PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-status/src/class-paths.php +53 -0 13.0.2 → 16.3-beta View file →
@@ -24,5 +24,58 @@
24 24 $args = wp_parse_args( $args, array( 'page' => 'jetpack' ) );
25 25 $url = add_query_arg( $args, admin_url( 'admin.php' ) );
26 26 return $url;
27 27 }
28 +
29 + /**
30 + * Determine if the current request is activating a plugin from the plugins page.
31 + *
32 + * @param string $plugin Plugin file path to check.
33 + * @return bool
34 + */
35 + public function is_current_request_activating_plugin_from_plugins_screen( $plugin ) {
36 + // Filter out common async request contexts
37 + if (
38 + wp_doing_ajax() ||
39 + ( defined( 'REST_REQUEST' ) && REST_REQUEST ) ||
40 + ( defined( 'REST_API_REQUEST' ) && REST_API_REQUEST ) ||
41 + ( defined( 'WP_CLI' ) && WP_CLI )
42 + ) {
43 + return false;
44 + }
45 +
46 + if ( isset( $_SERVER['SCRIPT_NAME'] ) ) {
47 + $request_file = esc_url_raw( wp_unslash( $_SERVER['SCRIPT_NAME'] ) );
48 + } elseif ( isset( $_SERVER['REQUEST_URI'] ) ) {
49 + list( $request_file ) = explode( '?', esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
50 + } else {
51 + return false;
52 + }
53 +
54 + // Not the plugins page
55 + if ( strpos( $request_file, 'wp-admin/plugins.php' ) === false ) {
56 + return false;
57 + }
58 +
59 + // Same method to get the action as used by plugins.php
60 + $wp_list_table = _get_list_table( 'WP_Plugins_List_Table' );
61 + $action = $wp_list_table->current_action();
62 +
63 + // Not a singular activation
64 + // This also means that if the plugin is activated as part of a group ( bulk activation ), this function will return false here.
65 + if ( 'activate' !== $action ) {
66 + return false;
67 + }
68 +
69 + // Check the nonce associated with the plugin activation
70 + // We are not changing any data here, so this is not super necessary, it's just a best practice before using the form data from $_REQUEST.
71 + check_admin_referer( 'activate-plugin_' . $plugin );
72 +
73 + // Not the right plugin
74 + $requested_plugin = isset( $_REQUEST['plugin'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['plugin'] ) ) : null;
75 + if ( $requested_plugin !== $plugin ) {
76 + return false;
77 + }
78 +
79 + return true;
80 + }
28 81 }