| @@ -936,8 +936,15 @@ | ||
| 936 | 936 | // whether the editor's recipient field is editable. Approximated with |
| 937 | 937 | // manage_options so editors, who can only test-send to themselves, |
| 938 | 938 | // aren't shown an editable field that would always be rejected. |
| 939 | 939 | 'can_send_test_email_to_others' => current_user_can( 'manage_options' ), |
| 940 | + // Which settings-driven subscribe placements are on, for the Site Editor's admin-only notice. | |
| 941 | + 'subscribe_placements' => current_user_can( 'manage_options' ) ? array( | |
| 942 | + 'sm_enabled' => (bool) get_option( 'sm_enabled', false ), | |
| 943 | + 'jetpack_subscribe_overlay_enabled' => (bool) get_option( 'jetpack_subscribe_overlay_enabled', false ), | |
| 944 | + 'jetpack_subscribe_floating_button_enabled' => (bool) get_option( 'jetpack_subscribe_floating_button_enabled', false ), | |
| 945 | + 'wpcom_action_bar' => ( new Host() )->is_wpcom_simple() && ! get_option( 'wpcom_hide_action_bar' ), | |
| 946 | + ) : null, | |
| 940 | 947 | // this is the equivalent of JP initial state siteData.showMyJetpack (class-jetpack-redux-state-helper) |
| 941 | 948 | // used to determine if we can link to My Jetpack from the block editor |
| 942 | 949 | 'is_my_jetpack_available' => My_Jetpack_Initializer::should_initialize(), |
| 943 | 950 | 'jetpack_plan' => array( |
| @@ -1574,8 +1581,16 @@ | ||
| 1574 | 1581 | $url_components = wp_parse_url( $url ); |
| 1575 | 1582 | |
| 1576 | 1583 | // Bail early if we cannot find a host. |
| 1577 | 1584 | if ( empty( $url_components['host'] ) ) { |
| 1585 | + return false; | |
| 1586 | + } | |
| 1587 | + | |
| 1588 | + // Only http and https URLs are valid. | |
| 1589 | + if ( | |
| 1590 | + isset( $url_components['scheme'] ) | |
| 1591 | + && ! in_array( strtolower( $url_components['scheme'] ), array( 'http', 'https' ), true ) | |
| 1592 | + ) { | |
| 1578 | 1593 | return false; |
| 1579 | 1594 | } |
| 1580 | 1595 | |
| 1581 | 1596 | // Normalize URL. |