| 1 |
<?php |
| 2 |
/** |
| 3 |
* The commenter's identity. |
| 4 |
* |
| 5 |
* @package automattic/jetpack-comments |
| 6 |
*/ |
| 7 |
|
| 8 |
namespace Automattic\Jetpack\Comments; |
| 9 |
|
| 10 |
/** |
| 11 |
* Who is leaving the comment being written now. |
| 12 |
*/ |
| 13 |
class Identity { |
| 14 |
|
| 15 |
/** |
| 16 |
* Who is leaving the comment, as far as this site knows. |
| 17 |
* |
| 18 |
* @return array |
| 19 |
*/ |
| 20 |
public static function settings() { |
| 21 |
$commenter = wp_get_current_commenter(); |
| 22 |
|
| 23 |
// Nothing under `identity` is about the visitor. This HTML is page-cached |
| 24 |
// and served to everyone, so who holds a passport comes from a cookie. |
| 25 |
$settings = array( |
| 26 |
'isLoggedIn' => is_user_logged_in(), |
| 27 |
'commenter' => array( |
| 28 |
'author' => $commenter['comment_author'], |
| 29 |
'email' => $commenter['comment_author_email'], |
| 30 |
'url' => $commenter['comment_author_url'], |
| 31 |
), |
| 32 |
'user' => null, |
| 33 |
'identity' => array( |
| 34 |
'blogId' => Checkpoint::blog_id(), |
| 35 |
'providers' => array(), |
| 36 |
'connect' => array(), |
| 37 |
'origin' => Checkpoint::MESSAGE_ORIGIN, |
| 38 |
'codeField' => Checkpoint::CODE_FIELD, |
| 39 |
'passportField' => Checkpoint::PASSPORT_FIELD, |
| 40 |
'displayCookie' => Passport::DISPLAY_COOKIE, |
| 41 |
'cookiePath' => COOKIEPATH, |
| 42 |
'cookieDomain' => COOKIE_DOMAIN ? COOKIE_DOMAIN : '', |
| 43 |
'defaultAvatar' => Avatars::default_url( 74 ), |
| 44 |
'refreshUrl' => Checkpoint_Endpoint::connect_url(), |
| 45 |
'logoutUrl' => admin_url( 'admin-ajax.php' ), |
| 46 |
'logoutAction' => Checkpoint_Endpoint::LOGOUT_ACTION, |
| 47 |
), |
| 48 |
); |
| 49 |
|
| 50 |
if ( is_user_logged_in() ) { |
| 51 |
$user = wp_get_current_user(); |
| 52 |
$settings['user'] = array( |
| 53 |
'avatarUrl' => get_avatar_url( $user->ID, array( 'size' => 74 ) ), |
| 54 |
'commentingAs' => sprintf( |
| 55 |
/* translators: %s is the display name of the logged-in user. */ |
| 56 |
__( 'Commenting as %s', 'jetpack-comments' ), |
| 57 |
$user->display_name |
| 58 |
), |
| 59 |
); |
| 60 |
|
| 61 |
return $settings; |
| 62 |
} |
| 63 |
|
| 64 |
if ( ! Checkpoint::is_available() ) { |
| 65 |
return $settings; |
| 66 |
} |
| 67 |
|
| 68 |
// The signed URLs get cached too, so visitors share a challenge until it |
| 69 |
// expires. That is fine: the challenge only filters messages to the |
| 70 |
// window that opened the popup, and the refresh route issues a fresh one. |
| 71 |
$challenge = rtrim( strtr( base64_encode( random_bytes( 32 ) ), '+/', '-_' ), '=' ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- base64url is the wire format. |
| 72 |
|
| 73 |
$settings['identity']['providers'] = Checkpoint::PROVIDERS; |
| 74 |
|
| 75 |
foreach ( Checkpoint::PROVIDERS as $provider ) { |
| 76 |
$connect = Checkpoint::connect_url( $provider, $challenge ); |
| 77 |
|
| 78 |
if ( ! is_wp_error( $connect ) ) { |
| 79 |
$settings['identity']['connect'][ $provider ] = $connect; |
| 80 |
} |
| 81 |
} |
| 82 |
|
| 83 |
return $settings; |
| 84 |
} |
| 85 |
} |
| 86 |
|