← All changes
|
extensions/blocks/subscriber-login/subscriber-login.php
+19
-6
13.4.5
→
16.3-beta
View file →
| @@ -11,13 +11,18 @@ | ||
| 11 | 11 | |
| 12 | 12 | use Automattic\Jetpack\Blocks; |
| 13 | 13 | use Automattic\Jetpack\Extensions\Premium_Content\Subscription_Service\Abstract_Token_Subscription_Service; |
| 14 | 14 | use Automattic\Jetpack\Status\Host; |
| 15 | +use Automattic\Jetpack\Status\Request; | |
| 15 | 16 | use Jetpack; |
| 16 | 17 | use Jetpack_Gutenberg; |
| 17 | 18 | use Jetpack_Memberships; |
| 18 | 19 | use Jetpack_Options; |
| 19 | 20 | |
| 21 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 22 | + exit( 0 ); | |
| 23 | +} | |
| 24 | + | |
| 20 | 25 | require_once __DIR__ . '/class-jetpack-subscription-site.php'; |
| 21 | 26 | |
| 22 | 27 | /** |
| 23 | 28 | * Registers the block for use in Gutenberg |
| @@ -47,9 +52,9 @@ | ||
| 47 | 52 | } |
| 48 | 53 | ); |
| 49 | 54 | |
| 50 | 55 | // If called via REST API, we need to register later in the lifecycle |
| 51 | - if ( ( new Host() )->is_wpcom_platform() && ! jetpack_is_frontend() ) { | |
| 56 | + if ( ( new Host() )->is_wpcom_platform() && ! Request::is_frontend() ) { | |
| 52 | 57 | add_action( |
| 53 | 58 | 'restapi_theme_init', |
| 54 | 59 | function () { |
| 55 | 60 | Jetpack_Subscription_Site::init()->handle_subscriber_login_block_placements(); |
| @@ -88,11 +93,16 @@ | ||
| 88 | 93 | // On WPCOM we will redirect immediately |
| 89 | 94 | return wpcom_logmein_redirect_url( $redirect, false, null, 'link', get_current_blog_id() ); |
| 90 | 95 | } |
| 91 | 96 | |
| 92 | - // On self-hosted we will save and hide the token | |
| 97 | + // On self-hosted we will save and hide the token. | |
| 98 | + // rawurlencode the redirect before nesting it: it is already percent-encoded | |
| 99 | + // (e.g. an emoji or non-ASCII slug comes through as %F0%9F%8C%91), and add_query_arg | |
| 100 | + // does not encode the values it inserts. Without this extra layer the value is | |
| 101 | + // over-decoded to raw bytes by the time it reaches the subscribers/auth endpoint, | |
| 102 | + // which strips it and 404s. See NL-273. | |
| 93 | 103 | $redirect_url = get_site_url() . '/wp-json/jetpack/v4/subscribers/auth'; |
| 94 | - $redirect_url = add_query_arg( 'redirect_url', $redirect, $redirect_url ); | |
| 104 | + $redirect_url = add_query_arg( 'redirect_url', rawurlencode( $redirect ), $redirect_url ); | |
| 95 | 105 | |
| 96 | 106 | return add_query_arg( |
| 97 | 107 | array( |
| 98 | 108 | 'site_id' => intval( Jetpack_Options::get_option( 'id' ) ), |
| @@ -102,14 +112,17 @@ | ||
| 102 | 112 | ); |
| 103 | 113 | } |
| 104 | 114 | |
| 105 | 115 | /** |
| 106 | - * Determines whether the current visitor is a logged in user or a subscriber. | |
| 116 | + * Determines whether the visitor has a subscriber session for the login UI. | |
| 107 | 117 | * |
| 118 | + * WordPress sessions count on Simple; other hosts require the subscriber cookie. | |
| 119 | + * Content access validates the token separately. | |
| 120 | + * | |
| 108 | 121 | * @return bool |
| 109 | 122 | */ |
| 110 | 123 | function is_subscriber_logged_in() { |
| 111 | - return is_user_logged_in() || Abstract_Token_Subscription_Service::has_token_from_cookie(); | |
| 124 | + return ( ( new Host() )->is_wpcom_simple() && is_user_logged_in() ) || Abstract_Token_Subscription_Service::has_token_from_cookie(); | |
| 112 | 125 | } |
| 113 | 126 | |
| 114 | 127 | /** |
| 115 | 128 | * Renders Subscriber Login block. |
| @@ -140,9 +153,9 @@ | ||
| 140 | 153 | if ( $show_manage_link && Jetpack_Memberships::is_current_user_subscribed() ) { |
| 141 | 154 | return sprintf( |
| 142 | 155 | $block_template, |
| 143 | 156 | get_block_wrapper_attributes(), |
| 144 | - 'https://wordpress.com/read/site/subscription/' . Jetpack_Memberships::get_blog_id(), | |
| 157 | + 'https://wordpress.com/reader/site/subscription/' . Jetpack_Memberships::get_blog_id(), | |
| 145 | 158 | $manage_subscriptions_label |
| 146 | 159 | ); |
| 147 | 160 | } |
| 148 | 161 | |