updated plugin ActivityPub version 8.3.0

This commit is contained in:
2026-06-03 21:28:46 +00:00
committed by Gitium
parent a4b78ec277
commit 6fe182458a
340 changed files with 43232 additions and 7568 deletions

View File

@ -8,7 +8,7 @@
namespace Activitypub;
use Activitypub\Collection\Actors;
use WP_Comment_Query;
use Activitypub\Collection\Remote_Posts;
/**
* ActivityPub Comment Class.
@ -23,23 +23,80 @@ class Comment {
public static function init() {
self::register_comment_types();
\add_filter( 'map_meta_cap', array( self::class, 'map_meta_cap' ), 10, 4 );
\add_filter( 'comment_reply_link', array( self::class, 'comment_reply_link' ), 10, 3 );
\add_filter( 'comment_class', array( self::class, 'comment_class' ), 10, 3 );
\add_filter( 'comment_feed_where', array( static::class, 'comment_feed_where' ) );
\add_filter( 'get_comment_link', array( self::class, 'remote_comment_link' ), 11, 2 );
\add_action( 'wp_enqueue_scripts', array( self::class, 'enqueue_scripts' ) );
\add_action( 'pre_get_comments', array( static::class, 'comment_query' ) );
\add_filter( 'pre_comment_approved', array( static::class, 'pre_comment_approved' ), 10, 2 );
\add_filter( 'pre_comment_approved', array( static::class, 'pre_comment_approved' ), 11, 2 );
\add_filter( 'get_avatar_comment_types', array( static::class, 'get_avatar_comment_types' ), 99 );
\add_action( 'update_option_activitypub_allow_likes', array( self::class, 'maybe_update_comment_counts' ), 10, 2 );
\add_action( 'update_option_activitypub_allow_reposts', array( self::class, 'maybe_update_comment_counts' ), 10, 2 );
\add_filter( 'pre_wp_update_comment_count_now', array( static::class, 'pre_wp_update_comment_count_now' ), 10, 3 );
\add_filter( 'pre_wp_update_comment_count_now', array( static::class, 'pre_wp_update_comment_count_now' ), 5, 3 );
\add_filter( 'get_comment_author', array( static::class, 'render_emoji' ), 10, 2 );
\add_filter( 'comment_author', array( static::class, 'unescape_emoji' ), 20 ); // After esc_html().
\add_filter( 'rest_comment_query', array( static::class, 'rest_comment_query' ) );
\add_filter( 'comment_text', array( static::class, 'render_blocks' ), 5 ); // Before other filters.
}
/**
* Render blocks in comment content.
*
* Comments don't automatically parse blocks like posts do.
* This filter applies do_blocks() to render activitypub/emoji
* and activitypub/image blocks in comment content.
*
* @param string $content The comment content.
*
* @return string The content with blocks rendered.
*/
public static function render_blocks( $content ) {
if ( empty( $content ) || ! \str_contains( $content, '<!-- wp:activitypub/' ) ) {
return $content;
}
$blocks = \parse_blocks( $content );
$output = '';
foreach ( $blocks as $block ) {
if ( ! empty( $block['blockName'] ) && \str_starts_with( $block['blockName'], 'activitypub/' ) ) {
$output .= \render_block( $block );
} else {
$output .= \serialize_block( $block );
}
}
return $output;
}
/**
* Remove edit capabilities for comments received via ActivityPub.
*
* @param array $caps Array of capabilities.
* @param string $cap Capability name.
* @param int $user_id User ID.
* @param array $args Array of arguments.
*
* @return array Modified array of capabilities.
*/
public static function map_meta_cap( $caps, $cap, $user_id, $args ) {
if ( 'edit_comment' === $cap && self::was_received( $args[0] ) ) {
if ( ! \is_admin() || ( isset( $GLOBALS['current_screen'] ) && 'comment' === $GLOBALS['current_screen']->id ) ) {
$caps[] = 'do_not_allow';
}
}
return $caps;
}
/**
* Filter the comment reply link.
*
* We don't want to show the comment reply link for federated comments
* if the user is disabled for federation.
* Handles three cases for replies to fediverse comments:
* 1. User can federate → show normal reply link
* 2. User is logged in but can't federate → show warning (no reply link)
* 3. User is not logged in → show remote reply block
*
* @param string $link The HTML markup for the comment reply link.
* @param array $args An array of arguments overriding the defaults.
@ -49,53 +106,60 @@ class Comment {
*/
public static function comment_reply_link( $link, $args, $comment ) {
if ( self::are_comments_allowed( $comment ) ) {
if ( \current_user_can( 'activitypub' ) && self::was_received( $comment ) ) {
return self::create_fediverse_reply_link( $link, $args );
}
return $link;
}
$attrs = array(
// Logged-in user without ActivityPub capability - show warning instead of reply link.
if ( \is_user_logged_in() ) {
$author = \esc_html( $comment->comment_author );
$message = sprintf(
/* translators: %s: comment author name */
\__( '%s is on the Fediverse. To reply to them, ask your administrator to enable ActivityPub for your account.', 'activitypub' ),
$author
);
// Add link to users page if current user can edit users.
if ( \current_user_can( 'edit_users' ) ) {
$message = sprintf(
/* translators: 1: comment author name, 2: URL to the users management page */
\__( '%1$s is on the Fediverse. To reply to them, <a href="%2$s">enable ActivityPub for your account</a>.', 'activitypub' ),
$author,
\esc_url( \admin_url( 'users.php' ) )
);
}
$warning = sprintf(
'<p class="activitypub-reply-warning"><em>%s</em></p>',
\wp_kses( $message, array( 'a' => array( 'href' => array() ) ) )
);
/**
* Filters the warning message shown to logged-in users without ActivityPub capability.
*
* @param string $warning The warning HTML markup.
* @param \WP_Comment $comment The comment being replied to.
*/
return \apply_filters( 'activitypub_federation_warning', $warning, $comment );
}
if ( ! \WP_Block_Type_Registry::get_instance()->is_registered( 'activitypub/remote-reply' ) ) {
\register_block_type_from_metadata( ACTIVITYPUB_PLUGIN_DIR . 'build/remote-reply' );
}
$attributes = array(
'selectedComment' => self::generate_id( $comment ),
'commentId' => $comment->comment_ID,
);
$div = sprintf(
'<div class="reply activitypub-remote-reply" data-attrs="%s"></div>',
esc_attr( wp_json_encode( $attrs ) )
);
$block = \do_blocks( \sprintf( '<!-- wp:activitypub/remote-reply %s /-->', \wp_json_encode( $attributes ) ) );
/**
* Filters the HTML markup for the ActivityPub remote comment reply container.
*
* @param string $div The HTML markup for the remote reply container. Default is a div
* with class 'activitypub-remote-reply' and data attributes for
* the selected comment ID and internal comment ID.
* @param string $block The HTML markup for the remote reply container.
*/
return apply_filters( 'activitypub_comment_reply_link', $div );
}
/**
* Create a link to reply to a federated comment.
*
* This function adds a title attribute to the reply link to inform the user
* that the comment was received from the fediverse and the reply will be sent
* to the original author.
*
* @param string $link The HTML markup for the comment reply link.
* @param array $args The args provided by the `comment_reply_link` filter.
*
* @return string The modified HTML markup for the comment reply link.
*/
private static function create_fediverse_reply_link( $link, $args ) {
$str_to_replace = sprintf( '>%s<', $args['reply_text'] );
$replace_with = sprintf(
' title="%s">%s<',
esc_attr__( 'This comment was received from the fediverse and your reply will be sent to the original author', 'activitypub' ),
esc_html__( 'Reply with federation', 'activitypub' )
);
return str_replace( $str_to_replace, $replace_with, $link );
return \apply_filters( 'activitypub_comment_reply_link', $block );
}
/**
@ -120,11 +184,12 @@ class Comment {
return false;
}
if ( is_single_user() && \user_can( $current_user, 'publish_posts' ) ) {
// On a single user site, comments by users with the `publish_posts` capability will be federated as the blog user.
if ( is_single_user() && \user_can( $current_user, 'activitypub' ) ) {
// On a single user site, comments by users with the `activitypub` capability will be federated as the blog user.
$current_user = Actors::BLOG_USER_ID;
}
// User is not allowed to federate comments.
return user_can_activitypub( $current_user );
}
@ -225,7 +290,7 @@ class Comment {
}
if ( is_single_user() && \user_can( $user_id, 'activitypub' ) ) {
// On a single user site, comments by users with the `publish_posts` capability will be federated as the blog user.
// On a single user site, comments by users with the `activitypub` capability will be federated as the blog user.
$user_id = Actors::BLOG_USER_ID;
}
@ -253,7 +318,7 @@ class Comment {
* @return \WP_Comment|false Comment object, or false on failure.
*/
public static function object_id_to_comment( $id ) {
$comment_query = new WP_Comment_Query(
$comment_query = new \WP_Comment_Query(
array(
'meta_key' => 'source_id', // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_key
'meta_value' => $id, // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_value
@ -278,16 +343,16 @@ class Comment {
* @return string|null Comment ID or null if not found.
*/
public static function url_to_commentid( $url ) {
if ( ! $url || ! filter_var( $url, \FILTER_VALIDATE_URL ) ) {
if ( ! $url || ! \filter_var( $url, \FILTER_VALIDATE_URL ) ) {
return null;
}
// Check for local comment.
if ( \wp_parse_url( \home_url(), \PHP_URL_HOST ) === \wp_parse_url( $url, \PHP_URL_HOST ) ) {
if ( is_same_domain( $url ) ) {
$query = \wp_parse_url( $url, \PHP_URL_QUERY );
if ( $query ) {
parse_str( $query, $params );
\parse_str( $query, $params );
if ( ! empty( $params['c'] ) ) {
$comment = \get_comment( $params['c'] );
@ -314,7 +379,7 @@ class Comment {
),
);
$query = new WP_Comment_Query();
$query = new \WP_Comment_Query();
$comments = $query->query( $args );
if ( $comments && is_array( $comments ) ) {
@ -342,6 +407,38 @@ class Comment {
return $classes;
}
/**
* Makes the comment feed filterable by comment type.
*
* Also excludes ActivityPub comment types from the feed when no type is specified.
*
* @param string $where The `WHERE` clause for the comment feed query.
*
* @return string The modified `WHERE` clause.
*/
public static function comment_feed_where( $where ) {
global $wpdb;
$comment_type = \get_query_var( 'type' );
if ( 'all' === $comment_type ) {
return $where;
}
$comment_types = self::get_comment_type_slugs();
if ( \in_array( $comment_type, $comment_types, true ) ) {
$where .= $wpdb->prepare( ' AND comment_type = %s', $comment_type );
} else {
$comment_types = \array_map( 'esc_sql', $comment_types );
$placeholders = implode( ', ', array_fill( 0, count( $comment_types ), '%s' ) );
// phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.ReplacementsWrongNumber, WordPress.DB.PreparedSQL.NotPrepared
$where .= $wpdb->prepare( sprintf( ' AND comment_type NOT IN (%s)', $placeholders ), ...$comment_types );
}
return $where;
}
/**
* Gets the public comment id via the WordPress comments meta.
*
@ -391,13 +488,16 @@ class Comment {
* @return string $url
*/
public static function remote_comment_link( $comment_link, $comment ) {
if ( ! $comment || is_admin() ) {
if ( ! $comment || \is_admin() || \is_search() ) {
return $comment_link;
}
$public_comment_link = self::get_source_url( $comment->comment_ID );
$remote_comment_link = null;
if ( 'comment' === $comment->comment_type ) {
$remote_comment_link = self::get_source_url( $comment->comment_ID );
}
return $public_comment_link ?? $comment_link;
return $remote_comment_link ?? $comment_link;
}
@ -419,7 +519,7 @@ class Comment {
}
// Generate URI based on comment ID.
return \add_query_arg( 'c', $comment->comment_ID, \trailingslashit( \home_url() ) );
return \add_query_arg( 'c', $comment->comment_ID, \home_url( '/' ) );
}
/**
@ -452,60 +552,6 @@ class Comment {
return ! empty( $comments );
}
/**
* Enqueue scripts for remote comments
*/
public static function enqueue_scripts() {
if ( ! \is_singular() || \is_user_logged_in() ) {
// Only on single pages, only for logged-out users.
return;
}
if ( ! \post_type_supports( \get_post_type(), 'activitypub' ) ) {
// Post type does not support ActivityPub.
return;
}
if ( ! \comments_open() || ! \get_comments_number() ) {
// No comments, no need to load the script.
return;
}
if ( ! self::post_has_remote_comments( \get_the_ID() ) ) {
// No remote comments, no need to load the script.
return;
}
$handle = 'activitypub-remote-reply';
$data = array(
'namespace' => ACTIVITYPUB_REST_NAMESPACE,
'defaultAvatarUrl' => ACTIVITYPUB_PLUGIN_URL . 'assets/img/mp.jpg',
);
$js = sprintf( 'var _activityPubOptions = %s;', wp_json_encode( $data ) );
$asset_file = ACTIVITYPUB_PLUGIN_DIR . 'build/remote-reply/index.asset.php';
if ( \file_exists( $asset_file ) ) {
$assets = require_once $asset_file;
\wp_enqueue_script(
$handle,
\plugins_url( 'build/remote-reply/index.js', __DIR__ ),
$assets['dependencies'],
$assets['version'],
true
);
\wp_add_inline_script( $handle, $js, 'before' );
\wp_set_script_translations( $handle, 'activitypub' );
\wp_enqueue_style(
$handle,
\plugins_url( 'build/remote-reply/style-index.css', __DIR__ ),
array( 'wp-components' ),
$assets['version']
);
}
}
/**
* Get the comment type by activity type.
*
@ -535,7 +581,7 @@ class Comment {
public static function get_comment_types() {
global $activitypub_comment_types;
return $activitypub_comment_types;
return (array) $activitypub_comment_types;
}
/**
@ -560,22 +606,15 @@ class Comment {
* @return array The registered custom comment type slugs.
*/
public static function get_comment_type_slugs() {
if ( ! did_action( 'init' ) ) {
_doing_it_wrong( __METHOD__, 'This function should not be called before the init action has run. Comment types are only available after init.', '7.5.0' );
return array();
}
return array_keys( self::get_comment_types() );
}
/**
* Return the registered custom comment type slugs.
*
* @deprecated 4.5.0 Use get_comment_type_slugs instead.
*
* @return array The registered custom comment type slugs.
*/
public static function get_comment_type_names() {
_deprecated_function( __METHOD__, '4.5.0', 'get_comment_type_slugs' );
return self::get_comment_type_slugs();
}
/**
* Get the custom comment type.
*
@ -643,7 +682,7 @@ class Comment {
array(
'label' => __( 'Reposts', 'activitypub' ),
'singular' => __( 'Repost', 'activitypub' ),
'description' => __( 'A repost on the indieweb is a post that is purely a 100% re-publication of another (typically someone else\'s) post.', 'activitypub' ),
'description' => 'A repost (or Announce) is when a post appears in the timeline because someone else shared it, while still showing the original author as the source.',
'icon' => '♻️',
'class' => 'p-repost',
'type' => 'repost',
@ -662,7 +701,7 @@ class Comment {
array(
'label' => __( 'Likes', 'activitypub' ),
'singular' => __( 'Like', 'activitypub' ),
'description' => __( 'A like is a popular webaction button and in some cases post type on various silos such as Facebook and Instagram.', 'activitypub' ),
'description' => 'A like is a small positive reaction that shows appreciation for a post without sharing it further.',
'icon' => '👍',
'class' => 'p-like',
'type' => 'like',
@ -675,6 +714,25 @@ class Comment {
'count_plural' => _x( '%d likes', 'number of likes', 'activitypub' ),
)
);
register_comment_type(
'quote',
array(
'label' => __( 'Quotes', 'activitypub' ),
'singular' => __( 'Quote', 'activitypub' ),
'description' => 'A quote is when a post is shared along with an added comment, so the original post appears together with the sharer&#8217;s own words.',
'icon' => '❞',
'class' => 'p-quote',
'type' => 'quote',
'collection' => 'quotes',
'activity_types' => array( 'quote' ),
'excerpt' => html_entity_decode( \__( '&hellip; quoted this!', 'activitypub' ) ),
/* translators: %d: Number of quotes */
'count_single' => _x( '%d quote', 'number of quotes', 'activitypub' ),
/* translators: %d: Number of quotes */
'count_plural' => _x( '%d quotes', 'number of quotes', 'activitypub' ),
)
);
}
/**
@ -698,10 +756,10 @@ class Comment {
*
* @see https://github.com/janboddez/indieblocks/blob/a2d59de358031056a649ee47a1332ce9e39d4ce2/includes/functions.php#L423-L432
*
* @param WP_Comment_Query $query Comment count.
* @param \WP_Comment_Query $query Comment count.
*/
public static function comment_query( $query ) {
if ( ! $query instanceof WP_Comment_Query ) {
if ( ! $query instanceof \WP_Comment_Query ) {
return;
}
@ -710,53 +768,125 @@ class Comment {
return;
}
// Do not exclude likes and reposts on REST requests.
// Do not exclude likes and reposts on REST requests (handled by rest_comment_query).
if ( \wp_is_serving_rest_request() ) {
return;
}
// Do not exclude likes and reposts on admin pages or on non-singular pages.
if ( is_admin() || ! is_singular() ) {
// Filter post types for admin requests.
if ( \is_admin() ) {
$query->query_vars['post_type'] = self::get_allowed_comment_post_types();
return;
}
// Do not exclude likes and reposts if the query is for comments.
// Do not exclude likes and reposts on non-singular pages.
if ( ! \is_singular() ) {
return;
}
// Do not exclude likes and reposts if the query is for specific types.
if ( ! empty( $query->query_vars['type__in'] ) || ! empty( $query->query_vars['type'] ) ) {
return;
}
// Do not exclude likes and reposts if the query is already excluding other comment types.
if ( ! empty( $query->query_vars['type__not_in'] ) ) {
return;
}
// Exclude likes and reposts by the ActivityPub plugin.
$query->query_vars['type__not_in'] = self::get_comment_type_slugs();
}
/**
* Filters comments in REST API requests.
*
* Excludes comments on ActivityPub post types and ActivityPub comment
* types (likes, reposts) from the REST API.
*
* @param array $prepared_args Array of arguments for WP_Comment_Query.
*
* @return array Modified array of arguments.
*/
public static function rest_comment_query( $prepared_args ) {
// Exclude comments on ActivityPub post types.
$prepared_args['post_type'] = self::get_allowed_comment_post_types();
// Exclude ActivityPub comment types (likes, reposts) unless explicitly requested.
if ( empty( $prepared_args['type'] ) && empty( $prepared_args['type__in'] ) ) {
$prepared_args['type__not_in'] = self::get_comment_type_slugs();
}
return $prepared_args;
}
/**
* Returns post types that should show comments (excluding hidden post types).
*
* @return array Array of post type names.
*/
private static function get_allowed_comment_post_types() {
$hide_for = self::hide_for();
if ( empty( $hide_for ) ) {
return \get_post_types_by_support( 'comments' );
}
return \array_diff( \get_post_types_by_support( 'comments' ), $hide_for );
}
/**
* Filter the comment status before it is set.
*
* @param string $approved The approved comment status.
* @param array $commentdata The comment data.
* @param int|string|\WP_Error $approved The approved comment status.
* @param array $comment_data The comment data.
*
* @return boolean `true` if the comment is approved, `false` otherwise.
* @return int|string|\WP_Error The approval status. 1, 0, 'spam', 'trash', or WP_Error.
*/
public static function pre_comment_approved( $approved, $commentdata ) {
if ( $approved || \is_wp_error( $approved ) ) {
public static function pre_comment_approved( $approved, $comment_data ) {
/*
* Only return early for already-approved comments, trash, or errors.
* Don't short-circuit on 'spam' - we may want to override Akismet.
* Respect 'trash' since it comes from the WordPress disallowed list.
*/
if ( 1 === $approved || '1' === $approved || 'trash' === $approved || \is_wp_error( $approved ) ) {
return $approved;
}
// Maybe auto-approve likes and reposts.
if (
\in_array( $comment_data['comment_type'], self::get_comment_type_slugs(), true ) &&
'1' === \get_option( 'activitypub_auto_approve_reactions' )
) {
return 1;
}
/*
* Always auto-approve comments on remote posts (ap_post) since
* they are not visible in the WP admin comment moderation screen.
*/
$post_id = $comment_data['comment_post_ID'];
$post = \get_post( $post_id );
if ( $post && \in_array( $post->post_type, self::hide_for(), true ) ) {
return 1;
}
if ( '1' !== \get_option( 'comment_previously_approved' ) ) {
return $approved;
}
if (
empty( $commentdata['comment_meta']['protocol'] ) ||
'activitypub' !== $commentdata['comment_meta']['protocol']
empty( $comment_data['comment_meta']['protocol'] ) ||
'activitypub' !== $comment_data['comment_meta']['protocol']
) {
return $approved;
}
global $wpdb;
$author = $commentdata['comment_author'];
$author_url = $commentdata['comment_author_url'];
$author = $comment_data['comment_author'];
$author_url = $comment_data['comment_author_url'];
// phpcs:ignore
$ok_to_comment = $wpdb->get_var( $wpdb->prepare( "SELECT comment_approved FROM $wpdb->comments WHERE comment_author = %s AND comment_author_url = %s and comment_approved = '1' LIMIT 1", $author, $author_url ) );
@ -795,6 +925,29 @@ class Comment {
$excluded_types = array_filter( self::get_comment_type_slugs(), array( self::class, 'is_comment_type_enabled' ) );
if ( ! empty( $excluded_types ) ) {
/*
* Include 'note' type when Gutenberg's filter is registered, so a
* single query excludes both ActivityPub and Gutenberg types.
*/
if ( \has_filter( 'pre_wp_update_comment_count_now', 'gutenberg_exclude_notes_from_comment_count' ) ) {
$excluded_types[] = 'note';
}
/**
* Filters the comment types excluded from the comment count.
*
* Runs at priority 5 on `pre_wp_update_comment_count_now` so that
* a single query can exclude types from multiple plugins. Other
* plugins can hook here to add their own comment types.
*
* @since 8.0.0
*
* @param string[] $excluded_types The comment type slugs to exclude.
* @param int $post_id The post ID.
*/
$excluded_types = \apply_filters( 'activitypub_excluded_comment_types', $excluded_types, $post_id );
$excluded_types = array_unique( array_filter( $excluded_types ) );
global $wpdb;
// phpcs:ignore WordPress.DB
@ -814,4 +967,72 @@ class Comment {
public static function is_comment_type_enabled( $comment_type ) {
return '1' === get_option( "activitypub_allow_{$comment_type}s", '1' );
}
/**
* Get post types to hide comments for in admin.
*
* These are non-public post types whose comments should not appear
* in the main comments list in the WordPress admin.
*
* @return string[] Array of post type names to hide comments for.
*/
public static function hide_for() {
$post_types = array( Remote_Posts::POST_TYPE );
/**
* Filters the list of post types to hide comments for.
*
* @param string[] $post_types Array of post type names to hide comments for.
*/
return \apply_filters( 'activitypub_hide_comments_for', $post_types );
}
/**
* Render emoji in comment author name.
*
* Replaces emoji shortcodes with img tags on the get_comment_author filter.
* Emoji data is retrieved from the linked remote actor.
*
* @param string $author The comment author name.
* @param string $comment_id The comment ID as a numeric string.
*
* @return string The comment author name with rendered emoji.
*/
public static function render_emoji( $author, $comment_id ) {
$remote_actor_id = \get_comment_meta( $comment_id, '_activitypub_remote_actor_id', true );
if ( empty( $remote_actor_id ) ) {
return $author;
}
$emoji_data = \get_post_meta( $remote_actor_id, '_activitypub_emoji', true );
if ( empty( $emoji_data ) ) {
return $author;
}
return Emoji::replace_from_json( $author, $emoji_data );
}
/**
* Selectively unescape emoji images in comment author.
*
* This runs at priority 20 after WordPress's esc_html() filter on comment_author.
*
* @param string $author The comment author name (already escaped by WordPress).
*
* @return string The comment author name with emoji images unescaped.
*/
public static function unescape_emoji( $author ) {
// Only attempt to unescape if there are emoji images present in the escaped string.
if ( false === \strpos( $author, 'class=&quot;emoji&quot;' ) ) {
return $author;
}
// Decode entities so we can selectively restore emoji <img> tags.
$decoded = \html_entity_decode( $author, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
// Use strict KSES validation to only allow valid emoji img tags.
return \wp_kses( $decoded, Emoji::get_kses_allowed_html() );
}
}