="<?php esc_attr_e('Collapse Sidebar'); ?>">
@@ -157,12 +187,14 @@ do_action( 'customize_controls_print_scripts' );
         */
        do_action( 'customize_controls_print_footer_scripts' );
 
-       // If the frontend and the admin are served from the same domain, load the
-       // preview over ssl if the customizer is being loaded over ssl. This avoids
-       // insecure content warnings. This is not attempted if the admin and frontend
-       // are on different domains to avoid the case where the frontend doesn't have
-       // ssl certs. Domain mapping plugins can allow other urls in these conditions
-       // using the customize_allowed_urls filter.
+       /*
+        * If the frontend and the admin are served from the same domain, load the
+        * preview over ssl if the customizer is being loaded over ssl. This avoids
+        * insecure content warnings. This is not attempted if the admin and frontend
+        * are on different domains to avoid the case where the frontend doesn't have
+        * ssl certs. Domain mapping plugins can allow other urls in these conditions
+        * using the customize_allowed_urls filter.
+        */
 
        $allowed_urls = array( home_url('/') );
        $admin_origin = parse_url( admin_url() );
@@ -194,21 +226,22 @@ do_action( 'customize_controls_print_scripts' );
                'customize-login' => 1
        ), wp_login_url() );
 
+       // Prepare customizer settings to pass to Javascript.
        $settings = array(
                'theme'    => array(
                        'stylesheet' => $wp_customize->get_stylesheet(),
                        'active'     => $wp_customize->is_theme_active(),
                ),
                'url'      => array(
-                       'preview'       => esc_url( $url ? $url : home_url( '/' ) ),
-                       'parent'        => esc_url( admin_url() ),
-                       'activated'     => admin_url( 'themes.php?activated=true&previewed' ),
-                       'ajax'          => esc_url( admin_url( 'admin-ajax.php', 'relative' ) ),
-                       'allowed'       => array_map( 'esc_url', $allowed_urls ),
+                       'preview'       => esc_url_raw( $url ? $url : home_url( '/' ) ),
+                       'parent'        => esc_url_raw( admin_url() ),
+                       'activated'     => esc_url_raw( admin_url( 'themes.php?activated=true&previewed' ) ),
+                       'ajax'          => esc_url_raw( admin_url( 'admin-ajax.php', 'relative' ) ),
+                       'allowed'       => array_map( 'esc_url_raw', $allowed_urls ),
                        'isCrossDomain' => $cross_domain,
-                       'fallback'      => $fallback_url,
-                       'home'          => esc_url( home_url( '/' ) ),
-                       'login'         => $login_url,
+                       'fallback'      => esc_url_raw( $fallback_url ),
+                       'home'          => esc_url_raw( home_url( '/' ) ),
+                       'login'         => esc_url_raw( $login_url ),
                ),
                'browser'  => array(
                        'mobile' => wp_is_mobile(),
@@ -217,11 +250,12 @@ do_action( 'customize_controls_print_scripts' );
                'settings' => array(),
                'controls' => array(),
                'nonce'    => array(
-                       'save'    => wp_create_nonce( 'save-customize_' . $wp_customize->get_stylesheet() ),
-                       'preview' => wp_create_nonce( 'preview-customize_' . $wp_customize->get_stylesheet() )
-               ),
+                       'save'    => wp_create_nonce( 'save-customize_' . $wp_customize->get_stylesheet() ),
+                       'preview' => wp_create_nonce( 'preview-customize_' . $wp_customize->get_stylesheet() )
+               ),
        );
 
+       // Prepare Customize Setting objects to pass to Javascript.
        foreach ( $wp_customize->settings() as $id => $setting ) {
                $settings['settings'][ $id ] = array(
                        'value'     => $setting->js_value(),
@@ -229,6 +263,7 @@ do_action( 'customize_controls_print_scripts' );
                );
        }
 
+       // Prepare Customize Control objects to pass to Javascript.
        foreach ( $wp_customize->controls() as $id => $control ) {
                $control->to_json();
                $settings['controls'][ $id ] = $control->json;