PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-connection/src/class-initial-state.php +88 -13 13.1.5 → 16.3-beta View file →
@@ -21,32 +21,107 @@
21 21 */
22 22 private static function get_data() {
23 23 global $wp_version;
24 24
25 - $status = new Status();
25 + $status = new Status();
26 + $manager = new Manager();
27 + $can_manage_connection = current_user_can( 'jetpack_connect' );
26 28
29 + // Only expose the owner's identity to users who can act on connection issues:
30 + // this state is printed for any logged-in user loading connection scripts
31 + // (e.g. contributors in the editor). The owner is derived from the master_user
32 + // option rather than the token-dependent Manager::get_connection_owner(): that
33 + // method returns false exactly when the owner's token is broken, which is the
34 + // scenario connection-error UIs need this data for (and it re-reports
35 + // invalid_connection_owner as a side effect). Unlike
36 + // userConnectionData.connectionOwner (the *connected* owner), this field
37 + // identifies who holds ownership regardless of token health.
38 + $connection_owner = null;
39 + if ( $can_manage_connection ) {
40 + $owner_id = (int) \Jetpack_Options::get_option( 'master_user' );
41 + $owner = $owner_id > 0 ? get_userdata( $owner_id ) : false;
42 +
43 + if ( $owner instanceof \WP_User ) {
44 + $connection_owner = array(
45 + 'id' => $owner_id,
46 + 'displayName' => $owner->display_name,
47 + );
48 + }
49 + }
50 +
51 + // Behind the same gate: on an anchored site, resolving the owner can cost a WordPress.com lookup.
52 + $has_protected_owner = null;
53 + $requires_protected_owner = null;
54 + $use_default_protected_owner_ui = null;
55 + if ( $can_manage_connection ) {
56 + $has_protected_owner = $manager->has_protected_owner();
57 + $requires_protected_owner = $manager->requires_protected_owner();
58 +
59 + /**
60 + * Filters whether the connection package renders its default protected owner UI.
61 + *
62 + * Return `false` from a consumer that renders its own confirmation flow.
63 + *
64 + * @since 9.7.0
65 + *
66 + * @param bool $use_default_ui Whether to render the default UI. Default true.
67 + */
68 + $use_default_protected_owner_ui = (bool) apply_filters( 'jetpack_connection_protected_owner_default_ui', true );
69 + }
70 +
27 71 return array(
28 - 'apiRoot' => esc_url_raw( rest_url() ),
29 - 'apiNonce' => wp_create_nonce( 'wp_rest' ),
30 - 'registrationNonce' => wp_create_nonce( 'jetpack-registration-nonce' ),
31 - 'connectionStatus' => REST_Connector::connection_status( false ),
32 - 'userConnectionData' => REST_Connector::get_user_connection_data( false ),
33 - 'connectedPlugins' => REST_Connector::get_connection_plugins( false ),
34 - 'wpVersion' => $wp_version,
35 - 'siteSuffix' => $status->get_site_suffix(),
36 - 'connectionErrors' => Error_Handler::get_instance()->get_verified_errors(),
37 - 'isOfflineMode' => $status->is_offline_mode(),
38 - 'calypsoEnv' => ( new Status\Host() )->get_calypso_env(),
72 + 'apiRoot' => esc_url_raw( rest_url() ),
73 + 'apiNonce' => wp_create_nonce( 'wp_rest' ),
74 + 'registrationNonce' => wp_create_nonce( 'jetpack-registration-nonce' ),
75 + 'connectionStatus' => REST_Connector::connection_status( false ),
76 + 'userConnectionData' => REST_Connector::get_user_connection_data( false ),
77 + 'connectedPlugins' => REST_Connector::get_connection_plugins( false ),
78 + 'wpVersion' => $wp_version,
79 + 'siteSuffix' => $status->get_site_suffix(),
80 + 'connectionErrors' => Error_Handler::get_instance()->get_displayable_errors(),
81 + 'isOfflineMode' => $status->is_offline_mode(),
82 + 'calypsoEnv' => ( new Status\Host() )->get_calypso_env(),
83 + 'isOwnershipTransferable' => $manager->is_ownership_transferable(),
84 + 'connectionOwner' => $connection_owner,
85 + 'hasProtectedOwner' => $has_protected_owner,
86 + 'requiresProtectedOwner' => $requires_protected_owner,
87 + 'useDefaultProtectedOwnerUi' => $use_default_protected_owner_ui,
39 88 );
40 89 }
41 90
42 91 /**
92 + * Set the connection script data.
93 + *
94 + * @param array $data The script data.
95 + */
96 + public static function set_connection_script_data( $data ) {
97 +
98 + $data['connection'] = self::get_data();
99 +
100 + if ( empty( $data['site']['wpcom']['blog_id'] ) ) {
101 + $data['site']['wpcom']['blog_id'] = absint( \Jetpack_Options::get_option( 'id', 0 ) );
102 + }
103 +
104 + return $data;
105 + }
106 +
107 + /**
43 108 * Render the initial state into a JavaScript variable.
44 109 *
45 110 * @return string
46 111 */
47 112 public static function render() {
48 - return 'var JP_CONNECTION_INITIAL_STATE; typeof JP_CONNECTION_INITIAL_STATE === "object" || (JP_CONNECTION_INITIAL_STATE = JSON.parse(decodeURIComponent("' . rawurlencode( wp_json_encode( self::get_data() ) ) . '")));';
113 + /*
114 + * `window.jpTracksContext` is an intentionally minimal, Tracks-specific global used by the
115 + * @automattic/jetpack-analytics package to read `blog_id` at event-fire time. It exists
116 + * separately from `window.JetpackScriptData` because the analytics package is consumed in
117 + * contexts (e.g. Boost frontend) where `JetpackScriptData` is not reliably available, and
118 + * coupling the analytics package to that schema would widen its surface unnecessarily.
119 + * When both are present, `JetpackScriptData.site.wpcom.blog_id` is populated via
120 + * `set_connection_script_data()` above for other consumers.
121 + */
122 + return 'var JP_CONNECTION_INITIAL_STATE; typeof JP_CONNECTION_INITIAL_STATE === "object" || (JP_CONNECTION_INITIAL_STATE = ' . wp_json_encode( self::get_data(), JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ) . ');'
123 + . sprintf( 'window.jpTracksContext = window.jpTracksContext || {}; window.jpTracksContext.blog_id = %s;', absint( \Jetpack_Options::get_option( 'id', 0 ) ) );
49 124 }
50 125
51 126 /**
52 127 * Render the initial state using an inline script.