PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | modules/wordads/php/class-wordads-consent-management-provider.php +8 -2 13.3.3 → 16.3-beta View file →
@@ -6,8 +6,12 @@
6 6 */
7 7
8 8 use Automattic\Jetpack\Assets;
9 9
10 +if ( ! defined( 'ABSPATH' ) ) {
11 + exit( 0 );
12 +}
13 +
10 14 /**
11 15 * Class WordAds_Consent_Management_Provider
12 16 *
13 17 * This is an integration with the GDPR Consent Management Provider
@@ -50,9 +54,10 @@
50 54 public static function handle_set_consent_request() {
51 55
52 56 // phpcs:disable WordPress.Security.NonceVerification.Missing
53 57 if ( ! isset( $_POST['consent'] ) ) {
54 - wp_send_json_error();
58 + // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
59 + wp_send_json_error( null, null, JSON_UNESCAPED_SLASHES );
55 60 }
56 61
57 62 // TODO: Is there better sanitizing we can do here?
58 63 $consent = trim( wp_unslash( $_POST['consent'] ) ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
@@ -58,9 +63,10 @@
58 63 $consent = trim( wp_unslash( $_POST['consent'] ) ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
59 64
60 65 setcookie( self::COOKIE_NAME, $consent, time() + YEAR_IN_SECONDS, '/', self::get_cookie_domain(), is_ssl(), false ); // phpcs:ignore Jetpack.Functions.SetCookie -- Client side CMP needs to be able to read this value.
61 66
62 - wp_send_json_success( true );
67 + // @phan-suppress-next-line PhanTypeMismatchArgumentProbablyReal -- It takes null, but its phpdoc only says int.
68 + wp_send_json_success( true, null, JSON_UNESCAPED_SLASHES );
63 69
64 70 // phpcs:enable WordPress.Security.NonceVerification.Missing
65 71 }
66 72