PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | modules/memberships/class-jetpack-memberships.php +33 -3 16.3-a.7 → 16.3 View file →
@@ -825,8 +825,31 @@
825 825 *
826 826 * @return bool Whether the post can be viewed
827 827 */
828 828 public static function user_can_view_post( $post_id = null ) {
829 + return self::check_post_access( $post_id, true );
830 + }
831 +
832 + /**
833 + * Check the post's subscription requirement without granting access for editing it.
834 + *
835 + * @since $$next-version$$
836 + *
837 + * @param int|null $post_id Explicit post ID, or the loop post when omitted.
838 + * @return bool Whether the visitor meets the post's subscription requirement.
839 + */
840 + public static function user_has_subscription_access( $post_id = null ) {
841 + return self::check_post_access( $post_id, false );
842 + }
843 +
844 + /**
845 + * Evaluate and cache post access with or without the editorial exception.
846 + *
847 + * @param int|null $post_id Post to check.
848 + * @param bool $allow_editor_access Whether editing the post can grant access.
849 + * @return bool Whether access is granted.
850 + */
851 + private static function check_post_access( $post_id, $allow_editor_access ) {
829 852 $user_id = get_current_user_id();
830 853 if ( null === $post_id ) {
831 854 $post_id = get_the_ID();
832 855 }
@@ -834,9 +857,9 @@
834 857 if ( false === $post_id ) {
835 858 $post_id = 0;
836 859 }
837 860
838 - $cache_key = sprintf( '%d_%d', $user_id, $post_id );
861 + $cache_key = sprintf( '%d_%d_%d', $user_id, $post_id, (int) $allow_editor_access );
839 862 if ( isset( self::$user_can_view_post_cache[ $cache_key ] ) ) {
840 863 return self::$user_can_view_post_cache[ $cache_key ];
841 864 }
842 865
@@ -846,9 +869,9 @@
846 869 return true;
847 870 }
848 871
849 872 // we are sending the post to subscribers so the user is a subscriber
850 - if ( defined( 'WPCOM_SENDING_POST_TO_SUBSCRIBERS' ) && WPCOM_SENDING_POST_TO_SUBSCRIBERS && Abstract_Token_Subscription_Service::POST_ACCESS_LEVEL_SUBSCRIBERS === $post_access_level ) {
873 + if ( $allow_editor_access && defined( 'WPCOM_SENDING_POST_TO_SUBSCRIBERS' ) && WPCOM_SENDING_POST_TO_SUBSCRIBERS && Abstract_Token_Subscription_Service::POST_ACCESS_LEVEL_SUBSCRIBERS === $post_access_level ) {
851 874 self::$user_can_view_post_cache[ $cache_key ] = true;
852 875 return true;
853 876 }
854 877
@@ -867,9 +890,16 @@
867 890 // We downgrade the post level to subscribers-only
868 891 $post_access_level = Abstract_Token_Subscription_Service::POST_ACCESS_LEVEL_SUBSCRIBERS;
869 892 }
870 893
871 - $can_view_post = $paywall->visitor_can_view_content( $all_newsletters_plan_ids, $post_access_level );
894 + // Pass the post explicitly: callers outside the loop have no get_the_ID() to fall back on.
895 + if ( $allow_editor_access ) {
896 + // @phan-suppress-next-line PhanParamTooMany -- Concrete services accept the optional $post_id; interface omits it on purpose.
897 + $can_view_post = $paywall->visitor_can_view_content( $all_newsletters_plan_ids, $post_access_level, $post_id );
898 + } else {
899 + $can_view_post = is_callable( array( $paywall, 'visitor_has_subscription_access' ) )
900 + && $paywall->visitor_has_subscription_access( $all_newsletters_plan_ids, $post_access_level, $post_id );
901 + }
872 902
873 903 self::$user_can_view_post_cache[ $cache_key ] = $can_view_post;
874 904 return $can_view_post;
875 905 }