← All changes
|
jetpack_vendor/automattic/jetpack-connection/src/class-webhooks.php
+20
-2
13.3.3
→
16.3-beta
View file →
| @@ -100,8 +100,16 @@ | ||
| 100 | 100 | */ |
| 101 | 101 | public function handle_authorize() { |
| 102 | 102 | if ( $this->connection->is_connected() && $this->connection->is_user_connected() ) { |
| 103 | 103 | $redirect_url = apply_filters( 'jetpack_client_authorize_already_authorized_url', admin_url() ); |
| 104 | + | |
| 105 | + if ( ! empty( $_GET['redirect'] ) ) { | |
| 106 | + $explicit = esc_url_raw( wp_unslash( $_GET['redirect'] ) ); | |
| 107 | + if ( wp_validate_redirect( $explicit ) ) { | |
| 108 | + $redirect_url = $explicit; | |
| 109 | + } | |
| 110 | + } | |
| 111 | + | |
| 104 | 112 | wp_safe_redirect( $redirect_url ); |
| 105 | 113 | |
| 106 | 114 | return; |
| 107 | 115 | } |
| @@ -106,9 +114,9 @@ | ||
| 106 | 114 | return; |
| 107 | 115 | } |
| 108 | 116 | do_action( 'jetpack_client_authorize_processing' ); |
| 109 | 117 | |
| 110 | - $data = stripslashes_deep( $_GET ); | |
| 118 | + $data = stripslashes_deep( $_GET ); // We need all request data under the context of an authorization request. | |
| 111 | 119 | $data['auth_type'] = 'client'; |
| 112 | 120 | $roles = new Roles(); |
| 113 | 121 | $role = $roles->translate_current_user_to_role(); |
| 114 | 122 | $redirect = isset( $data['redirect'] ) ? esc_url_raw( (string) $data['redirect'] ) : ''; |
| @@ -162,9 +170,9 @@ | ||
| 162 | 170 | * |
| 163 | 171 | * @return never |
| 164 | 172 | */ |
| 165 | 173 | protected function do_exit() { |
| 166 | - exit; | |
| 174 | + exit( 0 ); | |
| 167 | 175 | } |
| 168 | 176 | |
| 169 | 177 | /** |
| 170 | 178 | * Handle the `connect_url_redirect` action, |
| @@ -175,8 +183,10 @@ | ||
| 175 | 183 | public function handle_connect_url_redirect() { |
| 176 | 184 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes. |
| 177 | 185 | $from = ! empty( $_GET['from'] ) ? sanitize_text_field( wp_unslash( $_GET['from'] ) ) : 'iframe'; |
| 178 | 186 | |
| 187 | + $skip_pricing = filter_input( INPUT_GET, 'skip_pricing', FILTER_VALIDATE_BOOLEAN ); | |
| 188 | + | |
| 179 | 189 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- no site changes, sanitization happens in get_authorization_url() |
| 180 | 190 | $redirect = ! empty( $_GET['redirect_after_auth'] ) ? wp_unslash( $_GET['redirect_after_auth'] ) : false; |
| 181 | 191 | |
| 182 | 192 | add_filter( 'allowed_redirect_hosts', array( Host::class, 'allow_wpcom_environments' ) ); |
| @@ -187,8 +197,12 @@ | ||
| 187 | 197 | } |
| 188 | 198 | |
| 189 | 199 | $connect_url = add_query_arg( 'from', $from, $this->connection->get_authorization_url( null, $redirect ) ); |
| 190 | 200 | |
| 201 | + if ( $skip_pricing ) { | |
| 202 | + $connect_url = add_query_arg( 'skip_pricing', '1', $connect_url ); | |
| 203 | + } | |
| 204 | + | |
| 191 | 205 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes. |
| 192 | 206 | if ( isset( $_GET['notes_iframe'] ) ) { |
| 193 | 207 | $connect_url .= '¬es_iframe'; |
| 194 | 208 | } |
| @@ -198,8 +212,12 @@ | ||
| 198 | 212 | ( new CookieState() )->state( 'message', 'already_authorized' ); |
| 199 | 213 | wp_safe_redirect( $redirect ); |
| 200 | 214 | $this->do_exit(); |
| 201 | 215 | } else { |
| 216 | + if ( 'connect-after-checkout' === $from && $redirect ) { | |
| 217 | + wp_safe_redirect( $redirect ); | |
| 218 | + $this->do_exit(); | |
| 219 | + } | |
| 202 | 220 | $connect_url = add_query_arg( |
| 203 | 221 | array( |
| 204 | 222 | 'from' => $from, |
| 205 | 223 | 'already_authorized' => true, |