← All changes
|
jetpack_vendor/automattic/jetpack-import/src/endpoints/class-post.php
+16
-21
12.7.3
→
16.3-beta
View file →
| @@ -7,9 +7,16 @@ | ||
| 7 | 7 | |
| 8 | 8 | namespace Automattic\Jetpack\Import\Endpoints; |
| 9 | 9 | |
| 10 | 10 | use Automattic\Jetpack\Sync\Settings; |
| 11 | +use WP_Error; | |
| 12 | +use WP_REST_Request; | |
| 13 | +use WP_REST_Response; | |
| 11 | 14 | |
| 15 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 16 | + exit( 0 ); | |
| 17 | +} | |
| 18 | + | |
| 12 | 19 | if ( ! function_exists( 'post_exists' ) ) { |
| 13 | 20 | require_once ABSPATH . 'wp-admin/includes/post.php'; |
| 14 | 21 | } |
| 15 | 22 | |
| @@ -70,8 +77,11 @@ | ||
| 70 | 77 | * @param WP_REST_Request $request Full details about the request. |
| 71 | 78 | * @return WP_REST_Response|WP_Error Response object on success, or WP_Error object on failure. |
| 72 | 79 | */ |
| 73 | 80 | public function create_item( $request ) { |
| 81 | + // Set the WP_IMPORTING constant to prevent sync notifications | |
| 82 | + $this->set_importing(); | |
| 83 | + | |
| 74 | 84 | // Skip if the post already exists. |
| 75 | 85 | $post_id = \post_exists( |
| 76 | 86 | $request['title'], |
| 77 | 87 | '', |
| @@ -80,9 +90,9 @@ | ||
| 80 | 90 | $request['status'] |
| 81 | 91 | ); |
| 82 | 92 | |
| 83 | 93 | if ( $post_id ) { |
| 84 | - return new \WP_Error( | |
| 94 | + return new WP_Error( | |
| 85 | 95 | 'post_exists', |
| 86 | 96 | __( 'Cannot create existing post.', 'jetpack-import' ), |
| 87 | 97 | array( |
| 88 | 98 | 'status' => 409, |
| @@ -184,26 +194,13 @@ | ||
| 184 | 194 | if ( ! is_string( $value ) || ! is_serialized( $value ) ) { |
| 185 | 195 | return $value; |
| 186 | 196 | } |
| 187 | 197 | |
| 188 | - $value = trim( $value ); | |
| 189 | - | |
| 190 | - // unserialize()'s $options parameter is PHP 7.0+; on 5.6 the 2-arg call warns and returns false. | |
| 191 | - if ( PHP_VERSION_ID < 70000 ) { | |
| 192 | - // Refuse declared objects: a type token can only open the string or follow `;` or `{`. | |
| 193 | - if ( preg_match( '/(?:^|[;{])[OC]:[0-9]+:"/', $value ) ) { | |
| 194 | - return null; | |
| 195 | - } | |
| 196 | - | |
| 197 | - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- object payloads refused above. | |
| 198 | - return self::strip_objects( @unserialize( $value ) ); | |
| 199 | - } | |
| 200 | - | |
| 201 | 198 | // maybe_unserialize() decodes with no `allowed_classes`; call unserialize() directly with classes |
| 202 | 199 | // disallowed so meta is only ever restored as plain data. The is_serialized() guard above and the |
| 203 | 200 | // @ (warnings on malformed input) mirror maybe_unserialize()'s own behavior. |
| 204 | - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize, PHPCompatibility.FunctionUse.NewFunctionParameters.unserialize_optionsFound -- allowed_classes => false makes this decode safe; the gate above keeps this line off PHP 5.6. | |
| 205 | - $decoded = @unserialize( $value, array( 'allowed_classes' => false ) ); | |
| 201 | + // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- allowed_classes => false makes this decode safe. | |
| 202 | + $decoded = @unserialize( trim( $value ), array( 'allowed_classes' => false ) ); | |
| 206 | 203 | |
| 207 | 204 | return self::strip_objects( $decoded ); |
| 208 | 205 | } |
| 209 | 206 | |
| @@ -233,18 +230,16 @@ | ||
| 233 | 230 | * @param array $metas An array of metas to filter. |
| 234 | 231 | * @return array The filtered array of meta keys. |
| 235 | 232 | */ |
| 236 | 233 | private function filter_post_meta_keys( $metas ) { |
| 237 | - // Define an array of keys to exclude from the filtered array | |
| 238 | - $excluded_keys = array(); | |
| 239 | 234 | // Convert array of keys to a plain array of key strings |
| 240 | - $meta_keys = array_unique( array_values( array_keys( $metas ) ) ); | |
| 235 | + $meta_keys = array_unique( array_keys( $metas ) ); | |
| 241 | 236 | // // Filter the array by removing the excluded keys and any keys that include '_oembed' |
| 242 | 237 | $filtered_keys = array_filter( |
| 243 | 238 | $meta_keys, |
| 244 | - function ( $key ) use ( $excluded_keys ) { | |
| 239 | + function ( $key ) { | |
| 245 | 240 | // We also don't want to include any oembed post meta because it gets created after a post created |
| 246 | - return ! in_array( $key, $excluded_keys, true ) && strpos( $key, '_oembed' ) === false; | |
| 241 | + return ! str_contains( $key, '_oembed' ); | |
| 247 | 242 | } |
| 248 | 243 | ); |
| 249 | 244 | // Return the filtered array |
| 250 | 245 | return $filtered_keys; |