| 1 |
<?php |
| 2 |
/** |
| 3 |
* The commenter's identity. |
| 4 |
* |
| 5 |
* @package automattic/jetpack-comments |
| 6 |
*/ |
| 7 |
|
| 8 |
namespace Automattic\Jetpack\Comments; |
| 9 |
|
| 10 |
/** |
| 11 |
* Who is leaving the comment being written now. |
| 12 |
*/ |
| 13 |
class Identity { |
| 14 |
|
| 15 |
/** |
| 16 |
* Who is leaving the comment, as far as this site knows. |
| 17 |
* |
| 18 |
* @return array |
| 19 |
*/ |
| 20 |
public static function settings() { |
| 21 |
$commenter = wp_get_current_commenter(); |
| 22 |
|
| 23 |
// Nothing under `identity` is about the visitor: the HTML is page-cached |
| 24 |
// and served to everyone, so who holds a passport comes from a cookie. |
| 25 |
$settings = array( |
| 26 |
'isLoggedIn' => is_user_logged_in(), |
| 27 |
'avatarUrl' => '', |
| 28 |
'commenter' => array( |
| 29 |
'author' => $commenter['comment_author'], |
| 30 |
'email' => $commenter['comment_author_email'], |
| 31 |
'url' => $commenter['comment_author_url'], |
| 32 |
), |
| 33 |
'user' => null, |
| 34 |
'identity' => array( |
| 35 |
'blogId' => Checkpoint::blog_id(), |
| 36 |
'canSignIn' => false, |
| 37 |
'connect' => null, |
| 38 |
'connectUrl' => Checkpoint_Endpoint::route_url( Checkpoint_Endpoint::CONNECT_ROUTE ), |
| 39 |
'emailUrl' => Checkpoint_Endpoint::route_url( Checkpoint_Endpoint::EMAIL_ROUTE ), |
| 40 |
'origin' => 'https://public-api.wordpress.com', |
| 41 |
'codeField' => Checkpoint::CODE_FIELD, |
| 42 |
'passportField' => Checkpoint::PASSPORT_FIELD, |
| 43 |
'displayCookie' => Passport::DISPLAY_COOKIE, |
| 44 |
'cookieHash' => COOKIEHASH, |
| 45 |
'cookiePath' => COOKIEPATH, |
| 46 |
'cookieDomain' => COOKIE_DOMAIN ? COOKIE_DOMAIN : '', |
| 47 |
'defaultAvatar' => Avatars::default_url( 80 ), |
| 48 |
// A path: Simple's admin_url() is the .wordpress.com host, which cannot clear a custom domain's cookies. |
| 49 |
'logoutUrl' => wp_make_link_relative( admin_url( 'admin-ajax.php' ) ), |
| 50 |
'logoutAction' => Checkpoint_Endpoint::LOGOUT_ACTION, |
| 51 |
), |
| 52 |
); |
| 53 |
|
| 54 |
if ( is_user_logged_in() ) { |
| 55 |
$user = wp_get_current_user(); |
| 56 |
$settings['avatarUrl'] = html_entity_decode( (string) get_avatar_url( $user->ID, array( 'size' => 80 ) ), ENT_QUOTES ); |
| 57 |
$settings['user'] = array( 'name' => $user->display_name ); |
| 58 |
|
| 59 |
return $settings; |
| 60 |
} |
| 61 |
|
| 62 |
if ( get_option( 'show_avatars' ) ) { |
| 63 |
$settings['avatarUrl'] = $commenter['comment_author_email'] |
| 64 |
? html_entity_decode( (string) get_avatar_url( $commenter['comment_author_email'], array( 'size' => 80 ) ), ENT_QUOTES ) |
| 65 |
: Avatars::default_url( 80 ); |
| 66 |
} |
| 67 |
|
| 68 |
if ( ! Checkpoint::is_available() ) { |
| 69 |
return $settings; |
| 70 |
} |
| 71 |
|
| 72 |
// Visitors share this challenge until it expires: it only filters messages |
| 73 |
// to the window that opened the popup, and the connect route issues fresh ones. |
| 74 |
$challenge = rtrim( strtr( base64_encode( random_bytes( 32 ) ), '+/', '-_' ), '=' ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- base64url is the wire format. |
| 75 |
|
| 76 |
$connect = Checkpoint::connect_url( $challenge ); |
| 77 |
|
| 78 |
$settings['identity']['canSignIn'] = true; |
| 79 |
$settings['identity']['connect'] = is_wp_error( $connect ) ? null : $connect; |
| 80 |
|
| 81 |
return $settings; |
| 82 |
} |
| 83 |
} |
| 84 |
|