| 1 |
<?php |
| 2 |
/** |
| 3 |
* Status and information regarding the site visitor. |
| 4 |
* |
| 5 |
* @package automattic/jetpack-status |
| 6 |
*/ |
| 7 |
|
| 8 |
namespace Automattic\Jetpack\Status; |
| 9 |
|
| 10 |
/** |
| 11 |
* Visitor class. |
| 12 |
*/ |
| 13 |
class Visitor { |
| 14 |
|
| 15 |
/** |
| 16 |
* Gets current user IP address. |
| 17 |
* |
| 18 |
* @param bool $check_all_headers Check all headers? Default is `false`. |
| 19 |
* |
| 20 |
* @return string Current user IP address. |
| 21 |
*/ |
| 22 |
public function get_ip( $check_all_headers = false ) { |
| 23 |
if ( $check_all_headers ) { |
| 24 |
foreach ( array( |
| 25 |
'HTTP_CF_CONNECTING_IP', |
| 26 |
'HTTP_CLIENT_IP', |
| 27 |
'HTTP_X_FORWARDED_FOR', |
| 28 |
'HTTP_X_FORWARDED', |
| 29 |
'HTTP_X_CLUSTER_CLIENT_IP', |
| 30 |
'HTTP_FORWARDED_FOR', |
| 31 |
'HTTP_FORWARDED', |
| 32 |
'HTTP_VIA', |
| 33 |
) as $key ) { |
| 34 |
if ( ! empty( $_SERVER[ $key ] ) ) { |
| 35 |
// @todo Some of these might actually be lists of IPs (e.g. HTTP_X_FORWARDED_FOR) or something else entirely (HTTP_VIA). |
| 36 |
return filter_var( wp_unslash( $_SERVER[ $key ] ) ); |
| 37 |
} |
| 38 |
} |
| 39 |
} |
| 40 |
|
| 41 |
return ! empty( $_SERVER['REMOTE_ADDR'] ) ? filter_var( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : ''; |
| 42 |
} |
| 43 |
|
| 44 |
/** |
| 45 |
* Simple gate check for a11n feature testing purposes using AT_PROXIED_REQUEST constant. |
| 46 |
* IMPORTANT: Only use it for internal feature test purposes, not authorization. |
| 47 |
* |
| 48 |
* The goal of this function is to help us gate features by using a similar function name |
| 49 |
* we find on simple sites: is_automattician(). |
| 50 |
* |
| 51 |
* @return bool True if the current request is PROXIED, false otherwise. |
| 52 |
*/ |
| 53 |
public function is_automattician_feature_flags_only() { |
| 54 |
return ( defined( 'AT_PROXIED_REQUEST' ) && AT_PROXIED_REQUEST ); |
| 55 |
} |
| 56 |
|
| 57 |
/** |
| 58 |
* Whether the current request should be attributed to an Automattician in analytics. |
| 59 |
* |
| 60 |
* True for an identified Automattician on WordPress.com Simple, and for A8C-proxied |
| 61 |
* requests on both Simple and WoA. Use it to tag Tracks events as internal traffic so |
| 62 |
* it can be filtered out of product reporting — this matters most for newly launched |
| 63 |
* features, where a small amount of internal testing is a large share of the totals |
| 64 |
* and there is no way to separate it after the fact. |
| 65 |
* |
| 66 |
* IMPORTANT: Reporting signal only, never authorization. A proxied request says |
| 67 |
* something about where the request came from, not who the user is. |
| 68 |
* |
| 69 |
* @since 6.4.0 |
| 70 |
* |
| 71 |
* @return bool True if the request looks like Automattician traffic, false otherwise. |
| 72 |
*/ |
| 73 |
public function is_tracking_automattician() { |
| 74 |
// Identified Automattician on WordPress.com Simple. |
| 75 |
if ( function_exists( 'is_automattician' ) && \is_automattician() ) { |
| 76 |
return true; |
| 77 |
} |
| 78 |
|
| 79 |
// Proxied A8C request on WordPress.com Simple. |
| 80 |
if ( function_exists( 'wpcom_is_proxied_request' ) && \wpcom_is_proxied_request() ) { |
| 81 |
return true; |
| 82 |
} |
| 83 |
|
| 84 |
// Proxied A8C request on WoA. |
| 85 |
return $this->is_automattician_feature_flags_only(); |
| 86 |
} |
| 87 |
} |
| 88 |
|