Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
87.34% covered (warning)
87.34%
331 / 379
56.00% covered (warning)
56.00%
14 / 25
CRAP
0.00% covered (danger)
0.00%
0 / 1
REST_Controller
87.53% covered (warning)
87.53%
330 / 377
56.00% covered (warning)
56.00%
14 / 25
146.44
0.00% covered (danger)
0.00%
0 / 1
 __construct
100.00% covered (success)
100.00%
3 / 3
100.00% covered (success)
100.00%
1 / 1
3
 register
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
 register_rest_routes
75.00% covered (warning)
75.00%
3 / 4
0.00% covered (danger)
0.00%
0 / 1
2.06
 register_common_rest_routes
100.00% covered (success)
100.00%
60 / 60
100.00% covered (success)
100.00%
1 / 1
1
 register_jetpack_only_rest_routes
100.00% covered (success)
100.00%
52 / 52
100.00% covered (success)
100.00%
1 / 1
1
 register_wpcom_only_rest_routes
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
 require_admin_privilege_callback
100.00% covered (success)
100.00%
3 / 3
100.00% covered (success)
100.00%
1 / 1
2
 require_valid_blog_token_callback
100.00% covered (success)
100.00%
3 / 3
100.00% covered (success)
100.00%
1 / 1
2
 get_forbidden_error
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
 get_search_plan
100.00% covered (success)
100.00%
2 / 2
100.00% covered (success)
100.00%
1 / 1
1
 update_settings
74.55% covered (warning)
74.55%
41 / 55
0.00% covered (danger)
0.00%
0 / 1
37.15
 validate_search_settings
98.18% covered (success)
98.18%
54 / 55
0.00% covered (danger)
0.00%
0 / 1
41
 get_settings
100.00% covered (success)
100.00%
14 / 14
100.00% covered (success)
100.00%
1 / 1
2
 is_reader_chat_setting_registered
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
1
 get_stats
0.00% covered (danger)
0.00%
0 / 2
0.00% covered (danger)
0.00%
0 / 1
2
 get_search_results
100.00% covered (success)
100.00%
8 / 8
100.00% covered (success)
100.00%
1 / 1
1
 activate_plan
92.50% covered (success)
92.50%
37 / 40
0.00% covered (danger)
0.00%
0 / 1
13.07
 activate_free_plan
42.86% covered (danger)
42.86%
6 / 14
0.00% covered (danger)
0.00%
0 / 1
6.99
 deactivate_plan
0.00% covered (danger)
0.00%
0 / 6
0.00% covered (danger)
0.00%
0 / 1
2
 get_local_stats
100.00% covered (success)
100.00%
4 / 4
100.00% covered (success)
100.00%
1 / 1
1
 reset_singleton_template
100.00% covered (success)
100.00%
21 / 21
100.00% covered (success)
100.00%
1 / 1
4
 resolve_singleton_template_class
100.00% covered (success)
100.00%
7 / 7
100.00% covered (success)
100.00%
1 / 1
1
 product_pricing
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
6
 make_proper_response
45.45% covered (danger)
45.45%
5 / 11
0.00% covered (danger)
0.00%
0 / 1
6.60
 get_blog_id
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
2
1<?php
2/**
3 * The Search Rest Controller class.
4 * Registers the REST routes for Search.
5 *
6 * @package automattic/jetpack-search
7 */
8
9namespace Automattic\Jetpack\Search;
10
11use Automattic\Jetpack\Connection\Client;
12use Automattic\Jetpack\Connection\Rest_Authentication;
13use Automattic\Jetpack\My_Jetpack\Products\Search as Search_Product;
14use Automattic\Jetpack\My_Jetpack\Products\Search_Stats as Search_Product_Stats;
15use Jetpack_Options;
16use WP_Error;
17use WP_REST_Request;
18use WP_REST_Response;
19use WP_REST_Server;
20
21if ( ! defined( 'ABSPATH' ) ) {
22    exit( 0 );
23}
24
25/**
26 * Registers the REST routes for Search.
27 */
28class REST_Controller {
29    /**
30     * Namespace for the REST API.
31     *
32     * This is overriden with value `wpcom-orgin/jetpack/v4` for WPCOM.
33     *
34     * @var string
35     */
36    public static $namespace = 'jetpack/v4';
37    /**
38     * Whether it's run on WPCOM.
39     *
40     * @var bool
41     */
42    protected $is_wpcom;
43
44    /**
45     * Module Control object.
46     *
47     * @var Module_Control
48     */
49    protected $search_module;
50
51    /**
52     * Plan object.
53     *
54     * @var Plan
55     */
56    public $plan;
57
58    /**
59     * Constructor
60     *
61     * @param bool                $is_wpcom - Whether it's run on WPCOM.
62     * @param Module_Control|null $module_control - Module_Control object if any.
63     * @param Plan|null           $plan - Plan object if any.
64     */
65    public function __construct( $is_wpcom = false, $module_control = null, $plan = null ) {
66        $this->is_wpcom      = $is_wpcom;
67        $this->search_module = $module_control === null ? new Module_Control() : $module_control;
68        $this->plan          = $plan === null ? new Plan() : $plan;
69    }
70
71    /**
72     * Registers the REST routes on the `rest_api_init` hook.
73     *
74     * Instantiated here, rather than eagerly, so the controller class only loads
75     * on requests that reach `rest_api_init`. Static so the callback can be
76     * unregistered.
77     *
78     * @access public
79     */
80    public static function register() {
81        ( new self() )->register_rest_routes();
82    }
83
84    /**
85     * Registers the REST routes for Search.
86     *
87     * @access public
88     * @static
89     */
90    public function register_rest_routes() {
91        $this->register_common_rest_routes();
92        if ( ! Helper::is_wpcom() ) {
93            $this->register_jetpack_only_rest_routes();
94        } else {
95            $this->register_wpcom_only_rest_routes();
96        }
97    }
98
99    /**
100     * Routes both existing in Jetpack and WPCOM simple sites.
101     */
102    protected function register_common_rest_routes() {
103        register_rest_route(
104            static::$namespace,
105            '/search/plan',
106            array(
107                'methods'             => WP_REST_Server::READABLE,
108                'callback'            => array( $this, 'get_search_plan' ),
109                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
110            )
111        );
112        register_rest_route(
113            static::$namespace,
114            '/search/settings',
115            array(
116                'methods'             => WP_REST_Server::EDITABLE,
117                'callback'            => array( $this, 'update_settings' ),
118                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
119            )
120        );
121        register_rest_route(
122            static::$namespace,
123            '/search/settings',
124            array(
125                'methods'             => WP_REST_Server::READABLE,
126                'callback'            => array( $this, 'get_settings' ),
127                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
128            )
129        );
130        register_rest_route(
131            static::$namespace,
132            '/search/stats',
133            array(
134                'methods'             => WP_REST_Server::READABLE,
135                'callback'            => array( $this, 'get_stats' ),
136                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
137            )
138        );
139        register_rest_route(
140            static::$namespace,
141            '/search/pricing',
142            array(
143                'methods'             => WP_REST_Server::READABLE,
144                'callback'            => array( $this, 'product_pricing' ),
145                'permission_callback' => 'is_user_logged_in',
146            )
147        );
148        // "Restore default" for the singleton-template CPTs. Lives on
149        // jetpack/v4 (not /wp/v2/<rest_base>) so wpcom-origin can proxy it
150        // on Simple sites — the Jetpack-registered CPT controller isn't on
151        // the wpcom REST surface. The allowed `<post_type>` slugs are
152        // enforced inside the handler (single source of truth) rather than
153        // duplicated into a route-level validate_callback.
154        register_rest_route(
155            static::$namespace,
156            '/search/templates/(?P<post_type>[a-z0-9_-]+)',
157            array(
158                'methods'             => WP_REST_Server::DELETABLE,
159                'callback'            => array( $this, 'reset_singleton_template' ),
160                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
161                'args'                => array(
162                    'post_type' => array(
163                        'required'          => true,
164                        'sanitize_callback' => 'sanitize_key',
165                    ),
166                ),
167            )
168        );
169    }
170
171    /**
172     * Routes only existing in Jetpack.
173     */
174    protected function register_jetpack_only_rest_routes() {
175        register_rest_route(
176            static::$namespace,
177            '/search/plan/activate',
178            array(
179                'methods'             => WP_REST_Server::EDITABLE,
180                'callback'            => array( $this, 'activate_plan' ),
181                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
182            )
183        );
184        register_rest_route(
185            static::$namespace,
186            '/search/plan/activate-free',
187            array(
188                'methods'             => WP_REST_Server::EDITABLE,
189                'callback'            => array( $this, 'activate_free_plan' ),
190                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
191                'args'                => array(
192                    'source' => array(
193                        'type'              => 'string',
194                        'required'          => false,
195                        'sanitize_callback' => 'sanitize_key',
196                    ),
197                ),
198            )
199        );
200        register_rest_route(
201            static::$namespace,
202            '/search/plan/deactivate',
203            array(
204                'methods'             => WP_REST_Server::EDITABLE,
205                'callback'            => array( $this, 'deactivate_plan' ),
206                'permission_callback' => array( $this, 'require_admin_privilege_callback' ),
207            )
208        );
209        register_rest_route(
210            static::$namespace,
211            '/search',
212            array(
213                'methods'             => WP_REST_Server::READABLE,
214                'callback'            => array( $this, 'get_search_results' ),
215                'permission_callback' => 'is_user_logged_in',
216            )
217        );
218        register_rest_route(
219            static::$namespace,
220            '/search/local-stats',
221            array(
222                'methods'             => WP_REST_Server::READABLE,
223                'callback'            => array( $this, 'get_local_stats' ),
224                'permission_callback' => array( $this, 'require_valid_blog_token_callback' ),
225            )
226        );
227    }
228
229    /**
230     * Routes only existing in WPCOM.
231     *
232     * We currently don't have any.
233     */
234    protected function register_wpcom_only_rest_routes() {
235        return true;
236    }
237
238    /**
239     * Only administrators can access the API.
240     *
241     * @return bool|WP_Error True if a blog token was used to sign the request, WP_Error otherwise.
242     */
243    public function require_admin_privilege_callback() {
244        if ( current_user_can( 'manage_options' ) ) {
245            return true;
246        }
247
248        return $this->get_forbidden_error();
249    }
250
251    /**
252     * The corresponding endpoints can only be accessible from WPCOM.
253     *
254     * @access public
255     * @static
256     *
257     * @return bool|WP_Error True if a blog token was used to sign the request, WP_Error otherwise.
258     */
259    public function require_valid_blog_token_callback() {
260        if ( Rest_Authentication::is_signed_with_blog_token() ) {
261            return true;
262        }
263
264        return $this->get_forbidden_error();
265    }
266
267    /**
268     * Return a WP_Error object with a forbidden error.
269     */
270    protected function get_forbidden_error() {
271        $error_msg = esc_html__(
272            'You are not allowed to perform this action.',
273            'jetpack-search-pkg'
274        );
275
276        return new WP_Error( 'rest_forbidden', $error_msg, array( 'status' => rest_authorization_required_code() ) );
277    }
278
279    /**
280     * Proxy the request to WPCOM and return the response.
281     *
282     * GET `jetpack/v4/search/plan`
283     */
284    public function get_search_plan() {
285        $response = ( new Plan() )->get_plan_info_from_wpcom();
286        return $this->make_proper_response( $response );
287    }
288
289    /**
290     * POST `jetpack/v4/search/settings`
291     *
292     * @param WP_REST_Request $request - REST request.
293     */
294    public function update_settings( $request ) {
295        $request_body = $request->get_json_params();
296        if ( ! is_array( $request_body ) ) {
297            $request_body = array();
298        }
299
300        $module_active                 = isset( $request_body['module_active'] ) ? (bool) $request_body['module_active'] : null;
301        $instant_search_enabled        = isset( $request_body['instant_search_enabled'] ) ? (bool) $request_body['instant_search_enabled'] : null;
302        $swap_classic_to_inline_search = isset( $request_body['swap_classic_to_inline_search'] ) ? (bool) $request_body['swap_classic_to_inline_search'] : null;
303        $experience                    = isset( $request_body['experience'] ) && is_string( $request_body['experience'] )
304            ? sanitize_text_field( $request_body['experience'] )
305            : null;
306        $reader_chat                   = array_key_exists( 'reader_chat', $request_body ) ? (bool) $request_body['reader_chat'] : null;
307        // rest_sanitize_boolean(), not (bool): this value now drives the paid-plan
308        // gate below, and a plain (bool) cast reads a JSON `"false"` string as true.
309        $ai_answers_enabled = isset( $request_body['ai_answers_enabled'] ) ? rest_sanitize_boolean( $request_body['ai_answers_enabled'] ) : null;
310
311        $search_suggestions_enabled = isset( $request_body['search_suggestions_enabled'] ) ? (bool) $request_body['search_suggestions_enabled'] : null;
312
313        $override_woocommerce_search_template = isset( $request_body['override_woocommerce_search_template'] ) ? (bool) $request_body['override_woocommerce_search_template'] : null;
314
315        $error = $this->validate_search_settings( $module_active, $instant_search_enabled, $swap_classic_to_inline_search, $experience, $reader_chat, $ai_answers_enabled, $search_suggestions_enabled, $override_woocommerce_search_template );
316
317        if ( is_wp_error( $error ) ) {
318            return $error;
319        }
320
321        // If an experience value was provided, delegate to Module_Control::update_experience(),
322        // which encapsulates the storage shape (off → module deactivate, inline → delete option,
323        // embedded/overlay → write affirmative value) and keeps the legacy booleans in lockstep.
324        if ( $experience !== null ) {
325            $result = $this->search_module->update_experience( $experience );
326            if ( is_wp_error( $result ) ) {
327                return $result;
328            }
329            return rest_ensure_response( $this->get_settings() );
330        }
331
332        // Enabling instant search should enable the module too.
333        if ( true === $instant_search_enabled && true !== $module_active ) {
334            $module_active = true;
335        }
336
337        $errors = array();
338        if ( $module_active !== null ) {
339            $module_active_updated = $this->search_module->update_status( $module_active );
340            if ( is_wp_error( $module_active_updated ) ) {
341                $errors['module_active'] = $module_active_updated;
342            }
343        }
344
345        if ( $instant_search_enabled !== null ) {
346            $instant_search_enabled_updated = $this->search_module->update_instant_search_status( $instant_search_enabled );
347            if ( is_wp_error( $instant_search_enabled_updated ) ) {
348                $errors['instant_search_enabled'] = $instant_search_enabled_updated;
349            }
350        }
351
352        if ( $swap_classic_to_inline_search !== null ) {
353            $this->search_module->update_swap_classic_to_inline_search( $swap_classic_to_inline_search );
354        }
355
356        if ( $reader_chat !== null ) {
357            update_option( 'reader_chat', $reader_chat );
358        }
359
360        if ( $ai_answers_enabled !== null ) {
361            update_option( 'jetpack_search_ai_answers_enabled', $ai_answers_enabled );
362        }
363        if ( $search_suggestions_enabled !== null ) {
364            update_option( 'jetpack_search_suggestions_enabled', $search_suggestions_enabled );
365        }
366        if ( $override_woocommerce_search_template !== null ) {
367            update_option( 'jetpack_search_override_woocommerce_search_template', $override_woocommerce_search_template );
368        }
369
370        if ( ! empty( $errors ) ) {
371            return new WP_Error(
372                'some_updated',
373                sprintf(
374                    /* translators: %s are the setting name that not updated. */
375                    __( 'Some settings ( %s ) not updated.', 'jetpack-search-pkg' ),
376                    implode(
377                        ',',
378                        array_keys( $errors )
379                    )
380                ),
381                array( 'status' => 400 )
382            );
383        }
384
385        return rest_ensure_response( $this->get_settings() );
386    }
387
388    /**
389     * Validate $module_active and $instant_search_enabled. Returns an WP_Error instance if invalid.
390     *
391     * @param boolean     $module_active - Module status.
392     * @param boolean     $instant_search_enabled - Instant Search status.
393     * @param boolean     $swap_classic_to_inline_search - New inline search status.
394     * @param string|null $experience - Experience value.
395     * @param bool|null   $reader_chat - Reader Chat status.
396     * @param bool|null   $ai_answers_enabled - Whether Jetpack Search AI answers is enabled.
397     * @param bool|null   $search_suggestions_enabled - New search suggestions status.
398     * @param bool|null   $override_woocommerce_search_template - New WooCommerce search-template override status.
399     */
400    protected function validate_search_settings( $module_active, $instant_search_enabled, $swap_classic_to_inline_search, $experience = null, $reader_chat = null, $ai_answers_enabled = null, $search_suggestions_enabled = null, $override_woocommerce_search_template = null ) {
401        if ( $reader_chat !== null && ! $this->is_reader_chat_setting_registered() ) {
402            return new WP_Error(
403                'rest_invalid_arguments',
404                esc_html__( 'The arguments passed in are invalid.', 'jetpack-search-pkg' ),
405                array( 'status' => 400 )
406            );
407        }
408
409        // AI Answers cannot be turned on while the site-wide Jetpack AI switch is
410        // off. Turning it off stays allowed, so a saved choice can still be cleared.
411        if ( true === $ai_answers_enabled && ! AI_Answers::is_master_enabled() ) {
412            return new WP_Error(
413                'rest_invalid_arguments',
414                esc_html__( 'AI Answers cannot be enabled while Jetpack AI is turned off for this site.', 'jetpack-search-pkg' ),
415                array( 'status' => 400 )
416            );
417        }
418
419        // AI Answers runs inside Instant Search, so enabling it requires Instant
420        // Search on — either already, or turned on by this same request.
421        if ( true === $ai_answers_enabled && true !== $instant_search_enabled && ! $this->search_module->is_instant_search_enabled() ) {
422            return new WP_Error(
423                'rest_invalid_arguments',
424                esc_html__( 'AI Answers cannot be enabled while Instant Search is off.', 'jetpack-search-pkg' ),
425                array( 'status' => 400 )
426            );
427        }
428
429        // `experience` is the canonical source of truth and writes the legacy booleans in lockstep.
430        // Reject requests that mix it with any other settings field so callers don't silently
431        // lose those fields — the `experience` branch in update_settings() early-returns and
432        // would otherwise drop them.
433        if ( $experience !== null ) {
434            if ( $module_active !== null || $instant_search_enabled !== null || $swap_classic_to_inline_search !== null || $reader_chat !== null || $ai_answers_enabled !== null || $search_suggestions_enabled !== null || $override_woocommerce_search_template !== null ) {
435                return new WP_Error(
436                    'rest_invalid_arguments',
437                    esc_html__( 'The `experience` field cannot be combined with `module_active`, `instant_search_enabled`, `swap_classic_to_inline_search`, `reader_chat`, `ai_answers_enabled`, `search_suggestions_enabled`, or `override_woocommerce_search_template`.', 'jetpack-search-pkg' ),
438                    array( 'status' => 400 )
439                );
440            }
441            return true;
442        }
443
444        if ( true === $reader_chat && ( ! $this->plan->supports_search() || $this->plan->is_free_plan() ) ) {
445            return new WP_Error(
446                'rest_forbidden',
447                esc_html__( 'Site Chat requires a paid Jetpack Search plan.', 'jetpack-search-pkg' ),
448                array( 'status' => 403 )
449            );
450        }
451
452        // AI Answers requires a paid Search plan; reject the write outright.
453        if ( true === $ai_answers_enabled && ! Search_Blocks::supports_paid_search() ) {
454            return new WP_Error(
455                'rest_forbidden',
456                esc_html__( 'AI Answers requires a paid Jetpack Search plan.', 'jetpack-search-pkg' ),
457                array( 'status' => 403 )
458            );
459        }
460
461        if (
462            $module_active === null &&
463            $instant_search_enabled === null &&
464            ( $swap_classic_to_inline_search !== null || $reader_chat !== null )
465        ) {
466            // Allow updating auxiliary settings without updating/validating the module settings.
467            return true;
468        }
469        if ( $module_active === null && $instant_search_enabled === null && $swap_classic_to_inline_search === null && $ai_answers_enabled !== null ) {
470            // allow updating 'ai_answers_enabled' without updating/validating other settings.
471            return true;
472        }
473        if ( $module_active === null && $instant_search_enabled === null && $swap_classic_to_inline_search === null && $search_suggestions_enabled !== null ) {
474            // allow updating 'search_suggestions_enabled' without updating/validating other settings.
475            return true;
476        }
477        if ( $module_active === null && $instant_search_enabled === null && $swap_classic_to_inline_search === null && $override_woocommerce_search_template !== null ) {
478            // allow updating 'override_woocommerce_search_template' without updating/validating other settings.
479            return true;
480        }
481        if ( ( true === $instant_search_enabled && false === $module_active ) || ( $module_active === null && $instant_search_enabled === null ) ) {
482            return new WP_Error(
483                'rest_invalid_arguments',
484                esc_html__( 'The arguments passed in are invalid.', 'jetpack-search-pkg' ),
485                array( 'status' => 400 )
486            );
487        }
488        return true;
489    }
490
491        /**
492         *     GET `jetpack/v4/search/settings`
493         */
494    public function get_settings() {
495        $settings = array(
496            'module_active'                        => $this->search_module->is_active(),
497            'instant_search_enabled'               => $this->search_module->is_instant_search_enabled(),
498            'swap_classic_to_inline_search'        => $this->search_module->is_swap_classic_to_inline_search(),
499            'experience'                           => $this->search_module->get_experience(),
500            'ai_answers_enabled'                   => AI_Answers::is_enabled(),
501            'ai_answers_saved'                     => AI_Answers::is_saved_on(),
502            'ai_master_enabled'                    => AI_Answers::is_master_enabled(),
503            'search_suggestions_enabled'           => (bool) get_option( 'jetpack_search_suggestions_enabled', false ),
504            'override_woocommerce_search_template' => Search_Blocks::woocommerce_search_template_override_enabled(),
505        );
506
507        if ( $this->is_reader_chat_setting_registered() ) {
508            $settings['reader_chat'] = (bool) get_option( 'reader_chat', false );
509        }
510
511        return rest_ensure_response( $settings );
512    }
513
514    /**
515     * Check whether Reader Chat is available through REST settings in this request.
516     *
517     * Reader Chat registers `reader_chat` only for proxied rollout contexts, so the
518     * Search dashboard should expose the toggle only when that setting exists.
519     *
520     * @return bool True when reader_chat is registered.
521     */
522    protected function is_reader_chat_setting_registered() {
523        return array_key_exists( 'reader_chat', get_registered_settings() );
524    }
525
526    /**
527     * Proxy the request to WPCOM and return the response.
528     *
529     * GET `jetpack/v4/search/stats`
530     */
531    public function get_stats() {
532        $response = ( new Stats() )->get_stats_from_wpcom();
533        return $this->make_proper_response( $response );
534    }
535
536    /**
537     * Search Endpoint for private sites.
538     *
539     * GET `jetpack/v4/search`
540     *
541     * @param WP_REST_Request $request - REST request.
542     */
543    public function get_search_results( $request ) {
544        $blog_id  = $this->get_blog_id();
545        $path     = sprintf( '/sites/%d/search', absint( $blog_id ) );
546        $path     = add_query_arg(
547            $request->get_query_params(),
548            sprintf( '/sites/%d/search', absint( $blog_id ) )
549        );
550        $response = Client::wpcom_json_api_request_as_blog( $path, '1.3', array(), null, 'rest' );
551        return rest_ensure_response( $this->make_proper_response( $response ) );
552    }
553
554    /**
555     * Activate plan: activate the search module, instant search and do initial configuration.
556     * Typically called from WPCOM.
557     *
558     * POST `jetpack/v4/search/plan/activate`
559     *
560     * @param WP_REST_Request $request - REST request.
561     */
562    public function activate_plan( $request ) {
563        $default_options = array(
564            'search_plan_info'      => null,
565            'enable_search'         => true,
566            'enable_instant_search' => true,
567            'search_experience'     => null,
568            'auto_config_search'    => true,
569        );
570        $payload         = $request->get_json_params();
571        $payload         = wp_parse_args( $payload, $default_options );
572
573        // Update plan data, plan info is in the request body.
574        // We do this to avoid another call to WPCOM and reduce latency.
575        if ( $payload['search_plan_info'] === null || ! $this->plan->set_plan_options( $payload['search_plan_info'] ) ) {
576            $this->plan->get_plan_info_from_wpcom();
577        }
578
579        // Enable search module by default, unless `enable_search` is explicitly set to boolean `false`.
580        if ( false !== $payload['enable_search'] ) {
581            $ret = $this->search_module->activate();
582            if ( is_wp_error( $ret ) ) {
583                return $ret;
584            }
585        }
586
587        if ( $payload['search_experience'] !== null ) {
588            // Canonical path. Restrict to activate-able experiences — `off`
589            // belongs on `/plan/deactivate`, and a non-string payload would
590            // blow up `update_experience(string $experience)`.
591            $valid_experiences = array(
592                Module_Control::EXPERIENCE_OVERLAY,
593                Module_Control::EXPERIENCE_INLINE,
594                Module_Control::EXPERIENCE_EMBEDDED,
595            );
596            if ( ! is_string( $payload['search_experience'] )
597                || ! in_array( $payload['search_experience'], $valid_experiences, true )
598            ) {
599                return new WP_Error(
600                    'invalid_experience',
601                    __( 'Invalid experience value.', 'jetpack-search-pkg' ),
602                    array( 'status' => 400 )
603                );
604            }
605            $ret = $this->search_module->update_experience( sanitize_text_field( $payload['search_experience'] ) );
606            if ( is_wp_error( $ret ) ) {
607                return $ret;
608            }
609        }
610
611        if ( $payload['search_experience'] === null && false !== $payload['enable_instant_search'] ) {
612            // Legacy path: old WPCOM callers send `enable_instant_search`
613            // instead of `search_experience`. Gated on the canonical value
614            // being absent so it doesn't overwrite a non-overlay experience
615            // the caller just set.
616            // Error handling intentionally skipped — this is the legacy fallback.
617            $ret = $this->search_module->enable_instant_search();
618        }
619
620        // `auto_config_search` wires up Overlay sidebar widgets — only meaningful
621        // when Overlay is the resulting experience. For Inline / Embedded, the
622        // caller would otherwise get widget side effects they didn't ask for.
623        if ( false !== $payload['auto_config_search'] && $this->search_module->is_instant_search_enabled() ) {
624            Instant_Search::instance( $this->get_blog_id() )->auto_config_search();
625        }
626
627        return rest_ensure_response(
628            array(
629                'code' => 'success',
630            )
631        );
632    }
633
634    /**
635     * Grant the free Search product to this site instead of sending the user to a $0 checkout.
636     *
637     * POST `jetpack/v4/search/plan/activate-free`
638     *
639     * @since 8.3.0
640     *
641     * @param WP_REST_Request $request - REST request.
642     * @return WP_REST_Response|WP_Error Errors carry `checkout_fallback`, which the dashboard
643     *                                   branches on to decide whether to fall back to checkout.
644     */
645    public function activate_free_plan( $request ) {
646        /*
647         * Another plugin can load an older My Jetpack before this package's copy registers, and
648         * that copy has no such method. Degrade to the checkout the dashboard still has.
649         */
650        if ( ! method_exists( Search_Product::class, 'activate_free_product' ) ) {
651            return new WP_Error(
652                'jetpack_search_free_activation_unavailable',
653                __( 'Jetpack Search Free could not be activated for this site.', 'jetpack-search-pkg' ),
654                array(
655                    'status'            => 501,
656                    'checkout_fallback' => true,
657                )
658            );
659        }
660
661        $source = $request->get_param( 'source' );
662        $result = Search_Product::activate_free_product( $source ? $source : 'search-dashboard' );
663        if ( is_wp_error( $result ) ) {
664            return $result;
665        }
666
667        return rest_ensure_response( $result );
668    }
669
670    /**
671     * Deactivate plan: turn off search module and instant search.
672     * If the plan is still valid then the function would simply deactivate the search module.
673     * Typically called from WPCOM.
674     *
675     * POST `jetpack/v4/search/plan/deactivate`
676     */
677    public function deactivate_plan() {
678        // Instant Search would be disabled along with search module.
679        $this->search_module->deactivate();
680        return rest_ensure_response(
681            array(
682                'code' => 'success',
683            )
684        );
685    }
686
687    /**
688     * Return post type breakdown for the site.
689     */
690    public function get_local_stats() {
691        return array(
692            'post_count'          => Search_Product_Stats::estimate_count(),
693            'post_type_breakdown' => Search_Product_Stats::get_post_type_breakdown(),
694        );
695    }
696
697    /**
698     * Force-delete the {@see Singleton_Template_Cpt} customization for the
699     * requested post type, backing the dashboard's "Restore default" link.
700     * `before_delete_post` in the base class clears the option pointer +
701     * per-request cache so the next render falls back to the bundled template.
702     *
703     * DELETE `jetpack/v4/search/templates/<post_type>`
704     *
705     * @param WP_REST_Request $request - REST request.
706     * @return WP_REST_Response|WP_Error
707     */
708    public function reset_singleton_template( $request ) {
709        $cpt_class = $this->resolve_singleton_template_class( $request['post_type'] );
710        if ( ! $cpt_class ) {
711            return new WP_Error(
712                'jetpack_search_template_unknown',
713                __( 'Unknown search template.', 'jetpack-search-pkg' ),
714                array( 'status' => 404 )
715            );
716        }
717        if ( ! $cpt_class::is_customized() ) {
718            return new WP_Error(
719                'jetpack_search_template_not_customized',
720                __( 'No customization to restore.', 'jetpack-search-pkg' ),
721                array( 'status' => 404 )
722            );
723        }
724        $post_id = $cpt_class::get_post_id();
725        if ( ! wp_delete_post( $post_id, true ) ) {
726            return new WP_Error(
727                'jetpack_search_template_reset_failed',
728                __( 'Failed to restore the default template.', 'jetpack-search-pkg' ),
729                array( 'status' => 500 )
730            );
731        }
732        return rest_ensure_response( array( 'deleted' => true ) );
733    }
734
735    /**
736     * Map a CPT slug to its concrete `Singleton_Template_Cpt` subclass.
737     * Returns null when the slug isn't one of the registered singleton-template
738     * CPTs — the route only sanitizes the slug (via `sanitize_key`), so this
739     * lookup is the primary "is this a known CPT?" filter, not a backup check.
740     *
741     * @param string $post_type Post type slug from the request.
742     * @return class-string<Singleton_Template_Cpt>|null
743     */
744    protected function resolve_singleton_template_class( $post_type ) {
745        $map = array(
746            Overlay_Template::POST_TYPE         => Overlay_Template::class,
747            Product_Overlay_Template::POST_TYPE => Product_Overlay_Template::class,
748            Search_Template::POST_TYPE          => Search_Template::class,
749            Product_Search_Template::POST_TYPE  => Product_Search_Template::class,
750        );
751        return $map[ $post_type ] ?? null;
752    }
753
754    /**
755     * Pricing for record count of the site
756     */
757    public function product_pricing() {
758        $tier_pricing = Search_Product::get_pricing_for_ui();
759        // we can force the plugin to use the new pricing by appending `new_pricing_202208=1` to URL.
760        if ( Helper::is_forced_new_pricing_202208() ) {
761            $tier_pricing['pricing_version'] = Plan::JETPACK_SEARCH_NEW_PRICING_VERSION;
762        }
763        return rest_ensure_response( $tier_pricing );
764    }
765
766    /**
767     * Forward remote response to client with error handling.
768     *
769     * @param array|WP_Error $response - Response from WPCOM.
770     */
771    protected function make_proper_response( $response ) {
772        if ( is_wp_error( $response ) ) {
773            return $response;
774        }
775
776        $body        = json_decode( wp_remote_retrieve_body( $response ), true );
777        $status_code = wp_remote_retrieve_response_code( $response );
778
779        if ( 200 === $status_code ) {
780            return $body;
781        }
782
783        return new WP_Error(
784            isset( $body['error'] ) ? 'remote-error-' . $body['error'] : 'remote-error',
785            $body['message'] ?? 'unknown remote error',
786            array( 'status' => $status_code )
787        );
788    }
789
790    /**
791     * Get blog id
792     */
793    protected function get_blog_id() {
794        return $this->is_wpcom ? get_current_blog_id() : Jetpack_Options::get_option( 'id' );
795    }
796}