PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-connection/src/class-webhooks.php +24 -4 12.1.3 → 16.3-beta View file →
@@ -85,13 +85,13 @@
85 85 switch ( $_GET['action'] ) {
86 86 case 'authorize':
87 87 $this->handle_authorize();
88 88 $this->do_exit();
89 - break;
89 + break; // @phan-suppress-current-line PhanPluginUnreachableCode -- Safer to include it even though do_exit never returns.
90 90 case 'authorize_redirect':
91 91 $this->handle_authorize_redirect();
92 92 $this->do_exit();
93 - break;
93 + break; // @phan-suppress-current-line PhanPluginUnreachableCode -- Safer to include it even though do_exit never returns.
94 94 // Class Jetpack::admin_page_load() still handles other cases.
95 95 }
96 96 }
97 97
@@ -100,8 +100,16 @@
100 100 */
101 101 public function handle_authorize() {
102 102 if ( $this->connection->is_connected() && $this->connection->is_user_connected() ) {
103 103 $redirect_url = apply_filters( 'jetpack_client_authorize_already_authorized_url', admin_url() );
104 +
105 + if ( ! empty( $_GET['redirect'] ) ) {
106 + $explicit = esc_url_raw( wp_unslash( $_GET['redirect'] ) );
107 + if ( wp_validate_redirect( $explicit ) ) {
108 + $redirect_url = $explicit;
109 + }
110 + }
111 +
104 112 wp_safe_redirect( $redirect_url );
105 113
106 114 return;
107 115 }
@@ -106,9 +114,9 @@
106 114 return;
107 115 }
108 116 do_action( 'jetpack_client_authorize_processing' );
109 117
110 - $data = stripslashes_deep( $_GET );
118 + $data = stripslashes_deep( $_GET ); // We need all request data under the context of an authorization request.
111 119 $data['auth_type'] = 'client';
112 120 $roles = new Roles();
113 121 $role = $roles->translate_current_user_to_role();
114 122 $redirect = isset( $data['redirect'] ) ? esc_url_raw( (string) $data['redirect'] ) : '';
@@ -158,11 +166,13 @@
158 166 }
159 167
160 168 /**
161 169 * The `exit` is wrapped into a method so we could mock it.
170 + *
171 + * @return never
162 172 */
163 173 protected function do_exit() {
164 - exit;
174 + exit( 0 );
165 175 }
166 176
167 177 /**
168 178 * Handle the `connect_url_redirect` action,
@@ -173,8 +183,10 @@
173 183 public function handle_connect_url_redirect() {
174 184 // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes.
175 185 $from = ! empty( $_GET['from'] ) ? sanitize_text_field( wp_unslash( $_GET['from'] ) ) : 'iframe';
176 186
187 + $skip_pricing = filter_input( INPUT_GET, 'skip_pricing', FILTER_VALIDATE_BOOLEAN );
188 +
177 189 // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- no site changes, sanitization happens in get_authorization_url()
178 190 $redirect = ! empty( $_GET['redirect_after_auth'] ) ? wp_unslash( $_GET['redirect_after_auth'] ) : false;
179 191
180 192 add_filter( 'allowed_redirect_hosts', array( Host::class, 'allow_wpcom_environments' ) );
@@ -185,8 +197,12 @@
185 197 }
186 198
187 199 $connect_url = add_query_arg( 'from', $from, $this->connection->get_authorization_url( null, $redirect ) );
188 200
201 + if ( $skip_pricing ) {
202 + $connect_url = add_query_arg( 'skip_pricing', '1', $connect_url );
203 + }
204 +
189 205 // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes.
190 206 if ( isset( $_GET['notes_iframe'] ) ) {
191 207 $connect_url .= '&notes_iframe';
192 208 }
@@ -196,8 +212,12 @@
196 212 ( new CookieState() )->state( 'message', 'already_authorized' );
197 213 wp_safe_redirect( $redirect );
198 214 $this->do_exit();
199 215 } else {
216 + if ( 'connect-after-checkout' === $from && $redirect ) {
217 + wp_safe_redirect( $redirect );
218 + $this->do_exit();
219 + }
200 220 $connect_url = add_query_arg(
201 221 array(
202 222 'from' => $from,
203 223 'already_authorized' => true,