PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / 5.3.5
Advanced Access Manager – Access Governance for WordPress v5.3.5
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / Application / Core / JwtAuth.php
advanced-access-manager / Application / Core Last commit date
Api 8 years ago ConfigPress 8 years ago Object 8 years ago Subject 8 years ago API.php 8 years ago Cache.php 8 years ago Compatibility.php 8 years ago Config.php 8 years ago ConfigPress.php 8 years ago Console.php 8 years ago Exporter.php 8 years ago Gateway.php 8 years ago Importer.php 8 years ago JwtAuth.php 8 years ago Login.php 8 years ago Media.php 8 years ago Object.php 8 years ago Request.php 8 years ago Server.php 8 years ago Subject.php 8 years ago
JwtAuth.php
183 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * AAM JWT Authentication
12 *
13 * @package AAM
14 * @author Vasyl Martyniuk <vasyl@vasyltech.com>
15 */
16 class AAM_Core_JwtAuth {
17
18 /**
19 * Single instance of itself
20 *
21 * @var AAM_Core_JwtAuth
22 *
23 * @access protected
24 * @static
25 */
26 protected static $instance = null;
27
28 /**
29 * Constructor
30 *
31 * @return void
32 *
33 * @access protected
34 */
35 protected function __construct() {
36 //register API endpoint
37 add_action('rest_api_init', array($this, 'registerAPI'));
38
39 //register authentication hook
40 add_filter('determine_current_user', array($this, 'determineCurrentUser'), 999);
41 }
42
43 /**
44 * Register APIs
45 *
46 * @return void
47 *
48 * @access public
49 */
50 public function registerAPI() {
51 register_rest_route('aam/v1', '/authenticate', array(
52 'methods' => 'POST',
53 'callback' => array($this, 'authenticate'),
54 'args' => array(
55 'username' => array(
56 'description' => __('Valid username.', AAM_KEY),
57 'type' => 'string',
58 ),
59 'password' => array(
60 'description' => __('Valid password.', AAM_KEY),
61 'type' => 'string',
62 )
63 ),
64 ));
65 }
66
67 /**
68 * Authenticate user
69 *
70 * @param WP_REST_Request $request
71 *
72 * @return WP_REST_Response
73 *
74 * @access public
75 */
76 public function authenticate(WP_REST_Request $request) {
77 $username = $request->get_param('username');
78 $password = $request->get_param('password');
79
80 // try to authenticate user
81 $result = AAM_Core_Login::getInstance()->execute(array(
82 'user_login' => $username,
83 'user_password' => $password
84 ), false);
85
86 $response = new WP_REST_Response();
87
88 if ($result['status'] == 'success') { // generate token
89 $key = AAM_Core_Config::get('authentication.jwt.secret', SECURE_AUTH_KEY);
90 $expire = AAM_Core_Config::get('authentication.jwt.expires', 86400);
91
92 if ($key) {
93 $claims = array(
94 "iat" => time(),
95 'exp' => time() + $expire, // by default expires in 1 day
96 'userId' => $result['user']->ID,
97 );
98
99 $response->data = array(
100 'token' => Firebase\JWT\JWT::encode(
101 apply_filters('aam-jwt-claims-filter', $claims), $key
102 ),
103 'token_expires' => $claims['exp'],
104 'user' => $result['user']
105 );
106 $response->status = 200;
107 } else {
108 $response->status = 400;
109 $response->data = new WP_Error(
110 'rest_jwt_empty_secret_key',
111 __('JWT Authentication is enabled but secret key is not defined', AAM_KEY)
112 );
113 }
114 } else {
115 $response->data = $result['error'];
116 $response->status = 403;
117 }
118
119 return apply_filters('aam-jwt-response-filter', $response);
120 }
121
122 /**
123 *
124 * @param type $result
125 */
126 public function determineCurrentUser($result) {
127 // get Authentication header
128 $token = null;
129
130 if (isset($_SERVER['HTTP_AUTHENTICATION'])) {
131 $token = preg_replace('/^Bearer /', '', $_SERVER['HTTP_AUTHENTICATION']);
132 }
133
134 $token = apply_filters('aam-jwt-authentication-header-filter', $token);
135 $key = AAM_Core_Config::get('authentication.jwt.secret', SECURE_AUTH_KEY);
136
137 if ($token) {
138 try {
139 $claims = Firebase\JWT\JWT::decode(
140 $token, $key, array_keys(Firebase\JWT\JWT::$supported_algs)
141 );
142
143 if (isset($claims->userId)) {
144 $result = $claims->userId;
145 }
146 } catch (Exception $ex) {
147 echo $ex->getMessage();
148 // Do nothing
149 }
150 }
151
152 return $result;
153 }
154
155 /**
156 * Get single instance of itself
157 *
158 * @return AAM_Core_JwtAuth
159 *
160 * @access public
161 * @static
162 */
163 public static function getInstance() {
164 if (is_null(self::$instance)) {
165 self::$instance = new self;
166 }
167
168 return self::$instance;
169 }
170
171 /**
172 * Bootstrap AAM JWT Authentication feature
173 *
174 * @return AAM_Core_JwtAuth
175 *
176 * @access public
177 * @static
178 */
179 public static function bootstrap() {
180 return self::getInstance();
181 }
182
183 }