Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
39.39% covered (danger)
39.39%
13 / 33
20.00% covered (danger)
20.00%
1 / 5
CRAP
0.00% covered (danger)
0.00%
0 / 1
Base_Controller
38.71% covered (danger)
38.71%
12 / 31
20.00% covered (danger)
20.00%
1 / 5
59.13
0.00% covered (danger)
0.00%
0 / 1
 __construct
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
1
 is_authorized_blog_request
50.00% covered (danger)
50.00%
2 / 4
0.00% covered (danger)
0.00%
0 / 1
4.12
 prepare_item_for_response
0.00% covered (danger)
0.00%
0 / 6
0.00% covered (danger)
0.00%
0 / 1
12
 publicize_permissions_check
60.00% covered (warning)
60.00%
9 / 15
0.00% covered (danger)
0.00%
0 / 1
6.60
 manage_connection_permission_check
0.00% covered (danger)
0.00%
0 / 5
0.00% covered (danger)
0.00%
0 / 1
6
1<?php
2/**
3 * Base Controller class.
4 *
5 * @package automattic/jetpack-publicize
6 */
7
8namespace Automattic\Jetpack\Publicize\REST_API;
9
10use Automattic\Jetpack\Publicize\Connections;
11use Automattic\Jetpack\Publicize\Publicize_Utils;
12use WP_Error;
13use WP_REST_Controller;
14use WP_REST_Request;
15use WP_REST_Response;
16
17if ( ! defined( 'ABSPATH' ) ) {
18    exit( 0 );
19}
20
21/**
22 * Base controller for Publicize endpoints.
23 */
24abstract class Base_Controller extends WP_REST_Controller {
25
26    /**
27     * Whether to allow requests as blog.
28     *
29     * @var bool
30     */
31    protected $allow_requests_as_blog = false;
32
33    /**
34     * Constructor.
35     */
36    public function __construct() {
37        $this->wpcom_is_wpcom_only_endpoint = true;
38    }
39
40    /**
41     * Check if the request is authorized for the blog.
42     *
43     * @return bool
44     */
45    protected static function is_authorized_blog_request() {
46        if ( Publicize_Utils::is_wpcom() && is_jetpack_site( get_current_blog_id() ) ) {
47
48            $jp_auth_endpoint = new \WPCOM_REST_API_V2_Endpoint_Jetpack_Auth();
49
50            return $jp_auth_endpoint->is_jetpack_authorized_for_site() === true;
51        }
52
53        return false;
54    }
55
56    /**
57     * Filters out data based on ?_fields= request parameter
58     *
59     * @param array           $item    Item to prepare.
60     * @param WP_REST_Request $request Full details about the request.
61     *
62     * @return WP_REST_Response filtered item
63     */
64    public function prepare_item_for_response( $item, $request ) {
65
66        $fields = $this->get_fields_for_response( $request );
67
68        $response_data = array();
69        foreach ( $item as $field => $value ) {
70            if ( rest_is_field_included( $field, $fields ) ) {
71                $response_data[ $field ] = $value;
72            }
73        }
74
75        return rest_ensure_response( $response_data );
76    }
77
78    /**
79     * Verify that user can access Publicize data
80     *
81     * @return true|WP_Error
82     */
83    protected function publicize_permissions_check() {
84
85        global $publicize;
86
87        if ( ! $publicize ) {
88            return new WP_Error(
89                'publicize_not_available',
90                __( 'Sorry, Jetpack Social is not available on your site right now.', 'jetpack-publicize-pkg' ),
91                array( 'status' => rest_authorization_required_code() )
92            );
93        }
94
95        if ( $this->allow_requests_as_blog && self::is_authorized_blog_request() ) {
96            return true;
97        }
98
99        if ( $publicize->current_user_can_access_publicize_data() ) {
100            return true;
101        }
102
103        return new WP_Error(
104            'invalid_user_permission_publicize',
105            __( 'Sorry, you are not allowed to access Jetpack Social data on this site.', 'jetpack-publicize-pkg' ),
106            array( 'status' => rest_authorization_required_code() )
107        );
108    }
109
110    /**
111     * Check whether the request is allowed to manage (update/delete) a connection.
112     *
113     * @param WP_REST_Request $request Full details about the request.
114     * @return bool True if the request can manage connection, false otherwise.
115     */
116    protected function manage_connection_permission_check( $request ) {
117        // Editors and above can manage any connection.
118        if ( current_user_can( 'edit_others_posts' ) ) {
119            return true;
120        }
121
122        $connection_id = $request->get_param( 'connection_id' );
123
124        $connection = Connections::get_by_id( $connection_id );
125
126        return Connections::user_owns_connection( $connection );
127    }
128}