PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 13.7.2
Jetpack – WP Security, Backup, Speed, & Growth v13.7.2
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / extensions / blocks / premium-content / _inc / access-check.php
jetpack / extensions / blocks / premium-content / _inc Last commit date
subscription-service 2 years ago access-check.php 2 years ago legacy-buttons.php 5 years ago
access-check.php
162 lines
1 <?php
2 /**
3 * Determine access to premium content.
4 *
5 * @package Automattic\Jetpack\Extensions\Premium_Content
6 */
7
8 namespace Automattic\Jetpack\Extensions\Premium_Content;
9
10 use Automattic\Jetpack\Extensions\Premium_Content\Subscription_Service\Abstract_Token_Subscription_Service;
11 use Automattic\Jetpack\Extensions\Premium_Content\Subscription_Service\WPCOM_Online_Subscription_Service;
12 use Automattic\Jetpack\Status\Host;
13
14 require_once __DIR__ . '/subscription-service/include.php';
15
16 /**
17 * Determines if the memberships module is set up.
18 *
19 * @return bool Whether the memberships module is set up.
20 */
21 function membership_checks() {
22 // If Jetpack is not yet configured, don't show anything ...
23 if ( ! class_exists( '\Jetpack_Memberships' ) ) {
24 return false;
25 }
26 // if stripe not connected don't show anything...
27 if ( ! \Jetpack_Memberships::has_connected_account() ) {
28 return false;
29 }
30 return true;
31 }
32
33 /**
34 * Determines if the site has a plan that supports the
35 * Premium Content block.
36 *
37 * @return bool
38 */
39 function required_plan_checks() {
40 $availability = \Jetpack_Gutenberg::get_cached_availability();
41 $slug = 'premium-content/container';
42 return ( isset( $availability[ $slug ] ) && $availability[ $slug ]['available'] );
43 }
44
45 /**
46 * Determines if the block should be rendered. Returns true
47 * if the block passes all required checks, or if the user is
48 * an editor.
49 *
50 * @return bool Whether the block should be rendered.
51 */
52 function pre_render_checks() {
53 return ( current_user_can_edit() || membership_checks() );
54 }
55
56 /**
57 * Determines whether the current user can edit.
58 *
59 * @return bool Whether the user can edit.
60 */
61 function current_user_can_edit() {
62 $user = wp_get_current_user();
63
64 return 0 !== $user->ID && current_user_can( 'edit_post', get_the_ID() );
65 }
66
67 /**
68 * Determines if the current user can view the protected content of the given block.
69 *
70 * @param array $attributes Block attributes.
71 * @param object $block Block to check.
72 *
73 * @return bool Whether the use can view the content.
74 */
75 function current_visitor_can_access( $attributes, $block ) {
76 /**
77 * If the current WordPress install has as signed in user
78 * they can see the content.
79 */
80
81 if ( current_user_can_edit() ) {
82 return true;
83 }
84
85 $selected_plan_ids = array();
86
87 if ( isset( $attributes['selectedPlanIds'] ) ) {
88 $selected_plan_ids = $attributes['selectedPlanIds'];
89 } elseif ( isset( $attributes['selectedPlanId'] ) ) {
90 $selected_plan_ids = array( $attributes['selectedPlanId'] );
91 }
92
93 if ( isset( $block ) && ! empty( $block->context['premium-content/planId'] ) ) {
94 $selected_plan_ids = array( $block->context['premium-content/planId'] );
95 } elseif ( isset( $block ) && ! empty( $block->context['premium-content/planIds'] ) ) {
96 $selected_plan_ids = $block->context['premium-content/planIds'];
97 }
98
99 if ( empty( $selected_plan_ids ) ) {
100 return false;
101 }
102
103 $can_view = false;
104 $paywall = subscription_service();
105 $access_level = Abstract_Token_Subscription_Service::POST_ACCESS_LEVEL_PAID_SUBSCRIBERS; // Only paid subscribers should be granted access to the premium content
106 $tier_ids = \Jetpack_Memberships::get_all_newsletter_plan_ids();
107 $tier_ids = array_intersect( $tier_ids, $selected_plan_ids );
108 if ( ! empty( $tier_ids ) ) {
109 // If the selected plan is a tier, we want to check directly if user has a higher "tier".
110 // This is to prevent situation where the user upgrades and lose access to premium-gated content
111
112 $subscriptions = array();
113 if ( ( new Host() )->is_wpcom_simple() && is_user_logged_in() ) {
114 $user_id = wp_get_current_user()->ID;
115 /**
116 * Filter the subscriptions attached to a specific user on a given site.
117 *
118 * @since 9.4.0
119 *
120 * @param array $subscriptions Array of subscriptions.
121 * @param int $user_id The user's ID.
122 * @param int $site_id ID of the current site.
123 */
124 $subscriptions = apply_filters( 'earn_get_user_subscriptions_for_site_id', array(), $user_id, get_current_blog_id() );
125 // format the subscriptions so that they can be validated.
126 $subscriptions = WPCOM_Online_Subscription_Service::abbreviate_subscriptions( $subscriptions );
127 } else {
128 $token = $paywall->get_and_set_token_from_request();
129 $payload = $paywall->decode_token( $token );
130 $is_valid_token = ! empty( $payload );
131
132 if ( $is_valid_token ) {
133 $subscriptions = (array) $payload['subscriptions'];
134 }
135 }
136
137 foreach ( $tier_ids as $tier_id ) {
138 $can_view = ! $paywall->maybe_gate_access_for_user_if_tier( $tier_id, $subscriptions );
139 if ( $can_view ) {
140 break;
141 }
142 }
143 }
144
145 $non_tier_ids = array_diff( $selected_plan_ids, $tier_ids );
146 if ( ! $can_view ) {
147 // For selected plans that are not tiers, we want to check if the user has any of the selected plans.
148 $can_view = $paywall->visitor_can_view_content( $non_tier_ids, $access_level );
149 }
150
151 if ( $can_view ) {
152 /**
153 * Fires when a visitor can view protected content on a site.
154 *
155 * @since 9.4.0
156 */
157 do_action( 'jetpack_earn_remove_cache_headers' );
158 }
159
160 return $can_view;
161 }
162