PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-status/src/class-host.php +49 -109 13.1.5 → 16.3 View file →
@@ -33,9 +33,9 @@
33 33 * Determine if the site is hosted on the Atomic hosting platform.
34 34 *
35 35 * @since 1.9.0
36 36 *
37 - * @return bool;
37 + * @return bool
38 38 */
39 39 public function is_atomic_platform() {
40 40 return Constants::is_true( 'ATOMIC_SITE_ID' ) && Constants::is_true( 'ATOMIC_CLIENT_ID' );
41 41 }
@@ -78,8 +78,36 @@
78 78 return $this->is_wpcom_simple() || $this->is_woa_site();
79 79 }
80 80
81 81 /**
82 + * Determine if this is a P2 site.
83 + * This covers both P2 and P2020 themes.
84 + *
85 + * @return bool
86 + */
87 + public function is_p2_site() {
88 + $site_id = $this->get_wpcom_site_id();
89 + if ( ! $site_id ) {
90 + return false;
91 + }
92 + return str_contains( get_stylesheet(), 'pub/p2' ) || ( function_exists( '\WPForTeams\is_wpforteams_site' ) && \WPForTeams\is_wpforteams_site( $site_id ) );
93 + }
94 +
95 + /**
96 + * Get the current site's WordPress.com ID.
97 + *
98 + * @return mixed The site's WordPress.com ID.
99 + */
100 + public function get_wpcom_site_id() {
101 + if ( $this->is_wpcom_simple() ) {
102 + return get_current_blog_id();
103 + } elseif ( class_exists( 'Jetpack' ) && \Jetpack::is_connection_ready() ) {
104 + return \Jetpack_Options::get_option( 'id' );
105 + }
106 + return false;
107 + }
108 +
109 + /**
82 110 * Add all wordpress.com environments to the safe redirect allowed list.
83 111 *
84 112 * To be used with a filter of allowed domains for a redirect.
85 113 *
@@ -126,9 +154,9 @@
126 154 * @return string "source" query param value
127 155 */
128 156 public function get_source_query() {
129 157 // phpcs:disable WordPress.Security.NonceVerification.Recommended
130 - $allowed_sources = array( 'jetpack-manage' );
158 + $allowed_sources = array( 'jetpack-manage', 'a8c-for-agencies' );
131 159 if ( isset( $_GET['source'] ) && in_array( $_GET['source'], $allowed_sources, true ) ) {
132 160 return sanitize_key( $_GET['source'] );
133 161 }
134 162
@@ -135,113 +163,16 @@
135 163 return '';
136 164 }
137 165
138 166 /**
139 - * Returns an array of nameservers for the current site.
167 + * Returns a guess of the hosting provider for the current site based on various checks.
140 168 *
141 - * @param string $domain The domain of the site to check.
142 - * @return string
143 - */
144 - public function get_nameserver_dns_records( $domain ) {
145 - $dns_records = dns_get_record( $domain, DNS_NS ); // Fetches the DNS records of type NS (Name Server)
146 - $nameservers = array();
147 -
148 - foreach ( $dns_records as $record ) {
149 - if ( isset( $record['target'] ) ) {
150 - $nameservers[] = $record['target']; // Adds the nameserver to the array
151 - }
152 - }
153 -
154 - return $nameservers; // Returns an array of nameserver names
155 - }
156 -
157 - /**
158 - * Given a DNS entry, will return a hosting provider if one can be determined. Otherwise, will return 'unknown'.
159 - * Sourced from: fbhepr%2Skers%2Sjcpbz%2Sjc%2Qpbagrag%2Syvo%2Subfgvat%2Qcebivqre%2Sanzrfreiref.cuc-og
169 + * @since 5.0.4 Added $guess parameter.
170 + * @since 6.0.0 Removed $guess parameter.
160 171 *
161 - * @param string $domain The domain of the site to check.
162 - * @return string The hosting provider of 'unknown'.
163 - */
164 - public function get_hosting_provider_by_nameserver( $domain ) {
165 - $known_nameservers = array(
166 - 'bluehost' => array(
167 - '.bluehost.com',
168 - ),
169 - 'dreamhost' => array(
170 - '.dreamhost.com',
171 - ),
172 - 'mediatemple' => array(
173 - '.mediatemple.net',
174 - ),
175 - 'xserver' => array(
176 - '.xserver.jp',
177 - ),
178 - 'namecheap' => array(
179 - '.namecheaphosting.com',
180 - ),
181 - 'hostmonster' => array(
182 - '.hostmonster.com',
183 - ),
184 - 'justhost' => array(
185 - '.justhost.com',
186 - ),
187 - 'digitalocean' => array(
188 - '.digitalocean.com',
189 - ),
190 - 'one' => array(
191 - '.one.com',
192 - ),
193 - 'hostpapa' => array(
194 - '.hostpapa.com',
195 - ),
196 - 'siteground' => array(
197 - '.sgcloud.net',
198 - '.sgedu.site',
199 - '.sgsrv1.com',
200 - '.sgvps.net',
201 - '.siteground.biz',
202 - '.siteground.net',
203 - '.siteground.eu',
204 - ),
205 - 'inmotion' => array(
206 - '.inmotionhosting.com',
207 - ),
208 - 'ionos' => array(
209 - '.ui-dns.org',
210 - '.ui-dns.de',
211 - '.ui-dns.biz',
212 - '.ui-dns.com',
213 - ),
214 - );
215 -
216 - $dns_records = $this->get_nameserver_dns_records( $domain );
217 - $dns_records = array_map( 'strtolower', $dns_records );
218 -
219 - foreach ( $known_nameservers as $host => $ns_patterns ) {
220 - foreach ( $ns_patterns as $ns_pattern ) {
221 - foreach ( $dns_records as $record ) {
222 - if ( false !== strpos( $record, $ns_pattern ) ) {
223 - return $host;
224 - }
225 - }
226 - }
227 - }
228 -
229 - return 'unknown';
230 - }
231 -
232 - /**
233 - * Returns a guess of the hosting provider for the current site based on various checks.
234 - *
235 172 * @return string
236 173 */
237 174 public function get_known_host_guess() {
238 - $host = Cache::get( 'host_guess' );
239 -
240 - if ( null !== $host ) {
241 - return $host;
242 - }
243 -
244 175 // First, let's check if we can recognize provider manually:
245 176 switch ( true ) {
246 177 case $this->is_woa_site():
247 178 $provider = 'woa';
@@ -263,14 +194,23 @@
263 194 $provider = 'unknown';
264 195 break;
265 196 }
266 197
267 - // Second, let's check if we can recognize provider by nameservers:
268 - $domain = isset( $_SERVER['SERVER_NAME'] ) ? sanitize_text_field( wp_unslash( $_SERVER['SERVER_NAME'] ) ) : '';
269 - if ( $provider === 'unknown' && ! empty( $domain ) ) {
270 - $provider = $this->get_hosting_provider_by_nameserver( $domain );
271 - }
198 + return $provider;
199 + }
272 200
273 - Cache::set( 'host_guess', $provider );
274 - return $provider;
201 + /**
202 + * Add public-api.wordpress.com to the safe redirect allowed list - only added when someone allows API access.
203 + *
204 + * @since 3.0.2 Ported from Jetpack to the Status package.
205 + *
206 + * To be used with a filter of allowed domains for a redirect.
207 + *
208 + * @param array $domains Allowed WP.com Environments.
209 + *
210 + * @return array
211 + */
212 + public static function allow_wpcom_public_api_domain( $domains ) {
213 + $domains[] = 'public-api.wordpress.com';
214 + return $domains;
275 215 }
276 216 }