PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-publicize/src/class-publicize.php +70 -138 16.2 → 16.3-beta View file →
@@ -7,9 +7,8 @@
7 7
8 8 namespace Automattic\Jetpack\Publicize;
9 9
10 10 use Automattic\Jetpack\Connection\Client;
11 -use Automattic\Jetpack\Connection\Tokens;
12 11 use Jetpack_IXR_Client;
13 12 use Jetpack_Options;
14 13 use WP_Error;
15 14 use WP_Post;
@@ -42,12 +41,8 @@
42 41 parent::__construct();
43 42
44 43 add_filter( 'jetpack_xmlrpc_unauthenticated_methods', array( $this, 'register_update_publicize_connections_xmlrpc_method' ) );
45 44
46 - add_action( 'load-settings_page_sharing', array( $this, 'admin_page_load' ), 9 );
47 -
48 - add_action( 'load-settings_page_sharing', array( $this, 'force_user_connection' ) );
49 -
50 45 add_filter( 'jetpack_published_post_flags', array( $this, 'set_post_flags' ), 10, 2 );
51 46
52 47 add_action( 'wp_insert_post', array( $this, 'save_publicized' ), 11, 2 );
53 48
@@ -62,70 +57,51 @@
62 57 }
63 58
64 59 /**
65 60 * Force user connection before showing the Publicize UI.
61 + *
62 + * @deprecated 0.88.0 Settings > Sharing no longer hosts the Publicize UI.
63 + *
64 + * @return void
66 65 */
67 66 public function force_user_connection() {
68 - global $current_user;
69 -
70 - $user_token = ( new Tokens() )->get_access_token( $current_user->ID );
71 - $is_user_connected = $user_token && ! is_wp_error( $user_token );
72 -
73 - // If the user is already connected via Jetpack, then we're good.
74 - if ( $is_user_connected ) {
75 - return;
76 - }
77 -
78 - // If they're not connected, then remove the Publicize UI and tell them they need to connect first.
79 - global $publicize_ui;
80 - remove_action( 'pre_admin_screen_sharing', array( $publicize_ui, 'admin_page' ) );
81 -
82 - // Do we really need `admin_styles`? With the new admin UI, it's breaking some bits.
83 - // Jetpack::init()->admin_styles();.
84 - add_action( 'pre_admin_screen_sharing', array( $this, 'admin_page_warning' ), 1 );
67 + _deprecated_function( __METHOD__, 'publicize-0.88.0' );
85 68 }
86 69
87 70 /**
88 71 * Show a warning when Publicize does not have a connection.
72 + *
73 + * @deprecated 0.88.0 Settings > Sharing no longer hosts the Publicize UI.
74 + *
75 + * @return void
89 76 */
90 77 public function admin_page_warning() {
91 - $jetpack = \Jetpack::init();
92 - $blog_name = get_bloginfo( 'blogname' );
93 - if ( empty( $blog_name ) ) {
94 - $blog_name = home_url( '/' );
95 - }
78 + _deprecated_function( __METHOD__, 'publicize-0.88.0' );
79 + }
96 80
97 - ?>
98 - <div id="message" class="updated jetpack-message jp-connect">
99 - <div class="jetpack-wrap-container">
100 - <div class="jetpack-text-container">
101 - <p>
102 - <?php
103 - printf(
104 - /* translators: %s is the name of the blog */
105 - esc_html( wptexturize( __( "To use Jetpack Social, you'll need to link your %s account to your WordPress.com account using the link below.", 'jetpack-publicize-pkg' ) ) ),
106 - '<strong>' . esc_html( $blog_name ) . '</strong>'
107 - );
108 - ?>
109 - </p>
110 - <p><?php echo esc_html( wptexturize( __( "If you don't have a WordPress.com account yet, you can sign up for free in just a few seconds.", 'jetpack-publicize-pkg' ) ) ); ?></p>
111 - </div>
112 - <div class="jetpack-install-container">
113 - <p class="submit"><a
114 - href="<?php echo esc_url( $jetpack->build_connect_url( false, menu_page_url( 'sharing', false ) ) ); ?>"
115 - class="button-connector"
116 - id="wpcom-connect"><?php esc_html_e( 'Link account with WordPress.com', 'jetpack-publicize-pkg' ); ?></a>
117 - </p>
118 - <p class="jetpack-install-blurb">
119 - <?php jetpack_render_tos_blurb(); ?>
120 - </p>
121 - </div>
122 - </div>
123 - </div>
124 - <?php
81 + /**
82 + * Show error on settings page if applicable.
83 + *
84 + * @deprecated 0.88.0 Settings > Sharing no longer hosts connection errors.
85 + *
86 + * @return void
87 + */
88 + public function admin_page_load() {
89 + _deprecated_function( __METHOD__, 'publicize-0.88.0' );
125 90 }
126 91
127 92 /**
93 + * Display an error message.
94 + *
95 + * @deprecated 0.88.0 Settings > Sharing no longer hosts connection errors.
96 + *
97 + * @return void
98 + */
99 + public function display_connection_error() {
100 + _deprecated_function( __METHOD__, 'publicize-0.88.0' );
101 + }
102 +
103 + /**
128 104 * Remove a Publicize Connection.
129 105 *
130 106 * @param string $service_name 'facebook', 'twitter', etc.
131 107 * @param string $connection_id Connection ID.
@@ -145,8 +121,10 @@
145 121 * @return true
146 122 */
147 123 public function receive_updated_publicize_connections( $publicize_connections ) {
148 124
125 + $publicize_connections = self::filter_usable_connections( $publicize_connections );
126 +
149 127 // Populate the cache with the new data.
150 128 Connections::get_all( array( 'ignore_cache' => true ) );
151 129
152 130 $expiry = 3600 * 4;
@@ -161,10 +139,47 @@
161 139 return true;
162 140 }
163 141
164 142 /**
143 + * Drop connections we cannot attribute to a user.
144 + *
145 + * A missing user ID reads as "shared with everyone" in is_global_connection(), so such a
146 + * connection would be exposed to every user on the site. User ID 0 is a genuine shared
147 + * connection and is kept; unknown fields pass through, as WPCOM adds to this payload.
148 + *
149 + * @param mixed $publicize_connections Connections, keyed by service name.
150 + * @return array
151 + */
152 + private static function filter_usable_connections( $publicize_connections ) {
153 + // An empty payload is valid - it means the site has no connections left.
154 + if ( ! is_array( $publicize_connections ) ) {
155 + return array();
156 + }
157 +
158 + $usable_connections = array();
159 +
160 + foreach ( $publicize_connections as $service_name => $connections_for_service ) {
161 + if ( ! is_array( $connections_for_service ) ) {
162 + continue;
163 + }
164 +
165 + foreach ( $connections_for_service as $id => $connection ) {
166 + if ( ! isset( $connection['connection_data']['user_id'] ) || ! is_numeric( $connection['connection_data']['user_id'] ) ) {
167 + continue;
168 + }
169 +
170 + $usable_connections[ $service_name ][ $id ] = $connection;
171 + }
172 + }
173 +
174 + return $usable_connections;
175 + }
176 +
177 + /**
165 178 * Add method to update Publicize connections.
166 179 *
180 + * @todo Kept as a fallback for the jetpack/v4/publicize/connections/sync REST endpoint that replaced it; remove after a few releases (CONNECT-446).
181 + *
167 182 * @param array $methods Array of registered methods.
168 183 * @return array
169 184 */
170 185 public function register_update_publicize_connections_xmlrpc_method( $methods ) {
@@ -326,91 +341,8 @@
326 341 */
327 342 public function get_connection_meta( $connection ) {
328 343 $connection['user_id'] = $connection['connection_data']['user_id']; // Allows for shared connections.
329 344 return $connection;
330 - }
331 -
332 - /**
333 - * Show error on settings page if applicable.
334 - */
335 - public function admin_page_load() {
336 - $action = isset( $_GET['action'] ) ? sanitize_text_field( wp_unslash( $_GET['action'] ) ) : null; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
337 -
338 - if ( 'error' === $action ) {
339 - add_action( 'pre_admin_screen_sharing', array( $this, 'display_connection_error' ), 9 );
340 - }
341 - }
342 -
343 - /**
344 - * Display an error message.
345 - */
346 - public function display_connection_error() {
347 - $code = false;
348 - // phpcs:disable WordPress.Security.NonceVerification.Recommended
349 - $service = isset( $_GET['service'] ) ? sanitize_text_field( wp_unslash( $_GET['service'] ) ) : null;
350 - $publicize_error = isset( $_GET['publicize_error'] ) ? sanitize_text_field( wp_unslash( $_GET['publicize_error'] ) ) : null;
351 - // phpcs:enable WordPress.Security.NonceVerification.Recommended
352 -
353 - if ( $service ) {
354 - /* translators: %s is the name of the Jetpack Social service (e.g. Facebook, Twitter) */
355 - $error = sprintf( __( 'There was a problem connecting to %s to create an authorized connection. Please try again in a moment.', 'jetpack-publicize-pkg' ), self::get_service_label( $service ) );
356 - } elseif ( $publicize_error ) {
357 - $code = strtolower( $publicize_error );
358 - switch ( $code ) {
359 - case '400':
360 - $error = __( 'An invalid request was made. This normally means that something intercepted or corrupted the request from your server to the Jetpack Server. Try again and see if it works this time.', 'jetpack-publicize-pkg' );
361 - break;
362 - case 'secret_mismatch':
363 - $error = __( 'We could not verify that your server is making an authorized request. Please try again, and make sure there is nothing interfering with requests from your server to the Jetpack Server.', 'jetpack-publicize-pkg' );
364 - break;
365 - case 'empty_blog_id':
366 - $error = __( 'No blog_id was included in your request. Please try disconnecting Jetpack from WordPress.com and then reconnecting it. Once you have done that, try connecting Jetpack Social again.', 'jetpack-publicize-pkg' );
367 - break;
368 - case 'empty_state':
369 - /* translators: %s is the URL of the Jetpack admin page */
370 - $error = sprintf( __( 'No user information was included in your request. Please make sure that your user account has connected to Jetpack. Connect your user account by going to the <a href="%s">Jetpack page</a> within wp-admin.', 'jetpack-publicize-pkg' ), \Jetpack::admin_url() );
371 - break;
372 - default:
373 - $error = __( 'Something which should never happen, happened. Sorry about that. If you try again, maybe it will work.', 'jetpack-publicize-pkg' );
374 - break;
375 - }
376 - } else {
377 - $error = __( 'There was a problem connecting with Jetpack Social. Please try again in a moment.', 'jetpack-publicize-pkg' );
378 - }
379 - // Using the same formatting/style as Jetpack::admin_notices() error.
380 - ?>
381 - <div id="message" class="jetpack-message jetpack-err">
382 - <div class="squeezer">
383 - <h2>
384 - <?php
385 - echo wp_kses(
386 - $error,
387 - array(
388 - 'a' => array(
389 - 'href' => true,
390 - ),
391 - 'code' => true,
392 - 'strong' => true,
393 - 'br' => true,
394 - 'b' => true,
395 - )
396 - );
397 - ?>
398 - </h2>
399 - <?php if ( $code ) : ?>
400 - <p>
401 - <?php
402 - printf(
403 - /* translators: %s is the name of the error */
404 - esc_html__( 'Error code: %s', 'jetpack-publicize-pkg' ),
405 - esc_html( stripslashes( $code ) )
406 - );
407 - ?>
408 - </p>
409 - <?php endif; ?>
410 - </div>
411 - </div>
412 - <?php
413 345 }
414 346
415 347 /**
416 348 * Show a message that the connection has been removed.