PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 13.6.2
Jetpack – WP Security, Backup, Speed, & Growth v13.6.2
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
jetpack / json-endpoints / jetpack / class.jetpack-json-api-plugins-endpoint.php

class.jetpack-json-api-plugins-endpoint.php in Jetpack – WP Security, Backup, Speed, & Growth 13.6.2, at json-endpoints/jetpack/class.jetpack-json-api-plugins-endpoint.php

498 lines 16.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2
3 use Automattic\Jetpack\Constants;
4 use Automattic\Jetpack\Current_Plan;
5 use Automattic\Jetpack\Sync\Functions;
6
7 /**
8 * Base class for working with plugins.
9 */
10 abstract class Jetpack_JSON_API_Plugins_Endpoint extends Jetpack_JSON_API_Endpoint {
11
12 /**
13 * Plugins.
14 *
15 * @var array
16 */
17 protected $plugins = array();
18
19 /**
20 * If the plugin is network wide.
21 *
22 * @var boolean
23 */
24 protected $network_wide = false;
25
26 /**
27 * If we're working in bulk.
28 *
29 * @var boolean
30 */
31 protected $bulk = true;
32
33 /**
34 * The log.
35 *
36 * @var array
37 */
38 protected $log;
39
40 /**
41 * If the request is a scheduled update.
42 *
43 * @var boolean
44 */
45 protected $scheduled_update = false;
46
47 /**
48 * Response format.
49 *
50 * @var array
51 */
52 public static $_response_format = array( // phpcs:ignore PSR2.Classes.PropertyDeclaration.Underscore
53 'id' => '(safehtml) The plugin\'s ID',
54 'slug' => '(safehtml) The plugin\'s .org slug',
55 'active' => '(boolean) The plugin status.',
56 'update' => '(object) The plugin update info.',
57 'name' => '(safehtml) The name of the plugin.',
58 'plugin_url' => '(url) Link to the plugin\'s web site.',
59 'version' => '(safehtml) The plugin version number.',
60 'description' => '(safehtml) Description of what the plugin does and/or notes from the author',
61 'author' => '(safehtml) The author\'s name',
62 'author_url' => '(url) The authors web site address',
63 'network' => '(boolean) Whether the plugin can only be activated network wide.',
64 'autoupdate' => '(boolean) Whether the plugin is automatically updated',
65 'autoupdate_translation' => '(boolean) Whether the plugin is automatically updating translations',
66 'next_autoupdate' => '(string) Y-m-d H:i:s for next scheduled update event',
67 'log' => '(array:safehtml) An array of update log strings.',
68 'uninstallable' => '(boolean) Whether the plugin is unistallable.',
69 'action_links' => '(array) An array of action links that the plugin uses.',
70 );
71
72 /**
73 * Response format v1_2
74 *
75 * @var array
76 */
77 public static $_response_format_v1_2 = array( // phpcs:ignore PSR2.Classes.PropertyDeclaration.Underscore
78 'slug' => '(safehtml) The plugin\'s .org slug',
79 'active' => '(boolean) The plugin status.',
80 'update' => '(object) The plugin update info.',
81 'name' => '(safehtml) The plugin\'s ID',
82 'display_name' => '(safehtml) The name of the plugin.',
83 'version' => '(safehtml) The plugin version number.',
84 'description' => '(safehtml) Description of what the plugin does and/or notes from the author',
85 'author' => '(safehtml) The author\'s name',
86 'author_url' => '(url) The authors web site address',
87 'plugin_url' => '(url) Link to the plugin\'s web site.',
88 'network' => '(boolean) Whether the plugin can only be activated network wide.',
89 'autoupdate' => '(boolean) Whether the plugin is automatically updated',
90 'autoupdate_translation' => '(boolean) Whether the plugin is automatically updating translations',
91 'uninstallable' => '(boolean) Whether the plugin is unistallable.',
92 'action_links' => '(array) An array of action links that the plugin uses.',
93 'log' => '(array:safehtml) An array of update log strings.',
94 );
95
96 /**
97 * The result.
98 *
99 * @return array
100 */
101 protected function result() {
102
103 $plugins = $this->get_plugins();
104
105 if ( ! $this->bulk && ! empty( $plugins ) ) {
106 return array_pop( $plugins );
107 }
108
109 return array( 'plugins' => $plugins );
110 }
111
112 /**
113 * Validate the input.
114 *
115 * @param string $plugin - the plugin we're validating.
116 *
117 * @return bool|WP_Error
118 */
119 protected function validate_input( $plugin ) {
120
121 $error = parent::validate_input( $plugin );
122 if ( is_wp_error( $error ) ) {
123 return $error;
124 }
125
126 $error = $this->validate_network_wide();
127 if ( is_wp_error( $error ) ) {
128 return $error;
129 }
130
131 $error = $this->validate_scheduled_update();
132 if ( is_wp_error( $error ) ) {
133 return $error;
134 }
135
136 $args = $this->input();
137 // find out what plugin, or plugins we are dealing with
138 // validate the requested plugins
139 if ( ! isset( $plugin ) || empty( $plugin ) ) {
140 if ( ! $args['plugins'] || empty( $args['plugins'] ) ) {
141 return new WP_Error( 'missing_plugin', __( 'You are required to specify a plugin.', 'jetpack' ), 400 );
142 }
143 if ( is_array( $args['plugins'] ) ) {
144 $this->plugins = $args['plugins'];
145 } else {
146 $this->plugins[] = $args['plugins'];
147 }
148 } else {
149 $this->bulk = false;
150 $this->plugins[] = urldecode( $plugin );
151 }
152
153 $error = $this->validate_plugins();
154 if ( is_wp_error( $error ) ) {
155 return $error;
156 }
157
158 return true;
159 }
160
161 /**
162 * Walks through submitted plugins to make sure they are valid
163 *
164 * @return bool|WP_Error
165 */
166 protected function validate_plugins() {
167 if ( empty( $this->plugins ) || ! is_array( $this->plugins ) ) {
168 return new WP_Error( 'missing_plugins', __( 'No plugins found.', 'jetpack' ) );
169 }
170 foreach ( $this->plugins as $index => $plugin ) {
171 if ( ! preg_match( '/\.php$/', $plugin ) ) {
172 $plugin = $plugin . '.php';
173 $this->plugins[ $index ] = $plugin;
174 }
175 $valid = $this->validate_plugin( urldecode( $plugin ) );
176 if ( is_wp_error( $valid ) ) {
177 return $valid;
178 }
179 }
180
181 return true;
182 }
183
184 /**
185 * Format the plugin.
186 *
187 * @param string $plugin_file - the plugin file.
188 * @param array $plugin_data - the plugin data.
189 *
190 * @return array
191 */
192 protected function format_plugin( $plugin_file, $plugin_data ) {
193 if ( version_compare( $this->min_version, '1.2', '>=' ) ) {
194 return $this->format_plugin_v1_2( $plugin_file, $plugin_data );
195 }
196 $plugin = array();
197 $plugin['id'] = preg_replace( '/(.+)\.php$/', '$1', $plugin_file );
198 $plugin['slug'] = Jetpack_Autoupdate::get_plugin_slug( $plugin_file );
199 $plugin['active'] = Jetpack::is_plugin_active( $plugin_file );
200 $plugin['name'] = $plugin_data['Name'];
201 $plugin['plugin_url'] = $plugin_data['PluginURI'];
202 $plugin['version'] = $plugin_data['Version'];
203 $plugin['description'] = $plugin_data['Description'];
204 $plugin['author'] = $plugin_data['Author'];
205 $plugin['author_url'] = $plugin_data['AuthorURI'];
206 $plugin['network'] = $plugin_data['Network'];
207 $plugin['update'] = $this->get_plugin_updates( $plugin_file );
208 $plugin['next_autoupdate'] = gmdate( 'Y-m-d H:i:s', wp_next_scheduled( 'wp_maybe_auto_update' ) );
209 $action_link = $this->get_plugin_action_links( $plugin_file );
210 if ( ! empty( $action_link ) ) {
211 $plugin['action_links'] = $action_link;
212 }
213
214 $plugin['plugin'] = $plugin_file;
215 if ( ! class_exists( 'WP_Automatic_Updater' ) ) {
216 require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
217 }
218 $autoupdate = ( new WP_Automatic_Updater() )->should_update( 'plugin', (object) $plugin, WP_PLUGIN_DIR );
219 $plugin['autoupdate'] = $autoupdate;
220
221 $autoupdate_translation = in_array( $plugin_file, Jetpack_Options::get_option( 'autoupdate_plugins_translations', array() ), true );
222 $plugin['autoupdate_translation'] = $autoupdate || $autoupdate_translation || Jetpack_Options::get_option( 'autoupdate_translations', false );
223
224 $plugin['uninstallable'] = is_uninstallable_plugin( $plugin_file );
225
226 if ( is_multisite() ) {
227 $plugin['network_active'] = is_plugin_active_for_network( $plugin_file );
228 }
229
230 if ( ! empty( $this->log[ $plugin_file ] ) ) {
231 $plugin['log'] = $this->log[ $plugin_file ];
232 }
233 return $plugin;
234 }
235
236 /**
237 * Format the plugin for v1_2.
238 *
239 * @param string $plugin_file - the plugin file.
240 * @param array $plugin_data - the plugin data.
241 *
242 * @return array
243 */
244 protected function format_plugin_v1_2( $plugin_file, $plugin_data ) {
245 $plugin = array();
246 $plugin['slug'] = Jetpack_Autoupdate::get_plugin_slug( $plugin_file );
247 $plugin['active'] = Jetpack::is_plugin_active( $plugin_file );
248 $plugin['name'] = preg_replace( '/(.+)\.php$/', '$1', $plugin_file );
249 $plugin['display_name'] = $plugin_data['Name'];
250 $plugin['plugin_url'] = $plugin_data['PluginURI'];
251 $plugin['version'] = $plugin_data['Version'];
252 $plugin['description'] = $plugin_data['Description'];
253 $plugin['author'] = $plugin_data['Author'];
254 $plugin['author_url'] = $plugin_data['AuthorURI'];
255 $plugin['network'] = $plugin_data['Network'];
256 $plugin['update'] = $this->get_plugin_updates( $plugin_file );
257 $action_link = $this->get_plugin_action_links( $plugin_file );
258 if ( ! empty( $action_link ) ) {
259 $plugin['action_links'] = $action_link;
260 }
261
262 $plugin['plugin'] = $plugin_file;
263 if ( ! class_exists( 'WP_Automatic_Updater' ) ) {
264 require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
265 }
266 $autoupdate = ( new WP_Automatic_Updater() )->should_update( 'plugin', (object) $plugin, WP_PLUGIN_DIR );
267 $plugin['autoupdate'] = $autoupdate;
268
269 $autoupdate_translation = $this->plugin_has_translations_autoupdates_enabled( $plugin_file );
270 $plugin['autoupdate_translation'] = $autoupdate || $autoupdate_translation || Jetpack_Options::get_option( 'autoupdate_translations', false );
271 $plugin['uninstallable'] = is_uninstallable_plugin( $plugin_file );
272
273 if ( is_multisite() ) {
274 $plugin['network_active'] = is_plugin_active_for_network( $plugin_file );
275 }
276
277 if ( ! empty( $this->log[ $plugin_file ] ) ) {
278 $plugin['log'] = $this->log[ $plugin_file ];
279 }
280
281 return $plugin;
282 }
283
284 /**
285 * Check if plugin has autoupdates for translations enabled.
286 *
287 * @param string $plugin_file - the plugin file.
288 *
289 * @return bool
290 */
291 protected function plugin_has_translations_autoupdates_enabled( $plugin_file ) {
292 return (bool) in_array( $plugin_file, Jetpack_Options::get_option( 'autoupdate_plugins_translations', array() ), true );
293 }
294
295 /**
296 * Get file mod capabilities.
297 */
298 protected function get_file_mod_capabilities() {
299 $reasons_can_not_autoupdate = array();
300 $reasons_can_not_modify_files = array();
301
302 $has_file_system_write_access = Functions::file_system_write_access();
303 if ( ! $has_file_system_write_access ) {
304 $reasons_can_not_modify_files['has_no_file_system_write_access'] = __( 'The file permissions on this host prevent editing files.', 'jetpack' );
305 }
306
307 $disallow_file_mods = Constants::get_constant( 'DISALLOW_FILE_MODS' );
308 if ( $disallow_file_mods ) {
309 $reasons_can_not_modify_files['disallow_file_mods'] = __( 'File modifications are explicitly disabled by a site administrator.', 'jetpack' );
310 }
311
312 $automatic_updater_disabled = Constants::get_constant( 'AUTOMATIC_UPDATER_DISABLED' );
313 if ( $automatic_updater_disabled ) {
314 $reasons_can_not_autoupdate['automatic_updater_disabled'] = __( 'Any autoupdates are explicitly disabled by a site administrator.', 'jetpack' );
315 }
316
317 if ( is_multisite() ) {
318 // is it the main network ? is really is multi network
319 if ( Jetpack::is_multi_network() ) {
320 $reasons_can_not_modify_files['is_multi_network'] = __( 'Multi network install are not supported.', 'jetpack' );
321 }
322 // Is the site the main site here.
323 if ( ! is_main_site() ) {
324 $reasons_can_not_modify_files['is_sub_site'] = __( 'The site is not the main network site', 'jetpack' );
325 }
326 }
327
328 $file_mod_capabilities = array(
329 'modify_files' => (bool) empty( $reasons_can_not_modify_files ), // install, remove, update
330 'autoupdate_files' => (bool) empty( $reasons_can_not_modify_files ) && empty( $reasons_can_not_autoupdate ), // enable autoupdates
331 );
332
333 if ( ! empty( $reasons_can_not_modify_files ) ) {
334 $file_mod_capabilities['reasons_modify_files_unavailable'] = $reasons_can_not_modify_files;
335 }
336
337 if ( ! $file_mod_capabilities['autoupdate_files'] ) {
338 $file_mod_capabilities['reasons_autoupdate_unavailable'] = array_merge( $reasons_can_not_autoupdate, $reasons_can_not_modify_files );
339 }
340 return $file_mod_capabilities;
341 }
342
343 /**
344 * Get plugins.
345 *
346 * @return array
347 */
348 protected function get_plugins() {
349 $plugins = array();
350 /** This filter is documented in wp-admin/includes/class-wp-plugins-list-table.php */
351 $installed_plugins = apply_filters( 'all_plugins', get_plugins() );
352 foreach ( $this->plugins as $plugin ) {
353 if ( ! isset( $installed_plugins[ $plugin ] ) ) {
354 continue;
355 }
356
357 $formatted_plugin = $this->format_plugin( $plugin, $installed_plugins[ $plugin ] );
358
359 // If this endpoint accepts site based authentication and a blog token is used, skip capabilities check.
360 if ( $this->accepts_site_based_authentication() ) {
361 $plugins[] = $formatted_plugin;
362 continue;
363 }
364
365 /*
366 * Do not show network-active plugins
367 * to folks who do not have the permission to see them.
368 */
369 if (
370 /** This filter is documented in src/wp-admin/includes/class-wp-plugins-list-table.php */
371 ! apply_filters( 'show_network_active_plugins', current_user_can( 'manage_network_plugins' ) )
372 && ! empty( $formatted_plugin['network_active'] )
373 && true === $formatted_plugin['network_active']
374 ) {
375 continue;
376 }
377
378 $plugins[] = $formatted_plugin;
379 }
380 $args = $this->query_args();
381
382 if ( isset( $args['offset'] ) ) {
383 $plugins = array_slice( $plugins, (int) $args['offset'] );
384 }
385 if ( isset( $args['limit'] ) ) {
386 $plugins = array_slice( $plugins, 0, (int) $args['limit'] );
387 }
388
389 return $plugins;
390 }
391
392 /**
393 * Validate network wide.
394 *
395 * @return bool|WP_Error
396 */
397 protected function validate_network_wide() {
398 $args = $this->input();
399
400 if ( isset( $args['network_wide'] ) && $args['network_wide'] ) {
401 $this->network_wide = true;
402 }
403
404 // If this endpoint accepts site based authentication and a blog token is used, skip capabilities check.
405 if ( $this->accepts_site_based_authentication() ) {
406 return true;
407 }
408
409 if ( $this->network_wide && ! current_user_can( 'manage_network_plugins' ) ) {
410 return new WP_Error( 'unauthorized', __( 'This user is not authorized to manage plugins network wide.', 'jetpack' ), 403 );
411 }
412
413 return true;
414 }
415
416 /**
417 * Validate the plugin.
418 *
419 * @param string $plugin - the plugin we're validating.
420 *
421 * @return bool|WP_Error
422 */
423 protected function validate_plugin( $plugin ) {
424 if ( ! isset( $plugin ) || empty( $plugin ) ) {
425 return new WP_Error( 'missing_plugin', __( 'You are required to specify a plugin to activate.', 'jetpack' ), 400 );
426 }
427
428 $error = validate_plugin( $plugin );
429 if ( is_wp_error( $error ) ) {
430 return new WP_Error( 'unknown_plugin', $error->get_error_messages(), 404 );
431 }
432
433 return true;
434 }
435
436 /**
437 * Validates if scheduled updates are allowed based on the current plan.
438 *
439 * @return bool|WP_Error True if scheduled updates are allowed or not provided, WP_Error otherwise.
440 */
441 protected function validate_scheduled_update() {
442 $args = $this->input();
443
444 if ( isset( $args['scheduled_update'] ) && $args['scheduled_update'] ) {
445 if ( Current_Plan::supports( 'scheduled-updates' ) ) {
446 $this->scheduled_update = true;
447 } else {
448 return new WP_Error( 'unauthorized', __( 'Scheduled updates are not available on your current plan. Please upgrade to a plan that supports scheduled updates to use this feature.', 'jetpack' ), 403 );
449 }
450 }
451
452 return true;
453 }
454
455 /**
456 * Get plugin updates.
457 *
458 * @param string $plugin_file - the plugin file.
459 *
460 * @return object|null
461 */
462 protected function get_plugin_updates( $plugin_file ) {
463 $plugin_updates = get_plugin_updates();
464 if ( isset( $plugin_updates[ $plugin_file ] ) ) {
465 $update = $plugin_updates[ $plugin_file ]->update;
466 $cleaned_update = array();
467 foreach ( (array) $update as $update_key => $update_value ) {
468 switch ( $update_key ) {
469 case 'id':
470 case 'slug':
471 case 'plugin':
472 case 'new_version':
473 case 'tested':
474 $cleaned_update[ $update_key ] = wp_kses( $update_value, array() );
475 break;
476 case 'url':
477 case 'package':
478 $cleaned_update[ $update_key ] = esc_url( $update_value );
479 break;
480 }
481 }
482 return (object) $cleaned_update;
483 }
484 return null;
485 }
486
487 /**
488 * Get plugin action links.
489 *
490 * @param string $plugin_file - the plugin file.
491 *
492 * @return array
493 */
494 protected function get_plugin_action_links( $plugin_file ) {
495 return Functions::get_plugins_action_links( $plugin_file );
496 }
497 }
498