PluginProbe
Authorizer / 2.6.12
Authorizer v2.6.12
3.15.3 3.15.2 3.15.1 3.15.0 3.14.3 3.14.4 3.14.2 3.14.1 2.8.1 2.8.2 2.8.3 2.8.4 2.8.5 2.8.6 2.8.7 2.8.8 2.9.0 2.9.1 2.9.10 2.9.11 2.9.12 2.9.13 2.9.2 2.9.3 2.9.6 All 126 releases
← All changes | authorizer.php +2121 -3983 2.8.62.6.12 View file →
@@ -1,31 +1,51 @@
1 1 <?php
2 -/**
3 - * Plugin Name: Authorizer
4 - * Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
5 - * Author: Paul Ryan <prar@hawaii.edu>
6 - * Plugin URI: https://github.com/uhm-coe/authorizer
7 - * Text Domain: authorizer
8 - * Domain Path: /languages
9 - * License: GPL2
10 - * Version: 2.8.6
11 - *
12 - * @package authorizer
13 - */
2 +/*
3 +Plugin Name: Authorizer
4 +Plugin URI: https://github.com/uhm-coe/authorizer
5 +Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
6 +Version: 2.6.12
7 +Author: Paul Ryan
8 +Author URI: http://www.linkedin.com/in/paulrryan/
9 +Text Domain: authorizer
10 +Domain Path: /languages
11 +License: GPL2
12 +*/
14 13
15 -/**
16 - * Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
17 - * Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
18 - * Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
19 - */
20 14
21 -/**
22 - * Add phpCAS library if it's not included.
23 - *
24 - * @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
25 - */
15 +/*
16 +Copyright 2014 Paul Ryan (email: prar@hawaii.edu)
17 +
18 +This program is free software; you can redistribute it and/or modify
19 +it under the terms of the GNU General Public License, version 2, as
20 +published by the Free Software Foundation.
21 +
22 +This program is distributed in the hope that it will be useful,
23 +but WITHOUT ANY WARRANTY; without even the implied warranty of
24 +MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
25 +GNU General Public License for more details.
26 +
27 +You should have received a copy of the GNU General Public License
28 +along with this program; if not, write to the Free Software
29 +Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
30 +*/
31 +
32 +
33 +/*
34 +Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
35 +Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
36 +Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
37 +*/
38 +
39 +
40 +define( 'MULTISITE_ADMIN', 'multisite_admin' );
41 +define( 'SINGLE_ADMIN', 'single_admin' );
42 +
43 +
44 +// Add phpCAS library if it's not included.
45 +// @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
26 46 if ( ! defined( 'PHPCAS_VERSION' ) ) {
27 - require_once dirname( __FILE__ ) . '/vendor/phpCAS-1.3.6/CAS.php';
47 + require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.4/CAS.php';
28 48 }
29 49
30 50
31 51 if ( ! class_exists( 'WP_Plugin_Authorizer' ) ) {
@@ -39,87 +59,18 @@
39 59 * @link http://hawaii.edu/coe/dcdc/wordpress/authorizer/doc/
40 60 */
41 61 class WP_Plugin_Authorizer {
42 62
43 - /**
44 - * Constants for determining our admin context (network or individual site).
45 - */
46 - const NETWORK_CONTEXT = 'multisite_admin';
47 - const SINGLE_CONTEXT = 'single_admin';
48 63
49 64 /**
50 - * Current site ID (Multisite).
51 - *
52 - * @var string
53 - */
54 - public $current_site_blog_id = 1;
55 -
56 - /**
57 - * HTML allowed when rendering translatable strings in the Authorizer UI.
58 - * This is passed to wp_kses() when sanitizing HMTL strings.
59 - *
60 - * @var array
61 - */
62 - private $allowed_html = array(
63 - 'a' => array(
64 - 'class' => array(),
65 - 'href' => array(),
66 - 'style' => array(),
67 - 'target' => array(),
68 - 'title' => array(),
69 - ),
70 - 'b' => array(),
71 - 'br' => array(),
72 - 'div' => array(
73 - 'class' => array(),
74 - ),
75 - 'em' => array(),
76 - 'hr' => array(),
77 - 'i' => array(),
78 - 'input' => array(
79 - 'aria-describedby' => array(),
80 - 'class' => array(),
81 - 'id' => array(),
82 - 'name' => array(),
83 - 'size' => array(),
84 - 'type' => array(),
85 - 'value' => array(),
86 - ),
87 - 'label' => array(
88 - 'class' => array(),
89 - 'for' => array(),
90 - ),
91 - 'p' => array(
92 - 'style' => array(),
93 - ),
94 - 'span' => array(
95 - 'aria-hidden' => array(),
96 - 'class' => array(),
97 - 'id' => array(),
98 - 'style' => array(),
99 - ),
100 - 'strong' => array(),
101 - );
102 -
103 - /**
104 65 * Constructor.
105 66 */
106 67 public function __construct() {
107 - // Save reference to current blog id in the network (support deprecated
108 - // constant BLOGID_CURRENT_SITE).
109 - if ( defined( 'BLOG_ID_CURRENT_SITE' ) ) {
110 - $this->current_site_blog_id = BLOG_ID_CURRENT_SITE;
111 - } elseif ( defined( 'BLOGID_CURRENT_SITE' ) ) { // deprecated.
112 - $this->current_site_blog_id = BLOGID_CURRENT_SITE;
113 - }
114 -
115 68 // Installation and uninstallation hooks.
116 69 register_activation_hook( __FILE__, array( $this, 'activate' ) );
117 70 register_deactivation_hook( __FILE__, array( $this, 'deactivate' ) );
118 71
119 - /**
120 - * Register filters.
121 - */
72 + // Register filters.
122 73
123 74 // Custom wp authentication routine using external service.
124 75 add_filter( 'authenticate', array( $this, 'custom_authenticate' ), 1, 3 );
125 76
@@ -125,9 +76,13 @@
125 76
126 77 // Custom logout action using external service.
127 78 add_action( 'wp_logout', array( $this, 'custom_logout' ) );
128 79
129 - // Create settings link on Plugins page.
80 + // Removing this bypasses Wordpress authentication (so if external auth fails,
81 + // no one can log in); with it enabled, it will run if external auth fails.
82 + //remove_filter('authenticate', 'wp_authenticate_username_password', 20, 3);
83 +
84 + // Create settings link on Plugins page
130 85 add_filter( 'plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'plugin_settings_link' ) );
131 86 add_filter( 'network_admin_plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'network_admin_plugin_settings_link' ) );
132 87
133 88 // Modify login page with a custom password url (if option is set).
@@ -138,11 +93,9 @@
138 93 if ( $error && strlen( $error ) > 0 ) {
139 94 add_filter( 'login_errors', array( $this, 'show_advanced_login_error' ) );
140 95 }
141 96
142 - /**
143 - * Register actions.
144 - */
97 + // Register actions.
145 98
146 99 // Enable localization. Translation files stored in /languages.
147 100 add_action( 'plugins_loaded', array( $this, 'load_textdomain' ) );
148 101
@@ -154,20 +107,18 @@
154 107
155 108 // Add users who successfully login to the approved list.
156 109 add_action( 'wp_login', array( $this, 'ensure_wordpress_user_in_approved_list_on_login' ), 10, 2 );
157 110
158 - // Create menu item in Settings.
111 + // Create menu item in Settings
159 112 add_action( 'admin_menu', array( $this, 'add_plugin_page' ) );
160 113
161 - // Create options page.
114 + // Create options page
162 115 add_action( 'admin_init', array( $this, 'page_init' ) );
163 116
164 117 // Update user role in approved list if it's changed in the WordPress edit user page.
165 - add_action( 'user_profile_update_errors', array( $this, 'edit_user_profile_update_role' ), 10, 3 );
118 + add_action( 'edit_user_profile_update', array( $this, 'edit_user_profile_update_role' ) );
119 + add_action( 'personal_options_update', array( $this, 'edit_user_profile_update_role' ) );
166 120
167 - // Update user email in approved list if it's changed in the WordPress edit user page.
168 - add_filter( 'send_email_change_email', array( $this, 'edit_user_profile_update_email' ), 10, 3 );
169 -
170 121 // Enqueue javascript and css on the plugin's options page, the
171 122 // dashboard (for the widget), and the network admin.
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
@@ -172,16 +123,13 @@
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
174 125 add_action( 'load-toplevel_page_authorizer', array( $this, 'load_options_page' ) );
175 126
176 - // Add custom css and js to wp-login.php.
127 + // Add custom css and js to wp-login.php
177 128 add_action( 'login_enqueue_scripts', array( $this, 'login_enqueue_scripts_and_styles' ) );
178 129 add_action( 'login_footer', array( $this, 'load_login_footer_js' ) );
179 130
180 - // Create google nonce cookie when loading wp-login.php if Google is enabled.
181 - add_action( 'login_init', array( $this, 'login_init__maybe_set_google_nonce_cookie' ) );
182 -
183 - // Modify login page with external auth links (if enabled; e.g., google or cas).
131 + // Modify login page with external auth links (if enabled; e.g., google or cas)
184 132 add_action( 'login_form', array( $this, 'login_form_add_external_service_links' ) );
185 133
186 134 // Redirect to CAS login when visiting login page (only if option is
187 135 // enabled, CAS is the only service, and WordPress logins are hidden).
@@ -190,28 +138,25 @@
190 138 // output is started (so the redirect header doesn't complain about data
191 139 // already being sent).
192 140 add_filter( 'wp_login_errors', array( $this, 'wp_login_errors__maybe_redirect_to_cas' ), 10, 2 );
193 141
194 - // Verify current user has access to page they are visiting.
142 + // Verify current user has access to page they are visiting
195 143 add_action( 'parse_request', array( $this, 'restrict_access' ), 9 );
196 144 add_action( 'init', array( $this, 'init__maybe_add_network_approved_user' ) );
197 145
198 - // AJAX: Save options from dashboard widget.
146 + // ajax save options from dashboard widget
199 147 add_action( 'wp_ajax_update_auth_user', array( $this, 'ajax_update_auth_user' ) );
200 148
201 - // AJAX: Save options from multisite options page.
149 + // ajax save options from multisite options page
202 150 add_action( 'wp_ajax_save_auth_multisite_settings', array( $this, 'ajax_save_auth_multisite_settings' ) );
203 151
204 - // AJAX: Save usermeta from options page.
152 + // ajax save usermeta from options page
205 153 add_action( 'wp_ajax_update_auth_usermeta', array( $this, 'ajax_update_auth_usermeta' ) );
206 154
207 - // AJAX: Verify google login.
155 + // ajax verify google login
208 156 add_action( 'wp_ajax_process_google_login', array( $this, 'ajax_process_google_login' ) );
209 157 add_action( 'wp_ajax_nopriv_process_google_login', array( $this, 'ajax_process_google_login' ) );
210 158
211 - // AJAX: Refresh approved user list.
212 - add_action( 'wp_ajax_refresh_approved_user_list', array( $this, 'ajax_refresh_approved_user_list' ) );
213 -
214 159 // Add dashboard widget so instructors can add/edit users with access.
215 160 // Hint: For Multisite Network Admin Dashboard use wp_network_dashboard_setup instead of wp_dashboard_setup.
216 161 add_action( 'wp_dashboard_setup', array( $this, 'add_dashboard_widgets' ) );
217 162
@@ -226,12 +171,17 @@
226 171 add_action( 'wp_enqueue_scripts', array( $this, 'auth_public_scripts' ), 20 );
227 172
228 173 // Multisite-specific actions.
229 174 if ( is_multisite() ) {
230 - // Add network admin options page (global settings for all sites).
175 + // Add network admin options page (global settings for all sites)
231 176 add_action( 'network_admin_menu', array( $this, 'network_admin_menu' ) );
232 177 }
233 178
179 + // Create login cookie (used by google login)
180 + if ( ! isset( $_COOKIE['login_unique'] ) ) {
181 + setcookie( 'login_unique', $this->get_cookie_value(), time()+1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
182 + }
183 +
234 184 // Remove user from authorizer lists when that user is deleted in WordPress.
235 185 add_action( 'delete_user', array( $this, 'remove_user_from_authorizer_when_deleted' ) );
236 186 if ( is_multisite() ) {
237 187 // Remove multisite user from authorizer lists when that user is deleted from Network Users.
@@ -264,20 +214,16 @@
264 214 * Will also activate the plugin for all sites/blogs if this is a "Network enable."
265 215 *
266 216 * @return void
267 217 */
268 - public function activate( $network_wide ) {
218 + public function activate() {
269 219 global $wpdb;
270 220
271 - // If we're in a multisite environment, run the plugin activation for each
272 - // site when network enabling.
273 - // Note: wp-cli does not use nonces, so we skip the nonce check here to
274 - // allow the "wp plugin activate authorizer" command.
275 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
276 - if ( is_multisite() && $network_wide ) {
221 + // If we're in a multisite environment, run the plugin activation for each site when network enabling
222 + if ( is_multisite() && isset( $_GET['networkwide'] ) && $_GET['networkwide'] == 1 ) {
277 223
278 224 // Add super admins to the multisite approved list.
279 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
225 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() );
280 226 $should_update_auth_multisite_settings_access_users_approved = false;
281 227 foreach ( get_super_admins() as $super_admin ) {
282 228 $user = get_user_by( 'login', $super_admin );
283 229 // Add to approved list if not there.
@@ -282,10 +228,10 @@
282 228 $user = get_user_by( 'login', $super_admin );
283 229 // Add to approved list if not there.
284 230 if ( ! $this->in_multi_array( $user->user_email, $auth_multisite_settings_access_users_approved ) ) {
285 231 $approved_user = array(
286 - 'email' => $this->lowercase( $user->user_email ),
287 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
232 + 'email' => $user->user_email,
233 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
288 234 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
289 235 'local_user' => true,
290 236 );
291 237 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
@@ -292,14 +238,13 @@
292 238 $should_update_auth_multisite_settings_access_users_approved = true;
293 239 }
294 240 }
295 241 if ( $should_update_auth_multisite_settings_access_users_approved ) {
296 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
242 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
297 243 }
298 244
299 245 // Run plugin activation on each site in the network.
300 246 $current_blog_id = $wpdb->blogid;
301 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
302 247 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
303 248 foreach ( $sites as $site ) {
304 249 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
305 250 switch_to_blog( $blog_id );
@@ -328,13 +273,13 @@
328 273 * @return void
329 274 */
330 275 private function add_wp_users_to_approved_list() {
331 276 // Add current WordPress users to the approved list.
332 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
333 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
334 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
335 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
336 - $updated = false;
277 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
278 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
279 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
280 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
281 + $updated = false;
337 282 foreach ( get_users() as $user ) {
338 283 // Skip if user is in blocked list.
339 284 if ( $this->in_multi_array( $user->user_email, $auth_settings_access_users_blocked ) ) {
340 285 continue;
@@ -340,10 +285,10 @@
340 285 continue;
341 286 }
342 287 // Remove from pending list if there.
343 288 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
344 - if ( 0 === strcasecmp( $pending_user['email'], $user->user_email ) ) {
345 - unset( $auth_settings_access_users_pending[ $key ] );
289 + if ( $pending_user['email'] == $user->user_email ) {
290 + unset( $auth_settings_access_users_pending[$key] );
346 291 $updated = true;
347 292 }
348 293 }
349 294 // Skip if user is in multisite approved list.
@@ -352,10 +297,10 @@
352 297 }
353 298 // Add to approved list if not there.
354 299 if ( ! $this->in_multi_array( $user->user_email, $auth_settings_access_users_approved ) ) {
355 300 $approved_user = array(
356 - 'email' => $this->lowercase( $user->user_email ),
357 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
301 + 'email' => $user->user_email,
302 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
358 303 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
359 304 'local_user' => true,
360 305 );
361 306 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -390,14 +335,13 @@
390 335
391 336 /**
392 337 * Authenticate against an external service.
393 338 *
394 - * Filter: authenticate
395 - *
396 - * @param WP_User $user user to authenticate.
339 + * @param WP_User $user user to authenticate
397 340 * @param string $username optional username to authenticate.
398 341 * @param string $password optional password to authenticate.
399 - * @return WP_User|WP_Error WP_User on success, WP_Error on failure.
342 + *
343 + * @return WP_User or WP_Error
400 344 */
401 345 public function custom_authenticate( $user, $username, $password ) {
402 346 // Pass through if already authenticated.
403 347 if ( is_a( $user, 'WP_User' ) ) {
@@ -405,20 +349,20 @@
405 349 } else {
406 350 $user = null;
407 351 }
408 352
409 - // If username and password are blank, this isn't a log in attempt.
353 + // If username and password are blank, this isn't a log in attempt
410 354 $is_login_attempt = strlen( $username ) > 0 && strlen( $password ) > 0;
411 355
412 356 // Check to make sure that $username is not locked out due to too
413 357 // many invalid login attempts. If it is, tell the user how much
414 358 // time remains until they can try again.
415 - $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
359 + $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
416 360 $unauthenticated_user_is_blocked = false;
417 - if ( $is_login_attempt && false !== $unauthenticated_user ) {
361 + if ( $is_login_attempt && $unauthenticated_user !== false ) {
418 362 $last_attempt = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
419 363 $num_attempts = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
420 - // Also check the auth_blocked user_meta flag (users in blocked list will get this flag).
364 + // Also check the auth_blocked user_meta flag (users in blocked list will get this flag)
421 365 $unauthenticated_user_is_blocked = get_user_meta( $unauthenticated_user->ID, 'auth_blocked', true ) === 'yes';
422 366 } else {
423 367 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
424 368 $num_attempts = get_option( 'auth_settings_advanced_lockouts_failed_attempts' );
@@ -432,9 +376,9 @@
432 376 return new WP_Error( 'empty_password', __( '<strong>ERROR</strong>: Incorrect username or password.', 'authorizer' ) );
433 377 }
434 378
435 379 // Grab plugin settings.
436 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
380 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
437 381
438 382 // Make sure $last_attempt (time) and $num_attempts are positive integers.
439 383 // Note: this addresses resetting them if either is unset from above.
440 384 $last_attempt = abs( intval( $last_attempt ) );
@@ -440,17 +384,17 @@
440 384 $last_attempt = abs( intval( $last_attempt ) );
441 385 $num_attempts = abs( intval( $num_attempts ) );
442 386
443 387 // Create semantic lockout variables.
444 - $lockouts = $auth_settings['advanced_lockouts'];
445 - $time_since_last_fail = time() - $last_attempt;
446 - $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds.
447 - $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
448 - $num_attempts_short_lockout = $lockouts['attempts_1'];
449 - $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
388 + $lockouts = $auth_settings['advanced_lockouts'];
389 + $time_since_last_fail = time() - $last_attempt;
390 + $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds
391 + $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
392 + $num_attempts_short_lockout = $lockouts['attempts_1'];
393 + $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
450 394 $seconds_remaining_short_lockout = $lockouts['duration_1'] * 60 - $time_since_last_fail;
451 395
452 - // Check if we need to institute a lockout delay.
396 + // Check if we need to institute a lockout delay
453 397 if ( $is_login_attempt && $time_since_last_fail > $reset_duration ) {
454 398 // Enough time has passed since the last invalid attempt and
455 399 // now that we can reset the failed attempt count, and let this
456 400 // login attempt go through.
@@ -463,9 +407,8 @@
463 407 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
464 408 return new WP_Error(
465 409 'empty_password',
466 410 sprintf(
467 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
468 411 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
469 412 $username,
470 413 $seconds_remaining_long_lockout,
471 414 $this->seconds_as_sentence( $seconds_remaining_long_lockout ),
@@ -480,9 +423,8 @@
480 423 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
481 424 return new WP_Error(
482 425 'empty_password',
483 426 sprintf(
484 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
485 427 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
486 428 $username,
487 429 $seconds_remaining_short_lockout,
488 430 $this->seconds_as_sentence( $seconds_remaining_short_lockout ),
@@ -492,16 +434,16 @@
492 434 }
493 435
494 436 // Start external authentication.
495 437 $externally_authenticated_emails = array();
496 - $authenticated_by = '';
497 - $result = null;
438 + $authenticated_by = '';
439 + $result = null;
498 440
499 441 // Try Google authentication if it's enabled and we don't have a
500 442 // successful login yet.
501 443 if (
502 - '1' === $auth_settings['google'] &&
503 - 0 === count( $externally_authenticated_emails ) &&
444 + $auth_settings['google'] === '1' &&
445 + count( $externally_authenticated_emails ) === 0 &&
504 446 ! is_wp_error( $result )
505 447 ) {
506 448 $result = $this->custom_authenticate_google( $auth_settings );
507 449 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -516,10 +458,10 @@
516 458
517 459 // Try CAS authentication if it's enabled and we don't have a
518 460 // successful login yet.
519 461 if (
520 - '1' === $auth_settings['cas'] &&
521 - 0 === count( $externally_authenticated_emails ) &&
462 + $auth_settings['cas'] === '1' &&
463 + count( $externally_authenticated_emails ) === 0 &&
522 464 ! is_wp_error( $result )
523 465 ) {
524 466 $result = $this->custom_authenticate_cas( $auth_settings );
525 467 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -534,10 +476,10 @@
534 476
535 477 // Try LDAP authentication if it's enabled and we don't have an
536 478 // authenticated user yet.
537 479 if (
538 - '1' === $auth_settings['ldap'] &&
539 - 0 === count( $externally_authenticated_emails ) &&
480 + $auth_settings['ldap'] === '1' &&
481 + count( $externally_authenticated_emails ) === 0 &&
540 482 ! is_wp_error( $result )
541 483 ) {
542 484 $result = $this->custom_authenticate_ldap( $auth_settings, $username, $password );
543 485 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -558,37 +500,35 @@
558 500
559 501 // Remove duplicate and blank emails, if any.
560 502 $externally_authenticated_emails = array_filter( array_unique( $externally_authenticated_emails ) );
561 503
562 - /**
563 - * If we've made it this far, we should have an externally
564 - * authenticated user. The following should be set:
565 - * $externally_authenticated_emails
566 - * $authenticated_by
567 - */
504 + // If we've made it this far, we should have an externally
505 + // authenticated user. The following should be set:
506 + // $externally_authenticated_emails
507 + // $authenticated_by
568 508
569 509 // Get the external user's WordPress account by email address.
570 510 foreach ( $externally_authenticated_emails as $externally_authenticated_email ) {
571 - $user = get_user_by( 'email', $this->lowercase( $externally_authenticated_email ) );
511 + $user = get_user_by( 'email', $externally_authenticated_email );
572 512
573 513 // If we've already found a WordPress user associated with one
574 514 // of the supplied email addresses, don't keep examining other
575 515 // email addresses associated with the externally authenticated user.
576 - if ( false !== $user ) {
516 + if ( $user !== FALSE ) {
577 517 break;
578 518 }
579 519 }
580 520
581 521 // Check this external user's access against the access lists
582 - // (pending, approved, blocked).
522 + // (pending, approved, blocked)
583 523 $result = $this->check_user_access( $user, $externally_authenticated_emails, $result );
584 524
585 525 // Fail with message if there was an error creating/adding the user.
586 - if ( is_wp_error( $result ) || 0 === $result ) {
526 + if ( is_wp_error( $result ) || $result === 0 ) {
587 527 return $result;
588 528 }
589 529
590 - // If we have a valid user from check_user_access(), log that user in.
530 + // If we created a new user in check_user_access(), log that user in.
591 531 if ( get_class( $result ) === 'WP_User' ) {
592 532 $user = $result;
593 533 }
594 534
@@ -605,29 +545,27 @@
605 545 /**
606 546 * This function will fail with a wp_die() message to the user if they
607 547 * don't have access.
608 548 *
609 - * @param WP_User $user User to check.
610 - * @param array $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account).
611 - * @param array $user_data Array of keys for email, username, first_name, last_name,
612 - * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
613 - * @return WP_Error|void|WP_User
614 - * WP_Error if there was an error on user creation / adding user to blog.
615 - * wp_die() if user does not have access.
616 - * WP_User if user has access.
549 + * @param WP_User $user User to check
550 + * @param [type] $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account)
551 + * @param [type] $user_data Array of keys for email, username, first_name, last_name,
552 + * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
553 + * @return WP_Error if there was an error on user creation / adding user to blog
554 + * wp_die() if user does not have access
555 + * null if user has access (success)
556 + * WP_User if user has access and a new account was created for them
617 557 */
618 558 private function check_user_access( $user, $user_emails, $user_data = array() ) {
619 559 // Grab plugin settings.
620 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
621 - $auth_settings_access_users_pending = $this->sanitize_user_list(
622 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
560 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
561 + $auth_settings_access_users_pending = $this->sanitize_user_list(
562 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
623 563 );
624 - $auth_settings_access_users_approved_single = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
625 - $auth_settings_access_users_approved_multi = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
626 - $auth_settings_access_users_approved = $this->sanitize_user_list(
564 + $auth_settings_access_users_approved = $this->sanitize_user_list(
627 565 array_merge(
628 - $auth_settings_access_users_approved_single,
629 - $auth_settings_access_users_approved_multi
566 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
567 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
630 568 )
631 569 );
632 570
633 571 /**
@@ -636,9 +574,9 @@
636 574 *
637 575 * @param bool $allow_login Whether to block the currently logging in user.
638 576 * @param array $user_data User data returned from external service.
639 577 */
640 - $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
578 + $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
641 579 $blocked_by_filter = ! $allow_login; // Use this for better readability.
642 580
643 581 // Check our externally authenticated user against the block list.
644 582 // If any of their email addresses are blocked, set the relevant user
@@ -648,16 +586,14 @@
648 586
649 587 // Add user to blocked list if it was blocked via the filter.
650 588 if ( $blocked_by_filter && ! $this->is_email_in_list( $user_email, 'blocked' ) ) {
651 589 $auth_settings_access_users_blocked = $this->sanitize_user_list(
652 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
590 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
653 591 );
654 - array_push(
655 - $auth_settings_access_users_blocked, array(
656 - 'email' => $this->lowercase( $user_email ),
657 - 'date_added' => date( 'M Y' ),
658 - )
659 - );
592 + array_push( $auth_settings_access_users_blocked, array(
593 + 'email' => $user_email,
594 + 'date_added' => date( 'M Y' ),
595 + ));
660 596 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
661 597 }
662 598
663 599 // If the blocked external user has a WordPress account, mark it as
@@ -666,11 +602,10 @@
666 602 update_user_meta( $user->ID, 'auth_blocked', 'yes' );
667 603 }
668 604
669 605 // Notify user about blocked status and return without authenticating them.
670 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
671 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
672 - $page_title = sprintf(
606 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
607 + $page_title = sprintf(
673 608 /* TRANSLATORS: %s: Name of blog */
674 609 __( '%s - Access Restricted', 'authorizer' ),
675 610 get_bloginfo( 'name' )
676 611 );
@@ -681,14 +616,13 @@
681 616 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
682 617 __( 'Back', 'authorizer' ) .
683 618 '</a></p>';
684 619 update_option( 'auth_settings_advanced_login_error', $error_message );
685 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
620 + wp_die( $error_message, $page_title );
686 621 }
687 622 }
688 623
689 - // Get the default role for this user (or their current role, if they
690 - // already have an account).
624 + // Get the default role for this new user.
691 625 $default_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $auth_settings['access_default_role'];
692 626 /**
693 627 * Filter the role of the user currently logging in. The role will be
694 628 * set to the default (specified in Authorizer options) for new users,
@@ -693,9 +627,8 @@
693 627 * Filter the role of the user currently logging in. The role will be
694 628 * set to the default (specified in Authorizer options) for new users,
695 629 * or the user's current role for existing users. This filter allows
696 630 * changing user roles based on custom CAS/LDAP attributes.
697 - *
698 631 * @param bool $role Role of the user currently logging in.
699 632 * @param array $user_data User data returned from external service.
700 633 */
701 634 $approved_role = apply_filters( 'authorizer_custom_role', $default_role, $user_data );
@@ -720,9 +653,9 @@
720 653 // If this externally authenticated user is an existing administrator
721 654 // (administrator in single site mode, or super admin in network mode),
722 655 // and is not in the blocked list, let them in.
723 656 if ( $user && is_super_admin( $user->ID ) ) {
724 - return $user;
657 + return;
725 658 }
726 659
727 660 // If this externally authenticated user isn't in the approved list
728 661 // and login access is set to "All authenticated users," or if they were
@@ -728,12 +661,14 @@
728 661 // and login access is set to "All authenticated users," or if they were
729 662 // automatically approved in the "authorizer_approve_login" filter
730 663 // above, then add them to the approved list (they'll get an account
731 664 // created below if they don't have one yet).
732 - if (
665 + if ( (
733 666 ! $this->is_email_in_list( $user_email, 'approved' ) &&
734 - ( 'external_users' === $auth_settings['access_who_can_login'] || $automatically_approve_login )
735 - ) {
667 + $auth_settings['access_who_can_login'] === 'external_users'
668 + ) || (
669 + $automatically_approve_login
670 + ) ) {
736 671 $is_newly_approved_user = true;
737 672
738 673 // If this user happens to be in the pending list (rare),
739 674 // remove them from pending before adding them to approved.
@@ -738,9 +673,9 @@
738 673 // If this user happens to be in the pending list (rare),
739 674 // remove them from pending before adding them to approved.
740 675 if ( $this->is_email_in_list( $user_email, 'pending' ) ) {
741 676 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
742 - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
677 + if ( $pending_user['email'] === $user_email ) {
743 678 unset( $auth_settings_access_users_pending[ $key ] );
744 679 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
745 680 break;
746 681 }
@@ -748,15 +683,14 @@
748 683 }
749 684
750 685 // Add this user to the approved list.
751 686 $approved_user = array(
752 - 'email' => $this->lowercase( $user_email ),
753 - 'role' => $approved_role,
754 - 'date_added' => date( 'Y-m-d H:i:s' ),
687 + 'email' => $user_email,
688 + 'role' => $approved_role,
689 + 'date_added' => date( "Y-m-d H:i:s" ),
755 690 );
756 691 array_push( $auth_settings_access_users_approved, $approved_user );
757 - array_push( $auth_settings_access_users_approved_single, $approved_user );
758 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
692 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
759 693 }
760 694
761 695 // Check our externally authenticated user against the approved
762 696 // list. If they are approved, log them in (and create their account
@@ -770,9 +704,9 @@
770 704 if ( $default_role !== $approved_role ) {
771 705 $user_info['role'] = $approved_role;
772 706 }
773 707
774 - // If the approved external user does not have a WordPress account, create it.
708 + // If the approved external user does not have a WordPress account, create it
775 709 if ( ! $user ) {
776 710 // If there's already a user with this username (e.g.,
777 711 // johndoe/johndoe@gmail.com exists, and we're trying to add
778 712 // johndoe/johndoe@example.com), use the full email address
@@ -787,47 +721,26 @@
787 721 $username = $user_info['email'];
788 722 }
789 723 $result = wp_insert_user(
790 724 array(
791 - 'user_login' => strtolower( $username ),
792 - 'user_pass' => wp_generate_password(), // random password.
793 - 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
794 - 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
795 - 'user_email' => $this->lowercase( $user_info['email'] ),
725 + 'user_login' => strtolower( $username ),
726 + 'user_pass' => wp_generate_password(), // random password
727 + 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
728 + 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
729 + 'user_email' => strtolower( $user_info['email'] ),
796 730 'user_registered' => date( 'Y-m-d H:i:s' ),
797 - 'role' => $user_info['role'],
731 + 'role' => $user_info['role'],
798 732 )
799 733 );
800 734
801 735 // Fail with message if error.
802 - if ( is_wp_error( $result ) || 0 === $result ) {
736 + if ( is_wp_error( $result ) || $result === 0 ) {
803 737 return $result;
804 738 }
805 739
806 - // Authenticate as new user.
740 + // Authenticate as new user
807 741 $user = new WP_User( $result );
808 742
809 - /**
810 - * Fires after an external user is authenticated for the first time
811 - * and a new WordPress account is created for them.
812 - *
813 - * @since 2.8.0
814 - *
815 - * @param WP_User $user User object.
816 - * @param array $user_data User data from external service.
817 - *
818 - * Example $user_data:
819 - * array(
820 - * 'email' => 'user@example.edu',
821 - * 'username' => 'user',
822 - * 'first_name' => 'First',
823 - * 'last_name' => 'Last',
824 - * 'authenticated_by' => 'cas',
825 - * 'cas_attributes' => array( ... ),
826 - * );
827 - */
828 - do_action( 'authorizer_user_register', $user, $user_data );
829 -
830 743 // If multisite, iterate through all sites in the network and add the user
831 744 // currently logging in to any of them that have the user on the approved list.
832 745 // Note: this is useful for first-time logins--some users will have access
833 746 // to multiple sites, and this prevents them from having to log into each
@@ -833,21 +746,18 @@
833 746 // to multiple sites, and this prevents them from having to log into each
834 747 // site individually to get access.
835 748 if ( is_multisite() ) {
836 749 $site_ids_of_user = array_map(
837 - function ( $site_of_user ) {
838 - return intval( $site_of_user->userblog_id );
839 - },
750 + function ( $site_of_user ) { return $site_of_user->userblog_id; },
840 751 get_blogs_of_user( $user->ID )
841 752 );
842 753
843 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
844 754 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
845 755 foreach ( $sites as $site ) {
846 756 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
847 757
848 758 // Skip if user is already added to this site.
849 - if ( in_array( intval( $blog_id ), $site_ids_of_user, true ) ) {
759 + if ( in_array( $blog_id, $site_ids_of_user ) ) {
850 760 continue;
851 761 }
852 762
853 763 // Check if user is on the approved list of this site they are not added to.
@@ -873,9 +783,9 @@
873 783 if ( $meta_key === $user_info['usermeta']['meta_key'] ) {
874 784 // Update user's usermeta value for usermeta key stored in authorizer options.
875 785 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
876 786 // We have an ACF field value, so use the ACF function to update it.
877 - update_field( str_replace( 'acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
787 + update_field( str_replace('acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
878 788 } else {
879 789 // We have a normal usermeta value, so just update it via the WordPress function.
880 790 update_user_meta( $user->ID, $meta_key, $user_info['usermeta']['meta_value'] );
881 791 }
@@ -891,9 +801,9 @@
891 801 switch_to_blog( $blog_id );
892 802 // Update user's usermeta value for usermeta key stored in authorizer options.
893 803 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
894 804 // We have an ACF field value, so use the ACF function to update it.
895 - update_field( str_replace( 'acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
805 + update_field( str_replace('acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
896 806 } else {
897 807 // We have a normal usermeta value, so just update it via the WordPress function.
898 808 update_user_meta( $user->ID, $meta_key, $usermeta['meta_value'] );
899 809 }
@@ -904,24 +814,20 @@
904 814 }
905 815 } else {
906 816 // Update first/last names of WordPress user from external
907 817 // service if that option is set.
908 - if ( ( array_key_exists( 'authenticated_by', $user_data ) && 'cas' === $user_data['authenticated_by'] && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['cas_attr_update_on_login'] ) ) || ( array_key_exists( 'authenticated_by', $user_data ) && 'ldap' === $user_data['authenticated_by'] && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['ldap_attr_update_on_login'] ) ) ) {
909 - if ( array_key_exists( 'first_name', $user_data ) && 0 < strlen( $user_data['first_name'] ) ) {
910 - wp_update_user(
911 - array(
912 - 'ID' => $user->ID,
913 - 'first_name' => $user_data['first_name'],
914 - )
915 - );
818 + if ( ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'cas' && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && $auth_settings['cas_attr_update_on_login'] == 1 ) || ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'ldap' && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && $auth_settings['ldap_attr_update_on_login'] == 1 ) ) {
819 + if ( array_key_exists( 'first_name', $user_data ) && strlen( $user_data['first_name'] ) > 0 ) {
820 + wp_update_user( array(
821 + 'ID' => $user->ID,
822 + 'first_name' => $user_data['first_name'],
823 + ));
916 824 }
917 825 if ( array_key_exists( 'last_name', $user_data ) && strlen( $user_data['last_name'] ) > 0 ) {
918 - wp_update_user(
919 - array(
920 - 'ID' => $user->ID,
921 - 'last_name' => $user_data['last_name'],
922 - )
923 - );
826 + wp_update_user( array(
827 + 'ID' => $user->ID,
828 + 'last_name' => $user_data['last_name'],
829 + ));
924 830 }
925 831 }
926 832
927 833 // Update this user's role if it was modified in the
@@ -926,19 +832,12 @@
926 832
927 833 // Update this user's role if it was modified in the
928 834 // authorizer_custom_role filter.
929 835 if ( $default_role !== $approved_role ) {
930 - // Update user's role in WordPress.
931 - $user->set_role( $approved_role );
932 -
933 - // Update user's role in this site's approved list and save.
934 - foreach ( $auth_settings_access_users_approved_single as $key => $existing_user ) {
935 - if ( 0 === strcasecmp( $user->user_email, $existing_user['email'] ) ) {
936 - $auth_settings_access_users_approved_single[ $key ]['role'] = $approved_role;
937 - break;
938 - }
939 - }
940 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
836 + wp_update_user( array(
837 + 'ID' => $user->ID,
838 + 'role' => $approved_role,
839 + ));
941 840 }
942 841 }
943 842
944 843 // If this is multisite, add new user to current blog.
@@ -951,34 +850,33 @@
951 850 }
952 851 }
953 852
954 853 // Ensure user has the same role as their entry in the approved list.
955 - if ( $user_info && ! in_array( $user_info['role'], $user->roles, true ) ) {
854 + // (This is just a precaution, the role should already be set when
855 + // saving admin options in the sanitizing function.)
856 + if ( $user_info && ! array_key_exists( $user_info['role'], $user->roles ) ) {
956 857 $user->set_role( $user_info['role'] );
957 858 }
958 859
959 860 return $user;
960 861
961 - } elseif ( 0 === strcasecmp( $user_email, $last_email ) ) {
962 - /**
963 - * Note: only do this for the last email address we are checking (we need
964 - * to iterate through them all to make sure one of them isn't approved).
965 - */
966 -
862 + // Note: only do this for the last email address we are checking (we need
863 + // to iterate through them all to make sure one of them isn't approved).
864 + } elseif ( $user_email === $last_email ) {
967 865 // User isn't an admin, is not blocked, and is not approved.
968 866 // Add them to the pending list and notify them and their instructor.
969 867 if ( strlen( $user_email ) > 0 && ! $this->is_email_in_list( $user_email, 'pending' ) ) {
970 - $pending_user = array();
971 - $pending_user['email'] = $this->lowercase( $user_email );
972 - $pending_user['role'] = $approved_role;
868 + $pending_user = array();
869 + $pending_user['email'] = $user_email;
870 + $pending_user['role'] = $approved_role;
973 871 $pending_user['date_added'] = '';
974 872 array_push( $auth_settings_access_users_pending, $pending_user );
975 873 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
976 874
977 875 // Create strings used in the email notification.
978 - $site_name = get_bloginfo( 'name' );
979 - $site_url = get_bloginfo( 'url' );
980 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
876 + $site_name = get_bloginfo( 'name' );
877 + $site_url = get_bloginfo( 'url' );
878 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
981 879
982 880 // Notify users with the role specified in "Which role should
983 881 // receive email notifications about pending users?".
984 882 if ( strlen( $auth_settings['access_role_receive_pending_emails'] ) > 0 ) {
@@ -1003,11 +901,10 @@
1003 901 }
1004 902 }
1005 903
1006 904 // Notify user about pending status and return without authenticating them.
1007 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1008 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
1009 - $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
905 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
906 + $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
1010 907 $error_message =
1011 908 apply_filters( 'the_content', $auth_settings['access_pending_redirect_to_message'] ) .
1012 909 '<hr />' .
1013 910 '<p style="text-align: center;">' .
@@ -1014,9 +911,9 @@
1014 911 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
1015 912 __( 'Back', 'authorizer' ) .
1016 913 '</a></p>';
1017 914 update_option( 'auth_settings_advanced_login_error', $error_message );
1018 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
915 + wp_die( $error_message, $page_title );
1019 916 }
1020 917 }
1021 918
1022 919 // Sanity check: if we made it here without returning, something has gone wrong.
@@ -1039,34 +936,24 @@
1039 936 * custom_authenticate_google() runs to verify the token; once verified
1040 937 * custom_authenticate proceeds as normal with the google email address
1041 938 * as a successfully authenticated external user.
1042 939 *
1043 - * Action: wp_ajax_process_google_login
1044 - * Action: wp_ajax_nopriv_process_google_login
1045 - *
1046 - * @return void, but die with the value to return to the success() function in AJAX call signInCallback().
940 + * @return void, but die with the value to return to the success() function in AJAX call signInCallback()
1047 941 */
1048 - public function ajax_process_google_login() {
942 + function ajax_process_google_login() {
943 + $nonce = array_key_exists( 'nonce', $_POST ) ? $_POST['nonce'] : '';
944 + $code = array_key_exists( 'code', $_POST ) ? $_POST['code'] : null;
945 +
1049 946 // Nonce check.
1050 - if (
1051 - ! isset( $_POST['nonce'] ) ||
1052 - ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'google_csrf_nonce' )
1053 - ) {
1054 - die( '' );
947 + if ( ! wp_verify_nonce( $nonce, 'google_csrf_nonce' ) ) {
948 + return '';
1055 949 }
1056 950
1057 - // Google authentication token.
1058 - // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput.InputNotSanitized
1059 - $code = isset( $_POST['code'] ) ? wp_unslash( $_POST['code'] ) : null;
1060 -
1061 951 // Grab plugin settings.
1062 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
952 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1063 953
1064 - /**
1065 - * Add Google API PHP Client.
1066 - *
1067 - * @see https://github.com/google/google-api-php-client branch:v1-master
1068 - */
954 + // Add Google API PHP Client.
955 + // @see https://github.com/google/google-api-php-client branch:v1-master
1069 956 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1070 957
1071 958 // Build the Google Client.
1072 959 $client = new Google_Client();
@@ -1074,26 +961,19 @@
1074 961 $client->setClientId( $auth_settings['google_clientid'] );
1075 962 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1076 963 $client->setRedirectUri( 'postmessage' );
1077 964
1078 - /**
1079 - * If the hosted domain parameter is set, restrict logins to that domain.
1080 - *
1081 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1082 - * this to function server-side; it's not complete in v1, so this check
1083 - * is performed manually below.
1084 - *
1085 - * if (
1086 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1087 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1088 - * ) {
1089 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1090 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1091 - * $client->setHostedDomain( $google_hosteddomain );
1092 - * }
1093 - */
965 + // If the hosted domain parameter is set, restrict logins to that domain.
966 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
967 + // this to function server-side; it's not complete in v1, so this check
968 + // is performed manually below.
969 + // if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
970 + // $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
971 + // $google_hosteddomain = trim( $google_hosteddomains[0] );
972 + // $client->setHostedDomain( $google_hosteddomain );
973 + // }
1094 974
1095 - // Get one time use token (if it doesn't exist, we'll create one below).
975 + // Get one time use token (if it doesn't exist, we'll create one below)
1096 976 session_start();
1097 977 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1098 978
1099 979 if ( empty( $token ) ) {
@@ -1101,18 +981,18 @@
1101 981 $client->authenticate( $code );
1102 982 $token = json_decode( $client->getAccessToken() );
1103 983
1104 984 // Store the token in the session for later use.
1105 - $_SESSION['token'] = wp_json_encode( $token );
985 + $_SESSION['token'] = json_encode( $token );
1106 986
1107 - $response = 'Successfully authenticated.';
987 + $response = "Successfully authenticated.";
1108 988 } else {
1109 - $client->setAccessToken( wp_json_encode( $token ) );
989 + $client->setAccessToken( json_encode( $token ) );
1110 990
1111 991 $response = 'Already authenticated.';
1112 992 }
1113 993
1114 - die( esc_html( $response ) );
994 + die( $response );
1115 995 }
1116 996
1117 997
1118 998 /**
@@ -1117,22 +997,22 @@
1117 997
1118 998 /**
1119 999 * Validate this user's credentials against Google.
1120 1000 *
1121 - * @param array $auth_settings Plugin settings.
1122 - * @return array|WP_Error Array containing email, authenticated_by, first_name,
1123 - * last_name, and username strings for the successfully
1124 - * authenticated user, or WP_Error() object on failure,
1125 - * or null if not attempting a google login.
1001 + * @param array $auth_settings Plugin settings
1002 + * @return [mixed] Array containing email, authenticated_by,
1003 + * first_name, last_name, and username
1004 + * strings for the successfully authenticated
1005 + * user, or WP_Error() object on failure,
1006 + * or null if not attempting a google login.
1126 1007 */
1127 1008 private function custom_authenticate_google( $auth_settings ) {
1128 1009 // Move on if Google auth hasn't been requested here.
1129 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1130 - if ( empty( $_GET['external'] ) || 'google' !== $_GET['external'] ) {
1010 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'google' ) {
1131 1011 return null;
1132 1012 }
1133 1013
1134 - // Get one time use token.
1014 + // Get one time use token
1135 1015 session_start();
1136 1016 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1137 1017
1138 1018 // No token, so this is not a succesful Google login.
@@ -1139,13 +1019,10 @@
1139 1019 if ( is_null( $token ) ) {
1140 1020 return null;
1141 1021 }
1142 1022
1143 - /**
1144 - * Add Google API PHP Client.
1145 - *
1146 - * @see https://github.com/google/google-api-php-client branch:v1-master
1147 - */
1023 + // Add Google API PHP Client.
1024 + // @see https://github.com/google/google-api-php-client branch:v1-master
1148 1025 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1149 1026
1150 1027 // Build the Google Client.
1151 1028 $client = new Google_Client();
@@ -1153,24 +1030,19 @@
1153 1030 $client->setClientId( $auth_settings['google_clientid'] );
1154 1031 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1155 1032 $client->setRedirectUri( 'postmessage' );
1156 1033
1157 - /**
1158 - * If the hosted domain parameter is set, restrict logins to that domain.
1159 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1160 - * this to function server-side; it's not complete in v1, so this check
1161 - * is performed manually later.
1162 - * if (
1163 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1164 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1165 - * ) {
1166 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1167 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1168 - * $client->setHostedDomain( $google_hosteddomain );
1169 - * }
1170 - */
1034 + // If the hosted domain parameter is set, restrict logins to that domain.
1035 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1036 + // this to function server-side; it's not complete in v1, so this check
1037 + // is performed manually below.
1038 + // if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1039 + // $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1040 + // $google_hosteddomain = trim( $google_hosteddomains[0] );
1041 + // $client->setHostedDomain( $google_hosteddomain );
1042 + // }
1171 1043
1172 - // Verify this is a successful Google authentication.
1044 + // Verify this is a successful Google authentication
1173 1045 try {
1174 1046 $ticket = $client->verifyIdToken( $token->id_token, $auth_settings['google_clientid'] );
1175 1047 } catch ( Google_Auth_Exception $e ) {
1176 1048 // Invalid ticket, so this in not a successful Google login.
@@ -1181,29 +1053,25 @@
1181 1053 if ( ! $ticket ) {
1182 1054 return new WP_Error( 'invalid_google_login', __( 'Invalid Google credentials provided.', 'authorizer' ) );
1183 1055 }
1184 1056
1185 - // Get email address.
1186 - $attributes = $ticket->getAttributes();
1187 - $email = $this->lowercase( $attributes['payload']['email'] );
1057 + // Get email address
1058 + $attributes = $ticket->getAttributes();
1059 + $email = $attributes['payload']['email'];
1188 1060 $email_domain = substr( strrchr( $email, '@' ), 1 );
1189 - $username = current( explode( '@', $email ) );
1061 + $username = current( explode( '@', $email ) );
1190 1062
1191 - /**
1192 - * Fail if hd param is set and the logging in user's email address doesn't
1193 - * match the allowed hosted domain.
1194 - *
1195 - * See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1196 - * See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1197 - *
1198 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1199 - * this to function server-side; it's not complete in v1, so this check
1200 - * is only performed here.
1201 - */
1063 + // Fail if hd param is set and the logging in user's email address doesn't
1064 + // match the allowed hosted domain.
1065 + // See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1066 + // See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1067 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1068 + // this to function server-side; it's not complete in v1, so this check
1069 + // is only performed here.
1202 1070 if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1203 1071 // Allow multiple whitelisted domains.
1204 1072 $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1205 - if ( ! in_array( $email_domain, $google_hosteddomains, true ) ) {
1073 + if ( ! in_array( $email_domain, $google_hosteddomains ) ) {
1206 1074 $this->custom_logout();
1207 1075 return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) );
1208 1076 }
1209 1077 }
@@ -1208,13 +1076,13 @@
1208 1076 }
1209 1077 }
1210 1078
1211 1079 return array(
1212 - 'email' => $email,
1213 - 'username' => $username,
1214 - 'first_name' => '',
1215 - 'last_name' => '',
1216 - 'authenticated_by' => 'google',
1080 + 'email' => $email,
1081 + 'username' => $username,
1082 + 'first_name' => '',
1083 + 'last_name' => '',
1084 + 'authenticated_by' => 'google',
1217 1085 'google_attributes' => $attributes,
1218 1086 );
1219 1087 }
1220 1088
@@ -1221,47 +1089,40 @@
1221 1089
1222 1090 /**
1223 1091 * Validate this user's credentials against CAS.
1224 1092 *
1225 - * @param array $auth_settings Plugin settings.
1226 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1227 - * for the successfully authenticated user, or WP_Error()
1228 - * object on failure, or null if not attempting a CAS login.
1093 + * @param array $auth_settings Plugin settings
1094 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1095 + * strings for the successfully authenticated
1096 + * user, or WP_Error() object on failure,
1097 + * or null if not attempting a CAS login.
1229 1098 */
1230 1099 private function custom_authenticate_cas( $auth_settings ) {
1231 1100 // Move on if CAS hasn't been requested here.
1232 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1233 - if ( empty( $_GET['external'] ) || 'cas' !== $_GET['external'] ) {
1101 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'cas' ) {
1234 1102 return null;
1235 1103 }
1236 1104
1237 - /**
1238 - * Get the CAS server version (default to SAML_VERSION_1_1).
1239 - *
1240 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1241 - */
1105 + // Get the CAS server version (default to SAML_VERSION_1_1).
1106 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1242 1107 $cas_version = SAML_VERSION_1_1;
1243 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1108 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1244 1109 $cas_version = CAS_VERSION_3_0;
1245 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1110 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1246 1111 $cas_version = CAS_VERSION_2_0;
1247 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1112 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1248 1113 $cas_version = CAS_VERSION_1_0;
1249 1114 }
1250 1115
1251 - // Set the CAS client configuration.
1116 + // Set the CAS client configuration
1252 1117 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1253 1118
1254 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1255 - // at an old CAS URL that redirects to a newer CAS URL).
1256 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1257 -
1258 1119 // Update server certificate bundle if it doesn't exist or is older
1259 1120 // than 6 months, then use it to ensure CAS server is legitimate.
1260 1121 // Note: only try to update if the system has the php_openssl extension.
1261 - $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1262 - $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1263 - $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds.
1122 + $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1123 + $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1124 + $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds
1264 1125 $time_180_days_ago = time() - $time_180_days;
1265 1126 if (
1266 1127 extension_loaded( 'openssl' ) &&
1267 1128 ( ! file_exists( $cacert_path ) || filemtime( $cacert_path ) < $time_180_days_ago )
@@ -1277,34 +1138,28 @@
1277 1138 }
1278 1139 $cacert_contents = $response['body'];
1279 1140
1280 1141 // Write out the updated certs to the plugin directory.
1281 - // Note: Don't use WP_Filesystem because we are not in an admin context
1282 - // and don't want to potentially prompt the end user for credentials.
1283 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_read_file_put_contents
1284 1142 file_put_contents( $cacert_path, $cacert_contents );
1285 1143 }
1286 1144 phpCAS::setCasServerCACert( $cacert_path );
1287 1145
1288 1146 // Set the CAS service URL (including the redirect URL for WordPress when it comes back from CAS).
1289 - $cas_service_url = site_url( '/wp-login.php?external=cas' );
1290 - $login_querystring = array();
1291 - if ( isset( $_SERVER['QUERY_STRING'] ) ) {
1292 - parse_str( $_SERVER['QUERY_STRING'], $login_querystring ); // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput
1293 - }
1147 + $cas_service_url = site_url( '/wp-login.php?external=cas' );
1148 + $login_querystring = array(); parse_str( $_SERVER['QUERY_STRING'], $login_querystring );
1294 1149 if ( isset( $login_querystring['redirect_to'] ) ) {
1295 - $cas_service_url .= '&redirect_to=' . rawurlencode( $login_querystring['redirect_to'] );
1150 + $cas_service_url .= '&redirect_to=' . urlencode( $login_querystring['redirect_to'] );
1296 1151 }
1297 1152 phpCAS::setFixedServiceURL( $cas_service_url );
1298 1153
1299 - // Authenticate against CAS.
1154 + // Authenticate against CAS
1300 1155 try {
1301 1156 phpCAS::forceAuthentication();
1302 1157 } catch ( CAS_AuthenticationException $e ) {
1303 1158 // CAS server threw an error in isAuthenticated(), potentially because
1304 1159 // the cached ticket is outdated. Try renewing the authentication.
1305 - error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) ); // phpcs:ignore
1306 - error_log( print_r( $e, true ) ); // phpcs:ignore
1160 + error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) );
1161 + error_log( print_r( $e, true ) );
1307 1162
1308 1163 // CAS server is throwing errors on this login, so try logging the
1309 1164 // user out of CAS and redirecting them to the login page.
1310 1165 phpCAS::logoutWithRedirectService( wp_login_url() );
@@ -1319,10 +1174,10 @@
1319 1174 if ( ! filter_var( $externally_authenticated_email, FILTER_VALIDATE_EMAIL ) ) {
1320 1175 // If we can't get the user's email address from a CAS attribute,
1321 1176 // try to guess the domain from the CAS server hostname. This will only
1322 1177 // be used if we can't discover the email address from CAS attributes.
1323 - $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1324 - $externally_authenticated_email = $this->lowercase( $username ) . '@' . $domain_guess;
1178 + $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1179 + $externally_authenticated_email = strtolower( $username ) . '@' . $domain_guess;
1325 1180 }
1326 1181
1327 1182 // Retrieve the user attributes (e.g., email address, first name, last name) from the CAS server.
1328 1183 $cas_attributes = phpCAS::getAttributes();
@@ -1333,45 +1188,37 @@
1333 1188 // email domain is manually entered there (instead of a reference to a
1334 1189 // CAS attribute), and combine that with the username to create the email.
1335 1190 // Otherwise, look up the CAS attribute for email.
1336 1191 if ( substr( $auth_settings['cas_attr_email'], 0, 1 ) === '@' ) {
1337 - $externally_authenticated_email = $this->lowercase( $username . $auth_settings['cas_attr_email'] );
1192 + $externally_authenticated_email = strtolower( $username . $auth_settings['cas_attr_email'] );
1338 1193 } elseif (
1339 1194 // If a CAS attribute has been specified as containing the email address, use that instead.
1340 1195 // Email attribute can be a string or an array of strings.
1341 1196 array_key_exists( $auth_settings['cas_attr_email'], $cas_attributes ) && (
1342 1197 (
1343 - is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1344 - count( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1198 + is_array( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1199 + count( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1345 1200 ) || (
1346 - is_string( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1347 - strlen( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1201 + is_string( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1202 + strlen( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1348 1203 )
1349 1204 )
1350 1205 ) {
1351 - // Each of the emails in the array needs to be set to lowercase.
1352 - if ( is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) ) {
1353 - $externally_authenticated_email = array();
1354 - foreach ( $cas_attributes[ $auth_settings['cas_attr_email'] ] as $external_email ) {
1355 - $externally_authenticated_email[] = $this->lowercase( $external_email );
1356 - }
1357 - } else {
1358 - $externally_authenticated_email = $this->lowercase( $cas_attributes[ $auth_settings['cas_attr_email'] ] );
1359 - }
1206 + $externally_authenticated_email = $cas_attributes[$auth_settings['cas_attr_email']];
1360 1207 }
1361 1208 }
1362 1209
1363 1210 // Get user first name and last name.
1364 - $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_first_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_first_name'] ] : '';
1365 - $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_last_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_last_name'] ] : '';
1211 + $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_first_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_first_name']] : '';
1212 + $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_last_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_last_name']] : '';
1366 1213
1367 1214 return array(
1368 - 'email' => $externally_authenticated_email,
1369 - 'username' => $username,
1370 - 'first_name' => $first_name,
1371 - 'last_name' => $last_name,
1215 + 'email' => $externally_authenticated_email,
1216 + 'username' => $username,
1217 + 'first_name' => $first_name,
1218 + 'last_name' => $last_name,
1372 1219 'authenticated_by' => 'cas',
1373 - 'cas_attributes' => $cas_attributes,
1220 + 'cas_attributes' => $cas_attributes,
1374 1221 );
1375 1222 }
1376 1223
1377 1224
@@ -1377,32 +1224,24 @@
1377 1224
1378 1225 /**
1379 1226 * Validate this user's credentials against LDAP.
1380 1227 *
1381 - * @param array $auth_settings Plugin settings.
1382 - * @param string $username Attempted username from authenticate action.
1383 - * @param string $password Attempted password from authenticate action.
1384 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1385 - * for the successfully authenticated user, or WP_Error()
1386 - * object on failure, or null if skipping LDAP auth and
1387 - * falling back to WP auth.
1228 + * @param array $auth_settings Plugin settings
1229 + * @param string $username Attempted username from authenticate action
1230 + * @param string $password Attempted password from authenticate action
1231 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1232 + * strings for the successfully authenticated
1233 + * user, or WP_Error() object on failure,
1234 + * or null if skipping LDAP auth and falling back to WP auth.
1388 1235 */
1389 1236 private function custom_authenticate_ldap( $auth_settings, $username, $password ) {
1390 - // Get LDAP search base(s).
1391 - $search_bases = explode( "\n", str_replace( "\r", '', trim( $auth_settings['ldap_search_base'] ) ) );
1392 -
1393 - // Fail silently (fall back to WordPress authentication) if no search base specified.
1394 - if ( count( $search_bases ) < 1 ) {
1395 - return null;
1396 - }
1397 -
1398 - // Get the FQDN from the first LDAP search base domain components (dc). For
1399 - // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk.
1400 - $search_base_components = explode( ',', trim( $search_bases[0] ) );
1401 - $domain = array();
1237 + // Get the FQDN from the LDAP search base domain components (dc). For
1238 + // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk
1239 + $search_base_components = explode( ',', trim( $auth_settings['ldap_search_base'] ) );
1240 + $domain = array();
1402 1241 foreach ( $search_base_components as $search_base_component ) {
1403 1242 $component = explode( '=', $search_base_component );
1404 - if ( 2 === count( $component ) && 'dc' === $component[0] ) {
1243 + if ( count( $component ) === 2 && $component[0] === 'dc' ) {
1405 1244 $domain[] = $component[1];
1406 1245 }
1407 1246 }
1408 1247 $domain = implode( '.', $domain );
@@ -1413,9 +1252,9 @@
1413 1252 if ( empty( $domain ) ) {
1414 1253 $domain = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['ldap_host'], $matches ) === 1 ? $matches[0] : '';
1415 1254 }
1416 1255
1417 - // remove @domain if it exists in the username (i.e., if user entered their email).
1256 + // remove @domain if it exists in the username (i.e., if user entered their email)
1418 1257 $username = str_replace( '@' . $domain, '', $username );
1419 1258
1420 1259 // Fail silently (fall back to WordPress authentication) if both username
1421 1260 // and password are empty (this will be the case when visiting wp-login.php
@@ -1438,13 +1277,13 @@
1438 1277 return null;
1439 1278 }
1440 1279
1441 1280 // Authenticate against LDAP using options provided in plugin settings.
1442 - $result = false;
1281 + $result = false;
1443 1282 $ldap_user_dn = '';
1444 - $first_name = '';
1445 - $last_name = '';
1446 - $email = '';
1283 + $first_name = '';
1284 + $last_name = '';
1285 + $email = '';
1447 1286
1448 1287 // Construct LDAP connection parameters. ldap_connect() takes either a
1449 1288 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1450 1289 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
@@ -1449,13 +1288,13 @@
1449 1288 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1450 1289 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
1451 1290 // ignored, and port must be specified in the full URI. An LDAP URI is of
1452 1291 // the form ldap://hostname:port or ldaps://hostname:port.
1453 - $ldap_host = $auth_settings['ldap_host'];
1454 - $ldap_port = intval( $auth_settings['ldap_port'] );
1455 - $parsed_host = wp_parse_url( $ldap_host );
1292 + $ldap_host = $auth_settings['ldap_host'];
1293 + $ldap_port = intval( $auth_settings['ldap_port'] );
1294 + $parsed_host = parse_url( $ldap_host );
1456 1295 // Fail (fall back to WordPress auth) if invalid host is specified.
1457 - if ( false === $parsed_host ) {
1296 + if ( $parsed_host === false ) {
1458 1297 return null;
1459 1298 }
1460 1299 // If a scheme is in the LDAP host, use full LDAP URI instead of just hostname.
1461 1300 if ( array_key_exists( 'scheme', $parsed_host ) ) {
@@ -1468,24 +1307,24 @@
1468 1307
1469 1308 // Establish LDAP connection.
1470 1309 $ldap = ldap_connect( $ldap_host, $ldap_port );
1471 1310 ldap_set_option( $ldap, LDAP_OPT_PROTOCOL_VERSION, 3 );
1472 - if ( 1 === intval( $auth_settings['ldap_tls'] ) ) {
1473 - if ( ! ldap_start_tls( $ldap ) ) {
1311 + if ( $auth_settings['ldap_tls'] == 1 ) {
1312 + if( ! ldap_start_tls( $ldap ) ) {
1474 1313 return null;
1475 1314 }
1476 1315 }
1477 1316
1478 1317 // Set bind credentials; attempt an anonymous bind if not provided.
1479 - $bind_rdn = null;
1480 - $bind_password = null;
1318 + $bind_rdn = NULL;
1319 + $bind_password = NULL;
1481 1320 if ( strlen( $auth_settings['ldap_user'] ) > 0 ) {
1482 - $bind_rdn = $auth_settings['ldap_user'];
1321 + $bind_rdn = $auth_settings['ldap_user'];
1483 1322 $bind_password = $this->decrypt( $auth_settings['ldap_password'] );
1484 1323 }
1485 1324
1486 1325 // Attempt LDAP bind.
1487 - $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) ); // phpcs:ignore
1326 + $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) );
1488 1327 if ( ! $result ) {
1489 1328 // Can't connect to LDAP, so fall back to WordPress authentication.
1490 1329 return null;
1491 1330 }
@@ -1499,40 +1338,18 @@
1499 1338 if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 ) {
1500 1339 array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_last_name'] );
1501 1340 }
1502 1341 if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 && substr( $auth_settings['ldap_attr_email'], 0, 1 ) !== '@' ) {
1503 - array_push( $ldap_attributes_to_retrieve, $this->lowercase( $auth_settings['ldap_attr_email'] ) );
1342 + array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_email'] );
1504 1343 }
1344 + $ldap_search = ldap_search(
1345 + $ldap,
1346 + $auth_settings['ldap_search_base'],
1347 + "(" . $auth_settings['ldap_uid'] . "=" . $username . ")",
1348 + $ldap_attributes_to_retrieve
1349 + );
1350 + $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1505 1351
1506 - // Create default LDAP search filter (uid=$username).
1507 - $search_filter = '(' . $auth_settings['ldap_uid'] . '=' . $username . ')';
1508 -
1509 - /**
1510 - * Filter LDAP search filter.
1511 - *
1512 - * Allows for custom LDAP authentication rules (e.g., restricting login
1513 - * access to users in multiple groups, or having certain attributes).
1514 - *
1515 - * @param string $search_filter The filter to pass to ldap_search().
1516 - * @param string $ldap_uid The attribute to compare username against (from Authorizer Settings).
1517 - * @param string $username The username attempting to log in.
1518 - */
1519 - $search_filter = apply_filters( 'authorizer_ldap_search_filter', $search_filter, $auth_settings['ldap_uid'], $username );
1520 -
1521 - // Multiple search bases can be provided, so iterate through them until a match is found.
1522 - foreach ( $search_bases as $search_base ) {
1523 - $ldap_search = ldap_search(
1524 - $ldap,
1525 - $search_base,
1526 - $search_filter,
1527 - $ldap_attributes_to_retrieve
1528 - );
1529 - $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1530 - if ( $ldap_entries['count'] > 0 ) {
1531 - break;
1532 - }
1533 - }
1534 -
1535 1352 // If we didn't find any users in ldap, fall back to WordPress authentication.
1536 1353 if ( $ldap_entries['count'] < 1 ) {
1537 1354 return null;
1538 1355 }
@@ -1538,21 +1355,21 @@
1538 1355 }
1539 1356
1540 1357 // Get the bind dn and first/last names; if there are multiple results returned, just get the last one.
1541 1358 for ( $i = 0; $i < $ldap_entries['count']; $i++ ) {
1542 - $ldap_user_dn = $ldap_entries[ $i ]['dn'];
1359 + $ldap_user_dn = $ldap_entries[$i]['dn'];
1543 1360
1544 1361 // Get user first name and last name.
1545 - $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_first_name'] ) : '';
1546 - if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_first_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_first_name ][0] ) > 0 ) {
1547 - $first_name = $ldap_entries[ $i ][ $ldap_attr_first_name ][0];
1362 + $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? strtolower( $auth_settings['ldap_attr_first_name'] ) : '';
1363 + if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_first_name]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_first_name][0] ) > 0 ) {
1364 + $first_name = $ldap_entries[$i][$ldap_attr_first_name][0];
1548 1365 }
1549 - $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_last_name'] ) : '';
1550 - if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_last_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_last_name ][0] ) > 0 ) {
1551 - $last_name = $ldap_entries[ $i ][ $ldap_attr_last_name ][0];
1366 + $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? strtolower( $auth_settings['ldap_attr_last_name'] ) : '';
1367 + if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_last_name]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_last_name][0] ) > 0 ) {
1368 + $last_name = $ldap_entries[$i][$ldap_attr_last_name][0];
1552 1369 }
1553 1370 // Get user email if it is specified in another field.
1554 - $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_email'] ) : '';
1371 + $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? strtolower( $auth_settings['ldap_attr_email'] ) : '';
1555 1372 if ( strlen( $ldap_attr_email ) > 0 ) {
1556 1373 // If the email attribute starts with an at symbol (@), assume that the
1557 1374 // email domain is manually entered there (instead of a reference to an
1558 1375 // LDAP attribute), and combine that with the username to create the email.
@@ -1557,16 +1374,16 @@
1557 1374 // email domain is manually entered there (instead of a reference to an
1558 1375 // LDAP attribute), and combine that with the username to create the email.
1559 1376 // Otherwise, look up the LDAP attribute for email.
1560 1377 if ( substr( $ldap_attr_email, 0, 1 ) === '@' ) {
1561 - $email = $this->lowercase( $username . $ldap_attr_email );
1562 - } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_email ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_email ][0] ) > 0 ) {
1563 - $email = $this->lowercase( $ldap_entries[ $i ][ $ldap_attr_email ][0] );
1378 + $email = strtolower( $username . $ldap_attr_email );
1379 + } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_email]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_email][0] ) > 0 ) {
1380 + $email = strtolower( $ldap_entries[$i][$ldap_attr_email][0] );
1564 1381 }
1565 1382 }
1566 1383 }
1567 1384
1568 - $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) ); // phpcs:ignore
1385 + $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) );
1569 1386 if ( ! $result ) {
1570 1387 // We have a real ldap user, but an invalid password. Pass
1571 1388 // through to wp authentication after failing LDAP (since
1572 1389 // this could be a local account that happens to be the
@@ -1574,22 +1391,22 @@
1574 1391 return null;
1575 1392 }
1576 1393
1577 1394 // User successfully authenticated against LDAP, so set the relevant variables.
1578 - $externally_authenticated_email = $this->lowercase( $username . '@' . $domain );
1395 + $externally_authenticated_email = $username . '@' . $domain;
1579 1396
1580 1397 // If an LDAP attribute has been specified as containing the email address, use that instead.
1581 1398 if ( strlen( $email ) > 0 ) {
1582 - $externally_authenticated_email = $this->lowercase( $email );
1399 + $externally_authenticated_email = $email;
1583 1400 }
1584 1401
1585 1402 return array(
1586 - 'email' => $externally_authenticated_email,
1587 - 'username' => $username,
1588 - 'first_name' => $first_name,
1589 - 'last_name' => $last_name,
1403 + 'email' => $externally_authenticated_email,
1404 + 'username' => $username,
1405 + 'first_name' => $first_name,
1406 + 'last_name' => $last_name,
1590 1407 'authenticated_by' => 'ldap',
1591 - 'ldap_attributes' => $ldap_entries,
1408 + 'ldap_attributes' => $ldap_entries,
1592 1409 );
1593 1410 }
1594 1411
1595 1412
@@ -1595,20 +1412,18 @@
1595 1412
1596 1413 /**
1597 1414 * Log out of the attached external service.
1598 1415 *
1599 - * Action: wp_logout
1600 - *
1601 1416 * @return void
1602 1417 */
1603 1418 public function custom_logout() {
1604 1419 // Grab plugin settings.
1605 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1420 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1606 1421
1607 1422 // Reset option containing old error messages.
1608 1423 delete_option( 'auth_settings_advanced_login_error' );
1609 1424
1610 - if ( session_id() === '' ) {
1425 + if ( session_id() == '' ) {
1611 1426 session_start();
1612 1427 }
1613 1428
1614 1429 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
@@ -1613,53 +1428,38 @@
1613 1428
1614 1429 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
1615 1430
1616 1431 // If logged in to CAS, Log out of CAS.
1617 - if ( 'cas' === $current_user_authenticated_by && '1' === $auth_settings['cas'] ) {
1432 + if ( $current_user_authenticated_by === 'cas' && $auth_settings['cas'] === '1' ) {
1618 1433 if ( ! array_key_exists( 'PHPCAS_CLIENT', $GLOBALS ) || ! array_key_exists( 'phpCAS', $_SESSION ) ) {
1619 1434
1620 - /**
1621 - * Get the CAS server version (default to SAML_VERSION_1_1).
1622 - *
1623 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1624 - */
1435 + // Get the CAS server version (default to SAML_VERSION_1_1).
1436 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1625 1437 $cas_version = SAML_VERSION_1_1;
1626 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1438 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1627 1439 $cas_version = CAS_VERSION_3_0;
1628 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1440 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1629 1441 $cas_version = CAS_VERSION_2_0;
1630 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1442 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1631 1443 $cas_version = CAS_VERSION_1_0;
1632 1444 }
1633 1445
1634 1446 // Set the CAS client configuration if it hasn't been set already.
1635 1447 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1636 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1637 - // at an old CAS URL that redirects to a newer CAS URL).
1638 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1639 1448 // Restrict logout request origin to the CAS server only (prevent DDOS).
1640 1449 phpCAS::handleLogoutRequests( true, array( $auth_settings['cas_host'] ) );
1641 1450 }
1642 - if ( phpCAS::isAuthenticated() || phpCAS::isInitialized() ) {
1643 - // Redirect to home page, or specified page if it's been provided.
1644 - $redirect_to = site_url( '/' );
1645 - if ( ! empty( $_REQUEST['redirect_to'] ) && isset( $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'log-out' ) ) {
1646 - $redirect_to = esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) );
1647 - }
1648 -
1649 - phpCAS::logoutWithRedirectService( $redirect_to );
1451 + if ( phpCAS::isAuthenticated() ) {
1452 + phpCAS::logoutWithRedirectService( site_url( '/' ) );
1650 1453 }
1651 1454 }
1652 1455
1653 1456 // If session token set, log out of Google.
1654 - if ( 'google' === $current_user_authenticated_by || array_key_exists( 'token', $_SESSION ) ) {
1457 + if ( $current_user_authenticated_by === 'google' || array_key_exists( 'token', $_SESSION ) ) {
1655 1458 $token = json_decode( $_SESSION['token'] )->access_token;
1656 1459
1657 - /**
1658 - * Add Google API PHP Client.
1659 - *
1660 - * @see https://github.com/google/google-api-php-client branch:v1-master
1661 - */
1460 + // Add Google API PHP Client.
1461 + // @see https://github.com/google/google-api-php-client branch:v1-master
1662 1462 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1663 1463
1664 1464 // Build the Google Client.
1665 1465 $client = new Google_Client();
@@ -1667,9 +1467,9 @@
1667 1467 $client->setClientId( $auth_settings['google_clientid'] );
1668 1468 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1669 1469 $client->setRedirectUri( 'postmessage' );
1670 1470
1671 - // Revoke the token.
1471 + // Revoke the token
1672 1472 $client->revokeToken( $token );
1673 1473
1674 1474 // Remove the credentials from the user's session.
1675 1475 unset( $_SESSION['token'] );
@@ -1688,61 +1488,60 @@
1688 1488
1689 1489
1690 1490 /**
1691 1491 * Restrict access to WordPress site based on settings (everyone, logged_in_users).
1492 + * Hook: parse_request http://codex.wordpress.org/Plugin_API/Action_Reference/parse_request
1692 1493 *
1693 - * Action: parse_request
1494 + * @param array $wp WordPress object.
1694 1495 *
1695 - * @param array $wp WordPress object.
1696 - * @return WP|void WP object when passing through to WordPress authentication, or void.
1496 + * @return void
1697 1497 */
1698 1498 public function restrict_access( $wp ) {
1699 1499 // Grab plugin settings.
1700 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1500 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1701 1501
1702 1502 // Grab current user.
1703 1503 $current_user = wp_get_current_user();
1704 1504
1705 1505 $has_access = (
1706 - // Always allow access if WordPress is installing.
1707 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1506 + // Always allow access if WordPress is installing
1708 1507 ( defined( 'WP_INSTALLING' ) && isset( $_GET['key'] ) ) ||
1709 - // Always allow access to admins.
1508 + // Always allow access to admins
1710 1509 ( current_user_can( 'create_users' ) ) ||
1711 - // Allow access if option is set to 'everyone'.
1712 - ( 'everyone' === $auth_settings['access_who_can_view'] ) ||
1713 - // Allow access to approved external users and logged in users if option is set to 'logged_in_users'.
1714 - ( 'logged_in_users' === $auth_settings['access_who_can_view'] && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1715 - // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API.
1716 - ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_oauth1=' ) === 0 ) ||
1717 - // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them.
1718 - ( property_exists( $wp, 'matched_query' ) && 0 === stripos( $wp->matched_query, 'rest_route=' ) && isset( $_SERVER['REQUEST_METHOD'] ) && 'GET' !== $_SERVER['REQUEST_METHOD'] ) ||
1719 - // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this.
1720 - ( property_exists( $wp, 'matched_query' ) && 'rest_route=/' === $wp->matched_query )
1510 + // Allow access if option is set to 'everyone'
1511 + ( $auth_settings['access_who_can_view'] == 'everyone' ) ||
1512 + // Allow access to approved external users and logged in users if option is set to 'logged_in_users'
1513 + ( $auth_settings['access_who_can_view'] == 'logged_in_users' && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1514 + // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API
1515 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_oauth1=" ) === 0 ) ||
1516 + // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them
1517 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] !== 'GET' ) ||
1518 + // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this
1519 + ( property_exists( $wp, 'matched_query' ) && $wp->matched_query === 'rest_route=/' )
1721 1520 // Note that GET requests to a rest endpoint will be restricted by authorizer. In that case, error messages will be returned as JSON.
1722 1521 );
1723 1522
1724 1523 /**
1725 - * Developers can use the `authorizer_has_access` filter to override
1726 - * restricted access on certain pages. Note that the restriction checks
1727 - * happens before WordPress executes any queries, so use the $wp variable
1728 - * to investigate what the visitor is trying to load.
1524 + * Developers can use the `authorizer_has_access` filter
1525 + * to override restricted access on certain pages. Note that the
1526 + * restriction checks happens before WordPress executes any queries, so
1527 + * use the global `$wp` variable to investigate what the visitor is
1528 + * trying to load.
1729 1529 *
1730 1530 * For example, to unblock an RSS feed, place the following PHP code in
1731 1531 * the theme's functions.php file or in a simple plug-in:
1732 1532 *
1733 - * function my_feed_access_override( $has_access, $wp ) {
1734 - * // Check query variables to see if this is the feed.
1735 - * if ( ! empty( $wp->query_vars['feed'] ) ) {
1533 + * function my_rsa_feed_access_override( $has_access ) {
1534 + * global $wp;
1535 + * // check query variables to see if this is the feed
1536 + * if ( ! empty( $wp->query_vars['feed'] ) )
1736 1537 * $has_access = true;
1737 - * }
1738 - *
1739 1538 * return $has_access;
1740 1539 * }
1741 - * add_filter( 'authorizer_has_access', 'my_feed_access_override', 10, 2 );
1540 + * add_filter( 'authorizer_has_access', 'my_rsa_feed_access_override' );
1742 1541 */
1743 1542 if ( apply_filters( 'authorizer_has_access', $has_access, $wp ) === true ) {
1744 - // Turn off the public notice about browsing anonymously.
1543 + // Turn off the public notice about browsing anonymously
1745 1544 update_option( 'auth_settings_advanced_public_notice', false );
1746 1545
1747 1546 // We've determined that the current user has access, so simply return to grant access.
1748 1547 return $wp;
@@ -1748,13 +1547,13 @@
1748 1547 return $wp;
1749 1548 }
1750 1549
1751 1550 // Allow HEAD requests to the root (usually discovery from a REST client).
1752 - if ( 'HEAD' === $_SERVER['REQUEST_METHOD'] && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1551 + if ( $_SERVER['REQUEST_METHOD'] === 'HEAD' && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1753 1552 return $wp;
1754 1553 }
1755 1554
1756 - /* We've determined that the current user doesn't have access, so we deal with them now. */
1555 + // We've determined that the current user doesn't have access, so we deal with them now.
1757 1556
1758 1557 // Fringe case: In a multisite, a user of a different blog can successfully
1759 1558 // log in, but they aren't on the 'approved' whitelist for this blog.
1760 1559 // If that's the case, add them to the pending list for this blog.
@@ -1765,19 +1564,29 @@
1765 1564 $result = $this->check_user_access( $current_user, array( $current_user->user_email ) );
1766 1565 }
1767 1566
1768 1567 // Check to see if the requested page is public. If so, show it.
1568 + $current_page_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'name', $wp->query_vars ) && strlen( $wp->query_vars['name'] ) > 0 ? $wp->query_vars['name'] : '';
1569 + if ( ! $current_page_name ) {
1570 + // Different WordPress versions store the page slug in different places; look for it elsewhere.
1571 + if ( property_exists( $wp, 'query_vars' ) && array_key_exists( 'pagename', $wp->query_vars ) && strlen( $wp->query_vars['pagename'] ) > 0 ) {
1572 + $current_page_name = $wp->query_vars['pagename'];
1573 + }
1574 + }
1575 + $current_page_id = '';
1769 1576 if ( empty( $wp->request ) ) {
1770 1577 $current_page_id = 'home';
1771 1578 } else {
1772 - $request_query = isset( $wp->query_vars ) ? new WP_Query( $wp->query_vars ) : null;
1773 - $current_page_id = isset( $request_query->post_count ) && $request_query->post_count > 0 ? $request_query->post->ID : '';
1579 + $current_page = get_page_by_path( $current_page_name );
1580 + if ( is_object( $current_page ) && isset( $current_page->ID ) ) {
1581 + $current_page_id = $current_page->ID;
1582 + }
1774 1583 }
1775 1584 if ( ! array_key_exists( 'access_public_pages', $auth_settings ) || ! is_array( $auth_settings['access_public_pages'] ) ) {
1776 1585 $auth_settings['access_public_pages'] = array();
1777 1586 }
1778 - if ( in_array( strval( $current_page_id ), $auth_settings['access_public_pages'], true ) ) {
1779 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1587 + if ( in_array( $current_page_id, $auth_settings['access_public_pages'] ) ) {
1588 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1780 1589 update_option( 'auth_settings_advanced_public_notice', false );
1781 1590 } else {
1782 1591 update_option( 'auth_settings_advanced_public_notice', true );
1783 1592 }
@@ -1785,11 +1594,11 @@
1785 1594 }
1786 1595
1787 1596 // Check to see if any category assigned to the requested page is public. If so, show it.
1788 1597 $current_page_categories = wp_get_post_categories( $current_page_id, array( 'fields' => 'slugs' ) );
1789 - foreach ( $current_page_categories as $current_page_category ) {
1790 - if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'], true ) ) {
1791 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1598 + foreach( $current_page_categories as $current_page_category ) {
1599 + if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'] ) ) {
1600 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1792 1601 update_option( 'auth_settings_advanced_public_notice', false );
1793 1602 } else {
1794 1603 update_option( 'auth_settings_advanced_public_notice', true );
1795 1604 }
@@ -1797,11 +1606,11 @@
1797 1606 }
1798 1607 }
1799 1608
1800 1609 // Check to see if this page can't be found. If so, allow showing the 404 page.
1801 - if ( strlen( $current_page_id ) < 1 ) {
1802 - if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'], true ) ) {
1803 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1610 + if ( strlen( $current_page_name ) > 0 && strlen( $current_page_id ) < 1 ) {
1611 + if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'] ) ) {
1612 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1804 1613 update_option( 'auth_settings_advanced_public_notice', false );
1805 1614 } else {
1806 1615 update_option( 'auth_settings_advanced_public_notice', true );
1807 1616 }
@@ -1806,8 +1615,9 @@
1806 1615 update_option( 'auth_settings_advanced_public_notice', true );
1807 1616 }
1808 1617 return $wp;
1809 1618 }
1619 +
1810 1620 }
1811 1621
1812 1622 // Check to see if the requested category is public. If so, show it.
1813 1623 $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
@@ -1812,10 +1622,10 @@
1812 1622 // Check to see if the requested category is public. If so, show it.
1813 1623 $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
1814 1624 if ( $current_category_name ) {
1815 1625 $current_category_name = end( explode( '/', $current_category_name ) );
1816 - if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'], true ) ) {
1817 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1626 + if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'] ) ) {
1627 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1818 1628 update_option( 'auth_settings_advanced_public_notice', false );
1819 1629 } else {
1820 1630 update_option( 'auth_settings_advanced_public_notice', true );
1821 1631 }
@@ -1825,20 +1635,18 @@
1825 1635
1826 1636 // User is denied access, so show them the error message. Render as JSON
1827 1637 // if this is a REST API call; otherwise, show the error message via
1828 1638 // wp_die() (rendered html), or redirect to the login URL.
1829 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1830 - if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_route=' ) === 0 && 'GET' === $_SERVER['REQUEST_METHOD'] ) {
1831 - wp_send_json(
1832 - array(
1833 - 'code' => 'rest_cannot_view',
1834 - 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1835 - 'data' => array(
1836 - 'status' => 401,
1837 - ),
1838 - )
1839 - );
1840 - } elseif ( 'message' === $auth_settings['access_redirect'] ) {
1639 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1640 + if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] === 'GET' ) {
1641 + wp_send_json( array(
1642 + 'code' => 'rest_cannot_view',
1643 + 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1644 + 'data' => array(
1645 + 'status' => 401,
1646 + ),
1647 + ));
1648 + } elseif ( $auth_settings['access_redirect'] === 'message' ) {
1841 1649 $page_title = sprintf(
1842 1650 /* TRANSLATORS: %s: Name of blog */
1843 1651 __( '%s - Access Restricted', 'authorizer' ),
1844 1652 get_bloginfo( 'name' )
@@ -1849,15 +1657,15 @@
1849 1657 '<p style="text-align: center;margin-bottom: -15px;">' .
1850 1658 '<a class="button" href="' . wp_login_url( $current_path ) . '">' .
1851 1659 __( 'Log In', 'authorizer' ) .
1852 1660 '</a></p>';
1853 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
1854 - } else {
1661 + wp_die( $error_message, $page_title );
1662 + } else { // if ( $auth_settings['access_redirect'] === 'login' ) {
1855 1663 wp_redirect( wp_login_url( $current_path ), 302 );
1856 1664 exit;
1857 1665 }
1858 1666
1859 - // Sanity check: we should never get here.
1667 + // Sanity check: we should never get here
1860 1668 wp_die( '<p>Access denied.</p>', 'Site Access Restricted' );
1861 1669 }
1862 1670
1863 1671
@@ -1866,11 +1674,9 @@
1866 1674 * not yet been added to this particular blog in a multisite). Note: we do
1867 1675 * this because check_user_access() runs on the parse_request hook, which
1868 1676 * does not fire on wp-admin pages.
1869 1677 *
1870 - * Action: init
1871 - *
1872 - * @return void
1678 + * Hook: admin_menu
1873 1679 */
1874 1680 public function init__maybe_add_network_approved_user() {
1875 1681 global $current_user;
1876 1682
@@ -1885,10 +1691,10 @@
1885 1691 ) {
1886 1692 // Get all approved users.
1887 1693 $auth_settings_access_users_approved = $this->sanitize_user_list(
1888 1694 array_merge(
1889 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
1890 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
1695 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
1696 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
1891 1697 )
1892 1698 );
1893 1699
1894 1700 // Get user info (we need user role).
@@ -1900,9 +1706,9 @@
1900 1706 // Add user to blog.
1901 1707 add_user_to_blog( get_current_blog_id(), $current_user->ID, $user_info['role'] );
1902 1708
1903 1709 // Refresh user permissions.
1904 - $current_user = new WP_User( $current_user->ID ); // phpcs:ignore WordPress.Variables.GlobalVariables.OverrideProhibited
1710 + $current_user = new WP_User( $current_user->ID );
1905 1711 }
1906 1712 }
1907 1713
1908 1714
@@ -1916,15 +1722,11 @@
1916 1722
1917 1723
1918 1724 /**
1919 1725 * Add custom error message to login screen.
1920 - *
1921 1726 * Filter: login_errors
1922 - *
1923 - * @param string $errors Error description.
1924 - * @return string Error description with Authorizer errors added.
1925 1727 */
1926 - public function show_advanced_login_error( $errors ) {
1728 + function show_advanced_login_error( $errors ) {
1927 1729 $error = get_option( 'auth_settings_advanced_login_error' );
1928 1730 delete_option( 'auth_settings_advanced_login_error' );
1929 1731 $errors = ' ' . $error . "<br />\n";
1930 1732 return $errors;
@@ -1932,25 +1734,24 @@
1932 1734
1933 1735
1934 1736 /**
1935 1737 * Load external resources for the public-facing site.
1936 - *
1937 - * Action: wp_enqueue_scripts
1938 1738 */
1939 - public function auth_public_scripts() {
1940 - // Load (and localize) public scripts.
1941 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1942 - wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1739 + function auth_public_scripts() {
1740 + // Load (and localize) public scripts
1741 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1742 + wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1943 1743 $auth_localized = array(
1944 - 'wpLoginUrl' => wp_login_url( $current_path ),
1945 - 'publicWarning' => get_option( 'auth_settings_advanced_public_notice' ),
1946 - 'anonymousNotice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1947 - 'logIn' => esc_html__( 'Log In', 'authorizer' ),
1744 + 'wp_login_url' => wp_login_url( $current_path ),
1745 + 'public_warning' => get_option( 'auth_settings_advanced_public_notice' ),
1746 + 'anonymous_notice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1747 + 'log_in' => esc_html__( 'Log In', 'authorizer' ),
1948 1748 );
1949 1749 wp_localize_script( 'auth_public_scripts', 'auth', $auth_localized );
1750 + //update_option( 'auth_settings_advanced_public_notice', false);
1950 1751
1951 - // Load public css.
1952 - wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.8.0' );
1752 + // Load public css
1753 + wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.3.2' );
1953 1754 wp_enqueue_style( 'authorizer-public-css' );
1954 1755 }
1955 1756
1956 1757
@@ -1956,21 +1757,19 @@
1956 1757
1957 1758 /**
1958 1759 * Enqueue JS scripts and CSS styles appearing on wp-login.php.
1959 1760 *
1960 - * Action: login_enqueue_scripts
1961 - *
1962 1761 * @return void
1963 1762 */
1964 - public function login_enqueue_scripts_and_styles() {
1763 + function login_enqueue_scripts_and_styles() {
1965 1764 // Grab plugin settings.
1966 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1765 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1967 1766
1968 1767 // Enqueue scripts appearing on wp-login.php.
1969 - wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1768 + wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1970 1769
1971 1770 // Enqueue styles appearing on wp-login.php.
1972 - wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.8.0' );
1771 + wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.3.2' );
1973 1772 wp_enqueue_style( 'authorizer-login-css' );
1974 1773
1975 1774 /**
1976 1775 * Developers can use the `authorizer_add_branding_option` filter
@@ -1975,8 +1774,9 @@
1975 1774 /**
1976 1775 * Developers can use the `authorizer_add_branding_option` filter
1977 1776 * to add a radio button for "Custom WordPress login branding"
1978 1777 * under the "Advanced" tab in Authorizer options. Example:
1778 + *
1979 1779 * function my_authorizer_add_branding_option( $branding_options ) {
1980 1780 * $new_branding_option = array(
1981 1781 * 'value' => 'your_brand'
1982 1782 * 'description' => 'Custom Your Brand Login Screen',
@@ -1990,23 +1790,23 @@
1990 1790 */
1991 1791 $branding_options = array();
1992 1792 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
1993 1793 foreach ( $branding_options as $branding_option ) {
1994 - // Make sure the custom brands have the required values.
1794 + // Make sure the custom brands have the required values
1995 1795 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'css_url', $branding_option ) && array_key_exists( 'js_url', $branding_option ) ) ) {
1996 1796 continue;
1997 1797 }
1998 1798 if ( $auth_settings['advanced_branding'] === $branding_option['value'] ) {
1999 - wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.8.0' );
2000 - wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.8.0' );
1799 + wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.3.2' );
1800 + wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.3.2' );
2001 1801 wp_enqueue_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ) );
2002 1802 }
2003 1803 }
2004 1804
2005 1805 // If we're using Google logins, load those resources.
2006 - if ( '1' === $auth_settings['google'] ) {
2007 - wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); ?>
2008 - <meta name="google-signin-clientid" content="<?php echo esc_attr( $auth_settings['google_clientid'] ); ?>" />
1806 + if ( $auth_settings['google'] === '1' ) {
1807 + wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); ?>
1808 + <meta name="google-signin-clientid" content="<?php echo $auth_settings['google_clientid']; ?>" />
2009 1809 <meta name="google-signin-scope" content="email" />
2010 1810 <meta name="google-signin-cookiepolicy" content="single_host_origin" />
2011 1811 <?php
2012 1812 }
@@ -2014,127 +1814,110 @@
2014 1814
2015 1815
2016 1816 /**
2017 1817 * Load external resources in the footer of the wp-login.php page.
2018 - *
2019 - * Action: login_footer
1818 + * Run on action hook: login_footer
2020 1819 */
2021 - public function load_login_footer_js() {
1820 + function load_login_footer_js() {
2022 1821 // Grab plugin settings.
2023 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2024 - $ajaxurl = admin_url( 'admin-ajax.php' );
2025 - if ( '1' === $auth_settings['google'] ) :
2026 - ?>
2027 -<script type="text/javascript">
2028 -/* global location, window */
2029 -// Reload login page if reauth querystring param exists,
2030 -// since reauth interrupts external logins (e.g., google).
2031 -if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
2032 - location.href = location.href.replace( 'reauth=1', '' );
2033 -}
1822 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
1823 + <?php if ( $auth_settings['google'] === '1' ): ?>
1824 + <script type="text/javascript">
1825 + // Reload login page if reauth querystring param exists,
1826 + // since reauth interrupts external logins (e.g., google).
1827 + if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
1828 + location.href = location.href.replace( 'reauth=1', '' );
1829 + }
2034 1830
2035 -// eslint-disable-next-line no-implicit-globals
2036 -function authUpdateQuerystringParam( uri, key, value ) {
2037 - var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
2038 - var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
2039 - if ( uri.match( re ) ) {
2040 - return uri.replace( re, '$1' + key + '=' + value + '$2' );
2041 - } else {
2042 - return uri + separator + key + '=' + value;
2043 - }
2044 -}
1831 + function auth_update_querystring_param( uri, key, value ) {
1832 + var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
1833 + var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
1834 + if ( uri.match( re ) ) {
1835 + return uri.replace( re, '$1' + key + '=' + value + '$2' );
1836 + } else {
1837 + return uri + separator + key + '=' + value;
1838 + }
1839 + }
2045 1840
2046 -// eslint-disable-next-line
2047 -function signInCallback( authResult ) { // jshint ignore:line
2048 - var $ = jQuery;
2049 - if ( authResult.status && authResult.status.signed_in ) {
2050 - // Hide the sign-in button now that the user is authorized, for example:
2051 - $( '#googleplus_button' ).attr( 'style', 'display: none' );
1841 + function signInCallback( authResult ) {
1842 + var $ = jQuery;
1843 + if ( authResult['status'] && authResult['status']['signed_in'] ) {
1844 + // Hide the sign-in button now that the user is authorized, for example:
1845 + $( '#googleplus_button' ).attr( 'style', 'display: none' );
2052 1846
2053 - // Send the code to the server
2054 - var ajaxurl = '<?php echo esc_attr( $ajaxurl ); ?>';
2055 - $.post(ajaxurl, {
2056 - action: 'process_google_login',
2057 - code: authResult.code,
2058 - nonce: $('#nonce_google_auth-<?php echo esc_attr( $this->get_cookie_value() ); ?>' ).val(),
2059 - }, function() {
2060 - // Handle or verify the server response if necessary.
2061 - // console.log( response );
1847 + // Send the code to the server
1848 + var ajaxurl = '<?php echo admin_url( "admin-ajax.php" ); ?>';
1849 + $.post(ajaxurl, {
1850 + action: 'process_google_login',
1851 + 'code': authResult['code'],
1852 + 'nonce': $('#nonce_google_auth-<?php echo $this->get_cookie_value(); ?>' ).val(),
1853 + }, function( response ) {
1854 + // Handle or verify the server response if necessary.
1855 + //console.log( response );
2062 1856
2063 - // Reload wp-login.php to continue the authentication process.
2064 - var newHref = authUpdateQuerystringParam( location.href, 'external', 'google' );
2065 - if ( location.href === newHref ) {
2066 - location.reload();
2067 - } else {
2068 - location.href = newHref;
2069 - }
2070 - });
2071 - } else {
2072 - // Update the app to reflect a signed out user
2073 - // Possible error values:
2074 - // "user_signed_out" - User is signed-out
2075 - // "access_denied" - User denied access to your app
2076 - // "immediate_failed" - Could not automatically log in the user
2077 - // console.log('Sign-in state: ' + authResult['error']);
1857 + // Reload wp-login.php to continue the authentication process.
1858 + var new_href = auth_update_querystring_param( location.href, 'external', 'google' );
1859 + if ( location.href === new_href ) {
1860 + location.reload();
1861 + } else {
1862 + location.href = new_href;
1863 + }
1864 + });
1865 + } else {
1866 + // Update the app to reflect a signed out user
1867 + // Possible error values:
1868 + // "user_signed_out" - User is signed-out
1869 + // "access_denied" - User denied access to your app
1870 + // "immediate_failed" - Could not automatically log in the user
1871 + //console.log('Sign-in state: ' + authResult['error']);
2078 1872
2079 - // If user denies access, reload the login page.
2080 - if ( authResult.error === 'access_denied' || authResult.error === 'user_signed_out' ) {
2081 - window.location.reload();
1873 + // If user denies access, reload the login page.
1874 + if ( authResult['error'] === 'access_denied' || authResult['error'] === 'user_signed_out' ) {
1875 + window.location.reload();
1876 + }
1877 + }
1878 + }
1879 + </script>
1880 + <?php endif;
2082 1881 }
2083 - }
2084 -}
2085 -</script>
2086 - <?php
2087 - endif;
2088 - }
2089 1882
2090 1883
2091 1884 /**
2092 1885 * Create links for any external authentication services that are enabled.
2093 - *
2094 - * Action: login_form
2095 1886 */
2096 - public function login_form_add_external_service_links() {
1887 + function login_form_add_external_service_links() {
2097 1888 // Grab plugin settings.
2098 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2099 - ?>
1889 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
2100 1890 <div id="auth-external-service-login">
2101 - <?php if ( '1' === $auth_settings['google'] ) : ?>
2102 - <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php esc_html_e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
1891 + <?php if ( $auth_settings['google'] === '1' ): ?>
1892 + <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php _e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
2103 1893 <?php wp_nonce_field( 'google_csrf_nonce', 'nonce_google_auth-' . $this->get_cookie_value() ); ?>
2104 1894 <?php endif; ?>
2105 1895
2106 - <?php if ( '1' === $auth_settings['cas'] ) : ?>
2107 - <p><a class="button button-primary button-external button-cas" href="<?php echo esc_attr( $this->modify_current_url_for_cas_login() ); ?>">
1896 + <?php if ( $auth_settings['cas'] === '1' ): ?>
1897 + <p><a class="button button-primary button-external button-cas" href="<?php echo $this->modify_current_url_for_cas_login(); ?>">
2108 1898 <span class="dashicons dashicons-lock"></span>
2109 - <span class="label">
2110 - <?php
2111 - echo esc_html(
2112 - sprintf(
2113 - /* TRANSLATORS: %s: Custom CAS label from authorizer options */
2114 - __( 'Sign in with %s', 'authorizer' ),
2115 - $auth_settings['cas_custom_label']
2116 - )
1899 + <span class="label"><?php
1900 + printf(
1901 + /* TRANSLATORS: %s: Custom CAS label from authorizer options */
1902 + __( 'Sign in with %s', 'authorizer' ),
1903 + $auth_settings['cas_custom_label']
2117 1904 );
2118 - ?>
2119 - </span>
1905 + ?></span>
2120 1906 </a></p>
2121 1907 <?php endif; ?>
2122 1908
2123 - <?php if ( '1' === $auth_settings['advanced_hide_wp_login'] && isset( $_SERVER['QUERY_STRING'] ) && false === strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) ) : // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput ?>
1909 + <?php if ( $auth_settings['advanced_hide_wp_login'] === '1' && strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false ): ?>
2124 1910 <style type="text/css">
2125 - body.login-action-login form {
2126 - padding-bottom: 8px;
1911 + #loginform {
1912 + padding-bottom: 8px !important;
2127 1913 }
2128 - body.login-action-login form p > label,
2129 - body.login-action-login form .forgetmenot,
2130 - body.login-action-login form .submit,
2131 - body.login-action-login #nav { /* csslint allow: ids */
2132 - display: none;
1914 + #loginform p>label, #loginform p.forgetmenot, #loginform p.submit, p#nav {
1915 + display: none !important;
2133 1916 }
2134 1917 </style>
2135 - <?php elseif ( '1' === $auth_settings['cas'] || '1' === $auth_settings['google'] ) : ?>
2136 - <h3> &mdash; <?php esc_html_e( 'or', 'authorizer' ); ?> &mdash; </h3>
1918 + <?php elseif ( $auth_settings['cas'] === '1' || $auth_settings['google'] === '1' ): ?>
1919 + <h3> &mdash; <?php _e( 'or', 'authorizer' ); ?> &mdash; </h3>
2137 1920 <?php endif; ?>
2138 1921 </div>
2139 1922 <?php
2140 1923
@@ -2147,28 +1930,21 @@
2147 1930 * Note: hook into wp_login_errors filter so this fires after the
2148 1931 * authenticate hook (where the redirect to CAS happens), but before html
2149 1932 * output is started (so the redirect header doesn't complain about data
2150 1933 * already being sent).
2151 - *
2152 - * Filter: wp_login_errors
2153 - *
2154 - * @param object $errors WP Error object.
2155 - * @param string $redirect_to Where to redirect on error.
2156 - * @return WP_Error|void WP Error object or void on redirect.
2157 1934 */
2158 - public function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
1935 + function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
2159 1936 // Grab plugin settings.
2160 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1937 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2161 1938
2162 1939 // Check whether we should redirect to CAS.
2163 1940 if (
2164 - isset( $_SERVER['QUERY_STRING'] ) &&
2165 - strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false && // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput
2166 - array_key_exists( 'cas_auto_login', $auth_settings ) && '1' === $auth_settings['cas_auto_login'] &&
2167 - array_key_exists( 'cas', $auth_settings ) && '1' === $auth_settings['cas'] &&
2168 - ( ! array_key_exists( 'ldap', $auth_settings ) || '1' !== $auth_settings['ldap'] ) &&
2169 - ( ! array_key_exists( 'google', $auth_settings ) || '1' !== $auth_settings['google'] ) &&
2170 - array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && '1' === $auth_settings['advanced_hide_wp_login']
1941 + strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false &&
1942 + array_key_exists( 'cas_auto_login', $auth_settings ) && $auth_settings['cas_auto_login'] === '1' &&
1943 + array_key_exists( 'cas', $auth_settings ) && $auth_settings['cas'] === '1' &&
1944 + ( ! array_key_exists( 'ldap', $auth_settings ) || $auth_settings['ldap'] !== '1' ) &&
1945 + ( ! array_key_exists( 'google', $auth_settings ) || $auth_settings['google'] !== '1' ) &&
1946 + array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && $auth_settings['advanced_hide_wp_login'] === '1'
2171 1947 ) {
2172 1948 wp_redirect( $this->modify_current_url_for_cas_login() );
2173 1949 exit;
2174 1950 }
@@ -2177,45 +1953,15 @@
2177 1953 }
2178 1954
2179 1955
2180 1956 /**
2181 - * Set a unique cookie to add to Google auth nonce to avoid CSRF detection.
2182 - * Note: hook into login_init so this fires at the start of the visit to
2183 - * wp-login.php, but before any html output is started (so setting the
2184 - * cookie header doesn't complain about data already being sent).
2185 - *
2186 - * Action: login_init
2187 - *
2188 - * @return void
2189 - */
2190 - public function login_init__maybe_set_google_nonce_cookie() {
2191 - // Grab plugin settings.
2192 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2193 -
2194 - // If Google logins are enabled, make sure the cookie is set.
2195 - if ( array_key_exists( 'google', $auth_settings ) && '1' === $auth_settings['google'] ) {
2196 - if ( ! isset( $_COOKIE['login_unique'] ) ) {
2197 - $this->cookie_value = md5( rand() );
2198 - setcookie( 'login_unique', $this->cookie_value, time() + 1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
2199 - $_COOKIE['login_unique'] = $this->cookie_value;
2200 - }
2201 - }
2202 - }
2203 -
2204 -
2205 - /**
2206 1957 * Implements hook: do_action( 'wp_login_failed', $username );
2207 1958 * Update the user meta for the user that just failed logging in.
2208 1959 * Keep track of time of last failed attempt and number of failed attempts.
2209 - *
2210 - * Action: wp_login_failed
2211 - *
2212 - * @param string $username Username to update login count for.
2213 - * @return void
2214 1960 */
2215 - public function update_login_failed_count( $username ) {
1961 + function update_login_failed_count( $username ) {
2216 1962 // Grab plugin settings.
2217 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1963 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2218 1964
2219 1965 // Get user trying to log in.
2220 1966 // If this isn't a real user, update the global failed attempt
2221 1967 // variables. We'll use these global variables to institute the
@@ -2223,9 +1969,9 @@
2223 1969 // won't be able to determine which accounts are real by which
2224 1970 // accounts get locked out on multiple invalid attempts.
2225 1971 $user = get_user_by( 'login', $username );
2226 1972
2227 - if ( false !== $user ) {
1973 + if ( $user !== FALSE ) {
2228 1974 $last_attempt = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
2229 1975 $num_attempts = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
2230 1976 } else {
2231 1977 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
@@ -2239,15 +1985,15 @@
2239 1985
2240 1986 // Reset the failed attempt count if the time since the last
2241 1987 // failed attempt is greater than the reset duration.
2242 1988 $time_since_last_fail = time() - $last_attempt;
2243 - $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds.
1989 + $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds
2244 1990 if ( $time_since_last_fail > $reset_duration ) {
2245 1991 $num_attempts = 0;
2246 1992 }
2247 1993
2248 1994 // Set last failed time to now and increment last failed count.
2249 - if ( false !== $user ) {
1995 + if ( $user !== FALSE ) {
2250 1996 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', time() );
2251 1997 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', $num_attempts + 1 );
2252 1998 } else {
2253 1999 update_option( 'auth_settings_advanced_lockouts_time_last_failed', time() );
@@ -2258,16 +2004,16 @@
2258 2004
2259 2005 /**
2260 2006 * When they successfully log in, make sure WordPress users are in the approved list.
2261 2007 *
2262 - * Action: wp_login
2008 + * @action wp_login
2263 2009 *
2264 2010 * @param string $user_login Username of the user logging in.
2265 - * @param object $user WP_User object of the user logging in.
2266 - * @return void
2011 + * @param WP_User $user WP_User object of the user logging in.
2012 + * @return null
2267 2013 */
2268 - public function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2269 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
2014 + function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2015 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
2270 2016 }
2271 2017
2272 2018
2273 2019 /**
@@ -2273,17 +2019,12 @@
2273 2019 /**
2274 2020 * Overwrite the URL for the lost password link on the login form.
2275 2021 * If we're authenticating against an external service, standard
2276 2022 * WordPress password resets won't work.
2277 - *
2278 - * Filter: lostpassword_url
2279 - *
2280 - * @param string $lostpassword_url URL to reset password.
2281 - * @return string URL to reset password.
2282 2023 */
2283 - public function custom_lostpassword_url( $lostpassword_url ) {
2024 + function custom_lostpassword_url( $lostpassword_url ) {
2284 2025 // Grab plugin settings.
2285 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2026 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2286 2027
2287 2028 if (
2288 2029 array_key_exists( 'ldap_lostpassword_url', $auth_settings ) &&
2289 2030 filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_VALIDATE_URL )
@@ -2306,16 +2047,15 @@
2306 2047 /**
2307 2048 * Add a link to this plugin's settings page from the WordPress Plugins page.
2308 2049 * Called from "plugin_action_links" filter in __construct() above.
2309 2050 *
2310 - * Filter: plugin_action_links_authorizer.php
2051 + * @param array $links array of links in the admin sidebar
2311 2052 *
2312 - * @param array $links Admin sidebar links.
2313 - * @return array Admin sidebar links with Authorizer added.
2053 + * @return array of links to show in the admin sidebar.
2314 2054 */
2315 2055 public function plugin_settings_link( $links ) {
2316 - $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2317 - $settings_url = 'settings' === $admin_menu ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2056 + $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2057 + $settings_url = $admin_menu === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2318 2058 array_unshift( $links, '<a href="' . $settings_url . '">' . __( 'Settings', 'authorizer' ) . '</a>' );
2319 2059 return $links;
2320 2060 }
2321 2061
@@ -2323,12 +2063,11 @@
2323 2063 /**
2324 2064 * Add a link to this plugin's network settings page from the WordPress Plugins page.
2325 2065 * Called from "network_admin_plugin_action_links" filter in __construct() above.
2326 2066 *
2327 - * Filter: network_admin_plugin_action_links_authorizer.php
2067 + * @param array $links array of links in the network admin sidebar
2328 2068 *
2329 - * @param array $links Network admin sidebar links.
2330 - * @return array Network admin sidebar links with Authorizer added.
2069 + * @return array of links to show in the network admin sidebar.
2331 2070 */
2332 2071 public function network_admin_plugin_settings_link( $links ) {
2333 2072 $settings_link = '<a href="admin.php?page=authorizer">' . __( 'Network Settings', 'authorizer' ) . '</a>';
2334 2073 array_unshift( $links, $settings_link );
@@ -2336,33 +2075,32 @@
2336 2075 }
2337 2076
2338 2077
2339 2078 /**
2340 - * Create the options page under Dashboard > Settings.
2341 - *
2342 - * Action: admin_menu
2079 + * Create the options page under Dashboard > Settings
2080 + * Run on action hook: admin_menu
2343 2081 */
2344 2082 public function add_plugin_page() {
2345 2083 $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2346 - if ( 'settings' === $admin_menu ) {
2084 + if ( $admin_menu === 'settings' ) {
2347 2085 // @see http://codex.wordpress.org/Function_Reference/add_options_page
2348 2086 add_options_page(
2349 - 'Authorizer',
2350 - 'Authorizer',
2351 - 'create_users',
2352 - 'authorizer',
2353 - array( $this, 'create_admin_page' )
2087 + 'Authorizer', // Page title
2088 + 'Authorizer', // Menu title
2089 + 'create_users', // Capability
2090 + 'authorizer', // Menu slug
2091 + array( $this, 'create_admin_page' ) // function
2354 2092 );
2355 2093 } else {
2356 2094 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
2357 2095 add_menu_page(
2358 - 'Authorizer',
2359 - 'Authorizer',
2360 - 'create_users',
2361 - 'authorizer',
2362 - array( $this, 'create_admin_page' ),
2363 - 'dashicons-groups',
2364 - '99.0018465' // position (decimal is to make overlap with other plugins less likely).
2096 + 'Authorizer', // Page title
2097 + 'Authorizer', // Menu title
2098 + 'create_users', // Capability
2099 + 'authorizer', // Menu slug
2100 + array( $this, 'create_admin_page' ), // callback
2101 + 'dashicons-groups', // icon
2102 + '99.0018465' // position (decimal is to make overlap with other plugins less likely)
2365 2103 );
2366 2104 }
2367 2105 }
2368 2106
@@ -2367,75 +2105,56 @@
2367 2105 }
2368 2106
2369 2107
2370 2108 /**
2371 - * Output the HTML for the options page.
2109 + * Output the HTML for the options page
2372 2110 */
2373 - public function create_admin_page() {
2374 - ?>
2111 + public function create_admin_page() { ?>
2375 2112 <div class="wrap">
2376 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2377 - <form method="post" action="options.php" autocomplete="off">
2378 - <?php
2379 - // This prints out all hidden settings fields.
2113 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2114 + <form method="post" action="options.php" autocomplete="off"><?php
2115 + // This prints out all hidden settings fields
2116 + // @see http://codex.wordpress.org/Function_Reference/settings_fields
2380 2117 settings_fields( 'auth_settings_group' );
2381 - // This prints out all the sections.
2118 + // This prints out all the sections
2119 + // @see http://codex.wordpress.org/Function_Reference/do_settings_sections
2382 2120 do_settings_sections( 'authorizer' );
2383 - submit_button();
2384 - ?>
2121 + submit_button(); ?>
2385 2122 </form>
2386 - </div>
2387 - <?php
2123 + </div><?php
2388 2124 }
2389 2125
2390 2126
2391 2127 /**
2392 2128 * Load external resources on this plugin's options page.
2393 - *
2394 - * Action: load-settings_page_authorizer
2395 - * Action: load-toplevel_page_authorizer
2396 - * Action: admin_head-index.php
2129 + * Run on action hooks: load-settings_page_authorizer, load-toplevel_page_authorizer, admin_head-index.php
2397 2130 */
2398 2131 public function load_options_page() {
2399 2132 wp_enqueue_script(
2400 2133 'authorizer',
2401 2134 plugins_url( 'js/authorizer.js', __FILE__ ),
2402 - array( 'jquery-effects-shake' ), '2.8.6', true
2135 + array( 'jquery-effects-shake' ), '2.3.2', true
2403 2136 );
2404 - wp_localize_script(
2405 - 'authorizer', 'authL10n', array(
2406 - 'baseurl' => get_bloginfo( 'url' ),
2407 - 'saved' => esc_html__( 'Saved', 'authorizer' ),
2408 - 'duplicate' => esc_html__( 'Duplicate', 'authorizer' ),
2409 - 'failed' => esc_html__( 'Failed', 'authorizer' ),
2410 - 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2411 - 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2412 - 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2413 - 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2414 - 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2415 - 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2416 - 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2417 - 'first_page' => esc_html__( 'First page' ),
2418 - 'previous_page' => esc_html__( 'Previous page' ),
2419 - 'next_page' => esc_html__( 'Next page' ),
2420 - 'last_page' => esc_html__( 'Last page' ),
2421 - 'is_network_admin' => is_network_admin() ? '1' : '0',
2422 - )
2423 - );
2137 + wp_localize_script( 'authorizer', 'auth_L10n', array(
2138 + 'baseurl' => get_bloginfo( 'url' ),
2139 + 'saved' => esc_html__( 'Saved', 'authorizer' ),
2140 + 'failed' => esc_html__( 'Failed', 'authorizer' ),
2141 + 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2142 + 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2143 + 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2144 + 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2145 + 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2146 + 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2147 + 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2148 + ));
2424 2149
2425 2150 wp_enqueue_script(
2426 - 'jquery-autogrow-textarea',
2427 - plugins_url( 'vendor/jquery.autogrow-textarea/jquery.autogrow-textarea.js', __FILE__ ),
2428 - array( 'jquery' ), '2.7.0', true
2429 - );
2430 -
2431 - wp_enqueue_script(
2432 2151 'jquery.multi-select',
2433 2152 plugins_url( 'vendor/jquery.multi-select/js/jquery.multi-select.js', __FILE__ ),
2434 2153 array( 'jquery' ), '1.8', true
2435 2154 );
2436 2155
2437 - wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.7.3' );
2156 + wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.3.2' );
2438 2157 wp_enqueue_style( 'authorizer-css' );
2439 2158
2440 2159 wp_register_style( 'jquery-multi-select-css', plugins_url( 'vendor/jquery.multi-select/css/multi-select.css', __FILE__ ), array(), '1.8' );
2441 2160 wp_enqueue_style( 'jquery-multi-select-css' );
@@ -2446,26 +2165,18 @@
2446 2165
2447 2166
2448 2167 /**
2449 2168 * Show custom admin notice.
2450 - *
2451 - * Note: currently unused, but if anywhere we:
2452 - * add_option( 'auth_settings_advanced_admin_notice, 'Your message.' );
2453 - * It will display and then delete that message on the admin dashboard.
2454 - *
2455 - * Filter: admin_notices
2456 - * filter: network_admin_notices
2169 + * Filter: admin_notice
2457 2170 */
2458 - public function show_advanced_admin_notice() {
2171 + function show_advanced_admin_notice() {
2459 2172 $notice = get_option( 'auth_settings_advanced_admin_notice' );
2460 2173 delete_option( 'auth_settings_advanced_admin_notice' );
2461 2174
2462 - if ( $notice && strlen( $notice ) > 0 ) {
2463 - ?>
2175 + if ( $notice && strlen( $notice ) > 0 ) { ?>
2464 2176 <div class="error">
2465 - <p><?php echo wp_kses( $notice, $this->allowed_html ); ?></p>
2466 - </div>
2467 - <?php
2177 + <p><?php echo $notice; ?></p>
2178 + </div><?php
2468 2179 }
2469 2180 }
2470 2181
2471 2182
@@ -2470,11 +2181,9 @@
2470 2181
2471 2182
2472 2183 /**
2473 2184 * Add notices to the top of the options page.
2474 - *
2475 - * Action: load-settings_page_authorizer > admin_notices
2476 - *
2185 + * Run on action hook chain: load-settings_page_authorizer > admin_notices
2477 2186 * Description: Check for invalid settings combinations and show a warning message, e.g.:
2478 2187 * if ( cas url inaccessible ) : ?>
2479 2188 * <div class='updated settings-error'><p>Can't reach CAS server.</p></div>
2480 2189 * <?php endif;
@@ -2480,23 +2189,20 @@
2480 2189 * <?php endif;
2481 2190 */
2482 2191 public function admin_notices() {
2483 2192 // Grab plugin settings.
2484 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2193 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2485 2194
2486 - if ( '1' === $auth_settings['cas'] ) :
2195 + if ( $auth_settings['cas'] === '1' ) :
2487 2196 // Check if provided CAS URL is accessible.
2488 - $protocol = in_array( strval( $auth_settings['cas_port'] ), array( '80', '8080' ), true ) ? 'http' : 'https';
2489 - $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2490 - $legacy_cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint (old; some servers don't register a ./login endpoint, use serviceValidate instead).
2491 - $cas_url = trailingslashit( $cas_url ) . 'serviceValidate'; // Check the specific CAS login endpoint.
2492 - if ( ! $this->url_is_accessible( $cas_url ) && ! $this->url_is_accessible( $legacy_cas_url ) ) :
2493 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2494 - ?>
2495 - <div class='notice notice-warning is-dismissible'>
2496 - <p><?php esc_html_e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo esc_attr( $authorizer_options_url ); ?>&tab=external'><?php esc_html_e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php esc_html_e( 'if you intend to use it.', 'authorizer' ); ?></p>
2497 - </div>
2498 - <?php
2197 + $protocol = in_array( $auth_settings['cas_port'], array( '80', '8080' ) ) ? 'http' : 'https';
2198 + $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2199 + $cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint
2200 + if ( ! $this->url_is_accessible( $cas_url ) ) :
2201 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2202 + ?><div class='notice notice-warning is-dismissible'>
2203 + <p><?php _e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo $authorizer_options_url; ?>&tab=external'><?php _e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php _e( 'if you intend to use it.', 'authorizer' ); ?></p>
2204 + </div><?php
2499 2205 endif;
2500 2206 endif;
2501 2207 }
2502 2208
@@ -2501,430 +2207,399 @@
2501 2207 }
2502 2208
2503 2209
2504 2210 /**
2505 - * Create sections and options.
2506 - *
2507 - * Action: admin_init
2211 + * Create sections and options
2212 + * Run on action hook: admin_init
2508 2213 */
2509 2214 public function page_init() {
2510 - /**
2511 - * Create one setting that holds all the options (array).
2512 - *
2513 - * @see http://codex.wordpress.org/Function_Reference/register_setting
2514 - * @see http://codex.wordpress.org/Function_Reference/add_settings_section
2515 - * @see http://codex.wordpress.org/Function_Reference/add_settings_field
2516 - */
2215 + // Create one setting that holds all the options (array)
2216 + // @see http://codex.wordpress.org/Function_Reference/register_setting
2217 + // @see http://codex.wordpress.org/Function_Reference/add_settings_section
2218 + // @see http://codex.wordpress.org/Function_Reference/add_settings_field
2517 2219 register_setting(
2518 - 'auth_settings_group',
2519 - 'auth_settings',
2520 - array( $this, 'sanitize_options' )
2220 + 'auth_settings_group', // Option group
2221 + 'auth_settings', // Option name
2222 + array( $this, 'sanitize_options' ) // Sanitize callback
2521 2223 );
2522 2224
2523 2225 add_settings_section(
2524 - 'auth_settings_tabs',
2525 - '',
2526 - array( $this, 'print_section_info_tabs' ),
2527 - 'authorizer'
2226 + 'auth_settings_tabs', // HTML element ID
2227 + '', // HTML element Title
2228 + array( $this, 'print_section_info_tabs' ), // Callback (echos section content)
2229 + 'authorizer' // Page this section is shown on (slug)
2528 2230 );
2529 2231
2530 - // Create Access Lists section.
2232 + // Create Access Lists section
2531 2233 add_settings_section(
2532 - 'auth_settings_lists',
2533 - '',
2534 - array( $this, 'print_section_info_access_lists' ),
2535 - 'authorizer'
2234 + 'auth_settings_lists', // HTML element ID
2235 + '', // HTML element Title
2236 + array( $this, 'print_section_info_access_lists' ), // Callback (echos section content)
2237 + 'authorizer' // Page this section is shown on (slug)
2536 2238 );
2537 2239
2538 - // Create Login Access section.
2240 + // Create Login Access section
2539 2241 add_settings_section(
2540 - 'auth_settings_access_login',
2541 - '',
2542 - array( $this, 'print_section_info_access_login' ),
2543 - 'authorizer'
2242 + 'auth_settings_access_login', // HTML element ID
2243 + '', // HTML element Title
2244 + array( $this, 'print_section_info_access_login' ), // Callback (echos section content)
2245 + 'authorizer' // Page this section is shown on (slug)
2544 2246 );
2545 2247 add_settings_field(
2546 - 'auth_settings_access_who_can_login',
2547 - __( 'Who can log into the site?', 'authorizer' ),
2548 - array( $this, 'print_radio_auth_access_who_can_login' ),
2549 - 'authorizer',
2550 - 'auth_settings_access_login'
2248 + 'auth_settings_access_who_can_login', // HTML element ID
2249 + __( 'Who can log into the site?', 'authorizer' ), // HTML element Title
2250 + array( $this, 'print_radio_auth_access_who_can_login' ), // Callback (echos form element)
2251 + 'authorizer', // Page this setting is shown on (slug)
2252 + 'auth_settings_access_login' // Section this setting is shown on
2551 2253 );
2552 2254 add_settings_field(
2553 - 'auth_settings_access_role_receive_pending_emails',
2554 - __( 'Which role should receive email notifications about pending users?', 'authorizer' ),
2555 - array( $this, 'print_select_auth_access_role_receive_pending_emails' ),
2556 - 'authorizer',
2557 - 'auth_settings_access_login'
2255 + 'auth_settings_access_role_receive_pending_emails', // HTML element ID
2256 + __( 'Which role should receive email notifications about pending users?', 'authorizer' ), // HTML element Title
2257 + array( $this, 'print_select_auth_access_role_receive_pending_emails' ), // Callback (echos form element)
2258 + 'authorizer', // Page this setting is shown on (slug)
2259 + 'auth_settings_access_login' // Section this setting is shown on
2558 2260 );
2559 2261 add_settings_field(
2560 - 'auth_settings_access_pending_redirect_to_message',
2561 - __( 'What message should pending users see after attempting to log in?', 'authorizer' ),
2562 - array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ),
2563 - 'authorizer',
2564 - 'auth_settings_access_login'
2262 + 'auth_settings_access_pending_redirect_to_message', // HTML element ID
2263 + __( 'What message should pending users see after attempting to log in?', 'authorizer' ), // HTML element Title
2264 + array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ), // Callback (echos form element)
2265 + 'authorizer', // Page this setting is shown on (slug)
2266 + 'auth_settings_access_login' // Section this setting is shown on
2565 2267 );
2566 2268 add_settings_field(
2567 - 'auth_settings_access_blocked_redirect_to_message',
2568 - __( 'What message should blocked users see after attempting to log in?', 'authorizer' ),
2569 - array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ),
2570 - 'authorizer',
2571 - 'auth_settings_access_login'
2269 + 'auth_settings_access_blocked_redirect_to_message', // HTML element ID
2270 + __( 'What message should blocked users see after attempting to log in?', 'authorizer' ), // HTML element Title
2271 + array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ), // Callback (echos form element)
2272 + 'authorizer', // Page this setting is shown on (slug)
2273 + 'auth_settings_access_login' // Section this setting is shown on
2572 2274 );
2573 2275 add_settings_field(
2574 - 'auth_settings_access_should_email_approved_users',
2575 - __( 'Send welcome email to new approved users?', 'authorizer' ),
2576 - array( $this, 'print_checkbox_auth_access_should_email_approved_users' ),
2577 - 'authorizer',
2578 - 'auth_settings_access_login'
2276 + 'auth_settings_access_should_email_approved_users', // HTML element ID
2277 + __( 'Send welcome email to new approved users?', 'authorizer' ), // HTML element Title
2278 + array( $this, 'print_checkbox_auth_access_should_email_approved_users' ), // Callback (echos form element)
2279 + 'authorizer', // Page this setting is shown on (slug)
2280 + 'auth_settings_access_login' // Section this setting is shown on
2579 2281 );
2580 2282 add_settings_field(
2581 - 'auth_settings_access_email_approved_users_subject',
2582 - __( 'Welcome email subject', 'authorizer' ),
2583 - array( $this, 'print_text_auth_access_email_approved_users_subject' ),
2584 - 'authorizer',
2585 - 'auth_settings_access_login'
2283 + 'auth_settings_access_email_approved_users_subject', // HTML element ID
2284 + __( 'Welcome email subject', 'authorizer' ), // HTML element Title
2285 + array( $this, 'print_text_auth_access_email_approved_users_subject' ), // Callback (echos form element)
2286 + 'authorizer', // Page this setting is shown on (slug)
2287 + 'auth_settings_access_login' // Section this setting is shown on
2586 2288 );
2587 2289 add_settings_field(
2588 - 'auth_settings_access_email_approved_users_body',
2589 - __( 'Welcome email body', 'authorizer' ),
2590 - array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ),
2591 - 'authorizer',
2592 - 'auth_settings_access_login'
2290 + 'auth_settings_access_email_approved_users_body', // HTML element ID
2291 + __( 'Welcome email body', 'authorizer' ), // HTML element Title
2292 + array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ), // Callback (echos form element)
2293 + 'authorizer', // Page this setting is shown on (slug)
2294 + 'auth_settings_access_login' // Section this setting is shown on
2593 2295 );
2594 2296
2595 - // Create Public Access section.
2297 +
2298 + // Create Public Access section
2596 2299 add_settings_section(
2597 - 'auth_settings_access_public',
2598 - '',
2599 - array( $this, 'print_section_info_access_public' ),
2600 - 'authorizer'
2300 + 'auth_settings_access_public', // HTML element ID
2301 + '', // HTML element Title
2302 + array( $this, 'print_section_info_access_public' ), // Callback (echos section content)
2303 + 'authorizer' // Page this section is shown on (slug)
2601 2304 );
2602 2305 add_settings_field(
2603 - 'auth_settings_access_who_can_view',
2604 - __( 'Who can view the site?', 'authorizer' ),
2605 - array( $this, 'print_radio_auth_access_who_can_view' ),
2606 - 'authorizer',
2607 - 'auth_settings_access_public'
2306 + 'auth_settings_access_who_can_view', // HTML element ID
2307 + __( 'Who can view the site?', 'authorizer' ), // HTML element Title
2308 + array( $this, 'print_radio_auth_access_who_can_view' ), // Callback (echos form element)
2309 + 'authorizer', // Page this setting is shown on (slug)
2310 + 'auth_settings_access_public' // Section this setting is shown on
2608 2311 );
2609 2312 add_settings_field(
2610 - 'auth_settings_access_public_pages',
2611 - __( 'What pages (if any) should be available to everyone?', 'authorizer' ),
2612 - array( $this, 'print_multiselect_auth_access_public_pages' ),
2613 - 'authorizer',
2614 - 'auth_settings_access_public'
2313 + 'auth_settings_access_public_pages', // HTML element ID
2314 + __( 'What pages (if any) should be available to everyone?', 'authorizer' ), // HTML element Title
2315 + array( $this, 'print_multiselect_auth_access_public_pages' ), // Callback (echos form element)
2316 + 'authorizer', // Page this setting is shown on (slug)
2317 + 'auth_settings_access_public' // Section this setting is shown on
2615 2318 );
2616 2319 add_settings_field(
2617 - 'auth_settings_access_redirect',
2618 - __( 'What happens to people without access when they visit a private page?', 'authorizer' ),
2619 - array( $this, 'print_radio_auth_access_redirect' ),
2620 - 'authorizer',
2621 - 'auth_settings_access_public'
2320 + 'auth_settings_access_redirect', // HTML element ID
2321 + __( 'What happens to people without access when they visit a private page?', 'authorizer' ), // HTML element Title
2322 + array( $this, 'print_radio_auth_access_redirect' ), // Callback (echos form element)
2323 + 'authorizer', // Page this setting is shown on (slug)
2324 + 'auth_settings_access_public' // Section this setting is shown on
2622 2325 );
2623 2326 add_settings_field(
2624 - 'auth_settings_access_public_warning',
2625 - __( 'What happens to people without access when they visit a public page?', 'authorizer' ),
2626 - array( $this, 'print_radio_auth_access_public_warning' ),
2627 - 'authorizer',
2628 - 'auth_settings_access_public'
2327 + 'auth_settings_access_public_warning', // HTML element ID
2328 + __( 'What happens to people without access when they visit a public page?', 'authorizer' ), // HTML element Title
2329 + array( $this, 'print_radio_auth_access_public_warning' ), // Callback (echos form element)
2330 + 'authorizer', // Page this setting is shown on (slug)
2331 + 'auth_settings_access_public' // Section this setting is shown on
2629 2332 );
2630 2333 add_settings_field(
2631 - 'auth_settings_access_redirect_to_message',
2632 - __( 'What message should people without access see?', 'authorizer' ),
2633 - array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ),
2634 - 'authorizer',
2635 - 'auth_settings_access_public'
2334 + 'auth_settings_access_redirect_to_message', // HTML element ID
2335 + __( 'What message should people without access see?', 'authorizer' ), // HTML element Title
2336 + array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ), // Callback (echos form element)
2337 + 'authorizer', // Page this setting is shown on (slug)
2338 + 'auth_settings_access_public' // Section this setting is shown on
2636 2339 );
2637 2340
2638 - // Create External Service Settings section.
2341 + // Create External Service Settings section
2639 2342 add_settings_section(
2640 - 'auth_settings_external',
2641 - '',
2642 - array( $this, 'print_section_info_external' ),
2643 - 'authorizer'
2343 + 'auth_settings_external', // HTML element ID
2344 + '', // HTML element Title
2345 + array( $this, 'print_section_info_external' ), // Callback (echos section content)
2346 + 'authorizer' // Page this section is shown on (slug)
2644 2347 );
2645 2348 add_settings_field(
2646 - 'auth_settings_access_default_role',
2647 - __( 'Default role for new users', 'authorizer' ),
2648 - array( $this, 'print_select_auth_access_default_role' ),
2649 - 'authorizer',
2650 - 'auth_settings_external'
2349 + 'auth_settings_access_default_role', // HTML element ID
2350 + __( 'Default role for new users', 'authorizer' ), // HTML element Title
2351 + array( $this, 'print_select_auth_access_default_role' ), // Callback (echos form element)
2352 + 'authorizer', // Page this setting is shown on (slug)
2353 + 'auth_settings_external' // Section this setting is shown on
2651 2354 );
2652 2355 add_settings_field(
2653 - 'auth_settings_external_google',
2654 - __( 'Google Logins', 'authorizer' ),
2655 - array( $this, 'print_checkbox_auth_external_google' ),
2656 - 'authorizer',
2657 - 'auth_settings_external'
2356 + 'auth_settings_external_google', // HTML element ID
2357 + __( 'Google Logins', 'authorizer' ), // HTML element Title
2358 + array( $this, 'print_checkbox_auth_external_google' ), // Callback (echos form element)
2359 + 'authorizer', // Page this setting is shown on (slug)
2360 + 'auth_settings_external' // Section this setting is shown on
2658 2361 );
2659 2362 add_settings_field(
2660 - 'auth_settings_google_clientid',
2661 - __( 'Google Client ID', 'authorizer' ),
2662 - array( $this, 'print_text_google_clientid' ),
2663 - 'authorizer',
2664 - 'auth_settings_external'
2363 + 'auth_settings_google_clientid', // HTML element ID
2364 + __( 'Google Client ID', 'authorizer' ), // HTML element Title
2365 + array( $this, 'print_text_google_clientid' ), // Callback (echos form element)
2366 + 'authorizer', // Page this setting is shown on (slug)
2367 + 'auth_settings_external' // Section this setting is shown on
2665 2368 );
2666 2369 add_settings_field(
2667 - 'auth_settings_google_clientsecret',
2668 - __( 'Google Client Secret', 'authorizer' ),
2669 - array( $this, 'print_text_google_clientsecret' ),
2670 - 'authorizer',
2671 - 'auth_settings_external'
2370 + 'auth_settings_google_clientsecret', // HTML element ID
2371 + __( 'Google Client Secret', 'authorizer' ), // HTML element Title
2372 + array( $this, 'print_text_google_clientsecret' ), // Callback (echos form element)
2373 + 'authorizer', // Page this setting is shown on (slug)
2374 + 'auth_settings_external' // Section this setting is shown on
2672 2375 );
2673 2376 add_settings_field(
2674 - 'auth_settings_google_hosteddomain',
2675 - __( 'Google Hosted Domain', 'authorizer' ),
2676 - array( $this, 'print_text_google_hosteddomain' ),
2677 - 'authorizer',
2678 - 'auth_settings_external'
2377 + 'auth_settings_google_hosteddomain', // HTML element ID
2378 + __( 'Google Hosted Domain', 'authorizer' ), // HTML element Title
2379 + array( $this, 'print_text_google_hosteddomain' ), // Callback (echos form element)
2380 + 'authorizer', // Page this setting is shown on (slug)
2381 + 'auth_settings_external' // Section this setting is shown on
2679 2382 );
2680 2383 add_settings_field(
2681 - 'auth_settings_external_cas',
2682 - __( 'CAS Logins', 'authorizer' ),
2683 - array( $this, 'print_checkbox_auth_external_cas' ),
2684 - 'authorizer',
2685 - 'auth_settings_external'
2384 + 'auth_settings_external_cas', // HTML element ID
2385 + __( 'CAS Logins', 'authorizer' ), // HTML element Title
2386 + array( $this, 'print_checkbox_auth_external_cas' ), // Callback (echos form element)
2387 + 'authorizer', // Page this setting is shown on (slug)
2388 + 'auth_settings_external' // Section this setting is shown on
2686 2389 );
2687 2390 add_settings_field(
2688 - 'auth_settings_cas_custom_label',
2689 - __( 'CAS custom label', 'authorizer' ),
2690 - array( $this, 'print_text_cas_custom_label' ),
2691 - 'authorizer',
2692 - 'auth_settings_external'
2391 + 'auth_settings_cas_custom_label', // HTML element ID
2392 + __( 'CAS custom label', 'authorizer' ), // HTML element Title
2393 + array( $this, 'print_text_cas_custom_label' ), // Callback (echos form element)
2394 + 'authorizer', // Page this setting is shown on (slug)
2395 + 'auth_settings_external' // Section this setting is shown on
2693 2396 );
2694 2397 add_settings_field(
2695 - 'auth_settings_cas_host',
2696 - __( 'CAS server hostname', 'authorizer' ),
2697 - array( $this, 'print_text_cas_host' ),
2698 - 'authorizer',
2699 - 'auth_settings_external'
2398 + 'auth_settings_cas_host', // HTML element ID
2399 + __( 'CAS server hostname', 'authorizer' ), // HTML element Title
2400 + array( $this, 'print_text_cas_host' ), // Callback (echos form element)
2401 + 'authorizer', // Page this setting is shown on (slug)
2402 + 'auth_settings_external' // Section this setting is shown on
2700 2403 );
2701 2404 add_settings_field(
2702 - 'auth_settings_cas_port',
2703 - __( 'CAS server port', 'authorizer' ),
2704 - array( $this, 'print_text_cas_port' ),
2705 - 'authorizer',
2706 - 'auth_settings_external'
2405 + 'auth_settings_cas_port', // HTML element ID
2406 + __( 'CAS server port', 'authorizer' ), // HTML element Title
2407 + array( $this, 'print_text_cas_port' ), // Callback (echos form element)
2408 + 'authorizer', // Page this setting is shown on (slug)
2409 + 'auth_settings_external' // Section this setting is shown on
2707 2410 );
2708 2411 add_settings_field(
2709 - 'auth_settings_cas_path',
2710 - __( 'CAS server path/context', 'authorizer' ),
2711 - array( $this, 'print_text_cas_path' ),
2712 - 'authorizer',
2713 - 'auth_settings_external'
2412 + 'auth_settings_cas_path', // HTML element ID
2413 + __( 'CAS server path/context', 'authorizer' ), // HTML element Title
2414 + array( $this, 'print_text_cas_path' ), // Callback (echos form element)
2415 + 'authorizer', // Page this setting is shown on (slug)
2416 + 'auth_settings_external' // Section this setting is shown on
2714 2417 );
2715 2418 add_settings_field(
2716 - 'auth_settings_cas_version',
2717 - 'CAS server version',
2718 - array( $this, 'print_select_cas_version' ),
2719 - 'authorizer',
2720 - 'auth_settings_external'
2419 + 'auth_settings_cas_version', // HTML element ID
2420 + 'CAS server version', // HTML element Title
2421 + array( $this, 'print_select_cas_version' ), // Callback (echos form element)
2422 + 'authorizer', // Page this setting is shown on (slug)
2423 + 'auth_settings_external' // Section this setting is shown on
2721 2424 );
2722 2425 add_settings_field(
2723 - 'auth_settings_cas_attr_email',
2724 - __( 'CAS attribute containing email address', 'authorizer' ),
2725 - array( $this, 'print_text_cas_attr_email' ),
2726 - 'authorizer',
2727 - 'auth_settings_external'
2426 + 'auth_settings_cas_attr_email', // HTML element ID
2427 + __( 'CAS attribute containing email address', 'authorizer' ), // HTML element Title
2428 + array( $this, 'print_text_cas_attr_email' ), // Callback (echos form element)
2429 + 'authorizer', // Page this setting is shown on (slug)
2430 + 'auth_settings_external' // Section this setting is shown on
2728 2431 );
2729 2432 add_settings_field(
2730 - 'auth_settings_cas_attr_first_name',
2731 - __( 'CAS attribute containing first name', 'authorizer' ),
2732 - array( $this, 'print_text_cas_attr_first_name' ),
2733 - 'authorizer',
2734 - 'auth_settings_external'
2433 + 'auth_settings_cas_attr_first_name', // HTML element ID
2434 + __( 'CAS attribute containing first name', 'authorizer' ), // HTML element Title
2435 + array( $this, 'print_text_cas_attr_first_name' ), // Callback (echos form element)
2436 + 'authorizer', // Page this setting is shown on (slug)
2437 + 'auth_settings_external' // Section this setting is shown on
2735 2438 );
2736 2439 add_settings_field(
2737 - 'auth_settings_cas_attr_last_name',
2738 - __( 'CAS attribute containing last name', 'authorizer' ),
2739 - array( $this, 'print_text_cas_attr_last_name' ),
2740 - 'authorizer',
2741 - 'auth_settings_external'
2440 + 'auth_settings_cas_attr_last_name', // HTML element ID
2441 + __( 'CAS attribute containing last name', 'authorizer' ), // HTML element Title
2442 + array( $this, 'print_text_cas_attr_last_name' ), // Callback (echos form element)
2443 + 'authorizer', // Page this setting is shown on (slug)
2444 + 'auth_settings_external' // Section this setting is shown on
2742 2445 );
2743 2446 add_settings_field(
2744 - 'auth_settings_cas_attr_update_on_login',
2745 - __( 'CAS attribute update', 'authorizer' ),
2746 - array( $this, 'print_checkbox_cas_attr_update_on_login' ),
2747 - 'authorizer',
2748 - 'auth_settings_external'
2447 + 'auth_settings_cas_attr_update_on_login', // HTML element ID
2448 + __( 'CAS attribute update', 'authorizer' ), // HTML element Title
2449 + array( $this, 'print_checkbox_cas_attr_update_on_login' ), // Callback (echos form element)
2450 + 'authorizer', // Page this setting is shown on (slug)
2451 + 'auth_settings_external' // Section this setting is shown on
2749 2452 );
2750 2453 add_settings_field(
2751 - 'auth_settings_cas_auto_login',
2752 - __( 'CAS automatic login', 'authorizer' ),
2753 - array( $this, 'print_checkbox_cas_auto_login' ),
2754 - 'authorizer',
2755 - 'auth_settings_external'
2454 + 'auth_settings_cas_auto_login', // HTML element ID
2455 + __( 'CAS automatic login', 'authorizer' ), // HTML element Title
2456 + array( $this, 'print_checkbox_cas_auto_login' ), // Callback (echos form element)
2457 + 'authorizer', // Page this setting is shown on (slug)
2458 + 'auth_settings_external' // Section this setting is shown on
2756 2459 );
2757 2460 add_settings_field(
2758 - 'auth_settings_external_ldap',
2759 - __( 'LDAP Logins', 'authorizer' ),
2760 - array( $this, 'print_checkbox_auth_external_ldap' ),
2761 - 'authorizer',
2762 - 'auth_settings_external'
2461 + 'auth_settings_external_ldap', // HTML element ID
2462 + __( 'LDAP Logins', 'authorizer' ), // HTML element Title
2463 + array( $this, 'print_checkbox_auth_external_ldap' ), // Callback (echos form element)
2464 + 'authorizer', // Page this setting is shown on (slug)
2465 + 'auth_settings_external' // Section this setting is shown on
2763 2466 );
2764 2467 add_settings_field(
2765 - 'auth_settings_ldap_host',
2766 - __( 'LDAP Host', 'authorizer' ),
2767 - array( $this, 'print_text_ldap_host' ),
2768 - 'authorizer',
2769 - 'auth_settings_external'
2468 + 'auth_settings_ldap_host', // HTML element ID
2469 + __( 'LDAP Host', 'authorizer' ), // HTML element Title
2470 + array( $this, 'print_text_ldap_host' ), // Callback (echos form element)
2471 + 'authorizer', // Page this setting is shown on (slug)
2472 + 'auth_settings_external' // Section this setting is shown on
2770 2473 );
2771 2474 add_settings_field(
2772 - 'auth_settings_ldap_port',
2773 - __( 'LDAP Port', 'authorizer' ),
2774 - array( $this, 'print_text_ldap_port' ),
2775 - 'authorizer',
2776 - 'auth_settings_external'
2475 + 'auth_settings_ldap_port', // HTML element ID
2476 + __( 'LDAP Port', 'authorizer' ), // HTML element Title
2477 + array( $this, 'print_text_ldap_port' ), // Callback (echos form element)
2478 + 'authorizer', // Page this setting is shown on (slug)
2479 + 'auth_settings_external' // Section this setting is shown on
2777 2480 );
2778 2481 add_settings_field(
2779 - 'auth_settings_ldap_tls',
2780 - __( 'Use TLS', 'authorizer' ),
2781 - array( $this, 'print_checkbox_ldap_tls' ),
2782 - 'authorizer',
2783 - 'auth_settings_external'
2482 + 'auth_settings_ldap_tls', // HTML element ID
2483 + __( 'Secure Connection (TLS)', 'authorizer' ), // HTML element Title
2484 + array( $this, 'print_checkbox_ldap_tls' ), // Callback (echos form element)
2485 + 'authorizer', // Page this setting is shown on (slug)
2486 + 'auth_settings_external' // Section this setting is shown on
2784 2487 );
2785 2488 add_settings_field(
2786 - 'auth_settings_ldap_search_base',
2787 - __( 'LDAP Search Base', 'authorizer' ),
2788 - array( $this, 'print_text_ldap_search_base' ),
2789 - 'authorizer',
2790 - 'auth_settings_external'
2489 + 'auth_settings_ldap_search_base', // HTML element ID
2490 + __( 'LDAP Search Base', 'authorizer' ), // HTML element Title
2491 + array( $this, 'print_text_ldap_search_base' ), // Callback (echos form element)
2492 + 'authorizer', // Page this setting is shown on (slug)
2493 + 'auth_settings_external' // Section this setting is shown on
2791 2494 );
2792 2495 add_settings_field(
2793 - 'auth_settings_ldap_uid',
2794 - __( 'LDAP attribute containing username', 'authorizer' ),
2795 - array( $this, 'print_text_ldap_uid' ),
2796 - 'authorizer',
2797 - 'auth_settings_external'
2496 + 'auth_settings_ldap_uid', // HTML element ID
2497 + __( 'LDAP attribute containing username', 'authorizer' ), // HTML element Title
2498 + array( $this, 'print_text_ldap_uid' ), // Callback (echos form element)
2499 + 'authorizer', // Page this setting is shown on (slug)
2500 + 'auth_settings_external' // Section this setting is shown on
2798 2501 );
2799 2502 add_settings_field(
2800 - 'auth_settings_ldap_attr_email',
2801 - __( 'LDAP attribute containing email address', 'authorizer' ),
2802 - array( $this, 'print_text_ldap_attr_email' ),
2803 - 'authorizer',
2804 - 'auth_settings_external'
2503 + 'auth_settings_ldap_attr_email', // HTML element ID
2504 + __( 'LDAP attribute containing email address', 'authorizer' ), // HTML element Title
2505 + array( $this, 'print_text_ldap_attr_email' ), // Callback (echos form element)
2506 + 'authorizer', // Page this setting is shown on (slug)
2507 + 'auth_settings_external' // Section this setting is shown on
2805 2508 );
2806 2509 add_settings_field(
2807 - 'auth_settings_ldap_user',
2808 - __( 'LDAP Directory User', 'authorizer' ),
2809 - array( $this, 'print_text_ldap_user' ),
2810 - 'authorizer',
2811 - 'auth_settings_external'
2510 + 'auth_settings_ldap_user', // HTML element ID
2511 + __( 'LDAP Directory User', 'authorizer' ), // HTML element Title
2512 + array( $this, 'print_text_ldap_user' ), // Callback (echos form element)
2513 + 'authorizer', // Page this setting is shown on (slug)
2514 + 'auth_settings_external' // Section this setting is shown on
2812 2515 );
2813 2516 add_settings_field(
2814 - 'auth_settings_ldap_password',
2815 - __( 'LDAP Directory User Password', 'authorizer' ),
2816 - array( $this, 'print_password_ldap_password' ),
2817 - 'authorizer',
2818 - 'auth_settings_external'
2517 + 'auth_settings_ldap_password', // HTML element ID
2518 + __( 'LDAP Directory User Password', 'authorizer' ), // HTML element Title
2519 + array( $this, 'print_password_ldap_password' ), // Callback (echos form element)
2520 + 'authorizer', // Page this setting is shown on (slug)
2521 + 'auth_settings_external' // Section this setting is shown on
2819 2522 );
2820 2523 add_settings_field(
2821 - 'auth_settings_ldap_lostpassword_url',
2822 - __( 'Custom lost password URL', 'authorizer' ),
2823 - array( $this, 'print_text_ldap_lostpassword_url' ),
2824 - 'authorizer',
2825 - 'auth_settings_external'
2524 + 'auth_settings_ldap_lostpassword_url', // HTML element ID
2525 + __( 'Custom lost password URL', 'authorizer' ), // HTML element Title
2526 + array( $this, 'print_text_ldap_lostpassword_url' ), // Callback (echos form element)
2527 + 'authorizer', // Page this setting is shown on (slug)
2528 + 'auth_settings_external' // Section this setting is shown on
2826 2529 );
2827 2530 add_settings_field(
2828 - 'auth_settings_ldap_attr_first_name',
2829 - __( 'LDAP attribute containing first name', 'authorizer' ),
2830 - array( $this, 'print_text_ldap_attr_first_name' ),
2831 - 'authorizer',
2832 - 'auth_settings_external'
2531 + 'auth_settings_ldap_attr_first_name', // HTML element ID
2532 + __( 'LDAP attribute containing first name', 'authorizer' ), // HTML element Title
2533 + array( $this, 'print_text_ldap_attr_first_name' ), // Callback (echos form element)
2534 + 'authorizer', // Page this setting is shown on (slug)
2535 + 'auth_settings_external' // Section this setting is shown on
2833 2536 );
2834 2537 add_settings_field(
2835 - 'auth_settings_ldap_attr_last_name',
2836 - __( 'LDAP attribute containing last name', 'authorizer' ),
2837 - array( $this, 'print_text_ldap_attr_last_name' ),
2838 - 'authorizer',
2839 - 'auth_settings_external'
2538 + 'auth_settings_ldap_attr_last_name', // HTML element ID
2539 + __( 'LDAP attribute containing last name', 'authorizer' ), // HTML element Title
2540 + array( $this, 'print_text_ldap_attr_last_name' ), // Callback (echos form element)
2541 + 'authorizer', // Page this setting is shown on (slug)
2542 + 'auth_settings_external' // Section this setting is shown on
2840 2543 );
2841 2544 add_settings_field(
2842 - 'auth_settings_ldap_attr_update_on_login',
2843 - __( 'LDAP attribute update', 'authorizer' ),
2844 - array( $this, 'print_checkbox_ldap_attr_update_on_login' ),
2845 - 'authorizer',
2846 - 'auth_settings_external'
2545 + 'auth_settings_ldap_attr_update_on_login', // HTML element ID
2546 + __( 'LDAP attribute update', 'authorizer' ), // HTML element Title
2547 + array( $this, 'print_checkbox_ldap_attr_update_on_login' ), // Callback (echos form element)
2548 + 'authorizer', // Page this setting is shown on (slug)
2549 + 'auth_settings_external' // Section this setting is shown on
2847 2550 );
2848 2551
2849 - // Create Advanced Settings section.
2552 + // Create Advanced Settings section
2850 2553 add_settings_section(
2851 - 'auth_settings_advanced',
2852 - '',
2853 - array( $this, 'print_section_info_advanced' ),
2854 - 'authorizer'
2554 + 'auth_settings_advanced', // HTML element ID
2555 + '', // HTML element Title
2556 + array( $this, 'print_section_info_advanced' ), // Callback (echos section content)
2557 + 'authorizer' // Page this section is shown on (slug)
2855 2558 );
2856 2559 add_settings_field(
2857 - 'auth_settings_advanced_lockouts',
2858 - __( 'Limit invalid login attempts', 'authorizer' ),
2859 - array( $this, 'print_text_auth_advanced_lockouts' ),
2860 - 'authorizer',
2861 - 'auth_settings_advanced'
2560 + 'auth_settings_advanced_lockouts', // HTML element ID
2561 + __( 'Limit invalid login attempts', 'authorizer' ), // HTML element Title
2562 + array( $this, 'print_text_auth_advanced_lockouts' ), // Callback (echos form element)
2563 + 'authorizer', // Page this setting is shown on (slug)
2564 + 'auth_settings_advanced' // Section this setting is shown on
2862 2565 );
2863 2566 add_settings_field(
2864 - 'auth_settings_advanced_hide_wp_login',
2865 - __( 'Hide WordPress Login', 'authorizer' ),
2866 - array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ),
2867 - 'authorizer',
2868 - 'auth_settings_advanced'
2567 + 'auth_settings_advanced_hide_wp_login', // HTML element ID
2568 + __( 'Hide WordPress Login', 'authorizer' ), // HTML element Title
2569 + array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ), // Callback (echos form element)
2570 + 'authorizer', // Page this setting is shown on (slug)
2571 + 'auth_settings_advanced' // Section this setting is shown on
2869 2572 );
2870 2573 add_settings_field(
2871 - 'auth_settings_advanced_branding',
2872 - __( 'Custom WordPress login branding', 'authorizer' ),
2873 - array( $this, 'print_radio_auth_advanced_branding' ),
2874 - 'authorizer',
2875 - 'auth_settings_advanced'
2574 + 'auth_settings_advanced_branding', // HTML element ID
2575 + __( 'Custom WordPress login branding', 'authorizer' ), // HTML element Title
2576 + array( $this, 'print_radio_auth_advanced_branding' ), // Callback (echos form element)
2577 + 'authorizer', // Page this setting is shown on (slug)
2578 + 'auth_settings_advanced' // Section this setting is shown on
2876 2579 );
2877 2580 add_settings_field(
2878 - 'auth_settings_advanced_admin_menu',
2879 - __( 'Authorizer admin menu item location', 'authorizer' ),
2880 - array( $this, 'print_radio_auth_advanced_admin_menu' ),
2881 - 'authorizer',
2882 - 'auth_settings_advanced'
2581 + 'auth_settings_advanced_admin_menu', // HTML element ID
2582 + __( 'Authorizer admin menu item location', 'authorizer' ), // HTML element Title
2583 + array( $this, 'print_radio_auth_advanced_admin_menu' ), // Callback (echos form element)
2584 + 'authorizer', // Page this setting is shown on (slug)
2585 + 'auth_settings_advanced' // Section this setting is shown on
2883 2586 );
2884 2587 add_settings_field(
2885 - 'auth_settings_advanced_usermeta',
2886 - __( 'Show custom usermeta in user list', 'authorizer' ),
2887 - array( $this, 'print_select_auth_advanced_usermeta' ),
2888 - 'authorizer',
2889 - 'auth_settings_advanced'
2588 + 'auth_settings_advanced_usermeta', // HTML element ID
2589 + __( 'Show custom usermeta in user list', 'authorizer' ), // HTML element Title
2590 + array( $this, 'print_select_auth_advanced_usermeta' ), // Callback (echos form element)
2591 + 'authorizer', // Page this setting is shown on (slug)
2592 + 'auth_settings_advanced' // Section this setting is shown on
2890 2593 );
2891 - add_settings_field(
2892 - 'auth_settings_advanced_users_per_page',
2893 - __( 'Number of users per page', 'authorizer' ),
2894 - array( $this, 'print_text_auth_advanced_users_per_page' ),
2895 - 'authorizer',
2896 - 'auth_settings_advanced'
2897 - );
2898 - add_settings_field(
2899 - 'auth_settings_advanced_users_sort_by',
2900 - __( 'Approved users sort method', 'authorizer' ),
2901 - array( $this, 'print_select_auth_advanced_users_sort_by' ),
2902 - 'authorizer',
2903 - 'auth_settings_advanced'
2904 - );
2905 - add_settings_field(
2906 - 'auth_settings_advanced_users_sort_order',
2907 - __( 'Approved users sort order', 'authorizer' ),
2908 - array( $this, 'print_select_auth_advanced_users_sort_order' ),
2909 - 'authorizer',
2910 - 'auth_settings_advanced'
2911 - );
2912 - add_settings_field(
2913 - 'auth_settings_advanced_widget_enabled',
2914 - __( 'Show dashboard widget to admin users', 'authorizer' ),
2915 - array( $this, 'print_checkbox_auth_advanced_widget_enabled' ),
2916 - 'authorizer',
2917 - 'auth_settings_advanced'
2918 - );
2919 2594 // On multisite installs, add an option to override all multisite settings on individual sites.
2920 2595 if ( is_multisite() ) {
2921 2596 add_settings_field(
2922 - 'auth_settings_advanced_override_multisite',
2923 - __( 'Override multisite options', 'authorizer' ),
2924 - array( $this, 'print_checkbox_auth_advanced_override_multisite' ),
2925 - 'authorizer',
2926 - 'auth_settings_advanced'
2597 + 'auth_settings_advanced_override_multisite', // HTML element ID
2598 + __( 'Override multisite options', 'authorizer' ), // HTML element Title
2599 + array( $this, 'print_checkbox_auth_advanced_override_multisite' ), // Callback (echos form element)
2600 + 'authorizer', // Page this setting is shown on (slug)
2601 + 'auth_settings_advanced' // Section this setting is shown on
2927 2602 );
2928 2603 }
2929 2604 }
2930 2605
@@ -2930,30 +2605,29 @@
2930 2605
2931 2606
2932 2607 /**
2933 2608 * Set meaningful defaults for the plugin options.
2934 - *
2935 2609 * Note: This function is called on plugin activation.
2936 2610 */
2937 - private function set_default_options() {
2611 + function set_default_options() {
2938 2612 global $wp_roles;
2939 2613
2940 2614 $auth_settings = get_option( 'auth_settings' );
2941 - if ( false === $auth_settings ) {
2615 + if ( $auth_settings === FALSE ) {
2942 2616 $auth_settings = array();
2943 2617 }
2944 2618
2945 2619 // Access Lists Defaults.
2946 2620 $auth_settings_access_users_pending = get_option( 'auth_settings_access_users_pending' );
2947 - if ( false === $auth_settings_access_users_pending ) {
2621 + if ( $auth_settings_access_users_pending === FALSE ) {
2948 2622 $auth_settings_access_users_pending = array();
2949 2623 }
2950 2624 $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
2951 - if ( false === $auth_settings_access_users_approved ) {
2625 + if ( $auth_settings_access_users_approved === FALSE ) {
2952 2626 $auth_settings_access_users_approved = array();
2953 2627 }
2954 2628 $auth_settings_access_users_blocked = get_option( 'auth_settings_access_users_blocked' );
2955 - if ( false === $auth_settings_access_users_blocked ) {
2629 + if ( $auth_settings_access_users_blocked === FALSE ) {
2956 2630 $auth_settings_access_users_blocked = array();
2957 2631 }
2958 2632
2959 2633 // Login Access Defaults.
@@ -3005,12 +2679,13 @@
3005 2679 if ( ! array_key_exists( 'access_redirect_to_message', $auth_settings ) ) {
3006 2680 $auth_settings['access_redirect_to_message'] = '<p>' . __( 'Notice: You are browsing this site anonymously, and only have access to a portion of its content.', 'authorizer' ) . '</p>';
3007 2681 }
3008 2682
2683 +
3009 2684 // External Service Defaults.
3010 2685 if ( ! array_key_exists( 'access_default_role', $auth_settings ) ) {
3011 2686 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3012 - $all_roles = $wp_roles->roles;
2687 + $all_roles = $wp_roles->roles;
3013 2688 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3014 2689 if ( array_key_exists( 'student', $editable_roles ) ) {
3015 2690 $auth_settings['access_default_role'] = 'student';
3016 2691 } else {
@@ -3108,12 +2783,12 @@
3108 2783
3109 2784 // Advanced defaults.
3110 2785 if ( ! array_key_exists( 'advanced_lockouts', $auth_settings ) ) {
3111 2786 $auth_settings['advanced_lockouts'] = array(
3112 - 'attempts_1' => 10,
3113 - 'duration_1' => 1,
3114 - 'attempts_2' => 10,
3115 - 'duration_2' => 10,
2787 + 'attempts_1' => 10,
2788 + 'duration_1' => 1,
2789 + 'attempts_2' => 10,
2790 + 'duration_2' => 10,
3116 2791 'reset_duration' => 120,
3117 2792 );
3118 2793 }
3119 2794 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_settings ) ) {
@@ -3127,20 +2802,8 @@
3127 2802 }
3128 2803 if ( ! array_key_exists( 'advanced_usermeta', $auth_settings ) ) {
3129 2804 $auth_settings['advanced_usermeta'] = '';
3130 2805 }
3131 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_settings ) ) {
3132 - $auth_settings['advanced_users_per_page'] = 20;
3133 - }
3134 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_settings ) ) {
3135 - $auth_settings['advanced_users_sort_by'] = 'created';
3136 - }
3137 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_settings ) ) {
3138 - $auth_settings['advanced_users_sort_order'] = 'asc';
3139 - }
3140 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_settings ) ) {
3141 - $auth_settings['advanced_widget_enabled'] = '1';
3142 - }
3143 2806 if ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) ) {
3144 2807 $auth_settings['advanced_override_multisite'] = '';
3145 2808 }
3146 2809
@@ -3151,11 +2814,11 @@
3151 2814 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
3152 2815
3153 2816 // Multisite defaults.
3154 2817 if ( is_multisite() ) {
3155 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
2818 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
3156 2819
3157 - if ( false === $auth_multisite_settings ) {
2820 + if ( $auth_multisite_settings === FALSE ) {
3158 2821 $auth_multisite_settings = array();
3159 2822 }
3160 2823 // Global switch for enabling multisite options.
3161 2824 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
@@ -3161,10 +2824,10 @@
3161 2824 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
3162 2825 $auth_multisite_settings['multisite_override'] = '';
3163 2826 }
3164 2827 // Access Lists Defaults.
3165 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved' );
3166 - if ( false === $auth_multisite_settings_access_users_approved ) {
2828 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved' );
2829 + if ( $auth_multisite_settings_access_users_approved === FALSE ) {
3167 2830 $auth_multisite_settings_access_users_approved = array();
3168 2831 }
3169 2832 // Login Access Defaults.
3170 2833 if ( ! array_key_exists( 'access_who_can_login', $auth_multisite_settings ) ) {
@@ -3176,9 +2839,9 @@
3176 2839 }
3177 2840 // External Service Defaults.
3178 2841 if ( ! array_key_exists( 'access_default_role', $auth_multisite_settings ) ) {
3179 2842 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3180 - $all_roles = $wp_roles->roles;
2843 + $all_roles = $wp_roles->roles;
3181 2844 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3182 2845 if ( array_key_exists( 'student', $editable_roles ) ) {
3183 2846 $auth_multisite_settings['access_default_role'] = 'student';
3184 2847 } else {
@@ -3271,12 +2934,12 @@
3271 2934 }
3272 2935 // Advanced defaults.
3273 2936 if ( ! array_key_exists( 'advanced_lockouts', $auth_multisite_settings ) ) {
3274 2937 $auth_multisite_settings['advanced_lockouts'] = array(
3275 - 'attempts_1' => 10,
3276 - 'duration_1' => 1,
3277 - 'attempts_2' => 10,
3278 - 'duration_2' => 10,
2938 + 'attempts_1' => 10,
2939 + 'duration_1' => 1,
2940 + 'attempts_2' => 10,
2941 + 'duration_2' => 10,
3279 2942 'reset_duration' => 120,
3280 2943 );
3281 2944 }
3282 2945 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
@@ -3281,23 +2944,11 @@
3281 2944 }
3282 2945 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
3283 2946 $auth_multisite_settings['advanced_hide_wp_login'] = '';
3284 2947 }
3285 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_multisite_settings ) ) {
3286 - $auth_multisite_settings['advanced_users_per_page'] = 20;
3287 - }
3288 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_multisite_settings ) ) {
3289 - $auth_multisite_settings['advanced_users_sort_by'] = 'created';
3290 - }
3291 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_multisite_settings ) ) {
3292 - $auth_multisite_settings['advanced_users_sort_order'] = 'asc';
3293 - }
3294 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_multisite_settings ) ) {
3295 - $auth_multisite_settings['advanced_widget_enabled'] = '1';
3296 - }
3297 2948 // Save default network options to database.
3298 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
3299 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
2949 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
2950 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3300 2951 }
3301 2952
3302 2953 return $auth_settings;
3303 2954 }
@@ -3304,15 +2955,12 @@
3304 2955
3305 2956
3306 2957 /**
3307 2958 * List sanitizer.
3308 - *
3309 - * @param array $list Array of users to sanitize.
3310 - * @param string $side_effect Set to 'update roles' if role syncing should be performed.
3311 - * @param string $multisite_mode Set to 'multisite' to sync roles on all sites the user belongs to.
3312 - * @return array Array of sanitized users.
2959 + * $side_effect = 'none' or 'update roles' to make sure WP user roles match
2960 + * $multisite_mode = 'single' or 'multisite' to indicate which user roles to change (this site or all sites)
3313 2961 */
3314 - private function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
2962 + function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
3315 2963 // If it's not a list, make it so.
3316 2964 if ( ! is_array( $list ) ) {
3317 2965 $list = array();
3318 2966 }
@@ -3317,16 +2965,16 @@
3317 2965 $list = array();
3318 2966 }
3319 2967 foreach ( $list as $key => $user_info ) {
3320 2968 if ( strlen( $user_info['email'] ) < 1 ) {
3321 - // Make sure there are no empty entries in the list.
3322 - unset( $list[ $key ] );
3323 - } elseif ( 'update roles' === $side_effect ) {
2969 + // Make sure there are no empty entries in the list
2970 + unset( $list[$key] );
2971 + } elseif ( $side_effect === 'update roles' ) {
3324 2972 // Make sure the WordPress user accounts have the same role
3325 2973 // as that indicated in the list.
3326 2974 $wp_user = get_user_by( 'email', $user_info['email'] );
3327 2975 if ( $wp_user ) {
3328 - if ( is_multisite() && 'multisite' === $multisite_mode ) {
2976 + if ( is_multisite() && $multisite_mode === 'multisite' ) {
3329 2977 foreach ( get_blogs_of_user( $wp_user->ID ) as $blog ) {
3330 2978 add_user_to_blog( $blog->userblog_id, $wp_user->ID, $user_info['role'] );
3331 2979 }
3332 2980 } else {
@@ -3339,21 +2987,18 @@
3339 2987 }
3340 2988
3341 2989
3342 2990 /**
3343 - * Settings sanitizer callback.
3344 - *
3345 - * @param array $auth_settings Authorizer settings array.
3346 - * @return array Sanitized Authorizer settings array.
2991 + * Settings sanitizer callback
3347 2992 */
3348 - public function sanitize_options( $auth_settings ) {
2993 + function sanitize_options( $auth_settings ) {
3349 2994 // Default to "Approved Users" login access restriction.
3350 - if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ), true ) ) {
2995 + if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ) ) ) {
3351 2996 $auth_settings['access_who_can_login'] = 'approved_users';
3352 2997 }
3353 2998
3354 2999 // Default to "Everyone" view access restriction.
3355 - if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ), true ) ) {
3000 + if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ) ) ) {
3356 3001 $auth_settings['access_who_can_view'] = 'everyone';
3357 3002 }
3358 3003
3359 3004 // Default to WordPress login access redirect.
@@ -3358,9 +3003,9 @@
3358 3003
3359 3004 // Default to WordPress login access redirect.
3360 3005 // Note: this option doesn't exist in multisite options, so we first
3361 3006 // check to see if it exists.
3362 - if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ), true ) ) {
3007 + if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ) ) ) {
3363 3008 $auth_settings['access_redirect'] = 'login';
3364 3009 }
3365 3010
3366 3011 // Default to warning message for anonymous users on public pages.
@@ -3365,61 +3010,61 @@
3365 3010
3366 3011 // Default to warning message for anonymous users on public pages.
3367 3012 // Note: this option doesn't exist in multisite options, so we first
3368 3013 // check to see if it exists.
3369 - if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ), true ) ) {
3014 + if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ) ) ) {
3370 3015 $auth_settings['access_public_warning'] = 'no_warning';
3371 3016 }
3372 3017
3373 - // Sanitize Send welcome email (checkbox: value can only be '1' or empty string).
3018 + // Sanitize Send welcome email (checkbox: value can only be '1' or empty string)
3374 3019 $auth_settings['access_should_email_approved_users'] = array_key_exists( 'access_should_email_approved_users', $auth_settings ) && strlen( $auth_settings['access_should_email_approved_users'] ) > 0 ? '1' : '';
3375 3020
3376 - // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string).
3021 + // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string)
3377 3022 $auth_settings['google'] = array_key_exists( 'google', $auth_settings ) && strlen( $auth_settings['google'] ) > 0 ? '1' : '';
3378 3023
3379 - // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string).
3024 + // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string)
3380 3025 $auth_settings['cas'] = array_key_exists( 'cas', $auth_settings ) && strlen( $auth_settings['cas'] ) > 0 ? '1' : '';
3381 3026
3382 - // Sanitize CAS Host setting.
3027 + // Sanitize CAS Host setting
3383 3028 $auth_settings['cas_host'] = filter_var( $auth_settings['cas_host'], FILTER_SANITIZE_URL );
3384 3029
3385 - // Sanitize CAS Port (int).
3030 + // Sanitize CAS Port (int)
3386 3031 $auth_settings['cas_port'] = filter_var( $auth_settings['cas_port'], FILTER_SANITIZE_NUMBER_INT );
3387 3032
3388 - // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string).
3033 + // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string)
3389 3034 $auth_settings['cas_attr_update_on_login'] = array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['cas_attr_update_on_login'] ) > 0 ? '1' : '';
3390 3035
3391 - // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string).
3036 + // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string)
3392 3037 $auth_settings['cas_auto_login'] = array_key_exists( 'cas_auto_login', $auth_settings ) && strlen( $auth_settings['cas_auto_login'] ) > 0 ? '1' : '';
3393 3038
3394 - // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string).
3039 + // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string)
3395 3040 $auth_settings['ldap'] = array_key_exists( 'ldap', $auth_settings ) && strlen( $auth_settings['ldap'] ) > 0 ? '1' : '';
3396 3041
3397 - // Sanitize LDAP Host setting.
3042 + // Sanitize LDAP Host setting
3398 3043 $auth_settings['ldap_host'] = filter_var( $auth_settings['ldap_host'], FILTER_SANITIZE_URL );
3399 3044
3400 - // Sanitize LDAP Port (int).
3045 + // Sanitize LDAP Port (int)
3401 3046 $auth_settings['ldap_port'] = filter_var( $auth_settings['ldap_port'], FILTER_SANITIZE_NUMBER_INT );
3402 3047
3403 - // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string).
3048 + // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string)
3404 3049 $auth_settings['ldap_tls'] = array_key_exists( 'ldap_tls', $auth_settings ) && strlen( $auth_settings['ldap_tls'] ) > 0 ? '1' : '';
3405 3050
3406 - // Sanitize LDAP attributes (basically make sure they don't have any parentheses).
3051 + // Sanitize LDAP attributes (basically make sure they don't have any parentheses)
3407 3052 $auth_settings['ldap_uid'] = filter_var( $auth_settings['ldap_uid'], FILTER_SANITIZE_EMAIL );
3408 3053
3409 - // Sanitize LDAP Lost Password URL.
3054 + // Sanitize LDAP Lost Password URL
3410 3055 $auth_settings['ldap_lostpassword_url'] = filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_SANITIZE_URL );
3411 3056
3412 - // Obfuscate LDAP directory user password.
3057 + // Obfuscate LDAP directory user password
3413 3058 if ( strlen( $auth_settings['ldap_password'] ) > 0 ) {
3414 3059 // encrypt the directory user password for some minor obfuscation in the database.
3415 3060 $auth_settings['ldap_password'] = $this->encrypt( $auth_settings['ldap_password'] );
3416 3061 }
3417 3062
3418 - // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string).
3063 + // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string)
3419 3064 $auth_settings['ldap_attr_update_on_login'] = array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['ldap_attr_update_on_login'] ) > 0 ? '1' : '';
3420 3065
3421 - // Make sure public pages is an empty array if it's empty.
3066 + // Make sure public pages is an empty array if it's empty
3422 3067 // Note: this option doesn't exist in multisite options, so we first
3423 3068 // check to see if it exists.
3424 3069 if ( array_key_exists( 'access_public_pages', $auth_settings ) && ! is_array( $auth_settings['access_public_pages'] ) ) {
3425 3070 $auth_settings['access_public_pages'] = array();
@@ -3427,31 +3072,15 @@
3427 3072
3428 3073 // Make sure all lockout options are integers (attempts_1,
3429 3074 // duration_1, attempts_2, duration_2, reset_duration).
3430 3075 foreach ( $auth_settings['advanced_lockouts'] as $key => $value ) {
3431 - $auth_settings['advanced_lockouts'][ $key ] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3076 + $auth_settings['advanced_lockouts'][$key] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3432 3077 }
3433 3078
3434 - // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string).
3079 + // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string)
3435 3080 $auth_settings['advanced_hide_wp_login'] = array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && strlen( $auth_settings['advanced_hide_wp_login'] ) > 0 ? '1' : '';
3436 3081
3437 - // Sanitize Users per page (text: value can only int from 1 to MAX_INT).
3438 - $auth_settings['advanced_users_per_page'] = array_key_exists( 'advanced_users_per_page', $auth_settings ) && intval( $auth_settings['advanced_users_per_page'] ) > 0 ? intval( $auth_settings['advanced_users_per_page'] ) : 1;
3439 -
3440 - // Sanitize Sort users by (select: value can be 'email', 'role', 'date_added', 'created').
3441 - if ( ! isset( $auth_settings['advanced_users_sort_by'] ) || ! in_array( $auth_settings['advanced_users_sort_by'], array( 'email', 'role', 'date_added', 'created' ), true ) ) {
3442 - $auth_settings['advanced_users_sort_by'] = 'created';
3443 - }
3444 -
3445 - // Sanitize Sort users order (select: value can be 'asc', 'desc').
3446 - if ( ! isset( $auth_settings['advanced_users_sort_order'] ) || ! in_array( $auth_settings['advanced_users_sort_order'], array( 'asc', 'desc' ), true ) ) {
3447 - $auth_settings['advanced_users_sort_order'] = 'asc';
3448 - }
3449 -
3450 - // Sanitize Show Dashboard Widget (checkbox: value can only be '1' or empty string).
3451 - $auth_settings['advanced_widget_enabled'] = array_key_exists( 'advanced_widget_enabled', $auth_settings ) && strlen( $auth_settings['advanced_widget_enabled'] ) > 0 ? '1' : '';
3452 -
3453 - // Sanitize Override multisite options (checkbox: value can only be '1' or empty string).
3082 + // Sanitize Override multisite options (checkbox: value can only be '1' or empty string)
3454 3083 $auth_settings['advanced_override_multisite'] = array_key_exists( 'advanced_override_multisite', $auth_settings ) && strlen( $auth_settings['advanced_override_multisite'] ) > 0 ? '1' : '';
3455 3084
3456 3085 return $auth_settings;
3457 3086 }
@@ -3458,201 +3087,90 @@
3458 3087
3459 3088
3460 3089 /**
3461 3090 * Keep authorizer approved users' roles in sync with WordPress roles
3462 - * if someone changes the role via the WordPress Edit User page
3463 - * (wp-admin/user-edit.php or wp-admin/profile.php).
3091 + * if someone changes the role via the WordPress Edit User options page.
3464 3092 *
3465 - * Action: user_profile_update_errors
3466 - *
3467 - * @param WP_Error $errors Errors object to add any custom errors to (passed by reference).
3468 - * @param bool $update True if updating existing user, false if saving a new one.
3469 - * @param stdClass $user Updated WP_User object for user being edited (passed by reference).
3093 + * @action edit_user_profile_update
3094 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/edit_user_profile_update
3095 + * @param int $user_id The user ID of the user being edited
3096 +
3097 + * @action personal_options_update
3098 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/personal_options_update
3099 + * @param int $user_id The user ID of the user being edited
3470 3100 */
3471 - public function edit_user_profile_update_role( &$errors, $update, &$user ) {
3472 - // Do nothing if we're not updating role.
3473 - if ( ! property_exists( $user, 'role' ) ) {
3101 + function edit_user_profile_update_role( $user_id ) {
3102 + if ( ! current_user_can( 'edit_user', $user_id ) ) {
3474 3103 return;
3475 3104 }
3476 3105
3477 - // Safety check; will likely not fire if we reach this function.
3478 - if ( ! current_user_can( 'edit_user', $user->ID ) ) {
3479 - return;
3480 - }
3481 -
3482 - // Don't perform Authorizer updates if we have a WordPress error.
3483 - $errors_on_user_update = $errors->get_error_codes();
3484 - if ( ! empty( $errors_on_user_update ) ) {
3485 - return;
3486 - }
3487 -
3488 - // Get original user object (fail if not a real WordPress user).
3489 - $userdata = get_userdata( $user->ID );
3490 - if ( ! $userdata ) {
3491 - return;
3492 - }
3493 -
3494 3106 // If user is in approved list, update his/her associated role.
3495 - if ( $this->is_email_in_list( $userdata->user_email, 'approved' ) ) {
3496 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3497 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3498 - if ( 0 === strcasecmp( $check_user['email'], $userdata->user_email ) ) {
3499 - $auth_settings_access_users_approved[ $key ]['role'] = $user->role;
3500 - }
3501 - }
3502 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3503 - }
3504 - }
3505 -
3506 -
3507 - /**
3508 - * Sync any email address changes to WordPress accounts to the corresponding
3509 - * entry in the Authorizer approved list.
3510 - *
3511 - * Note: This filter fires in wp_update_user() if the update includes an
3512 - * email address change, and fires after all security and integrity checks
3513 - * have been performed, so we can simply update the Authorizer approved
3514 - * list, changing the email address on the approved entry, and removing any
3515 - * existing entries that also have the new email address (duplicates).
3516 - *
3517 - * Filter: send_email_change_email
3518 - *
3519 - * @param bool $send Whether to send the email.
3520 - * @param array $user The original user array.
3521 - * @param array $userdata The updated user array.
3522 - */
3523 - public function edit_user_profile_update_email( $send, $user, $userdata ) {
3524 - // If we're in multisite, update the email on all sites in the network
3525 - // (and remove from any subsites if it's a network-approved user).
3526 - if ( is_multisite() ) {
3527 - // If it's a multisite approved user, sync the email there.
3528 - $changed_user_is_multisite_user = false;
3529 - if ( $this->is_email_in_list( $user['user_email'], 'approved', 'multisite' ) ) {
3530 - $changed_user_is_multisite_user = true;
3531 - $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
3532 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
3533 - );
3534 - foreach ( $auth_multisite_settings_access_users_approved as $key => $check_user ) {
3535 - // Update old user email in approved list to the new email.
3536 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3537 - $auth_multisite_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3107 + $wp_user = get_user_by( 'id', $user_id );
3108 + if ( $this->is_email_in_list( $wp_user->get( 'user_email' ), 'approved' ) ) {
3109 + $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) );
3110 + // Find approved user and sync with the corresponding WP_User.
3111 + foreach ( $auth_settings_access_users_approved as $key => $user ) {
3112 + if ( $user['email'] === $wp_user->user_email ) {
3113 + // Sync user role.
3114 + if ( array_key_exists( 'role', $_REQUEST ) ) {
3115 + $auth_settings_access_users_approved[$key]['role'] = $_REQUEST['role'];
3538 3116 }
3539 - // If new user email is already in approved list, remove that entry.
3540 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3541 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
3117 + // Sync email address.
3118 + if ( array_key_exists( 'email', $_REQUEST ) ) {
3119 + $auth_settings_access_users_approved[$key]['email'] = $_REQUEST['email'];
3542 3120 }
3543 3121 }
3544 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3545 3122 }
3546 3123
3547 - // Go through all approved lists on individual sites and sync this user there.
3548 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
3549 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
3550 - foreach ( $sites as $site ) {
3551 - $updated = false;
3552 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
3553 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
3554 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3555 - // Update old user email in approved list to the new email.
3556 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3557 - // But if the user is already a multisite user, just remove the entry in the subsite.
3558 - if ( $changed_user_is_multisite_user ) {
3559 - unset( $auth_settings_access_users_approved[ $key ] );
3560 - } else {
3561 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3562 - }
3563 - $updated = true;
3564 - }
3565 - // If new user email is already in approved list, remove that entry.
3566 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3567 - unset( $auth_settings_access_users_approved[ $key ] );
3568 - $updated = true;
3569 - }
3570 - }
3571 - if ( $updated ) {
3572 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3573 - }
3574 - }
3575 - } else {
3576 - // In a single site environment, just find the old user in the approved list and update the email.
3577 - if ( $this->is_email_in_list( $user['user_email'], 'approved' ) ) {
3578 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3579 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3580 - // Update old user email in approved list to the new email.
3581 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3582 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3583 - }
3584 - // If new user email is already in approved list, remove that entry.
3585 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3586 - unset( $auth_settings_access_users_approved[ $key ] );
3587 - }
3588 - }
3589 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3590 - }
3124 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3591 3125 }
3592 -
3593 - // We're hooking into this filter merely for its location in the codebase,
3594 - // so make sure to return the filter value unmodified.
3595 - return $send;
3596 3126 }
3597 3127
3598 3128
3599 3129 /**
3600 - * Settings print callback.
3601 - *
3602 - * @param string $args Args (e.g., multisite admin mode).
3603 - * @return void
3130 + * Settings print callbacks
3604 3131 */
3605 - public function print_section_info_tabs( $args = '' ) {
3606 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $this->get_admin_mode( $args ) ) :
3607 - ?>
3132 + function print_section_info_tabs( $args = '' ) {
3133 + if ( MULTISITE_ADMIN === $this->get_admin_mode( $args )): ?>
3608 3134 <h2 class="nav-tab-wrapper">
3609 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3610 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3611 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3135 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3136 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3137 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3612 3138 </h2>
3613 - <?php else : ?>
3139 + <?php else: ?>
3614 3140 <h2 class="nav-tab-wrapper">
3615 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3616 - <a class="nav-tab nav-tab-access_login" href="javascript:chooseTab('access_login' );"><?php esc_html_e( 'Login Access', 'authorizer' ); ?></a>
3617 - <a class="nav-tab nav-tab-access_public" href="javascript:chooseTab('access_public' );"><?php esc_html_e( 'Public Access', 'authorizer' ); ?></a>
3618 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3619 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3141 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3142 + <a class="nav-tab nav-tab-access_login" href="javascript:choose_tab('access_login' );"><?php _e( 'Login Access', 'authorizer' ); ?></a>
3143 + <a class="nav-tab nav-tab-access_public" href="javascript:choose_tab('access_public' );"><?php _e( 'Public Access', 'authorizer' ); ?></a>
3144 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3145 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3620 3146 </h2>
3621 - <?php
3622 - endif;
3147 + <?php endif;
3623 3148 }
3624 3149
3625 3150
3626 - /**
3627 - * Settings print callback.
3628 - *
3629 - * @param string $args Args (e.g., multisite admin mode).
3630 - * @return void
3631 - */
3632 - public function print_section_info_access_lists( $args = '' ) {
3151 + function print_section_info_access_lists( $args = '' ) {
3633 3152 $admin_mode = $this->get_admin_mode( $args );
3634 - ?>
3635 - <div id="section_info_access_lists" class="section_info">
3636 - <p><?php esc_html_e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3153 + ?><div id="section_info_access_lists" class="section_info">
3154 + <p><?php _e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3637 3155 <ol>
3638 - <li><?php echo wp_kses( __( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ), $this->allowed_html ); ?></li>
3639 - <li><?php echo wp_kses( __( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ), $this->allowed_html ); ?></li>
3640 - <li><?php echo wp_kses( __( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ), $this->allowed_html ); ?><br><?php esc_html_e( 'Note: if you want to block all email addresses from a domain, say anyone@example.com, simply add "@example.com" to the blocked list.', 'authorizer' ); ?></li>
3156 + <li><?php _e( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ); ?></li>
3157 + <li><?php _e( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ); ?></li>
3158 + <li><?php _e( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ); ?></li>
3641 3159 </ol>
3642 3160 </div>
3643 3161 <table class="form-table">
3644 3162 <tbody>
3645 3163 <tr>
3646 - <th scope="row"><?php esc_html_e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'pending', $admin_mode ) ); ?>)</em></th>
3164 + <th scope="row"><?php _e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'pending', $admin_mode ); ?>)</em></th>
3647 3165 <td><?php $this->print_combo_auth_access_users_pending(); ?></td>
3648 3166 </tr>
3649 3167 <tr>
3650 - <th scope="row"><?php esc_html_e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'approved', $admin_mode ) ); ?>)</em></th>
3168 + <th scope="row"><?php _e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'approved', $admin_mode ); ?>)</em></th>
3651 3169 <td><?php $this->print_combo_auth_access_users_approved(); ?></td>
3652 3170 </tr>
3653 3171 <tr>
3654 - <th scope="row"><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'blocked', $admin_mode ) ); ?>)</em></th>
3172 + <th scope="row"><?php _e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'blocked', $admin_mode ); ?>)</em></th>
3655 3173 <td><?php $this->print_combo_auth_access_users_blocked(); ?></td>
3656 3174 </tr>
3657 3175 </tbody>
3658 3176 </table>
@@ -3659,516 +3177,276 @@
3659 3177 <?php
3660 3178 }
3661 3179
3662 3180
3663 - /**
3664 - * Settings print callback.
3665 - *
3666 - * @param string $args Args (e.g., multisite admin mode).
3667 - * @return void
3668 - */
3669 - public function print_combo_auth_access_users_pending( $args = '' ) {
3181 + function print_combo_auth_access_users_pending( $args = '' ) {
3670 3182 // Get plugin option.
3671 - $option = 'access_users_pending';
3183 + $option = 'access_users_pending';
3672 3184 $auth_settings_option = $this->get_plugin_option( $option );
3673 3185 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3674 3186
3675 - // Render wrapper div (for aligning pager to width of content).
3676 - ?>
3677 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3678 - <ul id="list_auth_settings_access_users_pending" style="margin:0;">
3679 - <?php
3680 - if ( count( $auth_settings_option ) > 0 ) :
3681 - foreach ( $auth_settings_option as $key => $pending_user ) :
3682 - if ( empty( $pending_user ) || count( $pending_user ) < 1 ) :
3683 - continue;
3684 - endif;
3685 - $pending_user['is_wp_user'] = false;
3686 - ?>
3687 - <li>
3688 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $pending_user['email'] ); ?>" readonly="true" class="auth-email" />
3689 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
3690 - <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3691 - </select>
3692 - <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'approved', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3693 - <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'blocked', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
3694 - <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'pending' );" title="<?php esc_html_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php esc_html_e( 'Ignore', 'authorizer' ); ?></a>
3695 - </li>
3696 - <?php endforeach; ?>
3697 - <?php else : ?>
3698 - <li class="auth-empty"><em><?php esc_html_e( 'No pending users', 'authorizer' ); ?></em></li>
3699 - <?php endif; ?>
3700 - </ul>
3701 - </div>
3187 + // Print option elements.
3188 + ?><ul id="list_auth_settings_access_users_pending" style="margin:0;">
3189 + <?php if ( count( $auth_settings_option ) > 0 ) : ?>
3190 + <?php foreach ( $auth_settings_option as $key => $pending_user ): ?>
3191 + <?php if ( empty( $pending_user ) || count( $pending_user ) < 1 ) continue; ?>
3192 + <?php $pending_user['is_wp_user'] = false; ?>
3193 + <li>
3194 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $pending_user['email']; ?>" readonly="true" class="auth-email" />
3195 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3196 + <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3197 + </select>
3198 + <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'approved', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3199 + <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'blocked', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
3200 + <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user( this, 'pending' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php _e( 'Ignore', 'authorizer' ); ?></a>
3201 + </li>
3202 + <?php endforeach; ?>
3203 + <?php else: ?>
3204 + <li class="auth-empty"><em><?php _e( 'No pending users', 'authorizer' ); ?></em></li>
3205 + <?php endif; ?>
3206 + </ul>
3702 3207 <?php
3703 3208 }
3704 3209
3705 3210
3706 - /**
3707 - * Settings print callback.
3708 - *
3709 - * @param string $args Args (e.g., multisite admin mode).
3710 - * @return void
3711 - */
3712 - public function print_combo_auth_access_users_approved( $args = '' ) {
3211 + function print_combo_auth_access_users_approved( $args = '' ) {
3713 3212 // Get plugin option.
3714 - $option = 'access_users_approved';
3715 - $admin_mode = $this->get_admin_mode( $args );
3213 + $option = 'access_users_approved';
3214 + $admin_mode = $this->get_admin_mode( $args );
3716 3215 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
3717 3216 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3718 3217
3719 - // Get multisite approved users (will be added to top of list, greyed out).
3720 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3721 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
3218 + // Get multisite approved users (add them to top of list, greyed out).
3219 + $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3220 + $auth_multisite_settings = $this->get_plugin_options( MULTISITE_ADMIN );
3722 3221 $auth_settings_option_multisite = array();
3723 3222 if (
3724 3223 is_multisite() &&
3725 - ! is_network_admin() &&
3726 - '1' !== intval( $auth_override_multisite ) &&
3224 + $auth_override_multisite != '1' &&
3727 3225 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
3728 - '1' === $auth_multisite_settings['multisite_override']
3226 + $auth_multisite_settings['multisite_override'] === '1'
3729 3227 ) {
3730 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
3228 + $auth_settings_option_multisite = $this->get_plugin_option( $option, MULTISITE_ADMIN, 'allow override' );
3731 3229 $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
3732 - // Add multisite users to the beginning of the main user array.
3733 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
3734 - $approved_user['multisite_user'] = true;
3735 - array_unshift( $auth_settings_option, $approved_user );
3736 - }
3737 3230 }
3738 3231
3739 3232 // Get default role for new user dropdown.
3740 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3233 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
3741 3234
3742 3235 // Get custom usermeta field to show.
3743 3236 $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
3744 3237
3745 3238 // Adjust javascript function prefixes if multisite.
3746 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3747 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3239 + $js_function_prefix = $admin_mode === MULTISITE_ADMIN ? 'auth_multisite_' : 'auth_';
3240 + $multisite_admin_page = $admin_mode === MULTISITE_ADMIN;
3748 3241
3749 - // Filter user list to search terms.
3750 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3751 - if ( isset( $_REQUEST['search'] ) && strlen( sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) ) > 0 ) {
3752 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3753 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
3754 - $auth_settings_option = array_filter(
3755 - $auth_settings_option, function ( $user ) use ( $search_term ) {
3756 - return stripos( $user['email'], $search_term ) !== false ||
3757 - stripos( $user['role'], $search_term ) !== false ||
3758 - stripos( $user['date_added'], $search_term ) !== false;
3759 - }
3760 - );
3761 - }
3762 -
3763 - // Sort user list.
3764 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
3765 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
3766 - $sort_dimension = array();
3767 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
3768 - foreach ( $auth_settings_option as $key => $user ) {
3769 - if ( 'date_added' === $sort_by ) {
3770 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
3771 - } else {
3772 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
3773 - }
3774 - }
3775 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
3776 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
3777 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
3778 - // If default sort method and reverse order, just reverse the array.
3779 - $auth_settings_option = array_reverse( $auth_settings_option );
3780 - }
3781 -
3782 - // Ensure array keys run from 0..max (keys in database will be the original,
3783 - // index, and removing users will not reorder the array keys of other users).
3784 - $auth_settings_option = array_values( $auth_settings_option );
3785 -
3786 - // Get pager params.
3787 - $total_users = count( $auth_settings_option );
3788 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
3789 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3790 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
3791 - $total_pages = ceil( $total_users / $users_per_page );
3792 - if ( $total_pages < 1 ) {
3793 - $total_pages = 1;
3794 - }
3795 -
3796 - // Make sure current_page is between 1 and max pages.
3797 - if ( $current_page < 1 ) {
3798 - $current_page = 1;
3799 - } elseif ( $current_page > $total_pages ) {
3800 - $current_page = $total_pages;
3801 - }
3802 -
3803 - // Render wrapper div (for aligning pager to width of content).
3804 - ?>
3805 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3806 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'top' ); ?>
3807 - <ul id="list_auth_settings_access_users_approved" class="<?php echo strlen( $advanced_usermeta ) > 0 ? 'has-usermeta' : ''; ?>">
3808 - <?php
3809 - $offset = ( $current_page - 1 ) * $users_per_page;
3810 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
3811 - for ( $key = $offset; $key < $max; $key++ ) :
3812 - $approved_user = $auth_settings_option[ $key ];
3242 + ?><ul id="list_auth_settings_access_users_approved" style="margin:0;">
3243 + <?php if ( ! $multisite_admin_page ) :
3244 + foreach ( $auth_settings_option_multisite as $key => $approved_user ) :
3813 3245 if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3814 3246 continue;
3815 3247 endif;
3816 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
3817 - endfor;
3818 - ?>
3819 - </ul>
3248 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3249 + if ( $approved_wp_user ) :
3250 + $approved_user['email'] = $approved_wp_user->user_email;
3251 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3252 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3253 + // Get usermeta field from the WordPress user's real usermeta.
3254 + if ( strlen( $advanced_usermeta ) > 0 ) :
3255 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3256 + // Get ACF Field value for the user
3257 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3258 + else :
3259 + // Get regular usermeta value for the user.
3260 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3261 + endif;
3820 3262
3821 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
3822 - <textarea id="new_approved_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new autogrow-short" rows="1"></textarea>
3823 - <select id="new_approved_user_role" class="auth-role">
3824 - <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
3825 - </select>
3826 - <div class="btn-group">
3827 - <a href="javascript:void(0);" class="btn button-primary dropdown-toggle button-add-user" id="approve_user_new" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3828 - <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3829 - <span class="caret"></span>
3830 - <span class="sr-only"><?php esc_html_e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3831 - </button>
3832 - <ul class="dropdown-menu" role="menu">
3833 - <li><a href="javascript:void(0);" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( document.getElementById( 'approve_user_new' ), 'approved', true);"><?php esc_html_e( 'Create a local WordPress account instead, and email the user their password.', 'authorizer' ); ?></a></li>
3834 - </ul>
3835 - </div>
3836 - </div>
3837 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'bottom' ); ?>
3838 - </div>
3839 - <?php
3840 - }
3263 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3264 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3265 + endif;
3266 + endif;
3267 + endif;
3268 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3269 + $approved_user['usermeta'] = '';
3270 + endif; ?>
3271 + <li>
3272 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email auth-multisite-email" />
3273 + <select id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role auth-multisite-role" disabled="disabled">
3274 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'] ); ?>
3275 + </select>
3276 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added auth-multisite-date-added" disabled="disabled" />
3277 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3278 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3279 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3280 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3281 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3282 + $should_show_usermeta_in_text_field = false; ?>
3283 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta auth-multisite-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );">
3284 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3285 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3286 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && array_key_exists( get_current_blog_id(), $approved_user['usermeta'] ) && $key === $approved_user['usermeta'][get_current_blog_id()]['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3287 + <?php endforeach; ?>
3288 + </select>
3289 + <?php endif; ?>
3290 + <?php endif; ?>
3291 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3292 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta auth-multisite-usermeta" />
3293 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3294 + <?php endif; ?>
3295 + <?php endif; ?>
3296 + &nbsp;&nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
3297 + </li>
3298 + <?php endforeach;
3299 + endif;
3300 + foreach ( $auth_settings_option as $key => $approved_user ):
3301 + $is_current_user = false;
3302 + $local_user_icon = array_key_exists( 'local_user', $approved_user ) && $approved_user['local_user'] === 'true' ? '&nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>' : '';
3303 + if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3304 + continue;
3305 + endif;
3306 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3307 + if ( $approved_wp_user ) :
3308 + $approved_user['email'] = $approved_wp_user->user_email;
3309 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3310 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3311 + $approved_user['is_wp_user'] = true;
3312 + $is_current_user = $approved_wp_user->ID === get_current_user_id();
3313 + // Get usermeta field from the WordPress user's real usermeta.
3314 + if ( strlen( $advanced_usermeta ) > 0 ) :
3315 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3316 + // Get ACF Field value for the user
3317 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3318 + else :
3319 + // Get regular usermeta value for the user.
3320 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3321 + endif;
3841 3322
3842 -
3843 - /**
3844 - * Renders the html elements for the pager above and below the Approved User list.
3845 - *
3846 - * @param integer $current_page Which page we are currently viewing.
3847 - * @param integer $users_per_page How many users to show per page.
3848 - * @param integer $total_users Total count of users in list.
3849 - * @param string $which Where to render the pager ('top' or 'bottom').
3850 - * @return void
3851 - */
3852 - private function render_user_pager( $current_page = 1, $users_per_page = 20, $total_users = 0, $which = 'top' ) {
3853 - $total_pages = ceil( $total_users / $users_per_page );
3854 - if ( $total_pages < 1 ) {
3855 - $total_pages = 1;
3856 - }
3857 -
3858 - /* TRANSLATORS: %s: number of users */
3859 - $output = ' <span class="displaying-num">' . sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ) . '</span>';
3860 -
3861 - $disable_first = $current_page <= 1;
3862 - $disable_prev = $current_page <= 1;
3863 - $disable_next = $current_page >= $total_pages;
3864 - $disable_last = $current_page >= $total_pages;
3865 -
3866 - $current_url = '';
3867 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
3868 - $current_url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
3869 - $current_url = remove_query_arg( wp_removable_query_args(), $current_url );
3870 - }
3871 -
3872 - $page_links = array();
3873 -
3874 - $total_pages_before = '<span class="paging-input">';
3875 - $total_pages_after = '</span></span>';
3876 -
3877 - if ( $disable_first ) {
3878 - $page_links[] = '<span class="first-page tablenav-pages-navspan" aria-hidden="true">&laquo;</span>';
3879 - } else {
3880 - $page_links[] = sprintf(
3881 - "<a class='first-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3882 - esc_url( remove_query_arg( 'paged', $current_url ) ),
3883 - __( 'First page' ),
3884 - '&laquo;'
3885 - );
3886 - }
3887 -
3888 - if ( $disable_prev ) {
3889 - $page_links[] = '<span class="prev-page tablenav-pages-navspan" aria-hidden="true">&lsaquo;</span>';
3890 - } else {
3891 - $page_links[] = sprintf(
3892 - "<a class='prev-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3893 - esc_url( add_query_arg( 'paged', max( 1, $current_page - 1 ), $current_url ) ),
3894 - __( 'Previous page' ),
3895 - '&lsaquo;'
3896 - );
3897 - }
3898 -
3899 - if ( 'bottom' === $which ) {
3900 - $html_current_page = '<span class="current-page-text">' . $current_page . '</span>';
3901 - $total_pages_before = '<span class="screen-reader-text">' . __( 'Current Page' ) . '</span><span id="table-paging" class="paging-input"><span class="tablenav-paging-text">';
3902 - } else {
3903 - $html_current_page = sprintf(
3904 - "%s<input class='current-page' id='current-page-selector' type='text' name='paged' value='%s' size='%d' aria-describedby='table-paging' /><span class='tablenav-paging-text'>",
3905 - '<label for="current-page-selector" class="screen-reader-text">' . __( 'Current Page' ) . '</label>',
3906 - $current_page,
3907 - strlen( $total_pages )
3908 - );
3909 - }
3910 - /* TRANSLATORS: %s: number of pages */
3911 - $html_total_pages = sprintf( "<span class='total-pages'>%s</span>", number_format_i18n( $total_pages ) );
3912 - /* TRANSLATORS: 1: number of current page 2: number of total pages */
3913 - $page_links[] = $total_pages_before . sprintf( _x( '%1$s of %2$s', 'paging' ), $html_current_page, $html_total_pages ) . $total_pages_after;
3914 -
3915 - if ( $disable_next ) {
3916 - $page_links[] = '<span class="next-page tablenav-pages-navspan" aria-hidden="true">&rsaquo;</span>';
3917 - } else {
3918 - $page_links[] = sprintf(
3919 - "<a class='next-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3920 - esc_url( add_query_arg( 'paged', min( $total_pages, $current_page + 1 ), $current_url ) ),
3921 - __( 'Next page' ),
3922 - '&rsaquo;'
3923 - );
3924 - }
3925 -
3926 - if ( $disable_last ) {
3927 - $page_links[] = '<span class="last-page tablenav-pages-navspan" aria-hidden="true">&raquo;</span>';
3928 - } else {
3929 - $page_links[] = sprintf(
3930 - "<a class='last-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3931 - esc_url( add_query_arg( 'paged', $total_pages, $current_url ) ),
3932 - __( 'Last page' ),
3933 - '&raquo;'
3934 - );
3935 - }
3936 -
3937 - $pagination_links_class = 'pagination-links';
3938 - $output .= "\n<span class='$pagination_links_class'>" . join( "\n", $page_links ) . '</span>';
3939 -
3940 - $search_form = array();
3941 - if ( 'top' === $which ) {
3942 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3943 - $search_term = isset( $_REQUEST['search'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) : '';
3944 - $search_form[] = '<div class="search-box">';
3945 - $search_form[] = '<label class="screen-reader-text" for="user-search-input">' . __( 'Search Users', 'authorizer' ) . '</label>';
3946 - $search_form[] = '<input type="search" size="14" id="user-search-input" name="search" value="' . $search_term . '">';
3947 - $search_form[] = '<input type="button" id="search-submit" class="button" value="' . __( 'Search', 'authorizer' ) . '">';
3948 - $search_form[] = '</div>';
3949 - }
3950 - $search_form = join( "\n", $search_form );
3951 -
3952 - $output = "<div class='tablenav-pages'>$output</div>";
3953 - ?>
3954 - <div class="tablenav top">
3955 - <?php echo wp_kses( $output, $this->allowed_html ); ?>
3956 - <?php echo wp_kses( $search_form, $this->allowed_html ); ?>
3957 - </div>
3958 - <?php
3959 - }
3960 -
3961 -
3962 - /**
3963 - * Renders the html <li> element for a given user in a list.
3964 - *
3965 - * @param array $approved_user User array to render.
3966 - * @param int $key Index of user in list of users.
3967 - * @param string $option List user is in (e.g., 'access_users_approved').
3968 - * @param string $admin_mode Current admin context.
3969 - * @param string $advanced_usermeta Usermeta field to display.
3970 - * @return void
3971 - */
3972 - private function render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ) {
3973 - $is_local_user = array_key_exists( 'local_user', $approved_user ) && 'true' === $approved_user['local_user'];
3974 - $is_multisite_user = array_key_exists( 'multisite_user', $approved_user ) && true === $approved_user['multisite_user'];
3975 - $option_prefix = $is_multisite_user ? 'auth_multisite_settings_' : 'auth_settings_';
3976 - $option_id = $option_prefix . $option . '_' . $key;
3977 - $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3978 - $is_current_user = $approved_wp_user && get_current_user_id() === $approved_wp_user->ID;
3979 -
3980 - // Adjust javascript function prefixes if multisite.
3981 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3982 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3983 -
3984 - if ( ! $approved_wp_user ) :
3985 - $approved_user['is_wp_user'] = false;
3986 - else :
3987 - $approved_user['is_wp_user'] = true;
3988 - $approved_user['email'] = $approved_wp_user->user_email;
3989 - $approved_user['role'] = $is_multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3990 - $approved_user['date_added'] = $approved_wp_user->user_registered;
3991 -
3992 - // Get usermeta field from the WordPress user's real usermeta.
3993 - if ( strlen( $advanced_usermeta ) > 0 ) :
3994 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3995 - // Get ACF Field value for the user.
3996 - $approved_user['usermeta'] = get_field( str_replace( 'acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3323 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3324 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3325 + endif;
3326 + endif;
3997 3327 else :
3998 - // Get regular usermeta value for the user.
3999 - $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3328 + $approved_user['is_wp_user'] = false;
4000 3329 endif;
4001 - if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
4002 - $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
4003 - endif;
4004 - endif;
4005 - endif;
4006 - if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
4007 - $approved_user['usermeta'] = '';
4008 - endif;
4009 - ?>
4010 - <li>
4011 - <input
4012 - type="text"
4013 - id="<?php echo esc_attr( $option_id ); ?>"
4014 - value="<?php echo esc_attr( $approved_user['email'] ); ?>"
4015 - readonly="true"
4016 - class="<?php echo esc_attr( $this->create_class_name( 'email', $is_multisite_user ) ); ?>"
4017 - />
4018 - <select
4019 - id="<?php echo esc_attr( $option_id ); ?>_role"
4020 - class="<?php echo esc_attr( $this->create_class_name( 'role', $is_multisite_user ) ); ?>"
4021 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>ChangeRole( this );"
4022 - <?php if ( $is_multisite_user ) : ?>
4023 - disabled="disabled"
4024 - <?php endif; ?>
4025 - >
4026 - <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
4027 - <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3330 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3331 + $approved_user['usermeta'] = '';
3332 + endif; ?>
3333 + <li>
3334 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email" />
3335 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role" onchange="<?php echo $js_function_prefix; ?>change_role( this );">
3336 + <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
3337 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3338 + </select>
3339 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3340 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3341 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3342 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3343 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3344 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3345 + $should_show_usermeta_in_text_field = false; ?>
3346 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );" >
3347 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3348 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3349 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && $key === $approved_user['usermeta']['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3350 + <?php endforeach; ?>
3351 + </select>
3352 + <?php endif; ?>
3353 + <?php endif; ?>
3354 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3355 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta" />
3356 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3357 + <?php endif; ?>
3358 + <?php endif; ?>
3359 + <?php if ( ! $is_current_user ): ?>
3360 + <?php if ( ! $multisite_admin_page ) : ?>
3361 + <a class="button" id="block_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>add_user( this, 'blocked', false ); <?php echo $js_function_prefix; ?>ignore_user( this, 'approved' );" title="<?php _e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
3362 + <?php endif; ?>
3363 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>ignore_user(this, 'approved' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3364 + <?php endif; ?>
3365 + <?php echo $local_user_icon; ?>
3366 + </li>
3367 + <?php endforeach; ?>
3368 + </ul>
3369 + <div id="new_auth_settings_<?php echo $option; ?>">
3370 + <input type="text" id="new_approved_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3371 + <select id="new_approved_user_role" class="auth-role">
3372 + <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
4028 3373 </select>
4029 - <input
4030 - type="text"
4031 - id="<?php echo esc_attr( $option_id ); ?>_date_added"
4032 - value="<?php echo esc_attr( date( 'M Y', strtotime( $approved_user['date_added'] ) ) ); ?>"
4033 - readonly="true"
4034 - class="<?php echo esc_attr( $this->create_class_name( 'date-added', $is_multisite_user ) ); ?>"
4035 - />
4036 - <?php
4037 - if ( strlen( $advanced_usermeta ) > 0 ) :
4038 - $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
4039 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
4040 - $field_object = get_field_object( str_replace( 'acf___', '', $advanced_usermeta ) );
4041 - if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && 'select' === $field_object['type'] ) :
4042 - $should_show_usermeta_in_text_field = false;
4043 - ?>
4044 - <select
4045 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4046 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4047 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );"
4048 - >
4049 - <option value=""<?php selected( empty( $approved_user['usermeta'] ) ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4050 - <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
4051 - <option value="<?php echo esc_attr( $key ); ?>"<?php selected( $key === $approved_user['usermeta'] || ( isset( $approved_user['usermeta']['meta_value'] ) && $key === $approved_user['usermeta']['meta_value'] ) ); ?>><?php echo esc_html( $label ); ?></option>
4052 - <?php endforeach; ?>
4053 - </select>
4054 - <?php endif; ?>
4055 - <?php endif; ?>
4056 - <?php if ( $should_show_usermeta_in_text_field ) : ?>
4057 - <input
4058 - type="text"
4059 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4060 - value="<?php echo esc_attr( $approved_user['usermeta'], ENT_COMPAT ); ?>"
4061 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4062 - />
4063 - <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
4064 - <?php endif; ?>
4065 - <?php endif; ?>
4066 - <?php if ( ! $is_current_user && ! $is_multisite_user ) : ?>
4067 - <?php if ( ! $is_multisite_admin_page ) : ?>
4068 - <a class="button" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( this, 'blocked', false ); <?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser( this, 'approved' );" title="<?php esc_attr_e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
4069 - <?php endif; ?>
4070 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser(this, 'approved' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4071 - <?php endif; ?>
4072 - <?php if ( $is_local_user ) : ?>
4073 - &nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>
4074 - <?php endif; ?>
4075 - <?php if ( $is_multisite_user ) : ?>
4076 - &nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
4077 - <?php endif; ?>
4078 - </li>
3374 + <div class="btn-group">
3375 + <a href="javascript:void(0);" class="btn button-primary dropdown-toggle" id="approve_user_new" onclick="<?php echo $js_function_prefix; ?>add_user(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3376 + <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3377 + <span class="caret"></span>
3378 + <span class="sr-only"><?php _e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3379 + </button>
3380 + <ul class="dropdown-menu" role="menu">
3381 + <li><a href="javascript:void(0);" onclick="<?php echo $js_function_prefix; ?>add_user( document.getElementById('approve_user_new' ), 'approved', true);"><?php _e( 'Create a local WordPress <br />account instead, and email <br />the user their password.', 'authorizer' ); ?></a></li>
3382 + </ul>
3383 + </div>
3384 + </div>
4079 3385 <?php
4080 3386 }
4081 3387
4082 3388
4083 - /**
4084 - * Settings print callback.
4085 - *
4086 - * @param string $args Args (e.g., multisite admin mode).
4087 - * @return void
4088 - */
4089 - public function print_combo_auth_access_users_blocked( $args = '' ) {
3389 + function print_combo_auth_access_users_blocked( $args = '' ) {
4090 3390 // Get plugin option.
4091 - $option = 'access_users_blocked';
3391 + $option = 'access_users_blocked';
4092 3392 $auth_settings_option = $this->get_plugin_option( $option );
4093 3393 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4094 3394
4095 3395 // Get default role for new blocked user dropdown.
4096 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3396 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
4097 3397
4098 - // Render wrapper div (for aligning pager to width of content).
4099 - ?>
4100 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
4101 - <ul id="list_auth_settings_<?php echo esc_attr( $option ); ?>" style="margin:0;">
4102 - <?php
4103 - foreach ( $auth_settings_option as $key => $blocked_user ) :
4104 - if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) :
4105 - continue;
4106 - endif;
4107 - $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
4108 - if ( $blocked_wp_user ) :
4109 - $blocked_user['email'] = $blocked_wp_user->user_email;
4110 - $blocked_user['role'] = array_shift( $blocked_wp_user->roles );
4111 - $blocked_user['date_added'] = $blocked_wp_user->user_registered;
4112 - $blocked_user['is_wp_user'] = true;
4113 - else :
4114 - $blocked_user['is_wp_user'] = false;
4115 - endif;
4116 - ?>
4117 - <li>
4118 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $blocked_user['email'] ); ?>" readonly="true" class="auth-email" />
4119 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
4120 - <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
4121 - </select>
4122 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_date_added" value="<?php echo esc_attr( date( 'M Y', strtotime( $blocked_user['date_added'] ) ) ); ?>" readonly="true" class="auth-date-added" />
4123 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'blocked' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4124 - </li>
4125 - <?php endforeach; ?>
4126 - </ul>
4127 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
4128 - <input type="text" id="new_blocked_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
4129 - <select id="new_blocked_user_role" class="auth-role">
4130 - <option value="<?php echo esc_attr( $access_default_role ); ?>"><?php echo esc_html( ucfirst( $access_default_role ) ); ?></option>
4131 - </select>
4132 - <a href="javascript:void(0);" class="button-primary button-add-user" id="block_user_new" onclick="authAddUser( this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
4133 - </div>
3398 + // Print option elements.
3399 + ?><ul id="list_auth_settings_<?php echo $option; ?>" style="margin:0;">
3400 + <?php foreach ( $auth_settings_option as $key => $blocked_user ): ?>
3401 + <?php if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) continue; ?>
3402 + <?php if ( $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ) ): ?>
3403 + <?php $blocked_user['email'] = $blocked_wp_user->user_email; ?>
3404 + <?php $blocked_user['role'] = array_shift( $blocked_wp_user->roles ); ?>
3405 + <?php $blocked_user['date_added'] = $blocked_wp_user->user_registered; ?>
3406 + <?php $blocked_user['is_wp_user'] = true; ?>
3407 + <?php else: ?>
3408 + <?php $blocked_user['is_wp_user'] = false; ?>
3409 + <?php endif; ?>
3410 + <li>
3411 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $blocked_user['email']; ?>" readonly="true" class="auth-email" />
3412 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3413 + <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
3414 + </select>
3415 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $blocked_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3416 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user(this, 'blocked' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3417 + </li>
3418 + <?php endforeach; ?>
3419 + </ul>
3420 + <div id="new_auth_settings_<?php echo $option; ?>">
3421 + <input type="text" id="new_blocked_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3422 + <select id="new_blocked_user_role" class="auth-role">
3423 + <option value="<?php echo $access_default_role; ?>"><?php echo ucfirst( $access_default_role ); ?></option>
3424 + </select>
3425 + <a href="javascript:void(0);" class="button-primary" id="block_user_new" onclick="auth_add_user(this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
4134 3426 </div>
4135 3427 <?php
4136 3428 }
4137 3429
4138 3430
4139 - /**
4140 - * Settings print callback.
4141 - *
4142 - * @param string $args Args (e.g., multisite admin mode).
4143 - * @return void
4144 - */
4145 - public function print_section_info_access_login( $args = '' ) {
4146 - ?>
4147 - <div id="section_info_access_login" class="section_info">
3431 + function print_section_info_access_login( $args = '' ) {
3432 + ?><div id="section_info_access_login" class="section_info">
4148 3433 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
4149 - <p><?php esc_html_e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
4150 - </div>
4151 - <?php
3434 + <p><?php _e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
3435 + </div><?php
4152 3436 }
4153 3437
4154 3438
4155 - /**
4156 - * Settings print callback.
4157 - *
4158 - * @param string $args Args (e.g., multisite admin mode).
4159 - * @return void
4160 - */
4161 - public function print_radio_auth_access_who_can_login( $args = '' ) {
3439 + function print_radio_auth_access_who_can_login( $args = '' ) {
4162 3440 // Get plugin option.
4163 - $option = 'access_who_can_login';
4164 - $admin_mode = $this->get_admin_mode( $args );
3441 + $option = 'access_who_can_login';
3442 + $admin_mode = $this->get_admin_mode( $args );
4165 3443 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4166 3444
4167 3445 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4168 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3446 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4169 3447 $auth_settings_option = $this->get_plugin_option( $option );
4170 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) === '1' ) {
3448 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4171 3449 // Workaround: javascript code hides/shows other settings based
4172 3450 // on the selection in this option. If this option is overridden
4173 3451 // by a multisite option, it should show that value in order to
4174 3452 // correctly display the other appropriate options.
@@ -4174,49 +3452,33 @@
4174 3452 // correctly display the other appropriate options.
4175 3453 // Side effect: this site option will be overwritten by the
4176 3454 // multisite option on save. Since this is a 2-item radio, we
4177 3455 // determined this was acceptable.
4178 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3456 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4179 3457 }
4180 3458
4181 3459 // Print option elements.
4182 - ?>
4183 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="external_users"<?php checked( 'external_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users"><?php esc_html_e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
4184 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="approved_users"<?php checked( 'approved_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users"><?php esc_html_e( 'Only', 'authorizer' ); ?> <a href="javascript:chooseTab('access_lists' );" id="dashboard_link_approved_users"><?php esc_html_e( 'approved users', 'authorizer' ); ?></a> <?php esc_html_e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br />
4185 - <?php
3460 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_external_users" name="auth_settings[<?php echo $option; ?>]" value="external_users"<?php checked( 'external_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_external_users"><?php _e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
3461 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_approved_users" name="auth_settings[<?php echo $option; ?>]" value="approved_users"<?php checked( 'approved_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_approved_users"><?php _e( 'Only', 'authorizer' ); ?> <a href="javascript:choose_tab('access_lists' );" id="dashboard_link_approved_users"><?php _e( 'approved users', 'authorizer' ); ?></a> <?php _e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br /><?php
4186 3462 }
4187 3463
4188 3464
4189 - /**
4190 - * Settings print callback.
4191 - *
4192 - * @param string $args Args (e.g., multisite admin mode).
4193 - * @return void
4194 - */
4195 - public function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
3465 + function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
4196 3466 // Get plugin option.
4197 - $option = 'access_role_receive_pending_emails';
3467 + $option = 'access_role_receive_pending_emails';
4198 3468 $auth_settings_option = $this->get_plugin_option( $option );
4199 3469
4200 3470 // Print option elements.
4201 - ?>
4202 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
4203 - <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php esc_html_e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
3471 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
3472 + <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php _e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
4204 3473 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4205 - </select>
4206 - <?php
3474 + </select><?php
4207 3475 }
4208 3476
4209 3477
4210 - /**
4211 - * Settings print callback.
4212 - *
4213 - * @param string $args Args (e.g., multisite admin mode).
4214 - * @return void
4215 - */
4216 - public function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
3478 + function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
4217 3479 // Get plugin option.
4218 - $option = 'access_pending_redirect_to_message';
3480 + $option = 'access_pending_redirect_to_message';
4219 3481 $auth_settings_option = $this->get_plugin_option( $option );
4220 3482
4221 3483 // Print option elements.
4222 3484 wp_editor(
@@ -4225,25 +3487,19 @@
4225 3487 array(
4226 3488 'media_buttons' => false,
4227 3489 'textarea_name' => "auth_settings[$option]",
4228 3490 'textarea_rows' => 5,
4229 - 'tinymce' => true,
4230 - 'teeny' => true,
4231 - 'quicktags' => false,
3491 + 'tinymce' => true,
3492 + 'teeny' => true,
3493 + 'quicktags' => false,
4232 3494 )
4233 3495 );
4234 3496 }
4235 3497
4236 3498
4237 - /**
4238 - * Settings print callback.
4239 - *
4240 - * @param string $args Args (e.g., multisite admin mode).
4241 - * @return void
4242 - */
4243 - public function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
3499 + function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
4244 3500 // Get plugin option.
4245 - $option = 'access_blocked_redirect_to_message';
3501 + $option = 'access_blocked_redirect_to_message';
4246 3502 $auth_settings_option = $this->get_plugin_option( $option );
4247 3503
4248 3504 // Print option elements.
4249 3505 wp_editor(
@@ -4252,61 +3508,39 @@
4252 3508 array(
4253 3509 'media_buttons' => false,
4254 3510 'textarea_name' => "auth_settings[$option]",
4255 3511 'textarea_rows' => 5,
4256 - 'tinymce' => true,
4257 - 'teeny' => true,
4258 - 'quicktags' => false,
3512 + 'tinymce' => true,
3513 + 'teeny' => true,
3514 + 'quicktags' => false,
4259 3515 )
4260 3516 );
4261 3517 }
4262 3518
4263 3519
4264 - /**
4265 - * Settings print callback.
4266 - *
4267 - * @param string $args Args (e.g., multisite admin mode).
4268 - * @return void
4269 - */
4270 - public function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
3520 + function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
4271 3521 // Get plugin option.
4272 - $option = 'access_should_email_approved_users';
3522 + $option = 'access_should_email_approved_users';
4273 3523 $auth_settings_option = $this->get_plugin_option( $option );
4274 3524
4275 3525 // Print option elements.
4276 - ?>
4277 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label>
4278 - <?php
3526 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label><?php
4279 3527 }
4280 3528
4281 3529
4282 - /**
4283 - * Settings print callback.
4284 - *
4285 - * @param string $args Args (e.g., multisite admin mode).
4286 - * @return void
4287 - */
4288 - public function print_text_auth_access_email_approved_users_subject( $args = '' ) {
3530 + function print_text_auth_access_email_approved_users_subject( $args = '' ) {
4289 3531 // Get plugin option.
4290 - $option = 'access_email_approved_users_subject';
3532 + $option = 'access_email_approved_users_subject';
4291 3533 $auth_settings_option = $this->get_plugin_option( $option );
4292 3534
4293 3535 // Print option elements.
4294 - ?>
4295 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php echo wp_kses( __( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ), $this->allowed_html ); ?></small>
4296 - <?php
3536 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php _e( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ); ?></small><?php
4297 3537 }
4298 3538
4299 3539
4300 - /**
4301 - * Settings print callback.
4302 - *
4303 - * @param string $args Args (e.g., multisite admin mode).
4304 - * @return void
4305 - */
4306 - public function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
3540 + function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
4307 3541 // Get plugin option.
4308 - $option = 'access_email_approved_users_body';
3542 + $option = 'access_email_approved_users_body';
4309 3543 $auth_settings_option = $this->get_plugin_option( $option );
4310 3544
4311 3545 // Print option elements.
4312 3546 wp_editor(
@@ -4315,60 +3549,42 @@
4315 3549 array(
4316 3550 'media_buttons' => false,
4317 3551 'textarea_name' => "auth_settings[$option]",
4318 3552 'textarea_rows' => 9,
4319 - 'tinymce' => true,
4320 - 'teeny' => true,
4321 - 'quicktags' => false,
3553 + 'tinymce' => true,
3554 + 'teeny' => true,
3555 + 'quicktags' => false,
4322 3556 )
4323 3557 );
4324 - ?>
4325 - <small>
4326 - <?php
4327 - printf(
4328 - /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
4329 - wp_kses( __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ), $this->allowed_html ),
4330 - '<b>[site_name]</b>',
4331 - '<b>[site_url]</b>',
4332 - '<b>[user_email]</b>'
4333 - );
4334 - ?>
4335 - </small>
4336 - <?php
3558 +
3559 + ?><small><?php printf(
3560 + /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
3561 + __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ),
3562 + '<b>[site_name]</b>',
3563 + '<b>[site_url]</b>',
3564 + '<b>[user_email]</b>'
3565 + ); ?></small><?php
3566 +
4337 3567 }
4338 3568
4339 3569
4340 - /**
4341 - * Settings print callback.
4342 - *
4343 - * @param string $args Args (e.g., multisite admin mode).
4344 - * @return void
4345 - */
4346 - public function print_section_info_access_public( $args = '' ) {
4347 - ?>
4348 - <div id="section_info_access_public" class="section_info">
4349 - <p><?php esc_html_e( 'Choose your public access options here.', 'authorizer' ); ?></p>
4350 - </div>
4351 - <?php
3570 + function print_section_info_access_public( $args = '' ) {
3571 + ?><div id="section_info_access_public" class="section_info">
3572 + <p><?php _e( 'Choose your public access options here.', 'authorizer' ); ?></p>
3573 + </div><?php
4352 3574 }
4353 3575
4354 3576
4355 - /**
4356 - * Settings print callback.
4357 - *
4358 - * @param string $args Args (e.g., multisite admin mode).
4359 - * @return void
4360 - */
4361 - public function print_radio_auth_access_who_can_view( $args = '' ) {
3577 + function print_radio_auth_access_who_can_view( $args = '' ) {
4362 3578 // Get plugin option.
4363 - $option = 'access_who_can_view';
4364 - $admin_mode = $this->get_admin_mode( $args );
3579 + $option = 'access_who_can_view';
3580 + $admin_mode = $this->get_admin_mode( $args );
4365 3581 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4366 3582
4367 3583 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4368 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3584 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4369 3585 $auth_settings_option = $this->get_plugin_option( $option );
4370 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && '1' === $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) ) {
3586 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4371 3587 // Workaround: javascript code hides/shows other settings based
4372 3588 // on the selection in this option. If this option is overridden
4373 3589 // by a multisite option, it should show that value in order to
4374 3590 // correctly display the other appropriate options.
@@ -4374,66 +3590,42 @@
4374 3590 // correctly display the other appropriate options.
4375 3591 // Side effect: this site option will be overwritten by the
4376 3592 // multisite option on save. Since this is a 2-item radio, we
4377 3593 // determined this was acceptable.
4378 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3594 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4379 3595 }
4380 3596
4381 3597 // Print option elements.
4382 - ?>
4383 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="everyone"<?php checked( 'everyone' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone"><?php esc_html_e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
4384 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="logged_in_users"<?php checked( 'logged_in_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users"><?php esc_html_e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br />
4385 - <?php
3598 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_everyone" name="auth_settings[<?php echo $option; ?>]" value="everyone"<?php checked( 'everyone' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_everyone"><?php _e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
3599 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_logged_in_users" name="auth_settings[<?php echo $option; ?>]" value="logged_in_users"<?php checked( 'logged_in_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_logged_in_users"><?php _e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br /><?php
4386 3600 }
4387 3601
4388 3602
4389 - /**
4390 - * Settings print callback.
4391 - *
4392 - * @param string $args Args (e.g., multisite admin mode).
4393 - * @return void
4394 - */
4395 - public function print_radio_auth_access_redirect( $args = '' ) {
3603 + function print_radio_auth_access_redirect( $args = '' ) {
4396 3604 // Get plugin option.
4397 - $option = 'access_redirect';
3605 + $option = 'access_redirect';
4398 3606 $auth_settings_option = $this->get_plugin_option( $option );
4399 3607
4400 3608 // Print option elements.
4401 - ?>
4402 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="login"<?php checked( 'login' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login"><?php esc_html_e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
4403 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="message"<?php checked( 'message' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message"><?php esc_html_e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label>
4404 - <?php
3609 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_login" name="auth_settings[<?php echo $option; ?>]" value="login"<?php checked( 'login' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_login"><?php _e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
3610 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_message" name="auth_settings[<?php echo $option; ?>]" value="message"<?php checked( 'message' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_message"><?php _e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label><?php
4405 3611 }
4406 3612
4407 3613
4408 - /**
4409 - * Settings print callback.
4410 - *
4411 - * @param string $args Args (e.g., multisite admin mode).
4412 - * @return void
4413 - */
4414 - public function print_radio_auth_access_public_warning( $args = '' ) {
3614 + function print_radio_auth_access_public_warning( $args = '' ) {
4415 3615 // Get plugin option.
4416 - $option = 'access_public_warning';
3616 + $option = 'access_public_warning';
4417 3617 $auth_settings_option = $this->get_plugin_option( $option );
4418 3618
4419 3619 // Print option elements.
4420 - ?>
4421 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="no_warning"<?php checked( 'no_warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no"><?php echo wp_kses( __( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ), $this->allowed_html ); ?></label><br />
4422 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="warning"<?php checked( 'warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>"><?php echo wp_kses( __( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ), $this->allowed_html ); ?></label>
4423 - <?php
3620 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_no" name="auth_settings[<?php echo $option; ?>]" value="no_warning"<?php checked( 'no_warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_no"><?php _e( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ); ?></label><br />
3621 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="warning"<?php checked( 'warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>"><?php _e( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ); ?></label><?php
4424 3622 }
4425 3623
4426 3624
4427 - /**
4428 - * Settings print callback.
4429 - *
4430 - * @param string $args Args (e.g., multisite admin mode).
4431 - * @return void
4432 - */
4433 - public function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
3625 + function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
4434 3626 // Get plugin option.
4435 - $option = 'access_redirect_to_message';
3627 + $option = 'access_redirect_to_message';
4436 3628 $auth_settings_option = $this->get_plugin_option( $option );
4437 3629
4438 3630 // Print option elements.
4439 3631 wp_editor(
@@ -4442,25 +3634,19 @@
4442 3634 array(
4443 3635 'media_buttons' => false,
4444 3636 'textarea_name' => "auth_settings[$option]",
4445 3637 'textarea_rows' => 5,
4446 - 'tinymce' => true,
4447 - 'teeny' => true,
4448 - 'quicktags' => false,
3638 + 'tinymce' => true,
3639 + 'teeny' => true,
3640 + 'quicktags' => false,
4449 3641 )
4450 3642 );
4451 3643 }
4452 3644
4453 3645
4454 - /**
4455 - * Settings print callback.
4456 - *
4457 - * @param string $args Args (e.g., multisite admin mode).
4458 - * @return void
4459 - */
4460 - public function print_multiselect_auth_access_public_pages( $args = '' ) {
3646 + function print_multiselect_auth_access_public_pages( $args = '' ) {
4461 3647 // Get plugin option.
4462 - $option = 'access_public_pages';
3648 + $option = 'access_public_pages';
4463 3649 $auth_settings_option = $this->get_plugin_option( $option );
4464 3650 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4465 3651
4466 3652 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
@@ -4466,31 +3652,23 @@
4466 3652 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
4467 3653 $post_types = is_array( $post_types ) ? $post_types : array();
4468 3654
4469 3655 // Print option elements.
4470 - ?>
4471 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" multiple="multiple" name="auth_settings[<?php echo esc_attr( $option ); ?>][]">
4472 - <optgroup label="<?php esc_attr_e( 'Home', 'authorizer' ); ?>">
4473 - <option value="home" <?php selected( in_array( 'home', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Home Page', 'authorizer' ); ?></option>
4474 - <option value="auth_public_404" <?php selected( in_array( 'auth_public_404', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
3656 + ?><select id="auth_settings_<?php echo $option; ?>" multiple="multiple" name="auth_settings[<?php echo $option; ?>][]">
3657 + <optgroup label="<?php _e( 'Home', 'authorizer' ); ?>">
3658 + <option value="home" <?php echo in_array( 'home', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Home Page', 'authorizer' ); ?></option>
3659 + <option value="auth_public_404" <?php echo in_array( 'auth_public_404', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
4475 3660 </optgroup>
4476 - <?php foreach ( $post_types as $post_type ) : ?>
4477 - <optgroup label="<?php echo esc_attr( ucfirst( $post_type ) ); ?>">
4478 - <?php
4479 - $pages = get_posts(
4480 - array(
4481 - 'post_type' => $post_type,
4482 - 'posts_per_page' => 1000, // phpcs:ignore WordPress.VIP.PostsPerPage.posts_per_page_posts_per_page
4483 - )
4484 - );
4485 - $pages = is_array( $pages ) ? $pages : array();
4486 - foreach ( $pages as $page ) :
4487 - ?>
4488 - <option value="<?php echo esc_attr( $page->ID ); ?>" <?php selected( in_array( strval( $page->ID ), $auth_settings_option, true ) ); ?>><?php echo esc_html( $page->post_title ); ?></option>
3661 + <?php foreach ( $post_types as $post_type ): ?>
3662 + <optgroup label="<?php echo ucfirst( $post_type ); ?>">
3663 + <?php $pages = get_posts( array( 'post_type' => $post_type, 'posts_per_page' => -1 ) ); ?>
3664 + <?php $pages = is_array( $pages ) ? $pages : array(); ?>
3665 + <?php foreach ( $pages as $page ): ?>
3666 + <option value="<?php echo $page->ID; ?>" <?php echo in_array( $page->ID, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $page->post_title; ?></option>
4489 3667 <?php endforeach; ?>
4490 3668 </optgroup>
4491 3669 <?php endforeach; ?>
4492 - <optgroup label="<?php esc_attr_e( 'Categories', 'authorizer' ); ?>">
3670 + <optgroup label="<?php _e( 'Categories', 'authorizer' ); ?>">
4493 3671 <?php
4494 3672 // If sitepress-multilingual-cms plugin is enabled, temporarily disable
4495 3673 // its terms_clauses filter since it conflicts with the category handling.
4496 3674 if ( array_key_exists( 'sitepress', $GLOBALS ) && is_object( $GLOBALS['sitepress'] ) ) {
@@ -4499,155 +3677,107 @@
4499 3677 add_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) );
4500 3678 } else {
4501 3679 $categories = get_categories( array( 'hide_empty' => false ) );
4502 3680 }
4503 - foreach ( $categories as $category ) :
4504 - ?>
4505 - <option value="<?php echo esc_attr( 'cat_' . $category->slug ); ?>" <?php selected( in_array( 'cat_' . $category->slug, $auth_settings_option, true ) ); ?>><?php echo esc_html( $category->name ); ?></option>
3681 + foreach ( $categories as $category ) : ?>
3682 + <option value="<?php echo 'cat_' . $category->slug; ?>" <?php echo in_array( 'cat_' . $category->slug, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $category->name; ?></option>
4506 3683 <?php endforeach; ?>
4507 3684 </optgroup>
4508 - </select>
4509 - <?php
3685 + </select><?php
4510 3686 }
4511 3687
4512 3688
4513 - /**
4514 - * Settings print callback.
4515 - *
4516 - * @param string $args Args (e.g., multisite admin mode).
4517 - * @return void
4518 - */
4519 - public function print_section_info_external( $args = '' ) {
4520 - ?>
4521 - <div id="section_info_external" class="section_info">
4522 - <p><?php esc_html_e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
4523 - </div>
4524 - <?php
3689 + function print_section_info_external( $args = '' ) {
3690 + ?><div id="section_info_external" class="section_info">
3691 + <p><?php _e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
3692 + </div><?php
4525 3693 }
4526 3694
4527 3695
4528 - /**
4529 - * Settings print callback.
4530 - *
4531 - * @param string $args Args (e.g., multisite admin mode).
4532 - * @return void
4533 - */
4534 - public function print_select_auth_access_default_role( $args = '' ) {
3696 + function get_admin_mode( $args ) {
3697 + if ( is_array( $args ) && array_key_exists( MULTISITE_ADMIN, $args ) && $args[MULTISITE_ADMIN] === true ) {
3698 + return MULTISITE_ADMIN;
3699 + } else {
3700 + return SINGLE_ADMIN;
3701 + }
3702 + }
3703 +
3704 +
3705 + function print_select_auth_access_default_role( $args = '' ) {
4535 3706 // Get plugin option.
4536 - $option = 'access_default_role';
3707 + $option = 'access_default_role';
4537 3708 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4538 3709
4539 3710 // Print option elements.
4540 - ?>
4541 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3711 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4542 3712 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4543 - <option value=""<?php selected( '' === $auth_settings_option ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4544 - </select>
4545 - <?php
3713 + </select><?php
4546 3714 }
4547 3715
4548 3716
4549 - /**
4550 - * Settings print callback.
4551 - *
4552 - * @param string $args Args (e.g., multisite admin mode).
4553 - * @return void
4554 - */
4555 - public function print_checkbox_auth_external_google( $args = '' ) {
3717 + function print_checkbox_auth_external_google( $args = '' ) {
4556 3718 // Get plugin option.
4557 - $option = 'google';
3719 + $option = 'google';
4558 3720 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4559 3721
4560 3722 // Print option elements.
4561 - ?>
4562 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable Google Logins', 'authorizer' ); ?></label>
4563 - <?php
3723 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable Google Logins', 'authorizer' ); ?></label><?php
4564 3724 }
4565 3725
4566 3726
4567 - /**
4568 - * Settings print callback.
4569 - *
4570 - * @param string $args Args (e.g., multisite admin mode).
4571 - * @return void
4572 - */
4573 - public function print_text_google_clientid( $args = '' ) {
3727 + function print_text_google_clientid( $args = '' ) {
4574 3728 // Get plugin option.
4575 - $option = 'google_clientid';
3729 + $option = 'google_clientid';
4576 3730 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4577 3731
4578 3732 // Print option elements.
4579 - $site_url_parts = wp_parse_url( get_site_url() );
4580 - $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
4581 -
4582 - esc_html_e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' );
4583 - ?>
3733 + $site_url_parts = parse_url( get_site_url() );
3734 + $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
3735 + ?><?php _e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' ); ?>
4584 3736 <ol>
4585 - <li><?php echo wp_kses( __( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ), $this->allowed_html ); ?></li>
4586 - <li><?php echo wp_kses( __( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ), $this->allowed_html ); ?>
3737 + <li><?php _e( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ); ?></li>
3738 + <li><?php _e( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ); ?>
4587 3739 <ul>
4588 - <li><?php echo wp_kses( __( 'Application Type: <strong>Web application</strong>', 'authorizer' ), $this->allowed_html ); ?></li>
4589 - <li><?php esc_html_e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo esc_html( rtrim( $site_url_host, '/' ) ); ?></strong></li>
4590 - <li><?php echo wp_kses( __( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ), $this->allowed_html ); ?></li>
3740 + <li><?php _e( 'Application Type: <strong>Web application</strong>', 'authorizer' ); ?></li>
3741 + <li><?php _e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo rtrim( $site_url_host, '/' ); ?></strong></li>
3742 + <li><?php _e( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ); ?></li>
4591 3743 </ul>
4592 3744 </li>
4593 - <li><?php esc_html_e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
4594 - <li><?php echo wp_kses( __( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ), $this->allowed_html ); ?></li>
4595 - <li><?php echo wp_kses( __( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ), $this->allowed_html ); ?></li>
3745 + <li><?php _e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
3746 + <li><?php _e( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ); ?></li>
3747 + <li><?php _e( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ); ?></li>
4596 3748 </ol>
4597 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:560px;" />
4598 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer' ); ?></label>
4599 - <?php
3749 + <input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:560px;" />
3750 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer'); ?></label><?php
4600 3751 }
4601 3752
4602 3753
4603 - /**
4604 - * Settings print callback.
4605 - *
4606 - * @param string $args Args (e.g., multisite admin mode).
4607 - * @return void
4608 - */
4609 - public function print_text_google_clientsecret( $args = '' ) {
3754 + function print_text_google_clientsecret( $args = '' ) {
4610 3755 // Get plugin option.
4611 - $option = 'google_clientsecret';
3756 + $option = 'google_clientsecret';
4612 3757 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4613 3758
4614 3759 // Print option elements.
4615 - ?>
4616 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:220px;" />
4617 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer' ); ?></label>
4618 - <?php
3760 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:220px;" />
3761 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer'); ?></label><?php
4619 3762 }
4620 3763
4621 3764
4622 - /**
4623 - * Settings print callback.
4624 - *
4625 - * @param string $args Args (e.g., multisite admin mode).
4626 - * @return void
4627 - */
4628 - public function print_text_google_hosteddomain( $args = '' ) {
3765 + function print_text_google_hosteddomain( $args = '' ) {
4629 3766 // Get plugin option.
4630 - $option = 'google_hosteddomain';
3767 + $option = 'google_hosteddomain';
4631 3768 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4632 3769
4633 3770 // Print option elements.
4634 - ?>
4635 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:220px;"><?php echo esc_html( $auth_settings_option ); ?></textarea>
4636 - <br /><small><?php esc_html_e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php esc_html_e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
3771 + ?><textarea id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" placeholder="" style="width:220px;"><?php echo $auth_settings_option; ?></textarea>
3772 + <br /><small><?php _e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php _e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
4637 3773 <?php
4638 3774 }
4639 3775
4640 3776
4641 - /**
4642 - * Settings print callback.
4643 - *
4644 - * @param string $args Args (e.g., multisite admin mode).
4645 - * @return void
4646 - */
4647 - public function print_checkbox_auth_external_cas( $args = '' ) {
3777 + function print_checkbox_auth_external_cas( $args = '' ) {
4648 3778 // Get plugin option.
4649 - $option = 'cas';
3779 + $option = 'cas';
4650 3780 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4651 3781
4652 3782 // Make sure php5-curl extension is installed on server.
4653 3783 $curl_installed_message = ! function_exists( 'curl_init' ) ? __( '<a href="http://www.php.net//manual/en/curl.installation.php" target="_blank" style="color: red;">PHP CURL extension</a> is not installed', 'authorizer' ) : '';
@@ -4666,217 +3796,128 @@
4666 3796 ')</span>';
4667 3797 }
4668 3798
4669 3799 // Print option elements.
4670 - ?>
4671 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $error_message, $this->allowed_html ); ?>
4672 - <?php
3800 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo $error_message; ?><?php
4673 3801 }
4674 3802
4675 3803
4676 - /**
4677 - * Settings print callback.
4678 - *
4679 - * @param string $args Args (e.g., multisite admin mode).
4680 - * @return void
4681 - */
4682 - public function print_text_cas_custom_label( $args = '' ) {
3804 + function print_text_cas_custom_label( $args = '' ) {
4683 3805 // Get plugin option.
4684 - $option = 'cas_custom_label';
3806 + $option = 'cas_custom_label';
4685 3807 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4686 3808
4687 3809 // Print option elements.
4688 - esc_html_e( 'The button on the login page will read:', 'authorizer' );
4689 - ?>
4690 - <p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php esc_html_e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="CAS" style="width: 100px;" /></a></p>
4691 - <?php
3810 + ?><?php _e( 'The button on the login page will read:', 'authorizer' ); ?><p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php _e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="CAS" style="width: 100px;" /></a></p><?php
4692 3811 }
4693 3812
4694 3813
4695 - /**
4696 - * Settings print callback.
4697 - *
4698 - * @param string $args Args (e.g., multisite admin mode).
4699 - * @return void
4700 - */
4701 - public function print_text_cas_host( $args = '' ) {
3814 + function print_text_cas_host( $args = '' ) {
4702 3815 // Get plugin option.
4703 - $option = 'cas_host';
3816 + $option = 'cas_host';
4704 3817 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4705 3818
4706 3819 // Print option elements.
4707 - ?>
4708 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4709 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: authn.example.edu', 'authorizer' ); ?></label>
4710 - <?php
3820 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3821 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: authn.example.edu', 'authorizer'); ?></label><?php
4711 3822 }
4712 3823
4713 3824
4714 - /**
4715 - * Settings print callback.
4716 - *
4717 - * @param string $args Args (e.g., multisite admin mode).
4718 - * @return void
4719 - */
4720 - public function print_text_cas_port( $args = '' ) {
3825 + function print_text_cas_port( $args = '' ) {
4721 3826 // Get plugin option.
4722 - $option = 'cas_port';
3827 + $option = 'cas_port';
4723 3828 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4724 3829
4725 3830 // Print option elements.
4726 - ?>
4727 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4728 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 443', 'authorizer' ); ?></label>
4729 - <?php
3831 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:50px;" />
3832 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 443', 'authorizer'); ?></label><?php
4730 3833 }
4731 3834
4732 3835
4733 - /**
4734 - * Settings print callback.
4735 - *
4736 - * @param string $args Args (e.g., multisite admin mode).
4737 - * @return void
4738 - */
4739 - public function print_text_cas_path( $args = '' ) {
3836 + function print_text_cas_path( $args = '' ) {
4740 3837 // Get plugin option.
4741 - $option = 'cas_path';
3838 + $option = 'cas_path';
4742 3839 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4743 3840
4744 3841 // Print option elements.
4745 - ?>
4746 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4747 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: /cas', 'authorizer' ); ?></label>
4748 - <?php
3842 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3843 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: /cas', 'authorizer'); ?></label><?php
4749 3844 }
4750 3845
4751 3846
4752 - /**
4753 - * Settings print callback.
4754 - *
4755 - * @param string $args Args (e.g., multisite admin mode).
4756 - * @return void
4757 - */
4758 - public function print_select_cas_version( $args = '' ) {
3847 + function print_select_cas_version( $args = '' ) {
4759 3848 // Get plugin option.
4760 - $option = 'cas_version';
3849 + $option = 'cas_version';
4761 3850 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4762 3851
4763 3852 // Print option elements.
4764 - ?>
4765 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3853 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4766 3854 <option value="SAML_VERSION_1_1" <?php selected( $auth_settings_option, 'SAML_VERSION_1_1' ); ?>>SAML_VERSION_1_1</option>
4767 3855 <option value="CAS_VERSION_3_0" <?php selected( $auth_settings_option, 'CAS_VERSION_3_0' ); ?>>CAS_VERSION_3_0</option>
4768 3856 <option value="CAS_VERSION_2_0" <?php selected( $auth_settings_option, 'CAS_VERSION_2_0' ); ?>>CAS_VERSION_2_0</option>
4769 3857 <option value="CAS_VERSION_1_0" <?php selected( $auth_settings_option, 'CAS_VERSION_1_0' ); ?>>CAS_VERSION_1_0</option>
4770 - </select>
4771 - <?php
3858 + </select><?php
4772 3859 }
4773 3860
4774 3861
4775 - /**
4776 - * Settings print callback.
4777 - *
4778 - * @param string $args Args (e.g., multisite admin mode).
4779 - * @return void
4780 - */
4781 - public function print_text_cas_attr_email( $args = '' ) {
3862 + function print_text_cas_attr_email( $args = '' ) {
4782 3863 // Get plugin option.
4783 - $option = 'cas_attr_email';
3864 + $option = 'cas_attr_email';
4784 3865 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4785 3866
4786 3867 // Print option elements.
4787 - ?>
4788 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4789 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
4790 - <br /><small><?php echo wp_kses( __( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
4791 - <?php
3868 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3869 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: mail', 'authorizer'); ?></label>
3870 + <br /><small><?php _e( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
4792 3871 }
4793 3872
4794 3873
4795 - /**
4796 - * Settings print callback.
4797 - *
4798 - * @param string $args Args (e.g., multisite admin mode).
4799 - * @return void
4800 - */
4801 - public function print_text_cas_attr_first_name( $args = '' ) {
3874 + function print_text_cas_attr_first_name( $args = '' ) {
4802 3875 // Get plugin option.
4803 - $option = 'cas_attr_first_name';
3876 + $option = 'cas_attr_first_name';
4804 3877 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4805 3878
4806 3879 // Print option elements.
4807 - ?>
4808 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4809 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenName', 'authorizer' ); ?></label>
4810 - <?php
3880 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3881 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: givenName', 'authorizer'); ?></label><?php
4811 3882 }
4812 3883
4813 3884
4814 - /**
4815 - * Settings print callback.
4816 - *
4817 - * @param string $args Args (e.g., multisite admin mode).
4818 - * @return void
4819 - */
4820 - public function print_text_cas_attr_last_name( $args = '' ) {
3885 + function print_text_cas_attr_last_name( $args = '' ) {
4821 3886 // Get plugin option.
4822 - $option = 'cas_attr_last_name';
3887 + $option = 'cas_attr_last_name';
4823 3888 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4824 3889
4825 3890 // Print option elements.
4826 - ?>
4827 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4828 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
4829 - <?php
3891 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3892 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sn', 'authorizer'); ?></label><?php
4830 3893 }
4831 3894
4832 3895
4833 - /**
4834 - * Settings print callback.
4835 - *
4836 - * @param string $args Args (e.g., multisite admin mode).
4837 - * @return void
4838 - */
4839 - public function print_checkbox_cas_attr_update_on_login( $args = '' ) {
3896 + function print_checkbox_cas_attr_update_on_login( $args = '' ) {
4840 3897 // Get plugin option.
4841 - $option = 'cas_attr_update_on_login';
3898 + $option = 'cas_attr_update_on_login';
4842 3899 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4843 3900
4844 3901 // Print option elements.
4845 - ?>
4846 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
4847 - <?php
3902 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
4848 3903 }
4849 3904
4850 3905
4851 - /**
4852 - * Settings print callback.
4853 - *
4854 - * @param string $args Args (e.g., multisite admin mode).
4855 - * @return void
4856 - */
4857 - public function print_checkbox_cas_auto_login( $args = '' ) {
3906 + function print_checkbox_cas_auto_login( $args = '' ) {
4858 3907 // Get plugin option.
4859 - $option = 'cas_auto_login';
3908 + $option = 'cas_auto_login';
4860 3909 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4861 3910
4862 3911 // Print option elements.
4863 - ?>
4864 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
4865 - <p><small><?php esc_html_e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p>
4866 - <?php
3912 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
3913 + <p><small><?php _e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p><?php
4867 3914 }
4868 3915
4869 3916
4870 - /**
4871 - * Settings print callback.
4872 - *
4873 - * @param string $args Args (e.g., multisite admin mode).
4874 - * @return void
4875 - */
4876 - public function print_checkbox_auth_external_ldap( $args = '' ) {
3917 + function print_checkbox_auth_external_ldap( $args = '' ) {
4877 3918 // Get plugin option.
4878 - $option = 'ldap';
3919 + $option = 'ldap';
4879 3920 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4880 3921
4881 3922 // Make sure php5-ldap extension is installed on server.
4882 3923 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
@@ -4881,324 +3922,193 @@
4881 3922 // Make sure php5-ldap extension is installed on server.
4882 3923 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
4883 3924
4884 3925 // Print option elements.
4885 - ?>
4886 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $ldap_installed_message, $this->allowed_html ); ?>
4887 - <?php
3926 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo $ldap_installed_message; ?><?php
4888 3927 }
4889 3928
4890 3929
4891 - /**
4892 - * Settings print callback.
4893 - *
4894 - * @param string $args Args (e.g., multisite admin mode).
4895 - * @return void
4896 - */
4897 - public function print_text_ldap_host( $args = '' ) {
3930 + function print_text_ldap_host( $args = '' ) {
4898 3931 // Get plugin option.
4899 - $option = 'ldap_host';
3932 + $option = 'ldap_host';
4900 3933 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4901 3934
4902 3935 // Print option elements.
4903 - ?>
4904 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
4905 - <br /><small><?php esc_html_e( 'Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).', 'authorizer' ); ?></small>
4906 - <?php
3936 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
3937 + <br /><small><?php _e( "Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).", 'authorizer' ); ?></small><?php
4907 3938 }
4908 3939
4909 3940
4910 - /**
4911 - * Settings print callback.
4912 - *
4913 - * @param string $args Args (e.g., multisite admin mode).
4914 - * @return void
4915 - */
4916 - public function print_text_ldap_port( $args = '' ) {
3941 + function print_text_ldap_port( $args = '' ) {
4917 3942 // Get plugin option.
4918 - $option = 'ldap_port';
3943 + $option = 'ldap_port';
4919 3944 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4920 3945
4921 3946 // Print option elements.
4922 - ?>
4923 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4924 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 389', 'authorizer' ); ?></label>
4925 - <br /><small><?php esc_html_e( 'If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.', 'authorizer' ); ?></small>
4926 - <?php
3947 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:50px;" />
3948 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 389', 'authorizer' ); ?></label>
3949 + <br /><small><?php _e( "If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.", 'authorizer' ); ?></small><?php
4927 3950 }
4928 3951
4929 3952
4930 - /**
4931 - * Settings print callback.
4932 - *
4933 - * @param string $args Args (e.g., multisite admin mode).
4934 - * @return void
4935 - */
4936 - public function print_checkbox_ldap_tls( $args = '' ) {
3953 + function print_checkbox_ldap_tls( $args = '' ) {
4937 3954 // Get plugin option.
4938 - $option = 'ldap_tls';
3955 + $option = 'ldap_tls';
4939 3956 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4940 3957
4941 3958 // Print option elements.
4942 - ?>
4943 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></label>
4944 - <br /><small><?php esc_html_e( 'If ldaps is used, this should be unchecked', 'authorizer' ); ?></small>
4945 - <?php
3959 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Use TLS', 'authorizer' ); ?></label><?php
4946 3960 }
4947 3961
4948 3962
4949 - /**
4950 - * Settings print callback.
4951 - *
4952 - * @param string $args Args (e.g., multisite admin mode).
4953 - * @return void
4954 - */
4955 - public function print_text_ldap_search_base( $args = '' ) {
3963 + function print_text_ldap_search_base( $args = '' ) {
4956 3964 // Get plugin option.
4957 - $option = 'ldap_search_base';
3965 + $option = 'ldap_search_base';
4958 3966 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4959 3967
4960 3968 // Print option elements.
4961 - ?>
4962 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:330px;"><?php echo esc_attr( $auth_settings_option ); ?></textarea>
4963 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: ou=people,dc=example,dc=edu', 'authorizer' ); ?></label>
4964 - <br /><small><?php esc_html_e( 'If you have multiple search bases, separate them by newlines (one per line).', 'authorizer' ); ?></small>
4965 - <?php
3969 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
3970 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: ou=people,dc=example,dc=edu', 'authorizer'); ?></label><?php
4966 3971 }
4967 3972
4968 3973
4969 - /**
4970 - * Settings print callback.
4971 - *
4972 - * @param string $args Args (e.g., multisite admin mode).
4973 - * @return void
4974 - */
4975 - public function print_text_ldap_uid( $args = '' ) {
3974 + function print_text_ldap_uid( $args = '' ) {
4976 3975 // Get plugin option.
4977 - $option = 'ldap_uid';
3976 + $option = 'ldap_uid';
4978 3977 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4979 3978
4980 3979 // Print option elements.
4981 - ?>
4982 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:80px;" />
4983 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: uid', 'authorizer' ); ?></label>
4984 - <?php
3980 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:80px;" />
3981 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: uid', 'authorizer' ); ?></label><?php
4985 3982 }
4986 3983
4987 3984
4988 - /**
4989 - * Settings print callback.
4990 - *
4991 - * @param string $args Args (e.g., multisite admin mode).
4992 - * @return void
4993 - */
4994 - public function print_text_ldap_attr_email( $args = '' ) {
3985 + function print_text_ldap_attr_email( $args = '' ) {
4995 3986 // Get plugin option.
4996 - $option = 'ldap_attr_email';
3987 + $option = 'ldap_attr_email';
4997 3988 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4998 3989
4999 3990 // Print option elements.
5000 - ?>
5001 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5002 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
5003 - <br /><small><?php echo wp_kses( __( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
5004 - <?php
3991 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3992 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: mail', 'authorizer' ); ?></label>
3993 + <br /><small><?php _e( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
5005 3994 }
5006 3995
5007 3996
5008 - /**
5009 - * Settings print callback.
5010 - *
5011 - * @param string $args Args (e.g., multisite admin mode).
5012 - * @return void
5013 - */
5014 - public function print_text_ldap_user( $args = '' ) {
3997 + function print_text_ldap_user( $args = '' ) {
5015 3998 // Get plugin option.
5016 - $option = 'ldap_user';
3999 + $option = 'ldap_user';
5017 4000 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5018 4001
5019 4002 // Print option elements.
5020 - ?>
5021 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
5022 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label>
5023 - <?php
4003 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
4004 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label><?php
5024 4005 }
5025 4006
5026 4007
5027 - /**
5028 - * Settings print callback.
5029 - *
5030 - * @param string $args Args (e.g., multisite admin mode).
5031 - * @return void
5032 - */
5033 - public function print_password_ldap_password( $args = '' ) {
4008 + function print_password_ldap_password( $args = '' ) {
5034 4009 // Get plugin option.
5035 - $option = 'ldap_password';
4010 + $option = 'ldap_password';
5036 4011 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5037 4012
5038 4013 // Print option elements.
5039 - ?>
5040 - <input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
5041 - <input type="password" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $this->decrypt( $auth_settings_option ) ); ?>" autocomplete="off" />
5042 - <?php
4014 + ?><input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
4015 + <input type="password" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $this->decrypt( $auth_settings_option ); ?>" autocomplete="off" /><?php
5043 4016 }
5044 4017
5045 4018
5046 - /**
5047 - * Settings print callback.
5048 - *
5049 - * @param string $args Args (e.g., multisite admin mode).
5050 - * @return void
5051 - */
5052 - public function print_text_ldap_lostpassword_url( $args = '' ) {
4019 + function print_text_ldap_lostpassword_url( $args = '' ) {
5053 4020 // Get plugin option.
5054 - $option = 'ldap_lostpassword_url';
4021 + $option = 'ldap_lostpassword_url';
5055 4022 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5056 4023
5057 4024 // Print option elements.
5058 - ?>
5059 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width: 400px;" />
5060 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label>
5061 - <?php
4025 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width: 400px;" />
4026 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label><?php
5062 4027 }
5063 4028
5064 4029
5065 - /**
5066 - * Settings print callback.
5067 - *
5068 - * @param string $args Args (e.g., multisite admin mode).
5069 - * @return void
5070 - */
5071 - public function print_text_ldap_attr_first_name( $args = '' ) {
4030 + function print_text_ldap_attr_first_name( $args = '' ) {
5072 4031 // Get plugin option.
5073 - $option = 'ldap_attr_first_name';
4032 + $option = 'ldap_attr_first_name';
5074 4033 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5075 4034
5076 4035 // Print option elements.
5077 - ?>
5078 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5079 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenname', 'authorizer' ); ?></label>
5080 - <?php
4036 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4037 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: givenname', 'authorizer' ); ?></label><?php
5081 4038 }
5082 4039
5083 4040
5084 - /**
5085 - * Settings print callback.
5086 - *
5087 - * @param string $args Args (e.g., multisite admin mode).
5088 - * @return void
5089 - */
5090 - public function print_text_ldap_attr_last_name( $args = '' ) {
4041 + function print_text_ldap_attr_last_name( $args = '' ) {
5091 4042 // Get plugin option.
5092 - $option = 'ldap_attr_last_name';
4043 + $option = 'ldap_attr_last_name';
5093 4044 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5094 4045
5095 4046 // Print option elements.
5096 - ?>
5097 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5098 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
5099 - <?php
4047 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4048 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sn', 'authorizer' ); ?></label><?php
5100 4049 }
5101 4050
5102 4051
5103 - /**
5104 - * Settings print callback.
5105 - *
5106 - * @param string $args Args (e.g., multisite admin mode).
5107 - * @return void
5108 - */
5109 - public function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
4052 + function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
5110 4053 // Get plugin option.
5111 - $option = 'ldap_attr_update_on_login';
4054 + $option = 'ldap_attr_update_on_login';
5112 4055 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5113 4056
5114 4057 // Print option elements.
5115 - ?>
5116 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
5117 - <?php
4058 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
5118 4059 }
5119 4060
5120 4061
5121 - /**
5122 - * Settings print callback.
5123 - *
5124 - * @param string $args Args (e.g., multisite admin mode).
5125 - * @return void
5126 - */
5127 - public function print_section_info_advanced( $args = '' ) {
5128 - ?>
5129 - <div id="section_info_advanced" class="section_info">
5130 - <p><?php esc_html_e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
5131 - </div>
5132 - <?php
4062 + function print_section_info_advanced( $args = '' ) {
4063 + ?><div id="section_info_advanced" class="section_info">
4064 + <p><?php _e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
4065 + </div><?php
5133 4066 }
5134 4067
5135 4068
5136 - /**
5137 - * Settings print callback.
5138 - *
5139 - * @param string $args Args (e.g., multisite admin mode).
5140 - * @return void
5141 - */
5142 - public function print_text_auth_advanced_lockouts( $args = '' ) {
4069 + function print_text_auth_advanced_lockouts( $args = '' ) {
5143 4070 // Get plugin option.
5144 - $option = 'advanced_lockouts';
4071 + $option = 'advanced_lockouts';
5145 4072 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5146 4073
5147 4074 // Print option elements.
5148 - esc_html_e( 'After', 'authorizer' );
5149 - ?>
5150 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_1]" value="<?php echo esc_attr( $auth_settings_option['attempts_1'] ); ?>" placeholder="10" style="width:30px;" />
5151 - <?php esc_html_e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
5152 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_1]" value="<?php echo esc_attr( $auth_settings_option['duration_1'] ); ?>" placeholder="1" style="width:30px;" />
5153 - <?php esc_html_e( 'minute(s).', 'authorizer' ); ?>
4075 + ?><?php _e( 'After', 'authorizer' ); ?>
4076 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_1" name="auth_settings[<?php echo $option; ?>][attempts_1]" value="<?php echo $auth_settings_option['attempts_1']; ?>" placeholder="10" style="width:30px;" />
4077 + <?php _e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
4078 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_1" name="auth_settings[<?php echo $option; ?>][duration_1]" value="<?php echo $auth_settings_option['duration_1']; ?>" placeholder="1" style="width:30px;" />
4079 + <?php _e( 'minute(s).', 'authorizer' ); ?>
5154 4080 <br />
5155 - <?php esc_html_e( 'After', 'authorizer' ); ?>
5156 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_2]" value="<?php echo esc_attr( $auth_settings_option['attempts_2'] ); ?>" placeholder="10" style="width:30px;" />
5157 - <?php esc_html_e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
5158 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_2]" value="<?php echo esc_attr( $auth_settings_option['duration_2'] ); ?>" placeholder="10" style="width:30px;" />
5159 - <?php esc_html_e( 'minutes.', 'authorizer' ); ?>
4081 + <?php _e( 'After', 'authorizer' ); ?>
4082 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_2" name="auth_settings[<?php echo $option; ?>][attempts_2]" value="<?php echo $auth_settings_option['attempts_2']; ?>" placeholder="10" style="width:30px;" />
4083 + <?php _e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
4084 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_2" name="auth_settings[<?php echo $option; ?>][duration_2]" value="<?php echo $auth_settings_option['duration_2']; ?>" placeholder="10" style="width:30px;" />
4085 + <?php _e( 'minutes.', 'authorizer' ); ?>
5160 4086 <br />
5161 - <?php esc_html_e( 'Reset the delays after', 'authorizer' ); ?>
5162 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_reset_duration" name="auth_settings[<?php echo esc_attr( $option ); ?>][reset_duration]" value="<?php echo esc_attr( $auth_settings_option['reset_duration'] ); ?>" placeholder="240" style="width:40px;" />
5163 - <?php esc_html_e( 'minutes with no invalid attempts.', 'authorizer' ); ?>
5164 - <?php
4087 + <?php _e( 'Reset the delays after', 'authorizer' ); ?>
4088 + <input type="text" id="auth_settings_<?php echo $option; ?>_reset_duration" name="auth_settings[<?php echo $option; ?>][reset_duration]" value="<?php echo $auth_settings_option['reset_duration']; ?>" placeholder="240" style="width:40px;" />
4089 + <?php _e( 'minutes with no invalid attempts.', 'authorizer' ); ?><?php
5165 4090 }
5166 4091
5167 4092
5168 - /**
5169 - * Settings print callback.
5170 - *
5171 - * @param string $args Args (e.g., multisite admin mode).
5172 - * @return void
5173 - */
5174 - public function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
4093 + function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
5175 4094 // Get plugin option.
5176 - $option = 'advanced_hide_wp_login';
4095 + $option = 'advanced_hide_wp_login';
5177 4096 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5178 4097
5179 4098 // Print option elements.
5180 - ?>
5181 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
5182 - <p><small><?php esc_html_e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo esc_attr( wp_login_url() ); ?>?external=wordpress" target="_blank"><?php echo esc_html( wp_login_url() ); ?>?external=wordpress</a>.</p>
5183 - <?php
4099 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
4100 + <p><small><?php _e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo wp_login_url(); ?>?external=wordpress" target="_blank"><?php echo wp_login_url(); ?>?external=wordpress</a>.</p><?php
5184 4101 }
5185 4102
5186 4103
5187 - /**
5188 - * Settings print callback.
5189 - *
5190 - * @param string $args Args (e.g., multisite admin mode).
5191 - * @return void
5192 - */
5193 - public function print_radio_auth_advanced_branding( $args = '' ) {
4104 + function print_radio_auth_advanced_branding( $args = '' ) {
5194 4105 // Get plugin option.
5195 - $option = 'advanced_branding';
4106 + $option = 'advanced_branding';
5196 4107 $auth_settings_option = $this->get_plugin_option( $option );
5197 4108
5198 4109 // Print option elements.
5199 - ?>
5200 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="default"<?php checked( 'default' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default"><?php esc_html_e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
4110 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_default" name="auth_settings[<?php echo $option; ?>]" value="default"<?php checked( 'default' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_default"><?php _e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
5201 4111 <?php
5202 4112
5203 4113 /**
5204 4114 * Developers can use the `authorizer_add_branding_option` filter
@@ -5203,8 +4113,9 @@
5203 4113 /**
5204 4114 * Developers can use the `authorizer_add_branding_option` filter
5205 4115 * to add a radio button for "Custom WordPress login branding"
5206 4116 * under the "Advanced" tab in Authorizer options. Example:
4117 + *
5207 4118 * function my_authorizer_add_branding_option( $branding_options ) {
5208 4119 * $new_branding_option = array(
5209 4120 * 'value' => 'your_brand'
5210 4121 * 'description' => 'Custom Your Brand Login Screen',
@@ -5218,274 +4129,133 @@
5218 4129 */
5219 4130 $branding_options = array();
5220 4131 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
5221 4132 foreach ( $branding_options as $branding_option ) {
5222 - // Make sure the custom brands have the required values.
4133 + // Make sure the custom brands have the required values
5223 4134 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'description', $branding_option ) ) ) {
5224 4135 continue;
5225 4136 }
5226 - ?>
5227 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $branding_option['value'] ); ?>"<?php checked( $branding_option['value'] === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>"><?php echo esc_html( $branding_option['description'] ); ?></label><br />
5228 - <?php
4137 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $branding_option['value']; ?>"<?php checked( $branding_option['value'] == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>"><?php echo $branding_option['description']; ?></label><br /><?php
5229 4138 }
5230 4139
5231 4140 // Print message about adding custom brands if there are none.
5232 4141 if ( count( $branding_options ) === 0 ) {
5233 - ?>
5234 - <p><em><?php echo wp_kses( __( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ), $this->allowed_html ); ?></em></p>
5235 - <?php
4142 + ?><p><em><?php _e( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ); ?></em></p><?php
5236 4143 }
5237 4144 }
5238 4145
5239 4146
5240 - /**
5241 - * Settings print callback.
5242 - *
5243 - * @param string $args Args (e.g., multisite admin mode).
5244 - * @return void
5245 - */
5246 - public function print_radio_auth_advanced_admin_menu( $args = '' ) {
4147 + function print_radio_auth_advanced_admin_menu( $args = '' ) {
5247 4148 // Get plugin option.
5248 - $option = 'advanced_admin_menu';
4149 + $option = 'advanced_admin_menu';
5249 4150 $auth_settings_option = $this->get_plugin_option( $option );
5250 4151
5251 4152 // Print option elements.
5252 - ?>
5253 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="settings"<?php checked( 'settings' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings"><?php esc_html_e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
5254 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="top"<?php checked( 'top' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top"><?php esc_html_e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br />
5255 - <?php
4153 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_settings" name="auth_settings[<?php echo $option; ?>]" value="settings"<?php checked( 'settings' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_settings"><?php _e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
4154 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_top" name="auth_settings[<?php echo $option; ?>]" value="top"<?php checked( 'top' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_top"><?php _e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br /><?php
5256 4155
5257 4156 }
5258 4157
5259 4158
5260 - /**
5261 - * Settings print callback.
5262 - *
5263 - * @param string $args Args (e.g., multisite admin mode).
5264 - * @return void
5265 - */
5266 - public function print_select_auth_advanced_usermeta( $args = '' ) {
4159 + function print_select_auth_advanced_usermeta( $args = '' ) {
5267 4160 // Get plugin option.
5268 - $option = 'advanced_usermeta';
4161 + $option = 'advanced_usermeta';
5269 4162 $auth_settings_option = $this->get_plugin_option( $option );
5270 4163
5271 4164 // Print option elements.
5272 - ?>
5273 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5274 - <option value=""><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
5275 - <?php
5276 - if ( class_exists( 'acf' ) ) :
4165 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4166 + <option value=""><?php _e( '-- None --', 'authorizer' ); ?></option>
4167 + <?php if ( class_exists( 'acf' ) ) :
5277 4168 // Get ACF 5 fields. Note: it would be much easier to use `get_field_objects()`
5278 4169 // or `get_field_objects( 'user_' . get_current_user_id() )`, but neither will
5279 4170 // list fields that have never been given values for users (i.e., new ACF
5280 4171 // fields). Therefore we fall back on finding any ACF fields applied to users
5281 4172 // (user_role or user_form location rules in the field group definition).
5282 - $fields = array();
4173 + $fields = array();
5283 4174 $acf_field_group_ids = array();
5284 - $acf_field_groups = new WP_Query(
5285 - array(
5286 - 'post_type' => 'acf-field-group',
5287 - )
5288 - );
4175 + $acf_field_groups = new WP_Query( array(
4176 + 'post_type' => 'acf-field-group',
4177 + ));
5289 4178 while ( $acf_field_groups->have_posts() ) : $acf_field_groups->the_post();
5290 4179 if ( strpos( get_the_content(), 's:5:"param";s:9:"user_role"' ) !== false || strpos( get_the_content(), 's:5:"param";s:9:"user_form"' ) !== false ) :
5291 4180 array_push( $acf_field_group_ids, get_the_ID() );
5292 4181 endif;
5293 - endwhile;
5294 - wp_reset_postdata();
4182 + endwhile; wp_reset_postdata();
5295 4183 foreach ( $acf_field_group_ids as $acf_field_group_id ) :
5296 - $acf_fields = new WP_Query(
5297 - array(
5298 - 'post_type' => 'acf-field',
5299 - 'post_parent' => $acf_field_group_id,
5300 - )
5301 - );
4184 + $acf_fields = new WP_Query( array(
4185 + 'post_type' => 'acf-field',
4186 + 'post_parent' => $acf_field_group_id,
4187 + ));
5302 4188 while ( $acf_fields->have_posts() ) : $acf_fields->the_post();
5303 4189 global $post;
5304 - $fields[ $post->post_name ] = get_field_object( $post->post_name );
5305 - endwhile;
5306 - wp_reset_postdata();
4190 + $fields[$post->post_name] = get_field_object( $post->post_name );
4191 + endwhile; wp_reset_postdata();
5307 4192 endforeach;
5308 4193 // Get ACF 4 fields.
5309 - $acf4_field_groups = new WP_Query(
5310 - array(
5311 - 'post_type' => 'acf',
5312 - )
5313 - );
4194 + $acf4_field_groups = new WP_Query( array(
4195 + 'post_type' => 'acf',
4196 + ));
5314 4197 while ( $acf4_field_groups->have_posts() ) : $acf4_field_groups->the_post();
5315 4198 $field_group_rules = get_post_meta( get_the_ID(), 'rule', true );
5316 - if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && 'ef_user' === $field_group_rules['param'] ) :
4199 + if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && $field_group_rules['param'] === 'ef_user' ) :
5317 4200 $acf4_fields = get_post_custom( get_the_ID() );
5318 4201 foreach ( $acf4_fields as $meta_key => $meta_value ) :
5319 4202 if ( strpos( $meta_key, 'field_' ) === 0 ) :
5320 - $meta_value = unserialize( $meta_value[0] );
5321 - $fields[ $meta_key ] = $meta_value;
4203 + $meta_value = unserialize( $meta_value[0] );
4204 + $fields[$meta_key] = $meta_value;
5322 4205 endif;
5323 4206 endforeach;
5324 4207 endif;
5325 - endwhile;
5326 - wp_reset_postdata();
5327 - ?>
4208 + endwhile; wp_reset_postdata(); ?>
5328 4209 <optgroup label="ACF User Fields:">
5329 - <?php foreach ( (array) $fields as $field => $field_object ) : ?>
5330 - <option value="acf___<?php echo esc_attr( $field_object['key'] ); ?>"<?php selected( "acf___{$field_object['key']}" === $auth_settings_option ); ?>><?php echo esc_html( $field_object['label'] ); ?></option>
4210 + <?php foreach ( (array)$fields as $field => $field_object ) : ?>
4211 + <option value="acf___<?php echo $field_object['key']; ?>"<?php if ( $auth_settings_option === "acf___{$field_object['key']}" ) echo ' selected="selected"'; ?>><?php echo $field_object['label']; ?></option>
5331 4212 <?php endforeach; ?>
5332 4213 </optgroup>
5333 4214 <?php endif; ?>
5334 - <optgroup label="<?php esc_attr_e( 'All Usermeta:', 'authorizer' ); ?>">
5335 - <?php
5336 - foreach ( $this->get_all_usermeta_keys() as $meta_key ) :
5337 - if ( substr( $meta_key, 0, 3 ) === 'wp_' ) :
5338 - continue;
5339 - endif;
5340 - ?>
5341 - <option value="<?php echo esc_attr( $meta_key ); ?>"<?php selected( $auth_settings_option === $meta_key ); ?>><?php echo esc_html( $meta_key ); ?></option>
4215 + <optgroup label="<?php _e( 'All Usermeta:', 'authorizer' ); ?>">
4216 + <?php foreach ( $this->get_all_usermeta_keys() as $meta_key ) : if ( substr( $meta_key, 0, 3 ) === 'wp_' ) continue; ?>
4217 + <option value="<?php echo $meta_key; ?>"<?php if ( $auth_settings_option === $meta_key ) echo ' selected="selected"'; ?>><?php echo $meta_key; ?></option>
5342 4218 <?php endforeach; ?>
5343 4219 </optgroup>
5344 - </select>
5345 - <?php
4220 + </select><?php
5346 4221 }
5347 4222
5348 4223
5349 - /**
5350 - * Settings print callback.
5351 - *
5352 - * @param string $args Args (e.g., multisite admin mode).
5353 - * @return void
5354 - */
5355 - public function print_text_auth_advanced_users_per_page( $args = '' ) {
4224 + function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5356 4225 // Get plugin option.
5357 - $option = 'advanced_users_per_page';
5358 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5359 -
5360 - // Print option elements.
5361 - ?>
5362 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" size="4" />
5363 - <?php
5364 - }
5365 -
5366 -
5367 - /**
5368 - * Settings print callback.
5369 - *
5370 - * @param string $args Args (e.g., multisite admin mode).
5371 - * @return void
5372 - */
5373 - public function print_select_auth_advanced_users_sort_by( $args = '' ) {
5374 - // Get plugin option.
5375 - $option = 'advanced_users_sort_by';
5376 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5377 -
5378 - // Print option elements.
5379 - ?>
5380 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5381 - <option value="created" <?php selected( $auth_settings_option, 'created' ); ?>><?php esc_html_e( 'Date approved', 'authorizer' ); ?></option>
5382 - <option value="email" <?php selected( $auth_settings_option, 'email' ); ?>><?php esc_html_e( 'Email', 'authorizer' ); ?></option>
5383 - <option value="role" <?php selected( $auth_settings_option, 'role' ); ?>><?php esc_html_e( 'Role', 'authorizer' ); ?></option>
5384 - <option value="date_added" <?php selected( $auth_settings_option, 'date_added' ); ?>><?php esc_html_e( 'Date registered', 'authorizer' ); ?></option>
5385 - </select>
5386 - <?php
5387 - }
5388 -
5389 -
5390 - /**
5391 - * Settings print callback.
5392 - *
5393 - * @param string $args Args (e.g., multisite admin mode).
5394 - * @return void
5395 - */
5396 - public function print_select_auth_advanced_users_sort_order( $args = '' ) {
5397 - // Get plugin option.
5398 - $option = 'advanced_users_sort_order';
5399 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5400 -
5401 - // Print option elements.
5402 - ?>
5403 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5404 - <option value="asc" <?php selected( $auth_settings_option, 'asc' ); ?>><?php esc_html_e( 'Ascending', 'authorizer' ); ?></option>
5405 - <option value="desc" <?php selected( $auth_settings_option, 'desc' ); ?>><?php esc_html_e( 'Descending', 'authorizer' ); ?></option>
5406 - </select>
5407 - <?php
5408 - }
5409 -
5410 -
5411 - /**
5412 - * Settings print callback.
5413 - *
5414 - * @param string $args Args (e.g., multisite admin mode).
5415 - * @return void
5416 - */
5417 - public function print_checkbox_auth_advanced_widget_enabled( $args = '' ) {
5418 - // Get plugin option.
5419 - $option = 'advanced_widget_enabled';
5420 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5421 -
5422 - // Print option elements.
5423 - ?>
5424 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></label>
5425 - <p><small><?php esc_html_e( 'Note: Only users with the create_users capability will be able to see the dashboard widget.', 'authorizer' ); ?></small></p>
5426 - <?php
5427 - }
5428 -
5429 -
5430 - /**
5431 - * Settings print callback.
5432 - *
5433 - * @param string $args Args (e.g., multisite admin mode).
5434 - * @return void
5435 - */
5436 - public function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5437 - // Get plugin option.
5438 - $option = 'advanced_override_multisite';
4226 + $option = 'advanced_override_multisite';
5439 4227 $auth_settings_option = $this->get_plugin_option( $option );
5440 4228
5441 4229 // Print option elements.
5442 - ?>
5443 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label>
5444 - <?php
4230 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label><?php
5445 4231 }
5446 4232
5447 4233
5448 4234
5449 4235 /**
5450 - * Determines whether we are in single site or multisite admin context.
5451 - *
5452 - * @param string $args Args (e.g., multisite admin mode).
5453 - * @return int Current mode.
5454 - */
5455 - private function get_admin_mode( $args ) {
5456 - if ( is_array( $args ) && array_key_exists( WP_Plugin_Authorizer::NETWORK_CONTEXT, $args ) && true === $args[ WP_Plugin_Authorizer::NETWORK_CONTEXT ] ) {
5457 - return WP_Plugin_Authorizer::NETWORK_CONTEXT;
5458 - } else {
5459 - return WP_Plugin_Authorizer::SINGLE_CONTEXT;
5460 - }
5461 - }
5462 -
5463 -
5464 - /**
5465 4236 * Add help documentation to the options page.
5466 - *
5467 - * Action: load-settings_page_authorizer > admin_head
4237 + * Run on action hook chain: load-settings_page_authorizer > admin_head
5468 4238 */
5469 4239 public function admin_head() {
5470 4240 $screen = get_current_screen();
5471 4241
5472 - // Add help tab for Access Lists Settings.
4242 + // Add help tab for Access Lists Settings
5473 4243 $help_auth_settings_access_lists_content = '
5474 - <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) . '</p>
5475 - <p>' . __( '<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.', 'authorizer' ) . '</p>
5476 - <p>' . __( '<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ) . '</p>
5477 - <p>' . __( 'Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.', 'authorizer' ) . '</p>
4244 + <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) .'</p>
4245 + <p>' . __( "<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.", 'authorizer' ) . '</p>
4246 + <p>' . __( "<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.", 'authorizer' ) . '</p>
4247 + <p>' . __( "Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.", 'authorizer' ) . '</p>
5478 4248 ';
5479 4249 $screen->add_help_tab(
5480 4250 array(
5481 - 'id' => 'help_auth_settings_access_lists_content',
5482 - 'title' => __( 'Access Lists', 'authorizer' ),
4251 + 'id' => 'help_auth_settings_access_lists_content',
4252 + 'title' => __( 'Access Lists', 'authorizer' ),
5483 4253 'content' => $help_auth_settings_access_lists_content,
5484 4254 )
5485 4255 );
5486 4256
5487 - // Add help tab for Login Access Settings.
4257 + // Add help tab for Login Access Settings
5488 4258 $help_auth_settings_access_login_content = '
5489 4259 <p>' . __( "<strong>Who can log in to the site?</strong>: Choose the level of access restriction you'd like to use on your site here. You can leave the site open to anyone with a WordPress account or an account on an external service like Google, CAS, or LDAP, or restrict it to WordPress users and only the external users that you specify via the <em>Access Lists</em>.", 'authorizer' ) . '</p>
5490 4260 <p>' . __( "<strong>Which role should receive email notifications about pending users?</strong>: If you've restricted access to <strong>approved users</strong>, you can determine which WordPress users will receive a notification email everytime a new external user successfully logs in and is added to the pending list. All users of the specified role will receive an email, and the external user will get a message (specified below) telling them their access is pending approval.", 'authorizer' ) . '</p>
5491 4261 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
@@ -5491,84 +4261,84 @@
5491 4261 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
5492 4262 ';
5493 4263 $screen->add_help_tab(
5494 4264 array(
5495 - 'id' => 'help_auth_settings_access_login_content',
5496 - 'title' => __( 'Login Access', 'authorizer' ),
4265 + 'id' => 'help_auth_settings_access_login_content',
4266 + 'title' => __( 'Login Access', 'authorizer' ),
5497 4267 'content' => $help_auth_settings_access_login_content,
5498 4268 )
5499 4269 );
5500 4270
5501 - // Add help tab for Public Access Settings.
4271 + // Add help tab for Public Access Settings
5502 4272 $help_auth_settings_access_public_content = '
5503 4273 <p>' . __( "<strong>Who can view the site?</strong>: You can restrict the site's visibility by only allowing logged in users to see pages. If you do so, you can customize the specifics about the site's privacy using the settings below.", 'authorizer' ) . '</p>
5504 4274 <p>' . __( "<strong>What pages (if any) should be available to everyone?</strong>: If you'd like to declare certain pages on your site as always public (such as the course syllabus, introduction, or calendar), specify those pages here. These pages will always be available no matter what access restrictions exist.", 'authorizer' ) . '</p>
5505 - <p>' . __( '<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.', 'authorizer' ) . '</p>
5506 - <p>' . __( '<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.', 'authorizer' ) . '</p>
5507 - <p>' . __( '<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.', 'authorizer' ) . '</p>
4275 + <p>' . __( "<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.", 'authorizer' ) . '</p>
4276 + <p>' . __( "<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.", 'authorizer' ) . '</p>
4277 + <p>' . __( "<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.", 'authorizer' ) . '</p>
5508 4278 ';
5509 4279 $screen->add_help_tab(
5510 4280 array(
5511 - 'id' => 'help_auth_settings_access_public_content',
5512 - 'title' => __( 'Public Access', 'authorizer' ),
4281 + 'id' => 'help_auth_settings_access_public_content',
4282 + 'title' => __( 'Public Access', 'authorizer' ),
5513 4283 'content' => $help_auth_settings_access_public_content,
5514 4284 )
5515 4285 );
5516 4286
5517 - // Add help tab for External Service (CAS, LDAP) Settings.
4287 + // Add help tab for External Service (CAS, LDAP) Settings
5518 4288 $help_auth_settings_external_content = '
5519 4289 <p>' . __( "<strong>Type of external service to authenticate against</strong>: Choose which authentication service type you will be using. You'll have to fill out different fields below depending on which service you choose.", 'authorizer' ) . '</p>
5520 - <p>' . __( '<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.', 'authorizer' ) . '</p>
5521 - <p>' . __( '<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.', 'authorizer' ) . '</p>
5522 - <p>' . __( '<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.', 'authorizer' ) . '</p>
5523 - <p>' . __( '<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!', 'authorizer' ) . '</p>
5524 - <p><strong><em>' . __( 'If you enable Google logins:', 'authorizer' ) . '</em></strong></p>
4290 + <p>' . __( "<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.", 'authorizer' ) . '</p>
4291 + <p>' . __( "<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.", 'authorizer' ) . '</p>
4292 + <p>' . __( "<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.", 'authorizer' ) . '</p>
4293 + <p>' . __( "<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!", 'authorizer' ) . '</p>
4294 + <p><strong><em>' . __( "If you enable Google logins:", 'authorizer' ) . '</em></strong></p>
5525 4295 <ul>
5526 4296 <li>' . __( "<strong>Google Client ID</strong>: You can generate this ID by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client ID typically looks something like this: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com", 'authorizer' ) . '</li>
5527 4297 <li>' . __( "<strong>Google Client Secret</strong>: You can generate this secret by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client Secret typically looks something like this: sDNgX5_pr_5bly-frKmvp8jT", 'authorizer' ) . '</li>
5528 4298 </ul>
5529 - <p><strong><em>' . __( 'If you enable CAS logins:', 'authorizer' ) . '</em></strong></p>
4299 + <p><strong><em>' . __( "If you enable CAS logins:", 'authorizer' ) . '</em></strong></p>
5530 4300 <ul>
5531 - <li>' . __( '<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).', 'authorizer' ) . '</li>
5532 - <li>' . __( '<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).', 'authorizer' ) . '</li>
5533 - <li>' . __( '<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).', 'authorizer' ) . '</li>
4301 + <li>' . __( "<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).", 'authorizer' ) . '</li>
4302 + <li>' . __( "<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).", 'authorizer' ) . '</li>
4303 + <li>' . __( "<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).", 'authorizer' ) . '</li>
5534 4304 <li>' . __( "<strong>CAS attribute containing first name</strong>: Enter the CAS attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5535 4305 <li>' . __( "<strong>CAS attribute containing last name</strong>: Enter the CAS attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5536 - <li>' . __( '<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4306 + <li>' . __( "<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5537 4307 </ul>
5538 - <p><strong><em>' . __( 'If you enable LDAP logins:', 'authorizer' ) . '</em></strong></p>
4308 + <p><strong><em>' . __( "If you enable LDAP logins:", 'authorizer' ) . '</em></strong></p>
5539 4309 <ul>
5540 - <li>' . __( '<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.', 'authorizer' ) . '</li>
5541 - <li>' . __( '<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.', 'authorizer' ) . '</li>
5542 - <li>' . __( '<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu', 'authorizer' ) . '</li>
5543 - <li>' . __( '<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.', 'authorizer' ) . '</li>
5544 - <li>' . __( '<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.', 'authorizer' ) . '</li>
5545 - <li>' . __( '<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.', 'authorizer' ) . '</li>
5546 - <li>' . __( '<strong>Use TLS</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.', 'authorizer' ) . '</li>
4310 + <li>' . __( "<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.", 'authorizer' ) . '</li>
4311 + <li>' . __( "<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.", 'authorizer' ) . '</li>
4312 + <li>' . __( "<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu", 'authorizer' ) . '</li>
4313 + <li>' . __( "<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.", 'authorizer' ) . '</li>
4314 + <li>' . __( "<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.", 'authorizer' ) . '</li>
4315 + <li>' . __( "<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.", 'authorizer' ) . '</li>
4316 + <li>' . __( "<strong>Secure Connection (TLS)</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.", 'authorizer' ) . '</li>
5547 4317 <li>' . __( "<strong>Custom lost password URL</strong>: The WordPress login page contains a link to recover a lost password. If you have external users who shouldn't change the password on their WordPress account, point them to the appropriate location to change the password on their external authentication service here.", 'authorizer' ) . '</li>
5548 4318 <li>' . __( "<strong>LDAP attribute containing first name</strong>: Enter the LDAP attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5549 4319 <li>' . __( "<strong>LDAP attribute containing last name</strong>: Enter the LDAP attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5550 - <li>' . __( '<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4320 + <li>' . __( "<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5551 4321 </ul>
5552 4322 ';
5553 4323 $screen->add_help_tab(
5554 4324 array(
5555 - 'id' => 'help_auth_settings_external_content',
5556 - 'title' => __( 'External Service', 'authorizer' ),
4325 + 'id' => 'help_auth_settings_external_content',
4326 + 'title' => __( 'External Service', 'authorizer' ),
5557 4327 'content' => $help_auth_settings_external_content,
5558 4328 )
5559 4329 );
5560 4330
5561 - // Add help tab for Advanced Settings.
4331 + // Add help tab for Advanced Settings
5562 4332 $help_auth_settings_advanced_content = '
5563 - <p>' . __( '<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.', 'authorizer' ) . '</p>
5564 - <p>' . __( '<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
4333 + <p>' . __( "<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.", 'authorizer' ) . '</p>
4334 + <p>' . __( "<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:", 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
5565 4335 <p>' . __( "<strong>Custom WordPress login branding</strong>: If you'd like to use custom branding on the WordPress login page, select that here. You will need to use the `authorizer_add_branding_option` filter in your theme to add it. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.", 'authorizer' ) . '</p>
5566 4336 ';
5567 4337 $screen->add_help_tab(
5568 4338 array(
5569 - 'id' => 'help_auth_settings_advanced_content',
5570 - 'title' => __( 'Advanced', 'authorizer' ),
4339 + 'id' => 'help_auth_settings_advanced_content',
4340 + 'title' => __( 'Advanced', 'authorizer' ),
5571 4341 'content' => $help_auth_settings_advanced_content,
5572 4342 )
5573 4343 );
5574 4344 }
@@ -5583,66 +4353,65 @@
5583 4353
5584 4354
5585 4355 /**
5586 4356 * Network Admin menu item
4357 + * Hook: network_admin_menu
5587 4358 *
5588 - * Action: network_admin_menu
5589 - *
4359 + * @param none
5590 4360 * @return void
5591 4361 */
5592 4362 public function network_admin_menu() {
5593 4363 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
5594 4364 add_menu_page(
5595 - 'Authorizer',
5596 - 'Authorizer',
5597 - 'manage_network_options',
5598 - 'authorizer',
4365 + 'Authorizer', // Page title
4366 + 'Authorizer', // Menu title
4367 + 'manage_network_options', // Capability
4368 + 'authorizer', // Menu slug
5599 4369 array( $this, 'create_network_admin_page' ),
5600 - 'dashicons-groups',
5601 - 89 // Position.
4370 + 'dashicons-groups', // Icon URL
4371 + 89 // Position
5602 4372 );
5603 4373 }
5604 4374
5605 4375
5606 4376 /**
5607 - * Output the HTML for the options page.
4377 + * Output the HTML for the options page
5608 4378 */
5609 4379 public function create_network_admin_page() {
5610 4380 if ( ! current_user_can( 'manage_network_options' ) ) {
5611 - wp_die( wp_kses( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ), $this->allowed_html ) );
4381 + wp_die( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ) );
5612 4382 }
5613 - $auth_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5614 - ?>
4383 + $auth_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); ?>
5615 4384 <div class="wrap">
5616 4385 <form method="post" action="" autocomplete="off">
5617 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
5618 - <p><?php echo wp_kses( __( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ), $this->allowed_html ); ?></p>
4386 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
4387 + <p><?php _e( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ); ?></p>
5619 4388
5620 - <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 === intval( $auth_settings['multisite_override'] ) ); ?> /><label for="auth_settings_multisite_override"><?php esc_html_e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
4389 + <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 == $auth_settings['multisite_override'] ); ?> /><label for="auth_settings_multisite_override"><?php _e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
5621 4390
5622 4391 <div id="auth_multisite_settings_disabled_overlay" style="display: none;"></div>
5623 4392
5624 4393 <div class="wrap" id="auth_multisite_settings">
5625 - <?php $this->print_section_info_tabs( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?>
4394 + <?php $this->print_section_info_tabs( array( MULTISITE_ADMIN => true ) ); ?>
5626 4395
5627 4396 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
5628 4397
5629 - <?php // Custom access lists (for network, we only really want approved list, not pending or blocked). ?>
4398 + <?php // Custom access lists (for network, we only really want approved list, not pending or blocked) ?>
5630 4399 <div id="section_info_access_lists" class="section_info">
5631 - <p><?php esc_html_e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
4400 + <p><?php _e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
5632 4401 </div>
5633 4402 <table class="form-table"><tbody>
5634 4403 <tr>
5635 - <th scope="row"><?php esc_html_e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
5636 - <td><?php $this->print_radio_auth_access_who_can_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4404 + <th scope="row"><?php _e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
4405 + <td><?php $this->print_radio_auth_access_who_can_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5637 4406 </tr>
5638 4407 <tr>
5639 - <th scope="row"><?php esc_html_e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
5640 - <td><?php $this->print_radio_auth_access_who_can_view( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4408 + <th scope="row"><?php _e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
4409 + <td><?php $this->print_radio_auth_access_who_can_view( array( MULTISITE_ADMIN => true ) ); ?></td>
5641 4410 </tr>
5642 4411 <tr>
5643 - <th scope="row"><?php esc_html_e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php echo wp_kses( __( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ), $this->allowed_html ); ?></em></small></th>
5644 - <td><?php $this->print_combo_auth_access_users_approved( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4412 + <th scope="row"><?php _e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php _e( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ); ?></em></small></th>
4413 + <td><?php $this->print_combo_auth_access_users_approved( array( MULTISITE_ADMIN => true ) ); ?></td>
5645 4414 </tr>
5646 4415 </tbody></table>
5647 4416
5648 4417 <?php $this->print_section_info_external(); ?>
@@ -5647,122 +4416,122 @@
5647 4416
5648 4417 <?php $this->print_section_info_external(); ?>
5649 4418 <table class="form-table"><tbody>
5650 4419 <tr>
5651 - <th scope="row"><?php esc_html_e( 'Default role for new users', 'authorizer' ); ?></th>
5652 - <td><?php $this->print_select_auth_access_default_role( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4420 + <th scope="row"><?php _e( 'Default role for new users', 'authorizer' ); ?></th>
4421 + <td><?php $this->print_select_auth_access_default_role( array( MULTISITE_ADMIN => true ) ); ?></td>
5653 4422 </tr>
5654 4423 <tr>
5655 - <th scope="row"><?php esc_html_e( 'Google Logins', 'authorizer' ); ?></th>
5656 - <td><?php $this->print_checkbox_auth_external_google( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4424 + <th scope="row"><?php _e( 'Google Logins', 'authorizer' ); ?></th>
4425 + <td><?php $this->print_checkbox_auth_external_google( array( MULTISITE_ADMIN => true ) ); ?></td>
5657 4426 </tr>
5658 4427 <tr>
5659 - <th scope="row"><?php esc_html_e( 'Google Client ID', 'authorizer' ); ?></th>
5660 - <td><?php $this->print_text_google_clientid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4428 + <th scope="row"><?php _e( 'Google Client ID', 'authorizer' ); ?></th>
4429 + <td><?php $this->print_text_google_clientid( array( MULTISITE_ADMIN => true ) ); ?></td>
5661 4430 </tr>
5662 4431 <tr>
5663 - <th scope="row"><?php esc_html_e( 'Google Client Secret', 'authorizer' ); ?></th>
5664 - <td><?php $this->print_text_google_clientsecret( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4432 + <th scope="row"><?php _e( 'Google Client Secret', 'authorizer' ); ?></th>
4433 + <td><?php $this->print_text_google_clientsecret( array( MULTISITE_ADMIN => true ) ); ?></td>
5665 4434 </tr>
5666 4435 <tr>
5667 - <th scope="row"><?php esc_html_e( 'Google Hosted Domain', 'authorizer' ); ?></th>
5668 - <td><?php $this->print_text_google_hosteddomain( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4436 + <th scope="row"><?php _e( 'Google Hosted Domain', 'authorizer' ); ?></th>
4437 + <td><?php $this->print_text_google_hosteddomain( array( MULTISITE_ADMIN => true ) ); ?></td>
5669 4438 </tr>
5670 4439 <tr>
5671 - <th scope="row"><?php esc_html_e( 'CAS Logins', 'authorizer' ); ?></th>
5672 - <td><?php $this->print_checkbox_auth_external_cas( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4440 + <th scope="row"><?php _e( 'CAS Logins', 'authorizer' ); ?></th>
4441 + <td><?php $this->print_checkbox_auth_external_cas( array( MULTISITE_ADMIN => true ) ); ?></td>
5673 4442 </tr>
5674 4443 <tr>
5675 - <th scope="row"><?php esc_html_e( 'CAS Custom Label', 'authorizer' ); ?></th>
5676 - <td><?php $this->print_text_cas_custom_label( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4444 + <th scope="row"><?php _e( 'CAS Custom Label', 'authorizer' ); ?></th>
4445 + <td><?php $this->print_text_cas_custom_label( array( MULTISITE_ADMIN => true ) ); ?></td>
5677 4446 </tr>
5678 4447 <tr>
5679 - <th scope="row"><?php esc_html_e( 'CAS server hostname', 'authorizer' ); ?></th>
5680 - <td><?php $this->print_text_cas_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4448 + <th scope="row"><?php _e( 'CAS server hostname', 'authorizer' ); ?></th>
4449 + <td><?php $this->print_text_cas_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5681 4450 </tr>
5682 4451 <tr>
5683 - <th scope="row"><?php esc_html_e( 'CAS server port', 'authorizer' ); ?></th>
5684 - <td><?php $this->print_text_cas_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4452 + <th scope="row"><?php _e( 'CAS server port', 'authorizer' ); ?></th>
4453 + <td><?php $this->print_text_cas_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5685 4454 </tr>
5686 4455 <tr>
5687 - <th scope="row"><?php esc_html_e( 'CAS server path/context', 'authorizer' ); ?></th>
5688 - <td><?php $this->print_text_cas_path( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4456 + <th scope="row"><?php _e( 'CAS server path/context', 'authorizer' ); ?></th>
4457 + <td><?php $this->print_text_cas_path( array( MULTISITE_ADMIN => true ) ); ?></td>
5689 4458 </tr>
5690 4459 <tr>
5691 - <th scope="row"><?php esc_html_e( 'CAS server version', 'authorizer' ); ?></th>
5692 - <td><?php $this->print_select_cas_version( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4460 + <th scope="row"><?php _e( 'CAS server version', 'authorizer' ); ?></th>
4461 + <td><?php $this->print_select_cas_version( array( MULTISITE_ADMIN => true ) ); ?></td>
5693 4462 </tr>
5694 4463 <tr>
5695 - <th scope="row"><?php esc_html_e( 'CAS attribute containing email', 'authorizer' ); ?></th>
5696 - <td><?php $this->print_text_cas_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4464 + <th scope="row"><?php _e( 'CAS attribute containing email', 'authorizer' ); ?></th>
4465 + <td><?php $this->print_text_cas_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5697 4466 </tr>
5698 4467 <tr>
5699 - <th scope="row"><?php esc_html_e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
5700 - <td><?php $this->print_text_cas_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4468 + <th scope="row"><?php _e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
4469 + <td><?php $this->print_text_cas_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5701 4470 </tr>
5702 4471 <tr>
5703 - <th scope="row"><?php esc_html_e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
5704 - <td><?php $this->print_text_cas_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4472 + <th scope="row"><?php _e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
4473 + <td><?php $this->print_text_cas_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5705 4474 </tr>
5706 4475 <tr>
5707 - <th scope="row"><?php esc_html_e( 'CAS attribute update', 'authorizer' ); ?></th>
5708 - <td><?php $this->print_checkbox_cas_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4476 + <th scope="row"><?php _e( 'CAS attribute update', 'authorizer' ); ?></th>
4477 + <td><?php $this->print_checkbox_cas_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5709 4478 </tr>
5710 4479 <tr>
5711 - <th scope="row"><?php esc_html_e( 'CAS automatic login', 'authorizer' ); ?></th>
5712 - <td><?php $this->print_checkbox_cas_auto_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4480 + <th scope="row"><?php _e( 'CAS automatic login', 'authorizer' ); ?></th>
4481 + <td><?php $this->print_checkbox_cas_auto_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5713 4482 </tr>
5714 4483 <tr>
5715 - <th scope="row"><?php esc_html_e( 'LDAP Logins', 'authorizer' ); ?></th>
5716 - <td><?php $this->print_checkbox_auth_external_ldap( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4484 + <th scope="row"><?php _e( 'LDAP Logins', 'authorizer' ); ?></th>
4485 + <td><?php $this->print_checkbox_auth_external_ldap( array( MULTISITE_ADMIN => true ) ); ?></td>
5717 4486 </tr>
5718 4487 <tr>
5719 - <th scope="row"><?php esc_html_e( 'LDAP Host', 'authorizer' ); ?></th>
5720 - <td><?php $this->print_text_ldap_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4488 + <th scope="row"><?php _e( 'LDAP Host', 'authorizer' ); ?></th>
4489 + <td><?php $this->print_text_ldap_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5721 4490 </tr>
5722 4491 <tr>
5723 - <th scope="row"><?php esc_html_e( 'LDAP Port', 'authorizer' ); ?></th>
5724 - <td><?php $this->print_text_ldap_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4492 + <th scope="row"><?php _e( 'LDAP Port', 'authorizer' ); ?></th>
4493 + <td><?php $this->print_text_ldap_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5725 4494 </tr>
5726 4495 <tr>
5727 - <th scope="row"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></th>
5728 - <td><?php $this->print_checkbox_ldap_tls( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4496 + <th scope="row"><?php _e( 'Secure Connection (TLS)', 'authorizer' ); ?></th>
4497 + <td><?php $this->print_checkbox_ldap_tls( array( MULTISITE_ADMIN => true ) ); ?></td>
5729 4498 </tr>
5730 4499 <tr>
5731 - <th scope="row"><?php esc_html_e( 'LDAP Search Base', 'authorizer' ); ?></th>
5732 - <td><?php $this->print_text_ldap_search_base( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4500 + <th scope="row"><?php _e( 'LDAP Search Base', 'authorizer' ); ?></th>
4501 + <td><?php $this->print_text_ldap_search_base( array( MULTISITE_ADMIN => true ) ); ?></td>
5733 4502 </tr>
5734 4503 <tr>
5735 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
5736 - <td><?php $this->print_text_ldap_uid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4504 + <th scope="row"><?php _e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
4505 + <td><?php $this->print_text_ldap_uid( array( MULTISITE_ADMIN => true ) ); ?></td>
5737 4506 </tr>
5738 4507 <tr>
5739 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
5740 - <td><?php $this->print_text_ldap_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4508 + <th scope="row"><?php _e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
4509 + <td><?php $this->print_text_ldap_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5741 4510 </tr>
5742 4511 <tr>
5743 - <th scope="row"><?php esc_html_e( 'LDAP Directory User', 'authorizer' ); ?></th>
5744 - <td><?php $this->print_text_ldap_user( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4512 + <th scope="row"><?php _e( 'LDAP Directory User', 'authorizer' ); ?></th>
4513 + <td><?php $this->print_text_ldap_user( array( MULTISITE_ADMIN => true ) ); ?></td>
5745 4514 </tr>
5746 4515 <tr>
5747 - <th scope="row"><?php esc_html_e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
5748 - <td><?php $this->print_password_ldap_password( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4516 + <th scope="row"><?php _e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
4517 + <td><?php $this->print_password_ldap_password( array( MULTISITE_ADMIN => true ) ); ?></td>
5749 4518 </tr>
5750 4519 <tr>
5751 - <th scope="row"><?php esc_html_e( 'Custom lost password URL', 'authorizer' ); ?></th>
5752 - <td><?php $this->print_text_ldap_lostpassword_url( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4520 + <th scope="row"><?php _e( 'Custom lost password URL', 'authorizer' ); ?></th>
4521 + <td><?php $this->print_text_ldap_lostpassword_url( array( MULTISITE_ADMIN => true ) ); ?></td>
5753 4522 </tr>
5754 4523 <tr>
5755 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
5756 - <td><?php $this->print_text_ldap_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4524 + <th scope="row"><?php _e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
4525 + <td><?php $this->print_text_ldap_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5757 4526 </tr>
5758 4527 <tr>
5759 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
5760 - <td><?php $this->print_text_ldap_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4528 + <th scope="row"><?php _e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
4529 + <td><?php $this->print_text_ldap_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5761 4530 </tr>
5762 4531 <tr>
5763 - <th scope="row"><?php esc_html_e( 'LDAP attribute update', 'authorizer' ); ?></th>
5764 - <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4532 + <th scope="row"><?php _e( 'LDAP attribute update', 'authorizer' ); ?></th>
4533 + <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5765 4534 </tr>
5766 4535 </tbody></table>
5767 4536
5768 4537 <?php $this->print_section_info_advanced(); ?>
@@ -5767,36 +4536,20 @@
5767 4536
5768 4537 <?php $this->print_section_info_advanced(); ?>
5769 4538 <table class="form-table"><tbody>
5770 4539 <tr>
5771 - <th scope="row"><?php esc_html_e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
5772 - <td><?php $this->print_text_auth_advanced_lockouts( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4540 + <th scope="row"><?php _e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
4541 + <td><?php $this->print_text_auth_advanced_lockouts( array( MULTISITE_ADMIN => true ) ); ?></td>
5773 4542 </tr>
5774 4543 <tr>
5775 - <th scope="row"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
5776 - <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4544 + <th scope="row"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
4545 + <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5777 4546 </tr>
5778 - <tr>
5779 - <th scope="row"><?php esc_html_e( 'Number of users per page', 'authorizer' ); ?></th>
5780 - <td><?php $this->print_text_auth_advanced_users_per_page( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5781 - </tr>
5782 - <tr>
5783 - <th scope="row"><?php esc_html_e( 'Approved users sort method', 'authorizer' ); ?></th>
5784 - <td><?php $this->print_select_auth_advanced_users_sort_by( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5785 - </tr>
5786 - <tr>
5787 - <th scope="row"><?php esc_html_e( 'Approved users sort order', 'authorizer' ); ?></th>
5788 - <td><?php $this->print_select_auth_advanced_users_sort_order( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5789 - </tr>
5790 - <tr>
5791 - <th scope="row"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></th>
5792 - <td><?php $this->print_checkbox_auth_advanced_widget_enabled( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5793 - </tr>
5794 4547 </tbody></table>
5795 4548
5796 4549 <br class="clear" />
5797 4550 </div>
5798 - <input type="button" name="submit" id="submit" class="button button-primary" value="<?php esc_attr_e( 'Save Changes', 'authorizer' ); ?>" onclick="saveAuthMultisiteSettings(this);" />
4551 + <input type="button" name="submit" id="submit" class="button button-primary" value="<?php _e( 'Save Changes', 'authorizer' ); ?>" onclick="save_auth_multisite_settings(this);" />
5799 4552 </form>
5800 4553 </div>
5801 4554 <?php
5802 4555 }
@@ -5803,12 +4556,10 @@
5803 4556
5804 4557
5805 4558 /**
5806 4559 * Save multisite settings (ajax call).
5807 - *
5808 - * Action: wp_ajax_save_auth_multisite_settings
5809 4560 */
5810 - public function ajax_save_auth_multisite_settings() {
4561 + function ajax_save_auth_multisite_settings() {
5811 4562 // Fail silently if current user doesn't have permissions.
5812 4563 if ( ! current_user_can( 'manage_network_options' ) ) {
5813 4564 die( '' );
5814 4565 }
@@ -5813,14 +4564,14 @@
5813 4564 die( '' );
5814 4565 }
5815 4566
5816 4567 // Make sure nonce exists.
5817 - if ( empty( $_POST['nonce'] ) ) {
4568 + if ( empty( $_POST['nonce_save_auth_settings'] ) ) {
5818 4569 die( '' );
5819 4570 }
5820 4571
5821 4572 // Nonce check.
5822 - if ( ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4573 + if ( ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5823 4574 die( '' );
5824 4575 }
5825 4576
5826 4577 // Assert multisite.
@@ -5828,15 +4579,15 @@
5828 4579 die( '' );
5829 4580 }
5830 4581
5831 4582 // Get multisite settings.
5832 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
4583 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
5833 4584
5834 - // Sanitize settings.
4585 + // Sanitize settings
5835 4586 $auth_multisite_settings = $this->sanitize_options( $_POST );
5836 4587
5837 - // Filter options to only the allowed values (multisite options are a subset of all options).
5838 - $allowed = array(
4588 + // Filter options to only the allowed values (multisite options are a subset of all options)
4589 + $allowed = array(
5839 4590 'multisite_override',
5840 4591 'access_who_can_login',
5841 4592 'access_who_can_view',
5842 4593 'access_default_role',
@@ -5869,17 +4620,13 @@
5869 4620 'ldap_attr_last_name',
5870 4621 'ldap_attr_update_on_login',
5871 4622 'advanced_lockouts',
5872 4623 'advanced_hide_wp_login',
5873 - 'advanced_users_per_page',
5874 - 'advanced_users_sort_by',
5875 - 'advanced_users_sort_order',
5876 - 'advanced_widget_enabled',
5877 4624 );
5878 4625 $auth_multisite_settings = array_intersect_key( $auth_multisite_settings, array_flip( $allowed ) );
5879 4626
5880 4627 // Update multisite settings in database.
5881 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
4628 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
5882 4629
5883 4630 // Return 'success' value to AJAX call.
5884 4631 die( 'success' );
5885 4632 }
@@ -5893,67 +4640,42 @@
5893 4640 */
5894 4641
5895 4642
5896 4643
5897 - /**
5898 - * Load Authorizer dashboard widget if it's enabled.
5899 - *
5900 - * Action: wp_dashboard_setup
5901 - */
5902 - public function add_dashboard_widgets() {
5903 - $widget_enabled = $this->get_plugin_option( 'advanced_widget_enabled', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) === '1';
5904 -
5905 - // Load authorizer dashboard widget if it's enabled and user has permission.
5906 - if ( current_user_can( 'create_users' ) && $widget_enabled ) {
5907 - // Add dashboard widget for adding/editing users with access.
4644 + function add_dashboard_widgets() {
4645 + // Only users who can edit can see the authorizer dashboard widget
4646 + if ( current_user_can( 'create_users' ) ) {
4647 + // Add dashboard widget for adding/editing users with access
5908 4648 wp_add_dashboard_widget( 'auth_dashboard_widget', __( 'Authorizer Settings', 'authorizer' ), array( $this, 'add_auth_dashboard_widget' ) );
5909 4649 }
5910 4650 }
5911 4651
5912 4652
5913 - /**
5914 - * Render Authorizer dashboard widget (callback).
5915 - */
5916 - public function add_auth_dashboard_widget() {
5917 - ?>
5918 - <form method="post" id="auth_settings_access_form" action="">
4653 + function add_auth_dashboard_widget() {
4654 + ?><form method="post" id="auth_settings_access_form" action="">
5919 4655 <?php $this->print_section_info_access_login(); ?>
5920 4656 <div>
5921 - <h2><?php esc_html_e( 'Pending Users', 'authorizer' ); ?></h2>
4657 + <h2><?php _e( 'Pending Users', 'authorizer' ); ?></h2>
5922 4658 <?php $this->print_combo_auth_access_users_pending(); ?>
5923 4659 </div>
5924 4660 <div>
5925 - <h2><?php esc_html_e( 'Approved Users', 'authorizer' ); ?></h2>
4661 + <h2><?php _e( 'Approved Users', 'authorizer' ); ?></h2>
5926 4662 <?php $this->print_combo_auth_access_users_approved(); ?>
5927 4663 </div>
5928 4664 <div>
5929 - <h2><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?></h2>
4665 + <h2><?php _e( 'Blocked Users', 'authorizer' ); ?></h2>
5930 4666 <?php $this->print_combo_auth_access_users_blocked(); ?>
5931 4667 </div>
5932 4668 <br class="clear" />
5933 - </form>
5934 - <?php
4669 + </form><?php
5935 4670 }
5936 4671
5937 4672
5938 -
5939 - /**
5940 - * ***************************
5941 - * AJAX Actions
5942 - * ***************************
5943 - */
5944 -
5945 -
5946 -
5947 - /**
5948 - * Re-render the Approved User list (usually triggered if pager params have
5949 - * changed, e.g., current page, search term, sort order).
5950 - *
5951 - * Action: wp_ajax_refresh_approved_user_list
5952 - *
5953 - * @return void
5954 - */
5955 - public function ajax_refresh_approved_user_list() {
4673 + // Fired on a change event from the optional usermeta field in the
4674 + // approved user list. Updates the selected usermeta value, or saves it
4675 + // in the user's approved list entry if the user hasn't logged in yet
4676 + // and created a WordPress account.
4677 + function ajax_update_auth_usermeta() {
5956 4678 // Fail silently if current user doesn't have permissions.
5957 4679 if ( ! current_user_can( 'create_users' ) ) {
5958 4680 die( '' );
5959 4681 }
@@ -5958,175 +4680,35 @@
5958 4680 die( '' );
5959 4681 }
5960 4682
5961 4683 // Nonce check.
5962 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4684 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5963 4685 die( '' );
5964 4686 }
5965 4687
5966 4688 // Fail if required post data doesn't exist.
5967 - if ( ! array_key_exists( 'paged', $_REQUEST ) ) {
4689 + if ( ! array_key_exists( 'email', $_REQUEST ) || ! array_key_exists( 'usermeta', $_REQUEST ) ) {
5968 4690 die( '' );
5969 4691 }
5970 4692
5971 - // Get defaults.
5972 - $success = true;
5973 - $message = '';
5974 - $is_network_admin = isset( $_REQUEST['is_network_admin'] ) && '1' === $_REQUEST['is_network_admin'];
5975 -
5976 - // Get user list.
5977 - $option = 'access_users_approved';
5978 - $admin_mode = is_multisite() && $is_network_admin ? WP_Plugin_Authorizer::NETWORK_CONTEXT : WP_Plugin_Authorizer::SINGLE_CONTEXT;
5979 - $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
5980 - $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
5981 -
5982 - // Get multisite approved users (will be added to top of list, greyed out).
5983 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
5984 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
5985 - $auth_settings_option_multisite = array();
5986 - if (
5987 - is_multisite() &&
5988 - ! $is_network_admin &&
5989 - 1 !== intval( $auth_override_multisite ) &&
5990 - array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
5991 - '1' === $auth_multisite_settings['multisite_override']
5992 - ) {
5993 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
5994 - $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
5995 - // Add multisite users to the beginning of the main user array.
5996 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
5997 - $approved_user['multisite_user'] = true;
5998 - array_unshift( $auth_settings_option, $approved_user );
5999 - }
6000 - }
6001 -
6002 - // Get custom usermeta field to show.
6003 - $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
6004 -
6005 - // Filter user list to search terms.
6006 - if ( ! empty( $_REQUEST['search'] ) ) {
6007 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
6008 - $auth_settings_option = array_filter(
6009 - $auth_settings_option, function ( $user ) use ( $search_term ) {
6010 - return stripos( $user['email'], $search_term ) !== false ||
6011 - stripos( $user['role'], $search_term ) !== false ||
6012 - stripos( $user['date_added'], $search_term ) !== false;
6013 - }
6014 - );
6015 - }
6016 -
6017 - // Sort user list.
6018 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
6019 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
6020 - $sort_dimension = array();
6021 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
6022 - foreach ( $auth_settings_option as $key => $user ) {
6023 - if ( 'date_added' === $sort_by ) {
6024 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
6025 - } else {
6026 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
6027 - }
6028 - }
6029 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
6030 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
6031 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
6032 - // If default sort method and reverse order, just reverse the array.
6033 - $auth_settings_option = array_reverse( $auth_settings_option );
6034 - }
6035 -
6036 - // Ensure array keys run from 0..max (keys in database will be the original,
6037 - // index, and removing users will not reorder the array keys of other users).
6038 - $auth_settings_option = array_values( $auth_settings_option );
6039 -
6040 - // Get pager params.
6041 - $total_users = count( $auth_settings_option );
6042 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
6043 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
6044 - $total_pages = ceil( $total_users / $users_per_page );
6045 - if ( $total_pages < 1 ) {
6046 - $total_pages = 1;
6047 - }
6048 -
6049 - // Make sure current_page is between 1 and max pages.
6050 - if ( $current_page < 1 ) {
6051 - $current_page = 1;
6052 - } elseif ( $current_page > $total_pages ) {
6053 - $current_page = $total_pages;
6054 - }
6055 -
6056 - // Render user list.
6057 - ob_start();
6058 - $offset = ( $current_page - 1 ) * $users_per_page;
6059 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
6060 - for ( $key = $offset; $key < $max; $key++ ) :
6061 - $approved_user = $auth_settings_option[ $key ];
6062 - if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
6063 - continue;
6064 - endif;
6065 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
6066 - endfor;
6067 -
6068 - // Send response to client.
6069 - $response = array(
6070 - 'success' => $success,
6071 - 'message' => $message,
6072 - 'html' => ob_get_clean(),
6073 - /* TRANSLATORS: %s: number of users */
6074 - 'total_users_html' => sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ),
6075 - 'total_pages_html' => number_format_i18n( $total_pages ),
6076 - 'total_pages' => $total_pages,
6077 - );
6078 - header( 'content-type: application/json' );
6079 - echo wp_json_encode( $response );
6080 - exit;
6081 - }
6082 -
6083 -
6084 - /**
6085 - * Fired on a change event from the optional usermeta field in the approved
6086 - * user list. Updates the selected usermeta value, or saves it in the user's
6087 - * approved list entry if the user hasn't logged in yet and created a
6088 - * WordPress account.
6089 - *
6090 - * Action: wp_ajax_update_auth_usermeta
6091 - *
6092 - * @return void
6093 - */
6094 - public function ajax_update_auth_usermeta() {
6095 - // Fail silently if current user doesn't have permissions.
6096 - if ( ! current_user_can( 'create_users' ) ) {
6097 - die( '' );
6098 - }
6099 -
6100 - // Nonce check.
6101 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
6102 - die( '' );
6103 - }
6104 -
6105 - // Fail if required post data doesn't exist.
6106 - if ( ! isset( $_REQUEST['email'], $_REQUEST['usermeta'] ) ) {
6107 - die( '' );
6108 - }
6109 -
6110 4693 // Get values to update from post data.
6111 - $email = sanitize_email( wp_unslash( $_REQUEST['email'] ) );
6112 - $meta_value = sanitize_meta( 'authorizer-usermeta', wp_unslash( $_REQUEST['usermeta'] ), 'user' );
6113 - $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
4694 + $email = $_REQUEST['email'];
4695 + $meta_value = $_REQUEST['usermeta'];
4696 + $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
6114 4697
6115 4698 // If user doesn't exist, save usermeta selection to authorizer
6116 4699 // list. This value will get saved to usermeta when the user first
6117 4700 // logs in (i.e., when their WordPress account is created).
6118 - $wp_user = get_user_by( 'email', $email );
6119 - if ( ! $wp_user ) {
4701 + if ( ! ( $wp_user = get_user_by( 'email', $email ) ) ) {
6120 4702 // Look through multisite approved users and add a usermeta
6121 4703 // reference for the current blog if the user is found.
6122 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
4704 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
6123 4705 $should_update_auth_multisite_settings_access_users_approved = false;
6124 4706 foreach ( $auth_multisite_settings_access_users_approved as $index => $approved_user ) {
6125 - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6126 - if ( ! is_array( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] ) ) {
4707 + if ( $email === $approved_user['email'] ) {
4708 + if ( ! is_array( $auth_multisite_settings_access_users_approved[$index]['usermeta'] ) ) {
6127 4709 // Initialize the array of usermeta for each blog this user belongs to.
6128 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] = array();
4710 + $auth_multisite_settings_access_users_approved[$index]['usermeta'] = array();
6129 4711 } else {
6130 4712 // There is already usermeta associated with this
6131 4713 // preapproved user; iterate through it and make
6132 4714 // sure it's not for old meta_keys (delete it if
@@ -6132,53 +4714,55 @@
6132 4714 // sure it's not for old meta_keys (delete it if
6133 4715 // so). This can happen if someone changes the
6134 4716 // usermeta key in authorizer options, and we don't
6135 4717 // want to hang on to old data.
6136 - foreach ( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] as $blog_id => $usermeta ) {
4718 + foreach ( $auth_multisite_settings_access_users_approved[$index]['usermeta'] as $blog_id => $usermeta ) {
6137 4719 if ( array_key_exists( 'meta_key', $usermeta ) && $usermeta['meta_key'] === $meta_key ) {
6138 4720 continue;
6139 4721 } else {
6140 - unset( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ $blog_id ] );
4722 + unset( $auth_multisite_settings_access_users_approved[$index]['usermeta'][$blog_id] );
6141 4723 }
6142 4724 }
6143 4725 }
6144 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ get_current_blog_id() ] = array(
6145 - 'meta_key' => $meta_key,
4726 + $auth_multisite_settings_access_users_approved[$index]['usermeta'][get_current_blog_id()] = array(
4727 + 'meta_key' => $meta_key,
6146 4728 'meta_value' => $meta_value,
6147 4729 );
6148 - $should_update_auth_multisite_settings_access_users_approved = true;
4730 + $should_update_auth_multisite_settings_access_users_approved = true;
6149 4731 }
6150 4732 }
6151 4733 if ( $should_update_auth_multisite_settings_access_users_approved ) {
6152 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4734 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6153 4735 }
6154 4736
6155 4737 // Look through the approved users (of the current blog in a
6156 4738 // multisite install, or just of the single site) and add a
6157 4739 // usermeta reference if the user is found.
6158 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
4740 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
6159 4741 $should_update_auth_settings_access_users_approved = false;
6160 4742 foreach ( $auth_settings_access_users_approved as $index => $approved_user ) {
6161 - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6162 - $auth_settings_access_users_approved[ $index ]['usermeta'] = array(
6163 - 'meta_key' => $meta_key,
4743 + if ( $email === $approved_user['email'] ) {
4744 + $auth_settings_access_users_approved[$index]['usermeta'] = array(
4745 + 'meta_key' => $meta_key,
6164 4746 'meta_value' => $meta_value,
6165 4747 );
6166 - $should_update_auth_settings_access_users_approved = true;
4748 + $should_update_auth_settings_access_users_approved = true;
6167 4749 }
6168 4750 }
6169 4751 if ( $should_update_auth_settings_access_users_approved ) {
6170 4752 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6171 4753 }
4754 +
6172 4755 } else {
6173 4756 // Update user's usermeta value for usermeta key stored in authorizer options.
6174 4757 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
6175 4758 // We have an ACF field value, so use the ACF function to update it.
6176 - update_field( str_replace( 'acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
4759 + update_field( str_replace('acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
6177 4760 } else {
6178 4761 // We have a normal usermeta value, so just update it via the WordPress function.
6179 4762 update_user_meta( $wp_user->ID, $meta_key, $meta_value );
6180 4763 }
4764 +
6181 4765 }
6182 4766
6183 4767 // Return 'success' value to AJAX call.
6184 4768 die( 'success' );
@@ -6184,17 +4768,9 @@
6184 4768 die( 'success' );
6185 4769 }
6186 4770
6187 4771
6188 - /**
6189 - * Fired on a change event from the user fields in the user lists. Updates
6190 - * the selected user value.
6191 - *
6192 - * Action: wp_ajax_update_auth_user
6193 - *
6194 - * @return void
6195 - */
6196 - public function ajax_update_auth_user() {
4772 + function ajax_update_auth_user() {
6197 4773 // Fail silently if current user doesn't have permissions.
6198 4774 if ( ! current_user_can( 'create_users' ) ) {
6199 4775 die( '' );
6200 4776 }
@@ -6199,79 +4775,76 @@
6199 4775 die( '' );
6200 4776 }
6201 4777
6202 4778 // Nonce check.
6203 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4779 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
6204 4780 die( '' );
6205 4781 }
6206 4782
6207 4783 // Fail if requesting a change to an invalid setting.
6208 - if ( ! isset( $_POST['setting'] ) || ! in_array( wp_unslash( $_POST['setting'] ), array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
4784 + if ( ! in_array( $_POST['setting'], array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
6209 4785 die( '' );
6210 4786 }
6211 4787
6212 - // Track any emails that couldn't be added (used when adding users).
6213 - $invalid_emails = array();
6214 -
6215 4788 // Editing a pending list entry.
6216 - if ( 'access_users_pending' === $_POST['setting'] ) {
6217 - // Sanitize posted data.
6218 - $access_users_pending = array();
6219 - if ( isset( $_POST['access_users_pending'] ) && is_array( $_POST['access_users_pending'] ) ) {
6220 - $access_users_pending = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_pending'] ) );
4789 + if ( $_POST['setting'] === 'access_users_pending' ) {
4790 + // Initialize posted data if empty.
4791 + if ( ! ( array_key_exists( 'access_users_pending', $_POST ) && is_array( $_POST['access_users_pending'] ) ) ) {
4792 + $_POST['access_users_pending'] = array();
6221 4793 }
6222 4794
6223 4795 // Deal with each modified user (add or remove).
6224 - foreach ( $access_users_pending as $pending_user ) {
4796 + foreach ( $_POST['access_users_pending'] as $pending_user ) {
6225 4797
6226 - if ( 'add' === $pending_user['edit_action'] ) {
4798 + if ( $pending_user['edit_action'] === 'add' ) {
6227 4799
6228 4800 // Add new user to pending list and save (skip if it's
6229 4801 // already there--someone else might have just done it).
6230 4802 if ( ! $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
6231 4803 $auth_settings_access_users_pending = $this->sanitize_user_list(
6232 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4804 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
6233 4805 );
6234 4806 array_push( $auth_settings_access_users_pending, $pending_user );
6235 4807 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6236 4808 }
6237 - } elseif ( 'remove' === $pending_user['edit_action'] ) {
6238 4809
6239 - // Remove user from pending list and save.
6240 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6241 - foreach ( $auth_settings_access_users_pending as $key => $existing_user ) {
6242 - if ( 0 === strcasecmp( $pending_user['email'], $existing_user['email'] ) ) {
6243 - unset( $auth_settings_access_users_pending[ $key ] );
6244 - update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6245 - break;
4810 + } elseif ( $pending_user['edit_action'] === 'remove' ) {
4811 +
4812 + // Remove user from pending list and save
4813 + if ( $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
4814 + $auth_settings_access_users_pending = $this->sanitize_user_list(
4815 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
4816 + );
4817 + foreach ( $auth_settings_access_users_pending as $key => $existing_user ) {
4818 + if ( $pending_user['email'] == $existing_user['email'] ) {
4819 + unset( $auth_settings_access_users_pending[$key] );
4820 + break;
4821 + }
6246 4822 }
4823 + update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6247 4824 }
4825 +
6248 4826 }
6249 4827 }
6250 4828 }
6251 4829
6252 4830 // Editing an approved list entry.
6253 - if ( 'access_users_approved' === $_POST['setting'] ) {
6254 - // Sanitize posted data.
6255 - $access_users_approved = array();
6256 - if ( isset( $_POST['access_users_approved'] ) && is_array( $_POST['access_users_approved'] ) ) {
6257 - $access_users_approved = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_approved'] ) );
4831 + if ( $_POST['setting'] === 'access_users_approved' ) {
4832 + // Initialize posted data if empty.
4833 + if ( ! ( array_key_exists( 'access_users_approved', $_POST ) && is_array( $_POST['access_users_approved'] ) ) ) {
4834 + $_POST['access_users_approved'] = array();
6258 4835 }
6259 4836
6260 4837 // Deal with each modified user (add, remove, or change_role).
6261 - foreach ( $access_users_approved as $approved_user ) {
6262 - // Skip blank entries.
6263 - if ( strlen( $approved_user['email'] ) < 1 ) {
6264 - continue;
6265 - }
4838 + foreach ( $_POST['access_users_approved'] as $approved_user ) {
6266 4839
6267 4840 // New user (create user, or add existing user to current site in multisite).
6268 - if ( 'add' === $approved_user['edit_action'] ) {
4841 + if ( $approved_user['edit_action'] === 'add' ) {
6269 4842 $new_user = get_user_by( 'email', $approved_user['email'] );
6270 - if ( false !== $new_user ) {
4843 + if ( $new_user !== false ) {
6271 4844 // If we're adding an existing multisite user, make sure their
6272 4845 // newly-assigned role is updated on all sites they are already in.
6273 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4846 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6274 4847 foreach ( get_blogs_of_user( $new_user->ID ) as $blog ) {
6275 4848 add_user_to_blog( $blog->userblog_id, $new_user->ID, $approved_user['role'] );
6276 4849 }
6277 4850 }
@@ -6278,9 +4851,9 @@
6278 4851 // If this user already has an account on another site in the network, add them to this site.
6279 4852 if ( is_multisite() ) {
6280 4853 add_user_to_blog( get_current_blog_id(), $new_user->ID, $approved_user['role'] );
6281 4854 }
6282 - } elseif ( $approved_user['local_user'] && 'false' !== $approved_user['local_user'] ) {
4855 + } elseif ( $approved_user['local_user'] === 'true' ) {
6283 4856 // Create a WP account for this new *local* user and email the password.
6284 4857 $plaintext_password = wp_generate_password(); // random password
6285 4858 // If there's already a user with this username (e.g.,
6286 4859 // johndoe/johndoe@gmail.com exists, and we're trying to add
@@ -6288,26 +4861,26 @@
6288 4861 // as the username.
6289 4862 $username = explode( '@', $approved_user['email'] );
6290 4863 $username = $username[0];
6291 4864 if ( get_user_by( 'login', $username ) !== false ) {
6292 - $username = $this->lowercase( $approved_user['email'] );
4865 + $username = $approved_user['email'];
6293 4866 }
6294 - if ( 'false' !== $approved_user['multisite_user'] ) {
4867 + if ( $approved_user['multisite_user'] !== 'false' ) {
6295 4868 $result = wpmu_create_user(
6296 4869 strtolower( $username ),
6297 4870 $plaintext_password,
6298 - $this->lowercase( $approved_user['email'] )
4871 + strtolower( $approved_user['email'] )
6299 4872 );
6300 4873 } else {
6301 4874 $result = wp_insert_user(
6302 4875 array(
6303 - 'user_login' => strtolower( $username ),
6304 - 'user_pass' => $plaintext_password,
6305 - 'first_name' => '',
6306 - 'last_name' => '',
6307 - 'user_email' => $this->lowercase( $approved_user['email'] ),
4876 + 'user_login' => strtolower( $username ),
4877 + 'user_pass' => $plaintext_password,
4878 + 'first_name' => '',
4879 + 'last_name' => '',
4880 + 'user_email' => strtolower( $approved_user['email'] ),
6308 4881 'user_registered' => date( 'Y-m-d H:i:s' ),
6309 - 'role' => $approved_user['role'],
4882 + 'role' => $approved_user['role'],
6310 4883 )
6311 4884 );
6312 4885 }
6313 4886 if ( ! is_wp_error( $result ) ) {
@@ -6313,8 +4886,9 @@
6313 4886 if ( ! is_wp_error( $result ) ) {
6314 4887 // Email login credentials to new user.
6315 4888 wp_new_user_notification( $result, null, 'both' );
6316 4889 }
4890 +
6317 4891 }
6318 4892
6319 4893 // Email new user welcome message if plugin option is set.
6320 4894 $this->maybe_email_welcome_message( $approved_user['email'] );
@@ -6320,46 +4894,41 @@
6320 4894 $this->maybe_email_welcome_message( $approved_user['email'] );
6321 4895
6322 4896 // Add new user to approved list and save (skip if it's
6323 4897 // already there--someone else might have just done it).
6324 - if ( 'false' !== $approved_user['multisite_user'] ) {
4898 + if ( $approved_user['multisite_user'] !== 'false' ) {
6325 4899 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6326 4900 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6327 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4901 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6328 4902 );
6329 - $approved_user['date_added'] = date( 'M Y' );
4903 + $approved_user['date_added'] = date( 'M Y' );
6330 4904 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
6331 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6332 - } else {
6333 - $invalid_emails[] = $approved_user['email'];
4905 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6334 4906 }
6335 4907 } else {
6336 4908 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6337 4909 $auth_settings_access_users_approved = $this->sanitize_user_list(
6338 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4910 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6339 4911 );
6340 - $approved_user['date_added'] = date( 'M Y' );
4912 + $approved_user['date_added'] = date( 'M Y' );
6341 4913 array_push( $auth_settings_access_users_approved, $approved_user );
6342 4914 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6343 - } else {
6344 - $invalid_emails[] = $approved_user['email'];
6345 4915 }
6346 4916 }
6347 4917
6348 4918 // If we've added a new multisite user, go through all pending/approved/blocked lists
6349 4919 // on individual sites and remove this user from them (to prevent duplicate entries).
6350 - if ( 'false' !== $approved_user['multisite_user'] && is_multisite() ) {
4920 + if ( $approved_user['multisite_user'] !== 'false' && is_multisite() ) {
6351 4921 $list_names = array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' );
6352 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6353 4922 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6354 4923 foreach ( $sites as $site ) {
6355 4924 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6356 4925 foreach ( $list_names as $list_name ) {
6357 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
4926 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6358 4927 $list_changed = false;
6359 4928 foreach ( $user_list as $key => $user ) {
6360 - if ( 0 === strcasecmp( $user['email'], $approved_user['email'] ) ) {
6361 - unset( $user_list[ $key ] );
4929 + if ( $user['email'] == $approved_user['email'] ) {
4930 + unset( $user_list[$key] );
6362 4931 $list_changed = true;
6363 4932 }
6364 4933 }
6365 4934 if ( $list_changed ) {
@@ -6367,47 +4936,44 @@
6367 4936 }
6368 4937 }
6369 4938 }
6370 4939 }
6371 - } elseif ( 'remove' === $approved_user['edit_action'] ) { // Remove user from approved list and save (also remove their role if they have a WordPress account).
6372 - if ( 'false' !== $approved_user['multisite_user'] ) {
6373 - $auth_multisite_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
6374 - foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6375 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6376 - // Remove role of the associated WordPress user from all blogs (but don't delete the user).
6377 - $user = get_user_by( 'email', $approved_user['email'] );
6378 - if ( false !== $user ) {
6379 - // Loop through all of the blogs this user is a member of and remove their capabilities.
6380 - foreach ( get_blogs_of_user( $user->ID ) as $blog ) {
6381 - remove_user_from_blog( $user->ID, $blog->userblog_id, '' );
6382 - }
4940 +
4941 + // Remove user from approved list and save
4942 + } elseif ( $approved_user['edit_action'] === 'remove' ) {
4943 + if ( $approved_user['multisite_user'] !== 'false' ) {
4944 + if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
4945 + $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
4946 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
4947 + );
4948 + foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
4949 + if ( $approved_user['email'] == $existing_user['email'] ) {
4950 + unset( $auth_multisite_settings_access_users_approved[$key] );
4951 + break;
6383 4952 }
6384 - // Remove entry from Approved Users list.
6385 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
6386 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6387 - break;
6388 4953 }
4954 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6389 4955 }
6390 4956 } else {
6391 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6392 - foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6393 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6394 - // Remove role of the associated WordPress user (but don't delete the user).
6395 - $user = get_user_by( 'email', $approved_user['email'] );
6396 - if ( false !== $user ) {
6397 - $user->set_role( '' );
4957 + if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
4958 + $auth_settings_access_users_approved = $this->sanitize_user_list(
4959 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
4960 + );
4961 + foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
4962 + if ( $approved_user['email'] == $existing_user['email'] ) {
4963 + unset( $auth_settings_access_users_approved[$key] );
4964 + break;
6398 4965 }
6399 - // Remove entry from Approved Users list.
6400 - unset( $auth_settings_access_users_approved[ $key ] );
6401 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6402 - break;
6403 4966 }
4967 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6404 4968 }
6405 4969 }
6406 - } elseif ( 'change_role' === $approved_user['edit_action'] ) { // Update user's role in WordPress.
4970 +
4971 + // Update user's role in WordPress
4972 + } elseif ( $approved_user['edit_action'] === 'change_role' ) {
6407 4973 $changed_user = get_user_by( 'email', $approved_user['email'] );
6408 4974 if ( $changed_user ) {
6409 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4975 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6410 4976 foreach ( get_blogs_of_user( $changed_user->ID ) as $blog ) {
6411 4977 add_user_to_blog( $blog->userblog_id, $changed_user->ID, $approved_user['role'] );
6412 4978 }
6413 4979 } else {
@@ -6414,30 +4980,30 @@
6414 4980 $changed_user->set_role( $approved_user['role'] );
6415 4981 }
6416 4982 }
6417 4983
6418 - if ( 'false' !== $approved_user['multisite_user'] ) {
4984 + if ( $approved_user['multisite_user'] !== 'false' ) {
6419 4985 if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6420 4986 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6421 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4987 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6422 4988 );
6423 4989 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6424 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6425 - $auth_multisite_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
4990 + if ( $approved_user['email'] == $existing_user['email'] ) {
4991 + $auth_multisite_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6426 4992 break;
6427 4993 }
6428 4994 }
6429 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4995 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6430 4996 }
6431 4997 } else {
6432 4998 // Update user's role in approved list and save.
6433 4999 if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6434 5000 $auth_settings_access_users_approved = $this->sanitize_user_list(
6435 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5001 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6436 5002 );
6437 5003 foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6438 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6439 - $auth_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
5004 + if ( $approved_user['email'] == $existing_user['email'] ) {
5005 + $auth_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6440 5006 break;
6441 5007 }
6442 5008 }
6443 5009 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
@@ -6442,33 +5008,28 @@
6442 5008 }
6443 5009 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6444 5010 }
6445 5011 }
5012 +
6446 5013 }
6447 5014 }
6448 5015 }
6449 5016
6450 5017 // Editing a blocked list entry.
6451 - if ( 'access_users_blocked' === $_POST['setting'] ) {
6452 - // Sanitize post data.
6453 - $access_users_blocked = array();
6454 - if ( isset( $_POST['access_users_blocked'] ) && is_array( $_POST['access_users_blocked'] ) ) {
6455 - $access_users_blocked = $this->sanitize_update_auth_users(
6456 - wp_unslash( $_POST['access_users_blocked'] ),
6457 - array(
6458 - 'allow_wildcard_email' => true,
6459 - )
6460 - );
5018 + if ( $_POST['setting'] === 'access_users_blocked' ) {
5019 + // Initialize posted data if empty.
5020 + if ( ! ( array_key_exists( 'access_users_blocked', $_POST ) && is_array( $_POST['access_users_blocked'] ) ) ) {
5021 + $_POST['access_users_blocked'] = array();
6461 5022 }
6462 5023
6463 5024 // Deal with each modified user (add or remove).
6464 - foreach ( $access_users_blocked as $blocked_user ) {
5025 + foreach ( $_POST['access_users_blocked'] as $blocked_user ) {
6465 5026
6466 - if ( 'add' === $blocked_user['edit_action'] ) {
5027 + if ( $blocked_user['edit_action'] === 'add' ) {
6467 5028
6468 5029 // Add auth_blocked usermeta for the user.
6469 5030 $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
6470 - if ( false !== $blocked_wp_user ) {
5031 + if ( $blocked_wp_user !== false ) {
6471 5032 update_user_meta( $blocked_wp_user->ID, 'auth_blocked', 'yes' );
6472 5033 }
6473 5034
6474 5035 // Add new user to blocked list and save (skip if it's
@@ -6474,162 +5035,48 @@
6474 5035 // Add new user to blocked list and save (skip if it's
6475 5036 // already there--someone else might have just done it).
6476 5037 if ( ! $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
6477 5038 $auth_settings_access_users_blocked = $this->sanitize_user_list(
6478 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5039 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
6479 5040 );
6480 - $blocked_user['date_added'] = date( 'M Y' );
5041 + $blocked_user['date_added'] = date( 'M Y' );
6481 5042 array_push( $auth_settings_access_users_blocked, $blocked_user );
6482 5043 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6483 - } else {
6484 - $invalid_emails[] = $blocked_user['email'];
6485 5044 }
6486 - } elseif ( 'remove' === $blocked_user['edit_action'] ) {
6487 5045
5046 + } elseif ( $blocked_user['edit_action'] === 'remove' ) {
5047 +
6488 5048 // Remove auth_blocked usermeta for the user.
6489 5049 $unblocked_user = get_user_by( 'email', $blocked_user['email'] );
6490 - if ( false !== $unblocked_user ) {
5050 + if ( $unblocked_user !== false ) {
6491 5051 delete_user_meta( $unblocked_user->ID, 'auth_blocked', 'yes' );
6492 5052 }
6493 5053
6494 - // Remove user from blocked list and save.
6495 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6496 - foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) {
6497 - if ( 0 === strcasecmp( $blocked_user['email'], $existing_user['email'] ) ) {
6498 - unset( $auth_settings_access_users_blocked[ $key ] );
6499 - update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6500 - break;
5054 + // Remove user from blocked list and save
5055 + if ( $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
5056 + $auth_settings_access_users_blocked = $this->sanitize_user_list(
5057 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
5058 + );
5059 + foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) {
5060 + if ( $blocked_user['email'] == $existing_user['email'] ) {
5061 + unset( $auth_settings_access_users_blocked[$key] );
5062 + break;
5063 + }
6501 5064 }
5065 + update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6502 5066 }
5067 +
6503 5068 }
6504 5069 }
6505 5070 }
6506 5071
6507 - // Send response to client.
6508 - $response = array(
6509 - 'success' => true,
6510 - 'invalid_emails' => $invalid_emails,
6511 - );
6512 - header( 'content-type: application/json' );
6513 - echo wp_json_encode( $response );
6514 - exit;
5072 + // Return 'success' value to AJAX call.
5073 + die( 'success' );
6515 5074 }
6516 5075
6517 5076
6518 - /**
6519 - * Sanitizes an array of user update commands coming from the AJAX handler in Authorizer Settings.
6520 - *
6521 - * Example $users array:
6522 - * array(
6523 - * array(
6524 - * edit_action: 'add' or 'remove' or 'change_role',
6525 - * email: 'johndoe@example.com',
6526 - * role: 'subscriber',
6527 - * date_added: 'Jun 2014',
6528 - * local_user: 'true' or 'false',
6529 - * multisite_user: 'true' or 'false',
6530 - * ),
6531 - * ...
6532 - * )
6533 - *
6534 - * @param array $users Users to edit.
6535 - * @param array $args Options (e.g., 'allow_wildcard_email' => true).
6536 - * @return array Sanitized users to edit.
6537 - */
6538 - private function sanitize_update_auth_users( $users = array(), $args = array() ) {
6539 - if ( ! is_array( $users ) ) {
6540 - $users = array();
6541 - }
6542 - if ( isset( $args['allow_wildcard_email'] ) && $args['allow_wildcard_email'] ) {
6543 - $users = array_map( array( $this, 'sanitize_update_auth_user_allow_wildcard_email' ), $users );
6544 - } else {
6545 - $users = array_map( array( $this, 'sanitize_update_auth_user' ), $users );
6546 - }
6547 5077
6548 - // Remove any entries that failed email address validation.
6549 - $users = array_filter( $users, array( $this, 'remove_invalid_auth_users' ) );
6550 -
6551 - return $users;
6552 - }
6553 -
6554 -
6555 5078 /**
6556 - * This array filter will remove any users who failed email address validation
6557 - * (which would set their email to a blank string).
6558 - * @param array $user User data to check for a valid email.
6559 - * @return bool Whether to filter out the user.
6560 - */
6561 - private function remove_invalid_auth_users( $user ) {
6562 - return isset( $user['email'] ) && strlen( $user['email'] ) > 0;
6563 - }
6564 -
6565 - /**
6566 - * Callback for array_map in sanitize_update_auth_users().
6567 - *
6568 - * @param array $user User data to sanitize.
6569 - * @return array Sanitized user data.
6570 - */
6571 - private function sanitize_update_auth_user( $user ) {
6572 - if ( array_key_exists( 'edit_action', $user ) ) {
6573 - $user['edit_action'] = sanitize_text_field( $user['edit_action'] );
6574 - }
6575 - if ( isset( $user['email'] ) ) {
6576 - $user['email'] = sanitize_email( $user['email'] );
6577 - }
6578 - if ( isset( $user['role'] ) ) {
6579 - $user['role'] = sanitize_text_field( $user['role'] );
6580 - }
6581 - if ( isset( $user['date_added'] ) ) {
6582 - $user['date_added'] = sanitize_text_field( $user['date_added'] );
6583 - }
6584 - if ( isset( $user['local_user'] ) ) {
6585 - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false';
6586 - }
6587 - if ( isset( $user['multisite_user'] ) ) {
6588 - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false';
6589 - }
6590 -
6591 - return $user;
6592 - }
6593 -
6594 -
6595 -
6596 - /**
6597 - * Callback for array_map in sanitize_update_auth_users().
6598 - *
6599 - * @param array $user User data to sanitize.
6600 - * @return array Sanitized user data.
6601 - */
6602 - private function sanitize_update_auth_user_allow_wildcard_email( $user ) {
6603 - if ( array_key_exists( 'edit_action', $user ) ) {
6604 - $user['edit_action'] = sanitize_text_field( $user['edit_action'] );
6605 - }
6606 - if ( isset( $user['email'] ) ) {
6607 - if ( strpos( $user['email'], '@' ) === 0 ) {
6608 - $user['email'] = sanitize_text_field( $user['email'] );
6609 - } else {
6610 - $user['email'] = sanitize_email( $user['email'] );
6611 - }
6612 - }
6613 - if ( isset( $user['role'] ) ) {
6614 - $user['role'] = sanitize_text_field( $user['role'] );
6615 - }
6616 - if ( isset( $user['date_added'] ) ) {
6617 - $user['date_added'] = sanitize_text_field( $user['date_added'] );
6618 - }
6619 - if ( isset( $user['local_user'] ) ) {
6620 - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false';
6621 - }
6622 - if ( isset( $user['multisite_user'] ) ) {
6623 - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false';
6624 - }
6625 -
6626 - return $user;
6627 - }
6628 -
6629 -
6630 -
6631 - /**
6632 5079 * ***************************
6633 5080 * Helper functions
6634 5081 * ***************************
6635 5082 */
@@ -6637,20 +5084,20 @@
6637 5084
6638 5085 /**
6639 5086 * Retrieves a specific plugin option from db. Multisite enabled.
6640 5087 *
6641 - * @param string $option Option name.
6642 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6643 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6644 - * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page.
6645 - * @return mixed Option value, or null on failure.
5088 + * @param string $option Option name
5089 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5090 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5091 + * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page
5092 + * @return mixed Option value, or null on failure
6646 5093 */
6647 - private function get_plugin_option( $option, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override', $print_mode = 'no overlay' ) {
5094 + private function get_plugin_option( $option, $admin_mode = SINGLE_ADMIN, $override_mode = 'no override', $print_mode = 'no overlay' ) {
6648 5095 // Special case for user lists (they are saved seperately to prevent concurrency issues).
6649 - if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
6650 - $list = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings_' . $option );
6651 - if ( is_multisite() && WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
6652 - $list = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_' . $option, array() );
5096 + if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
5097 + $list = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings_' . $option );
5098 + if ( is_multisite() && $admin_mode === MULTISITE_ADMIN ) {
5099 + $list = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_' . $option, array() );
6653 5100 }
6654 5101 return $list;
6655 5102 }
6656 5103
@@ -6664,26 +5111,24 @@
6664 5111
6665 5112 // If requested and appropriate, print the overlay hiding the
6666 5113 // single site option that is overridden by a multisite option.
6667 5114 if (
6668 - WP_Plugin_Authorizer::NETWORK_CONTEXT !== $admin_mode &&
6669 - 'allow override' === $override_mode &&
6670 - 'print overlay' === $print_mode &&
5115 + $admin_mode !== MULTISITE_ADMIN &&
5116 + $override_mode === 'allow override' &&
5117 + $print_mode === 'print overlay' &&
6671 5118 array_key_exists( 'multisite_override', $auth_settings ) &&
6672 - '1' === $auth_settings['multisite_override'] &&
6673 - ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) )
5119 + $auth_settings['multisite_override'] === '1' &&
5120 + ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' )
6674 5121 ) {
6675 5122 // Get original plugin options (not overridden value). We'll
6676 5123 // show this old value behind the disabled overlay.
6677 - // $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6678 - // (This feature is disabled).
6679 - //
5124 + $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
5125 +
6680 5126 $name = "auth_settings[$option]";
6681 - $id = "auth_settings_$option";
6682 - ?>
6683 - <div id="overlay-hide-auth_settings_<?php echo esc_attr( $option ); ?>" class="auth_multisite_override_overlay">
5127 + $id = "auth_settings_$option"; ?>
5128 + <div id="overlay-hide-auth_settings_<?php echo $option; ?>" class="auth_multisite_override_overlay">
6684 5129 <span class="overlay-note">
6685 - <?php esc_html_e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo esc_attr( network_admin_url( 'admin.php?page=authorizer' ) ); ?>"><?php esc_html_e( 'multisite option', 'authorizer' ); ?></a>.
5130 + <?php _e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo network_admin_url( 'admin.php?page=authorizer&tab=external' ); ?>"><?php _e( 'multisite option', 'authorizer' ); ?></a>.
6686 5131 </span>
6687 5132 </div>
6688 5133 <?php
6689 5134 }
@@ -6689,9 +5134,9 @@
6689 5134 }
6690 5135
6691 5136 // If we're getting an option in a site that has overridden the multisite override, make
6692 5137 // sure we are returning the option value from that site (not the multisite value).
6693 - if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && 1 === intval( $auth_settings['advanced_override_multisite'] ) ) {
5138 + if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && $auth_settings['advanced_override_multisite'] == '1' ) {
6694 5139 $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6695 5140 }
6696 5141
6697 5142 // Set option to null if it wasn't found.
@@ -6698,115 +5143,98 @@
6698 5143 if ( ! array_key_exists( $option, $auth_settings ) ) {
6699 5144 return null;
6700 5145 }
6701 5146
6702 - return $auth_settings[ $option ];
5147 + return $auth_settings[$option];
6703 5148 }
6704 5149
6705 5150 /**
6706 5151 * Retrieves all plugin options from db. Multisite enabled.
6707 5152 *
6708 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6709 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6710 - * @return mixed Option value, or null on failure.
5153 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5154 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5155 + * @return mixed Option value, or null on failure
6711 5156 */
6712 - private function get_plugin_options( $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override' ) {
6713 - // Grab plugin settings (skip if in WP_Plugin_Authorizer::NETWORK_CONTEXT mode).
6714 - $auth_settings = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings' );
5157 + private function get_plugin_options( $admin_mode = SINGLE_ADMIN, $override_mode = 'no override' ) {
5158 + // Grab plugin settings (skip if in MULTISITE_ADMIN mode).
5159 + $auth_settings = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings' );
6715 5160
6716 5161 // Initialize to default values if the plugin option doesn't exist.
6717 - if ( false === $auth_settings ) {
5162 + if ( $auth_settings === FALSE ) {
6718 5163 $auth_settings = $this->set_default_options();
6719 5164 }
6720 5165
6721 5166 // Merge multisite options if we're in a network and the current site hasn't overridden multisite settings.
6722 - if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) ) ) {
5167 + if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' ) ) {
6723 5168 // Get multisite options.
6724 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5169 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
6725 5170
6726 5171 // Return the multisite options if we're viewing the network admin options page.
6727 5172 // Otherwise override options with their multisite equivalents.
6728 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
5173 + if ( $admin_mode === MULTISITE_ADMIN ) {
6729 5174 $auth_settings = $auth_multisite_settings;
6730 5175 } elseif (
6731 - 'allow override' === $override_mode &&
5176 + $override_mode === 'allow override' &&
6732 5177 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
6733 - '1' === $auth_multisite_settings['multisite_override']
5178 + $auth_multisite_settings['multisite_override'] === '1'
6734 5179 ) {
6735 5180 // Keep track of the multisite override selection.
6736 5181 $auth_settings['multisite_override'] = $auth_multisite_settings['multisite_override'];
6737 5182
6738 - /**
6739 - * Note: the options below should be the complete list of overridden
6740 - * options. It is *not* the complete list of all options (some options
6741 - * don't have a multisite equivalent).
6742 - */
5183 + // Note: the options below should be the complete list of
5184 + // overridden options. It is *not* the complete list of all
5185 + // options (some options don't have a multisite equivalent)
6743 5186
6744 - /**
6745 - * Note: access_users_approved, access_users_pending, and
6746 - * access_users_blocked do not get overridden. However, since
6747 - * access_users_approved has a multisite equivalent, you must retrieve
6748 - * them both seperately. This is done because the two lists should be
6749 - * treated differently.
6750 - *
6751 - * $approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6752 - * $ms_approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
6753 - */
5187 + // Note: access_users_approved, access_users_pending, and
5188 + // access_users_blocked do not get overridden. However,
5189 + // since access_users_approved has a multisite equivalent,
5190 + // you must retrieve them both seperately. This is done
5191 + // because the two lists should be treated differently.
5192 + // $approved_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5193 + // $ms_approved_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
6754 5194
6755 - // Override external services (google, cas, or ldap) and associated options.
6756 - $auth_settings['google'] = $auth_multisite_settings['google'];
6757 - $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
6758 - $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
6759 - $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
6760 - $auth_settings['cas'] = $auth_multisite_settings['cas'];
6761 - $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
6762 - $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
6763 - $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
6764 - $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
6765 - $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
6766 - $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
6767 - $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
6768 - $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
6769 - $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
6770 - $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
6771 - $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
6772 - $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
6773 - $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
6774 - $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
6775 - $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
6776 - $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
6777 - $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
6778 - $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
6779 - $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
6780 - $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
6781 - $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
6782 - $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
5195 + // Override external services (google, cas, or ldap) and associated options
5196 + $auth_settings['google'] = $auth_multisite_settings['google'];
5197 + $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
5198 + $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
5199 + $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
5200 + $auth_settings['cas'] = $auth_multisite_settings['cas'];
5201 + $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
5202 + $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
5203 + $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
5204 + $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
5205 + $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
5206 + $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
5207 + $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
5208 + $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
5209 + $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
5210 + $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
5211 + $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
5212 + $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
5213 + $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
5214 + $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
5215 + $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
5216 + $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
5217 + $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
5218 + $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
5219 + $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
5220 + $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
5221 + $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
5222 + $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
6783 5223 $auth_settings['ldap_attr_update_on_login'] = $auth_multisite_settings['ldap_attr_update_on_login'];
6784 5224
6785 - // Override access_who_can_login and access_who_can_view.
5225 + // Override access_who_can_login and access_who_can_view
6786 5226 $auth_settings['access_who_can_login'] = $auth_multisite_settings['access_who_can_login'];
6787 - $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
5227 + $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
6788 5228
6789 - // Override access_default_role.
5229 + // Override access_default_role
6790 5230 $auth_settings['access_default_role'] = $auth_multisite_settings['access_default_role'];
6791 5231
6792 - // Override lockouts.
5232 + // Override lockouts
6793 5233 $auth_settings['advanced_lockouts'] = $auth_multisite_settings['advanced_lockouts'];
6794 5234
6795 - // Override Hide WordPress login.
5235 + // Override Hide WordPress login
6796 5236 $auth_settings['advanced_hide_wp_login'] = $auth_multisite_settings['advanced_hide_wp_login'];
6797 -
6798 - // Override Users per page.
6799 - $auth_settings['advanced_users_per_page'] = $auth_multisite_settings['advanced_users_per_page'];
6800 -
6801 - // Override Sort users by.
6802 - $auth_settings['advanced_users_sort_by'] = $auth_multisite_settings['advanced_users_sort_by'];
6803 -
6804 - // Override Sort users order.
6805 - $auth_settings['advanced_users_sort_order'] = $auth_multisite_settings['advanced_users_sort_order'];
6806 -
6807 - // Override Show Dashboard Widget.
6808 - $auth_settings['advanced_widget_enabled'] = $auth_multisite_settings['advanced_widget_enabled'];
6809 5237 }
6810 5238 }
6811 5239 return $auth_settings;
6812 5240 }
@@ -6813,27 +5241,23 @@
6813 5241
6814 5242
6815 5243 /**
6816 5244 * Remove user from authorizer lists when that user is deleted in WordPress.
6817 - *
6818 - * Action: delete_user
6819 - *
6820 - * @param int $user_id User ID to remove.
6821 - * @return void
5245 + * Run on action hook: delete_user
6822 5246 */
6823 - public function remove_user_from_authorizer_when_deleted( $user_id ) {
6824 - $user = get_user_by( 'id', $user_id );
5247 + function remove_user_from_authorizer_when_deleted( $user_id ) {
5248 + $user = get_user_by( 'id', $user_id );
6825 5249 $deleted_email = $user->user_email;
6826 5250
6827 5251 // Remove user from pending/approved lists and save.
6828 5252 $list_names = array( 'access_users_pending', 'access_users_approved' );
6829 5253 foreach ( $list_names as $list_name ) {
6830 - $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
5254 + $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, SINGLE_ADMIN ) );
6831 5255 $list_changed = false;
6832 5256 foreach ( $user_list as $key => $existing_user ) {
6833 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5257 + if ( $deleted_email === $existing_user['email'] ) {
6834 5258 $list_changed = true;
6835 - unset( $user_list[ $key ] );
5259 + unset( $user_list[$key] );
6836 5260 }
6837 5261 }
6838 5262 if ( $list_changed ) {
6839 5263 update_option( 'auth_settings_' . $list_name, $user_list );
@@ -6843,35 +5267,30 @@
6843 5267
6844 5268
6845 5269 /**
6846 5270 * Remove multisite user from authorizer lists when that user is deleted from Network Users.
6847 - *
6848 - * Action: wpmu_delete_user
6849 - *
6850 - * @param int $user_id User ID to remove.
6851 - * @return void
5271 + * Run on action hook: wpmu_delete_user
6852 5272 */
6853 - public function remove_network_user_from_authorizer_when_deleted( $user_id ) {
6854 - $user = get_user_by( 'id', $user_id );
5273 + function remove_network_user_from_authorizer_when_deleted( $user_id ) {
5274 + $user = get_user_by( 'id', $user_id );
6855 5275 $deleted_email = $user->user_email;
6856 5276
6857 5277 // Go through multisite approved user list and remove this user.
6858 5278 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6859 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5279 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6860 5280 );
6861 - $list_changed = false;
5281 + $list_changed = false;
6862 5282 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6863 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5283 + if ( $deleted_email === $existing_user['email'] ) {
6864 5284 $list_changed = true;
6865 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5285 + unset( $auth_multisite_settings_access_users_approved[$key] );
6866 5286 }
6867 5287 }
6868 5288 if ( $list_changed ) {
6869 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5289 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6870 5290 }
6871 5291
6872 5292 // Go through all pending/approved lists on individual sites and remove this user from them.
6873 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6874 5293 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6875 5294 foreach ( $sites as $site ) {
6876 5295 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6877 5296 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -6881,27 +5300,22 @@
6881 5300
6882 5301
6883 5302 /**
6884 5303 * Remove multisite user from a specific site's lists when that user is removed from the site.
6885 - *
6886 - * Action: remove_user_from_blog
6887 - *
6888 - * @param int $user_id User ID to remove.
6889 - * @param int $blog_id Blog ID to remove from.
6890 - * @return void
5304 + * Run on action hook: remove_user_from_blog
6891 5305 */
6892 - public function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
6893 - $user = get_user_by( 'id', $user_id );
5306 + function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
5307 + $user = get_user_by( 'id', $user_id );
6894 5308 $deleted_email = $user->user_email;
6895 5309
6896 5310 $list_names = array( 'access_users_pending', 'access_users_approved' );
6897 5311 foreach ( $list_names as $list_name ) {
6898 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
5312 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6899 5313 $list_changed = false;
6900 5314 foreach ( $user_list as $key => $existing_user ) {
6901 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5315 + if ( $deleted_email === $existing_user['email'] ) {
6902 5316 $list_changed = true;
6903 - unset( $user_list[ $key ] );
5317 + unset( $user_list[$key] );
6904 5318 }
6905 5319 }
6906 5320 if ( $list_changed ) {
6907 5321 update_blog_option( $blog_id, 'auth_settings_' . $list_name, $user_list );
@@ -6911,30 +5325,26 @@
6911 5325
6912 5326
6913 5327 /**
6914 5328 * Helper: Add multisite user to a specific site's approved list.
6915 - *
6916 - * @param int $user_id User ID to add.
6917 - * @param int $blog_id Blog ID to add to.
6918 - * @return void
6919 5329 */
6920 - private function add_network_user_to_site( $user_id, $blog_id ) {
5330 + function add_network_user_to_site( $user_id, $blog_id ) {
6921 5331 // Switch to blog.
6922 5332 switch_to_blog( $blog_id );
6923 5333
6924 5334 // Get user details and role.
6925 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
6926 - $user = get_user_by( 'id', $user_id );
6927 - $user_email = $user->user_email;
6928 - $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
5335 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
5336 + $user = get_user_by( 'id', $user_id );
5337 + $user_email = $user->user_email;
5338 + $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
6929 5339
6930 5340 // Add user to approved list if not already there and not in blocked list.
6931 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6932 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5341 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5342 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
6933 5343 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) && ! $this->in_multi_array( $user_email, $auth_settings_access_users_blocked ) ) {
6934 5344 $approved_user = array(
6935 - 'email' => $this->lowercase( $user_email ),
6936 - 'role' => $user_role,
5345 + 'email' => $user_email,
5346 + 'role' => $user_role,
6937 5347 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
6938 5348 'local_user' => true,
6939 5349 );
6940 5350 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -6951,17 +5361,17 @@
6951 5361 * When an existing user is invited to the current site (or a new user is created),
6952 5362 * add them to the authorizer approved list. This action fires when the admin
6953 5363 * doesn't select the "Skip Confirmation Email" option.
6954 5364 *
6955 - * Action: invite_user
5365 + * @action invite_user
6956 5366 *
6957 - * @param int $user_id The invited user's ID.
6958 - * @param array $role The role of the invited user (or none if a new user creation).
5367 + * @param int $user_id The invited user's ID.
5368 + * @param array $role The role of the invited user (or none if a new user creation).
6959 5369 * @param string $newuser_key The key of the invitation.
6960 5370 */
6961 - public function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
5371 + function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
6962 5372 $user = get_user_by( 'id', $user_id );
6963 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles, $role );
5373 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles, $role );
6964 5374 }
6965 5375
6966 5376
6967 5377 /**
@@ -6969,16 +5379,16 @@
6969 5379 * When an existing user is invited to the current site (or a new user is created),
6970 5380 * add them to the authorizer approved list. This action fires when the admin
6971 5381 * selects the "Skip Confirmation Email" option.
6972 5382 *
6973 - * Action: added_existing_user
5383 + * @action added_existing_user
6974 5384 *
6975 - * @param int $user_id The invited user's ID.
6976 - * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
5385 + * @param int $user_id The invited user's ID.
5386 + * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
6977 5387 */
6978 - public function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
5388 + function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
6979 5389 $user = get_user_by( 'id', $user_id );
6980 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5390 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
6981 5391 }
6982 5392
6983 5393
6984 5394 /**
@@ -6985,18 +5395,17 @@
6985 5395 * Multisite:
6986 5396 * When a new user is invited to the current site (or a new user is created),
6987 5397 * add them to the authorizer approved list.
6988 5398 *
6989 - * Action: after_signup_user
5399 + * @action after_signup_user
6990 5400 *
6991 - * @param string $user User's requested login name.
5401 + * @param string $user User's requested login name.
6992 5402 * @param string $user_email User's email address.
6993 - * @param string $key User's activation key.
6994 - * @param array $meta Additional signup meta, including initially set roles.
5403 + * @param string $key User's activation key.
5404 + * @param array $meta Additional signup meta.
6995 5405 */
6996 - public function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
6997 - $user_roles = isset( $meta['new_role'] ) ? array( $meta['new_role'] ) : array();
6998 - $this->add_user_to_authorizer_when_created( $user_email, time(), $user_roles );
5406 + function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
5407 + $this->add_user_to_authorizer_when_created( $user_email, time() );
6999 5408 }
7000 5409
7001 5410
7002 5411 /**
@@ -7003,18 +5412,17 @@
7003 5412 * Single site:
7004 5413 * When a new user is added in single site mode, add them to the authorizer
7005 5414 * approved list.
7006 5415 *
7007 - * Action: edit_user_created_user
5416 + * @action edit_user_created_user
7008 5417 *
7009 - * @param int $user_id ID of the newly created user.
7010 - * @param string $notify Type of notification that should happen. See
7011 - * wp_send_new_user_notifications() for more
7012 - * information on possible values.
5418 + * @param int $user_id ID of the newly created user.
5419 + * @param string $notify Type of notification that should happen. See wp_send_new_user_notifications()
5420 + * for more information on possible values.
7013 5421 */
7014 - public function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
5422 + function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
7015 5423 $user = get_user_by( 'id', $user_id );
7016 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5424 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
7017 5425 }
7018 5426
7019 5427
7020 5428 /**
@@ -7019,36 +5427,20 @@
7019 5427
7020 5428 /**
7021 5429 * Helper: When a new user is added/invited to the current site (or a new
7022 5430 * user is created), add them to the authorizer approved list.
7023 - *
7024 - * @param string $user_email Email address of user to add.
7025 - * @param string $date_registered Date user registered.
7026 - * @param array $user_roles Role to add for user.
7027 - * @param array $default_role Default role, if no role specified.
7028 5431 */
7029 5432 private function add_user_to_authorizer_when_created( $user_email, $date_registered, $user_roles = array(), $default_role = array() ) {
7030 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
7031 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7032 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7033 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5433 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
5434 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5435 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5436 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
7034 5437
7035 5438 // Get default role if one isn't specified.
7036 5439 if ( count( $default_role ) < 1 ) {
7037 5440 $default_role = '';
7038 5441 } else {
7039 - // If default role was provided, it came from the invite_user hook, and
7040 - // only contains the role's display name. Here we look up the actual role
7041 - // name to save (and default to no role if the display name isn't found).
7042 - global $wp_roles;
7043 - $default_role_display_name = $default_role['name'];
7044 - $default_role = '';
7045 - foreach ( $wp_roles->role_names as $role_name => $display_name ) {
7046 - if ( $default_role_display_name === $display_name ) {
7047 - $default_role = $role_name;
7048 - break;
7049 - }
7050 - }
5442 + $default_role = strtolower( $default_role['name'] );
7051 5443 }
7052 5444
7053 5445 $updated = false;
7054 5446
@@ -7057,10 +5449,10 @@
7057 5449 return;
7058 5450 }
7059 5451 // Remove from pending list if there.
7060 5452 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
7061 - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
7062 - unset( $auth_settings_access_users_pending[ $key ] );
5453 + if ( $pending_user['email'] == $user_email ) {
5454 + unset( $auth_settings_access_users_pending[$key] );
7063 5455 $updated = true;
7064 5456 }
7065 5457 }
7066 5458 // Skip if user is in multisite approved list.
@@ -7069,10 +5461,10 @@
7069 5461 }
7070 5462 // Add to approved list if not there.
7071 5463 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) ) {
7072 5464 $approved_user = array(
7073 - 'email' => $this->lowercase( $user_email ),
7074 - 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
5465 + 'email' => $user_email,
5466 + 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
7075 5467 'date_added' => date( 'M Y', strtotime( $date_registered ) ),
7076 5468 'local_user' => true,
7077 5469 );
7078 5470 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -7091,33 +5483,32 @@
7091 5483 * When a user is granted super admin status (checkbox on network user edit
7092 5484 * screen), add them to the authorizer network approved list. Also remove
7093 5485 * them from pending/approved list on any individual sites.
7094 5486 *
7095 - * Action: grant_super_admin
5487 + * @action grant_super_admin
7096 5488 *
7097 5489 * @param int $user_id The user's ID.
7098 5490 */
7099 - public function grant_super_admin__add_to_network_approved( $user_id ) {
7100 - $user = get_user_by( 'id', $user_id );
5491 + function grant_super_admin__add_to_network_approved( $user_id ) {
5492 + $user = get_user_by( 'id', $user_id );
7101 5493 $user_email = $user->user_email;
7102 5494
7103 5495 // Add user to multisite approved user list (if not already there).
7104 5496 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7105 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5497 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7106 5498 );
7107 5499 if ( ! $this->in_multi_array( $user_email, $auth_multisite_settings_access_users_approved ) ) {
7108 5500 $multisite_approved_user = array(
7109 - 'email' => $this->lowercase( $user_email ),
7110 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
5501 + 'email' => $user_email,
5502 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
7111 5503 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
7112 5504 'local_user' => true,
7113 5505 );
7114 5506 array_push( $auth_multisite_settings_access_users_approved, $multisite_approved_user );
7115 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5507 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7116 5508 }
7117 5509
7118 5510 // Go through all pending/approved lists on individual sites and remove this user from them.
7119 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7120 5511 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7121 5512 foreach ( $sites as $site ) {
7122 5513 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7123 5514 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -7130,29 +5521,29 @@
7130 5521 * When a user's super admin status is revoked (checkbox on network user edit
7131 5522 * screen), remove them from the authorizer network approved list. Also add
7132 5523 * them to approved list on any individual sites they are already a part of.
7133 5524 *
7134 - * Action: revoke_super_admin
5525 + * @action revoke_super_admin
7135 5526 *
7136 5527 * @param int $user_id The user's ID.
7137 5528 */
7138 - public function revoke_super_admin__remove_from_network_approved( $user_id ) {
7139 - $user = get_user_by( 'id', $user_id );
5529 + function revoke_super_admin__remove_from_network_approved( $user_id ) {
5530 + $user = get_user_by( 'id', $user_id );
7140 5531 $revoked_email = $user->user_email;
7141 5532
7142 5533 // Go through multisite approved user list and remove this user.
7143 5534 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7144 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5535 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7145 5536 );
7146 - $list_changed = false;
5537 + $list_changed = false;
7147 5538 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
7148 - if ( 0 === strcasecmp( $revoked_email, $existing_user['email'] ) ) {
5539 + if ( $revoked_email === $existing_user['email'] ) {
7149 5540 $list_changed = true;
7150 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5541 + unset( $auth_multisite_settings_access_users_approved[$key] );
7151 5542 }
7152 5543 }
7153 5544 if ( $list_changed ) {
7154 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5545 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7155 5546 }
7156 5547
7157 5548 // Go through this user's current sites and add them to the approved list
7158 5549 // (since they are no longer on the network approved list).
@@ -7163,21 +5554,14 @@
7163 5554 }
7164 5555
7165 5556 }
7166 5557
7167 - /**
7168 - * Send a welcome email message to a newly approved user (if the "Should
7169 - * email approved users" setting is enabled).
7170 - *
7171 - * @param string $email Email address to send welcome email to.
7172 - * @return bool Whether the email was sent.
7173 - */
7174 5558 private function maybe_email_welcome_message( $email ) {
7175 5559 // Get option for whether to email welcome messages.
7176 5560 $should_email_new_approved_users = $this->get_plugin_option( 'access_should_email_approved_users' );
7177 5561
7178 5562 // Do not send welcome email if option not enabled.
7179 - if ( '1' !== $should_email_new_approved_users ) {
5563 + if ( $should_email_new_approved_users !== '1' ) {
7180 5564 return false;
7181 5565 }
7182 5566
7183 5567 // Make sure we didn't just email this user (can happen with
@@ -7183,15 +5567,15 @@
7183 5567 // Make sure we didn't just email this user (can happen with
7184 5568 // multiple admins saving at the same time, or by clicking
7185 5569 // Approve button too rapidly).
7186 5570 $recently_sent_emails = get_option( 'auth_settings_recently_sent_emails' );
7187 - if ( false === $recently_sent_emails ) {
5571 + if ( $recently_sent_emails === FALSE ) {
7188 5572 $recently_sent_emails = array();
7189 5573 }
7190 5574 foreach ( $recently_sent_emails as $key => $recently_sent_email ) {
7191 5575 if ( $recently_sent_email['time'] < strtotime( 'now -1 minutes' ) ) {
7192 5576 // Remove emails sent more than 1 minute ago.
7193 - unset( $recently_sent_emails[ $key ] );
5577 + unset( $recently_sent_emails[$key] );
7194 5578 } elseif ( $recently_sent_email['email'] === $email ) {
7195 5579 // Sent an email to this user within the last 1 minute, so
7196 5580 // quit without sending.
7197 5581 return false;
@@ -7199,15 +5583,15 @@
7199 5583 }
7200 5584 // Add the email we're about to send to the list.
7201 5585 $recently_sent_emails[] = array(
7202 5586 'email' => $email,
7203 - 'time' => time(),
5587 + 'time' => time(),
7204 5588 );
7205 5589 update_option( 'auth_settings_recently_sent_emails', $recently_sent_emails );
7206 5590
7207 - // Get welcome email subject and body text.
5591 + // Get welcome email subject and body text
7208 5592 $subject = $this->get_plugin_option( 'access_email_approved_users_subject' );
7209 - $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
5593 + $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
7210 5594
7211 5595 // Fail if the subject/body options don't exist or are empty.
7212 5596 if ( is_null( $subject ) || is_null( $body ) || strlen( $subject ) === 0 || strlen( $body ) === 0 ) {
7213 5597 return false;
@@ -7214,14 +5598,14 @@
7214 5598 }
7215 5599
7216 5600 // Replace approved shortcode patterns in subject and body.
7217 5601 $site_name = get_bloginfo( 'name' );
7218 - $site_url = get_site_url();
7219 - $subject = str_replace( '[site_name]', $site_name, $subject );
7220 - $body = str_replace( '[site_name]', $site_name, $body );
7221 - $body = str_replace( '[site_url]', $site_url, $body );
7222 - $body = str_replace( '[user_email]', $email, $body );
7223 - $headers = 'Content-type: text/html' . "\r\n";
5602 + $site_url = get_site_url();
5603 + $subject = str_replace( '[site_name]', $site_name, $subject );
5604 + $body = str_replace( '[site_name]', $site_name, $body );
5605 + $body = str_replace( '[site_url]', $site_url, $body );
5606 + $body = str_replace( '[user_email]', $email, $body );
5607 + $headers = 'Content-type: text/html' . "\r\n";
7224 5608
7225 5609 // Send email.
7226 5610 wp_mail( $email, $subject, $body, $headers );
7227 5611
@@ -7231,22 +5615,14 @@
7231 5615
7232 5616
7233 5617 /**
7234 5618 * Generate a unique cookie to add to nonces to prevent CSRF.
7235 - *
7236 - * @var string
7237 5619 */
7238 - private $cookie_value = null;
7239 -
7240 - /**
7241 - * Retrieve the unique login cookie.
7242 - *
7243 - * @return string Login cookie value.
7244 - */
7245 - private function get_cookie_value() {
5620 + protected $cookie_value = null;
5621 + function get_cookie_value() {
7246 5622 if ( ! $this->cookie_value ) {
7247 5623 if ( isset( $_COOKIE['login_unique'] ) ) {
7248 - $this->cookie_value = sanitize_key( wp_unslash( $_COOKIE['login_unique'] ) );
5624 + $this->cookie_value = $_COOKIE['login_unique'];
7249 5625 } else {
7250 5626 $this->cookie_value = md5( rand() );
7251 5627 }
7252 5628 }
@@ -7254,51 +5630,37 @@
7254 5630 }
7255 5631
7256 5632
7257 5633 /**
7258 - * Encryption key (not secret!).
7259 - *
7260 - * @var string
7261 - */
7262 - private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
7263 -
7264 - /**
7265 - * Encryption salt (not secret!).
7266 - *
7267 - * @var string
7268 - */
7269 - private static $iv = 'R_O2D]jPn]1[fhJl!-P1.oe';
7270 -
7271 - /**
7272 5634 * Basic encryption using a public (not secret!) key. Used for general
7273 5635 * database obfuscation of passwords.
7274 - *
7275 - * @param string $text String to encrypt.
7276 - * @param string $library Encryption library to use (openssl).
7277 - * @return string Encrypted string.
5636 + * @param $text String to encrypt.
5637 + * @param $library Encryption lib to use (openssl).
5638 + * @return Encrypted string
7278 5639 */
7279 - private function encrypt( $text, $library = 'openssl' ) {
5640 + private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
5641 + private static $iv = "R_O2D]jPn]1[fhJl!-P1.oe";
5642 + function encrypt( $text, $library = 'openssl' ) {
7280 5643 $result = '';
7281 5644
7282 5645 // Use openssl library (better) if it is enabled.
7283 - if ( function_exists( 'openssl_encrypt' ) && 'openssl' === $library ) {
7284 - $result = base64_encode(
7285 - openssl_encrypt(
7286 - $text,
7287 - 'AES-256-CBC',
7288 - hash( 'sha256', self::$key ),
7289 - 0,
7290 - substr( hash( 'sha256', self::$iv ), 0, 16 )
7291 - )
7292 - );
7293 - } elseif ( function_exists( 'mcrypt_encrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5646 + if ( function_exists( 'openssl_encrypt' ) && $library === 'openssl' ) {
5647 + $result = base64_encode( openssl_encrypt(
5648 + $text,
5649 + 'AES-256-CBC',
5650 + hash( 'sha256', self::$key ),
5651 + 0,
5652 + substr( hash( 'sha256', self::$iv ), 0, 16 )
5653 + ) );
5654 + // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5655 + } else if ( function_exists( 'mcrypt_encrypt' ) ) {
7294 5656 $result = base64_encode( mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ) );
7295 - } else { // Fall back to basic obfuscation.
7296 - $length = strlen( $text );
7297 - for ( $i = 0; $i < $length; $i++ ) {
7298 - $char = substr( $text, $i, 1 );
5657 + // Fall back to basic obfuscation.
5658 + } else {
5659 + for ( $i = 0; $i < strlen( $text ); $i++ ) {
5660 + $char = substr( $text, $i, 1 );
7299 5661 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7300 - $char = chr( ord( $char ) + ord( $keychar ) );
5662 + $char = chr( ord( $char ) + ord( $keychar ) );
7301 5663 $result .= $char;
7302 5664 }
7303 5665 $result = base64_encode( $result );
7304 5666 }
@@ -7309,18 +5671,17 @@
7309 5671
7310 5672 /**
7311 5673 * Basic decryption using a public (not secret!) key. Used for general
7312 5674 * database obfuscation of passwords.
7313 - *
7314 - * @param string $secret String to encrypt.
7315 - * @param string $library Encryption lib to use (openssl).
7316 - * @return string Decrypted string
5675 + * @param $text String to encrypt.
5676 + * @param $library Encryption lib to use (openssl).
5677 + * @return Decrypted string
7317 5678 */
7318 - private function decrypt( $secret, $library = 'openssl' ) {
5679 + function decrypt( $secret, $library = 'openssl' ) {
7319 5680 $result = '';
7320 5681
7321 5682 // Use openssl library (better) if it is enabled.
7322 - if ( function_exists( 'openssl_decrypt' ) && 'openssl' === $library ) {
5683 + if ( function_exists( 'openssl_decrypt' ) && $library === 'openssl' ) {
7323 5684 $result = openssl_decrypt(
7324 5685 base64_decode( $secret ),
7325 5686 'AES-256-CBC',
7326 5687 hash( 'sha256', self::$key ),
@@ -7326,18 +5687,19 @@
7326 5687 hash( 'sha256', self::$key ),
7327 5688 0,
7328 5689 substr( hash( 'sha256', self::$iv ), 0, 16 )
7329 5690 );
7330 - } elseif ( function_exists( 'mcrypt_decrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5691 + // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5692 + } else if ( function_exists( 'mcrypt_decrypt' ) ) {
7331 5693 $secret = base64_decode( $secret );
7332 5694 $result = rtrim( mcrypt_decrypt( MCRYPT_RIJNDAEL_256, self::$key, $secret, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ), "\0$result" );
7333 - } else { // Fall back to basic obfuscation.
5695 + // Fall back to basic obfuscation.
5696 + } else {
7334 5697 $secret = base64_decode( $secret );
7335 - $length = strlen( $secret );
7336 - for ( $i = 0; $i < $length; $i++ ) {
7337 - $char = substr( $secret, $i, 1 );
5698 + for ( $i = 0; $i < strlen( $secret ); $i++ ) {
5699 + $char = substr( $secret, $i, 1 );
7338 5700 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7339 - $char = chr( ord( $char ) - ord( $keychar ) );
5701 + $char = chr( ord( $char ) - ord( $keychar ) );
7340 5702 $result .= $char;
7341 5703 }
7342 5704 }
7343 5705
@@ -7348,12 +5710,10 @@
7348 5710 /**
7349 5711 * In a multisite environment, returns true if the current user is logged
7350 5712 * in and a user of the current blog. In single site mode, simply returns
7351 5713 * true if the current user is logged in.
7352 - *
7353 - * @return bool Whether current user is logged in and a user of the current blog.
7354 5714 */
7355 - protected function is_user_logged_in_and_blog_user() {
5715 + function is_user_logged_in_and_blog_user() {
7356 5716 $is_user_logged_in_and_blog_user = false;
7357 5717 if ( is_multisite() ) {
7358 5718 $is_user_logged_in_and_blog_user = is_user_logged_in() && is_user_member_of_blog( get_current_user_id() );
7359 5719 } else {
@@ -7366,57 +5726,39 @@
7366 5726 /**
7367 5727 * Helper function to determine whether a given email is in one of
7368 5728 * the lists (pending, approved, blocked). Defaults to the list of
7369 5729 * approved users.
7370 - *
7371 - * @param string $email Email to check existent of.
7372 - * @param string $list List to look for email in.
7373 - * @param string $multisite_mode Admin context.
7374 - * @return boolean Whether email was found.
7375 5730 */
7376 - protected function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
7377 - if ( empty( $email ) ) {
5731 + function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
5732 + if ( empty( $email ) )
7378 5733 return false;
7379 - }
7380 5734
7381 5735 switch ( $list ) {
7382 - case 'pending':
7383 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7384 - return $this->in_multi_array( $email, $auth_settings_access_users_pending );
7385 - case 'blocked':
7386 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7387 - // Blocked list can have wildcard matches, e.g., @baddomain.com, which
7388 - // should match any email address at that domain. Check if any wildcards
7389 - // exist, and if the email address has that domain.
7390 - $email_in_blocked_domain = false;
7391 - $blocked_domains = preg_grep( '/^@.*/', array_map(
7392 - function ( $blocked_item ) { return $blocked_item['email']; },
7393 - $auth_settings_access_users_blocked
7394 - ) );
7395 - foreach ( $blocked_domains as $blocked_domain ) {
7396 - $email_domain = substr( $email, strrpos( $email, '@' ) );
7397 - if ( $email_domain === $blocked_domain ) {
7398 - $email_in_blocked_domain = true;
7399 - break;
7400 - }
7401 - }
7402 - return $email_in_blocked_domain || $this->in_multi_array( $email, $auth_settings_access_users_blocked );
7403 - case 'approved':
7404 - default:
7405 - if ( 'single' !== $multisite_mode ) {
7406 - // Get multisite users only.
7407 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7408 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7409 - // This site has overridden any multisite settings, so only get its users.
7410 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7411 - } else {
7412 - // Get all site users and all multisite users.
7413 - $auth_settings_access_users_approved = array_merge(
7414 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7415 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7416 - );
7417 - }
7418 - return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5736 + case 'pending':
5737 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5738 + return $this->in_multi_array( $email, $auth_settings_access_users_pending );
5739 + break;
5740 + case 'blocked':
5741 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5742 + return $this->in_multi_array( $email, $auth_settings_access_users_blocked );
5743 + break;
5744 + case 'approved':
5745 + default:
5746 + if ( $multisite_mode !== 'single' ) {
5747 + // Get multisite users only.
5748 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5749 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5750 + // This site has overridden any multisite settings, so only get its users.
5751 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5752 + } else {
5753 + // Get all site users and all multisite users.
5754 + $auth_settings_access_users_approved = array_merge(
5755 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5756 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5757 + );
5758 + }
5759 + return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5760 + break;
7419 5761 }
7420 5762 }
7421 5763
7422 5764
@@ -7422,37 +5764,36 @@
7422 5764
7423 5765 /**
7424 5766 * Helper function to get number of users (including multisite users)
7425 5767 * in a given list (pending, approved, or blocked).
7426 - *
7427 - * @param string $list List to get count of.
7428 - * @param string $admin_mode WP_Plugin_Authorizer::SINGLE_CONTEXT or WP_Plugin_Authorizer::NETWORK_CONTEXT determines whether to include multisite users.
7429 - * @return int Number of users in list.
5768 + * @param string $list
5769 + * @param string $admin_mode SINGLE_ADMIN or MULTISITE_ADMIN determines whether to include multisite users
5770 + * @return int number of users in list
7430 5771 */
7431 - protected function get_user_count_from_list( $list, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
5772 + function get_user_count_from_list( $list, $admin_mode = SINGLE_ADMIN ) {
7432 5773 $auth_settings_access_users = array();
7433 5774
7434 5775 switch ( $list ) {
7435 - case 'pending':
7436 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7437 - break;
7438 - case 'blocked':
7439 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7440 - break;
7441 - case 'approved':
7442 - if ( WP_Plugin_Authorizer::SINGLE_CONTEXT !== $admin_mode ) {
7443 - // Get multisite users only.
7444 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7445 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7446 - // This site has overridden any multisite settings, so only get its users.
7447 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7448 - } else {
7449 - // Get all site users and all multisite users.
7450 - $auth_settings_access_users = array_merge(
7451 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7452 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7453 - );
7454 - }
5776 + case 'pending':
5777 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5778 + break;
5779 + case 'blocked':
5780 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5781 + break;
5782 + case 'approved':
5783 + if ( $admin_mode !== SINGLE_ADMIN ) {
5784 + // Get multisite users only.
5785 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5786 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5787 + // This site has overridden any multisite settings, so only get its users.
5788 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5789 + } else {
5790 + // Get all site users and all multisite users.
5791 + $auth_settings_access_users = array_merge(
5792 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5793 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5794 + );
5795 + }
7455 5796 }
7456 5797
7457 5798 return count( $auth_settings_access_users );
7458 5799 }
@@ -7459,27 +5800,21 @@
7459 5800
7460 5801
7461 5802 /**
7462 5803 * Helper function to search a multidimensional array for a value.
7463 - *
7464 - * @param string $needle Value to search for.
7465 - * @param array $haystack Multidimensional array to search.
7466 - * @param string $strict_mode 'strict' if strict comparisons should be used.
7467 - * @param string $case_sensitivity 'case sensitive' if comparisons should respect case.
7468 - * @return bool Whether needle was found.
7469 5804 */
7470 - protected function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
5805 + function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
7471 5806 if ( ! is_array( $haystack ) ) {
7472 5807 return false;
7473 5808 }
7474 - if ( 'case insensitive' === $case_sensitivity ) {
5809 + if ( $case_sensitivity === 'case insensitive' ) {
7475 5810 $needle = strtolower( $needle );
7476 5811 }
7477 5812 foreach ( $haystack as $item ) {
7478 - if ( 'case insensitive' === $case_sensitivity && ! is_array( $item ) ) {
5813 + if ( $case_sensitivity === 'case insensitive' && ! is_array( $item ) ) {
7479 5814 $item = strtolower( $item );
7480 5815 }
7481 - if ( ( 'strict' === $strict_mode ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) { // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison
5816 + if ( ( $strict_mode === 'strict' ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) {
7482 5817 return true;
7483 5818 }
7484 5819 }
7485 5820 return false;
@@ -7488,29 +5823,28 @@
7488 5823
7489 5824 /**
7490 5825 * Helper function to determine if an URL is accessible.
7491 5826 *
7492 - * @param string $url URL that should be publicly reachable.
7493 - * @return boolean Whether the URL is publicly reachable.
5827 + * @param string $url URL that should be publicly reachable
5828 + * @return boolean Whether the URL is publicly reachable
7494 5829 */
7495 - protected function url_is_accessible( $url ) {
5830 + function url_is_accessible( $url ) {
7496 5831 // Use wp_remote_retrieve_response_code() to retrieve the URL.
7497 - $response = wp_remote_get( $url );
5832 + $response = wp_remote_get( $url );
7498 5833 $response_code = wp_remote_retrieve_response_code( $response );
7499 5834
7500 - // Return true if the document has loaded successfully without any redirection or error.
7501 - return $response_code >= 200 && $response_code < 400;
5835 + // Return true if the document has loaded successfully without any redirection or error
5836 + return $response_code >= 200 && $response_code < 300;
7502 5837 }
7503 5838
7504 5839
7505 5840 /**
7506 5841 * Helper function to reconstruct a URL split using parse_url().
7507 - *
7508 - * @param array $parts Array returned from parse_url().
7509 - * @return string URL.
5842 + * @param array $parts Array returned from parse_url().
5843 + * @return string URL.
7510 5844 */
7511 - protected function build_url( $parts = array() ) {
7512 - return (
5845 + function build_url( $parts = array() ) {
5846 + return
7513 5847 ( isset( $parts['scheme'] ) ? "{$parts['scheme']}:" : '' ) .
7514 5848 ( ( isset( $parts['user'] ) || isset( $parts['host'] ) ) ? '//' : '' ) .
7515 5849 ( isset( $parts['user'] ) ? "{$parts['user']}" : '' ) .
7516 5850 ( isset( $parts['pass'] ) ? ":{$parts['pass']}" : '' ) .
@@ -7518,30 +5852,21 @@
7518 5852 ( isset( $parts['host'] ) ? "{$parts['host']}" : '' ) .
7519 5853 ( isset( $parts['port'] ) ? ":{$parts['port']}" : '' ) .
7520 5854 ( isset( $parts['path'] ) ? "{$parts['path']}" : '' ) .
7521 5855 ( isset( $parts['query'] ) ? "?{$parts['query']}" : '' ) .
7522 - ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' )
7523 - );
5856 + ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' );
7524 5857 }
7525 5858
7526 5859
7527 - /**
7528 - * Helper function that prints option tags for a select element for all
7529 - * roles the current user has permission to assign.
7530 - *
7531 - * @param string $selected_role Which role should be selected in the dropdown.
7532 - * @param string $disable_input 'disabled' if select element should be disabled.
7533 - * @param int $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT if we are in that context.
7534 - * @return void
7535 - */
7536 - protected function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
7537 - $roles = get_editable_roles();
5860 + // Helper function that builds option tags for a select element for all
5861 + // roles the current user has permission to assign.
5862 + function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = SINGLE_ADMIN ) {
5863 + $roles = get_editable_roles();
7538 5864 $current_user = wp_get_current_user();
7539 5865
7540 5866 // If we're in network admin, also show any roles that might exist only on
7541 5867 // specific sites in the network (themes can add their own roles).
7542 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
7543 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
5868 + if ( $admin_mode === MULTISITE_ADMIN ) {
7544 5869 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7545 5870 foreach ( $sites as $site ) {
7546 5871 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7547 5872 switch_to_blog( $blog_id );
@@ -7550,11 +5875,11 @@
7550 5875 }
7551 5876 $unique_role_names = array();
7552 5877 foreach ( $roles as $role_name => $role_info ) {
7553 5878 if ( array_key_exists( $role_name, $unique_role_names ) ) {
7554 - unset( $roles[ $role_name ] );
5879 + unset( $roles[$role_name] );
7555 5880 } else {
7556 - $unique_role_names[ $role_name ] = true;
5881 + $unique_role_names[$role_name] = true;
7557 5882 }
7558 5883 }
7559 5884 }
7560 5885
@@ -7566,43 +5891,39 @@
7566 5891 }
7567 5892
7568 5893 // Print an option element for each permitted role.
7569 5894 foreach ( $roles as $name => $role ) {
7570 - $is_selected = $selected_role === $name;
5895 + $selected = $selected_role === $name ? ' selected="selected"' : '';
7571 5896
7572 - // Don't let a user change their own role (but network admins always can).
7573 - $is_disabled = $selected_role !== $name && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7574 - ?>
7575 - <option value="<?php echo esc_attr( $name ); ?>"<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php echo esc_html( $role['name'] ); ?></option>
7576 - <?php
5897 + // Don't let a user change their own role
5898 + $disabled = $selected_role !== $name && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5899 +
5900 + // But network admins can always change their role.
5901 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5902 + $disabled = '';
5903 + }
5904 +
5905 + ?><option value="<?php echo $name; ?>"<?php echo $selected . $disabled; ?>><?php echo $role['name']; ?></option><?php
7577 5906 }
7578 5907
7579 5908 // Print default role (no role).
7580 - $is_selected = strlen( $selected_role ) === 0 || ! array_key_exists( $selected_role, $roles );
7581 - $is_disabled = strlen( $selected_role ) > 0 && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7582 - ?>
7583 - <option value=""<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php esc_html_e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option>
7584 - <?php
5909 + $selected = strlen( $selected_role ) == 0 || ! array_key_exists( $selected_role, $roles ) ? ' selected="selected"' : '';
5910 + $disabled = strlen( $selected_role ) > 0 && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5911 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5912 + $disabled = '';
5913 + }
5914 + ?><option value=""<?php echo $selected . $disabled; ?>><?php _e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option><?php
7585 5915
7586 5916 }
7587 5917
7588 5918
7589 - /**
7590 - * Helper function to get a single user info array from one of the access
7591 - * control lists (pending, approved, or blocked).
7592 - *
7593 - * @param string $email Email address to retrieve info for.
7594 - * @param string $list List to get info from.
7595 - * @return mixed false if not found, otherwise: array(
7596 - * 'email' => '',
7597 - * 'role' => '',
7598 - * 'date_added' => '',
7599 - * ['usermeta' => [''|array()]]
7600 - * );
7601 - */
7602 - protected function get_user_info_from_list( $email, $list ) {
5919 + // Helper function to get a single user info array from one of the
5920 + // access control lists (pending, approved, or blocked).
5921 + // Returns: false if not found; otherwise
5922 + // array( 'email' => '', 'role' => '', 'date_added' => '', ['usermeta' => [''|array()]] );
5923 + function get_user_info_from_list( $email, $list ) {
7603 5924 foreach ( $list as $user_info ) {
7604 - if ( 0 === strcasecmp( $user_info['email'], $email ) ) {
5925 + if ( $user_info['email'] === $email ) {
7605 5926 return $user_info;
7606 5927 }
7607 5928 }
7608 5929 return false;
@@ -7607,49 +5928,29 @@
7607 5928 }
7608 5929 return false;
7609 5930 }
7610 5931
7611 - /**
7612 - * Helper function to convert a string to lowercase. Prefers to use mb_strtolower,
7613 - * but will fall back to strtolower if the former is not available.
7614 - *
7615 - * @param string $string String to convert to lowercase.
7616 - * @return string Input in lowercase.
7617 - */
7618 - protected function lowercase( $string ) {
7619 - return function_exists( 'mb_strtolower' ) ? mb_strtolower( $string ) : strtolower( $string );
7620 - }
7621 5932
7622 -
7623 - /**
7624 - * Helper function to convert seconds to human readable text.
7625 - *
7626 - * @see: http://csl.name/php-secs-to-human-text/
7627 - *
7628 - * @param int $secs Seconds to display as readable text.
7629 - * @return string Readable version of number of seconds.
7630 - */
7631 - protected function seconds_as_sentence( $secs ) {
5933 + // Helper function to convert seconds to human readable text.
5934 + // Source: http://csl.name/php-secs-to-human-text/
5935 + function seconds_as_sentence( $secs ) {
7632 5936 $units = array(
7633 - 'week' => 3600 * 24 * 7,
7634 - 'day' => 3600 * 24,
7635 - 'hour' => 3600,
7636 - 'minute' => 60,
7637 - 'second' => 1,
5937 + "week" => 7 * 24 * 3600,
5938 + "day" => 24 * 3600,
5939 + "hour" => 3600,
5940 + "minute" => 60,
5941 + "second" => 1,
7638 5942 );
7639 5943
7640 - // Specifically handle zero.
7641 - if ( 0 === intval( $secs ) ) {
7642 - return '0 seconds';
7643 - }
5944 + // specifically handle zero
5945 + if ( $secs == 0 ) return "0 seconds";
7644 5946
7645 - $s = '';
5947 + $s = "";
7646 5948
7647 5949 foreach ( $units as $name => $divisor ) {
7648 - $quot = intval( $secs / $divisor );
7649 - if ( $quot ) {
7650 - $s .= "$quot $name";
7651 - $s .= ( abs( $quot ) > 1 ? 's' : '' ) . ', ';
5950 + if ( $quot = intval( $secs / $divisor ) ) {
5951 + $s .= "$quot $name";
5952 + $s .= ( abs( $quot ) > 1 ? "s" : "" ) . ", ";
7652 5953 $secs -= $quot * $divisor;
7653 5954 }
7654 5955 }
7655 5956
@@ -7655,14 +5956,10 @@
7655 5956
7656 5957 return substr( $s, 0, -2 );
7657 5958 }
7658 5959
7659 - /**
7660 - * Helper function to get all available usermeta keys as an array.
7661 - *
7662 - * @return array All usermeta keys for user.
7663 - */
7664 - protected function get_all_usermeta_keys() {
5960 + // Helper function to get all available usermeta keys as an array.
5961 + function get_all_usermeta_keys() {
7665 5962 global $wpdb;
7666 5963 $usermeta_keys = $wpdb->get_col( "SELECT DISTINCT $wpdb->usermeta.meta_key FROM $wpdb->usermeta" );
7667 5964 return $usermeta_keys;
7668 5965 }
@@ -7669,12 +5966,10 @@
7669 5966
7670 5967
7671 5968 /**
7672 5969 * Load translated strings from *.mo files in /languages.
7673 - *
7674 - * Action: plugins_loaded
7675 5970 */
7676 - public function load_textdomain() {
5971 + function load_textdomain() {
7677 5972 load_plugin_textdomain(
7678 5973 'authorizer',
7679 5974 false,
7680 5975 plugin_basename( dirname( __FILE__ ) ) . '/languages'
@@ -7685,17 +5980,14 @@
7685 5980 /**
7686 5981 * Generate CAS authentication URL (wp-login.php URL with reauth=1 removed
7687 5982 * and external=cas added).
7688 5983 */
7689 - private function modify_current_url_for_cas_login() {
5984 + function modify_current_url_for_cas_login() {
7690 5985 // Construct the URL of the current page (wp-login.php).
7691 - $url = '';
7692 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
7693 - $url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
7694 - }
5986 + $url = 'http' . ( isset( $_SERVER['HTTPS'] ) ? 's' : '' ) . '://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
7695 5987
7696 5988 // Parse the URL into its components.
7697 - $parsed_url = wp_parse_url( $url );
5989 + $parsed_url = parse_url( $url );
7698 5990
7699 5991 // Fix up the querystring values (remove reauth, make sure external=cas).
7700 5992 $querystring = array();
7701 5993 if ( array_key_exists( 'query', $parsed_url ) ) {
@@ -7702,9 +5994,9 @@
7702 5994 parse_str( $parsed_url['query'], $querystring );
7703 5995 }
7704 5996 unset( $querystring['reauth'] );
7705 5997 $querystring['external'] = 'cas';
7706 - $parsed_url['query'] = http_build_query( $querystring );
5998 + $parsed_url['query'] = http_build_query( $querystring );
7707 5999
7708 6000 // Return the URL as a string.
7709 6001 return $this->unparse_url( $parsed_url );
7710 6002 }
@@ -7711,21 +6003,20 @@
7711 6003
7712 6004
7713 6005 /**
7714 6006 * Reconstruct a URL after it has been deconstructed with parse_url().
7715 - *
7716 - * @param array $parsed_url Keys from parse_url().
7717 - * @return string URL constructed from the components in $parsed_url.
6007 + * @param $parsed_url array() with keys from parse_url().
6008 + * @return string URL constructed from the components in $parsed_url.
7718 6009 */
7719 - protected function unparse_url( $parsed_url = array() ) {
7720 - $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
7721 - $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
7722 - $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
7723 - $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
7724 - $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
7725 - $pass = $user || $pass ? "$pass@" : '';
7726 - $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
7727 - $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
6010 + function unparse_url( $parsed_url = array() ) {
6011 + $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
6012 + $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
6013 + $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
6014 + $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
6015 + $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
6016 + $pass = $user || $pass ? "$pass@" : '';
6017 + $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
6018 + $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
7728 6019 $fragment = isset( $parsed_url['fragment'] ) ? '#' . $parsed_url['fragment'] : '';
7729 6020 return "$scheme$user$pass$host$port$path$query$fragment";
7730 6021 }
7731 6022
@@ -7730,30 +6021,15 @@
7730 6021 }
7731 6022
7732 6023
7733 6024 /**
7734 - * Helper function to generate an HTML class name for an option (used in
7735 - * Authorizer Settings in the Approved User list).
7736 - *
7737 - * @param string $suffix Unique part of class name.
7738 - * @param boolean $is_multisite_user Whether the class name should indicate it's a multisite user.
7739 - * @return string Class name, e.g., "auth-email auth-multisite-email".
7740 - */
7741 - private function create_class_name( $suffix = '', $is_multisite_user = false ) {
7742 - return $is_multisite_user ? "auth-$suffix auth-multisite-$suffix" : "auth-$suffix";
7743 - }
7744 -
7745 -
7746 - /**
7747 6025 * Plugin Update Routines.
7748 - *
7749 - * Action: plugins_loaded
7750 6026 */
7751 - public function auth_update_check() {
6027 + function auth_update_check() {
7752 6028 // Get current version.
7753 6029 $needs_updating = false;
7754 6030 if ( is_multisite() ) {
7755 - $auth_version = get_blog_option( $this->current_site_blog_id, 'auth_version' );
6031 + $auth_version = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_version' );
7756 6032 } else {
7757 6033 $auth_version = get_option( 'auth_version' );
7758 6034 }
7759 6035
@@ -7765,9 +6041,9 @@
7765 6041 // log in; approved and blocked lists are changed whenever an admin
7766 6042 // changes them from the multisite panel, the dashboard widget, or
7767 6043 // the plugin options page.
7768 6044 $update_if_older_than = 20140709;
7769 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6045 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7770 6046 // Copy single site user lists to new options (if they exist).
7771 6047 $auth_settings = get_option( 'auth_settings' );
7772 6048 if ( is_array( $auth_settings ) && array_key_exists( 'access_users_pending', $auth_settings ) ) {
7773 6049 update_option( 'auth_settings_access_users_pending', $auth_settings['access_users_pending'] );
@@ -7785,27 +6061,27 @@
7785 6061 update_option( 'auth_settings', $auth_settings );
7786 6062 }
7787 6063 // Copy multisite user lists to new options (if they exist).
7788 6064 if ( is_multisite() ) {
7789 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
6065 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7790 6066 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_pending', $auth_multisite_settings ) ) {
7791 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
6067 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
7792 6068 unset( $auth_multisite_settings['access_users_pending'] );
7793 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6069 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7794 6070 }
7795 6071 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_approved', $auth_multisite_settings ) ) {
7796 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
6072 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
7797 6073 unset( $auth_multisite_settings['access_users_approved'] );
7798 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6074 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7799 6075 }
7800 6076 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_blocked', $auth_multisite_settings ) ) {
7801 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
6077 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
7802 6078 unset( $auth_multisite_settings['access_users_blocked'] );
7803 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6079 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7804 6080 }
7805 6081 }
7806 6082 // Update version to reflect this change has been made.
7807 - $auth_version = $update_if_older_than;
6083 + $auth_version = $update_if_older_than;
7808 6084 $needs_updating = true;
7809 6085 }
7810 6086
7811 6087 // Update: Set default values for newly added options (forgot to do
@@ -7811,13 +6087,12 @@
7811 6087 // Update: Set default values for newly added options (forgot to do
7812 6088 // this, so some users are getting debug log notices about undefined
7813 6089 // indexes in $auth_settings).
7814 6090 $update_if_older_than = 20160831;
7815 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6091 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7816 6092 // Provide default values for any $auth_settings options that don't exist.
7817 6093 if ( is_multisite() ) {
7818 - // Get all blog ids.
7819 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6094 + // Get all blog ids
7820 6095 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7821 6096 foreach ( $sites as $site ) {
7822 6097 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7823 6098 switch_to_blog( $blog_id );
@@ -7822,9 +6097,9 @@
7822 6097 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7823 6098 switch_to_blog( $blog_id );
7824 6099 // Set meaningful defaults for other sites in the network.
7825 6100 $this->set_default_options();
7826 - // Switch back to original blog.
6101 + // Switch back to original blog. See: https://codex.wordpress.org/Function_Reference/restore_current_blog
7827 6102 restore_current_blog();
7828 6103 }
7829 6104 } else {
7830 6105 // Set meaningful defaults for this site.
@@ -7830,9 +6105,9 @@
7830 6105 // Set meaningful defaults for this site.
7831 6106 $this->set_default_options();
7832 6107 }
7833 6108 // Update version to reflect this change has been made.
7834 - $auth_version = $update_if_older_than;
6109 + $auth_version = $update_if_older_than;
7835 6110 $needs_updating = true;
7836 6111 }
7837 6112
7838 6113 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
@@ -7837,18 +6112,17 @@
7837 6112
7838 6113 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7839 6114 // deprecated as of PHP 7.1. Use openssl library instead.
7840 6115 $update_if_older_than = 20170510;
7841 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6116 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7842 6117 if ( is_multisite() ) {
7843 6118 // Reencrypt LDAP passwords in each site in the network.
7844 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7845 6119 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7846 6120 foreach ( $sites as $site ) {
7847 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6121 + $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7848 6122 $auth_settings = get_blog_option( $blog_id, 'auth_settings', array() );
7849 6123 if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7850 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
6124 + $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7851 6125 $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7852 6126 update_blog_option( $blog_id, 'auth_settings', $auth_settings );
7853 6127 }
7854 6128 }
@@ -7855,15 +6129,15 @@
7855 6129 } else {
7856 6130 // Reencrypt LDAP password on this single-site install.
7857 6131 $auth_settings = get_option( 'auth_settings', array() );
7858 6132 if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7859 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
6133 + $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7860 6134 $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7861 6135 update_option( 'auth_settings', $auth_settings );
7862 6136 }
7863 6137 }
7864 6138 // Update version to reflect this change has been made.
7865 - $auth_version = $update_if_older_than;
6139 + $auth_version = $update_if_older_than;
7866 6140 $needs_updating = true;
7867 6141 }
7868 6142
7869 6143 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
@@ -7869,171 +6143,35 @@
7869 6143 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7870 6144 // deprecated as of PHP 7.1. Use openssl library instead.
7871 6145 // Note: Forgot to update the auth_multisite_settings ldap password! Do it here.
7872 6146 $update_if_older_than = 20170511;
7873 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6147 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7874 6148 if ( is_multisite() ) {
7875 6149 // Reencrypt LDAP password in network (multisite) options.
7876 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
6150 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7877 6151 if ( array_key_exists( 'ldap_password', $auth_multisite_settings ) && strlen( $auth_multisite_settings['ldap_password'] ) > 0 ) {
7878 - $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
6152 + $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
7879 6153 $auth_multisite_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7880 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6154 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7881 6155 }
7882 6156 }
7883 6157 // Update version to reflect this change has been made.
7884 - $auth_version = $update_if_older_than;
6158 + $auth_version = $update_if_older_than;
7885 6159 $needs_updating = true;
7886 6160 }
7887 6161
7888 - // Update: Remove duplicates from approved list caused by authorizer_automatically_approve_login
7889 - // filter not respecting users who are already in the approved list
7890 - // (causing them to get re-added each time they logged in).
7891 - $update_if_older_than = 20170711;
7892 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7893 - // Remove duplicates from approved user lists.
7894 - if ( is_multisite() ) {
7895 - // Remove duplicates from each site in the multisite.
7896 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7897 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7898 - foreach ( $sites as $site ) {
7899 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7900 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
7901 - if ( is_array( $auth_settings_access_users_approved ) ) {
7902 - $should_update = false;
7903 - $distinct_emails = array();
7904 - foreach ( $auth_settings_access_users_approved as $key => $user ) {
7905 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7906 - $should_update = true;
7907 - unset( $auth_settings_access_users_approved[ $key ] );
7908 - } else {
7909 - $distinct_emails[] = $user['email'];
7910 - }
7911 - }
7912 - if ( $should_update ) {
7913 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
7914 - }
7915 - }
7916 - }
7917 - // Remove duplicates from multisite approved user list.
7918 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
7919 - if ( is_array( $auth_multisite_settings_access_users_approved ) ) {
7920 - $should_update = false;
7921 - $distinct_emails = array();
7922 - foreach ( $auth_multisite_settings_access_users_approved as $key => $user ) {
7923 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7924 - $should_update = true;
7925 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
7926 - } else {
7927 - $distinct_emails[] = $user['email'];
7928 - }
7929 - }
7930 - if ( $should_update ) {
7931 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7932 - }
7933 - }
7934 - } else {
7935 - // Remove duplicates from single site approved user list.
7936 - $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
7937 - if ( is_array( $auth_settings_access_users_approved ) ) {
7938 - $should_update = false;
7939 - $distinct_emails = array();
7940 - foreach ( $auth_settings_access_users_approved as $key => $user ) {
7941 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7942 - $should_update = true;
7943 - unset( $auth_settings_access_users_approved[ $key ] );
7944 - } else {
7945 - $distinct_emails[] = $user['email'];
7946 - }
7947 - }
7948 - if ( $should_update ) {
7949 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
7950 - }
7951 - }
7952 - }
7953 - // Update version to reflect this change has been made.
7954 - $auth_version = $update_if_older_than;
7955 - $needs_updating = true;
7956 - }
6162 + // // Update: TEMPLATE
6163 + // $update_if_older_than = YYYYMMDD;
6164 + // if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
6165 + // UPDATE CODE HERE
6166 + // // Update version to reflect this change has been made.
6167 + // $auth_version = $update_if_older_than;
6168 + // $needs_updating = true;
6169 + // }
7957 6170
7958 - // Update: Set default value for newly added option advanced_widget_enabled.
7959 - $update_if_older_than = 20171023;
7960 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7961 - // Provide default values for any $auth_settings options that don't exist.
7962 - if ( is_multisite() ) {
7963 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7964 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7965 - foreach ( $sites as $site ) {
7966 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7967 - switch_to_blog( $blog_id );
7968 - $this->set_default_options();
7969 - restore_current_blog();
7970 - }
7971 - } else {
7972 - $this->set_default_options();
7973 - }
7974 - // Update version to reflect this change has been made.
7975 - $auth_version = $update_if_older_than;
7976 - $needs_updating = true;
7977 - }
7978 -
7979 - // Update: Set default value for newly added option advanced_users_per_page.
7980 - $update_if_older_than = 20171215;
7981 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7982 - // Provide default values for any $auth_settings options that don't exist.
7983 - if ( is_multisite() ) {
7984 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7985 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7986 - foreach ( $sites as $site ) {
7987 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7988 - switch_to_blog( $blog_id );
7989 - $this->set_default_options();
7990 - restore_current_blog();
7991 - }
7992 - } else {
7993 - $this->set_default_options();
7994 - }
7995 - // Update version to reflect this change has been made.
7996 - $auth_version = $update_if_older_than;
7997 - $needs_updating = true;
7998 - }
7999 -
8000 - // Update: Set default value for newly added options advanced_users_sort_by and advanced_users_sort_order.
8001 - $update_if_older_than = 20171219;
8002 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
8003 - // Provide default values for any $auth_settings options that don't exist.
8004 - if ( is_multisite() ) {
8005 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
8006 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
8007 - foreach ( $sites as $site ) {
8008 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
8009 - switch_to_blog( $blog_id );
8010 - $this->set_default_options();
8011 - restore_current_blog();
8012 - }
8013 - } else {
8014 - $this->set_default_options();
8015 - }
8016 - // Update version to reflect this change has been made.
8017 - $auth_version = $update_if_older_than;
8018 - $needs_updating = true;
8019 - }
8020 -
8021 - /*
8022 - // Update: TEMPLATE
8023 - $update_if_older_than = YYYYMMDD;
8024 - if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
8025 - UPDATE CODE HERE
8026 - // Update version to reflect this change has been made.
8027 - $auth_version = $update_if_older_than;
8028 - $needs_updating = true;
8029 - }
8030 - */
8031 -
8032 6171 // Save new version number if we performed any updates.
8033 6172 if ( $needs_updating ) {
8034 6173 if ( is_multisite() ) {
8035 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
8036 6174 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
8037 6175 foreach ( $sites as $site ) {
8038 6176 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
8039 6177 update_blog_option( $blog_id, 'auth_version', $auth_version );