← All changes
|
jetpack_vendor/automattic/jetpack-connection/src/class-webhooks.php
+24
-4
12.1.3
→
16.3-beta
View file →
| @@ -85,13 +85,13 @@ | ||
| 85 | 85 | switch ( $_GET['action'] ) { |
| 86 | 86 | case 'authorize': |
| 87 | 87 | $this->handle_authorize(); |
| 88 | 88 | $this->do_exit(); |
| 89 | - break; | |
| 89 | + break; // @phan-suppress-current-line PhanPluginUnreachableCode -- Safer to include it even though do_exit never returns. | |
| 90 | 90 | case 'authorize_redirect': |
| 91 | 91 | $this->handle_authorize_redirect(); |
| 92 | 92 | $this->do_exit(); |
| 93 | - break; | |
| 93 | + break; // @phan-suppress-current-line PhanPluginUnreachableCode -- Safer to include it even though do_exit never returns. | |
| 94 | 94 | // Class Jetpack::admin_page_load() still handles other cases. |
| 95 | 95 | } |
| 96 | 96 | } |
| 97 | 97 | |
| @@ -100,8 +100,16 @@ | ||
| 100 | 100 | */ |
| 101 | 101 | public function handle_authorize() { |
| 102 | 102 | if ( $this->connection->is_connected() && $this->connection->is_user_connected() ) { |
| 103 | 103 | $redirect_url = apply_filters( 'jetpack_client_authorize_already_authorized_url', admin_url() ); |
| 104 | + | |
| 105 | + if ( ! empty( $_GET['redirect'] ) ) { | |
| 106 | + $explicit = esc_url_raw( wp_unslash( $_GET['redirect'] ) ); | |
| 107 | + if ( wp_validate_redirect( $explicit ) ) { | |
| 108 | + $redirect_url = $explicit; | |
| 109 | + } | |
| 110 | + } | |
| 111 | + | |
| 104 | 112 | wp_safe_redirect( $redirect_url ); |
| 105 | 113 | |
| 106 | 114 | return; |
| 107 | 115 | } |
| @@ -106,9 +114,9 @@ | ||
| 106 | 114 | return; |
| 107 | 115 | } |
| 108 | 116 | do_action( 'jetpack_client_authorize_processing' ); |
| 109 | 117 | |
| 110 | - $data = stripslashes_deep( $_GET ); | |
| 118 | + $data = stripslashes_deep( $_GET ); // We need all request data under the context of an authorization request. | |
| 111 | 119 | $data['auth_type'] = 'client'; |
| 112 | 120 | $roles = new Roles(); |
| 113 | 121 | $role = $roles->translate_current_user_to_role(); |
| 114 | 122 | $redirect = isset( $data['redirect'] ) ? esc_url_raw( (string) $data['redirect'] ) : ''; |
| @@ -158,11 +166,13 @@ | ||
| 158 | 166 | } |
| 159 | 167 | |
| 160 | 168 | /** |
| 161 | 169 | * The `exit` is wrapped into a method so we could mock it. |
| 170 | + * | |
| 171 | + * @return never | |
| 162 | 172 | */ |
| 163 | 173 | protected function do_exit() { |
| 164 | - exit; | |
| 174 | + exit( 0 ); | |
| 165 | 175 | } |
| 166 | 176 | |
| 167 | 177 | /** |
| 168 | 178 | * Handle the `connect_url_redirect` action, |
| @@ -173,8 +183,10 @@ | ||
| 173 | 183 | public function handle_connect_url_redirect() { |
| 174 | 184 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes. |
| 175 | 185 | $from = ! empty( $_GET['from'] ) ? sanitize_text_field( wp_unslash( $_GET['from'] ) ) : 'iframe'; |
| 176 | 186 | |
| 187 | + $skip_pricing = filter_input( INPUT_GET, 'skip_pricing', FILTER_VALIDATE_BOOLEAN ); | |
| 188 | + | |
| 177 | 189 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- no site changes, sanitization happens in get_authorization_url() |
| 178 | 190 | $redirect = ! empty( $_GET['redirect_after_auth'] ) ? wp_unslash( $_GET['redirect_after_auth'] ) : false; |
| 179 | 191 | |
| 180 | 192 | add_filter( 'allowed_redirect_hosts', array( Host::class, 'allow_wpcom_environments' ) ); |
| @@ -185,8 +197,12 @@ | ||
| 185 | 197 | } |
| 186 | 198 | |
| 187 | 199 | $connect_url = add_query_arg( 'from', $from, $this->connection->get_authorization_url( null, $redirect ) ); |
| 188 | 200 | |
| 201 | + if ( $skip_pricing ) { | |
| 202 | + $connect_url = add_query_arg( 'skip_pricing', '1', $connect_url ); | |
| 203 | + } | |
| 204 | + | |
| 189 | 205 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes. |
| 190 | 206 | if ( isset( $_GET['notes_iframe'] ) ) { |
| 191 | 207 | $connect_url .= '¬es_iframe'; |
| 192 | 208 | } |
| @@ -196,8 +212,12 @@ | ||
| 196 | 212 | ( new CookieState() )->state( 'message', 'already_authorized' ); |
| 197 | 213 | wp_safe_redirect( $redirect ); |
| 198 | 214 | $this->do_exit(); |
| 199 | 215 | } else { |
| 216 | + if ( 'connect-after-checkout' === $from && $redirect ) { | |
| 217 | + wp_safe_redirect( $redirect ); | |
| 218 | + $this->do_exit(); | |
| 219 | + } | |
| 200 | 220 | $connect_url = add_query_arg( |
| 201 | 221 | array( |
| 202 | 222 | 'from' => $from, |
| 203 | 223 | 'already_authorized' => true, |