X-Git-Url: https://scripts.mit.edu/gitweb/autoinstalls/wordpress.git/blobdiff_plain/7f1521bf193b382565eb753043c161f4cb3fcda7..e3ff8f35458a959c1879c0a4976701ed8dcfe651:/wp-admin/includes/class-wp-press-this.php diff --git a/wp-admin/includes/class-wp-press-this.php b/wp-admin/includes/class-wp-press-this.php index 257c76dc..71ce5153 100644 --- a/wp-admin/includes/class-wp-press-this.php +++ b/wp-admin/includes/class-wp-press-this.php @@ -13,8 +13,8 @@ * @since 4.2.0 */ class WP_Press_This { - // Used to trigger the bookmarklet update notice. + const VERSION = 8; public $version = 8; private $images = array(); @@ -42,11 +42,11 @@ class WP_Press_This { public function site_settings() { return array( /** - * Filter whether or not Press This should redirect the user in the parent window upon save. + * Filters whether or not Press This should redirect the user in the parent window upon save. * * @since 4.2.0 * - * @param bool false Whether to redirect in parent window or not. Default false. + * @param bool $redirect Whether to redirect in parent window or not. Default false. */ 'redirInParent' => apply_filters( 'press_this_redirect_in_parent', false ), ); @@ -91,12 +91,12 @@ class WP_Press_This { } } - // Edxpected slashed + // Expected slashed return wp_slash( $content ); } /** - * AJAX handler for saving the post as draft or published. + * Ajax handler for saving the post as draft or published. * * @since 4.2.0 * @access public @@ -112,7 +112,7 @@ class WP_Press_This { wp_send_json_error( array( 'errorMessage' => __( 'Invalid post.' ) ) ); } - $post = array( + $post_data = array( 'ID' => $post_id, 'post_title' => ( ! empty( $_POST['post_title'] ) ) ? sanitize_text_field( trim( $_POST['post_title'] ) ) : '', 'post_content' => ( ! empty( $_POST['post_content'] ) ) ? trim( $_POST['post_content'] ) : '', @@ -125,35 +125,51 @@ class WP_Press_This { if ( ! empty( $_POST['post_status'] ) && 'publish' === $_POST['post_status'] ) { if ( current_user_can( 'publish_posts' ) ) { - $post['post_status'] = 'publish'; + $post_data['post_status'] = 'publish'; } else { - $post['post_status'] = 'pending'; + $post_data['post_status'] = 'pending'; } } - $post['post_content'] = $this->side_load_images( $post_id, $post['post_content'] ); + $post_data['post_content'] = $this->side_load_images( $post_id, $post_data['post_content'] ); + + /** + * Filters the post data of a Press This post before saving/updating. + * + * The {@see 'side_load_images'} action has already run at this point. + * + * @since 4.5.0 + * + * @param array $post_data The post data. + */ + $post_data = apply_filters( 'press_this_save_post', $post_data ); - $updated = wp_update_post( $post, true ); + $updated = wp_update_post( $post_data, true ); if ( is_wp_error( $updated ) ) { wp_send_json_error( array( 'errorMessage' => $updated->get_error_message() ) ); } else { - if ( isset( $post['post_format'] ) ) { - if ( current_theme_supports( 'post-formats', $post['post_format'] ) ) { - set_post_format( $post_id, $post['post_format'] ); - } elseif ( $post['post_format'] ) { + if ( isset( $post_data['post_format'] ) ) { + if ( current_theme_supports( 'post-formats', $post_data['post_format'] ) ) { + set_post_format( $post_id, $post_data['post_format'] ); + } elseif ( $post_data['post_format'] ) { set_post_format( $post_id, false ); } } + $forceRedirect = false; + if ( 'publish' === get_post_status( $post_id ) ) { $redirect = get_post_permalink( $post_id ); + } elseif ( isset( $_POST['pt-force-redirect'] ) && $_POST['pt-force-redirect'] === 'true' ) { + $forceRedirect = true; + $redirect = get_edit_post_link( $post_id, 'js' ); } else { $redirect = false; } /** - * Filter the URL to redirect to when Press This saves. + * Filters the URL to redirect to when Press This saves. * * @since 4.2.0 * @@ -162,10 +178,10 @@ class WP_Press_This { * @param int $post_id Post ID. * @param string $status Post status. */ - $redirect = apply_filters( 'press_this_save_redirect', $redirect, $post_id, $post['post_status'] ); + $redirect = apply_filters( 'press_this_save_redirect', $redirect, $post_id, $post_data['post_status'] ); if ( $redirect ) { - wp_send_json_success( array( 'redirect' => $redirect ) ); + wp_send_json_success( array( 'redirect' => $redirect, 'force' => $forceRedirect ) ); } else { wp_send_json_success( array( 'postSaved' => true ) ); } @@ -173,7 +189,7 @@ class WP_Press_This { } /** - * AJAX handler for adding a new category. + * Ajax handler for adding a new category. * * @since 4.2.0 * @access public @@ -201,11 +217,17 @@ class WP_Press_This { continue; } - // @todo Find a more performant to check existence, maybe get_term() with a separate parent check. - if ( ! $cat_id = term_exists( $cat_name, $taxonomy->name, $parent ) ) { - $cat_id = wp_insert_term( $cat_name, $taxonomy->name, array( 'parent' => $parent ) ); + // @todo Find a more performant way to check existence, maybe get_term() with a separate parent check. + if ( term_exists( $cat_name, $taxonomy->name, $parent ) ) { + if ( count( $names ) === 1 ) { + wp_send_json_error( array( 'errorMessage' => __( 'This category already exists.' ) ) ); + } else { + continue; + } } + $cat_id = wp_insert_term( $cat_name, $taxonomy->name, array( 'parent' => $parent ) ); + if ( is_wp_error( $cat_id ) ) { continue; } elseif ( is_array( $cat_id ) ) { @@ -245,46 +267,44 @@ class WP_Press_This { * @return string Source's HTML sanitized markup */ public function fetch_source_html( $url ) { - // Download source page to tmp file. - $source_tmp_file = ( ! empty( $url ) ) ? download_url( $url, 30 ) : ''; - $source_content = ''; - - if ( ! is_wp_error( $source_tmp_file ) && file_exists( $source_tmp_file ) ) { - - // Get the content of the source page from the tmp file.. - $source_content = wp_kses( - @file_get_contents( $source_tmp_file ), - array( - 'img' => array( - 'src' => array(), - 'width' => array(), - 'height' => array(), - ), - 'iframe' => array( - 'src' => array(), - ), - 'link' => array( - 'rel' => array(), - 'itemprop' => array(), - 'href' => array(), - ), - 'meta' => array( - 'property' => array(), - 'name' => array(), - 'content' => array(), - ) - ) - ); + if ( empty( $url ) ) { + return new WP_Error( 'invalid-url', __( 'A valid URL was not provided.' ) ); + } - // All done with backward compatibility. Let's do some cleanup, for good measure :) - unlink( $source_tmp_file ); + $remote_url = wp_safe_remote_get( $url, array( + 'timeout' => 30, + // Use an explicit user-agent for Press This + 'user-agent' => 'Press This (WordPress/' . get_bloginfo( 'version' ) . '); ' . get_bloginfo( 'url' ) + ) ); - } else if ( is_wp_error( $source_tmp_file ) ) { - $source_content = new WP_Error( 'upload-error', sprintf( __( 'Error: %s' ), sprintf( __( 'Could not download the source URL (native error: %s).' ), $source_tmp_file->get_error_message() ) ) ); - } else if ( ! file_exists( $source_tmp_file ) ) { - $source_content = new WP_Error( 'no-local-file', sprintf( __( 'Error: %s' ), __( 'Could not save or locate the temporary download file for the source URL.' ) ) ); + if ( is_wp_error( $remote_url ) ) { + return $remote_url; } + $allowed_elements = array( + 'img' => array( + 'src' => true, + 'width' => true, + 'height' => true, + ), + 'iframe' => array( + 'src' => true, + ), + 'link' => array( + 'rel' => true, + 'itemprop' => true, + 'href' => true, + ), + 'meta' => array( + 'property' => true, + 'name' => true, + 'content' => true, + ) + ); + + $source_content = wp_remote_retrieve_body( $remote_url ); + $source_content = wp_kses( $source_content, $allowed_elements ); + return $source_content; } @@ -358,7 +378,7 @@ class WP_Press_This { return ''; // Return empty rather than a truncated/invalid URL } - // Does not look like an URL. + // Does not look like a URL. if ( ! preg_match( '/^([!#$&-;=?-\[\]_a-z~]|%[0-9a-fA-F]{2})+$/', $url ) ) { return ''; } @@ -379,8 +399,8 @@ class WP_Press_This { /** * Utility method to limit image source URLs. * - * Excluded URLs include share-this type buttons, loaders, spinners, spacers, WP interface images, - * tiny buttons or thumbs, mathtag.com or quantserve.com images, or the WP stats gif. + * Excluded URLs include share-this type buttons, loaders, spinners, spacers, WordPress interface images, + * tiny buttons or thumbs, mathtag.com or quantserve.com images, or the WordPress.com stats gif. * * @ignore * @since 4.2.0 @@ -391,32 +411,32 @@ class WP_Press_This { private function _limit_img( $src ) { $src = $this->_limit_url( $src ); - if ( preg_match( '/\/ad[sx]{1}?\//', $src ) ) { + if ( preg_match( '!/ad[sx]?/!i', $src ) ) { // Ads return ''; - } else if ( preg_match( '/(\/share-?this[^\.]+?\.[a-z0-9]{3,4})(\?.*)?$/', $src ) ) { + } else if ( preg_match( '!(/share-?this[^.]+?\.[a-z0-9]{3,4})(\?.*)?$!i', $src ) ) { // Share-this type button return ''; - } else if ( preg_match( '/\/(spinner|loading|spacer|blank|rss)\.(gif|jpg|png)/', $src ) ) { + } else if ( preg_match( '!/(spinner|loading|spacer|blank|rss)\.(gif|jpg|png)!i', $src ) ) { // Loaders, spinners, spacers return ''; - } else if ( preg_match( '/\/([^\.\/]+[-_]{1})?(spinner|loading|spacer|blank)s?([-_]{1}[^\.\/]+)?\.[a-z0-9]{3,4}/', $src ) ) { + } else if ( preg_match( '!/([^./]+[-_])?(spinner|loading|spacer|blank)s?([-_][^./]+)?\.[a-z0-9]{3,4}!i', $src ) ) { // Fancy loaders, spinners, spacers return ''; - } else if ( preg_match( '/([^\.\/]+[-_]{1})?thumb[^.]*\.(gif|jpg|png)$/', $src ) ) { + } else if ( preg_match( '!([^./]+[-_])?thumb[^.]*\.(gif|jpg|png)$!i', $src ) ) { // Thumbnails, too small, usually irrelevant to context return ''; - } else if ( preg_match( '/\/wp-includes\//', $src ) ) { - // Classic WP interface images + } else if ( false !== stripos( $src, '/wp-includes/' ) ) { + // Classic WordPress interface images return ''; - } else if ( preg_match( '/[^\d]{1}\d{1,2}x\d+\.(gif|jpg|png)$/', $src ) ) { + } else if ( preg_match( '![^\d]\d{1,2}x\d+\.(gif|jpg|png)$!i', $src ) ) { // Most often tiny buttons/thumbs (< 100px wide) return ''; - } else if ( preg_match( '/\/pixel\.(mathtag|quantserve)\.com/', $src ) ) { + } else if ( preg_match( '!/pixel\.(mathtag|quantserve)\.com!i', $src ) ) { // See mathtag.com and https://www.quantcast.com/how-we-do-it/iab-standard-measurement/how-we-collect-data/ return ''; - } else if ( preg_match( '/\/[gb]\.gif(\?.+)?$/', $src ) ) { - // Classic WP stats gif + } else if ( preg_match( '!/[gb]\.gif(\?.+)?$!i', $src ) ) { + // WordPress.com stats gif return ''; } @@ -438,29 +458,30 @@ class WP_Press_This { private function _limit_embed( $src ) { $src = $this->_limit_url( $src ); - if ( preg_match( '/\/\/(m|www)\.youtube\.com\/(embed|v)\/([^\?]+)\?.+$/', $src, $src_matches ) ) { + if ( empty( $src ) ) + return ''; + + if ( preg_match( '!//(m|www)\.youtube\.com/(embed|v)/([^?]+)\?.+$!i', $src, $src_matches ) ) { // Embedded Youtube videos (www or mobile) $src = 'https://www.youtube.com/watch?v=' . $src_matches[3]; - } else if ( preg_match( '/\/\/player\.vimeo\.com\/video\/([\d]+)([\?\/]{1}.*)?$/', $src, $src_matches ) ) { + } else if ( preg_match( '!//player\.vimeo\.com/video/([\d]+)([?/].*)?$!i', $src, $src_matches ) ) { // Embedded Vimeo iframe videos $src = 'https://vimeo.com/' . (int) $src_matches[1]; - } else if ( preg_match( '/\/\/vimeo\.com\/moogaloop\.swf\?clip_id=([\d]+)$/', $src, $src_matches ) ) { + } else if ( preg_match( '!//vimeo\.com/moogaloop\.swf\?clip_id=([\d]+)$!i', $src, $src_matches ) ) { // Embedded Vimeo Flash videos $src = 'https://vimeo.com/' . (int) $src_matches[1]; - } else if ( preg_match( '/\/\/vine\.co\/v\/([^\/]+)\/embed/', $src, $src_matches ) ) { + } else if ( preg_match( '!//vine\.co/v/([^/]+)/embed!i', $src, $src_matches ) ) { // Embedded Vine videos $src = 'https://vine.co/v/' . $src_matches[1]; - } else if ( preg_match( '/\/\/(www\.)?dailymotion\.com\/embed\/video\/([^\/\?]+)([\/\?]{1}.+)?/', $src, $src_matches ) ) { + } else if ( preg_match( '!//(www\.)?dailymotion\.com/embed/video/([^/?]+)([/?].+)?!i', $src, $src_matches ) ) { // Embedded Daily Motion videos $src = 'https://www.dailymotion.com/video/' . $src_matches[2]; - } else if ( ! preg_match( '/\/\/(m|www)\.youtube\.com\/watch\?/', $src ) // Youtube video page (www or mobile) - && ! preg_match( '/\/youtu\.be\/.+$/', $src ) // Youtu.be video page - && ! preg_match( '/\/\/vimeo\.com\/[\d]+$/', $src ) // Vimeo video page - && ! preg_match( '/\/\/(www\.)?dailymotion\.com\/video\/.+$/', $src ) // Daily Motion video page - && ! preg_match( '/\/\/soundcloud\.com\/.+$/', $src ) // SoundCloud audio page - && ! preg_match( '/\/\/twitter\.com\/[^\/]+\/status\/[\d]+$/', $src ) // Twitter status page - && ! preg_match( '/\/\/vine\.co\/v\/[^\/]+/', $src ) ) { // Vine video page - $src = ''; + } else { + $oembed = _wp_oembed_get_object(); + + if ( ! $oembed->get_provider( $src, array( 'discover' => false ) ) ) { + $src = ''; + } } return $src; @@ -667,7 +688,7 @@ class WP_Press_This { } /** - * Filter whether to enable in-source media discovery in Press This. + * Filters whether to enable in-source media discovery in Press This. * * @since 4.2.0 * @@ -730,10 +751,19 @@ class WP_Press_This { } } } + + // Support passing a single image src as `i` + if ( ! empty( $_REQUEST['i'] ) && ( $img_src = $this->_limit_img( wp_unslash( $_REQUEST['i'] ) ) ) ) { + if ( empty( $data['_images'] ) ) { + $data['_images'] = array( $img_src ); + } elseif ( ! in_array( $img_src, $data['_images'], true ) ) { + array_unshift( $data['_images'], $img_src ); + } + } } /** - * Filter the Press This data array. + * Filters the Press This data array. * * @since 4.2.0 * @@ -790,7 +820,7 @@ class WP_Press_This { ?>
-
+
/> cap->edit_terms ) ) { ?> -
  - - - - +
+
+ +
+
    +
  • +
  • +
  • +
+
@@ -1450,6 +1500,9 @@ class WP_Press_This { /** This action is documented in wp-admin/admin-footer.php */ do_action( 'admin_footer' ); + /** This action is documented in wp-admin/admin-footer.php */ + do_action( 'admin_print_footer_scripts-press-this.php' ); + /** This action is documented in wp-admin/admin-footer.php */ do_action( 'admin_print_footer_scripts' ); @@ -1462,5 +1515,3 @@ class WP_Press_This { die(); } } - -$GLOBALS['wp_press_this'] = new WP_Press_This;