Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
60.00% covered (warning)
60.00%
21 / 35
33.33% covered (danger)
33.33%
2 / 6
CRAP
n/a
0 / 0
Automattic\Jetpack\Extensions\Premium_Content\register_login_button_block
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 1
2
Automattic\Jetpack\Extensions\Premium_Content\get_current_url
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
20
Automattic\Jetpack\Extensions\Premium_Content\get_subscriber_login_url
91.67% covered (success)
91.67%
11 / 12
0.00% covered (danger)
0.00%
0 / 1
3.01
Automattic\Jetpack\Extensions\Premium_Content\is_subscriber_logged_in
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
3
Automattic\Jetpack\Extensions\Premium_Content\render_login_button_block
88.89% covered (warning)
88.89%
8 / 9
0.00% covered (danger)
0.00%
0 / 1
3.01
Automattic\Jetpack\Extensions\Premium_Content\render_login_button_block_email
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
1
1<?php
2/**
3 * Premium Content Login Button Child Block.
4 *
5 * @package automattic/jetpack
6 */
7
8namespace Automattic\Jetpack\Extensions\Premium_Content;
9
10use Automattic\Jetpack\Blocks;
11use Automattic\Jetpack\Extensions\Premium_Content\Subscription_Service\Abstract_Token_Subscription_Service;
12use Automattic\Jetpack\Status\Host;
13use Jetpack_Gutenberg;
14use Jetpack_Options;
15
16require_once dirname( __DIR__ ) . '/_inc/subscription-service/include.php';
17
18const LOGIN_BUTTON_NAME = 'premium-content/login-button';
19
20/**
21 * Registers the block for use in Gutenberg
22 * This is done via an action so that we can disable
23 * registration if we need to.
24 */
25function register_login_button_block() {
26    Blocks::jetpack_register_block(
27        LOGIN_BUTTON_NAME,
28        array(
29            'render_callback'       => __NAMESPACE__ . '\render_login_button_block',
30            'render_email_callback' => __NAMESPACE__ . '\render_login_button_block_email',
31        )
32    );
33}
34add_action( 'init', __NAMESPACE__ . '\register_login_button_block' );
35
36/**
37 * Returns current URL.
38 *
39 * @return string
40 */
41function get_current_url() {
42    if ( ! isset( $_SERVER['HTTP_HOST'] ) || ! isset( $_SERVER['REQUEST_URI'] ) ) {
43        return '';
44    }
45
46    return ( is_ssl() ? 'https://' : 'http://' ) . wp_unslash( $_SERVER['HTTP_HOST'] ) . wp_unslash( $_SERVER['REQUEST_URI'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
47}
48
49/**
50 * Returns subscriber log in URL.
51 *
52 * @param string $redirect Path to redirect to on login.
53 *
54 * @return string
55 */
56function get_subscriber_login_url( $redirect ) {
57    $redirect = ! empty( $redirect ) ? $redirect : get_site_url();
58
59    if ( ( new Host() )->is_wpcom_simple() ) {
60        // On WPCOM we will redirect immediately
61        return wpcom_logmein_redirect_url( $redirect, false, null, 'link', get_current_blog_id() );
62    }
63
64    // On self-hosted we will save and hide the token.
65    // rawurlencode the redirect before nesting it: it is already percent-encoded
66    // (e.g. an emoji or non-ASCII slug comes through as %F0%9F%8C%91), and add_query_arg
67    // does not encode the values it inserts. Without this extra layer the value is
68    // over-decoded to raw bytes by the time it reaches the subscribers/auth endpoint,
69    // which strips it and 404s. See NL-273.
70    $redirect_url = get_site_url() . '/wp-json/jetpack/v4/subscribers/auth';
71    $redirect_url = add_query_arg( 'redirect_url', rawurlencode( $redirect ), $redirect_url );
72
73    return add_query_arg(
74        array(
75            'site_id'      => intval( Jetpack_Options::get_option( 'id' ) ),
76            'redirect_url' => rawurlencode( $redirect_url ),
77        ),
78        'https://subscribe.wordpress.com/memberships/jwt/'
79    );
80}
81
82/**
83 * Determines whether the visitor has a subscriber session for the login UI.
84 *
85 * WordPress sessions count on Simple; other hosts require the subscriber cookie.
86 * Content access validates the token separately.
87 *
88 * @return bool
89 */
90function is_subscriber_logged_in() {
91    return ( ( new Host() )->is_wpcom_simple() && is_user_logged_in() ) || Abstract_Token_Subscription_Service::has_token_from_cookie();
92}
93
94/**
95 * Render callback.
96 *
97 * @param array  $attributes Array containing the block attributes.
98 * @param string $content    String containing the block content.
99 *
100 * @return string
101 */
102function render_login_button_block( $attributes, $content ) {
103    if ( ! pre_render_checks() ) {
104        return '';
105    }
106
107    // The viewer is logged it, so they shouldn't see the login button.
108    if ( is_subscriber_logged_in() ) {
109        return '';
110    }
111
112    Jetpack_Gutenberg::load_styles_as_required( LOGIN_BUTTON_NAME );
113
114    $redirect_url = get_current_url();
115    $url          = get_subscriber_login_url( $redirect_url );
116
117    $content = preg_replace( '/(<a\b[^><]*)>/i', '$1 href="' . esc_url( $url ) . '">', $content );
118
119    // Defense in depth: the label is inner block content (KSES-filtered on save for
120    // roles without `unfiltered_html`), but escape it again on output so a stored
121    // payload can never render as live markup.
122    return wp_kses_post( $content );
123}
124
125/**
126 * Render email callback.
127 *
128 * @return string
129 */
130function render_login_button_block_email() {
131    // We don't want to render the login button in emails.
132    // The subscriber is already considered logged in in emails.
133    return '';
134}