PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | modules/sso.php +13 -1216 13.2.4 → 16.3-a.7 View file →
@@ -1,24 +1,8 @@
1 -<?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
1 +<?php
2 2 /**
3 - * Jetpack_SSO module main class file.
4 - *
5 - * @package automattic/jetpack
6 - */
7 -
8 -use Automattic\Jetpack\Connection\Manager as Connection_Manager;
9 -use Automattic\Jetpack\Roles;
10 -use Automattic\Jetpack\Status;
11 -use Automattic\Jetpack\Status\Host;
12 -use Automattic\Jetpack\Tracking;
13 -
14 -require_once JETPACK__PLUGIN_DIR . 'modules/sso/class.jetpack-sso-helpers.php';
15 -require_once JETPACK__PLUGIN_DIR . 'modules/sso/class.jetpack-sso-notices.php';
16 -require_once JETPACK__PLUGIN_DIR . 'modules/sso/class.jetpack-sso-user-admin.php';
17 -
18 -/**
19 3 * Module Name: Secure Sign On
20 - * Module Description: Allow users to log in to this site using WordPress.com accounts
4 + * Module Description: Let users log in with their WordPress.com account for quick, secure access.
21 5 * Sort Order: 30
22 6 * Recommendation Order: 5
23 7 * First Introduced: 2.6
24 8 * Requires Connection: Yes
@@ -26,1209 +10,22 @@
26 10 * Auto Activate: No
27 11 * Module Tags: Developers
28 12 * Feature: Security
29 13 * Additional Search Queries: sso, single sign on, login, log in, 2fa, two-factor
14 + *
15 + * @package automattic/jetpack
30 16 */
31 -class Jetpack_SSO {
32 - /**
33 - * Jetpack_SSO instance.
34 - *
35 - * @var Jetpack_SSO
36 - */
37 - public static $instance = null;
38 17
39 - /**
40 - * Jetpack_SSO constructor.
41 - */
42 - private function __construct() {
18 +use Automattic\Jetpack\Connection\SSO;
43 19
44 - self::$instance = $this;
45 - new Jetpack_SSO_User_Admin();
20 +if ( ! defined( 'ABSPATH' ) ) {
21 + exit( 0 );
22 +}
46 23
47 - add_action( 'admin_init', array( $this, 'maybe_authorize_user_after_sso' ), 1 );
48 - add_action( 'admin_init', array( $this, 'register_settings' ) );
49 - add_action( 'login_init', array( $this, 'login_init' ) );
50 - add_filter( 'jetpack_xmlrpc_methods', array( $this, 'xmlrpc_methods' ) );
51 - add_action( 'init', array( $this, 'maybe_logout_user' ), 5 );
52 - add_action( 'jetpack_modules_loaded', array( $this, 'module_configure_button' ) );
53 - add_action( 'login_form_logout', array( $this, 'store_wpcom_profile_cookies_on_logout' ) );
54 - add_action( 'jetpack_unlinked_user', array( 'Jetpack_SSO_Helpers', 'delete_connection_for_user' ) );
24 +SSO::get_instance();
55 25
56 - add_action( 'jetpack_site_before_disconnected', array( static::class, 'disconnect' ) );
57 - add_action( 'wp_login', array( 'Jetpack_SSO', 'clear_cookies_after_login' ) );
58 -
59 - // Adding this action so that on login_init, the action won't be sanitized out of the $action global.
60 - add_action( 'login_form_jetpack-sso', '__return_true' );
61 -
62 - add_filter( 'wp_login_errors', array( $this, 'sso_reminder_logout_wpcom' ) );
63 -
64 - /**
65 - * Filter to include Force 2FA feature.
66 - *
67 - * By default, `manage_options` users are forced when enable. The capability can be modified
68 - * with the `jetpack_force_2fa_cap` filter.
69 - *
70 - * To enable the feature, add the following code:
71 - * add_filter( 'jetpack_force_2fa', '__return_true' );
72 - *
73 - * @param bool $force_2fa Whether to force 2FA or not.
74 - *
75 - * @todo Provide a UI to enable/disable the feature.
76 - *
77 - * @since 12.7
78 - * @module SSO
79 - * @return bool
80 - */
81 - if ( ! class_exists( 'Jetpack_Force_2FA' ) && apply_filters( 'jetpack_force_2fa', false ) ) {
82 - // Checking for the class to avoid collisions with existing standalone Jetpack Force 2FA plugin and break out if so.
83 - require_once JETPACK__PLUGIN_DIR . 'modules/sso/class-jetpack-force-2fa.php';
84 - new Jetpack_Force_2FA();
85 - }
86 - }
87 -
88 - /**
89 - * Returns the single instance of the Jetpack_SSO object
90 - *
91 - * @since 2.8
92 - * @return Jetpack_SSO
93 - **/
94 - public static function get_instance() {
95 - if ( self::$instance !== null ) {
96 - return self::$instance;
97 - }
98 -
99 - self::$instance = new Jetpack_SSO();
100 - return self::$instance;
101 - }
102 -
103 - /**
104 - * Add configure button and functionality to the module card on the Jetpack screen
105 - **/
106 - public static function module_configure_button() {
26 +add_action(
27 + 'jetpack_modules_loaded',
28 + function () {
107 29 Jetpack::enable_module_configurable( __FILE__ );
108 30 }
109 -
110 - /**
111 - * Safety heads-up added to the logout messages when SSO is enabled.
112 - * Some folks on a shared computer don't know that they need to log out of WordPress.com as well.
113 - *
114 - * @param WP_Error $errors WP_Error object.
115 - */
116 - public function sso_reminder_logout_wpcom( $errors ) {
117 - if ( ( new Host() )->is_wpcom_platform() ) {
118 - return $errors;
119 - }
120 -
121 - if ( ! empty( $errors->errors['loggedout'] ) ) {
122 - $logout_message = wp_kses(
123 - sprintf(
124 - /* translators: %1$s is a link to the WordPress.com account settings page. */
125 - __( 'If you are on a shared computer, remember to also <a href="%1$s">log out of WordPress.com</a>.', 'jetpack' ),
126 - 'https://wordpress.com/me'
127 - ),
128 - array(
129 - 'a' => array(
130 - 'href' => array(),
131 - ),
132 - )
133 - );
134 - $errors->add( 'jetpack-sso-show-logout', $logout_message, 'message' );
135 - }
136 - return $errors;
137 - }
138 -
139 - /**
140 - * If jetpack_force_logout == 1 in current user meta the user will be forced
141 - * to logout and reauthenticate with the site.
142 - **/
143 - public function maybe_logout_user() {
144 - global $current_user;
145 -
146 - if ( 1 === (int) $current_user->jetpack_force_logout ) {
147 - delete_user_meta( $current_user->ID, 'jetpack_force_logout' );
148 - Jetpack_SSO_Helpers::delete_connection_for_user( $current_user->ID );
149 - wp_logout();
150 - wp_safe_redirect( wp_login_url() );
151 - exit;
152 - }
153 - }
154 -
155 - /**
156 - * Adds additional methods the WordPress xmlrpc API for handling SSO specific features
157 - *
158 - * @param array $methods API methods.
159 - * @return array
160 - **/
161 - public function xmlrpc_methods( $methods ) {
162 - $methods['jetpack.userDisconnect'] = array( $this, 'xmlrpc_user_disconnect' );
163 - return $methods;
164 - }
165 -
166 - /**
167 - * Marks a user's profile for disconnect from WordPress.com and forces a logout
168 - * the next time the user visits the site.
169 - *
170 - * @param int $user_id User to disconnect from the site.
171 - **/
172 - public function xmlrpc_user_disconnect( $user_id ) {
173 - $user_query = new WP_User_Query(
174 - array(
175 - 'meta_key' => 'wpcom_user_id',
176 - 'meta_value' => $user_id,
177 - )
178 - );
179 - $user = $user_query->get_results();
180 - $user = $user[0];
181 -
182 - if ( $user instanceof WP_User ) {
183 - $user = wp_set_current_user( $user->ID );
184 - update_user_meta( $user->ID, 'jetpack_force_logout', '1' );
185 - Jetpack_SSO_Helpers::delete_connection_for_user( $user->ID );
186 - return true;
187 - }
188 - return false;
189 - }
190 -
191 - /**
192 - * Enqueues scripts and styles necessary for SSO login.
193 - */
194 - public function login_enqueue_scripts() {
195 - global $action;
196 -
197 - if ( ! Jetpack_SSO_Helpers::display_sso_form_for_action( $action ) ) {
198 - return;
199 - }
200 -
201 - if ( is_rtl() ) {
202 - wp_enqueue_style( 'jetpack-sso-login', plugins_url( 'modules/sso/jetpack-sso-login-rtl.css', JETPACK__PLUGIN_FILE ), array( 'login', 'genericons' ), JETPACK__VERSION );
203 - } else {
204 - wp_enqueue_style( 'jetpack-sso-login', plugins_url( 'modules/sso/jetpack-sso-login.css', JETPACK__PLUGIN_FILE ), array( 'login', 'genericons' ), JETPACK__VERSION );
205 - }
206 -
207 - wp_enqueue_script( 'jetpack-sso-login', plugins_url( 'modules/sso/jetpack-sso-login.js', JETPACK__PLUGIN_FILE ), array( 'jquery' ), JETPACK__VERSION, false );
208 - }
209 -
210 - /**
211 - * Adds Jetpack SSO classes to login body
212 - *
213 - * @param array $classes Array of classes to add to body tag.
214 - * @return array Array of classes to add to body tag.
215 - */
216 - public function login_body_class( $classes ) {
217 - global $action;
218 -
219 - if ( ! Jetpack_SSO_Helpers::display_sso_form_for_action( $action ) ) {
220 - return $classes;
221 - }
222 -
223 - // Always add the jetpack-sso class so that we can add SSO specific styling even when the SSO form isn't being displayed.
224 - $classes[] = 'jetpack-sso';
225 -
226 - if ( ! ( new Status() )->is_staging_site() ) {
227 - /**
228 - * Should we show the SSO login form?
229 - *
230 - * $_GET['jetpack-sso-default-form'] is used to provide a fallback in case JavaScript is not enabled.
231 - *
232 - * The default_to_sso_login() method allows us to dynamically decide whether we show the SSO login form or not.
233 - * The SSO module uses the method to display the default login form if we can not find a user to log in via SSO.
234 - * But, the method could be filtered by a site admin to always show the default login form if that is preferred.
235 - */
236 - if ( empty( $_GET['jetpack-sso-show-default-form'] ) && Jetpack_SSO_Helpers::show_sso_login() ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
237 - $classes[] = 'jetpack-sso-form-display';
238 - }
239 - }
240 -
241 - return $classes;
242 - }
243 -
244 - /**
245 - * Inlined admin styles for SSO.
246 - */
247 - public function print_inline_admin_css() {
248 - ?>
249 - <style>
250 - .jetpack-sso .message {
251 - margin-top: 20px;
252 - }
253 -
254 - .jetpack-sso #login .message:first-child,
255 - .jetpack-sso #login h1 + .message {
256 - margin-top: 0;
257 - }
258 - </style>
259 - <?php
260 - }
261 -
262 - /**
263 - * Adds settings fields to Settings > General > Secure Sign On that allows users to
264 - * turn off the login form on wp-login.php
265 - *
266 - * @since 2.7
267 - **/
268 - public function register_settings() {
269 -
270 - add_settings_section(
271 - 'jetpack_sso_settings',
272 - __( 'Secure Sign On', 'jetpack' ),
273 - '__return_false',
274 - 'jetpack-sso'
275 - );
276 -
277 - /*
278 - * Settings > General > Secure Sign On
279 - * Require two step authentication
280 - */
281 - register_setting(
282 - 'jetpack-sso',
283 - 'jetpack_sso_require_two_step',
284 - array( $this, 'validate_jetpack_sso_require_two_step' )
285 - );
286 -
287 - add_settings_field(
288 - 'jetpack_sso_require_two_step',
289 - '', // Output done in render $callback: __( 'Require Two-Step Authentication' , 'jetpack' ).
290 - array( $this, 'render_require_two_step' ),
291 - 'jetpack-sso',
292 - 'jetpack_sso_settings'
293 - );
294 -
295 - /*
296 - * Settings > General > Secure Sign On
297 - */
298 - register_setting(
299 - 'jetpack-sso',
300 - 'jetpack_sso_match_by_email',
301 - array( $this, 'validate_jetpack_sso_match_by_email' )
302 - );
303 -
304 - add_settings_field(
305 - 'jetpack_sso_match_by_email',
306 - '', // Output done in render $callback: __( 'Match by Email' , 'jetpack' ).
307 - array( $this, 'render_match_by_email' ),
308 - 'jetpack-sso',
309 - 'jetpack_sso_settings'
310 - );
311 - }
312 -
313 - /**
314 - * Builds the display for the checkbox allowing user to require two step
315 - * auth be enabled on WordPress.com accounts before login. Displays in Settings > General
316 - *
317 - * @since 2.7
318 - **/
319 - public function render_require_two_step() {
320 - ?>
321 - <label>
322 - <input
323 - type="checkbox"
324 - name="jetpack_sso_require_two_step"
325 - <?php checked( Jetpack_SSO_Helpers::is_two_step_required() ); ?>
326 - <?php disabled( Jetpack_SSO_Helpers::is_require_two_step_checkbox_disabled() ); ?>
327 - >
328 - <?php esc_html_e( 'Require Two-Step Authentication', 'jetpack' ); ?>
329 - </label>
330 - <?php
331 - }
332 -
333 - /**
334 - * Validate the require two step checkbox in Settings > General.
335 - *
336 - * @param bool $input The jetpack_sso_require_two_step option setting.
337 - *
338 - * @since 2.7
339 - * @return boolean
340 - **/
341 - public function validate_jetpack_sso_require_two_step( $input ) {
342 - return ( ! empty( $input ) ) ? 1 : 0;
343 - }
344 -
345 - /**
346 - * Builds the display for the checkbox allowing the user to allow matching logins by email
347 - * Displays in Settings > General
348 - *
349 - * @since 2.9
350 - **/
351 - public function render_match_by_email() {
352 - ?>
353 - <label>
354 - <input
355 - type="checkbox"
356 - name="jetpack_sso_match_by_email"
357 - <?php checked( Jetpack_SSO_Helpers::match_by_email() ); ?>
358 - <?php disabled( Jetpack_SSO_Helpers::is_match_by_email_checkbox_disabled() ); ?>
359 - >
360 - <?php esc_html_e( 'Match by Email', 'jetpack' ); ?>
361 - </label>
362 - <?php
363 - }
364 -
365 - /**
366 - * Validate the match by email check in Settings > General.
367 - *
368 - * @param bool $input The jetpack_sso_match_by_email option setting.
369 - *
370 - * @since 2.9
371 - * @return boolean
372 - **/
373 - public function validate_jetpack_sso_match_by_email( $input ) {
374 - return ( ! empty( $input ) ) ? 1 : 0;
375 - }
376 -
377 - /**
378 - * Checks to determine if the user wants to login on wp-login
379 - *
380 - * This function mostly exists to cover the exceptions to login
381 - * that may exist as other parameters to $_GET[action] as $_GET[action]
382 - * does not have to exist. By default WordPress assumes login if an action
383 - * is not set, however this may not be true, as in the case of logout
384 - * where $_GET[loggedout] is instead set
385 - *
386 - * @return boolean
387 - **/
388 - private function wants_to_login() {
389 - $wants_to_login = false;
390 -
391 - // Cover default WordPress behavior.
392 - $action = isset( $_REQUEST['action'] ) ? filter_var( wp_unslash( $_REQUEST['action'] ) ) : 'login'; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
393 -
394 - // And now the exceptions.
395 - $action = isset( $_GET['loggedout'] ) ? 'loggedout' : $action; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
396 -
397 - if ( Jetpack_SSO_Helpers::display_sso_form_for_action( $action ) ) {
398 - $wants_to_login = true;
399 - }
400 -
401 - return $wants_to_login;
402 - }
403 -
404 - /**
405 - * Checks to determine if the user has indicated they want to use the wp-admin interface.
406 - */
407 - private function use_wp_admin_interface() {
408 - return 'wp-admin' === get_option( 'wpcom_admin_interface' );
409 - }
410 -
411 - /**
412 - * Initialization for a SSO request.
413 - */
414 - public function login_init() {
415 - global $action;
416 -
417 - $tracking = new Tracking();
418 -
419 - if ( Jetpack_SSO_Helpers::should_hide_login_form() ) {
420 - /**
421 - * Since the default authenticate filters fire at priority 20 for checking username and password,
422 - * let's fire at priority 30. wp_authenticate_spam_check is fired at priority 99, but since we return a
423 - * WP_Error in disable_default_login_form, then we won't trigger spam processing logic.
424 - */
425 - add_filter( 'authenticate', array( 'Jetpack_SSO_Notices', 'disable_default_login_form' ), 30 );
426 -
427 - /**
428 - * Filter the display of the disclaimer message appearing when default WordPress login form is disabled.
429 - *
430 - * @module sso
431 - *
432 - * @since 2.8.0
433 - *
434 - * @param bool true Should the disclaimer be displayed. Default to true.
435 - */
436 - $display_sso_disclaimer = apply_filters( 'jetpack_sso_display_disclaimer', true );
437 - if ( $display_sso_disclaimer ) {
438 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'msg_login_by_jetpack' ) );
439 - }
440 - }
441 -
442 - if ( 'jetpack-sso' === $action ) {
443 - if ( isset( $_GET['result'] ) && isset( $_GET['user_id'] ) && isset( $_GET['sso_nonce'] ) && 'success' === $_GET['result'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
444 - $this->handle_login();
445 - $this->display_sso_login_form();
446 - } elseif ( ( new Status() )->is_staging_site() ) {
447 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'sso_not_allowed_in_staging' ) );
448 - } else {
449 - // Is it wiser to just use wp_redirect than do this runaround to wp_safe_redirect?
450 - add_filter( 'allowed_redirect_hosts', array( 'Jetpack_SSO_Helpers', 'allowed_redirect_hosts' ) );
451 - $reauth = ! empty( $_GET['force_reauth'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
452 - $sso_url = $this->get_sso_url_or_die( $reauth );
453 -
454 - $tracking->record_user_event( 'sso_login_redirect_success' );
455 - wp_safe_redirect( $sso_url );
456 - exit;
457 - }
458 - } elseif ( Jetpack_SSO_Helpers::display_sso_form_for_action( $action ) ) {
459 -
460 - // Save cookies so we can handle redirects after SSO.
461 - static::save_cookies();
462 -
463 - /**
464 - * Check to see if the site admin wants to automagically forward the user
465 - * to the WordPress.com login page AND that the request to wp-login.php
466 - * is not something other than login (Like logout!)
467 - */
468 - if ( ! $this->use_wp_admin_interface() && Jetpack_SSO_Helpers::bypass_login_forward_wpcom() && $this->wants_to_login() ) {
469 - add_filter( 'allowed_redirect_hosts', array( 'Jetpack_SSO_Helpers', 'allowed_redirect_hosts' ) );
470 - $reauth = ! empty( $_GET['force_reauth'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
471 - $sso_url = $this->get_sso_url_or_die( $reauth );
472 - $tracking->record_user_event( 'sso_login_redirect_bypass_success' );
473 - wp_safe_redirect( $sso_url );
474 - exit;
475 - }
476 -
477 - $this->display_sso_login_form();
478 - }
479 - }
480 -
481 - /**
482 - * Ensures that we can get a nonce from WordPress.com via XML-RPC before setting
483 - * up the hooks required to display the SSO form.
484 - */
485 - public function display_sso_login_form() {
486 - add_filter( 'login_body_class', array( $this, 'login_body_class' ) );
487 - add_action( 'login_head', array( $this, 'print_inline_admin_css' ) );
488 -
489 - if ( ( new Status() )->is_staging_site() ) {
490 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'sso_not_allowed_in_staging' ) );
491 - return;
492 - }
493 -
494 - $sso_nonce = self::request_initial_nonce();
495 - if ( is_wp_error( $sso_nonce ) ) {
496 - return;
497 - }
498 -
499 - add_action( 'login_form', array( $this, 'login_form' ) );
500 - add_action( 'login_enqueue_scripts', array( $this, 'login_enqueue_scripts' ) );
501 - }
502 -
503 - /**
504 - * Conditionally save the redirect_to url as a cookie.
505 - *
506 - * @since 4.6.0 Renamed to save_cookies from maybe_save_redirect_cookies
507 - */
508 - public static function save_cookies() {
509 - if ( headers_sent() ) {
510 - return new WP_Error( 'headers_sent', __( 'Cannot deal with cookie redirects, as headers are already sent.', 'jetpack' ) );
511 - }
512 -
513 - setcookie(
514 - 'jetpack_sso_original_request',
515 - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Sniff misses the wrapping esc_url_raw().
516 - esc_url_raw( set_url_scheme( ( isset( $_SERVER['HTTP_HOST'] ) ? wp_unslash( $_SERVER['HTTP_HOST'] ) : '' ) . ( isset( $_SERVER['REQUEST_URI'] ) ? wp_unslash( $_SERVER['REQUEST_URI'] ) : '' ) ) ),
517 - time() + HOUR_IN_SECONDS,
518 - COOKIEPATH,
519 - COOKIE_DOMAIN,
520 - is_ssl(),
521 - true
522 - );
523 -
524 - if ( ! empty( $_GET['redirect_to'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
525 - // If we have something to redirect to.
526 - $url = esc_url_raw( wp_unslash( $_GET['redirect_to'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
527 - setcookie( 'jetpack_sso_redirect_to', $url, time() + HOUR_IN_SECONDS, COOKIEPATH, COOKIE_DOMAIN, is_ssl(), true );
528 - } elseif ( ! empty( $_COOKIE['jetpack_sso_redirect_to'] ) ) {
529 - // Otherwise, if it's already set, purge it.
530 - setcookie( 'jetpack_sso_redirect_to', ' ', time() - YEAR_IN_SECONDS, COOKIEPATH, COOKIE_DOMAIN, is_ssl(), true );
531 - }
532 - }
533 -
534 - /**
535 - * Outputs the Jetpack SSO button and description as well as the toggle link
536 - * for switching between Jetpack SSO and default login.
537 - */
538 - public function login_form() {
539 - $site_name = get_bloginfo( 'name' );
540 - if ( ! $site_name ) {
541 - $site_name = get_bloginfo( 'url' );
542 - }
543 -
544 - $display_name = ! empty( $_COOKIE[ 'jetpack_sso_wpcom_name_' . COOKIEHASH ] )
545 - ? sanitize_text_field( wp_unslash( $_COOKIE[ 'jetpack_sso_wpcom_name_' . COOKIEHASH ] ) )
546 - : false;
547 - $gravatar = ! empty( $_COOKIE[ 'jetpack_sso_wpcom_gravatar_' . COOKIEHASH ] )
548 - ? esc_url_raw( wp_unslash( $_COOKIE[ 'jetpack_sso_wpcom_gravatar_' . COOKIEHASH ] ) )
549 - : false;
550 -
551 - ?>
552 - <div id="jetpack-sso-wrap">
553 - <?php
554 - /**
555 - * Allow extension above Jetpack's SSO form.
556 - *
557 - * @module sso
558 - *
559 - * @since 8.6.0
560 - */
561 - do_action( 'jetpack_sso_login_form_above_wpcom' );
562 -
563 - if ( $display_name && $gravatar ) :
564 - ?>
565 - <div id="jetpack-sso-wrap__user">
566 - <img width="72" height="72" src="<?php echo esc_html( $gravatar ); ?>" />
567 -
568 - <h2>
569 - <?php
570 - echo wp_kses(
571 - /* translators: %s a user display name. */
572 - sprintf( __( 'Log in as <span>%s</span>', 'jetpack' ), esc_html( $display_name ) ),
573 - array( 'span' => true )
574 - );
575 - ?>
576 - </h2>
577 - </div>
578 -
579 - <?php endif; ?>
580 -
581 -
582 - <div id="jetpack-sso-wrap__action">
583 - <?php echo $this->build_sso_button( array(), 'is_primary' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Escaping done in build_sso_button() ?>
584 -
585 - <?php if ( $display_name && $gravatar ) : ?>
586 - <a rel="nofollow" class="jetpack-sso-wrap__reauth" href="<?php echo esc_url( $this->build_sso_button_url( array( 'force_reauth' => '1' ) ) ); ?>">
587 - <?php esc_html_e( 'Log in as a different WordPress.com user', 'jetpack' ); ?>
588 - </a>
589 - <?php else : ?>
590 - <p>
591 - <?php
592 - /**
593 - * Filter the messeage displayed below the SSO button.
594 - *
595 - * @module sso
596 - *
597 - * @since 10.3.0
598 - *
599 - * @param string $sso_explanation Message displayed below the SSO button.
600 - */
601 - $sso_explanation = apply_filters(
602 - 'jetpack_sso_login_form_explanation_text',
603 - sprintf(
604 - /* Translators: %s is the name of the site. */
605 - __( 'You can now save time spent logging in by connecting your WordPress.com account to %s.', 'jetpack' ),
606 - esc_html( $site_name )
607 - )
608 - );
609 - echo esc_html( $sso_explanation );
610 - ?>
611 - </p>
612 - <?php endif; ?>
613 - </div>
614 -
615 - <?php
616 - /**
617 - * Allow extension below Jetpack's SSO form.
618 - *
619 - * @module sso
620 - *
621 - * @since 8.6.0
622 - */
623 - do_action( 'jetpack_sso_login_form_below_wpcom' );
624 -
625 - if ( ! Jetpack_SSO_Helpers::should_hide_login_form() ) :
626 - ?>
627 - <div class="jetpack-sso-or">
628 - <span><?php esc_html_e( 'Or', 'jetpack' ); ?></span>
629 - </div>
630 -
631 - <a href="<?php echo esc_url( add_query_arg( 'jetpack-sso-show-default-form', '1' ) ); ?>" class="jetpack-sso-toggle wpcom">
632 - <?php
633 - esc_html_e( 'Log in with username and password', 'jetpack' )
634 - ?>
635 - </a>
636 -
637 - <a href="<?php echo esc_url( add_query_arg( 'jetpack-sso-show-default-form', '0' ) ); ?>" class="jetpack-sso-toggle default">
638 - <?php
639 - esc_html_e( 'Log in with WordPress.com', 'jetpack' )
640 - ?>
641 - </a>
642 - <?php endif; ?>
643 - </div>
644 - <?php
645 - }
646 -
647 - /**
648 - * Clear cookies that are no longer needed once the user has logged in.
649 - *
650 - * @since 4.8.0
651 - */
652 - public static function clear_cookies_after_login() {
653 - Jetpack_SSO_Helpers::clear_wpcom_profile_cookies();
654 - if ( isset( $_COOKIE['jetpack_sso_nonce'] ) ) {
655 - setcookie(
656 - 'jetpack_sso_nonce',
657 - ' ',
658 - time() - YEAR_IN_SECONDS,
659 - COOKIEPATH,
660 - COOKIE_DOMAIN,
661 - is_ssl(),
662 - true
663 - );
664 - }
665 -
666 - if ( isset( $_COOKIE['jetpack_sso_original_request'] ) ) {
667 - setcookie(
668 - 'jetpack_sso_original_request',
669 - ' ',
670 - time() - YEAR_IN_SECONDS,
671 - COOKIEPATH,
672 - COOKIE_DOMAIN,
673 - is_ssl(),
674 - true
675 - );
676 - }
677 -
678 - if ( isset( $_COOKIE['jetpack_sso_redirect_to'] ) ) {
679 - setcookie(
680 - 'jetpack_sso_redirect_to',
681 - ' ',
682 - time() - YEAR_IN_SECONDS,
683 - COOKIEPATH,
684 - COOKIE_DOMAIN,
685 - is_ssl(),
686 - true
687 - );
688 - }
689 - }
690 -
691 - /**
692 - * Clean up after Jetpack gets disconnected.
693 - *
694 - * @since 10.7
695 - */
696 - public static function disconnect() {
697 - if ( Jetpack::connection()->is_user_connected() ) {
698 - Jetpack_SSO_Helpers::delete_connection_for_user( get_current_user_id() );
699 - }
700 - }
701 -
702 - /**
703 - * Retrieves nonce used for SSO form.
704 - */
705 - public static function request_initial_nonce() {
706 - $nonce = ! empty( $_COOKIE['jetpack_sso_nonce'] )
707 - ? sanitize_key( wp_unslash( $_COOKIE['jetpack_sso_nonce'] ) )
708 - : false;
709 -
710 - if ( ! $nonce ) {
711 - $xml = new Jetpack_IXR_Client();
712 - $xml->query( 'jetpack.sso.requestNonce' );
713 -
714 - if ( $xml->isError() ) {
715 - return new WP_Error( $xml->getErrorCode(), $xml->getErrorMessage() );
716 - }
717 -
718 - $nonce = sanitize_key( $xml->getResponse() );
719 -
720 - setcookie(
721 - 'jetpack_sso_nonce',
722 - $nonce,
723 - time() + ( 10 * MINUTE_IN_SECONDS ),
724 - COOKIEPATH,
725 - COOKIE_DOMAIN,
726 - is_ssl(),
727 - true
728 - );
729 - }
730 -
731 - return $nonce;
732 - }
733 -
734 - /**
735 - * The function that actually handles the login!
736 - */
737 - public function handle_login() {
738 - $wpcom_nonce = isset( $_GET['sso_nonce'] ) ? sanitize_key( $_GET['sso_nonce'] ) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
739 - $wpcom_user_id = isset( $_GET['user_id'] ) ? (int) $_GET['user_id'] : 0; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
740 -
741 - $xml = new Jetpack_IXR_Client();
742 - $xml->query( 'jetpack.sso.validateResult', $wpcom_nonce, $wpcom_user_id );
743 -
744 - $user_data = $xml->isError() ? false : $xml->getResponse();
745 - if ( empty( $user_data ) ) {
746 - add_filter( 'jetpack_sso_default_to_sso_login', '__return_false' );
747 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'error_invalid_response_data' ) );
748 - return;
749 - }
750 -
751 - $user_data = (object) $user_data;
752 - $user = null;
753 -
754 - /**
755 - * Fires before Jetpack's SSO modifies the log in form.
756 - *
757 - * @module sso
758 - *
759 - * @since 2.6.0
760 - *
761 - * @param object $user_data WordPress.com User information.
762 - */
763 - do_action( 'jetpack_sso_pre_handle_login', $user_data );
764 -
765 - $tracking = new Tracking();
766 -
767 - if ( Jetpack_SSO_Helpers::is_two_step_required() && 0 === (int) $user_data->two_step_enabled ) {
768 - $this->user_data = $user_data;
769 -
770 - $tracking->record_user_event(
771 - 'sso_login_failed',
772 - array(
773 - 'error_message' => 'error_msg_enable_two_step',
774 - )
775 - );
776 -
777 - $error = new WP_Error( 'two_step_required', __( 'You must have Two-Step Authentication enabled on your WordPress.com account.', 'jetpack' ) );
778 -
779 - /** This filter is documented in core/src/wp-includes/pluggable.php */
780 - do_action( 'wp_login_failed', $user_data->login, $error );
781 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'error_msg_enable_two_step' ) );
782 - return;
783 - }
784 -
785 - $user_found_with = '';
786 - if ( empty( $user ) && isset( $user_data->external_user_id ) ) {
787 - $user_found_with = 'external_user_id';
788 - $user = get_user_by( 'id', (int) $user_data->external_user_id );
789 - if ( $user ) {
790 - $expected_id = get_user_meta( $user->ID, 'wpcom_user_id', true );
791 - if ( $expected_id && $expected_id != $user_data->ID ) { // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison, Universal.Operators.StrictComparisons.LooseNotEqual
792 - $error = new WP_Error( 'expected_wpcom_user', __( 'Something got a little mixed up and an unexpected WordPress.com user logged in.', 'jetpack' ) );
793 -
794 - $tracking->record_user_event(
795 - 'sso_login_failed',
796 - array(
797 - 'error_message' => 'error_unexpected_wpcom_user',
798 - )
799 - );
800 -
801 - /** This filter is documented in core/src/wp-includes/pluggable.php */
802 - do_action( 'wp_login_failed', $user_data->login, $error );
803 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'error_invalid_response_data' ) ); // @todo Need to have a better notice. This is only for the sake of testing the validation.
804 - return;
805 - }
806 - update_user_meta( $user->ID, 'wpcom_user_id', $user_data->ID );
807 - }
808 - }
809 -
810 - // If we don't have one by wpcom_user_id, try by the email?
811 - if ( empty( $user ) && Jetpack_SSO_Helpers::match_by_email() ) {
812 - $user_found_with = 'match_by_email';
813 - $user = get_user_by( 'email', $user_data->email );
814 - if ( $user ) {
815 - update_user_meta( $user->ID, 'wpcom_user_id', $user_data->ID );
816 - }
817 - }
818 -
819 - // If we've still got nothing, create the user.
820 - $new_user_override_role = Jetpack_SSO_Helpers::new_user_override( $user_data );
821 - if ( empty( $user ) && ( get_option( 'users_can_register' ) || $new_user_override_role ) ) {
822 - /**
823 - * If not matching by email we still need to verify the email does not exist
824 - * or this blows up
825 - *
826 - * If match_by_email is true, we know the email doesn't exist, as it would have
827 - * been found in the first pass. If get_user_by( 'email' ) doesn't find the
828 - * user, then we know that email is unused, so it's safe to add.
829 - */
830 - if ( Jetpack_SSO_Helpers::match_by_email() || ! get_user_by( 'email', $user_data->email ) ) {
831 -
832 - if ( $new_user_override_role ) {
833 - $user_data->role = $new_user_override_role;
834 - }
835 -
836 - $user = Jetpack_SSO_Helpers::generate_user( $user_data );
837 - if ( ! $user ) {
838 - $tracking->record_user_event(
839 - 'sso_login_failed',
840 - array(
841 - 'error_message' => 'could_not_create_username',
842 - )
843 - );
844 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'error_unable_to_create_user' ) );
845 - return;
846 - }
847 -
848 - $user_found_with = $new_user_override_role
849 - ? 'user_created_new_user_override'
850 - : 'user_created_users_can_register';
851 - } else {
852 - $tracking->record_user_event(
853 - 'sso_login_failed',
854 - array(
855 - 'error_message' => 'error_msg_email_already_exists',
856 - )
857 - );
858 -
859 - $this->user_data = $user_data;
860 - add_action( 'login_message', array( 'Jetpack_SSO_Notices', 'error_msg_email_already_exists' ) );
861 - return;
862 - }
863 - }
864 -
865 - /**
866 - * Fires after we got login information from WordPress.com.
867 - *
868 - * @module sso
869 - *
870 - * @since 2.6.0
871 - *
872 - * @param WP_User|false|null $user Local User information.
873 - * @param object $user_data WordPress.com User Login information.
874 - */
875 - do_action( 'jetpack_sso_handle_login', $user, $user_data );
876 -
877 - if ( $user ) {
878 - // Cache the user's details, so we can present it back to them on their user screen.
879 - update_user_meta( $user->ID, 'wpcom_user_data', $user_data );
880 -
881 - add_filter( 'auth_cookie_expiration', array( 'Jetpack_SSO_Helpers', 'extend_auth_cookie_expiration_for_sso' ) );
882 - wp_set_auth_cookie( $user->ID, true );
883 - remove_filter( 'auth_cookie_expiration', array( 'Jetpack_SSO_Helpers', 'extend_auth_cookie_expiration_for_sso' ) );
884 -
885 - /** This filter is documented in core/src/wp-includes/user.php */
886 - do_action( 'wp_login', $user->user_login, $user );
887 -
888 - wp_set_current_user( $user->ID );
889 -
890 - $_request_redirect_to = isset( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
891 - $redirect_to = user_can( $user, 'edit_posts' ) ? admin_url() : self::profile_page_url();
892 -
893 - // If we have a saved redirect to request in a cookie.
894 - if ( ! empty( $_COOKIE['jetpack_sso_redirect_to'] ) ) {
895 - // Set that as the requested redirect to.
896 - $redirect_to = esc_url_raw( wp_unslash( $_COOKIE['jetpack_sso_redirect_to'] ) );
897 - $_request_redirect_to = $redirect_to;
898 - }
899 -
900 - $json_api_auth_environment = Jetpack_SSO_Helpers::get_json_api_auth_environment();
901 -
902 - $is_json_api_auth = ! empty( $json_api_auth_environment );
903 - $is_user_connected = ( new Connection_Manager( 'jetpack' ) )->is_user_connected( $user->ID );
904 - $roles = new Roles();
905 - $tracking->record_user_event(
906 - 'sso_user_logged_in',
907 - array(
908 - 'user_found_with' => $user_found_with,
909 - 'user_connected' => (bool) $is_user_connected,
910 - 'user_role' => $roles->translate_current_user_to_role(),
911 - 'is_json_api_auth' => (bool) $is_json_api_auth,
912 - )
913 - );
914 -
915 - if ( $is_json_api_auth ) {
916 - Jetpack::init()->verify_json_api_authorization_request( $json_api_auth_environment );
917 - Jetpack::init()->store_json_api_authorization_token( $user->user_login, $user );
918 -
919 - } elseif ( ! $is_user_connected ) {
920 - wp_safe_redirect(
921 - add_query_arg(
922 - array(
923 - 'redirect_to' => $redirect_to,
924 - 'request_redirect_to' => $_request_redirect_to,
925 - 'calypso_env' => ( new Host() )->get_calypso_env(),
926 - 'jetpack-sso-auth-redirect' => '1',
927 - ),
928 - admin_url()
929 - )
930 - );
931 - exit;
932 - }
933 -
934 - add_filter( 'allowed_redirect_hosts', array( 'Jetpack_SSO_Helpers', 'allowed_redirect_hosts' ) );
935 - wp_safe_redirect(
936 - /** This filter is documented in core/src/wp-login.php */
937 - apply_filters( 'login_redirect', $redirect_to, $_request_redirect_to, $user )
938 - );
939 - exit;
940 - }
941 -
942 - add_filter( 'jetpack_sso_default_to_sso_login', '__return_false' );
943 -
944 - $tracking->record_user_event(
945 - 'sso_login_failed',
946 - array(
947 - 'error_message' => 'cant_find_user',
948 - )
949 - );
950 -
951 - $this->user_data = $user_data;
952 -
953 - $error = new WP_Error( 'account_not_found', __( 'Account not found. If you already have an account, make sure you have connected to WordPress.com.', 'jetpack' ) );
954 -
955 - /** This filter is documented in core/src/wp-includes/pluggable.php */
956 - do_action( 'wp_login_failed', $user_data->login, $error );
957 - add_filter( 'login_message', array( 'Jetpack_SSO_Notices', 'cant_find_user' ) );
958 - }
959 -
960 - /**
961 - * Retrieve the admin profile page URL.
962 - */
963 - public static function profile_page_url() {
964 - return admin_url( 'profile.php' );
965 - }
966 -
967 - /**
968 - * Builds the "Login to WordPress.com" button that is displayed on the login page as well as user profile page.
969 - *
970 - * @param array $args An array of arguments to add to the SSO URL.
971 - * @param boolean $is_primary If the button have the `button-primary` class.
972 - * @return string Returns the HTML markup for the button.
973 - */
974 - public function build_sso_button( $args = array(), $is_primary = false ) {
975 - $url = $this->build_sso_button_url( $args );
976 - $classes = $is_primary
977 - ? 'jetpack-sso button button-primary'
978 - : 'jetpack-sso button';
979 -
980 - return sprintf(
981 - '<a rel="nofollow" href="%1$s" class="%2$s">%3$s %4$s</a>',
982 - esc_url( $url ),
983 - $classes,
984 - '<span class="genericon genericon-wordpress"></span>',
985 - esc_html__( 'Log in with WordPress.com', 'jetpack' )
986 - );
987 - }
988 -
989 - /**
990 - * Builds a URL with `jetpack-sso` action and option args which is used to setup SSO.
991 - *
992 - * @param array $args An array of arguments to add to the SSO URL.
993 - * @return string The URL used for SSO.
994 - */
995 - public function build_sso_button_url( $args = array() ) {
996 - $defaults = array(
997 - 'action' => 'jetpack-sso',
998 - );
999 -
1000 - $args = wp_parse_args( $args, $defaults );
1001 -
1002 - if ( ! empty( $_GET['redirect_to'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1003 - $args['redirect_to'] = rawurlencode( esc_url_raw( wp_unslash( $_GET['redirect_to'] ) ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1004 - }
1005 -
1006 - return add_query_arg( $args, wp_login_url() );
1007 - }
1008 -
1009 - /**
1010 - * Retrieves a WordPress.com SSO URL with appropriate query parameters or dies.
1011 - *
1012 - * @param boolean $reauth If the user be forced to reauthenticate on WordPress.com.
1013 - * @param array $args Optional query parameters.
1014 - * @return string The WordPress.com SSO URL.
1015 - */
1016 - public function get_sso_url_or_die( $reauth = false, $args = array() ) {
1017 - $custom_login_url = Jetpack_SSO_Helpers::get_custom_login_url();
1018 - if ( $custom_login_url ) {
1019 - $args['login_url'] = rawurlencode( $custom_login_url );
1020 - }
1021 -
1022 - if ( empty( $reauth ) ) {
1023 - $sso_redirect = $this->build_sso_url( $args );
1024 - } else {
1025 - Jetpack_SSO_Helpers::clear_wpcom_profile_cookies();
1026 - $sso_redirect = $this->build_reauth_and_sso_url( $args );
1027 - }
1028 -
1029 - // If there was an error retrieving the SSO URL, then error.
1030 - if ( is_wp_error( $sso_redirect ) ) {
1031 - $error_message = sanitize_text_field(
1032 - sprintf( '%s: %s', $sso_redirect->get_error_code(), $sso_redirect->get_error_message() )
1033 - );
1034 - $tracking = new Tracking();
1035 - $tracking->record_user_event(
1036 - 'sso_login_redirect_failed',
1037 - array(
1038 - 'error_message' => $error_message,
1039 - )
1040 - );
1041 - wp_die( esc_html( $error_message ) );
1042 - }
1043 -
1044 - return $sso_redirect;
1045 - }
1046 -
1047 - /**
1048 - * Build WordPress.com SSO URL with appropriate query parameters.
1049 - *
1050 - * @param array $args Optional query parameters.
1051 - * @return string WordPress.com SSO URL
1052 - */
1053 - public function build_sso_url( $args = array() ) {
1054 - $sso_nonce = ! empty( $args['sso_nonce'] ) ? $args['sso_nonce'] : self::request_initial_nonce();
1055 - $defaults = array(
1056 - 'action' => 'jetpack-sso',
1057 - 'site_id' => Jetpack_Options::get_option( 'id' ),
1058 - 'sso_nonce' => $sso_nonce,
1059 - 'calypso_auth' => '1',
1060 - );
1061 -
1062 - $args = wp_parse_args( $args, $defaults );
1063 -
1064 - if ( is_wp_error( $args['sso_nonce'] ) ) {
1065 - return $args['sso_nonce'];
1066 - }
1067 -
1068 - return add_query_arg( $args, 'https://wordpress.com/wp-login.php' );
1069 - }
1070 -
1071 - /**
1072 - * Build WordPress.com SSO URL with appropriate query parameters,
1073 - * including the parameters necessary to force the user to reauthenticate
1074 - * on WordPress.com.
1075 - *
1076 - * @param array $args Optional query parameters.
1077 - * @return string WordPress.com SSO URL
1078 - */
1079 - public function build_reauth_and_sso_url( $args = array() ) {
1080 - $sso_nonce = ! empty( $args['sso_nonce'] ) ? $args['sso_nonce'] : self::request_initial_nonce();
1081 - $redirect = $this->build_sso_url(
1082 - array(
1083 - 'force_auth' => '1',
1084 - 'sso_nonce' => $sso_nonce,
1085 - )
1086 - );
1087 -
1088 - if ( is_wp_error( $redirect ) ) {
1089 - return $redirect;
1090 - }
1091 -
1092 - $defaults = array(
1093 - 'action' => 'jetpack-sso',
1094 - 'site_id' => Jetpack_Options::get_option( 'id' ),
1095 - 'sso_nonce' => $sso_nonce,
1096 - 'reauth' => '1',
1097 - 'redirect_to' => rawurlencode( $redirect ),
1098 - 'calypso_auth' => '1',
1099 - );
1100 -
1101 - $args = wp_parse_args( $args, $defaults );
1102 -
1103 - if ( is_wp_error( $args['sso_nonce'] ) ) {
1104 - return $args['sso_nonce'];
1105 - }
1106 -
1107 - return add_query_arg( $args, 'https://wordpress.com/wp-login.php' );
1108 - }
1109 -
1110 - /**
1111 - * Determines local user associated with a given WordPress.com user ID.
1112 - *
1113 - * @since 2.6.0
1114 - *
1115 - * @param int $wpcom_user_id User ID from WordPress.com.
1116 - * @return object Local user object if found, null if not.
1117 - */
1118 - public static function get_user_by_wpcom_id( $wpcom_user_id ) {
1119 - $user_query = new WP_User_Query(
1120 - array(
1121 - 'meta_key' => 'wpcom_user_id',
1122 - 'meta_value' => (int) $wpcom_user_id,
1123 - 'number' => 1,
1124 - )
1125 - );
1126 -
1127 - $users = $user_query->get_results();
1128 - return $users ? array_shift( $users ) : null;
1129 - }
1130 -
1131 - /**
1132 - * When jetpack-sso-auth-redirect query parameter is set, will redirect user to
1133 - * WordPress.com authorization flow.
1134 - *
1135 - * We redirect here instead of in handle_login() because Jetpack::init()->build_connect_url
1136 - * calls menu_page_url() which doesn't work properly until admin menus are registered.
1137 - */
1138 - public function maybe_authorize_user_after_sso() {
1139 - if ( empty( $_GET['jetpack-sso-auth-redirect'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1140 - return;
1141 - }
1142 -
1143 - $redirect_to = ! empty( $_GET['redirect_to'] ) ? esc_url_raw( wp_unslash( $_GET['redirect_to'] ) ) : admin_url(); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1144 - $request_redirect_to = ! empty( $_GET['request_redirect_to'] ) ? esc_url_raw( wp_unslash( $_GET['request_redirect_to'] ) ) : $redirect_to; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1145 -
1146 - /** This filter is documented in core/src/wp-login.php */
1147 - $redirect_after_auth = apply_filters( 'login_redirect', $redirect_to, $request_redirect_to, wp_get_current_user() );
1148 -
1149 - /**
1150 - * Since we are passing this redirect to WordPress.com and therefore can not use wp_safe_redirect(),
1151 - * let's sanitize it here to make sure it's safe. If the redirect is not safe, then use admin_url().
1152 - */
1153 - $redirect_after_auth = wp_sanitize_redirect( $redirect_after_auth );
1154 - $redirect_after_auth = wp_validate_redirect( $redirect_after_auth, admin_url() );
1155 -
1156 - /**
1157 - * Return the raw connect URL with our redirect and attribute connection to SSO.
1158 - * We remove any other filters that may be turning on the in-place connection
1159 - * since we will be redirecting the user as opposed to iFraming.
1160 - */
1161 - remove_all_filters( 'jetpack_use_iframe_authorization_flow' );
1162 - add_filter( 'jetpack_use_iframe_authorization_flow', '__return_false' );
1163 - $connect_url = Jetpack::init()->build_connect_url( true, $redirect_after_auth, 'sso' );
1164 -
1165 - add_filter( 'allowed_redirect_hosts', array( 'Jetpack_SSO_Helpers', 'allowed_redirect_hosts' ) );
1166 - wp_safe_redirect( $connect_url );
1167 - exit;
1168 - }
1169 -
1170 - /**
1171 - * Cache user's display name and Gravatar so it can be displayed on the login screen. These cookies are
1172 - * stored when the user logs out, and then deleted when the user logs in.
1173 - */
1174 - public function store_wpcom_profile_cookies_on_logout() {
1175 - if ( ! ( new Connection_Manager( 'jetpack' ) )->is_user_connected( get_current_user_id() ) ) {
1176 - return;
1177 - }
1178 -
1179 - $user_data = $this->get_user_data( get_current_user_id() );
1180 - if ( ! $user_data ) {
1181 - return;
1182 - }
1183 -
1184 - setcookie(
1185 - 'jetpack_sso_wpcom_name_' . COOKIEHASH,
1186 - $user_data->display_name,
1187 - time() + WEEK_IN_SECONDS,
1188 - COOKIEPATH,
1189 - COOKIE_DOMAIN,
1190 - is_ssl(),
1191 - true
1192 - );
1193 -
1194 - setcookie(
1195 - 'jetpack_sso_wpcom_gravatar_' . COOKIEHASH,
1196 - get_avatar_url(
1197 - $user_data->email,
1198 - array(
1199 - 'size' => 144,
1200 - 'default' => 'mystery',
1201 - )
1202 - ),
1203 - time() + WEEK_IN_SECONDS,
1204 - COOKIEPATH,
1205 - COOKIE_DOMAIN,
1206 - is_ssl(),
1207 - true
1208 - );
1209 - }
1210 -
1211 - /**
1212 - * Determines if a local user is connected to WordPress.com
1213 - *
1214 - * @since 2.8
1215 - * @param integer $user_id - Local user id.
1216 - * @return boolean
1217 - **/
1218 - public function is_user_connected( $user_id ) {
1219 - return $this->get_user_data( $user_id );
1220 - }
1221 -
1222 - /**
1223 - * Retrieves a user's WordPress.com data
1224 - *
1225 - * @since 2.8
1226 - * @param integer $user_id - Local user id.
1227 - * @return mixed null or stdClass
1228 - **/
1229 - public function get_user_data( $user_id ) {
1230 - return get_user_meta( $user_id, 'wpcom_user_data', true );
1231 - }
1232 -}
1233 -
1234 -Jetpack_SSO::get_instance();
31 +);