← All changes
|
modules/verification-tools/verification-tools-utils.php
+74
-18
16.2-beta
→
16.3-a.5
View file →
| @@ -5,26 +5,75 @@ | ||
| 5 | 5 | * |
| 6 | 6 | * @package jetpack |
| 7 | 7 | */ |
| 8 | 8 | |
| 9 | -if ( ! function_exists( 'jetpack_verification_validate' ) ) { | |
| 9 | +if ( ! function_exists( 'jetpack_verification_extract_code' ) ) { | |
| 10 | 10 | /** |
| 11 | + * Extract a site verification code from a meta tag. | |
| 12 | + * | |
| 13 | + * @since 16.3 | |
| 14 | + * | |
| 15 | + * @param string $code Verification meta tag. | |
| 16 | + * @return string|false Extracted code, or false when none is found. | |
| 17 | + */ | |
| 18 | + function jetpack_verification_extract_code( $code ) { | |
| 19 | + $pattern = '/content=["\']?([^"\' ]*)["\' ]/is'; | |
| 20 | + preg_match( $pattern, $code, $match ); | |
| 21 | + | |
| 22 | + return $match ? rawurldecode( $match[1] ) : false; | |
| 23 | + } | |
| 24 | +} | |
| 25 | + | |
| 26 | +if ( ! function_exists( 'jetpack_verification_validate_code' ) ) { | |
| 27 | + /** | |
| 28 | + * Validate and normalize a site verification code. | |
| 29 | + * | |
| 30 | + * @since 16.3 | |
| 31 | + * | |
| 32 | + * @param mixed $code Verification code or meta tag. | |
| 33 | + * @return string|false Normalized code, or false when invalid. | |
| 34 | + */ | |
| 35 | + function jetpack_verification_validate_code( $code ) { | |
| 36 | + if ( ! is_scalar( $code ) ) { | |
| 37 | + return false; | |
| 38 | + } | |
| 39 | + | |
| 40 | + // Allow printable ASCII except characters that can delimit HTML attributes or tags. | |
| 41 | + $code_pattern = '/^(?!.*[<>"\'])[!-~]+$/'; | |
| 42 | + $code = trim( (string) $code ); | |
| 43 | + | |
| 44 | + if ( '' === $code ) { | |
| 45 | + return ''; | |
| 46 | + } | |
| 47 | + | |
| 48 | + // Parse html meta tag if it does not look like a valid code. | |
| 49 | + if ( ! preg_match( $code_pattern, $code ) ) { | |
| 50 | + $code = jetpack_verification_extract_code( $code ); | |
| 51 | + } | |
| 52 | + | |
| 53 | + $code = trim( (string) $code ); | |
| 54 | + if ( '' === $code || ! preg_match( $code_pattern, $code ) ) { | |
| 55 | + return false; | |
| 56 | + } | |
| 57 | + | |
| 58 | + return substr( $code, 0, 100 ); | |
| 59 | + } | |
| 60 | +} | |
| 61 | + | |
| 62 | +if ( ! function_exists( 'jetpack_verification_validate_codes' ) ) { | |
| 63 | + /** | |
| 11 | 64 | * Validate jetpack verification codes. |
| 12 | 65 | * |
| 66 | + * @since 16.3 | |
| 67 | + * | |
| 13 | 68 | * @param array $verification_services_codes - array of verification codes. |
| 69 | + * @return array Validated verification codes. | |
| 14 | 70 | */ |
| 15 | - function jetpack_verification_validate( $verification_services_codes ) { | |
| 71 | + function jetpack_verification_validate_codes( $verification_services_codes ) { | |
| 16 | 72 | foreach ( $verification_services_codes as $key => $code ) { |
| 17 | - // Parse html meta tag if it does not look like a valid code. | |
| 18 | - if ( ! preg_match( '/^[a-z0-9_-]+$/i', $code ) ) { | |
| 19 | - $code = jetpack_verification_get_code( $code ); | |
| 20 | - } | |
| 73 | + $code = jetpack_verification_validate_code( $code ); | |
| 74 | + $code = false === $code ? '' : $code; | |
| 21 | 75 | |
| 22 | - $code = esc_attr( trim( $code ) ); | |
| 23 | - | |
| 24 | - // limit length to 100 chars. | |
| 25 | - $code = substr( $code, 0, 100 ); | |
| 26 | - | |
| 27 | 76 | /** |
| 28 | 77 | * Fire after each Verification code was validated. |
| 29 | 78 | * |
| 30 | 79 | * @module verification-tools |
| @@ -41,20 +90,27 @@ | ||
| 41 | 90 | return $verification_services_codes; |
| 42 | 91 | } |
| 43 | 92 | } |
| 44 | 93 | |
| 94 | +if ( ! function_exists( 'jetpack_verification_validate' ) ) { | |
| 95 | + /** | |
| 96 | + * Validate jetpack verification codes. | |
| 97 | + * | |
| 98 | + * @param array $verification_services_codes - array of verification codes. | |
| 99 | + * @return array Validated verification codes. | |
| 100 | + */ | |
| 101 | + function jetpack_verification_validate( $verification_services_codes ) { | |
| 102 | + return jetpack_verification_validate_codes( $verification_services_codes ); | |
| 103 | + } | |
| 104 | +} | |
| 105 | + | |
| 45 | 106 | if ( ! function_exists( 'jetpack_verification_get_code' ) ) { |
| 46 | 107 | /** |
| 47 | 108 | * Return the code we're trying to verify after decoding. |
| 48 | 109 | * |
| 49 | 110 | * @param string $code - the code we need to parse. |
| 111 | + * @return string|false Extracted code, or false when none is found. | |
| 50 | 112 | */ |
| 51 | 113 | function jetpack_verification_get_code( $code ) { |
| 52 | - $pattern = '/content=["\']?([^"\' ]*)["\' ]/is'; | |
| 53 | - preg_match( $pattern, $code, $match ); | |
| 54 | - if ( $match ) { | |
| 55 | - return urldecode( $match[1] ); | |
| 56 | - } else { | |
| 57 | - return false; | |
| 58 | - } | |
| 114 | + return jetpack_verification_extract_code( $code ); | |
| 59 | 115 | } |
| 60 | 116 | } |