PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | jetpack_vendor/automattic/jetpack-connection/src/class-utils.php +84 -1 13.7.2 → 16.3-a.7 View file →
@@ -128,8 +128,91 @@
128 128 }
129 129
130 130 $created_user_id = wp_insert_user( $user );
131 131
132 - update_user_meta( $created_user_id, 'wpcom_user_id', $user_data->ID );
132 + // `clean_user_cache()` calls `exists()` on anything non-numeric, which a WP_Error does not have.
133 + if ( is_wp_error( $created_user_id ) ) {
134 + return false;
135 + }
136 +
137 + self::set_wpcom_user_id( $created_user_id, (int) $user_data->ID );
133 138 return get_userdata( $created_user_id );
139 + }
140 +
141 + /**
142 + * Get the WordPress.com user ID bound to a local user.
143 + *
144 + * The `wpcom_user_id` meta is a durable, one-to-one, WordPress.com-asserted identity binding,
145 + * not a cache of any one token: SSO and Premium Content read and write it too, and it outlives
146 + * the connection that first established it. Do not drop it because a token went away.
147 + *
148 + * @since 9.2.0
149 + *
150 + * @param int $user_id The local WordPress user ID.
151 + * @return int The WordPress.com user ID, or 0 when none is bound.
152 + */
153 + public static function get_wpcom_user_id( $user_id ) {
154 + return (int) get_user_meta( absint( $user_id ), 'wpcom_user_id', true );
155 + }
156 +
157 + /**
158 + * Bind a WordPress.com user ID to a local user, removing it from any other user first.
159 + *
160 + * Two local users answering to the same WordPress.com identity would make owner resolution
161 + * ambiguous, so the previous holder is cleared. That only holds for writes routed through here:
162 + * Premium Content writes the same key directly, so uniqueness is not guaranteed site-wide. On
163 + * multisite the lookup is scoped to the current site.
164 + *
165 + * @since 9.2.0
166 + *
167 + * @param int $user_id The local WordPress user ID.
168 + * @param int $wpcom_user_id The WordPress.com user ID.
169 + */
170 + public static function set_wpcom_user_id( $user_id, $wpcom_user_id ) {
171 + $user_id = absint( $user_id );
172 + $wpcom_user_id = absint( $wpcom_user_id );
173 +
174 + // 0 is what `get_wpcom_user_id()` returns for "nothing bound", so it is not storable.
175 + if ( ! $user_id || ! $wpcom_user_id ) {
176 + return;
177 + }
178 +
179 + $existing = new \WP_User_Query(
180 + array(
181 + 'meta_key' => 'wpcom_user_id',
182 + 'meta_value' => $wpcom_user_id,
183 + 'exclude' => array( $user_id ),
184 + 'fields' => 'ID',
185 + 'count_total' => false,
186 + )
187 + );
188 +
189 + foreach ( $existing->get_results() as $stale_user_id ) {
190 + delete_user_meta( $stale_user_id, 'wpcom_user_id' );
191 + clean_user_cache( $stale_user_id );
192 + }
193 +
194 + update_user_meta( $user_id, 'wpcom_user_id', $wpcom_user_id );
195 + clean_user_cache( $user_id );
196 + }
197 +
198 + /**
199 + * Drop the WordPress.com user ID bound to a local user.
200 + *
201 + * Only for when the binding itself is known to be wrong — a token replaced with a different
202 + * WordPress.com account. A disconnect does not make it wrong, and other subsystems store their
203 + * own meaning in this key.
204 + *
205 + * @since 9.2.0
206 + *
207 + * @param int $user_id The local WordPress user ID.
208 + */
209 + public static function delete_wpcom_user_id( $user_id ) {
210 + $user_id = absint( $user_id );
211 +
212 + // `clean_user_cache()` bumps the site-wide users cache salt, so skip it on the common
213 + // no-op path where there was nothing bound.
214 + if ( delete_user_meta( $user_id, 'wpcom_user_id' ) ) {
215 + clean_user_cache( $user_id );
216 + }
134 217 }
135 218 }