PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-import/src/endpoints/class-post.php +23 -37 12.0.3 → 16.3-beta View file →
@@ -7,9 +7,16 @@
7 7
8 8 namespace Automattic\Jetpack\Import\Endpoints;
9 9
10 10 use Automattic\Jetpack\Sync\Settings;
11 +use WP_Error;
12 +use WP_REST_Request;
13 +use WP_REST_Response;
11 14
15 +if ( ! defined( 'ABSPATH' ) ) {
16 + exit( 0 );
17 +}
18 +
12 19 if ( ! function_exists( 'post_exists' ) ) {
13 20 require_once ABSPATH . 'wp-admin/includes/post.php';
14 21 }
15 22
@@ -18,11 +25,16 @@
18 25 */
19 26 class Post extends \WP_REST_Posts_Controller {
20 27
21 28 /**
29 + * Base class
30 + */
31 + use Import;
32 +
33 + /**
22 34 * The Import ID add a new item to the schema.
23 35 */
24 - use Import;
36 + use Import_ID;
25 37
26 38 /**
27 39 * Whether the controller supports batching.
28 40 *
@@ -42,21 +54,8 @@
42 54 $this->import_id_meta_type = $post_type;
43 55 }
44 56
45 57 /**
46 - * Registers the routes for the objects of the controller.
47 - *
48 - * @see WP_REST_Posts_Controller::register_rest_route()
49 - */
50 - public function register_routes() {
51 - register_rest_route(
52 - self::$rest_namespace,
53 - '/' . $this->rest_base,
54 - $this->get_route_options()
55 - );
56 - }
57 -
58 - /**
59 58 * Adds the schema from additional fields to a schema array.
60 59 *
61 60 * The type of object is inferred from the passed schema.
62 61 *
@@ -78,8 +77,11 @@
78 77 * @param WP_REST_Request $request Full details about the request.
79 78 * @return WP_REST_Response|WP_Error Response object on success, or WP_Error object on failure.
80 79 */
81 80 public function create_item( $request ) {
81 + // Set the WP_IMPORTING constant to prevent sync notifications
82 + $this->set_importing();
83 +
82 84 // Skip if the post already exists.
83 85 $post_id = \post_exists(
84 86 $request['title'],
85 87 '',
@@ -88,13 +90,13 @@
88 90 $request['status']
89 91 );
90 92
91 93 if ( $post_id ) {
92 - return new \WP_Error(
94 + return new WP_Error(
93 95 'post_exists',
94 96 __( 'Cannot create existing post.', 'jetpack-import' ),
95 97 array(
96 - 'status' => 400,
98 + 'status' => 409,
97 99 'post_id' => $post_id,
98 100 )
99 101 );
100 102 }
@@ -192,26 +194,13 @@
192 194 if ( ! is_string( $value ) || ! is_serialized( $value ) ) {
193 195 return $value;
194 196 }
195 197
196 - $value = trim( $value );
197 -
198 - // unserialize()'s $options parameter is PHP 7.0+; on 5.6 the 2-arg call warns and returns false.
199 - if ( PHP_VERSION_ID < 70000 ) {
200 - // Refuse declared objects: a type token can only open the string or follow `;` or `{`.
201 - if ( preg_match( '/(?:^|[;{])[OC]:[0-9]+:"/', $value ) ) {
202 - return null;
203 - }
204 -
205 - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- object payloads refused above.
206 - return self::strip_objects( @unserialize( $value ) );
207 - }
208 -
209 198 // maybe_unserialize() decodes with no `allowed_classes`; call unserialize() directly with classes
210 199 // disallowed so meta is only ever restored as plain data. The is_serialized() guard above and the
211 200 // @ (warnings on malformed input) mirror maybe_unserialize()'s own behavior.
212 - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize, PHPCompatibility.FunctionUse.NewFunctionParameters.unserialize_optionsFound -- allowed_classes => false makes this decode safe; the gate above keeps this line off PHP 5.6.
213 - $decoded = @unserialize( $value, array( 'allowed_classes' => false ) );
201 + // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- allowed_classes => false makes this decode safe.
202 + $decoded = @unserialize( trim( $value ), array( 'allowed_classes' => false ) );
214 203
215 204 return self::strip_objects( $decoded );
216 205 }
217 206
@@ -241,18 +230,16 @@
241 230 * @param array $metas An array of metas to filter.
242 231 * @return array The filtered array of meta keys.
243 232 */
244 233 private function filter_post_meta_keys( $metas ) {
245 - // Define an array of keys to exclude from the filtered array
246 - $excluded_keys = array();
247 234 // Convert array of keys to a plain array of key strings
248 - $meta_keys = array_unique( array_values( array_keys( $metas ) ) );
235 + $meta_keys = array_unique( array_keys( $metas ) );
249 236 // // Filter the array by removing the excluded keys and any keys that include '_oembed'
250 237 $filtered_keys = array_filter(
251 238 $meta_keys,
252 - function ( $key ) use ( $excluded_keys ) {
239 + function ( $key ) {
253 240 // We also don't want to include any oembed post meta because it gets created after a post created
254 - return ! in_array( $key, $excluded_keys, true ) && strpos( $key, '_oembed' ) === false;
241 + return ! str_contains( $key, '_oembed' );
255 242 }
256 243 );
257 244 // Return the filtered array
258 245 return $filtered_keys;
@@ -312,6 +299,5 @@
312 299 $name = str_replace( array( '-', '_' ), ' ', $slug );
313 300 $name = ucwords( $name );
314 301 return $name;
315 302 }
316 -
317 303 }