PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.3
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
jetpack / jetpack_vendor / automattic / jetpack-comments / src / identity / class-identity.php

class-identity.php in Jetpack – WP Security, Backup, Speed, & Growth 16.3-a.3, at jetpack_vendor/automattic/jetpack-comments/src/identity/class-identity.php

86 lines 2.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * The commenter's identity.
4 *
5 * @package automattic/jetpack-comments
6 */
7
8 namespace Automattic\Jetpack\Comments;
9
10 /**
11 * Who is leaving the comment being written now.
12 */
13 class Identity {
14
15 /**
16 * Who is leaving the comment, as far as this site knows.
17 *
18 * @return array
19 */
20 public static function settings() {
21 $commenter = wp_get_current_commenter();
22
23 // Nothing under `identity` is about the visitor. This HTML is page-cached
24 // and served to everyone, so who holds a passport comes from a cookie.
25 $settings = array(
26 'isLoggedIn' => is_user_logged_in(),
27 'commenter' => array(
28 'author' => $commenter['comment_author'],
29 'email' => $commenter['comment_author_email'],
30 'url' => $commenter['comment_author_url'],
31 ),
32 'user' => null,
33 'identity' => array(
34 'blogId' => Checkpoint::blog_id(),
35 'providers' => array(),
36 'connect' => array(),
37 'origin' => Checkpoint::MESSAGE_ORIGIN,
38 'codeField' => Checkpoint::CODE_FIELD,
39 'passportField' => Checkpoint::PASSPORT_FIELD,
40 'displayCookie' => Passport::DISPLAY_COOKIE,
41 'cookiePath' => COOKIEPATH,
42 'cookieDomain' => COOKIE_DOMAIN ? COOKIE_DOMAIN : '',
43 'defaultAvatar' => Avatars::default_url( 74 ),
44 'refreshUrl' => Checkpoint_Endpoint::connect_url(),
45 'logoutUrl' => admin_url( 'admin-ajax.php' ),
46 'logoutAction' => Checkpoint_Endpoint::LOGOUT_ACTION,
47 ),
48 );
49
50 if ( is_user_logged_in() ) {
51 $user = wp_get_current_user();
52 $settings['user'] = array(
53 'avatarUrl' => get_avatar_url( $user->ID, array( 'size' => 74 ) ),
54 'commentingAs' => sprintf(
55 /* translators: %s is the display name of the logged-in user. */
56 __( 'Commenting as %s', 'jetpack-comments' ),
57 $user->display_name
58 ),
59 );
60
61 return $settings;
62 }
63
64 if ( ! Checkpoint::is_available() ) {
65 return $settings;
66 }
67
68 // The signed URLs get cached too, so visitors share a challenge until it
69 // expires. That is fine: the challenge only filters messages to the
70 // window that opened the popup, and the refresh route issues a fresh one.
71 $challenge = rtrim( strtr( base64_encode( random_bytes( 32 ) ), '+/', '-_' ), '=' ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- base64url is the wire format.
72
73 $settings['identity']['providers'] = Checkpoint::PROVIDERS;
74
75 foreach ( Checkpoint::PROVIDERS as $provider ) {
76 $connect = Checkpoint::connect_url( $provider, $challenge );
77
78 if ( ! is_wp_error( $connect ) ) {
79 $settings['identity']['connect'][ $provider ] = $connect;
80 }
81 }
82
83 return $settings;
84 }
85 }
86