Completed
Push — branch-6.3 ( c1d480...871a3b )
by
unknown
28:13 queued 16:11
created

Publicize::options_save_facebook()   A

Complexity

Conditions 5
Paths 4

Size

Total Lines 34

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 5
nc 4
nop 0
dl 0
loc 34
rs 9.0648
c 0
b 0
f 0
1
<?php
2
3
class Publicize extends Publicize_Base {
4
5
	function __construct() {
6
		parent::__construct();
7
8
		add_filter( 'jetpack_xmlrpc_methods', array( $this, 'register_update_publicize_connections_xmlrpc_method' ) );
9
10
		add_action( 'load-settings_page_sharing', array( $this, 'admin_page_load' ), 9 );
11
12
		add_action( 'wp_ajax_publicize_tumblr_options_page', array( $this, 'options_page_tumblr' ) );
13
		add_action( 'wp_ajax_publicize_facebook_options_page', array( $this, 'options_page_facebook' ) );
14
		add_action( 'wp_ajax_publicize_twitter_options_page', array( $this, 'options_page_twitter' ) );
15
		add_action( 'wp_ajax_publicize_linkedin_options_page', array( $this, 'options_page_linkedin' ) );
16
		add_action( 'wp_ajax_publicize_path_options_page', array( $this, 'options_page_path' ) );
17
		add_action( 'wp_ajax_publicize_google_plus_options_page', array( $this, 'options_page_google_plus' ) );
18
19
		add_action( 'wp_ajax_publicize_tumblr_options_save', array( $this, 'options_save_tumblr' ) );
20
		add_action( 'wp_ajax_publicize_facebook_options_save', array( $this, 'options_save_facebook' ) );
21
		add_action( 'wp_ajax_publicize_twitter_options_save', array( $this, 'options_save_twitter' ) );
22
		add_action( 'wp_ajax_publicize_linkedin_options_save', array( $this, 'options_save_linkedin' ) );
23
		add_action( 'wp_ajax_publicize_path_options_save', array( $this, 'options_save_path' ) );
24
		add_action( 'wp_ajax_publicize_google_plus_options_save', array( $this, 'options_save_google_plus' ) );
25
26
		add_action( 'load-settings_page_sharing', array( $this, 'force_user_connection' ) );
27
28
		add_filter( 'publicize_checkbox_default', array( $this, 'publicize_checkbox_default' ), 10, 4 );
29
30
		add_filter( 'jetpack_published_post_flags', array( $this, 'set_post_flags' ), 10, 2 );
31
32
		add_action( 'wp_insert_post', array( $this, 'save_publicized' ), 11, 3 );
33
34
		add_filter( 'jetpack_twitter_cards_site_tag', array( $this, 'enhaced_twitter_cards_site_tag' ) );
35
36
		add_action( 'publicize_save_meta', array( $this, 'save_publicized_twitter_account' ), 10, 4 );
37
		add_action( 'publicize_save_meta', array( $this, 'save_publicized_facebook_account' ), 10, 4 );
38
39
		add_filter( 'jetpack_sharing_twitter_via', array( $this, 'get_publicized_twitter_account' ), 10, 2 );
40
41
		include_once( JETPACK__PLUGIN_DIR . 'modules/publicize/enhanced-open-graph.php' );
42
	}
43
44
	function force_user_connection() {
45
		global $current_user;
46
		$user_token        = Jetpack_Data::get_access_token( $current_user->ID );
47
		$is_user_connected = $user_token && ! is_wp_error( $user_token );
48
49
		// If the user is already connected via Jetpack, then we're good
50
		if ( $is_user_connected ) {
51
			return;
52
		}
53
54
		// If they're not connected, then remove the Publicize UI and tell them they need to connect first
55
		global $publicize_ui;
56
		remove_action( 'pre_admin_screen_sharing', array( $publicize_ui, 'admin_page' ) );
57
58
		// Do we really need `admin_styles`? With the new admin UI, it's breaking some bits.
59
		// Jetpack::init()->admin_styles();
60
		add_action( 'pre_admin_screen_sharing', array( $this, 'admin_page_warning' ), 1 );
61
	}
62
63
	function admin_page_warning() {
64
		$jetpack   = Jetpack::init();
65
		$blog_name = get_bloginfo( 'blogname' );
66
		if ( empty( $blog_name ) ) {
67
			$blog_name = home_url( '/' );
68
		}
69
70
		?>
71
		<div id="message" class="updated jetpack-message jp-connect">
72
			<div class="jetpack-wrap-container">
73
				<div class="jetpack-text-container">
74
					<p><?php printf(
75
							/* translators: %s is the name of the blog */
76
							esc_html( wptexturize( __( "To use Publicize, you'll need to link your %s account to your WordPress.com account using the link below.", 'jetpack' ) ) ),
77
							'<strong>' . esc_html( $blog_name ) . '</strong>'
78
						); ?></p>
79
					<p><?php echo esc_html( wptexturize( __( "If you don't have a WordPress.com account yet, you can sign up for free in just a few seconds.", 'jetpack' ) ) ); ?></p>
80
				</div>
81
				<div class="jetpack-install-container">
82
					<p class="submit"><a
83
							href="<?php echo $jetpack->build_connect_url( false, menu_page_url( 'sharing', false ) ); ?>"
84
							class="button-connector"
85
							id="wpcom-connect"><?php esc_html_e( 'Link account with WordPress.com', 'jetpack' ); ?></a>
86
					</p>
87
					<p class="jetpack-install-blurb">
88
						<?php jetpack_render_tos_blurb(); ?>
89
					</p>
90
				</div>
91
			</div>
92
		</div>
93
		<?php
94
	}
95
96
	/**
97
	 * Remove a Publicize connection
98
	 */
99
	function disconnect( $service_name, $connection_id, $_blog_id = false, $_user_id = false, $force_delete = false ) {
100
		Jetpack::load_xml_rpc_client();
101
		$xml = new Jetpack_IXR_Client();
102
		$xml->query( 'jetpack.deletePublicizeConnection', $connection_id );
103
104
		if ( ! $xml->isError() ) {
105
			Jetpack_Options::update_option( 'publicize_connections', $xml->getResponse() );
106
		} else {
107
			return false;
108
		}
109
	}
110
111
	function receive_updated_publicize_connections( $publicize_connections ) {
112
		Jetpack_Options::update_option( 'publicize_connections', $publicize_connections );
113
114
		return true;
115
	}
116
117
	function register_update_publicize_connections_xmlrpc_method( $methods ) {
118
		return array_merge( $methods, array(
119
			'jetpack.updatePublicizeConnections' => array( $this, 'receive_updated_publicize_connections' ),
120
		) );
121
	}
122
123
	function get_connections( $service_name, $_blog_id = false, $_user_id = false ) {
124
		$connections           = Jetpack_Options::get_option( 'publicize_connections' );
125
		$connections_to_return = array();
126
		if ( ! empty( $connections ) && is_array( $connections ) ) {
127
			if ( ! empty( $connections[ $service_name ] ) ) {
128
				foreach ( $connections[ $service_name ] as $id => $connection ) {
129
					if ( 0 == $connection['connection_data']['user_id'] || $this->user_id() == $connection['connection_data']['user_id'] ) {
130
						$connections_to_return[ $id ] = $connection;
131
					}
132
				}
133
			}
134
135
			return $connections_to_return;
136
		}
137
138
		return false;
139
	}
140
141
	function get_all_connections_for_user() {
142
		$connections = Jetpack_Options::get_option( 'publicize_connections' );
143
144
		$connections_to_return = array();
145
		if ( ! empty( $connections ) ) {
146
			foreach ( (array) $connections as $service_name => $connections_for_service ) {
147
				foreach ( $connections_for_service as $id => $connection ) {
148
					$user_id = intval( $connection['connection_data']['user_id'] );
149
					// phpcs:ignore WordPress.PHP.YodaConditions.NotYoda
150
					if ( $user_id === 0 || $this->user_id() === $user_id ) {
151
						$connections_to_return[ $service_name ][ $id ] = $connection;
152
					}
153
				}
154
			}
155
156
			return $connections_to_return;
157
		}
158
159
		return false;
160
	}
161
162
	function get_connection_id( $connection ) {
163
		return $connection['connection_data']['id'];
164
	}
165
166
	function get_connection_meta( $connection ) {
167
		$connection['user_id'] = $connection['connection_data']['user_id']; // Allows for shared connections
168
		return $connection;
169
	}
170
171
	function admin_page_load() {
172
		if ( isset( $_GET['action'] ) ) {
173
			if ( isset( $_GET['service'] ) ) {
174
				$service_name = $_GET['service'];
175
			}
176
177
			switch ( $_GET['action'] ) {
178
				case 'error':
179
					add_action( 'pre_admin_screen_sharing', array( $this, 'display_connection_error' ), 9 );
180
					break;
181
182
				case 'request':
183
					check_admin_referer( 'keyring-request', 'kr_nonce' );
184
					check_admin_referer( "keyring-request-$service_name", 'nonce' );
0 ignored issues
show
Bug introduced by
The variable $service_name does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
185
186
					$verification = Jetpack::generate_secrets( 'publicize' );
187
					if ( ! $verification ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $verification of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
188
						$url = Jetpack::admin_url( 'jetpack#/settings' );
189
						wp_die( sprintf( __( "Jetpack is not connected. Please connect Jetpack by visiting <a href='%s'>Settings</a>.", 'jetpack' ), $url ) );
190
191
					}
192
					$stats_options = get_option( 'stats_options' );
193
					$wpcom_blog_id = Jetpack_Options::get_option( 'id' );
194
					$wpcom_blog_id = ! empty( $wpcom_blog_id ) ? $wpcom_blog_id : $stats_options['blog_id'];
195
196
					$user     = wp_get_current_user();
197
					$redirect = $this->api_url( $service_name, urlencode_deep( array(
198
						'action'       => 'request',
199
						'redirect_uri' => add_query_arg( array( 'action' => 'done' ), menu_page_url( 'sharing', false ) ),
200
						'for'          => 'publicize',
201
						// required flag that says this connection is intended for publicize
202
						'siteurl'      => site_url(),
203
						'state'        => $user->ID,
204
						'blog_id'      => $wpcom_blog_id,
205
						'secret_1'     => $verification['secret_1'],
206
						'secret_2'     => $verification['secret_2'],
207
						'eol'          => $verification['exp'],
208
					) ) );
209
					wp_redirect( $redirect );
210
					exit;
0 ignored issues
show
Coding Style Compatibility introduced by
The method admin_page_load() contains an exit expression.

An exit expression should only be used in rare cases. For example, if you write a short command line script.

In most cases however, using an exit expression makes the code untestable and often causes incompatibilities with other libraries. Thus, unless you are absolutely sure it is required here, we recommend to refactor your code to avoid its usage.

Loading history...
211
					break;
0 ignored issues
show
Unused Code introduced by
break; does not seem to be reachable.

This check looks for unreachable code. It uses sophisticated control flow analysis techniques to find statements which will never be executed.

Unreachable code is most often the result of return, die or exit statements that have been added for debug purposes.

function fx() {
    try {
        doSomething();
        return true;
    }
    catch (\Exception $e) {
        return false;
    }

    return false;
}

In the above example, the last return false will never be executed, because a return statement has already been met in every possible execution path.

Loading history...
212
213
				case 'completed':
214
					Jetpack::load_xml_rpc_client();
215
					$xml = new Jetpack_IXR_Client();
216
					$xml->query( 'jetpack.fetchPublicizeConnections' );
217
218
					if ( ! $xml->isError() ) {
219
						$response = $xml->getResponse();
220
						Jetpack_Options::update_option( 'publicize_connections', $response );
221
					}
222
223
					break;
224
225
				case 'delete':
226
					$id = $_GET['id'];
227
228
					check_admin_referer( 'keyring-request', 'kr_nonce' );
229
					check_admin_referer( "keyring-request-$service_name", 'nonce' );
230
231
					$this->disconnect( $service_name, $id );
232
233
					add_action( 'admin_notices', array( $this, 'display_disconnected' ) );
234
					break;
235
			}
236
		}
237
238
		// Do we really need `admin_styles`? With the new admin UI, it's breaking some bits.
239
		// Errors encountered on WordPress.com's end are passed back as a code
240
		/*
241
		if ( isset( $_GET['action'] ) && 'error' == $_GET['action'] ) {
242
			// Load Jetpack's styles to handle the box
243
			Jetpack::init()->admin_styles();
244
		}
245
		*/
246
	}
247
248
	function display_connection_error() {
249
		$code = false;
250
		if ( isset( $_GET['service'] ) ) {
251
			$service_name = $_GET['service'];
252
			$error        = sprintf( __( 'There was a problem connecting to %s to create an authorized connection. Please try again in a moment.', 'jetpack' ), Publicize::get_service_label( $service_name ) );
253
		} else {
254
			if ( isset( $_GET['publicize_error'] ) ) {
255
				$code = strtolower( $_GET['publicize_error'] );
256
				switch ( $code ) {
257
					case '400':
258
						$error = __( 'An invalid request was made. This normally means that something intercepted or corrupted the request from your server to the Jetpack Server. Try again and see if it works this time.', 'jetpack' );
259
						break;
260
					case 'secret_mismatch':
261
						$error = __( 'We could not verify that your server is making an authorized request. Please try again, and make sure there is nothing interfering with requests from your server to the Jetpack Server.', 'jetpack' );
262
						break;
263
					case 'empty_blog_id':
264
						$error = __( 'No blog_id was included in your request. Please try disconnecting Jetpack from WordPress.com and then reconnecting it. Once you have done that, try connecting Publicize again.', 'jetpack' );
265
						break;
266
					case 'empty_state':
267
						$error = sprintf( __( 'No user information was included in your request. Please make sure that your user account has connected to Jetpack. Connect your user account by going to the <a href="%s">Jetpack page</a> within wp-admin.', 'jetpack' ), Jetpack::admin_url() );
268
						break;
269
					default:
270
						$error = __( 'Something which should never happen, happened. Sorry about that. If you try again, maybe it will work.', 'jetpack' );
271
						break;
272
				}
273
			} else {
274
				$error = __( 'There was a problem connecting with Publicize. Please try again in a moment.', 'jetpack' );
275
			}
276
		}
277
		// Using the same formatting/style as Jetpack::admin_notices() error
278
		?>
279
		<div id="message" class="jetpack-message jetpack-err">
280
			<div class="squeezer">
281
				<h2><?php echo wp_kses( $error, array( 'a'      => array( 'href' => true ),
282
				                                       'code'   => true,
283
				                                       'strong' => true,
284
				                                       'br'     => true,
285
				                                       'b'      => true
286
					) ); ?></h2>
287
				<?php if ( $code ) : ?>
0 ignored issues
show
Bug Best Practice introduced by
The expression $code of type false|string is loosely compared to true; this is ambiguous if the string can be empty. You might want to explicitly use !== false instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For string values, the empty string '' is a special case, in particular the following results might be unexpected:

''   == false // true
''   == null  // true
'ab' == false // false
'ab' == null  // false

// It is often better to use strict comparison
'' === false // false
'' === null  // false
Loading history...
288
					<p><?php printf( __( 'Error code: %s', 'jetpack' ), esc_html( stripslashes( $code ) ) ); ?></p>
289
				<?php endif; ?>
290
			</div>
291
		</div>
292
		<?php
293
	}
294
295
	function display_disconnected() {
296
		echo "<div class='updated'>\n";
297
		echo '<p>' . esc_html( __( 'That connection has been removed.', 'jetpack' ) ) . "</p>\n";
298
		echo "</div>\n\n";
299
	}
300
301
	function globalization() {
302
		if ( 'on' == $_REQUEST['global'] ) {
303
			$id = $_REQUEST['connection'];
304
305
			if ( ! current_user_can( $this->GLOBAL_CAP ) ) {
306
				return;
307
			}
308
309
			Jetpack::load_xml_rpc_client();
310
			$xml = new Jetpack_IXR_Client();
311
			$xml->query( 'jetpack.globalizePublicizeConnection', $id, 'globalize' );
312
313
			if ( ! $xml->isError() ) {
314
				$response = $xml->getResponse();
315
				Jetpack_Options::update_option( 'publicize_connections', $response );
316
			}
317
		}
318
	}
319
320
	/**
321
	 * Gets a URL to the public-api actions. Works like WP's admin_url
322
	 *
323
	 * @param string $service Shortname of a specific service.
324
	 *
325
	 * @return URL to specific public-api process
326
	 */
327
	// on WordPress.com this is/calls Keyring::admin_url
328
	function api_url( $service = false, $params = array() ) {
329
		/**
330
		 * Filters the API URL used to interact with WordPress.com.
331
		 *
332
		 * @module publicize
333
		 *
334
		 * @since 2.0.0
335
		 *
336
		 * @param string https://public-api.wordpress.com/connect/?jetpack=publicize Default Publicize API URL.
337
		 */
338
		$url = apply_filters( 'publicize_api_url', 'https://public-api.wordpress.com/connect/?jetpack=publicize' );
339
340
		if ( $service ) {
341
			$url = add_query_arg( array( 'service' => $service ), $url );
342
		}
343
344
		if ( count( $params ) ) {
345
			$url = add_query_arg( $params, $url );
346
		}
347
348
		return $url;
349
	}
350
351 View Code Duplication
	function connect_url( $service_name ) {
352
		return add_query_arg( array(
353
			'action'   => 'request',
354
			'service'  => $service_name,
355
			'kr_nonce' => wp_create_nonce( 'keyring-request' ),
356
			'nonce'    => wp_create_nonce( "keyring-request-$service_name" ),
357
		), menu_page_url( 'sharing', false ) );
358
	}
359
360
	function refresh_url( $service_name ) {
361
		return add_query_arg( array(
362
			'action'   => 'request',
363
			'service'  => $service_name,
364
			'kr_nonce' => wp_create_nonce( 'keyring-request' ),
365
			'refresh'  => 1,
366
			'for'      => 'publicize',
367
			'nonce'    => wp_create_nonce( "keyring-request-$service_name" ),
368
		), admin_url( 'options-general.php?page=sharing' ) );
369
	}
370
371 View Code Duplication
	function disconnect_url( $service_name, $id ) {
372
		return add_query_arg( array(
373
			'action'   => 'delete',
374
			'service'  => $service_name,
375
			'id'       => $id,
376
			'kr_nonce' => wp_create_nonce( 'keyring-request' ),
377
			'nonce'    => wp_create_nonce( "keyring-request-$service_name" ),
378
		), menu_page_url( 'sharing', false ) );
379
	}
380
381
	/**
382
	 * Get social networks, either all available or only those that the site is connected to.
383
	 *
384
	 * @since 2.0
385
	 *
386
	 * @param string $filter Select the list of services that will be returned. Defaults to 'all', accepts 'connected'.
387
	 *
388
	 * @return array List of social networks.
389
	 */
390
	function get_services( $filter = 'all' ) {
391
		$services = array(
392
			'facebook'    => array(),
393
			'twitter'     => array(),
394
			'linkedin'    => array(),
395
			'tumblr'      => array(),
396
			'path'        => array(),
397
			'google_plus' => array(),
398
		);
399
400
		if ( 'all' == $filter ) {
401
			return $services;
402
		} else {
403
			$connected_services = array();
404
			foreach ( $services as $service => $empty ) {
405
				$connections = $this->get_connections( $service );
406
				if ( $connections ) {
407
					$connected_services[ $service ] = $connections;
408
				}
409
			}
410
			return $connected_services;
411
		}
412
	}
413
414
	function get_connection( $service, $id, $_blog_id = false, $_user_id = false ) {
415
		// Stub
416
	}
417
418
	function flag_post_for_publicize( $new_status, $old_status, $post ) {
419
		if ( ! $this->post_type_is_publicizeable( $post->post_type ) ) {
420
			return;
421
		}
422
423
		if ( 'publish' == $new_status && 'publish' != $old_status ) {
424
			/**
425
			 * Determines whether a post being published gets publicized.
426
			 *
427
			 * Side-note: Possibly our most alliterative filter name.
428
			 *
429
			 * @module publicize
430
			 *
431
			 * @since 4.1.0
432
			 *
433
			 * @param bool $should_publicize Should the post be publicized? Default to true.
434
			 * @param WP_POST $post Current Post object.
435
			 */
436
			$should_publicize = apply_filters( 'publicize_should_publicize_published_post', true, $post );
437
438
			if ( $should_publicize ) {
439
				update_post_meta( $post->ID, $this->PENDING, true );
440
			}
441
		}
442
	}
443
444
	function test_connection( $service_name, $connection ) {
445
		$connection_test_passed  = true;
446
		$connection_test_message = '';
447
		$user_can_refresh        = false;
0 ignored issues
show
Unused Code introduced by
$user_can_refresh is not used, you could remove the assignment.

This check looks for variable assignements that are either overwritten by other assignments or where the variable is not used subsequently.

$myVar = 'Value';
$higher = false;

if (rand(1, 6) > 3) {
    $higher = true;
} else {
    $higher = false;
}

Both the $myVar assignment in line 1 and the $higher assignment in line 2 are dead. The first because $myVar is never used and the second because $higher is always overwritten for every possible time line.

Loading history...
448
449
		$id = $this->get_connection_id( $connection );
450
451
		Jetpack::load_xml_rpc_client();
452
		$xml = new Jetpack_IXR_Client();
453
		$xml->query( 'jetpack.testPublicizeConnection', $id );
454
455
		if ( $xml->isError() ) {
456
			$xml_response            = $xml->getResponse();
457
			$connection_test_message = $xml_response['faultString'];
458
			$connection_test_passed  = false;
459
		}
460
461
		// Bail if all is well
462
		if ( $connection_test_passed ) {
463
			return true;
464
		}
465
466
		// Set up refresh if the user can
467
		$user_can_refresh = current_user_can( $this->GLOBAL_CAP );
468
		if ( $user_can_refresh ) {
469
			$nonce        = wp_create_nonce( "keyring-request-" . $service_name );
0 ignored issues
show
Unused Code introduced by
$nonce is not used, you could remove the assignment.

This check looks for variable assignements that are either overwritten by other assignments or where the variable is not used subsequently.

$myVar = 'Value';
$higher = false;

if (rand(1, 6) > 3) {
    $higher = true;
} else {
    $higher = false;
}

Both the $myVar assignment in line 1 and the $higher assignment in line 2 are dead. The first because $myVar is never used and the second because $higher is always overwritten for every possible time line.

Loading history...
470
			$refresh_text = sprintf( _x( 'Refresh connection with %s', 'Refresh connection with {social media service}', 'jetpack' ), $this->get_service_label( $service_name ) );
471
			$refresh_url  = $this->refresh_url( $service_name );
472
		}
473
474
		$error_data = array(
475
			'user_can_refresh' => $user_can_refresh,
476
			'refresh_text'     => $refresh_text,
0 ignored issues
show
Bug introduced by
The variable $refresh_text does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
477
			'refresh_url'      => $refresh_url
0 ignored issues
show
Bug introduced by
The variable $refresh_url does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
478
		);
479
480
		return new WP_Error( 'pub_conn_test_failed', $connection_test_message, $error_data );
481
	}
482
483
	/**
484
	 * Save a flag locally to indicate that this post has already been Publicized via the selected
485
	 * connections.
486
	 */
487
	function save_publicized( $post_ID, $post = null, $update = null ) {
488
		if ( is_null( $post ) ) {
489
			return;
490
		}
491
		// Only do this when a post transitions to being published
492
		if ( get_post_meta( $post->ID, $this->PENDING ) && $this->post_type_is_publicizeable( $post->post_type ) ) {
493
			$connected_services = Jetpack_Options::get_option( 'publicize_connections' );
494
			if ( ! empty( $connected_services ) ) {
495
				/**
496
				 * Fires when a post is saved that has is marked as pending publicizing
497
				 *
498
				 * @since 4.1.0
499
				 *
500
				 * @param int The post ID
501
				 */
502
				do_action_deprecated( 'jetpack_publicize_post', $post->ID, '4.8.0', 'jetpack_published_post_flags' );
503
			}
504
			delete_post_meta( $post->ID, $this->PENDING );
505
			update_post_meta( $post->ID, $this->POST_DONE . 'all', true );
506
		}
507
	}
508
509
	function set_post_flags( $flags, $post ) {
510
		$flags['publicize_post'] = false;
511
		if ( ! $this->post_type_is_publicizeable( $post->post_type ) ) {
512
			return $flags;
513
		}
514
		/** This filter is already documented in modules/publicize/publicize-jetpack.php */
515
		if ( ! apply_filters( 'publicize_should_publicize_published_post', true, $post ) ) {
516
			return $flags;
517
		}
518
519
		$connected_services = Jetpack_Options::get_option( 'publicize_connections' );
520
521
		if ( empty( $connected_services ) ) {
522
			return $flags;
523
		}
524
525
		$flags['publicize_post'] = true;
526
527
		return $flags;
528
	}
529
530
	/**
531
	 * Options Code
532
	 */
533
534
	function options_page_facebook() {
535
		$connected_services = Jetpack_Options::get_option( 'publicize_connections' );
536
		$connection         = $connected_services['facebook'][ $_REQUEST['connection'] ];
537
		$options_to_show    = ( ! empty( $connection['connection_data']['meta']['options_responses'] ) ? $connection['connection_data']['meta']['options_responses'] : false );
538
539
		// Nonce check
540
		check_admin_referer( 'options_page_facebook_' . $_REQUEST['connection'] );
541
542
		$pages = ( ! empty( $options_to_show[1]['data'] ) ? $options_to_show[1]['data'] : false );
543
544
		$page_selected   = false;
0 ignored issues
show
Coding Style introduced by
Equals sign not aligned correctly; expected 1 space but found 3 spaces

This check looks for improperly formatted assignments.

Every assignment must have exactly one space before and one space after the equals operator.

To illustrate:

$a = "a";
$ab = "ab";
$abc = "abc";

will have no issues, while

$a   = "a";
$ab  = "ab";
$abc = "abc";

will report issues in lines 1 and 2.

Loading history...
545
		if ( ! empty( $connection['connection_data']['meta']['facebook_page'] ) ) {
546
			$found = false;
547
			if ( $pages && is_array( $pages->data ) ) {
548
				foreach ( $pages->data as $page ) {
549
					if ( $page->id == $connection['connection_data']['meta']['facebook_page'] ) {
550
						$found = true;
551
						break;
552
					}
553
				}
554
			}
555
556
			if ( $found ) {
557
				$page_selected   = $connection['connection_data']['meta']['facebook_page'];
0 ignored issues
show
Coding Style introduced by
Equals sign not aligned correctly; expected 1 space but found 3 spaces

This check looks for improperly formatted assignments.

Every assignment must have exactly one space before and one space after the equals operator.

To illustrate:

$a = "a";
$ab = "ab";
$abc = "abc";

will have no issues, while

$a   = "a";
$ab  = "ab";
$abc = "abc";

will report issues in lines 1 and 2.

Loading history...
558
			}
559
		}
560
561
		?>
562
563
		<div id="thickbox-content">
564
565
			<?php
566
			ob_start();
567
			Publicize_UI::connected_notice( 'Facebook' );
568
			$update_notice = ob_get_clean();
569
570
			if ( ! empty( $update_notice ) ) {
571
				echo $update_notice;
572
			}
573
			$page_info_message = sprintf(
574
				__( 'Facebook supports Publicize connections to Facebook Pages, but not to Facebook Profiles. <a href="%s">Learn More about Publicize for Facebook</a>', 'jetpack' ),
575
				'https://jetpack.com/support/publicize/facebook'
576
			);
577
578
			if ( $pages ) : ?>
579
				<p><?php _e( 'Publicize to my <strong>Facebook Page</strong>:', 'jetpack' ); ?></p>
580
				<table id="option-fb-fanpage">
581
					<tbody>
582
583
					<?php foreach ( $pages as $i => $page ) : ?>
584
						<?php if ( ! ( $i % 2 ) ) : ?>
585
							<tr>
586
						<?php endif; ?>
587
						<td class="radio"><input type="radio" name="option" data-type="page"
588
						                         id="<?php echo esc_attr( $page['id'] ) ?>"
589
						                         value="<?php echo esc_attr( $page['id'] ) ?>" <?php checked( $page_selected && $page_selected == $page['id'], true ); ?> />
590
						</td>
591
						<td class="thumbnail"><label for="<?php echo esc_attr( $page['id'] ) ?>"><img
592
									src="<?php echo esc_url( str_replace( '_s', '_q', $page['picture']['data']['url'] ) ) ?>"
593
									width="50" height="50"/></label></td>
594
						<td class="details">
595
							<label for="<?php echo esc_attr( $page['id'] ) ?>">
596
								<span class="name"><?php echo esc_html( $page['name'] ) ?></span><br/>
597
								<span class="category"><?php echo esc_html( $page['category'] ) ?></span>
598
							</label>
599
						</td>
600
						<?php if ( ( $i % 2 ) || ( $i == count( $pages ) - 1 ) ): ?>
601
							</tr>
602
						<?php endif; ?>
603
					<?php endforeach; ?>
604
605
					</tbody>
606
				</table>
607
608
				<?php Publicize_UI::global_checkbox( 'facebook', $_REQUEST['connection'] ); ?>
609
				<p style="text-align: center;">
610
					<input type="submit" value="<?php esc_attr_e( 'OK', 'jetpack' ) ?>"
611
					       class="button fb-options save-options" name="save"
612
					       data-connection="<?php echo esc_attr( $_REQUEST['connection'] ); ?>"
613
					       rel="<?php echo wp_create_nonce( 'save_fb_token_' . $_REQUEST['connection'] ) ?>"/>
614
				</p><br/>
615
				<p><?php echo $page_info_message; ?></p>
616
			<?php else: ?>
617
				<div>
618
					<p><?php echo $page_info_message; ?></p>
619
					<p><?php printf( __( '<a class="button" href="%s" target="%s">Create a Facebook page</a> to get started.', 'jetpack' ), 'https://www.facebook.com/pages/creation/', '_blank noopener noreferrer' ); ?></p>
620
				</div>
621
			<?php endif; ?>
622
		</div>
623
		<?php
624
	}
625
626
	function options_save_facebook() {
627
		// Nonce check
628
		check_admin_referer( 'save_fb_token_' . $_REQUEST['connection'] );
629
630
		$id = $_POST['connection'];
631
632
		// Check for a numeric page ID
633
		$page_id = $_POST['selected_id'];
634
		if ( ! ctype_digit( $page_id ) ) {
635
			die( 'Security check' );
0 ignored issues
show
Coding Style Compatibility introduced by
The method options_save_facebook() contains an exit expression.

An exit expression should only be used in rare cases. For example, if you write a short command line script.

In most cases however, using an exit expression makes the code untestable and often causes incompatibilities with other libraries. Thus, unless you are absolutely sure it is required here, we recommend to refactor your code to avoid its usage.

Loading history...
636
		}
637
638
		if ( 'page' != $_POST['type'] || ! isset( $_POST['selected_id'] ) ) {
639
			return;
640
		}
641
642
		// Publish to Page
643
		$options = array(
644
			'facebook_page'    => $page_id,
645
			'facebook_profile' => null
646
		);
647
648
649
		Jetpack::load_xml_rpc_client();
650
		$xml = new Jetpack_IXR_Client();
651
		$xml->query( 'jetpack.setPublicizeOptions', $id, $options );
652
653
		if ( ! $xml->isError() ) {
654
			$response = $xml->getResponse();
655
			Jetpack_Options::update_option( 'publicize_connections', $response );
656
		}
657
658
		$this->globalization();
659
	}
660
661
	function options_page_tumblr() {
662
		// Nonce check
663
		check_admin_referer( 'options_page_tumblr_' . $_REQUEST['connection'] );
664
665
		$connected_services = Jetpack_Options::get_option( 'publicize_connections' );
666
		$connection         = $connected_services['tumblr'][ $_POST['connection'] ];
667
		$options_to_show    = $connection['connection_data']['meta']['options_responses'];
668
		$request            = $options_to_show[0];
669
670
		$blogs = $request['response']['user']['blogs'];
671
672
		$blog_selected = false;
673
674
		if ( ! empty( $connection['connection_data']['meta']['tumblr_base_hostname'] ) ) {
675
			foreach ( $blogs as $blog ) {
676
				if ( $connection['connection_data']['meta']['tumblr_base_hostname'] == $this->get_basehostname( $blog['url'] ) ) {
677
					$blog_selected = $connection['connection_data']['meta']['tumblr_base_hostname'];
678
					break;
679
				}
680
			}
681
682
		}
683
684
		// Use their Primary blog if they haven't selected one yet
685
		if ( ! $blog_selected ) {
686
			foreach ( $blogs as $blog ) {
687
				if ( $blog['primary'] ) {
688
					$blog_selected = $this->get_basehostname( $blog['url'] );
689
				}
690
			}
691
		} ?>
692
693
		<div id="thickbox-content">
694
695
			<?php
696
			ob_start();
697
			Publicize_UI::connected_notice( 'Tumblr' );
698
			$update_notice = ob_get_clean();
699
700
			if ( ! empty( $update_notice ) ) {
701
				echo $update_notice;
702
			}
703
			?>
704
705
			<p><?php _e( 'Publicize to my <strong>Tumblr blog</strong>:', 'jetpack' ); ?></p>
706
707
			<ul id="option-tumblr-blog">
708
709
				<?php
710
				foreach ( $blogs as $blog ) {
711
					$url = $this->get_basehostname( $blog['url'] ); ?>
712
					<li>
713
						<input type="radio" name="option" data-type="blog" id="<?php echo esc_attr( $url ) ?>"
714
						       value="<?php echo esc_attr( $url ) ?>" <?php checked( $blog_selected == $url, true ); ?> />
715
						<label for="<?php echo esc_attr( $url ) ?>"><span
716
								class="name"><?php echo esc_html( $blog['title'] ) ?></span></label>
717
					</li>
718
				<?php } ?>
719
720
			</ul>
721
722
			<?php Publicize_UI::global_checkbox( 'tumblr', $_REQUEST['connection'] ); ?>
723
724
			<p style="text-align: center;">
725
				<input type="submit" value="<?php esc_attr_e( 'OK', 'jetpack' ) ?>"
726
				       class="button tumblr-options save-options" name="save"
727
				       data-connection="<?php echo esc_attr( $_REQUEST['connection'] ); ?>"
728
				       rel="<?php echo wp_create_nonce( 'save_tumblr_blog_' . $_REQUEST['connection'] ) ?>"/>
729
			</p> <br/>
730
		</div>
731
732
		<?php
733
	}
734
735
	function get_basehostname( $url ) {
736
		return parse_url( $url, PHP_URL_HOST );
737
	}
738
739
	function options_save_tumblr() {
740
		// Nonce check
741
		check_admin_referer( 'save_tumblr_blog_' . $_REQUEST['connection'] );
742
743
		$id = $_POST['connection'];
744
745
		$options = array( 'tumblr_base_hostname' => $_POST['selected_id'] );
746
747
		Jetpack::load_xml_rpc_client();
748
		$xml = new Jetpack_IXR_Client();
749
		$xml->query( 'jetpack.setPublicizeOptions', $id, $options );
750
751
		if ( ! $xml->isError() ) {
752
			$response = $xml->getResponse();
753
			Jetpack_Options::update_option( 'publicize_connections', $response );
754
		}
755
756
		$this->globalization();
757
	}
758
759
	function options_page_twitter() {
760
		Publicize_UI::options_page_other( 'twitter' );
761
	}
762
763
	function options_page_linkedin() {
764
		Publicize_UI::options_page_other( 'linkedin' );
765
	}
766
767
	function options_page_path() {
768
		Publicize_UI::options_page_other( 'path' );
769
	}
770
771
	function options_page_google_plus() {
772
		Publicize_UI::options_page_other( 'google_plus' );
773
	}
774
775
	function options_save_twitter() {
776
		$this->options_save_other( 'twitter' );
777
	}
778
779
	function options_save_linkedin() {
780
		$this->options_save_other( 'linkedin' );
781
	}
782
783
	function options_save_path() {
784
		$this->options_save_other( 'path' );
785
	}
786
787
	function options_save_google_plus() {
788
		$this->options_save_other( 'google_plus' );
789
	}
790
791
	function options_save_other( $service_name ) {
792
		// Nonce check
793
		check_admin_referer( 'save_' . $service_name . '_token_' . $_REQUEST['connection'] );
794
		$this->globalization();
795
	}
796
797
	/**
798
	 * Already-published posts should not be Publicized by default. This filter sets checked to
799
	 * false if a post has already been published.
800
	 */
801
	function publicize_checkbox_default( $checked, $post_id, $name, $connection ) {
802
		if ( 'publish' == get_post_status( $post_id ) ) {
803
			return false;
804
		}
805
806
		return $checked;
807
	}
808
809
	/**
810
	 * If there's only one shared connection to Twitter set it as twitter:site tag.
811
	 */
812
	function enhaced_twitter_cards_site_tag( $tag ) {
813
		$custom_site_tag = get_option( 'jetpack-twitter-cards-site-tag' );
814
		if ( ! empty( $custom_site_tag ) ) {
815
			return $tag;
816
		}
817
		if ( ! $this->is_enabled( 'twitter' ) ) {
818
			return $tag;
819
		}
820
		$connections = $this->get_connections( 'twitter' );
821
		foreach ( $connections as $connection ) {
0 ignored issues
show
Bug introduced by
The expression $connections of type array|false is not guaranteed to be traversable. How about adding an additional type check?

There are different options of fixing this problem.

  1. If you want to be on the safe side, you can add an additional type-check:

    $collection = json_decode($data, true);
    if ( ! is_array($collection)) {
        throw new \RuntimeException('$collection must be an array.');
    }
    
    foreach ($collection as $item) { /** ... */ }
    
  2. If you are sure that the expression is traversable, you might want to add a doc comment cast to improve IDE auto-completion and static analysis:

    /** @var array $collection */
    $collection = json_decode($data, true);
    
    foreach ($collection as $item) { /** .. */ }
    
  3. Mark the issue as a false-positive: Just hover the remove button, in the top-right corner of this issue for more options.

Loading history...
822
			$connection_meta = $this->get_connection_meta( $connection );
823
			if ( 0 == $connection_meta['connection_data']['user_id'] ) {
824
				// If the connection is shared
825
				return $this->get_display_name( 'twitter', $connection );
826
			}
827
		}
828
829
		return $tag;
830
	}
831
832
	function save_publicized_twitter_account( $submit_post, $post_id, $service_name, $connection ) {
833
		if ( 'twitter' == $service_name && $submit_post ) {
834
			$connection_meta        = $this->get_connection_meta( $connection );
835
			$publicize_twitter_user = get_post_meta( $post_id, '_publicize_twitter_user' );
836
			if ( empty( $publicize_twitter_user ) || 0 != $connection_meta['connection_data']['user_id'] ) {
837
				update_post_meta( $post_id, '_publicize_twitter_user', $this->get_display_name( 'twitter', $connection ) );
838
			}
839
		}
840
	}
841
842
	function get_publicized_twitter_account( $account, $post_id ) {
843
		if ( ! empty( $account ) ) {
844
			return $account;
845
		}
846
		$account = get_post_meta( $post_id, '_publicize_twitter_user', true );
847
		if ( ! empty( $account ) ) {
848
			return $account;
849
		}
850
851
		return '';
852
	}
853
854
	/**
855
	 * Save the Publicized Facebook account when publishing a post
856
	 * Use only Personal accounts, not Facebook Pages
857
	 */
858
	function save_publicized_facebook_account( $submit_post, $post_id, $service_name, $connection ) {
859
		$connection_meta = $this->get_connection_meta( $connection );
860
		if ( 'facebook' == $service_name && isset( $connection_meta['connection_data']['meta']['facebook_profile'] ) && $submit_post ) {
861
			$publicize_facebook_user = get_post_meta( $post_id, '_publicize_facebook_user' );
862
			if ( empty( $publicize_facebook_user ) || 0 != $connection_meta['connection_data']['user_id'] ) {
863
				$profile_link = $this->get_profile_link( 'facebook', $connection );
864
865
				if ( false !== $profile_link ) {
866
					update_post_meta( $post_id, '_publicize_facebook_user', $profile_link );
867
				}
868
			}
869
		}
870
	}
871
}
872