← All changes
|
jetpack_vendor/automattic/jetpack-connection/src/class-rest-authentication.php
+22
-4
12.4.2
→
16.3-beta
View file →
| @@ -6,8 +6,10 @@ | ||
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | 8 | namespace Automattic\Jetpack\Connection; |
| 9 | 9 | |
| 10 | +use WP_Error; | |
| 11 | + | |
| 10 | 12 | /** |
| 11 | 13 | * The Jetpack Connection Rest Authentication class. |
| 12 | 14 | */ |
| 13 | 15 | class Rest_Authentication { |
| @@ -116,10 +118,13 @@ | ||
| 116 | 118 | // Nothing to do for this authentication method. |
| 117 | 119 | return null; |
| 118 | 120 | } |
| 119 | 121 | |
| 122 | + // These `rest_invalid_request` errors occur before `verify_xml_rpc_signature()`, | |
| 123 | + // so the request has not been authenticated as WP.com. Do not report them to | |
| 124 | + // Error_Handler: they are malformed unauthenticated requests, not connection errors. | |
| 120 | 125 | if ( ! isset( $_SERVER['REQUEST_METHOD'] ) ) { |
| 121 | - $this->rest_authentication_status = new \WP_Error( | |
| 126 | + $this->rest_authentication_status = new WP_Error( | |
| 122 | 127 | 'rest_invalid_request', |
| 123 | 128 | __( 'The request method is missing.', 'jetpack-connection' ), |
| 124 | 129 | array( 'status' => 400 ) |
| 125 | 130 | ); |
| @@ -130,9 +135,9 @@ | ||
| 130 | 135 | // are known to work with signature verification. A different method |
| 131 | 136 | // can be passed to the WP REST API via the '?_method=' parameter if |
| 132 | 137 | // needed. |
| 133 | 138 | if ( 'GET' !== $_SERVER['REQUEST_METHOD'] && 'POST' !== $_SERVER['REQUEST_METHOD'] ) { |
| 134 | - $this->rest_authentication_status = new \WP_Error( | |
| 139 | + $this->rest_authentication_status = new WP_Error( | |
| 135 | 140 | 'rest_invalid_request', |
| 136 | 141 | __( 'This request method is not supported.', 'jetpack-connection' ), |
| 137 | 142 | array( 'status' => 400 ) |
| 138 | 143 | ); |
| @@ -138,9 +143,9 @@ | ||
| 138 | 143 | ); |
| 139 | 144 | return null; |
| 140 | 145 | } |
| 141 | 146 | if ( 'POST' !== $_SERVER['REQUEST_METHOD'] && ! empty( file_get_contents( 'php://input' ) ) ) { |
| 142 | - $this->rest_authentication_status = new \WP_Error( | |
| 147 | + $this->rest_authentication_status = new WP_Error( | |
| 143 | 148 | 'rest_invalid_request', |
| 144 | 149 | __( 'This request method does not support body parameters.', 'jetpack-connection' ), |
| 145 | 150 | array( 'status' => 400 ) |
| 146 | 151 | ); |
| @@ -172,9 +177,9 @@ | ||
| 172 | 177 | return $verified['user_id']; |
| 173 | 178 | } |
| 174 | 179 | |
| 175 | 180 | // Something else went wrong. Probably a signature error. |
| 176 | - $this->rest_authentication_status = new \WP_Error( | |
| 181 | + $this->rest_authentication_status = new WP_Error( | |
| 177 | 182 | 'rest_invalid_signature', |
| 178 | 183 | __( 'The request is not signed correctly.', 'jetpack-connection' ), |
| 179 | 184 | array( 'status' => 400 ) |
| 180 | 185 | ); |
| @@ -215,6 +220,19 @@ | ||
| 215 | 220 | public static function is_signed_with_blog_token() { |
| 216 | 221 | $instance = self::init(); |
| 217 | 222 | |
| 218 | 223 | return true === $instance->rest_authentication_status && 'blog' === $instance->rest_authentication_type; |
| 224 | + } | |
| 225 | + | |
| 226 | + /** | |
| 227 | + * Whether the request was signed with a user token. | |
| 228 | + * | |
| 229 | + * @since 6.7.0 | |
| 230 | + * | |
| 231 | + * @return bool True if the request was signed with a valid user token, false otherwise. | |
| 232 | + */ | |
| 233 | + public static function is_signed_with_user_token() { | |
| 234 | + $instance = self::init(); | |
| 235 | + | |
| 236 | + return true === $instance->rest_authentication_status && 'user' === $instance->rest_authentication_type; | |
| 219 | 237 | } |
| 220 | 238 | } |