PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | modules/comments/comments.php +343 -69 13.0.2 → 16.3-a.7 View file →
@@ -8,8 +8,12 @@
8 8 require __DIR__ . '/base.php';
9 9 use Automattic\Jetpack\Connection\Tokens;
10 10 use Automattic\Jetpack\Status\Host;
11 11
12 +if ( ! defined( 'ABSPATH' ) ) {
13 + exit( 0 );
14 +}
15 +
12 16 /**
13 17 * Main Comments class
14 18 *
15 19 * @package automattic/jetpack
@@ -84,9 +88,9 @@
84 88 */
85 89 public function set_default_color_theme_based_on_theme_settings() {
86 90 if ( function_exists( 'twentyeleven_get_theme_options' ) ) {
87 91 $theme_options = twentyeleven_get_theme_options();
88 - $theme_color_scheme = isset( $theme_options['color_scheme'] ) ? $theme_options['color_scheme'] : 'transparent';
92 + $theme_color_scheme = $theme_options['color_scheme'] ?? 'transparent';
89 93 } else {
90 94 $theme_color_scheme = get_theme_mod( 'color_scheme', 'transparent' );
91 95 }
92 96 // Default for $theme_color_scheme is 'transparent' just so it doesn't match 'light' or 'dark'.
@@ -120,13 +124,30 @@
120 124 );
121 125 }
122 126
123 127 /**
128 + * Whether the rebuilt Jetpack Comments form has taken over from this one.
129 + *
130 + * Guarded because this file and the jetpack-comments package can land in
131 + * either order on a staged deploy.
132 + *
133 + * @return bool
134 + */
135 + private static function new_comments_enabled() {
136 + return class_exists( '\Automattic\Jetpack\Comments\Comments' )
137 + && \Automattic\Jetpack\Comments\Comments::is_enabled();
138 + }
139 +
140 + /**
124 141 * Setup actions for methods in this class
125 142 *
126 143 * @since 1.4
127 144 */
128 145 protected function setup_actions() {
146 + if ( self::new_comments_enabled() ) {
147 + return;
148 + }
149 +
129 150 parent::setup_actions();
130 151
131 152 // Selfishly remove everything from the existing comment form.
132 153 remove_all_actions( 'comment_form_before' );
@@ -131,8 +152,9 @@
131 152 // Selfishly remove everything from the existing comment form.
132 153 remove_all_actions( 'comment_form_before' );
133 154
134 155 // Selfishly add only our actions back to the comment form.
156 + add_action( 'comment_form_before', array( $this, 'manage_post_cookie' ) );
135 157 add_action( 'comment_form_before', array( $this, 'comment_form_before' ) );
136 158 add_action( 'comment_form_after', array( $this, 'comment_form_after' ), 1 ); // Set very early since we remove everything outputed before our action.
137 159
138 160 // Before a comment is posted.
@@ -147,11 +169,16 @@
147 169 *
148 170 * @since 1.6.2
149 171 */
150 172 protected function setup_filters() {
173 + if ( self::new_comments_enabled() ) {
174 + return;
175 + }
176 +
151 177 parent::setup_filters();
152 178
153 179 add_filter( 'comment_post_redirect', array( $this, 'capture_comment_post_redirect_to_reload_parent_frame' ), 100 );
180 + add_filter( 'comment_duplicate_trigger', array( $this, 'capture_comment_duplicate_trigger' ), 100 );
154 181 add_filter( 'get_avatar', array( $this, 'get_avatar' ), 10, 4 );
155 182 // Fix comment reply link when `comment_registration` is required.
156 183 add_filter( 'comment_reply_link', array( $this, 'comment_reply_link' ), 10, 4 );
157 184 }
@@ -156,8 +183,55 @@
156 183 add_filter( 'comment_reply_link', array( $this, 'comment_reply_link' ), 10, 4 );
157 184 }
158 185
159 186 /**
187 + * In order for comments to work properly for password-protected posts we need to set `wp-postpass` cookie to SameSite none.
188 + */
189 + public function manage_post_cookie() {
190 + if ( headers_sent() ) {
191 + return;
192 + }
193 +
194 + $postpass_cookie_key = 'wp-postpass_' . COOKIEHASH;
195 +
196 + if ( empty( $_COOKIE[ $postpass_cookie_key ] ) ) {
197 + return;
198 + }
199 +
200 + $postpass_cookie_value = sanitize_text_field( wp_unslash( $_COOKIE[ $postpass_cookie_key ] ) );
201 +
202 + if ( empty( $_COOKIE['verbum-wp-postpass'] ) || ( $_COOKIE['verbum-wp-postpass'] !== $postpass_cookie_value ) ) {
203 + $expire = apply_filters( 'post_password_expires', time() + 10 * DAY_IN_SECONDS );
204 +
205 + setcookie(
206 + $postpass_cookie_key,
207 + $postpass_cookie_value,
208 + array(
209 + 'expires' => $expire,
210 + 'samesite' => 'None',
211 + 'path' => '/',
212 + 'domain' => COOKIE_DOMAIN,
213 + 'secure' => is_ssl(),
214 + 'httponly' => false, // phpcs:ignore Jetpack.Functions.SetCookie.FoundNonHTTPOnlyFalse -- @todo Can this be set true?
215 + )
216 + );
217 +
218 + setcookie(
219 + 'verbum-wp-postpass',
220 + $postpass_cookie_value,
221 + array(
222 + 'expires' => $expire,
223 + 'samesite' => 'None',
224 + 'path' => '/',
225 + 'domain' => COOKIE_DOMAIN,
226 + 'secure' => is_ssl(),
227 + 'httponly' => false, // phpcs:ignore Jetpack.Functions.SetCookie.FoundNonHTTPOnlyFalse -- @todo Can this be set true?
228 + )
229 + );
230 + }
231 + }
232 +
233 + /**
160 234 * Get the comment avatar from Gravatar or Twitter/Facebook.
161 235 *
162 236 * Leaving the Twitter reference for legacy comments even though support is no longer offered.
163 237 *
@@ -182,10 +256,18 @@
182 256 ! preg_match( '/\.?(graph\.facebook\.com|twimg\.com)$/', $foreign_avatar_hostname ) ) {
183 257 return $avatar;
184 258 }
185 259
186 - // Return the Facebook or Twitter avatar.
187 - return preg_replace( '#src=([\'"])[^\'"]+\\1#', 'src=\\1' . esc_url( set_url_scheme( $this->photon_avatar( $foreign_avatar, $size ), 'https' ) ) . '\\1', $avatar );
260 + // Insert the escaped URL through a callback: a preg_replace() replacement string would expand a
261 + // `$1` inside it into the captured quote, breaking out of the src attribute (stored-XSS vector).
262 + $photon_url = esc_url( set_url_scheme( $this->photon_avatar( $foreign_avatar, $size ), 'https' ) );
263 + return preg_replace_callback(
264 + '#src=([\'"])[^\'"]+\\1#',
265 + static function ( $matches ) use ( $photon_url ) {
266 + return 'src=' . $matches[1] . $photon_url . $matches[1];
267 + },
268 + $avatar
269 + );
188 270 }
189 271
190 272 /**
191 273 * Set comment reply link.
@@ -350,8 +432,9 @@
350 432 ),
351 433 'color_scheme' => get_option( 'jetpack_comment_form_color_scheme', $this->default_color_scheme ),
352 434 'lang' => get_locale(),
353 435 'jetpack_version' => JETPACK__VERSION,
436 + 'iframe_unique_id' => wp_unique_id(),
354 437 );
355 438
356 439 // Extra parameters for logged in user.
357 440 if ( is_user_logged_in() ) {
@@ -367,9 +450,9 @@
367 450 } else {
368 451 $commenter = wp_get_current_commenter();
369 452 $params['show_cookie_consent'] = (int) has_action( 'set_comment_cookies', 'wp_set_comment_cookies' );
370 453 $params['has_cookie_consent'] = (int) ! empty( $commenter['comment_author_email'] );
371 - // Jetpack_Memberships for logged out users only checks for the jp-premium-content-session cookie
454 + // Jetpack_Memberships for logged out users only checks for the wp-jp-premium-content-session cookie
372 455 $params['is_current_user_subscribed'] = class_exists( '\Jetpack_Memberships' ) ? (int) Jetpack_Memberships::is_current_user_subscribed() : 0;
373 456 }
374 457
375 458 list( $token_key ) = explode( '.', $blog_token->secret, 2 );
@@ -512,52 +595,72 @@
512 595 return;
513 596 }
514 597 ?>
515 598 <script type="text/javascript">
516 - const iframe = document.getElementById( 'jetpack_remote_comment' );
517 - <?php if ( get_option( 'thread_comments' ) && get_option( 'thread_comments_depth' ) ) : ?>
518 - const watchReply = function() {
519 - // Check addComment._Jetpack_moveForm to make sure we don't monkey-patch twice.
520 - if ( 'undefined' !== typeof addComment && ! addComment._Jetpack_moveForm ) {
521 - // Cache the Core function.
522 - addComment._Jetpack_moveForm = addComment.moveForm;
523 - const commentParent = document.getElementById( 'comment_parent' );
524 - const cancel = document.getElementById( 'cancel-comment-reply-link' );
599 + (function () {
600 + const iframe = document.getElementById( 'jetpack_remote_comment' );
601 + <?php if ( get_option( 'thread_comments' ) && get_option( 'thread_comments_depth' ) ) : ?>
602 + const watchReply = function() {
603 + // Check addComment._Jetpack_moveForm to make sure we don't monkey-patch twice.
604 + if ( 'undefined' !== typeof addComment && ! addComment._Jetpack_moveForm ) {
605 + // Cache the Core function.
606 + addComment._Jetpack_moveForm = addComment.moveForm;
607 + const commentParent = document.getElementById( 'comment_parent' );
608 + const cancel = document.getElementById( 'cancel-comment-reply-link' );
525 609
526 - function tellFrameNewParent ( commentParentValue ) {
527 - const url = new URL( iframe.src );
528 - if ( commentParentValue ) {
529 - url.searchParams.set( 'replytocom', commentParentValue )
530 - } else {
531 - url.searchParams.delete( 'replytocom' );
532 - }
533 - if( iframe.src !== url.href ) {
534 - iframe.src = url.href;
535 - }
536 - };
610 + function tellFrameNewParent ( commentParentValue ) {
611 + const url = new URL( iframe.src );
612 + if ( commentParentValue ) {
613 + url.searchParams.set( 'replytocom', commentParentValue )
614 + } else {
615 + url.searchParams.delete( 'replytocom' );
616 + }
617 + if( iframe.src !== url.href ) {
618 + iframe.src = url.href;
619 + }
620 + };
537 621
538 - cancel.addEventListener( 'click', function () {
539 - tellFrameNewParent( false );
540 - } );
622 + cancel.addEventListener( 'click', function () {
623 + tellFrameNewParent( false );
624 + } );
541 625
542 - addComment.moveForm = function ( _, parentId ) {
543 - tellFrameNewParent( parentId );
544 - return addComment._Jetpack_moveForm.apply( null, arguments );
545 - };
626 + addComment.moveForm = function ( _, parentId ) {
627 + tellFrameNewParent( parentId );
628 + return addComment._Jetpack_moveForm.apply( null, arguments );
629 + };
630 + }
546 631 }
547 - }
548 - document.addEventListener( 'DOMContentLoaded', watchReply );
549 - // In WP 6.4+, the script is loaded asynchronously, so we need to wait for it to load before we monkey-patch the functions it introduces.
550 - document.querySelector('#comment-reply-js')?.addEventListener( 'load', watchReply );
632 + document.addEventListener( 'DOMContentLoaded', watchReply );
633 + // In WP 6.4+, the script is loaded asynchronously, so we need to wait for it to load before we monkey-patch the functions it introduces.
634 + document.querySelector('#comment-reply-js')?.addEventListener( 'load', watchReply );
551 635
552 - <?php endif; ?>
636 + <?php endif; ?>
637 +
638 + const commentIframes = document.getElementsByClassName('jetpack_remote_comment');
553 639
554 - window.addEventListener( 'message', function ( event ) {
555 - if ( event.origin !== 'https://jetpack.wordpress.com' ) {
556 - return;
557 - }
558 - iframe.style.height = event.data + 'px';
559 - });
640 + window.addEventListener('message', function(event) {
641 + if (event.origin !== 'https://jetpack.wordpress.com') {
642 + return;
643 + }
644 +
645 + if (!event?.data?.iframeUniqueId && !event?.data?.height) {
646 + return;
647 + }
648 +
649 + const eventDataUniqueId = event.data.iframeUniqueId;
650 +
651 + // Change height for the matching comment iframe
652 + for (let i = 0; i < commentIframes.length; i++) {
653 + const iframe = commentIframes[i];
654 + const url = new URL(iframe.src);
655 + const iframeUniqueIdParam = url.searchParams.get('iframe_unique_id');
656 + if (iframeUniqueIdParam == event.data.iframeUniqueId) {
657 + iframe.style.height = event.data.height + 'px';
658 + return;
659 + }
660 + }
661 + });
662 + })();
560 663 </script>
561 664 <?php
562 665 }
563 666
@@ -572,19 +675,21 @@
572 675 public function pre_comment_on_post() {
573 676 $post_array = stripslashes_deep( $_POST );
574 677
575 678 // Bail if missing the Jetpack token.
576 - if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) ) {
679 + if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) || ! is_string( $post_array['sig'] ) || ! is_string( $post_array['token_key'] ) ) {
577 680 unset( $_POST['hc_post_as'] );
578 -
579 681 return;
580 682 }
581 683
582 684 if ( empty( $post_array['jetpack_comments_nonce'] ) || ! wp_verify_nonce( $post_array['jetpack_comments_nonce'], "jetpack_comments_nonce-{$post_array['comment_post_ID']}" ) ) {
583 - wp_die( esc_html__( 'Nonce verification failed.', 'jetpack' ), 400 );
685 + if ( ! isset( $_GET['only_once'] ) ) {
686 + self::retry_submit_comment_form_locally();
687 + }
688 + wp_die( esc_html__( 'Nonce verification failed.', 'jetpack' ), 400 );
584 689 }
585 690
586 - if ( str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
691 + if ( isset( $post_array['hc_avatar'] ) && is_string( $post_array['hc_avatar'] ) && str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
587 692 $post_array['hc_avatar'] = htmlentities( $post_array['hc_avatar'], ENT_COMPAT );
588 693 }
589 694
590 695 $blog_token = ( new Tokens() )->get_access_token( false, $post_array['token_key'] );
@@ -609,8 +714,67 @@
609 714 wp_die( esc_html__( 'Comments are not allowed.', 'jetpack' ), 403 );
610 715 }
611 716 }
612 717
718 + /**
719 + * Handle Jetpack Comments POST requests: process the comment form, then client-side POST the results to the self-hosted blog
720 + *
721 + * This function exists because when we submit the form via the jetpack.wordpress.com iframe
722 + * in Chrome the request comes in to Jetpack but for some reason the request doesn't have access to cookies yet.
723 + * By submitting the form again locally with the same data the process works as expected.
724 + *
725 + * @return never
726 + */
727 + public function retry_submit_comment_form_locally() {
728 + // We are not doing any validation here since all the validation will be done again by pre_comment_on_post().
729 + // phpcs:ignore WordPress.Security.NonceVerification.Missing
730 + $comment_data = stripslashes_deep( $_POST );
731 + ?>
732 + <!DOCTYPE html>
733 + <html>
734 + <head>
735 + <meta charset="utf-8">
736 + <title><?php echo esc_html__( 'Submitting Comment', 'jetpack' ); ?></title>
737 + <style type="text/css">
738 + body {
739 + display: table;
740 + width: 100%;
741 + height: 60%;
742 + position: absolute;
743 + top: 0;
744 + left: 0;
745 + overflow: hidden;
746 + color: #333;
747 + }
748 + .jetpack-comment-spinner {
749 + display: table-cell;
750 + vertical-align: middle;
751 + text-align: center;
752 + }
753 + </style>
754 + </head>
755 + <body>
756 + <div class="jetpack-comment-spinner">
757 + <?php
758 + require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-spinner.php';
759 + echo Jetpack_Spinner::render( 28 ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- static SVG markup.
760 + ?>
761 + </div>
762 + <form id="jetpack-remote-comment-post-form" action="<?php echo esc_url( get_site_url() ); ?>/wp-comments-post.php?for=jetpack&only_once=true" method="POST">
763 + <?php foreach ( $comment_data as $key => $val ) : ?>
764 + <input type="hidden" name="<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $val ); ?>" />
765 + <?php endforeach; ?>
766 + </form>
767 +
768 + <script type="text/javascript">
769 + document.getElementById("jetpack-remote-comment-post-form").submit();
770 + </script>
771 + </body>
772 + </html>
773 + <?php
774 + exit( 0 );
775 + }
776 +
613 777 /** Capabilities **********************************************************/
614 778
615 779 /**
616 780 * Add some additional comment meta after comment is saved about what
@@ -620,16 +784,36 @@
620 784 *
621 785 * @param int $comment_id The comment ID.
622 786 */
623 787 public function add_comment_meta( $comment_id ) {
788 + // phpcs:disable WordPress.Security.NonceVerification.Missing -- The hc_* fields are authenticated by the HMAC check below.
789 + $post_array = stripslashes_deep( $_POST );
790 +
791 + // The hc_* identity fields are only trustworthy on a signed request. pre_comment_on_post() checks
792 + // that, but only on wp-comments-post.php, so re-check here for any other producer that reaches
793 + // comment_post (e.g. Carousel's unauthenticated post_attachment_comment endpoint).
794 + if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) || ! is_string( $post_array['sig'] ) || ! is_string( $post_array['token_key'] ) ) {
795 + return;
796 + }
797 + if ( isset( $post_array['hc_avatar'] ) && is_string( $post_array['hc_avatar'] ) && str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
798 + $post_array['hc_avatar'] = htmlentities( $post_array['hc_avatar'], ENT_COMPAT );
799 + }
800 + $blog_token = ( new Tokens() )->get_access_token( false, $post_array['token_key'] );
801 + if ( ! $blog_token || is_wp_error( $blog_token ) ) {
802 + return;
803 + }
804 + $check = self::sign_remote_comment_parameters( $post_array, $blog_token->secret );
805 + if ( is_wp_error( $check ) || ! hash_equals( $check, $post_array['sig'] ) ) {
806 + return;
807 + }
808 +
624 809 $comment_meta = array();
625 810
626 - // phpcs:disable WordPress.Security.NonceVerification.Missing
627 811 switch ( $this->is_highlander_comment_post() ) {
628 812 case 'facebook':
629 813 $comment_meta['hc_post_as'] = 'facebook';
630 - $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? filter_var( wp_unslash( $_POST['hc_avatar'] ) ) : null;
631 - $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? filter_var( wp_unslash( $_POST['hc_userid'] ) ) : null;
814 + $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
815 + $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
632 816 break;
633 817
634 818 // phpcs:ignore WordPress.WP.CapitalPDangit
635 819 case 'wordpress':
@@ -634,17 +818,17 @@
634 818 // phpcs:ignore WordPress.WP.CapitalPDangit
635 819 case 'wordpress':
636 820 // phpcs:ignore WordPress.WP.CapitalPDangit
637 821 $comment_meta['hc_post_as'] = 'wordpress';
638 - $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? filter_var( wp_unslash( $_POST['hc_avatar'] ) ) : null;
639 - $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? filter_var( wp_unslash( $_POST['hc_userid'] ) ) : null;
640 - $comment_meta['hc_wpcom_id_sig'] = isset( $_POST['hc_wpcom_id_sig'] ) ? filter_var( wp_unslash( $_POST['hc_wpcom_id_sig'] ) ) : null; // since 1.9.
822 + $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
823 + $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
824 + $comment_meta['hc_wpcom_id_sig'] = isset( $_POST['hc_wpcom_id_sig'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_wpcom_id_sig'] ) ) : null; // since 1.9.
641 825 break;
642 826
643 827 case 'jetpack':
644 828 $comment_meta['hc_post_as'] = 'jetpack';
645 - $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? filter_var( wp_unslash( $_POST['hc_avatar'] ) ) : null;
646 - $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? filter_var( wp_unslash( $_POST['hc_userid'] ) ) : null;
829 + $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
830 + $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
647 831 break;
648 832
649 833 }
650 834 // phpcs:enable WordPress.Security.NonceVerification.Missing
@@ -672,9 +856,9 @@
672 856 return false;
673 857 }
674 858
675 859 // phpcs:disable WordPress.Security.NonceVerification.Missing
676 - $is_current_user_subscribed = (bool) isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
860 + $is_current_user_subscribed = isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
677 861
678 862 // Atomic sites with jetpack_verbum_subscription_modal option enabled
679 863 $modal_enabled = ( new Host() )->is_woa_site() && get_option( 'jetpack_verbum_subscription_modal', true );
680 864
@@ -713,9 +897,9 @@
713 897 $tracking_event = 'hidden_self_hosted';
714 898 }
715 899
716 900 // phpcs:disable WordPress.Security.NonceVerification.Missing
717 - $is_current_user_subscribed = (bool) isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
901 + $is_current_user_subscribed = isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
718 902
719 903 if ( $is_current_user_subscribed ) {
720 904 $tracking_event = 'hidden_already_subscribed';
721 905 }
@@ -726,8 +910,97 @@
726 910 $jetpack->do_stats( 'server_side' );
727 911 }
728 912
729 913 /**
914 + * Catch the duplicated comment error and show a custom error page
915 + *
916 + * @return never
917 + */
918 + public function capture_comment_duplicate_trigger() {
919 + if ( ! isset( $_GET['for'] ) || 'jetpack' !== $_GET['for'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
920 + exit( 0 );
921 + }
922 +
923 + ?>
924 + <!DOCTYPE html>
925 + <html <?php language_attributes(); ?>>
926 + <!--<![endif]-->
927 + <head>
928 + <meta charset="<?php bloginfo( 'charset' ); ?>" />
929 + <title>
930 + <?php
931 + wp_kses_post(
932 + printf(
933 + /* translators: %s is replaced by an ellipsis */
934 + __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
935 + '&hellip;'
936 + )
937 + );
938 + ?>
939 + </title>
940 + <style type="text/css">
941 + body {
942 + display: table;
943 + width: 100%;
944 + height: 60%;
945 + position: absolute;
946 + top: 0;
947 + left: 0;
948 + overflow: hidden;
949 + color: #333;
950 + padding-top: 3%;
951 + }
952 + div {
953 + text-align: left;
954 + margin: 0;
955 + padding: 0;
956 + display: table-cell;
957 + vertical-align: top;
958 + font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
959 + font-weight: normal;
960 + }
961 +
962 + h3 {
963 + margin: 0;
964 + padding-bottom: 3%;
965 + font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
966 + font-weight: normal;
967 + }
968 + a {
969 + text-decoration: underline;
970 + color: #333 !important;
971 + }
972 + </style>
973 + </head>
974 + <body>
975 + <div>
976 + <h3>
977 + <?php
978 + esc_html_e( 'Duplicate comment detected; it looks as though you’ve already said that!', 'jetpack' );
979 + ?>
980 + </h3>
981 + <a href="javascript:backToComments()"><?php esc_html_e( '&laquo; Back', 'jetpack' ); ?></a>
982 + </div>
983 + <script type="text/javascript">
984 + function backToComments() {
985 + const test = regexp => {
986 + return regexp.test(navigator.userAgent);
987 + };
988 + if (test(/chrome|chromium|crios|safari|edg/i)) {
989 + history.go(-2);
990 + return;
991 + }
992 + history.back();
993 + }
994 + </script>
995 +
996 + </body>
997 + </html>
998 + <?php
999 + exit( 0 );
1000 + }
1001 +
1002 + /**
730 1003 * POST the submitted comment to the iframe
731 1004 *
732 1005 * @param string $url The comment URL origin.
733 1006 */
@@ -768,16 +1041,17 @@
768 1041 top: 0;
769 1042 left: 0;
770 1043 overflow: hidden;
771 1044 color: #333;
1045 + padding-top: 3%;
772 1046 }
773 1047
774 - h1 {
1048 + h3 {
775 1049 text-align: center;
776 1050 margin: 0;
777 1051 padding: 0;
778 1052 display: table-cell;
779 - vertical-align: middle;
1053 + vertical-align: top;
780 1054 font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
781 1055 font-weight: normal;
782 1056 }
783 1057
@@ -784,9 +1058,9 @@
784 1058 .hidden {
785 1059 opacity: 0;
786 1060 }
787 1061
788 - h1 span {
1062 + h3 span {
789 1063 -moz-transition-property: opacity;
790 1064 -moz-transition-duration: 1s;
791 1065 -moz-transition-timing-function: ease-in-out;
792 1066
@@ -809,9 +1083,9 @@
809 1083 </style>
810 1084 </head>
811 1085 <body>
812 1086 <?php if ( ! $should_show_subscription_modal ) { ?>
813 - <h1>
1087 + <h3>
814 1088 <?php
815 1089 wp_kses_post(
816 1090 printf(
817 1091 /* translators: %s is replaced by HTML markup to include an ellipsis */
@@ -819,16 +1093,16 @@
819 1093 '<span id="ellipsis" class="hidden">&hellip;</span>'
820 1094 )
821 1095 );
822 1096 ?>
823 - </h1>
1097 + </h3>
824 1098 <script type="text/javascript">
825 1099 try {
826 - window.parent.location = <?php echo wp_json_encode( $url ); ?>;
827 - window.parent.location.reload(true);
1100 + window.parent.location.href = <?php echo wp_json_encode( $url, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>;
1101 + window.parent.location.reload( true );
828 1102 } catch (e) {
829 - window.location = <?php echo wp_json_encode( $url ); ?>;
830 - window.location.reload(true);
1103 + window.location.href = <?php echo wp_json_encode( $url, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>;
1104 + window.location.reload( true );
831 1105 }
832 1106 ellipsis = document.getElementById('ellipsis');
833 1107
834 1108 function toggleEllipsis() {
@@ -837,15 +1111,15 @@
837 1111
838 1112 setInterval(toggleEllipsis, 1200);
839 1113 </script>
840 1114 <?php } else { ?>
841 - <h1>
1115 + <h3>
842 1116 <?php
843 1117 wp_kses_post(
844 1118 print __( 'Comment sent', 'jetpack' ) // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
845 1119 );
846 1120 ?>
847 - </h1>
1121 + </h3>
848 1122 <script type="text/javascript">
849 1123 if ( window.parent && window.parent !== window ) {
850 1124
851 1125 window.parent.postMessage(
@@ -850,9 +1124,9 @@
850 1124
851 1125 window.parent.postMessage(
852 1126 {
853 1127 type: 'subscriptionModalShow',
854 - data: <?php echo wp_json_encode( $this->get_subscription_modal_data_to_parent( $url ) ); ?>,
1128 + data: <?php echo wp_json_encode( $this->get_subscription_modal_data_to_parent( $url ), JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>,
855 1129 },
856 1130 window.location.origin
857 1131 );
858 1132 }
@@ -860,9 +1134,9 @@
860 1134 <?php } ?>
861 1135 </body>
862 1136 </html>
863 1137 <?php
864 - exit;
1138 + exit( 0 );
865 1139 }
866 1140 }
867 1141
868 1142 Jetpack_Comments::init();