PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.1-beta.2
Jetpack – WP Security, Backup, Speed, & Growth v16.1-beta.2
16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / src / reprint-export / class-rest-controller.php
jetpack / src / reprint-export Last commit date
class-reprint-exporter.php 5 days ago class-rest-controller.php 5 days ago
class-rest-controller.php
122 lines
1 <?php
2 /**
3 * REST controller for the Jetpack Reprint exporter secret-rotation endpoint.
4 *
5 * Requires a Jetpack-signed request (WordPress.com public API proxy only).
6 *
7 * @package automattic/jetpack
8 */
9
10 namespace Automattic\Jetpack\Reprint_Export;
11
12 use Automattic\Jetpack\Connection\Manager;
13 use WP_REST_Controller;
14 use WP_REST_Response;
15 use WP_REST_Server;
16
17 /**
18 * Reprint exporter REST controller.
19 */
20 class REST_Controller extends WP_REST_Controller {
21
22 /**
23 * The API namespace.
24 *
25 * @var string
26 */
27 protected $namespace = 'jetpack/v4';
28
29 /**
30 * The REST base path.
31 *
32 * @var string
33 */
34 protected $rest_base = 'reprint';
35
36 /**
37 * Registers the reprint export routes.
38 */
39 public function register_routes() {
40 register_rest_route(
41 $this->namespace,
42 '/' . $this->rest_base . '/rotate-export-secret',
43 array(
44 array(
45 'methods' => WP_REST_Server::CREATABLE,
46 'callback' => array( $this, 'rotate_secret' ),
47 'permission_callback' => array( $this, 'permission_check' ),
48 ),
49 )
50 );
51
52 register_rest_route(
53 $this->namespace,
54 '/' . $this->rest_base . '/enable-export',
55 array(
56 array(
57 'methods' => WP_REST_Server::CREATABLE,
58 'callback' => array( $this, 'enable_export' ),
59 'permission_callback' => array( $this, 'permission_check' ),
60 ),
61 )
62 );
63 }
64
65 /**
66 * Opens the 60-minute export window without rotating the secret.
67 *
68 * Purpose-built enable endpoint: a client that already holds a valid
69 * secret can re-open a lapsed window without minting a new one. The
70 * route is only registered when the feature is available, so a 404
71 * here doubles as the client's "is Reprint export available?" probe.
72 *
73 * @return WP_REST_Response The unix timestamp the window was opened at.
74 */
75 public function enable_export() {
76 return new WP_REST_Response(
77 array( 'enabled_at' => Reprint_Exporter::open_export_window() ),
78 200
79 );
80 }
81
82 /**
83 * Rotates the shared secret and opens the export window.
84 *
85 * Generates a cryptographically random 64-character hex secret, stores it
86 * in a WordPress option (autoload disabled), opens the 60-minute export
87 * window, and returns the secret. The caller uses this secret to
88 * authenticate export requests via HMAC.
89 *
90 * Rotating the secret intentionally also opens the export window so the
91 * Pressable client flow is a single round trip: rotate, then immediately
92 * stream from ?reprint-api-jetpack using HMAC.
93 *
94 * @return WP_REST_Response The new secret on success, or a 500 error.
95 */
96 public function rotate_secret() {
97 $secret = bin2hex( random_bytes( 32 ) );
98
99 if ( ! update_option( Reprint_Exporter::SECRET_OPTION, $secret, false ) ) {
100 return new WP_REST_Response(
101 array( 'error' => 'Failed to persist the new secret.' ),
102 500
103 );
104 }
105
106 // Open the sliding export window so the client can stream right away.
107 Reprint_Exporter::open_export_window();
108
109 return new WP_REST_Response( array( 'secret' => $secret ), 200 );
110 }
111
112 /**
113 * Permission callback: only Jetpack-signed requests (public API proxy).
114 *
115 * @return bool
116 */
117 public function permission_check() {
118 return method_exists( Manager::class, 'verify_xml_rpc_signature' )
119 && ( new Manager() )->verify_xml_rpc_signature();
120 }
121 }
122