PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.1-beta.2
Jetpack – WP Security, Backup, Speed, & Growth v16.1-beta.2
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-publicize / src / rest-api / class-render-messages-controller.php
jetpack / jetpack_vendor / automattic / jetpack-publicize / src / rest-api Last commit date
class-base-controller.php 9 months ago class-connections-controller.php 3 weeks ago class-connections-post-field.php 4 weeks ago class-keyring-result-controller.php 2 months ago class-message-templates-placeholders-controller.php 3 months ago class-proxy-requests.php 9 months ago class-render-messages-controller.php 4 weeks ago class-scheduled-actions-controller.php 9 months ago class-services-controller.php 3 weeks ago class-share-post-controller.php 9 months ago class-share-status-controller.php 9 months ago class-social-image-generator-controller.php 9 months ago
class-render-messages-controller.php
253 lines
1 <?php
2 /**
3 * Publicize: Render Messages Controller
4 *
5 * @package automattic/jetpack-publicize
6 */
7
8 namespace Automattic\Jetpack\Publicize\REST_API;
9
10 use Automattic\Jetpack\Connection\Traits\WPCOM_REST_API_Proxy_Request;
11 use Automattic\Jetpack\Publicize\Publicize_Utils as Utils;
12 use WP_Error;
13 use WP_REST_Request;
14 use WP_REST_Server;
15
16 if ( ! defined( 'ABSPATH' ) ) {
17 exit( 0 );
18 }
19
20 /**
21 * Publicize: Render Messages Controller class.
22 *
23 * Renders Publicize message templates for a given post and a batch of
24 * connection inputs in a single request, so the block-editor preview can
25 * fetch all enabled connections' previews in one round-trip on sites with
26 * social paid features.
27 *
28 * POST takes a JSON body of `{ post_id, items: [...], post_intent: {...} }`
29 * and returns one record per input item, in input order, keyed by the
30 * client-supplied `connection_id`. Body-based POST is used instead of a GET
31 * collection so multi-connection / long-message batches don't hit
32 * infrastructure URL caps.
33 *
34 * @phan-constructor-used-for-side-effects
35 */
36 class Render_Messages_Controller extends Base_Controller {
37
38 use WPCOM_REST_API_Proxy_Request;
39
40 /**
41 * Constructor.
42 */
43 public function __construct() {
44 parent::__construct();
45
46 $this->base_api_path = 'wpcom';
47 $this->version = 'v2';
48
49 $this->namespace = "{$this->base_api_path}/{$this->version}";
50 $this->rest_base = 'publicize/render-messages';
51
52 $this->allow_requests_as_blog = true;
53
54 add_action( 'rest_api_init', array( $this, 'register_routes' ) );
55 }
56
57 /**
58 * Register the routes.
59 */
60 public function register_routes() {
61 register_rest_route(
62 $this->namespace,
63 '/' . $this->rest_base,
64 array(
65 'methods' => WP_REST_Server::CREATABLE,
66 'callback' => array( $this, 'render_messages' ),
67 'permission_callback' => array( $this, 'permissions_check' ),
68 'private_site_security_settings' => array(
69 'allow_blog_token_access' => true,
70 ),
71 'args' => array(
72 'post_id' => array(
73 'description' => __( 'The ID of the post to render the messages for.', 'jetpack-publicize-pkg' ),
74 'type' => 'integer',
75 'required' => true,
76 ),
77 'items' => array(
78 'description' => __( 'List of per-connection render inputs.', 'jetpack-publicize-pkg' ),
79 'type' => 'array',
80 'required' => true,
81 'minItems' => 1,
82 'items' => array(
83 'type' => 'object',
84 'additionalProperties' => false,
85 'required' => array( 'connection_id' ),
86 'properties' => array(
87 'connection_id' => array(
88 'description' => __( 'Publicize connection ID — used to dispatch the renderer and resolve the per-connection template.', 'jetpack-publicize-pkg' ),
89 'type' => 'string',
90 ),
91 'message' => array(
92 'description' => __( 'Optional message override. Empty walks the per-connection / site / network-default chain.', 'jetpack-publicize-pkg' ),
93 'type' => 'string',
94 'default' => '',
95 ),
96 'is_social_post' => array(
97 'description' => __( 'Whether the post will be shared as a social post (media attached) rather than a link share.', 'jetpack-publicize-pkg' ),
98 'type' => 'boolean',
99 'default' => false,
100 ),
101 ),
102 ),
103 ),
104 'post_intent' => array(
105 'description' => __( 'Edited post fields to use when rendering unsaved preview changes.', 'jetpack-publicize-pkg' ),
106 'type' => 'object',
107 'default' => array(),
108 'additionalProperties' => false,
109 'properties' => array(
110 'title' => array(
111 'description' => __( 'Edited post title.', 'jetpack-publicize-pkg' ),
112 'type' => 'string',
113 'default' => '',
114 ),
115 'excerpt' => array(
116 'description' => __( 'Edited post excerpt.', 'jetpack-publicize-pkg' ),
117 'type' => 'string',
118 'default' => '',
119 ),
120 'content' => array(
121 'description' => __( 'Edited post content.', 'jetpack-publicize-pkg' ),
122 'type' => 'string',
123 'default' => '',
124 ),
125 ),
126 ),
127 ),
128 'schema' => array( $this, 'get_public_item_schema' ),
129 )
130 );
131 }
132
133 /**
134 * Retrieves the JSON schema for a single rendered-message item.
135 *
136 * @return array Schema data.
137 */
138 public function get_item_schema() {
139 return array(
140 '$schema' => 'http://json-schema.org/draft-04/schema#',
141 'title' => 'publicize-render-messages-item',
142 'type' => 'object',
143 'properties' => array(
144 'connection_id' => array(
145 'description' => __( 'Connection identifier echoed back from the request.', 'jetpack-publicize-pkg' ),
146 'type' => 'string',
147 'readonly' => true,
148 'context' => array( 'view', 'edit' ),
149 ),
150 'rendered_message' => array(
151 'description' => __( 'The rendered message for this item. Absent when the item failed to render.', 'jetpack-publicize-pkg' ),
152 'type' => 'string',
153 'readonly' => true,
154 'context' => array( 'view', 'edit' ),
155 ),
156 'error' => array(
157 'description' => __( 'Per-item error. Present only when this item failed to render.', 'jetpack-publicize-pkg' ),
158 'type' => 'object',
159 'readonly' => true,
160 'context' => array( 'view', 'edit' ),
161 'properties' => array(
162 'code' => array( 'type' => 'string' ),
163 'message' => array( 'type' => 'string' ),
164 ),
165 ),
166 ),
167 );
168 }
169
170 /**
171 * Permission check.
172 *
173 * Preserves the blog-token proxy path via Base_Controller::publicize_permissions_check()
174 * (which returns true for authorized blog requests when allow_requests_as_blog is set),
175 * and enforces post-level `edit_post` capability for regular user requests.
176 *
177 * @param WP_REST_Request $request Full details about the request.
178 * @return true|WP_Error True if authorized, WP_Error otherwise.
179 */
180 public function permissions_check( $request ) {
181 $base_check = $this->publicize_permissions_check();
182
183 if ( is_wp_error( $base_check ) ) {
184 return $base_check;
185 }
186
187 // Blog-token proxy requests don't have a user context; the publicize check
188 // above already returned true for those.
189 if ( self::is_authorized_blog_request() ) {
190 return true;
191 }
192
193 $post_id = (int) $request->get_param( 'post_id' );
194
195 if ( ! $post_id || ! current_user_can( 'edit_post', $post_id ) ) {
196 return new WP_Error(
197 'invalid_user_permission_publicize',
198 __( 'Sorry, you are not allowed to access Jetpack Social data for this post.', 'jetpack-publicize-pkg' ),
199 array( 'status' => rest_authorization_required_code() )
200 );
201 }
202
203 return true;
204 }
205
206 /**
207 * Render the messages for the given post and items.
208 *
209 * Top-level errors (feature off, post not found) short-circuit the whole batch.
210 * Per-item failures are returned as `{ id, error: { code, message } }` so a
211 * single bad item never fails the batch.
212 *
213 * @param WP_REST_Request $request The request object.
214 * @return mixed The rendered items array, or a WP_Error for top-level failures.
215 */
216 public function render_messages( $request ) {
217 if ( Utils::is_wpcom() ) {
218 if ( ! wpcom_site_has_feature( \WPCOM_Features::SOCIAL_ENHANCED_PUBLISHING ) ) {
219 return new WP_Error(
220 'feature_not_enabled',
221 __( 'Publicize message templates are not enabled for this site.', 'jetpack-publicize-pkg' ),
222 array( 'status' => 403 )
223 );
224 }
225
226 $post_id = (int) $request->get_param( 'post_id' );
227 $items = (array) $request->get_param( 'items' );
228 $intent = (array) $request->get_param( 'post_intent' );
229
230 $post = get_post( $post_id );
231
232 if ( ! $post ) {
233 return new WP_Error(
234 'post_not_found',
235 __( 'Post not found.', 'jetpack-publicize-pkg' ),
236 array( 'status' => 404 )
237 );
238 }
239
240 require_lib( 'publicize/util/message-templates' );
241
242 return rest_ensure_response(
243 \Publicize\render_messages( $post, $items, $intent )
244 );
245 }
246
247 // Self-hosted Jetpack: proxy the request body to WPCOM.
248 return rest_ensure_response(
249 $this->proxy_request_to_wpcom_as_blog( $request )
250 );
251 }
252 }
253