Automattic\WooCommerce\Internal\ProductFeed\Storage

JsonFileFeed::is_valid_feed_identifier │ private │ WC 1.0

Checks that a feed identifier is a plain feed file name, not a path.

Identifiers round-trip through the persisted status option and are accepted by the public {@see delete()}, so a corrupted or hostile value (e.g. containing ../) must never be concatenated into a path that escapes the feed directory.

Method of the class: JsonFileFeed{}

No Hooks.

Returns

bool. True if the identifier is a safe, plain .json file name.

Usage

// private - for code of main (parent) class only
$result = $this->is_valid_feed_identifier( $identifier ): bool;
$identifier(string) (required)
The feed file identifier to check.

JsonFileFeed::is_valid_feed_identifier() code WC 11.1.2

private function is_valid_feed_identifier( string $identifier ): bool {
	return '' !== $identifier
		&& wp_basename( $identifier ) === $identifier
		&& 'json' === strtolower( (string) pathinfo( $identifier, PATHINFO_EXTENSION ) );
}