PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-comments/src/identity/class-identity.php +45 -9 16.2 → 16.3 View file →
@@ -19,10 +19,13 @@
19 19 */
20 20 public static function settings() {
21 21 $commenter = wp_get_current_commenter();
22 22
23 + // Nothing under `identity` is about the visitor: the HTML is page-cached
24 + // and served to everyone, so who holds a passport comes from a cookie.
23 25 $settings = array(
24 26 'isLoggedIn' => is_user_logged_in(),
27 + 'avatarUrl' => '',
25 28 'commenter' => array(
26 29 'author' => $commenter['comment_author'],
27 30 'email' => $commenter['comment_author_email'],
28 31 'url' => $commenter['comment_author_url'],
@@ -27,21 +30,54 @@
27 30 'email' => $commenter['comment_author_email'],
28 31 'url' => $commenter['comment_author_url'],
29 32 ),
30 33 'user' => null,
34 + 'identity' => array(
35 + 'blogId' => Checkpoint::blog_id(),
36 + 'canSignIn' => false,
37 + 'connect' => null,
38 + 'connectUrl' => Checkpoint_Endpoint::route_url( Checkpoint_Endpoint::CONNECT_ROUTE ),
39 + 'emailUrl' => Checkpoint_Endpoint::route_url( Checkpoint_Endpoint::EMAIL_ROUTE ),
40 + 'origin' => 'https://public-api.wordpress.com',
41 + 'codeField' => Checkpoint::CODE_FIELD,
42 + 'passportField' => Checkpoint::PASSPORT_FIELD,
43 + 'displayCookie' => Passport::DISPLAY_COOKIE,
44 + 'cookieHash' => COOKIEHASH,
45 + 'cookiePath' => COOKIEPATH,
46 + 'cookieDomain' => COOKIE_DOMAIN ? COOKIE_DOMAIN : '',
47 + 'defaultAvatar' => Avatars::default_url( 80 ),
48 + // A path: Simple's admin_url() is the .wordpress.com host, which cannot clear a custom domain's cookies.
49 + 'logoutUrl' => wp_make_link_relative( admin_url( 'admin-ajax.php' ) ),
50 + 'logoutAction' => Checkpoint_Endpoint::LOGOUT_ACTION,
51 + ),
31 52 );
32 53
33 54 if ( is_user_logged_in() ) {
34 - $user = wp_get_current_user();
35 - $settings['user'] = array(
36 - 'avatarUrl' => get_avatar_url( $user->ID, array( 'size' => 74 ) ),
37 - 'commentingAs' => sprintf(
38 - /* translators: %s is the display name of the logged-in user. */
39 - __( 'Commenting as %s', 'jetpack-comments' ),
40 - $user->display_name
41 - ),
42 - );
55 + $user = wp_get_current_user();
56 + $settings['avatarUrl'] = html_entity_decode( (string) get_avatar_url( $user->ID, array( 'size' => 80 ) ), ENT_QUOTES );
57 + $settings['user'] = array( 'name' => $user->display_name );
58 +
59 + return $settings;
43 60 }
61 +
62 + if ( get_option( 'show_avatars' ) ) {
63 + $settings['avatarUrl'] = $commenter['comment_author_email']
64 + ? html_entity_decode( (string) get_avatar_url( $commenter['comment_author_email'], array( 'size' => 80 ) ), ENT_QUOTES )
65 + : Avatars::default_url( 80 );
66 + }
67 +
68 + if ( ! Checkpoint::is_available() ) {
69 + return $settings;
70 + }
71 +
72 + // Visitors share this challenge until it expires: it only filters messages
73 + // to the window that opened the popup, and the connect route issues fresh ones.
74 + $challenge = rtrim( strtr( base64_encode( random_bytes( 32 ) ), '+/', '-_' ), '=' ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- base64url is the wire format.
75 +
76 + $connect = Checkpoint::connect_url( $challenge );
77 +
78 + $settings['identity']['canSignIn'] = true;
79 + $settings['identity']['connect'] = is_wp_error( $connect ) ? null : $connect;
44 80
45 81 return $settings;
46 82 }
47 83 }