class.jetpack.php 202 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036
  1. <?php
  2. /*
  3. Options:
  4. jetpack_options (array)
  5. An array of options.
  6. @see Jetpack_Options::get_option_names()
  7. jetpack_register (string)
  8. Temporary verification secrets.
  9. jetpack_activated (int)
  10. 1: the plugin was activated normally
  11. 2: the plugin was activated on this site because of a network-wide activation
  12. 3: the plugin was auto-installed
  13. 4: the plugin was manually disconnected (but is still installed)
  14. jetpack_active_modules (array)
  15. Array of active module slugs.
  16. jetpack_do_activate (bool)
  17. Flag for "activating" the plugin on sites where the activation hook never fired (auto-installs)
  18. */
  19. class Jetpack {
  20. public $xmlrpc_server = null;
  21. private $xmlrpc_verification = null;
  22. public $HTTP_RAW_POST_DATA = null; // copy of $GLOBALS['HTTP_RAW_POST_DATA']
  23. /**
  24. * @var array The handles of styles that are concatenated into jetpack.css
  25. */
  26. public $concatenated_style_handles = array(
  27. 'jetpack-carousel',
  28. 'grunion.css',
  29. 'the-neverending-homepage',
  30. 'jetpack_likes',
  31. 'jetpack_related-posts',
  32. 'sharedaddy',
  33. 'jetpack-slideshow',
  34. 'presentations',
  35. 'jetpack-subscriptions',
  36. 'jetpack-responsive-videos-style',
  37. 'jetpack-social-menu',
  38. 'tiled-gallery',
  39. 'jetpack_display_posts_widget',
  40. 'gravatar-profile-widget',
  41. 'goodreads-widget',
  42. 'jetpack_social_media_icons_widget',
  43. 'jetpack-top-posts-widget',
  44. 'jetpack_image_widget',
  45. );
  46. public $plugins_to_deactivate = array(
  47. 'stats' => array( 'stats/stats.php', 'WordPress.com Stats' ),
  48. 'shortlinks' => array( 'stats/stats.php', 'WordPress.com Stats' ),
  49. 'sharedaddy' => array( 'sharedaddy/sharedaddy.php', 'Sharedaddy' ),
  50. 'twitter-widget' => array( 'wickett-twitter-widget/wickett-twitter-widget.php', 'Wickett Twitter Widget' ),
  51. 'after-the-deadline' => array( 'after-the-deadline/after-the-deadline.php', 'After The Deadline' ),
  52. 'contact-form' => array( 'grunion-contact-form/grunion-contact-form.php', 'Grunion Contact Form' ),
  53. 'contact-form' => array( 'mullet/mullet-contact-form.php', 'Mullet Contact Form' ),
  54. 'custom-css' => array( 'safecss/safecss.php', 'WordPress.com Custom CSS' ),
  55. 'random-redirect' => array( 'random-redirect/random-redirect.php', 'Random Redirect' ),
  56. 'videopress' => array( 'video/video.php', 'VideoPress' ),
  57. 'widget-visibility' => array( 'jetpack-widget-visibility/widget-visibility.php', 'Jetpack Widget Visibility' ),
  58. 'widget-visibility' => array( 'widget-visibility-without-jetpack/widget-visibility-without-jetpack.php', 'Widget Visibility Without Jetpack' ),
  59. 'sharedaddy' => array( 'jetpack-sharing/sharedaddy.php', 'Jetpack Sharing' ),
  60. 'omnisearch' => array( 'jetpack-omnisearch/omnisearch.php', 'Jetpack Omnisearch' ),
  61. 'gravatar-hovercards' => array( 'jetpack-gravatar-hovercards/gravatar-hovercards.php', 'Jetpack Gravatar Hovercards' ),
  62. 'latex' => array( 'wp-latex/wp-latex.php', 'WP LaTeX' )
  63. );
  64. static $capability_translations = array(
  65. 'administrator' => 'manage_options',
  66. 'editor' => 'edit_others_posts',
  67. 'author' => 'publish_posts',
  68. 'contributor' => 'edit_posts',
  69. 'subscriber' => 'read',
  70. );
  71. /**
  72. * Map of modules that have conflicts with plugins and should not be auto-activated
  73. * if the plugins are active. Used by filter_default_modules
  74. *
  75. * Plugin Authors: If you'd like to prevent a single module from auto-activating,
  76. * change `module-slug` and add this to your plugin:
  77. *
  78. * add_filter( 'jetpack_get_default_modules', 'my_jetpack_get_default_modules' );
  79. * function my_jetpack_get_default_modules( $modules ) {
  80. * return array_diff( $modules, array( 'module-slug' ) );
  81. * }
  82. *
  83. * @var array
  84. */
  85. private $conflicting_plugins = array(
  86. 'comments' => array(
  87. 'Intense Debate' => 'intensedebate/intensedebate.php',
  88. 'Disqus' => 'disqus-comment-system/disqus.php',
  89. 'Livefyre' => 'livefyre-comments/livefyre.php',
  90. 'Comments Evolved for WordPress' => 'gplus-comments/comments-evolved.php',
  91. 'Google+ Comments' => 'google-plus-comments/google-plus-comments.php',
  92. 'WP-SpamShield Anti-Spam' => 'wp-spamshield/wp-spamshield.php',
  93. ),
  94. 'contact-form' => array(
  95. 'Contact Form 7' => 'contact-form-7/wp-contact-form-7.php',
  96. 'Gravity Forms' => 'gravityforms/gravityforms.php',
  97. 'Contact Form Plugin' => 'contact-form-plugin/contact_form.php',
  98. 'Easy Contact Forms' => 'easy-contact-forms/easy-contact-forms.php',
  99. 'Fast Secure Contact Form' => 'si-contact-form/si-contact-form.php',
  100. ),
  101. 'minileven' => array(
  102. 'WPtouch' => 'wptouch/wptouch.php',
  103. ),
  104. 'latex' => array(
  105. 'LaTeX for WordPress' => 'latex/latex.php',
  106. 'Youngwhans Simple Latex' => 'youngwhans-simple-latex/yw-latex.php',
  107. 'Easy WP LaTeX' => 'easy-wp-latex-lite/easy-wp-latex-lite.php',
  108. 'MathJax-LaTeX' => 'mathjax-latex/mathjax-latex.php',
  109. 'Enable Latex' => 'enable-latex/enable-latex.php',
  110. 'WP QuickLaTeX' => 'wp-quicklatex/wp-quicklatex.php',
  111. ),
  112. 'protect' => array(
  113. 'Limit Login Attempts' => 'limit-login-attempts/limit-login-attempts.php',
  114. 'Captcha' => 'captcha/captcha.php',
  115. 'Brute Force Login Protection' => 'brute-force-login-protection/brute-force-login-protection.php',
  116. 'Login Security Solution' => 'login-security-solution/login-security-solution.php',
  117. 'WPSecureOps Brute Force Protect' => 'wpsecureops-bruteforce-protect/wpsecureops-bruteforce-protect.php',
  118. 'BulletProof Security' => 'bulletproof-security/bulletproof-security.php',
  119. 'SiteGuard WP Plugin' => 'siteguard/siteguard.php',
  120. 'Security-protection' => 'security-protection/security-protection.php',
  121. 'Login Security' => 'login-security/login-security.php',
  122. 'Botnet Attack Blocker' => 'botnet-attack-blocker/botnet-attack-blocker.php',
  123. 'Wordfence Security' => 'wordfence/wordfence.php',
  124. 'All In One WP Security & Firewall' => 'all-in-one-wp-security-and-firewall/wp-security.php',
  125. 'iThemes Security' => 'better-wp-security/better-wp-security.php',
  126. ),
  127. 'random-redirect' => array(
  128. 'Random Redirect 2' => 'random-redirect-2/random-redirect.php',
  129. ),
  130. 'related-posts' => array(
  131. 'YARPP' => 'yet-another-related-posts-plugin/yarpp.php',
  132. 'WordPress Related Posts' => 'wordpress-23-related-posts-plugin/wp_related_posts.php',
  133. 'nrelate Related Content' => 'nrelate-related-content/nrelate-related.php',
  134. 'Contextual Related Posts' => 'contextual-related-posts/contextual-related-posts.php',
  135. 'Related Posts for WordPress' => 'microkids-related-posts/microkids-related-posts.php',
  136. 'outbrain' => 'outbrain/outbrain.php',
  137. 'Shareaholic' => 'shareaholic/shareaholic.php',
  138. 'Sexybookmarks' => 'sexybookmarks/shareaholic.php',
  139. ),
  140. 'sharedaddy' => array(
  141. 'AddThis' => 'addthis/addthis_social_widget.php',
  142. 'Add To Any' => 'add-to-any/add-to-any.php',
  143. 'ShareThis' => 'share-this/sharethis.php',
  144. 'Shareaholic' => 'shareaholic/shareaholic.php',
  145. ),
  146. 'verification-tools' => array(
  147. 'WordPress SEO by Yoast' => 'wordpress-seo/wp-seo.php',
  148. 'WordPress SEO Premium by Yoast' => 'wordpress-seo-premium/wp-seo-premium.php',
  149. 'All in One SEO Pack' => 'all-in-one-seo-pack/all_in_one_seo_pack.php',
  150. ),
  151. 'widget-visibility' => array(
  152. 'Widget Logic' => 'widget-logic/widget_logic.php',
  153. 'Dynamic Widgets' => 'dynamic-widgets/dynamic-widgets.php',
  154. ),
  155. 'sitemaps' => array(
  156. 'Google XML Sitemaps' => 'google-sitemap-generator/sitemap.php',
  157. 'Better WordPress Google XML Sitemaps' => 'bwp-google-xml-sitemaps/bwp-simple-gxs.php',
  158. 'Google XML Sitemaps for qTranslate' => 'google-xml-sitemaps-v3-for-qtranslate/sitemap.php',
  159. 'XML Sitemap & Google News feeds' => 'xml-sitemap-feed/xml-sitemap.php',
  160. 'Google Sitemap by BestWebSoft' => 'google-sitemap-plugin/google-sitemap-plugin.php',
  161. 'WordPress SEO by Yoast' => 'wordpress-seo/wp-seo.php',
  162. 'WordPress SEO Premium by Yoast' => 'wordpress-seo-premium/wp-seo-premium.php',
  163. 'All in One SEO Pack' => 'all-in-one-seo-pack/all_in_one_seo_pack.php',
  164. 'Sitemap' => 'sitemap/sitemap.php',
  165. 'Simple Wp Sitemap' => 'simple-wp-sitemap/simple-wp-sitemap.php',
  166. 'Simple Sitemap' => 'simple-sitemap/simple-sitemap.php',
  167. 'XML Sitemaps' => 'xml-sitemaps/xml-sitemaps.php',
  168. 'MSM Sitemaps' => 'msm-sitemap/msm-sitemap.php',
  169. ),
  170. );
  171. /**
  172. * Plugins for which we turn off our Facebook OG Tags implementation.
  173. *
  174. * Note: WordPress SEO by Yoast and WordPress SEO Premium by Yoast automatically deactivate
  175. * Jetpack's Open Graph tags via filter when their Social Meta modules are active.
  176. *
  177. * Plugin authors: If you'd like to prevent Jetpack's Open Graph tag generation in your plugin, you can do so via this filter:
  178. * add_filter( 'jetpack_enable_open_graph', '__return_false' );
  179. */
  180. private $open_graph_conflicting_plugins = array(
  181. '2-click-socialmedia-buttons/2-click-socialmedia-buttons.php',
  182. // 2 Click Social Media Buttons
  183. 'add-link-to-facebook/add-link-to-facebook.php', // Add Link to Facebook
  184. 'add-meta-tags/add-meta-tags.php', // Add Meta Tags
  185. 'autodescription/autodescription.php', // The SEO Framework
  186. 'easy-facebook-share-thumbnails/esft.php', // Easy Facebook Share Thumbnail
  187. 'heateor-open-graph-meta-tags/heateor-open-graph-meta-tags.php',
  188. // Open Graph Meta Tags by Heateor
  189. 'facebook/facebook.php', // Facebook (official plugin)
  190. 'facebook-awd/AWD_facebook.php', // Facebook AWD All in one
  191. 'facebook-featured-image-and-open-graph-meta-tags/fb-featured-image.php',
  192. // Facebook Featured Image & OG Meta Tags
  193. 'facebook-meta-tags/facebook-metatags.php', // Facebook Meta Tags
  194. 'wonderm00ns-simple-facebook-open-graph-tags/wonderm00n-open-graph.php',
  195. // Facebook Open Graph Meta Tags for WordPress
  196. 'facebook-revised-open-graph-meta-tag/index.php', // Facebook Revised Open Graph Meta Tag
  197. 'facebook-thumb-fixer/_facebook-thumb-fixer.php', // Facebook Thumb Fixer
  198. 'facebook-and-digg-thumbnail-generator/facebook-and-digg-thumbnail-generator.php',
  199. // Fedmich's Facebook Open Graph Meta
  200. 'header-footer/plugin.php', // Header and Footer
  201. 'network-publisher/networkpub.php', // Network Publisher
  202. 'nextgen-facebook/nextgen-facebook.php', // NextGEN Facebook OG
  203. 'social-networks-auto-poster-facebook-twitter-g/NextScripts_SNAP.php',
  204. // NextScripts SNAP
  205. 'og-tags/og-tags.php', // OG Tags
  206. 'opengraph/opengraph.php', // Open Graph
  207. 'open-graph-protocol-framework/open-graph-protocol-framework.php',
  208. // Open Graph Protocol Framework
  209. 'seo-facebook-comments/seofacebook.php', // SEO Facebook Comments
  210. 'seo-ultimate/seo-ultimate.php', // SEO Ultimate
  211. 'sexybookmarks/sexy-bookmarks.php', // Shareaholic
  212. 'shareaholic/sexy-bookmarks.php', // Shareaholic
  213. 'sharepress/sharepress.php', // SharePress
  214. 'simple-facebook-connect/sfc.php', // Simple Facebook Connect
  215. 'social-discussions/social-discussions.php', // Social Discussions
  216. 'social-sharing-toolkit/social_sharing_toolkit.php', // Social Sharing Toolkit
  217. 'socialize/socialize.php', // Socialize
  218. 'only-tweet-like-share-and-google-1/tweet-like-plusone.php',
  219. // Tweet, Like, Google +1 and Share
  220. 'wordbooker/wordbooker.php', // Wordbooker
  221. 'wpsso/wpsso.php', // WordPress Social Sharing Optimization
  222. 'wp-caregiver/wp-caregiver.php', // WP Caregiver
  223. 'wp-facebook-like-send-open-graph-meta/wp-facebook-like-send-open-graph-meta.php',
  224. // WP Facebook Like Send & Open Graph Meta
  225. 'wp-facebook-open-graph-protocol/wp-facebook-ogp.php', // WP Facebook Open Graph protocol
  226. 'wp-ogp/wp-ogp.php', // WP-OGP
  227. 'zoltonorg-social-plugin/zosp.php', // Zolton.org Social Plugin
  228. 'wp-fb-share-like-button/wp_fb_share-like_widget.php' // WP Facebook Like Button
  229. );
  230. /**
  231. * Plugins for which we turn off our Twitter Cards Tags implementation.
  232. */
  233. private $twitter_cards_conflicting_plugins = array(
  234. // 'twitter/twitter.php', // The official one handles this on its own.
  235. // // https://github.com/twitter/wordpress/blob/master/src/Twitter/WordPress/Cards/Compatibility.php
  236. 'eewee-twitter-card/index.php', // Eewee Twitter Card
  237. 'ig-twitter-cards/ig-twitter-cards.php', // IG:Twitter Cards
  238. 'jm-twitter-cards/jm-twitter-cards.php', // JM Twitter Cards
  239. 'kevinjohn-gallagher-pure-web-brilliants-social-graph-twitter-cards-extention/kevinjohn_gallagher___social_graph_twitter_output.php',
  240. // Pure Web Brilliant's Social Graph Twitter Cards Extension
  241. 'twitter-cards/twitter-cards.php', // Twitter Cards
  242. 'twitter-cards-meta/twitter-cards-meta.php', // Twitter Cards Meta
  243. 'wp-twitter-cards/twitter_cards.php', // WP Twitter Cards
  244. );
  245. /**
  246. * Message to display in admin_notice
  247. * @var string
  248. */
  249. public $message = '';
  250. /**
  251. * Error to display in admin_notice
  252. * @var string
  253. */
  254. public $error = '';
  255. /**
  256. * Modules that need more privacy description.
  257. * @var string
  258. */
  259. public $privacy_checks = '';
  260. /**
  261. * Stats to record once the page loads
  262. *
  263. * @var array
  264. */
  265. public $stats = array();
  266. /**
  267. * Jetpack_Sync object
  268. */
  269. public $sync;
  270. /**
  271. * Verified data for JSON authorization request
  272. */
  273. public $json_api_authorization_request = array();
  274. /**
  275. * Holds the singleton instance of this class
  276. * @since 2.3.3
  277. * @var Jetpack
  278. */
  279. static $instance = false;
  280. /**
  281. * Singleton
  282. * @static
  283. */
  284. public static function init() {
  285. if ( ! self::$instance ) {
  286. self::$instance = new Jetpack;
  287. self::$instance->plugin_upgrade();
  288. }
  289. return self::$instance;
  290. }
  291. /**
  292. * Must never be called statically
  293. */
  294. function plugin_upgrade() {
  295. if ( Jetpack::is_active() ) {
  296. list( $version ) = explode( ':', Jetpack_Options::get_option( 'version' ) );
  297. if ( JETPACK__VERSION != $version ) {
  298. // Check which active modules actually exist and remove others from active_modules list
  299. $unfiltered_modules = Jetpack::get_active_modules();
  300. $modules = array_filter( $unfiltered_modules, array( 'Jetpack', 'is_module' ) );
  301. if ( array_diff( $unfiltered_modules, $modules ) ) {
  302. Jetpack::update_active_modules( $modules );
  303. }
  304. add_action( 'init', array( __CLASS__, 'activate_new_modules' ) );
  305. // Upgrade to 4.3.0
  306. if ( Jetpack_Options::get_option( 'identity_crisis_whitelist' ) ) {
  307. Jetpack_Options::delete_option( 'identity_crisis_whitelist' );
  308. }
  309. Jetpack::maybe_set_version_option();
  310. }
  311. }
  312. }
  313. static function activate_manage( ) {
  314. if ( did_action( 'init' ) || current_filter() == 'init' ) {
  315. self::activate_module( 'manage', false, false );
  316. } else if ( ! has_action( 'init' , array( __CLASS__, 'activate_manage' ) ) ) {
  317. add_action( 'init', array( __CLASS__, 'activate_manage' ) );
  318. }
  319. }
  320. static function update_active_modules( $modules ) {
  321. $current_modules = Jetpack_Options::get_option( 'active_modules', array() );
  322. $success = Jetpack_Options::update_option( 'active_modules', array_unique( $modules ) );
  323. if ( is_array( $modules ) && is_array( $current_modules ) ) {
  324. $new_active_modules = array_diff( $modules, $current_modules );
  325. foreach( $new_active_modules as $module ) {
  326. /**
  327. * Fires when a specific module is activated.
  328. *
  329. * @since 1.9.0
  330. *
  331. * @param string $module Module slug.
  332. * @param boolean $success whether the module was activated. @since 4.2
  333. */
  334. do_action( 'jetpack_activate_module', $module, $success );
  335. /**
  336. * Fires when a module is activated.
  337. * The dynamic part of the filter, $module, is the module slug.
  338. *
  339. * @since 1.9.0
  340. *
  341. * @param string $module Module slug.
  342. */
  343. do_action( "jetpack_activate_module_$module", $module );
  344. }
  345. $new_deactive_modules = array_diff( $current_modules, $modules );
  346. foreach( $new_deactive_modules as $module ) {
  347. /**
  348. * Fired after a module has been deactivated.
  349. *
  350. * @since 4.2.0
  351. *
  352. * @param string $module Module slug.
  353. * @param boolean $success whether the module was deactivated.
  354. */
  355. do_action( 'jetpack_deactivate_module', $module, $success );
  356. /**
  357. * Fires when a module is deactivated.
  358. * The dynamic part of the filter, $module, is the module slug.
  359. *
  360. * @since 1.9.0
  361. *
  362. * @param string $module Module slug.
  363. */
  364. do_action( "jetpack_deactivate_module_$module", $module );
  365. }
  366. }
  367. return $success;
  368. }
  369. static function delete_active_modules() {
  370. self::update_active_modules( array() );
  371. }
  372. /**
  373. * Constructor. Initializes WordPress hooks
  374. */
  375. private function __construct() {
  376. /*
  377. * Check for and alert any deprecated hooks
  378. */
  379. add_action( 'init', array( $this, 'deprecated_hooks' ) );
  380. /*
  381. * Load things that should only be in Network Admin.
  382. *
  383. * For now blow away everything else until a more full
  384. * understanding of what is needed at the network level is
  385. * available
  386. */
  387. if( is_multisite() ) {
  388. Jetpack_Network::init();
  389. }
  390. // Unlink user before deleting the user from .com
  391. add_action( 'deleted_user', array( $this, 'unlink_user' ), 10, 1 );
  392. add_action( 'remove_user_from_blog', array( $this, 'unlink_user' ), 10, 1 );
  393. if ( defined( 'XMLRPC_REQUEST' ) && XMLRPC_REQUEST && isset( $_GET['for'] ) && 'jetpack' == $_GET['for'] ) {
  394. @ini_set( 'display_errors', false ); // Display errors can cause the XML to be not well formed.
  395. require_once JETPACK__PLUGIN_DIR . 'class.jetpack-xmlrpc-server.php';
  396. $this->xmlrpc_server = new Jetpack_XMLRPC_Server();
  397. $this->require_jetpack_authentication();
  398. if ( Jetpack::is_active() ) {
  399. // Hack to preserve $HTTP_RAW_POST_DATA
  400. add_filter( 'xmlrpc_methods', array( $this, 'xmlrpc_methods' ) );
  401. $signed = $this->verify_xml_rpc_signature();
  402. if ( $signed && ! is_wp_error( $signed ) ) {
  403. // The actual API methods.
  404. add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'xmlrpc_methods' ) );
  405. } else {
  406. // The jetpack.authorize method should be available for unauthenticated users on a site with an
  407. // active Jetpack connection, so that additional users can link their account.
  408. add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'authorize_xmlrpc_methods' ) );
  409. }
  410. } else {
  411. // The bootstrap API methods.
  412. add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'bootstrap_xmlrpc_methods' ) );
  413. }
  414. // Now that no one can authenticate, and we're whitelisting all XML-RPC methods, force enable_xmlrpc on.
  415. add_filter( 'pre_option_enable_xmlrpc', '__return_true' );
  416. } elseif ( is_admin() && isset( $_POST['action'] ) && 'jetpack_upload_file' == $_POST['action'] ) {
  417. $this->require_jetpack_authentication();
  418. $this->add_remote_request_handlers();
  419. } else {
  420. if ( Jetpack::is_active() ) {
  421. add_action( 'login_form_jetpack_json_api_authorization', array( &$this, 'login_form_json_api_authorization' ) );
  422. add_filter( 'xmlrpc_methods', array( $this, 'public_xmlrpc_methods' ) );
  423. }
  424. }
  425. if ( Jetpack::is_active() ) {
  426. Jetpack_Heartbeat::init();
  427. }
  428. add_action( 'jetpack_clean_nonces', array( 'Jetpack', 'clean_nonces' ) );
  429. if ( ! wp_next_scheduled( 'jetpack_clean_nonces' ) ) {
  430. wp_schedule_event( time(), 'hourly', 'jetpack_clean_nonces' );
  431. }
  432. add_filter( 'xmlrpc_blog_options', array( $this, 'xmlrpc_options' ) );
  433. add_action( 'admin_init', array( $this, 'admin_init' ) );
  434. add_action( 'admin_init', array( $this, 'dismiss_jetpack_notice' ) );
  435. add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
  436. add_action( 'wp_dashboard_setup', array( $this, 'wp_dashboard_setup' ) );
  437. // Filter the dashboard meta box order to swap the new one in in place of the old one.
  438. add_filter( 'get_user_option_meta-box-order_dashboard', array( $this, 'get_user_option_meta_box_order_dashboard' ) );
  439. // returns HTTPS support status
  440. add_action( 'wp_ajax_jetpack-recheck-ssl', array( $this, 'ajax_recheck_ssl' ) );
  441. // If any module option is updated before Jump Start is dismissed, hide Jump Start.
  442. add_action( 'update_option', array( $this, 'jumpstart_has_updated_module_option' ) );
  443. // JITM AJAX callback function
  444. add_action( 'wp_ajax_jitm_ajax', array( $this, 'jetpack_jitm_ajax_callback' ) );
  445. // Universal ajax callback for all tracking events triggered via js
  446. add_action( 'wp_ajax_jetpack_tracks', array( $this, 'jetpack_admin_ajax_tracks_callback' ) );
  447. add_action( 'wp_loaded', array( $this, 'register_assets' ) );
  448. add_action( 'wp_enqueue_scripts', array( $this, 'devicepx' ) );
  449. add_action( 'customize_controls_enqueue_scripts', array( $this, 'devicepx' ) );
  450. add_action( 'admin_enqueue_scripts', array( $this, 'devicepx' ) );
  451. add_action( 'plugins_loaded', array( $this, 'extra_oembed_providers' ), 100 );
  452. /**
  453. * These actions run checks to load additional files.
  454. * They check for external files or plugins, so they need to run as late as possible.
  455. */
  456. add_action( 'wp_head', array( $this, 'check_open_graph' ), 1 );
  457. add_action( 'plugins_loaded', array( $this, 'check_twitter_tags' ), 999 );
  458. add_action( 'plugins_loaded', array( $this, 'check_rest_api_compat' ), 1000 );
  459. add_filter( 'plugins_url', array( 'Jetpack', 'maybe_min_asset' ), 1, 3 );
  460. add_filter( 'style_loader_tag', array( 'Jetpack', 'maybe_inline_style' ), 10, 2 );
  461. add_filter( 'map_meta_cap', array( $this, 'jetpack_custom_caps' ), 1, 4 );
  462. add_filter( 'jetpack_get_default_modules', array( $this, 'filter_default_modules' ) );
  463. add_filter( 'jetpack_get_default_modules', array( $this, 'handle_deprecated_modules' ), 99 );
  464. // A filter to control all just in time messages
  465. add_filter( 'jetpack_just_in_time_msgs', '__return_false' );
  466. /**
  467. * This is the hack to concatinate all css files into one.
  468. * For description and reasoning see the implode_frontend_css method
  469. *
  470. * Super late priority so we catch all the registered styles
  471. */
  472. if( !is_admin() ) {
  473. add_action( 'wp_print_styles', array( $this, 'implode_frontend_css' ), -1 ); // Run first
  474. add_action( 'wp_print_footer_scripts', array( $this, 'implode_frontend_css' ), -1 ); // Run first to trigger before `print_late_styles`
  475. }
  476. }
  477. function jetpack_admin_ajax_tracks_callback() {
  478. // Check for nonce
  479. if ( ! isset( $_REQUEST['tracksNonce'] ) || ! wp_verify_nonce( $_REQUEST['tracksNonce'], 'jp-tracks-ajax-nonce' ) ) {
  480. wp_die( 'Permissions check failed.' );
  481. }
  482. if ( ! isset( $_REQUEST['tracksEventName'] ) || ! isset( $_REQUEST['tracksEventType'] ) ) {
  483. wp_die( 'No valid event name or type.' );
  484. }
  485. $tracks_data = array();
  486. if ( 'click' === $_REQUEST['tracksEventType'] && isset( $_REQUEST['tracksEventProp'] ) ) {
  487. $tracks_data = array( 'clicked' => $_REQUEST['tracksEventProp'] );
  488. }
  489. JetpackTracking::record_user_event( $_REQUEST['tracksEventName'], $tracks_data );
  490. wp_send_json_success();
  491. wp_die();
  492. }
  493. /**
  494. * The callback for the JITM ajax requests.
  495. */
  496. function jetpack_jitm_ajax_callback() {
  497. // Check for nonce
  498. if ( ! isset( $_REQUEST['jitmNonce'] ) || ! wp_verify_nonce( $_REQUEST['jitmNonce'], 'jetpack-jitm-nonce' ) ) {
  499. wp_die( 'Module activation failed due to lack of appropriate permissions' );
  500. }
  501. if ( isset( $_REQUEST['jitmActionToTake'] ) && 'activate' == $_REQUEST['jitmActionToTake'] ) {
  502. $module_slug = $_REQUEST['jitmModule'];
  503. Jetpack::log( 'activate', $module_slug );
  504. Jetpack::activate_module( $module_slug, false, false );
  505. Jetpack::state( 'message', 'no_message' );
  506. //A Jetpack module is being activated through a JITM, track it
  507. $this->stat( 'jitm', $module_slug.'-activated-' . JETPACK__VERSION );
  508. $this->do_stats( 'server_side' );
  509. wp_send_json_success();
  510. }
  511. if ( isset( $_REQUEST['jitmActionToTake'] ) && 'dismiss' == $_REQUEST['jitmActionToTake'] ) {
  512. // get the hide_jitm options array
  513. $jetpack_hide_jitm = Jetpack_Options::get_option( 'hide_jitm' );
  514. $module_slug = $_REQUEST['jitmModule'];
  515. if( ! $jetpack_hide_jitm ) {
  516. $jetpack_hide_jitm = array(
  517. $module_slug => 'hide'
  518. );
  519. } else {
  520. $jetpack_hide_jitm[$module_slug] = 'hide';
  521. }
  522. Jetpack_Options::update_option( 'hide_jitm', $jetpack_hide_jitm );
  523. //jitm is being dismissed forever, track it
  524. $this->stat( 'jitm', $module_slug.'-dismissed-' . JETPACK__VERSION );
  525. $this->do_stats( 'server_side' );
  526. wp_send_json_success();
  527. }
  528. if ( isset( $_REQUEST['jitmActionToTake'] ) && 'launch' == $_REQUEST['jitmActionToTake'] ) {
  529. $module_slug = $_REQUEST['jitmModule'];
  530. // User went to WordPress.com, track this
  531. $this->stat( 'jitm', $module_slug.'-wordpress-tools-' . JETPACK__VERSION );
  532. $this->do_stats( 'server_side' );
  533. wp_send_json_success();
  534. }
  535. if ( isset( $_REQUEST['jitmActionToTake'] ) && 'viewed' == $_REQUEST['jitmActionToTake'] ) {
  536. $track = $_REQUEST['jitmModule'];
  537. // User is viewing JITM, track it.
  538. $this->stat( 'jitm', $track . '-viewed-' . JETPACK__VERSION );
  539. $this->do_stats( 'server_side' );
  540. wp_send_json_success();
  541. }
  542. }
  543. /**
  544. * If there are any stats that need to be pushed, but haven't been, push them now.
  545. */
  546. function __destruct() {
  547. if ( ! empty( $this->stats ) ) {
  548. $this->do_stats( 'server_side' );
  549. }
  550. }
  551. function jetpack_custom_caps( $caps, $cap, $user_id, $args ) {
  552. switch( $cap ) {
  553. case 'jetpack_connect' :
  554. case 'jetpack_reconnect' :
  555. if ( Jetpack::is_development_mode() ) {
  556. $caps = array( 'do_not_allow' );
  557. break;
  558. }
  559. /**
  560. * Pass through. If it's not development mode, these should match disconnect.
  561. * Let users disconnect if it's development mode, just in case things glitch.
  562. */
  563. case 'jetpack_disconnect' :
  564. /**
  565. * In multisite, can individual site admins manage their own connection?
  566. *
  567. * Ideally, this should be extracted out to a separate filter in the Jetpack_Network class.
  568. */
  569. if ( is_multisite() && ! is_super_admin() && is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
  570. if ( ! Jetpack_Network::init()->get_option( 'sub-site-connection-override' ) ) {
  571. /**
  572. * We need to update the option name -- it's terribly unclear which
  573. * direction the override goes.
  574. *
  575. * @todo: Update the option name to `sub-sites-can-manage-own-connections`
  576. */
  577. $caps = array( 'do_not_allow' );
  578. break;
  579. }
  580. }
  581. $caps = array( 'manage_options' );
  582. break;
  583. case 'jetpack_manage_modules' :
  584. case 'jetpack_activate_modules' :
  585. case 'jetpack_deactivate_modules' :
  586. $caps = array( 'manage_options' );
  587. break;
  588. case 'jetpack_configure_modules' :
  589. $caps = array( 'manage_options' );
  590. break;
  591. case 'jetpack_network_admin_page':
  592. case 'jetpack_network_settings_page':
  593. $caps = array( 'manage_network_plugins' );
  594. break;
  595. case 'jetpack_network_sites_page':
  596. $caps = array( 'manage_sites' );
  597. break;
  598. case 'jetpack_admin_page' :
  599. if ( Jetpack::is_development_mode() ) {
  600. $caps = array( 'manage_options' );
  601. break;
  602. } else {
  603. $caps = array( 'read' );
  604. }
  605. break;
  606. case 'jetpack_connect_user' :
  607. if ( Jetpack::is_development_mode() ) {
  608. $caps = array( 'do_not_allow' );
  609. break;
  610. }
  611. $caps = array( 'read' );
  612. break;
  613. }
  614. return $caps;
  615. }
  616. function require_jetpack_authentication() {
  617. // Don't let anyone authenticate
  618. $_COOKIE = array();
  619. remove_all_filters( 'authenticate' );
  620. remove_all_actions( 'wp_login_failed' );
  621. if ( Jetpack::is_active() ) {
  622. // Allow Jetpack authentication
  623. add_filter( 'authenticate', array( $this, 'authenticate_jetpack' ), 10, 3 );
  624. }
  625. }
  626. /**
  627. * Load language files
  628. * @action plugins_loaded
  629. */
  630. public static function plugin_textdomain() {
  631. // Note to self, the third argument must not be hardcoded, to account for relocated folders.
  632. load_plugin_textdomain( 'jetpack', false, dirname( plugin_basename( JETPACK__PLUGIN_FILE ) ) . '/languages/' );
  633. }
  634. /**
  635. * Register assets for use in various modules and the Jetpack admin page.
  636. *
  637. * @uses wp_script_is, wp_register_script, plugins_url
  638. * @action wp_loaded
  639. * @return null
  640. */
  641. public function register_assets() {
  642. if ( ! wp_script_is( 'spin', 'registered' ) ) {
  643. wp_register_script( 'spin', plugins_url( '_inc/spin.js', JETPACK__PLUGIN_FILE ), false, '1.3' );
  644. }
  645. if ( ! wp_script_is( 'jquery.spin', 'registered' ) ) {
  646. wp_register_script( 'jquery.spin', plugins_url( '_inc/jquery.spin.js', JETPACK__PLUGIN_FILE ) , array( 'jquery', 'spin' ), '1.3' );
  647. }
  648. if ( ! wp_script_is( 'jetpack-gallery-settings', 'registered' ) ) {
  649. wp_register_script( 'jetpack-gallery-settings', plugins_url( '_inc/gallery-settings.js', JETPACK__PLUGIN_FILE ), array( 'media-views' ), '20121225' );
  650. }
  651. if ( ! wp_script_is( 'jetpack-twitter-timeline', 'registered' ) ) {
  652. wp_register_script( 'jetpack-twitter-timeline', plugins_url( '_inc/twitter-timeline.js', JETPACK__PLUGIN_FILE ) , array( 'jquery' ), '4.0.0', true );
  653. }
  654. if ( ! wp_script_is( 'jetpack-facebook-embed', 'registered' ) ) {
  655. wp_register_script( 'jetpack-facebook-embed', plugins_url( '_inc/facebook-embed.js', __FILE__ ), array( 'jquery' ), null, true );
  656. /** This filter is documented in modules/sharedaddy/sharing-sources.php */
  657. $fb_app_id = apply_filters( 'jetpack_sharing_facebook_app_id', '249643311490' );
  658. if ( ! is_numeric( $fb_app_id ) ) {
  659. $fb_app_id = '';
  660. }
  661. wp_localize_script(
  662. 'jetpack-facebook-embed',
  663. 'jpfbembed',
  664. array(
  665. 'appid' => $fb_app_id,
  666. 'locale' => $this->get_locale(),
  667. )
  668. );
  669. }
  670. /**
  671. * As jetpack_register_genericons is by default fired off a hook,
  672. * the hook may have already fired by this point.
  673. * So, let's just trigger it manually.
  674. */
  675. require_once( JETPACK__PLUGIN_DIR . '_inc/genericons.php' );
  676. jetpack_register_genericons();
  677. /**
  678. * Register the social logos
  679. */
  680. require_once( JETPACK__PLUGIN_DIR . '_inc/social-logos.php' );
  681. jetpack_register_social_logos();
  682. if ( ! wp_style_is( 'jetpack-icons', 'registered' ) )
  683. wp_register_style( 'jetpack-icons', plugins_url( 'css/jetpack-icons.min.css', JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION );
  684. }
  685. /**
  686. * Guess locale from language code.
  687. *
  688. * @param string $lang Language code.
  689. * @return string|bool
  690. */
  691. function guess_locale_from_lang( $lang ) {
  692. if ( 'en' === $lang || 'en_US' === $lang || ! $lang ) {
  693. return 'en_US';
  694. }
  695. if ( ! class_exists( 'GP_Locales' ) ) {
  696. if ( ! defined( 'JETPACK__GLOTPRESS_LOCALES_PATH' ) || ! file_exists( JETPACK__GLOTPRESS_LOCALES_PATH ) ) {
  697. return false;
  698. }
  699. require JETPACK__GLOTPRESS_LOCALES_PATH;
  700. }
  701. if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
  702. // WP.com: get_locale() returns 'it'
  703. $locale = GP_Locales::by_slug( $lang );
  704. } else {
  705. // Jetpack: get_locale() returns 'it_IT';
  706. $locale = GP_Locales::by_field( 'facebook_locale', $lang );
  707. }
  708. if ( ! $locale ) {
  709. return false;
  710. }
  711. if ( empty( $locale->facebook_locale ) ) {
  712. if ( empty( $locale->wp_locale ) ) {
  713. return false;
  714. } else {
  715. // Facebook SDK is smart enough to fall back to en_US if a
  716. // locale isn't supported. Since supported Facebook locales
  717. // can fall out of sync, we'll attempt to use the known
  718. // wp_locale value and rely on said fallback.
  719. return $locale->wp_locale;
  720. }
  721. }
  722. return $locale->facebook_locale;
  723. }
  724. /**
  725. * Get the locale.
  726. *
  727. * @return string|bool
  728. */
  729. function get_locale() {
  730. $locale = $this->guess_locale_from_lang( get_locale() );
  731. if ( ! $locale ) {
  732. $locale = 'en_US';
  733. }
  734. return $locale;
  735. }
  736. /**
  737. * Device Pixels support
  738. * This improves the resolution of gravatars and wordpress.com uploads on hi-res and zoomed browsers.
  739. */
  740. function devicepx() {
  741. if ( Jetpack::is_active() ) {
  742. wp_enqueue_script( 'devicepx', set_url_scheme( 'http://s0.wp.com/wp-content/js/devicepx-jetpack.js' ), array(), gmdate( 'oW' ), true );
  743. }
  744. }
  745. /**
  746. * Return the network_site_url so that .com knows what network this site is a part of.
  747. * @param bool $option
  748. * @return string
  749. */
  750. public function jetpack_main_network_site_option( $option ) {
  751. return network_site_url();
  752. }
  753. /**
  754. * Network Name.
  755. */
  756. static function network_name( $option = null ) {
  757. global $current_site;
  758. return $current_site->site_name;
  759. }
  760. /**
  761. * Does the network allow new user and site registrations.
  762. * @return string
  763. */
  764. static function network_allow_new_registrations( $option = null ) {
  765. return ( in_array( get_site_option( 'registration' ), array('none', 'user', 'blog', 'all' ) ) ? get_site_option( 'registration') : 'none' );
  766. }
  767. /**
  768. * Does the network allow admins to add new users.
  769. * @return boolian
  770. */
  771. static function network_add_new_users( $option = null ) {
  772. return (bool) get_site_option( 'add_new_users' );
  773. }
  774. /**
  775. * File upload psace left per site in MB.
  776. * -1 means NO LIMIT.
  777. * @return number
  778. */
  779. static function network_site_upload_space( $option = null ) {
  780. // value in MB
  781. return ( get_site_option( 'upload_space_check_disabled' ) ? -1 : get_space_allowed() );
  782. }
  783. /**
  784. * Network allowed file types.
  785. * @return string
  786. */
  787. static function network_upload_file_types( $option = null ) {
  788. return get_site_option( 'upload_filetypes', 'jpg jpeg png gif' );
  789. }
  790. /**
  791. * Maximum file upload size set by the network.
  792. * @return number
  793. */
  794. static function network_max_upload_file_size( $option = null ) {
  795. // value in KB
  796. return get_site_option( 'fileupload_maxk', 300 );
  797. }
  798. /**
  799. * Lets us know if a site allows admins to manage the network.
  800. * @return array
  801. */
  802. static function network_enable_administration_menus( $option = null ) {
  803. return get_site_option( 'menu_items' );
  804. }
  805. /**
  806. * Return whether we are dealing with a multi network setup or not.
  807. * The reason we are type casting this is because we want to avoid the situation where
  808. * the result is false since when is_main_network_option return false it cases
  809. * the rest the get_option( 'jetpack_is_multi_network' ); to return the value that is set in the
  810. * database which could be set to anything as opposed to what this function returns.
  811. * @param bool $option
  812. *
  813. * @return boolean
  814. */
  815. public function is_main_network_option( $option ) {
  816. // return '1' or ''
  817. return (string) (bool) Jetpack::is_multi_network();
  818. }
  819. /**
  820. * Return true if we are with multi-site or multi-network false if we are dealing with single site.
  821. *
  822. * @param string $option
  823. * @return boolean
  824. */
  825. public function is_multisite( $option ) {
  826. return (string) (bool) is_multisite();
  827. }
  828. /**
  829. * Implemented since there is no core is multi network function
  830. * Right now there is no way to tell if we which network is the dominant network on the system
  831. *
  832. * @since 3.3
  833. * @return boolean
  834. */
  835. public static function is_multi_network() {
  836. global $wpdb;
  837. // if we don't have a multi site setup no need to do any more
  838. if ( ! is_multisite() ) {
  839. return false;
  840. }
  841. $num_sites = $wpdb->get_var( "SELECT COUNT(*) FROM {$wpdb->site}" );
  842. if ( $num_sites > 1 ) {
  843. return true;
  844. } else {
  845. return false;
  846. }
  847. }
  848. /**
  849. * Trigger an update to the main_network_site when we update the siteurl of a site.
  850. * @return null
  851. */
  852. function update_jetpack_main_network_site_option() {
  853. _deprecated_function( __METHOD__, 'jetpack-4.2' );
  854. }
  855. /**
  856. * Triggered after a user updates the network settings via Network Settings Admin Page
  857. *
  858. */
  859. function update_jetpack_network_settings() {
  860. _deprecated_function( __METHOD__, 'jetpack-4.2' );
  861. // Only sync this info for the main network site.
  862. }
  863. /**
  864. * Get back if the current site is single user site.
  865. *
  866. * @return bool
  867. */
  868. public static function is_single_user_site() {
  869. global $wpdb;
  870. $some_users = $wpdb->get_var( "select count(*) from (select user_id from $wpdb->usermeta where meta_key = '{$wpdb->prefix}capabilities' LIMIT 2) as someusers" );
  871. return 1 === (int) $some_users;
  872. }
  873. /**
  874. * Returns true if the site has file write access false otherwise.
  875. * @return string ( '1' | '0' )
  876. **/
  877. public static function file_system_write_access() {
  878. if ( ! function_exists( 'get_filesystem_method' ) ) {
  879. require_once( ABSPATH . 'wp-admin/includes/file.php' );
  880. }
  881. require_once( ABSPATH . 'wp-admin/includes/template.php' );
  882. $filesystem_method = get_filesystem_method();
  883. if ( $filesystem_method === 'direct' ) {
  884. return 1;
  885. }
  886. ob_start();
  887. $filesystem_credentials_are_stored = request_filesystem_credentials( self_admin_url() );
  888. ob_end_clean();
  889. if ( $filesystem_credentials_are_stored ) {
  890. return 1;
  891. }
  892. return 0;
  893. }
  894. /**
  895. * Finds out if a site is using a version control system.
  896. * @return string ( '1' | '0' )
  897. **/
  898. public static function is_version_controlled() {
  899. _deprecated_function( __METHOD__, 'jetpack-4.2', 'Jetpack_Sync_Functions::is_version_controlled' );
  900. return (string) (int) Jetpack_Sync_Functions::is_version_controlled();
  901. }
  902. /**
  903. * Determines whether the current theme supports featured images or not.
  904. * @return string ( '1' | '0' )
  905. */
  906. public static function featured_images_enabled() {
  907. _deprecated_function( __METHOD__, 'jetpack-4.2' );
  908. return current_theme_supports( 'post-thumbnails' ) ? '1' : '0';
  909. }
  910. /**
  911. * jetpack_updates is saved in the following schema:
  912. *
  913. * array (
  914. * 'plugins' => (int) Number of plugin updates available.
  915. * 'themes' => (int) Number of theme updates available.
  916. * 'wordpress' => (int) Number of WordPress core updates available.
  917. * 'translations' => (int) Number of translation updates available.
  918. * 'total' => (int) Total of all available updates.
  919. * 'wp_update_version' => (string) The latest available version of WordPress, only present if a WordPress update is needed.
  920. * )
  921. * @return array
  922. */
  923. public static function get_updates() {
  924. $update_data = wp_get_update_data();
  925. // Stores the individual update counts as well as the total count.
  926. if ( isset( $update_data['counts'] ) ) {
  927. $updates = $update_data['counts'];
  928. }
  929. // If we need to update WordPress core, let's find the latest version number.
  930. if ( ! empty( $updates['wordpress'] ) ) {
  931. $cur = get_preferred_from_update_core();
  932. if ( isset( $cur->response ) && 'upgrade' === $cur->response ) {
  933. $updates['wp_update_version'] = $cur->current;
  934. }
  935. }
  936. return isset( $updates ) ? $updates : array();
  937. }
  938. public static function get_update_details() {
  939. $update_details = array(
  940. 'update_core' => get_site_transient( 'update_core' ),
  941. 'update_plugins' => get_site_transient( 'update_plugins' ),
  942. 'update_themes' => get_site_transient( 'update_themes' ),
  943. );
  944. return $update_details;
  945. }
  946. public static function refresh_update_data() {
  947. _deprecated_function( __METHOD__, 'jetpack-4.2' );
  948. }
  949. public static function refresh_theme_data() {
  950. _deprecated_function( __METHOD__, 'jetpack-4.2' );
  951. }
  952. /**
  953. * Is Jetpack active?
  954. */
  955. public static function is_active() {
  956. return (bool) Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
  957. }
  958. /**
  959. * Is Jetpack in development (offline) mode?
  960. */
  961. public static function is_development_mode() {
  962. $development_mode = false;
  963. if ( defined( 'JETPACK_DEV_DEBUG' ) ) {
  964. $development_mode = JETPACK_DEV_DEBUG;
  965. }
  966. elseif ( site_url() && false === strpos( site_url(), '.' ) ) {
  967. $development_mode = true;
  968. }
  969. /**
  970. * Filters Jetpack's development mode.
  971. *
  972. * @see https://jetpack.com/support/development-mode/
  973. *
  974. * @since 2.2.1
  975. *
  976. * @param bool $development_mode Is Jetpack's development mode active.
  977. */
  978. return apply_filters( 'jetpack_development_mode', $development_mode );
  979. }
  980. /**
  981. * Get Jetpack development mode notice text and notice class.
  982. *
  983. * Mirrors the checks made in Jetpack::is_development_mode
  984. *
  985. */
  986. public static function show_development_mode_notice() {
  987. if ( Jetpack::is_development_mode() ) {
  988. if ( defined( 'JETPACK_DEV_DEBUG' ) && JETPACK_DEV_DEBUG ) {
  989. $notice = sprintf(
  990. /* translators: %s is a URL */
  991. __( 'In <a href="%s" target="_blank">Development Mode</a>, via the JETPACK_DEV_DEBUG constant being defined in wp-config.php or elsewhere.', 'jetpack' ),
  992. 'https://jetpack.com/support/development-mode/'
  993. );
  994. } elseif ( site_url() && false === strpos( site_url(), '.' ) ) {
  995. $notice = sprintf(
  996. /* translators: %s is a URL */
  997. __( 'In <a href="%s" target="_blank">Development Mode</a>, via site URL lacking a dot (e.g. http://localhost).', 'jetpack' ),
  998. 'https://jetpack.com/support/development-mode/'
  999. );
  1000. } else {
  1001. $notice = sprintf(
  1002. /* translators: %s is a URL */
  1003. __( 'In <a href="%s" target="_blank">Development Mode</a>, via the jetpack_development_mode filter.', 'jetpack' ),
  1004. 'https://jetpack.com/support/development-mode/'
  1005. );
  1006. }
  1007. echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
  1008. }
  1009. // Throw up a notice if using a development version and as for feedback.
  1010. if ( Jetpack::is_development_version() ) {
  1011. /* translators: %s is a URL */
  1012. $notice = sprintf( __( 'You are currently running a development version of Jetpack. <a href="%s" target="_blank">Submit your feedback</a>', 'jetpack' ), 'https://jetpack.com/contact-support/beta-group/' );
  1013. echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
  1014. }
  1015. // Throw up a notice if using staging mode
  1016. if ( Jetpack::is_staging_site() ) {
  1017. /* translators: %s is a URL */
  1018. $notice = sprintf( __( 'You are running Jetpack on a <a href="%s" target="_blank">staging server</a>.', 'jetpack' ), 'https://jetpack.com/support/staging-sites/' );
  1019. echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
  1020. }
  1021. }
  1022. /**
  1023. * Whether Jetpack's version maps to a public release, or a development version.
  1024. */
  1025. public static function is_development_version() {
  1026. /**
  1027. * Allows filtering whether this is a development version of Jetpack.
  1028. *
  1029. * This filter is especially useful for tests.
  1030. *
  1031. * @since 4.3.0
  1032. *
  1033. * @param bool $development_version Is this a develoment version of Jetpack?
  1034. */
  1035. return (bool) apply_filters(
  1036. 'jetpack_development_version',
  1037. ! preg_match( '/^\d+(\.\d+)+$/', JETPACK__VERSION )
  1038. );
  1039. }
  1040. /**
  1041. * Is a given user (or the current user if none is specified) linked to a WordPress.com user?
  1042. */
  1043. public static function is_user_connected( $user_id = false ) {
  1044. $user_id = false === $user_id ? get_current_user_id() : absint( $user_id );
  1045. if ( ! $user_id ) {
  1046. return false;
  1047. }
  1048. return (bool) Jetpack_Data::get_access_token( $user_id );
  1049. }
  1050. /**
  1051. * Get the wpcom user data of the current|specified connected user.
  1052. */
  1053. public static function get_connected_user_data( $user_id = null ) {
  1054. if ( ! $user_id ) {
  1055. $user_id = get_current_user_id();
  1056. }
  1057. $transient_key = "jetpack_connected_user_data_$user_id";
  1058. if ( $cached_user_data = get_transient( $transient_key ) ) {
  1059. return $cached_user_data;
  1060. }
  1061. Jetpack::load_xml_rpc_client();
  1062. $xml = new Jetpack_IXR_Client( array(
  1063. 'user_id' => $user_id,
  1064. ) );
  1065. $xml->query( 'wpcom.getUser' );
  1066. if ( ! $xml->isError() ) {
  1067. $user_data = $xml->getResponse();
  1068. set_transient( $transient_key, $xml->getResponse(), DAY_IN_SECONDS );
  1069. return $user_data;
  1070. }
  1071. return false;
  1072. }
  1073. /**
  1074. * Get the wpcom email of the current|specified connected user.
  1075. */
  1076. public static function get_connected_user_email( $user_id = null ) {
  1077. if ( ! $user_id ) {
  1078. $user_id = get_current_user_id();
  1079. }
  1080. Jetpack::load_xml_rpc_client();
  1081. $xml = new Jetpack_IXR_Client( array(
  1082. 'user_id' => $user_id,
  1083. ) );
  1084. $xml->query( 'wpcom.getUserEmail' );
  1085. if ( ! $xml->isError() ) {
  1086. return $xml->getResponse();
  1087. }
  1088. return false;
  1089. }
  1090. /**
  1091. * Get the wpcom email of the master user.
  1092. */
  1093. public static function get_master_user_email() {
  1094. $master_user_id = Jetpack_Options::get_option( 'master_user' );
  1095. if ( $master_user_id ) {
  1096. return self::get_connected_user_email( $master_user_id );
  1097. }
  1098. return '';
  1099. }
  1100. function current_user_is_connection_owner() {
  1101. $user_token = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
  1102. return $user_token && is_object( $user_token ) && isset( $user_token->external_user_id ) && get_current_user_id() === $user_token->external_user_id;
  1103. }
  1104. /**
  1105. * Add any extra oEmbed providers that we know about and use on wpcom for feature parity.
  1106. */
  1107. function extra_oembed_providers() {
  1108. // Cloudup: https://dev.cloudup.com/#oembed
  1109. wp_oembed_add_provider( 'https://cloudup.com/*' , 'https://cloudup.com/oembed' );
  1110. wp_oembed_add_provider( 'https://me.sh/*', 'https://me.sh/oembed?format=json' );
  1111. wp_oembed_add_provider( '#https?://(www\.)?gfycat\.com/.*#i', 'https://api.gfycat.com/v1/oembed', true );
  1112. wp_oembed_add_provider( '#https?://[^.]+\.(wistia\.com|wi\.st)/(medias|embed)/.*#', 'https://fast.wistia.com/oembed', true );
  1113. wp_oembed_add_provider( '#https?://sketchfab\.com/.*#i', 'https://sketchfab.com/oembed', true );
  1114. }
  1115. /**
  1116. * Synchronize connected user role changes
  1117. */
  1118. function user_role_change( $user_id ) {
  1119. _deprecated_function( __METHOD__, 'jetpack-4.2', 'Jetpack_Sync_Users::user_role_change()' );
  1120. Jetpack_Sync_Users::user_role_change( $user_id );
  1121. }
  1122. /**
  1123. * Loads the currently active modules.
  1124. */
  1125. public static function load_modules() {
  1126. if ( ! self::is_active() && !self::is_development_mode() ) {
  1127. if ( ! is_multisite() || ! get_site_option( 'jetpack_protect_active' ) ) {
  1128. return;
  1129. }
  1130. }
  1131. $version = Jetpack_Options::get_option( 'version' );
  1132. if ( ! $version ) {
  1133. $version = $old_version = JETPACK__VERSION . ':' . time();
  1134. /** This action is documented in class.jetpack.php */
  1135. do_action( 'updating_jetpack_version', $version, false );
  1136. Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
  1137. }
  1138. list( $version ) = explode( ':', $version );
  1139. $modules = array_filter( Jetpack::get_active_modules(), array( 'Jetpack', 'is_module' ) );
  1140. $modules_data = array();
  1141. // Don't load modules that have had "Major" changes since the stored version until they have been deactivated/reactivated through the lint check.
  1142. if ( version_compare( $version, JETPACK__VERSION, '<' ) ) {
  1143. $updated_modules = array();
  1144. foreach ( $modules as $module ) {
  1145. $modules_data[ $module ] = Jetpack::get_module( $module );
  1146. if ( ! isset( $modules_data[ $module ]['changed'] ) ) {
  1147. continue;
  1148. }
  1149. if ( version_compare( $modules_data[ $module ]['changed'], $version, '<=' ) ) {
  1150. continue;
  1151. }
  1152. $updated_modules[] = $module;
  1153. }
  1154. $modules = array_diff( $modules, $updated_modules );
  1155. }
  1156. $is_development_mode = Jetpack::is_development_mode();
  1157. foreach ( $modules as $index => $module ) {
  1158. // If we're in dev mode, disable modules requiring a connection
  1159. if ( $is_development_mode ) {
  1160. // Prime the pump if we need to
  1161. if ( empty( $modules_data[ $module ] ) ) {
  1162. $modules_data[ $module ] = Jetpack::get_module( $module );
  1163. }
  1164. // If the module requires a connection, but we're in local mode, don't include it.
  1165. if ( $modules_data[ $module ]['requires_connection'] ) {
  1166. continue;
  1167. }
  1168. }
  1169. if ( did_action( 'jetpack_module_loaded_' . $module ) ) {
  1170. continue;
  1171. }
  1172. if ( ! @include( Jetpack::get_module_path( $module ) ) ) {
  1173. unset( $modules[ $index ] );
  1174. self::update_active_modules( array_values( $modules ) );
  1175. continue;
  1176. }
  1177. /**
  1178. * Fires when a specific module is loaded.
  1179. * The dynamic part of the hook, $module, is the module slug.
  1180. *
  1181. * @since 1.1.0
  1182. */
  1183. do_action( 'jetpack_module_loaded_' . $module );
  1184. }
  1185. /**
  1186. * Fires when all the modules are loaded.
  1187. *
  1188. * @since 1.1.0
  1189. */
  1190. do_action( 'jetpack_modules_loaded' );
  1191. // Load module-specific code that is needed even when a module isn't active. Loaded here because code contained therein may need actions such as setup_theme.
  1192. if ( Jetpack::is_active() || Jetpack::is_development_mode() )
  1193. require_once( JETPACK__PLUGIN_DIR . 'modules/module-extras.php' );
  1194. }
  1195. /**
  1196. * Check if Jetpack's REST API compat file should be included
  1197. * @action plugins_loaded
  1198. * @return null
  1199. */
  1200. public function check_rest_api_compat() {
  1201. /**
  1202. * Filters the list of REST API compat files to be included.
  1203. *
  1204. * @since 2.2.5
  1205. *
  1206. * @param array $args Array of REST API compat files to include.
  1207. */
  1208. $_jetpack_rest_api_compat_includes = apply_filters( 'jetpack_rest_api_compat', array() );
  1209. if ( function_exists( 'bbpress' ) )
  1210. $_jetpack_rest_api_compat_includes[] = JETPACK__PLUGIN_DIR . 'class.jetpack-bbpress-json-api-compat.php';
  1211. foreach ( $_jetpack_rest_api_compat_includes as $_jetpack_rest_api_compat_include )
  1212. require_once $_jetpack_rest_api_compat_include;
  1213. }
  1214. /**
  1215. * Gets all plugins currently active in values, regardless of whether they're
  1216. * traditionally activated or network activated.
  1217. *
  1218. * @todo Store the result in core's object cache maybe?
  1219. */
  1220. public static function get_active_plugins() {
  1221. $active_plugins = (array) get_option( 'active_plugins', array() );
  1222. if ( is_multisite() ) {
  1223. // Due to legacy code, active_sitewide_plugins stores them in the keys,
  1224. // whereas active_plugins stores them in the values.
  1225. $network_plugins = array_keys( get_site_option( 'active_sitewide_plugins', array() ) );
  1226. if ( $network_plugins ) {
  1227. $active_plugins = array_merge( $active_plugins, $network_plugins );
  1228. }
  1229. }
  1230. sort( $active_plugins );
  1231. return array_unique( $active_plugins );
  1232. }
  1233. /**
  1234. * Gets and parses additional plugin data to send with the heartbeat data
  1235. *
  1236. * @since 3.8.1
  1237. *
  1238. * @return array Array of plugin data
  1239. */
  1240. public static function get_parsed_plugin_data() {
  1241. if ( ! function_exists( 'get_plugins' ) ) {
  1242. require_once( ABSPATH . 'wp-admin/includes/plugin.php' );
  1243. }
  1244. /** This filter is documented in wp-admin/includes/class-wp-plugins-list-table.php */
  1245. $all_plugins = apply_filters( 'all_plugins', get_plugins() );
  1246. $active_plugins = Jetpack::get_active_plugins();
  1247. $plugins = array();
  1248. foreach ( $all_plugins as $path => $plugin_data ) {
  1249. $plugins[ $path ] = array(
  1250. 'is_active' => in_array( $path, $active_plugins ),
  1251. 'file' => $path,
  1252. 'name' => $plugin_data['Name'],
  1253. 'version' => $plugin_data['Version'],
  1254. 'author' => $plugin_data['Author'],
  1255. );
  1256. }
  1257. return $plugins;
  1258. }
  1259. /**
  1260. * Gets and parses theme data to send with the heartbeat data
  1261. *
  1262. * @since 3.8.1
  1263. *
  1264. * @return array Array of theme data
  1265. */
  1266. public static function get_parsed_theme_data() {
  1267. $all_themes = wp_get_themes( array( 'allowed' => true ) );
  1268. $header_keys = array( 'Name', 'Author', 'Version', 'ThemeURI', 'AuthorURI', 'Status', 'Tags' );
  1269. $themes = array();
  1270. foreach ( $all_themes as $slug => $theme_data ) {
  1271. $theme_headers = array();
  1272. foreach ( $header_keys as $header_key ) {
  1273. $theme_headers[ $header_key ] = $theme_data->get( $header_key );
  1274. }
  1275. $themes[ $slug ] = array(
  1276. 'is_active_theme' => $slug == wp_get_theme()->get_template(),
  1277. 'slug' => $slug,
  1278. 'theme_root' => $theme_data->get_theme_root_uri(),
  1279. 'parent' => $theme_data->parent(),
  1280. 'headers' => $theme_headers
  1281. );
  1282. }
  1283. return $themes;
  1284. }
  1285. /**
  1286. * Checks whether a specific plugin is active.
  1287. *
  1288. * We don't want to store these in a static variable, in case
  1289. * there are switch_to_blog() calls involved.
  1290. */
  1291. public static function is_plugin_active( $plugin = 'jetpack/jetpack.php' ) {
  1292. return in_array( $plugin, self::get_active_plugins() );
  1293. }
  1294. /**
  1295. * Check if Jetpack's Open Graph tags should be used.
  1296. * If certain plugins are active, Jetpack's og tags are suppressed.
  1297. *
  1298. * @uses Jetpack::get_active_modules, add_filter, get_option, apply_filters
  1299. * @action plugins_loaded
  1300. * @return null
  1301. */
  1302. public function check_open_graph() {
  1303. if ( in_array( 'publicize', Jetpack::get_active_modules() ) || in_array( 'sharedaddy', Jetpack::get_active_modules() ) ) {
  1304. add_filter( 'jetpack_enable_open_graph', '__return_true', 0 );
  1305. }
  1306. $active_plugins = self::get_active_plugins();
  1307. if ( ! empty( $active_plugins ) ) {
  1308. foreach ( $this->open_graph_conflicting_plugins as $plugin ) {
  1309. if ( in_array( $plugin, $active_plugins ) ) {
  1310. add_filter( 'jetpack_enable_open_graph', '__return_false', 99 );
  1311. break;
  1312. }
  1313. }
  1314. }
  1315. /**
  1316. * Allow the addition of Open Graph Meta Tags to all pages.
  1317. *
  1318. * @since 2.0.3
  1319. *
  1320. * @param bool false Should Open Graph Meta tags be added. Default to false.
  1321. */
  1322. if ( apply_filters( 'jetpack_enable_open_graph', false ) ) {
  1323. require_once JETPACK__PLUGIN_DIR . 'functions.opengraph.php';
  1324. }
  1325. }
  1326. /**
  1327. * Check if Jetpack's Twitter tags should be used.
  1328. * If certain plugins are active, Jetpack's twitter tags are suppressed.
  1329. *
  1330. * @uses Jetpack::get_active_modules, add_filter, get_option, apply_filters
  1331. * @action plugins_loaded
  1332. * @return null
  1333. */
  1334. public function check_twitter_tags() {
  1335. $active_plugins = self::get_active_plugins();
  1336. if ( ! empty( $active_plugins ) ) {
  1337. foreach ( $this->twitter_cards_conflicting_plugins as $plugin ) {
  1338. if ( in_array( $plugin, $active_plugins ) ) {
  1339. add_filter( 'jetpack_disable_twitter_cards', '__return_true', 99 );
  1340. break;
  1341. }
  1342. }
  1343. }
  1344. /**
  1345. * Allow Twitter Card Meta tags to be disabled.
  1346. *
  1347. * @since 2.6.0
  1348. *
  1349. * @param bool true Should Twitter Card Meta tags be disabled. Default to true.
  1350. */
  1351. if ( ! apply_filters( 'jetpack_disable_twitter_cards', false ) ) {
  1352. require_once JETPACK__PLUGIN_DIR . 'class.jetpack-twitter-cards.php';
  1353. }
  1354. }
  1355. /**
  1356. * Allows plugins to submit security reports.
  1357. *
  1358. * @param string $type Report type (login_form, backup, file_scanning, spam)
  1359. * @param string $plugin_file Plugin __FILE__, so that we can pull plugin data
  1360. * @param array $args See definitions above
  1361. */
  1362. public static function submit_security_report( $type = '', $plugin_file = '', $args = array() ) {
  1363. _deprecated_function( __FUNCTION__, 'jetpack-4.2', null );
  1364. }
  1365. /* Jetpack Options API */
  1366. public static function get_option_names( $type = 'compact' ) {
  1367. return Jetpack_Options::get_option_names( $type );
  1368. }
  1369. /**
  1370. * Returns the requested option. Looks in jetpack_options or jetpack_$name as appropriate.
  1371. *
  1372. * @param string $name Option name
  1373. * @param mixed $default (optional)
  1374. */
  1375. public static function get_option( $name, $default = false ) {
  1376. return Jetpack_Options::get_option( $name, $default );
  1377. }
  1378. /**
  1379. * Stores two secrets and a timestamp so WordPress.com can make a request back and verify an action
  1380. * Does some extra verification so urls (such as those to public-api, register, etc) can't just be crafted
  1381. * $name must be a registered option name.
  1382. */
  1383. public static function create_nonce( $name ) {
  1384. $secret = wp_generate_password( 32, false ) . ':' . wp_generate_password( 32, false ) . ':' . ( time() + 600 );
  1385. Jetpack_Options::update_option( $name, $secret );
  1386. @list( $secret_1, $secret_2, $eol ) = explode( ':', Jetpack_Options::get_option( $name ) );
  1387. if ( empty( $secret_1 ) || empty( $secret_2 ) || $eol < time() )
  1388. return new Jetpack_Error( 'missing_secrets' );
  1389. return array(
  1390. 'secret_1' => $secret_1,
  1391. 'secret_2' => $secret_2,
  1392. 'eol' => $eol,
  1393. );
  1394. }
  1395. /**
  1396. * Updates the single given option. Updates jetpack_options or jetpack_$name as appropriate.
  1397. *
  1398. * @deprecated 3.4 use Jetpack_Options::update_option() instead.
  1399. * @param string $name Option name
  1400. * @param mixed $value Option value
  1401. */
  1402. public static function update_option( $name, $value ) {
  1403. _deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::update_option()' );
  1404. return Jetpack_Options::update_option( $name, $value );
  1405. }
  1406. /**
  1407. * Updates the multiple given options. Updates jetpack_options and/or jetpack_$name as appropriate.
  1408. *
  1409. * @deprecated 3.4 use Jetpack_Options::update_options() instead.
  1410. * @param array $array array( option name => option value, ... )
  1411. */
  1412. public static function update_options( $array ) {
  1413. _deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::update_options()' );
  1414. return Jetpack_Options::update_options( $array );
  1415. }
  1416. /**
  1417. * Deletes the given option. May be passed multiple option names as an array.
  1418. * Updates jetpack_options and/or deletes jetpack_$name as appropriate.
  1419. *
  1420. * @deprecated 3.4 use Jetpack_Options::delete_option() instead.
  1421. * @param string|array $names
  1422. */
  1423. public static function delete_option( $names ) {
  1424. _deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::delete_option()' );
  1425. return Jetpack_Options::delete_option( $names );
  1426. }
  1427. /**
  1428. * Enters a user token into the user_tokens option
  1429. *
  1430. * @param int $user_id
  1431. * @param string $token
  1432. * return bool
  1433. */
  1434. public static function update_user_token( $user_id, $token, $is_master_user ) {
  1435. // not designed for concurrent updates
  1436. $user_tokens = Jetpack_Options::get_option( 'user_tokens' );
  1437. if ( ! is_array( $user_tokens ) )
  1438. $user_tokens = array();
  1439. $user_tokens[$user_id] = $token;
  1440. if ( $is_master_user ) {
  1441. $master_user = $user_id;
  1442. $options = compact( 'user_tokens', 'master_user' );
  1443. } else {
  1444. $options = compact( 'user_tokens' );
  1445. }
  1446. return Jetpack_Options::update_options( $options );
  1447. }
  1448. /**
  1449. * Returns an array of all PHP files in the specified absolute path.
  1450. * Equivalent to glob( "$absolute_path/*.php" ).
  1451. *
  1452. * @param string $absolute_path The absolute path of the directory to search.
  1453. * @return array Array of absolute paths to the PHP files.
  1454. */
  1455. public static function glob_php( $absolute_path ) {
  1456. if ( function_exists( 'glob' ) ) {
  1457. return glob( "$absolute_path/*.php" );
  1458. }
  1459. $absolute_path = untrailingslashit( $absolute_path );
  1460. $files = array();
  1461. if ( ! $dir = @opendir( $absolute_path ) ) {
  1462. return $files;
  1463. }
  1464. while ( false !== $file = readdir( $dir ) ) {
  1465. if ( '.' == substr( $file, 0, 1 ) || '.php' != substr( $file, -4 ) ) {
  1466. continue;
  1467. }
  1468. $file = "$absolute_path/$file";
  1469. if ( ! is_file( $file ) ) {
  1470. continue;
  1471. }
  1472. $files[] = $file;
  1473. }
  1474. closedir( $dir );
  1475. return $files;
  1476. }
  1477. public static function activate_new_modules( $redirect = false ) {
  1478. if ( ! Jetpack::is_active() && ! Jetpack::is_development_mode() ) {
  1479. return;
  1480. }
  1481. $jetpack_old_version = Jetpack_Options::get_option( 'version' ); // [sic]
  1482. if ( ! $jetpack_old_version ) {
  1483. $jetpack_old_version = $version = $old_version = '1.1:' . time();
  1484. /** This action is documented in class.jetpack.php */
  1485. do_action( 'updating_jetpack_version', $version, false );
  1486. Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
  1487. }
  1488. list( $jetpack_version ) = explode( ':', $jetpack_old_version ); // [sic]
  1489. if ( version_compare( JETPACK__VERSION, $jetpack_version, '<=' ) ) {
  1490. return;
  1491. }
  1492. $active_modules = Jetpack::get_active_modules();
  1493. $reactivate_modules = array();
  1494. foreach ( $active_modules as $active_module ) {
  1495. $module = Jetpack::get_module( $active_module );
  1496. if ( ! isset( $module['changed'] ) ) {
  1497. continue;
  1498. }
  1499. if ( version_compare( $module['changed'], $jetpack_version, '<=' ) ) {
  1500. continue;
  1501. }
  1502. $reactivate_modules[] = $active_module;
  1503. Jetpack::deactivate_module( $active_module );
  1504. }
  1505. $new_version = JETPACK__VERSION . ':' . time();
  1506. /** This action is documented in class.jetpack.php */
  1507. do_action( 'updating_jetpack_version', $new_version, $jetpack_old_version );
  1508. Jetpack_Options::update_options(
  1509. array(
  1510. 'version' => $new_version,
  1511. 'old_version' => $jetpack_old_version,
  1512. )
  1513. );
  1514. Jetpack::state( 'message', 'modules_activated' );
  1515. Jetpack::activate_default_modules( $jetpack_version, JETPACK__VERSION, $reactivate_modules );
  1516. if ( $redirect ) {
  1517. $page = 'jetpack'; // make sure we redirect to either settings or the jetpack page
  1518. if ( isset( $_GET['page'] ) && in_array( $_GET['page'], array( 'jetpack', 'jetpack_modules' ) ) ) {
  1519. $page = $_GET['page'];
  1520. }
  1521. wp_safe_redirect( Jetpack::admin_url( 'page=' . $page ) );
  1522. exit;
  1523. }
  1524. }
  1525. /**
  1526. * List available Jetpack modules. Simply lists .php files in /modules/.
  1527. * Make sure to tuck away module "library" files in a sub-directory.
  1528. */
  1529. public static function get_available_modules( $min_version = false, $max_version = false ) {
  1530. static $modules = null;
  1531. if ( ! isset( $modules ) ) {
  1532. $available_modules_option = Jetpack_Options::get_option( 'available_modules', array() );
  1533. // Use the cache if we're on the front-end and it's available...
  1534. if ( ! is_admin() && ! empty( $available_modules_option[ JETPACK__VERSION ] ) ) {
  1535. $modules = $available_modules_option[ JETPACK__VERSION ];
  1536. } else {
  1537. $files = Jetpack::glob_php( JETPACK__PLUGIN_DIR . 'modules' );
  1538. $modules = array();
  1539. foreach ( $files as $file ) {
  1540. if ( ! $headers = Jetpack::get_module( $file ) ) {
  1541. continue;
  1542. }
  1543. $modules[ Jetpack::get_module_slug( $file ) ] = $headers['introduced'];
  1544. }
  1545. Jetpack_Options::update_option( 'available_modules', array(
  1546. JETPACK__VERSION => $modules,
  1547. ) );
  1548. }
  1549. }
  1550. /**
  1551. * Filters the array of modules available to be activated.
  1552. *
  1553. * @since 2.4.0
  1554. *
  1555. * @param array $modules Array of available modules.
  1556. * @param string $min_version Minimum version number required to use modules.
  1557. * @param string $max_version Maximum version number required to use modules.
  1558. */
  1559. $mods = apply_filters( 'jetpack_get_available_modules', $modules, $min_version, $max_version );
  1560. if ( ! $min_version && ! $max_version ) {
  1561. return array_keys( $mods );
  1562. }
  1563. $r = array();
  1564. foreach ( $mods as $slug => $introduced ) {
  1565. if ( $min_version && version_compare( $min_version, $introduced, '>=' ) ) {
  1566. continue;
  1567. }
  1568. if ( $max_version && version_compare( $max_version, $introduced, '<' ) ) {
  1569. continue;
  1570. }
  1571. $r[] = $slug;
  1572. }
  1573. return $r;
  1574. }
  1575. /**
  1576. * Default modules loaded on activation.
  1577. */
  1578. public static function get_default_modules( $min_version = false, $max_version = false ) {
  1579. $return = array();
  1580. foreach ( Jetpack::get_available_modules( $min_version, $max_version ) as $module ) {
  1581. $module_data = Jetpack::get_module( $module );
  1582. switch ( strtolower( $module_data['auto_activate'] ) ) {
  1583. case 'yes' :
  1584. $return[] = $module;
  1585. break;
  1586. case 'public' :
  1587. if ( Jetpack_Options::get_option( 'public' ) ) {
  1588. $return[] = $module;
  1589. }
  1590. break;
  1591. case 'no' :
  1592. default :
  1593. break;
  1594. }
  1595. }
  1596. /**
  1597. * Filters the array of default modules.
  1598. *
  1599. * @since 2.5.0
  1600. *
  1601. * @param array $return Array of default modules.
  1602. * @param string $min_version Minimum version number required to use modules.
  1603. * @param string $max_version Maximum version number required to use modules.
  1604. */
  1605. return apply_filters( 'jetpack_get_default_modules', $return, $min_version, $max_version );
  1606. }
  1607. /**
  1608. * Checks activated modules during auto-activation to determine
  1609. * if any of those modules are being deprecated. If so, close
  1610. * them out, and add any replacement modules.
  1611. *
  1612. * Runs at priority 99 by default.
  1613. *
  1614. * This is run late, so that it can still activate a module if
  1615. * the new module is a replacement for another that the user
  1616. * currently has active, even if something at the normal priority
  1617. * would kibosh everything.
  1618. *
  1619. * @since 2.6
  1620. * @uses jetpack_get_default_modules filter
  1621. * @param array $modules
  1622. * @return array
  1623. */
  1624. function handle_deprecated_modules( $modules ) {
  1625. $deprecated_modules = array(
  1626. 'debug' => null, // Closed out and moved to ./class.jetpack-debugger.php
  1627. 'wpcc' => 'sso', // Closed out in 2.6 -- SSO provides the same functionality.
  1628. 'gplus-authorship' => null, // Closed out in 3.2 -- Google dropped support.
  1629. );
  1630. // Don't activate SSO if they never completed activating WPCC.
  1631. if ( Jetpack::is_module_active( 'wpcc' ) ) {
  1632. $wpcc_options = Jetpack_Options::get_option( 'wpcc_options' );
  1633. if ( empty( $wpcc_options ) || empty( $wpcc_options['client_id'] ) || empty( $wpcc_options['client_id'] ) ) {
  1634. $deprecated_modules['wpcc'] = null;
  1635. }
  1636. }
  1637. foreach ( $deprecated_modules as $module => $replacement ) {
  1638. if ( Jetpack::is_module_active( $module ) ) {
  1639. self::deactivate_module( $module );
  1640. if ( $replacement ) {
  1641. $modules[] = $replacement;
  1642. }
  1643. }
  1644. }
  1645. return array_unique( $modules );
  1646. }
  1647. /**
  1648. * Checks activated plugins during auto-activation to determine
  1649. * if any of those plugins are in the list with a corresponding module
  1650. * that is not compatible with the plugin. The module will not be allowed
  1651. * to auto-activate.
  1652. *
  1653. * @since 2.6
  1654. * @uses jetpack_get_default_modules filter
  1655. * @param array $modules
  1656. * @return array
  1657. */
  1658. function filter_default_modules( $modules ) {
  1659. $active_plugins = self::get_active_plugins();
  1660. if ( ! empty( $active_plugins ) ) {
  1661. // For each module we'd like to auto-activate...
  1662. foreach ( $modules as $key => $module ) {
  1663. // If there are potential conflicts for it...
  1664. if ( ! empty( $this->conflicting_plugins[ $module ] ) ) {
  1665. // For each potential conflict...
  1666. foreach ( $this->conflicting_plugins[ $module ] as $title => $plugin ) {
  1667. // If that conflicting plugin is active...
  1668. if ( in_array( $plugin, $active_plugins ) ) {
  1669. // Remove that item from being auto-activated.
  1670. unset( $modules[ $key ] );
  1671. }
  1672. }
  1673. }
  1674. }
  1675. }
  1676. return $modules;
  1677. }
  1678. /**
  1679. * Extract a module's slug from its full path.
  1680. */
  1681. public static function get_module_slug( $file ) {
  1682. return str_replace( '.php', '', basename( $file ) );
  1683. }
  1684. /**
  1685. * Generate a module's path from its slug.
  1686. */
  1687. public static function get_module_path( $slug ) {
  1688. return JETPACK__PLUGIN_DIR . "modules/$slug.php";
  1689. }
  1690. /**
  1691. * Load module data from module file. Headers differ from WordPress
  1692. * plugin headers to avoid them being identified as standalone
  1693. * plugins on the WordPress plugins page.
  1694. */
  1695. public static function get_module( $module ) {
  1696. $headers = array(
  1697. 'name' => 'Module Name',
  1698. 'description' => 'Module Description',
  1699. 'jumpstart_desc' => 'Jumpstart Description',
  1700. 'sort' => 'Sort Order',
  1701. 'recommendation_order' => 'Recommendation Order',
  1702. 'introduced' => 'First Introduced',
  1703. 'changed' => 'Major Changes In',
  1704. 'deactivate' => 'Deactivate',
  1705. 'free' => 'Free',
  1706. 'requires_connection' => 'Requires Connection',
  1707. 'auto_activate' => 'Auto Activate',
  1708. 'module_tags' => 'Module Tags',
  1709. 'feature' => 'Feature',
  1710. 'additional_search_queries' => 'Additional Search Queries',
  1711. );
  1712. $file = Jetpack::get_module_path( Jetpack::get_module_slug( $module ) );
  1713. $mod = Jetpack::get_file_data( $file, $headers );
  1714. if ( empty( $mod['name'] ) ) {
  1715. return false;
  1716. }
  1717. $mod['sort'] = empty( $mod['sort'] ) ? 10 : (int) $mod['sort'];
  1718. $mod['recommendation_order'] = empty( $mod['recommendation_order'] ) ? 20 : (int) $mod['recommendation_order'];
  1719. $mod['deactivate'] = empty( $mod['deactivate'] );
  1720. $mod['free'] = empty( $mod['free'] );
  1721. $mod['requires_connection'] = ( ! empty( $mod['requires_connection'] ) && 'No' == $mod['requires_connection'] ) ? false : true;
  1722. if ( empty( $mod['auto_activate'] ) || ! in_array( strtolower( $mod['auto_activate'] ), array( 'yes', 'no', 'public' ) ) ) {
  1723. $mod['auto_activate'] = 'No';
  1724. } else {
  1725. $mod['auto_activate'] = (string) $mod['auto_activate'];
  1726. }
  1727. if ( $mod['module_tags'] ) {
  1728. $mod['module_tags'] = explode( ',', $mod['module_tags'] );
  1729. $mod['module_tags'] = array_map( 'trim', $mod['module_tags'] );
  1730. $mod['module_tags'] = array_map( array( __CLASS__, 'translate_module_tag' ), $mod['module_tags'] );
  1731. } else {
  1732. $mod['module_tags'] = array( self::translate_module_tag( 'Other' ) );
  1733. }
  1734. if ( $mod['feature'] ) {
  1735. $mod['feature'] = explode( ',', $mod['feature'] );
  1736. $mod['feature'] = array_map( 'trim', $mod['feature'] );
  1737. } else {
  1738. $mod['feature'] = array( self::translate_module_tag( 'Other' ) );
  1739. }
  1740. /**
  1741. * Filters the feature array on a module.
  1742. *
  1743. * This filter allows you to control where each module is filtered: Recommended,
  1744. * Jumpstart, and the default "Other" listing.
  1745. *
  1746. * @since 3.5.0
  1747. *
  1748. * @param array $mod['feature'] The areas to feature this module:
  1749. * 'Jumpstart' adds to the "Jumpstart" option to activate many modules at once.
  1750. * 'Recommended' shows on the main Jetpack admin screen.
  1751. * 'Other' should be the default if no other value is in the array.
  1752. * @param string $module The slug of the module, e.g. sharedaddy.
  1753. * @param array $mod All the currently assembled module data.
  1754. */
  1755. $mod['feature'] = apply_filters( 'jetpack_module_feature', $mod['feature'], $module, $mod );
  1756. /**
  1757. * Filter the returned data about a module.
  1758. *
  1759. * This filter allows overriding any info about Jetpack modules. It is dangerous,
  1760. * so please be careful.
  1761. *
  1762. * @since 3.6.0
  1763. *
  1764. * @param array $mod The details of the requested module.
  1765. * @param string $module The slug of the module, e.g. sharedaddy
  1766. * @param string $file The path to the module source file.
  1767. */
  1768. return apply_filters( 'jetpack_get_module', $mod, $module, $file );
  1769. }
  1770. /**
  1771. * Like core's get_file_data implementation, but caches the result.
  1772. */
  1773. public static function get_file_data( $file, $headers ) {
  1774. //Get just the filename from $file (i.e. exclude full path) so that a consistent hash is generated
  1775. $file_name = basename( $file );
  1776. $file_data_option = Jetpack_Options::get_option( 'file_data', array() );
  1777. $key = md5( $file_name . serialize( $headers ) );
  1778. $refresh_cache = is_admin() && isset( $_GET['page'] ) && 'jetpack' === substr( $_GET['page'], 0, 7 );
  1779. // If we don't need to refresh the cache, and already have the value, short-circuit!
  1780. if ( ! $refresh_cache && isset( $file_data_option[ JETPACK__VERSION ][ $key ] ) ) {
  1781. return $file_data_option[ JETPACK__VERSION ][ $key ];
  1782. }
  1783. $data = get_file_data( $file, $headers );
  1784. // Strip out any old Jetpack versions that are cluttering the option.
  1785. $file_data_option = array_intersect_key( (array) $file_data_option, array( JETPACK__VERSION => null ) );
  1786. $file_data_option[ JETPACK__VERSION ][ $key ] = $data;
  1787. Jetpack_Options::update_option( 'file_data', $file_data_option );
  1788. return $data;
  1789. }
  1790. /**
  1791. * Return translated module tag.
  1792. *
  1793. * @param string $tag Tag as it appears in each module heading.
  1794. *
  1795. * @return mixed
  1796. */
  1797. public static function translate_module_tag( $tag ) {
  1798. return jetpack_get_module_i18n_tag( $tag );
  1799. }
  1800. /**
  1801. * Return module name translation. Uses matching string created in modules/module-headings.php.
  1802. *
  1803. * @since 3.9.2
  1804. *
  1805. * @param array $modules
  1806. *
  1807. * @return string|void
  1808. */
  1809. public static function get_translated_modules( $modules ) {
  1810. foreach ( $modules as $index => $module ) {
  1811. $i18n_module = jetpack_get_module_i18n( $module['module'] );
  1812. if ( isset( $module['name'] ) ) {
  1813. $modules[ $index ]['name'] = $i18n_module['name'];
  1814. }
  1815. if ( isset( $module['description'] ) ) {
  1816. $modules[ $index ]['description'] = $i18n_module['description'];
  1817. $modules[ $index ]['short_description'] = $i18n_module['description'];
  1818. }
  1819. }
  1820. return $modules;
  1821. }
  1822. /**
  1823. * Get a list of activated modules as an array of module slugs.
  1824. */
  1825. public static function get_active_modules() {
  1826. $active = Jetpack_Options::get_option( 'active_modules' );
  1827. if ( ! is_array( $active ) )
  1828. $active = array();
  1829. if ( class_exists( 'VaultPress' ) || function_exists( 'vaultpress_contact_service' ) ) {
  1830. $active[] = 'vaultpress';
  1831. } else {
  1832. $active = array_diff( $active, array( 'vaultpress' ) );
  1833. }
  1834. //If protect is active on the main site of a multisite, it should be active on all sites.
  1835. if ( ! in_array( 'protect', $active ) && is_multisite() && get_site_option( 'jetpack_protect_active' ) ) {
  1836. $active[] = 'protect';
  1837. }
  1838. return array_unique( $active );
  1839. }
  1840. /**
  1841. * Check whether or not a Jetpack module is active.
  1842. *
  1843. * @param string $module The slug of a Jetpack module.
  1844. * @return bool
  1845. *
  1846. * @static
  1847. */
  1848. public static function is_module_active( $module ) {
  1849. return in_array( $module, self::get_active_modules() );
  1850. }
  1851. public static function is_module( $module ) {
  1852. return ! empty( $module ) && ! validate_file( $module, Jetpack::get_available_modules() );
  1853. }
  1854. /**
  1855. * Catches PHP errors. Must be used in conjunction with output buffering.
  1856. *
  1857. * @param bool $catch True to start catching, False to stop.
  1858. *
  1859. * @static
  1860. */
  1861. public static function catch_errors( $catch ) {
  1862. static $display_errors, $error_reporting;
  1863. if ( $catch ) {
  1864. $display_errors = @ini_set( 'display_errors', 1 );
  1865. $error_reporting = @error_reporting( E_ALL );
  1866. add_action( 'shutdown', array( 'Jetpack', 'catch_errors_on_shutdown' ), 0 );
  1867. } else {
  1868. @ini_set( 'display_errors', $display_errors );
  1869. @error_reporting( $error_reporting );
  1870. remove_action( 'shutdown', array( 'Jetpack', 'catch_errors_on_shutdown' ), 0 );
  1871. }
  1872. }
  1873. /**
  1874. * Saves any generated PHP errors in ::state( 'php_errors', {errors} )
  1875. */
  1876. public static function catch_errors_on_shutdown() {
  1877. Jetpack::state( 'php_errors', ob_get_clean() );
  1878. }
  1879. public static function activate_default_modules( $min_version = false, $max_version = false, $other_modules = array(), $redirect = true ) {
  1880. $jetpack = Jetpack::init();
  1881. $modules = Jetpack::get_default_modules( $min_version, $max_version );
  1882. $modules = array_merge( $other_modules, $modules );
  1883. // Look for standalone plugins and disable if active.
  1884. $to_deactivate = array();
  1885. foreach ( $modules as $module ) {
  1886. if ( isset( $jetpack->plugins_to_deactivate[$module] ) ) {
  1887. $to_deactivate[$module] = $jetpack->plugins_to_deactivate[$module];
  1888. }
  1889. }
  1890. $deactivated = array();
  1891. foreach ( $to_deactivate as $module => $deactivate_me ) {
  1892. list( $probable_file, $probable_title ) = $deactivate_me;
  1893. if ( Jetpack_Client_Server::deactivate_plugin( $probable_file, $probable_title ) ) {
  1894. $deactivated[] = $module;
  1895. }
  1896. }
  1897. if ( $deactivated && $redirect ) {
  1898. Jetpack::state( 'deactivated_plugins', join( ',', $deactivated ) );
  1899. $url = add_query_arg(
  1900. array(
  1901. 'action' => 'activate_default_modules',
  1902. '_wpnonce' => wp_create_nonce( 'activate_default_modules' ),
  1903. ),
  1904. add_query_arg( compact( 'min_version', 'max_version', 'other_modules' ), Jetpack::admin_url( 'page=jetpack' ) )
  1905. );
  1906. wp_safe_redirect( $url );
  1907. exit;
  1908. }
  1909. /**
  1910. * Fires before default modules are activated.
  1911. *
  1912. * @since 1.9.0
  1913. *
  1914. * @param string $min_version Minimum version number required to use modules.
  1915. * @param string $max_version Maximum version number required to use modules.
  1916. * @param array $other_modules Array of other modules to activate alongside the default modules.
  1917. */
  1918. do_action( 'jetpack_before_activate_default_modules', $min_version, $max_version, $other_modules );
  1919. // Check each module for fatal errors, a la wp-admin/plugins.php::activate before activating
  1920. Jetpack::restate();
  1921. Jetpack::catch_errors( true );
  1922. $active = Jetpack::get_active_modules();
  1923. foreach ( $modules as $module ) {
  1924. if ( did_action( "jetpack_module_loaded_$module" ) ) {
  1925. $active[] = $module;
  1926. self::update_active_modules( $active );
  1927. continue;
  1928. }
  1929. if ( in_array( $module, $active ) ) {
  1930. $module_info = Jetpack::get_module( $module );
  1931. if ( ! $module_info['deactivate'] ) {
  1932. $state = in_array( $module, $other_modules ) ? 'reactivated_modules' : 'activated_modules';
  1933. if ( $active_state = Jetpack::state( $state ) ) {
  1934. $active_state = explode( ',', $active_state );
  1935. } else {
  1936. $active_state = array();
  1937. }
  1938. $active_state[] = $module;
  1939. Jetpack::state( $state, implode( ',', $active_state ) );
  1940. }
  1941. continue;
  1942. }
  1943. $file = Jetpack::get_module_path( $module );
  1944. if ( ! file_exists( $file ) ) {
  1945. continue;
  1946. }
  1947. // we'll override this later if the plugin can be included without fatal error
  1948. if ( $redirect ) {
  1949. wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
  1950. }
  1951. Jetpack::state( 'error', 'module_activation_failed' );
  1952. Jetpack::state( 'module', $module );
  1953. ob_start();
  1954. require $file;
  1955. $active[] = $module;
  1956. $state = in_array( $module, $other_modules ) ? 'reactivated_modules' : 'activated_modules';
  1957. if ( $active_state = Jetpack::state( $state ) ) {
  1958. $active_state = explode( ',', $active_state );
  1959. } else {
  1960. $active_state = array();
  1961. }
  1962. $active_state[] = $module;
  1963. Jetpack::state( $state, implode( ',', $active_state ) );
  1964. Jetpack::update_active_modules( $active );
  1965. ob_end_clean();
  1966. }
  1967. Jetpack::state( 'error', false );
  1968. Jetpack::state( 'module', false );
  1969. Jetpack::catch_errors( false );
  1970. /**
  1971. * Fires when default modules are activated.
  1972. *
  1973. * @since 1.9.0
  1974. *
  1975. * @param string $min_version Minimum version number required to use modules.
  1976. * @param string $max_version Maximum version number required to use modules.
  1977. * @param array $other_modules Array of other modules to activate alongside the default modules.
  1978. */
  1979. do_action( 'jetpack_activate_default_modules', $min_version, $max_version, $other_modules );
  1980. }
  1981. public static function activate_module( $module, $exit = true, $redirect = true ) {
  1982. /**
  1983. * Fires before a module is activated.
  1984. *
  1985. * @since 2.6.0
  1986. *
  1987. * @param string $module Module slug.
  1988. * @param bool $exit Should we exit after the module has been activated. Default to true.
  1989. * @param bool $redirect Should the user be redirected after module activation? Default to true.
  1990. */
  1991. do_action( 'jetpack_pre_activate_module', $module, $exit, $redirect );
  1992. $jetpack = Jetpack::init();
  1993. if ( ! strlen( $module ) )
  1994. return false;
  1995. if ( ! Jetpack::is_module( $module ) )
  1996. return false;
  1997. // If it's already active, then don't do it again
  1998. $active = Jetpack::get_active_modules();
  1999. foreach ( $active as $act ) {
  2000. if ( $act == $module )
  2001. return true;
  2002. }
  2003. $module_data = Jetpack::get_module( $module );
  2004. if ( ! Jetpack::is_active() ) {
  2005. if ( !Jetpack::is_development_mode() )
  2006. return false;
  2007. // If we're not connected but in development mode, make sure the module doesn't require a connection
  2008. if ( Jetpack::is_development_mode() && $module_data['requires_connection'] )
  2009. return false;
  2010. }
  2011. // Check and see if the old plugin is active
  2012. if ( isset( $jetpack->plugins_to_deactivate[ $module ] ) ) {
  2013. // Deactivate the old plugin
  2014. if ( Jetpack_Client_Server::deactivate_plugin( $jetpack->plugins_to_deactivate[ $module ][0], $jetpack->plugins_to_deactivate[ $module ][1] ) ) {
  2015. // If we deactivated the old plugin, remembere that with ::state() and redirect back to this page to activate the module
  2016. // We can't activate the module on this page load since the newly deactivated old plugin is still loaded on this page load.
  2017. Jetpack::state( 'deactivated_plugins', $module );
  2018. wp_safe_redirect( add_query_arg( 'jetpack_restate', 1 ) );
  2019. exit;
  2020. }
  2021. }
  2022. // Check the file for fatal errors, a la wp-admin/plugins.php::activate
  2023. Jetpack::state( 'module', $module );
  2024. Jetpack::state( 'error', 'module_activation_failed' ); // we'll override this later if the plugin can be included without fatal error
  2025. Jetpack::catch_errors( true );
  2026. ob_start();
  2027. require Jetpack::get_module_path( $module );
  2028. /** This action is documented in class.jetpack.php */
  2029. do_action( 'jetpack_activate_module', $module );
  2030. $active[] = $module;
  2031. Jetpack::update_active_modules( $active );
  2032. Jetpack::state( 'error', false ); // the override
  2033. ob_end_clean();
  2034. Jetpack::catch_errors( false );
  2035. // A flag for Jump Start so it's not shown again. Only set if it hasn't been yet.
  2036. if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
  2037. Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
  2038. //Jump start is being dismissed send data to MC Stats
  2039. $jetpack->stat( 'jumpstart', 'manual,'.$module );
  2040. $jetpack->do_stats( 'server_side' );
  2041. }
  2042. if ( $redirect ) {
  2043. wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
  2044. }
  2045. if ( $exit ) {
  2046. exit;
  2047. }
  2048. return true;
  2049. }
  2050. function activate_module_actions( $module ) {
  2051. _deprecated_function( __METHOD__, 'jeptack-4.2' );
  2052. }
  2053. public static function deactivate_module( $module ) {
  2054. /**
  2055. * Fires when a module is deactivated.
  2056. *
  2057. * @since 1.9.0
  2058. *
  2059. * @param string $module Module slug.
  2060. */
  2061. do_action( 'jetpack_pre_deactivate_module', $module );
  2062. $jetpack = Jetpack::init();
  2063. $active = Jetpack::get_active_modules();
  2064. $new = array_filter( array_diff( $active, (array) $module ) );
  2065. // A flag for Jump Start so it's not shown again.
  2066. if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
  2067. Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
  2068. //Jump start is being dismissed send data to MC Stats
  2069. $jetpack->stat( 'jumpstart', 'manual,deactivated-'.$module );
  2070. $jetpack->do_stats( 'server_side' );
  2071. }
  2072. return self::update_active_modules( $new );
  2073. }
  2074. public static function enable_module_configurable( $module ) {
  2075. $module = Jetpack::get_module_slug( $module );
  2076. add_filter( 'jetpack_module_configurable_' . $module, '__return_true' );
  2077. }
  2078. public static function module_configuration_url( $module ) {
  2079. $module = Jetpack::get_module_slug( $module );
  2080. return Jetpack::admin_url( array( 'page' => 'jetpack', 'configure' => $module ) );
  2081. }
  2082. public static function module_configuration_load( $module, $method ) {
  2083. $module = Jetpack::get_module_slug( $module );
  2084. add_action( 'jetpack_module_configuration_load_' . $module, $method );
  2085. }
  2086. public static function module_configuration_head( $module, $method ) {
  2087. $module = Jetpack::get_module_slug( $module );
  2088. add_action( 'jetpack_module_configuration_head_' . $module, $method );
  2089. }
  2090. public static function module_configuration_screen( $module, $method ) {
  2091. $module = Jetpack::get_module_slug( $module );
  2092. add_action( 'jetpack_module_configuration_screen_' . $module, $method );
  2093. }
  2094. public static function module_configuration_activation_screen( $module, $method ) {
  2095. $module = Jetpack::get_module_slug( $module );
  2096. add_action( 'display_activate_module_setting_' . $module, $method );
  2097. }
  2098. /* Installation */
  2099. public static function bail_on_activation( $message, $deactivate = true ) {
  2100. ?>
  2101. <!doctype html>
  2102. <html>
  2103. <head>
  2104. <meta charset="<?php bloginfo( 'charset' ); ?>">
  2105. <style>
  2106. * {
  2107. text-align: center;
  2108. margin: 0;
  2109. padding: 0;
  2110. font-family: "Lucida Grande",Verdana,Arial,"Bitstream Vera Sans",sans-serif;
  2111. }
  2112. p {
  2113. margin-top: 1em;
  2114. font-size: 18px;
  2115. }
  2116. </style>
  2117. <body>
  2118. <p><?php echo esc_html( $message ); ?></p>
  2119. </body>
  2120. </html>
  2121. <?php
  2122. if ( $deactivate ) {
  2123. $plugins = get_option( 'active_plugins' );
  2124. $jetpack = plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' );
  2125. $update = false;
  2126. foreach ( $plugins as $i => $plugin ) {
  2127. if ( $plugin === $jetpack ) {
  2128. $plugins[$i] = false;
  2129. $update = true;
  2130. }
  2131. }
  2132. if ( $update ) {
  2133. update_option( 'active_plugins', array_filter( $plugins ) );
  2134. }
  2135. }
  2136. exit;
  2137. }
  2138. /**
  2139. * Attached to activate_{ plugin_basename( __FILES__ ) } by register_activation_hook()
  2140. * @static
  2141. */
  2142. public static function plugin_activation( $network_wide ) {
  2143. Jetpack_Options::update_option( 'activated', 1 );
  2144. if ( version_compare( $GLOBALS['wp_version'], JETPACK__MINIMUM_WP_VERSION, '<' ) ) {
  2145. Jetpack::bail_on_activation( sprintf( __( 'Jetpack requires WordPress version %s or later.', 'jetpack' ), JETPACK__MINIMUM_WP_VERSION ) );
  2146. }
  2147. if ( $network_wide )
  2148. Jetpack::state( 'network_nag', true );
  2149. Jetpack::plugin_initialize();
  2150. }
  2151. /**
  2152. * Runs before bumping version numbers up to a new version
  2153. * @param (string) $version Version:timestamp
  2154. * @param (string) $old_version Old Version:timestamp or false if not set yet.
  2155. * @return null [description]
  2156. */
  2157. public static function do_version_bump( $version, $old_version ) {
  2158. if ( ! $old_version ) { // For new sites
  2159. // Setting up jetpack manage
  2160. Jetpack::activate_manage();
  2161. }
  2162. }
  2163. /**
  2164. * Sets the internal version number and activation state.
  2165. * @static
  2166. */
  2167. public static function plugin_initialize() {
  2168. if ( ! Jetpack_Options::get_option( 'activated' ) ) {
  2169. Jetpack_Options::update_option( 'activated', 2 );
  2170. }
  2171. if ( ! Jetpack_Options::get_option( 'version' ) ) {
  2172. $version = $old_version = JETPACK__VERSION . ':' . time();
  2173. /** This action is documented in class.jetpack.php */
  2174. do_action( 'updating_jetpack_version', $version, false );
  2175. Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
  2176. }
  2177. Jetpack::load_modules();
  2178. Jetpack_Options::delete_option( 'do_activate' );
  2179. }
  2180. /**
  2181. * Removes all connection options
  2182. * @static
  2183. */
  2184. public static function plugin_deactivation( ) {
  2185. require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
  2186. if( is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
  2187. Jetpack_Network::init()->deactivate();
  2188. } else {
  2189. Jetpack::disconnect( false );
  2190. //Jetpack_Heartbeat::init()->deactivate();
  2191. }
  2192. }
  2193. /**
  2194. * Disconnects from the Jetpack servers.
  2195. * Forgets all connection details and tells the Jetpack servers to do the same.
  2196. * @static
  2197. */
  2198. public static function disconnect( $update_activated_state = true ) {
  2199. wp_clear_scheduled_hook( 'jetpack_clean_nonces' );
  2200. Jetpack::clean_nonces( true );
  2201. Jetpack::load_xml_rpc_client();
  2202. $xml = new Jetpack_IXR_Client();
  2203. $xml->query( 'jetpack.deregister' );
  2204. Jetpack_Options::delete_option(
  2205. array(
  2206. 'register',
  2207. 'blog_token',
  2208. 'user_token',
  2209. 'user_tokens',
  2210. 'master_user',
  2211. 'time_diff',
  2212. 'fallback_no_verify_ssl_certs',
  2213. )
  2214. );
  2215. if ( $update_activated_state ) {
  2216. Jetpack_Options::update_option( 'activated', 4 );
  2217. }
  2218. if ( $jetpack_unique_connection = Jetpack_Options::get_option( 'unique_connection' ) ) {
  2219. // Check then record unique disconnection if site has never been disconnected previously
  2220. if ( - 1 == $jetpack_unique_connection['disconnected'] ) {
  2221. $jetpack_unique_connection['disconnected'] = 1;
  2222. } else {
  2223. if ( 0 == $jetpack_unique_connection['disconnected'] ) {
  2224. //track unique disconnect
  2225. $jetpack = Jetpack::init();
  2226. $jetpack->stat( 'connections', 'unique-disconnect' );
  2227. $jetpack->do_stats( 'server_side' );
  2228. }
  2229. // increment number of times disconnected
  2230. $jetpack_unique_connection['disconnected'] += 1;
  2231. }
  2232. Jetpack_Options::update_option( 'unique_connection', $jetpack_unique_connection );
  2233. }
  2234. // Delete all the sync related data. Since it could be taking up space.
  2235. require_once JETPACK__PLUGIN_DIR . 'sync/class.jetpack-sync-sender.php';
  2236. Jetpack_Sync_Sender::get_instance()->uninstall();
  2237. // Disable the Heartbeat cron
  2238. Jetpack_Heartbeat::init()->deactivate();
  2239. }
  2240. /**
  2241. * Unlinks the current user from the linked WordPress.com user
  2242. */
  2243. public static function unlink_user( $user_id = null ) {
  2244. if ( ! $tokens = Jetpack_Options::get_option( 'user_tokens' ) )
  2245. return false;
  2246. $user_id = empty( $user_id ) ? get_current_user_id() : intval( $user_id );
  2247. if ( Jetpack_Options::get_option( 'master_user' ) == $user_id )
  2248. return false;
  2249. if ( ! isset( $tokens[ $user_id ] ) )
  2250. return false;
  2251. Jetpack::load_xml_rpc_client();
  2252. $xml = new Jetpack_IXR_Client( compact( 'user_id' ) );
  2253. $xml->query( 'jetpack.unlink_user', $user_id );
  2254. unset( $tokens[ $user_id ] );
  2255. Jetpack_Options::update_option( 'user_tokens', $tokens );
  2256. /**
  2257. * Fires after the current user has been unlinked from WordPress.com.
  2258. *
  2259. * @since 4.1.0
  2260. *
  2261. * @param int $user_id The current user's ID.
  2262. */
  2263. do_action( 'jetpack_unlinked_user', $user_id );
  2264. return true;
  2265. }
  2266. /**
  2267. * Attempts Jetpack registration. If it fail, a state flag is set: @see ::admin_page_load()
  2268. */
  2269. public static function try_registration() {
  2270. // Let's get some testing in beta versions and such.
  2271. if ( self::is_development_version() && defined( 'PHP_URL_HOST' ) ) {
  2272. // Before attempting to connect, let's make sure that the domains are viable.
  2273. $domains_to_check = array_unique( array(
  2274. 'siteurl' => parse_url( get_site_url(), PHP_URL_HOST ),
  2275. 'homeurl' => parse_url( get_home_url(), PHP_URL_HOST ),
  2276. ) );
  2277. foreach ( $domains_to_check as $domain ) {
  2278. $result = Jetpack_Data::is_usable_domain( $domain );
  2279. if ( is_wp_error( $result ) ) {
  2280. return $result;
  2281. }
  2282. }
  2283. }
  2284. $result = Jetpack::register();
  2285. // If there was an error with registration and the site was not registered, record this so we can show a message.
  2286. if ( ! $result || is_wp_error( $result ) ) {
  2287. return $result;
  2288. } else {
  2289. return true;
  2290. }
  2291. }
  2292. /**
  2293. * Tracking an internal event log. Try not to put too much chaff in here.
  2294. *
  2295. * [Everyone Loves a Log!](https://www.youtube.com/watch?v=2C7mNr5WMjA)
  2296. */
  2297. public static function log( $code, $data = null ) {
  2298. // only grab the latest 200 entries
  2299. $log = array_slice( Jetpack_Options::get_option( 'log', array() ), -199, 199 );
  2300. // Append our event to the log
  2301. $log_entry = array(
  2302. 'time' => time(),
  2303. 'user_id' => get_current_user_id(),
  2304. 'blog_id' => Jetpack_Options::get_option( 'id' ),
  2305. 'code' => $code,
  2306. );
  2307. // Don't bother storing it unless we've got some.
  2308. if ( ! is_null( $data ) ) {
  2309. $log_entry['data'] = $data;
  2310. }
  2311. $log[] = $log_entry;
  2312. // Try add_option first, to make sure it's not autoloaded.
  2313. // @todo: Add an add_option method to Jetpack_Options
  2314. if ( ! add_option( 'jetpack_log', $log, null, 'no' ) ) {
  2315. Jetpack_Options::update_option( 'log', $log );
  2316. }
  2317. /**
  2318. * Fires when Jetpack logs an internal event.
  2319. *
  2320. * @since 3.0.0
  2321. *
  2322. * @param array $log_entry {
  2323. * Array of details about the log entry.
  2324. *
  2325. * @param string time Time of the event.
  2326. * @param int user_id ID of the user who trigerred the event.
  2327. * @param int blog_id Jetpack Blog ID.
  2328. * @param string code Unique name for the event.
  2329. * @param string data Data about the event.
  2330. * }
  2331. */
  2332. do_action( 'jetpack_log_entry', $log_entry );
  2333. }
  2334. /**
  2335. * Get the internal event log.
  2336. *
  2337. * @param $event (string) - only return the specific log events
  2338. * @param $num (int) - get specific number of latest results, limited to 200
  2339. *
  2340. * @return array of log events || WP_Error for invalid params
  2341. */
  2342. public static function get_log( $event = false, $num = false ) {
  2343. if ( $event && ! is_string( $event ) ) {
  2344. return new WP_Error( __( 'First param must be string or empty', 'jetpack' ) );
  2345. }
  2346. if ( $num && ! is_numeric( $num ) ) {
  2347. return new WP_Error( __( 'Second param must be numeric or empty', 'jetpack' ) );
  2348. }
  2349. $entire_log = Jetpack_Options::get_option( 'log', array() );
  2350. // If nothing set - act as it did before, otherwise let's start customizing the output
  2351. if ( ! $num && ! $event ) {
  2352. return $entire_log;
  2353. } else {
  2354. $entire_log = array_reverse( $entire_log );
  2355. }
  2356. $custom_log_output = array();
  2357. if ( $event ) {
  2358. foreach ( $entire_log as $log_event ) {
  2359. if ( $event == $log_event[ 'code' ] ) {
  2360. $custom_log_output[] = $log_event;
  2361. }
  2362. }
  2363. } else {
  2364. $custom_log_output = $entire_log;
  2365. }
  2366. if ( $num ) {
  2367. $custom_log_output = array_slice( $custom_log_output, 0, $num );
  2368. }
  2369. return $custom_log_output;
  2370. }
  2371. /**
  2372. * Log modification of important settings.
  2373. */
  2374. public static function log_settings_change( $option, $old_value, $value ) {
  2375. switch( $option ) {
  2376. case 'jetpack_sync_non_public_post_stati':
  2377. self::log( $option, $value );
  2378. break;
  2379. }
  2380. }
  2381. /**
  2382. * Return stat data for WPCOM sync
  2383. */
  2384. public static function get_stat_data( $encode = true ) {
  2385. $heartbeat_data = Jetpack_Heartbeat::generate_stats_array();
  2386. $additional_data = self::get_additional_stat_data();
  2387. $merged_data = array_merge( $heartbeat_data, $additional_data );
  2388. if ( $encode ) {
  2389. return json_encode( $merged_data );
  2390. }
  2391. return $merged_data;
  2392. }
  2393. /**
  2394. * Get additional stat data to sync to WPCOM
  2395. */
  2396. public static function get_additional_stat_data( $prefix = '' ) {
  2397. $return["{$prefix}themes"] = Jetpack::get_parsed_theme_data();
  2398. $return["{$prefix}plugins-extra"] = Jetpack::get_parsed_plugin_data();
  2399. $return["{$prefix}users"] = count_users();
  2400. $return["{$prefix}site-count"] = 0;
  2401. if ( function_exists( 'get_blog_count' ) ) {
  2402. $return["{$prefix}site-count"] = get_blog_count();
  2403. }
  2404. return $return;
  2405. }
  2406. /* Admin Pages */
  2407. function admin_init() {
  2408. // If the plugin is not connected, display a connect message.
  2409. if (
  2410. // the plugin was auto-activated and needs its candy
  2411. Jetpack_Options::get_option_and_ensure_autoload( 'do_activate', '0' )
  2412. ||
  2413. // the plugin is active, but was never activated. Probably came from a site-wide network activation
  2414. ! Jetpack_Options::get_option( 'activated' )
  2415. ) {
  2416. Jetpack::plugin_initialize();
  2417. }
  2418. if ( ! Jetpack::is_active() && ! Jetpack::is_development_mode() ) {
  2419. if ( 4 != Jetpack_Options::get_option( 'activated' ) ) {
  2420. // Show connect notice on dashboard and plugins pages
  2421. add_action( 'load-index.php', array( $this, 'prepare_connect_notice' ) );
  2422. add_action( 'load-plugins.php', array( $this, 'prepare_connect_notice' ) );
  2423. }
  2424. } elseif ( false === Jetpack_Options::get_option( 'fallback_no_verify_ssl_certs' ) ) {
  2425. // Upgrade: 1.1 -> 1.1.1
  2426. // Check and see if host can verify the Jetpack servers' SSL certificate
  2427. $args = array();
  2428. Jetpack_Client::_wp_remote_request(
  2429. Jetpack::fix_url_for_bad_hosts( Jetpack::api_url( 'test' ) ),
  2430. $args,
  2431. true
  2432. );
  2433. } else {
  2434. // Show the notice on the Dashboard only for now
  2435. add_action( 'load-index.php', array( $this, 'prepare_manage_jetpack_notice' ) );
  2436. }
  2437. if ( current_user_can( 'manage_options' ) && 'AUTO' == JETPACK_CLIENT__HTTPS && ! self::permit_ssl() ) {
  2438. add_action( 'jetpack_notices', array( $this, 'alert_auto_ssl_fail' ) );
  2439. }
  2440. add_action( 'load-plugins.php', array( $this, 'intercept_plugin_error_scrape_init' ) );
  2441. add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
  2442. add_filter( 'plugin_action_links_' . plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' ), array( $this, 'plugin_action_links' ) );
  2443. if ( Jetpack::is_active() || Jetpack::is_development_mode() ) {
  2444. // Artificially throw errors in certain whitelisted cases during plugin activation
  2445. add_action( 'activate_plugin', array( $this, 'throw_error_on_activate_plugin' ) );
  2446. }
  2447. // Jetpack Manage Activation Screen from .com
  2448. Jetpack::module_configuration_activation_screen( 'manage', array( $this, 'manage_activate_screen' ) );
  2449. // Add custom column in wp-admin/users.php to show whether user is linked.
  2450. add_filter( 'manage_users_columns', array( $this, 'jetpack_icon_user_connected' ) );
  2451. add_action( 'manage_users_custom_column', array( $this, 'jetpack_show_user_connected_icon' ), 10, 3 );
  2452. add_action( 'admin_print_styles', array( $this, 'jetpack_user_col_style' ) );
  2453. }
  2454. function admin_body_class( $admin_body_class = '' ) {
  2455. $classes = explode( ' ', trim( $admin_body_class ) );
  2456. $classes[] = self::is_active() ? 'jetpack-connected' : 'jetpack-disconnected';
  2457. $admin_body_class = implode( ' ', array_unique( $classes ) );
  2458. return " $admin_body_class ";
  2459. }
  2460. static function add_jetpack_pagestyles( $admin_body_class = '' ) {
  2461. return $admin_body_class . ' jetpack-pagestyles ';
  2462. }
  2463. function prepare_connect_notice() {
  2464. add_action( 'admin_print_styles', array( $this, 'admin_banner_styles' ) );
  2465. add_action( 'admin_notices', array( $this, 'admin_connect_notice' ) );
  2466. if ( Jetpack::state( 'network_nag' ) )
  2467. add_action( 'network_admin_notices', array( $this, 'network_connect_notice' ) );
  2468. }
  2469. /**
  2470. * Call this function if you want the Big Jetpack Manage Notice to show up.
  2471. *
  2472. * @return null
  2473. */
  2474. function prepare_manage_jetpack_notice() {
  2475. add_action( 'admin_print_styles', array( $this, 'admin_banner_styles' ) );
  2476. add_action( 'admin_notices', array( $this, 'admin_jetpack_manage_notice' ) );
  2477. }
  2478. function manage_activate_screen() {
  2479. include ( JETPACK__PLUGIN_DIR . 'modules/manage/activate-admin.php' );
  2480. }
  2481. /**
  2482. * Sometimes a plugin can activate without causing errors, but it will cause errors on the next page load.
  2483. * This function artificially throws errors for such cases (whitelisted).
  2484. *
  2485. * @param string $plugin The activated plugin.
  2486. */
  2487. function throw_error_on_activate_plugin( $plugin ) {
  2488. $active_modules = Jetpack::get_active_modules();
  2489. // The Shortlinks module and the Stats plugin conflict, but won't cause errors on activation because of some function_exists() checks.
  2490. if ( function_exists( 'stats_get_api_key' ) && in_array( 'shortlinks', $active_modules ) ) {
  2491. $throw = false;
  2492. // Try and make sure it really was the stats plugin
  2493. if ( ! class_exists( 'ReflectionFunction' ) ) {
  2494. if ( 'stats.php' == basename( $plugin ) ) {
  2495. $throw = true;
  2496. }
  2497. } else {
  2498. $reflection = new ReflectionFunction( 'stats_get_api_key' );
  2499. if ( basename( $plugin ) == basename( $reflection->getFileName() ) ) {
  2500. $throw = true;
  2501. }
  2502. }
  2503. if ( $throw ) {
  2504. trigger_error( sprintf( __( 'Jetpack contains the most recent version of the old &#8220;%1$s&#8221; plugin.', 'jetpack' ), 'WordPress.com Stats' ), E_USER_ERROR );
  2505. }
  2506. }
  2507. }
  2508. function intercept_plugin_error_scrape_init() {
  2509. add_action( 'check_admin_referer', array( $this, 'intercept_plugin_error_scrape' ), 10, 2 );
  2510. }
  2511. function intercept_plugin_error_scrape( $action, $result ) {
  2512. if ( ! $result ) {
  2513. return;
  2514. }
  2515. foreach ( $this->plugins_to_deactivate as $deactivate_me ) {
  2516. if ( "plugin-activation-error_{$deactivate_me[0]}" == $action ) {
  2517. Jetpack::bail_on_activation( sprintf( __( 'Jetpack contains the most recent version of the old &#8220;%1$s&#8221; plugin.', 'jetpack' ), $deactivate_me[1] ), false );
  2518. }
  2519. }
  2520. }
  2521. function add_remote_request_handlers() {
  2522. add_action( 'wp_ajax_nopriv_jetpack_upload_file', array( $this, 'remote_request_handlers' ) );
  2523. }
  2524. function remote_request_handlers() {
  2525. switch ( current_filter() ) {
  2526. case 'wp_ajax_nopriv_jetpack_upload_file' :
  2527. $response = $this->upload_handler();
  2528. break;
  2529. default :
  2530. $response = new Jetpack_Error( 'unknown_handler', 'Unknown Handler', 400 );
  2531. break;
  2532. }
  2533. if ( ! $response ) {
  2534. $response = new Jetpack_Error( 'unknown_error', 'Unknown Error', 400 );
  2535. }
  2536. if ( is_wp_error( $response ) ) {
  2537. $status_code = $response->get_error_data();
  2538. $error = $response->get_error_code();
  2539. $error_description = $response->get_error_message();
  2540. if ( ! is_int( $status_code ) ) {
  2541. $status_code = 400;
  2542. }
  2543. status_header( $status_code );
  2544. die( json_encode( (object) compact( 'error', 'error_description' ) ) );
  2545. }
  2546. status_header( 200 );
  2547. if ( true === $response ) {
  2548. exit;
  2549. }
  2550. die( json_encode( (object) $response ) );
  2551. }
  2552. function upload_handler() {
  2553. if ( 'POST' !== strtoupper( $_SERVER['REQUEST_METHOD'] ) ) {
  2554. return new Jetpack_Error( 405, get_status_header_desc( 405 ), 405 );
  2555. }
  2556. $user = wp_authenticate( '', '' );
  2557. if ( ! $user || is_wp_error( $user ) ) {
  2558. return new Jetpack_Error( 403, get_status_header_desc( 403 ), 403 );
  2559. }
  2560. wp_set_current_user( $user->ID );
  2561. if ( ! current_user_can( 'upload_files' ) ) {
  2562. return new Jetpack_Error( 'cannot_upload_files', 'User does not have permission to upload files', 403 );
  2563. }
  2564. if ( empty( $_FILES ) ) {
  2565. return new Jetpack_Error( 'no_files_uploaded', 'No files were uploaded: nothing to process', 400 );
  2566. }
  2567. foreach ( array_keys( $_FILES ) as $files_key ) {
  2568. if ( ! isset( $_POST["_jetpack_file_hmac_{$files_key}"] ) ) {
  2569. return new Jetpack_Error( 'missing_hmac', 'An HMAC for one or more files is missing', 400 );
  2570. }
  2571. }
  2572. $media_keys = array_keys( $_FILES['media'] );
  2573. $token = Jetpack_Data::get_access_token( get_current_user_id() );
  2574. if ( ! $token || is_wp_error( $token ) ) {
  2575. return new Jetpack_Error( 'unknown_token', 'Unknown Jetpack token', 403 );
  2576. }
  2577. $uploaded_files = array();
  2578. $global_post = isset( $GLOBALS['post'] ) ? $GLOBALS['post'] : null;
  2579. unset( $GLOBALS['post'] );
  2580. foreach ( $_FILES['media']['name'] as $index => $name ) {
  2581. $file = array();
  2582. foreach ( $media_keys as $media_key ) {
  2583. $file[$media_key] = $_FILES['media'][$media_key][$index];
  2584. }
  2585. list( $hmac_provided, $salt ) = explode( ':', $_POST['_jetpack_file_hmac_media'][$index] );
  2586. $hmac_file = hash_hmac_file( 'sha1', $file['tmp_name'], $salt . $token->secret );
  2587. if ( $hmac_provided !== $hmac_file ) {
  2588. $uploaded_files[$index] = (object) array( 'error' => 'invalid_hmac', 'error_description' => 'The corresponding HMAC for this file does not match' );
  2589. continue;
  2590. }
  2591. $_FILES['.jetpack.upload.'] = $file;
  2592. $post_id = isset( $_POST['post_id'][$index] ) ? absint( $_POST['post_id'][$index] ) : 0;
  2593. if ( ! current_user_can( 'edit_post', $post_id ) ) {
  2594. $post_id = 0;
  2595. }
  2596. $attachment_id = media_handle_upload(
  2597. '.jetpack.upload.',
  2598. $post_id,
  2599. array(),
  2600. array(
  2601. 'action' => 'jetpack_upload_file',
  2602. )
  2603. );
  2604. if ( ! $attachment_id ) {
  2605. $uploaded_files[$index] = (object) array( 'error' => 'unknown', 'error_description' => 'An unknown problem occurred processing the upload on the Jetpack site' );
  2606. } elseif ( is_wp_error( $attachment_id ) ) {
  2607. $uploaded_files[$index] = (object) array( 'error' => 'attachment_' . $attachment_id->get_error_code(), 'error_description' => $attachment_id->get_error_message() );
  2608. } else {
  2609. $attachment = get_post( $attachment_id );
  2610. $uploaded_files[$index] = (object) array(
  2611. 'id' => (string) $attachment_id,
  2612. 'file' => $attachment->post_title,
  2613. 'url' => wp_get_attachment_url( $attachment_id ),
  2614. 'type' => $attachment->post_mime_type,
  2615. 'meta' => wp_get_attachment_metadata( $attachment_id ),
  2616. );
  2617. }
  2618. }
  2619. if ( ! is_null( $global_post ) ) {
  2620. $GLOBALS['post'] = $global_post;
  2621. }
  2622. return $uploaded_files;
  2623. }
  2624. /**
  2625. * Add help to the Jetpack page
  2626. *
  2627. * @since Jetpack (1.2.3)
  2628. * @return false if not the Jetpack page
  2629. */
  2630. function admin_help() {
  2631. $current_screen = get_current_screen();
  2632. // Overview
  2633. $current_screen->add_help_tab(
  2634. array(
  2635. 'id' => 'home',
  2636. 'title' => __( 'Home', 'jetpack' ),
  2637. 'content' =>
  2638. '<p><strong>' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</strong></p>' .
  2639. '<p>' . __( 'Jetpack supercharges your self-hosted WordPress site with the awesome cloud power of WordPress.com.', 'jetpack' ) . '</p>' .
  2640. '<p>' . __( 'On this page, you are able to view the modules available within Jetpack, learn more about them, and activate or deactivate them as needed.', 'jetpack' ) . '</p>',
  2641. )
  2642. );
  2643. // Screen Content
  2644. if ( current_user_can( 'manage_options' ) ) {
  2645. $current_screen->add_help_tab(
  2646. array(
  2647. 'id' => 'settings',
  2648. 'title' => __( 'Settings', 'jetpack' ),
  2649. 'content' =>
  2650. '<p><strong>' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</strong></p>' .
  2651. '<p>' . __( 'You can activate or deactivate individual Jetpack modules to suit your needs.', 'jetpack' ) . '</p>' .
  2652. '<ol>' .
  2653. '<li>' . __( 'Each module has an Activate or Deactivate link so you can toggle one individually.', 'jetpack' ) . '</li>' .
  2654. '<li>' . __( 'Using the checkboxes next to each module, you can select multiple modules to toggle via the Bulk Actions menu at the top of the list.', 'jetpack' ) . '</li>' .
  2655. '</ol>' .
  2656. '<p>' . __( 'Using the tools on the right, you can search for specific modules, filter by module categories or which are active, or change the sorting order.', 'jetpack' ) . '</p>'
  2657. )
  2658. );
  2659. }
  2660. // Help Sidebar
  2661. $current_screen->set_help_sidebar(
  2662. '<p><strong>' . __( 'For more information:', 'jetpack' ) . '</strong></p>' .
  2663. '<p><a href="https://jetpack.com/faq/" target="_blank">' . __( 'Jetpack FAQ', 'jetpack' ) . '</a></p>' .
  2664. '<p><a href="https://jetpack.com/support/" target="_blank">' . __( 'Jetpack Support', 'jetpack' ) . '</a></p>' .
  2665. '<p><a href="' . Jetpack::admin_url( array( 'page' => 'jetpack-debugger' ) ) .'">' . __( 'Jetpack Debugging Center', 'jetpack' ) . '</a></p>'
  2666. );
  2667. }
  2668. function admin_menu_css() {
  2669. wp_enqueue_style( 'jetpack-icons' );
  2670. }
  2671. function admin_menu_order() {
  2672. return true;
  2673. }
  2674. function jetpack_menu_order( $menu_order ) {
  2675. $jp_menu_order = array();
  2676. foreach ( $menu_order as $index => $item ) {
  2677. if ( $item != 'jetpack' ) {
  2678. $jp_menu_order[] = $item;
  2679. }
  2680. if ( $index == 0 ) {
  2681. $jp_menu_order[] = 'jetpack';
  2682. }
  2683. }
  2684. return $jp_menu_order;
  2685. }
  2686. function admin_head() {
  2687. if ( isset( $_GET['configure'] ) && Jetpack::is_module( $_GET['configure'] ) && current_user_can( 'manage_options' ) )
  2688. /** This action is documented in class.jetpack-admin-page.php */
  2689. do_action( 'jetpack_module_configuration_head_' . $_GET['configure'] );
  2690. }
  2691. function admin_banner_styles() {
  2692. $min = ( defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ) ? '' : '.min';
  2693. wp_enqueue_style( 'jetpack', plugins_url( "css/jetpack-banners{$min}.css", JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION . '-20121016' );
  2694. wp_style_add_data( 'jetpack', 'rtl', 'replace' );
  2695. wp_style_add_data( 'jetpack', 'suffix', $min );
  2696. }
  2697. function plugin_action_links( $actions ) {
  2698. $jetpack_home = array( 'jetpack-home' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack' ), __( 'Jetpack', 'jetpack' ) ) );
  2699. if( current_user_can( 'jetpack_manage_modules' ) && ( Jetpack::is_active() || Jetpack::is_development_mode() ) ) {
  2700. return array_merge(
  2701. $jetpack_home,
  2702. array( 'settings' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack_modules' ), __( 'Settings', 'jetpack' ) ) ),
  2703. array( 'support' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack-debugger '), __( 'Support', 'jetpack' ) ) ),
  2704. $actions
  2705. );
  2706. }
  2707. return array_merge( $jetpack_home, $actions );
  2708. }
  2709. function admin_connect_notice() {
  2710. // Don't show the connect notice anywhere but the plugins.php after activating
  2711. $current = get_current_screen();
  2712. if ( 'plugins' !== $current->parent_base )
  2713. return;
  2714. if ( ! current_user_can( 'jetpack_connect' ) )
  2715. return;
  2716. $dismiss_and_deactivate_url = wp_nonce_url( Jetpack::admin_url( '?page=jetpack&jetpack-notice=dismiss' ), 'jetpack-deactivate' );
  2717. ?>
  2718. <div id="message" class="updated jp-banner">
  2719. <a href="<?php echo esc_url( $dismiss_and_deactivate_url ); ?>" class="notice-dismiss" title="<?php esc_attr_e( 'Dismiss this notice', 'jetpack' ); ?>"></a>
  2720. <?php if ( in_array( Jetpack_Options::get_option( 'activated' ) , array( 1, 2, 3 ) ) ) : ?>
  2721. <div class="jp-banner__description-container">
  2722. <h2 class="jp-banner__header"><?php _e( 'Your Jetpack is almost ready!', 'jetpack' ); ?></h2>
  2723. <p class="jp-banner__description"><?php _e( 'Please connect to or create a WordPress.com account to enable Jetpack, including powerful security, traffic, and customization services.', 'jetpack' ); ?></p>
  2724. <p class="jp-banner__button-container">
  2725. <a href="<?php echo $this->build_connect_url( false, false, 'banner' ) ?>" class="button button-primary" id="wpcom-connect"><?php _e( 'Connect to WordPress.com', 'jetpack' ); ?></a>
  2726. <a href="<?php echo Jetpack::admin_url( 'admin.php?page=jetpack' ) ?>" class="button" title="<?php esc_attr_e( 'Learn about the benefits you receive when you connect Jetpack to WordPress.com', 'jetpack' ); ?>"><?php _e( 'Learn more', 'jetpack' ); ?></a>
  2727. </p>
  2728. </div>
  2729. <?php else : ?>
  2730. <div class="jp-banner__content">
  2731. <h2><?php _e( 'Jetpack is installed!', 'jetpack' ) ?></h2>
  2732. <p><?php _e( 'It\'s ready to bring awesome, WordPress.com cloud-powered features to your site.', 'jetpack' ) ?></p>
  2733. </div>
  2734. <div class="jp-banner__action-container">
  2735. <a href="<?php echo Jetpack::admin_url() ?>" class="jp-banner__button" id="wpcom-connect"><?php _e( 'Learn More', 'jetpack' ); ?></a>
  2736. </div>
  2737. <?php endif; ?>
  2738. </div>
  2739. <?php
  2740. }
  2741. /**
  2742. * This is the first banner
  2743. * It should be visible only to user that can update the option
  2744. * Are not connected
  2745. *
  2746. * @return null
  2747. */
  2748. function admin_jetpack_manage_notice() {
  2749. $screen = get_current_screen();
  2750. // Don't show the connect notice on the jetpack settings page.
  2751. if ( ! in_array( $screen->base, array( 'dashboard' ) ) || $screen->is_network || $screen->action )
  2752. return;
  2753. // Only show it if don't have the managment option set.
  2754. // And not dismissed it already.
  2755. if ( ! $this->can_display_jetpack_manage_notice() || Jetpack_Options::get_option( 'dismissed_manage_banner' ) ) {
  2756. return;
  2757. }
  2758. $opt_out_url = $this->opt_out_jetpack_manage_url();
  2759. $opt_in_url = $this->opt_in_jetpack_manage_url();
  2760. /**
  2761. * I think it would be great to have different wordsing depending on where you are
  2762. * for example if we show the notice on dashboard and a different one if we show it on Plugins screen
  2763. * etc..
  2764. */
  2765. ?>
  2766. <div id="message" class="updated jp-banner">
  2767. <a href="<?php echo esc_url( $opt_out_url ); ?>" class="notice-dismiss" title="<?php esc_attr_e( 'Dismiss this notice', 'jetpack' ); ?>"></a>
  2768. <div class="jp-banner__description-container">
  2769. <h2 class="jp-banner__header"><?php esc_html_e( 'Jetpack Centralized Site Management', 'jetpack' ); ?></h2>
  2770. <p class="jp-banner__description"><?php printf( __( 'Manage multiple Jetpack enabled sites from one single dashboard at wordpress.com. Allows all existing, connected Administrators to modify your site.', 'jetpack' ), 'https://jetpack.com/support/site-management' ); ?></p>
  2771. <p class="jp-banner__button-container">
  2772. <a href="<?php echo esc_url( $opt_in_url ); ?>" class="button button-primary" id="wpcom-connect"><?php _e( 'Activate Jetpack Manage', 'jetpack' ); ?></a>
  2773. <a href="https://jetpack.com/support/site-management" class="button" target="_blank" title="<?php esc_attr_e( 'Learn more about Jetpack Manage on Jetpack.com', 'jetpack' ); ?>"><?php _e( 'Learn more', 'jetpack' ); ?></a>
  2774. </p>
  2775. </div>
  2776. </div>
  2777. <?php
  2778. }
  2779. /**
  2780. * Returns the url that the user clicks to remove the notice for the big banner
  2781. * @return (string)
  2782. */
  2783. function opt_out_jetpack_manage_url() {
  2784. $referer = '&_wp_http_referer=' . add_query_arg( '_wp_http_referer', null );
  2785. return wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=jetpack-manage-opt-out' . $referer ), 'jetpack_manage_banner_opt_out' );
  2786. }
  2787. /**
  2788. * Returns the url that the user clicks to opt in to Jetpack Manage
  2789. * @return (string)
  2790. */
  2791. function opt_in_jetpack_manage_url() {
  2792. return wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=jetpack-manage-opt-in' ), 'jetpack_manage_banner_opt_in' );
  2793. }
  2794. function opt_in_jetpack_manage_notice() {
  2795. ?>
  2796. <div class="wrap">
  2797. <div id="message" class="jetpack-message is-opt-in">
  2798. <?php echo sprintf( __( '<p><a href="%1$s" title="Opt in to WordPress.com Site Management" >Activate Site Management</a> to manage multiple sites from our centralized dashboard at wordpress.com/sites. <a href="%2$s" target="_blank">Learn more</a>.</p><a href="%1$s" class="jp-button">Activate Now</a>', 'jetpack' ), $this->opt_in_jetpack_manage_url(), 'https://jetpack.com/support/site-management' ); ?>
  2799. </div>
  2800. </div>
  2801. <?php
  2802. }
  2803. /**
  2804. * Determines whether to show the notice of not true = display notice
  2805. * @return (bool)
  2806. */
  2807. function can_display_jetpack_manage_notice() {
  2808. // never display the notice to users that can't do anything about it anyways
  2809. if( ! current_user_can( 'jetpack_manage_modules' ) )
  2810. return false;
  2811. // don't display if we are in development more
  2812. if( Jetpack::is_development_mode() ) {
  2813. return false;
  2814. }
  2815. // don't display if the site is private
  2816. if( ! Jetpack_Options::get_option( 'public' ) )
  2817. return false;
  2818. /**
  2819. * Should the Jetpack Remote Site Management notice be displayed.
  2820. *
  2821. * @since 3.3.0
  2822. *
  2823. * @param bool ! self::is_module_active( 'manage' ) Is the Manage module inactive.
  2824. */
  2825. return apply_filters( 'can_display_jetpack_manage_notice', ! self::is_module_active( 'manage' ) );
  2826. }
  2827. function network_connect_notice() {
  2828. ?>
  2829. <div id="message" class="updated jetpack-message">
  2830. <div class="squeezer">
  2831. <h2><?php _e( '<strong>Jetpack is activated!</strong> Each site on your network must be connected individually by an admin on that site.', 'jetpack' ) ?></h2>
  2832. </div>
  2833. </div>
  2834. <?php
  2835. }
  2836. /*
  2837. * Registration flow:
  2838. * 1 - ::admin_page_load() action=register
  2839. * 2 - ::try_registration()
  2840. * 3 - ::register()
  2841. * - Creates jetpack_register option containing two secrets and a timestamp
  2842. * - Calls https://jetpack.wordpress.com/jetpack.register/1/ with
  2843. * siteurl, home, gmt_offset, timezone_string, site_name, secret_1, secret_2, site_lang, timeout, stats_id
  2844. * - That request to jetpack.wordpress.com does not immediately respond. It first makes a request BACK to this site's
  2845. * xmlrpc.php?for=jetpack: RPC method: jetpack.verifyRegistration, Parameters: secret_1
  2846. * - The XML-RPC request verifies secret_1, deletes both secrets and responds with: secret_2
  2847. * - https://jetpack.wordpress.com/jetpack.register/1/ verifies that XML-RPC response (secret_2) then finally responds itself with
  2848. * jetpack_id, jetpack_secret, jetpack_public
  2849. * - ::register() then stores jetpack_options: id => jetpack_id, blog_token => jetpack_secret
  2850. * 4 - redirect to https://wordpress.com/start/jetpack-connect
  2851. * 5 - user logs in with WP.com account
  2852. * 6 - remote request to this site's xmlrpc.php with action remoteAuthorize, Jetpack_XMLRPC_Server->remote_authorize
  2853. * - Jetpack_Client_Server::authorize()
  2854. * - Jetpack_Client_Server::get_token()
  2855. * - GET https://jetpack.wordpress.com/jetpack.token/1/ with
  2856. * client_id, client_secret, grant_type, code, redirect_uri:action=authorize, state, scope, user_email, user_login
  2857. * - which responds with access_token, token_type, scope
  2858. * - Jetpack_Client_Server::authorize() stores jetpack_options: user_token => access_token.$user_id
  2859. * - Jetpack::activate_default_modules()
  2860. * - Deactivates deprecated plugins
  2861. * - Activates all default modules
  2862. * - Responds with either error, or 'connected' for new connection, or 'linked' for additional linked users
  2863. * 7 - For a new connection, user selects a Jetpack plan on wordpress.com
  2864. * 8 - User is redirected back to wp-admin/index.php?page=jetpack with state:message=authorized
  2865. * Done!
  2866. */
  2867. /**
  2868. * Handles the page load events for the Jetpack admin page
  2869. */
  2870. function admin_page_load() {
  2871. $error = false;
  2872. // Make sure we have the right body class to hook stylings for subpages off of.
  2873. add_filter( 'admin_body_class', array( __CLASS__, 'add_jetpack_pagestyles' ) );
  2874. if ( ! empty( $_GET['jetpack_restate'] ) ) {
  2875. // Should only be used in intermediate redirects to preserve state across redirects
  2876. Jetpack::restate();
  2877. }
  2878. if ( isset( $_GET['connect_url_redirect'] ) ) {
  2879. // User clicked in the iframe to link their accounts
  2880. if ( ! Jetpack::is_user_connected() ) {
  2881. $connect_url = $this->build_connect_url( true, false, 'iframe' );
  2882. if ( isset( $_GET['notes_iframe'] ) )
  2883. $connect_url .= '&notes_iframe';
  2884. wp_redirect( $connect_url );
  2885. exit;
  2886. } else {
  2887. if ( ! isset( $_GET['calypso_env'] ) ) {
  2888. Jetpack::state( 'message', 'already_authorized' );
  2889. wp_safe_redirect( Jetpack::admin_url() );
  2890. } else {
  2891. $connect_url = $this->build_connect_url( true, false, 'iframe' );
  2892. $connect_url .= '&already_authorized=true';
  2893. wp_redirect( $connect_url );
  2894. }
  2895. }
  2896. }
  2897. if ( isset( $_GET['action'] ) ) {
  2898. switch ( $_GET['action'] ) {
  2899. case 'authorize':
  2900. if ( Jetpack::is_active() && Jetpack::is_user_connected() ) {
  2901. Jetpack::state( 'message', 'already_authorized' );
  2902. wp_safe_redirect( Jetpack::admin_url() );
  2903. exit;
  2904. }
  2905. Jetpack::log( 'authorize' );
  2906. $client_server = new Jetpack_Client_Server;
  2907. $client_server->client_authorize();
  2908. exit;
  2909. case 'register' :
  2910. if ( ! current_user_can( 'jetpack_connect' ) ) {
  2911. $error = 'cheatin';
  2912. break;
  2913. }
  2914. check_admin_referer( 'jetpack-register' );
  2915. Jetpack::log( 'register' );
  2916. Jetpack::maybe_set_version_option();
  2917. $registered = Jetpack::try_registration();
  2918. if ( is_wp_error( $registered ) ) {
  2919. $error = $registered->get_error_code();
  2920. Jetpack::state( 'error', $error );
  2921. Jetpack::state( 'error', $registered->get_error_message() );
  2922. break;
  2923. }
  2924. $from = isset( $_GET['from'] ) ? $_GET['from'] : false;
  2925. wp_redirect( $this->build_connect_url( true, false, $from ) );
  2926. exit;
  2927. case 'activate' :
  2928. if ( ! current_user_can( 'jetpack_activate_modules' ) ) {
  2929. $error = 'cheatin';
  2930. break;
  2931. }
  2932. $module = stripslashes( $_GET['module'] );
  2933. check_admin_referer( "jetpack_activate-$module" );
  2934. Jetpack::log( 'activate', $module );
  2935. Jetpack::activate_module( $module );
  2936. // The following two lines will rarely happen, as Jetpack::activate_module normally exits at the end.
  2937. wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
  2938. exit;
  2939. case 'activate_default_modules' :
  2940. check_admin_referer( 'activate_default_modules' );
  2941. Jetpack::log( 'activate_default_modules' );
  2942. Jetpack::restate();
  2943. $min_version = isset( $_GET['min_version'] ) ? $_GET['min_version'] : false;
  2944. $max_version = isset( $_GET['max_version'] ) ? $_GET['max_version'] : false;
  2945. $other_modules = isset( $_GET['other_modules'] ) && is_array( $_GET['other_modules'] ) ? $_GET['other_modules'] : array();
  2946. Jetpack::activate_default_modules( $min_version, $max_version, $other_modules );
  2947. wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
  2948. exit;
  2949. case 'disconnect' :
  2950. if ( ! current_user_can( 'jetpack_disconnect' ) ) {
  2951. $error = 'cheatin';
  2952. break;
  2953. }
  2954. check_admin_referer( 'jetpack-disconnect' );
  2955. Jetpack::log( 'disconnect' );
  2956. Jetpack::disconnect();
  2957. wp_safe_redirect( Jetpack::admin_url( 'disconnected=true' ) );
  2958. exit;
  2959. case 'reconnect' :
  2960. if ( ! current_user_can( 'jetpack_reconnect' ) ) {
  2961. $error = 'cheatin';
  2962. break;
  2963. }
  2964. check_admin_referer( 'jetpack-reconnect' );
  2965. Jetpack::log( 'reconnect' );
  2966. $this->disconnect();
  2967. wp_redirect( $this->build_connect_url( true, false, 'reconnect' ) );
  2968. exit;
  2969. case 'deactivate' :
  2970. if ( ! current_user_can( 'jetpack_deactivate_modules' ) ) {
  2971. $error = 'cheatin';
  2972. break;
  2973. }
  2974. $modules = stripslashes( $_GET['module'] );
  2975. check_admin_referer( "jetpack_deactivate-$modules" );
  2976. foreach ( explode( ',', $modules ) as $module ) {
  2977. Jetpack::log( 'deactivate', $module );
  2978. Jetpack::deactivate_module( $module );
  2979. Jetpack::state( 'message', 'module_deactivated' );
  2980. }
  2981. Jetpack::state( 'module', $modules );
  2982. wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
  2983. exit;
  2984. case 'unlink' :
  2985. $redirect = isset( $_GET['redirect'] ) ? $_GET['redirect'] : '';
  2986. check_admin_referer( 'jetpack-unlink' );
  2987. Jetpack::log( 'unlink' );
  2988. $this->unlink_user();
  2989. Jetpack::state( 'message', 'unlinked' );
  2990. if ( 'sub-unlink' == $redirect ) {
  2991. wp_safe_redirect( admin_url() );
  2992. } else {
  2993. wp_safe_redirect( Jetpack::admin_url( array( 'page' => $redirect ) ) );
  2994. }
  2995. exit;
  2996. default:
  2997. /**
  2998. * Fires when a Jetpack admin page is loaded with an unrecognized parameter.
  2999. *
  3000. * @since 2.6.0
  3001. *
  3002. * @param string sanitize_key( $_GET['action'] ) Unrecognized URL parameter.
  3003. */
  3004. do_action( 'jetpack_unrecognized_action', sanitize_key( $_GET['action'] ) );
  3005. }
  3006. }
  3007. if ( ! $error = $error ? $error : Jetpack::state( 'error' ) ) {
  3008. self::activate_new_modules( true );
  3009. }
  3010. $message_code = Jetpack::state( 'message' );
  3011. if ( Jetpack::state( 'optin-manage' ) ) {
  3012. $activated_manage = $message_code;
  3013. $message_code = 'jetpack-manage';
  3014. }
  3015. switch ( $message_code ) {
  3016. case 'jetpack-manage':
  3017. $this->message = '<strong>' . sprintf( __( 'You are all set! Your site can now be managed from <a href="%s" target="_blank">wordpress.com/sites</a>.', 'jetpack' ), 'https://wordpress.com/sites' ) . '</strong>';
  3018. if ( $activated_manage ) {
  3019. $this->message .= '<br /><strong>' . __( 'Manage has been activated for you!', 'jetpack' ) . '</strong>';
  3020. }
  3021. break;
  3022. }
  3023. $deactivated_plugins = Jetpack::state( 'deactivated_plugins' );
  3024. if ( ! empty( $deactivated_plugins ) ) {
  3025. $deactivated_plugins = explode( ',', $deactivated_plugins );
  3026. $deactivated_titles = array();
  3027. foreach ( $deactivated_plugins as $deactivated_plugin ) {
  3028. if ( ! isset( $this->plugins_to_deactivate[$deactivated_plugin] ) ) {
  3029. continue;
  3030. }
  3031. $deactivated_titles[] = '<strong>' . str_replace( ' ', '&nbsp;', $this->plugins_to_deactivate[$deactivated_plugin][1] ) . '</strong>';
  3032. }
  3033. if ( $deactivated_titles ) {
  3034. if ( $this->message ) {
  3035. $this->message .= "<br /><br />\n";
  3036. }
  3037. $this->message .= wp_sprintf(
  3038. _n(
  3039. 'Jetpack contains the most recent version of the old %l plugin.',
  3040. 'Jetpack contains the most recent versions of the old %l plugins.',
  3041. count( $deactivated_titles ),
  3042. 'jetpack'
  3043. ),
  3044. $deactivated_titles
  3045. );
  3046. $this->message .= "<br />\n";
  3047. $this->message .= _n(
  3048. 'The old version has been deactivated and can be removed from your site.',
  3049. 'The old versions have been deactivated and can be removed from your site.',
  3050. count( $deactivated_titles ),
  3051. 'jetpack'
  3052. );
  3053. }
  3054. }
  3055. $this->privacy_checks = Jetpack::state( 'privacy_checks' );
  3056. if ( $this->message || $this->error || $this->privacy_checks || $this->can_display_jetpack_manage_notice() ) {
  3057. add_action( 'jetpack_notices', array( $this, 'admin_notices' ) );
  3058. }
  3059. if ( isset( $_GET['configure'] ) && Jetpack::is_module( $_GET['configure'] ) && current_user_can( 'manage_options' ) ) {
  3060. /**
  3061. * Fires when a module configuration page is loaded.
  3062. * The dynamic part of the hook is the configure parameter from the URL.
  3063. *
  3064. * @since 1.1.0
  3065. */
  3066. do_action( 'jetpack_module_configuration_load_' . $_GET['configure'] );
  3067. }
  3068. add_filter( 'jetpack_short_module_description', 'wptexturize' );
  3069. }
  3070. function admin_notices() {
  3071. if ( $this->error ) {
  3072. ?>
  3073. <div id="message" class="jetpack-message jetpack-err">
  3074. <div class="squeezer">
  3075. <h2><?php echo wp_kses( $this->error, array( 'a' => array( 'href' => array() ), 'small' => true, 'code' => true, 'strong' => true, 'br' => true, 'b' => true ) ); ?></h2>
  3076. <?php if ( $desc = Jetpack::state( 'error_description' ) ) : ?>
  3077. <p><?php echo esc_html( stripslashes( $desc ) ); ?></p>
  3078. <?php endif; ?>
  3079. </div>
  3080. </div>
  3081. <?php
  3082. }
  3083. if ( $this->message ) {
  3084. ?>
  3085. <div id="message" class="jetpack-message">
  3086. <div class="squeezer">
  3087. <h2><?php echo wp_kses( $this->message, array( 'strong' => array(), 'a' => array( 'href' => true ), 'br' => true ) ); ?></h2>
  3088. </div>
  3089. </div>
  3090. <?php
  3091. }
  3092. if ( $this->privacy_checks ) :
  3093. $module_names = $module_slugs = array();
  3094. $privacy_checks = explode( ',', $this->privacy_checks );
  3095. $privacy_checks = array_filter( $privacy_checks, array( 'Jetpack', 'is_module' ) );
  3096. foreach ( $privacy_checks as $module_slug ) {
  3097. $module = Jetpack::get_module( $module_slug );
  3098. if ( ! $module ) {
  3099. continue;
  3100. }
  3101. $module_slugs[] = $module_slug;
  3102. $module_names[] = "<strong>{$module['name']}</strong>";
  3103. }
  3104. $module_slugs = join( ',', $module_slugs );
  3105. ?>
  3106. <div id="message" class="jetpack-message jetpack-err">
  3107. <div class="squeezer">
  3108. <h2><strong><?php esc_html_e( 'Is this site private?', 'jetpack' ); ?></strong></h2><br />
  3109. <p><?php
  3110. echo wp_kses(
  3111. wptexturize(
  3112. wp_sprintf(
  3113. _nx(
  3114. "Like your site's RSS feeds, %l allows access to your posts and other content to third parties.",
  3115. "Like your site's RSS feeds, %l allow access to your posts and other content to third parties.",
  3116. count( $privacy_checks ),
  3117. '%l = list of Jetpack module/feature names',
  3118. 'jetpack'
  3119. ),
  3120. $module_names
  3121. )
  3122. ),
  3123. array( 'strong' => true )
  3124. );
  3125. echo "\n<br />\n";
  3126. echo wp_kses(
  3127. sprintf(
  3128. _nx(
  3129. 'If your site is not publicly accessible, consider <a href="%1$s" title="%2$s">deactivating this feature</a>.',
  3130. 'If your site is not publicly accessible, consider <a href="%1$s" title="%2$s">deactivating these features</a>.',
  3131. count( $privacy_checks ),
  3132. '%1$s = deactivation URL, %2$s = "Deactivate {list of Jetpack module/feature names}',
  3133. 'jetpack'
  3134. ),
  3135. wp_nonce_url(
  3136. Jetpack::admin_url(
  3137. array(
  3138. 'page' => 'jetpack',
  3139. 'action' => 'deactivate',
  3140. 'module' => urlencode( $module_slugs ),
  3141. )
  3142. ),
  3143. "jetpack_deactivate-$module_slugs"
  3144. ),
  3145. esc_attr( wp_kses( wp_sprintf( _x( 'Deactivate %l', '%l = list of Jetpack module/feature names', 'jetpack' ), $module_names ), array() ) )
  3146. ),
  3147. array( 'a' => array( 'href' => true, 'title' => true ) )
  3148. );
  3149. ?></p>
  3150. </div>
  3151. </div>
  3152. <?php endif;
  3153. // only display the notice if the other stuff is not there
  3154. if( $this->can_display_jetpack_manage_notice() && ! $this->error && ! $this->message && ! $this->privacy_checks ) {
  3155. if( isset( $_GET['page'] ) && 'jetpack' != $_GET['page'] )
  3156. $this->opt_in_jetpack_manage_notice();
  3157. }
  3158. }
  3159. /**
  3160. * Record a stat for later output. This will only currently output in the admin_footer.
  3161. */
  3162. function stat( $group, $detail ) {
  3163. if ( ! isset( $this->stats[ $group ] ) )
  3164. $this->stats[ $group ] = array();
  3165. $this->stats[ $group ][] = $detail;
  3166. }
  3167. /**
  3168. * Load stats pixels. $group is auto-prefixed with "x_jetpack-"
  3169. */
  3170. function do_stats( $method = '' ) {
  3171. if ( is_array( $this->stats ) && count( $this->stats ) ) {
  3172. foreach ( $this->stats as $group => $stats ) {
  3173. if ( is_array( $stats ) && count( $stats ) ) {
  3174. $args = array( "x_jetpack-{$group}" => implode( ',', $stats ) );
  3175. if ( 'server_side' === $method ) {
  3176. self::do_server_side_stat( $args );
  3177. } else {
  3178. echo '<img src="' . esc_url( self::build_stats_url( $args ) ) . '" width="1" height="1" style="display:none;" />';
  3179. }
  3180. }
  3181. unset( $this->stats[ $group ] );
  3182. }
  3183. }
  3184. }
  3185. /**
  3186. * Runs stats code for a one-off, server-side.
  3187. *
  3188. * @param $args array|string The arguments to append to the URL. Should include `x_jetpack-{$group}={$stats}` or whatever we want to store.
  3189. *
  3190. * @return bool If it worked.
  3191. */
  3192. static function do_server_side_stat( $args ) {
  3193. $response = wp_remote_get( esc_url_raw( self::build_stats_url( $args ) ) );
  3194. if ( is_wp_error( $response ) )
  3195. return false;
  3196. if ( 200 !== wp_remote_retrieve_response_code( $response ) )
  3197. return false;
  3198. return true;
  3199. }
  3200. /**
  3201. * Builds the stats url.
  3202. *
  3203. * @param $args array|string The arguments to append to the URL.
  3204. *
  3205. * @return string The URL to be pinged.
  3206. */
  3207. static function build_stats_url( $args ) {
  3208. $defaults = array(
  3209. 'v' => 'wpcom2',
  3210. 'rand' => md5( mt_rand( 0, 999 ) . time() ),
  3211. );
  3212. $args = wp_parse_args( $args, $defaults );
  3213. /**
  3214. * Filter the URL used as the Stats tracking pixel.
  3215. *
  3216. * @since 2.3.2
  3217. *
  3218. * @param string $url Base URL used as the Stats tracking pixel.
  3219. */
  3220. $base_url = apply_filters(
  3221. 'jetpack_stats_base_url',
  3222. 'https://pixel.wp.com/g.gif'
  3223. );
  3224. $url = add_query_arg( $args, $base_url );
  3225. return $url;
  3226. }
  3227. static function translate_current_user_to_role() {
  3228. foreach ( self::$capability_translations as $role => $cap ) {
  3229. if ( current_user_can( $role ) || current_user_can( $cap ) ) {
  3230. return $role;
  3231. }
  3232. }
  3233. return false;
  3234. }
  3235. static function translate_role_to_cap( $role ) {
  3236. if ( ! isset( self::$capability_translations[$role] ) ) {
  3237. return false;
  3238. }
  3239. return self::$capability_translations[$role];
  3240. }
  3241. static function sign_role( $role ) {
  3242. if ( ! $user_id = (int) get_current_user_id() ) {
  3243. return false;
  3244. }
  3245. $token = Jetpack_Data::get_access_token();
  3246. if ( ! $token || is_wp_error( $token ) ) {
  3247. return false;
  3248. }
  3249. return $role . ':' . hash_hmac( 'md5', "{$role}|{$user_id}", $token->secret );
  3250. }
  3251. /**
  3252. * Builds a URL to the Jetpack connection auth page
  3253. *
  3254. * @since 3.9.5
  3255. *
  3256. * @param bool $raw If true, URL will not be escaped.
  3257. * @param bool|string $redirect If true, will redirect back to Jetpack wp-admin landing page after connection.
  3258. * If string, will be a custom redirect.
  3259. * @param bool|string $from If not false, adds 'from=$from' param to the connect URL.
  3260. *
  3261. * @return string Connect URL
  3262. */
  3263. function build_connect_url( $raw = false, $redirect = false, $from = false ) {
  3264. if ( ! Jetpack_Options::get_option( 'blog_token' ) || ! Jetpack_Options::get_option( 'id' ) ) {
  3265. $url = Jetpack::nonce_url_no_esc( Jetpack::admin_url( 'action=register' ), 'jetpack-register' );
  3266. if( is_network_admin() ) {
  3267. $url = add_query_arg( 'is_multisite', network_admin_url(
  3268. 'admin.php?page=jetpack-settings' ), $url );
  3269. }
  3270. } else {
  3271. if ( defined( 'JETPACK__GLOTPRESS_LOCALES_PATH' ) && include_once JETPACK__GLOTPRESS_LOCALES_PATH ) {
  3272. $gp_locale = GP_Locales::by_field( 'wp_locale', get_locale() );
  3273. }
  3274. $role = self::translate_current_user_to_role();
  3275. $signed_role = self::sign_role( $role );
  3276. $user = wp_get_current_user();
  3277. $jetpack_admin_page = esc_url_raw( admin_url( 'admin.php?page=jetpack' ) );
  3278. $redirect = $redirect
  3279. ? wp_validate_redirect( esc_url_raw( $redirect ), $jetpack_admin_page )
  3280. : $jetpack_admin_page;
  3281. if( isset( $_REQUEST['is_multisite'] ) ) {
  3282. $redirect = Jetpack_Network::init()->get_url( 'network_admin_page' );
  3283. }
  3284. $secrets = Jetpack::init()->generate_secrets( 'authorize' );
  3285. @list( $secret ) = explode( ':', $secrets );
  3286. $site_icon = ( function_exists( 'has_site_icon') && has_site_icon() )
  3287. ? get_site_icon_url()
  3288. : false;
  3289. $args = urlencode_deep(
  3290. array(
  3291. 'response_type' => 'code',
  3292. 'client_id' => Jetpack_Options::get_option( 'id' ),
  3293. 'redirect_uri' => add_query_arg(
  3294. array(
  3295. 'action' => 'authorize',
  3296. '_wpnonce' => wp_create_nonce( "jetpack-authorize_{$role}_{$redirect}" ),
  3297. 'redirect' => urlencode( $redirect ),
  3298. ),
  3299. esc_url( admin_url( 'admin.php?page=jetpack' ) )
  3300. ),
  3301. 'state' => $user->ID,
  3302. 'scope' => $signed_role,
  3303. 'user_email' => $user->user_email,
  3304. 'user_login' => $user->user_login,
  3305. 'is_active' => Jetpack::is_active(),
  3306. 'jp_version' => JETPACK__VERSION,
  3307. 'auth_type' => 'calypso',
  3308. 'secret' => $secret,
  3309. 'locale' => isset( $gp_locale->slug ) ? $gp_locale->slug : '',
  3310. 'blogname' => get_option( 'blogname' ),
  3311. 'site_url' => site_url(),
  3312. 'home_url' => home_url(),
  3313. 'site_icon' => $site_icon,
  3314. )
  3315. );
  3316. $url = add_query_arg( $args, Jetpack::api_url( 'authorize' ) );
  3317. }
  3318. if ( $from ) {
  3319. $url = add_query_arg( 'from', $from, $url );
  3320. }
  3321. if ( isset( $_GET['calypso_env'] ) ) {
  3322. $url = add_query_arg( 'calypso_env', sanitize_key( $_GET['calypso_env'] ), $url );
  3323. }
  3324. return $raw ? $url : esc_url( $url );
  3325. }
  3326. function build_reconnect_url( $raw = false ) {
  3327. $url = wp_nonce_url( Jetpack::admin_url( 'action=reconnect' ), 'jetpack-reconnect' );
  3328. return $raw ? $url : esc_url( $url );
  3329. }
  3330. public static function admin_url( $args = null ) {
  3331. $args = wp_parse_args( $args, array( 'page' => 'jetpack' ) );
  3332. $url = add_query_arg( $args, admin_url( 'admin.php' ) );
  3333. return $url;
  3334. }
  3335. public static function nonce_url_no_esc( $actionurl, $action = -1, $name = '_wpnonce' ) {
  3336. $actionurl = str_replace( '&amp;', '&', $actionurl );
  3337. return add_query_arg( $name, wp_create_nonce( $action ), $actionurl );
  3338. }
  3339. function dismiss_jetpack_notice() {
  3340. if ( ! isset( $_GET['jetpack-notice'] ) ) {
  3341. return;
  3342. }
  3343. switch( $_GET['jetpack-notice'] ) {
  3344. case 'dismiss':
  3345. if ( check_admin_referer( 'jetpack-deactivate' ) && ! is_plugin_active_for_network( plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' ) ) ) {
  3346. require_once ABSPATH . 'wp-admin/includes/plugin.php';
  3347. deactivate_plugins( JETPACK__PLUGIN_DIR . 'jetpack.php', false, false );
  3348. wp_safe_redirect( admin_url() . 'plugins.php?deactivate=true&plugin_status=all&paged=1&s=' );
  3349. }
  3350. break;
  3351. case 'jetpack-manage-opt-out':
  3352. if ( check_admin_referer( 'jetpack_manage_banner_opt_out' ) ) {
  3353. // Don't show the banner again
  3354. Jetpack_Options::update_option( 'dismissed_manage_banner', true );
  3355. // redirect back to the page that had the notice
  3356. if ( wp_get_referer() ) {
  3357. wp_safe_redirect( wp_get_referer() );
  3358. } else {
  3359. // Take me to Jetpack
  3360. wp_safe_redirect( admin_url( 'admin.php?page=jetpack' ) );
  3361. }
  3362. }
  3363. break;
  3364. case 'jetpack-protect-multisite-opt-out':
  3365. if ( check_admin_referer( 'jetpack_protect_multisite_banner_opt_out' ) ) {
  3366. // Don't show the banner again
  3367. update_site_option( 'jetpack_dismissed_protect_multisite_banner', true );
  3368. // redirect back to the page that had the notice
  3369. if ( wp_get_referer() ) {
  3370. wp_safe_redirect( wp_get_referer() );
  3371. } else {
  3372. // Take me to Jetpack
  3373. wp_safe_redirect( admin_url( 'admin.php?page=jetpack' ) );
  3374. }
  3375. }
  3376. break;
  3377. case 'jetpack-manage-opt-in':
  3378. if ( check_admin_referer( 'jetpack_manage_banner_opt_in' ) ) {
  3379. // This makes sure that we are redirect to jetpack home so that we can see the Success Message.
  3380. $redirection_url = Jetpack::admin_url();
  3381. remove_action( 'jetpack_pre_activate_module', array( Jetpack_Admin::init(), 'fix_redirect' ) );
  3382. // Don't redirect form the Jetpack Setting Page
  3383. $referer_parsed = parse_url ( wp_get_referer() );
  3384. // check that we do have a wp_get_referer and the query paramater is set orderwise go to the Jetpack Home
  3385. if ( isset( $referer_parsed['query'] ) && false !== strpos( $referer_parsed['query'], 'page=jetpack_modules' ) ) {
  3386. // Take the user to Jetpack home except when on the setting page
  3387. $redirection_url = wp_get_referer();
  3388. add_action( 'jetpack_pre_activate_module', array( Jetpack_Admin::init(), 'fix_redirect' ) );
  3389. }
  3390. // Also update the JSON API FULL MANAGEMENT Option
  3391. Jetpack::activate_module( 'manage', false, false );
  3392. // Special Message when option in.
  3393. Jetpack::state( 'optin-manage', 'true' );
  3394. // Activate the Module if not activated already
  3395. // Redirect properly
  3396. wp_safe_redirect( $redirection_url );
  3397. }
  3398. break;
  3399. }
  3400. }
  3401. function debugger_page() {
  3402. nocache_headers();
  3403. if ( ! current_user_can( 'manage_options' ) ) {
  3404. die( '-1' );
  3405. }
  3406. Jetpack_Debugger::jetpack_debug_display_handler();
  3407. exit;
  3408. }
  3409. public static function admin_screen_configure_module( $module_id ) {
  3410. // User that doesn't have 'jetpack_configure_modules' will never end up here since Jetpack Landing Page woun't let them.
  3411. if ( ! in_array( $module_id, Jetpack::get_active_modules() ) && current_user_can( 'manage_options' ) ) {
  3412. if ( has_action( 'display_activate_module_setting_' . $module_id ) ) {
  3413. /**
  3414. * Fires to diplay a custom module activation screen.
  3415. *
  3416. * To add a module actionation screen use Jetpack::module_configuration_activation_screen method.
  3417. * Example: Jetpack::module_configuration_activation_screen( 'manage', array( $this, 'manage_activate_screen' ) );
  3418. *
  3419. * @module manage
  3420. *
  3421. * @since 3.8.0
  3422. *
  3423. * @param int $module_id Module ID.
  3424. */
  3425. do_action( 'display_activate_module_setting_' . $module_id );
  3426. } else {
  3427. self::display_activate_module_link( $module_id );
  3428. }
  3429. return false;
  3430. } ?>
  3431. <div id="jp-settings-screen" style="position: relative">
  3432. <h3>
  3433. <?php
  3434. $module = Jetpack::get_module( $module_id );
  3435. echo '<a href="' . Jetpack::admin_url( 'page=jetpack_modules' ) . '">' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</a> &rarr; ';
  3436. printf( __( 'Configure %s', 'jetpack' ), $module['name'] );
  3437. ?>
  3438. </h3>
  3439. <?php
  3440. /**
  3441. * Fires within the displayed message when a feature configuation is updated.
  3442. *
  3443. * @since 3.4.0
  3444. *
  3445. * @param int $module_id Module ID.
  3446. */
  3447. do_action( 'jetpack_notices_update_settings', $module_id );
  3448. /**
  3449. * Fires when a feature configuation screen is loaded.
  3450. * The dynamic part of the hook, $module_id, is the module ID.
  3451. *
  3452. * @since 1.1.0
  3453. */
  3454. do_action( 'jetpack_module_configuration_screen_' . $module_id );
  3455. ?>
  3456. </div><?php
  3457. }
  3458. /**
  3459. * Display link to activate the module to see the settings screen.
  3460. * @param string $module_id
  3461. * @return null
  3462. */
  3463. public static function display_activate_module_link( $module_id ) {
  3464. $info = Jetpack::get_module( $module_id );
  3465. $extra = '';
  3466. $activate_url = wp_nonce_url(
  3467. Jetpack::admin_url(
  3468. array(
  3469. 'page' => 'jetpack',
  3470. 'action' => 'activate',
  3471. 'module' => $module_id,
  3472. )
  3473. ),
  3474. "jetpack_activate-$module_id"
  3475. );
  3476. ?>
  3477. <div class="wrap configure-module">
  3478. <div id="jp-settings-screen">
  3479. <?php
  3480. if ( $module_id == 'json-api' ) {
  3481. $info['name'] = esc_html__( 'Activate Site Management and JSON API', 'jetpack' );
  3482. $activate_url = Jetpack::init()->opt_in_jetpack_manage_url();
  3483. $info['description'] = sprintf( __( 'Manage your multiple Jetpack sites from our centralized dashboard at wordpress.com/sites. <a href="%s" target="_blank">Learn more</a>.', 'jetpack' ), 'https://jetpack.com/support/site-management' );
  3484. // $extra = __( 'To use Site Management, you need to first activate JSON API to allow remote management of your site. ', 'jetpack' );
  3485. } ?>
  3486. <h3><?php echo esc_html( $info['name'] ); ?></h3>
  3487. <div class="narrow">
  3488. <p><?php echo $info['description']; ?></p>
  3489. <?php if( $extra ) { ?>
  3490. <p><?php echo esc_html( $extra ); ?></p>
  3491. <?php } ?>
  3492. <p>
  3493. <?php
  3494. if( wp_get_referer() ) {
  3495. printf( __( '<a class="button-primary" href="%s">Activate Now</a> or <a href="%s" >return to previous page</a>.', 'jetpack' ) , $activate_url, wp_get_referer() );
  3496. } else {
  3497. printf( __( '<a class="button-primary" href="%s">Activate Now</a>', 'jetpack' ) , $activate_url );
  3498. } ?>
  3499. </p>
  3500. </div>
  3501. </div>
  3502. </div>
  3503. <?php
  3504. }
  3505. public static function sort_modules( $a, $b ) {
  3506. if ( $a['sort'] == $b['sort'] )
  3507. return 0;
  3508. return ( $a['sort'] < $b['sort'] ) ? -1 : 1;
  3509. }
  3510. function ajax_recheck_ssl() {
  3511. check_ajax_referer( 'recheck-ssl', 'ajax-nonce' );
  3512. $result = Jetpack::permit_ssl( true );
  3513. wp_send_json( array(
  3514. 'enabled' => $result,
  3515. 'message' => get_transient( 'jetpack_https_test_message' )
  3516. ) );
  3517. }
  3518. /* Client API */
  3519. /**
  3520. * Returns the requested Jetpack API URL
  3521. *
  3522. * @return string
  3523. */
  3524. public static function api_url( $relative_url ) {
  3525. return trailingslashit( JETPACK__API_BASE . $relative_url ) . JETPACK__API_VERSION . '/';
  3526. }
  3527. /**
  3528. * Some hosts disable the OpenSSL extension and so cannot make outgoing HTTPS requsets
  3529. */
  3530. public static function fix_url_for_bad_hosts( $url ) {
  3531. if ( 0 !== strpos( $url, 'https://' ) ) {
  3532. return $url;
  3533. }
  3534. switch ( JETPACK_CLIENT__HTTPS ) {
  3535. case 'ALWAYS' :
  3536. return $url;
  3537. case 'NEVER' :
  3538. return set_url_scheme( $url, 'http' );
  3539. // default : case 'AUTO' :
  3540. }
  3541. // we now return the unmodified SSL URL by default, as a security precaution
  3542. return $url;
  3543. }
  3544. /**
  3545. * Checks to see if the URL is using SSL to connect with Jetpack
  3546. *
  3547. * @since 2.3.3
  3548. * @return boolean
  3549. */
  3550. public static function permit_ssl( $force_recheck = false ) {
  3551. // Do some fancy tests to see if ssl is being supported
  3552. if ( $force_recheck || false === ( $ssl = get_transient( 'jetpack_https_test' ) ) ) {
  3553. $message = '';
  3554. if ( 'https' !== substr( JETPACK__API_BASE, 0, 5 ) ) {
  3555. $ssl = 0;
  3556. } else {
  3557. switch ( JETPACK_CLIENT__HTTPS ) {
  3558. case 'NEVER':
  3559. $ssl = 0;
  3560. $message = __( 'JETPACK_CLIENT__HTTPS is set to NEVER', 'jetpack' );
  3561. break;
  3562. case 'ALWAYS':
  3563. case 'AUTO':
  3564. default:
  3565. $ssl = 1;
  3566. break;
  3567. }
  3568. // If it's not 'NEVER', test to see
  3569. if ( $ssl ) {
  3570. if ( ! wp_http_supports( array( 'ssl' => true ) ) ) {
  3571. $ssl = 0;
  3572. $message = __( 'WordPress reports no SSL support', 'jetpack' );
  3573. } else {
  3574. $response = wp_remote_get( JETPACK__API_BASE . 'test/1/' );
  3575. if ( is_wp_error( $response ) ) {
  3576. $ssl = 0;
  3577. $message = __( 'WordPress reports no SSL support', 'jetpack' );
  3578. } elseif ( 'OK' !== wp_remote_retrieve_body( $response ) ) {
  3579. $ssl = 0;
  3580. $message = __( 'Response was not OK: ', 'jetpack' ) . wp_remote_retrieve_body( $response );
  3581. }
  3582. }
  3583. }
  3584. }
  3585. set_transient( 'jetpack_https_test', $ssl, DAY_IN_SECONDS );
  3586. set_transient( 'jetpack_https_test_message', $message, DAY_IN_SECONDS );
  3587. }
  3588. return (bool) $ssl;
  3589. }
  3590. /*
  3591. * Displays an admin_notice, alerting the user to their JETPACK_CLIENT__HTTPS constant being 'AUTO' but SSL isn't working.
  3592. */
  3593. public function alert_auto_ssl_fail() {
  3594. if ( ! current_user_can( 'manage_options' ) )
  3595. return;
  3596. $ajax_nonce = wp_create_nonce( 'recheck-ssl' );
  3597. ?>
  3598. <div id="jetpack-ssl-warning" class="error jp-identity-crisis">
  3599. <div class="jp-banner__content">
  3600. <h2><?php _e( 'Outbound HTTPS not working', 'jetpack' ); ?></h2>
  3601. <p><?php _e( 'Your site could not connect to WordPress.com via HTTPS. This could be due to any number of reasons, including faulty SSL certificates, misconfigured or missing SSL libraries, or network issues.', 'jetpack' ); ?></p>
  3602. <p>
  3603. <?php _e( 'Jetpack will re-test for HTTPS support once a day, but you can click here to try again immediately: ', 'jetpack' ); ?>
  3604. <a href="#" id="jetpack-recheck-ssl-button"><?php _e( 'Try again', 'jetpack' ); ?></a>
  3605. <span id="jetpack-recheck-ssl-output"><?php echo get_transient( 'jetpack_https_test_message' ); ?></span>
  3606. </p>
  3607. <p>
  3608. <?php printf( __( 'For more help, try our <a href="%1$s">connection debugger</a> or <a href="%2$s" target="_blank">troubleshooting tips</a>.', 'jetpack' ),
  3609. esc_url( Jetpack::admin_url( array( 'page' => 'jetpack-debugger' ) ) ),
  3610. esc_url( 'https://jetpack.com/support/getting-started-with-jetpack/troubleshooting-tips/' ) ); ?>
  3611. </p>
  3612. </div>
  3613. </div>
  3614. <style>
  3615. #jetpack-recheck-ssl-output { margin-left: 5px; color: red; }
  3616. </style>
  3617. <script type="text/javascript">
  3618. jQuery( document ).ready( function( $ ) {
  3619. $( '#jetpack-recheck-ssl-button' ).click( function( e ) {
  3620. var $this = $( this );
  3621. $this.html( <?php echo json_encode( __( 'Checking', 'jetpack' ) ); ?> );
  3622. $( '#jetpack-recheck-ssl-output' ).html( '' );
  3623. e.preventDefault();
  3624. var data = { action: 'jetpack-recheck-ssl', 'ajax-nonce': '<?php echo $ajax_nonce; ?>' };
  3625. $.post( ajaxurl, data )
  3626. .done( function( response ) {
  3627. if ( response.enabled ) {
  3628. $( '#jetpack-ssl-warning' ).hide();
  3629. } else {
  3630. this.html( <?php echo json_encode( __( 'Try again', 'jetpack' ) ); ?> );
  3631. $( '#jetpack-recheck-ssl-output' ).html( 'SSL Failed: ' + response.message );
  3632. }
  3633. }.bind( $this ) );
  3634. } );
  3635. } );
  3636. </script>
  3637. <?php
  3638. }
  3639. /**
  3640. * Returns the Jetpack XML-RPC API
  3641. *
  3642. * @return string
  3643. */
  3644. public static function xmlrpc_api_url() {
  3645. $base = preg_replace( '#(https?://[^?/]+)(/?.*)?$#', '\\1', JETPACK__API_BASE );
  3646. return untrailingslashit( $base ) . '/xmlrpc.php';
  3647. }
  3648. /**
  3649. * Creates two secret tokens and the end of life timestamp for them.
  3650. *
  3651. * Note these tokens are unique per call, NOT static per site for connecting.
  3652. *
  3653. * @since 2.6
  3654. * @return array
  3655. */
  3656. public function generate_secrets( $action, $exp = 600 ) {
  3657. $secret = wp_generate_password( 32, false ) // secret_1
  3658. . ':' . wp_generate_password( 32, false ) // secret_2
  3659. . ':' . ( time() + $exp ) // eol ( End of Life )
  3660. . ':' . get_current_user_id(); // ties the secrets to the current user
  3661. Jetpack_Options::update_option( $action, $secret );
  3662. return Jetpack_Options::get_option( $action );
  3663. }
  3664. /**
  3665. * Builds the timeout limit for queries talking with the wpcom servers.
  3666. *
  3667. * Based on local php max_execution_time in php.ini
  3668. *
  3669. * @since 2.6
  3670. * @return int
  3671. **/
  3672. public function get_remote_query_timeout_limit() {
  3673. $timeout = (int) ini_get( 'max_execution_time' );
  3674. if ( ! $timeout ) // Ensure exec time set in php.ini
  3675. $timeout = 30;
  3676. return intval( $timeout / 2 );
  3677. }
  3678. /**
  3679. * Takes the response from the Jetpack register new site endpoint and
  3680. * verifies it worked properly.
  3681. *
  3682. * @since 2.6
  3683. * @return true or Jetpack_Error
  3684. **/
  3685. public function validate_remote_register_response( $response ) {
  3686. if ( is_wp_error( $response ) ) {
  3687. return new Jetpack_Error( 'register_http_request_failed', $response->get_error_message() );
  3688. }
  3689. $code = wp_remote_retrieve_response_code( $response );
  3690. $entity = wp_remote_retrieve_body( $response );
  3691. if ( $entity )
  3692. $json = json_decode( $entity );
  3693. else
  3694. $json = false;
  3695. $code_type = intval( $code / 100 );
  3696. if ( 5 == $code_type ) {
  3697. return new Jetpack_Error( 'wpcom_5??', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
  3698. } elseif ( 408 == $code ) {
  3699. return new Jetpack_Error( 'wpcom_408', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
  3700. } elseif ( ! empty( $json->error ) ) {
  3701. $error_description = isset( $json->error_description ) ? sprintf( __( 'Error Details: %s', 'jetpack' ), (string) $json->error_description ) : '';
  3702. return new Jetpack_Error( (string) $json->error, $error_description, $code );
  3703. } elseif ( 200 != $code ) {
  3704. return new Jetpack_Error( 'wpcom_bad_response', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
  3705. }
  3706. // Jetpack ID error block
  3707. if ( empty( $json->jetpack_id ) ) {
  3708. return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID is empty. Do not publicly post this error message! %s', 'jetpack' ), $entity ), $entity );
  3709. } elseif ( ! is_scalar( $json->jetpack_id ) ) {
  3710. return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID is not a scalar. Do not publicly post this error message! %s', 'jetpack' ) , $entity ), $entity );
  3711. } elseif ( preg_match( '/[^0-9]/', $json->jetpack_id ) ) {
  3712. return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID begins with a numeral. Do not publicly post this error message! %s', 'jetpack' ) , $entity ), $entity );
  3713. }
  3714. return true;
  3715. }
  3716. /**
  3717. * @return bool|WP_Error
  3718. */
  3719. public static function register() {
  3720. add_action( 'pre_update_jetpack_option_register', array( 'Jetpack_Options', 'delete_option' ) );
  3721. $secrets = Jetpack::init()->generate_secrets( 'register' );
  3722. @list( $secret_1, $secret_2, $secret_eol ) = explode( ':', $secrets );
  3723. if ( empty( $secret_1 ) || empty( $secret_2 ) || empty( $secret_eol ) || $secret_eol < time() ) {
  3724. return new Jetpack_Error( 'missing_secrets' );
  3725. }
  3726. $timeout = Jetpack::init()->get_remote_query_timeout_limit();
  3727. $gmt_offset = get_option( 'gmt_offset' );
  3728. if ( ! $gmt_offset ) {
  3729. $gmt_offset = 0;
  3730. }
  3731. $stats_options = get_option( 'stats_options' );
  3732. $stats_id = isset($stats_options['blog_id']) ? $stats_options['blog_id'] : null;
  3733. $args = array(
  3734. 'method' => 'POST',
  3735. 'body' => array(
  3736. 'siteurl' => site_url(),
  3737. 'home' => home_url(),
  3738. 'gmt_offset' => $gmt_offset,
  3739. 'timezone_string' => (string) get_option( 'timezone_string' ),
  3740. 'site_name' => (string) get_option( 'blogname' ),
  3741. 'secret_1' => $secret_1,
  3742. 'secret_2' => $secret_2,
  3743. 'site_lang' => get_locale(),
  3744. 'timeout' => $timeout,
  3745. 'stats_id' => $stats_id,
  3746. 'state' => get_current_user_id(),
  3747. ),
  3748. 'headers' => array(
  3749. 'Accept' => 'application/json',
  3750. ),
  3751. 'timeout' => $timeout,
  3752. );
  3753. $response = Jetpack_Client::_wp_remote_request( Jetpack::fix_url_for_bad_hosts( Jetpack::api_url( 'register' ) ), $args, true );
  3754. // Make sure the response is valid and does not contain any Jetpack errors
  3755. $valid_response = Jetpack::init()->validate_remote_register_response( $response );
  3756. if( is_wp_error( $valid_response ) || !$valid_response ) {
  3757. return $valid_response;
  3758. }
  3759. // Grab the response values to work with
  3760. $code = wp_remote_retrieve_response_code( $response );
  3761. $entity = wp_remote_retrieve_body( $response );
  3762. if ( $entity )
  3763. $json = json_decode( $entity );
  3764. else
  3765. $json = false;
  3766. if ( empty( $json->jetpack_secret ) || ! is_string( $json->jetpack_secret ) )
  3767. return new Jetpack_Error( 'jetpack_secret', '', $code );
  3768. if ( isset( $json->jetpack_public ) ) {
  3769. $jetpack_public = (int) $json->jetpack_public;
  3770. } else {
  3771. $jetpack_public = false;
  3772. }
  3773. Jetpack_Options::update_options(
  3774. array(
  3775. 'id' => (int) $json->jetpack_id,
  3776. 'blog_token' => (string) $json->jetpack_secret,
  3777. 'public' => $jetpack_public,
  3778. )
  3779. );
  3780. /**
  3781. * Fires when a site is registered on WordPress.com.
  3782. *
  3783. * @since 3.7.0
  3784. *
  3785. * @param int $json->jetpack_id Jetpack Blog ID.
  3786. * @param string $json->jetpack_secret Jetpack Blog Token.
  3787. * @param int|bool $jetpack_public Is the site public.
  3788. */
  3789. do_action( 'jetpack_site_registered', $json->jetpack_id, $json->jetpack_secret, $jetpack_public );
  3790. // Initialize Jump Start for the first and only time.
  3791. if ( ! Jetpack_Options::get_option( 'jumpstart' ) ) {
  3792. Jetpack_Options::update_option( 'jumpstart', 'new_connection' );
  3793. $jetpack = Jetpack::init();
  3794. $jetpack->stat( 'jumpstart', 'unique-views' );
  3795. $jetpack->do_stats( 'server_side' );
  3796. };
  3797. return true;
  3798. }
  3799. /**
  3800. * If the db version is showing something other that what we've got now, bump it to current.
  3801. *
  3802. * @return bool: True if the option was incorrect and updated, false if nothing happened.
  3803. */
  3804. public static function maybe_set_version_option() {
  3805. list( $version ) = explode( ':', Jetpack_Options::get_option( 'version' ) );
  3806. if ( JETPACK__VERSION != $version ) {
  3807. Jetpack_Options::update_option( 'version', JETPACK__VERSION . ':' . time() );
  3808. if ( version_compare( JETPACK__VERSION, $version, '>' ) ) {
  3809. /** This action is documented in class.jetpack.php */
  3810. do_action( 'updating_jetpack_version', JETPACK__VERSION, $version );
  3811. }
  3812. return true;
  3813. }
  3814. return false;
  3815. }
  3816. /* Client Server API */
  3817. /**
  3818. * Loads the Jetpack XML-RPC client
  3819. */
  3820. public static function load_xml_rpc_client() {
  3821. require_once ABSPATH . WPINC . '/class-IXR.php';
  3822. require_once JETPACK__PLUGIN_DIR . 'class.jetpack-ixr-client.php';
  3823. }
  3824. function verify_xml_rpc_signature() {
  3825. if ( $this->xmlrpc_verification ) {
  3826. return $this->xmlrpc_verification;
  3827. }
  3828. // It's not for us
  3829. if ( ! isset( $_GET['token'] ) || empty( $_GET['signature'] ) ) {
  3830. return false;
  3831. }
  3832. @list( $token_key, $version, $user_id ) = explode( ':', $_GET['token'] );
  3833. if (
  3834. empty( $token_key )
  3835. ||
  3836. empty( $version ) || strval( JETPACK__API_VERSION ) !== $version
  3837. ) {
  3838. return false;
  3839. }
  3840. if ( '0' === $user_id ) {
  3841. $token_type = 'blog';
  3842. $user_id = 0;
  3843. } else {
  3844. $token_type = 'user';
  3845. if ( empty( $user_id ) || ! ctype_digit( $user_id ) ) {
  3846. return false;
  3847. }
  3848. $user_id = (int) $user_id;
  3849. $user = new WP_User( $user_id );
  3850. if ( ! $user || ! $user->exists() ) {
  3851. return false;
  3852. }
  3853. }
  3854. $token = Jetpack_Data::get_access_token( $user_id );
  3855. if ( ! $token ) {
  3856. return false;
  3857. }
  3858. $token_check = "$token_key.";
  3859. if ( ! hash_equals( substr( $token->secret, 0, strlen( $token_check ) ), $token_check ) ) {
  3860. return false;
  3861. }
  3862. require_once JETPACK__PLUGIN_DIR . 'class.jetpack-signature.php';
  3863. $jetpack_signature = new Jetpack_Signature( $token->secret, (int) Jetpack_Options::get_option( 'time_diff' ) );
  3864. if ( isset( $_POST['_jetpack_is_multipart'] ) ) {
  3865. $post_data = $_POST;
  3866. $file_hashes = array();
  3867. foreach ( $post_data as $post_data_key => $post_data_value ) {
  3868. if ( 0 !== strpos( $post_data_key, '_jetpack_file_hmac_' ) ) {
  3869. continue;
  3870. }
  3871. $post_data_key = substr( $post_data_key, strlen( '_jetpack_file_hmac_' ) );
  3872. $file_hashes[$post_data_key] = $post_data_value;
  3873. }
  3874. foreach ( $file_hashes as $post_data_key => $post_data_value ) {
  3875. unset( $post_data["_jetpack_file_hmac_{$post_data_key}"] );
  3876. $post_data[$post_data_key] = $post_data_value;
  3877. }
  3878. ksort( $post_data );
  3879. $body = http_build_query( stripslashes_deep( $post_data ) );
  3880. } elseif ( is_null( $this->HTTP_RAW_POST_DATA ) ) {
  3881. $body = file_get_contents( 'php://input' );
  3882. } else {
  3883. $body = null;
  3884. }
  3885. $signature = $jetpack_signature->sign_current_request(
  3886. array( 'body' => is_null( $body ) ? $this->HTTP_RAW_POST_DATA : $body, )
  3887. );
  3888. if ( ! $signature ) {
  3889. return false;
  3890. } else if ( is_wp_error( $signature ) ) {
  3891. return $signature;
  3892. } else if ( ! hash_equals( $signature, $_GET['signature'] ) ) {
  3893. return false;
  3894. }
  3895. $timestamp = (int) $_GET['timestamp'];
  3896. $nonce = stripslashes( (string) $_GET['nonce'] );
  3897. if ( ! $this->add_nonce( $timestamp, $nonce ) ) {
  3898. return false;
  3899. }
  3900. $this->xmlrpc_verification = array(
  3901. 'type' => $token_type,
  3902. 'user_id' => $token->external_user_id,
  3903. );
  3904. return $this->xmlrpc_verification;
  3905. }
  3906. /**
  3907. * Authenticates XML-RPC and other requests from the Jetpack Server
  3908. */
  3909. function authenticate_jetpack( $user, $username, $password ) {
  3910. if ( is_a( $user, 'WP_User' ) ) {
  3911. return $user;
  3912. }
  3913. $token_details = $this->verify_xml_rpc_signature();
  3914. if ( ! $token_details || is_wp_error( $token_details ) ) {
  3915. return $user;
  3916. }
  3917. if ( 'user' !== $token_details['type'] ) {
  3918. return $user;
  3919. }
  3920. if ( ! $token_details['user_id'] ) {
  3921. return $user;
  3922. }
  3923. nocache_headers();
  3924. return new WP_User( $token_details['user_id'] );
  3925. }
  3926. function add_nonce( $timestamp, $nonce ) {
  3927. global $wpdb;
  3928. static $nonces_used_this_request = array();
  3929. if ( isset( $nonces_used_this_request["$timestamp:$nonce"] ) ) {
  3930. return $nonces_used_this_request["$timestamp:$nonce"];
  3931. }
  3932. // This should always have gone through Jetpack_Signature::sign_request() first to check $timestamp an $nonce
  3933. $timestamp = (int) $timestamp;
  3934. $nonce = esc_sql( $nonce );
  3935. // Raw query so we can avoid races: add_option will also update
  3936. $show_errors = $wpdb->show_errors( false );
  3937. $old_nonce = $wpdb->get_row(
  3938. $wpdb->prepare( "SELECT * FROM `$wpdb->options` WHERE option_name = %s", "jetpack_nonce_{$timestamp}_{$nonce}" )
  3939. );
  3940. if ( is_null( $old_nonce ) ) {
  3941. $return = $wpdb->query(
  3942. $wpdb->prepare(
  3943. "INSERT INTO `$wpdb->options` (`option_name`, `option_value`, `autoload`) VALUES (%s, %s, %s)",
  3944. "jetpack_nonce_{$timestamp}_{$nonce}",
  3945. time(),
  3946. 'no'
  3947. )
  3948. );
  3949. } else {
  3950. $return = false;
  3951. }
  3952. $wpdb->show_errors( $show_errors );
  3953. $nonces_used_this_request["$timestamp:$nonce"] = $return;
  3954. return $return;
  3955. }
  3956. /**
  3957. * In some setups, $HTTP_RAW_POST_DATA can be emptied during some IXR_Server paths since it is passed by reference to various methods.
  3958. * Capture it here so we can verify the signature later.
  3959. */
  3960. function xmlrpc_methods( $methods ) {
  3961. $this->HTTP_RAW_POST_DATA = $GLOBALS['HTTP_RAW_POST_DATA'];
  3962. return $methods;
  3963. }
  3964. function public_xmlrpc_methods( $methods ) {
  3965. if ( array_key_exists( 'wp.getOptions', $methods ) ) {
  3966. $methods['wp.getOptions'] = array( $this, 'jetpack_getOptions' );
  3967. }
  3968. return $methods;
  3969. }
  3970. function jetpack_getOptions( $args ) {
  3971. global $wp_xmlrpc_server;
  3972. $wp_xmlrpc_server->escape( $args );
  3973. $username = $args[1];
  3974. $password = $args[2];
  3975. if ( !$user = $wp_xmlrpc_server->login($username, $password) ) {
  3976. return $wp_xmlrpc_server->error;
  3977. }
  3978. $options = array();
  3979. $user_data = $this->get_connected_user_data();
  3980. if ( is_array( $user_data ) ) {
  3981. $options['jetpack_user_id'] = array(
  3982. 'desc' => __( 'The WP.com user ID of the connected user', 'jetpack' ),
  3983. 'readonly' => true,
  3984. 'value' => $user_data['ID'],
  3985. );
  3986. $options['jetpack_user_login'] = array(
  3987. 'desc' => __( 'The WP.com username of the connected user', 'jetpack' ),
  3988. 'readonly' => true,
  3989. 'value' => $user_data['login'],
  3990. );
  3991. $options['jetpack_user_email'] = array(
  3992. 'desc' => __( 'The WP.com user email of the connected user', 'jetpack' ),
  3993. 'readonly' => true,
  3994. 'value' => $user_data['email'],
  3995. );
  3996. $options['jetpack_user_site_count'] = array(
  3997. 'desc' => __( 'The number of sites of the connected WP.com user', 'jetpack' ),
  3998. 'readonly' => true,
  3999. 'value' => $user_data['site_count'],
  4000. );
  4001. }
  4002. $wp_xmlrpc_server->blog_options = array_merge( $wp_xmlrpc_server->blog_options, $options );
  4003. $args = stripslashes_deep( $args );
  4004. return $wp_xmlrpc_server->wp_getOptions( $args );
  4005. }
  4006. function xmlrpc_options( $options ) {
  4007. $jetpack_client_id = false;
  4008. if ( self::is_active() ) {
  4009. $jetpack_client_id = Jetpack_Options::get_option( 'id' );
  4010. }
  4011. $options['jetpack_version'] = array(
  4012. 'desc' => __( 'Jetpack Plugin Version', 'jetpack' ),
  4013. 'readonly' => true,
  4014. 'value' => JETPACK__VERSION,
  4015. );
  4016. $options['jetpack_client_id'] = array(
  4017. 'desc' => __( 'The Client ID/WP.com Blog ID of this site', 'jetpack' ),
  4018. 'readonly' => true,
  4019. 'value' => $jetpack_client_id,
  4020. );
  4021. return $options;
  4022. }
  4023. public static function clean_nonces( $all = false ) {
  4024. global $wpdb;
  4025. $sql = "DELETE FROM `$wpdb->options` WHERE `option_name` LIKE %s";
  4026. if ( method_exists ( $wpdb , 'esc_like' ) ) {
  4027. $sql_args = array( $wpdb->esc_like( 'jetpack_nonce_' ) . '%' );
  4028. } else {
  4029. $sql_args = array( like_escape( 'jetpack_nonce_' ) . '%' );
  4030. }
  4031. if ( true !== $all ) {
  4032. $sql .= ' AND CAST( `option_value` AS UNSIGNED ) < %d';
  4033. $sql_args[] = time() - 3600;
  4034. }
  4035. $sql .= ' ORDER BY `option_id` LIMIT 100';
  4036. $sql = $wpdb->prepare( $sql, $sql_args );
  4037. for ( $i = 0; $i < 1000; $i++ ) {
  4038. if ( ! $wpdb->query( $sql ) ) {
  4039. break;
  4040. }
  4041. }
  4042. }
  4043. /**
  4044. * State is passed via cookies from one request to the next, but never to subsequent requests.
  4045. * SET: state( $key, $value );
  4046. * GET: $value = state( $key );
  4047. *
  4048. * @param string $key
  4049. * @param string $value
  4050. * @param bool $restate private
  4051. */
  4052. public static function state( $key = null, $value = null, $restate = false ) {
  4053. static $state = array();
  4054. static $path, $domain;
  4055. if ( ! isset( $path ) ) {
  4056. require_once( ABSPATH . 'wp-admin/includes/plugin.php' );
  4057. $admin_url = Jetpack::admin_url();
  4058. $bits = parse_url( $admin_url );
  4059. if ( is_array( $bits ) ) {
  4060. $path = ( isset( $bits['path'] ) ) ? dirname( $bits['path'] ) : null;
  4061. $domain = ( isset( $bits['host'] ) ) ? $bits['host'] : null;
  4062. } else {
  4063. $path = $domain = null;
  4064. }
  4065. }
  4066. // Extract state from cookies and delete cookies
  4067. if ( isset( $_COOKIE[ 'jetpackState' ] ) && is_array( $_COOKIE[ 'jetpackState' ] ) ) {
  4068. $yum = $_COOKIE[ 'jetpackState' ];
  4069. unset( $_COOKIE[ 'jetpackState' ] );
  4070. foreach ( $yum as $k => $v ) {
  4071. if ( strlen( $v ) )
  4072. $state[ $k ] = $v;
  4073. setcookie( "jetpackState[$k]", false, 0, $path, $domain );
  4074. }
  4075. }
  4076. if ( $restate ) {
  4077. foreach ( $state as $k => $v ) {
  4078. setcookie( "jetpackState[$k]", $v, 0, $path, $domain );
  4079. }
  4080. return;
  4081. }
  4082. // Get a state variable
  4083. if ( isset( $key ) && ! isset( $value ) ) {
  4084. if ( array_key_exists( $key, $state ) )
  4085. return $state[ $key ];
  4086. return null;
  4087. }
  4088. // Set a state variable
  4089. if ( isset ( $key ) && isset( $value ) ) {
  4090. if( is_array( $value ) && isset( $value[0] ) ) {
  4091. $value = $value[0];
  4092. }
  4093. $state[ $key ] = $value;
  4094. setcookie( "jetpackState[$key]", $value, 0, $path, $domain );
  4095. }
  4096. }
  4097. public static function restate() {
  4098. Jetpack::state( null, null, true );
  4099. }
  4100. public static function check_privacy( $file ) {
  4101. static $is_site_publicly_accessible = null;
  4102. if ( is_null( $is_site_publicly_accessible ) ) {
  4103. $is_site_publicly_accessible = false;
  4104. Jetpack::load_xml_rpc_client();
  4105. $rpc = new Jetpack_IXR_Client();
  4106. $success = $rpc->query( 'jetpack.isSitePubliclyAccessible', home_url() );
  4107. if ( $success ) {
  4108. $response = $rpc->getResponse();
  4109. if ( $response ) {
  4110. $is_site_publicly_accessible = true;
  4111. }
  4112. }
  4113. Jetpack_Options::update_option( 'public', (int) $is_site_publicly_accessible );
  4114. }
  4115. if ( $is_site_publicly_accessible ) {
  4116. return;
  4117. }
  4118. $module_slug = self::get_module_slug( $file );
  4119. $privacy_checks = Jetpack::state( 'privacy_checks' );
  4120. if ( ! $privacy_checks ) {
  4121. $privacy_checks = $module_slug;
  4122. } else {
  4123. $privacy_checks .= ",$module_slug";
  4124. }
  4125. Jetpack::state( 'privacy_checks', $privacy_checks );
  4126. }
  4127. /**
  4128. * Helper method for multicall XMLRPC.
  4129. */
  4130. public static function xmlrpc_async_call() {
  4131. global $blog_id;
  4132. static $clients = array();
  4133. $client_blog_id = is_multisite() ? $blog_id : 0;
  4134. if ( ! isset( $clients[$client_blog_id] ) ) {
  4135. Jetpack::load_xml_rpc_client();
  4136. $clients[$client_blog_id] = new Jetpack_IXR_ClientMulticall( array( 'user_id' => JETPACK_MASTER_USER, ) );
  4137. if ( function_exists( 'ignore_user_abort' ) ) {
  4138. ignore_user_abort( true );
  4139. }
  4140. add_action( 'shutdown', array( 'Jetpack', 'xmlrpc_async_call' ) );
  4141. }
  4142. $args = func_get_args();
  4143. if ( ! empty( $args[0] ) ) {
  4144. call_user_func_array( array( $clients[$client_blog_id], 'addCall' ), $args );
  4145. } elseif ( is_multisite() ) {
  4146. foreach ( $clients as $client_blog_id => $client ) {
  4147. if ( ! $client_blog_id || empty( $client->calls ) ) {
  4148. continue;
  4149. }
  4150. $switch_success = switch_to_blog( $client_blog_id, true );
  4151. if ( ! $switch_success ) {
  4152. continue;
  4153. }
  4154. flush();
  4155. $client->query();
  4156. restore_current_blog();
  4157. }
  4158. } else {
  4159. if ( isset( $clients[0] ) && ! empty( $clients[0]->calls ) ) {
  4160. flush();
  4161. $clients[0]->query();
  4162. }
  4163. }
  4164. }
  4165. public static function staticize_subdomain( $url ) {
  4166. // Extract hostname from URL
  4167. $host = parse_url( $url, PHP_URL_HOST );
  4168. // Explode hostname on '.'
  4169. $exploded_host = explode( '.', $host );
  4170. // Retrieve the name and TLD
  4171. if ( count( $exploded_host ) > 1 ) {
  4172. $name = $exploded_host[ count( $exploded_host ) - 2 ];
  4173. $tld = $exploded_host[ count( $exploded_host ) - 1 ];
  4174. // Rebuild domain excluding subdomains
  4175. $domain = $name . '.' . $tld;
  4176. } else {
  4177. $domain = $host;
  4178. }
  4179. // Array of Automattic domains
  4180. $domain_whitelist = array( 'wordpress.com', 'wp.com' );
  4181. // Return $url if not an Automattic domain
  4182. if ( ! in_array( $domain, $domain_whitelist ) ) {
  4183. return $url;
  4184. }
  4185. if ( is_ssl() ) {
  4186. return preg_replace( '|https?://[^/]++/|', 'https://s-ssl.wordpress.com/', $url );
  4187. }
  4188. srand( crc32( basename( $url ) ) );
  4189. $static_counter = rand( 0, 2 );
  4190. srand(); // this resets everything that relies on this, like array_rand() and shuffle()
  4191. return preg_replace( '|://[^/]+?/|', "://s$static_counter.wp.com/", $url );
  4192. }
  4193. /* JSON API Authorization */
  4194. /**
  4195. * Handles the login action for Authorizing the JSON API
  4196. */
  4197. function login_form_json_api_authorization() {
  4198. $this->verify_json_api_authorization_request();
  4199. add_action( 'wp_login', array( &$this, 'store_json_api_authorization_token' ), 10, 2 );
  4200. add_action( 'login_message', array( &$this, 'login_message_json_api_authorization' ) );
  4201. add_action( 'login_form', array( &$this, 'preserve_action_in_login_form_for_json_api_authorization' ) );
  4202. add_filter( 'site_url', array( &$this, 'post_login_form_to_signed_url' ), 10, 3 );
  4203. }
  4204. // Make sure the login form is POSTed to the signed URL so we can reverify the request
  4205. function post_login_form_to_signed_url( $url, $path, $scheme ) {
  4206. if ( 'wp-login.php' !== $path || ( 'login_post' !== $scheme && 'login' !== $scheme ) ) {
  4207. return $url;
  4208. }
  4209. $parsed_url = parse_url( $url );
  4210. $url = strtok( $url, '?' );
  4211. $url = "$url?{$_SERVER['QUERY_STRING']}";
  4212. if ( ! empty( $parsed_url['query'] ) )
  4213. $url .= "&{$parsed_url['query']}";
  4214. return $url;
  4215. }
  4216. // Make sure the POSTed request is handled by the same action
  4217. function preserve_action_in_login_form_for_json_api_authorization() {
  4218. echo "<input type='hidden' name='action' value='jetpack_json_api_authorization' />\n";
  4219. echo "<input type='hidden' name='jetpack_json_api_original_query' value='" . esc_url( set_url_scheme( $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'] ) ) . "' />\n";
  4220. }
  4221. // If someone logs in to approve API access, store the Access Code in usermeta
  4222. function store_json_api_authorization_token( $user_login, $user ) {
  4223. add_filter( 'login_redirect', array( &$this, 'add_token_to_login_redirect_json_api_authorization' ), 10, 3 );
  4224. add_filter( 'allowed_redirect_hosts', array( &$this, 'allow_wpcom_public_api_domain' ) );
  4225. $token = wp_generate_password( 32, false );
  4226. update_user_meta( $user->ID, 'jetpack_json_api_' . $this->json_api_authorization_request['client_id'], $token );
  4227. }
  4228. // Add public-api.wordpress.com to the safe redirect whitelist - only added when someone allows API access
  4229. function allow_wpcom_public_api_domain( $domains ) {
  4230. $domains[] = 'public-api.wordpress.com';
  4231. return $domains;
  4232. }
  4233. // Add the Access Code details to the public-api.wordpress.com redirect
  4234. function add_token_to_login_redirect_json_api_authorization( $redirect_to, $original_redirect_to, $user ) {
  4235. return add_query_arg(
  4236. urlencode_deep(
  4237. array(
  4238. 'jetpack-code' => get_user_meta( $user->ID, 'jetpack_json_api_' . $this->json_api_authorization_request['client_id'], true ),
  4239. 'jetpack-user-id' => (int) $user->ID,
  4240. 'jetpack-state' => $this->json_api_authorization_request['state'],
  4241. )
  4242. ),
  4243. $redirect_to
  4244. );
  4245. }
  4246. // Verifies the request by checking the signature
  4247. function verify_json_api_authorization_request() {
  4248. require_once JETPACK__PLUGIN_DIR . 'class.jetpack-signature.php';
  4249. $token = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
  4250. if ( ! $token || empty( $token->secret ) ) {
  4251. wp_die( __( 'You must connect your Jetpack plugin to WordPress.com to use this feature.' , 'jetpack' ) );
  4252. }
  4253. $die_error = __( 'Someone may be trying to trick you into giving them access to your site. Or it could be you just encountered a bug :). Either way, please close this window.', 'jetpack' );
  4254. $jetpack_signature = new Jetpack_Signature( $token->secret, (int) Jetpack_Options::get_option( 'time_diff' ) );
  4255. if ( isset( $_POST['jetpack_json_api_original_query'] ) ) {
  4256. $signature = $jetpack_signature->sign_request( $_GET['token'], $_GET['timestamp'], $_GET['nonce'], '', 'GET', $_POST['jetpack_json_api_original_query'], null, true );
  4257. } else {
  4258. $signature = $jetpack_signature->sign_current_request( array( 'body' => null, 'method' => 'GET' ) );
  4259. }
  4260. if ( ! $signature ) {
  4261. wp_die( $die_error );
  4262. } else if ( is_wp_error( $signature ) ) {
  4263. wp_die( $die_error );
  4264. } else if ( ! hash_equals( $signature, $_GET['signature'] ) ) {
  4265. if ( is_ssl() ) {
  4266. // If we signed an HTTP request on the Jetpack Servers, but got redirected to HTTPS by the local blog, check the HTTP signature as well
  4267. $signature = $jetpack_signature->sign_current_request( array( 'scheme' => 'http', 'body' => null, 'method' => 'GET' ) );
  4268. if ( ! $signature || is_wp_error( $signature ) || ! hash_equals( $signature, $_GET['signature'] ) ) {
  4269. wp_die( $die_error );
  4270. }
  4271. } else {
  4272. wp_die( $die_error );
  4273. }
  4274. }
  4275. $timestamp = (int) $_GET['timestamp'];
  4276. $nonce = stripslashes( (string) $_GET['nonce'] );
  4277. if ( ! $this->add_nonce( $timestamp, $nonce ) ) {
  4278. // De-nonce the nonce, at least for 5 minutes.
  4279. // We have to reuse this nonce at least once (used the first time when the initial request is made, used a second time when the login form is POSTed)
  4280. $old_nonce_time = get_option( "jetpack_nonce_{$timestamp}_{$nonce}" );
  4281. if ( $old_nonce_time < time() - 300 ) {
  4282. wp_die( __( 'The authorization process expired. Please go back and try again.' , 'jetpack' ) );
  4283. }
  4284. }
  4285. $data = json_decode( base64_decode( stripslashes( $_GET['data'] ) ) );
  4286. $data_filters = array(
  4287. 'state' => 'opaque',
  4288. 'client_id' => 'int',
  4289. 'client_title' => 'string',
  4290. 'client_image' => 'url',
  4291. );
  4292. foreach ( $data_filters as $key => $sanitation ) {
  4293. if ( ! isset( $data->$key ) ) {
  4294. wp_die( $die_error );
  4295. }
  4296. switch ( $sanitation ) {
  4297. case 'int' :
  4298. $this->json_api_authorization_request[$key] = (int) $data->$key;
  4299. break;
  4300. case 'opaque' :
  4301. $this->json_api_authorization_request[$key] = (string) $data->$key;
  4302. break;
  4303. case 'string' :
  4304. $this->json_api_authorization_request[$key] = wp_kses( (string) $data->$key, array() );
  4305. break;
  4306. case 'url' :
  4307. $this->json_api_authorization_request[$key] = esc_url_raw( (string) $data->$key );
  4308. break;
  4309. }
  4310. }
  4311. if ( empty( $this->json_api_authorization_request['client_id'] ) ) {
  4312. wp_die( $die_error );
  4313. }
  4314. }
  4315. function login_message_json_api_authorization( $message ) {
  4316. return '<p class="message">' . sprintf(
  4317. esc_html__( '%s wants to access your site&#8217;s data. Log in to authorize that access.' , 'jetpack' ),
  4318. '<strong>' . esc_html( $this->json_api_authorization_request['client_title'] ) . '</strong>'
  4319. ) . '<img src="' . esc_url( $this->json_api_authorization_request['client_image'] ) . '" /></p>';
  4320. }
  4321. /**
  4322. * Get $content_width, but with a <s>twist</s> filter.
  4323. */
  4324. public static function get_content_width() {
  4325. $content_width = isset( $GLOBALS['content_width'] ) ? $GLOBALS['content_width'] : false;
  4326. /**
  4327. * Filter the Content Width value.
  4328. *
  4329. * @since 2.2.3
  4330. *
  4331. * @param string $content_width Content Width value.
  4332. */
  4333. return apply_filters( 'jetpack_content_width', $content_width );
  4334. }
  4335. /**
  4336. * Centralize the function here until it gets added to core.
  4337. *
  4338. * @param int|string|object $id_or_email A user ID, email address, or comment object
  4339. * @param int $size Size of the avatar image
  4340. * @param string $default URL to a default image to use if no avatar is available
  4341. * @param bool $force_display Whether to force it to return an avatar even if show_avatars is disabled
  4342. *
  4343. * @return array First element is the URL, second is the class.
  4344. */
  4345. public static function get_avatar_url( $id_or_email, $size = 96, $default = '', $force_display = false ) {
  4346. // Don't bother adding the __return_true filter if it's already there.
  4347. $has_filter = has_filter( 'pre_option_show_avatars', '__return_true' );
  4348. if ( $force_display && ! $has_filter )
  4349. add_filter( 'pre_option_show_avatars', '__return_true' );
  4350. $avatar = get_avatar( $id_or_email, $size, $default );
  4351. if ( $force_display && ! $has_filter )
  4352. remove_filter( 'pre_option_show_avatars', '__return_true' );
  4353. // If no data, fail out.
  4354. if ( is_wp_error( $avatar ) || ! $avatar )
  4355. return array( null, null );
  4356. // Pull out the URL. If it's not there, fail out.
  4357. if ( ! preg_match( '/src=["\']([^"\']+)["\']/', $avatar, $url_matches ) )
  4358. return array( null, null );
  4359. $url = wp_specialchars_decode( $url_matches[1], ENT_QUOTES );
  4360. // Pull out the class, but it's not a big deal if it's missing.
  4361. $class = '';
  4362. if ( preg_match( '/class=["\']([^"\']+)["\']/', $avatar, $class_matches ) )
  4363. $class = wp_specialchars_decode( $class_matches[1], ENT_QUOTES );
  4364. return array( $url, $class );
  4365. }
  4366. /**
  4367. * Pings the WordPress.com Mirror Site for the specified options.
  4368. *
  4369. * @param string|array $option_names The option names to request from the WordPress.com Mirror Site
  4370. *
  4371. * @return array An associative array of the option values as stored in the WordPress.com Mirror Site
  4372. */
  4373. public function get_cloud_site_options( $option_names ) {
  4374. $option_names = array_filter( (array) $option_names, 'is_string' );
  4375. Jetpack::load_xml_rpc_client();
  4376. $xml = new Jetpack_IXR_Client( array( 'user_id' => JETPACK_MASTER_USER, ) );
  4377. $xml->query( 'jetpack.fetchSiteOptions', $option_names );
  4378. if ( $xml->isError() ) {
  4379. return array(
  4380. 'error_code' => $xml->getErrorCode(),
  4381. 'error_msg' => $xml->getErrorMessage(),
  4382. );
  4383. }
  4384. $cloud_site_options = $xml->getResponse();
  4385. return $cloud_site_options;
  4386. }
  4387. /**
  4388. * Fetch the filtered array of options that we should compare to determine an identity crisis.
  4389. *
  4390. * @return array An array of options to check.
  4391. */
  4392. public static function identity_crisis_options_to_check() {
  4393. return array(
  4394. 'siteurl',
  4395. 'home',
  4396. );
  4397. }
  4398. /**
  4399. * Checks to make sure that local options have the same values as remote options. Will cache the results for up to 24 hours.
  4400. *
  4401. * @param bool $force_recheck Whether to ignore any cached transient and manually re-check.
  4402. *
  4403. * @return array An array of options that do not match. If everything is good, it will evaluate to false.
  4404. */
  4405. public static function check_identity_crisis( $force_recheck = false ) {
  4406. if ( ! Jetpack::is_active() || Jetpack::is_development_mode() || Jetpack::is_staging_site() )
  4407. return false;
  4408. if ( $force_recheck || false === ( $errors = get_transient( 'jetpack_has_identity_crisis' ) ) ) {
  4409. $options_to_check = self::identity_crisis_options_to_check();
  4410. $cloud_options = Jetpack::init()->get_cloud_site_options( $options_to_check );
  4411. $errors = array();
  4412. foreach ( $cloud_options as $cloud_key => $cloud_value ) {
  4413. // If it's not the same as the local value...
  4414. if ( $cloud_value !== get_option( $cloud_key ) ) {
  4415. // Break out if we're getting errors. We are going to check the error keys later when we alert.
  4416. if ( 'error_code' == $cloud_key ) {
  4417. $errors[ $cloud_key ] = $cloud_value;
  4418. break;
  4419. }
  4420. $parsed_cloud_value = parse_url( $cloud_value );
  4421. // If the current options is an IP address
  4422. if ( filter_var( $parsed_cloud_value['host'], FILTER_VALIDATE_IP ) ) {
  4423. // Give the new value a Jetpack to fly in to the clouds
  4424. continue;
  4425. }
  4426. // And it's not been added to the whitelist...
  4427. if ( ! self::is_identity_crisis_value_whitelisted( $cloud_key, $cloud_value ) ) {
  4428. /*
  4429. * This should be a temporary hack until a cleaner solution is found.
  4430. *
  4431. * The siteurl and home can be set to use http in General > Settings
  4432. * however some constants can be defined that can force https in wp-admin
  4433. * when this happens wpcom can confuse wporg with a fake identity
  4434. * crisis with a mismatch of http vs https when it should be allowed.
  4435. * we need to check that here.
  4436. *
  4437. * @see https://github.com/Automattic/jetpack/issues/1006
  4438. */
  4439. if ( ( 'home' == $cloud_key || 'siteurl' == $cloud_key )
  4440. && ( substr( $cloud_value, 0, 8 ) == "https://" )
  4441. && Jetpack::init()->is_ssl_required_to_visit_site() ) {
  4442. // Ok, we found a mismatch of http and https because of wp-config, not an invalid url
  4443. continue;
  4444. }
  4445. // Then kick an error!
  4446. $errors[ $cloud_key ] = $cloud_value;
  4447. }
  4448. }
  4449. }
  4450. }
  4451. /**
  4452. * Filters the errors returned when checking for an Identity Crisis.
  4453. *
  4454. * @since 2.3.2
  4455. *
  4456. * @param array $errors Array of Identity Crisis errors.
  4457. * @param bool $force_recheck Ignore any cached transient and manually re-check. Default to false.
  4458. */
  4459. return apply_filters( 'jetpack_has_identity_crisis', $errors, $force_recheck );
  4460. }
  4461. /**
  4462. * Checks whether a value is already whitelisted.
  4463. *
  4464. * @param string $key The option name that we're checking the value for.
  4465. * @param string $value The value that we're curious to see if it's on the whitelist.
  4466. *
  4467. * @return bool Whether the value is whitelisted.
  4468. */
  4469. public static function is_identity_crisis_value_whitelisted( $key, $value ) {
  4470. $whitelist = Jetpack_Options::get_option( 'identity_crisis_whitelist', array() );
  4471. if ( ! empty( $whitelist[ $key ] ) && is_array( $whitelist[ $key ] ) && in_array( $value, $whitelist[ $key ] ) ) {
  4472. return true;
  4473. }
  4474. return false;
  4475. }
  4476. /**
  4477. * Checks whether the home and siteurl specifically are whitelisted
  4478. * Written so that we don't have re-check $key and $value params every time
  4479. * we want to check if this site is whitelisted, for example in footer.php
  4480. *
  4481. * @since 3.8.0
  4482. * @return bool True = already whitelisted False = not whitelisted
  4483. */
  4484. public static function is_staging_site() {
  4485. $is_staging = false;
  4486. $known_staging = array(
  4487. 'urls' => array(
  4488. '#\.staging\.wpengine\.com$#i', // WP Engine
  4489. ),
  4490. 'constants' => array(
  4491. 'IS_WPE_SNAPSHOT', // WP Engine
  4492. 'KINSTA_DEV_ENV', // Kinsta.com
  4493. 'WPSTAGECOACH_STAGING', // WP Stagecoach
  4494. 'JETPACK_STAGING_MODE', // Generic
  4495. )
  4496. );
  4497. /**
  4498. * Filters the flags of known staging sites.
  4499. *
  4500. * @since 3.9.0
  4501. *
  4502. * @param array $known_staging {
  4503. * An array of arrays that each are used to check if the current site is staging.
  4504. * @type array $urls URLs of staging sites in regex to check against site_url.
  4505. * @type array $constants PHP constants of known staging/developement environments.
  4506. * }
  4507. */
  4508. $known_staging = apply_filters( 'jetpack_known_staging', $known_staging );
  4509. if ( isset( $known_staging['urls'] ) ) {
  4510. foreach ( $known_staging['urls'] as $url ){
  4511. if ( preg_match( $url, site_url() ) ) {
  4512. $is_staging = true;
  4513. break;
  4514. }
  4515. }
  4516. }
  4517. if ( isset( $known_staging['constants'] ) ) {
  4518. foreach ( $known_staging['constants'] as $constant ) {
  4519. if ( defined( $constant ) && constant( $constant ) ) {
  4520. $is_staging = true;
  4521. }
  4522. }
  4523. }
  4524. /**
  4525. * Filters is_staging_site check.
  4526. *
  4527. * @since 3.9.0
  4528. *
  4529. * @param bool $is_staging If the current site is a staging site.
  4530. */
  4531. return apply_filters( 'jetpack_is_staging_site', $is_staging );
  4532. }
  4533. /**
  4534. * Maybe Use a .min.css stylesheet, maybe not.
  4535. *
  4536. * Hooks onto `plugins_url` filter at priority 1, and accepts all 3 args.
  4537. */
  4538. public static function maybe_min_asset( $url, $path, $plugin ) {
  4539. // Short out on things trying to find actual paths.
  4540. if ( ! $path || empty( $plugin ) ) {
  4541. return $url;
  4542. }
  4543. // Strip out the abspath.
  4544. $base = dirname( plugin_basename( $plugin ) );
  4545. // Short out on non-Jetpack assets.
  4546. if ( 'jetpack/' !== substr( $base, 0, 8 ) ) {
  4547. return $url;
  4548. }
  4549. // File name parsing.
  4550. $file = "{$base}/{$path}";
  4551. $full_path = JETPACK__PLUGIN_DIR . substr( $file, 8 );
  4552. $file_name = substr( $full_path, strrpos( $full_path, '/' ) + 1 );
  4553. $file_name_parts_r = array_reverse( explode( '.', $file_name ) );
  4554. $extension = array_shift( $file_name_parts_r );
  4555. if ( in_array( strtolower( $extension ), array( 'css', 'js' ) ) ) {
  4556. // Already pointing at the minified version.
  4557. if ( 'min' === $file_name_parts_r[0] ) {
  4558. return $url;
  4559. }
  4560. $min_full_path = preg_replace( "#\.{$extension}$#", ".min.{$extension}", $full_path );
  4561. if ( file_exists( $min_full_path ) ) {
  4562. $url = preg_replace( "#\.{$extension}$#", ".min.{$extension}", $url );
  4563. }
  4564. }
  4565. return $url;
  4566. }
  4567. /**
  4568. * Maybe inlines a stylesheet.
  4569. *
  4570. * If you'd like to inline a stylesheet instead of printing a link to it,
  4571. * wp_style_add_data( 'handle', 'jetpack-inline', true );
  4572. *
  4573. * Attached to `style_loader_tag` filter.
  4574. *
  4575. * @param string $tag The tag that would link to the external asset.
  4576. * @param string $handle The registered handle of the script in question.
  4577. *
  4578. * @return string
  4579. */
  4580. public static function maybe_inline_style( $tag, $handle ) {
  4581. global $wp_styles;
  4582. $item = $wp_styles->registered[ $handle ];
  4583. if ( ! isset( $item->extra['jetpack-inline'] ) || ! $item->extra['jetpack-inline'] ) {
  4584. return $tag;
  4585. }
  4586. if ( preg_match( '# href=\'([^\']+)\' #i', $tag, $matches ) ) {
  4587. $href = $matches[1];
  4588. // Strip off query string
  4589. if ( $pos = strpos( $href, '?' ) ) {
  4590. $href = substr( $href, 0, $pos );
  4591. }
  4592. // Strip off fragment
  4593. if ( $pos = strpos( $href, '#' ) ) {
  4594. $href = substr( $href, 0, $pos );
  4595. }
  4596. } else {
  4597. return $tag;
  4598. }
  4599. $plugins_dir = plugin_dir_url( JETPACK__PLUGIN_FILE );
  4600. if ( $plugins_dir !== substr( $href, 0, strlen( $plugins_dir ) ) ) {
  4601. return $tag;
  4602. }
  4603. // If this stylesheet has a RTL version, and the RTL version replaces normal...
  4604. if ( isset( $item->extra['rtl'] ) && 'replace' === $item->extra['rtl'] && is_rtl() ) {
  4605. // And this isn't the pass that actually deals with the RTL version...
  4606. if ( false === strpos( $tag, " id='$handle-rtl-css' " ) ) {
  4607. // Short out, as the RTL version will deal with it in a moment.
  4608. return $tag;
  4609. }
  4610. }
  4611. $file = JETPACK__PLUGIN_DIR . substr( $href, strlen( $plugins_dir ) );
  4612. $css = Jetpack::absolutize_css_urls( file_get_contents( $file ), $href );
  4613. if ( $css ) {
  4614. $tag = "<!-- Inline {$item->handle} -->\r\n";
  4615. if ( empty( $item->extra['after'] ) ) {
  4616. wp_add_inline_style( $handle, $css );
  4617. } else {
  4618. array_unshift( $item->extra['after'], $css );
  4619. wp_style_add_data( $handle, 'after', $item->extra['after'] );
  4620. }
  4621. }
  4622. return $tag;
  4623. }
  4624. /**
  4625. * Loads a view file from the views
  4626. *
  4627. * Data passed in with the $data parameter will be available in the
  4628. * template file as $data['value']
  4629. *
  4630. * @param string $template - Template file to load
  4631. * @param array $data - Any data to pass along to the template
  4632. * @return boolean - If template file was found
  4633. **/
  4634. public function load_view( $template, $data = array() ) {
  4635. $views_dir = JETPACK__PLUGIN_DIR . 'views/';
  4636. if( file_exists( $views_dir . $template ) ) {
  4637. require_once( $views_dir . $template );
  4638. return true;
  4639. }
  4640. error_log( "Jetpack: Unable to find view file $views_dir$template" );
  4641. return false;
  4642. }
  4643. /**
  4644. * Throws warnings for deprecated hooks to be removed from Jetpack
  4645. */
  4646. public function deprecated_hooks() {
  4647. global $wp_filter;
  4648. /*
  4649. * Format:
  4650. * deprecated_filter_name => replacement_name
  4651. *
  4652. * If there is no replacement us null for replacement_name
  4653. */
  4654. $deprecated_list = array(
  4655. 'jetpack_bail_on_shortcode' => 'jetpack_shortcodes_to_include',
  4656. 'wpl_sharing_2014_1' => null,
  4657. 'jetpack-tools-to-include' => 'jetpack_tools_to_include',
  4658. 'jetpack_identity_crisis_options_to_check' => null,
  4659. 'update_option_jetpack_single_user_site' => null,
  4660. 'audio_player_default_colors' => null,
  4661. 'add_option_jetpack_featured_images_enabled' => null,
  4662. 'add_option_jetpack_update_details' => null,
  4663. 'add_option_jetpack_updates' => null,
  4664. 'add_option_jetpack_network_name' => null,
  4665. 'add_option_jetpack_network_allow_new_registrations' => null,
  4666. 'add_option_jetpack_network_add_new_users' => null,
  4667. 'add_option_jetpack_network_site_upload_space' => null,
  4668. 'add_option_jetpack_network_upload_file_types' => null,
  4669. 'add_option_jetpack_network_enable_administration_menus' => null,
  4670. 'add_option_jetpack_is_multi_site' => null,
  4671. 'add_option_jetpack_is_main_network' => null,
  4672. 'add_option_jetpack_main_network_site' => null,
  4673. 'jetpack_sync_all_registered_options' => null,
  4674. );
  4675. // This is a silly loop depth. Better way?
  4676. foreach( $deprecated_list AS $hook => $hook_alt ) {
  4677. if( isset( $wp_filter[ $hook ] ) && is_array( $wp_filter[ $hook ] ) ) {
  4678. foreach( $wp_filter[$hook] AS $func => $values ) {
  4679. foreach( $values AS $hooked ) {
  4680. _deprecated_function( $hook . ' used for ' . $hooked['function'], null, $hook_alt );
  4681. }
  4682. }
  4683. }
  4684. }
  4685. }
  4686. /**
  4687. * Converts any url in a stylesheet, to the correct absolute url.
  4688. *
  4689. * Considerations:
  4690. * - Normal, relative URLs `feh.png`
  4691. * - Data URLs ``
  4692. * - Schema-agnostic URLs `//domain.com/feh.png`
  4693. * - Absolute URLs `http://domain.com/feh.png`
  4694. * - Domain root relative URLs `/feh.png`
  4695. *
  4696. * @param $css string: The raw CSS -- should be read in directly from the file.
  4697. * @param $css_file_url : The URL that the file can be accessed at, for calculating paths from.
  4698. *
  4699. * @return mixed|string
  4700. */
  4701. public static function absolutize_css_urls( $css, $css_file_url ) {
  4702. $pattern = '#url\((?P<path>[^)]*)\)#i';
  4703. $css_dir = dirname( $css_file_url );
  4704. $p = parse_url( $css_dir );
  4705. $domain = sprintf(
  4706. '%1$s//%2$s%3$s%4$s',
  4707. isset( $p['scheme'] ) ? "{$p['scheme']}:" : '',
  4708. isset( $p['user'], $p['pass'] ) ? "{$p['user']}:{$p['pass']}@" : '',
  4709. $p['host'],
  4710. isset( $p['port'] ) ? ":{$p['port']}" : ''
  4711. );
  4712. if ( preg_match_all( $pattern, $css, $matches, PREG_SET_ORDER ) ) {
  4713. $find = $replace = array();
  4714. foreach ( $matches as $match ) {
  4715. $url = trim( $match['path'], "'\" \t" );
  4716. // If this is a data url, we don't want to mess with it.
  4717. if ( 'data:' === substr( $url, 0, 5 ) ) {
  4718. continue;
  4719. }
  4720. // If this is an absolute or protocol-agnostic url,
  4721. // we don't want to mess with it.
  4722. if ( preg_match( '#^(https?:)?//#i', $url ) ) {
  4723. continue;
  4724. }
  4725. switch ( substr( $url, 0, 1 ) ) {
  4726. case '/':
  4727. $absolute = $domain . $url;
  4728. break;
  4729. default:
  4730. $absolute = $css_dir . '/' . $url;
  4731. }
  4732. $find[] = $match[0];
  4733. $replace[] = sprintf( 'url("%s")', $absolute );
  4734. }
  4735. $css = str_replace( $find, $replace, $css );
  4736. }
  4737. return $css;
  4738. }
  4739. /**
  4740. * This method checks to see if SSL is required by the site in
  4741. * order to visit it in some way other than only setting the
  4742. * https value in the home or siteurl values.
  4743. *
  4744. * @since 3.2
  4745. * @return boolean
  4746. **/
  4747. private function is_ssl_required_to_visit_site() {
  4748. global $wp_version;
  4749. $ssl = is_ssl();
  4750. if ( force_ssl_admin() ) {
  4751. $ssl = true;
  4752. }
  4753. return $ssl;
  4754. }
  4755. /**
  4756. * This methods removes all of the registered css files on the front end
  4757. * from Jetpack in favor of using a single file. In effect "imploding"
  4758. * all the files into one file.
  4759. *
  4760. * Pros:
  4761. * - Uses only ONE css asset connection instead of 15
  4762. * - Saves a minimum of 56k
  4763. * - Reduces server load
  4764. * - Reduces time to first painted byte
  4765. *
  4766. * Cons:
  4767. * - Loads css for ALL modules. However all selectors are prefixed so it
  4768. * should not cause any issues with themes.
  4769. * - Plugins/themes dequeuing styles no longer do anything. See
  4770. * jetpack_implode_frontend_css filter for a workaround
  4771. *
  4772. * For some situations developers may wish to disable css imploding and
  4773. * instead operate in legacy mode where each file loads seperately and
  4774. * can be edited individually or dequeued. This can be accomplished with
  4775. * the following line:
  4776. *
  4777. * add_filter( 'jetpack_implode_frontend_css', '__return_false' );
  4778. *
  4779. * @since 3.2
  4780. **/
  4781. public function implode_frontend_css( $travis_test = false ) {
  4782. $do_implode = true;
  4783. if ( defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ) {
  4784. $do_implode = false;
  4785. }
  4786. /**
  4787. * Allow CSS to be concatenated into a single jetpack.css file.
  4788. *
  4789. * @since 3.2.0
  4790. *
  4791. * @param bool $do_implode Should CSS be concatenated? Default to true.
  4792. */
  4793. $do_implode = apply_filters( 'jetpack_implode_frontend_css', $do_implode );
  4794. // Do not use the imploded file when default behaviour was altered through the filter
  4795. if ( ! $do_implode ) {
  4796. return;
  4797. }
  4798. // We do not want to use the imploded file in dev mode, or if not connected
  4799. if ( Jetpack::is_development_mode() || ! self::is_active() ) {
  4800. if ( ! $travis_test ) {
  4801. return;
  4802. }
  4803. }
  4804. // Do not use the imploded file if sharing css was dequeued via the sharing settings screen
  4805. if ( get_option( 'sharedaddy_disable_resources' ) ) {
  4806. return;
  4807. }
  4808. /*
  4809. * Now we assume Jetpack is connected and able to serve the single
  4810. * file.
  4811. *
  4812. * In the future there will be a check here to serve the file locally
  4813. * or potentially from the Jetpack CDN
  4814. *
  4815. * For now:
  4816. * - Enqueue a single imploded css file
  4817. * - Zero out the style_loader_tag for the bundled ones
  4818. * - Be happy, drink scotch
  4819. */
  4820. add_filter( 'style_loader_tag', array( $this, 'concat_remove_style_loader_tag' ), 10, 2 );
  4821. $version = Jetpack::is_development_version() ? filemtime( JETPACK__PLUGIN_DIR . 'css/jetpack.css' ) : JETPACK__VERSION;
  4822. wp_enqueue_style( 'jetpack_css', plugins_url( 'css/jetpack.css', __FILE__ ), array(), $version );
  4823. wp_style_add_data( 'jetpack_css', 'rtl', 'replace' );
  4824. }
  4825. function concat_remove_style_loader_tag( $tag, $handle ) {
  4826. if ( in_array( $handle, $this->concatenated_style_handles ) ) {
  4827. $tag = '';
  4828. if ( defined( 'WP_DEBUG' ) && WP_DEBUG ) {
  4829. $tag = "<!-- `" . esc_html( $handle ) . "` is included in the concatenated jetpack.css -->\r\n";
  4830. }
  4831. }
  4832. return $tag;
  4833. }
  4834. /*
  4835. * Check the heartbeat data
  4836. *
  4837. * Organizes the heartbeat data by severity. For example, if the site
  4838. * is in an ID crisis, it will be in the $filtered_data['bad'] array.
  4839. *
  4840. * Data will be added to "caution" array, if it either:
  4841. * - Out of date Jetpack version
  4842. * - Out of date WP version
  4843. * - Out of date PHP version
  4844. *
  4845. * $return array $filtered_data
  4846. */
  4847. public static function jetpack_check_heartbeat_data() {
  4848. $raw_data = Jetpack_Heartbeat::generate_stats_array();
  4849. $good = array();
  4850. $caution = array();
  4851. $bad = array();
  4852. foreach ( $raw_data as $stat => $value ) {
  4853. // Check jetpack version
  4854. if ( 'version' == $stat ) {
  4855. if ( version_compare( $value, JETPACK__VERSION, '<' ) ) {
  4856. $caution[ $stat ] = $value . " - min supported is " . JETPACK__VERSION;
  4857. continue;
  4858. }
  4859. }
  4860. // Check WP version
  4861. if ( 'wp-version' == $stat ) {
  4862. if ( version_compare( $value, JETPACK__MINIMUM_WP_VERSION, '<' ) ) {
  4863. $caution[ $stat ] = $value . " - min supported is " . JETPACK__MINIMUM_WP_VERSION;
  4864. continue;
  4865. }
  4866. }
  4867. // Check PHP version
  4868. if ( 'php-version' == $stat ) {
  4869. if ( version_compare( PHP_VERSION, '5.2.4', '<' ) ) {
  4870. $caution[ $stat ] = $value . " - min supported is 5.2.4";
  4871. continue;
  4872. }
  4873. }
  4874. // Check ID crisis
  4875. if ( 'identitycrisis' == $stat ) {
  4876. if ( 'yes' == $value ) {
  4877. $bad[ $stat ] = $value;
  4878. continue;
  4879. }
  4880. }
  4881. // The rest are good :)
  4882. $good[ $stat ] = $value;
  4883. }
  4884. $filtered_data = array(
  4885. 'good' => $good,
  4886. 'caution' => $caution,
  4887. 'bad' => $bad
  4888. );
  4889. return $filtered_data;
  4890. }
  4891. /*
  4892. * This method is used to organize all options that can be reset
  4893. * without disconnecting Jetpack.
  4894. *
  4895. * It is used in class.jetpack-cli.php to reset options
  4896. *
  4897. * @return array of options to delete.
  4898. */
  4899. public static function get_jetpack_options_for_reset() {
  4900. $jetpack_options = Jetpack_Options::get_option_names();
  4901. $jetpack_options_non_compat = Jetpack_Options::get_option_names( 'non_compact' );
  4902. $jetpack_options_private = Jetpack_Options::get_option_names( 'private' );
  4903. $all_jp_options = array_merge( $jetpack_options, $jetpack_options_non_compat, $jetpack_options_private );
  4904. // A manual build of the wp options
  4905. $wp_options = array(
  4906. 'sharing-options',
  4907. 'disabled_likes',
  4908. 'disabled_reblogs',
  4909. 'jetpack_comments_likes_enabled',
  4910. 'wp_mobile_excerpt',
  4911. 'wp_mobile_featured_images',
  4912. 'wp_mobile_app_promos',
  4913. 'stats_options',
  4914. 'stats_dashboard_widget',
  4915. 'safecss_preview_rev',
  4916. 'safecss_rev',
  4917. 'safecss_revision_migrated',
  4918. 'nova_menu_order',
  4919. 'jetpack_portfolio',
  4920. 'jetpack_portfolio_posts_per_page',
  4921. 'jetpack_testimonial',
  4922. 'jetpack_testimonial_posts_per_page',
  4923. 'wp_mobile_custom_css',
  4924. 'sharedaddy_disable_resources',
  4925. 'sharing-options',
  4926. 'sharing-services',
  4927. 'site_icon_temp_data',
  4928. 'featured-content',
  4929. 'site_logo',
  4930. 'jetpack_dismissed_notices',
  4931. );
  4932. // Flag some Jetpack options as unsafe
  4933. $unsafe_options = array(
  4934. 'id', // (int) The Client ID/WP.com Blog ID of this site.
  4935. 'master_user', // (int) The local User ID of the user who connected this site to jetpack.wordpress.com.
  4936. 'version', // (string) Used during upgrade procedure to auto-activate new modules. version:time
  4937. 'jumpstart', // (string) A flag for whether or not to show the Jump Start. Accepts: new_connection, jumpstart_activated, jetpack_action_taken, jumpstart_dismissed.
  4938. // non_compact
  4939. 'activated',
  4940. // private
  4941. 'register',
  4942. 'blog_token', // (string) The Client Secret/Blog Token of this site.
  4943. 'user_token', // (string) The User Token of this site. (deprecated)
  4944. 'user_tokens'
  4945. );
  4946. // Remove the unsafe Jetpack options
  4947. foreach ( $unsafe_options as $unsafe_option ) {
  4948. if ( false !== ( $key = array_search( $unsafe_option, $all_jp_options ) ) ) {
  4949. unset( $all_jp_options[ $key ] );
  4950. }
  4951. }
  4952. $options = array(
  4953. 'jp_options' => $all_jp_options,
  4954. 'wp_options' => $wp_options
  4955. );
  4956. return $options;
  4957. }
  4958. /**
  4959. * Check if an option of a Jetpack module has been updated.
  4960. *
  4961. * If any module option has been updated before Jump Start has been dismissed,
  4962. * update the 'jumpstart' option so we can hide Jump Start.
  4963. *
  4964. * @param string $option_name
  4965. *
  4966. * @return bool
  4967. */
  4968. public static function jumpstart_has_updated_module_option( $option_name = '' ) {
  4969. // Bail if Jump Start has already been dismissed
  4970. if ( 'new_connection' !== Jetpack_Options::get_option( 'jumpstart' ) ) {
  4971. return false;
  4972. }
  4973. $jetpack = Jetpack::init();
  4974. // Manual build of module options
  4975. $option_names = self::get_jetpack_options_for_reset();
  4976. if ( in_array( $option_name, $option_names['wp_options'] ) ) {
  4977. Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
  4978. //Jump start is being dismissed send data to MC Stats
  4979. $jetpack->stat( 'jumpstart', 'manual,'.$option_name );
  4980. $jetpack->do_stats( 'server_side' );
  4981. }
  4982. }
  4983. /*
  4984. * Strip http:// or https:// from a url, replaces forward slash with ::,
  4985. * so we can bring them directly to their site in calypso.
  4986. *
  4987. * @param string | url
  4988. * @return string | url without the guff
  4989. */
  4990. public static function build_raw_urls( $url ) {
  4991. $strip_http = '/.*?:\/\//i';
  4992. $url = preg_replace( $strip_http, '', $url );
  4993. $url = str_replace( '/', '::', $url );
  4994. return $url;
  4995. }
  4996. /**
  4997. * Stores and prints out domains to prefetch for page speed optimization.
  4998. *
  4999. * @param mixed $new_urls
  5000. */
  5001. public static function dns_prefetch( $new_urls = null ) {
  5002. static $prefetch_urls = array();
  5003. if ( empty( $new_urls ) && ! empty( $prefetch_urls ) ) {
  5004. echo "\r\n";
  5005. foreach ( $prefetch_urls as $this_prefetch_url ) {
  5006. printf( "<link rel='dns-prefetch' href='%s'>\r\n", esc_attr( $this_prefetch_url ) );
  5007. }
  5008. } elseif ( ! empty( $new_urls ) ) {
  5009. if ( ! has_action( 'wp_head', array( __CLASS__, __FUNCTION__ ) ) ) {
  5010. add_action( 'wp_head', array( __CLASS__, __FUNCTION__ ) );
  5011. }
  5012. foreach ( (array) $new_urls as $this_new_url ) {
  5013. $prefetch_urls[] = strtolower( untrailingslashit( preg_replace( '#^https?://#i', '//', $this_new_url ) ) );
  5014. }
  5015. $prefetch_urls = array_unique( $prefetch_urls );
  5016. }
  5017. }
  5018. public function wp_dashboard_setup() {
  5019. if ( self::is_active() ) {
  5020. add_action( 'jetpack_dashboard_widget', array( __CLASS__, 'dashboard_widget_footer' ), 999 );
  5021. $widget_title = __( 'Site Stats', 'jetpack' );
  5022. } elseif ( ! self::is_development_mode() && current_user_can( 'jetpack_connect' ) ) {
  5023. add_action( 'jetpack_dashboard_widget', array( $this, 'dashboard_widget_connect_to_wpcom' ) );
  5024. $widget_title = __( 'Please Connect Jetpack', 'jetpack' );
  5025. }
  5026. if ( has_action( 'jetpack_dashboard_widget' ) ) {
  5027. wp_add_dashboard_widget(
  5028. 'jetpack_summary_widget',
  5029. $widget_title,
  5030. array( __CLASS__, 'dashboard_widget' )
  5031. );
  5032. wp_enqueue_style( 'jetpack-dashboard-widget', plugins_url( 'css/dashboard-widget.css', JETPACK__PLUGIN_FILE ), array(), JETPACK__VERSION );
  5033. // If we're inactive and not in development mode, sort our box to the top.
  5034. if ( ! self::is_active() && ! self::is_development_mode() ) {
  5035. global $wp_meta_boxes;
  5036. $dashboard = $wp_meta_boxes['dashboard']['normal']['core'];
  5037. $ours = array( 'jetpack_summary_widget' => $dashboard['jetpack_summary_widget'] );
  5038. $wp_meta_boxes['dashboard']['normal']['core'] = array_merge( $ours, $dashboard );
  5039. }
  5040. }
  5041. }
  5042. /**
  5043. * @param mixed $result Value for the user's option
  5044. * @return mixed
  5045. */
  5046. function get_user_option_meta_box_order_dashboard( $sorted ) {
  5047. if ( ! is_array( $sorted ) ) {
  5048. return $sorted;
  5049. }
  5050. foreach ( $sorted as $box_context => $ids ) {
  5051. if ( false === strpos( $ids, 'dashboard_stats' ) ) {
  5052. // If the old id isn't anywhere in the ids, don't bother exploding and fail out.
  5053. continue;
  5054. }
  5055. $ids_array = explode( ',', $ids );
  5056. $key = array_search( 'dashboard_stats', $ids_array );
  5057. if ( false !== $key ) {
  5058. // If we've found that exact value in the option (and not `google_dashboard_stats` for example)
  5059. $ids_array[ $key ] = 'jetpack_summary_widget';
  5060. $sorted[ $box_context ] = implode( ',', $ids_array );
  5061. // We've found it, stop searching, and just return.
  5062. break;
  5063. }
  5064. }
  5065. return $sorted;
  5066. }
  5067. public static function dashboard_widget() {
  5068. /**
  5069. * Fires when the dashboard is loaded.
  5070. *
  5071. * @since 3.4.0
  5072. */
  5073. do_action( 'jetpack_dashboard_widget' );
  5074. }
  5075. public static function dashboard_widget_footer() {
  5076. ?>
  5077. <footer>
  5078. <div class="protect">
  5079. <?php if ( Jetpack::is_module_active( 'protect' ) ) : ?>
  5080. <h3><?php echo number_format_i18n( get_site_option( 'jetpack_protect_blocked_attempts', 0 ) ); ?></h3>
  5081. <p><?php echo esc_html_x( 'Blocked malicious login attempts', '{#} Blocked malicious login attempts -- number is on a prior line, text is a caption.', 'jetpack' ); ?></p>
  5082. <?php elseif ( current_user_can( 'jetpack_activate_modules' ) && ! self::is_development_mode() ) : ?>
  5083. <a href="<?php echo esc_url( wp_nonce_url( Jetpack::admin_url( array( 'action' => 'activate', 'module' => 'protect' ) ), 'jetpack_activate-protect' ) ); ?>" class="button button-jetpack" title="<?php esc_attr_e( 'Protect helps to keep you secure from brute-force login attacks.', 'jetpack' ); ?>">
  5084. <?php esc_html_e( 'Activate Protect', 'jetpack' ); ?>
  5085. </a>
  5086. <?php else : ?>
  5087. <?php esc_html_e( 'Protect is inactive.', 'jetpack' ); ?>
  5088. <?php endif; ?>
  5089. </div>
  5090. <div class="akismet">
  5091. <?php if ( is_plugin_active( 'akismet/akismet.php' ) ) : ?>
  5092. <h3><?php echo number_format_i18n( get_option( 'akismet_spam_count', 0 ) ); ?></h3>
  5093. <p><?php echo esc_html_x( 'Spam comments blocked by Akismet.', '{#} Spam comments blocked by Akismet -- number is on a prior line, text is a caption.', 'jetpack' ); ?></p>
  5094. <?php elseif ( current_user_can( 'activate_plugins' ) && ! is_wp_error( validate_plugin( 'akismet/akismet.php' ) ) ) : ?>
  5095. <a href="<?php echo esc_url( wp_nonce_url( add_query_arg( array( 'action' => 'activate', 'plugin' => 'akismet/akismet.php' ), admin_url( 'plugins.php' ) ), 'activate-plugin_akismet/akismet.php' ) ); ?>" class="button button-jetpack">
  5096. <?php esc_html_e( 'Activate Akismet', 'jetpack' ); ?>
  5097. </a>
  5098. <?php else : ?>
  5099. <p><a href="<?php echo esc_url( 'https://akismet.com/?utm_source=jetpack&utm_medium=link&utm_campaign=Jetpack%20Dashboard%20Widget%20Footer%20Link' ); ?>"><?php esc_html_e( 'Akismet can help to keep your blog safe from spam!', 'jetpack' ); ?></a></p>
  5100. <?php endif; ?>
  5101. </div>
  5102. </footer>
  5103. <?php
  5104. }
  5105. public function dashboard_widget_connect_to_wpcom() {
  5106. if ( Jetpack::is_active() || Jetpack::is_development_mode() || ! current_user_can( 'jetpack_connect' ) ) {
  5107. return;
  5108. }
  5109. ?>
  5110. <div class="wpcom-connect">
  5111. <div class="jp-emblem">
  5112. <svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0" y="0" viewBox="0 0 172.9 172.9" enable-background="new 0 0 172.9 172.9" xml:space="preserve">
  5113. <path d="M86.4 0C38.7 0 0 38.7 0 86.4c0 47.7 38.7 86.4 86.4 86.4s86.4-38.7 86.4-86.4C172.9 38.7 134.2 0 86.4 0zM83.1 106.6l-27.1-6.9C49 98 45.7 90.1 49.3 84l33.8-58.5V106.6zM124.9 88.9l-33.8 58.5V66.3l27.1 6.9C125.1 74.9 128.4 82.8 124.9 88.9z"/>
  5114. </svg>
  5115. </div>
  5116. <h3><?php esc_html_e( 'Please Connect Jetpack', 'jetpack' ); ?></h3>
  5117. <p><?php echo wp_kses( __( 'Connecting Jetpack will show you <strong>stats</strong> about your traffic, <strong>protect</strong> you from brute force attacks, <strong>speed up</strong> your images and photos, and enable other <strong>traffic and security</strong> features.', 'jetpack' ), 'jetpack' ) ?></p>
  5118. <div class="actions">
  5119. <a href="<?php echo $this->build_connect_url( false, false, 'widget-btn' ); ?>" class="button button-primary">
  5120. <?php esc_html_e( 'Connect Jetpack', 'jetpack' ); ?>
  5121. </a>
  5122. </div>
  5123. </div>
  5124. <?php
  5125. }
  5126. /*
  5127. * A graceful transition to using Core's site icon.
  5128. *
  5129. * All of the hard work has already been done with the image
  5130. * in all_done_page(). All that needs to be done now is update
  5131. * the option and display proper messaging.
  5132. *
  5133. * @todo remove when WP 4.3 is minimum
  5134. *
  5135. * @since 3.6.1
  5136. *
  5137. * @return bool false = Core's icon not available || true = Core's icon is available
  5138. */
  5139. public static function jetpack_site_icon_available_in_core() {
  5140. global $wp_version;
  5141. $core_icon_available = function_exists( 'has_site_icon' ) && version_compare( $wp_version, '4.3-beta' ) >= 0;
  5142. if ( ! $core_icon_available ) {
  5143. return false;
  5144. }
  5145. // No need for Jetpack's site icon anymore if core's is already set
  5146. if ( has_site_icon() ) {
  5147. if ( Jetpack::is_module_active( 'site-icon' ) ) {
  5148. Jetpack::log( 'deactivate', 'site-icon' );
  5149. Jetpack::deactivate_module( 'site-icon' );
  5150. }
  5151. return true;
  5152. }
  5153. // Transfer Jetpack's site icon to use core.
  5154. $site_icon_id = Jetpack::get_option( 'site_icon_id' );
  5155. if ( $site_icon_id ) {
  5156. // Update core's site icon
  5157. update_option( 'site_icon', $site_icon_id );
  5158. // Delete Jetpack's icon option. We still want the blavatar and attached data though.
  5159. delete_option( 'site_icon_id' );
  5160. }
  5161. // No need for Jetpack's site icon anymore
  5162. if ( Jetpack::is_module_active( 'site-icon' ) ) {
  5163. Jetpack::log( 'deactivate', 'site-icon' );
  5164. Jetpack::deactivate_module( 'site-icon' );
  5165. }
  5166. return true;
  5167. }
  5168. /**
  5169. * Return string containing the Jetpack logo.
  5170. *
  5171. * @since 3.9.0
  5172. *
  5173. * @return string
  5174. */
  5175. public static function get_jp_emblem() {
  5176. return '<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0" y="0" viewBox="0 0 172.9 172.9" enable-background="new 0 0 172.9 172.9" xml:space="preserve"> <path d="M86.4 0C38.7 0 0 38.7 0 86.4c0 47.7 38.7 86.4 86.4 86.4s86.4-38.7 86.4-86.4C172.9 38.7 134.2 0 86.4 0zM83.1 106.6l-27.1-6.9C49 98 45.7 90.1 49.3 84l33.8-58.5V106.6zM124.9 88.9l-33.8 58.5V66.3l27.1 6.9C125.1 74.9 128.4 82.8 124.9 88.9z" /></svg>';
  5177. }
  5178. /*
  5179. * Adds a "blank" column in the user admin table to display indication of user connection.
  5180. */
  5181. function jetpack_icon_user_connected( $columns ) {
  5182. $columns['user_jetpack'] = '';
  5183. return $columns;
  5184. }
  5185. /*
  5186. * Show Jetpack icon if the user is linked.
  5187. */
  5188. function jetpack_show_user_connected_icon( $val, $col, $user_id ) {
  5189. if ( 'user_jetpack' == $col && Jetpack::is_user_connected( $user_id ) ) {
  5190. $emblem_html = sprintf(
  5191. '<a title="%1$s" class="jp-emblem-user-admin">%2$s</a>',
  5192. esc_attr__( 'This user is linked and ready to fly with Jetpack.', 'jetpack' ),
  5193. Jetpack::get_jp_emblem()
  5194. );
  5195. return $emblem_html;
  5196. }
  5197. return $val;
  5198. }
  5199. /*
  5200. * Style the Jetpack user column
  5201. */
  5202. function jetpack_user_col_style() {
  5203. global $current_screen;
  5204. if ( ! empty( $current_screen->base ) && 'users' == $current_screen->base ) { ?>
  5205. <style>
  5206. .fixed .column-user_jetpack {
  5207. width: 21px;
  5208. }
  5209. .jp-emblem-user-admin path {
  5210. fill: #8cc258;
  5211. }
  5212. </style>
  5213. <?php }
  5214. }
  5215. }