PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 14.1.1
Jetpack – WP Security, Backup, Speed, & Growth v14.1.1
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / json-endpoints / class.wpcom-json-api-update-user-endpoint.php
jetpack / json-endpoints Last commit date
jetpack 1 year ago class.wpcom-json-api-add-widget-endpoint.php 2 years ago class.wpcom-json-api-autosave-post-v1-1-endpoint.php 5 years ago class.wpcom-json-api-bulk-delete-post-endpoint.php 4 years ago class.wpcom-json-api-bulk-restore-post-endpoint.php 2 years ago class.wpcom-json-api-bulk-update-comments-endpoint.php 3 years ago class.wpcom-json-api-comment-endpoint.php 2 years ago class.wpcom-json-api-delete-media-endpoint.php 4 years ago class.wpcom-json-api-delete-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-edit-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-autosave-v1-1-endpoint.php 5 years ago class.wpcom-json-api-get-comment-counts-endpoint.php 4 years ago class.wpcom-json-api-get-comment-endpoint.php 4 years ago class.wpcom-json-api-get-comment-history-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-2-endpoint.php 4 years ago class.wpcom-json-api-get-customcss.php 2 years ago class.wpcom-json-api-get-media-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-post-counts-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-post-endpoint.php 2 years ago class.wpcom-json-api-get-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-site-endpoint.php 1 year ago class.wpcom-json-api-get-site-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomies-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-get-term-endpoint.php 4 years ago class.wpcom-json-api-list-comments-endpoint.php 2 years ago class.wpcom-json-api-list-dropdown-pages-endpoint.php 3 years ago class.wpcom-json-api-list-embeds-endpoint.php 4 years ago class.wpcom-json-api-list-media-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-list-post-type-taxonomies-endpoint.php 4 years ago class.wpcom-json-api-list-post-types-endpoint.php 3 years ago class.wpcom-json-api-list-posts-endpoint.php 2 years ago class.wpcom-json-api-list-posts-v1-1-endpoint.php 3 years ago class.wpcom-json-api-list-posts-v1-2-endpoint.php 3 years ago class.wpcom-json-api-list-roles-endpoint.php 1 year ago class.wpcom-json-api-list-shortcodes-endpoint.php 4 years ago class.wpcom-json-api-list-terms-endpoint.php 2 years ago class.wpcom-json-api-list-users-endpoint.php 2 years ago class.wpcom-json-api-menus-v1-1-endpoint.php 2 years ago class.wpcom-json-api-post-endpoint.php 2 years ago class.wpcom-json-api-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-render-embed-endpoint.php 2 years ago class.wpcom-json-api-render-embed-reversal-endpoint.php 2 years ago class.wpcom-json-api-render-endpoint.php 3 years ago class.wpcom-json-api-render-shortcode-endpoint.php 3 years ago class.wpcom-json-api-sharing-buttons-endpoint.php 2 years ago class.wpcom-json-api-site-settings-endpoint.php 1 year ago class.wpcom-json-api-site-settings-v1-2-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-3-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-4-endpoint.php 1 year ago class.wpcom-json-api-site-user-endpoint.php 2 years ago class.wpcom-json-api-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-comment-endpoint.php 2 years ago class.wpcom-json-api-update-customcss.php 2 years ago class.wpcom-json-api-update-media-endpoint.php 4 years ago class.wpcom-json-api-update-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-update-post-endpoint.php 3 years ago class.wpcom-json-api-update-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-update-post-v1-2-endpoint.php 1 year ago class.wpcom-json-api-update-site-homepage-endpoint.php 4 years ago class.wpcom-json-api-update-site-logo-endpoint.php 2 years ago class.wpcom-json-api-update-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-term-endpoint.php 4 years ago class.wpcom-json-api-update-user-endpoint.php 3 years ago class.wpcom-json-api-upload-media-endpoint.php 3 years ago class.wpcom-json-api-upload-media-v1-1-endpoint.php 1 year ago
class.wpcom-json-api-update-user-endpoint.php
196 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Update site users API endpoint.
4 *
5 * Endpoint: /sites/%s/users/%d/delete
6 */
7
8 new WPCOM_JSON_API_Update_User_Endpoint(
9 array(
10 'description' => 'Deletes or removes a user of a site.',
11 'group' => 'users',
12 'stat' => 'users:delete',
13
14 'method' => 'POST',
15 'path' => '/sites/%s/users/%d/delete',
16 'path_labels' => array(
17 '$site' => '(int|string) The site ID or domain.',
18 '$user_ID' => '(int) The user\'s ID',
19 ),
20
21 'request_format' => array(
22 'reassign' => '(int) An optional id of a user to reassign posts to.',
23 ),
24
25 'response_format' => array(
26 'success' => '(bool) Was the deletion of user successful?',
27 ),
28
29 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/82974409/users/1/delete',
30 'example_request_data' => array(
31 'headers' => array(
32 'authorization' => 'Bearer YOUR_API_TOKEN',
33 ),
34 ),
35
36 'example_response' => '
37 {
38 "success": true
39 }',
40 )
41 );
42
43 /**
44 * Update site users API class.
45 */
46 class WPCOM_JSON_API_Update_User_Endpoint extends WPCOM_JSON_API_Endpoint {
47 /**
48 * Update site users API callback.
49 *
50 * @param string $path API path.
51 * @param int $blog_id Blog ID.
52 * @param int $user_id User ID.
53 */
54 public function callback( $path = '', $blog_id = 0, $user_id = 0 ) {
55 $blog_id = $this->api->switch_to_blog_and_validate_user( $this->api->get_blog_id( $blog_id ) );
56 if ( is_wp_error( $blog_id ) ) {
57 return $blog_id;
58 }
59
60 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
61 if ( (int) wpcom_get_blog_owner( $blog_id ) === (int) $user_id ) {
62 return new WP_Error( 'forbidden', 'A site owner can not be removed through this endpoint.', 403 );
63 }
64 }
65
66 if ( $this->api->ends_with( $path, '/delete' ) ) {
67 return $this->delete_or_remove_user( $user_id );
68 }
69
70 return false;
71 }
72
73 /**
74 * Checks if a user exists by checking to see if a WP_User object exists for a user ID.
75 *
76 * @param int $user_id User ID.
77 * @return bool
78 */
79 public function user_exists( $user_id ) {
80 $user = get_user_by( 'id', $user_id );
81
82 return false !== $user && is_a( $user, 'WP_User' );
83 }
84
85 /**
86 * Return the domain name of a subscription.
87 *
88 * @param Store_Subscription $subscription Subscription object.
89 * @return string
90 */
91 protected function get_subscription_domain_name( $subscription ) {
92 return $subscription->meta;
93 }
94
95 /**
96 * Get a list of the domains owned by the given user.
97 *
98 * @param int $user_id User ID.
99 * @return array
100 */
101 protected function domain_subscriptions_for_site_owned_by_user( $user_id ) {
102 $subscriptions = WPCOM_Store::get_subscriptions( get_current_blog_id(), $user_id, domains::get_domain_products() );
103
104 $domains = array_unique( array_map( array( $this, 'get_subscription_domain_name' ), $subscriptions ) );
105
106 return array_values( $domains );
107 }
108
109 /**
110 * Validates user input and then decides whether to remove or delete a user.
111 *
112 * @param int $user_id User ID.
113 * @return array|WP_Error
114 */
115 public function delete_or_remove_user( $user_id ) {
116 if ( 0 === (int) $user_id ) {
117 return new WP_Error( 'invalid_input', 'A valid user ID must be specified.', 400 );
118 }
119
120 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
121 $domains = $this->domain_subscriptions_for_site_owned_by_user( $user_id );
122 if ( ! empty( $domains ) ) {
123 $error = new WP_Error( 'user_owns_domain_subscription', implode( ', ', $domains ) );
124 $error->add_data( $domains, 'additional_data' );
125 return $error;
126 }
127
128 $active_user_subscriptions = WPCOM_Store::get_user_subscriptions( $user_id, get_current_blog_id() );
129 if ( ! empty( $active_user_subscriptions ) ) {
130 $product_names = array_values( wp_list_pluck( $active_user_subscriptions, 'product_name' ) );
131 $error = new WP_Error( 'user_has_active_subscriptions', 'User has active subscriptions' );
132 $error->add_data( $product_names, 'additional_data' );
133 return $error;
134 }
135 }
136
137 if ( get_current_user_id() === (int) $user_id ) {
138 return new WP_Error( 'invalid_input', 'User can not remove or delete self through this endpoint.', 400 );
139 }
140
141 if ( ! $this->user_exists( $user_id ) ) {
142 return new WP_Error( 'invalid_input', 'A user does not exist with that ID.', 400 );
143 }
144
145 return is_multisite() ? $this->remove_user( $user_id ) : $this->delete_user( $user_id );
146 }
147
148 /**
149 * Removes a user from the current site.
150 *
151 * @param int $user_id User ID.
152 * @return array|WP_Error
153 */
154 public function remove_user( $user_id ) {
155 if ( ! current_user_can( 'remove_users' ) ) {
156 return new WP_Error( 'unauthorized', 'User cannot remove users for specified site.', 403 );
157 }
158
159 if ( ! is_user_member_of_blog( $user_id, get_current_blog_id() ) ) {
160 return new WP_Error( 'invalid_input', 'User is not a member of the specified site.', 400 );
161 }
162
163 return array(
164 'success' => remove_user_from_blog( $user_id, get_current_blog_id() ),
165 );
166 }
167
168 /**
169 * Deletes a user and optionally reassigns posts to another user.
170 *
171 * @param int $user_id User ID.
172 * @return array|WP_Error
173 */
174 public function delete_user( $user_id ) {
175 if ( ! current_user_can( 'delete_users' ) ) {
176 return new WP_Error( 'unauthorized', 'User cannot delete users for specified site.', 403 );
177 }
178
179 $input = (array) $this->input();
180
181 if ( isset( $input['reassign'] ) ) {
182 if ( (int) $user_id === (int) $input['reassign'] ) {
183 return new WP_Error( 'invalid_input', 'Can not reassign posts to user being deleted.', 400 );
184 }
185
186 if ( ! $this->user_exists( $input['reassign'] ) ) {
187 return new WP_Error( 'invalid_input', 'User specified in reassign argument is not a member of the specified site.', 400 );
188 }
189 }
190
191 return array(
192 'success' => wp_delete_user( $user_id, (int) $input['reassign'] ),
193 );
194 }
195 }
196