Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
65.52% covered (warning)
65.52%
19 / 29
33.33% covered (danger)
33.33%
1 / 3
CRAP
0.00% covered (danger)
0.00%
0 / 1
AI_Launchpad_Dev_Enable
67.86% covered (warning)
67.86%
19 / 28
33.33% covered (danger)
33.33%
1 / 3
18.61
0.00% covered (danger)
0.00%
0 / 1
 register
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
 maybe_handle_request
0.00% covered (danger)
0.00%
0 / 8
0.00% covered (danger)
0.00%
0 / 1
12
 handle
100.00% covered (success)
100.00%
19 / 19
100.00% covered (success)
100.00%
1 / 1
9
1<?php
2/**
3 * AI Launchpad no-CLI test-enable handler.
4 *
5 * Lets a tester turn the AI Launchpad on (and reset its state) for a site straight from the browser.
6 *
7 * Recognized query args (on any admin page, for a `manage_options` user):
8 *   ?enable-ai-launchpad=1  Set wpcom_ai_launchpad_enabled to 1 (and clear both no-guidance sources: the option and dismissed).
9 *   ?enable-ai-launchpad=0  Delete wpcom_ai_launchpad_enabled (turn back off).
10 *   ?reset-ai-launchpad=1   Clear the wizard / AI-output / dismissed / skipped / task-status options so the wizard runs fresh.
11 *
12 * Hooked on `admin_menu`, not `admin_init`: when the feature is OFF its page is unregistered and
13 * `user_can_access_admin_page()` dies before `admin_init`; `admin_menu` fires before that check, so the page's own
14 * URL can self-enable instead of dying first.
15 *
16 * Gate: current_user_can( 'manage_options' ) only, no nonce, so the URL stays bookmarkable; it also lets an admin
17 * leave the no-guidance experience.
18 *
19 * @package automattic/jetpack-mu-wpcom
20 */
21
22/**
23 * Handles the AI Launchpad test-enable / reset query params.
24 */
25class AI_Launchpad_Dev_Enable {
26
27    /**
28     * The per-site enablement option, mirrored from AI_Launchpad::is_enabled_for_site().
29     */
30    const OPTION_ENABLED = 'wpcom_ai_launchpad_enabled';
31
32    /**
33     * Options cleared by a reset.
34     *
35     * The first three reference the REST controller's constants so a rename there can't leave a stale option name here.
36     */
37    const RESET_OPTIONS = array(
38        AI_Launchpad_REST::OPTION_WIZARD,
39        AI_Launchpad_REST::OPTION_AI_OUTPUT,
40        AI_Launchpad_REST::OPTION_DISMISSED,
41        AI_Launchpad_REST::OPTION_SKIPPED,
42        AI_Launchpad_REST::OPTION_COMPLETED,
43        'launchpad_checklist_tasks_statuses', // Shared completion option; no dedicated constant.
44    );
45
46    /**
47     * Redirect targets returned by handle(), kept as abstract tokens (not URLs) so handle() can be unit-tested.
48     */
49    const REDIRECT_NONE      = '';
50    const REDIRECT_PAGE      = 'page';
51    const REDIRECT_DASHBOARD = 'dashboard';
52
53    /**
54     * Register the admin-request handler.
55     *
56     * @return void
57     */
58    public static function register() {
59        add_action( 'admin_menu', array( __CLASS__, 'maybe_handle_request' ) );
60    }
61
62    /**
63     * Acts on the test-enable / reset query params, then redirects so a refresh does not re-fire the action.
64     *
65     * Disabling lands on the dashboard (the gated page is gone); everything else lands on the AI Launchpad page.
66     *
67     * @return void
68     */
69    public static function maybe_handle_request() {
70        $target = self::handle();
71
72        if ( self::REDIRECT_NONE === $target ) {
73            return;
74        }
75
76        $url = self::REDIRECT_DASHBOARD === $target
77            ? admin_url()
78            : admin_url( 'admin.php?page=' . \Automattic\Jetpack\Jetpack_Mu_Wpcom\AI_Launchpad::MENU_SLUG );
79
80        wp_safe_redirect( $url );
81        exit;
82    }
83
84    /**
85     * Applies the requested option changes and returns where to send the user, as one of the REDIRECT_* tokens.
86     *
87     * Split from the redirect/exit so it can be unit-tested in isolation.
88     *
89     * @return string One of the REDIRECT_* constants (REDIRECT_NONE when there is
90     *                nothing to do: no recognized param, or no capability).
91     */
92    public static function handle() {
93        // phpcs:disable WordPress.Security.NonceVerification.Recommended -- Intentional no-nonce toggle, see file docblock; cap-gated below.
94        $enable = isset( $_GET['enable-ai-launchpad'] );
95        $reset  = isset( $_GET['reset-ai-launchpad'] );
96
97        if ( ! $enable && ! $reset ) {
98            return self::REDIRECT_NONE;
99        }
100
101        if ( ! current_user_can( 'manage_options' ) ) {
102            return self::REDIRECT_NONE;
103        }
104
105        $disabling = false;
106
107        if ( $enable ) {
108            $value = sanitize_text_field( wp_unslash( $_GET['enable-ai-launchpad'] ) );
109            if ( '0' === $value ) {
110                delete_option( self::OPTION_ENABLED );
111                $disabling = true;
112            } else {
113                update_option( self::OPTION_ENABLED, 1 );
114                // Either no-guidance source would otherwise win over the flag just set.
115                delete_option( 'wpcom_ai_launchpad_no_guidance' );
116                delete_option( AI_Launchpad_REST::OPTION_DISMISSED );
117            }
118        }
119
120        if ( $reset ) {
121            foreach ( self::RESET_OPTIONS as $option ) {
122                delete_option( $option );
123            }
124        }
125        // phpcs:enable WordPress.Security.NonceVerification.Recommended
126
127        // Disabling removes the gated launchpad page, so land on the dashboard rather than the now-inaccessible page.
128        return $disabling ? self::REDIRECT_DASHBOARD : self::REDIRECT_PAGE;
129    }
130}
131
132AI_Launchpad_Dev_Enable::register();