PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | json-endpoints/jetpack/class.jetpack-json-api-plugins-new-endpoint.php +70 -57 12.1.3 → 16.3-a.7 View file →
@@ -1,69 +1,24 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 -require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
4 -require_once ABSPATH . 'wp-admin/includes/file.php';
5 -
6 3 use Automattic\Jetpack\Automatic_Install_Skin;
7 4
8 -// POST /sites/%s/plugins/new
9 -new Jetpack_JSON_API_Plugins_New_Endpoint(
10 - array(
11 - 'description' => 'Install a plugin to a Jetpack site by uploading a zip file',
12 - 'group' => '__do_not_document',
13 - 'stat' => 'plugins:new',
14 - 'min_version' => '1',
15 - 'max_version' => '1.1',
16 - 'method' => 'POST',
17 - 'path' => '/sites/%s/plugins/new',
18 - 'path_labels' => array(
19 - '$site' => '(int|string) Site ID or domain',
20 - ),
21 - 'request_format' => array(
22 - 'zip' => '(zip) Plugin package zip file. multipart/form-data encoded. ',
23 - ),
24 - 'response_format' => Jetpack_JSON_API_Plugins_Endpoint::$_response_format,
25 - 'allow_jetpack_site_auth' => true,
26 - 'example_request_data' => array(
27 - 'headers' => array(
28 - 'authorization' => 'Bearer YOUR_API_TOKEN',
29 - ),
30 - ),
31 - 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/example.wordpress.org/plugins/new',
32 - )
33 -);
5 +if ( ! defined( 'ABSPATH' ) ) {
6 + exit( 0 );
7 +}
34 8
35 -new Jetpack_JSON_API_Plugins_New_Endpoint(
36 - array(
37 - 'description' => 'Install a plugin to a Jetpack site by uploading a zip file',
38 - 'group' => '__do_not_document',
39 - 'stat' => 'plugins:new',
40 - 'min_version' => '1.2',
41 - 'method' => 'POST',
42 - 'path' => '/sites/%s/plugins/new',
43 - 'path_labels' => array(
44 - '$site' => '(int|string) Site ID or domain',
45 - ),
46 - 'request_format' => array(
47 - 'zip' => '(zip) Plugin package zip file. multipart/form-data encoded. ',
48 - ),
49 - 'response_format' => Jetpack_JSON_API_Plugins_Endpoint::$_response_format_v1_2,
50 - 'allow_jetpack_site_auth' => true,
51 - 'example_request_data' => array(
52 - 'headers' => array(
53 - 'authorization' => 'Bearer YOUR_API_TOKEN',
54 - ),
55 - ),
56 - 'example_request' => 'https://public-api.wordpress.com/rest/v1.2/sites/example.wordpress.org/plugins/new',
57 - )
58 -);
9 +require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
10 +require_once ABSPATH . 'wp-admin/includes/file.php';
59 11
60 12 /**
61 13 * Plugins new endpoint class.
62 14 *
63 15 * POST /sites/%s/plugins/new
16 + *
17 + * @phan-constructor-used-for-side-effects
64 18 */
65 19 class Jetpack_JSON_API_Plugins_New_Endpoint extends Jetpack_JSON_API_Plugins_Endpoint {
20 + use Jetpack_JSON_API_Attachment_Ownership_Trait;
66 21
67 22 /**
68 23 * Needed capabilities.
69 24 *
@@ -91,11 +46,17 @@
91 46 $validate = parent::validate_call( $_blog_id, $capability, $check_manage_active );
92 47 if ( is_wp_error( $validate ) ) {
93 48
94 49 // Lets delete the attachment... if the user doesn't have the right permissions to do things.
50 + // Only clean up an upload the caller actually owns. This runs *after* the capability check
51 + // has already failed, so without the ownership guard any connected user could name someone
52 + // else's attachment and have it hard-deleted on their behalf.
95 53 $args = $this->input();
96 - if ( isset( $args['zip'][0]['id'] ) ) {
97 - wp_delete_attachment( $args['zip'][0]['id'], true );
54 + if ( isset( $args['zip'][0]['id'] ) && is_scalar( $args['zip'][0]['id'] ) ) {
55 + $attachment_id = (int) $args['zip'][0]['id'];
56 + if ( true === $this->validate_attachment_ownership( $attachment_id ) ) {
57 + wp_delete_attachment( $attachment_id, true );
58 + }
98 59 }
99 60 }
100 61
101 62 return $validate;
@@ -141,10 +102,10 @@
141 102 $after_install_plugin_list = get_plugins();
142 103 $plugin = array_values( array_diff( array_keys( $after_install_plugin_list ), array_keys( $pre_install_plugin_list ) ) );
143 104
144 105 if ( ! $result ) {
145 - $error_code = $upgrader->skin->get_main_error_code();
146 - $message = $upgrader->skin->get_main_error_message();
106 + $error_code = $skin->get_main_error_code();
107 + $message = $skin->get_main_error_message();
147 108 if ( empty( $message ) ) {
148 109 $message = __( 'An unknown error occurred during installation', 'jetpack' );
149 110 }
150 111
@@ -167,4 +128,56 @@
167 128
168 129 return new WP_Error( 'no_plugin_installed' );
169 130 }
170 131 }
132 +
133 +// POST /sites/%s/plugins/new
134 +new Jetpack_JSON_API_Plugins_New_Endpoint(
135 + array(
136 + 'description' => 'Install a plugin to a Jetpack site by uploading a zip file',
137 + 'group' => '__do_not_document',
138 + 'stat' => 'plugins:new',
139 + 'min_version' => '1',
140 + 'max_version' => '1.1',
141 + 'method' => 'POST',
142 + 'path' => '/sites/%s/plugins/new',
143 + 'path_labels' => array(
144 + '$site' => '(int|string) Site ID or domain',
145 + ),
146 + 'request_format' => array(
147 + 'zip' => '(array) Reference to an uploaded plugin package zip file.',
148 + ),
149 + 'response_format' => Jetpack_JSON_API_Plugins_Endpoint::$_response_format,
150 + 'allow_jetpack_site_auth' => true,
151 + 'example_request_data' => array(
152 + 'headers' => array(
153 + 'authorization' => 'Bearer YOUR_API_TOKEN',
154 + ),
155 + ),
156 + 'example_request' => 'https://public-api.wordpress.com/rest/v1/sites/example.wordpress.org/plugins/new',
157 + )
158 +);
159 +
160 +new Jetpack_JSON_API_Plugins_New_Endpoint(
161 + array(
162 + 'description' => 'Install a plugin to a Jetpack site by uploading a zip file',
163 + 'group' => '__do_not_document',
164 + 'stat' => 'plugins:new',
165 + 'min_version' => '1.2',
166 + 'method' => 'POST',
167 + 'path' => '/sites/%s/plugins/new',
168 + 'path_labels' => array(
169 + '$site' => '(int|string) Site ID or domain',
170 + ),
171 + 'request_format' => array(
172 + 'zip' => '(array) Reference to an uploaded plugin package zip file.',
173 + ),
174 + 'response_format' => Jetpack_JSON_API_Plugins_Endpoint::$_response_format_v1_2,
175 + 'allow_jetpack_site_auth' => true,
176 + 'example_request_data' => array(
177 + 'headers' => array(
178 + 'authorization' => 'Bearer YOUR_API_TOKEN',
179 + ),
180 + ),
181 + 'example_request' => 'https://public-api.wordpress.com/rest/v1.2/sites/example.wordpress.org/plugins/new',
182 + )
183 +);