Completed
Push — update/heartbeat-sync ( 9fb678...610eb9 )
by
unknown
235:18 queued 228:01
created

class.jetpack.php (1 issue)

Labels
Severity

Upgrade to new PHP Analysis Engine

These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more

1
<?php
2
3
/*
4
Options:
5
jetpack_options (array)
6
	An array of options.
7
	@see Jetpack_Options::get_option_names()
8
9
jetpack_register (string)
10
	Temporary verification secrets.
11
12
jetpack_activated (int)
13
	1: the plugin was activated normally
14
	2: the plugin was activated on this site because of a network-wide activation
15
	3: the plugin was auto-installed
16
	4: the plugin was manually disconnected (but is still installed)
17
18
jetpack_active_modules (array)
19
	Array of active module slugs.
20
21
jetpack_do_activate (bool)
22
	Flag for "activating" the plugin on sites where the activation hook never fired (auto-installs)
23
*/
24
25
class Jetpack {
26
	public $xmlrpc_server = null;
27
28
	private $xmlrpc_verification = null;
29
30
	public $HTTP_RAW_POST_DATA = null; // copy of $GLOBALS['HTTP_RAW_POST_DATA']
31
32
	/**
33
	 * @var array The handles of styles that are concatenated into jetpack.css
34
	 */
35
	public $concatenated_style_handles = array(
36
		'jetpack-carousel',
37
		'grunion.css',
38
		'the-neverending-homepage',
39
		'jetpack_likes',
40
		'jetpack_related-posts',
41
		'sharedaddy',
42
		'jetpack-slideshow',
43
		'presentations',
44
		'jetpack-subscriptions',
45
		'jetpack-responsive-videos-style',
46
		'jetpack-social-menu',
47
		'tiled-gallery',
48
		'jetpack_display_posts_widget',
49
		'gravatar-profile-widget',
50
		'goodreads-widget',
51
		'jetpack_social_media_icons_widget',
52
		'jetpack-top-posts-widget',
53
		'jetpack_image_widget',
54
	);
55
56
	public $plugins_to_deactivate = array(
57
		'stats'               => array( 'stats/stats.php', 'WordPress.com Stats' ),
58
		'shortlinks'          => array( 'stats/stats.php', 'WordPress.com Stats' ),
59
		'sharedaddy'          => array( 'sharedaddy/sharedaddy.php', 'Sharedaddy' ),
60
		'twitter-widget'      => array( 'wickett-twitter-widget/wickett-twitter-widget.php', 'Wickett Twitter Widget' ),
61
		'after-the-deadline'  => array( 'after-the-deadline/after-the-deadline.php', 'After The Deadline' ),
62
		'contact-form'        => array( 'grunion-contact-form/grunion-contact-form.php', 'Grunion Contact Form' ),
63
		'contact-form'        => array( 'mullet/mullet-contact-form.php', 'Mullet Contact Form' ),
64
		'custom-css'          => array( 'safecss/safecss.php', 'WordPress.com Custom CSS' ),
65
		'random-redirect'     => array( 'random-redirect/random-redirect.php', 'Random Redirect' ),
66
		'videopress'          => array( 'video/video.php', 'VideoPress' ),
67
		'widget-visibility'   => array( 'jetpack-widget-visibility/widget-visibility.php', 'Jetpack Widget Visibility' ),
68
		'widget-visibility'   => array( 'widget-visibility-without-jetpack/widget-visibility-without-jetpack.php', 'Widget Visibility Without Jetpack' ),
69
		'sharedaddy'          => array( 'jetpack-sharing/sharedaddy.php', 'Jetpack Sharing' ),
70
		'omnisearch'          => array( 'jetpack-omnisearch/omnisearch.php', 'Jetpack Omnisearch' ),
71
		'gravatar-hovercards' => array( 'jetpack-gravatar-hovercards/gravatar-hovercards.php', 'Jetpack Gravatar Hovercards' ),
72
		'latex'               => array( 'wp-latex/wp-latex.php', 'WP LaTeX' )
73
	);
74
75
	static $capability_translations = array(
76
		'administrator' => 'manage_options',
77
		'editor'        => 'edit_others_posts',
78
		'author'        => 'publish_posts',
79
		'contributor'   => 'edit_posts',
80
		'subscriber'    => 'read',
81
	);
82
83
	/**
84
	 * Map of modules that have conflicts with plugins and should not be auto-activated
85
	 * if the plugins are active.  Used by filter_default_modules
86
	 *
87
	 * Plugin Authors: If you'd like to prevent a single module from auto-activating,
88
	 * change `module-slug` and add this to your plugin:
89
	 *
90
	 * add_filter( 'jetpack_get_default_modules', 'my_jetpack_get_default_modules' );
91
	 * function my_jetpack_get_default_modules( $modules ) {
92
	 *     return array_diff( $modules, array( 'module-slug' ) );
93
	 * }
94
	 *
95
	 * @var array
96
	 */
97
	private $conflicting_plugins = array(
98
		'comments'          => array(
99
			'Intense Debate'                       => 'intensedebate/intensedebate.php',
100
			'Disqus'                               => 'disqus-comment-system/disqus.php',
101
			'Livefyre'                             => 'livefyre-comments/livefyre.php',
102
			'Comments Evolved for WordPress'       => 'gplus-comments/comments-evolved.php',
103
			'Google+ Comments'                     => 'google-plus-comments/google-plus-comments.php',
104
			'WP-SpamShield Anti-Spam'              => 'wp-spamshield/wp-spamshield.php',
105
		),
106
		'contact-form'      => array(
107
			'Contact Form 7'                       => 'contact-form-7/wp-contact-form-7.php',
108
			'Gravity Forms'                        => 'gravityforms/gravityforms.php',
109
			'Contact Form Plugin'                  => 'contact-form-plugin/contact_form.php',
110
			'Easy Contact Forms'                   => 'easy-contact-forms/easy-contact-forms.php',
111
			'Fast Secure Contact Form'             => 'si-contact-form/si-contact-form.php',
112
		),
113
		'minileven'         => array(
114
			'WPtouch'                              => 'wptouch/wptouch.php',
115
		),
116
		'latex'             => array(
117
			'LaTeX for WordPress'                  => 'latex/latex.php',
118
			'Youngwhans Simple Latex'              => 'youngwhans-simple-latex/yw-latex.php',
119
			'Easy WP LaTeX'                        => 'easy-wp-latex-lite/easy-wp-latex-lite.php',
120
			'MathJax-LaTeX'                        => 'mathjax-latex/mathjax-latex.php',
121
			'Enable Latex'                         => 'enable-latex/enable-latex.php',
122
			'WP QuickLaTeX'                        => 'wp-quicklatex/wp-quicklatex.php',
123
		),
124
		'protect'           => array(
125
			'Limit Login Attempts'                 => 'limit-login-attempts/limit-login-attempts.php',
126
			'Captcha'                              => 'captcha/captcha.php',
127
			'Brute Force Login Protection'         => 'brute-force-login-protection/brute-force-login-protection.php',
128
			'Login Security Solution'              => 'login-security-solution/login-security-solution.php',
129
			'WPSecureOps Brute Force Protect'      => 'wpsecureops-bruteforce-protect/wpsecureops-bruteforce-protect.php',
130
			'BulletProof Security'                 => 'bulletproof-security/bulletproof-security.php',
131
			'SiteGuard WP Plugin'                  => 'siteguard/siteguard.php',
132
			'Security-protection'                  => 'security-protection/security-protection.php',
133
			'Login Security'                       => 'login-security/login-security.php',
134
			'Botnet Attack Blocker'                => 'botnet-attack-blocker/botnet-attack-blocker.php',
135
			'Wordfence Security'                   => 'wordfence/wordfence.php',
136
			'All In One WP Security & Firewall'    => 'all-in-one-wp-security-and-firewall/wp-security.php',
137
			'iThemes Security'                     => 'better-wp-security/better-wp-security.php',
138
		),
139
		'random-redirect'   => array(
140
			'Random Redirect 2'                    => 'random-redirect-2/random-redirect.php',
141
		),
142
		'related-posts'     => array(
143
			'YARPP'                                => 'yet-another-related-posts-plugin/yarpp.php',
144
			'WordPress Related Posts'              => 'wordpress-23-related-posts-plugin/wp_related_posts.php',
145
			'nrelate Related Content'              => 'nrelate-related-content/nrelate-related.php',
146
			'Contextual Related Posts'             => 'contextual-related-posts/contextual-related-posts.php',
147
			'Related Posts for WordPress'          => 'microkids-related-posts/microkids-related-posts.php',
148
			'outbrain'                             => 'outbrain/outbrain.php',
149
			'Shareaholic'                          => 'shareaholic/shareaholic.php',
150
			'Sexybookmarks'                        => 'sexybookmarks/shareaholic.php',
151
		),
152
		'sharedaddy'        => array(
153
			'AddThis'                              => 'addthis/addthis_social_widget.php',
154
			'Add To Any'                           => 'add-to-any/add-to-any.php',
155
			'ShareThis'                            => 'share-this/sharethis.php',
156
			'Shareaholic'                          => 'shareaholic/shareaholic.php',
157
		),
158
		'verification-tools' => array(
159
			'WordPress SEO by Yoast'               => 'wordpress-seo/wp-seo.php',
160
			'WordPress SEO Premium by Yoast'       => 'wordpress-seo-premium/wp-seo-premium.php',
161
			'All in One SEO Pack'                  => 'all-in-one-seo-pack/all_in_one_seo_pack.php',
162
		),
163
		'widget-visibility' => array(
164
			'Widget Logic'                         => 'widget-logic/widget_logic.php',
165
			'Dynamic Widgets'                      => 'dynamic-widgets/dynamic-widgets.php',
166
		),
167
		'sitemaps' => array(
168
			'Google XML Sitemaps'                  => 'google-sitemap-generator/sitemap.php',
169
			'Better WordPress Google XML Sitemaps' => 'bwp-google-xml-sitemaps/bwp-simple-gxs.php',
170
			'Google XML Sitemaps for qTranslate'   => 'google-xml-sitemaps-v3-for-qtranslate/sitemap.php',
171
			'XML Sitemap & Google News feeds'      => 'xml-sitemap-feed/xml-sitemap.php',
172
			'Google Sitemap by BestWebSoft'        => 'google-sitemap-plugin/google-sitemap-plugin.php',
173
			'WordPress SEO by Yoast'               => 'wordpress-seo/wp-seo.php',
174
			'WordPress SEO Premium by Yoast'       => 'wordpress-seo-premium/wp-seo-premium.php',
175
			'All in One SEO Pack'                  => 'all-in-one-seo-pack/all_in_one_seo_pack.php',
176
			'Sitemap'                              => 'sitemap/sitemap.php',
177
			'Simple Wp Sitemap'                    => 'simple-wp-sitemap/simple-wp-sitemap.php',
178
			'Simple Sitemap'                       => 'simple-sitemap/simple-sitemap.php',
179
			'XML Sitemaps'                         => 'xml-sitemaps/xml-sitemaps.php',
180
			'MSM Sitemaps'                         => 'msm-sitemap/msm-sitemap.php',
181
		),
182
	);
183
184
	/**
185
	 * Plugins for which we turn off our Facebook OG Tags implementation.
186
	 *
187
	 * Note: WordPress SEO by Yoast and WordPress SEO Premium by Yoast automatically deactivate
188
	 * Jetpack's Open Graph tags via filter when their Social Meta modules are active.
189
	 *
190
	 * Plugin authors: If you'd like to prevent Jetpack's Open Graph tag generation in your plugin, you can do so via this filter:
191
	 * add_filter( 'jetpack_enable_open_graph', '__return_false' );
192
	 */
193
	private $open_graph_conflicting_plugins = array(
194
		'2-click-socialmedia-buttons/2-click-socialmedia-buttons.php',
195
		                                                         // 2 Click Social Media Buttons
196
		'add-link-to-facebook/add-link-to-facebook.php',         // Add Link to Facebook
197
		'add-meta-tags/add-meta-tags.php',                       // Add Meta Tags
198
		'autodescription/autodescription.php',                   // The SEO Framework
199
		'easy-facebook-share-thumbnails/esft.php',               // Easy Facebook Share Thumbnail
200
		'heateor-open-graph-meta-tags/heateor-open-graph-meta-tags.php',
201
		                                                         // Open Graph Meta Tags by Heateor
202
		'facebook/facebook.php',                                 // Facebook (official plugin)
203
		'facebook-awd/AWD_facebook.php',                         // Facebook AWD All in one
204
		'facebook-featured-image-and-open-graph-meta-tags/fb-featured-image.php',
205
		                                                         // Facebook Featured Image & OG Meta Tags
206
		'facebook-meta-tags/facebook-metatags.php',              // Facebook Meta Tags
207
		'wonderm00ns-simple-facebook-open-graph-tags/wonderm00n-open-graph.php',
208
		                                                         // Facebook Open Graph Meta Tags for WordPress
209
		'facebook-revised-open-graph-meta-tag/index.php',        // Facebook Revised Open Graph Meta Tag
210
		'facebook-thumb-fixer/_facebook-thumb-fixer.php',        // Facebook Thumb Fixer
211
		'facebook-and-digg-thumbnail-generator/facebook-and-digg-thumbnail-generator.php',
212
		                                                         // Fedmich's Facebook Open Graph Meta
213
		'header-footer/plugin.php',                              // Header and Footer
214
		'network-publisher/networkpub.php',                      // Network Publisher
215
		'nextgen-facebook/nextgen-facebook.php',                 // NextGEN Facebook OG
216
		'social-networks-auto-poster-facebook-twitter-g/NextScripts_SNAP.php',
217
		                                                         // NextScripts SNAP
218
		'og-tags/og-tags.php',                                   // OG Tags
219
		'opengraph/opengraph.php',                               // Open Graph
220
		'open-graph-protocol-framework/open-graph-protocol-framework.php',
221
		                                                         // Open Graph Protocol Framework
222
		'seo-facebook-comments/seofacebook.php',                 // SEO Facebook Comments
223
		'seo-ultimate/seo-ultimate.php',                         // SEO Ultimate
224
		'sexybookmarks/sexy-bookmarks.php',                      // Shareaholic
225
		'shareaholic/sexy-bookmarks.php',                        // Shareaholic
226
		'sharepress/sharepress.php',                             // SharePress
227
		'simple-facebook-connect/sfc.php',                       // Simple Facebook Connect
228
		'social-discussions/social-discussions.php',             // Social Discussions
229
		'social-sharing-toolkit/social_sharing_toolkit.php',     // Social Sharing Toolkit
230
		'socialize/socialize.php',                               // Socialize
231
		'only-tweet-like-share-and-google-1/tweet-like-plusone.php',
232
		                                                         // Tweet, Like, Google +1 and Share
233
		'wordbooker/wordbooker.php',                             // Wordbooker
234
		'wpsso/wpsso.php',                                       // WordPress Social Sharing Optimization
235
		'wp-caregiver/wp-caregiver.php',                         // WP Caregiver
236
		'wp-facebook-like-send-open-graph-meta/wp-facebook-like-send-open-graph-meta.php',
237
		                                                         // WP Facebook Like Send & Open Graph Meta
238
		'wp-facebook-open-graph-protocol/wp-facebook-ogp.php',   // WP Facebook Open Graph protocol
239
		'wp-ogp/wp-ogp.php',                                     // WP-OGP
240
		'zoltonorg-social-plugin/zosp.php',                      // Zolton.org Social Plugin
241
		'wp-fb-share-like-button/wp_fb_share-like_widget.php'    // WP Facebook Like Button
242
	);
243
244
	/**
245
	 * Plugins for which we turn off our Twitter Cards Tags implementation.
246
	 */
247
	private $twitter_cards_conflicting_plugins = array(
248
	//	'twitter/twitter.php',                       // The official one handles this on its own.
249
	//	                                             // https://github.com/twitter/wordpress/blob/master/src/Twitter/WordPress/Cards/Compatibility.php
250
		'eewee-twitter-card/index.php',              // Eewee Twitter Card
251
		'ig-twitter-cards/ig-twitter-cards.php',     // IG:Twitter Cards
252
		'jm-twitter-cards/jm-twitter-cards.php',     // JM Twitter Cards
253
		'kevinjohn-gallagher-pure-web-brilliants-social-graph-twitter-cards-extention/kevinjohn_gallagher___social_graph_twitter_output.php',
254
		                                             // Pure Web Brilliant's Social Graph Twitter Cards Extension
255
		'twitter-cards/twitter-cards.php',           // Twitter Cards
256
		'twitter-cards-meta/twitter-cards-meta.php', // Twitter Cards Meta
257
		'wp-twitter-cards/twitter_cards.php',        // WP Twitter Cards
258
	);
259
260
	/**
261
	 * Message to display in admin_notice
262
	 * @var string
263
	 */
264
	public $message = '';
265
266
	/**
267
	 * Error to display in admin_notice
268
	 * @var string
269
	 */
270
	public $error = '';
271
272
	/**
273
	 * Modules that need more privacy description.
274
	 * @var string
275
	 */
276
	public $privacy_checks = '';
277
278
	/**
279
	 * Stats to record once the page loads
280
	 *
281
	 * @var array
282
	 */
283
	public $stats = array();
284
285
	/**
286
	 * Jetpack_Sync object
287
	 */
288
	public $sync;
289
290
	/**
291
	 * Verified data for JSON authorization request
292
	 */
293
	public $json_api_authorization_request = array();
294
295
	/**
296
	 * Holds the singleton instance of this class
297
	 * @since 2.3.3
298
	 * @var Jetpack
299
	 */
300
	static $instance = false;
301
302
	/**
303
	 * Singleton
304
	 * @static
305
	 */
306
	public static function init() {
307
		if ( ! self::$instance ) {
308
			self::$instance = new Jetpack;
309
310
			self::$instance->plugin_upgrade();
311
		}
312
313
		return self::$instance;
314
	}
315
316
	/**
317
	 * Must never be called statically
318
	 */
319
	function plugin_upgrade() {
320
		if ( Jetpack::is_active() ) {
321
			list( $version ) = explode( ':', Jetpack_Options::get_option( 'version' ) );
322
			if ( JETPACK__VERSION != $version ) {
323
324
				// Check which active modules actually exist and remove others from active_modules list
325
				$unfiltered_modules = Jetpack::get_active_modules();
326
				$modules = array_filter( $unfiltered_modules, array( 'Jetpack', 'is_module' ) );
327
				if ( array_diff( $unfiltered_modules, $modules ) ) {
328
					Jetpack::update_active_modules( $modules );
329
				}
330
331
				add_action( 'init', array( __CLASS__, 'activate_new_modules' ) );
332
333
				// Upgrade to 4.3.0
334
				if ( Jetpack_Options::get_option( 'identity_crisis_whitelist' ) ) {
335
					Jetpack_Options::delete_option( 'identity_crisis_whitelist' );
336
				}
337
338
				Jetpack::maybe_set_version_option();
339
			}
340
		}
341
	}
342
343
	static function activate_manage( ) {
344
		if ( did_action( 'init' ) || current_filter() == 'init' ) {
345
			self::activate_module( 'manage', false, false );
346
		} else if ( !  has_action( 'init' , array( __CLASS__, 'activate_manage' ) ) ) {
347
			add_action( 'init', array( __CLASS__, 'activate_manage' ) );
348
		}
349
	}
350
351
	static function update_active_modules( $modules ) {
352
		$current_modules = Jetpack_Options::get_option( 'active_modules', array() );
353
354
		$success = Jetpack_Options::update_option( 'active_modules', array_unique( $modules ) );
355
356
		if ( is_array( $modules ) && is_array( $current_modules ) ) {
357
			$new_active_modules = array_diff( $modules, $current_modules );
358
			foreach( $new_active_modules as $module ) {
359
				/**
360
				 * Fires when a specific module is activated.
361
				 *
362
				 * @since 1.9.0
363
				 *
364
				 * @param string $module Module slug.
365
				 * @param boolean $success whether the module was activated. @since 4.2
366
				 */
367
				do_action( 'jetpack_activate_module', $module, $success );
368
369
				/**
370
				 * Fires when a module is activated.
371
				 * The dynamic part of the filter, $module, is the module slug.
372
				 *
373
				 * @since 1.9.0
374
				 *
375
				 * @param string $module Module slug.
376
				 */
377
				do_action( "jetpack_activate_module_$module", $module );
378
			}
379
380
			$new_deactive_modules = array_diff( $current_modules, $modules );
381
			foreach( $new_deactive_modules as $module ) {
382
				/**
383
				 * Fired after a module has been deactivated.
384
				 *
385
				 * @since 4.2.0
386
				 *
387
				 * @param string $module Module slug.
388
				 * @param boolean $success whether the module was deactivated.
389
				 */
390
				do_action( 'jetpack_deactivate_module', $module, $success );
391
				/**
392
				 * Fires when a module is deactivated.
393
				 * The dynamic part of the filter, $module, is the module slug.
394
				 *
395
				 * @since 1.9.0
396
				 *
397
				 * @param string $module Module slug.
398
				 */
399
				do_action( "jetpack_deactivate_module_$module", $module );
400
			}
401
		}
402
403
		return $success;
404
	}
405
406
	static function delete_active_modules() {
407
		self::update_active_modules( array() );
408
	}
409
410
	/**
411
	 * Constructor.  Initializes WordPress hooks
412
	 */
413
	private function __construct() {
414
		/*
415
		 * Check for and alert any deprecated hooks
416
		 */
417
		add_action( 'init', array( $this, 'deprecated_hooks' ) );
418
419
420
		/*
421
		 * Load things that should only be in Network Admin.
422
		 *
423
		 * For now blow away everything else until a more full
424
		 * understanding of what is needed at the network level is
425
		 * available
426
		 */
427
		if( is_multisite() ) {
428
			Jetpack_Network::init();
429
		}
430
431
		add_action( 'set_user_role', array( $this, 'maybe_clear_other_linked_admins_transient' ), 10, 3 );
432
433
		// Unlink user before deleting the user from .com
434
		add_action( 'deleted_user', array( $this, 'unlink_user' ), 10, 1 );
435
		add_action( 'remove_user_from_blog', array( $this, 'unlink_user' ), 10, 1 );
436
437
		if ( defined( 'XMLRPC_REQUEST' ) && XMLRPC_REQUEST && isset( $_GET['for'] ) && 'jetpack' == $_GET['for'] ) {
438
			@ini_set( 'display_errors', false ); // Display errors can cause the XML to be not well formed.
439
440
			require_once JETPACK__PLUGIN_DIR . 'class.jetpack-xmlrpc-server.php';
441
			$this->xmlrpc_server = new Jetpack_XMLRPC_Server();
442
443
			$this->require_jetpack_authentication();
444
445
			if ( Jetpack::is_active() ) {
446
				// Hack to preserve $HTTP_RAW_POST_DATA
447
				add_filter( 'xmlrpc_methods', array( $this, 'xmlrpc_methods' ) );
448
449
				$signed = $this->verify_xml_rpc_signature();
450
				if ( $signed && ! is_wp_error( $signed ) ) {
451
					// The actual API methods.
452
					add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'xmlrpc_methods' ) );
453
				} else {
454
					// The jetpack.authorize method should be available for unauthenticated users on a site with an
455
					// active Jetpack connection, so that additional users can link their account.
456
					add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'authorize_xmlrpc_methods' ) );
457
				}
458
			} else {
459
				// The bootstrap API methods.
460
				add_filter( 'xmlrpc_methods', array( $this->xmlrpc_server, 'bootstrap_xmlrpc_methods' ) );
461
			}
462
463
			// Now that no one can authenticate, and we're whitelisting all XML-RPC methods, force enable_xmlrpc on.
464
			add_filter( 'pre_option_enable_xmlrpc', '__return_true' );
465
		} elseif ( is_admin() && isset( $_POST['action'] ) && 'jetpack_upload_file' == $_POST['action'] ) {
466
			$this->require_jetpack_authentication();
467
			$this->add_remote_request_handlers();
468
		} else {
469
			if ( Jetpack::is_active() ) {
470
				add_action( 'login_form_jetpack_json_api_authorization', array( &$this, 'login_form_json_api_authorization' ) );
471
				add_filter( 'xmlrpc_methods', array( $this, 'public_xmlrpc_methods' ) );
472
			}
473
		}
474
475
		if ( Jetpack::is_active() ) {
476
			Jetpack_Heartbeat::init();
477
		}
478
479
		add_action( 'jetpack_clean_nonces', array( 'Jetpack', 'clean_nonces' ) );
480
		if ( ! wp_next_scheduled( 'jetpack_clean_nonces' ) ) {
481
			wp_schedule_event( time(), 'hourly', 'jetpack_clean_nonces' );
482
		}
483
484
		add_filter( 'xmlrpc_blog_options', array( $this, 'xmlrpc_options' ) );
485
486
		add_action( 'admin_init', array( $this, 'admin_init' ) );
487
		add_action( 'admin_init', array( $this, 'dismiss_jetpack_notice' ) );
488
489
		add_filter( 'admin_body_class', array( $this, 'admin_body_class' ) );
490
491
		add_action( 'wp_dashboard_setup', array( $this, 'wp_dashboard_setup' ) );
492
		// Filter the dashboard meta box order to swap the new one in in place of the old one.
493
		add_filter( 'get_user_option_meta-box-order_dashboard', array( $this, 'get_user_option_meta_box_order_dashboard' ) );
494
495
		// returns HTTPS support status
496
		add_action( 'wp_ajax_jetpack-recheck-ssl', array( $this, 'ajax_recheck_ssl' ) );
497
498
		// If any module option is updated before Jump Start is dismissed, hide Jump Start.
499
		add_action( 'update_option', array( $this, 'jumpstart_has_updated_module_option' ) );
500
501
		// JITM AJAX callback function
502
		add_action( 'wp_ajax_jitm_ajax',  array( $this, 'jetpack_jitm_ajax_callback' ) );
503
504
		// Universal ajax callback for all tracking events triggered via js
505
		add_action( 'wp_ajax_jetpack_tracks', array( $this, 'jetpack_admin_ajax_tracks_callback' ) );
506
507
		add_action( 'wp_loaded', array( $this, 'register_assets' ) );
508
		add_action( 'wp_enqueue_scripts', array( $this, 'devicepx' ) );
509
		add_action( 'customize_controls_enqueue_scripts', array( $this, 'devicepx' ) );
510
		add_action( 'admin_enqueue_scripts', array( $this, 'devicepx' ) );
511
512
		add_action( 'plugins_loaded', array( $this, 'extra_oembed_providers' ), 100 );
513
514
		/**
515
		 * These actions run checks to load additional files.
516
		 * They check for external files or plugins, so they need to run as late as possible.
517
		 */
518
		add_action( 'wp_head', array( $this, 'check_open_graph' ),       1 );
519
		add_action( 'plugins_loaded', array( $this, 'check_twitter_tags' ),     999 );
520
		add_action( 'plugins_loaded', array( $this, 'check_rest_api_compat' ), 1000 );
521
522
		add_filter( 'plugins_url',      array( 'Jetpack', 'maybe_min_asset' ),     1, 3 );
523
		add_filter( 'style_loader_tag', array( 'Jetpack', 'maybe_inline_style' ), 10, 2 );
524
525
		add_filter( 'map_meta_cap', array( $this, 'jetpack_custom_caps' ), 1, 4 );
526
527
		add_filter( 'jetpack_get_default_modules', array( $this, 'filter_default_modules' ) );
528
		add_filter( 'jetpack_get_default_modules', array( $this, 'handle_deprecated_modules' ), 99 );
529
530
		// A filter to control all just in time messages
531
		add_filter( 'jetpack_just_in_time_msgs', '__return_false' );
532
533
		/**
534
		 * This is the hack to concatinate all css files into one.
535
		 * For description and reasoning see the implode_frontend_css method
536
		 *
537
		 * Super late priority so we catch all the registered styles
538
		 */
539
		if( !is_admin() ) {
540
			add_action( 'wp_print_styles', array( $this, 'implode_frontend_css' ), -1 ); // Run first
541
			add_action( 'wp_print_footer_scripts', array( $this, 'implode_frontend_css' ), -1 ); // Run first to trigger before `print_late_styles`
542
		}
543
544
	}
545
546
	function jetpack_admin_ajax_tracks_callback() {
547
		// Check for nonce
548
		if ( ! isset( $_REQUEST['tracksNonce'] ) || ! wp_verify_nonce( $_REQUEST['tracksNonce'], 'jp-tracks-ajax-nonce' ) ) {
549
			wp_die( 'Permissions check failed.' );
550
		}
551
552
		if ( ! isset( $_REQUEST['tracksEventName'] ) || ! isset( $_REQUEST['tracksEventType'] )  ) {
553
			wp_die( 'No valid event name or type.' );
554
		}
555
556
		$tracks_data = array();
557
		if ( 'click' === $_REQUEST['tracksEventType'] && isset( $_REQUEST['tracksEventProp'] ) ) {
558
			$tracks_data = array( 'clicked' => $_REQUEST['tracksEventProp'] );
559
		}
560
561
		JetpackTracking::record_user_event( $_REQUEST['tracksEventName'], $tracks_data );
562
		wp_send_json_success();
563
		wp_die();
564
	}
565
566
	/**
567
	 * The callback for the JITM ajax requests.
568
	 */
569
	function jetpack_jitm_ajax_callback() {
570
		// Check for nonce
571
		if ( ! isset( $_REQUEST['jitmNonce'] ) || ! wp_verify_nonce( $_REQUEST['jitmNonce'], 'jetpack-jitm-nonce' ) ) {
572
			wp_die( 'Module activation failed due to lack of appropriate permissions' );
573
		}
574
		if ( isset( $_REQUEST['jitmActionToTake'] ) && 'activate' == $_REQUEST['jitmActionToTake'] ) {
575
			$module_slug = $_REQUEST['jitmModule'];
576
			Jetpack::log( 'activate', $module_slug );
577
			Jetpack::activate_module( $module_slug, false, false );
578
			Jetpack::state( 'message', 'no_message' );
579
580
			//A Jetpack module is being activated through a JITM, track it
581
			$this->stat( 'jitm', $module_slug.'-activated-' . JETPACK__VERSION );
582
			$this->do_stats( 'server_side' );
583
584
			wp_send_json_success();
585
		}
586
		if ( isset( $_REQUEST['jitmActionToTake'] ) && 'dismiss' == $_REQUEST['jitmActionToTake'] ) {
587
			// get the hide_jitm options array
588
			$jetpack_hide_jitm = Jetpack_Options::get_option( 'hide_jitm' );
589
			$module_slug = $_REQUEST['jitmModule'];
590
591
			if( ! $jetpack_hide_jitm ) {
592
				$jetpack_hide_jitm = array(
593
					$module_slug => 'hide'
594
				);
595
			} else {
596
				$jetpack_hide_jitm[$module_slug] = 'hide';
597
			}
598
599
			Jetpack_Options::update_option( 'hide_jitm', $jetpack_hide_jitm );
600
601
			//jitm is being dismissed forever, track it
602
			$this->stat( 'jitm', $module_slug.'-dismissed-' . JETPACK__VERSION );
603
			$this->do_stats( 'server_side' );
604
605
			wp_send_json_success();
606
		}
607 View Code Duplication
		if ( isset( $_REQUEST['jitmActionToTake'] ) && 'launch' == $_REQUEST['jitmActionToTake'] ) {
608
			$module_slug = $_REQUEST['jitmModule'];
609
610
			// User went to WordPress.com, track this
611
			$this->stat( 'jitm', $module_slug.'-wordpress-tools-' . JETPACK__VERSION );
612
			$this->do_stats( 'server_side' );
613
614
			wp_send_json_success();
615
		}
616 View Code Duplication
		if ( isset( $_REQUEST['jitmActionToTake'] ) && 'viewed' == $_REQUEST['jitmActionToTake'] ) {
617
			$track = $_REQUEST['jitmModule'];
618
619
			// User is viewing JITM, track it.
620
			$this->stat( 'jitm', $track . '-viewed-' . JETPACK__VERSION );
621
			$this->do_stats( 'server_side' );
622
623
			wp_send_json_success();
624
		}
625
	}
626
627
	/**
628
	 * If there are any stats that need to be pushed, but haven't been, push them now.
629
	 */
630
	function __destruct() {
631
		if ( ! empty( $this->stats ) ) {
632
			$this->do_stats( 'server_side' );
633
		}
634
	}
635
636
	function jetpack_custom_caps( $caps, $cap, $user_id, $args ) {
637
		switch( $cap ) {
638
			case 'jetpack_connect' :
639
			case 'jetpack_reconnect' :
640
				if ( Jetpack::is_development_mode() ) {
641
					$caps = array( 'do_not_allow' );
642
					break;
643
				}
644
				/**
645
				 * Pass through. If it's not development mode, these should match disconnect.
646
				 * Let users disconnect if it's development mode, just in case things glitch.
647
				 */
648
			case 'jetpack_disconnect' :
649
				/**
650
				 * In multisite, can individual site admins manage their own connection?
651
				 *
652
				 * Ideally, this should be extracted out to a separate filter in the Jetpack_Network class.
653
				 */
654
				if ( is_multisite() && ! is_super_admin() && is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
655
					if ( ! Jetpack_Network::init()->get_option( 'sub-site-connection-override' ) ) {
656
						/**
657
						 * We need to update the option name -- it's terribly unclear which
658
						 * direction the override goes.
659
						 *
660
						 * @todo: Update the option name to `sub-sites-can-manage-own-connections`
661
						 */
662
						$caps = array( 'do_not_allow' );
663
						break;
664
					}
665
				}
666
667
				$caps = array( 'manage_options' );
668
				break;
669
			case 'jetpack_manage_modules' :
670
			case 'jetpack_activate_modules' :
671
			case 'jetpack_deactivate_modules' :
672
				$caps = array( 'manage_options' );
673
				break;
674
			case 'jetpack_configure_modules' :
675
				$caps = array( 'manage_options' );
676
				break;
677
			case 'jetpack_network_admin_page':
678
			case 'jetpack_network_settings_page':
679
				$caps = array( 'manage_network_plugins' );
680
				break;
681
			case 'jetpack_network_sites_page':
682
				$caps = array( 'manage_sites' );
683
				break;
684
			case 'jetpack_admin_page' :
685
				if ( Jetpack::is_development_mode() ) {
686
					$caps = array( 'manage_options' );
687
					break;
688
				} else {
689
					$caps = array( 'read' );
690
				}
691
				break;
692
			case 'jetpack_connect_user' :
693
				if ( Jetpack::is_development_mode() ) {
694
					$caps = array( 'do_not_allow' );
695
					break;
696
				}
697
				$caps = array( 'read' );
698
				break;
699
		}
700
		return $caps;
701
	}
702
703
	function require_jetpack_authentication() {
704
		// Don't let anyone authenticate
705
		$_COOKIE = array();
706
		remove_all_filters( 'authenticate' );
707
		remove_all_actions( 'wp_login_failed' );
708
709
		if ( Jetpack::is_active() ) {
710
			// Allow Jetpack authentication
711
			add_filter( 'authenticate', array( $this, 'authenticate_jetpack' ), 10, 3 );
712
		}
713
	}
714
715
	/**
716
	 * Load language files
717
	 * @action plugins_loaded
718
	 */
719
	public static function plugin_textdomain() {
720
		// Note to self, the third argument must not be hardcoded, to account for relocated folders.
721
		load_plugin_textdomain( 'jetpack', false, dirname( plugin_basename( JETPACK__PLUGIN_FILE ) ) . '/languages/' );
722
	}
723
724
	/**
725
	 * Register assets for use in various modules and the Jetpack admin page.
726
	 *
727
	 * @uses wp_script_is, wp_register_script, plugins_url
728
	 * @action wp_loaded
729
	 * @return null
730
	 */
731
	public function register_assets() {
732
		if ( ! wp_script_is( 'spin', 'registered' ) ) {
733
			wp_register_script( 'spin', plugins_url( '_inc/spin.js', JETPACK__PLUGIN_FILE ), false, '1.3' );
734
		}
735
736 View Code Duplication
		if ( ! wp_script_is( 'jquery.spin', 'registered' ) ) {
737
			wp_register_script( 'jquery.spin', plugins_url( '_inc/jquery.spin.js', JETPACK__PLUGIN_FILE ) , array( 'jquery', 'spin' ), '1.3' );
738
		}
739
740 View Code Duplication
		if ( ! wp_script_is( 'jetpack-gallery-settings', 'registered' ) ) {
741
			wp_register_script( 'jetpack-gallery-settings', plugins_url( '_inc/gallery-settings.js', JETPACK__PLUGIN_FILE ), array( 'media-views' ), '20121225' );
742
		}
743
744 View Code Duplication
		if ( ! wp_script_is( 'jetpack-twitter-timeline', 'registered' ) ) {
745
			wp_register_script( 'jetpack-twitter-timeline', plugins_url( '_inc/twitter-timeline.js', JETPACK__PLUGIN_FILE ) , array( 'jquery' ), '4.0.0', true );
746
		}
747
748
		if ( ! wp_script_is( 'jetpack-facebook-embed', 'registered' ) ) {
749
			wp_register_script( 'jetpack-facebook-embed', plugins_url( '_inc/facebook-embed.js', __FILE__ ), array( 'jquery' ), null, true );
750
751
			/** This filter is documented in modules/sharedaddy/sharing-sources.php */
752
			$fb_app_id = apply_filters( 'jetpack_sharing_facebook_app_id', '249643311490' );
753
			if ( ! is_numeric( $fb_app_id ) ) {
754
				$fb_app_id = '';
755
			}
756
			wp_localize_script(
757
				'jetpack-facebook-embed',
758
				'jpfbembed',
759
				array(
760
					'appid' => $fb_app_id,
761
					'locale' => $this->get_locale(),
762
				)
763
			);
764
		}
765
766
		/**
767
		 * As jetpack_register_genericons is by default fired off a hook,
768
		 * the hook may have already fired by this point.
769
		 * So, let's just trigger it manually.
770
		 */
771
		require_once( JETPACK__PLUGIN_DIR . '_inc/genericons.php' );
772
		jetpack_register_genericons();
773
774
		/**
775
		 * Register the social logos
776
		 */
777
		require_once( JETPACK__PLUGIN_DIR . '_inc/social-logos.php' );
778
		jetpack_register_social_logos();
779
780 View Code Duplication
		if ( ! wp_style_is( 'jetpack-icons', 'registered' ) )
781
			wp_register_style( 'jetpack-icons', plugins_url( 'css/jetpack-icons.min.css', JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION );
782
	}
783
784
	/**
785
	 * Guess locale from language code.
786
	 *
787
	 * @param string $lang Language code.
788
	 * @return string|bool
789
	 */
790 View Code Duplication
	function guess_locale_from_lang( $lang ) {
791
		if ( 'en' === $lang || 'en_US' === $lang || ! $lang ) {
792
			return 'en_US';
793
		}
794
795
		if ( ! class_exists( 'GP_Locales' ) ) {
796
			if ( ! defined( 'JETPACK__GLOTPRESS_LOCALES_PATH' ) || ! file_exists( JETPACK__GLOTPRESS_LOCALES_PATH ) ) {
797
				return false;
798
			}
799
800
			require JETPACK__GLOTPRESS_LOCALES_PATH;
801
		}
802
803
		if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
804
			// WP.com: get_locale() returns 'it'
805
			$locale = GP_Locales::by_slug( $lang );
806
		} else {
807
			// Jetpack: get_locale() returns 'it_IT';
808
			$locale = GP_Locales::by_field( 'facebook_locale', $lang );
809
		}
810
811
		if ( ! $locale ) {
812
			return false;
813
		}
814
815
		if ( empty( $locale->facebook_locale ) ) {
816
			if ( empty( $locale->wp_locale ) ) {
817
				return false;
818
			} else {
819
				// Facebook SDK is smart enough to fall back to en_US if a
820
				// locale isn't supported. Since supported Facebook locales
821
				// can fall out of sync, we'll attempt to use the known
822
				// wp_locale value and rely on said fallback.
823
				return $locale->wp_locale;
824
			}
825
		}
826
827
		return $locale->facebook_locale;
828
	}
829
830
	/**
831
	 * Get the locale.
832
	 *
833
	 * @return string|bool
834
	 */
835
	function get_locale() {
836
		$locale = $this->guess_locale_from_lang( get_locale() );
837
838
		if ( ! $locale ) {
839
			$locale = 'en_US';
840
		}
841
842
		return $locale;
843
	}
844
845
	/**
846
	 * Device Pixels support
847
	 * This improves the resolution of gravatars and wordpress.com uploads on hi-res and zoomed browsers.
848
	 */
849
	function devicepx() {
850
		if ( Jetpack::is_active() ) {
851
			wp_enqueue_script( 'devicepx', set_url_scheme( 'http://s0.wp.com/wp-content/js/devicepx-jetpack.js' ), array(), gmdate( 'oW' ), true );
852
		}
853
	}
854
855
	/**
856
	 * Return the network_site_url so that .com knows what network this site is a part of.
857
	 * @param  bool $option
858
	 * @return string
859
	 */
860
	public function jetpack_main_network_site_option( $option ) {
861
		return network_site_url();
862
	}
863
	/**
864
	 * Network Name.
865
	 */
866
	static function network_name( $option = null ) {
867
		global $current_site;
868
		return $current_site->site_name;
869
	}
870
	/**
871
	 * Does the network allow new user and site registrations.
872
	 * @return string
873
	 */
874
	static function network_allow_new_registrations( $option = null ) {
875
		return ( in_array( get_site_option( 'registration' ), array('none', 'user', 'blog', 'all' ) ) ? get_site_option( 'registration') : 'none' );
876
	}
877
	/**
878
	 * Does the network allow admins to add new users.
879
	 * @return boolian
880
	 */
881
	static function network_add_new_users( $option = null ) {
882
		return (bool) get_site_option( 'add_new_users' );
883
	}
884
	/**
885
	 * File upload psace left per site in MB.
886
	 *  -1 means NO LIMIT.
887
	 * @return number
888
	 */
889
	static function network_site_upload_space( $option = null ) {
890
		// value in MB
891
		return ( get_site_option( 'upload_space_check_disabled' ) ? -1 : get_space_allowed() );
892
	}
893
894
	/**
895
	 * Network allowed file types.
896
	 * @return string
897
	 */
898
	static function network_upload_file_types( $option = null ) {
899
		return get_site_option( 'upload_filetypes', 'jpg jpeg png gif' );
900
	}
901
902
	/**
903
	 * Maximum file upload size set by the network.
904
	 * @return number
905
	 */
906
	static function network_max_upload_file_size( $option = null ) {
907
		// value in KB
908
		return get_site_option( 'fileupload_maxk', 300 );
909
	}
910
911
	/**
912
	 * Lets us know if a site allows admins to manage the network.
913
	 * @return array
914
	 */
915
	static function network_enable_administration_menus( $option = null ) {
916
		return get_site_option( 'menu_items' );
917
	}
918
919
	/**
920
	 * If a user has been promoted to or demoted from admin, we need to clear the
921
	 * jetpack_other_linked_admins transient.
922
	 *
923
	 * @param $user_id
924
	 * @param $role
925
	 * @param $old_roles
926
	 */
927
	function maybe_clear_other_linked_admins_transient( $user_id, $role, $old_roles ) {
928
		if ( 'administrator' == $role || ( is_array( $old_roles ) && in_array( 'administrator', $old_roles ) )
929
		) {
930
			delete_transient( 'jetpack_other_linked_admins' );
931
		}
932
	}
933
934
	/**
935
	 * Checks to see if there are any other users available to become primary
936
	 * Users must both:
937
	 * - Be linked to wpcom
938
	 * - Be an admin
939
	 *
940
	 * @return mixed False if no other users are linked, Int if there are.
941
	 */
942
	static function get_other_linked_admins() {
943
		$other_linked_users = get_transient( 'jetpack_other_linked_admins' );
944
945
		if ( false === $other_linked_users ) {
946
			$admins = get_users( array( 'role' => 'administrator' ) );
947
			if ( count( $admins ) > 1 ) {
948
				$available = array();
949
				foreach ( $admins as $admin ) {
950
					if ( Jetpack::is_user_connected( $admin->ID ) ) {
951
						$available[] = $admin->ID;
952
					}
953
				}
954
955
				$count_connected_admins = count( $available );
956
				if ( count( $available ) > 1 ) {
957
					$other_linked_users = $count_connected_admins;
958
				} else {
959
					$other_linked_users = 0;
960
				}
961
			} else {
962
				$other_linked_users = 0;
963
			}
964
965
			set_transient( 'jetpack_other_linked_admins', $other_linked_users, HOUR_IN_SECONDS );
966
		}
967
968
		return ( 0 === $other_linked_users ) ? false : $other_linked_users;
969
	}
970
971
	/**
972
	 * Return whether we are dealing with a multi network setup or not.
973
	 * The reason we are type casting this is because we want to avoid the situation where
974
	 * the result is false since when is_main_network_option return false it cases
975
	 * the rest the get_option( 'jetpack_is_multi_network' ); to return the value that is set in the
976
	 * database which could be set to anything as opposed to what this function returns.
977
	 * @param  bool  $option
978
	 *
979
	 * @return boolean
980
	 */
981
	public function is_main_network_option( $option ) {
982
		// return '1' or ''
983
		return (string) (bool) Jetpack::is_multi_network();
984
	}
985
986
	/**
987
	 * Return true if we are with multi-site or multi-network false if we are dealing with single site.
988
	 *
989
	 * @param  string  $option
990
	 * @return boolean
991
	 */
992
	public function is_multisite( $option ) {
993
		return (string) (bool) is_multisite();
994
	}
995
996
	/**
997
	 * Implemented since there is no core is multi network function
998
	 * Right now there is no way to tell if we which network is the dominant network on the system
999
	 *
1000
	 * @since  3.3
1001
	 * @return boolean
1002
	 */
1003
	public static function is_multi_network() {
1004
		global  $wpdb;
1005
1006
		// if we don't have a multi site setup no need to do any more
1007
		if ( ! is_multisite() ) {
1008
			return false;
1009
		}
1010
1011
		$num_sites = $wpdb->get_var( "SELECT COUNT(*) FROM {$wpdb->site}" );
1012
		if ( $num_sites > 1 ) {
1013
			return true;
1014
		} else {
1015
			return false;
1016
		}
1017
	}
1018
1019
	/**
1020
	 * Trigger an update to the main_network_site when we update the siteurl of a site.
1021
	 * @return null
1022
	 */
1023
	function update_jetpack_main_network_site_option() {
1024
		_deprecated_function( __METHOD__, 'jetpack-4.2' );
1025
	}
1026
	/**
1027
	 * Triggered after a user updates the network settings via Network Settings Admin Page
1028
	 *
1029
	 */
1030
	function update_jetpack_network_settings() {
1031
		_deprecated_function( __METHOD__, 'jetpack-4.2' );
1032
		// Only sync this info for the main network site.
1033
	}
1034
1035
	/**
1036
	 * Get back if the current site is single user site.
1037
	 *
1038
	 * @return bool
1039
	 */
1040
	public static function is_single_user_site() {
1041
		global $wpdb;
1042
1043 View Code Duplication
		if ( false === ( $some_users = get_transient( 'jetpack_is_single_user' ) ) ) {
1044
			$some_users = $wpdb->get_var( "SELECT COUNT(*) FROM (SELECT user_id FROM $wpdb->usermeta WHERE meta_key = '{$wpdb->prefix}capabilities' LIMIT 2) AS someusers" );
1045
			set_transient( 'jetpack_is_single_user', (int) $some_users, 12 * HOUR_IN_SECONDS );
1046
		}
1047
		return 1 === (int) $some_users;
1048
	}
1049
1050
	/**
1051
	 * Returns true if the site has file write access false otherwise.
1052
	 * @return string ( '1' | '0' )
1053
	 **/
1054
	public static function file_system_write_access() {
1055
		if ( ! function_exists( 'get_filesystem_method' ) ) {
1056
			require_once( ABSPATH . 'wp-admin/includes/file.php' );
1057
		}
1058
1059
		require_once( ABSPATH . 'wp-admin/includes/template.php' );
1060
1061
		$filesystem_method = get_filesystem_method();
1062
		if ( $filesystem_method === 'direct' ) {
1063
			return 1;
1064
		}
1065
1066
		ob_start();
1067
		$filesystem_credentials_are_stored = request_filesystem_credentials( self_admin_url() );
1068
		ob_end_clean();
1069
		if ( $filesystem_credentials_are_stored ) {
1070
			return 1;
1071
		}
1072
		return 0;
1073
	}
1074
1075
	/**
1076
	 * Finds out if a site is using a version control system.
1077
	 * @return string ( '1' | '0' )
1078
	 **/
1079
	public static function is_version_controlled() {
1080
		_deprecated_function( __METHOD__, 'jetpack-4.2', 'Jetpack_Sync_Functions::is_version_controlled' );
1081
		return (string) (int) Jetpack_Sync_Functions::is_version_controlled();
1082
	}
1083
1084
	/**
1085
	 * Determines whether the current theme supports featured images or not.
1086
	 * @return string ( '1' | '0' )
1087
	 */
1088
	public static function featured_images_enabled() {
1089
		_deprecated_function( __METHOD__, 'jetpack-4.2' );
1090
		return current_theme_supports( 'post-thumbnails' ) ? '1' : '0';
1091
	}
1092
1093
	/**
1094
	 * jetpack_updates is saved in the following schema:
1095
	 *
1096
	 * array (
1097
	 *      'plugins'                       => (int) Number of plugin updates available.
1098
	 *      'themes'                        => (int) Number of theme updates available.
1099
	 *      'wordpress'                     => (int) Number of WordPress core updates available.
1100
	 *      'translations'                  => (int) Number of translation updates available.
1101
	 *      'total'                         => (int) Total of all available updates.
1102
	 *      'wp_update_version'             => (string) The latest available version of WordPress, only present if a WordPress update is needed.
1103
	 * )
1104
	 * @return array
1105
	 */
1106
	public static function get_updates() {
1107
		$update_data = wp_get_update_data();
1108
1109
		// Stores the individual update counts as well as the total count.
1110
		if ( isset( $update_data['counts'] ) ) {
1111
			$updates = $update_data['counts'];
1112
		}
1113
1114
		// If we need to update WordPress core, let's find the latest version number.
1115 View Code Duplication
		if ( ! empty( $updates['wordpress'] ) ) {
1116
			$cur = get_preferred_from_update_core();
1117
			if ( isset( $cur->response ) && 'upgrade' === $cur->response ) {
1118
				$updates['wp_update_version'] = $cur->current;
1119
			}
1120
		}
1121
		return isset( $updates ) ? $updates : array();
1122
	}
1123
1124
	public static function get_update_details() {
1125
		$update_details = array(
1126
			'update_core' => get_site_transient( 'update_core' ),
1127
			'update_plugins' => get_site_transient( 'update_plugins' ),
1128
			'update_themes' => get_site_transient( 'update_themes' ),
1129
		);
1130
		return $update_details;
1131
	}
1132
1133
	public static function refresh_update_data() {
1134
		_deprecated_function( __METHOD__, 'jetpack-4.2' );
1135
1136
	}
1137
1138
	public static function refresh_theme_data() {
1139
		_deprecated_function( __METHOD__, 'jetpack-4.2' );
1140
	}
1141
1142
	/**
1143
	 * Is Jetpack active?
1144
	 */
1145
	public static function is_active() {
1146
		return (bool) Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
1147
	}
1148
1149
	/**
1150
	 * Is Jetpack in development (offline) mode?
1151
	 */
1152
	public static function is_development_mode() {
1153
		$development_mode = false;
1154
1155
		if ( defined( 'JETPACK_DEV_DEBUG' ) ) {
1156
			$development_mode = JETPACK_DEV_DEBUG;
1157
		}
1158
1159
		elseif ( site_url() && false === strpos( site_url(), '.' ) ) {
1160
			$development_mode = true;
1161
		}
1162
		/**
1163
		 * Filters Jetpack's development mode.
1164
		 *
1165
		 * @see https://jetpack.com/support/development-mode/
1166
		 *
1167
		 * @since 2.2.1
1168
		 *
1169
		 * @param bool $development_mode Is Jetpack's development mode active.
1170
		 */
1171
		return apply_filters( 'jetpack_development_mode', $development_mode );
1172
	}
1173
1174
	/**
1175
	* Get Jetpack development mode notice text and notice class.
1176
	*
1177
	* Mirrors the checks made in Jetpack::is_development_mode
1178
	*
1179
	*/
1180
	public static function show_development_mode_notice() {
1181
		if ( Jetpack::is_development_mode() ) {
1182
			if ( defined( 'JETPACK_DEV_DEBUG' ) && JETPACK_DEV_DEBUG ) {
1183
				$notice = sprintf(
1184
					/* translators: %s is a URL */
1185
					__( 'In <a href="%s" target="_blank">Development Mode</a>, via the JETPACK_DEV_DEBUG constant being defined in wp-config.php or elsewhere.', 'jetpack' ),
1186
					'https://jetpack.com/support/development-mode/'
1187
				);
1188
			} elseif ( site_url() && false === strpos( site_url(), '.' ) ) {
1189
				$notice = sprintf(
1190
					/* translators: %s is a URL */
1191
					__( 'In <a href="%s" target="_blank">Development Mode</a>, via site URL lacking a dot (e.g. http://localhost).', 'jetpack' ),
1192
					'https://jetpack.com/support/development-mode/'
1193
				);
1194
			} else {
1195
				$notice = sprintf(
1196
					/* translators: %s is a URL */
1197
					__( 'In <a href="%s" target="_blank">Development Mode</a>, via the jetpack_development_mode filter.', 'jetpack' ),
1198
					'https://jetpack.com/support/development-mode/'
1199
				);
1200
			}
1201
1202
			echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
1203
		}
1204
1205
		// Throw up a notice if using a development version and as for feedback.
1206
		if ( Jetpack::is_development_version() ) {
1207
			/* translators: %s is a URL */
1208
			$notice = sprintf( __( 'You are currently running a development version of Jetpack. <a href="%s" target="_blank">Submit your feedback</a>', 'jetpack' ), 'https://jetpack.com/contact-support/beta-group/' );
1209
1210
			echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
1211
		}
1212
		// Throw up a notice if using staging mode
1213
		if ( Jetpack::is_staging_site() ) {
1214
			/* translators: %s is a URL */
1215
			$notice = sprintf( __( 'You are running Jetpack on a <a href="%s" target="_blank">staging server</a>.', 'jetpack' ), 'https://jetpack.com/support/staging-sites/' );
1216
1217
			echo '<div class="updated" style="border-color: #f0821e;"><p>' . $notice . '</p></div>';
1218
		}
1219
	}
1220
1221
	/**
1222
	 * Whether Jetpack's version maps to a public release, or a development version.
1223
	 */
1224
	public static function is_development_version() {
1225
		/**
1226
		 * Allows filtering whether this is a development version of Jetpack.
1227
		 *
1228
		 * This filter is especially useful for tests.
1229
		 *
1230
		 * @since 4.3.0
1231
		 *
1232
		 * @param bool $development_version Is this a develoment version of Jetpack?
1233
		 */
1234
		return (bool) apply_filters(
1235
			'jetpack_development_version',
1236
			! preg_match( '/^\d+(\.\d+)+$/', Jetpack_Constants::get_constant( 'JETPACK__VERSION' ) )
1237
		);
1238
	}
1239
1240
	/**
1241
	 * Is a given user (or the current user if none is specified) linked to a WordPress.com user?
1242
	 */
1243
	public static function is_user_connected( $user_id = false ) {
1244
		$user_id = false === $user_id ? get_current_user_id() : absint( $user_id );
1245
		if ( ! $user_id ) {
1246
			return false;
1247
		}
1248
1249
		return (bool) Jetpack_Data::get_access_token( $user_id );
1250
	}
1251
1252
	/**
1253
	 * Get the wpcom user data of the current|specified connected user.
1254
	 */
1255
	public static function get_connected_user_data( $user_id = null ) {
1256
		if ( ! $user_id ) {
1257
			$user_id = get_current_user_id();
1258
		}
1259
1260
		$transient_key = "jetpack_connected_user_data_$user_id";
1261
1262
		if ( $cached_user_data = get_transient( $transient_key ) ) {
1263
			return $cached_user_data;
1264
		}
1265
1266
		Jetpack::load_xml_rpc_client();
1267
		$xml = new Jetpack_IXR_Client( array(
1268
			'user_id' => $user_id,
1269
		) );
1270
		$xml->query( 'wpcom.getUser' );
1271
		if ( ! $xml->isError() ) {
1272
			$user_data = $xml->getResponse();
1273
			set_transient( $transient_key, $xml->getResponse(), DAY_IN_SECONDS );
1274
			return $user_data;
1275
		}
1276
1277
		return false;
1278
	}
1279
1280
	/**
1281
	 * Get the wpcom email of the current|specified connected user.
1282
	 */
1283 View Code Duplication
	public static function get_connected_user_email( $user_id = null ) {
1284
		if ( ! $user_id ) {
1285
			$user_id = get_current_user_id();
1286
		}
1287
		Jetpack::load_xml_rpc_client();
1288
		$xml = new Jetpack_IXR_Client( array(
1289
			'user_id' => $user_id,
1290
		) );
1291
		$xml->query( 'wpcom.getUserEmail' );
1292
		if ( ! $xml->isError() ) {
1293
			return $xml->getResponse();
1294
		}
1295
		return false;
1296
	}
1297
1298
	/**
1299
	 * Get the wpcom email of the master user.
1300
	 */
1301
	public static function get_master_user_email() {
1302
		$master_user_id = Jetpack_Options::get_option( 'master_user' );
1303
		if ( $master_user_id ) {
1304
			return self::get_connected_user_email( $master_user_id );
1305
		}
1306
		return '';
1307
	}
1308
1309
	function current_user_is_connection_owner() {
1310
		$user_token = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
1311
		return $user_token && is_object( $user_token ) && isset( $user_token->external_user_id ) && get_current_user_id() === $user_token->external_user_id;
1312
	}
1313
1314
	/**
1315
	 * Add any extra oEmbed providers that we know about and use on wpcom for feature parity.
1316
	 */
1317
	function extra_oembed_providers() {
1318
		// Cloudup: https://dev.cloudup.com/#oembed
1319
		wp_oembed_add_provider( 'https://cloudup.com/*' , 'https://cloudup.com/oembed' );
1320
		wp_oembed_add_provider( 'https://me.sh/*', 'https://me.sh/oembed?format=json' );
1321
		wp_oembed_add_provider( '#https?://(www\.)?gfycat\.com/.*#i', 'https://api.gfycat.com/v1/oembed', true );
1322
		wp_oembed_add_provider( '#https?://[^.]+\.(wistia\.com|wi\.st)/(medias|embed)/.*#', 'https://fast.wistia.com/oembed', true );
1323
		wp_oembed_add_provider( '#https?://sketchfab\.com/.*#i', 'https://sketchfab.com/oembed', true );
1324
	}
1325
1326
	/**
1327
	 * Synchronize connected user role changes
1328
	 */
1329
	function user_role_change( $user_id ) {
1330
		_deprecated_function( __METHOD__, 'jetpack-4.2', 'Jetpack_Sync_Users::user_role_change()' );
1331
		Jetpack_Sync_Users::user_role_change( $user_id );
1332
	}
1333
1334
	/**
1335
	 * Loads the currently active modules.
1336
	 */
1337
	public static function load_modules() {
1338
		if ( ! self::is_active() && !self::is_development_mode() ) {
1339
			if ( ! is_multisite() || ! get_site_option( 'jetpack_protect_active' ) ) {
1340
				return;
1341
			}
1342
		}
1343
1344
		$version = Jetpack_Options::get_option( 'version' );
1345 View Code Duplication
		if ( ! $version ) {
1346
			$version = $old_version = JETPACK__VERSION . ':' . time();
1347
			/** This action is documented in class.jetpack.php */
1348
			do_action( 'updating_jetpack_version', $version, false );
1349
			Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
1350
		}
1351
		list( $version ) = explode( ':', $version );
1352
1353
		$modules = array_filter( Jetpack::get_active_modules(), array( 'Jetpack', 'is_module' ) );
1354
1355
		$modules_data = array();
1356
1357
		// Don't load modules that have had "Major" changes since the stored version until they have been deactivated/reactivated through the lint check.
1358
		if ( version_compare( $version, JETPACK__VERSION, '<' ) ) {
1359
			$updated_modules = array();
1360
			foreach ( $modules as $module ) {
1361
				$modules_data[ $module ] = Jetpack::get_module( $module );
1362
				if ( ! isset( $modules_data[ $module ]['changed'] ) ) {
1363
					continue;
1364
				}
1365
1366
				if ( version_compare( $modules_data[ $module ]['changed'], $version, '<=' ) ) {
1367
					continue;
1368
				}
1369
1370
				$updated_modules[] = $module;
1371
			}
1372
1373
			$modules = array_diff( $modules, $updated_modules );
1374
		}
1375
1376
		$is_development_mode = Jetpack::is_development_mode();
1377
1378
		foreach ( $modules as $index => $module ) {
1379
			// If we're in dev mode, disable modules requiring a connection
1380
			if ( $is_development_mode ) {
1381
				// Prime the pump if we need to
1382
				if ( empty( $modules_data[ $module ] ) ) {
1383
					$modules_data[ $module ] = Jetpack::get_module( $module );
1384
				}
1385
				// If the module requires a connection, but we're in local mode, don't include it.
1386
				if ( $modules_data[ $module ]['requires_connection'] ) {
1387
					continue;
1388
				}
1389
			}
1390
1391
			if ( did_action( 'jetpack_module_loaded_' . $module ) ) {
1392
				continue;
1393
			}
1394
1395
			if ( ! @include( Jetpack::get_module_path( $module ) ) ) {
1396
				unset( $modules[ $index ] );
1397
				self::update_active_modules( array_values( $modules ) );
1398
				continue;
1399
			}
1400
1401
			/**
1402
			 * Fires when a specific module is loaded.
1403
			 * The dynamic part of the hook, $module, is the module slug.
1404
			 *
1405
			 * @since 1.1.0
1406
			 */
1407
			do_action( 'jetpack_module_loaded_' . $module );
1408
		}
1409
1410
		/**
1411
		 * Fires when all the modules are loaded.
1412
		 *
1413
		 * @since 1.1.0
1414
		 */
1415
		do_action( 'jetpack_modules_loaded' );
1416
1417
		// Load module-specific code that is needed even when a module isn't active. Loaded here because code contained therein may need actions such as setup_theme.
1418
		if ( Jetpack::is_active() || Jetpack::is_development_mode() )
1419
			require_once( JETPACK__PLUGIN_DIR . 'modules/module-extras.php' );
1420
	}
1421
1422
	/**
1423
	 * Check if Jetpack's REST API compat file should be included
1424
	 * @action plugins_loaded
1425
	 * @return null
1426
	 */
1427
	public function check_rest_api_compat() {
1428
		/**
1429
		 * Filters the list of REST API compat files to be included.
1430
		 *
1431
		 * @since 2.2.5
1432
		 *
1433
		 * @param array $args Array of REST API compat files to include.
1434
		 */
1435
		$_jetpack_rest_api_compat_includes = apply_filters( 'jetpack_rest_api_compat', array() );
1436
1437
		if ( function_exists( 'bbpress' ) )
1438
			$_jetpack_rest_api_compat_includes[] = JETPACK__PLUGIN_DIR . 'class.jetpack-bbpress-json-api-compat.php';
1439
1440
		foreach ( $_jetpack_rest_api_compat_includes as $_jetpack_rest_api_compat_include )
1441
			require_once $_jetpack_rest_api_compat_include;
1442
	}
1443
1444
	/**
1445
	 * Gets all plugins currently active in values, regardless of whether they're
1446
	 * traditionally activated or network activated.
1447
	 *
1448
	 * @todo Store the result in core's object cache maybe?
1449
	 */
1450
	public static function get_active_plugins() {
1451
		$active_plugins = (array) get_option( 'active_plugins', array() );
1452
1453
		if ( is_multisite() ) {
1454
			// Due to legacy code, active_sitewide_plugins stores them in the keys,
1455
			// whereas active_plugins stores them in the values.
1456
			$network_plugins = array_keys( get_site_option( 'active_sitewide_plugins', array() ) );
1457
			if ( $network_plugins ) {
1458
				$active_plugins = array_merge( $active_plugins, $network_plugins );
1459
			}
1460
		}
1461
1462
		sort( $active_plugins );
1463
1464
		return array_unique( $active_plugins );
1465
	}
1466
1467
	/**
1468
	 * Gets and parses additional plugin data to send with the heartbeat data
1469
	 *
1470
	 * @since 3.8.1
1471
	 *
1472
	 * @return array Array of plugin data
1473
	 */
1474
	public static function get_parsed_plugin_data() {
1475
		if ( ! function_exists( 'get_plugins' ) ) {
1476
			require_once( ABSPATH . 'wp-admin/includes/plugin.php' );
1477
		}
1478
		/** This filter is documented in wp-admin/includes/class-wp-plugins-list-table.php */
1479
		$all_plugins    = apply_filters( 'all_plugins', get_plugins() );
1480
		$active_plugins = Jetpack::get_active_plugins();
1481
1482
		$plugins = array();
1483
		foreach ( $all_plugins as $path => $plugin_data ) {
1484
			$plugins[ $path ] = array(
1485
					'is_active' => in_array( $path, $active_plugins ),
1486
					'file'      => $path,
1487
					'name'      => $plugin_data['Name'],
1488
					'version'   => $plugin_data['Version'],
1489
					'author'    => $plugin_data['Author'],
1490
			);
1491
		}
1492
1493
		return $plugins;
1494
	}
1495
1496
	/**
1497
	 * Gets and parses theme data to send with the heartbeat data
1498
	 *
1499
	 * @since 3.8.1
1500
	 *
1501
	 * @return array Array of theme data
1502
	 */
1503
	public static function get_parsed_theme_data() {
1504
		$all_themes = wp_get_themes( array( 'allowed' => true ) );
1505
		$header_keys = array( 'Name', 'Author', 'Version', 'ThemeURI', 'AuthorURI', 'Status', 'Tags' );
1506
1507
		$themes = array();
1508
		foreach ( $all_themes as $slug => $theme_data ) {
1509
			$theme_headers = array();
1510
			foreach ( $header_keys as $header_key ) {
1511
				$theme_headers[ $header_key ] = $theme_data->get( $header_key );
1512
			}
1513
1514
			$themes[ $slug ] = array(
1515
					'is_active_theme' => $slug == wp_get_theme()->get_template(),
1516
					'slug' => $slug,
1517
					'theme_root' => $theme_data->get_theme_root_uri(),
1518
					'parent' => $theme_data->parent(),
1519
					'headers' => $theme_headers
1520
			);
1521
		}
1522
1523
		return $themes;
1524
	}
1525
1526
	/**
1527
	 * Checks whether a specific plugin is active.
1528
	 *
1529
	 * We don't want to store these in a static variable, in case
1530
	 * there are switch_to_blog() calls involved.
1531
	 */
1532
	public static function is_plugin_active( $plugin = 'jetpack/jetpack.php' ) {
1533
		return in_array( $plugin, self::get_active_plugins() );
1534
	}
1535
1536
	/**
1537
	 * Check if Jetpack's Open Graph tags should be used.
1538
	 * If certain plugins are active, Jetpack's og tags are suppressed.
1539
	 *
1540
	 * @uses Jetpack::get_active_modules, add_filter, get_option, apply_filters
1541
	 * @action plugins_loaded
1542
	 * @return null
1543
	 */
1544
	public function check_open_graph() {
1545
		if ( in_array( 'publicize', Jetpack::get_active_modules() ) || in_array( 'sharedaddy', Jetpack::get_active_modules() ) ) {
1546
			add_filter( 'jetpack_enable_open_graph', '__return_true', 0 );
1547
		}
1548
1549
		$active_plugins = self::get_active_plugins();
1550
1551
		if ( ! empty( $active_plugins ) ) {
1552
			foreach ( $this->open_graph_conflicting_plugins as $plugin ) {
1553
				if ( in_array( $plugin, $active_plugins ) ) {
1554
					add_filter( 'jetpack_enable_open_graph', '__return_false', 99 );
1555
					break;
1556
				}
1557
			}
1558
		}
1559
1560
		/**
1561
		 * Allow the addition of Open Graph Meta Tags to all pages.
1562
		 *
1563
		 * @since 2.0.3
1564
		 *
1565
		 * @param bool false Should Open Graph Meta tags be added. Default to false.
1566
		 */
1567
		if ( apply_filters( 'jetpack_enable_open_graph', false ) ) {
1568
			require_once JETPACK__PLUGIN_DIR . 'functions.opengraph.php';
1569
		}
1570
	}
1571
1572
	/**
1573
	 * Check if Jetpack's Twitter tags should be used.
1574
	 * If certain plugins are active, Jetpack's twitter tags are suppressed.
1575
	 *
1576
	 * @uses Jetpack::get_active_modules, add_filter, get_option, apply_filters
1577
	 * @action plugins_loaded
1578
	 * @return null
1579
	 */
1580
	public function check_twitter_tags() {
1581
1582
		$active_plugins = self::get_active_plugins();
1583
1584
		if ( ! empty( $active_plugins ) ) {
1585
			foreach ( $this->twitter_cards_conflicting_plugins as $plugin ) {
1586
				if ( in_array( $plugin, $active_plugins ) ) {
1587
					add_filter( 'jetpack_disable_twitter_cards', '__return_true', 99 );
1588
					break;
1589
				}
1590
			}
1591
		}
1592
1593
		/**
1594
		 * Allow Twitter Card Meta tags to be disabled.
1595
		 *
1596
		 * @since 2.6.0
1597
		 *
1598
		 * @param bool true Should Twitter Card Meta tags be disabled. Default to true.
1599
		 */
1600
		if ( ! apply_filters( 'jetpack_disable_twitter_cards', false ) ) {
1601
			require_once JETPACK__PLUGIN_DIR . 'class.jetpack-twitter-cards.php';
1602
		}
1603
	}
1604
1605
	/**
1606
	 * Allows plugins to submit security reports.
1607
 	 *
1608
	 * @param string  $type         Report type (login_form, backup, file_scanning, spam)
1609
	 * @param string  $plugin_file  Plugin __FILE__, so that we can pull plugin data
1610
	 * @param array   $args         See definitions above
1611
	 */
1612
	public static function submit_security_report( $type = '', $plugin_file = '', $args = array() ) {
1613
		_deprecated_function( __FUNCTION__, 'jetpack-4.2', null );
1614
	}
1615
1616
/* Jetpack Options API */
1617
1618
	public static function get_option_names( $type = 'compact' ) {
1619
		return Jetpack_Options::get_option_names( $type );
1620
	}
1621
1622
	/**
1623
	 * Returns the requested option.  Looks in jetpack_options or jetpack_$name as appropriate.
1624
 	 *
1625
	 * @param string $name    Option name
1626
	 * @param mixed  $default (optional)
1627
	 */
1628
	public static function get_option( $name, $default = false ) {
1629
		return Jetpack_Options::get_option( $name, $default );
1630
	}
1631
1632
	/**
1633
	* Stores two secrets and a timestamp so WordPress.com can make a request back and verify an action
1634
	* Does some extra verification so urls (such as those to public-api, register, etc) can't just be crafted
1635
	* $name must be a registered option name.
1636
	*/
1637
	public static function create_nonce( $name ) {
1638
		$secret = wp_generate_password( 32, false ) . ':' . wp_generate_password( 32, false ) . ':' . ( time() + 600 );
1639
1640
		Jetpack_Options::update_option( $name, $secret );
1641
		@list( $secret_1, $secret_2, $eol ) = explode( ':', Jetpack_Options::get_option( $name ) );
1642
		if ( empty( $secret_1 ) || empty( $secret_2 ) || $eol < time() )
1643
			return new Jetpack_Error( 'missing_secrets' );
1644
1645
		return array(
1646
			'secret_1' => $secret_1,
1647
			'secret_2' => $secret_2,
1648
			'eol'      => $eol,
1649
		);
1650
	}
1651
1652
	/**
1653
	 * Updates the single given option.  Updates jetpack_options or jetpack_$name as appropriate.
1654
 	 *
1655
	 * @deprecated 3.4 use Jetpack_Options::update_option() instead.
1656
	 * @param string $name  Option name
1657
	 * @param mixed  $value Option value
1658
	 */
1659
	public static function update_option( $name, $value ) {
1660
		_deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::update_option()' );
1661
		return Jetpack_Options::update_option( $name, $value );
1662
	}
1663
1664
	/**
1665
	 * Updates the multiple given options.  Updates jetpack_options and/or jetpack_$name as appropriate.
1666
 	 *
1667
	 * @deprecated 3.4 use Jetpack_Options::update_options() instead.
1668
	 * @param array $array array( option name => option value, ... )
1669
	 */
1670
	public static function update_options( $array ) {
1671
		_deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::update_options()' );
1672
		return Jetpack_Options::update_options( $array );
1673
	}
1674
1675
	/**
1676
	 * Deletes the given option.  May be passed multiple option names as an array.
1677
	 * Updates jetpack_options and/or deletes jetpack_$name as appropriate.
1678
	 *
1679
	 * @deprecated 3.4 use Jetpack_Options::delete_option() instead.
1680
	 * @param string|array $names
1681
	 */
1682
	public static function delete_option( $names ) {
1683
		_deprecated_function( __METHOD__, 'jetpack-3.4', 'Jetpack_Options::delete_option()' );
1684
		return Jetpack_Options::delete_option( $names );
1685
	}
1686
1687
	/**
1688
	 * Enters a user token into the user_tokens option
1689
	 *
1690
	 * @param int $user_id
1691
	 * @param string $token
1692
	 * return bool
1693
	 */
1694
	public static function update_user_token( $user_id, $token, $is_master_user ) {
1695
		// not designed for concurrent updates
1696
		$user_tokens = Jetpack_Options::get_option( 'user_tokens' );
1697
		if ( ! is_array( $user_tokens ) )
1698
			$user_tokens = array();
1699
		$user_tokens[$user_id] = $token;
1700
		if ( $is_master_user ) {
1701
			$master_user = $user_id;
1702
			$options     = compact( 'user_tokens', 'master_user' );
1703
		} else {
1704
			$options = compact( 'user_tokens' );
1705
		}
1706
		return Jetpack_Options::update_options( $options );
1707
	}
1708
1709
	/**
1710
	 * Returns an array of all PHP files in the specified absolute path.
1711
	 * Equivalent to glob( "$absolute_path/*.php" ).
1712
	 *
1713
	 * @param string $absolute_path The absolute path of the directory to search.
1714
	 * @return array Array of absolute paths to the PHP files.
1715
	 */
1716
	public static function glob_php( $absolute_path ) {
1717
		if ( function_exists( 'glob' ) ) {
1718
			return glob( "$absolute_path/*.php" );
1719
		}
1720
1721
		$absolute_path = untrailingslashit( $absolute_path );
1722
		$files = array();
1723
		if ( ! $dir = @opendir( $absolute_path ) ) {
1724
			return $files;
1725
		}
1726
1727
		while ( false !== $file = readdir( $dir ) ) {
1728
			if ( '.' == substr( $file, 0, 1 ) || '.php' != substr( $file, -4 ) ) {
1729
				continue;
1730
			}
1731
1732
			$file = "$absolute_path/$file";
1733
1734
			if ( ! is_file( $file ) ) {
1735
				continue;
1736
			}
1737
1738
			$files[] = $file;
1739
		}
1740
1741
		closedir( $dir );
1742
1743
		return $files;
1744
	}
1745
1746
	public static function activate_new_modules( $redirect = false ) {
1747
		if ( ! Jetpack::is_active() && ! Jetpack::is_development_mode() ) {
1748
			return;
1749
		}
1750
1751
		$jetpack_old_version = Jetpack_Options::get_option( 'version' ); // [sic]
1752 View Code Duplication
		if ( ! $jetpack_old_version ) {
1753
			$jetpack_old_version = $version = $old_version = '1.1:' . time();
1754
			/** This action is documented in class.jetpack.php */
1755
			do_action( 'updating_jetpack_version', $version, false );
1756
			Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
1757
		}
1758
1759
		list( $jetpack_version ) = explode( ':', $jetpack_old_version ); // [sic]
1760
1761
		if ( version_compare( JETPACK__VERSION, $jetpack_version, '<=' ) ) {
1762
			return;
1763
		}
1764
1765
		$active_modules     = Jetpack::get_active_modules();
1766
		$reactivate_modules = array();
1767
		foreach ( $active_modules as $active_module ) {
1768
			$module = Jetpack::get_module( $active_module );
1769
			if ( ! isset( $module['changed'] ) ) {
1770
				continue;
1771
			}
1772
1773
			if ( version_compare( $module['changed'], $jetpack_version, '<=' ) ) {
1774
				continue;
1775
			}
1776
1777
			$reactivate_modules[] = $active_module;
1778
			Jetpack::deactivate_module( $active_module );
1779
		}
1780
1781
		$new_version = JETPACK__VERSION . ':' . time();
1782
		/** This action is documented in class.jetpack.php */
1783
		do_action( 'updating_jetpack_version', $new_version, $jetpack_old_version );
1784
		Jetpack_Options::update_options(
1785
			array(
1786
				'version'     => $new_version,
1787
				'old_version' => $jetpack_old_version,
1788
			)
1789
		);
1790
1791
		Jetpack::state( 'message', 'modules_activated' );
1792
		Jetpack::activate_default_modules( $jetpack_version, JETPACK__VERSION, $reactivate_modules );
1793
1794
		if ( $redirect ) {
1795
			$page = 'jetpack'; // make sure we redirect to either settings or the jetpack page
1796
			if ( isset( $_GET['page'] ) && in_array( $_GET['page'], array( 'jetpack', 'jetpack_modules' ) ) ) {
1797
				$page = $_GET['page'];
1798
			}
1799
1800
			wp_safe_redirect( Jetpack::admin_url( 'page=' . $page ) );
1801
			exit;
1802
		}
1803
	}
1804
1805
	/**
1806
	 * List available Jetpack modules. Simply lists .php files in /modules/.
1807
	 * Make sure to tuck away module "library" files in a sub-directory.
1808
	 */
1809
	public static function get_available_modules( $min_version = false, $max_version = false ) {
1810
		static $modules = null;
1811
1812
		if ( ! isset( $modules ) ) {
1813
			$available_modules_option = Jetpack_Options::get_option( 'available_modules', array() );
1814
			// Use the cache if we're on the front-end and it's available...
1815
			if ( ! is_admin() && ! empty( $available_modules_option[ JETPACK__VERSION ] ) ) {
1816
				$modules = $available_modules_option[ JETPACK__VERSION ];
1817
			} else {
1818
				$files = Jetpack::glob_php( JETPACK__PLUGIN_DIR . 'modules' );
1819
1820
				$modules = array();
1821
1822
				foreach ( $files as $file ) {
1823
					if ( ! $headers = Jetpack::get_module( $file ) ) {
1824
						continue;
1825
					}
1826
1827
					$modules[ Jetpack::get_module_slug( $file ) ] = $headers['introduced'];
1828
				}
1829
1830
				Jetpack_Options::update_option( 'available_modules', array(
1831
					JETPACK__VERSION => $modules,
1832
				) );
1833
			}
1834
		}
1835
1836
		/**
1837
		 * Filters the array of modules available to be activated.
1838
		 *
1839
		 * @since 2.4.0
1840
		 *
1841
		 * @param array $modules Array of available modules.
1842
		 * @param string $min_version Minimum version number required to use modules.
1843
		 * @param string $max_version Maximum version number required to use modules.
1844
		 */
1845
		$mods = apply_filters( 'jetpack_get_available_modules', $modules, $min_version, $max_version );
1846
1847
		if ( ! $min_version && ! $max_version ) {
1848
			return array_keys( $mods );
1849
		}
1850
1851
		$r = array();
1852
		foreach ( $mods as $slug => $introduced ) {
1853
			if ( $min_version && version_compare( $min_version, $introduced, '>=' ) ) {
1854
				continue;
1855
			}
1856
1857
			if ( $max_version && version_compare( $max_version, $introduced, '<' ) ) {
1858
				continue;
1859
			}
1860
1861
			$r[] = $slug;
1862
		}
1863
1864
		return $r;
1865
	}
1866
1867
	/**
1868
	 * Default modules loaded on activation.
1869
	 */
1870
	public static function get_default_modules( $min_version = false, $max_version = false ) {
1871
		$return = array();
1872
1873
		foreach ( Jetpack::get_available_modules( $min_version, $max_version ) as $module ) {
1874
			$module_data = Jetpack::get_module( $module );
1875
1876
			switch ( strtolower( $module_data['auto_activate'] ) ) {
1877
				case 'yes' :
1878
					$return[] = $module;
1879
					break;
1880
				case 'public' :
1881
					if ( Jetpack_Options::get_option( 'public' ) ) {
1882
						$return[] = $module;
1883
					}
1884
					break;
1885
				case 'no' :
1886
				default :
1887
					break;
1888
			}
1889
		}
1890
		/**
1891
		 * Filters the array of default modules.
1892
		 *
1893
		 * @since 2.5.0
1894
		 *
1895
		 * @param array $return Array of default modules.
1896
		 * @param string $min_version Minimum version number required to use modules.
1897
		 * @param string $max_version Maximum version number required to use modules.
1898
		 */
1899
		return apply_filters( 'jetpack_get_default_modules', $return, $min_version, $max_version );
1900
	}
1901
1902
	/**
1903
	 * Checks activated modules during auto-activation to determine
1904
	 * if any of those modules are being deprecated.  If so, close
1905
	 * them out, and add any replacement modules.
1906
	 *
1907
	 * Runs at priority 99 by default.
1908
	 *
1909
	 * This is run late, so that it can still activate a module if
1910
	 * the new module is a replacement for another that the user
1911
	 * currently has active, even if something at the normal priority
1912
	 * would kibosh everything.
1913
	 *
1914
	 * @since 2.6
1915
	 * @uses jetpack_get_default_modules filter
1916
	 * @param array $modules
1917
	 * @return array
1918
	 */
1919
	function handle_deprecated_modules( $modules ) {
1920
		$deprecated_modules = array(
1921
			'debug'            => null,  // Closed out and moved to ./class.jetpack-debugger.php
1922
			'wpcc'             => 'sso', // Closed out in 2.6 -- SSO provides the same functionality.
1923
			'gplus-authorship' => null,  // Closed out in 3.2 -- Google dropped support.
1924
		);
1925
1926
		// Don't activate SSO if they never completed activating WPCC.
1927
		if ( Jetpack::is_module_active( 'wpcc' ) ) {
1928
			$wpcc_options = Jetpack_Options::get_option( 'wpcc_options' );
1929
			if ( empty( $wpcc_options ) || empty( $wpcc_options['client_id'] ) || empty( $wpcc_options['client_id'] ) ) {
1930
				$deprecated_modules['wpcc'] = null;
1931
			}
1932
		}
1933
1934
		foreach ( $deprecated_modules as $module => $replacement ) {
1935
			if ( Jetpack::is_module_active( $module ) ) {
1936
				self::deactivate_module( $module );
1937
				if ( $replacement ) {
1938
					$modules[] = $replacement;
1939
				}
1940
			}
1941
		}
1942
1943
		return array_unique( $modules );
1944
	}
1945
1946
	/**
1947
	 * Checks activated plugins during auto-activation to determine
1948
	 * if any of those plugins are in the list with a corresponding module
1949
	 * that is not compatible with the plugin. The module will not be allowed
1950
	 * to auto-activate.
1951
	 *
1952
	 * @since 2.6
1953
	 * @uses jetpack_get_default_modules filter
1954
	 * @param array $modules
1955
	 * @return array
1956
	 */
1957
	function filter_default_modules( $modules ) {
1958
1959
		$active_plugins = self::get_active_plugins();
1960
1961
		if ( ! empty( $active_plugins ) ) {
1962
1963
			// For each module we'd like to auto-activate...
1964
			foreach ( $modules as $key => $module ) {
1965
				// If there are potential conflicts for it...
1966
				if ( ! empty( $this->conflicting_plugins[ $module ] ) ) {
1967
					// For each potential conflict...
1968
					foreach ( $this->conflicting_plugins[ $module ] as $title => $plugin ) {
1969
						// If that conflicting plugin is active...
1970
						if ( in_array( $plugin, $active_plugins ) ) {
1971
							// Remove that item from being auto-activated.
1972
							unset( $modules[ $key ] );
1973
						}
1974
					}
1975
				}
1976
			}
1977
		}
1978
1979
		return $modules;
1980
	}
1981
1982
	/**
1983
	 * Extract a module's slug from its full path.
1984
	 */
1985
	public static function get_module_slug( $file ) {
1986
		return str_replace( '.php', '', basename( $file ) );
1987
	}
1988
1989
	/**
1990
	 * Generate a module's path from its slug.
1991
	 */
1992
	public static function get_module_path( $slug ) {
1993
		return JETPACK__PLUGIN_DIR . "modules/$slug.php";
1994
	}
1995
1996
	/**
1997
	 * Load module data from module file. Headers differ from WordPress
1998
	 * plugin headers to avoid them being identified as standalone
1999
	 * plugins on the WordPress plugins page.
2000
	 */
2001
	public static function get_module( $module ) {
2002
		$headers = array(
2003
			'name'                      => 'Module Name',
2004
			'description'               => 'Module Description',
2005
			'jumpstart_desc'            => 'Jumpstart Description',
2006
			'sort'                      => 'Sort Order',
2007
			'recommendation_order'      => 'Recommendation Order',
2008
			'introduced'                => 'First Introduced',
2009
			'changed'                   => 'Major Changes In',
2010
			'deactivate'                => 'Deactivate',
2011
			'free'                      => 'Free',
2012
			'requires_connection'       => 'Requires Connection',
2013
			'auto_activate'             => 'Auto Activate',
2014
			'module_tags'               => 'Module Tags',
2015
			'feature'                   => 'Feature',
2016
			'additional_search_queries' => 'Additional Search Queries',
2017
		);
2018
2019
		$file = Jetpack::get_module_path( Jetpack::get_module_slug( $module ) );
2020
2021
		$mod = Jetpack::get_file_data( $file, $headers );
2022
		if ( empty( $mod['name'] ) ) {
2023
			return false;
2024
		}
2025
2026
		$mod['sort']                    = empty( $mod['sort'] ) ? 10 : (int) $mod['sort'];
2027
		$mod['recommendation_order']    = empty( $mod['recommendation_order'] ) ? 20 : (int) $mod['recommendation_order'];
2028
		$mod['deactivate']              = empty( $mod['deactivate'] );
2029
		$mod['free']                    = empty( $mod['free'] );
2030
		$mod['requires_connection']     = ( ! empty( $mod['requires_connection'] ) && 'No' == $mod['requires_connection'] ) ? false : true;
2031
2032
		if ( empty( $mod['auto_activate'] ) || ! in_array( strtolower( $mod['auto_activate'] ), array( 'yes', 'no', 'public' ) ) ) {
2033
			$mod['auto_activate'] = 'No';
2034
		} else {
2035
			$mod['auto_activate'] = (string) $mod['auto_activate'];
2036
		}
2037
2038
		if ( $mod['module_tags'] ) {
2039
			$mod['module_tags'] = explode( ',', $mod['module_tags'] );
2040
			$mod['module_tags'] = array_map( 'trim', $mod['module_tags'] );
2041
			$mod['module_tags'] = array_map( array( __CLASS__, 'translate_module_tag' ), $mod['module_tags'] );
2042
		} else {
2043
			$mod['module_tags'] = array( self::translate_module_tag( 'Other' ) );
2044
		}
2045
2046
		if ( $mod['feature'] ) {
2047
			$mod['feature'] = explode( ',', $mod['feature'] );
2048
			$mod['feature'] = array_map( 'trim', $mod['feature'] );
2049
		} else {
2050
			$mod['feature'] = array( self::translate_module_tag( 'Other' ) );
2051
		}
2052
2053
		/**
2054
		 * Filters the feature array on a module.
2055
		 *
2056
		 * This filter allows you to control where each module is filtered: Recommended,
2057
		 * Jumpstart, and the default "Other" listing.
2058
		 *
2059
		 * @since 3.5.0
2060
		 *
2061
		 * @param array   $mod['feature'] The areas to feature this module:
2062
		 *     'Jumpstart' adds to the "Jumpstart" option to activate many modules at once.
2063
		 *     'Recommended' shows on the main Jetpack admin screen.
2064
		 *     'Other' should be the default if no other value is in the array.
2065
		 * @param string  $module The slug of the module, e.g. sharedaddy.
2066
		 * @param array   $mod All the currently assembled module data.
2067
		 */
2068
		$mod['feature'] = apply_filters( 'jetpack_module_feature', $mod['feature'], $module, $mod );
2069
2070
		/**
2071
		 * Filter the returned data about a module.
2072
		 *
2073
		 * This filter allows overriding any info about Jetpack modules. It is dangerous,
2074
		 * so please be careful.
2075
		 *
2076
		 * @since 3.6.0
2077
		 *
2078
		 * @param array   $mod    The details of the requested module.
2079
		 * @param string  $module The slug of the module, e.g. sharedaddy
2080
		 * @param string  $file   The path to the module source file.
2081
		 */
2082
		return apply_filters( 'jetpack_get_module', $mod, $module, $file );
2083
	}
2084
2085
	/**
2086
	 * Like core's get_file_data implementation, but caches the result.
2087
	 */
2088
	public static function get_file_data( $file, $headers ) {
2089
		//Get just the filename from $file (i.e. exclude full path) so that a consistent hash is generated
2090
		$file_name = basename( $file );
2091
		$file_data_option = Jetpack_Options::get_option( 'file_data', array() );
2092
		$key              = md5( $file_name . serialize( $headers ) );
2093
		$refresh_cache    = is_admin() && isset( $_GET['page'] ) && 'jetpack' === substr( $_GET['page'], 0, 7 );
2094
2095
		// If we don't need to refresh the cache, and already have the value, short-circuit!
2096
		if ( ! $refresh_cache && isset( $file_data_option[ JETPACK__VERSION ][ $key ] ) ) {
2097
			return $file_data_option[ JETPACK__VERSION ][ $key ];
2098
		}
2099
2100
		$data = get_file_data( $file, $headers );
2101
2102
		// Strip out any old Jetpack versions that are cluttering the option.
2103
		$file_data_option = array_intersect_key( (array) $file_data_option, array( JETPACK__VERSION => null ) );
2104
		$file_data_option[ JETPACK__VERSION ][ $key ] = $data;
2105
		Jetpack_Options::update_option( 'file_data', $file_data_option );
2106
2107
		return $data;
2108
	}
2109
2110
	/**
2111
	 * Return translated module tag.
2112
	 *
2113
	 * @param string $tag Tag as it appears in each module heading.
2114
	 *
2115
	 * @return mixed
2116
	 */
2117
	public static function translate_module_tag( $tag ) {
2118
		return jetpack_get_module_i18n_tag( $tag );
2119
	}
2120
2121
	/**
2122
	 * Return module name translation. Uses matching string created in modules/module-headings.php.
2123
	 *
2124
	 * @since 3.9.2
2125
	 *
2126
	 * @param array $modules
2127
	 *
2128
	 * @return string|void
2129
	 */
2130
	public static function get_translated_modules( $modules ) {
2131
		foreach ( $modules as $index => $module ) {
2132
			$i18n_module = jetpack_get_module_i18n( $module['module'] );
2133
			if ( isset( $module['name'] ) ) {
2134
				$modules[ $index ]['name'] = $i18n_module['name'];
2135
			}
2136
			if ( isset( $module['description'] ) ) {
2137
				$modules[ $index ]['description'] = $i18n_module['description'];
2138
				$modules[ $index ]['short_description'] = $i18n_module['description'];
2139
			}
2140
		}
2141
		return $modules;
2142
	}
2143
2144
	/**
2145
	 * Get a list of activated modules as an array of module slugs.
2146
	 */
2147
	public static function get_active_modules() {
2148
		$active = Jetpack_Options::get_option( 'active_modules' );
2149
		if ( ! is_array( $active ) )
2150
			$active = array();
2151
		if ( class_exists( 'VaultPress' ) || function_exists( 'vaultpress_contact_service' ) ) {
2152
			$active[] = 'vaultpress';
2153
		} else {
2154
			$active = array_diff( $active, array( 'vaultpress' ) );
2155
		}
2156
2157
		//If protect is active on the main site of a multisite, it should be active on all sites.
2158
		if ( ! in_array( 'protect', $active ) && is_multisite() && get_site_option( 'jetpack_protect_active' ) ) {
2159
			$active[] = 'protect';
2160
		}
2161
2162
		return array_unique( $active );
2163
	}
2164
2165
	/**
2166
	 * Check whether or not a Jetpack module is active.
2167
	 *
2168
	 * @param string $module The slug of a Jetpack module.
2169
	 * @return bool
2170
	 *
2171
	 * @static
2172
	 */
2173
	public static function is_module_active( $module ) {
2174
		return in_array( $module, self::get_active_modules() );
2175
	}
2176
2177
	public static function is_module( $module ) {
2178
		return ! empty( $module ) && ! validate_file( $module, Jetpack::get_available_modules() );
2179
	}
2180
2181
	/**
2182
	 * Catches PHP errors.  Must be used in conjunction with output buffering.
2183
	 *
2184
	 * @param bool $catch True to start catching, False to stop.
2185
	 *
2186
	 * @static
2187
	 */
2188
	public static function catch_errors( $catch ) {
2189
		static $display_errors, $error_reporting;
2190
2191
		if ( $catch ) {
2192
			$display_errors  = @ini_set( 'display_errors', 1 );
2193
			$error_reporting = @error_reporting( E_ALL );
2194
			add_action( 'shutdown', array( 'Jetpack', 'catch_errors_on_shutdown' ), 0 );
2195
		} else {
2196
			@ini_set( 'display_errors', $display_errors );
2197
			@error_reporting( $error_reporting );
2198
			remove_action( 'shutdown', array( 'Jetpack', 'catch_errors_on_shutdown' ), 0 );
2199
		}
2200
	}
2201
2202
	/**
2203
	 * Saves any generated PHP errors in ::state( 'php_errors', {errors} )
2204
	 */
2205
	public static function catch_errors_on_shutdown() {
2206
		Jetpack::state( 'php_errors', ob_get_clean() );
2207
	}
2208
2209
	public static function activate_default_modules( $min_version = false, $max_version = false, $other_modules = array(), $redirect = true ) {
2210
		$jetpack = Jetpack::init();
2211
2212
		$modules = Jetpack::get_default_modules( $min_version, $max_version );
2213
		$modules = array_merge( $other_modules, $modules );
2214
2215
		// Look for standalone plugins and disable if active.
2216
2217
		$to_deactivate = array();
2218
		foreach ( $modules as $module ) {
2219
			if ( isset( $jetpack->plugins_to_deactivate[$module] ) ) {
2220
				$to_deactivate[$module] = $jetpack->plugins_to_deactivate[$module];
2221
			}
2222
		}
2223
2224
		$deactivated = array();
2225
		foreach ( $to_deactivate as $module => $deactivate_me ) {
2226
			list( $probable_file, $probable_title ) = $deactivate_me;
2227
			if ( Jetpack_Client_Server::deactivate_plugin( $probable_file, $probable_title ) ) {
2228
				$deactivated[] = $module;
2229
			}
2230
		}
2231
2232
		if ( $deactivated && $redirect ) {
2233
			Jetpack::state( 'deactivated_plugins', join( ',', $deactivated ) );
2234
2235
			$url = add_query_arg(
2236
				array(
2237
					'action'   => 'activate_default_modules',
2238
					'_wpnonce' => wp_create_nonce( 'activate_default_modules' ),
2239
				),
2240
				add_query_arg( compact( 'min_version', 'max_version', 'other_modules' ), Jetpack::admin_url( 'page=jetpack' ) )
2241
			);
2242
			wp_safe_redirect( $url );
2243
			exit;
2244
		}
2245
2246
		/**
2247
		 * Fires before default modules are activated.
2248
		 *
2249
		 * @since 1.9.0
2250
		 *
2251
		 * @param string $min_version Minimum version number required to use modules.
2252
		 * @param string $max_version Maximum version number required to use modules.
2253
		 * @param array $other_modules Array of other modules to activate alongside the default modules.
2254
		 */
2255
		do_action( 'jetpack_before_activate_default_modules', $min_version, $max_version, $other_modules );
2256
2257
		// Check each module for fatal errors, a la wp-admin/plugins.php::activate before activating
2258
		Jetpack::restate();
2259
		Jetpack::catch_errors( true );
2260
2261
		$active = Jetpack::get_active_modules();
2262
2263
		foreach ( $modules as $module ) {
2264
			if ( did_action( "jetpack_module_loaded_$module" ) ) {
2265
				$active[] = $module;
2266
				self::update_active_modules( $active );
2267
				continue;
2268
			}
2269
2270
			if ( in_array( $module, $active ) ) {
2271
				$module_info = Jetpack::get_module( $module );
2272
				if ( ! $module_info['deactivate'] ) {
2273
					$state = in_array( $module, $other_modules ) ? 'reactivated_modules' : 'activated_modules';
2274 View Code Duplication
					if ( $active_state = Jetpack::state( $state ) ) {
2275
						$active_state = explode( ',', $active_state );
2276
					} else {
2277
						$active_state = array();
2278
					}
2279
					$active_state[] = $module;
2280
					Jetpack::state( $state, implode( ',', $active_state ) );
2281
				}
2282
				continue;
2283
			}
2284
2285
			$file = Jetpack::get_module_path( $module );
2286
			if ( ! file_exists( $file ) ) {
2287
				continue;
2288
			}
2289
2290
			// we'll override this later if the plugin can be included without fatal error
2291
			if ( $redirect ) {
2292
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
2293
			}
2294
			Jetpack::state( 'error', 'module_activation_failed' );
2295
			Jetpack::state( 'module', $module );
2296
			ob_start();
2297
			require $file;
2298
2299
			$active[] = $module;
2300
			$state    = in_array( $module, $other_modules ) ? 'reactivated_modules' : 'activated_modules';
2301 View Code Duplication
			if ( $active_state = Jetpack::state( $state ) ) {
2302
				$active_state = explode( ',', $active_state );
2303
			} else {
2304
				$active_state = array();
2305
			}
2306
			$active_state[] = $module;
2307
			Jetpack::state( $state, implode( ',', $active_state ) );
2308
			Jetpack::update_active_modules( $active );
2309
2310
			ob_end_clean();
2311
		}
2312
		Jetpack::state( 'error', false );
2313
		Jetpack::state( 'module', false );
2314
		Jetpack::catch_errors( false );
2315
		/**
2316
		 * Fires when default modules are activated.
2317
		 *
2318
		 * @since 1.9.0
2319
		 *
2320
		 * @param string $min_version Minimum version number required to use modules.
2321
		 * @param string $max_version Maximum version number required to use modules.
2322
		 * @param array $other_modules Array of other modules to activate alongside the default modules.
2323
		 */
2324
		do_action( 'jetpack_activate_default_modules', $min_version, $max_version, $other_modules );
2325
	}
2326
2327
	public static function activate_module( $module, $exit = true, $redirect = true ) {
2328
		/**
2329
		 * Fires before a module is activated.
2330
		 *
2331
		 * @since 2.6.0
2332
		 *
2333
		 * @param string $module Module slug.
2334
		 * @param bool $exit Should we exit after the module has been activated. Default to true.
2335
		 * @param bool $redirect Should the user be redirected after module activation? Default to true.
2336
		 */
2337
		do_action( 'jetpack_pre_activate_module', $module, $exit, $redirect );
2338
2339
		$jetpack = Jetpack::init();
2340
2341
		if ( ! strlen( $module ) )
2342
			return false;
2343
2344
		if ( ! Jetpack::is_module( $module ) )
2345
			return false;
2346
2347
		// If it's already active, then don't do it again
2348
		$active = Jetpack::get_active_modules();
2349
		foreach ( $active as $act ) {
2350
			if ( $act == $module )
2351
				return true;
2352
		}
2353
2354
		$module_data = Jetpack::get_module( $module );
2355
2356
		if ( ! Jetpack::is_active() ) {
2357
			if ( !Jetpack::is_development_mode() )
2358
				return false;
2359
2360
			// If we're not connected but in development mode, make sure the module doesn't require a connection
2361
			if ( Jetpack::is_development_mode() && $module_data['requires_connection'] )
2362
				return false;
2363
		}
2364
2365
		// Check and see if the old plugin is active
2366
		if ( isset( $jetpack->plugins_to_deactivate[ $module ] ) ) {
2367
			// Deactivate the old plugin
2368
			if ( Jetpack_Client_Server::deactivate_plugin( $jetpack->plugins_to_deactivate[ $module ][0], $jetpack->plugins_to_deactivate[ $module ][1] ) ) {
2369
				// If we deactivated the old plugin, remembere that with ::state() and redirect back to this page to activate the module
2370
				// We can't activate the module on this page load since the newly deactivated old plugin is still loaded on this page load.
2371
				Jetpack::state( 'deactivated_plugins', $module );
2372
				wp_safe_redirect( add_query_arg( 'jetpack_restate', 1 ) );
2373
				exit;
2374
			}
2375
		}
2376
2377
		// Check the file for fatal errors, a la wp-admin/plugins.php::activate
2378
		Jetpack::state( 'module', $module );
2379
		Jetpack::state( 'error', 'module_activation_failed' ); // we'll override this later if the plugin can be included without fatal error
2380
2381
		Jetpack::catch_errors( true );
2382
		ob_start();
2383
		require Jetpack::get_module_path( $module );
2384
		/** This action is documented in class.jetpack.php */
2385
		do_action( 'jetpack_activate_module', $module );
2386
		$active[] = $module;
2387
		Jetpack::update_active_modules( $active );
2388
2389
		Jetpack::state( 'error', false ); // the override
2390
		ob_end_clean();
2391
		Jetpack::catch_errors( false );
2392
2393
		// A flag for Jump Start so it's not shown again. Only set if it hasn't been yet.
2394 View Code Duplication
		if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
2395
			Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
2396
2397
			//Jump start is being dismissed send data to MC Stats
2398
			$jetpack->stat( 'jumpstart', 'manual,'.$module );
2399
2400
			$jetpack->do_stats( 'server_side' );
2401
		}
2402
2403
		if ( $redirect ) {
2404
			wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
2405
		}
2406
		if ( $exit ) {
2407
			exit;
2408
		}
2409
		return true;
2410
	}
2411
2412
	function activate_module_actions( $module ) {
2413
		_deprecated_function( __METHOD__, 'jeptack-4.2' );
2414
	}
2415
2416
	public static function deactivate_module( $module ) {
2417
		/**
2418
		 * Fires when a module is deactivated.
2419
		 *
2420
		 * @since 1.9.0
2421
		 *
2422
		 * @param string $module Module slug.
2423
		 */
2424
		do_action( 'jetpack_pre_deactivate_module', $module );
2425
2426
		$jetpack = Jetpack::init();
2427
2428
		$active = Jetpack::get_active_modules();
2429
		$new    = array_filter( array_diff( $active, (array) $module ) );
2430
2431
		// A flag for Jump Start so it's not shown again.
2432 View Code Duplication
		if ( 'new_connection' === Jetpack_Options::get_option( 'jumpstart' ) ) {
2433
			Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
2434
2435
			//Jump start is being dismissed send data to MC Stats
2436
			$jetpack->stat( 'jumpstart', 'manual,deactivated-'.$module );
2437
2438
			$jetpack->do_stats( 'server_side' );
2439
		}
2440
2441
		return self::update_active_modules( $new );
2442
	}
2443
2444
	public static function enable_module_configurable( $module ) {
2445
		$module = Jetpack::get_module_slug( $module );
2446
		add_filter( 'jetpack_module_configurable_' . $module, '__return_true' );
2447
	}
2448
2449
	public static function module_configuration_url( $module ) {
2450
		$module = Jetpack::get_module_slug( $module );
2451
		return Jetpack::admin_url( array( 'page' => 'jetpack', 'configure' => $module ) );
2452
	}
2453
2454
	public static function module_configuration_load( $module, $method ) {
2455
		$module = Jetpack::get_module_slug( $module );
2456
		add_action( 'jetpack_module_configuration_load_' . $module, $method );
2457
	}
2458
2459
	public static function module_configuration_head( $module, $method ) {
2460
		$module = Jetpack::get_module_slug( $module );
2461
		add_action( 'jetpack_module_configuration_head_' . $module, $method );
2462
	}
2463
2464
	public static function module_configuration_screen( $module, $method ) {
2465
		$module = Jetpack::get_module_slug( $module );
2466
		add_action( 'jetpack_module_configuration_screen_' . $module, $method );
2467
	}
2468
2469
	public static function module_configuration_activation_screen( $module, $method ) {
2470
		$module = Jetpack::get_module_slug( $module );
2471
		add_action( 'display_activate_module_setting_' . $module, $method );
2472
	}
2473
2474
/* Installation */
2475
2476
	public static function bail_on_activation( $message, $deactivate = true ) {
2477
?>
2478
<!doctype html>
2479
<html>
2480
<head>
2481
<meta charset="<?php bloginfo( 'charset' ); ?>">
2482
<style>
2483
* {
2484
	text-align: center;
2485
	margin: 0;
2486
	padding: 0;
2487
	font-family: "Lucida Grande",Verdana,Arial,"Bitstream Vera Sans",sans-serif;
2488
}
2489
p {
2490
	margin-top: 1em;
2491
	font-size: 18px;
2492
}
2493
</style>
2494
<body>
2495
<p><?php echo esc_html( $message ); ?></p>
2496
</body>
2497
</html>
2498
<?php
2499
		if ( $deactivate ) {
2500
			$plugins = get_option( 'active_plugins' );
2501
			$jetpack = plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' );
2502
			$update  = false;
2503
			foreach ( $plugins as $i => $plugin ) {
2504
				if ( $plugin === $jetpack ) {
2505
					$plugins[$i] = false;
2506
					$update = true;
2507
				}
2508
			}
2509
2510
			if ( $update ) {
2511
				update_option( 'active_plugins', array_filter( $plugins ) );
2512
			}
2513
		}
2514
		exit;
2515
	}
2516
2517
	/**
2518
	 * Attached to activate_{ plugin_basename( __FILES__ ) } by register_activation_hook()
2519
	 * @static
2520
	 */
2521
	public static function plugin_activation( $network_wide ) {
2522
		Jetpack_Options::update_option( 'activated', 1 );
2523
2524
		if ( version_compare( $GLOBALS['wp_version'], JETPACK__MINIMUM_WP_VERSION, '<' ) ) {
2525
			Jetpack::bail_on_activation( sprintf( __( 'Jetpack requires WordPress version %s or later.', 'jetpack' ), JETPACK__MINIMUM_WP_VERSION ) );
2526
		}
2527
2528
		if ( $network_wide )
2529
			Jetpack::state( 'network_nag', true );
2530
2531
		Jetpack::plugin_initialize();
2532
	}
2533
	/**
2534
	 * Runs before bumping version numbers up to a new version
2535
	 * @param  (string) $version    Version:timestamp
2536
	 * @param  (string) $old_version Old Version:timestamp or false if not set yet.
2537
	 * @return null              [description]
2538
	 */
2539
	public static function do_version_bump( $version, $old_version ) {
2540
2541
		if ( ! $old_version ) { // For new sites
2542
			// Setting up jetpack manage
2543
			Jetpack::activate_manage();
2544
		}
2545
	}
2546
2547
	/**
2548
	 * Sets the internal version number and activation state.
2549
	 * @static
2550
	 */
2551
	public static function plugin_initialize() {
2552
		if ( ! Jetpack_Options::get_option( 'activated' ) ) {
2553
			Jetpack_Options::update_option( 'activated', 2 );
2554
		}
2555
2556 View Code Duplication
		if ( ! Jetpack_Options::get_option( 'version' ) ) {
2557
			$version = $old_version = JETPACK__VERSION . ':' . time();
2558
			/** This action is documented in class.jetpack.php */
2559
			do_action( 'updating_jetpack_version', $version, false );
2560
			Jetpack_Options::update_options( compact( 'version', 'old_version' ) );
2561
		}
2562
2563
		Jetpack::load_modules();
2564
2565
		Jetpack_Options::delete_option( 'do_activate' );
2566
	}
2567
2568
	/**
2569
	 * Removes all connection options
2570
	 * @static
2571
	 */
2572
	public static function plugin_deactivation( ) {
2573
		require_once( ABSPATH . '/wp-admin/includes/plugin.php' );
2574
		if( is_plugin_active_for_network( 'jetpack/jetpack.php' ) ) {
2575
			Jetpack_Network::init()->deactivate();
2576
		} else {
2577
			Jetpack::disconnect( false );
2578
			//Jetpack_Heartbeat::init()->deactivate();
2579
		}
2580
	}
2581
2582
	/**
2583
	 * Disconnects from the Jetpack servers.
2584
	 * Forgets all connection details and tells the Jetpack servers to do the same.
2585
	 * @static
2586
	 */
2587
	public static function disconnect( $update_activated_state = true ) {
2588
		wp_clear_scheduled_hook( 'jetpack_clean_nonces' );
2589
		Jetpack::clean_nonces( true );
2590
2591
		// If the site is in an IDC because sync is not allowed,
2592
		// let's make sure to not disconnect the production site.
2593
		if ( ! self::validate_sync_error_idc_option() ) {
2594
			Jetpack::load_xml_rpc_client();
2595
			$xml = new Jetpack_IXR_Client();
2596
			$xml->query( 'jetpack.deregister' );
2597
		}
2598
2599
		Jetpack_Options::delete_option(
2600
			array(
2601
				'register',
2602
				'blog_token',
2603
				'user_token',
2604
				'user_tokens',
2605
				'master_user',
2606
				'time_diff',
2607
				'fallback_no_verify_ssl_certs',
2608
				'sync_error_idc',
2609
			)
2610
		);
2611
2612
		if ( $update_activated_state ) {
2613
			Jetpack_Options::update_option( 'activated', 4 );
2614
		}
2615
2616
		if ( $jetpack_unique_connection = Jetpack_Options::get_option( 'unique_connection' ) ) {
2617
			// Check then record unique disconnection if site has never been disconnected previously
2618
			if ( - 1 == $jetpack_unique_connection['disconnected'] ) {
2619
				$jetpack_unique_connection['disconnected'] = 1;
2620
			} else {
2621
				if ( 0 == $jetpack_unique_connection['disconnected'] ) {
2622
					//track unique disconnect
2623
					$jetpack = Jetpack::init();
2624
2625
					$jetpack->stat( 'connections', 'unique-disconnect' );
2626
					$jetpack->do_stats( 'server_side' );
2627
				}
2628
				// increment number of times disconnected
2629
				$jetpack_unique_connection['disconnected'] += 1;
2630
			}
2631
2632
			Jetpack_Options::update_option( 'unique_connection', $jetpack_unique_connection );
2633
		}
2634
2635
		// Delete all the sync related data. Since it could be taking up space.
2636
		require_once JETPACK__PLUGIN_DIR . 'sync/class.jetpack-sync-sender.php';
2637
		Jetpack_Sync_Sender::get_instance()->uninstall();
2638
2639
		// Disable the Heartbeat cron
2640
		Jetpack_Heartbeat::init()->deactivate();
2641
	}
2642
2643
	/**
2644
	 * Unlinks the current user from the linked WordPress.com user
2645
	 */
2646
	public static function unlink_user( $user_id = null ) {
2647
		if ( ! $tokens = Jetpack_Options::get_option( 'user_tokens' ) )
2648
			return false;
2649
2650
		$user_id = empty( $user_id ) ? get_current_user_id() : intval( $user_id );
2651
2652
		if ( Jetpack_Options::get_option( 'master_user' ) == $user_id )
2653
			return false;
2654
2655
		if ( ! isset( $tokens[ $user_id ] ) )
2656
			return false;
2657
2658
		Jetpack::load_xml_rpc_client();
2659
		$xml = new Jetpack_IXR_Client( compact( 'user_id' ) );
2660
		$xml->query( 'jetpack.unlink_user', $user_id );
2661
2662
		unset( $tokens[ $user_id ] );
2663
2664
		Jetpack_Options::update_option( 'user_tokens', $tokens );
2665
2666
		/**
2667
		 * Fires after the current user has been unlinked from WordPress.com.
2668
		 *
2669
		 * @since 4.1.0
2670
		 *
2671
		 * @param int $user_id The current user's ID.
2672
		 */
2673
		do_action( 'jetpack_unlinked_user', $user_id );
2674
2675
		return true;
2676
	}
2677
2678
	/**
2679
	 * Attempts Jetpack registration.  If it fail, a state flag is set: @see ::admin_page_load()
2680
	 */
2681
	public static function try_registration() {
2682
		// Let's get some testing in beta versions and such.
2683
		if ( self::is_development_version() && defined( 'PHP_URL_HOST' ) ) {
2684
			// Before attempting to connect, let's make sure that the domains are viable.
2685
			$domains_to_check = array_unique( array(
2686
				'siteurl' => parse_url( get_site_url(), PHP_URL_HOST ),
2687
				'homeurl' => parse_url( get_home_url(), PHP_URL_HOST ),
2688
			) );
2689
			foreach ( $domains_to_check as $domain ) {
2690
				$result = Jetpack_Data::is_usable_domain( $domain );
2691
				if ( is_wp_error( $result ) ) {
2692
					return $result;
2693
				}
2694
			}
2695
		}
2696
2697
		$result = Jetpack::register();
2698
2699
		// If there was an error with registration and the site was not registered, record this so we can show a message.
2700
		if ( ! $result || is_wp_error( $result ) ) {
2701
			return $result;
2702
		} else {
2703
			return true;
2704
		}
2705
	}
2706
2707
	/**
2708
	 * Tracking an internal event log. Try not to put too much chaff in here.
2709
	 *
2710
	 * [Everyone Loves a Log!](https://www.youtube.com/watch?v=2C7mNr5WMjA)
2711
	 */
2712
	public static function log( $code, $data = null ) {
2713
		// only grab the latest 200 entries
2714
		$log = array_slice( Jetpack_Options::get_option( 'log', array() ), -199, 199 );
2715
2716
		// Append our event to the log
2717
		$log_entry = array(
2718
			'time'    => time(),
2719
			'user_id' => get_current_user_id(),
2720
			'blog_id' => Jetpack_Options::get_option( 'id' ),
2721
			'code'    => $code,
2722
		);
2723
		// Don't bother storing it unless we've got some.
2724
		if ( ! is_null( $data ) ) {
2725
			$log_entry['data'] = $data;
2726
		}
2727
		$log[] = $log_entry;
2728
2729
		// Try add_option first, to make sure it's not autoloaded.
2730
		// @todo: Add an add_option method to Jetpack_Options
2731
		if ( ! add_option( 'jetpack_log', $log, null, 'no' ) ) {
2732
			Jetpack_Options::update_option( 'log', $log );
2733
		}
2734
2735
		/**
2736
		 * Fires when Jetpack logs an internal event.
2737
		 *
2738
		 * @since 3.0.0
2739
		 *
2740
		 * @param array $log_entry {
2741
		 *	Array of details about the log entry.
2742
		 *
2743
		 *	@param string time Time of the event.
2744
		 *	@param int user_id ID of the user who trigerred the event.
2745
		 *	@param int blog_id Jetpack Blog ID.
2746
		 *	@param string code Unique name for the event.
2747
		 *	@param string data Data about the event.
2748
		 * }
2749
		 */
2750
		do_action( 'jetpack_log_entry', $log_entry );
2751
	}
2752
2753
	/**
2754
	 * Get the internal event log.
2755
	 *
2756
	 * @param $event (string) - only return the specific log events
2757
	 * @param $num   (int)    - get specific number of latest results, limited to 200
2758
	 *
2759
	 * @return array of log events || WP_Error for invalid params
2760
	 */
2761
	public static function get_log( $event = false, $num = false ) {
2762
		if ( $event && ! is_string( $event ) ) {
2763
			return new WP_Error( __( 'First param must be string or empty', 'jetpack' ) );
2764
		}
2765
2766
		if ( $num && ! is_numeric( $num ) ) {
2767
			return new WP_Error( __( 'Second param must be numeric or empty', 'jetpack' ) );
2768
		}
2769
2770
		$entire_log = Jetpack_Options::get_option( 'log', array() );
2771
2772
		// If nothing set - act as it did before, otherwise let's start customizing the output
2773
		if ( ! $num && ! $event ) {
2774
			return $entire_log;
2775
		} else {
2776
			$entire_log = array_reverse( $entire_log );
2777
		}
2778
2779
		$custom_log_output = array();
2780
2781
		if ( $event ) {
2782
			foreach ( $entire_log as $log_event ) {
2783
				if ( $event == $log_event[ 'code' ] ) {
2784
					$custom_log_output[] = $log_event;
2785
				}
2786
			}
2787
		} else {
2788
			$custom_log_output = $entire_log;
2789
		}
2790
2791
		if ( $num ) {
2792
			$custom_log_output = array_slice( $custom_log_output, 0, $num );
2793
		}
2794
2795
		return $custom_log_output;
2796
	}
2797
2798
	/**
2799
	 * Log modification of important settings.
2800
	 */
2801
	public static function log_settings_change( $option, $old_value, $value ) {
2802
		switch( $option ) {
2803
			case 'jetpack_sync_non_public_post_stati':
2804
				self::log( $option, $value );
2805
				break;
2806
		}
2807
	}
2808
2809
	/**
2810
	 * Return stat data for WPCOM sync
2811
	 */
2812
	public static function get_stat_data( $encode = true, $extended = true ) {
2813
		$heartbeat_data = Jetpack_Heartbeat::generate_stats_array();
2814
		if ( $extended ) {
2815
			$additional_data = self::get_additional_stat_data();
2816
		}
2817
2818
		$merged_data = array_merge( $heartbeat_data, $additional_data );
0 ignored issues
show
The variable $additional_data does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
2819
2820
		if ( $encode ) {
2821
			return json_encode( $merged_data );
2822
		}
2823
2824
		return $merged_data;
2825
	}
2826
2827
	/**
2828
	 * Get additional stat data to sync to WPCOM
2829
	 */
2830
	public static function get_additional_stat_data( $prefix = '' ) {
2831
		$return["{$prefix}themes"]         = Jetpack::get_parsed_theme_data();
2832
		$return["{$prefix}plugins-extra"]  = Jetpack::get_parsed_plugin_data();
2833
		$return["{$prefix}users"]          = (int) Jetpack::get_site_user_count();
2834
		$return["{$prefix}site-count"]     = 0;
2835
2836
		if ( function_exists( 'get_blog_count' ) ) {
2837
			$return["{$prefix}site-count"] = get_blog_count();
2838
		}
2839
		return $return;
2840
	}
2841
2842
	private static function get_site_user_count() {
2843
		global $wpdb;
2844
2845
		if ( function_exists( 'wp_is_large_network' ) ) {
2846
			if ( wp_is_large_network( 'users' ) ) {
2847
				return 10101; // Not a real value but should tell us that we are dealing with a large network.
2848
			}
2849
		}
2850 View Code Duplication
		if ( false === ( $user_count = get_transient( 'jetpack_site_user_count' ) ) ) {
2851
			// It wasn't there, so regenerate the data and save the transient
2852
			$user_count = $wpdb->get_var( "SELECT COUNT(*) FROM $wpdb->usermeta WHERE meta_key = '{$wpdb->prefix}capabilities'" );
2853
			set_transient( 'jetpack_site_user_count', $user_count, DAY_IN_SECONDS );
2854
		}
2855
		return $user_count;
2856
	}
2857
2858
	/* Admin Pages */
2859
2860
	function admin_init() {
2861
		// If the plugin is not connected, display a connect message.
2862
		if (
2863
			// the plugin was auto-activated and needs its candy
2864
			Jetpack_Options::get_option_and_ensure_autoload( 'do_activate', '0' )
2865
		||
2866
			// the plugin is active, but was never activated.  Probably came from a site-wide network activation
2867
			! Jetpack_Options::get_option( 'activated' )
2868
		) {
2869
			Jetpack::plugin_initialize();
2870
		}
2871
2872
		if ( ! Jetpack::is_active() && ! Jetpack::is_development_mode() ) {
2873
			if ( 4 != Jetpack_Options::get_option( 'activated' ) ) {
2874
				// Show connect notice on dashboard and plugins pages
2875
				add_action( 'load-index.php', array( $this, 'prepare_connect_notice' ) );
2876
				add_action( 'load-plugins.php', array( $this, 'prepare_connect_notice' ) );
2877
			}
2878
		} elseif ( false === Jetpack_Options::get_option( 'fallback_no_verify_ssl_certs' ) ) {
2879
			// Upgrade: 1.1 -> 1.1.1
2880
			// Check and see if host can verify the Jetpack servers' SSL certificate
2881
			$args = array();
2882
			Jetpack_Client::_wp_remote_request(
2883
				Jetpack::fix_url_for_bad_hosts( Jetpack::api_url( 'test' ) ),
2884
				$args,
2885
				true
2886
			);
2887
		} else {
2888
			// Show the notice on the Dashboard only for now
2889
2890
			add_action( 'load-index.php', array( $this, 'prepare_manage_jetpack_notice' ) );
2891
		}
2892
2893
		if ( current_user_can( 'manage_options' ) && 'AUTO' == JETPACK_CLIENT__HTTPS && ! self::permit_ssl() ) {
2894
			add_action( 'jetpack_notices', array( $this, 'alert_auto_ssl_fail' ) );
2895
		}
2896
2897
		add_action( 'load-plugins.php', array( $this, 'intercept_plugin_error_scrape_init' ) );
2898
		add_action( 'admin_enqueue_scripts', array( $this, 'admin_menu_css' ) );
2899
		add_filter( 'plugin_action_links_' . plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' ), array( $this, 'plugin_action_links' ) );
2900
2901
		if ( Jetpack::is_active() || Jetpack::is_development_mode() ) {
2902
			// Artificially throw errors in certain whitelisted cases during plugin activation
2903
			add_action( 'activate_plugin', array( $this, 'throw_error_on_activate_plugin' ) );
2904
		}
2905
2906
		// Jetpack Manage Activation Screen from .com
2907
		Jetpack::module_configuration_activation_screen( 'manage', array( $this, 'manage_activate_screen' ) );
2908
2909
		// Add custom column in wp-admin/users.php to show whether user is linked.
2910
		add_filter( 'manage_users_columns',       array( $this, 'jetpack_icon_user_connected' ) );
2911
		add_action( 'manage_users_custom_column', array( $this, 'jetpack_show_user_connected_icon' ), 10, 3 );
2912
		add_action( 'admin_print_styles',         array( $this, 'jetpack_user_col_style' ) );
2913
	}
2914
2915
	function admin_body_class( $admin_body_class = '' ) {
2916
		$classes = explode( ' ', trim( $admin_body_class ) );
2917
2918
		$classes[] = self::is_active() ? 'jetpack-connected' : 'jetpack-disconnected';
2919
2920
		$admin_body_class = implode( ' ', array_unique( $classes ) );
2921
		return " $admin_body_class ";
2922
	}
2923
2924
	static function add_jetpack_pagestyles( $admin_body_class = '' ) {
2925
		return $admin_body_class . ' jetpack-pagestyles ';
2926
	}
2927
2928
	function prepare_connect_notice() {
2929
		add_action( 'admin_print_styles', array( $this, 'admin_banner_styles' ) );
2930
2931
		add_action( 'admin_notices', array( $this, 'admin_connect_notice' ) );
2932
2933
		if ( Jetpack::state( 'network_nag' ) )
2934
			add_action( 'network_admin_notices', array( $this, 'network_connect_notice' ) );
2935
	}
2936
	/**
2937
	 * Call this function if you want the Big Jetpack Manage Notice to show up.
2938
	 *
2939
	 * @return null
2940
	 */
2941
	function prepare_manage_jetpack_notice() {
2942
2943
		add_action( 'admin_print_styles', array( $this, 'admin_banner_styles' ) );
2944
		add_action( 'admin_notices', array( $this, 'admin_jetpack_manage_notice' ) );
2945
	}
2946
2947
	function manage_activate_screen() {
2948
		include ( JETPACK__PLUGIN_DIR . 'modules/manage/activate-admin.php' );
2949
	}
2950
	/**
2951
	 * Sometimes a plugin can activate without causing errors, but it will cause errors on the next page load.
2952
	 * This function artificially throws errors for such cases (whitelisted).
2953
	 *
2954
	 * @param string $plugin The activated plugin.
2955
	 */
2956
	function throw_error_on_activate_plugin( $plugin ) {
2957
		$active_modules = Jetpack::get_active_modules();
2958
2959
		// The Shortlinks module and the Stats plugin conflict, but won't cause errors on activation because of some function_exists() checks.
2960
		if ( function_exists( 'stats_get_api_key' ) && in_array( 'shortlinks', $active_modules ) ) {
2961
			$throw = false;
2962
2963
			// Try and make sure it really was the stats plugin
2964
			if ( ! class_exists( 'ReflectionFunction' ) ) {
2965
				if ( 'stats.php' == basename( $plugin ) ) {
2966
					$throw = true;
2967
				}
2968
			} else {
2969
				$reflection = new ReflectionFunction( 'stats_get_api_key' );
2970
				if ( basename( $plugin ) == basename( $reflection->getFileName() ) ) {
2971
					$throw = true;
2972
				}
2973
			}
2974
2975
			if ( $throw ) {
2976
				trigger_error( sprintf( __( 'Jetpack contains the most recent version of the old &#8220;%1$s&#8221; plugin.', 'jetpack' ), 'WordPress.com Stats' ), E_USER_ERROR );
2977
			}
2978
		}
2979
	}
2980
2981
	function intercept_plugin_error_scrape_init() {
2982
		add_action( 'check_admin_referer', array( $this, 'intercept_plugin_error_scrape' ), 10, 2 );
2983
	}
2984
2985
	function intercept_plugin_error_scrape( $action, $result ) {
2986
		if ( ! $result ) {
2987
			return;
2988
		}
2989
2990
		foreach ( $this->plugins_to_deactivate as $deactivate_me ) {
2991
			if ( "plugin-activation-error_{$deactivate_me[0]}" == $action ) {
2992
				Jetpack::bail_on_activation( sprintf( __( 'Jetpack contains the most recent version of the old &#8220;%1$s&#8221; plugin.', 'jetpack' ), $deactivate_me[1] ), false );
2993
			}
2994
		}
2995
	}
2996
2997
	function add_remote_request_handlers() {
2998
		add_action( 'wp_ajax_nopriv_jetpack_upload_file', array( $this, 'remote_request_handlers' ) );
2999
	}
3000
3001
	function remote_request_handlers() {
3002
		switch ( current_filter() ) {
3003
		case 'wp_ajax_nopriv_jetpack_upload_file' :
3004
			$response = $this->upload_handler();
3005
			break;
3006
		default :
3007
			$response = new Jetpack_Error( 'unknown_handler', 'Unknown Handler', 400 );
3008
			break;
3009
		}
3010
3011
		if ( ! $response ) {
3012
			$response = new Jetpack_Error( 'unknown_error', 'Unknown Error', 400 );
3013
		}
3014
3015
		if ( is_wp_error( $response ) ) {
3016
			$status_code       = $response->get_error_data();
3017
			$error             = $response->get_error_code();
3018
			$error_description = $response->get_error_message();
3019
3020
			if ( ! is_int( $status_code ) ) {
3021
				$status_code = 400;
3022
			}
3023
3024
			status_header( $status_code );
3025
			die( json_encode( (object) compact( 'error', 'error_description' ) ) );
3026
		}
3027
3028
		status_header( 200 );
3029
		if ( true === $response ) {
3030
			exit;
3031
		}
3032
3033
		die( json_encode( (object) $response ) );
3034
	}
3035
3036
	function upload_handler() {
3037
		if ( 'POST' !== strtoupper( $_SERVER['REQUEST_METHOD'] ) ) {
3038
			return new Jetpack_Error( 405, get_status_header_desc( 405 ), 405 );
3039
		}
3040
3041
		$user = wp_authenticate( '', '' );
3042
		if ( ! $user || is_wp_error( $user ) ) {
3043
			return new Jetpack_Error( 403, get_status_header_desc( 403 ), 403 );
3044
		}
3045
3046
		wp_set_current_user( $user->ID );
3047
3048
		if ( ! current_user_can( 'upload_files' ) ) {
3049
			return new Jetpack_Error( 'cannot_upload_files', 'User does not have permission to upload files', 403 );
3050
		}
3051
3052
		if ( empty( $_FILES ) ) {
3053
			return new Jetpack_Error( 'no_files_uploaded', 'No files were uploaded: nothing to process', 400 );
3054
		}
3055
3056
		foreach ( array_keys( $_FILES ) as $files_key ) {
3057
			if ( ! isset( $_POST["_jetpack_file_hmac_{$files_key}"] ) ) {
3058
				return new Jetpack_Error( 'missing_hmac', 'An HMAC for one or more files is missing', 400 );
3059
			}
3060
		}
3061
3062
		$media_keys = array_keys( $_FILES['media'] );
3063
3064
		$token = Jetpack_Data::get_access_token( get_current_user_id() );
3065
		if ( ! $token || is_wp_error( $token ) ) {
3066
			return new Jetpack_Error( 'unknown_token', 'Unknown Jetpack token', 403 );
3067
		}
3068
3069
		$uploaded_files = array();
3070
		$global_post    = isset( $GLOBALS['post'] ) ? $GLOBALS['post'] : null;
3071
		unset( $GLOBALS['post'] );
3072
		foreach ( $_FILES['media']['name'] as $index => $name ) {
3073
			$file = array();
3074
			foreach ( $media_keys as $media_key ) {
3075
				$file[$media_key] = $_FILES['media'][$media_key][$index];
3076
			}
3077
3078
			list( $hmac_provided, $salt ) = explode( ':', $_POST['_jetpack_file_hmac_media'][$index] );
3079
3080
			$hmac_file = hash_hmac_file( 'sha1', $file['tmp_name'], $salt . $token->secret );
3081
			if ( $hmac_provided !== $hmac_file ) {
3082
				$uploaded_files[$index] = (object) array( 'error' => 'invalid_hmac', 'error_description' => 'The corresponding HMAC for this file does not match' );
3083
				continue;
3084
			}
3085
3086
			$_FILES['.jetpack.upload.'] = $file;
3087
			$post_id = isset( $_POST['post_id'][$index] ) ? absint( $_POST['post_id'][$index] ) : 0;
3088
			if ( ! current_user_can( 'edit_post', $post_id ) ) {
3089
				$post_id = 0;
3090
			}
3091
			$attachment_id = media_handle_upload(
3092
				'.jetpack.upload.',
3093
				$post_id,
3094
				array(),
3095
				array(
3096
					'action' => 'jetpack_upload_file',
3097
				)
3098
			);
3099
3100
			if ( ! $attachment_id ) {
3101
				$uploaded_files[$index] = (object) array( 'error' => 'unknown', 'error_description' => 'An unknown problem occurred processing the upload on the Jetpack site' );
3102
			} elseif ( is_wp_error( $attachment_id ) ) {
3103
				$uploaded_files[$index] = (object) array( 'error' => 'attachment_' . $attachment_id->get_error_code(), 'error_description' => $attachment_id->get_error_message() );
3104
			} else {
3105
				$attachment = get_post( $attachment_id );
3106
				$uploaded_files[$index] = (object) array(
3107
					'id'   => (string) $attachment_id,
3108
					'file' => $attachment->post_title,
3109
					'url'  => wp_get_attachment_url( $attachment_id ),
3110
					'type' => $attachment->post_mime_type,
3111
					'meta' => wp_get_attachment_metadata( $attachment_id ),
3112
				);
3113
			}
3114
		}
3115
		if ( ! is_null( $global_post ) ) {
3116
			$GLOBALS['post'] = $global_post;
3117
		}
3118
3119
		return $uploaded_files;
3120
	}
3121
3122
	/**
3123
	 * Add help to the Jetpack page
3124
	 *
3125
	 * @since Jetpack (1.2.3)
3126
	 * @return false if not the Jetpack page
3127
	 */
3128
	function admin_help() {
3129
		$current_screen = get_current_screen();
3130
3131
		// Overview
3132
		$current_screen->add_help_tab(
3133
			array(
3134
				'id'		=> 'home',
3135
				'title'		=> __( 'Home', 'jetpack' ),
3136
				'content'	=>
3137
					'<p><strong>' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</strong></p>' .
3138
					'<p>' . __( 'Jetpack supercharges your self-hosted WordPress site with the awesome cloud power of WordPress.com.', 'jetpack' ) . '</p>' .
3139
					'<p>' . __( 'On this page, you are able to view the modules available within Jetpack, learn more about them, and activate or deactivate them as needed.', 'jetpack' ) . '</p>',
3140
			)
3141
		);
3142
3143
		// Screen Content
3144
		if ( current_user_can( 'manage_options' ) ) {
3145
			$current_screen->add_help_tab(
3146
				array(
3147
					'id'		=> 'settings',
3148
					'title'		=> __( 'Settings', 'jetpack' ),
3149
					'content'	=>
3150
						'<p><strong>' . __( 'Jetpack by WordPress.com',                                              'jetpack' ) . '</strong></p>' .
3151
						'<p>' . __( 'You can activate or deactivate individual Jetpack modules to suit your needs.', 'jetpack' ) . '</p>' .
3152
						'<ol>' .
3153
							'<li>' . __( 'Each module has an Activate or Deactivate link so you can toggle one individually.',														'jetpack' ) . '</li>' .
3154
							'<li>' . __( 'Using the checkboxes next to each module, you can select multiple modules to toggle via the Bulk Actions menu at the top of the list.',	'jetpack' ) . '</li>' .
3155
						'</ol>' .
3156
						'<p>' . __( 'Using the tools on the right, you can search for specific modules, filter by module categories or which are active, or change the sorting order.', 'jetpack' ) . '</p>'
3157
				)
3158
			);
3159
		}
3160
3161
		// Help Sidebar
3162
		$current_screen->set_help_sidebar(
3163
			'<p><strong>' . __( 'For more information:', 'jetpack' ) . '</strong></p>' .
3164
			'<p><a href="https://jetpack.com/faq/" target="_blank">'     . __( 'Jetpack FAQ',     'jetpack' ) . '</a></p>' .
3165
			'<p><a href="https://jetpack.com/support/" target="_blank">' . __( 'Jetpack Support', 'jetpack' ) . '</a></p>' .
3166
			'<p><a href="' . Jetpack::admin_url( array( 'page' => 'jetpack-debugger' )  ) .'">' . __( 'Jetpack Debugging Center', 'jetpack' ) . '</a></p>'
3167
		);
3168
	}
3169
3170
	function admin_menu_css() {
3171
		wp_enqueue_style( 'jetpack-icons' );
3172
	}
3173
3174
	function admin_menu_order() {
3175
		return true;
3176
	}
3177
3178 View Code Duplication
	function jetpack_menu_order( $menu_order ) {
3179
		$jp_menu_order = array();
3180
3181
		foreach ( $menu_order as $index => $item ) {
3182
			if ( $item != 'jetpack' ) {
3183
				$jp_menu_order[] = $item;
3184
			}
3185
3186
			if ( $index == 0 ) {
3187
				$jp_menu_order[] = 'jetpack';
3188
			}
3189
		}
3190
3191
		return $jp_menu_order;
3192
	}
3193
3194
	function admin_head() {
3195 View Code Duplication
		if ( isset( $_GET['configure'] ) && Jetpack::is_module( $_GET['configure'] ) && current_user_can( 'manage_options' ) )
3196
			/** This action is documented in class.jetpack-admin-page.php */
3197
			do_action( 'jetpack_module_configuration_head_' . $_GET['configure'] );
3198
	}
3199
3200 View Code Duplication
	function admin_banner_styles() {
3201
		$min = ( defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ) ? '' : '.min';
3202
3203
		wp_enqueue_style( 'jetpack', plugins_url( "css/jetpack-banners{$min}.css", JETPACK__PLUGIN_FILE ), false, JETPACK__VERSION . '-20121016' );
3204
		wp_style_add_data( 'jetpack', 'rtl', 'replace' );
3205
		wp_style_add_data( 'jetpack', 'suffix', $min );
3206
	}
3207
3208
	function plugin_action_links( $actions ) {
3209
3210
		$jetpack_home = array( 'jetpack-home' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack' ), __( 'Jetpack', 'jetpack' ) ) );
3211
3212
		if( current_user_can( 'jetpack_manage_modules' ) && ( Jetpack::is_active() || Jetpack::is_development_mode() ) ) {
3213
			return array_merge(
3214
				$jetpack_home,
3215
				array( 'settings' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack_modules' ), __( 'Settings', 'jetpack' ) ) ),
3216
				array( 'support' => sprintf( '<a href="%s">%s</a>', Jetpack::admin_url( 'page=jetpack-debugger '), __( 'Support', 'jetpack' ) ) ),
3217
				$actions
3218
				);
3219
			}
3220
3221
		return array_merge( $jetpack_home, $actions );
3222
	}
3223
3224
	function admin_connect_notice() {
3225
		// Don't show the connect notice anywhere but the plugins.php after activating
3226
		$current = get_current_screen();
3227
		if ( 'plugins' !== $current->parent_base )
3228
			return;
3229
3230
		if ( ! current_user_can( 'jetpack_connect' ) )
3231
			return;
3232
3233
		$dismiss_and_deactivate_url = wp_nonce_url( Jetpack::admin_url( '?page=jetpack&jetpack-notice=dismiss' ), 'jetpack-deactivate' );
3234
		?>
3235
		<div id="message" class="updated jp-banner">
3236
			<a href="<?php echo esc_url( $dismiss_and_deactivate_url ); ?>" class="notice-dismiss" title="<?php esc_attr_e( 'Dismiss this notice', 'jetpack' ); ?>"></a>
3237
			<?php if ( in_array( Jetpack_Options::get_option( 'activated' ) , array( 1, 2, 3 ) ) ) : ?>
3238
					<div class="jp-banner__description-container">
3239
						<h2 class="jp-banner__header"><?php _e( 'Your Jetpack is almost ready!', 'jetpack' ); ?></h2>
3240
						<p class="jp-banner__description"><?php _e( 'Please connect to or create a WordPress.com account to enable Jetpack, including powerful security, traffic, and customization services.', 'jetpack' ); ?></p>
3241
						<p class="jp-banner__button-container">
3242
							<a href="<?php echo $this->build_connect_url( false, false, 'banner' ) ?>" class="button button-primary" id="wpcom-connect"><?php _e( 'Connect to WordPress.com', 'jetpack' ); ?></a>
3243
							<a href="<?php echo Jetpack::admin_url( 'admin.php?page=jetpack' ) ?>" class="button" title="<?php esc_attr_e( 'Learn about the benefits you receive when you connect Jetpack to WordPress.com', 'jetpack' ); ?>"><?php _e( 'Learn more', 'jetpack' ); ?></a>
3244
						</p>
3245
					</div>
3246
			<?php else : ?>
3247
				<div class="jp-banner__content">
3248
					<h2><?php _e( 'Jetpack is installed!', 'jetpack' ) ?></h2>
3249
					<p><?php _e( 'It\'s ready to bring awesome, WordPress.com cloud-powered features to your site.', 'jetpack' ) ?></p>
3250
				</div>
3251
				<div class="jp-banner__action-container">
3252
					<a href="<?php echo Jetpack::admin_url() ?>" class="jp-banner__button" id="wpcom-connect"><?php _e( 'Learn More', 'jetpack' ); ?></a>
3253
				</div>
3254
			<?php endif; ?>
3255
		</div>
3256
3257
		<?php
3258
	}
3259
3260
	/**
3261
	 * This is the first banner
3262
	 * It should be visible only to user that can update the option
3263
	 * Are not connected
3264
	 *
3265
	 * @return null
3266
	 */
3267
	function admin_jetpack_manage_notice() {
3268
		$screen = get_current_screen();
3269
3270
		// Don't show the connect notice on the jetpack settings page.
3271
		if ( ! in_array( $screen->base, array( 'dashboard' ) ) || $screen->is_network || $screen->action )
3272
			return;
3273
3274
		// Only show it if don't have the managment option set.
3275
		// And not dismissed it already.
3276
		if ( ! $this->can_display_jetpack_manage_notice() || Jetpack_Options::get_option( 'dismissed_manage_banner' ) ) {
3277
			return;
3278
		}
3279
3280
		$opt_out_url = $this->opt_out_jetpack_manage_url();
3281
		$opt_in_url  = $this->opt_in_jetpack_manage_url();
3282
		/**
3283
		 * I think it would be great to have different wordsing depending on where you are
3284
		 * for example if we show the notice on dashboard and a different one if we show it on Plugins screen
3285
		 * etc..
3286
		 */
3287
3288
		?>
3289
		<div id="message" class="updated jp-banner">
3290
				<a href="<?php echo esc_url( $opt_out_url ); ?>" class="notice-dismiss" title="<?php esc_attr_e( 'Dismiss this notice', 'jetpack' ); ?>"></a>
3291
				<div class="jp-banner__description-container">
3292
					<h2 class="jp-banner__header"><?php esc_html_e( 'Jetpack Centralized Site Management', 'jetpack' ); ?></h2>
3293
					<p class="jp-banner__description"><?php printf( __( 'Manage multiple Jetpack enabled sites from one single dashboard at wordpress.com. Allows all existing, connected Administrators to modify your site.', 'jetpack' ), 'https://jetpack.com/support/site-management' ); ?></p>
3294
					<p class="jp-banner__button-container">
3295
						<a href="<?php echo esc_url( $opt_in_url ); ?>" class="button button-primary" id="wpcom-connect"><?php _e( 'Activate Jetpack Manage', 'jetpack' ); ?></a>
3296
						<a href="https://jetpack.com/support/site-management" class="button" target="_blank" title="<?php esc_attr_e( 'Learn more about Jetpack Manage on Jetpack.com', 'jetpack' ); ?>"><?php _e( 'Learn more', 'jetpack' ); ?></a>
3297
					</p>
3298
				</div>
3299
		</div>
3300
		<?php
3301
	}
3302
3303
	/**
3304
	 * Returns the url that the user clicks to remove the notice for the big banner
3305
	 * @return (string)
3306
	 */
3307
	function opt_out_jetpack_manage_url() {
3308
		$referer = '&_wp_http_referer=' . add_query_arg( '_wp_http_referer', null );
3309
		return wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=jetpack-manage-opt-out' . $referer ), 'jetpack_manage_banner_opt_out' );
3310
	}
3311
	/**
3312
	 * Returns the url that the user clicks to opt in to Jetpack Manage
3313
	 * @return (string)
3314
	 */
3315
	function opt_in_jetpack_manage_url() {
3316
		return wp_nonce_url( Jetpack::admin_url( 'jetpack-notice=jetpack-manage-opt-in' ), 'jetpack_manage_banner_opt_in' );
3317
	}
3318
3319
	function opt_in_jetpack_manage_notice() {
3320
		?>
3321
		<div class="wrap">
3322
			<div id="message" class="jetpack-message is-opt-in">
3323
				<?php echo sprintf( __( '<p><a href="%1$s" title="Opt in to WordPress.com Site Management" >Activate Site Management</a> to manage multiple sites from our centralized dashboard at wordpress.com/sites. <a href="%2$s" target="_blank">Learn more</a>.</p><a href="%1$s" class="jp-button">Activate Now</a>', 'jetpack' ), $this->opt_in_jetpack_manage_url(), 'https://jetpack.com/support/site-management' ); ?>
3324
			</div>
3325
		</div>
3326
		<?php
3327
3328
	}
3329
	/**
3330
	 * Determines whether to show the notice of not true = display notice
3331
	 * @return (bool)
3332
	 */
3333
	function can_display_jetpack_manage_notice() {
3334
		// never display the notice to users that can't do anything about it anyways
3335
		if( ! current_user_can( 'jetpack_manage_modules' ) )
3336
			return false;
3337
3338
		// don't display if we are in development more
3339
		if( Jetpack::is_development_mode() ) {
3340
			return false;
3341
		}
3342
		// don't display if the site is private
3343
		if(  ! Jetpack_Options::get_option( 'public' ) )
3344
			return false;
3345
3346
		/**
3347
		 * Should the Jetpack Remote Site Management notice be displayed.
3348
		 *
3349
		 * @since 3.3.0
3350
		 *
3351
		 * @param bool ! self::is_module_active( 'manage' ) Is the Manage module inactive.
3352
		 */
3353
		return apply_filters( 'can_display_jetpack_manage_notice', ! self::is_module_active( 'manage' ) );
3354
	}
3355
3356
	function network_connect_notice() {
3357
		?>
3358
		<div id="message" class="updated jetpack-message">
3359
			<div class="squeezer">
3360
				<h2><?php _e( '<strong>Jetpack is activated!</strong> Each site on your network must be connected individually by an admin on that site.', 'jetpack' ) ?></h2>
3361
			</div>
3362
		</div>
3363
		<?php
3364
	}
3365
3366
	/*
3367
	 * Registration flow:
3368
	 * 1 - ::admin_page_load() action=register
3369
	 * 2 - ::try_registration()
3370
	 * 3 - ::register()
3371
	 *     - Creates jetpack_register option containing two secrets and a timestamp
3372
	 *     - Calls https://jetpack.wordpress.com/jetpack.register/1/ with
3373
	 *       siteurl, home, gmt_offset, timezone_string, site_name, secret_1, secret_2, site_lang, timeout, stats_id
3374
	 *     - That request to jetpack.wordpress.com does not immediately respond.  It first makes a request BACK to this site's
3375
	 *       xmlrpc.php?for=jetpack: RPC method: jetpack.verifyRegistration, Parameters: secret_1
3376
	 *     - The XML-RPC request verifies secret_1, deletes both secrets and responds with: secret_2
3377
	 *     - https://jetpack.wordpress.com/jetpack.register/1/ verifies that XML-RPC response (secret_2) then finally responds itself with
3378
	 *       jetpack_id, jetpack_secret, jetpack_public
3379
	 *     - ::register() then stores jetpack_options: id => jetpack_id, blog_token => jetpack_secret
3380
	 * 4 - redirect to https://wordpress.com/start/jetpack-connect
3381
	 * 5 - user logs in with WP.com account
3382
	 * 6 - remote request to this site's xmlrpc.php with action remoteAuthorize, Jetpack_XMLRPC_Server->remote_authorize
3383
	 *		- Jetpack_Client_Server::authorize()
3384
	 *		- Jetpack_Client_Server::get_token()
3385
	 *		- GET https://jetpack.wordpress.com/jetpack.token/1/ with
3386
	 *        client_id, client_secret, grant_type, code, redirect_uri:action=authorize, state, scope, user_email, user_login
3387
	 *			- which responds with access_token, token_type, scope
3388
	 *		- Jetpack_Client_Server::authorize() stores jetpack_options: user_token => access_token.$user_id
3389
	 *		- Jetpack::activate_default_modules()
3390
	 *     		- Deactivates deprecated plugins
3391
	 *     		- Activates all default modules
3392
	 *		- Responds with either error, or 'connected' for new connection, or 'linked' for additional linked users
3393
	 * 7 - For a new connection, user selects a Jetpack plan on wordpress.com
3394
	 * 8 - User is redirected back to wp-admin/index.php?page=jetpack with state:message=authorized
3395
	 *     Done!
3396
	 */
3397
3398
	/**
3399
	 * Handles the page load events for the Jetpack admin page
3400
	 */
3401
	function admin_page_load() {
3402
		$error = false;
3403
3404
		// Make sure we have the right body class to hook stylings for subpages off of.
3405
		add_filter( 'admin_body_class', array( __CLASS__, 'add_jetpack_pagestyles' ) );
3406
3407
		if ( ! empty( $_GET['jetpack_restate'] ) ) {
3408
			// Should only be used in intermediate redirects to preserve state across redirects
3409
			Jetpack::restate();
3410
		}
3411
3412
		if ( isset( $_GET['connect_url_redirect'] ) ) {
3413
			// User clicked in the iframe to link their accounts
3414
			if ( ! Jetpack::is_user_connected() ) {
3415
				$connect_url = $this->build_connect_url( true, false, 'iframe' );
3416
				if ( isset( $_GET['notes_iframe'] ) )
3417
					$connect_url .= '&notes_iframe';
3418
				wp_redirect( $connect_url );
3419
				exit;
3420
			} else {
3421
				if ( ! isset( $_GET['calypso_env'] ) ) {
3422
					Jetpack::state( 'message', 'already_authorized' );
3423
					wp_safe_redirect( Jetpack::admin_url() );
3424
				} else {
3425
					$connect_url = $this->build_connect_url( true, false, 'iframe' );
3426
					$connect_url .= '&already_authorized=true';
3427
					wp_redirect( $connect_url );
3428
				}
3429
			}
3430
		}
3431
3432
3433
		if ( isset( $_GET['action'] ) ) {
3434
			switch ( $_GET['action'] ) {
3435
			case 'authorize':
3436
				if ( Jetpack::is_active() && Jetpack::is_user_connected() ) {
3437
					Jetpack::state( 'message', 'already_authorized' );
3438
					wp_safe_redirect( Jetpack::admin_url() );
3439
					exit;
3440
				}
3441
				Jetpack::log( 'authorize' );
3442
				$client_server = new Jetpack_Client_Server;
3443
				$client_server->client_authorize();
3444
				exit;
3445
			case 'register' :
3446
				if ( ! current_user_can( 'jetpack_connect' ) ) {
3447
					$error = 'cheatin';
3448
					break;
3449
				}
3450
				check_admin_referer( 'jetpack-register' );
3451
				Jetpack::log( 'register' );
3452
				Jetpack::maybe_set_version_option();
3453
				$registered = Jetpack::try_registration();
3454
				if ( is_wp_error( $registered ) ) {
3455
					$error = $registered->get_error_code();
3456
					Jetpack::state( 'error', $error );
3457
					Jetpack::state( 'error', $registered->get_error_message() );
3458
					break;
3459
				}
3460
3461
				$from = isset( $_GET['from'] ) ? $_GET['from'] : false;
3462
3463
				wp_redirect( $this->build_connect_url( true, false, $from ) );
3464
				exit;
3465
			case 'activate' :
3466
				if ( ! current_user_can( 'jetpack_activate_modules' ) ) {
3467
					$error = 'cheatin';
3468
					break;
3469
				}
3470
3471
				$module = stripslashes( $_GET['module'] );
3472
				check_admin_referer( "jetpack_activate-$module" );
3473
				Jetpack::log( 'activate', $module );
3474
				Jetpack::activate_module( $module );
3475
				// The following two lines will rarely happen, as Jetpack::activate_module normally exits at the end.
3476
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
3477
				exit;
3478
			case 'activate_default_modules' :
3479
				check_admin_referer( 'activate_default_modules' );
3480
				Jetpack::log( 'activate_default_modules' );
3481
				Jetpack::restate();
3482
				$min_version   = isset( $_GET['min_version'] ) ? $_GET['min_version'] : false;
3483
				$max_version   = isset( $_GET['max_version'] ) ? $_GET['max_version'] : false;
3484
				$other_modules = isset( $_GET['other_modules'] ) && is_array( $_GET['other_modules'] ) ? $_GET['other_modules'] : array();
3485
				Jetpack::activate_default_modules( $min_version, $max_version, $other_modules );
3486
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
3487
				exit;
3488
			case 'disconnect' :
3489
				if ( ! current_user_can( 'jetpack_disconnect' ) ) {
3490
					$error = 'cheatin';
3491
					break;
3492
				}
3493
3494
				check_admin_referer( 'jetpack-disconnect' );
3495
				Jetpack::log( 'disconnect' );
3496
				Jetpack::disconnect();
3497
				wp_safe_redirect( Jetpack::admin_url( 'disconnected=true' ) );
3498
				exit;
3499
			case 'reconnect' :
3500
				if ( ! current_user_can( 'jetpack_reconnect' ) ) {
3501
					$error = 'cheatin';
3502
					break;
3503
				}
3504
3505
				check_admin_referer( 'jetpack-reconnect' );
3506
				Jetpack::log( 'reconnect' );
3507
				$this->disconnect();
3508
				wp_redirect( $this->build_connect_url( true, false, 'reconnect' ) );
3509
				exit;
3510 View Code Duplication
			case 'deactivate' :
3511
				if ( ! current_user_can( 'jetpack_deactivate_modules' ) ) {
3512
					$error = 'cheatin';
3513
					break;
3514
				}
3515
3516
				$modules = stripslashes( $_GET['module'] );
3517
				check_admin_referer( "jetpack_deactivate-$modules" );
3518
				foreach ( explode( ',', $modules ) as $module ) {
3519
					Jetpack::log( 'deactivate', $module );
3520
					Jetpack::deactivate_module( $module );
3521
					Jetpack::state( 'message', 'module_deactivated' );
3522
				}
3523
				Jetpack::state( 'module', $modules );
3524
				wp_safe_redirect( Jetpack::admin_url( 'page=jetpack' ) );
3525
				exit;
3526
			case 'unlink' :
3527
				$redirect = isset( $_GET['redirect'] ) ? $_GET['redirect'] : '';
3528
				check_admin_referer( 'jetpack-unlink' );
3529
				Jetpack::log( 'unlink' );
3530
				$this->unlink_user();
3531
				Jetpack::state( 'message', 'unlinked' );
3532
				if ( 'sub-unlink' == $redirect ) {
3533
					wp_safe_redirect( admin_url() );
3534
				} else {
3535
					wp_safe_redirect( Jetpack::admin_url( array( 'page' => $redirect ) ) );
3536
				}
3537
				exit;
3538
			default:
3539
				/**
3540
				 * Fires when a Jetpack admin page is loaded with an unrecognized parameter.
3541
				 *
3542
				 * @since 2.6.0
3543
				 *
3544
				 * @param string sanitize_key( $_GET['action'] ) Unrecognized URL parameter.
3545
				 */
3546
				do_action( 'jetpack_unrecognized_action', sanitize_key( $_GET['action'] ) );
3547
			}
3548
		}
3549
3550
		if ( ! $error = $error ? $error : Jetpack::state( 'error' ) ) {
3551
			self::activate_new_modules( true );
3552
		}
3553
3554
		$message_code = Jetpack::state( 'message' );
3555
		if ( Jetpack::state( 'optin-manage' ) ) {
3556
			$activated_manage = $message_code;
3557
			$message_code = 'jetpack-manage';
3558
		}
3559
3560
		switch ( $message_code ) {
3561
		case 'jetpack-manage':
3562
			$this->message = '<strong>' . sprintf( __( 'You are all set! Your site can now be managed from <a href="%s" target="_blank">wordpress.com/sites</a>.', 'jetpack' ), 'https://wordpress.com/sites' ) . '</strong>';
3563
			if ( $activated_manage ) {
3564
				$this->message .= '<br /><strong>' . __( 'Manage has been activated for you!', 'jetpack'  ) . '</strong>';
3565
			}
3566
			break;
3567
3568
		}
3569
3570
		$deactivated_plugins = Jetpack::state( 'deactivated_plugins' );
3571
3572
		if ( ! empty( $deactivated_plugins ) ) {
3573
			$deactivated_plugins = explode( ',', $deactivated_plugins );
3574
			$deactivated_titles  = array();
3575
			foreach ( $deactivated_plugins as $deactivated_plugin ) {
3576
				if ( ! isset( $this->plugins_to_deactivate[$deactivated_plugin] ) ) {
3577
					continue;
3578
				}
3579
3580
				$deactivated_titles[] = '<strong>' . str_replace( ' ', '&nbsp;', $this->plugins_to_deactivate[$deactivated_plugin][1] ) . '</strong>';
3581
			}
3582
3583
			if ( $deactivated_titles ) {
3584
				if ( $this->message ) {
3585
					$this->message .= "<br /><br />\n";
3586
				}
3587
3588
				$this->message .= wp_sprintf(
3589
					_n(
3590
						'Jetpack contains the most recent version of the old %l plugin.',
3591
						'Jetpack contains the most recent versions of the old %l plugins.',
3592
						count( $deactivated_titles ),
3593
						'jetpack'
3594
					),
3595
					$deactivated_titles
3596
				);
3597
3598
				$this->message .= "<br />\n";
3599
3600
				$this->message .= _n(
3601
					'The old version has been deactivated and can be removed from your site.',
3602
					'The old versions have been deactivated and can be removed from your site.',
3603
					count( $deactivated_titles ),
3604
					'jetpack'
3605
				);
3606
			}
3607
		}
3608
3609
		$this->privacy_checks = Jetpack::state( 'privacy_checks' );
3610
3611
		if ( $this->message || $this->error || $this->privacy_checks || $this->can_display_jetpack_manage_notice() ) {
3612
			add_action( 'jetpack_notices', array( $this, 'admin_notices' ) );
3613
		}
3614
3615 View Code Duplication
		if ( isset( $_GET['configure'] ) && Jetpack::is_module( $_GET['configure'] ) && current_user_can( 'manage_options' ) ) {
3616
			/**
3617
			 * Fires when a module configuration page is loaded.
3618
			 * The dynamic part of the hook is the configure parameter from the URL.
3619
			 *
3620
			 * @since 1.1.0
3621
			 */
3622
			do_action( 'jetpack_module_configuration_load_' . $_GET['configure'] );
3623
		}
3624
3625
		add_filter( 'jetpack_short_module_description', 'wptexturize' );
3626
	}
3627
3628
	function admin_notices() {
3629
3630
		if ( $this->error ) {
3631
?>
3632
<div id="message" class="jetpack-message jetpack-err">
3633
	<div class="squeezer">
3634
		<h2><?php echo wp_kses( $this->error, array( 'a' => array( 'href' => array() ), 'small' => true, 'code' => true, 'strong' => true, 'br' => true, 'b' => true ) ); ?></h2>
3635
<?php	if ( $desc = Jetpack::state( 'error_description' ) ) : ?>
3636
		<p><?php echo esc_html( stripslashes( $desc ) ); ?></p>
3637
<?php	endif; ?>
3638
	</div>
3639
</div>
3640
<?php
3641
		}
3642
3643
		if ( $this->message ) {
3644
?>
3645
<div id="message" class="jetpack-message">
3646
	<div class="squeezer">
3647
		<h2><?php echo wp_kses( $this->message, array( 'strong' => array(), 'a' => array( 'href' => true ), 'br' => true ) ); ?></h2>
3648
	</div>
3649
</div>
3650
<?php
3651
		}
3652
3653
		if ( $this->privacy_checks ) :
3654
			$module_names = $module_slugs = array();
3655
3656
			$privacy_checks = explode( ',', $this->privacy_checks );
3657
			$privacy_checks = array_filter( $privacy_checks, array( 'Jetpack', 'is_module' ) );
3658
			foreach ( $privacy_checks as $module_slug ) {
3659
				$module = Jetpack::get_module( $module_slug );
3660
				if ( ! $module ) {
3661
					continue;
3662
				}
3663
3664
				$module_slugs[] = $module_slug;
3665
				$module_names[] = "<strong>{$module['name']}</strong>";
3666
			}
3667
3668
			$module_slugs = join( ',', $module_slugs );
3669
?>
3670
<div id="message" class="jetpack-message jetpack-err">
3671
	<div class="squeezer">
3672
		<h2><strong><?php esc_html_e( 'Is this site private?', 'jetpack' ); ?></strong></h2><br />
3673
		<p><?php
3674
			echo wp_kses(
3675
				wptexturize(
3676
					wp_sprintf(
3677
						_nx(
3678
							"Like your site's RSS feeds, %l allows access to your posts and other content to third parties.",
3679
							"Like your site's RSS feeds, %l allow access to your posts and other content to third parties.",
3680
							count( $privacy_checks ),
3681
							'%l = list of Jetpack module/feature names',
3682
							'jetpack'
3683
						),
3684
						$module_names
3685
					)
3686
				),
3687
				array( 'strong' => true )
3688
			);
3689
3690
			echo "\n<br />\n";
3691
3692
			echo wp_kses(
3693
				sprintf(
3694
					_nx(
3695
						'If your site is not publicly accessible, consider <a href="%1$s" title="%2$s">deactivating this feature</a>.',
3696
						'If your site is not publicly accessible, consider <a href="%1$s" title="%2$s">deactivating these features</a>.',
3697
						count( $privacy_checks ),
3698
						'%1$s = deactivation URL, %2$s = "Deactivate {list of Jetpack module/feature names}',
3699
						'jetpack'
3700
					),
3701
					wp_nonce_url(
3702
						Jetpack::admin_url(
3703
							array(
3704
								'page'   => 'jetpack',
3705
								'action' => 'deactivate',
3706
								'module' => urlencode( $module_slugs ),
3707
							)
3708
						),
3709
						"jetpack_deactivate-$module_slugs"
3710
					),
3711
					esc_attr( wp_kses( wp_sprintf( _x( 'Deactivate %l', '%l = list of Jetpack module/feature names', 'jetpack' ), $module_names ), array() ) )
3712
				),
3713
				array( 'a' => array( 'href' => true, 'title' => true ) )
3714
			);
3715
		?></p>
3716
	</div>
3717
</div>
3718
<?php endif;
3719
	// only display the notice if the other stuff is not there
3720
	if( $this->can_display_jetpack_manage_notice() && !  $this->error && ! $this->message && ! $this->privacy_checks ) {
3721
		if( isset( $_GET['page'] ) && 'jetpack' != $_GET['page'] )
3722
			$this->opt_in_jetpack_manage_notice();
3723
		}
3724
	}
3725
3726
	/**
3727
	 * Record a stat for later output.  This will only currently output in the admin_footer.
3728
	 */
3729
	function stat( $group, $detail ) {
3730
		if ( ! isset( $this->stats[ $group ] ) )
3731
			$this->stats[ $group ] = array();
3732
		$this->stats[ $group ][] = $detail;
3733
	}
3734
3735
	/**
3736
	 * Load stats pixels. $group is auto-prefixed with "x_jetpack-"
3737
	 */
3738
	function do_stats( $method = '' ) {
3739
		if ( is_array( $this->stats ) && count( $this->stats ) ) {
3740
			foreach ( $this->stats as $group => $stats ) {
3741
				if ( is_array( $stats ) && count( $stats ) ) {
3742
					$args = array( "x_jetpack-{$group}" => implode( ',', $stats ) );
3743
					if ( 'server_side' === $method ) {
3744
						self::do_server_side_stat( $args );
3745
					} else {
3746
						echo '<img src="' . esc_url( self::build_stats_url( $args ) ) . '" width="1" height="1" style="display:none;" />';
3747
					}
3748
				}
3749
				unset( $this->stats[ $group ] );
3750
			}
3751
		}
3752
	}
3753
3754
	/**
3755
	 * Runs stats code for a one-off, server-side.
3756
	 *
3757
	 * @param $args array|string The arguments to append to the URL. Should include `x_jetpack-{$group}={$stats}` or whatever we want to store.
3758
	 *
3759
	 * @return bool If it worked.
3760
	 */
3761
	static function do_server_side_stat( $args ) {
3762
		$response = wp_remote_get( esc_url_raw( self::build_stats_url( $args ) ) );
3763
		if ( is_wp_error( $response ) )
3764
			return false;
3765
3766
		if ( 200 !== wp_remote_retrieve_response_code( $response ) )
3767
			return false;
3768
3769
		return true;
3770
	}
3771
3772
	/**
3773
	 * Builds the stats url.
3774
	 *
3775
	 * @param $args array|string The arguments to append to the URL.
3776
	 *
3777
	 * @return string The URL to be pinged.
3778
	 */
3779
	static function build_stats_url( $args ) {
3780
		$defaults = array(
3781
			'v'    => 'wpcom2',
3782
			'rand' => md5( mt_rand( 0, 999 ) . time() ),
3783
		);
3784
		$args     = wp_parse_args( $args, $defaults );
3785
		/**
3786
		 * Filter the URL used as the Stats tracking pixel.
3787
		 *
3788
		 * @since 2.3.2
3789
		 *
3790
		 * @param string $url Base URL used as the Stats tracking pixel.
3791
		 */
3792
		$base_url = apply_filters(
3793
			'jetpack_stats_base_url',
3794
			'https://pixel.wp.com/g.gif'
3795
		);
3796
		$url      = add_query_arg( $args, $base_url );
3797
		return $url;
3798
	}
3799
3800
	static function translate_current_user_to_role() {
3801
		foreach ( self::$capability_translations as $role => $cap ) {
3802
			if ( current_user_can( $role ) || current_user_can( $cap ) ) {
3803
				return $role;
3804
			}
3805
		}
3806
3807
		return false;
3808
	}
3809
3810
	static function translate_role_to_cap( $role ) {
3811
		if ( ! isset( self::$capability_translations[$role] ) ) {
3812
			return false;
3813
		}
3814
3815
		return self::$capability_translations[$role];
3816
	}
3817
3818
	static function sign_role( $role ) {
3819
		if ( ! $user_id = (int) get_current_user_id() ) {
3820
			return false;
3821
		}
3822
3823
		$token = Jetpack_Data::get_access_token();
3824
		if ( ! $token || is_wp_error( $token ) ) {
3825
			return false;
3826
		}
3827
3828
		return $role . ':' . hash_hmac( 'md5', "{$role}|{$user_id}", $token->secret );
3829
	}
3830
3831
3832
	/**
3833
	 * Builds a URL to the Jetpack connection auth page
3834
	 *
3835
	 * @since 3.9.5
3836
	 *
3837
	 * @param bool $raw If true, URL will not be escaped.
3838
	 * @param bool|string $redirect If true, will redirect back to Jetpack wp-admin landing page after connection.
3839
	 *                              If string, will be a custom redirect.
3840
	 * @param bool|string $from If not false, adds 'from=$from' param to the connect URL.
3841
	 *
3842
	 * @return string Connect URL
3843
	 */
3844
	function build_connect_url( $raw = false, $redirect = false, $from = false ) {
3845
		if ( ! Jetpack_Options::get_option( 'blog_token' ) || ! Jetpack_Options::get_option( 'id' ) ) {
3846
			$url = Jetpack::nonce_url_no_esc( Jetpack::admin_url( 'action=register' ), 'jetpack-register' );
3847
			if( is_network_admin() ) {
3848
				$url = add_query_arg( 'is_multisite', network_admin_url( 'admin.php?page=jetpack-settings' ), $url );
3849
			}
3850
		} else {
3851
			if ( defined( 'JETPACK__GLOTPRESS_LOCALES_PATH' ) && include_once JETPACK__GLOTPRESS_LOCALES_PATH ) {
3852
				$gp_locale = GP_Locales::by_field( 'wp_locale', get_locale() );
3853
			}
3854
3855
			$role = self::translate_current_user_to_role();
3856
			$signed_role = self::sign_role( $role );
3857
3858
			$user = wp_get_current_user();
3859
3860
			$jetpack_admin_page = esc_url_raw( admin_url( 'admin.php?page=jetpack' ) );
3861
			$redirect = $redirect
3862
				? wp_validate_redirect( esc_url_raw( $redirect ), $jetpack_admin_page )
3863
				: $jetpack_admin_page;
3864
3865
			if( isset( $_REQUEST['is_multisite'] ) ) {
3866
				$redirect = Jetpack_Network::init()->get_url( 'network_admin_page' );
3867
			}
3868
3869
			$secrets = Jetpack::init()->generate_secrets( 'authorize' );
3870
			@list( $secret ) = explode( ':', $secrets );
3871
3872
			$site_icon = ( function_exists( 'has_site_icon') && has_site_icon() )
3873
				? get_site_icon_url()
3874
				: false;
3875
3876
			/**
3877
			 * Filter the type of authorization.
3878
			 * 'calypso' completes authorization on wordpress.com/jetpack/connect
3879
			 * while 'jetpack' ( or any other value ) completes the authorization at jetpack.wordpress.com.
3880
			 *
3881
			 * @since 4.3.3
3882
			 *
3883
			 * @param string $auth_type Defaults to 'calypso', can also be 'jetpack'.
3884
			 */
3885
			$auth_type = apply_filters( 'jetpack_auth_type', 'calypso' );
3886
3887
			$args = urlencode_deep(
3888
				array(
3889
					'response_type' => 'code',
3890
					'client_id'     => Jetpack_Options::get_option( 'id' ),
3891
					'redirect_uri'  => add_query_arg(
3892
						array(
3893
							'action'   => 'authorize',
3894
							'_wpnonce' => wp_create_nonce( "jetpack-authorize_{$role}_{$redirect}" ),
3895
							'redirect' => urlencode( $redirect ),
3896
						),
3897
						esc_url( admin_url( 'admin.php?page=jetpack' ) )
3898
					),
3899
					'state'         => $user->ID,
3900
					'scope'         => $signed_role,
3901
					'user_email'    => $user->user_email,
3902
					'user_login'    => $user->user_login,
3903
					'is_active'     => Jetpack::is_active(),
3904
					'jp_version'    => JETPACK__VERSION,
3905
					'auth_type'     => $auth_type,
3906
					'secret'        => $secret,
3907
					'locale'        => isset( $gp_locale->slug ) ? $gp_locale->slug : '',
3908
					'blogname'      => get_option( 'blogname' ),
3909
					'site_url'      => site_url(),
3910
					'home_url'      => home_url(),
3911
					'site_icon'     => $site_icon,
3912
				)
3913
			);
3914
3915
			$url = add_query_arg( $args, Jetpack::api_url( 'authorize' ) );
3916
		}
3917
3918
		if ( $from ) {
3919
			$url = add_query_arg( 'from', $from, $url );
3920
		}
3921
3922
		if ( isset( $_GET['calypso_env'] ) ) {
3923
			$url = add_query_arg( 'calypso_env', sanitize_key( $_GET['calypso_env'] ), $url );
3924
		}
3925
3926
		return $raw ? $url : esc_url( $url );
3927
	}
3928
3929
	function build_reconnect_url( $raw = false ) {
3930
		$url = wp_nonce_url( Jetpack::admin_url( 'action=reconnect' ), 'jetpack-reconnect' );
3931
		return $raw ? $url : esc_url( $url );
3932
	}
3933
3934
	public static function admin_url( $args = null ) {
3935
		$args = wp_parse_args( $args, array( 'page' => 'jetpack' ) );
3936
		$url = add_query_arg( $args, admin_url( 'admin.php' ) );
3937
		return $url;
3938
	}
3939
3940
	public static function nonce_url_no_esc( $actionurl, $action = -1, $name = '_wpnonce' ) {
3941
		$actionurl = str_replace( '&amp;', '&', $actionurl );
3942
		return add_query_arg( $name, wp_create_nonce( $action ), $actionurl );
3943
	}
3944
3945
	function dismiss_jetpack_notice() {
3946
3947
		if ( ! isset( $_GET['jetpack-notice'] ) ) {
3948
			return;
3949
		}
3950
3951
		switch( $_GET['jetpack-notice'] ) {
3952
			case 'dismiss':
3953
				if ( check_admin_referer( 'jetpack-deactivate' ) && ! is_plugin_active_for_network( plugin_basename( JETPACK__PLUGIN_DIR . 'jetpack.php' ) ) ) {
3954
3955
					require_once ABSPATH . 'wp-admin/includes/plugin.php';
3956
					deactivate_plugins( JETPACK__PLUGIN_DIR . 'jetpack.php', false, false );
3957
					wp_safe_redirect( admin_url() . 'plugins.php?deactivate=true&plugin_status=all&paged=1&s=' );
3958
				}
3959
				break;
3960 View Code Duplication
			case 'jetpack-manage-opt-out':
3961
3962
				if ( check_admin_referer( 'jetpack_manage_banner_opt_out' ) ) {
3963
					// Don't show the banner again
3964
3965
					Jetpack_Options::update_option( 'dismissed_manage_banner', true );
3966
					// redirect back to the page that had the notice
3967
					if ( wp_get_referer() ) {
3968
						wp_safe_redirect( wp_get_referer() );
3969
					} else {
3970
						// Take me to Jetpack
3971
						wp_safe_redirect( admin_url( 'admin.php?page=jetpack' ) );
3972
					}
3973
				}
3974
				break;
3975 View Code Duplication
			case 'jetpack-protect-multisite-opt-out':
3976
3977
				if ( check_admin_referer( 'jetpack_protect_multisite_banner_opt_out' ) ) {
3978
					// Don't show the banner again
3979
3980
					update_site_option( 'jetpack_dismissed_protect_multisite_banner', true );
3981
					// redirect back to the page that had the notice
3982
					if ( wp_get_referer() ) {
3983
						wp_safe_redirect( wp_get_referer() );
3984
					} else {
3985
						// Take me to Jetpack
3986
						wp_safe_redirect( admin_url( 'admin.php?page=jetpack' ) );
3987
					}
3988
				}
3989
				break;
3990
			case 'jetpack-manage-opt-in':
3991
				if ( check_admin_referer( 'jetpack_manage_banner_opt_in' ) ) {
3992
					// This makes sure that we are redirect to jetpack home so that we can see the Success Message.
3993
3994
					$redirection_url = Jetpack::admin_url();
3995
					remove_action( 'jetpack_pre_activate_module',   array( Jetpack_Admin::init(), 'fix_redirect' ) );
3996
3997
					// Don't redirect form the Jetpack Setting Page
3998
					$referer_parsed = parse_url ( wp_get_referer() );
3999
					// check that we do have a wp_get_referer and the query paramater is set orderwise go to the Jetpack Home
4000
					if ( isset( $referer_parsed['query'] ) && false !== strpos( $referer_parsed['query'], 'page=jetpack_modules' ) ) {
4001
						// Take the user to Jetpack home except when on the setting page
4002
						$redirection_url = wp_get_referer();
4003
						add_action( 'jetpack_pre_activate_module',   array( Jetpack_Admin::init(), 'fix_redirect' ) );
4004
					}
4005
					// Also update the JSON API FULL MANAGEMENT Option
4006
					Jetpack::activate_module( 'manage', false, false );
4007
4008
					// Special Message when option in.
4009
					Jetpack::state( 'optin-manage', 'true' );
4010
					// Activate the Module if not activated already
4011
4012
					// Redirect properly
4013
					wp_safe_redirect( $redirection_url );
4014
4015
				}
4016
				break;
4017
		}
4018
	}
4019
4020
	function debugger_page() {
4021
		nocache_headers();
4022
		if ( ! current_user_can( 'manage_options' ) ) {
4023
			die( '-1' );
4024
		}
4025
		Jetpack_Debugger::jetpack_debug_display_handler();
4026
		exit;
4027
	}
4028
4029
	public static function admin_screen_configure_module( $module_id ) {
4030
4031
		// User that doesn't have 'jetpack_configure_modules' will never end up here since Jetpack Landing Page woun't let them.
4032
		if ( ! in_array( $module_id, Jetpack::get_active_modules() ) && current_user_can( 'manage_options' ) ) {
4033
			if ( has_action( 'display_activate_module_setting_' . $module_id ) ) {
4034
				/**
4035
				 * Fires to diplay a custom module activation screen.
4036
				 *
4037
				 * To add a module actionation screen use Jetpack::module_configuration_activation_screen method.
4038
				 * Example: Jetpack::module_configuration_activation_screen( 'manage', array( $this, 'manage_activate_screen' ) );
4039
				 *
4040
				 * @module manage
4041
				 *
4042
				 * @since 3.8.0
4043
				 *
4044
				 * @param int $module_id Module ID.
4045
				 */
4046
				do_action( 'display_activate_module_setting_' . $module_id );
4047
			} else {
4048
				self::display_activate_module_link( $module_id );
4049
			}
4050
4051
			return false;
4052
		} ?>
4053
4054
		<div id="jp-settings-screen" style="position: relative">
4055
			<h3>
4056
			<?php
4057
				$module = Jetpack::get_module( $module_id );
4058
				echo '<a href="' . Jetpack::admin_url( 'page=jetpack_modules' ) . '">' . __( 'Jetpack by WordPress.com', 'jetpack' ) . '</a> &rarr; ';
4059
				printf( __( 'Configure %s', 'jetpack' ), $module['name'] );
4060
			?>
4061
			</h3>
4062
			<?php
4063
				/**
4064
				 * Fires within the displayed message when a feature configuation is updated.
4065
				 *
4066
				 * @since 3.4.0
4067
				 *
4068
				 * @param int $module_id Module ID.
4069
				 */
4070
				do_action( 'jetpack_notices_update_settings', $module_id );
4071
				/**
4072
				 * Fires when a feature configuation screen is loaded.
4073
				 * The dynamic part of the hook, $module_id, is the module ID.
4074
				 *
4075
				 * @since 1.1.0
4076
				 */
4077
				do_action( 'jetpack_module_configuration_screen_' . $module_id );
4078
			?>
4079
		</div><?php
4080
	}
4081
4082
	/**
4083
	 * Display link to activate the module to see the settings screen.
4084
	 * @param  string $module_id
4085
	 * @return null
4086
	 */
4087
	public static function display_activate_module_link( $module_id ) {
4088
4089
		$info =  Jetpack::get_module( $module_id );
4090
		$extra = '';
4091
		$activate_url = wp_nonce_url(
4092
				Jetpack::admin_url(
4093
					array(
4094
						'page'   => 'jetpack',
4095
						'action' => 'activate',
4096
						'module' => $module_id,
4097
					)
4098
				),
4099
				"jetpack_activate-$module_id"
4100
			);
4101
4102
		?>
4103
4104
		<div class="wrap configure-module">
4105
			<div id="jp-settings-screen">
4106
				<?php
4107
				if ( $module_id == 'json-api' ) {
4108
4109
					$info['name'] = esc_html__( 'Activate Site Management and JSON API', 'jetpack' );
4110
4111
					$activate_url = Jetpack::init()->opt_in_jetpack_manage_url();
4112
4113
					$info['description'] = sprintf( __( 'Manage your multiple Jetpack sites from our centralized dashboard at wordpress.com/sites. <a href="%s" target="_blank">Learn more</a>.', 'jetpack' ), 'https://jetpack.com/support/site-management' );
4114
4115
					// $extra = __( 'To use Site Management, you need to first activate JSON API to allow remote management of your site. ', 'jetpack' );
4116
				} ?>
4117
4118
				<h3><?php echo esc_html( $info['name'] ); ?></h3>
4119
				<div class="narrow">
4120
					<p><?php echo  $info['description']; ?></p>
4121
					<?php if( $extra ) { ?>
4122
					<p><?php echo esc_html( $extra ); ?></p>
4123
					<?php } ?>
4124
					<p>
4125
						<?php
4126
						if( wp_get_referer() ) {
4127
							printf( __( '<a class="button-primary" href="%s">Activate Now</a> or <a href="%s" >return to previous page</a>.', 'jetpack' ) , $activate_url, wp_get_referer() );
4128
						} else {
4129
							printf( __( '<a class="button-primary" href="%s">Activate Now</a>', 'jetpack' ) , $activate_url  );
4130
						} ?>
4131
					</p>
4132
				</div>
4133
4134
			</div>
4135
		</div>
4136
4137
		<?php
4138
	}
4139
4140
	public static function sort_modules( $a, $b ) {
4141
		if ( $a['sort'] == $b['sort'] )
4142
			return 0;
4143
4144
		return ( $a['sort'] < $b['sort'] ) ? -1 : 1;
4145
	}
4146
4147
	function ajax_recheck_ssl() {
4148
		check_ajax_referer( 'recheck-ssl', 'ajax-nonce' );
4149
		$result = Jetpack::permit_ssl( true );
4150
		wp_send_json( array(
4151
			'enabled' => $result,
4152
			'message' => get_transient( 'jetpack_https_test_message' )
4153
		) );
4154
	}
4155
4156
/* Client API */
4157
4158
	/**
4159
	 * Returns the requested Jetpack API URL
4160
	 *
4161
	 * @return string
4162
	 */
4163
	public static function api_url( $relative_url ) {
4164
		return trailingslashit( JETPACK__API_BASE . $relative_url  ) . JETPACK__API_VERSION . '/';
4165
	}
4166
4167
	/**
4168
	 * Some hosts disable the OpenSSL extension and so cannot make outgoing HTTPS requsets
4169
	 */
4170
	public static function fix_url_for_bad_hosts( $url ) {
4171
		if ( 0 !== strpos( $url, 'https://' ) ) {
4172
			return $url;
4173
		}
4174
4175
		switch ( JETPACK_CLIENT__HTTPS ) {
4176
			case 'ALWAYS' :
4177
				return $url;
4178
			case 'NEVER' :
4179
				return set_url_scheme( $url, 'http' );
4180
			// default : case 'AUTO' :
4181
		}
4182
4183
		// we now return the unmodified SSL URL by default, as a security precaution
4184
		return $url;
4185
	}
4186
4187
	/**
4188
	 * Checks to see if the URL is using SSL to connect with Jetpack
4189
	 *
4190
	 * @since 2.3.3
4191
	 * @return boolean
4192
	 */
4193
	public static function permit_ssl( $force_recheck = false ) {
4194
		// Do some fancy tests to see if ssl is being supported
4195
		if ( $force_recheck || false === ( $ssl = get_transient( 'jetpack_https_test' ) ) ) {
4196
			$message = '';
4197
			if ( 'https' !== substr( JETPACK__API_BASE, 0, 5 ) ) {
4198
				$ssl = 0;
4199
			} else {
4200
				switch ( JETPACK_CLIENT__HTTPS ) {
4201
					case 'NEVER':
4202
						$ssl = 0;
4203
						$message = __( 'JETPACK_CLIENT__HTTPS is set to NEVER', 'jetpack' );
4204
						break;
4205
					case 'ALWAYS':
4206
					case 'AUTO':
4207
					default:
4208
						$ssl = 1;
4209
						break;
4210
				}
4211
4212
				// If it's not 'NEVER', test to see
4213
				if ( $ssl ) {
4214
					if ( ! wp_http_supports( array( 'ssl' => true ) ) ) {
4215
						$ssl = 0;
4216
						$message = __( 'WordPress reports no SSL support', 'jetpack' );
4217
					} else {
4218
						$response = wp_remote_get( JETPACK__API_BASE . 'test/1/' );
4219
						if ( is_wp_error( $response ) ) {
4220
							$ssl = 0;
4221
							$message = __( 'WordPress reports no SSL support', 'jetpack' );
4222
						} elseif ( 'OK' !== wp_remote_retrieve_body( $response ) ) {
4223
							$ssl = 0;
4224
							$message = __( 'Response was not OK: ', 'jetpack' ) . wp_remote_retrieve_body( $response );
4225
						}
4226
					}
4227
				}
4228
			}
4229
			set_transient( 'jetpack_https_test', $ssl, DAY_IN_SECONDS );
4230
			set_transient( 'jetpack_https_test_message', $message, DAY_IN_SECONDS );
4231
		}
4232
4233
		return (bool) $ssl;
4234
	}
4235
4236
	/*
4237
	 * Displays an admin_notice, alerting the user to their JETPACK_CLIENT__HTTPS constant being 'AUTO' but SSL isn't working.
4238
	 */
4239
	public function alert_auto_ssl_fail() {
4240
		if ( ! current_user_can( 'manage_options' ) )
4241
			return;
4242
4243
		$ajax_nonce = wp_create_nonce( 'recheck-ssl' );
4244
		?>
4245
4246
		<div id="jetpack-ssl-warning" class="error jp-identity-crisis">
4247
			<div class="jp-banner__content">
4248
				<h2><?php _e( 'Outbound HTTPS not working', 'jetpack' ); ?></h2>
4249
				<p><?php _e( 'Your site could not connect to WordPress.com via HTTPS. This could be due to any number of reasons, including faulty SSL certificates, misconfigured or missing SSL libraries, or network issues.', 'jetpack' ); ?></p>
4250
				<p>
4251
					<?php _e( 'Jetpack will re-test for HTTPS support once a day, but you can click here to try again immediately: ', 'jetpack' ); ?>
4252
					<a href="#" id="jetpack-recheck-ssl-button"><?php _e( 'Try again', 'jetpack' ); ?></a>
4253
					<span id="jetpack-recheck-ssl-output"><?php echo get_transient( 'jetpack_https_test_message' ); ?></span>
4254
				</p>
4255
				<p>
4256
					<?php printf( __( 'For more help, try our <a href="%1$s">connection debugger</a> or <a href="%2$s" target="_blank">troubleshooting tips</a>.', 'jetpack' ),
4257
							esc_url( Jetpack::admin_url( array( 'page' => 'jetpack-debugger' )  ) ),
4258
							esc_url( 'https://jetpack.com/support/getting-started-with-jetpack/troubleshooting-tips/' ) ); ?>
4259
				</p>
4260
			</div>
4261
		</div>
4262
		<style>
4263
			#jetpack-recheck-ssl-output { margin-left: 5px; color: red; }
4264
		</style>
4265
		<script type="text/javascript">
4266
			jQuery( document ).ready( function( $ ) {
4267
				$( '#jetpack-recheck-ssl-button' ).click( function( e ) {
4268
					var $this = $( this );
4269
					$this.html( <?php echo json_encode( __( 'Checking', 'jetpack' ) ); ?> );
4270
					$( '#jetpack-recheck-ssl-output' ).html( '' );
4271
					e.preventDefault();
4272
					var data = { action: 'jetpack-recheck-ssl', 'ajax-nonce': '<?php echo $ajax_nonce; ?>' };
4273
					$.post( ajaxurl, data )
4274
					  .done( function( response ) {
4275
					  	if ( response.enabled ) {
4276
					  		$( '#jetpack-ssl-warning' ).hide();
4277
					  	} else {
4278
					  		this.html( <?php echo json_encode( __( 'Try again', 'jetpack' ) ); ?> );
4279
					  		$( '#jetpack-recheck-ssl-output' ).html( 'SSL Failed: ' + response.message );
4280
					  	}
4281
					  }.bind( $this ) );
4282
				} );
4283
			} );
4284
		</script>
4285
4286
		<?php
4287
	}
4288
4289
	/**
4290
	 * Returns the Jetpack XML-RPC API
4291
	 *
4292
	 * @return string
4293
	 */
4294
	public static function xmlrpc_api_url() {
4295
		$base = preg_replace( '#(https?://[^?/]+)(/?.*)?$#', '\\1', JETPACK__API_BASE );
4296
		return untrailingslashit( $base ) . '/xmlrpc.php';
4297
	}
4298
4299
	/**
4300
	 * Creates two secret tokens and the end of life timestamp for them.
4301
	 *
4302
	 * Note these tokens are unique per call, NOT static per site for connecting.
4303
	 *
4304
	 * @since 2.6
4305
	 * @return array
4306
	 */
4307
	public function generate_secrets( $action, $exp = 600 ) {
4308
	    $secret = wp_generate_password( 32, false ) // secret_1
4309
	    		. ':' . wp_generate_password( 32, false ) // secret_2
4310
	    		. ':' . ( time() + $exp ) // eol ( End of Life )
4311
	    		. ':' . get_current_user_id(); // ties the secrets to the current user
4312
		Jetpack_Options::update_option( $action, $secret );
4313
	    return Jetpack_Options::get_option( $action );
4314
	}
4315
4316
	/**
4317
	 * Builds the timeout limit for queries talking with the wpcom servers.
4318
	 *
4319
	 * Based on local php max_execution_time in php.ini
4320
	 *
4321
	 * @since 2.6
4322
	 * @return int
4323
	 **/
4324
	public function get_remote_query_timeout_limit() {
4325
	    $timeout = (int) ini_get( 'max_execution_time' );
4326
	    if ( ! $timeout ) // Ensure exec time set in php.ini
4327
		$timeout = 30;
4328
	    return intval( $timeout / 2 );
4329
	}
4330
4331
4332
	/**
4333
	 * Takes the response from the Jetpack register new site endpoint and
4334
	 * verifies it worked properly.
4335
	 *
4336
	 * @since 2.6
4337
	 * @return true or Jetpack_Error
4338
	 **/
4339
	public function validate_remote_register_response( $response ) {
4340
	    	if ( is_wp_error( $response ) ) {
4341
			return new Jetpack_Error( 'register_http_request_failed', $response->get_error_message() );
4342
		}
4343
4344
		$code   = wp_remote_retrieve_response_code( $response );
4345
		$entity = wp_remote_retrieve_body( $response );
4346
		if ( $entity )
4347
			$json = json_decode( $entity );
4348
		else
4349
			$json = false;
4350
4351
		$code_type = intval( $code / 100 );
4352
		if ( 5 == $code_type ) {
4353
			return new Jetpack_Error( 'wpcom_5??', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
4354
		} elseif ( 408 == $code ) {
4355
			return new Jetpack_Error( 'wpcom_408', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
4356
		} elseif ( ! empty( $json->error ) ) {
4357
			$error_description = isset( $json->error_description ) ? sprintf( __( 'Error Details: %s', 'jetpack' ), (string) $json->error_description ) : '';
4358
			return new Jetpack_Error( (string) $json->error, $error_description, $code );
4359
		} elseif ( 200 != $code ) {
4360
			return new Jetpack_Error( 'wpcom_bad_response', sprintf( __( 'Error Details: %s', 'jetpack' ), $code ), $code );
4361
		}
4362
4363
		// Jetpack ID error block
4364
		if ( empty( $json->jetpack_id ) ) {
4365
			return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID is empty. Do not publicly post this error message! %s', 'jetpack' ), $entity ), $entity );
4366
		} elseif ( ! is_scalar( $json->jetpack_id ) ) {
4367
			return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID is not a scalar. Do not publicly post this error message! %s', 'jetpack' ) , $entity ), $entity );
4368
		} elseif ( preg_match( '/[^0-9]/', $json->jetpack_id ) ) {
4369
			return new Jetpack_Error( 'jetpack_id', sprintf( __( 'Error Details: Jetpack ID begins with a numeral. Do not publicly post this error message! %s', 'jetpack' ) , $entity ), $entity );
4370
		}
4371
4372
	    return true;
4373
	}
4374
	/**
4375
	 * @return bool|WP_Error
4376
	 */
4377
	public static function register() {
4378
		add_action( 'pre_update_jetpack_option_register', array( 'Jetpack_Options', 'delete_option' ) );
4379
		$secrets = Jetpack::init()->generate_secrets( 'register' );
4380
4381
		@list( $secret_1, $secret_2, $secret_eol ) = explode( ':', $secrets );
4382 View Code Duplication
		if ( empty( $secret_1 ) || empty( $secret_2 ) || empty( $secret_eol ) || $secret_eol < time() ) {
4383
			return new Jetpack_Error( 'missing_secrets' );
4384
		}
4385
4386
		$timeout = Jetpack::init()->get_remote_query_timeout_limit();
4387
4388
		$gmt_offset = get_option( 'gmt_offset' );
4389
		if ( ! $gmt_offset ) {
4390
			$gmt_offset = 0;
4391
		}
4392
4393
		$stats_options = get_option( 'stats_options' );
4394
		$stats_id = isset($stats_options['blog_id']) ? $stats_options['blog_id'] : null;
4395
4396
		$args = array(
4397
			'method'  => 'POST',
4398
			'body'    => array(
4399
				'siteurl'         => site_url(),
4400
				'home'            => home_url(),
4401
				'gmt_offset'      => $gmt_offset,
4402
				'timezone_string' => (string) get_option( 'timezone_string' ),
4403
				'site_name'       => (string) get_option( 'blogname' ),
4404
				'secret_1'        => $secret_1,
4405
				'secret_2'        => $secret_2,
4406
				'site_lang'       => get_locale(),
4407
				'timeout'         => $timeout,
4408
				'stats_id'        => $stats_id,
4409
				'state'           => get_current_user_id(),
4410
			),
4411
			'headers' => array(
4412
				'Accept' => 'application/json',
4413
			),
4414
			'timeout' => $timeout,
4415
		);
4416
		$response = Jetpack_Client::_wp_remote_request( Jetpack::fix_url_for_bad_hosts( Jetpack::api_url( 'register' ) ), $args, true );
4417
4418
4419
		// Make sure the response is valid and does not contain any Jetpack errors
4420
		$valid_response = Jetpack::init()->validate_remote_register_response( $response );
4421
		if( is_wp_error( $valid_response ) || !$valid_response ) {
4422
		    return $valid_response;
4423
		}
4424
4425
		// Grab the response values to work with
4426
		$code   = wp_remote_retrieve_response_code( $response );
4427
		$entity = wp_remote_retrieve_body( $response );
4428
4429
		if ( $entity )
4430
			$json = json_decode( $entity );
4431
		else
4432
			$json = false;
4433
4434 View Code Duplication
		if ( empty( $json->jetpack_secret ) || ! is_string( $json->jetpack_secret ) )
4435
			return new Jetpack_Error( 'jetpack_secret', '', $code );
4436
4437
		if ( isset( $json->jetpack_public ) ) {
4438
			$jetpack_public = (int) $json->jetpack_public;
4439
		} else {
4440
			$jetpack_public = false;
4441
		}
4442
4443
		Jetpack_Options::update_options(
4444
			array(
4445
				'id'         => (int)    $json->jetpack_id,
4446
				'blog_token' => (string) $json->jetpack_secret,
4447
				'public'     => $jetpack_public,
4448
			)
4449
		);
4450
4451
		/**
4452
		 * Fires when a site is registered on WordPress.com.
4453
		 *
4454
		 * @since 3.7.0
4455
		 *
4456
		 * @param int $json->jetpack_id Jetpack Blog ID.
4457
		 * @param string $json->jetpack_secret Jetpack Blog Token.
4458
		 * @param int|bool $jetpack_public Is the site public.
4459
		 */
4460
		do_action( 'jetpack_site_registered', $json->jetpack_id, $json->jetpack_secret, $jetpack_public );
4461
4462
		// Initialize Jump Start for the first and only time.
4463
		if ( ! Jetpack_Options::get_option( 'jumpstart' ) ) {
4464
			Jetpack_Options::update_option( 'jumpstart', 'new_connection' );
4465
4466
			$jetpack = Jetpack::init();
4467
4468
			$jetpack->stat( 'jumpstart', 'unique-views' );
4469
			$jetpack->do_stats( 'server_side' );
4470
		};
4471
4472
		return true;
4473
	}
4474
4475
	/**
4476
	 * If the db version is showing something other that what we've got now, bump it to current.
4477
	 *
4478
	 * @return bool: True if the option was incorrect and updated, false if nothing happened.
4479
	 */
4480
	public static function maybe_set_version_option() {
4481
		list( $version ) = explode( ':', Jetpack_Options::get_option( 'version' ) );
4482
		if ( JETPACK__VERSION != $version ) {
4483
			Jetpack_Options::update_option( 'version', JETPACK__VERSION . ':' . time() );
4484
4485
			if ( version_compare( JETPACK__VERSION, $version, '>' ) ) {
4486
				/** This action is documented in class.jetpack.php */
4487
				do_action( 'updating_jetpack_version', JETPACK__VERSION, $version );
4488
			}
4489
4490
			return true;
4491
		}
4492
		return false;
4493
	}
4494
4495
/* Client Server API */
4496
4497
	/**
4498
	 * Loads the Jetpack XML-RPC client
4499
	 */
4500
	public static function load_xml_rpc_client() {
4501
		require_once ABSPATH . WPINC . '/class-IXR.php';
4502
		require_once JETPACK__PLUGIN_DIR . 'class.jetpack-ixr-client.php';
4503
	}
4504
4505
	function verify_xml_rpc_signature() {
4506
		if ( $this->xmlrpc_verification ) {
4507
			return $this->xmlrpc_verification;
4508
		}
4509
4510
		// It's not for us
4511
		if ( ! isset( $_GET['token'] ) || empty( $_GET['signature'] ) ) {
4512
			return false;
4513
		}
4514
4515
		@list( $token_key, $version, $user_id ) = explode( ':', $_GET['token'] );
4516
		if (
4517
			empty( $token_key )
4518
		||
4519
			empty( $version ) || strval( JETPACK__API_VERSION ) !== $version
4520
		) {
4521
			return false;
4522
		}
4523
4524
		if ( '0' === $user_id ) {
4525
			$token_type = 'blog';
4526
			$user_id = 0;
4527
		} else {
4528
			$token_type = 'user';
4529
			if ( empty( $user_id ) || ! ctype_digit( $user_id ) ) {
4530
				return false;
4531
			}
4532
			$user_id = (int) $user_id;
4533
4534
			$user = new WP_User( $user_id );
4535
			if ( ! $user || ! $user->exists() ) {
4536
				return false;
4537
			}
4538
		}
4539
4540
		$token = Jetpack_Data::get_access_token( $user_id );
4541
		if ( ! $token ) {
4542
			return false;
4543
		}
4544
4545
		$token_check = "$token_key.";
4546
		if ( ! hash_equals( substr( $token->secret, 0, strlen( $token_check ) ), $token_check ) ) {
4547
			return false;
4548
		}
4549
4550
		require_once JETPACK__PLUGIN_DIR . 'class.jetpack-signature.php';
4551
4552
		$jetpack_signature = new Jetpack_Signature( $token->secret, (int) Jetpack_Options::get_option( 'time_diff' ) );
4553
		if ( isset( $_POST['_jetpack_is_multipart'] ) ) {
4554
			$post_data   = $_POST;
4555
			$file_hashes = array();
4556
			foreach ( $post_data as $post_data_key => $post_data_value ) {
4557
				if ( 0 !== strpos( $post_data_key, '_jetpack_file_hmac_' ) ) {
4558
					continue;
4559
				}
4560
				$post_data_key = substr( $post_data_key, strlen( '_jetpack_file_hmac_' ) );
4561
				$file_hashes[$post_data_key] = $post_data_value;
4562
			}
4563
4564
			foreach ( $file_hashes as $post_data_key => $post_data_value ) {
4565
				unset( $post_data["_jetpack_file_hmac_{$post_data_key}"] );
4566
				$post_data[$post_data_key] = $post_data_value;
4567
			}
4568
4569
			ksort( $post_data );
4570
4571
			$body = http_build_query( stripslashes_deep( $post_data ) );
4572
		} elseif ( is_null( $this->HTTP_RAW_POST_DATA ) ) {
4573
			$body = file_get_contents( 'php://input' );
4574
		} else {
4575
			$body = null;
4576
		}
4577
		$signature = $jetpack_signature->sign_current_request(
4578
			array( 'body' => is_null( $body ) ? $this->HTTP_RAW_POST_DATA : $body, )
4579
		);
4580
4581
		if ( ! $signature ) {
4582
			return false;
4583
		} else if ( is_wp_error( $signature ) ) {
4584
			return $signature;
4585
		} else if ( ! hash_equals( $signature, $_GET['signature'] ) ) {
4586
			return false;
4587
		}
4588
4589
		$timestamp = (int) $_GET['timestamp'];
4590
		$nonce     = stripslashes( (string) $_GET['nonce'] );
4591
4592
		if ( ! $this->add_nonce( $timestamp, $nonce ) ) {
4593
			return false;
4594
		}
4595
4596
		$this->xmlrpc_verification = array(
4597
			'type'    => $token_type,
4598
			'user_id' => $token->external_user_id,
4599
		);
4600
4601
		return $this->xmlrpc_verification;
4602
	}
4603
4604
	/**
4605
	 * Authenticates XML-RPC and other requests from the Jetpack Server
4606
	 */
4607
	function authenticate_jetpack( $user, $username, $password ) {
4608
		if ( is_a( $user, 'WP_User' ) ) {
4609
			return $user;
4610
		}
4611
4612
		$token_details = $this->verify_xml_rpc_signature();
4613
4614
		if ( ! $token_details || is_wp_error( $token_details ) ) {
4615
			return $user;
4616
		}
4617
4618
		if ( 'user' !== $token_details['type'] ) {
4619
			return $user;
4620
		}
4621
4622
		if ( ! $token_details['user_id'] ) {
4623
			return $user;
4624
		}
4625
4626
		nocache_headers();
4627
4628
		return new WP_User( $token_details['user_id'] );
4629
	}
4630
4631
	function add_nonce( $timestamp, $nonce ) {
4632
		global $wpdb;
4633
		static $nonces_used_this_request = array();
4634
4635
		if ( isset( $nonces_used_this_request["$timestamp:$nonce"] ) ) {
4636
			return $nonces_used_this_request["$timestamp:$nonce"];
4637
		}
4638
4639
		// This should always have gone through Jetpack_Signature::sign_request() first to check $timestamp an $nonce
4640
		$timestamp = (int) $timestamp;
4641
		$nonce     = esc_sql( $nonce );
4642
4643
		// Raw query so we can avoid races: add_option will also update
4644
		$show_errors = $wpdb->show_errors( false );
4645
4646
		$old_nonce = $wpdb->get_row(
4647
			$wpdb->prepare( "SELECT * FROM `$wpdb->options` WHERE option_name = %s", "jetpack_nonce_{$timestamp}_{$nonce}" )
4648
		);
4649
4650
		if ( is_null( $old_nonce ) ) {
4651
			$return = $wpdb->query(
4652
				$wpdb->prepare(
4653
					"INSERT INTO `$wpdb->options` (`option_name`, `option_value`, `autoload`) VALUES (%s, %s, %s)",
4654
					"jetpack_nonce_{$timestamp}_{$nonce}",
4655
					time(),
4656
					'no'
4657
				)
4658
			);
4659
		} else {
4660
			$return = false;
4661
		}
4662
4663
		$wpdb->show_errors( $show_errors );
4664
4665
		$nonces_used_this_request["$timestamp:$nonce"] = $return;
4666
4667
		return $return;
4668
	}
4669
4670
	/**
4671
	 * In some setups, $HTTP_RAW_POST_DATA can be emptied during some IXR_Server paths since it is passed by reference to various methods.
4672
	 * Capture it here so we can verify the signature later.
4673
	 */
4674
	function xmlrpc_methods( $methods ) {
4675
		$this->HTTP_RAW_POST_DATA = $GLOBALS['HTTP_RAW_POST_DATA'];
4676
		return $methods;
4677
	}
4678
4679
	function public_xmlrpc_methods( $methods ) {
4680
		if ( array_key_exists( 'wp.getOptions', $methods ) ) {
4681
			$methods['wp.getOptions'] = array( $this, 'jetpack_getOptions' );
4682
		}
4683
		return $methods;
4684
	}
4685
4686
	function jetpack_getOptions( $args ) {
4687
		global $wp_xmlrpc_server;
4688
4689
		$wp_xmlrpc_server->escape( $args );
4690
4691
		$username	= $args[1];
4692
		$password	= $args[2];
4693
4694
		if ( !$user = $wp_xmlrpc_server->login($username, $password) ) {
4695
			return $wp_xmlrpc_server->error;
4696
		}
4697
4698
		$options = array();
4699
		$user_data = $this->get_connected_user_data();
4700
		if ( is_array( $user_data ) ) {
4701
			$options['jetpack_user_id'] = array(
4702
				'desc'          => __( 'The WP.com user ID of the connected user', 'jetpack' ),
4703
				'readonly'      => true,
4704
				'value'         => $user_data['ID'],
4705
			);
4706
			$options['jetpack_user_login'] = array(
4707
				'desc'          => __( 'The WP.com username of the connected user', 'jetpack' ),
4708
				'readonly'      => true,
4709
				'value'         => $user_data['login'],
4710
			);
4711
			$options['jetpack_user_email'] = array(
4712
				'desc'          => __( 'The WP.com user email of the connected user', 'jetpack' ),
4713
				'readonly'      => true,
4714
				'value'         => $user_data['email'],
4715
			);
4716
			$options['jetpack_user_site_count'] = array(
4717
				'desc'          => __( 'The number of sites of the connected WP.com user', 'jetpack' ),
4718
				'readonly'      => true,
4719
				'value'         => $user_data['site_count'],
4720
			);
4721
		}
4722
		$wp_xmlrpc_server->blog_options = array_merge( $wp_xmlrpc_server->blog_options, $options );
4723
		$args = stripslashes_deep( $args );
4724
		return $wp_xmlrpc_server->wp_getOptions( $args );
4725
	}
4726
4727
	function xmlrpc_options( $options ) {
4728
		$jetpack_client_id = false;
4729
		if ( self::is_active() ) {
4730
			$jetpack_client_id = Jetpack_Options::get_option( 'id' );
4731
		}
4732
		$options['jetpack_version'] = array(
4733
				'desc'          => __( 'Jetpack Plugin Version', 'jetpack' ),
4734
				'readonly'      => true,
4735
				'value'         => JETPACK__VERSION,
4736
		);
4737
4738
		$options['jetpack_client_id'] = array(
4739
				'desc'          => __( 'The Client ID/WP.com Blog ID of this site', 'jetpack' ),
4740
				'readonly'      => true,
4741
				'value'         => $jetpack_client_id,
4742
		);
4743
		return $options;
4744
	}
4745
4746
	public static function clean_nonces( $all = false ) {
4747
		global $wpdb;
4748
4749
		$sql = "DELETE FROM `$wpdb->options` WHERE `option_name` LIKE %s";
4750
		$sql_args = array( $wpdb->esc_like( 'jetpack_nonce_' ) . '%' );
4751
4752
		if ( true !== $all ) {
4753
			$sql .= ' AND CAST( `option_value` AS UNSIGNED ) < %d';
4754
			$sql_args[] = time() - 3600;
4755
		}
4756
4757
		$sql .= ' ORDER BY `option_id` LIMIT 100';
4758
4759
		$sql = $wpdb->prepare( $sql, $sql_args );
4760
4761
		for ( $i = 0; $i < 1000; $i++ ) {
4762
			if ( ! $wpdb->query( $sql ) ) {
4763
				break;
4764
			}
4765
		}
4766
	}
4767
4768
	/**
4769
	 * State is passed via cookies from one request to the next, but never to subsequent requests.
4770
	 * SET: state( $key, $value );
4771
	 * GET: $value = state( $key );
4772
	 *
4773
	 * @param string $key
4774
	 * @param string $value
4775
	 * @param bool $restate private
4776
	 */
4777
	public static function state( $key = null, $value = null, $restate = false ) {
4778
		static $state = array();
4779
		static $path, $domain;
4780
		if ( ! isset( $path ) ) {
4781
			require_once( ABSPATH . 'wp-admin/includes/plugin.php' );
4782
			$admin_url = Jetpack::admin_url();
4783
			$bits      = parse_url( $admin_url );
4784
4785
			if ( is_array( $bits ) ) {
4786
				$path   = ( isset( $bits['path'] ) ) ? dirname( $bits['path'] ) : null;
4787
				$domain = ( isset( $bits['host'] ) ) ? $bits['host'] : null;
4788
			} else {
4789
				$path = $domain = null;
4790
			}
4791
		}
4792
4793
		// Extract state from cookies and delete cookies
4794
		if ( isset( $_COOKIE[ 'jetpackState' ] ) && is_array( $_COOKIE[ 'jetpackState' ] ) ) {
4795
			$yum = $_COOKIE[ 'jetpackState' ];
4796
			unset( $_COOKIE[ 'jetpackState' ] );
4797
			foreach ( $yum as $k => $v ) {
4798
				if ( strlen( $v ) )
4799
					$state[ $k ] = $v;
4800
				setcookie( "jetpackState[$k]", false, 0, $path, $domain );
4801
			}
4802
		}
4803
4804
		if ( $restate ) {
4805
			foreach ( $state as $k => $v ) {
4806
				setcookie( "jetpackState[$k]", $v, 0, $path, $domain );
4807
			}
4808
			return;
4809
		}
4810
4811
		// Get a state variable
4812
		if ( isset( $key ) && ! isset( $value ) ) {
4813
			if ( array_key_exists( $key, $state ) )
4814
				return $state[ $key ];
4815
			return null;
4816
		}
4817
4818
		// Set a state variable
4819
		if ( isset ( $key ) && isset( $value ) ) {
4820
			if( is_array( $value ) && isset( $value[0] ) ) {
4821
				$value = $value[0];
4822
			}
4823
			$state[ $key ] = $value;
4824
			setcookie( "jetpackState[$key]", $value, 0, $path, $domain );
4825
		}
4826
	}
4827
4828
	public static function restate() {
4829
		Jetpack::state( null, null, true );
4830
	}
4831
4832
	public static function check_privacy( $file ) {
4833
		static $is_site_publicly_accessible = null;
4834
4835
		if ( is_null( $is_site_publicly_accessible ) ) {
4836
			$is_site_publicly_accessible = false;
4837
4838
			Jetpack::load_xml_rpc_client();
4839
			$rpc = new Jetpack_IXR_Client();
4840
4841
			$success = $rpc->query( 'jetpack.isSitePubliclyAccessible', home_url() );
4842
			if ( $success ) {
4843
				$response = $rpc->getResponse();
4844
				if ( $response ) {
4845
					$is_site_publicly_accessible = true;
4846
				}
4847
			}
4848
4849
			Jetpack_Options::update_option( 'public', (int) $is_site_publicly_accessible );
4850
		}
4851
4852
		if ( $is_site_publicly_accessible ) {
4853
			return;
4854
		}
4855
4856
		$module_slug = self::get_module_slug( $file );
4857
4858
		$privacy_checks = Jetpack::state( 'privacy_checks' );
4859
		if ( ! $privacy_checks ) {
4860
			$privacy_checks = $module_slug;
4861
		} else {
4862
			$privacy_checks .= ",$module_slug";
4863
		}
4864
4865
		Jetpack::state( 'privacy_checks', $privacy_checks );
4866
	}
4867
4868
	/**
4869
	 * Helper method for multicall XMLRPC.
4870
	 */
4871
	public static function xmlrpc_async_call() {
4872
		global $blog_id;
4873
		static $clients = array();
4874
4875
		$client_blog_id = is_multisite() ? $blog_id : 0;
4876
4877
		if ( ! isset( $clients[$client_blog_id] ) ) {
4878
			Jetpack::load_xml_rpc_client();
4879
			$clients[$client_blog_id] = new Jetpack_IXR_ClientMulticall( array( 'user_id' => JETPACK_MASTER_USER, ) );
4880
			if ( function_exists( 'ignore_user_abort' ) ) {
4881
				ignore_user_abort( true );
4882
			}
4883
			add_action( 'shutdown', array( 'Jetpack', 'xmlrpc_async_call' ) );
4884
		}
4885
4886
		$args = func_get_args();
4887
4888
		if ( ! empty( $args[0] ) ) {
4889
			call_user_func_array( array( $clients[$client_blog_id], 'addCall' ), $args );
4890
		} elseif ( is_multisite() ) {
4891
			foreach ( $clients as $client_blog_id => $client ) {
4892
				if ( ! $client_blog_id || empty( $client->calls ) ) {
4893
					continue;
4894
				}
4895
4896
				$switch_success = switch_to_blog( $client_blog_id, true );
4897
				if ( ! $switch_success ) {
4898
					continue;
4899
				}
4900
4901
				flush();
4902
				$client->query();
4903
4904
				restore_current_blog();
4905
			}
4906
		} else {
4907
			if ( isset( $clients[0] ) && ! empty( $clients[0]->calls ) ) {
4908
				flush();
4909
				$clients[0]->query();
4910
			}
4911
		}
4912
	}
4913
4914
	public static function staticize_subdomain( $url ) {
4915
4916
		// Extract hostname from URL
4917
		$host = parse_url( $url, PHP_URL_HOST );
4918
4919
		// Explode hostname on '.'
4920
		$exploded_host = explode( '.', $host );
4921
4922
		// Retrieve the name and TLD
4923
		if ( count( $exploded_host ) > 1 ) {
4924
			$name = $exploded_host[ count( $exploded_host ) - 2 ];
4925
			$tld = $exploded_host[ count( $exploded_host ) - 1 ];
4926
			// Rebuild domain excluding subdomains
4927
			$domain = $name . '.' . $tld;
4928
		} else {
4929
			$domain = $host;
4930
		}
4931
		// Array of Automattic domains
4932
		$domain_whitelist = array( 'wordpress.com', 'wp.com' );
4933
4934
		// Return $url if not an Automattic domain
4935
		if ( ! in_array( $domain, $domain_whitelist ) ) {
4936
			return $url;
4937
		}
4938
4939
		if ( is_ssl() ) {
4940
			return preg_replace( '|https?://[^/]++/|', 'https://s-ssl.wordpress.com/', $url );
4941
		}
4942
4943
		srand( crc32( basename( $url ) ) );
4944
		$static_counter = rand( 0, 2 );
4945
		srand(); // this resets everything that relies on this, like array_rand() and shuffle()
4946
4947
		return preg_replace( '|://[^/]+?/|', "://s$static_counter.wp.com/", $url );
4948
	}
4949
4950
/* JSON API Authorization */
4951
4952
	/**
4953
	 * Handles the login action for Authorizing the JSON API
4954
	 */
4955
	function login_form_json_api_authorization() {
4956
		$this->verify_json_api_authorization_request();
4957
4958
		add_action( 'wp_login', array( &$this, 'store_json_api_authorization_token' ), 10, 2 );
4959
4960
		add_action( 'login_message', array( &$this, 'login_message_json_api_authorization' ) );
4961
		add_action( 'login_form', array( &$this, 'preserve_action_in_login_form_for_json_api_authorization' ) );
4962
		add_filter( 'site_url', array( &$this, 'post_login_form_to_signed_url' ), 10, 3 );
4963
	}
4964
4965
	// Make sure the login form is POSTed to the signed URL so we can reverify the request
4966
	function post_login_form_to_signed_url( $url, $path, $scheme ) {
4967
		if ( 'wp-login.php' !== $path || ( 'login_post' !== $scheme && 'login' !== $scheme ) ) {
4968
			return $url;
4969
		}
4970
4971
		$parsed_url = parse_url( $url );
4972
		$url = strtok( $url, '?' );
4973
		$url = "$url?{$_SERVER['QUERY_STRING']}";
4974
		if ( ! empty( $parsed_url['query'] ) )
4975
			$url .= "&{$parsed_url['query']}";
4976
4977
		return $url;
4978
	}
4979
4980
	// Make sure the POSTed request is handled by the same action
4981
	function preserve_action_in_login_form_for_json_api_authorization() {
4982
		echo "<input type='hidden' name='action' value='jetpack_json_api_authorization' />\n";
4983
		echo "<input type='hidden' name='jetpack_json_api_original_query' value='" . esc_url( set_url_scheme( $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'] ) ) . "' />\n";
4984
	}
4985
4986
	// If someone logs in to approve API access, store the Access Code in usermeta
4987
	function store_json_api_authorization_token( $user_login, $user ) {
4988
		add_filter( 'login_redirect', array( &$this, 'add_token_to_login_redirect_json_api_authorization' ), 10, 3 );
4989
		add_filter( 'allowed_redirect_hosts', array( &$this, 'allow_wpcom_public_api_domain' ) );
4990
		$token = wp_generate_password( 32, false );
4991
		update_user_meta( $user->ID, 'jetpack_json_api_' . $this->json_api_authorization_request['client_id'], $token );
4992
	}
4993
4994
	// Add public-api.wordpress.com to the safe redirect whitelist - only added when someone allows API access
4995
	function allow_wpcom_public_api_domain( $domains ) {
4996
		$domains[] = 'public-api.wordpress.com';
4997
		return $domains;
4998
	}
4999
5000
	// Add the Access Code details to the public-api.wordpress.com redirect
5001
	function add_token_to_login_redirect_json_api_authorization( $redirect_to, $original_redirect_to, $user ) {
5002
		return add_query_arg(
5003
			urlencode_deep(
5004
				array(
5005
					'jetpack-code'    => get_user_meta( $user->ID, 'jetpack_json_api_' . $this->json_api_authorization_request['client_id'], true ),
5006
					'jetpack-user-id' => (int) $user->ID,
5007
					'jetpack-state'   => $this->json_api_authorization_request['state'],
5008
				)
5009
			),
5010
			$redirect_to
5011
		);
5012
	}
5013
5014
	// Verifies the request by checking the signature
5015
	function verify_json_api_authorization_request() {
5016
		require_once JETPACK__PLUGIN_DIR . 'class.jetpack-signature.php';
5017
5018
		$token = Jetpack_Data::get_access_token( JETPACK_MASTER_USER );
5019
		if ( ! $token || empty( $token->secret ) ) {
5020
			wp_die( __( 'You must connect your Jetpack plugin to WordPress.com to use this feature.' , 'jetpack' ) );
5021
		}
5022
5023
		$die_error = __( 'Someone may be trying to trick you into giving them access to your site.  Or it could be you just encountered a bug :).  Either way, please close this window.', 'jetpack' );
5024
5025
		$jetpack_signature = new Jetpack_Signature( $token->secret, (int) Jetpack_Options::get_option( 'time_diff' ) );
5026
5027
		if ( isset( $_POST['jetpack_json_api_original_query'] ) ) {
5028
			$signature = $jetpack_signature->sign_request( $_GET['token'], $_GET['timestamp'], $_GET['nonce'], '', 'GET', $_POST['jetpack_json_api_original_query'], null, true );
5029
		} else {
5030
			$signature = $jetpack_signature->sign_current_request( array( 'body' => null, 'method' => 'GET' ) );
5031
		}
5032
5033
		if ( ! $signature ) {
5034
			wp_die( $die_error );
5035
		} else if ( is_wp_error( $signature ) ) {
5036
			wp_die( $die_error );
5037
		} else if ( ! hash_equals( $signature, $_GET['signature'] ) ) {
5038
			if ( is_ssl() ) {
5039
				// If we signed an HTTP request on the Jetpack Servers, but got redirected to HTTPS by the local blog, check the HTTP signature as well
5040
				$signature = $jetpack_signature->sign_current_request( array( 'scheme' => 'http', 'body' => null, 'method' => 'GET' ) );
5041
				if ( ! $signature || is_wp_error( $signature ) || ! hash_equals( $signature, $_GET['signature'] ) ) {
5042
					wp_die( $die_error );
5043
				}
5044
			} else {
5045
				wp_die( $die_error );
5046
			}
5047
		}
5048
5049
		$timestamp = (int) $_GET['timestamp'];
5050
		$nonce     = stripslashes( (string) $_GET['nonce'] );
5051
5052
		if ( ! $this->add_nonce( $timestamp, $nonce ) ) {
5053
			// De-nonce the nonce, at least for 5 minutes.
5054
			// We have to reuse this nonce at least once (used the first time when the initial request is made, used a second time when the login form is POSTed)
5055
			$old_nonce_time = get_option( "jetpack_nonce_{$timestamp}_{$nonce}" );
5056
			if ( $old_nonce_time < time() - 300 ) {
5057
				wp_die( __( 'The authorization process expired.  Please go back and try again.' , 'jetpack' ) );
5058
			}
5059
		}
5060
5061
		$data = json_decode( base64_decode( stripslashes( $_GET['data'] ) ) );
5062
		$data_filters = array(
5063
			'state'        => 'opaque',
5064
			'client_id'    => 'int',
5065
			'client_title' => 'string',
5066
			'client_image' => 'url',
5067
		);
5068
5069
		foreach ( $data_filters as $key => $sanitation ) {
5070
			if ( ! isset( $data->$key ) ) {
5071
				wp_die( $die_error );
5072
			}
5073
5074
			switch ( $sanitation ) {
5075
			case 'int' :
5076
				$this->json_api_authorization_request[$key] = (int) $data->$key;
5077
				break;
5078
			case 'opaque' :
5079
				$this->json_api_authorization_request[$key] = (string) $data->$key;
5080
				break;
5081
			case 'string' :
5082
				$this->json_api_authorization_request[$key] = wp_kses( (string) $data->$key, array() );
5083
				break;
5084
			case 'url' :
5085
				$this->json_api_authorization_request[$key] = esc_url_raw( (string) $data->$key );
5086
				break;
5087
			}
5088
		}
5089
5090
		if ( empty( $this->json_api_authorization_request['client_id'] ) ) {
5091
			wp_die( $die_error );
5092
		}
5093
	}
5094
5095
	function login_message_json_api_authorization( $message ) {
5096
		return '<p class="message">' . sprintf(
5097
			esc_html__( '%s wants to access your site&#8217;s data.  Log in to authorize that access.' , 'jetpack' ),
5098
			'<strong>' . esc_html( $this->json_api_authorization_request['client_title'] ) . '</strong>'
5099
		) . '<img src="' . esc_url( $this->json_api_authorization_request['client_image'] ) . '" /></p>';
5100
	}
5101
5102
	/**
5103
	 * Get $content_width, but with a <s>twist</s> filter.
5104
	 */
5105
	public static function get_content_width() {
5106
		$content_width = isset( $GLOBALS['content_width'] ) ? $GLOBALS['content_width'] : false;
5107
		/**
5108
		 * Filter the Content Width value.
5109
		 *
5110
		 * @since 2.2.3
5111
		 *
5112
		 * @param string $content_width Content Width value.
5113
		 */
5114
		return apply_filters( 'jetpack_content_width', $content_width );
5115
	}
5116
5117
	/**
5118
	 * Centralize the function here until it gets added to core.
5119
	 *
5120
	 * @param int|string|object $id_or_email A user ID,  email address, or comment object
5121
	 * @param int $size Size of the avatar image
5122
	 * @param string $default URL to a default image to use if no avatar is available
5123
	 * @param bool $force_display Whether to force it to return an avatar even if show_avatars is disabled
5124
	 *
5125
	 * @return array First element is the URL, second is the class.
5126
	 */
5127
	public static function get_avatar_url( $id_or_email, $size = 96, $default = '', $force_display = false ) {
5128
		// Don't bother adding the __return_true filter if it's already there.
5129
		$has_filter = has_filter( 'pre_option_show_avatars', '__return_true' );
5130
5131
		if ( $force_display && ! $has_filter )
5132
			add_filter( 'pre_option_show_avatars', '__return_true' );
5133
5134
		$avatar = get_avatar( $id_or_email, $size, $default );
5135
5136
		if ( $force_display && ! $has_filter )
5137
			remove_filter( 'pre_option_show_avatars', '__return_true' );
5138
5139
		// If no data, fail out.
5140
		if ( is_wp_error( $avatar ) || ! $avatar )
5141
			return array( null, null );
5142
5143
		// Pull out the URL.  If it's not there, fail out.
5144
		if ( ! preg_match( '/src=["\']([^"\']+)["\']/', $avatar, $url_matches ) )
5145
			return array( null, null );
5146
		$url = wp_specialchars_decode( $url_matches[1], ENT_QUOTES );
5147
5148
		// Pull out the class, but it's not a big deal if it's missing.
5149
		$class = '';
5150
		if ( preg_match( '/class=["\']([^"\']+)["\']/', $avatar, $class_matches ) )
5151
			$class = wp_specialchars_decode( $class_matches[1], ENT_QUOTES );
5152
5153
		return array( $url, $class );
5154
	}
5155
5156
	/**
5157
	 * Pings the WordPress.com Mirror Site for the specified options.
5158
	 *
5159
	 * @param string|array $option_names The option names to request from the WordPress.com Mirror Site
5160
	 *
5161
	 * @return array An associative array of the option values as stored in the WordPress.com Mirror Site
5162
	 */
5163
	public function get_cloud_site_options( $option_names ) {
5164
		$option_names = array_filter( (array) $option_names, 'is_string' );
5165
5166
		Jetpack::load_xml_rpc_client();
5167
		$xml = new Jetpack_IXR_Client( array( 'user_id' => JETPACK_MASTER_USER, ) );
5168
		$xml->query( 'jetpack.fetchSiteOptions', $option_names );
5169
		if ( $xml->isError() ) {
5170
			return array(
5171
				'error_code' => $xml->getErrorCode(),
5172
				'error_msg'  => $xml->getErrorMessage(),
5173
			);
5174
		}
5175
		$cloud_site_options = $xml->getResponse();
5176
5177
		return $cloud_site_options;
5178
	}
5179
5180
	/**
5181
	 * Fetch the filtered array of options that we should compare to determine an identity crisis.
5182
	 *
5183
	 * @return array An array of options to check.
5184
	 */
5185
	public static function identity_crisis_options_to_check() {
5186
		return array(
5187
			'siteurl',
5188
			'home',
5189
		);
5190
	}
5191
5192
	/**
5193
	 * Checks to make sure that local options have the same values as remote options.  Will cache the results for up to 24 hours.
5194
	 *
5195
	 * @param bool $force_recheck Whether to ignore any cached transient and manually re-check.
5196
	 *
5197
	 * @return array An array of options that do not match.  If everything is good, it will evaluate to false.
5198
	 */
5199
	public static function check_identity_crisis( $force_recheck = false ) {
5200
		if ( ! Jetpack::is_active() || Jetpack::is_development_mode() || Jetpack::is_staging_site() )
5201
			return false;
5202
5203
		if ( $force_recheck || false === ( $errors = get_transient( 'jetpack_has_identity_crisis' ) ) ) {
5204
			$options_to_check = self::identity_crisis_options_to_check();
5205
			$cloud_options = Jetpack::init()->get_cloud_site_options( $options_to_check );
5206
			$errors        = array();
5207
5208
			foreach ( $cloud_options as $cloud_key => $cloud_value ) {
5209
5210
				// If it's not the same as the local value...
5211
				if ( $cloud_value !== get_option( $cloud_key ) ) {
5212
5213
					// Break out if we're getting errors.  We are going to check the error keys later when we alert.
5214
					if ( 'error_code' == $cloud_key ) {
5215
						$errors[ $cloud_key ] = $cloud_value;
5216
						break;
5217
					}
5218
5219
					$parsed_cloud_value = parse_url( $cloud_value );
5220
					// If the current options is an IP address
5221
					if ( filter_var( $parsed_cloud_value['host'], FILTER_VALIDATE_IP ) ) {
5222
						// Give the new value a Jetpack to fly in to the clouds
5223
						continue;
5224
					}
5225
5226
					// And it's not been added to the whitelist...
5227
					if ( ! self::is_identity_crisis_value_whitelisted( $cloud_key, $cloud_value ) ) {
5228
						/*
5229
						 * This should be a temporary hack until a cleaner solution is found.
5230
						 *
5231
						 * The siteurl and home can be set to use http in General > Settings
5232
						 * however some constants can be defined that can force https in wp-admin
5233
						 * when this happens wpcom can confuse wporg with a fake identity
5234
						 * crisis with a mismatch of http vs https when it should be allowed.
5235
						 * we need to check that here.
5236
						 *
5237
						 * @see https://github.com/Automattic/jetpack/issues/1006
5238
						 */
5239
						if ( ( 'home' == $cloud_key || 'siteurl' == $cloud_key )
5240
							&& ( substr( $cloud_value, 0, 8 ) == "https://" )
5241
							&& Jetpack::init()->is_ssl_required_to_visit_site() ) {
5242
							// Ok, we found a mismatch of http and https because of wp-config, not an invalid url
5243
							continue;
5244
						}
5245
5246
5247
						// Then kick an error!
5248
						$errors[ $cloud_key ] = $cloud_value;
5249
					}
5250
				}
5251
			}
5252
		}
5253
5254
		/**
5255
		 * Filters the errors returned when checking for an Identity Crisis.
5256
		 *
5257
		 * @since 2.3.2
5258
		 *
5259
		 * @param array $errors Array of Identity Crisis errors.
5260
		 * @param bool $force_recheck Ignore any cached transient and manually re-check. Default to false.
5261
		 */
5262
		return apply_filters( 'jetpack_has_identity_crisis', $errors, $force_recheck );
5263
	}
5264
5265
	/**
5266
	 * Checks whether a value is already whitelisted.
5267
	 *
5268
	 * @param string $key The option name that we're checking the value for.
5269
	 * @param string $value The value that we're curious to see if it's on the whitelist.
5270
	 *
5271
	 * @return bool Whether the value is whitelisted.
5272
	 */
5273
	public static function is_identity_crisis_value_whitelisted( $key, $value ) {
5274
		$whitelist = Jetpack_Options::get_option( 'identity_crisis_whitelist', array() );
5275
		if ( ! empty( $whitelist[ $key ] ) && is_array( $whitelist[ $key ] ) && in_array( $value, $whitelist[ $key ] ) ) {
5276
			return true;
5277
		}
5278
		return false;
5279
	}
5280
5281
	/**
5282
	 * Checks whether the home and siteurl specifically are whitelisted
5283
	 * Written so that we don't have re-check $key and $value params every time
5284
	 * we want to check if this site is whitelisted, for example in footer.php
5285
	 *
5286
	 * @since  3.8.0
5287
	 * @return bool True = already whitelisted False = not whitelisted
5288
	 */
5289
	public static function is_staging_site() {
5290
		$is_staging = false;
5291
5292
		$known_staging = array(
5293
			'urls' => array(
5294
				'#\.staging\.wpengine\.com$#i', // WP Engine
5295
				'#\.staging\.kinsta\.com$#i',   // Kinsta.com
5296
				),
5297
			'constants' => array(
5298
				'IS_WPE_SNAPSHOT',      // WP Engine
5299
				'KINSTA_DEV_ENV',       // Kinsta.com
5300
				'WPSTAGECOACH_STAGING', // WP Stagecoach
5301
				'JETPACK_STAGING_MODE', // Generic
5302
				)
5303
			);
5304
		/**
5305
		 * Filters the flags of known staging sites.
5306
		 *
5307
		 * @since 3.9.0
5308
		 *
5309
		 * @param array $known_staging {
5310
		 *     An array of arrays that each are used to check if the current site is staging.
5311
		 *     @type array $urls      URLs of staging sites in regex to check against site_url.
5312
		 *     @type array $constants PHP constants of known staging/developement environments.
5313
		 *  }
5314
		 */
5315
		$known_staging = apply_filters( 'jetpack_known_staging', $known_staging );
5316
5317
		if ( isset( $known_staging['urls'] ) ) {
5318
			foreach ( $known_staging['urls'] as $url ){
5319
				if ( preg_match( $url, site_url() ) ) {
5320
					$is_staging = true;
5321
					break;
5322
				}
5323
			}
5324
		}
5325
5326
		if ( isset( $known_staging['constants'] ) ) {
5327
			foreach ( $known_staging['constants'] as $constant ) {
5328
				if ( defined( $constant ) && constant( $constant ) ) {
5329
					$is_staging = true;
5330
				}
5331
			}
5332
		}
5333
5334
		// Last, let's check if sync is erroring due to an IDC. If so, set the site to staging mode.
5335
		if ( ! $is_staging && self::validate_sync_error_idc_option() ) {
5336
			$is_staging = true;
5337
		}
5338
5339
		/**
5340
		 * Filters is_staging_site check.
5341
		 *
5342
		 * @since 3.9.0
5343
		 *
5344
		 * @param bool $is_staging If the current site is a staging site.
5345
		 */
5346
		return apply_filters( 'jetpack_is_staging_site', $is_staging );
5347
	}
5348
5349
	/**
5350
	 * Checks whether the sync_error_idc option is valid or not, and if not, will do cleanup.
5351
	 *
5352
	 * @return bool
5353
	 */
5354
	public static function validate_sync_error_idc_option() {
5355
		$is_valid = false;
5356
		$sync_error = Jetpack_Options::get_option( 'sync_error_idc' );
5357
5358
		// Is the site opted in and does the stored sync_error_idc option match what we now generate?
5359
		if ( $sync_error && self::sync_idc_optin() ) {
5360
			$error_diff = array_diff_assoc( $sync_error, self::get_sync_error_idc_option() );
5361
			if ( empty( $error_diff ) ) {
5362
				$is_valid = true;
5363
			}
5364
		}
5365
5366
		/**
5367
		 * Filters whether the sync_error_idc option is valid.
5368
		 *
5369
		 * @since 4.4.0
5370
		 *
5371
		 * @param bool $is_valid If the sync_error_idc is valid or not.
5372
		 */
5373
		$is_valid = (bool) apply_filters( 'jetpack_sync_error_idc_validation', $is_valid );
5374
5375
		if ( ! $is_valid && $sync_error ) {
5376
			// Since the option exists, and did not validate, delete it
5377
			Jetpack_Options::delete_option( 'sync_error_idc' );
5378
		}
5379
5380
		return $is_valid;
5381
	}
5382
5383
	/**
5384
	 * Gets the value that is to be saved in the jetpack_sync_error_idc option.
5385
	 *
5386
	 * @since 4.4.0
5387
	 *
5388
	 * @return array {
5389
	 *     @type string 'home'    The current home URL.
5390
	 *     @type string 'siteurl' The current site URL.
5391
	 * }
5392
	 */
5393
	public static function get_sync_error_idc_option() {
5394
		$options = array(
5395
			'home'    => get_home_url(),
5396
			'siteurl' => get_site_url(),
5397
		);
5398
5399
		$returned_values = array();
5400
		foreach( $options as $key => $option ) {
5401
			$parsed_url = wp_parse_url( trailingslashit( esc_url_raw( $option ) ) );
5402
5403
			if ( ! $parsed_url ) {
5404
				$returned_values[ $key ] = $option;
5405
				continue;
5406
			}
5407
5408
			$returned_values[ $key ] = preg_replace( '/^www\./i', '', $parsed_url['host'] . $parsed_url['path'] );
5409
		}
5410
5411
		return $returned_values;
5412
	}
5413
5414
	/**
5415
	 * Returns the value of the jetpack_sync_idc_optin filter, or constant.
5416
	 * If set to true, the site will be put into staging mode.
5417
	 *
5418
	 * @since 4.3.2
5419
	 * @return bool
5420
	 */
5421
	public static function sync_idc_optin() {
5422
		if ( Jetpack_Constants::is_defined( 'JETPACK_SYNC_IDC_OPTIN' ) ) {
5423
			$default = Jetpack_Constants::get_constant( 'JETPACK_SYNC_IDC_OPTIN' );
5424
		} else {
5425
			$default = false;
5426
		}
5427
5428
		/**
5429
		 * Allows sites to optin to IDC mitigation which blocks the site from syncing to WordPress.com when the home
5430
		 * URL or site URL do not match what WordPress.com expects. The default value is either false, or the value of
5431
		 * JETPACK_SYNC_IDC_OPTIN constant if set.
5432
		 *
5433
		 * @since 4.3.2
5434
		 *
5435
		 * @param bool $default Whether the site is opted in to IDC mitigation.
5436
		 */
5437
		return (bool) apply_filters( 'jetpack_sync_idc_optin', $default );
5438
	}
5439
5440
	/**
5441
	 * Maybe Use a .min.css stylesheet, maybe not.
5442
	 *
5443
	 * Hooks onto `plugins_url` filter at priority 1, and accepts all 3 args.
5444
	 */
5445
	public static function maybe_min_asset( $url, $path, $plugin ) {
5446
		// Short out on things trying to find actual paths.
5447
		if ( ! $path || empty( $plugin ) ) {
5448
			return $url;
5449
		}
5450
5451
		// Strip out the abspath.
5452
		$base = dirname( plugin_basename( $plugin ) );
5453
5454
		// Short out on non-Jetpack assets.
5455
		if ( 'jetpack/' !== substr( $base, 0, 8 ) ) {
5456
			return $url;
5457
		}
5458
5459
		// File name parsing.
5460
		$file              = "{$base}/{$path}";
5461
		$full_path         = JETPACK__PLUGIN_DIR . substr( $file, 8 );
5462
		$file_name         = substr( $full_path, strrpos( $full_path, '/' ) + 1 );
5463
		$file_name_parts_r = array_reverse( explode( '.', $file_name ) );
5464
		$extension         = array_shift( $file_name_parts_r );
5465
5466
		if ( in_array( strtolower( $extension ), array( 'css', 'js' ) ) ) {
5467
			// Already pointing at the minified version.
5468
			if ( 'min' === $file_name_parts_r[0] ) {
5469
				return $url;
5470
			}
5471
5472
			$min_full_path = preg_replace( "#\.{$extension}$#", ".min.{$extension}", $full_path );
5473
			if ( file_exists( $min_full_path ) ) {
5474
				$url = preg_replace( "#\.{$extension}$#", ".min.{$extension}", $url );
5475
			}
5476
		}
5477
5478
		return $url;
5479
	}
5480
5481
	/**
5482
	 * Maybe inlines a stylesheet.
5483
	 *
5484
	 * If you'd like to inline a stylesheet instead of printing a link to it,
5485
	 * wp_style_add_data( 'handle', 'jetpack-inline', true );
5486
	 *
5487
	 * Attached to `style_loader_tag` filter.
5488
	 *
5489
	 * @param string $tag The tag that would link to the external asset.
5490
	 * @param string $handle The registered handle of the script in question.
5491
	 *
5492
	 * @return string
5493
	 */
5494
	public static function maybe_inline_style( $tag, $handle ) {
5495
		global $wp_styles;
5496
		$item = $wp_styles->registered[ $handle ];
5497
5498
		if ( ! isset( $item->extra['jetpack-inline'] ) || ! $item->extra['jetpack-inline'] ) {
5499
			return $tag;
5500
		}
5501
5502
		if ( preg_match( '# href=\'([^\']+)\' #i', $tag, $matches ) ) {
5503
			$href = $matches[1];
5504
			// Strip off query string
5505
			if ( $pos = strpos( $href, '?' ) ) {
5506
				$href = substr( $href, 0, $pos );
5507
			}
5508
			// Strip off fragment
5509
			if ( $pos = strpos( $href, '#' ) ) {
5510
				$href = substr( $href, 0, $pos );
5511
			}
5512
		} else {
5513
			return $tag;
5514
		}
5515
5516
		$plugins_dir = plugin_dir_url( JETPACK__PLUGIN_FILE );
5517
		if ( $plugins_dir !== substr( $href, 0, strlen( $plugins_dir ) ) ) {
5518
			return $tag;
5519
		}
5520
5521
		// If this stylesheet has a RTL version, and the RTL version replaces normal...
5522
		if ( isset( $item->extra['rtl'] ) && 'replace' === $item->extra['rtl'] && is_rtl() ) {
5523
			// And this isn't the pass that actually deals with the RTL version...
5524
			if ( false === strpos( $tag, " id='$handle-rtl-css' " ) ) {
5525
				// Short out, as the RTL version will deal with it in a moment.
5526
				return $tag;
5527
			}
5528
		}
5529
5530
		$file = JETPACK__PLUGIN_DIR . substr( $href, strlen( $plugins_dir ) );
5531
		$css  = Jetpack::absolutize_css_urls( file_get_contents( $file ), $href );
5532
		if ( $css ) {
5533
			$tag = "<!-- Inline {$item->handle} -->\r\n";
5534
			if ( empty( $item->extra['after'] ) ) {
5535
				wp_add_inline_style( $handle, $css );
5536
			} else {
5537
				array_unshift( $item->extra['after'], $css );
5538
				wp_style_add_data( $handle, 'after', $item->extra['after'] );
5539
			}
5540
		}
5541
5542
		return $tag;
5543
	}
5544
5545
	/**
5546
	 * Loads a view file from the views
5547
	 *
5548
	 * Data passed in with the $data parameter will be available in the
5549
	 * template file as $data['value']
5550
	 *
5551
	 * @param string $template - Template file to load
5552
	 * @param array $data - Any data to pass along to the template
5553
	 * @return boolean - If template file was found
5554
	 **/
5555
	public function load_view( $template, $data = array() ) {
5556
		$views_dir = JETPACK__PLUGIN_DIR . 'views/';
5557
5558
		if( file_exists( $views_dir . $template ) ) {
5559
			require_once( $views_dir . $template );
5560
			return true;
5561
		}
5562
5563
		error_log( "Jetpack: Unable to find view file $views_dir$template" );
5564
		return false;
5565
	}
5566
5567
	/**
5568
	 * Throws warnings for deprecated hooks to be removed from Jetpack
5569
	 */
5570
	public function deprecated_hooks() {
5571
		global $wp_filter;
5572
5573
		/*
5574
		 * Format:
5575
		 * deprecated_filter_name => replacement_name
5576
		 *
5577
		 * If there is no replacement us null for replacement_name
5578
		 */
5579
		$deprecated_list = array(
5580
			'jetpack_bail_on_shortcode'                              => 'jetpack_shortcodes_to_include',
5581
			'wpl_sharing_2014_1'                                     => null,
5582
			'jetpack-tools-to-include'                               => 'jetpack_tools_to_include',
5583
			'jetpack_identity_crisis_options_to_check'               => null,
5584
			'update_option_jetpack_single_user_site'                 => null,
5585
			'audio_player_default_colors'                            => null,
5586
			'add_option_jetpack_featured_images_enabled'             => null,
5587
			'add_option_jetpack_update_details'                      => null,
5588
			'add_option_jetpack_updates'                             => null,
5589
			'add_option_jetpack_network_name'                        => null,
5590
			'add_option_jetpack_network_allow_new_registrations'     => null,
5591
			'add_option_jetpack_network_add_new_users'               => null,
5592
			'add_option_jetpack_network_site_upload_space'           => null,
5593
			'add_option_jetpack_network_upload_file_types'           => null,
5594
			'add_option_jetpack_network_enable_administration_menus' => null,
5595
			'add_option_jetpack_is_multi_site'                       => null,
5596
			'add_option_jetpack_is_main_network'                     => null,
5597
			'add_option_jetpack_main_network_site'                   => null,
5598
			'jetpack_sync_all_registered_options'                    => null,
5599
		);
5600
5601
		// This is a silly loop depth. Better way?
5602
		foreach( $deprecated_list AS $hook => $hook_alt ) {
5603
			if( isset( $wp_filter[ $hook ] ) && is_array( $wp_filter[ $hook ] ) ) {
5604
				foreach( $wp_filter[$hook] AS $func => $values ) {
5605
					foreach( $values AS $hooked ) {
5606
						_deprecated_function( $hook . ' used for ' . $hooked['function'], null, $hook_alt );
5607
					}
5608
				}
5609
			}
5610
		}
5611
	}
5612
5613
	/**
5614
	 * Converts any url in a stylesheet, to the correct absolute url.
5615
	 *
5616
	 * Considerations:
5617
	 *  - Normal, relative URLs     `feh.png`
5618
	 *  - Data URLs                 ``
5619
	 *  - Schema-agnostic URLs      `//domain.com/feh.png`
5620
	 *  - Absolute URLs             `http://domain.com/feh.png`
5621
	 *  - Domain root relative URLs `/feh.png`
5622
	 *
5623
	 * @param $css string: The raw CSS -- should be read in directly from the file.
5624
	 * @param $css_file_url : The URL that the file can be accessed at, for calculating paths from.
5625
	 *
5626
	 * @return mixed|string
5627
	 */
5628
	public static function absolutize_css_urls( $css, $css_file_url ) {
5629
		$pattern = '#url\((?P<path>[^)]*)\)#i';
5630
		$css_dir = dirname( $css_file_url );
5631
		$p       = parse_url( $css_dir );
5632
		$domain  = sprintf(
5633
					'%1$s//%2$s%3$s%4$s',
5634
					isset( $p['scheme'] )           ? "{$p['scheme']}:" : '',
5635
					isset( $p['user'], $p['pass'] ) ? "{$p['user']}:{$p['pass']}@" : '',
5636
					$p['host'],
5637
					isset( $p['port'] )             ? ":{$p['port']}" : ''
5638
				);
5639
5640
		if ( preg_match_all( $pattern, $css, $matches, PREG_SET_ORDER ) ) {
5641
			$find = $replace = array();
5642
			foreach ( $matches as $match ) {
5643
				$url = trim( $match['path'], "'\" \t" );
5644
5645
				// If this is a data url, we don't want to mess with it.
5646
				if ( 'data:' === substr( $url, 0, 5 ) ) {
5647
					continue;
5648
				}
5649
5650
				// If this is an absolute or protocol-agnostic url,
5651
				// we don't want to mess with it.
5652
				if ( preg_match( '#^(https?:)?//#i', $url ) ) {
5653
					continue;
5654
				}
5655
5656
				switch ( substr( $url, 0, 1 ) ) {
5657
					case '/':
5658
						$absolute = $domain . $url;
5659
						break;
5660
					default:
5661
						$absolute = $css_dir . '/' . $url;
5662
				}
5663
5664
				$find[]    = $match[0];
5665
				$replace[] = sprintf( 'url("%s")', $absolute );
5666
			}
5667
			$css = str_replace( $find, $replace, $css );
5668
		}
5669
5670
		return $css;
5671
	}
5672
5673
	/**
5674
	 * This method checks to see if SSL is required by the site in
5675
	 * order to visit it in some way other than only setting the
5676
	 * https value in the home or siteurl values.
5677
	 *
5678
	 * @since 3.2
5679
	 * @return boolean
5680
	 **/
5681
	private function is_ssl_required_to_visit_site() {
5682
		global $wp_version;
5683
		$ssl = is_ssl();
5684
5685
		if ( force_ssl_admin() ) {
5686
			$ssl = true;
5687
		}
5688
		return $ssl;
5689
	}
5690
5691
	/**
5692
	 * This methods removes all of the registered css files on the front end
5693
	 * from Jetpack in favor of using a single file. In effect "imploding"
5694
	 * all the files into one file.
5695
	 *
5696
	 * Pros:
5697
	 * - Uses only ONE css asset connection instead of 15
5698
	 * - Saves a minimum of 56k
5699
	 * - Reduces server load
5700
	 * - Reduces time to first painted byte
5701
	 *
5702
	 * Cons:
5703
	 * - Loads css for ALL modules. However all selectors are prefixed so it
5704
	 *		should not cause any issues with themes.
5705
	 * - Plugins/themes dequeuing styles no longer do anything. See
5706
	 *		jetpack_implode_frontend_css filter for a workaround
5707
	 *
5708
	 * For some situations developers may wish to disable css imploding and
5709
	 * instead operate in legacy mode where each file loads seperately and
5710
	 * can be edited individually or dequeued. This can be accomplished with
5711
	 * the following line:
5712
	 *
5713
	 * add_filter( 'jetpack_implode_frontend_css', '__return_false' );
5714
	 *
5715
	 * @since 3.2
5716
	 **/
5717
	public function implode_frontend_css( $travis_test = false ) {
5718
		$do_implode = true;
5719
		if ( defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ) {
5720
			$do_implode = false;
5721
		}
5722
5723
		/**
5724
		 * Allow CSS to be concatenated into a single jetpack.css file.
5725
		 *
5726
		 * @since 3.2.0
5727
		 *
5728
		 * @param bool $do_implode Should CSS be concatenated? Default to true.
5729
		 */
5730
		$do_implode = apply_filters( 'jetpack_implode_frontend_css', $do_implode );
5731
5732
		// Do not use the imploded file when default behaviour was altered through the filter
5733
		if ( ! $do_implode ) {
5734
			return;
5735
		}
5736
5737
		// We do not want to use the imploded file in dev mode, or if not connected
5738
		if ( Jetpack::is_development_mode() || ! self::is_active() ) {
5739
			if ( ! $travis_test ) {
5740
				return;
5741
			}
5742
		}
5743
5744
		// Do not use the imploded file if sharing css was dequeued via the sharing settings screen
5745
		if ( get_option( 'sharedaddy_disable_resources' ) ) {
5746
			return;
5747
		}
5748
5749
		/*
5750
		 * Now we assume Jetpack is connected and able to serve the single
5751
		 * file.
5752
		 *
5753
		 * In the future there will be a check here to serve the file locally
5754
		 * or potentially from the Jetpack CDN
5755
		 *
5756
		 * For now:
5757
		 * - Enqueue a single imploded css file
5758
		 * - Zero out the style_loader_tag for the bundled ones
5759
		 * - Be happy, drink scotch
5760
		 */
5761
5762
		add_filter( 'style_loader_tag', array( $this, 'concat_remove_style_loader_tag' ), 10, 2 );
5763
5764
		$version = Jetpack::is_development_version() ? filemtime( JETPACK__PLUGIN_DIR . 'css/jetpack.css' ) : JETPACK__VERSION;
5765
5766
		wp_enqueue_style( 'jetpack_css', plugins_url( 'css/jetpack.css', __FILE__ ), array(), $version );
5767
		wp_style_add_data( 'jetpack_css', 'rtl', 'replace' );
5768
	}
5769
5770
	function concat_remove_style_loader_tag( $tag, $handle ) {
5771
		if ( in_array( $handle, $this->concatenated_style_handles ) ) {
5772
			$tag = '';
5773
			if ( defined( 'WP_DEBUG' ) && WP_DEBUG ) {
5774
				$tag = "<!-- `" . esc_html( $handle ) . "` is included in the concatenated jetpack.css -->\r\n";
5775
			}
5776
		}
5777
5778
		return $tag;
5779
	}
5780
5781
	/*
5782
	 * Check the heartbeat data
5783
	 *
5784
	 * Organizes the heartbeat data by severity.  For example, if the site
5785
	 * is in an ID crisis, it will be in the $filtered_data['bad'] array.
5786
	 *
5787
	 * Data will be added to "caution" array, if it either:
5788
	 *  - Out of date Jetpack version
5789
	 *  - Out of date WP version
5790
	 *  - Out of date PHP version
5791
	 *
5792
	 * $return array $filtered_data
5793
	 */
5794
	public static function jetpack_check_heartbeat_data() {
5795
		$raw_data = Jetpack_Heartbeat::generate_stats_array();
5796
5797
		$good    = array();
5798
		$caution = array();
5799
		$bad     = array();
5800
5801
		foreach ( $raw_data as $stat => $value ) {
5802
5803
			// Check jetpack version
5804
			if ( 'version' == $stat ) {
5805
				if ( version_compare( $value, JETPACK__VERSION, '<' ) ) {
5806
					$caution[ $stat ] = $value . " - min supported is " . JETPACK__VERSION;
5807
					continue;
5808
				}
5809
			}
5810
5811
			// Check WP version
5812
			if ( 'wp-version' == $stat ) {
5813
				if ( version_compare( $value, JETPACK__MINIMUM_WP_VERSION, '<' ) ) {
5814
					$caution[ $stat ] = $value . " - min supported is " . JETPACK__MINIMUM_WP_VERSION;
5815
					continue;
5816
				}
5817
			}
5818
5819
			// Check PHP version
5820
			if ( 'php-version' == $stat ) {
5821
				if ( version_compare( PHP_VERSION, '5.2.4', '<' ) ) {
5822
					$caution[ $stat ] = $value . " - min supported is 5.2.4";
5823
					continue;
5824
				}
5825
			}
5826
5827
			// Check ID crisis
5828
			if ( 'identitycrisis' == $stat ) {
5829
				if ( 'yes' == $value ) {
5830
					$bad[ $stat ] = $value;
5831
					continue;
5832
				}
5833
			}
5834
5835
			// The rest are good :)
5836
			$good[ $stat ] = $value;
5837
		}
5838
5839
		$filtered_data = array(
5840
			'good'    => $good,
5841
			'caution' => $caution,
5842
			'bad'     => $bad
5843
		);
5844
5845
		return $filtered_data;
5846
	}
5847
5848
5849
	/*
5850
	 * This method is used to organize all options that can be reset
5851
	 * without disconnecting Jetpack.
5852
	 *
5853
	 * It is used in class.jetpack-cli.php to reset options
5854
	 *
5855
	 * @return array of options to delete.
5856
	 */
5857
	public static function get_jetpack_options_for_reset() {
5858
		$jetpack_options            = Jetpack_Options::get_option_names();
5859
		$jetpack_options_non_compat = Jetpack_Options::get_option_names( 'non_compact' );
5860
		$jetpack_options_private    = Jetpack_Options::get_option_names( 'private' );
5861
5862
		$all_jp_options = array_merge( $jetpack_options, $jetpack_options_non_compat, $jetpack_options_private );
5863
5864
		// A manual build of the wp options
5865
		$wp_options = array(
5866
			'sharing-options',
5867
			'disabled_likes',
5868
			'disabled_reblogs',
5869
			'jetpack_comments_likes_enabled',
5870
			'wp_mobile_excerpt',
5871
			'wp_mobile_featured_images',
5872
			'wp_mobile_app_promos',
5873
			'stats_options',
5874
			'stats_dashboard_widget',
5875
			'safecss_preview_rev',
5876
			'safecss_rev',
5877
			'safecss_revision_migrated',
5878
			'nova_menu_order',
5879
			'jetpack_portfolio',
5880
			'jetpack_portfolio_posts_per_page',
5881
			'jetpack_testimonial',
5882
			'jetpack_testimonial_posts_per_page',
5883
			'wp_mobile_custom_css',
5884
			'sharedaddy_disable_resources',
5885
			'sharing-options',
5886
			'sharing-services',
5887
			'site_icon_temp_data',
5888
			'featured-content',
5889
			'site_logo',
5890
			'jetpack_dismissed_notices',
5891
		);
5892
5893
		// Flag some Jetpack options as unsafe
5894
		$unsafe_options = array(
5895
			'id',                           // (int)    The Client ID/WP.com Blog ID of this site.
5896
			'master_user',                  // (int)    The local User ID of the user who connected this site to jetpack.wordpress.com.
5897
			'version',                      // (string) Used during upgrade procedure to auto-activate new modules. version:time
5898
			'jumpstart',                    // (string) A flag for whether or not to show the Jump Start.  Accepts: new_connection, jumpstart_activated, jetpack_action_taken, jumpstart_dismissed.
5899
5900
			// non_compact
5901
			'activated',
5902
5903
			// private
5904
			'register',
5905
			'blog_token',                  // (string) The Client Secret/Blog Token of this site.
5906
			'user_token',                  // (string) The User Token of this site. (deprecated)
5907
			'user_tokens'
5908
		);
5909
5910
		// Remove the unsafe Jetpack options
5911
		foreach ( $unsafe_options as $unsafe_option ) {
5912
			if ( false !== ( $key = array_search( $unsafe_option, $all_jp_options ) ) ) {
5913
				unset( $all_jp_options[ $key ] );
5914
			}
5915
		}
5916
5917
		$options = array(
5918
			'jp_options' => $all_jp_options,
5919
			'wp_options' => $wp_options
5920
		);
5921
5922
		return $options;
5923
	}
5924
5925
	/**
5926
	 * Check if an option of a Jetpack module has been updated.
5927
	 *
5928
	 * If any module option has been updated before Jump Start has been dismissed,
5929
	 * update the 'jumpstart' option so we can hide Jump Start.
5930
	 *
5931
	 * @param string $option_name
5932
	 *
5933
	 * @return bool
5934
	 */
5935
	public static function jumpstart_has_updated_module_option( $option_name = '' ) {
5936
		// Bail if Jump Start has already been dismissed
5937
		if ( 'new_connection' !== Jetpack_Options::get_option( 'jumpstart' ) ) {
5938
			return false;
5939
		}
5940
5941
		$jetpack = Jetpack::init();
5942
5943
		// Manual build of module options
5944
		$option_names = self::get_jetpack_options_for_reset();
5945
5946
		if ( in_array( $option_name, $option_names['wp_options'] ) ) {
5947
			Jetpack_Options::update_option( 'jumpstart', 'jetpack_action_taken' );
5948
5949
			//Jump start is being dismissed send data to MC Stats
5950
			$jetpack->stat( 'jumpstart', 'manual,'.$option_name );
5951
5952
			$jetpack->do_stats( 'server_side' );
5953
		}
5954
5955
	}
5956
5957
	/*
5958
	 * Strip http:// or https:// from a url, replaces forward slash with ::,
5959
	 * so we can bring them directly to their site in calypso.
5960
	 *
5961
	 * @param string | url
5962
	 * @return string | url without the guff
5963
	 */
5964
	public static function build_raw_urls( $url ) {
5965
		$strip_http = '/.*?:\/\//i';
5966
		$url = preg_replace( $strip_http, '', $url  );
5967
		$url = str_replace( '/', '::', $url );
5968
		return $url;
5969
	}
5970
5971
	/**
5972
	 * Stores and prints out domains to prefetch for page speed optimization.
5973
	 *
5974
	 * @param mixed $new_urls
5975
	 */
5976
	public static function dns_prefetch( $new_urls = null ) {
5977
		static $prefetch_urls = array();
5978
		if ( empty( $new_urls ) && ! empty( $prefetch_urls ) ) {
5979
			echo "\r\n";
5980
			foreach ( $prefetch_urls as $this_prefetch_url ) {
5981
				printf( "<link rel='dns-prefetch' href='%s'>\r\n", esc_attr( $this_prefetch_url ) );
5982
			}
5983
		} elseif ( ! empty( $new_urls ) ) {
5984
			if ( ! has_action( 'wp_head', array( __CLASS__, __FUNCTION__ ) ) ) {
5985
				add_action( 'wp_head', array( __CLASS__, __FUNCTION__ ) );
5986
			}
5987
			foreach ( (array) $new_urls as $this_new_url ) {
5988
				$prefetch_urls[] = strtolower( untrailingslashit( preg_replace( '#^https?://#i', '//', $this_new_url ) ) );
5989
			}
5990
			$prefetch_urls = array_unique( $prefetch_urls );
5991
		}
5992
	}
5993
5994
	public function wp_dashboard_setup() {
5995
		if ( self::is_active() ) {
5996
			add_action( 'jetpack_dashboard_widget', array( __CLASS__, 'dashboard_widget_footer' ), 999 );
5997
			$widget_title = __( 'Site Stats', 'jetpack' );
5998
		} elseif ( ! self::is_development_mode() && current_user_can( 'jetpack_connect' ) ) {
5999
			add_action( 'jetpack_dashboard_widget', array( $this, 'dashboard_widget_connect_to_wpcom' ) );
6000
			$widget_title = __( 'Please Connect Jetpack', 'jetpack' );
6001
		}
6002
6003
		if ( has_action( 'jetpack_dashboard_widget' ) ) {
6004
			wp_add_dashboard_widget(
6005
				'jetpack_summary_widget',
6006
				$widget_title,
6007
				array( __CLASS__, 'dashboard_widget' )
6008
			);
6009
			wp_enqueue_style( 'jetpack-dashboard-widget', plugins_url( 'css/dashboard-widget.css', JETPACK__PLUGIN_FILE ), array(), JETPACK__VERSION );
6010
6011
			// If we're inactive and not in development mode, sort our box to the top.
6012
			if ( ! self::is_active() && ! self::is_development_mode() ) {
6013
				global $wp_meta_boxes;
6014
6015
				$dashboard = $wp_meta_boxes['dashboard']['normal']['core'];
6016
				$ours      = array( 'jetpack_summary_widget' => $dashboard['jetpack_summary_widget'] );
6017
6018
				$wp_meta_boxes['dashboard']['normal']['core'] = array_merge( $ours, $dashboard );
6019
			}
6020
		}
6021
	}
6022
6023
	/**
6024
	 * @param mixed $result Value for the user's option
6025
	 * @return mixed
6026
	 */
6027
	function get_user_option_meta_box_order_dashboard( $sorted ) {
6028
		if ( ! is_array( $sorted ) ) {
6029
			return $sorted;
6030
		}
6031
6032
		foreach ( $sorted as $box_context => $ids ) {
6033
			if ( false === strpos( $ids, 'dashboard_stats' ) ) {
6034
				// If the old id isn't anywhere in the ids, don't bother exploding and fail out.
6035
				continue;
6036
			}
6037
6038
			$ids_array = explode( ',', $ids );
6039
			$key = array_search( 'dashboard_stats', $ids_array );
6040
6041
			if ( false !== $key ) {
6042
				// If we've found that exact value in the option (and not `google_dashboard_stats` for example)
6043
				$ids_array[ $key ] = 'jetpack_summary_widget';
6044
				$sorted[ $box_context ] = implode( ',', $ids_array );
6045
				// We've found it, stop searching, and just return.
6046
				break;
6047
			}
6048
		}
6049
6050
		return $sorted;
6051
	}
6052
6053
	public static function dashboard_widget() {
6054
		/**
6055
		 * Fires when the dashboard is loaded.
6056
		 *
6057
		 * @since 3.4.0
6058
		 */
6059
		do_action( 'jetpack_dashboard_widget' );
6060
	}
6061
6062
	public static function dashboard_widget_footer() {
6063
		?>
6064
		<footer>
6065
6066
		<div class="protect">
6067
			<?php if ( Jetpack::is_module_active( 'protect' ) ) : ?>
6068
				<h3><?php echo number_format_i18n( get_site_option( 'jetpack_protect_blocked_attempts', 0 ) ); ?></h3>
6069
				<p><?php echo esc_html_x( 'Blocked malicious login attempts', '{#} Blocked malicious login attempts -- number is on a prior line, text is a caption.', 'jetpack' ); ?></p>
6070
			<?php elseif ( current_user_can( 'jetpack_activate_modules' ) && ! self::is_development_mode() ) : ?>
6071
				<a href="<?php echo esc_url( wp_nonce_url( Jetpack::admin_url( array( 'action' => 'activate', 'module' => 'protect' ) ), 'jetpack_activate-protect' ) ); ?>" class="button button-jetpack" title="<?php esc_attr_e( 'Protect helps to keep you secure from brute-force login attacks.', 'jetpack' ); ?>">
6072
					<?php esc_html_e( 'Activate Protect', 'jetpack' ); ?>
6073
				</a>
6074
			<?php else : ?>
6075
				<?php esc_html_e( 'Protect is inactive.', 'jetpack' ); ?>
6076
			<?php endif; ?>
6077
		</div>
6078
6079
		<div class="akismet">
6080
			<?php if ( is_plugin_active( 'akismet/akismet.php' ) ) : ?>
6081
				<h3><?php echo number_format_i18n( get_option( 'akismet_spam_count', 0 ) ); ?></h3>
6082
				<p><?php echo esc_html_x( 'Spam comments blocked by Akismet.', '{#} Spam comments blocked by Akismet -- number is on a prior line, text is a caption.', 'jetpack' ); ?></p>
6083
			<?php elseif ( current_user_can( 'activate_plugins' ) && ! is_wp_error( validate_plugin( 'akismet/akismet.php' ) ) ) : ?>
6084
				<a href="<?php echo esc_url( wp_nonce_url( add_query_arg( array( 'action' => 'activate', 'plugin' => 'akismet/akismet.php' ), admin_url( 'plugins.php' ) ), 'activate-plugin_akismet/akismet.php' ) ); ?>" class="button button-jetpack">
6085
					<?php esc_html_e( 'Activate Akismet', 'jetpack' ); ?>
6086
				</a>
6087
			<?php else : ?>
6088
				<p><a href="<?php echo esc_url( 'https://akismet.com/?utm_source=jetpack&utm_medium=link&utm_campaign=Jetpack%20Dashboard%20Widget%20Footer%20Link' ); ?>"><?php esc_html_e( 'Akismet can help to keep your blog safe from spam!', 'jetpack' ); ?></a></p>
6089
			<?php endif; ?>
6090
		</div>
6091
6092
		</footer>
6093
		<?php
6094
	}
6095
6096
	public function dashboard_widget_connect_to_wpcom() {
6097
		if ( Jetpack::is_active() || Jetpack::is_development_mode() || ! current_user_can( 'jetpack_connect' ) ) {
6098
			return;
6099
		}
6100
		?>
6101
		<div class="wpcom-connect">
6102
			<div class="jp-emblem">
6103
			<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0" y="0" viewBox="0 0 172.9 172.9" enable-background="new 0 0 172.9 172.9" xml:space="preserve">
6104
				<path d="M86.4 0C38.7 0 0 38.7 0 86.4c0 47.7 38.7 86.4 86.4 86.4s86.4-38.7 86.4-86.4C172.9 38.7 134.2 0 86.4 0zM83.1 106.6l-27.1-6.9C49 98 45.7 90.1 49.3 84l33.8-58.5V106.6zM124.9 88.9l-33.8 58.5V66.3l27.1 6.9C125.1 74.9 128.4 82.8 124.9 88.9z"/>
6105
			</svg>
6106
			</div>
6107
			<h3><?php esc_html_e( 'Please Connect Jetpack', 'jetpack' ); ?></h3>
6108
			<p><?php echo wp_kses( __( 'Connecting Jetpack will show you <strong>stats</strong> about your traffic, <strong>protect</strong> you from brute force attacks, <strong>speed up</strong> your images and photos, and enable other <strong>traffic and security</strong> features.', 'jetpack' ), 'jetpack' ) ?></p>
6109
6110
			<div class="actions">
6111
				<a href="<?php echo $this->build_connect_url( false, false, 'widget-btn' ); ?>" class="button button-primary">
6112
					<?php esc_html_e( 'Connect Jetpack', 'jetpack' ); ?>
6113
				</a>
6114
			</div>
6115
		</div>
6116
		<?php
6117
	}
6118
6119
	/*
6120
	 * A graceful transition to using Core's site icon.
6121
	 *
6122
	 * All of the hard work has already been done with the image
6123
	 * in all_done_page(). All that needs to be done now is update
6124
	 * the option and display proper messaging.
6125
	 *
6126
	 * @todo remove when WP 4.3 is minimum
6127
	 *
6128
	 * @since 3.6.1
6129
	 *
6130
	 * @return bool false = Core's icon not available || true = Core's icon is available
6131
	 */
6132
	public static function jetpack_site_icon_available_in_core() {
6133
		global $wp_version;
6134
		$core_icon_available = function_exists( 'has_site_icon' ) && version_compare( $wp_version, '4.3-beta' ) >= 0;
6135
6136
		if ( ! $core_icon_available ) {
6137
			return false;
6138
		}
6139
6140
		// No need for Jetpack's site icon anymore if core's is already set
6141
		if ( has_site_icon() ) {
6142
			if ( Jetpack::is_module_active( 'site-icon' ) ) {
6143
				Jetpack::log( 'deactivate', 'site-icon' );
6144
				Jetpack::deactivate_module( 'site-icon' );
6145
			}
6146
			return true;
6147
		}
6148
6149
		// Transfer Jetpack's site icon to use core.
6150
		$site_icon_id = Jetpack::get_option( 'site_icon_id' );
6151
		if ( $site_icon_id ) {
6152
			// Update core's site icon
6153
			update_option( 'site_icon', $site_icon_id );
6154
6155
			// Delete Jetpack's icon option. We still want the blavatar and attached data though.
6156
			delete_option( 'site_icon_id' );
6157
		}
6158
6159
		// No need for Jetpack's site icon anymore
6160
		if ( Jetpack::is_module_active( 'site-icon' ) ) {
6161
			Jetpack::log( 'deactivate', 'site-icon' );
6162
			Jetpack::deactivate_module( 'site-icon' );
6163
		}
6164
6165
		return true;
6166
	}
6167
6168
	/**
6169
	 * Return string containing the Jetpack logo.
6170
	 *
6171
	 * @since 3.9.0
6172
	 *
6173
	 * @return string
6174
	 */
6175
	public static function get_jp_emblem() {
6176
		return '<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0" y="0" viewBox="0 0 172.9 172.9" enable-background="new 0 0 172.9 172.9" xml:space="preserve">	<path d="M86.4 0C38.7 0 0 38.7 0 86.4c0 47.7 38.7 86.4 86.4 86.4s86.4-38.7 86.4-86.4C172.9 38.7 134.2 0 86.4 0zM83.1 106.6l-27.1-6.9C49 98 45.7 90.1 49.3 84l33.8-58.5V106.6zM124.9 88.9l-33.8 58.5V66.3l27.1 6.9C125.1 74.9 128.4 82.8 124.9 88.9z" /></svg>';
6177
	}
6178
6179
	/*
6180
	 * Adds a "blank" column in the user admin table to display indication of user connection.
6181
	 */
6182
	function jetpack_icon_user_connected( $columns ) {
6183
		$columns['user_jetpack'] = '';
6184
		return $columns;
6185
	}
6186
6187
	/*
6188
	 * Show Jetpack icon if the user is linked.
6189
	 */
6190
	function jetpack_show_user_connected_icon( $val, $col, $user_id ) {
6191
		if ( 'user_jetpack' == $col && Jetpack::is_user_connected( $user_id ) ) {
6192
			$emblem_html = sprintf(
6193
				'<a title="%1$s" class="jp-emblem-user-admin">%2$s</a>',
6194
				esc_attr__( 'This user is linked and ready to fly with Jetpack.', 'jetpack' ),
6195
				Jetpack::get_jp_emblem()
6196
			);
6197
			return $emblem_html;
6198
		}
6199
6200
		return $val;
6201
	}
6202
6203
	/*
6204
	 * Style the Jetpack user column
6205
	 */
6206
	function jetpack_user_col_style() {
6207
		global $current_screen;
6208
		if ( ! empty( $current_screen->base ) && 'users' == $current_screen->base ) { ?>
6209
			<style>
6210
				.fixed .column-user_jetpack {
6211
					width: 21px;
6212
				}
6213
				.jp-emblem-user-admin path {
6214
					fill: #8cc258;
6215
				}
6216
			</style>
6217
		<?php }
6218
	}
6219
6220
}
6221