PluginProbe
Authorizer / 2.6.12
Authorizer v2.6.12
3.15.3 3.15.2 3.15.1 3.15.0 3.14.3 3.14.4 3.14.2 3.14.1 2.8.1 2.8.2 2.8.3 2.8.4 2.8.5 2.8.6 2.8.7 2.8.8 2.9.0 2.9.1 2.9.10 2.9.11 2.9.12 2.9.13 2.9.2 2.9.3 2.9.6 All 126 releases
← All changes | authorizer.php +2154 -4061 2.8.82.6.12 View file →
@@ -1,31 +1,51 @@
1 1 <?php
2 -/**
3 - * Plugin Name: Authorizer
4 - * Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
5 - * Author: Paul Ryan <prar@hawaii.edu>
6 - * Plugin URI: https://github.com/uhm-coe/authorizer
7 - * Text Domain: authorizer
8 - * Domain Path: /languages
9 - * License: GPL2
10 - * Version: 2.8.8
11 - *
12 - * @package authorizer
13 - */
2 +/*
3 +Plugin Name: Authorizer
4 +Plugin URI: https://github.com/uhm-coe/authorizer
5 +Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
6 +Version: 2.6.12
7 +Author: Paul Ryan
8 +Author URI: http://www.linkedin.com/in/paulrryan/
9 +Text Domain: authorizer
10 +Domain Path: /languages
11 +License: GPL2
12 +*/
14 13
15 -/**
16 - * Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
17 - * Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
18 - * Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
19 - */
20 14
21 -/**
22 - * Add phpCAS library if it's not included.
23 - *
24 - * @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
25 - */
15 +/*
16 +Copyright 2014 Paul Ryan (email: prar@hawaii.edu)
17 +
18 +This program is free software; you can redistribute it and/or modify
19 +it under the terms of the GNU General Public License, version 2, as
20 +published by the Free Software Foundation.
21 +
22 +This program is distributed in the hope that it will be useful,
23 +but WITHOUT ANY WARRANTY; without even the implied warranty of
24 +MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
25 +GNU General Public License for more details.
26 +
27 +You should have received a copy of the GNU General Public License
28 +along with this program; if not, write to the Free Software
29 +Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
30 +*/
31 +
32 +
33 +/*
34 +Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
35 +Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
36 +Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
37 +*/
38 +
39 +
40 +define( 'MULTISITE_ADMIN', 'multisite_admin' );
41 +define( 'SINGLE_ADMIN', 'single_admin' );
42 +
43 +
44 +// Add phpCAS library if it's not included.
45 +// @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
26 46 if ( ! defined( 'PHPCAS_VERSION' ) ) {
27 - require_once dirname( __FILE__ ) . '/vendor/phpCAS-1.3.6/CAS.php';
47 + require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.4/CAS.php';
28 48 }
29 49
30 50
31 51 if ( ! class_exists( 'WP_Plugin_Authorizer' ) ) {
@@ -39,87 +59,18 @@
39 59 * @link http://hawaii.edu/coe/dcdc/wordpress/authorizer/doc/
40 60 */
41 61 class WP_Plugin_Authorizer {
42 62
43 - /**
44 - * Constants for determining our admin context (network or individual site).
45 - */
46 - const NETWORK_CONTEXT = 'multisite_admin';
47 - const SINGLE_CONTEXT = 'single_admin';
48 63
49 64 /**
50 - * Current site ID (Multisite).
51 - *
52 - * @var string
53 - */
54 - public $current_site_blog_id = 1;
55 -
56 - /**
57 - * HTML allowed when rendering translatable strings in the Authorizer UI.
58 - * This is passed to wp_kses() when sanitizing HMTL strings.
59 - *
60 - * @var array
61 - */
62 - private $allowed_html = array(
63 - 'a' => array(
64 - 'class' => array(),
65 - 'href' => array(),
66 - 'style' => array(),
67 - 'target' => array(),
68 - 'title' => array(),
69 - ),
70 - 'b' => array(),
71 - 'br' => array(),
72 - 'div' => array(
73 - 'class' => array(),
74 - ),
75 - 'em' => array(),
76 - 'hr' => array(),
77 - 'i' => array(),
78 - 'input' => array(
79 - 'aria-describedby' => array(),
80 - 'class' => array(),
81 - 'id' => array(),
82 - 'name' => array(),
83 - 'size' => array(),
84 - 'type' => array(),
85 - 'value' => array(),
86 - ),
87 - 'label' => array(
88 - 'class' => array(),
89 - 'for' => array(),
90 - ),
91 - 'p' => array(
92 - 'style' => array(),
93 - ),
94 - 'span' => array(
95 - 'aria-hidden' => array(),
96 - 'class' => array(),
97 - 'id' => array(),
98 - 'style' => array(),
99 - ),
100 - 'strong' => array(),
101 - );
102 -
103 - /**
104 65 * Constructor.
105 66 */
106 67 public function __construct() {
107 - // Save reference to current blog id in the network (support deprecated
108 - // constant BLOGID_CURRENT_SITE).
109 - if ( defined( 'BLOG_ID_CURRENT_SITE' ) ) {
110 - $this->current_site_blog_id = BLOG_ID_CURRENT_SITE;
111 - } elseif ( defined( 'BLOGID_CURRENT_SITE' ) ) { // deprecated.
112 - $this->current_site_blog_id = BLOGID_CURRENT_SITE;
113 - }
114 -
115 68 // Installation and uninstallation hooks.
116 69 register_activation_hook( __FILE__, array( $this, 'activate' ) );
117 70 register_deactivation_hook( __FILE__, array( $this, 'deactivate' ) );
118 71
119 - /**
120 - * Register filters.
121 - */
72 + // Register filters.
122 73
123 74 // Custom wp authentication routine using external service.
124 75 add_filter( 'authenticate', array( $this, 'custom_authenticate' ), 1, 3 );
125 76
@@ -125,9 +76,13 @@
125 76
126 77 // Custom logout action using external service.
127 78 add_action( 'wp_logout', array( $this, 'custom_logout' ) );
128 79
129 - // Create settings link on Plugins page.
80 + // Removing this bypasses Wordpress authentication (so if external auth fails,
81 + // no one can log in); with it enabled, it will run if external auth fails.
82 + //remove_filter('authenticate', 'wp_authenticate_username_password', 20, 3);
83 +
84 + // Create settings link on Plugins page
130 85 add_filter( 'plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'plugin_settings_link' ) );
131 86 add_filter( 'network_admin_plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'network_admin_plugin_settings_link' ) );
132 87
133 88 // Modify login page with a custom password url (if option is set).
@@ -138,11 +93,9 @@
138 93 if ( $error && strlen( $error ) > 0 ) {
139 94 add_filter( 'login_errors', array( $this, 'show_advanced_login_error' ) );
140 95 }
141 96
142 - /**
143 - * Register actions.
144 - */
97 + // Register actions.
145 98
146 99 // Enable localization. Translation files stored in /languages.
147 100 add_action( 'plugins_loaded', array( $this, 'load_textdomain' ) );
148 101
@@ -154,20 +107,18 @@
154 107
155 108 // Add users who successfully login to the approved list.
156 109 add_action( 'wp_login', array( $this, 'ensure_wordpress_user_in_approved_list_on_login' ), 10, 2 );
157 110
158 - // Create menu item in Settings.
111 + // Create menu item in Settings
159 112 add_action( 'admin_menu', array( $this, 'add_plugin_page' ) );
160 113
161 - // Create options page.
114 + // Create options page
162 115 add_action( 'admin_init', array( $this, 'page_init' ) );
163 116
164 117 // Update user role in approved list if it's changed in the WordPress edit user page.
165 - add_action( 'user_profile_update_errors', array( $this, 'edit_user_profile_update_role' ), 10, 3 );
118 + add_action( 'edit_user_profile_update', array( $this, 'edit_user_profile_update_role' ) );
119 + add_action( 'personal_options_update', array( $this, 'edit_user_profile_update_role' ) );
166 120
167 - // Update user email in approved list if it's changed in the WordPress edit user page.
168 - add_filter( 'send_email_change_email', array( $this, 'edit_user_profile_update_email' ), 10, 3 );
169 -
170 121 // Enqueue javascript and css on the plugin's options page, the
171 122 // dashboard (for the widget), and the network admin.
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
@@ -172,16 +123,13 @@
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
174 125 add_action( 'load-toplevel_page_authorizer', array( $this, 'load_options_page' ) );
175 126
176 - // Add custom css and js to wp-login.php.
127 + // Add custom css and js to wp-login.php
177 128 add_action( 'login_enqueue_scripts', array( $this, 'login_enqueue_scripts_and_styles' ) );
178 129 add_action( 'login_footer', array( $this, 'load_login_footer_js' ) );
179 130
180 - // Create google nonce cookie when loading wp-login.php if Google is enabled.
181 - add_action( 'login_init', array( $this, 'login_init__maybe_set_google_nonce_cookie' ) );
182 -
183 - // Modify login page with external auth links (if enabled; e.g., google or cas).
131 + // Modify login page with external auth links (if enabled; e.g., google or cas)
184 132 add_action( 'login_form', array( $this, 'login_form_add_external_service_links' ) );
185 133
186 134 // Redirect to CAS login when visiting login page (only if option is
187 135 // enabled, CAS is the only service, and WordPress logins are hidden).
@@ -190,28 +138,25 @@
190 138 // output is started (so the redirect header doesn't complain about data
191 139 // already being sent).
192 140 add_filter( 'wp_login_errors', array( $this, 'wp_login_errors__maybe_redirect_to_cas' ), 10, 2 );
193 141
194 - // Verify current user has access to page they are visiting.
142 + // Verify current user has access to page they are visiting
195 143 add_action( 'parse_request', array( $this, 'restrict_access' ), 9 );
196 144 add_action( 'init', array( $this, 'init__maybe_add_network_approved_user' ) );
197 145
198 - // AJAX: Save options from dashboard widget.
146 + // ajax save options from dashboard widget
199 147 add_action( 'wp_ajax_update_auth_user', array( $this, 'ajax_update_auth_user' ) );
200 148
201 - // AJAX: Save options from multisite options page.
149 + // ajax save options from multisite options page
202 150 add_action( 'wp_ajax_save_auth_multisite_settings', array( $this, 'ajax_save_auth_multisite_settings' ) );
203 151
204 - // AJAX: Save usermeta from options page.
152 + // ajax save usermeta from options page
205 153 add_action( 'wp_ajax_update_auth_usermeta', array( $this, 'ajax_update_auth_usermeta' ) );
206 154
207 - // AJAX: Verify google login.
155 + // ajax verify google login
208 156 add_action( 'wp_ajax_process_google_login', array( $this, 'ajax_process_google_login' ) );
209 157 add_action( 'wp_ajax_nopriv_process_google_login', array( $this, 'ajax_process_google_login' ) );
210 158
211 - // AJAX: Refresh approved user list.
212 - add_action( 'wp_ajax_refresh_approved_user_list', array( $this, 'ajax_refresh_approved_user_list' ) );
213 -
214 159 // Add dashboard widget so instructors can add/edit users with access.
215 160 // Hint: For Multisite Network Admin Dashboard use wp_network_dashboard_setup instead of wp_dashboard_setup.
216 161 add_action( 'wp_dashboard_setup', array( $this, 'add_dashboard_widgets' ) );
217 162
@@ -226,12 +171,17 @@
226 171 add_action( 'wp_enqueue_scripts', array( $this, 'auth_public_scripts' ), 20 );
227 172
228 173 // Multisite-specific actions.
229 174 if ( is_multisite() ) {
230 - // Add network admin options page (global settings for all sites).
175 + // Add network admin options page (global settings for all sites)
231 176 add_action( 'network_admin_menu', array( $this, 'network_admin_menu' ) );
232 177 }
233 178
179 + // Create login cookie (used by google login)
180 + if ( ! isset( $_COOKIE['login_unique'] ) ) {
181 + setcookie( 'login_unique', $this->get_cookie_value(), time()+1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
182 + }
183 +
234 184 // Remove user from authorizer lists when that user is deleted in WordPress.
235 185 add_action( 'delete_user', array( $this, 'remove_user_from_authorizer_when_deleted' ) );
236 186 if ( is_multisite() ) {
237 187 // Remove multisite user from authorizer lists when that user is deleted from Network Users.
@@ -264,20 +214,16 @@
264 214 * Will also activate the plugin for all sites/blogs if this is a "Network enable."
265 215 *
266 216 * @return void
267 217 */
268 - public function activate( $network_wide ) {
218 + public function activate() {
269 219 global $wpdb;
270 220
271 - // If we're in a multisite environment, run the plugin activation for each
272 - // site when network enabling.
273 - // Note: wp-cli does not use nonces, so we skip the nonce check here to
274 - // allow the "wp plugin activate authorizer" command.
275 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
276 - if ( is_multisite() && $network_wide ) {
221 + // If we're in a multisite environment, run the plugin activation for each site when network enabling
222 + if ( is_multisite() && isset( $_GET['networkwide'] ) && $_GET['networkwide'] == 1 ) {
277 223
278 224 // Add super admins to the multisite approved list.
279 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
225 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() );
280 226 $should_update_auth_multisite_settings_access_users_approved = false;
281 227 foreach ( get_super_admins() as $super_admin ) {
282 228 $user = get_user_by( 'login', $super_admin );
283 229 // Add to approved list if not there.
@@ -282,10 +228,10 @@
282 228 $user = get_user_by( 'login', $super_admin );
283 229 // Add to approved list if not there.
284 230 if ( ! $this->in_multi_array( $user->user_email, $auth_multisite_settings_access_users_approved ) ) {
285 231 $approved_user = array(
286 - 'email' => $this->lowercase( $user->user_email ),
287 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
232 + 'email' => $user->user_email,
233 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
288 234 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
289 235 'local_user' => true,
290 236 );
291 237 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
@@ -292,14 +238,13 @@
292 238 $should_update_auth_multisite_settings_access_users_approved = true;
293 239 }
294 240 }
295 241 if ( $should_update_auth_multisite_settings_access_users_approved ) {
296 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
242 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
297 243 }
298 244
299 245 // Run plugin activation on each site in the network.
300 246 $current_blog_id = $wpdb->blogid;
301 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
302 247 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
303 248 foreach ( $sites as $site ) {
304 249 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
305 250 switch_to_blog( $blog_id );
@@ -328,13 +273,13 @@
328 273 * @return void
329 274 */
330 275 private function add_wp_users_to_approved_list() {
331 276 // Add current WordPress users to the approved list.
332 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
333 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
334 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
335 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
336 - $updated = false;
277 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
278 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
279 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
280 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
281 + $updated = false;
337 282 foreach ( get_users() as $user ) {
338 283 // Skip if user is in blocked list.
339 284 if ( $this->in_multi_array( $user->user_email, $auth_settings_access_users_blocked ) ) {
340 285 continue;
@@ -340,10 +285,10 @@
340 285 continue;
341 286 }
342 287 // Remove from pending list if there.
343 288 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
344 - if ( 0 === strcasecmp( $pending_user['email'], $user->user_email ) ) {
345 - unset( $auth_settings_access_users_pending[ $key ] );
289 + if ( $pending_user['email'] == $user->user_email ) {
290 + unset( $auth_settings_access_users_pending[$key] );
346 291 $updated = true;
347 292 }
348 293 }
349 294 // Skip if user is in multisite approved list.
@@ -352,10 +297,10 @@
352 297 }
353 298 // Add to approved list if not there.
354 299 if ( ! $this->in_multi_array( $user->user_email, $auth_settings_access_users_approved ) ) {
355 300 $approved_user = array(
356 - 'email' => $this->lowercase( $user->user_email ),
357 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
301 + 'email' => $user->user_email,
302 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
358 303 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
359 304 'local_user' => true,
360 305 );
361 306 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -390,14 +335,13 @@
390 335
391 336 /**
392 337 * Authenticate against an external service.
393 338 *
394 - * Filter: authenticate
395 - *
396 - * @param WP_User $user user to authenticate.
339 + * @param WP_User $user user to authenticate
397 340 * @param string $username optional username to authenticate.
398 341 * @param string $password optional password to authenticate.
399 - * @return WP_User|WP_Error WP_User on success, WP_Error on failure.
342 + *
343 + * @return WP_User or WP_Error
400 344 */
401 345 public function custom_authenticate( $user, $username, $password ) {
402 346 // Pass through if already authenticated.
403 347 if ( is_a( $user, 'WP_User' ) ) {
@@ -405,20 +349,20 @@
405 349 } else {
406 350 $user = null;
407 351 }
408 352
409 - // If username and password are blank, this isn't a log in attempt.
353 + // If username and password are blank, this isn't a log in attempt
410 354 $is_login_attempt = strlen( $username ) > 0 && strlen( $password ) > 0;
411 355
412 356 // Check to make sure that $username is not locked out due to too
413 357 // many invalid login attempts. If it is, tell the user how much
414 358 // time remains until they can try again.
415 - $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
359 + $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
416 360 $unauthenticated_user_is_blocked = false;
417 - if ( $is_login_attempt && false !== $unauthenticated_user ) {
361 + if ( $is_login_attempt && $unauthenticated_user !== false ) {
418 362 $last_attempt = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
419 363 $num_attempts = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
420 - // Also check the auth_blocked user_meta flag (users in blocked list will get this flag).
364 + // Also check the auth_blocked user_meta flag (users in blocked list will get this flag)
421 365 $unauthenticated_user_is_blocked = get_user_meta( $unauthenticated_user->ID, 'auth_blocked', true ) === 'yes';
422 366 } else {
423 367 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
424 368 $num_attempts = get_option( 'auth_settings_advanced_lockouts_failed_attempts' );
@@ -432,9 +376,9 @@
432 376 return new WP_Error( 'empty_password', __( '<strong>ERROR</strong>: Incorrect username or password.', 'authorizer' ) );
433 377 }
434 378
435 379 // Grab plugin settings.
436 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
380 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
437 381
438 382 // Make sure $last_attempt (time) and $num_attempts are positive integers.
439 383 // Note: this addresses resetting them if either is unset from above.
440 384 $last_attempt = abs( intval( $last_attempt ) );
@@ -440,17 +384,17 @@
440 384 $last_attempt = abs( intval( $last_attempt ) );
441 385 $num_attempts = abs( intval( $num_attempts ) );
442 386
443 387 // Create semantic lockout variables.
444 - $lockouts = $auth_settings['advanced_lockouts'];
445 - $time_since_last_fail = time() - $last_attempt;
446 - $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds.
447 - $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
448 - $num_attempts_short_lockout = $lockouts['attempts_1'];
449 - $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
388 + $lockouts = $auth_settings['advanced_lockouts'];
389 + $time_since_last_fail = time() - $last_attempt;
390 + $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds
391 + $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
392 + $num_attempts_short_lockout = $lockouts['attempts_1'];
393 + $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
450 394 $seconds_remaining_short_lockout = $lockouts['duration_1'] * 60 - $time_since_last_fail;
451 395
452 - // Check if we need to institute a lockout delay.
396 + // Check if we need to institute a lockout delay
453 397 if ( $is_login_attempt && $time_since_last_fail > $reset_duration ) {
454 398 // Enough time has passed since the last invalid attempt and
455 399 // now that we can reset the failed attempt count, and let this
456 400 // login attempt go through.
@@ -463,9 +407,8 @@
463 407 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
464 408 return new WP_Error(
465 409 'empty_password',
466 410 sprintf(
467 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
468 411 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
469 412 $username,
470 413 $seconds_remaining_long_lockout,
471 414 $this->seconds_as_sentence( $seconds_remaining_long_lockout ),
@@ -480,9 +423,8 @@
480 423 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
481 424 return new WP_Error(
482 425 'empty_password',
483 426 sprintf(
484 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
485 427 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
486 428 $username,
487 429 $seconds_remaining_short_lockout,
488 430 $this->seconds_as_sentence( $seconds_remaining_short_lockout ),
@@ -492,16 +434,16 @@
492 434 }
493 435
494 436 // Start external authentication.
495 437 $externally_authenticated_emails = array();
496 - $authenticated_by = '';
497 - $result = null;
438 + $authenticated_by = '';
439 + $result = null;
498 440
499 441 // Try Google authentication if it's enabled and we don't have a
500 442 // successful login yet.
501 443 if (
502 - '1' === $auth_settings['google'] &&
503 - 0 === count( $externally_authenticated_emails ) &&
444 + $auth_settings['google'] === '1' &&
445 + count( $externally_authenticated_emails ) === 0 &&
504 446 ! is_wp_error( $result )
505 447 ) {
506 448 $result = $this->custom_authenticate_google( $auth_settings );
507 449 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -516,10 +458,10 @@
516 458
517 459 // Try CAS authentication if it's enabled and we don't have a
518 460 // successful login yet.
519 461 if (
520 - '1' === $auth_settings['cas'] &&
521 - 0 === count( $externally_authenticated_emails ) &&
462 + $auth_settings['cas'] === '1' &&
463 + count( $externally_authenticated_emails ) === 0 &&
522 464 ! is_wp_error( $result )
523 465 ) {
524 466 $result = $this->custom_authenticate_cas( $auth_settings );
525 467 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -534,10 +476,10 @@
534 476
535 477 // Try LDAP authentication if it's enabled and we don't have an
536 478 // authenticated user yet.
537 479 if (
538 - '1' === $auth_settings['ldap'] &&
539 - 0 === count( $externally_authenticated_emails ) &&
480 + $auth_settings['ldap'] === '1' &&
481 + count( $externally_authenticated_emails ) === 0 &&
540 482 ! is_wp_error( $result )
541 483 ) {
542 484 $result = $this->custom_authenticate_ldap( $auth_settings, $username, $password );
543 485 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -558,46 +500,35 @@
558 500
559 501 // Remove duplicate and blank emails, if any.
560 502 $externally_authenticated_emails = array_filter( array_unique( $externally_authenticated_emails ) );
561 503
562 - /**
563 - * If we've made it this far, we should have an externally
564 - * authenticated user. The following should be set:
565 - * $externally_authenticated_emails
566 - * $authenticated_by
567 - */
504 + // If we've made it this far, we should have an externally
505 + // authenticated user. The following should be set:
506 + // $externally_authenticated_emails
507 + // $authenticated_by
568 508
569 - // Look for an existing WordPress account matching the externally
570 - // authenticated user. Perform the match either by username or email.
571 - if ( isset( $auth_settings['cas_link_on_username'] ) && 1 === intval( $auth_settings['cas_link_on_username'] ) ) {
572 - // Get the external user's WordPress account by username. This is less
573 - // secure, but a user reported having an installation where a previous
574 - // CAS plugin had created over 9000 WordPress accounts without email
575 - // addresses. This option was created to support that case, and any
576 - // other CAS servers where emails are not used as account identifiers.
577 - $user = get_user_by( 'login', $result['username']);
578 - } else {
579 - // Get the external user's WordPress account by email address. This is
580 - // the normal behavior (and the most secure).
581 - foreach ( $externally_authenticated_emails as $externally_authenticated_email ) {
582 - $user = get_user_by( 'email', $this->lowercase( $externally_authenticated_email ) );
583 - // Stop trying email addresses once we have found a match.
584 - if ( false !== $user ) {
585 - break;
586 - }
509 + // Get the external user's WordPress account by email address.
510 + foreach ( $externally_authenticated_emails as $externally_authenticated_email ) {
511 + $user = get_user_by( 'email', $externally_authenticated_email );
512 +
513 + // If we've already found a WordPress user associated with one
514 + // of the supplied email addresses, don't keep examining other
515 + // email addresses associated with the externally authenticated user.
516 + if ( $user !== FALSE ) {
517 + break;
587 518 }
588 519 }
589 520
590 521 // Check this external user's access against the access lists
591 - // (pending, approved, blocked).
522 + // (pending, approved, blocked)
592 523 $result = $this->check_user_access( $user, $externally_authenticated_emails, $result );
593 524
594 525 // Fail with message if there was an error creating/adding the user.
595 - if ( is_wp_error( $result ) || 0 === $result ) {
526 + if ( is_wp_error( $result ) || $result === 0 ) {
596 527 return $result;
597 528 }
598 529
599 - // If we have a valid user from check_user_access(), log that user in.
530 + // If we created a new user in check_user_access(), log that user in.
600 531 if ( get_class( $result ) === 'WP_User' ) {
601 532 $user = $result;
602 533 }
603 534
@@ -614,29 +545,27 @@
614 545 /**
615 546 * This function will fail with a wp_die() message to the user if they
616 547 * don't have access.
617 548 *
618 - * @param WP_User $user User to check.
619 - * @param array $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account).
620 - * @param array $user_data Array of keys for email, username, first_name, last_name,
621 - * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
622 - * @return WP_Error|WP_User
623 - * WP_Error if there was an error on user creation / adding user to blog.
624 - * WP_Error / wp_die() if user does not have access.
625 - * WP_User if user has access.
549 + * @param WP_User $user User to check
550 + * @param [type] $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account)
551 + * @param [type] $user_data Array of keys for email, username, first_name, last_name,
552 + * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
553 + * @return WP_Error if there was an error on user creation / adding user to blog
554 + * wp_die() if user does not have access
555 + * null if user has access (success)
556 + * WP_User if user has access and a new account was created for them
626 557 */
627 558 private function check_user_access( $user, $user_emails, $user_data = array() ) {
628 559 // Grab plugin settings.
629 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
630 - $auth_settings_access_users_pending = $this->sanitize_user_list(
631 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
560 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
561 + $auth_settings_access_users_pending = $this->sanitize_user_list(
562 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
632 563 );
633 - $auth_settings_access_users_approved_single = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
634 - $auth_settings_access_users_approved_multi = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
635 - $auth_settings_access_users_approved = $this->sanitize_user_list(
564 + $auth_settings_access_users_approved = $this->sanitize_user_list(
636 565 array_merge(
637 - $auth_settings_access_users_approved_single,
638 - $auth_settings_access_users_approved_multi
566 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
567 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
639 568 )
640 569 );
641 570
642 571 /**
@@ -645,9 +574,9 @@
645 574 *
646 575 * @param bool $allow_login Whether to block the currently logging in user.
647 576 * @param array $user_data User data returned from external service.
648 577 */
649 - $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
578 + $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
650 579 $blocked_by_filter = ! $allow_login; // Use this for better readability.
651 580
652 581 // Check our externally authenticated user against the block list.
653 582 // If any of their email addresses are blocked, set the relevant user
@@ -657,16 +586,14 @@
657 586
658 587 // Add user to blocked list if it was blocked via the filter.
659 588 if ( $blocked_by_filter && ! $this->is_email_in_list( $user_email, 'blocked' ) ) {
660 589 $auth_settings_access_users_blocked = $this->sanitize_user_list(
661 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
590 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
662 591 );
663 - array_push(
664 - $auth_settings_access_users_blocked, array(
665 - 'email' => $this->lowercase( $user_email ),
666 - 'date_added' => date( 'M Y' ),
667 - )
668 - );
592 + array_push( $auth_settings_access_users_blocked, array(
593 + 'email' => $user_email,
594 + 'date_added' => date( 'M Y' ),
595 + ));
669 596 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
670 597 }
671 598
672 599 // If the blocked external user has a WordPress account, mark it as
@@ -675,11 +602,10 @@
675 602 update_user_meta( $user->ID, 'auth_blocked', 'yes' );
676 603 }
677 604
678 605 // Notify user about blocked status and return without authenticating them.
679 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
680 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
681 - $page_title = sprintf(
606 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
607 + $page_title = sprintf(
682 608 /* TRANSLATORS: %s: Name of blog */
683 609 __( '%s - Access Restricted', 'authorizer' ),
684 610 get_bloginfo( 'name' )
685 611 );
@@ -690,15 +616,13 @@
690 616 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
691 617 __( 'Back', 'authorizer' ) .
692 618 '</a></p>';
693 619 update_option( 'auth_settings_advanced_login_error', $error_message );
694 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
695 - return new WP_Error( 'invalid_login', __( 'Invalid login attempted.', 'authorizer' ) );
620 + wp_die( $error_message, $page_title );
696 621 }
697 622 }
698 623
699 - // Get the default role for this user (or their current role, if they
700 - // already have an account).
624 + // Get the default role for this new user.
701 625 $default_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $auth_settings['access_default_role'];
702 626 /**
703 627 * Filter the role of the user currently logging in. The role will be
704 628 * set to the default (specified in Authorizer options) for new users,
@@ -703,9 +627,8 @@
703 627 * Filter the role of the user currently logging in. The role will be
704 628 * set to the default (specified in Authorizer options) for new users,
705 629 * or the user's current role for existing users. This filter allows
706 630 * changing user roles based on custom CAS/LDAP attributes.
707 - *
708 631 * @param bool $role Role of the user currently logging in.
709 632 * @param array $user_data User data returned from external service.
710 633 */
711 634 $approved_role = apply_filters( 'authorizer_custom_role', $default_role, $user_data );
@@ -730,9 +653,9 @@
730 653 // If this externally authenticated user is an existing administrator
731 654 // (administrator in single site mode, or super admin in network mode),
732 655 // and is not in the blocked list, let them in.
733 656 if ( $user && is_super_admin( $user->ID ) ) {
734 - return $user;
657 + return;
735 658 }
736 659
737 660 // If this externally authenticated user isn't in the approved list
738 661 // and login access is set to "All authenticated users," or if they were
@@ -738,12 +661,14 @@
738 661 // and login access is set to "All authenticated users," or if they were
739 662 // automatically approved in the "authorizer_approve_login" filter
740 663 // above, then add them to the approved list (they'll get an account
741 664 // created below if they don't have one yet).
742 - if (
665 + if ( (
743 666 ! $this->is_email_in_list( $user_email, 'approved' ) &&
744 - ( 'external_users' === $auth_settings['access_who_can_login'] || $automatically_approve_login )
745 - ) {
667 + $auth_settings['access_who_can_login'] === 'external_users'
668 + ) || (
669 + $automatically_approve_login
670 + ) ) {
746 671 $is_newly_approved_user = true;
747 672
748 673 // If this user happens to be in the pending list (rare),
749 674 // remove them from pending before adding them to approved.
@@ -748,9 +673,9 @@
748 673 // If this user happens to be in the pending list (rare),
749 674 // remove them from pending before adding them to approved.
750 675 if ( $this->is_email_in_list( $user_email, 'pending' ) ) {
751 676 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
752 - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
677 + if ( $pending_user['email'] === $user_email ) {
753 678 unset( $auth_settings_access_users_pending[ $key ] );
754 679 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
755 680 break;
756 681 }
@@ -758,15 +683,14 @@
758 683 }
759 684
760 685 // Add this user to the approved list.
761 686 $approved_user = array(
762 - 'email' => $this->lowercase( $user_email ),
763 - 'role' => $approved_role,
764 - 'date_added' => date( 'Y-m-d H:i:s' ),
687 + 'email' => $user_email,
688 + 'role' => $approved_role,
689 + 'date_added' => date( "Y-m-d H:i:s" ),
765 690 );
766 691 array_push( $auth_settings_access_users_approved, $approved_user );
767 - array_push( $auth_settings_access_users_approved_single, $approved_user );
768 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
692 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
769 693 }
770 694
771 695 // Check our externally authenticated user against the approved
772 696 // list. If they are approved, log them in (and create their account
@@ -780,10 +704,14 @@
780 704 if ( $default_role !== $approved_role ) {
781 705 $user_info['role'] = $approved_role;
782 706 }
783 707
784 - // If the approved external user does not have a WordPress account, create it.
708 + // If the approved external user does not have a WordPress account, create it
785 709 if ( ! $user ) {
710 + // If there's already a user with this username (e.g.,
711 + // johndoe/johndoe@gmail.com exists, and we're trying to add
712 + // johndoe/johndoe@example.com), use the full email address
713 + // as the username.
786 714 if ( array_key_exists( 'username', $user_data ) ) {
787 715 $username = $user_data['username'];
788 716 } else {
789 717 $username = explode( '@', $user_info['email'] );
@@ -788,56 +716,31 @@
788 716 } else {
789 717 $username = explode( '@', $user_info['email'] );
790 718 $username = $username[0];
791 719 }
792 - // If there's already a user with this username (e.g.,
793 - // johndoe/johndoe@gmail.com exists, and we're trying to add
794 - // johndoe/johndoe@example.com), use the full email address
795 - // as the username.
796 720 if ( get_user_by( 'login', $username ) !== false ) {
797 721 $username = $user_info['email'];
798 722 }
799 723 $result = wp_insert_user(
800 724 array(
801 - 'user_login' => strtolower( $username ),
802 - 'user_pass' => wp_generate_password(), // random password.
803 - 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
804 - 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
805 - 'user_email' => $this->lowercase( $user_info['email'] ),
725 + 'user_login' => strtolower( $username ),
726 + 'user_pass' => wp_generate_password(), // random password
727 + 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
728 + 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
729 + 'user_email' => strtolower( $user_info['email'] ),
806 730 'user_registered' => date( 'Y-m-d H:i:s' ),
807 - 'role' => $user_info['role'],
731 + 'role' => $user_info['role'],
808 732 )
809 733 );
810 734
811 735 // Fail with message if error.
812 - if ( is_wp_error( $result ) || 0 === $result ) {
736 + if ( is_wp_error( $result ) || $result === 0 ) {
813 737 return $result;
814 738 }
815 739
816 - // Authenticate as new user.
740 + // Authenticate as new user
817 741 $user = new WP_User( $result );
818 742
819 - /**
820 - * Fires after an external user is authenticated for the first time
821 - * and a new WordPress account is created for them.
822 - *
823 - * @since 2.8.0
824 - *
825 - * @param WP_User $user User object.
826 - * @param array $user_data User data from external service.
827 - *
828 - * Example $user_data:
829 - * array(
830 - * 'email' => 'user@example.edu',
831 - * 'username' => 'user',
832 - * 'first_name' => 'First',
833 - * 'last_name' => 'Last',
834 - * 'authenticated_by' => 'cas',
835 - * 'cas_attributes' => array( ... ),
836 - * );
837 - */
838 - do_action( 'authorizer_user_register', $user, $user_data );
839 -
840 743 // If multisite, iterate through all sites in the network and add the user
841 744 // currently logging in to any of them that have the user on the approved list.
842 745 // Note: this is useful for first-time logins--some users will have access
843 746 // to multiple sites, and this prevents them from having to log into each
@@ -843,21 +746,18 @@
843 746 // to multiple sites, and this prevents them from having to log into each
844 747 // site individually to get access.
845 748 if ( is_multisite() ) {
846 749 $site_ids_of_user = array_map(
847 - function ( $site_of_user ) {
848 - return intval( $site_of_user->userblog_id );
849 - },
750 + function ( $site_of_user ) { return $site_of_user->userblog_id; },
850 751 get_blogs_of_user( $user->ID )
851 752 );
852 753
853 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
854 754 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
855 755 foreach ( $sites as $site ) {
856 756 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
857 757
858 758 // Skip if user is already added to this site.
859 - if ( in_array( intval( $blog_id ), $site_ids_of_user, true ) ) {
759 + if ( in_array( $blog_id, $site_ids_of_user ) ) {
860 760 continue;
861 761 }
862 762
863 763 // Check if user is on the approved list of this site they are not added to.
@@ -883,9 +783,9 @@
883 783 if ( $meta_key === $user_info['usermeta']['meta_key'] ) {
884 784 // Update user's usermeta value for usermeta key stored in authorizer options.
885 785 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
886 786 // We have an ACF field value, so use the ACF function to update it.
887 - update_field( str_replace( 'acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
787 + update_field( str_replace('acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
888 788 } else {
889 789 // We have a normal usermeta value, so just update it via the WordPress function.
890 790 update_user_meta( $user->ID, $meta_key, $user_info['usermeta']['meta_value'] );
891 791 }
@@ -901,9 +801,9 @@
901 801 switch_to_blog( $blog_id );
902 802 // Update user's usermeta value for usermeta key stored in authorizer options.
903 803 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
904 804 // We have an ACF field value, so use the ACF function to update it.
905 - update_field( str_replace( 'acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
805 + update_field( str_replace('acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
906 806 } else {
907 807 // We have a normal usermeta value, so just update it via the WordPress function.
908 808 update_user_meta( $user->ID, $meta_key, $usermeta['meta_value'] );
909 809 }
@@ -914,24 +814,20 @@
914 814 }
915 815 } else {
916 816 // Update first/last names of WordPress user from external
917 817 // service if that option is set.
918 - if ( ( array_key_exists( 'authenticated_by', $user_data ) && 'cas' === $user_data['authenticated_by'] && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['cas_attr_update_on_login'] ) ) || ( array_key_exists( 'authenticated_by', $user_data ) && 'ldap' === $user_data['authenticated_by'] && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['ldap_attr_update_on_login'] ) ) ) {
919 - if ( array_key_exists( 'first_name', $user_data ) && 0 < strlen( $user_data['first_name'] ) ) {
920 - wp_update_user(
921 - array(
922 - 'ID' => $user->ID,
923 - 'first_name' => $user_data['first_name'],
924 - )
925 - );
818 + if ( ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'cas' && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && $auth_settings['cas_attr_update_on_login'] == 1 ) || ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'ldap' && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && $auth_settings['ldap_attr_update_on_login'] == 1 ) ) {
819 + if ( array_key_exists( 'first_name', $user_data ) && strlen( $user_data['first_name'] ) > 0 ) {
820 + wp_update_user( array(
821 + 'ID' => $user->ID,
822 + 'first_name' => $user_data['first_name'],
823 + ));
926 824 }
927 825 if ( array_key_exists( 'last_name', $user_data ) && strlen( $user_data['last_name'] ) > 0 ) {
928 - wp_update_user(
929 - array(
930 - 'ID' => $user->ID,
931 - 'last_name' => $user_data['last_name'],
932 - )
933 - );
826 + wp_update_user( array(
827 + 'ID' => $user->ID,
828 + 'last_name' => $user_data['last_name'],
829 + ));
934 830 }
935 831 }
936 832
937 833 // Update this user's role if it was modified in the
@@ -936,19 +832,12 @@
936 832
937 833 // Update this user's role if it was modified in the
938 834 // authorizer_custom_role filter.
939 835 if ( $default_role !== $approved_role ) {
940 - // Update user's role in WordPress.
941 - $user->set_role( $approved_role );
942 -
943 - // Update user's role in this site's approved list and save.
944 - foreach ( $auth_settings_access_users_approved_single as $key => $existing_user ) {
945 - if ( 0 === strcasecmp( $user->user_email, $existing_user['email'] ) ) {
946 - $auth_settings_access_users_approved_single[ $key ]['role'] = $approved_role;
947 - break;
948 - }
949 - }
950 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
836 + wp_update_user( array(
837 + 'ID' => $user->ID,
838 + 'role' => $approved_role,
839 + ));
951 840 }
952 841 }
953 842
954 843 // If this is multisite, add new user to current blog.
@@ -961,34 +850,33 @@
961 850 }
962 851 }
963 852
964 853 // Ensure user has the same role as their entry in the approved list.
965 - if ( $user_info && ! in_array( $user_info['role'], $user->roles, true ) ) {
854 + // (This is just a precaution, the role should already be set when
855 + // saving admin options in the sanitizing function.)
856 + if ( $user_info && ! array_key_exists( $user_info['role'], $user->roles ) ) {
966 857 $user->set_role( $user_info['role'] );
967 858 }
968 859
969 860 return $user;
970 861
971 - } elseif ( 0 === strcasecmp( $user_email, $last_email ) ) {
972 - /**
973 - * Note: only do this for the last email address we are checking (we need
974 - * to iterate through them all to make sure one of them isn't approved).
975 - */
976 -
862 + // Note: only do this for the last email address we are checking (we need
863 + // to iterate through them all to make sure one of them isn't approved).
864 + } elseif ( $user_email === $last_email ) {
977 865 // User isn't an admin, is not blocked, and is not approved.
978 866 // Add them to the pending list and notify them and their instructor.
979 867 if ( strlen( $user_email ) > 0 && ! $this->is_email_in_list( $user_email, 'pending' ) ) {
980 - $pending_user = array();
981 - $pending_user['email'] = $this->lowercase( $user_email );
982 - $pending_user['role'] = $approved_role;
868 + $pending_user = array();
869 + $pending_user['email'] = $user_email;
870 + $pending_user['role'] = $approved_role;
983 871 $pending_user['date_added'] = '';
984 872 array_push( $auth_settings_access_users_pending, $pending_user );
985 873 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
986 874
987 875 // Create strings used in the email notification.
988 - $site_name = get_bloginfo( 'name' );
989 - $site_url = get_bloginfo( 'url' );
990 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
876 + $site_name = get_bloginfo( 'name' );
877 + $site_url = get_bloginfo( 'url' );
878 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
991 879
992 880 // Notify users with the role specified in "Which role should
993 881 // receive email notifications about pending users?".
994 882 if ( strlen( $auth_settings['access_role_receive_pending_emails'] ) > 0 ) {
@@ -1013,11 +901,10 @@
1013 901 }
1014 902 }
1015 903
1016 904 // Notify user about pending status and return without authenticating them.
1017 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1018 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
1019 - $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
905 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
906 + $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
1020 907 $error_message =
1021 908 apply_filters( 'the_content', $auth_settings['access_pending_redirect_to_message'] ) .
1022 909 '<hr />' .
1023 910 '<p style="text-align: center;">' .
@@ -1024,9 +911,9 @@
1024 911 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
1025 912 __( 'Back', 'authorizer' ) .
1026 913 '</a></p>';
1027 914 update_option( 'auth_settings_advanced_login_error', $error_message );
1028 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
915 + wp_die( $error_message, $page_title );
1029 916 }
1030 917 }
1031 918
1032 919 // Sanity check: if we made it here without returning, something has gone wrong.
@@ -1049,34 +936,24 @@
1049 936 * custom_authenticate_google() runs to verify the token; once verified
1050 937 * custom_authenticate proceeds as normal with the google email address
1051 938 * as a successfully authenticated external user.
1052 939 *
1053 - * Action: wp_ajax_process_google_login
1054 - * Action: wp_ajax_nopriv_process_google_login
1055 - *
1056 - * @return void, but die with the value to return to the success() function in AJAX call signInCallback().
940 + * @return void, but die with the value to return to the success() function in AJAX call signInCallback()
1057 941 */
1058 - public function ajax_process_google_login() {
942 + function ajax_process_google_login() {
943 + $nonce = array_key_exists( 'nonce', $_POST ) ? $_POST['nonce'] : '';
944 + $code = array_key_exists( 'code', $_POST ) ? $_POST['code'] : null;
945 +
1059 946 // Nonce check.
1060 - if (
1061 - ! isset( $_POST['nonce'] ) ||
1062 - ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'google_csrf_nonce' )
1063 - ) {
1064 - die( '' );
947 + if ( ! wp_verify_nonce( $nonce, 'google_csrf_nonce' ) ) {
948 + return '';
1065 949 }
1066 950
1067 - // Google authentication token.
1068 - // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput.InputNotSanitized
1069 - $code = isset( $_POST['code'] ) ? wp_unslash( $_POST['code'] ) : null;
1070 -
1071 951 // Grab plugin settings.
1072 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
952 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1073 953
1074 - /**
1075 - * Add Google API PHP Client.
1076 - *
1077 - * @see https://github.com/google/google-api-php-client branch:v1-master
1078 - */
954 + // Add Google API PHP Client.
955 + // @see https://github.com/google/google-api-php-client branch:v1-master
1079 956 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1080 957
1081 958 // Build the Google Client.
1082 959 $client = new Google_Client();
@@ -1084,26 +961,19 @@
1084 961 $client->setClientId( $auth_settings['google_clientid'] );
1085 962 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1086 963 $client->setRedirectUri( 'postmessage' );
1087 964
1088 - /**
1089 - * If the hosted domain parameter is set, restrict logins to that domain.
1090 - *
1091 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1092 - * this to function server-side; it's not complete in v1, so this check
1093 - * is performed manually below.
1094 - *
1095 - * if (
1096 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1097 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1098 - * ) {
1099 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1100 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1101 - * $client->setHostedDomain( $google_hosteddomain );
1102 - * }
1103 - */
965 + // If the hosted domain parameter is set, restrict logins to that domain.
966 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
967 + // this to function server-side; it's not complete in v1, so this check
968 + // is performed manually below.
969 + // if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
970 + // $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
971 + // $google_hosteddomain = trim( $google_hosteddomains[0] );
972 + // $client->setHostedDomain( $google_hosteddomain );
973 + // }
1104 974
1105 - // Get one time use token (if it doesn't exist, we'll create one below).
975 + // Get one time use token (if it doesn't exist, we'll create one below)
1106 976 session_start();
1107 977 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1108 978
1109 979 if ( empty( $token ) ) {
@@ -1111,18 +981,18 @@
1111 981 $client->authenticate( $code );
1112 982 $token = json_decode( $client->getAccessToken() );
1113 983
1114 984 // Store the token in the session for later use.
1115 - $_SESSION['token'] = wp_json_encode( $token );
985 + $_SESSION['token'] = json_encode( $token );
1116 986
1117 - $response = 'Successfully authenticated.';
987 + $response = "Successfully authenticated.";
1118 988 } else {
1119 - $client->setAccessToken( wp_json_encode( $token ) );
989 + $client->setAccessToken( json_encode( $token ) );
1120 990
1121 991 $response = 'Already authenticated.';
1122 992 }
1123 993
1124 - die( esc_html( $response ) );
994 + die( $response );
1125 995 }
1126 996
1127 997
1128 998 /**
@@ -1127,22 +997,22 @@
1127 997
1128 998 /**
1129 999 * Validate this user's credentials against Google.
1130 1000 *
1131 - * @param array $auth_settings Plugin settings.
1132 - * @return array|WP_Error Array containing email, authenticated_by, first_name,
1133 - * last_name, and username strings for the successfully
1134 - * authenticated user, or WP_Error() object on failure,
1135 - * or null if not attempting a google login.
1001 + * @param array $auth_settings Plugin settings
1002 + * @return [mixed] Array containing email, authenticated_by,
1003 + * first_name, last_name, and username
1004 + * strings for the successfully authenticated
1005 + * user, or WP_Error() object on failure,
1006 + * or null if not attempting a google login.
1136 1007 */
1137 1008 private function custom_authenticate_google( $auth_settings ) {
1138 1009 // Move on if Google auth hasn't been requested here.
1139 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1140 - if ( empty( $_GET['external'] ) || 'google' !== $_GET['external'] ) {
1010 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'google' ) {
1141 1011 return null;
1142 1012 }
1143 1013
1144 - // Get one time use token.
1014 + // Get one time use token
1145 1015 session_start();
1146 1016 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1147 1017
1148 1018 // No token, so this is not a succesful Google login.
@@ -1149,13 +1019,10 @@
1149 1019 if ( is_null( $token ) ) {
1150 1020 return null;
1151 1021 }
1152 1022
1153 - /**
1154 - * Add Google API PHP Client.
1155 - *
1156 - * @see https://github.com/google/google-api-php-client branch:v1-master
1157 - */
1023 + // Add Google API PHP Client.
1024 + // @see https://github.com/google/google-api-php-client branch:v1-master
1158 1025 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1159 1026
1160 1027 // Build the Google Client.
1161 1028 $client = new Google_Client();
@@ -1163,24 +1030,19 @@
1163 1030 $client->setClientId( $auth_settings['google_clientid'] );
1164 1031 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1165 1032 $client->setRedirectUri( 'postmessage' );
1166 1033
1167 - /**
1168 - * If the hosted domain parameter is set, restrict logins to that domain.
1169 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1170 - * this to function server-side; it's not complete in v1, so this check
1171 - * is performed manually later.
1172 - * if (
1173 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1174 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1175 - * ) {
1176 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1177 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1178 - * $client->setHostedDomain( $google_hosteddomain );
1179 - * }
1180 - */
1034 + // If the hosted domain parameter is set, restrict logins to that domain.
1035 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1036 + // this to function server-side; it's not complete in v1, so this check
1037 + // is performed manually below.
1038 + // if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1039 + // $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1040 + // $google_hosteddomain = trim( $google_hosteddomains[0] );
1041 + // $client->setHostedDomain( $google_hosteddomain );
1042 + // }
1181 1043
1182 - // Verify this is a successful Google authentication.
1044 + // Verify this is a successful Google authentication
1183 1045 try {
1184 1046 $ticket = $client->verifyIdToken( $token->id_token, $auth_settings['google_clientid'] );
1185 1047 } catch ( Google_Auth_Exception $e ) {
1186 1048 // Invalid ticket, so this in not a successful Google login.
@@ -1191,29 +1053,25 @@
1191 1053 if ( ! $ticket ) {
1192 1054 return new WP_Error( 'invalid_google_login', __( 'Invalid Google credentials provided.', 'authorizer' ) );
1193 1055 }
1194 1056
1195 - // Get email address.
1196 - $attributes = $ticket->getAttributes();
1197 - $email = $this->lowercase( $attributes['payload']['email'] );
1057 + // Get email address
1058 + $attributes = $ticket->getAttributes();
1059 + $email = $attributes['payload']['email'];
1198 1060 $email_domain = substr( strrchr( $email, '@' ), 1 );
1199 - $username = current( explode( '@', $email ) );
1061 + $username = current( explode( '@', $email ) );
1200 1062
1201 - /**
1202 - * Fail if hd param is set and the logging in user's email address doesn't
1203 - * match the allowed hosted domain.
1204 - *
1205 - * See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1206 - * See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1207 - *
1208 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1209 - * this to function server-side; it's not complete in v1, so this check
1210 - * is only performed here.
1211 - */
1063 + // Fail if hd param is set and the logging in user's email address doesn't
1064 + // match the allowed hosted domain.
1065 + // See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1066 + // See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1067 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1068 + // this to function server-side; it's not complete in v1, so this check
1069 + // is only performed here.
1212 1070 if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1213 1071 // Allow multiple whitelisted domains.
1214 1072 $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1215 - if ( ! in_array( $email_domain, $google_hosteddomains, true ) ) {
1073 + if ( ! in_array( $email_domain, $google_hosteddomains ) ) {
1216 1074 $this->custom_logout();
1217 1075 return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) );
1218 1076 }
1219 1077 }
@@ -1218,13 +1076,13 @@
1218 1076 }
1219 1077 }
1220 1078
1221 1079 return array(
1222 - 'email' => $email,
1223 - 'username' => $username,
1224 - 'first_name' => '',
1225 - 'last_name' => '',
1226 - 'authenticated_by' => 'google',
1080 + 'email' => $email,
1081 + 'username' => $username,
1082 + 'first_name' => '',
1083 + 'last_name' => '',
1084 + 'authenticated_by' => 'google',
1227 1085 'google_attributes' => $attributes,
1228 1086 );
1229 1087 }
1230 1088
@@ -1231,63 +1089,77 @@
1231 1089
1232 1090 /**
1233 1091 * Validate this user's credentials against CAS.
1234 1092 *
1235 - * @param array $auth_settings Plugin settings.
1236 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1237 - * for the successfully authenticated user, or WP_Error()
1238 - * object on failure, or null if not attempting a CAS login.
1093 + * @param array $auth_settings Plugin settings
1094 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1095 + * strings for the successfully authenticated
1096 + * user, or WP_Error() object on failure,
1097 + * or null if not attempting a CAS login.
1239 1098 */
1240 1099 private function custom_authenticate_cas( $auth_settings ) {
1241 1100 // Move on if CAS hasn't been requested here.
1242 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1243 - if ( empty( $_GET['external'] ) || 'cas' !== $_GET['external'] ) {
1101 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'cas' ) {
1244 1102 return null;
1245 1103 }
1246 1104
1247 - /**
1248 - * Get the CAS server version (default to SAML_VERSION_1_1).
1249 - *
1250 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1251 - */
1105 + // Get the CAS server version (default to SAML_VERSION_1_1).
1106 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1252 1107 $cas_version = SAML_VERSION_1_1;
1253 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1108 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1254 1109 $cas_version = CAS_VERSION_3_0;
1255 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1110 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1256 1111 $cas_version = CAS_VERSION_2_0;
1257 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1112 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1258 1113 $cas_version = CAS_VERSION_1_0;
1259 1114 }
1260 1115
1261 - // Set the CAS client configuration.
1116 + // Set the CAS client configuration
1262 1117 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1263 1118
1264 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1265 - // at an old CAS URL that redirects to a newer CAS URL).
1266 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1119 + // Update server certificate bundle if it doesn't exist or is older
1120 + // than 6 months, then use it to ensure CAS server is legitimate.
1121 + // Note: only try to update if the system has the php_openssl extension.
1122 + $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1123 + $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1124 + $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds
1125 + $time_180_days_ago = time() - $time_180_days;
1126 + if (
1127 + extension_loaded( 'openssl' ) &&
1128 + ( ! file_exists( $cacert_path ) || filemtime( $cacert_path ) < $time_180_days_ago )
1129 + ) {
1130 + // Get new cacert.pem file from https://curl.haxx.se/ca/cacert.pem.
1131 + $response = wp_safe_remote_get( $cacert_url );
1132 + if (
1133 + is_wp_error( $response ) ||
1134 + 200 !== wp_remote_retrieve_response_code( $response ) ||
1135 + ! array_key_exists( 'body', $response )
1136 + ) {
1137 + new WP_Error( 'cannot_update_cacert', __( 'Unable to update outdated server certificates from https://curl.haxx.se/ca/cacert.pem.', 'authorizer' ) );
1138 + }
1139 + $cacert_contents = $response['body'];
1267 1140
1268 - // Use the WordPress certificate bundle at /wp-includes/certificates/ca-bundle.crt.
1269 - phpCAS::setCasServerCACert( ABSPATH . WPINC . '/certificates/ca-bundle.crt' );
1141 + // Write out the updated certs to the plugin directory.
1142 + file_put_contents( $cacert_path, $cacert_contents );
1143 + }
1144 + phpCAS::setCasServerCACert( $cacert_path );
1270 1145
1271 1146 // Set the CAS service URL (including the redirect URL for WordPress when it comes back from CAS).
1272 - $cas_service_url = site_url( '/wp-login.php?external=cas' );
1273 - $login_querystring = array();
1274 - if ( isset( $_SERVER['QUERY_STRING'] ) ) {
1275 - parse_str( $_SERVER['QUERY_STRING'], $login_querystring ); // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput
1276 - }
1147 + $cas_service_url = site_url( '/wp-login.php?external=cas' );
1148 + $login_querystring = array(); parse_str( $_SERVER['QUERY_STRING'], $login_querystring );
1277 1149 if ( isset( $login_querystring['redirect_to'] ) ) {
1278 - $cas_service_url .= '&redirect_to=' . rawurlencode( $login_querystring['redirect_to'] );
1150 + $cas_service_url .= '&redirect_to=' . urlencode( $login_querystring['redirect_to'] );
1279 1151 }
1280 1152 phpCAS::setFixedServiceURL( $cas_service_url );
1281 1153
1282 - // Authenticate against CAS.
1154 + // Authenticate against CAS
1283 1155 try {
1284 1156 phpCAS::forceAuthentication();
1285 1157 } catch ( CAS_AuthenticationException $e ) {
1286 1158 // CAS server threw an error in isAuthenticated(), potentially because
1287 1159 // the cached ticket is outdated. Try renewing the authentication.
1288 - error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) ); // phpcs:ignore
1289 - error_log( print_r( $e, true ) ); // phpcs:ignore
1160 + error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) );
1161 + error_log( print_r( $e, true ) );
1290 1162
1291 1163 // CAS server is throwing errors on this login, so try logging the
1292 1164 // user out of CAS and redirecting them to the login page.
1293 1165 phpCAS::logoutWithRedirectService( wp_login_url() );
@@ -1302,10 +1174,10 @@
1302 1174 if ( ! filter_var( $externally_authenticated_email, FILTER_VALIDATE_EMAIL ) ) {
1303 1175 // If we can't get the user's email address from a CAS attribute,
1304 1176 // try to guess the domain from the CAS server hostname. This will only
1305 1177 // be used if we can't discover the email address from CAS attributes.
1306 - $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1307 - $externally_authenticated_email = $this->lowercase( $username ) . '@' . $domain_guess;
1178 + $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1179 + $externally_authenticated_email = strtolower( $username ) . '@' . $domain_guess;
1308 1180 }
1309 1181
1310 1182 // Retrieve the user attributes (e.g., email address, first name, last name) from the CAS server.
1311 1183 $cas_attributes = phpCAS::getAttributes();
@@ -1316,45 +1188,37 @@
1316 1188 // email domain is manually entered there (instead of a reference to a
1317 1189 // CAS attribute), and combine that with the username to create the email.
1318 1190 // Otherwise, look up the CAS attribute for email.
1319 1191 if ( substr( $auth_settings['cas_attr_email'], 0, 1 ) === '@' ) {
1320 - $externally_authenticated_email = $this->lowercase( $username . $auth_settings['cas_attr_email'] );
1192 + $externally_authenticated_email = strtolower( $username . $auth_settings['cas_attr_email'] );
1321 1193 } elseif (
1322 1194 // If a CAS attribute has been specified as containing the email address, use that instead.
1323 1195 // Email attribute can be a string or an array of strings.
1324 1196 array_key_exists( $auth_settings['cas_attr_email'], $cas_attributes ) && (
1325 1197 (
1326 - is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1327 - count( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1198 + is_array( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1199 + count( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1328 1200 ) || (
1329 - is_string( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1330 - strlen( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1201 + is_string( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1202 + strlen( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1331 1203 )
1332 1204 )
1333 1205 ) {
1334 - // Each of the emails in the array needs to be set to lowercase.
1335 - if ( is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) ) {
1336 - $externally_authenticated_email = array();
1337 - foreach ( $cas_attributes[ $auth_settings['cas_attr_email'] ] as $external_email ) {
1338 - $externally_authenticated_email[] = $this->lowercase( $external_email );
1339 - }
1340 - } else {
1341 - $externally_authenticated_email = $this->lowercase( $cas_attributes[ $auth_settings['cas_attr_email'] ] );
1342 - }
1206 + $externally_authenticated_email = $cas_attributes[$auth_settings['cas_attr_email']];
1343 1207 }
1344 1208 }
1345 1209
1346 1210 // Get user first name and last name.
1347 - $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_first_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_first_name'] ] : '';
1348 - $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_last_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_last_name'] ] : '';
1211 + $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_first_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_first_name']] : '';
1212 + $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_last_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_last_name']] : '';
1349 1213
1350 1214 return array(
1351 - 'email' => $externally_authenticated_email,
1352 - 'username' => $username,
1353 - 'first_name' => $first_name,
1354 - 'last_name' => $last_name,
1215 + 'email' => $externally_authenticated_email,
1216 + 'username' => $username,
1217 + 'first_name' => $first_name,
1218 + 'last_name' => $last_name,
1355 1219 'authenticated_by' => 'cas',
1356 - 'cas_attributes' => $cas_attributes,
1220 + 'cas_attributes' => $cas_attributes,
1357 1221 );
1358 1222 }
1359 1223
1360 1224
@@ -1360,32 +1224,24 @@
1360 1224
1361 1225 /**
1362 1226 * Validate this user's credentials against LDAP.
1363 1227 *
1364 - * @param array $auth_settings Plugin settings.
1365 - * @param string $username Attempted username from authenticate action.
1366 - * @param string $password Attempted password from authenticate action.
1367 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1368 - * for the successfully authenticated user, or WP_Error()
1369 - * object on failure, or null if skipping LDAP auth and
1370 - * falling back to WP auth.
1228 + * @param array $auth_settings Plugin settings
1229 + * @param string $username Attempted username from authenticate action
1230 + * @param string $password Attempted password from authenticate action
1231 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1232 + * strings for the successfully authenticated
1233 + * user, or WP_Error() object on failure,
1234 + * or null if skipping LDAP auth and falling back to WP auth.
1371 1235 */
1372 1236 private function custom_authenticate_ldap( $auth_settings, $username, $password ) {
1373 - // Get LDAP search base(s).
1374 - $search_bases = explode( "\n", str_replace( "\r", '', trim( $auth_settings['ldap_search_base'] ) ) );
1375 -
1376 - // Fail silently (fall back to WordPress authentication) if no search base specified.
1377 - if ( count( $search_bases ) < 1 ) {
1378 - return null;
1379 - }
1380 -
1381 - // Get the FQDN from the first LDAP search base domain components (dc). For
1382 - // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk.
1383 - $search_base_components = explode( ',', trim( $search_bases[0] ) );
1384 - $domain = array();
1237 + // Get the FQDN from the LDAP search base domain components (dc). For
1238 + // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk
1239 + $search_base_components = explode( ',', trim( $auth_settings['ldap_search_base'] ) );
1240 + $domain = array();
1385 1241 foreach ( $search_base_components as $search_base_component ) {
1386 1242 $component = explode( '=', $search_base_component );
1387 - if ( 2 === count( $component ) && 'dc' === $component[0] ) {
1243 + if ( count( $component ) === 2 && $component[0] === 'dc' ) {
1388 1244 $domain[] = $component[1];
1389 1245 }
1390 1246 }
1391 1247 $domain = implode( '.', $domain );
@@ -1396,9 +1252,9 @@
1396 1252 if ( empty( $domain ) ) {
1397 1253 $domain = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['ldap_host'], $matches ) === 1 ? $matches[0] : '';
1398 1254 }
1399 1255
1400 - // remove @domain if it exists in the username (i.e., if user entered their email).
1256 + // remove @domain if it exists in the username (i.e., if user entered their email)
1401 1257 $username = str_replace( '@' . $domain, '', $username );
1402 1258
1403 1259 // Fail silently (fall back to WordPress authentication) if both username
1404 1260 // and password are empty (this will be the case when visiting wp-login.php
@@ -1421,13 +1277,13 @@
1421 1277 return null;
1422 1278 }
1423 1279
1424 1280 // Authenticate against LDAP using options provided in plugin settings.
1425 - $result = false;
1281 + $result = false;
1426 1282 $ldap_user_dn = '';
1427 - $first_name = '';
1428 - $last_name = '';
1429 - $email = '';
1283 + $first_name = '';
1284 + $last_name = '';
1285 + $email = '';
1430 1286
1431 1287 // Construct LDAP connection parameters. ldap_connect() takes either a
1432 1288 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1433 1289 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
@@ -1432,13 +1288,13 @@
1432 1288 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1433 1289 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
1434 1290 // ignored, and port must be specified in the full URI. An LDAP URI is of
1435 1291 // the form ldap://hostname:port or ldaps://hostname:port.
1436 - $ldap_host = $auth_settings['ldap_host'];
1437 - $ldap_port = intval( $auth_settings['ldap_port'] );
1438 - $parsed_host = wp_parse_url( $ldap_host );
1292 + $ldap_host = $auth_settings['ldap_host'];
1293 + $ldap_port = intval( $auth_settings['ldap_port'] );
1294 + $parsed_host = parse_url( $ldap_host );
1439 1295 // Fail (fall back to WordPress auth) if invalid host is specified.
1440 - if ( false === $parsed_host ) {
1296 + if ( $parsed_host === false ) {
1441 1297 return null;
1442 1298 }
1443 1299 // If a scheme is in the LDAP host, use full LDAP URI instead of just hostname.
1444 1300 if ( array_key_exists( 'scheme', $parsed_host ) ) {
@@ -1451,24 +1307,24 @@
1451 1307
1452 1308 // Establish LDAP connection.
1453 1309 $ldap = ldap_connect( $ldap_host, $ldap_port );
1454 1310 ldap_set_option( $ldap, LDAP_OPT_PROTOCOL_VERSION, 3 );
1455 - if ( 1 === intval( $auth_settings['ldap_tls'] ) ) {
1456 - if ( ! ldap_start_tls( $ldap ) ) {
1311 + if ( $auth_settings['ldap_tls'] == 1 ) {
1312 + if( ! ldap_start_tls( $ldap ) ) {
1457 1313 return null;
1458 1314 }
1459 1315 }
1460 1316
1461 1317 // Set bind credentials; attempt an anonymous bind if not provided.
1462 - $bind_rdn = null;
1463 - $bind_password = null;
1318 + $bind_rdn = NULL;
1319 + $bind_password = NULL;
1464 1320 if ( strlen( $auth_settings['ldap_user'] ) > 0 ) {
1465 - $bind_rdn = $auth_settings['ldap_user'];
1321 + $bind_rdn = $auth_settings['ldap_user'];
1466 1322 $bind_password = $this->decrypt( $auth_settings['ldap_password'] );
1467 1323 }
1468 1324
1469 1325 // Attempt LDAP bind.
1470 - $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) ); // phpcs:ignore
1326 + $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) );
1471 1327 if ( ! $result ) {
1472 1328 // Can't connect to LDAP, so fall back to WordPress authentication.
1473 1329 return null;
1474 1330 }
@@ -1482,40 +1338,18 @@
1482 1338 if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 ) {
1483 1339 array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_last_name'] );
1484 1340 }
1485 1341 if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 && substr( $auth_settings['ldap_attr_email'], 0, 1 ) !== '@' ) {
1486 - array_push( $ldap_attributes_to_retrieve, $this->lowercase( $auth_settings['ldap_attr_email'] ) );
1342 + array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_email'] );
1487 1343 }
1344 + $ldap_search = ldap_search(
1345 + $ldap,
1346 + $auth_settings['ldap_search_base'],
1347 + "(" . $auth_settings['ldap_uid'] . "=" . $username . ")",
1348 + $ldap_attributes_to_retrieve
1349 + );
1350 + $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1488 1351
1489 - // Create default LDAP search filter (uid=$username).
1490 - $search_filter = '(' . $auth_settings['ldap_uid'] . '=' . $username . ')';
1491 -
1492 - /**
1493 - * Filter LDAP search filter.
1494 - *
1495 - * Allows for custom LDAP authentication rules (e.g., restricting login
1496 - * access to users in multiple groups, or having certain attributes).
1497 - *
1498 - * @param string $search_filter The filter to pass to ldap_search().
1499 - * @param string $ldap_uid The attribute to compare username against (from Authorizer Settings).
1500 - * @param string $username The username attempting to log in.
1501 - */
1502 - $search_filter = apply_filters( 'authorizer_ldap_search_filter', $search_filter, $auth_settings['ldap_uid'], $username );
1503 -
1504 - // Multiple search bases can be provided, so iterate through them until a match is found.
1505 - foreach ( $search_bases as $search_base ) {
1506 - $ldap_search = ldap_search(
1507 - $ldap,
1508 - $search_base,
1509 - $search_filter,
1510 - $ldap_attributes_to_retrieve
1511 - );
1512 - $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1513 - if ( $ldap_entries['count'] > 0 ) {
1514 - break;
1515 - }
1516 - }
1517 -
1518 1352 // If we didn't find any users in ldap, fall back to WordPress authentication.
1519 1353 if ( $ldap_entries['count'] < 1 ) {
1520 1354 return null;
1521 1355 }
@@ -1521,21 +1355,21 @@
1521 1355 }
1522 1356
1523 1357 // Get the bind dn and first/last names; if there are multiple results returned, just get the last one.
1524 1358 for ( $i = 0; $i < $ldap_entries['count']; $i++ ) {
1525 - $ldap_user_dn = $ldap_entries[ $i ]['dn'];
1359 + $ldap_user_dn = $ldap_entries[$i]['dn'];
1526 1360
1527 1361 // Get user first name and last name.
1528 - $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_first_name'] ) : '';
1529 - if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_first_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_first_name ][0] ) > 0 ) {
1530 - $first_name = $ldap_entries[ $i ][ $ldap_attr_first_name ][0];
1362 + $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? strtolower( $auth_settings['ldap_attr_first_name'] ) : '';
1363 + if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_first_name]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_first_name][0] ) > 0 ) {
1364 + $first_name = $ldap_entries[$i][$ldap_attr_first_name][0];
1531 1365 }
1532 - $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_last_name'] ) : '';
1533 - if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_last_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_last_name ][0] ) > 0 ) {
1534 - $last_name = $ldap_entries[ $i ][ $ldap_attr_last_name ][0];
1366 + $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? strtolower( $auth_settings['ldap_attr_last_name'] ) : '';
1367 + if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_last_name]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_last_name][0] ) > 0 ) {
1368 + $last_name = $ldap_entries[$i][$ldap_attr_last_name][0];
1535 1369 }
1536 1370 // Get user email if it is specified in another field.
1537 - $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_email'] ) : '';
1371 + $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? strtolower( $auth_settings['ldap_attr_email'] ) : '';
1538 1372 if ( strlen( $ldap_attr_email ) > 0 ) {
1539 1373 // If the email attribute starts with an at symbol (@), assume that the
1540 1374 // email domain is manually entered there (instead of a reference to an
1541 1375 // LDAP attribute), and combine that with the username to create the email.
@@ -1540,16 +1374,16 @@
1540 1374 // email domain is manually entered there (instead of a reference to an
1541 1375 // LDAP attribute), and combine that with the username to create the email.
1542 1376 // Otherwise, look up the LDAP attribute for email.
1543 1377 if ( substr( $ldap_attr_email, 0, 1 ) === '@' ) {
1544 - $email = $this->lowercase( $username . $ldap_attr_email );
1545 - } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_email ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_email ][0] ) > 0 ) {
1546 - $email = $this->lowercase( $ldap_entries[ $i ][ $ldap_attr_email ][0] );
1378 + $email = strtolower( $username . $ldap_attr_email );
1379 + } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_email]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_email][0] ) > 0 ) {
1380 + $email = strtolower( $ldap_entries[$i][$ldap_attr_email][0] );
1547 1381 }
1548 1382 }
1549 1383 }
1550 1384
1551 - $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) ); // phpcs:ignore
1385 + $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) );
1552 1386 if ( ! $result ) {
1553 1387 // We have a real ldap user, but an invalid password. Pass
1554 1388 // through to wp authentication after failing LDAP (since
1555 1389 // this could be a local account that happens to be the
@@ -1557,22 +1391,22 @@
1557 1391 return null;
1558 1392 }
1559 1393
1560 1394 // User successfully authenticated against LDAP, so set the relevant variables.
1561 - $externally_authenticated_email = $this->lowercase( $username . '@' . $domain );
1395 + $externally_authenticated_email = $username . '@' . $domain;
1562 1396
1563 1397 // If an LDAP attribute has been specified as containing the email address, use that instead.
1564 1398 if ( strlen( $email ) > 0 ) {
1565 - $externally_authenticated_email = $this->lowercase( $email );
1399 + $externally_authenticated_email = $email;
1566 1400 }
1567 1401
1568 1402 return array(
1569 - 'email' => $externally_authenticated_email,
1570 - 'username' => $username,
1571 - 'first_name' => $first_name,
1572 - 'last_name' => $last_name,
1403 + 'email' => $externally_authenticated_email,
1404 + 'username' => $username,
1405 + 'first_name' => $first_name,
1406 + 'last_name' => $last_name,
1573 1407 'authenticated_by' => 'ldap',
1574 - 'ldap_attributes' => $ldap_entries,
1408 + 'ldap_attributes' => $ldap_entries,
1575 1409 );
1576 1410 }
1577 1411
1578 1412
@@ -1578,20 +1412,18 @@
1578 1412
1579 1413 /**
1580 1414 * Log out of the attached external service.
1581 1415 *
1582 - * Action: wp_logout
1583 - *
1584 1416 * @return void
1585 1417 */
1586 1418 public function custom_logout() {
1587 1419 // Grab plugin settings.
1588 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1420 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1589 1421
1590 1422 // Reset option containing old error messages.
1591 1423 delete_option( 'auth_settings_advanced_login_error' );
1592 1424
1593 - if ( session_id() === '' ) {
1425 + if ( session_id() == '' ) {
1594 1426 session_start();
1595 1427 }
1596 1428
1597 1429 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
@@ -1596,53 +1428,38 @@
1596 1428
1597 1429 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
1598 1430
1599 1431 // If logged in to CAS, Log out of CAS.
1600 - if ( 'cas' === $current_user_authenticated_by && '1' === $auth_settings['cas'] ) {
1432 + if ( $current_user_authenticated_by === 'cas' && $auth_settings['cas'] === '1' ) {
1601 1433 if ( ! array_key_exists( 'PHPCAS_CLIENT', $GLOBALS ) || ! array_key_exists( 'phpCAS', $_SESSION ) ) {
1602 1434
1603 - /**
1604 - * Get the CAS server version (default to SAML_VERSION_1_1).
1605 - *
1606 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1607 - */
1435 + // Get the CAS server version (default to SAML_VERSION_1_1).
1436 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1608 1437 $cas_version = SAML_VERSION_1_1;
1609 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1438 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1610 1439 $cas_version = CAS_VERSION_3_0;
1611 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1440 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1612 1441 $cas_version = CAS_VERSION_2_0;
1613 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1442 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1614 1443 $cas_version = CAS_VERSION_1_0;
1615 1444 }
1616 1445
1617 1446 // Set the CAS client configuration if it hasn't been set already.
1618 1447 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1619 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1620 - // at an old CAS URL that redirects to a newer CAS URL).
1621 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1622 1448 // Restrict logout request origin to the CAS server only (prevent DDOS).
1623 1449 phpCAS::handleLogoutRequests( true, array( $auth_settings['cas_host'] ) );
1624 1450 }
1625 - if ( phpCAS::isAuthenticated() || phpCAS::isInitialized() ) {
1626 - // Redirect to home page, or specified page if it's been provided.
1627 - $redirect_to = site_url( '/' );
1628 - if ( ! empty( $_REQUEST['redirect_to'] ) && isset( $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'log-out' ) ) {
1629 - $redirect_to = esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) );
1630 - }
1631 -
1632 - phpCAS::logoutWithRedirectService( $redirect_to );
1451 + if ( phpCAS::isAuthenticated() ) {
1452 + phpCAS::logoutWithRedirectService( site_url( '/' ) );
1633 1453 }
1634 1454 }
1635 1455
1636 1456 // If session token set, log out of Google.
1637 - if ( 'google' === $current_user_authenticated_by || array_key_exists( 'token', $_SESSION ) ) {
1457 + if ( $current_user_authenticated_by === 'google' || array_key_exists( 'token', $_SESSION ) ) {
1638 1458 $token = json_decode( $_SESSION['token'] )->access_token;
1639 1459
1640 - /**
1641 - * Add Google API PHP Client.
1642 - *
1643 - * @see https://github.com/google/google-api-php-client branch:v1-master
1644 - */
1460 + // Add Google API PHP Client.
1461 + // @see https://github.com/google/google-api-php-client branch:v1-master
1645 1462 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1646 1463
1647 1464 // Build the Google Client.
1648 1465 $client = new Google_Client();
@@ -1650,9 +1467,9 @@
1650 1467 $client->setClientId( $auth_settings['google_clientid'] );
1651 1468 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1652 1469 $client->setRedirectUri( 'postmessage' );
1653 1470
1654 - // Revoke the token.
1471 + // Revoke the token
1655 1472 $client->revokeToken( $token );
1656 1473
1657 1474 // Remove the credentials from the user's session.
1658 1475 unset( $_SESSION['token'] );
@@ -1671,61 +1488,60 @@
1671 1488
1672 1489
1673 1490 /**
1674 1491 * Restrict access to WordPress site based on settings (everyone, logged_in_users).
1492 + * Hook: parse_request http://codex.wordpress.org/Plugin_API/Action_Reference/parse_request
1675 1493 *
1676 - * Action: parse_request
1494 + * @param array $wp WordPress object.
1677 1495 *
1678 - * @param array $wp WordPress object.
1679 - * @return WP|void WP object when passing through to WordPress authentication, or void.
1496 + * @return void
1680 1497 */
1681 1498 public function restrict_access( $wp ) {
1682 1499 // Grab plugin settings.
1683 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1500 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1684 1501
1685 1502 // Grab current user.
1686 1503 $current_user = wp_get_current_user();
1687 1504
1688 1505 $has_access = (
1689 - // Always allow access if WordPress is installing.
1690 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1506 + // Always allow access if WordPress is installing
1691 1507 ( defined( 'WP_INSTALLING' ) && isset( $_GET['key'] ) ) ||
1692 - // Always allow access to admins.
1508 + // Always allow access to admins
1693 1509 ( current_user_can( 'create_users' ) ) ||
1694 - // Allow access if option is set to 'everyone'.
1695 - ( 'everyone' === $auth_settings['access_who_can_view'] ) ||
1696 - // Allow access to approved external users and logged in users if option is set to 'logged_in_users'.
1697 - ( 'logged_in_users' === $auth_settings['access_who_can_view'] && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1698 - // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API.
1699 - ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_oauth1=' ) === 0 ) ||
1700 - // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them.
1701 - ( property_exists( $wp, 'matched_query' ) && 0 === stripos( $wp->matched_query, 'rest_route=' ) && isset( $_SERVER['REQUEST_METHOD'] ) && 'GET' !== $_SERVER['REQUEST_METHOD'] ) ||
1702 - // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this.
1703 - ( property_exists( $wp, 'matched_query' ) && 'rest_route=/' === $wp->matched_query )
1510 + // Allow access if option is set to 'everyone'
1511 + ( $auth_settings['access_who_can_view'] == 'everyone' ) ||
1512 + // Allow access to approved external users and logged in users if option is set to 'logged_in_users'
1513 + ( $auth_settings['access_who_can_view'] == 'logged_in_users' && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1514 + // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API
1515 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_oauth1=" ) === 0 ) ||
1516 + // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them
1517 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] !== 'GET' ) ||
1518 + // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this
1519 + ( property_exists( $wp, 'matched_query' ) && $wp->matched_query === 'rest_route=/' )
1704 1520 // Note that GET requests to a rest endpoint will be restricted by authorizer. In that case, error messages will be returned as JSON.
1705 1521 );
1706 1522
1707 1523 /**
1708 - * Developers can use the `authorizer_has_access` filter to override
1709 - * restricted access on certain pages. Note that the restriction checks
1710 - * happens before WordPress executes any queries, so use the $wp variable
1711 - * to investigate what the visitor is trying to load.
1524 + * Developers can use the `authorizer_has_access` filter
1525 + * to override restricted access on certain pages. Note that the
1526 + * restriction checks happens before WordPress executes any queries, so
1527 + * use the global `$wp` variable to investigate what the visitor is
1528 + * trying to load.
1712 1529 *
1713 1530 * For example, to unblock an RSS feed, place the following PHP code in
1714 1531 * the theme's functions.php file or in a simple plug-in:
1715 1532 *
1716 - * function my_feed_access_override( $has_access, $wp ) {
1717 - * // Check query variables to see if this is the feed.
1718 - * if ( ! empty( $wp->query_vars['feed'] ) ) {
1533 + * function my_rsa_feed_access_override( $has_access ) {
1534 + * global $wp;
1535 + * // check query variables to see if this is the feed
1536 + * if ( ! empty( $wp->query_vars['feed'] ) )
1719 1537 * $has_access = true;
1720 - * }
1721 - *
1722 1538 * return $has_access;
1723 1539 * }
1724 - * add_filter( 'authorizer_has_access', 'my_feed_access_override', 10, 2 );
1540 + * add_filter( 'authorizer_has_access', 'my_rsa_feed_access_override' );
1725 1541 */
1726 1542 if ( apply_filters( 'authorizer_has_access', $has_access, $wp ) === true ) {
1727 - // Turn off the public notice about browsing anonymously.
1543 + // Turn off the public notice about browsing anonymously
1728 1544 update_option( 'auth_settings_advanced_public_notice', false );
1729 1545
1730 1546 // We've determined that the current user has access, so simply return to grant access.
1731 1547 return $wp;
@@ -1731,13 +1547,13 @@
1731 1547 return $wp;
1732 1548 }
1733 1549
1734 1550 // Allow HEAD requests to the root (usually discovery from a REST client).
1735 - if ( 'HEAD' === $_SERVER['REQUEST_METHOD'] && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1551 + if ( $_SERVER['REQUEST_METHOD'] === 'HEAD' && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1736 1552 return $wp;
1737 1553 }
1738 1554
1739 - /* We've determined that the current user doesn't have access, so we deal with them now. */
1555 + // We've determined that the current user doesn't have access, so we deal with them now.
1740 1556
1741 1557 // Fringe case: In a multisite, a user of a different blog can successfully
1742 1558 // log in, but they aren't on the 'approved' whitelist for this blog.
1743 1559 // If that's the case, add them to the pending list for this blog.
@@ -1748,19 +1564,29 @@
1748 1564 $result = $this->check_user_access( $current_user, array( $current_user->user_email ) );
1749 1565 }
1750 1566
1751 1567 // Check to see if the requested page is public. If so, show it.
1568 + $current_page_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'name', $wp->query_vars ) && strlen( $wp->query_vars['name'] ) > 0 ? $wp->query_vars['name'] : '';
1569 + if ( ! $current_page_name ) {
1570 + // Different WordPress versions store the page slug in different places; look for it elsewhere.
1571 + if ( property_exists( $wp, 'query_vars' ) && array_key_exists( 'pagename', $wp->query_vars ) && strlen( $wp->query_vars['pagename'] ) > 0 ) {
1572 + $current_page_name = $wp->query_vars['pagename'];
1573 + }
1574 + }
1575 + $current_page_id = '';
1752 1576 if ( empty( $wp->request ) ) {
1753 1577 $current_page_id = 'home';
1754 1578 } else {
1755 - $request_query = isset( $wp->query_vars ) ? new WP_Query( $wp->query_vars ) : null;
1756 - $current_page_id = isset( $request_query->post_count ) && $request_query->post_count > 0 ? $request_query->post->ID : '';
1579 + $current_page = get_page_by_path( $current_page_name );
1580 + if ( is_object( $current_page ) && isset( $current_page->ID ) ) {
1581 + $current_page_id = $current_page->ID;
1582 + }
1757 1583 }
1758 1584 if ( ! array_key_exists( 'access_public_pages', $auth_settings ) || ! is_array( $auth_settings['access_public_pages'] ) ) {
1759 1585 $auth_settings['access_public_pages'] = array();
1760 1586 }
1761 - if ( in_array( strval( $current_page_id ), $auth_settings['access_public_pages'], true ) ) {
1762 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1587 + if ( in_array( $current_page_id, $auth_settings['access_public_pages'] ) ) {
1588 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1763 1589 update_option( 'auth_settings_advanced_public_notice', false );
1764 1590 } else {
1765 1591 update_option( 'auth_settings_advanced_public_notice', true );
1766 1592 }
@@ -1768,11 +1594,11 @@
1768 1594 }
1769 1595
1770 1596 // Check to see if any category assigned to the requested page is public. If so, show it.
1771 1597 $current_page_categories = wp_get_post_categories( $current_page_id, array( 'fields' => 'slugs' ) );
1772 - foreach ( $current_page_categories as $current_page_category ) {
1773 - if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'], true ) ) {
1774 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1598 + foreach( $current_page_categories as $current_page_category ) {
1599 + if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'] ) ) {
1600 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1775 1601 update_option( 'auth_settings_advanced_public_notice', false );
1776 1602 } else {
1777 1603 update_option( 'auth_settings_advanced_public_notice', true );
1778 1604 }
@@ -1780,11 +1606,11 @@
1780 1606 }
1781 1607 }
1782 1608
1783 1609 // Check to see if this page can't be found. If so, allow showing the 404 page.
1784 - if ( strlen( $current_page_id ) < 1 ) {
1785 - if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'], true ) ) {
1786 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1610 + if ( strlen( $current_page_name ) > 0 && strlen( $current_page_id ) < 1 ) {
1611 + if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'] ) ) {
1612 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1787 1613 update_option( 'auth_settings_advanced_public_notice', false );
1788 1614 } else {
1789 1615 update_option( 'auth_settings_advanced_public_notice', true );
1790 1616 }
@@ -1789,8 +1615,9 @@
1789 1615 update_option( 'auth_settings_advanced_public_notice', true );
1790 1616 }
1791 1617 return $wp;
1792 1618 }
1619 +
1793 1620 }
1794 1621
1795 1622 // Check to see if the requested category is public. If so, show it.
1796 1623 $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
@@ -1795,10 +1622,10 @@
1795 1622 // Check to see if the requested category is public. If so, show it.
1796 1623 $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
1797 1624 if ( $current_category_name ) {
1798 1625 $current_category_name = end( explode( '/', $current_category_name ) );
1799 - if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'], true ) ) {
1800 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1626 + if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'] ) ) {
1627 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1801 1628 update_option( 'auth_settings_advanced_public_notice', false );
1802 1629 } else {
1803 1630 update_option( 'auth_settings_advanced_public_notice', true );
1804 1631 }
@@ -1808,20 +1635,18 @@
1808 1635
1809 1636 // User is denied access, so show them the error message. Render as JSON
1810 1637 // if this is a REST API call; otherwise, show the error message via
1811 1638 // wp_die() (rendered html), or redirect to the login URL.
1812 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1813 - if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_route=' ) === 0 && 'GET' === $_SERVER['REQUEST_METHOD'] ) {
1814 - wp_send_json(
1815 - array(
1816 - 'code' => 'rest_cannot_view',
1817 - 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1818 - 'data' => array(
1819 - 'status' => 401,
1820 - ),
1821 - )
1822 - );
1823 - } elseif ( 'message' === $auth_settings['access_redirect'] ) {
1639 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1640 + if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] === 'GET' ) {
1641 + wp_send_json( array(
1642 + 'code' => 'rest_cannot_view',
1643 + 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1644 + 'data' => array(
1645 + 'status' => 401,
1646 + ),
1647 + ));
1648 + } elseif ( $auth_settings['access_redirect'] === 'message' ) {
1824 1649 $page_title = sprintf(
1825 1650 /* TRANSLATORS: %s: Name of blog */
1826 1651 __( '%s - Access Restricted', 'authorizer' ),
1827 1652 get_bloginfo( 'name' )
@@ -1832,15 +1657,15 @@
1832 1657 '<p style="text-align: center;margin-bottom: -15px;">' .
1833 1658 '<a class="button" href="' . wp_login_url( $current_path ) . '">' .
1834 1659 __( 'Log In', 'authorizer' ) .
1835 1660 '</a></p>';
1836 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
1837 - } else {
1661 + wp_die( $error_message, $page_title );
1662 + } else { // if ( $auth_settings['access_redirect'] === 'login' ) {
1838 1663 wp_redirect( wp_login_url( $current_path ), 302 );
1839 1664 exit;
1840 1665 }
1841 1666
1842 - // Sanity check: we should never get here.
1667 + // Sanity check: we should never get here
1843 1668 wp_die( '<p>Access denied.</p>', 'Site Access Restricted' );
1844 1669 }
1845 1670
1846 1671
@@ -1849,11 +1674,9 @@
1849 1674 * not yet been added to this particular blog in a multisite). Note: we do
1850 1675 * this because check_user_access() runs on the parse_request hook, which
1851 1676 * does not fire on wp-admin pages.
1852 1677 *
1853 - * Action: init
1854 - *
1855 - * @return void
1678 + * Hook: admin_menu
1856 1679 */
1857 1680 public function init__maybe_add_network_approved_user() {
1858 1681 global $current_user;
1859 1682
@@ -1868,10 +1691,10 @@
1868 1691 ) {
1869 1692 // Get all approved users.
1870 1693 $auth_settings_access_users_approved = $this->sanitize_user_list(
1871 1694 array_merge(
1872 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
1873 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
1695 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
1696 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
1874 1697 )
1875 1698 );
1876 1699
1877 1700 // Get user info (we need user role).
@@ -1883,9 +1706,9 @@
1883 1706 // Add user to blog.
1884 1707 add_user_to_blog( get_current_blog_id(), $current_user->ID, $user_info['role'] );
1885 1708
1886 1709 // Refresh user permissions.
1887 - $current_user = new WP_User( $current_user->ID ); // phpcs:ignore WordPress.Variables.GlobalVariables.OverrideProhibited
1710 + $current_user = new WP_User( $current_user->ID );
1888 1711 }
1889 1712 }
1890 1713
1891 1714
@@ -1899,15 +1722,11 @@
1899 1722
1900 1723
1901 1724 /**
1902 1725 * Add custom error message to login screen.
1903 - *
1904 1726 * Filter: login_errors
1905 - *
1906 - * @param string $errors Error description.
1907 - * @return string Error description with Authorizer errors added.
1908 1727 */
1909 - public function show_advanced_login_error( $errors ) {
1728 + function show_advanced_login_error( $errors ) {
1910 1729 $error = get_option( 'auth_settings_advanced_login_error' );
1911 1730 delete_option( 'auth_settings_advanced_login_error' );
1912 1731 $errors = ' ' . $error . "<br />\n";
1913 1732 return $errors;
@@ -1915,25 +1734,24 @@
1915 1734
1916 1735
1917 1736 /**
1918 1737 * Load external resources for the public-facing site.
1919 - *
1920 - * Action: wp_enqueue_scripts
1921 1738 */
1922 - public function auth_public_scripts() {
1923 - // Load (and localize) public scripts.
1924 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1925 - wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1739 + function auth_public_scripts() {
1740 + // Load (and localize) public scripts
1741 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1742 + wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1926 1743 $auth_localized = array(
1927 - 'wpLoginUrl' => wp_login_url( $current_path ),
1928 - 'publicWarning' => get_option( 'auth_settings_advanced_public_notice' ),
1929 - 'anonymousNotice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1930 - 'logIn' => esc_html__( 'Log In', 'authorizer' ),
1744 + 'wp_login_url' => wp_login_url( $current_path ),
1745 + 'public_warning' => get_option( 'auth_settings_advanced_public_notice' ),
1746 + 'anonymous_notice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1747 + 'log_in' => esc_html__( 'Log In', 'authorizer' ),
1931 1748 );
1932 1749 wp_localize_script( 'auth_public_scripts', 'auth', $auth_localized );
1750 + //update_option( 'auth_settings_advanced_public_notice', false);
1933 1751
1934 - // Load public css.
1935 - wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.8.0' );
1752 + // Load public css
1753 + wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.3.2' );
1936 1754 wp_enqueue_style( 'authorizer-public-css' );
1937 1755 }
1938 1756
1939 1757
@@ -1939,21 +1757,19 @@
1939 1757
1940 1758 /**
1941 1759 * Enqueue JS scripts and CSS styles appearing on wp-login.php.
1942 1760 *
1943 - * Action: login_enqueue_scripts
1944 - *
1945 1761 * @return void
1946 1762 */
1947 - public function login_enqueue_scripts_and_styles() {
1763 + function login_enqueue_scripts_and_styles() {
1948 1764 // Grab plugin settings.
1949 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1765 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1950 1766
1951 1767 // Enqueue scripts appearing on wp-login.php.
1952 - wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1768 + wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1953 1769
1954 1770 // Enqueue styles appearing on wp-login.php.
1955 - wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.8.0' );
1771 + wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.3.2' );
1956 1772 wp_enqueue_style( 'authorizer-login-css' );
1957 1773
1958 1774 /**
1959 1775 * Developers can use the `authorizer_add_branding_option` filter
@@ -1958,8 +1774,9 @@
1958 1774 /**
1959 1775 * Developers can use the `authorizer_add_branding_option` filter
1960 1776 * to add a radio button for "Custom WordPress login branding"
1961 1777 * under the "Advanced" tab in Authorizer options. Example:
1778 + *
1962 1779 * function my_authorizer_add_branding_option( $branding_options ) {
1963 1780 * $new_branding_option = array(
1964 1781 * 'value' => 'your_brand'
1965 1782 * 'description' => 'Custom Your Brand Login Screen',
@@ -1973,23 +1790,23 @@
1973 1790 */
1974 1791 $branding_options = array();
1975 1792 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
1976 1793 foreach ( $branding_options as $branding_option ) {
1977 - // Make sure the custom brands have the required values.
1794 + // Make sure the custom brands have the required values
1978 1795 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'css_url', $branding_option ) && array_key_exists( 'js_url', $branding_option ) ) ) {
1979 1796 continue;
1980 1797 }
1981 1798 if ( $auth_settings['advanced_branding'] === $branding_option['value'] ) {
1982 - wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.8.0' );
1983 - wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.8.0' );
1799 + wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.3.2' );
1800 + wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.3.2' );
1984 1801 wp_enqueue_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ) );
1985 1802 }
1986 1803 }
1987 1804
1988 1805 // If we're using Google logins, load those resources.
1989 - if ( '1' === $auth_settings['google'] ) {
1990 - wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); ?>
1991 - <meta name="google-signin-clientid" content="<?php echo esc_attr( $auth_settings['google_clientid'] ); ?>" />
1806 + if ( $auth_settings['google'] === '1' ) {
1807 + wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); ?>
1808 + <meta name="google-signin-clientid" content="<?php echo $auth_settings['google_clientid']; ?>" />
1992 1809 <meta name="google-signin-scope" content="email" />
1993 1810 <meta name="google-signin-cookiepolicy" content="single_host_origin" />
1994 1811 <?php
1995 1812 }
@@ -1997,127 +1814,110 @@
1997 1814
1998 1815
1999 1816 /**
2000 1817 * Load external resources in the footer of the wp-login.php page.
2001 - *
2002 - * Action: login_footer
1818 + * Run on action hook: login_footer
2003 1819 */
2004 - public function load_login_footer_js() {
1820 + function load_login_footer_js() {
2005 1821 // Grab plugin settings.
2006 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2007 - $ajaxurl = admin_url( 'admin-ajax.php' );
2008 - if ( '1' === $auth_settings['google'] ) :
2009 - ?>
2010 -<script type="text/javascript">
2011 -/* global location, window */
2012 -// Reload login page if reauth querystring param exists,
2013 -// since reauth interrupts external logins (e.g., google).
2014 -if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
2015 - location.href = location.href.replace( 'reauth=1', '' );
2016 -}
1822 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
1823 + <?php if ( $auth_settings['google'] === '1' ): ?>
1824 + <script type="text/javascript">
1825 + // Reload login page if reauth querystring param exists,
1826 + // since reauth interrupts external logins (e.g., google).
1827 + if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
1828 + location.href = location.href.replace( 'reauth=1', '' );
1829 + }
2017 1830
2018 -// eslint-disable-next-line no-implicit-globals
2019 -function authUpdateQuerystringParam( uri, key, value ) {
2020 - var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
2021 - var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
2022 - if ( uri.match( re ) ) {
2023 - return uri.replace( re, '$1' + key + '=' + value + '$2' );
2024 - } else {
2025 - return uri + separator + key + '=' + value;
2026 - }
2027 -}
1831 + function auth_update_querystring_param( uri, key, value ) {
1832 + var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
1833 + var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
1834 + if ( uri.match( re ) ) {
1835 + return uri.replace( re, '$1' + key + '=' + value + '$2' );
1836 + } else {
1837 + return uri + separator + key + '=' + value;
1838 + }
1839 + }
2028 1840
2029 -// eslint-disable-next-line
2030 -function signInCallback( authResult ) { // jshint ignore:line
2031 - var $ = jQuery;
2032 - if ( authResult.status && authResult.status.signed_in ) {
2033 - // Hide the sign-in button now that the user is authorized, for example:
2034 - $( '#googleplus_button' ).attr( 'style', 'display: none' );
1841 + function signInCallback( authResult ) {
1842 + var $ = jQuery;
1843 + if ( authResult['status'] && authResult['status']['signed_in'] ) {
1844 + // Hide the sign-in button now that the user is authorized, for example:
1845 + $( '#googleplus_button' ).attr( 'style', 'display: none' );
2035 1846
2036 - // Send the code to the server
2037 - var ajaxurl = '<?php echo esc_attr( $ajaxurl ); ?>';
2038 - $.post(ajaxurl, {
2039 - action: 'process_google_login',
2040 - code: authResult.code,
2041 - nonce: $('#nonce_google_auth-<?php echo esc_attr( $this->get_cookie_value() ); ?>' ).val(),
2042 - }, function() {
2043 - // Handle or verify the server response if necessary.
2044 - // console.log( response );
1847 + // Send the code to the server
1848 + var ajaxurl = '<?php echo admin_url( "admin-ajax.php" ); ?>';
1849 + $.post(ajaxurl, {
1850 + action: 'process_google_login',
1851 + 'code': authResult['code'],
1852 + 'nonce': $('#nonce_google_auth-<?php echo $this->get_cookie_value(); ?>' ).val(),
1853 + }, function( response ) {
1854 + // Handle or verify the server response if necessary.
1855 + //console.log( response );
2045 1856
2046 - // Reload wp-login.php to continue the authentication process.
2047 - var newHref = authUpdateQuerystringParam( location.href, 'external', 'google' );
2048 - if ( location.href === newHref ) {
2049 - location.reload();
2050 - } else {
2051 - location.href = newHref;
2052 - }
2053 - });
2054 - } else {
2055 - // Update the app to reflect a signed out user
2056 - // Possible error values:
2057 - // "user_signed_out" - User is signed-out
2058 - // "access_denied" - User denied access to your app
2059 - // "immediate_failed" - Could not automatically log in the user
2060 - // console.log('Sign-in state: ' + authResult['error']);
1857 + // Reload wp-login.php to continue the authentication process.
1858 + var new_href = auth_update_querystring_param( location.href, 'external', 'google' );
1859 + if ( location.href === new_href ) {
1860 + location.reload();
1861 + } else {
1862 + location.href = new_href;
1863 + }
1864 + });
1865 + } else {
1866 + // Update the app to reflect a signed out user
1867 + // Possible error values:
1868 + // "user_signed_out" - User is signed-out
1869 + // "access_denied" - User denied access to your app
1870 + // "immediate_failed" - Could not automatically log in the user
1871 + //console.log('Sign-in state: ' + authResult['error']);
2061 1872
2062 - // If user denies access, reload the login page.
2063 - if ( authResult.error === 'access_denied' || authResult.error === 'user_signed_out' ) {
2064 - window.location.reload();
1873 + // If user denies access, reload the login page.
1874 + if ( authResult['error'] === 'access_denied' || authResult['error'] === 'user_signed_out' ) {
1875 + window.location.reload();
1876 + }
1877 + }
1878 + }
1879 + </script>
1880 + <?php endif;
2065 1881 }
2066 - }
2067 -}
2068 -</script>
2069 - <?php
2070 - endif;
2071 - }
2072 1882
2073 1883
2074 1884 /**
2075 1885 * Create links for any external authentication services that are enabled.
2076 - *
2077 - * Action: login_form
2078 1886 */
2079 - public function login_form_add_external_service_links() {
1887 + function login_form_add_external_service_links() {
2080 1888 // Grab plugin settings.
2081 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2082 - ?>
1889 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
2083 1890 <div id="auth-external-service-login">
2084 - <?php if ( '1' === $auth_settings['google'] ) : ?>
2085 - <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php esc_html_e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
1891 + <?php if ( $auth_settings['google'] === '1' ): ?>
1892 + <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php _e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
2086 1893 <?php wp_nonce_field( 'google_csrf_nonce', 'nonce_google_auth-' . $this->get_cookie_value() ); ?>
2087 1894 <?php endif; ?>
2088 1895
2089 - <?php if ( '1' === $auth_settings['cas'] ) : ?>
2090 - <p><a class="button button-primary button-external button-cas" href="<?php echo esc_attr( $this->modify_current_url_for_cas_login() ); ?>">
1896 + <?php if ( $auth_settings['cas'] === '1' ): ?>
1897 + <p><a class="button button-primary button-external button-cas" href="<?php echo $this->modify_current_url_for_cas_login(); ?>">
2091 1898 <span class="dashicons dashicons-lock"></span>
2092 - <span class="label">
2093 - <?php
2094 - echo esc_html(
2095 - sprintf(
2096 - /* TRANSLATORS: %s: Custom CAS label from authorizer options */
2097 - __( 'Sign in with %s', 'authorizer' ),
2098 - $auth_settings['cas_custom_label']
2099 - )
1899 + <span class="label"><?php
1900 + printf(
1901 + /* TRANSLATORS: %s: Custom CAS label from authorizer options */
1902 + __( 'Sign in with %s', 'authorizer' ),
1903 + $auth_settings['cas_custom_label']
2100 1904 );
2101 - ?>
2102 - </span>
1905 + ?></span>
2103 1906 </a></p>
2104 1907 <?php endif; ?>
2105 1908
2106 - <?php if ( '1' === $auth_settings['advanced_hide_wp_login'] && isset( $_SERVER['QUERY_STRING'] ) && false === strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) ) : // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput ?>
1909 + <?php if ( $auth_settings['advanced_hide_wp_login'] === '1' && strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false ): ?>
2107 1910 <style type="text/css">
2108 - body.login-action-login form {
2109 - padding-bottom: 8px;
1911 + #loginform {
1912 + padding-bottom: 8px !important;
2110 1913 }
2111 - body.login-action-login form p > label,
2112 - body.login-action-login form .forgetmenot,
2113 - body.login-action-login form .submit,
2114 - body.login-action-login #nav { /* csslint allow: ids */
2115 - display: none;
1914 + #loginform p>label, #loginform p.forgetmenot, #loginform p.submit, p#nav {
1915 + display: none !important;
2116 1916 }
2117 1917 </style>
2118 - <?php elseif ( '1' === $auth_settings['cas'] || '1' === $auth_settings['google'] ) : ?>
2119 - <h3> &mdash; <?php esc_html_e( 'or', 'authorizer' ); ?> &mdash; </h3>
1918 + <?php elseif ( $auth_settings['cas'] === '1' || $auth_settings['google'] === '1' ): ?>
1919 + <h3> &mdash; <?php _e( 'or', 'authorizer' ); ?> &mdash; </h3>
2120 1920 <?php endif; ?>
2121 1921 </div>
2122 1922 <?php
2123 1923
@@ -2130,28 +1930,21 @@
2130 1930 * Note: hook into wp_login_errors filter so this fires after the
2131 1931 * authenticate hook (where the redirect to CAS happens), but before html
2132 1932 * output is started (so the redirect header doesn't complain about data
2133 1933 * already being sent).
2134 - *
2135 - * Filter: wp_login_errors
2136 - *
2137 - * @param object $errors WP Error object.
2138 - * @param string $redirect_to Where to redirect on error.
2139 - * @return WP_Error|void WP Error object or void on redirect.
2140 1934 */
2141 - public function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
1935 + function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
2142 1936 // Grab plugin settings.
2143 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1937 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2144 1938
2145 1939 // Check whether we should redirect to CAS.
2146 1940 if (
2147 - isset( $_SERVER['QUERY_STRING'] ) &&
2148 - strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false && // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput
2149 - array_key_exists( 'cas_auto_login', $auth_settings ) && '1' === $auth_settings['cas_auto_login'] &&
2150 - array_key_exists( 'cas', $auth_settings ) && '1' === $auth_settings['cas'] &&
2151 - ( ! array_key_exists( 'ldap', $auth_settings ) || '1' !== $auth_settings['ldap'] ) &&
2152 - ( ! array_key_exists( 'google', $auth_settings ) || '1' !== $auth_settings['google'] ) &&
2153 - array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && '1' === $auth_settings['advanced_hide_wp_login']
1941 + strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false &&
1942 + array_key_exists( 'cas_auto_login', $auth_settings ) && $auth_settings['cas_auto_login'] === '1' &&
1943 + array_key_exists( 'cas', $auth_settings ) && $auth_settings['cas'] === '1' &&
1944 + ( ! array_key_exists( 'ldap', $auth_settings ) || $auth_settings['ldap'] !== '1' ) &&
1945 + ( ! array_key_exists( 'google', $auth_settings ) || $auth_settings['google'] !== '1' ) &&
1946 + array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && $auth_settings['advanced_hide_wp_login'] === '1'
2154 1947 ) {
2155 1948 wp_redirect( $this->modify_current_url_for_cas_login() );
2156 1949 exit;
2157 1950 }
@@ -2160,45 +1953,15 @@
2160 1953 }
2161 1954
2162 1955
2163 1956 /**
2164 - * Set a unique cookie to add to Google auth nonce to avoid CSRF detection.
2165 - * Note: hook into login_init so this fires at the start of the visit to
2166 - * wp-login.php, but before any html output is started (so setting the
2167 - * cookie header doesn't complain about data already being sent).
2168 - *
2169 - * Action: login_init
2170 - *
2171 - * @return void
2172 - */
2173 - public function login_init__maybe_set_google_nonce_cookie() {
2174 - // Grab plugin settings.
2175 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2176 -
2177 - // If Google logins are enabled, make sure the cookie is set.
2178 - if ( array_key_exists( 'google', $auth_settings ) && '1' === $auth_settings['google'] ) {
2179 - if ( ! isset( $_COOKIE['login_unique'] ) ) {
2180 - $this->cookie_value = md5( rand() );
2181 - setcookie( 'login_unique', $this->cookie_value, time() + 1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
2182 - $_COOKIE['login_unique'] = $this->cookie_value;
2183 - }
2184 - }
2185 - }
2186 -
2187 -
2188 - /**
2189 1957 * Implements hook: do_action( 'wp_login_failed', $username );
2190 1958 * Update the user meta for the user that just failed logging in.
2191 1959 * Keep track of time of last failed attempt and number of failed attempts.
2192 - *
2193 - * Action: wp_login_failed
2194 - *
2195 - * @param string $username Username to update login count for.
2196 - * @return void
2197 1960 */
2198 - public function update_login_failed_count( $username ) {
1961 + function update_login_failed_count( $username ) {
2199 1962 // Grab plugin settings.
2200 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1963 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2201 1964
2202 1965 // Get user trying to log in.
2203 1966 // If this isn't a real user, update the global failed attempt
2204 1967 // variables. We'll use these global variables to institute the
@@ -2206,9 +1969,9 @@
2206 1969 // won't be able to determine which accounts are real by which
2207 1970 // accounts get locked out on multiple invalid attempts.
2208 1971 $user = get_user_by( 'login', $username );
2209 1972
2210 - if ( false !== $user ) {
1973 + if ( $user !== FALSE ) {
2211 1974 $last_attempt = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
2212 1975 $num_attempts = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
2213 1976 } else {
2214 1977 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
@@ -2222,15 +1985,15 @@
2222 1985
2223 1986 // Reset the failed attempt count if the time since the last
2224 1987 // failed attempt is greater than the reset duration.
2225 1988 $time_since_last_fail = time() - $last_attempt;
2226 - $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds.
1989 + $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds
2227 1990 if ( $time_since_last_fail > $reset_duration ) {
2228 1991 $num_attempts = 0;
2229 1992 }
2230 1993
2231 1994 // Set last failed time to now and increment last failed count.
2232 - if ( false !== $user ) {
1995 + if ( $user !== FALSE ) {
2233 1996 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', time() );
2234 1997 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', $num_attempts + 1 );
2235 1998 } else {
2236 1999 update_option( 'auth_settings_advanced_lockouts_time_last_failed', time() );
@@ -2241,16 +2004,16 @@
2241 2004
2242 2005 /**
2243 2006 * When they successfully log in, make sure WordPress users are in the approved list.
2244 2007 *
2245 - * Action: wp_login
2008 + * @action wp_login
2246 2009 *
2247 2010 * @param string $user_login Username of the user logging in.
2248 - * @param object $user WP_User object of the user logging in.
2249 - * @return void
2011 + * @param WP_User $user WP_User object of the user logging in.
2012 + * @return null
2250 2013 */
2251 - public function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2252 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
2014 + function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2015 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
2253 2016 }
2254 2017
2255 2018
2256 2019 /**
@@ -2256,17 +2019,12 @@
2256 2019 /**
2257 2020 * Overwrite the URL for the lost password link on the login form.
2258 2021 * If we're authenticating against an external service, standard
2259 2022 * WordPress password resets won't work.
2260 - *
2261 - * Filter: lostpassword_url
2262 - *
2263 - * @param string $lostpassword_url URL to reset password.
2264 - * @return string URL to reset password.
2265 2023 */
2266 - public function custom_lostpassword_url( $lostpassword_url ) {
2024 + function custom_lostpassword_url( $lostpassword_url ) {
2267 2025 // Grab plugin settings.
2268 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2026 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2269 2027
2270 2028 if (
2271 2029 array_key_exists( 'ldap_lostpassword_url', $auth_settings ) &&
2272 2030 filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_VALIDATE_URL )
@@ -2289,16 +2047,15 @@
2289 2047 /**
2290 2048 * Add a link to this plugin's settings page from the WordPress Plugins page.
2291 2049 * Called from "plugin_action_links" filter in __construct() above.
2292 2050 *
2293 - * Filter: plugin_action_links_authorizer.php
2051 + * @param array $links array of links in the admin sidebar
2294 2052 *
2295 - * @param array $links Admin sidebar links.
2296 - * @return array Admin sidebar links with Authorizer added.
2053 + * @return array of links to show in the admin sidebar.
2297 2054 */
2298 2055 public function plugin_settings_link( $links ) {
2299 - $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2300 - $settings_url = 'settings' === $admin_menu ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2056 + $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2057 + $settings_url = $admin_menu === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2301 2058 array_unshift( $links, '<a href="' . $settings_url . '">' . __( 'Settings', 'authorizer' ) . '</a>' );
2302 2059 return $links;
2303 2060 }
2304 2061
@@ -2306,12 +2063,11 @@
2306 2063 /**
2307 2064 * Add a link to this plugin's network settings page from the WordPress Plugins page.
2308 2065 * Called from "network_admin_plugin_action_links" filter in __construct() above.
2309 2066 *
2310 - * Filter: network_admin_plugin_action_links_authorizer.php
2067 + * @param array $links array of links in the network admin sidebar
2311 2068 *
2312 - * @param array $links Network admin sidebar links.
2313 - * @return array Network admin sidebar links with Authorizer added.
2069 + * @return array of links to show in the network admin sidebar.
2314 2070 */
2315 2071 public function network_admin_plugin_settings_link( $links ) {
2316 2072 $settings_link = '<a href="admin.php?page=authorizer">' . __( 'Network Settings', 'authorizer' ) . '</a>';
2317 2073 array_unshift( $links, $settings_link );
@@ -2319,33 +2075,32 @@
2319 2075 }
2320 2076
2321 2077
2322 2078 /**
2323 - * Create the options page under Dashboard > Settings.
2324 - *
2325 - * Action: admin_menu
2079 + * Create the options page under Dashboard > Settings
2080 + * Run on action hook: admin_menu
2326 2081 */
2327 2082 public function add_plugin_page() {
2328 2083 $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2329 - if ( 'settings' === $admin_menu ) {
2084 + if ( $admin_menu === 'settings' ) {
2330 2085 // @see http://codex.wordpress.org/Function_Reference/add_options_page
2331 2086 add_options_page(
2332 - 'Authorizer',
2333 - 'Authorizer',
2334 - 'create_users',
2335 - 'authorizer',
2336 - array( $this, 'create_admin_page' )
2087 + 'Authorizer', // Page title
2088 + 'Authorizer', // Menu title
2089 + 'create_users', // Capability
2090 + 'authorizer', // Menu slug
2091 + array( $this, 'create_admin_page' ) // function
2337 2092 );
2338 2093 } else {
2339 2094 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
2340 2095 add_menu_page(
2341 - 'Authorizer',
2342 - 'Authorizer',
2343 - 'create_users',
2344 - 'authorizer',
2345 - array( $this, 'create_admin_page' ),
2346 - 'dashicons-groups',
2347 - '99.0018465' // position (decimal is to make overlap with other plugins less likely).
2096 + 'Authorizer', // Page title
2097 + 'Authorizer', // Menu title
2098 + 'create_users', // Capability
2099 + 'authorizer', // Menu slug
2100 + array( $this, 'create_admin_page' ), // callback
2101 + 'dashicons-groups', // icon
2102 + '99.0018465' // position (decimal is to make overlap with other plugins less likely)
2348 2103 );
2349 2104 }
2350 2105 }
2351 2106
@@ -2350,75 +2105,56 @@
2350 2105 }
2351 2106
2352 2107
2353 2108 /**
2354 - * Output the HTML for the options page.
2109 + * Output the HTML for the options page
2355 2110 */
2356 - public function create_admin_page() {
2357 - ?>
2111 + public function create_admin_page() { ?>
2358 2112 <div class="wrap">
2359 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2360 - <form method="post" action="options.php" autocomplete="off">
2361 - <?php
2362 - // This prints out all hidden settings fields.
2113 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2114 + <form method="post" action="options.php" autocomplete="off"><?php
2115 + // This prints out all hidden settings fields
2116 + // @see http://codex.wordpress.org/Function_Reference/settings_fields
2363 2117 settings_fields( 'auth_settings_group' );
2364 - // This prints out all the sections.
2118 + // This prints out all the sections
2119 + // @see http://codex.wordpress.org/Function_Reference/do_settings_sections
2365 2120 do_settings_sections( 'authorizer' );
2366 - submit_button();
2367 - ?>
2121 + submit_button(); ?>
2368 2122 </form>
2369 - </div>
2370 - <?php
2123 + </div><?php
2371 2124 }
2372 2125
2373 2126
2374 2127 /**
2375 2128 * Load external resources on this plugin's options page.
2376 - *
2377 - * Action: load-settings_page_authorizer
2378 - * Action: load-toplevel_page_authorizer
2379 - * Action: admin_head-index.php
2129 + * Run on action hooks: load-settings_page_authorizer, load-toplevel_page_authorizer, admin_head-index.php
2380 2130 */
2381 2131 public function load_options_page() {
2382 2132 wp_enqueue_script(
2383 2133 'authorizer',
2384 2134 plugins_url( 'js/authorizer.js', __FILE__ ),
2385 - array( 'jquery-effects-shake' ), '2.8.7', true
2135 + array( 'jquery-effects-shake' ), '2.3.2', true
2386 2136 );
2387 - wp_localize_script(
2388 - 'authorizer', 'authL10n', array(
2389 - 'baseurl' => get_bloginfo( 'url' ),
2390 - 'saved' => esc_html__( 'Saved', 'authorizer' ),
2391 - 'duplicate' => esc_html__( 'Duplicate', 'authorizer' ),
2392 - 'failed' => esc_html__( 'Failed', 'authorizer' ),
2393 - 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2394 - 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2395 - 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2396 - 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2397 - 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2398 - 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2399 - 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2400 - 'first_page' => esc_html__( 'First page' ),
2401 - 'previous_page' => esc_html__( 'Previous page' ),
2402 - 'next_page' => esc_html__( 'Next page' ),
2403 - 'last_page' => esc_html__( 'Last page' ),
2404 - 'is_network_admin' => is_network_admin() ? '1' : '0',
2405 - )
2406 - );
2137 + wp_localize_script( 'authorizer', 'auth_L10n', array(
2138 + 'baseurl' => get_bloginfo( 'url' ),
2139 + 'saved' => esc_html__( 'Saved', 'authorizer' ),
2140 + 'failed' => esc_html__( 'Failed', 'authorizer' ),
2141 + 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2142 + 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2143 + 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2144 + 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2145 + 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2146 + 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2147 + 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2148 + ));
2407 2149
2408 2150 wp_enqueue_script(
2409 - 'jquery-autogrow-textarea',
2410 - plugins_url( 'vendor/jquery.autogrow-textarea/jquery.autogrow-textarea.js', __FILE__ ),
2411 - array( 'jquery' ), '2.7.0', true
2412 - );
2413 -
2414 - wp_enqueue_script(
2415 2151 'jquery.multi-select',
2416 2152 plugins_url( 'vendor/jquery.multi-select/js/jquery.multi-select.js', __FILE__ ),
2417 2153 array( 'jquery' ), '1.8', true
2418 2154 );
2419 2155
2420 - wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.8.7' );
2156 + wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.3.2' );
2421 2157 wp_enqueue_style( 'authorizer-css' );
2422 2158
2423 2159 wp_register_style( 'jquery-multi-select-css', plugins_url( 'vendor/jquery.multi-select/css/multi-select.css', __FILE__ ), array(), '1.8' );
2424 2160 wp_enqueue_style( 'jquery-multi-select-css' );
@@ -2429,26 +2165,18 @@
2429 2165
2430 2166
2431 2167 /**
2432 2168 * Show custom admin notice.
2433 - *
2434 - * Note: currently unused, but if anywhere we:
2435 - * add_option( 'auth_settings_advanced_admin_notice, 'Your message.' );
2436 - * It will display and then delete that message on the admin dashboard.
2437 - *
2438 - * Filter: admin_notices
2439 - * filter: network_admin_notices
2169 + * Filter: admin_notice
2440 2170 */
2441 - public function show_advanced_admin_notice() {
2171 + function show_advanced_admin_notice() {
2442 2172 $notice = get_option( 'auth_settings_advanced_admin_notice' );
2443 2173 delete_option( 'auth_settings_advanced_admin_notice' );
2444 2174
2445 - if ( $notice && strlen( $notice ) > 0 ) {
2446 - ?>
2175 + if ( $notice && strlen( $notice ) > 0 ) { ?>
2447 2176 <div class="error">
2448 - <p><?php echo wp_kses( $notice, $this->allowed_html ); ?></p>
2449 - </div>
2450 - <?php
2177 + <p><?php echo $notice; ?></p>
2178 + </div><?php
2451 2179 }
2452 2180 }
2453 2181
2454 2182
@@ -2453,11 +2181,9 @@
2453 2181
2454 2182
2455 2183 /**
2456 2184 * Add notices to the top of the options page.
2457 - *
2458 - * Action: load-settings_page_authorizer > admin_notices
2459 - *
2185 + * Run on action hook chain: load-settings_page_authorizer > admin_notices
2460 2186 * Description: Check for invalid settings combinations and show a warning message, e.g.:
2461 2187 * if ( cas url inaccessible ) : ?>
2462 2188 * <div class='updated settings-error'><p>Can't reach CAS server.</p></div>
2463 2189 * <?php endif;
@@ -2463,23 +2189,20 @@
2463 2189 * <?php endif;
2464 2190 */
2465 2191 public function admin_notices() {
2466 2192 // Grab plugin settings.
2467 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2193 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2468 2194
2469 - if ( '1' === $auth_settings['cas'] ) :
2195 + if ( $auth_settings['cas'] === '1' ) :
2470 2196 // Check if provided CAS URL is accessible.
2471 - $protocol = in_array( strval( $auth_settings['cas_port'] ), array( '80', '8080' ), true ) ? 'http' : 'https';
2472 - $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2473 - $legacy_cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint (old; some servers don't register a ./login endpoint, use serviceValidate instead).
2474 - $cas_url = trailingslashit( $cas_url ) . 'serviceValidate'; // Check the specific CAS login endpoint.
2475 - if ( ! $this->url_is_accessible( $cas_url ) && ! $this->url_is_accessible( $legacy_cas_url ) ) :
2476 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2477 - ?>
2478 - <div class='notice notice-warning is-dismissible'>
2479 - <p><?php esc_html_e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo esc_attr( $authorizer_options_url ); ?>&tab=external'><?php esc_html_e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php esc_html_e( 'if you intend to use it.', 'authorizer' ); ?></p>
2480 - </div>
2481 - <?php
2197 + $protocol = in_array( $auth_settings['cas_port'], array( '80', '8080' ) ) ? 'http' : 'https';
2198 + $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2199 + $cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint
2200 + if ( ! $this->url_is_accessible( $cas_url ) ) :
2201 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2202 + ?><div class='notice notice-warning is-dismissible'>
2203 + <p><?php _e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo $authorizer_options_url; ?>&tab=external'><?php _e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php _e( 'if you intend to use it.', 'authorizer' ); ?></p>
2204 + </div><?php
2482 2205 endif;
2483 2206 endif;
2484 2207 }
2485 2208
@@ -2484,437 +2207,399 @@
2484 2207 }
2485 2208
2486 2209
2487 2210 /**
2488 - * Create sections and options.
2489 - *
2490 - * Action: admin_init
2211 + * Create sections and options
2212 + * Run on action hook: admin_init
2491 2213 */
2492 2214 public function page_init() {
2493 - /**
2494 - * Create one setting that holds all the options (array).
2495 - *
2496 - * @see http://codex.wordpress.org/Function_Reference/register_setting
2497 - * @see http://codex.wordpress.org/Function_Reference/add_settings_section
2498 - * @see http://codex.wordpress.org/Function_Reference/add_settings_field
2499 - */
2215 + // Create one setting that holds all the options (array)
2216 + // @see http://codex.wordpress.org/Function_Reference/register_setting
2217 + // @see http://codex.wordpress.org/Function_Reference/add_settings_section
2218 + // @see http://codex.wordpress.org/Function_Reference/add_settings_field
2500 2219 register_setting(
2501 - 'auth_settings_group',
2502 - 'auth_settings',
2503 - array( $this, 'sanitize_options' )
2220 + 'auth_settings_group', // Option group
2221 + 'auth_settings', // Option name
2222 + array( $this, 'sanitize_options' ) // Sanitize callback
2504 2223 );
2505 2224
2506 2225 add_settings_section(
2507 - 'auth_settings_tabs',
2508 - '',
2509 - array( $this, 'print_section_info_tabs' ),
2510 - 'authorizer'
2226 + 'auth_settings_tabs', // HTML element ID
2227 + '', // HTML element Title
2228 + array( $this, 'print_section_info_tabs' ), // Callback (echos section content)
2229 + 'authorizer' // Page this section is shown on (slug)
2511 2230 );
2512 2231
2513 - // Create Access Lists section.
2232 + // Create Access Lists section
2514 2233 add_settings_section(
2515 - 'auth_settings_lists',
2516 - '',
2517 - array( $this, 'print_section_info_access_lists' ),
2518 - 'authorizer'
2234 + 'auth_settings_lists', // HTML element ID
2235 + '', // HTML element Title
2236 + array( $this, 'print_section_info_access_lists' ), // Callback (echos section content)
2237 + 'authorizer' // Page this section is shown on (slug)
2519 2238 );
2520 2239
2521 - // Create Login Access section.
2240 + // Create Login Access section
2522 2241 add_settings_section(
2523 - 'auth_settings_access_login',
2524 - '',
2525 - array( $this, 'print_section_info_access_login' ),
2526 - 'authorizer'
2242 + 'auth_settings_access_login', // HTML element ID
2243 + '', // HTML element Title
2244 + array( $this, 'print_section_info_access_login' ), // Callback (echos section content)
2245 + 'authorizer' // Page this section is shown on (slug)
2527 2246 );
2528 2247 add_settings_field(
2529 - 'auth_settings_access_who_can_login',
2530 - __( 'Who can log into the site?', 'authorizer' ),
2531 - array( $this, 'print_radio_auth_access_who_can_login' ),
2532 - 'authorizer',
2533 - 'auth_settings_access_login'
2248 + 'auth_settings_access_who_can_login', // HTML element ID
2249 + __( 'Who can log into the site?', 'authorizer' ), // HTML element Title
2250 + array( $this, 'print_radio_auth_access_who_can_login' ), // Callback (echos form element)
2251 + 'authorizer', // Page this setting is shown on (slug)
2252 + 'auth_settings_access_login' // Section this setting is shown on
2534 2253 );
2535 2254 add_settings_field(
2536 - 'auth_settings_access_role_receive_pending_emails',
2537 - __( 'Which role should receive email notifications about pending users?', 'authorizer' ),
2538 - array( $this, 'print_select_auth_access_role_receive_pending_emails' ),
2539 - 'authorizer',
2540 - 'auth_settings_access_login'
2255 + 'auth_settings_access_role_receive_pending_emails', // HTML element ID
2256 + __( 'Which role should receive email notifications about pending users?', 'authorizer' ), // HTML element Title
2257 + array( $this, 'print_select_auth_access_role_receive_pending_emails' ), // Callback (echos form element)
2258 + 'authorizer', // Page this setting is shown on (slug)
2259 + 'auth_settings_access_login' // Section this setting is shown on
2541 2260 );
2542 2261 add_settings_field(
2543 - 'auth_settings_access_pending_redirect_to_message',
2544 - __( 'What message should pending users see after attempting to log in?', 'authorizer' ),
2545 - array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ),
2546 - 'authorizer',
2547 - 'auth_settings_access_login'
2262 + 'auth_settings_access_pending_redirect_to_message', // HTML element ID
2263 + __( 'What message should pending users see after attempting to log in?', 'authorizer' ), // HTML element Title
2264 + array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ), // Callback (echos form element)
2265 + 'authorizer', // Page this setting is shown on (slug)
2266 + 'auth_settings_access_login' // Section this setting is shown on
2548 2267 );
2549 2268 add_settings_field(
2550 - 'auth_settings_access_blocked_redirect_to_message',
2551 - __( 'What message should blocked users see after attempting to log in?', 'authorizer' ),
2552 - array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ),
2553 - 'authorizer',
2554 - 'auth_settings_access_login'
2269 + 'auth_settings_access_blocked_redirect_to_message', // HTML element ID
2270 + __( 'What message should blocked users see after attempting to log in?', 'authorizer' ), // HTML element Title
2271 + array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ), // Callback (echos form element)
2272 + 'authorizer', // Page this setting is shown on (slug)
2273 + 'auth_settings_access_login' // Section this setting is shown on
2555 2274 );
2556 2275 add_settings_field(
2557 - 'auth_settings_access_should_email_approved_users',
2558 - __( 'Send welcome email to new approved users?', 'authorizer' ),
2559 - array( $this, 'print_checkbox_auth_access_should_email_approved_users' ),
2560 - 'authorizer',
2561 - 'auth_settings_access_login'
2276 + 'auth_settings_access_should_email_approved_users', // HTML element ID
2277 + __( 'Send welcome email to new approved users?', 'authorizer' ), // HTML element Title
2278 + array( $this, 'print_checkbox_auth_access_should_email_approved_users' ), // Callback (echos form element)
2279 + 'authorizer', // Page this setting is shown on (slug)
2280 + 'auth_settings_access_login' // Section this setting is shown on
2562 2281 );
2563 2282 add_settings_field(
2564 - 'auth_settings_access_email_approved_users_subject',
2565 - __( 'Welcome email subject', 'authorizer' ),
2566 - array( $this, 'print_text_auth_access_email_approved_users_subject' ),
2567 - 'authorizer',
2568 - 'auth_settings_access_login'
2283 + 'auth_settings_access_email_approved_users_subject', // HTML element ID
2284 + __( 'Welcome email subject', 'authorizer' ), // HTML element Title
2285 + array( $this, 'print_text_auth_access_email_approved_users_subject' ), // Callback (echos form element)
2286 + 'authorizer', // Page this setting is shown on (slug)
2287 + 'auth_settings_access_login' // Section this setting is shown on
2569 2288 );
2570 2289 add_settings_field(
2571 - 'auth_settings_access_email_approved_users_body',
2572 - __( 'Welcome email body', 'authorizer' ),
2573 - array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ),
2574 - 'authorizer',
2575 - 'auth_settings_access_login'
2290 + 'auth_settings_access_email_approved_users_body', // HTML element ID
2291 + __( 'Welcome email body', 'authorizer' ), // HTML element Title
2292 + array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ), // Callback (echos form element)
2293 + 'authorizer', // Page this setting is shown on (slug)
2294 + 'auth_settings_access_login' // Section this setting is shown on
2576 2295 );
2577 2296
2578 - // Create Public Access section.
2297 +
2298 + // Create Public Access section
2579 2299 add_settings_section(
2580 - 'auth_settings_access_public',
2581 - '',
2582 - array( $this, 'print_section_info_access_public' ),
2583 - 'authorizer'
2300 + 'auth_settings_access_public', // HTML element ID
2301 + '', // HTML element Title
2302 + array( $this, 'print_section_info_access_public' ), // Callback (echos section content)
2303 + 'authorizer' // Page this section is shown on (slug)
2584 2304 );
2585 2305 add_settings_field(
2586 - 'auth_settings_access_who_can_view',
2587 - __( 'Who can view the site?', 'authorizer' ),
2588 - array( $this, 'print_radio_auth_access_who_can_view' ),
2589 - 'authorizer',
2590 - 'auth_settings_access_public'
2306 + 'auth_settings_access_who_can_view', // HTML element ID
2307 + __( 'Who can view the site?', 'authorizer' ), // HTML element Title
2308 + array( $this, 'print_radio_auth_access_who_can_view' ), // Callback (echos form element)
2309 + 'authorizer', // Page this setting is shown on (slug)
2310 + 'auth_settings_access_public' // Section this setting is shown on
2591 2311 );
2592 2312 add_settings_field(
2593 - 'auth_settings_access_public_pages',
2594 - __( 'What pages (if any) should be available to everyone?', 'authorizer' ),
2595 - array( $this, 'print_multiselect_auth_access_public_pages' ),
2596 - 'authorizer',
2597 - 'auth_settings_access_public'
2313 + 'auth_settings_access_public_pages', // HTML element ID
2314 + __( 'What pages (if any) should be available to everyone?', 'authorizer' ), // HTML element Title
2315 + array( $this, 'print_multiselect_auth_access_public_pages' ), // Callback (echos form element)
2316 + 'authorizer', // Page this setting is shown on (slug)
2317 + 'auth_settings_access_public' // Section this setting is shown on
2598 2318 );
2599 2319 add_settings_field(
2600 - 'auth_settings_access_redirect',
2601 - __( 'What happens to people without access when they visit a private page?', 'authorizer' ),
2602 - array( $this, 'print_radio_auth_access_redirect' ),
2603 - 'authorizer',
2604 - 'auth_settings_access_public'
2320 + 'auth_settings_access_redirect', // HTML element ID
2321 + __( 'What happens to people without access when they visit a private page?', 'authorizer' ), // HTML element Title
2322 + array( $this, 'print_radio_auth_access_redirect' ), // Callback (echos form element)
2323 + 'authorizer', // Page this setting is shown on (slug)
2324 + 'auth_settings_access_public' // Section this setting is shown on
2605 2325 );
2606 2326 add_settings_field(
2607 - 'auth_settings_access_public_warning',
2608 - __( 'What happens to people without access when they visit a public page?', 'authorizer' ),
2609 - array( $this, 'print_radio_auth_access_public_warning' ),
2610 - 'authorizer',
2611 - 'auth_settings_access_public'
2327 + 'auth_settings_access_public_warning', // HTML element ID
2328 + __( 'What happens to people without access when they visit a public page?', 'authorizer' ), // HTML element Title
2329 + array( $this, 'print_radio_auth_access_public_warning' ), // Callback (echos form element)
2330 + 'authorizer', // Page this setting is shown on (slug)
2331 + 'auth_settings_access_public' // Section this setting is shown on
2612 2332 );
2613 2333 add_settings_field(
2614 - 'auth_settings_access_redirect_to_message',
2615 - __( 'What message should people without access see?', 'authorizer' ),
2616 - array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ),
2617 - 'authorizer',
2618 - 'auth_settings_access_public'
2334 + 'auth_settings_access_redirect_to_message', // HTML element ID
2335 + __( 'What message should people without access see?', 'authorizer' ), // HTML element Title
2336 + array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ), // Callback (echos form element)
2337 + 'authorizer', // Page this setting is shown on (slug)
2338 + 'auth_settings_access_public' // Section this setting is shown on
2619 2339 );
2620 2340
2621 - // Create External Service Settings section.
2341 + // Create External Service Settings section
2622 2342 add_settings_section(
2623 - 'auth_settings_external',
2624 - '',
2625 - array( $this, 'print_section_info_external' ),
2626 - 'authorizer'
2343 + 'auth_settings_external', // HTML element ID
2344 + '', // HTML element Title
2345 + array( $this, 'print_section_info_external' ), // Callback (echos section content)
2346 + 'authorizer' // Page this section is shown on (slug)
2627 2347 );
2628 2348 add_settings_field(
2629 - 'auth_settings_access_default_role',
2630 - __( 'Default role for new users', 'authorizer' ),
2631 - array( $this, 'print_select_auth_access_default_role' ),
2632 - 'authorizer',
2633 - 'auth_settings_external'
2349 + 'auth_settings_access_default_role', // HTML element ID
2350 + __( 'Default role for new users', 'authorizer' ), // HTML element Title
2351 + array( $this, 'print_select_auth_access_default_role' ), // Callback (echos form element)
2352 + 'authorizer', // Page this setting is shown on (slug)
2353 + 'auth_settings_external' // Section this setting is shown on
2634 2354 );
2635 2355 add_settings_field(
2636 - 'auth_settings_external_google',
2637 - __( 'Google Logins', 'authorizer' ),
2638 - array( $this, 'print_checkbox_auth_external_google' ),
2639 - 'authorizer',
2640 - 'auth_settings_external'
2356 + 'auth_settings_external_google', // HTML element ID
2357 + __( 'Google Logins', 'authorizer' ), // HTML element Title
2358 + array( $this, 'print_checkbox_auth_external_google' ), // Callback (echos form element)
2359 + 'authorizer', // Page this setting is shown on (slug)
2360 + 'auth_settings_external' // Section this setting is shown on
2641 2361 );
2642 2362 add_settings_field(
2643 - 'auth_settings_google_clientid',
2644 - __( 'Google Client ID', 'authorizer' ),
2645 - array( $this, 'print_text_google_clientid' ),
2646 - 'authorizer',
2647 - 'auth_settings_external'
2363 + 'auth_settings_google_clientid', // HTML element ID
2364 + __( 'Google Client ID', 'authorizer' ), // HTML element Title
2365 + array( $this, 'print_text_google_clientid' ), // Callback (echos form element)
2366 + 'authorizer', // Page this setting is shown on (slug)
2367 + 'auth_settings_external' // Section this setting is shown on
2648 2368 );
2649 2369 add_settings_field(
2650 - 'auth_settings_google_clientsecret',
2651 - __( 'Google Client Secret', 'authorizer' ),
2652 - array( $this, 'print_text_google_clientsecret' ),
2653 - 'authorizer',
2654 - 'auth_settings_external'
2370 + 'auth_settings_google_clientsecret', // HTML element ID
2371 + __( 'Google Client Secret', 'authorizer' ), // HTML element Title
2372 + array( $this, 'print_text_google_clientsecret' ), // Callback (echos form element)
2373 + 'authorizer', // Page this setting is shown on (slug)
2374 + 'auth_settings_external' // Section this setting is shown on
2655 2375 );
2656 2376 add_settings_field(
2657 - 'auth_settings_google_hosteddomain',
2658 - __( 'Google Hosted Domain', 'authorizer' ),
2659 - array( $this, 'print_text_google_hosteddomain' ),
2660 - 'authorizer',
2661 - 'auth_settings_external'
2377 + 'auth_settings_google_hosteddomain', // HTML element ID
2378 + __( 'Google Hosted Domain', 'authorizer' ), // HTML element Title
2379 + array( $this, 'print_text_google_hosteddomain' ), // Callback (echos form element)
2380 + 'authorizer', // Page this setting is shown on (slug)
2381 + 'auth_settings_external' // Section this setting is shown on
2662 2382 );
2663 2383 add_settings_field(
2664 - 'auth_settings_external_cas',
2665 - __( 'CAS Logins', 'authorizer' ),
2666 - array( $this, 'print_checkbox_auth_external_cas' ),
2667 - 'authorizer',
2668 - 'auth_settings_external'
2384 + 'auth_settings_external_cas', // HTML element ID
2385 + __( 'CAS Logins', 'authorizer' ), // HTML element Title
2386 + array( $this, 'print_checkbox_auth_external_cas' ), // Callback (echos form element)
2387 + 'authorizer', // Page this setting is shown on (slug)
2388 + 'auth_settings_external' // Section this setting is shown on
2669 2389 );
2670 2390 add_settings_field(
2671 - 'auth_settings_cas_custom_label',
2672 - __( 'CAS custom label', 'authorizer' ),
2673 - array( $this, 'print_text_cas_custom_label' ),
2674 - 'authorizer',
2675 - 'auth_settings_external'
2391 + 'auth_settings_cas_custom_label', // HTML element ID
2392 + __( 'CAS custom label', 'authorizer' ), // HTML element Title
2393 + array( $this, 'print_text_cas_custom_label' ), // Callback (echos form element)
2394 + 'authorizer', // Page this setting is shown on (slug)
2395 + 'auth_settings_external' // Section this setting is shown on
2676 2396 );
2677 2397 add_settings_field(
2678 - 'auth_settings_cas_host',
2679 - __( 'CAS server hostname', 'authorizer' ),
2680 - array( $this, 'print_text_cas_host' ),
2681 - 'authorizer',
2682 - 'auth_settings_external'
2398 + 'auth_settings_cas_host', // HTML element ID
2399 + __( 'CAS server hostname', 'authorizer' ), // HTML element Title
2400 + array( $this, 'print_text_cas_host' ), // Callback (echos form element)
2401 + 'authorizer', // Page this setting is shown on (slug)
2402 + 'auth_settings_external' // Section this setting is shown on
2683 2403 );
2684 2404 add_settings_field(
2685 - 'auth_settings_cas_port',
2686 - __( 'CAS server port', 'authorizer' ),
2687 - array( $this, 'print_text_cas_port' ),
2688 - 'authorizer',
2689 - 'auth_settings_external'
2405 + 'auth_settings_cas_port', // HTML element ID
2406 + __( 'CAS server port', 'authorizer' ), // HTML element Title
2407 + array( $this, 'print_text_cas_port' ), // Callback (echos form element)
2408 + 'authorizer', // Page this setting is shown on (slug)
2409 + 'auth_settings_external' // Section this setting is shown on
2690 2410 );
2691 2411 add_settings_field(
2692 - 'auth_settings_cas_path',
2693 - __( 'CAS server path/context', 'authorizer' ),
2694 - array( $this, 'print_text_cas_path' ),
2695 - 'authorizer',
2696 - 'auth_settings_external'
2412 + 'auth_settings_cas_path', // HTML element ID
2413 + __( 'CAS server path/context', 'authorizer' ), // HTML element Title
2414 + array( $this, 'print_text_cas_path' ), // Callback (echos form element)
2415 + 'authorizer', // Page this setting is shown on (slug)
2416 + 'auth_settings_external' // Section this setting is shown on
2697 2417 );
2698 2418 add_settings_field(
2699 - 'auth_settings_cas_version',
2700 - 'CAS server version',
2701 - array( $this, 'print_select_cas_version' ),
2702 - 'authorizer',
2703 - 'auth_settings_external'
2419 + 'auth_settings_cas_version', // HTML element ID
2420 + 'CAS server version', // HTML element Title
2421 + array( $this, 'print_select_cas_version' ), // Callback (echos form element)
2422 + 'authorizer', // Page this setting is shown on (slug)
2423 + 'auth_settings_external' // Section this setting is shown on
2704 2424 );
2705 2425 add_settings_field(
2706 - 'auth_settings_cas_attr_email',
2707 - __( 'CAS attribute containing email address', 'authorizer' ),
2708 - array( $this, 'print_text_cas_attr_email' ),
2709 - 'authorizer',
2710 - 'auth_settings_external'
2426 + 'auth_settings_cas_attr_email', // HTML element ID
2427 + __( 'CAS attribute containing email address', 'authorizer' ), // HTML element Title
2428 + array( $this, 'print_text_cas_attr_email' ), // Callback (echos form element)
2429 + 'authorizer', // Page this setting is shown on (slug)
2430 + 'auth_settings_external' // Section this setting is shown on
2711 2431 );
2712 2432 add_settings_field(
2713 - 'auth_settings_cas_attr_first_name',
2714 - __( 'CAS attribute containing first name', 'authorizer' ),
2715 - array( $this, 'print_text_cas_attr_first_name' ),
2716 - 'authorizer',
2717 - 'auth_settings_external'
2433 + 'auth_settings_cas_attr_first_name', // HTML element ID
2434 + __( 'CAS attribute containing first name', 'authorizer' ), // HTML element Title
2435 + array( $this, 'print_text_cas_attr_first_name' ), // Callback (echos form element)
2436 + 'authorizer', // Page this setting is shown on (slug)
2437 + 'auth_settings_external' // Section this setting is shown on
2718 2438 );
2719 2439 add_settings_field(
2720 - 'auth_settings_cas_attr_last_name',
2721 - __( 'CAS attribute containing last name', 'authorizer' ),
2722 - array( $this, 'print_text_cas_attr_last_name' ),
2723 - 'authorizer',
2724 - 'auth_settings_external'
2440 + 'auth_settings_cas_attr_last_name', // HTML element ID
2441 + __( 'CAS attribute containing last name', 'authorizer' ), // HTML element Title
2442 + array( $this, 'print_text_cas_attr_last_name' ), // Callback (echos form element)
2443 + 'authorizer', // Page this setting is shown on (slug)
2444 + 'auth_settings_external' // Section this setting is shown on
2725 2445 );
2726 2446 add_settings_field(
2727 - 'auth_settings_cas_attr_update_on_login',
2728 - __( 'CAS attribute update', 'authorizer' ),
2729 - array( $this, 'print_checkbox_cas_attr_update_on_login' ),
2730 - 'authorizer',
2731 - 'auth_settings_external'
2447 + 'auth_settings_cas_attr_update_on_login', // HTML element ID
2448 + __( 'CAS attribute update', 'authorizer' ), // HTML element Title
2449 + array( $this, 'print_checkbox_cas_attr_update_on_login' ), // Callback (echos form element)
2450 + 'authorizer', // Page this setting is shown on (slug)
2451 + 'auth_settings_external' // Section this setting is shown on
2732 2452 );
2733 2453 add_settings_field(
2734 - 'auth_settings_cas_auto_login',
2735 - __( 'CAS automatic login', 'authorizer' ),
2736 - array( $this, 'print_checkbox_cas_auto_login' ),
2737 - 'authorizer',
2738 - 'auth_settings_external'
2454 + 'auth_settings_cas_auto_login', // HTML element ID
2455 + __( 'CAS automatic login', 'authorizer' ), // HTML element Title
2456 + array( $this, 'print_checkbox_cas_auto_login' ), // Callback (echos form element)
2457 + 'authorizer', // Page this setting is shown on (slug)
2458 + 'auth_settings_external' // Section this setting is shown on
2739 2459 );
2740 2460 add_settings_field(
2741 - 'auth_settings_cas_link_on_username',
2742 - __( 'CAS users linked by username', 'authorizer' ),
2743 - array( $this, 'print_checkbox_cas_link_on_username' ),
2744 - 'authorizer',
2745 - 'auth_settings_external'
2461 + 'auth_settings_external_ldap', // HTML element ID
2462 + __( 'LDAP Logins', 'authorizer' ), // HTML element Title
2463 + array( $this, 'print_checkbox_auth_external_ldap' ), // Callback (echos form element)
2464 + 'authorizer', // Page this setting is shown on (slug)
2465 + 'auth_settings_external' // Section this setting is shown on
2746 2466 );
2747 2467 add_settings_field(
2748 - 'auth_settings_external_ldap',
2749 - __( 'LDAP Logins', 'authorizer' ),
2750 - array( $this, 'print_checkbox_auth_external_ldap' ),
2751 - 'authorizer',
2752 - 'auth_settings_external'
2468 + 'auth_settings_ldap_host', // HTML element ID
2469 + __( 'LDAP Host', 'authorizer' ), // HTML element Title
2470 + array( $this, 'print_text_ldap_host' ), // Callback (echos form element)
2471 + 'authorizer', // Page this setting is shown on (slug)
2472 + 'auth_settings_external' // Section this setting is shown on
2753 2473 );
2754 2474 add_settings_field(
2755 - 'auth_settings_ldap_host',
2756 - __( 'LDAP Host', 'authorizer' ),
2757 - array( $this, 'print_text_ldap_host' ),
2758 - 'authorizer',
2759 - 'auth_settings_external'
2475 + 'auth_settings_ldap_port', // HTML element ID
2476 + __( 'LDAP Port', 'authorizer' ), // HTML element Title
2477 + array( $this, 'print_text_ldap_port' ), // Callback (echos form element)
2478 + 'authorizer', // Page this setting is shown on (slug)
2479 + 'auth_settings_external' // Section this setting is shown on
2760 2480 );
2761 2481 add_settings_field(
2762 - 'auth_settings_ldap_port',
2763 - __( 'LDAP Port', 'authorizer' ),
2764 - array( $this, 'print_text_ldap_port' ),
2765 - 'authorizer',
2766 - 'auth_settings_external'
2482 + 'auth_settings_ldap_tls', // HTML element ID
2483 + __( 'Secure Connection (TLS)', 'authorizer' ), // HTML element Title
2484 + array( $this, 'print_checkbox_ldap_tls' ), // Callback (echos form element)
2485 + 'authorizer', // Page this setting is shown on (slug)
2486 + 'auth_settings_external' // Section this setting is shown on
2767 2487 );
2768 2488 add_settings_field(
2769 - 'auth_settings_ldap_tls',
2770 - __( 'Use TLS', 'authorizer' ),
2771 - array( $this, 'print_checkbox_ldap_tls' ),
2772 - 'authorizer',
2773 - 'auth_settings_external'
2489 + 'auth_settings_ldap_search_base', // HTML element ID
2490 + __( 'LDAP Search Base', 'authorizer' ), // HTML element Title
2491 + array( $this, 'print_text_ldap_search_base' ), // Callback (echos form element)
2492 + 'authorizer', // Page this setting is shown on (slug)
2493 + 'auth_settings_external' // Section this setting is shown on
2774 2494 );
2775 2495 add_settings_field(
2776 - 'auth_settings_ldap_search_base',
2777 - __( 'LDAP Search Base', 'authorizer' ),
2778 - array( $this, 'print_text_ldap_search_base' ),
2779 - 'authorizer',
2780 - 'auth_settings_external'
2496 + 'auth_settings_ldap_uid', // HTML element ID
2497 + __( 'LDAP attribute containing username', 'authorizer' ), // HTML element Title
2498 + array( $this, 'print_text_ldap_uid' ), // Callback (echos form element)
2499 + 'authorizer', // Page this setting is shown on (slug)
2500 + 'auth_settings_external' // Section this setting is shown on
2781 2501 );
2782 2502 add_settings_field(
2783 - 'auth_settings_ldap_uid',
2784 - __( 'LDAP attribute containing username', 'authorizer' ),
2785 - array( $this, 'print_text_ldap_uid' ),
2786 - 'authorizer',
2787 - 'auth_settings_external'
2503 + 'auth_settings_ldap_attr_email', // HTML element ID
2504 + __( 'LDAP attribute containing email address', 'authorizer' ), // HTML element Title
2505 + array( $this, 'print_text_ldap_attr_email' ), // Callback (echos form element)
2506 + 'authorizer', // Page this setting is shown on (slug)
2507 + 'auth_settings_external' // Section this setting is shown on
2788 2508 );
2789 2509 add_settings_field(
2790 - 'auth_settings_ldap_attr_email',
2791 - __( 'LDAP attribute containing email address', 'authorizer' ),
2792 - array( $this, 'print_text_ldap_attr_email' ),
2793 - 'authorizer',
2794 - 'auth_settings_external'
2510 + 'auth_settings_ldap_user', // HTML element ID
2511 + __( 'LDAP Directory User', 'authorizer' ), // HTML element Title
2512 + array( $this, 'print_text_ldap_user' ), // Callback (echos form element)
2513 + 'authorizer', // Page this setting is shown on (slug)
2514 + 'auth_settings_external' // Section this setting is shown on
2795 2515 );
2796 2516 add_settings_field(
2797 - 'auth_settings_ldap_user',
2798 - __( 'LDAP Directory User', 'authorizer' ),
2799 - array( $this, 'print_text_ldap_user' ),
2800 - 'authorizer',
2801 - 'auth_settings_external'
2517 + 'auth_settings_ldap_password', // HTML element ID
2518 + __( 'LDAP Directory User Password', 'authorizer' ), // HTML element Title
2519 + array( $this, 'print_password_ldap_password' ), // Callback (echos form element)
2520 + 'authorizer', // Page this setting is shown on (slug)
2521 + 'auth_settings_external' // Section this setting is shown on
2802 2522 );
2803 2523 add_settings_field(
2804 - 'auth_settings_ldap_password',
2805 - __( 'LDAP Directory User Password', 'authorizer' ),
2806 - array( $this, 'print_password_ldap_password' ),
2807 - 'authorizer',
2808 - 'auth_settings_external'
2524 + 'auth_settings_ldap_lostpassword_url', // HTML element ID
2525 + __( 'Custom lost password URL', 'authorizer' ), // HTML element Title
2526 + array( $this, 'print_text_ldap_lostpassword_url' ), // Callback (echos form element)
2527 + 'authorizer', // Page this setting is shown on (slug)
2528 + 'auth_settings_external' // Section this setting is shown on
2809 2529 );
2810 2530 add_settings_field(
2811 - 'auth_settings_ldap_lostpassword_url',
2812 - __( 'Custom lost password URL', 'authorizer' ),
2813 - array( $this, 'print_text_ldap_lostpassword_url' ),
2814 - 'authorizer',
2815 - 'auth_settings_external'
2531 + 'auth_settings_ldap_attr_first_name', // HTML element ID
2532 + __( 'LDAP attribute containing first name', 'authorizer' ), // HTML element Title
2533 + array( $this, 'print_text_ldap_attr_first_name' ), // Callback (echos form element)
2534 + 'authorizer', // Page this setting is shown on (slug)
2535 + 'auth_settings_external' // Section this setting is shown on
2816 2536 );
2817 2537 add_settings_field(
2818 - 'auth_settings_ldap_attr_first_name',
2819 - __( 'LDAP attribute containing first name', 'authorizer' ),
2820 - array( $this, 'print_text_ldap_attr_first_name' ),
2821 - 'authorizer',
2822 - 'auth_settings_external'
2538 + 'auth_settings_ldap_attr_last_name', // HTML element ID
2539 + __( 'LDAP attribute containing last name', 'authorizer' ), // HTML element Title
2540 + array( $this, 'print_text_ldap_attr_last_name' ), // Callback (echos form element)
2541 + 'authorizer', // Page this setting is shown on (slug)
2542 + 'auth_settings_external' // Section this setting is shown on
2823 2543 );
2824 2544 add_settings_field(
2825 - 'auth_settings_ldap_attr_last_name',
2826 - __( 'LDAP attribute containing last name', 'authorizer' ),
2827 - array( $this, 'print_text_ldap_attr_last_name' ),
2828 - 'authorizer',
2829 - 'auth_settings_external'
2545 + 'auth_settings_ldap_attr_update_on_login', // HTML element ID
2546 + __( 'LDAP attribute update', 'authorizer' ), // HTML element Title
2547 + array( $this, 'print_checkbox_ldap_attr_update_on_login' ), // Callback (echos form element)
2548 + 'authorizer', // Page this setting is shown on (slug)
2549 + 'auth_settings_external' // Section this setting is shown on
2830 2550 );
2831 - add_settings_field(
2832 - 'auth_settings_ldap_attr_update_on_login',
2833 - __( 'LDAP attribute update', 'authorizer' ),
2834 - array( $this, 'print_checkbox_ldap_attr_update_on_login' ),
2835 - 'authorizer',
2836 - 'auth_settings_external'
2837 - );
2838 2551
2839 - // Create Advanced Settings section.
2552 + // Create Advanced Settings section
2840 2553 add_settings_section(
2841 - 'auth_settings_advanced',
2842 - '',
2843 - array( $this, 'print_section_info_advanced' ),
2844 - 'authorizer'
2554 + 'auth_settings_advanced', // HTML element ID
2555 + '', // HTML element Title
2556 + array( $this, 'print_section_info_advanced' ), // Callback (echos section content)
2557 + 'authorizer' // Page this section is shown on (slug)
2845 2558 );
2846 2559 add_settings_field(
2847 - 'auth_settings_advanced_lockouts',
2848 - __( 'Limit invalid login attempts', 'authorizer' ),
2849 - array( $this, 'print_text_auth_advanced_lockouts' ),
2850 - 'authorizer',
2851 - 'auth_settings_advanced'
2560 + 'auth_settings_advanced_lockouts', // HTML element ID
2561 + __( 'Limit invalid login attempts', 'authorizer' ), // HTML element Title
2562 + array( $this, 'print_text_auth_advanced_lockouts' ), // Callback (echos form element)
2563 + 'authorizer', // Page this setting is shown on (slug)
2564 + 'auth_settings_advanced' // Section this setting is shown on
2852 2565 );
2853 2566 add_settings_field(
2854 - 'auth_settings_advanced_hide_wp_login',
2855 - __( 'Hide WordPress Login', 'authorizer' ),
2856 - array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ),
2857 - 'authorizer',
2858 - 'auth_settings_advanced'
2567 + 'auth_settings_advanced_hide_wp_login', // HTML element ID
2568 + __( 'Hide WordPress Login', 'authorizer' ), // HTML element Title
2569 + array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ), // Callback (echos form element)
2570 + 'authorizer', // Page this setting is shown on (slug)
2571 + 'auth_settings_advanced' // Section this setting is shown on
2859 2572 );
2860 2573 add_settings_field(
2861 - 'auth_settings_advanced_branding',
2862 - __( 'Custom WordPress login branding', 'authorizer' ),
2863 - array( $this, 'print_radio_auth_advanced_branding' ),
2864 - 'authorizer',
2865 - 'auth_settings_advanced'
2574 + 'auth_settings_advanced_branding', // HTML element ID
2575 + __( 'Custom WordPress login branding', 'authorizer' ), // HTML element Title
2576 + array( $this, 'print_radio_auth_advanced_branding' ), // Callback (echos form element)
2577 + 'authorizer', // Page this setting is shown on (slug)
2578 + 'auth_settings_advanced' // Section this setting is shown on
2866 2579 );
2867 2580 add_settings_field(
2868 - 'auth_settings_advanced_admin_menu',
2869 - __( 'Authorizer admin menu item location', 'authorizer' ),
2870 - array( $this, 'print_radio_auth_advanced_admin_menu' ),
2871 - 'authorizer',
2872 - 'auth_settings_advanced'
2581 + 'auth_settings_advanced_admin_menu', // HTML element ID
2582 + __( 'Authorizer admin menu item location', 'authorizer' ), // HTML element Title
2583 + array( $this, 'print_radio_auth_advanced_admin_menu' ), // Callback (echos form element)
2584 + 'authorizer', // Page this setting is shown on (slug)
2585 + 'auth_settings_advanced' // Section this setting is shown on
2873 2586 );
2874 2587 add_settings_field(
2875 - 'auth_settings_advanced_usermeta',
2876 - __( 'Show custom usermeta in user list', 'authorizer' ),
2877 - array( $this, 'print_select_auth_advanced_usermeta' ),
2878 - 'authorizer',
2879 - 'auth_settings_advanced'
2588 + 'auth_settings_advanced_usermeta', // HTML element ID
2589 + __( 'Show custom usermeta in user list', 'authorizer' ), // HTML element Title
2590 + array( $this, 'print_select_auth_advanced_usermeta' ), // Callback (echos form element)
2591 + 'authorizer', // Page this setting is shown on (slug)
2592 + 'auth_settings_advanced' // Section this setting is shown on
2880 2593 );
2881 - add_settings_field(
2882 - 'auth_settings_advanced_users_per_page',
2883 - __( 'Number of users per page', 'authorizer' ),
2884 - array( $this, 'print_text_auth_advanced_users_per_page' ),
2885 - 'authorizer',
2886 - 'auth_settings_advanced'
2887 - );
2888 - add_settings_field(
2889 - 'auth_settings_advanced_users_sort_by',
2890 - __( 'Approved users sort method', 'authorizer' ),
2891 - array( $this, 'print_select_auth_advanced_users_sort_by' ),
2892 - 'authorizer',
2893 - 'auth_settings_advanced'
2894 - );
2895 - add_settings_field(
2896 - 'auth_settings_advanced_users_sort_order',
2897 - __( 'Approved users sort order', 'authorizer' ),
2898 - array( $this, 'print_select_auth_advanced_users_sort_order' ),
2899 - 'authorizer',
2900 - 'auth_settings_advanced'
2901 - );
2902 - add_settings_field(
2903 - 'auth_settings_advanced_widget_enabled',
2904 - __( 'Show dashboard widget to admin users', 'authorizer' ),
2905 - array( $this, 'print_checkbox_auth_advanced_widget_enabled' ),
2906 - 'authorizer',
2907 - 'auth_settings_advanced'
2908 - );
2909 2594 // On multisite installs, add an option to override all multisite settings on individual sites.
2910 2595 if ( is_multisite() ) {
2911 2596 add_settings_field(
2912 - 'auth_settings_advanced_override_multisite',
2913 - __( 'Override multisite options', 'authorizer' ),
2914 - array( $this, 'print_checkbox_auth_advanced_override_multisite' ),
2915 - 'authorizer',
2916 - 'auth_settings_advanced'
2597 + 'auth_settings_advanced_override_multisite', // HTML element ID
2598 + __( 'Override multisite options', 'authorizer' ), // HTML element Title
2599 + array( $this, 'print_checkbox_auth_advanced_override_multisite' ), // Callback (echos form element)
2600 + 'authorizer', // Page this setting is shown on (slug)
2601 + 'auth_settings_advanced' // Section this setting is shown on
2917 2602 );
2918 2603 }
2919 2604 }
2920 2605
@@ -2920,30 +2605,29 @@
2920 2605
2921 2606
2922 2607 /**
2923 2608 * Set meaningful defaults for the plugin options.
2924 - *
2925 2609 * Note: This function is called on plugin activation.
2926 2610 */
2927 - private function set_default_options() {
2611 + function set_default_options() {
2928 2612 global $wp_roles;
2929 2613
2930 2614 $auth_settings = get_option( 'auth_settings' );
2931 - if ( false === $auth_settings ) {
2615 + if ( $auth_settings === FALSE ) {
2932 2616 $auth_settings = array();
2933 2617 }
2934 2618
2935 2619 // Access Lists Defaults.
2936 2620 $auth_settings_access_users_pending = get_option( 'auth_settings_access_users_pending' );
2937 - if ( false === $auth_settings_access_users_pending ) {
2621 + if ( $auth_settings_access_users_pending === FALSE ) {
2938 2622 $auth_settings_access_users_pending = array();
2939 2623 }
2940 2624 $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
2941 - if ( false === $auth_settings_access_users_approved ) {
2625 + if ( $auth_settings_access_users_approved === FALSE ) {
2942 2626 $auth_settings_access_users_approved = array();
2943 2627 }
2944 2628 $auth_settings_access_users_blocked = get_option( 'auth_settings_access_users_blocked' );
2945 - if ( false === $auth_settings_access_users_blocked ) {
2629 + if ( $auth_settings_access_users_blocked === FALSE ) {
2946 2630 $auth_settings_access_users_blocked = array();
2947 2631 }
2948 2632
2949 2633 // Login Access Defaults.
@@ -2995,12 +2679,13 @@
2995 2679 if ( ! array_key_exists( 'access_redirect_to_message', $auth_settings ) ) {
2996 2680 $auth_settings['access_redirect_to_message'] = '<p>' . __( 'Notice: You are browsing this site anonymously, and only have access to a portion of its content.', 'authorizer' ) . '</p>';
2997 2681 }
2998 2682
2683 +
2999 2684 // External Service Defaults.
3000 2685 if ( ! array_key_exists( 'access_default_role', $auth_settings ) ) {
3001 2686 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3002 - $all_roles = $wp_roles->roles;
2687 + $all_roles = $wp_roles->roles;
3003 2688 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3004 2689 if ( array_key_exists( 'student', $editable_roles ) ) {
3005 2690 $auth_settings['access_default_role'] = 'student';
3006 2691 } else {
@@ -3057,11 +2742,8 @@
3057 2742 }
3058 2743 if ( ! array_key_exists( 'cas_auto_login', $auth_settings ) ) {
3059 2744 $auth_settings['cas_auto_login'] = '';
3060 2745 }
3061 - if ( ! array_key_exists( 'cas_link_on_username', $auth_settings ) ) {
3062 - $auth_settings['cas_link_on_username'] = '';
3063 - }
3064 2746
3065 2747 if ( ! array_key_exists( 'ldap_host', $auth_settings ) ) {
3066 2748 $auth_settings['ldap_host'] = '';
3067 2749 }
@@ -3101,12 +2783,12 @@
3101 2783
3102 2784 // Advanced defaults.
3103 2785 if ( ! array_key_exists( 'advanced_lockouts', $auth_settings ) ) {
3104 2786 $auth_settings['advanced_lockouts'] = array(
3105 - 'attempts_1' => 10,
3106 - 'duration_1' => 1,
3107 - 'attempts_2' => 10,
3108 - 'duration_2' => 10,
2787 + 'attempts_1' => 10,
2788 + 'duration_1' => 1,
2789 + 'attempts_2' => 10,
2790 + 'duration_2' => 10,
3109 2791 'reset_duration' => 120,
3110 2792 );
3111 2793 }
3112 2794 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_settings ) ) {
@@ -3120,20 +2802,8 @@
3120 2802 }
3121 2803 if ( ! array_key_exists( 'advanced_usermeta', $auth_settings ) ) {
3122 2804 $auth_settings['advanced_usermeta'] = '';
3123 2805 }
3124 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_settings ) ) {
3125 - $auth_settings['advanced_users_per_page'] = 20;
3126 - }
3127 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_settings ) ) {
3128 - $auth_settings['advanced_users_sort_by'] = 'created';
3129 - }
3130 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_settings ) ) {
3131 - $auth_settings['advanced_users_sort_order'] = 'asc';
3132 - }
3133 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_settings ) ) {
3134 - $auth_settings['advanced_widget_enabled'] = '1';
3135 - }
3136 2806 if ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) ) {
3137 2807 $auth_settings['advanced_override_multisite'] = '';
3138 2808 }
3139 2809
@@ -3144,11 +2814,11 @@
3144 2814 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
3145 2815
3146 2816 // Multisite defaults.
3147 2817 if ( is_multisite() ) {
3148 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
2818 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
3149 2819
3150 - if ( false === $auth_multisite_settings ) {
2820 + if ( $auth_multisite_settings === FALSE ) {
3151 2821 $auth_multisite_settings = array();
3152 2822 }
3153 2823 // Global switch for enabling multisite options.
3154 2824 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
@@ -3154,10 +2824,10 @@
3154 2824 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
3155 2825 $auth_multisite_settings['multisite_override'] = '';
3156 2826 }
3157 2827 // Access Lists Defaults.
3158 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved' );
3159 - if ( false === $auth_multisite_settings_access_users_approved ) {
2828 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved' );
2829 + if ( $auth_multisite_settings_access_users_approved === FALSE ) {
3160 2830 $auth_multisite_settings_access_users_approved = array();
3161 2831 }
3162 2832 // Login Access Defaults.
3163 2833 if ( ! array_key_exists( 'access_who_can_login', $auth_multisite_settings ) ) {
@@ -3169,9 +2839,9 @@
3169 2839 }
3170 2840 // External Service Defaults.
3171 2841 if ( ! array_key_exists( 'access_default_role', $auth_multisite_settings ) ) {
3172 2842 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3173 - $all_roles = $wp_roles->roles;
2843 + $all_roles = $wp_roles->roles;
3174 2844 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3175 2845 if ( array_key_exists( 'student', $editable_roles ) ) {
3176 2846 $auth_multisite_settings['access_default_role'] = 'student';
3177 2847 } else {
@@ -3225,11 +2895,8 @@
3225 2895 }
3226 2896 if ( ! array_key_exists( 'cas_auto_login', $auth_multisite_settings ) ) {
3227 2897 $auth_multisite_settings['cas_auto_login'] = '';
3228 2898 }
3229 - if ( ! array_key_exists( 'cas_link_on_username', $auth_multisite_settings ) ) {
3230 - $auth_multisite_settings['cas_link_on_username'] = '';
3231 - }
3232 2899 if ( ! array_key_exists( 'ldap_host', $auth_multisite_settings ) ) {
3233 2900 $auth_multisite_settings['ldap_host'] = '';
3234 2901 }
3235 2902 if ( ! array_key_exists( 'ldap_port', $auth_multisite_settings ) ) {
@@ -3267,12 +2934,12 @@
3267 2934 }
3268 2935 // Advanced defaults.
3269 2936 if ( ! array_key_exists( 'advanced_lockouts', $auth_multisite_settings ) ) {
3270 2937 $auth_multisite_settings['advanced_lockouts'] = array(
3271 - 'attempts_1' => 10,
3272 - 'duration_1' => 1,
3273 - 'attempts_2' => 10,
3274 - 'duration_2' => 10,
2938 + 'attempts_1' => 10,
2939 + 'duration_1' => 1,
2940 + 'attempts_2' => 10,
2941 + 'duration_2' => 10,
3275 2942 'reset_duration' => 120,
3276 2943 );
3277 2944 }
3278 2945 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
@@ -3277,23 +2944,11 @@
3277 2944 }
3278 2945 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
3279 2946 $auth_multisite_settings['advanced_hide_wp_login'] = '';
3280 2947 }
3281 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_multisite_settings ) ) {
3282 - $auth_multisite_settings['advanced_users_per_page'] = 20;
3283 - }
3284 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_multisite_settings ) ) {
3285 - $auth_multisite_settings['advanced_users_sort_by'] = 'created';
3286 - }
3287 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_multisite_settings ) ) {
3288 - $auth_multisite_settings['advanced_users_sort_order'] = 'asc';
3289 - }
3290 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_multisite_settings ) ) {
3291 - $auth_multisite_settings['advanced_widget_enabled'] = '1';
3292 - }
3293 2948 // Save default network options to database.
3294 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
3295 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
2949 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
2950 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3296 2951 }
3297 2952
3298 2953 return $auth_settings;
3299 2954 }
@@ -3300,15 +2955,12 @@
3300 2955
3301 2956
3302 2957 /**
3303 2958 * List sanitizer.
3304 - *
3305 - * @param array $list Array of users to sanitize.
3306 - * @param string $side_effect Set to 'update roles' if role syncing should be performed.
3307 - * @param string $multisite_mode Set to 'multisite' to sync roles on all sites the user belongs to.
3308 - * @return array Array of sanitized users.
2959 + * $side_effect = 'none' or 'update roles' to make sure WP user roles match
2960 + * $multisite_mode = 'single' or 'multisite' to indicate which user roles to change (this site or all sites)
3309 2961 */
3310 - private function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
2962 + function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
3311 2963 // If it's not a list, make it so.
3312 2964 if ( ! is_array( $list ) ) {
3313 2965 $list = array();
3314 2966 }
@@ -3313,16 +2965,16 @@
3313 2965 $list = array();
3314 2966 }
3315 2967 foreach ( $list as $key => $user_info ) {
3316 2968 if ( strlen( $user_info['email'] ) < 1 ) {
3317 - // Make sure there are no empty entries in the list.
3318 - unset( $list[ $key ] );
3319 - } elseif ( 'update roles' === $side_effect ) {
2969 + // Make sure there are no empty entries in the list
2970 + unset( $list[$key] );
2971 + } elseif ( $side_effect === 'update roles' ) {
3320 2972 // Make sure the WordPress user accounts have the same role
3321 2973 // as that indicated in the list.
3322 2974 $wp_user = get_user_by( 'email', $user_info['email'] );
3323 2975 if ( $wp_user ) {
3324 - if ( is_multisite() && 'multisite' === $multisite_mode ) {
2976 + if ( is_multisite() && $multisite_mode === 'multisite' ) {
3325 2977 foreach ( get_blogs_of_user( $wp_user->ID ) as $blog ) {
3326 2978 add_user_to_blog( $blog->userblog_id, $wp_user->ID, $user_info['role'] );
3327 2979 }
3328 2980 } else {
@@ -3335,21 +2987,18 @@
3335 2987 }
3336 2988
3337 2989
3338 2990 /**
3339 - * Settings sanitizer callback.
3340 - *
3341 - * @param array $auth_settings Authorizer settings array.
3342 - * @return array Sanitized Authorizer settings array.
2991 + * Settings sanitizer callback
3343 2992 */
3344 - public function sanitize_options( $auth_settings ) {
2993 + function sanitize_options( $auth_settings ) {
3345 2994 // Default to "Approved Users" login access restriction.
3346 - if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ), true ) ) {
2995 + if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ) ) ) {
3347 2996 $auth_settings['access_who_can_login'] = 'approved_users';
3348 2997 }
3349 2998
3350 2999 // Default to "Everyone" view access restriction.
3351 - if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ), true ) ) {
3000 + if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ) ) ) {
3352 3001 $auth_settings['access_who_can_view'] = 'everyone';
3353 3002 }
3354 3003
3355 3004 // Default to WordPress login access redirect.
@@ -3354,9 +3003,9 @@
3354 3003
3355 3004 // Default to WordPress login access redirect.
3356 3005 // Note: this option doesn't exist in multisite options, so we first
3357 3006 // check to see if it exists.
3358 - if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ), true ) ) {
3007 + if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ) ) ) {
3359 3008 $auth_settings['access_redirect'] = 'login';
3360 3009 }
3361 3010
3362 3011 // Default to warning message for anonymous users on public pages.
@@ -3361,64 +3010,61 @@
3361 3010
3362 3011 // Default to warning message for anonymous users on public pages.
3363 3012 // Note: this option doesn't exist in multisite options, so we first
3364 3013 // check to see if it exists.
3365 - if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ), true ) ) {
3014 + if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ) ) ) {
3366 3015 $auth_settings['access_public_warning'] = 'no_warning';
3367 3016 }
3368 3017
3369 - // Sanitize Send welcome email (checkbox: value can only be '1' or empty string).
3018 + // Sanitize Send welcome email (checkbox: value can only be '1' or empty string)
3370 3019 $auth_settings['access_should_email_approved_users'] = array_key_exists( 'access_should_email_approved_users', $auth_settings ) && strlen( $auth_settings['access_should_email_approved_users'] ) > 0 ? '1' : '';
3371 3020
3372 - // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string).
3021 + // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string)
3373 3022 $auth_settings['google'] = array_key_exists( 'google', $auth_settings ) && strlen( $auth_settings['google'] ) > 0 ? '1' : '';
3374 3023
3375 - // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string).
3024 + // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string)
3376 3025 $auth_settings['cas'] = array_key_exists( 'cas', $auth_settings ) && strlen( $auth_settings['cas'] ) > 0 ? '1' : '';
3377 3026
3378 - // Sanitize CAS Host setting.
3027 + // Sanitize CAS Host setting
3379 3028 $auth_settings['cas_host'] = filter_var( $auth_settings['cas_host'], FILTER_SANITIZE_URL );
3380 3029
3381 - // Sanitize CAS Port (int).
3030 + // Sanitize CAS Port (int)
3382 3031 $auth_settings['cas_port'] = filter_var( $auth_settings['cas_port'], FILTER_SANITIZE_NUMBER_INT );
3383 3032
3384 - // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string).
3033 + // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string)
3385 3034 $auth_settings['cas_attr_update_on_login'] = array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['cas_attr_update_on_login'] ) > 0 ? '1' : '';
3386 3035
3387 - // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string).
3036 + // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string)
3388 3037 $auth_settings['cas_auto_login'] = array_key_exists( 'cas_auto_login', $auth_settings ) && strlen( $auth_settings['cas_auto_login'] ) > 0 ? '1' : '';
3389 3038
3390 - // Sanitize CAS link on username (checkbox: value can only be '1' or empty string).
3391 - $auth_settings['cas_link_on_username'] = array_key_exists( 'cas_link_on_username', $auth_settings ) && strlen( $auth_settings['cas_link_on_username'] ) > 0 ? '1' : '';
3392 -
3393 - // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string).
3039 + // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string)
3394 3040 $auth_settings['ldap'] = array_key_exists( 'ldap', $auth_settings ) && strlen( $auth_settings['ldap'] ) > 0 ? '1' : '';
3395 3041
3396 - // Sanitize LDAP Host setting.
3042 + // Sanitize LDAP Host setting
3397 3043 $auth_settings['ldap_host'] = filter_var( $auth_settings['ldap_host'], FILTER_SANITIZE_URL );
3398 3044
3399 - // Sanitize LDAP Port (int).
3045 + // Sanitize LDAP Port (int)
3400 3046 $auth_settings['ldap_port'] = filter_var( $auth_settings['ldap_port'], FILTER_SANITIZE_NUMBER_INT );
3401 3047
3402 - // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string).
3048 + // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string)
3403 3049 $auth_settings['ldap_tls'] = array_key_exists( 'ldap_tls', $auth_settings ) && strlen( $auth_settings['ldap_tls'] ) > 0 ? '1' : '';
3404 3050
3405 - // Sanitize LDAP attributes (basically make sure they don't have any parentheses).
3051 + // Sanitize LDAP attributes (basically make sure they don't have any parentheses)
3406 3052 $auth_settings['ldap_uid'] = filter_var( $auth_settings['ldap_uid'], FILTER_SANITIZE_EMAIL );
3407 3053
3408 - // Sanitize LDAP Lost Password URL.
3054 + // Sanitize LDAP Lost Password URL
3409 3055 $auth_settings['ldap_lostpassword_url'] = filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_SANITIZE_URL );
3410 3056
3411 - // Obfuscate LDAP directory user password.
3057 + // Obfuscate LDAP directory user password
3412 3058 if ( strlen( $auth_settings['ldap_password'] ) > 0 ) {
3413 3059 // encrypt the directory user password for some minor obfuscation in the database.
3414 3060 $auth_settings['ldap_password'] = $this->encrypt( $auth_settings['ldap_password'] );
3415 3061 }
3416 3062
3417 - // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string).
3063 + // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string)
3418 3064 $auth_settings['ldap_attr_update_on_login'] = array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['ldap_attr_update_on_login'] ) > 0 ? '1' : '';
3419 3065
3420 - // Make sure public pages is an empty array if it's empty.
3066 + // Make sure public pages is an empty array if it's empty
3421 3067 // Note: this option doesn't exist in multisite options, so we first
3422 3068 // check to see if it exists.
3423 3069 if ( array_key_exists( 'access_public_pages', $auth_settings ) && ! is_array( $auth_settings['access_public_pages'] ) ) {
3424 3070 $auth_settings['access_public_pages'] = array();
@@ -3426,31 +3072,15 @@
3426 3072
3427 3073 // Make sure all lockout options are integers (attempts_1,
3428 3074 // duration_1, attempts_2, duration_2, reset_duration).
3429 3075 foreach ( $auth_settings['advanced_lockouts'] as $key => $value ) {
3430 - $auth_settings['advanced_lockouts'][ $key ] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3076 + $auth_settings['advanced_lockouts'][$key] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3431 3077 }
3432 3078
3433 - // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string).
3079 + // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string)
3434 3080 $auth_settings['advanced_hide_wp_login'] = array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && strlen( $auth_settings['advanced_hide_wp_login'] ) > 0 ? '1' : '';
3435 3081
3436 - // Sanitize Users per page (text: value can only int from 1 to MAX_INT).
3437 - $auth_settings['advanced_users_per_page'] = array_key_exists( 'advanced_users_per_page', $auth_settings ) && intval( $auth_settings['advanced_users_per_page'] ) > 0 ? intval( $auth_settings['advanced_users_per_page'] ) : 1;
3438 -
3439 - // Sanitize Sort users by (select: value can be 'email', 'role', 'date_added', 'created').
3440 - if ( ! isset( $auth_settings['advanced_users_sort_by'] ) || ! in_array( $auth_settings['advanced_users_sort_by'], array( 'email', 'role', 'date_added', 'created' ), true ) ) {
3441 - $auth_settings['advanced_users_sort_by'] = 'created';
3442 - }
3443 -
3444 - // Sanitize Sort users order (select: value can be 'asc', 'desc').
3445 - if ( ! isset( $auth_settings['advanced_users_sort_order'] ) || ! in_array( $auth_settings['advanced_users_sort_order'], array( 'asc', 'desc' ), true ) ) {
3446 - $auth_settings['advanced_users_sort_order'] = 'asc';
3447 - }
3448 -
3449 - // Sanitize Show Dashboard Widget (checkbox: value can only be '1' or empty string).
3450 - $auth_settings['advanced_widget_enabled'] = array_key_exists( 'advanced_widget_enabled', $auth_settings ) && strlen( $auth_settings['advanced_widget_enabled'] ) > 0 ? '1' : '';
3451 -
3452 - // Sanitize Override multisite options (checkbox: value can only be '1' or empty string).
3082 + // Sanitize Override multisite options (checkbox: value can only be '1' or empty string)
3453 3083 $auth_settings['advanced_override_multisite'] = array_key_exists( 'advanced_override_multisite', $auth_settings ) && strlen( $auth_settings['advanced_override_multisite'] ) > 0 ? '1' : '';
3454 3084
3455 3085 return $auth_settings;
3456 3086 }
@@ -3457,201 +3087,90 @@
3457 3087
3458 3088
3459 3089 /**
3460 3090 * Keep authorizer approved users' roles in sync with WordPress roles
3461 - * if someone changes the role via the WordPress Edit User page
3462 - * (wp-admin/user-edit.php or wp-admin/profile.php).
3091 + * if someone changes the role via the WordPress Edit User options page.
3463 3092 *
3464 - * Action: user_profile_update_errors
3465 - *
3466 - * @param WP_Error $errors Errors object to add any custom errors to (passed by reference).
3467 - * @param bool $update True if updating existing user, false if saving a new one.
3468 - * @param stdClass $user Updated WP_User object for user being edited (passed by reference).
3093 + * @action edit_user_profile_update
3094 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/edit_user_profile_update
3095 + * @param int $user_id The user ID of the user being edited
3096 +
3097 + * @action personal_options_update
3098 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/personal_options_update
3099 + * @param int $user_id The user ID of the user being edited
3469 3100 */
3470 - public function edit_user_profile_update_role( &$errors, $update, &$user ) {
3471 - // Do nothing if we're not updating role.
3472 - if ( ! property_exists( $user, 'role' ) ) {
3101 + function edit_user_profile_update_role( $user_id ) {
3102 + if ( ! current_user_can( 'edit_user', $user_id ) ) {
3473 3103 return;
3474 3104 }
3475 3105
3476 - // Safety check; will likely not fire if we reach this function.
3477 - if ( ! current_user_can( 'edit_user', $user->ID ) ) {
3478 - return;
3479 - }
3480 -
3481 - // Don't perform Authorizer updates if we have a WordPress error.
3482 - $errors_on_user_update = $errors->get_error_codes();
3483 - if ( ! empty( $errors_on_user_update ) ) {
3484 - return;
3485 - }
3486 -
3487 - // Get original user object (fail if not a real WordPress user).
3488 - $userdata = get_userdata( $user->ID );
3489 - if ( ! $userdata ) {
3490 - return;
3491 - }
3492 -
3493 3106 // If user is in approved list, update his/her associated role.
3494 - if ( $this->is_email_in_list( $userdata->user_email, 'approved' ) ) {
3495 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3496 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3497 - if ( 0 === strcasecmp( $check_user['email'], $userdata->user_email ) ) {
3498 - $auth_settings_access_users_approved[ $key ]['role'] = $user->role;
3499 - }
3500 - }
3501 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3502 - }
3503 - }
3504 -
3505 -
3506 - /**
3507 - * Sync any email address changes to WordPress accounts to the corresponding
3508 - * entry in the Authorizer approved list.
3509 - *
3510 - * Note: This filter fires in wp_update_user() if the update includes an
3511 - * email address change, and fires after all security and integrity checks
3512 - * have been performed, so we can simply update the Authorizer approved
3513 - * list, changing the email address on the approved entry, and removing any
3514 - * existing entries that also have the new email address (duplicates).
3515 - *
3516 - * Filter: send_email_change_email
3517 - *
3518 - * @param bool $send Whether to send the email.
3519 - * @param array $user The original user array.
3520 - * @param array $userdata The updated user array.
3521 - */
3522 - public function edit_user_profile_update_email( $send, $user, $userdata ) {
3523 - // If we're in multisite, update the email on all sites in the network
3524 - // (and remove from any subsites if it's a network-approved user).
3525 - if ( is_multisite() ) {
3526 - // If it's a multisite approved user, sync the email there.
3527 - $changed_user_is_multisite_user = false;
3528 - if ( $this->is_email_in_list( $user['user_email'], 'approved', 'multisite' ) ) {
3529 - $changed_user_is_multisite_user = true;
3530 - $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
3531 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
3532 - );
3533 - foreach ( $auth_multisite_settings_access_users_approved as $key => $check_user ) {
3534 - // Update old user email in approved list to the new email.
3535 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3536 - $auth_multisite_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3107 + $wp_user = get_user_by( 'id', $user_id );
3108 + if ( $this->is_email_in_list( $wp_user->get( 'user_email' ), 'approved' ) ) {
3109 + $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) );
3110 + // Find approved user and sync with the corresponding WP_User.
3111 + foreach ( $auth_settings_access_users_approved as $key => $user ) {
3112 + if ( $user['email'] === $wp_user->user_email ) {
3113 + // Sync user role.
3114 + if ( array_key_exists( 'role', $_REQUEST ) ) {
3115 + $auth_settings_access_users_approved[$key]['role'] = $_REQUEST['role'];
3537 3116 }
3538 - // If new user email is already in approved list, remove that entry.
3539 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3540 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
3117 + // Sync email address.
3118 + if ( array_key_exists( 'email', $_REQUEST ) ) {
3119 + $auth_settings_access_users_approved[$key]['email'] = $_REQUEST['email'];
3541 3120 }
3542 3121 }
3543 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3544 3122 }
3545 3123
3546 - // Go through all approved lists on individual sites and sync this user there.
3547 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
3548 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
3549 - foreach ( $sites as $site ) {
3550 - $updated = false;
3551 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
3552 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
3553 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3554 - // Update old user email in approved list to the new email.
3555 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3556 - // But if the user is already a multisite user, just remove the entry in the subsite.
3557 - if ( $changed_user_is_multisite_user ) {
3558 - unset( $auth_settings_access_users_approved[ $key ] );
3559 - } else {
3560 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3561 - }
3562 - $updated = true;
3563 - }
3564 - // If new user email is already in approved list, remove that entry.
3565 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3566 - unset( $auth_settings_access_users_approved[ $key ] );
3567 - $updated = true;
3568 - }
3569 - }
3570 - if ( $updated ) {
3571 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3572 - }
3573 - }
3574 - } else {
3575 - // In a single site environment, just find the old user in the approved list and update the email.
3576 - if ( $this->is_email_in_list( $user['user_email'], 'approved' ) ) {
3577 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3578 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3579 - // Update old user email in approved list to the new email.
3580 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3581 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3582 - }
3583 - // If new user email is already in approved list, remove that entry.
3584 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3585 - unset( $auth_settings_access_users_approved[ $key ] );
3586 - }
3587 - }
3588 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3589 - }
3124 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3590 3125 }
3591 -
3592 - // We're hooking into this filter merely for its location in the codebase,
3593 - // so make sure to return the filter value unmodified.
3594 - return $send;
3595 3126 }
3596 3127
3597 3128
3598 3129 /**
3599 - * Settings print callback.
3600 - *
3601 - * @param string $args Args (e.g., multisite admin mode).
3602 - * @return void
3130 + * Settings print callbacks
3603 3131 */
3604 - public function print_section_info_tabs( $args = '' ) {
3605 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $this->get_admin_mode( $args ) ) :
3606 - ?>
3132 + function print_section_info_tabs( $args = '' ) {
3133 + if ( MULTISITE_ADMIN === $this->get_admin_mode( $args )): ?>
3607 3134 <h2 class="nav-tab-wrapper">
3608 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3609 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3610 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3135 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3136 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3137 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3611 3138 </h2>
3612 - <?php else : ?>
3139 + <?php else: ?>
3613 3140 <h2 class="nav-tab-wrapper">
3614 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3615 - <a class="nav-tab nav-tab-access_login" href="javascript:chooseTab('access_login' );"><?php esc_html_e( 'Login Access', 'authorizer' ); ?></a>
3616 - <a class="nav-tab nav-tab-access_public" href="javascript:chooseTab('access_public' );"><?php esc_html_e( 'Public Access', 'authorizer' ); ?></a>
3617 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3618 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3141 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3142 + <a class="nav-tab nav-tab-access_login" href="javascript:choose_tab('access_login' );"><?php _e( 'Login Access', 'authorizer' ); ?></a>
3143 + <a class="nav-tab nav-tab-access_public" href="javascript:choose_tab('access_public' );"><?php _e( 'Public Access', 'authorizer' ); ?></a>
3144 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3145 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3619 3146 </h2>
3620 - <?php
3621 - endif;
3147 + <?php endif;
3622 3148 }
3623 3149
3624 3150
3625 - /**
3626 - * Settings print callback.
3627 - *
3628 - * @param string $args Args (e.g., multisite admin mode).
3629 - * @return void
3630 - */
3631 - public function print_section_info_access_lists( $args = '' ) {
3151 + function print_section_info_access_lists( $args = '' ) {
3632 3152 $admin_mode = $this->get_admin_mode( $args );
3633 - ?>
3634 - <div id="section_info_access_lists" class="section_info">
3635 - <p><?php esc_html_e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3153 + ?><div id="section_info_access_lists" class="section_info">
3154 + <p><?php _e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3636 3155 <ol>
3637 - <li><?php echo wp_kses( __( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ), $this->allowed_html ); ?></li>
3638 - <li><?php echo wp_kses( __( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ), $this->allowed_html ); ?></li>
3639 - <li><?php echo wp_kses( __( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ), $this->allowed_html ); ?><br><?php esc_html_e( 'Note: if you want to block all email addresses from a domain, say anyone@example.com, simply add "@example.com" to the blocked list.', 'authorizer' ); ?></li>
3156 + <li><?php _e( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ); ?></li>
3157 + <li><?php _e( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ); ?></li>
3158 + <li><?php _e( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ); ?></li>
3640 3159 </ol>
3641 3160 </div>
3642 3161 <table class="form-table">
3643 3162 <tbody>
3644 3163 <tr>
3645 - <th scope="row"><?php esc_html_e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'pending', $admin_mode ) ); ?>)</em></th>
3164 + <th scope="row"><?php _e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'pending', $admin_mode ); ?>)</em></th>
3646 3165 <td><?php $this->print_combo_auth_access_users_pending(); ?></td>
3647 3166 </tr>
3648 3167 <tr>
3649 - <th scope="row"><?php esc_html_e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'approved', $admin_mode ) ); ?>)</em></th>
3168 + <th scope="row"><?php _e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'approved', $admin_mode ); ?>)</em></th>
3650 3169 <td><?php $this->print_combo_auth_access_users_approved(); ?></td>
3651 3170 </tr>
3652 3171 <tr>
3653 - <th scope="row"><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'blocked', $admin_mode ) ); ?>)</em></th>
3172 + <th scope="row"><?php _e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'blocked', $admin_mode ); ?>)</em></th>
3654 3173 <td><?php $this->print_combo_auth_access_users_blocked(); ?></td>
3655 3174 </tr>
3656 3175 </tbody>
3657 3176 </table>
@@ -3658,516 +3177,276 @@
3658 3177 <?php
3659 3178 }
3660 3179
3661 3180
3662 - /**
3663 - * Settings print callback.
3664 - *
3665 - * @param string $args Args (e.g., multisite admin mode).
3666 - * @return void
3667 - */
3668 - public function print_combo_auth_access_users_pending( $args = '' ) {
3181 + function print_combo_auth_access_users_pending( $args = '' ) {
3669 3182 // Get plugin option.
3670 - $option = 'access_users_pending';
3183 + $option = 'access_users_pending';
3671 3184 $auth_settings_option = $this->get_plugin_option( $option );
3672 3185 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3673 3186
3674 - // Render wrapper div (for aligning pager to width of content).
3675 - ?>
3676 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3677 - <ul id="list_auth_settings_access_users_pending" style="margin:0;">
3678 - <?php
3679 - if ( count( $auth_settings_option ) > 0 ) :
3680 - foreach ( $auth_settings_option as $key => $pending_user ) :
3681 - if ( empty( $pending_user ) || count( $pending_user ) < 1 ) :
3682 - continue;
3683 - endif;
3684 - $pending_user['is_wp_user'] = false;
3685 - ?>
3686 - <li>
3687 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $pending_user['email'] ); ?>" readonly="true" class="auth-email" />
3688 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
3689 - <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3690 - </select>
3691 - <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'approved', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3692 - <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'blocked', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
3693 - <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'pending' );" title="<?php esc_html_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php esc_html_e( 'Ignore', 'authorizer' ); ?></a>
3694 - </li>
3695 - <?php endforeach; ?>
3696 - <?php else : ?>
3697 - <li class="auth-empty"><em><?php esc_html_e( 'No pending users', 'authorizer' ); ?></em></li>
3698 - <?php endif; ?>
3699 - </ul>
3700 - </div>
3187 + // Print option elements.
3188 + ?><ul id="list_auth_settings_access_users_pending" style="margin:0;">
3189 + <?php if ( count( $auth_settings_option ) > 0 ) : ?>
3190 + <?php foreach ( $auth_settings_option as $key => $pending_user ): ?>
3191 + <?php if ( empty( $pending_user ) || count( $pending_user ) < 1 ) continue; ?>
3192 + <?php $pending_user['is_wp_user'] = false; ?>
3193 + <li>
3194 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $pending_user['email']; ?>" readonly="true" class="auth-email" />
3195 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3196 + <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3197 + </select>
3198 + <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'approved', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3199 + <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'blocked', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
3200 + <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user( this, 'pending' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php _e( 'Ignore', 'authorizer' ); ?></a>
3201 + </li>
3202 + <?php endforeach; ?>
3203 + <?php else: ?>
3204 + <li class="auth-empty"><em><?php _e( 'No pending users', 'authorizer' ); ?></em></li>
3205 + <?php endif; ?>
3206 + </ul>
3701 3207 <?php
3702 3208 }
3703 3209
3704 3210
3705 - /**
3706 - * Settings print callback.
3707 - *
3708 - * @param string $args Args (e.g., multisite admin mode).
3709 - * @return void
3710 - */
3711 - public function print_combo_auth_access_users_approved( $args = '' ) {
3211 + function print_combo_auth_access_users_approved( $args = '' ) {
3712 3212 // Get plugin option.
3713 - $option = 'access_users_approved';
3714 - $admin_mode = $this->get_admin_mode( $args );
3213 + $option = 'access_users_approved';
3214 + $admin_mode = $this->get_admin_mode( $args );
3715 3215 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
3716 3216 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3717 3217
3718 - // Get multisite approved users (will be added to top of list, greyed out).
3719 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3720 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
3218 + // Get multisite approved users (add them to top of list, greyed out).
3219 + $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3220 + $auth_multisite_settings = $this->get_plugin_options( MULTISITE_ADMIN );
3721 3221 $auth_settings_option_multisite = array();
3722 3222 if (
3723 3223 is_multisite() &&
3724 - ! is_network_admin() &&
3725 - 1 !== intval( $auth_override_multisite ) &&
3224 + $auth_override_multisite != '1' &&
3726 3225 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
3727 - '1' === $auth_multisite_settings['multisite_override']
3226 + $auth_multisite_settings['multisite_override'] === '1'
3728 3227 ) {
3729 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
3228 + $auth_settings_option_multisite = $this->get_plugin_option( $option, MULTISITE_ADMIN, 'allow override' );
3730 3229 $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
3731 - // Add multisite users to the beginning of the main user array.
3732 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
3733 - $approved_user['multisite_user'] = true;
3734 - array_unshift( $auth_settings_option, $approved_user );
3735 - }
3736 3230 }
3737 3231
3738 3232 // Get default role for new user dropdown.
3739 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3233 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
3740 3234
3741 3235 // Get custom usermeta field to show.
3742 3236 $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
3743 3237
3744 3238 // Adjust javascript function prefixes if multisite.
3745 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3746 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3239 + $js_function_prefix = $admin_mode === MULTISITE_ADMIN ? 'auth_multisite_' : 'auth_';
3240 + $multisite_admin_page = $admin_mode === MULTISITE_ADMIN;
3747 3241
3748 - // Filter user list to search terms.
3749 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3750 - if ( isset( $_REQUEST['search'] ) && strlen( sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) ) > 0 ) {
3751 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3752 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
3753 - $auth_settings_option = array_filter(
3754 - $auth_settings_option, function ( $user ) use ( $search_term ) {
3755 - return stripos( $user['email'], $search_term ) !== false ||
3756 - stripos( $user['role'], $search_term ) !== false ||
3757 - stripos( $user['date_added'], $search_term ) !== false;
3758 - }
3759 - );
3760 - }
3761 -
3762 - // Sort user list.
3763 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
3764 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
3765 - $sort_dimension = array();
3766 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
3767 - foreach ( $auth_settings_option as $key => $user ) {
3768 - if ( 'date_added' === $sort_by ) {
3769 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
3770 - } else {
3771 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
3772 - }
3773 - }
3774 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
3775 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
3776 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
3777 - // If default sort method and reverse order, just reverse the array.
3778 - $auth_settings_option = array_reverse( $auth_settings_option );
3779 - }
3780 -
3781 - // Ensure array keys run from 0..max (keys in database will be the original,
3782 - // index, and removing users will not reorder the array keys of other users).
3783 - $auth_settings_option = array_values( $auth_settings_option );
3784 -
3785 - // Get pager params.
3786 - $total_users = count( $auth_settings_option );
3787 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
3788 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3789 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
3790 - $total_pages = ceil( $total_users / $users_per_page );
3791 - if ( $total_pages < 1 ) {
3792 - $total_pages = 1;
3793 - }
3794 -
3795 - // Make sure current_page is between 1 and max pages.
3796 - if ( $current_page < 1 ) {
3797 - $current_page = 1;
3798 - } elseif ( $current_page > $total_pages ) {
3799 - $current_page = $total_pages;
3800 - }
3801 -
3802 - // Render wrapper div (for aligning pager to width of content).
3803 - ?>
3804 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3805 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'top' ); ?>
3806 - <ul id="list_auth_settings_access_users_approved" class="<?php echo strlen( $advanced_usermeta ) > 0 ? 'has-usermeta' : ''; ?>">
3807 - <?php
3808 - $offset = ( $current_page - 1 ) * $users_per_page;
3809 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
3810 - for ( $key = $offset; $key < $max; $key++ ) :
3811 - $approved_user = $auth_settings_option[ $key ];
3242 + ?><ul id="list_auth_settings_access_users_approved" style="margin:0;">
3243 + <?php if ( ! $multisite_admin_page ) :
3244 + foreach ( $auth_settings_option_multisite as $key => $approved_user ) :
3812 3245 if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3813 3246 continue;
3814 3247 endif;
3815 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
3816 - endfor;
3817 - ?>
3818 - </ul>
3248 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3249 + if ( $approved_wp_user ) :
3250 + $approved_user['email'] = $approved_wp_user->user_email;
3251 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3252 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3253 + // Get usermeta field from the WordPress user's real usermeta.
3254 + if ( strlen( $advanced_usermeta ) > 0 ) :
3255 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3256 + // Get ACF Field value for the user
3257 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3258 + else :
3259 + // Get regular usermeta value for the user.
3260 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3261 + endif;
3819 3262
3820 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
3821 - <textarea id="new_approved_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new autogrow-short" rows="1"></textarea>
3822 - <select id="new_approved_user_role" class="auth-role">
3823 - <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
3824 - </select>
3825 - <div class="btn-group">
3826 - <a href="javascript:void(0);" class="btn button-primary dropdown-toggle button-add-user" id="approve_user_new" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3827 - <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3828 - <span class="caret"></span>
3829 - <span class="sr-only"><?php esc_html_e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3830 - </button>
3831 - <ul class="dropdown-menu" role="menu">
3832 - <li><a href="javascript:void(0);" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( document.getElementById( 'approve_user_new' ), 'approved', true);"><?php esc_html_e( 'Create a new WordPress account, and email the user an activation link.', 'authorizer' ); ?></a></li>
3833 - </ul>
3834 - </div>
3835 - </div>
3836 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'bottom' ); ?>
3837 - </div>
3838 - <?php
3839 - }
3263 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3264 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3265 + endif;
3266 + endif;
3267 + endif;
3268 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3269 + $approved_user['usermeta'] = '';
3270 + endif; ?>
3271 + <li>
3272 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email auth-multisite-email" />
3273 + <select id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role auth-multisite-role" disabled="disabled">
3274 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'] ); ?>
3275 + </select>
3276 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added auth-multisite-date-added" disabled="disabled" />
3277 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3278 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3279 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3280 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3281 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3282 + $should_show_usermeta_in_text_field = false; ?>
3283 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta auth-multisite-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );">
3284 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3285 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3286 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && array_key_exists( get_current_blog_id(), $approved_user['usermeta'] ) && $key === $approved_user['usermeta'][get_current_blog_id()]['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3287 + <?php endforeach; ?>
3288 + </select>
3289 + <?php endif; ?>
3290 + <?php endif; ?>
3291 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3292 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta auth-multisite-usermeta" />
3293 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3294 + <?php endif; ?>
3295 + <?php endif; ?>
3296 + &nbsp;&nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
3297 + </li>
3298 + <?php endforeach;
3299 + endif;
3300 + foreach ( $auth_settings_option as $key => $approved_user ):
3301 + $is_current_user = false;
3302 + $local_user_icon = array_key_exists( 'local_user', $approved_user ) && $approved_user['local_user'] === 'true' ? '&nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>' : '';
3303 + if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3304 + continue;
3305 + endif;
3306 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3307 + if ( $approved_wp_user ) :
3308 + $approved_user['email'] = $approved_wp_user->user_email;
3309 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3310 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3311 + $approved_user['is_wp_user'] = true;
3312 + $is_current_user = $approved_wp_user->ID === get_current_user_id();
3313 + // Get usermeta field from the WordPress user's real usermeta.
3314 + if ( strlen( $advanced_usermeta ) > 0 ) :
3315 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3316 + // Get ACF Field value for the user
3317 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3318 + else :
3319 + // Get regular usermeta value for the user.
3320 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3321 + endif;
3840 3322
3841 -
3842 - /**
3843 - * Renders the html elements for the pager above and below the Approved User list.
3844 - *
3845 - * @param integer $current_page Which page we are currently viewing.
3846 - * @param integer $users_per_page How many users to show per page.
3847 - * @param integer $total_users Total count of users in list.
3848 - * @param string $which Where to render the pager ('top' or 'bottom').
3849 - * @return void
3850 - */
3851 - private function render_user_pager( $current_page = 1, $users_per_page = 20, $total_users = 0, $which = 'top' ) {
3852 - $total_pages = ceil( $total_users / $users_per_page );
3853 - if ( $total_pages < 1 ) {
3854 - $total_pages = 1;
3855 - }
3856 -
3857 - /* TRANSLATORS: %s: number of users */
3858 - $output = ' <span class="displaying-num">' . sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ) . '</span>';
3859 -
3860 - $disable_first = $current_page <= 1;
3861 - $disable_prev = $current_page <= 1;
3862 - $disable_next = $current_page >= $total_pages;
3863 - $disable_last = $current_page >= $total_pages;
3864 -
3865 - $current_url = '';
3866 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
3867 - $current_url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
3868 - $current_url = remove_query_arg( wp_removable_query_args(), $current_url );
3869 - }
3870 -
3871 - $page_links = array();
3872 -
3873 - $total_pages_before = '<span class="paging-input">';
3874 - $total_pages_after = '</span></span>';
3875 -
3876 - if ( $disable_first ) {
3877 - $page_links[] = '<span class="button disabled first-page tablenav-pages-navspan" aria-hidden="true">&laquo;</span>';
3878 - } else {
3879 - $page_links[] = sprintf(
3880 - "<a class='button first-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3881 - esc_url( remove_query_arg( 'paged', $current_url ) ),
3882 - __( 'First page' ),
3883 - '&laquo;'
3884 - );
3885 - }
3886 -
3887 - if ( $disable_prev ) {
3888 - $page_links[] = '<span class="button disabled prev-page tablenav-pages-navspan" aria-hidden="true">&lsaquo;</span>';
3889 - } else {
3890 - $page_links[] = sprintf(
3891 - "<a class='button prev-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3892 - esc_url( add_query_arg( 'paged', max( 1, $current_page - 1 ), $current_url ) ),
3893 - __( 'Previous page' ),
3894 - '&lsaquo;'
3895 - );
3896 - }
3897 -
3898 - if ( 'bottom' === $which ) {
3899 - $html_current_page = '<span class="current-page-text">' . $current_page . '</span>';
3900 - $total_pages_before = '<span class="screen-reader-text">' . __( 'Current Page' ) . '</span><span id="table-paging" class="paging-input"><span class="tablenav-paging-text">';
3901 - } else {
3902 - $html_current_page = sprintf(
3903 - "%s<input class='current-page' id='current-page-selector' type='text' name='paged' value='%s' size='%d' aria-describedby='table-paging' /><span class='tablenav-paging-text'>",
3904 - '<label for="current-page-selector" class="screen-reader-text">' . __( 'Current Page' ) . '</label>',
3905 - $current_page,
3906 - strlen( $total_pages )
3907 - );
3908 - }
3909 - /* TRANSLATORS: %s: number of pages */
3910 - $html_total_pages = sprintf( "<span class='total-pages'>%s</span>", number_format_i18n( $total_pages ) );
3911 - /* TRANSLATORS: 1: number of current page 2: number of total pages */
3912 - $page_links[] = $total_pages_before . sprintf( _x( '%1$s of %2$s', 'paging' ), $html_current_page, $html_total_pages ) . $total_pages_after;
3913 -
3914 - if ( $disable_next ) {
3915 - $page_links[] = '<span class="button disabled next-page tablenav-pages-navspan" aria-hidden="true">&rsaquo;</span>';
3916 - } else {
3917 - $page_links[] = sprintf(
3918 - "<a class='button next-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3919 - esc_url( add_query_arg( 'paged', min( $total_pages, $current_page + 1 ), $current_url ) ),
3920 - __( 'Next page' ),
3921 - '&rsaquo;'
3922 - );
3923 - }
3924 -
3925 - if ( $disable_last ) {
3926 - $page_links[] = '<span class="button disabled last-page tablenav-pages-navspan" aria-hidden="true">&raquo;</span>';
3927 - } else {
3928 - $page_links[] = sprintf(
3929 - "<a class='button last-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3930 - esc_url( add_query_arg( 'paged', $total_pages, $current_url ) ),
3931 - __( 'Last page' ),
3932 - '&raquo;'
3933 - );
3934 - }
3935 -
3936 - $pagination_links_class = 'pagination-links';
3937 - $output .= "\n<span class='$pagination_links_class'>" . join( "\n", $page_links ) . '</span>';
3938 -
3939 - $search_form = array();
3940 - if ( 'top' === $which ) {
3941 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3942 - $search_term = isset( $_REQUEST['search'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) : '';
3943 - $search_form[] = '<div class="search-box">';
3944 - $search_form[] = '<label class="screen-reader-text" for="user-search-input">' . __( 'Search Users', 'authorizer' ) . '</label>';
3945 - $search_form[] = '<input type="search" size="14" id="user-search-input" name="search" value="' . $search_term . '">';
3946 - $search_form[] = '<input type="button" id="search-submit" class="button" value="' . __( 'Search', 'authorizer' ) . '">';
3947 - $search_form[] = '</div>';
3948 - }
3949 - $search_form = join( "\n", $search_form );
3950 -
3951 - $output = "<div class='tablenav-pages'>$output</div>";
3952 - ?>
3953 - <div class="tablenav top">
3954 - <?php echo wp_kses( $output, $this->allowed_html ); ?>
3955 - <?php echo wp_kses( $search_form, $this->allowed_html ); ?>
3956 - </div>
3957 - <?php
3958 - }
3959 -
3960 -
3961 - /**
3962 - * Renders the html <li> element for a given user in a list.
3963 - *
3964 - * @param array $approved_user User array to render.
3965 - * @param int $key Index of user in list of users.
3966 - * @param string $option List user is in (e.g., 'access_users_approved').
3967 - * @param string $admin_mode Current admin context.
3968 - * @param string $advanced_usermeta Usermeta field to display.
3969 - * @return void
3970 - */
3971 - private function render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ) {
3972 - $is_local_user = array_key_exists( 'local_user', $approved_user ) && 'true' === $approved_user['local_user'];
3973 - $is_multisite_user = array_key_exists( 'multisite_user', $approved_user ) && true === $approved_user['multisite_user'];
3974 - $option_prefix = $is_multisite_user ? 'auth_multisite_settings_' : 'auth_settings_';
3975 - $option_id = $option_prefix . $option . '_' . $key;
3976 - $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3977 - $is_current_user = $approved_wp_user && get_current_user_id() === $approved_wp_user->ID;
3978 -
3979 - // Adjust javascript function prefixes if multisite.
3980 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3981 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3982 -
3983 - if ( ! $approved_wp_user ) :
3984 - $approved_user['is_wp_user'] = false;
3985 - else :
3986 - $approved_user['is_wp_user'] = true;
3987 - $approved_user['email'] = $approved_wp_user->user_email;
3988 - $approved_user['role'] = $is_multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3989 - $approved_user['date_added'] = $approved_wp_user->user_registered;
3990 -
3991 - // Get usermeta field from the WordPress user's real usermeta.
3992 - if ( strlen( $advanced_usermeta ) > 0 ) :
3993 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3994 - // Get ACF Field value for the user.
3995 - $approved_user['usermeta'] = get_field( str_replace( 'acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3323 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3324 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3325 + endif;
3326 + endif;
3996 3327 else :
3997 - // Get regular usermeta value for the user.
3998 - $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3328 + $approved_user['is_wp_user'] = false;
3999 3329 endif;
4000 - if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
4001 - $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
4002 - endif;
4003 - endif;
4004 - endif;
4005 - if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
4006 - $approved_user['usermeta'] = '';
4007 - endif;
4008 - ?>
4009 - <li>
4010 - <input
4011 - type="text"
4012 - id="<?php echo esc_attr( $option_id ); ?>"
4013 - value="<?php echo esc_attr( $approved_user['email'] ); ?>"
4014 - readonly="true"
4015 - class="<?php echo esc_attr( $this->create_class_name( 'email', $is_multisite_user ) ); ?>"
4016 - />
4017 - <select
4018 - id="<?php echo esc_attr( $option_id ); ?>_role"
4019 - class="<?php echo esc_attr( $this->create_class_name( 'role', $is_multisite_user ) ); ?>"
4020 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>ChangeRole( this );"
4021 - <?php if ( $is_multisite_user ) : ?>
4022 - disabled="disabled"
4023 - <?php endif; ?>
4024 - >
4025 - <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
4026 - <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3330 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3331 + $approved_user['usermeta'] = '';
3332 + endif; ?>
3333 + <li>
3334 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email" />
3335 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role" onchange="<?php echo $js_function_prefix; ?>change_role( this );">
3336 + <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
3337 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3338 + </select>
3339 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3340 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3341 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3342 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3343 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3344 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3345 + $should_show_usermeta_in_text_field = false; ?>
3346 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );" >
3347 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3348 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3349 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && $key === $approved_user['usermeta']['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3350 + <?php endforeach; ?>
3351 + </select>
3352 + <?php endif; ?>
3353 + <?php endif; ?>
3354 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3355 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta" />
3356 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3357 + <?php endif; ?>
3358 + <?php endif; ?>
3359 + <?php if ( ! $is_current_user ): ?>
3360 + <?php if ( ! $multisite_admin_page ) : ?>
3361 + <a class="button" id="block_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>add_user( this, 'blocked', false ); <?php echo $js_function_prefix; ?>ignore_user( this, 'approved' );" title="<?php _e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
3362 + <?php endif; ?>
3363 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>ignore_user(this, 'approved' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3364 + <?php endif; ?>
3365 + <?php echo $local_user_icon; ?>
3366 + </li>
3367 + <?php endforeach; ?>
3368 + </ul>
3369 + <div id="new_auth_settings_<?php echo $option; ?>">
3370 + <input type="text" id="new_approved_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3371 + <select id="new_approved_user_role" class="auth-role">
3372 + <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
4027 3373 </select>
4028 - <input
4029 - type="text"
4030 - id="<?php echo esc_attr( $option_id ); ?>_date_added"
4031 - value="<?php echo esc_attr( date( 'M Y', strtotime( $approved_user['date_added'] ) ) ); ?>"
4032 - readonly="true"
4033 - class="<?php echo esc_attr( $this->create_class_name( 'date-added', $is_multisite_user ) ); ?>"
4034 - />
4035 - <?php
4036 - if ( strlen( $advanced_usermeta ) > 0 ) :
4037 - $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
4038 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
4039 - $field_object = get_field_object( str_replace( 'acf___', '', $advanced_usermeta ) );
4040 - if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && 'select' === $field_object['type'] ) :
4041 - $should_show_usermeta_in_text_field = false;
4042 - ?>
4043 - <select
4044 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4045 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4046 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );"
4047 - >
4048 - <option value=""<?php selected( empty( $approved_user['usermeta'] ) ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4049 - <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
4050 - <option value="<?php echo esc_attr( $key ); ?>"<?php selected( $key === $approved_user['usermeta'] || ( isset( $approved_user['usermeta']['meta_value'] ) && $key === $approved_user['usermeta']['meta_value'] ) ); ?>><?php echo esc_html( $label ); ?></option>
4051 - <?php endforeach; ?>
4052 - </select>
4053 - <?php endif; ?>
4054 - <?php endif; ?>
4055 - <?php if ( $should_show_usermeta_in_text_field ) : ?>
4056 - <input
4057 - type="text"
4058 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4059 - value="<?php echo esc_attr( $approved_user['usermeta'], ENT_COMPAT ); ?>"
4060 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4061 - />
4062 - <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
4063 - <?php endif; ?>
4064 - <?php endif; ?>
4065 - <?php if ( ! $is_current_user && ! $is_multisite_user ) : ?>
4066 - <?php if ( ! $is_multisite_admin_page ) : ?>
4067 - <a class="button" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( this, 'blocked', false ); <?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser( this, 'approved' );" title="<?php esc_attr_e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
4068 - <?php endif; ?>
4069 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser(this, 'approved' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4070 - <?php endif; ?>
4071 - <?php if ( $is_local_user ) : ?>
4072 - &nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>
4073 - <?php endif; ?>
4074 - <?php if ( $is_multisite_user ) : ?>
4075 - &nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
4076 - <?php endif; ?>
4077 - </li>
3374 + <div class="btn-group">
3375 + <a href="javascript:void(0);" class="btn button-primary dropdown-toggle" id="approve_user_new" onclick="<?php echo $js_function_prefix; ?>add_user(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3376 + <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3377 + <span class="caret"></span>
3378 + <span class="sr-only"><?php _e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3379 + </button>
3380 + <ul class="dropdown-menu" role="menu">
3381 + <li><a href="javascript:void(0);" onclick="<?php echo $js_function_prefix; ?>add_user( document.getElementById('approve_user_new' ), 'approved', true);"><?php _e( 'Create a local WordPress <br />account instead, and email <br />the user their password.', 'authorizer' ); ?></a></li>
3382 + </ul>
3383 + </div>
3384 + </div>
4078 3385 <?php
4079 3386 }
4080 3387
4081 3388
4082 - /**
4083 - * Settings print callback.
4084 - *
4085 - * @param string $args Args (e.g., multisite admin mode).
4086 - * @return void
4087 - */
4088 - public function print_combo_auth_access_users_blocked( $args = '' ) {
3389 + function print_combo_auth_access_users_blocked( $args = '' ) {
4089 3390 // Get plugin option.
4090 - $option = 'access_users_blocked';
3391 + $option = 'access_users_blocked';
4091 3392 $auth_settings_option = $this->get_plugin_option( $option );
4092 3393 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4093 3394
4094 3395 // Get default role for new blocked user dropdown.
4095 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3396 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
4096 3397
4097 - // Render wrapper div (for aligning pager to width of content).
4098 - ?>
4099 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
4100 - <ul id="list_auth_settings_<?php echo esc_attr( $option ); ?>" style="margin:0;">
4101 - <?php
4102 - foreach ( $auth_settings_option as $key => $blocked_user ) :
4103 - if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) :
4104 - continue;
4105 - endif;
4106 - $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
4107 - if ( $blocked_wp_user ) :
4108 - $blocked_user['email'] = $blocked_wp_user->user_email;
4109 - $blocked_user['role'] = array_shift( $blocked_wp_user->roles );
4110 - $blocked_user['date_added'] = $blocked_wp_user->user_registered;
4111 - $blocked_user['is_wp_user'] = true;
4112 - else :
4113 - $blocked_user['is_wp_user'] = false;
4114 - endif;
4115 - ?>
4116 - <li>
4117 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $blocked_user['email'] ); ?>" readonly="true" class="auth-email" />
4118 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
4119 - <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
4120 - </select>
4121 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_date_added" value="<?php echo esc_attr( date( 'M Y', strtotime( $blocked_user['date_added'] ) ) ); ?>" readonly="true" class="auth-date-added" />
4122 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'blocked' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4123 - </li>
4124 - <?php endforeach; ?>
4125 - </ul>
4126 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
4127 - <input type="text" id="new_blocked_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
4128 - <select id="new_blocked_user_role" class="auth-role">
4129 - <option value="<?php echo esc_attr( $access_default_role ); ?>"><?php echo esc_html( ucfirst( $access_default_role ) ); ?></option>
4130 - </select>
4131 - <a href="javascript:void(0);" class="button-primary button-add-user" id="block_user_new" onclick="authAddUser( this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
4132 - </div>
3398 + // Print option elements.
3399 + ?><ul id="list_auth_settings_<?php echo $option; ?>" style="margin:0;">
3400 + <?php foreach ( $auth_settings_option as $key => $blocked_user ): ?>
3401 + <?php if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) continue; ?>
3402 + <?php if ( $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ) ): ?>
3403 + <?php $blocked_user['email'] = $blocked_wp_user->user_email; ?>
3404 + <?php $blocked_user['role'] = array_shift( $blocked_wp_user->roles ); ?>
3405 + <?php $blocked_user['date_added'] = $blocked_wp_user->user_registered; ?>
3406 + <?php $blocked_user['is_wp_user'] = true; ?>
3407 + <?php else: ?>
3408 + <?php $blocked_user['is_wp_user'] = false; ?>
3409 + <?php endif; ?>
3410 + <li>
3411 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $blocked_user['email']; ?>" readonly="true" class="auth-email" />
3412 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3413 + <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
3414 + </select>
3415 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $blocked_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3416 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user(this, 'blocked' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3417 + </li>
3418 + <?php endforeach; ?>
3419 + </ul>
3420 + <div id="new_auth_settings_<?php echo $option; ?>">
3421 + <input type="text" id="new_blocked_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3422 + <select id="new_blocked_user_role" class="auth-role">
3423 + <option value="<?php echo $access_default_role; ?>"><?php echo ucfirst( $access_default_role ); ?></option>
3424 + </select>
3425 + <a href="javascript:void(0);" class="button-primary" id="block_user_new" onclick="auth_add_user(this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
4133 3426 </div>
4134 3427 <?php
4135 3428 }
4136 3429
4137 3430
4138 - /**
4139 - * Settings print callback.
4140 - *
4141 - * @param string $args Args (e.g., multisite admin mode).
4142 - * @return void
4143 - */
4144 - public function print_section_info_access_login( $args = '' ) {
4145 - ?>
4146 - <div id="section_info_access_login" class="section_info">
3431 + function print_section_info_access_login( $args = '' ) {
3432 + ?><div id="section_info_access_login" class="section_info">
4147 3433 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
4148 - <p><?php esc_html_e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
4149 - </div>
4150 - <?php
3434 + <p><?php _e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
3435 + </div><?php
4151 3436 }
4152 3437
4153 3438
4154 - /**
4155 - * Settings print callback.
4156 - *
4157 - * @param string $args Args (e.g., multisite admin mode).
4158 - * @return void
4159 - */
4160 - public function print_radio_auth_access_who_can_login( $args = '' ) {
3439 + function print_radio_auth_access_who_can_login( $args = '' ) {
4161 3440 // Get plugin option.
4162 - $option = 'access_who_can_login';
4163 - $admin_mode = $this->get_admin_mode( $args );
3441 + $option = 'access_who_can_login';
3442 + $admin_mode = $this->get_admin_mode( $args );
4164 3443 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4165 3444
4166 3445 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4167 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3446 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4168 3447 $auth_settings_option = $this->get_plugin_option( $option );
4169 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) === '1' ) {
3448 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4170 3449 // Workaround: javascript code hides/shows other settings based
4171 3450 // on the selection in this option. If this option is overridden
4172 3451 // by a multisite option, it should show that value in order to
4173 3452 // correctly display the other appropriate options.
@@ -4173,49 +3452,33 @@
4173 3452 // correctly display the other appropriate options.
4174 3453 // Side effect: this site option will be overwritten by the
4175 3454 // multisite option on save. Since this is a 2-item radio, we
4176 3455 // determined this was acceptable.
4177 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3456 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4178 3457 }
4179 3458
4180 3459 // Print option elements.
4181 - ?>
4182 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="external_users"<?php checked( 'external_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users"><?php esc_html_e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
4183 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="approved_users"<?php checked( 'approved_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users"><?php esc_html_e( 'Only', 'authorizer' ); ?> <a href="javascript:chooseTab('access_lists' );" id="dashboard_link_approved_users"><?php esc_html_e( 'approved users', 'authorizer' ); ?></a> <?php esc_html_e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br />
4184 - <?php
3460 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_external_users" name="auth_settings[<?php echo $option; ?>]" value="external_users"<?php checked( 'external_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_external_users"><?php _e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
3461 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_approved_users" name="auth_settings[<?php echo $option; ?>]" value="approved_users"<?php checked( 'approved_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_approved_users"><?php _e( 'Only', 'authorizer' ); ?> <a href="javascript:choose_tab('access_lists' );" id="dashboard_link_approved_users"><?php _e( 'approved users', 'authorizer' ); ?></a> <?php _e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br /><?php
4185 3462 }
4186 3463
4187 3464
4188 - /**
4189 - * Settings print callback.
4190 - *
4191 - * @param string $args Args (e.g., multisite admin mode).
4192 - * @return void
4193 - */
4194 - public function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
3465 + function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
4195 3466 // Get plugin option.
4196 - $option = 'access_role_receive_pending_emails';
3467 + $option = 'access_role_receive_pending_emails';
4197 3468 $auth_settings_option = $this->get_plugin_option( $option );
4198 3469
4199 3470 // Print option elements.
4200 - ?>
4201 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
4202 - <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php esc_html_e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
3471 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
3472 + <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php _e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
4203 3473 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4204 - </select>
4205 - <?php
3474 + </select><?php
4206 3475 }
4207 3476
4208 3477
4209 - /**
4210 - * Settings print callback.
4211 - *
4212 - * @param string $args Args (e.g., multisite admin mode).
4213 - * @return void
4214 - */
4215 - public function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
3478 + function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
4216 3479 // Get plugin option.
4217 - $option = 'access_pending_redirect_to_message';
3480 + $option = 'access_pending_redirect_to_message';
4218 3481 $auth_settings_option = $this->get_plugin_option( $option );
4219 3482
4220 3483 // Print option elements.
4221 3484 wp_editor(
@@ -4224,25 +3487,19 @@
4224 3487 array(
4225 3488 'media_buttons' => false,
4226 3489 'textarea_name' => "auth_settings[$option]",
4227 3490 'textarea_rows' => 5,
4228 - 'tinymce' => true,
4229 - 'teeny' => true,
4230 - 'quicktags' => false,
3491 + 'tinymce' => true,
3492 + 'teeny' => true,
3493 + 'quicktags' => false,
4231 3494 )
4232 3495 );
4233 3496 }
4234 3497
4235 3498
4236 - /**
4237 - * Settings print callback.
4238 - *
4239 - * @param string $args Args (e.g., multisite admin mode).
4240 - * @return void
4241 - */
4242 - public function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
3499 + function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
4243 3500 // Get plugin option.
4244 - $option = 'access_blocked_redirect_to_message';
3501 + $option = 'access_blocked_redirect_to_message';
4245 3502 $auth_settings_option = $this->get_plugin_option( $option );
4246 3503
4247 3504 // Print option elements.
4248 3505 wp_editor(
@@ -4251,61 +3508,39 @@
4251 3508 array(
4252 3509 'media_buttons' => false,
4253 3510 'textarea_name' => "auth_settings[$option]",
4254 3511 'textarea_rows' => 5,
4255 - 'tinymce' => true,
4256 - 'teeny' => true,
4257 - 'quicktags' => false,
3512 + 'tinymce' => true,
3513 + 'teeny' => true,
3514 + 'quicktags' => false,
4258 3515 )
4259 3516 );
4260 3517 }
4261 3518
4262 3519
4263 - /**
4264 - * Settings print callback.
4265 - *
4266 - * @param string $args Args (e.g., multisite admin mode).
4267 - * @return void
4268 - */
4269 - public function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
3520 + function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
4270 3521 // Get plugin option.
4271 - $option = 'access_should_email_approved_users';
3522 + $option = 'access_should_email_approved_users';
4272 3523 $auth_settings_option = $this->get_plugin_option( $option );
4273 3524
4274 3525 // Print option elements.
4275 - ?>
4276 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label>
4277 - <?php
3526 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label><?php
4278 3527 }
4279 3528
4280 3529
4281 - /**
4282 - * Settings print callback.
4283 - *
4284 - * @param string $args Args (e.g., multisite admin mode).
4285 - * @return void
4286 - */
4287 - public function print_text_auth_access_email_approved_users_subject( $args = '' ) {
3530 + function print_text_auth_access_email_approved_users_subject( $args = '' ) {
4288 3531 // Get plugin option.
4289 - $option = 'access_email_approved_users_subject';
3532 + $option = 'access_email_approved_users_subject';
4290 3533 $auth_settings_option = $this->get_plugin_option( $option );
4291 3534
4292 3535 // Print option elements.
4293 - ?>
4294 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php echo wp_kses( __( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ), $this->allowed_html ); ?></small>
4295 - <?php
3536 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php _e( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ); ?></small><?php
4296 3537 }
4297 3538
4298 3539
4299 - /**
4300 - * Settings print callback.
4301 - *
4302 - * @param string $args Args (e.g., multisite admin mode).
4303 - * @return void
4304 - */
4305 - public function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
3540 + function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
4306 3541 // Get plugin option.
4307 - $option = 'access_email_approved_users_body';
3542 + $option = 'access_email_approved_users_body';
4308 3543 $auth_settings_option = $this->get_plugin_option( $option );
4309 3544
4310 3545 // Print option elements.
4311 3546 wp_editor(
@@ -4314,60 +3549,42 @@
4314 3549 array(
4315 3550 'media_buttons' => false,
4316 3551 'textarea_name' => "auth_settings[$option]",
4317 3552 'textarea_rows' => 9,
4318 - 'tinymce' => true,
4319 - 'teeny' => true,
4320 - 'quicktags' => false,
3553 + 'tinymce' => true,
3554 + 'teeny' => true,
3555 + 'quicktags' => false,
4321 3556 )
4322 3557 );
4323 - ?>
4324 - <small>
4325 - <?php
4326 - printf(
4327 - /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
4328 - wp_kses( __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ), $this->allowed_html ),
4329 - '<b>[site_name]</b>',
4330 - '<b>[site_url]</b>',
4331 - '<b>[user_email]</b>'
4332 - );
4333 - ?>
4334 - </small>
4335 - <?php
3558 +
3559 + ?><small><?php printf(
3560 + /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
3561 + __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ),
3562 + '<b>[site_name]</b>',
3563 + '<b>[site_url]</b>',
3564 + '<b>[user_email]</b>'
3565 + ); ?></small><?php
3566 +
4336 3567 }
4337 3568
4338 3569
4339 - /**
4340 - * Settings print callback.
4341 - *
4342 - * @param string $args Args (e.g., multisite admin mode).
4343 - * @return void
4344 - */
4345 - public function print_section_info_access_public( $args = '' ) {
4346 - ?>
4347 - <div id="section_info_access_public" class="section_info">
4348 - <p><?php esc_html_e( 'Choose your public access options here.', 'authorizer' ); ?></p>
4349 - </div>
4350 - <?php
3570 + function print_section_info_access_public( $args = '' ) {
3571 + ?><div id="section_info_access_public" class="section_info">
3572 + <p><?php _e( 'Choose your public access options here.', 'authorizer' ); ?></p>
3573 + </div><?php
4351 3574 }
4352 3575
4353 3576
4354 - /**
4355 - * Settings print callback.
4356 - *
4357 - * @param string $args Args (e.g., multisite admin mode).
4358 - * @return void
4359 - */
4360 - public function print_radio_auth_access_who_can_view( $args = '' ) {
3577 + function print_radio_auth_access_who_can_view( $args = '' ) {
4361 3578 // Get plugin option.
4362 - $option = 'access_who_can_view';
4363 - $admin_mode = $this->get_admin_mode( $args );
3579 + $option = 'access_who_can_view';
3580 + $admin_mode = $this->get_admin_mode( $args );
4364 3581 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4365 3582
4366 3583 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4367 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3584 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4368 3585 $auth_settings_option = $this->get_plugin_option( $option );
4369 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && '1' === $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) ) {
3586 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4370 3587 // Workaround: javascript code hides/shows other settings based
4371 3588 // on the selection in this option. If this option is overridden
4372 3589 // by a multisite option, it should show that value in order to
4373 3590 // correctly display the other appropriate options.
@@ -4373,66 +3590,42 @@
4373 3590 // correctly display the other appropriate options.
4374 3591 // Side effect: this site option will be overwritten by the
4375 3592 // multisite option on save. Since this is a 2-item radio, we
4376 3593 // determined this was acceptable.
4377 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3594 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4378 3595 }
4379 3596
4380 3597 // Print option elements.
4381 - ?>
4382 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="everyone"<?php checked( 'everyone' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone"><?php esc_html_e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
4383 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="logged_in_users"<?php checked( 'logged_in_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users"><?php esc_html_e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br />
4384 - <?php
3598 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_everyone" name="auth_settings[<?php echo $option; ?>]" value="everyone"<?php checked( 'everyone' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_everyone"><?php _e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
3599 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_logged_in_users" name="auth_settings[<?php echo $option; ?>]" value="logged_in_users"<?php checked( 'logged_in_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_logged_in_users"><?php _e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br /><?php
4385 3600 }
4386 3601
4387 3602
4388 - /**
4389 - * Settings print callback.
4390 - *
4391 - * @param string $args Args (e.g., multisite admin mode).
4392 - * @return void
4393 - */
4394 - public function print_radio_auth_access_redirect( $args = '' ) {
3603 + function print_radio_auth_access_redirect( $args = '' ) {
4395 3604 // Get plugin option.
4396 - $option = 'access_redirect';
3605 + $option = 'access_redirect';
4397 3606 $auth_settings_option = $this->get_plugin_option( $option );
4398 3607
4399 3608 // Print option elements.
4400 - ?>
4401 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="login"<?php checked( 'login' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login"><?php esc_html_e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
4402 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="message"<?php checked( 'message' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message"><?php esc_html_e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label>
4403 - <?php
3609 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_login" name="auth_settings[<?php echo $option; ?>]" value="login"<?php checked( 'login' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_login"><?php _e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
3610 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_message" name="auth_settings[<?php echo $option; ?>]" value="message"<?php checked( 'message' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_message"><?php _e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label><?php
4404 3611 }
4405 3612
4406 3613
4407 - /**
4408 - * Settings print callback.
4409 - *
4410 - * @param string $args Args (e.g., multisite admin mode).
4411 - * @return void
4412 - */
4413 - public function print_radio_auth_access_public_warning( $args = '' ) {
3614 + function print_radio_auth_access_public_warning( $args = '' ) {
4414 3615 // Get plugin option.
4415 - $option = 'access_public_warning';
3616 + $option = 'access_public_warning';
4416 3617 $auth_settings_option = $this->get_plugin_option( $option );
4417 3618
4418 3619 // Print option elements.
4419 - ?>
4420 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="no_warning"<?php checked( 'no_warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no"><?php echo wp_kses( __( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ), $this->allowed_html ); ?></label><br />
4421 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="warning"<?php checked( 'warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>"><?php echo wp_kses( __( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ), $this->allowed_html ); ?></label>
4422 - <?php
3620 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_no" name="auth_settings[<?php echo $option; ?>]" value="no_warning"<?php checked( 'no_warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_no"><?php _e( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ); ?></label><br />
3621 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="warning"<?php checked( 'warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>"><?php _e( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ); ?></label><?php
4423 3622 }
4424 3623
4425 3624
4426 - /**
4427 - * Settings print callback.
4428 - *
4429 - * @param string $args Args (e.g., multisite admin mode).
4430 - * @return void
4431 - */
4432 - public function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
3625 + function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
4433 3626 // Get plugin option.
4434 - $option = 'access_redirect_to_message';
3627 + $option = 'access_redirect_to_message';
4435 3628 $auth_settings_option = $this->get_plugin_option( $option );
4436 3629
4437 3630 // Print option elements.
4438 3631 wp_editor(
@@ -4441,25 +3634,19 @@
4441 3634 array(
4442 3635 'media_buttons' => false,
4443 3636 'textarea_name' => "auth_settings[$option]",
4444 3637 'textarea_rows' => 5,
4445 - 'tinymce' => true,
4446 - 'teeny' => true,
4447 - 'quicktags' => false,
3638 + 'tinymce' => true,
3639 + 'teeny' => true,
3640 + 'quicktags' => false,
4448 3641 )
4449 3642 );
4450 3643 }
4451 3644
4452 3645
4453 - /**
4454 - * Settings print callback.
4455 - *
4456 - * @param string $args Args (e.g., multisite admin mode).
4457 - * @return void
4458 - */
4459 - public function print_multiselect_auth_access_public_pages( $args = '' ) {
3646 + function print_multiselect_auth_access_public_pages( $args = '' ) {
4460 3647 // Get plugin option.
4461 - $option = 'access_public_pages';
3648 + $option = 'access_public_pages';
4462 3649 $auth_settings_option = $this->get_plugin_option( $option );
4463 3650 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4464 3651
4465 3652 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
@@ -4465,31 +3652,23 @@
4465 3652 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
4466 3653 $post_types = is_array( $post_types ) ? $post_types : array();
4467 3654
4468 3655 // Print option elements.
4469 - ?>
4470 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" multiple="multiple" name="auth_settings[<?php echo esc_attr( $option ); ?>][]">
4471 - <optgroup label="<?php esc_attr_e( 'Home', 'authorizer' ); ?>">
4472 - <option value="home" <?php selected( in_array( 'home', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Home Page', 'authorizer' ); ?></option>
4473 - <option value="auth_public_404" <?php selected( in_array( 'auth_public_404', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
3656 + ?><select id="auth_settings_<?php echo $option; ?>" multiple="multiple" name="auth_settings[<?php echo $option; ?>][]">
3657 + <optgroup label="<?php _e( 'Home', 'authorizer' ); ?>">
3658 + <option value="home" <?php echo in_array( 'home', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Home Page', 'authorizer' ); ?></option>
3659 + <option value="auth_public_404" <?php echo in_array( 'auth_public_404', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
4474 3660 </optgroup>
4475 - <?php foreach ( $post_types as $post_type ) : ?>
4476 - <optgroup label="<?php echo esc_attr( ucfirst( $post_type ) ); ?>">
4477 - <?php
4478 - $pages = get_posts(
4479 - array(
4480 - 'post_type' => $post_type,
4481 - 'posts_per_page' => 1000, // phpcs:ignore WordPress.VIP.PostsPerPage.posts_per_page_posts_per_page
4482 - )
4483 - );
4484 - $pages = is_array( $pages ) ? $pages : array();
4485 - foreach ( $pages as $page ) :
4486 - ?>
4487 - <option value="<?php echo esc_attr( $page->ID ); ?>" <?php selected( in_array( strval( $page->ID ), $auth_settings_option, true ) ); ?>><?php echo esc_html( $page->post_title ); ?></option>
3661 + <?php foreach ( $post_types as $post_type ): ?>
3662 + <optgroup label="<?php echo ucfirst( $post_type ); ?>">
3663 + <?php $pages = get_posts( array( 'post_type' => $post_type, 'posts_per_page' => -1 ) ); ?>
3664 + <?php $pages = is_array( $pages ) ? $pages : array(); ?>
3665 + <?php foreach ( $pages as $page ): ?>
3666 + <option value="<?php echo $page->ID; ?>" <?php echo in_array( $page->ID, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $page->post_title; ?></option>
4488 3667 <?php endforeach; ?>
4489 3668 </optgroup>
4490 3669 <?php endforeach; ?>
4491 - <optgroup label="<?php esc_attr_e( 'Categories', 'authorizer' ); ?>">
3670 + <optgroup label="<?php _e( 'Categories', 'authorizer' ); ?>">
4492 3671 <?php
4493 3672 // If sitepress-multilingual-cms plugin is enabled, temporarily disable
4494 3673 // its terms_clauses filter since it conflicts with the category handling.
4495 3674 if ( array_key_exists( 'sitepress', $GLOBALS ) && is_object( $GLOBALS['sitepress'] ) ) {
@@ -4498,155 +3677,107 @@
4498 3677 add_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) );
4499 3678 } else {
4500 3679 $categories = get_categories( array( 'hide_empty' => false ) );
4501 3680 }
4502 - foreach ( $categories as $category ) :
4503 - ?>
4504 - <option value="<?php echo esc_attr( 'cat_' . $category->slug ); ?>" <?php selected( in_array( 'cat_' . $category->slug, $auth_settings_option, true ) ); ?>><?php echo esc_html( $category->name ); ?></option>
3681 + foreach ( $categories as $category ) : ?>
3682 + <option value="<?php echo 'cat_' . $category->slug; ?>" <?php echo in_array( 'cat_' . $category->slug, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $category->name; ?></option>
4505 3683 <?php endforeach; ?>
4506 3684 </optgroup>
4507 - </select>
4508 - <?php
3685 + </select><?php
4509 3686 }
4510 3687
4511 3688
4512 - /**
4513 - * Settings print callback.
4514 - *
4515 - * @param string $args Args (e.g., multisite admin mode).
4516 - * @return void
4517 - */
4518 - public function print_section_info_external( $args = '' ) {
4519 - ?>
4520 - <div id="section_info_external" class="section_info">
4521 - <p><?php esc_html_e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
4522 - </div>
4523 - <?php
3689 + function print_section_info_external( $args = '' ) {
3690 + ?><div id="section_info_external" class="section_info">
3691 + <p><?php _e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
3692 + </div><?php
4524 3693 }
4525 3694
4526 3695
4527 - /**
4528 - * Settings print callback.
4529 - *
4530 - * @param string $args Args (e.g., multisite admin mode).
4531 - * @return void
4532 - */
4533 - public function print_select_auth_access_default_role( $args = '' ) {
3696 + function get_admin_mode( $args ) {
3697 + if ( is_array( $args ) && array_key_exists( MULTISITE_ADMIN, $args ) && $args[MULTISITE_ADMIN] === true ) {
3698 + return MULTISITE_ADMIN;
3699 + } else {
3700 + return SINGLE_ADMIN;
3701 + }
3702 + }
3703 +
3704 +
3705 + function print_select_auth_access_default_role( $args = '' ) {
4534 3706 // Get plugin option.
4535 - $option = 'access_default_role';
3707 + $option = 'access_default_role';
4536 3708 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4537 3709
4538 3710 // Print option elements.
4539 - ?>
4540 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3711 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4541 3712 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4542 - <option value=""<?php selected( '' === $auth_settings_option ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4543 - </select>
4544 - <?php
3713 + </select><?php
4545 3714 }
4546 3715
4547 3716
4548 - /**
4549 - * Settings print callback.
4550 - *
4551 - * @param string $args Args (e.g., multisite admin mode).
4552 - * @return void
4553 - */
4554 - public function print_checkbox_auth_external_google( $args = '' ) {
3717 + function print_checkbox_auth_external_google( $args = '' ) {
4555 3718 // Get plugin option.
4556 - $option = 'google';
3719 + $option = 'google';
4557 3720 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4558 3721
4559 3722 // Print option elements.
4560 - ?>
4561 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable Google Logins', 'authorizer' ); ?></label>
4562 - <?php
3723 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable Google Logins', 'authorizer' ); ?></label><?php
4563 3724 }
4564 3725
4565 3726
4566 - /**
4567 - * Settings print callback.
4568 - *
4569 - * @param string $args Args (e.g., multisite admin mode).
4570 - * @return void
4571 - */
4572 - public function print_text_google_clientid( $args = '' ) {
3727 + function print_text_google_clientid( $args = '' ) {
4573 3728 // Get plugin option.
4574 - $option = 'google_clientid';
3729 + $option = 'google_clientid';
4575 3730 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4576 3731
4577 3732 // Print option elements.
4578 - $site_url_parts = wp_parse_url( get_site_url() );
4579 - $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
4580 -
4581 - esc_html_e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' );
4582 - ?>
3733 + $site_url_parts = parse_url( get_site_url() );
3734 + $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
3735 + ?><?php _e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' ); ?>
4583 3736 <ol>
4584 - <li><?php echo wp_kses( __( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ), $this->allowed_html ); ?></li>
4585 - <li><?php echo wp_kses( __( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ), $this->allowed_html ); ?>
3737 + <li><?php _e( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ); ?></li>
3738 + <li><?php _e( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ); ?>
4586 3739 <ul>
4587 - <li><?php echo wp_kses( __( 'Application Type: <strong>Web application</strong>', 'authorizer' ), $this->allowed_html ); ?></li>
4588 - <li><?php esc_html_e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo esc_html( rtrim( $site_url_host, '/' ) ); ?></strong></li>
4589 - <li><?php echo wp_kses( __( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ), $this->allowed_html ); ?></li>
3740 + <li><?php _e( 'Application Type: <strong>Web application</strong>', 'authorizer' ); ?></li>
3741 + <li><?php _e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo rtrim( $site_url_host, '/' ); ?></strong></li>
3742 + <li><?php _e( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ); ?></li>
4590 3743 </ul>
4591 3744 </li>
4592 - <li><?php esc_html_e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
4593 - <li><?php echo wp_kses( __( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ), $this->allowed_html ); ?></li>
4594 - <li><?php echo wp_kses( __( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ), $this->allowed_html ); ?></li>
3745 + <li><?php _e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
3746 + <li><?php _e( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ); ?></li>
3747 + <li><?php _e( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ); ?></li>
4595 3748 </ol>
4596 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:560px;" />
4597 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer' ); ?></label>
4598 - <?php
3749 + <input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:560px;" />
3750 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer'); ?></label><?php
4599 3751 }
4600 3752
4601 3753
4602 - /**
4603 - * Settings print callback.
4604 - *
4605 - * @param string $args Args (e.g., multisite admin mode).
4606 - * @return void
4607 - */
4608 - public function print_text_google_clientsecret( $args = '' ) {
3754 + function print_text_google_clientsecret( $args = '' ) {
4609 3755 // Get plugin option.
4610 - $option = 'google_clientsecret';
3756 + $option = 'google_clientsecret';
4611 3757 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4612 3758
4613 3759 // Print option elements.
4614 - ?>
4615 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:220px;" />
4616 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer' ); ?></label>
4617 - <?php
3760 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:220px;" />
3761 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer'); ?></label><?php
4618 3762 }
4619 3763
4620 3764
4621 - /**
4622 - * Settings print callback.
4623 - *
4624 - * @param string $args Args (e.g., multisite admin mode).
4625 - * @return void
4626 - */
4627 - public function print_text_google_hosteddomain( $args = '' ) {
3765 + function print_text_google_hosteddomain( $args = '' ) {
4628 3766 // Get plugin option.
4629 - $option = 'google_hosteddomain';
3767 + $option = 'google_hosteddomain';
4630 3768 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4631 3769
4632 3770 // Print option elements.
4633 - ?>
4634 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:220px;"><?php echo esc_html( $auth_settings_option ); ?></textarea>
4635 - <br /><small><?php esc_html_e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php esc_html_e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
3771 + ?><textarea id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" placeholder="" style="width:220px;"><?php echo $auth_settings_option; ?></textarea>
3772 + <br /><small><?php _e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php _e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
4636 3773 <?php
4637 3774 }
4638 3775
4639 3776
4640 - /**
4641 - * Settings print callback.
4642 - *
4643 - * @param string $args Args (e.g., multisite admin mode).
4644 - * @return void
4645 - */
4646 - public function print_checkbox_auth_external_cas( $args = '' ) {
3777 + function print_checkbox_auth_external_cas( $args = '' ) {
4647 3778 // Get plugin option.
4648 - $option = 'cas';
3779 + $option = 'cas';
4649 3780 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4650 3781
4651 3782 // Make sure php5-curl extension is installed on server.
4652 3783 $curl_installed_message = ! function_exists( 'curl_init' ) ? __( '<a href="http://www.php.net//manual/en/curl.installation.php" target="_blank" style="color: red;">PHP CURL extension</a> is not installed', 'authorizer' ) : '';
@@ -4665,558 +3796,319 @@
4665 3796 ')</span>';
4666 3797 }
4667 3798
4668 3799 // Print option elements.
4669 - ?>
4670 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $error_message, $this->allowed_html ); ?>
4671 - <?php
3800 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo $error_message; ?><?php
4672 3801 }
4673 3802
4674 3803
4675 - /**
4676 - * Settings print callback.
4677 - *
4678 - * @param string $args Args (e.g., multisite admin mode).
4679 - * @return void
4680 - */
4681 - public function print_text_cas_custom_label( $args = '' ) {
3804 + function print_text_cas_custom_label( $args = '' ) {
4682 3805 // Get plugin option.
4683 - $option = 'cas_custom_label';
3806 + $option = 'cas_custom_label';
4684 3807 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4685 3808
4686 3809 // Print option elements.
4687 - esc_html_e( 'The button on the login page will read:', 'authorizer' );
4688 - ?>
4689 - <p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php esc_html_e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="CAS" style="width: 100px;" /></a></p>
4690 - <?php
3810 + ?><?php _e( 'The button on the login page will read:', 'authorizer' ); ?><p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php _e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="CAS" style="width: 100px;" /></a></p><?php
4691 3811 }
4692 3812
4693 3813
4694 - /**
4695 - * Settings print callback.
4696 - *
4697 - * @param string $args Args (e.g., multisite admin mode).
4698 - * @return void
4699 - */
4700 - public function print_text_cas_host( $args = '' ) {
3814 + function print_text_cas_host( $args = '' ) {
4701 3815 // Get plugin option.
4702 - $option = 'cas_host';
3816 + $option = 'cas_host';
4703 3817 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4704 3818
4705 3819 // Print option elements.
4706 - ?>
4707 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4708 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: authn.example.edu', 'authorizer' ); ?></label>
4709 - <?php
3820 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3821 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: authn.example.edu', 'authorizer'); ?></label><?php
4710 3822 }
4711 3823
4712 3824
4713 - /**
4714 - * Settings print callback.
4715 - *
4716 - * @param string $args Args (e.g., multisite admin mode).
4717 - * @return void
4718 - */
4719 - public function print_text_cas_port( $args = '' ) {
3825 + function print_text_cas_port( $args = '' ) {
4720 3826 // Get plugin option.
4721 - $option = 'cas_port';
3827 + $option = 'cas_port';
4722 3828 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4723 3829
4724 3830 // Print option elements.
4725 - ?>
4726 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4727 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 443', 'authorizer' ); ?></label>
4728 - <?php
3831 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:50px;" />
3832 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 443', 'authorizer'); ?></label><?php
4729 3833 }
4730 3834
4731 3835
4732 - /**
4733 - * Settings print callback.
4734 - *
4735 - * @param string $args Args (e.g., multisite admin mode).
4736 - * @return void
4737 - */
4738 - public function print_text_cas_path( $args = '' ) {
3836 + function print_text_cas_path( $args = '' ) {
4739 3837 // Get plugin option.
4740 - $option = 'cas_path';
3838 + $option = 'cas_path';
4741 3839 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4742 3840
4743 3841 // Print option elements.
4744 - ?>
4745 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4746 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: /cas', 'authorizer' ); ?></label>
4747 - <?php
3842 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3843 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: /cas', 'authorizer'); ?></label><?php
4748 3844 }
4749 3845
4750 3846
4751 - /**
4752 - * Settings print callback.
4753 - *
4754 - * @param string $args Args (e.g., multisite admin mode).
4755 - * @return void
4756 - */
4757 - public function print_select_cas_version( $args = '' ) {
3847 + function print_select_cas_version( $args = '' ) {
4758 3848 // Get plugin option.
4759 - $option = 'cas_version';
3849 + $option = 'cas_version';
4760 3850 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4761 3851
4762 3852 // Print option elements.
4763 - ?>
4764 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3853 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4765 3854 <option value="SAML_VERSION_1_1" <?php selected( $auth_settings_option, 'SAML_VERSION_1_1' ); ?>>SAML_VERSION_1_1</option>
4766 3855 <option value="CAS_VERSION_3_0" <?php selected( $auth_settings_option, 'CAS_VERSION_3_0' ); ?>>CAS_VERSION_3_0</option>
4767 3856 <option value="CAS_VERSION_2_0" <?php selected( $auth_settings_option, 'CAS_VERSION_2_0' ); ?>>CAS_VERSION_2_0</option>
4768 3857 <option value="CAS_VERSION_1_0" <?php selected( $auth_settings_option, 'CAS_VERSION_1_0' ); ?>>CAS_VERSION_1_0</option>
4769 - </select>
4770 - <?php
3858 + </select><?php
4771 3859 }
4772 3860
4773 3861
4774 - /**
4775 - * Settings print callback.
4776 - *
4777 - * @param string $args Args (e.g., multisite admin mode).
4778 - * @return void
4779 - */
4780 - public function print_text_cas_attr_email( $args = '' ) {
3862 + function print_text_cas_attr_email( $args = '' ) {
4781 3863 // Get plugin option.
4782 - $option = 'cas_attr_email';
3864 + $option = 'cas_attr_email';
4783 3865 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4784 3866
4785 3867 // Print option elements.
4786 - ?>
4787 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4788 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
4789 - <br /><small><?php echo wp_kses( __( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
4790 - <?php
3868 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3869 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: mail', 'authorizer'); ?></label>
3870 + <br /><small><?php _e( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
4791 3871 }
4792 3872
4793 3873
4794 - /**
4795 - * Settings print callback.
4796 - *
4797 - * @param string $args Args (e.g., multisite admin mode).
4798 - * @return void
4799 - */
4800 - public function print_text_cas_attr_first_name( $args = '' ) {
3874 + function print_text_cas_attr_first_name( $args = '' ) {
4801 3875 // Get plugin option.
4802 - $option = 'cas_attr_first_name';
3876 + $option = 'cas_attr_first_name';
4803 3877 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4804 3878
4805 3879 // Print option elements.
4806 - ?>
4807 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4808 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenName', 'authorizer' ); ?></label>
4809 - <?php
3880 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3881 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: givenName', 'authorizer'); ?></label><?php
4810 3882 }
4811 3883
4812 3884
4813 - /**
4814 - * Settings print callback.
4815 - *
4816 - * @param string $args Args (e.g., multisite admin mode).
4817 - * @return void
4818 - */
4819 - public function print_text_cas_attr_last_name( $args = '' ) {
3885 + function print_text_cas_attr_last_name( $args = '' ) {
4820 3886 // Get plugin option.
4821 - $option = 'cas_attr_last_name';
3887 + $option = 'cas_attr_last_name';
4822 3888 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4823 3889
4824 3890 // Print option elements.
4825 - ?>
4826 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4827 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
4828 - <?php
3891 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3892 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sn', 'authorizer'); ?></label><?php
4829 3893 }
4830 3894
4831 3895
4832 - /**
4833 - * Settings print callback.
4834 - *
4835 - * @param string $args Args (e.g., multisite admin mode).
4836 - * @return void
4837 - */
4838 - public function print_checkbox_cas_attr_update_on_login( $args = '' ) {
3896 + function print_checkbox_cas_attr_update_on_login( $args = '' ) {
4839 3897 // Get plugin option.
4840 - $option = 'cas_attr_update_on_login';
3898 + $option = 'cas_attr_update_on_login';
4841 3899 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4842 3900
4843 3901 // Print option elements.
4844 - ?>
4845 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
4846 - <?php
3902 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
4847 3903 }
4848 3904
4849 3905
4850 - /**
4851 - * Settings print callback.
4852 - *
4853 - * @param string $args Args (e.g., multisite admin mode).
4854 - * @return void
4855 - */
4856 - public function print_checkbox_cas_auto_login( $args = '' ) {
3906 + function print_checkbox_cas_auto_login( $args = '' ) {
4857 3907 // Get plugin option.
4858 - $option = 'cas_auto_login';
3908 + $option = 'cas_auto_login';
4859 3909 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4860 3910
4861 3911 // Print option elements.
4862 - ?>
4863 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
4864 - <p><small><?php esc_html_e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p>
4865 - <?php
3912 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
3913 + <p><small><?php _e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p><?php
4866 3914 }
4867 3915
4868 3916
4869 - /**
4870 - * Settings print callback.
4871 - *
4872 - * @param string $args Args (e.g., multisite admin mode).
4873 - * @return void
4874 - */
4875 - public function print_checkbox_cas_link_on_username( $args = '' ) {
3917 + function print_checkbox_auth_external_ldap( $args = '' ) {
4876 3918 // Get plugin option.
4877 - $option = 'cas_link_on_username';
3919 + $option = 'ldap';
4878 3920 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4879 3921
4880 - // Print option elements.
4881 - ?>
4882 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Link CAS accounts to WordPress accounts by their username (leave this off to link by email address)", 'authorizer' ); ?></label>
4883 - <p><small><?php esc_html_e( "Note: The default (and most secure) behavior is to associate WordPress accounts with CAS accounts by the email they have in common. However, some uncommon CAS server configurations don't contain email addresses for users. Enable this option if your CAS server doesn't have an attribute containing an email, or if you have WordPress accounts that don't have emails.", 'authorizer' ); ?></small></p>
4884 - <?php
4885 - }
4886 -
4887 -
4888 - /**
4889 - * Settings print callback.
4890 - *
4891 - * @param string $args Args (e.g., multisite admin mode).
4892 - * @return void
4893 - */
4894 - public function print_checkbox_auth_external_ldap( $args = '' ) {
4895 - // Get plugin option.
4896 - $option = 'ldap';
4897 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4898 -
4899 3922 // Make sure php5-ldap extension is installed on server.
4900 3923 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
4901 3924
4902 3925 // Print option elements.
4903 - ?>
4904 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $ldap_installed_message, $this->allowed_html ); ?>
4905 - <?php
3926 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo $ldap_installed_message; ?><?php
4906 3927 }
4907 3928
4908 3929
4909 - /**
4910 - * Settings print callback.
4911 - *
4912 - * @param string $args Args (e.g., multisite admin mode).
4913 - * @return void
4914 - */
4915 - public function print_text_ldap_host( $args = '' ) {
3930 + function print_text_ldap_host( $args = '' ) {
4916 3931 // Get plugin option.
4917 - $option = 'ldap_host';
3932 + $option = 'ldap_host';
4918 3933 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4919 3934
4920 3935 // Print option elements.
4921 - ?>
4922 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
4923 - <br /><small><?php esc_html_e( 'Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).', 'authorizer' ); ?></small>
4924 - <?php
3936 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
3937 + <br /><small><?php _e( "Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).", 'authorizer' ); ?></small><?php
4925 3938 }
4926 3939
4927 3940
4928 - /**
4929 - * Settings print callback.
4930 - *
4931 - * @param string $args Args (e.g., multisite admin mode).
4932 - * @return void
4933 - */
4934 - public function print_text_ldap_port( $args = '' ) {
3941 + function print_text_ldap_port( $args = '' ) {
4935 3942 // Get plugin option.
4936 - $option = 'ldap_port';
3943 + $option = 'ldap_port';
4937 3944 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4938 3945
4939 3946 // Print option elements.
4940 - ?>
4941 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4942 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 389', 'authorizer' ); ?></label>
4943 - <br /><small><?php esc_html_e( 'If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.', 'authorizer' ); ?></small>
4944 - <?php
3947 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:50px;" />
3948 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 389', 'authorizer' ); ?></label>
3949 + <br /><small><?php _e( "If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.", 'authorizer' ); ?></small><?php
4945 3950 }
4946 3951
4947 3952
4948 - /**
4949 - * Settings print callback.
4950 - *
4951 - * @param string $args Args (e.g., multisite admin mode).
4952 - * @return void
4953 - */
4954 - public function print_checkbox_ldap_tls( $args = '' ) {
3953 + function print_checkbox_ldap_tls( $args = '' ) {
4955 3954 // Get plugin option.
4956 - $option = 'ldap_tls';
3955 + $option = 'ldap_tls';
4957 3956 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4958 3957
4959 3958 // Print option elements.
4960 - ?>
4961 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></label>
4962 - <br /><small><?php esc_html_e( 'If ldaps is used, this should be unchecked', 'authorizer' ); ?></small>
4963 - <?php
3959 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Use TLS', 'authorizer' ); ?></label><?php
4964 3960 }
4965 3961
4966 3962
4967 - /**
4968 - * Settings print callback.
4969 - *
4970 - * @param string $args Args (e.g., multisite admin mode).
4971 - * @return void
4972 - */
4973 - public function print_text_ldap_search_base( $args = '' ) {
3963 + function print_text_ldap_search_base( $args = '' ) {
4974 3964 // Get plugin option.
4975 - $option = 'ldap_search_base';
3965 + $option = 'ldap_search_base';
4976 3966 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4977 3967
4978 3968 // Print option elements.
4979 - ?>
4980 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:330px;"><?php echo esc_attr( $auth_settings_option ); ?></textarea>
4981 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: ou=people,dc=example,dc=edu', 'authorizer' ); ?></label>
4982 - <br /><small><?php esc_html_e( 'If you have multiple search bases, separate them by newlines (one per line).', 'authorizer' ); ?></small>
4983 - <?php
3969 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
3970 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: ou=people,dc=example,dc=edu', 'authorizer'); ?></label><?php
4984 3971 }
4985 3972
4986 3973
4987 - /**
4988 - * Settings print callback.
4989 - *
4990 - * @param string $args Args (e.g., multisite admin mode).
4991 - * @return void
4992 - */
4993 - public function print_text_ldap_uid( $args = '' ) {
3974 + function print_text_ldap_uid( $args = '' ) {
4994 3975 // Get plugin option.
4995 - $option = 'ldap_uid';
3976 + $option = 'ldap_uid';
4996 3977 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4997 3978
4998 3979 // Print option elements.
4999 - ?>
5000 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:80px;" />
5001 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: uid', 'authorizer' ); ?></label>
5002 - <?php
3980 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:80px;" />
3981 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: uid', 'authorizer' ); ?></label><?php
5003 3982 }
5004 3983
5005 3984
5006 - /**
5007 - * Settings print callback.
5008 - *
5009 - * @param string $args Args (e.g., multisite admin mode).
5010 - * @return void
5011 - */
5012 - public function print_text_ldap_attr_email( $args = '' ) {
3985 + function print_text_ldap_attr_email( $args = '' ) {
5013 3986 // Get plugin option.
5014 - $option = 'ldap_attr_email';
3987 + $option = 'ldap_attr_email';
5015 3988 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5016 3989
5017 3990 // Print option elements.
5018 - ?>
5019 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5020 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
5021 - <br /><small><?php echo wp_kses( __( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
5022 - <?php
3991 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3992 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: mail', 'authorizer' ); ?></label>
3993 + <br /><small><?php _e( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
5023 3994 }
5024 3995
5025 3996
5026 - /**
5027 - * Settings print callback.
5028 - *
5029 - * @param string $args Args (e.g., multisite admin mode).
5030 - * @return void
5031 - */
5032 - public function print_text_ldap_user( $args = '' ) {
3997 + function print_text_ldap_user( $args = '' ) {
5033 3998 // Get plugin option.
5034 - $option = 'ldap_user';
3999 + $option = 'ldap_user';
5035 4000 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5036 4001
5037 4002 // Print option elements.
5038 - ?>
5039 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
5040 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label>
5041 - <?php
4003 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
4004 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label><?php
5042 4005 }
5043 4006
5044 4007
5045 - /**
5046 - * Settings print callback.
5047 - *
5048 - * @param string $args Args (e.g., multisite admin mode).
5049 - * @return void
5050 - */
5051 - public function print_password_ldap_password( $args = '' ) {
4008 + function print_password_ldap_password( $args = '' ) {
5052 4009 // Get plugin option.
5053 - $option = 'ldap_password';
4010 + $option = 'ldap_password';
5054 4011 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5055 4012
5056 4013 // Print option elements.
5057 - ?>
5058 - <input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
5059 - <input type="password" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $this->decrypt( $auth_settings_option ) ); ?>" autocomplete="new-password" />
5060 - <?php
4014 + ?><input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
4015 + <input type="password" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $this->decrypt( $auth_settings_option ); ?>" autocomplete="off" /><?php
5061 4016 }
5062 4017
5063 4018
5064 - /**
5065 - * Settings print callback.
5066 - *
5067 - * @param string $args Args (e.g., multisite admin mode).
5068 - * @return void
5069 - */
5070 - public function print_text_ldap_lostpassword_url( $args = '' ) {
4019 + function print_text_ldap_lostpassword_url( $args = '' ) {
5071 4020 // Get plugin option.
5072 - $option = 'ldap_lostpassword_url';
4021 + $option = 'ldap_lostpassword_url';
5073 4022 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5074 4023
5075 4024 // Print option elements.
5076 - ?>
5077 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width: 400px;" />
5078 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label>
5079 - <?php
4025 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width: 400px;" />
4026 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label><?php
5080 4027 }
5081 4028
5082 4029
5083 - /**
5084 - * Settings print callback.
5085 - *
5086 - * @param string $args Args (e.g., multisite admin mode).
5087 - * @return void
5088 - */
5089 - public function print_text_ldap_attr_first_name( $args = '' ) {
4030 + function print_text_ldap_attr_first_name( $args = '' ) {
5090 4031 // Get plugin option.
5091 - $option = 'ldap_attr_first_name';
4032 + $option = 'ldap_attr_first_name';
5092 4033 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5093 4034
5094 4035 // Print option elements.
5095 - ?>
5096 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5097 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenname', 'authorizer' ); ?></label>
5098 - <?php
4036 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4037 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: givenname', 'authorizer' ); ?></label><?php
5099 4038 }
5100 4039
5101 4040
5102 - /**
5103 - * Settings print callback.
5104 - *
5105 - * @param string $args Args (e.g., multisite admin mode).
5106 - * @return void
5107 - */
5108 - public function print_text_ldap_attr_last_name( $args = '' ) {
4041 + function print_text_ldap_attr_last_name( $args = '' ) {
5109 4042 // Get plugin option.
5110 - $option = 'ldap_attr_last_name';
4043 + $option = 'ldap_attr_last_name';
5111 4044 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5112 4045
5113 4046 // Print option elements.
5114 - ?>
5115 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5116 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
5117 - <?php
4047 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4048 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sn', 'authorizer' ); ?></label><?php
5118 4049 }
5119 4050
5120 4051
5121 - /**
5122 - * Settings print callback.
5123 - *
5124 - * @param string $args Args (e.g., multisite admin mode).
5125 - * @return void
5126 - */
5127 - public function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
4052 + function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
5128 4053 // Get plugin option.
5129 - $option = 'ldap_attr_update_on_login';
4054 + $option = 'ldap_attr_update_on_login';
5130 4055 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5131 4056
5132 4057 // Print option elements.
5133 - ?>
5134 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
5135 - <?php
4058 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
5136 4059 }
5137 4060
5138 4061
5139 - /**
5140 - * Settings print callback.
5141 - *
5142 - * @param string $args Args (e.g., multisite admin mode).
5143 - * @return void
5144 - */
5145 - public function print_section_info_advanced( $args = '' ) {
5146 - ?>
5147 - <div id="section_info_advanced" class="section_info">
5148 - <p><?php esc_html_e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
5149 - </div>
5150 - <?php
4062 + function print_section_info_advanced( $args = '' ) {
4063 + ?><div id="section_info_advanced" class="section_info">
4064 + <p><?php _e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
4065 + </div><?php
5151 4066 }
5152 4067
5153 4068
5154 - /**
5155 - * Settings print callback.
5156 - *
5157 - * @param string $args Args (e.g., multisite admin mode).
5158 - * @return void
5159 - */
5160 - public function print_text_auth_advanced_lockouts( $args = '' ) {
4069 + function print_text_auth_advanced_lockouts( $args = '' ) {
5161 4070 // Get plugin option.
5162 - $option = 'advanced_lockouts';
4071 + $option = 'advanced_lockouts';
5163 4072 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5164 4073
5165 4074 // Print option elements.
5166 - esc_html_e( 'After', 'authorizer' );
5167 - ?>
5168 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_1]" value="<?php echo esc_attr( $auth_settings_option['attempts_1'] ); ?>" placeholder="10" style="width:30px;" />
5169 - <?php esc_html_e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
5170 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_1]" value="<?php echo esc_attr( $auth_settings_option['duration_1'] ); ?>" placeholder="1" style="width:30px;" />
5171 - <?php esc_html_e( 'minute(s).', 'authorizer' ); ?>
4075 + ?><?php _e( 'After', 'authorizer' ); ?>
4076 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_1" name="auth_settings[<?php echo $option; ?>][attempts_1]" value="<?php echo $auth_settings_option['attempts_1']; ?>" placeholder="10" style="width:30px;" />
4077 + <?php _e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
4078 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_1" name="auth_settings[<?php echo $option; ?>][duration_1]" value="<?php echo $auth_settings_option['duration_1']; ?>" placeholder="1" style="width:30px;" />
4079 + <?php _e( 'minute(s).', 'authorizer' ); ?>
5172 4080 <br />
5173 - <?php esc_html_e( 'After', 'authorizer' ); ?>
5174 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_2]" value="<?php echo esc_attr( $auth_settings_option['attempts_2'] ); ?>" placeholder="10" style="width:30px;" />
5175 - <?php esc_html_e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
5176 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_2]" value="<?php echo esc_attr( $auth_settings_option['duration_2'] ); ?>" placeholder="10" style="width:30px;" />
5177 - <?php esc_html_e( 'minutes.', 'authorizer' ); ?>
4081 + <?php _e( 'After', 'authorizer' ); ?>
4082 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_2" name="auth_settings[<?php echo $option; ?>][attempts_2]" value="<?php echo $auth_settings_option['attempts_2']; ?>" placeholder="10" style="width:30px;" />
4083 + <?php _e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
4084 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_2" name="auth_settings[<?php echo $option; ?>][duration_2]" value="<?php echo $auth_settings_option['duration_2']; ?>" placeholder="10" style="width:30px;" />
4085 + <?php _e( 'minutes.', 'authorizer' ); ?>
5178 4086 <br />
5179 - <?php esc_html_e( 'Reset the delays after', 'authorizer' ); ?>
5180 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_reset_duration" name="auth_settings[<?php echo esc_attr( $option ); ?>][reset_duration]" value="<?php echo esc_attr( $auth_settings_option['reset_duration'] ); ?>" placeholder="240" style="width:40px;" />
5181 - <?php esc_html_e( 'minutes with no invalid attempts.', 'authorizer' ); ?>
5182 - <?php
4087 + <?php _e( 'Reset the delays after', 'authorizer' ); ?>
4088 + <input type="text" id="auth_settings_<?php echo $option; ?>_reset_duration" name="auth_settings[<?php echo $option; ?>][reset_duration]" value="<?php echo $auth_settings_option['reset_duration']; ?>" placeholder="240" style="width:40px;" />
4089 + <?php _e( 'minutes with no invalid attempts.', 'authorizer' ); ?><?php
5183 4090 }
5184 4091
5185 4092
5186 - /**
5187 - * Settings print callback.
5188 - *
5189 - * @param string $args Args (e.g., multisite admin mode).
5190 - * @return void
5191 - */
5192 - public function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
4093 + function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
5193 4094 // Get plugin option.
5194 - $option = 'advanced_hide_wp_login';
4095 + $option = 'advanced_hide_wp_login';
5195 4096 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5196 4097
5197 4098 // Print option elements.
5198 - ?>
5199 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
5200 - <p><small><?php esc_html_e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo esc_attr( wp_login_url() ); ?>?external=wordpress" target="_blank"><?php echo esc_html( wp_login_url() ); ?>?external=wordpress</a>.</p>
5201 - <?php
4099 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
4100 + <p><small><?php _e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo wp_login_url(); ?>?external=wordpress" target="_blank"><?php echo wp_login_url(); ?>?external=wordpress</a>.</p><?php
5202 4101 }
5203 4102
5204 4103
5205 - /**
5206 - * Settings print callback.
5207 - *
5208 - * @param string $args Args (e.g., multisite admin mode).
5209 - * @return void
5210 - */
5211 - public function print_radio_auth_advanced_branding( $args = '' ) {
4104 + function print_radio_auth_advanced_branding( $args = '' ) {
5212 4105 // Get plugin option.
5213 - $option = 'advanced_branding';
4106 + $option = 'advanced_branding';
5214 4107 $auth_settings_option = $this->get_plugin_option( $option );
5215 4108
5216 4109 // Print option elements.
5217 - ?>
5218 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="default"<?php checked( 'default' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default"><?php esc_html_e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
4110 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_default" name="auth_settings[<?php echo $option; ?>]" value="default"<?php checked( 'default' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_default"><?php _e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
5219 4111 <?php
5220 4112
5221 4113 /**
5222 4114 * Developers can use the `authorizer_add_branding_option` filter
@@ -5221,8 +4113,9 @@
5221 4113 /**
5222 4114 * Developers can use the `authorizer_add_branding_option` filter
5223 4115 * to add a radio button for "Custom WordPress login branding"
5224 4116 * under the "Advanced" tab in Authorizer options. Example:
4117 + *
5225 4118 * function my_authorizer_add_branding_option( $branding_options ) {
5226 4119 * $new_branding_option = array(
5227 4120 * 'value' => 'your_brand'
5228 4121 * 'description' => 'Custom Your Brand Login Screen',
@@ -5236,274 +4129,133 @@
5236 4129 */
5237 4130 $branding_options = array();
5238 4131 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
5239 4132 foreach ( $branding_options as $branding_option ) {
5240 - // Make sure the custom brands have the required values.
4133 + // Make sure the custom brands have the required values
5241 4134 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'description', $branding_option ) ) ) {
5242 4135 continue;
5243 4136 }
5244 - ?>
5245 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $branding_option['value'] ); ?>"<?php checked( $branding_option['value'] === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>"><?php echo esc_html( $branding_option['description'] ); ?></label><br />
5246 - <?php
4137 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $branding_option['value']; ?>"<?php checked( $branding_option['value'] == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>"><?php echo $branding_option['description']; ?></label><br /><?php
5247 4138 }
5248 4139
5249 4140 // Print message about adding custom brands if there are none.
5250 4141 if ( count( $branding_options ) === 0 ) {
5251 - ?>
5252 - <p><em><?php echo wp_kses( __( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ), $this->allowed_html ); ?></em></p>
5253 - <?php
4142 + ?><p><em><?php _e( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ); ?></em></p><?php
5254 4143 }
5255 4144 }
5256 4145
5257 4146
5258 - /**
5259 - * Settings print callback.
5260 - *
5261 - * @param string $args Args (e.g., multisite admin mode).
5262 - * @return void
5263 - */
5264 - public function print_radio_auth_advanced_admin_menu( $args = '' ) {
4147 + function print_radio_auth_advanced_admin_menu( $args = '' ) {
5265 4148 // Get plugin option.
5266 - $option = 'advanced_admin_menu';
4149 + $option = 'advanced_admin_menu';
5267 4150 $auth_settings_option = $this->get_plugin_option( $option );
5268 4151
5269 4152 // Print option elements.
5270 - ?>
5271 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="settings"<?php checked( 'settings' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings"><?php esc_html_e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
5272 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="top"<?php checked( 'top' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top"><?php esc_html_e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br />
5273 - <?php
4153 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_settings" name="auth_settings[<?php echo $option; ?>]" value="settings"<?php checked( 'settings' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_settings"><?php _e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
4154 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_top" name="auth_settings[<?php echo $option; ?>]" value="top"<?php checked( 'top' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_top"><?php _e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br /><?php
5274 4155
5275 4156 }
5276 4157
5277 4158
5278 - /**
5279 - * Settings print callback.
5280 - *
5281 - * @param string $args Args (e.g., multisite admin mode).
5282 - * @return void
5283 - */
5284 - public function print_select_auth_advanced_usermeta( $args = '' ) {
4159 + function print_select_auth_advanced_usermeta( $args = '' ) {
5285 4160 // Get plugin option.
5286 - $option = 'advanced_usermeta';
4161 + $option = 'advanced_usermeta';
5287 4162 $auth_settings_option = $this->get_plugin_option( $option );
5288 4163
5289 4164 // Print option elements.
5290 - ?>
5291 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5292 - <option value=""><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
5293 - <?php
5294 - if ( class_exists( 'acf' ) ) :
4165 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4166 + <option value=""><?php _e( '-- None --', 'authorizer' ); ?></option>
4167 + <?php if ( class_exists( 'acf' ) ) :
5295 4168 // Get ACF 5 fields. Note: it would be much easier to use `get_field_objects()`
5296 4169 // or `get_field_objects( 'user_' . get_current_user_id() )`, but neither will
5297 4170 // list fields that have never been given values for users (i.e., new ACF
5298 4171 // fields). Therefore we fall back on finding any ACF fields applied to users
5299 4172 // (user_role or user_form location rules in the field group definition).
5300 - $fields = array();
4173 + $fields = array();
5301 4174 $acf_field_group_ids = array();
5302 - $acf_field_groups = new WP_Query(
5303 - array(
5304 - 'post_type' => 'acf-field-group',
5305 - )
5306 - );
4175 + $acf_field_groups = new WP_Query( array(
4176 + 'post_type' => 'acf-field-group',
4177 + ));
5307 4178 while ( $acf_field_groups->have_posts() ) : $acf_field_groups->the_post();
5308 4179 if ( strpos( get_the_content(), 's:5:"param";s:9:"user_role"' ) !== false || strpos( get_the_content(), 's:5:"param";s:9:"user_form"' ) !== false ) :
5309 4180 array_push( $acf_field_group_ids, get_the_ID() );
5310 4181 endif;
5311 - endwhile;
5312 - wp_reset_postdata();
4182 + endwhile; wp_reset_postdata();
5313 4183 foreach ( $acf_field_group_ids as $acf_field_group_id ) :
5314 - $acf_fields = new WP_Query(
5315 - array(
5316 - 'post_type' => 'acf-field',
5317 - 'post_parent' => $acf_field_group_id,
5318 - )
5319 - );
4184 + $acf_fields = new WP_Query( array(
4185 + 'post_type' => 'acf-field',
4186 + 'post_parent' => $acf_field_group_id,
4187 + ));
5320 4188 while ( $acf_fields->have_posts() ) : $acf_fields->the_post();
5321 4189 global $post;
5322 - $fields[ $post->post_name ] = get_field_object( $post->post_name );
5323 - endwhile;
5324 - wp_reset_postdata();
4190 + $fields[$post->post_name] = get_field_object( $post->post_name );
4191 + endwhile; wp_reset_postdata();
5325 4192 endforeach;
5326 4193 // Get ACF 4 fields.
5327 - $acf4_field_groups = new WP_Query(
5328 - array(
5329 - 'post_type' => 'acf',
5330 - )
5331 - );
4194 + $acf4_field_groups = new WP_Query( array(
4195 + 'post_type' => 'acf',
4196 + ));
5332 4197 while ( $acf4_field_groups->have_posts() ) : $acf4_field_groups->the_post();
5333 4198 $field_group_rules = get_post_meta( get_the_ID(), 'rule', true );
5334 - if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && 'ef_user' === $field_group_rules['param'] ) :
4199 + if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && $field_group_rules['param'] === 'ef_user' ) :
5335 4200 $acf4_fields = get_post_custom( get_the_ID() );
5336 4201 foreach ( $acf4_fields as $meta_key => $meta_value ) :
5337 4202 if ( strpos( $meta_key, 'field_' ) === 0 ) :
5338 - $meta_value = unserialize( $meta_value[0] );
5339 - $fields[ $meta_key ] = $meta_value;
4203 + $meta_value = unserialize( $meta_value[0] );
4204 + $fields[$meta_key] = $meta_value;
5340 4205 endif;
5341 4206 endforeach;
5342 4207 endif;
5343 - endwhile;
5344 - wp_reset_postdata();
5345 - ?>
4208 + endwhile; wp_reset_postdata(); ?>
5346 4209 <optgroup label="ACF User Fields:">
5347 - <?php foreach ( (array) $fields as $field => $field_object ) : ?>
5348 - <option value="acf___<?php echo esc_attr( $field_object['key'] ); ?>"<?php selected( "acf___{$field_object['key']}" === $auth_settings_option ); ?>><?php echo esc_html( $field_object['label'] ); ?></option>
4210 + <?php foreach ( (array)$fields as $field => $field_object ) : ?>
4211 + <option value="acf___<?php echo $field_object['key']; ?>"<?php if ( $auth_settings_option === "acf___{$field_object['key']}" ) echo ' selected="selected"'; ?>><?php echo $field_object['label']; ?></option>
5349 4212 <?php endforeach; ?>
5350 4213 </optgroup>
5351 4214 <?php endif; ?>
5352 - <optgroup label="<?php esc_attr_e( 'All Usermeta:', 'authorizer' ); ?>">
5353 - <?php
5354 - foreach ( $this->get_all_usermeta_keys() as $meta_key ) :
5355 - if ( substr( $meta_key, 0, 3 ) === 'wp_' ) :
5356 - continue;
5357 - endif;
5358 - ?>
5359 - <option value="<?php echo esc_attr( $meta_key ); ?>"<?php selected( $auth_settings_option === $meta_key ); ?>><?php echo esc_html( $meta_key ); ?></option>
4215 + <optgroup label="<?php _e( 'All Usermeta:', 'authorizer' ); ?>">
4216 + <?php foreach ( $this->get_all_usermeta_keys() as $meta_key ) : if ( substr( $meta_key, 0, 3 ) === 'wp_' ) continue; ?>
4217 + <option value="<?php echo $meta_key; ?>"<?php if ( $auth_settings_option === $meta_key ) echo ' selected="selected"'; ?>><?php echo $meta_key; ?></option>
5360 4218 <?php endforeach; ?>
5361 4219 </optgroup>
5362 - </select>
5363 - <?php
4220 + </select><?php
5364 4221 }
5365 4222
5366 4223
5367 - /**
5368 - * Settings print callback.
5369 - *
5370 - * @param string $args Args (e.g., multisite admin mode).
5371 - * @return void
5372 - */
5373 - public function print_text_auth_advanced_users_per_page( $args = '' ) {
4224 + function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5374 4225 // Get plugin option.
5375 - $option = 'advanced_users_per_page';
5376 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5377 -
5378 - // Print option elements.
5379 - ?>
5380 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" size="4" />
5381 - <?php
5382 - }
5383 -
5384 -
5385 - /**
5386 - * Settings print callback.
5387 - *
5388 - * @param string $args Args (e.g., multisite admin mode).
5389 - * @return void
5390 - */
5391 - public function print_select_auth_advanced_users_sort_by( $args = '' ) {
5392 - // Get plugin option.
5393 - $option = 'advanced_users_sort_by';
5394 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5395 -
5396 - // Print option elements.
5397 - ?>
5398 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5399 - <option value="created" <?php selected( $auth_settings_option, 'created' ); ?>><?php esc_html_e( 'Date approved', 'authorizer' ); ?></option>
5400 - <option value="email" <?php selected( $auth_settings_option, 'email' ); ?>><?php esc_html_e( 'Email', 'authorizer' ); ?></option>
5401 - <option value="role" <?php selected( $auth_settings_option, 'role' ); ?>><?php esc_html_e( 'Role', 'authorizer' ); ?></option>
5402 - <option value="date_added" <?php selected( $auth_settings_option, 'date_added' ); ?>><?php esc_html_e( 'Date registered', 'authorizer' ); ?></option>
5403 - </select>
5404 - <?php
5405 - }
5406 -
5407 -
5408 - /**
5409 - * Settings print callback.
5410 - *
5411 - * @param string $args Args (e.g., multisite admin mode).
5412 - * @return void
5413 - */
5414 - public function print_select_auth_advanced_users_sort_order( $args = '' ) {
5415 - // Get plugin option.
5416 - $option = 'advanced_users_sort_order';
5417 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5418 -
5419 - // Print option elements.
5420 - ?>
5421 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5422 - <option value="asc" <?php selected( $auth_settings_option, 'asc' ); ?>><?php esc_html_e( 'Ascending', 'authorizer' ); ?></option>
5423 - <option value="desc" <?php selected( $auth_settings_option, 'desc' ); ?>><?php esc_html_e( 'Descending', 'authorizer' ); ?></option>
5424 - </select>
5425 - <?php
5426 - }
5427 -
5428 -
5429 - /**
5430 - * Settings print callback.
5431 - *
5432 - * @param string $args Args (e.g., multisite admin mode).
5433 - * @return void
5434 - */
5435 - public function print_checkbox_auth_advanced_widget_enabled( $args = '' ) {
5436 - // Get plugin option.
5437 - $option = 'advanced_widget_enabled';
5438 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5439 -
5440 - // Print option elements.
5441 - ?>
5442 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></label>
5443 - <p><small><?php esc_html_e( 'Note: Only users with the create_users capability will be able to see the dashboard widget.', 'authorizer' ); ?></small></p>
5444 - <?php
5445 - }
5446 -
5447 -
5448 - /**
5449 - * Settings print callback.
5450 - *
5451 - * @param string $args Args (e.g., multisite admin mode).
5452 - * @return void
5453 - */
5454 - public function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5455 - // Get plugin option.
5456 - $option = 'advanced_override_multisite';
4226 + $option = 'advanced_override_multisite';
5457 4227 $auth_settings_option = $this->get_plugin_option( $option );
5458 4228
5459 4229 // Print option elements.
5460 - ?>
5461 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label>
5462 - <?php
4230 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label><?php
5463 4231 }
5464 4232
5465 4233
5466 4234
5467 4235 /**
5468 - * Determines whether we are in single site or multisite admin context.
5469 - *
5470 - * @param string $args Args (e.g., multisite admin mode).
5471 - * @return int Current mode.
5472 - */
5473 - private function get_admin_mode( $args ) {
5474 - if ( is_array( $args ) && array_key_exists( WP_Plugin_Authorizer::NETWORK_CONTEXT, $args ) && true === $args[ WP_Plugin_Authorizer::NETWORK_CONTEXT ] ) {
5475 - return WP_Plugin_Authorizer::NETWORK_CONTEXT;
5476 - } else {
5477 - return WP_Plugin_Authorizer::SINGLE_CONTEXT;
5478 - }
5479 - }
5480 -
5481 -
5482 - /**
5483 4236 * Add help documentation to the options page.
5484 - *
5485 - * Action: load-settings_page_authorizer > admin_head
4237 + * Run on action hook chain: load-settings_page_authorizer > admin_head
5486 4238 */
5487 4239 public function admin_head() {
5488 4240 $screen = get_current_screen();
5489 4241
5490 - // Add help tab for Access Lists Settings.
4242 + // Add help tab for Access Lists Settings
5491 4243 $help_auth_settings_access_lists_content = '
5492 - <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) . '</p>
5493 - <p>' . __( '<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.', 'authorizer' ) . '</p>
5494 - <p>' . __( '<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ) . '</p>
5495 - <p>' . __( 'Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.', 'authorizer' ) . '</p>
4244 + <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) .'</p>
4245 + <p>' . __( "<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.", 'authorizer' ) . '</p>
4246 + <p>' . __( "<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.", 'authorizer' ) . '</p>
4247 + <p>' . __( "Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.", 'authorizer' ) . '</p>
5496 4248 ';
5497 4249 $screen->add_help_tab(
5498 4250 array(
5499 - 'id' => 'help_auth_settings_access_lists_content',
5500 - 'title' => __( 'Access Lists', 'authorizer' ),
4251 + 'id' => 'help_auth_settings_access_lists_content',
4252 + 'title' => __( 'Access Lists', 'authorizer' ),
5501 4253 'content' => $help_auth_settings_access_lists_content,
5502 4254 )
5503 4255 );
5504 4256
5505 - // Add help tab for Login Access Settings.
4257 + // Add help tab for Login Access Settings
5506 4258 $help_auth_settings_access_login_content = '
5507 4259 <p>' . __( "<strong>Who can log in to the site?</strong>: Choose the level of access restriction you'd like to use on your site here. You can leave the site open to anyone with a WordPress account or an account on an external service like Google, CAS, or LDAP, or restrict it to WordPress users and only the external users that you specify via the <em>Access Lists</em>.", 'authorizer' ) . '</p>
5508 4260 <p>' . __( "<strong>Which role should receive email notifications about pending users?</strong>: If you've restricted access to <strong>approved users</strong>, you can determine which WordPress users will receive a notification email everytime a new external user successfully logs in and is added to the pending list. All users of the specified role will receive an email, and the external user will get a message (specified below) telling them their access is pending approval.", 'authorizer' ) . '</p>
5509 4261 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
@@ -5509,84 +4261,84 @@
5509 4261 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
5510 4262 ';
5511 4263 $screen->add_help_tab(
5512 4264 array(
5513 - 'id' => 'help_auth_settings_access_login_content',
5514 - 'title' => __( 'Login Access', 'authorizer' ),
4265 + 'id' => 'help_auth_settings_access_login_content',
4266 + 'title' => __( 'Login Access', 'authorizer' ),
5515 4267 'content' => $help_auth_settings_access_login_content,
5516 4268 )
5517 4269 );
5518 4270
5519 - // Add help tab for Public Access Settings.
4271 + // Add help tab for Public Access Settings
5520 4272 $help_auth_settings_access_public_content = '
5521 4273 <p>' . __( "<strong>Who can view the site?</strong>: You can restrict the site's visibility by only allowing logged in users to see pages. If you do so, you can customize the specifics about the site's privacy using the settings below.", 'authorizer' ) . '</p>
5522 4274 <p>' . __( "<strong>What pages (if any) should be available to everyone?</strong>: If you'd like to declare certain pages on your site as always public (such as the course syllabus, introduction, or calendar), specify those pages here. These pages will always be available no matter what access restrictions exist.", 'authorizer' ) . '</p>
5523 - <p>' . __( '<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.', 'authorizer' ) . '</p>
5524 - <p>' . __( '<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.', 'authorizer' ) . '</p>
5525 - <p>' . __( '<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.', 'authorizer' ) . '</p>
4275 + <p>' . __( "<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.", 'authorizer' ) . '</p>
4276 + <p>' . __( "<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.", 'authorizer' ) . '</p>
4277 + <p>' . __( "<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.", 'authorizer' ) . '</p>
5526 4278 ';
5527 4279 $screen->add_help_tab(
5528 4280 array(
5529 - 'id' => 'help_auth_settings_access_public_content',
5530 - 'title' => __( 'Public Access', 'authorizer' ),
4281 + 'id' => 'help_auth_settings_access_public_content',
4282 + 'title' => __( 'Public Access', 'authorizer' ),
5531 4283 'content' => $help_auth_settings_access_public_content,
5532 4284 )
5533 4285 );
5534 4286
5535 - // Add help tab for External Service (CAS, LDAP) Settings.
4287 + // Add help tab for External Service (CAS, LDAP) Settings
5536 4288 $help_auth_settings_external_content = '
5537 4289 <p>' . __( "<strong>Type of external service to authenticate against</strong>: Choose which authentication service type you will be using. You'll have to fill out different fields below depending on which service you choose.", 'authorizer' ) . '</p>
5538 - <p>' . __( '<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.', 'authorizer' ) . '</p>
5539 - <p>' . __( '<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.', 'authorizer' ) . '</p>
5540 - <p>' . __( '<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.', 'authorizer' ) . '</p>
5541 - <p>' . __( '<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!', 'authorizer' ) . '</p>
5542 - <p><strong><em>' . __( 'If you enable Google logins:', 'authorizer' ) . '</em></strong></p>
4290 + <p>' . __( "<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.", 'authorizer' ) . '</p>
4291 + <p>' . __( "<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.", 'authorizer' ) . '</p>
4292 + <p>' . __( "<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.", 'authorizer' ) . '</p>
4293 + <p>' . __( "<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!", 'authorizer' ) . '</p>
4294 + <p><strong><em>' . __( "If you enable Google logins:", 'authorizer' ) . '</em></strong></p>
5543 4295 <ul>
5544 4296 <li>' . __( "<strong>Google Client ID</strong>: You can generate this ID by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client ID typically looks something like this: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com", 'authorizer' ) . '</li>
5545 4297 <li>' . __( "<strong>Google Client Secret</strong>: You can generate this secret by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client Secret typically looks something like this: sDNgX5_pr_5bly-frKmvp8jT", 'authorizer' ) . '</li>
5546 4298 </ul>
5547 - <p><strong><em>' . __( 'If you enable CAS logins:', 'authorizer' ) . '</em></strong></p>
4299 + <p><strong><em>' . __( "If you enable CAS logins:", 'authorizer' ) . '</em></strong></p>
5548 4300 <ul>
5549 - <li>' . __( '<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).', 'authorizer' ) . '</li>
5550 - <li>' . __( '<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).', 'authorizer' ) . '</li>
5551 - <li>' . __( '<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).', 'authorizer' ) . '</li>
4301 + <li>' . __( "<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).", 'authorizer' ) . '</li>
4302 + <li>' . __( "<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).", 'authorizer' ) . '</li>
4303 + <li>' . __( "<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).", 'authorizer' ) . '</li>
5552 4304 <li>' . __( "<strong>CAS attribute containing first name</strong>: Enter the CAS attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5553 4305 <li>' . __( "<strong>CAS attribute containing last name</strong>: Enter the CAS attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5554 - <li>' . __( '<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4306 + <li>' . __( "<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5555 4307 </ul>
5556 - <p><strong><em>' . __( 'If you enable LDAP logins:', 'authorizer' ) . '</em></strong></p>
4308 + <p><strong><em>' . __( "If you enable LDAP logins:", 'authorizer' ) . '</em></strong></p>
5557 4309 <ul>
5558 - <li>' . __( '<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.', 'authorizer' ) . '</li>
5559 - <li>' . __( '<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.', 'authorizer' ) . '</li>
5560 - <li>' . __( '<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu', 'authorizer' ) . '</li>
5561 - <li>' . __( '<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.', 'authorizer' ) . '</li>
5562 - <li>' . __( '<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.', 'authorizer' ) . '</li>
5563 - <li>' . __( '<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.', 'authorizer' ) . '</li>
5564 - <li>' . __( '<strong>Use TLS</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.', 'authorizer' ) . '</li>
4310 + <li>' . __( "<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.", 'authorizer' ) . '</li>
4311 + <li>' . __( "<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.", 'authorizer' ) . '</li>
4312 + <li>' . __( "<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu", 'authorizer' ) . '</li>
4313 + <li>' . __( "<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.", 'authorizer' ) . '</li>
4314 + <li>' . __( "<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.", 'authorizer' ) . '</li>
4315 + <li>' . __( "<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.", 'authorizer' ) . '</li>
4316 + <li>' . __( "<strong>Secure Connection (TLS)</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.", 'authorizer' ) . '</li>
5565 4317 <li>' . __( "<strong>Custom lost password URL</strong>: The WordPress login page contains a link to recover a lost password. If you have external users who shouldn't change the password on their WordPress account, point them to the appropriate location to change the password on their external authentication service here.", 'authorizer' ) . '</li>
5566 4318 <li>' . __( "<strong>LDAP attribute containing first name</strong>: Enter the LDAP attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5567 4319 <li>' . __( "<strong>LDAP attribute containing last name</strong>: Enter the LDAP attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5568 - <li>' . __( '<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4320 + <li>' . __( "<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5569 4321 </ul>
5570 4322 ';
5571 4323 $screen->add_help_tab(
5572 4324 array(
5573 - 'id' => 'help_auth_settings_external_content',
5574 - 'title' => __( 'External Service', 'authorizer' ),
4325 + 'id' => 'help_auth_settings_external_content',
4326 + 'title' => __( 'External Service', 'authorizer' ),
5575 4327 'content' => $help_auth_settings_external_content,
5576 4328 )
5577 4329 );
5578 4330
5579 - // Add help tab for Advanced Settings.
4331 + // Add help tab for Advanced Settings
5580 4332 $help_auth_settings_advanced_content = '
5581 - <p>' . __( '<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.', 'authorizer' ) . '</p>
5582 - <p>' . __( '<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
4333 + <p>' . __( "<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.", 'authorizer' ) . '</p>
4334 + <p>' . __( "<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:", 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
5583 4335 <p>' . __( "<strong>Custom WordPress login branding</strong>: If you'd like to use custom branding on the WordPress login page, select that here. You will need to use the `authorizer_add_branding_option` filter in your theme to add it. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.", 'authorizer' ) . '</p>
5584 4336 ';
5585 4337 $screen->add_help_tab(
5586 4338 array(
5587 - 'id' => 'help_auth_settings_advanced_content',
5588 - 'title' => __( 'Advanced', 'authorizer' ),
4339 + 'id' => 'help_auth_settings_advanced_content',
4340 + 'title' => __( 'Advanced', 'authorizer' ),
5589 4341 'content' => $help_auth_settings_advanced_content,
5590 4342 )
5591 4343 );
5592 4344 }
@@ -5601,66 +4353,65 @@
5601 4353
5602 4354
5603 4355 /**
5604 4356 * Network Admin menu item
4357 + * Hook: network_admin_menu
5605 4358 *
5606 - * Action: network_admin_menu
5607 - *
4359 + * @param none
5608 4360 * @return void
5609 4361 */
5610 4362 public function network_admin_menu() {
5611 4363 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
5612 4364 add_menu_page(
5613 - 'Authorizer',
5614 - 'Authorizer',
5615 - 'manage_network_options',
5616 - 'authorizer',
4365 + 'Authorizer', // Page title
4366 + 'Authorizer', // Menu title
4367 + 'manage_network_options', // Capability
4368 + 'authorizer', // Menu slug
5617 4369 array( $this, 'create_network_admin_page' ),
5618 - 'dashicons-groups',
5619 - 89 // Position.
4370 + 'dashicons-groups', // Icon URL
4371 + 89 // Position
5620 4372 );
5621 4373 }
5622 4374
5623 4375
5624 4376 /**
5625 - * Output the HTML for the options page.
4377 + * Output the HTML for the options page
5626 4378 */
5627 4379 public function create_network_admin_page() {
5628 4380 if ( ! current_user_can( 'manage_network_options' ) ) {
5629 - wp_die( wp_kses( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ), $this->allowed_html ) );
4381 + wp_die( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ) );
5630 4382 }
5631 - $auth_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5632 - ?>
4383 + $auth_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); ?>
5633 4384 <div class="wrap">
5634 4385 <form method="post" action="" autocomplete="off">
5635 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
5636 - <p><?php echo wp_kses( __( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ), $this->allowed_html ); ?></p>
4386 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
4387 + <p><?php _e( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ); ?></p>
5637 4388
5638 - <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 === intval( $auth_settings['multisite_override'] ) ); ?> /><label for="auth_settings_multisite_override"><?php esc_html_e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
4389 + <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 == $auth_settings['multisite_override'] ); ?> /><label for="auth_settings_multisite_override"><?php _e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
5639 4390
5640 4391 <div id="auth_multisite_settings_disabled_overlay" style="display: none;"></div>
5641 4392
5642 4393 <div class="wrap" id="auth_multisite_settings">
5643 - <?php $this->print_section_info_tabs( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?>
4394 + <?php $this->print_section_info_tabs( array( MULTISITE_ADMIN => true ) ); ?>
5644 4395
5645 4396 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
5646 4397
5647 - <?php // Custom access lists (for network, we only really want approved list, not pending or blocked). ?>
4398 + <?php // Custom access lists (for network, we only really want approved list, not pending or blocked) ?>
5648 4399 <div id="section_info_access_lists" class="section_info">
5649 - <p><?php esc_html_e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
4400 + <p><?php _e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
5650 4401 </div>
5651 4402 <table class="form-table"><tbody>
5652 4403 <tr>
5653 - <th scope="row"><?php esc_html_e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
5654 - <td><?php $this->print_radio_auth_access_who_can_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4404 + <th scope="row"><?php _e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
4405 + <td><?php $this->print_radio_auth_access_who_can_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5655 4406 </tr>
5656 4407 <tr>
5657 - <th scope="row"><?php esc_html_e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
5658 - <td><?php $this->print_radio_auth_access_who_can_view( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4408 + <th scope="row"><?php _e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
4409 + <td><?php $this->print_radio_auth_access_who_can_view( array( MULTISITE_ADMIN => true ) ); ?></td>
5659 4410 </tr>
5660 4411 <tr>
5661 - <th scope="row"><?php esc_html_e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php echo wp_kses( __( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ), $this->allowed_html ); ?></em></small></th>
5662 - <td><?php $this->print_combo_auth_access_users_approved( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4412 + <th scope="row"><?php _e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php _e( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ); ?></em></small></th>
4413 + <td><?php $this->print_combo_auth_access_users_approved( array( MULTISITE_ADMIN => true ) ); ?></td>
5663 4414 </tr>
5664 4415 </tbody></table>
5665 4416
5666 4417 <?php $this->print_section_info_external(); ?>
@@ -5665,160 +4416,140 @@
5665 4416
5666 4417 <?php $this->print_section_info_external(); ?>
5667 4418 <table class="form-table"><tbody>
5668 4419 <tr>
5669 - <th scope="row"><?php esc_html_e( 'Default role for new users', 'authorizer' ); ?></th>
5670 - <td><?php $this->print_select_auth_access_default_role( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4420 + <th scope="row"><?php _e( 'Default role for new users', 'authorizer' ); ?></th>
4421 + <td><?php $this->print_select_auth_access_default_role( array( MULTISITE_ADMIN => true ) ); ?></td>
5671 4422 </tr>
5672 4423 <tr>
5673 - <th scope="row"><?php esc_html_e( 'Google Logins', 'authorizer' ); ?></th>
5674 - <td><?php $this->print_checkbox_auth_external_google( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4424 + <th scope="row"><?php _e( 'Google Logins', 'authorizer' ); ?></th>
4425 + <td><?php $this->print_checkbox_auth_external_google( array( MULTISITE_ADMIN => true ) ); ?></td>
5675 4426 </tr>
5676 4427 <tr>
5677 - <th scope="row"><?php esc_html_e( 'Google Client ID', 'authorizer' ); ?></th>
5678 - <td><?php $this->print_text_google_clientid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4428 + <th scope="row"><?php _e( 'Google Client ID', 'authorizer' ); ?></th>
4429 + <td><?php $this->print_text_google_clientid( array( MULTISITE_ADMIN => true ) ); ?></td>
5679 4430 </tr>
5680 4431 <tr>
5681 - <th scope="row"><?php esc_html_e( 'Google Client Secret', 'authorizer' ); ?></th>
5682 - <td><?php $this->print_text_google_clientsecret( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4432 + <th scope="row"><?php _e( 'Google Client Secret', 'authorizer' ); ?></th>
4433 + <td><?php $this->print_text_google_clientsecret( array( MULTISITE_ADMIN => true ) ); ?></td>
5683 4434 </tr>
5684 4435 <tr>
5685 - <th scope="row"><?php esc_html_e( 'Google Hosted Domain', 'authorizer' ); ?></th>
5686 - <td><?php $this->print_text_google_hosteddomain( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4436 + <th scope="row"><?php _e( 'Google Hosted Domain', 'authorizer' ); ?></th>
4437 + <td><?php $this->print_text_google_hosteddomain( array( MULTISITE_ADMIN => true ) ); ?></td>
5687 4438 </tr>
5688 4439 <tr>
5689 - <th scope="row"><?php esc_html_e( 'CAS Logins', 'authorizer' ); ?></th>
5690 - <td><?php $this->print_checkbox_auth_external_cas( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4440 + <th scope="row"><?php _e( 'CAS Logins', 'authorizer' ); ?></th>
4441 + <td><?php $this->print_checkbox_auth_external_cas( array( MULTISITE_ADMIN => true ) ); ?></td>
5691 4442 </tr>
5692 4443 <tr>
5693 - <th scope="row"><?php esc_html_e( 'CAS Custom Label', 'authorizer' ); ?></th>
5694 - <td><?php $this->print_text_cas_custom_label( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4444 + <th scope="row"><?php _e( 'CAS Custom Label', 'authorizer' ); ?></th>
4445 + <td><?php $this->print_text_cas_custom_label( array( MULTISITE_ADMIN => true ) ); ?></td>
5695 4446 </tr>
5696 4447 <tr>
5697 - <th scope="row"><?php esc_html_e( 'CAS server hostname', 'authorizer' ); ?></th>
5698 - <td><?php $this->print_text_cas_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4448 + <th scope="row"><?php _e( 'CAS server hostname', 'authorizer' ); ?></th>
4449 + <td><?php $this->print_text_cas_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5699 4450 </tr>
5700 4451 <tr>
5701 - <th scope="row"><?php esc_html_e( 'CAS server port', 'authorizer' ); ?></th>
5702 - <td><?php $this->print_text_cas_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4452 + <th scope="row"><?php _e( 'CAS server port', 'authorizer' ); ?></th>
4453 + <td><?php $this->print_text_cas_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5703 4454 </tr>
5704 4455 <tr>
5705 - <th scope="row"><?php esc_html_e( 'CAS server path/context', 'authorizer' ); ?></th>
5706 - <td><?php $this->print_text_cas_path( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4456 + <th scope="row"><?php _e( 'CAS server path/context', 'authorizer' ); ?></th>
4457 + <td><?php $this->print_text_cas_path( array( MULTISITE_ADMIN => true ) ); ?></td>
5707 4458 </tr>
5708 4459 <tr>
5709 - <th scope="row"><?php esc_html_e( 'CAS server version', 'authorizer' ); ?></th>
5710 - <td><?php $this->print_select_cas_version( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4460 + <th scope="row"><?php _e( 'CAS server version', 'authorizer' ); ?></th>
4461 + <td><?php $this->print_select_cas_version( array( MULTISITE_ADMIN => true ) ); ?></td>
5711 4462 </tr>
5712 4463 <tr>
5713 - <th scope="row"><?php esc_html_e( 'CAS attribute containing email', 'authorizer' ); ?></th>
5714 - <td><?php $this->print_text_cas_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4464 + <th scope="row"><?php _e( 'CAS attribute containing email', 'authorizer' ); ?></th>
4465 + <td><?php $this->print_text_cas_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5715 4466 </tr>
5716 4467 <tr>
5717 - <th scope="row"><?php esc_html_e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
5718 - <td><?php $this->print_text_cas_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4468 + <th scope="row"><?php _e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
4469 + <td><?php $this->print_text_cas_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5719 4470 </tr>
5720 4471 <tr>
5721 - <th scope="row"><?php esc_html_e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
5722 - <td><?php $this->print_text_cas_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4472 + <th scope="row"><?php _e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
4473 + <td><?php $this->print_text_cas_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5723 4474 </tr>
5724 4475 <tr>
5725 - <th scope="row"><?php esc_html_e( 'CAS attribute update', 'authorizer' ); ?></th>
5726 - <td><?php $this->print_checkbox_cas_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4476 + <th scope="row"><?php _e( 'CAS attribute update', 'authorizer' ); ?></th>
4477 + <td><?php $this->print_checkbox_cas_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5727 4478 </tr>
5728 4479 <tr>
5729 - <th scope="row"><?php esc_html_e( 'CAS automatic login', 'authorizer' ); ?></th>
5730 - <td><?php $this->print_checkbox_cas_auto_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4480 + <th scope="row"><?php _e( 'CAS automatic login', 'authorizer' ); ?></th>
4481 + <td><?php $this->print_checkbox_cas_auto_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5731 4482 </tr>
5732 4483 <tr>
5733 - <th scope="row"><?php esc_html_e( 'CAS users linked by username', 'authorizer' ); ?></th>
5734 - <td><?php $this->print_checkbox_cas_link_on_username( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4484 + <th scope="row"><?php _e( 'LDAP Logins', 'authorizer' ); ?></th>
4485 + <td><?php $this->print_checkbox_auth_external_ldap( array( MULTISITE_ADMIN => true ) ); ?></td>
5735 4486 </tr>
5736 4487 <tr>
5737 - <th scope="row"><?php esc_html_e( 'LDAP Logins', 'authorizer' ); ?></th>
5738 - <td><?php $this->print_checkbox_auth_external_ldap( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4488 + <th scope="row"><?php _e( 'LDAP Host', 'authorizer' ); ?></th>
4489 + <td><?php $this->print_text_ldap_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5739 4490 </tr>
5740 4491 <tr>
5741 - <th scope="row"><?php esc_html_e( 'LDAP Host', 'authorizer' ); ?></th>
5742 - <td><?php $this->print_text_ldap_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4492 + <th scope="row"><?php _e( 'LDAP Port', 'authorizer' ); ?></th>
4493 + <td><?php $this->print_text_ldap_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5743 4494 </tr>
5744 4495 <tr>
5745 - <th scope="row"><?php esc_html_e( 'LDAP Port', 'authorizer' ); ?></th>
5746 - <td><?php $this->print_text_ldap_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4496 + <th scope="row"><?php _e( 'Secure Connection (TLS)', 'authorizer' ); ?></th>
4497 + <td><?php $this->print_checkbox_ldap_tls( array( MULTISITE_ADMIN => true ) ); ?></td>
5747 4498 </tr>
5748 4499 <tr>
5749 - <th scope="row"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></th>
5750 - <td><?php $this->print_checkbox_ldap_tls( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4500 + <th scope="row"><?php _e( 'LDAP Search Base', 'authorizer' ); ?></th>
4501 + <td><?php $this->print_text_ldap_search_base( array( MULTISITE_ADMIN => true ) ); ?></td>
5751 4502 </tr>
5752 4503 <tr>
5753 - <th scope="row"><?php esc_html_e( 'LDAP Search Base', 'authorizer' ); ?></th>
5754 - <td><?php $this->print_text_ldap_search_base( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4504 + <th scope="row"><?php _e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
4505 + <td><?php $this->print_text_ldap_uid( array( MULTISITE_ADMIN => true ) ); ?></td>
5755 4506 </tr>
5756 4507 <tr>
5757 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
5758 - <td><?php $this->print_text_ldap_uid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4508 + <th scope="row"><?php _e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
4509 + <td><?php $this->print_text_ldap_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5759 4510 </tr>
5760 4511 <tr>
5761 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
5762 - <td><?php $this->print_text_ldap_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4512 + <th scope="row"><?php _e( 'LDAP Directory User', 'authorizer' ); ?></th>
4513 + <td><?php $this->print_text_ldap_user( array( MULTISITE_ADMIN => true ) ); ?></td>
5763 4514 </tr>
5764 4515 <tr>
5765 - <th scope="row"><?php esc_html_e( 'LDAP Directory User', 'authorizer' ); ?></th>
5766 - <td><?php $this->print_text_ldap_user( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4516 + <th scope="row"><?php _e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
4517 + <td><?php $this->print_password_ldap_password( array( MULTISITE_ADMIN => true ) ); ?></td>
5767 4518 </tr>
5768 4519 <tr>
5769 - <th scope="row"><?php esc_html_e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
5770 - <td><?php $this->print_password_ldap_password( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4520 + <th scope="row"><?php _e( 'Custom lost password URL', 'authorizer' ); ?></th>
4521 + <td><?php $this->print_text_ldap_lostpassword_url( array( MULTISITE_ADMIN => true ) ); ?></td>
5771 4522 </tr>
5772 4523 <tr>
5773 - <th scope="row"><?php esc_html_e( 'Custom lost password URL', 'authorizer' ); ?></th>
5774 - <td><?php $this->print_text_ldap_lostpassword_url( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4524 + <th scope="row"><?php _e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
4525 + <td><?php $this->print_text_ldap_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5775 4526 </tr>
5776 4527 <tr>
5777 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
5778 - <td><?php $this->print_text_ldap_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4528 + <th scope="row"><?php _e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
4529 + <td><?php $this->print_text_ldap_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5779 4530 </tr>
5780 4531 <tr>
5781 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
5782 - <td><?php $this->print_text_ldap_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4532 + <th scope="row"><?php _e( 'LDAP attribute update', 'authorizer' ); ?></th>
4533 + <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5783 4534 </tr>
5784 - <tr>
5785 - <th scope="row"><?php esc_html_e( 'LDAP attribute update', 'authorizer' ); ?></th>
5786 - <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5787 - </tr>
5788 4535 </tbody></table>
5789 4536
5790 4537 <?php $this->print_section_info_advanced(); ?>
5791 4538 <table class="form-table"><tbody>
5792 4539 <tr>
5793 - <th scope="row"><?php esc_html_e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
5794 - <td><?php $this->print_text_auth_advanced_lockouts( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4540 + <th scope="row"><?php _e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
4541 + <td><?php $this->print_text_auth_advanced_lockouts( array( MULTISITE_ADMIN => true ) ); ?></td>
5795 4542 </tr>
5796 4543 <tr>
5797 - <th scope="row"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
5798 - <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4544 + <th scope="row"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
4545 + <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5799 4546 </tr>
5800 - <tr>
5801 - <th scope="row"><?php esc_html_e( 'Number of users per page', 'authorizer' ); ?></th>
5802 - <td><?php $this->print_text_auth_advanced_users_per_page( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5803 - </tr>
5804 - <tr>
5805 - <th scope="row"><?php esc_html_e( 'Approved users sort method', 'authorizer' ); ?></th>
5806 - <td><?php $this->print_select_auth_advanced_users_sort_by( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5807 - </tr>
5808 - <tr>
5809 - <th scope="row"><?php esc_html_e( 'Approved users sort order', 'authorizer' ); ?></th>
5810 - <td><?php $this->print_select_auth_advanced_users_sort_order( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5811 - </tr>
5812 - <tr>
5813 - <th scope="row"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></th>
5814 - <td><?php $this->print_checkbox_auth_advanced_widget_enabled( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5815 - </tr>
5816 4547 </tbody></table>
5817 4548
5818 4549 <br class="clear" />
5819 4550 </div>
5820 - <input type="button" name="submit" id="submit" class="button button-primary" value="<?php esc_attr_e( 'Save Changes', 'authorizer' ); ?>" onclick="saveAuthMultisiteSettings(this);" />
4551 + <input type="button" name="submit" id="submit" class="button button-primary" value="<?php _e( 'Save Changes', 'authorizer' ); ?>" onclick="save_auth_multisite_settings(this);" />
5821 4552 </form>
5822 4553 </div>
5823 4554 <?php
5824 4555 }
@@ -5825,12 +4556,10 @@
5825 4556
5826 4557
5827 4558 /**
5828 4559 * Save multisite settings (ajax call).
5829 - *
5830 - * Action: wp_ajax_save_auth_multisite_settings
5831 4560 */
5832 - public function ajax_save_auth_multisite_settings() {
4561 + function ajax_save_auth_multisite_settings() {
5833 4562 // Fail silently if current user doesn't have permissions.
5834 4563 if ( ! current_user_can( 'manage_network_options' ) ) {
5835 4564 die( '' );
5836 4565 }
@@ -5835,14 +4564,14 @@
5835 4564 die( '' );
5836 4565 }
5837 4566
5838 4567 // Make sure nonce exists.
5839 - if ( empty( $_POST['nonce'] ) ) {
4568 + if ( empty( $_POST['nonce_save_auth_settings'] ) ) {
5840 4569 die( '' );
5841 4570 }
5842 4571
5843 4572 // Nonce check.
5844 - if ( ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4573 + if ( ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5845 4574 die( '' );
5846 4575 }
5847 4576
5848 4577 // Assert multisite.
@@ -5850,15 +4579,15 @@
5850 4579 die( '' );
5851 4580 }
5852 4581
5853 4582 // Get multisite settings.
5854 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
4583 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
5855 4584
5856 - // Sanitize settings.
4585 + // Sanitize settings
5857 4586 $auth_multisite_settings = $this->sanitize_options( $_POST );
5858 4587
5859 - // Filter options to only the allowed values (multisite options are a subset of all options).
5860 - $allowed = array(
4588 + // Filter options to only the allowed values (multisite options are a subset of all options)
4589 + $allowed = array(
5861 4590 'multisite_override',
5862 4591 'access_who_can_login',
5863 4592 'access_who_can_view',
5864 4593 'access_default_role',
@@ -5876,9 +4605,8 @@
5876 4605 'cas_attr_first_name',
5877 4606 'cas_attr_last_name',
5878 4607 'cas_attr_update_on_login',
5879 4608 'cas_auto_login',
5880 - 'cas_link_on_username',
5881 4609 'ldap',
5882 4610 'ldap_host',
5883 4611 'ldap_port',
5884 4612 'ldap_tls',
@@ -5892,17 +4620,13 @@
5892 4620 'ldap_attr_last_name',
5893 4621 'ldap_attr_update_on_login',
5894 4622 'advanced_lockouts',
5895 4623 'advanced_hide_wp_login',
5896 - 'advanced_users_per_page',
5897 - 'advanced_users_sort_by',
5898 - 'advanced_users_sort_order',
5899 - 'advanced_widget_enabled',
5900 4624 );
5901 4625 $auth_multisite_settings = array_intersect_key( $auth_multisite_settings, array_flip( $allowed ) );
5902 4626
5903 4627 // Update multisite settings in database.
5904 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
4628 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
5905 4629
5906 4630 // Return 'success' value to AJAX call.
5907 4631 die( 'success' );
5908 4632 }
@@ -5916,67 +4640,42 @@
5916 4640 */
5917 4641
5918 4642
5919 4643
5920 - /**
5921 - * Load Authorizer dashboard widget if it's enabled.
5922 - *
5923 - * Action: wp_dashboard_setup
5924 - */
5925 - public function add_dashboard_widgets() {
5926 - $widget_enabled = $this->get_plugin_option( 'advanced_widget_enabled', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) === '1';
5927 -
5928 - // Load authorizer dashboard widget if it's enabled and user has permission.
5929 - if ( current_user_can( 'create_users' ) && $widget_enabled ) {
5930 - // Add dashboard widget for adding/editing users with access.
4644 + function add_dashboard_widgets() {
4645 + // Only users who can edit can see the authorizer dashboard widget
4646 + if ( current_user_can( 'create_users' ) ) {
4647 + // Add dashboard widget for adding/editing users with access
5931 4648 wp_add_dashboard_widget( 'auth_dashboard_widget', __( 'Authorizer Settings', 'authorizer' ), array( $this, 'add_auth_dashboard_widget' ) );
5932 4649 }
5933 4650 }
5934 4651
5935 4652
5936 - /**
5937 - * Render Authorizer dashboard widget (callback).
5938 - */
5939 - public function add_auth_dashboard_widget() {
5940 - ?>
5941 - <form method="post" id="auth_settings_access_form" action="">
4653 + function add_auth_dashboard_widget() {
4654 + ?><form method="post" id="auth_settings_access_form" action="">
5942 4655 <?php $this->print_section_info_access_login(); ?>
5943 4656 <div>
5944 - <h2><?php esc_html_e( 'Pending Users', 'authorizer' ); ?></h2>
4657 + <h2><?php _e( 'Pending Users', 'authorizer' ); ?></h2>
5945 4658 <?php $this->print_combo_auth_access_users_pending(); ?>
5946 4659 </div>
5947 4660 <div>
5948 - <h2><?php esc_html_e( 'Approved Users', 'authorizer' ); ?></h2>
4661 + <h2><?php _e( 'Approved Users', 'authorizer' ); ?></h2>
5949 4662 <?php $this->print_combo_auth_access_users_approved(); ?>
5950 4663 </div>
5951 4664 <div>
5952 - <h2><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?></h2>
4665 + <h2><?php _e( 'Blocked Users', 'authorizer' ); ?></h2>
5953 4666 <?php $this->print_combo_auth_access_users_blocked(); ?>
5954 4667 </div>
5955 4668 <br class="clear" />
5956 - </form>
5957 - <?php
4669 + </form><?php
5958 4670 }
5959 4671
5960 4672
5961 -
5962 - /**
5963 - * ***************************
5964 - * AJAX Actions
5965 - * ***************************
5966 - */
5967 -
5968 -
5969 -
5970 - /**
5971 - * Re-render the Approved User list (usually triggered if pager params have
5972 - * changed, e.g., current page, search term, sort order).
5973 - *
5974 - * Action: wp_ajax_refresh_approved_user_list
5975 - *
5976 - * @return void
5977 - */
5978 - public function ajax_refresh_approved_user_list() {
4673 + // Fired on a change event from the optional usermeta field in the
4674 + // approved user list. Updates the selected usermeta value, or saves it
4675 + // in the user's approved list entry if the user hasn't logged in yet
4676 + // and created a WordPress account.
4677 + function ajax_update_auth_usermeta() {
5979 4678 // Fail silently if current user doesn't have permissions.
5980 4679 if ( ! current_user_can( 'create_users' ) ) {
5981 4680 die( '' );
5982 4681 }
@@ -5981,175 +4680,35 @@
5981 4680 die( '' );
5982 4681 }
5983 4682
5984 4683 // Nonce check.
5985 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4684 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5986 4685 die( '' );
5987 4686 }
5988 4687
5989 4688 // Fail if required post data doesn't exist.
5990 - if ( ! array_key_exists( 'paged', $_REQUEST ) ) {
4689 + if ( ! array_key_exists( 'email', $_REQUEST ) || ! array_key_exists( 'usermeta', $_REQUEST ) ) {
5991 4690 die( '' );
5992 4691 }
5993 4692
5994 - // Get defaults.
5995 - $success = true;
5996 - $message = '';
5997 - $is_network_admin = isset( $_REQUEST['is_network_admin'] ) && '1' === $_REQUEST['is_network_admin'];
5998 -
5999 - // Get user list.
6000 - $option = 'access_users_approved';
6001 - $admin_mode = is_multisite() && $is_network_admin ? WP_Plugin_Authorizer::NETWORK_CONTEXT : WP_Plugin_Authorizer::SINGLE_CONTEXT;
6002 - $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
6003 - $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
6004 -
6005 - // Get multisite approved users (will be added to top of list, greyed out).
6006 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
6007 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
6008 - $auth_settings_option_multisite = array();
6009 - if (
6010 - is_multisite() &&
6011 - ! $is_network_admin &&
6012 - 1 !== intval( $auth_override_multisite ) &&
6013 - array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
6014 - '1' === $auth_multisite_settings['multisite_override']
6015 - ) {
6016 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
6017 - $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
6018 - // Add multisite users to the beginning of the main user array.
6019 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
6020 - $approved_user['multisite_user'] = true;
6021 - array_unshift( $auth_settings_option, $approved_user );
6022 - }
6023 - }
6024 -
6025 - // Get custom usermeta field to show.
6026 - $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
6027 -
6028 - // Filter user list to search terms.
6029 - if ( ! empty( $_REQUEST['search'] ) ) {
6030 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
6031 - $auth_settings_option = array_filter(
6032 - $auth_settings_option, function ( $user ) use ( $search_term ) {
6033 - return stripos( $user['email'], $search_term ) !== false ||
6034 - stripos( $user['role'], $search_term ) !== false ||
6035 - stripos( $user['date_added'], $search_term ) !== false;
6036 - }
6037 - );
6038 - }
6039 -
6040 - // Sort user list.
6041 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
6042 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
6043 - $sort_dimension = array();
6044 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
6045 - foreach ( $auth_settings_option as $key => $user ) {
6046 - if ( 'date_added' === $sort_by ) {
6047 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
6048 - } else {
6049 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
6050 - }
6051 - }
6052 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
6053 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
6054 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
6055 - // If default sort method and reverse order, just reverse the array.
6056 - $auth_settings_option = array_reverse( $auth_settings_option );
6057 - }
6058 -
6059 - // Ensure array keys run from 0..max (keys in database will be the original,
6060 - // index, and removing users will not reorder the array keys of other users).
6061 - $auth_settings_option = array_values( $auth_settings_option );
6062 -
6063 - // Get pager params.
6064 - $total_users = count( $auth_settings_option );
6065 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
6066 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
6067 - $total_pages = ceil( $total_users / $users_per_page );
6068 - if ( $total_pages < 1 ) {
6069 - $total_pages = 1;
6070 - }
6071 -
6072 - // Make sure current_page is between 1 and max pages.
6073 - if ( $current_page < 1 ) {
6074 - $current_page = 1;
6075 - } elseif ( $current_page > $total_pages ) {
6076 - $current_page = $total_pages;
6077 - }
6078 -
6079 - // Render user list.
6080 - ob_start();
6081 - $offset = ( $current_page - 1 ) * $users_per_page;
6082 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
6083 - for ( $key = $offset; $key < $max; $key++ ) :
6084 - $approved_user = $auth_settings_option[ $key ];
6085 - if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
6086 - continue;
6087 - endif;
6088 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
6089 - endfor;
6090 -
6091 - // Send response to client.
6092 - $response = array(
6093 - 'success' => $success,
6094 - 'message' => $message,
6095 - 'html' => ob_get_clean(),
6096 - /* TRANSLATORS: %s: number of users */
6097 - 'total_users_html' => sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ),
6098 - 'total_pages_html' => number_format_i18n( $total_pages ),
6099 - 'total_pages' => $total_pages,
6100 - );
6101 - header( 'content-type: application/json' );
6102 - echo wp_json_encode( $response );
6103 - exit;
6104 - }
6105 -
6106 -
6107 - /**
6108 - * Fired on a change event from the optional usermeta field in the approved
6109 - * user list. Updates the selected usermeta value, or saves it in the user's
6110 - * approved list entry if the user hasn't logged in yet and created a
6111 - * WordPress account.
6112 - *
6113 - * Action: wp_ajax_update_auth_usermeta
6114 - *
6115 - * @return void
6116 - */
6117 - public function ajax_update_auth_usermeta() {
6118 - // Fail silently if current user doesn't have permissions.
6119 - if ( ! current_user_can( 'create_users' ) ) {
6120 - die( '' );
6121 - }
6122 -
6123 - // Nonce check.
6124 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
6125 - die( '' );
6126 - }
6127 -
6128 - // Fail if required post data doesn't exist.
6129 - if ( ! isset( $_REQUEST['email'], $_REQUEST['usermeta'] ) ) {
6130 - die( '' );
6131 - }
6132 -
6133 4693 // Get values to update from post data.
6134 - $email = sanitize_email( wp_unslash( $_REQUEST['email'] ) );
6135 - $meta_value = sanitize_meta( 'authorizer-usermeta', wp_unslash( $_REQUEST['usermeta'] ), 'user' );
6136 - $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
4694 + $email = $_REQUEST['email'];
4695 + $meta_value = $_REQUEST['usermeta'];
4696 + $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
6137 4697
6138 4698 // If user doesn't exist, save usermeta selection to authorizer
6139 4699 // list. This value will get saved to usermeta when the user first
6140 4700 // logs in (i.e., when their WordPress account is created).
6141 - $wp_user = get_user_by( 'email', $email );
6142 - if ( ! $wp_user ) {
4701 + if ( ! ( $wp_user = get_user_by( 'email', $email ) ) ) {
6143 4702 // Look through multisite approved users and add a usermeta
6144 4703 // reference for the current blog if the user is found.
6145 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
4704 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
6146 4705 $should_update_auth_multisite_settings_access_users_approved = false;
6147 4706 foreach ( $auth_multisite_settings_access_users_approved as $index => $approved_user ) {
6148 - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6149 - if ( ! is_array( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] ) ) {
4707 + if ( $email === $approved_user['email'] ) {
4708 + if ( ! is_array( $auth_multisite_settings_access_users_approved[$index]['usermeta'] ) ) {
6150 4709 // Initialize the array of usermeta for each blog this user belongs to.
6151 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] = array();
4710 + $auth_multisite_settings_access_users_approved[$index]['usermeta'] = array();
6152 4711 } else {
6153 4712 // There is already usermeta associated with this
6154 4713 // preapproved user; iterate through it and make
6155 4714 // sure it's not for old meta_keys (delete it if
@@ -6155,53 +4714,55 @@
6155 4714 // sure it's not for old meta_keys (delete it if
6156 4715 // so). This can happen if someone changes the
6157 4716 // usermeta key in authorizer options, and we don't
6158 4717 // want to hang on to old data.
6159 - foreach ( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] as $blog_id => $usermeta ) {
4718 + foreach ( $auth_multisite_settings_access_users_approved[$index]['usermeta'] as $blog_id => $usermeta ) {
6160 4719 if ( array_key_exists( 'meta_key', $usermeta ) && $usermeta['meta_key'] === $meta_key ) {
6161 4720 continue;
6162 4721 } else {
6163 - unset( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ $blog_id ] );
4722 + unset( $auth_multisite_settings_access_users_approved[$index]['usermeta'][$blog_id] );
6164 4723 }
6165 4724 }
6166 4725 }
6167 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ get_current_blog_id() ] = array(
6168 - 'meta_key' => $meta_key,
4726 + $auth_multisite_settings_access_users_approved[$index]['usermeta'][get_current_blog_id()] = array(
4727 + 'meta_key' => $meta_key,
6169 4728 'meta_value' => $meta_value,
6170 4729 );
6171 - $should_update_auth_multisite_settings_access_users_approved = true;
4730 + $should_update_auth_multisite_settings_access_users_approved = true;
6172 4731 }
6173 4732 }
6174 4733 if ( $should_update_auth_multisite_settings_access_users_approved ) {
6175 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4734 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6176 4735 }
6177 4736
6178 4737 // Look through the approved users (of the current blog in a
6179 4738 // multisite install, or just of the single site) and add a
6180 4739 // usermeta reference if the user is found.
6181 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
4740 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
6182 4741 $should_update_auth_settings_access_users_approved = false;
6183 4742 foreach ( $auth_settings_access_users_approved as $index => $approved_user ) {
6184 - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6185 - $auth_settings_access_users_approved[ $index ]['usermeta'] = array(
6186 - 'meta_key' => $meta_key,
4743 + if ( $email === $approved_user['email'] ) {
4744 + $auth_settings_access_users_approved[$index]['usermeta'] = array(
4745 + 'meta_key' => $meta_key,
6187 4746 'meta_value' => $meta_value,
6188 4747 );
6189 - $should_update_auth_settings_access_users_approved = true;
4748 + $should_update_auth_settings_access_users_approved = true;
6190 4749 }
6191 4750 }
6192 4751 if ( $should_update_auth_settings_access_users_approved ) {
6193 4752 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6194 4753 }
4754 +
6195 4755 } else {
6196 4756 // Update user's usermeta value for usermeta key stored in authorizer options.
6197 4757 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
6198 4758 // We have an ACF field value, so use the ACF function to update it.
6199 - update_field( str_replace( 'acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
4759 + update_field( str_replace('acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
6200 4760 } else {
6201 4761 // We have a normal usermeta value, so just update it via the WordPress function.
6202 4762 update_user_meta( $wp_user->ID, $meta_key, $meta_value );
6203 4763 }
4764 +
6204 4765 }
6205 4766
6206 4767 // Return 'success' value to AJAX call.
6207 4768 die( 'success' );
@@ -6207,17 +4768,9 @@
6207 4768 die( 'success' );
6208 4769 }
6209 4770
6210 4771
6211 - /**
6212 - * Fired on a change event from the user fields in the user lists. Updates
6213 - * the selected user value.
6214 - *
6215 - * Action: wp_ajax_update_auth_user
6216 - *
6217 - * @return void
6218 - */
6219 - public function ajax_update_auth_user() {
4772 + function ajax_update_auth_user() {
6220 4773 // Fail silently if current user doesn't have permissions.
6221 4774 if ( ! current_user_can( 'create_users' ) ) {
6222 4775 die( '' );
6223 4776 }
@@ -6222,79 +4775,76 @@
6222 4775 die( '' );
6223 4776 }
6224 4777
6225 4778 // Nonce check.
6226 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4779 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
6227 4780 die( '' );
6228 4781 }
6229 4782
6230 4783 // Fail if requesting a change to an invalid setting.
6231 - if ( ! isset( $_POST['setting'] ) || ! in_array( wp_unslash( $_POST['setting'] ), array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
4784 + if ( ! in_array( $_POST['setting'], array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
6232 4785 die( '' );
6233 4786 }
6234 4787
6235 - // Track any emails that couldn't be added (used when adding users).
6236 - $invalid_emails = array();
6237 -
6238 4788 // Editing a pending list entry.
6239 - if ( 'access_users_pending' === $_POST['setting'] ) {
6240 - // Sanitize posted data.
6241 - $access_users_pending = array();
6242 - if ( isset( $_POST['access_users_pending'] ) && is_array( $_POST['access_users_pending'] ) ) {
6243 - $access_users_pending = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_pending'] ) );
4789 + if ( $_POST['setting'] === 'access_users_pending' ) {
4790 + // Initialize posted data if empty.
4791 + if ( ! ( array_key_exists( 'access_users_pending', $_POST ) && is_array( $_POST['access_users_pending'] ) ) ) {
4792 + $_POST['access_users_pending'] = array();
6244 4793 }
6245 4794
6246 4795 // Deal with each modified user (add or remove).
6247 - foreach ( $access_users_pending as $pending_user ) {
4796 + foreach ( $_POST['access_users_pending'] as $pending_user ) {
6248 4797
6249 - if ( 'add' === $pending_user['edit_action'] ) {
4798 + if ( $pending_user['edit_action'] === 'add' ) {
6250 4799
6251 4800 // Add new user to pending list and save (skip if it's
6252 4801 // already there--someone else might have just done it).
6253 4802 if ( ! $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
6254 4803 $auth_settings_access_users_pending = $this->sanitize_user_list(
6255 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4804 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
6256 4805 );
6257 4806 array_push( $auth_settings_access_users_pending, $pending_user );
6258 4807 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6259 4808 }
6260 - } elseif ( 'remove' === $pending_user['edit_action'] ) {
6261 4809
6262 - // Remove user from pending list and save.
6263 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6264 - foreach ( $auth_settings_access_users_pending as $key => $existing_user ) {
6265 - if ( 0 === strcasecmp( $pending_user['email'], $existing_user['email'] ) ) {
6266 - unset( $auth_settings_access_users_pending[ $key ] );
6267 - update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6268 - break;
4810 + } elseif ( $pending_user['edit_action'] === 'remove' ) {
4811 +
4812 + // Remove user from pending list and save
4813 + if ( $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
4814 + $auth_settings_access_users_pending = $this->sanitize_user_list(
4815 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
4816 + );
4817 + foreach ( $auth_settings_access_users_pending as $key => $existing_user ) {
4818 + if ( $pending_user['email'] == $existing_user['email'] ) {
4819 + unset( $auth_settings_access_users_pending[$key] );
4820 + break;
4821 + }
6269 4822 }
4823 + update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6270 4824 }
4825 +
6271 4826 }
6272 4827 }
6273 4828 }
6274 4829
6275 4830 // Editing an approved list entry.
6276 - if ( 'access_users_approved' === $_POST['setting'] ) {
6277 - // Sanitize posted data.
6278 - $access_users_approved = array();
6279 - if ( isset( $_POST['access_users_approved'] ) && is_array( $_POST['access_users_approved'] ) ) {
6280 - $access_users_approved = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_approved'] ) );
4831 + if ( $_POST['setting'] === 'access_users_approved' ) {
4832 + // Initialize posted data if empty.
4833 + if ( ! ( array_key_exists( 'access_users_approved', $_POST ) && is_array( $_POST['access_users_approved'] ) ) ) {
4834 + $_POST['access_users_approved'] = array();
6281 4835 }
6282 4836
6283 4837 // Deal with each modified user (add, remove, or change_role).
6284 - foreach ( $access_users_approved as $approved_user ) {
6285 - // Skip blank entries.
6286 - if ( strlen( $approved_user['email'] ) < 1 ) {
6287 - continue;
6288 - }
4838 + foreach ( $_POST['access_users_approved'] as $approved_user ) {
6289 4839
6290 4840 // New user (create user, or add existing user to current site in multisite).
6291 - if ( 'add' === $approved_user['edit_action'] ) {
4841 + if ( $approved_user['edit_action'] === 'add' ) {
6292 4842 $new_user = get_user_by( 'email', $approved_user['email'] );
6293 - if ( false !== $new_user ) {
4843 + if ( $new_user !== false ) {
6294 4844 // If we're adding an existing multisite user, make sure their
6295 4845 // newly-assigned role is updated on all sites they are already in.
6296 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4846 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6297 4847 foreach ( get_blogs_of_user( $new_user->ID ) as $blog ) {
6298 4848 add_user_to_blog( $blog->userblog_id, $new_user->ID, $approved_user['role'] );
6299 4849 }
6300 4850 }
@@ -6301,9 +4851,9 @@
6301 4851 // If this user already has an account on another site in the network, add them to this site.
6302 4852 if ( is_multisite() ) {
6303 4853 add_user_to_blog( get_current_blog_id(), $new_user->ID, $approved_user['role'] );
6304 4854 }
6305 - } elseif ( $approved_user['local_user'] && 'false' !== $approved_user['local_user'] ) {
4855 + } elseif ( $approved_user['local_user'] === 'true' ) {
6306 4856 // Create a WP account for this new *local* user and email the password.
6307 4857 $plaintext_password = wp_generate_password(); // random password
6308 4858 // If there's already a user with this username (e.g.,
6309 4859 // johndoe/johndoe@gmail.com exists, and we're trying to add
@@ -6311,26 +4861,26 @@
6311 4861 // as the username.
6312 4862 $username = explode( '@', $approved_user['email'] );
6313 4863 $username = $username[0];
6314 4864 if ( get_user_by( 'login', $username ) !== false ) {
6315 - $username = $this->lowercase( $approved_user['email'] );
4865 + $username = $approved_user['email'];
6316 4866 }
6317 - if ( 'false' !== $approved_user['multisite_user'] ) {
4867 + if ( $approved_user['multisite_user'] !== 'false' ) {
6318 4868 $result = wpmu_create_user(
6319 4869 strtolower( $username ),
6320 4870 $plaintext_password,
6321 - $this->lowercase( $approved_user['email'] )
4871 + strtolower( $approved_user['email'] )
6322 4872 );
6323 4873 } else {
6324 4874 $result = wp_insert_user(
6325 4875 array(
6326 - 'user_login' => strtolower( $username ),
6327 - 'user_pass' => $plaintext_password,
6328 - 'first_name' => '',
6329 - 'last_name' => '',
6330 - 'user_email' => $this->lowercase( $approved_user['email'] ),
4876 + 'user_login' => strtolower( $username ),
4877 + 'user_pass' => $plaintext_password,
4878 + 'first_name' => '',
4879 + 'last_name' => '',
4880 + 'user_email' => strtolower( $approved_user['email'] ),
6331 4881 'user_registered' => date( 'Y-m-d H:i:s' ),
6332 - 'role' => $approved_user['role'],
4882 + 'role' => $approved_user['role'],
6333 4883 )
6334 4884 );
6335 4885 }
6336 4886 if ( ! is_wp_error( $result ) ) {
@@ -6336,8 +4886,9 @@
6336 4886 if ( ! is_wp_error( $result ) ) {
6337 4887 // Email login credentials to new user.
6338 4888 wp_new_user_notification( $result, null, 'both' );
6339 4889 }
4890 +
6340 4891 }
6341 4892
6342 4893 // Email new user welcome message if plugin option is set.
6343 4894 $this->maybe_email_welcome_message( $approved_user['email'] );
@@ -6343,46 +4894,41 @@
6343 4894 $this->maybe_email_welcome_message( $approved_user['email'] );
6344 4895
6345 4896 // Add new user to approved list and save (skip if it's
6346 4897 // already there--someone else might have just done it).
6347 - if ( 'false' !== $approved_user['multisite_user'] ) {
4898 + if ( $approved_user['multisite_user'] !== 'false' ) {
6348 4899 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6349 4900 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6350 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4901 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6351 4902 );
6352 - $approved_user['date_added'] = date( 'M Y' );
4903 + $approved_user['date_added'] = date( 'M Y' );
6353 4904 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
6354 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6355 - } else {
6356 - $invalid_emails[] = $approved_user['email'];
4905 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6357 4906 }
6358 4907 } else {
6359 4908 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6360 4909 $auth_settings_access_users_approved = $this->sanitize_user_list(
6361 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4910 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6362 4911 );
6363 - $approved_user['date_added'] = date( 'M Y' );
4912 + $approved_user['date_added'] = date( 'M Y' );
6364 4913 array_push( $auth_settings_access_users_approved, $approved_user );
6365 4914 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6366 - } else {
6367 - $invalid_emails[] = $approved_user['email'];
6368 4915 }
6369 4916 }
6370 4917
6371 4918 // If we've added a new multisite user, go through all pending/approved/blocked lists
6372 4919 // on individual sites and remove this user from them (to prevent duplicate entries).
6373 - if ( 'false' !== $approved_user['multisite_user'] && is_multisite() ) {
4920 + if ( $approved_user['multisite_user'] !== 'false' && is_multisite() ) {
6374 4921 $list_names = array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' );
6375 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6376 4922 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6377 4923 foreach ( $sites as $site ) {
6378 4924 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6379 4925 foreach ( $list_names as $list_name ) {
6380 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
4926 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6381 4927 $list_changed = false;
6382 4928 foreach ( $user_list as $key => $user ) {
6383 - if ( 0 === strcasecmp( $user['email'], $approved_user['email'] ) ) {
6384 - unset( $user_list[ $key ] );
4929 + if ( $user['email'] == $approved_user['email'] ) {
4930 + unset( $user_list[$key] );
6385 4931 $list_changed = true;
6386 4932 }
6387 4933 }
6388 4934 if ( $list_changed ) {
@@ -6390,47 +4936,44 @@
6390 4936 }
6391 4937 }
6392 4938 }
6393 4939 }
6394 - } elseif ( 'remove' === $approved_user['edit_action'] ) { // Remove user from approved list and save (also remove their role if they have a WordPress account).
6395 - if ( 'false' !== $approved_user['multisite_user'] ) {
6396 - $auth_multisite_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
6397 - foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6398 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6399 - // Remove role of the associated WordPress user from all blogs (but don't delete the user).
6400 - $user = get_user_by( 'email', $approved_user['email'] );
6401 - if ( false !== $user ) {
6402 - // Loop through all of the blogs this user is a member of and remove their capabilities.
6403 - foreach ( get_blogs_of_user( $user->ID ) as $blog ) {
6404 - remove_user_from_blog( $user->ID, $blog->userblog_id, '' );
6405 - }
4940 +
4941 + // Remove user from approved list and save
4942 + } elseif ( $approved_user['edit_action'] === 'remove' ) {
4943 + if ( $approved_user['multisite_user'] !== 'false' ) {
4944 + if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
4945 + $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
4946 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
4947 + );
4948 + foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
4949 + if ( $approved_user['email'] == $existing_user['email'] ) {
4950 + unset( $auth_multisite_settings_access_users_approved[$key] );
4951 + break;
6406 4952 }
6407 - // Remove entry from Approved Users list.
6408 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
6409 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6410 - break;
6411 4953 }
4954 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6412 4955 }
6413 4956 } else {
6414 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6415 - foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6416 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6417 - // Remove role of the associated WordPress user (but don't delete the user).
6418 - $user = get_user_by( 'email', $approved_user['email'] );
6419 - if ( false !== $user ) {
6420 - $user->set_role( '' );
4957 + if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
4958 + $auth_settings_access_users_approved = $this->sanitize_user_list(
4959 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
4960 + );
4961 + foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
4962 + if ( $approved_user['email'] == $existing_user['email'] ) {
4963 + unset( $auth_settings_access_users_approved[$key] );
4964 + break;
6421 4965 }
6422 - // Remove entry from Approved Users list.
6423 - unset( $auth_settings_access_users_approved[ $key ] );
6424 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6425 - break;
6426 4966 }
4967 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6427 4968 }
6428 4969 }
6429 - } elseif ( 'change_role' === $approved_user['edit_action'] ) { // Update user's role in WordPress.
4970 +
4971 + // Update user's role in WordPress
4972 + } elseif ( $approved_user['edit_action'] === 'change_role' ) {
6430 4973 $changed_user = get_user_by( 'email', $approved_user['email'] );
6431 4974 if ( $changed_user ) {
6432 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4975 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6433 4976 foreach ( get_blogs_of_user( $changed_user->ID ) as $blog ) {
6434 4977 add_user_to_blog( $blog->userblog_id, $changed_user->ID, $approved_user['role'] );
6435 4978 }
6436 4979 } else {
@@ -6437,30 +4980,30 @@
6437 4980 $changed_user->set_role( $approved_user['role'] );
6438 4981 }
6439 4982 }
6440 4983
6441 - if ( 'false' !== $approved_user['multisite_user'] ) {
4984 + if ( $approved_user['multisite_user'] !== 'false' ) {
6442 4985 if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6443 4986 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6444 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4987 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6445 4988 );
6446 4989 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6447 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6448 - $auth_multisite_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
4990 + if ( $approved_user['email'] == $existing_user['email'] ) {
4991 + $auth_multisite_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6449 4992 break;
6450 4993 }
6451 4994 }
6452 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4995 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6453 4996 }
6454 4997 } else {
6455 4998 // Update user's role in approved list and save.
6456 4999 if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6457 5000 $auth_settings_access_users_approved = $this->sanitize_user_list(
6458 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5001 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6459 5002 );
6460 5003 foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6461 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6462 - $auth_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
5004 + if ( $approved_user['email'] == $existing_user['email'] ) {
5005 + $auth_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6463 5006 break;
6464 5007 }
6465 5008 }
6466 5009 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
@@ -6465,33 +5008,28 @@
6465 5008 }
6466 5009 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6467 5010 }
6468 5011 }
5012 +
6469 5013 }
6470 5014 }
6471 5015 }
6472 5016
6473 5017 // Editing a blocked list entry.
6474 - if ( 'access_users_blocked' === $_POST['setting'] ) {
6475 - // Sanitize post data.
6476 - $access_users_blocked = array();
6477 - if ( isset( $_POST['access_users_blocked'] ) && is_array( $_POST['access_users_blocked'] ) ) {
6478 - $access_users_blocked = $this->sanitize_update_auth_users(
6479 - wp_unslash( $_POST['access_users_blocked'] ),
6480 - array(
6481 - 'allow_wildcard_email' => true,
6482 - )
6483 - );
5018 + if ( $_POST['setting'] === 'access_users_blocked' ) {
5019 + // Initialize posted data if empty.
5020 + if ( ! ( array_key_exists( 'access_users_blocked', $_POST ) && is_array( $_POST['access_users_blocked'] ) ) ) {
5021 + $_POST['access_users_blocked'] = array();
6484 5022 }
6485 5023
6486 5024 // Deal with each modified user (add or remove).
6487 - foreach ( $access_users_blocked as $blocked_user ) {
5025 + foreach ( $_POST['access_users_blocked'] as $blocked_user ) {
6488 5026
6489 - if ( 'add' === $blocked_user['edit_action'] ) {
5027 + if ( $blocked_user['edit_action'] === 'add' ) {
6490 5028
6491 5029 // Add auth_blocked usermeta for the user.
6492 5030 $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
6493 - if ( false !== $blocked_wp_user ) {
5031 + if ( $blocked_wp_user !== false ) {
6494 5032 update_user_meta( $blocked_wp_user->ID, 'auth_blocked', 'yes' );
6495 5033 }
6496 5034
6497 5035 // Add new user to blocked list and save (skip if it's
@@ -6497,162 +5035,48 @@
6497 5035 // Add new user to blocked list and save (skip if it's
6498 5036 // already there--someone else might have just done it).
6499 5037 if ( ! $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
6500 5038 $auth_settings_access_users_blocked = $this->sanitize_user_list(
6501 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5039 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
6502 5040 );
6503 - $blocked_user['date_added'] = date( 'M Y' );
5041 + $blocked_user['date_added'] = date( 'M Y' );
6504 5042 array_push( $auth_settings_access_users_blocked, $blocked_user );
6505 5043 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6506 - } else {
6507 - $invalid_emails[] = $blocked_user['email'];
6508 5044 }
6509 - } elseif ( 'remove' === $blocked_user['edit_action'] ) {
6510 5045
5046 + } elseif ( $blocked_user['edit_action'] === 'remove' ) {
5047 +
6511 5048 // Remove auth_blocked usermeta for the user.
6512 5049 $unblocked_user = get_user_by( 'email', $blocked_user['email'] );
6513 - if ( false !== $unblocked_user ) {
5050 + if ( $unblocked_user !== false ) {
6514 5051 delete_user_meta( $unblocked_user->ID, 'auth_blocked', 'yes' );
6515 5052 }
6516 5053
6517 - // Remove user from blocked list and save.
6518 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6519 - foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) {
6520 - if ( 0 === strcasecmp( $blocked_user['email'], $existing_user['email'] ) ) {
6521 - unset( $auth_settings_access_users_blocked[ $key ] );
6522 - update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6523 - break;
5054 + // Remove user from blocked list and save
5055 + if ( $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
5056 + $auth_settings_access_users_blocked = $this->sanitize_user_list(
5057 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
5058 + );
5059 + foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) {
5060 + if ( $blocked_user['email'] == $existing_user['email'] ) {
5061 + unset( $auth_settings_access_users_blocked[$key] );
5062 + break;
5063 + }
6524 5064 }
5065 + update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6525 5066 }
5067 +
6526 5068 }
6527 5069 }
6528 5070 }
6529 5071
6530 - // Send response to client.
6531 - $response = array(
6532 - 'success' => true,
6533 - 'invalid_emails' => $invalid_emails,
6534 - );
6535 - header( 'content-type: application/json' );
6536 - echo wp_json_encode( $response );
6537 - exit;
5072 + // Return 'success' value to AJAX call.
5073 + die( 'success' );
6538 5074 }
6539 5075
6540 5076
6541 - /**
6542 - * Sanitizes an array of user update commands coming from the AJAX handler in Authorizer Settings.
6543 - *
6544 - * Example $users array:
6545 - * array(
6546 - * array(
6547 - * edit_action: 'add' or 'remove' or 'change_role',
6548 - * email: 'johndoe@example.com',
6549 - * role: 'subscriber',
6550 - * date_added: 'Jun 2014',
6551 - * local_user: 'true' or 'false',
6552 - * multisite_user: 'true' or 'false',
6553 - * ),
6554 - * ...
6555 - * )
6556 - *
6557 - * @param array $users Users to edit.
6558 - * @param array $args Options (e.g., 'allow_wildcard_email' => true).
6559 - * @return array Sanitized users to edit.
6560 - */
6561 - private function sanitize_update_auth_users( $users = array(), $args = array() ) {
6562 - if ( ! is_array( $users ) ) {
6563 - $users = array();
6564 - }
6565 - if ( isset( $args['allow_wildcard_email'] ) && $args['allow_wildcard_email'] ) {
6566 - $users = array_map( array( $this, 'sanitize_update_auth_user_allow_wildcard_email' ), $users );
6567 - } else {
6568 - $users = array_map( array( $this, 'sanitize_update_auth_user' ), $users );
6569 - }
6570 5077
6571 - // Remove any entries that failed email address validation.
6572 - $users = array_filter( $users, array( $this, 'remove_invalid_auth_users' ) );
6573 -
6574 - return $users;
6575 - }
6576 -
6577 -
6578 5078 /**
6579 - * This array filter will remove any users who failed email address validation
6580 - * (which would set their email to a blank string).
6581 - * @param array $user User data to check for a valid email.
6582 - * @return bool Whether to filter out the user.
6583 - */
6584 - private function remove_invalid_auth_users( $user ) {
6585 - return isset( $user['email'] ) && strlen( $user['email'] ) > 0;
6586 - }
6587 -
6588 - /**
6589 - * Callback for array_map in sanitize_update_auth_users().
6590 - *
6591 - * @param array $user User data to sanitize.
6592 - * @return array Sanitized user data.
6593 - */
6594 - private function sanitize_update_auth_user( $user ) {
6595 - if ( array_key_exists( 'edit_action', $user ) ) {
6596 - $user['edit_action'] = sanitize_text_field( $user['edit_action'] );
6597 - }
6598 - if ( isset( $user['email'] ) ) {
6599 - $user['email'] = sanitize_email( $user['email'] );
6600 - }
6601 - if ( isset( $user['role'] ) ) {
6602 - $user['role'] = sanitize_text_field( $user['role'] );
6603 - }
6604 - if ( isset( $user['date_added'] ) ) {
6605 - $user['date_added'] = sanitize_text_field( $user['date_added'] );
6606 - }
6607 - if ( isset( $user['local_user'] ) ) {
6608 - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false';
6609 - }
6610 - if ( isset( $user['multisite_user'] ) ) {
6611 - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false';
6612 - }
6613 -
6614 - return $user;
6615 - }
6616 -
6617 -
6618 -
6619 - /**
6620 - * Callback for array_map in sanitize_update_auth_users().
6621 - *
6622 - * @param array $user User data to sanitize.
6623 - * @return array Sanitized user data.
6624 - */
6625 - private function sanitize_update_auth_user_allow_wildcard_email( $user ) {
6626 - if ( array_key_exists( 'edit_action', $user ) ) {
6627 - $user['edit_action'] = sanitize_text_field( $user['edit_action'] );
6628 - }
6629 - if ( isset( $user['email'] ) ) {
6630 - if ( strpos( $user['email'], '@' ) === 0 ) {
6631 - $user['email'] = sanitize_text_field( $user['email'] );
6632 - } else {
6633 - $user['email'] = sanitize_email( $user['email'] );
6634 - }
6635 - }
6636 - if ( isset( $user['role'] ) ) {
6637 - $user['role'] = sanitize_text_field( $user['role'] );
6638 - }
6639 - if ( isset( $user['date_added'] ) ) {
6640 - $user['date_added'] = sanitize_text_field( $user['date_added'] );
6641 - }
6642 - if ( isset( $user['local_user'] ) ) {
6643 - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false';
6644 - }
6645 - if ( isset( $user['multisite_user'] ) ) {
6646 - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false';
6647 - }
6648 -
6649 - return $user;
6650 - }
6651 -
6652 -
6653 -
6654 - /**
6655 5079 * ***************************
6656 5080 * Helper functions
6657 5081 * ***************************
6658 5082 */
@@ -6660,20 +5084,20 @@
6660 5084
6661 5085 /**
6662 5086 * Retrieves a specific plugin option from db. Multisite enabled.
6663 5087 *
6664 - * @param string $option Option name.
6665 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6666 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6667 - * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page.
6668 - * @return mixed Option value, or null on failure.
5088 + * @param string $option Option name
5089 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5090 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5091 + * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page
5092 + * @return mixed Option value, or null on failure
6669 5093 */
6670 - private function get_plugin_option( $option, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override', $print_mode = 'no overlay' ) {
5094 + private function get_plugin_option( $option, $admin_mode = SINGLE_ADMIN, $override_mode = 'no override', $print_mode = 'no overlay' ) {
6671 5095 // Special case for user lists (they are saved seperately to prevent concurrency issues).
6672 - if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
6673 - $list = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings_' . $option );
6674 - if ( is_multisite() && WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
6675 - $list = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_' . $option, array() );
5096 + if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
5097 + $list = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings_' . $option );
5098 + if ( is_multisite() && $admin_mode === MULTISITE_ADMIN ) {
5099 + $list = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_' . $option, array() );
6676 5100 }
6677 5101 return $list;
6678 5102 }
6679 5103
@@ -6687,26 +5111,24 @@
6687 5111
6688 5112 // If requested and appropriate, print the overlay hiding the
6689 5113 // single site option that is overridden by a multisite option.
6690 5114 if (
6691 - WP_Plugin_Authorizer::NETWORK_CONTEXT !== $admin_mode &&
6692 - 'allow override' === $override_mode &&
6693 - 'print overlay' === $print_mode &&
5115 + $admin_mode !== MULTISITE_ADMIN &&
5116 + $override_mode === 'allow override' &&
5117 + $print_mode === 'print overlay' &&
6694 5118 array_key_exists( 'multisite_override', $auth_settings ) &&
6695 - '1' === $auth_settings['multisite_override'] &&
6696 - ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) )
5119 + $auth_settings['multisite_override'] === '1' &&
5120 + ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' )
6697 5121 ) {
6698 5122 // Get original plugin options (not overridden value). We'll
6699 5123 // show this old value behind the disabled overlay.
6700 - // $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6701 - // (This feature is disabled).
6702 - //
5124 + $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
5125 +
6703 5126 $name = "auth_settings[$option]";
6704 - $id = "auth_settings_$option";
6705 - ?>
6706 - <div id="overlay-hide-auth_settings_<?php echo esc_attr( $option ); ?>" class="auth_multisite_override_overlay">
5127 + $id = "auth_settings_$option"; ?>
5128 + <div id="overlay-hide-auth_settings_<?php echo $option; ?>" class="auth_multisite_override_overlay">
6707 5129 <span class="overlay-note">
6708 - <?php esc_html_e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo esc_attr( network_admin_url( 'admin.php?page=authorizer' ) ); ?>"><?php esc_html_e( 'multisite option', 'authorizer' ); ?></a>.
5130 + <?php _e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo network_admin_url( 'admin.php?page=authorizer&tab=external' ); ?>"><?php _e( 'multisite option', 'authorizer' ); ?></a>.
6709 5131 </span>
6710 5132 </div>
6711 5133 <?php
6712 5134 }
@@ -6712,9 +5134,9 @@
6712 5134 }
6713 5135
6714 5136 // If we're getting an option in a site that has overridden the multisite override, make
6715 5137 // sure we are returning the option value from that site (not the multisite value).
6716 - if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && 1 === intval( $auth_settings['advanced_override_multisite'] ) ) {
5138 + if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && $auth_settings['advanced_override_multisite'] == '1' ) {
6717 5139 $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6718 5140 }
6719 5141
6720 5142 // Set option to null if it wasn't found.
@@ -6721,116 +5143,98 @@
6721 5143 if ( ! array_key_exists( $option, $auth_settings ) ) {
6722 5144 return null;
6723 5145 }
6724 5146
6725 - return $auth_settings[ $option ];
5147 + return $auth_settings[$option];
6726 5148 }
6727 5149
6728 5150 /**
6729 5151 * Retrieves all plugin options from db. Multisite enabled.
6730 5152 *
6731 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6732 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6733 - * @return mixed Option value, or null on failure.
5153 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5154 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5155 + * @return mixed Option value, or null on failure
6734 5156 */
6735 - private function get_plugin_options( $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override' ) {
6736 - // Grab plugin settings (skip if in WP_Plugin_Authorizer::NETWORK_CONTEXT mode).
6737 - $auth_settings = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings' );
5157 + private function get_plugin_options( $admin_mode = SINGLE_ADMIN, $override_mode = 'no override' ) {
5158 + // Grab plugin settings (skip if in MULTISITE_ADMIN mode).
5159 + $auth_settings = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings' );
6738 5160
6739 5161 // Initialize to default values if the plugin option doesn't exist.
6740 - if ( false === $auth_settings ) {
5162 + if ( $auth_settings === FALSE ) {
6741 5163 $auth_settings = $this->set_default_options();
6742 5164 }
6743 5165
6744 5166 // Merge multisite options if we're in a network and the current site hasn't overridden multisite settings.
6745 - if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) ) ) {
5167 + if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' ) ) {
6746 5168 // Get multisite options.
6747 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5169 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
6748 5170
6749 5171 // Return the multisite options if we're viewing the network admin options page.
6750 5172 // Otherwise override options with their multisite equivalents.
6751 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
5173 + if ( $admin_mode === MULTISITE_ADMIN ) {
6752 5174 $auth_settings = $auth_multisite_settings;
6753 5175 } elseif (
6754 - 'allow override' === $override_mode &&
5176 + $override_mode === 'allow override' &&
6755 5177 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
6756 - '1' === $auth_multisite_settings['multisite_override']
5178 + $auth_multisite_settings['multisite_override'] === '1'
6757 5179 ) {
6758 5180 // Keep track of the multisite override selection.
6759 5181 $auth_settings['multisite_override'] = $auth_multisite_settings['multisite_override'];
6760 5182
6761 - /**
6762 - * Note: the options below should be the complete list of overridden
6763 - * options. It is *not* the complete list of all options (some options
6764 - * don't have a multisite equivalent).
6765 - */
5183 + // Note: the options below should be the complete list of
5184 + // overridden options. It is *not* the complete list of all
5185 + // options (some options don't have a multisite equivalent)
6766 5186
6767 - /**
6768 - * Note: access_users_approved, access_users_pending, and
6769 - * access_users_blocked do not get overridden. However, since
6770 - * access_users_approved has a multisite equivalent, you must retrieve
6771 - * them both seperately. This is done because the two lists should be
6772 - * treated differently.
6773 - *
6774 - * $approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6775 - * $ms_approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
6776 - */
5187 + // Note: access_users_approved, access_users_pending, and
5188 + // access_users_blocked do not get overridden. However,
5189 + // since access_users_approved has a multisite equivalent,
5190 + // you must retrieve them both seperately. This is done
5191 + // because the two lists should be treated differently.
5192 + // $approved_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5193 + // $ms_approved_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
6777 5194
6778 - // Override external services (google, cas, or ldap) and associated options.
6779 - $auth_settings['google'] = $auth_multisite_settings['google'];
6780 - $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
6781 - $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
6782 - $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
6783 - $auth_settings['cas'] = $auth_multisite_settings['cas'];
6784 - $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
6785 - $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
6786 - $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
6787 - $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
6788 - $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
6789 - $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
6790 - $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
6791 - $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
6792 - $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
6793 - $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
6794 - $auth_settings['cas_link_on_username'] = $auth_multisite_settings['cas_link_on_username'];
6795 - $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
6796 - $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
6797 - $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
6798 - $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
6799 - $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
6800 - $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
6801 - $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
6802 - $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
6803 - $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
6804 - $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
6805 - $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
6806 - $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
5195 + // Override external services (google, cas, or ldap) and associated options
5196 + $auth_settings['google'] = $auth_multisite_settings['google'];
5197 + $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
5198 + $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
5199 + $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
5200 + $auth_settings['cas'] = $auth_multisite_settings['cas'];
5201 + $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
5202 + $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
5203 + $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
5204 + $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
5205 + $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
5206 + $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
5207 + $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
5208 + $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
5209 + $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
5210 + $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
5211 + $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
5212 + $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
5213 + $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
5214 + $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
5215 + $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
5216 + $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
5217 + $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
5218 + $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
5219 + $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
5220 + $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
5221 + $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
5222 + $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
6807 5223 $auth_settings['ldap_attr_update_on_login'] = $auth_multisite_settings['ldap_attr_update_on_login'];
6808 5224
6809 - // Override access_who_can_login and access_who_can_view.
5225 + // Override access_who_can_login and access_who_can_view
6810 5226 $auth_settings['access_who_can_login'] = $auth_multisite_settings['access_who_can_login'];
6811 - $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
5227 + $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
6812 5228
6813 - // Override access_default_role.
5229 + // Override access_default_role
6814 5230 $auth_settings['access_default_role'] = $auth_multisite_settings['access_default_role'];
6815 5231
6816 - // Override lockouts.
5232 + // Override lockouts
6817 5233 $auth_settings['advanced_lockouts'] = $auth_multisite_settings['advanced_lockouts'];
6818 5234
6819 - // Override Hide WordPress login.
5235 + // Override Hide WordPress login
6820 5236 $auth_settings['advanced_hide_wp_login'] = $auth_multisite_settings['advanced_hide_wp_login'];
6821 -
6822 - // Override Users per page.
6823 - $auth_settings['advanced_users_per_page'] = $auth_multisite_settings['advanced_users_per_page'];
6824 -
6825 - // Override Sort users by.
6826 - $auth_settings['advanced_users_sort_by'] = $auth_multisite_settings['advanced_users_sort_by'];
6827 -
6828 - // Override Sort users order.
6829 - $auth_settings['advanced_users_sort_order'] = $auth_multisite_settings['advanced_users_sort_order'];
6830 -
6831 - // Override Show Dashboard Widget.
6832 - $auth_settings['advanced_widget_enabled'] = $auth_multisite_settings['advanced_widget_enabled'];
6833 5237 }
6834 5238 }
6835 5239 return $auth_settings;
6836 5240 }
@@ -6837,27 +5241,23 @@
6837 5241
6838 5242
6839 5243 /**
6840 5244 * Remove user from authorizer lists when that user is deleted in WordPress.
6841 - *
6842 - * Action: delete_user
6843 - *
6844 - * @param int $user_id User ID to remove.
6845 - * @return void
5245 + * Run on action hook: delete_user
6846 5246 */
6847 - public function remove_user_from_authorizer_when_deleted( $user_id ) {
6848 - $user = get_user_by( 'id', $user_id );
5247 + function remove_user_from_authorizer_when_deleted( $user_id ) {
5248 + $user = get_user_by( 'id', $user_id );
6849 5249 $deleted_email = $user->user_email;
6850 5250
6851 5251 // Remove user from pending/approved lists and save.
6852 5252 $list_names = array( 'access_users_pending', 'access_users_approved' );
6853 5253 foreach ( $list_names as $list_name ) {
6854 - $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
5254 + $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, SINGLE_ADMIN ) );
6855 5255 $list_changed = false;
6856 5256 foreach ( $user_list as $key => $existing_user ) {
6857 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5257 + if ( $deleted_email === $existing_user['email'] ) {
6858 5258 $list_changed = true;
6859 - unset( $user_list[ $key ] );
5259 + unset( $user_list[$key] );
6860 5260 }
6861 5261 }
6862 5262 if ( $list_changed ) {
6863 5263 update_option( 'auth_settings_' . $list_name, $user_list );
@@ -6867,35 +5267,30 @@
6867 5267
6868 5268
6869 5269 /**
6870 5270 * Remove multisite user from authorizer lists when that user is deleted from Network Users.
6871 - *
6872 - * Action: wpmu_delete_user
6873 - *
6874 - * @param int $user_id User ID to remove.
6875 - * @return void
5271 + * Run on action hook: wpmu_delete_user
6876 5272 */
6877 - public function remove_network_user_from_authorizer_when_deleted( $user_id ) {
6878 - $user = get_user_by( 'id', $user_id );
5273 + function remove_network_user_from_authorizer_when_deleted( $user_id ) {
5274 + $user = get_user_by( 'id', $user_id );
6879 5275 $deleted_email = $user->user_email;
6880 5276
6881 5277 // Go through multisite approved user list and remove this user.
6882 5278 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6883 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5279 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6884 5280 );
6885 - $list_changed = false;
5281 + $list_changed = false;
6886 5282 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6887 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5283 + if ( $deleted_email === $existing_user['email'] ) {
6888 5284 $list_changed = true;
6889 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5285 + unset( $auth_multisite_settings_access_users_approved[$key] );
6890 5286 }
6891 5287 }
6892 5288 if ( $list_changed ) {
6893 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5289 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6894 5290 }
6895 5291
6896 5292 // Go through all pending/approved lists on individual sites and remove this user from them.
6897 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6898 5293 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6899 5294 foreach ( $sites as $site ) {
6900 5295 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6901 5296 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -6905,27 +5300,22 @@
6905 5300
6906 5301
6907 5302 /**
6908 5303 * Remove multisite user from a specific site's lists when that user is removed from the site.
6909 - *
6910 - * Action: remove_user_from_blog
6911 - *
6912 - * @param int $user_id User ID to remove.
6913 - * @param int $blog_id Blog ID to remove from.
6914 - * @return void
5304 + * Run on action hook: remove_user_from_blog
6915 5305 */
6916 - public function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
6917 - $user = get_user_by( 'id', $user_id );
5306 + function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
5307 + $user = get_user_by( 'id', $user_id );
6918 5308 $deleted_email = $user->user_email;
6919 5309
6920 5310 $list_names = array( 'access_users_pending', 'access_users_approved' );
6921 5311 foreach ( $list_names as $list_name ) {
6922 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
5312 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6923 5313 $list_changed = false;
6924 5314 foreach ( $user_list as $key => $existing_user ) {
6925 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5315 + if ( $deleted_email === $existing_user['email'] ) {
6926 5316 $list_changed = true;
6927 - unset( $user_list[ $key ] );
5317 + unset( $user_list[$key] );
6928 5318 }
6929 5319 }
6930 5320 if ( $list_changed ) {
6931 5321 update_blog_option( $blog_id, 'auth_settings_' . $list_name, $user_list );
@@ -6935,30 +5325,26 @@
6935 5325
6936 5326
6937 5327 /**
6938 5328 * Helper: Add multisite user to a specific site's approved list.
6939 - *
6940 - * @param int $user_id User ID to add.
6941 - * @param int $blog_id Blog ID to add to.
6942 - * @return void
6943 5329 */
6944 - private function add_network_user_to_site( $user_id, $blog_id ) {
5330 + function add_network_user_to_site( $user_id, $blog_id ) {
6945 5331 // Switch to blog.
6946 5332 switch_to_blog( $blog_id );
6947 5333
6948 5334 // Get user details and role.
6949 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
6950 - $user = get_user_by( 'id', $user_id );
6951 - $user_email = $user->user_email;
6952 - $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
5335 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
5336 + $user = get_user_by( 'id', $user_id );
5337 + $user_email = $user->user_email;
5338 + $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
6953 5339
6954 5340 // Add user to approved list if not already there and not in blocked list.
6955 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6956 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5341 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5342 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
6957 5343 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) && ! $this->in_multi_array( $user_email, $auth_settings_access_users_blocked ) ) {
6958 5344 $approved_user = array(
6959 - 'email' => $this->lowercase( $user_email ),
6960 - 'role' => $user_role,
5345 + 'email' => $user_email,
5346 + 'role' => $user_role,
6961 5347 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
6962 5348 'local_user' => true,
6963 5349 );
6964 5350 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -6975,17 +5361,17 @@
6975 5361 * When an existing user is invited to the current site (or a new user is created),
6976 5362 * add them to the authorizer approved list. This action fires when the admin
6977 5363 * doesn't select the "Skip Confirmation Email" option.
6978 5364 *
6979 - * Action: invite_user
5365 + * @action invite_user
6980 5366 *
6981 - * @param int $user_id The invited user's ID.
6982 - * @param array $role The role of the invited user (or none if a new user creation).
5367 + * @param int $user_id The invited user's ID.
5368 + * @param array $role The role of the invited user (or none if a new user creation).
6983 5369 * @param string $newuser_key The key of the invitation.
6984 5370 */
6985 - public function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
5371 + function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
6986 5372 $user = get_user_by( 'id', $user_id );
6987 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles, $role );
5373 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles, $role );
6988 5374 }
6989 5375
6990 5376
6991 5377 /**
@@ -6993,16 +5379,16 @@
6993 5379 * When an existing user is invited to the current site (or a new user is created),
6994 5380 * add them to the authorizer approved list. This action fires when the admin
6995 5381 * selects the "Skip Confirmation Email" option.
6996 5382 *
6997 - * Action: added_existing_user
5383 + * @action added_existing_user
6998 5384 *
6999 - * @param int $user_id The invited user's ID.
7000 - * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
5385 + * @param int $user_id The invited user's ID.
5386 + * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
7001 5387 */
7002 - public function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
5388 + function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
7003 5389 $user = get_user_by( 'id', $user_id );
7004 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5390 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
7005 5391 }
7006 5392
7007 5393
7008 5394 /**
@@ -7009,18 +5395,17 @@
7009 5395 * Multisite:
7010 5396 * When a new user is invited to the current site (or a new user is created),
7011 5397 * add them to the authorizer approved list.
7012 5398 *
7013 - * Action: after_signup_user
5399 + * @action after_signup_user
7014 5400 *
7015 - * @param string $user User's requested login name.
5401 + * @param string $user User's requested login name.
7016 5402 * @param string $user_email User's email address.
7017 - * @param string $key User's activation key.
7018 - * @param array $meta Additional signup meta, including initially set roles.
5403 + * @param string $key User's activation key.
5404 + * @param array $meta Additional signup meta.
7019 5405 */
7020 - public function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
7021 - $user_roles = isset( $meta['new_role'] ) ? array( $meta['new_role'] ) : array();
7022 - $this->add_user_to_authorizer_when_created( $user_email, time(), $user_roles );
5406 + function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
5407 + $this->add_user_to_authorizer_when_created( $user_email, time() );
7023 5408 }
7024 5409
7025 5410
7026 5411 /**
@@ -7027,18 +5412,17 @@
7027 5412 * Single site:
7028 5413 * When a new user is added in single site mode, add them to the authorizer
7029 5414 * approved list.
7030 5415 *
7031 - * Action: edit_user_created_user
5416 + * @action edit_user_created_user
7032 5417 *
7033 - * @param int $user_id ID of the newly created user.
7034 - * @param string $notify Type of notification that should happen. See
7035 - * wp_send_new_user_notifications() for more
7036 - * information on possible values.
5418 + * @param int $user_id ID of the newly created user.
5419 + * @param string $notify Type of notification that should happen. See wp_send_new_user_notifications()
5420 + * for more information on possible values.
7037 5421 */
7038 - public function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
5422 + function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
7039 5423 $user = get_user_by( 'id', $user_id );
7040 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5424 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
7041 5425 }
7042 5426
7043 5427
7044 5428 /**
@@ -7043,36 +5427,20 @@
7043 5427
7044 5428 /**
7045 5429 * Helper: When a new user is added/invited to the current site (or a new
7046 5430 * user is created), add them to the authorizer approved list.
7047 - *
7048 - * @param string $user_email Email address of user to add.
7049 - * @param string $date_registered Date user registered.
7050 - * @param array $user_roles Role to add for user.
7051 - * @param array $default_role Default role, if no role specified.
7052 5431 */
7053 5432 private function add_user_to_authorizer_when_created( $user_email, $date_registered, $user_roles = array(), $default_role = array() ) {
7054 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
7055 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7056 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7057 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5433 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
5434 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5435 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5436 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
7058 5437
7059 5438 // Get default role if one isn't specified.
7060 5439 if ( count( $default_role ) < 1 ) {
7061 5440 $default_role = '';
7062 5441 } else {
7063 - // If default role was provided, it came from the invite_user hook, and
7064 - // only contains the role's display name. Here we look up the actual role
7065 - // name to save (and default to no role if the display name isn't found).
7066 - global $wp_roles;
7067 - $default_role_display_name = $default_role['name'];
7068 - $default_role = '';
7069 - foreach ( $wp_roles->role_names as $role_name => $display_name ) {
7070 - if ( $default_role_display_name === $display_name ) {
7071 - $default_role = $role_name;
7072 - break;
7073 - }
7074 - }
5442 + $default_role = strtolower( $default_role['name'] );
7075 5443 }
7076 5444
7077 5445 $updated = false;
7078 5446
@@ -7081,10 +5449,10 @@
7081 5449 return;
7082 5450 }
7083 5451 // Remove from pending list if there.
7084 5452 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
7085 - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
7086 - unset( $auth_settings_access_users_pending[ $key ] );
5453 + if ( $pending_user['email'] == $user_email ) {
5454 + unset( $auth_settings_access_users_pending[$key] );
7087 5455 $updated = true;
7088 5456 }
7089 5457 }
7090 5458 // Skip if user is in multisite approved list.
@@ -7093,10 +5461,10 @@
7093 5461 }
7094 5462 // Add to approved list if not there.
7095 5463 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) ) {
7096 5464 $approved_user = array(
7097 - 'email' => $this->lowercase( $user_email ),
7098 - 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
5465 + 'email' => $user_email,
5466 + 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
7099 5467 'date_added' => date( 'M Y', strtotime( $date_registered ) ),
7100 5468 'local_user' => true,
7101 5469 );
7102 5470 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -7115,33 +5483,32 @@
7115 5483 * When a user is granted super admin status (checkbox on network user edit
7116 5484 * screen), add them to the authorizer network approved list. Also remove
7117 5485 * them from pending/approved list on any individual sites.
7118 5486 *
7119 - * Action: grant_super_admin
5487 + * @action grant_super_admin
7120 5488 *
7121 5489 * @param int $user_id The user's ID.
7122 5490 */
7123 - public function grant_super_admin__add_to_network_approved( $user_id ) {
7124 - $user = get_user_by( 'id', $user_id );
5491 + function grant_super_admin__add_to_network_approved( $user_id ) {
5492 + $user = get_user_by( 'id', $user_id );
7125 5493 $user_email = $user->user_email;
7126 5494
7127 5495 // Add user to multisite approved user list (if not already there).
7128 5496 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7129 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5497 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7130 5498 );
7131 5499 if ( ! $this->in_multi_array( $user_email, $auth_multisite_settings_access_users_approved ) ) {
7132 5500 $multisite_approved_user = array(
7133 - 'email' => $this->lowercase( $user_email ),
7134 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
5501 + 'email' => $user_email,
5502 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
7135 5503 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
7136 5504 'local_user' => true,
7137 5505 );
7138 5506 array_push( $auth_multisite_settings_access_users_approved, $multisite_approved_user );
7139 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5507 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7140 5508 }
7141 5509
7142 5510 // Go through all pending/approved lists on individual sites and remove this user from them.
7143 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7144 5511 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7145 5512 foreach ( $sites as $site ) {
7146 5513 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7147 5514 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -7154,29 +5521,29 @@
7154 5521 * When a user's super admin status is revoked (checkbox on network user edit
7155 5522 * screen), remove them from the authorizer network approved list. Also add
7156 5523 * them to approved list on any individual sites they are already a part of.
7157 5524 *
7158 - * Action: revoke_super_admin
5525 + * @action revoke_super_admin
7159 5526 *
7160 5527 * @param int $user_id The user's ID.
7161 5528 */
7162 - public function revoke_super_admin__remove_from_network_approved( $user_id ) {
7163 - $user = get_user_by( 'id', $user_id );
5529 + function revoke_super_admin__remove_from_network_approved( $user_id ) {
5530 + $user = get_user_by( 'id', $user_id );
7164 5531 $revoked_email = $user->user_email;
7165 5532
7166 5533 // Go through multisite approved user list and remove this user.
7167 5534 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7168 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5535 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7169 5536 );
7170 - $list_changed = false;
5537 + $list_changed = false;
7171 5538 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
7172 - if ( 0 === strcasecmp( $revoked_email, $existing_user['email'] ) ) {
5539 + if ( $revoked_email === $existing_user['email'] ) {
7173 5540 $list_changed = true;
7174 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5541 + unset( $auth_multisite_settings_access_users_approved[$key] );
7175 5542 }
7176 5543 }
7177 5544 if ( $list_changed ) {
7178 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5545 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7179 5546 }
7180 5547
7181 5548 // Go through this user's current sites and add them to the approved list
7182 5549 // (since they are no longer on the network approved list).
@@ -7187,21 +5554,14 @@
7187 5554 }
7188 5555
7189 5556 }
7190 5557
7191 - /**
7192 - * Send a welcome email message to a newly approved user (if the "Should
7193 - * email approved users" setting is enabled).
7194 - *
7195 - * @param string $email Email address to send welcome email to.
7196 - * @return bool Whether the email was sent.
7197 - */
7198 5558 private function maybe_email_welcome_message( $email ) {
7199 5559 // Get option for whether to email welcome messages.
7200 5560 $should_email_new_approved_users = $this->get_plugin_option( 'access_should_email_approved_users' );
7201 5561
7202 5562 // Do not send welcome email if option not enabled.
7203 - if ( '1' !== $should_email_new_approved_users ) {
5563 + if ( $should_email_new_approved_users !== '1' ) {
7204 5564 return false;
7205 5565 }
7206 5566
7207 5567 // Make sure we didn't just email this user (can happen with
@@ -7207,15 +5567,15 @@
7207 5567 // Make sure we didn't just email this user (can happen with
7208 5568 // multiple admins saving at the same time, or by clicking
7209 5569 // Approve button too rapidly).
7210 5570 $recently_sent_emails = get_option( 'auth_settings_recently_sent_emails' );
7211 - if ( false === $recently_sent_emails ) {
5571 + if ( $recently_sent_emails === FALSE ) {
7212 5572 $recently_sent_emails = array();
7213 5573 }
7214 5574 foreach ( $recently_sent_emails as $key => $recently_sent_email ) {
7215 5575 if ( $recently_sent_email['time'] < strtotime( 'now -1 minutes' ) ) {
7216 5576 // Remove emails sent more than 1 minute ago.
7217 - unset( $recently_sent_emails[ $key ] );
5577 + unset( $recently_sent_emails[$key] );
7218 5578 } elseif ( $recently_sent_email['email'] === $email ) {
7219 5579 // Sent an email to this user within the last 1 minute, so
7220 5580 // quit without sending.
7221 5581 return false;
@@ -7223,15 +5583,15 @@
7223 5583 }
7224 5584 // Add the email we're about to send to the list.
7225 5585 $recently_sent_emails[] = array(
7226 5586 'email' => $email,
7227 - 'time' => time(),
5587 + 'time' => time(),
7228 5588 );
7229 5589 update_option( 'auth_settings_recently_sent_emails', $recently_sent_emails );
7230 5590
7231 - // Get welcome email subject and body text.
5591 + // Get welcome email subject and body text
7232 5592 $subject = $this->get_plugin_option( 'access_email_approved_users_subject' );
7233 - $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
5593 + $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
7234 5594
7235 5595 // Fail if the subject/body options don't exist or are empty.
7236 5596 if ( is_null( $subject ) || is_null( $body ) || strlen( $subject ) === 0 || strlen( $body ) === 0 ) {
7237 5597 return false;
@@ -7238,14 +5598,14 @@
7238 5598 }
7239 5599
7240 5600 // Replace approved shortcode patterns in subject and body.
7241 5601 $site_name = get_bloginfo( 'name' );
7242 - $site_url = get_site_url();
7243 - $subject = str_replace( '[site_name]', $site_name, $subject );
7244 - $body = str_replace( '[site_name]', $site_name, $body );
7245 - $body = str_replace( '[site_url]', $site_url, $body );
7246 - $body = str_replace( '[user_email]', $email, $body );
7247 - $headers = 'Content-type: text/html' . "\r\n";
5602 + $site_url = get_site_url();
5603 + $subject = str_replace( '[site_name]', $site_name, $subject );
5604 + $body = str_replace( '[site_name]', $site_name, $body );
5605 + $body = str_replace( '[site_url]', $site_url, $body );
5606 + $body = str_replace( '[user_email]', $email, $body );
5607 + $headers = 'Content-type: text/html' . "\r\n";
7248 5608
7249 5609 // Send email.
7250 5610 wp_mail( $email, $subject, $body, $headers );
7251 5611
@@ -7255,22 +5615,14 @@
7255 5615
7256 5616
7257 5617 /**
7258 5618 * Generate a unique cookie to add to nonces to prevent CSRF.
7259 - *
7260 - * @var string
7261 5619 */
7262 - private $cookie_value = null;
7263 -
7264 - /**
7265 - * Retrieve the unique login cookie.
7266 - *
7267 - * @return string Login cookie value.
7268 - */
7269 - private function get_cookie_value() {
5620 + protected $cookie_value = null;
5621 + function get_cookie_value() {
7270 5622 if ( ! $this->cookie_value ) {
7271 5623 if ( isset( $_COOKIE['login_unique'] ) ) {
7272 - $this->cookie_value = sanitize_key( wp_unslash( $_COOKIE['login_unique'] ) );
5624 + $this->cookie_value = $_COOKIE['login_unique'];
7273 5625 } else {
7274 5626 $this->cookie_value = md5( rand() );
7275 5627 }
7276 5628 }
@@ -7278,51 +5630,37 @@
7278 5630 }
7279 5631
7280 5632
7281 5633 /**
7282 - * Encryption key (not secret!).
7283 - *
7284 - * @var string
7285 - */
7286 - private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
7287 -
7288 - /**
7289 - * Encryption salt (not secret!).
7290 - *
7291 - * @var string
7292 - */
7293 - private static $iv = 'R_O2D]jPn]1[fhJl!-P1.oe';
7294 -
7295 - /**
7296 5634 * Basic encryption using a public (not secret!) key. Used for general
7297 5635 * database obfuscation of passwords.
7298 - *
7299 - * @param string $text String to encrypt.
7300 - * @param string $library Encryption library to use (openssl).
7301 - * @return string Encrypted string.
5636 + * @param $text String to encrypt.
5637 + * @param $library Encryption lib to use (openssl).
5638 + * @return Encrypted string
7302 5639 */
7303 - private function encrypt( $text, $library = 'openssl' ) {
5640 + private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
5641 + private static $iv = "R_O2D]jPn]1[fhJl!-P1.oe";
5642 + function encrypt( $text, $library = 'openssl' ) {
7304 5643 $result = '';
7305 5644
7306 5645 // Use openssl library (better) if it is enabled.
7307 - if ( function_exists( 'openssl_encrypt' ) && 'openssl' === $library ) {
7308 - $result = base64_encode(
7309 - openssl_encrypt(
7310 - $text,
7311 - 'AES-256-CBC',
7312 - hash( 'sha256', self::$key ),
7313 - 0,
7314 - substr( hash( 'sha256', self::$iv ), 0, 16 )
7315 - )
7316 - );
7317 - } elseif ( function_exists( 'mcrypt_encrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5646 + if ( function_exists( 'openssl_encrypt' ) && $library === 'openssl' ) {
5647 + $result = base64_encode( openssl_encrypt(
5648 + $text,
5649 + 'AES-256-CBC',
5650 + hash( 'sha256', self::$key ),
5651 + 0,
5652 + substr( hash( 'sha256', self::$iv ), 0, 16 )
5653 + ) );
5654 + // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5655 + } else if ( function_exists( 'mcrypt_encrypt' ) ) {
7318 5656 $result = base64_encode( mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ) );
7319 - } else { // Fall back to basic obfuscation.
7320 - $length = strlen( $text );
7321 - for ( $i = 0; $i < $length; $i++ ) {
7322 - $char = substr( $text, $i, 1 );
5657 + // Fall back to basic obfuscation.
5658 + } else {
5659 + for ( $i = 0; $i < strlen( $text ); $i++ ) {
5660 + $char = substr( $text, $i, 1 );
7323 5661 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7324 - $char = chr( ord( $char ) + ord( $keychar ) );
5662 + $char = chr( ord( $char ) + ord( $keychar ) );
7325 5663 $result .= $char;
7326 5664 }
7327 5665 $result = base64_encode( $result );
7328 5666 }
@@ -7333,18 +5671,17 @@
7333 5671
7334 5672 /**
7335 5673 * Basic decryption using a public (not secret!) key. Used for general
7336 5674 * database obfuscation of passwords.
7337 - *
7338 - * @param string $secret String to encrypt.
7339 - * @param string $library Encryption lib to use (openssl).
7340 - * @return string Decrypted string
5675 + * @param $text String to encrypt.
5676 + * @param $library Encryption lib to use (openssl).
5677 + * @return Decrypted string
7341 5678 */
7342 - private function decrypt( $secret, $library = 'openssl' ) {
5679 + function decrypt( $secret, $library = 'openssl' ) {
7343 5680 $result = '';
7344 5681
7345 5682 // Use openssl library (better) if it is enabled.
7346 - if ( function_exists( 'openssl_decrypt' ) && 'openssl' === $library ) {
5683 + if ( function_exists( 'openssl_decrypt' ) && $library === 'openssl' ) {
7347 5684 $result = openssl_decrypt(
7348 5685 base64_decode( $secret ),
7349 5686 'AES-256-CBC',
7350 5687 hash( 'sha256', self::$key ),
@@ -7350,18 +5687,19 @@
7350 5687 hash( 'sha256', self::$key ),
7351 5688 0,
7352 5689 substr( hash( 'sha256', self::$iv ), 0, 16 )
7353 5690 );
7354 - } elseif ( function_exists( 'mcrypt_decrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5691 + // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5692 + } else if ( function_exists( 'mcrypt_decrypt' ) ) {
7355 5693 $secret = base64_decode( $secret );
7356 5694 $result = rtrim( mcrypt_decrypt( MCRYPT_RIJNDAEL_256, self::$key, $secret, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ), "\0$result" );
7357 - } else { // Fall back to basic obfuscation.
5695 + // Fall back to basic obfuscation.
5696 + } else {
7358 5697 $secret = base64_decode( $secret );
7359 - $length = strlen( $secret );
7360 - for ( $i = 0; $i < $length; $i++ ) {
7361 - $char = substr( $secret, $i, 1 );
5698 + for ( $i = 0; $i < strlen( $secret ); $i++ ) {
5699 + $char = substr( $secret, $i, 1 );
7362 5700 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7363 - $char = chr( ord( $char ) - ord( $keychar ) );
5701 + $char = chr( ord( $char ) - ord( $keychar ) );
7364 5702 $result .= $char;
7365 5703 }
7366 5704 }
7367 5705
@@ -7372,12 +5710,10 @@
7372 5710 /**
7373 5711 * In a multisite environment, returns true if the current user is logged
7374 5712 * in and a user of the current blog. In single site mode, simply returns
7375 5713 * true if the current user is logged in.
7376 - *
7377 - * @return bool Whether current user is logged in and a user of the current blog.
7378 5714 */
7379 - protected function is_user_logged_in_and_blog_user() {
5715 + function is_user_logged_in_and_blog_user() {
7380 5716 $is_user_logged_in_and_blog_user = false;
7381 5717 if ( is_multisite() ) {
7382 5718 $is_user_logged_in_and_blog_user = is_user_logged_in() && is_user_member_of_blog( get_current_user_id() );
7383 5719 } else {
@@ -7390,57 +5726,39 @@
7390 5726 /**
7391 5727 * Helper function to determine whether a given email is in one of
7392 5728 * the lists (pending, approved, blocked). Defaults to the list of
7393 5729 * approved users.
7394 - *
7395 - * @param string $email Email to check existent of.
7396 - * @param string $list List to look for email in.
7397 - * @param string $multisite_mode Admin context.
7398 - * @return boolean Whether email was found.
7399 5730 */
7400 - protected function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
7401 - if ( empty( $email ) ) {
5731 + function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
5732 + if ( empty( $email ) )
7402 5733 return false;
7403 - }
7404 5734
7405 5735 switch ( $list ) {
7406 - case 'pending':
7407 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7408 - return $this->in_multi_array( $email, $auth_settings_access_users_pending );
7409 - case 'blocked':
7410 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7411 - // Blocked list can have wildcard matches, e.g., @baddomain.com, which
7412 - // should match any email address at that domain. Check if any wildcards
7413 - // exist, and if the email address has that domain.
7414 - $email_in_blocked_domain = false;
7415 - $blocked_domains = preg_grep( '/^@.*/', array_map(
7416 - function ( $blocked_item ) { return $blocked_item['email']; },
7417 - $auth_settings_access_users_blocked
7418 - ) );
7419 - foreach ( $blocked_domains as $blocked_domain ) {
7420 - $email_domain = substr( $email, strrpos( $email, '@' ) );
7421 - if ( $email_domain === $blocked_domain ) {
7422 - $email_in_blocked_domain = true;
7423 - break;
7424 - }
7425 - }
7426 - return $email_in_blocked_domain || $this->in_multi_array( $email, $auth_settings_access_users_blocked );
7427 - case 'approved':
7428 - default:
7429 - if ( 'single' !== $multisite_mode ) {
7430 - // Get multisite users only.
7431 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7432 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7433 - // This site has overridden any multisite settings, so only get its users.
7434 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7435 - } else {
7436 - // Get all site users and all multisite users.
7437 - $auth_settings_access_users_approved = array_merge(
7438 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7439 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7440 - );
7441 - }
7442 - return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5736 + case 'pending':
5737 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5738 + return $this->in_multi_array( $email, $auth_settings_access_users_pending );
5739 + break;
5740 + case 'blocked':
5741 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5742 + return $this->in_multi_array( $email, $auth_settings_access_users_blocked );
5743 + break;
5744 + case 'approved':
5745 + default:
5746 + if ( $multisite_mode !== 'single' ) {
5747 + // Get multisite users only.
5748 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5749 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5750 + // This site has overridden any multisite settings, so only get its users.
5751 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5752 + } else {
5753 + // Get all site users and all multisite users.
5754 + $auth_settings_access_users_approved = array_merge(
5755 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5756 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5757 + );
5758 + }
5759 + return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5760 + break;
7443 5761 }
7444 5762 }
7445 5763
7446 5764
@@ -7446,37 +5764,36 @@
7446 5764
7447 5765 /**
7448 5766 * Helper function to get number of users (including multisite users)
7449 5767 * in a given list (pending, approved, or blocked).
7450 - *
7451 - * @param string $list List to get count of.
7452 - * @param string $admin_mode WP_Plugin_Authorizer::SINGLE_CONTEXT or WP_Plugin_Authorizer::NETWORK_CONTEXT determines whether to include multisite users.
7453 - * @return int Number of users in list.
5768 + * @param string $list
5769 + * @param string $admin_mode SINGLE_ADMIN or MULTISITE_ADMIN determines whether to include multisite users
5770 + * @return int number of users in list
7454 5771 */
7455 - protected function get_user_count_from_list( $list, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
5772 + function get_user_count_from_list( $list, $admin_mode = SINGLE_ADMIN ) {
7456 5773 $auth_settings_access_users = array();
7457 5774
7458 5775 switch ( $list ) {
7459 - case 'pending':
7460 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7461 - break;
7462 - case 'blocked':
7463 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7464 - break;
7465 - case 'approved':
7466 - if ( WP_Plugin_Authorizer::SINGLE_CONTEXT !== $admin_mode ) {
7467 - // Get multisite users only.
7468 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7469 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7470 - // This site has overridden any multisite settings, so only get its users.
7471 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7472 - } else {
7473 - // Get all site users and all multisite users.
7474 - $auth_settings_access_users = array_merge(
7475 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7476 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7477 - );
7478 - }
5776 + case 'pending':
5777 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5778 + break;
5779 + case 'blocked':
5780 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5781 + break;
5782 + case 'approved':
5783 + if ( $admin_mode !== SINGLE_ADMIN ) {
5784 + // Get multisite users only.
5785 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5786 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5787 + // This site has overridden any multisite settings, so only get its users.
5788 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5789 + } else {
5790 + // Get all site users and all multisite users.
5791 + $auth_settings_access_users = array_merge(
5792 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5793 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5794 + );
5795 + }
7479 5796 }
7480 5797
7481 5798 return count( $auth_settings_access_users );
7482 5799 }
@@ -7483,27 +5800,21 @@
7483 5800
7484 5801
7485 5802 /**
7486 5803 * Helper function to search a multidimensional array for a value.
7487 - *
7488 - * @param string $needle Value to search for.
7489 - * @param array $haystack Multidimensional array to search.
7490 - * @param string $strict_mode 'strict' if strict comparisons should be used.
7491 - * @param string $case_sensitivity 'case sensitive' if comparisons should respect case.
7492 - * @return bool Whether needle was found.
7493 5804 */
7494 - protected function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
5805 + function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
7495 5806 if ( ! is_array( $haystack ) ) {
7496 5807 return false;
7497 5808 }
7498 - if ( 'case insensitive' === $case_sensitivity ) {
5809 + if ( $case_sensitivity === 'case insensitive' ) {
7499 5810 $needle = strtolower( $needle );
7500 5811 }
7501 5812 foreach ( $haystack as $item ) {
7502 - if ( 'case insensitive' === $case_sensitivity && ! is_array( $item ) ) {
5813 + if ( $case_sensitivity === 'case insensitive' && ! is_array( $item ) ) {
7503 5814 $item = strtolower( $item );
7504 5815 }
7505 - if ( ( 'strict' === $strict_mode ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) { // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison
5816 + if ( ( $strict_mode === 'strict' ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) {
7506 5817 return true;
7507 5818 }
7508 5819 }
7509 5820 return false;
@@ -7512,29 +5823,28 @@
7512 5823
7513 5824 /**
7514 5825 * Helper function to determine if an URL is accessible.
7515 5826 *
7516 - * @param string $url URL that should be publicly reachable.
7517 - * @return boolean Whether the URL is publicly reachable.
5827 + * @param string $url URL that should be publicly reachable
5828 + * @return boolean Whether the URL is publicly reachable
7518 5829 */
7519 - protected function url_is_accessible( $url ) {
5830 + function url_is_accessible( $url ) {
7520 5831 // Use wp_remote_retrieve_response_code() to retrieve the URL.
7521 - $response = wp_remote_get( $url );
5832 + $response = wp_remote_get( $url );
7522 5833 $response_code = wp_remote_retrieve_response_code( $response );
7523 5834
7524 - // Return true if the document has loaded successfully without any redirection or error.
7525 - return $response_code >= 200 && $response_code < 400;
5835 + // Return true if the document has loaded successfully without any redirection or error
5836 + return $response_code >= 200 && $response_code < 300;
7526 5837 }
7527 5838
7528 5839
7529 5840 /**
7530 5841 * Helper function to reconstruct a URL split using parse_url().
7531 - *
7532 - * @param array $parts Array returned from parse_url().
7533 - * @return string URL.
5842 + * @param array $parts Array returned from parse_url().
5843 + * @return string URL.
7534 5844 */
7535 - protected function build_url( $parts = array() ) {
7536 - return (
5845 + function build_url( $parts = array() ) {
5846 + return
7537 5847 ( isset( $parts['scheme'] ) ? "{$parts['scheme']}:" : '' ) .
7538 5848 ( ( isset( $parts['user'] ) || isset( $parts['host'] ) ) ? '//' : '' ) .
7539 5849 ( isset( $parts['user'] ) ? "{$parts['user']}" : '' ) .
7540 5850 ( isset( $parts['pass'] ) ? ":{$parts['pass']}" : '' ) .
@@ -7542,30 +5852,21 @@
7542 5852 ( isset( $parts['host'] ) ? "{$parts['host']}" : '' ) .
7543 5853 ( isset( $parts['port'] ) ? ":{$parts['port']}" : '' ) .
7544 5854 ( isset( $parts['path'] ) ? "{$parts['path']}" : '' ) .
7545 5855 ( isset( $parts['query'] ) ? "?{$parts['query']}" : '' ) .
7546 - ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' )
7547 - );
5856 + ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' );
7548 5857 }
7549 5858
7550 5859
7551 - /**
7552 - * Helper function that prints option tags for a select element for all
7553 - * roles the current user has permission to assign.
7554 - *
7555 - * @param string $selected_role Which role should be selected in the dropdown.
7556 - * @param string $disable_input 'disabled' if select element should be disabled.
7557 - * @param int $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT if we are in that context.
7558 - * @return void
7559 - */
7560 - protected function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
7561 - $roles = get_editable_roles();
5860 + // Helper function that builds option tags for a select element for all
5861 + // roles the current user has permission to assign.
5862 + function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = SINGLE_ADMIN ) {
5863 + $roles = get_editable_roles();
7562 5864 $current_user = wp_get_current_user();
7563 5865
7564 5866 // If we're in network admin, also show any roles that might exist only on
7565 5867 // specific sites in the network (themes can add their own roles).
7566 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
7567 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
5868 + if ( $admin_mode === MULTISITE_ADMIN ) {
7568 5869 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7569 5870 foreach ( $sites as $site ) {
7570 5871 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7571 5872 switch_to_blog( $blog_id );
@@ -7574,11 +5875,11 @@
7574 5875 }
7575 5876 $unique_role_names = array();
7576 5877 foreach ( $roles as $role_name => $role_info ) {
7577 5878 if ( array_key_exists( $role_name, $unique_role_names ) ) {
7578 - unset( $roles[ $role_name ] );
5879 + unset( $roles[$role_name] );
7579 5880 } else {
7580 - $unique_role_names[ $role_name ] = true;
5881 + $unique_role_names[$role_name] = true;
7581 5882 }
7582 5883 }
7583 5884 }
7584 5885
@@ -7590,43 +5891,39 @@
7590 5891 }
7591 5892
7592 5893 // Print an option element for each permitted role.
7593 5894 foreach ( $roles as $name => $role ) {
7594 - $is_selected = $selected_role === $name;
5895 + $selected = $selected_role === $name ? ' selected="selected"' : '';
7595 5896
7596 - // Don't let a user change their own role (but network admins always can).
7597 - $is_disabled = $selected_role !== $name && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7598 - ?>
7599 - <option value="<?php echo esc_attr( $name ); ?>"<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php echo esc_html( $role['name'] ); ?></option>
7600 - <?php
5897 + // Don't let a user change their own role
5898 + $disabled = $selected_role !== $name && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5899 +
5900 + // But network admins can always change their role.
5901 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5902 + $disabled = '';
5903 + }
5904 +
5905 + ?><option value="<?php echo $name; ?>"<?php echo $selected . $disabled; ?>><?php echo $role['name']; ?></option><?php
7601 5906 }
7602 5907
7603 5908 // Print default role (no role).
7604 - $is_selected = strlen( $selected_role ) === 0 || ! array_key_exists( $selected_role, $roles );
7605 - $is_disabled = strlen( $selected_role ) > 0 && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7606 - ?>
7607 - <option value=""<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php esc_html_e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option>
7608 - <?php
5909 + $selected = strlen( $selected_role ) == 0 || ! array_key_exists( $selected_role, $roles ) ? ' selected="selected"' : '';
5910 + $disabled = strlen( $selected_role ) > 0 && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5911 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5912 + $disabled = '';
5913 + }
5914 + ?><option value=""<?php echo $selected . $disabled; ?>><?php _e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option><?php
7609 5915
7610 5916 }
7611 5917
7612 5918
7613 - /**
7614 - * Helper function to get a single user info array from one of the access
7615 - * control lists (pending, approved, or blocked).
7616 - *
7617 - * @param string $email Email address to retrieve info for.
7618 - * @param string $list List to get info from.
7619 - * @return mixed false if not found, otherwise: array(
7620 - * 'email' => '',
7621 - * 'role' => '',
7622 - * 'date_added' => '',
7623 - * ['usermeta' => [''|array()]]
7624 - * );
7625 - */
7626 - protected function get_user_info_from_list( $email, $list ) {
5919 + // Helper function to get a single user info array from one of the
5920 + // access control lists (pending, approved, or blocked).
5921 + // Returns: false if not found; otherwise
5922 + // array( 'email' => '', 'role' => '', 'date_added' => '', ['usermeta' => [''|array()]] );
5923 + function get_user_info_from_list( $email, $list ) {
7627 5924 foreach ( $list as $user_info ) {
7628 - if ( 0 === strcasecmp( $user_info['email'], $email ) ) {
5925 + if ( $user_info['email'] === $email ) {
7629 5926 return $user_info;
7630 5927 }
7631 5928 }
7632 5929 return false;
@@ -7631,49 +5928,29 @@
7631 5928 }
7632 5929 return false;
7633 5930 }
7634 5931
7635 - /**
7636 - * Helper function to convert a string to lowercase. Prefers to use mb_strtolower,
7637 - * but will fall back to strtolower if the former is not available.
7638 - *
7639 - * @param string $string String to convert to lowercase.
7640 - * @return string Input in lowercase.
7641 - */
7642 - protected function lowercase( $string ) {
7643 - return function_exists( 'mb_strtolower' ) ? mb_strtolower( $string ) : strtolower( $string );
7644 - }
7645 5932
7646 -
7647 - /**
7648 - * Helper function to convert seconds to human readable text.
7649 - *
7650 - * @see: http://csl.name/php-secs-to-human-text/
7651 - *
7652 - * @param int $secs Seconds to display as readable text.
7653 - * @return string Readable version of number of seconds.
7654 - */
7655 - protected function seconds_as_sentence( $secs ) {
5933 + // Helper function to convert seconds to human readable text.
5934 + // Source: http://csl.name/php-secs-to-human-text/
5935 + function seconds_as_sentence( $secs ) {
7656 5936 $units = array(
7657 - 'week' => 3600 * 24 * 7,
7658 - 'day' => 3600 * 24,
7659 - 'hour' => 3600,
7660 - 'minute' => 60,
7661 - 'second' => 1,
5937 + "week" => 7 * 24 * 3600,
5938 + "day" => 24 * 3600,
5939 + "hour" => 3600,
5940 + "minute" => 60,
5941 + "second" => 1,
7662 5942 );
7663 5943
7664 - // Specifically handle zero.
7665 - if ( 0 === intval( $secs ) ) {
7666 - return '0 seconds';
7667 - }
5944 + // specifically handle zero
5945 + if ( $secs == 0 ) return "0 seconds";
7668 5946
7669 - $s = '';
5947 + $s = "";
7670 5948
7671 5949 foreach ( $units as $name => $divisor ) {
7672 - $quot = intval( $secs / $divisor );
7673 - if ( $quot ) {
7674 - $s .= "$quot $name";
7675 - $s .= ( abs( $quot ) > 1 ? 's' : '' ) . ', ';
5950 + if ( $quot = intval( $secs / $divisor ) ) {
5951 + $s .= "$quot $name";
5952 + $s .= ( abs( $quot ) > 1 ? "s" : "" ) . ", ";
7676 5953 $secs -= $quot * $divisor;
7677 5954 }
7678 5955 }
7679 5956
@@ -7679,14 +5956,10 @@
7679 5956
7680 5957 return substr( $s, 0, -2 );
7681 5958 }
7682 5959
7683 - /**
7684 - * Helper function to get all available usermeta keys as an array.
7685 - *
7686 - * @return array All usermeta keys for user.
7687 - */
7688 - protected function get_all_usermeta_keys() {
5960 + // Helper function to get all available usermeta keys as an array.
5961 + function get_all_usermeta_keys() {
7689 5962 global $wpdb;
7690 5963 $usermeta_keys = $wpdb->get_col( "SELECT DISTINCT $wpdb->usermeta.meta_key FROM $wpdb->usermeta" );
7691 5964 return $usermeta_keys;
7692 5965 }
@@ -7693,12 +5966,10 @@
7693 5966
7694 5967
7695 5968 /**
7696 5969 * Load translated strings from *.mo files in /languages.
7697 - *
7698 - * Action: plugins_loaded
7699 5970 */
7700 - public function load_textdomain() {
5971 + function load_textdomain() {
7701 5972 load_plugin_textdomain(
7702 5973 'authorizer',
7703 5974 false,
7704 5975 plugin_basename( dirname( __FILE__ ) ) . '/languages'
@@ -7709,17 +5980,14 @@
7709 5980 /**
7710 5981 * Generate CAS authentication URL (wp-login.php URL with reauth=1 removed
7711 5982 * and external=cas added).
7712 5983 */
7713 - private function modify_current_url_for_cas_login() {
5984 + function modify_current_url_for_cas_login() {
7714 5985 // Construct the URL of the current page (wp-login.php).
7715 - $url = '';
7716 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
7717 - $url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
7718 - }
5986 + $url = 'http' . ( isset( $_SERVER['HTTPS'] ) ? 's' : '' ) . '://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
7719 5987
7720 5988 // Parse the URL into its components.
7721 - $parsed_url = wp_parse_url( $url );
5989 + $parsed_url = parse_url( $url );
7722 5990
7723 5991 // Fix up the querystring values (remove reauth, make sure external=cas).
7724 5992 $querystring = array();
7725 5993 if ( array_key_exists( 'query', $parsed_url ) ) {
@@ -7726,9 +5994,9 @@
7726 5994 parse_str( $parsed_url['query'], $querystring );
7727 5995 }
7728 5996 unset( $querystring['reauth'] );
7729 5997 $querystring['external'] = 'cas';
7730 - $parsed_url['query'] = http_build_query( $querystring );
5998 + $parsed_url['query'] = http_build_query( $querystring );
7731 5999
7732 6000 // Return the URL as a string.
7733 6001 return $this->unparse_url( $parsed_url );
7734 6002 }
@@ -7735,21 +6003,20 @@
7735 6003
7736 6004
7737 6005 /**
7738 6006 * Reconstruct a URL after it has been deconstructed with parse_url().
7739 - *
7740 - * @param array $parsed_url Keys from parse_url().
7741 - * @return string URL constructed from the components in $parsed_url.
6007 + * @param $parsed_url array() with keys from parse_url().
6008 + * @return string URL constructed from the components in $parsed_url.
7742 6009 */
7743 - protected function unparse_url( $parsed_url = array() ) {
7744 - $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
7745 - $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
7746 - $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
7747 - $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
7748 - $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
7749 - $pass = $user || $pass ? "$pass@" : '';
7750 - $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
7751 - $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
6010 + function unparse_url( $parsed_url = array() ) {
6011 + $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
6012 + $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
6013 + $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
6014 + $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
6015 + $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
6016 + $pass = $user || $pass ? "$pass@" : '';
6017 + $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
6018 + $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
7752 6019 $fragment = isset( $parsed_url['fragment'] ) ? '#' . $parsed_url['fragment'] : '';
7753 6020 return "$scheme$user$pass$host$port$path$query$fragment";
7754 6021 }
7755 6022
@@ -7754,30 +6021,15 @@
7754 6021 }
7755 6022
7756 6023
7757 6024 /**
7758 - * Helper function to generate an HTML class name for an option (used in
7759 - * Authorizer Settings in the Approved User list).
7760 - *
7761 - * @param string $suffix Unique part of class name.
7762 - * @param boolean $is_multisite_user Whether the class name should indicate it's a multisite user.
7763 - * @return string Class name, e.g., "auth-email auth-multisite-email".
7764 - */
7765 - private function create_class_name( $suffix = '', $is_multisite_user = false ) {
7766 - return $is_multisite_user ? "auth-$suffix auth-multisite-$suffix" : "auth-$suffix";
7767 - }
7768 -
7769 -
7770 - /**
7771 6025 * Plugin Update Routines.
7772 - *
7773 - * Action: plugins_loaded
7774 6026 */
7775 - public function auth_update_check() {
6027 + function auth_update_check() {
7776 6028 // Get current version.
7777 6029 $needs_updating = false;
7778 6030 if ( is_multisite() ) {
7779 - $auth_version = get_blog_option( $this->current_site_blog_id, 'auth_version' );
6031 + $auth_version = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_version' );
7780 6032 } else {
7781 6033 $auth_version = get_option( 'auth_version' );
7782 6034 }
7783 6035
@@ -7789,9 +6041,9 @@
7789 6041 // log in; approved and blocked lists are changed whenever an admin
7790 6042 // changes them from the multisite panel, the dashboard widget, or
7791 6043 // the plugin options page.
7792 6044 $update_if_older_than = 20140709;
7793 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6045 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7794 6046 // Copy single site user lists to new options (if they exist).
7795 6047 $auth_settings = get_option( 'auth_settings' );
7796 6048 if ( is_array( $auth_settings ) && array_key_exists( 'access_users_pending', $auth_settings ) ) {
7797 6049 update_option( 'auth_settings_access_users_pending', $auth_settings['access_users_pending'] );
@@ -7809,27 +6061,27 @@
7809 6061 update_option( 'auth_settings', $auth_settings );
7810 6062 }
7811 6063 // Copy multisite user lists to new options (if they exist).
7812 6064 if ( is_multisite() ) {
7813 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
6065 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7814 6066 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_pending', $auth_multisite_settings ) ) {
7815 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
6067 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
7816 6068 unset( $auth_multisite_settings['access_users_pending'] );
7817 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6069 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7818 6070 }
7819 6071 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_approved', $auth_multisite_settings ) ) {
7820 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
6072 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
7821 6073 unset( $auth_multisite_settings['access_users_approved'] );
7822 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6074 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7823 6075 }
7824 6076 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_blocked', $auth_multisite_settings ) ) {
7825 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
6077 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
7826 6078 unset( $auth_multisite_settings['access_users_blocked'] );
7827 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6079 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7828 6080 }
7829 6081 }
7830 6082 // Update version to reflect this change has been made.
7831 - $auth_version = $update_if_older_than;
6083 + $auth_version = $update_if_older_than;
7832 6084 $needs_updating = true;
7833 6085 }
7834 6086
7835 6087 // Update: Set default values for newly added options (forgot to do
@@ -7835,13 +6087,12 @@
7835 6087 // Update: Set default values for newly added options (forgot to do
7836 6088 // this, so some users are getting debug log notices about undefined
7837 6089 // indexes in $auth_settings).
7838 6090 $update_if_older_than = 20160831;
7839 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6091 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7840 6092 // Provide default values for any $auth_settings options that don't exist.
7841 6093 if ( is_multisite() ) {
7842 - // Get all blog ids.
7843 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6094 + // Get all blog ids
7844 6095 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7845 6096 foreach ( $sites as $site ) {
7846 6097 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7847 6098 switch_to_blog( $blog_id );
@@ -7846,9 +6097,9 @@
7846 6097 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7847 6098 switch_to_blog( $blog_id );
7848 6099 // Set meaningful defaults for other sites in the network.
7849 6100 $this->set_default_options();
7850 - // Switch back to original blog.
6101 + // Switch back to original blog. See: https://codex.wordpress.org/Function_Reference/restore_current_blog
7851 6102 restore_current_blog();
7852 6103 }
7853 6104 } else {
7854 6105 // Set meaningful defaults for this site.
@@ -7854,9 +6105,9 @@
7854 6105 // Set meaningful defaults for this site.
7855 6106 $this->set_default_options();
7856 6107 }
7857 6108 // Update version to reflect this change has been made.
7858 - $auth_version = $update_if_older_than;
6109 + $auth_version = $update_if_older_than;
7859 6110 $needs_updating = true;
7860 6111 }
7861 6112
7862 6113 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
@@ -7861,18 +6112,17 @@
7861 6112
7862 6113 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7863 6114 // deprecated as of PHP 7.1. Use openssl library instead.
7864 6115 $update_if_older_than = 20170510;
7865 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6116 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7866 6117 if ( is_multisite() ) {
7867 6118 // Reencrypt LDAP passwords in each site in the network.
7868 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7869 6119 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7870 6120 foreach ( $sites as $site ) {
7871 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6121 + $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7872 6122 $auth_settings = get_blog_option( $blog_id, 'auth_settings', array() );
7873 6123 if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7874 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
6124 + $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7875 6125 $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7876 6126 update_blog_option( $blog_id, 'auth_settings', $auth_settings );
7877 6127 }
7878 6128 }
@@ -7879,15 +6129,15 @@
7879 6129 } else {
7880 6130 // Reencrypt LDAP password on this single-site install.
7881 6131 $auth_settings = get_option( 'auth_settings', array() );
7882 6132 if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7883 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
6133 + $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7884 6134 $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7885 6135 update_option( 'auth_settings', $auth_settings );
7886 6136 }
7887 6137 }
7888 6138 // Update version to reflect this change has been made.
7889 - $auth_version = $update_if_older_than;
6139 + $auth_version = $update_if_older_than;
7890 6140 $needs_updating = true;
7891 6141 }
7892 6142
7893 6143 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
@@ -7893,192 +6143,35 @@
7893 6143 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7894 6144 // deprecated as of PHP 7.1. Use openssl library instead.
7895 6145 // Note: Forgot to update the auth_multisite_settings ldap password! Do it here.
7896 6146 $update_if_older_than = 20170511;
7897 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6147 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7898 6148 if ( is_multisite() ) {
7899 6149 // Reencrypt LDAP password in network (multisite) options.
7900 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
6150 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7901 6151 if ( array_key_exists( 'ldap_password', $auth_multisite_settings ) && strlen( $auth_multisite_settings['ldap_password'] ) > 0 ) {
7902 - $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
6152 + $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
7903 6153 $auth_multisite_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7904 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6154 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7905 6155 }
7906 6156 }
7907 6157 // Update version to reflect this change has been made.
7908 - $auth_version = $update_if_older_than;
6158 + $auth_version = $update_if_older_than;
7909 6159 $needs_updating = true;
7910 6160 }
7911 6161
7912 - // Update: Remove duplicates from approved list caused by authorizer_automatically_approve_login
7913 - // filter not respecting users who are already in the approved list
7914 - // (causing them to get re-added each time they logged in).
7915 - $update_if_older_than = 20170711;
7916 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7917 - // Remove duplicates from approved user lists.
7918 - if ( is_multisite() ) {
7919 - // Remove duplicates from each site in the multisite.
7920 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7921 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7922 - foreach ( $sites as $site ) {
7923 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7924 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
7925 - if ( is_array( $auth_settings_access_users_approved ) ) {
7926 - $should_update = false;
7927 - $distinct_emails = array();
7928 - foreach ( $auth_settings_access_users_approved as $key => $user ) {
7929 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7930 - $should_update = true;
7931 - unset( $auth_settings_access_users_approved[ $key ] );
7932 - } else {
7933 - $distinct_emails[] = $user['email'];
7934 - }
7935 - }
7936 - if ( $should_update ) {
7937 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
7938 - }
7939 - }
7940 - }
7941 - // Remove duplicates from multisite approved user list.
7942 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
7943 - if ( is_array( $auth_multisite_settings_access_users_approved ) ) {
7944 - $should_update = false;
7945 - $distinct_emails = array();
7946 - foreach ( $auth_multisite_settings_access_users_approved as $key => $user ) {
7947 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7948 - $should_update = true;
7949 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
7950 - } else {
7951 - $distinct_emails[] = $user['email'];
7952 - }
7953 - }
7954 - if ( $should_update ) {
7955 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7956 - }
7957 - }
7958 - } else {
7959 - // Remove duplicates from single site approved user list.
7960 - $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
7961 - if ( is_array( $auth_settings_access_users_approved ) ) {
7962 - $should_update = false;
7963 - $distinct_emails = array();
7964 - foreach ( $auth_settings_access_users_approved as $key => $user ) {
7965 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7966 - $should_update = true;
7967 - unset( $auth_settings_access_users_approved[ $key ] );
7968 - } else {
7969 - $distinct_emails[] = $user['email'];
7970 - }
7971 - }
7972 - if ( $should_update ) {
7973 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
7974 - }
7975 - }
7976 - }
7977 - // Update version to reflect this change has been made.
7978 - $auth_version = $update_if_older_than;
7979 - $needs_updating = true;
7980 - }
6162 + // // Update: TEMPLATE
6163 + // $update_if_older_than = YYYYMMDD;
6164 + // if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
6165 + // UPDATE CODE HERE
6166 + // // Update version to reflect this change has been made.
6167 + // $auth_version = $update_if_older_than;
6168 + // $needs_updating = true;
6169 + // }
7981 6170
7982 - // Update: Set default value for newly added option advanced_widget_enabled.
7983 - $update_if_older_than = 20171023;
7984 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7985 - // Provide default values for any $auth_settings options that don't exist.
7986 - if ( is_multisite() ) {
7987 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7988 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7989 - foreach ( $sites as $site ) {
7990 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7991 - switch_to_blog( $blog_id );
7992 - $this->set_default_options();
7993 - restore_current_blog();
7994 - }
7995 - } else {
7996 - $this->set_default_options();
7997 - }
7998 - // Update version to reflect this change has been made.
7999 - $auth_version = $update_if_older_than;
8000 - $needs_updating = true;
8001 - }
8002 -
8003 - // Update: Set default value for newly added option advanced_users_per_page.
8004 - $update_if_older_than = 20171215;
8005 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
8006 - // Provide default values for any $auth_settings options that don't exist.
8007 - if ( is_multisite() ) {
8008 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
8009 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
8010 - foreach ( $sites as $site ) {
8011 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
8012 - switch_to_blog( $blog_id );
8013 - $this->set_default_options();
8014 - restore_current_blog();
8015 - }
8016 - } else {
8017 - $this->set_default_options();
8018 - }
8019 - // Update version to reflect this change has been made.
8020 - $auth_version = $update_if_older_than;
8021 - $needs_updating = true;
8022 - }
8023 -
8024 - // Update: Set default value for newly added options advanced_users_sort_by and advanced_users_sort_order.
8025 - $update_if_older_than = 20171219;
8026 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
8027 - // Provide default values for any $auth_settings options that don't exist.
8028 - if ( is_multisite() ) {
8029 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
8030 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
8031 - foreach ( $sites as $site ) {
8032 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
8033 - switch_to_blog( $blog_id );
8034 - $this->set_default_options();
8035 - restore_current_blog();
8036 - }
8037 - } else {
8038 - $this->set_default_options();
8039 - }
8040 - // Update version to reflect this change has been made.
8041 - $auth_version = $update_if_older_than;
8042 - $needs_updating = true;
8043 - }
8044 -
8045 - // Update: Set default value for newly added option cas_link_on_username.
8046 - $update_if_older_than = 20190227;
8047 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
8048 - // Provide default values for any $auth_settings options that don't exist.
8049 - if ( is_multisite() ) {
8050 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
8051 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
8052 - foreach ( $sites as $site ) {
8053 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
8054 - switch_to_blog( $blog_id );
8055 - $this->set_default_options();
8056 - restore_current_blog();
8057 - }
8058 - } else {
8059 - $this->set_default_options();
8060 - }
8061 - // Update version to reflect this change has been made.
8062 - $auth_version = $update_if_older_than;
8063 - $needs_updating = true;
8064 - }
8065 -
8066 - /*
8067 - // Update: TEMPLATE
8068 - $update_if_older_than = YYYYMMDD;
8069 - if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
8070 - UPDATE CODE HERE
8071 - // Update version to reflect this change has been made.
8072 - $auth_version = $update_if_older_than;
8073 - $needs_updating = true;
8074 - }
8075 - */
8076 -
8077 6171 // Save new version number if we performed any updates.
8078 6172 if ( $needs_updating ) {
8079 6173 if ( is_multisite() ) {
8080 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
8081 6174 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
8082 6175 foreach ( $sites as $site ) {
8083 6176 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
8084 6177 update_blog_option( $blog_id, 'auth_version', $auth_version );