PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.2
Jetpack – WP Security, Backup, Speed, & Growth v16.2
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
jetpack / jetpack_vendor / automattic / jetpack-videopress / src / class-uploader-rest-endpoints.php

class-uploader-rest-endpoints.php in Jetpack – WP Security, Backup, Speed, & Growth 16.2, at jetpack_vendor/automattic/jetpack-videopress/src/class-uploader-rest-endpoints.php

144 lines 3.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * VideoPress Uploader
4 *
5 * @package automattic/jetpack-videopress
6 */
7
8 namespace Automattic\Jetpack\VideoPress;
9
10 use WP_Error;
11
12 /**
13 * VideoPress Uploader class
14 *
15 * Handles the upload from the Media Library to VideoPress servers
16 */
17 class Uploader_Rest_Endpoints {
18
19 /**
20 * Initializes the endpoints
21 *
22 * @return void
23 */
24 public static function init() {
25 add_action( 'rest_api_init', array( __CLASS__, 'register_rest_endpoints' ) );
26 }
27
28 /**
29 * Register the REST API routes.
30 *
31 * @return void
32 */
33 public static function register_rest_endpoints() {
34 /*
35 * Keep route validation structural. WordPress validates arguments before
36 * running permission callbacks, so inspecting the attachment or its file
37 * here would reveal which IDs contain readable videos to unauthorized
38 * callers. Uploader validates the attachment after authorization instead.
39 */
40 $id_arg = array(
41 'description' => __( 'The ID of the attachment you want to upload to VideoPress', 'jetpack-videopress-pkg' ),
42 'type' => 'integer',
43 'required' => true,
44 );
45 register_rest_route(
46 'videopress/v1',
47 'upload/(?P<attachment_id>\d+)',
48 array(
49 array(
50 'methods' => \WP_REST_Server::READABLE,
51 'callback' => __CLASS__ . '::check_status',
52 'permission_callback' => __CLASS__ . '::permissions_callback',
53 'args' => array(
54 'attachment_id' => $id_arg,
55 ),
56 ),
57 array(
58 'methods' => \WP_REST_Server::EDITABLE,
59 'callback' => __CLASS__ . '::do_upload',
60 'permission_callback' => __CLASS__ . '::permissions_callback',
61 'args' => array(
62 'attachment_id' => $id_arg,
63 ),
64 ),
65 )
66 );
67 }
68
69 /**
70 * Checks whether the user has permission to perform the upload.
71 *
72 * The site-wide `upload_files` capability is not sufficient on its own: the
73 * endpoint operates on a caller-supplied attachment id, so we must also
74 * confirm the current user is allowed to edit that specific attachment.
75 * Without the per-object check any author could target another user's
76 * private/draft video attachment by id (IDOR).
77 *
78 * @param \WP_REST_Request $request The request object.
79 * @return boolean
80 */
81 public static function permissions_callback( $request ) {
82 if ( ! current_user_can( 'upload_files' ) ) {
83 return false;
84 }
85
86 return current_user_can( 'edit_post', (int) $request['attachment_id'] );
87 }
88
89 /**
90 * Validates the attachment ID argument.
91 *
92 * This remains available to existing callers, but must not be registered as
93 * the REST argument validator because those run before route authorization.
94 *
95 * @param integer|string $value The attachment ID passed as an argument to the endpoint.
96 * @return boolean|WP_Error
97 */
98 public static function validate_attachment_id( $value ) {
99 return Uploader::is_valid_attachment_id( $value );
100 }
101
102 /**
103 * Endpoint callback for the GET method. Checks the upload status
104 *
105 * @param \WP_REST_Request $request The request object.
106 * @return array|WP_Error
107 */
108 public static function check_status( $request ) {
109 $attachment_id = $request->get_param( 'attachment_id' );
110 try {
111 $uploader = new Uploader( $attachment_id );
112 $status = $uploader->check_status();
113 return rest_ensure_response( $status );
114 } catch ( Upload_Exception $e ) {
115 return new WP_Error(
116 'rest_invalid_param',
117 $e->getMessage(),
118 array( 'status' => 400 )
119 );
120 }
121 }
122
123 /**
124 * Endpoint callback for the POST method. Uploads the video
125 *
126 * @param \WP_REST_Request $request The request object.
127 * @return array|WP_Error
128 */
129 public static function do_upload( $request ) {
130 $attachment_id = $request->get_param( 'attachment_id' );
131 try {
132 $uploader = new Uploader( $attachment_id );
133 $status = $uploader->upload();
134 return rest_ensure_response( $status );
135 } catch ( Upload_Exception $e ) {
136 return new WP_Error(
137 'rest_invalid_param',
138 $e->getMessage(),
139 array( 'status' => 400 )
140 );
141 }
142 }
143 }
144