PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 7.4.2
Admin and Site Enhancements (ASE) v7.4.2
9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-change-login-url.php
admin-site-enhancements / classes Last commit date
class-activation.php 1 year ago class-admin-columns-manager.php 1 year ago class-admin-menu-organizer.php 1 year ago class-auto-publish-posts-with-missed-schedule.php 1 year ago class-avif-upload.php 1 year ago class-change-login-url.php 1 year ago class-cleanup-admin-bar.php 1 year ago class-code-snippets-manager.php 1 year ago class-common-methods.php 1 year ago class-content-duplication.php 1 year ago class-content-order.php 1 year ago class-custom-admin-footer-text.php 1 year ago class-custom-body-class.php 1 year ago class-custom-content-types.php 1 year ago class-custom-css.php 1 year ago class-custom-nav-menu-items-in-new-tab.php 1 year ago class-deactivation.php 1 year ago class-disable-comments.php 1 year ago class-disable-dashboard-widgets.php 1 year ago class-disable-feeds.php 1 year ago class-disable-gutenberg.php 1 year ago class-disable-rest-api.php 1 year ago class-disable-smaller-components.php 1 year ago class-disable-updates.php 1 year ago class-disable-xml-rpc.php 1 year ago class-display-system-summary.php 1 year ago class-email-address-obfuscator.php 1 year ago class-email-delivery.php 1 year ago class-enhance-list-tables.php 1 year ago class-external-permalinks.php 1 year ago class-heartbeat-control.php 1 year ago class-hide-admin-bar.php 1 year ago class-hide-admin-notices.php 1 year ago class-image-sizes-panel.php 1 year ago class-image-upload-control.php 1 year ago class-insert-head-body-footer-code.php 1 year ago class-last-login-column.php 1 year ago class-limit-login-attempts.php 1 year ago class-login-id-type.php 1 year ago class-login-logout-menu.php 1 year ago class-maintenance-mode.php 1 year ago class-manage-ads-appads-txt.php 1 year ago class-manage-robots-txt.php 1 year ago class-media-replacement.php 1 year ago class-multiple-user-roles.php 1 year ago class-obfuscate-author-slugs.php 1 year ago class-open-external-links-in-new-tab.php 1 year ago class-password-protection.php 1 year ago class-redirect-after-login.php 1 year ago class-redirect-after-logout.php 1 year ago class-redirect-fourofour.php 1 year ago class-revisions-control.php 1 year ago class-search-engines-visibility.php 1 year ago class-settings-fields-render.php 1 year ago class-settings-sanitization.php 1 year ago class-settings-sections-fields.php 1 year ago class-show-custom-taxonomy-filters.php 1 year ago class-site-identity-on-login-page.php 1 year ago class-svg-upload.php 1 year ago class-various-admin-ui-enhancements.php 1 year ago class-view-admin-as-role.php 1 year ago class-wider-admin-menu.php 1 year ago
class-change-login-url.php
335 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 /**
6 * Class for Change Login URL module
7 *
8 * @since 6.9.5
9 */
10 class Change_Login_URL {
11 /**
12 * Redirect to valid login URL when custom login slug is part of the request URL
13 *
14 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L134
15 * @since 1.4.0
16 */
17 public function redirect_on_custom_login_url() {
18 $options = get_option( ASENHA_SLUG_U );
19 $custom_login_slug = $options['custom_login_slug'];
20 $url_input = sanitize_text_field( $_SERVER['REQUEST_URI'] );
21 // Make sure $url_input ends with /
22 if ( false !== strpos( $url_input, $custom_login_slug ) ) {
23 if ( substr( $url_input, -1 ) != '/' ) {
24 $url_input = $url_input . '/';
25 }
26 }
27 // If URL contains the custom login slug, redirect to the dashboard
28 if ( false !== strpos( $url_input, '/' . $custom_login_slug . '/' ) ) {
29 if ( is_user_logged_in() ) {
30 if ( array_key_exists( 'redirect_after_login', $options ) && $options['redirect_after_login'] ) {
31 if ( array_key_exists( 'redirect_after_login_for', $options ) && !empty( $options['redirect_after_login_for'] ) ) {
32 $redirect_after_login_to_slug_raw = ( isset( $options['redirect_after_login_to_slug'] ) ? $options['redirect_after_login_to_slug'] : '' );
33 if ( !empty( $redirect_after_login_to_slug_raw ) ) {
34 $redirect_after_login_to_slug = trim( trim( $redirect_after_login_to_slug_raw ), '/' );
35 if ( false !== strpos( $redirect_after_login_to_slug, '.php' ) ) {
36 $slug_suffix = '';
37 } else {
38 $slug_suffix = '/';
39 }
40 $relative_path = $redirect_after_login_to_slug . $slug_suffix;
41 } else {
42 $relative_path = '';
43 }
44 $redirect_after_login_for = $options['redirect_after_login_for'];
45 if ( isset( $redirect_after_login_for ) && count( $redirect_after_login_for ) > 0 ) {
46 // Assemble single-dimensional array of roles for which custom URL redirection should happen
47 $roles_for_custom_redirect = array();
48 foreach ( $redirect_after_login_for as $role_slug => $custom_redirect ) {
49 if ( $custom_redirect ) {
50 $roles_for_custom_redirect[] = $role_slug;
51 }
52 }
53 // Does the user have roles data in array form?
54 $user = wp_get_current_user();
55 if ( isset( $user->roles ) && is_array( $user->roles ) ) {
56 $current_user_roles = $user->roles;
57 }
58 // Set custom redirect URL for roles set in the settings. Otherwise, leave redirect URL to the default, i.e. admin dashboard.
59 foreach ( $current_user_roles as $role ) {
60 if ( in_array( $role, $roles_for_custom_redirect ) ) {
61 if ( isset( $_GET['action'] ) ) {
62 // User Switching plugin
63 if ( 'switch_to_user' == $_GET['action'] || 'switch_to_olduser' == $_GET['action'] ) {
64 return;
65 // This ensures user switching proceeds
66 } else {
67 wp_safe_redirect( home_url( $relative_path ) );
68 exit;
69 }
70 } else {
71 // Redirect to dashboard
72 wp_safe_redirect( get_admin_url() );
73 exit;
74 }
75 } else {
76 if ( isset( $_GET['action'] ) ) {
77 // User Switching plugin
78 if ( 'switch_to_user' == $_GET['action'] || 'switch_to_olduser' == $_GET['action'] ) {
79 return;
80 // This ensures user switching proceeds
81 } else {
82 // Redirect to dashboard
83 wp_safe_redirect( get_admin_url() );
84 exit;
85 }
86 } else {
87 // Redirect to dashboard
88 wp_safe_redirect( get_admin_url() );
89 exit;
90 }
91 }
92 }
93 } else {
94 if ( isset( $_GET['action'] ) && ('switch_to_user' == $_GET['action'] || 'switch_to_olduser' == $_GET['action']) ) {
95 return;
96 // This ensures user switching proceeds
97 }
98 }
99 } else {
100 // Redirect to dashboard
101 wp_safe_redirect( get_admin_url() );
102 exit;
103 }
104 } else {
105 if ( isset( $_GET['action'] ) ) {
106 // User Switching plugin
107 if ( 'switch_to_user' == $_GET['action'] || 'switch_to_olduser' == $_GET['action'] ) {
108 return;
109 // This ensures user switching proceeds
110 } else {
111 // Redirect to dashboard
112 wp_safe_redirect( get_admin_url() );
113 exit;
114 }
115 } else {
116 // Redirect to dashboard
117 wp_safe_redirect( get_admin_url() );
118 exit;
119 }
120 }
121 } else {
122 // Redirect to the login URL with custom login slug in the query parameters
123 wp_safe_redirect( site_url( '/wp-login.php?' . $custom_login_slug . '&redirect=false' ) );
124 exit;
125 }
126 }
127 }
128
129 /**
130 * Customize login URL returned when calling wp_login_url(). Add the custom login slug.
131 *
132 * @since 5.8.0
133 */
134 public function customize_login_url( $login_url, $redirect, $force_reauth ) {
135 $options = get_option( ASENHA_SLUG_U );
136 $custom_login_slug = $options['custom_login_slug'];
137 $login_url = home_url( '/' . $custom_login_slug . '/' );
138 if ( !empty( $redirect ) ) {
139 $login_url = add_query_arg( 'redirect_to', urlencode( $redirect ), $login_url );
140 }
141 if ( $force_reauth ) {
142 $login_url = add_query_arg( 'reauth', '1', $login_url );
143 }
144 return $login_url;
145 }
146
147 /**
148 * Customize lost password URL. Add the custom login slug.
149 *
150 * @since 5.8.0
151 */
152 public function customize_lost_password_url( $lostpassword_url ) {
153 $options = get_option( ASENHA_SLUG_U );
154 $custom_login_slug = $options['custom_login_slug'];
155 // return home_url( '/wp-login.php?manage&action=lostpassword' );
156 return $lostpassword_url . '&' . $custom_login_slug;
157 }
158
159 /**
160 * Customize registration URL. Add the custom login slug.
161 *
162 * @since 6.2.5
163 */
164 public function customize_register_url( $registration_url ) {
165 $options = get_option( ASENHA_SLUG_U );
166 $custom_login_slug = $options['custom_login_slug'];
167 // return home_url( '/wp-login.php?manage&action=lostpassword' );
168 return $registration_url . '&' . $custom_login_slug;
169 }
170
171 /**
172 * Redirect to /not_found when login URL does not contain the custom login slug
173 * This will redirect /wp-login.php and /wp-admin/ to /not_found/
174 *
175 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L121
176 * @since 1.4.0
177 */
178 public function redirect_on_default_login_urls() {
179 global $interim_login;
180 if ( defined( 'DOING_AJAX' ) && DOING_AJAX ) {
181 return;
182 }
183 if ( defined( 'DOING_CRON' ) && DOING_CRON ) {
184 return;
185 }
186 $options = get_option( ASENHA_SLUG_U );
187 $custom_login_slug = $options['custom_login_slug'];
188 // e.g. manage
189 $url_input = sanitize_text_field( $_SERVER['REQUEST_URI'] );
190 // e.g. /wp-admin/index.php?page=page-slug
191 $url_input_parts = explode( '/', $url_input );
192 $redirect_slug = 'not_found';
193 // When logging-in
194 if ( isset( $_POST['log'] ) && isset( $_POST['pwd'] ) || isset( $_POST['post_password'] ) ) {
195 // Do nothing. i.e. do not redirect to /not_found/ as this contains a login POST request
196 // upon successful login, redirection to logged-in view of /wp-admin/ happens.
197 // Without this condition, login attempt will redirect to /not_found/
198 } elseif ( is_user_logged_in() ) {
199 // Do nothing user is already logged-in
200 // Redirect to /wp-admin/ (Dashboard) when accessing /wp-login.php without any $_POST data
201 if ( isset( $url_input_parts[1] ) && 'wp-login.php' == $url_input_parts[1] && empty( $_POST ) ) {
202 wp_safe_redirect( admin_url(), 302 );
203 exit;
204 }
205 } elseif ( !is_user_logged_in() ) {
206 // Check if request URL ends in /admin/, /wp-admin/, /login/, /wp-login/ or /wp-login.php
207 if ( isset( $url_input_parts[1] ) && in_array( $url_input_parts[1], array(
208 'admin',
209 'wp-admin',
210 'login',
211 'wp-login',
212 'wp-login.php',
213 'login.php'
214 ) ) && (!isset( $url_input_parts[2] ) || isset( $url_input_parts[2] ) && empty( $url_input_parts[2] ) || isset( $url_input_parts[2] ) && false !== strpos( $url_input_parts[2], '.php' )) ) {
215 // Redirect to /not_found/ or custom redirect slug
216 wp_safe_redirect( home_url( $redirect_slug . '/' ), 302 );
217 exit;
218 } elseif ( false !== strpos( $url_input, 'wp-login.php' ) ) {
219 if ( isset( $_GET['action'] ) && ('logout' == $_GET['action'] || 'rp' == $_GET['action'] || 'resetpass' == $_GET['action']) || isset( $_GET['checkemail'] ) && ('confirm' == $_GET['checkemail'] || 'registered' == $_GET['checkemail']) || isset( $_GET['interim-login'] ) && '1' == $_GET['interim-login'] || 'success' == $interim_login || isset( $_GET['redirect_to'] ) && isset( $_GET['reauth'] ) && false !== strpos( $url_input, 'comment' ) ) {
220 // When we're logging out, inside the reset password flow, inside the registration flow or within the interim login flow
221 // e.g. https://www.example.com/wp-login.php?action=logout&_wpnonce=49bb818269
222 // e.g. https://www.example.com/wp-login.php?action=rp --> reset password
223 // e.g. https://www.example.com/wp-login.php?action=resetpass --> reset password
224 // e.g. https://www.example.com/wp-login.php?checkmail=confirm --> reset password
225 // e.g. https://www.example.com/wp-login.php?checkmail=registered --> register account
226 // e.g. https://www.example.com/wp-login.php?interim-login=1&wp_lang=en_US
227 // e.g. https://www.example.com/wp-admin/comment.php?action=approve&c=14#wpbody-content --> https://www.example.com/wp-login.php?redirect_to=https%3A%2F%2Fwww.example.com%2Fwp-admin%2Fcomment.php%3Faction%3Dapprove%26c%3D14&reauth=1#wpbody-content --> comment approve
228 // Do nothing.. proceed...
229 } elseif ( isset( $_GET['action'] ) && ('lostpassword' == $_GET['action'] || 'register' == $_GET['action']) ) {
230 // When resetting password or registering an account
231 if ( isset( $_POST['user_login'] ) ) {
232 // Sending the form to reset password or register an account...
233 // Do nothing.. proceed with password reset or account registration
234 } else {
235 // When landing on the password reset or registration form
236 // ...and custom login slug is not in the URL
237 if ( false === strpos( $url_input, $custom_login_slug ) ) {
238 // Redirect to /not_found/
239 wp_safe_redirect( home_url( $redirect_slug . '/' ), 302 );
240 exit;
241 }
242 // or, custom login slug is in the url
243 // e.g. https://www.example.com/wp-login.php?action=lostpassword&customloginslug
244 // e.g. https://www.example.com/wp-login.php?action=register&customloginslug
245 // Do nothing... allow reset password or registration
246 }
247 } elseif ( false === strpos( $url_input, $custom_login_slug ) ) {
248 // When landing on the login form /wp-login.php
249 // ...and custom login slug is not in the URL
250 // Redirect to /not_found/
251 wp_safe_redirect( home_url( $redirect_slug . '/' ), 302 );
252 exit;
253 } elseif ( false !== strpos( $url_input, $custom_login_slug ) ) {
254 // When landing on the login form /wp-login.php
255 // ...and custom login slug is in the URL
256 // e.g. https://www.example.com/wp-login.php?customloginslug&redirect=false
257 // Do nothing. Do not redirect. Allow login.
258 } else {
259 }
260 } else {
261 }
262 } else {
263 }
264 }
265
266 /**
267 * Redirect to custom login URL on failed login
268 *
269 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L148
270 * @since 1.4.0
271 */
272 public function redirect_to_custom_login_url_on_login_fail() {
273 global $asenha_limit_login;
274 $options = get_option( ASENHA_SLUG_U );
275 $custom_login_slug = $options['custom_login_slug'];
276 if ( isset( $asenha_limit_login ) && is_array( $asenha_limit_login ) && $asenha_limit_login['within_lockout_period'] ) {
277 // Do nothing. This prevents redirection loop.
278 } else {
279 $should_redirect = true;
280 if ( $should_redirect ) {
281 // Append 'failed_login=true' so we can output custom error message above the login form
282 wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false&failed_login=true' ) );
283 exit;
284 }
285 }
286 }
287
288 /**
289 * Add login error message on top of the login form.
290 * Only shown if there's a failed_login URL parameter, and Limit Login Attempts module is not enabled.
291 * If LLA module is enabled, the same custom login error message is handled there.
292 *
293 * @since 6.9.1
294 */
295 public function add_failed_login_message( $message ) {
296 global $asenha_limit_login;
297 if ( isset( $_REQUEST['failed_login'] ) && $_REQUEST['failed_login'] == 'true' ) {
298 if ( is_null( $asenha_limit_login ) ) {
299 $message = '<div id="login_error" class="notice notice-error"><b>' . __( 'Error:', 'admin-site-enhancements' ) . '</b> ' . __( 'Invalid username/email or incorrect password.', 'admin-site-enhancements' ) . '</div>';
300 }
301 }
302 return $message;
303 }
304
305 /**
306 * Redirect to custom login URL on successful logout
307 *
308 * @link https://plugins.trac.wordpress.org/browser/admin-login-url-change/trunk/admin-login-url-change.php#L148
309 * @since 1.4.0
310 */
311 public function redirect_to_custom_login_url_on_logout_success() {
312 $options = get_option( ASENHA_SLUG_U );
313 $custom_login_slug = $options['custom_login_slug'];
314 // Redirect to the login URL with custom login slug in it
315 wp_safe_redirect( home_url( 'wp-login.php?' . $custom_login_slug . '&redirect=false' ) );
316 exit;
317 }
318
319 /**
320 * Customize logout URL by adding the custom login slug to it
321 *
322 * @since 7.0.2.3
323 */
324 public function customize_logout_url( $logout_url, $redirect ) {
325 $options = get_option( ASENHA_SLUG_U );
326 $custom_login_slug = $options['custom_login_slug'];
327 if ( !empty( $redirect ) ) {
328 $logout_url = add_query_arg( 'redirect_to', urlencode( $redirect ), $logout_url );
329 }
330 $logout_url .= '&' . $custom_login_slug;
331 return $logout_url;
332 }
333
334 }
335