PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-connection/src/class-rest-authentication.php +22 -4 12.3.2 → 16.3-beta View file →
@@ -6,8 +6,10 @@
6 6 */
7 7
8 8 namespace Automattic\Jetpack\Connection;
9 9
10 +use WP_Error;
11 +
10 12 /**
11 13 * The Jetpack Connection Rest Authentication class.
12 14 */
13 15 class Rest_Authentication {
@@ -116,10 +118,13 @@
116 118 // Nothing to do for this authentication method.
117 119 return null;
118 120 }
119 121
122 + // These `rest_invalid_request` errors occur before `verify_xml_rpc_signature()`,
123 + // so the request has not been authenticated as WP.com. Do not report them to
124 + // Error_Handler: they are malformed unauthenticated requests, not connection errors.
120 125 if ( ! isset( $_SERVER['REQUEST_METHOD'] ) ) {
121 - $this->rest_authentication_status = new \WP_Error(
126 + $this->rest_authentication_status = new WP_Error(
122 127 'rest_invalid_request',
123 128 __( 'The request method is missing.', 'jetpack-connection' ),
124 129 array( 'status' => 400 )
125 130 );
@@ -130,9 +135,9 @@
130 135 // are known to work with signature verification. A different method
131 136 // can be passed to the WP REST API via the '?_method=' parameter if
132 137 // needed.
133 138 if ( 'GET' !== $_SERVER['REQUEST_METHOD'] && 'POST' !== $_SERVER['REQUEST_METHOD'] ) {
134 - $this->rest_authentication_status = new \WP_Error(
139 + $this->rest_authentication_status = new WP_Error(
135 140 'rest_invalid_request',
136 141 __( 'This request method is not supported.', 'jetpack-connection' ),
137 142 array( 'status' => 400 )
138 143 );
@@ -138,9 +143,9 @@
138 143 );
139 144 return null;
140 145 }
141 146 if ( 'POST' !== $_SERVER['REQUEST_METHOD'] && ! empty( file_get_contents( 'php://input' ) ) ) {
142 - $this->rest_authentication_status = new \WP_Error(
147 + $this->rest_authentication_status = new WP_Error(
143 148 'rest_invalid_request',
144 149 __( 'This request method does not support body parameters.', 'jetpack-connection' ),
145 150 array( 'status' => 400 )
146 151 );
@@ -172,9 +177,9 @@
172 177 return $verified['user_id'];
173 178 }
174 179
175 180 // Something else went wrong. Probably a signature error.
176 - $this->rest_authentication_status = new \WP_Error(
181 + $this->rest_authentication_status = new WP_Error(
177 182 'rest_invalid_signature',
178 183 __( 'The request is not signed correctly.', 'jetpack-connection' ),
179 184 array( 'status' => 400 )
180 185 );
@@ -215,6 +220,19 @@
215 220 public static function is_signed_with_blog_token() {
216 221 $instance = self::init();
217 222
218 223 return true === $instance->rest_authentication_status && 'blog' === $instance->rest_authentication_type;
224 + }
225 +
226 + /**
227 + * Whether the request was signed with a user token.
228 + *
229 + * @since 6.7.0
230 + *
231 + * @return bool True if the request was signed with a valid user token, false otherwise.
232 + */
233 + public static function is_signed_with_user_token() {
234 + $instance = self::init();
235 +
236 + return true === $instance->rest_authentication_status && 'user' === $instance->rest_authentication_type;
219 237 }
220 238 }