Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
45.55% covered (danger)
45.55%
87 / 191
0.00% covered (danger)
0.00%
0 / 7
CRAP
0.00% covered (danger)
0.00%
0 / 1
VideoPress_Player
46.03% covered (danger)
46.03%
87 / 189
0.00% covered (danger)
0.00%
0 / 7
1392.66
0.00% covered (danger)
0.00%
0 / 1
 __construct
43.18% covered (danger)
43.18%
19 / 44
0.00% covered (danger)
0.00%
0 / 1
77.43
 html_wrapper
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
6
 as_xml
0.00% covered (danger)
0.00%
0 / 3
0.00% covered (danger)
0.00%
0 / 1
12
 as_html
0.00% covered (danger)
0.00%
0 / 10
0.00% covered (danger)
0.00%
0 / 1
56
 error_message
0.00% covered (danger)
0.00%
0 / 8
0.00% covered (danger)
0.00%
0 / 1
20
 html5_static
0.00% covered (danger)
0.00%
0 / 34
0.00% covered (danger)
0.00%
0 / 1
306
 html5_dynamic_next
78.16% covered (warning)
78.16%
68 / 87
0.00% covered (danger)
0.00%
0 / 1
42.67
 esc_flash_params
n/a
0 / 0
n/a
0 / 0
8
1<?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2use Automattic\Jetpack\VideoPress\Inline_Player;
3use Automattic\Jetpack\VideoPress\Jwt_Token_Bridge;
4
5if ( ! defined( 'ABSPATH' ) ) {
6    exit( 0 );
7}
8
9/**
10 * VideoPress playback module markup generator.
11 *
12 * @since 1.3
13 */
14class VideoPress_Player {
15    /**
16     * Video data for the requested guid and maximum width
17     *
18     * @since 1.3
19     * @var VideoPress_Video
20     */
21    protected $video;
22
23    /**
24     * DOM identifier of the video container
25     *
26     * @var string
27     * @since 1.3
28     */
29    protected $video_container_id;
30
31    /**
32     * DOM identifier of the video element
33     *
34     * @var string
35     * @since 1.3
36     */
37    protected $video_id;
38
39    /**
40     * Array of playback options.
41     *
42     * @var array
43     * @since 1.3
44     */
45    protected $options;
46
47    /**
48     * Array of video GUIDs shown and their counts,
49     * moved from the old VideoPress class.
50     *
51     * @var array
52     */
53    public static $shown = array();
54
55    /**
56     * Fallback video title.
57     *
58     * @var ?string
59     */
60    protected $title;
61
62    /**
63     * Initiate a player object based on shortcode values and possible blog-level option overrides
64     *
65     * @since 1.3
66     * @param string $guid VideoPress unique identifier.
67     * @param int    $maxwidth Maximum desired width of the video player if specified.
68     * @param array  $options Player customizations.
69     */
70    public function __construct( $guid, $maxwidth = 0, $options = array() ) {
71        if ( empty( self::$shown[ $guid ] ) ) {
72            self::$shown[ $guid ] = 0;
73        }
74
75        ++self::$shown[ $guid ];
76
77        $this->video_container_id = 'v-' . $guid . '-' . self::$shown[ $guid ];
78        $this->video_id           = $this->video_container_id . '-video';
79
80        if ( is_array( $options ) ) {
81            $this->options = $options;
82        } else {
83            $this->options = array();
84        }
85
86        // set up the video
87        $cache_key = null;
88
89        // disable cache in debug mode
90        if ( defined( 'WP_DEBUG' ) && WP_DEBUG === true ) {
91            $cached_video = null;
92        } else {
93            $cache_key_pieces = array( 'video' );
94
95            if ( is_multisite() && is_subdomain_install() ) {
96                $cache_key_pieces[] = get_current_blog_id();
97            }
98
99            $cache_key_pieces[] = $guid;
100            if ( $maxwidth > 0 ) {
101                $cache_key_pieces[] = $maxwidth;
102            }
103            if ( is_ssl() ) {
104                $cache_key_pieces[] = 'ssl';
105            }
106            $cache_key = implode( '-', $cache_key_pieces );
107            unset( $cache_key_pieces );
108            $cached_video = wp_cache_get( $cache_key, 'video' );
109        }
110        if ( empty( $cached_video ) ) {
111            $video = new VideoPress_Video( $guid, $maxwidth );
112            if ( isset( $video->error ) ) {
113                $this->video = $video->error;
114                return;
115            } elseif ( is_wp_error( $video ) ) {
116                $this->video = $video;
117                return;
118            }
119
120            $this->video = $video;
121            unset( $video );
122
123            if ( ! defined( 'WP_DEBUG' ) || WP_DEBUG !== true ) {
124                $expire = 3600;
125                if ( isset( $this->video->expires ) && is_int( $this->video->expires ) ) {
126                    $expires_diff = time() - $this->video->expires;
127                    if ( $expires_diff > 0 && $expires_diff < 86400 ) { // allowed range: 1 second to 1 day
128                        $expire = $expires_diff;
129                    }
130                    unset( $expires_diff );
131                }
132
133                wp_cache_set( $cache_key, serialize( $this->video ), 'video', $expire ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.serialize_serialize
134                unset( $expire );
135            }
136        } else {
137            $this->video = unserialize( $cached_video ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize -- Make sure to unserialize as VideoPress_Video class.
138        }
139        unset( $cache_key );
140        unset( $cached_video );
141    }
142
143    /**
144     * Wrap output in a VideoPress player container.
145     *
146     * @since 1.3
147     * @param string $content HTML string.
148     * @return string HTML string or blank string if nothing to wrap.
149     */
150    private function html_wrapper( $content ) {
151        if ( empty( $content ) ) {
152            return '';
153        } else {
154            return '<div id="' . esc_attr( $this->video_container_id ) . '" class="video-player">' . $content . '</div>';
155        }
156    }
157
158    /**
159     * Output content suitable for a feed reader displaying RSS or Atom feeds.
160     * We do not display error messages in the feed view due to caching concerns.
161     *
162     * @since 1.3
163     * @return string HTML string or empty string if error
164     */
165    public function as_xml() {
166        if ( empty( $this->video ) || is_wp_error( $this->video ) ) {
167            return '';
168        }
169
170        return $this->html_wrapper( $this->html5_static() );
171    }
172
173    /**
174     * Video player markup for best matching the current request and publisher options
175     *
176     * @since 1.3
177     * @return string HTML markup string or empty string if no video property found
178     */
179    public function as_html() {
180        if ( empty( $this->video ) ) {
181            $content = '';
182
183        } elseif ( is_wp_error( $this->video ) ) {
184            $content = $this->error_message( $this->video );
185
186        } elseif ( isset( $this->video->restricted_embed ) && true === $this->video->restricted_embed ) {
187            // Restricted videos always get the dynamic player, even with `freedom` set.
188            $content = $this->html5_dynamic_next();
189
190        } elseif ( isset( $this->options['freedom'] ) && true === $this->options['freedom'] ) {
191            $content = $this->html5_static();
192
193        } else {
194            $content = $this->html5_dynamic_next();
195        }
196
197        return $this->html_wrapper( $content );
198    }
199
200    /**
201     * Display an error message to users capable of doing something about the error
202     *
203     * @since 1.3
204     * @uses current_user_can() to test if current user has edit_posts capability.
205     * @param WP_Error $error WordPress error.
206     * @return string HTML string
207     */
208    private function error_message( $error ) {
209        if ( ! current_user_can( 'edit_posts' ) || empty( $error ) ) {
210            return '';
211        }
212
213        $html = '<div class="videopress-error" style="background-color:rgb(255,0,0);color:rgb(255,255,255);font-family:font-family:\'Helvetica Neue\',Arial,Helvetica,\'Nimbus Sans L\',sans-serif;font-size:140%;min-height:10em;padding-top:1.5em;padding-bottom:1.5em">';
214        /* translators: %s is 'VideoPress' */
215        $html .= '<h1 style="font-size:180%;font-style:bold;line-height:130%;text-decoration:underline">' . esc_html( sprintf( __( '%s Error', 'jetpack' ), 'VideoPress' ) ) . '</h1>';
216        foreach ( $error->get_error_messages() as $message ) {
217            $html .= $message;
218        }
219        $html .= '</div>';
220        return $html;
221    }
222
223    /**
224     * Return HTML5 video static markup for the given video parameters.
225     * Use default browser player controls.
226     *
227     * @since 1.2
228     * @link https://html.spec.whatwg.org/multipage/media.html#the-video-element HTML5 video
229     * @return string HTML5 video element and children
230     */
231    private function html5_static() {
232        $thumbnail = esc_url( $this->video->poster_frame_uri );
233        $html      = "<video id=\"{$this->video_id}\" width=\"{$this->video->calculated_width}\" height=\"{$this->video->calculated_height}\" poster=\"$thumbnail\" controls=\"true\"";
234
235        $preload = 'metadata';
236        if ( isset( $this->options['preloadContent'] ) && videopress_is_valid_preload( $this->options['preloadContent'] ) ) {
237            $preload = $this->options['preloadContent'];
238        }
239
240        if ( isset( $this->options['autoplay'] ) && $this->options['autoplay'] === true ) {
241            $html .= ' autoplay="true"';
242        } else {
243            $html .= ' preload="' . esc_attr( $preload ) . '"';
244        }
245        if ( isset( $this->video->text_direction ) ) {
246            $html .= ' dir="' . esc_attr( $this->video->text_direction ) . '"';
247        }
248        if ( isset( $this->video->language ) ) {
249            $html .= ' lang="' . esc_attr( $this->video->language ) . '"';
250        }
251        $html .= '>';
252        if (
253            ( ! isset( $this->options['freedom'] ) || $this->options['freedom'] === false )
254            && isset( $this->video->videos->mp4 )
255        ) {
256            $mp4 = $this->video->videos->mp4->url;
257            if ( ! empty( $mp4 ) ) {
258                $html .= '<source src="' . esc_url( $mp4 ) . '" type="video/mp4; codecs=&quot;' . esc_attr( $this->video->videos->mp4->codecs ) . '&quot;" />';
259            }
260            unset( $mp4 );
261        }
262
263        if ( isset( $this->video->videos->ogv ) ) {
264            $ogg = $this->video->videos->ogv->url;
265            if ( ! empty( $ogg ) ) {
266                $html .= '<source src="' . esc_url( $ogg ) . '" type="video/ogg; codecs=&quot;' . esc_attr( $this->video->videos->ogv->codecs ) . '&quot;" />';
267            }
268
269            unset( $ogg );
270        }
271
272        $html .= '<div><img alt="';
273        if ( isset( $this->video->title ) ) {
274            $html .= esc_attr( $this->video->title );
275        }
276        $html .= '" src="' . $thumbnail . '" width="' . $this->video->calculated_width . '" height="' . $this->video->calculated_height . '" /></div>';
277        if ( isset( $this->options['freedom'] ) && $this->options['freedom'] === true ) {
278            /* translators: %s url to the gnu.org website */
279            $html .= '<p class="robots-nocontent">' . sprintf( __( 'You do not have sufficient <a rel="nofollow noopener noreferrer" href="%s" target="_blank">freedom levels</a> to view this video. Support free software and upgrade.', 'jetpack' ), 'https://www.gnu.org/philosophy/free-sw.html' ) . '</p>';
280        } elseif ( isset( $this->video->title ) ) {
281            $html .= '<p>' . esc_html( $this->video->title ) . '</p>';
282        }
283        $html .= '</video>';
284        return $html;
285    }
286
287    /**
288     * Output for the HTML5 player.
289     */
290    public function html5_dynamic_next() {
291        $video_container_id = 'v-' . $this->video->guid;
292
293        Jwt_Token_Bridge::enqueue_jwt_token_bridge();
294
295        // Must not use iframes for IE11 due to a fullscreen bug
296        if ( isset( $_SERVER['HTTP_USER_AGENT'] ) && stristr( sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) ), 'Trident/7.0; rv:11.0' ) ) {
297            $iframe_embed = false;
298        } else {
299            // The site setting and the `jetpack_videopress_player_use_iframe` filter decide; see Inline_Player::is_enabled().
300            $iframe_embed = ! Inline_Player::is_enabled();
301        }
302
303        if ( ! array_key_exists( 'hd', $this->options ) ) {
304            $this->options['hd'] = (bool) get_option( 'video_player_high_quality', false );
305        }
306
307        if ( ! array_key_exists( 'cover', $this->options ) ) {
308            $this->options['cover'] = true;
309        }
310
311        $videopress_options = array(
312            'width'  => absint( $this->video->calculated_width ),
313            'height' => absint( $this->video->calculated_height ),
314        );
315        foreach ( $this->options as $option => $value ) {
316            switch ( $option ) {
317                case 'at':
318                    if ( (int) $value ) {
319                        $videopress_options[ $option ] = (int) $value;
320                    }
321                    break;
322                case 'autoplay':
323                    $option = 'autoPlay'; // Fall-through ok.
324                case 'hd':
325                case 'loop':
326                case 'permalink':
327                case 'cover':
328                case 'muted':
329                case 'controls':
330                case 'playsinline':
331                case 'useAverageColor':
332                    if ( in_array( $value, array( true, 1, 'true' ), true ) ) {
333                        $videopress_options[ $option ] = true;
334                    } elseif ( in_array( $value, array( false, 0, 'false' ), true ) ) {
335                        $videopress_options[ $option ] = false;
336                    }
337                    // phpcs:enable
338                    break;
339                case 'defaultlangcode':
340                    $option = 'defaultLangCode';
341                    if ( $value ) {
342                        $videopress_options[ $option ] = $value;
343                    }
344                    break;
345                case 'preloadContent':
346                    if ( $value ) {
347                        $videopress_options['preloadContent'] = $value;
348                    }
349            }
350        }
351
352        if ( $iframe_embed ) {
353            $iframe_url = "https://videopress.com/embed/{$this->video->guid}";
354
355            foreach ( $videopress_options as $option => $value ) {
356                if ( ! in_array( $option, array( 'width', 'height' ), true ) ) {
357
358                    // add_query_arg ignores false as a value, so replacing it with 0
359                    // @phan-suppress-next-line PhanPluginSimplifyExpressionBool -- Probably it could, but semantically let's keep it as-is.
360                    $iframe_url = add_query_arg( $option, ( false === $value ) ? 0 : $value, $iframe_url );
361                }
362            }
363
364            $cover = $videopress_options['cover'] ? ' data-resize-to-parent="true"' : '';
365
366            wp_enqueue_script( 'videopress-iframe', 'https://videopress.com/videopress-iframe.js', array(), JETPACK__VERSION, true );
367
368            return "<iframe title='" . __( 'VideoPress Video Player', 'jetpack' )
369                . "' aria-label='" . __( 'VideoPress Video Player', 'jetpack' )
370                . "' width='" . esc_attr( $videopress_options['width'] )
371                . "' height='" . esc_attr( $videopress_options['height'] )
372                . "' src='" . esc_attr( $iframe_url )
373                . "' frameborder='0' allowfullscreen"
374                . $cover
375                . " allow='clipboard-write; presentation'></iframe>";
376
377        } else {
378            $attributes = array(
379                'autoplay'        => $videopress_options['autoPlay'] ?? false,
380                'controls'        => $videopress_options['controls'] ?? true,
381                'loop'            => $videopress_options['loop'] ?? false,
382                'muted'           => $videopress_options['muted'] ?? false,
383                'playsinline'     => $videopress_options['playsinline'] ?? false,
384                'useAverageColor' => $videopress_options['useAverageColor'] ?? true,
385                'cover'           => $videopress_options['cover'],
386                'hd'              => $videopress_options['hd'],
387                'at'              => $videopress_options['at'] ?? 0,
388                'preload'         => $videopress_options['preloadContent'] ?? 'metadata',
389                'defaultLangCode' => $videopress_options['defaultLangCode'] ?? '',
390            );
391            $ratio      = $videopress_options['width'] > 0
392                ? ( $videopress_options['height'] / $videopress_options['width'] ) * 100
393                : null;
394
395            $guid = (string) $this->video->guid;
396
397            // The video data already carries the poster frame VideoPress serves for this site.
398            $poster = ! empty( $this->video->poster_frame_uri ) && is_string( $this->video->poster_frame_uri )
399                ? $this->video->poster_frame_uri
400                : Inline_Player::get_poster_url( $guid );
401
402            return "<div id='" . esc_attr( $video_container_id ) . "'>"
403                . Inline_Player::render(
404                    $guid,
405                    Inline_Player::get_player_options( $attributes ),
406                    $ratio,
407                    array(
408                        'poster' => $poster,
409                        'title'  => isset( $this->video->title ) ? (string) $this->video->title : '',
410                    )
411                )
412                . '</div>';
413        }
414    }
415
416    /**
417     * Validate legacy Flash parameters for backward compatibility.
418     *
419     * @since 1.2
420     * @deprecated $$next-version$$ Flash playback is no longer supported.
421     * @param array $flash_params Flash parameters expressed in key-value form.
422     * @return array Validated Flash parameters.
423     */
424    public static function esc_flash_params( $flash_params ) {
425        _deprecated_function( __METHOD__, 'jetpack-$$next-version$$' );
426
427        $allowed_params = array(
428            'swliveconnect'         => array( 'true', 'false' ),
429            'play'                  => array( 'true', 'false' ),
430            'loop'                  => array( 'true', 'false' ),
431            'menu'                  => array( 'true', 'false' ),
432            'quality'               => array( 'low', 'autolow', 'autohigh', 'medium', 'high', 'best' ),
433            'scale'                 => array( 'default', 'noborder', 'exactfit', 'noscale' ),
434            'align'                 => array( 'l', 'r', 't' ),
435            'salign'                => array( 'l', 'r', 't', 'tl', 'tr', 'bl', 'br' ),
436            'wmode'                 => array( 'window', 'opaque', 'transparent', 'direct', 'gpu' ),
437            'devicefont'            => array( '_sans', '_serif', '_typewriter' ),
438            'allowscriptaccess'     => array( 'always', 'samedomain', 'never' ),
439            'allownetworking'       => array( 'all', 'internal', 'none' ),
440            'seamlesstabbing'       => array( 'true', 'false' ),
441            'allowfullscreen'       => array( 'true', 'false' ),
442            'fullScreenAspectRatio' => array( 'portrait', 'landscape' ),
443        );
444
445        $filtered_params = array();
446        foreach ( $flash_params as $param => $value ) {
447            if ( empty( $param ) || empty( $value ) ) {
448                continue;
449            }
450            $param = strtolower( $param );
451            if ( isset( $allowed_params[ $param ] ) ) {
452                $value = strtolower( $value );
453                if ( in_array( $value, $allowed_params[ $param ], true ) ) {
454                    $filtered_params[ $param ] = $value;
455                }
456            }
457        }
458
459        // Flash requires the case-sensitive value sameDomain.
460        if ( isset( $filtered_params['allowscriptaccess'] ) && $filtered_params['allowscriptaccess'] === 'samedomain' ) {
461            $filtered_params['allowscriptaccess'] = 'sameDomain';
462        }
463
464        return $filtered_params;
465    }
466}