| @@ -521,8 +521,35 @@ | ||
| 521 | 521 | if ( in_array( 'cloudflare/cloudflare.php', $active, true ) ) { |
| 522 | 522 | return self::answer( 'cloudflare', self::CONFIRMED, 'plugin' ); |
| 523 | 523 | } |
| 524 | 524 | |
| 525 | + // xCloud's Cloudflare Enterprise purge mu-plugin. xCloud installs it | |
| 526 | + // on a site whose domain has Cloudflare Enterprise bought through | |
| 527 | + // xCloud, and it defines this constant whatever version it is. Its | |
| 528 | + // whole job is purging that Cloudflare zone, so the site is behind | |
| 529 | + // Cloudflare. | |
| 530 | + // | |
| 531 | + // `confirmed`, like the plugin signals above. The evidence is | |
| 532 | + // server-side state that no visitor can send, so it is safe to bake | |
| 533 | + // into the drop-in and replay from a sidecar. On these sites it is | |
| 534 | + // the one signal that names Cloudflare in a `bake`, which is what | |
| 535 | + // lets the drop-in carry a hold that needs evidence. | |
| 536 | + // | |
| 537 | + // It is wrong only when the mu-plugin outlives the CFE subscription. | |
| 538 | + // That costs what a grey-clouded zone costs above, one inert | |
| 539 | + // `cf-edge-cache` header, because the Cloudflare set is the blind set | |
| 540 | + // plus that one. The value is not read. xCloud renders the version | |
| 541 | + // into the file, and a copy rendered without one still says the | |
| 542 | + // same thing about the zone. | |
| 543 | + // | |
| 544 | + // Below the pins and the filter, so `off` and a named provider still | |
| 545 | + // win. A mu-plugin loads before plugins, so the constant is there by | |
| 546 | + // the time anything here runs, CLI and cron included. The drop-in | |
| 547 | + // runs before mu-plugins, which is why it gets this as a baked answer. | |
| 548 | + if ( defined( 'XCLOUD_CFE_PURGE_VERSION' ) ) { | |
| 549 | + return self::answer( 'cloudflare', self::CONFIRMED, 'xcloud-cfe' ); | |
| 550 | + } | |
| 551 | + | |
| 525 | 552 | // Everything below reads the inbound request, so it is skipped |
| 526 | 553 | // outside `request`. A bake runs once in an admin or CLI request and |
| 527 | 554 | // answers for every page on the site; a sidecar is written from one |
| 528 | 555 | // visitor's request and replayed to every later visitor of that page. |