PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 13.0.2
Jetpack – WP Security, Backup, Speed, & Growth v13.0.2
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / extensions / blocks / premium-content / _inc / access-check.php
jetpack / extensions / blocks / premium-content / _inc Last commit date
subscription-service 2 years ago access-check.php 2 years ago legacy-buttons.php 5 years ago
access-check.php
137 lines
1 <?php
2 /**
3 * Determine access to premium content.
4 *
5 * @package Automattic\Jetpack\Extensions\Premium_Content
6 */
7
8 namespace Automattic\Jetpack\Extensions\Premium_Content;
9
10 use Automattic\Jetpack\Extensions\Premium_Content\Subscription_Service\Abstract_Token_Subscription_Service;
11
12 require_once __DIR__ . '/subscription-service/include.php';
13
14 /**
15 * Determines if the memberships module is set up.
16 *
17 * @return bool Whether the memberships module is set up.
18 */
19 function membership_checks() {
20 // If Jetpack is not yet configured, don't show anything ...
21 if ( ! class_exists( '\Jetpack_Memberships' ) ) {
22 return false;
23 }
24 // if stripe not connected don't show anything...
25 if ( ! \Jetpack_Memberships::has_connected_account() ) {
26 return false;
27 }
28 return true;
29 }
30
31 /**
32 * Determines if the site has a plan that supports the
33 * Premium Content block.
34 *
35 * @return bool
36 */
37 function required_plan_checks() {
38 $availability = \Jetpack_Gutenberg::get_cached_availability();
39 $slug = 'premium-content/container';
40 return ( isset( $availability[ $slug ] ) && $availability[ $slug ]['available'] );
41 }
42
43 /**
44 * Determines if the block should be rendered. Returns true
45 * if the block passes all required checks, or if the user is
46 * an editor.
47 *
48 * @return bool Whether the block should be rendered.
49 */
50 function pre_render_checks() {
51 return ( current_user_can_edit() || membership_checks() );
52 }
53
54 /**
55 * Determines whether the current user can edit.
56 *
57 * @return bool Whether the user can edit.
58 */
59 function current_user_can_edit() {
60 $user = wp_get_current_user();
61
62 return 0 !== $user->ID && current_user_can( 'edit_post', get_the_ID() );
63 }
64
65 /**
66 * Determines if the current user can view the protected content of the given block.
67 *
68 * @param array $attributes Block attributes.
69 * @param object $block Block to check.
70 *
71 * @return bool Whether the use can view the content.
72 */
73 function current_visitor_can_access( $attributes, $block ) {
74 /**
75 * If the current WordPress install has as signed in user
76 * they can see the content.
77 */
78
79 if ( current_user_can_edit() ) {
80 return true;
81 }
82
83 $selected_plan_ids = array();
84
85 if ( isset( $attributes['selectedPlanIds'] ) ) {
86 $selected_plan_ids = $attributes['selectedPlanIds'];
87 } elseif ( isset( $attributes['selectedPlanId'] ) ) {
88 $selected_plan_ids = array( $attributes['selectedPlanId'] );
89 }
90
91 if ( isset( $block ) && ! empty( $block->context['premium-content/planId'] ) ) {
92 $selected_plan_ids = array( $block->context['premium-content/planId'] );
93 } elseif ( isset( $block ) && ! empty( $block->context['premium-content/planIds'] ) ) {
94 $selected_plan_ids = $block->context['premium-content/planIds'];
95 }
96
97 if ( empty( $selected_plan_ids ) ) {
98 return false;
99 }
100
101 $paywall = subscription_service();
102 $access_level = Abstract_Token_Subscription_Service::POST_ACCESS_LEVEL_PAID_SUBSCRIBERS; // Only paid subscribers should be granted access to the premium content
103 $tier_ids = \Jetpack_Memberships::get_all_newsletter_plan_ids();
104 $tier_ids = array_intersect( $tier_ids, $selected_plan_ids );
105 if ( ! empty( $tier_ids ) ) {
106 // If the selected plan is a tier, we want to check directly if user has a higher "tier".
107 // This is to prevent situation where the user upgrades and lose access to premium-gated content
108 $token = $paywall->get_and_set_token_from_request();
109 $payload = $paywall->decode_token( $token );
110 $is_valid_token = ! empty( $payload );
111
112 $can_view = false;
113 if ( $is_valid_token ) {
114 $subscriptions = (array) $payload['subscriptions'];
115 foreach ( $tier_ids as $tier_id ) {
116 $can_view = ! $paywall->maybe_gate_access_for_user_if_tier( $tier_id, $subscriptions );
117 if ( $can_view ) {
118 break;
119 }
120 }
121 }
122 } else {
123 $can_view = $paywall->visitor_can_view_content( $selected_plan_ids, $access_level );
124 }
125
126 if ( $can_view ) {
127 /**
128 * Fires when a visitor can view protected content on a site.
129 *
130 * @since 9.4.0
131 */
132 do_action( 'jetpack_earn_remove_cache_headers' );
133 }
134
135 return $can_view;
136 }
137