Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
36.59% covered (danger)
36.59%
30 / 82
10.00% covered (danger)
10.00%
1 / 10
CRAP
0.00% covered (danger)
0.00%
0 / 1
Notices
36.59% covered (danger)
36.59%
30 / 82
10.00% covered (danger)
10.00%
1 / 10
63.98
0.00% covered (danger)
0.00%
0 / 1
 error_msg_enable_two_step
100.00% covered (success)
100.00%
30 / 30
100.00% covered (success)
100.00%
1 / 1
4
 error_msg_email_already_exists
0.00% covered (danger)
0.00%
0 / 12
0.00% covered (danger)
0.00%
0 / 1
2
 error_msg_identity_crisis
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
2
 error_invalid_response_data
0.00% covered (danger)
0.00%
0 / 6
0.00% covered (danger)
0.00%
0 / 1
2
 error_unable_to_create_user
0.00% covered (danger)
0.00%
0 / 6
0.00% covered (danger)
0.00%
0 / 1
2
 disable_default_login_form
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
6
 msg_login_by_jetpack
0.00% covered (danger)
0.00%
0 / 2
0.00% covered (danger)
0.00%
0 / 1
2
 get_sso_required_message
0.00% covered (danger)
0.00%
0 / 5
0.00% covered (danger)
0.00%
0 / 1
2
 cant_find_user
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
2
 sso_not_allowed_in_safe_mode
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
2
1<?php
2/**
3 * A collection of helper functions used in the SSO module.
4 *
5 * @package automattic/jetpack-connection
6 */
7
8namespace Automattic\Jetpack\Connection\SSO;
9
10use Automattic\Jetpack\Redirect;
11use WP_Error;
12use WP_User;
13
14/**
15 * A collection of helper functions used in the SSO module.
16 *
17 * @since jetpack-4.4.0
18 */
19class Notices {
20    /**
21     * Error message displayed on the login form when two step is required and
22     * the user's account on WordPress.com does not have two step enabled.
23     *
24     * @since jetpack-2.7
25     * @since $$next-version$$ Added the `$user_data` parameter.
26     * @param string      $message   Error message.
27     * @param object|null $user_data WordPress.com user information returned by the SSO attempt.
28     * @return string
29     **/
30    public static function error_msg_enable_two_step( $message, $user_data = null ) {
31        $account_name = '';
32        if ( is_object( $user_data ) ) {
33            $account_name = ! empty( $user_data->display_name ) ? $user_data->display_name : ( $user_data->login ?? '' );
34        }
35
36        $allowed_html = array(
37            'a'      => array(
38                'href'   => array(),
39                'rel'    => array(),
40                'target' => array(),
41            ),
42            'strong' => array(),
43        );
44        $setup_url    = esc_url( Redirect::get_url( 'calypso-me-security-two-step' ) );
45
46        if ( $account_name ) {
47            $error = sprintf(
48                wp_kses(
49                    /* translators: %1$s is a WordPress.com account name, %2$s is the URL of the two-step authentication settings. */
50                    __( 'You are logged in to WordPress.com as <strong>%1$s</strong>, but this site requires two-step authentication for added security. <a href="%2$s" rel="noopener noreferrer" target="_blank">Set it up for your account</a>, then log in again.', 'jetpack-connection' ),
51                    $allowed_html
52                ),
53                esc_html( $account_name ),
54                $setup_url
55            );
56        } else {
57            $error = sprintf(
58                wp_kses(
59                    /* translators: %s is the URL of the two-step authentication settings. */
60                    __( 'This site requires two-step authentication for added security. <a href="%s" rel="noopener noreferrer" target="_blank">Set it up for your WordPress.com account</a>, then log in again.', 'jetpack-connection' ),
61                    $allowed_html
62                ),
63                $setup_url
64            );
65        }
66
67        $message .= sprintf( '<p class="message" id="login_error">%s</p>', $error );
68
69        return $message;
70    }
71
72    /**
73     * Error message displayed when the user tries to SSO, but match by email
74     * is off and they already have an account with their email address on
75     * this site.
76     *
77     * @param string $message Error message.
78     * @return string
79     */
80    public static function error_msg_email_already_exists( $message ) {
81        $error = sprintf(
82            wp_kses(
83            /* translators: login URL */
84                __(
85                    'You already have an account on this site. Please <a href="%1$s">sign in</a> with your username and password and then connect to WordPress.com.',
86                    'jetpack-connection'
87                ),
88                array( 'a' => array( 'href' => array() ) )
89            ),
90            esc_url_raw( add_query_arg( 'jetpack-sso-show-default-form', '1', wp_login_url() ) )
91        );
92
93        $message .= sprintf( '<p class="message" id="login_error">%s</p>', $error );
94
95        return $message;
96    }
97
98    /**
99     * Error message that is displayed when the current site is in an identity crisis and SSO cannot be used.
100     *
101     * @since jetpack-4.3.2
102     *
103     * @param string $message Error Message.
104     *
105     * @return string
106     */
107    public static function error_msg_identity_crisis( $message ) {
108        $error    = esc_html__( 'Logging in with WordPress.com is not currently available because this site is experiencing connection problems.', 'jetpack-connection' );
109        $message .= sprintf( '<p class="message" id="login_error">%s</p>', $error );
110        return $message;
111    }
112
113    /**
114     * Error message that is displayed when we are not able to verify the SSO nonce due to an XML error or
115     * failed validation. In either case, we prompt the user to try again or log in with username and password.
116     *
117     * @since jetpack-4.3.2
118     *
119     * @param string $message Error message.
120     *
121     * @return string
122     */
123    public static function error_invalid_response_data( $message ) {
124        $error    = esc_html__(
125            'There was an error logging you in via WordPress.com, please try again or try logging in with your username and password.',
126            'jetpack-connection'
127        );
128        $message .= sprintf( '<p class="message" id="login_error">%s</p>', $error );
129        return $message;
130    }
131
132    /**
133     * Error message that is displayed when we were not able to automatically create an account for a user
134     * after a user has logged in via SSO. By default, this message is triggered after trying to create an account 5 times.
135     *
136     * @since jetpack-4.3.2
137     *
138     * @param string $message Error message.
139     *
140     * @return string
141     */
142    public static function error_unable_to_create_user( $message ) {
143        $error    = esc_html__(
144            'There was an error creating a user for you. Please contact the administrator of your site.',
145            'jetpack-connection'
146        );
147        $message .= sprintf( '<p class="message" id="login_error">%s</p>', $error );
148        return $message;
149    }
150
151    /**
152     * When the default login form is hidden, this method is called on the 'authenticate' filter with a priority of 30.
153     * This method disables the ability to submit the default login form.
154     *
155     * @param WP_User|WP_Error $user Either the user attempting to login or an existing authentication failure.
156     *
157     * @return WP_Error
158     */
159    public static function disable_default_login_form( $user ) {
160        if ( is_wp_error( $user ) ) {
161            return $user;
162        }
163
164        /**
165         * Since we're returning an error that will be shown as a red notice, let's remove the
166         * informational "blue" notice.
167         */
168        remove_filter( 'login_message', array( static::class, 'msg_login_by_jetpack' ) );
169        return new WP_Error( 'jetpack_sso_required', self::get_sso_required_message() );
170    }
171
172    /**
173     * Message displayed when the site admin has disabled the default WordPress
174     * login form in Settings > General > Secure Sign On
175     *
176     * @since jetpack-2.7
177     * @param string $message Error message.
178     *
179     * @return string
180     **/
181    public static function msg_login_by_jetpack( $message ) {
182        $message .= sprintf( '<p class="message">%s</p>', self::get_sso_required_message() );
183        return $message;
184    }
185
186    /**
187     * Get the message for SSO required.
188     *
189     * @return string
190     */
191    public static function get_sso_required_message() {
192        $msg = esc_html__(
193            'A WordPress.com account is required to access this site. Click the button below to sign in or create a free WordPress.com account.',
194            'jetpack-connection'
195        );
196
197        /**
198         * Filter the message displayed when the default WordPress login form is disabled.
199         *
200         * @module sso
201         *
202         * @since jetpack-2.8.0
203         *
204         * @param string $msg Disclaimer when default WordPress login form is disabled.
205         */
206        return apply_filters( 'jetpack_sso_disclaimer_message', $msg );
207    }
208
209    /**
210     * Message displayed when the user cannot be found after approving the SSO process on WordPress.com
211     *
212     * @param string $message Error message.
213     *
214     * @return string
215     */
216    public static function cant_find_user( $message ) {
217        $error = __(
218            "We couldn't find your account. If you already have an account, make sure you have connected to WordPress.com.",
219            'jetpack-connection'
220        );
221
222        /**
223         * Filters the "couldn't find your account" notice after an attempted SSO.
224         *
225         * @module sso
226         *
227         * @since jetpack-10.5.0
228         *
229         * @param string $error Error text.
230         */
231        $error = apply_filters( 'jetpack_sso_unknown_user_notice', $error );
232
233        $message .= sprintf( '<p class="message" id="login_error">%s</p>', esc_html( $error ) );
234
235        return $message;
236    }
237
238    /**
239     * Error message that is displayed when the current site is in an identity crisis and SSO cannot be used.
240     *
241     * @since 2.10.0
242     *
243     * @param string $message Error message.
244     *
245     * @return string
246     */
247    public static function sso_not_allowed_in_safe_mode( $message ) {
248        $error = __(
249            'Logging in with WordPress.com is disabled for sites that are in safe mode.',
250            'jetpack-connection'
251        );
252
253        /**
254         * Filters the disallowed notice for sites in safe mode attempting SSO.
255         *
256         * @module sso
257         *
258         * @since 2.10.0
259         *
260         * @param string $error Error text.
261         */
262        $error    = apply_filters( 'jetpack_sso_disallowed_safe_mode_notice', $error );
263        $message .= sprintf( '<p class="message">%s</p>', esc_html( $error ) );
264        return $message;
265    }
266}