PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 13.2.4
Jetpack – WP Security, Backup, Speed, & Growth v13.2.4
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / json-endpoints / class.wpcom-json-api-site-user-endpoint.php
jetpack / json-endpoints Last commit date
jetpack 2 years ago class.wpcom-json-api-add-widget-endpoint.php 2 years ago class.wpcom-json-api-autosave-post-v1-1-endpoint.php 5 years ago class.wpcom-json-api-bulk-delete-post-endpoint.php 4 years ago class.wpcom-json-api-bulk-restore-post-endpoint.php 4 years ago class.wpcom-json-api-bulk-update-comments-endpoint.php 3 years ago class.wpcom-json-api-comment-endpoint.php 2 years ago class.wpcom-json-api-delete-media-endpoint.php 4 years ago class.wpcom-json-api-delete-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-edit-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-autosave-v1-1-endpoint.php 5 years ago class.wpcom-json-api-get-comment-counts-endpoint.php 4 years ago class.wpcom-json-api-get-comment-endpoint.php 4 years ago class.wpcom-json-api-get-comment-history-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-2-endpoint.php 4 years ago class.wpcom-json-api-get-customcss.php 2 years ago class.wpcom-json-api-get-media-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-post-counts-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-post-endpoint.php 2 years ago class.wpcom-json-api-get-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-site-endpoint.php 2 years ago class.wpcom-json-api-get-site-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomies-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-get-term-endpoint.php 4 years ago class.wpcom-json-api-list-comments-endpoint.php 2 years ago class.wpcom-json-api-list-dropdown-pages-endpoint.php 3 years ago class.wpcom-json-api-list-embeds-endpoint.php 4 years ago class.wpcom-json-api-list-media-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-list-post-type-taxonomies-endpoint.php 4 years ago class.wpcom-json-api-list-post-types-endpoint.php 3 years ago class.wpcom-json-api-list-posts-endpoint.php 3 years ago class.wpcom-json-api-list-posts-v1-1-endpoint.php 3 years ago class.wpcom-json-api-list-posts-v1-2-endpoint.php 3 years ago class.wpcom-json-api-list-roles-endpoint.php 2 years ago class.wpcom-json-api-list-shortcodes-endpoint.php 4 years ago class.wpcom-json-api-list-terms-endpoint.php 2 years ago class.wpcom-json-api-list-users-endpoint.php 2 years ago class.wpcom-json-api-menus-v1-1-endpoint.php 2 years ago class.wpcom-json-api-post-endpoint.php 3 years ago class.wpcom-json-api-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-render-embed-endpoint.php 2 years ago class.wpcom-json-api-render-embed-reversal-endpoint.php 2 years ago class.wpcom-json-api-render-endpoint.php 3 years ago class.wpcom-json-api-render-shortcode-endpoint.php 3 years ago class.wpcom-json-api-sharing-buttons-endpoint.php 2 years ago class.wpcom-json-api-site-settings-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-2-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-3-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-4-endpoint.php 2 years ago class.wpcom-json-api-site-user-endpoint.php 2 years ago class.wpcom-json-api-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-comment-endpoint.php 2 years ago class.wpcom-json-api-update-customcss.php 2 years ago class.wpcom-json-api-update-media-endpoint.php 4 years ago class.wpcom-json-api-update-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-update-post-endpoint.php 3 years ago class.wpcom-json-api-update-post-v1-1-endpoint.php 3 years ago class.wpcom-json-api-update-post-v1-2-endpoint.php 2 years ago class.wpcom-json-api-update-site-homepage-endpoint.php 4 years ago class.wpcom-json-api-update-site-logo-endpoint.php 2 years ago class.wpcom-json-api-update-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-term-endpoint.php 4 years ago class.wpcom-json-api-update-user-endpoint.php 3 years ago class.wpcom-json-api-upload-media-endpoint.php 3 years ago class.wpcom-json-api-upload-media-v1-1-endpoint.php 2 years ago
class.wpcom-json-api-site-user-endpoint.php
267 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2
3 new WPCOM_JSON_API_Site_User_Endpoint(
4 array(
5 'description' => 'Get details of a user of a site by ID.',
6 'group' => '__do_not_document', // 'users'
7 'stat' => 'sites:1:user',
8 'method' => 'GET',
9 'path' => '/sites/%s/users/%d',
10 'path_labels' => array(
11 '$site' => '(int|string) Site ID or domain',
12 '$user_id' => '(int) User ID',
13 ),
14 'response_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
15 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/30434183/user/23',
16 'example_request_data' => array(
17 'headers' => array(
18 'authorization' => 'Bearer YOUR_API_TOKEN',
19 ),
20 ),
21 'example_response' => '{
22 "ID": 18342963,
23 "login": "binarysmash",
24 "email": false,
25 "name": "binarysmash",
26 "URL": "http:\/\/binarysmash.wordpress.com",
27 "avatar_URL": "http:\/\/0.gravatar.com\/avatar\/a178ebb1731d432338e6bb0158720fcc?s=96&d=identicon&r=G",
28 "profile_URL": "http:\/\/gravatar.com\/binarysmash",
29 "roles": [ "administrator" ]
30 }',
31 )
32 );
33
34 new WPCOM_JSON_API_Site_User_Endpoint(
35 array(
36 'description' => 'Get details of a user of a site by login.',
37 'group' => 'users',
38 'stat' => 'sites:1:user',
39 'method' => 'GET',
40 'path' => '/sites/%s/users/login:%s',
41 'path_labels' => array(
42 '$site' => '(int|string) The site ID or domain.',
43 '$user_id' => '(string) The user\'s login.',
44 ),
45 'response_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
46 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/30434183/user/login:binarysmash',
47 'example_request_data' => array(
48 'headers' => array(
49 'authorization' => 'Bearer YOUR_API_TOKEN',
50 ),
51 ),
52 'example_response' => '{
53 "ID": 18342963,
54 "login": "binarysmash",
55 "email": false,
56 "name": "binarysmash",
57 "URL": "http:\/\/binarysmash.wordpress.com",
58 "avatar_URL": "http:\/\/0.gravatar.com\/avatar\/a178ebb1731d432338e6bb0158720fcc?s=96&d=identicon&r=G",
59 "profile_URL": "http:\/\/gravatar.com\/binarysmash",
60 "roles": [ "administrator" ]
61 }',
62 )
63 );
64
65 new WPCOM_JSON_API_Site_User_Endpoint(
66 array(
67 'description' => 'Update details of a user of a site.',
68 'group' => 'users',
69 'stat' => 'sites:1:user',
70 'method' => 'POST',
71 'path' => '/sites/%s/users/%d',
72 'path_labels' => array(
73 '$site' => '(int|string) The site ID or domain.',
74 '$user_id' => '(int) The user\'s ID.',
75 ),
76 'request_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
77 'response_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
78 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/30434183/user/23',
79 'example_request_data' => array(
80 'headers' => array(
81 'authorization' => 'Bearer YOUR_API_TOKEN',
82 ),
83 'body' => array(
84 'roles' => array(
85 array(
86 'administrator',
87 ),
88 ),
89 'first_name' => 'Rocco',
90 'last_name' => 'Tripaldi',
91 ),
92 ),
93 'example_response' => '{
94 "ID": 18342963,
95 "login": "binarysmash",
96 "email": false,
97 "name": "binarysmash",
98 "URL": "http:\/\/binarysmash.wordpress.com",
99 "avatar_URL": "http:\/\/0.gravatar.com\/avatar\/a178ebb1731d432338e6bb0158720fcc?s=96&d=identicon&r=G",
100 "profile_URL": "http:\/\/gravatar.com\/binarysmash",
101 "roles": [ "administrator" ]
102 }',
103 )
104 );
105
106 /**
107 * Site user endpoint class.
108 *
109 * /sites/%s/users/%d -> $blog_id, $user_id
110 */
111 class WPCOM_JSON_API_Site_User_Endpoint extends WPCOM_JSON_API_Endpoint {
112
113 /**
114 * User format.
115 *
116 * @var array
117 */
118 public static $user_format = array(
119 'ID' => '(int) The ID of the user',
120 'login' => '(string) The login username of the user',
121 'email' => '(string) The email of the user',
122 'name' => '(string) The name to display for the user',
123 'first_name' => '(string) The first name of the user',
124 'last_name' => '(string) The last name of the user',
125 'nice_name' => '(string) The nice_name to display for the user',
126 'URL' => '(string) The primary blog of the user',
127 'avatar_URL' => '(url) Gravatar image URL',
128 'profile_URL' => '(url) Gravatar Profile URL',
129 'site_ID' => '(int) ID of the user\'s primary blog',
130 'roles' => '(array|string) The role or roles of the user',
131 );
132
133 /**
134 * API Callback.
135 *
136 * @param string $path - the path.
137 * @param int $blog_id - the blog ID.
138 * @param int $user_id - the user ID.
139 *
140 * @return array|WP_Error
141 */
142 public function callback( $path = '', $blog_id = 0, $user_id = 0 ) {
143 $blog_id = $this->api->switch_to_blog_and_validate_user( $this->api->get_blog_id( $blog_id ) );
144 if ( is_wp_error( $blog_id ) ) {
145 return $blog_id;
146 }
147 if ( ! current_user_can_for_blog( $blog_id, 'list_users' ) ) {
148 return new WP_Error( 'unauthorized', 'User cannot view users for specified site', 403 );
149 }
150
151 // Get the user by ID or login
152 $get_by = str_contains( $path, '/users/login:' ) ? 'login' : 'id';
153 $user = get_user_by( $get_by, $user_id );
154
155 if ( ! $user ) {
156 return new WP_Error( 'unknown_user', 'Unknown user', 404 );
157 }
158
159 if ( ! is_user_member_of_blog( $user->ID, $blog_id ) ) {
160 return new WP_Error( 'unknown_user_for_site', 'Unknown user for site', 404 );
161 }
162
163 if ( 'GET' === $this->api->method ) {
164 return $this->get_user( $user->ID );
165 } elseif ( 'POST' === $this->api->method ) {
166 if ( ! current_user_can_for_blog( $blog_id, 'promote_users' ) ) {
167 return new WP_Error( 'unauthorized_no_promote_cap', 'User cannot promote users for specified site', 403 );
168 }
169 return $this->update_user( $user_id, $blog_id );
170 } else {
171 return new WP_Error( 'bad_request', 'An unsupported request method was used.' );
172 }
173 }
174
175 /**
176 * Get the user.
177 *
178 * @param int $user_id - the user ID.
179 *
180 * @return object
181 */
182 public function get_user( $user_id ) {
183 $the_user = $this->get_author( $user_id, true );
184 if ( $the_user && ! is_wp_error( $the_user ) ) {
185 $userdata = get_userdata( $user_id );
186 $the_user->roles = ! is_wp_error( $userdata ) ? array_values( $userdata->roles ) : array();
187 if ( is_multisite() ) {
188 $the_user->is_super_admin = user_can( $the_user->ID, 'manage_network' );
189 }
190 }
191
192 return $the_user;
193 }
194
195 /**
196 * Updates user data.
197 *
198 * @param int $user_id - the user ID.
199 * @param int $blog_id - the blog ID.
200 *
201 * @return array|WP_Error
202 */
203 public function update_user( $user_id, $blog_id ) {
204 $user = array();
205 $input = $this->input();
206 $user['ID'] = $user_id;
207 $is_wpcom = defined( 'IS_WPCOM' ) && IS_WPCOM;
208
209 if ( get_current_user_id() === (int) $user_id && isset( $input['roles'] ) ) {
210 return new WP_Error( 'unauthorized', 'You cannot change your own role', 403 );
211 }
212
213 if ( $is_wpcom && $user_id !== get_current_user_id() && (int) $user_id === wpcom_get_blog_owner( $blog_id ) ) {
214 return new WP_Error( 'unauthorized_edit_owner', 'Current user can not edit blog owner', 403 );
215 }
216
217 if ( ! $is_wpcom ) {
218 foreach ( $input as $key => $value ) {
219 if ( ! is_array( $value ) ) {
220 $value = trim( $value );
221 }
222 $value = wp_unslash( $value );
223 switch ( $key ) {
224 case 'first_name':
225 case 'last_name':
226 $user[ $key ] = $value;
227 break;
228 case 'display_name':
229 case 'name':
230 $user['display_name'] = $value;
231 break;
232 }
233 }
234 }
235
236 if ( isset( $input['roles'] ) ) {
237 // For now, we only use the first role in the array.
238 if ( is_array( $input['roles'] ) ) {
239 $user['role'] = $input['roles'][0];
240 } elseif ( is_string( $input['roles'] ) ) {
241 $user['role'] = $input['roles'];
242 } else {
243 return new WP_Error( 'invalid_input', __( 'The roles property must be a string or an array.', 'jetpack' ), 400 );
244 }
245
246 $editable_roles = array_keys( get_editable_roles() );
247 if ( ! in_array( $user['role'], $editable_roles, true ) ) {
248 return new WP_Error(
249 'invalid_input',
250 sprintf(
251 /* Translators: placeholder is an invalid role name */
252 esc_html__( '%s is not a valid role.', 'jetpack' ),
253 $editable_roles
254 ),
255 400
256 );
257 }
258 }
259
260 $result = wp_update_user( $user );
261 if ( is_wp_error( $result ) ) {
262 return $result;
263 }
264 return $this->get_user( $user_id );
265 }
266 }
267