PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 7.2.0
Admin and Site Enhancements (ASE) v7.2.0
9.1.1 9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-change-login-url.php
admin-site-enhancements / classes Last commit date
class-activation.php 2 years ago class-admin-columns-manager.php 2 years ago class-admin-menu-organizer.php 2 years ago class-auto-publish-posts-with-missed-schedule.php 2 years ago class-avif-upload.php 2 years ago class-change-login-url.php 2 years ago class-cleanup-admin-bar.php 2 years ago class-code-snippets-manager.php 2 years ago class-common-methods.php 2 years ago class-content-duplication.php 2 years ago class-content-order.php 2 years ago class-custom-admin-footer-text.php 2 years ago class-custom-body-class.php 2 years ago class-custom-content-types.php 2 years ago class-custom-css.php 2 years ago class-custom-nav-menu-items-in-new-tab.php 2 years ago class-deactivation.php 2 years ago class-disable-comments.php 2 years ago class-disable-dashboard-widgets.php 2 years ago class-disable-feeds.php 2 years ago class-disable-gutenberg.php 2 years ago class-disable-rest-api.php 2 years ago class-disable-smaller-components.php 2 years ago class-disable-updates.php 2 years ago class-disable-xml-rpc.php 2 years ago class-display-system-summary.php 2 years ago class-email-address-obfuscator.php 2 years ago class-email-delivery.php 2 years ago class-enhance-list-tables.php 2 years ago class-external-permalinks.php 2 years ago class-heartbeat-control.php 2 years ago class-hide-admin-bar.php 2 years ago class-hide-admin-notices.php 2 years ago class-image-sizes-panel.php 2 years ago class-image-upload-control.php 2 years ago class-insert-head-body-footer-code.php 2 years ago class-last-login-column.php 2 years ago class-limit-login-attempts.php 2 years ago class-login-id-type.php 2 years ago class-login-logout-menu.php 2 years ago class-maintenance-mode.php 2 years ago class-manage-ads-appads-txt.php 2 years ago class-manage-robots-txt.php 2 years ago class-media-replacement.php 2 years ago class-multiple-user-roles.php 2 years ago class-obfuscate-author-slugs.php 2 years ago class-open-external-links-in-new-tab.php 2 years ago class-password-protection.php 2 years ago class-redirect-after-login.php 2 years ago class-redirect-after-logout.php 2 years ago class-redirect-fourofour.php 2 years ago class-revisions-control.php 2 years ago class-search-engines-visibility.php 2 years ago class-settings-fields-render.php 2 years ago class-settings-sanitization.php 2 years ago class-settings-sections-fields.php 2 years ago class-show-custom-taxonomy-filters.php 2 years ago class-site-identity-on-login-page.php 2 years ago class-svg-upload.php 2 years ago class-various-admin-ui-enhancements.php 2 years ago class-view-admin-as-role.php 2 years ago class-wider-admin-menu.php 2 years ago
class-change-login-url.php
308 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 /**
6 * Class for Change Login URL module
7 *
8 * @since 6.9.5
9 */
10 class Change_Login_URL {
11 /**
12 * Redirect to valid login URL when custom login slug is part of the request URL
13 *
14 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L134
15 * @since 1.4.0
16 */
17 public function redirect_on_custom_login_url() {
18 $options = get_option( ASENHA_SLUG_U );
19 $custom_login_slug = $options['custom_login_slug'];
20 $url_input = sanitize_text_field( $_SERVER['REQUEST_URI'] );
21 // Make sure $url_input ends with /
22 if ( false !== strpos( $url_input, $custom_login_slug ) ) {
23 if ( substr( $url_input, -1 ) != '/' ) {
24 $url_input = $url_input . '/';
25 }
26 }
27 // If URL contains the custom login slug, redirect to the dashboard
28 if ( false !== strpos( $url_input, '/' . $custom_login_slug . '/' ) ) {
29 if ( is_user_logged_in() ) {
30 if ( array_key_exists( 'redirect_after_login', $options ) && $options['redirect_after_login'] ) {
31 if ( array_key_exists( 'redirect_after_login_for', $options ) && !empty( $options['redirect_after_login_for'] ) ) {
32 // An almost exact replica of redirect_after_login() in class-redirect-after-login.php
33 $redirect_after_login_to_slug_raw = ( isset( $options['redirect_after_login_to_slug'] ) ? $options['redirect_after_login_to_slug'] : '' );
34 if ( !empty( $redirect_after_login_to_slug_raw ) ) {
35 $redirect_after_login_to_slug = trim( trim( $redirect_after_login_to_slug_raw ), '/' );
36 if ( false !== strpos( $redirect_after_login_to_slug, '.php' ) ) {
37 $slug_suffix = '';
38 } else {
39 $slug_suffix = '/';
40 }
41 $relative_path = $redirect_after_login_to_slug . $slug_suffix;
42 } else {
43 $relative_path = '';
44 }
45 $redirect_after_login_for = $options['redirect_after_login_for'];
46 if ( isset( $redirect_after_login_for ) && count( $redirect_after_login_for ) > 0 ) {
47 // Assemble single-dimensional array of roles for which custom URL redirection should happen
48 $roles_for_custom_redirect = array();
49 foreach ( $redirect_after_login_for as $role_slug => $custom_redirect ) {
50 if ( $custom_redirect ) {
51 $roles_for_custom_redirect[] = $role_slug;
52 }
53 }
54 // Does the user have roles data in array form?
55 $user = wp_get_current_user();
56 if ( isset( $user->roles ) && is_array( $user->roles ) ) {
57 $current_user_roles = $user->roles;
58 }
59 // Set custom redirect URL for roles set in the settings. Otherwise, leave redirect URL to the default, i.e. admin dashboard.
60 foreach ( $current_user_roles as $role ) {
61 if ( in_array( $role, $roles_for_custom_redirect ) ) {
62 if ( 'switch_to_user' != $_GET['action'] && 'switch_to_olduser' != $_GET['action'] ) {
63 wp_safe_redirect( home_url( $relative_path ) );
64 exit;
65 } else {
66 return;
67 }
68 } else {
69 if ( 'switch_to_user' != $_GET['action'] && 'switch_to_olduser' != $_GET['action'] ) {
70 // Redirect to dashboard
71 wp_safe_redirect( get_admin_url() );
72 } else {
73 return;
74 }
75 }
76 }
77 } else {
78 if ( 'switch_to_user' == $_GET['action'] || 'switch_to_olduser' == $_GET['action'] ) {
79 return;
80 }
81 }
82 } else {
83 // Redirect to dashboard
84 wp_safe_redirect( get_admin_url() );
85 }
86 } else {
87 if ( 'switch_to_user' != $_GET['action'] && 'switch_to_olduser' != $_GET['action'] ) {
88 // Redirect to dashboard
89 wp_safe_redirect( get_admin_url() );
90 } else {
91 return;
92 }
93 }
94 } else {
95 // Redirect to the login URL with custom login slug in the query parameters
96 wp_safe_redirect( site_url( '/wp-login.php?' . $custom_login_slug . '&redirect=false' ) );
97 }
98 exit;
99 }
100 }
101
102 /**
103 * Customize login URL returned when calling wp_login_url(). Add the custom login slug.
104 *
105 * @since 5.8.0
106 */
107 public function customize_login_url( $login_url, $redirect, $force_reauth ) {
108 $options = get_option( ASENHA_SLUG_U );
109 $custom_login_slug = $options['custom_login_slug'];
110 $login_url = home_url( '/' . $custom_login_slug . '/' );
111 if ( !empty( $redirect ) ) {
112 $login_url = add_query_arg( 'redirect_to', urlencode( $redirect ), $login_url );
113 }
114 if ( $force_reauth ) {
115 $login_url = add_query_arg( 'reauth', '1', $login_url );
116 }
117 return $login_url;
118 }
119
120 /**
121 * Customize lost password URL. Add the custom login slug.
122 *
123 * @since 5.8.0
124 */
125 public function customize_lost_password_url( $lostpassword_url ) {
126 $options = get_option( ASENHA_SLUG_U );
127 $custom_login_slug = $options['custom_login_slug'];
128 // return home_url( '/wp-login.php?manage&action=lostpassword' );
129 return $lostpassword_url . '&' . $custom_login_slug;
130 }
131
132 /**
133 * Customize registration URL. Add the custom login slug.
134 *
135 * @since 6.2.5
136 */
137 public function customize_register_url( $registration_url ) {
138 $options = get_option( ASENHA_SLUG_U );
139 $custom_login_slug = $options['custom_login_slug'];
140 // return home_url( '/wp-login.php?manage&action=lostpassword' );
141 return $registration_url . '&' . $custom_login_slug;
142 }
143
144 /**
145 * Redirect to /not_found when login URL does not contain the custom login slug
146 * This will redirect /wp-login.php and /wp-admin/ to /not_found/
147 *
148 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L121
149 * @since 1.4.0
150 */
151 public function redirect_on_default_login_urls() {
152 global $interim_login;
153 if ( defined( 'DOING_AJAX' ) && DOING_AJAX ) {
154 return;
155 }
156 if ( defined( 'DOING_CRON' ) && DOING_CRON ) {
157 return;
158 }
159 $options = get_option( ASENHA_SLUG_U );
160 $custom_login_slug = $options['custom_login_slug'];
161 // e.g. manage
162 $url_input = sanitize_text_field( $_SERVER['REQUEST_URI'] );
163 // e.g. /wp-admin/index.php?page=page-slug
164 $url_input_parts = explode( '/', $url_input );
165 $redirect_slug = 'not_found';
166 // When logging-in
167 if ( isset( $_POST['log'] ) && isset( $_POST['pwd'] ) || isset( $_POST['post_password'] ) ) {
168 // Do nothing. i.e. do not redirect to /not_found/ as this contains a login POST request
169 // upon successful login, redirection to logged-in view of /wp-admin/ happens.
170 // Without this condition, login attempt will redirect to /not_found/
171 } elseif ( is_user_logged_in() ) {
172 // Do nothing user is already logged-in
173 // Redirect to /wp-admin/ (Dashboard) when accessing /wp-login.php without any $_POST data
174 if ( isset( $url_input_parts[1] ) && 'wp-login.php' == $url_input_parts[1] && empty( $_POST ) ) {
175 wp_safe_redirect( admin_url(), 302 );
176 exit;
177 }
178 } elseif ( !is_user_logged_in() ) {
179 // Check if request URL ends in /admin/, /wp-admin/, /login/, /wp-login/ or /wp-login.php
180 if ( isset( $url_input_parts[1] ) && in_array( $url_input_parts[1], array(
181 'admin',
182 'wp-admin',
183 'login',
184 'wp-login',
185 'wp-login.php',
186 'login.php'
187 ) ) && (!isset( $url_input_parts[2] ) || isset( $url_input_parts[2] ) && empty( $url_input_parts[2] ) || isset( $url_input_parts[2] ) && false !== strpos( $url_input_parts[2], '.php' )) ) {
188 // Redirect to /not_found/ or custom redirect slug
189 wp_safe_redirect( home_url( $redirect_slug . '/' ), 302 );
190 exit;
191 } elseif ( false !== strpos( $url_input, 'wp-login.php' ) ) {
192 if ( isset( $_GET['action'] ) && ('logout' == $_GET['action'] || 'rp' == $_GET['action'] || 'resetpass' == $_GET['action']) || isset( $_GET['checkemail'] ) && ('confirm' == $_GET['checkemail'] || 'registered' == $_GET['checkemail']) || isset( $_GET['interim-login'] ) && '1' == $_GET['interim-login'] || 'success' == $interim_login || isset( $_GET['redirect_to'] ) && isset( $_GET['reauth'] ) && false !== strpos( $url_input, 'comment' ) ) {
193 // When we're logging out, inside the reset password flow, inside the registration flow or within the interim login flow
194 // e.g. https://www.example.com/wp-login.php?action=logout&_wpnonce=49bb818269
195 // e.g. https://www.example.com/wp-login.php?action=rp --> reset password
196 // e.g. https://www.example.com/wp-login.php?action=resetpass --> reset password
197 // e.g. https://www.example.com/wp-login.php?checkmail=confirm --> reset password
198 // e.g. https://www.example.com/wp-login.php?checkmail=registered --> register account
199 // e.g. https://www.example.com/wp-login.php?interim-login=1&wp_lang=en_US
200 // e.g. https://www.example.com/wp-admin/comment.php?action=approve&c=14#wpbody-content --> https://www.example.com/wp-login.php?redirect_to=https%3A%2F%2Fwww.example.com%2Fwp-admin%2Fcomment.php%3Faction%3Dapprove%26c%3D14&reauth=1#wpbody-content --> comment approve
201 // Do nothing.. proceed...
202 } elseif ( isset( $_GET['action'] ) && ('lostpassword' == $_GET['action'] || 'register' == $_GET['action']) ) {
203 // When resetting password or registering an account
204 if ( isset( $_POST['user_login'] ) ) {
205 // Sending the form to reset password or register an account...
206 // Do nothing.. proceed with password reset or account registration
207 } else {
208 // When landing on the password reset or registration form
209 // ...and custom login slug is not in the URL
210 if ( false === strpos( $url_input, $custom_login_slug ) ) {
211 // Redirect to /not_found/
212 wp_safe_redirect( home_url( $redirect_slug . '/' ), 302 );
213 exit;
214 }
215 // or, custom login slug is in the url
216 // e.g. https://www.example.com/wp-login.php?action=lostpassword&customloginslug
217 // e.g. https://www.example.com/wp-login.php?action=register&customloginslug
218 // Do nothing... allow reset password or registration
219 }
220 } elseif ( false === strpos( $url_input, $custom_login_slug ) ) {
221 // When landing on the login form /wp-login.php
222 // ...and custom login slug is not in the URL
223 // Redirect to /not_found/
224 wp_safe_redirect( home_url( $redirect_slug . '/' ), 302 );
225 exit;
226 } elseif ( false !== strpos( $url_input, $custom_login_slug ) ) {
227 // When landing on the login form /wp-login.php
228 // ...and custom login slug is in the URL
229 // e.g. https://www.example.com/wp-login.php?customloginslug&redirect=false
230 // Do nothing. Do not redirect. Allow login.
231 } else {
232 }
233 } else {
234 }
235 } else {
236 }
237 }
238
239 /**
240 * Redirect to custom login URL on failed login
241 *
242 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L148
243 * @since 1.4.0
244 */
245 public function redirect_to_custom_login_url_on_login_fail() {
246 global $asenha_limit_login;
247 $options = get_option( ASENHA_SLUG_U );
248 $custom_login_slug = $options['custom_login_slug'];
249 if ( isset( $asenha_limit_login ) && is_array( $asenha_limit_login ) && $asenha_limit_login['within_lockout_period'] ) {
250 // Do nothing. This prevents redirection loop.
251 } else {
252 $should_redirect = true;
253 if ( $should_redirect ) {
254 // Append 'failed_login=true' so we can output custom error message above the login form
255 wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false&failed_login=true' ) );
256 exit;
257 }
258 }
259 }
260
261 /**
262 * Add login error message on top of the login form.
263 * Only shown if there's a failed_login URL parameter, and Limit Login Attempts module is not enabled.
264 * If LLA module is enabled, the same custom login error message is handled there.
265 *
266 * @since 6.9.1
267 */
268 public function add_failed_login_message( $message ) {
269 global $asenha_limit_login;
270 if ( isset( $_REQUEST['failed_login'] ) && $_REQUEST['failed_login'] == 'true' ) {
271 if ( is_null( $asenha_limit_login ) ) {
272 $message = '<div id="login_error" class="notice notice-error"><b>' . __( 'Error:', 'admin-site-enhancements' ) . '</b> ' . __( 'Invalid username/email or incorrect password.', 'admin-site-enhancements' ) . '</div>';
273 }
274 }
275 return $message;
276 }
277
278 /**
279 * Redirect to custom login URL on successful logout
280 *
281 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L148
282 * @since 1.4.0
283 */
284 public function redirect_to_custom_login_url_on_logout_success() {
285 $options = get_option( ASENHA_SLUG_U );
286 $custom_login_slug = $options['custom_login_slug'];
287 // Redirect to the login URL with custom login slug in it
288 wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false' ) );
289 exit;
290 }
291
292 /**
293 * Customize logout URL by adding the custom login slug to it
294 *
295 * @since 7.0.2.3
296 */
297 public function customize_logout_url( $logout_url, $redirect ) {
298 $options = get_option( ASENHA_SLUG_U );
299 $custom_login_slug = $options['custom_login_slug'];
300 if ( !empty( $redirect ) ) {
301 $logout_url = add_query_arg( 'redirect_to', urlencode( $redirect ), $logout_url );
302 }
303 $logout_url .= '&' . $custom_login_slug;
304 return $logout_url;
305 }
306
307 }
308