PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-comments/src/identity/class-identity.php +83 -0 16.2-beta → 16.3 View file →
@@ -1,0 +1,83 @@
1 +<?php
2 +/**
3 + * The commenter's identity.
4 + *
5 + * @package automattic/jetpack-comments
6 + */
7 +
8 +namespace Automattic\Jetpack\Comments;
9 +
10 +/**
11 + * Who is leaving the comment being written now.
12 + */
13 +class Identity {
14 +
15 + /**
16 + * Who is leaving the comment, as far as this site knows.
17 + *
18 + * @return array
19 + */
20 + public static function settings() {
21 + $commenter = wp_get_current_commenter();
22 +
23 + // Nothing under `identity` is about the visitor: the HTML is page-cached
24 + // and served to everyone, so who holds a passport comes from a cookie.
25 + $settings = array(
26 + 'isLoggedIn' => is_user_logged_in(),
27 + 'avatarUrl' => '',
28 + 'commenter' => array(
29 + 'author' => $commenter['comment_author'],
30 + 'email' => $commenter['comment_author_email'],
31 + 'url' => $commenter['comment_author_url'],
32 + ),
33 + 'user' => null,
34 + 'identity' => array(
35 + 'blogId' => Checkpoint::blog_id(),
36 + 'canSignIn' => false,
37 + 'connect' => null,
38 + 'connectUrl' => Checkpoint_Endpoint::route_url( Checkpoint_Endpoint::CONNECT_ROUTE ),
39 + 'emailUrl' => Checkpoint_Endpoint::route_url( Checkpoint_Endpoint::EMAIL_ROUTE ),
40 + 'origin' => 'https://public-api.wordpress.com',
41 + 'codeField' => Checkpoint::CODE_FIELD,
42 + 'passportField' => Checkpoint::PASSPORT_FIELD,
43 + 'displayCookie' => Passport::DISPLAY_COOKIE,
44 + 'cookieHash' => COOKIEHASH,
45 + 'cookiePath' => COOKIEPATH,
46 + 'cookieDomain' => COOKIE_DOMAIN ? COOKIE_DOMAIN : '',
47 + 'defaultAvatar' => Avatars::default_url( 80 ),
48 + // A path: Simple's admin_url() is the .wordpress.com host, which cannot clear a custom domain's cookies.
49 + 'logoutUrl' => wp_make_link_relative( admin_url( 'admin-ajax.php' ) ),
50 + 'logoutAction' => Checkpoint_Endpoint::LOGOUT_ACTION,
51 + ),
52 + );
53 +
54 + if ( is_user_logged_in() ) {
55 + $user = wp_get_current_user();
56 + $settings['avatarUrl'] = html_entity_decode( (string) get_avatar_url( $user->ID, array( 'size' => 80 ) ), ENT_QUOTES );
57 + $settings['user'] = array( 'name' => $user->display_name );
58 +
59 + return $settings;
60 + }
61 +
62 + if ( get_option( 'show_avatars' ) ) {
63 + $settings['avatarUrl'] = $commenter['comment_author_email']
64 + ? html_entity_decode( (string) get_avatar_url( $commenter['comment_author_email'], array( 'size' => 80 ) ), ENT_QUOTES )
65 + : Avatars::default_url( 80 );
66 + }
67 +
68 + if ( ! Checkpoint::is_available() ) {
69 + return $settings;
70 + }
71 +
72 + // Visitors share this challenge until it expires: it only filters messages
73 + // to the window that opened the popup, and the connect route issues fresh ones.
74 + $challenge = rtrim( strtr( base64_encode( random_bytes( 32 ) ), '+/', '-_' ), '=' ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- base64url is the wire format.
75 +
76 + $connect = Checkpoint::connect_url( $challenge );
77 +
78 + $settings['identity']['canSignIn'] = true;
79 + $settings['identity']['connect'] = is_wp_error( $connect ) ? null : $connect;
80 +
81 + return $settings;
82 + }
83 +}