PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Audit / RoleCapabilityNamingConventionCheck.php
advanced-access-manager / application / Audit Last commit date
AuditCheckTrait.php 1 year ago CoreUserRoleOptionIntegrityCheck.php 1 year ago EditableFileSystemCheck.php 7 months ago ElevatedCoreRoleCheck.php 7 months ago EmptyUnusedRoleCheck.php 7 months ago HighPrivilegeContentModeratorCheck.php 7 months ago HighPrivilegeOrElevatedUserCheck.php 7 months ago HighPrivilegeRoleCheck.php 7 months ago HighPrivilegeUserCountCheck.php 7 months ago RestfulAutoDiscoverEndpointCheck.php 7 months ago RoleCapabilityNamingConventionCheck.php 7 months ago RoleIntegrityCheck.php 7 months ago RoleTransparencyCheck.php 7 months ago XmlRpcEndpointCheck.php 7 months ago
RoleCapabilityNamingConventionCheck.php
140 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * Check if roles and capabilities follow proper naming convention
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Audit_RoleCapabilityNamingConventionCheck
17 {
18
19 use AAM_Audit_AuditCheckTrait;
20
21 /**
22 * Step ID
23 *
24 * @version 7.0.0
25 */
26 const ID = 'roles_caps_naming_convention';
27
28 /**
29 * Run the check
30 *
31 * @return array
32 *
33 * @access public
34 * @static
35 *
36 * @version 7.0.0
37 */
38 public static function run()
39 {
40 $issues = [];
41 $response = [ 'is_completed' => true ];
42
43 try {
44 array_push(
45 $issues,
46 ...self::_validate_naming_convention(self::_read_role_key_option())
47 );
48 } catch (Exception $e) {
49 array_push($issues, self::_format_issue(
50 'APPLICATION_ERROR',
51 [
52 'message' => $e->getMessage()
53 ],
54 'error'
55 ));
56 }
57
58 if (count($issues) > 0) {
59 $response['issues'] = $issues;
60 }
61
62 // Determine final status for the check
63 self::_determine_check_status($response);
64
65 return $response;
66 }
67
68 /**
69 * Get a collection of error messages for current step
70 *
71 * @return array
72 * @access private
73 * @static
74 *
75 * @version 7.0.0
76 */
77 private static function _get_message_templates()
78 {
79 return [
80 'INVALID_ROLE_SLUG' => __(
81 'Detected role %s (%s) with invalid slug',
82 'advanced-access-manager'
83 ),
84 'INVALID_CAP_SLUG' => __(
85 'Detected invalid capability %s for %s (%s) role',
86 'advanced-access-manager'
87 )
88 ];
89 }
90
91 /**
92 * Validate that all roles and capabilities are following proper naming
93 * convention
94 *
95 * @param array $db_roles
96 *
97 * @return array
98 *
99 * @access private
100 * @static
101 *
102 * @version 7.0.0
103 */
104 private static function _validate_naming_convention($db_roles)
105 {
106 $response = [];
107
108 foreach($db_roles as $role_id => $role) {
109 if (preg_match('/^[a-z\d_\-]+$/', $role_id) !== 1) {
110 array_push($response, self::_format_issue(
111 'INVALID_ROLE_SLUG',
112 [
113 'name' => translate_user_role(
114 !empty($role['name']) ? $role['name'] : $role_id
115 ),
116 'slug' => $role_id
117 ]
118 ));
119 }
120
121 foreach(array_keys($role['capabilities']) as $cap) {
122 if (preg_match('/^[a-z\d_\-]+$/', $cap) !== 1) {
123 array_push($response, self::_format_issue(
124 'INVALID_CAP_SLUG',
125 [
126 'slug' => $cap,
127 'role_name' => translate_user_role(
128 !empty($role['name']) ? $role['name'] : $role_id
129 ),
130 'role_slug' => $role_id
131 ]
132 ));
133 }
134 }
135 }
136
137 return $response;
138 }
139
140 }