get_error_code(), array( 'missing_token', 'no_possible_tokens', 'malformed_token' ), true ) ) { return new WP_Error( 'site_not_connected', __( 'This site is not connected to WordPress.com.', 'jetpack-stats-admin' ), array( 'status' => 400 ) ); } return $response; } $response_code = wp_remote_retrieve_response_code( $response ); $response_body_content = wp_remote_retrieve_body( $response ); $response_body = json_decode( $response_body_content, true ); $error = static::get_wp_error( $response_body, (int) $response_code ); if ( is_wp_error( $error ) ) { // Unknown token keys and incorrect secrets also mean the site cannot authenticate. // Expose these rejections like a missing token so callers can identify the broken connection. if ( in_array( $error->get_error_code(), array( 'invalid_token', 'unknown_token', 'signature_mismatch' ), true ) ) { return new WP_Error( 'site_not_connected', __( 'This site is not connected to WordPress.com.', 'jetpack-stats-admin' ), array( 'status' => 400 ) ); } return $error; } return $response_body; } /** * Build error object from remote response body and status code. * * @param array $response_body Remote response body. * @param int $response_code Http response code. * @return WP_Error */ protected static function get_wp_error( $response_body, $response_code = 200 ) { $error_code = null; foreach ( array( 'code', 'error' ) as $error_code_key ) { if ( isset( $response_body[ $error_code_key ] ) ) { $error_code = $response_body[ $error_code_key ]; break; } } // Sometimes the response code could be 200 but the response body still contains an error. if ( $error_code !== null || $response_code !== 200 ) { return new WP_Error( $error_code, $response_body['message'] ?? 'unknown remote error', array( 'status' => $response_code ) ); } // No error. return null; } /** * Check if the cache should be bypassed. * * @return bool */ protected static function should_bypass_cache() { // phpcs:ignore WordPress.Security.NonceVerification.Recommended return isset( $_GET['force_refresh'] ) || isset( $_GET['statsPurchaseSuccess'] ) || // phpcs:ignore WordPress.Arrays.ArrayKeySpacingRestrictions.SpacesAroundArrayKeys, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized ( isset( $_SERVER[ 'HTTP_REFERER' ] ) && false !== strpos( $_SERVER[ 'HTTP_REFERER' ], 'force_refresh' ) ) || // phpcs:ignore WordPress.Arrays.ArrayKeySpacingRestrictions.SpacesAroundArrayKeys, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized ( isset( $_SERVER[ 'HTTP_REFERER' ] ) && false !== strpos( $_SERVER[ 'HTTP_REFERER' ], 'statsPurchaseSuccess' ) ); } }