PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.5
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.5
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | json-endpoints/class.wpcom-json-api-site-settings-endpoint.php +577 -201 12.8.3 → 16.3-a.5 View file →
@@ -6,8 +6,14 @@
6 6 */
7 7
8 8 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection_Shared_Functions;
9 9
10 +if ( ! defined( 'ABSPATH' ) ) {
11 + exit( 0 );
12 +}
13 +
14 +require_once dirname( __DIR__ ) . '/modules/verification-tools/verification-tools-utils.php';
15 +
10 16 new WPCOM_JSON_API_Site_Settings_Endpoint(
11 17 array(
12 18 'description' => 'Get detailed settings information about a site.',
13 19 'group' => '__do_not_document',
@@ -44,81 +50,99 @@
44 50 '$site' => '(int|string) Site ID or domain',
45 51 ),
46 52
47 53 'request_format' => array(
48 - 'blogname' => '(string) Blog name',
49 - 'blogdescription' => '(string) Blog description',
50 - 'default_pingback_flag' => '(bool) Notify blogs linked from article?',
51 - 'default_ping_status' => '(bool) Allow link notifications from other blogs?',
52 - 'default_comment_status' => '(bool) Allow comments on new articles?',
53 - 'blog_public' => '(string) Site visibility; -1: private, 0: discourage search engines, 1: allow search engines',
54 - 'jetpack_sync_non_public_post_stati' => '(bool) allow sync of post and pages with non-public posts stati',
55 - 'jetpack_relatedposts_enabled' => '(bool) Enable related posts?',
56 - 'jetpack_relatedposts_show_context' => '(bool) Show post\'s tags and category in related posts?',
57 - 'jetpack_relatedposts_show_date' => '(bool) Show date in related posts?',
58 - 'jetpack_relatedposts_show_headline' => '(bool) Show headline in related posts?',
59 - 'jetpack_relatedposts_show_thumbnails' => '(bool) Show thumbnails in related posts?',
60 - 'jetpack_protect_whitelist' => '(array) List of IP addresses to always allow',
61 - 'instant_search_enabled' => '(bool) Enable the new Jetpack Instant Search interface',
62 - 'jetpack_search_enabled' => '(bool) Enable Jetpack Search',
63 - 'jetpack_search_supported' => '(bool) Jetpack Search is supported',
64 - 'infinite_scroll' => '(bool) Support infinite scroll of posts?',
65 - 'default_category' => '(int) Default post category',
66 - 'default_post_format' => '(string) Default post format',
67 - 'require_name_email' => '(bool) Require comment authors to fill out name and email?',
68 - 'comment_registration' => '(bool) Require users to be registered and logged in to comment?',
69 - 'close_comments_for_old_posts' => '(bool) Automatically close comments on old posts?',
70 - 'close_comments_days_old' => '(int) Age at which to close comments',
71 - 'thread_comments' => '(bool) Enable threaded comments?',
72 - 'thread_comments_depth' => '(int) Depth to thread comments',
73 - 'page_comments' => '(bool) Break comments into pages?',
74 - 'comments_per_page' => '(int) Number of comments to display per page',
75 - 'default_comments_page' => '(string) newest|oldest Which page of comments to display first',
76 - 'comment_order' => '(string) asc|desc Order to display comments within page',
77 - 'comments_notify' => '(bool) Email me when someone comments?',
78 - 'moderation_notify' => '(bool) Email me when a comment is helf for moderation?',
79 - 'social_notifications_like' => '(bool) Email me when someone likes my post?',
80 - 'social_notifications_reblog' => '(bool) Email me when someone reblogs my post?',
81 - 'social_notifications_subscribe' => '(bool) Email me when someone follows my blog?',
82 - 'comment_moderation' => '(bool) Moderate comments for manual approval?',
83 - 'comment_previously_approved' => '(bool) Moderate comments unless author has a previously-approved comment?',
84 - 'comment_max_links' => '(int) Moderate comments that contain X or more links',
85 - 'moderation_keys' => '(string) Words or phrases that trigger comment moderation, one per line',
86 - 'disallowed_keys' => '(string) Words or phrases that mark comment spam, one per line',
87 - 'lang_id' => '(int) ID for language blog is written in',
88 - 'wga' => '(array) Google Analytics Settings',
89 - 'disabled_likes' => '(bool) Are likes globally disabled (they can still be turned on per post)?',
90 - 'disabled_reblogs' => '(bool) Are reblogs disabled on posts?',
91 - 'jetpack_comment_likes_enabled' => '(bool) Are comment likes enabled for all comments?',
92 - 'sharing_button_style' => '(string) Style to use for sharing buttons (icon-text, icon, text, or official)',
93 - 'sharing_label' => '(string) Label to use for sharing buttons, e.g. "Share this:"',
94 - 'sharing_show' => '(string|array:string) Post type or array of types where sharing buttons are to be displayed',
95 - 'sharing_open_links' => '(string) Link target for sharing buttons (same or new)',
96 - 'twitter_via' => '(string) Twitter username to include in tweets when people share using the Twitter button',
97 - 'jetpack-twitter-cards-site-tag' => '(string) The Twitter username of the owner of the site\'s domain.',
98 - 'eventbrite_api_token' => '(int) The Keyring token ID for an Eventbrite token to associate with the site',
99 - 'timezone_string' => '(string) PHP-compatible timezone string like \'UTC-5\'',
100 - 'gmt_offset' => '(int) Site offset from UTC in hours',
101 - 'date_format' => '(string) PHP Date-compatible date format',
102 - 'time_format' => '(string) PHP Date-compatible time format',
103 - 'start_of_week' => '(int) Starting day of week (0 = Sunday, 6 = Saturday)',
104 - 'jetpack_testimonial' => '(bool) Whether testimonial custom post type is enabled for the site',
105 - 'jetpack_testimonial_posts_per_page' => '(int) Number of testimonials to show per page',
106 - 'jetpack_portfolio' => '(bool) Whether portfolio custom post type is enabled for the site',
107 - 'jetpack_portfolio_posts_per_page' => '(int) Number of portfolio projects to show per page',
108 - Jetpack_SEO_Utils::FRONT_PAGE_META_OPTION => '(string) The seo meta description for the site.',
109 - Jetpack_SEO_Titles::TITLE_FORMATS_OPTION => '(array) SEO meta title formats. Allowed keys: front_page, posts, pages, groups, archives',
110 - 'verification_services_codes' => '(array) Website verification codes. Allowed keys: google, pinterest, bing, yandex, facebook',
111 - 'markdown_supported' => '(bool) Whether markdown is supported for this site',
112 - 'wpcom_publish_posts_with_markdown' => '(bool) Whether markdown is enabled for posts',
113 - 'wpcom_publish_comments_with_markdown' => '(bool) Whether markdown is enabled for comments',
114 - 'site_icon' => '(int) Media attachment ID to use as site icon. Set to zero or an otherwise empty value to clear',
115 - 'api_cache' => '(bool) Turn on/off the Jetpack JSON API cache',
116 - 'posts_per_page' => '(int) Number of posts to show on blog pages',
117 - 'posts_per_rss' => '(int) Number of posts to show in the RSS feed',
118 - 'rss_use_excerpt' => '(bool) Whether the RSS feed will use post excerpts',
119 - 'launchpad_screen' => '(string) Whether or not launchpad is presented and what size it will be',
120 - 'sm_enabled' => '(bool) Whether the newsletter subscribe modal is enabled',
54 + 'migration_source_site_domain' => '(string) The source site URL, from the migration flow',
55 + 'in_site_migration_flow' => '(string) The migration flow the site is in',
56 + 'blogname' => '(string) Blog name',
57 + 'blogdescription' => '(string) Blog description',
58 + 'default_pingback_flag' => '(bool) Notify blogs linked from article?',
59 + 'default_ping_status' => '(bool) Allow link notifications from other blogs?',
60 + 'default_comment_status' => '(bool) Allow comments on new articles?',
61 + 'blog_public' => '(string) Site visibility; -1: private, 0: discourage search engines, 1: allow search engines',
62 + 'wpcom_data_sharing_opt_out' => '(bool) Did the site opt out of sharing public content with third parties and research partners?',
63 + 'jetpack_sync_non_public_post_stati' => '(bool) allow sync of post and pages with non-public posts stati',
64 + 'jetpack_relatedposts_enabled' => '(bool) Enable related posts?',
65 + 'jetpack_relatedposts_show_context' => '(bool) Show post\'s tags and category in related posts?',
66 + 'jetpack_relatedposts_show_date' => '(bool) Show date in related posts?',
67 + 'jetpack_relatedposts_show_headline' => '(bool) Show headline in related posts?',
68 + 'jetpack_relatedposts_show_thumbnails' => '(bool) Show thumbnails in related posts?',
69 + 'jetpack_protect_whitelist' => '(array) List of IP addresses to always allow',
70 + 'instant_search_enabled' => '(bool) Enable the new Jetpack Instant Search interface',
71 + 'jetpack_search_enabled' => '(bool) Enable Jetpack Search',
72 + 'jetpack_search_supported' => '(bool) Jetpack Search is supported',
73 + 'infinite_scroll' => '(bool) Support infinite scroll of posts?',
74 + 'default_category' => '(int) Default post category',
75 + 'default_post_format' => '(string) Default post format',
76 + 'require_name_email' => '(bool) Require comment authors to fill out name and email?',
77 + 'comment_registration' => '(bool) Require users to be registered and logged in to comment?',
78 + 'close_comments_for_old_posts' => '(bool) Automatically close comments on old posts?',
79 + 'close_comments_days_old' => '(int) Age at which to close comments',
80 + 'thread_comments' => '(bool) Enable threaded comments?',
81 + 'thread_comments_depth' => '(int) Depth to thread comments',
82 + 'page_comments' => '(bool) Break comments into pages?',
83 + 'comments_per_page' => '(int) Number of comments to display per page',
84 + 'default_comments_page' => '(string) newest|oldest Which page of comments to display first',
85 + 'comment_order' => '(string) asc|desc Order to display comments within page',
86 + 'comments_notify' => '(bool) Email me when someone comments?',
87 + 'moderation_notify' => '(bool) Email me when a comment is helf for moderation?',
88 + 'social_notifications_like' => '(bool) Email me when someone likes my post?',
89 + 'social_notifications_reblog' => '(bool) Email me when someone reblogs my post?',
90 + 'social_notifications_subscribe' => '(bool) Email me when someone subscribes to my blog?',
91 + 'comment_moderation' => '(bool) Moderate comments for manual approval?',
92 + 'comment_previously_approved' => '(bool) Moderate comments unless author has a previously-approved comment?',
93 + 'comment_max_links' => '(int) Moderate comments that contain X or more links',
94 + 'moderation_keys' => '(string) Words or phrases that trigger comment moderation, one per line',
95 + 'disallowed_keys' => '(string) Words or phrases that mark comment spam, one per line',
96 + 'lang_id' => '(int) ID for language blog is written in',
97 + 'wga' => '(array) Google Analytics Settings',
98 + 'disabled_likes' => '(bool) Are likes globally disabled (they can still be turned on per post)?',
99 + 'disabled_reblogs' => '(bool) Are reblogs disabled on posts?',
100 + 'jetpack_comment_likes_enabled' => '(bool) Are comment likes enabled for all comments?',
101 + 'sharing_button_style' => '(string) Style to use for sharing buttons (icon-text, icon, text, or official)',
102 + 'sharing_label' => '(string) Label to use for sharing buttons, e.g. "Share this:"',
103 + 'sharing_show' => '(string|array:string) Post type or array of types where sharing buttons are to be displayed',
104 + 'sharing_open_links' => '(string) Link target for sharing buttons (same or new)',
105 + 'twitter_via' => '(string) Twitter username to include in tweets when people share using the Twitter button',
106 + 'jetpack-twitter-cards-site-tag' => '(string) The Twitter username of the owner of the site\'s domain.',
107 + 'eventbrite_api_token' => '(int) The Keyring token ID for an Eventbrite token to associate with the site',
108 + 'timezone_string' => '(string) PHP-compatible timezone string like \'UTC-5\'',
109 + 'gmt_offset' => '(int) Site offset from UTC in hours',
110 + 'date_format' => '(string) PHP Date-compatible date format',
111 + 'time_format' => '(string) PHP Date-compatible time format',
112 + 'start_of_week' => '(int) Starting day of week (0 = Sunday, 6 = Saturday)',
113 + 'jetpack_testimonial' => '(bool) Whether testimonial custom post type is enabled for the site',
114 + 'jetpack_testimonial_posts_per_page' => '(int) Number of testimonials to show per page',
115 + 'jetpack_portfolio' => '(bool) Whether portfolio custom post type is enabled for the site',
116 + 'jetpack_portfolio_posts_per_page' => '(int) Number of portfolio projects to show per page',
117 + Jetpack_SEO_Utils::FRONT_PAGE_META_OPTION => '(string) The seo meta description for the site.',
118 + Jetpack_SEO_Titles::TITLE_FORMATS_OPTION => '(array) SEO meta title formats. Allowed keys: front_page, posts, pages, groups, archives',
119 + 'verification_services_codes' => '(array) Website verification codes. Allowed keys: google, pinterest, bing, yandex, facebook',
120 + 'markdown_supported' => '(bool) Whether markdown is supported for this site',
121 + 'wpcom_publish_posts_with_markdown' => '(bool) Whether markdown is enabled for posts',
122 + 'wpcom_publish_comments_with_markdown' => '(bool) Whether markdown is enabled for comments',
123 + 'site_icon' => '(int) Media attachment ID to use as site icon. Set to zero or an otherwise empty value to clear',
124 + 'api_cache' => '(bool) Turn on/off the Jetpack JSON API cache',
125 + 'posts_per_page' => '(int) Number of posts to show on blog pages',
126 + 'posts_per_rss' => '(int) Number of posts to show in the RSS feed',
127 + 'rss_use_excerpt' => '(bool) Whether the RSS feed will use post excerpts',
128 + 'launchpad_screen' => '(string) Whether or not launchpad is presented and what size it will be',
129 + 'sm_enabled' => '(bool) Whether the newsletter subscribe modal is enabled',
130 + 'jetpack_subscribe_overlay_enabled' => '(bool) Whether the newsletter subscribe overlay is enabled',
131 + 'jetpack_subscribe_floating_button_enabled' => '(bool) Whether the newsletter floating subscribe button is enabled',
132 + 'jetpack_subscriptions_subscribe_post_end_enabled' => '(bool) Whether the Subscribe block at the end of each post placement is enabled',
133 + 'jetpack_subscriptions_login_navigation_enabled' => '(bool) Whether the Subscriber Login block navigation placement is enabled',
134 + 'jetpack_subscriptions_subscribe_navigation_enabled' => '(Bool) Whether the Subscribe block navigation placement is enabled',
135 + 'wpcom_ai_site_prompt' => '(string) User input in the AI site prompt',
136 + 'jetpack_waf_automatic_rules' => '(bool) Whether the WAF should enforce automatic firewall rules',
137 + 'jetpack_waf_ip_allow_list' => '(string) List of IP addresses to always allow',
138 + 'jetpack_waf_ip_allow_list_enabled' => '(bool) Whether the IP allow list is enabled',
139 + 'jetpack_waf_ip_block_list' => '(string) List of IP addresses the WAF should always block',
140 + 'jetpack_waf_ip_block_list_enabled' => '(bool) Whether the IP block list is enabled',
141 + 'jetpack_waf_share_data' => '(bool) Whether the WAF should share basic data with Jetpack',
142 + 'jetpack_waf_share_debug_data' => '(bool) Whether the WAF should share debug data with Jetpack',
143 + 'jetpack_waf_automatic_rules_last_updated_timestamp' => '(int) Timestamp of the last time the automatic rules were updated',
144 + 'mcp_abilities' => '(array) List of MCP Abilities',
121 145 ),
122 146
123 147 'response_format' => array(
124 148 'updated' => '(array)',
@@ -129,8 +153,10 @@
129 153 );
130 154
131 155 /**
132 156 * Manage Site settings endpoint.
157 + *
158 + * @phan-constructor-used-for-side-effects
133 159 */
134 160 class WPCOM_JSON_API_Site_Settings_Endpoint extends WPCOM_JSON_API_Endpoint {
135 161
136 162 /**
@@ -202,9 +228,9 @@
202 228 * @see the_neverending_home_page_theme_support
203 229 *
204 230 * @param array $copy_dirs Array of files to be included in theme context.
205 231 */
206 - public function wpcom_restapi_copy_theme_plugin_actions( $copy_dirs ) {
232 + public static function wpcom_restapi_copy_theme_plugin_actions( $copy_dirs ) {
207 233 $theme_name = get_stylesheet();
208 234 $default_file_name = WP_CONTENT_DIR . "/mu-plugins/infinity/themes/{$theme_name}.php";
209 235
210 236 /**
@@ -310,12 +336,14 @@
310 336 case 'ID':
311 337 $response[ $key ] = $blog_id;
312 338 break;
313 339 case 'name':
314 - $response[ $key ] = (string) htmlspecialchars_decode( get_bloginfo( 'name' ), ENT_QUOTES );
340 + $name = get_bloginfo( 'name' );
341 + $response[ $key ] = is_string( $name ) ? htmlspecialchars_decode( $name, ENT_QUOTES ) : '';
315 342 break;
316 343 case 'description':
317 - $response[ $key ] = (string) htmlspecialchars_decode( get_bloginfo( 'description' ), ENT_QUOTES );
344 + $description = get_bloginfo( 'description' );
345 + $response[ $key ] = is_string( $description ) ? htmlspecialchars_decode( $description, ENT_QUOTES ) : '';
318 346 break;
319 347 case 'URL':
320 348 $response[ $key ] = (string) home_url();
321 349 break;
@@ -354,18 +382,19 @@
354 382 get_categories( array( 'hide_empty' => false ) )
355 383 )
356 384 );
357 385
358 - $newsletter_categories = maybe_unserialize( get_option( 'wpcom_newsletter_categories', array() ) );
359 - $newsletter_category_ids = array_map(
360 - function ( $newsletter_category ) {
361 - return $newsletter_category['term_id'];
362 - },
363 - $newsletter_categories
364 - );
386 + // Make sure we are returning a consistent type
387 + if ( ! class_exists( 'Jetpack_Newsletter_Category_Helper' ) ) {
388 + require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-newsletter-category-helper.php';
389 + }
390 + $newsletter_category_ids = Jetpack_Newsletter_Category_Helper::get_category_ids();
365 391
366 392 $api_cache = $site->is_jetpack() ? (bool) get_option( 'jetpack_api_cache_enabled' ) : true;
367 393
394 + // Get Sites MCP settings
395 + $mcp_abilities = $this->get_site_mcp_abilities();
396 +
368 397 $response[ $key ] = array(
369 398 // also exists as "options".
370 399 'admin_url' => get_admin_url(),
371 400 'default_ping_status' => 'closed' !== get_option( 'default_ping_status' ),
@@ -373,8 +402,9 @@
373 402
374 403 // new stuff starts here.
375 404 'instant_search_enabled' => (bool) get_option( 'instant_search_enabled' ),
376 405 'blog_public' => (int) get_option( 'blog_public' ),
406 + 'wpcom_data_sharing_opt_out' => (bool) get_option( 'wpcom_data_sharing_opt_out' ),
377 407 'jetpack_sync_non_public_post_stati' => (bool) Jetpack_Options::get_option( 'sync_non_public_post_stati' ),
378 408 'jetpack_relatedposts_allowed' => (bool) $this->jetpack_relatedposts_supported(),
379 409 'jetpack_relatedposts_enabled' => (bool) $jetpack_relatedposts_options['enabled'],
380 410 'jetpack_relatedposts_show_context' => ! empty( $jetpack_relatedposts_options['show_context'] ),
@@ -380,9 +410,9 @@
380 410 'jetpack_relatedposts_show_context' => ! empty( $jetpack_relatedposts_options['show_context'] ),
381 411 'jetpack_relatedposts_show_date' => ! empty( $jetpack_relatedposts_options['show_date'] ),
382 412 'jetpack_relatedposts_show_headline' => ! empty( $jetpack_relatedposts_options['show_headline'] ),
383 413 'jetpack_relatedposts_show_thumbnails' => ! empty( $jetpack_relatedposts_options['show_thumbnails'] ),
384 - 'jetpack_search_enabled' => (bool) $jetpack_search_active,
414 + 'jetpack_search_enabled' => $jetpack_search_active,
385 415 'jetpack_search_supported' => (bool) $jetpack_search_supported,
386 416 'default_category' => (int) get_option( 'default_category' ),
387 417 'post_categories' => (array) $post_categories,
388 418 'default_post_format' => get_option( 'default_post_format' ),
@@ -412,9 +442,8 @@
412 442 'lang_id' => defined( 'IS_WPCOM' ) && IS_WPCOM
413 443 ? get_lang_id_by_code( wpcom_l10n_get_blog_locale_variant( $blog_id, true ) )
414 444 : get_option( 'lang_id' ),
415 445 'site_vertical_id' => (string) get_option( 'site_vertical_id' ),
416 - 'wga' => $this->get_google_analytics(),
417 446 'jetpack_cloudflare_analytics' => get_option( 'jetpack_cloudflare_analytics' ),
418 447 'disabled_likes' => (bool) get_option( 'disabled_likes' ),
419 448 'disabled_reblogs' => (bool) get_option( 'disabled_reblogs' ),
420 449 'jetpack_comment_likes_enabled' => (bool) get_option( 'jetpack_comment_likes_enabled', false ),
@@ -439,26 +468,79 @@
439 468 'markdown_supported' => true,
440 469 'site_icon' => $this->get_cast_option_value_or_null( 'site_icon', 'intval' ),
441 470 Jetpack_SEO_Utils::FRONT_PAGE_META_OPTION => get_option( Jetpack_SEO_Utils::FRONT_PAGE_META_OPTION, '' ),
442 471 Jetpack_SEO_Titles::TITLE_FORMATS_OPTION => get_option( Jetpack_SEO_Titles::TITLE_FORMATS_OPTION, array() ),
472 + 'verification_services_codes' => get_option( 'verification_services_codes', null ),
443 473 'api_cache' => $api_cache,
444 474 'posts_per_page' => (int) get_option( 'posts_per_page' ),
445 475 'posts_per_rss' => (int) get_option( 'posts_per_rss' ),
446 476 'rss_use_excerpt' => (bool) get_option( 'rss_use_excerpt' ),
447 477 'launchpad_screen' => (string) get_option( 'launchpad_screen' ),
448 - 'wpcom_featured_image_in_email' => (bool) get_option( 'wpcom_featured_image_in_email' ),
478 + 'wpcom_newsletter_send_default' => (bool) get_option( 'wpcom_newsletter_send_default', true ),
479 + 'wpcom_featured_image_in_email' => ( function () use ( $site ) {
480 + if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
481 + $registered_date = method_exists( $site, 'get_registered_date' ) ? $site->get_registered_date() : '';
482 + // Compare to May 2, 2025 (ISO 8601 format)
483 + if ( $registered_date && $registered_date !== '0000-00-00T00:00:00+00:00' && strtotime( $registered_date ) >= strtotime( '2025-05-02T00:00:00+00:00' ) ) {
484 + return (bool) get_option( 'wpcom_featured_image_in_email', true );
485 + }
486 + }
487 + // For all other sites, use the saved value or default to false for legacy behavior.
488 + return (bool) get_option( 'wpcom_featured_image_in_email', false );
489 + } )(),
490 + 'jetpack_gravatar_in_email' => (bool) get_option( 'jetpack_gravatar_in_email', true ),
491 + 'jetpack_author_in_email' => (bool) get_option( 'jetpack_author_in_email', true ),
492 + 'jetpack_post_date_in_email' => (bool) get_option( 'jetpack_post_date_in_email', true ),
449 493 'wpcom_newsletter_categories' => $newsletter_category_ids,
450 494 'wpcom_newsletter_categories_enabled' => (bool) get_option( 'wpcom_newsletter_categories_enabled' ),
451 495 'sm_enabled' => (bool) get_option( 'sm_enabled' ),
496 + 'jetpack_subscribe_overlay_enabled' => (bool) get_option( 'jetpack_subscribe_overlay_enabled' ),
497 + 'jetpack_subscribe_floating_button_enabled' => (bool) get_option( 'jetpack_subscribe_floating_button_enabled' ),
498 + 'jetpack_subscriptions_subscribe_post_end_enabled' => (bool) get_option( 'jetpack_subscriptions_subscribe_post_end_enabled' ),
499 + 'jetpack_subscriptions_login_navigation_enabled' => (bool) get_option( 'jetpack_subscriptions_login_navigation_enabled' ),
500 + 'jetpack_subscriptions_subscribe_navigation_enabled' => (bool) get_option( 'jetpack_subscriptions_subscribe_navigation_enabled' ),
452 501 'wpcom_gifting_subscription' => (bool) get_option( 'wpcom_gifting_subscription', $this->get_wpcom_gifting_subscription_default() ),
453 502 'wpcom_reader_views_enabled' => (bool) get_option( 'wpcom_reader_views_enabled', true ),
454 - 'wpcom_subscription_emails_use_excerpt' => $this->get_wpcom_subscription_emails_use_excerpt_option(),
503 + 'wpcom_subscription_emails_use_excerpt' => (bool) get_option( 'wpcom_subscription_emails_use_excerpt' ),
504 + 'jetpack_subscriptions_reply_to' => (string) $this->get_subscriptions_reply_to_option(),
505 + 'jetpack_subscriptions_from_name' => (string) get_option( 'jetpack_subscriptions_from_name' ),
455 506 'show_on_front' => (string) get_option( 'show_on_front' ),
456 507 'page_on_front' => (string) get_option( 'page_on_front' ),
457 508 'page_for_posts' => (string) get_option( 'page_for_posts' ),
458 - 'subscription_options' => (array) get_option( 'subscription_options' ),
509 + 'subscription_options' => $this->get_subscription_options_in_user_locale(),
510 + 'supports_free_tier_customization' => true,
511 + 'jetpack_verbum_subscription_modal' => (bool) get_option( 'jetpack_verbum_subscription_modal', true ),
512 + 'enable_verbum_commenting' => (bool) get_option( 'enable_verbum_commenting', true ),
513 + 'enable_blocks_comments' => (bool) get_option( 'enable_blocks_comments', true ),
514 + 'highlander_comment_form_prompt' => $this->get_highlander_comment_form_prompt_option(),
515 + 'jetpack_comment_form_color_scheme' => (string) get_option( 'jetpack_comment_form_color_scheme' ),
516 + 'in_site_migration_flow' => (string) get_option( 'in_site_migration_flow', '' ),
517 + 'migration_source_site_domain' => (string) get_option( 'migration_source_site_domain' ),
518 + 'jetpack_waf_automatic_rules' => (bool) get_option( 'jetpack_waf_automatic_rules' ),
519 + 'jetpack_waf_ip_allow_list' => (string) get_option( 'jetpack_waf_ip_allow_list' ),
520 + 'jetpack_waf_ip_allow_list_enabled' => (bool) get_option( 'jetpack_waf_ip_allow_list_enabled' ),
521 + 'jetpack_waf_ip_block_list' => (string) get_option( 'jetpack_waf_ip_block_list' ),
522 + 'jetpack_waf_ip_block_list_enabled' => (bool) get_option( 'jetpack_waf_ip_block_list_enabled' ),
523 + 'jetpack_waf_share_data' => (bool) get_option( 'jetpack_waf_share_data' ),
524 + 'jetpack_waf_share_debug_data' => (bool) get_option( 'jetpack_waf_share_debug_data' ),
525 + 'jetpack_waf_automatic_rules_last_updated_timestamp' => (int) get_option( 'jetpack_waf_automatic_rules_last_updated_timestamp' ),
526 + 'is_fully_managed_agency_site' => (bool) get_option( 'is_fully_managed_agency_site' ),
527 + 'wpcom_hide_action_bar' => (bool) get_option( 'wpcom_hide_action_bar' ),
528 + 'mcp_abilities' => $mcp_abilities,
459 529 );
460 530
531 + require_once JETPACK__PLUGIN_DIR . '/modules/memberships/class-jetpack-memberships.php';
532 + if ( class_exists( 'Jetpack_Memberships' ) ) {
533 + $response[ $key ]['newsletter_has_active_plan'] = count( Jetpack_Memberships::get_all_newsletter_plan_ids( false ) ) > 0;
534 + // Read-only/derived: the free tier's markdown description rendered to
535 + // safe HTML, colocated with subscription_options so it's
536 + // read-after-write consistent. Not part of the writable
537 + // subscription_options bag (which would round-trip and persist it).
538 + $response[ $key ]['free_tier_description_rendered'] = Jetpack_Memberships::render_tier_description_html(
539 + ( (array) get_option( 'subscription_options' ) )['free_tier_description'] ?? ''
540 + );
541 + }
542 +
461 543 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
462 544 $response[ $key ]['wpcom_publish_posts_with_markdown'] = (bool) WPCom_Markdown::get_instance()->is_posting_enabled();
463 545 $response[ $key ]['wpcom_publish_comments_with_markdown'] = (bool) WPCom_Markdown::get_instance()->is_commenting_enabled();
464 546
@@ -489,12 +571,14 @@
489 571 *
490 572 * @module json-api
491 573 *
492 574 * @since 3.9.3
575 + * @since 13.6 Added the API object parameter.
493 576 *
494 577 * @param mixed $response_item A single site setting.
578 + * @param WPCOM_JSON_API_Site_Settings_Endpoint $this The API object.
495 579 */
496 - $response[ $key ] = apply_filters( 'site_settings_endpoint_get', $response[ $key ] );
580 + $response[ $key ] = apply_filters( 'site_settings_endpoint_get', $response[ $key ], $this );
497 581
498 582 if ( class_exists( 'Sharing_Service' ) ) {
499 583 $ss = new Sharing_Service();
500 584 $sharing = $ss->get_global_options();
@@ -532,9 +616,9 @@
532 616 * - 54 days before the annual plan expiration.
533 617 * - 5 days before the monthly plan expiration.
534 618 * This is to match the gifting banner logic.
535 619 */
536 - $days_of_warning = false !== strpos( $purchase->product_slug, 'monthly' ) ? 5 : 54;
620 + $days_of_warning = str_contains( $purchase->product_slug, 'monthly' ) ? 5 : 54;
537 621 $seconds_until_expiration = strtotime( $purchase->expiry_date ) - time();
538 622 if ( $seconds_until_expiration >= $days_of_warning * DAY_IN_SECONDS ) {
539 623 return false;
540 624 }
@@ -551,8 +635,157 @@
551 635 return false;
552 636 }
553 637
554 638 /**
639 + * Reads `subscription_options` with the current user's locale active, to
640 + * ensure that the defaults would be translated when displaying to the user
641 + * or comparing the options before saving.
642 + *
643 + * @return array The `subscription_options` value, defaults included.
644 + */
645 + private function get_subscription_options_in_user_locale() {
646 + $switched_locale = false;
647 +
648 + if ( function_exists( 'wpcom_switch_to_user_locale' ) ) {
649 + // Compare the locales before/after switch to decide if we should switch back
650 + $locale_before = determine_locale();
651 + wpcom_switch_to_user_locale();
652 + $switched_locale = determine_locale() !== $locale_before;
653 + }
654 +
655 + // Resolve the defaults the same way get_option() does for a missing row (via the
656 + // `default_option_*` filter with $passed_default = false), then let any stored
657 + // sub-keys take precedence. Passing an array default keeps get_option() from
658 + // re-populating the defaults, so a partial row stays partial before the merge.
659 + $default_subscription_options = (array) apply_filters( 'default_option_subscription_options', array(), 'subscription_options', false );
660 + $stored_subscription_options = (array) get_option( 'subscription_options', array() );
661 + $subscription_options = array_merge( $default_subscription_options, $stored_subscription_options );
662 +
663 + if ( $switched_locale ) {
664 + restore_previous_locale();
665 + }
666 +
667 + return $subscription_options;
668 + }
669 +
670 + /**
671 + * Get list of all site level MCP abilities.
672 + *
673 + * @return array
674 + */
675 + private function get_all_site_mcp_abilities(): array {
676 + $all_abilities = array();
677 + $ability_registry_file = WP_CONTENT_DIR . '/mu-plugins/wpcom-mcp/includes/AbilitiesRegistry/Registry/AbilityRegistry.php';
678 + if ( file_exists( $ability_registry_file ) ) {
679 + require_once $ability_registry_file;
680 + // @phan-suppress-next-line PhanUndeclaredClassMethod
681 + $abilities_resources = Automattic\WpcomMcp\AbilitiesRegistry\Registry\AbilityRegistry::get_resources_for_server( 'site-level' );
682 + // @phan-suppress-next-line PhanUndeclaredClassMethod
683 + $abilities_tools = Automattic\WpcomMcp\AbilitiesRegistry\Registry\AbilityRegistry::get_tools_for_server( 'site-level' );
684 + // @phan-suppress-next-line PhanUndeclaredClassMethod
685 + $abilities_prompts = Automattic\WpcomMcp\AbilitiesRegistry\Registry\AbilityRegistry::get_prompts_for_server( 'site-level' );
686 + $all_abilities = array_merge( $abilities_resources, $abilities_tools, $abilities_prompts );
687 + }
688 + return apply_filters( 'jetpack_site_mcp_abilities', $all_abilities );
689 + }
690 +
691 + /**
692 + * Get ability meta from config.
693 + *
694 + * @param string $ability_name Ability name, i.e. wpcom-mcp/posts-search.
695 + *
696 + * @return array
697 + */
698 + private function get_mcp_abilities_metadata( string $ability_name ): array {
699 + $ability_meta = array();
700 + $ability_registry_file = WP_CONTENT_DIR . '/mu-plugins/wpcom-mcp/includes/AbilitiesRegistry/Registry/AbilityRegistry.php';
701 + if ( file_exists( $ability_registry_file ) ) {
702 + require_once $ability_registry_file;
703 + // @phan-suppress-next-line PhanUndeclaredClassMethod
704 + $ability_meta = Automattic\WpcomMcp\AbilitiesRegistry\Registry\AbilityRegistry::get_metadata( $ability_name );
705 + }
706 + return apply_filters( 'jetpack_site_mcp_ability_meta', $ability_meta, $ability_name );
707 + }
708 +
709 + /**
710 + * Get MCP abilities for the current site.
711 + *
712 + * @return array
713 + */
714 + public function get_site_mcp_abilities(): array {
715 + $current_mcp_abilities = get_option( 'mcp_abilities', array() );
716 + if ( ! is_array( $current_mcp_abilities ) ) {
717 + $current_mcp_abilities = array();
718 + }
719 +
720 + $all_abilities = $this->get_all_site_mcp_abilities();
721 + if ( empty( $all_abilities ) ) {
722 + return array();
723 + }
724 +
725 + $computed_abilities = array();
726 + foreach ( $all_abilities as $ability_name ) {
727 + // Get base metadata first
728 + $ability_meta = $this->get_mcp_abilities_metadata( $ability_name );
729 + if ( ! empty( $ability_meta ) ) {
730 + // Use stored value or fall back to metadata default
731 + $enabled = $current_mcp_abilities[ $ability_name ] ?? $ability_meta['enabled'] ?? false;
732 +
733 + $computed_abilities[ $ability_name ] = array(
734 + 'name' => $ability_name,
735 + 'title' => $ability_meta['title'] ?? '',
736 + 'description' => $ability_meta['description'] ?? '',
737 + 'category' => $ability_meta['category'] ?? '',
738 + 'type' => $ability_meta['type'] ?? '',
739 + 'enabled' => (bool) $enabled,
740 + );
741 + }
742 + }
743 + return $computed_abilities;
744 + }
745 +
746 + /**
747 + * Sets the MCP abilities for the current site.
748 + *
749 + * @param mixed $value MCP abilities array.
750 + *
751 + * @return true|WP_Error
752 + */
753 + public function set_site_mcp_abilities( $value ) {
754 + // Validate input format
755 + if ( ! is_array( $value ) ) {
756 + return new WP_Error( 'invalid_format', __( 'Site MCP abilities must be an array', 'jetpack' ) );
757 + }
758 +
759 + $all_abilities = $this->get_all_site_mcp_abilities();
760 +
761 + // Filter ability names that don't exist
762 + $value = array_filter(
763 + $value,
764 + function ( $ability_name ) use ( $all_abilities ) {
765 + return in_array( $ability_name, $all_abilities, true );
766 + },
767 + ARRAY_FILTER_USE_KEY
768 + );
769 +
770 + // Validate each ability exists and value is boolean-like
771 + foreach ( $value as $ability_name => $enabled ) {
772 + if ( ! is_string( $ability_name ) || ( ! WPCOM_JSON_API::is_truthy( $enabled ) && ! WPCOM_JSON_API::is_falsy( $enabled ) ) ) {
773 + $error_message = sprintf(
774 + // Translators: %s is an MCP ability name
775 + __( 'Invalid ability: %s', 'jetpack' ),
776 + $ability_name
777 + );
778 + return new WP_Error( 'invalid_ability', $error_message );
779 + }
780 + }
781 +
782 + update_option( 'mcp_abilities', $value );
783 +
784 + return true;
785 + }
786 +
787 + /**
555 788 * Get locale.
556 789 *
557 790 * @param string $key Language.
558 791 */
@@ -568,31 +801,11 @@
568 801 return false;
569 802 }
570 803
571 804 /**
572 - * Get GA tracking code.
573 - */
574 - protected function get_google_analytics() {
575 - $option_name = $this->get_google_analytics_option_name();
576 -
577 - return get_option( $option_name );
578 - }
579 -
580 - /**
581 - * Get GA tracking code option name.
582 - */
583 - protected function get_google_analytics_option_name() {
584 - /** This filter is documented in class.json-api-endpoints.php */
585 - $is_jetpack = true === apply_filters( 'is_jetpack_site', false, get_current_blog_id() );
586 - $option_name = $is_jetpack ? 'jetpack_wga' : 'wga';
587 -
588 - return $option_name;
589 - }
590 -
591 - /**
592 805 * Updates site settings for authorized users
593 806 *
594 - * @return array
807 + * @return array|WP_Error
595 808 */
596 809 public function update_settings() {
597 810 /*
598 811 * $this->input() retrieves posted arguments whitelisted and casted to the $request_format
@@ -620,8 +833,12 @@
620 833 $jetpack_relatedposts_options = array();
621 834 $sharing_options = array();
622 835 $updated = array();
623 836
837 + if ( ! class_exists( 'Jetpack_Newsletter_Category_Helper' ) ) {
838 + require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-newsletter-category-helper.php';
839 + }
840 +
624 841 foreach ( $input as $key => $value ) {
625 842
626 843 if ( ! is_array( $value ) ) {
627 844 $value = trim( $value );
@@ -663,8 +880,9 @@
663 880 case 'jetpack_search_enabled':
664 881 if ( $value ) {
665 882 Jetpack::activate_module( $blog_id, 'search' );
666 883 } else {
884 + // @phan-suppress-next-line PhanParamTooMany -- Phan doesn't know about the WP.com variant of the Jetpack class.
667 885 Jetpack::deactivate_module( $blog_id, 'search' );
668 886 }
669 887 $updated[ $key ] = (bool) $value;
670 888 break;
@@ -679,8 +897,9 @@
679 897 if ( 'jetpack_relatedposts_enabled' === $key ) {
680 898 if ( $value ) {
681 899 Jetpack::activate_module( $blog_id, 'related-posts' );
682 900 } else {
901 + // @phan-suppress-next-line PhanParamTooMany -- Phan doesn't know about the WP.com variant of the Jetpack class.
683 902 Jetpack::deactivate_module( $blog_id, 'related-posts' );
684 903 }
685 904 }
686 905 $just_the_key = substr( $key, 21 );
@@ -695,45 +914,9 @@
695 914 if ( update_option( $key, $coerce_value ) ) {
696 915 $updated[ $key ] = $value;
697 916 }
698 917 break;
699 - case 'wga':
700 - case 'jetpack_wga':
701 - if ( ! isset( $value['code'] ) || ! preg_match( '/^$|^(UA-\d+-\d+)|(G-[A-Z0-9]+)$/i', $value['code'] ) ) {
702 - return new WP_Error( 'invalid_code', 'Invalid UA ID' );
703 - }
704 918
705 - $option_name = $this->get_google_analytics_option_name();
706 -
707 - $wga = get_option( $option_name, array() );
708 - $wga['code'] = $value['code']; // maintain compatibility with wp-google-analytics.
709 -
710 - /**
711 - * Allow newer versions of this endpoint to filter in additional fields for Google Analytics
712 - *
713 - * @since 5.4.0
714 - *
715 - * @param array $wga Associative array of existing Google Analytics settings.
716 - * @param array $value Associative array of new Google Analytics settings passed to the endpoint.
717 - */
718 - $wga = apply_filters( 'site_settings_update_wga', $wga, $value );
719 -
720 - if ( update_option( $option_name, $wga ) ) {
721 - $updated[ $key ] = $value;
722 - }
723 -
724 - $enabled_or_disabled = $wga['code'] ? 'enabled' : 'disabled';
725 -
726 - /** This action is documented in modules/widgets/social-media-icons.php */
727 - do_action( 'jetpack_bump_stats_extras', 'google-analytics', $enabled_or_disabled );
728 -
729 - $is_wpcom = defined( 'IS_WPCOM' ) && IS_WPCOM;
730 - if ( $is_wpcom ) {
731 - $business_plugins = WPCOM_Business_Plugins::instance();
732 - $business_plugins->activate_plugin( 'wp-google-analytics' );
733 - }
734 - break;
735 -
736 919 case 'cloudflare_analytics':
737 920 if ( ! isset( $value['code'] ) || ! preg_match( '/^$|^[a-fA-F0-9]+$/i', $value['code'] ) ) {
738 921 return new WP_Error( 'invalid_code', __( 'Invalid Cloudflare Analytics ID', 'jetpack' ) );
739 922 }
@@ -746,8 +929,9 @@
746 929 case 'jetpack_testimonial':
747 930 case 'jetpack_portfolio':
748 931 case 'jetpack_comment_likes_enabled':
749 932 case 'wpcom_reader_views_enabled':
933 + case 'jetpack_verbum_subscription_modal':
750 934 // settings are stored as 1|0.
751 935 $coerce_value = (int) $value;
752 936 if ( update_option( $key, $coerce_value ) ) {
753 937 $updated[ $key ] = (bool) $value;
@@ -824,9 +1008,9 @@
824 1008 if ( ! is_array( $value ) ) {
825 1009 break;
826 1010 }
827 1011
828 - $allowed_keys = array( 'invitation', 'comment_follow', 'welcome' );
1012 + $allowed_keys = array( 'invitation', 'comment_follow', 'welcome', 'subscribe_modal_heading', 'free_tier_description', 'hide_free_tier' );
829 1013 $filtered_value = array_filter(
830 1014 $value,
831 1015 function ( $key ) use ( $allowed_keys ) {
832 1016 return in_array( $key, $allowed_keys, true );
@@ -837,8 +1021,16 @@
837 1021 if ( empty( $filtered_value ) ) {
838 1022 break;
839 1023 }
840 1024
1025 + // `hide_free_tier` is a boolean flag, so pull it out before the HTML
1026 + // sanitization below (which expects strings). Parse it with is_truthy()
1027 + // so stringy booleans (e.g. "false", "0") are interpreted correctly
1028 + // rather than being treated as truthy by a plain `! empty()`.
1029 + $has_hide_free_tier = array_key_exists( 'hide_free_tier', $filtered_value );
1030 + $hide_free_tier = $has_hide_free_tier && WPCOM_JSON_API::is_truthy( $filtered_value['hide_free_tier'] );
1031 + unset( $filtered_value['hide_free_tier'] );
1032 +
841 1033 array_walk_recursive(
842 1034 $filtered_value,
843 1035 function ( &$value ) {
844 1036 $value = wp_kses(
@@ -851,13 +1043,89 @@
851 1043 );
852 1044 }
853 1045 );
854 1046
855 - $old_subscription_options = get_option( 'subscription_options' );
856 - $new_subscription_options = array_merge( $old_subscription_options, $filtered_value );
1047 + // Normalize whitespace-only `subscribe_modal_heading` input to empty so
1048 + // the modal template's `empty()` fallback fires. PHP's `empty()` treats
1049 + // `" "` as non-empty, which would otherwise render a blank heading.
1050 + if ( isset( $filtered_value['subscribe_modal_heading'] ) ) {
1051 + $filtered_value['subscribe_modal_heading'] = trim( $filtered_value['subscribe_modal_heading'] );
1052 + }
857 1053
1054 + // The free tier description is stored as plain markdown source, so strip
1055 + // all HTML and cap its length to match the paid-tier description field.
1056 + // WordPress core guarantees mb_substr() (polyfilled in wp-includes/compat.php
1057 + // when the mbstring extension is unavailable), so it's safe to use directly.
1058 + // A JSON payload could supply a non-scalar (array/object) for this field,
1059 + // which would fatal in wp_kses()/mb_substr() on PHP 8+, so drop invalid values.
1060 + if ( isset( $filtered_value['free_tier_description'] ) ) {
1061 + if ( is_scalar( $filtered_value['free_tier_description'] ) ) {
1062 + $filtered_value['free_tier_description'] = mb_substr( wp_kses( (string) $filtered_value['free_tier_description'], array() ), 0, 500 );
1063 + } else {
1064 + unset( $filtered_value['free_tier_description'] );
1065 + }
1066 + }
1067 +
1068 + if ( $has_hide_free_tier ) {
1069 + $filtered_value['hide_free_tier'] = $hide_free_tier;
1070 + }
1071 +
1072 + // Clients that render the settings form tend to post the whole
1073 + // `subscription_options` bag back, including sub-keys the user never
1074 + // touched. This could result in a translated value inadvertently
1075 + // saved in the database.
1076 + // Get the value from db or the default options populated by filter.
1077 + $current_subscription_options = $this->get_subscription_options_in_user_locale();
1078 + $changed_subscription_options = array();
1079 +
1080 + foreach ( $filtered_value as $subscription_option_key => $subscription_option_value ) {
1081 + $current_subscription_option = $current_subscription_options[ $subscription_option_key ] ?? null;
1082 +
1083 + // The incoming value has already been through wp_kses() above, and
1084 + // wp_kses() is not guaranteed to be byte-preserving — it rewrites
1085 + // attribute quoting, and differently across WordPress versions. Put the
1086 + // current value through the same pass so the comparison reflects a real
1087 + // edit rather than a sanitizer rewrite; without this, a default carrying
1088 + // markup (`invitation`) never compares equal and is persisted on every
1089 + // save. Safe to apply to an already-sanitized value: the pass is
1090 + // idempotent.
1091 + if ( is_string( $current_subscription_option ) ) {
1092 + $current_subscription_option = wp_kses(
1093 + $current_subscription_option,
1094 + array(
1095 + 'a' => array(
1096 + 'href' => array(),
1097 + ),
1098 + )
1099 + );
1100 + }
1101 +
1102 + // A sub-key the site has never stored reads as unset everywhere this
1103 + // option is consumed, so an empty incoming value for it is not a change.
1104 + if (
1105 + null === $current_subscription_option
1106 + && ( '' === $subscription_option_value || false === $subscription_option_value )
1107 + ) {
1108 + continue;
1109 + }
1110 +
1111 + if ( $current_subscription_option === $subscription_option_value ) {
1112 + continue;
1113 + }
1114 +
1115 + $changed_subscription_options[ $subscription_option_key ] = $subscription_option_value;
1116 + }
1117 +
1118 + if ( empty( $changed_subscription_options ) ) {
1119 + break;
1120 + }
1121 +
1122 + // Get the value from the database or an empty array.
1123 + $old_subscription_options = get_option( 'subscription_options', array() );
1124 + $new_subscription_options = array_merge( $old_subscription_options, $changed_subscription_options );
1125 +
858 1126 if ( update_option( $key, $new_subscription_options ) ) {
859 - $updated[ $key ] = $filtered_value;
1127 + $updated[ $key ] = $changed_subscription_options;
860 1128 }
861 1129 break;
862 1130
863 1131 case 'woocommerce_onboarding_profile':
@@ -966,10 +1234,24 @@
966 1234 }
967 1235 break;
968 1236
969 1237 case 'verification_services_codes':
970 - $verification_codes = jetpack_verification_validate( $value );
1238 + foreach ( $value as $raw_code ) {
1239 + if ( '' === $raw_code || null === $raw_code || false === $raw_code ) {
1240 + continue;
1241 + }
971 1242
1243 + if ( false === jetpack_verification_validate_code( $raw_code ) ) {
1244 + return new WP_Error(
1245 + 'invalid_input',
1246 + __( 'Invalid site verification code. Enter a verification code or verification tag.', 'jetpack' ),
1247 + 400
1248 + );
1249 + }
1250 + }
1251 +
1252 + $verification_codes = jetpack_verification_validate_codes( $value );
1253 +
972 1254 if ( update_option( 'verification_services_codes', $verification_codes ) ) {
973 1255 $updated[ $key ] = $verification_codes;
974 1256 }
975 1257 break;
@@ -1000,9 +1282,11 @@
1000 1282 }
1001 1283 break;
1002 1284
1003 1285 case 'rss_use_excerpt':
1004 - update_option( 'rss_use_excerpt', (int) (bool) $value );
1286 + $sanitized_value = (int) (bool) $value;
1287 + update_option( $key, $sanitized_value );
1288 + $updated[ $key ] = $sanitized_value;
1005 1289 break;
1006 1290
1007 1291 case 'wpcom_subscription_emails_use_excerpt':
1008 1292 update_option( 'wpcom_subscription_emails_use_excerpt', (bool) $value );
@@ -1008,8 +1292,26 @@
1008 1292 update_option( 'wpcom_subscription_emails_use_excerpt', (bool) $value );
1009 1293 $updated[ $key ] = (bool) $value;
1010 1294 break;
1011 1295
1296 + case 'jetpack_subscriptions_reply_to':
1297 + require_once JETPACK__PLUGIN_DIR . 'modules/subscriptions/class-settings.php';
1298 + $to_set_value = Automattic\Jetpack\Modules\Subscriptions\Settings::is_valid_reply_to( $value )
1299 + ? (string) $value
1300 + : Automattic\Jetpack\Modules\Subscriptions\Settings::$default_reply_to;
1301 +
1302 + if ( update_option( $key, $to_set_value ) ) {
1303 + $updated[ $key ] = $to_set_value;
1304 + }
1305 + break;
1306 +
1307 + case 'jetpack_subscriptions_from_name':
1308 + $sanitized_value = sanitize_text_field( $value );
1309 + if ( update_option( $key, $sanitized_value ) ) {
1310 + $updated[ $key ] = $sanitized_value;
1311 + }
1312 + break;
1313 +
1012 1314 case 'instant_search_enabled':
1013 1315 update_option( 'instant_search_enabled', (bool) $value );
1014 1316 $updated[ $key ] = (bool) $value;
1015 1317 break;
@@ -1025,61 +1327,61 @@
1025 1327 update_option( 'lang_id', (int) $value );
1026 1328 $updated[ $key ] = (int) $value;
1027 1329 break;
1028 1330
1331 + case 'wpcom_newsletter_send_default':
1332 + update_option( 'wpcom_newsletter_send_default', (int) (bool) $value );
1333 + $updated[ $key ] = (int) (bool) $value;
1334 + break;
1335 +
1029 1336 case 'wpcom_featured_image_in_email':
1030 1337 update_option( 'wpcom_featured_image_in_email', (int) (bool) $value );
1031 1338 $updated[ $key ] = (int) (bool) $value;
1032 1339 break;
1033 1340
1034 - case 'wpcom_newsletter_categories':
1035 - $sanitized_category_ids = (array) $value;
1341 + case Jetpack_Newsletter_Category_Helper::NEWSLETTER_CATEGORIES_OPTION:
1342 + $update_newsletter_categories = Jetpack_Newsletter_Category_Helper::save_category_ids( (array) $value );
1343 + if ( $update_newsletter_categories ) {
1344 + $updated[ $key ] = $update_newsletter_categories;
1345 + }
1036 1346
1037 - array_walk_recursive(
1038 - $sanitized_category_ids,
1039 - function ( &$value ) {
1040 - if ( is_int( $value ) && $value > 0 ) {
1041 - return;
1042 - }
1347 + break;
1043 1348
1044 - $value = (int) $value;
1045 - if ( $value <= 0 ) {
1046 - $value = null;
1047 - }
1048 - }
1049 - );
1349 + case 'wpcom_newsletter_categories_enabled':
1350 + update_option( 'wpcom_newsletter_categories_enabled', (int) (bool) $value );
1351 + $updated[ $key ] = (int) (bool) $value;
1352 + break;
1050 1353
1051 - $sanitized_category_ids = array_unique(
1052 - array_filter(
1053 - $sanitized_category_ids,
1054 - function ( $category_id ) {
1055 - return $category_id !== null;
1056 - }
1057 - )
1058 - );
1354 + case 'sm_enabled':
1355 + update_option( 'sm_enabled', (int) (bool) $value );
1356 + $updated[ $key ] = (int) (bool) $value;
1357 + break;
1059 1358
1060 - $new_value = array_map(
1061 - function ( $category_id ) {
1062 - return array( 'term_id' => $category_id );
1063 - },
1064 - $sanitized_category_ids
1065 - );
1359 + case 'jetpack_subscribe_overlay_enabled':
1360 + update_option( 'jetpack_subscribe_overlay_enabled', (int) (bool) $value );
1361 + $updated[ $key ] = (int) (bool) $value;
1362 + break;
1066 1363
1067 - if ( update_option( $key, $new_value ) ) {
1068 - $updated[ $key ] = $new_value;
1069 - }
1364 + case 'jetpack_subscribe_floating_button_enabled':
1365 + update_option( 'jetpack_subscribe_floating_button_enabled', (int) (bool) $value );
1366 + $updated[ $key ] = (int) (bool) $value;
1070 1367 break;
1071 1368
1072 - case 'wpcom_newsletter_categories_enabled':
1073 - update_option( 'wpcom_newsletter_categories_enabled', (int) (bool) $value );
1369 + case 'jetpack_subscriptions_subscribe_post_end_enabled':
1370 + update_option( 'jetpack_subscriptions_subscribe_post_end_enabled', (int) (bool) $value );
1074 1371 $updated[ $key ] = (int) (bool) $value;
1075 1372 break;
1076 1373
1077 - case 'sm_enabled':
1078 - update_option( 'sm_enabled', (int) (bool) $value );
1374 + case 'jetpack_subscriptions_login_navigation_enabled':
1375 + update_option( 'jetpack_subscriptions_login_navigation_enabled', (int) (bool) $value );
1079 1376 $updated[ $key ] = (int) (bool) $value;
1080 1377 break;
1081 1378
1379 + case 'jetpack_subscriptions_subscribe_navigation_enabled':
1380 + update_option( 'jetpack_subscriptions_subscribe_navigation_enabled', (int) (bool) $value );
1381 + $updated[ $key ] = (int) (bool) $value;
1382 + break;
1383 +
1082 1384 case 'show_on_front':
1083 1385 if ( in_array( $value, array( 'page', 'posts' ), true ) && update_option( $key, $value ) ) {
1084 1386 $updated[ $key ] = $value;
1085 1387 }
@@ -1111,8 +1413,59 @@
1111 1413 }
1112 1414
1113 1415 break;
1114 1416
1417 + case 'in_site_migration_flow':
1418 + if ( empty( $value ) ) {
1419 + delete_option( 'in_site_migration_flow' );
1420 + break;
1421 + }
1422 +
1423 + $migration_flow_whitelist = array(
1424 + 'site-migration',
1425 + 'migration-signup',
1426 + );
1427 +
1428 + if ( ! in_array( $value, $migration_flow_whitelist, true ) ) {
1429 + break;
1430 + }
1431 +
1432 + update_option( 'in_site_migration_flow', $value );
1433 + $updated[ $key ] = $value;
1434 + break;
1435 +
1436 + case 'migration_source_site_domain':
1437 + // If we get an empty value, delete the option
1438 + if ( empty( $value ) ) {
1439 + delete_option( 'migration_source_site_domain' );
1440 + break;
1441 + }
1442 +
1443 + // If we get a non-url value, don't update the option.
1444 + if ( wp_http_validate_url( $value ) === false ) {
1445 + break;
1446 + }
1447 +
1448 + update_option( 'migration_source_site_domain', $value );
1449 + $updated[ $key ] = $value;
1450 + break;
1451 +
1452 + case 'is_fully_managed_agency_site':
1453 + case 'wpcom_hide_action_bar':
1454 + $coerce_value = (int) (bool) $value;
1455 + if ( update_option( $key, $coerce_value ) ) {
1456 + $updated[ $key ] = (bool) $coerce_value;
1457 + }
1458 + break;
1459 +
1460 + case 'mcp_abilities':
1461 + $result = $this->set_site_mcp_abilities( $value );
1462 + if ( is_wp_error( $result ) ) {
1463 + return $result;
1464 + }
1465 + $updated[ $key ] = $this->get_site_mcp_abilities();
1466 + break;
1467 +
1115 1468 default:
1116 1469 // allow future versions of this endpoint to support additional settings keys.
1117 1470 if ( has_filter( 'site_settings_endpoint_update_' . $key ) ) {
1118 1471 /**
@@ -1120,13 +1473,22 @@
1120 1473 *
1121 1474 * @module json-api
1122 1475 *
1123 1476 * @since 3.9.3
1477 + * @since 13.6 Added the API object parameter.
1124 1478 *
1125 1479 * @param mixed $response_item A single site setting value.
1480 + * @param WPCOM_JSON_API_Site_Settings_Endpoint The API object parameter.
1126 1481 */
1127 - $value = apply_filters( 'site_settings_endpoint_update_' . $key, $value );
1128 - $updated[ $key ] = $value;
1482 + $value = apply_filters( 'site_settings_endpoint_update_' . $key, $value, $this );
1483 +
1484 + if ( is_wp_error( $value ) ) {
1485 + return $value;
1486 + }
1487 +
1488 + if ( $value ) {
1489 + $updated[ $key ] = $value;
1490 + }
1129 1491 break;
1130 1492 }
1131 1493 // no worries, we've already whitelisted and casted arguments above.
1132 1494 if ( update_option( $key, $value ) ) {
@@ -1196,22 +1558,20 @@
1196 1558 );
1197 1559 }
1198 1560
1199 1561 /**
1200 - * Get the value of the wpcom_subscription_emails_use_excerpt option.
1201 - * When the option is not set, it will return the value of the rss_use_excerpt option.
1562 + * Get the string value of the jetpack_subscriptions_reply_to option.
1563 + * When the option is not set, it will retun 'no-reply'.
1202 1564 *
1203 - * @return bool
1565 + * @return string
1204 1566 */
1205 - protected function get_wpcom_subscription_emails_use_excerpt_option() {
1206 - $wpcom_subscription_emails_use_excerpt = get_option( 'wpcom_subscription_emails_use_excerpt', null );
1207 -
1208 - if ( $wpcom_subscription_emails_use_excerpt === null ) {
1209 - $rss_use_excerpt = get_option( 'rss_use_excerpt', null );
1210 - $wpcom_subscription_emails_use_excerpt = $rss_use_excerpt === null ? false : $rss_use_excerpt;
1567 + protected function get_subscriptions_reply_to_option() {
1568 + $reply_to = get_option( 'jetpack_subscriptions_reply_to', null );
1569 + if ( $reply_to === null ) {
1570 + require_once JETPACK__PLUGIN_DIR . 'modules/subscriptions/class-settings.php';
1571 + return Automattic\Jetpack\Modules\Subscriptions\Settings::$default_reply_to;
1211 1572 }
1212 -
1213 - return (bool) $wpcom_subscription_emails_use_excerpt;
1573 + return $reply_to;
1214 1574 }
1215 1575
1216 1576 /**
1217 1577 * Check if the given value is a valid page ID for the current site.
@@ -1230,6 +1590,22 @@
1230 1590 }
1231 1591 }
1232 1592
1233 1593 return $valid_page_id;
1594 + }
1595 +
1596 + /**
1597 + * Get the value of the highlander_comment_form_prompt option.
1598 + * When the option is not set, it will return the default value.
1599 + *
1600 + * @return string
1601 + */
1602 + protected function get_highlander_comment_form_prompt_option() {
1603 + $highlander_comment_form_prompt_option = get_option( 'highlander_comment_form_prompt' );
1604 +
1605 + if ( empty( $highlander_comment_form_prompt_option ) ) {
1606 + return (string) __( 'Leave a comment', 'jetpack' );
1607 + }
1608 +
1609 + return (string) $highlander_comment_form_prompt_option;
1234 1610 }
1235 1611 }