PluginProbe
ActivityPub / 2.6.0
ActivityPub v2.6.0
9.3.1 9.3.0 9.2.2 9.2.1 9.2.0 9.1.0 9.0.2 9.0.1 9.0.0 8.3.0 8.2.1 8.2.0 8.1.1 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.2.0 1.3.0 2.0.0 2.0.1 2.1.0 2.1.1 All 160 releases
← All changes | includes/functions.php +501 -5 1.2.02.6.0 View file →
@@ -1,9 +1,12 @@
1 1 <?php
2 2 namespace Activitypub;
3 3
4 +use WP_Query;
4 5 use WP_Error;
5 6 use Activitypub\Http;
7 +use Activitypub\Comment;
8 +use Activitypub\Webfinger;
6 9 use Activitypub\Activity\Activity;
7 10 use Activitypub\Collection\Followers;
8 11 use Activitypub\Collection\Users;
9 12
@@ -12,9 +15,9 @@
12 15 *
13 16 * @return array the activitypub context
14 17 */
15 18 function get_context() {
16 - $context = Activity::CONTEXT;
19 + $context = Activity::JSON_LD_CONTEXT;
17 20
18 21 return \apply_filters( 'activitypub_json_context', $context );
19 22 }
20 23
@@ -49,8 +52,19 @@
49 52 $pre = apply_filters( 'pre_get_remote_metadata_by_actor', false, $actor );
50 53 if ( $pre ) {
51 54 return $pre;
52 55 }
56 +
57 + if ( is_array( $actor ) ) {
58 + if ( array_key_exists( 'id', $actor ) ) {
59 + $actor = $actor['id'];
60 + } elseif ( array_key_exists( 'url', $actor ) ) {
61 + $actor = $actor['url'];
62 + } else {
63 + return new WP_Error( 'activitypub_no_valid_actor_identifier', \__( 'The "actor" identifier is not valid', 'activitypub' ), array( 'status' => 404, 'actor' => $actor ) );
64 + }
65 + }
66 +
53 67 if ( preg_match( '/^@?' . ACTIVITYPUB_USERNAME_REGEXP . '$/i', $actor ) ) {
54 68 $actor = Webfinger::resolve( $actor );
55 69 }
56 70
@@ -131,9 +145,9 @@
131 145 function url_to_authorid( $url ) {
132 146 global $wp_rewrite;
133 147
134 148 // check if url hase the same host
135 - if ( \wp_parse_url( \site_url(), \PHP_URL_HOST ) !== \wp_parse_url( $url, \PHP_URL_HOST ) ) {
149 + if ( \wp_parse_url( \home_url(), \PHP_URL_HOST ) !== \wp_parse_url( $url, \PHP_URL_HOST ) ) {
136 150 return 0;
137 151 }
138 152
139 153 // first, check to see if there is a 'author=N' to match against
@@ -167,8 +181,29 @@
167 181 return 0;
168 182 }
169 183
170 184 /**
185 + * Verify if url is a wp_ap_comment,
186 + * Or if it is a previously received remote comment
187 + *
188 + * @return int comment_id
189 + */
190 +function is_comment() {
191 + $comment_id = get_query_var( 'c', null );
192 +
193 + if ( ! is_null( $comment_id ) ) {
194 + $comment = \get_comment( $comment_id );
195 +
196 + // Only return local origin comments
197 + if ( $comment && $comment->user_id ) {
198 + return $comment_id;
199 + }
200 + }
201 +
202 + return false;
203 +}
204 +
205 +/**
171 206 * Check for Tombstone Objects
172 207 *
173 208 * @see https://www.w3.org/TR/activitypub/#delete-activity-outbox
174 209 *
@@ -278,8 +313,24 @@
278 313 if ( ! \is_author() && ! \is_singular() && ! \is_home() && ! defined( '\REST_REQUEST' ) ) {
279 314 return false;
280 315 }
281 316
317 + // Check if the current post type supports ActivityPub.
318 + if ( \is_singular() ) {
319 + $queried_object = \get_queried_object();
320 + $post_type = \get_post_type( $queried_object );
321 +
322 + if ( ! \post_type_supports( $post_type, 'activitypub' ) ) {
323 + return false;
324 + }
325 + }
326 +
327 + // Check if header already sent.
328 + if ( ! \headers_sent() && ACTIVITYPUB_SEND_VARY_HEADER ) {
329 + // Send Vary header for Accept header.
330 + \header( 'Vary: Accept' );
331 + }
332 +
282 333 // One can trigger an ActivityPub request by adding ?activitypub to the URL.
283 334 // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.VariableRedeclaration
284 335 global $wp_query;
285 336 if ( isset( $wp_query->query_vars['activitypub'] ) ) {
@@ -344,9 +395,9 @@
344 395 $return = true;
345 396 break;
346 397 }
347 398
348 - if ( ! \user_can( $user_id, 'publish_posts' ) ) {
399 + if ( ! \user_can( $user_id, 'activitypub' ) ) {
349 400 $return = true;
350 401 break;
351 402 }
352 403
@@ -476,8 +527,83 @@
476 527 return (bool) apply_filters( 'activitypub_is_blog_public', \get_option( 'blog_public', 1 ) );
477 528 }
478 529
479 530 /**
531 + * Sanitize a URL
532 + *
533 + * @param string $value The URL to sanitize
534 + *
535 + * @return string|null The sanitized URL or null if invalid
536 + */
537 +function sanitize_url( $value ) {
538 + if ( filter_var( $value, FILTER_VALIDATE_URL ) === false ) {
539 + return null;
540 + }
541 +
542 + return esc_url_raw( $value );
543 +}
544 +
545 +/**
546 + * Extract recipient URLs from Activity object
547 + *
548 + * @param array $data
549 + *
550 + * @return array The list of user URLs
551 + */
552 +function extract_recipients_from_activity( $data ) {
553 + $recipient_items = array();
554 +
555 + foreach ( array( 'to', 'bto', 'cc', 'bcc', 'audience' ) as $i ) {
556 + if ( array_key_exists( $i, $data ) ) {
557 + if ( is_array( $data[ $i ] ) ) {
558 + $recipient = $data[ $i ];
559 + } else {
560 + $recipient = array( $data[ $i ] );
561 + }
562 + $recipient_items = array_merge( $recipient_items, $recipient );
563 + }
564 +
565 + if ( is_array( $data['object'] ) && array_key_exists( $i, $data['object'] ) ) {
566 + if ( is_array( $data['object'][ $i ] ) ) {
567 + $recipient = $data['object'][ $i ];
568 + } else {
569 + $recipient = array( $data['object'][ $i ] );
570 + }
571 + $recipient_items = array_merge( $recipient_items, $recipient );
572 + }
573 + }
574 +
575 + $recipients = array();
576 +
577 + // flatten array
578 + foreach ( $recipient_items as $recipient ) {
579 + if ( is_array( $recipient ) ) {
580 + // check if recipient is an object
581 + if ( array_key_exists( 'id', $recipient ) ) {
582 + $recipients[] = $recipient['id'];
583 + }
584 + } else {
585 + $recipients[] = $recipient;
586 + }
587 + }
588 +
589 + return array_unique( $recipients );
590 +}
591 +
592 +/**
593 + * Check if passed Activity is Public
594 + *
595 + * @param array $data The Activity object as array
596 + *
597 + * @return boolean True if public, false if not
598 + */
599 +function is_activity_public( $data ) {
600 + $recipients = extract_recipients_from_activity( $data );
601 +
602 + return in_array( 'https://www.w3.org/ns/activitystreams#Public', $recipients, true );
603 +}
604 +
605 +/**
480 606 * Get active users based on a given duration
481 607 *
482 608 * @param int $duration The duration to check in month(s)
483 609 *
@@ -492,9 +618,9 @@
492 618 if ( false === $count ) {
493 619 global $wpdb;
494 620 $query = "SELECT COUNT( DISTINCT post_author ) FROM {$wpdb->posts} WHERE post_type = 'post' AND post_status = 'publish' AND post_date <= DATE_SUB( NOW(), INTERVAL %d MONTH )";
495 621 $query = $wpdb->prepare( $query, $duration );
496 - $count = $wpdb->get_var( $query ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
622 + $count = $wpdb->get_var( $query ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
497 623
498 624 set_transient( $transient_key, $count, DAY_IN_SECONDS );
499 625 }
500 626
@@ -529,9 +655,9 @@
529 655 }
530 656
531 657 $users = \get_users(
532 658 array(
533 - 'capability__in' => array( 'publish_posts' ),
659 + 'capability__in' => array( 'activitypub' ),
534 660 )
535 661 );
536 662
537 663 if ( is_array( $users ) ) {
@@ -545,5 +671,375 @@
545 671 return $users;
546 672 }
547 673
548 674 return $users + 1;
675 +}
676 +
677 +/**
678 + * Examine a comment ID and look up an existing comment it represents.
679 + *
680 + * @param string $id ActivityPub object ID (usually a URL) to check.
681 + *
682 + * @return int|boolean Comment ID, or false on failure.
683 + */
684 +function object_id_to_comment( $id ) {
685 + return Comment::object_id_to_comment( $id );
686 +}
687 +
688 +/**
689 + * Verify if URL is a local comment,
690 + * Or if it is a previously received remote comment
691 + * (For threading comments locally)
692 + *
693 + * @param string $url The URL to check.
694 + *
695 + * @return int comment_ID or null if not found
696 + */
697 +function url_to_commentid( $url ) {
698 + return Comment::url_to_commentid( $url );
699 +}
700 +
701 +/**
702 + * Get the URI of an ActivityPub object
703 + *
704 + * @param array $object The ActivityPub object
705 + *
706 + * @return string The URI of the ActivityPub object
707 + */
708 +function object_to_uri( $object ) {
709 + // check if it is already simple
710 + if ( ! $object || is_string( $object ) ) {
711 + return $object;
712 + }
713 +
714 + // check if it is a list, then take first item
715 + // this plugin does not support collections
716 + if ( array_is_list( $object ) ) {
717 + $object = $object[0];
718 + }
719 +
720 + // check if it is simplified now
721 + if ( is_string( $object ) ) {
722 + return $object;
723 + }
724 +
725 + // return part of Object that makes most sense
726 + switch ( $object['type'] ) {
727 + case 'Link':
728 + $object = $object['href'];
729 + break;
730 + default:
731 + $object = $object['id'];
732 + break;
733 + }
734 +
735 + return $object;
736 +}
737 +
738 +/**
739 + * Check if a comment should be federated.
740 + *
741 + * We consider a comment should be federated if it is authored by a user that is
742 + * not disabled for federation and if it is a reply directly to the post or to a
743 + * federated comment.
744 + *
745 + * @param mixed $comment Comment object or ID.
746 + *
747 + * @return boolean True if the comment should be federated, false otherwise.
748 + */
749 +function should_comment_be_federated( $comment ) {
750 + return Comment::should_be_federated( $comment );
751 +}
752 +
753 +/**
754 + * Check if a comment was federated.
755 + *
756 + * This function checks if a comment was federated via ActivityPub.
757 + *
758 + * @param mixed $comment Comment object or ID.
759 + *
760 + * @return boolean True if the comment was federated, false otherwise.
761 + */
762 +function was_comment_sent( $comment ) {
763 + return Comment::was_sent( $comment );
764 +}
765 +
766 +/**
767 + * Check if a comment is federated.
768 + *
769 + * We consider a comment federated if comment was received via ActivityPub.
770 + *
771 + * Use this function to check if it is comment that was received via ActivityPub.
772 + *
773 + * @param mixed $comment Comment object or ID.
774 + *
775 + * @return boolean True if the comment is federated, false otherwise.
776 + */
777 +function was_comment_received( $comment ) {
778 + return Comment::was_received( $comment );
779 +}
780 +
781 +/**
782 + * Check if a comment is local only.
783 + *
784 + * This function checks if a comment is local only and was not sent or received via ActivityPub.
785 + *
786 + * @param mixed $comment Comment object or ID.
787 + *
788 + * @return boolean True if the comment is local only, false otherwise.
789 + */
790 +function is_local_comment( $comment ) {
791 + return Comment::is_local( $comment );
792 +}
793 +
794 +/**
795 + * Mark a WordPress object as federated.
796 + *
797 + * @param WP_Comment|WP_Post|mixed $wp_object
798 + *
799 + * @return void
800 + */
801 +function set_wp_object_state( $wp_object, $state ) {
802 + $meta_key = 'activitypub_status';
803 +
804 + if ( $wp_object instanceof \WP_Post ) {
805 + \update_post_meta( $wp_object->ID, $meta_key, $state );
806 + } elseif ( $wp_object instanceof \WP_Comment ) {
807 + \update_comment_meta( $wp_object->comment_ID, $meta_key, $state );
808 + } else {
809 + \apply_filters( 'activitypub_mark_wp_object_as_federated', $wp_object );
810 + }
811 +}
812 +
813 +/**
814 + * Get the federation state of a WordPress object.
815 + *
816 + * @param WP_Comment|WP_Post|mixed $wp_object
817 + *
818 + * @return string|false The state of the object or false if not found.
819 + */
820 +function get_wp_object_state( $wp_object ) {
821 + $meta_key = 'activitypub_status';
822 +
823 + if ( $wp_object instanceof \WP_Post ) {
824 + return \get_post_meta( $wp_object->ID, $meta_key, true );
825 + } elseif ( $wp_object instanceof \WP_Comment ) {
826 + return \get_comment_meta( $wp_object->comment_ID, $meta_key, true );
827 + } else {
828 + return \apply_filters( 'activitypub_get_wp_object_state', false, $wp_object );
829 + }
830 +}
831 +
832 +/**
833 + * Get the description of a post type.
834 + *
835 + * Set some default descriptions for the default post types.
836 + *
837 + * @param WP_Post_Type $post_type The post type object.
838 + *
839 + * @return string The description of the post type.
840 + */
841 +function get_post_type_description( $post_type ) {
842 + $description = '';
843 +
844 + switch ( $post_type->name ) {
845 + case 'post':
846 + $description = '';
847 + break;
848 + case 'page':
849 + $description = '';
850 + break;
851 + case 'attachment':
852 + $description = ' - ' . __( 'The attachments that you have uploaded to a post (images, videos, documents or other files).', 'activitypub' );
853 + break;
854 + default:
855 + if ( ! empty( $post_type->description ) ) {
856 + $description = ' - ' . $post_type->description;
857 + }
858 + }
859 +
860 + return apply_filters( 'activitypub_post_type_description', $description, $post_type->name, $post_type );
861 +}
862 +
863 +/**
864 + * Get the masked WordPress version to only show the major and minor version.
865 + *
866 + * @return string The masked version.
867 + */
868 +function get_masked_wp_version() {
869 + // only show the major and minor version
870 + $version = get_bloginfo( 'version' );
871 + // strip the RC or beta part
872 + $version = preg_replace( '/-.*$/', '', $version );
873 + $version = explode( '.', $version );
874 + $version = array_slice( $version, 0, 2 );
875 +
876 + return implode( '.', $version );
877 +}
878 +
879 +/**
880 + * Get the enclosures of a post.
881 + *
882 + * @param int $post_id The post ID.
883 + *
884 + * @return array The enclosures.
885 + */
886 +function get_enclosures( $post_id ) {
887 + $enclosures = get_post_meta( $post_id, 'enclosure' );
888 +
889 + if ( ! $enclosures ) {
890 + return array();
891 + }
892 +
893 + $enclosures = array_map(
894 + function ( $enclosure ) {
895 + $attributes = explode( "\n", $enclosure );
896 +
897 + if ( ! isset( $attributes[0] ) || ! \wp_http_validate_url( $attributes[0] ) ) {
898 + return false;
899 + }
900 +
901 + return array(
902 + 'url' => $attributes[0],
903 + 'length' => isset( $attributes[1] ) ? trim( $attributes[1] ) : null,
904 + 'mediaType' => isset( $attributes[2] ) ? trim( $attributes[2] ) : null,
905 + );
906 + },
907 + $enclosures
908 + );
909 +
910 + return array_filter( $enclosures );
911 +}
912 +
913 +/**
914 + * Retrieves the IDs of the ancestors of a comment.
915 + *
916 + * Adaption of `get_post_ancestors` from WordPress core.
917 + *
918 + * @see https://developer.wordpress.org/reference/functions/get_post_ancestors/
919 + *
920 + * @param int|WP_Comment $comment Comment ID or comment object.
921 + *
922 + * @return WP_Comment[] Array of ancestor comments or empty array if there are none.
923 + */
924 +function get_comment_ancestors( $comment ) {
925 + $comment = \get_comment( $comment );
926 +
927 + // phpcs:ignore Universal.Operators.StrictComparisons.LooseEqual
928 + if ( ! $comment || empty( $comment->comment_parent ) || $comment->comment_parent == $comment->comment_ID ) {
929 + return array();
930 + }
931 +
932 + $ancestors = array();
933 +
934 + $id = (int) $comment->comment_parent;
935 + $ancestors[] = $id;
936 +
937 + // phpcs:ignore Generic.CodeAnalysis.AssignmentInCondition.FoundInWhileCondition
938 + while ( $id > 0 ) {
939 + $ancestor = \get_comment( $id );
940 + $parent_id = (int) $ancestor->comment_parent;
941 +
942 + // Loop detection: If the ancestor has been seen before, break.
943 + if ( empty( $parent_id ) || ( $parent_id === (int) $comment->comment_ID ) || in_array( $parent_id, $ancestors, true ) ) {
944 + break;
945 + }
946 +
947 + $id = $parent_id;
948 + $ancestors[] = $id;
949 + }
950 +
951 + return $ancestors;
952 +}
953 +
954 +/**
955 + * Change the display of large numbers on the site.
956 + *
957 + * @author Jeremy Herve
958 + *
959 + * @see https://wordpress.org/support/topic/abbreviate-numbers-with-k/
960 + *
961 + * @param string $formatted Converted number in string format.
962 + * @param float $number The number to convert based on locale.
963 + * @param int $decimals Precision of the number of decimal places.
964 + *
965 + * @return string Converted number in string format.
966 + */
967 +function custom_large_numbers( $formatted, $number, $decimals ) {
968 + global $wp_locale;
969 +
970 + $decimals = 0;
971 + $decimal_point = '.';
972 + $thousands_sep = ',';
973 +
974 + if ( isset( $wp_locale ) ) {
975 + $decimals = (int) $wp_locale->number_format['decimal_point'];
976 + $decimal_point = $wp_locale->number_format['decimal_point'];
977 + $thousands_sep = $wp_locale->number_format['thousands_sep'];
978 + }
979 +
980 + if ( $number < 1000 ) { // any number less than a Thousand.
981 + return \number_format( $number, $decimals, $decimal_point, $thousands_sep );
982 + } elseif ( $number < 1000000 ) { // any number less than a million
983 + return \number_format( $number / 1000, $decimals, $decimal_point, $thousands_sep ) . 'K';
984 + } elseif ( $number < 1000000000 ) { // any number less than a billion
985 + return \number_format( $number / 1000000, $decimals, $decimal_point, $thousands_sep ) . 'M';
986 + } else { // at least a billion
987 + return \number_format( $number / 1000000000, $decimals, $decimal_point, $thousands_sep ) . 'B';
988 + }
989 +
990 + // Default fallback. We should not get here.
991 + return $formatted;
992 +}
993 +
994 +/**
995 + * Normalize a URL.
996 + *
997 + * @param string $url The URL.
998 + *
999 + * @return string The normalized URL.
1000 + */
1001 +function normalize_url( $url ) {
1002 + $url = \untrailingslashit( $url );
1003 + $url = \str_replace( 'https://', '', $url );
1004 + $url = \str_replace( 'http://', '', $url );
1005 + $url = \str_replace( 'www.', '', $url );
1006 +
1007 + return $url;
1008 +}
1009 +
1010 +/**
1011 + * Normalize a host.
1012 + *
1013 + * @param string $host The host.
1014 + *
1015 + * @return string The normalized host.
1016 + */
1017 +function normalize_host( $host ) {
1018 + return \str_replace( 'www.', '', $host );
1019 +}
1020 +
1021 +/**
1022 + * Get the Extra Fields of an Actor
1023 + *
1024 + * @param int $user_id The User-ID.
1025 + *
1026 + * @return array The extra fields.
1027 + */
1028 +function get_actor_extra_fields( $user_id ) {
1029 + $extra_fields = new WP_Query(
1030 + array(
1031 + 'post_type' => 'ap_extrafield',
1032 + 'nopaging' => true,
1033 + 'status' => 'publish',
1034 + 'author' => $user_id,
1035 + )
1036 + );
1037 +
1038 + if ( $extra_fields->have_posts() ) {
1039 + $extra_fields = $extra_fields->posts;
1040 + } else {
1041 + $extra_fields = array();
1042 + }
1043 +
1044 + return apply_filters( 'activitypub_get_actor_extra_fields', $extra_fields, $user_id );
549 1045 }