PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 8.2.6
Jetpack – WP Security, Backup, Speed, & Growth v8.2.6
16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 All 501 releases
jetpack / modules / shortcodes / youtube.php

youtube.php in Jetpack – WP Security, Backup, Speed, & Growth 8.2.6, at modules/shortcodes/youtube.php

506 lines 17.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Youtube shortcode
4 *
5 * Contains shortcode + some improvements over the Core Embeds syntax (see http://codex.wordpress.org/Embeds )
6 *
7 * Examples:
8 * [youtube https://www.youtube.com/watch?v=WVbQ-oro7FQ]
9 * [youtube=http://www.youtube.com/watch?v=wq0rXGLs0YM&fs=1&hl=bg_BG&autohide=1&rel=0]
10 * http://www.youtube.com/watch?v=H2Ncxw1xfck&w=320&h=240&fmt=1&rel=0&showsearch=1&hd=0
11 * http://www.youtube.com/v/9FhMMmqzbD8?fs=1&hl=en_US
12 * https://www.youtube.com/playlist?list=PLP7HaNDU4Cifov7C2fQM8Ij6Ew_uPHEXW
13 *
14 * @package Jetpack
15 */
16
17 /**
18 * Replaces YouTube embeds with YouTube shortcodes.
19 *
20 * Covers the following formats:
21 * 2008-07-15:
22 * <object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/bZBHZT3a-FA&hl=en&fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/bZBHZT3a-FA&hl=en&fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object>
23 * around 2008-06-06 youtube changed their old embed code to this:
24 * <object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/M1D30gS7Z8U&hl=en"></param><embed src="http://www.youtube.com/v/M1D30gS7Z8U&hl=en" type="application/x-shockwave-flash" width="425" height="344"></embed></object>
25 * old style was:
26 * <object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/dGY28Qbj76A&rel=0"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/dGY28Qbj76A&rel=0" type="application/x-shockwave-flash" wmode="transparent" width="425" height="344"></embed></object>
27 * 12-2010:
28 * <object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/3H8bnKdf654?fs=1&amp;hl=en_GB"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/3H8bnKdf654?fs=1&amp;hl=en_GB" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"></embed></object>
29 * 01-2011:
30 * <iframe title="YouTube video player" class="youtube-player" type="text/html" width="640" height="390" src="http://www.youtube.com/embed/Qq9El3ki0_g" frameborder="0" allowFullScreen></iframe>
31 * <iframe class="youtube-player" type="text/html" width="640" height="385" src="http://www.youtube.com/embed/VIDEO_ID" frameborder="0"></iframe>
32 *
33 * @param string $content HTML content.
34 * @return string The content with YouTube embeds replaced with YouTube shortcodes.
35 */
36 function youtube_embed_to_short_code( $content ) {
37 if ( ! is_string( $content ) || false === strpos( $content, 'youtube.com' ) ) {
38 return $content;
39 }
40
41 // older codes.
42 $regexp = '!<object(.*?)>.*?<param\s+name=[\'"]movie[\'"]\s+value=[\'"](https?:)?//www\.youtube\.com/v/([^\'"]+)[\'"].*?>.*?</object>!i';
43 $regexp_ent = htmlspecialchars( $regexp, ENT_NOQUOTES );
44 $old_regexp = '!<embed(?:\s+\w+="[^"]*")*\s+src="https?(?:\:|&#0*58;)//www\.youtube\.com/v/([^"]+)"(?:\s+\w+="[^"]*")*\s*(?:/>|>\s*</embed>)!';
45 $old_regexp_ent = str_replace( '&amp;#0*58;', '&amp;#0*58;|&#0*58;', htmlspecialchars( $old_regexp, ENT_NOQUOTES ) );
46
47 // new code.
48 $ifr_regexp = '!<iframe((?:\s+\w+="[^"]*")*?)\s+src="(https?:)?//(?:www\.)*youtube.com/embed/([^"]+)".*?</iframe>!i';
49 $ifr_regexp_ent = str_replace( '&amp;#0*58;', '&amp;#0*58;|&#0*58;', htmlspecialchars( $ifr_regexp, ENT_NOQUOTES ) );
50
51 foreach ( compact( 'regexp', 'regexp_ent', 'old_regexp', 'old_regexp_ent', 'ifr_regexp', 'ifr_regexp_ent' ) as $reg => $regexp ) {
52 if ( ! preg_match_all( $regexp, $content, $matches, PREG_SET_ORDER ) ) {
53 continue;
54 }
55
56 foreach ( $matches as $match ) {
57 /*
58 * Hack, but '?' should only ever appear once, and
59 * it should be for the 1st field-value pair in query string,
60 * if it is present
61 * YouTube changed their embed code.
62 * Example of how it is now:
63 * <object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/aP9AaD4tgBY?fs=1&amp;hl=en_US"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/aP9AaD4tgBY?fs=1&amp;hl=en_US" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"></embed></object>
64 * As shown at the start of function, previous YouTube didn't '?'
65 * the 1st field-value pair.
66 */
67 if ( in_array( $reg, array( 'ifr_regexp', 'ifr_regexp_ent', 'regexp', 'regexp_ent' ), true ) ) {
68 $params = $match[1];
69
70 if ( in_array( $reg, array( 'ifr_regexp_ent', 'regexp_ent' ), true ) ) {
71 $params = html_entity_decode( $params );
72 }
73
74 $params = wp_kses_hair( $params, array( 'http' ) );
75
76 $width = isset( $params['width'] ) ? (int) $params['width']['value'] : 0;
77 $height = isset( $params['height'] ) ? (int) $params['height']['value'] : 0;
78 $wh = '';
79
80 if ( $width && $height ) {
81 $wh = "&w=$width&h=$height";
82 }
83
84 $url = esc_url_raw( "https://www.youtube.com/watch?v={$match[3]}{$wh}" );
85 } else {
86 $match[1] = str_replace( '?', '&', $match[1] );
87
88 $url = esc_url_raw( 'https://www.youtube.com/watch?v=' . html_entity_decode( $match[1] ) );
89 }
90
91 $content = str_replace( $match[0], "[youtube $url]", $content );
92
93 /**
94 * Fires before the YouTube embed is transformed into a shortcode.
95 *
96 * @module shortcodes
97 *
98 * @since 1.2.0
99 *
100 * @param string youtube Shortcode name.
101 * @param string $url YouTube video URL.
102 */
103 do_action( 'jetpack_embed_to_shortcode', 'youtube', $url );
104 }
105 }
106
107 return $content;
108 }
109 add_filter( 'pre_kses', 'youtube_embed_to_short_code' );
110
111 /**
112 * Replaces plain-text links to YouTube videos with YouTube embeds.
113 *
114 * @param string $content HTML content.
115 *
116 * @return string The content with embeds instead of URLs
117 */
118 function youtube_link( $content ) {
119 return jetpack_preg_replace_callback_outside_tags( '!(?:\n|\A)https?://(?:www\.)?(?:youtube.com/(?:v/|playlist|watch[/\#?])|youtu\.be/)[^\s]+?(?:\n|\Z)!i', 'youtube_link_callback', $content, 'youtube.com/' );
120 }
121
122 /**
123 * Callback function for the regex that replaces YouTube URLs with
124 * YouTube embeds.
125 *
126 * @param array $matches An array containing a YouTube URL.
127 */
128 function youtube_link_callback( $matches ) {
129 return "\n" . youtube_id( $matches[0] ) . "\n";
130 }
131
132 /**
133 * Normalizes a YouTube URL to include a v= parameter and a query string free of encoded ampersands.
134 *
135 * @param string $url
136 * @return string The normalized URL
137 */
138 if ( ! function_exists( 'youtube_sanitize_url' ) ) :
139 /**
140 * Clean up Youtube URL to match a single format.
141 *
142 * @param string $url Youtube URL.
143 */
144 function youtube_sanitize_url( $url ) {
145 $url = trim( $url, ' "' );
146 $url = trim( $url );
147 $url = str_replace( array( 'youtu.be/', '/v/', '#!v=', '&amp;', '&#038;', 'playlist' ), array( 'youtu.be/?v=', '/?v=', '?v=', '&', '&', 'videoseries' ), $url );
148
149 // Replace any extra question marks with ampersands - the result of a URL like "http://www.youtube.com/v/9FhMMmqzbD8?fs=1&hl=en_US" being passed in.
150 $query_string_start = strpos( $url, '?' );
151
152 if ( false !== $query_string_start ) {
153 $url = substr( $url, 0, $query_string_start + 1 ) . str_replace( '?', '&', substr( $url, $query_string_start + 1 ) );
154 }
155
156 return $url;
157 }
158 endif;
159
160 /**
161 * Converts a YouTube URL into an embedded YouTube video.
162 *
163 * URL can be:
164 * http://www.youtube.com/embed/videoseries?list=PL94269DA08231042B&amp;hl=en_US
165 * http://www.youtube.com/watch#!v=H2Ncxw1xfck
166 * http://www.youtube.com/watch?v=H2Ncxw1xfck
167 * http://www.youtube.com/watch?v=H2Ncxw1xfck&w=320&h=240&fmt=1&rel=0&showsearch=1&hd=0
168 * http://www.youtube.com/v/jF-kELmmvgA
169 * http://www.youtube.com/v/9FhMMmqzbD8?fs=1&hl=en_US
170 * http://youtu.be/Rrohlqeir5E
171 *
172 * @param string $url Youtube URL.
173 */
174 function youtube_id( $url ) {
175 $id = jetpack_get_youtube_id( $url );
176
177 if ( ! $id ) {
178 return sprintf( '<!--%s-->', esc_html__( 'YouTube Error: bad URL entered', 'jetpack' ) );
179 }
180
181 $url = youtube_sanitize_url( $url );
182 $url = wp_parse_url( $url );
183
184 $args = jetpack_shortcode_youtube_args( $url );
185 if ( empty( $args ) ) {
186 return sprintf( '<!--%s-->', esc_html__( 'YouTube Error: empty URL args', 'jetpack' ) );
187 }
188
189 list( $w, $h ) = jetpack_shortcode_youtube_dimensions( $args );
190 $rel = ( isset( $args['rel'] ) && '0' === $args['rel'] ) ? 0 : 1;
191 $search = ( isset( $args['showsearch'] ) && '1' === $args['showsearch'] ) ? 1 : 0;
192 $info = ( isset( $args['showinfo'] ) && '0' === $args['showinfo'] ) ? 0 : 1;
193 $iv = ( isset( $args['iv_load_policy'] ) && '3' === $args['iv_load_policy'] ) ? 3 : 1;
194
195 $fmt = ( isset( $args['fmt'] ) && intval( $args['fmt'] ) ) ? '&fmt=' . (int) $args['fmt'] : '';
196
197 if ( ! isset( $args['autohide'] ) || ( $args['autohide'] < 0 || 2 < $args['autohide'] ) ) {
198 $autohide = '&autohide=2';
199 } else {
200 $autohide = '&autohide=' . absint( $args['autohide'] );
201 }
202
203 $start = 0;
204 if ( isset( $args['start'] ) ) {
205 $start = intval( $args['start'] );
206 } elseif ( isset( $args['t'] ) ) {
207 $time_pieces = preg_split( '/(?<=\D)(?=\d+)/', $args['t'] );
208
209 foreach ( $time_pieces as $time_piece ) {
210 $int = (int) $time_piece;
211 switch ( substr( $time_piece, -1 ) ) {
212 case 'h':
213 $start += $int * 3600;
214 break;
215 case 'm':
216 $start += $int * 60;
217 break;
218 case 's':
219 $start += $int;
220 break;
221 }
222 }
223 }
224
225 $start = $start ? '&start=' . $start : '';
226 $end = ( isset( $args['end'] ) && intval( $args['end'] ) ) ? '&end=' . (int) $args['end'] : '';
227 $hd = ( isset( $args['hd'] ) && intval( $args['hd'] ) ) ? '&hd=' . (int) $args['hd'] : '';
228
229 $vq = ( isset( $args['vq'] ) && in_array( $args['vq'], array( 'hd720', 'hd1080' ), true ) ) ? '&vq=' . $args['vq'] : '';
230
231 $cc = ( isset( $args['cc_load_policy'] ) ) ? '&cc_load_policy=1' : '';
232 $cc_lang = ( isset( $args['cc_lang_pref'] ) ) ? '&cc_lang_pref=' . preg_replace( '/[^_a-z0-9-]/i', '', $args['cc_lang_pref'] ) : '';
233
234 $wmode = ( isset( $args['wmode'] ) && in_array( strtolower( $args['wmode'] ), array( 'opaque', 'window', 'transparent' ), true ) ) ? $args['wmode'] : 'transparent';
235
236 $theme = ( isset( $args['theme'] ) && in_array( strtolower( $args['theme'] ), array( 'dark', 'light' ), true ) ) ? '&theme=' . $args['theme'] : '';
237
238 $autoplay = '';
239 /**
240 * Allow YouTube videos to start playing automatically.
241 *
242 * @module shortcodes
243 *
244 * @since 2.2.2
245 *
246 * @param bool false Enable autoplay for YouTube videos.
247 */
248 if ( apply_filters( 'jetpack_youtube_allow_autoplay', false ) && isset( $args['autoplay'] ) ) {
249 $autoplay = '&autoplay=' . (int) $args['autoplay'];
250 }
251
252 if (
253 ( isset( $url['path'] ) && '/videoseries' === $url['path'] )
254 || isset( $args['list'] )
255 ) {
256 $html = "<iframe class='youtube-player' type='text/html' width='$w' height='$h' src='" . esc_url( "https://www.youtube.com/embed/videoseries?list=$id&hl=en_US" ) . "' allowfullscreen='true' style='border:0;'></iframe>";
257 } else {
258 $html = "<iframe class='youtube-player' type='text/html' width='$w' height='$h' src='" . esc_url( "https://www.youtube.com/embed/$id?version=3&rel=$rel&fs=1$fmt$autohide&showsearch=$search&showinfo=$info&iv_load_policy=$iv$start$end$hd&wmode=$wmode$theme$autoplay$vq{$cc}{$cc_lang}" ) . "' allowfullscreen='true' style='border:0;'></iframe>";
259 }
260
261 // Let's do some alignment wonder in a span, unless we're producing a feed.
262 if ( ! is_feed() ) {
263 $alignmentcss = 'text-align:center;';
264 if ( isset( $args['align'] ) ) {
265 switch ( $args['align'] ) {
266 case 'left':
267 $alignmentcss = "float:left; width:{$w}px; height:{$h}px; margin-right:10px; margin-bottom: 10px;";
268 break;
269 case 'right':
270 $alignmentcss = "float:right; width:{$w}px; height:{$h}px; margin-left:10px; margin-bottom: 10px;";
271 break;
272 }
273 }
274
275 $html = sprintf(
276 '<span class="embed-youtube" style="%s display: block;">%s</span>',
277 esc_attr( $alignmentcss ),
278 $html
279 );
280
281 }
282
283 /**
284 * Filter the YouTube video HTML output.
285 *
286 * @module shortcodes
287 *
288 * @since 1.2.3
289 *
290 * @param string $html YouTube video HTML output.
291 */
292 $html = apply_filters( 'video_embed_html', $html );
293
294 return $html;
295 }
296
297 /**
298 * Gets the args present in the YouTube shortcode URL.
299 *
300 * @since 8.0.0
301 *
302 * @param string $url The URL of the shortcode.
303 *
304 * @return array|false The query args of the URL, or false.
305 */
306 function jetpack_shortcode_youtube_args( $url ) {
307 $qargs = array();
308 if ( ! empty( $url['query'] ) ) {
309 wp_parse_str( $url['query'], $qargs );
310 } else {
311 return false;
312 }
313
314 $fargs = array();
315 if ( ! empty( $url['fragment'] ) ) {
316 wp_parse_str( $url['fragment'], $fargs );
317 }
318
319 return array_merge( $fargs, $qargs );
320 }
321
322 /**
323 * Display the Youtube shortcode.
324 *
325 * @param array $atts Shortcode attributes.
326 *
327 * @return string The rendered shortcode.
328 */
329 function youtube_shortcode( $atts ) {
330 $url = ( isset( $atts[0] ) ) ? ltrim( $atts[0], '=' ) : shortcode_new_to_old_params( $atts );
331
332 if (
333 class_exists( 'Jetpack_AMP_Support' )
334 && Jetpack_AMP_Support::is_amp_request()
335 ) {
336 return jetpack_amp_youtube_shortcode( $url );
337 } else {
338 return youtube_id( $url );
339 }
340 }
341 add_shortcode( 'youtube', 'youtube_shortcode' );
342
343 /**
344 * Renders the [youtube] shortcode as an AMP component.
345 *
346 * @since 8.0.0
347 *
348 * @param string $url The YouTube URL.
349 *
350 * @return string The AMP-compatible rendered shortcode.
351 */
352 function jetpack_amp_youtube_shortcode( $url ) {
353 $video_id = jetpack_get_youtube_id( $url );
354 if ( empty( $video_id ) ) {
355 return sprintf(
356 '<a href="%1$s" class="amp-wp-embed-fallback">%1$s</a>',
357 esc_url( $url )
358 );
359 }
360
361 $sanitized_url = youtube_sanitize_url( $url );
362 $parsed_url = wp_parse_url( $sanitized_url );
363 $args = jetpack_shortcode_youtube_args( $parsed_url );
364 list( $width, $height ) = jetpack_shortcode_youtube_dimensions( $args );
365 return sprintf(
366 '<amp-youtube data-videoid="%s" layout="responsive" width="%d" height="%d"></amp-youtube>',
367 esc_attr( $video_id ),
368 absint( $width ),
369 absint( $height )
370 );
371 }
372
373 /**
374 * Gets the dimensions of the [youtube] shortcode.
375 *
376 * Calculates the width and height, taking $content_width into consideration.
377 *
378 * @since 8.0.0
379 *
380 * @param array $query_args The query args of the URL.
381 *
382 * @return array The width and height of the shortcode.
383 */
384 function jetpack_shortcode_youtube_dimensions( $query_args ) {
385 global $content_width;
386
387 $input_w = ( isset( $query_args['w'] ) && intval( $query_args['w'] ) ) ? intval( $query_args['w'] ) : 0;
388 $input_h = ( isset( $query_args['h'] ) && intval( $query_args['h'] ) ) ? intval( $query_args['h'] ) : 0;
389
390 // If we have $content_width, use it.
391 if ( ! empty( $content_width ) ) {
392 $default_width = $content_width;
393 } else {
394 // Otherwise get default width from the old, now deprecated embed_size_w option.
395 $default_width = get_option( 'embed_size_w' );
396 }
397
398 // If we don't know those 2 values use a hardcoded width.
399 if ( empty( $default_width ) ) {
400 $default_width = 640;
401 }
402
403 if ( $input_w > 0 && $input_h > 0 ) {
404 $w = $input_w;
405 $h = $input_h;
406 } elseif ( 0 === $input_w && 0 === $input_h ) {
407 if ( isset( $query_args['fmt'] ) && intval( $query_args['fmt'] ) ) {
408 $w = ( ! empty( $content_width ) ? min( $content_width, 480 ) : 480 );
409 } else {
410 $w = ( ! empty( $content_width ) ? min( $content_width, $default_width ) : $default_width );
411 $h = ceil( ( $w / 16 ) * 9 );
412 }
413 } elseif ( $input_w > 0 ) {
414 $w = $input_w;
415 $h = ceil( ( $w / 16 ) * 9 );
416 } else {
417 if ( isset( $query_args['fmt'] ) && intval( $query_args['fmt'] ) ) {
418 $w = ( ! empty( $content_width ) ? min( $content_width, 480 ) : 480 );
419 } else {
420 $w = ( ! empty( $content_width ) ? min( $content_width, $default_width ) : $default_width );
421 $h = $input_h;
422 }
423 }
424
425 /**
426 * Filter the YouTube player width.
427 *
428 * @module shortcodes
429 *
430 * @since 1.1.0
431 *
432 * @param int $w Width of the YouTube player in pixels.
433 */
434 $w = (int) apply_filters( 'youtube_width', $w );
435
436 /**
437 * Filter the YouTube player height.
438 *
439 * @module shortcodes
440 *
441 * @since 1.1.0
442 *
443 * @param int $h Height of the YouTube player in pixels.
444 */
445 $h = (int) apply_filters( 'youtube_height', $h );
446
447 return array( $w, $h );
448 }
449
450 /**
451 * For bare URLs on their own line of the form
452 * http://www.youtube.com/v/9FhMMmqzbD8?fs=1&hl=en_US
453 *
454 * @param array $matches Regex partial matches against the URL passed.
455 * @param array $attr Attributes received in embed response.
456 * @param array $url Requested URL to be embedded.
457 */
458 function wpcom_youtube_embed_crazy_url( $matches, $attr, $url ) {
459 return youtube_id( $url );
460 }
461
462 /**
463 * Add a new handler to automatically transform custom Youtube URLs (like playlists) into embeds.
464 */
465 function wpcom_youtube_embed_crazy_url_init() {
466 wp_embed_register_handler( 'wpcom_youtube_embed_crazy_url', '#https?://(?:www\.)?(?:youtube.com/(?:v/|playlist|watch[/\#?])|youtu\.be/).*#i', 'wpcom_youtube_embed_crazy_url' );
467 }
468 add_action( 'init', 'wpcom_youtube_embed_crazy_url_init' );
469
470 /**
471 * Allow oEmbeds in Jetpack's Comment form.
472 *
473 * @module shortcodes
474 *
475 * @since 2.8.0
476 *
477 * @param int get_option('embed_autourls') Option to automatically embed all plain text URLs.
478 */
479 if ( ! is_admin() && apply_filters( 'jetpack_comments_allow_oembed', true ) ) {
480 /*
481 * We attach wp_kses_post to comment_text in default-filters.php with priority of 10 anyway,
482 * so the iframe gets filtered out.
483 * Higher priority because we need it before auto-link and autop get to it.
484 */
485 add_filter( 'comment_text', 'youtube_link', 1 );
486 }
487
488 /**
489 * Core changes to do_shortcode (https://core.trac.wordpress.org/changeset/34747) broke "improper" shortcodes
490 * with the format [shortcode=http://url.com].
491 *
492 * This removes the "=" from the shortcode so it can be parsed.
493 *
494 * @see https://github.com/Automattic/jetpack/issues/3121
495 *
496 * @param string $content HTML content.
497 */
498 function jetpack_fix_youtube_shortcode_display_filter( $content ) {
499 if ( strpos( $content, '[youtube=' ) !== false ) {
500 $content = preg_replace( '@\[youtube=(.*?)\]@', '[youtube $1]', $content );
501 }
502
503 return $content;
504 }
505 add_filter( 'the_content', 'jetpack_fix_youtube_shortcode_display_filter', 7 );
506