PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
jetpack / jetpack_vendor / automattic / jetpack-my-jetpack / src / class-initializer.php

class-initializer.php in Jetpack – WP Security, Backup, Speed, & Growth 16.3-a.3, at jetpack_vendor/automattic/jetpack-my-jetpack/src/class-initializer.php

1,252 lines 39.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * WP Admin page with information and configuration shared among all Jetpack stand-alone plugins
4 *
5 * @package automattic/my-jetpack
6 */
7
8 namespace Automattic\Jetpack\My_Jetpack;
9
10 use Automattic\Jetpack\Admin_UI\Admin_Menu;
11 use Automattic\Jetpack\Assets;
12 use Automattic\Jetpack\Boost_Speed_Score\Speed_Score;
13 use Automattic\Jetpack\Boost_Speed_Score\Speed_Score_History;
14 use Automattic\Jetpack\Connection\Client;
15 use Automattic\Jetpack\Connection\Error_Handler as Connection_Error_Handler;
16 use Automattic\Jetpack\Connection\Initial_State as Connection_Initial_State;
17 use Automattic\Jetpack\Connection\Manager as Connection_Manager;
18 use Automattic\Jetpack\Connection\Rest_Authentication as Connection_Rest_Authentication;
19 use Automattic\Jetpack\Connection\REST_Jetpack_AI_JWT;
20 use Automattic\Jetpack\Constants as Jetpack_Constants;
21 use Automattic\Jetpack\ExPlat;
22 use Automattic\Jetpack\Feature_Flags\Feature_Flags;
23 use Automattic\Jetpack\JITMS\JITM;
24 use Automattic\Jetpack\Licensing;
25 use Automattic\Jetpack\Menu_Badges\Menu_Badges;
26 use Automattic\Jetpack\Menu_Badges\Notification_Counts;
27 use Automattic\Jetpack\Modules;
28 use Automattic\Jetpack\Plugins_Installer;
29 use Automattic\Jetpack\Status;
30 use Automattic\Jetpack\Status\Host as Status_Host;
31 use Automattic\Jetpack\Sync\Functions as Sync_Functions;
32 use Automattic\Jetpack\Terms_Of_Service;
33 use Automattic\Jetpack\Tracking;
34 use Automattic\Jetpack\WP_Build_Polyfills\WP_Build_Polyfills;
35 use Jetpack;
36 use WP_Error;
37
38 /**
39 * The main Initializer class that registers the admin menu and eneuque the assets.
40 */
41 class Initializer {
42
43 /**
44 * My Jetpack package version
45 *
46 * @var string
47 */
48 const PACKAGE_VERSION = '6.4.1';
49
50 /**
51 * Feature flag that swaps the My Jetpack Products tab for a Features tab.
52 */
53 const FEATURES_TAB_FEATURE_FLAG = 'my-jetpack-features-tab';
54
55 /**
56 * Handle for the classic script that carries the React initial state.
57 *
58 * Plugins that render My Jetpack components on their own pages (Boost) depend on this name.
59 */
60 const DATA_SCRIPT_HANDLE = 'my_jetpack_main_app';
61
62 /**
63 * Handle for the webpack bundle that renders the onboarding takeover.
64 */
65 const ONBOARDING_SCRIPT_HANDLE = 'my_jetpack_onboarding';
66
67 /**
68 * The wp-build page ID, which the generated enqueue check expects as the screen ID.
69 */
70 const WP_BUILD_PAGE_ID = 'my-jetpack-dashboard';
71
72 /**
73 * HTML container ID for the IDC screen on My Jetpack page.
74 */
75 private const IDC_CONTAINER_ID = 'my-jetpack-identity-crisis-container';
76
77 public const JETPACK_PLUGIN_SLUGS = array(
78 'jetpack-backup',
79 'jetpack-boost',
80 'zerobscrm',
81 'jetpack',
82 'jetpack-protect',
83 'jetpack-social',
84 'jetpack-videopress',
85 'jetpack-search',
86 );
87
88 private const MY_JETPACK_SITE_INFO_TRANSIENT_KEY = 'my-jetpack-site-info';
89
90 /**
91 * Holds info/data about the site (from the /sites/%d endpoint)
92 *
93 * @var object
94 */
95 public static $site_info;
96
97 /**
98 * The screen ID alias_screen_id_for_wp_build() replaced, until it is restored.
99 *
100 * @var string|null
101 */
102 private static $wp_build_original_screen_id = null;
103
104 /**
105 * Initialize My Jetpack
106 *
107 * @return void
108 */
109 public static function init() {
110 // Before the gate, so the flag stays listed while diagnosing why My Jetpack is off.
111 self::register_feature_flags();
112
113 // Before the gate: the Jetpack plugin renders this package's connection screen and footer
114 // links even where My Jetpack is off, and `myJetpackInitialState` only exists on its own page.
115 add_filter( 'jetpack_admin_js_script_data', array( __CLASS__, 'add_admin_script_data' ) );
116
117 if ( ! self::should_initialize() || did_action( 'my_jetpack_init' ) ) {
118 return;
119 }
120
121 // Answer "is this product on?" for admin menu registration.
122 Menu_Visibility::init();
123
124 // Extend jetpack plugins action links.
125 Products::extend_plugins_action_links();
126
127 // Set up the REST authentication hooks.
128 Connection_Rest_Authentication::init();
129
130 if ( self::is_licensing_ui_enabled() ) {
131 Licensing::instance()->initialize();
132 }
133
134 // Initialize Boost Speed Score
135 new Speed_Score( array(), 'jetpack-my-jetpack' );
136
137 // Add custom WP REST API endoints.
138 add_action( 'rest_api_init', array( __CLASS__, 'register_rest_endpoints' ) );
139
140 // Both of wp-build's deadlines fall later in this request: its enqueue check must be
141 // hooked before `admin_enqueue_scripts`, and its render function defined before
142 // the page callback.
143 add_action( 'admin_menu', array( __CLASS__, 'maybe_load_wp_build' ), 1 );
144
145 add_action( 'admin_menu', array( __CLASS__, 'add_my_jetpack_menu_item' ) );
146
147 add_action( 'admin_init', array( __CLASS__, 'setup_historically_active_jetpack_modules_sync' ) );
148 // Registered on admin_menu (not admin_init) and well before priority 100000, so the
149 // counts it registers exist before the menu-badges renderer runs on admin_menu 100000.
150 add_action( 'admin_menu', array( __CLASS__, 'maybe_show_red_bubble' ), 30 );
151
152 // Set up the ExPlat package endpoints
153 ExPlat::init();
154
155 // Sets up JITMS.
156 JITM::configure();
157
158 // Add "Jetpack Manage" menu item.
159 Jetpack_Manage::init();
160
161 /**
162 * Fires after the My Jetpack package is initialized
163 *
164 * @since 0.1.0
165 */
166 do_action( 'my_jetpack_init' );
167 }
168
169 /**
170 * Acts as a feature flag, returning a boolean for whether we should show the licensing UI.
171 *
172 * @since 1.2.0
173 *
174 * @return boolean
175 */
176 public static function is_licensing_ui_enabled() {
177 // Default changed to true in 1.5.0.
178 $is_enabled = true;
179
180 /*
181 * Bail if My Jetpack is not enabled,
182 * and thus the licensing UI shouldn't be enabled either.
183 */
184 if ( ! self::should_initialize() ) {
185 $is_enabled = false;
186 }
187
188 /**
189 * Acts as a feature flag, returning a boolean for whether we should show the licensing UI.
190 *
191 * @param bool $is_enabled Defaults to true.
192 *
193 * @since 1.2.0
194 * @since 1.5.0 Update default value to true.
195 */
196 return apply_filters(
197 'jetpack_my_jetpack_should_enable_add_license_screen',
198 $is_enabled
199 );
200 }
201
202 /**
203 * Add My Jetpack menu item to the admin menu.
204 *
205 * @return void
206 */
207 public static function add_my_jetpack_menu_item() {
208 $page_suffix = Admin_Menu::add_menu(
209 __( 'My Jetpack', 'jetpack-my-jetpack' ),
210 __( 'My Jetpack', 'jetpack-my-jetpack' ),
211 'edit_posts',
212 'my-jetpack',
213 array( __CLASS__, 'admin_page' ),
214 Admin_Menu::POSITION_FIRST
215 );
216 add_action( 'load-' . $page_suffix, array( __CLASS__, 'admin_init' ) );
217 }
218
219 /**
220 * Callback for the load my jetpack page hook.
221 *
222 * @return void
223 */
224 public static function admin_init() {
225 $connection = new Connection_Manager();
226
227 // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- No nonce needed for redirect flow control
228 $step = isset( $_GET['step'] ) ? sanitize_text_field( wp_unslash( $_GET['step'] ) ) : '';
229
230 // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Checking for partner coupon redemption flow
231 $show_coupon_redemption = isset( $_GET['showCouponRedemption'] );
232
233 // Redirect to Jetpack dashboard for partner coupon redemption
234 if ( $show_coupon_redemption ) {
235 wp_safe_redirect( admin_url( 'admin.php?page=jetpack&showCouponRedemption=1#/dashboard' ) );
236 exit( 0 );
237 }
238
239 // Handle onboarding redirects based on connection status
240 $redirect_args = self::get_onboarding_redirect_args( $step, $connection->is_connected(), self::is_onboarding_available() );
241
242 if ( null !== $redirect_args ) {
243 $admin_page = add_query_arg( $redirect_args, admin_url( 'admin.php' ) );
244 $location = wp_sanitize_redirect( $admin_page );
245
246 // Remove wp_get_referer filter applied in `fix_redirect` method of `Jetpack_Admin` class
247 remove_filter( 'wp_redirect', 'wp_get_referer' );
248 wp_safe_redirect( $location );
249
250 exit( 0 );
251 }
252
253 // If the user reaches the onboarding page, add a class to the body
254 if ( $step === 'onboarding' ) {
255 add_filter( 'admin_body_class', array( __CLASS__, 'add_onboarding_admin_body_class' ) );
256 }
257
258 self::$site_info = self::get_site_info();
259 add_filter( 'identity_crisis_container_id', array( static::class, 'get_idc_container_id' ) );
260 add_action( 'admin_enqueue_scripts', array( __CLASS__, 'enqueue_scripts' ) );
261 }
262
263 /**
264 * Whether the My Jetpack onboarding flow is available on this site.
265 *
266 * WordPress.com Simple sites are connected by definition and don't manage their
267 * connection through My Jetpack, so the onboarding flow (which asks the user to
268 * connect) never applies there.
269 *
270 * @internal Not part of the package's public API.
271 *
272 * @return bool
273 */
274 public static function is_onboarding_available() {
275 return ! ( new Status_Host() )->is_wpcom_simple();
276 }
277
278 /**
279 * Decide whether the current My Jetpack request should redirect, and where to.
280 *
281 * @internal Not part of the package's public API.
282 *
283 * @param string $step The current `step` query param.
284 * @param bool $is_connected Whether the site is connected to WordPress.com.
285 * @param bool $onboarding_available Whether the onboarding flow is available on this site.
286 * @return array|null Query args for the redirect, or null to stay on the current page.
287 */
288 public static function get_onboarding_redirect_args( $step, $is_connected, $onboarding_available ) {
289 if ( $onboarding_available && ! $is_connected && $step !== 'onboarding' ) {
290 // Redirect to onboarding if not connected
291 return array(
292 'page' => 'my-jetpack',
293 'step' => 'onboarding',
294 );
295 }
296
297 if ( $step === 'onboarding' && ( ! $onboarding_available || $is_connected ) ) {
298 // Redirect away from onboarding if already connected or onboarding is not available on this site
299 return array( 'page' => 'my-jetpack' );
300 }
301
302 return null;
303 }
304
305 /**
306 * Add a body class to the My Jetpack onboarding page.
307 * This class hides the WP Admin toolbar and the sidebar menu.
308 *
309 * @param string $classes The body classes.
310 * @return string The modified body classes.
311 */
312 public static function add_onboarding_admin_body_class( $classes ) {
313 $classes .= 'jetpack-admin-full-screen';
314 return $classes;
315 }
316
317 /**
318 * Returns whether we are in condition to track to use
319 * Analytics functionality like Tracks, MC, or GA.
320 */
321 public static function can_use_analytics() {
322 $status = new Status();
323 $connection = new Connection_Manager();
324 $tracking = new Tracking( 'jetpack', $connection );
325
326 return $tracking->should_enable_tracking( new Terms_Of_Service(), $status );
327 }
328
329 /**
330 * Register the package's feature flags.
331 *
332 * @since 6.3.0
333 *
334 * @return void
335 */
336 public static function register_feature_flags() {
337 Feature_Flags::register(
338 self::FEATURES_TAB_FEATURE_FLAG,
339 array(
340 'default' => false,
341 'description' => 'Replace the My Jetpack Products tab with a Features tab.',
342 'owner' => 'my-jetpack',
343 )
344 );
345 }
346
347 /**
348 * Whether the dashboard shows a Features tab in place of the Products tab.
349 *
350 * @since 6.4.0
351 *
352 * @return bool
353 */
354 public static function is_features_tab_enabled() {
355 return Feature_Flags::is_enabled( self::FEATURES_TAB_FEATURE_FLAG );
356 }
357
358 /**
359 * Get the slug and label that replace the Products tab, for links to it.
360 *
361 * Null while the tab is unchanged, so links keep their own translated "Products" label.
362 *
363 * @since 6.4.0
364 *
365 * @return array{slug: string, label: string}|null
366 */
367 public static function get_products_section() {
368 if ( ! self::is_features_tab_enabled() ) {
369 return null;
370 }
371
372 return array(
373 'slug' => 'features',
374 'label' => _x( 'Features', 'Navigation item', 'jetpack-my-jetpack' ),
375 );
376 }
377
378 /**
379 * Whether the current request targets the My Jetpack admin page.
380 *
381 * @since 6.3.0
382 *
383 * @return bool
384 */
385 public static function is_my_jetpack_admin_request() {
386 if ( ! isset( $_GET['page'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
387 return false;
388 }
389
390 return sanitize_text_field( wp_unslash( $_GET['page'] ) ) === 'my-jetpack'; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
391 }
392
393 /**
394 * Whether the current request is the full-viewport onboarding takeover.
395 *
396 * Onboarding hides all wp-admin chrome and never renders through wp-build.
397 *
398 * @since 6.3.0
399 *
400 * @return bool
401 */
402 public static function is_onboarding_request() {
403 if ( ! isset( $_GET['step'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
404 return false;
405 }
406
407 return sanitize_text_field( wp_unslash( $_GET['step'] ) ) === 'onboarding'; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
408 }
409
410 /**
411 * Whether this request is the onboarding takeover rather than the dashboard.
412 *
413 * Loading wp-build, enqueueing scripts and rendering the page must all agree,
414 * so they share this one expression.
415 *
416 * @since 6.3.0
417 *
418 * @return bool
419 */
420 public static function is_onboarding_takeover() {
421 return self::is_onboarding_request() && self::is_onboarding_available();
422 }
423
424 /**
425 * Alias the screen ID to satisfy wp-build's generated enqueue check.
426 *
427 * @since 6.3.0
428 *
429 * @return void
430 */
431 public static function alias_screen_id_for_wp_build() {
432 $screen = get_current_screen();
433
434 if ( ! $screen ) {
435 return;
436 }
437
438 self::$wp_build_original_screen_id = $screen->id;
439 $screen->id = self::WP_BUILD_PAGE_ID;
440 }
441
442 /**
443 * Undo alias_screen_id_for_wp_build(), since JITM builds its message path from the screen ID.
444 *
445 * @since 6.3.0
446 *
447 * @return void
448 */
449 public static function restore_screen_id_after_wp_build() {
450 $screen = get_current_screen();
451
452 if ( ! $screen || null === self::$wp_build_original_screen_id ) {
453 return;
454 }
455
456 $screen->id = self::$wp_build_original_screen_id;
457 self::$wp_build_original_screen_id = null;
458 }
459
460 /**
461 * Whether this request should load wp-build at all.
462 *
463 * Also what keeps WP_Build_Polyfills from replacing core scripts on every other admin page.
464 *
465 * @since 6.3.0
466 *
467 * @return bool
468 */
469 public static function should_load_wp_build() {
470 return self::is_my_jetpack_admin_request() && ! self::is_onboarding_takeover();
471 }
472
473 /**
474 * Whether this request renders the dashboard through wp-build.
475 *
476 * The generated render function is missing where the package was never built.
477 *
478 * @since 6.3.0
479 *
480 * @return bool
481 */
482 public static function should_render_wp_build() {
483 return ! self::is_onboarding_takeover()
484 && function_exists( 'jetpack_my_jetpack_my_jetpack_dashboard_wp_admin_render_page' );
485 }
486
487 /**
488 * Load wp-build for the My Jetpack dashboard.
489 *
490 * @since 6.3.0
491 *
492 * @return void
493 */
494 public static function maybe_load_wp_build() {
495 if ( ! self::should_load_wp_build() ) {
496 return;
497 }
498
499 $build_index = dirname( __DIR__ ) . '/build/build.php';
500
501 if ( file_exists( $build_index ) ) {
502 self::load_wp_build( $build_index );
503 }
504 }
505
506 /**
507 * Require the generated wp-build index and wire it into this request.
508 *
509 * @since 6.3.0
510 *
511 * @param string $build_index Path to the generated `build.php`.
512 * @return void
513 */
514 public static function load_wp_build( $build_index ) {
515 // Hooked on either side of the require, so the alias holds only for the generated
516 // enqueue check it registers at the same priority.
517 add_action( 'admin_enqueue_scripts', array( __CLASS__, 'alias_screen_id_for_wp_build' ) );
518 require_once $build_index;
519 add_action( 'admin_enqueue_scripts', array( __CLASS__, 'restore_screen_id_after_wp_build' ) );
520
521 // wp-build hooks module registration to wp_default_scripts, which has
522 // already fired by admin_menu — call it directly or the init module
523 // never reaches the import map.
524 if ( function_exists( 'jetpack_my_jetpack_register_script_modules' ) ) {
525 jetpack_my_jetpack_register_script_modules(); // @phan-suppress-current-line PhanUndeclaredFunction -- Checked with function_exists(); defined in the generated build/modules.php, which Phan excludes.
526 }
527
528 WP_Build_Polyfills::register(
529 'my-jetpack',
530 array_merge( WP_Build_Polyfills::SCRIPT_HANDLES, WP_Build_Polyfills::MODULE_IDS )
531 );
532 }
533
534 /**
535 * Enqueue admin page assets.
536 *
537 * @return void
538 */
539 public static function enqueue_scripts() {
540 /**
541 * Fires after the My Jetpack page is initialized.
542 * Allows for enqueuing additional scripts only on the My Jetpack page.
543 *
544 * @since 4.35.7
545 */
546 do_action( 'myjetpack_enqueue_scripts' );
547 add_filter( 'jetpack_admin_js_script_data', array( __CLASS__, 'add_script_data' ) );
548
549 // Script-less: it only prints the state below, before the dashboard's boot runs on DOMContentLoaded.
550 $data_handle = self::DATA_SCRIPT_HANDLE;
551 wp_register_script( $data_handle, false, array(), self::PACKAGE_VERSION, true );
552 wp_enqueue_script( $data_handle );
553
554 if ( self::is_my_jetpack_admin_request() && self::is_onboarding_takeover() ) {
555 Assets::register_script(
556 self::ONBOARDING_SCRIPT_HANDLE,
557 '../build/onboarding.js',
558 __FILE__,
559 array(
560 'dependencies' => array( $data_handle ),
561 'enqueue' => true,
562 'in_footer' => true,
563 'textdomain' => 'jetpack-my-jetpack',
564 )
565 );
566 } elseif ( self::should_render_wp_build() && wp_script_is( 'wp-jp-i18n-loader', 'registered' ) ) {
567 // Registered on every admin page but only enqueued when depended on; the esbuild bundles don't pull it in.
568 wp_enqueue_script( 'wp-jp-i18n-loader' );
569 }
570
571 $modules = new Modules();
572 $connection = new Connection_Manager();
573 $speed_score_history = new Speed_Score_History( get_site_url() );
574 $latest_score = $speed_score_history->latest();
575 $previous_score = array();
576 if ( $speed_score_history->count() > 1 ) {
577 $previous_score = $speed_score_history->latest( 1 );
578 }
579 $latest_score['previousScores'] = $previous_score['scores'] ?? array();
580
581 $sandboxed_domain = '';
582 $is_dev_version = false;
583 if ( class_exists( 'Jetpack' ) ) {
584 $is_dev_version = Jetpack::is_development_version();
585 $sandboxed_domain = defined( 'JETPACK__SANDBOX_DOMAIN' ) ? JETPACK__SANDBOX_DOMAIN : '';
586 }
587
588 wp_localize_script(
589 $data_handle,
590 'myJetpackInitialState',
591 array(
592 'products' => array(
593 'items' => Products::get_products(),
594 ),
595 'plugins' => Plugins_Installer::get_plugins(),
596 'themes' => Sync_Functions::get_themes(),
597 'myJetpackUrl' => admin_url( 'admin.php?page=my-jetpack' ),
598 'myJetpackCheckoutUri' => admin_url( 'admin.php?page=my-jetpack' ),
599 'topJetpackMenuItemUrl' => Admin_Menu::get_top_level_menu_item_url(),
600 'siteSuffix' => ( new Status() )->get_site_suffix(),
601 'siteUrl' => esc_url( get_site_url() ),
602 'blogID' => Connection_Manager::get_site_id( true ),
603 'myJetpackVersion' => self::PACKAGE_VERSION,
604 'myJetpackFlags' => self::get_my_jetpack_flags(),
605 'fileSystemWriteAccess' => self::has_file_system_write_access(),
606 'loadAddLicenseScreen' => self::is_licensing_ui_enabled(),
607 'adminUrl' => esc_url( admin_url() ),
608 'assetsUrl' => self::get_assets_url(),
609 'IDCContainerID' => static::get_idc_container_id(),
610 'userIsAdmin' => current_user_can( 'manage_options' ),
611 'lifecycleStats' => array(
612 'jetpackPlugins' => self::get_installed_jetpack_plugins(),
613 'historicallyActiveModules' => \Jetpack_Options::get_option( 'historically_active_modules', array() ),
614 'brokenModules' => Red_Bubble_Notifications::check_for_broken_modules(),
615 'isSiteConnected' => $connection->is_connected(),
616 'isUserConnected' => $connection->is_user_connected(),
617 'modules' => self::get_active_modules(),
618 ),
619 'recommendedModules' => array(
620 'modules' => self::get_recommended_modules(),
621 'isFirstRun' => \Jetpack_Options::get_option( 'recommendations_first_run', true ),
622 'dismissed' => \Jetpack_Options::get_option( 'dismissed_recommendations', false ),
623 ),
624 'isStatsModuleActive' => $modules->is_active( 'stats' ),
625 'canUserViewStats' => current_user_can( 'manage_options' ) || current_user_can( 'view_stats' ),
626 'sandboxedDomain' => $sandboxed_domain,
627 'isDevVersion' => $is_dev_version,
628 'isAtomic' => ( new Status_Host() )->is_woa_site(),
629 'isJetpackPluginActive' => class_exists( 'Jetpack' ),
630 'latestBoostSpeedScores' => $latest_score,
631 'seoOptIn' => self::get_seo_opt_in_state(),
632 )
633 );
634
635 wp_localize_script(
636 $data_handle,
637 'myJetpackRest',
638 array(
639 'apiRoot' => esc_url_raw( rest_url() ),
640 'apiNonce' => wp_create_nonce( 'wp_rest' ),
641 )
642 );
643
644 // Connection Initial State.
645 Connection_Initial_State::render_script( $data_handle );
646
647 // Required for Analytics.
648 if ( self::can_use_analytics() ) {
649 Tracking::register_tracks_functions_scripts( true );
650 }
651 }
652
653 /**
654 * Add My Jetpack data to the unified script data object.
655 *
656 * @param array $data The script data.
657 * @return array
658 */
659 public static function add_script_data( $data ) {
660 $block_availability = class_exists( '\Jetpack_Gutenberg' )
661 ? \Jetpack_Gutenberg::get_cached_availability()
662 : array();
663
664 $data['myJetpack']['siteEditor'] = array(
665 'isBlockTheme' => function_exists( 'wp_is_block_theme' ) && wp_is_block_theme(),
666 'isSharingBlockAvailable' => isset( $block_availability['sharing-buttons'] )
667 && $block_availability['sharing-buttons']['available'],
668 'isLikeBlockAvailable' => isset( $block_availability['like'] )
669 && $block_availability['like']['available'],
670 'activeThemeStylesheet' => get_stylesheet(),
671 );
672
673 return $data;
674 }
675
676 /**
677 * Add the package's image base URL and products tab to the admin script data.
678 *
679 * Printed on every admin page by Script_Data, so the connection screen can resolve its
680 * illustrations and Jetpack footers can link to the products tab off the My Jetpack page.
681 *
682 * @since 6.3.0
683 *
684 * @param array $data Script data.
685 * @return array
686 */
687 public static function add_admin_script_data( $data ) {
688 $data['myJetpack']['assetsUrl'] = self::get_assets_url();
689 $data['myJetpack']['productsSection'] = self::get_products_section();
690
691 return $data;
692 }
693
694 /**
695 * Get the base URL of the package's built images, with a trailing slash.
696 *
697 * @since 6.3.0
698 *
699 * @return string
700 */
701 public static function get_assets_url() {
702 return trailingslashit( Assets::normalize_path( plugins_url( '../build/images/', __FILE__ ) ) );
703 }
704
705 /**
706 * Get installed Jetpack plugins
707 *
708 * @return array
709 */
710 public static function get_installed_jetpack_plugins() {
711 $plugin_slugs = array_keys( Plugins_Installer::get_plugins() );
712 $plugin_slugs = array_map(
713 static function ( $slug ) {
714 $parts = explode( '/', $slug );
715 // Return the last segment of the filepath without the PHP extension
716 return str_replace( '.php', '', $parts[ count( $parts ) - 1 ] );
717 },
718 $plugin_slugs
719 );
720
721 return array_values( array_intersect( self::JETPACK_PLUGIN_SLUGS, $plugin_slugs ) );
722 }
723
724 /**
725 * Get active modules (except ones enabled by default)
726 *
727 * @return array
728 */
729 public static function get_active_modules() {
730 $modules = new Modules();
731 $active_modules = $modules->get_active();
732
733 // if the Jetpack plugin is active, filter out the modules that are active by default
734 if ( class_exists( 'Jetpack' ) && ! empty( $active_modules ) ) {
735 $active_modules = array_diff( $active_modules, Jetpack::get_default_modules() );
736 }
737 return array_values( $active_modules );
738 }
739
740 /**
741 * Determine if the current user is "new" to Jetpack
742 * This is used to vary some messaging in My Jetpack
743 *
744 * On the front-end, purchases are also taken into account
745 *
746 * @return bool
747 */
748 public static function is_jetpack_user_new() {
749 // is the user connected?
750 $connection = new Connection_Manager();
751 if ( $connection->is_user_connected() ) {
752 return false;
753 }
754
755 // TODO: add a data point for the last known connection/ disconnection time
756
757 // are any modules active?
758 $active_modules = self::get_active_modules();
759 if ( ! empty( $active_modules ) ) {
760 return false;
761 }
762
763 // check for other Jetpack plugins that are installed on the site (active or not)
764 // If there's more than one Jetpack plugin active, this user is not "new"
765 $plugin_slugs = array_keys( Plugins_Installer::get_plugins() );
766 $plugin_slugs = array_map(
767 static function ( $slug ) {
768 $parts = explode( '/', $slug );
769 // Return the last segment of the filepath without the PHP extension
770 return str_replace( '.php', '', $parts[ count( $parts ) - 1 ] );
771 },
772 $plugin_slugs
773 );
774 $installed_jetpack_plugins = array_intersect( self::JETPACK_PLUGIN_SLUGS, $plugin_slugs );
775 if ( is_countable( $installed_jetpack_plugins ) && count( $installed_jetpack_plugins ) >= 2 ) {
776 return false;
777 }
778
779 // Does the site have any purchases?
780 $purchases = Wpcom_Products::get_site_current_purchases();
781 if ( ! empty( $purchases ) && ! is_wp_error( $purchases ) ) {
782 return false;
783 }
784
785 return true;
786 }
787
788 /**
789 * Build flags for My Jetpack UI
790 *
791 * @return array
792 */
793 public static function get_my_jetpack_flags() {
794 $flags = array(
795 'videoPressStats' => Jetpack_Constants::is_true( 'JETPACK_MY_JETPACK_VIDEOPRESS_STATS_ENABLED' ),
796 'showFullJetpackStatsCard' => class_exists( 'Jetpack' ),
797 // Only says which destination `manage_url` is: the legacy Stats page
798 // caches its report and wants a `force_refresh` hint the dashboard does not.
799 'premiumAnalyticsEnabled' => Products\Stats::is_premium_analytics_enabled(),
800 'showAiModuleToggle' => Products\Jetpack_Ai::is_feature_ui_enabled(),
801 );
802
803 return $flags;
804 }
805
806 /**
807 * Build the state the My Jetpack "try the new SEO experience" opt-in card hydrates from.
808 *
809 * The card invites an existing self-hosted install to switch over to the new Jetpack SEO
810 * dashboard (JETPACK-1700). Gating lives server-side, where the signals actually are. The
811 * card shows only when all of:
812 *
813 * - the new SEO product is available — the `rsm_jetpack_seo` feature filter is on (the SEO
814 * package autoloads regardless, so `class_exists()` alone isn't enough; the filter is the
815 * real availability switch and the same one the SEO package gates its own surface behind);
816 * - the site is self-hosted — WordPress.com (Simple + Atomic) decides its own SEO surface, so
817 * the opt-in card is for self-hosted installs only;
818 * - the install hasn't opted in yet — `jetpack_seo_surface_visible` is still false. On wpcom
819 * the SEO package's `is_seo_surface_visible()` short-circuits to `true`, so the
820 * "not visible yet" check also doubles as the self-hosted guard, but we check the platform
821 * explicitly for clarity.
822 *
823 * Referenced through `class_exists()` rather than a hard composer dependency: both packages
824 * ship inside the Jetpack plugin and the SEO surface is feature-flagged, so a guarded read of
825 * its public API keeps this from adding plumbing to consumers that don't load SEO.
826 *
827 * The on-success destination is computed by the opt-in endpoint itself; we only seed the card
828 * with the same admin URL so the button has a sensible fallback before the request resolves.
829 *
830 * @return array{showCard: bool, redirect: string}
831 */
832 public static function get_seo_opt_in_state() {
833 // Guard with method_exists rather than class_exists: an older bundled SEO package can ship
834 // the Initializer class without this method, and class_exists alone would still fatal.
835 $seo_initializer = 'Automattic\Jetpack\SEO\Initializer';
836 // @phan-suppress-next-line PhanUndeclaredClassReference -- optional SEO package, guarded by method_exists.
837 $show_card = method_exists( $seo_initializer, 'is_optin_available' ) && $seo_initializer::is_optin_available();
838
839 return array(
840 'showCard' => $show_card,
841 'redirect' => admin_url( 'admin.php?page=jetpack-seo' ),
842 );
843 }
844
845 /**
846 * Echoes the admin page content.
847 *
848 * @return void
849 */
850 public static function admin_page() {
851 // No connection check needed here: admin_init() has already redirected connected users
852 // away from onboarding. Availability is re-checked inside the helper on purpose — this
853 // render can run even when that redirect did not.
854 if ( self::is_onboarding_takeover() ) {
855 echo '<div id="my-jetpack-container"></div>';
856 return;
857 }
858
859 if ( self::should_render_wp_build() ) {
860 jetpack_my_jetpack_my_jetpack_dashboard_wp_admin_render_page(); // @phan-suppress-current-line PhanUndeclaredFunction -- should_render_wp_build() checks function_exists(); defined in the generated build/pages/, which Phan excludes.
861 }
862 }
863
864 /**
865 * Register the REST API routes.
866 *
867 * @return void
868 */
869 public static function register_rest_endpoints() {
870 new REST_Products();
871 new REST_Purchases();
872 new REST_Zendesk_Chat();
873 ( new REST_Jetpack_AI_JWT() )->register_rest_route();
874 new REST_Recommendations_Evaluation();
875
876 Products::register_product_endpoints();
877 Historically_Active_Modules::register_rest_endpoints();
878 Jetpack_Manage::register_rest_endpoints();
879 Red_Bubble_Notifications::register_rest_endpoints();
880
881 register_rest_route(
882 'my-jetpack/v1',
883 'site',
884 array(
885 'methods' => \WP_REST_Server::READABLE,
886 'callback' => __CLASS__ . '::get_site',
887 'permission_callback' => __CLASS__ . '::permissions_callback',
888 )
889 );
890
891 register_rest_route(
892 'my-jetpack/v1',
893 'site/dismiss-welcome-banner',
894 array(
895 'methods' => \WP_REST_Server::EDITABLE,
896 'callback' => __CLASS__ . '::dismiss_welcome_banner',
897 'permission_callback' => __CLASS__ . '::permissions_callback',
898 )
899 );
900 }
901
902 /**
903 * Check user capability to access the endpoint.
904 *
905 * @access public
906 * @static
907 *
908 * @return true|WP_Error
909 */
910 public static function permissions_callback() {
911 return current_user_can( 'manage_options' );
912 }
913
914 /**
915 * Return true if we should initialize the My Jetpack admin page.
916 */
917 public static function should_initialize() {
918 $should = true;
919
920 // All options presented in My Jetpack require a connection to WordPress.com.
921 if ( ( new Status() )->is_offline_mode() ) {
922 $should = false;
923 }
924
925 /**
926 * Allows filtering whether My Jetpack should be initialized.
927 *
928 * @since 0.5.0-alpha
929 *
930 * @param bool $shoud_initialize Should we initialize My Jetpack?
931 */
932 return apply_filters( 'jetpack_my_jetpack_should_initialize', $should );
933 }
934
935 /**
936 * Hook into several connection-based actions to update the historically active Jetpack modules
937 * If the transient that indicates the list needs to be synced, update it and delete the transient
938 *
939 * @return void
940 */
941 public static function setup_historically_active_jetpack_modules_sync() {
942 // yummmm. ham.
943 $ham = new Historically_Active_Modules();
944 if ( get_transient( $ham::UPDATE_HISTORICALLY_ACTIVE_JETPACK_MODULES_KEY ) && ! wp_doing_ajax() ) {
945 $ham::update_historically_active_jetpack_modules();
946 delete_transient( $ham::UPDATE_HISTORICALLY_ACTIVE_JETPACK_MODULES_KEY );
947 }
948
949 $actions = array(
950 'jetpack_site_registered',
951 'jetpack_user_authorized',
952 'activated_plugin',
953 );
954
955 foreach ( $actions as $action ) {
956 add_action( $action, array( $ham, 'queue_historically_active_jetpack_modules_update' ), 5 );
957 }
958
959 // Modules are often updated async, so we need to update them right away as there will sometimes be no page reload.
960 add_action( 'jetpack_activate_module', array( $ham, 'update_historically_active_jetpack_modules' ), 5 );
961 }
962
963 /**
964 * Site full-data endpoint.
965 *
966 * @return object Site data.
967 */
968 public static function get_site() {
969 $site_id = \Jetpack_Options::get_option( 'id' );
970 $wpcom_endpoint = sprintf( '/sites/%d?force=wpcom', $site_id );
971 $wpcom_api_version = '1.1';
972 $response = Client::wpcom_json_api_request_as_blog( $wpcom_endpoint, $wpcom_api_version );
973 $response_code = wp_remote_retrieve_response_code( $response );
974 $body = json_decode( wp_remote_retrieve_body( $response ) );
975
976 if ( is_wp_error( $response ) || empty( $response['body'] ) ) {
977 return new WP_Error( 'site_data_fetch_failed', 'Site data fetch failed', array( 'status' => $response_code ) );
978 }
979
980 return rest_ensure_response( $body );
981 }
982
983 /**
984 * Populates the self::$site_info var with site data from the /sites/%d endpoint
985 *
986 * @return object|WP_Error
987 */
988 public static function get_site_info() {
989 static $site_info = null;
990
991 if ( $site_info !== null ) {
992 return $site_info;
993 }
994
995 // Check for a cached value before doing lookup
996 $stored_site_info = get_transient( self::MY_JETPACK_SITE_INFO_TRANSIENT_KEY );
997 if ( $stored_site_info !== false ) {
998 return $stored_site_info;
999 }
1000
1001 $response = self::get_site();
1002 if ( is_wp_error( $response ) ) {
1003 return $response;
1004 }
1005 $site_info = $response->data;
1006 set_transient( self::MY_JETPACK_SITE_INFO_TRANSIENT_KEY, $site_info, DAY_IN_SECONDS );
1007
1008 return $site_info;
1009 }
1010
1011 /**
1012 * Returns whether a site has been determined "commercial" or not.
1013 *
1014 * @return bool|null
1015 */
1016 public static function is_commercial_site() {
1017 if ( is_wp_error( self::$site_info ) ) {
1018 return null;
1019 }
1020
1021 return empty( self::$site_info->options->is_commercial ) ? false : self::$site_info->options->is_commercial;
1022 }
1023
1024 /**
1025 * Check if site is registered (has been connected before).
1026 *
1027 * @return bool
1028 */
1029 public static function is_registered() {
1030 return (bool) \Jetpack_Options::get_option( 'id' );
1031 }
1032
1033 /**
1034 * Dismiss the welcome banner.
1035 *
1036 * @return \WP_REST_Response
1037 */
1038 public static function dismiss_welcome_banner() {
1039 \Jetpack_Options::update_option( 'dismissed_welcome_banner', true );
1040 return rest_ensure_response( array( 'success' => true ) );
1041 }
1042
1043 /**
1044 * Returns "yes" if the site has file write access to the plugins folder, "no" otherwise.
1045 *
1046 * @return string
1047 **/
1048 public static function has_file_system_write_access() {
1049
1050 $cache = get_transient( 'my_jetpack_write_access' );
1051
1052 if ( false !== $cache ) {
1053 return $cache;
1054 }
1055
1056 if ( ! function_exists( 'get_filesystem_method' ) ) {
1057 require_once ABSPATH . 'wp-admin/includes/file.php';
1058 }
1059
1060 require_once ABSPATH . 'wp-admin/includes/template.php';
1061
1062 $write_access = 'no';
1063
1064 $filesystem_method = get_filesystem_method( array(), WP_PLUGIN_DIR );
1065 if ( 'direct' === $filesystem_method ) {
1066 $write_access = 'yes';
1067 }
1068
1069 if ( 'no' === $write_access ) {
1070 ob_start();
1071 $filesystem_credentials_are_stored = request_filesystem_credentials( self_admin_url() );
1072 ob_end_clean();
1073
1074 if ( $filesystem_credentials_are_stored ) {
1075 $write_access = 'yes';
1076 }
1077 }
1078
1079 set_transient( 'my_jetpack_write_access', $write_access, 30 * MINUTE_IN_SECONDS );
1080
1081 return $write_access;
1082 }
1083
1084 /**
1085 * Get container IDC for the IDC screen.
1086 *
1087 * @return string
1088 */
1089 public static function get_idc_container_id() {
1090 return static::IDC_CONTAINER_ID;
1091 }
1092
1093 /**
1094 * Conditionally append the red bubble notification to the "Jetpack" menu item if there are alerts to show.
1095 *
1096 * On My Jetpack page: Uses blocking behavior to fetch fresh data.
1097 * On other admin pages: Uses cached data only to avoid blocking, with async JS fetch if cache is empty.
1098 *
1099 * @return void
1100 */
1101 public static function maybe_show_red_bubble() {
1102 global $pagenow;
1103
1104 // Don't show red bubble alerts for non-admin users
1105 // These alerts are generally only actionable for admins
1106 if ( ! current_user_can( 'manage_options' ) ) {
1107 return;
1108 }
1109
1110 // Don't show any red bubbles when Jetpack is disconnected
1111 // Users can't act on most alerts without a connection
1112 $connection = new Connection_Manager();
1113 if ( ! $connection->is_connected() ) {
1114 return;
1115 }
1116
1117 // Check if we're on the My Jetpack page.
1118 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1119 $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : '';
1120 $is_my_jetpack_page = $pagenow === 'admin.php' && $page === 'my-jetpack';
1121
1122 if ( $is_my_jetpack_page ) {
1123 // On My Jetpack page: use blocking behavior for fresh data.
1124 add_filter( 'my_jetpack_red_bubble_notification_slugs', array( Red_Bubble_Notifications::class, 'add_red_bubble_alerts' ) );
1125 $red_bubble_alerts = Red_Bubble_Notifications::get_red_bubble_alerts();
1126 } else {
1127 // On other pages: use cached data only to avoid blocking.
1128 $cached_alerts = Red_Bubble_Notifications::get_cached_alerts();
1129
1130 if ( false === $cached_alerts ) {
1131 // No cache: warm it asynchronously via JS. Register a hidden zero-count
1132 // placeholder so Menu_Renderer emits a `my-jetpack` badge element the
1133 // warmer can reveal (see async-notification-bubble.ts) without a reload.
1134 Menu_Badges::init(); // idempotent; wires the renderer.
1135 Notification_Counts::register(
1136 'my-jetpack',
1137 array(
1138 'menu_slug' => 'my-jetpack',
1139 'count' => 0,
1140 'type' => 'count',
1141 )
1142 );
1143 add_action( 'admin_enqueue_scripts', array( __CLASS__, 'enqueue_red_bubble_script' ) );
1144 return;
1145 }
1146
1147 $red_bubble_alerts = $cached_alerts;
1148 }
1149
1150 // Filter out silent alerts.
1151 $red_bubble_alerts = array_filter(
1152 $red_bubble_alerts,
1153 function ( $alert ) {
1154 return empty( $alert['is_silent'] );
1155 }
1156 );
1157
1158 // Report each non-silent alert to the central menu-badges registry as an
1159 // attention entry (count 1). The registry + renderer own the badge.
1160 Menu_Badges::init(); // idempotent; wires the renderer.
1161
1162 // Connection errors are owned by the Error Handler (the single source of truth):
1163 // surface any it reports for this viewer as their own attention entry. Read live
1164 // rather than from the red-bubble transient, since that cache is not viewer-keyed.
1165 $has_connection_error = self::has_connection_error();
1166 if ( $has_connection_error ) {
1167 Notification_Counts::register(
1168 'my-jetpack-connection-error',
1169 array(
1170 'menu_slug' => 'my-jetpack',
1171 'type' => 'attention',
1172 )
1173 );
1174 }
1175
1176 foreach ( array_keys( $red_bubble_alerts ) as $slug ) {
1177 // Protect reports its own count directly to the registry, but only when its
1178 // standalone plugin is active (see class-jetpack-protect.php::admin_page_init()).
1179 // If the standalone plugin isn't active, nobody else registers this count, so we
1180 // must not skip it here or the alert silently disappears from the menu total.
1181 if ( 'protect_has_threats' === $slug && Products\Protect::is_standalone_plugin_active() ) {
1182 continue;
1183 }
1184 // The missing-connection slug and a connection error describe the same broken
1185 // connection; count it once (the error, above, is the more specific signal).
1186 if ( $has_connection_error && 'missing-connection' === $slug ) {
1187 continue;
1188 }
1189 Notification_Counts::register(
1190 'my-jetpack-' . $slug,
1191 array(
1192 'menu_slug' => 'my-jetpack',
1193 'type' => 'attention',
1194 )
1195 );
1196 }
1197 }
1198
1199 /**
1200 * Whether the Connection Error Handler reports a displayable connection error
1201 * for the current viewer.
1202 *
1203 * Read live (not via the red-bubble transient): get_displayable_errors() is a
1204 * cached option read that the Error Handler already scopes and caches per viewer.
1205 * Guarded for the mid-plugin-update window, where a stale connection package
1206 * predating the method can be loaded.
1207 *
1208 * @return bool
1209 */
1210 private static function has_connection_error() {
1211 if ( ! class_exists( Connection_Error_Handler::class ) || ! method_exists( Connection_Error_Handler::class, 'get_displayable_errors' ) ) {
1212 return false;
1213 }
1214 return ! empty( Connection_Error_Handler::get_instance()->get_displayable_errors() );
1215 }
1216
1217 /**
1218 * Enqueue the notification bubble script.
1219 * Fetches fresh alert data via REST API without blocking page load.
1220 *
1221 * @return void
1222 */
1223 public static function enqueue_red_bubble_script() {
1224 Assets::register_script(
1225 'my-jetpack-notification-bubble',
1226 '../build/async-notification-bubble.js',
1227 __FILE__,
1228 array(
1229 'enqueue' => true,
1230 'in_footer' => true,
1231 )
1232 );
1233 }
1234
1235 /**
1236 * Get list of module names sorted by their recommendation score
1237 *
1238 * @return array|null
1239 */
1240 public static function get_recommended_modules() {
1241 $recommendations_evaluation = \Jetpack_Options::get_option( 'recommendations_evaluation', null );
1242
1243 if ( empty( $recommendations_evaluation ) || ! is_array( $recommendations_evaluation ) ) {
1244 return null;
1245 }
1246
1247 arsort( $recommendations_evaluation ); // Sort by scores in descending order
1248
1249 return array_keys( $recommendations_evaluation ); // Get only module names
1250 }
1251 }
1252