PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Restful / SecureLogin.php
advanced-access-manager / application / Restful Last commit date
AccessDeniedRedirect.php 1 year ago AdminToolbar.php 1 year ago ApiRoute.php 1 year ago BackendMenu.php 1 year ago BackwardCompatibility.php 1 year ago Capability.php 1 year ago Configs.php 5 months ago Content.php 1 year ago Identity.php 1 year ago Jwt.php 5 months ago LoginRedirect.php 1 year ago LogoutRedirect.php 1 year ago Metabox.php 1 year ago Mu.php 1 year ago NotFoundRedirect.php 1 year ago Policies.php 1 year ago Roles.php 1 year ago SecureLogin.php 1 year ago SecurityAudit.php 1 year ago ServiceTrait.php 1 year ago Settings.php 1 year ago Urls.php 1 year ago Users.php 1 year ago Widgets.php 1 year ago
SecureLogin.php
181 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * RESTful API for the Secure Login service
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Restful_SecureLogin
17 {
18
19 use AAM_Restful_ServiceTrait;
20
21 /**
22 * Necessary permissions to access endpoint
23 *
24 * @version 7.0.0
25 */
26 const PERMISSIONS = [
27 'aam_manager',
28 'aam_manage_admin_toolbar'
29 ];
30
31 /**
32 * Constructor
33 *
34 * @return void
35 * @access protected
36 *
37 * @version 7.0.0
38 */
39 protected function __construct()
40 {
41 // Register API endpoint
42 add_action('rest_api_init', function() {
43 // Create a redirect rule
44 $this->_register_route('/authenticate', [
45 'methods' => WP_REST_Server::CREATABLE,
46 'callback' => [ $this, 'authenticate' ],
47 'args' => [
48 'username' => [
49 'description' => 'Valid username',
50 'type' => 'string',
51 'required' => true
52 ],
53 'password' => [
54 'description' => 'Valid password',
55 'type' => 'string',
56 'required' => true
57 ],
58 'remember' => [
59 'description' => 'Prolong the user session.',
60 'type' => 'boolean',
61 'default' => false
62 ],
63 'return_auth_cookies' => [
64 'description' => 'Return auth cookies.',
65 'type' => 'boolean',
66 'default' => false
67 ],
68 'fields' => [
69 'description' => 'List of additional fields to return',
70 'type' => 'string',
71 'validate_callback' => function ($value) {
72 return $this->_validate_fields_input($value);
73 }
74 ]
75 ]
76 ], function() { return !is_user_logged_in(); }, false);
77 });
78 }
79
80 /**
81 * Authenticate user
82 *
83 * @param WP_REST_Request $request
84 *
85 * @return WP_REST_Response
86 * @access public
87 *
88 * @version 7.0.0
89 */
90 public function authenticate(WP_REST_Request $request)
91 {
92 try {
93 // No need to generate Auth cookies, unless explicitly stated so
94 if ($request->get_param('return_auth_cookies') !== true) {
95 add_filter('send_auth_cookies', '__return_false');
96 }
97
98 $user = wp_signon([
99 'user_login' => $request->get_param('username'),
100 'user_password' => $request->get_param('password'),
101 'remember' => $request->get_param('remember')
102 ]);
103
104 if (!is_wp_error($user)) {
105 $result = $this->_prepare_user_data($user, $request);
106 } else {
107 throw new DomainException($user->get_error_message());
108 }
109 } catch (Exception $e) {
110 $result = $this->_prepare_error_response($e);
111 }
112
113 return rest_ensure_response($result);
114 }
115
116 /**
117 * Prepare user data that is returned
118 *
119 * @param WP_User $user
120 * @param WP_REST_Request $request
121 *
122 * @return array
123 * @access protected
124 *
125 * @version 7.0.0
126 */
127 private function _prepare_user_data($user, $request)
128 {
129 $response = [];
130 $fields = $request->get_param('fields');
131 $props = array_unique(array_merge(
132 [ 'ID' ], is_string($fields) ? explode(',', $fields) : []
133 ));
134
135 foreach($props as $prop) {
136 if (isset($user->{$prop})) {
137 $response[$prop] = $user->{$prop};
138 }
139 }
140
141 return apply_filters(
142 'aam_rest_authenticated_user_data_filter', $response, $request, $user
143 );
144 }
145
146 /**
147 * Validate the input field "fields"
148 *
149 * @param string|null $value Input value
150 *
151 * @return bool|WP_Error
152 * @access private
153 *
154 * @version 7.0.0
155 */
156 private function _validate_fields_input($value)
157 {
158 $response = true;
159
160 if (is_string($value) && strlen($value) > 0) {
161 $invalid_fields = [];
162
163 foreach(explode(',', $value) as $field) {
164 if (strlen(sanitize_key($field)) !== strlen($field)) {
165 $invalid_fields[] = $field;
166 }
167 }
168
169 if (count($invalid_fields) > 0) {
170 $response = new WP_Error(
171 'rest_invalid_param',
172 sprintf('Invalid fields: %s', implode(', ', $invalid_fields)),
173 [ 'status' => 400 ]
174 );
175 }
176 }
177
178 return $response;
179 }
180
181 }