PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | extensions/blocks/premium-content/login-button/login-button.php +31 -6 13.5.2 → 16.3-a.7 View file →
@@ -25,9 +25,10 @@
25 25 function register_login_button_block() {
26 26 Blocks::jetpack_register_block(
27 27 LOGIN_BUTTON_NAME,
28 28 array(
29 - 'render_callback' => __NAMESPACE__ . '\render_login_button_block',
29 + 'render_callback' => __NAMESPACE__ . '\render_login_button_block',
30 + 'render_email_callback' => __NAMESPACE__ . '\render_login_button_block_email',
30 31 )
31 32 );
32 33 }
33 34 add_action( 'init', __NAMESPACE__ . '\register_login_button_block' );
@@ -59,11 +60,16 @@
59 60 // On WPCOM we will redirect immediately
60 61 return wpcom_logmein_redirect_url( $redirect, false, null, 'link', get_current_blog_id() );
61 62 }
62 63
63 - // On self-hosted we will save and hide the token
64 + // On self-hosted we will save and hide the token.
65 + // rawurlencode the redirect before nesting it: it is already percent-encoded
66 + // (e.g. an emoji or non-ASCII slug comes through as %F0%9F%8C%91), and add_query_arg
67 + // does not encode the values it inserts. Without this extra layer the value is
68 + // over-decoded to raw bytes by the time it reaches the subscribers/auth endpoint,
69 + // which strips it and 404s. See NL-273.
64 70 $redirect_url = get_site_url() . '/wp-json/jetpack/v4/subscribers/auth';
65 - $redirect_url = add_query_arg( 'redirect_url', $redirect, $redirect_url );
71 + $redirect_url = add_query_arg( 'redirect_url', rawurlencode( $redirect ), $redirect_url );
66 72
67 73 return add_query_arg(
68 74 array(
69 75 'site_id' => intval( Jetpack_Options::get_option( 'id' ) ),
@@ -73,14 +79,17 @@
73 79 );
74 80 }
75 81
76 82 /**
77 - * Determines whether the current visitor is a logged in user or a subscriber.
83 + * Determines whether the visitor has a subscriber session for the login UI.
78 84 *
85 + * WordPress sessions count on Simple; other hosts require the subscriber cookie.
86 + * Content access validates the token separately.
87 + *
79 88 * @return bool
80 89 */
81 90 function is_subscriber_logged_in() {
82 - return is_user_logged_in() || Abstract_Token_Subscription_Service::has_token_from_cookie();
91 + return ( ( new Host() )->is_wpcom_simple() && is_user_logged_in() ) || Abstract_Token_Subscription_Service::has_token_from_cookie();
83 92 }
84 93
85 94 /**
86 95 * Render callback.
@@ -104,6 +113,22 @@
104 113
105 114 $redirect_url = get_current_url();
106 115 $url = get_subscriber_login_url( $redirect_url );
107 116
108 - return preg_replace( '/(<a\b[^><]*)>/i', '$1 href="' . esc_url( $url ) . '">', $content );
117 + $content = preg_replace( '/(<a\b[^><]*)>/i', '$1 href="' . esc_url( $url ) . '">', $content );
118 +
119 + // Defense in depth: the label is inner block content (KSES-filtered on save for
120 + // roles without `unfiltered_html`), but escape it again on output so a stored
121 + // payload can never render as live markup.
122 + return wp_kses_post( $content );
123 +}
124 +
125 +/**
126 + * Render email callback.
127 + *
128 + * @return string
129 + */
130 +function render_login_button_block_email() {
131 + // We don't want to render the login button in emails.
132 + // The subscriber is already considered logged in in emails.
133 + return '';
109 134 }