PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / 5.3
Advanced Access Manager – Access Governance for WordPress v5.3
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / Application / Frontend / Authorization.php
advanced-access-manager / Application / Frontend Last commit date
phtml 8 years ago Authorization.php 8 years ago Filter.php 8 years ago Manager.php 8 years ago
Authorization.php
193 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * AAM frontend authorization
12 *
13 * @package AAM
14 * @author Vasyl Martyniuk <vasyl@vasyltech.com>
15 */
16 class AAM_Frontend_Authorization {
17
18 /**
19 * Instance of itself
20 *
21 * @var AAM_Frontend_Authorization
22 *
23 * @access private
24 */
25 private static $_instance = null;
26
27 /**
28 * Check post access
29 *
30 * Based on the provided post object, check if current user has access to it.
31 * This method run multiple checks at-once
32 *
33 * @param AAM_Core_Object_Post $post
34 *
35 * @return void
36 *
37 * @access public
38 */
39 public function chechReadAuth(AAM_Core_Object_Post $post) {
40 // pre post access hook
41 do_action('aam-pre-post-authorization-action', $post);
42
43 // Step #1. Check if access expired to the post
44 $this->checkExpiration($post);
45
46 // Step #2. Check if user has access to read the post
47 $this->checkReadAccess($post);
48
49 // Step #3. Check if counter exceeded max allowed views
50 $this->checkCounter($post);
51
52 // Step #4. Check if redirect is defined for the post
53 $this->checkRedirect($post);
54
55 // post post access hook
56 do_action('aam-post-post-authorization-action', $post);
57 }
58
59 /**
60 * Check ACCESS_EXPIRATION option
61 *
62 * If access is expired, override the access settings based on the
63 * post.access.expired ConfigPress settings (default frontend.read)
64 *
65 * @param AAM_Core_Object_Post $post
66 *
67 * @return void
68 *
69 * @access protected
70 */
71 protected function checkExpiration($post) {
72 $expire = $post->has('frontend.expire');
73
74 if ($expire) {
75 $date = strtotime($post->get('frontend.expire_datetime'));
76 if ($date <= time()) {
77 $actions = AAM_Core_Config::get(
78 'post.access.expired', 'frontend.read'
79 );
80
81 foreach(array_map('trim', explode(',', $actions)) as $action) {
82 $post->set($action, 1);
83 }
84 }
85 }
86 }
87
88 /**
89 * Check READ & READ_OTHERS options
90 *
91 * @param AAM_Core_Object_Post $post
92 *
93 * @return void
94 *
95 * @access protected
96 */
97 protected function checkReadAccess(AAM_Core_Object_Post $post) {
98 $read = $post->has('frontend.read');
99 $others = $post->has('frontend.read_others');
100
101 if ($read || ($others && ($post->post_author != get_current_user_id()))) {
102 $this->deny('post_read', 'frontend.read', $post->getPost());
103 }
104 }
105
106 /**
107 * Check ACCESS_COUNTER option
108 *
109 * @param AAM_Core_Object_Post $post
110 *
111 * @return void
112 *
113 * @access protected
114 */
115 protected function checkCounter(AAM_Core_Object_Post $post) {
116 $user = get_current_user_id();
117
118 //check counter only for authenticated users and if ACCESS COUNTER is set
119 if ($user && $post->has('frontend.access_counter')) {
120 $counter = intval(get_user_meta(
121 $user, 'aam-post-' . $post->ID . '-access-counter', true
122 ));
123
124 if ($counter >= $post->get('frontend.access_counter_limit')) {
125 $this->deny('post_read', 'frontend.access_counter', $post->getPost());
126 } else {
127 update_user_meta(
128 $user, 'aam-post-' . $post->ID . '-access-counter', ++$counter
129 );
130 }
131 }
132 }
133
134 /**
135 * Check REDIRECT option
136 *
137 * @param AAM_Core_Object_Post $post
138 *
139 * @return void
140 *
141 * @access protected
142 */
143 protected function checkRedirect(AAM_Core_Object_Post $post) {
144 if ($post->has('frontend.redirect')) {
145 AAM_Core_API::redirect($post->get('frontend.location'));
146 }
147 }
148
149 /**
150 * Deny access
151 *
152 * @param string $hook
153 * @param string $action
154 * @param WP_Post $post
155 *
156 * @return void
157 *
158 * @access protected
159 */
160 protected function deny($hook, $action, $post) {
161 AAM_Core_API::reject('frontend', array(
162 'hook' => $hook, 'action' => $action, 'post' => $post
163 ));
164 }
165
166 /**
167 * Alias for the bootstrap
168 *
169 * @return AAM_Frontend_Authorization
170 *
171 * @access public
172 * @static
173 */
174 public static function getInstance() {
175 return self::bootstrap();
176 }
177
178 /**
179 * Bootstrap authorization layer
180 *
181 * @return void
182 *
183 * @access public
184 */
185 public static function bootstrap() {
186 if (is_null(self::$_instance)) {
187 self::$_instance = new self;
188 }
189
190 return self::$_instance;
191 }
192
193 }