PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.2
Jetpack – WP Security, Backup, Speed, & Growth v16.2
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
jetpack / jetpack_vendor / automattic / jetpack-videopress / src / class-ajax.php

class-ajax.php in Jetpack – WP Security, Backup, Speed, & Growth 16.2, at jetpack_vendor/automattic/jetpack-videopress/src/class-ajax.php

310 lines 11.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2
3 namespace Automattic\Jetpack\VideoPress;
4
5 use Automattic\Jetpack\Connection\Client;
6
7 /**
8 * VideoPress AJAX action handlers and utilities.
9 *
10 * Note: this is also being used on WordPress.com.
11 * Use IS_WPCOM checks for functionality that is specific to WPCOM/Jetpack.
12 */
13 class AJAX {
14
15 /**
16 * Singleton AJAX instance.
17 *
18 * @var AJAX
19 **/
20 private static $instance = null;
21
22 /**
23 * Private AJAX constructor.
24 *
25 * Use the AJAX::init() method to get an instance.
26 */
27 private function __construct() {
28 add_action( 'wp_ajax_videopress-get-upload-token', array( $this, 'wp_ajax_videopress_get_upload_token' ) );
29 add_action( 'wp_ajax_videopress-get-upload-jwt', array( $this, 'wp_ajax_videopress_get_upload_jwt' ) );
30 add_action( 'wp_ajax_nopriv_videopress-get-playback-jwt', array( $this, 'wp_ajax_videopress_get_playback_jwt' ) );
31 add_action( 'wp_ajax_videopress-get-playback-jwt', array( $this, 'wp_ajax_videopress_get_playback_jwt' ) );
32
33 add_action(
34 'wp_ajax_videopress-update-transcoding-status',
35 array(
36 $this,
37 'wp_ajax_update_transcoding_status',
38 ),
39 -1
40 );
41 }
42
43 /**
44 * Initialize the AJAX and get back a singleton instance.
45 *
46 * @return AJAX
47 */
48 public static function init() {
49 if ( self::$instance === null ) {
50 self::$instance = new AJAX();
51 }
52
53 return self::$instance;
54 }
55
56 /**
57 * Validate a guid.
58 *
59 * @param string $guid The guid to validate.
60 *
61 * @return bool
62 **/
63 private function is_valid_guid( $guid ) {
64 if ( empty( $guid ) ) {
65 return false;
66 }
67
68 preg_match( '/^[a-z0-9]{8}$/i', $guid, $matches );
69
70 if ( empty( $matches ) ) {
71 return false;
72 }
73
74 return true;
75 }
76
77 /**
78 * Ajax method that is used by the VideoPress player to get a token to play a video.
79 *
80 * This is used for both logged in and logged out users.
81 *
82 * @return never
83 */
84 public function wp_ajax_videopress_get_playback_jwt() {
85 $guid = filter_input( INPUT_POST, 'guid' );
86 $embedded_post_id = filter_input( INPUT_POST, 'post_id', FILTER_VALIDATE_INT );
87 $selected_plan_id = filter_input( INPUT_POST, 'subscription_plan_id' );
88
89 if ( empty( $embedded_post_id ) ) {
90 $embedded_post_id = 0;
91 }
92
93 if ( empty( $guid ) || ! $this->is_valid_guid( $guid ) ) {
94 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
95 wp_send_json_error( array( 'message' => __( 'need a guid', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
96 }
97
98 if ( ! $this->is_current_user_authed_for_video( $guid, $embedded_post_id, $selected_plan_id ) ) {
99 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
100 wp_send_json_error( array( 'message' => __( 'You cannot view this video.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
101 }
102
103 $token = $this->request_jwt_from_wpcom( $guid );
104
105 if ( empty( $token ) ) {
106 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
107 wp_send_json_error( array( 'message' => __( 'Could not obtain a VideoPress playback JWT. Please try again later. (empty upload token)', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
108 }
109
110 if ( is_wp_error( $token ) ) {
111 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
112 wp_send_json_error( array( 'message' => __( 'Could not obtain a VideoPress upload JWT. Please try again later.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
113 }
114
115 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
116 wp_send_json_success( array( 'jwt' => $token ), null, JSON_UNESCAPED_SLASHES );
117 }
118
119 /**
120 * Determines if the current user can view the provided video. Only ever gets fired if site-wide private videos are enabled.
121 *
122 * Filterable for 3rd party plugins.
123 *
124 * @param string $guid The video id being checked.
125 * @param int $embedded_post_id The post id the video is embedded in or 0.
126 * @param int $selected_plan_id The plan id the earn block this video is embedded in has.
127 */
128 private function is_current_user_authed_for_video( $guid, $embedded_post_id, $selected_plan_id = 0 ) {
129 return Access_Control::instance()->is_current_user_authed_for_video( $guid, $embedded_post_id, $selected_plan_id );
130 }
131
132 /**
133 * Requests JWT from wpcom.
134 *
135 * @param string $guid The video id being checked.
136 */
137 private function request_jwt_from_wpcom( $guid ) {
138 if ( defined( 'IS_WPCOM' ) && IS_WPCOM && function_exists( 'video_wpcom_get_playback_jwt_for_guid' ) ) {
139 $jwt_data = video_wpcom_get_playback_jwt_for_guid( $guid );
140 if ( is_wp_error( $jwt_data ) ) {
141 return false;
142 }
143 return $jwt_data->metadata_token;
144 }
145
146 $video_blog_id = $this->get_videopress_blog_id();
147 $args = array(
148 'method' => 'POST',
149 );
150
151 $endpoint = "sites/{$video_blog_id}/media/videopress-playback-jwt/{$guid}";
152 $result = Client::wpcom_json_api_request_as_blog( $endpoint, 'v2', $args, null, 'wpcom' );
153 if ( is_wp_error( $result ) ) {
154 return $result;
155 }
156
157 $response = json_decode( $result['body'], true );
158
159 if ( empty( $response['metadata_token'] ) ) {
160 return false;
161 }
162
163 return $response['metadata_token'];
164 }
165
166 /**
167 * Ajax method that is used by the VideoPress uploader to get a token to upload a file to the wpcom api.
168 *
169 * @return never
170 */
171 public function wp_ajax_videopress_get_upload_jwt() {
172 if ( ! current_user_can( 'upload_files' ) ) {
173 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
174 wp_send_json_error( array( 'message' => __( 'You do not have permission to upload files.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
175 }
176
177 $video_blog_id = $this->get_videopress_blog_id();
178 $args = array(
179 'method' => 'POST',
180 );
181
182 $endpoint = "sites/{$video_blog_id}/media/videopress-upload-jwt";
183 $result = Client::wpcom_json_api_request_as_blog( $endpoint, 'v2', $args, null, 'wpcom' );
184 if ( is_wp_error( $result ) ) {
185 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
186 wp_send_json_error( array( 'message' => __( 'Could not obtain a VideoPress upload JWT. Please try again later.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
187 }
188
189 $response = json_decode( $result['body'], true );
190
191 if ( empty( $response['upload_token'] ) ) {
192 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
193 wp_send_json_error( array( 'message' => __( 'Could not obtain a VideoPress upload JWT. Please try again later. (empty upload token)', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
194 }
195
196 $response['upload_action_url'] = videopress_make_resumable_upload_path( $video_blog_id );
197
198 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
199 wp_send_json_success( $response, null, JSON_UNESCAPED_SLASHES );
200 }
201
202 /**
203 * Ajax method that is used by the VideoPress uploader to get a token to upload a file to the wpcom api.
204 *
205 * @return never
206 */
207 public function wp_ajax_videopress_get_upload_token() {
208 if ( ! current_user_can( 'upload_files' ) ) {
209 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
210 wp_send_json_error( array( 'message' => __( 'You do not have permission to upload files.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
211 }
212
213 $video_blog_id = $this->get_videopress_blog_id();
214
215 // On WordPress.com the classic `sites/{id}/media/token` (rest/v1.1) endpoint
216 // isn't reachable in-process (WPCOM_API_Direct only dispatches WP-REST routes),
217 // so mint the token via VideoPressToken, which has its own IS_WPCOM branch that
218 // mints locally. `get_videopress_blog_id()` is the current blog on Simple, matching
219 // the minted token. The self-hosted remote path below is left unchanged.
220 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
221 try {
222 $upload_token = VideoPressToken::videopress_onetime_upload_token();
223 } catch ( Upload_Exception $e ) {
224 // Explicit 200: identical to the null default (admin-ajax errors
225 // ride the success:false envelope), but typed as the phpdoc wants.
226 wp_send_json_error( array( 'message' => $e->getMessage() ), 200, JSON_UNESCAPED_SLASHES );
227 }
228
229 // `upload_action_url` (from `videopress_make_media_upload_path()`) is omitted:
230 // that helper isn't loaded in the Simple admin-ajax context, and only the
231 // legacy upload-form flow reads it — the track/poster consumers use the token
232 // and blog id, not the URL.
233 wp_send_json_success(
234 array(
235 'upload_token' => $upload_token,
236 'upload_blog_id' => $video_blog_id,
237 ),
238 200,
239 JSON_UNESCAPED_SLASHES
240 );
241 }
242
243 $args = array(
244 'method' => 'POST',
245 );
246
247 $endpoint = "sites/{$video_blog_id}/media/token";
248 $result = Client::wpcom_json_api_request_as_blog( $endpoint, Client::WPCOM_JSON_API_VERSION, $args );
249
250 if ( is_wp_error( $result ) ) {
251 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
252 wp_send_json_error( array( 'message' => __( 'Could not obtain a VideoPress upload token. Please try again later.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
253 }
254
255 $response = json_decode( $result['body'], true );
256
257 if ( empty( $response['upload_token'] ) ) {
258 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
259 wp_send_json_error( array( 'message' => __( 'Could not obtain a VideoPress upload token. Please try again later.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
260 }
261
262 $response['upload_action_url'] = videopress_make_media_upload_path( $video_blog_id );
263
264 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
265 wp_send_json_success( $response, null, JSON_UNESCAPED_SLASHES );
266 }
267
268 /**
269 * Ajax action to update the video transcoding status from the WPCOM API.
270 *
271 * @return never
272 */
273 public function wp_ajax_update_transcoding_status() {
274 if ( ! isset( $_POST['post_id'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- Informational AJAX response.
275 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
276 wp_send_json_error( array( 'message' => __( 'A valid post_id is required.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
277 }
278
279 $post_id = (int) $_POST['post_id']; // phpcs:ignore WordPress.Security.NonceVerification.Missing
280
281 if ( ! videopress_update_meta_data( $post_id ) ) {
282 // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
283 wp_send_json_error( array( 'message' => __( 'That post does not have a VideoPress video associated to it.', 'jetpack-videopress-pkg' ) ), null, JSON_UNESCAPED_SLASHES );
284 }
285
286 wp_send_json_success(
287 array(
288 'message' => __( 'Status updated', 'jetpack-videopress-pkg' ),
289 'status' => videopress_get_transcoding_status( $post_id ),
290 ),
291 null, // @phan-suppress-current-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
292 JSON_UNESCAPED_SLASHES
293 );
294 }
295
296 /**
297 * Returns the proper blog id depending on Jetpack or WP.com
298 *
299 * @return int the blog id
300 */
301 public function get_videopress_blog_id() {
302 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
303 return get_current_blog_id();
304 }
305
306 $options = Options::get_options();
307 return $options['shadow_blog_id'];
308 }
309 }
310