Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
37.81% covered (danger)
37.81%
332 / 878
3.45% covered (danger)
3.45%
1 / 29
CRAP
0.00% covered (danger)
0.00%
0 / 4
jetpack_do_after_gravatar_hovercards_activation
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
jetpack_do_after_gravatar_hovercards_deactivation
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
jetpack_do_after_markdown_activation
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
Jetpack_Core_API_Module_Toggle_Endpoint
53.25% covered (warning)
53.25%
41 / 77
0.00% covered (danger)
0.00%
0 / 4
55.89
0.00% covered (danger)
0.00%
0 / 1
 process
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
6
 activate_module
55.56% covered (warning)
55.56%
20 / 36
0.00% covered (danger)
0.00%
0 / 1
13.62
 deactivate_module
56.76% covered (warning)
56.76%
21 / 37
0.00% covered (danger)
0.00%
0 / 1
13.18
 can_request
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
Jetpack_Core_API_Module_List_Endpoint
41.79% covered (danger)
41.79%
28 / 67
0.00% covered (danger)
0.00%
0 / 4
98.89
0.00% covered (danger)
0.00%
0 / 1
 process
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
6
 get_modules
0.00% covered (danger)
0.00%
0 / 11
0.00% covered (danger)
0.00%
0 / 1
30
 activate_modules
56.00% covered (warning)
56.00%
28 / 50
0.00% covered (danger)
0.00%
0 / 1
21.31
 can_request
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
6
Jetpack_Core_API_Data
54.23% covered (warning)
54.23%
263 / 485
16.67% covered (danger)
16.67%
1 / 6
4905.01
0.00% covered (danger)
0.00%
0 / 1
 process
80.00% covered (warning)
80.00%
4 / 5
0.00% covered (danger)
0.00%
0 / 1
3.07
 get_module
0.00% covered (danger)
0.00%
0 / 22
0.00% covered (danger)
0.00%
0 / 1
90
 get_all_options
84.78% covered (warning)
84.78%
39 / 46
0.00% covered (danger)
0.00%
0 / 1
22.55
 update_data
52.69% covered (warning)
52.69%
206 / 391
0.00% covered (danger)
0.00%
0 / 1
3012.87
 process_onboarding
n/a
0 / 0
n/a
0 / 0
1
 handle_business_address
n/a
0 / 0
n/a
0 / 0
12
 has_business_address_widget
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
20
 can_request
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
7
Jetpack_Core_API_Module_Data_Endpoint
0.00% covered (danger)
0.00%
0 / 241
0.00% covered (danger)
0.00%
0 / 12
3906
0.00% covered (danger)
0.00%
0 / 1
 process
0.00% covered (danger)
0.00%
0 / 13
0.00% covered (danger)
0.00%
0 / 1
56
 key_check
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
20
 get_protect_data
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
6
 get_akismet_data
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
6
 check_akismet_key
0.00% covered (danger)
0.00%
0 / 23
0.00% covered (danger)
0.00%
0 / 1
56
 akismet_class_exists
0.00% covered (danger)
0.00%
0 / 5
0.00% covered (danger)
0.00%
0 / 1
12
 akismet_is_active_and_registered
0.00% covered (danger)
0.00%
0 / 9
0.00% covered (danger)
0.00%
0 / 1
30
 get_stats_data
0.00% covered (danger)
0.00%
0 / 39
0.00% covered (danger)
0.00%
0 / 1
42
 get_monitor_data
0.00% covered (danger)
0.00%
0 / 23
0.00% covered (danger)
0.00%
0 / 1
20
 get_verification_tools_data
0.00% covered (danger)
0.00%
0 / 63
0.00% covered (danger)
0.00%
0 / 1
210
 get_vaultpress_data
0.00% covered (danger)
0.00%
0 / 47
0.00% covered (danger)
0.00%
0 / 1
56
 can_request
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
1<?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2/**
3 * Tools to interact with Jetpack modules via API requests.
4 *
5 * @package automattic/jetpack
6 */
7
8use Automattic\Jetpack\Connection\REST_Connector;
9use Automattic\Jetpack\Current_Plan as Jetpack_Plan;
10use Automattic\Jetpack\Stats\WPCOM_Stats;
11use Automattic\Jetpack\Stats_Admin\Main as Stats_Admin_Main;
12use Automattic\Jetpack\Status;
13use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
14use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection_Shared_Functions;
15
16if ( ! defined( 'ABSPATH' ) ) {
17    exit( 0 );
18}
19
20/**
21 * This is the base class for every Core API endpoint Jetpack uses.
22 */
23class Jetpack_Core_API_Module_Toggle_Endpoint extends Jetpack_Core_API_XMLRPC_Consumer_Endpoint {
24
25    /**
26     * Check if the module requires the site to be publicly accessible from WPCOM.
27     * If the site meets this requirement, the module is activated. Otherwise an error is returned.
28     *
29     * @since 4.3.0
30     *
31     * @param WP_REST_Request $request {
32     *     Array of parameters received by request.
33     *
34     *     @type string $slug Module slug.
35     *     @type bool   $active should module be activated.
36     * }
37     *
38     * @return WP_REST_Response|WP_Error A REST response if the request was served successfully, otherwise an error.
39     */
40    public function process( $request ) {
41        if ( $request['active'] ) {
42            return $this->activate_module( $request );
43        } else {
44            return $this->deactivate_module( $request );
45        }
46    }
47
48    /**
49     * If it's a valid Jetpack module, activate it.
50     *
51     * @since 4.3.0
52     *
53     * @param string|WP_REST_Request $request It's a WP_REST_Request when called from endpoint /module/<slug>/*
54     *                                        and a string when called from Jetpack_Core_API_Data->update_data.
55     * {
56     *     Array of parameters received by request.
57     *
58     *     @type string $slug Module slug.
59     * }
60     *
61     * @return bool|WP_Error True if module was activated. Otherwise, a WP_Error instance with the corresponding error.
62     */
63    public function activate_module( $request ) {
64        $module_slug = '';
65
66        if (
67            (
68                is_array( $request )
69                || is_object( $request )
70            )
71            && isset( $request['slug'] )
72        ) {
73            $module_slug = $request['slug'];
74        } else {
75            $module_slug = $request;
76        }
77
78        if ( ! Jetpack::is_module( $module_slug ) ) {
79            return new WP_Error(
80                'not_found',
81                esc_html__( 'The requested Jetpack module was not found.', 'jetpack' ),
82                array( 'status' => 404 )
83            );
84        }
85
86        if ( ! Jetpack_Plan::supports( $module_slug ) ) {
87            return new WP_Error(
88                'not_supported',
89                esc_html__( 'The requested Jetpack module is not supported by your plan.', 'jetpack' ),
90                array( 'status' => 424 )
91            );
92        }
93
94        if ( Jetpack::activate_module( $module_slug, false, false ) ) {
95            if ( ! Jetpack::is_module_active( $module_slug ) ) {
96                return new WP_Error(
97                    'module_forced',
98                    esc_html__( 'The requested Jetpack module is disabled by your host or site administrator, so it stays off.', 'jetpack' ),
99                    array( 'status' => 409 )
100                );
101            }
102
103            return rest_ensure_response(
104                array(
105                    'code'    => 'success',
106                    'message' => esc_html__( 'The requested Jetpack module was activated.', 'jetpack' ),
107                )
108            );
109        }
110
111        return new WP_Error(
112            'activation_failed',
113            esc_html__( 'The requested Jetpack module could not be activated.', 'jetpack' ),
114            array( 'status' => 424 )
115        );
116    }
117
118    /**
119     * If it's a valid Jetpack module, deactivate it.
120     *
121     * @since 4.3.0
122     *
123     * @param string|WP_REST_Request $request It's a WP_REST_Request when called from endpoint /module/<slug>/*
124     *                                        and a string when called from Jetpack_Core_API_Data->update_data.
125     * {
126     *     Array of parameters received by request.
127     *
128     *     @type string $slug Module slug.
129     * }
130     *
131     * @return bool|WP_Error True if module was activated. Otherwise, a WP_Error instance with the corresponding error.
132     */
133    public function deactivate_module( $request ) {
134        $module_slug = '';
135
136        if (
137            (
138                is_array( $request )
139                || is_object( $request )
140            )
141            && isset( $request['slug'] )
142        ) {
143            $module_slug = $request['slug'];
144        } else {
145            $module_slug = $request;
146        }
147
148        if ( ! Jetpack::is_module( $module_slug ) ) {
149            return new WP_Error(
150                'not_found',
151                esc_html__( 'The requested Jetpack module was not found.', 'jetpack' ),
152                array( 'status' => 404 )
153            );
154        }
155
156        if ( ! Jetpack::is_module_active( $module_slug ) ) {
157            return new WP_Error(
158                'already_inactive',
159                esc_html__( 'The requested Jetpack module was already inactive.', 'jetpack' ),
160                array( 'status' => 409 )
161            );
162        }
163
164        $deactivated = Jetpack::deactivate_module( $module_slug );
165
166        // A module that was never saved as active leaves nothing to change, so check the outcome.
167        if ( Jetpack::is_module_active( $module_slug ) ) {
168            return new WP_Error(
169                'module_forced',
170                esc_html__( 'The requested Jetpack module is enabled by your host or site administrator, so it stays on.', 'jetpack' ),
171                array( 'status' => 409 )
172            );
173        }
174
175        if ( $deactivated ) {
176            return rest_ensure_response(
177                array(
178                    'code'    => 'success',
179                    'message' => esc_html__( 'The requested Jetpack module was deactivated.', 'jetpack' ),
180                )
181            );
182        }
183        return new WP_Error(
184            'deactivation_failed',
185            esc_html__( 'The requested Jetpack module could not be deactivated.', 'jetpack' ),
186            array( 'status' => 400 )
187        );
188    }
189
190    /**
191     * Check that the current user has permissions to manage Jetpack modules.
192     *
193     * @since 4.3.0
194     *
195     * @return bool
196     */
197    public function can_request() {
198        return current_user_can( 'jetpack_manage_modules' );
199    }
200}
201
202/**
203 * Interact with multiple modules at once (list or activate).
204 *
205 * // phpcs:disable Generic.Files.OneObjectStructurePerFile.MultipleFound
206 */
207class Jetpack_Core_API_Module_List_Endpoint {
208    // phpcs:enable Generic.Files.OneObjectStructurePerFile.MultipleFound
209
210    /**
211     * A WordPress REST API callback method that accepts a request object and decides what to do with it.
212     *
213     * @param WP_REST_Request $request The request sent to the WP REST API.
214     *
215     * @since 4.3.0
216     *
217     * @return bool|Array|WP_Error a resulting value or object, or an error.
218     */
219    public function process( $request ) {
220        if ( 'GET' === $request->get_method() ) {
221            return $this->get_modules();
222        } else {
223            return static::activate_modules( $request );
224        }
225    }
226
227    /**
228     * Get a list of all Jetpack modules and their information.
229     *
230     * @since 4.3.0
231     *
232     * @return array Array of Jetpack modules.
233     */
234    public function get_modules() {
235        require_once JETPACK__PLUGIN_DIR . 'class.jetpack-admin.php';
236
237        $modules = Jetpack_Admin::init()->get_modules();
238        foreach ( $modules as $slug => $properties ) {
239            $modules[ $slug ]['options'] =
240                Jetpack_Core_Json_Api_Endpoints::prepare_options_for_response( $slug );
241            if (
242                isset( $modules[ $slug ]['requires_connection'] )
243                && $modules[ $slug ]['requires_connection']
244                && ( new Status() )->is_offline_mode()
245            ) {
246                $modules[ $slug ]['activated'] = false;
247            }
248        }
249
250        $modules = Jetpack::get_translated_modules( $modules );
251
252        return Jetpack_Core_Json_Api_Endpoints::prepare_modules_for_response( $modules );
253    }
254
255    /**
256     * Activate a list of valid Jetpack modules.
257     *
258     * @since 4.3.0
259     *
260     * @param WP_REST_Request $request {
261     *     Array of parameters received by request.
262     *
263     *     @type string $slug Module slug.
264     * }
265     *
266     * @return bool|WP_Error True if modules were activated. Otherwise, a WP_Error instance with the corresponding error.
267     */
268    public static function activate_modules( $request ) {
269
270        if (
271            ! isset( $request['modules'] )
272            || ! is_array( $request['modules'] )
273        ) {
274            return new WP_Error(
275                'not_found',
276                esc_html__( 'The requested Jetpack module was not found.', 'jetpack' ),
277                array( 'status' => 404 )
278            );
279        }
280
281        $activated = array();
282        $failed    = array();
283
284        foreach ( $request['modules'] as $module ) {
285            if ( Jetpack::activate_module( $module, false, false ) && Jetpack::is_module_active( $module ) ) {
286                $activated[] = $module;
287            } else {
288                $failed[] = $module;
289            }
290        }
291
292        if ( empty( $failed ) ) {
293            return rest_ensure_response(
294                array(
295                    'code'    => 'success',
296                    'message' => esc_html__( 'All modules activated.', 'jetpack' ),
297                )
298            );
299        }
300
301        $error = '';
302
303        $activated_count = count( $activated );
304        if ( $activated_count > 0 ) {
305            $activated_last = array_pop( $activated );
306            $activated_text = $activated_count > 1 ? sprintf(
307                /* Translators: first variable is a list followed by the last item, which is the second variable. Example: dog, cat and bird. */
308                __( '%1$s and %2$s', 'jetpack' ),
309                implode( ', ', $activated ),
310                $activated_last
311            ) : $activated_last;
312
313            $error = sprintf(
314                /* Translators: the variable is a module name. */
315                _n( 'The module %s was activated.', 'The modules %s were activated.', $activated_count, 'jetpack' ),
316                $activated_text
317            ) . ' ';
318        }
319
320        $failed_count = count( $failed );
321        if ( count( $failed ) > 0 ) {
322            $failed_last = array_pop( $failed );
323            $failed_text = $failed_count > 1 ? sprintf(
324                /* Translators: first variable is a list followed by the last item, which is the second variable. Example: dog, cat and bird. */
325                __( '%1$s and %2$s', 'jetpack' ),
326                implode( ', ', $failed ),
327                $failed_last
328            ) : $failed_last;
329
330            $error = sprintf(
331                /* Translators: the variable is a module name. */
332                _n( 'The module %s failed to be activated.', 'The modules %s failed to be activated.', $failed_count, 'jetpack' ),
333                $failed_text
334            ) . ' ';
335        }
336
337        return new WP_Error(
338            'activation_failed',
339            esc_html( $error ),
340            array( 'status' => 424 )
341        );
342    }
343
344    /**
345     * A WordPress REST API permission callback method that accepts a request object and decides
346     * if the current user has enough privileges to act.
347     *
348     * @since 4.3.0
349     *
350     * @param WP_REST_Request $request The request sent to the WP REST API.
351     *
352     * @return bool does the current user have enough privilege.
353     */
354    public function can_request( $request ) {
355        if ( 'GET' === $request->get_method() ) {
356            return current_user_can( 'jetpack_admin_page' );
357        } else {
358            return current_user_can( 'jetpack_manage_modules' );
359        }
360    }
361}
362
363/**
364 * Class that manages updating of Jetpack module options and general Jetpack settings or retrieving module data.
365 * If no module is specified, all module settings are retrieved/updated.
366 *
367 * @since 4.3.0
368 * @since 4.4.0 Renamed Jetpack_Core_API_Module_Endpoint from to Jetpack_Core_API_Data.
369 *
370 * @author Automattic
371 *
372 * // phpcs:disable Generic.Files.OneObjectStructurePerFile.MultipleFound
373 */
374class Jetpack_Core_API_Data extends Jetpack_Core_API_XMLRPC_Consumer_Endpoint {
375    // phpcs:enable Generic.Files.OneObjectStructurePerFile.MultipleFound
376
377    /**
378     * Process request by returning the module or updating it.
379     * If no module is specified, settings for all modules are assumed.
380     *
381     * @since 4.3.0
382     *
383     * @param WP_REST_Request $request WP API request.
384     *
385     * @return bool|mixed|void|WP_Error
386     */
387    public function process( $request ) {
388        if ( 'GET' === $request->get_method() ) {
389            if ( isset( $request['slug'] ) ) {
390                return $this->get_module( $request );
391            }
392
393            return $this->get_all_options();
394        } else {
395            return $this->update_data( $request );
396        }
397    }
398
399    /**
400     * Get information about a specific and valid Jetpack module.
401     *
402     * @since 4.3.0
403     *
404     * @param WP_REST_Request $request {
405     *     Array of parameters received by request.
406     *
407     *     @type string $slug Module slug.
408     * }
409     *
410     * @return mixed|void|WP_Error
411     */
412    public function get_module( $request ) {
413        if ( Jetpack::is_module( $request['slug'] ) ) {
414
415            $module = Jetpack::get_module( $request['slug'] );
416
417            $module['options'] = Jetpack_Core_Json_Api_Endpoints::prepare_options_for_response( $request['slug'] );
418
419            if (
420                isset( $module['requires_connection'] )
421                && $module['requires_connection']
422                && ( new Status() )->is_offline_mode()
423            ) {
424                $module['activated'] = false;
425            }
426
427            $i18n = jetpack_get_module_i18n( $request['slug'] );
428            if ( $i18n ) {
429                if ( isset( $module['name'] ) ) {
430                    $module['name'] = $i18n['name'];
431                }
432                if ( isset( $module['description'] ) ) {
433                    $module['description']       = $i18n['description'];
434                    $module['short_description'] = $i18n['description'];
435                }
436            }
437            if ( isset( $module['module_tags'] ) ) {
438                $module['module_tags'] = array_map( 'jetpack_get_module_i18n_tag', $module['module_tags'] );
439            }
440
441            return Jetpack_Core_Json_Api_Endpoints::prepare_modules_for_response( $module );
442        }
443
444        return new WP_Error(
445            'not_found',
446            esc_html__( 'The requested Jetpack module was not found.', 'jetpack' ),
447            array( 'status' => 404 )
448        );
449    }
450
451    /**
452     * Get information about all Jetpack module options and settings.
453     *
454     * @since 4.6.0
455     *
456     * @return WP_REST_Response $response
457     */
458    public function get_all_options() {
459        $response = array();
460
461        $modules = Jetpack::get_available_modules();
462        if ( is_array( $modules ) && ! empty( $modules ) ) {
463            foreach ( $modules as $module ) {
464                // Add all module options.
465                $options = Jetpack_Core_Json_Api_Endpoints::prepare_options_for_response( $module );
466                foreach ( $options as $option_name => $option ) {
467                    $response[ $option_name ] = $option['current_value'];
468                }
469
470                // Add the module activation state.
471                $response[ $module ] = Jetpack::is_module_active( $module );
472            }
473        }
474
475        $settings = Jetpack_Core_Json_Api_Endpoints::filter_options_for_response(
476            Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list( 'settings' )
477        );
478
479        if ( ! function_exists( 'is_plugin_active' ) ) {
480            require_once ABSPATH . 'wp-admin/includes/plugin.php';
481        }
482
483        $response['categories'] = get_categories( array( 'get' => 'all' ) );
484
485        foreach ( $settings as $setting => $properties ) {
486            switch ( $setting ) {
487                case 'lang_id':
488                    if ( ! current_user_can( 'install_languages' ) ) {
489                        // The user doesn't have caps to install language packs, so warn the client.
490                        $response[ $setting ] = 'error_cap';
491                        break;
492                    }
493
494                    $value = get_option( 'WPLANG', '' );
495                    if ( empty( $value ) && defined( 'WPLANG' ) ) {
496                        $value = WPLANG;
497                    }
498                    $response[ $setting ] = empty( $value ) ? 'en_US' : $value;
499                    break;
500
501                case 'wordpress_api_key':
502                    // When field is clear, return empty. Otherwise it would return "false".
503                    if ( '' === get_option( 'wordpress_api_key', '' ) ) {
504                        $response[ $setting ] = '';
505                    } else {
506                        if ( ! class_exists( 'Akismet' ) ) {
507                            if ( is_readable( WP_PLUGIN_DIR . '/akismet/class.akismet.php' ) ) {
508                                require_once WP_PLUGIN_DIR . '/akismet/class.akismet.php';
509                            }
510                        }
511                        $response[ $setting ] = class_exists( 'Akismet' ) ? Akismet::get_api_key() : '';
512                    }
513                    break;
514
515                case 'search_auto_config':
516                    // Only writable.
517                    $response[ $setting ] = 1;
518                    break;
519
520                default:
521                    $default              = $settings[ $setting ]['default'] ?? false;
522                    $response[ $setting ] = Jetpack_Core_Json_Api_Endpoints::cast_value( get_option( $setting, $default ), $settings[ $setting ] );
523                    break;
524            }
525        }
526
527        $response['akismet'] = is_plugin_active( 'akismet/akismet.php' );
528
529        require_once JETPACK__PLUGIN_DIR . '/modules/memberships/class-jetpack-memberships.php';
530        if ( class_exists( 'Jetpack_Memberships' ) ) {
531            $response['newsletter_has_active_plan'] = count( Jetpack_Memberships::get_all_newsletter_plan_ids( false ) ) > 0;
532        }
533
534        // Make sure we are returning a consistent type
535        if ( ! class_exists( 'Jetpack_Newsletter_Category_Helper' ) ) {
536            require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-newsletter-category-helper.php';
537        }
538        $response['wpcom_newsletter_categories'] = Jetpack_Newsletter_Category_Helper::get_category_ids();
539
540        return rest_ensure_response( $response );
541    }
542
543    /**
544     * If it's a valid Jetpack module and configuration parameters have been sent, update it.
545     *
546     * @since 4.3.0
547     *
548     * @param WP_REST_Request $request {
549     *     Array of parameters received by request.
550     *
551     *     @type string $slug Module slug.
552     * }
553     *
554     * @return bool|WP_REST_Response|WP_Error True or a WP_REST_Response if module was updated. Otherwise, a WP_Error instance with the corresponding error.
555     */
556    public function update_data( $request ) {
557
558        // If it's null, we're trying to update many module options from different modules.
559        if ( $request['slug'] === null ) {
560
561            // Value admitted by Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list that will make it return all module options.
562            // It will not be passed. It's just checked in this method to pass that method a string or array.
563            $request['slug'] = 'any';
564        } else {
565            if ( ! Jetpack::is_module( $request['slug'] ) ) {
566                return new WP_Error( 'not_found', esc_html__( 'The requested Jetpack module was not found.', 'jetpack' ), array( 'status' => 404 ) );
567            }
568
569            if ( ! Jetpack::is_module_active( $request['slug'] ) ) {
570                return new WP_Error( 'inactive', esc_html__( 'The requested Jetpack module is inactive.', 'jetpack' ), array( 'status' => 409 ) );
571            }
572        }
573
574        /*
575         * Get parameters to update the module.
576         * We cannot simply use $request->get_params() because when we registered this route,
577         * we are adding the entire output of Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list()
578         * to the current request object's params. We are interested in body of the actual request.
579         * This may be JSON:
580         */
581        $params = $request->get_json_params();
582        if ( ! is_array( $params ) ) {
583            // Or it may be standard POST key-value pairs.
584            $params = $request->get_body_params();
585        }
586
587        // Exit if no parameters were passed.
588        if ( ! is_array( $params ) ) {
589            return new WP_Error( 'missing_options', esc_html__( 'Missing options.', 'jetpack' ), array( 'status' => 404 ) );
590        }
591
592        // If $params was set via `get_body_params()` there may be some additional variables in the request that can
593        // cause validation to fail. This method verifies that each param was in fact updated and will throw a `some_updated`
594        // error if unused variables are included in the request.
595        foreach ( array_keys( $params ) as $key ) {
596            if ( is_int( $key ) || 'slug' === $key || 'context' === $key ) {
597                unset( $params[ $key ] );
598            }
599        }
600
601        // Get available module options.
602        $options = Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list(
603            'any' === $request['slug']
604            ? $params
605            : $request['slug']
606        );
607
608        // Prepare to toggle module if needed.
609        $toggle_module = new Jetpack_Core_API_Module_Toggle_Endpoint( new Jetpack_IXR_Client() );
610
611        // Options that are invalid or failed to update.
612        $invalid     = array_keys( array_diff_key( $params, $options ) );
613        $not_updated = array();
614
615        // Remove invalid options.
616        $params = array_intersect_key( $params, $options );
617
618        // Used if response is successful. The message can be overwritten and additional data can be added here.
619        $response = array(
620            'code'    => 'success',
621            'message' => esc_html__( 'The requested Jetpack data updates were successful.', 'jetpack' ),
622        );
623
624        // If there are modules to activate, activate them first so they're ready when their options are set.
625        foreach ( $params as $option => $value ) {
626            if ( 'modules' === $options[ $option ]['jp_group'] ) {
627
628                // Used if there was an error. Can be overwritten with specific error messages.
629                $error = '';
630
631                // Set to true if the module toggling was successful.
632                $updated = false;
633
634                // Check if user can toggle the module.
635                if ( $toggle_module->can_request() ) {
636
637                    // Activate or deactivate the module according to the value passed.
638                    $toggle_result = $value
639                        ? $toggle_module->activate_module( $option )
640                        : $toggle_module->deactivate_module( $option );
641
642                    if (
643                        is_wp_error( $toggle_result )
644                        && 'already_inactive' === $toggle_result->get_error_code()
645                    ) {
646
647                        // If the module is already inactive, we don't fail.
648                        $updated = true;
649                    } elseif ( is_wp_error( $toggle_result ) ) {
650                        $error = $toggle_result->get_error_message();
651                    } else {
652                        $updated = true;
653                    }
654                } else {
655                    $error = REST_Connector::get_user_permissions_error_msg();
656                }
657
658                // The module was not toggled.
659                if ( ! $updated ) {
660                    $not_updated[ $option ] = $error;
661                }
662
663                if ( $updated ) {
664                    // Return the module state.
665                    $response[ $option ] = $value;
666                }
667
668                // Remove module from list so we don't go through it again.
669                unset( $params[ $option ] );
670            }
671        }
672
673        if ( ! class_exists( 'Jetpack_Newsletter_Category_Helper' ) ) {
674            require_once JETPACK__PLUGIN_DIR . '_inc/lib/class-jetpack-newsletter-category-helper.php';
675        }
676
677        foreach ( $params as $option => $value ) {
678
679            // Used if there was an error. Can be overwritten with specific error messages.
680            $error = '';
681
682            // Set to true if the option update was successful.
683            $updated = false;
684
685            // Get option attributes, including the group it belongs to.
686            $option_attrs = $options[ $option ];
687
688            // Everything outside the Post by Email group requires the admin capability.
689            if ( 'post-by-email' !== $option_attrs['jp_group'] && ! current_user_can( 'jetpack_configure_modules' ) ) {
690                $not_updated[ $option ] = REST_Connector::get_user_permissions_error_msg();
691                continue;
692            }
693
694            // If this is a module option and the related module isn't active for any reason, continue with the next one.
695            if ( 'settings' !== $option_attrs['jp_group'] ) {
696                if ( ! Jetpack::is_module( $option_attrs['jp_group'] ) ) {
697                    $not_updated[ $option ] = esc_html__( 'The requested Jetpack module was not found.', 'jetpack' );
698                    continue;
699                }
700
701                if (
702                    'any' !== $request['slug']
703                    && ! Jetpack::is_module_active( $option_attrs['jp_group'] )
704                ) {
705
706                    // We only take note of skipped options when updating one module.
707                    $not_updated[ $option ] = esc_html__( 'The requested Jetpack module is inactive.', 'jetpack' );
708                    continue;
709                }
710            }
711
712            // Properly cast value based on its type defined in endpoint accepted args.
713            $value = Jetpack_Core_Json_Api_Endpoints::cast_value( $value, $option_attrs );
714
715            switch ( $option ) {
716                case 'lang_id':
717                    if ( ! current_user_can( 'install_languages' ) ) {
718                        // We can't affect this setting.
719                        $updated = false;
720                        break;
721                    }
722
723                    if ( 'en_US' === $value || empty( $value ) ) {
724                        return delete_option( 'WPLANG' );
725                    }
726
727                    if ( ! function_exists( 'request_filesystem_credentials' ) ) {
728                        require_once ABSPATH . 'wp-admin/includes/file.php';
729                    }
730
731                    if ( ! function_exists( 'wp_download_language_pack' ) ) {
732                        require_once ABSPATH . 'wp-admin/includes/translation-install.php';
733                    }
734
735                    // `wp_download_language_pack` only tries to download packs if they're not already available.
736                    $language = wp_download_language_pack( $value );
737                    if ( false === $language ) {
738                        // The language pack download failed.
739                        $updated = false;
740                        break;
741                    }
742                    $updated = get_option( 'WPLANG' ) === $language ? true : update_option( 'WPLANG', $language );
743                    break;
744
745                case 'monitor_receive_notifications':
746                    if ( ! class_exists( 'Jetpack_Monitor' ) ) {
747                        $updated = false;
748                        break;
749                    }
750
751                    $monitor = new Jetpack_Monitor();
752
753                    // If we got true as response, consider it done.
754                    $updated = true === $monitor->update_option_receive_jetpack_monitor_notification( $value );
755                    break;
756
757                case 'post_by_email_address':
758                    if ( ! class_exists( 'Jetpack_Post_By_Email' ) ) {
759                        $updated = false;
760                        break;
761                    }
762
763                    $result = Jetpack_Post_By_Email::init()->process_api_request( $value );
764
765                    // If we got an email address (create or regenerate) or 1 (delete), consider it done.
766                    if ( is_string( $result ) && preg_match( '/[a-z0-9]+@post.wordpress.com/', $result ) ) {
767                        $response[ $option ] = $result;
768                        $updated             = true;
769                    } elseif ( 1 == $result ) { // phpcs:ignore Universal.Operators.StrictComparisons.LooseEqual
770                        $updated = true;
771                    } elseif ( is_array( $result ) && isset( $result['message'] ) ) {
772                        $error = $result['message'];
773                    }
774                    break;
775
776                case 'jetpack_protect_key':
777                    $brute_force_protection = Brute_Force_Protection::instance();
778                    if ( 'create' === $value ) {
779                        $result = $brute_force_protection->get_protect_key();
780                    } else {
781                        $result = false;
782                    }
783
784                    // If we got one of Protect keys, consider it done.
785                    if ( is_string( $result ) && preg_match( '/[a-z0-9]{40,}/i', $result ) ) {
786                        $response[ $option ] = $result;
787                        $updated             = true;
788                    }
789                    break;
790
791                case 'jetpack_protect_global_whitelist':
792                    $updated = Brute_Force_Protection_Shared_Functions::save_allow_list( explode( PHP_EOL, str_replace( array( ' ', ',' ), array( '', "\n" ), $value ) ) );
793
794                    if ( is_wp_error( $updated ) ) {
795                        $error = $updated->get_error_message();
796                    }
797                    break;
798
799                case 'show_headline':
800                case 'show_thumbnails':
801                    $grouped_options_current    = (array) Jetpack_Options::get_option( 'relatedposts' );
802                    $grouped_options            = $grouped_options_current;
803                    $grouped_options[ $option ] = $value;
804
805                    // If option value was the same, consider it done.
806                    $updated = $grouped_options_current !== $grouped_options ? Jetpack_Options::update_option( 'relatedposts', $grouped_options ) : true;
807                    break;
808
809                case 'search_auto_config':
810                    if ( ! $value ) {
811                        // Skip execution if no value is specified.
812                        $updated = true;
813                    } else {
814                        $plan = new Automattic\Jetpack\Search\Plan();
815                        if ( ! $plan->supports_instant_search() ) {
816                            $updated = new WP_Error( 'instant_search_not_supported', 'Instant Search is not supported by this site', array( 'status' => 400 ) );
817                            $error   = $updated->get_error_message();
818                        } elseif ( ! Automattic\Jetpack\Search\Options::is_instant_enabled() ) {
819                            $updated = new WP_Error( 'instant_search_disabled', 'Instant Search is disabled', array( 'status' => 400 ) );
820                            $error   = $updated->get_error_message();
821                        } else {
822                            $blog_id  = Automattic\Jetpack\Search\Helper::get_wpcom_site_id();
823                            $instance = Automattic\Jetpack\Search\Instant_Search::instance( $blog_id );
824                            $instance->auto_config_search();
825                            $updated = true;
826                        }
827                    }
828                    break;
829
830                case 'google':
831                case 'bing':
832                case 'pinterest':
833                case 'yandex':
834                case 'facebook':
835                    $grouped_options_current = (array) get_option( 'verification_services_codes' );
836                    $grouped_options         = $grouped_options_current;
837
838                    $validated_code = jetpack_verification_validate_code( $value );
839                    if ( false === $validated_code ) {
840                        $error = esc_html__( 'The site verification code is invalid.', 'jetpack' );
841                        break;
842                    }
843
844                    $grouped_options[ $option ] = $validated_code;
845
846                    // If option value was the same, consider it done.
847                    $updated = $grouped_options_current !== $grouped_options
848                        ? update_option( 'verification_services_codes', $grouped_options )
849                        : true;
850                    break;
851
852                case Jetpack_SEO_Utils::FRONT_PAGE_META_OPTION:
853                    Jetpack_SEO_Utils::update_front_page_meta_description( $value );
854                    $response[ $option ] = Jetpack_SEO_Utils::get_front_page_meta_description();
855                    // The helper returns an empty string for a successful clear or
856                    // same-value write, so use its authoritative getter for the response
857                    // and treat every valid request reaching this switch as handled.
858                    $updated = true;
859                    break;
860
861                case 'sharing_services':
862                    if ( ! class_exists( 'Sharing_Service' ) && ! include_once JETPACK__PLUGIN_DIR . 'modules/sharedaddy/sharing-service.php' ) {
863                        break;
864                    }
865
866                    $sharer = new Sharing_Service();
867
868                    // If option value was the same, consider it done.
869                    $updated = $value !== $sharer->get_blog_services()
870                        ? $sharer->set_blog_services( $value['visible'], $value['hidden'] )
871                        : true;
872                    break;
873
874                case 'button_style':
875                case 'sharing_label':
876                case 'show':
877                    if ( ! class_exists( 'Sharing_Service' ) && ! include_once JETPACK__PLUGIN_DIR . 'modules/sharedaddy/sharing-service.php' ) {
878                        break;
879                    }
880
881                    $sharer                     = new Sharing_Service();
882                    $grouped_options            = $sharer->get_global_options();
883                    $grouped_options[ $option ] = $value;
884                    $updated                    = $sharer->set_global_options( $grouped_options );
885                    break;
886
887                case 'custom':
888                    if ( ! class_exists( 'Sharing_Service' ) && ! include_once JETPACK__PLUGIN_DIR . 'modules/sharedaddy/sharing-service.php' ) {
889                        break;
890                    }
891
892                    $sharer  = new Sharing_Service();
893                    $updated = $sharer->new_service( stripslashes( $value['sharing_name'] ), stripslashes( $value['sharing_url'] ), stripslashes( $value['sharing_icon'] ) );
894
895                    // Return new custom service.
896                    $response[ $option ] = $updated;
897                    break;
898
899                case 'sharing_delete_service':
900                    if ( ! class_exists( 'Sharing_Service' ) && ! include_once JETPACK__PLUGIN_DIR . 'modules/sharedaddy/sharing-service.php' ) {
901                        break;
902                    }
903
904                    $sharer  = new Sharing_Service();
905                    $updated = $sharer->delete_service( $value );
906                    break;
907
908                case 'jetpack-twitter-cards-site-tag':
909                    $value   = trim( ltrim( wp_strip_all_tags( $value ), '@' ) );
910                    $updated = get_option( $option ) !== $value ? update_option( $option, $value ) : true;
911                    break;
912
913                case 'admin_bar':
914                case 'roles':
915                case 'count_roles':
916                case 'blog_id':
917                case 'do_not_track':
918                case 'version':
919                case 'collapse_nudges':
920                    $grouped_options_current    = (array) get_option( 'stats_options' );
921                    $grouped_options            = $grouped_options_current;
922                    $grouped_options[ $option ] = $value;
923
924                    // If option value was the same, consider it done.
925                    $updated = $grouped_options_current !== $grouped_options
926                        ? update_option( 'stats_options', $grouped_options )
927                        : true;
928                    break;
929
930                case 'enable_odyssey_stats':
931                    $updated = Stats_Admin_Main::update_new_stats_status( $value );
932
933                    break;
934
935                case 'akismet_show_user_comments_approved':
936                    // Save Akismet option '1' or '0' like it's done in akismet/class.akismet-admin.php.
937                    $updated = get_option( $option ) != $value // phpcs:ignore Universal.Operators.StrictComparisons.LooseNotEqual
938                        ? update_option( $option, $value ? '1' : '0' )
939                        : true;
940                    break;
941
942                case 'wordpress_api_key':
943                    if ( ! file_exists( WP_PLUGIN_DIR . '/akismet/class.akismet.php' ) ) {
944                        $error   = esc_html__( 'Please install Akismet.', 'jetpack' );
945                        $updated = false;
946                        break;
947                    }
948
949                    if ( ! defined( 'AKISMET_VERSION' ) ) {
950                        $error   = esc_html__( 'Please activate Akismet.', 'jetpack' );
951                        $updated = false;
952                        break;
953                    }
954
955                    // Allow to clear the API key field.
956                    if ( '' === $value ) {
957                        $updated = get_option( $option ) !== $value
958                            ? update_option( $option, $value )
959                            : true;
960                        break;
961                    }
962
963                    require_once WP_PLUGIN_DIR . '/akismet/class.akismet.php';
964                    require_once WP_PLUGIN_DIR . '/akismet/class.akismet-admin.php';
965
966                    if ( class_exists( 'Akismet_Admin' ) && method_exists( 'Akismet_Admin', 'save_key' ) ) {
967                        if ( Akismet::verify_key( $value ) === 'valid' ) {
968                            $akismet_user = Akismet_Admin::get_akismet_user( $value );
969                            if ( $akismet_user ) {
970                                if ( in_array( $akismet_user->status, array( 'active', 'active-dunning', 'no-sub' ), true ) ) {
971                                    $updated = get_option( $option ) !== $value
972                                        ? update_option( $option, $value )
973                                        : true;
974                                    break;
975                                } else {
976                                    $error = esc_html__( "Akismet user status doesn't allow to update the key", 'jetpack' );
977                                }
978                            } else {
979                                $error = esc_html__( 'Invalid Akismet user', 'jetpack' );
980                            }
981                        } else {
982                            $error = esc_html__( 'Invalid Akismet key', 'jetpack' );
983                        }
984                    } else {
985                        $error = esc_html__( 'Akismet is not installed or active', 'jetpack' );
986                    }
987                    $updated = false;
988                    break;
989
990                case 'google_analytics_tracking_id':
991                    $grouped_options_current = (array) get_option( 'jetpack_wga' );
992                    $grouped_options         = $grouped_options_current;
993                    $grouped_options['code'] = $value;
994
995                    // If option value was the same, consider it done.
996                    $updated = $grouped_options_current !== $grouped_options
997                        ? update_option( 'jetpack_wga', $grouped_options )
998                        : true;
999                    break;
1000
1001                case 'dismiss_empty_stats_card':
1002                case 'dismiss_dash_backup_getting_started':
1003                case 'dismiss_dash_agencies_learn_more':
1004                    // If option value was the same, consider it done.
1005                    $updated = get_option( $option ) != $value // phpcs:ignore Universal.Operators.StrictComparisons.LooseNotEqual -- ensure we support bools or strings saved by update_option.
1006                        ? update_option( $option, (bool) $value )
1007                        : true;
1008                    break;
1009
1010                case 'jetpack_subscriptions_reply_to':
1011                    // If option value was the same, consider it done.
1012                    require_once JETPACK__PLUGIN_DIR . 'modules/subscriptions/class-settings.php';
1013                    $sub_value = Automattic\Jetpack\Modules\Subscriptions\Settings::is_valid_reply_to( $value )
1014                        ? $value
1015                        : Automattic\Jetpack\Modules\Subscriptions\Settings::$default_reply_to;
1016
1017                        $updated = (string) get_option( $option ) !== (string) $sub_value ? update_option( $option, $sub_value ) : true;
1018                    break;
1019                case 'jetpack_subscriptions_from_name':
1020                    // If option value was the same, consider it done.
1021                    $sub_value = sanitize_text_field( $value );
1022                    $updated   = (string) get_option( $option ) !== (string) $sub_value ? update_option( $option, $sub_value ) : true;
1023                    break;
1024
1025                case 'stb_enabled':
1026                case 'stc_enabled':
1027                case 'sm_enabled':
1028                case 'jetpack_subscribe_overlay_enabled':
1029                case 'jetpack_subscribe_floating_button_enabled':
1030                case 'wpcom_newsletter_categories_enabled':
1031                case 'wpcom_featured_image_in_email':
1032                case 'jetpack_gravatar_in_email':
1033                case 'jetpack_author_in_email':
1034                case 'jetpack_post_date_in_email':
1035                case 'wpcom_subscription_emails_use_excerpt':
1036                case 'jetpack_subscriptions_subscribe_post_end_enabled':
1037                case 'jetpack_subscriptions_login_navigation_enabled':
1038                case 'jetpack_subscriptions_subscribe_navigation_enabled':
1039                    // Convert the false value to 0. This allows the option to be updated if it doesn't exist yet.
1040                    $sub_value = $value ? $value : 0;
1041                    $updated   = (string) get_option( $option ) !== (string) $sub_value ? update_option( $option, $sub_value ) : true;
1042                    break;
1043
1044                case 'jetpack_blocks_disabled':
1045                    $updated = (bool) get_option( $option ) !== (bool) $value ? update_option( $option, (bool) $value ) : true;
1046                    break;
1047
1048                case 'subscription_options':
1049                    if ( ! is_array( $value ) ) {
1050                        break;
1051                    }
1052
1053                    $allowed_keys   = array( 'invitation', 'comment_follow', 'welcome', 'subscribe_modal_heading', 'free_tier_description', 'hide_free_tier' );
1054                    $filtered_value = array_filter(
1055                        $value,
1056                        function ( $key ) use ( $allowed_keys ) {
1057                            return in_array( $key, $allowed_keys, true );
1058                        },
1059                        ARRAY_FILTER_USE_KEY
1060                    );
1061
1062                    if ( empty( $filtered_value ) ) {
1063                        break;
1064                    }
1065
1066                    // `hide_free_tier` is a boolean flag, so pull it out before the HTML
1067                    // sanitization below (which expects strings). Sanitize it with
1068                    // rest_sanitize_boolean() so stringy booleans (e.g. "false", "0")
1069                    // are interpreted correctly rather than being treated as truthy by a
1070                    // plain `! empty()`.
1071                    $has_hide_free_tier = array_key_exists( 'hide_free_tier', $filtered_value );
1072                    $hide_free_tier     = $has_hide_free_tier && rest_sanitize_boolean( $filtered_value['hide_free_tier'] );
1073                    unset( $filtered_value['hide_free_tier'] );
1074
1075                    array_walk_recursive(
1076                        $filtered_value,
1077                        function ( &$value ) {
1078                            $value = wp_kses(
1079                                $value,
1080                                array(
1081                                    'ul'     => array(),
1082                                    'li'     => array(),
1083                                    'p'      => array(),
1084                                    'strong' => array(),
1085                                    'ol'     => array(),
1086                                    'em'     => array(),
1087                                    'a'      => array(
1088                                        'href' => array(),
1089                                    ),
1090                                )
1091                            );
1092                        }
1093                    );
1094
1095                    // Normalize whitespace-only `subscribe_modal_heading` input to empty so
1096                    // the modal template's `empty()` fallback fires. PHP's `empty()` treats
1097                    // `"   "` as non-empty, which would otherwise render a blank heading.
1098                    if ( isset( $filtered_value['subscribe_modal_heading'] ) ) {
1099                        $filtered_value['subscribe_modal_heading'] = trim( $filtered_value['subscribe_modal_heading'] );
1100                    }
1101
1102                    // The free tier description is stored as plain markdown source, so strip
1103                    // all HTML and cap its length to match the paid-tier description field.
1104                    // WordPress core guarantees mb_substr() (polyfilled in wp-includes/compat.php
1105                    // when the mbstring extension is unavailable), so it's safe to use directly.
1106                    // A JSON payload could supply a non-scalar (array/object) for this field,
1107                    // which would fatal in wp_kses()/mb_substr() on PHP 8+, so drop invalid values.
1108                    if ( isset( $filtered_value['free_tier_description'] ) ) {
1109                        if ( is_scalar( $filtered_value['free_tier_description'] ) ) {
1110                            $filtered_value['free_tier_description'] = mb_substr( wp_kses( (string) $filtered_value['free_tier_description'], array() ), 0, 500 );
1111                        } else {
1112                            unset( $filtered_value['free_tier_description'] );
1113                        }
1114                    }
1115
1116                    if ( $has_hide_free_tier ) {
1117                        $filtered_value['hide_free_tier'] = $hide_free_tier;
1118                    }
1119
1120                    $old_subscription_options = get_option( 'subscription_options' );
1121                    if ( ! is_array( $old_subscription_options ) ) {
1122                        $old_subscription_options = array();
1123                    }
1124                    $new_subscription_options = array_merge( $old_subscription_options, $filtered_value );
1125                    $updated                  = true;
1126
1127                    if ( serialize( $old_subscription_options ) === serialize( $new_subscription_options ) ) { // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.serialize_serialize
1128                        break; // This prevents the option update to fail when the values are the same.
1129                    }
1130
1131                    if ( ! update_option( $option, $new_subscription_options ) ) {
1132                        $updated = false;
1133                        $error   = esc_html__( 'Subscription Options failed to process.', 'jetpack' );
1134                    }
1135                    break;
1136
1137                case Jetpack_Newsletter_Category_Helper::NEWSLETTER_CATEGORIES_OPTION:
1138                    if ( ! is_array( $value ) || empty( $value ) ) {
1139                        $updated = true;
1140                        break;
1141                    }
1142
1143                    // If we are already current, do nothing
1144                    $current_value = Jetpack_Newsletter_Category_Helper::get_category_ids();
1145                    if ( $value === $current_value ) {
1146                        $updated = true;
1147                        break;
1148                    }
1149
1150                    if ( Jetpack_Newsletter_Category_Helper::save_category_ids( $value ) ) {
1151                        $updated = true;
1152                    } else {
1153                        $updated = false;
1154                        $error   = esc_html__( 'Newsletter category did not update.', 'jetpack' );
1155                    }
1156
1157                    break;
1158
1159                default:
1160                    // Boolean values are stored as 1 or 0.
1161                    if ( isset( $options[ $option ]['type'] ) && 'boolean' === $options[ $option ]['type'] ) {
1162                        $value = (int) $value;
1163                    }
1164
1165                    // If option value was the same as it's current value, or it's default, consider it done.
1166                    $default = $options[ $option ]['default'] ?? false;
1167                    $updated = get_option( $option, $default ) != $value // phpcs:ignore Universal.Operators.StrictComparisons.LooseNotEqual -- ensure we support scalars or strings saved by update_option.
1168                        ? update_option( $option, $value )
1169                        : true;
1170                    break;
1171            }
1172
1173            // The option was not updated.
1174            if ( ! $updated ) {
1175                $not_updated[ $option ] = $error;
1176            }
1177        }
1178
1179        if ( empty( $invalid ) && empty( $not_updated ) ) {
1180            // The option was updated.
1181            return rest_ensure_response( $response );
1182        } else {
1183            $invalid_count     = count( $invalid );
1184            $not_updated_count = count( $not_updated );
1185            $error             = '';
1186            if ( $invalid_count > 0 ) {
1187                $error = sprintf(
1188                /* Translators: the plural variable is a comma-separated list. Example: dog, cat, bird. */
1189                    _n( 'Invalid option: %s.', 'Invalid options: %s.', $invalid_count, 'jetpack' ),
1190                    implode( ', ', $invalid )
1191                );
1192            }
1193            if ( $not_updated_count > 0 ) {
1194                $not_updated_messages = array();
1195                foreach ( $not_updated as $not_updated_option => $not_updated_message ) {
1196                    if ( ! empty( $not_updated_message ) ) {
1197                        $not_updated_messages[] = sprintf(
1198                            /* Translators: the first variable is a module option or slug, or setting. The second is the error message . */
1199                            __( '%1$s: %2$s', 'jetpack' ),
1200                            $not_updated_option,
1201                            $not_updated_message
1202                        );
1203                    }
1204                }
1205                if ( ! empty( $error ) ) {
1206                    $error .= ' ';
1207                }
1208                if ( ! empty( $not_updated_messages ) ) {
1209                    $error .= ' ' . implode( '. ', $not_updated_messages );
1210                }
1211            }
1212            // There was an error because some options were updated but others were invalid or failed to update.
1213            return new WP_Error( 'some_updated', esc_html( $error ), array( 'status' => 400 ) );
1214        }
1215    }
1216
1217    /**
1218     * Perform tasks in the site based on onboarding choices.
1219     *
1220     * @since 5.4.0
1221     *
1222     * @deprecated since 13.9
1223     *
1224     * @param array $data Onboarding choices made by user.
1225     *
1226     * @return string Result of onboarding processing and, if there is one, an error message.
1227     */
1228    private function process_onboarding( $data ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
1229        _deprecated_function( __METHOD__, '13.9' );
1230        return '';
1231    }
1232
1233    /**
1234     * Add or update Business Address widget.
1235     *
1236     * @deprecated since 13.9
1237     *
1238     * @param array $address Array of business address fields.
1239     *
1240     * @return WP_Error|true True if the data was saved correctly.
1241     */
1242    private static function handle_business_address( $address ) {
1243        _deprecated_function( __METHOD__, '13.9' );
1244        $first_sidebar = Jetpack_Widgets::get_first_sidebar();
1245
1246        $widgets_module_active = Jetpack::is_module_active( 'widgets' );
1247        if ( ! $widgets_module_active ) {
1248            $widgets_module_active = Jetpack::activate_module( 'widgets', false, false );
1249        }
1250        if ( ! $widgets_module_active ) {
1251            return new WP_Error( 'module_activation_failed', 'Failed to activate the widgets module.', 400 );
1252        }
1253
1254        if ( $first_sidebar ) {
1255            $title   = isset( $address['name'] ) ? sanitize_text_field( $address['name'] ) : '';
1256            $street  = isset( $address['street'] ) ? sanitize_text_field( $address['street'] ) : '';
1257            $city    = isset( $address['city'] ) ? sanitize_text_field( $address['city'] ) : '';
1258            $state   = isset( $address['state'] ) ? sanitize_text_field( $address['state'] ) : '';
1259            $zip     = isset( $address['zip'] ) ? sanitize_text_field( $address['zip'] ) : '';
1260            $country = isset( $address['country'] ) ? sanitize_text_field( $address['country'] ) : '';
1261
1262            $full_address = implode( ' ', array_filter( array( $street, $city, $state, $zip, $country ) ) );
1263
1264            $widget_options = array(
1265                'title'   => $title,
1266                'address' => $full_address,
1267                'phone'   => '',
1268                'hours'   => '',
1269                'showmap' => false,
1270                'email'   => '',
1271            );
1272
1273            $widget_updated = '';
1274            if ( ! self::has_business_address_widget( $first_sidebar ) ) {
1275                $widget_updated = Jetpack_Widgets::insert_widget_in_sidebar( 'widget_contact_info', $widget_options, $first_sidebar );
1276            } else {
1277                $widget_updated = Jetpack_Widgets::update_widget_in_sidebar( 'widget_contact_info', $widget_options, $first_sidebar );
1278            }
1279            if ( is_wp_error( $widget_updated ) ) {
1280                return new WP_Error( 'widget_update_failed', 'Widget could not be updated.', 400 );
1281            }
1282
1283            $address_save = array(
1284                'name'    => $title,
1285                'street'  => $street,
1286                'city'    => $city,
1287                'state'   => $state,
1288                'zip'     => $zip,
1289                'country' => $country,
1290            );
1291            update_option( 'jpo_business_address', $address_save );
1292            return true;
1293        }
1294
1295        // No sidebar to place the widget.
1296        return new WP_Error( 'sidebar_not_found', 'No sidebar.', 400 );
1297    }
1298
1299    /**
1300     * Check whether "Contact Info & Map" widget is present in a given sidebar.
1301     *
1302     * @param string $sidebar ID of the sidebar to which the widget will be added.
1303     *
1304     * @return bool Whether the widget is present in a given sidebar.
1305     */
1306    private static function has_business_address_widget( $sidebar ) {
1307        $sidebars_widgets = get_option( 'sidebars_widgets', array() );
1308        if ( ! isset( $sidebars_widgets[ $sidebar ] ) ) {
1309            return false;
1310        }
1311        foreach ( $sidebars_widgets[ $sidebar ] as $widget ) {
1312            if ( str_contains( $widget, 'widget_contact_info' ) ) {
1313                return true;
1314            }
1315        }
1316        return false;
1317    }
1318
1319    /**
1320     * Check if user is allowed to perform the update.
1321     *
1322     * @since 4.3.0
1323     *
1324     * @param WP_REST_Request $request The request sent to the WP REST API.
1325     *
1326     * @return bool
1327     */
1328    public function can_request( $request ) {
1329        if ( 'GET' === $request->get_method() ) {
1330            return current_user_can( 'jetpack_admin_page' );
1331        } else {
1332            $module = Jetpack_Core_Json_Api_Endpoints::get_module_requested();
1333            if ( empty( $module ) ) {
1334                $params = $request->get_json_params();
1335                if ( ! is_array( $params ) ) {
1336                    $params = $request->get_body_params();
1337                }
1338                $options = Jetpack_Core_Json_Api_Endpoints::get_updateable_data_list( $params );
1339
1340                // The Post by Email gate applies only when the request contains nothing else.
1341                $groups = array_values( array_unique( array_column( $options, 'jp_group' ) ) );
1342                if ( array( 'post-by-email' ) === $groups ) {
1343                    $module = 'post-by-email';
1344                }
1345            }
1346            // User is trying to create, regenerate or delete its PbE.
1347            if ( 'post-by-email' === $module ) {
1348                return current_user_can( 'edit_posts' ) && current_user_can( 'jetpack_admin_page' );
1349            }
1350            return current_user_can( 'jetpack_configure_modules' );
1351        }
1352    }
1353}
1354
1355/**
1356 * Get detailed data from a specific module.
1357 *
1358 * phpcs:disable Generic.Files.OneObjectStructurePerFile.MultipleFound
1359 */
1360class Jetpack_Core_API_Module_Data_Endpoint {
1361
1362    /**
1363     * Process request and return different data based on the module we are interested in.
1364     *
1365     * @param WP_REST_Request $request WP API request.
1366     *
1367     * @return WP_REST_Response|WP_Error A REST response if the request was served successfully, otherwise an error.
1368     */
1369    public function process( $request ) {
1370        switch ( $request['slug'] ) {
1371            case 'protect':
1372                return $this->get_protect_data();
1373            case 'stats':
1374                return $this->get_stats_data( $request );
1375            case 'akismet':
1376                return $this->get_akismet_data();
1377            case 'monitor':
1378                return $this->get_monitor_data();
1379            case 'verification-tools':
1380                return $this->get_verification_tools_data();
1381            case 'vaultpress':
1382                return $this->get_vaultpress_data();
1383        }
1384    }
1385
1386    /**
1387     * Decide against which service to check the key.
1388     *
1389     * @since 4.8.0
1390     *
1391     * @param WP_REST_Request $request WP API request.
1392     *
1393     * @return bool
1394     */
1395    public function key_check( $request ) {
1396        switch ( $request['service'] ) {
1397            case 'akismet':
1398                $params = $request->get_json_params();
1399                if ( isset( $params['api_key'] ) && ! empty( $params['api_key'] ) ) {
1400                    return $this->check_akismet_key( $params['api_key'] );
1401                }
1402                return $this->check_akismet_key();
1403        }
1404        return false;
1405    }
1406
1407    /**
1408     * Get number of blocked intrusion attempts.
1409     *
1410     * @since 4.3.0
1411     *
1412     * @return mixed|WP_Error Number of blocked attempts if protection is enabled. Otherwise, a WP_Error instance with the corresponding error.
1413     */
1414    public function get_protect_data() {
1415        if ( Jetpack::is_module_active( 'protect' ) ) {
1416            return (int) get_site_option( 'jetpack_protect_blocked_attempts', 0 );
1417        }
1418
1419        return new WP_Error(
1420            'not_active',
1421            esc_html__( 'The requested Jetpack module is not active.', 'jetpack' ),
1422            array( 'status' => 404 )
1423        );
1424    }
1425
1426    /**
1427     * Get number of spam messages blocked by Akismet.
1428     *
1429     * @since 4.3.0
1430     *
1431     * @return int|string Number of spam blocked by Akismet. Otherwise, an error message.
1432     */
1433    public function get_akismet_data() {
1434        $akismet_status = $this->akismet_is_active_and_registered();
1435        if ( ! is_wp_error( $akismet_status ) ) {
1436            return (int) get_option( 'akismet_spam_count', 0 );
1437        } else {
1438            return $akismet_status->get_error_code();
1439        }
1440    }
1441
1442    /**
1443     * Verify the Akismet API key.
1444     *
1445     * @since 4.8.0
1446     *
1447     * @param string $api_key Optional API key to check.
1448     *
1449     * @return array Information about the key. 'validKey' is true if key is valid, false otherwise.
1450     */
1451    public function check_akismet_key( $api_key = '' ) {
1452        $akismet_status = $this->akismet_class_exists();
1453        if ( is_wp_error( $akismet_status ) ) {
1454            return rest_ensure_response(
1455                array(
1456                    'validKey'          => false,
1457                    'invalidKeyCode'    => $akismet_status->get_error_code(),
1458                    'invalidKeyMessage' => $akismet_status->get_error_message(),
1459                )
1460            );
1461        }
1462
1463        $key_status = Akismet::check_key_status( empty( $api_key ) ? Akismet::get_api_key() : $api_key );
1464
1465        if ( ! $key_status || 'invalid' === $key_status || 'failed' === $key_status ) {
1466            return rest_ensure_response(
1467                array(
1468                    'validKey'          => false,
1469                    'invalidKeyCode'    => 'invalid_key',
1470                    'invalidKeyMessage' => esc_html__( 'Invalid Akismet key. Please contact support.', 'jetpack' ),
1471                )
1472            );
1473        }
1474
1475        return rest_ensure_response(
1476            array(
1477                'validKey' => isset( $key_status[1] ) && 'valid' === $key_status[1],
1478            )
1479        );
1480    }
1481
1482    /**
1483     * Check if Akismet class file exists and if class is loaded.
1484     *
1485     * @since 4.8.0
1486     *
1487     * @return bool|WP_Error Returns true if class file exists and class is loaded, WP_Error otherwise.
1488     */
1489    private function akismet_class_exists() {
1490        if ( ! file_exists( WP_PLUGIN_DIR . '/akismet/class.akismet.php' ) ) {
1491            return new WP_Error( 'not_installed', esc_html__( 'Please install Akismet.', 'jetpack' ), array( 'status' => 400 ) );
1492        }
1493
1494        if ( ! class_exists( 'Akismet' ) ) {
1495            return new WP_Error( 'not_active', esc_html__( 'Please activate Akismet.', 'jetpack' ), array( 'status' => 400 ) );
1496        }
1497
1498        return true;
1499    }
1500
1501    /**
1502     * Is Akismet registered and active?
1503     *
1504     * @since 4.3.0
1505     *
1506     * @return bool|WP_Error True if Akismet is active and registered. Otherwise, a WP_Error instance with the corresponding error.
1507     */
1508    private function akismet_is_active_and_registered() {
1509        $akismet_exists = $this->akismet_class_exists();
1510        if ( is_wp_error( $akismet_exists ) ) {
1511            return $akismet_exists;
1512        }
1513
1514        // What about if Akismet is put in a sub-directory or maybe in mu-plugins?
1515        require_once WP_PLUGIN_DIR . '/akismet/class.akismet.php';
1516        require_once WP_PLUGIN_DIR . '/akismet/class.akismet-admin.php';
1517        $akismet_key = Akismet::verify_key( Akismet::get_api_key() );
1518
1519        if ( ! $akismet_key || 'invalid' === $akismet_key || 'failed' === $akismet_key ) {
1520            return new WP_Error( 'invalid_key', esc_html__( 'Invalid Akismet key. Please contact support.', 'jetpack' ), array( 'status' => 400 ) );
1521        }
1522
1523        return true;
1524    }
1525
1526    /**
1527     * Get stats data for this site
1528     *
1529     * @since 4.1.0
1530     *
1531     * @param WP_REST_Request $request {
1532     *     Array of parameters received by request.
1533     *
1534     *     @type string $date Date range to restrict results to.
1535     * }
1536     *
1537     * @return WP_Error|WP_HTTP_Response|WP_REST_Response Stats information relayed from WordPress.com.
1538     */
1539    public function get_stats_data( WP_REST_Request $request ) {
1540        // Get parameters to fetch Stats data.
1541        $range = $request->get_param( 'range' );
1542
1543        // If no parameters were passed.
1544        if (
1545            empty( $range )
1546            || ! in_array( $range, array( 'day', 'week', 'month' ), true )
1547        ) {
1548            $range = 'day';
1549        }
1550
1551        $wpcom_stats = new WPCOM_Stats();
1552        switch ( $range ) {
1553
1554            // This is always called first on page load.
1555            case 'day':
1556                $initial_stats = $wpcom_stats->convert_stats_array_to_object( $wpcom_stats->get_stats() );
1557                return rest_ensure_response(
1558                    array(
1559                        'general' => $initial_stats,
1560
1561                        // Build data for 'day' as if it was $wpcom_stats ->get_visits( array( 'unit' => 'day, 'quantity' => 30).
1562                        'day'     => $initial_stats->visits ?? array(),
1563                    )
1564                );
1565            case 'week':
1566                return rest_ensure_response(
1567                    array(
1568                        'week' => $wpcom_stats->convert_stats_array_to_object(
1569                            $wpcom_stats->get_visits(
1570                                array(
1571                                    'unit'     => 'week',
1572                                    'quantity' => 14,
1573                                )
1574                            )
1575                        ),
1576                    )
1577                );
1578            case 'month':
1579                return rest_ensure_response(
1580                    array(
1581                        'month' => $wpcom_stats->convert_stats_array_to_object(
1582                            $wpcom_stats->get_visits(
1583                                array(
1584                                    'unit'     => 'month',
1585                                    'quantity' => 12,
1586                                )
1587                            )
1588                        ),
1589                    )
1590                );
1591        }
1592    }
1593
1594    /**
1595     * Get date of last downtime.
1596     *
1597     * @since 4.3.0
1598     *
1599     * @return mixed|WP_Error Number of days since last downtime. Otherwise, a WP_Error instance with the corresponding error.
1600     */
1601    public function get_monitor_data() {
1602        if ( ! Jetpack::is_module_active( 'monitor' ) ) {
1603            return new WP_Error(
1604                'not_active',
1605                esc_html__( 'The requested Jetpack module is not active.', 'jetpack' ),
1606                array( 'status' => 404 )
1607            );
1608        }
1609
1610        $monitor       = new Jetpack_Monitor();
1611        $last_downtime = $monitor->monitor_get_last_downtime();
1612        if ( is_wp_error( $last_downtime ) ) {
1613            return $last_downtime;
1614        } elseif ( false === strtotime( $last_downtime ) ) {
1615            return rest_ensure_response(
1616                array(
1617                    'code' => 'success',
1618                    'date' => null,
1619                )
1620            );
1621        } else {
1622            return rest_ensure_response(
1623                array(
1624                    'code' => 'success',
1625                    'date' => human_time_diff( strtotime( $last_downtime ), strtotime( 'now' ) ),
1626                )
1627            );
1628        }
1629    }
1630
1631    /**
1632     * Get services that this site is verified with.
1633     *
1634     * @since 4.3.0
1635     *
1636     * @return mixed|WP_Error List of services that verified this site. Otherwise, a WP_Error instance with the corresponding error.
1637     */
1638    public function get_verification_tools_data() {
1639        if ( ! Jetpack::is_module_active( 'verification-tools' ) ) {
1640            return new WP_Error(
1641                'not_active',
1642                esc_html__( 'The requested Jetpack module is not active.', 'jetpack' ),
1643                array( 'status' => 404 )
1644            );
1645        }
1646
1647        $verification_services_codes = get_option( 'verification_services_codes' );
1648        if (
1649            ! is_array( $verification_services_codes )
1650            || empty( $verification_services_codes )
1651        ) {
1652            return new WP_Error(
1653                'empty',
1654                esc_html__( 'Site not verified with any service.', 'jetpack' ),
1655                array( 'status' => 404 )
1656            );
1657        }
1658
1659        $services = array();
1660        foreach ( jetpack_verification_services() as $name => $service ) {
1661            if ( is_array( $service ) && ! empty( $verification_services_codes[ $name ] ) ) {
1662                switch ( $name ) {
1663                    case 'google':
1664                        $services[] = 'Google';
1665                        break;
1666                    case 'bing':
1667                        $services[] = 'Bing';
1668                        break;
1669                    case 'pinterest':
1670                        $services[] = 'Pinterest';
1671                        break;
1672                    case 'yandex':
1673                        $services[] = 'Yandex';
1674                        break;
1675                    case 'facebook':
1676                        $services[] = 'Facebook';
1677                        break;
1678                }
1679            }
1680        }
1681
1682        if ( empty( $services ) ) {
1683            return new WP_Error(
1684                'empty',
1685                esc_html__( 'Site not verified with any service.', 'jetpack' ),
1686                array( 'status' => 404 )
1687            );
1688        }
1689
1690        if ( 2 > count( $services ) ) {
1691            $message = esc_html(
1692                sprintf(
1693                    /* translators: %s is a service name like Google, Bing, Pinterest, etc. */
1694                    __( 'Your site is verified with %s.', 'jetpack' ),
1695                    $services[0]
1696                )
1697            );
1698        } else {
1699            $copy_services = $services;
1700            $last          = count( $copy_services ) - 1;
1701            $last_service  = $copy_services[ $last ];
1702            unset( $copy_services[ $last ] );
1703            $message = esc_html(
1704                sprintf(
1705                    /* translators: %1$s is a comma-separated list of services, and %2$s is a single service name like Google, Bing, Pinterest, etc. */
1706                    __( 'Your site is verified with %1$s and %2$s.', 'jetpack' ),
1707                    implode( ', ', $copy_services ),
1708                    $last_service
1709                )
1710            );
1711        }
1712
1713        return rest_ensure_response(
1714            array(
1715                'code'     => 'success',
1716                'message'  => $message,
1717                'services' => $services,
1718            )
1719        );
1720    }
1721
1722    /**
1723     * Get VaultPress site data including, among other things, the date of the last backup if it was completed.
1724     *
1725     * @since 4.3.0
1726     *
1727     * @return mixed|WP_Error VaultPress site data. Otherwise, a WP_Error instance with the corresponding error.
1728     */
1729    public function get_vaultpress_data() {
1730        if ( ! class_exists( 'VaultPress' ) ) {
1731            return new WP_Error(
1732                'not_active',
1733                esc_html__( 'The requested Jetpack module is not active.', 'jetpack' ),
1734                array( 'status' => 404 )
1735            );
1736        }
1737
1738        $vaultpress = new VaultPress();
1739        if ( ! $vaultpress->is_registered() ) {
1740            return rest_ensure_response(
1741                array(
1742                    'code'    => 'not_registered',
1743                    'message' => esc_html__( 'You need to register for VaultPress.', 'jetpack' ),
1744                )
1745            );
1746        }
1747
1748        $data = json_decode( base64_decode( $vaultpress->contact_service( 'plugin_data' ) ) ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode
1749        if ( false === $data ) {
1750            return rest_ensure_response(
1751                array(
1752                    'code'    => 'not_registered',
1753                    'message' => esc_html__( 'Could not connect to VaultPress.', 'jetpack' ),
1754                )
1755            );
1756        } elseif ( is_wp_error( $data ) || ! isset( $data->backups->last_backup ) ) {
1757            return $data;
1758        } elseif ( empty( $data->backups->last_backup ) ) {
1759            return rest_ensure_response(
1760                array(
1761                    'code'    => 'success',
1762                    'message' => esc_html__( 'VaultPress is active and will back up your site soon.', 'jetpack' ),
1763                    'data'    => $data,
1764                )
1765            );
1766        } else {
1767            return rest_ensure_response(
1768                array(
1769                    'code'    => 'success',
1770                    'message' => esc_html(
1771                        sprintf(
1772                            /* translators: placeholder is a unit of time (1 hour, 5 days, ...) */
1773                            esc_html__( 'Your site was successfully backed up %s ago.', 'jetpack' ),
1774                            human_time_diff(
1775                                $data->backups->last_backup,
1776                                current_time( 'timestamp' ) // phpcs:ignore WordPress.DateTime.CurrentTimeTimestamp.Requested -- We cannot switch to time() or another "unix" timestamp option as long as $data->backups->last_backup uses WP timestamps.
1777                            )
1778                        )
1779                    ),
1780                    'data'    => $data,
1781                )
1782            );
1783        }
1784    }
1785
1786    /**
1787     * A WordPress REST API permission callback method that accepts a request object and
1788     * decides if the current user has enough privileges to act.
1789     *
1790     * @since 4.3.0
1791     *
1792     * @return bool does a current user have enough privileges.
1793     */
1794    public function can_request() {
1795        return current_user_can( 'jetpack_admin_page' );
1796    }
1797}
1798
1799// phpcs:disable Universal.Files.SeparateFunctionsFromOO.Mixed -- TODO: Move these functions to some other file.
1800
1801/**
1802 * Actions performed only when Gravatar Hovercards is activated through the endpoint call.
1803 *
1804 * @since 4.3.1
1805 */
1806function jetpack_do_after_gravatar_hovercards_activation() {
1807
1808    // When Gravatar Hovercards is activated, enable them automatically.
1809    update_option( 'gravatar_disable_hovercards', 'enabled' );
1810}
1811add_action( 'jetpack_activate_module_gravatar-hovercards', 'jetpack_do_after_gravatar_hovercards_activation' );
1812
1813/**
1814 * Actions performed only when Gravatar Hovercards is activated through the endpoint call.
1815 *
1816 * @since 4.3.1
1817 */
1818function jetpack_do_after_gravatar_hovercards_deactivation() {
1819
1820    // When Gravatar Hovercards is deactivated, disable them automatically.
1821    update_option( 'gravatar_disable_hovercards', 'disabled' );
1822}
1823add_action( 'jetpack_deactivate_module_gravatar-hovercards', 'jetpack_do_after_gravatar_hovercards_deactivation' );
1824
1825/**
1826 * Actions performed only when Markdown is activated through the endpoint call.
1827 *
1828 * @since 4.7.0
1829 */
1830function jetpack_do_after_markdown_activation() {
1831
1832    // When Markdown is activated, enable support for post editing automatically.
1833    update_option( 'wpcom_publish_posts_with_markdown', true );
1834}
1835add_action( 'jetpack_activate_module_markdown', 'jetpack_do_after_markdown_activation' );