PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 10.3
Jetpack – WP Security, Backup, Speed, & Growth v10.3
16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 All 501 releases
jetpack / class.jetpack-network.php
class.jetpack-network.php
743 lines 20.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php //phpcs:ignore WordPress.Files.FileName.InvalidClassFilename
2 /**
3 * Jetpack Network Manager class file.
4 *
5 * @package automattic/jetpack
6 */
7
8 use Automattic\Jetpack\Connection\Manager;
9 use Automattic\Jetpack\Connection\Tokens;
10 use Automattic\Jetpack\Status;
11
12 /**
13 * Used to manage Jetpack installation on Multisite Network installs
14 *
15 * SINGLETON: To use call Jetpack_Network::init()
16 *
17 * DO NOT USE ANY STATIC METHODS IN THIS CLASS!!!!!!
18 *
19 * @since 2.9
20 */
21 class Jetpack_Network {
22
23 /**
24 * Holds a static copy of Jetpack_Network for the singleton
25 *
26 * @since 2.9
27 * @var Jetpack_Network
28 */
29 private static $instance = null;
30
31 /**
32 * An instance of the connection manager object.
33 *
34 * @since 7.7
35 * @var Automattic\Jetpack\Connection\Manager
36 */
37 private $connection;
38
39 /**
40 * Name of the network wide settings
41 *
42 * @since 2.9
43 * @var string
44 */
45 private $settings_name = 'jetpack-network-settings';
46
47 /**
48 * Defaults for settings found on the Jetpack > Settings page
49 *
50 * @since 2.9
51 * @var array
52 */
53 private $setting_defaults = array(
54 'auto-connect' => 0,
55 'sub-site-connection-override' => 1,
56 );
57
58 /**
59 * Constructor
60 *
61 * @since 2.9
62 */
63 private function __construct() {
64 require_once ABSPATH . '/wp-admin/includes/plugin.php'; // For the is_plugin... check.
65 require_once JETPACK__PLUGIN_DIR . 'modules/protect/shared-functions.php'; // For managing the global whitelist.
66
67 /**
68 * Sanity check to ensure the install is Multisite and we
69 * are in Network Admin
70 */
71 if ( is_multisite() && is_network_admin() ) {
72 add_action( 'network_admin_menu', array( $this, 'add_network_admin_menu' ) );
73 add_action( 'network_admin_edit_jetpack-network-settings', array( $this, 'save_network_settings_page' ), 10, 0 );
74 add_filter( 'admin_body_class', array( $this, 'body_class' ) );
75
76 if ( isset( $_GET['page'] ) && 'jetpack' == $_GET['page'] ) {
77 add_action( 'admin_init', array( $this, 'jetpack_sites_list' ) );
78 }
79 }
80
81 /*
82 * Things that should only run on multisite
83 */
84 if ( is_multisite() && is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
85 add_action( 'wp_before_admin_bar_render', array( $this, 'add_to_menubar' ) );
86 add_filter( 'jetpack_disconnect_cap', array( $this, 'set_multisite_disconnect_cap' ) );
87
88 /*
89 * If admin wants to automagically register new sites set the hook here
90 *
91 * This is a hacky way because xmlrpc is not available on wp_initialize_site
92 */
93 if ( 1 === $this->get_option( 'auto-connect' ) ) {
94 add_action( 'wp_initialize_site', array( $this, 'do_automatically_add_new_site' ) );
95 }
96 }
97 }
98
99 /**
100 * Sets a connection object.
101 *
102 * @param Automattic\Jetpack\Connection\Manager $connection the connection manager object.
103 */
104 public function set_connection( Manager $connection ) {
105 $this->connection = $connection;
106 }
107
108 /**
109 * Registers new sites upon creation
110 *
111 * @since 2.9
112 * @since 7.4.0 Uses a WP_Site object.
113 * @uses wp_initialize_site
114 *
115 * @param WP_Site $site the WordPress site object.
116 **/
117 public function do_automatically_add_new_site( $site ) {
118 if ( is_a( $site, 'WP_Site' ) ) {
119 $this->do_subsiteregister( $site->id );
120 }
121 }
122
123 /**
124 * Adds .network-admin class to the body tag
125 * Helps distinguish network admin JP styles from regular site JP styles
126 *
127 * @since 2.9
128 *
129 * @param String $classes current assigned body classes.
130 * @return String amended class string.
131 */
132 public function body_class( $classes ) {
133 return trim( $classes ) . ' network-admin ';
134 }
135
136 /**
137 * Provides access to an instance of Jetpack_Network
138 *
139 * This is how the Jetpack_Network object should *always* be accessed
140 *
141 * @since 2.9
142 * @return Jetpack_Network
143 */
144 public static function init() {
145 if ( ! self::$instance || ! is_a( self::$instance, 'Jetpack_Network' ) ) {
146 self::$instance = new Jetpack_Network();
147 }
148
149 return self::$instance;
150 }
151
152 /**
153 * Registers the Multisite admin bar menu item shortcut.
154 * This shortcut helps users quickly and easily navigate to the Jetpack Network Admin
155 * menu from anywhere in their network.
156 *
157 * @since 2.9
158 */
159 public function register_menubar() {
160 add_action( 'wp_before_admin_bar_render', array( $this, 'add_to_menubar' ) );
161 }
162
163 /**
164 * Runs when Jetpack is deactivated from the network admin plugins menu.
165 * Each individual site will need to have Jetpack::disconnect called on it.
166 * Site that had Jetpack individually enabled will not be disconnected as
167 * on Multisite individually activated plugins are still activated when
168 * a plugin is deactivated network wide.
169 *
170 * @since 2.9
171 **/
172 public function deactivate() {
173 // Only fire if in network admin.
174 if ( ! is_network_admin() ) {
175 return;
176 }
177
178 $sites = get_sites();
179
180 foreach ( $sites as $s ) {
181 switch_to_blog( $s->blog_id );
182 $active_plugins = get_option( 'active_plugins' );
183
184 /*
185 * If this plugin was activated in the subsite individually
186 * we do not want to call disconnect. Plugins activated
187 * individually (before network activation) stay activated
188 * when the network deactivation occurs
189 */
190 if ( ! in_array( 'jetpack/jetpack.php', $active_plugins, true ) ) {
191 Jetpack::disconnect();
192 }
193 restore_current_blog();
194 }
195
196 }
197
198 /**
199 * Adds a link to the Jetpack Network Admin page in the network admin menu bar.
200 *
201 * @since 2.9
202 **/
203 public function add_to_menubar() {
204 global $wp_admin_bar;
205 // Don't show for logged out users or single site mode.
206 if ( ! is_user_logged_in() || ! is_multisite() ) {
207 return;
208 }
209
210 $wp_admin_bar->add_node(
211 array(
212 'parent' => 'network-admin',
213 'id' => 'network-admin-jetpack',
214 'title' => 'Jetpack',
215 'href' => $this->get_url( 'network_admin_page' ),
216 )
217 );
218 }
219
220 /**
221 * Returns various URL strings. Factory like
222 *
223 * $args can be a string or an array.
224 * If $args is an array there must be an element called name for the switch statement
225 *
226 * Currently supports:
227 * - subsiteregister: Pass array( 'name' => 'subsiteregister', 'site_id' => SITE_ID )
228 * - network_admin_page: Provides link to /wp-admin/network/JETPACK
229 * - subsitedisconnect: Pass array( 'name' => 'subsitedisconnect', 'site_id' => SITE_ID )
230 *
231 * @since 2.9
232 *
233 * @param Mixed $args URL parameters.
234 *
235 * @return String
236 **/
237 public function get_url( $args ) {
238 $url = null; // Default url value.
239
240 if ( is_string( $args ) ) {
241 $name = $args;
242 } else if ( is_array( $args ) ) {
243 $name = $args['name'];
244 } else {
245 return $url;
246 }
247
248 switch ( $name ) {
249 case 'subsiteregister':
250 if ( ! isset( $args['site_id'] ) ) {
251 break; // If there is not a site id present we cannot go further.
252 }
253 $url = network_admin_url(
254 'admin.php?page=jetpack&action=subsiteregister&site_id='
255 . $args['site_id']
256 );
257 break;
258
259 case 'network_admin_page':
260 $url = network_admin_url( 'admin.php?page=jetpack' );
261 break;
262
263 case 'subsitedisconnect':
264 if ( ! isset( $args['site_id'] ) ) {
265 break; // If there is not a site id present we cannot go further.
266 }
267 $url = network_admin_url(
268 'admin.php?page=jetpack&action=subsitedisconnect&site_id='
269 . $args['site_id']
270 );
271 break;
272 }
273
274 return $url;
275 }
276
277 /**
278 * Adds the Jetpack menu item to the Network Admin area
279 *
280 * @since 2.9
281 */
282 public function add_network_admin_menu() {
283 add_menu_page( 'Jetpack', 'Jetpack', 'jetpack_network_admin_page', 'jetpack', array( $this, 'wrap_network_admin_page' ), 'div', 3 );
284 $jetpack_sites_page_hook = add_submenu_page( 'jetpack', __( 'Jetpack Sites', 'jetpack' ), __( 'Sites', 'jetpack' ), 'jetpack_network_sites_page', 'jetpack', array( $this, 'wrap_network_admin_page' ) );
285 $jetpack_settings_page_hook = add_submenu_page( 'jetpack', __( 'Settings', 'jetpack' ), __( 'Settings', 'jetpack' ), 'jetpack_network_settings_page', 'jetpack-settings', array( $this, 'wrap_render_network_admin_settings_page' ) );
286 add_action( "admin_print_styles-$jetpack_sites_page_hook", array( 'Jetpack_Admin_Page', 'load_wrapper_styles' ) );
287 add_action( "admin_print_styles-$jetpack_settings_page_hook", array( 'Jetpack_Admin_Page', 'load_wrapper_styles' ) );
288 /**
289 * As jetpack_register_genericons is by default fired off a hook,
290 * the hook may have already fired by this point.
291 * So, let's just trigger it manually.
292 */
293 require_once JETPACK__PLUGIN_DIR . '_inc/genericons.php';
294 jetpack_register_genericons();
295
296 if ( ! wp_style_is( 'jetpack-icons', 'registered' ) ) {
297 wp_register_style( 'jetpack-icons', plugins_url( 'css/jetpack-icons.min.css', JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION );
298 }
299
300 add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
301 }
302
303 /**
304 * Adds JP menu icon
305 *
306 * @since 2.9
307 **/
308 public function admin_menu_css() {
309 wp_enqueue_style( 'jetpack-icons' );
310 }
311
312 /**
313 * Provides functionality for the Jetpack > Sites page.
314 * Does not do the display!
315 *
316 * @since 2.9
317 */
318 public function jetpack_sites_list() {
319 Jetpack::init();
320
321 if ( isset( $_GET['action'] ) ) {
322 switch ( $_GET['action'] ) {
323 case 'subsiteregister':
324 /**
325 * Add actual referrer checking.
326 *
327 * @todo check_admin_referer( 'jetpack-subsite-register' );
328 */
329 Jetpack::log( 'subsiteregister' );
330
331 // If !$_GET['site_id'] stop registration and error.
332 if ( ! isset( $_GET['site_id'] ) || empty( $_GET['site_id'] ) ) {
333 /**
334 * Log error to state cookie for display later.
335 *
336 * @todo Make state messages show on Jetpack NA pages
337 */
338 Jetpack::state( 'missing_site_id', esc_html__( 'Site ID must be provided to register a sub-site.', 'jetpack' ) );
339 break;
340 }
341
342 // Send data to register endpoint and retrieve shadow blog details.
343 $result = $this->do_subsiteregister();
344 $url = $this->get_url( 'network_admin_page' );
345
346 if ( is_wp_error( $result ) ) {
347 $url = add_query_arg( 'action', 'connection_failed', $url );
348 } else {
349 $url = add_query_arg( 'action', 'connected', $url );
350 }
351
352 wp_safe_redirect( $url );
353 exit;
354
355 case 'subsitedisconnect':
356 Jetpack::log( 'subsitedisconnect' );
357
358 if ( ! isset( $_GET['site_id'] ) || empty( $_GET['site_id'] ) ) {
359 Jetpack::state( 'missing_site_id', esc_html__( 'Site ID must be provided to disconnect a sub-site.', 'jetpack' ) );
360 break;
361 }
362
363 $this->do_subsitedisconnect();
364 break;
365
366 case 'connected':
367 case 'connection_failed':
368 add_action( 'jetpack_notices', array( $this, 'show_jetpack_notice' ) );
369 break;
370 }
371 }
372 }
373
374 /**
375 * Set the disconnect capability for multisite.
376 *
377 * @param array $caps The capabilities array.
378 */
379 public function set_multisite_disconnect_cap( $caps ) {
380 // Can individual site admins manage their own connection?
381 if ( ! is_super_admin() && ! $this->get_option( 'sub-site-connection-override' ) ) {
382 /*
383 * We need to update the option name -- it's terribly unclear which
384 * direction the override goes.
385 *
386 * @todo: Update the option name to `sub-sites-can-manage-own-connections`
387 */
388 return array( 'do_not_allow' );
389 }
390
391 return $caps;
392 }
393
394 /**
395 * Shows the Jetpack plugin notices.
396 */
397 public function show_jetpack_notice() {
398 if ( isset( $_GET['action'] ) && 'connected' == $_GET['action'] ) {
399 $notice = __( 'Site successfully connected.', 'jetpack' );
400 $classname = 'updated';
401 } elseif ( isset( $_GET['action'] ) && 'connection_failed' == $_GET['action'] ) {
402 $notice = __( 'Site connection failed!', 'jetpack' );
403 $classname = 'error';
404 }
405 ?>
406 <div id="message" class="<?php echo esc_attr( $classname ); ?> jetpack-message jp-connect" style="display:block !important;">
407 <p><?php echo esc_html( $notice ); ?></p>
408 </div>
409 <?php
410 }
411
412 /**
413 * Disconnect functionality for an individual site
414 *
415 * @since 2.9
416 * @see Jetpack_Network::jetpack_sites_list()
417 *
418 * @param int $site_id the site identifier.
419 */
420 public function do_subsitedisconnect( $site_id = null ) {
421 if ( ! current_user_can( 'jetpack_disconnect' ) ) {
422 return;
423 }
424 $site_id = ( is_null( $site_id ) ) ? $_GET['site_id'] : $site_id;
425 switch_to_blog( $site_id );
426 Jetpack::disconnect();
427 restore_current_blog();
428 }
429
430 /**
431 * Registers a subsite with the Jetpack servers
432 *
433 * @since 2.9
434 * @todo Break apart into easier to manage chunks that can be unit tested
435 * @see Jetpack_Network::jetpack_sites_list();
436 *
437 * @param int $site_id the site identifier.
438 */
439 public function do_subsiteregister( $site_id = null ) {
440 if ( ! current_user_can( 'jetpack_disconnect' ) ) {
441 return;
442 }
443
444 if ( ( new Status() )->is_offline_mode() ) {
445 return;
446 }
447
448 // Figure out what site we are working on.
449 $site_id = ( is_null( $site_id ) ) ? $_GET['site_id'] : $site_id;
450
451 /*
452 * Here we need to switch to the subsite
453 * For the registration process we really only hijack how it
454 * works for an individual site and pass in some extra data here
455 */
456 switch_to_blog( $site_id );
457
458 add_filter( 'jetpack_register_request_body', array( $this, 'filter_register_request_body' ) );
459 add_action( 'jetpack_site_registered_user_token', array( $this, 'filter_register_user_token' ) );
460
461 // Save the secrets in the subsite so when the wpcom server does a pingback it
462 // will be able to validate the connection.
463 $result = $this->connection->register( 'subsiteregister' );
464
465 if ( is_wp_error( $result ) || ! $result ) {
466 restore_current_blog();
467 return $result;
468 }
469
470 Jetpack::activate_default_modules( false, false, array(), false );
471
472 restore_current_blog();
473 }
474
475 /**
476 * Receives the registration response token.
477 *
478 * @param Object $token the received token.
479 */
480 public function filter_register_user_token( $token ) {
481 $is_connection_owner = ! $this->connection->has_connected_owner();
482 ( new Tokens() )->update_user_token(
483 get_current_user_id(),
484 sprintf( '%s.%d', $token->secret, get_current_user_id() ),
485 $is_connection_owner
486 );
487 }
488
489 /**
490 * Filters the registration request body to include additional properties.
491 *
492 * @param array $properties standard register request body properties.
493 * @return array amended properties.
494 */
495 public function filter_register_request_body( $properties ) {
496 $blog_details = get_blog_details();
497
498 $network = get_network();
499
500 switch_to_blog( $network->blog_id );
501 // The blog id on WordPress.com of the primary network site.
502 $network_wpcom_blog_id = Jetpack_Options::get_option( 'id' );
503 restore_current_blog();
504
505 /**
506 * Both `state` and `user_id` need to be sent in the request, even though they are the same value.
507 * Connecting via the network admin combines `register()` and `authorize()` methods into one step,
508 * because we assume the main site is already authorized. `state` is used to verify the `register()`
509 * request, while `user_id()` is used to create the token in the `authorize()` request.
510 */
511 return array_merge(
512 $properties,
513 array(
514 'network_url' => $this->get_url( 'network_admin_page' ),
515 'network_wpcom_blog_id' => $network_wpcom_blog_id,
516 'user_id' => get_current_user_id(),
517
518 /*
519 * Use the subsite's registration date as the site creation date.
520 *
521 * This is in contrast to regular standalone sites, where we use the helper
522 * `Jetpack::get_assumed_site_creation_date()` to assume the site's creation date.
523 */
524 'site_created' => $blog_details->registered,
525 )
526 );
527 }
528
529 /**
530 * A hook handler for adding admin pages and subpages.
531 */
532 public function wrap_network_admin_page() {
533 Jetpack_Admin_Page::wrap_ui( array( $this, 'network_admin_page' ) );
534 }
535
536 /**
537 * Handles the displaying of all sites on the network that are
538 * dis/connected to Jetpack
539 *
540 * @since 2.9
541 * @see Jetpack_Network::jetpack_sites_list()
542 */
543 public function network_admin_page() {
544 global $current_site;
545 $this->network_admin_page_header();
546
547 $jp = Jetpack::init();
548
549 // We should be, but ensure we are on the main blog.
550 switch_to_blog( $current_site->blog_id );
551 $main_active = $jp->is_connection_ready();
552 restore_current_blog();
553
554 // If we are in dev mode, just show the notice and bail.
555 if ( ( new Status() )->is_offline_mode() ) {
556 Jetpack::show_development_mode_notice();
557 return;
558 }
559
560 /*
561 * Ensure the main blog is connected as all other subsite blog
562 * connections will feed off this one
563 */
564 if ( ! $main_active ) {
565 $url = $this->get_url(
566 array(
567 'name' => 'subsiteregister',
568 'site_id' => 1,
569 )
570 );
571 $data = array( 'url' => $jp->build_connect_url() );
572 Jetpack::init()->load_view( 'admin/must-connect-main-blog.php', $data );
573
574 return;
575 }
576
577 require_once 'class.jetpack-network-sites-list-table.php';
578
579 $network_sites_table = new Jetpack_Network_Sites_List_Table();
580 echo '<div class="wrap"><h2>' . esc_html__( 'Sites', 'jetpack' ) . '</h2>';
581 echo '<form method="post">';
582 $network_sites_table->prepare_items();
583 $network_sites_table->display();
584 echo '</form></div>';
585
586 }
587
588 /**
589 * Stylized JP header formatting
590 *
591 * @since 2.9
592 */
593 public function network_admin_page_header() {
594 $is_connected = Jetpack::is_connection_ready();
595
596 $data = array(
597 'is_connected' => $is_connected,
598 );
599 Jetpack::init()->load_view( 'admin/network-admin-header.php', $data );
600 }
601
602 /**
603 * Fires when the Jetpack > Settings page is saved.
604 *
605 * @since 2.9
606 */
607 public function save_network_settings_page() {
608
609 if ( ! wp_verify_nonce( $_POST['_wpnonce'], 'jetpack-network-settings' ) ) {
610 // No nonce, push back to settings page.
611 wp_safe_redirect(
612 add_query_arg(
613 array( 'page' => 'jetpack-settings' ),
614 network_admin_url( 'admin.php' )
615 )
616 );
617 exit();
618 }
619
620 // Try to save the Protect whitelist before anything else, since that action can result in errors.
621 $whitelist = str_replace( ' ', '', $_POST['global-whitelist'] );
622 $whitelist = explode( PHP_EOL, $whitelist );
623 $result = jetpack_protect_save_whitelist( $whitelist, true );
624 if ( is_wp_error( $result ) ) {
625 wp_safe_redirect(
626 add_query_arg(
627 array(
628 'page' => 'jetpack-settings',
629 'error' => 'jetpack_protect_whitelist',
630 ),
631 network_admin_url( 'admin.php' )
632 )
633 );
634 exit();
635 }
636
637 /*
638 * Fields
639 *
640 * auto-connect - Checkbox for global Jetpack connection
641 * sub-site-connection-override - Allow sub-site admins to (dis)reconnect with their own Jetpack account
642 */
643 $auto_connect = 0;
644 if ( isset( $_POST['auto-connect'] ) ) {
645 $auto_connect = 1;
646 }
647
648 $sub_site_connection_override = 0;
649 if ( isset( $_POST['sub-site-connection-override'] ) ) {
650 $sub_site_connection_override = 1;
651 }
652
653 $data = array(
654 'auto-connect' => $auto_connect,
655 'sub-site-connection-override' => $sub_site_connection_override,
656 );
657
658 update_site_option( $this->settings_name, $data );
659 wp_safe_redirect(
660 add_query_arg(
661 array(
662 'page' => 'jetpack-settings',
663 'updated' => 'true',
664 ),
665 network_admin_url( 'admin.php' )
666 )
667 );
668 exit();
669 }
670
671 /**
672 * A hook handler for adding admin pages and subpages.
673 */
674 public function wrap_render_network_admin_settings_page() {
675 Jetpack_Admin_Page::wrap_ui( array( $this, 'render_network_admin_settings_page' ) );
676 }
677
678 /**
679 * A hook rendering the admin settings page.
680 */
681 public function render_network_admin_settings_page() {
682 $this->network_admin_page_header();
683 $options = wp_parse_args( get_site_option( $this->settings_name ), $this->setting_defaults );
684
685 $modules = array();
686 $module_slugs = Jetpack::get_available_modules();
687 foreach ( $module_slugs as $slug ) {
688 $module = Jetpack::get_module( $slug );
689 $module['module'] = $slug;
690 $modules[] = $module;
691 }
692
693 usort( $modules, array( 'Jetpack', 'sort_modules' ) );
694
695 if ( ! isset( $options['modules'] ) ) {
696 $options['modules'] = $modules;
697 }
698
699 $data = array(
700 'modules' => $modules,
701 'options' => $options,
702 'jetpack_protect_whitelist' => jetpack_protect_format_whitelist(),
703 );
704
705 Jetpack::init()->load_view( 'admin/network-settings.php', $data );
706 }
707
708 /**
709 * Updates a site wide option
710 *
711 * @since 2.9
712 *
713 * @param string $key option name.
714 * @param mixed $value option value.
715 *
716 * @return boolean
717 **/
718 public function update_option( $key, $value ) {
719 $options = get_site_option( $this->settings_name, $this->setting_defaults );
720 $options[ $key ] = $value;
721
722 return update_site_option( $this->settings_name, $options );
723 }
724
725 /**
726 * Retrieves a site wide option
727 *
728 * @since 2.9
729 *
730 * @param string $name - Name of the option in the database.
731 **/
732 public function get_option( $name ) {
733 $options = get_site_option( $this->settings_name, $this->setting_defaults );
734 $options = wp_parse_args( $options, $this->setting_defaults );
735
736 if ( ! isset( $options[ $name ] ) ) {
737 $options[ $name ] = null;
738 }
739
740 return $options[ $name ];
741 }
742 }
743