PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 14.0.1
Jetpack – WP Security, Backup, Speed, & Growth v14.0.1
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / class-jetpack-xmlrpc-methods.php
jetpack Last commit date
3rd-party 1 year ago _inc 1 year ago css 1 year ago extensions 1 year ago images 1 year ago jetpack_vendor 17 hours ago json-endpoints 1 year ago modules 1 year ago sal 1 year ago src 1 year ago vendor 1 year ago views 2 years ago CHANGELOG.md 1 year ago LICENSE.txt 5 years ago SECURITY.md 2 years ago class-jetpack-connection-status.php 2 years ago class-jetpack-gallery-settings.php 3 years ago class-jetpack-pre-connection-jitms.php 2 years ago class-jetpack-stats-dashboard-widget.php 2 years ago class-jetpack-xmlrpc-methods.php 1 year ago class.frame-nonce-preview.php 4 years ago class.jetpack-admin.php 1 year ago class.jetpack-affiliate.php 2 years ago class.jetpack-autoupdate.php 2 years ago class.jetpack-bbpress-json-api.compat.php 2 years ago class.jetpack-cli.php 1 year ago class.jetpack-client-server.php 2 years ago class.jetpack-gutenberg.php 1 year ago class.jetpack-heartbeat.php 2 years ago class.jetpack-modules-list-table.php 2 years ago class.jetpack-network-sites-list-table.php 2 years ago class.jetpack-network.php 2 years ago class.jetpack-plan.php 3 years ago class.jetpack-post-images.php 2 years ago class.jetpack-twitter-cards.php 2 years ago class.jetpack-user-agent.php 2 years ago class.jetpack.php 1 year ago class.json-api-endpoints.php 1 year ago class.json-api.php 2 years ago class.photon.php 3 years ago composer.json 1 year ago enhanced-open-graph.php 3 years ago functions.compat.php 2 years ago functions.cookies.php 2 years ago functions.global.php 2 years ago functions.is-mobile.php 2 years ago functions.opengraph.php 2 years ago functions.photon.php 2 years ago global.d.ts 2 years ago jetpack.php 17 hours ago json-api-config.php 3 years ago json-endpoints.php 2 years ago load-jetpack.php 2 years ago locales.php 4 years ago readme.txt 17 hours ago uninstall.php 2 years ago wpml-config.xml 4 years ago
class-jetpack-xmlrpc-methods.php
273 lines
1 <?php
2 /**
3 * Jetpack XMLRPC Methods.
4 *
5 * Registers the Jetpack specific XMLRPC methods
6 *
7 * @package jetpack
8 */
9
10 use Automattic\Jetpack\Connection\Manager as Connection_Manager;
11 use Automattic\Jetpack\Connection\Tokens;
12
13 /**
14 * XMLRPC Methods registration and callbacks
15 */
16 class Jetpack_XMLRPC_Methods {
17
18 /**
19 * Initialize the main hooks.
20 */
21 public static function init() {
22 add_filter( 'jetpack_xmlrpc_unauthenticated_methods', array( __CLASS__, 'xmlrpc_methods' ) );
23 add_filter( 'jetpack_xmlrpc_test_connection_response', array( __CLASS__, 'test_connection' ) );
24 add_action( 'jetpack_xmlrpc_server_event', array( __CLASS__, 'jetpack_xmlrpc_server_event' ), 10, 4 );
25 add_action( 'jetpack_remote_connect_end', array( __CLASS__, 'remote_connect_end' ) );
26 add_filter( 'jetpack_xmlrpc_remote_register_redirect_uri', array( __CLASS__, 'remote_register_redirect_uri' ) );
27 }
28
29 /**
30 * Adds Jetpack specific methods to the methods added by the Connection package.
31 *
32 * @param array $methods Methods added by the Connection package.
33 */
34 public static function xmlrpc_methods( $methods ) {
35
36 $methods['jetpack.featuresAvailable'] = array( __CLASS__, 'features_available' );
37 $methods['jetpack.featuresEnabled'] = array( __CLASS__, 'features_enabled' );
38 $methods['jetpack.disconnectBlog'] = array( __CLASS__, 'disconnect_blog' );
39 $methods['jetpack.jsonAPI'] = array( __CLASS__, 'json_api' );
40
41 return $methods;
42 }
43
44 /**
45 * Returns what features are available. Uses the slug of the module files.
46 *
47 * @deprecated 13.9
48 * @see Jetpack_Core_Json_Api_Endpoints::get_features_available()
49 * @return array
50 */
51 public static function features_available() {
52 $raw_modules = Jetpack::get_available_modules();
53 $modules = array();
54 foreach ( $raw_modules as $module ) {
55 $modules[] = Jetpack::get_module_slug( $module );
56 }
57
58 return $modules;
59 }
60
61 /**
62 * Returns what features are enabled. Uses the slug of the modules files.
63 *
64 * @deprecated 13.9
65 * @see Jetpack_Core_Json_Api_Endpoints::get_features_enabled()
66 * @return array
67 */
68 public static function features_enabled() {
69 $raw_modules = Jetpack::get_active_modules();
70 $modules = array();
71 foreach ( $raw_modules as $module ) {
72 $modules[] = Jetpack::get_module_slug( $module );
73 }
74
75 return $modules;
76 }
77
78 /**
79 * Filters the result of test_connection XMLRPC method
80 *
81 * @return string The current Jetpack version number
82 */
83 public static function test_connection() {
84 return JETPACK__VERSION;
85 }
86
87 /**
88 * Disconnect this blog from the connected wordpress.com account
89 *
90 * @return boolean
91 */
92 public static function disconnect_blog() {
93
94 /**
95 * Fired when we want to log an event to the Jetpack event log.
96 *
97 * @since 7.7.0
98 *
99 * @param string $code Unique name for the event.
100 * @param string $data Optional data about the event.
101 */
102 do_action( 'jetpack_event_log', 'disconnect' );
103 ( new Connection_Manager( 'jetpack' ) )->disconnect_site();
104
105 return true;
106 }
107
108 /**
109 * Serve a JSON API request.
110 *
111 * @param array $args request arguments.
112 */
113 public static function json_api( $args = array() ) {
114 $json_api_args = $args[0];
115 $verify_api_user_args = $args[1];
116
117 $method = (string) $json_api_args[0];
118 $url = (string) $json_api_args[1];
119 $post_body = $json_api_args[2] === null ? null : (string) $json_api_args[2];
120 $user_details = (array) $json_api_args[4];
121 $locale = (string) $json_api_args[5];
122
123 if ( ! $verify_api_user_args ) {
124 $user_id = 0;
125 } elseif ( 'internal' === $verify_api_user_args[0] ) {
126 $user_id = (int) $verify_api_user_args[1];
127 if ( $user_id ) {
128 $user = get_user_by( 'id', $user_id );
129 if ( ! $user || is_wp_error( $user ) ) {
130 return false;
131 }
132 }
133 } else {
134 $user_id = call_user_func( array( new Jetpack_XMLRPC_Server(), 'test_api_user_code' ), $verify_api_user_args );
135 if ( ! $user_id ) {
136 return false;
137 }
138 }
139
140 if ( 'en' !== $locale ) {
141 // .org mo files are named slightly different from .com, and all we have is this the locale -- try to guess them.
142 $new_locale = $locale;
143 if ( str_contains( $locale, '-' ) ) {
144 $locale_pieces = explode( '-', $locale );
145 $new_locale = $locale_pieces[0];
146 $new_locale .= ( ! empty( $locale_pieces[1] ) ) ? '_' . strtoupper( $locale_pieces[1] ) : '';
147 } else { // phpcs:ignore Universal.ControlStructures.DisallowLonelyIf.Found
148 // .com might pass 'fr' because thats what our language files are named as, where core seems
149 // to do fr_FR - so try that if we don't think we can load the file.
150 if ( ! file_exists( WP_LANG_DIR . '/' . $locale . '.mo' ) ) {
151 $new_locale = $locale . '_' . strtoupper( $locale );
152 }
153 }
154
155 if ( file_exists( WP_LANG_DIR . '/' . $new_locale . '.mo' ) ) {
156 unload_textdomain( 'default' );
157 load_textdomain( 'default', WP_LANG_DIR . '/' . $new_locale . '.mo' );
158 }
159 }
160
161 $old_user = wp_get_current_user();
162 wp_set_current_user( $user_id );
163
164 if ( $user_id ) {
165 $token_key = false;
166 } else {
167 $verified = ( new Connection_Manager() )->verify_xml_rpc_signature();
168 $token_key = $verified['token_key'];
169 }
170
171 $token = ( new Tokens() )->get_access_token( $user_id, $token_key );
172 if ( ! $token || is_wp_error( $token ) ) {
173 return false;
174 }
175
176 define( 'REST_API_REQUEST', true );
177 define( 'WPCOM_JSON_API__BASE', 'public-api.wordpress.com/rest/v1' );
178
179 // needed?
180 require_once ABSPATH . 'wp-admin/includes/admin.php';
181
182 require_once JETPACK__PLUGIN_DIR . 'class.json-api.php';
183 $api = WPCOM_JSON_API::init( $method, $url, $post_body );
184 $api->token_details['user'] = $user_details;
185 require_once JETPACK__PLUGIN_DIR . 'class.json-api-endpoints.php';
186
187 $display_errors = ini_set( 'display_errors', 0 ); // phpcs:ignore WordPress.PHP.IniSet
188 ob_start();
189 $api->serve( false );
190 $output = ob_get_clean();
191 ini_set( 'display_errors', $display_errors ); // phpcs:ignore WordPress.PHP.IniSet
192
193 $nonce = wp_generate_password( 10, false );
194 $hmac = hash_hmac( 'md5', $nonce . $output, $token->secret );
195
196 wp_set_current_user( isset( $old_user->ID ) ? $old_user->ID : 0 );
197
198 return array(
199 (string) $output,
200 (string) $nonce,
201 (string) $hmac,
202 );
203 }
204
205 /**
206 * Filters the response of the remote_provision XMLRPC method
207 *
208 * @param array $response The response.
209 * @param array $request An array containing at minimum a nonce key and a local_username key.
210 *
211 * @since 9.8.0
212 * @deprecated since 13.9
213 *
214 * @return array
215 */
216 public static function remote_provision_response( $response, $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
217 _deprecated_function( __METHOD__, '13.9' );
218 return $response;
219 }
220
221 /**
222 * Runs Jetpack specific action in xmlrpc server events
223 *
224 * @param String $action the action name, i.e., 'remote_authorize'.
225 * @param String $stage the execution stage, can be 'begin', 'success', 'error', etc.
226 * @param array $parameters extra parameters from the event.
227 * @param WP_User $user the acting user.
228 * @return void
229 */
230 public static function jetpack_xmlrpc_server_event( $action, $stage, $parameters = array(), $user = null ) { //phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
231 if ( 'remote_register' === $action && 'begin' === $stage ) {
232 Jetpack::maybe_set_version_option();
233 }
234 }
235
236 /**
237 * Hooks into the remote_connect XMLRPC endpoint and triggers Jetpack::handle_post_authorization_actions
238 *
239 * @since 9.8.0
240 * @return void
241 */
242 public static function remote_connect_end() {
243 /** This filter is documented in class.jetpack-cli.php */
244 $enable_sso = apply_filters( 'jetpack_start_enable_sso', true );
245 Jetpack::handle_post_authorization_actions( $enable_sso, false, false );
246 }
247
248 /**
249 * Filters the Redirect URI returned by the remote_register XMLRPC method
250 *
251 * @since 9.8.0
252 *
253 * @param string $redirect_uri The Redirect URI.
254 * @return string
255 */
256 public static function remote_register_redirect_uri( $redirect_uri ) {
257 $auto_enable_sso = ( ! ( new Connection_Manager() )->has_connected_owner() || Jetpack::is_module_active( 'sso' ) );
258
259 /** This filter is documented in class.jetpack-cli.php */
260 if ( apply_filters( 'jetpack_start_enable_sso', $auto_enable_sso ) ) {
261 $redirect_uri = add_query_arg(
262 array(
263 'action' => 'jetpack-sso',
264 'redirect_to' => rawurlencode( admin_url() ),
265 ),
266 wp_login_url() // TODO: come back to Jetpack dashboard?
267 );
268 }
269
270 return $redirect_uri;
271 }
272 }
273