PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 12.1.3
Jetpack – WP Security, Backup, Speed, & Growth v12.1.3
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / _inc / lib / class.jetpack-keyring-service-helper.php
jetpack / _inc / lib Last commit date
admin-pages 3 years ago core-api 3 years ago debugger 3 years ago markdown 4 years ago class-jetpack-ai-helper.php 3 years ago class-jetpack-currencies.php 5 years ago class-jetpack-google-drive-helper.php 3 years ago class-jetpack-instagram-gallery-helper.php 3 years ago class-jetpack-mapbox-helper.php 3 years ago class-jetpack-podcast-feed-locator.php 5 years ago class-jetpack-podcast-helper.php 3 years ago class-jetpack-recommendations.php 4 years ago class-jetpack-tweetstorm-helper.php 3 years ago class-jetpack-wizard.php 5 years ago class.color.php 4 years ago class.core-rest-api-endpoints.php 3 years ago class.jetpack-automatic-install-skin.php 4 years ago class.jetpack-iframe-embed.php 4 years ago class.jetpack-keyring-service-helper.php 4 years ago class.jetpack-password-checker.php 3 years ago class.jetpack-photon-image-sizes.php 3 years ago class.jetpack-photon-image.php 4 years ago class.jetpack-search-performance-logger.php 4 years ago class.media-extractor.php 3 years ago class.media-summary.php 3 years ago class.media.php 3 years ago components.php 3 years ago debugger.php 4 years ago functions.wp-notify.php 4 years ago icalendar-reader.php 3 years ago markdown.php 3 years ago plans.php 4 years ago plugins.php 4 years ago tonesque.php 3 years ago widgets.php 4 years ago
class.jetpack-keyring-service-helper.php
316 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Utilities to interact with a Keyring instance.
4 * Used for Publicize as well as the Site Verification tools.
5 *
6 * @package automattic/jetpack
7 */
8
9 use Automattic\Jetpack\Connection\Secrets;
10
11 /**
12 * A series of utilities to interact with a Keyring instance.
13 */
14 class Jetpack_Keyring_Service_Helper {
15 /**
16 * Class instance
17 *
18 * @var Jetpack_Keyring_Service_Helper
19 */
20 private static $instance = null;
21
22 /**
23 * Whether the `sharing` page is registered.
24 *
25 * @var bool
26 */
27 private static $is_sharing_page_registered = false;
28
29 /**
30 * Initialize instance.
31 */
32 public static function init() {
33 if ( self::$instance === null ) {
34 self::$instance = new Jetpack_Keyring_Service_Helper();
35 }
36
37 return self::$instance;
38 }
39
40 const SERVICES = array(
41 'facebook' => array(
42 'for' => 'publicize',
43 ),
44 'twitter' => array(
45 'for' => 'publicize',
46 ),
47 'linkedin' => array(
48 'for' => 'publicize',
49 ),
50 'tumblr' => array(
51 'for' => 'publicize',
52 ),
53 'path' => array(
54 'for' => 'publicize',
55 ),
56 'google_plus' => array(
57 'for' => 'publicize',
58 ),
59 'google_site_verification' => array(
60 'for' => 'other',
61 ),
62 );
63
64 /**
65 * Constructor
66 */
67 private function __construct() {
68 add_action( 'admin_menu', array( __CLASS__, 'register_sharing_page' ) );
69
70 add_action( 'load-settings_page_sharing', array( __CLASS__, 'admin_page_load' ), 9 );
71 }
72
73 /**
74 * We need a `sharing` page to be able to connect and disconnect services.
75 */
76 public static function register_sharing_page() {
77 if ( self::$is_sharing_page_registered ) {
78 return;
79 }
80
81 self::$is_sharing_page_registered = true;
82
83 if ( ! current_user_can( 'manage_options' ) ) {
84 return;
85 }
86
87 global $_registered_pages;
88
89 require_once ABSPATH . 'wp-admin/includes/plugin.php';
90
91 $hookname = get_plugin_page_hookname( 'sharing', 'options-general.php' );
92 add_action( $hookname, array( __CLASS__, 'admin_page_load' ) );
93 $_registered_pages[ $hookname ] = true; // phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
94 }
95
96 /**
97 * Return a list of services.
98 *
99 * @param string $filter Choose 'all' to get all connected services, vs. just the connected ones.
100 */
101 public function get_services( $filter = 'all' ) {
102 $services = array();
103
104 if ( 'all' === $filter ) {
105 return $services;
106 } else {
107 $connected_services = array();
108 foreach ( $services as $service => $empty ) {
109 $connections = $this->get_connections( $service );
110 if ( $connections ) {
111 $connected_services[ $service ] = $connections;
112 }
113 }
114 return $connected_services;
115 }
116 }
117
118 /**
119 * Gets a URL to the public-api actions. Works like WP's admin_url.
120 * On WordPress.com this is/calls Keyring::admin_url.
121 *
122 * @param string $service Shortname of a specific service.
123 * @param array $params Parameters to append to an API connection URL.
124 *
125 * @return URL to specific public-api process
126 */
127 private static function api_url( $service = false, $params = array() ) {
128 /**
129 * Filters the API URL used to interact with WordPress.com.
130 *
131 * @since 2.0.0
132 *
133 * @param string https://public-api.wordpress.com/connect/?jetpack=publicize Default Publicize API URL.
134 */
135 $url = apply_filters( 'publicize_api_url', 'https://public-api.wordpress.com/connect/?jetpack=publicize' );
136
137 if ( $service ) {
138 $url = add_query_arg( array( 'service' => $service ), $url );
139 }
140
141 if ( count( $params ) ) {
142 $url = add_query_arg( $params, $url );
143 }
144
145 return $url;
146 }
147
148 /**
149 * Build a connection URL (sharing settings page with unique query args to create a connection).
150 *
151 * @param string $service_name Service name.
152 * @param string $for Feature name.
153 */
154 public static function connect_url( $service_name, $for ) {
155 return add_query_arg(
156 array(
157 'action' => 'request',
158 'service' => $service_name,
159 'kr_nonce' => wp_create_nonce( 'keyring-request' ),
160 'nonce' => wp_create_nonce( "keyring-request-$service_name" ),
161 'for' => $for,
162 ),
163 admin_url( 'options-general.php?page=sharing' )
164 );
165 }
166
167 /**
168 * Build a URL to refresh a connection (sharing settings page with unique query args to refresh a connection).
169 * Similar to connect_url, but with a refresh parameter.
170 *
171 * @param string $service_name Service name.
172 * @param string $for Feature name.
173 */
174 public static function refresh_url( $service_name, $for ) {
175 return add_query_arg(
176 array(
177 'action' => 'request',
178 'service' => $service_name,
179 'kr_nonce' => wp_create_nonce( 'keyring-request' ),
180 'refresh' => 1,
181 'for' => $for,
182 'nonce' => wp_create_nonce( "keyring-request-$service_name" ),
183 ),
184 admin_url( 'options-general.php?page=sharing' )
185 );
186 }
187
188 /**
189 * Build a URL to delete a connection (sharing settings page with unique query args to delete a connection).
190 *
191 * @param string $service_name Service name.
192 * @param string $id Connection ID.
193 */
194 public static function disconnect_url( $service_name, $id ) {
195 return add_query_arg(
196 array(
197 'action' => 'delete',
198 'service' => $service_name,
199 'id' => $id,
200 'kr_nonce' => wp_create_nonce( 'keyring-request' ),
201 'nonce' => wp_create_nonce( "keyring-request-$service_name" ),
202 ),
203 admin_url( 'options-general.php?page=sharing' )
204 );
205 }
206
207 /**
208 * Build contents handling Keyring connection management into Sharing settings screen.
209 */
210 public static function admin_page_load() {
211 if ( isset( $_GET['action'] ) ) {
212 if ( isset( $_GET['service'] ) ) {
213 $service_name = sanitize_text_field( wp_unslash( $_GET['service'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- We verify below.
214 }
215
216 switch ( $_GET['action'] ) {
217
218 case 'request':
219 check_admin_referer( 'keyring-request', 'kr_nonce' );
220 check_admin_referer( "keyring-request-$service_name", 'nonce' );
221
222 $verification = ( new Secrets() )->generate( 'publicize' );
223 if ( ! $verification ) {
224 $url = Jetpack::admin_url( 'jetpack#/settings' );
225 wp_die(
226 sprintf(
227 wp_kses(
228 /* Translators: placeholder is a URL to a Settings page. */
229 __( "Jetpack is not connected. Please connect Jetpack by visiting <a href='%s'>Settings</a>.", 'jetpack' ),
230 array(
231 'a' => array(
232 'href' => array(),
233 ),
234 )
235 ),
236 esc_url( $url )
237 )
238 );
239
240 }
241 $stats_options = get_option( 'stats_options' );
242 $wpcom_blog_id = Jetpack_Options::get_option( 'id' );
243 $wpcom_blog_id = ! empty( $wpcom_blog_id ) ? $wpcom_blog_id : $stats_options['blog_id'];
244
245 $user = wp_get_current_user();
246 $redirect = self::api_url(
247 $service_name,
248 urlencode_deep(
249 array(
250 'action' => 'request',
251 'redirect_uri' => add_query_arg( array( 'action' => 'done' ), menu_page_url( 'sharing', false ) ),
252 'for' => 'publicize',
253 // required flag that says this connection is intended for publicize.
254 'siteurl' => site_url(),
255 'state' => $user->ID,
256 'blog_id' => $wpcom_blog_id,
257 'secret_1' => $verification['secret_1'],
258 'secret_2' => $verification['secret_2'],
259 'eol' => $verification['exp'],
260 )
261 )
262 );
263 wp_redirect( $redirect ); // phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect -- The API URL is an external URL and is filterable.
264 exit;
265
266 case 'completed':
267 /*
268 * We do not use a nonce here,
269 * since we're populating a local cache of
270 * the Publicize connections that were created and stored on WordPress.com.
271 */
272 $xml = new Jetpack_IXR_Client();
273 $xml->query( 'jetpack.fetchPublicizeConnections' );
274
275 if ( ! $xml->isError() ) {
276 $response = $xml->getResponse();
277 Jetpack_Options::update_option( 'publicize_connections', $response );
278 }
279
280 break;
281
282 case 'delete':
283 $id = isset( $_GET['id'] ) ? sanitize_text_field( wp_unslash( $_GET['id'] ) ) : null;
284
285 check_admin_referer( 'keyring-request', 'kr_nonce' );
286 check_admin_referer( "keyring-request-$service_name", 'nonce' );
287
288 self::disconnect( $service_name, $id );
289
290 do_action( 'connection_disconnected', $service_name );
291 break;
292 }
293 }
294 }
295
296 /**
297 * Remove a Publicize connection
298 *
299 * @param string $service_name Service name.
300 * @param string $connection_id Connection ID.
301 * @param int|bool $_blog_id Blog ID.
302 * @param int|bool $_user_id User ID.
303 * @param bool $force_delete Force delete the connection.
304 */
305 public static function disconnect( $service_name, $connection_id, $_blog_id = false, $_user_id = false, $force_delete = false ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
306 $xml = new Jetpack_IXR_Client();
307 $xml->query( 'jetpack.deletePublicizeConnection', $connection_id );
308
309 if ( ! $xml->isError() ) {
310 Jetpack_Options::update_option( 'publicize_connections', $xml->getResponse() );
311 } else {
312 return false;
313 }
314 }
315 }
316