class-activation.php
3 years ago
class-admin-interface.php
3 years ago
class-content-management.php
3 years ago
class-deactivation.php
3 years ago
class-disable-components.php
3 years ago
class-security.php
3 years ago
class-settings-fields-render.php
3 years ago
class-settings-sanitization.php
3 years ago
class-settings-sections-fields.php
3 years ago
class-utilities.php
3 years ago
class-security.php
173 lines
| 1 | <?php |
| 2 | |
| 3 | namespace ASENHA\Classes; |
| 4 | |
| 5 | /** |
| 6 | * Class related to Security features |
| 7 | * |
| 8 | * @since 1.4.0 |
| 9 | */ |
| 10 | class Security { |
| 11 | |
| 12 | /** |
| 13 | * Redirect to /not_found when login URL does not contain the custom login slug |
| 14 | * |
| 15 | * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L121 |
| 16 | * @since 1.4.0 |
| 17 | */ |
| 18 | public function redirect_on_default_login_urls() { |
| 19 | |
| 20 | $options = get_option( ASENHA_SLUG_U ); |
| 21 | $custom_login_slug = $options['custom_login_slug']; |
| 22 | $url_input = sanitize_text_field( $_SERVER['REQUEST_URI'] ); |
| 23 | |
| 24 | // Custom login slug is not part of the login URL typed into the browser |
| 25 | // e.g. https://www.example.com/wp-admin/ or https://www.example.com/wp-login.php |
| 26 | if ( false === strpos( $url_input, $custom_login_slug ) ) { |
| 27 | |
| 28 | wp_safe_redirect( home_url( 'not_found/' ), 302 ); |
| 29 | exit(); |
| 30 | |
| 31 | } |
| 32 | |
| 33 | } |
| 34 | |
| 35 | /** |
| 36 | * Redirect to valid login URL when custom login slug is part of the request URL |
| 37 | * |
| 38 | * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L134 |
| 39 | * @since 1.4.0 |
| 40 | */ |
| 41 | public function redirect_on_custom_login_url() { |
| 42 | |
| 43 | $options = get_option( ASENHA_SLUG_U ); |
| 44 | $custom_login_slug = $options['custom_login_slug']; |
| 45 | $url_input = parse_url( sanitize_text_field( $_SERVER['REQUEST_URI'] ) ); // an array |
| 46 | |
| 47 | if ( ( $url_input['path'] == '/' . $custom_login_slug ) || ( $url_input['path'] == '/' . $custom_login_slug . '/' ) ) { |
| 48 | |
| 49 | wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false' ) ); |
| 50 | exit(); |
| 51 | |
| 52 | } |
| 53 | |
| 54 | } |
| 55 | |
| 56 | /** |
| 57 | * Redirect on successful logout |
| 58 | * |
| 59 | * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L148 |
| 60 | * @since 1.4.0 |
| 61 | */ |
| 62 | public function redirect_to_custom_login_url() { |
| 63 | |
| 64 | $options = get_option( ASENHA_SLUG_U ); |
| 65 | $custom_login_slug = $options['custom_login_slug']; |
| 66 | |
| 67 | wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false' ) ); |
| 68 | exit(); |
| 69 | |
| 70 | } |
| 71 | |
| 72 | /** |
| 73 | * If an author name is queried, decrypt it. Used by pre_get_posts action. |
| 74 | * |
| 75 | * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/tags/4.0.2/inc/class-smart-user-slug-hider.php |
| 76 | * @since 2.1.0 |
| 77 | */ |
| 78 | function alter_author_query( $query ) { |
| 79 | |
| 80 | // Check if it's a query for author data, and that 'author_name' is not empty |
| 81 | if ( $query->is_author() && $query->query_vars['author_name'] != '' ) { |
| 82 | |
| 83 | // Check for character(s) representing a hexadecimal digit |
| 84 | if ( ctype_xdigit( $query->query_vars['author_name'] ) ) { |
| 85 | |
| 86 | // Get user by the decrypted user ID |
| 87 | $user = get_user_by( 'id', $this->decrypt( $query->query_vars['author_name'] ) ); |
| 88 | |
| 89 | if ( $user ) { |
| 90 | |
| 91 | $query->set( 'author_name', $user->user_nicename ); |
| 92 | |
| 93 | } else { |
| 94 | |
| 95 | // No user found |
| 96 | $query->is_404 = true; |
| 97 | $query->is_author = false; |
| 98 | $query->is_archive = false; |
| 99 | |
| 100 | } |
| 101 | |
| 102 | } else { |
| 103 | |
| 104 | // No hexadecimal digit detected in URL, i.e. someone is trying to access URL with original author slug |
| 105 | $query->is_404 = true; |
| 106 | $query->is_author = false; |
| 107 | $query->is_archive = false; |
| 108 | |
| 109 | } |
| 110 | |
| 111 | } |
| 112 | |
| 113 | return; |
| 114 | } |
| 115 | |
| 116 | /** |
| 117 | * Replace author slug in author link to encrypted value. Used by author_link filter. |
| 118 | * |
| 119 | * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/tags/4.0.2/inc/class-smart-user-slug-hider.php |
| 120 | * @since 2.1.0 |
| 121 | */ |
| 122 | function alter_author_link( $link, $user_id, $author_slug ) { |
| 123 | |
| 124 | $encrypted_author_slug = $this->encrypt( $user_id ); |
| 125 | |
| 126 | return str_replace ( '/' . $author_slug, '/' . $encrypted_author_slug, $link ); |
| 127 | |
| 128 | } |
| 129 | |
| 130 | /** |
| 131 | * Replace author slug in REST API /users/ endpoint to encrypted value. Used by rest_prepare_user filter. |
| 132 | * |
| 133 | * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/tags/4.0.2/inc/class-smart-user-slug-hider.php |
| 134 | * @since 2.1.0 |
| 135 | */ |
| 136 | function alter_json_users($response, $user, $request) { |
| 137 | |
| 138 | $data = $response->get_data(); |
| 139 | $data['slug'] = $this->encrypt($data['id']); |
| 140 | $response->set_data($data); |
| 141 | |
| 142 | return $response; |
| 143 | |
| 144 | } |
| 145 | |
| 146 | /** |
| 147 | * Helper function to return an encrypted user ID, which will then be used to replace the author slug. |
| 148 | * |
| 149 | * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/trunk/inc/class-smart-user-slug-hider.php |
| 150 | * @since 2.1.0 |
| 151 | */ |
| 152 | private function encrypt( $user_id ) { |
| 153 | |
| 154 | // Returns encrypted encrypted author slug from user ID, e.g. encrypt user ID 3 to author slug 4e3062d8c8626a14 |
| 155 | return bin2hex( openssl_encrypt( base_convert( $user_id, 10, 36 ), 'DES-EDE3', md5( sanitize_text_field( $_SERVER['SERVER_ADDR'] ) . ASENHA_URL ), OPENSSL_RAW_DATA ) ); |
| 156 | |
| 157 | } |
| 158 | |
| 159 | |
| 160 | /** |
| 161 | * Helper function to decrypt an (encrypted) author slug and returns the user ID |
| 162 | * |
| 163 | * @link https://plugins.trac.wordpress.org/browser/smart-user-slug-hider/trunk/inc/class-smart-user-slug-hider.php |
| 164 | * @since 2.1.0 |
| 165 | */ |
| 166 | private function decrypt( $encrypted_author_slug ) { |
| 167 | |
| 168 | // Returns user ID, e.g. decrypts author slug 4e3062d8c8626a14 into user ID 3 |
| 169 | return base_convert( openssl_decrypt( pack('H*', $encrypted_author_slug), 'DES-EDE3', md5( sanitize_text_field( $_SERVER['SERVER_ADDR'] ) . ASENHA_URL ), OPENSSL_RAW_DATA ), 36, 10 ); |
| 170 | |
| 171 | } |
| 172 | |
| 173 | } |