PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.2
Jetpack – WP Security, Backup, Speed, & Growth v16.2
16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 All 502 releases
jetpack / extensions / blocks / goodreads / render.php

render.php in Jetpack – WP Security, Backup, Speed, & Growth 16.2, at extensions/blocks/goodreads/render.php

128 lines 3.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Goodreads block render implementation.
4 *
5 * Loaded lazily from goodreads.php only when the block is rendered, to keep
6 * the render body out of the eager front-end PHP/opcache footprint.
7 *
8 * @package automattic/jetpack
9 */
10
11 namespace Automattic\Jetpack\Extensions\Goodreads;
12
13 use Automattic\Jetpack\Blocks;
14 use Jetpack_Gutenberg;
15
16 if ( ! defined( 'ABSPATH' ) ) {
17 exit( 0 );
18 }
19
20 /**
21 * Validates a Goodreads widget script URL.
22 *
23 * Accepts only URLs shaped like those generated by createGoodreadsEmbedLink()
24 * in utils.js — keep the two in sync when either side changes.
25 *
26 * @param mixed $url URL to validate.
27 *
28 * @return string Canonical URL rebuilt from the validated components, or an empty string when the URL is not allowed.
29 */
30 function get_validated_script_url( $url ) {
31 if ( ! is_string( $url ) || str_contains( $url, '\\' ) ) {
32 return '';
33 }
34
35 $parsed = wp_parse_url( esc_url_raw( $url, array( 'https' ) ) );
36 $encoded_path = is_array( $parsed ) ? $parsed['path'] ?? '' : '';
37 $path = rawurldecode( $encoded_path );
38 $has_encoded_separator = 1 === preg_match( '~%(?:2f|5c)~i', $encoded_path );
39
40 if (
41 ! is_array( $parsed )
42 || empty( $parsed['scheme'] )
43 || 'https' !== strtolower( $parsed['scheme'] )
44 || empty( $parsed['host'] )
45 || 'www.goodreads.com' !== strtolower( $parsed['host'] )
46 || isset( $parsed['user'] )
47 || isset( $parsed['pass'] )
48 || isset( $parsed['port'] )
49 || isset( $parsed['fragment'] )
50 || empty( $parsed['query'] )
51 || $has_encoded_separator
52 || str_contains( $path, '\\' )
53 ) {
54 return '';
55 }
56
57 // Only the documented widget endpoints: a numeric Goodreads ID and a non-empty title.
58 // Goodreads treats literal slashes as part of the title, so allow them while
59 // rejecting dot segments that a URL parser could normalize outside this route.
60 if ( 1 !== preg_match( '~^/review/(custom|grid)_widget/[0-9]+\.(.+)$~', $path, $match ) ) {
61 return '';
62 }
63
64 foreach ( explode( '/', $match[2] ) as $title_segment ) {
65 if ( '.' === $title_segment || '..' === $title_segment ) {
66 return '';
67 }
68 }
69
70 $allowed_query_args = 'grid' === $match[1]
71 ? array( 'cover_size', 'num_books', 'order', 'shelf', 'sort', 'widget_id' )
72 : array( 'num_books', 'order', 'shelf', 'show_author', 'show_cover', 'show_rating', 'show_review', 'show_tags', 'show_title', 'sort', 'widget_id' );
73 $query_args = array();
74
75 wp_parse_str( $parsed['query'], $query_args );
76
77 if ( array_diff( array_keys( $query_args ), $allowed_query_args ) ) {
78 return '';
79 }
80
81 foreach ( $query_args as $value ) {
82 if ( is_array( $value ) ) {
83 return '';
84 }
85 }
86
87 return 'https://www.goodreads.com' . $parsed['path'] . '?' . $parsed['query'];
88 }
89
90 /**
91 * Dynamic rendering of the block.
92 *
93 * @param array $attr Array containing the Goodreads block attributes.
94 *
95 * @return string
96 */
97 function render_implementation( $attr ) {
98 Jetpack_Gutenberg::load_assets_as_required( __DIR__ );
99
100 if ( isset( $attr['id'] ) ) {
101 if ( isset( $attr['link'] ) ) {
102 $script_url = get_validated_script_url( $attr['link'] );
103
104 if ( '' !== $script_url ) {
105 wp_enqueue_script(
106 'jetpack-goodreads-' . esc_attr( $attr['id'] ),
107 $script_url,
108 array(),
109 JETPACK__VERSION,
110 true
111 );
112 }
113 }
114
115 $id = esc_attr( $attr['id'] );
116 } else {
117 $id = '';
118 }
119
120 $classes = esc_attr( Blocks::classes( Blocks::get_block_feature( __DIR__ ), $attr ) );
121
122 return sprintf(
123 '<div id="%1$s" class="%2$s"></div>',
124 $id,
125 $classes
126 );
127 }
128