Repository navigation
Expand file tree
/
Copy pathcron-trigger.php
More file actions
88 lines (76 loc) · 2.99 KB
/
Copy pathcron-trigger.php
File metadata and controls
88 lines (76 loc) · 2.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
<?php
/**
* External cron entry point.
*
* WordPress cron only fires when somebody visits the site, which is exactly what
* a brand-new site does not have. This file lets a real cron job drive it:
*
* curl -s "https://example.com/wp-content/plugins/deepseek-autoblogger-pro/cron-trigger.php?key=YOUR_KEY"
*
* Better options, in order of preference:
* 1. wp autoblog generate (WP-CLI, via your host's scheduler)
* 2. POST /wp-json/autoblogging-pro/v1/generate (application password)
* 3. this file
*
* Fixes over 2.1.0 (finding B13):
* - wp-load.php is found by walking up the tree, not by splitting the path on
* the literal string "wp-content" (which fatals on a renamed content dir,
* a symlinked plugin dir, or a non-standard layout)
* - the secret key is compared with hash_equals(), not !==
* - the key is NEVER created by an unauthenticated request; it is created in
* wp-admin. An unconfigured endpoint refuses instead of minting a secret.
*/
// ---------------------------------------------------------------- bootstrap
$dir = __DIR__;
$loaded = false;
for ( $i = 0; $i < 10; $i++ ) {
if ( file_exists( $dir . '/wp-load.php' ) ) {
require_once $dir . '/wp-load.php';
$loaded = true;
break;
}
$parent = dirname( $dir );
if ( $parent === $dir ) { break; } // reached the filesystem root
$dir = $parent;
}
if ( ! $loaded || ! defined( 'ABSPATH' ) ) {
http_response_code( 500 );
header( 'Content-Type: text/plain; charset=utf-8' );
exit( "Could not locate wp-load.php from this plugin's directory.\n" .
"Use WP-CLI instead: wp autoblog generate\n" );
}
header( 'Content-Type: text/plain; charset=utf-8' );
header( 'X-Robots-Tag: noindex, nofollow' );
// ---------------------------------------------------------------- auth
$secret = (string) get_option( 'dsap_cron_secret_key', '' );
if ( '' === $secret ) {
// Do not mint a secret for an anonymous caller.
http_response_code( 503 );
exit( "This endpoint is not configured. Open Auto-Blogger in wp-admin to generate a cron key.\n" );
}
$provided = isset( $_GET['key'] ) ? (string) wp_unslash( $_GET['key'] ) : '';
if ( ! hash_equals( $secret, $provided ) ) {
http_response_code( 403 );
// Deliberately vague, and no timing signal.
exit( "Forbidden.\n" );
}
// ---------------------------------------------------------------- run
if ( ! class_exists( 'DSAP_Scheduler' ) ) {
http_response_code( 500 );
exit( "AutoBlogging Pro is not active on this site.\n" );
}
DSAP_Logger::log( 'External cron trigger received.', 'INFO' );
$result = DSAP_Scheduler::get_instance()->run_generation( false );
DSAP_Logger::flush();
if ( is_wp_error( $result ) ) {
// 200, not 500: a reached cap or an exhausted topic list is a normal outcome,
// and cron services email you on every non-2xx.
http_response_code( 200 );
exit( 'SKIPPED: ' . $result->get_error_message() . "\n" );
}
printf(
"OK: post #%d (%s) — %s\n",
(int) $result,
esc_html( get_post_status( $result ) ),
esc_url_raw( get_permalink( $result ) )
);