PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-connection/src/class-webhooks.php +20 -2 13.3.3 → 16.3-beta View file →
@@ -100,8 +100,16 @@
100 100 */
101 101 public function handle_authorize() {
102 102 if ( $this->connection->is_connected() && $this->connection->is_user_connected() ) {
103 103 $redirect_url = apply_filters( 'jetpack_client_authorize_already_authorized_url', admin_url() );
104 +
105 + if ( ! empty( $_GET['redirect'] ) ) {
106 + $explicit = esc_url_raw( wp_unslash( $_GET['redirect'] ) );
107 + if ( wp_validate_redirect( $explicit ) ) {
108 + $redirect_url = $explicit;
109 + }
110 + }
111 +
104 112 wp_safe_redirect( $redirect_url );
105 113
106 114 return;
107 115 }
@@ -106,9 +114,9 @@
106 114 return;
107 115 }
108 116 do_action( 'jetpack_client_authorize_processing' );
109 117
110 - $data = stripslashes_deep( $_GET );
118 + $data = stripslashes_deep( $_GET ); // We need all request data under the context of an authorization request.
111 119 $data['auth_type'] = 'client';
112 120 $roles = new Roles();
113 121 $role = $roles->translate_current_user_to_role();
114 122 $redirect = isset( $data['redirect'] ) ? esc_url_raw( (string) $data['redirect'] ) : '';
@@ -162,9 +170,9 @@
162 170 *
163 171 * @return never
164 172 */
165 173 protected function do_exit() {
166 - exit;
174 + exit( 0 );
167 175 }
168 176
169 177 /**
170 178 * Handle the `connect_url_redirect` action,
@@ -175,8 +183,10 @@
175 183 public function handle_connect_url_redirect() {
176 184 // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes.
177 185 $from = ! empty( $_GET['from'] ) ? sanitize_text_field( wp_unslash( $_GET['from'] ) ) : 'iframe';
178 186
187 + $skip_pricing = filter_input( INPUT_GET, 'skip_pricing', FILTER_VALIDATE_BOOLEAN );
188 +
179 189 // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- no site changes, sanitization happens in get_authorization_url()
180 190 $redirect = ! empty( $_GET['redirect_after_auth'] ) ? wp_unslash( $_GET['redirect_after_auth'] ) : false;
181 191
182 192 add_filter( 'allowed_redirect_hosts', array( Host::class, 'allow_wpcom_environments' ) );
@@ -187,8 +197,12 @@
187 197 }
188 198
189 199 $connect_url = add_query_arg( 'from', $from, $this->connection->get_authorization_url( null, $redirect ) );
190 200
201 + if ( $skip_pricing ) {
202 + $connect_url = add_query_arg( 'skip_pricing', '1', $connect_url );
203 + }
204 +
191 205 // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes.
192 206 if ( isset( $_GET['notes_iframe'] ) ) {
193 207 $connect_url .= '&notes_iframe';
194 208 }
@@ -198,8 +212,12 @@
198 212 ( new CookieState() )->state( 'message', 'already_authorized' );
199 213 wp_safe_redirect( $redirect );
200 214 $this->do_exit();
201 215 } else {
216 + if ( 'connect-after-checkout' === $from && $redirect ) {
217 + wp_safe_redirect( $redirect );
218 + $this->do_exit();
219 + }
202 220 $connect_url = add_query_arg(
203 221 array(
204 222 'from' => $from,
205 223 'already_authorized' => true,