PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-import/src/endpoints/class-post.php +16 -21 12.1.3 → 16.3-beta View file →
@@ -7,9 +7,16 @@
7 7
8 8 namespace Automattic\Jetpack\Import\Endpoints;
9 9
10 10 use Automattic\Jetpack\Sync\Settings;
11 +use WP_Error;
12 +use WP_REST_Request;
13 +use WP_REST_Response;
11 14
15 +if ( ! defined( 'ABSPATH' ) ) {
16 + exit( 0 );
17 +}
18 +
12 19 if ( ! function_exists( 'post_exists' ) ) {
13 20 require_once ABSPATH . 'wp-admin/includes/post.php';
14 21 }
15 22
@@ -70,8 +77,11 @@
70 77 * @param WP_REST_Request $request Full details about the request.
71 78 * @return WP_REST_Response|WP_Error Response object on success, or WP_Error object on failure.
72 79 */
73 80 public function create_item( $request ) {
81 + // Set the WP_IMPORTING constant to prevent sync notifications
82 + $this->set_importing();
83 +
74 84 // Skip if the post already exists.
75 85 $post_id = \post_exists(
76 86 $request['title'],
77 87 '',
@@ -80,9 +90,9 @@
80 90 $request['status']
81 91 );
82 92
83 93 if ( $post_id ) {
84 - return new \WP_Error(
94 + return new WP_Error(
85 95 'post_exists',
86 96 __( 'Cannot create existing post.', 'jetpack-import' ),
87 97 array(
88 98 'status' => 409,
@@ -184,26 +194,13 @@
184 194 if ( ! is_string( $value ) || ! is_serialized( $value ) ) {
185 195 return $value;
186 196 }
187 197
188 - $value = trim( $value );
189 -
190 - // unserialize()'s $options parameter is PHP 7.0+; on 5.6 the 2-arg call warns and returns false.
191 - if ( PHP_VERSION_ID < 70000 ) {
192 - // Refuse declared objects: a type token can only open the string or follow `;` or `{`.
193 - if ( preg_match( '/(?:^|[;{])[OC]:[0-9]+:"/', $value ) ) {
194 - return null;
195 - }
196 -
197 - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- object payloads refused above.
198 - return self::strip_objects( @unserialize( $value ) );
199 - }
200 -
201 198 // maybe_unserialize() decodes with no `allowed_classes`; call unserialize() directly with classes
202 199 // disallowed so meta is only ever restored as plain data. The is_serialized() guard above and the
203 200 // @ (warnings on malformed input) mirror maybe_unserialize()'s own behavior.
204 - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize, PHPCompatibility.FunctionUse.NewFunctionParameters.unserialize_optionsFound -- allowed_classes => false makes this decode safe; the gate above keeps this line off PHP 5.6.
205 - $decoded = @unserialize( $value, array( 'allowed_classes' => false ) );
201 + // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- allowed_classes => false makes this decode safe.
202 + $decoded = @unserialize( trim( $value ), array( 'allowed_classes' => false ) );
206 203
207 204 return self::strip_objects( $decoded );
208 205 }
209 206
@@ -233,18 +230,16 @@
233 230 * @param array $metas An array of metas to filter.
234 231 * @return array The filtered array of meta keys.
235 232 */
236 233 private function filter_post_meta_keys( $metas ) {
237 - // Define an array of keys to exclude from the filtered array
238 - $excluded_keys = array();
239 234 // Convert array of keys to a plain array of key strings
240 - $meta_keys = array_unique( array_values( array_keys( $metas ) ) );
235 + $meta_keys = array_unique( array_keys( $metas ) );
241 236 // // Filter the array by removing the excluded keys and any keys that include '_oembed'
242 237 $filtered_keys = array_filter(
243 238 $meta_keys,
244 - function ( $key ) use ( $excluded_keys ) {
239 + function ( $key ) {
245 240 // We also don't want to include any oembed post meta because it gets created after a post created
246 - return ! in_array( $key, $excluded_keys, true ) && strpos( $key, '_oembed' ) === false;
241 + return ! str_contains( $key, '_oembed' );
247 242 }
248 243 );
249 244 // Return the filtered array
250 245 return $filtered_keys;