Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
87.23% covered (warning)
87.23%
451 / 517
62.50% covered (warning)
62.50%
25 / 40
CRAP
0.00% covered (danger)
0.00%
0 / 1
Jetpack_Backup
87.57% covered (warning)
87.57%
451 / 515
62.50% covered (warning)
62.50%
25 / 40
126.16
0.00% covered (danger)
0.00%
0 / 1
 initialize
100.00% covered (success)
100.00%
10 / 10
100.00% covered (success)
100.00%
1 / 1
3
 init_standalone_connection
45.00% covered (danger)
45.00%
9 / 20
0.00% covered (danger)
0.00%
0 / 1
1.17
 add_wp_admin_submenu
100.00% covered (success)
100.00%
20 / 20
100.00% covered (success)
100.00%
1 / 1
5
 admin_init
66.67% covered (warning)
66.67%
4 / 6
0.00% covered (danger)
0.00%
0 / 1
3.33
 maybe_upgrade_db
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
6
 can_use_analytics
100.00% covered (success)
100.00%
4 / 4
100.00% covered (success)
100.00%
1 / 1
1
 enqueue_admin_scripts
95.00% covered (success)
95.00%
19 / 20
0.00% covered (danger)
0.00%
0 / 1
5
 plugin_settings_page
0.00% covered (danger)
0.00%
0 / 2
0.00% covered (danger)
0.00%
0 / 1
2
 get_initial_state
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
1
 register_rest_routes
100.00% covered (success)
100.00%
129 / 129
100.00% covered (success)
100.00%
1 / 1
1
 backups_permissions_callback
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
1
 get_failed_fetch_error
100.00% covered (success)
100.00%
7 / 7
100.00% covered (success)
100.00%
1 / 1
2
 get_recent_backups
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 get_rewind_state_from_wpcom
93.75% covered (success)
93.75%
15 / 16
0.00% covered (danger)
0.00%
0 / 1
5.01
 get_backup_plan_state
100.00% covered (success)
100.00%
4 / 4
100.00% covered (success)
100.00%
1 / 1
2
 has_backup_plan
100.00% covered (success)
100.00%
2 / 2
100.00% covered (success)
100.00%
1 / 1
2
 get_backup_capabilities
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 get_recent_restores
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 list_backup_events
100.00% covered (success)
100.00%
24 / 24
100.00% covered (success)
100.00%
1 / 1
2
 get_backup_promoted_product_info
100.00% covered (success)
100.00%
27 / 27
100.00% covered (success)
100.00%
1 / 1
6
 jetpack_check_user_licenses
87.50% covered (warning)
87.50%
7 / 8
0.00% covered (danger)
0.00%
0 / 1
6.07
 get_site_current_purchases
0.00% covered (danger)
0.00%
0 / 10
0.00% covered (danger)
0.00%
0 / 1
30
 manage_dismissed_backup_review_request
80.00% covered (warning)
80.00%
4 / 5
0.00% covered (danger)
0.00%
0 / 1
2.03
 get_site_backup_size
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 get_site_backup_policies
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 get_storage_addon_upsell_slug
100.00% covered (success)
100.00%
22 / 22
100.00% covered (success)
100.00%
1 / 1
6
 get_site_backup_addon_offer
0.00% covered (danger)
0.00%
0 / 16
0.00% covered (danger)
0.00%
0 / 1
2
 enqueue_backup
100.00% covered (success)
100.00%
17 / 17
100.00% covered (success)
100.00%
1 / 1
2
 get_site_backup_schedule_time
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 plugin_deactivation
0.00% covered (danger)
0.00%
0 / 2
0.00% covered (danger)
0.00%
0 / 1
2
 maybe_load_wp_build
83.33% covered (warning)
83.33%
5 / 6
0.00% covered (danger)
0.00%
0 / 1
4.07
 render_connection_initial_state
100.00% covered (success)
100.00%
3 / 3
100.00% covered (success)
100.00%
1 / 1
1
 load_wp_build
27.27% covered (danger)
27.27%
3 / 11
0.00% covered (danger)
0.00%
0 / 1
3.54
 load_wp_build_with_screen_alias
75.00% covered (warning)
75.00%
9 / 12
0.00% covered (danger)
0.00%
0 / 1
2.06
 alias_screen_id_for_wp_build
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
2
 restore_screen_id_after_wp_build
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
3
 is_modernized
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
1
 is_internal_preview
100.00% covered (success)
100.00%
7 / 7
100.00% covered (success)
100.00%
1 / 1
7
 is_wp_build_dashboard_active
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
2
 is_backup_admin_request
66.67% covered (warning)
66.67%
2 / 3
0.00% covered (danger)
0.00%
0 / 1
3.33
1<?php
2/**
3 * Primary class file for the Jetpack Backup plugin.
4 *
5 * @package automattic/jetpack-backup-plugin
6 */
7
8// After changing this file, consider increasing the version number ("VXXX") in all the files using this namespace, in
9// order to ensure that the specific version of this file always get loaded. Otherwise, Jetpack autoloader might decide
10// to load an older/newer version of the class (if, for example, both the standalone and bundled versions of the plugin
11// are installed, or in some other cases).
12namespace Automattic\Jetpack\Backup\V0005;
13
14if ( ! defined( 'ABSPATH' ) ) {
15    exit( 0 );
16}
17
18use Automattic\Jetpack\Admin_UI\Admin_Menu;
19use Automattic\Jetpack\Assets;
20use Automattic\Jetpack\Backup\V0005\Initial_State as Backup_Initial_State;
21use Automattic\Jetpack\Config;
22use Automattic\Jetpack\Connection\Client;
23use Automattic\Jetpack\Connection\Initial_State as Connection_Initial_State;
24use Automattic\Jetpack\Connection\Manager as Connection_Manager;
25use Automattic\Jetpack\Connection\Rest_Authentication as Connection_Rest_Authentication;
26use Automattic\Jetpack\Constants;
27use Automattic\Jetpack\JITMS\JITM;
28use Automattic\Jetpack\My_Jetpack\Wpcom_Products;
29use Automattic\Jetpack\Status;
30use Automattic\Jetpack\Terms_Of_Service;
31use Automattic\Jetpack\Tracking;
32use Jetpack_Options;
33use WP_Error;
34use WP_REST_Server;
35use function add_action;
36use function add_filter;
37use function did_action;
38use function do_action;
39use function esc_url_raw;
40use function get_option;
41use function is_wp_error;
42use function rest_ensure_response;
43use function update_option;
44use function wp_add_inline_script;
45use function wp_remote_get;
46use function wp_remote_retrieve_body;
47use function wp_remote_retrieve_response_code;
48
49/**
50 * Class Jetpack_Backup
51 */
52class Jetpack_Backup {
53
54    /**
55     * Slug.
56     *
57     * @var string
58     */
59    const JETPACK_BACKUP_SLUG = 'jetpack-backup';
60
61    /**
62     * Backup name.
63     *
64     * @var string
65     */
66    const JETPACK_BACKUP_NAME = 'Jetpack Backup';
67
68    /**
69     * Backup URL.
70     *
71     * @var string
72     */
73    const JETPACK_BACKUP_URI = 'https://jetpack.com/jetpack-backup';
74
75    /**
76     * Promoted product.
77     *
78     * @var string
79     */
80    const JETPACK_BACKUP_PROMOTED_PRODUCT = 'jetpack_backup_t1_yearly';
81
82    /**
83     * Transient key prefix for the cached promoted product.
84     *
85     * Suffixed with the locale: it is a query arg on the catalogue request, so
86     * one shared key would serve one reader's language to another.
87     *
88     * @var string
89     */
90    const PROMOTED_PRODUCT_TRANSIENT_PREFIX = 'jetpack_backup_promoted_product_';
91
92    /**
93     * How long a fetched promoted product stays cached.
94     *
95     * The catalogue turns over on a marketing schedule rather than a
96     * session's, so half a day bounds how stale a price can get.
97     *
98     * @var int
99     */
100    const PROMOTED_PRODUCT_CACHE_TTL = 12 * HOUR_IN_SECONDS;
101
102    /**
103     * Licenses product ID.
104     *
105     * @var string
106     */
107    const JETPACK_BACKUP_PRODUCT_IDS = array(
108        2014, // JETPACK_COMPLETE.
109        2015, // JETPACK_COMPLETE_MONTHLY.
110        2016, // JETPACK_SECURITY_TIER_1_YEARLY.
111        2017, // JETPACK_SECURITY_TIER_1_MONTHLY.
112        2019, // JETPACK_SECURITY_TIER_2_YEARLY.
113        2020, // JETPACK_SECURITY_TIER_2_MONTHLY.
114        2112, // JETPACK_BACKUP_TIER_1_YEARLY.
115        2113, // JETPACK_BACKUP_TIER_1_MONTHLY.
116        2114, // JETPACK_BACKUP_TIER_2_YEARLY.
117        2115, // JETPACK_BACKUP_TIER_2_MONTHLY.
118    );
119
120    /**
121     * Jetpack Backup DB version.
122     *
123     * @var string
124     */
125    const JETPACK_BACKUP_DB_VERSION = '2';
126
127    /**
128     * Filter name that gates the wp-build–based dashboard.
129     *
130     * When this filter returns true, "Jetpack > Backup" renders the new
131     * wp-build dashboard instead of the legacy React app.
132     */
133    const MODERNIZATION_FILTER = 'rsm_jetpack_ui_modernization_backup';
134
135    /**
136     * Blog sticker that takes a site out of the internal preview.
137     *
138     * Atomic sees it only if it is on WordPress.com's `atomic_site_stickers()` allowlist.
139     */
140    const LEGACY_DASHBOARD_STICKER = 'use-backup-legacy-dashboard';
141
142    /**
143     * Rewind state read from WordPress.com, memoized for the request.
144     *
145     * A class property and not a function static so tests can clear it.
146     *
147     * @var object|null
148     */
149    private static $rewind_state = null;
150
151    /**
152     * The screen ID alias_screen_id_for_wp_build() replaced, until it is restored.
153     *
154     * @var string|null
155     */
156    private static $wp_build_original_screen_id = null;
157
158    /**
159     * Initialization options.
160     *
161     * @var array
162     */
163    const DEFAULT_INIT_OPTIONS = array(
164        // A host that already ensured a connection under its own slug must not have it
165        // re-ensured here as `jetpack-backup`, which would rename the site's connection.
166        'manage_connection' => true,
167    );
168
169    /**
170     * Constructor.
171     *
172     * @param array $options Overrides for self::DEFAULT_INIT_OPTIONS.
173     */
174    public static function initialize( array $options = array() ) {
175        if ( did_action( 'jetpack_backup_initialized' ) ) {
176            return;
177        }
178
179        $options = array_merge( self::DEFAULT_INIT_OPTIONS, $options );
180
181        add_action( 'rest_api_init', array( __CLASS__, 'register_rest_routes' ) );
182        add_action( 'rest_api_init', array( \Automattic\Jetpack\Backup\V0005\REST\Rest_Controller::class, 'register_routes' ) );
183
184        add_action( 'admin_menu', array( __CLASS__, 'maybe_load_wp_build' ), 1 );
185        add_action( 'admin_menu', array( __CLASS__, 'add_wp_admin_submenu' ), 1 ); // Akismet uses 4, so we need to use 1 to ensure both menus are added when only they exist.
186
187        if ( $options['manage_connection'] ) {
188            self::init_standalone_connection();
189        }
190
191        // Jetpack Backup abilities are registered from `actions.php` at package
192        // autoload time so the surface is available in every consumer that
193        // loads this package (both the standalone Backup plugin and the
194        // Jetpack plugin), not only when `Jetpack_Backup::initialize()` runs.
195
196        /**
197         * Runs right after the Jetpack Backup package is initialized.
198         *
199         * @since 1.3.0
200         */
201        do_action( 'jetpack_backup_initialized' );
202    }
203
204    /**
205     * Set up the connection, sync and identity-crisis packages under the standalone plugin's slug.
206     */
207    private static function init_standalone_connection() {
208        // Set up the REST authentication hooks.
209        Connection_Rest_Authentication::init();
210
211        // Init Jetpack packages.
212        add_action(
213            'plugins_loaded',
214            function () {
215                $config = new Config();
216                // Connection package.
217                $config->ensure(
218                    'connection',
219                    array(
220                        'slug'     => self::JETPACK_BACKUP_SLUG,
221                        'name'     => self::JETPACK_BACKUP_NAME,
222                        'url_info' => self::JETPACK_BACKUP_URI,
223                    )
224                );
225                // Sync package.
226                $config->ensure( 'sync' );
227
228                // Identity crisis package.
229                $config->ensure( 'identity_crisis' );
230            },
231            1
232        );
233
234        add_action( 'plugins_loaded', array( __CLASS__, 'maybe_upgrade_db' ), 20 );
235
236        add_filter( 'jetpack_connection_user_has_license', array( __CLASS__, 'jetpack_check_user_licenses' ), 10, 3 );
237    }
238
239    /**
240     * The page to be added to submenu
241     */
242    public static function add_wp_admin_submenu() {
243        $wp_build_active = self::is_wp_build_dashboard_active();
244        $callback        = $wp_build_active
245            ? 'jetpack_backup_jetpack_backup_dashboard_wp_admin_render_page'
246            : array( __CLASS__, 'plugin_settings_page' );
247
248        // The relabel rides the modernized dashboard rather than the filter alone,
249        // so a fallback to the legacy page also falls back to the legacy title.
250        $page_title = $wp_build_active ? 'Jetpack VaultPress Backup' : 'Jetpack Backup';
251        $menu_title = $wp_build_active ? 'VaultPress Backup' : 'Backup'; // Product name, do not translate.
252
253        $page_suffix = Admin_Menu::add_menu(
254            $page_title,
255            $menu_title,
256            'manage_options',
257            self::JETPACK_BACKUP_SLUG,
258            $callback,
259            null,
260            array(
261                'product' => 'backup',
262                'key'     => 'jetpack-backup',
263            )
264        );
265
266        if ( $page_suffix ) {
267            add_action( 'load-' . $page_suffix, array( __CLASS__, 'admin_init' ) );
268        }
269    }
270
271    /**
272     * Initialize the admin resources.
273     */
274    public static function admin_init() {
275        add_action( 'admin_enqueue_scripts', array( __CLASS__, 'enqueue_admin_scripts' ) );
276
277        if ( self::is_wp_build_dashboard_active() ) {
278            // Notices reflow the dual-pane layout, so clear them but keep our own.
279            // An older jetpack-jitm may predate the helper; the fallback costs the JITM.
280            if ( method_exists( JITM::class, 'suppress_foreign_admin_notices' ) ) {
281                JITM::suppress_foreign_admin_notices();
282            } else {
283                remove_all_actions( 'admin_notices' );
284                remove_all_actions( 'all_admin_notices' );
285            }
286        }
287    }
288
289    /**
290     * Checks current version against version in code and run upgrades if we are running a new version
291     */
292    public static function maybe_upgrade_db() {
293        $current_db_version = get_option( 'jetpack_backup_db_version' );
294        if ( version_compare( $current_db_version, self::JETPACK_BACKUP_DB_VERSION, '<' ) ) {
295            update_option( 'jetpack_backup_db_version', self::JETPACK_BACKUP_DB_VERSION );
296            Jetpack_Backup_Upgrades::upgrade();
297        }
298    }
299
300    /**
301     * Returns whether we are in condition to track to use
302     * Analytics functionality like Tracks, MC, or GA.
303     */
304    public static function can_use_analytics() {
305        $status     = new Status();
306        $connection = new Connection_Manager( 'jetpack-backup' );
307        $tracking   = new Tracking( 'jetpack', $connection );
308
309        return $tracking->should_enable_tracking( new Terms_Of_Service(), $status );
310    }
311
312    /**
313     * Enqueue plugin admin scripts and styles.
314     */
315    public static function enqueue_admin_scripts() {
316        // This callback is registered via `load-{$page_suffix}` in `add_wp_admin_submenu()`,
317        // so it only fires on the Backup admin page — no need to re-check the page here.
318        if ( self::is_wp_build_dashboard_active() ) {
319            // The i18n loader is registered on every admin page by jetpack-assets but
320            // only enqueued when depended on; the esbuild bundles don't pull it in.
321            // Enqueue it here, before the early return, so the wp-build dashboard's
322            // init module can download its JS translation catalogs.
323            if ( wp_script_is( 'wp-jp-i18n-loader', 'registered' ) ) {
324                wp_enqueue_script( 'wp-jp-i18n-loader' );
325            }
326
327            // The esbuild bundles don't declare the Tracks client as a dependency
328            // either, so it never reaches the page on its own.
329            if ( self::can_use_analytics() ) {
330                Tracking::register_tracks_functions_scripts( true );
331            }
332
333            // wp-build manages its own enqueue pipeline. The legacy script and
334            // its initial state are skipped for the wp-build dashboard.
335            return;
336        }
337
338        Assets::register_script(
339            'jetpack-backup',
340            '../build/index.js',
341            __FILE__,
342            array(
343                'in_footer'  => true,
344                'textdomain' => 'jetpack-backup-pkg',
345            )
346        );
347        Assets::enqueue_script( 'jetpack-backup' );
348        // Initial JS state including JP Connection data.
349        wp_add_inline_script( 'jetpack-backup', self::get_initial_state(), 'before' );
350        Connection_Initial_State::render_script( 'jetpack-backup' );
351
352        // Load script for analytics.
353        if ( self::can_use_analytics() ) {
354            Tracking::register_tracks_functions_scripts( true );
355        }
356    }
357
358    /**
359     * Main plugin settings page.
360     */
361    public static function plugin_settings_page() {
362        ?>
363            <div id="jetpack-backup-root"></div>
364        <?php
365    }
366
367    /**
368     * Return the rendered initial state JavaScript code.
369     *
370     * @return string
371     */
372    private static function get_initial_state() {
373        return ( new Backup_Initial_State() )->render();
374    }
375
376    /**
377     * Register REST API
378     */
379    public static function register_rest_routes() {
380
381        // Get information on most recent 10 backups.
382        register_rest_route(
383            'jetpack/v4',
384            '/backups',
385            array(
386                'methods'             => WP_REST_Server::READABLE,
387                'callback'            => __CLASS__ . '::get_recent_backups',
388                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
389            )
390        );
391
392        // Get site backup/scan/anti-spam capabilities.
393        register_rest_route(
394            'jetpack/v4',
395            '/backup-capabilities',
396            array(
397                'methods'             => WP_REST_Server::READABLE,
398                'callback'            => __CLASS__ . '::get_backup_capabilities',
399                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
400            )
401        );
402
403        // Get whether the site has a backup plan
404        register_rest_route(
405            'jetpack/v4',
406            '/has-backup-plan',
407            array(
408                'methods'             => WP_REST_Server::READABLE,
409                'callback'            => __CLASS__ . '::get_backup_plan_state',
410                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
411            )
412        );
413
414        // Get site rewind data.
415        register_rest_route(
416            'jetpack/v4',
417            '/restores',
418            array(
419                'methods'             => WP_REST_Server::READABLE,
420                'callback'            => __CLASS__ . '::get_recent_restores',
421                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
422            )
423        );
424
425        // Get information on site products.
426        // Backup plugin version of /site/purchases from JP plugin.
427        // Revert once this route and MyPlan component are extracted to a common package.
428        register_rest_route(
429            'jetpack/v4',
430            '/site/current-purchases',
431            array(
432                'methods'             => WP_REST_Server::READABLE,
433                'callback'            => __CLASS__ . '::get_site_current_purchases',
434                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
435            )
436        );
437
438        // Get currently promoted product from the product's endpoint.
439            register_rest_route(
440                'jetpack/v4',
441                '/backup-promoted-product-info',
442                array(
443                    'methods'             => WP_REST_Server::READABLE,
444                    'callback'            => __CLASS__ . '::get_backup_promoted_product_info',
445                    'permission_callback' => __CLASS__ . '::backups_permissions_callback',
446                )
447            );
448
449        // Get and set value of dismissed_backup_review_request option
450        register_rest_route(
451            'jetpack/v4',
452            '/site/dismissed-review-request',
453            array(
454                'methods'             => WP_REST_Server::EDITABLE,
455                'callback'            => __CLASS__ . '::manage_dismissed_backup_review_request',
456                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
457                'args'                => array(
458                    'option_name'    => array(
459                        'required' => true,
460                        'type'     => 'string',
461                        // The two names `Jetpack_Options` recognises. Anything else
462                        // falls through its allowlist to a `trigger_error()` and is
463                        // stored nowhere, so an unlisted reason would dismiss
464                        // nothing while answering as though it had — and on a site
465                        // with `display_errors` on, the warning is printed ahead of
466                        // the JSON and the response no longer parses.
467                        'enum'     => array( 'restore', 'backups' ),
468                    ),
469                    'should_dismiss' => array(
470                        'required' => true,
471                        'type'     => 'boolean',
472                    ),
473                ),
474            )
475        );
476
477        // Get site size
478        register_rest_route(
479            'jetpack/v4',
480            '/site/backup/size',
481            array(
482                'methods'             => WP_REST_Server::READABLE,
483                'callback'            => __CLASS__ . '::get_site_backup_size',
484                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
485            )
486        );
487
488        // Get backup schedule time
489        register_rest_route(
490            'jetpack/v4',
491            '/site/backup/schedule',
492            array(
493                'methods'             => WP_REST_Server::READABLE,
494                'callback'            => __CLASS__ . '::get_site_backup_schedule_time',
495                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
496            )
497        );
498
499        // Get site policies
500        register_rest_route(
501            'jetpack/v4',
502            '/site/backup/policies',
503            array(
504                'methods'             => WP_REST_Server::READABLE,
505                'callback'            => __CLASS__ . '::get_site_backup_policies',
506                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
507            )
508        );
509
510        // Get site add-on offer
511        register_rest_route(
512            'jetpack/v4',
513            '/site/backup/addon-offer',
514            array(
515                'methods'             => WP_REST_Server::READABLE,
516                'callback'            => __CLASS__ . '::get_site_backup_addon_offer',
517                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
518                'args'                => array(
519                    'storage_size'  => array(
520                        'required' => true,
521                        'type'     => 'numeric',
522                    ),
523                    'storage_limit' => array(
524                        'required' => true,
525                        'type'     => 'numeric',
526                    ),
527                ),
528            )
529        );
530
531        // Enqueue a new backup
532        register_rest_route(
533            'jetpack/v4',
534            '/site/backup/enqueue',
535            array(
536                'methods'             => WP_REST_Server::CREATABLE,
537                'callback'            => __CLASS__ . '::enqueue_backup',
538                'permission_callback' => __CLASS__ . '::backups_permissions_callback',
539            )
540        );
541    }
542
543    /**
544     * The backup calls should only occur from a signed in admin user
545     *
546     * @access public
547     * @static
548     *
549     * @return true|WP_Error
550     */
551    public static function backups_permissions_callback() {
552        return current_user_can( 'manage_options' );
553    }
554
555    /**
556     * The error a route answers with when its WordPress.com request did not come
557     * back with a 200.
558     *
559     * Returning `null` instead — which these routes used to do — is served as an
560     * HTTP 200 carrying a `null` body, so `apiFetch` resolves and nothing throws.
561     * A WordPress.com blip then reaches the dashboard as an empty success, which
562     * is how a paying customer ends up looking at the first-run screen. A
563     * WP_Error makes the REST layer answer with a status, so every caller's
564     * existing failure path runs.
565     *
566     * @param int $status The upstream response code, already cast to an int, or 0
567     *                    when the request never reached WordPress.com.
568     * @return WP_Error
569     */
570    private static function get_failed_fetch_error( $status = 0 ) {
571        return new WP_Error(
572            'failed_to_fetch_data',
573            esc_html__( 'Unable to fetch the requested data.', 'jetpack-backup-pkg' ),
574            array(
575                // A transport failure has no status at all, and `status_header( 0 )`
576                // emits an invalid status line — so anything falsy becomes a 500.
577                'status' => $status ? $status : 500,
578            )
579        );
580    }
581
582    /**
583     * Get information about recent backups
584     *
585     * @access public
586     * @static
587     *
588     * @return \WP_REST_Response|WP_Error The recent backups, or a WP_Error if WordPress.com could not be reached.
589     */
590    public static function get_recent_backups() {
591        $blog_id = Jetpack_Options::get_option( 'id' );
592
593        $response = Client::wpcom_json_api_request_as_blog(
594            '/sites/' . $blog_id . '/rewind/backups',
595            'v2',
596            array(),
597            null,
598            'wpcom'
599        );
600
601        $response_code = (int) wp_remote_retrieve_response_code( $response );
602
603        if ( 200 !== $response_code ) {
604            return self::get_failed_fetch_error( $response_code );
605        }
606
607        return rest_ensure_response(
608            json_decode( $response['body'], true )
609        );
610    }
611
612    /**
613     * Hits the wpcom api to check rewind status.
614     *
615     * Bounded well clear of a healthy round trip; `Client`'s 10s default is too
616     * long for the synchronous `authorize_redirect` this sits on.
617     *
618     * @return object|WP_Error The decoded rewind state, or a WP_Error if WordPress.com could not be read.
619     */
620    private static function get_rewind_state_from_wpcom() {
621        if ( self::$rewind_state !== null ) {
622            return self::$rewind_state;
623        }
624
625        $site_id = Jetpack_Options::get_option( 'id' );
626
627        $response = Client::wpcom_json_api_request_as_blog( sprintf( '/sites/%d/rewind', $site_id ) . '?force=wpcom', '2', array( 'timeout' => 5 ), null, 'wpcom' );
628
629        // Cast: `wp_remote_retrieve_response_code()` hands back whatever the
630        // transport put there, and a numeric-string `'200'` fails this strict
631        // comparison.
632        $response_code = (int) wp_remote_retrieve_response_code( $response );
633
634        if ( 200 !== $response_code ) {
635            return self::get_failed_fetch_error( $response_code );
636        }
637
638        $state = json_decode( wp_remote_retrieve_body( $response ) );
639
640        // A 200 with no `state` is a read that failed, not a site without a
641        // plan. Caching it would hold that answer for the rest of the request;
642        // refusing lets a later caller ask again and get a real one.
643        if ( ! is_object( $state ) || ! isset( $state->state ) ) {
644            return new WP_Error(
645                'rewind_state_unreadable',
646                esc_html__( 'Unable to read the backup plan details for this site.', 'jetpack-backup-pkg' ),
647                array( 'status' => 500 )
648            );
649        }
650
651        self::$rewind_state = $state;
652        return self::$rewind_state;
653    }
654
655    /**
656     * Checks whether the site supports the product, reporting an unreadable answer as an error.
657     *
658     * @since 5.0.1
659     *
660     * @return bool|WP_Error True when the site has Backup, or a WP_Error if WordPress.com could not be read.
661     */
662    public static function get_backup_plan_state() {
663        $rewind_data = static::get_rewind_state_from_wpcom();
664
665        if ( is_wp_error( $rewind_data ) ) {
666            return $rewind_data;
667        }
668
669        return 'unavailable' !== $rewind_data->state;
670    }
671
672    /**
673     * Checks whether the current plan (or purchases) of the site already supports the product
674     *
675     * Answers a plan it could not read as absent, which is the one place that
676     * decision is made for every `bool` caller.
677     *
678     * @return bool
679     */
680    public static function has_backup_plan() {
681        $state = static::get_backup_plan_state();
682
683        return ! is_wp_error( $state ) && $state;
684    }
685
686    /**
687     * Get an array of backup/scan/anti-spam site capabilities
688     *
689     * @access public
690     * @static
691     *
692     * @return \WP_REST_Response|WP_Error The site capabilities, or a WP_Error if WordPress.com could not be reached.
693     */
694    public static function get_backup_capabilities() {
695        $blog_id = Jetpack_Options::get_option( 'id' );
696
697        $response = Client::wpcom_json_api_request_as_user(
698            '/sites/' . $blog_id . '/rewind/capabilities',
699            'v2',
700            array(),
701            null,
702            'wpcom'
703        );
704
705        $response_code = (int) wp_remote_retrieve_response_code( $response );
706
707        if ( 200 !== $response_code ) {
708            return self::get_failed_fetch_error( $response_code );
709        }
710
711        return rest_ensure_response(
712            json_decode( $response['body'], true )
713        );
714    }
715
716    /**
717     * Get information about recent restores
718     *
719     * @access public
720     * @static
721     *
722     * @return \WP_REST_Response|WP_Error The recent restores, or a WP_Error if WordPress.com could not be reached.
723     */
724    public static function get_recent_restores() {
725        $blog_id  = Jetpack_Options::get_option( 'id' );
726        $response = Client::wpcom_json_api_request_as_blog(
727            '/sites/' . $blog_id . '/rewind/restores',
728            'v2',
729            array(),
730            null,
731            'wpcom'
732        );
733
734        $response_code = (int) wp_remote_retrieve_response_code( $response );
735
736        if ( 200 !== $response_code ) {
737            return self::get_failed_fetch_error( $response_code );
738        }
739
740        return rest_ensure_response(
741            json_decode( $response['body'], true )
742        );
743    }
744
745    /**
746     * Query backup-completion events from the wpcom activity-log via the
747     * general `/sites/<id>/activity` endpoint with the action filter pinned
748     * to backup-completion event names. This endpoint paginates real-ly
749     * (Elasticsearch `from` offset under the hood) — the `/activity/rewindable`
750     * sibling looks like a more natural fit but hardcodes `page: 1,
751     * totalPages: 1` and ignores the `page` parameter.
752     *
753     * Auth: signs as user. The endpoint gates on the requesting WP user
754     * being an administrator of the blog (see
755     * sites-activity.php::readable_permission_check); blog-level tokens
756     * return 401.
757     *
758     * Returned shape (success): a W3C ActivityStreams envelope:
759     *   {
760     *     "@context": ..., "type": "OrderedCollection", "totalItems": int,
761     *     "page": int, "totalPages": int, "itemsPerPage": int,
762     *     "orderedItems": [ <event>, ... ]
763     *   }
764     * Each event has at least `published`, `rewind_id`, `is_rewindable`,
765     * `name`, `status`, `summary`.
766     *
767     * @param array $args Query args passed through to wpcom. Supported keys:
768     *                    `after` (ISO 8601), `before` (ISO 8601), `on` (ISO 8601),
769     *                    `date_range`, `number` (max 1000), `page` (1-based),
770     *                    `sort_order` ('asc'|'desc'). Any `action` key is
771     *                    overridden with the curated backup-completion list.
772     * @return array|\WP_REST_Response|null
773     */
774    public static function list_backup_events( array $args = array() ) {
775        $blog_id = Jetpack_Options::get_option( 'id' );
776
777        // Curated set of activity actions that represent "a backup completed".
778        // Mirrors `WPCOM_REST_API_V2_Endpoint_Site_Activity::$backup_action_names`.
779        // Pinned here (and overriding any caller-supplied `action`) so the
780        // helper is always scoped to backups regardless of what the caller passes.
781        $args['action'] = array(
782            'backup_complete_full',
783            'backup_complete_initial',
784            'backup_only_complete_full',
785            'backup_only_complete_initial',
786            'rewind__backup_complete_full',
787            'rewind__backup_complete_initial',
788            'rewind__backup_only_complete_full',
789            'rewind__backup_only_complete_initial',
790        );
791
792        $path = '/sites/' . (int) $blog_id . '/activity?' . http_build_query( $args );
793
794        $response = Client::wpcom_json_api_request_as_user(
795            $path,
796            'v2',
797            array(),
798            null,
799            'wpcom'
800        );
801
802        // Cast, as everywhere else this package reads a status. Uncast, a
803        // numeric-string `'200'` discards a good activity page and the
804        // `jetpack-backup/list-backup-events` ability reports that the site
805        // has completed no backups — `unwrap_response()` flattens this
806        // `null` into an empty list, which is a claim rather than an error.
807        if ( 200 !== (int) wp_remote_retrieve_response_code( $response ) ) {
808            return null;
809        }
810
811        return rest_ensure_response(
812            json_decode( $response['body'], true )
813        );
814    }
815
816    /**
817     * Gets information about the currently promoted backup product.
818     *
819     * Answers from a per-locale transient when one is warm; failures are not cached.
820     *
821     * @return object|WP_Error The promoted product, or a WP_Error if it could not be read.
822     */
823    public static function get_backup_promoted_product_info() {
824        $locale        = get_user_locale();
825        $transient_key = self::PROMOTED_PRODUCT_TRANSIENT_PREFIX . sanitize_key( $locale );
826        $cached        = get_transient( $transient_key );
827
828        if ( false !== $cached ) {
829            return $cached;
830        }
831
832        $request_url   = 'https://public-api.wordpress.com/rest/v1.1/products?locale=' . $locale . '&type=jetpack';
833        $wpcom_request = wp_remote_get( esc_url_raw( $request_url ) );
834        // Cast: the transport may report the status as a numeric string, which
835        // a strict comparison against 200 sends down the failure path.
836        $response_code = (int) wp_remote_retrieve_response_code( $wpcom_request );
837
838        if ( 200 !== $response_code ) {
839            return new WP_Error(
840                'failed_to_fetch_data',
841                esc_html__( 'Unable to fetch the requested data.', 'jetpack-backup-pkg' ),
842                array(
843                    // A transport failure has no status at all; reporting 0 would
844                    // leave the REST layer with nothing to serve.
845                    'status'  => $response_code ? $response_code : 500,
846                    'request' => $wpcom_request,
847                )
848            );
849        }
850
851        $products = json_decode( wp_remote_retrieve_body( $wpcom_request ) );
852
853        // A 200 is not a promise that the promoted product is in the body. A
854        // truncated response decodes to null, and the slug is a constant here
855        // but a catalogue entry upstream — retiring it there leaves this a 200
856        // with the key absent. Reading through either emits a PHP warning and
857        // yields null, which the route then serves as a 200 carrying `null`:
858        // indistinguishable, to a caller, from a priced answer it failed to
859        // read. Refusing says which of the two happened.
860        if ( ! is_object( $products ) || ! isset( $products->{ self::JETPACK_BACKUP_PROMOTED_PRODUCT } ) ) {
861            return new WP_Error(
862                'promoted_product_unreadable',
863                esc_html__( 'Unable to read the promoted product information.', 'jetpack-backup-pkg' ),
864                array( 'status' => 500 )
865            );
866        }
867
868        $product = $products->{ self::JETPACK_BACKUP_PROMOTED_PRODUCT };
869
870        // Must stay below both guards: a cached failure would leave the no-plan
871        // screen without a price for the whole TTL after WordPress.com recovered.
872        set_transient( $transient_key, $product, self::PROMOTED_PRODUCT_CACHE_TTL );
873
874        return $product;
875    }
876
877    /**
878     * Check for user licenses.
879     *
880     * @param boolean $has_license If the user already has a license found.
881     * @param array   $licenses List of unattached licenses belonging to the user.
882     * @param string  $plugin_slug The plugin that initiated the flow.
883     *
884     * @return boolean
885     */
886    public static function jetpack_check_user_licenses( $has_license, $licenses, $plugin_slug ) {
887        if ( $plugin_slug !== static::JETPACK_BACKUP_SLUG || $has_license ) {
888            return $has_license;
889        }
890
891        $license_found = false;
892
893        foreach ( $licenses as $license ) {
894            if ( in_array( $license->product_id, static::JETPACK_BACKUP_PRODUCT_IDS, true ) ) {
895                $license_found = true;
896                break;
897            }
898        }
899
900        // Checking for existing backup plan is costly, so only check if there's an appropriate license.
901        return $license_found && ! static::has_backup_plan();
902    }
903
904    /**
905     * Returns the result of `/upgrades` endpoint call.
906     *
907     * @return \WP_REST_Response|WP_Error The site purchases, or a WP_Error if WordPress.com could not be reached.
908     */
909    public static function get_site_current_purchases() {
910
911        $request  = sprintf( '/upgrades?site=%d', Jetpack_Options::get_option( 'id' ) );
912        $response = Client::wpcom_json_api_request_as_blog( $request, '1.2' );
913
914        // Bail if there was an error or malformed response.
915        if ( is_wp_error( $response ) || ! is_array( $response ) || ! isset( $response['body'] ) ) {
916            return self::get_failed_fetch_error();
917        }
918
919        $response_code = (int) wp_remote_retrieve_response_code( $response );
920
921        if ( 200 !== $response_code ) {
922            return self::get_failed_fetch_error( $response_code );
923        }
924
925        return rest_ensure_response(
926            json_decode( $response['body'], true )
927        );
928    }
929
930    /**
931     * Set value of the dismissed_backup_review_request Jetack option.
932     * Get value if should_dismiss is false
933     *
934     * @access public
935     * @static
936     * @param array $request arguments should_dismiss and option_name.
937     * @return bool value of option if value is requested | updated or not if value is updated.
938     */
939    public static function manage_dismissed_backup_review_request( $request ) {
940
941        if ( ! $request['should_dismiss'] ) {
942
943            return rest_ensure_response(
944                Jetpack_Options::get_option( 'dismissed_backup_review_' . $request['option_name'] )
945            );
946        }
947
948        return Jetpack_Options::update_option( 'dismissed_backup_review_' . $request['option_name'], true );
949    }
950
951    /**
952     * Get site storage size
953     *
954     * @return \WP_REST_Response|WP_Error The site storage size, or a WP_Error if WordPress.com could not be reached.
955     */
956    public static function get_site_backup_size() {
957        $blog_id = Jetpack_Options::get_option( 'id' );
958
959        $response = Client::wpcom_json_api_request_as_user(
960            '/sites/' . $blog_id . '/rewind/size?force=wpcom',
961            'v2',
962            array(),
963            null,
964            'wpcom'
965        );
966
967        $response_code = (int) wp_remote_retrieve_response_code( $response );
968
969        if ( 200 !== $response_code ) {
970            return self::get_failed_fetch_error( $response_code );
971        }
972
973        return rest_ensure_response(
974            json_decode( $response['body'], true )
975        );
976    }
977
978    /**
979     * Get site policies from WPCOM. It includes the storage limit and activity log limit, if apply.
980     *
981     * @return \WP_REST_Response|WP_Error The site storage policies, or a WP_Error if WordPress.com could not be reached.
982     */
983    public static function get_site_backup_policies() {
984        $blog_id = Jetpack_Options::get_option( 'id' );
985
986        $response = Client::wpcom_json_api_request_as_user(
987            '/sites/' . $blog_id . '/rewind/policies?force=wpcom',
988            'v2',
989            array(),
990            null,
991            'wpcom'
992        );
993
994        $response_code = (int) wp_remote_retrieve_response_code( $response );
995
996        if ( 200 !== $response_code ) {
997            return self::get_failed_fetch_error( $response_code );
998        }
999
1000        return rest_ensure_response(
1001            json_decode( $response['body'], true )
1002        );
1003    }
1004
1005    /**
1006     * Get suggested storage addon based on storage usage
1007     *
1008     * @param int $bytes_used      Storage used.
1009     * @param int $bytes_available Storage limit.
1010     * @return string Suggested addon storage slug
1011     */
1012    public static function get_storage_addon_upsell_slug( $bytes_used, $bytes_available ) {
1013        $bytes_10gb  = 10 * 1024 * 1024 * 1024; // 10GB in bytes
1014        $bytes_100gb = 100 * 1024 * 1024 * 1024; // 100GB in bytes
1015        $bytes_1tb   = 1024 * 1024 * 1024 * 1024; // 1TB in bytes
1016
1017        $upsell_products = array(
1018            $bytes_10gb  => 'jetpack_backup_addon_storage_10gb_monthly',
1019            $bytes_100gb => 'jetpack_backup_addon_storage_100gb_monthly',
1020            $bytes_1tb   => 'jetpack_backup_addon_storage_1tb_monthly',
1021        );
1022
1023        // If usage has crossed over the storage limit, then dynamically calculate the upgrade option
1024        if ( $bytes_used > $bytes_available ) {
1025            $additional_bytes_used = $bytes_used - $bytes_available;
1026
1027            // Add aditional 25% buffer
1028            $additional_bytes_needed = $additional_bytes_used + $additional_bytes_used * 0.25;
1029
1030            // Since 1TB is our max upgrade but the additional storage needed is greater than 1TB, then just return 1TB
1031            if ( $additional_bytes_needed > $bytes_1tb ) {
1032                return $upsell_products[ $bytes_1tb ];
1033            }
1034
1035            $matched_bytes = $bytes_10gb;
1036            foreach ( $upsell_products as $bytes => $product ) {
1037                if ( $bytes > $additional_bytes_needed ) {
1038                    $matched_bytes = $bytes;
1039                    break;
1040                }
1041            }
1042
1043            return $upsell_products[ $matched_bytes ];
1044        }
1045
1046        // For 1 TB we are going to offer 1 TB by default
1047        if ( $bytes_1tb === $bytes_available ) {
1048            return $upsell_products[ $bytes_1tb ];
1049        }
1050
1051        // Otherwise, we are going to offer 10 GB
1052        return $upsell_products[ $bytes_10gb ];
1053    }
1054
1055    /**
1056     * Get the best addon offer for this site, including pricing details
1057     *
1058     * @param \WP_REST_Request $request Object including storage usage.
1059     *
1060     * @return string|WP_Error A JSON object with the suggested storage addon details if the request was successful,
1061     *                         or a WP_Error otherwise.
1062     */
1063    public static function get_site_backup_addon_offer( $request ) {
1064        $suggested_addon = self::get_storage_addon_upsell_slug(
1065            $request['storage_size'],
1066            $request['storage_limit']
1067        );
1068
1069        $addons_size_text_map = array(
1070            'jetpack_backup_addon_storage_10gb_monthly'  => '10GB',
1071            'jetpack_backup_addon_storage_100gb_monthly' => '100GB',
1072            'jetpack_backup_addon_storage_1tb_monthly'   => '1TB',
1073        );
1074
1075        // Fetch addon storage price information
1076        $pricing_info = Wpcom_Products::get_product_pricing( $suggested_addon );
1077
1078        // Response
1079        $response = array(
1080            'slug'      => $suggested_addon,
1081            'size_text' => $addons_size_text_map[ $suggested_addon ],
1082            'pricing'   => $pricing_info,
1083        );
1084
1085        return rest_ensure_response( $response );
1086    }
1087
1088    /**
1089     * Enqueue a new backup on demand
1090     *
1091     * @return \WP_REST_Response|WP_Error The enqueue result, or a WP_Error if WordPress.com could not be reached.
1092     */
1093    public static function enqueue_backup() {
1094        $blog_id  = Jetpack_Options::get_option( 'id' );
1095        $endpoint = sprintf( '/sites/%d/rewind/backups/enqueue', $blog_id );
1096
1097        $response = Client::wpcom_json_api_request_as_user(
1098            $endpoint,
1099            'v2',
1100            array(
1101                'method' => 'POST',
1102            ),
1103            null,
1104            'wpcom'
1105        );
1106
1107        $response_code = (int) wp_remote_retrieve_response_code( $response );
1108
1109        if ( 200 !== $response_code ) {
1110            return self::get_failed_fetch_error( $response_code );
1111        }
1112
1113        return rest_ensure_response(
1114            json_decode( $response['body'], true )
1115        );
1116    }
1117
1118    /**
1119     * Get site backup schedule time
1120     *
1121     * @return \WP_REST_Response|WP_Error The backup schedule time, or a WP_Error if WordPress.com could not be reached.
1122     */
1123    public static function get_site_backup_schedule_time() {
1124        $blog_id = Jetpack_Options::get_option( 'id' );
1125
1126        $response = Client::wpcom_json_api_request_as_user(
1127            '/sites/' . $blog_id . '/rewind/scheduled',
1128            'v2',
1129            array(),
1130            null,
1131            'wpcom'
1132        );
1133
1134        $response_code = (int) wp_remote_retrieve_response_code( $response );
1135
1136        if ( 200 !== $response_code ) {
1137            return self::get_failed_fetch_error( $response_code );
1138        }
1139
1140        return rest_ensure_response(
1141            json_decode( $response['body'], true )
1142        );
1143    }
1144
1145    /**
1146     * Removes plugin from the connection manager
1147     * If it's the last plugin using the connection, the site will be disconnected.
1148     *
1149     * @access public
1150     * @static
1151     */
1152    public static function plugin_deactivation() {
1153        $manager = new Connection_Manager( 'jetpack-backup' );
1154        $manager->remove_connection();
1155    }
1156
1157    /**
1158     * Load wp-build when modernization is enabled on the Backup admin page.
1159     *
1160     * @return void
1161     */
1162    public static function maybe_load_wp_build() {
1163        if ( ! self::is_modernized() || ! self::is_backup_admin_request() ) {
1164            return;
1165        }
1166
1167        self::load_wp_build_with_screen_alias();
1168
1169        // wp-build registers standalone modules (e.g. the init module) on
1170        // wp_default_scripts, which has already fired by admin_menu. Register them
1171        // directly so the init module makes it into the import map.
1172        if ( function_exists( 'jetpack_backup_register_script_modules' ) ) {
1173            jetpack_backup_register_script_modules(); // @phan-suppress-current-line PhanUndeclaredFunction -- Checked with function_exists(); defined in the generated build/modules.php, which Phan excludes.
1174        }
1175
1176        add_action( 'admin_print_scripts', array( __CLASS__, 'render_connection_initial_state' ), 1 );
1177    }
1178
1179    /**
1180     * Emit `window.JP_CONNECTION_INITIAL_STATE` inline on the modernized
1181     * Backup admin page.
1182     *
1183     * The modernized enqueue path short-circuits before the legacy
1184     * `Connection_Initial_State::render_script()` call, so without this
1185     * the React `<Gates>` component never sees the connection state and
1186     * sits on its loading skeleton forever. We emit the same JS payload
1187     * the legacy path emits, just outside of a registered script handle
1188     * (wp-build's handles aren't reliable here, and the global is
1189     * page-scoped — any tag setting it works).
1190     *
1191     * @return void
1192     */
1193    public static function render_connection_initial_state() {
1194        echo '<script id="jetpack-backup-connection-initial-state">'
1195            . Connection_Initial_State::render() // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- render() returns pre-escaped JSON.
1196            . '</script>';
1197    }
1198
1199    /**
1200     * Load the wp-build entry file and register its polyfills.
1201     *
1202     * Only called on `?page=jetpack-backup` admin requests when `is_modernized()`
1203     * is true. Keeps wp-build off every other request.
1204     *
1205     * @return void
1206     */
1207    private static function load_wp_build() {
1208        $build_index = dirname( __DIR__ ) . '/build/build.php';
1209
1210        if ( ! file_exists( $build_index ) ) {
1211            return;
1212        }
1213
1214        require_once $build_index;
1215
1216        \Automattic\Jetpack\WP_Build_Polyfills\WP_Build_Polyfills::register(
1217            'jetpack-backup',
1218            array_merge(
1219                \Automattic\Jetpack\WP_Build_Polyfills\WP_Build_Polyfills::SCRIPT_HANDLES,
1220                \Automattic\Jetpack\WP_Build_Polyfills\WP_Build_Polyfills::MODULE_IDS
1221            )
1222        );
1223    }
1224
1225    /**
1226     * Load wp-build with the screen ID aliased across its generated enqueue check.
1227     *
1228     * @see WP_Build_Screen_Id::load_with_alias()
1229     * @return void
1230     */
1231    private static function load_wp_build_with_screen_alias() {
1232        // Fallback: an older wp-build-polyfills under the jetpack-autoloader may predate load_with_alias().
1233        if ( method_exists( \Automattic\Jetpack\WP_Build_Polyfills\WP_Build_Screen_Id::class, 'load_with_alias' ) ) {
1234            \Automattic\Jetpack\WP_Build_Polyfills\WP_Build_Screen_Id::load_with_alias(
1235                array( __CLASS__, 'alias_screen_id_for_wp_build' ),
1236                array( __CLASS__, 'restore_screen_id_after_wp_build' ),
1237                function () {
1238                    self::load_wp_build();
1239                }
1240            );
1241            return;
1242        }
1243
1244        add_action( 'admin_enqueue_scripts', array( __CLASS__, 'alias_screen_id_for_wp_build' ) );
1245        self::load_wp_build();
1246        add_action( 'admin_enqueue_scripts', array( __CLASS__, 'restore_screen_id_after_wp_build' ) );
1247    }
1248
1249    /**
1250     * Alias the current screen ID to satisfy wp-build's auto-generated enqueue check.
1251     *
1252     * Wp-build's `<page>-wp-admin` enqueue callback enqueues only when the screen ID
1253     * matches the wp-build page slug (`jetpack-backup-dashboard`). Our WP-admin
1254     * menu slug stays `jetpack-backup`, so we mutate the screen object in place
1255     * to make the check pass without changing the user-facing URL.
1256     *
1257     * Hooked only when modernization is on AND we're on the Backup admin page,
1258     * so this never affects any other request.
1259     *
1260     * @since 5.0.4 Takes no argument; hooked on `admin_enqueue_scripts`.
1261     *
1262     * @return void
1263     */
1264    public static function alias_screen_id_for_wp_build() {
1265        $screen = get_current_screen();
1266        if ( ! $screen ) {
1267            return;
1268        }
1269
1270        self::$wp_build_original_screen_id = $screen->id;
1271        $screen->id                        = 'jetpack-backup-dashboard';
1272    }
1273
1274    /**
1275     * Undo alias_screen_id_for_wp_build(), so code after the generated check sees the real screen ID.
1276     *
1277     * @since 5.0.4
1278     *
1279     * @return void
1280     */
1281    public static function restore_screen_id_after_wp_build() {
1282        $screen = get_current_screen();
1283        if ( ! $screen || null === self::$wp_build_original_screen_id ) {
1284            return;
1285        }
1286
1287        $screen->id                        = self::$wp_build_original_screen_id;
1288        self::$wp_build_original_screen_id = null;
1289    }
1290
1291    /**
1292     * Returns the modernization filter's value, which defaults to the internal preview.
1293     *
1294     * @since 4.3.14 Changed from private to public; the REST bridges gate their route registration on it.
1295     *
1296     * @return bool
1297     */
1298    public static function is_modernized() {
1299        return (bool) apply_filters( self::MODERNIZATION_FILTER, self::is_internal_preview() );
1300    }
1301
1302    /**
1303     * Whether an internal user on the A8C proxy previews the dashboard. Not an authorization check.
1304     *
1305     * The proxy is checked first, so other requests never make the connected-user lookup.
1306     *
1307     * @return bool
1308     */
1309    private static function is_internal_preview() {
1310        if ( ! Constants::is_true( 'AT_PROXIED_REQUEST' ) ) {
1311            return false;
1312        }
1313
1314        if ( function_exists( 'wpcomsh_is_site_sticker_active' ) && wpcomsh_is_site_sticker_active( self::LEGACY_DASHBOARD_STICKER ) ) {
1315            return false;
1316        }
1317
1318        $user_data = ( new Connection_Manager() )->get_connected_user_data();
1319        $email     = is_array( $user_data ) && ! empty( $user_data['email'] ) ? strtolower( (string) $user_data['email'] ) : '';
1320
1321        return str_ends_with( $email, '@automattic.com' ) || str_ends_with( $email, '@a8c.com' );
1322    }
1323
1324    /**
1325     * Returns true when `is_modernized()` is true AND the wp-build dashboard loaded.
1326     *
1327     * `build/` is gitignored, so the render function is absent in any unbuilt checkout
1328     * and in any release whose wp-build step failed. Every consumer of the modernized
1329     * surface has to agree on this, or the menu falls back to the legacy page while the
1330     * enqueue path skips the legacy script — an empty div with no JS.
1331     *
1332     * Only meaningful once `maybe_load_wp_build()` has run. It is hooked on `admin_menu`
1333     * at the same priority as `add_wp_admin_submenu()`, so registration order — not
1334     * priority — is what keeps it first. Do not reorder those two `add_action()` calls.
1335     *
1336     * @return bool
1337     */
1338    private static function is_wp_build_dashboard_active() {
1339        return self::is_modernized() && function_exists( 'jetpack_backup_jetpack_backup_dashboard_wp_admin_render_page' );
1340    }
1341
1342    /**
1343     * Returns true when the current request targets the Backup admin page.
1344     *
1345     * Used to scope wp-build loading to the one page that needs it. The
1346     * `$_GET['page']` value is populated by wp-admin/admin.php before any of
1347     * our hooks fire, so this check is reliable from `initialize()` onwards.
1348     *
1349     * @return bool
1350     */
1351    private static function is_backup_admin_request() {
1352        if ( ! is_admin() || ! isset( $_GET['page'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1353            return false;
1354        }
1355
1356        return sanitize_text_field( wp_unslash( $_GET['page'] ) ) === self::JETPACK_BACKUP_SLUG; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1357    }
1358}