PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / 5.3.5
Advanced Access Manager – Access Governance for WordPress v5.3.5
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / Application / Frontend / Authorization.php
advanced-access-manager / Application / Frontend Last commit date
phtml 8 years ago Authorization.php 8 years ago Filter.php 8 years ago Manager.php 8 years ago
Authorization.php
203 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * AAM frontend authorization
12 *
13 * @package AAM
14 * @author Vasyl Martyniuk <vasyl@vasyltech.com>
15 */
16 class AAM_Frontend_Authorization {
17
18 /**
19 * Instance of itself
20 *
21 * @var AAM_Frontend_Authorization
22 *
23 * @access private
24 */
25 private static $_instance = null;
26
27 /**
28 * Check post access
29 *
30 * Based on the provided post object, check if current user has access to it.
31 * This method run multiple checks at-once
32 *
33 * @param AAM_Core_Object_Post $post
34 *
35 * @return void
36 *
37 * @access public
38 */
39 public function chechReadAuth(AAM_Core_Object_Post $post) {
40 // pre post access hook
41 do_action('aam-pre-post-authorization-action', $post);
42
43 // Step #1. Check if access expired to the post
44 $this->checkExpiration($post);
45
46 // Step #2. Check if user has access to read the post
47 $this->checkReadAccess($post);
48
49 // Step #3. Check if counter exceeded max allowed views
50 $this->checkCounter($post);
51
52 // Step #4. Check if redirect is defined for the post
53 $this->checkRedirect($post);
54
55 // post post access hook
56 do_action('aam-post-post-authorization-action', $post);
57 }
58
59 /**
60 * Check ACCESS_EXPIRATION option
61 *
62 * If access is expired, override the access settings based on the
63 * post.access.expired ConfigPress settings (default frontend.read)
64 *
65 * @param AAM_Core_Object_Post $post
66 *
67 * @return void
68 *
69 * @access protected
70 */
71 protected function checkExpiration($post) {
72 $expire = $post->has('frontend.expire');
73
74 if ($expire) {
75 $date = strtotime($post->get('frontend.expire_datetime'));
76 if ($date <= time()) {
77 $actions = AAM_Core_Config::get(
78 'feature.frontend.postAccess.expired', 'frontend.read'
79 );
80
81 foreach(array_map('trim', explode(',', $actions)) as $action) {
82 $post->set($action, 1);
83 }
84 }
85 }
86 }
87
88 /**
89 * Check READ & READ_OTHERS options
90 *
91 * @param AAM_Core_Object_Post $post
92 *
93 * @return void
94 *
95 * @access protected
96 */
97 protected function checkReadAccess(AAM_Core_Object_Post $post) {
98 $read = $post->has('frontend.read');
99 $others = $post->has('frontend.read_others');
100
101 if ($read || ($others && ($post->post_author != get_current_user_id()))) {
102 $this->deny('post_read', 'frontend.read', $post->getPost());
103 }
104 }
105
106 /**
107 * Check ACCESS_COUNTER option
108 *
109 * @param AAM_Core_Object_Post $post
110 *
111 * @return void
112 *
113 * @access protected
114 */
115 protected function checkCounter(AAM_Core_Object_Post $post) {
116 $user = get_current_user_id();
117
118 //check counter only for authenticated users and if ACCESS COUNTER is set
119 if ($user && $post->has('frontend.access_counter')) {
120 $counter = intval(get_user_meta(
121 $user, 'aam-post-' . $post->ID . '-access-counter', true
122 ));
123
124 if ($counter >= $post->get('frontend.access_counter_limit')) {
125 $this->deny('post_read', 'frontend.access_counter', $post->getPost());
126 } else {
127 update_user_meta(
128 $user, 'aam-post-' . $post->ID . '-access-counter', ++$counter
129 );
130 }
131 }
132 }
133
134 /**
135 * Check REDIRECT option
136 *
137 * @param AAM_Core_Object_Post $post
138 *
139 * @return void
140 *
141 * @access protected
142 */
143 protected function checkRedirect(AAM_Core_Object_Post $post) {
144 if ($post->has(AAM_Core_Api_Area::get() . '.redirect')) {
145 $rule = explode('|', $post->get(AAM_Core_Api_Area::get() . '.location'));
146
147 if (count($rule) == 1) { // TODO: legacy. Remove in Jul 2020
148 AAM_Core_API::redirect($rule[0]);
149 } elseif ($rule[0] == 'page') {
150 wp_safe_redirect(get_page_link($rule[1]), 307);
151 } elseif ($rule[0] == 'url') {
152 wp_redirect($rule[1], 307);
153 } elseif (($rule[0] == 'callback') && is_callable($rule[1])) {
154 call_user_func($rule[1], $post);
155 }
156 }
157 }
158
159 /**
160 * Deny access
161 *
162 * @param string $hook
163 * @param string $action
164 * @param WP_Post $post
165 *
166 * @return void
167 *
168 * @access protected
169 */
170 protected function deny($hook, $action, $post) {
171 AAM_Core_API::reject('frontend', array(
172 'hook' => $hook, 'action' => $action, 'post' => $post
173 ));
174 }
175
176 /**
177 * Alias for the bootstrap
178 *
179 * @return AAM_Frontend_Authorization
180 *
181 * @access public
182 * @static
183 */
184 public static function getInstance() {
185 return self::bootstrap();
186 }
187
188 /**
189 * Bootstrap authorization layer
190 *
191 * @return void
192 *
193 * @access public
194 */
195 public static function bootstrap() {
196 if (is_null(self::$_instance)) {
197 self::$_instance = new self;
198 }
199
200 return self::$_instance;
201 }
202
203 }