PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | _inc/lib/core-api/class.jetpack-core-api-module-endpoints.php +247 -281 13.0.2 → 16.3-a.7 View file →
@@ -6,9 +6,8 @@
6 6 */
7 7
8 8 use Automattic\Jetpack\Connection\REST_Connector;
9 9 use Automattic\Jetpack\Current_Plan as Jetpack_Plan;
10 -use Automattic\Jetpack\Plugins_Installer;
11 10 use Automattic\Jetpack\Stats\WPCOM_Stats;
12 11 use Automattic\Jetpack\Stats_Admin\Main as Stats_Admin_Main;
13 12 use Automattic\Jetpack\Status;
14 13 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
@@ -13,8 +12,12 @@
13 12 use Automattic\Jetpack\Status;
14 13 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
15 14 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection_Shared_Functions;
16 15
16 +if ( ! defined( 'ABSPATH' ) ) {
17 + exit( 0 );
18 +}
19 +
17 20 /**
18 21 * This is the base class for every Core API endpoint Jetpack uses.
19 22 */
20 23 class Jetpack_Core_API_Module_Toggle_Endpoint extends Jetpack_Core_API_XMLRPC_Consumer_Endpoint {
@@ -88,8 +91,16 @@
88 91 );
89 92 }
90 93
91 94 if ( Jetpack::activate_module( $module_slug, false, false ) ) {
95 + if ( ! Jetpack::is_module_active( $module_slug ) ) {
96 + return new WP_Error(
97 + 'module_forced',
98 + esc_html__( 'The requested Jetpack module is disabled by your host or site administrator, so it stays off.', 'jetpack' ),
99 + array( 'status' => 409 )
100 + );
101 + }
102 +
92 103 return rest_ensure_response(
93 104 array(
94 105 'code' => 'success',
95 106 'message' => esc_html__( 'The requested Jetpack module was activated.', 'jetpack' ),
@@ -149,9 +160,20 @@
149 160 array( 'status' => 409 )
150 161 );
151 162 }
152 163
153 - if ( Jetpack::deactivate_module( $module_slug ) ) {
164 + $deactivated = Jetpack::deactivate_module( $module_slug );
165 +
166 + // A module that was never saved as active leaves nothing to change, so check the outcome.
167 + if ( Jetpack::is_module_active( $module_slug ) ) {
168 + return new WP_Error(
169 + 'module_forced',
170 + esc_html__( 'The requested Jetpack module is enabled by your host or site administrator, so it stays on.', 'jetpack' ),
171 + array( 'status' => 409 )
172 + );
173 + }
174 +
175 + if ( $deactivated ) {
154 176 return rest_ensure_response(
155 177 array(
156 178 'code' => 'success',
157 179 'message' => esc_html__( 'The requested Jetpack module was deactivated.', 'jetpack' ),
@@ -259,9 +281,9 @@
259 281 $activated = array();
260 282 $failed = array();
261 283
262 284 foreach ( $request['modules'] as $module ) {
263 - if ( Jetpack::activate_module( $module, false, false ) ) {
285 + if ( Jetpack::activate_module( $module, false, false ) && Jetpack::is_module_active( $module ) ) {
264 286 $activated[] = $module;
265 287 } else {
266 288 $failed[] = $module;
267 289 }
@@ -402,15 +424,17 @@
402 424 $module['activated'] = false;
403 425 }
404 426
405 427 $i18n = jetpack_get_module_i18n( $request['slug'] );
406 - if ( isset( $module['name'] ) ) {
407 - $module['name'] = $i18n['name'];
428 + if ( $i18n ) {
429 + if ( isset( $module['name'] ) ) {
430 + $module['name'] = $i18n['name'];
431 + }
432 + if ( isset( $module['description'] ) ) {
433 + $module['description'] = $i18n['description'];
434 + $module['short_description'] = $i18n['description'];
435 + }
408 436 }
409 - if ( isset( $module['description'] ) ) {
410 - $module['description'] = $i18n['description'];
411 - $module['short_description'] = $i18n['description'];
412 - }
413 437 if ( isset( $module['module_tags'] ) ) {
414 438 $module['module_tags'] = array_map( 'jetpack_get_module_i18n_tag', $module['module_tags'] );
415 439 }
416 440
@@ -447,14 +471,18 @@
447 471 $response[ $module ] = Jetpack::is_module_active( $module );
448 472 }
449 473 }
450 474
451 - $settings = Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list( 'settings' );
475 + $settings = Jetpack_Core_Json_Api_Endpoints::filter_options_for_response(
476 + Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list( 'settings' )
477 + );
452 478
453 479 if ( ! function_exists( 'is_plugin_active' ) ) {
454 480 require_once ABSPATH . 'wp-admin/includes/plugin.php';
455 481 }
456 482
483 + $response['categories'] = get_categories( array( 'get' => 'all' ) );
484 +
457 485 foreach ( $settings as $setting => $properties ) {
458 486 switch ( $setting ) {
459 487 case 'lang_id':
460 488 if ( ! current_user_can( 'install_languages' ) ) {
@@ -483,24 +511,8 @@
483 511 $response[ $setting ] = class_exists( 'Akismet' ) ? Akismet::get_api_key() : '';
484 512 }
485 513 break;
486 514
487 - case 'onboarding':
488 - $business_address = get_option( 'jpo_business_address' );
489 - $business_address = is_array( $business_address ) ? array_map( array( $this, 'decode_special_characters' ), $business_address ) : $business_address;
490 -
491 - $response[ $setting ] = array(
492 - 'siteTitle' => $this->decode_special_characters( get_option( 'blogname' ) ),
493 - 'siteDescription' => $this->decode_special_characters( get_option( 'blogdescription' ) ),
494 - 'siteType' => get_option( 'jpo_site_type' ),
495 - 'homepageFormat' => get_option( 'jpo_homepage_format' ),
496 - 'addContactForm' => (int) get_option( 'jpo_contact_page' ),
497 - 'businessAddress' => $business_address,
498 - 'installWooCommerce' => is_plugin_active( 'woocommerce/woocommerce.php' ),
499 - 'stats' => Jetpack::is_connection_ready() && Jetpack::is_module_active( 'stats' ),
500 - );
501 - break;
502 -
503 515 case 'search_auto_config':
504 516 // Only writable.
505 517 $response[ $setting ] = 1;
506 518 break;
@@ -505,9 +517,9 @@
505 517 $response[ $setting ] = 1;
506 518 break;
507 519
508 520 default:
509 - $default = isset( $settings[ $setting ]['default'] ) ? $settings[ $setting ]['default'] : false;
521 + $default = $settings[ $setting ]['default'] ?? false;
510 522 $response[ $setting ] = Jetpack_Core_Json_Api_Endpoints::cast_value( get_option( $setting, $default ), $settings[ $setting ] );
511 523 break;
512 524 }
513 525 }
@@ -513,25 +525,23 @@
513 525 }
514 526
515 527 $response['akismet'] = is_plugin_active( 'akismet/akismet.php' );
516 528
529 + require_once JETPACK__PLUGIN_DIR . '/modules/memberships/class-jetpack-memberships.php';
530 + if ( class_exists( 'Jetpack_Memberships' ) ) {
531 + $response['newsletter_has_active_plan'] = count( Jetpack_Memberships::get_all_newsletter_plan_ids( false ) ) > 0;
532 + }
533 +
534 + // Make sure we are returning a consistent type
535 + if ( ! class_exists( 'Jetpack_Newsletter_Category_Helper' ) ) {
536 + require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-newsletter-category-helper.php';
537 + }
538 + $response['wpcom_newsletter_categories'] = Jetpack_Newsletter_Category_Helper::get_category_ids();
539 +
517 540 return rest_ensure_response( $response );
518 541 }
519 542
520 543 /**
521 - * Decode the special HTML characters in a certain value.
522 - *
523 - * @since 5.8
524 - *
525 - * @param string $value Value to decode.
526 - *
527 - * @return string Value with decoded HTML characters.
528 - */
529 - private function decode_special_characters( $value ) {
530 - return (string) htmlspecialchars_decode( $value, ENT_QUOTES );
531 - }
532 -
533 - /**
534 544 * If it's a valid Jetpack module and configuration parameters have been sent, update it.
535 545 *
536 546 * @since 4.3.0
537 547 *
@@ -540,9 +550,9 @@
540 550 *
541 551 * @type string $slug Module slug.
542 552 * }
543 553 *
544 - * @return bool|WP_Error True if module was updated. Otherwise, a WP_Error instance with the corresponding error.
554 + * @return bool|WP_REST_Response|WP_Error True or a WP_REST_Response if module was updated. Otherwise, a WP_Error instance with the corresponding error.
545 555 */
546 556 public function update_data( $request ) {
547 557
548 558 // If it's null, we're trying to update many module options from different modules.
@@ -562,9 +572,9 @@
562 572 }
563 573
564 574 /*
565 575 * Get parameters to update the module.
566 - * We can not simply use $request->get_params() because when we registered this route,
576 + * We cannot simply use $request->get_params() because when we registered this route,
567 577 * we are adding the entire output of Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list()
568 578 * to the current request object's params. We are interested in body of the actual request.
569 579 * This may be JSON:
570 580 */
@@ -649,13 +659,22 @@
649 659 if ( ! $updated ) {
650 660 $not_updated[ $option ] = $error;
651 661 }
652 662
663 + if ( $updated ) {
664 + // Return the module state.
665 + $response[ $option ] = $value;
666 + }
667 +
653 668 // Remove module from list so we don't go through it again.
654 669 unset( $params[ $option ] );
655 670 }
656 671 }
657 672
673 + if ( ! class_exists( 'Jetpack_Newsletter_Category_Helper' ) ) {
674 + require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-newsletter-category-helper.php';
675 + }
676 +
658 677 foreach ( $params as $option => $value ) {
659 678
660 679 // Used if there was an error. Can be overwritten with specific error messages.
661 680 $error = '';
@@ -665,8 +684,14 @@
665 684
666 685 // Get option attributes, including the group it belongs to.
667 686 $option_attrs = $options[ $option ];
668 687
688 + // Everything outside the Post by Email group requires the admin capability.
689 + if ( 'post-by-email' !== $option_attrs['jp_group'] && ! current_user_can( 'jetpack_configure_modules' ) ) {
690 + $not_updated[ $option ] = REST_Connector::get_user_permissions_error_msg();
691 + continue;
692 + }
693 +
669 694 // If this is a module option and the related module isn't active for any reason, continue with the next one.
670 695 if ( 'settings' !== $option_attrs['jp_group'] ) {
671 696 if ( ! Jetpack::is_module( $option_attrs['jp_group'] ) ) {
672 697 $not_updated[ $option ] = esc_html__( 'The requested Jetpack module was not found.', 'jetpack' );
@@ -717,8 +742,13 @@
717 742 $updated = get_option( 'WPLANG' ) === $language ? true : update_option( 'WPLANG', $language );
718 743 break;
719 744
720 745 case 'monitor_receive_notifications':
746 + if ( ! class_exists( 'Jetpack_Monitor' ) ) {
747 + $updated = false;
748 + break;
749 + }
750 +
721 751 $monitor = new Jetpack_Monitor();
722 752
723 753 // If we got true as response, consider it done.
724 754 $updated = true === $monitor->update_option_receive_jetpack_monitor_notification( $value );
@@ -724,8 +754,13 @@
724 754 $updated = true === $monitor->update_option_receive_jetpack_monitor_notification( $value );
725 755 break;
726 756
727 757 case 'post_by_email_address':
758 + if ( ! class_exists( 'Jetpack_Post_By_Email' ) ) {
759 + $updated = false;
760 + break;
761 + }
762 +
728 763 $result = Jetpack_Post_By_Email::init()->process_api_request( $value );
729 764
730 765 // If we got an email address (create or regenerate) or 1 (delete), consider it done.
731 766 if ( is_string( $result ) && preg_match( '/[a-z0-9][email protected]/', $result ) ) {
@@ -746,9 +781,9 @@
746 781 $result = false;
747 782 }
748 783
749 784 // If we got one of Protect keys, consider it done.
750 - if ( preg_match( '/[a-z0-9]{40,}/i', $result ) ) {
785 + if ( is_string( $result ) && preg_match( '/[a-z0-9]{40,}/i', $result ) ) {
751 786 $response[ $option ] = $result;
752 787 $updated = true;
753 788 }
754 789 break;
@@ -799,15 +834,16 @@
799 834 case 'facebook':
800 835 $grouped_options_current = (array) get_option( 'verification_services_codes' );
801 836 $grouped_options = $grouped_options_current;
802 837
803 - // Extracts the content attribute from the HTML meta tag if needed.
804 - if ( preg_match( '#.*<meta name="(?:[^"]+)" content="([^"]+)" />.*#i', $value, $matches ) ) {
805 - $grouped_options[ $option ] = $matches[1];
806 - } else {
807 - $grouped_options[ $option ] = $value;
838 + $validated_code = jetpack_verification_validate_code( $value );
839 + if ( false === $validated_code ) {
840 + $error = esc_html__( 'The site verification code is invalid.', 'jetpack' );
841 + break;
808 842 }
809 843
844 + $grouped_options[ $option ] = $validated_code;
845 +
810 846 // If option value was the same, consider it done.
811 847 $updated = $grouped_options_current !== $grouped_options
812 848 ? update_option( 'verification_services_codes', $grouped_options )
813 849 : true;
@@ -812,8 +848,17 @@
812 848 ? update_option( 'verification_services_codes', $grouped_options )
813 849 : true;
814 850 break;
815 851
852 + case Jetpack_SEO_Utils::FRONT_PAGE_META_OPTION:
853 + Jetpack_SEO_Utils::update_front_page_meta_description( $value );
854 + $response[ $option ] = Jetpack_SEO_Utils::get_front_page_meta_description();
855 + // The helper returns an empty string for a successful clear or
856 + // same-value write, so use its authoritative getter for the response
857 + // and treat every valid request reaching this switch as handled.
858 + $updated = true;
859 + break;
860 +
816 861 case 'sharing_services':
817 862 if ( ! class_exists( 'Sharing_Service' ) && ! include_once JETPACK__PLUGIN_DIR . 'modules/sharedaddy/sharing-service.php' ) {
818 863 break;
819 864 }
@@ -961,27 +1006,37 @@
961 1006 ? update_option( $option, (bool) $value )
962 1007 : true;
963 1008 break;
964 1009
965 - case 'onboarding':
966 - require_once JETPACK__PLUGIN_DIR . '_inc/lib/widgets.php';
967 - // Break apart and set Jetpack onboarding options.
968 - $result = $this->process_onboarding( (array) $value );
969 - if ( empty( $result ) ) {
970 - $updated = true;
971 - } else {
972 - $error = sprintf(
973 - /* Translators: placeholder is a list of error codes. */
974 - esc_html__( 'Onboarding failed to process: %s', 'jetpack' ),
975 - $result
976 - );
977 - $updated = false;
978 - }
1010 + case 'jetpack_subscriptions_reply_to':
1011 + // If option value was the same, consider it done.
1012 + require_once JETPACK__PLUGIN_DIR . 'modules/subscriptions/class-settings.php';
1013 + $sub_value = Automattic\Jetpack\Modules\Subscriptions\Settings::is_valid_reply_to( $value )
1014 + ? $value
1015 + : Automattic\Jetpack\Modules\Subscriptions\Settings::$default_reply_to;
1016 +
1017 + $updated = (string) get_option( $option ) !== (string) $sub_value ? update_option( $option, $sub_value ) : true;
979 1018 break;
1019 + case 'jetpack_subscriptions_from_name':
1020 + // If option value was the same, consider it done.
1021 + $sub_value = sanitize_text_field( $value );
1022 + $updated = (string) get_option( $option ) !== (string) $sub_value ? update_option( $option, $sub_value ) : true;
1023 + break;
980 1024
981 1025 case 'stb_enabled':
982 1026 case 'stc_enabled':
983 1027 case 'sm_enabled':
1028 + case 'jetpack_subscribe_overlay_enabled':
1029 + case 'jetpack_subscribe_floating_button_enabled':
1030 + case 'wpcom_newsletter_categories_enabled':
1031 + case 'wpcom_featured_image_in_email':
1032 + case 'jetpack_gravatar_in_email':
1033 + case 'jetpack_author_in_email':
1034 + case 'jetpack_post_date_in_email':
1035 + case 'wpcom_subscription_emails_use_excerpt':
1036 + case 'jetpack_subscriptions_subscribe_post_end_enabled':
1037 + case 'jetpack_subscriptions_login_navigation_enabled':
1038 + case 'jetpack_subscriptions_subscribe_navigation_enabled':
984 1039 // Convert the false value to 0. This allows the option to be updated if it doesn't exist yet.
985 1040 $sub_value = $value ? $value : 0;
986 1041 $updated = (string) get_option( $option ) !== (string) $sub_value ? update_option( $option, $sub_value ) : true;
987 1042 break;
@@ -989,8 +1044,119 @@
989 1044 case 'jetpack_blocks_disabled':
990 1045 $updated = (bool) get_option( $option ) !== (bool) $value ? update_option( $option, (bool) $value ) : true;
991 1046 break;
992 1047
1048 + case 'subscription_options':
1049 + if ( ! is_array( $value ) ) {
1050 + break;
1051 + }
1052 +
1053 + $allowed_keys = array( 'invitation', 'comment_follow', 'welcome', 'subscribe_modal_heading', 'free_tier_description', 'hide_free_tier' );
1054 + $filtered_value = array_filter(
1055 + $value,
1056 + function ( $key ) use ( $allowed_keys ) {
1057 + return in_array( $key, $allowed_keys, true );
1058 + },
1059 + ARRAY_FILTER_USE_KEY
1060 + );
1061 +
1062 + if ( empty( $filtered_value ) ) {
1063 + break;
1064 + }
1065 +
1066 + // `hide_free_tier` is a boolean flag, so pull it out before the HTML
1067 + // sanitization below (which expects strings). Sanitize it with
1068 + // rest_sanitize_boolean() so stringy booleans (e.g. "false", "0")
1069 + // are interpreted correctly rather than being treated as truthy by a
1070 + // plain `! empty()`.
1071 + $has_hide_free_tier = array_key_exists( 'hide_free_tier', $filtered_value );
1072 + $hide_free_tier = $has_hide_free_tier && rest_sanitize_boolean( $filtered_value['hide_free_tier'] );
1073 + unset( $filtered_value['hide_free_tier'] );
1074 +
1075 + array_walk_recursive(
1076 + $filtered_value,
1077 + function ( &$value ) {
1078 + $value = wp_kses(
1079 + $value,
1080 + array(
1081 + 'ul' => array(),
1082 + 'li' => array(),
1083 + 'p' => array(),
1084 + 'strong' => array(),
1085 + 'ol' => array(),
1086 + 'em' => array(),
1087 + 'a' => array(
1088 + 'href' => array(),
1089 + ),
1090 + )
1091 + );
1092 + }
1093 + );
1094 +
1095 + // Normalize whitespace-only `subscribe_modal_heading` input to empty so
1096 + // the modal template's `empty()` fallback fires. PHP's `empty()` treats
1097 + // `" "` as non-empty, which would otherwise render a blank heading.
1098 + if ( isset( $filtered_value['subscribe_modal_heading'] ) ) {
1099 + $filtered_value['subscribe_modal_heading'] = trim( $filtered_value['subscribe_modal_heading'] );
1100 + }
1101 +
1102 + // The free tier description is stored as plain markdown source, so strip
1103 + // all HTML and cap its length to match the paid-tier description field.
1104 + // WordPress core guarantees mb_substr() (polyfilled in wp-includes/compat.php
1105 + // when the mbstring extension is unavailable), so it's safe to use directly.
1106 + // A JSON payload could supply a non-scalar (array/object) for this field,
1107 + // which would fatal in wp_kses()/mb_substr() on PHP 8+, so drop invalid values.
1108 + if ( isset( $filtered_value['free_tier_description'] ) ) {
1109 + if ( is_scalar( $filtered_value['free_tier_description'] ) ) {
1110 + $filtered_value['free_tier_description'] = mb_substr( wp_kses( (string) $filtered_value['free_tier_description'], array() ), 0, 500 );
1111 + } else {
1112 + unset( $filtered_value['free_tier_description'] );
1113 + }
1114 + }
1115 +
1116 + if ( $has_hide_free_tier ) {
1117 + $filtered_value['hide_free_tier'] = $hide_free_tier;
1118 + }
1119 +
1120 + $old_subscription_options = get_option( 'subscription_options' );
1121 + if ( ! is_array( $old_subscription_options ) ) {
1122 + $old_subscription_options = array();
1123 + }
1124 + $new_subscription_options = array_merge( $old_subscription_options, $filtered_value );
1125 + $updated = true;
1126 +
1127 + if ( serialize( $old_subscription_options ) === serialize( $new_subscription_options ) ) { // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.serialize_serialize
1128 + break; // This prevents the option update to fail when the values are the same.
1129 + }
1130 +
1131 + if ( ! update_option( $option, $new_subscription_options ) ) {
1132 + $updated = false;
1133 + $error = esc_html__( 'Subscription Options failed to process.', 'jetpack' );
1134 + }
1135 + break;
1136 +
1137 + case Jetpack_Newsletter_Category_Helper::NEWSLETTER_CATEGORIES_OPTION:
1138 + if ( ! is_array( $value ) || empty( $value ) ) {
1139 + $updated = true;
1140 + break;
1141 + }
1142 +
1143 + // If we are already current, do nothing
1144 + $current_value = Jetpack_Newsletter_Category_Helper::get_category_ids();
1145 + if ( $value === $current_value ) {
1146 + $updated = true;
1147 + break;
1148 + }
1149 +
1150 + if ( Jetpack_Newsletter_Category_Helper::save_category_ids( $value ) ) {
1151 + $updated = true;
1152 + } else {
1153 + $updated = false;
1154 + $error = esc_html__( 'Newsletter category did not update.', 'jetpack' );
1155 + }
1156 +
1157 + break;
1158 +
993 1159 default:
994 1160 // Boolean values are stored as 1 or 0.
995 1161 if ( isset( $options[ $option ]['type'] ) && 'boolean' === $options[ $option ]['type'] ) {
996 1162 $value = (int) $value;
@@ -996,9 +1162,9 @@
996 1162 $value = (int) $value;
997 1163 }
998 1164
999 1165 // If option value was the same as it's current value, or it's default, consider it done.
1000 - $default = isset( $options[ $option ]['default'] ) ? $options[ $option ]['default'] : false;
1166 + $default = $options[ $option ]['default'] ?? false;
1001 1167 $updated = get_option( $option, $default ) != $value // phpcs:ignore Universal.Operators.StrictComparisons.LooseNotEqual -- ensure we support scalars or strings saved by update_option.
1002 1168 ? update_option( $option, $value )
1003 1169 : true;
1004 1170 break;
@@ -1052,218 +1218,30 @@
1052 1218 * Perform tasks in the site based on onboarding choices.
1053 1219 *
1054 1220 * @since 5.4.0
1055 1221 *
1222 + * @deprecated since 13.9
1223 + *
1056 1224 * @param array $data Onboarding choices made by user.
1057 1225 *
1058 1226 * @return string Result of onboarding processing and, if there is one, an error message.
1059 1227 */
1060 - private function process_onboarding( $data ) {
1061 - if ( isset( $data['end'] ) && $data['end'] ) {
1062 - return Jetpack::invalidate_onboarding_token()
1063 - ? ''
1064 - : esc_html__( "The onboarding token couldn't be deleted.", 'jetpack' );
1065 - }
1066 -
1067 - $error = array();
1068 -
1069 - if ( ! empty( $data['siteTitle'] ) ) {
1070 - // If option value was the same, consider it done.
1071 - if ( ! (
1072 - update_option( 'blogname', $data['siteTitle'] )
1073 - || get_option( 'blogname' ) === $data['siteTitle']
1074 - ) ) {
1075 - $error[] = 'siteTitle';
1076 - }
1077 - }
1078 -
1079 - if ( isset( $data['siteDescription'] ) ) {
1080 - // If option value was the same, consider it done.
1081 - if ( ! (
1082 - update_option( 'blogdescription', $data['siteDescription'] )
1083 - || get_option( 'blogdescription' ) === $data['siteDescription']
1084 - ) ) {
1085 - $error[] = 'siteDescription';
1086 - }
1087 - }
1088 -
1089 - $site_title = get_option( 'blogname' );
1090 - $author = get_current_user_id() || 1;
1091 -
1092 - if ( ! empty( $data['siteType'] ) ) {
1093 - if ( ! (
1094 - update_option( 'jpo_site_type', $data['siteType'] )
1095 - || get_option( 'jpo_site_type' ) === $data['siteType']
1096 - ) ) {
1097 - $error[] = 'siteType';
1098 - }
1099 - }
1100 -
1101 - if ( isset( $data['homepageFormat'] ) ) {
1102 - /*
1103 - * If $data['homepageFormat'] is 'posts',
1104 - * we have nothing to do since it's WordPress' default
1105 - * if it exists, just update
1106 - */
1107 - $homepage_format = get_option( 'jpo_homepage_format' );
1108 - if ( ! $homepage_format || $homepage_format !== $data['homepageFormat'] ) {
1109 - if ( 'page' === $data['homepageFormat'] ) {
1110 - if ( ! (
1111 - update_option( 'show_on_front', 'page' )
1112 - || get_option( 'show_on_front' ) === 'page'
1113 - ) ) {
1114 - $error[] = 'homepageFormat';
1115 - }
1116 -
1117 - $home = wp_insert_post(
1118 - array(
1119 - 'post_type' => 'page',
1120 - /* translators: this references the home page of a site, also called front page. */
1121 - 'post_title' => esc_html_x( 'Home Page', 'The home page of a website.', 'jetpack' ),
1122 - 'post_content' => sprintf(
1123 - /* Translators: placeholder is the site title. */
1124 - esc_html__( 'Welcome to %s.', 'jetpack' ),
1125 - $site_title
1126 - ),
1127 - 'post_status' => 'publish',
1128 - 'post_author' => $author,
1129 - )
1130 - );
1131 - if ( 0 === $home ) {
1132 - $error[] = 'home insert: 0';
1133 - } elseif ( is_wp_error( $home ) ) {
1134 - $error[] = 'home creation: ' . $home->get_error_message();
1135 - }
1136 - if ( ! (
1137 - update_option( 'page_on_front', $home )
1138 - || get_option( 'page_on_front' ) === $home
1139 - ) ) {
1140 -
1141 - $error[] = 'home set';
1142 - }
1143 -
1144 - $blog = wp_insert_post(
1145 - array(
1146 - 'post_type' => 'page',
1147 - /* translators: this references the page where blog posts are listed. */
1148 - 'post_title' => esc_html_x( 'Blog', 'The blog of a website.', 'jetpack' ),
1149 - 'post_content' => sprintf(
1150 - /* Translators: placeholder is the site title. */
1151 - esc_html__( 'These are the latest posts in %s.', 'jetpack' ),
1152 - $site_title
1153 - ),
1154 - 'post_status' => 'publish',
1155 - 'post_author' => $author,
1156 - )
1157 - );
1158 - if ( 0 === $blog ) {
1159 - $error[] = 'blog insert: 0';
1160 - } elseif ( is_wp_error( $blog ) ) {
1161 - $error[] = 'blog creation: ' . $blog->get_error_message();
1162 - }
1163 - if ( ! (
1164 - update_option( 'page_for_posts', $blog )
1165 - || get_option( 'page_for_posts' ) === $blog
1166 - ) ) {
1167 - $error[] = 'blog set';
1168 - }
1169 - } else {
1170 - $front_page = get_option( 'page_on_front' );
1171 - $posts_page = get_option( 'page_for_posts' );
1172 - if ( $posts_page && get_post( $posts_page ) ) {
1173 - wp_delete_post( $posts_page );
1174 - }
1175 - if ( $front_page && get_post( $front_page ) ) {
1176 - wp_delete_post( $front_page );
1177 - }
1178 - update_option( 'show_on_front', 'posts' );
1179 - }
1180 - }
1181 - update_option( 'jpo_homepage_format', $data['homepageFormat'] );
1182 - }
1183 -
1184 - // Setup contact page and add a form and/or business info.
1185 - $contact_page = '';
1186 - if ( ! empty( $data['addContactForm'] ) && ! get_option( 'jpo_contact_page' ) ) {
1187 - $contact_form_module_active = Jetpack::is_module_active( 'contact-form' );
1188 - if ( ! $contact_form_module_active ) {
1189 - $contact_form_module_active = Jetpack::activate_module( 'contact-form', false, false );
1190 - }
1191 -
1192 - if ( $contact_form_module_active ) {
1193 - $contact_page = '[contact-form][contact-field label="' . esc_html__( 'Name', 'jetpack' ) . '" type="name" required="true" /][contact-field label="' . esc_html__( 'Email', 'jetpack' ) . '" type="email" required="true" /][contact-field label="' . esc_html__( 'Website', 'jetpack' ) . '" type="url" /][contact-field label="' . esc_html__( 'Message', 'jetpack' ) . '" type="textarea" /][/contact-form]';
1194 - } else {
1195 - $error[] = 'contact-form activate';
1196 - }
1197 - }
1198 -
1199 - if ( isset( $data['businessPersonal'] ) && 'business' === $data['businessPersonal'] ) {
1200 - $contact_page .= "\n" . implode( "\n", $data['businessInfo'] );
1201 - }
1202 -
1203 - if ( ! empty( $contact_page ) ) {
1204 - $form = wp_insert_post(
1205 - array(
1206 - 'post_type' => 'page',
1207 - /* translators: this references a page with contact details and possibly a form. */
1208 - 'post_title' => esc_html_x( 'Contact us', 'Contact page for your website.', 'jetpack' ),
1209 - 'post_content' => esc_html__( 'Send us a message!', 'jetpack' ) . "\n" . $contact_page,
1210 - 'post_status' => 'publish',
1211 - 'post_author' => $author,
1212 - )
1213 - );
1214 - if ( 0 === $form ) {
1215 - $error[] = 'form insert: 0';
1216 - } elseif ( is_wp_error( $form ) ) {
1217 - $error[] = 'form creation: ' . $form->get_error_message();
1218 - } else {
1219 - update_option( 'jpo_contact_page', $form );
1220 - }
1221 - }
1222 -
1223 - if ( isset( $data['businessAddress'] ) ) {
1224 - $handled_business_address = self::handle_business_address( $data['businessAddress'] );
1225 - if ( is_wp_error( $handled_business_address ) ) {
1226 - $error[] = 'BusinessAddress';
1227 - }
1228 - }
1229 -
1230 - if ( ! empty( $data['installWooCommerce'] ) ) {
1231 - $wc_install_result = Plugins_Installer::install_and_activate_plugin( 'woocommerce' );
1232 - delete_transient( '_wc_activation_redirect' ); // Redirecting to WC setup would kill our users' flow.
1233 - if ( is_wp_error( $wc_install_result ) ) {
1234 - $error[] = 'woocommerce installation';
1235 - }
1236 - }
1237 -
1238 - if ( ! empty( $data['stats'] ) ) {
1239 - if ( Jetpack::is_connection_ready() ) {
1240 - $stats_module_active = Jetpack::is_module_active( 'stats' );
1241 - if ( ! $stats_module_active ) {
1242 - $stats_module_active = Jetpack::activate_module( 'stats', false, false );
1243 - }
1244 -
1245 - if ( ! $stats_module_active ) {
1246 - $error[] = 'stats activate';
1247 - }
1248 - } else {
1249 - $error[] = 'stats not connected';
1250 - }
1251 - }
1252 -
1253 - return empty( $error )
1254 - ? ''
1255 - : implode( ', ', $error );
1228 + private function process_onboarding( $data ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
1229 + _deprecated_function( __METHOD__, '13.9' );
1230 + return '';
1256 1231 }
1257 1232
1258 1233 /**
1259 1234 * Add or update Business Address widget.
1260 1235 *
1236 + * @deprecated since 13.9
1237 + *
1261 1238 * @param array $address Array of business address fields.
1262 1239 *
1263 1240 * @return WP_Error|true True if the data was saved correctly.
1264 1241 */
1265 1242 private static function handle_business_address( $address ) {
1243 + _deprecated_function( __METHOD__, '13.9' );
1266 1244 $first_sidebar = Jetpack_Widgets::get_first_sidebar();
1267 1245
1268 1246 $widgets_module_active = Jetpack::is_module_active( 'widgets' );
1269 1247 if ( ! $widgets_module_active ) {
@@ -1347,13 +1325,8 @@
1347 1325 *
1348 1326 * @return bool
1349 1327 */
1350 1328 public function can_request( $request ) {
1351 - $req_params = $request->get_params();
1352 - if ( ! empty( $req_params['onboarding']['token'] ) && isset( $req_params['rest_route'] ) ) {
1353 - return Jetpack::validate_onboarding_token_action( $req_params['onboarding']['token'], $req_params['rest_route'] );
1354 - }
1355 -
1356 1329 if ( 'GET' === $request->get_method() ) {
1357 1330 return current_user_can( 'jetpack_admin_page' );
1358 1331 } else {
1359 1332 $module = Jetpack_Core_Json_Api_Endpoints::get_module_requested();
@@ -1362,13 +1335,13 @@
1362 1335 if ( ! is_array( $params ) ) {
1363 1336 $params = $request->get_body_params();
1364 1337 }
1365 1338 $options = Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list( $params );
1366 - foreach ( $options as $option => $definition ) {
1367 - if ( in_array( $options[ $option ]['jp_group'], array( 'post-by-email' ), true ) ) {
1368 - $module = $options[ $option ]['jp_group'];
1369 - break;
1370 - }
1339 +
1340 + // The Post by Email gate applies only when the request contains nothing else.
1341 + $groups = array_values( array_unique( array_column( $options, 'jp_group' ) ) );
1342 + if ( array( 'post-by-email' ) === $groups ) {
1343 + $module = 'post-by-email';
1371 1344 }
1372 1345 }
1373 1346 // User is trying to create, regenerate or delete its PbE.
1374 1347 if ( 'post-by-email' === $module ) {
@@ -1384,9 +1357,8 @@
1384 1357 *
1385 1358 * phpcs:disable Generic.Files.OneObjectStructurePerFile.MultipleFound
1386 1359 */
1387 1360 class Jetpack_Core_API_Module_Data_Endpoint {
1388 - // phpcs:disable Generic.Files.OneObjectStructurePerFile.MultipleFound
1389 1361
1390 1362 /**
1391 1363 * Process request and return different data based on the module we are interested in.
1392 1364 *
@@ -1575,32 +1547,26 @@
1575 1547 ) {
1576 1548 $range = 'day';
1577 1549 }
1578 1550
1579 - if ( ! function_exists( 'convert_stats_array_to_object' ) ) {
1580 - require_once JETPACK__PLUGIN_DIR . 'modules/stats.php';
1581 - }
1582 -
1583 1551 $wpcom_stats = new WPCOM_Stats();
1584 1552 switch ( $range ) {
1585 1553
1586 1554 // This is always called first on page load.
1587 1555 case 'day':
1588 - $initial_stats = convert_stats_array_to_object( $wpcom_stats->get_stats() );
1556 + $initial_stats = $wpcom_stats->convert_stats_array_to_object( $wpcom_stats->get_stats() );
1589 1557 return rest_ensure_response(
1590 1558 array(
1591 1559 'general' => $initial_stats,
1592 1560
1593 1561 // Build data for 'day' as if it was $wpcom_stats ->get_visits( array( 'unit' => 'day, 'quantity' => 30).
1594 - 'day' => isset( $initial_stats->visits )
1595 - ? $initial_stats->visits
1596 - : array(),
1562 + 'day' => $initial_stats->visits ?? array(),
1597 1563 )
1598 1564 );
1599 1565 case 'week':
1600 1566 return rest_ensure_response(
1601 1567 array(
1602 - 'week' => convert_stats_array_to_object(
1568 + 'week' => $wpcom_stats->convert_stats_array_to_object(
1603 1569 $wpcom_stats->get_visits(
1604 1570 array(
1605 1571 'unit' => 'week',
1606 1572 'quantity' => 14,
@@ -1611,9 +1577,9 @@
1611 1577 );
1612 1578 case 'month':
1613 1579 return rest_ensure_response(
1614 1580 array(
1615 - 'month' => convert_stats_array_to_object(
1581 + 'month' => $wpcom_stats->convert_stats_array_to_object(
1616 1582 $wpcom_stats->get_visits(
1617 1583 array(
1618 1584 'unit' => 'month',
1619 1585 'quantity' => 12,
@@ -1735,9 +1701,9 @@
1735 1701 $last_service = $copy_services[ $last ];
1736 1702 unset( $copy_services[ $last ] );
1737 1703 $message = esc_html(
1738 1704 sprintf(
1739 - /* translators: %1$s is a comma separated list of services, and %2$s is a single service name like Google, Bing, Pinterest, etc. */
1705 + /* translators: %1$s is a comma-separated list of services, and %2$s is a single service name like Google, Bing, Pinterest, etc. */
1740 1706 __( 'Your site is verified with %1$s and %2$s.', 'jetpack' ),
1741 1707 implode( ', ', $copy_services ),
1742 1708 $last_service
1743 1709 )