PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 14.3.1
Jetpack – WP Security, Backup, Speed, & Growth v14.3.1
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / json-endpoints / class.wpcom-json-api-site-user-endpoint.php
jetpack / json-endpoints Last commit date
jetpack 1 year ago class.wpcom-json-api-add-widget-endpoint.php 2 years ago class.wpcom-json-api-autosave-post-v1-1-endpoint.php 5 years ago class.wpcom-json-api-bulk-delete-post-endpoint.php 4 years ago class.wpcom-json-api-bulk-restore-post-endpoint.php 2 years ago class.wpcom-json-api-bulk-update-comments-endpoint.php 3 years ago class.wpcom-json-api-comment-endpoint.php 1 year ago class.wpcom-json-api-delete-media-endpoint.php 4 years ago class.wpcom-json-api-delete-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-edit-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-autosave-v1-1-endpoint.php 5 years ago class.wpcom-json-api-get-comment-counts-endpoint.php 1 year ago class.wpcom-json-api-get-comment-endpoint.php 4 years ago class.wpcom-json-api-get-comment-history-endpoint.php 1 year ago class.wpcom-json-api-get-comments-tree-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-2-endpoint.php 4 years ago class.wpcom-json-api-get-customcss.php 2 years ago class.wpcom-json-api-get-media-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-post-counts-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-post-endpoint.php 2 years ago class.wpcom-json-api-get-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-site-endpoint.php 1 year ago class.wpcom-json-api-get-site-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomies-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-get-term-endpoint.php 4 years ago class.wpcom-json-api-list-comments-endpoint.php 1 year ago class.wpcom-json-api-list-dropdown-pages-endpoint.php 3 years ago class.wpcom-json-api-list-embeds-endpoint.php 4 years ago class.wpcom-json-api-list-media-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-list-post-type-taxonomies-endpoint.php 4 years ago class.wpcom-json-api-list-post-types-endpoint.php 3 years ago class.wpcom-json-api-list-posts-endpoint.php 2 years ago class.wpcom-json-api-list-posts-v1-1-endpoint.php 3 years ago class.wpcom-json-api-list-posts-v1-2-endpoint.php 3 years ago class.wpcom-json-api-list-roles-endpoint.php 1 year ago class.wpcom-json-api-list-shortcodes-endpoint.php 4 years ago class.wpcom-json-api-list-terms-endpoint.php 2 years ago class.wpcom-json-api-list-users-endpoint.php 2 years ago class.wpcom-json-api-menus-v1-1-endpoint.php 2 years ago class.wpcom-json-api-post-endpoint.php 2 years ago class.wpcom-json-api-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-render-embed-endpoint.php 2 years ago class.wpcom-json-api-render-embed-reversal-endpoint.php 2 years ago class.wpcom-json-api-render-endpoint.php 3 years ago class.wpcom-json-api-render-shortcode-endpoint.php 3 years ago class.wpcom-json-api-sharing-buttons-endpoint.php 2 years ago class.wpcom-json-api-site-settings-endpoint.php 1 year ago class.wpcom-json-api-site-settings-v1-2-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-3-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-4-endpoint.php 1 year ago class.wpcom-json-api-site-user-endpoint.php 1 year ago class.wpcom-json-api-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-comment-endpoint.php 2 years ago class.wpcom-json-api-update-customcss.php 2 years ago class.wpcom-json-api-update-media-endpoint.php 4 years ago class.wpcom-json-api-update-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-update-post-endpoint.php 1 year ago class.wpcom-json-api-update-post-v1-1-endpoint.php 1 year ago class.wpcom-json-api-update-post-v1-2-endpoint.php 1 year ago class.wpcom-json-api-update-site-homepage-endpoint.php 4 years ago class.wpcom-json-api-update-site-logo-endpoint.php 2 years ago class.wpcom-json-api-update-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-term-endpoint.php 4 years ago class.wpcom-json-api-update-user-endpoint.php 3 years ago class.wpcom-json-api-upload-media-endpoint.php 3 years ago class.wpcom-json-api-upload-media-v1-1-endpoint.php 1 year ago
class.wpcom-json-api-site-user-endpoint.php
269 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2
3 new WPCOM_JSON_API_Site_User_Endpoint(
4 array(
5 'description' => 'Get details of a user of a site by ID.',
6 'group' => '__do_not_document', // 'users'
7 'stat' => 'sites:1:user',
8 'method' => 'GET',
9 'path' => '/sites/%s/users/%d',
10 'path_labels' => array(
11 '$site' => '(int|string) Site ID or domain',
12 '$user_id' => '(int) User ID',
13 ),
14 'response_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
15 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/30434183/user/23',
16 'example_request_data' => array(
17 'headers' => array(
18 'authorization' => 'Bearer YOUR_API_TOKEN',
19 ),
20 ),
21 'example_response' => '{
22 "ID": 18342963,
23 "login": "binarysmash",
24 "email": false,
25 "name": "binarysmash",
26 "URL": "http:\/\/binarysmash.wordpress.com",
27 "avatar_URL": "http:\/\/0.gravatar.com\/avatar\/a178ebb1731d432338e6bb0158720fcc?s=96&d=identicon&r=G",
28 "profile_URL": "http:\/\/gravatar.com\/binarysmash",
29 "roles": [ "administrator" ]
30 }',
31 )
32 );
33
34 new WPCOM_JSON_API_Site_User_Endpoint(
35 array(
36 'description' => 'Get details of a user of a site by login.',
37 'group' => 'users',
38 'stat' => 'sites:1:user',
39 'method' => 'GET',
40 'path' => '/sites/%s/users/login:%s',
41 'path_labels' => array(
42 '$site' => '(int|string) The site ID or domain.',
43 '$user_id' => '(string) The user\'s login.',
44 ),
45 'response_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
46 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/30434183/user/login:binarysmash',
47 'example_request_data' => array(
48 'headers' => array(
49 'authorization' => 'Bearer YOUR_API_TOKEN',
50 ),
51 ),
52 'example_response' => '{
53 "ID": 18342963,
54 "login": "binarysmash",
55 "email": false,
56 "name": "binarysmash",
57 "URL": "http:\/\/binarysmash.wordpress.com",
58 "avatar_URL": "http:\/\/0.gravatar.com\/avatar\/a178ebb1731d432338e6bb0158720fcc?s=96&d=identicon&r=G",
59 "profile_URL": "http:\/\/gravatar.com\/binarysmash",
60 "roles": [ "administrator" ]
61 }',
62 )
63 );
64
65 new WPCOM_JSON_API_Site_User_Endpoint(
66 array(
67 'description' => 'Update details of a user of a site.',
68 'group' => 'users',
69 'stat' => 'sites:1:user',
70 'method' => 'POST',
71 'path' => '/sites/%s/users/%d',
72 'path_labels' => array(
73 '$site' => '(int|string) The site ID or domain.',
74 '$user_id' => '(int) The user\'s ID.',
75 ),
76 'request_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
77 'response_format' => WPCOM_JSON_API_Site_User_Endpoint::$user_format,
78 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/30434183/user/23',
79 'example_request_data' => array(
80 'headers' => array(
81 'authorization' => 'Bearer YOUR_API_TOKEN',
82 ),
83 'body' => array(
84 'roles' => array(
85 array(
86 'administrator',
87 ),
88 ),
89 'first_name' => 'Rocco',
90 'last_name' => 'Tripaldi',
91 ),
92 ),
93 'example_response' => '{
94 "ID": 18342963,
95 "login": "binarysmash",
96 "email": false,
97 "name": "binarysmash",
98 "URL": "http:\/\/binarysmash.wordpress.com",
99 "avatar_URL": "http:\/\/0.gravatar.com\/avatar\/a178ebb1731d432338e6bb0158720fcc?s=96&d=identicon&r=G",
100 "profile_URL": "http:\/\/gravatar.com\/binarysmash",
101 "roles": [ "administrator" ]
102 }',
103 )
104 );
105
106 /**
107 * Site user endpoint class.
108 *
109 * /sites/%s/users/%d -> $blog_id, $user_id
110 */
111 class WPCOM_JSON_API_Site_User_Endpoint extends WPCOM_JSON_API_Endpoint {
112
113 /**
114 * User format.
115 *
116 * @var array
117 */
118 public static $user_format = array(
119 'ID' => '(int) The ID of the user',
120 'login' => '(string) The login username of the user',
121 'email' => '(string) The email of the user',
122 'name' => '(string) The name to display for the user',
123 'first_name' => '(string) The first name of the user',
124 'last_name' => '(string) The last name of the user',
125 'nice_name' => '(string) The nice_name to display for the user',
126 'URL' => '(string) The primary blog of the user',
127 'avatar_URL' => '(url) Gravatar image URL',
128 'profile_URL' => '(url) Gravatar Profile URL',
129 'site_ID' => '(int) ID of the user\'s primary blog',
130 'roles' => '(array|string) The role or roles of the user',
131 );
132
133 /**
134 * API Callback.
135 *
136 * @param string $path - the path.
137 * @param int $blog_id - the blog ID.
138 * @param int $user_id - the user ID.
139 *
140 * @return array|WP_Error
141 */
142 public function callback( $path = '', $blog_id = 0, $user_id = 0 ) {
143 $blog_id = $this->api->switch_to_blog_and_validate_user( $this->api->get_blog_id( $blog_id ) );
144 if ( is_wp_error( $blog_id ) ) {
145 return $blog_id;
146 }
147 // @phan-suppress-next-line PhanDeprecatedFunction -- @todo Switch to current_user_can_for_site when we drop support for WP 6.6.
148 if ( ! current_user_can_for_blog( $blog_id, 'list_users' ) ) {
149 return new WP_Error( 'unauthorized', 'User cannot view users for specified site', 403 );
150 }
151
152 // Get the user by ID or login
153 $get_by = str_contains( $path, '/users/login:' ) ? 'login' : 'id';
154 $user = get_user_by( $get_by, $user_id );
155
156 if ( ! $user ) {
157 return new WP_Error( 'unknown_user', 'Unknown user', 404 );
158 }
159
160 if ( ! is_user_member_of_blog( $user->ID, $blog_id ) ) {
161 return new WP_Error( 'unknown_user_for_site', 'Unknown user for site', 404 );
162 }
163
164 if ( 'GET' === $this->api->method ) {
165 return $this->get_user( $user->ID );
166 } elseif ( 'POST' === $this->api->method ) {
167 // @phan-suppress-next-line PhanDeprecatedFunction -- @todo Switch to current_user_can_for_site when we drop support for WP 6.6.
168 if ( ! current_user_can_for_blog( $blog_id, 'promote_users' ) ) {
169 return new WP_Error( 'unauthorized_no_promote_cap', 'User cannot promote users for specified site', 403 );
170 }
171 return $this->update_user( $user_id, $blog_id );
172 } else {
173 return new WP_Error( 'bad_request', 'An unsupported request method was used.' );
174 }
175 }
176
177 /**
178 * Get the user.
179 *
180 * @param int $user_id - the user ID.
181 *
182 * @return object
183 */
184 public function get_user( $user_id ) {
185 $the_user = $this->get_author( $user_id, true );
186 if ( $the_user && ! is_wp_error( $the_user ) ) {
187 $userdata = get_userdata( $user_id );
188 $the_user->roles = ! is_wp_error( $userdata ) ? array_values( $userdata->roles ) : array();
189 if ( is_multisite() ) {
190 $the_user->is_super_admin = user_can( $the_user->ID, 'manage_network' );
191 }
192 }
193
194 return $the_user;
195 }
196
197 /**
198 * Updates user data.
199 *
200 * @param int $user_id - the user ID.
201 * @param int $blog_id - the blog ID.
202 *
203 * @return array|WP_Error
204 */
205 public function update_user( $user_id, $blog_id ) {
206 $user = array();
207 $input = $this->input();
208 $user['ID'] = $user_id;
209 $is_wpcom = defined( 'IS_WPCOM' ) && IS_WPCOM;
210
211 if ( get_current_user_id() === (int) $user_id && isset( $input['roles'] ) ) {
212 return new WP_Error( 'unauthorized', 'You cannot change your own role', 403 );
213 }
214
215 if ( $is_wpcom && $user_id !== get_current_user_id() && (int) $user_id === wpcom_get_blog_owner( $blog_id ) ) {
216 return new WP_Error( 'unauthorized_edit_owner', 'Current user can not edit blog owner', 403 );
217 }
218
219 if ( ! $is_wpcom ) {
220 foreach ( $input as $key => $value ) {
221 if ( ! is_array( $value ) ) {
222 $value = trim( $value );
223 }
224 $value = wp_unslash( $value );
225 switch ( $key ) {
226 case 'first_name':
227 case 'last_name':
228 $user[ $key ] = $value;
229 break;
230 case 'display_name':
231 case 'name':
232 $user['display_name'] = $value;
233 break;
234 }
235 }
236 }
237
238 if ( isset( $input['roles'] ) ) {
239 // For now, we only use the first role in the array.
240 if ( is_array( $input['roles'] ) ) {
241 $user['role'] = $input['roles'][0];
242 } elseif ( is_string( $input['roles'] ) ) {
243 $user['role'] = $input['roles'];
244 } else {
245 return new WP_Error( 'invalid_input', __( 'The roles property must be a string or an array.', 'jetpack' ), 400 );
246 }
247
248 $editable_roles = array_keys( get_editable_roles() );
249 if ( ! in_array( $user['role'], $editable_roles, true ) ) {
250 return new WP_Error(
251 'invalid_input',
252 sprintf(
253 /* Translators: placeholder is an invalid role name */
254 esc_html__( '%s is not a valid role.', 'jetpack' ),
255 $editable_roles
256 ),
257 400
258 );
259 }
260 }
261
262 $result = wp_update_user( $user );
263 if ( is_wp_error( $result ) ) {
264 return $result;
265 }
266 return $this->get_user( $user_id );
267 }
268 }
269