PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
jetpack / json-endpoints / class.wpcom-json-api-update-media-v1-1-endpoint.php

class.wpcom-json-api-update-media-v1-1-endpoint.php in Jetpack – WP Security, Backup, Speed, & Growth 16.3-a.7, at json-endpoints/class.wpcom-json-api-update-media-v1-1-endpoint.php

264 lines 9.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Update media item info v1.1 endpoint.
4 *
5 * Endpoint: v1.1/sites/%s/media/%d
6 */
7
8 if ( ! defined( 'ABSPATH' ) ) {
9 exit( 0 );
10 }
11
12 new WPCOM_JSON_API_Update_Media_v1_1_Endpoint(
13 array(
14 'description' => 'Edit basic information about a media item.',
15 'group' => 'media',
16 'stat' => 'media:1:POST',
17 'min_version' => '1.1',
18 'max_version' => '1.1',
19 'method' => 'POST',
20 'path' => '/sites/%s/media/%d',
21 'path_labels' => array(
22 '$site' => '(int|string) Site ID or domain',
23 '$media_ID' => '(int) The ID of the media item',
24 ),
25
26 'request_format' => array(
27 'parent_id' => '(int) ID of the post this media is attached to',
28 'title' => '(string) The file name.',
29 'caption' => '(string) File caption.',
30 'description' => '(HTML) Description of the file.',
31 'alt' => '(string) Alternative text for image files.',
32 'rating' => '(string) Video only. Video rating.',
33 'display_embed' => '(string) Video only. Whether to share or not the video.',
34 'allow_download' => '(string) Video only. Whether the video can be downloaded or not.',
35 'privacy_setting' => '(int) Video only. The privacy level for the video.',
36 'artist' => '(string) Audio Only. Artist metadata for the audio track.',
37 'album' => '(string) Audio Only. Album metadata for the audio track.',
38 ),
39
40 'response_format' => array(
41 'ID' => '(int) The ID of the media item',
42 'date' => '(ISO 8601 datetime) The date the media was uploaded',
43 'post_ID' => '(int) ID of the post this media is attached to',
44 'author_ID' => '(int) ID of the user who uploaded the media',
45 'URL' => '(string) URL to the file',
46 'guid' => '(string) Unique identifier',
47 'file' => '(string) File name',
48 'extension' => '(string) File extension',
49 'mime_type' => '(string) File mime type',
50 'title' => '(string) File name',
51 'caption' => '(string) User provided caption of the file',
52 'description' => '(string) Description of the file',
53 'alt' => '(string) Alternative text for image files.',
54 'thumbnails' => '(object) Media item thumbnail URL options',
55 'height' => '(int) (Image & video only) Height of the media item',
56 'width' => '(int) (Image & video only) Width of the media item',
57 'length' => '(int) (Video & audio only) Duration of the media item, in seconds',
58 'exif' => '(array) (Image & audio only) Exif (meta) information about the media item',
59 'rating' => '(string) (Video only) VideoPress rating of the video',
60 'display_embed' => '(string) Video only. Whether to share or not the video.',
61 'allow_download' => '(string) Video only. Whether the video can be downloaded or not.',
62 'privacy_setting' => '(int) Video only. The privacy level for the video.',
63 'videopress_guid' => '(string) (Video only) VideoPress GUID of the video when uploaded on a blog with VideoPress',
64 'videopress_processing_done' => '(bool) (Video only) If the video is uploaded on a blog with VideoPress, this will return the status of processing on the video.',
65 ),
66
67 'example_request' => 'https://public-api.wordpress.com/rest/v1.1/sites/82974409/media/446',
68 'example_request_data' => array(
69 'headers' => array(
70 'authorization' => 'Bearer YOUR_API_TOKEN',
71 ),
72 'body' => array(
73 'title' => 'Updated Title',
74 ),
75 ),
76 )
77 );
78
79 // phpcs:disable PEAR.NamingConventions.ValidClassName.Invalid
80 /**
81 * Update media item info v1.1 class.
82 *
83 * @phan-constructor-used-for-side-effects
84 */
85 class WPCOM_JSON_API_Update_Media_v1_1_Endpoint extends WPCOM_JSON_API_Endpoint {
86 /**
87 * Whether the current user may edit the given media item.
88 *
89 * `upload_files` is a primitive capability and ignores any object passed to it,
90 * so it only tells us the caller may upload something, never that they may edit
91 * this particular item. A missing item is passed through so the caller receives
92 * the endpoint's own 404 rather than a 403. A userless request gets no exemption:
93 * `edit_post` fails closed for user 0 like any other caller.
94 *
95 * Non-attachments are refused outright. `get_post()` resolves any post type, so
96 * without this test a media endpoint edits ordinary posts, pages and revisions.
97 * The post-type test must stay below the missing-post passthrough: that branch
98 * returns true, so testing there would skip `edit_post` for ordinary posts.
99 *
100 * A non-attachment yields 403, not the 404 a missing item gets. This is a boolean
101 * gate, and `get_media_item*()` resolves any post type, so a passthrough would
102 * return 200 rather than 404. Revisit if clients conflate it with an auth failure.
103 *
104 * Do not move this into a trait: this file instantiates the endpoint above the
105 * class declaration, and `use Trait;` disables PHP early binding, which makes the
106 * file fatal with "Class not found".
107 *
108 * @param int $media_id Media post ID.
109 * @return bool
110 */
111 protected function current_user_can_edit_media_item( $media_id ) {
112 if ( ! current_user_can( 'upload_files' ) ) {
113 return false;
114 }
115
116 $post = get_post( $media_id );
117
118 if ( ! $post ) {
119 return true;
120 }
121
122 if ( 'attachment' !== $post->post_type ) {
123 return false;
124 }
125
126 return current_user_can( 'edit_post', $media_id );
127 }
128
129 /**
130 * Update media item info API v1.1 callback.
131 *
132 * @param string $path API path.
133 * @param int $blog_id Blog ID.
134 * @param int $media_id Media ID.
135 *
136 * @return object|WP_Error
137 */
138 public function callback( $path = '', $blog_id = 0, $media_id = 0 ) {
139 $blog_id = $this->api->switch_to_blog_and_validate_user( $this->api->get_blog_id( $blog_id ) );
140 if ( is_wp_error( $blog_id ) ) {
141 return $blog_id;
142 }
143
144 if ( ! $this->current_user_can_edit_media_item( $media_id ) ) {
145 return new WP_Error( 'unauthorized', 'User cannot edit media', 403 );
146 }
147
148 $item = $this->get_media_item_v1_1( $media_id );
149
150 if ( is_wp_error( $item ) ) {
151 return new WP_Error( 'unknown_media', 'Unknown Media', 404 );
152 }
153
154 $input = $this->input( true );
155 $insert = array();
156
157 if ( isset( $input['title'] ) ) {
158 $insert['post_title'] = $input['title'];
159 }
160
161 if ( isset( $input['caption'] ) ) {
162 $insert['post_excerpt'] = $input['caption'];
163 }
164
165 if ( isset( $input['description'] ) ) {
166 $insert['post_content'] = $input['description'];
167 }
168
169 if ( isset( $input['parent_id'] ) ) {
170 $parent_id = (int) $input['parent_id'];
171
172 /*
173 * Attaching media to a post is an edit of that post, so it takes `edit_post` on
174 * the target, as core's WP_REST_Attachments_Controller does for the same field.
175 * Without this a caller attaches their own media to any post on the site.
176 *
177 * Zero is exempt: it detaches the item rather than naming a target, and
178 * `edit_post` fails closed on 0, which would make detaching impossible.
179 */
180 if ( $parent_id && ! current_user_can( 'edit_post', $parent_id ) ) {
181 return new WP_Error( 'unauthorized', 'User cannot edit the parent post', 403 );
182 }
183
184 $insert['post_parent'] = $parent_id;
185 }
186
187 if ( isset( $input['alt'] ) ) {
188 $alt = wp_strip_all_tags( $input['alt'], true );
189 update_post_meta( $media_id, '_wp_attachment_image_alt', $alt );
190 }
191
192 // audio only artist/album info.
193 if ( str_starts_with( $item->mime_type, 'audio/' ) ) {
194 $changed = false;
195 $id3data = wp_get_attachment_metadata( $media_id );
196
197 if ( ! is_array( $id3data ) ) {
198 $changed = true;
199 $id3data = array();
200 }
201
202 $id3_keys = array(
203 'artist' => __( 'Artist', 'jetpack' ),
204 'album' => __( 'Album', 'jetpack' ),
205 );
206
207 foreach ( $id3_keys as $key => $label ) {
208 if ( isset( $input[ $key ] ) ) {
209 $changed = true;
210 $id3data[ $key ] = wp_strip_all_tags( $input[ $key ], true );
211 }
212 }
213
214 if ( $changed ) {
215 wp_update_attachment_metadata( $media_id, $id3data );
216 }
217 }
218
219 // Pass the item to the handle_video_meta() that checks if it's a VideoPress item and saves it.
220 $result = $this->handle_video_meta( $media_id, $input, $item );
221
222 if ( is_wp_error( $result ) ) {
223 return $result;
224 }
225
226 $insert['ID'] = $media_id;
227 wp_update_post( (object) $insert );
228
229 $item = $this->get_media_item_v1_1( $media_id );
230 return $item;
231 }
232
233 /**
234 * Persist the VideoPress metadata if the given item argument is a VideoPress item.
235 *
236 * @param string $media_id The ID of the video.
237 * @param array $input The request input.
238 * @param stdClass $item The response item.
239 *
240 * @return bool|WP_Error
241 */
242 public function handle_video_meta( $media_id, $input, $item ) {
243 if ( ! class_exists( \Videopress_Attachment_Metadata::class ) ) {
244 return false;
245 }
246
247 if ( ! \Videopress_Attachment_Metadata::is_videopress_media( $item ) ) {
248 return false;
249 }
250
251 return \Videopress_Attachment_Metadata::persist_metadata(
252 $media_id,
253 $item->videopress_guid,
254 $input['title'] ?? null,
255 $input['caption'] ?? null,
256 $input['description'] ?? null,
257 $input['rating'] ?? null,
258 $input['display_embed'] ?? null,
259 $input['allow_download'] ?? null,
260 $input['privacy_setting'] ?? null
261 );
262 }
263 }
264