PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 12.6.4
Jetpack – WP Security, Backup, Speed, & Growth v12.6.4
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / _inc / lib / class.jetpack-keyring-service-helper.php
jetpack / _inc / lib Last commit date
admin-pages 2 years ago core-api 2 years ago debugger 2 years ago markdown 2 years ago class-jetpack-ai-helper.php 2 years ago class-jetpack-currencies.php 5 years ago class-jetpack-google-drive-helper.php 3 years ago class-jetpack-instagram-gallery-helper.php 3 years ago class-jetpack-mapbox-helper.php 3 years ago class-jetpack-podcast-feed-locator.php 2 years ago class-jetpack-podcast-helper.php 3 years ago class-jetpack-recommendations.php 3 years ago class-jetpack-tweetstorm-helper.php 2 years ago class-jetpack-wizard.php 5 years ago class.color.php 2 years ago class.core-rest-api-endpoints.php 2 years ago class.jetpack-automatic-install-skin.php 2 years ago class.jetpack-iframe-embed.php 3 years ago class.jetpack-keyring-service-helper.php 3 years ago class.jetpack-password-checker.php 3 years ago class.jetpack-search-performance-logger.php 4 years ago class.media-extractor.php 3 years ago class.media-summary.php 3 years ago class.media.php 3 years ago components.php 3 years ago debugger.php 4 years ago functions.wp-notify.php 3 years ago icalendar-reader.php 3 years ago markdown.php 3 years ago plans.php 4 years ago plugins.php 4 years ago tonesque.php 2 years ago widgets.php 4 years ago
class.jetpack-keyring-service-helper.php
317 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Utilities to interact with a Keyring instance.
4 * Used for Publicize as well as the Site Verification tools.
5 *
6 * @package automattic/jetpack
7 */
8
9 use Automattic\Jetpack\Connection\Secrets;
10
11 /**
12 * A series of utilities to interact with a Keyring instance.
13 */
14 class Jetpack_Keyring_Service_Helper {
15 /**
16 * Class instance
17 *
18 * @var Jetpack_Keyring_Service_Helper
19 */
20 private static $instance = null;
21
22 /**
23 * Whether the `sharing` page is registered.
24 *
25 * @var bool
26 */
27 private static $is_sharing_page_registered = false;
28
29 /**
30 * Initialize instance.
31 */
32 public static function init() {
33 if ( self::$instance === null ) {
34 self::$instance = new Jetpack_Keyring_Service_Helper();
35 }
36
37 return self::$instance;
38 }
39
40 const SERVICES = array(
41 'facebook' => array(
42 'for' => 'publicize',
43 ),
44 // @todo Remove when Twitter has been dropped from Publicize.
45 'twitter' => array(
46 'for' => 'publicize',
47 ),
48 'linkedin' => array(
49 'for' => 'publicize',
50 ),
51 'tumblr' => array(
52 'for' => 'publicize',
53 ),
54 'path' => array(
55 'for' => 'publicize',
56 ),
57 'google_plus' => array(
58 'for' => 'publicize',
59 ),
60 'google_site_verification' => array(
61 'for' => 'other',
62 ),
63 );
64
65 /**
66 * Constructor
67 */
68 private function __construct() {
69 add_action( 'admin_menu', array( __CLASS__, 'register_sharing_page' ) );
70
71 add_action( 'load-settings_page_sharing', array( __CLASS__, 'admin_page_load' ), 9 );
72 }
73
74 /**
75 * We need a `sharing` page to be able to connect and disconnect services.
76 */
77 public static function register_sharing_page() {
78 if ( self::$is_sharing_page_registered ) {
79 return;
80 }
81
82 self::$is_sharing_page_registered = true;
83
84 if ( ! current_user_can( 'manage_options' ) ) {
85 return;
86 }
87
88 global $_registered_pages;
89
90 require_once ABSPATH . 'wp-admin/includes/plugin.php';
91
92 $hookname = get_plugin_page_hookname( 'sharing', 'options-general.php' );
93 add_action( $hookname, array( __CLASS__, 'admin_page_load' ) );
94 $_registered_pages[ $hookname ] = true; // phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
95 }
96
97 /**
98 * Return a list of services.
99 *
100 * @param string $filter Choose 'all' to get all connected services, vs. just the connected ones.
101 */
102 public function get_services( $filter = 'all' ) {
103 $services = array();
104
105 if ( 'all' === $filter ) {
106 return $services;
107 } else {
108 $connected_services = array();
109 foreach ( $services as $service => $empty ) {
110 $connections = $this->get_connections( $service );
111 if ( $connections ) {
112 $connected_services[ $service ] = $connections;
113 }
114 }
115 return $connected_services;
116 }
117 }
118
119 /**
120 * Gets a URL to the public-api actions. Works like WP's admin_url.
121 * On WordPress.com this is/calls Keyring::admin_url.
122 *
123 * @param string $service Shortname of a specific service.
124 * @param array $params Parameters to append to an API connection URL.
125 *
126 * @return URL to specific public-api process
127 */
128 private static function api_url( $service = false, $params = array() ) {
129 /**
130 * Filters the API URL used to interact with WordPress.com.
131 *
132 * @since 2.0.0
133 *
134 * @param string https://public-api.wordpress.com/connect/?jetpack=publicize Default Publicize API URL.
135 */
136 $url = apply_filters( 'publicize_api_url', 'https://public-api.wordpress.com/connect/?jetpack=publicize' );
137
138 if ( $service ) {
139 $url = add_query_arg( array( 'service' => $service ), $url );
140 }
141
142 if ( count( $params ) ) {
143 $url = add_query_arg( $params, $url );
144 }
145
146 return $url;
147 }
148
149 /**
150 * Build a connection URL (sharing settings page with unique query args to create a connection).
151 *
152 * @param string $service_name Service name.
153 * @param string $for Feature name.
154 */
155 public static function connect_url( $service_name, $for ) {
156 return add_query_arg(
157 array(
158 'action' => 'request',
159 'service' => $service_name,
160 'kr_nonce' => wp_create_nonce( 'keyring-request' ),
161 'nonce' => wp_create_nonce( "keyring-request-$service_name" ),
162 'for' => $for,
163 ),
164 admin_url( 'options-general.php?page=sharing' )
165 );
166 }
167
168 /**
169 * Build a URL to refresh a connection (sharing settings page with unique query args to refresh a connection).
170 * Similar to connect_url, but with a refresh parameter.
171 *
172 * @param string $service_name Service name.
173 * @param string $for Feature name.
174 */
175 public static function refresh_url( $service_name, $for ) {
176 return add_query_arg(
177 array(
178 'action' => 'request',
179 'service' => $service_name,
180 'kr_nonce' => wp_create_nonce( 'keyring-request' ),
181 'refresh' => 1,
182 'for' => $for,
183 'nonce' => wp_create_nonce( "keyring-request-$service_name" ),
184 ),
185 admin_url( 'options-general.php?page=sharing' )
186 );
187 }
188
189 /**
190 * Build a URL to delete a connection (sharing settings page with unique query args to delete a connection).
191 *
192 * @param string $service_name Service name.
193 * @param string $id Connection ID.
194 */
195 public static function disconnect_url( $service_name, $id ) {
196 return add_query_arg(
197 array(
198 'action' => 'delete',
199 'service' => $service_name,
200 'id' => $id,
201 'kr_nonce' => wp_create_nonce( 'keyring-request' ),
202 'nonce' => wp_create_nonce( "keyring-request-$service_name" ),
203 ),
204 admin_url( 'options-general.php?page=sharing' )
205 );
206 }
207
208 /**
209 * Build contents handling Keyring connection management into Sharing settings screen.
210 */
211 public static function admin_page_load() {
212 if ( isset( $_GET['action'] ) ) {
213 if ( isset( $_GET['service'] ) ) {
214 $service_name = sanitize_text_field( wp_unslash( $_GET['service'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- We verify below.
215 }
216
217 switch ( $_GET['action'] ) {
218
219 case 'request':
220 check_admin_referer( 'keyring-request', 'kr_nonce' );
221 check_admin_referer( "keyring-request-$service_name", 'nonce' );
222
223 $verification = ( new Secrets() )->generate( 'publicize' );
224 if ( ! $verification ) {
225 $url = Jetpack::admin_url( 'jetpack#/settings' );
226 wp_die(
227 sprintf(
228 wp_kses(
229 /* Translators: placeholder is a URL to a Settings page. */
230 __( "Jetpack is not connected. Please connect Jetpack by visiting <a href='%s'>Settings</a>.", 'jetpack' ),
231 array(
232 'a' => array(
233 'href' => array(),
234 ),
235 )
236 ),
237 esc_url( $url )
238 )
239 );
240
241 }
242 $stats_options = get_option( 'stats_options' );
243 $wpcom_blog_id = Jetpack_Options::get_option( 'id' );
244 $wpcom_blog_id = ! empty( $wpcom_blog_id ) ? $wpcom_blog_id : $stats_options['blog_id'];
245
246 $user = wp_get_current_user();
247 $redirect = self::api_url(
248 $service_name,
249 urlencode_deep(
250 array(
251 'action' => 'request',
252 'redirect_uri' => add_query_arg( array( 'action' => 'done' ), menu_page_url( 'sharing', false ) ),
253 'for' => 'publicize',
254 // required flag that says this connection is intended for publicize.
255 'siteurl' => site_url(),
256 'state' => $user->ID,
257 'blog_id' => $wpcom_blog_id,
258 'secret_1' => $verification['secret_1'],
259 'secret_2' => $verification['secret_2'],
260 'eol' => $verification['exp'],
261 )
262 )
263 );
264 wp_redirect( $redirect ); // phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect -- The API URL is an external URL and is filterable.
265 exit;
266
267 case 'completed':
268 /*
269 * We do not use a nonce here,
270 * since we're populating a local cache of
271 * the Publicize connections that were created and stored on WordPress.com.
272 */
273 $xml = new Jetpack_IXR_Client();
274 $xml->query( 'jetpack.fetchPublicizeConnections' );
275
276 if ( ! $xml->isError() ) {
277 $response = $xml->getResponse();
278 Jetpack_Options::update_option( 'publicize_connections', $response );
279 }
280
281 break;
282
283 case 'delete':
284 $id = isset( $_GET['id'] ) ? sanitize_text_field( wp_unslash( $_GET['id'] ) ) : null;
285
286 check_admin_referer( 'keyring-request', 'kr_nonce' );
287 check_admin_referer( "keyring-request-$service_name", 'nonce' );
288
289 self::disconnect( $service_name, $id );
290
291 do_action( 'connection_disconnected', $service_name );
292 break;
293 }
294 }
295 }
296
297 /**
298 * Remove a Publicize connection
299 *
300 * @param string $service_name Service name.
301 * @param string $connection_id Connection ID.
302 * @param int|bool $_blog_id Blog ID.
303 * @param int|bool $_user_id User ID.
304 * @param bool $force_delete Force delete the connection.
305 */
306 public static function disconnect( $service_name, $connection_id, $_blog_id = false, $_user_id = false, $force_delete = false ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
307 $xml = new Jetpack_IXR_Client();
308 $xml->query( 'jetpack.deletePublicizeConnection', $connection_id );
309
310 if ( ! $xml->isError() ) {
311 Jetpack_Options::update_option( 'publicize_connections', $xml->getResponse() );
312 } else {
313 return false;
314 }
315 }
316 }
317