PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | extensions/blocks/subscriber-login/subscriber-login.php +44 -19 13.1.5 → 16.3-beta View file →
@@ -11,13 +11,20 @@
11 11
12 12 use Automattic\Jetpack\Blocks;
13 13 use Automattic\Jetpack\Extensions\Premium_Content\Subscription_Service\Abstract_Token_Subscription_Service;
14 14 use Automattic\Jetpack\Status\Host;
15 +use Automattic\Jetpack\Status\Request;
15 16 use Jetpack;
16 17 use Jetpack_Gutenberg;
17 18 use Jetpack_Memberships;
18 19 use Jetpack_Options;
19 20
21 +if ( ! defined( 'ABSPATH' ) ) {
22 + exit( 0 );
23 +}
24 +
25 +require_once __DIR__ . '/class-jetpack-subscription-site.php';
26 +
20 27 /**
21 28 * Registers the block for use in Gutenberg
22 29 * This is done via an action so that we can disable
23 30 * registration if we need to.
@@ -35,22 +42,32 @@
35 42 __DIR__,
36 43 array( 'render_callback' => __NAMESPACE__ . '\render_block' )
37 44 );
38 45
39 - add_action( 'wp_logout', __NAMESPACE__ . '\subscriber_logout' );
46 + add_filter(
47 + 'jetpack_options_whitelist',
48 + function ( $options ) {
49 + $options[] = 'jetpack_subscriptions_login_navigation_enabled';
50 +
51 + return $options;
52 + }
53 + );
54 +
55 + // If called via REST API, we need to register later in the lifecycle
56 + if ( ( new Host() )->is_wpcom_platform() && ! Request::is_frontend() ) {
57 + add_action(
58 + 'restapi_theme_init',
59 + function () {
60 + Jetpack_Subscription_Site::init()->handle_subscriber_login_block_placements();
61 + }
62 + );
63 + } else {
64 + Jetpack_Subscription_Site::init()->handle_subscriber_login_block_placements();
65 + }
40 66 }
41 67 add_action( 'init', __NAMESPACE__ . '\register_block' );
42 68
43 69 /**
44 - * Logs the subscriber out by clearing out the premium content cookie.
45 - *
46 - * @return void
47 - */
48 -function subscriber_logout() {
49 - Abstract_Token_Subscription_Service::clear_token_cookie();
50 -}
51 -
52 -/**
53 70 * Returns current URL.
54 71 *
55 72 * @return string
56 73 */
@@ -71,17 +88,21 @@
71 88 */
72 89 function get_subscriber_login_url( $redirect ) {
73 90 $redirect = ! empty( $redirect ) ? $redirect : get_site_url();
74 91
75 - // Taken from projects/plugins/jetpack/extensions/blocks/subscriptions/subscriptions.php and simplified a bit
76 92 if ( ( new Host() )->is_wpcom_simple() ) {
77 93 // On WPCOM we will redirect immediately
78 94 return wpcom_logmein_redirect_url( $redirect, false, null, 'link', get_current_blog_id() );
79 95 }
80 96
81 - // On self-hosted we will save and hide the token
97 + // On self-hosted we will save and hide the token.
98 + // rawurlencode the redirect before nesting it: it is already percent-encoded
99 + // (e.g. an emoji or non-ASCII slug comes through as %F0%9F%8C%91), and add_query_arg
100 + // does not encode the values it inserts. Without this extra layer the value is
101 + // over-decoded to raw bytes by the time it reaches the subscribers/auth endpoint,
102 + // which strips it and 404s. See NL-273.
82 103 $redirect_url = get_site_url() . '/wp-json/jetpack/v4/subscribers/auth';
83 - $redirect_url = add_query_arg( 'redirect_url', $redirect, $redirect_url );
104 + $redirect_url = add_query_arg( 'redirect_url', rawurlencode( $redirect ), $redirect_url );
84 105
85 106 return add_query_arg(
86 107 array(
87 108 'site_id' => intval( Jetpack_Options::get_option( 'id' ) ),
@@ -86,19 +107,22 @@
86 107 array(
87 108 'site_id' => intval( Jetpack_Options::get_option( 'id' ) ),
88 109 'redirect_url' => rawurlencode( $redirect_url ),
89 110 ),
90 - 'https://subscribe.wordpress.com/memberships/jwt'
111 + 'https://subscribe.wordpress.com/memberships/jwt/'
91 112 );
92 113 }
93 114
94 115 /**
95 - * Determines whether the current visitor is a logged in user or a subscriber.
116 + * Determines whether the visitor has a subscriber session for the login UI.
96 117 *
118 + * WordPress sessions count on Simple; other hosts require the subscriber cookie.
119 + * Content access validates the token separately.
120 + *
97 121 * @return bool
98 122 */
99 123 function is_subscriber_logged_in() {
100 - return is_user_logged_in() || Abstract_Token_Subscription_Service::has_token_from_cookie();
124 + return ( ( new Host() )->is_wpcom_simple() && is_user_logged_in() ) || Abstract_Token_Subscription_Service::has_token_from_cookie();
101 125 }
102 126
103 127 /**
104 128 * Renders Subscriber Login block.
@@ -113,9 +137,10 @@
113 137 $block_template = '<div %1$s><a href="%2$s">%3$s</a></div>';
114 138 $redirect_url = ! empty( $attributes['redirectToCurrent'] ) ? get_current_url() : get_site_url();
115 139 $log_in_label = ! empty( $attributes['logInLabel'] ) ? sanitize_text_field( $attributes['logInLabel'] ) : esc_html__( 'Log in', 'jetpack' );
116 140 $log_out_label = ! empty( $attributes['logOutLabel'] ) ? sanitize_text_field( $attributes['logOutLabel'] ) : esc_html__( 'Log out', 'jetpack' );
117 - $manage_subscriptions_label = ! empty( $attributes['manageSubscriptionsLabel'] ) ? sanitize_text_field( $attributes['manageSubscriptionsLabel'] ) : esc_html__( 'Manage subscriptions', 'jetpack' );
141 + $show_manage_link = ! empty( $attributes['showManageSubscriptionsLink'] );
142 + $manage_subscriptions_label = ! empty( $attributes['manageSubscriptionsLabel'] ) ? sanitize_text_field( $attributes['manageSubscriptionsLabel'] ) : esc_html__( 'Manage subscription', 'jetpack' );
118 143
119 144 if ( ! is_subscriber_logged_in() ) {
120 145 return sprintf(
121 146 $block_template,
@@ -124,13 +149,13 @@
124 149 $log_in_label
125 150 );
126 151 }
127 152
128 - if ( Jetpack_Memberships::is_current_user_subscribed() ) {
153 + if ( $show_manage_link && Jetpack_Memberships::is_current_user_subscribed() ) {
129 154 return sprintf(
130 155 $block_template,
131 156 get_block_wrapper_attributes(),
132 - 'https://wordpress.com/read/subscriptions',
157 + 'https://wordpress.com/reader/site/subscription/' . Jetpack_Memberships::get_blog_id(),
133 158 $manage_subscriptions_label
134 159 );
135 160 }
136 161