← All changes
|
jetpack_vendor/automattic/woocommerce-analytics/src/API/class-wc-analytics-tracking-proxy.php
+20
-3
16.3-a.5
→
16.3-beta
View file →
| @@ -40,9 +40,11 @@ | ||
| 40 | 40 | array( |
| 41 | 41 | array( |
| 42 | 42 | 'methods' => \WP_REST_Server::CREATABLE, |
| 43 | 43 | 'callback' => array( $this, 'track_events' ), |
| 44 | - 'permission_callback' => '__return_true', // no need to check permissions | |
| 44 | + // Unauthenticated front-end event endpoint. track_events() validates consent | |
| 45 | + // and records events without client-supplied server-owned properties. | |
| 46 | + 'permission_callback' => '__return_true', | |
| 45 | 47 | 'schema' => array( $this, 'get_public_item_schema' ), |
| 46 | 48 | ), |
| 47 | 49 | ) |
| 48 | 50 | ); |
| @@ -54,8 +56,18 @@ | ||
| 54 | 56 | * @param \WP_REST_Request $request Full data about the request. |
| 55 | 57 | * @return \WP_REST_Response|\WP_Error Response object on success, or WP_Error object on failure. |
| 56 | 58 | */ |
| 57 | 59 | public function track_events( $request ) { |
| 60 | + // Cached pages can still post here after proxy tracking is disabled; return a | |
| 61 | + // visible error instead of losing the event to a 404. | |
| 62 | + if ( ! Features::is_proxy_tracking_enabled() ) { | |
| 63 | + return new \WP_Error( | |
| 64 | + 'proxy_tracking_disabled', | |
| 65 | + 'Proxy tracking is not enabled on this site.', | |
| 66 | + array( 'status' => 403 ) | |
| 67 | + ); | |
| 68 | + } | |
| 69 | + | |
| 58 | 70 | // Check consent before processing any events |
| 59 | 71 | if ( ! Consent_Manager::has_analytics_consent() ) { |
| 60 | 72 | return new \WP_REST_Response( |
| 61 | 73 | array( |
| @@ -73,8 +85,13 @@ | ||
| 73 | 85 | // If $events is a single event (associative array), wrap it in an array. |
| 74 | 86 | $events = array( $events ); |
| 75 | 87 | } |
| 76 | 88 | |
| 89 | + // Limit unauthenticated callers to a bounded number of pixel requests. | |
| 90 | + if ( count( $events ) > WC_Analytics_Tracking::MAX_CLIENT_EVENTS_PER_REQUEST ) { | |
| 91 | + $events = array_slice( $events, 0, WC_Analytics_Tracking::MAX_CLIENT_EVENTS_PER_REQUEST, true ); | |
| 92 | + } | |
| 93 | + | |
| 77 | 94 | $results = array(); |
| 78 | 95 | $has_errors = false; |
| 79 | 96 | |
| 80 | 97 | foreach ( $events as $index => $event ) { |
| @@ -90,9 +107,9 @@ | ||
| 90 | 107 | |
| 91 | 108 | // Validate event name and properties. |
| 92 | 109 | $event_name = $event['event_name'] ?? null; |
| 93 | 110 | $properties = $event['properties'] ?? array(); |
| 94 | - if ( ! $event_name || ! is_array( $properties ) ) { | |
| 111 | + if ( ! $event_name || ! is_string( $event_name ) || ! is_array( $properties ) ) { | |
| 95 | 112 | $results[ $index ] = array( |
| 96 | 113 | 'success' => false, |
| 97 | 114 | 'error' => 'Missing event_name or invalid properties', |
| 98 | 115 | ); |
| @@ -99,9 +116,9 @@ | ||
| 99 | 116 | $has_errors = true; |
| 100 | 117 | continue; |
| 101 | 118 | } |
| 102 | 119 | |
| 103 | - $result = WC_Analytics_Tracking::record_event( $event_name, $properties ); | |
| 120 | + $result = WC_Analytics_Tracking::record_client_event( $event_name, $properties ); | |
| 104 | 121 | |
| 105 | 122 | if ( is_wp_error( $result ) ) { |
| 106 | 123 | $results[ $index ] = array( |
| 107 | 124 | 'success' => false, |