PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | jetpack_vendor/automattic/jetpack-assets/src/class-script-data.php +67 -28 13.8.3 → 16.3-a.7 View file →
@@ -7,8 +7,10 @@
7 7
8 8 namespace Automattic\Jetpack\Assets;
9 9
10 10 use Automattic\Jetpack\Assets;
11 +use Automattic\Jetpack\Status;
12 +use Automattic\Jetpack\Status\Host;
11 13
12 14 /**
13 15 * Class script data
14 16 */
@@ -16,11 +18,24 @@
16 18
17 19 const SCRIPT_HANDLE = 'jetpack-script-data';
18 20
19 21 /**
22 + * Whether the script data has been rendered.
23 + *
24 + * @var bool
25 + */
26 + private static $did_render_script_data = false;
27 +
28 + /**
20 29 * Configure.
21 30 */
22 31 public static function configure() {
32 + // Hooked by actions.php since 2.3.0, so this is the package's recovery point.
33 + // Assets can still resolve to an older copy than this class, hence the guard.
34 + if ( method_exists( Assets::class, 'ensure_package_bootstrap' ) ) {
35 + Assets::ensure_package_bootstrap();
36 + }
37 +
23 38 /**
24 39 * Ensure that assets are registered on wp_loaded,
25 40 * which is fired before *_enqueue_scripts actions.
26 41 * It means that when the dependent scripts are registered,
@@ -39,8 +54,9 @@
39 54 * to decide whether to update the script data or not.
40 55 */
41 56 $hook = is_admin() ? 'admin_print_scripts' : 'wp_print_scripts';
42 57 add_action( $hook, array( self::class, 'render_script_data' ), 1 );
58 + add_action( 'enqueue_block_editor_assets', array( self::class, 'render_script_data' ), 1 );
43 59 }
44 60
45 61 /**
46 62 * Register assets.
@@ -67,24 +83,44 @@
67 83 *
68 84 * @return void
69 85 */
70 86 public static function render_script_data() {
87 + // In case of 'enqueue_block_editor_assets' action, this can be called multiple times.
88 + if ( self::$did_render_script_data ) {
89 + return;
90 + }
71 91
72 - $script_data = is_admin() ? self::get_admin_script_data() : self::get_public_script_data();
92 + self::$did_render_script_data = true;
73 93
74 - $script_data = wp_json_encode(
75 - $script_data,
76 - JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP | JSON_UNESCAPED_UNICODE
77 - );
94 + $script_data = is_admin() || self::is_authenticated_rest_request()
95 + ? self::get_admin_script_data()
96 + : self::get_public_script_data();
78 97
79 - wp_add_inline_script(
80 - self::SCRIPT_HANDLE,
81 - sprintf( 'window.JetpackScriptData = %s;', $script_data ),
82 - 'before'
83 - );
98 + if ( ! empty( $script_data ) ) {
99 + $script_data = wp_json_encode(
100 + $script_data,
101 + JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP | JSON_UNESCAPED_UNICODE
102 + );
103 +
104 + wp_add_inline_script(
105 + self::SCRIPT_HANDLE,
106 + sprintf( 'window.JetpackScriptData = %s;', $script_data ),
107 + 'before'
108 + );
109 + Assets::enqueue_script( self::SCRIPT_HANDLE );
110 + }
84 111 }
85 112
86 113 /**
114 + * Whether the current request is an authenticated REST API request.
115 + *
116 + * @return bool
117 + */
118 + protected static function is_authenticated_rest_request() {
119 + return wp_is_serving_rest_request() && current_user_can( 'read' );
120 + }
121 +
122 + /**
87 123 * Get the admin script data.
88 124 *
89 125 * @return array
90 126 */
@@ -93,22 +129,25 @@
93 129 global $wp_version;
94 130
95 131 $data = array(
96 132 'site' => array(
97 - 'admin_url' => esc_url_raw( admin_url() ),
98 - 'date_format' => get_option( 'date_format' ),
99 - 'icon' => self::get_site_icon(),
100 - 'is_multisite' => is_multisite(),
101 - 'plan' => array(
133 + 'admin_url' => esc_url_raw( admin_url() ),
134 + 'date_format' => get_option( 'date_format' ),
135 + 'icon' => self::get_site_icon(),
136 + 'is_multisite' => is_multisite(),
137 + 'host' => ( new Host() )->get_known_host_guess(),
138 + 'is_wpcom_platform' => ( new Host() )->is_wpcom_platform(),
139 + 'plan' => array(
102 140 // The properties here should be updated by the consumer package/plugin.
103 141 // It includes properties like 'product_slug', 'features', etc.
104 142 'product_slug' => '',
105 143 ),
106 - 'rest_nonce' => wp_create_nonce( 'wp_rest' ),
107 - 'rest_root' => esc_url_raw( rest_url() ),
108 - 'title' => self::get_site_title(),
109 - 'wp_version' => $wp_version,
110 - 'wpcom' => array(
144 + 'rest_nonce' => wp_create_nonce( 'wp_rest' ),
145 + 'rest_root' => esc_url_raw( rest_url() ),
146 + 'suffix' => ( new Status() )->get_site_suffix(),
147 + 'title' => self::get_site_title(),
148 + 'wp_version' => $wp_version,
149 + 'wpcom' => array(
111 150 // This should contain the connected site details like blog_id, is_atomic etc.
112 151 'blog_id' => 0,
113 152 ),
114 153 ),
@@ -132,20 +171,15 @@
132 171 return apply_filters( 'jetpack_admin_js_script_data', $data );
133 172 }
134 173
135 174 /**
136 - * Get the admin script data.
175 + * Get the public script data.
137 176 *
138 177 * @return array
139 178 */
140 179 protected static function get_public_script_data() {
141 180
142 - $data = array(
143 - 'site' => array(
144 - 'icon' => self::get_site_icon(),
145 - 'title' => self::get_site_title(),
146 - ),
147 - );
181 + $data = array();
148 182
149 183 /**
150 184 * Filter the public script data.
151 185 *
@@ -163,9 +197,9 @@
163 197 *
164 198 * @return string
165 199 */
166 200 protected static function get_site_title() {
167 - $title = get_bloginfo( 'name' );
201 + $title = wp_specialchars_decode( get_bloginfo( 'name' ), ENT_QUOTES );
168 202
169 203 return $title ? $title : esc_url_raw( ( get_site_url() ) );
170 204 }
171 205
@@ -200,7 +234,12 @@
200 234
201 235 return array(
202 236 'display_name' => $current_user->display_name,
203 237 'id' => $current_user->ID,
238 + 'capabilities' => array(
239 + 'edit_others_posts' => current_user_can( 'edit_others_posts' ),
240 + 'manage_options' => current_user_can( 'manage_options' ),
241 + 'manage_modules' => current_user_can( 'jetpack_manage_modules' ),
242 + ),
204 243 );
205 244 }
206 245 }