PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.1
16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 All 504 releases
← All changes | json-endpoints/class.wpcom-json-api-post-endpoint.php +13 -119 12.0.3 → 16.3-a.1 View file →
@@ -1,6 +1,10 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 +if ( ! defined( 'ABSPATH' ) ) {
4 + exit( 0 );
5 +}
6 +
3 7 /**
4 8 * Post Endpoint class.
5 9 */
6 10 abstract class WPCOM_JSON_API_Post_Endpoint extends WPCOM_JSON_API_Endpoint {
@@ -50,9 +54,9 @@
50 54 'post_thumbnail' => '(object>attachment) The attachment object for the featured image if it has one.',
51 55 'format' => array(), // see constructor
52 56 'geo' => '(object>geo|false)',
53 57 'menu_order' => '(int) (Pages Only) The order pages should appear in.',
54 - 'publicize_URLs' => '(array:URL) Array of Twitter and Facebook URLs published by this post.',
58 + 'publicize_URLs' => '(array:URL) Array of Facebook URLs published by this post.',
55 59 'tags' => '(object:tag) Hash of tags (keyed by tag name) applied to the post.',
56 60 'categories' => '(object:category) Hash of categories (keyed by category name) applied to the post.',
57 61 'attachments' => '(object:attachment) Hash of post attachments (keyed by attachment ID).',
58 62 'metadata' => '(array) Array of post metadata keys and values. All unprotected meta keys are available by default for read requests. Both unprotected and protected meta keys are available for authenticated requests with access. Protected meta keys can be made available with the <code>rest_api_allowed_public_metadata</code> filter.',
@@ -111,13 +115,8 @@
111 115 $GLOBALS['content_width'] = (int) $args['content_width'];
112 116 }
113 117 }
114 118
115 - if ( isset( $_SERVER['HTTP_USER_AGENT'] ) && strpos( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ), 'wp-windows8' ) ) { // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- we're not using this value and making changes, just checking if it exists.
116 - remove_shortcode( 'gallery', 'gallery_shortcode' );
117 - add_shortcode( 'gallery', array( $this, 'win8_gallery_shortcode' ) );
118 - }
119 -
120 119 switch ( $field ) {
121 120 case 'name':
122 121 $post_id = $this->get_post_id_by_name( $field_value );
123 122 if ( is_wp_error( $post_id ) ) {
@@ -196,9 +195,9 @@
196 195 case 'title':
197 196 if ( 'display' === $context ) {
198 197 $response[ $key ] = (string) get_the_title( $post->ID );
199 198 } else {
200 - $response[ $key ] = (string) htmlspecialchars_decode( $post->post_title, ENT_QUOTES );
199 + $response[ $key ] = htmlspecialchars_decode( $post->post_title, ENT_QUOTES );
201 200 }
202 201 break;
203 202 case 'URL':
204 203 if ( 'revision' === $post->post_type ) {
@@ -244,9 +243,9 @@
244 243 break;
245 244 case 'password':
246 245 $response[ $key ] = (string) $post->post_password;
247 246 if ( 'edit' === $context ) {
248 - $response[ $key ] = htmlspecialchars_decode( (string) $response[ $key ], ENT_QUOTES );
247 + $response[ $key ] = htmlspecialchars_decode( $response[ $key ], ENT_QUOTES );
249 248 }
250 249 break;
251 250 /** (object|false) */
252 251 case 'parent':
@@ -254,9 +253,9 @@
254 253 $parent = get_post( $post->post_parent );
255 254 if ( 'display' === $context ) {
256 255 $parent_title = (string) get_the_title( $parent->ID );
257 256 } else {
258 - $parent_title = (string) htmlspecialchars_decode( $post->post_title, ENT_QUOTES );
257 + $parent_title = htmlspecialchars_decode( $post->post_title, ENT_QUOTES );
259 258 }
260 259 $response[ $key ] = (object) array(
261 260 'ID' => (int) $parent->ID,
262 261 'type' => (string) $parent->post_type,
@@ -280,9 +279,9 @@
280 279 /** This filter is documented in modules/likes.php */
281 280 $sitewide_likes_enabled = (bool) apply_filters( 'wpl_is_enabled_sitewide', ! get_option( 'disabled_likes' ) );
282 281 $post_likes_switched = get_post_meta( $post->ID, 'switch_like_status', true );
283 282 $post_likes_enabled = $post_likes_switched || ( $sitewide_likes_enabled && $post_likes_switched !== '0' );
284 - $response[ $key ] = (bool) $post_likes_enabled;
283 + $response[ $key ] = $post_likes_enabled;
285 284 break;
286 285 case 'sharing_enabled':
287 286 $show = true;
288 287 /** This filter is documented in modules/sharedaddy/sharing-service.php */
@@ -390,8 +389,9 @@
390 389 $publicize = get_post_meta( $post->ID, 'publicize_results', true );
391 390 if ( $publicize ) {
392 391 foreach ( $publicize as $service => $data ) {
393 392 switch ( $service ) {
393 + // @todo Explore removing once Twitter has been removed from Publicize.
394 394 case 'twitter':
395 395 foreach ( $data as $datum ) {
396 396 $publicize_urls[] = esc_url_raw( "https://twitter.com/{$datum['user_id']}/status/{$datum['post_id']}" );
397 397 }
@@ -403,9 +403,9 @@
403 403 break;
404 404 }
405 405 }
406 406 }
407 - $response[ $key ] = (array) $publicize_urls;
407 + $response[ $key ] = $publicize_urls;
408 408 break;
409 409 case 'tags':
410 410 $response[ $key ] = array();
411 411 $terms = wp_get_post_tags( $post->ID );
@@ -517,9 +517,9 @@
517 517
518 518 $old_pages = $pages;
519 519 $old_page = $page;
520 520
521 - $content = join( "\n\n", $pages );
521 + $content = implode( "\n\n", $pages );
522 522 $content = preg_replace( '/<!--more(.*?)?-->/', '', $content );
523 523 $pages = array( $content ); // phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
524 524 $page = 1; // phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
525 525
@@ -569,117 +569,11 @@
569 569 }
570 570 }
571 571
572 572 /**
573 - * Win8 Gallery shortcode.
574 - *
575 - * @param array $attr - the attribute.
576 - */
577 - public function win8_gallery_shortcode( $attr ) {
578 - global $post;
579 -
580 - static $instance = 0;
581 - ++$instance;
582 -
583 - // @todo - find out if this is a bug, intentionally unused, or can be removed.
584 - $output = ''; // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
585 -
586 - // We're trusting author input, so let's at least make sure it looks like a valid orderby statement
587 - if ( isset( $attr['orderby'] ) ) {
588 - $attr['orderby'] = sanitize_sql_orderby( $attr['orderby'] );
589 - if ( ! $attr['orderby'] ) {
590 - unset( $attr['orderby'] );
591 - }
592 - }
593 -
594 - $atts = shortcode_atts(
595 - array(
596 - 'order' => 'ASC',
597 - 'orderby' => 'menu_order ID',
598 - 'id' => $post->ID,
599 - 'include' => '',
600 - 'exclude' => '',
601 - 'slideshow' => false,
602 - ),
603 - $attr,
604 - 'gallery'
605 - );
606 - $id = ! empty( $atts['id'] ) ? (int) $atts['id'] : 0;
607 -
608 - // Custom image size and always use it.
609 - add_image_size( 'win8app-column', 480 );
610 - $size = 'win8app-column';
611 -
612 - if ( 'RAND' === $atts['order'] ) {
613 - $orderby = 'none';
614 - } else {
615 - $orderby = $atts['orderby'];
616 - }
617 -
618 - if ( ! empty( $atts['include'] ) ) {
619 - $include = preg_replace( '/[^0-9,]+/', '', $atts['include'] );
620 - $_attachments = get_posts(
621 - array(
622 - 'include' => $include,
623 - 'post_status' => 'inherit',
624 - 'post_type' => 'attachment',
625 - 'post_mime_type' => 'image',
626 - 'order' => $atts['order'],
627 - 'orderby' => $orderby,
628 - )
629 - );
630 - $attachments = array();
631 - foreach ( $_attachments as $key => $val ) {
632 - $attachments[ $val->ID ] = $_attachments[ $key ];
633 - }
634 - } elseif ( ! empty( $atts['exclude'] ) ) {
635 - $exclude = preg_replace( '/[^0-9,]+/', '', $atts['exclude'] );
636 - $attachments = get_children(
637 - array(
638 - 'post_parent' => $id,
639 - 'exclude' => $exclude,
640 - 'post_status' => 'inherit',
641 - 'post_type' => 'attachment',
642 - 'post_mime_type' => 'image',
643 - 'order' => $atts['order'],
644 - 'orderby' => $orderby,
645 - )
646 - );
647 - } else {
648 - $attachments = get_children(
649 - array(
650 - 'post_parent' => $id,
651 - 'post_status' => 'inherit',
652 - 'post_type' => 'attachment',
653 - 'post_mime_type' => 'image',
654 - 'order' => $atts['order'],
655 - 'orderby' => $orderby,
656 - )
657 - );
658 - }
659 -
660 - if ( ! empty( $attachments ) ) {
661 - foreach ( $attachments as $id => $attachment ) {
662 - $link = isset( $attr['link'] ) && 'file' === $attr['link']
663 - ? wp_get_attachment_link( $id, $size, false, false )
664 - : wp_get_attachment_link( $id, $size, true, false );
665 - // phpcs:disable VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
666 - if ( $captiontag && trim( $attachment->post_excerpt ) ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UndefinedVariable
667 - $output .= "<div class='wp-caption aligncenter'>$link
668 - <p class='wp-caption-text'>" . wptexturize( $attachment->post_excerpt ) . '</p>
669 - </div>';
670 - } else {
671 - $output .= $link . ' ';
672 - }
673 - // phpcs:enable VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
674 - }
675 - }
676 - }
677 -
678 - /**
679 573 * Returns attachment object.
680 574 *
681 - * @param object - $attachment attachment row.
575 + * @param object $attachment attachment row.
682 576 *
683 577 * @return object
684 578 */
685 579 public function get_attachment( $attachment ) {