| @@ -18,8 +18,97 @@ | ||
| 18 | 18 | |
| 19 | 19 | class Block extends BlockBaseAbstract { |
| 20 | 20 | protected $block_name = 'logout'; |
| 21 | 21 | |
| 22 | + /** | |
| 23 | + * Query arg carrying the signature of a block-issued logout redirect URL. | |
| 24 | + */ | |
| 25 | + const REDIRECT_SIGNATURE_ARG = 'ablocks_rs'; | |
| 26 | + | |
| 27 | + public function __construct( $keep_silent = false ) { | |
| 28 | + parent::__construct( $keep_silent ); | |
| 29 | + | |
| 30 | + if ( $this->is_enabled_block() && ! $keep_silent ) { | |
| 31 | + add_filter( 'allowed_redirect_hosts', array( $this, 'allow_signed_logout_redirect_host' ) ); | |
| 32 | + } | |
| 33 | + } | |
| 34 | + | |
| 35 | + /** | |
| 36 | + * wp-login.php ends a logout with wp_safe_redirect(), which swaps any host | |
| 37 | + * outside `allowed_redirect_hosts` for admin_url() — so a custom URL on | |
| 38 | + * another domain never took effect. Allow that host for this one request, | |
| 39 | + * and only when the redirect carries a signature this block produced from | |
| 40 | + * the site's secret salts: a hand-made or edited `redirect_to` stays | |
| 41 | + * rejected, so this is not an open redirect. | |
| 42 | + * | |
| 43 | + * @param string[] $hosts Allowed hosts. | |
| 44 | + * @return string[] | |
| 45 | + */ | |
| 46 | + public function allow_signed_logout_redirect_host( $hosts ) { | |
| 47 | + global $pagenow; | |
| 48 | + | |
| 49 | + // phpcs:disable WordPress.Security.NonceVerification.Recommended -- wp-login.php verifies the log-out nonce itself; this only reads the redirect target. | |
| 50 | + if ( | |
| 51 | + 'wp-login.php' !== $pagenow || | |
| 52 | + ! isset( $_REQUEST['action'], $_REQUEST['redirect_to'], $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) || | |
| 53 | + 'logout' !== $_REQUEST['action'] || | |
| 54 | + ! is_string( $_REQUEST['redirect_to'] ) || | |
| 55 | + ! is_string( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) | |
| 56 | + ) { | |
| 57 | + return $hosts; | |
| 58 | + } | |
| 59 | + | |
| 60 | + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- compared against an HMAC, never output. | |
| 61 | + $redirect = wp_unslash( $_REQUEST['redirect_to'] ); | |
| 62 | + $signature = sanitize_text_field( wp_unslash( $_REQUEST[ self::REDIRECT_SIGNATURE_ARG ] ) ); | |
| 63 | + // phpcs:enable WordPress.Security.NonceVerification.Recommended | |
| 64 | + | |
| 65 | + if ( ! hash_equals( self::sign_redirect_url( $redirect ), $signature ) ) { | |
| 66 | + return $hosts; | |
| 67 | + } | |
| 68 | + | |
| 69 | + $host = wp_parse_url( $redirect, PHP_URL_HOST ); | |
| 70 | + if ( $host ) { | |
| 71 | + $hosts[] = $host; | |
| 72 | + } | |
| 73 | + | |
| 74 | + return $hosts; | |
| 75 | + } | |
| 76 | + | |
| 77 | + private static function sign_redirect_url( $url ) { | |
| 78 | + return wp_hash( 'ablocks-logout-redirect|' . $url, 'nonce' ); | |
| 79 | + } | |
| 80 | + | |
| 81 | + /** | |
| 82 | + * Normalize the configured custom URL, falling back to the home URL for an | |
| 83 | + * empty, non-HTTP(S) or malformed value. | |
| 84 | + * | |
| 85 | + * @param string $url Configured URL. | |
| 86 | + * @return string | |
| 87 | + */ | |
| 88 | + private static function sanitize_custom_redirect_url( $url ) { | |
| 89 | + $url = esc_url_raw( trim( (string) $url ), array( 'http', 'https' ) ); | |
| 90 | + if ( '' === $url ) { | |
| 91 | + return home_url(); | |
| 92 | + } | |
| 93 | + | |
| 94 | + $parts = wp_parse_url( $url ); | |
| 95 | + if ( false === $parts ) { | |
| 96 | + return home_url(); | |
| 97 | + } | |
| 98 | + | |
| 99 | + // esc_url_raw() turns bare text such as "not a url" into "http://notaurl"; | |
| 100 | + // a real destination is either this site's host or a dotted domain name. | |
| 101 | + if ( isset( $parts['host'] ) ) { | |
| 102 | + $home_host = wp_parse_url( home_url(), PHP_URL_HOST ); | |
| 103 | + if ( $parts['host'] !== $home_host && false === strpos( $parts['host'], '.' ) ) { | |
| 104 | + return home_url(); | |
| 105 | + } | |
| 106 | + } | |
| 107 | + | |
| 108 | + return $url; | |
| 109 | + } | |
| 110 | + | |
| 22 | 111 | public function build_css( $attributes ) { |
| 23 | 112 | $css_generator = new CssGeneratorV2( $attributes, $this->block_name ); |
| 24 | 113 | |
| 25 | 114 | $css_generator->add_class_styles( |
| @@ -140,11 +229,9 @@ | ||
| 140 | 229 | if ( $logout_redirect_option === 'current-url' ) { |
| 141 | 230 | // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash |
| 142 | 231 | $logout_redirect_url = ( is_ssl() ? 'https://' : 'http://' ) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] ); |
| 143 | 232 | } elseif ( $logout_redirect_option === 'custom-url' ) { |
| 144 | - $logout_redirect_url = isset( $attributes['logoutCustomUrl'] ) && ! empty( $attributes['logoutCustomUrl'] ) | |
| 145 | - ? esc_url( $attributes['logoutCustomUrl'] ) | |
| 146 | - : home_url(); | |
| 233 | + $logout_redirect_url = self::sanitize_custom_redirect_url( isset( $attributes['logoutCustomUrl'] ) ? $attributes['logoutCustomUrl'] : '' ); | |
| 147 | 234 | } |
| 148 | 235 | |
| 149 | 236 | $login_redirect_option = isset( $attributes['loginRedirect'] ) ? $attributes['loginRedirect'] : 'current-url'; |
| 150 | 237 | |
| @@ -174,8 +261,18 @@ | ||
| 174 | 261 | ? ( isset( $attributes['logOutLabel'] ) ? sanitize_text_field( $attributes['logOutLabel'] ) : __( '(Log Out)', 'ablocks' ) ) |
| 175 | 262 | : ( isset( $attributes['logInLabel'] ) ? sanitize_text_field( $attributes['logInLabel'] ) : __( '(Log In)', 'ablocks' ) ); |
| 176 | 263 | |
| 177 | 264 | $action_url = $is_logged_in ? wp_logout_url( $logout_redirect_url ) : wp_login_url( $login_redirect_url ); |
| 265 | + | |
| 266 | + if ( $is_logged_in && 'custom-url' === $logout_redirect_option ) { | |
| 267 | + // wp_logout_url() returns an HTML-escaped URL; decode it before adding | |
| 268 | + // the arg, the anchor below escapes it again. | |
| 269 | + $action_url = add_query_arg( | |
| 270 | + self::REDIRECT_SIGNATURE_ARG, | |
| 271 | + self::sign_redirect_url( $logout_redirect_url ), | |
| 272 | + html_entity_decode( $action_url, ENT_QUOTES ) | |
| 273 | + ); | |
| 274 | + } | |
| 178 | 275 | |
| 179 | 276 | ob_start(); |
| 180 | 277 | ?> |
| 181 | 278 | <div class="ablocks-block-logout"> |