Skip to content

Sync: Provide explanation on missing nonce verifications - #37402

Merged
fgiannar merged 15 commits into
trunkfrom
update/sync-handle-missing-nonce-verification
May 21, 2024
Merged

Sync: Provide explanation on missing nonce verifications#37402
fgiannar merged 15 commits into
trunkfrom
update/sync-handle-missing-nonce-verification

Conversation

@fgiannar

Copy link
Copy Markdown
Contributor

We are adding explanations inside the Sync package when nonce verification is missing.

Proposed changes:

  • Accompany phpcs:ignore WordPress.Security.NonceVerification.Missing ignore rules for missing nonce verification with an explanation on why it's ok to skip it.

Other information:

  • Have you written new tests for your changes, if applicable?
  • Have you checked the E2E test CI results, and verified that your changes do not break them?
  • Have you tested your changes on WordPress.com, if applicable (if so, you'll see a generated comment below with a script to run)?

Jetpack product discussion

p9dueE-8ca-p2

Does this pull request change what data or activity we track or use?

No

Testing instructions:

  • Code Review: Are the explanations we provide acceptable?

@github-actions

github-actions Bot commented May 15, 2024

Copy link
Copy Markdown
Contributor

Are you an Automattician? Please test your changes on all WordPress.com environments to help mitigate accidental explosions.

  • To test on WoA, go to the Plugins menu on a WordPress.com Simple site. Click on the "Upload" button and follow the upgrade flow to be able to upload, install, and activate the Jetpack Beta plugin. Once the plugin is active, go to Jetpack > Jetpack Beta, select your plugin, and enable the update/sync-handle-missing-nonce-verification branch.

    • For jetpack-mu-wpcom changes, also add define( 'JETPACK_MU_WPCOM_LOAD_VIA_BETA_PLUGIN', true ); to your wp-config.php file.
  • To test on Simple, run the following command on your sandbox:

    bin/jetpack-downloader test jetpack update/sync-handle-missing-nonce-verification
    
    bin/jetpack-downloader test jetpack-mu-wpcom-plugin update/sync-handle-missing-nonce-verification
    

Interested in more tips and information?

  • In your local development environment, use the jetpack rsync command to sync your changes to a WoA dev blog.
  • Read more about our development workflow here: PCYsg-eg0-p2
  • Figure out when your changes will be shipped to customers here: PCYsg-eg5-p2

@github-actions

Copy link
Copy Markdown
Contributor

Thank you for your PR!

When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:

  • ✅ Include a description of your PR changes.
  • ✅ Add a "[Status]" label (In Progress, Needs Team Review, ...).
  • ✅ Add testing instructions.
  • ✅ Specify whether this PR includes any changes to data or privacy.
  • ✅ Add changelog entries to affected projects

This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖


The e2e test report can be found here. Please note that it can take a few minutes after the e2e tests checks are complete for the report to be available.


Once your PR is ready for review, check one last time that all required checks appearing at the bottom of this PR are passing or skipped.
Then, add the "[Status] Needs Team Review" label and ask someone from your team review the code. Once reviewed, it can then be merged.
If you need an extra review from someone familiar with the codebase, you can update the labels from "[Status] Needs Team Review" to "[Status] Needs Review", and in that case Jetpack Approvers will do a final review of your PR.

@fgiannar fgiannar added [Status] Needs Review This PR is ready for review. and removed [Status] In Progress labels May 16, 2024
@fgiannar
fgiannar requested review from anomiex May 16, 2024 10:07

@anomiex anomiex left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left some copy edits and suggestions inline. Feel free to disagree, maybe I want to be a little too explicit in the reasoning. 😅

Comment thread projects/packages/sync/src/modules/class-plugins.php Outdated
Comment thread projects/packages/sync/src/modules/class-posts.php
public function is_gutenberg_meta_box_update() {
// phpcs:disable WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
private function is_gutenberg_meta_box_update() {
// phpcs:disable WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- We are using $_POST['action'] to detect if this is a Gutenberg meta box update.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd say more like this

Suggested change
// phpcs:disable WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- We are using $_POST['action'] to detect if this is a Gutenberg meta box update.
// phpcs:disable WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- Nonce checking, if necessary, is the responsibility of the caller. We can't know here what the caller is going to do with the return value.

And possibly also put a note in the function's doc block about the caller being responsible for checking a nonce if necessary.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hmm if this becomes a private method we can be more explicit here I think and mention that we are only using it to detect if this is a Gutenberg meta box update and set a flag before sending the corresponding action to wpcom?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I updated it based on the above, however feel free to suggest and commit any alternative explanation you feel is better :)

Comment thread projects/packages/sync/src/modules/class-themes.php Outdated
Comment thread projects/packages/sync/src/modules/class-themes.php Outdated
Comment thread projects/packages/sync/src/modules/class-themes.php Outdated
Comment thread projects/packages/sync/src/modules/class-posts.php Outdated
Co-authored-by: Brad Jorsch <anomiex@users.noreply.github.com>
@fgiannar
fgiannar enabled auto-merge (squash) May 17, 2024 14:43
Comment thread projects/packages/sync/src/modules/class-themes.php Outdated
Comment thread projects/packages/sync/src/modules/class-themes.php Outdated
fgiannar and others added 2 commits May 21, 2024 18:17
Co-authored-by: Brad Jorsch <anomiex@users.noreply.github.com>
Co-authored-by: Brad Jorsch <anomiex@users.noreply.github.com>

@anomiex anomiex left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Haven't tested it though.

@fgiannar
fgiannar merged commit 391f1f2 into trunk May 21, 2024
@fgiannar
fgiannar deleted the update/sync-handle-missing-nonce-verification branch May 21, 2024 17:14
@github-actions github-actions Bot removed the [Status] Needs Review This PR is ready for review. label May 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants