PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | modules/comments/comments.php +1142 -0 16.2-beta → 16.3 View file →
@@ -1,0 +1,1142 @@
1 +<?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 +/**
3 + * Module: Comments
4 + *
5 + * @package automattic/jetpack
6 + */
7 +
8 +require __DIR__ . '/base.php';
9 +use Automattic\Jetpack\Connection\Tokens;
10 +use Automattic\Jetpack\Status\Host;
11 +
12 +if ( ! defined( 'ABSPATH' ) ) {
13 + exit( 0 );
14 +}
15 +
16 +/**
17 + * Main Comments class
18 + *
19 + * @package automattic/jetpack
20 + * @since 1.4
21 + */
22 +class Jetpack_Comments extends Highlander_Comments_Base {
23 +
24 + /** Variables *************************************************************/
25 +
26 + /**
27 + * Possible comment form sources - empty array as default
28 + *
29 + * @var array
30 + */
31 + public $id_sources = array();
32 +
33 + /**
34 + * Remote comment URL - empty string as default
35 + *
36 + * @var string
37 + */
38 + public $signed_url = '';
39 +
40 + /**
41 + * The default comment form color scheme - default is light
42 + *
43 + * @var string
44 + * @see ::set_default_color_theme_based_on_theme_settings()
45 + */
46 + public $default_color_scheme = 'light';
47 +
48 + /** Methods ***************************************************************/
49 +
50 + /**
51 + * Initialize class
52 + */
53 + public static function init() {
54 + static $instance = false;
55 +
56 + if ( ! $instance ) {
57 + $instance = new Jetpack_Comments();
58 + }
59 +
60 + return $instance;
61 + }
62 +
63 + /**
64 + * Main constructor for Comments
65 + *
66 + * @since 1.4
67 + */
68 + public function __construct() {
69 + parent::__construct();
70 +
71 + // Comments is loaded.
72 +
73 + /**
74 + * Fires after the Jetpack_Comments object has been instantiated
75 + *
76 + * @module comments
77 + *
78 + * @since 1.4.0
79 + *
80 + * @param array $jetpack_comments_loaded First element in array of type Jetpack_Comments
81 + */
82 + do_action_ref_array( 'jetpack_comments_loaded', array( $this ) );
83 + add_action( 'after_setup_theme', array( $this, 'set_default_color_theme_based_on_theme_settings' ), 100 );
84 + }
85 +
86 + /**
87 + * Set the default comments color theme based on theme settings
88 + */
89 + public function set_default_color_theme_based_on_theme_settings() {
90 + if ( function_exists( 'twentyeleven_get_theme_options' ) ) {
91 + $theme_options = twentyeleven_get_theme_options();
92 + $theme_color_scheme = $theme_options['color_scheme'] ?? 'transparent';
93 + } else {
94 + $theme_color_scheme = get_theme_mod( 'color_scheme', 'transparent' );
95 + }
96 + // Default for $theme_color_scheme is 'transparent' just so it doesn't match 'light' or 'dark'.
97 + // The default for Jetpack's color scheme is still defined above as 'light'.
98 +
99 + if ( false !== stripos( $theme_color_scheme, 'light' ) ) {
100 + $this->default_color_scheme = 'light';
101 + } elseif ( false !== stripos( $theme_color_scheme, 'dark' ) ) {
102 + $this->default_color_scheme = 'dark';
103 + }
104 + }
105 +
106 + /** Private Methods *******************************************************/
107 +
108 + /**
109 + * Set any global variables or class variables
110 + *
111 + * This is primarily defining the comment form sources.
112 + *
113 + * @since 1.4
114 + */
115 + protected function setup_globals() {
116 + parent::setup_globals();
117 +
118 + // Sources.
119 + $this->id_sources = array(
120 + 'guest',
121 + 'jetpack',
122 + 'wordpress',
123 + 'facebook',
124 + );
125 + }
126 +
127 + /**
128 + * Whether the rebuilt Jetpack Comments form has taken over from this one.
129 + *
130 + * Guarded because this file and the jetpack-comments package can land in
131 + * either order on a staged deploy.
132 + *
133 + * @return bool
134 + */
135 + private static function new_comments_enabled() {
136 + return class_exists( '\Automattic\Jetpack\Comments\Comments' )
137 + && \Automattic\Jetpack\Comments\Comments::is_enabled();
138 + }
139 +
140 + /**
141 + * Setup actions for methods in this class
142 + *
143 + * @since 1.4
144 + */
145 + protected function setup_actions() {
146 + if ( self::new_comments_enabled() ) {
147 + return;
148 + }
149 +
150 + parent::setup_actions();
151 +
152 + // Selfishly remove everything from the existing comment form.
153 + remove_all_actions( 'comment_form_before' );
154 +
155 + // Selfishly add only our actions back to the comment form.
156 + add_action( 'comment_form_before', array( $this, 'manage_post_cookie' ) );
157 + add_action( 'comment_form_before', array( $this, 'comment_form_before' ) );
158 + add_action( 'comment_form_after', array( $this, 'comment_form_after' ), 1 ); // Set very early since we remove everything outputed before our action.
159 +
160 + // Before a comment is posted.
161 + add_action( 'pre_comment_on_post', array( $this, 'pre_comment_on_post' ), 1 );
162 +
163 + // After a comment is posted.
164 + add_action( 'comment_post', array( $this, 'add_comment_meta' ) );
165 + }
166 +
167 + /**
168 + * Setup filters for methods in this class
169 + *
170 + * @since 1.6.2
171 + */
172 + protected function setup_filters() {
173 + if ( self::new_comments_enabled() ) {
174 + return;
175 + }
176 +
177 + parent::setup_filters();
178 +
179 + add_filter( 'comment_post_redirect', array( $this, 'capture_comment_post_redirect_to_reload_parent_frame' ), 100 );
180 + add_filter( 'comment_duplicate_trigger', array( $this, 'capture_comment_duplicate_trigger' ), 100 );
181 + add_filter( 'get_avatar', array( $this, 'get_avatar' ), 10, 4 );
182 + // Fix comment reply link when `comment_registration` is required.
183 + add_filter( 'comment_reply_link', array( $this, 'comment_reply_link' ), 10, 4 );
184 + }
185 +
186 + /**
187 + * In order for comments to work properly for password-protected posts we need to set `wp-postpass` cookie to SameSite none.
188 + */
189 + public function manage_post_cookie() {
190 + if ( headers_sent() ) {
191 + return;
192 + }
193 +
194 + $postpass_cookie_key = 'wp-postpass_' . COOKIEHASH;
195 +
196 + if ( empty( $_COOKIE[ $postpass_cookie_key ] ) ) {
197 + return;
198 + }
199 +
200 + $postpass_cookie_value = sanitize_text_field( wp_unslash( $_COOKIE[ $postpass_cookie_key ] ) );
201 +
202 + if ( empty( $_COOKIE['verbum-wp-postpass'] ) || ( $_COOKIE['verbum-wp-postpass'] !== $postpass_cookie_value ) ) {
203 + $expire = apply_filters( 'post_password_expires', time() + 10 * DAY_IN_SECONDS );
204 +
205 + setcookie(
206 + $postpass_cookie_key,
207 + $postpass_cookie_value,
208 + array(
209 + 'expires' => $expire,
210 + 'samesite' => 'None',
211 + 'path' => '/',
212 + 'domain' => COOKIE_DOMAIN,
213 + 'secure' => is_ssl(),
214 + 'httponly' => false, // phpcs:ignore Jetpack.Functions.SetCookie.FoundNonHTTPOnlyFalse -- @todo Can this be set true?
215 + )
216 + );
217 +
218 + setcookie(
219 + 'verbum-wp-postpass',
220 + $postpass_cookie_value,
221 + array(
222 + 'expires' => $expire,
223 + 'samesite' => 'None',
224 + 'path' => '/',
225 + 'domain' => COOKIE_DOMAIN,
226 + 'secure' => is_ssl(),
227 + 'httponly' => false, // phpcs:ignore Jetpack.Functions.SetCookie.FoundNonHTTPOnlyFalse -- @todo Can this be set true?
228 + )
229 + );
230 + }
231 + }
232 +
233 + /**
234 + * Get the comment avatar from Gravatar or Twitter/Facebook.
235 + *
236 + * Leaving the Twitter reference for legacy comments even though support is no longer offered.
237 + *
238 + * @since 1.4
239 + *
240 + * @param string $avatar Current avatar URL.
241 + * @param string $comment Comment for the avatar.
242 + * @param int $size Size of the avatar.
243 + *
244 + * @return string New avatar
245 + */
246 + public function get_avatar( $avatar, $comment, $size ) {
247 + if ( ! isset( $comment->comment_post_ID ) || ! isset( $comment->comment_ID ) ) {
248 + // it's not a comment - bail.
249 + return $avatar;
250 + }
251 +
252 + // Detect whether it's a Facebook avatar.
253 + $foreign_avatar = get_comment_meta( $comment->comment_ID, 'hc_avatar', true );
254 + $foreign_avatar_hostname = wp_parse_url( $foreign_avatar, PHP_URL_HOST );
255 + if ( ! $foreign_avatar_hostname ||
256 + ! preg_match( '/\.?(graph\.facebook\.com|twimg\.com)$/', $foreign_avatar_hostname ) ) {
257 + return $avatar;
258 + }
259 +
260 + // Insert the escaped URL through a callback: a preg_replace() replacement string would expand a
261 + // `$1` inside it into the captured quote, breaking out of the src attribute (stored-XSS vector).
262 + $photon_url = esc_url( set_url_scheme( $this->photon_avatar( $foreign_avatar, $size ), 'https' ) );
263 + return preg_replace_callback(
264 + '#src=([\'"])[^\'"]+\\1#',
265 + static function ( $matches ) use ( $photon_url ) {
266 + return 'src=' . $matches[1] . $photon_url . $matches[1];
267 + },
268 + $avatar
269 + );
270 + }
271 +
272 + /**
273 + * Set comment reply link.
274 + * This is to fix the reply link when comment registration is required.
275 + *
276 + * @param string $reply_link The HTML markup for the comment reply link.
277 + * @param array $args An array of arguments overriding the defaults.
278 + * @param WP_Comment $comment The object of the comment being replied.
279 + * @param WP_Post $post The WP_Post object.
280 + *
281 + * @return string New reply link.
282 + */
283 + public function comment_reply_link( $reply_link, $args, $comment, $post ) {
284 + // This is only necessary if comment_registration is required to post comments
285 + if ( ! get_option( 'comment_registration' ) ) {
286 + return $reply_link;
287 + }
288 +
289 + $respond_id = esc_attr( $args['respond_id'] );
290 + $add_below = esc_attr( $args['add_below'] );
291 + /* This is to accommodate some themes that add an SVG to the Reply link like twenty-seventeen. */
292 + $reply_text = wp_kses(
293 + $args['reply_text'],
294 + array(
295 + 'svg' => array(
296 + 'class' => true,
297 + 'aria-hidden' => true,
298 + 'aria-labelledby' => true,
299 + 'role' => true,
300 + 'xmlns' => true,
301 + 'width' => true,
302 + 'height' => true,
303 + 'viewbox' => true,
304 + ),
305 + 'use' => array(
306 + 'href' => true,
307 + 'xlink:href' => true,
308 + ),
309 + )
310 + );
311 + $before_link = wp_kses( $args['before'], wp_kses_allowed_html( 'post' ) );
312 + $after_link = wp_kses( $args['after'], wp_kses_allowed_html( 'post' ) );
313 +
314 + $reply_url = esc_url( add_query_arg( 'replytocom', $comment->comment_ID . '#' . $respond_id ) );
315 +
316 + return <<<HTML
317 + $before_link
318 + <a class="comment-reply-link" href="$reply_url" onclick="return addComment.moveForm( '$add_below-$comment->comment_ID', '$comment->comment_ID', '$respond_id', '$post->ID' )">$reply_text</a>
319 + $after_link
320 +HTML;
321 + }
322 +
323 + /**
324 + * Get the site's blog token.
325 + * This can be used to bypass Comments entirely if Jetpack is not properly connected.
326 + *
327 + * @since 11.2
328 + *
329 + * @return bool|object False if not properly connected. Object with the blog token if connected.
330 + */
331 + private function get_blog_token() {
332 + $blog_token = ( new Tokens() )->get_access_token();
333 + // If we have no token, bail.
334 + if ( ! $blog_token || is_wp_error( $blog_token ) ) {
335 + return false;
336 + }
337 +
338 + return $blog_token;
339 + }
340 +
341 + /** Output Methods ********************************************************/
342 +
343 + /**
344 + * Start capturing the core comment_form() output
345 + *
346 + * Comment form output will only be captured if comments are enabled - we return otherwise.
347 + *
348 + * @since 1.4
349 + */
350 + public function comment_form_before() {
351 + /**
352 + * Filters the setting that determines if Jetpack comments should be enabled for
353 + * the current post type.
354 + *
355 + * @module comments
356 + *
357 + * @since 3.8.1
358 + *
359 + * @param boolean $return Should comments be enabled?
360 + */
361 + if ( ! apply_filters( 'jetpack_comment_form_enabled_for_' . get_post_type(), true ) ) {
362 + return;
363 + }
364 +
365 + // If the Jetpack connection is not healthy, bail.
366 + if ( ! $this->get_blog_token() ) {
367 + return;
368 + }
369 +
370 + // Add some JS to the footer.
371 + add_action( 'wp_footer', array( $this, 'watch_comment_parent' ), 100 );
372 +
373 + ob_start();
374 + }
375 +
376 + /**
377 + * Noop the default comment form output, get some options, and output our
378 + * tricked out totally radical comment form.
379 + *
380 + * @since 1.4
381 + */
382 + public function comment_form_after() {
383 + /** This filter is documented in modules/comments/comments.php */
384 + if ( ! apply_filters( 'jetpack_comment_form_enabled_for_' . get_post_type(), true ) ) {
385 + return;
386 + }
387 +
388 + $blog_token = $this->get_blog_token();
389 + // If the Jetpack connection is not healthy, bail.
390 + if ( ! $blog_token ) {
391 + return;
392 + }
393 +
394 + // Throw it all out and drop in our replacement.
395 + ob_end_clean();
396 +
397 + if ( in_array( 'subscriptions', Jetpack::get_active_modules(), true ) ) {
398 + $stb_enabled = get_option( 'stb_enabled', 1 );
399 + $stb_enabled = empty( $stb_enabled ) ? 0 : 1;
400 +
401 + $stc_enabled = get_option( 'stc_enabled', 1 );
402 + $stc_enabled = empty( $stc_enabled ) ? 0 : 1;
403 + } else {
404 + $stb_enabled = 0;
405 + $stc_enabled = 0;
406 + }
407 +
408 + $params = array(
409 + 'blogid' => Jetpack_Options::get_option( 'id' ),
410 + 'postid' => get_the_ID(),
411 + 'comment_registration' => ( get_option( 'comment_registration' ) ? '1' : '0' ), // Need to explicitly send a '1' or a '0' for these.
412 + 'require_name_email' => ( get_option( 'require_name_email' ) ? '1' : '0' ),
413 + 'stc_enabled' => $stc_enabled,
414 + 'stb_enabled' => $stb_enabled,
415 + 'show_avatars' => ( get_option( 'show_avatars' ) ? '1' : '0' ),
416 + 'avatar_default' => get_option( 'avatar_default' ),
417 + 'greeting' => get_option( 'highlander_comment_form_prompt', __( 'Leave a Reply', 'jetpack' ) ),
418 + 'jetpack_comments_nonce' => wp_create_nonce( 'jetpack_comments_nonce-' . get_the_ID() ),
419 + /**
420 + * Changes the comment form prompt.
421 + *
422 + * @module comments
423 + *
424 + * @since 2.3.0
425 + *
426 + * @param string $var Default is "Leave a Reply to %s."
427 + */
428 + 'greeting_reply' => apply_filters(
429 + 'jetpack_comment_form_prompt_reply',
430 + /* translators: %s is the displayed username of the post (or comment) author */
431 + __( 'Leave a Reply to %s', 'jetpack' )
432 + ),
433 + 'color_scheme' => get_option( 'jetpack_comment_form_color_scheme', $this->default_color_scheme ),
434 + 'lang' => get_locale(),
435 + 'jetpack_version' => JETPACK__VERSION,
436 + 'iframe_unique_id' => wp_unique_id(),
437 + );
438 +
439 + // Extra parameters for logged in user.
440 + if ( is_user_logged_in() ) {
441 + $current_user = wp_get_current_user();
442 + $params['hc_post_as'] = 'jetpack';
443 + $params['hc_userid'] = $current_user->ID;
444 + $params['hc_username'] = $current_user->display_name;
445 + $params['hc_userurl'] = $current_user->user_url;
446 + $params['hc_useremail'] = md5( strtolower( trim( $current_user->user_email ) ) );
447 + if ( current_user_can( 'unfiltered_html' ) ) {
448 + $params['_wp_unfiltered_html_comment'] = wp_create_nonce( 'unfiltered-html-comment_' . get_the_ID() );
449 + }
450 + } else {
451 + $commenter = wp_get_current_commenter();
452 + $params['show_cookie_consent'] = (int) has_action( 'set_comment_cookies', 'wp_set_comment_cookies' );
453 + $params['has_cookie_consent'] = (int) ! empty( $commenter['comment_author_email'] );
454 + // Jetpack_Memberships for logged out users only checks for the wp-jp-premium-content-session cookie
455 + $params['is_current_user_subscribed'] = class_exists( '\Jetpack_Memberships' ) ? (int) Jetpack_Memberships::is_current_user_subscribed() : 0;
456 + }
457 +
458 + list( $token_key ) = explode( '.', $blog_token->secret, 2 );
459 + // Prophylactic check: anything else should never happen.
460 + if ( $token_key && $token_key !== $blog_token->secret ) {
461 + // Is the token a Special Token (@see class.tokens.php)?
462 + if ( preg_match( '/^;.\d+;\d+;$/', $token_key, $matches ) ) {
463 + // The token key for a Special Token is public.
464 + $params['token_key'] = $token_key;
465 + } else {
466 + /*
467 + * The token key for a Normal Token is public but
468 + * looks like sensitive data. Since there can only be
469 + * one Normal Token per site, avoid concern by
470 + * sending the magic "use the Normal Token" token key.
471 + */
472 + $params['token_key'] = Tokens::MAGIC_NORMAL_TOKEN_KEY;
473 + }
474 + }
475 +
476 + $signature = self::sign_remote_comment_parameters( $params, $blog_token->secret );
477 + if ( is_wp_error( $signature ) ) {
478 + $signature = 'error';
479 + }
480 +
481 + $params['sig'] = $signature;
482 + $url_origin = 'https://jetpack.wordpress.com';
483 + $url = "{$url_origin}/jetpack-comment/?" . http_build_query( $params );
484 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Sniff misses the esc_url_raw.
485 + $url = "{$url}#parent=" . rawurlencode( esc_url_raw( set_url_scheme( 'http://' . ( isset( $_SERVER['HTTP_HOST'] ) ? wp_unslash( $_SERVER['HTTP_HOST'] ) : '' ) . ( isset( $_SERVER['REQUEST_URI'] ) ? wp_unslash( $_SERVER['REQUEST_URI'] ) : '' ) ) ) );
486 + $this->signed_url = $url;
487 + $height = $params['comment_registration'] || is_user_logged_in() ? '315' : '430'; // Iframe can be shorter if we're not allowing guest commenting.
488 + $transparent = ( 'transparent' === $params['color_scheme'] ) ? 'true' : 'false';
489 +
490 + if ( isset( $_GET['replytocom'] ) ) { //phpcs:ignore WordPress.Security.NonceVerification.Recommended
491 + $url .= '&replytocom=' . (int) $_GET['replytocom']; //phpcs:ignore WordPress.Security.NonceVerification.Recommended
492 + }
493 +
494 + /**
495 + * Filter whether the comment title can be displayed.
496 + *
497 + * @module comments
498 + *
499 + * @since 4.7.0
500 + *
501 + * @param bool $show Can the comment be displayed? Default to true.
502 + */
503 + $show_greeting = apply_filters( 'jetpack_comment_form_display_greeting', true );
504 +
505 + /**
506 + * Filter the comment title tag.
507 + *
508 + * @module comments
509 + * @since 12.4
510 + *
511 + * @param string $comment_reply_title_tag The comment title tag. Default to h3.
512 + */
513 + $comment_reply_title_tag = apply_filters( 'jetpack_comment_reply_title_tag', 'h3' );
514 +
515 + // The actual iframe (loads comment form from Jetpack server).
516 +
517 + $is_amp = class_exists( Jetpack_AMP_Support::class ) && Jetpack_AMP_Support::is_amp_request();
518 + ?>
519 +
520 + <div id="respond" class="comment-respond">
521 + <?php
522 + if ( true === $show_greeting ) :
523 + printf(
524 + '<%1$s id="reply-title" class="comment-reply-title">',
525 + esc_html( $comment_reply_title_tag )
526 + );
527 +
528 + comment_form_title(
529 + esc_html( $params['greeting'] ),
530 + esc_html( $params['greeting_reply'] )
531 + );
532 + echo '<small>';
533 + cancel_comment_reply_link( esc_html__( 'Cancel reply', 'jetpack' ) );
534 + echo '</small>';
535 +
536 + printf(
537 + '</%1$s>',
538 + esc_html( $comment_reply_title_tag )
539 + );
540 + endif;
541 + ?>
542 + <form id="commentform" class="comment-form">
543 + <iframe
544 + title="<?php esc_attr_e( 'Comment Form', 'jetpack' ); ?>"
545 + src="<?php echo esc_url( $url ); ?>"
546 + <?php if ( $is_amp ) : ?>
547 + resizable
548 + layout="fixed-height"
549 + height="<?php echo esc_attr( $height ); ?>"
550 + <?php else : ?>
551 + name="jetpack_remote_comment"
552 + style="width:100%; height: <?php echo esc_attr( $height ); ?>px; border:0;"
553 + <?php endif; ?>
554 + class="jetpack_remote_comment"
555 + id="jetpack_remote_comment"
556 + sandbox="allow-same-origin allow-top-navigation allow-scripts allow-forms allow-popups"
557 + >
558 + <?php if ( $is_amp ) : ?>
559 + <button overflow><?php esc_html_e( 'Show more', 'jetpack' ); ?></button>
560 + <?php endif; ?>
561 + </iframe>
562 + <?php if ( ! $is_amp ) : ?>
563 + <!--[if !IE]><!-->
564 + <script>
565 + document.addEventListener('DOMContentLoaded', function () {
566 + var commentForms = document.getElementsByClassName('jetpack_remote_comment');
567 + for (var i = 0; i < commentForms.length; i++) {
568 + commentForms[i].allowTransparency = <?php echo esc_html( $transparent ); ?>;
569 + commentForms[i].scrolling = 'no';
570 + }
571 + });
572 + </script>
573 + <!--<![endif]-->
574 + <?php endif; ?>
575 + </form>
576 + </div>
577 +
578 + <?php // Below is required for comment reply JS to work. ?>
579 +
580 + <input type="hidden" name="comment_parent" id="comment_parent" value="" />
581 +
582 + <?php
583 + }
584 +
585 + /**
586 + * Add some JS to wp_footer to watch for hierarchical reply parent change
587 + *
588 + * If AMP is enabled, we don't make any changes.
589 + *
590 + * @since 1.4
591 + */
592 + public function watch_comment_parent() {
593 + if ( class_exists( Jetpack_AMP_Support::class ) && Jetpack_AMP_Support::is_amp_request() ) {
594 + // @todo Implement AMP support.
595 + return;
596 + }
597 + ?>
598 + <script type="text/javascript">
599 + (function () {
600 + const iframe = document.getElementById( 'jetpack_remote_comment' );
601 + <?php if ( get_option( 'thread_comments' ) && get_option( 'thread_comments_depth' ) ) : ?>
602 + const watchReply = function() {
603 + // Check addComment._Jetpack_moveForm to make sure we don't monkey-patch twice.
604 + if ( 'undefined' !== typeof addComment && ! addComment._Jetpack_moveForm ) {
605 + // Cache the Core function.
606 + addComment._Jetpack_moveForm = addComment.moveForm;
607 + const commentParent = document.getElementById( 'comment_parent' );
608 + const cancel = document.getElementById( 'cancel-comment-reply-link' );
609 +
610 + function tellFrameNewParent ( commentParentValue ) {
611 + const url = new URL( iframe.src );
612 + if ( commentParentValue ) {
613 + url.searchParams.set( 'replytocom', commentParentValue )
614 + } else {
615 + url.searchParams.delete( 'replytocom' );
616 + }
617 + if( iframe.src !== url.href ) {
618 + iframe.src = url.href;
619 + }
620 + };
621 +
622 + cancel.addEventListener( 'click', function () {
623 + tellFrameNewParent( false );
624 + } );
625 +
626 + addComment.moveForm = function ( _, parentId ) {
627 + tellFrameNewParent( parentId );
628 + return addComment._Jetpack_moveForm.apply( null, arguments );
629 + };
630 + }
631 + }
632 + document.addEventListener( 'DOMContentLoaded', watchReply );
633 + // In WP 6.4+, the script is loaded asynchronously, so we need to wait for it to load before we monkey-patch the functions it introduces.
634 + document.querySelector('#comment-reply-js')?.addEventListener( 'load', watchReply );
635 +
636 + <?php endif; ?>
637 +
638 + const commentIframes = document.getElementsByClassName('jetpack_remote_comment');
639 +
640 + window.addEventListener('message', function(event) {
641 + if (event.origin !== 'https://jetpack.wordpress.com') {
642 + return;
643 + }
644 +
645 + if (!event?.data?.iframeUniqueId && !event?.data?.height) {
646 + return;
647 + }
648 +
649 + const eventDataUniqueId = event.data.iframeUniqueId;
650 +
651 + // Change height for the matching comment iframe
652 + for (let i = 0; i < commentIframes.length; i++) {
653 + const iframe = commentIframes[i];
654 + const url = new URL(iframe.src);
655 + const iframeUniqueIdParam = url.searchParams.get('iframe_unique_id');
656 + if (iframeUniqueIdParam == event.data.iframeUniqueId) {
657 + iframe.style.height = event.data.height + 'px';
658 + return;
659 + }
660 + }
661 + });
662 + })();
663 + </script>
664 + <?php
665 + }
666 +
667 + /**
668 + * Verify the hash included in remote comments.
669 + *
670 + * If the Jetpack token is missing we return nothing,
671 + * and if the token is unknown or invalid, or comments not allowed, an error is returned.
672 + *
673 + * @since 1.4
674 + */
675 + public function pre_comment_on_post() {
676 + $post_array = stripslashes_deep( $_POST );
677 +
678 + // Bail if missing the Jetpack token.
679 + if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) || ! is_string( $post_array['sig'] ) || ! is_string( $post_array['token_key'] ) ) {
680 + unset( $_POST['hc_post_as'] );
681 + return;
682 + }
683 +
684 + if ( empty( $post_array['jetpack_comments_nonce'] ) || ! wp_verify_nonce( $post_array['jetpack_comments_nonce'], "jetpack_comments_nonce-{$post_array['comment_post_ID']}" ) ) {
685 + if ( ! isset( $_GET['only_once'] ) ) {
686 + self::retry_submit_comment_form_locally();
687 + }
688 + wp_die( esc_html__( 'Nonce verification failed.', 'jetpack' ), 400 );
689 + }
690 +
691 + if ( isset( $post_array['hc_avatar'] ) && is_string( $post_array['hc_avatar'] ) && str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
692 + $post_array['hc_avatar'] = htmlentities( $post_array['hc_avatar'], ENT_COMPAT );
693 + }
694 +
695 + $blog_token = ( new Tokens() )->get_access_token( false, $post_array['token_key'] );
696 + if ( ! $blog_token || is_wp_error( $blog_token ) ) {
697 + wp_die( esc_html__( 'Unknown security token.', 'jetpack' ), 400 );
698 + }
699 + $check = self::sign_remote_comment_parameters( $post_array, $blog_token->secret );
700 + if ( is_wp_error( $check ) ) {
701 + wp_die( esc_html( $check ) );
702 + }
703 +
704 + // Bail if token is expired or not valid.
705 + if ( ! hash_equals( $check, $post_array['sig'] ) ) {
706 + wp_die( esc_html__( 'Invalid security token.', 'jetpack' ), 400 );
707 + }
708 +
709 + /** This filter is documented in modules/comments/comments.php */
710 + if ( ! apply_filters( 'jetpack_comment_form_enabled_for_' . get_post_type( $post_array['comment_post_ID'] ), true ) ) {
711 + // In case the comment POST is legit, but the comments are
712 + // now disabled, we don't allow the comment.
713 +
714 + wp_die( esc_html__( 'Comments are not allowed.', 'jetpack' ), 403 );
715 + }
716 + }
717 +
718 + /**
719 + * Handle Jetpack Comments POST requests: process the comment form, then client-side POST the results to the self-hosted blog
720 + *
721 + * This function exists because when we submit the form via the jetpack.wordpress.com iframe
722 + * in Chrome the request comes in to Jetpack but for some reason the request doesn't have access to cookies yet.
723 + * By submitting the form again locally with the same data the process works as expected.
724 + *
725 + * @return never
726 + */
727 + public function retry_submit_comment_form_locally() {
728 + // We are not doing any validation here since all the validation will be done again by pre_comment_on_post().
729 + // phpcs:ignore WordPress.Security.NonceVerification.Missing
730 + $comment_data = stripslashes_deep( $_POST );
731 + ?>
732 + <!DOCTYPE html>
733 + <html>
734 + <head>
735 + <meta charset="utf-8">
736 + <title><?php echo esc_html__( 'Submitting Comment', 'jetpack' ); ?></title>
737 + <style type="text/css">
738 + body {
739 + display: table;
740 + width: 100%;
741 + height: 60%;
742 + position: absolute;
743 + top: 0;
744 + left: 0;
745 + overflow: hidden;
746 + color: #333;
747 + }
748 + .jetpack-comment-spinner {
749 + display: table-cell;
750 + vertical-align: middle;
751 + text-align: center;
752 + }
753 + </style>
754 + </head>
755 + <body>
756 + <div class="jetpack-comment-spinner">
757 + <?php
758 + require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-spinner.php';
759 + echo Jetpack_Spinner::render( 28 ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- static SVG markup.
760 + ?>
761 + </div>
762 + <form id="jetpack-remote-comment-post-form" action="<?php echo esc_url( get_site_url() ); ?>/wp-comments-post.php?for=jetpack&only_once=true" method="POST">
763 + <?php foreach ( $comment_data as $key => $val ) : ?>
764 + <input type="hidden" name="<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $val ); ?>" />
765 + <?php endforeach; ?>
766 + </form>
767 +
768 + <script type="text/javascript">
769 + document.getElementById("jetpack-remote-comment-post-form").submit();
770 + </script>
771 + </body>
772 + </html>
773 + <?php
774 + exit( 0 );
775 + }
776 +
777 + /** Capabilities **********************************************************/
778 +
779 + /**
780 + * Add some additional comment meta after comment is saved about what
781 + * service the comment is from, the avatar, user_id, etc...
782 + *
783 + * @since 1.4
784 + *
785 + * @param int $comment_id The comment ID.
786 + */
787 + public function add_comment_meta( $comment_id ) {
788 + // phpcs:disable WordPress.Security.NonceVerification.Missing -- The hc_* fields are authenticated by the HMAC check below.
789 + $post_array = stripslashes_deep( $_POST );
790 +
791 + // The hc_* identity fields are only trustworthy on a signed request. pre_comment_on_post() checks
792 + // that, but only on wp-comments-post.php, so re-check here for any other producer that reaches
793 + // comment_post (e.g. Carousel's unauthenticated post_attachment_comment endpoint).
794 + if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) || ! is_string( $post_array['sig'] ) || ! is_string( $post_array['token_key'] ) ) {
795 + return;
796 + }
797 + if ( isset( $post_array['hc_avatar'] ) && is_string( $post_array['hc_avatar'] ) && str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
798 + $post_array['hc_avatar'] = htmlentities( $post_array['hc_avatar'], ENT_COMPAT );
799 + }
800 + $blog_token = ( new Tokens() )->get_access_token( false, $post_array['token_key'] );
801 + if ( ! $blog_token || is_wp_error( $blog_token ) ) {
802 + return;
803 + }
804 + $check = self::sign_remote_comment_parameters( $post_array, $blog_token->secret );
805 + if ( is_wp_error( $check ) || ! hash_equals( $check, $post_array['sig'] ) ) {
806 + return;
807 + }
808 +
809 + $comment_meta = array();
810 +
811 + switch ( $this->is_highlander_comment_post() ) {
812 + case 'facebook':
813 + $comment_meta['hc_post_as'] = 'facebook';
814 + $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
815 + $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
816 + break;
817 +
818 + // phpcs:ignore WordPress.WP.CapitalPDangit
819 + case 'wordpress':
820 + // phpcs:ignore WordPress.WP.CapitalPDangit
821 + $comment_meta['hc_post_as'] = 'wordpress';
822 + $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
823 + $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
824 + $comment_meta['hc_wpcom_id_sig'] = isset( $_POST['hc_wpcom_id_sig'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_wpcom_id_sig'] ) ) : null; // since 1.9.
825 + break;
826 +
827 + case 'jetpack':
828 + $comment_meta['hc_post_as'] = 'jetpack';
829 + $comment_meta['hc_avatar'] = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
830 + $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
831 + break;
832 +
833 + }
834 + // phpcs:enable WordPress.Security.NonceVerification.Missing
835 +
836 + // Bail if no extra comment meta.
837 + if ( empty( $comment_meta ) ) {
838 + return;
839 + }
840 +
841 + // Loop through extra meta and add values.
842 + foreach ( $comment_meta as $key => $value ) {
843 + add_comment_meta( $comment_id, $key, $value, true );
844 + }
845 + }
846 +
847 + /**
848 + * Should show the subscription modal
849 + *
850 + * @return boolean
851 + */
852 + public function should_show_subscription_modal() {
853 +
854 + // Not allow it to run on self-hosted or simple sites
855 + if ( ! ( new Host() )->is_wpcom_platform() || ( new Host() )->is_wpcom_simple() ) {
856 + return false;
857 + }
858 +
859 + // phpcs:disable WordPress.Security.NonceVerification.Missing
860 + $is_current_user_subscribed = isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
861 +
862 + // Atomic sites with jetpack_verbum_subscription_modal option enabled
863 + $modal_enabled = ( new Host() )->is_woa_site() && get_option( 'jetpack_verbum_subscription_modal', true );
864 +
865 + return $modal_enabled && ! $is_current_user_subscribed;
866 + }
867 +
868 + /**
869 + * Get the data to send as an event to the parent window on subscription modal
870 + *
871 + * @param string $url url to redirect to.
872 + *
873 + * @return array
874 + */
875 + public function get_subscription_modal_data_to_parent( $url ) {
876 + // phpcs:ignore WordPress.Security.NonceVerification.Missing
877 + $current_user_email = isset( $_POST['email'] ) ? filter_var( wp_unslash( $_POST['email'] ) ) : null;
878 + // phpcs:ignore WordPress.Security.NonceVerification.Missing
879 + $post_id = isset( $_POST['comment_post_ID'] ) ? filter_var( wp_unslash( $_POST['comment_post_ID'] ) ) : null;
880 + return array(
881 + 'url' => $url,
882 + 'email' => $current_user_email,
883 + 'blog_id' => esc_attr( \Jetpack_Options::get_option( 'id' ) ),
884 + 'post_id' => esc_attr( $post_id ),
885 + 'lang' => esc_attr( get_locale() ),
886 + 'is_logged_in' => isset( $_POST['hc_userid'] ),
887 + );
888 + }
889 +
890 + /**
891 + * Track the hidden event for the subscription modal
892 + */
893 + public function subscription_modal_status_track_event() {
894 + $tracking_event = 'hidden_disabled';
895 + // Not allow it to run on self-hosted or simple sites
896 + if ( ! ( new Host() )->is_wpcom_platform() || ( new Host() )->is_wpcom_simple() ) {
897 + $tracking_event = 'hidden_self_hosted';
898 + }
899 +
900 + // phpcs:disable WordPress.Security.NonceVerification.Missing
901 + $is_current_user_subscribed = isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
902 +
903 + if ( $is_current_user_subscribed ) {
904 + $tracking_event = 'hidden_already_subscribed';
905 + }
906 +
907 + $jetpack = Jetpack::init();
908 + // $jetpack->stat automatically prepends the stat group with 'jetpack-'
909 + $jetpack->stat( 'subscribe-modal-comm', $tracking_event );
910 + $jetpack->do_stats( 'server_side' );
911 + }
912 +
913 + /**
914 + * Catch the duplicated comment error and show a custom error page
915 + *
916 + * @return never
917 + */
918 + public function capture_comment_duplicate_trigger() {
919 + if ( ! isset( $_GET['for'] ) || 'jetpack' !== $_GET['for'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
920 + exit( 0 );
921 + }
922 +
923 + ?>
924 + <!DOCTYPE html>
925 + <html <?php language_attributes(); ?>>
926 + <!--<![endif]-->
927 + <head>
928 + <meta charset="<?php bloginfo( 'charset' ); ?>" />
929 + <title>
930 + <?php
931 + wp_kses_post(
932 + printf(
933 + /* translators: %s is replaced by an ellipsis */
934 + __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
935 + '&hellip;'
936 + )
937 + );
938 + ?>
939 + </title>
940 + <style type="text/css">
941 + body {
942 + display: table;
943 + width: 100%;
944 + height: 60%;
945 + position: absolute;
946 + top: 0;
947 + left: 0;
948 + overflow: hidden;
949 + color: #333;
950 + padding-top: 3%;
951 + }
952 + div {
953 + text-align: left;
954 + margin: 0;
955 + padding: 0;
956 + display: table-cell;
957 + vertical-align: top;
958 + font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
959 + font-weight: normal;
960 + }
961 +
962 + h3 {
963 + margin: 0;
964 + padding-bottom: 3%;
965 + font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
966 + font-weight: normal;
967 + }
968 + a {
969 + text-decoration: underline;
970 + color: #333 !important;
971 + }
972 + </style>
973 + </head>
974 + <body>
975 + <div>
976 + <h3>
977 + <?php
978 + esc_html_e( 'Duplicate comment detected; it looks as though you’ve already said that!', 'jetpack' );
979 + ?>
980 + </h3>
981 + <a href="javascript:backToComments()"><?php esc_html_e( '&laquo; Back', 'jetpack' ); ?></a>
982 + </div>
983 + <script type="text/javascript">
984 + function backToComments() {
985 + const test = regexp => {
986 + return regexp.test(navigator.userAgent);
987 + };
988 + if (test(/chrome|chromium|crios|safari|edg/i)) {
989 + history.go(-2);
990 + return;
991 + }
992 + history.back();
993 + }
994 + </script>
995 +
996 + </body>
997 + </html>
998 + <?php
999 + exit( 0 );
1000 + }
1001 +
1002 + /**
1003 + * POST the submitted comment to the iframe
1004 + *
1005 + * @param string $url The comment URL origin.
1006 + */
1007 + public function capture_comment_post_redirect_to_reload_parent_frame( $url ) {
1008 + if ( ! isset( $_GET['for'] ) || 'jetpack' !== $_GET['for'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1009 + return $url;
1010 + }
1011 +
1012 + $should_show_subscription_modal = $this->should_show_subscription_modal();
1013 +
1014 + // Track event when not showing the subscription modal
1015 + if ( ! $should_show_subscription_modal ) {
1016 + $this->subscription_modal_status_track_event();
1017 + }
1018 + ?>
1019 + <!DOCTYPE html>
1020 + <html <?php language_attributes(); ?>>
1021 + <!--<![endif]-->
1022 + <head>
1023 + <meta charset="<?php bloginfo( 'charset' ); ?>" />
1024 + <title>
1025 + <?php
1026 + wp_kses_post(
1027 + printf(
1028 + /* translators: %s is replaced by an ellipsis */
1029 + __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1030 + '&hellip;'
1031 + )
1032 + );
1033 + ?>
1034 + </title>
1035 + <style type="text/css">
1036 + body {
1037 + display: table;
1038 + width: 100%;
1039 + height: 60%;
1040 + position: absolute;
1041 + top: 0;
1042 + left: 0;
1043 + overflow: hidden;
1044 + color: #333;
1045 + padding-top: 3%;
1046 + }
1047 +
1048 + h3 {
1049 + text-align: center;
1050 + margin: 0;
1051 + padding: 0;
1052 + display: table-cell;
1053 + vertical-align: top;
1054 + font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
1055 + font-weight: normal;
1056 + }
1057 +
1058 + .hidden {
1059 + opacity: 0;
1060 + }
1061 +
1062 + h3 span {
1063 + -moz-transition-property: opacity;
1064 + -moz-transition-duration: 1s;
1065 + -moz-transition-timing-function: ease-in-out;
1066 +
1067 + -webkit-transition-property: opacity;
1068 + -webkit-transition-duration: 1s;
1069 + -webbit-transition-timing-function: ease-in-out;
1070 +
1071 + -o-transition-property: opacity;
1072 + -o-transition-duration: 1s;
1073 + -o-transition-timing-function: ease-in-out;
1074 +
1075 + -ms-transition-property: opacity;
1076 + -ms-transition-duration: 1s;
1077 + -ms-transition-timing-function: ease-in-out;
1078 +
1079 + transition-property: opacity;
1080 + transition-duration: 1s;
1081 + transition-timing-function: ease-in-out;
1082 + }
1083 + </style>
1084 + </head>
1085 + <body>
1086 + <?php if ( ! $should_show_subscription_modal ) { ?>
1087 + <h3>
1088 + <?php
1089 + wp_kses_post(
1090 + printf(
1091 + /* translators: %s is replaced by HTML markup to include an ellipsis */
1092 + __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1093 + '<span id="ellipsis" class="hidden">&hellip;</span>'
1094 + )
1095 + );
1096 + ?>
1097 + </h3>
1098 + <script type="text/javascript">
1099 + try {
1100 + window.parent.location.href = <?php echo wp_json_encode( $url, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>;
1101 + window.parent.location.reload( true );
1102 + } catch (e) {
1103 + window.location.href = <?php echo wp_json_encode( $url, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>;
1104 + window.location.reload( true );
1105 + }
1106 + ellipsis = document.getElementById('ellipsis');
1107 +
1108 + function toggleEllipsis() {
1109 + ellipsis.className = ellipsis.className ? '' : 'hidden';
1110 + }
1111 +
1112 + setInterval(toggleEllipsis, 1200);
1113 + </script>
1114 + <?php } else { ?>
1115 + <h3>
1116 + <?php
1117 + wp_kses_post(
1118 + print __( 'Comment sent', 'jetpack' ) // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1119 + );
1120 + ?>
1121 + </h3>
1122 + <script type="text/javascript">
1123 + if ( window.parent && window.parent !== window ) {
1124 +
1125 + window.parent.postMessage(
1126 + {
1127 + type: 'subscriptionModalShow',
1128 + data: <?php echo wp_json_encode( $this->get_subscription_modal_data_to_parent( $url ), JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>,
1129 + },
1130 + window.location.origin
1131 + );
1132 + }
1133 + </script>
1134 + <?php } ?>
1135 + </body>
1136 + </html>
1137 + <?php
1138 + exit( 0 );
1139 + }
1140 +}
1141 +
1142 +Jetpack_Comments::init();