PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | modules/verification-tools/verification-tools-utils.php +74 -18 13.6.2 → 16.3-a.7 View file →
@@ -5,26 +5,75 @@
5 5 *
6 6 * @package jetpack
7 7 */
8 8
9 -if ( ! function_exists( 'jetpack_verification_validate' ) ) {
9 +if ( ! function_exists( 'jetpack_verification_extract_code' ) ) {
10 10 /**
11 + * Extract a site verification code from a meta tag.
12 + *
13 + * @since 16.3
14 + *
15 + * @param string $code Verification meta tag.
16 + * @return string|false Extracted code, or false when none is found.
17 + */
18 + function jetpack_verification_extract_code( $code ) {
19 + $pattern = '/content=["\']?([^"\' ]*)["\' ]/is';
20 + preg_match( $pattern, $code, $match );
21 +
22 + return $match ? rawurldecode( $match[1] ) : false;
23 + }
24 +}
25 +
26 +if ( ! function_exists( 'jetpack_verification_validate_code' ) ) {
27 + /**
28 + * Validate and normalize a site verification code.
29 + *
30 + * @since 16.3
31 + *
32 + * @param mixed $code Verification code or meta tag.
33 + * @return string|false Normalized code, or false when invalid.
34 + */
35 + function jetpack_verification_validate_code( $code ) {
36 + if ( ! is_scalar( $code ) ) {
37 + return false;
38 + }
39 +
40 + // Allow printable ASCII except characters that can delimit HTML attributes or tags.
41 + $code_pattern = '/^(?!.*[<>"\'])[!-~]+$/';
42 + $code = trim( (string) $code );
43 +
44 + if ( '' === $code ) {
45 + return '';
46 + }
47 +
48 + // Parse html meta tag if it does not look like a valid code.
49 + if ( ! preg_match( $code_pattern, $code ) ) {
50 + $code = jetpack_verification_extract_code( $code );
51 + }
52 +
53 + $code = trim( (string) $code );
54 + if ( '' === $code || ! preg_match( $code_pattern, $code ) ) {
55 + return false;
56 + }
57 +
58 + return substr( $code, 0, 100 );
59 + }
60 +}
61 +
62 +if ( ! function_exists( 'jetpack_verification_validate_codes' ) ) {
63 + /**
11 64 * Validate jetpack verification codes.
12 65 *
66 + * @since 16.3
67 + *
13 68 * @param array $verification_services_codes - array of verification codes.
69 + * @return array Validated verification codes.
14 70 */
15 - function jetpack_verification_validate( $verification_services_codes ) {
71 + function jetpack_verification_validate_codes( $verification_services_codes ) {
16 72 foreach ( $verification_services_codes as $key => $code ) {
17 - // Parse html meta tag if it does not look like a valid code.
18 - if ( ! preg_match( '/^[a-z0-9_-]+$/i', $code ) ) {
19 - $code = jetpack_verification_get_code( $code );
20 - }
73 + $code = jetpack_verification_validate_code( $code );
74 + $code = false === $code ? '' : $code;
21 75
22 - $code = esc_attr( trim( $code ) );
23 -
24 - // limit length to 100 chars.
25 - $code = substr( $code, 0, 100 );
26 -
27 76 /**
28 77 * Fire after each Verification code was validated.
29 78 *
30 79 * @module verification-tools
@@ -41,20 +90,27 @@
41 90 return $verification_services_codes;
42 91 }
43 92 }
44 93
94 +if ( ! function_exists( 'jetpack_verification_validate' ) ) {
95 + /**
96 + * Validate jetpack verification codes.
97 + *
98 + * @param array $verification_services_codes - array of verification codes.
99 + * @return array Validated verification codes.
100 + */
101 + function jetpack_verification_validate( $verification_services_codes ) {
102 + return jetpack_verification_validate_codes( $verification_services_codes );
103 + }
104 +}
105 +
45 106 if ( ! function_exists( 'jetpack_verification_get_code' ) ) {
46 107 /**
47 108 * Return the code we're trying to verify after decoding.
48 109 *
49 110 * @param string $code - the code we need to parse.
111 + * @return string|false Extracted code, or false when none is found.
50 112 */
51 113 function jetpack_verification_get_code( $code ) {
52 - $pattern = '/content=["\']?([^"\' ]*)["\' ]/is';
53 - preg_match( $pattern, $code, $match );
54 - if ( $match ) {
55 - return urldecode( $match[1] );
56 - } else {
57 - return false;
58 - }
114 + return jetpack_verification_extract_code( $code );
59 115 }
60 116 }