PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 14.7.1
Jetpack – WP Security, Backup, Speed, & Growth v14.7.1
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / json-endpoints / class.wpcom-json-api-update-user-endpoint.php
jetpack / json-endpoints Last commit date
jetpack 1 year ago class.wpcom-json-api-add-widget-endpoint.php 2 years ago class.wpcom-json-api-autosave-post-v1-1-endpoint.php 5 years ago class.wpcom-json-api-bulk-delete-post-endpoint.php 4 years ago class.wpcom-json-api-bulk-restore-post-endpoint.php 2 years ago class.wpcom-json-api-bulk-update-comments-endpoint.php 3 years ago class.wpcom-json-api-comment-endpoint.php 1 year ago class.wpcom-json-api-delete-media-endpoint.php 4 years ago class.wpcom-json-api-delete-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-edit-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-autosave-v1-1-endpoint.php 5 years ago class.wpcom-json-api-get-comment-counts-endpoint.php 1 year ago class.wpcom-json-api-get-comment-endpoint.php 4 years ago class.wpcom-json-api-get-comment-history-endpoint.php 1 year ago class.wpcom-json-api-get-comments-tree-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-comments-tree-v1-2-endpoint.php 4 years ago class.wpcom-json-api-get-customcss.php 2 years ago class.wpcom-json-api-get-media-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-1-endpoint.php 4 years ago class.wpcom-json-api-get-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-get-post-counts-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-post-endpoint.php 2 years ago class.wpcom-json-api-get-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-get-site-endpoint.php 1 year ago class.wpcom-json-api-get-site-v1-2-endpoint.php 1 year ago class.wpcom-json-api-get-taxonomies-endpoint.php 2 years ago class.wpcom-json-api-get-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-get-term-endpoint.php 4 years ago class.wpcom-json-api-list-comments-endpoint.php 1 year ago class.wpcom-json-api-list-dropdown-pages-endpoint.php 3 years ago class.wpcom-json-api-list-embeds-endpoint.php 4 years ago class.wpcom-json-api-list-media-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-list-media-v1-2-endpoint.php 2 years ago class.wpcom-json-api-list-post-type-taxonomies-endpoint.php 4 years ago class.wpcom-json-api-list-post-types-endpoint.php 3 years ago class.wpcom-json-api-list-posts-endpoint.php 1 year ago class.wpcom-json-api-list-posts-v1-1-endpoint.php 1 year ago class.wpcom-json-api-list-posts-v1-2-endpoint.php 1 year ago class.wpcom-json-api-list-roles-endpoint.php 1 year ago class.wpcom-json-api-list-shortcodes-endpoint.php 4 years ago class.wpcom-json-api-list-terms-endpoint.php 2 years ago class.wpcom-json-api-list-users-endpoint.php 1 year ago class.wpcom-json-api-menus-v1-1-endpoint.php 1 year ago class.wpcom-json-api-post-endpoint.php 2 years ago class.wpcom-json-api-post-v1-1-endpoint.php 2 years ago class.wpcom-json-api-render-embed-endpoint.php 2 years ago class.wpcom-json-api-render-embed-reversal-endpoint.php 2 years ago class.wpcom-json-api-render-endpoint.php 3 years ago class.wpcom-json-api-render-shortcode-endpoint.php 3 years ago class.wpcom-json-api-sharing-buttons-endpoint.php 2 years ago class.wpcom-json-api-site-settings-endpoint.php 1 year ago class.wpcom-json-api-site-settings-v1-2-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-3-endpoint.php 2 years ago class.wpcom-json-api-site-settings-v1-4-endpoint.php 1 year ago class.wpcom-json-api-site-user-endpoint.php 1 year ago class.wpcom-json-api-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-comment-endpoint.php 2 years ago class.wpcom-json-api-update-customcss.php 2 years ago class.wpcom-json-api-update-media-endpoint.php 4 years ago class.wpcom-json-api-update-media-v1-1-endpoint.php 2 years ago class.wpcom-json-api-update-post-endpoint.php 1 year ago class.wpcom-json-api-update-post-v1-1-endpoint.php 1 year ago class.wpcom-json-api-update-post-v1-2-endpoint.php 1 year ago class.wpcom-json-api-update-site-homepage-endpoint.php 4 years ago class.wpcom-json-api-update-site-logo-endpoint.php 2 years ago class.wpcom-json-api-update-taxonomy-endpoint.php 4 years ago class.wpcom-json-api-update-term-endpoint.php 4 years ago class.wpcom-json-api-update-user-endpoint.php 1 year ago class.wpcom-json-api-upload-media-endpoint.php 3 years ago class.wpcom-json-api-upload-media-v1-1-endpoint.php 1 year ago
class.wpcom-json-api-update-user-endpoint.php
197 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Update site users API endpoint.
4 *
5 * Endpoint: /sites/%s/users/%d/delete
6 */
7
8 new WPCOM_JSON_API_Update_User_Endpoint(
9 array(
10 'description' => 'Deletes or removes a user of a site.',
11 'group' => 'users',
12 'stat' => 'users:delete',
13
14 'method' => 'POST',
15 'path' => '/sites/%s/users/%d/delete',
16 'path_labels' => array(
17 '$site' => '(int|string) The site ID or domain.',
18 '$user_ID' => '(int) The user\'s ID',
19 ),
20
21 'request_format' => array(
22 'reassign' => '(int) An optional id of a user to reassign posts to.',
23 ),
24
25 'response_format' => array(
26 'success' => '(bool) Was the deletion of user successful?',
27 ),
28
29 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/82974409/users/1/delete',
30 'example_request_data' => array(
31 'headers' => array(
32 'authorization' => 'Bearer YOUR_API_TOKEN',
33 ),
34 ),
35
36 'example_response' => '
37 {
38 "success": true
39 }',
40 )
41 );
42
43 /**
44 * Update site users API class.
45 */
46 class WPCOM_JSON_API_Update_User_Endpoint extends WPCOM_JSON_API_Endpoint {
47 /**
48 * Update site users API callback.
49 *
50 * @param string $path API path.
51 * @param int $blog_id Blog ID.
52 * @param int $user_id User ID.
53 */
54 public function callback( $path = '', $blog_id = 0, $user_id = 0 ) {
55 $blog_id = $this->api->switch_to_blog_and_validate_user( $this->api->get_blog_id( $blog_id ) );
56 if ( is_wp_error( $blog_id ) ) {
57 return $blog_id;
58 }
59
60 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
61 if ( (int) wpcom_get_blog_owner( $blog_id ) === (int) $user_id ) {
62 return new WP_Error( 'forbidden', 'A site owner can not be removed through this endpoint.', 403 );
63 }
64 }
65
66 if ( $this->api->ends_with( $path, '/delete' ) ) {
67 return $this->delete_or_remove_user( $user_id );
68 }
69
70 return false;
71 }
72
73 /**
74 * Checks if a user exists by checking to see if a WP_User object exists for a user ID.
75 *
76 * @param int $user_id User ID.
77 * @return bool
78 */
79 public function user_exists( $user_id ) {
80 $user = get_user_by( 'id', $user_id );
81
82 return false !== $user && is_a( $user, 'WP_User' );
83 }
84
85 /**
86 * Return the domain name of a subscription.
87 *
88 * @param Store_Subscription $subscription Subscription object.
89 * @return string
90 */
91 protected function get_subscription_domain_name( $subscription ) {
92 return $subscription->meta;
93 }
94
95 /**
96 * Get a list of the domains owned by the given user.
97 *
98 * @param int $user_id User ID.
99 * @return array
100 */
101 protected function domain_subscriptions_for_site_owned_by_user( $user_id ) {
102 $subscriptions = WPCOM_Store::get_subscriptions( get_current_blog_id(), $user_id, domains::get_domain_products() );
103
104 $domains = array_unique( array_map( array( $this, 'get_subscription_domain_name' ), $subscriptions ) );
105
106 return array_values( $domains );
107 }
108
109 /**
110 * Validates user input and then decides whether to remove or delete a user.
111 *
112 * @param int $user_id User ID.
113 * @return array|WP_Error
114 */
115 public function delete_or_remove_user( $user_id ) {
116 if ( 0 === (int) $user_id ) {
117 return new WP_Error( 'invalid_input', 'A valid user ID must be specified.', 400 );
118 }
119
120 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
121 $domains = $this->domain_subscriptions_for_site_owned_by_user( $user_id );
122 if ( ! empty( $domains ) ) {
123 $error = new WP_Error( 'user_owns_domain_subscription', implode( ', ', $domains ) );
124 $error->add_data( $domains, 'additional_data' );
125 return $error;
126 }
127
128 $active_user_subscriptions = WPCOM_Store::get_user_subscriptions( $user_id, get_current_blog_id() );
129 if ( ! empty( $active_user_subscriptions ) ) {
130 $product_names = array_values( wp_list_pluck( $active_user_subscriptions, 'product_name' ) );
131 $error = new WP_Error( 'user_has_active_subscriptions', 'User has active subscriptions' );
132 $error->add_data( $product_names, 'additional_data' );
133 return $error;
134 }
135 }
136
137 if ( ! $this->user_exists( $user_id ) ) {
138 return new WP_Error( 'invalid_input', 'A user does not exist with that ID.', 400 );
139 }
140
141 return is_multisite() ? $this->remove_user( $user_id ) : $this->delete_user( $user_id );
142 }
143
144 /**
145 * Removes a user from the current site.
146 *
147 * @param int $user_id User ID.
148 * @return array|WP_Error
149 */
150 public function remove_user( $user_id ) {
151 // Skip the check if the user is removing themselves.
152 if ( ! current_user_can( 'remove_users' ) && get_current_user_id() !== (int) $user_id ) {
153 return new WP_Error( 'unauthorized', 'User cannot remove users for specified site.', 403 );
154 }
155
156 if ( ! is_user_member_of_blog( $user_id, get_current_blog_id() ) ) {
157 return new WP_Error( 'invalid_input', 'User is not a member of the specified site.', 400 );
158 }
159
160 return array(
161 'success' => remove_user_from_blog( $user_id, get_current_blog_id() ),
162 );
163 }
164
165 /**
166 * Deletes a user and optionally reassigns posts to another user.
167 *
168 * @param int $user_id User ID.
169 * @return array|WP_Error
170 */
171 public function delete_user( $user_id ) {
172 // Skip the check if the user is deleting themselves.
173 if ( ! current_user_can( 'delete_users' ) && get_current_user_id() !== (int) $user_id ) {
174 return new WP_Error( 'unauthorized', 'User cannot delete users for specified site.', 403 );
175 }
176
177 $input = (array) $this->input();
178 $reassign = isset( $input['reassign'] ) ? (int) $input['reassign'] : null;
179
180 if ( $reassign !== null ) {
181 if ( (int) $user_id === $reassign ) {
182 return new WP_Error( 'invalid_input', 'Can not reassign posts to user being deleted.', 400 );
183 }
184
185 if ( ! $this->user_exists( $reassign ) ) {
186 return new WP_Error( 'invalid_input', 'User specified in reassign argument is not a member of the specified site.', 400 );
187 }
188 }
189
190 $success = $reassign !== null ? wp_delete_user( $user_id, $reassign ) : wp_delete_user( $user_id );
191
192 return array(
193 'success' => $success,
194 );
195 }
196 }
197