PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-publicize/src/rest-api/class-base-controller.php +128 -0 16.2-beta → 16.3 View file →
@@ -1,0 +1,128 @@
1 +<?php
2 +/**
3 + * Base Controller class.
4 + *
5 + * @package automattic/jetpack-publicize
6 + */
7 +
8 +namespace Automattic\Jetpack\Publicize\REST_API;
9 +
10 +use Automattic\Jetpack\Publicize\Connections;
11 +use Automattic\Jetpack\Publicize\Publicize_Utils;
12 +use WP_Error;
13 +use WP_REST_Controller;
14 +use WP_REST_Request;
15 +use WP_REST_Response;
16 +
17 +if ( ! defined( 'ABSPATH' ) ) {
18 + exit( 0 );
19 +}
20 +
21 +/**
22 + * Base controller for Publicize endpoints.
23 + */
24 +abstract class Base_Controller extends WP_REST_Controller {
25 +
26 + /**
27 + * Whether to allow requests as blog.
28 + *
29 + * @var bool
30 + */
31 + protected $allow_requests_as_blog = false;
32 +
33 + /**
34 + * Constructor.
35 + */
36 + public function __construct() {
37 + $this->wpcom_is_wpcom_only_endpoint = true;
38 + }
39 +
40 + /**
41 + * Check if the request is authorized for the blog.
42 + *
43 + * @return bool
44 + */
45 + protected static function is_authorized_blog_request() {
46 + if ( Publicize_Utils::is_wpcom() && is_jetpack_site( get_current_blog_id() ) ) {
47 +
48 + $jp_auth_endpoint = new \WPCOM_REST_API_V2_Endpoint_Jetpack_Auth();
49 +
50 + return $jp_auth_endpoint->is_jetpack_authorized_for_site() === true;
51 + }
52 +
53 + return false;
54 + }
55 +
56 + /**
57 + * Filters out data based on ?_fields= request parameter
58 + *
59 + * @param array $item Item to prepare.
60 + * @param WP_REST_Request $request Full details about the request.
61 + *
62 + * @return WP_REST_Response filtered item
63 + */
64 + public function prepare_item_for_response( $item, $request ) {
65 +
66 + $fields = $this->get_fields_for_response( $request );
67 +
68 + $response_data = array();
69 + foreach ( $item as $field => $value ) {
70 + if ( rest_is_field_included( $field, $fields ) ) {
71 + $response_data[ $field ] = $value;
72 + }
73 + }
74 +
75 + return rest_ensure_response( $response_data );
76 + }
77 +
78 + /**
79 + * Verify that user can access Publicize data
80 + *
81 + * @return true|WP_Error
82 + */
83 + protected function publicize_permissions_check() {
84 +
85 + global $publicize;
86 +
87 + if ( ! $publicize ) {
88 + return new WP_Error(
89 + 'publicize_not_available',
90 + __( 'Sorry, Jetpack Social is not available on your site right now.', 'jetpack-publicize-pkg' ),
91 + array( 'status' => rest_authorization_required_code() )
92 + );
93 + }
94 +
95 + if ( $this->allow_requests_as_blog && self::is_authorized_blog_request() ) {
96 + return true;
97 + }
98 +
99 + if ( $publicize->current_user_can_access_publicize_data() ) {
100 + return true;
101 + }
102 +
103 + return new WP_Error(
104 + 'invalid_user_permission_publicize',
105 + __( 'Sorry, you are not allowed to access Jetpack Social data on this site.', 'jetpack-publicize-pkg' ),
106 + array( 'status' => rest_authorization_required_code() )
107 + );
108 + }
109 +
110 + /**
111 + * Check whether the request is allowed to manage (update/delete) a connection.
112 + *
113 + * @param WP_REST_Request $request Full details about the request.
114 + * @return bool True if the request can manage connection, false otherwise.
115 + */
116 + protected function manage_connection_permission_check( $request ) {
117 + // Editors and above can manage any connection.
118 + if ( current_user_can( 'edit_others_posts' ) ) {
119 + return true;
120 + }
121 +
122 + $connection_id = $request->get_param( 'connection_id' );
123 +
124 + $connection = Connections::get_by_id( $connection_id );
125 +
126 + return Connections::user_owns_connection( $connection );
127 + }
128 +}