PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/woocommerce-analytics/src/API/class-wc-analytics-tracking-proxy.php +20 -3 16.2 → 16.3-a.7 View file →
@@ -40,9 +40,11 @@
40 40 array(
41 41 array(
42 42 'methods' => \WP_REST_Server::CREATABLE,
43 43 'callback' => array( $this, 'track_events' ),
44 - 'permission_callback' => '__return_true', // no need to check permissions
44 + // Unauthenticated front-end event endpoint. track_events() validates consent
45 + // and records events without client-supplied server-owned properties.
46 + 'permission_callback' => '__return_true',
45 47 'schema' => array( $this, 'get_public_item_schema' ),
46 48 ),
47 49 )
48 50 );
@@ -54,8 +56,18 @@
54 56 * @param \WP_REST_Request $request Full data about the request.
55 57 * @return \WP_REST_Response|\WP_Error Response object on success, or WP_Error object on failure.
56 58 */
57 59 public function track_events( $request ) {
60 + // Cached pages can still post here after proxy tracking is disabled; return a
61 + // visible error instead of losing the event to a 404.
62 + if ( ! Features::is_proxy_tracking_enabled() ) {
63 + return new \WP_Error(
64 + 'proxy_tracking_disabled',
65 + 'Proxy tracking is not enabled on this site.',
66 + array( 'status' => 403 )
67 + );
68 + }
69 +
58 70 // Check consent before processing any events
59 71 if ( ! Consent_Manager::has_analytics_consent() ) {
60 72 return new \WP_REST_Response(
61 73 array(
@@ -73,8 +85,13 @@
73 85 // If $events is a single event (associative array), wrap it in an array.
74 86 $events = array( $events );
75 87 }
76 88
89 + // Limit unauthenticated callers to a bounded number of pixel requests.
90 + if ( count( $events ) > WC_Analytics_Tracking::MAX_CLIENT_EVENTS_PER_REQUEST ) {
91 + $events = array_slice( $events, 0, WC_Analytics_Tracking::MAX_CLIENT_EVENTS_PER_REQUEST, true );
92 + }
93 +
77 94 $results = array();
78 95 $has_errors = false;
79 96
80 97 foreach ( $events as $index => $event ) {
@@ -90,9 +107,9 @@
90 107
91 108 // Validate event name and properties.
92 109 $event_name = $event['event_name'] ?? null;
93 110 $properties = $event['properties'] ?? array();
94 - if ( ! $event_name || ! is_array( $properties ) ) {
111 + if ( ! $event_name || ! is_string( $event_name ) || ! is_array( $properties ) ) {
95 112 $results[ $index ] = array(
96 113 'success' => false,
97 114 'error' => 'Missing event_name or invalid properties',
98 115 );
@@ -99,9 +116,9 @@
99 116 $has_errors = true;
100 117 continue;
101 118 }
102 119
103 - $result = WC_Analytics_Tracking::record_event( $event_name, $properties );
120 + $result = WC_Analytics_Tracking::record_client_event( $event_name, $properties );
104 121
105 122 if ( is_wp_error( $result ) ) {
106 123 $results[ $index ] = array(
107 124 'success' => false,