PluginProbe ʕ •ᴥ•ʔ
Admin and Site Enhancements (ASE) / 7.6.2
Admin and Site Enhancements (ASE) v7.6.2
9.1.0 9.0.2 9.0.1 9.0.0 8.9.2 8.9.1 8.9.0 8.8.8 8.8.7 8.8.6 8.8.5 8.8.4 8.8.3 8.8.2 8.8.1 8.8.0 8.7.3 8.7.2 8.7.1 8.2.1 8.2.2 8.2.3 8.3.0 8.3.1 8.3.2 8.4.0 8.4.1 8.4.2 8.5.0 8.5.1 8.5.2 8.6.0 8.6.1 8.6.2 8.7.0 5.0.1 5.0.2 5.0.2.1 5.0.2.2 5.0.2.3 5.0.2.4 5.1.0 5.2.0 5.2.1 5.2.10 5.2.11 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.3.0 5.3.1 5.3.2 5.4.0 5.4.1 5.5.0 5.5.1 5.5.2 5.6.0 5.6.1 5.6.2 5.7.0 5.7.1 5.8.0 5.8.1 6.0.0 6.0.3 6.0.4 6.0.5 6.0.5.1 6.0.6 6.0.7 6.0.8.1 6.1.0 6.1.3 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.2.6 6.2.7 6.3.0 6.3.1 6.3.2 6.4.0 6.5.0 6.5.1 6.6.0 6.7.0 6.8.0 6.8.2 6.8.3 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13.1 6.9.13.2 6.9.2 6.9.3 6.9.4 6.9.5 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.2 7.0.2.1 7.0.2.2 7.0.2.3 7.0.3 7.1.0 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2.0 7.2.1 7.3.0 7.3.1 7.3.2 7.3.3 7.4.0 7.4.2 7.4.4 7.4.5 7.4.6 7.4.7 7.4.8 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.6.0 7.6.1 7.6.1.1 7.6.10 7.6.11 7.6.2 7.6.3 7.6.4 7.6.5 7.6.6 7.6.7 7.6.7.1 7.6.8 7.6.9 7.7.0 7.8.0 7.8.1 7.8.10 7.8.11 7.8.12 7.8.13 7.8.14 7.8.15 7.8.16 7.8.17 7.8.18 7.8.2 7.8.3 7.8.4 7.8.5 7.8.5.1 7.8.6 7.8.7 7.8.8 7.8.9 7.9.0 7.9.1 7.9.10 7.9.11 7.9.2 7.9.3 7.9.4 7.9.5 7.9.6 7.9.7 7.9.8 7.9.9 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.1.0 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 trunk 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 1.5.0 1.6.0 1.7.0 1.8.0 1.9.0 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.8.0 2.8.1 2.8.2 2.8.3 2.9.0 3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.1.0 3.2.0 3.3.0 3.4.0 3.5.0 3.6.1 3.7.0 3.8.0 3.9.0 3.9.1 3.9.2 4.0.0 4.0.1 4.1.0 4.2.0 4.2.1 4.2.2 4.3.0 4.3.1 4.4.0 4.5.0 4.6.0 4.7.0 4.7.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.1 4.8.2 4.8.3 4.9.0 4.9.1 4.9.2 4.9.3 5.0.0
admin-site-enhancements / classes / class-password-protection.php
admin-site-enhancements / classes Last commit date
class-activation.php 1 year ago class-admin-menu-organizer.php 1 year ago class-auto-publish-posts-with-missed-schedule.php 1 year ago class-avif-upload.php 1 year ago class-change-login-url.php 1 year ago class-cleanup-admin-bar.php 1 year ago class-common-methods.php 1 year ago class-content-duplication.php 1 year ago class-content-order.php 1 year ago class-custom-admin-footer-text.php 1 year ago class-custom-body-class.php 1 year ago class-custom-css.php 1 year ago class-custom-nav-menu-items-in-new-tab.php 1 year ago class-deactivation.php 1 year ago class-disable-comments.php 1 year ago class-disable-dashboard-widgets.php 1 year ago class-disable-feeds.php 1 year ago class-disable-gutenberg.php 1 year ago class-disable-rest-api.php 1 year ago class-disable-smaller-components.php 1 year ago class-disable-updates.php 1 year ago class-disable-xml-rpc.php 1 year ago class-display-system-summary.php 1 year ago class-email-address-obfuscator.php 1 year ago class-email-delivery.php 1 year ago class-enhance-list-tables.php 1 year ago class-external-permalinks.php 1 year ago class-heartbeat-control.php 1 year ago class-hide-admin-bar.php 1 year ago class-hide-admin-notices.php 1 year ago class-image-sizes-panel.php 1 year ago class-image-upload-control.php 1 year ago class-insert-head-body-footer-code.php 1 year ago class-last-login-column.php 1 year ago class-limit-login-attempts.php 1 year ago class-login-id-type.php 1 year ago class-login-logout-menu.php 1 year ago class-maintenance-mode.php 1 year ago class-manage-ads-appads-txt.php 1 year ago class-manage-robots-txt.php 1 year ago class-media-replacement.php 1 year ago class-multiple-user-roles.php 1 year ago class-obfuscate-author-slugs.php 1 year ago class-open-external-links-in-new-tab.php 1 year ago class-password-protection.php 1 year ago class-redirect-after-login.php 1 year ago class-redirect-after-logout.php 1 year ago class-redirect-fourofour.php 1 year ago class-registration-date-column.php 1 year ago class-revisions-control.php 1 year ago class-search-engines-visibility.php 1 year ago class-settings-fields-render.php 1 year ago class-settings-sanitization.php 1 year ago class-settings-sections-fields.php 1 year ago class-show-custom-taxonomy-filters.php 1 year ago class-site-identity-on-login-page.php 1 year ago class-svg-upload.php 1 year ago class-various-admin-ui-enhancements.php 1 year ago class-view-admin-as-role.php 1 year ago class-wider-admin-menu.php 1 year ago class-wp-config-transformer.php 1 year ago
class-password-protection.php
206 lines
1 <?php
2
3 namespace ASENHA\Classes;
4
5 use WP_Error;
6 /**
7 * Class for Password Protection module
8 *
9 * @since 6.9.5
10 */
11 class Password_Protection {
12 /**
13 * Show Password Protection admin bar status icon
14 *
15 * @since 4.1.0
16 */
17 public function show_password_protection_admin_bar_icon() {
18 add_action( 'wp_before_admin_bar_render', [$this, 'add_password_protection_admin_bar_item'] );
19 add_action( 'admin_head', [$this, 'add_password_protection_admin_bar_item_styles'] );
20 add_action( 'wp_head', [$this, 'add_password_protection_admin_bar_item_styles'] );
21 }
22
23 /**
24 * Add WP Admin Bar item
25 *
26 * @since 4.1.0
27 */
28 public function add_password_protection_admin_bar_item() {
29 global $wp_admin_bar;
30 if ( is_user_logged_in() ) {
31 if ( current_user_can( 'manage_options' ) ) {
32 $wp_admin_bar->add_menu( array(
33 'id' => 'password_protection',
34 'title' => '',
35 'href' => admin_url( 'tools.php?page=admin-site-enhancements#utilities' ),
36 'meta' => array(
37 'title' => __( 'Password protection is currently enabled for this site.', 'admin-site-enhancements' ),
38 ),
39 ) );
40 }
41 }
42 }
43
44 /**
45 * Add icon and CSS for admin bar item
46 *
47 * @since 4.1.0
48 */
49 public function add_password_protection_admin_bar_item_styles() {
50 if ( is_user_logged_in() ) {
51 if ( current_user_can( 'manage_options' ) ) {
52 ?>
53 <style>
54 #wp-admin-bar-password_protection {
55 background-color: #c32121 !important;
56 transition: .25s;
57 }
58 #wp-admin-bar-password_protection > .ab-item {
59 color: #fff !important;
60 }
61 #wp-admin-bar-password_protection > .ab-item:before {
62 content: "\f160";
63 top: 2px;
64 color: #fff !important;
65 margin-right: 0px;
66 }
67 #wp-admin-bar-password_protection:hover > .ab-item {
68 background-color: #af1d1d !important;
69 color: #fff;
70 }
71 </style>
72 <?php
73 }
74 }
75 }
76
77 /**
78 * Disable page caching
79 *
80 * @since 4.1.0
81 */
82 public function maybe_disable_page_caching() {
83 if ( !defined( 'DONOTCACHEPAGE' ) ) {
84 define( 'DONOTCACHEPAGE', true );
85 }
86 }
87
88 /**
89 * Maybe show login form
90 *
91 * @since 4.1.0
92 */
93 public function maybe_show_login_form() {
94 // When user is logged-in as in an administrator
95 if ( is_user_logged_in() ) {
96 if ( current_user_can( 'manage_options' ) ) {
97 return;
98 // Do not load login form or perform redirection to the login form
99 }
100 }
101 // When site visitor has entered correct password, get the auth cookie
102 $auth_cookie = ( isset( $_COOKIE['asenha_password_protection'] ) ? $_COOKIE['asenha_password_protection'] : '' );
103 // Compared against random string set in maybe_process_login()
104 if ( wp_check_password( 'MOeldTVhGnL18VfbDtXM7znSYXIUQn3z', $auth_cookie ) ) {
105 return;
106 // Do not load login form or perform redirection to the login form
107 }
108 if ( isset( $_REQUEST['protected-page'] ) && 'view' == $_REQUEST['protected-page'] ) {
109 // Show login form
110 $password_protected_login_page_template = ASENHA_PATH . 'includes/password-protected-login.php';
111 load_template( $password_protected_login_page_template );
112 exit;
113 } else {
114 // Redirect to login form
115 $current_url = (( is_ssl() ? 'https://' : 'http://' )) . sanitize_text_field( $_SERVER['HTTP_HOST'] ) . sanitize_text_field( $_SERVER['REQUEST_URI'] );
116 $args = array(
117 'protected-page' => 'view',
118 'source' => urlencode( $current_url ),
119 );
120 $pwd_protect_login_url = add_query_arg( $args, home_url( '/' ) );
121 nocache_headers();
122 wp_safe_redirect( $pwd_protect_login_url );
123 exit;
124 }
125 }
126
127 /**
128 * Maybe process login to access protected page content
129 *
130 * @since 4.1.0
131 */
132 public function maybe_process_login() {
133 global $password_protected_errors;
134 $password_protected_errors = new WP_Error();
135 if ( isset( $_REQUEST['protected_page_pwd'] ) ) {
136 $password_input = $_REQUEST['protected_page_pwd'];
137 $options = get_option( ASENHA_SLUG_U, array() );
138 $stored_password = $options['password_protection_password'];
139 if ( !empty( $password_input ) ) {
140 if ( $password_input == $stored_password ) {
141 // Password is correct
142 // Set auth cookie
143 // $expiration = time() + DAY_IN_SECONDS; // in 24 hours
144 $expiration = 0;
145 // by the end of browsing session
146 $hashed_cookie_value = wp_hash_password( 'MOeldTVhGnL18VfbDtXM7znSYXIUQn3z' );
147 // random string
148 setcookie(
149 'asenha_password_protection',
150 $hashed_cookie_value,
151 $expiration,
152 COOKIEPATH,
153 COOKIE_DOMAIN,
154 false,
155 true
156 );
157 // Redirect
158 $redirect_to_url = ( isset( $_REQUEST['source'] ) ? $_REQUEST['source'] : '' );
159 wp_safe_redirect( $redirect_to_url );
160 exit;
161 } else {
162 // Password is incorrect
163 // Add error message
164 $password_protected_errors->add( 'incorrect_password', 'Incorrect password.' );
165 }
166 } else {
167 // Password input is empty
168 // Add error message
169 $password_protected_errors->add( 'empty_password', 'Password can not be empty.' );
170 }
171 }
172 }
173
174 /**
175 * Add custom login error messages
176 *
177 * @since 4.1.0
178 */
179 public function add_login_error_messages() {
180 global $password_protected_errors;
181 if ( $password_protected_errors->get_error_code() ) {
182 $messages = '';
183 $errors = '';
184 // Extract the error message
185 foreach ( $password_protected_errors->get_error_codes() as $code ) {
186 $severity = $password_protected_errors->get_error_data( $code );
187 foreach ( $password_protected_errors->get_error_messages( $code ) as $error ) {
188 if ( 'message' == $severity ) {
189 $messages .= $error . '<br />';
190 } else {
191 $errors .= $error . '<br />';
192 }
193 }
194 }
195 // Output the error message
196 if ( !empty( $messages ) ) {
197 echo '<p class="message">' . wp_kses_post( $messages ) . '</p>';
198 }
199 if ( !empty( $errors ) ) {
200 echo '<div id="login_error">' . wp_kses_post( $errors ) . '</div>';
201 }
202 }
203 }
204
205 }
206