PluginProbe
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder / 2.9.0
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder v2.9.0
2.13.0 2.13.1 2.12.0 2.11.1 2.11.0 2.10.0 2.9.0 2.7.4 2.7.5 2.7.6 2.7.7 2.8.0 2.8.1 2.9.1 trunk 1.0 1.0-beta1 1.0-beta2 1.0-beta3 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.1.2 All 80 releases
ablocks / includes / blocks / form-builder / email-verification.php

email-verification.php in aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder 2.9.0, at includes/blocks/form-builder/email-verification.php

124 lines 3.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 namespace ABlocks\Blocks\FormBuilder;
3
4 if ( ! defined( 'ABSPATH' ) ) {
5 exit;
6 }
7
8 use Exception;
9 /**
10 * @class EmailVerification
11 * This class is user to verify forms email
12 */
13 class EmailVerification {
14 /** Link expiration time */
15 const EXPIRE_IN = 3600;
16 private int $id;
17 private string $email;
18 private string $verification_token;
19
20 private string $signature;
21 private bool $expiration_check = false;
22 private int $expire_at;
23
24 public function __construct( $id_or_email, ?string $search_key = null ) {
25 global $wpdb;
26 $table_entries = $wpdb->prefix . ABLOCKS_PLUGIN_SLUG . '_form_entries';
27
28 if ( $search_key === 'id' ) {
29 $query = "SELECT id, user_email, email_verification_token, expire, is_email_verified FROM {$table_entries} WHERE id = %d";
30 } else {
31 $query = "SELECT id, user_email, email_verification_token, expire, is_email_verified FROM {$table_entries} WHERE user_email = %s";
32 }
33 // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared
34 $entry = $wpdb->get_row( $wpdb->prepare( $query, $id_or_email ), ARRAY_A );
35
36 if (
37 ! array_key_exists( 'email_verification_token', $entry ) ||
38 $entry['is_email_verified'] === 'yes'
39 ) {
40 throw new Exception( 'Invalid ID or Email/ Already verified.' );
41 }
42
43 $this->id = $entry['id'];
44 $this->email = $entry['user_email'];
45 $this->verification_token = $entry['email_verification_token'];
46 $this->expire_at = $entry['expire'];
47 }
48
49 public function verify_signature( string $signature ) {
50 $saved_signature = $this->get_signature();
51 if ( $saved_signature ) {
52 return hash_equals( $saved_signature, $signature );
53 }
54 return false;
55 }
56
57 public function get_signature() {
58 if ( $this->verification_token ) {
59 return hash_hmac( 'sha256', $this->email . $this->expire_at, $this->verification_token );
60 }
61 return false;
62 }
63
64 public function get_signed_url() {
65 $signature = $this->get_signature();
66 if ( $signature ) {
67 return add_query_arg(
68 [
69 'id' => $this->id,
70 'signature' => $signature,
71 'expire' => $this->expire_at,
72 ],
73 home_url( '/' )
74 );
75 }
76 }
77
78 public function mark_email_as_verified() {
79 global $wpdb;
80 $table_entries = $wpdb->prefix . ABLOCKS_PLUGIN_SLUG . '_form_entries';
81 // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
82 if ( $wpdb->update( $table_entries, [ 'is_email_verified' => 'yes' ], [ 'id' => $this->id ] ) ) {
83 return true;
84 }
85 return false;
86 }
87
88
89
90 public static function verify( $post_data ) {
91 if (
92 ! isset( $post_data['id'] ) ||
93 ! isset( $post_data['signature'] ) ||
94 ! isset( $post_data['expire'] )
95 ) {
96 return 'no data';
97 }
98
99 $id = intval( sanitize_text_field( $post_data['id'] ) );
100 $expire = intval( sanitize_text_field( $post_data['expire'] ) );
101 $signature = sanitize_text_field( $post_data['signature'] );
102
103 try {
104
105 $verification_obj = new self( $id, 'id' );
106
107 if (
108 $verification_obj->expiration_check &&
109 $verification_obj->expire_at !== $expire &&
110 time() > $expire
111 ) {
112 return 'Link expired.';
113 }
114
115 if ( $verification_obj->verify_signature( $signature ) ) {
116 return $verification_obj->mark_email_as_verified() ? [ 'success' => true ] : 'error';
117 }
118 } catch ( Exception $e ) {
119 return 'Error';
120 }
121 return 'Error';
122 }
123 }
124