PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / 5.8.2
Advanced Access Manager – Access Governance for WordPress v5.8.2
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / Application / Frontend / Authorization.php
advanced-access-manager / Application / Frontend Last commit date
phtml 7 years ago Authorization.php 7 years ago Filter.php 7 years ago Manager.php 7 years ago
Authorization.php
201 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * AAM frontend authorization
12 *
13 * @package AAM
14 * @author Vasyl Martyniuk <vasyl@vasyltech.com>
15 */
16 class AAM_Frontend_Authorization {
17
18 /**
19 * Instance of itself
20 *
21 * @var AAM_Frontend_Authorization
22 *
23 * @access private
24 */
25 private static $_instance = null;
26
27 /**
28 * Check post access
29 *
30 * Based on the provided post object, check if current user has access to it.
31 * This method run multiple checks at-once
32 *
33 * @param AAM_Core_Object_Post $post
34 *
35 * @return void
36 *
37 * @access public
38 */
39 public function chechReadAuth(AAM_Core_Object_Post $post) {
40 // pre post access hook
41 do_action('aam-pre-post-authorization-action', $post);
42
43 // Step #1. Check if access expired to the post
44 $this->checkExpiration($post);
45
46 // Step #2. Check if user has access to read the post
47 $this->checkReadAccess($post);
48
49 // Step #3. Check if counter exceeded max allowed views
50 $this->checkCounter($post);
51
52 // Step #4. Check if redirect is defined for the post
53 $this->checkRedirect($post);
54
55 // post post access hook
56 do_action('aam-post-post-authorization-action', $post);
57 }
58
59 /**
60 * Check ACCESS_EXPIRATION option
61 *
62 * If access is expired, override the access settings based on the
63 * post.access.expired ConfigPress settings (default frontend.read)
64 *
65 * @param AAM_Core_Object_Post $post
66 *
67 * @return void
68 *
69 * @access protected
70 */
71 protected function checkExpiration($post) {
72 $expire = $post->has('frontend.expire');
73
74 if ($expire) {
75 $date = strtotime($post->get('frontend.expire_datetime'));
76 if ($date <= time()) {
77 $actions = AAM_Core_Config::get(
78 'feature.frontend.postAccess.expired', 'frontend.read'
79 );
80
81 foreach(array_map('trim', explode(',', $actions)) as $action) {
82 $post->set($action, 1);
83 }
84 }
85 }
86 }
87
88 /**
89 * Check READ & READ_OTHERS options
90 *
91 * @param AAM_Core_Object_Post $post
92 *
93 * @return void
94 *
95 * @access protected
96 */
97 protected function checkReadAccess(AAM_Core_Object_Post $post) {
98 if (!$post->allowed('frontend.read')) {
99 $this->deny('post_read', 'frontend.read', $post->getPost());
100 }
101 }
102
103 /**
104 * Check ACCESS_COUNTER option
105 *
106 * @param AAM_Core_Object_Post $post
107 *
108 * @return void
109 *
110 * @access protected
111 */
112 protected function checkCounter(AAM_Core_Object_Post $post) {
113 $user = get_current_user_id();
114
115 //check counter only for authenticated users and if ACCESS COUNTER is set
116 if ($user && $post->has('frontend.access_counter')) {
117 $counter = intval(get_user_meta(
118 $user, 'aam-post-' . $post->ID . '-access-counter', true
119 ));
120
121 if ($counter >= $post->get('frontend.access_counter_limit')) {
122 $this->deny('post_read', 'frontend.access_counter', $post->getPost());
123 } else {
124 update_user_meta(
125 $user, 'aam-post-' . $post->ID . '-access-counter', ++$counter
126 );
127 }
128 }
129 }
130
131 /**
132 * Check REDIRECT option
133 *
134 * @param AAM_Core_Object_Post $post
135 *
136 * @return void
137 *
138 * @access protected
139 */
140 protected function checkRedirect(AAM_Core_Object_Post $post) {
141 if ($post->has(AAM_Core_Api_Area::get() . '.redirect')) {
142 $rule = explode('|', $post->get(AAM_Core_Api_Area::get() . '.location'));
143 $code = apply_filters('aam-post-redirect-http-code-filter', 307);
144
145 if (count($rule) === 1) { // TODO: legacy. Remove in Jul 2020
146 AAM_Core_API::redirect($rule[0]);
147 } elseif ($rule[0] === 'page') {
148 wp_safe_redirect(get_page_link($rule[1]), $code); exit;
149 } elseif ($rule[0] === 'url') {
150 wp_redirect($rule[1], $code); exit;
151 } elseif (($rule[0] === 'callback') && is_callable($rule[1])) {
152 call_user_func($rule[1], $post);
153 }
154 }
155 }
156
157 /**
158 * Deny access
159 *
160 * @param string $hook
161 * @param string $action
162 * @param WP_Post $post
163 *
164 * @return void
165 *
166 * @access protected
167 */
168 protected function deny($hook, $action, $post) {
169 AAM_Core_API::reject('frontend', array(
170 'hook' => $hook, 'action' => $action, 'post' => $post
171 ));
172 }
173
174 /**
175 * Alias for the bootstrap
176 *
177 * @return AAM_Frontend_Authorization
178 *
179 * @access public
180 * @static
181 */
182 public static function getInstance() {
183 return self::bootstrap();
184 }
185
186 /**
187 * Bootstrap authorization layer
188 *
189 * @return void
190 *
191 * @access public
192 */
193 public static function bootstrap() {
194 if (is_null(self::$_instance)) {
195 self::$_instance = new self;
196 }
197
198 return self::$_instance;
199 }
200
201 }