PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 13.6.2
Jetpack – WP Security, Backup, Speed, & Growth v13.6.2
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / modules / sharedaddy / recaptcha.php
jetpack / modules / sharedaddy Last commit date
images 2 years ago services 2 years ago admin-sharing-rtl.css 2 years ago admin-sharing-rtl.min.css 2 years ago admin-sharing.css 2 years ago admin-sharing.js 2 years ago admin-sharing.min.css 2 years ago amp-sharing.css 2 years ago recaptcha.php 4 years ago sharedaddy.php 2 years ago sharing-service.php 2 years ago sharing-sources.php 2 years ago sharing.css 2 years ago sharing.js 3 years ago sharing.php 2 years ago
recaptcha.php
231 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Google reCAPTCHA utilities, for use in the sharing feature.
4 *
5 * @package automattic/jetpack
6 */
7
8 /**
9 * Class that handles reCAPTCHA.
10 *
11 * @deprecated 11.0
12 */
13 class Jetpack_ReCaptcha {
14
15 /**
16 * URL to which requests are POSTed.
17 *
18 * @const string
19 */
20 const VERIFY_URL = 'https://www.google.com/recaptcha/api/siteverify';
21
22 /**
23 * Site key to use in HTML code.
24 *
25 * @var string
26 */
27 private $site_key;
28
29 /**
30 * Shared secret for the site.
31 *
32 * @var string
33 */
34 private $secret_key;
35
36 /**
37 * Config for reCAPTCHA instance.
38 *
39 * @var array
40 */
41 private $config;
42
43 /**
44 * Error codes returned from reCAPTCHA API.
45 *
46 * @see https://developers.google.com/recaptcha/docs/verify
47 *
48 * @var array
49 */
50 private $error_codes;
51
52 /**
53 * Create a configured instance to use the reCAPTCHA service.
54 *
55 * @param string $site_key Site key to use in HTML code.
56 * @param string $secret_key Shared secret between site and reCAPTCHA server.
57 * @param array $config Config array to optionally configure reCAPTCHA instance.
58 */
59 public function __construct( $site_key, $secret_key, $config = array() ) {
60 $this->site_key = $site_key;
61 $this->secret_key = $secret_key;
62 $this->config = wp_parse_args( $config, $this->get_default_config() );
63
64 $this->error_codes = array(
65 'missing-input-secret' => __( 'The secret parameter is missing', 'jetpack' ),
66 'invalid-input-secret' => __( 'The secret parameter is invalid or malformed', 'jetpack' ),
67 'missing-input-response' => __( 'The response parameter is missing', 'jetpack' ),
68 'invalid-input-response' => __( 'The response parameter is invalid or malformed', 'jetpack' ),
69 'invalid-json' => __( 'Invalid JSON', 'jetpack' ),
70 'unexpected-response' => __( 'Unexpected response', 'jetpack' ),
71 'unexpected-hostname' => __( 'Unexpected hostname', 'jetpack' ),
72 );
73 }
74
75 /**
76 * Get default config for this reCAPTCHA instance.
77 *
78 * @return array Default config
79 */
80 public function get_default_config() {
81 return array(
82 'language' => get_locale(),
83 'script_async' => false,
84 'script_defer' => true,
85 'script_lazy' => false,
86 'tag_class' => 'g-recaptcha',
87 'tag_attributes' => array(
88 'theme' => 'light',
89 'type' => 'image',
90 'tabindex' => 0,
91 ),
92 );
93 }
94
95 /**
96 * Calls the reCAPTCHA siteverify API to verify whether the user passes
97 * CAPTCHA test.
98 *
99 * @param string $response The value of 'g-recaptcha-response' in the submitted
100 * form.
101 * @param string $remote_ip The end user's IP address.
102 *
103 * @return bool|WP_Error Returns true if verified. Otherwise WP_Error is returned.
104 */
105 public function verify( $response, $remote_ip ) {
106 // No need make a request if response is empty.
107 if ( empty( $response ) ) {
108 return new WP_Error( 'missing-input-response', $this->error_codes['missing-input-response'], 400 );
109 }
110
111 $resp = wp_remote_post( self::VERIFY_URL, $this->get_verify_request_params( $response, $remote_ip ) );
112 if ( is_wp_error( $resp ) ) {
113 return $resp;
114 }
115
116 $resp_decoded = json_decode( wp_remote_retrieve_body( $resp ), true );
117 if ( ! $resp_decoded ) {
118 return new WP_Error( 'invalid-json', $this->error_codes['invalid-json'], 400 );
119 }
120
121 // Default error code and message.
122 $error_code = 'unexpected-response';
123 $error_message = $this->error_codes['unexpected-response'];
124
125 // Use the first error code if exists.
126 if ( isset( $resp_decoded['error-codes'] ) && is_array( $resp_decoded['error-codes'] ) ) {
127 if ( isset( $resp_decoded['error-codes'][0] ) && isset( $this->error_codes[ $resp_decoded['error-codes'][0] ] ) ) {
128 $error_message = $this->error_codes[ $resp_decoded['error-codes'][0] ];
129 $error_code = $resp_decoded['error-codes'][0];
130 }
131 }
132
133 if ( ! isset( $resp_decoded['success'] ) ) {
134 return new WP_Error( $error_code, $error_message );
135 }
136
137 if ( true !== $resp_decoded['success'] ) {
138 return new WP_Error( $error_code, $error_message );
139 }
140 // Validate the hostname matches expected source
141 if ( isset( $resp_decoded['hostname'] ) ) {
142 $url = wp_parse_url( get_home_url() );
143
144 /**
145 * Allow other valid hostnames.
146 *
147 * This can be useful in cases where the token hostname is expected to be
148 * different from the get_home_url (ex. AMP recaptcha token contains a different hostname)
149 *
150 * @module sharedaddy
151 *
152 * @since 9.1.0
153 *
154 * @param array [ $url['host'] ] List of the valid hostnames to check against.
155 */
156 $valid_hostnames = apply_filters( 'jetpack_recaptcha_valid_hostnames', array( $url['host'] ) );
157
158 if ( ! in_array( $resp_decoded['hostname'], $valid_hostnames, true ) ) {
159 return new WP_Error( 'unexpected-host', $this->error_codes['unexpected-hostname'] );
160 }
161 }
162
163 return true;
164 }
165
166 /**
167 * Get siteverify request parameters.
168 *
169 * @param string $response The value of 'g-recaptcha-response' in the submitted
170 * form.
171 * @param string $remote_ip The end user's IP address.
172 *
173 * @return array
174 */
175 public function get_verify_request_params( $response, $remote_ip ) {
176 return array(
177 'body' => array(
178 'secret' => $this->secret_key,
179 'response' => $response,
180 'remoteip' => $remote_ip,
181 ),
182 'sslverify' => true,
183 );
184 }
185
186 /**
187 * Get reCAPTCHA HTML to render.
188 *
189 * @return string
190 */
191 public function get_recaptcha_html() {
192 $url = sprintf(
193 'https://www.google.com/recaptcha/api.js?hl=%s',
194 rawurlencode( $this->config['language'] )
195 );
196
197 $html = sprintf(
198 '
199 <div
200 class="%s"
201 data-sitekey="%s"
202 data-theme="%s"
203 data-type="%s"
204 data-tabindex="%s"
205 data-lazy="%s"
206 data-url="%s"></div>
207 ',
208 esc_attr( $this->config['tag_class'] ),
209 esc_attr( $this->site_key ),
210 esc_attr( $this->config['tag_attributes']['theme'] ),
211 esc_attr( $this->config['tag_attributes']['type'] ),
212 esc_attr( $this->config['tag_attributes']['tabindex'] ),
213 $this->config['script_lazy'] ? 'true' : 'false',
214 esc_attr( $url )
215 );
216
217 if ( ! $this->config['script_lazy'] ) {
218 $html = $html . sprintf(
219 // phpcs:ignore WordPress.WP.EnqueuedResources.NonEnqueuedScript
220 '<script src="%s"%s%s></script>
221 ',
222 $url,
223 $this->config['script_async'] && ! $this->config['script_defer'] ? ' async' : '',
224 $this->config['script_defer'] ? ' defer' : ''
225 );
226 }
227
228 return $html;
229 }
230 }
231