Completed
Push — master-stable ( 1c78dd...390e6d )
by
unknown
14:06
created

class.jetpack.php (18 issues)

Upgrade to new PHP Analysis Engine

These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more

1
<?php
2
3
/*
4
Options:
5
jetpack_options (array)
6
	An array of options.
7
	@see Jetpack_Options::get_option_names()
8
9
jetpack_register (string)
10
	Temporary verification secrets.
11
12
jetpack_activated (int)
13
	1: the plugin was activated normally
14
	2: the plugin was activated on this site because of a network-wide activation
15
	3: the plugin was auto-installed
16
	4: the plugin was manually disconnected (but is still installed)
17
18
jetpack_active_modules (array)
19
	Array of active module slugs.
20
21
jetpack_do_activate (bool)
22
	Flag for "activating" the plugin on sites where the activation hook never fired (auto-installs)
23
*/
24
25
class Jetpack {
26
	public $xmlrpc_server = null;
27
28
	private $xmlrpc_verification = null;
29
30
	public $HTTP_RAW_POST_DATA = null; // copy of $GLOBALS['HTTP_RAW_POST_DATA']
31
32
	/**
33
	 * @var array The handles of styles that are concatenated into jetpack.css
34
	 */
35
	public $concatenated_style_handles = array(
36
		'jetpack-carousel',
37
		'grunion.css',
38
		'the-neverending-homepage',
39
		'jetpack_likes',
40
		'jetpack_related-posts',
41
		'sharedaddy',
42
		'jetpack-slideshow',
43
		'presentations',
44
		'jetpack-subscriptions',
45
		'tiled-gallery',
46
		'widget-conditions',
47
		'jetpack_display_posts_widget',
48
		'gravatar-profile-widget',
49
		'widget-grid-and-list',
50
		'jetpack-widgets',
51
		'goodreads-widget',
52
	);
53
54
	public $plugins_to_deactivate = array(
55
		'stats'               => array( 'stats/stats.php', 'WordPress.com Stats' ),
56
		'shortlinks'          => array( 'stats/stats.php', 'WordPress.com Stats' ),
57
		'sharedaddy'          => array( 'sharedaddy/sharedaddy.php', 'Sharedaddy' ),
58
		'twitter-widget'      => array( 'wickett-twitter-widget/wickett-twitter-widget.php', 'Wickett Twitter Widget' ),
59
		'after-the-deadline'  => array( 'after-the-deadline/after-the-deadline.php', 'After The Deadline' ),
60
		'contact-form'        => array( 'grunion-contact-form/grunion-contact-form.php', 'Grunion Contact Form' ),
61
		'contact-form'        => array( 'mullet/mullet-contact-form.php', 'Mullet Contact Form' ),
62
		'custom-css'          => array( 'safecss/safecss.php', 'WordPress.com Custom CSS' ),
63
		'random-redirect'     => array( 'random-redirect/random-redirect.php', 'Random Redirect' ),
64
		'videopress'          => array( 'video/video.php', 'VideoPress' ),
65
		'widget-visibility'   => array( 'jetpack-widget-visibility/widget-visibility.php', 'Jetpack Widget Visibility' ),
66
		'widget-visibility'   => array( 'widget-visibility-without-jetpack/widget-visibility-without-jetpack.php', 'Widget Visibility Without Jetpack' ),
67
		'sharedaddy'          => array( 'jetpack-sharing/sharedaddy.php', 'Jetpack Sharing' ),
68
		'omnisearch'          => array( 'jetpack-omnisearch/omnisearch.php', 'Jetpack Omnisearch' ),
69
		'gravatar-hovercards' => array( 'jetpack-gravatar-hovercards/gravatar-hovercards.php', 'Jetpack Gravatar Hovercards' ),
70
		'latex'               => array( 'wp-latex/wp-latex.php', 'WP LaTeX' )
71
	);
72
73
	public $capability_translations = array(
74
		'administrator' => 'manage_options',
75
		'editor'        => 'edit_others_posts',
76
		'author'        => 'publish_posts',
77
		'contributor'   => 'edit_posts',
78
		'subscriber'    => 'read',
79
	);
80
81
	/**
82
	 * Map of modules that have conflicts with plugins and should not be auto-activated
83
	 * if the plugins are active.  Used by filter_default_modules
84
	 *
85
	 * Plugin Authors: If you'd like to prevent a single module from auto-activating,
86
	 * change `module-slug` and add this to your plugin:
87
	 *
88
	 * add_filter( 'jetpack_get_default_modules', 'my_jetpack_get_default_modules' );
89
	 * function my_jetpack_get_default_modules( $modules ) {
90
	 *     return array_diff( $modules, array( 'module-slug' ) );
91
	 * }
92
	 *
93
	 * @var array
94
	 */
95
	private $conflicting_plugins = array(
96
		'comments'          => array(
97
			'Intense Debate'                    => 'intensedebate/intensedebate.php',
98
			'Disqus'                            => 'disqus-comment-system/disqus.php',
99
			'Livefyre'                          => 'livefyre-comments/livefyre.php',
100
			'Comments Evolved for WordPress'    => 'gplus-comments/comments-evolved.php',
101
			'Google+ Comments'                  => 'google-plus-comments/google-plus-comments.php',
102
			'WP-SpamShield Anti-Spam'           => 'wp-spamshield/wp-spamshield.php',
103
		),
104
		'contact-form'      => array(
105
			'Contact Form 7'                    => 'contact-form-7/wp-contact-form-7.php',
106
			'Gravity Forms'                     => 'gravityforms/gravityforms.php',
107
			'Contact Form Plugin'               => 'contact-form-plugin/contact_form.php',
108
			'Easy Contact Forms'                => 'easy-contact-forms/easy-contact-forms.php',
109
			'Fast Secure Contact Form'          => 'si-contact-form/si-contact-form.php',
110
		),
111
		'minileven'         => array(
112
			'WPtouch'                           => 'wptouch/wptouch.php',
113
		),
114
		'latex'             => array(
115
			'LaTeX for WordPress'               => 'latex/latex.php',
116
			'Youngwhans Simple Latex'           => 'youngwhans-simple-latex/yw-latex.php',
117
			'Easy WP LaTeX'                     => 'easy-wp-latex-lite/easy-wp-latex-lite.php',
118
			'MathJax-LaTeX'                     => 'mathjax-latex/mathjax-latex.php',
119
			'Enable Latex'                      => 'enable-latex/enable-latex.php',
120
			'WP QuickLaTeX'                     => 'wp-quicklatex/wp-quicklatex.php',
121
		),
122
		'protect'           => array(
123
			'Limit Login Attempts'              => 'limit-login-attempts/limit-login-attempts.php',
124
			'Captcha'                           => 'captcha/captcha.php',
125
			'Brute Force Login Protection'      => 'brute-force-login-protection/brute-force-login-protection.php',
126
			'Login Security Solution'           => 'login-security-solution/login-security-solution.php',
127
			'WPSecureOps Brute Force Protect'   => 'wpsecureops-bruteforce-protect/wpsecureops-bruteforce-protect.php',
128
			'BulletProof Security'              => 'bulletproof-security/bulletproof-security.php',
129
			'SiteGuard WP Plugin'               => 'siteguard/siteguard.php',
130
			'Security-protection'               => 'security-protection/security-protection.php',
131
			'Login Security'                    => 'login-security/login-security.php',
132
			'Botnet Attack Blocker'             => 'botnet-attack-blocker/botnet-attack-blocker.php',
133
			'Wordfence Security'                => 'wordfence/wordfence.php',
134
			'All In One WP Security & Firewall' => 'all-in-one-wp-security-and-firewall/wp-security.php',
135
			'iThemes Security'                  => 'better-wp-security/better-wp-security.php',
136
		),
137
		'random-redirect'   => array(
138
			'Random Redirect 2'                 => 'random-redirect-2/random-redirect.php',
139
		),
140
		'related-posts'     => array(
141
			'YARPP'                             => 'yet-another-related-posts-plugin/yarpp.php',
142
			'WordPress Related Posts'           => 'wordpress-23-related-posts-plugin/wp_related_posts.php',
143
			'nrelate Related Content'           => 'nrelate-related-content/nrelate-related.php',
144
			'Contextual Related Posts'          => 'contextual-related-posts/contextual-related-posts.php',
145
			'Related Posts for WordPress'       => 'microkids-related-posts/microkids-related-posts.php',
146
			'outbrain'                          => 'outbrain/outbrain.php',
147
			'Shareaholic'                       => 'shareaholic/shareaholic.php',
148
			'Sexybookmarks'                     => 'sexybookmarks/shareaholic.php',
149
		),
150
		'sharedaddy'        => array(
151
			'AddThis'                           => 'addthis/addthis_social_widget.php',
152
			'Add To Any'                        => 'add-to-any/add-to-any.php',
153
			'ShareThis'                         => 'share-this/sharethis.php',
154
			'Shareaholic'                       => 'shareaholic/shareaholic.php',
155
		),
156
		'verification-tools' => array(
157
			'WordPress SEO by Yoast'            => 'wordpress-seo/wp-seo.php',
158
			'WordPress SEO Premium by Yoast'    => 'wordpress-seo-premium/wp-seo-premium.php',
159
			'All in One SEO Pack'               => 'all-in-one-seo-pack/all_in_one_seo_pack.php',
160
		),
161
		'widget-visibility' => array(
162
			'Widget Logic'                      => 'widget-logic/widget_logic.php',
163
			'Dynamic Widgets'                   => 'dynamic-widgets/dynamic-widgets.php',
164
		),
165
	);
166
167
	/**
168
	 * Plugins for which we turn off our Facebook OG Tags implementation.
169
	 *
170
	 * Note: WordPress SEO by Yoast and WordPress SEO Premium by Yoast automatically deactivate
171
	 * Jetpack's Open Graph tags via filter when their Social Meta modules are active.
172
	 *
173
	 * Plugin authors: If you'd like to prevent Jetpack's Open Graph tag generation in your plugin, you can do so via this filter:
174
	 * add_filter( 'jetpack_enable_open_graph', '__return_false' );
175
	 */
176
	private $open_graph_conflicting_plugins = array(
177
		'2-click-socialmedia-buttons/2-click-socialmedia-buttons.php',
178
		                                                         // 2 Click Social Media Buttons
179
		'add-link-to-facebook/add-link-to-facebook.php',         // Add Link to Facebook
180
		'add-meta-tags/add-meta-tags.php',                       // Add Meta Tags
181
		'easy-facebook-share-thumbnails/esft.php',               // Easy Facebook Share Thumbnail
182
		'facebook/facebook.php',                                 // Facebook (official plugin)
183
		'facebook-awd/AWD_facebook.php',                         // Facebook AWD All in one
184
		'facebook-featured-image-and-open-graph-meta-tags/fb-featured-image.php',
185
		                                                         // Facebook Featured Image & OG Meta Tags
186
		'facebook-meta-tags/facebook-metatags.php',              // Facebook Meta Tags
187
		'wonderm00ns-simple-facebook-open-graph-tags/wonderm00n-open-graph.php',
188
		                                                         // Facebook Open Graph Meta Tags for WordPress
189
		'facebook-revised-open-graph-meta-tag/index.php',        // Facebook Revised Open Graph Meta Tag
190
		'facebook-thumb-fixer/_facebook-thumb-fixer.php',        // Facebook Thumb Fixer
191
		'facebook-and-digg-thumbnail-generator/facebook-and-digg-thumbnail-generator.php',
192
		                                                         // Fedmich's Facebook Open Graph Meta
193
		'header-footer/plugin.php',                              // Header and Footer
194
		'network-publisher/networkpub.php',                      // Network Publisher
195
		'nextgen-facebook/nextgen-facebook.php',                 // NextGEN Facebook OG
196
		'social-networks-auto-poster-facebook-twitter-g/NextScripts_SNAP.php',
197
		                                                         // NextScripts SNAP
198
		'opengraph/opengraph.php',                               // Open Graph
199
		'open-graph-protocol-framework/open-graph-protocol-framework.php',
200
		                                                         // Open Graph Protocol Framework
201
		'seo-facebook-comments/seofacebook.php',                 // SEO Facebook Comments
202
		'seo-ultimate/seo-ultimate.php',                         // SEO Ultimate
203
		'sexybookmarks/sexy-bookmarks.php',                      // Shareaholic
204
		'shareaholic/sexy-bookmarks.php',                        // Shareaholic
205
		'sharepress/sharepress.php',                             // SharePress
206
		'simple-facebook-connect/sfc.php',                       // Simple Facebook Connect
207
		'social-discussions/social-discussions.php',             // Social Discussions
208
		'social-sharing-toolkit/social_sharing_toolkit.php',     // Social Sharing Toolkit
209
		'socialize/socialize.php',                               // Socialize
210
		'only-tweet-like-share-and-google-1/tweet-like-plusone.php',
211
		                                                         // Tweet, Like, Google +1 and Share
212
		'wordbooker/wordbooker.php',                             // Wordbooker
213
		'wpsso/wpsso.php',                                       // WordPress Social Sharing Optimization
214
		'wp-caregiver/wp-caregiver.php',                         // WP Caregiver
215
		'wp-facebook-like-send-open-graph-meta/wp-facebook-like-send-open-graph-meta.php',
216
		                                                         // WP Facebook Like Send & Open Graph Meta
217
		'wp-facebook-open-graph-protocol/wp-facebook-ogp.php',   // WP Facebook Open Graph protocol
218
		'wp-ogp/wp-ogp.php',                                     // WP-OGP
219
		'zoltonorg-social-plugin/zosp.php',                      // Zolton.org Social Plugin
220
		'wp-fb-share-like-button/wp_fb_share-like_widget.php'    // WP Facebook Like Button
221
	);
222
223
	/**
224
	 * Plugins for which we turn off our Twitter Cards Tags implementation.
225
	 */
226
	private $twitter_cards_conflicting_plugins = array(
227
	//	'twitter/twitter.php',                       // The official one handles this on its own.
228
	//	                                             // https://github.com/twitter/wordpress/blob/master/src/Twitter/WordPress/Cards/Compatibility.php
229
		'eewee-twitter-card/index.php',              // Eewee Twitter Card
230
		'ig-twitter-cards/ig-twitter-cards.php',     // IG:Twitter Cards
231
		'jm-twitter-cards/jm-twitter-cards.php',     // JM Twitter Cards
232
		'kevinjohn-gallagher-pure-web-brilliants-social-graph-twitter-cards-extention/kevinjohn_gallagher___social_graph_twitter_output.php',
233
		                                             // Pure Web Brilliant's Social Graph Twitter Cards Extension
234
		'twitter-cards/twitter-cards.php',           // Twitter Cards
235
		'twitter-cards-meta/twitter-cards-meta.php', // Twitter Cards Meta
236
		'wp-twitter-cards/twitter_cards.php',        // WP Twitter Cards
237
	);
238
239
	/**
240
	 * Message to display in admin_notice
241
	 * @var string
242
	 */
243
	public $message = '';
244
245
	/**
246
	 * Error to display in admin_notice
247
	 * @var string
248
	 */
249
	public $error = '';
250
251
	/**
252
	 * Modules that need more privacy description.
253
	 * @var string
254
	 */
255
	public $privacy_checks = '';
256
257
	/**
258
	 * Stats to record once the page loads
259
	 *
260
	 * @var array
261
	 */
262
	public $stats = array();
263
264
	/**
265
	 * Allows us to build a temporary security report
266
	 *
267
	 * @var array
268
	 */
269
	static $security_report = array();
270
271
	/**
272
	 * Jetpack_Sync object
273
	 */
274
	public $sync;
275
276
	/**
277
	 * Verified data for JSON authorization request
278
	 */
279
	public $json_api_authorization_request = array();
280
281
	/**
282
	 * Holds the singleton instance of this class
283
	 * @since 2.3.3
284
	 * @var Jetpack
285
	 */
286
	static $instance = false;
287
288
	/**
289
	 * Singleton
290
	 * @static
291
	 */
292
	public static function init() {
293
		if ( ! self::$instance ) {
294
			if ( did_action( 'plugins_loaded' ) )
295
				self::plugin_textdomain();
296
			else
297
				add_action( 'plugins_loaded', array( __CLASS__, 'plugin_textdomain' ), 99 );
298
299
			self::$instance = new Jetpack;
300
301
			self::$instance->plugin_upgrade();
302
303
			add_action( 'init', array( __CLASS__, 'perform_security_reporting' ) );
304
305
		}
306
307
		return self::$instance;
308
	}
309
310
	/**
311
	 * Must never be called statically
312
	 */
313
	function plugin_upgrade() {
314
		// Upgrade: 1.1 -> 1.2
315
		if ( get_option( 'jetpack_id' ) ) {
316
			// Move individual jetpack options to single array of options
317
			$options = array();
318
			foreach ( Jetpack_Options::get_option_names() as $option ) {
319
				if ( false !== $value = get_option( "jetpack_$option" ) ) {
320
					$options[$option] = $value;
321
				}
322
			}
323
324
			if ( $options ) {
325
				Jetpack_Options::update_options( $options );
326
327
				foreach ( array_keys( $options ) as $option ) {
328
					delete_option( "jetpack_$option" );
329
				}
330
			}
331
332
			// Add missing version and old_version options
333 View Code Duplication
			if ( ! $version = Jetpack_Options::get_option( 'version' ) ) {
334
				$version = $old_version = '1.1:' . time();
335
				/**
336
				 * Fires on update, before bumping version numbers up to a new version.
337
				 *
338
				 * @since 3.4.0
339
				 *
340
				 * @param string $version Jetpack version number.
341
				 * @param bool false Does an old version exist. Default is false.
342
				 */
343
				do_action( 'updating_jetpack_version', $version, false );
344
				Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
345
			}
346
		}
347
348
		// Upgrade from a single user token to a user_id-indexed array and a master_user ID
349
		if ( ! Jetpack_Options::get_option( 'user_tokens' ) ) {
350
			if ( $user_token = Jetpack_Options::get_option( 'user_token' ) ) {
351
				$token_parts = explode( '.', $user_token );
352
				if ( isset( $token_parts[2] ) ) {
353
					$master_user = $token_parts[2];
354
					$user_tokens = array( $master_user => $user_token );
355
					Jetpack_Options::update_options( compact( 'master_user', 'user_tokens' ) );
356
					Jetpack_Options::delete_option( 'user_token' );
357
				} else {
358
					// @todo: is this even possible?
359
					trigger_error( sprintf( 'Jetpack::plugin_upgrade found no user_id in user_token "%s"', $user_token ), E_USER_WARNING );
360
				}
361
			}
362
		}
363
364
		// Clean up legacy G+ Authorship data.
365
		if ( get_option( 'gplus_authors' ) ) {
366
			delete_option( 'gplus_authors' );
367
			delete_option( 'hide_gplus' );
368
			delete_metadata( 'post', 0, 'gplus_authorship_disabled', null, true );
369
		}
370
371
		if ( ! get_option( 'jetpack_private_options' ) ) {
372
			$jetpack_options = get_option( 'jetpack_options', array() );
373
			foreach( Jetpack_Options::get_option_names( 'private' ) as $option_name ) {
374
				if ( isset( $jetpack_options[ $option_name ] ) ) {
375
					Jetpack_Options::update_option( $option_name, $jetpack_options[ $option_name ] );
376
					unset( $jetpack_options[ $option_name ] );
377
				}
378
			}
379
			update_option( 'jetpack_options', $jetpack_options );
380
		}
381
382
		if ( Jetpack::is_active() ) {
383
			list( $version ) = explode( ':', Jetpack_Options::get_option( 'version' ) );
384
			if ( JETPACK__VERSION != $version ) {
385
				add_action( 'init', array( __CLASS__, 'activate_new_modules' ) );
386
				/**
387
				 * Fires when synchronizing all registered options and constants.
388
				 *
389
				 * @since 3.3.0
390
				 */
391
				do_action( 'jetpack_sync_all_registered_options' );
392
			}
393
			//if Jetpack is connected check if jetpack_unique_connection exists and if not then set it
394
			$jetpack_unique_connection = get_option( 'jetpack_unique_connection' );
395
			$is_unique_connection = $jetpack_unique_connection && array_key_exists( 'version', $jetpack_unique_connection );
396
			if ( ! $is_unique_connection ) {
397
				$jetpack_unique_connection = array(
398
					'connected'     => 1,
399
					'disconnected'  => -1,
400
					'version'       => '3.6.1'
401
				);
402
				update_option( 'jetpack_unique_connection', $jetpack_unique_connection );
403
			}
404
		}
405
406
		if ( get_option( 'jetpack_json_api_full_management' ) ) {
407
			delete_option( 'jetpack_json_api_full_management' );
408
			self::activate_manage();
409
		}
410
411
	}
412
413
	static function activate_manage( ) {
414
415
		if ( did_action( 'init' ) || current_filter() == 'init' ) {
416
			self::activate_module( 'manage', false, false );
417
		} else if ( !  has_action( 'init' , array( __CLASS__, 'activate_manage' ) ) ) {
418
			add_action( 'init', array( __CLASS__, 'activate_manage' ) );
419
		}
420
421
	}
422
423
	/**
424
	 * Constructor.  Initializes WordPress hooks
425
	 */
426
	private function __construct() {
427
		/*
428
		 * Check for and alert any deprecated hooks
429
		 */
430
		add_action( 'init', array( $this, 'deprecated_hooks' ) );
431
432
		/*
433
		 * Do things that should run even in the network admin
434
		 * here, before we potentially fail out.
435
		 */
436
		add_filter( 'jetpack_require_lib_dir', array( $this, 'require_lib_dir' ) );
437
438
		/**
439
		 * We need sync object even in Multisite mode
440
		 */
441
		$this->sync = new Jetpack_Sync;
442
443
		/**
444
		 * Trigger a wp_version sync when updating WP versions
445
		 **/
446
		add_action( 'upgrader_process_complete', array( 'Jetpack', 'update_get_wp_version' ), 10, 2 );
447
		$this->sync->mock_option( 'wp_version', array( 'Jetpack', 'get_wp_version' ) );
448
449
		add_action( 'init', array( $this, 'sync_update_data') );
450
451
		/*
452
		 * Load things that should only be in Network Admin.
453
		 *
454
		 * For now blow away everything else until a more full
455
		 * understanding of what is needed at the network level is
456
		 * available
457
		 */
458
		if( is_multisite() ) {
459
			Jetpack_Network::init();
460
461
			// Only sync this info if we are on a multi site
462
			// @since  3.7
463
			$this->sync->mock_option( 'network_name', array( 'Jetpack', 'network_name' ) );
464
			$this->sync->mock_option( 'network_allow_new_registrations', array( 'Jetpack', 'network_allow_new_registrations' ) );
465
			$this->sync->mock_option( 'network_add_new_users', array( 'Jetpack', 'network_add_new_users' ) );
466
			$this->sync->mock_option( 'network_site_upload_space', array( 'Jetpack', 'network_site_upload_space' ) );
467
			$this->sync->mock_option( 'network_upload_file_types', array( 'Jetpack', 'network_upload_file_types' ) );
468
			$this->sync->mock_option( 'network_enable_administration_menus', array( 'Jetpack', 'network_enable_administration_menus' ) );
469
470
			if( is_network_admin() ) {
471
				// Sync network site data if it is updated or not.
472
				add_action( 'update_wpmu_options', array( $this, 'update_jetpack_network_settings' ) );
473
				return; // End here to prevent single site actions from firing
474
			}
475
		}
476
477
478
		$theme_slug = get_option( 'stylesheet' );
479
480
481
		// Modules should do Jetpack_Sync::sync_options( __FILE__, $option, ... ); instead
482
		// We access the "internal" method here only because the Jetpack object isn't instantiated yet
483
		$this->sync->options(
484
			JETPACK__PLUGIN_DIR . 'jetpack.php',
485
			'home',
486
			'siteurl',
487
			'blogname',
488
			'gmt_offset',
489
			'timezone_string',
490
			'security_report',
491
			'stylesheet',
492
			"theme_mods_{$theme_slug}",
493
			'jetpack_sync_non_public_post_stati',
494
			'jetpack_options',
495
			'site_icon' // (int) - ID of core's Site Icon attachment ID
496
		);
497
498
		foreach( Jetpack_Options::get_option_names( 'non-compact' ) as $option ) {
499
			$this->sync->options( __FILE__, 'jetpack_' . $option );
500
		}
501
502
		/**
503
		 * Sometimes you want to sync data to .com without adding options to .org sites.
504
		 * The mock option allows you to do just that.
505
		 */
506
		$this->sync->mock_option( 'is_main_network',   array( $this, 'is_main_network_option' ) );
507
		$this->sync->mock_option( 'is_multi_site', array( $this, 'is_multisite' ) );
508
		$this->sync->mock_option( 'main_network_site', array( $this, 'jetpack_main_network_site_option' ) );
509
		$this->sync->mock_option( 'single_user_site', array( 'Jetpack', 'is_single_user_site' ) );
510
		$this->sync->mock_option( 'stat_data', array( $this, 'get_stat_data' ) );
511
512
		$this->sync->mock_option( 'has_file_system_write_access', array( 'Jetpack', 'file_system_write_access' ) );
513
		$this->sync->mock_option( 'is_version_controlled', array( 'Jetpack', 'is_version_controlled' ) );
514
		$this->sync->mock_option( 'max_upload_size', 'wp_max_upload_size' );
515
		$this->sync->mock_option( 'content_width', array( 'Jetpack', 'get_content_width' ) );
516
517
		/**
518
		 * Trigger an update to the main_network_site when we update the blogname of a site.
519
		 *
520
		 */
521
		add_action( 'update_option_siteurl', array( $this, 'update_jetpack_main_network_site_option' ) );
522
523
		add_action( 'update_option', array( $this, 'log_settings_change' ), 10, 3 );
524
525
		// Update the settings everytime the we register a new user to the site or we delete a user.
526
		add_action( 'user_register', array( $this, 'is_single_user_site_invalidate' ) );
527
		add_action( 'deleted_user', array( $this, 'is_single_user_site_invalidate' ) );
528
529
		// Unlink user before deleting the user from .com
530
		add_action( 'deleted_user', array( $this, 'unlink_user' ), 10, 1 );
531
		add_action( 'remove_user_from_blog', array( $this, 'unlink_user' ), 10, 1 );
532
533
		if ( defined( 'XMLRPC_REQUEST' ) && XMLRPC_REQUEST && isset( $_GET['for'] ) && 'jetpack' == $_GET['for'] ) {
534
			@ini_set( 'display_errors', false ); // Display errors can cause the XML to be not well formed.
535
536
			require_once JETPACK__PLUGIN_DIR . 'class.jetpack-xmlrpc-server.php';
537
			$this->xmlrpc_server = new Jetpack_XMLRPC_Server();
538
539
			$this->require_jetpack_authentication();
540
541
			if ( Jetpack::is_active() ) {
542
				// Hack to preserve $HTTP_RAW_POST_DATA
543
				add_filter( 'xmlrpc_methods', array( $this, 'xmlrpc_methods' ) );
544
545
				$signed = $this->verify_xml_rpc_signature();
546
				if ( $signed && ! is_wp_error( $signed ) ) {
547
					// The actual API methods.
548
					add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'xmlrpc_methods' ) );
549
				} else {
550
					add_filter( 'xmlrpc_methods', '__return_empty_array' );
551
				}
552
			} else {
553
				// The bootstrap API methods.
554
				add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'bootstrap_xmlrpc_methods' ) );
555
			}
556
557
			// Now that no one can authenticate, and we're whitelisting all XML-RPC methods, force enable_xmlrpc on.
558
			add_filter( 'pre_option_enable_xmlrpc', '__return_true' );
559
		} elseif ( is_admin() && isset( $_POST['action'] ) && 'jetpack_upload_file' == $_POST['action'] ) {
560
			$this->require_jetpack_authentication();
561
			$this->add_remote_request_handlers();
562
		} else {
563
			if ( Jetpack::is_active() ) {
564
				add_action( 'login_form_jetpack_json_api_authorization', array( &$this, 'login_form_json_api_authorization' ) );
565
				add_filter( 'xmlrpc_methods', array( $this, 'public_xmlrpc_methods' ) );
566
			}
567
		}
568
569
		if ( Jetpack::is_active() ) {
570
			Jetpack_Heartbeat::init();
571
		}
572
573
		add_action( 'jetpack_clean_nonces', array( 'Jetpack', 'clean_nonces' ) );
574
		if ( ! wp_next_scheduled( 'jetpack_clean_nonces' ) ) {
575
			wp_schedule_event( time(), 'hourly', 'jetpack_clean_nonces' );
576
		}
577
578
		add_filter( 'xmlrpc_blog_options', array( $this, 'xmlrpc_options' ) );
579
580
		add_action( 'admin_init', array( $this, 'admin_init' ) );
581
		add_action( 'admin_init', array( $this, 'dismiss_jetpack_notice' ) );
582
583
		add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
584
585
		add_action( 'wp_dashboard_setup', array( $this, 'wp_dashboard_setup' ) );
586
		// Filter the dashboard meta box order to swap the new one in in place of the old one.
587
		add_filter( 'get_user_option_meta-box-order_dashboard', array( $this, 'get_user_option_meta_box_order_dashboard' ) );
588
589
		add_action( 'wp_ajax_jetpack-sync-reindex-trigger', array( $this, 'sync_reindex_trigger' ) );
590
		add_action( 'wp_ajax_jetpack-sync-reindex-status', array( $this, 'sync_reindex_status' ) );
591
592
		// Jump Start AJAX callback function
593
		add_action( 'wp_ajax_jetpack_jumpstart_ajax',  array( $this, 'jetpack_jumpstart_ajax_callback' ) );
594
		add_action( 'update_option', array( $this, 'jumpstart_has_updated_module_option' ) );
595
596
		// Identity Crisis AJAX callback function
597
		add_action( 'wp_ajax_jetpack_resolve_identity_crisis', array( $this, 'resolve_identity_crisis_ajax_callback' ) );
598
599
		// JITM AJAX callback function
600
		add_action( 'wp_ajax_jitm_ajax',  array( $this, 'jetpack_jitm_ajax_callback' ) );
601
602
		add_action( 'wp_ajax_jetpack_admin_ajax',          array( $this, 'jetpack_admin_ajax_callback' ) );
603
		add_action( 'wp_ajax_jetpack_admin_ajax_refresh',  array( $this, 'jetpack_admin_ajax_refresh_data' ) );
604
605
		add_action( 'wp_loaded', array( $this, 'register_assets' ) );
606
		add_action( 'wp_enqueue_scripts', array( $this, 'devicepx' ) );
607
		add_action( 'customize_controls_enqueue_scripts', array( $this, 'devicepx' ) );
608
		add_action( 'admin_enqueue_scripts', array( $this, 'devicepx' ) );
609
610
		add_action( 'jetpack_activate_module', array( $this, 'activate_module_actions' ) );
611
612
		add_action( 'plugins_loaded', array( $this, 'extra_oembed_providers' ), 100 );
613
614
		add_action( 'jetpack_notices', array( $this, 'show_development_mode_notice' ) );
615
616
		/**
617
		 * These actions run checks to load additional files.
618
		 * They check for external files or plugins, so they need to run as late as possible.
619
		 */
620
		add_action( 'wp_head', array( $this, 'check_open_graph' ),       1 );
621
		add_action( 'plugins_loaded', array( $this, 'check_twitter_tags' ),     999 );
622
		add_action( 'plugins_loaded', array( $this, 'check_rest_api_compat' ), 1000 );
623
624
		add_filter( 'plugins_url',      array( 'Jetpack', 'maybe_min_asset' ),     1, 3 );
625
		add_filter( 'style_loader_tag', array( 'Jetpack', 'maybe_inline_style' ), 10, 2 );
626
627
		add_filter( 'map_meta_cap', array( $this, 'jetpack_custom_caps' ), 1, 4 );
628
629
		add_filter( 'jetpack_get_default_modules', array( $this, 'filter_default_modules' ) );
630
		add_filter( 'jetpack_get_default_modules', array( $this, 'handle_deprecated_modules' ), 99 );
631
632
		// A filter to control all just in time messages
633
		add_filter( 'jetpack_just_in_time_msgs', '__return_true' );
634
635
		/**
636
		 * This is the hack to concatinate all css files into one.
637
		 * For description and reasoning see the implode_frontend_css method
638
		 *
639
		 * Super late priority so we catch all the registered styles
640
		 */
641
		if( !is_admin() ) {
642
			add_action( 'wp_print_styles', array( $this, 'implode_frontend_css' ), -1 ); // Run first
643
			add_action( 'wp_print_footer_scripts', array( $this, 'implode_frontend_css' ), -1 ); // Run first to trigger before `print_late_styles`
644
		}
645
646
		// Sync Core Icon: Detect changes in Core's Site Icon and make it syncable.
647
		add_action( 'add_option_site_icon',    array( $this, 'jetpack_sync_core_icon' ) );
648
		add_action( 'update_option_site_icon', array( $this, 'jetpack_sync_core_icon' ) );
649
		add_action( 'delete_option_site_icon', array( $this, 'jetpack_sync_core_icon' ) );
650
		add_action( 'jetpack_heartbeat',       array( $this, 'jetpack_sync_core_icon' ) );
651
652
	}
653
654
	/*
655
	 * Make sure any site icon added to core can get
656
	 * synced back to dotcom, so we can display it there.
657
	 */
658
	function jetpack_sync_core_icon() {
659
		if ( function_exists( 'get_site_icon_url' ) ) {
660
			$url = get_site_icon_url();
661
		} else {
662
			return;
663
		}
664
665
		require_once( JETPACK__PLUGIN_DIR . 'modules/site-icon/site-icon-functions.php' );
666
		// If there's a core icon, maybe update the option.  If not, fall back to Jetpack's.
667
		if ( ! empty( $url ) && $url !== jetpack_site_icon_url() ) {
668
			// This is the option that is synced with dotcom
669
			Jetpack_Options::update_option( 'site_icon_url', $url );
670
		} else if ( empty( $url ) && did_action( 'delete_option_site_icon' ) ) {
671
			Jetpack_Options::delete_option( 'site_icon_url' );
672
		}
673
	}
674
675
	function jetpack_admin_ajax_callback() {
676
		// Check for nonce
677 View Code Duplication
		if ( ! isset( $_REQUEST['adminNonce'] ) || ! wp_verify_nonce( $_REQUEST['adminNonce'], 'jetpack-admin-nonce' ) || ! current_user_can( 'jetpack_manage_modules' ) ) {
678
			wp_die( 'permissions check failed' );
679
		}
680
681
		if ( isset( $_REQUEST['toggleModule'] ) && 'nux-toggle-module' == $_REQUEST['toggleModule'] ) {
682
			$slug = $_REQUEST['thisModuleSlug'];
683
684
			if ( ! in_array( $slug, Jetpack::get_available_modules() ) ) {
685
				wp_die( 'That is not a Jetpack module slug' );
686
			}
687
688
			if ( Jetpack::is_module_active( $slug ) ) {
689
				Jetpack::deactivate_module( $slug );
690
			} else {
691
				Jetpack::activate_module( $slug, false, false );
692
			}
693
694
			$modules = Jetpack_Admin::init()->get_modules();
695
			echo json_encode( $modules[ $slug ] );
696
697
			exit;
698
		}
699
700
		wp_die();
701
	}
702
703
	/*
704
	 * Sometimes we need to refresh the data,
705
	 * especially if the page is visited via a 'history'
706
	 * event like back/forward
707
	 */
708
	function jetpack_admin_ajax_refresh_data() {
709
		// Check for nonce
710 View Code Duplication
		if ( ! isset( $_REQUEST['adminNonce'] ) || ! wp_verify_nonce( $_REQUEST['adminNonce'], 'jetpack-admin-nonce' ) ) {
711
			wp_die( 'permissions check failed' );
712
		}
713
714
		if ( isset( $_REQUEST['refreshData'] ) && 'refresh' == $_REQUEST['refreshData'] ) {
715
			$modules = Jetpack_Admin::init()->get_modules();
716
			echo json_encode( $modules );
717
			exit;
718
		}
719
720
		wp_die();
721
	}
722
723
	/**
724
	 * The callback for the Jump Start ajax requests.
725
	 */
726
	function jetpack_jumpstart_ajax_callback() {
727
		// Check for nonce
728
		if ( ! isset( $_REQUEST['jumpstartNonce'] ) || ! wp_verify_nonce( $_REQUEST['jumpstartNonce'], 'jetpack-jumpstart-nonce' ) )
729
			wp_die( 'permissions check failed' );
730
731
		if ( isset( $_REQUEST['jumpStartActivate'] ) && 'jump-start-activate' == $_REQUEST['jumpStartActivate'] ) {
732
			// Update the jumpstart option
733
			if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
734
				Jetpack_Options::update_option( 'jumpstart', 'jumpstart_activated' );
735
			}
736
737
			// Loops through the requested "Jump Start" modules, and activates them.
738
			// Custom 'no_message' state, so that no message will be shown on reload.
739
			$modules = $_REQUEST['jumpstartModSlug'];
740
			$module_slugs = array();
741
			foreach( $modules as $module => $value ) {
742
				$module_slugs[] = $value['module_slug'];
743
			}
744
745
			// Check for possible conflicting plugins
746
			$module_slugs_filtered = $this->filter_default_modules( $module_slugs );
747
748
			foreach ( $module_slugs_filtered as $module_slug ) {
749
				Jetpack::log( 'activate', $module_slug );
750
				Jetpack::activate_module( $module_slug, false, false );
751
				Jetpack::state( 'message', 'no_message' );
752
			}
753
754
			// Set the default sharing buttons and set to display on posts if none have been set.
755
			$sharing_services = get_option( 'sharing-services' );
756
			$sharing_options  = get_option( 'sharing-options' );
757
			if ( empty( $sharing_services['visible'] ) ) {
758
				// Default buttons to set
759
				$visible = array(
760
					'twitter',
761
					'facebook',
762
					'google-plus-1',
763
				);
764
				$hidden = array();
765
766
				// Set some sharing settings
767
				$sharing = new Sharing_Service();
768
				$sharing_options['global'] = array(
769
					'button_style'  => 'icon',
770
					'sharing_label' => $sharing->default_sharing_label,
771
					'open_links'    => 'same',
772
					'show'          => array( 'post' ),
773
					'custom'        => isset( $sharing_options['global']['custom'] ) ? $sharing_options['global']['custom'] : array()
774
				);
775
776
				update_option( 'sharing-options', $sharing_options );
777
778
				// Send a success response so that we can display an error message.
779
				$success = update_option( 'sharing-services', array( 'visible' => $visible, 'hidden' => $hidden ) );
780
				echo json_encode( $success );
781
				exit;
782
			}
783
784
		} elseif ( isset( $_REQUEST['disableJumpStart'] ) && true == $_REQUEST['disableJumpStart'] ) {
785
			// If dismissed, flag the jumpstart option as such.
786
			// Send a success response so that we can display an error message.
787
			if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
788
				$success = Jetpack_Options::update_option( 'jumpstart', 'jumpstart_dismissed' );
789
				echo json_encode( $success );
790
				exit;
791
			}
792
793
		} elseif ( isset( $_REQUEST['jumpStartDeactivate'] ) && 'jump-start-deactivate' == $_REQUEST['jumpStartDeactivate'] ) {
794
795
			// FOR TESTING ONLY
796
			// @todo remove
797
			$modules = (array) $_REQUEST['jumpstartModSlug'];
798
			foreach( $modules as $module => $value ) {
799
				if ( !in_array( $value['module_slug'], Jetpack::get_default_modules() ) ) {
800
					Jetpack::log( 'deactivate', $value['module_slug'] );
801
					Jetpack::deactivate_module( $value['module_slug'] );
802
					Jetpack::state( 'message', 'no_message' );
803
				} else {
804
					Jetpack::log( 'activate', $value['module_slug'] );
805
					Jetpack::activate_module( $value['module_slug'], false, false );
806
					Jetpack::state( 'message', 'no_message' );
807
				}
808
			}
809
810
			Jetpack_Options::update_option( 'jumpstart', 'new_connection' );
811
			echo "reload the page";
812
		}
813
814
		wp_die();
815
	}
816
817
	/**
818
	 * The callback for the JITM ajax requests.
819
	 */
820
	function jetpack_jitm_ajax_callback() {
821
		// Check for nonce
822
		if ( ! isset( $_REQUEST['jitmNonce'] ) || ! wp_verify_nonce( $_REQUEST['jitmNonce'], 'jetpack-jitm-nonce' ) ) {
823
			wp_die( 'Module activation failed due to lack of appropriate permissions' );
824
		}
825
		if ( isset( $_REQUEST['jitmActionToTake'] ) && 'activate' == $_REQUEST['jitmActionToTake'] ) {
826
			$module_slug = $_REQUEST['jitmModule'];
827
			Jetpack::log( 'activate', $module_slug );
828
			Jetpack::activate_module( $module_slug, false, false );
829
			Jetpack::state( 'message', 'no_message' );
830
831
			//A Jetpack module is being activated through a JITM, track it
832
			$this->stat( 'jitm', $module_slug.'-activated-' . JETPACK__VERSION );
833
			$this->do_stats( 'server_side' );
834
835
			wp_send_json_success();
836
		}
837
		if ( isset( $_REQUEST['jitmActionToTake'] ) && 'dismiss' == $_REQUEST['jitmActionToTake'] ) {
838
			// get the hide_jitm options array
839
			$jetpack_hide_jitm = Jetpack_Options::get_option( 'hide_jitm' );
840
			$module_slug = $_REQUEST['jitmModule'];
841
842
			if( ! $jetpack_hide_jitm ) {
843
				$jetpack_hide_jitm = array(
844
					$module_slug => 'hide'
845
				);
846
			} else {
847
				$jetpack_hide_jitm[$module_slug] = 'hide';
848
			}
849
850
			Jetpack_Options::update_option( 'hide_jitm', $jetpack_hide_jitm );
851
852
			//jitm is being dismissed forever, track it
853
			$this->stat( 'jitm', $module_slug.'-dismissed-' . JETPACK__VERSION );
854
			$this->do_stats( 'server_side' );
855
856
			wp_send_json_success();
857
		}
858
	}
859
860
	/**
861
	 * If there are any stats that need to be pushed, but haven't been, push them now.
862
	 */
863
	function __destruct() {
864
		if ( ! empty( $this->stats ) ) {
865
			$this->do_stats( 'server_side' );
866
		}
867
	}
868
869
	function jetpack_custom_caps( $caps, $cap, $user_id, $args ) {
870
		switch( $cap ) {
871
			case 'jetpack_connect' :
872
			case 'jetpack_reconnect' :
873
				if ( Jetpack::is_development_mode() ) {
874
					$caps = array( 'do_not_allow' );
875
					break;
876
				}
877
				/**
878
				 * Pass through. If it's not development mode, these should match disconnect.
879
				 * Let users disconnect if it's development mode, just in case things glitch.
880
				 */
881
			case 'jetpack_disconnect' :
882
				/**
883
				 * In multisite, can individual site admins manage their own connection?
884
				 *
885
				 * Ideally, this should be extracted out to a separate filter in the Jetpack_Network class.
886
				 */
887
				if ( is_multisite() && ! is_super_admin() && is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
888
					if ( ! Jetpack_Network::init()->get_option( 'sub-site-connection-override' ) ) {
889
						/**
890
						 * We need to update the option name -- it's terribly unclear which
891
						 * direction the override goes.
892
						 *
893
						 * @todo: Update the option name to `sub-sites-can-manage-own-connections`
894
						 */
895
						$caps = array( 'do_not_allow' );
896
						break;
897
					}
898
				}
899
900
				$caps = array( 'manage_options' );
901
				break;
902
			case 'jetpack_manage_modules' :
903
			case 'jetpack_activate_modules' :
904
			case 'jetpack_deactivate_modules' :
905
				$caps = array( 'manage_options' );
906
				break;
907
			case 'jetpack_configure_modules' :
908
				$caps = array( 'manage_options' );
909
				break;
910
			case 'jetpack_network_admin_page':
911
			case 'jetpack_network_settings_page':
912
				$caps = array( 'manage_network_plugins' );
913
				break;
914
			case 'jetpack_network_sites_page':
915
				$caps = array( 'manage_sites' );
916
				break;
917
			case 'jetpack_admin_page' :
918
				if ( Jetpack::is_development_mode() ) {
919
					$caps = array( 'manage_options' );
920
					break;
921
				}
922
923
				// Don't ever show to subscribers, but allow access to the page if they're trying to unlink.
924
				if ( ! current_user_can( 'edit_posts' ) ) {
925
					if ( isset( $_GET['redirect'] ) && 'sub-unlink' == $_GET['redirect'] ) {
926
						// We need this in order to unlink the user.
927
						$this->admin_page_load();
928
					}
929
					if ( ! wp_verify_nonce( 'jetpack-unlink' ) ) {
930
						$caps = array( 'do_not_allow' );
931
						break;
932
					}
933
				}
934
935
				if ( ! self::is_active() && ! current_user_can( 'jetpack_connect' ) ) {
936
					$caps = array( 'do_not_allow' );
937
					break;
938
				}
939
				/**
940
				 * Pass through. If it's not development mode, these should match the admin page.
941
				 * Let users disconnect if it's development mode, just in case things glitch.
942
				 */
943
			case 'jetpack_connect_user' :
944
				if ( Jetpack::is_development_mode() ) {
945
					$caps = array( 'do_not_allow' );
946
					break;
947
				}
948
				$caps = array( 'read' );
949
				break;
950
		}
951
		return $caps;
952
	}
953
954
	function require_jetpack_authentication() {
955
		// Don't let anyone authenticate
956
		$_COOKIE = array();
957
		remove_all_filters( 'authenticate' );
958
959
		/**
960
		 * For the moment, remove Limit Login Attempts if its xmlrpc for Jetpack.
961
		 * If Limit Login Attempts is installed as a mu-plugin, it can occasionally
962
		 * generate false-positives.
963
		 */
964
		remove_filter( 'wp_login_failed', 'limit_login_failed' );
965
966
		if ( Jetpack::is_active() ) {
967
			// Allow Jetpack authentication
968
			add_filter( 'authenticate', array( $this, 'authenticate_jetpack' ), 10, 3 );
969
		}
970
	}
971
972
	/**
973
	 * Load language files
974
	 */
975
	public static function plugin_textdomain() {
976
		// Note to self, the third argument must not be hardcoded, to account for relocated folders.
977
		load_plugin_textdomain( 'jetpack', false, dirname( plugin_basename( JETPACK__PLUGIN_FILE ) ) . '/languages/' );
978
	}
979
980
	/**
981
	 * Register assets for use in various modules and the Jetpack admin page.
982
	 *
983
	 * @uses wp_script_is, wp_register_script, plugins_url
984
	 * @action wp_loaded
985
	 * @return null
986
	 */
987
	public function register_assets() {
988
		if ( ! wp_script_is( 'spin', 'registered' ) ) {
989
			wp_register_script( 'spin', plugins_url( '_inc/spin.js', JETPACK__PLUGIN_FILE ), false, '1.3' );
990
		}
991
992
		if ( ! wp_script_is( 'jquery.spin', 'registered' ) ) {
993
			wp_register_script( 'jquery.spin', plugins_url( '_inc/jquery.spin.js', JETPACK__PLUGIN_FILE ) , array( 'jquery', 'spin' ), '1.3' );
994
		}
995
996 View Code Duplication
		if ( ! wp_script_is( 'jetpack-gallery-settings', 'registered' ) ) {
997
			wp_register_script( 'jetpack-gallery-settings', plugins_url( '_inc/gallery-settings.js', JETPACK__PLUGIN_FILE ), array( 'media-views' ), '20121225' );
998
		}
999
1000
		/**
1001
		 * As jetpack_register_genericons is by default fired off a hook,
1002
		 * the hook may have already fired by this point.
1003
		 * So, let's just trigger it manually.
1004
		 */
1005
		require_once( JETPACK__PLUGIN_DIR . '_inc/genericons.php' );
1006
		jetpack_register_genericons();
1007
1008 View Code Duplication
		if ( ! wp_style_is( 'jetpack-icons', 'registered' ) )
1009
			wp_register_style( 'jetpack-icons', plugins_url( 'css/jetpack-icons.min.css', JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION );
1010
	}
1011
1012
	/**
1013
	 * Device Pixels support
1014
	 * This improves the resolution of gravatars and wordpress.com uploads on hi-res and zoomed browsers.
1015
	 */
1016
	function devicepx() {
1017
		if ( Jetpack::is_active() ) {
1018
			wp_enqueue_script( 'devicepx', set_url_scheme( 'http://s0.wp.com/wp-content/js/devicepx-jetpack.js' ), array(), gmdate( 'oW' ), true );
1019
		}
1020
	}
1021
1022
	/*
1023
	 * Returns the location of Jetpack's lib directory. This filter is applied
1024
	 * in require_lib().
1025
	 *
1026
	 * @filter require_lib_dir
1027
	 */
1028
	function require_lib_dir() {
1029
		return JETPACK__PLUGIN_DIR . '_inc/lib';
1030
	}
1031
1032
	/**
1033
	 * Return the network_site_url so that .com knows what network this site is a part of.
1034
	 * @param  bool $option
1035
	 * @return string
1036
	 */
1037
	public function jetpack_main_network_site_option( $option ) {
1038
		return network_site_url();
1039
	}
1040
	/**
1041
	 * Network Name.
1042
	 */
1043
	static function network_name( $option = null ) {
1044
		global $current_site;
1045
		return $current_site->site_name;
1046
	}
1047
	/**
1048
	 * Does the network allow new user and site registrations.
1049
	 * @return string
1050
	 */
1051
	static function network_allow_new_registrations( $option = null ) {
1052
		return ( in_array( get_site_option( 'registration' ), array('none', 'user', 'blog', 'all' ) ) ? get_site_option( 'registration') : 'none' );
1053
	}
1054
	/**
1055
	 * Does the network allow admins to add new users.
1056
	 * @return boolian
1057
	 */
1058
	static function network_add_new_users( $option = null ) {
1059
		return (bool) get_site_option( 'add_new_users' );
1060
	}
1061
	/**
1062
	 * File upload psace left per site in MB.
1063
	 *  -1 means NO LIMIT.
1064
	 * @return number
1065
	 */
1066
	static function network_site_upload_space( $option = null ) {
1067
		// value in MB
1068
		return ( get_site_option( 'upload_space_check_disabled' ) ? -1 : get_space_allowed() );
1069
	}
1070
1071
	/**
1072
	 * Network allowed file types.
1073
	 * @return string
1074
	 */
1075
	static function network_upload_file_types( $option = null ) {
1076
		return get_site_option( 'upload_filetypes', 'jpg jpeg png gif' );
1077
	}
1078
1079
	/**
1080
	 * Maximum file upload size set by the network.
1081
	 * @return number
1082
	 */
1083
	static function network_max_upload_file_size( $option = null ) {
1084
		// value in KB
1085
		return get_site_option( 'fileupload_maxk', 300 );
1086
	}
1087
1088
	/**
1089
	 * Lets us know if a site allows admins to manage the network.
1090
	 * @return array
1091
	 */
1092
	static function network_enable_administration_menus( $option = null ) {
1093
		return get_site_option( 'menu_items' );
1094
	}
1095
1096
	/**
1097
	 * Return whether we are dealing with a multi network setup or not.
1098
	 * The reason we are type casting this is because we want to avoid the situation where
1099
	 * the result is false since when is_main_network_option return false it cases
1100
	 * the rest the get_option( 'jetpack_is_multi_network' ); to return the value that is set in the
1101
	 * database which could be set to anything as opposed to what this function returns.
1102
	 * @param  bool  $option
1103
	 *
1104
	 * @return boolean
1105
	 */
1106
	public function is_main_network_option( $option ) {
1107
		// return '1' or ''
1108
		return (string) (bool) Jetpack::is_multi_network();
1109
	}
1110
1111
	/**
1112
	 * Return true if we are with multi-site or multi-network false if we are dealing with single site.
1113
	 *
1114
	 * @param  string  $option
1115
	 * @return boolean
1116
	 */
1117
	public function is_multisite( $option ) {
1118
		return (string) (bool) is_multisite();
1119
	}
1120
1121
	/**
1122
	 * Implemented since there is no core is multi network function
1123
	 * Right now there is no way to tell if we which network is the dominant network on the system
1124
	 *
1125
	 * @since  3.3
1126
	 * @return boolean
1127
	 */
1128
	public static function is_multi_network() {
1129
		global  $wpdb;
1130
1131
		// if we don't have a multi site setup no need to do any more
1132
		if ( ! is_multisite() ) {
1133
			return false;
1134
		}
1135
1136
		$num_sites = $wpdb->get_var( "SELECT COUNT(*) FROM {$wpdb->site}" );
1137
		if ( $num_sites > 1 ) {
1138
			return true;
1139
		} else {
1140
			return false;
1141
		}
1142
	}
1143
1144
	/**
1145
	 * Trigger an update to the main_network_site when we update the siteurl of a site.
1146
	 * @return null
1147
	 */
1148
	function update_jetpack_main_network_site_option() {
1149
		// do_action( 'add_option_$option', '$option', '$value-of-the-option' );
1150
		/**
1151
		 * Fires when the site URL is updated.
1152
		 * Determines if the site is the main site of a Mulitiste network.
1153
		 *
1154
		 * @since 3.3.0
1155
		 *
1156
		 * @param string jetpack_main_network_site.
1157
		 * @param string network_site_url() Site URL for the "main" site of the current Multisite network.
1158
		 */
1159
		do_action( 'add_option_jetpack_main_network_site', 'jetpack_main_network_site', network_site_url() );
1160
		/**
1161
		 * Fires when the site URL is updated.
1162
		 * Determines if the is part of a multi network.
1163
		 *
1164
		 * @since 3.3.0
1165
		 *
1166
		 * @param string jetpack_is_main_network.
1167
		 * @param bool Jetpack::is_multi_network() Is the site part of a multi network.
1168
		 */
1169
		do_action( 'add_option_jetpack_is_main_network', 'jetpack_is_main_network', (string) (bool) Jetpack::is_multi_network() );
1170
		/**
1171
		 * Fires when the site URL is updated.
1172
		 * Determines if the site is part of a multisite network.
1173
		 *
1174
		 * @since 3.4.0
1175
		 *
1176
		 * @param string jetpack_is_multi_site.
1177
		 * @param bool is_multisite() Is the site part of a mutlisite network.
1178
		 */
1179
		do_action( 'add_option_jetpack_is_multi_site', 'jetpack_is_multi_site', (string) (bool) is_multisite() );
1180
	}
1181
	/**
1182
	 * Triggered after a user updates the network settings via Network Settings Admin Page
1183
	 *
1184
	 */
1185
	function update_jetpack_network_settings() {
1186
		// Only sync this info for the main network site.
1187
		do_action( 'add_option_jetpack_network_name', 'jetpack_network_name', Jetpack::network_name() );
1188
		do_action( 'add_option_jetpack_network_allow_new_registrations', 'jetpack_network_allow_new_registrations', Jetpack::network_allow_new_registrations() );
1189
		do_action( 'add_option_jetpack_network_add_new_users', 'jetpack_network_add_new_users', Jetpack::network_add_new_users() );
1190
		do_action( 'add_option_jetpack_network_site_upload_space', 'jetpack_network_site_upload_space', Jetpack::network_site_upload_space() );
1191
		do_action( 'add_option_jetpack_network_upload_file_types', 'jetpack_network_upload_file_types', Jetpack::network_upload_file_types() );
1192
		do_action( 'add_option_jetpack_network_enable_administration_menus', 'jetpack_network_enable_administration_menus', Jetpack::network_enable_administration_menus() );
1193
1194
	}
1195
1196
	/**
1197
	 * Get back if the current site is single user site.
1198
	 *
1199
	 * @return bool
1200
	 */
1201
	public static function is_single_user_site() {
1202
1203
		$user_query = new WP_User_Query( array(
1204
			'blog_id' => get_current_blog_id(),
1205
			'fields'  => 'ID',
1206
			'number' => 2
1207
		) );
1208
		return 1 === (int) $user_query->get_total();
1209
	}
1210
1211
	/**
1212
	 * Returns true if the site has file write access false otherwise.
1213
	 * @return string ( '1' | '0' )
1214
	 **/
1215
	public static function file_system_write_access() {
1216
		if ( ! function_exists( 'get_filesystem_method' ) ) {
1217
			require_once( ABSPATH . 'wp-admin/includes/file.php' );
1218
		}
1219
1220
		require_once( ABSPATH . 'wp-admin/includes/template.php' );
1221
1222
		$filesystem_method = get_filesystem_method();
1223
		if ( $filesystem_method === 'direct' ) {
1224
			return 1;
1225
		}
1226
1227
		ob_start();
1228
		$filesystem_credentials_are_stored = request_filesystem_credentials( self_admin_url() );
1229
		ob_end_clean();
1230
		if ( $filesystem_credentials_are_stored ) {
1231
			return 1;
1232
		}
1233
		return 0;
1234
	}
1235
1236
	/**
1237
	 * Finds out if a site is using a version control system.
1238
	 * @return string ( '1' | '0' )
1239
	 **/
1240
	public static function is_version_controlled() {
1241
1242
		if ( !class_exists( 'WP_Automatic_Updater' ) ) {
1243
			require_once( ABSPATH . 'wp-admin/includes/class-wp-upgrader.php' );
1244
		}
1245
		$updater = new WP_Automatic_Updater();
1246
		$is_version_controlled = strval( $updater->is_vcs_checkout( $context = ABSPATH ) );
1247
		// transients should not be empty
1248
		if ( empty( $is_version_controlled ) ) {
1249
			$is_version_controlled = '0';
1250
		}
1251
		return $is_version_controlled;
1252
	}
1253
	/*
1254
	 * Sync back wp_version
1255
	 */
1256
	public static function get_wp_version() {
1257
		global $wp_version;
1258
		return $wp_version;
1259
	}
1260
	/**
1261
	 * Keeps wp_version in sync with .com when WordPress core updates
1262
	 **/
1263
	public static function update_get_wp_version( $update, $meta_data ) {
1264
		if ( 'update' === $meta_data['action'] && 'core' === $meta_data['type'] ) {
1265
			/** This action is documented in wp-includes/option.php */
1266
			/**
1267
			 * This triggers the sync for the jetpack version
1268
			 * See Jetpack_Sync options method for more info.
1269
			 */
1270
			do_action( 'add_option_jetpack_wp_version', 'jetpack_wp_version', (string) Jetpack::get_wp_version() );
1271
		}
1272
	}
1273
1274
	/**
1275
	 * Triggers a sync of update counts and update details
1276
	 */
1277
	function sync_update_data() {
1278
		// Anytime WordPress saves update data, we'll want to sync update data
1279
		add_action( 'set_site_transient_update_plugins', array( 'Jetpack', 'refresh_update_data' ) );
1280
		add_action( 'set_site_transient_update_themes', array( 'Jetpack', 'refresh_update_data' ) );
1281
		add_action( 'set_site_transient_update_core', array( 'Jetpack', 'refresh_update_data' ) );
1282
		// Anytime a connection to jetpack is made, sync the update data
1283
		add_action( 'jetpack_site_registered', array( 'Jetpack', 'refresh_update_data' ) );
1284
		// Anytime the Jetpack Version changes, sync the the update data
1285
		add_action( 'updating_jetpack_version', array( 'Jetpack', 'refresh_update_data' ) );
1286
1287
		if ( current_user_can( 'update_core' ) && current_user_can( 'update_plugins' ) && current_user_can( 'update_themes' ) ) {
1288
			$this->sync->mock_option( 'updates', array( 'Jetpack', 'get_updates' ) );
1289
		}
1290
1291
		$this->sync->mock_option( 'update_details', array( 'Jetpack', 'get_update_details' ) );
1292
	}
1293
1294
	/**
1295
	 * jetpack_updates is saved in the following schema:
1296
	 *
1297
	 * array (
1298
	 *      'plugins'                       => (int) Number of plugin updates available.
1299
	 *      'themes'                        => (int) Number of theme updates available.
1300
	 *      'wordpress'                     => (int) Number of WordPress core updates available.
1301
	 *      'translations'                  => (int) Number of translation updates available.
1302
	 *      'total'                         => (int) Total of all available updates.
1303
	 *      'wp_update_version'             => (string) The latest available version of WordPress, only present if a WordPress update is needed.
1304
	 * )
1305
	 * @return array
1306
	 */
1307
	public static function get_updates() {
1308
		$update_data = wp_get_update_data();
1309
1310
		// Stores the individual update counts as well as the total count.
1311
		if ( isset( $update_data['counts'] ) ) {
1312
			$updates = $update_data['counts'];
1313
		}
1314
1315
		// If we need to update WordPress core, let's find the latest version number.
1316 View Code Duplication
		if ( ! empty( $updates['wordpress'] ) ) {
1317
			$cur = get_preferred_from_update_core();
1318
			if ( isset( $cur->response ) && 'upgrade' === $cur->response ) {
1319
				$updates['wp_update_version'] = $cur->current;
1320
			}
1321
		}
1322
		return isset( $updates ) ? $updates : array();
1323
	}
1324
1325
	public static function get_update_details() {
1326
		$update_details = array(
1327
			'update_core' => get_site_transient( 'update_core' ),
1328
			'update_plugins' => get_site_transient( 'update_plugins' ),
1329
			'update_themes' => get_site_transient( 'update_themes' ),
1330
		);
1331
		return $update_details;
1332
	}
1333
1334
	public static function refresh_update_data() {
1335
		if ( current_user_can( 'update_core' ) && current_user_can( 'update_plugins' ) && current_user_can( 'update_themes' ) ) {
1336
			/**
1337
			 * Fires whenever the amount of updates needed for a site changes.
1338
			 * Syncs an array that includes the number of theme, plugin, and core updates available, as well as the latest core version available.
1339
			 *
1340
			 * @since 3.7.0
1341
			 *
1342
			 * @param string jetpack_updates
1343
			 * @param array Update counts calculated by Jetpack::get_updates
1344
			 */
1345
			do_action( 'add_option_jetpack_updates', 'jetpack_updates', Jetpack::get_updates() );
1346
		}
1347
		/**
1348
		 * Fires whenever the amount of updates needed for a site changes.
1349
		 * Syncs an array of core, theme, and plugin data, and which of each is out of date
1350
		 *
1351
		 * @since 3.7.0
1352
		 *
1353
		 * @param string jetpack_update_details
1354
		 * @param array Update details calculated by Jetpack::get_update_details
1355
		 */
1356
		do_action( 'add_option_jetpack_update_details', 'jetpack_update_details', Jetpack::get_update_details() );
1357
	}
1358
1359
	/**
1360
	 * Invalides the transient as well as triggers the update of the mock option.
1361
	 *
1362
	 * @return null
1363
	 */
1364
	function is_single_user_site_invalidate() {
1365
		/**
1366
		 * Fires when a user is added or removed from a site.
1367
		 * Determines if the site is a single user site.
1368
		 *
1369
		 * @since 3.4.0
1370
		 *
1371
		 * @param string jetpack_single_user_site.
1372
		 * @param bool Jetpack::is_single_user_site() Is the current site a single user site.
1373
		 */
1374
		do_action( 'update_option_jetpack_single_user_site', 'jetpack_single_user_site', (bool) Jetpack::is_single_user_site() );
1375
	}
1376
1377
	/**
1378
	 * Is Jetpack active?
1379
	 */
1380
	public static function is_active() {
1381
		return (bool) Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
1382
	}
1383
1384
	/**
1385
	 * Is Jetpack in development (offline) mode?
1386
	 */
1387
	public static function is_development_mode() {
1388
		$development_mode = false;
1389
1390
		if ( defined( 'JETPACK_DEV_DEBUG' ) ) {
1391
			$development_mode = JETPACK_DEV_DEBUG;
1392
		}
1393
1394
		elseif ( site_url() && false === strpos( site_url(), '.' ) ) {
1395
			$development_mode = true;
1396
		}
1397
		/**
1398
		 * Filters Jetpack's development mode.
1399
		 *
1400
		 * @see http://jetpack.me/support/development-mode/
1401
		 *
1402
		 * @since 2.2.1
1403
		 *
1404
		 * @param bool $development_mode Is Jetpack's development mode active.
1405
		 */
1406
		return apply_filters( 'jetpack_development_mode', $development_mode );
1407
	}
1408
1409
	/**
1410
	* Get Jetpack development mode notice text and notice class.
1411
	*
1412
	* Mirrors the checks made in Jetpack::is_development_mode
1413
	*
1414
	*/
1415
	public static function show_development_mode_notice() {
1416
		if ( Jetpack::is_development_mode() ) {
1417
			if ( defined( 'JETPACK_DEV_DEBUG' ) && JETPACK_DEV_DEBUG ) {
1418
				$notice = sprintf(
1419
					/* translators: %s is a URL */
1420
					__( 'In <a href="%s" target="_blank">Development Mode</a>, via the JETPACK_DEV_DEBUG constant being defined in wp-config.php or elsewhere.', 'jetpack' ),
1421
					'http://jetpack.me/support/development-mode/'
1422
				);
1423
			} elseif ( site_url() && false === strpos( site_url(), '.' ) ) {
1424
				$notice = sprintf(
1425
					/* translators: %s is a URL */
1426
					__( 'In <a href="%s" target="_blank">Development Mode</a>, via site URL lacking a dot (e.g. http://localhost).', 'jetpack' ),
1427
					'http://jetpack.me/support/development-mode/'
1428
				);
1429
			} else {
1430
				$notice = sprintf(
1431
					/* translators: %s is a URL */
1432
					__( 'In <a href="%s" target="_blank">Development Mode</a>, via the jetpack_development_mode filter.', 'jetpack' ),
1433
					'http://jetpack.me/support/development-mode/'
1434
				);
1435
			}
1436
1437
			echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
1438
		}
1439
1440
		// Throw up a notice if using a development version and as for feedback.
1441
		if ( Jetpack::is_development_version() ) {
1442
			/* translators: %s is a URL */
1443
			$notice = sprintf( __( 'You are currently running a development version of Jetpack. <a href="%s" target="_blank">Submit your feedback</a>', 'jetpack' ), 'https://jetpack.me/contact-support/beta-group/' );
1444
1445
			echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
1446
		}
1447
	}
1448
1449
	/**
1450
	 * Whether Jetpack's version maps to a public release, or a development version.
1451
	 */
1452
	public static function is_development_version() {
1453
		return ! preg_match( '/^\d+(\.\d+)+$/', JETPACK__VERSION );
1454
	}
1455
1456
	/**
1457
	 * Is a given user (or the current user if none is specified) linked to a WordPress.com user?
1458
	 */
1459
	public static function is_user_connected( $user_id = false ) {
1460
		$user_id = false === $user_id ? get_current_user_id() : absint( $user_id );
1461
		if ( ! $user_id ) {
1462
			return false;
1463
		}
1464
		return (bool) Jetpack_Data::get_access_token( $user_id );
1465
	}
1466
1467
	/**
1468
	 * Get the wpcom user data of the current|specified connected user.
1469
	 */
1470 View Code Duplication
	public static function get_connected_user_data( $user_id = null ) {
1471
		if ( ! $user_id ) {
1472
			$user_id = get_current_user_id();
1473
		}
1474
		Jetpack::load_xml_rpc_client();
1475
		$xml = new Jetpack_IXR_Client( array(
1476
			'user_id' => $user_id,
1477
		) );
1478
		$xml->query( 'wpcom.getUser' );
1479
		if ( ! $xml->isError() ) {
1480
			return $xml->getResponse();
1481
		}
1482
		return false;
1483
	}
1484
1485
	/**
1486
	 * Get the wpcom email of the current|specified connected user.
1487
	 */
1488 View Code Duplication
	public static function get_connected_user_email( $user_id = null ) {
1489
		if ( ! $user_id ) {
1490
			$user_id = get_current_user_id();
1491
		}
1492
		Jetpack::load_xml_rpc_client();
1493
		$xml = new Jetpack_IXR_Client( array(
1494
			'user_id' => $user_id,
1495
		) );
1496
		$xml->query( 'wpcom.getUserEmail' );
1497
		if ( ! $xml->isError() ) {
1498
			return $xml->getResponse();
1499
		}
1500
		return false;
1501
	}
1502
1503
	/**
1504
	 * Get the wpcom email of the master user.
1505
	 */
1506
	public static function get_master_user_email() {
1507
		$master_user_id = Jetpack_Options::get_option( 'master_user' );
1508
		if ( $master_user_id ) {
1509
			return self::get_connected_user_email( $master_user_id );
1510
		}
1511
		return '';
1512
	}
1513
1514
	function current_user_is_connection_owner() {
1515
		$user_token = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
1516
		return $user_token && is_object( $user_token ) && isset( $user_token->external_user_id ) && get_current_user_id() === $user_token->external_user_id;
1517
	}
1518
1519
	/**
1520
	 * Add any extra oEmbed providers that we know about and use on wpcom for feature parity.
1521
	 */
1522
	function extra_oembed_providers() {
1523
		// Cloudup: https://dev.cloudup.com/#oembed
1524
		wp_oembed_add_provider( 'https://cloudup.com/*' , 'https://cloudup.com/oembed' );
1525
		wp_oembed_add_provider( 'https://me.sh/*', 'https://me.sh/oembed?format=json' );
1526
	}
1527
1528
	/**
1529
	 * Synchronize connected user role changes
1530
	 */
1531
	function user_role_change( $user_id ) {
1532
		if ( Jetpack::is_active() && Jetpack::is_user_connected( $user_id ) ) {
1533
			$current_user_id = get_current_user_id();
1534
			wp_set_current_user( $user_id );
1535
			$role = $this->translate_current_user_to_role();
1536
			$signed_role = $this->sign_role( $role );
1537
			wp_set_current_user( $current_user_id );
1538
1539
			$master_token   = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
1540
			$master_user_id = absint( $master_token->external_user_id );
1541
1542
			if ( ! $master_user_id )
1543
				return; // this shouldn't happen
1544
1545
			Jetpack::xmlrpc_async_call( 'jetpack.updateRole', $user_id, $signed_role );
1546
			//@todo retry on failure
1547
1548
			//try to choose a new master if we're demoting the current one
1549
			if ( $user_id == $master_user_id && 'administrator' != $role ) {
1550
				$query = new WP_User_Query(
1551
					array(
1552
						'fields'  => array( 'id' ),
1553
						'role'    => 'administrator',
1554
						'orderby' => 'id',
1555
						'exclude' => array( $master_user_id ),
1556
					)
1557
				);
1558
				$new_master = false;
1559
				foreach ( $query->results as $result ) {
1560
					$uid = absint( $result->id );
1561
					if ( $uid && Jetpack::is_user_connected( $uid ) ) {
1562
						$new_master = $uid;
1563
						break;
1564
					}
1565
				}
1566
1567
				if ( $new_master ) {
1568
					Jetpack_Options::update_option( 'master_user', $new_master );
1569
				}
1570
				// else disconnect..?
1571
			}
1572
		}
1573
	}
1574
1575
	/**
1576
	 * Loads the currently active modules.
1577
	 */
1578
	public static function load_modules() {
1579
		if ( ! self::is_active() && !self::is_development_mode() ) {
1580
			if ( ! is_multisite() || ! get_site_option( 'jetpack_protect_active' ) ) {
1581
				return;
1582
			}
1583
		}
1584
1585
		$version = Jetpack_Options::get_option( 'version' );
1586 View Code Duplication
		if ( ! $version ) {
1587
			$version = $old_version = JETPACK__VERSION . ':' . time();
1588
			/** This action is documented in class.jetpack.php */
1589
			do_action( 'updating_jetpack_version', $version, false );
1590
			Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
1591
		}
1592
		list( $version ) = explode( ':', $version );
1593
1594
		$modules = array_filter( Jetpack::get_active_modules(), array( 'Jetpack', 'is_module' ) );
1595
1596
		$modules_data = array();
1597
1598
		// Don't load modules that have had "Major" changes since the stored version until they have been deactivated/reactivated through the lint check.
1599
		if ( version_compare( $version, JETPACK__VERSION, '<' ) ) {
1600
			$updated_modules = array();
1601
			foreach ( $modules as $module ) {
1602
				$modules_data[ $module ] = Jetpack::get_module( $module );
1603
				if ( ! isset( $modules_data[ $module ]['changed'] ) ) {
1604
					continue;
1605
				}
1606
1607
				if ( version_compare( $modules_data[ $module ]['changed'], $version, '<=' ) ) {
1608
					continue;
1609
				}
1610
1611
				$updated_modules[] = $module;
1612
			}
1613
1614
			$modules = array_diff( $modules, $updated_modules );
1615
		}
1616
1617
		$is_development_mode = Jetpack::is_development_mode();
1618
1619
		foreach ( $modules as $module ) {
1620
			// If we're in dev mode, disable modules requiring a connection
1621
			if ( $is_development_mode ) {
1622
				// Prime the pump if we need to
1623
				if ( empty( $modules_data[ $module ] ) ) {
1624
					$modules_data[ $module ] = Jetpack::get_module( $module );
1625
				}
1626
				// If the module requires a connection, but we're in local mode, don't include it.
1627
				if ( $modules_data[ $module ]['requires_connection'] ) {
1628
					continue;
1629
				}
1630
			}
1631
1632
			if ( did_action( 'jetpack_module_loaded_' . $module ) ) {
1633
				continue;
1634
			}
1635
1636
			require Jetpack::get_module_path( $module );
1637
			/**
1638
			 * Fires when a specific module is loaded.
1639
			 * The dynamic part of the hook, $module, is the module slug.
1640
			 *
1641
			 * @since 1.1.0
1642
			 */
1643
			do_action( 'jetpack_module_loaded_' . $module );
1644
		}
1645
1646
		/**
1647
		 * Fires when all the modules are loaded.
1648
		 *
1649
		 * @since 1.1.0
1650
		 */
1651
		do_action( 'jetpack_modules_loaded' );
1652
1653
		// Load module-specific code that is needed even when a module isn't active. Loaded here because code contained therein may need actions such as setup_theme.
1654
		if ( Jetpack::is_active() || Jetpack::is_development_mode() )
1655
			require_once( JETPACK__PLUGIN_DIR . 'modules/module-extras.php' );
1656
	}
1657
1658
	/**
1659
	 * Check if Jetpack's REST API compat file should be included
1660
	 * @action plugins_loaded
1661
	 * @return null
1662
	 */
1663
	public function check_rest_api_compat() {
1664
		/**
1665
		 * Filters the list of REST API compat files to be included.
1666
		 *
1667
		 * @since 2.2.5
1668
		 *
1669
		 * @param array $args Array of REST API compat files to include.
1670
		 */
1671
		$_jetpack_rest_api_compat_includes = apply_filters( 'jetpack_rest_api_compat', array() );
1672
1673
		if ( function_exists( 'bbpress' ) )
1674
			$_jetpack_rest_api_compat_includes[] = JETPACK__PLUGIN_DIR . 'class.jetpack-bbpress-json-api-compat.php';
1675
1676
		foreach ( $_jetpack_rest_api_compat_includes as $_jetpack_rest_api_compat_include )
1677
			require_once $_jetpack_rest_api_compat_include;
1678
	}
1679
1680
	/**
1681
	 * Gets all plugins currently active in values, regardless of whether they're
1682
	 * traditionally activated or network activated.
1683
	 *
1684
	 * @todo Store the result in core's object cache maybe?
1685
	 */
1686
	public static function get_active_plugins() {
1687
		$active_plugins = (array) get_option( 'active_plugins', array() );
1688
1689
		if ( is_multisite() ) {
1690
			// Due to legacy code, active_sitewide_plugins stores them in the keys,
1691
			// whereas active_plugins stores them in the values.
1692
			$network_plugins = array_keys( get_site_option( 'active_sitewide_plugins', array() ) );
1693
			if ( $network_plugins ) {
1694
				$active_plugins = array_merge( $active_plugins, $network_plugins );
1695
			}
1696
		}
1697
1698
		sort( $active_plugins );
1699
1700
		return array_unique( $active_plugins );
1701
	}
1702
1703
	/**
1704
	 * Gets and parses additional plugin data to send with the heartbeat data
1705
	 *
1706
	 * @since 3.8.1
1707
	 *
1708
	 * @return array Array of plugin data
1709
	 */
1710
	public static function get_parsed_plugin_data() {
1711
		$all_plugins    = get_plugins();
1712
		$active_plugins = Jetpack::get_active_plugins();
1713
1714
		$plugins = array();
1715
		foreach ( $all_plugins as $path => $plugin_data ) {
1716
			$plugins[ $path ] = array(
1717
					'is_active' => in_array( $path, $active_plugins ),
1718
					'file'      => $path,
1719
					'name'      => $plugin_data['Name'],
1720
					'version'   => $plugin_data['Version'],
1721
					'author'    => $plugin_data['Author'],
1722
			);
1723
		}
1724
1725
		return $plugins;
1726
	}
1727
1728
	/**
1729
	 * Gets and parses theme data to send with the heartbeat data
1730
	 *
1731
	 * @since 3.8.1
1732
	 *
1733
	 * @return array Array of theme data
1734
	 */
1735
	public static function get_parsed_theme_data() {
1736
		$all_themes = wp_get_themes( array( 'allowed' => true ) );
1737
		$header_keys = array( 'Name', 'Author', 'Version', 'ThemeURI', 'AuthorURI', 'Status', 'Tags' );
1738
1739
		$themes = array();
1740
		foreach ( $all_themes as $slug => $theme_data ) {
1741
			$theme_headers = array();
1742
			foreach ( $header_keys as $header_key ) {
1743
				$theme_headers[ $header_key ] = $theme_data->get( $header_key );
1744
			}
1745
1746
			$themes[ $slug ] = array(
1747
					'is_active_theme' => $slug == wp_get_theme()->get_template(),
1748
					'slug' => $slug,
1749
					'theme_root' => $theme_data->get_theme_root_uri(),
1750
					'parent' => $theme_data->parent(),
1751
					'headers' => $theme_headers
1752
			);
1753
		}
1754
1755
		return $themes;
1756
	}
1757
1758
	/**
1759
	 * Checks whether a specific plugin is active.
1760
	 *
1761
	 * We don't want to store these in a static variable, in case
1762
	 * there are switch_to_blog() calls involved.
1763
	 */
1764
	public static function is_plugin_active( $plugin = 'jetpack/jetpack.php' ) {
1765
		return in_array( $plugin, self::get_active_plugins() );
1766
	}
1767
1768
	/**
1769
	 * Check if Jetpack's Open Graph tags should be used.
1770
	 * If certain plugins are active, Jetpack's og tags are suppressed.
1771
	 *
1772
	 * @uses Jetpack::get_active_modules, add_filter, get_option, apply_filters
1773
	 * @action plugins_loaded
1774
	 * @return null
1775
	 */
1776
	public function check_open_graph() {
1777
		if ( in_array( 'publicize', Jetpack::get_active_modules() ) || in_array( 'sharedaddy', Jetpack::get_active_modules() ) ) {
1778
			add_filter( 'jetpack_enable_open_graph', '__return_true', 0 );
1779
		}
1780
1781
		$active_plugins = self::get_active_plugins();
1782
1783
		if ( ! empty( $active_plugins ) ) {
1784
			foreach ( $this->open_graph_conflicting_plugins as $plugin ) {
1785
				if ( in_array( $plugin, $active_plugins ) ) {
1786
					add_filter( 'jetpack_enable_open_graph', '__return_false', 99 );
1787
					break;
1788
				}
1789
			}
1790
		}
1791
1792
		/**
1793
		 * Allow the addition of Open Graph Meta Tags to all pages.
1794
		 *
1795
		 * @since 2.0.3
1796
		 *
1797
		 * @param bool false Should Open Graph Meta tags be added. Default to false.
1798
		 */
1799
		if ( apply_filters( 'jetpack_enable_open_graph', false ) ) {
1800
			require_once JETPACK__PLUGIN_DIR . 'functions.opengraph.php';
1801
		}
1802
	}
1803
1804
	/**
1805
	 * Check if Jetpack's Twitter tags should be used.
1806
	 * If certain plugins are active, Jetpack's twitter tags are suppressed.
1807
	 *
1808
	 * @uses Jetpack::get_active_modules, add_filter, get_option, apply_filters
1809
	 * @action plugins_loaded
1810
	 * @return null
1811
	 */
1812
	public function check_twitter_tags() {
1813
1814
		$active_plugins = self::get_active_plugins();
1815
1816
		if ( ! empty( $active_plugins ) ) {
1817
			foreach ( $this->twitter_cards_conflicting_plugins as $plugin ) {
1818
				if ( in_array( $plugin, $active_plugins ) ) {
1819
					add_filter( 'jetpack_disable_twitter_cards', '__return_true', 99 );
1820
					break;
1821
				}
1822
			}
1823
		}
1824
1825
		/**
1826
		 * Allow Twitter Card Meta tags to be disabled.
1827
		 *
1828
		 * @since 2.6.0
1829
		 *
1830
		 * @param bool true Should Twitter Card Meta tags be disabled. Default to true.
1831
		 */
1832
		if ( apply_filters( 'jetpack_disable_twitter_cards', true ) ) {
1833
			require_once JETPACK__PLUGIN_DIR . 'class.jetpack-twitter-cards.php';
1834
		}
1835
	}
1836
1837
1838
1839
1840
	/*
1841
	 *
1842
	 * Jetpack Security Reports
1843
	 *
1844
	 * Allowed types: login_form, backup, file_scanning, spam
1845
	 *
1846
	 * Args for login_form and spam: 'blocked'=>(int)(optional), 'status'=>(string)(ok, warning, error), 'message'=>(optional, disregarded if status is ok, allowed tags: a, em, strong)
1847
	 *
1848
	 * Args for backup and file_scanning: 'last'=>(timestamp)(optional), 'next'=>(timestamp)(optional), 'status'=>(string)(ok, warning, error), 'message'=>(optional, disregarded if status is ok, allowed tags: a, em, strong)
1849
	 *
1850
	 *
1851
	 * Example code to submit a security report:
1852
	 *
1853
	 *  function akismet_submit_jetpack_security_report() {
1854
	 *  	Jetpack::submit_security_report( 'spam', __FILE__, $args = array( 'blocked' => 138284, status => 'ok' ) );
1855
	 *  }
1856
	 *  add_action( 'jetpack_security_report', 'akismet_submit_jetpack_security_report' );
1857
	 *
1858
	 */
1859
1860
1861
	/**
1862
	 * Calls for security report submissions.
1863
	 *
1864
	 * @return null
1865
	 */
1866
	public static function perform_security_reporting() {
1867
		$no_check_needed = get_site_transient( 'security_report_performed_recently' );
1868
1869
		if ( $no_check_needed ) {
1870
			return;
1871
		}
1872
1873
		/**
1874
		 * Fires before a security report is created.
1875
		 *
1876
		 * @since 3.4.0
1877
		 */
1878
		do_action( 'jetpack_security_report' );
1879
1880
		Jetpack_Options::update_option( 'security_report', self::$security_report );
1881
		set_site_transient( 'security_report_performed_recently', 1, 15 * MINUTE_IN_SECONDS );
1882
	}
1883
1884
	/**
1885
	 * Allows plugins to submit security reports.
1886
 	 *
1887
	 * @param string  $type         Report type (login_form, backup, file_scanning, spam)
1888
	 * @param string  $plugin_file  Plugin __FILE__, so that we can pull plugin data
1889
	 * @param array   $args         See definitions above
1890
	 */
1891
	public static function submit_security_report( $type = '', $plugin_file = '', $args = array() ) {
1892
1893
		if( !doing_action( 'jetpack_security_report' ) ) {
1894
			return new WP_Error( 'not_collecting_report', 'Not currently collecting security reports.  Please use the jetpack_security_report hook.' );
1895
		}
1896
1897
		if( !is_string( $type ) || !is_string( $plugin_file ) ) {
1898
			return new WP_Error( 'invalid_security_report', 'Invalid Security Report' );
1899
		}
1900
1901
		if( !function_exists( 'get_plugin_data' ) ) {
1902
			include( ABSPATH . 'wp-admin/includes/plugin.php' );
1903
		}
1904
1905
		//Get rid of any non-allowed args
1906
		$args = array_intersect_key( $args, array_flip( array( 'blocked', 'last', 'next', 'status', 'message' ) ) );
1907
1908
		$plugin = get_plugin_data( $plugin_file );
1909
1910
		if ( !$plugin['Name'] ) {
1911
			return new WP_Error( 'security_report_missing_plugin_name', 'Invalid Plugin File Provided' );
1912
		}
1913
1914
		// Sanitize everything to make sure we're not syncing something wonky
1915
		$type = sanitize_key( $type );
1916
1917
		$args['plugin'] = $plugin;
1918
1919
		// Cast blocked, last and next as integers.
1920
		// Last and next should be in unix timestamp format
1921
		if ( isset( $args['blocked'] ) ) {
1922
			$args['blocked'] = (int) $args['blocked'];
1923
		}
1924
		if ( isset( $args['last'] ) ) {
1925
			$args['last'] = (int) $args['last'];
1926
		}
1927
		if ( isset( $args['next'] ) ) {
1928
			$args['next'] = (int) $args['next'];
1929
		}
1930
		if ( !in_array( $args['status'], array( 'ok', 'warning', 'error' ) ) ) {
1931
			$args['status'] = 'ok';
1932
		}
1933
		if ( isset( $args['message'] ) ) {
1934
1935
			if( $args['status'] == 'ok' ) {
1936
				unset( $args['message'] );
1937
			}
1938
1939
			$allowed_html = array(
1940
			    'a' => array(
1941
			        'href' => array(),
1942
			        'title' => array()
1943
			    ),
1944
			    'em' => array(),
1945
			    'strong' => array(),
1946
			);
1947
1948
			$args['message'] = wp_kses( $args['message'], $allowed_html );
1949
		}
1950
1951
		$plugin_name = $plugin[ 'Name' ];
1952
1953
		self::$security_report[ $type ][ $plugin_name ] = $args;
1954
	}
1955
1956
	/**
1957
	 * Collects a new report if needed, then returns it.
1958
	 */
1959
	public function get_security_report() {
1960
		self::perform_security_reporting();
1961
		return Jetpack_Options::get_option( 'security_report' );
1962
	}
1963
1964
1965
/* Jetpack Options API */
1966
1967
	public static function get_option_names( $type = 'compact' ) {
1968
		return Jetpack_Options::get_option_names( $type );
1969
	}
1970
1971
	/**
1972
	 * Returns the requested option.  Looks in jetpack_options or jetpack_$name as appropriate.
1973
 	 *
1974
	 * @param string $name    Option name
1975
	 * @param mixed  $default (optional)
1976
	 */
1977
	public static function get_option( $name, $default = false ) {
1978
		return Jetpack_Options::get_option( $name, $default );
1979
	}
1980
1981
	/**
1982
	* Stores two secrets and a timestamp so WordPress.com can make a request back and verify an action
1983
	* Does some extra verification so urls (such as those to public-api, register, etc) can't just be crafted
1984
	* $name must be a registered option name.
1985
	*/
1986
	public static function create_nonce( $name ) {
1987
		$secret = wp_generate_password( 32, false ) . ':' . wp_generate_password( 32, false ) . ':' . ( time() + 600 );
1988
1989
		Jetpack_Options::update_option( $name, $secret );
1990
		@list( $secret_1, $secret_2, $eol ) = explode( ':', Jetpack_Options::get_option( $name ) );
1991
		if ( empty( $secret_1 ) || empty( $secret_2 ) || $eol < time() )
1992
			return new Jetpack_Error( 'missing_secrets' );
1993
1994
		return array(
1995
			'secret_1' => $secret_1,
1996
			'secret_2' => $secret_2,
1997
			'eol'      => $eol,
1998
		);
1999
	}
2000
2001
	/**
2002
	 * Updates the single given option.  Updates jetpack_options or jetpack_$name as appropriate.
2003
 	 *
2004
	 * @deprecated 3.4 use Jetpack_Options::update_option() instead.
2005
	 * @param string $name  Option name
2006
	 * @param mixed  $value Option value
2007
	 */
2008
	public static function update_option( $name, $value ) {
2009
		_deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::update_option()' );
2010
		return Jetpack_Options::update_option( $name, $value );
2011
	}
2012
2013
	/**
2014
	 * Updates the multiple given options.  Updates jetpack_options and/or jetpack_$name as appropriate.
2015
 	 *
2016
	 * @deprecated 3.4 use Jetpack_Options::update_options() instead.
2017
	 * @param array $array array( option name => option value, ... )
2018
	 */
2019
	public static function update_options( $array ) {
2020
		_deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::update_options()' );
2021
		return Jetpack_Options::update_options( $array );
2022
	}
2023
2024
	/**
2025
	 * Deletes the given option.  May be passed multiple option names as an array.
2026
	 * Updates jetpack_options and/or deletes jetpack_$name as appropriate.
2027
	 *
2028
	 * @deprecated 3.4 use Jetpack_Options::delete_option() instead.
2029
	 * @param string|array $names
2030
	 */
2031
	public static function delete_option( $names ) {
2032
		_deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::delete_option()' );
2033
		return Jetpack_Options::delete_option( $names );
2034
	}
2035
2036
	/**
2037
	 * Enters a user token into the user_tokens option
2038
	 *
2039
	 * @param int $user_id
2040
	 * @param string $token
2041
	 * return bool
2042
	 */
2043
	public static function update_user_token( $user_id, $token, $is_master_user ) {
2044
		// not designed for concurrent updates
2045
		$user_tokens = Jetpack_Options::get_option( 'user_tokens' );
2046
		if ( ! is_array( $user_tokens ) )
2047
			$user_tokens = array();
2048
		$user_tokens[$user_id] = $token;
2049
		if ( $is_master_user ) {
2050
			$master_user = $user_id;
2051
			$options     = compact( 'user_tokens', 'master_user' );
2052
		} else {
2053
			$options = compact( 'user_tokens' );
2054
		}
2055
		return Jetpack_Options::update_options( $options );
2056
	}
2057
2058
	/**
2059
	 * Returns an array of all PHP files in the specified absolute path.
2060
	 * Equivalent to glob( "$absolute_path/*.php" ).
2061
	 *
2062
	 * @param string $absolute_path The absolute path of the directory to search.
2063
	 * @return array Array of absolute paths to the PHP files.
2064
	 */
2065
	public static function glob_php( $absolute_path ) {
2066
		if ( function_exists( 'glob' ) ) {
2067
			return glob( "$absolute_path/*.php" );
2068
		}
2069
2070
		$absolute_path = untrailingslashit( $absolute_path );
2071
		$files = array();
2072
		if ( ! $dir = @opendir( $absolute_path ) ) {
2073
			return $files;
2074
		}
2075
2076
		while ( false !== $file = readdir( $dir ) ) {
2077
			if ( '.' == substr( $file, 0, 1 ) || '.php' != substr( $file, -4 ) ) {
2078
				continue;
2079
			}
2080
2081
			$file = "$absolute_path/$file";
2082
2083
			if ( ! is_file( $file ) ) {
2084
				continue;
2085
			}
2086
2087
			$files[] = $file;
2088
		}
2089
2090
		closedir( $dir );
2091
2092
		return $files;
2093
	}
2094
2095
	public static function activate_new_modules( $redirect = false ) {
2096
		if ( ! Jetpack::is_active() && ! Jetpack::is_development_mode() ) {
2097
			return;
2098
		}
2099
2100
		$jetpack_old_version = Jetpack_Options::get_option( 'version' ); // [sic]
2101 View Code Duplication
		if ( ! $jetpack_old_version ) {
2102
			$jetpack_old_version = $version = $old_version = '1.1:' . time();
2103
			/** This action is documented in class.jetpack.php */
2104
			do_action( 'updating_jetpack_version', $version, false );
2105
			Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
2106
		}
2107
2108
		list( $jetpack_version ) = explode( ':', $jetpack_old_version ); // [sic]
2109
2110
		if ( version_compare( JETPACK__VERSION, $jetpack_version, '<=' ) ) {
2111
			return;
2112
		}
2113
2114
		$active_modules     = Jetpack::get_active_modules();
2115
		$reactivate_modules = array();
2116
		foreach ( $active_modules as $active_module ) {
2117
			$module = Jetpack::get_module( $active_module );
2118
			if ( ! isset( $module['changed'] ) ) {
2119
				continue;
2120
			}
2121
2122
			if ( version_compare( $module['changed'], $jetpack_version, '<=' ) ) {
2123
				continue;
2124
			}
2125
2126
			$reactivate_modules[] = $active_module;
2127
			Jetpack::deactivate_module( $active_module );
2128
		}
2129
2130
		$new_version = JETPACK__VERSION . ':' . time();
2131
		/** This action is documented in class.jetpack.php */
2132
		do_action( 'updating_jetpack_version', $new_version, $jetpack_old_version );
2133
		Jetpack_Options::update_options(
2134
			array(
2135
				'version'     => $new_version,
2136
				'old_version' => $jetpack_old_version,
2137
			)
2138
		);
2139
2140
		Jetpack::state( 'message', 'modules_activated' );
2141
		Jetpack::activate_default_modules( $jetpack_version, JETPACK__VERSION, $reactivate_modules );
2142
2143
		if ( $redirect ) {
2144
			$page = 'jetpack'; // make sure we redirect to either settings or the jetpack page
2145
			if ( isset( $_GET['page'] ) && in_array( $_GET['page'], array( 'jetpack', 'jetpack_modules' ) ) ) {
2146
				$page = $_GET['page'];
2147
			}
2148
2149
			wp_safe_redirect( Jetpack::admin_url( 'page=' . $page ) );
2150
			exit;
2151
		}
2152
	}
2153
2154
	/**
2155
	 * List available Jetpack modules. Simply lists .php files in /modules/.
2156
	 * Make sure to tuck away module "library" files in a sub-directory.
2157
	 */
2158
	public static function get_available_modules( $min_version = false, $max_version = false ) {
2159
		static $modules = null;
2160
2161
		if ( ! isset( $modules ) ) {
2162
			$available_modules_option = Jetpack_Options::get_option( 'available_modules', array() );
2163
			// Use the cache if we're on the front-end and it's available...
2164
			if ( ! is_admin() && ! empty( $available_modules_option[ JETPACK__VERSION ] ) ) {
2165
				$modules = $available_modules_option[ JETPACK__VERSION ];
2166
			} else {
2167
				$files = Jetpack::glob_php( JETPACK__PLUGIN_DIR . 'modules' );
2168
2169
				$modules = array();
2170
2171
				foreach ( $files as $file ) {
2172
					if ( ! $headers = Jetpack::get_module( $file ) ) {
2173
						continue;
2174
					}
2175
2176
					$modules[ Jetpack::get_module_slug( $file ) ] = $headers['introduced'];
2177
				}
2178
2179
				Jetpack_Options::update_option( 'available_modules', array(
2180
					JETPACK__VERSION => $modules,
2181
				) );
2182
			}
2183
		}
2184
2185
		/**
2186
		 * Filters the array of modules available to be activated.
2187
		 *
2188
		 * @since 2.4.0
2189
		 *
2190
		 * @param array $modules Array of available modules.
2191
		 * @param string $min_version Minimum version number required to use modules.
2192
		 * @param string $max_version Maximum version number required to use modules.
2193
		 */
2194
		$mods = apply_filters( 'jetpack_get_available_modules', $modules, $min_version, $max_version );
2195
2196
		if ( ! $min_version && ! $max_version ) {
2197
			return array_keys( $mods );
2198
		}
2199
2200
		$r = array();
2201
		foreach ( $mods as $slug => $introduced ) {
2202
			if ( $min_version && version_compare( $min_version, $introduced, '>=' ) ) {
2203
				continue;
2204
			}
2205
2206
			if ( $max_version && version_compare( $max_version, $introduced, '<' ) ) {
2207
				continue;
2208
			}
2209
2210
			$r[] = $slug;
2211
		}
2212
2213
		return $r;
2214
	}
2215
2216
	/**
2217
	 * Default modules loaded on activation.
2218
	 */
2219
	public static function get_default_modules( $min_version = false, $max_version = false ) {
2220
		$return = array();
2221
2222
		foreach ( Jetpack::get_available_modules( $min_version, $max_version ) as $module ) {
2223
			$module_data = Jetpack::get_module( $module );
2224
2225
			switch ( strtolower( $module_data['auto_activate'] ) ) {
2226
				case 'yes' :
2227
					$return[] = $module;
2228
					break;
2229
				case 'public' :
2230
					if ( Jetpack_Options::get_option( 'public' ) ) {
2231
						$return[] = $module;
2232
					}
2233
					break;
2234
				case 'no' :
2235
				default :
2236
					break;
2237
			}
2238
		}
2239
		/**
2240
		 * Filters the array of default modules.
2241
		 *
2242
		 * @since 2.5.0
2243
		 *
2244
		 * @param array $return Array of default modules.
2245
		 * @param string $min_version Minimum version number required to use modules.
2246
		 * @param string $max_version Maximum version number required to use modules.
2247
		 */
2248
		return apply_filters( 'jetpack_get_default_modules', $return, $min_version, $max_version );
2249
	}
2250
2251
	/**
2252
	 * Checks activated modules during auto-activation to determine
2253
	 * if any of those modules are being deprecated.  If so, close
2254
	 * them out, and add any replacement modules.
2255
	 *
2256
	 * Runs at priority 99 by default.
2257
	 *
2258
	 * This is run late, so that it can still activate a module if
2259
	 * the new module is a replacement for another that the user
2260
	 * currently has active, even if something at the normal priority
2261
	 * would kibosh everything.
2262
	 *
2263
	 * @since 2.6
2264
	 * @uses jetpack_get_default_modules filter
2265
	 * @param array $modules
2266
	 * @return array
2267
	 */
2268
	function handle_deprecated_modules( $modules ) {
2269
		$deprecated_modules = array(
2270
			'debug'            => null,  // Closed out and moved to ./class.jetpack-debugger.php
2271
			'wpcc'             => 'sso', // Closed out in 2.6 -- SSO provides the same functionality.
2272
			'gplus-authorship' => null,  // Closed out in 3.2 -- Google dropped support.
2273
		);
2274
2275
		// Don't activate SSO if they never completed activating WPCC.
2276
		if ( Jetpack::is_module_active( 'wpcc' ) ) {
2277
			$wpcc_options = Jetpack_Options::get_option( 'wpcc_options' );
2278
			if ( empty( $wpcc_options ) || empty( $wpcc_options['client_id'] ) || empty( $wpcc_options['client_id'] ) ) {
2279
				$deprecated_modules['wpcc'] = null;
2280
			}
2281
		}
2282
2283
		foreach ( $deprecated_modules as $module => $replacement ) {
2284
			if ( Jetpack::is_module_active( $module ) ) {
2285
				self::deactivate_module( $module );
2286
				if ( $replacement ) {
2287
					$modules[] = $replacement;
2288
				}
2289
			}
2290
		}
2291
2292
		return array_unique( $modules );
2293
	}
2294
2295
	/**
2296
	 * Checks activated plugins during auto-activation to determine
2297
	 * if any of those plugins are in the list with a corresponding module
2298
	 * that is not compatible with the plugin. The module will not be allowed
2299
	 * to auto-activate.
2300
	 *
2301
	 * @since 2.6
2302
	 * @uses jetpack_get_default_modules filter
2303
	 * @param array $modules
2304
	 * @return array
2305
	 */
2306
	function filter_default_modules( $modules ) {
2307
2308
		$active_plugins = self::get_active_plugins();
2309
2310
		if ( ! empty( $active_plugins ) ) {
2311
2312
			// For each module we'd like to auto-activate...
2313
			foreach ( $modules as $key => $module ) {
2314
				// If there are potential conflicts for it...
2315
				if ( ! empty( $this->conflicting_plugins[ $module ] ) ) {
2316
					// For each potential conflict...
2317
					foreach ( $this->conflicting_plugins[ $module ] as $title => $plugin ) {
2318
						// If that conflicting plugin is active...
2319
						if ( in_array( $plugin, $active_plugins ) ) {
2320
							// Remove that item from being auto-activated.
2321
							unset( $modules[ $key ] );
2322
						}
2323
					}
2324
				}
2325
			}
2326
		}
2327
2328
		return $modules;
2329
	}
2330
2331
	/**
2332
	 * Extract a module's slug from its full path.
2333
	 */
2334
	public static function get_module_slug( $file ) {
2335
		return str_replace( '.php', '', basename( $file ) );
2336
	}
2337
2338
	/**
2339
	 * Generate a module's path from its slug.
2340
	 */
2341
	public static function get_module_path( $slug ) {
2342
		return JETPACK__PLUGIN_DIR . "modules/$slug.php";
2343
	}
2344
2345
	/**
2346
	 * Load module data from module file. Headers differ from WordPress
2347
	 * plugin headers to avoid them being identified as standalone
2348
	 * plugins on the WordPress plugins page.
2349
	 */
2350
	public static function get_module( $module ) {
2351
		$headers = array(
2352
			'name'                      => 'Module Name',
2353
			'description'               => 'Module Description',
2354
			'jumpstart_desc'            => 'Jumpstart Description',
2355
			'sort'                      => 'Sort Order',
2356
			'recommendation_order'      => 'Recommendation Order',
2357
			'introduced'                => 'First Introduced',
2358
			'changed'                   => 'Major Changes In',
2359
			'deactivate'                => 'Deactivate',
2360
			'free'                      => 'Free',
2361
			'requires_connection'       => 'Requires Connection',
2362
			'auto_activate'             => 'Auto Activate',
2363
			'module_tags'               => 'Module Tags',
2364
			'feature'                   => 'Feature',
2365
			'additional_search_queries' => 'Additional Search Queries',
2366
		);
2367
2368
		$file = Jetpack::get_module_path( Jetpack::get_module_slug( $module ) );
2369
2370
		$mod = Jetpack::get_file_data( $file, $headers );
2371
		if ( empty( $mod['name'] ) ) {
2372
			return false;
2373
		}
2374
2375
		$mod['sort']                    = empty( $mod['sort'] ) ? 10 : (int) $mod['sort'];
2376
		$mod['recommendation_order']    = empty( $mod['recommendation_order'] ) ? 20 : (int) $mod['recommendation_order'];
2377
		$mod['deactivate']              = empty( $mod['deactivate'] );
2378
		$mod['free']                    = empty( $mod['free'] );
2379
		$mod['requires_connection']     = ( ! empty( $mod['requires_connection'] ) && 'No' == $mod['requires_connection'] ) ? false : true;
2380
2381
		if ( empty( $mod['auto_activate'] ) || ! in_array( strtolower( $mod['auto_activate'] ), array( 'yes', 'no', 'public' ) ) ) {
2382
			$mod['auto_activate'] = 'No';
2383
		} else {
2384
			$mod['auto_activate'] = (string) $mod['auto_activate'];
2385
		}
2386
2387
		if ( $mod['module_tags'] ) {
2388
			$mod['module_tags'] = explode( ',', $mod['module_tags'] );
2389
			$mod['module_tags'] = array_map( 'trim', $mod['module_tags'] );
2390
			$mod['module_tags'] = array_map( array( __CLASS__, 'translate_module_tag' ), $mod['module_tags'] );
2391
		} else {
2392
			$mod['module_tags'] = array( self::translate_module_tag( 'Other' ) );
2393
		}
2394
2395
		if ( $mod['feature'] ) {
2396
			$mod['feature'] = explode( ',', $mod['feature'] );
2397
			$mod['feature'] = array_map( 'trim', $mod['feature'] );
2398
		} else {
2399
			$mod['feature'] = array( self::translate_module_tag( 'Other' ) );
2400
		}
2401
2402
		/**
2403
		 * Filters the feature array on a module.
2404
		 *
2405
		 * This filter allows you to control where each module is filtered: Recommended,
2406
		 * Jumpstart, and the default "Other" listing.
2407
		 *
2408
		 * @since 3.5.0
2409
		 *
2410
		 * @param array   $mod['feature'] The areas to feature this module:
2411
		 *     'Jumpstart' adds to the "Jumpstart" option to activate many modules at once.
2412
		 *     'Recommended' shows on the main Jetpack admin screen.
2413
		 *     'Other' should be the default if no other value is in the array.
2414
		 * @param string  $module The slug of the module, e.g. sharedaddy.
2415
		 * @param array   $mod All the currently assembled module data.
2416
		 */
2417
		$mod['feature'] = apply_filters( 'jetpack_module_feature', $mod['feature'], $module, $mod );
2418
2419
		/**
2420
		 * Filter the returned data about a module.
2421
		 *
2422
		 * This filter allows overriding any info about Jetpack modules. It is dangerous,
2423
		 * so please be careful.
2424
		 *
2425
		 * @since 3.6.0
2426
		 *
2427
		 * @param array   $mod    The details of the requested module.
2428
		 * @param string  $module The slug of the module, e.g. sharedaddy
2429
		 * @param string  $file   The path to the module source file.
2430
		 */
2431
		return apply_filters( 'jetpack_get_module', $mod, $module, $file );
2432
	}
2433
2434
	/**
2435
	 * Like core's get_file_data implementation, but caches the result.
2436
	 */
2437
	public static function get_file_data( $file, $headers ) {
2438
		//Get just the filename from $file (i.e. exclude full path) so that a consistent hash is generated
2439
		$file_name = basename( $file );
2440
		$file_data_option = Jetpack_Options::get_option( 'file_data', array() );
2441
		$key              = md5( $file_name . serialize( $headers ) );
2442
		$refresh_cache    = is_admin() && isset( $_GET['page'] ) && 'jetpack' === substr( $_GET['page'], 0, 7 );
2443
2444
		// If we don't need to refresh the cache, and already have the value, short-circuit!
2445
		if ( ! $refresh_cache && isset( $file_data_option[ JETPACK__VERSION ][ $key ] ) ) {
2446
			return $file_data_option[ JETPACK__VERSION ][ $key ];
2447
		}
2448
2449
		$data = get_file_data( $file, $headers );
2450
2451
		// Strip out any old Jetpack versions that are cluttering the option.
2452
		$file_data_option = array_intersect_key( (array) $file_data_option, array( JETPACK__VERSION => null ) );
2453
		$file_data_option[ JETPACK__VERSION ][ $key ] = $data;
2454
		Jetpack_Options::update_option( 'file_data', $file_data_option );
2455
2456
		return $data;
2457
	}
2458
2459
	public static function translate_module_tag( $untranslated_tag ) {
2460
		// Tags are aggregated by tools/build-module-headings-translations.php
2461
		// and output in modules/module-headings.php
2462
		return _x( $untranslated_tag, 'Module Tag', 'jetpack' );
2463
	}
2464
2465
	/**
2466
	 * Get a list of activated modules as an array of module slugs.
2467
	 */
2468
	public static function get_active_modules() {
2469
		$active = Jetpack_Options::get_option( 'active_modules' );
2470
		if ( ! is_array( $active ) )
2471
			$active = array();
2472
		if ( is_admin() && ( class_exists( 'VaultPress' ) || function_exists( 'vaultpress_contact_service' ) ) ) {
2473
			$active[] = 'vaultpress';
2474
		} else {
2475
			$active = array_diff( $active, array( 'vaultpress' ) );
2476
		}
2477
2478
		//If protect is active on the main site of a multisite, it should be active on all sites.
2479
		if ( ! in_array( 'protect', $active ) && is_multisite() && get_site_option( 'jetpack_protect_active' ) ) {
2480
			$active[] = 'protect';
2481
		}
2482
2483
		return array_unique( $active );
2484
	}
2485
2486
	/**
2487
	 * Check whether or not a Jetpack module is active.
2488
	 *
2489
	 * @param string $module The slug of a Jetpack module.
2490
	 * @return bool
2491
	 *
2492
	 * @static
2493
	 */
2494
	public static function is_module_active( $module ) {
2495
		return in_array( $module, self::get_active_modules() );
2496
	}
2497
2498
	public static function is_module( $module ) {
2499
		return ! empty( $module ) && ! validate_file( $module, Jetpack::get_available_modules() );
2500
	}
2501
2502
	/**
2503
	 * Catches PHP errors.  Must be used in conjunction with output buffering.
2504
	 *
2505
	 * @param bool $catch True to start catching, False to stop.
2506
	 *
2507
	 * @static
2508
	 */
2509
	public static function catch_errors( $catch ) {
2510
		static $display_errors, $error_reporting;
2511
2512
		if ( $catch ) {
2513
			$display_errors  = @ini_set( 'display_errors', 1 );
2514
			$error_reporting = @error_reporting( E_ALL );
2515
			add_action( 'shutdown', array( 'Jetpack', 'catch_errors_on_shutdown' ), 0 );
2516
		} else {
2517
			@ini_set( 'display_errors', $display_errors );
2518
			@error_reporting( $error_reporting );
2519
			remove_action( 'shutdown', array( 'Jetpack', 'catch_errors_on_shutdown' ), 0 );
2520
		}
2521
	}
2522
2523
	/**
2524
	 * Saves any generated PHP errors in ::state( 'php_errors', {errors} )
2525
	 */
2526
	public static function catch_errors_on_shutdown() {
2527
		Jetpack::state( 'php_errors', ob_get_clean() );
2528
	}
2529
2530
	public static function activate_default_modules( $min_version = false, $max_version = false, $other_modules = array() ) {
2531
		$jetpack = Jetpack::init();
2532
2533
		$modules = Jetpack::get_default_modules( $min_version, $max_version );
2534
		$modules = array_merge( $other_modules, $modules );
2535
2536
		// Look for standalone plugins and disable if active.
2537
2538
		$to_deactivate = array();
2539
		foreach ( $modules as $module ) {
2540
			if ( isset( $jetpack->plugins_to_deactivate[$module] ) ) {
2541
				$to_deactivate[$module] = $jetpack->plugins_to_deactivate[$module];
2542
			}
2543
		}
2544
2545
		$deactivated = array();
2546
		foreach ( $to_deactivate as $module => $deactivate_me ) {
2547
			list( $probable_file, $probable_title ) = $deactivate_me;
2548
			if ( Jetpack_Client_Server::deactivate_plugin( $probable_file, $probable_title ) ) {
2549
				$deactivated[] = $module;
2550
			}
2551
		}
2552
2553
		if ( $deactivated ) {
2554
			Jetpack::state( 'deactivated_plugins', join( ',', $deactivated ) );
2555
2556
			$url = add_query_arg(
2557
				array(
2558
					'action'   => 'activate_default_modules',
2559
					'_wpnonce' => wp_create_nonce( 'activate_default_modules' ),
2560
				),
2561
				add_query_arg( compact( 'min_version', 'max_version', 'other_modules' ), Jetpack::admin_url( 'page=jetpack' ) )
2562
			);
2563
			wp_safe_redirect( $url );
2564
			exit;
2565
		}
2566
2567
		/**
2568
		 * Fires before default modules are activated.
2569
		 *
2570
		 * @since 1.9.0
2571
		 *
2572
		 * @param string $min_version Minimum version number required to use modules.
2573
		 * @param string $max_version Maximum version number required to use modules.
2574
		 * @param array $other_modules Array of other modules to activate alongside the default modules.
2575
		 */
2576
		do_action( 'jetpack_before_activate_default_modules', $min_version, $max_version, $other_modules );
2577
2578
		// Check each module for fatal errors, a la wp-admin/plugins.php::activate before activating
2579
		Jetpack::restate();
2580
		Jetpack::catch_errors( true );
2581
2582
		$active = Jetpack::get_active_modules();
2583
2584
		foreach ( $modules as $module ) {
2585
			if ( did_action( "jetpack_module_loaded_$module" ) ) {
2586
				$active[] = $module;
2587
				Jetpack_Options::update_option( 'active_modules', array_unique( $active ) );
2588
				continue;
2589
			}
2590
2591
			if ( in_array( $module, $active ) ) {
2592
				$module_info = Jetpack::get_module( $module );
2593
				if ( ! $module_info['deactivate'] ) {
2594
					$state = in_array( $module, $other_modules ) ? 'reactivated_modules' : 'activated_modules';
2595 View Code Duplication
					if ( $active_state = Jetpack::state( $state ) ) {
2596
						$active_state = explode( ',', $active_state );
2597
					} else {
2598
						$active_state = array();
2599
					}
2600
					$active_state[] = $module;
2601
					Jetpack::state( $state, implode( ',', $active_state ) );
2602
				}
2603
				continue;
2604
			}
2605
2606
			$file = Jetpack::get_module_path( $module );
2607
			if ( ! file_exists( $file ) ) {
2608
				continue;
2609
			}
2610
2611
			// we'll override this later if the plugin can be included without fatal error
2612
			wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
2613
			Jetpack::state( 'error', 'module_activation_failed' );
2614
			Jetpack::state( 'module', $module );
2615
			ob_start();
2616
			require $file;
2617
			/**
2618
			 * Fires when a specific module is activated.
2619
			 *
2620
			 * @since 1.9.0
2621
			 *
2622
			 * @param string $module Module slug.
2623
			 */
2624
			do_action( 'jetpack_activate_module', $module );
2625
			$active[] = $module;
2626
			$state    = in_array( $module, $other_modules ) ? 'reactivated_modules' : 'activated_modules';
2627 View Code Duplication
			if ( $active_state = Jetpack::state( $state ) ) {
2628
				$active_state = explode( ',', $active_state );
2629
			} else {
2630
				$active_state = array();
2631
			}
2632
			$active_state[] = $module;
2633
			Jetpack::state( $state, implode( ',', $active_state ) );
2634
			Jetpack_Options::update_option( 'active_modules', array_unique( $active ) );
2635
			ob_end_clean();
2636
		}
2637
		Jetpack::state( 'error', false );
2638
		Jetpack::state( 'module', false );
2639
		Jetpack::catch_errors( false );
2640
		/**
2641
		 * Fires when default modules are activated.
2642
		 *
2643
		 * @since 1.9.0
2644
		 *
2645
		 * @param string $min_version Minimum version number required to use modules.
2646
		 * @param string $max_version Maximum version number required to use modules.
2647
		 * @param array $other_modules Array of other modules to activate alongside the default modules.
2648
		 */
2649
		do_action( 'jetpack_activate_default_modules', $min_version, $max_version, $other_modules );
2650
	}
2651
2652
	public static function activate_module( $module, $exit = true, $redirect = true ) {
2653
		/**
2654
		 * Fires before a module is activated.
2655
		 *
2656
		 * @since 2.6.0
2657
		 *
2658
		 * @param string $module Module slug.
2659
		 * @param bool $exit Should we exit after the module has been activated. Default to true.
2660
		 * @param bool $redirect Should the user be redirected after module activation? Default to true.
2661
		 */
2662
		do_action( 'jetpack_pre_activate_module', $module, $exit, $redirect );
2663
2664
		$jetpack = Jetpack::init();
2665
2666
		if ( ! strlen( $module ) )
2667
			return false;
2668
2669
		if ( ! Jetpack::is_module( $module ) )
2670
			return false;
2671
2672
		// If it's already active, then don't do it again
2673
		$active = Jetpack::get_active_modules();
2674
		foreach ( $active as $act ) {
2675
			if ( $act == $module )
2676
				return true;
2677
		}
2678
2679
		$module_data = Jetpack::get_module( $module );
2680
2681
		if ( ! Jetpack::is_active() ) {
2682
			if ( !Jetpack::is_development_mode() )
2683
				return false;
2684
2685
			// If we're not connected but in development mode, make sure the module doesn't require a connection
2686
			if ( Jetpack::is_development_mode() && $module_data['requires_connection'] )
2687
				return false;
2688
		}
2689
2690
		// Check and see if the old plugin is active
2691
		if ( isset( $jetpack->plugins_to_deactivate[ $module ] ) ) {
2692
			// Deactivate the old plugin
2693
			if ( Jetpack_Client_Server::deactivate_plugin( $jetpack->plugins_to_deactivate[ $module ][0], $jetpack->plugins_to_deactivate[ $module ][1] ) ) {
2694
				// If we deactivated the old plugin, remembere that with ::state() and redirect back to this page to activate the module
2695
				// We can't activate the module on this page load since the newly deactivated old plugin is still loaded on this page load.
2696
				Jetpack::state( 'deactivated_plugins', $module );
2697
				wp_safe_redirect( add_query_arg( 'jetpack_restate', 1 ) );
2698
				exit;
2699
			}
2700
		}
2701
2702
		// Check the file for fatal errors, a la wp-admin/plugins.php::activate
2703
		Jetpack::state( 'module', $module );
2704
		Jetpack::state( 'error', 'module_activation_failed' ); // we'll override this later if the plugin can be included without fatal error
2705
2706
		Jetpack::catch_errors( true );
2707
		ob_start();
2708
		require Jetpack::get_module_path( $module );
2709
		/** This action is documented in class.jetpack.php */
2710
		do_action( 'jetpack_activate_module', $module );
2711
		$active[] = $module;
2712
		Jetpack_Options::update_option( 'active_modules', array_unique( $active ) );
2713
		Jetpack::state( 'error', false ); // the override
2714
		Jetpack::state( 'message', 'module_activated' );
2715
		Jetpack::state( 'module', $module );
2716
		ob_end_clean();
2717
		Jetpack::catch_errors( false );
2718
2719
		// A flag for Jump Start so it's not shown again. Only set if it hasn't been yet.
2720 View Code Duplication
		if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
2721
			Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
2722
2723
			//Jump start is being dismissed send data to MC Stats
2724
			$jetpack->stat( 'jumpstart', 'manual,'.$module );
2725
2726
			$jetpack->do_stats( 'server_side' );
2727
		}
2728
2729
		if ( $redirect ) {
2730
			wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
2731
		}
2732
		if ( $exit ) {
2733
			exit;
2734
		}
2735
	}
2736
2737
	function activate_module_actions( $module ) {
2738
		/**
2739
		 * Fires when a module is activated.
2740
		 * The dynamic part of the filter, $module, is the module slug.
2741
		 *
2742
		 * @since 1.9.0
2743
		 *
2744
		 * @param string $module Module slug.
2745
		 */
2746
		do_action( "jetpack_activate_module_$module", $module );
2747
2748
		$this->sync->sync_all_module_options( $module );
2749
	}
2750
2751
	public static function deactivate_module( $module ) {
2752
		/**
2753
		 * Fires when a module is deactivated.
2754
		 *
2755
		 * @since 1.9.0
2756
		 *
2757
		 * @param string $module Module slug.
2758
		 */
2759
		do_action( 'jetpack_pre_deactivate_module', $module );
2760
2761
		$jetpack = Jetpack::init();
2762
2763
		$active = Jetpack::get_active_modules();
2764
		$new    = array_filter( array_diff( $active, (array) $module ) );
2765
2766
		/**
2767
		 * Fires when a module is deactivated.
2768
		 * The dynamic part of the filter, $module, is the module slug.
2769
		 *
2770
		 * @since 1.9.0
2771
		 *
2772
		 * @param string $module Module slug.
2773
		 */
2774
		do_action( "jetpack_deactivate_module_$module", $module );
2775
2776
		// A flag for Jump Start so it's not shown again.
2777 View Code Duplication
		if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
2778
			Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
2779
2780
			//Jump start is being dismissed send data to MC Stats
2781
			$jetpack->stat( 'jumpstart', 'manual,deactivated-'.$module );
2782
2783
			$jetpack->do_stats( 'server_side' );
2784
		}
2785
2786
		return Jetpack_Options::update_option( 'active_modules', array_unique( $new ) );
2787
	}
2788
2789
	public static function enable_module_configurable( $module ) {
2790
		$module = Jetpack::get_module_slug( $module );
2791
		add_filter( 'jetpack_module_configurable_' . $module, '__return_true' );
2792
	}
2793
2794
	public static function module_configuration_url( $module ) {
2795
		$module = Jetpack::get_module_slug( $module );
2796
		return Jetpack::admin_url( array( 'page' => 'jetpack', 'configure' => $module ) );
2797
	}
2798
2799
	public static function module_configuration_load( $module, $method ) {
2800
		$module = Jetpack::get_module_slug( $module );
2801
		add_action( 'jetpack_module_configuration_load_' . $module, $method );
2802
	}
2803
2804
	public static function module_configuration_head( $module, $method ) {
2805
		$module = Jetpack::get_module_slug( $module );
2806
		add_action( 'jetpack_module_configuration_head_' . $module, $method );
2807
	}
2808
2809
	public static function module_configuration_screen( $module, $method ) {
2810
		$module = Jetpack::get_module_slug( $module );
2811
		add_action( 'jetpack_module_configuration_screen_' . $module, $method );
2812
	}
2813
2814
	public static function module_configuration_activation_screen( $module, $method ) {
2815
		$module = Jetpack::get_module_slug( $module );
2816
		add_action( 'display_activate_module_setting_' . $module, $method );
2817
	}
2818
2819
/* Installation */
2820
2821
	public static function bail_on_activation( $message, $deactivate = true ) {
2822
?>
2823
<!doctype html>
2824
<html>
2825
<head>
2826
<meta charset="<?php bloginfo( 'charset' ); ?>">
2827
<style>
2828
* {
2829
	text-align: center;
2830
	margin: 0;
2831
	padding: 0;
2832
	font-family: "Lucida Grande",Verdana,Arial,"Bitstream Vera Sans",sans-serif;
2833
}
2834
p {
2835
	margin-top: 1em;
2836
	font-size: 18px;
2837
}
2838
</style>
2839
<body>
2840
<p><?php echo esc_html( $message ); ?></p>
2841
</body>
2842
</html>
2843
<?php
2844
		if ( $deactivate ) {
2845
			$plugins = get_option( 'active_plugins' );
2846
			$jetpack = plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' );
2847
			$update  = false;
2848
			foreach ( $plugins as $i => $plugin ) {
2849
				if ( $plugin === $jetpack ) {
2850
					$plugins[$i] = false;
2851
					$update = true;
2852
				}
2853
			}
2854
2855
			if ( $update ) {
2856
				update_option( 'active_plugins', array_filter( $plugins ) );
2857
			}
2858
		}
2859
		exit;
2860
	}
2861
2862
	/**
2863
	 * Attached to activate_{ plugin_basename( __FILES__ ) } by register_activation_hook()
2864
	 * @static
2865
	 */
2866
	public static function plugin_activation( $network_wide ) {
2867
		Jetpack_Options::update_option( 'activated', 1 );
2868
2869
		if ( version_compare( $GLOBALS['wp_version'], JETPACK__MINIMUM_WP_VERSION, '<' ) ) {
2870
			Jetpack::bail_on_activation( sprintf( __( 'Jetpack requires WordPress version %s or later.', 'jetpack' ), JETPACK__MINIMUM_WP_VERSION ) );
2871
		}
2872
2873
		if ( $network_wide )
2874
			Jetpack::state( 'network_nag', true );
2875
2876
		Jetpack::plugin_initialize();
2877
	}
2878
	/**
2879
	 * Runs before bumping version numbers up to a new version
2880
	 * @param  (string) $version    Version:timestamp
2881
	 * @param  (string) $old_version Old Version:timestamp or false if not set yet.
2882
	 * @return null              [description]
2883
	 */
2884
	public static function do_version_bump( $version, $old_version ) {
2885
2886
		if ( ! $old_version ) { // For new sites
2887
			// Setting up jetpack manage
2888
			Jetpack::activate_manage();
2889
		}
2890
	}
2891
2892
	/**
2893
	 * Sets the internal version number and activation state.
2894
	 * @static
2895
	 */
2896
	public static function plugin_initialize() {
2897
		if ( ! Jetpack_Options::get_option( 'activated' ) ) {
2898
			Jetpack_Options::update_option( 'activated', 2 );
2899
		}
2900
2901 View Code Duplication
		if ( ! Jetpack_Options::get_option( 'version' ) ) {
2902
			$version = $old_version = JETPACK__VERSION . ':' . time();
2903
			/** This action is documented in class.jetpack.php */
2904
			do_action( 'updating_jetpack_version', $version, false );
2905
			Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
2906
		}
2907
2908
		Jetpack::load_modules();
2909
2910
		Jetpack_Options::delete_option( 'do_activate' );
2911
	}
2912
2913
	/**
2914
	 * Removes all connection options
2915
	 * @static
2916
	 */
2917
	public static function plugin_deactivation( ) {
2918
		require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
2919
		if( is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
2920
			Jetpack_Network::init()->deactivate();
2921
		} else {
2922
			Jetpack::disconnect( false );
2923
			//Jetpack_Heartbeat::init()->deactivate();
2924
		}
2925
	}
2926
2927
	/**
2928
	 * Disconnects from the Jetpack servers.
2929
	 * Forgets all connection details and tells the Jetpack servers to do the same.
2930
	 * @static
2931
	 */
2932
	public static function disconnect( $update_activated_state = true ) {
2933
		wp_clear_scheduled_hook( 'jetpack_clean_nonces' );
2934
		Jetpack::clean_nonces( true );
2935
2936
		Jetpack::load_xml_rpc_client();
2937
		$xml = new Jetpack_IXR_Client();
2938
		$xml->query( 'jetpack.deregister' );
2939
2940
		Jetpack_Options::delete_option(
2941
			array(
2942
				'register',
2943
				'blog_token',
2944
				'user_token',
2945
				'user_tokens',
2946
				'master_user',
2947
				'time_diff',
2948
				'fallback_no_verify_ssl_certs',
2949
			)
2950
		);
2951
2952
		if ( $update_activated_state ) {
2953
			Jetpack_Options::update_option( 'activated', 4 );
2954
		}
2955
2956
		$jetpack_unique_connection = Jetpack_Options::get_option( 'unique_connection' );
2957
		// Check then record unique disconnection if site has never been disconnected previously
2958
		if ( -1 == $jetpack_unique_connection['disconnected'] ) {
2959
			$jetpack_unique_connection['disconnected'] = 1;
2960
		}
2961
		else {
2962
			if ( 0 == $jetpack_unique_connection['disconnected'] ) {
2963
				//track unique disconnect
2964
				$jetpack = Jetpack::init();
2965
2966
				$jetpack->stat( 'connections', 'unique-disconnect' );
2967
				$jetpack->do_stats( 'server_side' );
2968
			}
2969
			// increment number of times disconnected
2970
			$jetpack_unique_connection['disconnected'] += 1;
2971
		}
2972
2973
		Jetpack_Options::update_option( 'unique_connection', $jetpack_unique_connection );
2974
2975
		// Disable the Heartbeat cron
2976
		Jetpack_Heartbeat::init()->deactivate();
2977
	}
2978
2979
	/**
2980
	 * Unlinks the current user from the linked WordPress.com user
2981
	 */
2982
	public static function unlink_user( $user_id = null ) {
2983
		if ( ! $tokens = Jetpack_Options::get_option( 'user_tokens' ) )
2984
			return false;
2985
2986
		$user_id = empty( $user_id ) ? get_current_user_id() : intval( $user_id );
2987
2988
		if ( Jetpack_Options::get_option( 'master_user' ) == $user_id )
2989
			return false;
2990
2991
		if ( ! isset( $tokens[ $user_id ] ) )
2992
			return false;
2993
2994
		Jetpack::load_xml_rpc_client();
2995
		$xml = new Jetpack_IXR_Client( compact( 'user_id' ) );
2996
		$xml->query( 'jetpack.unlink_user', $user_id );
2997
2998
		unset( $tokens[ $user_id ] );
2999
3000
		Jetpack_Options::update_option( 'user_tokens', $tokens );
3001
3002
		return true;
3003
	}
3004
3005
	/**
3006
	 * Attempts Jetpack registration.  If it fail, a state flag is set: @see ::admin_page_load()
3007
	 */
3008
	public static function try_registration() {
3009
		// Let's get some testing in beta versions and such.
3010
		if ( self::is_development_version() && defined( 'PHP_URL_HOST' ) ) {
3011
			// Before attempting to connect, let's make sure that the domains are viable.
3012
			$domains_to_check = array_unique( array(
3013
				'siteurl' => parse_url( get_site_url(), PHP_URL_HOST ),
3014
				'homeurl' => parse_url( get_home_url(), PHP_URL_HOST ),
3015
			) );
3016
			foreach ( $domains_to_check as $domain ) {
3017
				$result = Jetpack_Data::is_usable_domain( $domain );
3018
				if ( is_wp_error( $result ) ) {
3019
					return $result;
3020
				}
3021
			}
3022
		}
3023
3024
		$result = Jetpack::register();
3025
3026
		// If there was an error with registration and the site was not registered, record this so we can show a message.
3027
		if ( ! $result || is_wp_error( $result ) ) {
3028
			return $result;
3029
		} else {
3030
			return true;
3031
		}
3032
	}
3033
3034
	/**
3035
	 * Tracking an internal event log. Try not to put too much chaff in here.
3036
	 *
3037
	 * [Everyone Loves a Log!](https://www.youtube.com/watch?v=2C7mNr5WMjA)
3038
	 */
3039
	public static function log( $code, $data = null ) {
3040
		// only grab the latest 200 entries
3041
		$log = array_slice( Jetpack_Options::get_option( 'log', array() ), -199, 199 );
3042
3043
		// Append our event to the log
3044
		$log_entry = array(
3045
			'time'    => time(),
3046
			'user_id' => get_current_user_id(),
3047
			'blog_id' => Jetpack_Options::get_option( 'id' ),
3048
			'code'    => $code,
3049
		);
3050
		// Don't bother storing it unless we've got some.
3051
		if ( ! is_null( $data ) ) {
1 ignored issue
show
As per coding-style, please use === null instead of is_null.
Loading history...
3052
			$log_entry['data'] = $data;
3053
		}
3054
		$log[] = $log_entry;
3055
3056
		// Try add_option first, to make sure it's not autoloaded.
3057
		// @todo: Add an add_option method to Jetpack_Options
3058
		if ( ! add_option( 'jetpack_log', $log, null, 'no' ) ) {
3059
			Jetpack_Options::update_option( 'log', $log );
3060
		}
3061
3062
		/**
3063
		 * Fires when Jetpack logs an internal event.
3064
		 *
3065
		 * @since 3.0.0
3066
		 *
3067
		 * @param array $log_entry {
3068
		 *	Array of details about the log entry.
3069
		 *
3070
		 *	@param string time Time of the event.
3071
		 *	@param int user_id ID of the user who trigerred the event.
3072
		 *	@param int blog_id Jetpack Blog ID.
3073
		 *	@param string code Unique name for the event.
3074
		 *	@param string data Data about the event.
3075
		 * }
3076
		 */
3077
		do_action( 'jetpack_log_entry', $log_entry );
3078
	}
3079
3080
	/**
3081
	 * Get the internal event log.
3082
	 *
3083
	 * @param $event (string) - only return the specific log events
3084
	 * @param $num   (int)    - get specific number of latest results, limited to 200
3085
	 *
3086
	 * @return array of log events || WP_Error for invalid params
3087
	 */
3088
	public static function get_log( $event = false, $num = false ) {
3089
		if ( $event && ! is_string( $event ) ) {
3090
			return new WP_Error( __( 'First param must be string or empty', 'jetpack' ) );
3091
		}
3092
3093
		if ( $num && ! is_numeric( $num ) ) {
3094
			return new WP_Error( __( 'Second param must be numeric or empty', 'jetpack' ) );
3095
		}
3096
3097
		$entire_log = Jetpack_Options::get_option( 'log', array() );
3098
3099
		// If nothing set - act as it did before, otherwise let's start customizing the output
3100
		if ( ! $num && ! $event ) {
3101
			return $entire_log;
3102
		} else {
3103
			$entire_log = array_reverse( $entire_log );
3104
		}
3105
3106
		$custom_log_output = array();
3107
3108
		if ( $event ) {
3109
			foreach ( $entire_log as $log_event ) {
3110
				if ( $event == $log_event[ 'code' ] ) {
3111
					$custom_log_output[] = $log_event;
3112
				}
3113
			}
3114
		} else {
3115
			$custom_log_output = $entire_log;
3116
		}
3117
3118
		if ( $num ) {
3119
			$custom_log_output = array_slice( $custom_log_output, 0, $num );
3120
		}
3121
3122
		return $custom_log_output;
3123
	}
3124
3125
	/**
3126
	 * Log modification of important settings.
3127
	 */
3128
	public static function log_settings_change( $option, $old_value, $value ) {
3129
		switch( $option ) {
3130
			case 'jetpack_sync_non_public_post_stati':
3131
				self::log( $option, $value );
3132
				break;
3133
		}
3134
	}
3135
3136
	/**
3137
	 * Return stat data for WPCOM sync
3138
	 */
3139
	function get_stat_data() {
3140
		$heartbeat_data = Jetpack_Heartbeat::generate_stats_array();
3141
		$additional_data = $this->get_additional_stat_data();
3142
3143
		return json_encode( array_merge( $heartbeat_data, $additional_data ) );
3144
	}
3145
3146
	/**
3147
	 * Get additional stat data to sync to WPCOM
3148
	 */
3149
	function get_additional_stat_data( $prefix = '' ) {
3150
		$return["{$prefix}themes"]         = Jetpack::get_parsed_theme_data();
3151
		$return["{$prefix}plugins-extra"]  = Jetpack::get_parsed_plugin_data();
3152
		$return["{$prefix}users"]          = count_users();
3153
		$return["{$prefix}site-count"]     = 0;
3154
		if ( function_exists( 'get_blog_count' ) ) {
3155
			$return["{$prefix}site-count"] = get_blog_count();
3156
		}
3157
		return $return;
3158
	}
3159
3160
	/* Admin Pages */
3161
3162
	function admin_init() {
3163
		// If the plugin is not connected, display a connect message.
3164
		if (
3165
			// the plugin was auto-activated and needs its candy
3166
			Jetpack_Options::get_option( 'do_activate' )
3167
		||
3168
			// the plugin is active, but was never activated.  Probably came from a site-wide network activation
3169
			! Jetpack_Options::get_option( 'activated' )
3170
		) {
3171
			Jetpack::plugin_initialize();
3172
		}
3173
3174
		if ( ! Jetpack::is_active() && ! Jetpack::is_development_mode() ) {
3175
			if ( 4 != Jetpack_Options::get_option( 'activated' ) ) {
3176
				// Show connect notice on dashboard and plugins pages
3177
				add_action( 'load-index.php', array( $this, 'prepare_connect_notice' ) );
3178
				add_action( 'load-plugins.php', array( $this, 'prepare_connect_notice' ) );
3179
			}
3180
		} elseif ( false === Jetpack_Options::get_option( 'fallback_no_verify_ssl_certs' ) ) {
3181
			// Upgrade: 1.1 -> 1.1.1
3182
			// Check and see if host can verify the Jetpack servers' SSL certificate
3183
			$args = array();
3184
			Jetpack_Client::_wp_remote_request(
3185
				Jetpack::fix_url_for_bad_hosts( Jetpack::api_url( 'test' ) ),
3186
				$args,
3187
				true
3188
			);
3189
		} else {
3190
			// Show the notice on the Dashboard only for now
3191
3192
			add_action( 'load-index.php', array( $this, 'prepare_manage_jetpack_notice' ) );
3193
3194
			// Identity crisis notices
3195
			add_action( 'jetpack_notices', array( $this, 'alert_identity_crisis' ) );
3196
		}
3197
3198
		// If the plugin has just been disconnected from WP.com, show the survey notice
3199
		if ( isset( $_GET['disconnected'] ) && 'true' === $_GET['disconnected'] ) {
3200
			add_action( 'jetpack_notices', array( $this, 'disconnect_survey_notice' ) );
3201
		}
3202
3203
		if ( current_user_can( 'manage_options' ) && 'ALWAYS' == JETPACK_CLIENT__HTTPS && ! self::permit_ssl() ) {
3204
			add_action( 'admin_notices', array( $this, 'alert_required_ssl_fail' ) );
3205
		}
3206
3207
		add_action( 'load-plugins.php', array( $this, 'intercept_plugin_error_scrape_init' ) );
3208
		add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
3209
		add_filter( 'plugin_action_links_' . plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' ), array( $this, 'plugin_action_links' ) );
3210
3211
		if ( Jetpack::is_active() || Jetpack::is_development_mode() ) {
3212
			// Artificially throw errors in certain whitelisted cases during plugin activation
3213
			add_action( 'activate_plugin', array( $this, 'throw_error_on_activate_plugin' ) );
3214
3215
			// Kick off synchronization of user role when it changes
3216
			add_action( 'set_user_role', array( $this, 'user_role_change' ) );
3217
		}
3218
3219
		// Jetpack Manage Activation Screen from .com
3220
		Jetpack::module_configuration_activation_screen( 'manage', array( $this, 'manage_activate_screen' ) );
3221
	}
3222
3223
	function admin_body_class( $admin_body_class = '' ) {
3224
		$classes = explode( ' ', trim( $admin_body_class ) );
3225
3226
		$classes[] = self::is_active() ? 'jetpack-connected' : 'jetpack-disconnected';
3227
3228
		$admin_body_class = implode( ' ', array_unique( $classes ) );
3229
		return " $admin_body_class ";
3230
	}
3231
3232
	static function add_jetpack_pagestyles( $admin_body_class = '' ) {
3233
		return $admin_body_class . ' jetpack-pagestyles ';
3234
	}
3235
3236
	function prepare_connect_notice() {
3237
		add_action( 'admin_print_styles', array( $this, 'admin_banner_styles' ) );
3238
3239
		add_action( 'admin_notices', array( $this, 'admin_connect_notice' ) );
3240
3241
		if ( Jetpack::state( 'network_nag' ) )
3242
			add_action( 'network_admin_notices', array( $this, 'network_connect_notice' ) );
3243
	}
3244
	/**
3245
	 * Call this function if you want the Big Jetpack Manage Notice to show up.
3246
	 *
3247
	 * @return null
3248
	 */
3249
	function prepare_manage_jetpack_notice() {
3250
3251
		add_action( 'admin_print_styles', array( $this, 'admin_banner_styles' ) );
3252
		add_action( 'admin_notices', array( $this, 'admin_jetpack_manage_notice' ) );
3253
	}
3254
3255
	function manage_activate_screen() {
3256
		include ( JETPACK__PLUGIN_DIR . 'modules/manage/activate-admin.php' );
3257
	}
3258
	/**
3259
	 * Sometimes a plugin can activate without causing errors, but it will cause errors on the next page load.
3260
	 * This function artificially throws errors for such cases (whitelisted).
3261
	 *
3262
	 * @param string $plugin The activated plugin.
3263
	 */
3264
	function throw_error_on_activate_plugin( $plugin ) {
3265
		$active_modules = Jetpack::get_active_modules();
3266
3267
		// The Shortlinks module and the Stats plugin conflict, but won't cause errors on activation because of some function_exists() checks.
3268
		if ( function_exists( 'stats_get_api_key' ) && in_array( 'shortlinks', $active_modules ) ) {
3269
			$throw = false;
3270
3271
			// Try and make sure it really was the stats plugin
3272
			if ( ! class_exists( 'ReflectionFunction' ) ) {
3273
				if ( 'stats.php' == basename( $plugin ) ) {
3274
					$throw = true;
3275
				}
3276
			} else {
3277
				$reflection = new ReflectionFunction( 'stats_get_api_key' );
3278
				if ( basename( $plugin ) == basename( $reflection->getFileName() ) ) {
3279
					$throw = true;
3280
				}
3281
			}
3282
3283
			if ( $throw ) {
3284
				trigger_error( sprintf( __( 'Jetpack contains the most recent version of the old &#8220;%1$s&#8221; plugin.', 'jetpack' ), 'WordPress.com Stats' ), E_USER_ERROR );
3285
			}
3286
		}
3287
	}
3288
3289
	function intercept_plugin_error_scrape_init() {
3290
		add_action( 'check_admin_referer', array( $this, 'intercept_plugin_error_scrape' ), 10, 2 );
3291
	}
3292
3293
	function intercept_plugin_error_scrape( $action, $result ) {
3294
		if ( ! $result ) {
3295
			return;
3296
		}
3297
3298
		foreach ( $this->plugins_to_deactivate as $deactivate_me ) {
3299
			if ( "plugin-activation-error_{$deactivate_me[0]}" == $action ) {
3300
				Jetpack::bail_on_activation( sprintf( __( 'Jetpack contains the most recent version of the old &#8220;%1$s&#8221; plugin.', 'jetpack' ), $deactivate_me[1] ), false );
3301
			}
3302
		}
3303
	}
3304
3305
	function add_remote_request_handlers() {
3306
		add_action( 'wp_ajax_nopriv_jetpack_upload_file', array( $this, 'remote_request_handlers' ) );
3307
	}
3308
3309
	function remote_request_handlers() {
3310
		switch ( current_filter() ) {
3311
		case 'wp_ajax_nopriv_jetpack_upload_file' :
3312
			$response = $this->upload_handler();
3313
			break;
3314
		default :
3315
			$response = new Jetpack_Error( 'unknown_handler', 'Unknown Handler', 400 );
3316
			break;
3317
		}
3318
3319
		if ( ! $response ) {
3320
			$response = new Jetpack_Error( 'unknown_error', 'Unknown Error', 400 );
3321
		}
3322
3323
		if ( is_wp_error( $response ) ) {
3324
			$status_code       = $response->get_error_data();
3325
			$error             = $response->get_error_code();
3326
			$error_description = $response->get_error_message();
3327
3328
			if ( ! is_int( $status_code ) ) {
3329
				$status_code = 400;
3330
			}
3331
3332
			status_header( $status_code );
3333
			die( json_encode( (object) compact( 'error', 'error_description' ) ) );
3334
		}
3335
3336
		status_header( 200 );
3337
		if ( true === $response ) {
3338
			exit;
3339
		}
3340
3341
		die( json_encode( (object) $response ) );
3342
	}
3343
3344
	function upload_handler() {
3345
		if ( 'POST' !== strtoupper( $_SERVER['REQUEST_METHOD'] ) ) {
3346
			return new Jetpack_Error( 405, get_status_header_desc( 405 ), 405 );
3347
		}
3348
3349
		$user = wp_authenticate( '', '' );
3350
		if ( ! $user || is_wp_error( $user ) ) {
3351
			return new Jetpack_Error( 403, get_status_header_desc( 403 ), 403 );
3352
		}
3353
3354
		wp_set_current_user( $user->ID );
3355
3356
		if ( ! current_user_can( 'upload_files' ) ) {
3357
			return new Jetpack_Error( 'cannot_upload_files', 'User does not have permission to upload files', 403 );
3358
		}
3359
3360
		if ( empty( $_FILES ) ) {
3361
			return new Jetpack_Error( 'no_files_uploaded', 'No files were uploaded: nothing to process', 400 );
3362
		}
3363
3364
		foreach ( array_keys( $_FILES ) as $files_key ) {
3365
			if ( ! isset( $_POST["_jetpack_file_hmac_{$files_key}"] ) ) {
3366
				return new Jetpack_Error( 'missing_hmac', 'An HMAC for one or more files is missing', 400 );
3367
			}
3368
		}
3369
3370
		$media_keys = array_keys( $_FILES['media'] );
3371
3372
		$token = Jetpack_Data::get_access_token( get_current_user_id() );
3373
		if ( ! $token || is_wp_error( $token ) ) {
3374
			return new Jetpack_Error( 'unknown_token', 'Unknown Jetpack token', 403 );
3375
		}
3376
3377
		$uploaded_files = array();
3378
		$global_post    = isset( $GLOBALS['post'] ) ? $GLOBALS['post'] : null;
3379
		unset( $GLOBALS['post'] );
3380
		foreach ( $_FILES['media']['name'] as $index => $name ) {
3381
			$file = array();
3382
			foreach ( $media_keys as $media_key ) {
3383
				$file[$media_key] = $_FILES['media'][$media_key][$index];
3384
			}
3385
3386
			list( $hmac_provided, $salt ) = explode( ':', $_POST['_jetpack_file_hmac_media'][$index] );
3387
3388
			$hmac_file = hash_hmac_file( 'sha1', $file['tmp_name'], $salt . $token->secret );
3389
			if ( $hmac_provided !== $hmac_file ) {
3390
				$uploaded_files[$index] = (object) array( 'error' => 'invalid_hmac', 'error_description' => 'The corresponding HMAC for this file does not match' );
3391
				continue;
3392
			}
3393
3394
			$_FILES['.jetpack.upload.'] = $file;
3395
			$post_id = isset( $_POST['post_id'][$index] ) ? absint( $_POST['post_id'][$index] ) : 0;
3396
			if ( ! current_user_can( 'edit_post', $post_id ) ) {
3397
				$post_id = 0;
3398
			}
3399
			$attachment_id = media_handle_upload(
3400
				'.jetpack.upload.',
3401
				$post_id,
3402
				array(),
3403
				array(
3404
					'action' => 'jetpack_upload_file',
3405
				)
3406
			);
3407
3408
			if ( ! $attachment_id ) {
3409
				$uploaded_files[$index] = (object) array( 'error' => 'unknown', 'error_description' => 'An unknown problem occurred processing the upload on the Jetpack site' );
3410
			} elseif ( is_wp_error( $attachment_id ) ) {
3411
				$uploaded_files[$index] = (object) array( 'error' => 'attachment_' . $attachment_id->get_error_code(), 'error_description' => $attachment_id->get_error_message() );
3412
			} else {
3413
				$attachment = get_post( $attachment_id );
3414
				$uploaded_files[$index] = (object) array(
3415
					'id'   => (string) $attachment_id,
3416
					'file' => $attachment->post_title,
3417
					'url'  => wp_get_attachment_url( $attachment_id ),
3418
					'type' => $attachment->post_mime_type,
3419
					'meta' => wp_get_attachment_metadata( $attachment_id ),
3420
				);
3421
			}
3422
		}
3423
		if ( ! is_null( $global_post ) ) {
1 ignored issue
show
As per coding-style, please use === null instead of is_null.
Loading history...
3424
			$GLOBALS['post'] = $global_post;
3425
		}
3426
3427
		return $uploaded_files;
3428
	}
3429
3430
	/**
3431
	 * Add help to the Jetpack page
3432
	 *
3433
	 * @since Jetpack (1.2.3)
3434
	 * @return false if not the Jetpack page
3435
	 */
3436
	function admin_help() {
3437
		$current_screen = get_current_screen();
3438
3439
		// Overview
3440
		$current_screen->add_help_tab(
3441
			array(
3442
				'id'		=> 'home',
3443
				'title'		=> __( 'Home', 'jetpack' ),
3444
				'content'	=>
3445
					'<p><strong>' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</strong></p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3446
					'<p>' . __( 'Jetpack supercharges your self-hosted WordPress site with the awesome cloud power of WordPress.com.', 'jetpack' ) . '</p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3447
					'<p>' . __( 'On this page, you are able to view the modules available within Jetpack, learn more about them, and activate or deactivate them as needed.', 'jetpack' ) . '</p>',
3448
			)
3449
		);
3450
3451
		// Screen Content
3452
		if ( current_user_can( 'manage_options' ) ) {
3453
			$current_screen->add_help_tab(
3454
				array(
3455
					'id'		=> 'settings',
3456
					'title'		=> __( 'Settings', 'jetpack' ),
3457
					'content'	=>
3458
						'<p><strong>' . __( 'Jetpack by WordPress.com',                                              'jetpack' ) . '</strong></p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3459
						'<p>' . __( 'You can activate or deactivate individual Jetpack modules to suit your needs.', 'jetpack' ) . '</p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3460
						'<ol>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3461
							'<li>' . __( 'Each module has an Activate or Deactivate link so you can toggle one individually.',														'jetpack' ) . '</li>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3462
							'<li>' . __( 'Using the checkboxes next to each module, you can select multiple modules to toggle via the Bulk Actions menu at the top of the list.',	'jetpack' ) . '</li>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3463
						'</ol>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3464
						'<p>' . __( 'Using the tools on the right, you can search for specific modules, filter by module categories or which are active, or change the sorting order.', 'jetpack' ) . '</p>'
3465
				)
3466
			);
3467
		}
3468
3469
		// Help Sidebar
3470
		$current_screen->set_help_sidebar(
3471
			'<p><strong>' . __( 'For more information:', 'jetpack' ) . '</strong></p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3472
			'<p><a href="http://jetpack.me/faq/" target="_blank">'     . __( 'Jetpack FAQ',     'jetpack' ) . '</a></p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3473
			'<p><a href="http://jetpack.me/support/" target="_blank">' . __( 'Jetpack Support', 'jetpack' ) . '</a></p>' .
1 ignored issue
show
String concat is not required here; use a single string instead
Loading history...
3474
			'<p><a href="' . Jetpack::admin_url( array( 'page' => 'jetpack-debugger' )  ) .'">' . __( 'Jetpack Debugging Center', 'jetpack' ) . '</a></p>'
3475
		);
3476
	}
3477
3478
	function admin_menu_css() {
3479
		wp_enqueue_style( 'jetpack-icons' );
3480
	}
3481
3482
	function admin_menu_order() {
3483
		return true;
3484
	}
3485
3486 View Code Duplication
	function jetpack_menu_order( $menu_order ) {
3487
		$jp_menu_order = array();
3488
3489
		foreach ( $menu_order as $index => $item ) {
3490
			if ( $item != 'jetpack' ) {
3491
				$jp_menu_order[] = $item;
3492
			}
3493
3494
			if ( $index == 0 ) {
3495
				$jp_menu_order[] = 'jetpack';
3496
			}
3497
		}
3498
3499
		return $jp_menu_order;
3500
	}
3501
3502
	function admin_head() {
3503 View Code Duplication
		if ( isset( $_GET['configure'] ) && Jetpack::is_module( $_GET['configure'] ) && current_user_can( 'manage_options' ) )
3504
			/** This action is documented in class.jetpack-admin-page.php */
3505
			do_action( 'jetpack_module_configuration_head_' . $_GET['configure'] );
3506
	}
3507
3508
	function admin_banner_styles() {
3509
		$min = ( defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ) ? '' : '.min';
3510
3511
		wp_enqueue_style( 'jetpack', plugins_url( "css/jetpack-banners{$min}.css", JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION . '-20121016' );
3512
		wp_style_add_data( 'jetpack', 'rtl', 'replace' );
3513
		wp_style_add_data( 'jetpack', 'suffix', $min );
3514
	}
3515
3516
	function admin_scripts() {
3517
		wp_enqueue_script( 'jetpack-js', plugins_url( '_inc/jp.js', JETPACK__PLUGIN_FILE ), array( 'jquery', 'wp-util' ), JETPACK__VERSION . '-20121111' );
3518
		wp_localize_script(
3519
			'jetpack-js',
3520
			'jetpackL10n',
3521
			array(
3522
				'ays_disconnect' => "This will deactivate all Jetpack modules.\nAre you sure you want to disconnect?",
3523
				'ays_unlink'     => "This will prevent user-specific modules such as Publicize, Notifications and Post By Email from working.\nAre you sure you want to unlink?",
3524
				'ays_dismiss'    => "This will deactivate Jetpack.\nAre you sure you want to deactivate Jetpack?",
3525
			)
3526
		);
3527
		add_action( 'admin_footer', array( $this, 'do_stats' ) );
3528
	}
3529
3530
	function plugin_action_links( $actions ) {
3531
3532
		$jetpack_home = array( 'jetpack-home' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack' ), __( 'Jetpack', 'jetpack' ) ) );
3533
3534
		if( current_user_can( 'jetpack_manage_modules' ) && ( Jetpack::is_active() || Jetpack::is_development_mode() ) ) {
3535
			return array_merge(
3536
				$jetpack_home,
3537
				array( 'settings' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack_modules' ), __( 'Settings', 'jetpack' ) ) ),
3538
				array( 'support' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack-debugger '), __( 'Support', 'jetpack' ) ) ),
3539
				$actions
3540
				);
3541
			}
3542
3543
		return array_merge( $jetpack_home, $actions );
3544
	}
3545
3546
	function admin_connect_notice() {
3547
		// Don't show the connect notice anywhere but the plugins.php after activating
3548
		$current = get_current_screen();
3549
		if ( 'plugins' !== $current->parent_base )
3550
			return;
3551
3552
		if ( ! current_user_can( 'jetpack_connect' ) )
3553
			return;
3554
3555
		$dismiss_and_deactivate_url = wp_nonce_url( Jetpack::admin_url( '?page=jetpack&jetpack-notice=dismiss' ), 'jetpack-deactivate' );
3556
		?>
3557
		<div id="message" class="updated jetpack-message jp-banner" style="display:block !important;">
3558
			<a class="jp-banner__dismiss" href="<?php echo esc_url( $dismiss_and_deactivate_url ); ?>" title="<?php esc_attr_e( 'Dismiss this notice and deactivate Jetpack.', 'jetpack' ); ?>"></a>
3559
			<?php if ( in_array( Jetpack_Options::get_option( 'activated' ) , array( 1, 2, 3 ) ) ) : ?>
3560
				<div class="jp-banner__content is-connection">
3561
					<h2><?php _e( 'Your Jetpack is almost ready!', 'jetpack' ); ?></h2>
3562
					<p><?php _e( 'Connect now to enable features like Stats, Likes, and Social Sharing.', 'jetpack' ); ?></p>
3563
				</div>
3564
				<div class="jp-banner__action-container is-connection">
3565
						<a href="<?php echo $this->build_connect_url() ?>" class="jp-banner__button" id="wpcom-connect"><?php _e( 'Connect to WordPress.com', 'jetpack' ); ?></a>
3566
				</div>
3567 View Code Duplication
			<?php else : ?>
3568
				<div class="jp-banner__content">
3569
					<h2><?php _e( 'Jetpack is installed!', 'jetpack' ) ?></h2>
3570
					<p><?php _e( 'It\'s ready to bring awesome, WordPress.com cloud-powered features to your site.', 'jetpack' ) ?></p>
3571
				</div>
3572
				<div class="jp-banner__action-container">
3573
					<a href="<?php echo Jetpack::admin_url() ?>" class="jp-banner__button" id="wpcom-connect"><?php _e( 'Learn More', 'jetpack' ); ?></a>
3574
				</div>
3575
			<?php endif; ?>
3576
		</div>
3577
3578
		<?php
3579
	}
3580
3581
	/**
3582
	 * This is the first banner
3583
	 * It should be visible only to user that can update the option
3584
	 * Are not connected
3585
	 *
3586
	 * @return null
3587
	 */
3588
	function admin_jetpack_manage_notice() {
3589
		$screen = get_current_screen();
3590
3591
		// Don't show the connect notice on the jetpack settings page.
3592
		if ( ! in_array( $screen->base, array( 'dashboard' ) ) || $screen->is_network || $screen->action )
3593
			return;
3594
3595
		// Only show it if don't have the managment option set.
3596
		// And not dismissed it already.
3597
		if ( ! $this->can_display_jetpack_manage_notice() || Jetpack_Options::get_option( 'dismissed_manage_banner' ) ) {
3598
			return;
3599
		}
3600
3601
		$opt_out_url = $this->opt_out_jetpack_manage_url();
3602
		$opt_in_url  = $this->opt_in_jetpack_manage_url();
3603
		/**
3604
		 * I think it would be great to have different wordsing depending on where you are
3605
		 * for example if we show the notice on dashboard and a different one if we show it on Plugins screen
3606
		 * etc..
3607
		 */
3608
3609
		?>
3610
		<div id="message" class="updated jetpack-message jp-banner is-opt-in" style="display:block !important;">
3611
			<a class="jp-banner__dismiss" href="<?php echo esc_url( $opt_out_url ); ?>" title="<?php esc_attr_e( 'Dismiss this notice for now.', 'jetpack' ); ?>"></a>
3612
			<div class="jp-banner__content">
3613
				<h2><?php esc_html_e( 'New in Jetpack: Centralized Site Management', 'jetpack' ); ?></h2>
3614
				<p><?php printf( __( 'Manage multiple sites from one dashboard at wordpress.com/sites. Enabling allows all existing, connected Administrators to modify your site from WordPress.com. <a href="%s" target="_blank">Learn More</a>.', 'jetpack' ), 'http://jetpack.me/support/site-management' ); ?></p>
3615
			</div>
3616
			<div class="jp-banner__action-container is-opt-in">
3617
				<a href="<?php echo esc_url( $opt_in_url ); ?>" class="jp-banner__button" id="wpcom-connect"><?php _e( 'Activate now', 'jetpack' ); ?></a>
3618
			</div>
3619
		</div>
3620
		<?php
3621
	}
3622
3623
	/**
3624
	 * Returns the url that the user clicks to remove the notice for the big banner
3625
	 * @return (string)
3626
	 */
3627
	function opt_out_jetpack_manage_url() {
3628
		$referer = '&_wp_http_referer=' . add_query_arg( '_wp_http_referer', null );
3629
		return wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=jetpack-manage-opt-out' . $referer ), 'jetpack_manage_banner_opt_out' );
3630
	}
3631
	/**
3632
	 * Returns the url that the user clicks to opt in to Jetpack Manage
3633
	 * @return (string)
3634
	 */
3635
	function opt_in_jetpack_manage_url() {
3636
		return wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=jetpack-manage-opt-in' ), 'jetpack_manage_banner_opt_in' );
3637
	}
3638
3639
	function opt_in_jetpack_manage_notice() {
3640
		?>
3641
		<div class="wrap">
3642
			<div id="message" class="jetpack-message is-opt-in">
3643
				<?php echo sprintf( __( '<p><a href="%1$s" title="Opt in to WordPress.com Site Management" >Activate Site Management</a> to manage multiple sites from our centralized dashboard at wordpress.com/sites. <a href="%2$s" target="_blank">Learn more</a>.</p><a href="%1$s" class="jp-button">Activate Now</a>', 'jetpack' ), $this->opt_in_jetpack_manage_url(), 'http://jetpack.me/support/site-management' ); ?>
3644
			</div>
3645
		</div>
3646
		<?php
3647
3648
	}
3649
	/**
3650
	 * Determines whether to show the notice of not true = display notice
3651
	 * @return (bool)
3652
	 */
3653
	function can_display_jetpack_manage_notice() {
3654
		// never display the notice to users that can't do anything about it anyways
3655
		if( ! current_user_can( 'jetpack_manage_modules' ) )
3656
			return false;
3657
3658
		// don't display if we are in development more
3659
		if( Jetpack::is_development_mode() ) {
3660
			return false;
3661
		}
3662
		// don't display if the site is private
3663
		if(  ! Jetpack_Options::get_option( 'public' ) )
3664
			return false;
3665
3666
		/**
3667
		 * Should the Jetpack Remote Site Management notice be displayed.
3668
		 *
3669
		 * @since 3.3.0
3670
		 *
3671
		 * @param bool ! self::is_module_active( 'manage' ) Is the Manage module inactive.
3672
		 */
3673
		return apply_filters( 'can_display_jetpack_manage_notice', ! self::is_module_active( 'manage' ) );
3674
	}
3675
3676
	function network_connect_notice() {
3677
		?>
3678
		<div id="message" class="updated jetpack-message">
3679
			<div class="squeezer">
3680
				<h2><?php _e( '<strong>Jetpack is activated!</strong> Each site on your network must be connected individually by an admin on that site.', 'jetpack' ) ?></h2>
3681
			</div>
3682
		</div>
3683
		<?php
3684
	}
3685
3686
	public static function jetpack_comment_notice() {
3687
		if ( in_array( 'comments', Jetpack::get_active_modules() ) ) {
3688
			return '';
3689
		}
3690
3691
		$jetpack_old_version = explode( ':', Jetpack_Options::get_option( 'old_version' ) );
3692
		$jetpack_new_version = explode( ':', Jetpack_Options::get_option( 'version' ) );
3693
3694
		if ( $jetpack_old_version ) {
3695
			if ( version_compare( $jetpack_old_version[0], '1.4', '>=' ) ) {
3696
				return '';
3697
			}
3698
		}
3699
3700
		if ( $jetpack_new_version ) {
3701
			if ( version_compare( $jetpack_new_version[0], '1.4-something', '<' ) ) {
3702
				return '';
3703
			}
3704
		}
3705
3706
		return '<br /><br />' . sprintf(
3707
			__( 'Jetpack now includes Comments, which enables your visitors to use their WordPress.com, Twitter, or Facebook accounts when commenting on your site. To activate Comments, <a href="%s">%s</a>.', 'jetpack' ),
3708
			wp_nonce_url(
3709
				Jetpack::admin_url(
3710
					array(
3711
						'page'   => 'jetpack',
3712
						'action' => 'activate',
3713
						'module' => 'comments',
3714
					)
3715
				),
3716
				'jetpack_activate-comments'
3717
			),
3718
			__( 'click here', 'jetpack' )
3719
		);
3720
	}
3721
3722
	/**
3723
	 * Show the survey link when the user has just disconnected Jetpack.
3724
	 */
3725
	function disconnect_survey_notice() {
3726
		?>
3727
		<div class="wrap">
3728
			<div id="message" class="jetpack-message stay-visible">
3729
				<div class="squeezer">
3730
					<h2>
3731
						<?php _e( 'You have successfully disconnected Jetpack.', 'jetpack' ); ?>
3732
						<br />
3733
						<?php echo sprintf(
3734
							__( 'Would you tell us why? Just <a href="%1$s" target="%2$s">answering two simple questions</a> would help us improve Jetpack.', 'jetpack' ),
3735
							'https://jetpack.me/survey-disconnected/',
3736
							'_blank'
3737
						); ?>
3738
					</h2>
3739
				</div>
3740
			</div>
3741
		</div>
3742
		<?php
3743
	}
3744
3745
	/*
3746
	 * Registration flow:
3747
	 * 1 - ::admin_page_load() action=register
3748
	 * 2 - ::try_registration()
3749
	 * 3 - ::register()
3750
	 *     - Creates jetpack_register option containing two secrets and a timestamp
3751
	 *     - Calls https://jetpack.wordpress.com/jetpack.register/1/ with
3752
	 *       siteurl, home, gmt_offset, timezone_string, site_name, secret_1, secret_2, site_lang, timeout, stats_id
3753
	 *     - That request to jetpack.wordpress.com does not immediately respond.  It first makes a request BACK to this site's
3754
	 *       xmlrpc.php?for=jetpack: RPC method: jetpack.verifyRegistration, Parameters: secret_1
3755
	 *     - The XML-RPC request verifies secret_1, deletes both secrets and responds with: secret_2
3756
	 *     - https://jetpack.wordpress.com/jetpack.register/1/ verifies that XML-RPC response (secret_2) then finally responds itself with
3757
	 *       jetpack_id, jetpack_secret, jetpack_public
3758
	 *     - ::register() then stores jetpack_options: id => jetpack_id, blog_token => jetpack_secret
3759
	 * 4 - redirect to https://jetpack.wordpress.com/jetpack.authorize/1/
3760
	 * 5 - user logs in with WP.com account
3761
	 * 6 - redirect to this site's wp-admin/index.php?page=jetpack&action=authorize with
3762
	 *     code <-- OAuth2 style authorization code
3763
	 * 7 - ::admin_page_load() action=authorize
3764
	 * 8 - Jetpack_Client_Server::authorize()
3765
	 * 9 - Jetpack_Client_Server::get_token()
3766
	 * 10- GET https://jetpack.wordpress.com/jetpack.token/1/ with
3767
	 *     client_id, client_secret, grant_type, code, redirect_uri:action=authorize, state, scope, user_email, user_login
3768
	 * 11- which responds with
3769
	 *     access_token, token_type, scope
3770
	 * 12- Jetpack_Client_Server::authorize() stores jetpack_options: user_token => access_token.$user_id
3771
	 * 13- Jetpack::activate_default_modules()
3772
	 *     Deactivates deprecated plugins
3773
	 *     Activates all default modules
3774
	 *     Catches errors: redirects to wp-admin/index.php?page=jetpack state:error=something
3775
	 * 14- redirect to this site's wp-admin/index.php?page=jetpack with state:message=authorized
3776
	 *     Done!
3777
	 */
3778
3779
	/**
3780
	 * Handles the page load events for the Jetpack admin page
3781
	 */
3782
	function admin_page_load() {
3783
		$error = false;
3784
3785
		// Make sure we have the right body class to hook stylings for subpages off of.
3786
		add_filter( 'admin_body_class', array( __CLASS__, 'add_jetpack_pagestyles' ) );
3787
3788
		if ( ! empty( $_GET['jetpack_restate'] ) ) {
3789
			// Should only be used in intermediate redirects to preserve state across redirects
3790
			Jetpack::restate();
3791
		}
3792
3793
		if ( isset( $_GET['connect_url_redirect'] ) ) {
3794
			// User clicked in the iframe to link their accounts
3795
			if ( ! Jetpack::is_user_connected() ) {
3796
				$connect_url = $this->build_connect_url( true );
3797
				if ( isset( $_GET['notes_iframe'] ) )
3798
					$connect_url .= '&notes_iframe';
3799
				wp_redirect( $connect_url );
3800
				exit;
3801
			} else {
3802
				Jetpack::state( 'message', 'already_authorized' );
3803
				wp_safe_redirect( Jetpack::admin_url() );
3804
				exit;
3805
			}
3806
		}
3807
3808
3809
		if ( isset( $_GET['action'] ) ) {
3810
			switch ( $_GET['action'] ) {
3811
			case 'authorize' :
3812
				if ( Jetpack::is_active() && Jetpack::is_user_connected() ) {
3813
					Jetpack::state( 'message', 'already_authorized' );
3814
					wp_safe_redirect( Jetpack::admin_url() );
3815
					exit;
3816
				}
3817
				Jetpack::log( 'authorize' );
3818
				$client_server = new Jetpack_Client_Server;
3819
				$client_server->authorize();
3820
				exit;
3821
			case 'register' :
3822
				if ( ! current_user_can( 'jetpack_connect' ) ) {
3823
					$error = 'cheatin';
3824
					break;
3825
				}
3826
				check_admin_referer( 'jetpack-register' );
3827
				Jetpack::log( 'register' );
3828
				Jetpack::maybe_set_version_option();
3829
				$registered = Jetpack::try_registration();
3830
				if ( is_wp_error( $registered ) ) {
3831
					$error = $registered->get_error_code();
3832
					Jetpack::state( 'error_description', $registered->get_error_message() );
3833
					break;
3834
				}
3835
3836
				wp_redirect( $this->build_connect_url( true ) );
3837
				exit;
3838
			case 'activate' :
3839
				if ( ! current_user_can( 'jetpack_activate_modules' ) ) {
3840
					$error = 'cheatin';
3841
					break;
3842
				}
3843
3844
				$module = stripslashes( $_GET['module'] );
3845
				check_admin_referer( "jetpack_activate-$module" );
3846
				Jetpack::log( 'activate', $module );
3847
				Jetpack::activate_module( $module );
3848
				// The following two lines will rarely happen, as Jetpack::activate_module normally exits at the end.
3849
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
3850
				exit;
3851
			case 'activate_default_modules' :
3852
				check_admin_referer( 'activate_default_modules' );
3853
				Jetpack::log( 'activate_default_modules' );
3854
				Jetpack::restate();
3855
				$min_version   = isset( $_GET['min_version'] ) ? $_GET['min_version'] : false;
3856
				$max_version   = isset( $_GET['max_version'] ) ? $_GET['max_version'] : false;
3857
				$other_modules = isset( $_GET['other_modules'] ) && is_array( $_GET['other_modules'] ) ? $_GET['other_modules'] : array();
3858
				Jetpack::activate_default_modules( $min_version, $max_version, $other_modules );
3859
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
3860
				exit;
3861
			case 'disconnect' :
3862
				if ( ! current_user_can( 'jetpack_disconnect' ) ) {
3863
					$error = 'cheatin';
3864
					break;
3865
				}
3866
3867
				check_admin_referer( 'jetpack-disconnect' );
3868
				Jetpack::log( 'disconnect' );
3869
				Jetpack::disconnect();
3870
				wp_safe_redirect( Jetpack::admin_url( 'disconnected=true' ) );
3871
				exit;
3872
			case 'reconnect' :
3873
				if ( ! current_user_can( 'jetpack_reconnect' ) ) {
3874
					$error = 'cheatin';
3875
					break;
3876
				}
3877
3878
				check_admin_referer( 'jetpack-reconnect' );
3879
				Jetpack::log( 'reconnect' );
3880
				$this->disconnect();
3881
				wp_redirect( $this->build_connect_url( true ) );
3882
				exit;
3883 View Code Duplication
			case 'deactivate' :
3884
				if ( ! current_user_can( 'jetpack_deactivate_modules' ) ) {
3885
					$error = 'cheatin';
3886
					break;
3887
				}
3888
3889
				$modules = stripslashes( $_GET['module'] );
3890
				check_admin_referer( "jetpack_deactivate-$modules" );
3891
				foreach ( explode( ',', $modules ) as $module ) {
3892
					Jetpack::log( 'deactivate', $module );
3893
					Jetpack::deactivate_module( $module );
3894
					Jetpack::state( 'message', 'module_deactivated' );
3895
				}
3896
				Jetpack::state( 'module', $modules );
3897
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
3898
				exit;
3899
			case 'unlink' :
3900
				$redirect = isset( $_GET['redirect'] ) ? $_GET['redirect'] : '';
3901
				check_admin_referer( 'jetpack-unlink' );
3902
				Jetpack::log( 'unlink' );
3903
				$this->unlink_user();
3904
				Jetpack::state( 'message', 'unlinked' );
3905
				if ( 'sub-unlink' == $redirect ) {
3906
					wp_safe_redirect( admin_url() );
3907
				} else {
3908
					wp_safe_redirect( Jetpack::admin_url( array( 'page' => $redirect ) ) );
3909
				}
3910
				exit;
3911
			default:
3912
				/**
3913
				 * Fires when a Jetpack admin page is loaded with an unrecognized parameter.
3914
				 *
3915
				 * @since 2.6.0
3916
				 *
3917
				 * @param string sanitize_key( $_GET['action'] ) Unrecognized URL parameter.
3918
				 */
3919
				do_action( 'jetpack_unrecognized_action', sanitize_key( $_GET['action'] ) );
3920
			}
3921
		}
3922
3923
		if ( ! $error = $error ? $error : Jetpack::state( 'error' ) ) {
3924
			self::activate_new_modules( true );
3925
		}
3926
3927
		switch ( $error ) {
3928
		case 'cheatin' :
3929
			$this->error = __( 'Cheatin&#8217; uh?', 'jetpack' );
3930
			break;
3931
		case 'access_denied' :
3932
			$this->error = __( 'You need to authorize the Jetpack connection between your site and WordPress.com to enable the awesome features.', 'jetpack' );
3933
			break;
3934
		case 'wrong_state' :
3935
			$this->error = __( 'Don&#8217;t cross the streams!  You need to stay logged in to your WordPress blog while you authorize Jetpack.', 'jetpack' );
3936
			break;
3937
		case 'invalid_client' :
3938
			// @todo re-register instead of deactivate/reactivate
3939
			$this->error = __( 'Return to sender.  Whoops! It looks like you got the wrong Jetpack in the mail; deactivate then reactivate the Jetpack plugin to get a new one.', 'jetpack' );
3940
			break;
3941
		case 'invalid_grant' :
3942
			$this->error = __( 'Wrong size.  Hm&#8230; it seems your Jetpack doesn&#8217;t quite fit.  Have you lost weight? Click &#8220;Connect to WordPress.com&#8221; again to get your Jetpack adjusted.', 'jetpack' );
3943
			break;
3944
		case 'site_inaccessible' :
3945
		case 'site_requires_authorization' :
3946
			$this->error = sprintf( __( 'Your website needs to be publicly accessible to use Jetpack: %s', 'jetpack' ), "<code>$error</code>" );
3947
			break;
3948
		case 'module_activation_failed' :
3949
			$module = Jetpack::state( 'module' );
3950
			if ( ! empty( $module ) && $mod = Jetpack::get_module( $module ) ) {
3951
				$this->error = sprintf( __( '%s could not be activated because it triggered a <strong>fatal error</strong>. Perhaps there is a conflict with another plugin you have installed?', 'jetpack' ), $mod['name'] );
3952
				if ( isset( $this->plugins_to_deactivate[$module] ) ) {
3953
					$this->error .= ' ' . sprintf( __( 'Do you still have the %s plugin installed?', 'jetpack' ), $this->plugins_to_deactivate[$module][1] );
3954
				}
3955
			} else {
3956
				$this->error = __( 'Module could not be activated because it triggered a <strong>fatal error</strong>. Perhaps there is a conflict with another plugin you have installed?', 'jetpack' );
3957
			}
3958
			if ( $php_errors = Jetpack::state( 'php_errors' ) ) {
3959
				$this->error .= "<br />\n";
3960
				$this->error .= $php_errors;
3961
			}
3962
			break;
3963
		case 'master_user_required' :
3964
			$module = Jetpack::state( 'module' );
3965
			$module_name = '';
3966
			if ( ! empty( $module ) && $mod = Jetpack::get_module( $module ) ) {
3967
				$module_name = $mod['name'];
3968
			}
3969
3970
			$master_user = Jetpack_Options::get_option( 'master_user' );
3971
			$master_userdata = get_userdata( $master_user ) ;
3972
			if ( $master_userdata ) {
3973
				if ( ! in_array( $module, Jetpack::get_active_modules() ) ) {
3974
					$this->error = sprintf( __( '%s was not activated.' , 'jetpack' ), $module_name );
3975
				} else {
3976
					$this->error = sprintf( __( '%s was not deactivated.' , 'jetpack' ), $module_name );
3977
				}
3978
				$this->error .= '  ' . sprintf( __( 'This module can only be altered by %s, the user who initiated the Jetpack connection on this site.' , 'jetpack' ), esc_html( $master_userdata->display_name ) );
3979
3980
			} else {
3981
				$this->error = sprintf( __( 'Only the user who initiated the Jetpack connection on this site can toggle %s, but that user no longer exists. This should not happen.', 'jetpack' ), $module_name );
3982
			}
3983
			break;
3984
		case 'not_public' :
3985
			$this->error = __( '<strong>Your Jetpack has a glitch.</strong> Connecting this site with WordPress.com is not possible. This usually means your site is not publicly accessible (localhost).', 'jetpack' );
3986
			break;
3987
		case 'wpcom_408' :
3988
		case 'wpcom_5??' :
3989
		case 'wpcom_bad_response' :
3990
		case 'wpcom_outage' :
3991
			$this->error = __( 'WordPress.com is currently having problems and is unable to fuel up your Jetpack.  Please try again later.', 'jetpack' );
3992
			break;
3993
		case 'register_http_request_failed' :
3994
		case 'token_http_request_failed' :
3995
			$this->error = sprintf( __( 'Jetpack could not contact WordPress.com: %s.  This usually means something is incorrectly configured on your web host.', 'jetpack' ), "<code>$error</code>" );
3996
			break;
3997
		default :
3998
			if ( empty( $error ) ) {
3999
				break;
4000
			}
4001
			$error = trim( substr( strip_tags( $error ), 0, 20 ) );
4002
			// no break: fall through
4003
		case 'no_role' :
4004
		case 'no_cap' :
4005
		case 'no_code' :
4006
		case 'no_state' :
4007
		case 'invalid_state' :
4008
		case 'invalid_request' :
4009
		case 'invalid_scope' :
4010
		case 'unsupported_response_type' :
4011
		case 'invalid_token' :
4012
		case 'no_token' :
4013
		case 'missing_secrets' :
4014
		case 'home_missing' :
4015
		case 'siteurl_missing' :
4016
		case 'gmt_offset_missing' :
4017
		case 'site_name_missing' :
4018
		case 'secret_1_missing' :
4019
		case 'secret_2_missing' :
4020
		case 'site_lang_missing' :
4021
		case 'home_malformed' :
4022
		case 'siteurl_malformed' :
4023
		case 'gmt_offset_malformed' :
4024
		case 'timezone_string_malformed' :
4025
		case 'site_name_malformed' :
4026
		case 'secret_1_malformed' :
4027
		case 'secret_2_malformed' :
4028
		case 'site_lang_malformed' :
4029
		case 'secrets_mismatch' :
4030
		case 'verify_secret_1_missing' :
4031
		case 'verify_secret_1_malformed' :
4032
		case 'verify_secrets_missing' :
4033
		case 'verify_secrets_mismatch' :
4034
			$error = esc_html( $error );
4035
			$this->error = sprintf( __( '<strong>Your Jetpack has a glitch.</strong>  Something went wrong that&#8217;s never supposed to happen.  Guess you&#8217;re just lucky: %s', 'jetpack' ), "<code>$error</code>" );
4036
			if ( ! Jetpack::is_active() ) {
4037
				$this->error .= '<br />';
4038
				$this->error .= sprintf( __( 'Try connecting again.', 'jetpack' ) );
4039
			}
4040
			break;
4041
		}
4042
4043
		$message_code = Jetpack::state( 'message' );
4044
4045
		$active_state = Jetpack::state( 'activated_modules' );
4046
		if ( ! empty( $active_state ) ) {
4047
			$available    = Jetpack::get_available_modules();
4048
			$active_state = explode( ',', $active_state );
4049
			$active_state = array_intersect( $active_state, $available );
4050
			if ( count( $active_state ) ) {
4051
				foreach ( $active_state as $mod ) {
4052
					$this->stat( 'module-activated', $mod );
4053
				}
4054
			} else {
4055
				$active_state = false;
4056
			}
4057
		}
4058
		if( Jetpack::state( 'optin-manage' ) ) {
4059
			$activated_manage = $message_code;
4060
			$message_code = 'jetpack-manage';
4061
4062
		}
4063
		switch ( $message_code ) {
4064
		case 'modules_activated' :
4065
			$this->message = sprintf(
4066
				__( 'Welcome to <strong>Jetpack %s</strong>!', 'jetpack' ),
4067
				JETPACK__VERSION
4068
			);
4069
4070
			if ( $active_state ) {
4071
				$titles = array();
4072 View Code Duplication
				foreach ( $active_state as $mod ) {
4073
					if ( $mod_headers = Jetpack::get_module( $mod ) ) {
4074
						$titles[] = '<strong>' . preg_replace( '/\s+(?![^<>]++>)/', '&nbsp;', $mod_headers['name'] ) . '</strong>';
4075
					}
4076
				}
4077
				if ( $titles ) {
4078
					$this->message .= '<br /><br />' . wp_sprintf( __( 'The following new modules have been activated: %l.', 'jetpack' ), $titles );
4079
				}
4080
			}
4081
4082
			if ( $reactive_state = Jetpack::state( 'reactivated_modules' ) ) {
4083
				$titles = array();
4084 View Code Duplication
				foreach ( explode( ',',  $reactive_state ) as $mod ) {
4085
					if ( $mod_headers = Jetpack::get_module( $mod ) ) {
4086
						$titles[] = '<strong>' . preg_replace( '/\s+(?![^<>]++>)/', '&nbsp;', $mod_headers['name'] ) . '</strong>';
4087
					}
4088
				}
4089
				if ( $titles ) {
4090
					$this->message .= '<br /><br />' . wp_sprintf( __( 'The following modules have been updated: %l.', 'jetpack' ), $titles );
4091
				}
4092
			}
4093
4094
			$this->message .= Jetpack::jetpack_comment_notice();
4095
			break;
4096
		case 'jetpack-manage':
4097
			$this->message = '<strong>' . sprintf( __( 'You are all set! Your site can now be managed from <a href="%s" target="_blank">wordpress.com/sites</a>.', 'jetpack' ), 'https://wordpress.com/sites' ) . '</strong>';
4098
			if ( $activated_manage ) {
4099
				$this->message .= '<br /><strong>' . __( 'Manage has been activated for you!', 'jetpack'  ) . '</strong>';
4100
			}
4101
			break;
4102
		case 'module_activated' :
4103
			if ( $module = Jetpack::get_module( Jetpack::state( 'module' ) ) ) {
4104
				$this->message = sprintf( __( '<strong>%s Activated!</strong> You can deactivate at any time by clicking the Deactivate link next to each module.', 'jetpack' ), $module['name'] );
4105
				$this->stat( 'module-activated', Jetpack::state( 'module' ) );
4106
			}
4107
			break;
4108
4109
		case 'module_deactivated' :
4110
			$modules = Jetpack::state( 'module' );
4111
			if ( ! $modules ) {
4112
				break;
4113
			}
4114
4115
			$module_names = array();
4116
			foreach ( explode( ',', $modules ) as $module_slug ) {
4117
				$module = Jetpack::get_module( $module_slug );
4118
				if ( $module ) {
4119
					$module_names[] = $module['name'];
4120
				}
4121
4122
				$this->stat( 'module-deactivated', $module_slug );
4123
			}
4124
4125
			if ( ! $module_names ) {
4126
				break;
4127
			}
4128
4129
			$this->message = wp_sprintf(
4130
				_nx(
4131
					'<strong>%l Deactivated!</strong> You can activate it again at any time using the activate link next to each module.',
4132
					'<strong>%l Deactivated!</strong> You can activate them again at any time using the activate links next to each module.',
4133
					count( $module_names ),
4134
					'%l = list of Jetpack module/feature names',
4135
					'jetpack'
4136
				),
4137
				$module_names
4138
			);
4139
			break;
4140
4141
		case 'module_configured' :
4142
			$this->message = __( '<strong>Module settings were saved.</strong> ', 'jetpack' );
4143
			break;
4144
4145
		case 'already_authorized' :
4146
			$this->message = __( '<strong>Your Jetpack is already connected.</strong> ', 'jetpack' );
4147
			break;
4148
4149
		case 'authorized' :
4150
			$this->message  = __( '<strong>You&#8217;re fueled up and ready to go, Jetpack is now active.</strong> ', 'jetpack' );
4151
			$this->message .= Jetpack::jetpack_comment_notice();
4152
			break;
4153
4154
		case 'linked' :
4155
			$this->message  = __( '<strong>You&#8217;re fueled up and ready to go.</strong> ', 'jetpack' );
4156
			$this->message .= Jetpack::jetpack_comment_notice();
4157
			break;
4158
4159
		case 'unlinked' :
4160
			$user = wp_get_current_user();
4161
			$this->message = sprintf( __( '<strong>You have unlinked your account (%s) from WordPress.com.</strong>', 'jetpack' ), $user->user_login );
4162
			break;
4163
4164
		case 'switch_master' :
4165
			global $current_user;
4166
			$is_master_user = $current_user->ID == Jetpack_Options::get_option( 'master_user' );
4167
			$master_userdata = get_userdata( Jetpack_Options::get_option( 'master_user' ) );
4168
			if ( $is_master_user ) {
4169
				$this->message = __( 'You have successfully set yourself as Jetpack’s primary user.', 'jetpack' );
4170
			} else {
4171
				$this->message = sprintf( _x( 'You have successfully set %s as Jetpack’s primary user.', '%s is a username', 'jetpack' ), $master_userdata->user_login );
4172
			}
4173
			break;
4174
		}
4175
4176
		$deactivated_plugins = Jetpack::state( 'deactivated_plugins' );
4177
4178
		if ( ! empty( $deactivated_plugins ) ) {
4179
			$deactivated_plugins = explode( ',', $deactivated_plugins );
4180
			$deactivated_titles  = array();
4181
			foreach ( $deactivated_plugins as $deactivated_plugin ) {
4182
				if ( ! isset( $this->plugins_to_deactivate[$deactivated_plugin] ) ) {
4183
					continue;
4184
				}
4185
4186
				$deactivated_titles[] = '<strong>' . str_replace( ' ', '&nbsp;', $this->plugins_to_deactivate[$deactivated_plugin][1] ) . '</strong>';
4187
			}
4188
4189
			if ( $deactivated_titles ) {
4190
				if ( $this->message ) {
4191
					$this->message .= "<br /><br />\n";
4192
				}
4193
4194
				$this->message .= wp_sprintf(
4195
					_n(
4196
						'Jetpack contains the most recent version of the old %l plugin.',
4197
						'Jetpack contains the most recent versions of the old %l plugins.',
4198
						count( $deactivated_titles ),
4199
						'jetpack'
4200
					),
4201
					$deactivated_titles
4202
				);
4203
4204
				$this->message .= "<br />\n";
4205
4206
				$this->message .= _n(
4207
					'The old version has been deactivated and can be removed from your site.',
4208
					'The old versions have been deactivated and can be removed from your site.',
4209
					count( $deactivated_titles ),
4210
					'jetpack'
4211
				);
4212
			}
4213
		}
4214
4215
		$this->privacy_checks = Jetpack::state( 'privacy_checks' );
4216
4217
		if ( $this->message || $this->error || $this->privacy_checks || $this->can_display_jetpack_manage_notice() ) {
4218
			add_action( 'jetpack_notices', array( $this, 'admin_notices' ) );
4219
		}
4220
4221 View Code Duplication
		if ( isset( $_GET['configure'] ) && Jetpack::is_module( $_GET['configure'] ) && current_user_can( 'manage_options' ) ) {
4222
			/**
4223
			 * Fires when a module configuration page is loaded.
4224
			 * The dynamic part of the hook is the configure parameter from the URL.
4225
			 *
4226
			 * @since 1.1.0
4227
			 */
4228
			do_action( 'jetpack_module_configuration_load_' . $_GET['configure'] );
4229
		}
4230
4231
		add_filter( 'jetpack_short_module_description', 'wptexturize' );
4232
	}
4233
4234
	function admin_notices() {
4235
4236
		if ( $this->error ) {
4237
?>
4238
<div id="message" class="jetpack-message jetpack-err">
4239
	<div class="squeezer">
4240
		<h2><?php echo wp_kses( $this->error, array( 'code' => true, 'strong' => true, 'br' => true, 'b' => true ) ); ?></h2>
4241
<?php	if ( $desc = Jetpack::state( 'error_description' ) ) : ?>
4242
		<p><?php echo esc_html( stripslashes( $desc ) ); ?></p>
4243
<?php	endif; ?>
4244
	</div>
4245
</div>
4246
<?php
4247
		}
4248
4249
		if ( $this->message ) {
4250
?>
4251
<div id="message" class="jetpack-message">
4252
	<div class="squeezer">
4253
		<h2><?php echo wp_kses( $this->message, array( 'strong' => array(), 'a' => array( 'href' => true ), 'br' => true ) ); ?></h2>
4254
	</div>
4255
</div>
4256
<?php
4257
		}
4258
4259
		if ( $this->privacy_checks ) :
4260
			$module_names = $module_slugs = array();
4261
4262
			$privacy_checks = explode( ',', $this->privacy_checks );
4263
			$privacy_checks = array_filter( $privacy_checks, array( 'Jetpack', 'is_module' ) );
4264
			foreach ( $privacy_checks as $module_slug ) {
4265
				$module = Jetpack::get_module( $module_slug );
4266
				if ( ! $module ) {
4267
					continue;
4268
				}
4269
4270
				$module_slugs[] = $module_slug;
4271
				$module_names[] = "<strong>{$module['name']}</strong>";
4272
			}
4273
4274
			$module_slugs = join( ',', $module_slugs );
4275
?>
4276
<div id="message" class="jetpack-message jetpack-err">
4277
	<div class="squeezer">
4278
		<h2><strong><?php esc_html_e( 'Is this site private?', 'jetpack' ); ?></strong></h2><br />
4279
		<p><?php
4280
			echo wp_kses(
4281
				wptexturize(
4282
					wp_sprintf(
4283
						_nx(
4284
							"Like your site's RSS feeds, %l allows access to your posts and other content to third parties.",
4285
							"Like your site's RSS feeds, %l allow access to your posts and other content to third parties.",
4286
							count( $privacy_checks ),
4287
							'%l = list of Jetpack module/feature names',
4288
							'jetpack'
4289
						),
4290
						$module_names
4291
					)
4292
				),
4293
				array( 'strong' => true )
4294
			);
4295
4296
			echo "\n<br />\n";
4297
4298
			echo wp_kses(
4299
				sprintf(
4300
					_nx(
4301
						'If your site is not publicly accessible, consider <a href="%1$s" title="%2$s">deactivating this feature</a>.',
4302
						'If your site is not publicly accessible, consider <a href="%1$s" title="%2$s">deactivating these features</a>.',
4303
						count( $privacy_checks ),
4304
						'%1$s = deactivation URL, %2$s = "Deactivate {list of Jetpack module/feature names}',
4305
						'jetpack'
4306
					),
4307
					wp_nonce_url(
4308
						Jetpack::admin_url(
4309
							array(
4310
								'page'   => 'jetpack',
4311
								'action' => 'deactivate',
4312
								'module' => urlencode( $module_slugs ),
4313
							)
4314
						),
4315
						"jetpack_deactivate-$module_slugs"
4316
					),
4317
					esc_attr( wp_kses( wp_sprintf( _x( 'Deactivate %l', '%l = list of Jetpack module/feature names', 'jetpack' ), $module_names ), array() ) )
4318
				),
4319
				array( 'a' => array( 'href' => true, 'title' => true ) )
4320
			);
4321
		?></p>
4322
	</div>
4323
</div>
4324
<?php endif;
4325
	// only display the notice if the other stuff is not there
4326
	if( $this->can_display_jetpack_manage_notice() && !  $this->error && ! $this->message && ! $this->privacy_checks ) {
4327
		if( isset( $_GET['page'] ) && 'jetpack' != $_GET['page'] )
4328
			$this->opt_in_jetpack_manage_notice();
4329
		}
4330
	}
4331
4332
	/**
4333
	 * Record a stat for later output.  This will only currently output in the admin_footer.
4334
	 */
4335
	function stat( $group, $detail ) {
4336
		if ( ! isset( $this->stats[ $group ] ) )
4337
			$this->stats[ $group ] = array();
4338
		$this->stats[ $group ][] = $detail;
4339
	}
4340
4341
	/**
4342
	 * Load stats pixels. $group is auto-prefixed with "x_jetpack-"
4343
	 */
4344
	function do_stats( $method = '' ) {
4345
		if ( is_array( $this->stats ) && count( $this->stats ) ) {
4346
			foreach ( $this->stats as $group => $stats ) {
4347
				if ( is_array( $stats ) && count( $stats ) ) {
4348
					$args = array( "x_jetpack-{$group}" => implode( ',', $stats ) );
4349
					if ( 'server_side' === $method ) {
4350
						self::do_server_side_stat( $args );
4351
					} else {
4352
						echo '<img src="' . esc_url( self::build_stats_url( $args ) ) . '" width="1" height="1" style="display:none;" />';
4353
					}
4354
				}
4355
				unset( $this->stats[ $group ] );
4356
			}
4357
		}
4358
	}
4359
4360
	/**
4361
	 * Runs stats code for a one-off, server-side.
4362
	 *
4363
	 * @param $args array|string The arguments to append to the URL. Should include `x_jetpack-{$group}={$stats}` or whatever we want to store.
4364
	 *
4365
	 * @return bool If it worked.
4366
	 */
4367
	static function do_server_side_stat( $args ) {
4368
		$response = wp_remote_get( esc_url_raw( self::build_stats_url( $args ) ) );
4369
		if ( is_wp_error( $response ) )
4370
			return false;
4371
4372
		if ( 200 !== wp_remote_retrieve_response_code( $response ) )
4373
			return false;
4374
4375
		return true;
4376
	}
4377
4378
	/**
4379
	 * Builds the stats url.
4380
	 *
4381
	 * @param $args array|string The arguments to append to the URL.
4382
	 *
4383
	 * @return string The URL to be pinged.
4384
	 */
4385
	static function build_stats_url( $args ) {
4386
		$defaults = array(
4387
			'v'    => 'wpcom2',
4388
			'rand' => md5( mt_rand( 0, 999 ) . time() ),
4389
		);
4390
		$args     = wp_parse_args( $args, $defaults );
4391
		/**
4392
		 * Filter the URL used as the Stats tracking pixel.
4393
		 *
4394
		 * @since 2.3.2
4395
		 *
4396
		 * @param string $url Base URL used as the Stats tracking pixel.
4397
		 */
4398
		$base_url = apply_filters(
4399
			'jetpack_stats_base_url',
4400
			set_url_scheme( 'http://pixel.wp.com/g.gif' )
4401
		);
4402
		$url      = add_query_arg( $args, $base_url );
4403
		return $url;
4404
	}
4405
4406
	function translate_current_user_to_role() {
4407
		foreach ( $this->capability_translations as $role => $cap ) {
4408
			if ( current_user_can( $role ) || current_user_can( $cap ) ) {
4409
				return $role;
4410
			}
4411
		}
4412
4413
		return false;
4414
	}
4415
4416
	function translate_role_to_cap( $role ) {
4417
		if ( ! isset( $this->capability_translations[$role] ) ) {
4418
			return false;
4419
		}
4420
4421
		return $this->capability_translations[$role];
4422
	}
4423
4424
	function sign_role( $role ) {
4425
		if ( ! $user_id = (int) get_current_user_id() ) {
4426
			return false;
4427
		}
4428
4429
		$token = Jetpack_Data::get_access_token();
4430
		if ( ! $token || is_wp_error( $token ) ) {
4431
			return false;
4432
		}
4433
4434
		return $role . ':' . hash_hmac( 'md5', "{$role}|{$user_id}", $token->secret );
4435
	}
4436
4437
	function build_connect_url( $raw = false, $redirect = false ) {
4438
		if ( ! Jetpack_Options::get_option( 'blog_token' ) || ! Jetpack_Options::get_option( 'id' ) ) {
4439
			$url = Jetpack::nonce_url_no_esc( Jetpack::admin_url( 'action=register' ), 'jetpack-register' );
4440
			if( is_network_admin() ) {
4441
			    $url = add_query_arg( 'is_multisite', network_admin_url(
4442
			    'admin.php?page=jetpack-settings' ), $url );
4443
			}
4444
		} else {
4445
			$role = $this->translate_current_user_to_role();
4446
			$signed_role = $this->sign_role( $role );
4447
4448
			$user = wp_get_current_user();
4449
4450
			$redirect = $redirect ? esc_url_raw( $redirect ) : '';
4451
4452
			if( isset( $_REQUEST['is_multisite'] ) ) {
4453
				$redirect = Jetpack_Network::init()->get_url( 'network_admin_page' );
4454
			}
4455
4456
			$args = urlencode_deep(
4457
				array(
4458
					'response_type' => 'code',
4459
					'client_id'     => Jetpack_Options::get_option( 'id' ),
4460
					'redirect_uri'  => add_query_arg(
4461
						array(
4462
							'action'   => 'authorize',
4463
							'_wpnonce' => wp_create_nonce( "jetpack-authorize_{$role}_{$redirect}" ),
4464
							'redirect' => $redirect ? urlencode( $redirect ) : false,
4465
						),
4466
						menu_page_url( 'jetpack', false )
4467
					),
4468
					'state'         => $user->ID,
4469
					'scope'         => $signed_role,
4470
					'user_email'    => $user->user_email,
4471
					'user_login'    => $user->user_login,
4472
					'is_active'     => Jetpack::is_active(),
4473
					'jp_version'    => JETPACK__VERSION,
4474
				)
4475
			);
4476
4477
			$url = add_query_arg( $args, Jetpack::api_url( 'authorize' ) );
4478
		}
4479
4480
		return $raw ? $url : esc_url( $url );
4481
	}
4482
4483
	function build_reconnect_url( $raw = false ) {
4484
		$url = wp_nonce_url( Jetpack::admin_url( 'action=reconnect' ), 'jetpack-reconnect' );
4485
		return $raw ? $url : esc_url( $url );
4486
	}
4487
4488
	public static function admin_url( $args = null ) {
4489
		$args = wp_parse_args( $args, array( 'page' => 'jetpack' ) );
4490
		$url = add_query_arg( $args, admin_url( 'admin.php' ) );
4491
		return $url;
4492
	}
4493
4494
	public static function nonce_url_no_esc( $actionurl, $action = -1, $name = '_wpnonce' ) {
4495
		$actionurl = str_replace( '&amp;', '&', $actionurl );
4496
		return add_query_arg( $name, wp_create_nonce( $action ), $actionurl );
4497
	}
4498
4499
	function dismiss_jetpack_notice() {
4500
4501
		if ( ! isset( $_GET['jetpack-notice'] ) ) {
4502
			return;
4503
		}
4504
4505
		switch( $_GET['jetpack-notice'] ) {
4506
			case 'dismiss':
4507
				if ( check_admin_referer( 'jetpack-deactivate' ) && ! is_plugin_active_for_network( plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' ) ) ) {
4508
4509
					require_once ABSPATH . 'wp-admin/includes/plugin.php';
4510
					deactivate_plugins( JETPACK__PLUGIN_DIR . 'jetpack.php', false, false );
4511
					wp_safe_redirect( admin_url() . 'plugins.php?deactivate=true&plugin_status=all&paged=1&s=' );
4512
				}
4513
				break;
4514 View Code Duplication
			case 'jetpack-manage-opt-out':
4515
4516
				if ( check_admin_referer( 'jetpack_manage_banner_opt_out' ) ) {
4517
					// Don't show the banner again
4518
4519
					Jetpack_Options::update_option( 'dismissed_manage_banner', true );
4520
					// redirect back to the page that had the notice
4521
					if ( wp_get_referer() ) {
4522
						wp_safe_redirect( wp_get_referer() );
4523
					} else {
4524
						// Take me to Jetpack
4525
						wp_safe_redirect( admin_url( 'admin.php?page=jetpack' ) );
4526
					}
4527
				}
4528
				break;
4529 View Code Duplication
			case 'jetpack-protect-multisite-opt-out':
4530
4531
				if ( check_admin_referer( 'jetpack_protect_multisite_banner_opt_out' ) ) {
4532
					// Don't show the banner again
4533
4534
					update_site_option( 'jetpack_dismissed_protect_multisite_banner', true );
4535
					// redirect back to the page that had the notice
4536
					if ( wp_get_referer() ) {
4537
						wp_safe_redirect( wp_get_referer() );
4538
					} else {
4539
						// Take me to Jetpack
4540
						wp_safe_redirect( admin_url( 'admin.php?page=jetpack' ) );
4541
					}
4542
				}
4543
				break;
4544
			case 'jetpack-manage-opt-in':
4545
				if ( check_admin_referer( 'jetpack_manage_banner_opt_in' ) ) {
4546
					// This makes sure that we are redirect to jetpack home so that we can see the Success Message.
4547
4548
					$redirection_url = Jetpack::admin_url();
4549
					remove_action( 'jetpack_pre_activate_module',   array( Jetpack_Admin::init(), 'fix_redirect' ) );
4550
4551
					// Don't redirect form the Jetpack Setting Page
4552
					$referer_parsed = parse_url ( wp_get_referer() );
4553
					// check that we do have a wp_get_referer and the query paramater is set orderwise go to the Jetpack Home
4554
					if ( isset( $referer_parsed['query'] ) && false !== strpos( $referer_parsed['query'], 'page=jetpack_modules' ) ) {
4555
						// Take the user to Jetpack home except when on the setting page
4556
						$redirection_url = wp_get_referer();
4557
						add_action( 'jetpack_pre_activate_module',   array( Jetpack_Admin::init(), 'fix_redirect' ) );
4558
					}
4559
					// Also update the JSON API FULL MANAGEMENT Option
4560
					Jetpack::activate_module( 'manage', false, false );
4561
4562
					// Special Message when option in.
4563
					Jetpack::state( 'optin-manage', 'true' );
4564
					// Activate the Module if not activated already
4565
4566
					// Redirect properly
4567
					wp_safe_redirect( $redirection_url );
4568
4569
				}
4570
				break;
4571
		}
4572
	}
4573
4574
	function debugger_page() {
4575
		nocache_headers();
4576
		if ( ! current_user_can( 'manage_options' ) ) {
4577
			die( '-1' );
4578
		}
4579
		Jetpack_Debugger::jetpack_debug_display_handler();
4580
		exit;
4581
	}
4582
4583
	public static function admin_screen_configure_module( $module_id ) {
4584
4585
		// User that doesn't have 'jetpack_configure_modules' will never end up here since Jetpack Landing Page woun't let them.
4586
		if ( ! in_array( $module_id, Jetpack::get_active_modules() ) && current_user_can( 'manage_options' ) ) {
4587
			if ( has_action( 'display_activate_module_setting_' . $module_id ) ) {
4588
				/**
4589
				 * Fires to diplay a custom module activation screen.
4590
				 *
4591
				 * To add a module actionation screen use Jetpack::module_configuration_activation_screen method.
4592
				 * Example: Jetpack::module_configuration_activation_screen( 'manage', array( $this, 'manage_activate_screen' ) );
4593
				 *
4594
				 * @module manage
4595
				 *
4596
				 * @since 3.8.0
4597
				 *
4598
				 * @param int $module_id Module ID.
4599
				 */
4600
				do_action( 'display_activate_module_setting_' . $module_id );
4601
			} else {
4602
				self::display_activate_module_link( $module_id );
4603
			}
4604
4605
			return false;
4606
		} ?>
4607
4608
		<div id="jp-settings-screen" style="position: relative">
4609
			<h3>
4610
			<?php
4611
				$module = Jetpack::get_module( $module_id );
4612
				echo '<a href="' . Jetpack::admin_url( 'page=jetpack_modules' ) . '">' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</a> &rarr; ';
4613
				printf( __( 'Configure %s', 'jetpack' ), $module['name'] );
4614
			?>
4615
			</h3>
4616
			<?php
4617
				/**
4618
				 * Fires within the displayed message when a feature configuation is updated.
4619
				 *
4620
				 * @since 3.4.0
4621
				 *
4622
				 * @param int $module_id Module ID.
4623
				 */
4624
				do_action( 'jetpack_notices_update_settings', $module_id );
4625
				/**
4626
				 * Fires when a feature configuation screen is loaded.
4627
				 * The dynamic part of the hook, $module_id, is the module ID.
4628
				 *
4629
				 * @since 1.1.0
4630
				 */
4631
				do_action( 'jetpack_module_configuration_screen_' . $module_id );
4632
			?>
4633
		</div><?php
4634
	}
4635
4636
	/**
4637
	 * Display link to activate the module to see the settings screen.
4638
	 * @param  string $module_id
4639
	 * @return null
4640
	 */
4641
	public static function display_activate_module_link( $module_id ) {
4642
4643
		$info =  Jetpack::get_module( $module_id );
4644
		$extra = '';
4645
		$activate_url = wp_nonce_url(
4646
				Jetpack::admin_url(
4647
					array(
4648
						'page'   => 'jetpack',
4649
						'action' => 'activate',
4650
						'module' => $module_id,
4651
					)
4652
				),
4653
				"jetpack_activate-$module_id"
4654
			);
4655
4656
		?>
4657
4658
		<div class="wrap configure-module">
4659
			<div id="jp-settings-screen">
4660
				<?php
4661
				if ( $module_id == 'json-api' ) {
4662
4663
					$info['name'] = esc_html__( 'Activate Site Management and JSON API', 'jetpack' );
4664
4665
					$activate_url = Jetpack::init()->opt_in_jetpack_manage_url();
4666
4667
					$info['description'] = sprintf( __( 'Manage your multiple Jetpack sites from our centralized dashboard at wordpress.com/sites. <a href="%s" target="_blank">Learn more</a>.', 'jetpack' ), 'http://jetpack.me/support/site-management' );
4668
4669
					// $extra = __( 'To use Site Management, you need to first activate JSON API to allow remote management of your site. ', 'jetpack' );
4670
				} ?>
4671
4672
				<h3><?php echo esc_html( $info['name'] ); ?></h3>
4673
				<div class="narrow">
4674
					<p><?php echo  $info['description']; ?></p>
4675
					<?php if( $extra ) { ?>
4676
					<p><?php echo esc_html( $extra ); ?></p>
4677
					<?php } ?>
4678
					<p>
4679
						<?php
4680
						if( wp_get_referer() ) {
4681
							printf( __( '<a class="button-primary" href="%s">Activate Now</a> or <a href="%s" >return to previous page</a>.', 'jetpack' ) , $activate_url, wp_get_referer() );
4682
						} else {
4683
							printf( __( '<a class="button-primary" href="%s">Activate Now</a>', 'jetpack' ) , $activate_url  );
4684
						} ?>
4685
					</p>
4686
				</div>
4687
4688
			</div>
4689
		</div>
4690
4691
		<?php
4692
	}
4693
4694
	public static function sort_modules( $a, $b ) {
4695
		if ( $a['sort'] == $b['sort'] )
4696
			return 0;
4697
4698
		return ( $a['sort'] < $b['sort'] ) ? -1 : 1;
4699
	}
4700
4701 View Code Duplication
	function sync_reindex_trigger() {
4702
		if ( $this->current_user_is_connection_owner() && current_user_can( 'manage_options' ) ) {
4703
			echo json_encode( $this->sync->reindex_trigger() );
4704
		} else {
4705
			echo '{"status":"ERROR"}';
4706
		}
4707
		exit;
4708
	}
4709
4710 View Code Duplication
	function sync_reindex_status(){
4711
		if ( $this->current_user_is_connection_owner() && current_user_can( 'manage_options' ) ) {
4712
			echo json_encode( $this->sync->reindex_status() );
4713
		} else {
4714
			echo '{"status":"ERROR"}';
4715
		}
4716
		exit;
4717
	}
4718
4719
/* Client API */
4720
4721
	/**
4722
	 * Returns the requested Jetpack API URL
4723
	 *
4724
	 * @return string
4725
	 */
4726
	public static function api_url( $relative_url ) {
4727
		return trailingslashit( JETPACK__API_BASE . $relative_url  ) . JETPACK__API_VERSION . '/';
4728
	}
4729
4730
	/**
4731
	 * Some hosts disable the OpenSSL extension and so cannot make outgoing HTTPS requsets
4732
	 */
4733
	public static function fix_url_for_bad_hosts( $url ) {
4734
		if ( 0 !== strpos( $url, 'https://' ) ) {
4735
			return $url;
4736
		}
4737
4738
		switch ( JETPACK_CLIENT__HTTPS ) {
4739
			case 'ALWAYS' :
4740
				return $url;
4741
			case 'NEVER' :
4742
				return set_url_scheme( $url, 'http' );
4743
			// default : case 'AUTO' :
4744
		}
4745
4746
		// Yay! Your host is good!
4747
		if ( self::permit_ssl() && wp_http_supports( array( 'ssl' => true ) ) ) {
4748
			return $url;
4749
		}
4750
4751
		// Boo! Your host is bad and makes Jetpack cry!
4752
		return set_url_scheme( $url, 'http' );
4753
	}
4754
4755
	/**
4756
	 * Checks to see if the URL is using SSL to connect with Jetpack
4757
	 *
4758
	 * @since 2.3.3
4759
	 * @return boolean
4760
	 */
4761
	public static function permit_ssl( $force_recheck = false ) {
4762
		// Do some fancy tests to see if ssl is being supported
4763
		if ( $force_recheck || false === ( $ssl = get_transient( 'jetpack_https_test' ) ) ) {
4764
			if ( 'https' !== substr( JETPACK__API_BASE, 0, 5 ) ) {
4765
				$ssl = 0;
4766
			} else {
4767
				switch ( JETPACK_CLIENT__HTTPS ) {
4768
					case 'NEVER':
4769
						$ssl = 0;
4770
						break;
4771
					case 'ALWAYS':
4772
					case 'AUTO':
4773
					default:
4774
						$ssl = 1;
4775
						break;
4776
				}
4777
4778
				// If it's not 'NEVER', test to see
4779
				if ( $ssl ) {
4780
					$response = wp_remote_get( JETPACK__API_BASE . 'test/1/' );
4781
					if ( is_wp_error( $response ) || ( 'OK' !== wp_remote_retrieve_body( $response ) ) ) {
4782
						$ssl = 0;
4783
					}
4784
				}
4785
			}
4786
			set_transient( 'jetpack_https_test', $ssl, DAY_IN_SECONDS );
4787
		}
4788
4789
		return (bool) $ssl;
4790
	}
4791
4792
	/*
4793
	 * Displays an admin_notice, alerting the user to their JETPACK_CLIENT__HTTPS constant being 'ALWAYS' but SSL isn't working.
4794
	 */
4795
	public function alert_required_ssl_fail() {
4796
		if ( ! current_user_can( 'manage_options' ) )
4797
			return;
4798
		?>
4799
4800
		<div id="message" class="error jetpack-message jp-identity-crisis">
4801
			<div class="jp-banner__content">
4802
				<h2><?php _e( 'Something is being cranky!', 'jetpack' ); ?></h2>
4803
				<p><?php _e( 'Your site is configured to only permit SSL connections to Jetpack, but SSL connections don\'t seem to be functional!', 'jetpack' ); ?></p>
4804
			</div>
4805
		</div>
4806
4807
		<?php
4808
	}
4809
4810
	/**
4811
	 * Returns the Jetpack XML-RPC API
4812
	 *
4813
	 * @return string
4814
	 */
4815
	public static function xmlrpc_api_url() {
4816
		$base = preg_replace( '#(https?://[^?/]+)(/?.*)?$#', '\\1', JETPACK__API_BASE );
4817
		return untrailingslashit( $base ) . '/xmlrpc.php';
4818
	}
4819
4820
	/**
4821
	 * Creates two secret tokens and the end of life timestamp for them.
4822
	 *
4823
	 * Note these tokens are unique per call, NOT static per site for connecting.
4824
	 *
4825
	 * @since 2.6
4826
	 * @return array
4827
	 */
4828
	public function generate_secrets() {
4829
	    $secrets = array(
4830
		wp_generate_password( 32, false ), // secret_1
4831
		wp_generate_password( 32, false ), // secret_2
4832
		( time() + 600 ), // eol ( End of Life )
4833
	    );
4834
4835
	    return $secrets;
4836
	}
4837
4838
	/**
4839
	 * Builds the timeout limit for queries talking with the wpcom servers.
4840
	 *
4841
	 * Based on local php max_execution_time in php.ini
4842
	 *
4843
	 * @since 2.6
4844
	 * @return int
4845
	 **/
4846
	public function get_remote_query_timeout_limit() {
4847
	    $timeout = (int) ini_get( 'max_execution_time' );
4848
	    if ( ! $timeout ) // Ensure exec time set in php.ini
4849
		$timeout = 30;
4850
	    return intval( $timeout / 2 );
4851
	}
4852
4853
4854
	/**
4855
	 * Takes the response from the Jetpack register new site endpoint and
4856
	 * verifies it worked properly.
4857
	 *
4858
	 * @since 2.6
4859
	 * @return true or Jetpack_Error
4860
	 **/
4861
	public function validate_remote_register_response( $response ) {
4862
	    	if ( is_wp_error( $response ) ) {
4863
			return new Jetpack_Error( 'register_http_request_failed', $response->get_error_message() );
4864
		}
4865
4866
		$code   = wp_remote_retrieve_response_code( $response );
4867
		$entity = wp_remote_retrieve_body( $response );
4868
		if ( $entity )
4869
			$json = json_decode( $entity );
4870
		else
4871
			$json = false;
4872
4873
		$code_type = intval( $code / 100 );
4874
		if ( 5 == $code_type ) {
4875
			return new Jetpack_Error( 'wpcom_5??', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
4876
		} elseif ( 408 == $code ) {
4877
			return new Jetpack_Error( 'wpcom_408', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
4878
		} elseif ( ! empty( $json->error ) ) {
4879
			$error_description = isset( $json->error_description ) ? sprintf( __( 'Error Details: %s', 'jetpack' ), (string) $json->error_description ) : '';
4880
			return new Jetpack_Error( (string) $json->error, $error_description, $code );
4881
		} elseif ( 200 != $code ) {
4882
			return new Jetpack_Error( 'wpcom_bad_response', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
4883
		}
4884
4885
		// Jetpack ID error block
4886
		if ( empty( $json->jetpack_id ) ) {
4887
			return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID is empty. Do not publicly post this error message! %s', 'jetpack' ), $entity ), $entity );
4888
		} elseif ( ! is_scalar( $json->jetpack_id ) ) {
4889
			return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID is not a scalar. Do not publicly post this error message! %s', 'jetpack' ) , $entity ), $entity );
4890
		} elseif ( preg_match( '/[^0-9]/', $json->jetpack_id ) ) {
4891
			return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID begins with a numeral. Do not publicly post this error message! %s', 'jetpack' ) , $entity ), $entity );
4892
		}
4893
4894
	    return true;
4895
	}
4896
	/**
4897
	 * @return bool|WP_Error
4898
	 */
4899
	public static function register() {
4900
		add_action( 'pre_update_jetpack_option_register', array( 'Jetpack_Options', 'delete_option' ) );
4901
		$secrets = Jetpack::init()->generate_secrets();
4902
4903
		Jetpack_Options::update_option( 'register', $secrets[0] . ':' . $secrets[1] . ':' . $secrets[2] );
4904
4905
		@list( $secret_1, $secret_2, $secret_eol ) = explode( ':', Jetpack_Options::get_option( 'register' ) );
4906
		if ( empty( $secret_1 ) || empty( $secret_2 ) || empty( $secret_eol ) || $secret_eol < time() ) {
4907
			return new Jetpack_Error( 'missing_secrets' );
4908
		}
4909
4910
		$timeout = Jetpack::init()->get_remote_query_timeout_limit();
4911
4912
		$gmt_offset = get_option( 'gmt_offset' );
4913
		if ( ! $gmt_offset ) {
4914
			$gmt_offset = 0;
4915
		}
4916
4917
		$stats_options = get_option( 'stats_options' );
4918
		$stats_id = isset($stats_options['blog_id']) ? $stats_options['blog_id'] : null;
4919
4920
		$args = array(
4921
			'method'  => 'POST',
4922
			'body'    => array(
4923
				'siteurl'         => site_url(),
4924
				'home'            => home_url(),
4925
				'gmt_offset'      => $gmt_offset,
4926
				'timezone_string' => (string) get_option( 'timezone_string' ),
4927
				'site_name'       => (string) get_option( 'blogname' ),
4928
				'secret_1'        => $secret_1,
4929
				'secret_2'        => $secret_2,
4930
				'site_lang'       => get_locale(),
4931
				'timeout'         => $timeout,
4932
				'stats_id'        => $stats_id,
4933
			),
4934
			'headers' => array(
4935
				'Accept' => 'application/json',
4936
			),
4937
			'timeout' => $timeout,
4938
		);
4939
		$response = Jetpack_Client::_wp_remote_request( Jetpack::fix_url_for_bad_hosts( Jetpack::api_url( 'register' ) ), $args, true );
4940
4941
4942
		// Make sure the response is valid and does not contain any Jetpack errors
4943
		$valid_response = Jetpack::init()->validate_remote_register_response( $response );
4944
		if( is_wp_error( $valid_response ) || !$valid_response ) {
4945
		    return $valid_response;
4946
		}
4947
4948
4949
		// Grab the response values to work with
4950
		$code   = wp_remote_retrieve_response_code( $response );
4951
		$entity = wp_remote_retrieve_body( $response );
4952
4953
		if ( $entity )
4954
			$json = json_decode( $entity );
4955
		else
4956
			$json = false;
4957
4958 View Code Duplication
		if ( empty( $json->jetpack_secret ) || ! is_string( $json->jetpack_secret ) )
4959
			return new Jetpack_Error( 'jetpack_secret', '', $code );
4960
4961
		if ( isset( $json->jetpack_public ) ) {
4962
			$jetpack_public = (int) $json->jetpack_public;
4963
		} else {
4964
			$jetpack_public = false;
4965
		}
4966
4967
		Jetpack_Options::update_options(
4968
			array(
4969
				'id'         => (int)    $json->jetpack_id,
4970
				'blog_token' => (string) $json->jetpack_secret,
4971
				'public'     => $jetpack_public,
4972
			)
4973
		);
4974
4975
		/**
4976
		 * Fires when a site is registered on WordPress.com.
4977
		 *
4978
		 * @since 3.7.0
4979
		 *
4980
		 * @param int $json->jetpack_id Jetpack Blog ID.
4981
		 * @param string $json->jetpack_secret Jetpack Blog Token.
4982
		 * @param int|bool $jetpack_public Is the site public.
4983
		 */
4984
		do_action( 'jetpack_site_registered', $json->jetpack_id, $json->jetpack_secret, $jetpack_public );
4985
4986
		// Initialize Jump Start for the first and only time.
4987
		if ( ! Jetpack_Options::get_option( 'jumpstart' ) ) {
4988
			Jetpack_Options::update_option( 'jumpstart', 'new_connection' );
4989
4990
			$jetpack = Jetpack::init();
4991
4992
			$jetpack->stat( 'jumpstart', 'unique-views' );
4993
			$jetpack->do_stats( 'server_side' );
4994
		};
4995
4996
		return true;
4997
	}
4998
4999
	/**
5000
	 * If the db version is showing something other that what we've got now, bump it to current.
5001
	 *
5002
	 * @return bool: True if the option was incorrect and updated, false if nothing happened.
5003
	 */
5004
	public static function maybe_set_version_option() {
5005
		list( $version ) = explode( ':', Jetpack_Options::get_option( 'version' ) );
5006
		if ( JETPACK__VERSION != $version ) {
5007
			Jetpack_Options::update_option( 'version', JETPACK__VERSION . ':' . time() );
5008
			return true;
5009
		}
5010
		return false;
5011
	}
5012
5013
/* Client Server API */
5014
5015
	/**
5016
	 * Loads the Jetpack XML-RPC client
5017
	 */
5018
	public static function load_xml_rpc_client() {
5019
		require_once ABSPATH . WPINC . '/class-IXR.php';
5020
		require_once JETPACK__PLUGIN_DIR . 'class.jetpack-ixr-client.php';
5021
	}
5022
5023
	function verify_xml_rpc_signature() {
5024
		if ( $this->xmlrpc_verification ) {
5025
			return $this->xmlrpc_verification;
5026
		}
5027
5028
		// It's not for us
5029
		if ( ! isset( $_GET['token'] ) || empty( $_GET['signature'] ) ) {
5030
			return false;
5031
		}
5032
5033
		@list( $token_key, $version, $user_id ) = explode( ':', $_GET['token'] );
5034
		if (
5035
			empty( $token_key )
5036
		||
5037
			empty( $version ) || strval( JETPACK__API_VERSION ) !== $version
5038
		) {
5039
			return false;
5040
		}
5041
5042
		if ( '0' === $user_id ) {
5043
			$token_type = 'blog';
5044
			$user_id = 0;
5045
		} else {
5046
			$token_type = 'user';
5047
			if ( empty( $user_id ) || ! ctype_digit( $user_id ) ) {
5048
				return false;
5049
			}
5050
			$user_id = (int) $user_id;
5051
5052
			$user = new WP_User( $user_id );
5053
			if ( ! $user || ! $user->exists() ) {
5054
				return false;
5055
			}
5056
		}
5057
5058
		$token = Jetpack_Data::get_access_token( $user_id );
5059
		if ( ! $token ) {
5060
			return false;
5061
		}
5062
5063
		$token_check = "$token_key.";
5064
		if ( ! hash_equals( substr( $token->secret, 0, strlen( $token_check ) ), $token_check ) ) {
5065
			return false;
5066
		}
5067
5068
		require_once JETPACK__PLUGIN_DIR . 'class.jetpack-signature.php';
5069
5070
		$jetpack_signature = new Jetpack_Signature( $token->secret, (int) Jetpack_Options::get_option( 'time_diff' ) );
5071
		if ( isset( $_POST['_jetpack_is_multipart'] ) ) {
5072
			$post_data   = $_POST;
5073
			$file_hashes = array();
5074
			foreach ( $post_data as $post_data_key => $post_data_value ) {
5075
				if ( 0 !== strpos( $post_data_key, '_jetpack_file_hmac_' ) ) {
5076
					continue;
5077
				}
5078
				$post_data_key = substr( $post_data_key, strlen( '_jetpack_file_hmac_' ) );
5079
				$file_hashes[$post_data_key] = $post_data_value;
5080
			}
5081
5082
			foreach ( $file_hashes as $post_data_key => $post_data_value ) {
5083
				unset( $post_data["_jetpack_file_hmac_{$post_data_key}"] );
5084
				$post_data[$post_data_key] = $post_data_value;
5085
			}
5086
5087
			ksort( $post_data );
5088
5089
			$body = http_build_query( stripslashes_deep( $post_data ) );
5090
		} elseif ( is_null( $this->HTTP_RAW_POST_DATA ) ) {
1 ignored issue
show
As per coding-style, please use === null instead of is_null.
Loading history...
5091
			$body = file_get_contents( 'php://input' );
5092
		} else {
5093
			$body = null;
5094
		}
5095
		$signature = $jetpack_signature->sign_current_request(
5096
			array( 'body' => is_null( $body ) ? $this->HTTP_RAW_POST_DATA : $body, )
1 ignored issue
show
As per coding-style, please use === null instead of is_null.
Loading history...
5097
		);
5098
5099
		if ( ! $signature ) {
5100
			return false;
5101
		} else if ( is_wp_error( $signature ) ) {
5102
			return $signature;
5103
		} else if ( ! hash_equals( $signature, $_GET['signature'] ) ) {
5104
			return false;
5105
		}
5106
5107
		$timestamp = (int) $_GET['timestamp'];
5108
		$nonce     = stripslashes( (string) $_GET['nonce'] );
5109
5110
		if ( ! $this->add_nonce( $timestamp, $nonce ) ) {
5111
			return false;
5112
		}
5113
5114
		$this->xmlrpc_verification = array(
5115
			'type'    => $token_type,
5116
			'user_id' => $token->external_user_id,
5117
		);
5118
5119
		return $this->xmlrpc_verification;
5120
	}
5121
5122
	/**
5123
	 * Authenticates XML-RPC and other requests from the Jetpack Server
5124
	 */
5125
	function authenticate_jetpack( $user, $username, $password ) {
5126
		if ( is_a( $user, 'WP_User' ) ) {
5127
			return $user;
5128
		}
5129
5130
		$token_details = $this->verify_xml_rpc_signature();
5131
5132
		if ( ! $token_details || is_wp_error( $token_details ) ) {
5133
			return $user;
5134
		}
5135
5136
		if ( 'user' !== $token_details['type'] ) {
5137
			return $user;
5138
		}
5139
5140
		if ( ! $token_details['user_id'] ) {
5141
			return $user;
5142
		}
5143
5144
		nocache_headers();
5145
5146
		return new WP_User( $token_details['user_id'] );
5147
	}
5148
5149
	function add_nonce( $timestamp, $nonce ) {
5150
		global $wpdb;
5151
		static $nonces_used_this_request = array();
5152
5153
		if ( isset( $nonces_used_this_request["$timestamp:$nonce"] ) ) {
5154
			return $nonces_used_this_request["$timestamp:$nonce"];
5155
		}
5156
5157
		// This should always have gone through Jetpack_Signature::sign_request() first to check $timestamp an $nonce
5158
		$timestamp = (int) $timestamp;
5159
		$nonce     = esc_sql( $nonce );
5160
5161
		// Raw query so we can avoid races: add_option will also update
5162
		$show_errors = $wpdb->show_errors( false );
5163
5164
		$old_nonce = $wpdb->get_row(
5165
			$wpdb->prepare( "SELECT * FROM `$wpdb->options` WHERE option_name = %s", "jetpack_nonce_{$timestamp}_{$nonce}" )
5166
		);
5167
5168
		if ( is_null( $old_nonce ) ) {
1 ignored issue
show
As per coding-style, please use === null instead of is_null.
Loading history...
5169
			$return = $wpdb->query(
5170
				$wpdb->prepare(
5171
					"INSERT INTO `$wpdb->options` (`option_name`, `option_value`, `autoload`) VALUES (%s, %s, %s)",
5172
					"jetpack_nonce_{$timestamp}_{$nonce}",
5173
					time(),
5174
					'no'
5175
				)
5176
			);
5177
		} else {
5178
			$return = false;
5179
		}
5180
5181
		$wpdb->show_errors( $show_errors );
5182
5183
		$nonces_used_this_request["$timestamp:$nonce"] = $return;
5184
5185
		return $return;
5186
	}
5187
5188
	/**
5189
	 * In some setups, $HTTP_RAW_POST_DATA can be emptied during some IXR_Server paths since it is passed by reference to various methods.
5190
	 * Capture it here so we can verify the signature later.
5191
	 */
5192
	function xmlrpc_methods( $methods ) {
5193
		$this->HTTP_RAW_POST_DATA = $GLOBALS['HTTP_RAW_POST_DATA'];
5194
		return $methods;
5195
	}
5196
5197
	function public_xmlrpc_methods( $methods ) {
5198
		if ( array_key_exists( 'wp.getOptions', $methods ) ) {
5199
			$methods['wp.getOptions'] = array( $this, 'jetpack_getOptions' );
5200
		}
5201
		return $methods;
5202
	}
5203
5204
	function jetpack_getOptions( $args ) {
5205
		global $wp_xmlrpc_server;
5206
5207
		$wp_xmlrpc_server->escape( $args );
5208
5209
		$username	= $args[1];
5210
		$password	= $args[2];
5211
5212
		if ( !$user = $wp_xmlrpc_server->login($username, $password) ) {
5213
			return $wp_xmlrpc_server->error;
5214
		}
5215
5216
		$options = array();
5217
		$user_data = $this->get_connected_user_data();
5218
		if ( is_array( $user_data ) ) {
5219
			$options['jetpack_user_id'] = array(
5220
				'desc'          => __( 'The WP.com user ID of the connected user', 'jetpack' ),
5221
				'readonly'      => true,
5222
				'value'         => $user_data['ID'],
5223
			);
5224
			$options['jetpack_user_login'] = array(
5225
				'desc'          => __( 'The WP.com username of the connected user', 'jetpack' ),
5226
				'readonly'      => true,
5227
				'value'         => $user_data['login'],
5228
			);
5229
			$options['jetpack_user_email'] = array(
5230
				'desc'          => __( 'The WP.com user email of the connected user', 'jetpack' ),
5231
				'readonly'      => true,
5232
				'value'         => $user_data['email'],
5233
			);
5234
			$options['jetpack_user_site_count'] = array(
5235
				'desc'          => __( 'The number of sites of the connected WP.com user', 'jetpack' ),
5236
				'readonly'      => true,
5237
				'value'         => $user_data['site_count'],
5238
			);
5239
		}
5240
		$wp_xmlrpc_server->blog_options = array_merge( $wp_xmlrpc_server->blog_options, $options );
5241
		$args = stripslashes_deep( $args );
5242
		return $wp_xmlrpc_server->wp_getOptions( $args );
5243
	}
5244
5245
	function xmlrpc_options( $options ) {
5246
		$jetpack_client_id = false;
5247
		if ( self::is_active() ) {
5248
			$jetpack_client_id = Jetpack_Options::get_option( 'id' );
5249
		}
5250
		$options['jetpack_version'] = array(
5251
				'desc'          => __( 'Jetpack Plugin Version', 'jetpack' ),
5252
				'readonly'      => true,
5253
				'value'         => JETPACK__VERSION,
5254
		);
5255
5256
		$options['jetpack_client_id'] = array(
5257
				'desc'          => __( 'The Client ID/WP.com Blog ID of this site', 'jetpack' ),
5258
				'readonly'      => true,
5259
				'value'         => $jetpack_client_id,
5260
		);
5261
		return $options;
5262
	}
5263
5264
	public static function clean_nonces( $all = false ) {
5265
		global $wpdb;
5266
5267
		$sql = "DELETE FROM `$wpdb->options` WHERE `option_name` LIKE %s";
5268
		if ( method_exists ( $wpdb , 'esc_like' ) ) {
5269
			$sql_args = array( $wpdb->esc_like( 'jetpack_nonce_' ) . '%' );
5270
		} else {
5271
			$sql_args = array( like_escape( 'jetpack_nonce_' ) . '%' );
5272
		}
5273
5274
		if ( true !== $all ) {
5275
			$sql .= ' AND CAST( `option_value` AS UNSIGNED ) < %d';
5276
			$sql_args[] = time() - 3600;
5277
		}
5278
5279
		$sql .= ' ORDER BY `option_id` LIMIT 100';
5280
5281
		$sql = $wpdb->prepare( $sql, $sql_args );
5282
5283
		for ( $i = 0; $i < 1000; $i++ ) {
5284
			if ( ! $wpdb->query( $sql ) ) {
5285
				break;
5286
			}
5287
		}
5288
	}
5289
5290
	/**
5291
	 * State is passed via cookies from one request to the next, but never to subsequent requests.
5292
	 * SET: state( $key, $value );
5293
	 * GET: $value = state( $key );
5294
	 *
5295
	 * @param string $key
5296
	 * @param string $value
5297
	 * @param bool $restate private
5298
	 */
5299
	public static function state( $key = null, $value = null, $restate = false ) {
5300
		static $state = array();
5301
		static $path, $domain;
5302
		if ( ! isset( $path ) ) {
5303
			require_once( ABSPATH . 'wp-admin/includes/plugin.php' );
5304
			$admin_url = Jetpack::admin_url();
5305
			$bits      = parse_url( $admin_url );
5306
5307
			if ( is_array( $bits ) ) {
5308
				$path   = ( isset( $bits['path'] ) ) ? dirname( $bits['path'] ) : null;
5309
				$domain = ( isset( $bits['host'] ) ) ? $bits['host'] : null;
5310
			} else {
5311
				$path = $domain = null;
5312
			}
5313
		}
5314
5315
		// Extract state from cookies and delete cookies
5316
		if ( isset( $_COOKIE[ 'jetpackState' ] ) && is_array( $_COOKIE[ 'jetpackState' ] ) ) {
5317
			$yum = $_COOKIE[ 'jetpackState' ];
5318
			unset( $_COOKIE[ 'jetpackState' ] );
5319
			foreach ( $yum as $k => $v ) {
5320
				if ( strlen( $v ) )
5321
					$state[ $k ] = $v;
5322
				setcookie( "jetpackState[$k]", false, 0, $path, $domain );
5323
			}
5324
		}
5325
5326
		if ( $restate ) {
5327
			foreach ( $state as $k => $v ) {
5328
				setcookie( "jetpackState[$k]", $v, 0, $path, $domain );
5329
			}
5330
			return;
5331
		}
5332
5333
		// Get a state variable
5334
		if ( isset( $key ) && ! isset( $value ) ) {
5335
			if ( array_key_exists( $key, $state ) )
5336
				return $state[ $key ];
5337
			return null;
5338
		}
5339
5340
		// Set a state variable
5341
		if ( isset ( $key ) && isset( $value ) ) {
5342
			if( is_array( $value ) && isset( $value[0] ) ) {
5343
				$value = $value[0];
5344
			}
5345
			$state[ $key ] = $value;
5346
			setcookie( "jetpackState[$key]", $value, 0, $path, $domain );
5347
		}
5348
	}
5349
5350
	public static function restate() {
5351
		Jetpack::state( null, null, true );
5352
	}
5353
5354
	public static function check_privacy( $file ) {
5355
		static $is_site_publicly_accessible = null;
5356
5357
		if ( is_null( $is_site_publicly_accessible ) ) {
1 ignored issue
show
As per coding-style, please use === null instead of is_null.
Loading history...
5358
			$is_site_publicly_accessible = false;
5359
5360
			Jetpack::load_xml_rpc_client();
5361
			$rpc = new Jetpack_IXR_Client();
5362
5363
			$success = $rpc->query( 'jetpack.isSitePubliclyAccessible', home_url() );
5364
			if ( $success ) {
5365
				$response = $rpc->getResponse();
5366
				if ( $response ) {
5367
					$is_site_publicly_accessible = true;
5368
				}
5369
			}
5370
5371
			Jetpack_Options::update_option( 'public', (int) $is_site_publicly_accessible );
5372
		}
5373
5374
		if ( $is_site_publicly_accessible ) {
5375
			return;
5376
		}
5377
5378
		$module_slug = self::get_module_slug( $file );
5379
5380
		$privacy_checks = Jetpack::state( 'privacy_checks' );
5381
		if ( ! $privacy_checks ) {
5382
			$privacy_checks = $module_slug;
5383
		} else {
5384
			$privacy_checks .= ",$module_slug";
5385
		}
5386
5387
		Jetpack::state( 'privacy_checks', $privacy_checks );
5388
	}
5389
5390
	/**
5391
	 * Helper method for multicall XMLRPC.
5392
	 */
5393
	public static function xmlrpc_async_call() {
5394
		global $blog_id;
5395
		static $clients = array();
5396
5397
		$client_blog_id = is_multisite() ? $blog_id : 0;
5398
5399
		if ( ! isset( $clients[$client_blog_id] ) ) {
5400
			Jetpack::load_xml_rpc_client();
5401
			$clients[$client_blog_id] = new Jetpack_IXR_ClientMulticall( array( 'user_id' => JETPACK_MASTER_USER, ) );
5402
			if ( function_exists( 'ignore_user_abort' ) ) {
5403
				ignore_user_abort( true );
5404
			}
5405
			add_action( 'shutdown', array( 'Jetpack', 'xmlrpc_async_call' ) );
5406
		}
5407
5408
		$args = func_get_args();
5409
5410
		if ( ! empty( $args[0] ) ) {
5411
			call_user_func_array( array( $clients[$client_blog_id], 'addCall' ), $args );
5412
		} elseif ( is_multisite() ) {
5413
			foreach ( $clients as $client_blog_id => $client ) {
5414
				if ( ! $client_blog_id || empty( $client->calls ) ) {
5415
					continue;
5416
				}
5417
5418
				$switch_success = switch_to_blog( $client_blog_id, true );
5419
				if ( ! $switch_success ) {
5420
					continue;
5421
				}
5422
5423
				flush();
5424
				$client->query();
5425
5426
				restore_current_blog();
5427
			}
5428
		} else {
5429
			if ( isset( $clients[0] ) && ! empty( $clients[0]->calls ) ) {
5430
				flush();
5431
				$clients[0]->query();
5432
			}
5433
		}
5434
	}
5435
5436
	public static function staticize_subdomain( $url ) {
5437
5438
		// Extract hostname from URL
5439
		$host = parse_url( $url, PHP_URL_HOST );
5440
5441
		// Explode hostname on '.'
5442
		$exploded_host = explode( '.', $host );
5443
5444
		// Retrieve the name and TLD
5445
		if ( count( $exploded_host ) > 1 ) {
5446
			$name = $exploded_host[ count( $exploded_host ) - 2 ];
5447
			$tld = $exploded_host[ count( $exploded_host ) - 1 ];
5448
			// Rebuild domain excluding subdomains
5449
			$domain = $name . '.' . $tld;
5450
		} else {
5451
			$domain = $host;
5452
		}
5453
		// Array of Automattic domains
5454
		$domain_whitelist = array( 'wordpress.com', 'wp.com' );
5455
5456
		// Return $url if not an Automattic domain
5457
		if ( ! in_array( $domain, $domain_whitelist ) ) {
5458
			return $url;
5459
		}
5460
5461
		if ( is_ssl() ) {
5462
			return preg_replace( '|https?://[^/]++/|', 'https://s-ssl.wordpress.com/', $url );
5463
		}
5464
5465
		srand( crc32( basename( $url ) ) );
5466
		$static_counter = rand( 0, 2 );
5467
		srand(); // this resets everything that relies on this, like array_rand() and shuffle()
5468
5469
		return preg_replace( '|://[^/]+?/|', "://s$static_counter.wp.com/", $url );
5470
	}
5471
5472
/* JSON API Authorization */
5473
5474
	/**
5475
	 * Handles the login action for Authorizing the JSON API
5476
	 */
5477
	function login_form_json_api_authorization() {
5478
		$this->verify_json_api_authorization_request();
5479
5480
		add_action( 'wp_login', array( &$this, 'store_json_api_authorization_token' ), 10, 2 );
5481
5482
		add_action( 'login_message', array( &$this, 'login_message_json_api_authorization' ) );
5483
		add_action( 'login_form', array( &$this, 'preserve_action_in_login_form_for_json_api_authorization' ) );
5484
		add_filter( 'site_url', array( &$this, 'post_login_form_to_signed_url' ), 10, 3 );
5485
	}
5486
5487
	// Make sure the login form is POSTed to the signed URL so we can reverify the request
5488
	function post_login_form_to_signed_url( $url, $path, $scheme ) {
5489
		if ( 'wp-login.php' !== $path || ( 'login_post' !== $scheme && 'login' !== $scheme ) ) {
5490
			return $url;
5491
		}
5492
5493
		$parsed_url = parse_url( $url );
5494
		$url = strtok( $url, '?' );
5495
		$url = "$url?{$_SERVER['QUERY_STRING']}";
5496
		if ( ! empty( $parsed_url['query'] ) )
5497
			$url .= "&{$parsed_url['query']}";
5498
5499
		return $url;
5500
	}
5501
5502
	// Make sure the POSTed request is handled by the same action
5503
	function preserve_action_in_login_form_for_json_api_authorization() {
5504
		echo "<input type='hidden' name='action' value='jetpack_json_api_authorization' />\n";
5505
		echo "<input type='hidden' name='jetpack_json_api_original_query' value='" . esc_url( set_url_scheme( $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'] ) ) . "' />\n";
5506
	}
5507
5508
	// If someone logs in to approve API access, store the Access Code in usermeta
5509
	function store_json_api_authorization_token( $user_login, $user ) {
5510
		add_filter( 'login_redirect', array( &$this, 'add_token_to_login_redirect_json_api_authorization' ), 10, 3 );
5511
		add_filter( 'allowed_redirect_hosts', array( &$this, 'allow_wpcom_public_api_domain' ) );
5512
		$token = wp_generate_password( 32, false );
5513
		update_user_meta( $user->ID, 'jetpack_json_api_' . $this->json_api_authorization_request['client_id'], $token );
5514
	}
5515
5516
	// Add public-api.wordpress.com to the safe redirect whitelist - only added when someone allows API access
5517
	function allow_wpcom_public_api_domain( $domains ) {
5518
		$domains[] = 'public-api.wordpress.com';
5519
		return $domains;
5520
	}
5521
5522
	// Add the Access Code details to the public-api.wordpress.com redirect
5523
	function add_token_to_login_redirect_json_api_authorization( $redirect_to, $original_redirect_to, $user ) {
5524
		return add_query_arg(
5525
			urlencode_deep(
5526
				array(
5527
					'jetpack-code'    => get_user_meta( $user->ID, 'jetpack_json_api_' . $this->json_api_authorization_request['client_id'], true ),
5528
					'jetpack-user-id' => (int) $user->ID,
5529
					'jetpack-state'   => $this->json_api_authorization_request['state'],
5530
				)
5531
			),
5532
			$redirect_to
5533
		);
5534
	}
5535
5536
	// Verifies the request by checking the signature
5537
	function verify_json_api_authorization_request() {
5538
		require_once JETPACK__PLUGIN_DIR . 'class.jetpack-signature.php';
5539
5540
		$token = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
5541
		if ( ! $token || empty( $token->secret ) ) {
5542
			wp_die( __( 'You must connect your Jetpack plugin to WordPress.com to use this feature.' , 'jetpack' ) );
5543
		}
5544
5545
		$die_error = __( 'Someone may be trying to trick you into giving them access to your site.  Or it could be you just encountered a bug :).  Either way, please close this window.', 'jetpack' );
5546
5547
		$jetpack_signature = new Jetpack_Signature( $token->secret, (int) Jetpack_Options::get_option( 'time_diff' ) );
5548
5549
		if ( isset( $_POST['jetpack_json_api_original_query'] ) ) {
5550
			$signature = $jetpack_signature->sign_request( $_GET['token'], $_GET['timestamp'], $_GET['nonce'], '', 'GET', $_POST['jetpack_json_api_original_query'], null, true );
5551
		} else {
5552
			$signature = $jetpack_signature->sign_current_request( array( 'body' => null, 'method' => 'GET' ) );
5553
		}
5554
5555
		if ( ! $signature ) {
5556
			wp_die( $die_error );
5557
		} else if ( is_wp_error( $signature ) ) {
5558
			wp_die( $die_error );
5559
		} else if ( $signature !== $_GET['signature'] ) {
5560
			if ( is_ssl() ) {
5561
				// If we signed an HTTP request on the Jetpack Servers, but got redirected to HTTPS by the local blog, check the HTTP signature as well
5562
				$signature = $jetpack_signature->sign_current_request( array( 'scheme' => 'http', 'body' => null, 'method' => 'GET' ) );
5563
				if ( ! $signature || is_wp_error( $signature ) || $signature !== $_GET['signature'] ) {
5564
					wp_die( $die_error );
5565
				}
5566
			} else {
5567
				wp_die( $die_error );
5568
			}
5569
		}
5570
5571
		$timestamp = (int) $_GET['timestamp'];
5572
		$nonce     = stripslashes( (string) $_GET['nonce'] );
5573
5574
		if ( ! $this->add_nonce( $timestamp, $nonce ) ) {
5575
			// De-nonce the nonce, at least for 5 minutes.
5576
			// We have to reuse this nonce at least once (used the first time when the initial request is made, used a second time when the login form is POSTed)
5577
			$old_nonce_time = get_option( "jetpack_nonce_{$timestamp}_{$nonce}" );
5578
			if ( $old_nonce_time < time() - 300 ) {
5579
				wp_die( __( 'The authorization process expired.  Please go back and try again.' , 'jetpack' ) );
5580
			}
5581
		}
5582
5583
		$data = json_decode( base64_decode( stripslashes( $_GET['data'] ) ) );
5584
		$data_filters = array(
5585
			'state'        => 'opaque',
5586
			'client_id'    => 'int',
5587
			'client_title' => 'string',
5588
			'client_image' => 'url',
5589
		);
5590
5591
		foreach ( $data_filters as $key => $sanitation ) {
5592
			if ( ! isset( $data->$key ) ) {
5593
				wp_die( $die_error );
5594
			}
5595
5596
			switch ( $sanitation ) {
5597
			case 'int' :
5598
				$this->json_api_authorization_request[$key] = (int) $data->$key;
5599
				break;
5600
			case 'opaque' :
5601
				$this->json_api_authorization_request[$key] = (string) $data->$key;
5602
				break;
5603
			case 'string' :
5604
				$this->json_api_authorization_request[$key] = wp_kses( (string) $data->$key, array() );
5605
				break;
5606
			case 'url' :
5607
				$this->json_api_authorization_request[$key] = esc_url_raw( (string) $data->$key );
5608
				break;
5609
			}
5610
		}
5611
5612
		if ( empty( $this->json_api_authorization_request['client_id'] ) ) {
5613
			wp_die( $die_error );
5614
		}
5615
	}
5616
5617
	function login_message_json_api_authorization( $message ) {
5618
		return '<p class="message">' . sprintf(
5619
			esc_html__( '%s wants to access your site&#8217;s data.  Log in to authorize that access.' , 'jetpack' ),
5620
			'<strong>' . esc_html( $this->json_api_authorization_request['client_title'] ) . '</strong>'
5621
		) . '<img src="' . esc_url( $this->json_api_authorization_request['client_image'] ) . '" /></p>';
5622
	}
5623
5624
	/**
5625
	 * Get $content_width, but with a <s>twist</s> filter.
5626
	 */
5627
	public static function get_content_width() {
5628
		$content_width = isset( $GLOBALS['content_width'] ) ? $GLOBALS['content_width'] : false;
5629
		/**
5630
		 * Filter the Content Width value.
5631
		 *
5632
		 * @since 2.2.3
5633
		 *
5634
		 * @param string $content_width Content Width value.
5635
		 */
5636
		return apply_filters( 'jetpack_content_width', $content_width );
5637
	}
5638
5639
	/**
5640
	 * Centralize the function here until it gets added to core.
5641
	 *
5642
	 * @param int|string|object $id_or_email A user ID,  email address, or comment object
5643
	 * @param int $size Size of the avatar image
5644
	 * @param string $default URL to a default image to use if no avatar is available
5645
	 * @param bool $force_display Whether to force it to return an avatar even if show_avatars is disabled
5646
	 *
5647
	 * @return array First element is the URL, second is the class.
5648
	 */
5649
	public static function get_avatar_url( $id_or_email, $size = 96, $default = '', $force_display = false ) {
5650
		// Don't bother adding the __return_true filter if it's already there.
5651
		$has_filter = has_filter( 'pre_option_show_avatars', '__return_true' );
5652
5653
		if ( $force_display && ! $has_filter )
5654
			add_filter( 'pre_option_show_avatars', '__return_true' );
5655
5656
		$avatar = get_avatar( $id_or_email, $size, $default );
5657
5658
		if ( $force_display && ! $has_filter )
5659
			remove_filter( 'pre_option_show_avatars', '__return_true' );
5660
5661
		// If no data, fail out.
5662
		if ( is_wp_error( $avatar ) || ! $avatar )
5663
			return array( null, null );
5664
5665
		// Pull out the URL.  If it's not there, fail out.
5666
		if ( ! preg_match( '/src=["\']([^"\']+)["\']/', $avatar, $url_matches ) )
5667
			return array( null, null );
5668
		$url = wp_specialchars_decode( $url_matches[1], ENT_QUOTES );
5669
5670
		// Pull out the class, but it's not a big deal if it's missing.
5671
		$class = '';
5672
		if ( preg_match( '/class=["\']([^"\']+)["\']/', $avatar, $class_matches ) )
5673
			$class = wp_specialchars_decode( $class_matches[1], ENT_QUOTES );
5674
5675
		return array( $url, $class );
5676
	}
5677
5678
	/**
5679
	 * Pings the WordPress.com Mirror Site for the specified options.
5680
	 *
5681
	 * @param string|array $option_names The option names to request from the WordPress.com Mirror Site
5682
	 *
5683
	 * @return array An associative array of the option values as stored in the WordPress.com Mirror Site
5684
	 */
5685
	public function get_cloud_site_options( $option_names ) {
5686
		$option_names = array_filter( (array) $option_names, 'is_string' );
5687
5688
		Jetpack::load_xml_rpc_client();
5689
		$xml = new Jetpack_IXR_Client( array( 'user_id' => JETPACK_MASTER_USER, ) );
5690
		$xml->query( 'jetpack.fetchSiteOptions', $option_names );
5691
		if ( $xml->isError() ) {
5692
			return array(
5693
				'error_code' => $xml->getErrorCode(),
5694
				'error_msg'  => $xml->getErrorMessage(),
5695
			);
5696
		}
5697
		$cloud_site_options = $xml->getResponse();
5698
5699
		return $cloud_site_options;
5700
	}
5701
5702
	/**
5703
	 * Fetch the filtered array of options that we should compare to determine an identity crisis.
5704
	 *
5705
	 * @return array An array of options to check.
5706
	 */
5707
	public static function identity_crisis_options_to_check() {
5708
		$options = array(
5709
			'siteurl',
5710
			'home',
5711
		);
5712
		/**
5713
		 * Filter the options that we should compare to determine an identity crisis.
5714
		 *
5715
		 * @since 2.5.0
5716
		 *
5717
		 * @param array $options Array of options to compare to determine an identity crisis.
5718
		 */
5719
		return apply_filters( 'jetpack_identity_crisis_options_to_check', $options );
5720
	}
5721
5722
	/**
5723
	 * Checks to make sure that local options have the same values as remote options.  Will cache the results for up to 24 hours.
5724
	 *
5725
	 * @param bool $force_recheck Whether to ignore any cached transient and manually re-check.
5726
	 *
5727
	 * @return array An array of options that do not match.  If everything is good, it will evaluate to false.
5728
	 */
5729
	public static function check_identity_crisis( $force_recheck = false ) {
5730
		if ( ! Jetpack::is_active() || Jetpack::is_development_mode() )
5731
			return false;
5732
5733
		if ( $force_recheck || false === ( $errors = get_transient( 'jetpack_has_identity_crisis' ) ) ) {
5734
			$options_to_check = self::identity_crisis_options_to_check();
5735
			$cloud_options = Jetpack::init()->get_cloud_site_options( $options_to_check );
5736
			$errors        = array();
5737
5738
			foreach ( $cloud_options as $cloud_key => $cloud_value ) {
5739
5740
				// If it's not the same as the local value...
5741
				if ( $cloud_value !== get_option( $cloud_key ) ) {
5742
5743
					// Break out if we're getting errors.  We are going to check the error keys later when we alert.
5744
					if ( 'error_code' == $cloud_key ) {
5745
						$errors[ $cloud_key ] = $cloud_value;
5746
						break;
5747
					}
5748
5749
					$parsed_cloud_value = parse_url( $cloud_value );
5750
					// If the current options is an IP address
5751
					if ( filter_var( $parsed_cloud_value['host'], FILTER_VALIDATE_IP ) ) {
5752
						// Give the new value a Jetpack to fly in to the clouds
5753
						Jetpack::resolve_identity_crisis( $cloud_key );
5754
						continue;
5755
					}
5756
5757
					// And it's not been added to the whitelist...
5758
					if ( ! self::is_identity_crisis_value_whitelisted( $cloud_key, $cloud_value ) ) {
5759
						/*
5760
						 * This should be a temporary hack until a cleaner solution is found.
5761
						 *
5762
						 * The siteurl and home can be set to use http in General > Settings
5763
						 * however some constants can be defined that can force https in wp-admin
5764
						 * when this happens wpcom can confuse wporg with a fake identity
5765
						 * crisis with a mismatch of http vs https when it should be allowed.
5766
						 * we need to check that here.
5767
						 *
5768
						 * @see https://github.com/Automattic/jetpack/issues/1006
5769
						 */
5770
						if ( ( 'home' == $cloud_key || 'siteurl' == $cloud_key )
5771
							&& ( substr( $cloud_value, 0, 8 ) == "https://" )
5772
							&& Jetpack::init()->is_ssl_required_to_visit_site() ) {
5773
							// Ok, we found a mismatch of http and https because of wp-config, not an invalid url
5774
							continue;
5775
						}
5776
5777
5778
						// Then kick an error!
5779
						$errors[ $cloud_key ] = $cloud_value;
5780
					}
5781
				}
5782
			}
5783
		}
5784
5785
		/**
5786
		 * Filters the errors returned when checking for an Identity Crisis.
5787
		 *
5788
		 * @since 2.3.2
5789
		 *
5790
		 * @param array $errors Array of Identity Crisis errors.
5791
		 * @param bool $force_recheck Ignore any cached transient and manually re-check. Default to false.
5792
		 */
5793
		return apply_filters( 'jetpack_has_identity_crisis', $errors, $force_recheck );
5794
	}
5795
5796
	/*
5797
	 * Resolve ID crisis
5798
	 *
5799
	 * If the URL has changed, but the rest of the options are the same (i.e. blog/user tokens)
5800
	 * The user has the option to update the shadow site with the new URL before a new
5801
	 * token is created.
5802
	 *
5803
	 * @param $key : Which option to sync.  null defautlts to home and siteurl
5804
	 */
5805
	public static function resolve_identity_crisis( $key = null ) {
5806
		if ( $key ) {
5807
			$identity_options = array( $key );
5808
		} else {
5809
			$identity_options = self::identity_crisis_options_to_check();
5810
		}
5811
5812
		if ( is_array( $identity_options ) ) {
5813
			foreach( $identity_options as $identity_option ) {
5814
				Jetpack_Sync::sync_options( __FILE__, $identity_option );
5815
5816
				/**
5817
				 * Fires when a shadow site option is updated.
5818
				 * These options are updated via the Identity Crisis UI.
5819
				 * $identity_option is the option that gets updated.
5820
				 *
5821
				 * @since 3.7.0
5822
				 */
5823
				do_action( "update_option_{$identity_option}" );
5824
			}
5825
		}
5826
	}
5827
5828
	/*
5829
	 * Whitelist URL
5830
	 *
5831
	 * Ignore the URL differences between the blog and the shadow site.
5832
	 */
5833
	public static function whitelist_current_url() {
5834
		$options_to_check = Jetpack::identity_crisis_options_to_check();
5835
		$cloud_options = Jetpack::init()->get_cloud_site_options( $options_to_check );
5836
5837
		foreach ( $cloud_options as $cloud_key => $cloud_value ) {
5838
			Jetpack::whitelist_identity_crisis_value( $cloud_key, $cloud_value );
5839
		}
5840
	}
5841
5842
	/*
5843
	 * Ajax callbacks for ID crisis resolutions
5844
	 *
5845
	 * Things that could happen here:
5846
	 *  - site_migrated : Update the URL on the shadow blog to match new domain
5847
	 *  - whitelist     : Ignore the URL difference
5848
	 *  - default       : Error message
5849
	 */
5850
	public static function resolve_identity_crisis_ajax_callback() {
5851
		check_ajax_referer( 'resolve-identity-crisis', 'ajax-nonce' );
5852
5853
		switch ( $_POST[ 'crisis_resolution_action' ] ) {
5854
			case 'site_migrated':
5855
				Jetpack::resolve_identity_crisis();
5856
				echo 'resolved';
5857
				break;
5858
5859
			case 'whitelist':
5860
				Jetpack::whitelist_current_url();
5861
				echo 'whitelisted';
5862
				break;
5863
5864
			case 'reset_connection':
5865
				// Delete the options first so it doesn't get confused which site to disconnect dotcom-side
5866
				Jetpack_Options::delete_option(
5867
					array(
5868
						'register',
5869
						'blog_token',
5870
						'user_token',
5871
						'user_tokens',
5872
						'master_user',
5873
						'time_diff',
5874
						'fallback_no_verify_ssl_certs',
5875
						'id',
5876
					)
5877
				);
5878
				delete_transient( 'jetpack_has_identity_crisis' );
5879
5880
				echo 'reset-connection-success';
5881
				break;
5882
5883
			default:
5884
				echo 'missing action';
5885
				break;
5886
		}
5887
5888
		wp_die();
5889
	}
5890
5891
	/**
5892
	 * Adds a value to the whitelist for the specified key.
5893
	 *
5894
	 * @param string $key The option name that we're whitelisting the value for.
5895
	 * @param string $value The value that we're intending to add to the whitelist.
5896
	 *
5897
	 * @return bool Whether the value was added to the whitelist, or false if it was already there.
5898
	 */
5899
	public static function whitelist_identity_crisis_value( $key, $value ) {
5900
		if ( Jetpack::is_identity_crisis_value_whitelisted( $key, $value ) ) {
5901
			return false;
5902
		}
5903
5904
		$whitelist = Jetpack_Options::get_option( 'identity_crisis_whitelist', array() );
5905
		if ( empty( $whitelist[ $key ] ) || ! is_array( $whitelist[ $key ] ) ) {
5906
			$whitelist[ $key ] = array();
5907
		}
5908
		array_push( $whitelist[ $key ], $value );
5909
5910
		Jetpack_Options::update_option( 'identity_crisis_whitelist', $whitelist );
5911
		return true;
5912
	}
5913
5914
	/**
5915
	 * Checks whether a value is already whitelisted.
5916
	 *
5917
	 * @param string $key The option name that we're checking the value for.
5918
	 * @param string $value The value that we're curious to see if it's on the whitelist.
5919
	 *
5920
	 * @return bool Whether the value is whitelisted.
5921
	 */
5922
	public static function is_identity_crisis_value_whitelisted( $key, $value ) {
5923
		$whitelist = Jetpack_Options::get_option( 'identity_crisis_whitelist', array() );
5924
		if ( ! empty( $whitelist[ $key ] ) && is_array( $whitelist[ $key ] ) && in_array( $value, $whitelist[ $key ] ) ) {
5925
			return true;
5926
		}
5927
		return false;
5928
	}
5929
5930
	/**
5931
	 * Checks whether the home and siteurl specifically are whitelisted
5932
	 * Written so that we don't have re-check $key and $value params every time
5933
	 * we want to check if this site is whitelisted, for example in footer.php
5934
	 *
5935
	 * @return bool True = already whitelsisted False = not whitelisted
5936
	 */
5937
	public static function jetpack_is_staging_site() {
5938
		$current_whitelist = Jetpack_Options::get_option( 'identity_crisis_whitelist' );
5939
		if ( ! $current_whitelist ) {
5940
			return false;
5941
		}
5942
5943
		$options_to_check  = Jetpack::identity_crisis_options_to_check();
5944
		$cloud_options     = Jetpack::init()->get_cloud_site_options( $options_to_check );
5945
5946
		foreach ( $cloud_options as $cloud_key => $cloud_value ) {
5947
			if ( ! self::is_identity_crisis_value_whitelisted( $cloud_key, $cloud_value ) ) {
5948
				return false;
5949
			}
5950
		}
5951
		return true;
5952
	}
5953
5954
	public function identity_crisis_js( $nonce ) {
5955
?>
5956
<script>
5957
(function( $ ) {
5958
	var SECOND_IN_MS = 1000;
5959
5960
	function contactSupport( e ) {
5961
		e.preventDefault();
5962
		$( '.jp-id-crisis-question' ).hide();
5963
		$( '#jp-id-crisis-contact-support' ).show();
5964
	}
5965
5966
	function autodismissSuccessBanner() {
5967
		$( '.jp-identity-crisis' ).fadeOut(600); //.addClass( 'dismiss' );
5968
	}
5969
5970
	var data = { action: 'jetpack_resolve_identity_crisis', 'ajax-nonce': '<?php echo $nonce; ?>' };
5971
5972
	$( document ).ready(function() {
5973
5974
		// Site moved: Update the URL on the shadow blog
5975
		$( '.site-moved' ).click(function( e ) {
5976
			e.preventDefault();
5977
			data.crisis_resolution_action = 'site_migrated';
5978
			$( '#jp-id-crisis-question-1 .spinner' ).show();
5979
			$.post( ajaxurl, data, function() {
5980
				$( '.jp-id-crisis-question' ).hide();
5981
				$( '.banner-title' ).hide();
5982
				$( '#jp-id-crisis-success' ).show();
5983
				setTimeout( autodismissSuccessBanner, 6 * SECOND_IN_MS );
5984
			});
5985
5986
		});
5987
5988
		// URL hasn't changed, next question please.
5989
		$( '.site-not-moved' ).click(function( e ) {
5990
			e.preventDefault();
5991
			$( '.jp-id-crisis-question' ).hide();
5992
			$( '#jp-id-crisis-question-2' ).show();
5993
		});
5994
5995
		// Reset connection: two separate sites.
5996
		$( '.reset-connection' ).click(function( e ) {
5997
			data.crisis_resolution_action = 'reset_connection';
5998
			$.post( ajaxurl, data, function( response ) {
5999
				if ( 'reset-connection-success' === response ) {
6000
					window.location.replace( '<?php echo Jetpack::admin_url(); ?>' );
6001
				}
6002
			});
6003
		});
6004
6005
		// It's a dev environment.  Ignore.
6006
		$( '.is-dev-env' ).click(function( e ) {
6007
			data.crisis_resolution_action = 'whitelist';
6008
			$( '#jp-id-crisis-question-2 .spinner' ).show();
6009
			$.post( ajaxurl, data, function() {
6010
				$( '.jp-id-crisis-question' ).hide();
6011
				$( '.banner-title' ).hide();
6012
				$( '#jp-id-crisis-success' ).show();
6013
				setTimeout( autodismissSuccessBanner, 4 * SECOND_IN_MS );
6014
			});
6015
		});
6016
6017
		$( '.not-reconnecting' ).click(contactSupport);
6018
		$( '.not-staging-or-dev' ).click(contactSupport);
6019
	});
6020
})( jQuery );
6021
</script>
6022
<?php
6023
	}
6024
6025
	/**
6026
	 * Displays an admin_notice, alerting the user to an identity crisis.
6027
	 */
6028
	public function alert_identity_crisis() {
6029
		// @todo temporary killing of feature in 3.8.1 as it revealed a number of scenarios not foreseen.
6030
		if ( ! Jetpack::is_development_version() ) {
6031
			return;
6032
		}
6033
6034
		// @todo temporary copout for dealing with domain mapping
6035
		// @see https://github.com/Automattic/jetpack/issues/2702
6036
		if ( is_multisite() && defined( 'SUNRISE' ) && ! Jetpack::is_development_version() ) {
6037
			return;
6038
		}
6039
6040
		if ( ! current_user_can( 'jetpack_disconnect' ) ) {
6041
			return;
6042
		}
6043
6044
		if ( ! $errors = self::check_identity_crisis() ) {
6045
			return;
6046
		}
6047
6048
		// Only show on dashboard and jetpack pages
6049
		$screen = get_current_screen();
6050
		if ( 'dashboard' !== $screen->base && ! did_action( 'jetpack_notices' ) ) {
6051
			return;
6052
		}
6053
6054
		// Include the js!
6055
		$ajax_nonce = wp_create_nonce( 'resolve-identity-crisis' );
6056
		$this->identity_crisis_js( $ajax_nonce );
6057
6058
		// Include the CSS!
6059
		if ( ! wp_script_is( 'jetpack', 'done' ) ) {
6060
			$this->admin_banner_styles();
6061
		}
6062
6063
		if ( ! array_key_exists( 'error_code', $errors ) ) {
6064
			$key = 'siteurl';
6065
			if ( ! $errors[ $key ] ) {
6066
				$key = 'home';
6067
			}
6068
		} else {
6069
			$key = 'error_code';
6070
			// 401 is the only error we care about.  Any other errors should not trigger the alert.
6071
			if ( 401 !== $errors[ $key ] ) {
6072
				return;
6073
			}
6074
		}
6075
6076
		?>
6077
6078
		<style>
6079
			.jp-identity-crisis .jp-btn-group {
6080
					margin: 15px 0;
6081
				}
6082
			.jp-identity-crisis strong {
6083
					color: #518d2a;
6084
				}
6085
			.jp-identity-crisis.dismiss {
6086
				display: none;
6087
			}
6088
			.jp-identity-crisis .button {
6089
				margin-right: 4px;
6090
			}
6091
		</style>
6092
6093
		<div id="message" class="error jetpack-message jp-identity-crisis stay-visible">
6094
			<div class="service-mark"></div>
6095
			<div class="jp-id-banner__content">
6096
				<!-- <h3 class="banner-title"><?php _e( 'Something\'s not quite right with your Jetpack connection! Let\'s fix that.', 'jetpack' ); ?></h3> -->
6097
6098
				<div class="jp-id-crisis-question" id="jp-id-crisis-question-1">
6099
					<?php
6100
					// 401 means that this site has been disconnected from wpcom, but the remote site still thinks it's connected.
6101
					if ( 'error_code' == $key && '401' == $errors[ $key ] ) : ?>
6102
						<div class="banner-content">
6103
							<p><?php
6104
								/* translators: %s is a URL */
6105
								printf( __( 'Our records show that this site does not have a valid connection to WordPress.com. Please reset your connection to fix this. <a href="%s" target="_blank">What caused this?</a>', 'jetpack' ), 'https://jetpack.me/support/no-valid-wordpress-com-connection/' );
6106
							?></p>
6107
						</div>
6108
						<div class="jp-btn-group">
6109
							<a href="#" class="reset-connection"><?php _e( 'Reset the connection', 'jetpack' ); ?></a>
6110
							<span class="idc-separator">|</span>
6111
							<a href="<?php echo esc_url( wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=dismiss' ), 'jetpack-deactivate' ) ); ?>"><?php _e( 'Deactivate Jetpack', 'jetpack' ); ?></a>
6112
						</div>
6113
					<?php else : ?>
6114
							<div class="banner-content">
6115
							<p><?php printf( __( 'It looks like you may have changed your domain. Is <strong>%1$s</strong> still your site\'s domain, or have you updated it to <strong> %2$s </strong>?', 'jetpack' ), $errors[ $key ], (string) get_option( $key ) ); ?></p>
6116
							</div>
6117
						<div class="jp-btn-group">
6118
							<a href="#" class="regular site-moved"><?php printf( __( '%s is now my domain.', 'jetpack' ), $errors[ $key ] ); ?></a> <span class="idc-separator">|</span> <a href="#" class="site-not-moved" ><?php printf( __( '%s is still my domain.', 'jetpack' ), (string) get_option( $key ) ); ?></a>
6119
							<span class="spinner"></span>
6120
						</div>
6121
					<?php endif ; ?>
6122
				</div>
6123
6124
				<div class="jp-id-crisis-question" id="jp-id-crisis-question-2" style="display: none;">
6125
					<div class="banner-content">
6126
						<p><?php printf(
6127
							/* translators: %1$s, %2$s and %3$s are URLs */
6128
							__(
6129
								'Are <strong> %2$s </strong> and <strong> %1$s </strong> two completely separate websites? If so we should create a new connection, which will reset your followers and linked services. <a href="%3$s"><em>What does this mean?</em></a>',
6130
								'jetpack'
6131
							),
6132
							$errors[ $key ],
6133
							(string) get_option( $key ),
6134
							'https://jetpack.me/support/what-does-resetting-the-connection-mean/'
6135
						); ?></p>
6136
					</div>
6137
					<div class="jp-btn-group">
6138
						<a href="#" class="reset-connection"><?php _e( 'Reset the connection', 'jetpack' ); ?></a> <span class="idc-separator">|</span>
6139
						<a href="#" class="is-dev-env"><?php _e( 'This is a development environment', 'jetpack' ); ?></a> <span class="idc-separator">|</span>
6140
						<a href="https://jetpack.me/contact-support/" class="contact-support"><?php _e( 'Submit a support ticket', 'jetpack' ); ?></a>
6141
						<span class="spinner"></span>
6142
					</div>
6143
				</div>
6144
6145
				<div class="jp-id-crisis-success" id="jp-id-crisis-success" style="display: none;">
6146
					<h3 class="success-notice"><?php printf( __( 'Thanks for taking the time to sort things out. We&#039;ve updated our records accordingly!', 'jetpack' ) ); ?></h3>
6147
				</div>
6148
			</div>
6149
		</div>
6150
6151
		<?php
6152
	}
6153
6154
	/**
6155
	 * Maybe Use a .min.css stylesheet, maybe not.
6156
	 *
6157
	 * Hooks onto `plugins_url` filter at priority 1, and accepts all 3 args.
6158
	 */
6159
	public static function maybe_min_asset( $url, $path, $plugin ) {
6160
		// Short out on things trying to find actual paths.
6161
		if ( ! $path || empty( $plugin ) ) {
6162
			return $url;
6163
		}
6164
6165
		// Strip out the abspath.
6166
		$base = dirname( plugin_basename( $plugin ) );
6167
6168
		// Short out on non-Jetpack assets.
6169
		if ( 'jetpack/' !== substr( $base, 0, 8 ) ) {
6170
			return $url;
6171
		}
6172
6173
		// File name parsing.
6174
		$file              = "{$base}/{$path}";
6175
		$full_path         = JETPACK__PLUGIN_DIR . substr( $file, 8 );
6176
		$file_name         = substr( $full_path, strrpos( $full_path, '/' ) + 1 );
6177
		$file_name_parts_r = array_reverse( explode( '.', $file_name ) );
6178
		$extension         = array_shift( $file_name_parts_r );
6179
6180
		if ( in_array( strtolower( $extension ), array( 'css', 'js' ) ) ) {
6181
			// Already pointing at the minified version.
6182
			if ( 'min' === $file_name_parts_r[0] ) {
6183
				return $url;
6184
			}
6185
6186
			$min_full_path = preg_replace( "#\.{$extension}$#", ".min.{$extension}", $full_path );
6187
			if ( file_exists( $min_full_path ) ) {
6188
				$url = preg_replace( "#\.{$extension}$#", ".min.{$extension}", $url );
6189
			}
6190
		}
6191
6192
		return $url;
6193
	}
6194
6195
	/**
6196
	 * Maybe inlines a stylesheet.
6197
	 *
6198
	 * If you'd like to inline a stylesheet instead of printing a link to it,
6199
	 * wp_style_add_data( 'handle', 'jetpack-inline', true );
6200
	 *
6201
	 * Attached to `style_loader_tag` filter.
6202
	 *
6203
	 * @param string $tag The tag that would link to the external asset.
6204
	 * @param string $handle The registered handle of the script in question.
6205
	 *
6206
	 * @return string
6207
	 */
6208
	public static function maybe_inline_style( $tag, $handle ) {
6209
		global $wp_styles;
6210
		$item = $wp_styles->registered[ $handle ];
6211
6212
		if ( ! isset( $item->extra['jetpack-inline'] ) || ! $item->extra['jetpack-inline'] ) {
6213
			return $tag;
6214
		}
6215
6216
		if ( preg_match( '# href=\'([^\']+)\' #i', $tag, $matches ) ) {
6217
			$href = $matches[1];
6218
			// Strip off query string
6219
			if ( $pos = strpos( $href, '?' ) ) {
6220
				$href = substr( $href, 0, $pos );
6221
			}
6222
			// Strip off fragment
6223
			if ( $pos = strpos( $href, '#' ) ) {
6224
				$href = substr( $href, 0, $pos );
6225
			}
6226
		} else {
6227
			return $tag;
6228
		}
6229
6230
		$plugins_dir = plugin_dir_url( JETPACK__PLUGIN_FILE );
6231
		if ( $plugins_dir !== substr( $href, 0, strlen( $plugins_dir ) ) ) {
6232
			return $tag;
6233
		}
6234
6235
		// If this stylesheet has a RTL version, and the RTL version replaces normal...
6236
		if ( isset( $item->extra['rtl'] ) && 'replace' === $item->extra['rtl'] && is_rtl() ) {
6237
			// And this isn't the pass that actually deals with the RTL version...
6238
			if ( false === strpos( $tag, " id='$handle-rtl-css' " ) ) {
6239
				// Short out, as the RTL version will deal with it in a moment.
6240
				return $tag;
6241
			}
6242
		}
6243
6244
		$file = JETPACK__PLUGIN_DIR . substr( $href, strlen( $plugins_dir ) );
6245
		$css  = Jetpack::absolutize_css_urls( file_get_contents( $file ), $href );
6246
		if ( $css ) {
6247
			$tag = "<!-- Inline {$item->handle} -->\r\n";
6248
			if ( empty( $item->extra['after'] ) ) {
6249
				wp_add_inline_style( $handle, $css );
6250
			} else {
6251
				array_unshift( $item->extra['after'], $css );
6252
				wp_style_add_data( $handle, 'after', $item->extra['after'] );
6253
			}
6254
		}
6255
6256
		return $tag;
6257
	}
6258
6259
	/**
6260
	 * Loads a view file from the views
6261
	 *
6262
	 * Data passed in with the $data parameter will be available in the
6263
	 * template file as $data['value']
6264
	 *
6265
	 * @param string $template - Template file to load
6266
	 * @param array $data - Any data to pass along to the template
6267
	 * @return boolean - If template file was found
6268
	 **/
6269
	public function load_view( $template, $data = array() ) {
6270
		$views_dir = JETPACK__PLUGIN_DIR . 'views/';
6271
6272
		if( file_exists( $views_dir . $template ) ) {
6273
			require_once( $views_dir . $template );
6274
			return true;
6275
		}
6276
6277
		error_log( "Jetpack: Unable to find view file $views_dir$template" );
6278
		return false;
6279
	}
6280
6281
	/**
6282
	 * Sends a ping to the Jetpack servers to toggle on/off remote portions
6283
	 * required by some modules.
6284
	 *
6285
	 * @param string $module_slug
6286
	 */
6287
	public function toggle_module_on_wpcom( $module_slug ) {
6288
		Jetpack::init()->sync->register( 'noop' );
6289
6290
		if ( false !== strpos( current_filter(), 'jetpack_activate_module_' ) ) {
6291
			self::check_privacy( $module_slug );
6292
		}
6293
6294
	}
6295
6296
	/**
6297
	 * Throws warnings for deprecated hooks to be removed from Jetpack
6298
	 */
6299
	public function deprecated_hooks() {
6300
		global $wp_filter;
6301
6302
		/*
6303
		 * Format:
6304
		 * deprecated_filter_name => replacement_name
6305
		 *
6306
		 * If there is no replacement us null for replacement_name
6307
		 */
6308
		$deprecated_list = array(
6309
			'jetpack_bail_on_shortcode' => 'jetpack_shortcodes_to_include',
6310
			'wpl_sharing_2014_1'        => null,
6311
		);
6312
6313
		// This is a silly loop depth. Better way?
6314
		foreach( $deprecated_list AS $hook => $hook_alt ) {
6315
			if( isset( $wp_filter[ $hook ] ) && is_array( $wp_filter[ $hook ] ) ) {
6316
				foreach( $wp_filter[$hook] AS $func => $values ) {
6317
					foreach( $values AS $hooked ) {
6318
						_deprecated_function( $hook . ' used for ' . $hooked['function'], null, $hook_alt );
6319
					}
6320
				}
6321
			}
6322
		}
6323
	}
6324
6325
	/**
6326
	 * Converts any url in a stylesheet, to the correct absolute url.
6327
	 *
6328
	 * Considerations:
6329
	 *  - Normal, relative URLs     `feh.png`
6330
	 *  - Data URLs                 `data:image/gif;base64,eh129ehiuehjdhsa==`
6331
	 *  - Schema-agnostic URLs      `//domain.com/feh.png`
6332
	 *  - Absolute URLs             `http://domain.com/feh.png`
6333
	 *  - Domain root relative URLs `/feh.png`
6334
	 *
6335
	 * @param $css string: The raw CSS -- should be read in directly from the file.
6336
	 * @param $css_file_url : The URL that the file can be accessed at, for calculating paths from.
6337
	 *
6338
	 * @return mixed|string
6339
	 */
6340
	public static function absolutize_css_urls( $css, $css_file_url ) {
6341
		$pattern = '#url\((?P<path>[^)]*)\)#i';
6342
		$css_dir = dirname( $css_file_url );
6343
		$p       = parse_url( $css_dir );
6344
		$domain  = sprintf(
6345
					'%1$s//%2$s%3$s%4$s',
6346
					isset( $p['scheme'] )           ? "{$p['scheme']}:" : '',
6347
					isset( $p['user'], $p['pass'] ) ? "{$p['user']}:{$p['pass']}@" : '',
6348
					$p['host'],
6349
					isset( $p['port'] )             ? ":{$p['port']}" : ''
6350
				);
6351
6352
		if ( preg_match_all( $pattern, $css, $matches, PREG_SET_ORDER ) ) {
6353
			$find = $replace = array();
6354
			foreach ( $matches as $match ) {
6355
				$url = trim( $match['path'], "'\" \t" );
6356
6357
				// If this is a data url, we don't want to mess with it.
6358
				if ( 'data:' === substr( $url, 0, 5 ) ) {
6359
					continue;
6360
				}
6361
6362
				// If this is an absolute or protocol-agnostic url,
6363
				// we don't want to mess with it.
6364
				if ( preg_match( '#^(https?:)?//#i', $url ) ) {
6365
					continue;
6366
				}
6367
6368
				switch ( substr( $url, 0, 1 ) ) {
6369
					case '/':
6370
						$absolute = $domain . $url;
6371
						break;
6372
					default:
6373
						$absolute = $css_dir . '/' . $url;
6374
				}
6375
6376
				$find[]    = $match[0];
6377
				$replace[] = sprintf( 'url("%s")', $absolute );
6378
			}
6379
			$css = str_replace( $find, $replace, $css );
6380
		}
6381
6382
		return $css;
6383
	}
6384
6385
	/**
6386
	 * This method checks to see if SSL is required by the site in
6387
	 * order to visit it in some way other than only setting the
6388
	 * https value in the home or siteurl values.
6389
	 *
6390
	 * @since 3.2
6391
	 * @return boolean
6392
	 **/
6393
	private function is_ssl_required_to_visit_site() {
6394
		global $wp_version;
6395
		$ssl = is_ssl();
6396
6397
		if ( version_compare( $wp_version, '4.4-alpha', '<=' ) && force_ssl_login() ) { // force_ssl_login deprecated WP 4.4.
6398
			$ssl = true;
6399
		} else if ( force_ssl_admin() ) {
6400
			$ssl = true;
6401
		}
6402
		return $ssl;
6403
	}
6404
6405
	/**
6406
	 * This methods removes all of the registered css files on the frontend
6407
	 * from Jetpack in favor of using a single file. In effect "imploding"
6408
	 * all the files into one file.
6409
	 *
6410
	 * Pros:
6411
	 * - Uses only ONE css asset connection instead of 15
6412
	 * - Saves a minimum of 56k
6413
	 * - Reduces server load
6414
	 * - Reduces time to first painted byte
6415
	 *
6416
	 * Cons:
6417
	 * - Loads css for ALL modules. However all selectors are prefixed so it
6418
	 *		should not cause any issues with themes.
6419
	 * - Plugins/themes dequeuing styles no longer do anything. See
6420
	 *		jetpack_implode_frontend_css filter for a workaround
6421
	 *
6422
	 * For some situations developers may wish to disable css imploding and
6423
	 * instead operate in legacy mode where each file loads seperately and
6424
	 * can be edited individually or dequeued. This can be accomplished with
6425
	 * the following line:
6426
	 *
6427
	 * add_filter( 'jetpack_implode_frontend_css', '__return_false' );
6428
	 *
6429
	 * @since 3.2
6430
	 **/
6431
	public function implode_frontend_css( $travis_test = false ) {
6432
		$do_implode = true;
6433
		if ( defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ) {
6434
			$do_implode = false;
6435
		}
6436
6437
		/**
6438
		 * Allow CSS to be concatenated into a single jetpack.css file.
6439
		 *
6440
		 * @since 3.2.0
6441
		 *
6442
		 * @param bool $do_implode Should CSS be concatenated? Default to true.
6443
		 */
6444
		$do_implode = apply_filters( 'jetpack_implode_frontend_css', $do_implode );
6445
6446
		// Do not use the imploded file when default behaviour was altered through the filter
6447
		if ( ! $do_implode ) {
6448
			return;
6449
		}
6450
6451
		// We do not want to use the imploded file in dev mode, or if not connected
6452
		if ( Jetpack::is_development_mode() || ! self::is_active() ) {
6453
			if ( ! $travis_test ) {
6454
				return;
6455
			}
6456
		}
6457
6458
		// Do not use the imploded file if sharing css was dequeued via the sharing settings screen
6459
		if ( get_option( 'sharedaddy_disable_resources' ) ) {
6460
			return;
6461
		}
6462
6463
		/*
6464
		 * Now we assume Jetpack is connected and able to serve the single
6465
		 * file.
6466
		 *
6467
		 * In the future there will be a check here to serve the file locally
6468
		 * or potentially from the Jetpack CDN
6469
		 *
6470
		 * For now:
6471
		 * - Enqueue a single imploded css file
6472
		 * - Zero out the style_loader_tag for the bundled ones
6473
		 * - Be happy, drink scotch
6474
		 */
6475
6476
		add_filter( 'style_loader_tag', array( $this, 'concat_remove_style_loader_tag' ), 10, 2 );
6477
6478
		$version = Jetpack::is_development_version() ? filemtime( JETPACK__PLUGIN_DIR . 'css/jetpack.css' ) : JETPACK__VERSION;
6479
6480
		wp_enqueue_style( 'jetpack_css', plugins_url( 'css/jetpack.css', __FILE__ ), array(), $version );
6481
		wp_style_add_data( 'jetpack_css', 'rtl', 'replace' );
6482
	}
6483
6484
	function concat_remove_style_loader_tag( $tag, $handle ) {
6485
		if ( in_array( $handle, $this->concatenated_style_handles ) ) {
6486
			$tag = '';
6487
			if ( defined( 'WP_DEBUG' ) && WP_DEBUG ) {
6488
				$tag = "<!-- `" . esc_html( $handle ) . "` is included in the concatenated jetpack.css -->\r\n";
6489
			}
6490
		}
6491
6492
		return $tag;
6493
	}
6494
6495
	/*
6496
	 * Check the heartbeat data
6497
	 *
6498
	 * Organizes the heartbeat data by severity.  For example, if the site
6499
	 * is in an ID crisis, it will be in the $filtered_data['bad'] array.
6500
	 *
6501
	 * Data will be added to "caution" array, if it either:
6502
	 *  - Out of date Jetpack version
6503
	 *  - Out of date WP version
6504
	 *  - Out of date PHP version
6505
	 *
6506
	 * $return array $filtered_data
6507
	 */
6508
	public static function jetpack_check_heartbeat_data() {
6509
		$raw_data = Jetpack_Heartbeat::generate_stats_array();
6510
6511
		$good    = array();
6512
		$caution = array();
6513
		$bad     = array();
6514
6515
		foreach ( $raw_data as $stat => $value ) {
6516
6517
			// Check jetpack version
6518
			if ( 'version' == $stat ) {
6519
				if ( version_compare( $value, JETPACK__VERSION, '<' ) ) {
6520
					$caution[ $stat ] = $value . " - min supported is " . JETPACK__VERSION;
6521
					continue;
6522
				}
6523
			}
6524
6525
			// Check WP version
6526
			if ( 'wp-version' == $stat ) {
6527
				if ( version_compare( $value, JETPACK__MINIMUM_WP_VERSION, '<' ) ) {
6528
					$caution[ $stat ] = $value . " - min supported is " . JETPACK__MINIMUM_WP_VERSION;
6529
					continue;
6530
				}
6531
			}
6532
6533
			// Check PHP version
6534
			if ( 'php-version' == $stat ) {
6535
				if ( version_compare( PHP_VERSION, '5.2.4', '<' ) ) {
6536
					$caution[ $stat ] = $value . " - min supported is 5.2.4";
6537
					continue;
6538
				}
6539
			}
6540
6541
			// Check ID crisis
6542
			if ( 'identitycrisis' == $stat ) {
6543
				if ( 'yes' == $value ) {
6544
					$bad[ $stat ] = $value;
6545
					continue;
6546
				}
6547
			}
6548
6549
			// The rest are good :)
6550
			$good[ $stat ] = $value;
6551
		}
6552
6553
		$filtered_data = array(
6554
			'good'    => $good,
6555
			'caution' => $caution,
6556
			'bad'     => $bad
6557
		);
6558
6559
		return $filtered_data;
6560
	}
6561
6562
6563
	/*
6564
	 * This method is used to organize all options that can be reset
6565
	 * without disconnecting Jetpack.
6566
	 *
6567
	 * It is used in class.jetpack-cli.php to reset options
6568
	 *
6569
	 * @return array of options to delete.
6570
	 */
6571
	public static function get_jetpack_options_for_reset() {
6572
		$jetpack_options            = Jetpack_Options::get_option_names();
6573
		$jetpack_options_non_compat = Jetpack_Options::get_option_names( 'non_compact' );
6574
		$jetpack_options_private    = Jetpack_Options::get_option_names( 'private' );
6575
6576
		$all_jp_options = array_merge( $jetpack_options, $jetpack_options_non_compat, $jetpack_options_private );
6577
6578
		// A manual build of the wp options
6579
		$wp_options = array(
6580
			'sharing-options',
6581
			'disabled_likes',
6582
			'disabled_reblogs',
6583
			'jetpack_comments_likes_enabled',
6584
			'wp_mobile_excerpt',
6585
			'wp_mobile_featured_images',
6586
			'wp_mobile_app_promos',
6587
			'stats_options',
6588
			'stats_dashboard_widget',
6589
			'safecss_preview_rev',
6590
			'safecss_rev',
6591
			'safecss_revision_migrated',
6592
			'nova_menu_order',
6593
			'jetpack_portfolio',
6594
			'jetpack_portfolio_posts_per_page',
6595
			'jetpack_testimonial',
6596
			'jetpack_testimonial_posts_per_page',
6597
			'wp_mobile_custom_css',
6598
			'sharedaddy_disable_resources',
6599
			'sharing-options',
6600
			'sharing-services',
6601
			'site_icon_temp_data',
6602
			'featured-content',
6603
			'site_logo',
6604
		);
6605
6606
		// Flag some Jetpack options as unsafe
6607
		$unsafe_options = array(
6608
			'id',                           // (int)    The Client ID/WP.com Blog ID of this site.
6609
			'master_user',                  // (int)    The local User ID of the user who connected this site to jetpack.wordpress.com.
6610
			'version',                      // (string) Used during upgrade procedure to auto-activate new modules. version:time
6611
			'jumpstart',                    // (string) A flag for whether or not to show the Jump Start.  Accepts: new_connection, jumpstart_activated, jetpack_action_taken, jumpstart_dismissed.
6612
6613
			// non_compact
6614
			'activated',
6615
6616
			// private
6617
			'register',
6618
			'blog_token',                  // (string) The Client Secret/Blog Token of this site.
6619
			'user_token',                  // (string) The User Token of this site. (deprecated)
6620
			'user_tokens'
6621
		);
6622
6623
		// Remove the unsafe Jetpack options
6624
		foreach ( $unsafe_options as $unsafe_option ) {
6625
			if ( false !== ( $key = array_search( $unsafe_option, $all_jp_options ) ) ) {
6626
				unset( $all_jp_options[ $key ] );
6627
			}
6628
		}
6629
6630
		$options = array(
6631
			'jp_options' => $all_jp_options,
6632
			'wp_options' => $wp_options
6633
		);
6634
6635
		return $options;
6636
	}
6637
6638
	/*
6639
	 * Check if an option of a Jetpack module has been updated.
6640
	 *
6641
	 * If any module option has been updated before Jump Start has been dismissed,
6642
	 * update the 'jumpstart' option so we can hide Jump Start.
6643
	 */
6644
	public static function jumpstart_has_updated_module_option( $option_name = '' ) {
6645
		// Bail if Jump Start has already been dismissed
6646
		if ( 'new_connection' !== Jetpack::get_option( 'jumpstart' ) ) {
6647
			return false;
6648
		}
6649
6650
		$jetpack = Jetpack::init();
6651
6652
6653
		// Manual build of module options
6654
		$option_names = self::get_jetpack_options_for_reset();
6655
6656
		if ( in_array( $option_name, $option_names['wp_options'] ) ) {
6657
			Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
6658
6659
			//Jump start is being dismissed send data to MC Stats
6660
			$jetpack->stat( 'jumpstart', 'manual,'.$option_name );
6661
6662
			$jetpack->do_stats( 'server_side' );
6663
		}
6664
6665
	}
6666
6667
	/*
6668
	 * Strip http:// or https:// from a url, replaces forward slash with ::,
6669
	 * so we can bring them directly to their site in calypso.
6670
	 *
6671
	 * @param string | url
6672
	 * @return string | url without the guff
6673
	 */
6674
	public static function build_raw_urls( $url ) {
6675
		$strip_http = '/.*?:\/\//i';
6676
		$url = preg_replace( $strip_http, '', $url  );
6677
		$url = str_replace( '/', '::', $url );
6678
		return $url;
6679
	}
6680
6681
	/**
6682
	 * Stores and prints out domains to prefetch for page speed optimization.
6683
	 *
6684
	 * @param mixed $new_urls
6685
	 */
6686
	public static function dns_prefetch( $new_urls = null ) {
6687
		static $prefetch_urls = array();
6688
		if ( empty( $new_urls ) && ! empty( $prefetch_urls ) ) {
6689
			echo "\r\n";
6690
			foreach ( $prefetch_urls as $this_prefetch_url ) {
6691
				printf( "<link rel='dns-prefetch' href='%s'>\r\n", esc_attr( $this_prefetch_url ) );
6692
			}
6693
		} elseif ( ! empty( $new_urls ) ) {
6694
			if ( ! has_action( 'wp_head', array( __CLASS__, __FUNCTION__ ) ) ) {
6695
				add_action( 'wp_head', array( __CLASS__, __FUNCTION__ ) );
6696
			}
6697
			foreach ( (array) $new_urls as $this_new_url ) {
6698
				$prefetch_urls[] = strtolower( untrailingslashit( preg_replace( '#^https?://#i', '//', $this_new_url ) ) );
6699
			}
6700
			$prefetch_urls = array_unique( $prefetch_urls );
6701
		}
6702
	}
6703
6704
	public function wp_dashboard_setup() {
6705
		if ( self::is_active() ) {
6706
			add_action( 'jetpack_dashboard_widget', array( __CLASS__, 'dashboard_widget_footer' ), 999 );
6707
			$widget_title = __( 'Site Stats', 'jetpack' );
6708
		} elseif ( ! self::is_development_mode() && current_user_can( 'jetpack_connect' ) ) {
6709
			add_action( 'jetpack_dashboard_widget', array( $this, 'dashboard_widget_connect_to_wpcom' ) );
6710
			$widget_title = __( 'Please Connect Jetpack', 'jetpack' );
6711
		}
6712
6713
		if ( has_action( 'jetpack_dashboard_widget' ) ) {
6714
			wp_add_dashboard_widget(
6715
				'jetpack_summary_widget',
6716
				$widget_title,
6717
				array( __CLASS__, 'dashboard_widget' )
6718
			);
6719
			wp_enqueue_style( 'jetpack-dashboard-widget', plugins_url( 'css/dashboard-widget.css', JETPACK__PLUGIN_FILE ), array(), JETPACK__VERSION );
6720
6721
			// If we're inactive and not in development mode, sort our box to the top.
6722
			if ( ! self::is_active() && ! self::is_development_mode() ) {
6723
				global $wp_meta_boxes;
6724
6725
				$dashboard = $wp_meta_boxes['dashboard']['normal']['core'];
6726
				$ours      = array( 'jetpack_summary_widget' => $dashboard['jetpack_summary_widget'] );
6727
6728
				$wp_meta_boxes['dashboard']['normal']['core'] = array_merge( $ours, $dashboard );
6729
			}
6730
		}
6731
	}
6732
6733
	/**
6734
	 * @param mixed $result Value for the user's option
6735
	 * @return mixed
6736
	 */
6737
	function get_user_option_meta_box_order_dashboard( $sorted ) {
6738
		if ( ! is_array( $sorted ) ) {
6739
			return $sorted;
6740
		}
6741
6742
		foreach ( $sorted as $box_context => $ids ) {
6743
			if ( false === strpos( $ids, 'dashboard_stats' ) ) {
6744
				// If the old id isn't anywhere in the ids, don't bother exploding and fail out.
6745
				continue;
6746
			}
6747
6748
			$ids_array = explode( ',', $ids );
6749
			$key = array_search( 'dashboard_stats', $ids_array );
6750
6751
			if ( false !== $key ) {
6752
				// If we've found that exact value in the option (and not `google_dashboard_stats` for example)
6753
				$ids_array[ $key ] = 'jetpack_summary_widget';
6754
				$sorted[ $box_context ] = implode( ',', $ids_array );
6755
				// We've found it, stop searching, and just return.
6756
				break;
6757
			}
6758
		}
6759
6760
		return $sorted;
6761
	}
6762
6763
	public static function dashboard_widget() {
6764
		/**
6765
		 * Fires when the dashboard is loaded.
6766
		 *
6767
		 * @since 3.4.0
6768
		 */
6769
		do_action( 'jetpack_dashboard_widget' );
6770
	}
6771
6772
	public static function dashboard_widget_footer() {
6773
		?>
6774
		<footer>
6775
6776
		<div class="protect">
6777
			<?php if ( Jetpack::is_module_active( 'protect' ) ) : ?>
6778
				<h3><?php echo number_format_i18n( get_site_option( 'jetpack_protect_blocked_attempts', 0 ) ); ?></h3>
6779
				<p><?php echo esc_html_x( 'Blocked malicious login attempts', '{#} Blocked malicious login attempts -- number is on a prior line, text is a caption.', 'jetpack' ); ?></p>
6780
			<?php elseif ( current_user_can( 'jetpack_activate_modules' ) && ! self::is_development_mode() ) : ?>
6781
				<a href="<?php echo esc_url( wp_nonce_url( Jetpack::admin_url( array( 'action' => 'activate', 'module' => 'protect' ) ), 'jetpack_activate-protect' ) ); ?>" class="button button-jetpack" title="<?php esc_attr_e( 'Protect helps to keep you secure from brute-force login attacks.', 'jetpack' ); ?>">
6782
					<?php esc_html_e( 'Activate Protect', 'jetpack' ); ?>
6783
				</a>
6784
			<?php else : ?>
6785
				<?php esc_html_e( 'Protect is inactive.', 'jetpack' ); ?>
6786
			<?php endif; ?>
6787
		</div>
6788
6789
		<div class="akismet">
6790
			<?php if ( is_plugin_active( 'akismet/akismet.php' ) ) : ?>
6791
				<h3><?php echo number_format_i18n( get_option( 'akismet_spam_count', 0 ) ); ?></h3>
6792
				<p><?php echo esc_html_x( 'Spam comments blocked by Akismet.', '{#} Spam comments blocked by Akismet -- number is on a prior line, text is a caption.', 'jetpack' ); ?></p>
6793 View Code Duplication
			<?php elseif ( current_user_can( 'activate_plugins' ) && ! is_wp_error( validate_plugin( 'akismet/akismet.php' ) ) ) : ?>
6794
				<a href="<?php echo esc_url( wp_nonce_url( add_query_arg( array( 'action' => 'activate', 'plugin' => 'akismet/akismet.php' ), admin_url( 'plugins.php' ) ), 'activate-plugin_akismet/akismet.php' ) ); ?>" class="button button-jetpack">
6795
					<?php esc_html_e( 'Activate Akismet', 'jetpack' ); ?>
6796
				</a>
6797
			<?php else : ?>
6798
				<p><a href="<?php echo esc_url( 'https://akismet.com/?utm_source=jetpack&utm_medium=link&utm_campaign=Jetpack%20Dashboard%20Widget%20Footer%20Link' ); ?>"><?php esc_html_e( 'Akismet can help to keep your blog safe from spam!', 'jetpack' ); ?></a></p>
6799
			<?php endif; ?>
6800
		</div>
6801
6802
6803 View Code Duplication
		<?php if ( ! current_user_can( 'edit_posts' ) && self::is_user_connected() ) : ?>
6804
			<div style="width: 100%; text-align: center; padding-top: 20px; clear: both;"><a class="button" title="<?php esc_attr_e( 'Unlink your account from WordPress.com', 'jetpack' ); ?>" href="<?php echo esc_url( wp_nonce_url( add_query_arg( array( 'action' => 'unlink', 'redirect' => 'sub-unlink' ), admin_url( 'index.php' ) ), 'jetpack-unlink' ) ); ?>"><?php esc_html_e( 'Unlink your account from WordPress.com', 'jetpack' ); ?></a></div>
6805
		<?php endif; ?>
6806
6807
		</footer>
6808
		<?php
6809
	}
6810
6811
	public function dashboard_widget_connect_to_wpcom() {
6812
		if ( Jetpack::is_active() || Jetpack::is_development_mode() || ! current_user_can( 'jetpack_connect' ) ) {
6813
			return;
6814
		}
6815
		?>
6816
		<div class="wpcom-connect">
6817
			<div class="jp-emblem">
6818
			<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0" y="0" viewBox="0 0 172.9 172.9" enable-background="new 0 0 172.9 172.9" xml:space="preserve">
6819
				<path d="M86.4 0C38.7 0 0 38.7 0 86.4c0 47.7 38.7 86.4 86.4 86.4s86.4-38.7 86.4-86.4C172.9 38.7 134.2 0 86.4 0zM83.1 106.6l-27.1-6.9C49 98 45.7 90.1 49.3 84l33.8-58.5V106.6zM124.9 88.9l-33.8 58.5V66.3l27.1 6.9C125.1 74.9 128.4 82.8 124.9 88.9z"/>
6820
			</svg>
6821
			</div>
6822
			<h3><?php esc_html_e( 'Please Connect Jetpack', 'jetpack' ); ?></h3>
6823
			<p><?php echo wp_kses( __( 'Connecting Jetpack will show you <strong>stats</strong> about your traffic, <strong>protect</strong> you from brute force attacks, <strong>speed up</strong> your images and photos, and enable other <strong>traffic and security</strong> features.', 'jetpack' ), 'jetpack' ) ?></p>
6824
6825
			<div class="actions">
6826
				<a href="<?php echo $this->build_connect_url() ?>" class="button button-primary">
6827
					<?php esc_html_e( 'Connect Jetpack', 'jetpack' ); ?>
6828
				</a>
6829
			</div>
6830
		</div>
6831
		<?php
6832
	}
6833
6834
	/*
6835
	 * A graceful transition to using Core's site icon.
6836
	 *
6837
	 * All of the hard work has already been done with the image
6838
	 * in all_done_page(). All that needs to be done now is update
6839
	 * the option and display proper messaging.
6840
	 *
6841
	 * @todo remove when WP 4.3 is minimum
6842
	 *
6843
	 * @since 3.6.1
6844
	 *
6845
	 * @return bool false = Core's icon not available || true = Core's icon is available
6846
	 */
6847
	public static function jetpack_site_icon_available_in_core() {
6848
		global $wp_version;
6849
		$core_icon_available = function_exists( 'has_site_icon' ) && version_compare( $wp_version, '4.3-beta' ) >= 0;
6850
6851
		if ( ! $core_icon_available ) {
6852
			return false;
6853
		}
6854
6855
		// No need for Jetpack's site icon anymore if core's is already set
6856
		if ( has_site_icon() ) {
6857
			if ( Jetpack::is_module_active( 'site-icon' ) ) {
6858
				Jetpack::log( 'deactivate', 'site-icon' );
6859
				Jetpack::deactivate_module( 'site-icon' );
6860
			}
6861
			return true;
6862
		}
6863
6864
		// Transfer Jetpack's site icon to use core.
6865
		$site_icon_id = Jetpack::get_option( 'site_icon_id' );
6866
		if ( $site_icon_id ) {
6867
			// Update core's site icon
6868
			update_option( 'site_icon', $site_icon_id );
6869
6870
			// Delete Jetpack's icon option. We still want the blavatar and attached data though.
6871
			delete_option( 'site_icon_id' );
6872
		}
6873
6874
		// No need for Jetpack's site icon anymore
6875
		if ( Jetpack::is_module_active( 'site-icon' ) ) {
6876
			Jetpack::log( 'deactivate', 'site-icon' );
6877
			Jetpack::deactivate_module( 'site-icon' );
6878
		}
6879
6880
		return true;
6881
	}
6882
6883
}
1 ignored issue
show
According to PSR2, the closing brace of classes should be placed on the next line directly after the body.

Below you find some examples:

// Incorrect placement according to PSR2
class MyClass
{
    public function foo()
    {

    }
    // This blank line is not allowed.

}

// Correct
class MyClass
{
    public function foo()
    {

    } // No blank lines after this line.
}
Loading history...
6884