Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
0.00% covered (danger)
0.00%
0 / 544
0.00% covered (danger)
0.00%
0 / 22
CRAP
0.00% covered (danger)
0.00%
0 / 1
Jetpack_Comments
0.00% covered (danger)
0.00%
0 / 540
0.00% covered (danger)
0.00%
0 / 22
16512
0.00% covered (danger)
0.00%
0 / 1
 init
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
6
 __construct
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
2
 set_default_color_theme_based_on_theme_settings
0.00% covered (danger)
0.00%
0 / 8
0.00% covered (danger)
0.00%
0 / 1
20
 setup_globals
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
2
 new_comments_enabled
0.00% covered (danger)
0.00%
0 / 2
0.00% covered (danger)
0.00%
0 / 1
6
 setup_actions
0.00% covered (danger)
0.00%
0 / 9
0.00% covered (danger)
0.00%
0 / 1
6
 setup_filters
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
6
 manage_post_cookie
0.00% covered (danger)
0.00%
0 / 32
0.00% covered (danger)
0.00%
0 / 1
30
 get_avatar
0.00% covered (danger)
0.00%
0 / 15
0.00% covered (danger)
0.00%
0 / 1
30
 comment_reply_link
0.00% covered (danger)
0.00%
0 / 31
0.00% covered (danger)
0.00%
0 / 1
6
 get_blog_token
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
12
 comment_form_before
0.00% covered (danger)
0.00%
0 / 6
0.00% covered (danger)
0.00%
0 / 1
12
 comment_form_after
0.00% covered (danger)
0.00%
0 / 113
0.00% covered (danger)
0.00%
0 / 1
756
 watch_comment_parent
0.00% covered (danger)
0.00%
0 / 60
0.00% covered (danger)
0.00%
0 / 1
30
 pre_comment_on_post
0.00% covered (danger)
0.00%
0 / 20
0.00% covered (danger)
0.00%
0 / 1
272
 retry_submit_comment_form_locally
0.00% covered (danger)
0.00%
0 / 20
0.00% covered (danger)
0.00%
0 / 1
6
 add_comment_meta
0.00% covered (danger)
0.00%
0 / 33
0.00% covered (danger)
0.00%
0 / 1
600
 should_show_subscription_modal
0.00% covered (danger)
0.00%
0 / 5
0.00% covered (danger)
0.00%
0 / 1
42
 get_subscription_modal_data_to_parent
0.00% covered (danger)
0.00%
0 / 10
0.00% covered (danger)
0.00%
0 / 1
12
 subscription_modal_status_track_event
0.00% covered (danger)
0.00%
0 / 9
0.00% covered (danger)
0.00%
0 / 1
30
 capture_comment_duplicate_trigger
0.00% covered (danger)
0.00%
0 / 53
0.00% covered (danger)
0.00%
0 / 1
12
 capture_comment_post_redirect_to_reload_parent_frame
0.00% covered (danger)
0.00%
0 / 89
0.00% covered (danger)
0.00%
0 / 1
30
1<?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2/**
3 * Module: Comments
4 *
5 * @package automattic/jetpack
6 */
7
8require __DIR__ . '/base.php';
9use Automattic\Jetpack\Connection\Tokens;
10use Automattic\Jetpack\Status\Host;
11
12if ( ! defined( 'ABSPATH' ) ) {
13    exit( 0 );
14}
15
16/**
17 * Main Comments class
18 *
19 * @package automattic/jetpack
20 * @since   1.4
21 */
22class Jetpack_Comments extends Highlander_Comments_Base {
23
24    /** Variables *************************************************************/
25
26    /**
27     * Possible comment form sources - empty array as default
28     *
29     * @var array
30     */
31    public $id_sources = array();
32
33    /**
34     * Remote comment URL - empty string as default
35     *
36     * @var string
37     */
38    public $signed_url = '';
39
40    /**
41     * The default comment form color scheme - default is light
42     *
43     * @var string
44     * @see ::set_default_color_theme_based_on_theme_settings()
45     */
46    public $default_color_scheme = 'light';
47
48    /** Methods ***************************************************************/
49
50    /**
51     * Initialize class
52     */
53    public static function init() {
54        static $instance = false;
55
56        if ( ! $instance ) {
57            $instance = new Jetpack_Comments();
58        }
59
60        return $instance;
61    }
62
63    /**
64     * Main constructor for Comments
65     *
66     * @since 1.4
67     */
68    public function __construct() {
69        parent::__construct();
70
71        // Comments is loaded.
72
73        /**
74         * Fires after the Jetpack_Comments object has been instantiated
75         *
76         * @module comments
77         *
78         * @since  1.4.0
79         *
80         * @param array $jetpack_comments_loaded First element in array of type Jetpack_Comments
81         */
82        do_action_ref_array( 'jetpack_comments_loaded', array( $this ) );
83        add_action( 'after_setup_theme', array( $this, 'set_default_color_theme_based_on_theme_settings' ), 100 );
84    }
85
86    /**
87     * Set the default comments color theme based on theme settings
88     */
89    public function set_default_color_theme_based_on_theme_settings() {
90        if ( function_exists( 'twentyeleven_get_theme_options' ) ) {
91            $theme_options      = twentyeleven_get_theme_options();
92            $theme_color_scheme = $theme_options['color_scheme'] ?? 'transparent';
93        } else {
94            $theme_color_scheme = get_theme_mod( 'color_scheme', 'transparent' );
95        }
96        // Default for $theme_color_scheme is 'transparent' just so it doesn't match 'light' or 'dark'.
97        // The default for Jetpack's color scheme is still defined above as 'light'.
98
99        if ( false !== stripos( $theme_color_scheme, 'light' ) ) {
100            $this->default_color_scheme = 'light';
101        } elseif ( false !== stripos( $theme_color_scheme, 'dark' ) ) {
102            $this->default_color_scheme = 'dark';
103        }
104    }
105
106    /** Private Methods *******************************************************/
107
108    /**
109     * Set any global variables or class variables
110     *
111     * This is primarily defining the comment form sources.
112     *
113     * @since 1.4
114     */
115    protected function setup_globals() {
116        parent::setup_globals();
117
118        // Sources.
119        $this->id_sources = array(
120            'guest',
121            'jetpack',
122            'wordpress',
123            'facebook',
124        );
125    }
126
127    /**
128     * Whether the rebuilt Jetpack Comments form has taken over from this one.
129     *
130     * Guarded because this file and the jetpack-comments package can land in
131     * either order on a staged deploy.
132     *
133     * @return bool
134     */
135    private static function new_comments_enabled() {
136        return class_exists( '\Automattic\Jetpack\Comments\Comments' )
137            && \Automattic\Jetpack\Comments\Comments::is_enabled();
138    }
139
140    /**
141     * Setup actions for methods in this class
142     *
143     * @since 1.4
144     */
145    protected function setup_actions() {
146        if ( self::new_comments_enabled() ) {
147            return;
148        }
149
150        parent::setup_actions();
151
152        // Selfishly remove everything from the existing comment form.
153        remove_all_actions( 'comment_form_before' );
154
155        // Selfishly add only our actions back to the comment form.
156        add_action( 'comment_form_before', array( $this, 'manage_post_cookie' ) );
157        add_action( 'comment_form_before', array( $this, 'comment_form_before' ) );
158        add_action( 'comment_form_after', array( $this, 'comment_form_after' ), 1 ); // Set very early since we remove everything outputed before our action.
159
160        // Before a comment is posted.
161        add_action( 'pre_comment_on_post', array( $this, 'pre_comment_on_post' ), 1 );
162
163        // After a comment is posted.
164        add_action( 'comment_post', array( $this, 'add_comment_meta' ) );
165    }
166
167    /**
168     * Setup filters for methods in this class
169     *
170     * @since 1.6.2
171     */
172    protected function setup_filters() {
173        if ( self::new_comments_enabled() ) {
174            return;
175        }
176
177        parent::setup_filters();
178
179        add_filter( 'comment_post_redirect', array( $this, 'capture_comment_post_redirect_to_reload_parent_frame' ), 100 );
180        add_filter( 'comment_duplicate_trigger', array( $this, 'capture_comment_duplicate_trigger' ), 100 );
181        add_filter( 'get_avatar', array( $this, 'get_avatar' ), 10, 4 );
182        // Fix comment reply link when `comment_registration` is required.
183        add_filter( 'comment_reply_link', array( $this, 'comment_reply_link' ), 10, 4 );
184    }
185
186    /**
187     * In order for comments to work properly for password-protected posts we need to set `wp-postpass` cookie to SameSite none.
188     */
189    public function manage_post_cookie() {
190        if ( headers_sent() ) {
191            return;
192        }
193
194        $postpass_cookie_key = 'wp-postpass_' . COOKIEHASH;
195
196        if ( empty( $_COOKIE[ $postpass_cookie_key ] ) ) {
197            return;
198        }
199
200        $postpass_cookie_value = sanitize_text_field( wp_unslash( $_COOKIE[ $postpass_cookie_key ] ) );
201
202        if ( empty( $_COOKIE['verbum-wp-postpass'] ) || ( $_COOKIE['verbum-wp-postpass'] !== $postpass_cookie_value ) ) {
203            $expire = apply_filters( 'post_password_expires', time() + 10 * DAY_IN_SECONDS );
204
205            setcookie(
206                $postpass_cookie_key,
207                $postpass_cookie_value,
208                array(
209                    'expires'  => $expire,
210                    'samesite' => 'None',
211                    'path'     => '/',
212                    'domain'   => COOKIE_DOMAIN,
213                    'secure'   => is_ssl(),
214                    'httponly' => false, // phpcs:ignore Jetpack.Functions.SetCookie.FoundNonHTTPOnlyFalse -- @todo Can this be set true?
215                )
216            );
217
218            setcookie(
219                'verbum-wp-postpass',
220                $postpass_cookie_value,
221                array(
222                    'expires'  => $expire,
223                    'samesite' => 'None',
224                    'path'     => '/',
225                    'domain'   => COOKIE_DOMAIN,
226                    'secure'   => is_ssl(),
227                    'httponly' => false, // phpcs:ignore Jetpack.Functions.SetCookie.FoundNonHTTPOnlyFalse -- @todo Can this be set true?
228                )
229            );
230        }
231    }
232
233    /**
234     * Get the comment avatar from Gravatar or Twitter/Facebook.
235     *
236     * Leaving the Twitter reference for legacy comments even though support is no longer offered.
237     *
238     * @since 1.4
239     *
240     * @param string $avatar  Current avatar URL.
241     * @param string $comment Comment for the avatar.
242     * @param int    $size    Size of the avatar.
243     *
244     * @return string New avatar
245     */
246    public function get_avatar( $avatar, $comment, $size ) {
247        if ( ! isset( $comment->comment_post_ID ) || ! isset( $comment->comment_ID ) ) {
248            // it's not a comment - bail.
249            return $avatar;
250        }
251
252        // Detect whether it's a Facebook avatar.
253        $foreign_avatar          = get_comment_meta( $comment->comment_ID, 'hc_avatar', true );
254        $foreign_avatar_hostname = wp_parse_url( $foreign_avatar, PHP_URL_HOST );
255        if ( ! $foreign_avatar_hostname ||
256            ! preg_match( '/\.?(graph\.facebook\.com|twimg\.com)$/', $foreign_avatar_hostname ) ) {
257            return $avatar;
258        }
259
260        // Insert the escaped URL through a callback: a preg_replace() replacement string would expand a
261        // `$1` inside it into the captured quote, breaking out of the src attribute (stored-XSS vector).
262        $photon_url = esc_url( set_url_scheme( $this->photon_avatar( $foreign_avatar, $size ), 'https' ) );
263        return preg_replace_callback(
264            '#src=([\'"])[^\'"]+\\1#',
265            static function ( $matches ) use ( $photon_url ) {
266                return 'src=' . $matches[1] . $photon_url . $matches[1];
267            },
268            $avatar
269        );
270    }
271
272    /**
273     * Set comment reply link.
274     * This is to fix the reply link when comment registration is required.
275     *
276     * @param string     $reply_link The HTML markup for the comment reply link.
277     * @param array      $args An array of arguments overriding the defaults.
278     * @param WP_Comment $comment The object of the comment being replied.
279     * @param WP_Post    $post    The WP_Post object.
280     *
281     * @return string New reply link.
282     */
283    public function comment_reply_link( $reply_link, $args, $comment, $post ) {
284        // This is only necessary if comment_registration is required to post comments
285        if ( ! get_option( 'comment_registration' ) ) {
286            return $reply_link;
287        }
288
289        $respond_id = esc_attr( $args['respond_id'] );
290        $add_below  = esc_attr( $args['add_below'] );
291        /* This is to accommodate some themes that add an SVG to the Reply link like twenty-seventeen. */
292        $reply_text  = wp_kses(
293            $args['reply_text'],
294            array(
295                'svg' => array(
296                    'class'           => true,
297                    'aria-hidden'     => true,
298                    'aria-labelledby' => true,
299                    'role'            => true,
300                    'xmlns'           => true,
301                    'width'           => true,
302                    'height'          => true,
303                    'viewbox'         => true,
304                ),
305                'use' => array(
306                    'href'       => true,
307                    'xlink:href' => true,
308                ),
309            )
310        );
311        $before_link = wp_kses( $args['before'], wp_kses_allowed_html( 'post' ) );
312        $after_link  = wp_kses( $args['after'], wp_kses_allowed_html( 'post' ) );
313
314        $reply_url = esc_url( add_query_arg( 'replytocom', $comment->comment_ID . '#' . $respond_id ) );
315
316        return <<<HTML
317            $before_link
318            <a class="comment-reply-link" href="$reply_url" onclick="return addComment.moveForm( '$add_below-$comment->comment_ID', '$comment->comment_ID', '$respond_id', '$post->ID' )">$reply_text</a>
319            $after_link
320HTML;
321    }
322
323    /**
324     * Get the site's blog token.
325     * This can be used to bypass Comments entirely if Jetpack is not properly connected.
326     *
327     * @since 11.2
328     *
329     * @return bool|object False if not properly connected. Object with the blog token if connected.
330     */
331    private function get_blog_token() {
332        $blog_token = ( new Tokens() )->get_access_token();
333        // If we have no token, bail.
334        if ( ! $blog_token || is_wp_error( $blog_token ) ) {
335            return false;
336        }
337
338        return $blog_token;
339    }
340
341    /** Output Methods ********************************************************/
342
343    /**
344     * Start capturing the core comment_form() output
345     *
346     * Comment form output will only be captured if comments are enabled - we return otherwise.
347     *
348     * @since 1.4
349     */
350    public function comment_form_before() {
351        /**
352         * Filters the setting that determines if Jetpack comments should be enabled for
353         * the current post type.
354         *
355         * @module comments
356         *
357         * @since  3.8.1
358         *
359         * @param boolean $return Should comments be enabled?
360         */
361        if ( ! apply_filters( 'jetpack_comment_form_enabled_for_' . get_post_type(), true ) ) {
362            return;
363        }
364
365        // If the Jetpack connection is not healthy, bail.
366        if ( ! $this->get_blog_token() ) {
367            return;
368        }
369
370        // Add some JS to the footer.
371        add_action( 'wp_footer', array( $this, 'watch_comment_parent' ), 100 );
372
373        ob_start();
374    }
375
376    /**
377     * Noop the default comment form output, get some options, and output our
378     * tricked out totally radical comment form.
379     *
380     * @since 1.4
381     */
382    public function comment_form_after() {
383        /** This filter is documented in modules/comments/comments.php */
384        if ( ! apply_filters( 'jetpack_comment_form_enabled_for_' . get_post_type(), true ) ) {
385            return;
386        }
387
388        $blog_token = $this->get_blog_token();
389        // If the Jetpack connection is not healthy, bail.
390        if ( ! $blog_token ) {
391            return;
392        }
393
394        // Throw it all out and drop in our replacement.
395        ob_end_clean();
396
397        if ( in_array( 'subscriptions', Jetpack::get_active_modules(), true ) ) {
398            $stb_enabled = get_option( 'stb_enabled', 1 );
399            $stb_enabled = empty( $stb_enabled ) ? 0 : 1;
400
401            $stc_enabled = get_option( 'stc_enabled', 1 );
402            $stc_enabled = empty( $stc_enabled ) ? 0 : 1;
403        } else {
404            $stb_enabled = 0;
405            $stc_enabled = 0;
406        }
407
408        $params = array(
409            'blogid'                 => Jetpack_Options::get_option( 'id' ),
410            'postid'                 => get_the_ID(),
411            'comment_registration'   => ( get_option( 'comment_registration' ) ? '1' : '0' ), // Need to explicitly send a '1' or a '0' for these.
412            'require_name_email'     => ( get_option( 'require_name_email' ) ? '1' : '0' ),
413            'stc_enabled'            => $stc_enabled,
414            'stb_enabled'            => $stb_enabled,
415            'show_avatars'           => ( get_option( 'show_avatars' ) ? '1' : '0' ),
416            'avatar_default'         => get_option( 'avatar_default' ),
417            'greeting'               => get_option( 'highlander_comment_form_prompt', __( 'Leave a Reply', 'jetpack' ) ),
418            'jetpack_comments_nonce' => wp_create_nonce( 'jetpack_comments_nonce-' . get_the_ID() ),
419            /**
420             * Changes the comment form prompt.
421             *
422             * @module comments
423             *
424             * @since  2.3.0
425             *
426             * @param string $var Default is "Leave a Reply to %s."
427             */
428            'greeting_reply'         => apply_filters(
429                'jetpack_comment_form_prompt_reply',
430                /* translators: %s is the displayed username of the post (or comment) author */
431                __( 'Leave a Reply to %s', 'jetpack' )
432            ),
433            'color_scheme'           => get_option( 'jetpack_comment_form_color_scheme', $this->default_color_scheme ),
434            'lang'                   => get_locale(),
435            'jetpack_version'        => JETPACK__VERSION,
436            'iframe_unique_id'       => wp_unique_id(),
437        );
438
439        // Extra parameters for logged in user.
440        if ( is_user_logged_in() ) {
441            $current_user           = wp_get_current_user();
442            $params['hc_post_as']   = 'jetpack';
443            $params['hc_userid']    = $current_user->ID;
444            $params['hc_username']  = $current_user->display_name;
445            $params['hc_userurl']   = $current_user->user_url;
446            $params['hc_useremail'] = md5( strtolower( trim( $current_user->user_email ) ) );
447            if ( current_user_can( 'unfiltered_html' ) ) {
448                $params['_wp_unfiltered_html_comment'] = wp_create_nonce( 'unfiltered-html-comment_' . get_the_ID() );
449            }
450        } else {
451            $commenter                     = wp_get_current_commenter();
452            $params['show_cookie_consent'] = (int) has_action( 'set_comment_cookies', 'wp_set_comment_cookies' );
453            $params['has_cookie_consent']  = (int) ! empty( $commenter['comment_author_email'] );
454            // Jetpack_Memberships for logged out users only checks for the wp-jp-premium-content-session cookie
455            $params['is_current_user_subscribed'] = class_exists( '\Jetpack_Memberships' ) ? (int) Jetpack_Memberships::is_current_user_subscribed() : 0;
456        }
457
458        list( $token_key ) = explode( '.', $blog_token->secret, 2 );
459        // Prophylactic check: anything else should never happen.
460        if ( $token_key && $token_key !== $blog_token->secret ) {
461            // Is the token a Special Token (@see class.tokens.php)?
462            if ( preg_match( '/^;.\d+;\d+;$/', $token_key, $matches ) ) {
463                // The token key for a Special Token is public.
464                $params['token_key'] = $token_key;
465            } else {
466                /*
467                 * The token key for a Normal Token is public but
468                 * looks like sensitive data. Since there can only be
469                 * one Normal Token per site, avoid concern by
470                 * sending the magic "use the Normal Token" token key.
471                 */
472                $params['token_key'] = Tokens::MAGIC_NORMAL_TOKEN_KEY;
473            }
474        }
475
476        $signature = self::sign_remote_comment_parameters( $params, $blog_token->secret );
477        if ( is_wp_error( $signature ) ) {
478            $signature = 'error';
479        }
480
481        $params['sig'] = $signature;
482        $url_origin    = 'https://jetpack.wordpress.com';
483        $url           = "{$url_origin}/jetpack-comment/?" . http_build_query( $params );
484        // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Sniff misses the esc_url_raw.
485        $url              = "{$url}#parent=" . rawurlencode( esc_url_raw( set_url_scheme( 'http://' . ( isset( $_SERVER['HTTP_HOST'] ) ? wp_unslash( $_SERVER['HTTP_HOST'] ) : '' ) . ( isset( $_SERVER['REQUEST_URI'] ) ? wp_unslash( $_SERVER['REQUEST_URI'] ) : '' ) ) ) );
486        $this->signed_url = $url;
487        $height           = $params['comment_registration'] || is_user_logged_in() ? '315' : '430'; // Iframe can be shorter if we're not allowing guest commenting.
488        $transparent      = ( 'transparent' === $params['color_scheme'] ) ? 'true' : 'false';
489
490        if ( isset( $_GET['replytocom'] ) ) { //phpcs:ignore WordPress.Security.NonceVerification.Recommended
491            $url .= '&replytocom=' . (int) $_GET['replytocom']; //phpcs:ignore WordPress.Security.NonceVerification.Recommended
492        }
493
494        /**
495         * Filter whether the comment title can be displayed.
496         *
497         * @module comments
498         *
499         * @since  4.7.0
500         *
501         * @param bool $show Can the comment be displayed? Default to true.
502         */
503        $show_greeting = apply_filters( 'jetpack_comment_form_display_greeting', true );
504
505        /**
506         * Filter the comment title tag.
507         *
508         * @module comments
509         * @since 12.4
510         *
511         * @param string $comment_reply_title_tag The comment title tag. Default to h3.
512         */
513        $comment_reply_title_tag = apply_filters( 'jetpack_comment_reply_title_tag', 'h3' );
514
515        // The actual iframe (loads comment form from Jetpack server).
516
517        $is_amp = class_exists( Jetpack_AMP_Support::class ) && Jetpack_AMP_Support::is_amp_request();
518        ?>
519
520        <div id="respond" class="comment-respond">
521            <?php
522            if ( true === $show_greeting ) :
523                printf(
524                    '<%1$s id="reply-title" class="comment-reply-title">',
525                    esc_html( $comment_reply_title_tag )
526                );
527
528                comment_form_title(
529                    esc_html( $params['greeting'] ),
530                    esc_html( $params['greeting_reply'] )
531                );
532                echo '<small>';
533                cancel_comment_reply_link( esc_html__( 'Cancel reply', 'jetpack' ) );
534                echo '</small>';
535
536                printf(
537                    '</%1$s>',
538                    esc_html( $comment_reply_title_tag )
539                );
540            endif;
541            ?>
542            <form id="commentform" class="comment-form">
543                <iframe
544                    title="<?php esc_attr_e( 'Comment Form', 'jetpack' ); ?>"
545                    src="<?php echo esc_url( $url ); ?>"
546                    <?php if ( $is_amp ) : ?>
547                        resizable
548                        layout="fixed-height"
549                        height="<?php echo esc_attr( $height ); ?>"
550                    <?php else : ?>
551                        name="jetpack_remote_comment"
552                        style="width:100%; height: <?php echo esc_attr( $height ); ?>px; border:0;"
553                    <?php endif; ?>
554                    class="jetpack_remote_comment"
555                    id="jetpack_remote_comment"
556                    sandbox="allow-same-origin allow-top-navigation allow-scripts allow-forms allow-popups"
557                >
558                    <?php if ( $is_amp ) : ?>
559                        <button overflow><?php esc_html_e( 'Show more', 'jetpack' ); ?></button>
560                    <?php endif; ?>
561                </iframe>
562                <?php if ( ! $is_amp ) : ?>
563                    <!--[if !IE]><!-->
564                    <script>
565                        document.addEventListener('DOMContentLoaded', function () {
566                            var commentForms = document.getElementsByClassName('jetpack_remote_comment');
567                            for (var i = 0; i < commentForms.length; i++) {
568                                commentForms[i].allowTransparency = <?php echo esc_html( $transparent ); ?>;
569                                commentForms[i].scrolling = 'no';
570                            }
571                        });
572                    </script>
573                    <!--<![endif]-->
574                <?php endif; ?>
575            </form>
576        </div>
577
578        <?php // Below is required for comment reply JS to work. ?>
579
580        <input type="hidden" name="comment_parent" id="comment_parent" value="" />
581
582        <?php
583    }
584
585    /**
586     * Add some JS to wp_footer to watch for hierarchical reply parent change
587     *
588     * If AMP is enabled, we don't make any changes.
589     *
590     * @since 1.4
591     */
592    public function watch_comment_parent() {
593        if ( class_exists( Jetpack_AMP_Support::class ) && Jetpack_AMP_Support::is_amp_request() ) {
594            // @todo Implement AMP support.
595            return;
596        }
597        ?>
598        <script type="text/javascript">
599            (function () {
600                const iframe = document.getElementById( 'jetpack_remote_comment' );
601                <?php if ( get_option( 'thread_comments' ) && get_option( 'thread_comments_depth' ) ) : ?>
602                const watchReply = function() {
603                    // Check addComment._Jetpack_moveForm to make sure we don't monkey-patch twice.
604                    if ( 'undefined' !== typeof addComment && ! addComment._Jetpack_moveForm ) {
605                        // Cache the Core function.
606                        addComment._Jetpack_moveForm = addComment.moveForm;
607                        const commentParent = document.getElementById( 'comment_parent' );
608                        const cancel = document.getElementById( 'cancel-comment-reply-link' );
609
610                        function tellFrameNewParent ( commentParentValue ) {
611                            const url = new URL( iframe.src );
612                            if ( commentParentValue ) {
613                                url.searchParams.set( 'replytocom', commentParentValue )
614                            } else {
615                                url.searchParams.delete( 'replytocom' );
616                            }
617                            if( iframe.src !== url.href ) {
618                                iframe.src = url.href;
619                            }
620                        };
621
622                        cancel.addEventListener( 'click', function () {
623                            tellFrameNewParent( false );
624                        } );
625
626                        addComment.moveForm = function ( _, parentId ) {
627                            tellFrameNewParent( parentId );
628                            return addComment._Jetpack_moveForm.apply( null, arguments );
629                        };
630                    }
631                }
632                document.addEventListener( 'DOMContentLoaded', watchReply );
633                // In WP 6.4+, the script is loaded asynchronously, so we need to wait for it to load before we monkey-patch the functions it introduces.
634                document.querySelector('#comment-reply-js')?.addEventListener( 'load', watchReply );
635
636                <?php endif; ?>
637                
638                const commentIframes = document.getElementsByClassName('jetpack_remote_comment');
639
640                window.addEventListener('message', function(event) {
641                    if (event.origin !== 'https://jetpack.wordpress.com') {
642                        return;
643                    }
644
645                    if (!event?.data?.iframeUniqueId && !event?.data?.height) {
646                        return;
647                    }
648
649                    const eventDataUniqueId = event.data.iframeUniqueId;
650
651                    // Change height for the matching comment iframe
652                    for (let i = 0; i < commentIframes.length; i++) {
653                        const iframe = commentIframes[i];
654                        const url = new URL(iframe.src);
655                        const iframeUniqueIdParam = url.searchParams.get('iframe_unique_id');
656                        if (iframeUniqueIdParam == event.data.iframeUniqueId) {
657                            iframe.style.height = event.data.height + 'px';
658                            return;
659                        }
660                    }
661                });
662            })();
663        </script>
664        <?php
665    }
666
667    /**
668     * Verify the hash included in remote comments.
669     *
670     * If the Jetpack token is missing we return nothing,
671     * and if the token is unknown or invalid, or comments not allowed, an error is returned.
672     *
673     * @since 1.4
674     */
675    public function pre_comment_on_post() {
676        $post_array = stripslashes_deep( $_POST );
677
678        // Bail if missing the Jetpack token.
679        if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) || ! is_string( $post_array['sig'] ) || ! is_string( $post_array['token_key'] ) ) {
680            unset( $_POST['hc_post_as'] );
681            return;
682        }
683
684        if ( empty( $post_array['jetpack_comments_nonce'] ) || ! wp_verify_nonce( $post_array['jetpack_comments_nonce'], "jetpack_comments_nonce-{$post_array['comment_post_ID']}" ) ) {
685            if ( ! isset( $_GET['only_once'] ) ) {
686                self::retry_submit_comment_form_locally();
687            }
688            wp_die( esc_html__( 'Nonce verification failed.', 'jetpack' ), 400 );
689        }
690
691        if ( isset( $post_array['hc_avatar'] ) && is_string( $post_array['hc_avatar'] ) && str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
692            $post_array['hc_avatar'] = htmlentities( $post_array['hc_avatar'], ENT_COMPAT );
693        }
694
695        $blog_token = ( new Tokens() )->get_access_token( false, $post_array['token_key'] );
696        if ( ! $blog_token || is_wp_error( $blog_token ) ) {
697            wp_die( esc_html__( 'Unknown security token.', 'jetpack' ), 400 );
698        }
699        $check = self::sign_remote_comment_parameters( $post_array, $blog_token->secret );
700        if ( is_wp_error( $check ) ) {
701            wp_die( esc_html( $check ) );
702        }
703
704        // Bail if token is expired or not valid.
705        if ( ! hash_equals( $check, $post_array['sig'] ) ) {
706            wp_die( esc_html__( 'Invalid security token.', 'jetpack' ), 400 );
707        }
708
709        /** This filter is documented in modules/comments/comments.php */
710        if ( ! apply_filters( 'jetpack_comment_form_enabled_for_' . get_post_type( $post_array['comment_post_ID'] ), true ) ) {
711            // In case the comment POST is legit, but the comments are
712            // now disabled, we don't allow the comment.
713
714            wp_die( esc_html__( 'Comments are not allowed.', 'jetpack' ), 403 );
715        }
716    }
717
718    /**
719     * Handle Jetpack Comments POST requests: process the comment form, then client-side POST the results to the self-hosted blog
720     *
721     * This function exists because when we submit the form via the jetpack.wordpress.com iframe
722     * in Chrome the request comes in to Jetpack but for some reason the request doesn't have access to cookies yet.
723     * By submitting the form again locally with the same data the process works as expected.
724     *
725     * @return never
726     */
727    public function retry_submit_comment_form_locally() {
728        // We are not doing any validation here since all the validation will be done again by pre_comment_on_post().
729        // phpcs:ignore WordPress.Security.NonceVerification.Missing
730        $comment_data = stripslashes_deep( $_POST );
731        ?>
732        <!DOCTYPE html>
733        <html>
734        <head>
735        <meta charset="utf-8">
736        <title><?php echo esc_html__( 'Submitting Comment', 'jetpack' ); ?></title>
737        <style type="text/css">
738            body {
739                display: table;
740                width: 100%;
741                height: 60%;
742                position: absolute;
743                top: 0;
744                left: 0;
745                overflow: hidden;
746                color: #333;
747            }
748            .jetpack-comment-spinner {
749                display: table-cell;
750                vertical-align: middle;
751                text-align: center;
752            }
753        </style>
754        </head>
755        <body>
756        <div class="jetpack-comment-spinner">
757            <?php
758            require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-spinner.php';
759            echo Jetpack_Spinner::render( 28 ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- static SVG markup.
760            ?>
761        </div>
762        <form id="jetpack-remote-comment-post-form" action="<?php echo esc_url( get_site_url() ); ?>/wp-comments-post.php?for=jetpack&only_once=true" method="POST">
763            <?php foreach ( $comment_data as $key => $val ) : ?>
764                <input type="hidden" name="<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $val ); ?>" />
765            <?php endforeach; ?>
766        </form>
767
768        <script type="text/javascript">
769            document.getElementById("jetpack-remote-comment-post-form").submit();
770        </script>
771        </body>
772        </html>
773        <?php
774        exit( 0 );
775    }
776
777    /** Capabilities **********************************************************/
778
779    /**
780     * Add some additional comment meta after comment is saved about what
781     * service the comment is from, the avatar, user_id, etc...
782     *
783     * @since 1.4
784     *
785     * @param int $comment_id The comment ID.
786     */
787    public function add_comment_meta( $comment_id ) {
788        // phpcs:disable WordPress.Security.NonceVerification.Missing -- The hc_* fields are authenticated by the HMAC check below.
789        $post_array = stripslashes_deep( $_POST );
790
791        // The hc_* identity fields are only trustworthy on a signed request. pre_comment_on_post() checks
792        // that, but only on wp-comments-post.php, so re-check here for any other producer that reaches
793        // comment_post (e.g. Carousel's unauthenticated post_attachment_comment endpoint).
794        if ( ! isset( $post_array['sig'] ) || ! isset( $post_array['token_key'] ) || ! is_string( $post_array['sig'] ) || ! is_string( $post_array['token_key'] ) ) {
795            return;
796        }
797        if ( isset( $post_array['hc_avatar'] ) && is_string( $post_array['hc_avatar'] ) && str_contains( $post_array['hc_avatar'], '.gravatar.com' ) ) {
798            $post_array['hc_avatar'] = htmlentities( $post_array['hc_avatar'], ENT_COMPAT );
799        }
800        $blog_token = ( new Tokens() )->get_access_token( false, $post_array['token_key'] );
801        if ( ! $blog_token || is_wp_error( $blog_token ) ) {
802            return;
803        }
804        $check = self::sign_remote_comment_parameters( $post_array, $blog_token->secret );
805        if ( is_wp_error( $check ) || ! hash_equals( $check, $post_array['sig'] ) ) {
806            return;
807        }
808
809        $comment_meta = array();
810
811        switch ( $this->is_highlander_comment_post() ) {
812            case 'facebook':
813                $comment_meta['hc_post_as']         = 'facebook';
814                $comment_meta['hc_avatar']          = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
815                $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
816                break;
817
818            // phpcs:ignore WordPress.WP.CapitalPDangit
819            case 'wordpress':
820                // phpcs:ignore WordPress.WP.CapitalPDangit
821                $comment_meta['hc_post_as']         = 'wordpress';
822                $comment_meta['hc_avatar']          = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
823                $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
824                $comment_meta['hc_wpcom_id_sig']    = isset( $_POST['hc_wpcom_id_sig'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_wpcom_id_sig'] ) ) : null; // since 1.9.
825                break;
826
827            case 'jetpack':
828                $comment_meta['hc_post_as']         = 'jetpack';
829                $comment_meta['hc_avatar']          = isset( $_POST['hc_avatar'] ) ? esc_url_raw( wp_unslash( $_POST['hc_avatar'] ) ) : null;
830                $comment_meta['hc_foreign_user_id'] = isset( $_POST['hc_userid'] ) ? sanitize_text_field( wp_unslash( $_POST['hc_userid'] ) ) : null;
831                break;
832
833        }
834        // phpcs:enable WordPress.Security.NonceVerification.Missing
835
836        // Bail if no extra comment meta.
837        if ( empty( $comment_meta ) ) {
838            return;
839        }
840
841        // Loop through extra meta and add values.
842        foreach ( $comment_meta as $key => $value ) {
843            add_comment_meta( $comment_id, $key, $value, true );
844        }
845    }
846
847    /**
848     * Should show the subscription modal
849     *
850     * @return boolean
851     */
852    public function should_show_subscription_modal() {
853
854        // Not allow it to run on self-hosted or simple sites
855        if ( ! ( new Host() )->is_wpcom_platform() || ( new Host() )->is_wpcom_simple() ) {
856            return false;
857        }
858
859        // phpcs:disable WordPress.Security.NonceVerification.Missing
860        $is_current_user_subscribed = isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
861
862        // Atomic sites with jetpack_verbum_subscription_modal option enabled
863        $modal_enabled = ( new Host() )->is_woa_site() && get_option( 'jetpack_verbum_subscription_modal', true );
864
865        return $modal_enabled && ! $is_current_user_subscribed;
866    }
867
868    /**
869     * Get the data to send as an event to the parent window on subscription modal
870     *
871     * @param string $url url to redirect to.
872     *
873     * @return array
874     */
875    public function get_subscription_modal_data_to_parent( $url ) {
876        // phpcs:ignore WordPress.Security.NonceVerification.Missing
877        $current_user_email = isset( $_POST['email'] ) ? filter_var( wp_unslash( $_POST['email'] ) ) : null;
878        // phpcs:ignore WordPress.Security.NonceVerification.Missing
879        $post_id = isset( $_POST['comment_post_ID'] ) ? filter_var( wp_unslash( $_POST['comment_post_ID'] ) ) : null;
880        return array(
881            'url'          => $url,
882            'email'        => $current_user_email,
883            'blog_id'      => esc_attr( \Jetpack_Options::get_option( 'id' ) ),
884            'post_id'      => esc_attr( $post_id ),
885            'lang'         => esc_attr( get_locale() ),
886            'is_logged_in' => isset( $_POST['hc_userid'] ),
887        );
888    }
889
890    /**
891     * Track the hidden event for the subscription modal
892     */
893    public function subscription_modal_status_track_event() {
894        $tracking_event = 'hidden_disabled';
895        // Not allow it to run on self-hosted or simple sites
896        if ( ! ( new Host() )->is_wpcom_platform() || ( new Host() )->is_wpcom_simple() ) {
897            $tracking_event = 'hidden_self_hosted';
898        }
899
900        // phpcs:disable WordPress.Security.NonceVerification.Missing
901        $is_current_user_subscribed = isset( $_POST['is_current_user_subscribed'] ) ? filter_var( wp_unslash( $_POST['is_current_user_subscribed'] ) ) : null;
902
903        if ( $is_current_user_subscribed ) {
904            $tracking_event = 'hidden_already_subscribed';
905        }
906
907        $jetpack = Jetpack::init();
908        // $jetpack->stat automatically prepends the stat group with 'jetpack-'
909        $jetpack->stat( 'subscribe-modal-comm', $tracking_event );
910        $jetpack->do_stats( 'server_side' );
911    }
912
913    /**
914     * Catch the duplicated comment error and show a custom error page
915     *
916     * @return never
917     */
918    public function capture_comment_duplicate_trigger() {
919        if ( ! isset( $_GET['for'] ) || 'jetpack' !== $_GET['for'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
920            exit( 0 );
921        }
922
923        ?>
924        <!DOCTYPE html>
925        <html <?php language_attributes(); ?>>
926        <!--<![endif]-->
927        <head>
928            <meta charset="<?php bloginfo( 'charset' ); ?>" />
929            <title>
930                <?php
931                    wp_kses_post(
932                        printf(
933                            /* translators: %s is replaced by an ellipsis */
934                            __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
935                            '&hellip;'
936                        )
937                    );
938                ?>
939                </title>
940            <style type="text/css">
941                body {
942                    display: table;
943                    width: 100%;
944                    height: 60%;
945                    position: absolute;
946                    top: 0;
947                    left: 0;
948                    overflow: hidden;
949                    color: #333;
950                    padding-top: 3%;
951                }
952                div {
953                    text-align: left;
954                    margin: 0;
955                    padding: 0;
956                    display: table-cell;
957                    vertical-align: top;
958                    font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
959                    font-weight: normal;
960                }
961
962                h3 {
963                    margin: 0;
964                    padding-bottom: 3%;
965                    font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
966                    font-weight: normal;
967                }
968                a {
969                    text-decoration: underline;
970                    color: #333 !important;
971                }
972            </style>
973        </head>
974        <body>
975        <div>
976            <h3>
977                <?php
978                    esc_html_e( 'Duplicate comment detected; it looks as though you’ve already said that!', 'jetpack' );
979                ?>
980            </h3>
981            <a href="javascript:backToComments()"><?php esc_html_e( '&laquo; Back', 'jetpack' ); ?></a>
982        </div>
983        <script type="text/javascript">
984            function backToComments() {
985                const test = regexp => {
986                        return regexp.test(navigator.userAgent);
987                };
988                if (test(/chrome|chromium|crios|safari|edg/i)) {
989                        history.go(-2);
990                        return;
991                }
992                history.back();
993            }
994        </script>
995
996        </body>
997        </html>
998        <?php
999        exit( 0 );
1000    }
1001
1002    /**
1003     * POST the submitted comment to the iframe
1004     *
1005     * @param string $url The comment URL origin.
1006     */
1007    public function capture_comment_post_redirect_to_reload_parent_frame( $url ) {
1008        if ( ! isset( $_GET['for'] ) || 'jetpack' !== $_GET['for'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1009            return $url;
1010        }
1011
1012        $should_show_subscription_modal = $this->should_show_subscription_modal();
1013
1014        // Track event when not showing the subscription modal
1015        if ( ! $should_show_subscription_modal ) {
1016            $this->subscription_modal_status_track_event();
1017        }
1018        ?>
1019        <!DOCTYPE html>
1020        <html <?php language_attributes(); ?>>
1021        <!--<![endif]-->
1022        <head>
1023            <meta charset="<?php bloginfo( 'charset' ); ?>" />
1024            <title>
1025                <?php
1026                    wp_kses_post(
1027                        printf(
1028                            /* translators: %s is replaced by an ellipsis */
1029                            __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1030                            '&hellip;'
1031                        )
1032                    );
1033                ?>
1034                </title>
1035            <style type="text/css">
1036                body {
1037                    display: table;
1038                    width: 100%;
1039                    height: 60%;
1040                    position: absolute;
1041                    top: 0;
1042                    left: 0;
1043                    overflow: hidden;
1044                    color: #333;
1045                    padding-top: 3%;
1046                }
1047
1048                h3 {
1049                    text-align: center;
1050                    margin: 0;
1051                    padding: 0;
1052                    display: table-cell;
1053                    vertical-align: top;
1054                    font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", sans-serif;
1055                    font-weight: normal;
1056                }
1057
1058                .hidden {
1059                    opacity: 0;
1060                }
1061
1062                h3 span {
1063                    -moz-transition-property: opacity;
1064                    -moz-transition-duration: 1s;
1065                    -moz-transition-timing-function: ease-in-out;
1066
1067                    -webkit-transition-property: opacity;
1068                    -webkit-transition-duration: 1s;
1069                    -webbit-transition-timing-function: ease-in-out;
1070
1071                    -o-transition-property: opacity;
1072                    -o-transition-duration: 1s;
1073                    -o-transition-timing-function: ease-in-out;
1074
1075                    -ms-transition-property: opacity;
1076                    -ms-transition-duration: 1s;
1077                    -ms-transition-timing-function: ease-in-out;
1078
1079                    transition-property: opacity;
1080                    transition-duration: 1s;
1081                    transition-timing-function: ease-in-out;
1082                }
1083            </style>
1084        </head>
1085        <body>
1086        <?php if ( ! $should_show_subscription_modal ) { ?>
1087        <h3>
1088            <?php
1089                wp_kses_post(
1090                    printf(
1091                        /* translators: %s is replaced by HTML markup to include an ellipsis */
1092                        __( 'Submitting Comment%s', 'jetpack' ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1093                        '<span id="ellipsis" class="hidden">&hellip;</span>'
1094                    )
1095                );
1096            ?>
1097        </h3>
1098        <script type="text/javascript">
1099            try {
1100                window.parent.location.href = <?php echo wp_json_encode( $url, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>;
1101                window.parent.location.reload( true );
1102            } catch (e) {
1103                window.location.href = <?php echo wp_json_encode( $url, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>;
1104                window.location.reload( true );
1105            }
1106            ellipsis = document.getElementById('ellipsis');
1107
1108            function toggleEllipsis() {
1109                ellipsis.className = ellipsis.className ? '' : 'hidden';
1110            }
1111
1112            setInterval(toggleEllipsis, 1200);
1113        </script>
1114        <?php } else { ?>
1115        <h3>
1116            <?php
1117                wp_kses_post(
1118                    print __( 'Comment sent', 'jetpack' ) // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1119                );
1120            ?>
1121        </h3>
1122        <script type="text/javascript">
1123            if ( window.parent && window.parent !== window ) {
1124
1125                window.parent.postMessage(
1126                    {
1127                        type: 'subscriptionModalShow',
1128                        data: <?php echo wp_json_encode( $this->get_subscription_modal_data_to_parent( $url ), JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ); ?>,
1129                    },
1130                    window.location.origin
1131                );
1132            }
1133        </script>
1134        <?php } ?>
1135        </body>
1136        </html>
1137        <?php
1138        exit( 0 );
1139    }
1140}
1141
1142Jetpack_Comments::init();