PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 2.2.0
Admin and Site Enhancements (ASE) v2.2.0
9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-security.php
admin-site-enhancements / classes Last commit date
class-activation.php 3 years ago class-admin-interface.php 3 years ago class-content-management.php 3 years ago class-deactivation.php 3 years ago class-disable-components.php 3 years ago class-security.php 3 years ago class-settings-fields-render.php 3 years ago class-settings-sanitization.php 3 years ago class-settings-sections-fields.php 3 years ago class-utilities.php 3 years ago
class-security.php
173 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 /**
6 * Class related to Security features
7 *
8 * @since 1.4.0
9 */
10 class Security {
11
12 /**
13 * Redirect to /not_found when login URL does not contain the custom login slug
14 *
15 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L121
16 * @since 1.4.0
17 */
18 public function redirect_on_default_login_urls() {
19
20 $options = get_option( ASENHA_SLUG_U );
21 $custom_login_slug = $options['custom_login_slug'];
22 $url_input = sanitize_text_field( $_SERVER['REQUEST_URI'] );
23
24 // Custom login slug is not part of the login URL typed into the browser
25 // e.g. https://www.example.com/wp-admin/ or https://www.example.com/wp-login.php
26 if ( false === strpos( $url_input, $custom_login_slug ) ) {
27
28 wp_safe_redirect( home_url( 'not_found/' ), 302 );
29 exit();
30
31 }
32
33 }
34
35 /**
36 * Redirect to valid login URL when custom login slug is part of the request URL
37 *
38 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L134
39 * @since 1.4.0
40 */
41 public function redirect_on_custom_login_url() {
42
43 $options = get_option( ASENHA_SLUG_U );
44 $custom_login_slug = $options['custom_login_slug'];
45 $url_input = parse_url( sanitize_text_field( $_SERVER['REQUEST_URI'] ) ); // an array
46
47 if ( ( $url_input['path'] == '/' . $custom_login_slug ) || ( $url_input['path'] == '/' . $custom_login_slug . '/' ) ) {
48
49 wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false' ) );
50 exit();
51
52 }
53
54 }
55
56 /**
57 * Redirect on successful logout
58 *
59 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L148
60 * @since 1.4.0
61 */
62 public function redirect_to_custom_login_url() {
63
64 $options = get_option( ASENHA_SLUG_U );
65 $custom_login_slug = $options['custom_login_slug'];
66
67 wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false' ) );
68 exit();
69
70 }
71
72 /**
73 * If an author name is queried, decrypt it. Used by pre_get_posts action.
74 *
75 * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/tags/4.0.2/inc/class-smart-user-slug-hider.php
76 * @since 2.1.0
77 */
78 function alter_author_query( $query ) {
79
80 // Check if it's a query for author data, and that 'author_name' is not empty
81 if ( $query->is_author() && $query->query_vars['author_name'] != '' ) {
82
83 // Check for character(s) representing a hexadecimal digit
84 if ( ctype_xdigit( $query->query_vars['author_name'] ) ) {
85
86 // Get user by the decrypted user ID
87 $user = get_user_by( 'id', $this->decrypt( $query->query_vars['author_name'] ) );
88
89 if ( $user ) {
90
91 $query->set( 'author_name', $user->user_nicename );
92
93 } else {
94
95 // No user found
96 $query->is_404 = true;
97 $query->is_author = false;
98 $query->is_archive = false;
99
100 }
101
102 } else {
103
104 // No hexadecimal digit detected in URL, i.e. someone is trying to access URL with original author slug
105 $query->is_404 = true;
106 $query->is_author = false;
107 $query->is_archive = false;
108
109 }
110
111 }
112
113 return;
114 }
115
116 /**
117 * Replace author slug in author link to encrypted value. Used by author_link filter.
118 *
119 * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/tags/4.0.2/inc/class-smart-user-slug-hider.php
120 * @since 2.1.0
121 */
122 function alter_author_link( $link, $user_id, $author_slug ) {
123
124 $encrypted_author_slug = $this->encrypt( $user_id );
125
126 return str_replace ( '/' . $author_slug, '/' . $encrypted_author_slug, $link );
127
128 }
129
130 /**
131 * Replace author slug in REST API /users/ endpoint to encrypted value. Used by rest_prepare_user filter.
132 *
133 * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/tags/4.0.2/inc/class-smart-user-slug-hider.php
134 * @since 2.1.0
135 */
136 function alter_json_users($response, $user, $request) {
137
138 $data = $response->get_data();
139 $data['slug'] = $this->encrypt($data['id']);
140 $response->set_data($data);
141
142 return $response;
143
144 }
145
146 /**
147 * Helper function to return an encrypted user ID, which will then be used to replace the author slug.
148 *
149 * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/trunk/inc/class-smart-user-slug-hider.php
150 * @since 2.1.0
151 */
152 private function encrypt( $user_id ) {
153
154 // Returns encrypted encrypted author slug from user ID, e.g. encrypt user ID 3 to author slug 4e3062d8c8626a14
155 return bin2hex( openssl_encrypt( base_convert( $user_id, 10, 36 ), 'DES-EDE3', md5( sanitize_text_field( $_SERVER['SERVER_ADDR'] ) . ASENHA_URL ), OPENSSL_RAW_DATA ) );
156
157 }
158
159
160 /**
161 * Helper function to decrypt an (encrypted) author slug and returns the user ID
162 *
163 * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/trunk/inc/class-smart-user-slug-hider.php
164 * @since 2.1.0
165 */
166 private function decrypt( $encrypted_author_slug ) {
167
168 // Returns user ID, e.g. decrypts author slug 4e3062d8c8626a14 into user ID 3
169 return base_convert( openssl_decrypt( pack('H*', $encrypted_author_slug), 'DES-EDE3', md5( sanitize_text_field( $_SERVER['SERVER_ADDR'] ) . ASENHA_URL ), OPENSSL_RAW_DATA ), 36, 10 );
170
171 }
172
173 }