PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.1
16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 All 504 releases
← All changes | extensions/blocks/map/map.php +130 -15 12.0.3 → 16.3-a.1 View file →
@@ -15,10 +15,11 @@
15 15 use Jetpack;
16 16 use Jetpack_Gutenberg;
17 17 use Jetpack_Mapbox_Helper;
18 18
19 -const FEATURE_NAME = 'map';
20 -const BLOCK_NAME = 'jetpack/' . FEATURE_NAME;
19 +if ( ! defined( 'ABSPATH' ) ) {
20 + exit( 0 );
21 +}
21 22
22 23 if ( ! class_exists( 'Jetpack_Mapbox_Helper' ) ) {
23 24 require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-mapbox-helper.php';
24 25 }
@@ -29,9 +30,9 @@
29 30 * registration if we need to.
30 31 */
31 32 function register_block() {
32 33 Blocks::jetpack_register_block(
33 - BLOCK_NAME,
34 + __DIR__,
34 35 array(
35 36 'render_callback' => __NAMESPACE__ . '\load_assets',
36 37 )
37 38 );
@@ -50,9 +51,10 @@
50 51
51 52 $event_name = 'map_block_mapbox_wpcom_key_load';
52 53 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
53 54 require_lib( 'tracks/client' );
54 - tracks_record_event( wp_get_current_user(), $event_name );
55 + // Tracking::record_user_event() prefixes the source itself; tracks_record_event() does not.
56 + tracks_record_event( wp_get_current_user(), 'jetpack_' . $event_name );
55 57 } elseif ( ( new Host() )->is_woa_site() && Jetpack::is_connection_ready() ) {
56 58 $tracking = new Tracking();
57 59 $tracking->record_user_event( $event_name );
58 60 }
@@ -58,8 +60,33 @@
58 60 }
59 61 }
60 62
61 63 /**
64 + * Function to determine which map provider to choose
65 + *
66 + * @param string $html The block's HTML - needed for the class name.
67 + *
68 + * @return string The name of the map provider.
69 + */
70 +function get_map_provider( $html ) {
71 + $mapbox_styles = array( 'is-style-terrain' );
72 + // return mapbox if html contains one of the mapbox styles
73 + foreach ( $mapbox_styles as $style ) {
74 + if ( str_contains( $html, $style ) ) {
75 + return 'mapbox';
76 + }
77 + }
78 +
79 + // you can override the map provider with a cookie
80 + if ( isset( $_COOKIE['map_provider'] ) ) {
81 + return sanitize_text_field( wp_unslash( $_COOKIE['map_provider'] ) );
82 + }
83 +
84 + // if we don't apply the filters & default to mapbox
85 + return apply_filters( 'wpcom_map_block_map_provider', 'mapbox' );
86 +}
87 +
88 +/**
62 89 * Map block registration/dependency declaration.
63 90 *
64 91 * @param array $attr Array containing the map block attributes.
65 92 * @param string $content String containing the map block content.
@@ -67,9 +94,8 @@
67 94 * @return string
68 95 */
69 96 function load_assets( $attr, $content ) {
70 97 $access_token = Jetpack_Mapbox_Helper::get_access_token();
71 -
72 98 wpcom_load_event( $access_token['source'] );
73 99
74 100 if ( Blocks::is_amp_request() ) {
75 101 static $map_block_counter = array();
@@ -98,21 +124,105 @@
98 124 $placeholder
99 125 );
100 126 }
101 127
102 - Jetpack_Gutenberg::load_assets_as_required( FEATURE_NAME );
128 + Jetpack_Gutenberg::load_assets_as_required( __DIR__ );
103 129
104 - return preg_replace( '/<div /', '<div data-api-key="' . esc_attr( $access_token['key'] ) . '" ', $content, 1 );
130 + $map_provider = get_map_provider( $content );
131 +
132 + return rebuild_map_block_div( $attr, $content, $map_provider, $access_token );
105 133 }
106 134
107 135 /**
136 + * Rebuild the map block div to move large JSON data from HTML attributes
137 + * into an inline JS payload, keeping the DOM lightweight.
138 + *
139 + * @param array $attr Array containing the map block attributes.
140 + * @param string $content String containing the map block content.
141 + * @param string $map_provider The map provider (mapbox or mapkit).
142 + * @param array $access_token The Mapbox/MapKit access token data.
143 + *
144 + * @return string
145 + */
146 +function rebuild_map_block_div( $attr, $content, $map_provider, $access_token ) {
147 + static $did_inline = false;
148 +
149 + $block_id = wp_unique_id( 'jp-map-' );
150 +
151 + // Extract map-style from the saved HTML since it's no longer a block attribute
152 + // (was deprecated and converted to CSS class names like is-style-terrain).
153 + $map_style = 'default';
154 + if ( preg_match( '/data-map-style="([^"]*)"/', $content, $matches ) ) {
155 + $map_style = $matches[1];
156 + }
157 +
158 + $classes = array( 'wp-block-jetpack-map' );
159 + if ( ! empty( $attr['align'] ) ) {
160 + $classes[] = 'align' . $attr['align'];
161 + }
162 + if ( ! empty( $attr['className'] ) ) {
163 + $classes[] = $attr['className'];
164 + }
165 +
166 + // Keep the tag small: no giant JSON in attributes.
167 + $data_attrs = array(
168 + 'class' => implode( ' ', $classes ),
169 + 'data-map-id' => $block_id,
170 + 'data-map-provider' => $map_provider,
171 + 'data-api-key' => $access_token['key'],
172 + 'data-map-style' => $map_style,
173 + );
174 +
175 + if ( 'mapkit' === $map_provider ) {
176 + $data_attrs['data-blog-id'] = \Jetpack_Options::get_option( 'id' );
177 + }
178 +
179 + // Put everything else in the JS payload (including points).
180 + $payload = array(
181 + 'points' => $attr['points'] ?? null,
182 + 'zoom' => $attr['zoom'] ?? null,
183 + 'mapCenter' => $attr['mapCenter'] ?? null,
184 + 'markerColor' => $attr['markerColor'] ?? null,
185 + 'scrollToZoom' => $attr['scrollToZoom'] ?? null,
186 + 'mapDetails' => $attr['mapDetails'] ?? null,
187 + 'mapHeight' => $attr['mapHeight'] ?? null,
188 + 'showFullscreenButton' => $attr['showFullscreenButton'] ?? null,
189 + 'mapStyle' => $map_style,
190 + );
191 +
192 + $handle = 'jetpack-block-map';
193 +
194 + // Seed global once.
195 + if ( ! $did_inline ) {
196 + wp_add_inline_script( $handle, 'window.JetpackMapBlockData = window.JetpackMapBlockData || {};', 'before' );
197 + $did_inline = true;
198 + }
199 +
200 + // Add this block's payload keyed by ID.
201 + wp_add_inline_script(
202 + $handle,
203 + 'window.JetpackMapBlockData[' . wp_json_encode( $block_id, JSON_HEX_TAG | JSON_HEX_AMP ) . '] = ' . wp_json_encode( $payload, JSON_HEX_TAG | JSON_HEX_AMP ) . ';',
204 + 'before'
205 + );
206 +
207 + $div_open = '<div';
208 + foreach ( $data_attrs as $key => $value ) {
209 + $div_open .= ' ' . $key . '="' . esc_attr( $value ) . '"';
210 + }
211 + $div_open .= '>';
212 +
213 + $result = preg_replace( '/<div[^>]*>/', $div_open, $content, 1 );
214 + return $result ?? $content;
215 +}
216 +
217 +/**
108 218 * Render a page containing only a single Map block.
109 219 */
110 220 function render_single_block_page() {
111 221 // phpcs:ignore WordPress.Security.NonceVerification
112 - $map_block_counter = isset( $_GET, $_GET['map-block-counter'] ) ? absint( $_GET['map-block-counter'] ) : null;
222 + $map_block_counter = isset( $_GET['map-block-counter'] ) ? absint( $_GET['map-block-counter'] ) : null;
113 223 // phpcs:ignore WordPress.Security.NonceVerification
114 - $map_block_post_id = isset( $_GET, $_GET['map-block-post-id'] ) ? absint( $_GET['map-block-post-id'] ) : null;
224 + $map_block_post_id = isset( $_GET['map-block-post-id'] ) ? absint( $_GET['map-block-post-id'] ) : null;
115 225
116 226 if ( ! $map_block_counter || ! $map_block_post_id ) {
117 227 return;
118 228 }
@@ -127,8 +237,13 @@
127 237 $post_html = new \DOMDocument();
128 238 /** This filter is already documented in core/wp-includes/post-template.php */
129 239 $content = apply_filters( 'the_content', $post->post_content );
130 240
241 + // Return early if empty to prevent DOMDocument::loadHTML fatal.
242 + if ( empty( $content ) ) {
243 + return;
244 + }
245 +
131 246 /* Suppress warnings */
132 247 libxml_use_internal_errors( true );
133 248 @$post_html->loadHTML( $content ); // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged
134 249 libxml_use_internal_errors( false );
@@ -145,9 +260,9 @@
145 260 ob_start();
146 261
147 262 add_filter( 'jetpack_is_amp_request', '__return_false' );
148 263
149 - Jetpack_Gutenberg::load_assets_as_required( FEATURE_NAME );
264 + Jetpack_Gutenberg::load_assets_as_required( __DIR__ );
150 265 wp_scripts()->do_items();
151 266 wp_styles()->do_items();
152 267
153 268 add_filter( 'jetpack_is_amp_request', '__return_true' );
@@ -162,9 +277,9 @@
162 277 $head_content,
163 278 preg_replace( '/(?<=<div\s)/', 'data-api-key="' . esc_attr( $access_token['key'] ) . '" ', $block_markup, 1 )
164 279 );
165 280 echo $page_html; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
166 - exit;
281 + exit( 0 );
167 282 }
168 283 add_action( 'wp', __NAMESPACE__ . '\render_single_block_page' );
169 284
170 285 /**
@@ -197,14 +312,14 @@
197 312 },
198 313 $points
199 314 );
200 315
201 - $map_block = '<!-- wp:jetpack/map ' . wp_json_encode( $map_block_data ) . ' -->' . PHP_EOL;
316 + $map_block = '<!-- wp:jetpack/map ' . wp_json_encode( $map_block_data, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ) . ' -->' . PHP_EOL;
202 317 $map_block .= sprintf(
203 318 '<div class="wp-block-jetpack-map" data-map-style="default" data-map-details="true" data-points="%1$s" data-zoom="%2$d" data-map-center="%3$s" data-marker-color="red" data-show-fullscreen-button="true">',
204 - esc_html( wp_json_encode( $map_block_data['points'] ) ),
205 - (int) $map_block_data['zoom'],
206 - esc_html( wp_json_encode( $map_block_data['mapCenter'] ) )
319 + esc_attr( wp_json_encode( $map_block_data['points'], JSON_HEX_AMP | JSON_UNESCAPED_SLASHES ) ),
320 + $map_block_data['zoom'],
321 + esc_attr( wp_json_encode( $map_block_data['mapCenter'], JSON_HEX_AMP | JSON_UNESCAPED_SLASHES ) )
207 322 );
208 323 $map_block .= '<ul>' . implode( "\n", $list_items ) . '</ul>';
209 324 $map_block .= '</div>' . PHP_EOL;
210 325 $map_block .= '<!-- /wp:jetpack/map -->';