PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-comments/src/class-avatars.php +9 -39 16.3-a.3 → 16.3 View file →
@@ -14,20 +14,8 @@
14 14 */
15 15 class Avatars {
16 16
17 17 /**
18 - * Comment meta Highlander and Verbum wrote a stored avatar URL to.
19 - */
20 - const AVATAR_META = 'hc_avatar';
21 -
22 - /**
23 - * Hosts whose avatars are served.
24 - *
25 - * @var string[]
26 - */
27 - private static $avatar_hosts = array( 'graph.facebook.com', 'twimg.com' );
28 -
29 - /**
30 18 * Register the avatar filters.
31 19 *
32 20 * @return void
33 21 */
@@ -54,9 +42,9 @@
54 42 if ( null !== $url ) {
55 43 $args['url'] = $url;
56 44 $args['found_avatar'] = true;
57 45 } elseif ( self::is_signed_in( (int) $id_or_email->comment_ID ) ) {
58 - // The provider had no photo, so show the site default rather than a Gravatar the commenter never chose.
46 + // The provider had no photo: the site default, not a Gravatar the commenter never chose.
59 47 $args['force_default'] = true;
60 48 }
61 49
62 50 return $args;
@@ -98,11 +86,12 @@
98 86 */
99 87 public static function default_url( $size ) {
100 88 if ( function_exists( 'wpcom_get_avatar_url' ) ) {
101 89 // Re-enters wpcom_avatar_url() with no comment, so it returns early there.
102 - $url_class = wpcom_get_avatar_url( '', $size, '', true, true );
90 + $url_class = wpcom_get_avatar_url( '', $size, '', false, true );
103 91
104 - return is_array( $url_class ) ? (string) $url_class[0] : '';
92 + // Built for HTML, so its query string is joined with &, which Gravatar reads as a parameter named amp;d.
93 + return is_array( $url_class ) ? html_entity_decode( (string) $url_class[0], ENT_QUOTES ) : '';
105 94 }
106 95
107 96 return (string) get_avatar_url(
108 97 '',
@@ -143,11 +132,14 @@
143 132 // Written only from an authenticated exchange with WordPress.com, so any https URL is served.
144 133 $stored = get_comment_meta( $comment_id, Checkpoint::META_AVATAR, true );
145 134
146 135 if ( ! is_string( $stored ) || $stored === '' || 'https' !== wp_parse_url( $stored, PHP_URL_SCHEME ) ) {
147 - $stored = get_comment_meta( $comment_id, self::AVATAR_META, true );
136 + // Highlander and Verbum stored a Facebook or X avatar here, which the email cannot
137 + // bring back. Written by the browser, so only those two hosts are served.
138 + $stored = get_comment_meta( $comment_id, 'hc_avatar', true );
139 + $host = is_string( $stored ) ? wp_parse_url( $stored, PHP_URL_HOST ) : null;
148 140
149 - if ( ! is_string( $stored ) || $stored === '' || ! self::is_servable_avatar( $stored ) ) {
141 + if ( ! is_string( $host ) || ! preg_match( '/(^|\.)(graph\.facebook\.com|twimg\.com)$/', $host ) ) {
150 142 $stored = null;
151 143 }
152 144 }
153 145
@@ -153,28 +145,6 @@
153 145
154 146 $resolved[ $key ] = null === $stored ? null : Image_CDN_Core::cdn_url( $stored, array( 'resize' => "$size,$size" ) );
155 147
156 148 return $resolved[ $key ];
157 - }
158 -
159 - /**
160 - * Whether a stored avatar URL is one we are willing to serve.
161 - *
162 - * @param string $url The stored avatar URL.
163 - * @return bool
164 - */
165 - private static function is_servable_avatar( $url ) {
166 - $host = wp_parse_url( $url, PHP_URL_HOST );
167 -
168 - if ( ! is_string( $host ) ) {
169 - return false;
170 - }
171 -
172 - foreach ( self::$avatar_hosts as $allowed ) {
173 - if ( $host === $allowed || str_ends_with( $host, ".$allowed" ) ) {
174 - return true;
175 - }
176 - }
177 -
178 - return false;
179 149 }
180 150 }