PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | extensions/blocks/premium-content/_inc/access-check.php +67 -11 16.3-a.3 → 16.3 View file →
@@ -251,8 +251,66 @@
251 251 if ( empty( $selected_plan_ids ) ) {
252 252 return false;
253 253 }
254 254
255 + $can_view = visitor_can_access_plan_ids( $selected_plan_ids );
256 +
257 + if ( $can_view ) {
258 + /**
259 + * Fires when a visitor can view protected content on a site.
260 + *
261 + * @since 9.4.0
262 + */
263 + do_action( 'jetpack_earn_remove_cache_headers' );
264 + }
265 +
266 + return $can_view;
267 +}
268 +
269 +/**
270 + * Check plan access for rendering, including the subscription service's editorial exception.
271 + *
272 + * Playback callers must use visitor_has_subscription_access_to_plan_ids() to exclude editorial access.
273 + *
274 + * @since $$next-version$$
275 + *
276 + * @param array $selected_plan_ids Plan ids the content is gated behind.
277 + * @param int|null $post_id Post the gated content belongs to. Defaults to the loop post, so
278 + * callers outside the loop must pass it.
279 + *
280 + * @return bool Whether the visitor can view the content.
281 + */
282 +function visitor_can_access_plan_ids( $selected_plan_ids, $post_id = null ) {
283 + return check_subscription_plan_access( $selected_plan_ids, $post_id, false );
284 +}
285 +
286 +/**
287 + * Check the required plans without granting access for editing the embedding post.
288 + *
289 + * @since $$next-version$$
290 + *
291 + * @param array $selected_plan_ids Required plan IDs from the stored content.
292 + * @param int|null $post_id Post to check, or the loop post when omitted.
293 + * @return bool Whether the visitor has the required subscription entitlement.
294 + */
295 +function visitor_has_subscription_access_to_plan_ids( $selected_plan_ids, $post_id = null ) {
296 + return check_subscription_plan_access( $selected_plan_ids, $post_id, true );
297 +}
298 +
299 +/**
300 + * Evaluate subscription plans for rendering or strict playback authorization.
301 + *
302 + * @since $$next-version$$
303 + *
304 + * @param array $selected_plan_ids Required subscription plan IDs.
305 + * @param int|null $post_id Post to check.
306 + * @param bool $require_entitlement Whether editorial access must be excluded.
307 + * @return bool Whether access is granted.
308 + */
309 +function check_subscription_plan_access( $selected_plan_ids, $post_id, $require_entitlement ) {
310 + // Callers outside the block render can get here first; this also defines the constants the paywall reads.
311 + require_once JETPACK__PLUGIN_DIR . 'modules/memberships/class-jetpack-memberships.php';
312 +
255 313 $can_view = false;
256 314 $paywall = subscription_service();
257 315 $access_level = Abstract_Token_Subscription_Service::POST_ACCESS_LEVEL_PAID_SUBSCRIBERS; // Only paid subscribers should be granted access to the premium content
258 316 $tier_ids = \Jetpack_Memberships::get_all_newsletter_plan_ids();
@@ -310,19 +368,17 @@
310 368 }
311 369
312 370 $non_tier_ids = array_diff( $selected_plan_ids, $tier_ids );
313 371 if ( ! $can_view ) {
314 - // For selected plans that are not tiers, we want to check if the user has any of the selected plans.
315 - $can_view = $paywall->visitor_can_view_content( $non_tier_ids, $access_level );
316 - }
317 -
318 - if ( $can_view ) {
319 - /**
320 - * Fires when a visitor can view protected content on a site.
321 - *
322 - * @since 9.4.0
323 - */
324 - do_action( 'jetpack_earn_remove_cache_headers' );
372 + if ( $require_entitlement ) {
373 + // Older or external services without the entitlement check deny.
374 + $can_view = is_callable( array( $paywall, 'visitor_has_subscription_access' ) )
375 + && $paywall->visitor_has_subscription_access( $non_tier_ids, $access_level, $post_id );
376 + } else {
377 + // For selected plans that are not tiers, we want to check if the user has any of the selected plans.
378 + // @phan-suppress-next-line PhanParamTooMany -- Concrete services accept the optional $post_id; interface omits it on purpose.
379 + $can_view = $paywall->visitor_can_view_content( $non_tier_ids, $access_level, $post_id );
380 + }
325 381 }
326 382
327 383 return $can_view;
328 384 }