← All changes
|
json-endpoints/jetpack/class.jetpack-json-api-themes-new-endpoint.php
+19
-6
12.3.2
→
16.3-a.5
View file →
| @@ -1,17 +1,24 @@ | ||
| 1 | 1 | <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName |
| 2 | 2 | |
| 3 | +use Automattic\Jetpack\Automatic_Install_Skin; | |
| 4 | + | |
| 5 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 6 | + exit( 0 ); | |
| 7 | +} | |
| 8 | + | |
| 3 | 9 | require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php'; |
| 4 | 10 | require_once ABSPATH . 'wp-admin/includes/file.php'; |
| 5 | 11 | |
| 6 | -use Automattic\Jetpack\Automatic_Install_Skin; | |
| 7 | - | |
| 8 | 12 | /** |
| 9 | 13 | * Themes new endpoint class. |
| 10 | 14 | * |
| 11 | 15 | * /sites/%s/themes/%s/install |
| 16 | + * | |
| 17 | + * @phan-constructor-used-for-side-effects | |
| 12 | 18 | */ |
| 13 | 19 | class Jetpack_JSON_API_Themes_New_Endpoint extends Jetpack_JSON_API_Themes_Endpoint { |
| 20 | + use Jetpack_JSON_API_Attachment_Ownership_Trait; | |
| 14 | 21 | |
| 15 | 22 | /** |
| 16 | 23 | * Needed capabilities. |
| 17 | 24 | * |
| @@ -45,11 +52,17 @@ | ||
| 45 | 52 | protected function validate_call( $_blog_id, $capability, $check_manage_active = true ) { |
| 46 | 53 | $validate = parent::validate_call( $_blog_id, $capability, $check_manage_active ); |
| 47 | 54 | if ( is_wp_error( $validate ) ) { |
| 48 | 55 | // Lets delete the attachment... if the user doesn't have the right permissions to do things. |
| 56 | + // Only clean up an upload the caller actually owns. This runs *after* the capability check | |
| 57 | + // has already failed, so without the ownership guard any connected user could name someone | |
| 58 | + // else's attachment and have it hard-deleted on their behalf. | |
| 49 | 59 | $args = $this->input(); |
| 50 | - if ( isset( $args['zip'][0]['id'] ) ) { | |
| 51 | - wp_delete_attachment( $args['zip'][0]['id'], true ); | |
| 60 | + if ( isset( $args['zip'][0]['id'] ) && is_scalar( $args['zip'][0]['id'] ) ) { | |
| 61 | + $attachment_id = (int) $args['zip'][0]['id']; | |
| 62 | + if ( true === $this->validate_attachment_ownership( $attachment_id ) ) { | |
| 63 | + wp_delete_attachment( $attachment_id, true ); | |
| 64 | + } | |
| 52 | 65 | } |
| 53 | 66 | } |
| 54 | 67 | |
| 55 | 68 | return $validate; |
| @@ -95,10 +108,10 @@ | ||
| 95 | 108 | $after_install_list = wp_get_themes(); |
| 96 | 109 | $plugin = array_values( array_diff( array_keys( $after_install_list ), array_keys( $pre_install_list ) ) ); |
| 97 | 110 | |
| 98 | 111 | if ( ! $result ) { |
| 99 | - $error_code = $upgrader->skin->get_main_error_code(); | |
| 100 | - $message = $upgrader->skin->get_main_error_message(); | |
| 112 | + $error_code = $skin->get_main_error_code(); | |
| 113 | + $message = $skin->get_main_error_message(); | |
| 101 | 114 | if ( empty( $message ) ) { |
| 102 | 115 | $message = __( 'An unknown error occurred during installation', 'jetpack' ); |
| 103 | 116 | } |
| 104 | 117 | |