PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | json-endpoints/class.wpcom-json-api-edit-media-v1-2-endpoint.php +31 -25 13.0.2 → 16.3-a.7 View file →
@@ -1,6 +1,10 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 +if ( ! defined( 'ABSPATH' ) ) {
4 + exit( 0 );
5 +}
6 +
3 7 require_once JETPACK__PLUGIN_DIR . '_inc/lib/class.media.php';
4 8
5 9 define( 'REVISION_HISTORY_MAXIMUM_AMOUNT', 5 );
6 10 define( 'WP_ATTACHMENT_IMAGE_ALT', '_wp_attachment_image_alt' );
@@ -33,9 +37,9 @@
33 37 'jpg, jpeg, png, gif, pdf, doc, ppt, odt, pptx, docx, pps, ppsx, xls, xlsx, key. ' .
34 38 'Audio and Video may also be available. See <code>allowed_file_types</code> ' .
35 39 'in the options response of the site endpoint. ' .
36 40 '<br /><br /><strong>Example</strong>:<br />' .
37 - "<code>curl \<br />--form 'title=Image' \<br />--form 'media=@/path/to/file.jpg' \<br />-H 'Authorization: BEARER your-token' \<br />'https://public-api.wordpress.com/rest/v1/sites/123/posts/new'</code>",
41 + "<code>curl \<br />--form 'title=Image' \<br />--form 'media=@/path/to/file.jpg' \<br />-H 'Authorization: BEARER your-token' \<br />'https://public-api.wordpress.com/rest/v1/sites/123/media/new'</code>",
38 42 'attrs' => '(object) An Object of attributes (`title`, `description` and `caption`) ' .
39 43 'are supported to assign to the media uploaded via the `media` or `media_url`',
40 44 'media_url' => '(string) An URL of the image to attach to a post.',
41 45 ),
@@ -80,16 +84,18 @@
80 84 );
81 85
82 86 /**
83 87 * Edit media v1_2 endpoint class.
88 + *
89 + * @phan-constructor-used-for-side-effects
84 90 */
85 91 class WPCOM_JSON_API_Edit_Media_v1_2_Endpoint extends WPCOM_JSON_API_Update_Media_v1_1_Endpoint { //phpcs:ignore
86 92 /**
87 93 * Return an array of mime_type items allowed when the media file is uploaded.
88 94 *
89 - * @param Array $default_mime_types - array of default mime types.
95 + * @param array $default_mime_types - array of default mime types.
90 96 *
91 - * @return {Array} mime_type array
97 + * @return array mime_type array
92 98 */
93 99 public static function get_allowed_mime_types( $default_mime_types ) {
94 100 return array_unique(
95 101 array_merge(
@@ -112,10 +118,10 @@
112 118 /**
113 119 * Update the media post grabbing the post values from
114 120 * the `attrs` parameter
115 121 *
116 - * @param {Number} $media_id - post media ID.
117 - * @param {Object} $attrs - `attrs` parameter sent from the client in the request body.
122 + * @param int $media_id - post media ID.
123 + * @param array $attrs - `attrs` parameter sent from the client in the request body.
118 124 */
119 125 private function update_by_attrs_parameter( $media_id, $attrs ) {
120 126 $post_update_action = null;
121 127 $insert = array();
@@ -176,10 +182,10 @@
176 182
177 183 /**
178 184 * Return an object to be used to store into the revision_history
179 185 *
180 - * @param {Object} $media_item - media post object.
181 - * @return {Object} the snapshot object
186 + * @param object $media_item - media post object.
187 + * @return object the snapshot object
182 188 */
183 189 private function get_snapshot( $media_item ) {
184 190 $current_file = get_attached_file( $media_item->ID );
185 191 $file_paths = pathinfo( $current_file );
@@ -198,9 +204,9 @@
198 204
199 205 /**
200 206 * Try to remove the temporal file from the given file array.
201 207 *
202 - * @param {Array} $file_array - Array with data about the temporal file.
208 + * @param array $file_array - Array with data about the temporal file.
203 209 */
204 210 private function remove_tmp_file( $file_array ) {
205 211 if ( file_exists( $file_array['tmp_name'] ) ) {
206 212 wp_delete_file( $file_array['tmp_name'] );
@@ -209,12 +215,12 @@
209 215
210 216 /**
211 217 * Save the given temporal file in a local folder.
212 218 *
213 - * @param {Array} $file_array - array containing file data.
214 - * @param {Number} $media_id - the media id.
215 - * @param {bool} $is_upload - True if `$file_array` derives from an upload in `$_FILES`, false if this is a sideload.
216 - * @return {Array|WP_Error} An array with information about the new file saved or a WP_Error is something went wrong.
219 + * @param array $file_array - array containing file data.
220 + * @param int $media_id - the media id.
221 + * @param bool $is_upload - True if `$file_array` derives from an upload in `$_FILES`, false if this is a sideload.
222 + * @return array|WP_Error An array with information about the new file saved or a WP_Error is something went wrong.
217 223 */
218 224 private function save_temporary_file( $file_array, $media_id, $is_upload ) {
219 225 $tmp_filename = $file_array['tmp_name'];
220 226
@@ -295,11 +301,11 @@
295 301
296 302 /**
297 303 * Get the image from a remote url and then save it locally.
298 304 *
299 - * @param {Number} $media_id - media post ID.
300 - * @param {String} $url - image URL to save locally.
301 - * @return {Array|WP_Error} An array with information about the new file saved or a WP_Error is something went wrong.
305 + * @param int $media_id - media post ID.
306 + * @param string $url - image URL to save locally.
307 + * @return array|WP_Error An array with information about the new file saved or a WP_Error is something went wrong.
302 308 */
303 309 private function build_file_array_from_url( $media_id, $url ) {
304 310 if ( ! $url ) {
305 311 return null;
@@ -329,12 +335,12 @@
329 335
330 336 /**
331 337 * Add a new item into revision_history array.
332 338 *
333 - * @param {Object} $media_item - media post.
334 - * @param {file} $file - file recentrly added.
335 - * @param {Boolean} $has_original_media - condition is the original media has been already added.
336 - * @return {Boolean} `true` if the item has been added. Otherwise `false`.
339 + * @param object $media_item - media post.
340 + * @param array|WP_Error $file - File data, or WP_Error on error.
341 + * @param bool $has_original_media - condition is the original media has been already added.
342 + * @return bool `true` if the item has been added. Otherwise `false`.
337 343 */
338 344 private function register_revision( $media_item, $file, $has_original_media ) {
339 345 if (
340 346 is_wp_error( $file ) ||
@@ -348,11 +354,11 @@
348 354
349 355 /**
350 356 * Restore the original media file.
351 357 *
352 - * @param {Number} $media_id - media post ID.
353 - * @param {Object} $original_media - orginal media data.
354 - * @return {Array} - restore media info.
358 + * @param int $media_id - media post ID.
359 + * @param object $original_media - orginal media data.
360 + * @return array - restore media info.
355 361 */
356 362 private function restore_original( $media_id, $original_media ) {
357 363 $revisions = (array) Jetpack_Media::get_revision_history( $media_id );
358 364 $revisions = array_filter(
@@ -400,10 +406,10 @@
400 406 if ( is_wp_error( $media_item ) ) {
401 407 return $media_item;
402 408 }
403 409
404 - if ( ! current_user_can( 'upload_files', $media_id ) ) {
405 - return new WP_Error( 'unauthorized', 'User cannot view media', 403 );
410 + if ( ! $this->current_user_can_edit_media_item( $media_id ) ) {
411 + return new WP_Error( 'unauthorized', 'User cannot edit media', 403 );
406 412 }
407 413
408 414 $input = $this->input( true );
409 415
@@ -408,9 +414,9 @@
408 414 $input = $this->input( true );
409 415
410 416 // Images.
411 417 $media_file = isset( $input['media'] ) ? (array) $input['media'] : null;
412 - $media_url = isset( $input['media_url'] ) ? $input['media_url'] : null;
418 + $media_url = $input['media_url'] ?? null;
413 419 $media_attrs = isset( $input['attrs'] ) ? (array) $input['attrs'] : null;
414 420
415 421 if ( isset( $media_url ) || $media_file ) {
416 422 $user_can_upload_files = current_user_can( 'upload_files' ) || $this->api->is_authorized_with_upload_token();