PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | sal/class.json-api-site-base.php +372 -54 13.3.3 → 16.3-a.7 View file →
@@ -14,8 +14,12 @@
14 14 use Automattic\Jetpack\Blaze;
15 15 use Automattic\Jetpack\Status;
16 16 use Automattic\Jetpack\Status\Host;
17 17
18 +if ( ! defined( 'ABSPATH' ) ) {
19 + exit( 0 );
20 +}
21 +
18 22 require_once __DIR__ . '/class.json-api-date.php';
19 23 require_once __DIR__ . '/class.json-api-post-base.php';
20 24
21 25 /**
@@ -60,14 +64,24 @@
60 64 return $this->blog_id;
61 65 }
62 66
63 67 /**
68 + * Returns the site slug.
69 + *
70 + * @return string
71 + */
72 + public function get_slug() {
73 + return ( new Status() )->get_site_suffix();
74 + }
75 +
76 + /**
64 77 * Returns the site name.
65 78 *
66 79 * @return string
67 80 */
68 81 public function get_name() {
69 - return (string) htmlspecialchars_decode( get_bloginfo( 'name' ), ENT_QUOTES );
82 + $name = get_bloginfo( 'name' );
83 + return is_string( $name ) ? htmlspecialchars_decode( $name, ENT_QUOTES ) : '';
70 84 }
71 85
72 86 /**
73 87 * Returns the site description.
@@ -74,9 +88,10 @@
74 88 *
75 89 * @return string
76 90 */
77 91 public function get_description() {
78 - return (string) htmlspecialchars_decode( get_bloginfo( 'description' ), ENT_QUOTES );
92 + $description = get_bloginfo( 'description' );
93 + return is_string( $description ) ? htmlspecialchars_decode( $description, ENT_QUOTES ) : '';
79 94 }
80 95
81 96 /**
82 97 * Returns the URL for the current site.
@@ -409,8 +424,45 @@
409 424 */
410 425 abstract public function get_user_interactions();
411 426
412 427 /**
428 + * Flag a site as deleted. Not used in Jetpack.
429 + *
430 + * @see class.json-api-site-jetpack.php for implementation.
431 + */
432 + abstract public function is_deleted();
433 +
434 + /**
435 + * Indicates that a site is an A4A client. Not used in Jetpack.
436 + *
437 + * @see class.json-api-site-jetpack.php for implementation.
438 + */
439 + abstract public function is_a4a_client();
440 +
441 + /**
442 + * Indicates that a site is an A4A dev site.
443 + *
444 + * @return bool
445 + */
446 + public function is_a4a_dev_site() {
447 + if ( function_exists( 'has_blog_sticker' ) ) {
448 + return has_blog_sticker( 'a4a-is-dev-site' );
449 + }
450 + return false;
451 + }
452 +
453 + /**
454 + * Return the user interactions with a site. Not used in Jetpack.
455 + *
456 + * @param string $role The capability to check.
457 + * @return bool
458 + * @see class.json-api-site-jetpack.php for implementation.
459 + * @see class.json-api-site-wpcom.php (on WPCOM) for Simple-site implementation.
460 + * @see class.json-api-site-jetpack-shadow.php (on WPCOM) for Atomic-site implementation.
461 + */
462 + abstract public function current_user_can( $role );
463 +
464 + /**
413 465 * Defines a filter to set whether a site is an automated_transfer site or not.
414 466 *
415 467 * Default is false.
416 468 *
@@ -438,9 +490,9 @@
438 490 * Defaulting to false and not relevant for Jetpack sites, this is expanded on the WordPress.com side for a specific wp.com/start 'WP for teams' flow.
439 491 *
440 492 * @see class.json-api-site-jetpack.php for implementation.
441 493 */
442 - abstract protected function is_wpforteams_site();
494 + abstract public function is_wpforteams_site();
443 495
444 496 /**
445 497 * Get hub blog id for P2 sites.
446 498 *
@@ -720,26 +772,29 @@
720 772 private function user_can_view_post( $post ) {
721 773 if ( ! $post || is_wp_error( $post ) ) {
722 774 return false;
723 775 }
724 -
725 - if ( 'inherit' === $post->post_status ) {
776 + // If the post is of status inherit, check if the parent exists ( different to 0 ) to check for the parent status object.
777 + if ( 'inherit' === $post->post_status && 0 !== (int) $post->post_parent ) {
726 778 $parent_post = get_post( $post->post_parent );
727 - $post_status_obj = get_post_status_object( $parent_post->post_status );
779 + $post_status_obj = $parent_post ? get_post_status_object( $parent_post->post_status ) : null;
728 780 } else {
729 781 $post_status_obj = get_post_status_object( $post->post_status );
730 782 }
731 783
732 - $authorized = (
733 - $post_status_obj->public ||
734 - ( is_user_logged_in() &&
735 - (
736 - ( $post_status_obj->protected && current_user_can( 'edit_post', $post->ID ) ) ||
737 - ( $post_status_obj->private && current_user_can( 'read_post', $post->ID ) ) ||
738 - ( 'trash' === $post->post_status && current_user_can( 'edit_post', $post->ID ) ) ||
739 - 'auto-draft' === $post->post_status
740 - )
741 - )
784 + $authorized = false;
785 +
786 + if ( $post_status_obj ) {
787 + $authorized = $post_status_obj->public
788 + || ( is_user_logged_in() && (
789 + ( $post_status_obj->protected && current_user_can( 'edit_post', $post->ID ) )
790 + || ( $post_status_obj->private && current_user_can( 'read_post', $post->ID ) )
791 + ) );
792 + }
793 +
794 + $authorized = $authorized || (
795 + ( 'trash' === $post->post_status && current_user_can( 'edit_post', $post->ID ) )
796 + || 'auto-draft' === $post->post_status
742 797 );
743 798
744 799 if ( ! $authorized ) {
745 800 return new WP_Error( 'unauthorized', 'User cannot view post', 403 );
@@ -902,39 +957,32 @@
902 957 public function get_capabilities() {
903 958 $is_wpcom_blog_owner = wpcom_get_blog_owner() === (int) get_current_user_id();
904 959
905 960 return array(
906 - 'edit_pages' => current_user_can( 'edit_pages' ),
907 - 'edit_posts' => current_user_can( 'edit_posts' ),
908 - 'edit_others_posts' => current_user_can( 'edit_others_posts' ),
909 - 'edit_others_pages' => current_user_can( 'edit_others_pages' ),
910 - 'delete_posts' => current_user_can( 'delete_posts' ),
911 - 'delete_others_posts' => current_user_can( 'delete_others_posts' ),
912 - 'edit_theme_options' => current_user_can( 'edit_theme_options' ),
913 - 'edit_users' => current_user_can( 'edit_users' ),
914 - 'list_users' => current_user_can( 'list_users' ),
915 - 'manage_categories' => current_user_can( 'manage_categories' ),
916 - 'manage_options' => current_user_can( 'manage_options' ),
917 - 'moderate_comments' => current_user_can( 'moderate_comments' ),
961 + 'edit_pages' => $this->current_user_can( 'edit_pages' ),
962 + 'edit_posts' => $this->current_user_can( 'edit_posts' ),
963 + 'edit_others_posts' => $this->current_user_can( 'edit_others_posts' ),
964 + 'edit_others_pages' => $this->current_user_can( 'edit_others_pages' ),
965 + 'delete_posts' => $this->current_user_can( 'delete_posts' ),
966 + 'delete_others_posts' => $this->current_user_can( 'delete_others_posts' ),
967 + 'edit_theme_options' => $this->current_user_can( 'edit_theme_options' ),
968 + 'edit_users' => $this->current_user_can( 'edit_users' ),
969 + 'list_users' => $this->current_user_can( 'list_users' ),
970 + 'manage_categories' => $this->current_user_can( 'manage_categories' ),
971 + 'manage_options' => $this->current_user_can( 'manage_options' ),
972 + 'moderate_comments' => $this->current_user_can( 'moderate_comments' ),
918 973 'activate_wordads' => $is_wpcom_blog_owner,
919 - 'promote_users' => current_user_can( 'promote_users' ),
920 - 'publish_posts' => current_user_can( 'publish_posts' ),
921 - 'upload_files' => current_user_can( 'upload_files' ),
922 - 'delete_users' => current_user_can( 'delete_users' ),
923 - 'remove_users' => current_user_can( 'remove_users' ),
974 + 'promote_users' => $this->current_user_can( 'promote_users' ),
975 + 'publish_posts' => $this->current_user_can( 'publish_posts' ),
976 + 'upload_files' => $this->current_user_can( 'upload_files' ),
977 + 'delete_users' => $this->current_user_can( 'delete_users' ),
978 + 'remove_users' => $this->current_user_can( 'remove_users' ),
924 979 'own_site' => $is_wpcom_blog_owner,
925 - /**
926 - * Filter whether the Hosting section in Calypso should be available for site.
927 - *
928 - * @module json-api
929 - *
930 - * @since 8.2.0
931 - *
932 - * @param bool $view_hosting Can site access Hosting section. Default to false.
933 - */
934 - 'view_hosting' => apply_filters( 'jetpack_json_api_site_can_view_hosting', false ),
935 980 'view_stats' => stats_is_blog_user( $this->blog_id ),
936 - 'activate_plugins' => current_user_can( 'activate_plugins' ),
981 + 'activate_plugins' => $this->current_user_can( 'activate_plugins' ),
982 + 'update_plugins' => $this->current_user_can( 'update_plugins' ),
983 + 'export' => $this->current_user_can( 'export' ),
984 + 'import' => $this->current_user_can( 'import' ),
937 985 );
938 986 }
939 987
940 988 /**
@@ -966,9 +1014,9 @@
966 1014 **/
967 1015 public function get_logo() {
968 1016 // Set an empty response array.
969 1017 $logo_setting = array(
970 - 'id' => (int) 0,
1018 + 'id' => 0,
971 1019 'sizes' => array(),
972 1020 'url' => '',
973 1021 );
974 1022
@@ -1029,8 +1077,31 @@
1029 1077 return get_option( 'stylesheet' );
1030 1078 }
1031 1079
1032 1080 /**
1081 + * Returns a list of errors for broken themes on the site.
1082 + *
1083 + * @return array
1084 + */
1085 + public function get_theme_errors() {
1086 + $themes_with_errors = wp_get_themes( array( 'errors' => true ) );
1087 + $theme_errors = array();
1088 +
1089 + foreach ( $themes_with_errors as $theme ) {
1090 + $errors = $theme->errors();
1091 +
1092 + if ( is_wp_error( $errors ) && ! empty( $errors->get_error_messages() ) ) {
1093 + $theme_errors[] = array(
1094 + 'name' => sanitize_title( $theme->get( 'Name' ) ),
1095 + 'errors' => (array) $errors->get_error_messages(),
1096 + );
1097 + }
1098 + }
1099 +
1100 + return $theme_errors;
1101 + }
1102 +
1103 + /**
1033 1104 * Gets the header image data.
1034 1105 *
1035 1106 * @return bool|object
1036 1107 **/
@@ -1184,9 +1255,9 @@
1184 1255 $ss = new Sharing_Service();
1185 1256 $blog_services = $ss->get_blog_services();
1186 1257 $default_sharing_status = ! empty( $blog_services['visible'] );
1187 1258 }
1188 - return (bool) $default_sharing_status;
1259 + return $default_sharing_status;
1189 1260 }
1190 1261
1191 1262 /**
1192 1263 * Displays the current comment status
@@ -1328,17 +1399,21 @@
1328 1399 return empty( $options['designType'] ) ? null : $options['designType'];
1329 1400 }
1330 1401
1331 1402 /**
1332 - * Returns the 'siteGoals' option if set (eg. share, promote, educate, sell, showcase), null otherwise.
1403 + * Returns the 'site_goals' option if set (eg. share, promote, educate, sell, showcase).
1333 1404 *
1334 - * @return string|null
1405 + * @return array
1335 1406 **/
1336 1407 public function get_site_goals() {
1337 - $options = get_option( 'options' );
1338 - return empty( $options['siteGoals'] ) ? null : $options['siteGoals'];
1408 + $site_goals_option = get_option( 'site_goals' );
1409 +
1410 + if ( is_array( $site_goals_option ) ) {
1411 + return $site_goals_option;
1412 + }
1413 +
1414 + return array();
1339 1415 }
1340 -
1341 1416 /**
1342 1417 * Return site's launch status. Expanded in class.json-api-site-jetpack.php.
1343 1418 *
1344 1419 * @return bool False in this case.
@@ -1444,17 +1519,81 @@
1444 1519 return false;
1445 1520 }
1446 1521
1447 1522 /**
1448 - * The site options for DIFM lite in the design picker step
1523 + * Get the DIFM Lite site options exposed to the frontend while a build is in progress.
1449 1524 *
1450 - * @return string
1525 + * Returns null unless the site has an active DIFM Lite build and the code is
1526 + * running on WordPress.com, where the DIFM Lite library exists.
1527 + *
1528 + * @return array|null
1451 1529 */
1452 1530 public function get_difm_lite_site_options() {
1453 - return get_option( 'difm_lite_site_options' );
1531 + if ( ! $this->is_difm_lite_in_progress() ) {
1532 + return null;
1533 + }
1534 + if ( ! defined( 'IS_WPCOM' ) || ! IS_WPCOM || ! function_exists( 'require_lib' ) ) {
1535 + return null;
1536 + }
1537 + require_lib( 'difm-lite' );
1538 + if ( ! class_exists( '\DIFM_Lite_Options' ) ) {
1539 + // Fail closed if the library did not define the class; this method
1540 + // documents null for every path where the options are unavailable.
1541 + return null;
1542 + }
1543 + // The submission state is canonical on the purchase blog. This site may be
1544 + // the stickered staging build target, whose own options blob is empty, so
1545 + // resolve to the purchase blog before reading — otherwise a post-submit
1546 + // staging target reports itself as pre-submit.
1547 + //
1548 + // resolve_purchase_site_id() ships in the wpcom DIFM Lite site-role
1549 + // pointers change. This Jetpack code can deploy before that lands, so
1550 + // fall back to the current blog when it is unavailable — no retargeted
1551 + // builds can exist until that change is live, so the current blog is the
1552 + // purchase blog in that window.
1553 + $purchase_blog_id = $this->blog_id;
1554 + // @phan-suppress-next-line PhanUndeclaredClassReference -- wpcom-only class, guarded above.
1555 + if ( method_exists( '\DIFM_Lite_Options', 'resolve_purchase_site_id' ) ) {
1556 + // @phan-suppress-next-line PhanUndeclaredClassMethod -- wpcom-only class, guarded above.
1557 + $purchase_blog_id = \DIFM_Lite_Options::resolve_purchase_site_id( $this->blog_id );
1558 + }
1559 + // @phan-suppress-next-line PhanUndeclaredClassMethod -- wpcom-only class, guarded above.
1560 + $difm_lite_options = new \DIFM_Lite_Options( $purchase_blog_id );
1561 + return array(
1562 + // @phan-suppress-next-line PhanUndeclaredClassProperty -- wpcom-only class, guarded above.
1563 + 'is_website_content_submitted' => (bool) $difm_lite_options->is_website_content_submitted,
1564 + );
1454 1565 }
1455 1566
1456 1567 /**
1568 + * Check if the site has the gating-business-q1 blog sticker.
1569 + *
1570 + * @return bool
1571 + */
1572 + public function is_gating_business_q1() {
1573 + if ( function_exists( 'has_blog_sticker' ) ) {
1574 + return has_blog_sticker( 'gating-business-q1' );
1575 + } elseif ( function_exists( 'wpcomsh_is_site_sticker_active' ) ) {
1576 + // For atomic sites
1577 + return wpcomsh_is_site_sticker_active( 'gating-business-q1' );
1578 + }
1579 + return false;
1580 + }
1581 +
1582 + /**
1583 + * Whether the site is still on the pre-2026 feature gating.
1584 + *
1585 + * @return bool
1586 + */
1587 + public function is_legacy_gating_site() {
1588 + if ( ! method_exists( 'WPCOM_Features', 'is_legacy_gating_site' ) ) {
1589 + return false;
1590 + }
1591 +
1592 + return (bool) WPCOM_Features::is_legacy_gating_site( $this->blog_id );
1593 + }
1594 +
1595 + /**
1457 1596 * Get the option of site intent which value is coming from the Hero Flow
1458 1597 *
1459 1598 * @return string
1460 1599 */
@@ -1462,8 +1601,17 @@
1462 1601 return get_option( 'site_intent', '' );
1463 1602 }
1464 1603
1465 1604 /**
1605 + * Get the option of site partner bundle which value is coming from the Partner Flow
1606 + *
1607 + * @return string
1608 + */
1609 + public function get_site_partner_bundle() {
1610 + return get_option( 'site_partner_bundle', '' );
1611 + }
1612 +
1613 + /**
1466 1614 * Get site option to determine if and how to display launchpad onboarding
1467 1615 *
1468 1616 * @return string
1469 1617 */
@@ -1471,8 +1619,17 @@
1471 1619 return get_option( 'launchpad_screen' );
1472 1620 }
1473 1621
1474 1622 /**
1623 + * Get the option onboarding_segment coming from the Guided Flow
1624 + *
1625 + * @return string
1626 + */
1627 + public function get_onboarding_segment() {
1628 + return get_option( 'onboarding_segment', '' );
1629 + }
1630 +
1631 + /**
1475 1632 * Get site option for completed launchpad checklist tasks
1476 1633 *
1477 1634 * @return string
1478 1635 */
@@ -1486,8 +1643,56 @@
1486 1643 return array();
1487 1644 }
1488 1645
1489 1646 /**
1647 + * Whether the AI Launchpad is enabled for this site, for the requesting user.
1648 + *
1649 + * The launchpad-personalization assignment is user-scoped: every site of an
1650 + * ai_launchpad user gets the AI Launchpad, however the site was created. Mirrors
1651 + * AI_Launchpad::is_enabled_for_site() in jetpack-mu-wpcom, so wp-admin and the
1652 + * Calypso-facing payload agree. Like the capabilities in this payload, the value
1653 + * is relative to the current user.
1654 + *
1655 + * @return bool
1656 + */
1657 + public function is_ai_launchpad_enabled() {
1658 + if ( (bool) get_option( 'wpcom_ai_launchpad_enabled' ) ) {
1659 + return true;
1660 + }
1661 +
1662 + return class_exists( '\Automattic\Jetpack\Jetpack_Mu_Wpcom\Launchpad_Personalization_Experiment' )
1663 + // @phan-suppress-next-line PhanUndeclaredClassMethod -- Lives in jetpack-mu-wpcom, outside this plugin's dependency graph; the class_exists guard above covers contexts where it isn't loaded.
1664 + && 'ai_launchpad' === \Automattic\Jetpack\Jetpack_Mu_Wpcom\Launchpad_Personalization_Experiment::get_variation();
1665 + }
1666 +
1667 + /**
1668 + * Whether the AI Launchpad was dismissed, reverting the site to the regular launchpad.
1669 + *
1670 + * @return bool
1671 + */
1672 + public function is_ai_launchpad_dismissed() {
1673 + return (bool) get_option( 'wpcom_ai_launchpad_dismissed' );
1674 + }
1675 +
1676 + /**
1677 + * Whether every AI Launchpad task has been completed.
1678 + *
1679 + * @return bool
1680 + */
1681 + public function is_ai_launchpad_completed() {
1682 + return (bool) get_option( 'wpcom_ai_launchpad_completed' );
1683 + }
1684 +
1685 + /**
1686 + * Get site option for migration source site domain
1687 + *
1688 + * @return string
1689 + */
1690 + public function get_migration_source_site_domain() {
1691 + return get_option( 'migration_source_site_domain', '' );
1692 + }
1693 +
1694 + /**
1490 1695 * Detect whether a site is WordPress.com Staging Site.
1491 1696 *
1492 1697 * @see class.json-api-site-jetpack.php for implementation.
1493 1698 */
@@ -1584,6 +1789,119 @@
1584 1789 * @return bool
1585 1790 **/
1586 1791 public function get_wpcom_classic_early_release() {
1587 1792 return ! empty( get_option( 'wpcom_classic_early_release' ) );
1793 + }
1794 +
1795 + /**
1796 + * Returns whether APM (Application Performance Monitoring) is enabled for the site.
1797 + *
1798 + * APM is an Atomic-only hosting feature. Non-Atomic site types (Simple wpcom, real
1799 + * Jetpack) return false; Jetpack_Shadow_Site overrides with the actual read.
1800 + *
1801 + * @return bool
1802 + **/
1803 + public function get_apm_enabled() {
1804 + return false;
1805 + }
1806 +
1807 + /**
1808 + * Get Zendesk site meta.
1809 + *
1810 + * @return array|null
1811 + */
1812 + abstract public function get_zendesk_site_meta();
1813 +
1814 + /**
1815 + * Detect whether there's a pending plan for this site.
1816 + *
1817 + * @return bool
1818 + */
1819 + abstract public function is_pending_plan();
1820 +
1821 + /**
1822 + * Detect whether the site is a Garden site.
1823 + *
1824 + * @return bool
1825 + */
1826 + public function is_garden() {
1827 + return false;
1828 + }
1829 +
1830 + /**
1831 + * Get the Garden name.
1832 + *
1833 + * @return string
1834 + */
1835 + public function garden_name() {
1836 + return null;
1837 + }
1838 +
1839 + /**
1840 + * Get the Garden partner.
1841 + *
1842 + * @return string
1843 + */
1844 + public function garden_partner() {
1845 + return null;
1846 + }
1847 +
1848 + /**
1849 + * Detect whether the Garden site is provisioned.
1850 + *
1851 + * @return bool|null
1852 + */
1853 + public function garden_is_provisioned() {
1854 + return null;
1855 + }
1856 +
1857 + /**
1858 + * Detect whether the site is a Flex site.
1859 + *
1860 + * @return bool
1861 + */
1862 + public function is_wpcom_flex() {
1863 + if ( function_exists( 'has_blog_sticker' ) ) {
1864 + return has_blog_sticker( 'flex-cache-site' );
1865 + }
1866 + return false;
1867 + }
1868 +
1869 + /**
1870 + * Detect whether Big Sky AI assistant is enabled for this site.
1871 + *
1872 + * @return bool
1873 + */
1874 + public function is_big_sky_enabled() {
1875 + return false;
1876 + }
1877 +
1878 + /**
1879 + * Get the state of any block on the site's outgoing email.
1880 + *
1881 + * @return array|null `status` (`blocked` or `at_risk`), `reason` and `expires_on`,
1882 + * or null if the site has never been blocked.
1883 + */
1884 + public function get_atomic_email_block() {
1885 + return null;
1886 + }
1887 +
1888 + /**
1889 + * Get Jetpack recovery mode status.
1890 + *
1891 + * @return array|null
1892 + */
1893 + public function get_jetpack_recovery_mode_status() {
1894 + $status = get_option( 'jetpack_recovery_mode_status' );
1895 + return is_array( $status ) ? $status : null;
1896 + }
1897 +
1898 + /**
1899 + * Whether WordPress.com accounts must have two-step authentication to log in through SSO.
1900 + *
1901 + * @return bool
1902 + */
1903 + public function get_jetpack_sso_require_two_step() {
1904 + /** This filter is documented in projects/packages/connection/src/sso/class-helpers.php */
1905 + return (bool) apply_filters( 'jetpack_sso_require_two_step', get_option( 'jetpack_sso_require_two_step', false ) );
1588 1906 }
1589 1907 }