PluginProbe
Authorizer / 2.6.20
Authorizer v2.6.20
3.15.3 3.15.2 3.15.1 3.15.0 3.14.3 3.14.4 3.14.2 3.14.1 2.8.1 2.8.2 2.8.3 2.8.4 2.8.5 2.8.6 2.8.7 2.8.8 2.9.0 2.9.1 2.9.10 2.9.11 2.9.12 2.9.13 2.9.2 2.9.3 2.9.6 All 126 releases
← All changes | authorizer.php +2073 -3750 2.8.12.6.20 View file →
@@ -1,29 +1,49 @@
1 1 <?php
2 -/**
3 - * Plugin Name: Authorizer
4 - * Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
5 - * Author: Paul Ryan <prar@hawaii.edu>
6 - * Plugin URI: https://github.com/uhm-coe/authorizer
7 - * Text Domain: authorizer
8 - * Domain Path: /languages
9 - * License: GPL2
10 - * Version: 2.8.1
11 - *
12 - * @package authorizer
13 - */
2 +/*
3 +Plugin Name: Authorizer
4 +Plugin URI: https://github.com/uhm-coe/authorizer
5 +Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
6 +Version: 2.6.20
7 +Author: Paul Ryan
8 +Author URI: http://www.linkedin.com/in/paulrryan/
9 +Text Domain: authorizer
10 +Domain Path: /languages
11 +License: GPL2
12 +*/
14 13
15 -/**
16 - * Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
17 - * Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
18 - * Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
19 - */
20 14
21 -/**
22 - * Add phpCAS library if it's not included.
23 - *
24 - * @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
25 - */
15 +/*
16 +Copyright 2014 Paul Ryan (email: prar@hawaii.edu)
17 +
18 +This program is free software; you can redistribute it and/or modify
19 +it under the terms of the GNU General Public License, version 2, as
20 +published by the Free Software Foundation.
21 +
22 +This program is distributed in the hope that it will be useful,
23 +but WITHOUT ANY WARRANTY; without even the implied warranty of
24 +MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
25 +GNU General Public License for more details.
26 +
27 +You should have received a copy of the GNU General Public License
28 +along with this program; if not, write to the Free Software
29 +Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
30 +*/
31 +
32 +
33 +/*
34 +Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
35 +Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
36 +Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
37 +*/
38 +
39 +
40 +define( 'MULTISITE_ADMIN', 'multisite_admin' );
41 +define( 'SINGLE_ADMIN', 'single_admin' );
42 +
43 +
44 +// Add phpCAS library if it's not included.
45 +// @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
26 46 if ( ! defined( 'PHPCAS_VERSION' ) ) {
27 47 require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.5/CAS.php';
28 48 }
29 49
@@ -39,87 +59,18 @@
39 59 * @link http://hawaii.edu/coe/dcdc/wordpress/authorizer/doc/
40 60 */
41 61 class WP_Plugin_Authorizer {
42 62
43 - /**
44 - * Constants for determining our admin context (network or individual site).
45 - */
46 - const NETWORK_CONTEXT = 'multisite_admin';
47 - const SINGLE_CONTEXT = 'single_admin';
48 63
49 64 /**
50 - * Current site ID (Multisite).
51 - *
52 - * @var string
53 - */
54 - public $current_site_blog_id = 1;
55 -
56 - /**
57 - * HTML allowed when rendering translatable strings in the Authorizer UI.
58 - * This is passed to wp_kses() when sanitizing HMTL strings.
59 - *
60 - * @var array
61 - */
62 - private $allowed_html = array(
63 - 'a' => array(
64 - 'class' => array(),
65 - 'href' => array(),
66 - 'style' => array(),
67 - 'target' => array(),
68 - 'title' => array(),
69 - ),
70 - 'b' => array(),
71 - 'br' => array(),
72 - 'div' => array(
73 - 'class' => array(),
74 - ),
75 - 'em' => array(),
76 - 'hr' => array(),
77 - 'i' => array(),
78 - 'input' => array(
79 - 'aria-describedby' => array(),
80 - 'class' => array(),
81 - 'id' => array(),
82 - 'name' => array(),
83 - 'size' => array(),
84 - 'type' => array(),
85 - 'value' => array(),
86 - ),
87 - 'label' => array(
88 - 'class' => array(),
89 - 'for' => array(),
90 - ),
91 - 'p' => array(
92 - 'style' => array(),
93 - ),
94 - 'span' => array(
95 - 'aria-hidden' => array(),
96 - 'class' => array(),
97 - 'id' => array(),
98 - 'style' => array(),
99 - ),
100 - 'strong' => array(),
101 - );
102 -
103 - /**
104 65 * Constructor.
105 66 */
106 67 public function __construct() {
107 - // Save reference to current blog id in the network (support deprecated
108 - // constant BLOGID_CURRENT_SITE).
109 - if ( defined( 'BLOG_ID_CURRENT_SITE' ) ) {
110 - $this->current_site_blog_id = BLOG_ID_CURRENT_SITE;
111 - } elseif ( defined( 'BLOGID_CURRENT_SITE' ) ) { // deprecated.
112 - $this->current_site_blog_id = BLOGID_CURRENT_SITE;
113 - }
114 -
115 68 // Installation and uninstallation hooks.
116 69 register_activation_hook( __FILE__, array( $this, 'activate' ) );
117 70 register_deactivation_hook( __FILE__, array( $this, 'deactivate' ) );
118 71
119 - /**
120 - * Register filters.
121 - */
72 + // Register filters.
122 73
123 74 // Custom wp authentication routine using external service.
124 75 add_filter( 'authenticate', array( $this, 'custom_authenticate' ), 1, 3 );
125 76
@@ -125,9 +76,13 @@
125 76
126 77 // Custom logout action using external service.
127 78 add_action( 'wp_logout', array( $this, 'custom_logout' ) );
128 79
129 - // Create settings link on Plugins page.
80 + // Removing this bypasses Wordpress authentication (so if external auth fails,
81 + // no one can log in); with it enabled, it will run if external auth fails.
82 + //remove_filter('authenticate', 'wp_authenticate_username_password', 20, 3);
83 +
84 + // Create settings link on Plugins page
130 85 add_filter( 'plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'plugin_settings_link' ) );
131 86 add_filter( 'network_admin_plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'network_admin_plugin_settings_link' ) );
132 87
133 88 // Modify login page with a custom password url (if option is set).
@@ -138,11 +93,9 @@
138 93 if ( $error && strlen( $error ) > 0 ) {
139 94 add_filter( 'login_errors', array( $this, 'show_advanced_login_error' ) );
140 95 }
141 96
142 - /**
143 - * Register actions.
144 - */
97 + // Register actions.
145 98
146 99 // Enable localization. Translation files stored in /languages.
147 100 add_action( 'plugins_loaded', array( $this, 'load_textdomain' ) );
148 101
@@ -154,20 +107,18 @@
154 107
155 108 // Add users who successfully login to the approved list.
156 109 add_action( 'wp_login', array( $this, 'ensure_wordpress_user_in_approved_list_on_login' ), 10, 2 );
157 110
158 - // Create menu item in Settings.
111 + // Create menu item in Settings
159 112 add_action( 'admin_menu', array( $this, 'add_plugin_page' ) );
160 113
161 - // Create options page.
114 + // Create options page
162 115 add_action( 'admin_init', array( $this, 'page_init' ) );
163 116
164 117 // Update user role in approved list if it's changed in the WordPress edit user page.
165 - add_action( 'user_profile_update_errors', array( $this, 'edit_user_profile_update_role' ), 10, 3 );
118 + add_action( 'edit_user_profile_update', array( $this, 'edit_user_profile_update_role' ) );
119 + add_action( 'personal_options_update', array( $this, 'edit_user_profile_update_role' ) );
166 120
167 - // Update user email in approved list if it's changed in the WordPress edit user page.
168 - add_filter( 'send_email_change_email', array( $this, 'edit_user_profile_update_email' ), 10, 3 );
169 -
170 121 // Enqueue javascript and css on the plugin's options page, the
171 122 // dashboard (for the widget), and the network admin.
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
@@ -172,9 +123,9 @@
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
174 125 add_action( 'load-toplevel_page_authorizer', array( $this, 'load_options_page' ) );
175 126
176 - // Add custom css and js to wp-login.php.
127 + // Add custom css and js to wp-login.php
177 128 add_action( 'login_enqueue_scripts', array( $this, 'login_enqueue_scripts_and_styles' ) );
178 129 add_action( 'login_footer', array( $this, 'load_login_footer_js' ) );
179 130
180 131 // Create google nonce cookie when loading wp-login.php if Google is enabled.
@@ -179,9 +130,9 @@
179 130
180 131 // Create google nonce cookie when loading wp-login.php if Google is enabled.
181 132 add_action( 'login_init', array( $this, 'login_init__maybe_set_google_nonce_cookie' ) );
182 133
183 - // Modify login page with external auth links (if enabled; e.g., google or cas).
134 + // Modify login page with external auth links (if enabled; e.g., google or cas)
184 135 add_action( 'login_form', array( $this, 'login_form_add_external_service_links' ) );
185 136
186 137 // Redirect to CAS login when visiting login page (only if option is
187 138 // enabled, CAS is the only service, and WordPress logins are hidden).
@@ -190,28 +141,25 @@
190 141 // output is started (so the redirect header doesn't complain about data
191 142 // already being sent).
192 143 add_filter( 'wp_login_errors', array( $this, 'wp_login_errors__maybe_redirect_to_cas' ), 10, 2 );
193 144
194 - // Verify current user has access to page they are visiting.
145 + // Verify current user has access to page they are visiting
195 146 add_action( 'parse_request', array( $this, 'restrict_access' ), 9 );
196 147 add_action( 'init', array( $this, 'init__maybe_add_network_approved_user' ) );
197 148
198 - // AJAX: Save options from dashboard widget.
149 + // ajax save options from dashboard widget
199 150 add_action( 'wp_ajax_update_auth_user', array( $this, 'ajax_update_auth_user' ) );
200 151
201 - // AJAX: Save options from multisite options page.
152 + // ajax save options from multisite options page
202 153 add_action( 'wp_ajax_save_auth_multisite_settings', array( $this, 'ajax_save_auth_multisite_settings' ) );
203 154
204 - // AJAX: Save usermeta from options page.
155 + // ajax save usermeta from options page
205 156 add_action( 'wp_ajax_update_auth_usermeta', array( $this, 'ajax_update_auth_usermeta' ) );
206 157
207 - // AJAX: Verify google login.
158 + // ajax verify google login
208 159 add_action( 'wp_ajax_process_google_login', array( $this, 'ajax_process_google_login' ) );
209 160 add_action( 'wp_ajax_nopriv_process_google_login', array( $this, 'ajax_process_google_login' ) );
210 161
211 - // AJAX: Refresh approved user list.
212 - add_action( 'wp_ajax_refresh_approved_user_list', array( $this, 'ajax_refresh_approved_user_list' ) );
213 -
214 162 // Add dashboard widget so instructors can add/edit users with access.
215 163 // Hint: For Multisite Network Admin Dashboard use wp_network_dashboard_setup instead of wp_dashboard_setup.
216 164 add_action( 'wp_dashboard_setup', array( $this, 'add_dashboard_widgets' ) );
217 165
@@ -226,9 +174,9 @@
226 174 add_action( 'wp_enqueue_scripts', array( $this, 'auth_public_scripts' ), 20 );
227 175
228 176 // Multisite-specific actions.
229 177 if ( is_multisite() ) {
230 - // Add network admin options page (global settings for all sites).
178 + // Add network admin options page (global settings for all sites)
231 179 add_action( 'network_admin_menu', array( $this, 'network_admin_menu' ) );
232 180 }
233 181
234 182 // Remove user from authorizer lists when that user is deleted in WordPress.
@@ -267,21 +215,13 @@
267 215 */
268 216 public function activate() {
269 217 global $wpdb;
270 218
271 - // Nonce check.
272 - if (
273 - ! isset( $_REQUEST['_wpnonce'], $_REQUEST['plugin'] ) ||
274 - ! wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'activate-plugin_' . sanitize_text_field( wp_unslash( $_REQUEST['plugin'] ) ) )
275 - ) {
276 - die( '' );
277 - }
219 + // If we're in a multisite environment, run the plugin activation for each site when network enabling
220 + if ( is_multisite() && isset( $_GET['networkwide'] ) && $_GET['networkwide'] == 1 ) {
278 221
279 - // If we're in a multisite environment, run the plugin activation for each site when network enabling.
280 - if ( is_multisite() && isset( $_GET['networkwide'] ) && 1 === intval( $_GET['networkwide'] ) ) {
281 -
282 222 // Add super admins to the multisite approved list.
283 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
223 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() );
284 224 $should_update_auth_multisite_settings_access_users_approved = false;
285 225 foreach ( get_super_admins() as $super_admin ) {
286 226 $user = get_user_by( 'login', $super_admin );
287 227 // Add to approved list if not there.
@@ -286,10 +226,10 @@
286 226 $user = get_user_by( 'login', $super_admin );
287 227 // Add to approved list if not there.
288 228 if ( ! $this->in_multi_array( $user->user_email, $auth_multisite_settings_access_users_approved ) ) {
289 229 $approved_user = array(
290 - 'email' => $this->lowercase( $user->user_email ),
291 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
230 + 'email' => mb_strtolower( $user->user_email ),
231 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
292 232 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
293 233 'local_user' => true,
294 234 );
295 235 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
@@ -296,14 +236,13 @@
296 236 $should_update_auth_multisite_settings_access_users_approved = true;
297 237 }
298 238 }
299 239 if ( $should_update_auth_multisite_settings_access_users_approved ) {
300 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
240 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
301 241 }
302 242
303 243 // Run plugin activation on each site in the network.
304 244 $current_blog_id = $wpdb->blogid;
305 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
306 245 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
307 246 foreach ( $sites as $site ) {
308 247 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
309 248 switch_to_blog( $blog_id );
@@ -332,13 +271,13 @@
332 271 * @return void
333 272 */
334 273 private function add_wp_users_to_approved_list() {
335 274 // Add current WordPress users to the approved list.
336 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
337 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
338 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
339 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
340 - $updated = false;
275 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
276 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
277 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
278 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
279 + $updated = false;
341 280 foreach ( get_users() as $user ) {
342 281 // Skip if user is in blocked list.
343 282 if ( $this->in_multi_array( $user->user_email, $auth_settings_access_users_blocked ) ) {
344 283 continue;
@@ -345,9 +284,9 @@
345 284 }
346 285 // Remove from pending list if there.
347 286 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
348 287 if ( 0 === strcasecmp( $pending_user['email'], $user->user_email ) ) {
349 - unset( $auth_settings_access_users_pending[ $key ] );
288 + unset( $auth_settings_access_users_pending[$key] );
350 289 $updated = true;
351 290 }
352 291 }
353 292 // Skip if user is in multisite approved list.
@@ -356,10 +295,10 @@
356 295 }
357 296 // Add to approved list if not there.
358 297 if ( ! $this->in_multi_array( $user->user_email, $auth_settings_access_users_approved ) ) {
359 298 $approved_user = array(
360 - 'email' => $this->lowercase( $user->user_email ),
361 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
299 + 'email' => mb_strtolower( $user->user_email ),
300 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
362 301 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
363 302 'local_user' => true,
364 303 );
365 304 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -394,14 +333,13 @@
394 333
395 334 /**
396 335 * Authenticate against an external service.
397 336 *
398 - * Filter: authenticate
399 - *
400 - * @param WP_User $user user to authenticate.
337 + * @param WP_User $user user to authenticate
401 338 * @param string $username optional username to authenticate.
402 339 * @param string $password optional password to authenticate.
403 - * @return WP_User|WP_Error WP_User on success, WP_Error on failure.
340 + *
341 + * @return WP_User or WP_Error
404 342 */
405 343 public function custom_authenticate( $user, $username, $password ) {
406 344 // Pass through if already authenticated.
407 345 if ( is_a( $user, 'WP_User' ) ) {
@@ -409,20 +347,20 @@
409 347 } else {
410 348 $user = null;
411 349 }
412 350
413 - // If username and password are blank, this isn't a log in attempt.
351 + // If username and password are blank, this isn't a log in attempt
414 352 $is_login_attempt = strlen( $username ) > 0 && strlen( $password ) > 0;
415 353
416 354 // Check to make sure that $username is not locked out due to too
417 355 // many invalid login attempts. If it is, tell the user how much
418 356 // time remains until they can try again.
419 - $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
357 + $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
420 358 $unauthenticated_user_is_blocked = false;
421 - if ( $is_login_attempt && false !== $unauthenticated_user ) {
359 + if ( $is_login_attempt && $unauthenticated_user !== false ) {
422 360 $last_attempt = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
423 361 $num_attempts = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
424 - // Also check the auth_blocked user_meta flag (users in blocked list will get this flag).
362 + // Also check the auth_blocked user_meta flag (users in blocked list will get this flag)
425 363 $unauthenticated_user_is_blocked = get_user_meta( $unauthenticated_user->ID, 'auth_blocked', true ) === 'yes';
426 364 } else {
427 365 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
428 366 $num_attempts = get_option( 'auth_settings_advanced_lockouts_failed_attempts' );
@@ -436,9 +374,9 @@
436 374 return new WP_Error( 'empty_password', __( '<strong>ERROR</strong>: Incorrect username or password.', 'authorizer' ) );
437 375 }
438 376
439 377 // Grab plugin settings.
440 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
378 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
441 379
442 380 // Make sure $last_attempt (time) and $num_attempts are positive integers.
443 381 // Note: this addresses resetting them if either is unset from above.
444 382 $last_attempt = abs( intval( $last_attempt ) );
@@ -444,17 +382,17 @@
444 382 $last_attempt = abs( intval( $last_attempt ) );
445 383 $num_attempts = abs( intval( $num_attempts ) );
446 384
447 385 // Create semantic lockout variables.
448 - $lockouts = $auth_settings['advanced_lockouts'];
449 - $time_since_last_fail = time() - $last_attempt;
450 - $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds.
451 - $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
452 - $num_attempts_short_lockout = $lockouts['attempts_1'];
453 - $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
386 + $lockouts = $auth_settings['advanced_lockouts'];
387 + $time_since_last_fail = time() - $last_attempt;
388 + $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds
389 + $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
390 + $num_attempts_short_lockout = $lockouts['attempts_1'];
391 + $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
454 392 $seconds_remaining_short_lockout = $lockouts['duration_1'] * 60 - $time_since_last_fail;
455 393
456 - // Check if we need to institute a lockout delay.
394 + // Check if we need to institute a lockout delay
457 395 if ( $is_login_attempt && $time_since_last_fail > $reset_duration ) {
458 396 // Enough time has passed since the last invalid attempt and
459 397 // now that we can reset the failed attempt count, and let this
460 398 // login attempt go through.
@@ -467,9 +405,8 @@
467 405 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
468 406 return new WP_Error(
469 407 'empty_password',
470 408 sprintf(
471 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
472 409 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
473 410 $username,
474 411 $seconds_remaining_long_lockout,
475 412 $this->seconds_as_sentence( $seconds_remaining_long_lockout ),
@@ -484,9 +421,8 @@
484 421 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
485 422 return new WP_Error(
486 423 'empty_password',
487 424 sprintf(
488 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
489 425 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
490 426 $username,
491 427 $seconds_remaining_short_lockout,
492 428 $this->seconds_as_sentence( $seconds_remaining_short_lockout ),
@@ -496,16 +432,16 @@
496 432 }
497 433
498 434 // Start external authentication.
499 435 $externally_authenticated_emails = array();
500 - $authenticated_by = '';
501 - $result = null;
436 + $authenticated_by = '';
437 + $result = null;
502 438
503 439 // Try Google authentication if it's enabled and we don't have a
504 440 // successful login yet.
505 441 if (
506 - '1' === $auth_settings['google'] &&
507 - 0 === count( $externally_authenticated_emails ) &&
442 + $auth_settings['google'] === '1' &&
443 + count( $externally_authenticated_emails ) === 0 &&
508 444 ! is_wp_error( $result )
509 445 ) {
510 446 $result = $this->custom_authenticate_google( $auth_settings );
511 447 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -520,10 +456,10 @@
520 456
521 457 // Try CAS authentication if it's enabled and we don't have a
522 458 // successful login yet.
523 459 if (
524 - '1' === $auth_settings['cas'] &&
525 - 0 === count( $externally_authenticated_emails ) &&
460 + $auth_settings['cas'] === '1' &&
461 + count( $externally_authenticated_emails ) === 0 &&
526 462 ! is_wp_error( $result )
527 463 ) {
528 464 $result = $this->custom_authenticate_cas( $auth_settings );
529 465 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -538,10 +474,10 @@
538 474
539 475 // Try LDAP authentication if it's enabled and we don't have an
540 476 // authenticated user yet.
541 477 if (
542 - '1' === $auth_settings['ldap'] &&
543 - 0 === count( $externally_authenticated_emails ) &&
478 + $auth_settings['ldap'] === '1' &&
479 + count( $externally_authenticated_emails ) === 0 &&
544 480 ! is_wp_error( $result )
545 481 ) {
546 482 $result = $this->custom_authenticate_ldap( $auth_settings, $username, $password );
547 483 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -562,33 +498,31 @@
562 498
563 499 // Remove duplicate and blank emails, if any.
564 500 $externally_authenticated_emails = array_filter( array_unique( $externally_authenticated_emails ) );
565 501
566 - /**
567 - * If we've made it this far, we should have an externally
568 - * authenticated user. The following should be set:
569 - * $externally_authenticated_emails
570 - * $authenticated_by
571 - */
502 + // If we've made it this far, we should have an externally
503 + // authenticated user. The following should be set:
504 + // $externally_authenticated_emails
505 + // $authenticated_by
572 506
573 507 // Get the external user's WordPress account by email address.
574 508 foreach ( $externally_authenticated_emails as $externally_authenticated_email ) {
575 - $user = get_user_by( 'email', $this->lowercase( $externally_authenticated_email ) );
509 + $user = get_user_by( 'email', mb_strtolower( $externally_authenticated_email ) );
576 510
577 511 // If we've already found a WordPress user associated with one
578 512 // of the supplied email addresses, don't keep examining other
579 513 // email addresses associated with the externally authenticated user.
580 - if ( false !== $user ) {
514 + if ( $user !== FALSE ) {
581 515 break;
582 516 }
583 517 }
584 518
585 519 // Check this external user's access against the access lists
586 - // (pending, approved, blocked).
520 + // (pending, approved, blocked)
587 521 $result = $this->check_user_access( $user, $externally_authenticated_emails, $result );
588 522
589 523 // Fail with message if there was an error creating/adding the user.
590 - if ( is_wp_error( $result ) || 0 === $result ) {
524 + if ( is_wp_error( $result ) || $result === 0 ) {
591 525 return $result;
592 526 }
593 527
594 528 // If we created a new user in check_user_access(), log that user in.
@@ -609,27 +543,26 @@
609 543 /**
610 544 * This function will fail with a wp_die() message to the user if they
611 545 * don't have access.
612 546 *
613 - * @param WP_User $user User to check.
614 - * @param array $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account).
615 - * @param array $user_data Array of keys for email, username, first_name, last_name,
616 - * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
617 - * @return WP_Error|void|null|WP_User
618 - * WP_Error if there was an error on user creation / adding user to blog.
619 - * wp_die() if user does not have access.
620 - * null if user has access (success).
621 - * WP_User if user has access and a new account was created for them.
547 + * @param WP_User $user User to check
548 + * @param [type] $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account)
549 + * @param [type] $user_data Array of keys for email, username, first_name, last_name,
550 + * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
551 + * @return WP_Error if there was an error on user creation / adding user to blog
552 + * wp_die() if user does not have access
553 + * null if user has access (success)
554 + * WP_User if user has access and a new account was created for them
622 555 */
623 556 private function check_user_access( $user, $user_emails, $user_data = array() ) {
624 557 // Grab plugin settings.
625 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
626 - $auth_settings_access_users_pending = $this->sanitize_user_list(
627 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
558 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
559 + $auth_settings_access_users_pending = $this->sanitize_user_list(
560 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
628 561 );
629 - $auth_settings_access_users_approved_single = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
630 - $auth_settings_access_users_approved_multi = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
631 - $auth_settings_access_users_approved = $this->sanitize_user_list(
562 + $auth_settings_access_users_approved_single = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
563 + $auth_settings_access_users_approved_multi = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
564 + $auth_settings_access_users_approved = $this->sanitize_user_list(
632 565 array_merge(
633 566 $auth_settings_access_users_approved_single,
634 567 $auth_settings_access_users_approved_multi
635 568 )
@@ -641,9 +574,9 @@
641 574 *
642 575 * @param bool $allow_login Whether to block the currently logging in user.
643 576 * @param array $user_data User data returned from external service.
644 577 */
645 - $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
578 + $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
646 579 $blocked_by_filter = ! $allow_login; // Use this for better readability.
647 580
648 581 // Check our externally authenticated user against the block list.
649 582 // If any of their email addresses are blocked, set the relevant user
@@ -653,16 +586,14 @@
653 586
654 587 // Add user to blocked list if it was blocked via the filter.
655 588 if ( $blocked_by_filter && ! $this->is_email_in_list( $user_email, 'blocked' ) ) {
656 589 $auth_settings_access_users_blocked = $this->sanitize_user_list(
657 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
590 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
658 591 );
659 - array_push(
660 - $auth_settings_access_users_blocked, array(
661 - 'email' => $this->lowercase( $user_email ),
662 - 'date_added' => date( 'M Y' ),
663 - )
664 - );
592 + array_push( $auth_settings_access_users_blocked, array(
593 + 'email' => mb_strtolower( $user_email ),
594 + 'date_added' => date( 'M Y' ),
595 + ));
665 596 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
666 597 }
667 598
668 599 // If the blocked external user has a WordPress account, mark it as
@@ -671,11 +602,10 @@
671 602 update_user_meta( $user->ID, 'auth_blocked', 'yes' );
672 603 }
673 604
674 605 // Notify user about blocked status and return without authenticating them.
675 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
676 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
677 - $page_title = sprintf(
606 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
607 + $page_title = sprintf(
678 608 /* TRANSLATORS: %s: Name of blog */
679 609 __( '%s - Access Restricted', 'authorizer' ),
680 610 get_bloginfo( 'name' )
681 611 );
@@ -686,9 +616,9 @@
686 616 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
687 617 __( 'Back', 'authorizer' ) .
688 618 '</a></p>';
689 619 update_option( 'auth_settings_advanced_login_error', $error_message );
690 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
620 + wp_die( $error_message, $page_title );
691 621 }
692 622 }
693 623
694 624 // Get the default role for this user (or their current role, if they
@@ -698,9 +628,8 @@
698 628 * Filter the role of the user currently logging in. The role will be
699 629 * set to the default (specified in Authorizer options) for new users,
700 630 * or the user's current role for existing users. This filter allows
701 631 * changing user roles based on custom CAS/LDAP attributes.
702 - *
703 632 * @param bool $role Role of the user currently logging in.
704 633 * @param array $user_data User data returned from external service.
705 634 */
706 635 $approved_role = apply_filters( 'authorizer_custom_role', $default_role, $user_data );
@@ -735,9 +664,9 @@
735 664 // above, then add them to the approved list (they'll get an account
736 665 // created below if they don't have one yet).
737 666 if (
738 667 ! $this->is_email_in_list( $user_email, 'approved' ) &&
739 - ( 'external_users' === $auth_settings['access_who_can_login'] || $automatically_approve_login )
668 + ( $auth_settings['access_who_can_login'] === 'external_users' || $automatically_approve_login )
740 669 ) {
741 670 $is_newly_approved_user = true;
742 671
743 672 // If this user happens to be in the pending list (rare),
@@ -753,11 +682,11 @@
753 682 }
754 683
755 684 // Add this user to the approved list.
756 685 $approved_user = array(
757 - 'email' => $this->lowercase( $user_email ),
758 - 'role' => $approved_role,
759 - 'date_added' => date( 'Y-m-d H:i:s' ),
686 + 'email' => mb_strtolower( $user_email ),
687 + 'role' => $approved_role,
688 + 'date_added' => date( "Y-m-d H:i:s" ),
760 689 );
761 690 array_push( $auth_settings_access_users_approved, $approved_user );
762 691 array_push( $auth_settings_access_users_approved_single, $approved_user );
763 692 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
@@ -775,9 +704,9 @@
775 704 if ( $default_role !== $approved_role ) {
776 705 $user_info['role'] = $approved_role;
777 706 }
778 707
779 - // If the approved external user does not have a WordPress account, create it.
708 + // If the approved external user does not have a WordPress account, create it
780 709 if ( ! $user ) {
781 710 // If there's already a user with this username (e.g.,
782 711 // johndoe/johndoe@gmail.com exists, and we're trying to add
783 712 // johndoe/johndoe@example.com), use the full email address
@@ -792,47 +721,26 @@
792 721 $username = $user_info['email'];
793 722 }
794 723 $result = wp_insert_user(
795 724 array(
796 - 'user_login' => strtolower( $username ),
797 - 'user_pass' => wp_generate_password(), // random password.
798 - 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
799 - 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
800 - 'user_email' => $this->lowercase( $user_info['email'] ),
725 + 'user_login' => strtolower( $username ),
726 + 'user_pass' => wp_generate_password(), // random password
727 + 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
728 + 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
729 + 'user_email' => mb_strtolower( $user_info['email'] ),
801 730 'user_registered' => date( 'Y-m-d H:i:s' ),
802 - 'role' => $user_info['role'],
731 + 'role' => $user_info['role'],
803 732 )
804 733 );
805 734
806 735 // Fail with message if error.
807 - if ( is_wp_error( $result ) || 0 === $result ) {
736 + if ( is_wp_error( $result ) || $result === 0 ) {
808 737 return $result;
809 738 }
810 739
811 - // Authenticate as new user.
740 + // Authenticate as new user
812 741 $user = new WP_User( $result );
813 742
814 - /**
815 - * Fires after an external user is authenticated for the first time
816 - * and a new WordPress account is created for them.
817 - *
818 - * @since 2.8.0
819 - *
820 - * @param WP_User $user User object.
821 - * @param array $user_data User data from external service.
822 - *
823 - * Example $user_data:
824 - * array(
825 - * 'email' => 'user@example.edu',
826 - * 'username' => 'user',
827 - * 'first_name' => 'First',
828 - * 'last_name' => 'Last',
829 - * 'authenticated_by' => 'cas',
830 - * 'cas_attributes' => array( ... ),
831 - * );
832 - */
833 - do_action( 'authorizer_user_register', $user, $user_data );
834 -
835 743 // If multisite, iterate through all sites in the network and add the user
836 744 // currently logging in to any of them that have the user on the approved list.
837 745 // Note: this is useful for first-time logins--some users will have access
838 746 // to multiple sites, and this prevents them from having to log into each
@@ -838,21 +746,18 @@
838 746 // to multiple sites, and this prevents them from having to log into each
839 747 // site individually to get access.
840 748 if ( is_multisite() ) {
841 749 $site_ids_of_user = array_map(
842 - function ( $site_of_user ) {
843 - return intval( $site_of_user->userblog_id );
844 - },
750 + function ( $site_of_user ) { return $site_of_user->userblog_id; },
845 751 get_blogs_of_user( $user->ID )
846 752 );
847 753
848 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
849 754 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
850 755 foreach ( $sites as $site ) {
851 756 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
852 757
853 758 // Skip if user is already added to this site.
854 - if ( in_array( intval( $blog_id ), $site_ids_of_user, true ) ) {
759 + if ( in_array( $blog_id, $site_ids_of_user ) ) {
855 760 continue;
856 761 }
857 762
858 763 // Check if user is on the approved list of this site they are not added to.
@@ -878,9 +783,9 @@
878 783 if ( $meta_key === $user_info['usermeta']['meta_key'] ) {
879 784 // Update user's usermeta value for usermeta key stored in authorizer options.
880 785 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
881 786 // We have an ACF field value, so use the ACF function to update it.
882 - update_field( str_replace( 'acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
787 + update_field( str_replace('acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
883 788 } else {
884 789 // We have a normal usermeta value, so just update it via the WordPress function.
885 790 update_user_meta( $user->ID, $meta_key, $user_info['usermeta']['meta_value'] );
886 791 }
@@ -896,9 +801,9 @@
896 801 switch_to_blog( $blog_id );
897 802 // Update user's usermeta value for usermeta key stored in authorizer options.
898 803 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
899 804 // We have an ACF field value, so use the ACF function to update it.
900 - update_field( str_replace( 'acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
805 + update_field( str_replace('acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
901 806 } else {
902 807 // We have a normal usermeta value, so just update it via the WordPress function.
903 808 update_user_meta( $user->ID, $meta_key, $usermeta['meta_value'] );
904 809 }
@@ -909,24 +814,20 @@
909 814 }
910 815 } else {
911 816 // Update first/last names of WordPress user from external
912 817 // service if that option is set.
913 - if ( ( array_key_exists( 'authenticated_by', $user_data ) && 'cas' === $user_data['authenticated_by'] && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['cas_attr_update_on_login'] ) ) || ( array_key_exists( 'authenticated_by', $user_data ) && 'ldap' === $user_data['authenticated_by'] && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['ldap_attr_update_on_login'] ) ) ) {
914 - if ( array_key_exists( 'first_name', $user_data ) && 0 < strlen( $user_data['first_name'] ) ) {
915 - wp_update_user(
916 - array(
917 - 'ID' => $user->ID,
918 - 'first_name' => $user_data['first_name'],
919 - )
920 - );
818 + if ( ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'cas' && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && $auth_settings['cas_attr_update_on_login'] == 1 ) || ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'ldap' && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && $auth_settings['ldap_attr_update_on_login'] == 1 ) ) {
819 + if ( array_key_exists( 'first_name', $user_data ) && strlen( $user_data['first_name'] ) > 0 ) {
820 + wp_update_user( array(
821 + 'ID' => $user->ID,
822 + 'first_name' => $user_data['first_name'],
823 + ));
921 824 }
922 825 if ( array_key_exists( 'last_name', $user_data ) && strlen( $user_data['last_name'] ) > 0 ) {
923 - wp_update_user(
924 - array(
925 - 'ID' => $user->ID,
926 - 'last_name' => $user_data['last_name'],
927 - )
928 - );
826 + wp_update_user( array(
827 + 'ID' => $user->ID,
828 + 'last_name' => $user_data['last_name'],
829 + ));
929 830 }
930 831 }
931 832
932 833 // Update this user's role if it was modified in the
@@ -937,9 +838,9 @@
937 838
938 839 // Update user's role in this site's approved list and save.
939 840 foreach ( $auth_settings_access_users_approved_single as $key => $existing_user ) {
940 841 if ( 0 === strcasecmp( $user->user_email, $existing_user['email'] ) ) {
941 - $auth_settings_access_users_approved_single[ $key ]['role'] = $approved_role;
842 + $auth_settings_access_users_approved_single[$key]['role'] = $approved_role;
942 843 break;
943 844 }
944 845 }
945 846 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
@@ -956,34 +857,33 @@
956 857 }
957 858 }
958 859
959 860 // Ensure user has the same role as their entry in the approved list.
960 - if ( $user_info && ! in_array( $user_info['role'], $user->roles, true ) ) {
861 + // (This is just a precaution, the role should already be set when
862 + // saving admin options in the sanitizing function.)
863 + if ( $user_info && ! array_key_exists( $user_info['role'], $user->roles ) ) {
961 864 $user->set_role( $user_info['role'] );
962 865 }
963 866
964 867 return $user;
965 868
869 + // Note: only do this for the last email address we are checking (we need
870 + // to iterate through them all to make sure one of them isn't approved).
966 871 } elseif ( 0 === strcasecmp( $user_email, $last_email ) ) {
967 - /**
968 - * Note: only do this for the last email address we are checking (we need
969 - * to iterate through them all to make sure one of them isn't approved).
970 - */
971 -
972 872 // User isn't an admin, is not blocked, and is not approved.
973 873 // Add them to the pending list and notify them and their instructor.
974 874 if ( strlen( $user_email ) > 0 && ! $this->is_email_in_list( $user_email, 'pending' ) ) {
975 - $pending_user = array();
976 - $pending_user['email'] = $this->lowercase( $user_email );
977 - $pending_user['role'] = $approved_role;
875 + $pending_user = array();
876 + $pending_user['email'] = mb_strtolower( $user_email );
877 + $pending_user['role'] = $approved_role;
978 878 $pending_user['date_added'] = '';
979 879 array_push( $auth_settings_access_users_pending, $pending_user );
980 880 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
981 881
982 882 // Create strings used in the email notification.
983 - $site_name = get_bloginfo( 'name' );
984 - $site_url = get_bloginfo( 'url' );
985 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
883 + $site_name = get_bloginfo( 'name' );
884 + $site_url = get_bloginfo( 'url' );
885 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
986 886
987 887 // Notify users with the role specified in "Which role should
988 888 // receive email notifications about pending users?".
989 889 if ( strlen( $auth_settings['access_role_receive_pending_emails'] ) > 0 ) {
@@ -1008,11 +908,10 @@
1008 908 }
1009 909 }
1010 910
1011 911 // Notify user about pending status and return without authenticating them.
1012 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1013 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
1014 - $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
912 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
913 + $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
1015 914 $error_message =
1016 915 apply_filters( 'the_content', $auth_settings['access_pending_redirect_to_message'] ) .
1017 916 '<hr />' .
1018 917 '<p style="text-align: center;">' .
@@ -1019,9 +918,9 @@
1019 918 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
1020 919 __( 'Back', 'authorizer' ) .
1021 920 '</a></p>';
1022 921 update_option( 'auth_settings_advanced_login_error', $error_message );
1023 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
922 + wp_die( $error_message, $page_title );
1024 923 }
1025 924 }
1026 925
1027 926 // Sanity check: if we made it here without returning, something has gone wrong.
@@ -1044,34 +943,24 @@
1044 943 * custom_authenticate_google() runs to verify the token; once verified
1045 944 * custom_authenticate proceeds as normal with the google email address
1046 945 * as a successfully authenticated external user.
1047 946 *
1048 - * Action: wp_ajax_process_google_login
1049 - * Action: wp_ajax_nopriv_process_google_login
1050 - *
1051 - * @return void, but die with the value to return to the success() function in AJAX call signInCallback().
947 + * @return void, but die with the value to return to the success() function in AJAX call signInCallback()
1052 948 */
1053 - public function ajax_process_google_login() {
949 + function ajax_process_google_login() {
950 + $nonce = array_key_exists( 'nonce', $_POST ) ? $_POST['nonce'] : '';
951 + $code = array_key_exists( 'code', $_POST ) ? $_POST['code'] : null;
952 +
1054 953 // Nonce check.
1055 - if (
1056 - ! isset( $_POST['nonce'] ) ||
1057 - ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'google_csrf_nonce' )
1058 - ) {
1059 - die( '' );
954 + if ( ! wp_verify_nonce( $nonce, 'google_csrf_nonce' ) ) {
955 + return '';
1060 956 }
1061 957
1062 - // Google authentication token.
1063 - // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput.InputNotSanitized
1064 - $code = isset( $_POST['code'] ) ? wp_unslash( $_POST['code'] ) : null;
1065 -
1066 958 // Grab plugin settings.
1067 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
959 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1068 960
1069 - /**
1070 - * Add Google API PHP Client.
1071 - *
1072 - * @see https://github.com/google/google-api-php-client branch:v1-master
1073 - */
961 + // Add Google API PHP Client.
962 + // @see https://github.com/google/google-api-php-client branch:v1-master
1074 963 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1075 964
1076 965 // Build the Google Client.
1077 966 $client = new Google_Client();
@@ -1079,26 +968,19 @@
1079 968 $client->setClientId( $auth_settings['google_clientid'] );
1080 969 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1081 970 $client->setRedirectUri( 'postmessage' );
1082 971
1083 - /**
1084 - * If the hosted domain parameter is set, restrict logins to that domain.
1085 - *
1086 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1087 - * this to function server-side; it's not complete in v1, so this check
1088 - * is performed manually below.
1089 - *
1090 - * if (
1091 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1092 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1093 - * ) {
1094 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1095 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1096 - * $client->setHostedDomain( $google_hosteddomain );
1097 - * }
1098 - */
972 + // If the hosted domain parameter is set, restrict logins to that domain.
973 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
974 + // this to function server-side; it's not complete in v1, so this check
975 + // is performed manually below.
976 + // if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
977 + // $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
978 + // $google_hosteddomain = trim( $google_hosteddomains[0] );
979 + // $client->setHostedDomain( $google_hosteddomain );
980 + // }
1099 981
1100 - // Get one time use token (if it doesn't exist, we'll create one below).
982 + // Get one time use token (if it doesn't exist, we'll create one below)
1101 983 session_start();
1102 984 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1103 985
1104 986 if ( empty( $token ) ) {
@@ -1106,18 +988,18 @@
1106 988 $client->authenticate( $code );
1107 989 $token = json_decode( $client->getAccessToken() );
1108 990
1109 991 // Store the token in the session for later use.
1110 - $_SESSION['token'] = wp_json_encode( $token );
992 + $_SESSION['token'] = json_encode( $token );
1111 993
1112 - $response = 'Successfully authenticated.';
994 + $response = "Successfully authenticated.";
1113 995 } else {
1114 - $client->setAccessToken( wp_json_encode( $token ) );
996 + $client->setAccessToken( json_encode( $token ) );
1115 997
1116 998 $response = 'Already authenticated.';
1117 999 }
1118 1000
1119 - die( esc_html( $response ) );
1001 + die( $response );
1120 1002 }
1121 1003
1122 1004
1123 1005 /**
@@ -1122,22 +1004,22 @@
1122 1004
1123 1005 /**
1124 1006 * Validate this user's credentials against Google.
1125 1007 *
1126 - * @param array $auth_settings Plugin settings.
1127 - * @return array|WP_Error Array containing email, authenticated_by, first_name,
1128 - * last_name, and username strings for the successfully
1129 - * authenticated user, or WP_Error() object on failure,
1130 - * or null if not attempting a google login.
1008 + * @param array $auth_settings Plugin settings
1009 + * @return [mixed] Array containing email, authenticated_by,
1010 + * first_name, last_name, and username
1011 + * strings for the successfully authenticated
1012 + * user, or WP_Error() object on failure,
1013 + * or null if not attempting a google login.
1131 1014 */
1132 1015 private function custom_authenticate_google( $auth_settings ) {
1133 1016 // Move on if Google auth hasn't been requested here.
1134 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1135 - if ( empty( $_GET['external'] ) || 'google' !== $_GET['external'] ) {
1017 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'google' ) {
1136 1018 return null;
1137 1019 }
1138 1020
1139 - // Get one time use token.
1021 + // Get one time use token
1140 1022 session_start();
1141 1023 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1142 1024
1143 1025 // No token, so this is not a succesful Google login.
@@ -1144,13 +1026,10 @@
1144 1026 if ( is_null( $token ) ) {
1145 1027 return null;
1146 1028 }
1147 1029
1148 - /**
1149 - * Add Google API PHP Client.
1150 - *
1151 - * @see https://github.com/google/google-api-php-client branch:v1-master
1152 - */
1030 + // Add Google API PHP Client.
1031 + // @see https://github.com/google/google-api-php-client branch:v1-master
1153 1032 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1154 1033
1155 1034 // Build the Google Client.
1156 1035 $client = new Google_Client();
@@ -1158,24 +1037,19 @@
1158 1037 $client->setClientId( $auth_settings['google_clientid'] );
1159 1038 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1160 1039 $client->setRedirectUri( 'postmessage' );
1161 1040
1162 - /**
1163 - * If the hosted domain parameter is set, restrict logins to that domain.
1164 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1165 - * this to function server-side; it's not complete in v1, so this check
1166 - * is performed manually later.
1167 - * if (
1168 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1169 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1170 - * ) {
1171 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1172 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1173 - * $client->setHostedDomain( $google_hosteddomain );
1174 - * }
1175 - */
1041 + // If the hosted domain parameter is set, restrict logins to that domain.
1042 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1043 + // this to function server-side; it's not complete in v1, so this check
1044 + // is performed manually below.
1045 + // if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1046 + // $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1047 + // $google_hosteddomain = trim( $google_hosteddomains[0] );
1048 + // $client->setHostedDomain( $google_hosteddomain );
1049 + // }
1176 1050
1177 - // Verify this is a successful Google authentication.
1051 + // Verify this is a successful Google authentication
1178 1052 try {
1179 1053 $ticket = $client->verifyIdToken( $token->id_token, $auth_settings['google_clientid'] );
1180 1054 } catch ( Google_Auth_Exception $e ) {
1181 1055 // Invalid ticket, so this in not a successful Google login.
@@ -1186,29 +1060,25 @@
1186 1060 if ( ! $ticket ) {
1187 1061 return new WP_Error( 'invalid_google_login', __( 'Invalid Google credentials provided.', 'authorizer' ) );
1188 1062 }
1189 1063
1190 - // Get email address.
1191 - $attributes = $ticket->getAttributes();
1192 - $email = $this->lowercase( $attributes['payload']['email'] );
1064 + // Get email address
1065 + $attributes = $ticket->getAttributes();
1066 + $email = mb_strtolower( $attributes['payload']['email'] );
1193 1067 $email_domain = substr( strrchr( $email, '@' ), 1 );
1194 - $username = current( explode( '@', $email ) );
1068 + $username = current( explode( '@', $email ) );
1195 1069
1196 - /**
1197 - * Fail if hd param is set and the logging in user's email address doesn't
1198 - * match the allowed hosted domain.
1199 - *
1200 - * See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1201 - * See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1202 - *
1203 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1204 - * this to function server-side; it's not complete in v1, so this check
1205 - * is only performed here.
1206 - */
1070 + // Fail if hd param is set and the logging in user's email address doesn't
1071 + // match the allowed hosted domain.
1072 + // See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1073 + // See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1074 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1075 + // this to function server-side; it's not complete in v1, so this check
1076 + // is only performed here.
1207 1077 if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1208 1078 // Allow multiple whitelisted domains.
1209 1079 $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1210 - if ( ! in_array( $email_domain, $google_hosteddomains, true ) ) {
1080 + if ( ! in_array( $email_domain, $google_hosteddomains ) ) {
1211 1081 $this->custom_logout();
1212 1082 return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) );
1213 1083 }
1214 1084 }
@@ -1213,13 +1083,13 @@
1213 1083 }
1214 1084 }
1215 1085
1216 1086 return array(
1217 - 'email' => $email,
1218 - 'username' => $username,
1219 - 'first_name' => '',
1220 - 'last_name' => '',
1221 - 'authenticated_by' => 'google',
1087 + 'email' => $email,
1088 + 'username' => $username,
1089 + 'first_name' => '',
1090 + 'last_name' => '',
1091 + 'authenticated_by' => 'google',
1222 1092 'google_attributes' => $attributes,
1223 1093 );
1224 1094 }
1225 1095
@@ -1226,47 +1096,40 @@
1226 1096
1227 1097 /**
1228 1098 * Validate this user's credentials against CAS.
1229 1099 *
1230 - * @param array $auth_settings Plugin settings.
1231 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1232 - * for the successfully authenticated user, or WP_Error()
1233 - * object on failure, or null if not attempting a CAS login.
1100 + * @param array $auth_settings Plugin settings
1101 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1102 + * strings for the successfully authenticated
1103 + * user, or WP_Error() object on failure,
1104 + * or null if not attempting a CAS login.
1234 1105 */
1235 1106 private function custom_authenticate_cas( $auth_settings ) {
1236 1107 // Move on if CAS hasn't been requested here.
1237 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1238 - if ( empty( $_GET['external'] ) || 'cas' !== $_GET['external'] ) {
1108 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'cas' ) {
1239 1109 return null;
1240 1110 }
1241 1111
1242 - /**
1243 - * Get the CAS server version (default to SAML_VERSION_1_1).
1244 - *
1245 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1246 - */
1112 + // Get the CAS server version (default to SAML_VERSION_1_1).
1113 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1247 1114 $cas_version = SAML_VERSION_1_1;
1248 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1115 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1249 1116 $cas_version = CAS_VERSION_3_0;
1250 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1117 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1251 1118 $cas_version = CAS_VERSION_2_0;
1252 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1119 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1253 1120 $cas_version = CAS_VERSION_1_0;
1254 1121 }
1255 1122
1256 - // Set the CAS client configuration.
1123 + // Set the CAS client configuration
1257 1124 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1258 1125
1259 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1260 - // at an old CAS URL that redirects to a newer CAS URL).
1261 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1262 -
1263 1126 // Update server certificate bundle if it doesn't exist or is older
1264 1127 // than 6 months, then use it to ensure CAS server is legitimate.
1265 1128 // Note: only try to update if the system has the php_openssl extension.
1266 - $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1267 - $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1268 - $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds.
1129 + $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1130 + $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1131 + $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds
1269 1132 $time_180_days_ago = time() - $time_180_days;
1270 1133 if (
1271 1134 extension_loaded( 'openssl' ) &&
1272 1135 ( ! file_exists( $cacert_path ) || filemtime( $cacert_path ) < $time_180_days_ago )
@@ -1282,34 +1145,28 @@
1282 1145 }
1283 1146 $cacert_contents = $response['body'];
1284 1147
1285 1148 // Write out the updated certs to the plugin directory.
1286 - // Note: Don't use WP_Filesystem because we are not in an admin context
1287 - // and don't want to potentially prompt the end user for credentials.
1288 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_read_file_put_contents
1289 1149 file_put_contents( $cacert_path, $cacert_contents );
1290 1150 }
1291 1151 phpCAS::setCasServerCACert( $cacert_path );
1292 1152
1293 1153 // Set the CAS service URL (including the redirect URL for WordPress when it comes back from CAS).
1294 - $cas_service_url = site_url( '/wp-login.php?external=cas' );
1295 - $login_querystring = array();
1296 - if ( isset( $_SERVER['QUERY_STRING'] ) ) {
1297 - parse_str( wp_parse_url( esc_url_raw( wp_unslash( $_SERVER['QUERY_STRING'] ) ), PHP_URL_HOST ), $login_querystring );
1298 - }
1154 + $cas_service_url = site_url( '/wp-login.php?external=cas' );
1155 + $login_querystring = array(); parse_str( $_SERVER['QUERY_STRING'], $login_querystring );
1299 1156 if ( isset( $login_querystring['redirect_to'] ) ) {
1300 - $cas_service_url .= '&redirect_to=' . rawurlencode( $login_querystring['redirect_to'] );
1157 + $cas_service_url .= '&redirect_to=' . urlencode( $login_querystring['redirect_to'] );
1301 1158 }
1302 1159 phpCAS::setFixedServiceURL( $cas_service_url );
1303 1160
1304 - // Authenticate against CAS.
1161 + // Authenticate against CAS
1305 1162 try {
1306 1163 phpCAS::forceAuthentication();
1307 1164 } catch ( CAS_AuthenticationException $e ) {
1308 1165 // CAS server threw an error in isAuthenticated(), potentially because
1309 1166 // the cached ticket is outdated. Try renewing the authentication.
1310 - error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) ); // phpcs:ignore
1311 - error_log( print_r( $e, true ) ); // phpcs:ignore
1167 + error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) );
1168 + error_log( print_r( $e, true ) );
1312 1169
1313 1170 // CAS server is throwing errors on this login, so try logging the
1314 1171 // user out of CAS and redirecting them to the login page.
1315 1172 phpCAS::logoutWithRedirectService( wp_login_url() );
@@ -1324,10 +1181,10 @@
1324 1181 if ( ! filter_var( $externally_authenticated_email, FILTER_VALIDATE_EMAIL ) ) {
1325 1182 // If we can't get the user's email address from a CAS attribute,
1326 1183 // try to guess the domain from the CAS server hostname. This will only
1327 1184 // be used if we can't discover the email address from CAS attributes.
1328 - $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1329 - $externally_authenticated_email = $this->lowercase( $username ) . '@' . $domain_guess;
1185 + $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1186 + $externally_authenticated_email = mb_strtolower( $username ) . '@' . $domain_guess;
1330 1187 }
1331 1188
1332 1189 // Retrieve the user attributes (e.g., email address, first name, last name) from the CAS server.
1333 1190 $cas_attributes = phpCAS::getAttributes();
@@ -1338,45 +1195,41 @@
1338 1195 // email domain is manually entered there (instead of a reference to a
1339 1196 // CAS attribute), and combine that with the username to create the email.
1340 1197 // Otherwise, look up the CAS attribute for email.
1341 1198 if ( substr( $auth_settings['cas_attr_email'], 0, 1 ) === '@' ) {
1342 - $externally_authenticated_email = $this->lowercase( $username . $auth_settings['cas_attr_email'] );
1199 + $externally_authenticated_email = mb_strtolower( $username . $auth_settings['cas_attr_email'] );
1343 1200 } elseif (
1344 1201 // If a CAS attribute has been specified as containing the email address, use that instead.
1345 1202 // Email attribute can be a string or an array of strings.
1346 1203 array_key_exists( $auth_settings['cas_attr_email'], $cas_attributes ) && (
1347 1204 (
1348 - is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1349 - count( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1205 + is_array( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1206 + count( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1350 1207 ) || (
1351 - is_string( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1352 - strlen( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1208 + is_string( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1209 + strlen( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1353 1210 )
1354 1211 )
1355 1212 ) {
1356 1213 // Each of the emails in the array needs to be set to lowercase.
1357 - if ( is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) ) {
1358 - $externally_authenticated_email = array();
1359 - foreach ( $cas_attributes[ $auth_settings['cas_attr_email'] ] as $external_email ) {
1360 - $externally_authenticated_email[] = $this->lowercase( $external_email );
1361 - }
1362 - } else {
1363 - $externally_authenticated_email = $this->lowercase( $cas_attributes[ $auth_settings['cas_attr_email'] ] );
1214 + $externally_authenticated_email = array();
1215 + foreach ( $cas_attributes[$auth_settings['cas_attr_email']] as $external_email ) {
1216 + $externally_authenticated_email[] = mb_strtolower( $external_email );
1364 1217 }
1365 1218 }
1366 1219 }
1367 1220
1368 1221 // Get user first name and last name.
1369 - $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_first_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_first_name'] ] : '';
1370 - $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_last_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_last_name'] ] : '';
1222 + $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_first_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_first_name']] : '';
1223 + $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_last_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_last_name']] : '';
1371 1224
1372 1225 return array(
1373 - 'email' => $externally_authenticated_email,
1374 - 'username' => $username,
1375 - 'first_name' => $first_name,
1376 - 'last_name' => $last_name,
1226 + 'email' => $externally_authenticated_email,
1227 + 'username' => $username,
1228 + 'first_name' => $first_name,
1229 + 'last_name' => $last_name,
1377 1230 'authenticated_by' => 'cas',
1378 - 'cas_attributes' => $cas_attributes,
1231 + 'cas_attributes' => $cas_attributes,
1379 1232 );
1380 1233 }
1381 1234
1382 1235
@@ -1382,32 +1235,24 @@
1382 1235
1383 1236 /**
1384 1237 * Validate this user's credentials against LDAP.
1385 1238 *
1386 - * @param array $auth_settings Plugin settings.
1387 - * @param string $username Attempted username from authenticate action.
1388 - * @param string $password Attempted password from authenticate action.
1389 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1390 - * for the successfully authenticated user, or WP_Error()
1391 - * object on failure, or null if skipping LDAP auth and
1392 - * falling back to WP auth.
1239 + * @param array $auth_settings Plugin settings
1240 + * @param string $username Attempted username from authenticate action
1241 + * @param string $password Attempted password from authenticate action
1242 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1243 + * strings for the successfully authenticated
1244 + * user, or WP_Error() object on failure,
1245 + * or null if skipping LDAP auth and falling back to WP auth.
1393 1246 */
1394 1247 private function custom_authenticate_ldap( $auth_settings, $username, $password ) {
1395 - // Get LDAP search base(s).
1396 - $search_bases = explode( "\n", str_replace( "\r", '', trim( $auth_settings['ldap_search_base'] ) ) );
1397 -
1398 - // Fail silently (fall back to WordPress authentication) if no search base specified.
1399 - if ( count( $search_bases ) < 1 ) {
1400 - return null;
1401 - }
1402 -
1403 - // Get the FQDN from the first LDAP search base domain components (dc). For
1404 - // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk.
1405 - $search_base_components = explode( ',', trim( $search_bases[0] ) );
1406 - $domain = array();
1248 + // Get the FQDN from the LDAP search base domain components (dc). For
1249 + // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk
1250 + $search_base_components = explode( ',', trim( $auth_settings['ldap_search_base'] ) );
1251 + $domain = array();
1407 1252 foreach ( $search_base_components as $search_base_component ) {
1408 1253 $component = explode( '=', $search_base_component );
1409 - if ( 2 === count( $component ) && 'dc' === $component[0] ) {
1254 + if ( count( $component ) === 2 && $component[0] === 'dc' ) {
1410 1255 $domain[] = $component[1];
1411 1256 }
1412 1257 }
1413 1258 $domain = implode( '.', $domain );
@@ -1418,9 +1263,9 @@
1418 1263 if ( empty( $domain ) ) {
1419 1264 $domain = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['ldap_host'], $matches ) === 1 ? $matches[0] : '';
1420 1265 }
1421 1266
1422 - // remove @domain if it exists in the username (i.e., if user entered their email).
1267 + // remove @domain if it exists in the username (i.e., if user entered their email)
1423 1268 $username = str_replace( '@' . $domain, '', $username );
1424 1269
1425 1270 // Fail silently (fall back to WordPress authentication) if both username
1426 1271 // and password are empty (this will be the case when visiting wp-login.php
@@ -1443,13 +1288,13 @@
1443 1288 return null;
1444 1289 }
1445 1290
1446 1291 // Authenticate against LDAP using options provided in plugin settings.
1447 - $result = false;
1292 + $result = false;
1448 1293 $ldap_user_dn = '';
1449 - $first_name = '';
1450 - $last_name = '';
1451 - $email = '';
1294 + $first_name = '';
1295 + $last_name = '';
1296 + $email = '';
1452 1297
1453 1298 // Construct LDAP connection parameters. ldap_connect() takes either a
1454 1299 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1455 1300 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
@@ -1454,13 +1299,13 @@
1454 1299 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1455 1300 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
1456 1301 // ignored, and port must be specified in the full URI. An LDAP URI is of
1457 1302 // the form ldap://hostname:port or ldaps://hostname:port.
1458 - $ldap_host = $auth_settings['ldap_host'];
1459 - $ldap_port = intval( $auth_settings['ldap_port'] );
1460 - $parsed_host = wp_parse_url( $ldap_host );
1303 + $ldap_host = $auth_settings['ldap_host'];
1304 + $ldap_port = intval( $auth_settings['ldap_port'] );
1305 + $parsed_host = parse_url( $ldap_host );
1461 1306 // Fail (fall back to WordPress auth) if invalid host is specified.
1462 - if ( false === $parsed_host ) {
1307 + if ( $parsed_host === false ) {
1463 1308 return null;
1464 1309 }
1465 1310 // If a scheme is in the LDAP host, use full LDAP URI instead of just hostname.
1466 1311 if ( array_key_exists( 'scheme', $parsed_host ) ) {
@@ -1473,24 +1318,24 @@
1473 1318
1474 1319 // Establish LDAP connection.
1475 1320 $ldap = ldap_connect( $ldap_host, $ldap_port );
1476 1321 ldap_set_option( $ldap, LDAP_OPT_PROTOCOL_VERSION, 3 );
1477 - if ( 1 === intval( $auth_settings['ldap_tls'] ) ) {
1478 - if ( ! ldap_start_tls( $ldap ) ) {
1322 + if ( $auth_settings['ldap_tls'] == 1 ) {
1323 + if( ! ldap_start_tls( $ldap ) ) {
1479 1324 return null;
1480 1325 }
1481 1326 }
1482 1327
1483 1328 // Set bind credentials; attempt an anonymous bind if not provided.
1484 - $bind_rdn = null;
1485 - $bind_password = null;
1329 + $bind_rdn = NULL;
1330 + $bind_password = NULL;
1486 1331 if ( strlen( $auth_settings['ldap_user'] ) > 0 ) {
1487 - $bind_rdn = $auth_settings['ldap_user'];
1332 + $bind_rdn = $auth_settings['ldap_user'];
1488 1333 $bind_password = $this->decrypt( $auth_settings['ldap_password'] );
1489 1334 }
1490 1335
1491 1336 // Attempt LDAP bind.
1492 - $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) ); // phpcs:ignore
1337 + $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) );
1493 1338 if ( ! $result ) {
1494 1339 // Can't connect to LDAP, so fall back to WordPress authentication.
1495 1340 return null;
1496 1341 }
@@ -1504,40 +1349,18 @@
1504 1349 if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 ) {
1505 1350 array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_last_name'] );
1506 1351 }
1507 1352 if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 && substr( $auth_settings['ldap_attr_email'], 0, 1 ) !== '@' ) {
1508 - array_push( $ldap_attributes_to_retrieve, $this->lowercase( $auth_settings['ldap_attr_email'] ) );
1353 + array_push( $ldap_attributes_to_retrieve, mb_strtolower( $auth_settings['ldap_attr_email'] ) );
1509 1354 }
1355 + $ldap_search = ldap_search(
1356 + $ldap,
1357 + $auth_settings['ldap_search_base'],
1358 + "(" . $auth_settings['ldap_uid'] . "=" . $username . ")",
1359 + $ldap_attributes_to_retrieve
1360 + );
1361 + $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1510 1362
1511 - // Create default LDAP search filter (uid=$username).
1512 - $search_filter = '(' . $auth_settings['ldap_uid'] . '=' . $username . ')';
1513 -
1514 - /**
1515 - * Filter LDAP search filter.
1516 - *
1517 - * Allows for custom LDAP authentication rules (e.g., restricting login
1518 - * access to users in multiple groups, or having certain attributes).
1519 - *
1520 - * @param string $search_filter The filter to pass to ldap_search().
1521 - * @param string $ldap_uid The attribute to compare username against (from Authorizer Settings).
1522 - * @param string $username The username attempting to log in.
1523 - */
1524 - $search_filter = apply_filters( 'authorizer_ldap_search_filter', $search_filter, $auth_settings['ldap_uid'], $username );
1525 -
1526 - // Multiple search bases can be provided, so iterate through them until a match is found.
1527 - foreach ( $search_bases as $search_base ) {
1528 - $ldap_search = ldap_search(
1529 - $ldap,
1530 - $search_base,
1531 - $search_filter,
1532 - $ldap_attributes_to_retrieve
1533 - );
1534 - $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1535 - if ( $ldap_entries['count'] > 0 ) {
1536 - break;
1537 - }
1538 - }
1539 -
1540 1363 // If we didn't find any users in ldap, fall back to WordPress authentication.
1541 1364 if ( $ldap_entries['count'] < 1 ) {
1542 1365 return null;
1543 1366 }
@@ -1543,21 +1366,21 @@
1543 1366 }
1544 1367
1545 1368 // Get the bind dn and first/last names; if there are multiple results returned, just get the last one.
1546 1369 for ( $i = 0; $i < $ldap_entries['count']; $i++ ) {
1547 - $ldap_user_dn = $ldap_entries[ $i ]['dn'];
1370 + $ldap_user_dn = $ldap_entries[$i]['dn'];
1548 1371
1549 1372 // Get user first name and last name.
1550 - $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_first_name'] ) : '';
1551 - if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_first_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_first_name ][0] ) > 0 ) {
1552 - $first_name = $ldap_entries[ $i ][ $ldap_attr_first_name ][0];
1373 + $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? mb_strtolower( $auth_settings['ldap_attr_first_name'] ) : '';
1374 + if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_first_name]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_first_name][0] ) > 0 ) {
1375 + $first_name = $ldap_entries[$i][$ldap_attr_first_name][0];
1553 1376 }
1554 - $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_last_name'] ) : '';
1555 - if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_last_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_last_name ][0] ) > 0 ) {
1556 - $last_name = $ldap_entries[ $i ][ $ldap_attr_last_name ][0];
1377 + $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? mb_strtolower( $auth_settings['ldap_attr_last_name'] ) : '';
1378 + if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_last_name]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_last_name][0] ) > 0 ) {
1379 + $last_name = $ldap_entries[$i][$ldap_attr_last_name][0];
1557 1380 }
1558 1381 // Get user email if it is specified in another field.
1559 - $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_email'] ) : '';
1382 + $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? mb_strtolower( $auth_settings['ldap_attr_email'] ) : '';
1560 1383 if ( strlen( $ldap_attr_email ) > 0 ) {
1561 1384 // If the email attribute starts with an at symbol (@), assume that the
1562 1385 // email domain is manually entered there (instead of a reference to an
1563 1386 // LDAP attribute), and combine that with the username to create the email.
@@ -1562,16 +1385,16 @@
1562 1385 // email domain is manually entered there (instead of a reference to an
1563 1386 // LDAP attribute), and combine that with the username to create the email.
1564 1387 // Otherwise, look up the LDAP attribute for email.
1565 1388 if ( substr( $ldap_attr_email, 0, 1 ) === '@' ) {
1566 - $email = $this->lowercase( $username . $ldap_attr_email );
1567 - } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_email ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_email ][0] ) > 0 ) {
1568 - $email = $this->lowercase( $ldap_entries[ $i ][ $ldap_attr_email ][0] );
1389 + $email = mb_strtolower( $username . $ldap_attr_email );
1390 + } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[$i] ) && $ldap_entries[$i][$ldap_attr_email]['count'] > 0 && strlen( $ldap_entries[$i][$ldap_attr_email][0] ) > 0 ) {
1391 + $email = mb_strtolower( $ldap_entries[$i][$ldap_attr_email][0] );
1569 1392 }
1570 1393 }
1571 1394 }
1572 1395
1573 - $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) ); // phpcs:ignore
1396 + $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) );
1574 1397 if ( ! $result ) {
1575 1398 // We have a real ldap user, but an invalid password. Pass
1576 1399 // through to wp authentication after failing LDAP (since
1577 1400 // this could be a local account that happens to be the
@@ -1579,22 +1402,22 @@
1579 1402 return null;
1580 1403 }
1581 1404
1582 1405 // User successfully authenticated against LDAP, so set the relevant variables.
1583 - $externally_authenticated_email = $this->lowercase( $username . '@' . $domain );
1406 + $externally_authenticated_email = mb_strtolower( $username . '@' . $domain );
1584 1407
1585 1408 // If an LDAP attribute has been specified as containing the email address, use that instead.
1586 1409 if ( strlen( $email ) > 0 ) {
1587 - $externally_authenticated_email = $this->lowercase( $email );
1410 + $externally_authenticated_email = mb_strtolower( $email );
1588 1411 }
1589 1412
1590 1413 return array(
1591 - 'email' => $externally_authenticated_email,
1592 - 'username' => $username,
1593 - 'first_name' => $first_name,
1594 - 'last_name' => $last_name,
1414 + 'email' => $externally_authenticated_email,
1415 + 'username' => $username,
1416 + 'first_name' => $first_name,
1417 + 'last_name' => $last_name,
1595 1418 'authenticated_by' => 'ldap',
1596 - 'ldap_attributes' => $ldap_entries,
1419 + 'ldap_attributes' => $ldap_entries,
1597 1420 );
1598 1421 }
1599 1422
1600 1423
@@ -1600,20 +1423,18 @@
1600 1423
1601 1424 /**
1602 1425 * Log out of the attached external service.
1603 1426 *
1604 - * Action: wp_logout
1605 - *
1606 1427 * @return void
1607 1428 */
1608 1429 public function custom_logout() {
1609 1430 // Grab plugin settings.
1610 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1431 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1611 1432
1612 1433 // Reset option containing old error messages.
1613 1434 delete_option( 'auth_settings_advanced_login_error' );
1614 1435
1615 - if ( session_id() === '' ) {
1436 + if ( session_id() == '' ) {
1616 1437 session_start();
1617 1438 }
1618 1439
1619 1440 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
@@ -1618,38 +1439,32 @@
1618 1439
1619 1440 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
1620 1441
1621 1442 // If logged in to CAS, Log out of CAS.
1622 - if ( 'cas' === $current_user_authenticated_by && '1' === $auth_settings['cas'] ) {
1443 + if ( $current_user_authenticated_by === 'cas' && $auth_settings['cas'] === '1' ) {
1623 1444 if ( ! array_key_exists( 'PHPCAS_CLIENT', $GLOBALS ) || ! array_key_exists( 'phpCAS', $_SESSION ) ) {
1624 1445
1625 - /**
1626 - * Get the CAS server version (default to SAML_VERSION_1_1).
1627 - *
1628 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1629 - */
1446 + // Get the CAS server version (default to SAML_VERSION_1_1).
1447 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1630 1448 $cas_version = SAML_VERSION_1_1;
1631 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1449 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1632 1450 $cas_version = CAS_VERSION_3_0;
1633 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1451 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1634 1452 $cas_version = CAS_VERSION_2_0;
1635 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1453 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1636 1454 $cas_version = CAS_VERSION_1_0;
1637 1455 }
1638 1456
1639 1457 // Set the CAS client configuration if it hasn't been set already.
1640 1458 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1641 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1642 - // at an old CAS URL that redirects to a newer CAS URL).
1643 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1644 1459 // Restrict logout request origin to the CAS server only (prevent DDOS).
1645 1460 phpCAS::handleLogoutRequests( true, array( $auth_settings['cas_host'] ) );
1646 1461 }
1647 - if ( phpCAS::isAuthenticated() || phpCAS::isInitialized() ) {
1462 + if ( phpCAS::isAuthenticated() ) {
1648 1463 // Redirect to home page, or specified page if it's been provided.
1649 1464 $redirect_to = site_url( '/' );
1650 - if ( ! empty( $_REQUEST['redirect_to'] ) && isset( $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'log-out' ) ) {
1651 - $redirect_to = esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) );
1465 + if ( array_key_exists( 'redirect_to', $_REQUEST ) && filter_var( $_REQUEST['redirect_to'], FILTER_VALIDATE_URL ) !== false ) {
1466 + $redirect_to = $_REQUEST['redirect_to'];
1652 1467 }
1653 1468
1654 1469 phpCAS::logoutWithRedirectService( $redirect_to );
1655 1470 }
@@ -1655,16 +1470,13 @@
1655 1470 }
1656 1471 }
1657 1472
1658 1473 // If session token set, log out of Google.
1659 - if ( 'google' === $current_user_authenticated_by || array_key_exists( 'token', $_SESSION ) ) {
1474 + if ( $current_user_authenticated_by === 'google' || array_key_exists( 'token', $_SESSION ) ) {
1660 1475 $token = json_decode( $_SESSION['token'] )->access_token;
1661 1476
1662 - /**
1663 - * Add Google API PHP Client.
1664 - *
1665 - * @see https://github.com/google/google-api-php-client branch:v1-master
1666 - */
1477 + // Add Google API PHP Client.
1478 + // @see https://github.com/google/google-api-php-client branch:v1-master
1667 1479 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1668 1480
1669 1481 // Build the Google Client.
1670 1482 $client = new Google_Client();
@@ -1672,9 +1484,9 @@
1672 1484 $client->setClientId( $auth_settings['google_clientid'] );
1673 1485 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1674 1486 $client->setRedirectUri( 'postmessage' );
1675 1487
1676 - // Revoke the token.
1488 + // Revoke the token
1677 1489 $client->revokeToken( $token );
1678 1490
1679 1491 // Remove the credentials from the user's session.
1680 1492 unset( $_SESSION['token'] );
@@ -1693,37 +1505,36 @@
1693 1505
1694 1506
1695 1507 /**
1696 1508 * Restrict access to WordPress site based on settings (everyone, logged_in_users).
1509 + * Hook: parse_request http://codex.wordpress.org/Plugin_API/Action_Reference/parse_request
1697 1510 *
1698 - * Action: parse_request
1511 + * @param array $wp WordPress object.
1699 1512 *
1700 - * @param array $wp WordPress object.
1701 - * @return WP|void WP object when passing through to WordPress authentication, or void.
1513 + * @return void
1702 1514 */
1703 1515 public function restrict_access( $wp ) {
1704 1516 // Grab plugin settings.
1705 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1517 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1706 1518
1707 1519 // Grab current user.
1708 1520 $current_user = wp_get_current_user();
1709 1521
1710 1522 $has_access = (
1711 - // Always allow access if WordPress is installing.
1712 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1523 + // Always allow access if WordPress is installing
1713 1524 ( defined( 'WP_INSTALLING' ) && isset( $_GET['key'] ) ) ||
1714 - // Always allow access to admins.
1525 + // Always allow access to admins
1715 1526 ( current_user_can( 'create_users' ) ) ||
1716 - // Allow access if option is set to 'everyone'.
1717 - ( 'everyone' === $auth_settings['access_who_can_view'] ) ||
1718 - // Allow access to approved external users and logged in users if option is set to 'logged_in_users'.
1719 - ( 'logged_in_users' === $auth_settings['access_who_can_view'] && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1720 - // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API.
1721 - ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_oauth1=' ) === 0 ) ||
1722 - // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them.
1723 - ( property_exists( $wp, 'matched_query' ) && 0 === stripos( $wp->matched_query, 'rest_route=' ) && isset( $_SERVER['REQUEST_METHOD'] ) && 'GET' !== $_SERVER['REQUEST_METHOD'] ) ||
1724 - // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this.
1725 - ( property_exists( $wp, 'matched_query' ) && 'rest_route=/' === $wp->matched_query )
1527 + // Allow access if option is set to 'everyone'
1528 + ( $auth_settings['access_who_can_view'] == 'everyone' ) ||
1529 + // Allow access to approved external users and logged in users if option is set to 'logged_in_users'
1530 + ( $auth_settings['access_who_can_view'] == 'logged_in_users' && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1531 + // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API
1532 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_oauth1=" ) === 0 ) ||
1533 + // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them
1534 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] !== 'GET' ) ||
1535 + // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this
1536 + ( property_exists( $wp, 'matched_query' ) && $wp->matched_query === 'rest_route=/' )
1726 1537 // Note that GET requests to a rest endpoint will be restricted by authorizer. In that case, error messages will be returned as JSON.
1727 1538 );
1728 1539
1729 1540 /**
@@ -1745,9 +1556,9 @@
1745 1556 * }
1746 1557 * add_filter( 'authorizer_has_access', 'my_rsa_feed_access_override' );
1747 1558 */
1748 1559 if ( apply_filters( 'authorizer_has_access', $has_access, $wp ) === true ) {
1749 - // Turn off the public notice about browsing anonymously.
1560 + // Turn off the public notice about browsing anonymously
1750 1561 update_option( 'auth_settings_advanced_public_notice', false );
1751 1562
1752 1563 // We've determined that the current user has access, so simply return to grant access.
1753 1564 return $wp;
@@ -1753,13 +1564,13 @@
1753 1564 return $wp;
1754 1565 }
1755 1566
1756 1567 // Allow HEAD requests to the root (usually discovery from a REST client).
1757 - if ( 'HEAD' === $_SERVER['REQUEST_METHOD'] && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1568 + if ( $_SERVER['REQUEST_METHOD'] === 'HEAD' && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1758 1569 return $wp;
1759 1570 }
1760 1571
1761 - /* We've determined that the current user doesn't have access, so we deal with them now. */
1572 + // We've determined that the current user doesn't have access, so we deal with them now.
1762 1573
1763 1574 // Fringe case: In a multisite, a user of a different blog can successfully
1764 1575 // log in, but they aren't on the 'approved' whitelist for this blog.
1765 1576 // If that's the case, add them to the pending list for this blog.
@@ -1770,19 +1581,29 @@
1770 1581 $result = $this->check_user_access( $current_user, array( $current_user->user_email ) );
1771 1582 }
1772 1583
1773 1584 // Check to see if the requested page is public. If so, show it.
1585 + $current_page_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'name', $wp->query_vars ) && strlen( $wp->query_vars['name'] ) > 0 ? $wp->query_vars['name'] : '';
1586 + if ( ! $current_page_name ) {
1587 + // Different WordPress versions store the page slug in different places; look for it elsewhere.
1588 + if ( property_exists( $wp, 'query_vars' ) && array_key_exists( 'pagename', $wp->query_vars ) && strlen( $wp->query_vars['pagename'] ) > 0 ) {
1589 + $current_page_name = $wp->query_vars['pagename'];
1590 + }
1591 + }
1592 + $current_page_id = '';
1774 1593 if ( empty( $wp->request ) ) {
1775 1594 $current_page_id = 'home';
1776 1595 } else {
1777 - $request_query = isset( $wp->query_vars ) ? new WP_Query( $wp->query_vars ) : null;
1778 - $current_page_id = isset( $request_query->post_count ) && $request_query->post_count > 0 ? $request_query->post->ID : '';
1596 + $current_page = get_page_by_path( $current_page_name );
1597 + if ( is_object( $current_page ) && isset( $current_page->ID ) ) {
1598 + $current_page_id = $current_page->ID;
1599 + }
1779 1600 }
1780 1601 if ( ! array_key_exists( 'access_public_pages', $auth_settings ) || ! is_array( $auth_settings['access_public_pages'] ) ) {
1781 1602 $auth_settings['access_public_pages'] = array();
1782 1603 }
1783 - if ( in_array( strval( $current_page_id ), $auth_settings['access_public_pages'], true ) ) {
1784 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1604 + if ( in_array( $current_page_id, $auth_settings['access_public_pages'] ) ) {
1605 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1785 1606 update_option( 'auth_settings_advanced_public_notice', false );
1786 1607 } else {
1787 1608 update_option( 'auth_settings_advanced_public_notice', true );
1788 1609 }
@@ -1790,11 +1611,11 @@
1790 1611 }
1791 1612
1792 1613 // Check to see if any category assigned to the requested page is public. If so, show it.
1793 1614 $current_page_categories = wp_get_post_categories( $current_page_id, array( 'fields' => 'slugs' ) );
1794 - foreach ( $current_page_categories as $current_page_category ) {
1795 - if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'], true ) ) {
1796 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1615 + foreach( $current_page_categories as $current_page_category ) {
1616 + if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'] ) ) {
1617 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1797 1618 update_option( 'auth_settings_advanced_public_notice', false );
1798 1619 } else {
1799 1620 update_option( 'auth_settings_advanced_public_notice', true );
1800 1621 }
@@ -1802,11 +1623,11 @@
1802 1623 }
1803 1624 }
1804 1625
1805 1626 // Check to see if this page can't be found. If so, allow showing the 404 page.
1806 - if ( strlen( $current_page_id ) < 1 ) {
1807 - if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'], true ) ) {
1808 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1627 + if ( strlen( $current_page_name ) > 0 && strlen( $current_page_id ) < 1 ) {
1628 + if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'] ) ) {
1629 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1809 1630 update_option( 'auth_settings_advanced_public_notice', false );
1810 1631 } else {
1811 1632 update_option( 'auth_settings_advanced_public_notice', true );
1812 1633 }
@@ -1811,8 +1632,9 @@
1811 1632 update_option( 'auth_settings_advanced_public_notice', true );
1812 1633 }
1813 1634 return $wp;
1814 1635 }
1636 +
1815 1637 }
1816 1638
1817 1639 // Check to see if the requested category is public. If so, show it.
1818 1640 $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
@@ -1817,10 +1639,10 @@
1817 1639 // Check to see if the requested category is public. If so, show it.
1818 1640 $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
1819 1641 if ( $current_category_name ) {
1820 1642 $current_category_name = end( explode( '/', $current_category_name ) );
1821 - if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'], true ) ) {
1822 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1643 + if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'] ) ) {
1644 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1823 1645 update_option( 'auth_settings_advanced_public_notice', false );
1824 1646 } else {
1825 1647 update_option( 'auth_settings_advanced_public_notice', true );
1826 1648 }
@@ -1830,20 +1652,18 @@
1830 1652
1831 1653 // User is denied access, so show them the error message. Render as JSON
1832 1654 // if this is a REST API call; otherwise, show the error message via
1833 1655 // wp_die() (rendered html), or redirect to the login URL.
1834 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1835 - if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_route=' ) === 0 && 'GET' === $_SERVER['REQUEST_METHOD'] ) {
1836 - wp_send_json(
1837 - array(
1838 - 'code' => 'rest_cannot_view',
1839 - 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1840 - 'data' => array(
1841 - 'status' => 401,
1842 - ),
1843 - )
1844 - );
1845 - } elseif ( 'message' === $auth_settings['access_redirect'] ) {
1656 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1657 + if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] === 'GET' ) {
1658 + wp_send_json( array(
1659 + 'code' => 'rest_cannot_view',
1660 + 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1661 + 'data' => array(
1662 + 'status' => 401,
1663 + ),
1664 + ));
1665 + } elseif ( $auth_settings['access_redirect'] === 'message' ) {
1846 1666 $page_title = sprintf(
1847 1667 /* TRANSLATORS: %s: Name of blog */
1848 1668 __( '%s - Access Restricted', 'authorizer' ),
1849 1669 get_bloginfo( 'name' )
@@ -1854,15 +1674,15 @@
1854 1674 '<p style="text-align: center;margin-bottom: -15px;">' .
1855 1675 '<a class="button" href="' . wp_login_url( $current_path ) . '">' .
1856 1676 __( 'Log In', 'authorizer' ) .
1857 1677 '</a></p>';
1858 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
1859 - } else {
1678 + wp_die( $error_message, $page_title );
1679 + } else { // if ( $auth_settings['access_redirect'] === 'login' ) {
1860 1680 wp_redirect( wp_login_url( $current_path ), 302 );
1861 1681 exit;
1862 1682 }
1863 1683
1864 - // Sanity check: we should never get here.
1684 + // Sanity check: we should never get here
1865 1685 wp_die( '<p>Access denied.</p>', 'Site Access Restricted' );
1866 1686 }
1867 1687
1868 1688
@@ -1871,11 +1691,9 @@
1871 1691 * not yet been added to this particular blog in a multisite). Note: we do
1872 1692 * this because check_user_access() runs on the parse_request hook, which
1873 1693 * does not fire on wp-admin pages.
1874 1694 *
1875 - * Action: init
1876 - *
1877 - * @return void
1695 + * Hook: admin_menu
1878 1696 */
1879 1697 public function init__maybe_add_network_approved_user() {
1880 1698 global $current_user;
1881 1699
@@ -1890,10 +1708,10 @@
1890 1708 ) {
1891 1709 // Get all approved users.
1892 1710 $auth_settings_access_users_approved = $this->sanitize_user_list(
1893 1711 array_merge(
1894 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
1895 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
1712 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
1713 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
1896 1714 )
1897 1715 );
1898 1716
1899 1717 // Get user info (we need user role).
@@ -1905,9 +1723,9 @@
1905 1723 // Add user to blog.
1906 1724 add_user_to_blog( get_current_blog_id(), $current_user->ID, $user_info['role'] );
1907 1725
1908 1726 // Refresh user permissions.
1909 - $current_user = new WP_User( $current_user->ID ); // phpcs:ignore WordPress.Variables.GlobalVariables.OverrideProhibited
1727 + $current_user = new WP_User( $current_user->ID );
1910 1728 }
1911 1729 }
1912 1730
1913 1731
@@ -1921,15 +1739,11 @@
1921 1739
1922 1740
1923 1741 /**
1924 1742 * Add custom error message to login screen.
1925 - *
1926 1743 * Filter: login_errors
1927 - *
1928 - * @param string $errors Error description.
1929 - * @return string Error description with Authorizer errors added.
1930 1744 */
1931 - public function show_advanced_login_error( $errors ) {
1745 + function show_advanced_login_error( $errors ) {
1932 1746 $error = get_option( 'auth_settings_advanced_login_error' );
1933 1747 delete_option( 'auth_settings_advanced_login_error' );
1934 1748 $errors = ' ' . $error . "<br />\n";
1935 1749 return $errors;
@@ -1937,25 +1751,24 @@
1937 1751
1938 1752
1939 1753 /**
1940 1754 * Load external resources for the public-facing site.
1941 - *
1942 - * Action: wp_enqueue_scripts
1943 1755 */
1944 - public function auth_public_scripts() {
1945 - // Load (and localize) public scripts.
1946 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1947 - wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1756 + function auth_public_scripts() {
1757 + // Load (and localize) public scripts
1758 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1759 + wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1948 1760 $auth_localized = array(
1949 - 'wpLoginUrl' => wp_login_url( $current_path ),
1950 - 'publicWarning' => get_option( 'auth_settings_advanced_public_notice' ),
1951 - 'anonymousNotice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1952 - 'logIn' => esc_html__( 'Log In', 'authorizer' ),
1761 + 'wp_login_url' => wp_login_url( $current_path ),
1762 + 'public_warning' => get_option( 'auth_settings_advanced_public_notice' ),
1763 + 'anonymous_notice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1764 + 'log_in' => esc_html__( 'Log In', 'authorizer' ),
1953 1765 );
1954 1766 wp_localize_script( 'auth_public_scripts', 'auth', $auth_localized );
1767 + //update_option( 'auth_settings_advanced_public_notice', false);
1955 1768
1956 - // Load public css.
1957 - wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.8.0' );
1769 + // Load public css
1770 + wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.3.2' );
1958 1771 wp_enqueue_style( 'authorizer-public-css' );
1959 1772 }
1960 1773
1961 1774
@@ -1961,21 +1774,19 @@
1961 1774
1962 1775 /**
1963 1776 * Enqueue JS scripts and CSS styles appearing on wp-login.php.
1964 1777 *
1965 - * Action: login_enqueue_scripts
1966 - *
1967 1778 * @return void
1968 1779 */
1969 - public function login_enqueue_scripts_and_styles() {
1780 + function login_enqueue_scripts_and_styles() {
1970 1781 // Grab plugin settings.
1971 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1782 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1972 1783
1973 1784 // Enqueue scripts appearing on wp-login.php.
1974 - wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1785 + wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1975 1786
1976 1787 // Enqueue styles appearing on wp-login.php.
1977 - wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.8.0' );
1788 + wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.3.2' );
1978 1789 wp_enqueue_style( 'authorizer-login-css' );
1979 1790
1980 1791 /**
1981 1792 * Developers can use the `authorizer_add_branding_option` filter
@@ -1980,8 +1791,9 @@
1980 1791 /**
1981 1792 * Developers can use the `authorizer_add_branding_option` filter
1982 1793 * to add a radio button for "Custom WordPress login branding"
1983 1794 * under the "Advanced" tab in Authorizer options. Example:
1795 + *
1984 1796 * function my_authorizer_add_branding_option( $branding_options ) {
1985 1797 * $new_branding_option = array(
1986 1798 * 'value' => 'your_brand'
1987 1799 * 'description' => 'Custom Your Brand Login Screen',
@@ -1995,23 +1807,23 @@
1995 1807 */
1996 1808 $branding_options = array();
1997 1809 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
1998 1810 foreach ( $branding_options as $branding_option ) {
1999 - // Make sure the custom brands have the required values.
1811 + // Make sure the custom brands have the required values
2000 1812 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'css_url', $branding_option ) && array_key_exists( 'js_url', $branding_option ) ) ) {
2001 1813 continue;
2002 1814 }
2003 1815 if ( $auth_settings['advanced_branding'] === $branding_option['value'] ) {
2004 - wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.8.0' );
2005 - wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.8.0' );
1816 + wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.3.2' );
1817 + wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.3.2' );
2006 1818 wp_enqueue_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ) );
2007 1819 }
2008 1820 }
2009 1821
2010 1822 // If we're using Google logins, load those resources.
2011 - if ( '1' === $auth_settings['google'] ) {
2012 - wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); ?>
2013 - <meta name="google-signin-clientid" content="<?php echo esc_attr( $auth_settings['google_clientid'] ); ?>" />
1823 + if ( $auth_settings['google'] === '1' ) {
1824 + wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); ?>
1825 + <meta name="google-signin-clientid" content="<?php echo $auth_settings['google_clientid']; ?>" />
2014 1826 <meta name="google-signin-scope" content="email" />
2015 1827 <meta name="google-signin-cookiepolicy" content="single_host_origin" />
2016 1828 <?php
2017 1829 }
@@ -2019,127 +1831,110 @@
2019 1831
2020 1832
2021 1833 /**
2022 1834 * Load external resources in the footer of the wp-login.php page.
2023 - *
2024 - * Action: login_footer
1835 + * Run on action hook: login_footer
2025 1836 */
2026 - public function load_login_footer_js() {
1837 + function load_login_footer_js() {
2027 1838 // Grab plugin settings.
2028 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2029 - $ajaxurl = admin_url( 'admin-ajax.php' );
2030 - if ( '1' === $auth_settings['google'] ) :
2031 - ?>
2032 -<script type="text/javascript">
2033 -/* global location, window */
2034 -// Reload login page if reauth querystring param exists,
2035 -// since reauth interrupts external logins (e.g., google).
2036 -if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
2037 - location.href = location.href.replace( 'reauth=1', '' );
2038 -}
1839 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
1840 + <?php if ( $auth_settings['google'] === '1' ): ?>
1841 + <script type="text/javascript">
1842 + // Reload login page if reauth querystring param exists,
1843 + // since reauth interrupts external logins (e.g., google).
1844 + if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
1845 + location.href = location.href.replace( 'reauth=1', '' );
1846 + }
2039 1847
2040 -// eslint-disable-next-line no-implicit-globals
2041 -function authUpdateQuerystringParam( uri, key, value ) {
2042 - var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
2043 - var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
2044 - if ( uri.match( re ) ) {
2045 - return uri.replace( re, '$1' + key + '=' + value + '$2' );
2046 - } else {
2047 - return uri + separator + key + '=' + value;
2048 - }
2049 -}
1848 + function auth_update_querystring_param( uri, key, value ) {
1849 + var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
1850 + var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
1851 + if ( uri.match( re ) ) {
1852 + return uri.replace( re, '$1' + key + '=' + value + '$2' );
1853 + } else {
1854 + return uri + separator + key + '=' + value;
1855 + }
1856 + }
2050 1857
2051 -// eslint-disable-next-line
2052 -function signInCallback( authResult ) { // jshint ignore:line
2053 - var $ = jQuery;
2054 - if ( authResult.status && authResult.status.signed_in ) {
2055 - // Hide the sign-in button now that the user is authorized, for example:
2056 - $( '#googleplus_button' ).attr( 'style', 'display: none' );
1858 + function signInCallback( authResult ) {
1859 + var $ = jQuery;
1860 + if ( authResult['status'] && authResult['status']['signed_in'] ) {
1861 + // Hide the sign-in button now that the user is authorized, for example:
1862 + $( '#googleplus_button' ).attr( 'style', 'display: none' );
2057 1863
2058 - // Send the code to the server
2059 - var ajaxurl = '<?php echo esc_attr( $ajaxurl ); ?>';
2060 - $.post(ajaxurl, {
2061 - action: 'process_google_login',
2062 - code: authResult.code,
2063 - nonce: $('#nonce_google_auth-<?php echo esc_attr( $this->get_cookie_value() ); ?>' ).val(),
2064 - }, function() {
2065 - // Handle or verify the server response if necessary.
2066 - // console.log( response );
1864 + // Send the code to the server
1865 + var ajaxurl = '<?php echo admin_url( "admin-ajax.php" ); ?>';
1866 + $.post(ajaxurl, {
1867 + action: 'process_google_login',
1868 + 'code': authResult['code'],
1869 + 'nonce': $('#nonce_google_auth-<?php echo $this->get_cookie_value(); ?>' ).val(),
1870 + }, function( response ) {
1871 + // Handle or verify the server response if necessary.
1872 + //console.log( response );
2067 1873
2068 - // Reload wp-login.php to continue the authentication process.
2069 - var newHref = authUpdateQuerystringParam( location.href, 'external', 'google' );
2070 - if ( location.href === newHref ) {
2071 - location.reload();
2072 - } else {
2073 - location.href = newHref;
2074 - }
2075 - });
2076 - } else {
2077 - // Update the app to reflect a signed out user
2078 - // Possible error values:
2079 - // "user_signed_out" - User is signed-out
2080 - // "access_denied" - User denied access to your app
2081 - // "immediate_failed" - Could not automatically log in the user
2082 - // console.log('Sign-in state: ' + authResult['error']);
1874 + // Reload wp-login.php to continue the authentication process.
1875 + var new_href = auth_update_querystring_param( location.href, 'external', 'google' );
1876 + if ( location.href === new_href ) {
1877 + location.reload();
1878 + } else {
1879 + location.href = new_href;
1880 + }
1881 + });
1882 + } else {
1883 + // Update the app to reflect a signed out user
1884 + // Possible error values:
1885 + // "user_signed_out" - User is signed-out
1886 + // "access_denied" - User denied access to your app
1887 + // "immediate_failed" - Could not automatically log in the user
1888 + //console.log('Sign-in state: ' + authResult['error']);
2083 1889
2084 - // If user denies access, reload the login page.
2085 - if ( authResult.error === 'access_denied' || authResult.error === 'user_signed_out' ) {
2086 - window.location.reload();
1890 + // If user denies access, reload the login page.
1891 + if ( authResult['error'] === 'access_denied' || authResult['error'] === 'user_signed_out' ) {
1892 + window.location.reload();
1893 + }
1894 + }
1895 + }
1896 + </script>
1897 + <?php endif;
2087 1898 }
2088 - }
2089 -}
2090 -</script>
2091 - <?php
2092 - endif;
2093 - }
2094 1899
2095 1900
2096 1901 /**
2097 1902 * Create links for any external authentication services that are enabled.
2098 - *
2099 - * Action: login_form
2100 1903 */
2101 - public function login_form_add_external_service_links() {
1904 + function login_form_add_external_service_links() {
2102 1905 // Grab plugin settings.
2103 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2104 - ?>
1906 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
2105 1907 <div id="auth-external-service-login">
2106 - <?php if ( '1' === $auth_settings['google'] ) : ?>
2107 - <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php esc_html_e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
1908 + <?php if ( $auth_settings['google'] === '1' ): ?>
1909 + <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php _e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
2108 1910 <?php wp_nonce_field( 'google_csrf_nonce', 'nonce_google_auth-' . $this->get_cookie_value() ); ?>
2109 1911 <?php endif; ?>
2110 1912
2111 - <?php if ( '1' === $auth_settings['cas'] ) : ?>
2112 - <p><a class="button button-primary button-external button-cas" href="<?php echo esc_attr( $this->modify_current_url_for_cas_login() ); ?>">
1913 + <?php if ( $auth_settings['cas'] === '1' ): ?>
1914 + <p><a class="button button-primary button-external button-cas" href="<?php echo $this->modify_current_url_for_cas_login(); ?>">
2113 1915 <span class="dashicons dashicons-lock"></span>
2114 - <span class="label">
2115 - <?php
2116 - echo esc_html(
2117 - sprintf(
2118 - /* TRANSLATORS: %s: Custom CAS label from authorizer options */
2119 - __( 'Sign in with %s', 'authorizer' ),
2120 - $auth_settings['cas_custom_label']
2121 - )
1916 + <span class="label"><?php
1917 + printf(
1918 + /* TRANSLATORS: %s: Custom CAS label from authorizer options */
1919 + __( 'Sign in with %s', 'authorizer' ),
1920 + $auth_settings['cas_custom_label']
2122 1921 );
2123 - ?>
2124 - </span>
1922 + ?></span>
2125 1923 </a></p>
2126 1924 <?php endif; ?>
2127 1925
2128 - <?php if ( '1' === $auth_settings['advanced_hide_wp_login'] && isset( $_SERVER['QUERY_STRING'] ) && false === strpos( wp_parse_url( esc_url_raw( wp_unslash( $_SERVER['QUERY_STRING'] ) ), PHP_URL_HOST ), 'external=wordpress' ) ) : ?>
1926 + <?php if ( $auth_settings['advanced_hide_wp_login'] === '1' && strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false ): ?>
2129 1927 <style type="text/css">
2130 - body.login-action-login form {
2131 - padding-bottom: 8px;
1928 + #loginform {
1929 + padding-bottom: 8px !important;
2132 1930 }
2133 - body.login-action-login form p > label,
2134 - body.login-action-login form .forgetmenot,
2135 - body.login-action-login form .submit,
2136 - body.login-action-login #nav { /* csslint allow: ids */
2137 - display: none;
1931 + #loginform p>label, #loginform p.forgetmenot, #loginform p.submit, p#nav {
1932 + display: none !important;
2138 1933 }
2139 1934 </style>
2140 - <?php elseif ( '1' === $auth_settings['cas'] || '1' === $auth_settings['google'] ) : ?>
2141 - <h3> &mdash; <?php esc_html_e( 'or', 'authorizer' ); ?> &mdash; </h3>
1935 + <?php elseif ( $auth_settings['cas'] === '1' || $auth_settings['google'] === '1' ): ?>
1936 + <h3> &mdash; <?php _e( 'or', 'authorizer' ); ?> &mdash; </h3>
2142 1937 <?php endif; ?>
2143 1938 </div>
2144 1939 <?php
2145 1940
@@ -2152,28 +1947,21 @@
2152 1947 * Note: hook into wp_login_errors filter so this fires after the
2153 1948 * authenticate hook (where the redirect to CAS happens), but before html
2154 1949 * output is started (so the redirect header doesn't complain about data
2155 1950 * already being sent).
2156 - *
2157 - * Filter: wp_login_errors
2158 - *
2159 - * @param object $errors WP Error object.
2160 - * @param string $redirect_to Where to redirect on error.
2161 - * @return WP_Error|void WP Error object or void on redirect.
2162 1951 */
2163 - public function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
1952 + function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
2164 1953 // Grab plugin settings.
2165 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1954 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2166 1955
2167 1956 // Check whether we should redirect to CAS.
2168 1957 if (
2169 - isset( $_SERVER['QUERY_STRING'] ) &&
2170 - strpos( wp_parse_url( esc_url_raw( wp_unslash( $_SERVER['QUERY_STRING'] ) ), PHP_URL_HOST ), 'external=wordpress' ) === false &&
2171 - array_key_exists( 'cas_auto_login', $auth_settings ) && '1' === $auth_settings['cas_auto_login'] &&
2172 - array_key_exists( 'cas', $auth_settings ) && '1' === $auth_settings['cas'] &&
2173 - ( ! array_key_exists( 'ldap', $auth_settings ) || '1' !== $auth_settings['ldap'] ) &&
2174 - ( ! array_key_exists( 'google', $auth_settings ) || '1' !== $auth_settings['google'] ) &&
2175 - array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && '1' === $auth_settings['advanced_hide_wp_login']
1958 + strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false &&
1959 + array_key_exists( 'cas_auto_login', $auth_settings ) && $auth_settings['cas_auto_login'] === '1' &&
1960 + array_key_exists( 'cas', $auth_settings ) && $auth_settings['cas'] === '1' &&
1961 + ( ! array_key_exists( 'ldap', $auth_settings ) || $auth_settings['ldap'] !== '1' ) &&
1962 + ( ! array_key_exists( 'google', $auth_settings ) || $auth_settings['google'] !== '1' ) &&
1963 + array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && $auth_settings['advanced_hide_wp_login'] === '1'
2176 1964 ) {
2177 1965 wp_redirect( $this->modify_current_url_for_cas_login() );
2178 1966 exit;
2179 1967 }
@@ -2186,22 +1974,18 @@
2186 1974 * Set a unique cookie to add to Google auth nonce to avoid CSRF detection.
2187 1975 * Note: hook into login_init so this fires at the start of the visit to
2188 1976 * wp-login.php, but before any html output is started (so setting the
2189 1977 * cookie header doesn't complain about data already being sent).
2190 - *
2191 - * Action: login_init
2192 - *
2193 - * @return void
2194 1978 */
2195 - public function login_init__maybe_set_google_nonce_cookie() {
1979 + function login_init__maybe_set_google_nonce_cookie() {
2196 1980 // Grab plugin settings.
2197 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1981 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2198 1982
2199 1983 // If Google logins are enabled, make sure the cookie is set.
2200 - if ( array_key_exists( 'google', $auth_settings ) && '1' === $auth_settings['google'] ) {
1984 + if ( array_key_exists( 'google', $auth_settings ) && $auth_settings['google'] === '1' ) {
2201 1985 if ( ! isset( $_COOKIE['login_unique'] ) ) {
2202 1986 $this->cookie_value = md5( rand() );
2203 - setcookie( 'login_unique', $this->cookie_value, time() + 1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
1987 + setcookie( 'login_unique', $this->cookie_value, time()+1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
2204 1988 $_COOKIE['login_unique'] = $this->cookie_value;
2205 1989 }
2206 1990 }
2207 1991 }
@@ -2210,17 +1994,12 @@
2210 1994 /**
2211 1995 * Implements hook: do_action( 'wp_login_failed', $username );
2212 1996 * Update the user meta for the user that just failed logging in.
2213 1997 * Keep track of time of last failed attempt and number of failed attempts.
2214 - *
2215 - * Action: wp_login_failed
2216 - *
2217 - * @param string $username Username to update login count for.
2218 - * @return void
2219 1998 */
2220 - public function update_login_failed_count( $username ) {
1999 + function update_login_failed_count( $username ) {
2221 2000 // Grab plugin settings.
2222 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2001 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2223 2002
2224 2003 // Get user trying to log in.
2225 2004 // If this isn't a real user, update the global failed attempt
2226 2005 // variables. We'll use these global variables to institute the
@@ -2228,9 +2007,9 @@
2228 2007 // won't be able to determine which accounts are real by which
2229 2008 // accounts get locked out on multiple invalid attempts.
2230 2009 $user = get_user_by( 'login', $username );
2231 2010
2232 - if ( false !== $user ) {
2011 + if ( $user !== FALSE ) {
2233 2012 $last_attempt = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
2234 2013 $num_attempts = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
2235 2014 } else {
2236 2015 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
@@ -2244,15 +2023,15 @@
2244 2023
2245 2024 // Reset the failed attempt count if the time since the last
2246 2025 // failed attempt is greater than the reset duration.
2247 2026 $time_since_last_fail = time() - $last_attempt;
2248 - $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds.
2027 + $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds
2249 2028 if ( $time_since_last_fail > $reset_duration ) {
2250 2029 $num_attempts = 0;
2251 2030 }
2252 2031
2253 2032 // Set last failed time to now and increment last failed count.
2254 - if ( false !== $user ) {
2033 + if ( $user !== FALSE ) {
2255 2034 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', time() );
2256 2035 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', $num_attempts + 1 );
2257 2036 } else {
2258 2037 update_option( 'auth_settings_advanced_lockouts_time_last_failed', time() );
@@ -2263,16 +2042,16 @@
2263 2042
2264 2043 /**
2265 2044 * When they successfully log in, make sure WordPress users are in the approved list.
2266 2045 *
2267 - * Action: wp_login
2046 + * @action wp_login
2268 2047 *
2269 2048 * @param string $user_login Username of the user logging in.
2270 - * @param object $user WP_User object of the user logging in.
2271 - * @return void
2049 + * @param WP_User $user WP_User object of the user logging in.
2050 + * @return null
2272 2051 */
2273 - public function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2274 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
2052 + function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2053 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
2275 2054 }
2276 2055
2277 2056
2278 2057 /**
@@ -2278,17 +2057,12 @@
2278 2057 /**
2279 2058 * Overwrite the URL for the lost password link on the login form.
2280 2059 * If we're authenticating against an external service, standard
2281 2060 * WordPress password resets won't work.
2282 - *
2283 - * Filter: lostpassword_url
2284 - *
2285 - * @param string $lostpassword_url URL to reset password.
2286 - * @return string URL to reset password.
2287 2061 */
2288 - public function custom_lostpassword_url( $lostpassword_url ) {
2062 + function custom_lostpassword_url( $lostpassword_url ) {
2289 2063 // Grab plugin settings.
2290 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2064 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2291 2065
2292 2066 if (
2293 2067 array_key_exists( 'ldap_lostpassword_url', $auth_settings ) &&
2294 2068 filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_VALIDATE_URL )
@@ -2311,16 +2085,15 @@
2311 2085 /**
2312 2086 * Add a link to this plugin's settings page from the WordPress Plugins page.
2313 2087 * Called from "plugin_action_links" filter in __construct() above.
2314 2088 *
2315 - * Filter: plugin_action_links_authorizer.php
2089 + * @param array $links array of links in the admin sidebar
2316 2090 *
2317 - * @param array $links Admin sidebar links.
2318 - * @return array Admin sidebar links with Authorizer added.
2091 + * @return array of links to show in the admin sidebar.
2319 2092 */
2320 2093 public function plugin_settings_link( $links ) {
2321 - $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2322 - $settings_url = 'settings' === $admin_menu ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2094 + $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2095 + $settings_url = $admin_menu === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2323 2096 array_unshift( $links, '<a href="' . $settings_url . '">' . __( 'Settings', 'authorizer' ) . '</a>' );
2324 2097 return $links;
2325 2098 }
2326 2099
@@ -2328,12 +2101,11 @@
2328 2101 /**
2329 2102 * Add a link to this plugin's network settings page from the WordPress Plugins page.
2330 2103 * Called from "network_admin_plugin_action_links" filter in __construct() above.
2331 2104 *
2332 - * Filter: network_admin_plugin_action_links_authorizer.php
2105 + * @param array $links array of links in the network admin sidebar
2333 2106 *
2334 - * @param array $links Network admin sidebar links.
2335 - * @return array Network admin sidebar links with Authorizer added.
2107 + * @return array of links to show in the network admin sidebar.
2336 2108 */
2337 2109 public function network_admin_plugin_settings_link( $links ) {
2338 2110 $settings_link = '<a href="admin.php?page=authorizer">' . __( 'Network Settings', 'authorizer' ) . '</a>';
2339 2111 array_unshift( $links, $settings_link );
@@ -2341,33 +2113,32 @@
2341 2113 }
2342 2114
2343 2115
2344 2116 /**
2345 - * Create the options page under Dashboard > Settings.
2346 - *
2347 - * Action: admin_menu
2117 + * Create the options page under Dashboard > Settings
2118 + * Run on action hook: admin_menu
2348 2119 */
2349 2120 public function add_plugin_page() {
2350 2121 $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2351 - if ( 'settings' === $admin_menu ) {
2122 + if ( $admin_menu === 'settings' ) {
2352 2123 // @see http://codex.wordpress.org/Function_Reference/add_options_page
2353 2124 add_options_page(
2354 - 'Authorizer',
2355 - 'Authorizer',
2356 - 'create_users',
2357 - 'authorizer',
2358 - array( $this, 'create_admin_page' )
2125 + 'Authorizer', // Page title
2126 + 'Authorizer', // Menu title
2127 + 'create_users', // Capability
2128 + 'authorizer', // Menu slug
2129 + array( $this, 'create_admin_page' ) // function
2359 2130 );
2360 2131 } else {
2361 2132 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
2362 2133 add_menu_page(
2363 - 'Authorizer',
2364 - 'Authorizer',
2365 - 'create_users',
2366 - 'authorizer',
2367 - array( $this, 'create_admin_page' ),
2368 - 'dashicons-groups',
2369 - '99.0018465' // position (decimal is to make overlap with other plugins less likely).
2134 + 'Authorizer', // Page title
2135 + 'Authorizer', // Menu title
2136 + 'create_users', // Capability
2137 + 'authorizer', // Menu slug
2138 + array( $this, 'create_admin_page' ), // callback
2139 + 'dashicons-groups', // icon
2140 + '99.0018465' // position (decimal is to make overlap with other plugins less likely)
2370 2141 );
2371 2142 }
2372 2143 }
2373 2144
@@ -2372,75 +2143,56 @@
2372 2143 }
2373 2144
2374 2145
2375 2146 /**
2376 - * Output the HTML for the options page.
2147 + * Output the HTML for the options page
2377 2148 */
2378 - public function create_admin_page() {
2379 - ?>
2149 + public function create_admin_page() { ?>
2380 2150 <div class="wrap">
2381 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2382 - <form method="post" action="options.php" autocomplete="off">
2383 - <?php
2384 - // This prints out all hidden settings fields.
2151 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2152 + <form method="post" action="options.php" autocomplete="off"><?php
2153 + // This prints out all hidden settings fields
2154 + // @see http://codex.wordpress.org/Function_Reference/settings_fields
2385 2155 settings_fields( 'auth_settings_group' );
2386 - // This prints out all the sections.
2156 + // This prints out all the sections
2157 + // @see http://codex.wordpress.org/Function_Reference/do_settings_sections
2387 2158 do_settings_sections( 'authorizer' );
2388 - submit_button();
2389 - ?>
2159 + submit_button(); ?>
2390 2160 </form>
2391 - </div>
2392 - <?php
2161 + </div><?php
2393 2162 }
2394 2163
2395 2164
2396 2165 /**
2397 2166 * Load external resources on this plugin's options page.
2398 - *
2399 - * Action: load-settings_page_authorizer
2400 - * Action: load-toplevel_page_authorizer
2401 - * Action: admin_head-index.php
2167 + * Run on action hooks: load-settings_page_authorizer, load-toplevel_page_authorizer, admin_head-index.php
2402 2168 */
2403 2169 public function load_options_page() {
2404 2170 wp_enqueue_script(
2405 2171 'authorizer',
2406 2172 plugins_url( 'js/authorizer.js', __FILE__ ),
2407 - array( 'jquery-effects-shake' ), '2.8.0', true
2173 + array( 'jquery-effects-shake' ), '2.3.2', true
2408 2174 );
2409 - wp_localize_script(
2410 - 'authorizer', 'authL10n', array(
2411 - 'baseurl' => get_bloginfo( 'url' ),
2412 - 'saved' => esc_html__( 'Saved', 'authorizer' ),
2413 - 'duplicate' => esc_html__( 'Duplicate', 'authorizer' ),
2414 - 'failed' => esc_html__( 'Failed', 'authorizer' ),
2415 - 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2416 - 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2417 - 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2418 - 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2419 - 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2420 - 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2421 - 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2422 - 'first_page' => esc_html__( 'First page' ),
2423 - 'previous_page' => esc_html__( 'Previous page' ),
2424 - 'next_page' => esc_html__( 'Next page' ),
2425 - 'last_page' => esc_html__( 'Last page' ),
2426 - 'is_network_admin' => is_network_admin() ? '1' : '0',
2427 - )
2428 - );
2175 + wp_localize_script( 'authorizer', 'auth_L10n', array(
2176 + 'baseurl' => get_bloginfo( 'url' ),
2177 + 'saved' => esc_html__( 'Saved', 'authorizer' ),
2178 + 'failed' => esc_html__( 'Failed', 'authorizer' ),
2179 + 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2180 + 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2181 + 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2182 + 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2183 + 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2184 + 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2185 + 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2186 + ));
2429 2187
2430 2188 wp_enqueue_script(
2431 - 'jquery-autogrow-textarea',
2432 - plugins_url( 'vendor/jquery.autogrow-textarea/jquery.autogrow-textarea.js', __FILE__ ),
2433 - array( 'jquery' ), '2.7.0', true
2434 - );
2435 -
2436 - wp_enqueue_script(
2437 2189 'jquery.multi-select',
2438 2190 plugins_url( 'vendor/jquery.multi-select/js/jquery.multi-select.js', __FILE__ ),
2439 2191 array( 'jquery' ), '1.8', true
2440 2192 );
2441 2193
2442 - wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.7.3' );
2194 + wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.3.2' );
2443 2195 wp_enqueue_style( 'authorizer-css' );
2444 2196
2445 2197 wp_register_style( 'jquery-multi-select-css', plugins_url( 'vendor/jquery.multi-select/css/multi-select.css', __FILE__ ), array(), '1.8' );
2446 2198 wp_enqueue_style( 'jquery-multi-select-css' );
@@ -2451,26 +2203,18 @@
2451 2203
2452 2204
2453 2205 /**
2454 2206 * Show custom admin notice.
2455 - *
2456 - * Note: currently unused, but if anywhere we:
2457 - * add_option( 'auth_settings_advanced_admin_notice, 'Your message.' );
2458 - * It will display and then delete that message on the admin dashboard.
2459 - *
2460 - * Filter: admin_notices
2461 - * filter: network_admin_notices
2207 + * Filter: admin_notice
2462 2208 */
2463 - public function show_advanced_admin_notice() {
2209 + function show_advanced_admin_notice() {
2464 2210 $notice = get_option( 'auth_settings_advanced_admin_notice' );
2465 2211 delete_option( 'auth_settings_advanced_admin_notice' );
2466 2212
2467 - if ( $notice && strlen( $notice ) > 0 ) {
2468 - ?>
2213 + if ( $notice && strlen( $notice ) > 0 ) { ?>
2469 2214 <div class="error">
2470 - <p><?php echo wp_kses( $notice, $this->allowed_html ); ?></p>
2471 - </div>
2472 - <?php
2215 + <p><?php echo $notice; ?></p>
2216 + </div><?php
2473 2217 }
2474 2218 }
2475 2219
2476 2220
@@ -2475,11 +2219,9 @@
2475 2219
2476 2220
2477 2221 /**
2478 2222 * Add notices to the top of the options page.
2479 - *
2480 - * Action: load-settings_page_authorizer > admin_notices
2481 - *
2223 + * Run on action hook chain: load-settings_page_authorizer > admin_notices
2482 2224 * Description: Check for invalid settings combinations and show a warning message, e.g.:
2483 2225 * if ( cas url inaccessible ) : ?>
2484 2226 * <div class='updated settings-error'><p>Can't reach CAS server.</p></div>
2485 2227 * <?php endif;
@@ -2485,23 +2227,20 @@
2485 2227 * <?php endif;
2486 2228 */
2487 2229 public function admin_notices() {
2488 2230 // Grab plugin settings.
2489 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2231 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2490 2232
2491 - if ( '1' === $auth_settings['cas'] ) :
2233 + if ( $auth_settings['cas'] === '1' ) :
2492 2234 // Check if provided CAS URL is accessible.
2493 - $protocol = in_array( strval( $auth_settings['cas_port'] ), array( '80', '8080' ), true ) ? 'http' : 'https';
2494 - $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2495 - $legacy_cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint (old; some servers don't register a ./login endpoint, use serviceValidate instead).
2496 - $cas_url = trailingslashit( $cas_url ) . 'serviceValidate'; // Check the specific CAS login endpoint.
2497 - if ( ! $this->url_is_accessible( $cas_url ) && ! $this->url_is_accessible( $legacy_cas_url ) ) :
2498 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2499 - ?>
2500 - <div class='notice notice-warning is-dismissible'>
2501 - <p><?php esc_html_e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo esc_attr( $authorizer_options_url ); ?>&tab=external'><?php esc_html_e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php esc_html_e( 'if you intend to use it.', 'authorizer' ); ?></p>
2502 - </div>
2503 - <?php
2235 + $protocol = in_array( $auth_settings['cas_port'], array( '80', '8080' ) ) ? 'http' : 'https';
2236 + $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2237 + $cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint
2238 + if ( ! $this->url_is_accessible( $cas_url ) ) :
2239 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2240 + ?><div class='notice notice-warning is-dismissible'>
2241 + <p><?php _e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo $authorizer_options_url; ?>&tab=external'><?php _e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php _e( 'if you intend to use it.', 'authorizer' ); ?></p>
2242 + </div><?php
2504 2243 endif;
2505 2244 endif;
2506 2245 }
2507 2246
@@ -2506,430 +2245,399 @@
2506 2245 }
2507 2246
2508 2247
2509 2248 /**
2510 - * Create sections and options.
2511 - *
2512 - * Action: admin_init
2249 + * Create sections and options
2250 + * Run on action hook: admin_init
2513 2251 */
2514 2252 public function page_init() {
2515 - /**
2516 - * Create one setting that holds all the options (array).
2517 - *
2518 - * @see http://codex.wordpress.org/Function_Reference/register_setting
2519 - * @see http://codex.wordpress.org/Function_Reference/add_settings_section
2520 - * @see http://codex.wordpress.org/Function_Reference/add_settings_field
2521 - */
2253 + // Create one setting that holds all the options (array)
2254 + // @see http://codex.wordpress.org/Function_Reference/register_setting
2255 + // @see http://codex.wordpress.org/Function_Reference/add_settings_section
2256 + // @see http://codex.wordpress.org/Function_Reference/add_settings_field
2522 2257 register_setting(
2523 - 'auth_settings_group',
2524 - 'auth_settings',
2525 - array( $this, 'sanitize_options' )
2258 + 'auth_settings_group', // Option group
2259 + 'auth_settings', // Option name
2260 + array( $this, 'sanitize_options' ) // Sanitize callback
2526 2261 );
2527 2262
2528 2263 add_settings_section(
2529 - 'auth_settings_tabs',
2530 - '',
2531 - array( $this, 'print_section_info_tabs' ),
2532 - 'authorizer'
2264 + 'auth_settings_tabs', // HTML element ID
2265 + '', // HTML element Title
2266 + array( $this, 'print_section_info_tabs' ), // Callback (echos section content)
2267 + 'authorizer' // Page this section is shown on (slug)
2533 2268 );
2534 2269
2535 - // Create Access Lists section.
2270 + // Create Access Lists section
2536 2271 add_settings_section(
2537 - 'auth_settings_lists',
2538 - '',
2539 - array( $this, 'print_section_info_access_lists' ),
2540 - 'authorizer'
2272 + 'auth_settings_lists', // HTML element ID
2273 + '', // HTML element Title
2274 + array( $this, 'print_section_info_access_lists' ), // Callback (echos section content)
2275 + 'authorizer' // Page this section is shown on (slug)
2541 2276 );
2542 2277
2543 - // Create Login Access section.
2278 + // Create Login Access section
2544 2279 add_settings_section(
2545 - 'auth_settings_access_login',
2546 - '',
2547 - array( $this, 'print_section_info_access_login' ),
2548 - 'authorizer'
2280 + 'auth_settings_access_login', // HTML element ID
2281 + '', // HTML element Title
2282 + array( $this, 'print_section_info_access_login' ), // Callback (echos section content)
2283 + 'authorizer' // Page this section is shown on (slug)
2549 2284 );
2550 2285 add_settings_field(
2551 - 'auth_settings_access_who_can_login',
2552 - __( 'Who can log into the site?', 'authorizer' ),
2553 - array( $this, 'print_radio_auth_access_who_can_login' ),
2554 - 'authorizer',
2555 - 'auth_settings_access_login'
2286 + 'auth_settings_access_who_can_login', // HTML element ID
2287 + __( 'Who can log into the site?', 'authorizer' ), // HTML element Title
2288 + array( $this, 'print_radio_auth_access_who_can_login' ), // Callback (echos form element)
2289 + 'authorizer', // Page this setting is shown on (slug)
2290 + 'auth_settings_access_login' // Section this setting is shown on
2556 2291 );
2557 2292 add_settings_field(
2558 - 'auth_settings_access_role_receive_pending_emails',
2559 - __( 'Which role should receive email notifications about pending users?', 'authorizer' ),
2560 - array( $this, 'print_select_auth_access_role_receive_pending_emails' ),
2561 - 'authorizer',
2562 - 'auth_settings_access_login'
2293 + 'auth_settings_access_role_receive_pending_emails', // HTML element ID
2294 + __( 'Which role should receive email notifications about pending users?', 'authorizer' ), // HTML element Title
2295 + array( $this, 'print_select_auth_access_role_receive_pending_emails' ), // Callback (echos form element)
2296 + 'authorizer', // Page this setting is shown on (slug)
2297 + 'auth_settings_access_login' // Section this setting is shown on
2563 2298 );
2564 2299 add_settings_field(
2565 - 'auth_settings_access_pending_redirect_to_message',
2566 - __( 'What message should pending users see after attempting to log in?', 'authorizer' ),
2567 - array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ),
2568 - 'authorizer',
2569 - 'auth_settings_access_login'
2300 + 'auth_settings_access_pending_redirect_to_message', // HTML element ID
2301 + __( 'What message should pending users see after attempting to log in?', 'authorizer' ), // HTML element Title
2302 + array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ), // Callback (echos form element)
2303 + 'authorizer', // Page this setting is shown on (slug)
2304 + 'auth_settings_access_login' // Section this setting is shown on
2570 2305 );
2571 2306 add_settings_field(
2572 - 'auth_settings_access_blocked_redirect_to_message',
2573 - __( 'What message should blocked users see after attempting to log in?', 'authorizer' ),
2574 - array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ),
2575 - 'authorizer',
2576 - 'auth_settings_access_login'
2307 + 'auth_settings_access_blocked_redirect_to_message', // HTML element ID
2308 + __( 'What message should blocked users see after attempting to log in?', 'authorizer' ), // HTML element Title
2309 + array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ), // Callback (echos form element)
2310 + 'authorizer', // Page this setting is shown on (slug)
2311 + 'auth_settings_access_login' // Section this setting is shown on
2577 2312 );
2578 2313 add_settings_field(
2579 - 'auth_settings_access_should_email_approved_users',
2580 - __( 'Send welcome email to new approved users?', 'authorizer' ),
2581 - array( $this, 'print_checkbox_auth_access_should_email_approved_users' ),
2582 - 'authorizer',
2583 - 'auth_settings_access_login'
2314 + 'auth_settings_access_should_email_approved_users', // HTML element ID
2315 + __( 'Send welcome email to new approved users?', 'authorizer' ), // HTML element Title
2316 + array( $this, 'print_checkbox_auth_access_should_email_approved_users' ), // Callback (echos form element)
2317 + 'authorizer', // Page this setting is shown on (slug)
2318 + 'auth_settings_access_login' // Section this setting is shown on
2584 2319 );
2585 2320 add_settings_field(
2586 - 'auth_settings_access_email_approved_users_subject',
2587 - __( 'Welcome email subject', 'authorizer' ),
2588 - array( $this, 'print_text_auth_access_email_approved_users_subject' ),
2589 - 'authorizer',
2590 - 'auth_settings_access_login'
2321 + 'auth_settings_access_email_approved_users_subject', // HTML element ID
2322 + __( 'Welcome email subject', 'authorizer' ), // HTML element Title
2323 + array( $this, 'print_text_auth_access_email_approved_users_subject' ), // Callback (echos form element)
2324 + 'authorizer', // Page this setting is shown on (slug)
2325 + 'auth_settings_access_login' // Section this setting is shown on
2591 2326 );
2592 2327 add_settings_field(
2593 - 'auth_settings_access_email_approved_users_body',
2594 - __( 'Welcome email body', 'authorizer' ),
2595 - array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ),
2596 - 'authorizer',
2597 - 'auth_settings_access_login'
2328 + 'auth_settings_access_email_approved_users_body', // HTML element ID
2329 + __( 'Welcome email body', 'authorizer' ), // HTML element Title
2330 + array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ), // Callback (echos form element)
2331 + 'authorizer', // Page this setting is shown on (slug)
2332 + 'auth_settings_access_login' // Section this setting is shown on
2598 2333 );
2599 2334
2600 - // Create Public Access section.
2335 +
2336 + // Create Public Access section
2601 2337 add_settings_section(
2602 - 'auth_settings_access_public',
2603 - '',
2604 - array( $this, 'print_section_info_access_public' ),
2605 - 'authorizer'
2338 + 'auth_settings_access_public', // HTML element ID
2339 + '', // HTML element Title
2340 + array( $this, 'print_section_info_access_public' ), // Callback (echos section content)
2341 + 'authorizer' // Page this section is shown on (slug)
2606 2342 );
2607 2343 add_settings_field(
2608 - 'auth_settings_access_who_can_view',
2609 - __( 'Who can view the site?', 'authorizer' ),
2610 - array( $this, 'print_radio_auth_access_who_can_view' ),
2611 - 'authorizer',
2612 - 'auth_settings_access_public'
2344 + 'auth_settings_access_who_can_view', // HTML element ID
2345 + __( 'Who can view the site?', 'authorizer' ), // HTML element Title
2346 + array( $this, 'print_radio_auth_access_who_can_view' ), // Callback (echos form element)
2347 + 'authorizer', // Page this setting is shown on (slug)
2348 + 'auth_settings_access_public' // Section this setting is shown on
2613 2349 );
2614 2350 add_settings_field(
2615 - 'auth_settings_access_public_pages',
2616 - __( 'What pages (if any) should be available to everyone?', 'authorizer' ),
2617 - array( $this, 'print_multiselect_auth_access_public_pages' ),
2618 - 'authorizer',
2619 - 'auth_settings_access_public'
2351 + 'auth_settings_access_public_pages', // HTML element ID
2352 + __( 'What pages (if any) should be available to everyone?', 'authorizer' ), // HTML element Title
2353 + array( $this, 'print_multiselect_auth_access_public_pages' ), // Callback (echos form element)
2354 + 'authorizer', // Page this setting is shown on (slug)
2355 + 'auth_settings_access_public' // Section this setting is shown on
2620 2356 );
2621 2357 add_settings_field(
2622 - 'auth_settings_access_redirect',
2623 - __( 'What happens to people without access when they visit a private page?', 'authorizer' ),
2624 - array( $this, 'print_radio_auth_access_redirect' ),
2625 - 'authorizer',
2626 - 'auth_settings_access_public'
2358 + 'auth_settings_access_redirect', // HTML element ID
2359 + __( 'What happens to people without access when they visit a private page?', 'authorizer' ), // HTML element Title
2360 + array( $this, 'print_radio_auth_access_redirect' ), // Callback (echos form element)
2361 + 'authorizer', // Page this setting is shown on (slug)
2362 + 'auth_settings_access_public' // Section this setting is shown on
2627 2363 );
2628 2364 add_settings_field(
2629 - 'auth_settings_access_public_warning',
2630 - __( 'What happens to people without access when they visit a public page?', 'authorizer' ),
2631 - array( $this, 'print_radio_auth_access_public_warning' ),
2632 - 'authorizer',
2633 - 'auth_settings_access_public'
2365 + 'auth_settings_access_public_warning', // HTML element ID
2366 + __( 'What happens to people without access when they visit a public page?', 'authorizer' ), // HTML element Title
2367 + array( $this, 'print_radio_auth_access_public_warning' ), // Callback (echos form element)
2368 + 'authorizer', // Page this setting is shown on (slug)
2369 + 'auth_settings_access_public' // Section this setting is shown on
2634 2370 );
2635 2371 add_settings_field(
2636 - 'auth_settings_access_redirect_to_message',
2637 - __( 'What message should people without access see?', 'authorizer' ),
2638 - array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ),
2639 - 'authorizer',
2640 - 'auth_settings_access_public'
2372 + 'auth_settings_access_redirect_to_message', // HTML element ID
2373 + __( 'What message should people without access see?', 'authorizer' ), // HTML element Title
2374 + array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ), // Callback (echos form element)
2375 + 'authorizer', // Page this setting is shown on (slug)
2376 + 'auth_settings_access_public' // Section this setting is shown on
2641 2377 );
2642 2378
2643 - // Create External Service Settings section.
2379 + // Create External Service Settings section
2644 2380 add_settings_section(
2645 - 'auth_settings_external',
2646 - '',
2647 - array( $this, 'print_section_info_external' ),
2648 - 'authorizer'
2381 + 'auth_settings_external', // HTML element ID
2382 + '', // HTML element Title
2383 + array( $this, 'print_section_info_external' ), // Callback (echos section content)
2384 + 'authorizer' // Page this section is shown on (slug)
2649 2385 );
2650 2386 add_settings_field(
2651 - 'auth_settings_access_default_role',
2652 - __( 'Default role for new users', 'authorizer' ),
2653 - array( $this, 'print_select_auth_access_default_role' ),
2654 - 'authorizer',
2655 - 'auth_settings_external'
2387 + 'auth_settings_access_default_role', // HTML element ID
2388 + __( 'Default role for new users', 'authorizer' ), // HTML element Title
2389 + array( $this, 'print_select_auth_access_default_role' ), // Callback (echos form element)
2390 + 'authorizer', // Page this setting is shown on (slug)
2391 + 'auth_settings_external' // Section this setting is shown on
2656 2392 );
2657 2393 add_settings_field(
2658 - 'auth_settings_external_google',
2659 - __( 'Google Logins', 'authorizer' ),
2660 - array( $this, 'print_checkbox_auth_external_google' ),
2661 - 'authorizer',
2662 - 'auth_settings_external'
2394 + 'auth_settings_external_google', // HTML element ID
2395 + __( 'Google Logins', 'authorizer' ), // HTML element Title
2396 + array( $this, 'print_checkbox_auth_external_google' ), // Callback (echos form element)
2397 + 'authorizer', // Page this setting is shown on (slug)
2398 + 'auth_settings_external' // Section this setting is shown on
2663 2399 );
2664 2400 add_settings_field(
2665 - 'auth_settings_google_clientid',
2666 - __( 'Google Client ID', 'authorizer' ),
2667 - array( $this, 'print_text_google_clientid' ),
2668 - 'authorizer',
2669 - 'auth_settings_external'
2401 + 'auth_settings_google_clientid', // HTML element ID
2402 + __( 'Google Client ID', 'authorizer' ), // HTML element Title
2403 + array( $this, 'print_text_google_clientid' ), // Callback (echos form element)
2404 + 'authorizer', // Page this setting is shown on (slug)
2405 + 'auth_settings_external' // Section this setting is shown on
2670 2406 );
2671 2407 add_settings_field(
2672 - 'auth_settings_google_clientsecret',
2673 - __( 'Google Client Secret', 'authorizer' ),
2674 - array( $this, 'print_text_google_clientsecret' ),
2675 - 'authorizer',
2676 - 'auth_settings_external'
2408 + 'auth_settings_google_clientsecret', // HTML element ID
2409 + __( 'Google Client Secret', 'authorizer' ), // HTML element Title
2410 + array( $this, 'print_text_google_clientsecret' ), // Callback (echos form element)
2411 + 'authorizer', // Page this setting is shown on (slug)
2412 + 'auth_settings_external' // Section this setting is shown on
2677 2413 );
2678 2414 add_settings_field(
2679 - 'auth_settings_google_hosteddomain',
2680 - __( 'Google Hosted Domain', 'authorizer' ),
2681 - array( $this, 'print_text_google_hosteddomain' ),
2682 - 'authorizer',
2683 - 'auth_settings_external'
2415 + 'auth_settings_google_hosteddomain', // HTML element ID
2416 + __( 'Google Hosted Domain', 'authorizer' ), // HTML element Title
2417 + array( $this, 'print_text_google_hosteddomain' ), // Callback (echos form element)
2418 + 'authorizer', // Page this setting is shown on (slug)
2419 + 'auth_settings_external' // Section this setting is shown on
2684 2420 );
2685 2421 add_settings_field(
2686 - 'auth_settings_external_cas',
2687 - __( 'CAS Logins', 'authorizer' ),
2688 - array( $this, 'print_checkbox_auth_external_cas' ),
2689 - 'authorizer',
2690 - 'auth_settings_external'
2422 + 'auth_settings_external_cas', // HTML element ID
2423 + __( 'CAS Logins', 'authorizer' ), // HTML element Title
2424 + array( $this, 'print_checkbox_auth_external_cas' ), // Callback (echos form element)
2425 + 'authorizer', // Page this setting is shown on (slug)
2426 + 'auth_settings_external' // Section this setting is shown on
2691 2427 );
2692 2428 add_settings_field(
2693 - 'auth_settings_cas_custom_label',
2694 - __( 'CAS custom label', 'authorizer' ),
2695 - array( $this, 'print_text_cas_custom_label' ),
2696 - 'authorizer',
2697 - 'auth_settings_external'
2429 + 'auth_settings_cas_custom_label', // HTML element ID
2430 + __( 'CAS custom label', 'authorizer' ), // HTML element Title
2431 + array( $this, 'print_text_cas_custom_label' ), // Callback (echos form element)
2432 + 'authorizer', // Page this setting is shown on (slug)
2433 + 'auth_settings_external' // Section this setting is shown on
2698 2434 );
2699 2435 add_settings_field(
2700 - 'auth_settings_cas_host',
2701 - __( 'CAS server hostname', 'authorizer' ),
2702 - array( $this, 'print_text_cas_host' ),
2703 - 'authorizer',
2704 - 'auth_settings_external'
2436 + 'auth_settings_cas_host', // HTML element ID
2437 + __( 'CAS server hostname', 'authorizer' ), // HTML element Title
2438 + array( $this, 'print_text_cas_host' ), // Callback (echos form element)
2439 + 'authorizer', // Page this setting is shown on (slug)
2440 + 'auth_settings_external' // Section this setting is shown on
2705 2441 );
2706 2442 add_settings_field(
2707 - 'auth_settings_cas_port',
2708 - __( 'CAS server port', 'authorizer' ),
2709 - array( $this, 'print_text_cas_port' ),
2710 - 'authorizer',
2711 - 'auth_settings_external'
2443 + 'auth_settings_cas_port', // HTML element ID
2444 + __( 'CAS server port', 'authorizer' ), // HTML element Title
2445 + array( $this, 'print_text_cas_port' ), // Callback (echos form element)
2446 + 'authorizer', // Page this setting is shown on (slug)
2447 + 'auth_settings_external' // Section this setting is shown on
2712 2448 );
2713 2449 add_settings_field(
2714 - 'auth_settings_cas_path',
2715 - __( 'CAS server path/context', 'authorizer' ),
2716 - array( $this, 'print_text_cas_path' ),
2717 - 'authorizer',
2718 - 'auth_settings_external'
2450 + 'auth_settings_cas_path', // HTML element ID
2451 + __( 'CAS server path/context', 'authorizer' ), // HTML element Title
2452 + array( $this, 'print_text_cas_path' ), // Callback (echos form element)
2453 + 'authorizer', // Page this setting is shown on (slug)
2454 + 'auth_settings_external' // Section this setting is shown on
2719 2455 );
2720 2456 add_settings_field(
2721 - 'auth_settings_cas_version',
2722 - 'CAS server version',
2723 - array( $this, 'print_select_cas_version' ),
2724 - 'authorizer',
2725 - 'auth_settings_external'
2457 + 'auth_settings_cas_version', // HTML element ID
2458 + 'CAS server version', // HTML element Title
2459 + array( $this, 'print_select_cas_version' ), // Callback (echos form element)
2460 + 'authorizer', // Page this setting is shown on (slug)
2461 + 'auth_settings_external' // Section this setting is shown on
2726 2462 );
2727 2463 add_settings_field(
2728 - 'auth_settings_cas_attr_email',
2729 - __( 'CAS attribute containing email address', 'authorizer' ),
2730 - array( $this, 'print_text_cas_attr_email' ),
2731 - 'authorizer',
2732 - 'auth_settings_external'
2464 + 'auth_settings_cas_attr_email', // HTML element ID
2465 + __( 'CAS attribute containing email address', 'authorizer' ), // HTML element Title
2466 + array( $this, 'print_text_cas_attr_email' ), // Callback (echos form element)
2467 + 'authorizer', // Page this setting is shown on (slug)
2468 + 'auth_settings_external' // Section this setting is shown on
2733 2469 );
2734 2470 add_settings_field(
2735 - 'auth_settings_cas_attr_first_name',
2736 - __( 'CAS attribute containing first name', 'authorizer' ),
2737 - array( $this, 'print_text_cas_attr_first_name' ),
2738 - 'authorizer',
2739 - 'auth_settings_external'
2471 + 'auth_settings_cas_attr_first_name', // HTML element ID
2472 + __( 'CAS attribute containing first name', 'authorizer' ), // HTML element Title
2473 + array( $this, 'print_text_cas_attr_first_name' ), // Callback (echos form element)
2474 + 'authorizer', // Page this setting is shown on (slug)
2475 + 'auth_settings_external' // Section this setting is shown on
2740 2476 );
2741 2477 add_settings_field(
2742 - 'auth_settings_cas_attr_last_name',
2743 - __( 'CAS attribute containing last name', 'authorizer' ),
2744 - array( $this, 'print_text_cas_attr_last_name' ),
2745 - 'authorizer',
2746 - 'auth_settings_external'
2478 + 'auth_settings_cas_attr_last_name', // HTML element ID
2479 + __( 'CAS attribute containing last name', 'authorizer' ), // HTML element Title
2480 + array( $this, 'print_text_cas_attr_last_name' ), // Callback (echos form element)
2481 + 'authorizer', // Page this setting is shown on (slug)
2482 + 'auth_settings_external' // Section this setting is shown on
2747 2483 );
2748 2484 add_settings_field(
2749 - 'auth_settings_cas_attr_update_on_login',
2750 - __( 'CAS attribute update', 'authorizer' ),
2751 - array( $this, 'print_checkbox_cas_attr_update_on_login' ),
2752 - 'authorizer',
2753 - 'auth_settings_external'
2485 + 'auth_settings_cas_attr_update_on_login', // HTML element ID
2486 + __( 'CAS attribute update', 'authorizer' ), // HTML element Title
2487 + array( $this, 'print_checkbox_cas_attr_update_on_login' ), // Callback (echos form element)
2488 + 'authorizer', // Page this setting is shown on (slug)
2489 + 'auth_settings_external' // Section this setting is shown on
2754 2490 );
2755 2491 add_settings_field(
2756 - 'auth_settings_cas_auto_login',
2757 - __( 'CAS automatic login', 'authorizer' ),
2758 - array( $this, 'print_checkbox_cas_auto_login' ),
2759 - 'authorizer',
2760 - 'auth_settings_external'
2492 + 'auth_settings_cas_auto_login', // HTML element ID
2493 + __( 'CAS automatic login', 'authorizer' ), // HTML element Title
2494 + array( $this, 'print_checkbox_cas_auto_login' ), // Callback (echos form element)
2495 + 'authorizer', // Page this setting is shown on (slug)
2496 + 'auth_settings_external' // Section this setting is shown on
2761 2497 );
2762 2498 add_settings_field(
2763 - 'auth_settings_external_ldap',
2764 - __( 'LDAP Logins', 'authorizer' ),
2765 - array( $this, 'print_checkbox_auth_external_ldap' ),
2766 - 'authorizer',
2767 - 'auth_settings_external'
2499 + 'auth_settings_external_ldap', // HTML element ID
2500 + __( 'LDAP Logins', 'authorizer' ), // HTML element Title
2501 + array( $this, 'print_checkbox_auth_external_ldap' ), // Callback (echos form element)
2502 + 'authorizer', // Page this setting is shown on (slug)
2503 + 'auth_settings_external' // Section this setting is shown on
2768 2504 );
2769 2505 add_settings_field(
2770 - 'auth_settings_ldap_host',
2771 - __( 'LDAP Host', 'authorizer' ),
2772 - array( $this, 'print_text_ldap_host' ),
2773 - 'authorizer',
2774 - 'auth_settings_external'
2506 + 'auth_settings_ldap_host', // HTML element ID
2507 + __( 'LDAP Host', 'authorizer' ), // HTML element Title
2508 + array( $this, 'print_text_ldap_host' ), // Callback (echos form element)
2509 + 'authorizer', // Page this setting is shown on (slug)
2510 + 'auth_settings_external' // Section this setting is shown on
2775 2511 );
2776 2512 add_settings_field(
2777 - 'auth_settings_ldap_port',
2778 - __( 'LDAP Port', 'authorizer' ),
2779 - array( $this, 'print_text_ldap_port' ),
2780 - 'authorizer',
2781 - 'auth_settings_external'
2513 + 'auth_settings_ldap_port', // HTML element ID
2514 + __( 'LDAP Port', 'authorizer' ), // HTML element Title
2515 + array( $this, 'print_text_ldap_port' ), // Callback (echos form element)
2516 + 'authorizer', // Page this setting is shown on (slug)
2517 + 'auth_settings_external' // Section this setting is shown on
2782 2518 );
2783 2519 add_settings_field(
2784 - 'auth_settings_ldap_tls',
2785 - __( 'Use TLS', 'authorizer' ),
2786 - array( $this, 'print_checkbox_ldap_tls' ),
2787 - 'authorizer',
2788 - 'auth_settings_external'
2520 + 'auth_settings_ldap_tls', // HTML element ID
2521 + __( 'Secure Connection (TLS)', 'authorizer' ), // HTML element Title
2522 + array( $this, 'print_checkbox_ldap_tls' ), // Callback (echos form element)
2523 + 'authorizer', // Page this setting is shown on (slug)
2524 + 'auth_settings_external' // Section this setting is shown on
2789 2525 );
2790 2526 add_settings_field(
2791 - 'auth_settings_ldap_search_base',
2792 - __( 'LDAP Search Base', 'authorizer' ),
2793 - array( $this, 'print_text_ldap_search_base' ),
2794 - 'authorizer',
2795 - 'auth_settings_external'
2527 + 'auth_settings_ldap_search_base', // HTML element ID
2528 + __( 'LDAP Search Base', 'authorizer' ), // HTML element Title
2529 + array( $this, 'print_text_ldap_search_base' ), // Callback (echos form element)
2530 + 'authorizer', // Page this setting is shown on (slug)
2531 + 'auth_settings_external' // Section this setting is shown on
2796 2532 );
2797 2533 add_settings_field(
2798 - 'auth_settings_ldap_uid',
2799 - __( 'LDAP attribute containing username', 'authorizer' ),
2800 - array( $this, 'print_text_ldap_uid' ),
2801 - 'authorizer',
2802 - 'auth_settings_external'
2534 + 'auth_settings_ldap_uid', // HTML element ID
2535 + __( 'LDAP attribute containing username', 'authorizer' ), // HTML element Title
2536 + array( $this, 'print_text_ldap_uid' ), // Callback (echos form element)
2537 + 'authorizer', // Page this setting is shown on (slug)
2538 + 'auth_settings_external' // Section this setting is shown on
2803 2539 );
2804 2540 add_settings_field(
2805 - 'auth_settings_ldap_attr_email',
2806 - __( 'LDAP attribute containing email address', 'authorizer' ),
2807 - array( $this, 'print_text_ldap_attr_email' ),
2808 - 'authorizer',
2809 - 'auth_settings_external'
2541 + 'auth_settings_ldap_attr_email', // HTML element ID
2542 + __( 'LDAP attribute containing email address', 'authorizer' ), // HTML element Title
2543 + array( $this, 'print_text_ldap_attr_email' ), // Callback (echos form element)
2544 + 'authorizer', // Page this setting is shown on (slug)
2545 + 'auth_settings_external' // Section this setting is shown on
2810 2546 );
2811 2547 add_settings_field(
2812 - 'auth_settings_ldap_user',
2813 - __( 'LDAP Directory User', 'authorizer' ),
2814 - array( $this, 'print_text_ldap_user' ),
2815 - 'authorizer',
2816 - 'auth_settings_external'
2548 + 'auth_settings_ldap_user', // HTML element ID
2549 + __( 'LDAP Directory User', 'authorizer' ), // HTML element Title
2550 + array( $this, 'print_text_ldap_user' ), // Callback (echos form element)
2551 + 'authorizer', // Page this setting is shown on (slug)
2552 + 'auth_settings_external' // Section this setting is shown on
2817 2553 );
2818 2554 add_settings_field(
2819 - 'auth_settings_ldap_password',
2820 - __( 'LDAP Directory User Password', 'authorizer' ),
2821 - array( $this, 'print_password_ldap_password' ),
2822 - 'authorizer',
2823 - 'auth_settings_external'
2555 + 'auth_settings_ldap_password', // HTML element ID
2556 + __( 'LDAP Directory User Password', 'authorizer' ), // HTML element Title
2557 + array( $this, 'print_password_ldap_password' ), // Callback (echos form element)
2558 + 'authorizer', // Page this setting is shown on (slug)
2559 + 'auth_settings_external' // Section this setting is shown on
2824 2560 );
2825 2561 add_settings_field(
2826 - 'auth_settings_ldap_lostpassword_url',
2827 - __( 'Custom lost password URL', 'authorizer' ),
2828 - array( $this, 'print_text_ldap_lostpassword_url' ),
2829 - 'authorizer',
2830 - 'auth_settings_external'
2562 + 'auth_settings_ldap_lostpassword_url', // HTML element ID
2563 + __( 'Custom lost password URL', 'authorizer' ), // HTML element Title
2564 + array( $this, 'print_text_ldap_lostpassword_url' ), // Callback (echos form element)
2565 + 'authorizer', // Page this setting is shown on (slug)
2566 + 'auth_settings_external' // Section this setting is shown on
2831 2567 );
2832 2568 add_settings_field(
2833 - 'auth_settings_ldap_attr_first_name',
2834 - __( 'LDAP attribute containing first name', 'authorizer' ),
2835 - array( $this, 'print_text_ldap_attr_first_name' ),
2836 - 'authorizer',
2837 - 'auth_settings_external'
2569 + 'auth_settings_ldap_attr_first_name', // HTML element ID
2570 + __( 'LDAP attribute containing first name', 'authorizer' ), // HTML element Title
2571 + array( $this, 'print_text_ldap_attr_first_name' ), // Callback (echos form element)
2572 + 'authorizer', // Page this setting is shown on (slug)
2573 + 'auth_settings_external' // Section this setting is shown on
2838 2574 );
2839 2575 add_settings_field(
2840 - 'auth_settings_ldap_attr_last_name',
2841 - __( 'LDAP attribute containing last name', 'authorizer' ),
2842 - array( $this, 'print_text_ldap_attr_last_name' ),
2843 - 'authorizer',
2844 - 'auth_settings_external'
2576 + 'auth_settings_ldap_attr_last_name', // HTML element ID
2577 + __( 'LDAP attribute containing last name', 'authorizer' ), // HTML element Title
2578 + array( $this, 'print_text_ldap_attr_last_name' ), // Callback (echos form element)
2579 + 'authorizer', // Page this setting is shown on (slug)
2580 + 'auth_settings_external' // Section this setting is shown on
2845 2581 );
2846 2582 add_settings_field(
2847 - 'auth_settings_ldap_attr_update_on_login',
2848 - __( 'LDAP attribute update', 'authorizer' ),
2849 - array( $this, 'print_checkbox_ldap_attr_update_on_login' ),
2850 - 'authorizer',
2851 - 'auth_settings_external'
2583 + 'auth_settings_ldap_attr_update_on_login', // HTML element ID
2584 + __( 'LDAP attribute update', 'authorizer' ), // HTML element Title
2585 + array( $this, 'print_checkbox_ldap_attr_update_on_login' ), // Callback (echos form element)
2586 + 'authorizer', // Page this setting is shown on (slug)
2587 + 'auth_settings_external' // Section this setting is shown on
2852 2588 );
2853 2589
2854 - // Create Advanced Settings section.
2590 + // Create Advanced Settings section
2855 2591 add_settings_section(
2856 - 'auth_settings_advanced',
2857 - '',
2858 - array( $this, 'print_section_info_advanced' ),
2859 - 'authorizer'
2592 + 'auth_settings_advanced', // HTML element ID
2593 + '', // HTML element Title
2594 + array( $this, 'print_section_info_advanced' ), // Callback (echos section content)
2595 + 'authorizer' // Page this section is shown on (slug)
2860 2596 );
2861 2597 add_settings_field(
2862 - 'auth_settings_advanced_lockouts',
2863 - __( 'Limit invalid login attempts', 'authorizer' ),
2864 - array( $this, 'print_text_auth_advanced_lockouts' ),
2865 - 'authorizer',
2866 - 'auth_settings_advanced'
2598 + 'auth_settings_advanced_lockouts', // HTML element ID
2599 + __( 'Limit invalid login attempts', 'authorizer' ), // HTML element Title
2600 + array( $this, 'print_text_auth_advanced_lockouts' ), // Callback (echos form element)
2601 + 'authorizer', // Page this setting is shown on (slug)
2602 + 'auth_settings_advanced' // Section this setting is shown on
2867 2603 );
2868 2604 add_settings_field(
2869 - 'auth_settings_advanced_hide_wp_login',
2870 - __( 'Hide WordPress Login', 'authorizer' ),
2871 - array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ),
2872 - 'authorizer',
2873 - 'auth_settings_advanced'
2605 + 'auth_settings_advanced_hide_wp_login', // HTML element ID
2606 + __( 'Hide WordPress Login', 'authorizer' ), // HTML element Title
2607 + array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ), // Callback (echos form element)
2608 + 'authorizer', // Page this setting is shown on (slug)
2609 + 'auth_settings_advanced' // Section this setting is shown on
2874 2610 );
2875 2611 add_settings_field(
2876 - 'auth_settings_advanced_branding',
2877 - __( 'Custom WordPress login branding', 'authorizer' ),
2878 - array( $this, 'print_radio_auth_advanced_branding' ),
2879 - 'authorizer',
2880 - 'auth_settings_advanced'
2612 + 'auth_settings_advanced_branding', // HTML element ID
2613 + __( 'Custom WordPress login branding', 'authorizer' ), // HTML element Title
2614 + array( $this, 'print_radio_auth_advanced_branding' ), // Callback (echos form element)
2615 + 'authorizer', // Page this setting is shown on (slug)
2616 + 'auth_settings_advanced' // Section this setting is shown on
2881 2617 );
2882 2618 add_settings_field(
2883 - 'auth_settings_advanced_admin_menu',
2884 - __( 'Authorizer admin menu item location', 'authorizer' ),
2885 - array( $this, 'print_radio_auth_advanced_admin_menu' ),
2886 - 'authorizer',
2887 - 'auth_settings_advanced'
2619 + 'auth_settings_advanced_admin_menu', // HTML element ID
2620 + __( 'Authorizer admin menu item location', 'authorizer' ), // HTML element Title
2621 + array( $this, 'print_radio_auth_advanced_admin_menu' ), // Callback (echos form element)
2622 + 'authorizer', // Page this setting is shown on (slug)
2623 + 'auth_settings_advanced' // Section this setting is shown on
2888 2624 );
2889 2625 add_settings_field(
2890 - 'auth_settings_advanced_usermeta',
2891 - __( 'Show custom usermeta in user list', 'authorizer' ),
2892 - array( $this, 'print_select_auth_advanced_usermeta' ),
2893 - 'authorizer',
2894 - 'auth_settings_advanced'
2626 + 'auth_settings_advanced_usermeta', // HTML element ID
2627 + __( 'Show custom usermeta in user list', 'authorizer' ), // HTML element Title
2628 + array( $this, 'print_select_auth_advanced_usermeta' ), // Callback (echos form element)
2629 + 'authorizer', // Page this setting is shown on (slug)
2630 + 'auth_settings_advanced' // Section this setting is shown on
2895 2631 );
2896 - add_settings_field(
2897 - 'auth_settings_advanced_users_per_page',
2898 - __( 'Number of users per page', 'authorizer' ),
2899 - array( $this, 'print_text_auth_advanced_users_per_page' ),
2900 - 'authorizer',
2901 - 'auth_settings_advanced'
2902 - );
2903 - add_settings_field(
2904 - 'auth_settings_advanced_users_sort_by',
2905 - __( 'Approved users sort method', 'authorizer' ),
2906 - array( $this, 'print_select_auth_advanced_users_sort_by' ),
2907 - 'authorizer',
2908 - 'auth_settings_advanced'
2909 - );
2910 - add_settings_field(
2911 - 'auth_settings_advanced_users_sort_order',
2912 - __( 'Approved users sort order', 'authorizer' ),
2913 - array( $this, 'print_select_auth_advanced_users_sort_order' ),
2914 - 'authorizer',
2915 - 'auth_settings_advanced'
2916 - );
2917 - add_settings_field(
2918 - 'auth_settings_advanced_widget_enabled',
2919 - __( 'Show dashboard widget to admin users', 'authorizer' ),
2920 - array( $this, 'print_checkbox_auth_advanced_widget_enabled' ),
2921 - 'authorizer',
2922 - 'auth_settings_advanced'
2923 - );
2924 2632 // On multisite installs, add an option to override all multisite settings on individual sites.
2925 2633 if ( is_multisite() ) {
2926 2634 add_settings_field(
2927 - 'auth_settings_advanced_override_multisite',
2928 - __( 'Override multisite options', 'authorizer' ),
2929 - array( $this, 'print_checkbox_auth_advanced_override_multisite' ),
2930 - 'authorizer',
2931 - 'auth_settings_advanced'
2635 + 'auth_settings_advanced_override_multisite', // HTML element ID
2636 + __( 'Override multisite options', 'authorizer' ), // HTML element Title
2637 + array( $this, 'print_checkbox_auth_advanced_override_multisite' ), // Callback (echos form element)
2638 + 'authorizer', // Page this setting is shown on (slug)
2639 + 'auth_settings_advanced' // Section this setting is shown on
2932 2640 );
2933 2641 }
2934 2642 }
2935 2643
@@ -2935,30 +2643,29 @@
2935 2643
2936 2644
2937 2645 /**
2938 2646 * Set meaningful defaults for the plugin options.
2939 - *
2940 2647 * Note: This function is called on plugin activation.
2941 2648 */
2942 - private function set_default_options() {
2649 + function set_default_options() {
2943 2650 global $wp_roles;
2944 2651
2945 2652 $auth_settings = get_option( 'auth_settings' );
2946 - if ( false === $auth_settings ) {
2653 + if ( $auth_settings === FALSE ) {
2947 2654 $auth_settings = array();
2948 2655 }
2949 2656
2950 2657 // Access Lists Defaults.
2951 2658 $auth_settings_access_users_pending = get_option( 'auth_settings_access_users_pending' );
2952 - if ( false === $auth_settings_access_users_pending ) {
2659 + if ( $auth_settings_access_users_pending === FALSE ) {
2953 2660 $auth_settings_access_users_pending = array();
2954 2661 }
2955 2662 $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
2956 - if ( false === $auth_settings_access_users_approved ) {
2663 + if ( $auth_settings_access_users_approved === FALSE ) {
2957 2664 $auth_settings_access_users_approved = array();
2958 2665 }
2959 2666 $auth_settings_access_users_blocked = get_option( 'auth_settings_access_users_blocked' );
2960 - if ( false === $auth_settings_access_users_blocked ) {
2667 + if ( $auth_settings_access_users_blocked === FALSE ) {
2961 2668 $auth_settings_access_users_blocked = array();
2962 2669 }
2963 2670
2964 2671 // Login Access Defaults.
@@ -3010,12 +2717,13 @@
3010 2717 if ( ! array_key_exists( 'access_redirect_to_message', $auth_settings ) ) {
3011 2718 $auth_settings['access_redirect_to_message'] = '<p>' . __( 'Notice: You are browsing this site anonymously, and only have access to a portion of its content.', 'authorizer' ) . '</p>';
3012 2719 }
3013 2720
2721 +
3014 2722 // External Service Defaults.
3015 2723 if ( ! array_key_exists( 'access_default_role', $auth_settings ) ) {
3016 2724 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3017 - $all_roles = $wp_roles->roles;
2725 + $all_roles = $wp_roles->roles;
3018 2726 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3019 2727 if ( array_key_exists( 'student', $editable_roles ) ) {
3020 2728 $auth_settings['access_default_role'] = 'student';
3021 2729 } else {
@@ -3113,12 +2821,12 @@
3113 2821
3114 2822 // Advanced defaults.
3115 2823 if ( ! array_key_exists( 'advanced_lockouts', $auth_settings ) ) {
3116 2824 $auth_settings['advanced_lockouts'] = array(
3117 - 'attempts_1' => 10,
3118 - 'duration_1' => 1,
3119 - 'attempts_2' => 10,
3120 - 'duration_2' => 10,
2825 + 'attempts_1' => 10,
2826 + 'duration_1' => 1,
2827 + 'attempts_2' => 10,
2828 + 'duration_2' => 10,
3121 2829 'reset_duration' => 120,
3122 2830 );
3123 2831 }
3124 2832 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_settings ) ) {
@@ -3132,20 +2840,8 @@
3132 2840 }
3133 2841 if ( ! array_key_exists( 'advanced_usermeta', $auth_settings ) ) {
3134 2842 $auth_settings['advanced_usermeta'] = '';
3135 2843 }
3136 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_settings ) ) {
3137 - $auth_settings['advanced_users_per_page'] = 20;
3138 - }
3139 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_settings ) ) {
3140 - $auth_settings['advanced_users_sort_by'] = 'created';
3141 - }
3142 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_settings ) ) {
3143 - $auth_settings['advanced_users_sort_order'] = 'asc';
3144 - }
3145 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_settings ) ) {
3146 - $auth_settings['advanced_widget_enabled'] = '1';
3147 - }
3148 2844 if ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) ) {
3149 2845 $auth_settings['advanced_override_multisite'] = '';
3150 2846 }
3151 2847
@@ -3156,11 +2852,11 @@
3156 2852 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
3157 2853
3158 2854 // Multisite defaults.
3159 2855 if ( is_multisite() ) {
3160 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
2856 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
3161 2857
3162 - if ( false === $auth_multisite_settings ) {
2858 + if ( $auth_multisite_settings === FALSE ) {
3163 2859 $auth_multisite_settings = array();
3164 2860 }
3165 2861 // Global switch for enabling multisite options.
3166 2862 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
@@ -3166,10 +2862,10 @@
3166 2862 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
3167 2863 $auth_multisite_settings['multisite_override'] = '';
3168 2864 }
3169 2865 // Access Lists Defaults.
3170 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved' );
3171 - if ( false === $auth_multisite_settings_access_users_approved ) {
2866 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved' );
2867 + if ( $auth_multisite_settings_access_users_approved === FALSE ) {
3172 2868 $auth_multisite_settings_access_users_approved = array();
3173 2869 }
3174 2870 // Login Access Defaults.
3175 2871 if ( ! array_key_exists( 'access_who_can_login', $auth_multisite_settings ) ) {
@@ -3181,9 +2877,9 @@
3181 2877 }
3182 2878 // External Service Defaults.
3183 2879 if ( ! array_key_exists( 'access_default_role', $auth_multisite_settings ) ) {
3184 2880 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3185 - $all_roles = $wp_roles->roles;
2881 + $all_roles = $wp_roles->roles;
3186 2882 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3187 2883 if ( array_key_exists( 'student', $editable_roles ) ) {
3188 2884 $auth_multisite_settings['access_default_role'] = 'student';
3189 2885 } else {
@@ -3276,12 +2972,12 @@
3276 2972 }
3277 2973 // Advanced defaults.
3278 2974 if ( ! array_key_exists( 'advanced_lockouts', $auth_multisite_settings ) ) {
3279 2975 $auth_multisite_settings['advanced_lockouts'] = array(
3280 - 'attempts_1' => 10,
3281 - 'duration_1' => 1,
3282 - 'attempts_2' => 10,
3283 - 'duration_2' => 10,
2976 + 'attempts_1' => 10,
2977 + 'duration_1' => 1,
2978 + 'attempts_2' => 10,
2979 + 'duration_2' => 10,
3284 2980 'reset_duration' => 120,
3285 2981 );
3286 2982 }
3287 2983 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
@@ -3286,23 +2982,11 @@
3286 2982 }
3287 2983 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
3288 2984 $auth_multisite_settings['advanced_hide_wp_login'] = '';
3289 2985 }
3290 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_multisite_settings ) ) {
3291 - $auth_multisite_settings['advanced_users_per_page'] = 20;
3292 - }
3293 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_multisite_settings ) ) {
3294 - $auth_multisite_settings['advanced_users_sort_by'] = 'created';
3295 - }
3296 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_multisite_settings ) ) {
3297 - $auth_multisite_settings['advanced_users_sort_order'] = 'asc';
3298 - }
3299 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_multisite_settings ) ) {
3300 - $auth_multisite_settings['advanced_widget_enabled'] = '1';
3301 - }
3302 2986 // Save default network options to database.
3303 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
3304 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
2987 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
2988 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3305 2989 }
3306 2990
3307 2991 return $auth_settings;
3308 2992 }
@@ -3309,15 +2993,12 @@
3309 2993
3310 2994
3311 2995 /**
3312 2996 * List sanitizer.
3313 - *
3314 - * @param array $list Array of users to sanitize.
3315 - * @param string $side_effect Set to 'update roles' if role syncing should be performed.
3316 - * @param string $multisite_mode Set to 'multisite' to sync roles on all sites the user belongs to.
3317 - * @return array Array of sanitized users.
2997 + * $side_effect = 'none' or 'update roles' to make sure WP user roles match
2998 + * $multisite_mode = 'single' or 'multisite' to indicate which user roles to change (this site or all sites)
3318 2999 */
3319 - private function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
3000 + function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
3320 3001 // If it's not a list, make it so.
3321 3002 if ( ! is_array( $list ) ) {
3322 3003 $list = array();
3323 3004 }
@@ -3322,16 +3003,16 @@
3322 3003 $list = array();
3323 3004 }
3324 3005 foreach ( $list as $key => $user_info ) {
3325 3006 if ( strlen( $user_info['email'] ) < 1 ) {
3326 - // Make sure there are no empty entries in the list.
3327 - unset( $list[ $key ] );
3328 - } elseif ( 'update roles' === $side_effect ) {
3007 + // Make sure there are no empty entries in the list
3008 + unset( $list[$key] );
3009 + } elseif ( $side_effect === 'update roles' ) {
3329 3010 // Make sure the WordPress user accounts have the same role
3330 3011 // as that indicated in the list.
3331 3012 $wp_user = get_user_by( 'email', $user_info['email'] );
3332 3013 if ( $wp_user ) {
3333 - if ( is_multisite() && 'multisite' === $multisite_mode ) {
3014 + if ( is_multisite() && $multisite_mode === 'multisite' ) {
3334 3015 foreach ( get_blogs_of_user( $wp_user->ID ) as $blog ) {
3335 3016 add_user_to_blog( $blog->userblog_id, $wp_user->ID, $user_info['role'] );
3336 3017 }
3337 3018 } else {
@@ -3344,21 +3025,18 @@
3344 3025 }
3345 3026
3346 3027
3347 3028 /**
3348 - * Settings sanitizer callback.
3349 - *
3350 - * @param array $auth_settings Authorizer settings array.
3351 - * @return array Sanitized Authorizer settings array.
3029 + * Settings sanitizer callback
3352 3030 */
3353 - public function sanitize_options( $auth_settings ) {
3031 + function sanitize_options( $auth_settings ) {
3354 3032 // Default to "Approved Users" login access restriction.
3355 - if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ), true ) ) {
3033 + if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ) ) ) {
3356 3034 $auth_settings['access_who_can_login'] = 'approved_users';
3357 3035 }
3358 3036
3359 3037 // Default to "Everyone" view access restriction.
3360 - if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ), true ) ) {
3038 + if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ) ) ) {
3361 3039 $auth_settings['access_who_can_view'] = 'everyone';
3362 3040 }
3363 3041
3364 3042 // Default to WordPress login access redirect.
@@ -3363,9 +3041,9 @@
3363 3041
3364 3042 // Default to WordPress login access redirect.
3365 3043 // Note: this option doesn't exist in multisite options, so we first
3366 3044 // check to see if it exists.
3367 - if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ), true ) ) {
3045 + if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ) ) ) {
3368 3046 $auth_settings['access_redirect'] = 'login';
3369 3047 }
3370 3048
3371 3049 // Default to warning message for anonymous users on public pages.
@@ -3370,61 +3048,61 @@
3370 3048
3371 3049 // Default to warning message for anonymous users on public pages.
3372 3050 // Note: this option doesn't exist in multisite options, so we first
3373 3051 // check to see if it exists.
3374 - if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ), true ) ) {
3052 + if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ) ) ) {
3375 3053 $auth_settings['access_public_warning'] = 'no_warning';
3376 3054 }
3377 3055
3378 - // Sanitize Send welcome email (checkbox: value can only be '1' or empty string).
3056 + // Sanitize Send welcome email (checkbox: value can only be '1' or empty string)
3379 3057 $auth_settings['access_should_email_approved_users'] = array_key_exists( 'access_should_email_approved_users', $auth_settings ) && strlen( $auth_settings['access_should_email_approved_users'] ) > 0 ? '1' : '';
3380 3058
3381 - // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string).
3059 + // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string)
3382 3060 $auth_settings['google'] = array_key_exists( 'google', $auth_settings ) && strlen( $auth_settings['google'] ) > 0 ? '1' : '';
3383 3061
3384 - // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string).
3062 + // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string)
3385 3063 $auth_settings['cas'] = array_key_exists( 'cas', $auth_settings ) && strlen( $auth_settings['cas'] ) > 0 ? '1' : '';
3386 3064
3387 - // Sanitize CAS Host setting.
3065 + // Sanitize CAS Host setting
3388 3066 $auth_settings['cas_host'] = filter_var( $auth_settings['cas_host'], FILTER_SANITIZE_URL );
3389 3067
3390 - // Sanitize CAS Port (int).
3068 + // Sanitize CAS Port (int)
3391 3069 $auth_settings['cas_port'] = filter_var( $auth_settings['cas_port'], FILTER_SANITIZE_NUMBER_INT );
3392 3070
3393 - // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string).
3071 + // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string)
3394 3072 $auth_settings['cas_attr_update_on_login'] = array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['cas_attr_update_on_login'] ) > 0 ? '1' : '';
3395 3073
3396 - // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string).
3074 + // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string)
3397 3075 $auth_settings['cas_auto_login'] = array_key_exists( 'cas_auto_login', $auth_settings ) && strlen( $auth_settings['cas_auto_login'] ) > 0 ? '1' : '';
3398 3076
3399 - // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string).
3077 + // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string)
3400 3078 $auth_settings['ldap'] = array_key_exists( 'ldap', $auth_settings ) && strlen( $auth_settings['ldap'] ) > 0 ? '1' : '';
3401 3079
3402 - // Sanitize LDAP Host setting.
3080 + // Sanitize LDAP Host setting
3403 3081 $auth_settings['ldap_host'] = filter_var( $auth_settings['ldap_host'], FILTER_SANITIZE_URL );
3404 3082
3405 - // Sanitize LDAP Port (int).
3083 + // Sanitize LDAP Port (int)
3406 3084 $auth_settings['ldap_port'] = filter_var( $auth_settings['ldap_port'], FILTER_SANITIZE_NUMBER_INT );
3407 3085
3408 - // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string).
3086 + // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string)
3409 3087 $auth_settings['ldap_tls'] = array_key_exists( 'ldap_tls', $auth_settings ) && strlen( $auth_settings['ldap_tls'] ) > 0 ? '1' : '';
3410 3088
3411 - // Sanitize LDAP attributes (basically make sure they don't have any parentheses).
3089 + // Sanitize LDAP attributes (basically make sure they don't have any parentheses)
3412 3090 $auth_settings['ldap_uid'] = filter_var( $auth_settings['ldap_uid'], FILTER_SANITIZE_EMAIL );
3413 3091
3414 - // Sanitize LDAP Lost Password URL.
3092 + // Sanitize LDAP Lost Password URL
3415 3093 $auth_settings['ldap_lostpassword_url'] = filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_SANITIZE_URL );
3416 3094
3417 - // Obfuscate LDAP directory user password.
3095 + // Obfuscate LDAP directory user password
3418 3096 if ( strlen( $auth_settings['ldap_password'] ) > 0 ) {
3419 3097 // encrypt the directory user password for some minor obfuscation in the database.
3420 3098 $auth_settings['ldap_password'] = $this->encrypt( $auth_settings['ldap_password'] );
3421 3099 }
3422 3100
3423 - // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string).
3101 + // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string)
3424 3102 $auth_settings['ldap_attr_update_on_login'] = array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['ldap_attr_update_on_login'] ) > 0 ? '1' : '';
3425 3103
3426 - // Make sure public pages is an empty array if it's empty.
3104 + // Make sure public pages is an empty array if it's empty
3427 3105 // Note: this option doesn't exist in multisite options, so we first
3428 3106 // check to see if it exists.
3429 3107 if ( array_key_exists( 'access_public_pages', $auth_settings ) && ! is_array( $auth_settings['access_public_pages'] ) ) {
3430 3108 $auth_settings['access_public_pages'] = array();
@@ -3432,31 +3110,15 @@
3432 3110
3433 3111 // Make sure all lockout options are integers (attempts_1,
3434 3112 // duration_1, attempts_2, duration_2, reset_duration).
3435 3113 foreach ( $auth_settings['advanced_lockouts'] as $key => $value ) {
3436 - $auth_settings['advanced_lockouts'][ $key ] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3114 + $auth_settings['advanced_lockouts'][$key] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3437 3115 }
3438 3116
3439 - // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string).
3117 + // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string)
3440 3118 $auth_settings['advanced_hide_wp_login'] = array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && strlen( $auth_settings['advanced_hide_wp_login'] ) > 0 ? '1' : '';
3441 3119
3442 - // Sanitize Users per page (text: value can only int from 1 to MAX_INT).
3443 - $auth_settings['advanced_users_per_page'] = array_key_exists( 'advanced_users_per_page', $auth_settings ) && intval( $auth_settings['advanced_users_per_page'] ) > 0 ? intval( $auth_settings['advanced_users_per_page'] ) : 1;
3444 -
3445 - // Sanitize Sort users by (select: value can be 'email', 'role', 'date_added', 'created').
3446 - if ( ! isset( $auth_settings['advanced_users_sort_by'] ) || ! in_array( $auth_settings['advanced_users_sort_by'], array( 'email', 'role', 'date_added', 'created' ), true ) ) {
3447 - $auth_settings['advanced_users_sort_by'] = 'created';
3448 - }
3449 -
3450 - // Sanitize Sort users order (select: value can be 'asc', 'desc').
3451 - if ( ! isset( $auth_settings['advanced_users_sort_order'] ) || ! in_array( $auth_settings['advanced_users_sort_order'], array( 'asc', 'desc' ), true ) ) {
3452 - $auth_settings['advanced_users_sort_order'] = 'asc';
3453 - }
3454 -
3455 - // Sanitize Show Dashboard Widget (checkbox: value can only be '1' or empty string).
3456 - $auth_settings['advanced_widget_enabled'] = array_key_exists( 'advanced_widget_enabled', $auth_settings ) && strlen( $auth_settings['advanced_widget_enabled'] ) > 0 ? '1' : '';
3457 -
3458 - // Sanitize Override multisite options (checkbox: value can only be '1' or empty string).
3120 + // Sanitize Override multisite options (checkbox: value can only be '1' or empty string)
3459 3121 $auth_settings['advanced_override_multisite'] = array_key_exists( 'advanced_override_multisite', $auth_settings ) && strlen( $auth_settings['advanced_override_multisite'] ) > 0 ? '1' : '';
3460 3122
3461 3123 return $auth_settings;
3462 3124 }
@@ -3463,201 +3125,90 @@
3463 3125
3464 3126
3465 3127 /**
3466 3128 * Keep authorizer approved users' roles in sync with WordPress roles
3467 - * if someone changes the role via the WordPress Edit User page
3468 - * (wp-admin/user-edit.php or wp-admin/profile.php).
3129 + * if someone changes the role via the WordPress Edit User options page.
3469 3130 *
3470 - * Action: user_profile_update_errors
3471 - *
3472 - * @param WP_Error $errors Errors object to add any custom errors to (passed by reference).
3473 - * @param bool $update True if updating existing user, false if saving a new one.
3474 - * @param stdClass $user Updated WP_User object for user being edited (passed by reference).
3131 + * @action edit_user_profile_update
3132 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/edit_user_profile_update
3133 + * @param int $user_id The user ID of the user being edited
3134 +
3135 + * @action personal_options_update
3136 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/personal_options_update
3137 + * @param int $user_id The user ID of the user being edited
3475 3138 */
3476 - public function edit_user_profile_update_role( &$errors, $update, &$user ) {
3477 - // Do nothing if we're not updating role.
3478 - if ( ! property_exists( $user, 'role' ) ) {
3139 + function edit_user_profile_update_role( $user_id ) {
3140 + if ( ! current_user_can( 'edit_user', $user_id ) ) {
3479 3141 return;
3480 3142 }
3481 3143
3482 - // Safety check; will likely not fire if we reach this function.
3483 - if ( ! current_user_can( 'edit_user', $user->ID ) ) {
3484 - return;
3485 - }
3486 -
3487 - // Don't perform Authorizer updates if we have a WordPress error.
3488 - $errors_on_user_update = $errors->get_error_codes();
3489 - if ( ! empty( $errors_on_user_update ) ) {
3490 - return;
3491 - }
3492 -
3493 - // Get original user object (fail if not a real WordPress user).
3494 - $userdata = get_userdata( $user->ID );
3495 - if ( ! $userdata ) {
3496 - return;
3497 - }
3498 -
3499 3144 // If user is in approved list, update his/her associated role.
3500 - if ( $this->is_email_in_list( $userdata->user_email, 'approved' ) ) {
3501 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3502 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3503 - if ( 0 === strcasecmp( $check_user['email'], $userdata->user_email ) ) {
3504 - $auth_settings_access_users_approved[ $key ]['role'] = $user->role;
3505 - }
3506 - }
3507 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3508 - }
3509 - }
3510 -
3511 -
3512 - /**
3513 - * Sync any email address changes to WordPress accounts to the corresponding
3514 - * entry in the Authorizer approved list.
3515 - *
3516 - * Note: This filter fires in wp_update_user() if the update includes an
3517 - * email address change, and fires after all security and integrity checks
3518 - * have been performed, so we can simply update the Authorizer approved
3519 - * list, changing the email address on the approved entry, and removing any
3520 - * existing entries that also have the new email address (duplicates).
3521 - *
3522 - * Filter: send_email_change_email
3523 - *
3524 - * @param bool $send Whether to send the email.
3525 - * @param array $user The original user array.
3526 - * @param array $userdata The updated user array.
3527 - */
3528 - public function edit_user_profile_update_email( $send, $user, $userdata ) {
3529 - // If we're in multisite, update the email on all sites in the network
3530 - // (and remove from any subsites if it's a network-approved user).
3531 - if ( is_multisite() ) {
3532 - // If it's a multisite approved user, sync the email there.
3533 - $changed_user_is_multisite_user = false;
3534 - if ( $this->is_email_in_list( $user['user_email'], 'approved', 'multisite' ) ) {
3535 - $changed_user_is_multisite_user = true;
3536 - $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
3537 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
3538 - );
3539 - foreach ( $auth_multisite_settings_access_users_approved as $key => $check_user ) {
3540 - // Update old user email in approved list to the new email.
3541 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3542 - $auth_multisite_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3145 + $wp_user = get_user_by( 'id', $user_id );
3146 + if ( $this->is_email_in_list( $wp_user->get( 'user_email' ), 'approved' ) ) {
3147 + $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) );
3148 + // Find approved user and sync with the corresponding WP_User.
3149 + foreach ( $auth_settings_access_users_approved as $key => $user ) {
3150 + if ( 0 === strcasecmp( $user['email'], $wp_user->user_email ) ) {
3151 + // Sync user role.
3152 + if ( array_key_exists( 'role', $_REQUEST ) ) {
3153 + $auth_settings_access_users_approved[$key]['role'] = $_REQUEST['role'];
3543 3154 }
3544 - // If new user email is already in approved list, remove that entry.
3545 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3546 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
3155 + // Sync email address.
3156 + if ( array_key_exists( 'email', $_REQUEST ) ) {
3157 + $auth_settings_access_users_approved[$key]['email'] = mb_strtolower( $_REQUEST['email'] );
3547 3158 }
3548 3159 }
3549 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3550 3160 }
3551 3161
3552 - // Go through all approved lists on individual sites and sync this user there.
3553 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
3554 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
3555 - foreach ( $sites as $site ) {
3556 - $updated = false;
3557 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
3558 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
3559 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3560 - // Update old user email in approved list to the new email.
3561 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3562 - // But if the user is already a multisite user, just remove the entry in the subsite.
3563 - if ( $changed_user_is_multisite_user ) {
3564 - unset( $auth_settings_access_users_approved[ $key ] );
3565 - } else {
3566 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3567 - }
3568 - $updated = true;
3569 - }
3570 - // If new user email is already in approved list, remove that entry.
3571 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3572 - unset( $auth_settings_access_users_approved[ $key ] );
3573 - $updated = true;
3574 - }
3575 - }
3576 - if ( $updated ) {
3577 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3578 - }
3579 - }
3580 - } else {
3581 - // In a single site environment, just find the old user in the approved list and update the email.
3582 - if ( $this->is_email_in_list( $user['user_email'], 'approved' ) ) {
3583 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3584 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3585 - // Update old user email in approved list to the new email.
3586 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3587 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3588 - }
3589 - // If new user email is already in approved list, remove that entry.
3590 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3591 - unset( $auth_settings_access_users_approved[ $key ] );
3592 - }
3593 - }
3594 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3595 - }
3162 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3596 3163 }
3597 -
3598 - // We're hooking into this filter merely for its location in the codebase,
3599 - // so make sure to return the filter value unmodified.
3600 - return $send;
3601 3164 }
3602 3165
3603 3166
3604 3167 /**
3605 - * Settings print callback.
3606 - *
3607 - * @param string $args Args (e.g., multisite admin mode).
3608 - * @return void
3168 + * Settings print callbacks
3609 3169 */
3610 - public function print_section_info_tabs( $args = '' ) {
3611 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $this->get_admin_mode( $args ) ) :
3612 - ?>
3170 + function print_section_info_tabs( $args = '' ) {
3171 + if ( MULTISITE_ADMIN === $this->get_admin_mode( $args )): ?>
3613 3172 <h2 class="nav-tab-wrapper">
3614 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3615 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3616 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3173 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3174 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3175 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3617 3176 </h2>
3618 - <?php else : ?>
3177 + <?php else: ?>
3619 3178 <h2 class="nav-tab-wrapper">
3620 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3621 - <a class="nav-tab nav-tab-access_login" href="javascript:chooseTab('access_login' );"><?php esc_html_e( 'Login Access', 'authorizer' ); ?></a>
3622 - <a class="nav-tab nav-tab-access_public" href="javascript:chooseTab('access_public' );"><?php esc_html_e( 'Public Access', 'authorizer' ); ?></a>
3623 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3624 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3179 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3180 + <a class="nav-tab nav-tab-access_login" href="javascript:choose_tab('access_login' );"><?php _e( 'Login Access', 'authorizer' ); ?></a>
3181 + <a class="nav-tab nav-tab-access_public" href="javascript:choose_tab('access_public' );"><?php _e( 'Public Access', 'authorizer' ); ?></a>
3182 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3183 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3625 3184 </h2>
3626 - <?php
3627 - endif;
3185 + <?php endif;
3628 3186 }
3629 3187
3630 3188
3631 - /**
3632 - * Settings print callback.
3633 - *
3634 - * @param string $args Args (e.g., multisite admin mode).
3635 - * @return void
3636 - */
3637 - public function print_section_info_access_lists( $args = '' ) {
3189 + function print_section_info_access_lists( $args = '' ) {
3638 3190 $admin_mode = $this->get_admin_mode( $args );
3639 - ?>
3640 - <div id="section_info_access_lists" class="section_info">
3641 - <p><?php esc_html_e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3191 + ?><div id="section_info_access_lists" class="section_info">
3192 + <p><?php _e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3642 3193 <ol>
3643 - <li><?php echo wp_kses( __( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ), $this->allowed_html ); ?></li>
3644 - <li><?php echo wp_kses( __( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ), $this->allowed_html ); ?></li>
3645 - <li><?php echo wp_kses( __( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ), $this->allowed_html ); ?></li>
3194 + <li><?php _e( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ); ?></li>
3195 + <li><?php _e( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ); ?></li>
3196 + <li><?php _e( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ); ?></li>
3646 3197 </ol>
3647 3198 </div>
3648 3199 <table class="form-table">
3649 3200 <tbody>
3650 3201 <tr>
3651 - <th scope="row"><?php esc_html_e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'pending', $admin_mode ) ); ?>)</em></th>
3202 + <th scope="row"><?php _e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'pending', $admin_mode ); ?>)</em></th>
3652 3203 <td><?php $this->print_combo_auth_access_users_pending(); ?></td>
3653 3204 </tr>
3654 3205 <tr>
3655 - <th scope="row"><?php esc_html_e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'approved', $admin_mode ) ); ?>)</em></th>
3206 + <th scope="row"><?php _e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'approved', $admin_mode ); ?>)</em></th>
3656 3207 <td><?php $this->print_combo_auth_access_users_approved(); ?></td>
3657 3208 </tr>
3658 3209 <tr>
3659 - <th scope="row"><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'blocked', $admin_mode ) ); ?>)</em></th>
3210 + <th scope="row"><?php _e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'blocked', $admin_mode ); ?>)</em></th>
3660 3211 <td><?php $this->print_combo_auth_access_users_blocked(); ?></td>
3661 3212 </tr>
3662 3213 </tbody>
3663 3214 </table>
@@ -3664,516 +3215,276 @@
3664 3215 <?php
3665 3216 }
3666 3217
3667 3218
3668 - /**
3669 - * Settings print callback.
3670 - *
3671 - * @param string $args Args (e.g., multisite admin mode).
3672 - * @return void
3673 - */
3674 - public function print_combo_auth_access_users_pending( $args = '' ) {
3219 + function print_combo_auth_access_users_pending( $args = '' ) {
3675 3220 // Get plugin option.
3676 - $option = 'access_users_pending';
3221 + $option = 'access_users_pending';
3677 3222 $auth_settings_option = $this->get_plugin_option( $option );
3678 3223 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3679 3224
3680 - // Render wrapper div (for aligning pager to width of content).
3681 - ?>
3682 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3683 - <ul id="list_auth_settings_access_users_pending" style="margin:0;">
3684 - <?php
3685 - if ( count( $auth_settings_option ) > 0 ) :
3686 - foreach ( $auth_settings_option as $key => $pending_user ) :
3687 - if ( empty( $pending_user ) || count( $pending_user ) < 1 ) :
3688 - continue;
3689 - endif;
3690 - $pending_user['is_wp_user'] = false;
3691 - ?>
3692 - <li>
3693 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $pending_user['email'] ); ?>" readonly="true" class="auth-email" />
3694 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
3695 - <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3696 - </select>
3697 - <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'approved', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3698 - <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'blocked', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
3699 - <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'pending' );" title="<?php esc_html_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php esc_html_e( 'Ignore', 'authorizer' ); ?></a>
3700 - </li>
3701 - <?php endforeach; ?>
3702 - <?php else : ?>
3703 - <li class="auth-empty"><em><?php esc_html_e( 'No pending users', 'authorizer' ); ?></em></li>
3704 - <?php endif; ?>
3705 - </ul>
3706 - </div>
3225 + // Print option elements.
3226 + ?><ul id="list_auth_settings_access_users_pending" style="margin:0;">
3227 + <?php if ( count( $auth_settings_option ) > 0 ) : ?>
3228 + <?php foreach ( $auth_settings_option as $key => $pending_user ): ?>
3229 + <?php if ( empty( $pending_user ) || count( $pending_user ) < 1 ) continue; ?>
3230 + <?php $pending_user['is_wp_user'] = false; ?>
3231 + <li>
3232 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $pending_user['email']; ?>" readonly="true" class="auth-email" />
3233 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3234 + <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3235 + </select>
3236 + <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'approved', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3237 + <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'blocked', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
3238 + <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user( this, 'pending' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php _e( 'Ignore', 'authorizer' ); ?></a>
3239 + </li>
3240 + <?php endforeach; ?>
3241 + <?php else: ?>
3242 + <li class="auth-empty"><em><?php _e( 'No pending users', 'authorizer' ); ?></em></li>
3243 + <?php endif; ?>
3244 + </ul>
3707 3245 <?php
3708 3246 }
3709 3247
3710 3248
3711 - /**
3712 - * Settings print callback.
3713 - *
3714 - * @param string $args Args (e.g., multisite admin mode).
3715 - * @return void
3716 - */
3717 - public function print_combo_auth_access_users_approved( $args = '' ) {
3249 + function print_combo_auth_access_users_approved( $args = '' ) {
3718 3250 // Get plugin option.
3719 - $option = 'access_users_approved';
3720 - $admin_mode = $this->get_admin_mode( $args );
3251 + $option = 'access_users_approved';
3252 + $admin_mode = $this->get_admin_mode( $args );
3721 3253 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
3722 3254 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3723 3255
3724 - // Get multisite approved users (will be added to top of list, greyed out).
3725 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3726 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
3256 + // Get multisite approved users (add them to top of list, greyed out).
3257 + $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3258 + $auth_multisite_settings = $this->get_plugin_options( MULTISITE_ADMIN );
3727 3259 $auth_settings_option_multisite = array();
3728 3260 if (
3729 3261 is_multisite() &&
3730 - ! is_network_admin() &&
3731 - '1' !== intval( $auth_override_multisite ) &&
3262 + $auth_override_multisite != '1' &&
3732 3263 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
3733 - '1' === $auth_multisite_settings['multisite_override']
3264 + $auth_multisite_settings['multisite_override'] === '1'
3734 3265 ) {
3735 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
3266 + $auth_settings_option_multisite = $this->get_plugin_option( $option, MULTISITE_ADMIN, 'allow override' );
3736 3267 $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
3737 - // Add multisite users to the beginning of the main user array.
3738 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
3739 - $approved_user['multisite_user'] = true;
3740 - array_unshift( $auth_settings_option, $approved_user );
3741 - }
3742 3268 }
3743 3269
3744 3270 // Get default role for new user dropdown.
3745 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3271 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
3746 3272
3747 3273 // Get custom usermeta field to show.
3748 3274 $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
3749 3275
3750 3276 // Adjust javascript function prefixes if multisite.
3751 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3752 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3277 + $js_function_prefix = $admin_mode === MULTISITE_ADMIN ? 'auth_multisite_' : 'auth_';
3278 + $multisite_admin_page = $admin_mode === MULTISITE_ADMIN;
3753 3279
3754 - // Filter user list to search terms.
3755 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3756 - if ( isset( $_REQUEST['search'] ) && strlen( sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) ) > 0 ) {
3757 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3758 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
3759 - $auth_settings_option = array_filter(
3760 - $auth_settings_option, function ( $user ) use ( $search_term ) {
3761 - return stripos( $user['email'], $search_term ) !== false ||
3762 - stripos( $user['role'], $search_term ) !== false ||
3763 - stripos( $user['date_added'], $search_term ) !== false;
3764 - }
3765 - );
3766 - }
3767 -
3768 - // Sort user list.
3769 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
3770 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
3771 - $sort_dimension = array();
3772 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
3773 - foreach ( $auth_settings_option as $key => $user ) {
3774 - if ( 'date_added' === $sort_by ) {
3775 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
3776 - } else {
3777 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
3778 - }
3779 - }
3780 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
3781 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
3782 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
3783 - // If default sort method and reverse order, just reverse the array.
3784 - $auth_settings_option = array_reverse( $auth_settings_option );
3785 - }
3786 -
3787 - // Ensure array keys run from 0..max (keys in database will be the original,
3788 - // index, and removing users will not reorder the array keys of other users).
3789 - $auth_settings_option = array_values( $auth_settings_option );
3790 -
3791 - // Get pager params.
3792 - $total_users = count( $auth_settings_option );
3793 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
3794 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3795 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
3796 - $total_pages = ceil( $total_users / $users_per_page );
3797 - if ( $total_pages < 1 ) {
3798 - $total_pages = 1;
3799 - }
3800 -
3801 - // Make sure current_page is between 1 and max pages.
3802 - if ( $current_page < 1 ) {
3803 - $current_page = 1;
3804 - } elseif ( $current_page > $total_pages ) {
3805 - $current_page = $total_pages;
3806 - }
3807 -
3808 - // Render wrapper div (for aligning pager to width of content).
3809 - ?>
3810 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3811 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'top' ); ?>
3812 - <ul id="list_auth_settings_access_users_approved" class="<?php echo strlen( $advanced_usermeta ) > 0 ? 'has-usermeta' : ''; ?>">
3813 - <?php
3814 - $offset = ( $current_page - 1 ) * $users_per_page;
3815 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
3816 - for ( $key = $offset; $key < $max; $key++ ) :
3817 - $approved_user = $auth_settings_option[ $key ];
3280 + ?><ul id="list_auth_settings_access_users_approved" style="margin:0;">
3281 + <?php if ( ! $multisite_admin_page ) :
3282 + foreach ( $auth_settings_option_multisite as $key => $approved_user ) :
3818 3283 if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3819 3284 continue;
3820 3285 endif;
3821 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
3822 - endfor;
3823 - ?>
3824 - </ul>
3286 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3287 + if ( $approved_wp_user ) :
3288 + $approved_user['email'] = $approved_wp_user->user_email;
3289 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3290 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3291 + // Get usermeta field from the WordPress user's real usermeta.
3292 + if ( strlen( $advanced_usermeta ) > 0 ) :
3293 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3294 + // Get ACF Field value for the user
3295 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3296 + else :
3297 + // Get regular usermeta value for the user.
3298 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3299 + endif;
3825 3300
3826 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
3827 - <textarea id="new_approved_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new autogrow-short" rows="1"></textarea>
3828 - <select id="new_approved_user_role" class="auth-role">
3829 - <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
3830 - </select>
3831 - <div class="btn-group">
3832 - <a href="javascript:void(0);" class="btn button-primary dropdown-toggle button-add-user" id="approve_user_new" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3833 - <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3834 - <span class="caret"></span>
3835 - <span class="sr-only"><?php esc_html_e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3836 - </button>
3837 - <ul class="dropdown-menu" role="menu">
3838 - <li><a href="javascript:void(0);" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( document.getElementById( 'approve_user_new' ), 'approved', true);"><?php esc_html_e( 'Create a local WordPress account instead, and email the user their password.', 'authorizer' ); ?></a></li>
3839 - </ul>
3840 - </div>
3841 - </div>
3842 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'bottom' ); ?>
3843 - </div>
3844 - <?php
3845 - }
3301 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3302 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3303 + endif;
3304 + endif;
3305 + endif;
3306 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3307 + $approved_user['usermeta'] = '';
3308 + endif; ?>
3309 + <li>
3310 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email auth-multisite-email" />
3311 + <select id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role auth-multisite-role" disabled="disabled">
3312 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'] ); ?>
3313 + </select>
3314 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added auth-multisite-date-added" disabled="disabled" />
3315 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3316 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3317 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3318 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3319 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3320 + $should_show_usermeta_in_text_field = false; ?>
3321 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta auth-multisite-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );">
3322 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3323 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3324 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && array_key_exists( get_current_blog_id(), $approved_user['usermeta'] ) && $key === $approved_user['usermeta'][get_current_blog_id()]['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3325 + <?php endforeach; ?>
3326 + </select>
3327 + <?php endif; ?>
3328 + <?php endif; ?>
3329 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3330 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta auth-multisite-usermeta" />
3331 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3332 + <?php endif; ?>
3333 + <?php endif; ?>
3334 + &nbsp;&nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
3335 + </li>
3336 + <?php endforeach;
3337 + endif;
3338 + foreach ( $auth_settings_option as $key => $approved_user ):
3339 + $is_current_user = false;
3340 + $local_user_icon = array_key_exists( 'local_user', $approved_user ) && $approved_user['local_user'] === 'true' ? '&nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>' : '';
3341 + if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3342 + continue;
3343 + endif;
3344 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3345 + if ( $approved_wp_user ) :
3346 + $approved_user['email'] = $approved_wp_user->user_email;
3347 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3348 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3349 + $approved_user['is_wp_user'] = true;
3350 + $is_current_user = $approved_wp_user->ID === get_current_user_id();
3351 + // Get usermeta field from the WordPress user's real usermeta.
3352 + if ( strlen( $advanced_usermeta ) > 0 ) :
3353 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3354 + // Get ACF Field value for the user
3355 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3356 + else :
3357 + // Get regular usermeta value for the user.
3358 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3359 + endif;
3846 3360
3847 -
3848 - /**
3849 - * Renders the html elements for the pager above and below the Approved User list.
3850 - *
3851 - * @param integer $current_page Which page we are currently viewing.
3852 - * @param integer $users_per_page How many users to show per page.
3853 - * @param integer $total_users Total count of users in list.
3854 - * @param string $which Where to render the pager ('top' or 'bottom').
3855 - * @return void
3856 - */
3857 - private function render_user_pager( $current_page = 1, $users_per_page = 20, $total_users = 0, $which = 'top' ) {
3858 - $total_pages = ceil( $total_users / $users_per_page );
3859 - if ( $total_pages < 1 ) {
3860 - $total_pages = 1;
3861 - }
3862 -
3863 - /* TRANSLATORS: %s: number of users */
3864 - $output = ' <span class="displaying-num">' . sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ) . '</span>';
3865 -
3866 - $disable_first = $current_page <= 1;
3867 - $disable_prev = $current_page <= 1;
3868 - $disable_next = $current_page >= $total_pages;
3869 - $disable_last = $current_page >= $total_pages;
3870 -
3871 - $current_url = '';
3872 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
3873 - $current_url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
3874 - $current_url = remove_query_arg( wp_removable_query_args(), $current_url );
3875 - }
3876 -
3877 - $page_links = array();
3878 -
3879 - $total_pages_before = '<span class="paging-input">';
3880 - $total_pages_after = '</span></span>';
3881 -
3882 - if ( $disable_first ) {
3883 - $page_links[] = '<span class="first-page tablenav-pages-navspan" aria-hidden="true">&laquo;</span>';
3884 - } else {
3885 - $page_links[] = sprintf(
3886 - "<a class='first-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3887 - esc_url( remove_query_arg( 'paged', $current_url ) ),
3888 - __( 'First page' ),
3889 - '&laquo;'
3890 - );
3891 - }
3892 -
3893 - if ( $disable_prev ) {
3894 - $page_links[] = '<span class="prev-page tablenav-pages-navspan" aria-hidden="true">&lsaquo;</span>';
3895 - } else {
3896 - $page_links[] = sprintf(
3897 - "<a class='prev-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3898 - esc_url( add_query_arg( 'paged', max( 1, $current_page - 1 ), $current_url ) ),
3899 - __( 'Previous page' ),
3900 - '&lsaquo;'
3901 - );
3902 - }
3903 -
3904 - if ( 'bottom' === $which ) {
3905 - $html_current_page = '<span class="current-page-text">' . $current_page . '</span>';
3906 - $total_pages_before = '<span class="screen-reader-text">' . __( 'Current Page' ) . '</span><span id="table-paging" class="paging-input"><span class="tablenav-paging-text">';
3907 - } else {
3908 - $html_current_page = sprintf(
3909 - "%s<input class='current-page' id='current-page-selector' type='text' name='paged' value='%s' size='%d' aria-describedby='table-paging' /><span class='tablenav-paging-text'>",
3910 - '<label for="current-page-selector" class="screen-reader-text">' . __( 'Current Page' ) . '</label>',
3911 - $current_page,
3912 - strlen( $total_pages )
3913 - );
3914 - }
3915 - /* TRANSLATORS: %s: number of pages */
3916 - $html_total_pages = sprintf( "<span class='total-pages'>%s</span>", number_format_i18n( $total_pages ) );
3917 - /* TRANSLATORS: 1: number of current page 2: number of total pages */
3918 - $page_links[] = $total_pages_before . sprintf( _x( '%1$s of %2$s', 'paging' ), $html_current_page, $html_total_pages ) . $total_pages_after;
3919 -
3920 - if ( $disable_next ) {
3921 - $page_links[] = '<span class="next-page tablenav-pages-navspan" aria-hidden="true">&rsaquo;</span>';
3922 - } else {
3923 - $page_links[] = sprintf(
3924 - "<a class='next-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3925 - esc_url( add_query_arg( 'paged', min( $total_pages, $current_page + 1 ), $current_url ) ),
3926 - __( 'Next page' ),
3927 - '&rsaquo;'
3928 - );
3929 - }
3930 -
3931 - if ( $disable_last ) {
3932 - $page_links[] = '<span class="last-page tablenav-pages-navspan" aria-hidden="true">&raquo;</span>';
3933 - } else {
3934 - $page_links[] = sprintf(
3935 - "<a class='last-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3936 - esc_url( add_query_arg( 'paged', $total_pages, $current_url ) ),
3937 - __( 'Last page' ),
3938 - '&raquo;'
3939 - );
3940 - }
3941 -
3942 - $pagination_links_class = 'pagination-links';
3943 - $output .= "\n<span class='$pagination_links_class'>" . join( "\n", $page_links ) . '</span>';
3944 -
3945 - $search_form = array();
3946 - if ( 'top' === $which ) {
3947 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3948 - $search_term = isset( $_REQUEST['search'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) : '';
3949 - $search_form[] = '<div class="search-box">';
3950 - $search_form[] = '<label class="screen-reader-text" for="user-search-input">' . __( 'Search Users', 'authorizer' ) . '</label>';
3951 - $search_form[] = '<input type="search" size="14" id="user-search-input" name="search" value="' . $search_term . '">';
3952 - $search_form[] = '<input type="button" id="search-submit" class="button" value="' . __( 'Search', 'authorizer' ) . '">';
3953 - $search_form[] = '</div>';
3954 - }
3955 - $search_form = join( "\n", $search_form );
3956 -
3957 - $output = "<div class='tablenav-pages'>$output</div>";
3958 - ?>
3959 - <div class="tablenav top">
3960 - <?php echo wp_kses( $output, $this->allowed_html ); ?>
3961 - <?php echo wp_kses( $search_form, $this->allowed_html ); ?>
3962 - </div>
3963 - <?php
3964 - }
3965 -
3966 -
3967 - /**
3968 - * Renders the html <li> element for a given user in a list.
3969 - *
3970 - * @param array $approved_user User array to render.
3971 - * @param int $key Index of user in list of users.
3972 - * @param string $option List user is in (e.g., 'access_users_approved').
3973 - * @param string $admin_mode Current admin context.
3974 - * @param string $advanced_usermeta Usermeta field to display.
3975 - * @return void
3976 - */
3977 - private function render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ) {
3978 - $is_local_user = array_key_exists( 'local_user', $approved_user ) && 'true' === $approved_user['local_user'];
3979 - $is_multisite_user = array_key_exists( 'multisite_user', $approved_user ) && true === $approved_user['multisite_user'];
3980 - $option_prefix = $is_multisite_user ? 'auth_multisite_settings_' : 'auth_settings_';
3981 - $option_id = $option_prefix . $option . '_' . $key;
3982 - $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3983 - $is_current_user = $approved_wp_user && get_current_user_id() === $approved_wp_user->ID;
3984 -
3985 - // Adjust javascript function prefixes if multisite.
3986 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3987 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3988 -
3989 - if ( ! $approved_wp_user ) :
3990 - $approved_user['is_wp_user'] = false;
3991 - else :
3992 - $approved_user['is_wp_user'] = true;
3993 - $approved_user['email'] = $approved_wp_user->user_email;
3994 - $approved_user['role'] = $is_multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3995 - $approved_user['date_added'] = $approved_wp_user->user_registered;
3996 -
3997 - // Get usermeta field from the WordPress user's real usermeta.
3998 - if ( strlen( $advanced_usermeta ) > 0 ) :
3999 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
4000 - // Get ACF Field value for the user.
4001 - $approved_user['usermeta'] = get_field( str_replace( 'acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3361 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3362 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3363 + endif;
3364 + endif;
4002 3365 else :
4003 - // Get regular usermeta value for the user.
4004 - $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3366 + $approved_user['is_wp_user'] = false;
4005 3367 endif;
4006 - if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
4007 - $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
4008 - endif;
4009 - endif;
4010 - endif;
4011 - if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
4012 - $approved_user['usermeta'] = '';
4013 - endif;
4014 - ?>
4015 - <li>
4016 - <input
4017 - type="text"
4018 - id="<?php echo esc_attr( $option_id ); ?>"
4019 - value="<?php echo esc_attr( $approved_user['email'] ); ?>"
4020 - readonly="true"
4021 - class="<?php echo esc_attr( $this->create_class_name( 'email', $is_multisite_user ) ); ?>"
4022 - />
4023 - <select
4024 - id="<?php echo esc_attr( $option_id ); ?>_role"
4025 - class="<?php echo esc_attr( $this->create_class_name( 'role', $is_multisite_user ) ); ?>"
4026 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>ChangeRole( this );"
4027 - <?php if ( $is_multisite_user ) : ?>
4028 - disabled="disabled"
4029 - <?php endif; ?>
4030 - >
4031 - <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
4032 - <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3368 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3369 + $approved_user['usermeta'] = '';
3370 + endif; ?>
3371 + <li>
3372 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email" />
3373 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role" onchange="<?php echo $js_function_prefix; ?>change_role( this );">
3374 + <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
3375 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3376 + </select>
3377 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3378 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3379 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3380 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3381 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3382 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3383 + $should_show_usermeta_in_text_field = false; ?>
3384 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );" >
3385 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3386 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3387 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && $key === $approved_user['usermeta']['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3388 + <?php endforeach; ?>
3389 + </select>
3390 + <?php endif; ?>
3391 + <?php endif; ?>
3392 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3393 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta" />
3394 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3395 + <?php endif; ?>
3396 + <?php endif; ?>
3397 + <?php if ( ! $is_current_user ): ?>
3398 + <?php if ( ! $multisite_admin_page ) : ?>
3399 + <a class="button" id="block_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>add_user( this, 'blocked', false ); <?php echo $js_function_prefix; ?>ignore_user( this, 'approved' );" title="<?php _e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
3400 + <?php endif; ?>
3401 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>ignore_user(this, 'approved' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3402 + <?php endif; ?>
3403 + <?php echo $local_user_icon; ?>
3404 + </li>
3405 + <?php endforeach; ?>
3406 + </ul>
3407 + <div id="new_auth_settings_<?php echo $option; ?>">
3408 + <input type="text" id="new_approved_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3409 + <select id="new_approved_user_role" class="auth-role">
3410 + <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
4033 3411 </select>
4034 - <input
4035 - type="text"
4036 - id="<?php echo esc_attr( $option_id ); ?>_date_added"
4037 - value="<?php echo esc_attr( date( 'M Y', strtotime( $approved_user['date_added'] ) ) ); ?>"
4038 - readonly="true"
4039 - class="<?php echo esc_attr( $this->create_class_name( 'date-added', $is_multisite_user ) ); ?>"
4040 - />
4041 - <?php
4042 - if ( strlen( $advanced_usermeta ) > 0 ) :
4043 - $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
4044 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
4045 - $field_object = get_field_object( str_replace( 'acf___', '', $advanced_usermeta ) );
4046 - if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && 'select' === $field_object['type'] ) :
4047 - $should_show_usermeta_in_text_field = false;
4048 - ?>
4049 - <select
4050 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4051 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4052 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );"
4053 - >
4054 - <option value=""<?php selected( empty( $approved_user['usermeta'] ) ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4055 - <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
4056 - <option value="<?php echo esc_attr( $key ); ?>"<?php selected( $key === $approved_user['usermeta'] || ( isset( $approved_user['usermeta']['meta_value'] ) && $key === $approved_user['usermeta']['meta_value'] ) ); ?>><?php echo esc_html( $label ); ?></option>
4057 - <?php endforeach; ?>
4058 - </select>
4059 - <?php endif; ?>
4060 - <?php endif; ?>
4061 - <?php if ( $should_show_usermeta_in_text_field ) : ?>
4062 - <input
4063 - type="text"
4064 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4065 - value="<?php echo esc_attr( $approved_user['usermeta'], ENT_COMPAT ); ?>"
4066 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4067 - />
4068 - <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
4069 - <?php endif; ?>
4070 - <?php endif; ?>
4071 - <?php if ( ! $is_current_user && ! $is_multisite_user ) : ?>
4072 - <?php if ( ! $is_multisite_admin_page ) : ?>
4073 - <a class="button" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( this, 'blocked', false ); <?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser( this, 'approved' );" title="<?php esc_attr_e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
4074 - <?php endif; ?>
4075 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser(this, 'approved' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4076 - <?php endif; ?>
4077 - <?php if ( $is_local_user ) : ?>
4078 - &nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>
4079 - <?php endif; ?>
4080 - <?php if ( $is_multisite_user ) : ?>
4081 - &nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
4082 - <?php endif; ?>
4083 - </li>
3412 + <div class="btn-group">
3413 + <a href="javascript:void(0);" class="btn button-primary dropdown-toggle" id="approve_user_new" onclick="<?php echo $js_function_prefix; ?>add_user(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3414 + <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3415 + <span class="caret"></span>
3416 + <span class="sr-only"><?php _e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3417 + </button>
3418 + <ul class="dropdown-menu" role="menu">
3419 + <li><a href="javascript:void(0);" onclick="<?php echo $js_function_prefix; ?>add_user( document.getElementById('approve_user_new' ), 'approved', true);"><?php _e( 'Create a local WordPress <br />account instead, and email <br />the user their password.', 'authorizer' ); ?></a></li>
3420 + </ul>
3421 + </div>
3422 + </div>
4084 3423 <?php
4085 3424 }
4086 3425
4087 3426
4088 - /**
4089 - * Settings print callback.
4090 - *
4091 - * @param string $args Args (e.g., multisite admin mode).
4092 - * @return void
4093 - */
4094 - public function print_combo_auth_access_users_blocked( $args = '' ) {
3427 + function print_combo_auth_access_users_blocked( $args = '' ) {
4095 3428 // Get plugin option.
4096 - $option = 'access_users_blocked';
3429 + $option = 'access_users_blocked';
4097 3430 $auth_settings_option = $this->get_plugin_option( $option );
4098 3431 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4099 3432
4100 3433 // Get default role for new blocked user dropdown.
4101 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3434 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
4102 3435
4103 - // Render wrapper div (for aligning pager to width of content).
4104 - ?>
4105 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
4106 - <ul id="list_auth_settings_<?php echo esc_attr( $option ); ?>" style="margin:0;">
4107 - <?php
4108 - foreach ( $auth_settings_option as $key => $blocked_user ) :
4109 - if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) :
4110 - continue;
4111 - endif;
4112 - $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
4113 - if ( $blocked_wp_user ) :
4114 - $blocked_user['email'] = $blocked_wp_user->user_email;
4115 - $blocked_user['role'] = array_shift( $blocked_wp_user->roles );
4116 - $blocked_user['date_added'] = $blocked_wp_user->user_registered;
4117 - $blocked_user['is_wp_user'] = true;
4118 - else :
4119 - $blocked_user['is_wp_user'] = false;
4120 - endif;
4121 - ?>
4122 - <li>
4123 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $blocked_user['email'] ); ?>" readonly="true" class="auth-email" />
4124 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
4125 - <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
4126 - </select>
4127 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_date_added" value="<?php echo esc_attr( date( 'M Y', strtotime( $blocked_user['date_added'] ) ) ); ?>" readonly="true" class="auth-date-added" />
4128 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'blocked' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4129 - </li>
4130 - <?php endforeach; ?>
4131 - </ul>
4132 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
4133 - <input type="text" id="new_blocked_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
4134 - <select id="new_blocked_user_role" class="auth-role">
4135 - <option value="<?php echo esc_attr( $access_default_role ); ?>"><?php echo esc_html( ucfirst( $access_default_role ) ); ?></option>
4136 - </select>
4137 - <a href="javascript:void(0);" class="button-primary button-add-user" id="block_user_new" onclick="authAddUser( this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
4138 - </div>
3436 + // Print option elements.
3437 + ?><ul id="list_auth_settings_<?php echo $option; ?>" style="margin:0;">
3438 + <?php foreach ( $auth_settings_option as $key => $blocked_user ): ?>
3439 + <?php if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) continue; ?>
3440 + <?php if ( $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ) ): ?>
3441 + <?php $blocked_user['email'] = $blocked_wp_user->user_email; ?>
3442 + <?php $blocked_user['role'] = array_shift( $blocked_wp_user->roles ); ?>
3443 + <?php $blocked_user['date_added'] = $blocked_wp_user->user_registered; ?>
3444 + <?php $blocked_user['is_wp_user'] = true; ?>
3445 + <?php else: ?>
3446 + <?php $blocked_user['is_wp_user'] = false; ?>
3447 + <?php endif; ?>
3448 + <li>
3449 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $blocked_user['email']; ?>" readonly="true" class="auth-email" />
3450 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3451 + <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
3452 + </select>
3453 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $blocked_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3454 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user(this, 'blocked' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3455 + </li>
3456 + <?php endforeach; ?>
3457 + </ul>
3458 + <div id="new_auth_settings_<?php echo $option; ?>">
3459 + <input type="text" id="new_blocked_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3460 + <select id="new_blocked_user_role" class="auth-role">
3461 + <option value="<?php echo $access_default_role; ?>"><?php echo ucfirst( $access_default_role ); ?></option>
3462 + </select>
3463 + <a href="javascript:void(0);" class="button-primary" id="block_user_new" onclick="auth_add_user(this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
4139 3464 </div>
4140 3465 <?php
4141 3466 }
4142 3467
4143 3468
4144 - /**
4145 - * Settings print callback.
4146 - *
4147 - * @param string $args Args (e.g., multisite admin mode).
4148 - * @return void
4149 - */
4150 - public function print_section_info_access_login( $args = '' ) {
4151 - ?>
4152 - <div id="section_info_access_login" class="section_info">
3469 + function print_section_info_access_login( $args = '' ) {
3470 + ?><div id="section_info_access_login" class="section_info">
4153 3471 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
4154 - <p><?php esc_html_e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
4155 - </div>
4156 - <?php
3472 + <p><?php _e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
3473 + </div><?php
4157 3474 }
4158 3475
4159 3476
4160 - /**
4161 - * Settings print callback.
4162 - *
4163 - * @param string $args Args (e.g., multisite admin mode).
4164 - * @return void
4165 - */
4166 - public function print_radio_auth_access_who_can_login( $args = '' ) {
3477 + function print_radio_auth_access_who_can_login( $args = '' ) {
4167 3478 // Get plugin option.
4168 - $option = 'access_who_can_login';
4169 - $admin_mode = $this->get_admin_mode( $args );
3479 + $option = 'access_who_can_login';
3480 + $admin_mode = $this->get_admin_mode( $args );
4170 3481 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4171 3482
4172 3483 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4173 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3484 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4174 3485 $auth_settings_option = $this->get_plugin_option( $option );
4175 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) === '1' ) {
3486 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4176 3487 // Workaround: javascript code hides/shows other settings based
4177 3488 // on the selection in this option. If this option is overridden
4178 3489 // by a multisite option, it should show that value in order to
4179 3490 // correctly display the other appropriate options.
@@ -4179,49 +3490,33 @@
4179 3490 // correctly display the other appropriate options.
4180 3491 // Side effect: this site option will be overwritten by the
4181 3492 // multisite option on save. Since this is a 2-item radio, we
4182 3493 // determined this was acceptable.
4183 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3494 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4184 3495 }
4185 3496
4186 3497 // Print option elements.
4187 - ?>
4188 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="external_users"<?php checked( 'external_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users"><?php esc_html_e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
4189 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="approved_users"<?php checked( 'approved_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users"><?php esc_html_e( 'Only', 'authorizer' ); ?> <a href="javascript:chooseTab('access_lists' );" id="dashboard_link_approved_users"><?php esc_html_e( 'approved users', 'authorizer' ); ?></a> <?php esc_html_e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br />
4190 - <?php
3498 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_external_users" name="auth_settings[<?php echo $option; ?>]" value="external_users"<?php checked( 'external_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_external_users"><?php _e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
3499 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_approved_users" name="auth_settings[<?php echo $option; ?>]" value="approved_users"<?php checked( 'approved_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_approved_users"><?php _e( 'Only', 'authorizer' ); ?> <a href="javascript:choose_tab('access_lists' );" id="dashboard_link_approved_users"><?php _e( 'approved users', 'authorizer' ); ?></a> <?php _e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br /><?php
4191 3500 }
4192 3501
4193 3502
4194 - /**
4195 - * Settings print callback.
4196 - *
4197 - * @param string $args Args (e.g., multisite admin mode).
4198 - * @return void
4199 - */
4200 - public function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
3503 + function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
4201 3504 // Get plugin option.
4202 - $option = 'access_role_receive_pending_emails';
3505 + $option = 'access_role_receive_pending_emails';
4203 3506 $auth_settings_option = $this->get_plugin_option( $option );
4204 3507
4205 3508 // Print option elements.
4206 - ?>
4207 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
4208 - <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php esc_html_e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
3509 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
3510 + <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php _e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
4209 3511 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4210 - </select>
4211 - <?php
3512 + </select><?php
4212 3513 }
4213 3514
4214 3515
4215 - /**
4216 - * Settings print callback.
4217 - *
4218 - * @param string $args Args (e.g., multisite admin mode).
4219 - * @return void
4220 - */
4221 - public function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
3516 + function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
4222 3517 // Get plugin option.
4223 - $option = 'access_pending_redirect_to_message';
3518 + $option = 'access_pending_redirect_to_message';
4224 3519 $auth_settings_option = $this->get_plugin_option( $option );
4225 3520
4226 3521 // Print option elements.
4227 3522 wp_editor(
@@ -4230,25 +3525,19 @@
4230 3525 array(
4231 3526 'media_buttons' => false,
4232 3527 'textarea_name' => "auth_settings[$option]",
4233 3528 'textarea_rows' => 5,
4234 - 'tinymce' => true,
4235 - 'teeny' => true,
4236 - 'quicktags' => false,
3529 + 'tinymce' => true,
3530 + 'teeny' => true,
3531 + 'quicktags' => false,
4237 3532 )
4238 3533 );
4239 3534 }
4240 3535
4241 3536
4242 - /**
4243 - * Settings print callback.
4244 - *
4245 - * @param string $args Args (e.g., multisite admin mode).
4246 - * @return void
4247 - */
4248 - public function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
3537 + function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
4249 3538 // Get plugin option.
4250 - $option = 'access_blocked_redirect_to_message';
3539 + $option = 'access_blocked_redirect_to_message';
4251 3540 $auth_settings_option = $this->get_plugin_option( $option );
4252 3541
4253 3542 // Print option elements.
4254 3543 wp_editor(
@@ -4257,61 +3546,39 @@
4257 3546 array(
4258 3547 'media_buttons' => false,
4259 3548 'textarea_name' => "auth_settings[$option]",
4260 3549 'textarea_rows' => 5,
4261 - 'tinymce' => true,
4262 - 'teeny' => true,
4263 - 'quicktags' => false,
3550 + 'tinymce' => true,
3551 + 'teeny' => true,
3552 + 'quicktags' => false,
4264 3553 )
4265 3554 );
4266 3555 }
4267 3556
4268 3557
4269 - /**
4270 - * Settings print callback.
4271 - *
4272 - * @param string $args Args (e.g., multisite admin mode).
4273 - * @return void
4274 - */
4275 - public function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
3558 + function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
4276 3559 // Get plugin option.
4277 - $option = 'access_should_email_approved_users';
3560 + $option = 'access_should_email_approved_users';
4278 3561 $auth_settings_option = $this->get_plugin_option( $option );
4279 3562
4280 3563 // Print option elements.
4281 - ?>
4282 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label>
4283 - <?php
3564 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label><?php
4284 3565 }
4285 3566
4286 3567
4287 - /**
4288 - * Settings print callback.
4289 - *
4290 - * @param string $args Args (e.g., multisite admin mode).
4291 - * @return void
4292 - */
4293 - public function print_text_auth_access_email_approved_users_subject( $args = '' ) {
3568 + function print_text_auth_access_email_approved_users_subject( $args = '' ) {
4294 3569 // Get plugin option.
4295 - $option = 'access_email_approved_users_subject';
3570 + $option = 'access_email_approved_users_subject';
4296 3571 $auth_settings_option = $this->get_plugin_option( $option );
4297 3572
4298 3573 // Print option elements.
4299 - ?>
4300 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php echo wp_kses( __( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ), $this->allowed_html ); ?></small>
4301 - <?php
3574 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php _e( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ); ?></small><?php
4302 3575 }
4303 3576
4304 3577
4305 - /**
4306 - * Settings print callback.
4307 - *
4308 - * @param string $args Args (e.g., multisite admin mode).
4309 - * @return void
4310 - */
4311 - public function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
3578 + function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
4312 3579 // Get plugin option.
4313 - $option = 'access_email_approved_users_body';
3580 + $option = 'access_email_approved_users_body';
4314 3581 $auth_settings_option = $this->get_plugin_option( $option );
4315 3582
4316 3583 // Print option elements.
4317 3584 wp_editor(
@@ -4320,60 +3587,42 @@
4320 3587 array(
4321 3588 'media_buttons' => false,
4322 3589 'textarea_name' => "auth_settings[$option]",
4323 3590 'textarea_rows' => 9,
4324 - 'tinymce' => true,
4325 - 'teeny' => true,
4326 - 'quicktags' => false,
3591 + 'tinymce' => true,
3592 + 'teeny' => true,
3593 + 'quicktags' => false,
4327 3594 )
4328 3595 );
4329 - ?>
4330 - <small>
4331 - <?php
4332 - printf(
4333 - /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
4334 - wp_kses( __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ), $this->allowed_html ),
4335 - '<b>[site_name]</b>',
4336 - '<b>[site_url]</b>',
4337 - '<b>[user_email]</b>'
4338 - );
4339 - ?>
4340 - </small>
4341 - <?php
3596 +
3597 + ?><small><?php printf(
3598 + /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
3599 + __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ),
3600 + '<b>[site_name]</b>',
3601 + '<b>[site_url]</b>',
3602 + '<b>[user_email]</b>'
3603 + ); ?></small><?php
3604 +
4342 3605 }
4343 3606
4344 3607
4345 - /**
4346 - * Settings print callback.
4347 - *
4348 - * @param string $args Args (e.g., multisite admin mode).
4349 - * @return void
4350 - */
4351 - public function print_section_info_access_public( $args = '' ) {
4352 - ?>
4353 - <div id="section_info_access_public" class="section_info">
4354 - <p><?php esc_html_e( 'Choose your public access options here.', 'authorizer' ); ?></p>
4355 - </div>
4356 - <?php
3608 + function print_section_info_access_public( $args = '' ) {
3609 + ?><div id="section_info_access_public" class="section_info">
3610 + <p><?php _e( 'Choose your public access options here.', 'authorizer' ); ?></p>
3611 + </div><?php
4357 3612 }
4358 3613
4359 3614
4360 - /**
4361 - * Settings print callback.
4362 - *
4363 - * @param string $args Args (e.g., multisite admin mode).
4364 - * @return void
4365 - */
4366 - public function print_radio_auth_access_who_can_view( $args = '' ) {
3615 + function print_radio_auth_access_who_can_view( $args = '' ) {
4367 3616 // Get plugin option.
4368 - $option = 'access_who_can_view';
4369 - $admin_mode = $this->get_admin_mode( $args );
3617 + $option = 'access_who_can_view';
3618 + $admin_mode = $this->get_admin_mode( $args );
4370 3619 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4371 3620
4372 3621 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4373 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3622 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4374 3623 $auth_settings_option = $this->get_plugin_option( $option );
4375 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && '1' === $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) ) {
3624 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4376 3625 // Workaround: javascript code hides/shows other settings based
4377 3626 // on the selection in this option. If this option is overridden
4378 3627 // by a multisite option, it should show that value in order to
4379 3628 // correctly display the other appropriate options.
@@ -4379,66 +3628,42 @@
4379 3628 // correctly display the other appropriate options.
4380 3629 // Side effect: this site option will be overwritten by the
4381 3630 // multisite option on save. Since this is a 2-item radio, we
4382 3631 // determined this was acceptable.
4383 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3632 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4384 3633 }
4385 3634
4386 3635 // Print option elements.
4387 - ?>
4388 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="everyone"<?php checked( 'everyone' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone"><?php esc_html_e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
4389 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="logged_in_users"<?php checked( 'logged_in_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users"><?php esc_html_e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br />
4390 - <?php
3636 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_everyone" name="auth_settings[<?php echo $option; ?>]" value="everyone"<?php checked( 'everyone' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_everyone"><?php _e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
3637 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_logged_in_users" name="auth_settings[<?php echo $option; ?>]" value="logged_in_users"<?php checked( 'logged_in_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_logged_in_users"><?php _e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br /><?php
4391 3638 }
4392 3639
4393 3640
4394 - /**
4395 - * Settings print callback.
4396 - *
4397 - * @param string $args Args (e.g., multisite admin mode).
4398 - * @return void
4399 - */
4400 - public function print_radio_auth_access_redirect( $args = '' ) {
3641 + function print_radio_auth_access_redirect( $args = '' ) {
4401 3642 // Get plugin option.
4402 - $option = 'access_redirect';
3643 + $option = 'access_redirect';
4403 3644 $auth_settings_option = $this->get_plugin_option( $option );
4404 3645
4405 3646 // Print option elements.
4406 - ?>
4407 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="login"<?php checked( 'login' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login"><?php esc_html_e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
4408 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="message"<?php checked( 'message' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message"><?php esc_html_e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label>
4409 - <?php
3647 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_login" name="auth_settings[<?php echo $option; ?>]" value="login"<?php checked( 'login' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_login"><?php _e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
3648 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_message" name="auth_settings[<?php echo $option; ?>]" value="message"<?php checked( 'message' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_message"><?php _e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label><?php
4410 3649 }
4411 3650
4412 3651
4413 - /**
4414 - * Settings print callback.
4415 - *
4416 - * @param string $args Args (e.g., multisite admin mode).
4417 - * @return void
4418 - */
4419 - public function print_radio_auth_access_public_warning( $args = '' ) {
3652 + function print_radio_auth_access_public_warning( $args = '' ) {
4420 3653 // Get plugin option.
4421 - $option = 'access_public_warning';
3654 + $option = 'access_public_warning';
4422 3655 $auth_settings_option = $this->get_plugin_option( $option );
4423 3656
4424 3657 // Print option elements.
4425 - ?>
4426 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="no_warning"<?php checked( 'no_warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no"><?php echo wp_kses( __( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ), $this->allowed_html ); ?></label><br />
4427 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="warning"<?php checked( 'warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>"><?php echo wp_kses( __( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ), $this->allowed_html ); ?></label>
4428 - <?php
3658 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_no" name="auth_settings[<?php echo $option; ?>]" value="no_warning"<?php checked( 'no_warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_no"><?php _e( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ); ?></label><br />
3659 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="warning"<?php checked( 'warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>"><?php _e( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ); ?></label><?php
4429 3660 }
4430 3661
4431 3662
4432 - /**
4433 - * Settings print callback.
4434 - *
4435 - * @param string $args Args (e.g., multisite admin mode).
4436 - * @return void
4437 - */
4438 - public function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
3663 + function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
4439 3664 // Get plugin option.
4440 - $option = 'access_redirect_to_message';
3665 + $option = 'access_redirect_to_message';
4441 3666 $auth_settings_option = $this->get_plugin_option( $option );
4442 3667
4443 3668 // Print option elements.
4444 3669 wp_editor(
@@ -4447,25 +3672,19 @@
4447 3672 array(
4448 3673 'media_buttons' => false,
4449 3674 'textarea_name' => "auth_settings[$option]",
4450 3675 'textarea_rows' => 5,
4451 - 'tinymce' => true,
4452 - 'teeny' => true,
4453 - 'quicktags' => false,
3676 + 'tinymce' => true,
3677 + 'teeny' => true,
3678 + 'quicktags' => false,
4454 3679 )
4455 3680 );
4456 3681 }
4457 3682
4458 3683
4459 - /**
4460 - * Settings print callback.
4461 - *
4462 - * @param string $args Args (e.g., multisite admin mode).
4463 - * @return void
4464 - */
4465 - public function print_multiselect_auth_access_public_pages( $args = '' ) {
3684 + function print_multiselect_auth_access_public_pages( $args = '' ) {
4466 3685 // Get plugin option.
4467 - $option = 'access_public_pages';
3686 + $option = 'access_public_pages';
4468 3687 $auth_settings_option = $this->get_plugin_option( $option );
4469 3688 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4470 3689
4471 3690 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
@@ -4471,31 +3690,23 @@
4471 3690 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
4472 3691 $post_types = is_array( $post_types ) ? $post_types : array();
4473 3692
4474 3693 // Print option elements.
4475 - ?>
4476 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" multiple="multiple" name="auth_settings[<?php echo esc_attr( $option ); ?>][]">
4477 - <optgroup label="<?php esc_attr_e( 'Home', 'authorizer' ); ?>">
4478 - <option value="home" <?php selected( in_array( 'home', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Home Page', 'authorizer' ); ?></option>
4479 - <option value="auth_public_404" <?php selected( in_array( 'auth_public_404', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
3694 + ?><select id="auth_settings_<?php echo $option; ?>" multiple="multiple" name="auth_settings[<?php echo $option; ?>][]">
3695 + <optgroup label="<?php _e( 'Home', 'authorizer' ); ?>">
3696 + <option value="home" <?php echo in_array( 'home', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Home Page', 'authorizer' ); ?></option>
3697 + <option value="auth_public_404" <?php echo in_array( 'auth_public_404', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
4480 3698 </optgroup>
4481 - <?php foreach ( $post_types as $post_type ) : ?>
4482 - <optgroup label="<?php echo esc_attr( ucfirst( $post_type ) ); ?>">
4483 - <?php
4484 - $pages = get_posts(
4485 - array(
4486 - 'post_type' => $post_type,
4487 - 'posts_per_page' => 1000, // phpcs:ignore WordPress.VIP.PostsPerPage.posts_per_page_posts_per_page
4488 - )
4489 - );
4490 - $pages = is_array( $pages ) ? $pages : array();
4491 - foreach ( $pages as $page ) :
4492 - ?>
4493 - <option value="<?php echo esc_attr( $page->ID ); ?>" <?php selected( in_array( strval( $page->ID ), $auth_settings_option, true ) ); ?>><?php echo esc_html( $page->post_title ); ?></option>
3699 + <?php foreach ( $post_types as $post_type ): ?>
3700 + <optgroup label="<?php echo ucfirst( $post_type ); ?>">
3701 + <?php $pages = get_posts( array( 'post_type' => $post_type, 'posts_per_page' => -1 ) ); ?>
3702 + <?php $pages = is_array( $pages ) ? $pages : array(); ?>
3703 + <?php foreach ( $pages as $page ): ?>
3704 + <option value="<?php echo $page->ID; ?>" <?php echo in_array( $page->ID, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $page->post_title; ?></option>
4494 3705 <?php endforeach; ?>
4495 3706 </optgroup>
4496 3707 <?php endforeach; ?>
4497 - <optgroup label="<?php esc_attr_e( 'Categories', 'authorizer' ); ?>">
3708 + <optgroup label="<?php _e( 'Categories', 'authorizer' ); ?>">
4498 3709 <?php
4499 3710 // If sitepress-multilingual-cms plugin is enabled, temporarily disable
4500 3711 // its terms_clauses filter since it conflicts with the category handling.
4501 3712 if ( array_key_exists( 'sitepress', $GLOBALS ) && is_object( $GLOBALS['sitepress'] ) ) {
@@ -4504,155 +3715,107 @@
4504 3715 add_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) );
4505 3716 } else {
4506 3717 $categories = get_categories( array( 'hide_empty' => false ) );
4507 3718 }
4508 - foreach ( $categories as $category ) :
4509 - ?>
4510 - <option value="<?php echo esc_attr( 'cat_' . $category->slug ); ?>" <?php selected( in_array( 'cat_' . $category->slug, $auth_settings_option, true ) ); ?>><?php echo esc_html( $category->name ); ?></option>
3719 + foreach ( $categories as $category ) : ?>
3720 + <option value="<?php echo 'cat_' . $category->slug; ?>" <?php echo in_array( 'cat_' . $category->slug, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $category->name; ?></option>
4511 3721 <?php endforeach; ?>
4512 3722 </optgroup>
4513 - </select>
4514 - <?php
3723 + </select><?php
4515 3724 }
4516 3725
4517 3726
4518 - /**
4519 - * Settings print callback.
4520 - *
4521 - * @param string $args Args (e.g., multisite admin mode).
4522 - * @return void
4523 - */
4524 - public function print_section_info_external( $args = '' ) {
4525 - ?>
4526 - <div id="section_info_external" class="section_info">
4527 - <p><?php esc_html_e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
4528 - </div>
4529 - <?php
3727 + function print_section_info_external( $args = '' ) {
3728 + ?><div id="section_info_external" class="section_info">
3729 + <p><?php _e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
3730 + </div><?php
4530 3731 }
4531 3732
4532 3733
4533 - /**
4534 - * Settings print callback.
4535 - *
4536 - * @param string $args Args (e.g., multisite admin mode).
4537 - * @return void
4538 - */
4539 - public function print_select_auth_access_default_role( $args = '' ) {
3734 + function get_admin_mode( $args ) {
3735 + if ( is_array( $args ) && array_key_exists( MULTISITE_ADMIN, $args ) && $args[MULTISITE_ADMIN] === true ) {
3736 + return MULTISITE_ADMIN;
3737 + } else {
3738 + return SINGLE_ADMIN;
3739 + }
3740 + }
3741 +
3742 +
3743 + function print_select_auth_access_default_role( $args = '' ) {
4540 3744 // Get plugin option.
4541 - $option = 'access_default_role';
3745 + $option = 'access_default_role';
4542 3746 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4543 3747
4544 3748 // Print option elements.
4545 - ?>
4546 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3749 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4547 3750 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4548 - <option value=""<?php selected( '' === $auth_settings_option ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4549 - </select>
4550 - <?php
3751 + </select><?php
4551 3752 }
4552 3753
4553 3754
4554 - /**
4555 - * Settings print callback.
4556 - *
4557 - * @param string $args Args (e.g., multisite admin mode).
4558 - * @return void
4559 - */
4560 - public function print_checkbox_auth_external_google( $args = '' ) {
3755 + function print_checkbox_auth_external_google( $args = '' ) {
4561 3756 // Get plugin option.
4562 - $option = 'google';
3757 + $option = 'google';
4563 3758 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4564 3759
4565 3760 // Print option elements.
4566 - ?>
4567 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable Google Logins', 'authorizer' ); ?></label>
4568 - <?php
3761 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable Google Logins', 'authorizer' ); ?></label><?php
4569 3762 }
4570 3763
4571 3764
4572 - /**
4573 - * Settings print callback.
4574 - *
4575 - * @param string $args Args (e.g., multisite admin mode).
4576 - * @return void
4577 - */
4578 - public function print_text_google_clientid( $args = '' ) {
3765 + function print_text_google_clientid( $args = '' ) {
4579 3766 // Get plugin option.
4580 - $option = 'google_clientid';
3767 + $option = 'google_clientid';
4581 3768 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4582 3769
4583 3770 // Print option elements.
4584 - $site_url_parts = wp_parse_url( get_site_url() );
4585 - $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
4586 -
4587 - esc_html_e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' );
4588 - ?>
3771 + $site_url_parts = parse_url( get_site_url() );
3772 + $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
3773 + ?><?php _e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' ); ?>
4589 3774 <ol>
4590 - <li><?php echo wp_kses( __( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ), $this->allowed_html ); ?></li>
4591 - <li><?php echo wp_kses( __( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ), $this->allowed_html ); ?>
3775 + <li><?php _e( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ); ?></li>
3776 + <li><?php _e( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ); ?>
4592 3777 <ul>
4593 - <li><?php echo wp_kses( __( 'Application Type: <strong>Web application</strong>', 'authorizer' ), $this->allowed_html ); ?></li>
4594 - <li><?php esc_html_e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo esc_html( rtrim( $site_url_host, '/' ) ); ?></strong></li>
4595 - <li><?php echo wp_kses( __( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ), $this->allowed_html ); ?></li>
3778 + <li><?php _e( 'Application Type: <strong>Web application</strong>', 'authorizer' ); ?></li>
3779 + <li><?php _e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo rtrim( $site_url_host, '/' ); ?></strong></li>
3780 + <li><?php _e( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ); ?></li>
4596 3781 </ul>
4597 3782 </li>
4598 - <li><?php esc_html_e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
4599 - <li><?php echo wp_kses( __( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ), $this->allowed_html ); ?></li>
4600 - <li><?php echo wp_kses( __( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ), $this->allowed_html ); ?></li>
3783 + <li><?php _e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
3784 + <li><?php _e( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ); ?></li>
3785 + <li><?php _e( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ); ?></li>
4601 3786 </ol>
4602 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:560px;" />
4603 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer' ); ?></label>
4604 - <?php
3787 + <input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:560px;" />
3788 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer'); ?></label><?php
4605 3789 }
4606 3790
4607 3791
4608 - /**
4609 - * Settings print callback.
4610 - *
4611 - * @param string $args Args (e.g., multisite admin mode).
4612 - * @return void
4613 - */
4614 - public function print_text_google_clientsecret( $args = '' ) {
3792 + function print_text_google_clientsecret( $args = '' ) {
4615 3793 // Get plugin option.
4616 - $option = 'google_clientsecret';
3794 + $option = 'google_clientsecret';
4617 3795 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4618 3796
4619 3797 // Print option elements.
4620 - ?>
4621 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:220px;" />
4622 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer' ); ?></label>
4623 - <?php
3798 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:220px;" />
3799 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer'); ?></label><?php
4624 3800 }
4625 3801
4626 3802
4627 - /**
4628 - * Settings print callback.
4629 - *
4630 - * @param string $args Args (e.g., multisite admin mode).
4631 - * @return void
4632 - */
4633 - public function print_text_google_hosteddomain( $args = '' ) {
3803 + function print_text_google_hosteddomain( $args = '' ) {
4634 3804 // Get plugin option.
4635 - $option = 'google_hosteddomain';
3805 + $option = 'google_hosteddomain';
4636 3806 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4637 3807
4638 3808 // Print option elements.
4639 - ?>
4640 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:220px;"><?php echo esc_html( $auth_settings_option ); ?></textarea>
4641 - <br /><small><?php esc_html_e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php esc_html_e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
3809 + ?><textarea id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" placeholder="" style="width:220px;"><?php echo $auth_settings_option; ?></textarea>
3810 + <br /><small><?php _e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php _e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
4642 3811 <?php
4643 3812 }
4644 3813
4645 3814
4646 - /**
4647 - * Settings print callback.
4648 - *
4649 - * @param string $args Args (e.g., multisite admin mode).
4650 - * @return void
4651 - */
4652 - public function print_checkbox_auth_external_cas( $args = '' ) {
3815 + function print_checkbox_auth_external_cas( $args = '' ) {
4653 3816 // Get plugin option.
4654 - $option = 'cas';
3817 + $option = 'cas';
4655 3818 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4656 3819
4657 3820 // Make sure php5-curl extension is installed on server.
4658 3821 $curl_installed_message = ! function_exists( 'curl_init' ) ? __( '<a href="http://www.php.net//manual/en/curl.installation.php" target="_blank" style="color: red;">PHP CURL extension</a> is not installed', 'authorizer' ) : '';
@@ -4671,217 +3834,128 @@
4671 3834 ')</span>';
4672 3835 }
4673 3836
4674 3837 // Print option elements.
4675 - ?>
4676 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $error_message, $this->allowed_html ); ?>
4677 - <?php
3838 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo $error_message; ?><?php
4678 3839 }
4679 3840
4680 3841
4681 - /**
4682 - * Settings print callback.
4683 - *
4684 - * @param string $args Args (e.g., multisite admin mode).
4685 - * @return void
4686 - */
4687 - public function print_text_cas_custom_label( $args = '' ) {
3842 + function print_text_cas_custom_label( $args = '' ) {
4688 3843 // Get plugin option.
4689 - $option = 'cas_custom_label';
3844 + $option = 'cas_custom_label';
4690 3845 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4691 3846
4692 3847 // Print option elements.
4693 - esc_html_e( 'The button on the login page will read:', 'authorizer' );
4694 - ?>
4695 - <p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php esc_html_e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="CAS" style="width: 100px;" /></a></p>
4696 - <?php
3848 + ?><?php _e( 'The button on the login page will read:', 'authorizer' ); ?><p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php _e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="CAS" style="width: 100px;" /></a></p><?php
4697 3849 }
4698 3850
4699 3851
4700 - /**
4701 - * Settings print callback.
4702 - *
4703 - * @param string $args Args (e.g., multisite admin mode).
4704 - * @return void
4705 - */
4706 - public function print_text_cas_host( $args = '' ) {
3852 + function print_text_cas_host( $args = '' ) {
4707 3853 // Get plugin option.
4708 - $option = 'cas_host';
3854 + $option = 'cas_host';
4709 3855 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4710 3856
4711 3857 // Print option elements.
4712 - ?>
4713 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4714 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: authn.example.edu', 'authorizer' ); ?></label>
4715 - <?php
3858 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3859 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: authn.example.edu', 'authorizer'); ?></label><?php
4716 3860 }
4717 3861
4718 3862
4719 - /**
4720 - * Settings print callback.
4721 - *
4722 - * @param string $args Args (e.g., multisite admin mode).
4723 - * @return void
4724 - */
4725 - public function print_text_cas_port( $args = '' ) {
3863 + function print_text_cas_port( $args = '' ) {
4726 3864 // Get plugin option.
4727 - $option = 'cas_port';
3865 + $option = 'cas_port';
4728 3866 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4729 3867
4730 3868 // Print option elements.
4731 - ?>
4732 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4733 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 443', 'authorizer' ); ?></label>
4734 - <?php
3869 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:50px;" />
3870 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 443', 'authorizer'); ?></label><?php
4735 3871 }
4736 3872
4737 3873
4738 - /**
4739 - * Settings print callback.
4740 - *
4741 - * @param string $args Args (e.g., multisite admin mode).
4742 - * @return void
4743 - */
4744 - public function print_text_cas_path( $args = '' ) {
3874 + function print_text_cas_path( $args = '' ) {
4745 3875 // Get plugin option.
4746 - $option = 'cas_path';
3876 + $option = 'cas_path';
4747 3877 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4748 3878
4749 3879 // Print option elements.
4750 - ?>
4751 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4752 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: /cas', 'authorizer' ); ?></label>
4753 - <?php
3880 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3881 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: /cas', 'authorizer'); ?></label><?php
4754 3882 }
4755 3883
4756 3884
4757 - /**
4758 - * Settings print callback.
4759 - *
4760 - * @param string $args Args (e.g., multisite admin mode).
4761 - * @return void
4762 - */
4763 - public function print_select_cas_version( $args = '' ) {
3885 + function print_select_cas_version( $args = '' ) {
4764 3886 // Get plugin option.
4765 - $option = 'cas_version';
3887 + $option = 'cas_version';
4766 3888 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4767 3889
4768 3890 // Print option elements.
4769 - ?>
4770 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3891 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4771 3892 <option value="SAML_VERSION_1_1" <?php selected( $auth_settings_option, 'SAML_VERSION_1_1' ); ?>>SAML_VERSION_1_1</option>
4772 3893 <option value="CAS_VERSION_3_0" <?php selected( $auth_settings_option, 'CAS_VERSION_3_0' ); ?>>CAS_VERSION_3_0</option>
4773 3894 <option value="CAS_VERSION_2_0" <?php selected( $auth_settings_option, 'CAS_VERSION_2_0' ); ?>>CAS_VERSION_2_0</option>
4774 3895 <option value="CAS_VERSION_1_0" <?php selected( $auth_settings_option, 'CAS_VERSION_1_0' ); ?>>CAS_VERSION_1_0</option>
4775 - </select>
4776 - <?php
3896 + </select><?php
4777 3897 }
4778 3898
4779 3899
4780 - /**
4781 - * Settings print callback.
4782 - *
4783 - * @param string $args Args (e.g., multisite admin mode).
4784 - * @return void
4785 - */
4786 - public function print_text_cas_attr_email( $args = '' ) {
3900 + function print_text_cas_attr_email( $args = '' ) {
4787 3901 // Get plugin option.
4788 - $option = 'cas_attr_email';
3902 + $option = 'cas_attr_email';
4789 3903 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4790 3904
4791 3905 // Print option elements.
4792 - ?>
4793 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4794 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
4795 - <br /><small><?php echo wp_kses( __( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
4796 - <?php
3906 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3907 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: mail', 'authorizer'); ?></label>
3908 + <br /><small><?php _e( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
4797 3909 }
4798 3910
4799 3911
4800 - /**
4801 - * Settings print callback.
4802 - *
4803 - * @param string $args Args (e.g., multisite admin mode).
4804 - * @return void
4805 - */
4806 - public function print_text_cas_attr_first_name( $args = '' ) {
3912 + function print_text_cas_attr_first_name( $args = '' ) {
4807 3913 // Get plugin option.
4808 - $option = 'cas_attr_first_name';
3914 + $option = 'cas_attr_first_name';
4809 3915 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4810 3916
4811 3917 // Print option elements.
4812 - ?>
4813 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4814 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenName', 'authorizer' ); ?></label>
4815 - <?php
3918 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3919 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: givenName', 'authorizer'); ?></label><?php
4816 3920 }
4817 3921
4818 3922
4819 - /**
4820 - * Settings print callback.
4821 - *
4822 - * @param string $args Args (e.g., multisite admin mode).
4823 - * @return void
4824 - */
4825 - public function print_text_cas_attr_last_name( $args = '' ) {
3923 + function print_text_cas_attr_last_name( $args = '' ) {
4826 3924 // Get plugin option.
4827 - $option = 'cas_attr_last_name';
3925 + $option = 'cas_attr_last_name';
4828 3926 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4829 3927
4830 3928 // Print option elements.
4831 - ?>
4832 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4833 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
4834 - <?php
3929 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
3930 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sn', 'authorizer'); ?></label><?php
4835 3931 }
4836 3932
4837 3933
4838 - /**
4839 - * Settings print callback.
4840 - *
4841 - * @param string $args Args (e.g., multisite admin mode).
4842 - * @return void
4843 - */
4844 - public function print_checkbox_cas_attr_update_on_login( $args = '' ) {
3934 + function print_checkbox_cas_attr_update_on_login( $args = '' ) {
4845 3935 // Get plugin option.
4846 - $option = 'cas_attr_update_on_login';
3936 + $option = 'cas_attr_update_on_login';
4847 3937 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4848 3938
4849 3939 // Print option elements.
4850 - ?>
4851 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
4852 - <?php
3940 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
4853 3941 }
4854 3942
4855 3943
4856 - /**
4857 - * Settings print callback.
4858 - *
4859 - * @param string $args Args (e.g., multisite admin mode).
4860 - * @return void
4861 - */
4862 - public function print_checkbox_cas_auto_login( $args = '' ) {
3944 + function print_checkbox_cas_auto_login( $args = '' ) {
4863 3945 // Get plugin option.
4864 - $option = 'cas_auto_login';
3946 + $option = 'cas_auto_login';
4865 3947 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4866 3948
4867 3949 // Print option elements.
4868 - ?>
4869 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
4870 - <p><small><?php esc_html_e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p>
4871 - <?php
3950 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
3951 + <p><small><?php _e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p><?php
4872 3952 }
4873 3953
4874 3954
4875 - /**
4876 - * Settings print callback.
4877 - *
4878 - * @param string $args Args (e.g., multisite admin mode).
4879 - * @return void
4880 - */
4881 - public function print_checkbox_auth_external_ldap( $args = '' ) {
3955 + function print_checkbox_auth_external_ldap( $args = '' ) {
4882 3956 // Get plugin option.
4883 - $option = 'ldap';
3957 + $option = 'ldap';
4884 3958 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4885 3959
4886 3960 // Make sure php5-ldap extension is installed on server.
4887 3961 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
@@ -4886,324 +3960,193 @@
4886 3960 // Make sure php5-ldap extension is installed on server.
4887 3961 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
4888 3962
4889 3963 // Print option elements.
4890 - ?>
4891 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $ldap_installed_message, $this->allowed_html ); ?>
4892 - <?php
3964 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo $ldap_installed_message; ?><?php
4893 3965 }
4894 3966
4895 3967
4896 - /**
4897 - * Settings print callback.
4898 - *
4899 - * @param string $args Args (e.g., multisite admin mode).
4900 - * @return void
4901 - */
4902 - public function print_text_ldap_host( $args = '' ) {
3968 + function print_text_ldap_host( $args = '' ) {
4903 3969 // Get plugin option.
4904 - $option = 'ldap_host';
3970 + $option = 'ldap_host';
4905 3971 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4906 3972
4907 3973 // Print option elements.
4908 - ?>
4909 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
4910 - <br /><small><?php esc_html_e( 'Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).', 'authorizer' ); ?></small>
4911 - <?php
3974 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
3975 + <br /><small><?php _e( "Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).", 'authorizer' ); ?></small><?php
4912 3976 }
4913 3977
4914 3978
4915 - /**
4916 - * Settings print callback.
4917 - *
4918 - * @param string $args Args (e.g., multisite admin mode).
4919 - * @return void
4920 - */
4921 - public function print_text_ldap_port( $args = '' ) {
3979 + function print_text_ldap_port( $args = '' ) {
4922 3980 // Get plugin option.
4923 - $option = 'ldap_port';
3981 + $option = 'ldap_port';
4924 3982 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4925 3983
4926 3984 // Print option elements.
4927 - ?>
4928 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4929 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 389', 'authorizer' ); ?></label>
4930 - <br /><small><?php esc_html_e( 'If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.', 'authorizer' ); ?></small>
4931 - <?php
3985 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:50px;" />
3986 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: 389', 'authorizer' ); ?></label>
3987 + <br /><small><?php _e( "If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.", 'authorizer' ); ?></small><?php
4932 3988 }
4933 3989
4934 3990
4935 - /**
4936 - * Settings print callback.
4937 - *
4938 - * @param string $args Args (e.g., multisite admin mode).
4939 - * @return void
4940 - */
4941 - public function print_checkbox_ldap_tls( $args = '' ) {
3991 + function print_checkbox_ldap_tls( $args = '' ) {
4942 3992 // Get plugin option.
4943 - $option = 'ldap_tls';
3993 + $option = 'ldap_tls';
4944 3994 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4945 3995
4946 3996 // Print option elements.
4947 - ?>
4948 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></label>
4949 - <br /><small><?php esc_html_e( 'If ldaps is used, this should be unchecked', 'authorizer' ); ?></small>
4950 - <?php
3997 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Use TLS', 'authorizer' ); ?></label><?php
4951 3998 }
4952 3999
4953 4000
4954 - /**
4955 - * Settings print callback.
4956 - *
4957 - * @param string $args Args (e.g., multisite admin mode).
4958 - * @return void
4959 - */
4960 - public function print_text_ldap_search_base( $args = '' ) {
4001 + function print_text_ldap_search_base( $args = '' ) {
4961 4002 // Get plugin option.
4962 - $option = 'ldap_search_base';
4003 + $option = 'ldap_search_base';
4963 4004 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4964 4005
4965 4006 // Print option elements.
4966 - ?>
4967 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:330px;"><?php echo esc_attr( $auth_settings_option ); ?></textarea>
4968 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: ou=people,dc=example,dc=edu', 'authorizer' ); ?></label>
4969 - <br /><small><?php esc_html_e( 'If you have multiple search bases, separate them by newlines (one per line).', 'authorizer' ); ?></small>
4970 - <?php
4007 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
4008 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: ou=people,dc=example,dc=edu', 'authorizer'); ?></label><?php
4971 4009 }
4972 4010
4973 4011
4974 - /**
4975 - * Settings print callback.
4976 - *
4977 - * @param string $args Args (e.g., multisite admin mode).
4978 - * @return void
4979 - */
4980 - public function print_text_ldap_uid( $args = '' ) {
4012 + function print_text_ldap_uid( $args = '' ) {
4981 4013 // Get plugin option.
4982 - $option = 'ldap_uid';
4014 + $option = 'ldap_uid';
4983 4015 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4984 4016
4985 4017 // Print option elements.
4986 - ?>
4987 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:80px;" />
4988 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: uid', 'authorizer' ); ?></label>
4989 - <?php
4018 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:80px;" />
4019 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: uid', 'authorizer' ); ?></label><?php
4990 4020 }
4991 4021
4992 4022
4993 - /**
4994 - * Settings print callback.
4995 - *
4996 - * @param string $args Args (e.g., multisite admin mode).
4997 - * @return void
4998 - */
4999 - public function print_text_ldap_attr_email( $args = '' ) {
4023 + function print_text_ldap_attr_email( $args = '' ) {
5000 4024 // Get plugin option.
5001 - $option = 'ldap_attr_email';
4025 + $option = 'ldap_attr_email';
5002 4026 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5003 4027
5004 4028 // Print option elements.
5005 - ?>
5006 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5007 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
5008 - <br /><small><?php echo wp_kses( __( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
5009 - <?php
4029 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4030 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: mail', 'authorizer' ); ?></label>
4031 + <br /><small><?php _e( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
5010 4032 }
5011 4033
5012 4034
5013 - /**
5014 - * Settings print callback.
5015 - *
5016 - * @param string $args Args (e.g., multisite admin mode).
5017 - * @return void
5018 - */
5019 - public function print_text_ldap_user( $args = '' ) {
4035 + function print_text_ldap_user( $args = '' ) {
5020 4036 // Get plugin option.
5021 - $option = 'ldap_user';
4037 + $option = 'ldap_user';
5022 4038 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5023 4039
5024 4040 // Print option elements.
5025 - ?>
5026 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
5027 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label>
5028 - <?php
4041 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:330px;" />
4042 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label><?php
5029 4043 }
5030 4044
5031 4045
5032 - /**
5033 - * Settings print callback.
5034 - *
5035 - * @param string $args Args (e.g., multisite admin mode).
5036 - * @return void
5037 - */
5038 - public function print_password_ldap_password( $args = '' ) {
4046 + function print_password_ldap_password( $args = '' ) {
5039 4047 // Get plugin option.
5040 - $option = 'ldap_password';
4048 + $option = 'ldap_password';
5041 4049 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5042 4050
5043 4051 // Print option elements.
5044 - ?>
5045 - <input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
5046 - <input type="password" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $this->decrypt( $auth_settings_option ) ); ?>" autocomplete="off" />
5047 - <?php
4052 + ?><input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
4053 + <input type="password" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $this->decrypt( $auth_settings_option ); ?>" autocomplete="off" /><?php
5048 4054 }
5049 4055
5050 4056
5051 - /**
5052 - * Settings print callback.
5053 - *
5054 - * @param string $args Args (e.g., multisite admin mode).
5055 - * @return void
5056 - */
5057 - public function print_text_ldap_lostpassword_url( $args = '' ) {
4057 + function print_text_ldap_lostpassword_url( $args = '' ) {
5058 4058 // Get plugin option.
5059 - $option = 'ldap_lostpassword_url';
4059 + $option = 'ldap_lostpassword_url';
5060 4060 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5061 4061
5062 4062 // Print option elements.
5063 - ?>
5064 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width: 400px;" />
5065 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label>
5066 - <?php
4063 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width: 400px;" />
4064 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label><?php
5067 4065 }
5068 4066
5069 4067
5070 - /**
5071 - * Settings print callback.
5072 - *
5073 - * @param string $args Args (e.g., multisite admin mode).
5074 - * @return void
5075 - */
5076 - public function print_text_ldap_attr_first_name( $args = '' ) {
4068 + function print_text_ldap_attr_first_name( $args = '' ) {
5077 4069 // Get plugin option.
5078 - $option = 'ldap_attr_first_name';
4070 + $option = 'ldap_attr_first_name';
5079 4071 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5080 4072
5081 4073 // Print option elements.
5082 - ?>
5083 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5084 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenname', 'authorizer' ); ?></label>
5085 - <?php
4074 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4075 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: givenname', 'authorizer' ); ?></label><?php
5086 4076 }
5087 4077
5088 4078
5089 - /**
5090 - * Settings print callback.
5091 - *
5092 - * @param string $args Args (e.g., multisite admin mode).
5093 - * @return void
5094 - */
5095 - public function print_text_ldap_attr_last_name( $args = '' ) {
4079 + function print_text_ldap_attr_last_name( $args = '' ) {
5096 4080 // Get plugin option.
5097 - $option = 'ldap_attr_last_name';
4081 + $option = 'ldap_attr_last_name';
5098 4082 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5099 4083
5100 4084 // Print option elements.
5101 - ?>
5102 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5103 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
5104 - <?php
4085 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" />
4086 + <br /><label for="auth_settings_<?php echo $option; ?>" class="helper"><?php _e( 'Example: sn', 'authorizer' ); ?></label><?php
5105 4087 }
5106 4088
5107 4089
5108 - /**
5109 - * Settings print callback.
5110 - *
5111 - * @param string $args Args (e.g., multisite admin mode).
5112 - * @return void
5113 - */
5114 - public function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
4090 + function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
5115 4091 // Get plugin option.
5116 - $option = 'ldap_attr_update_on_login';
4092 + $option = 'ldap_attr_update_on_login';
5117 4093 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5118 4094
5119 4095 // Print option elements.
5120 - ?>
5121 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
5122 - <?php
4096 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
5123 4097 }
5124 4098
5125 4099
5126 - /**
5127 - * Settings print callback.
5128 - *
5129 - * @param string $args Args (e.g., multisite admin mode).
5130 - * @return void
5131 - */
5132 - public function print_section_info_advanced( $args = '' ) {
5133 - ?>
5134 - <div id="section_info_advanced" class="section_info">
5135 - <p><?php esc_html_e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
5136 - </div>
5137 - <?php
4100 + function print_section_info_advanced( $args = '' ) {
4101 + ?><div id="section_info_advanced" class="section_info">
4102 + <p><?php _e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
4103 + </div><?php
5138 4104 }
5139 4105
5140 4106
5141 - /**
5142 - * Settings print callback.
5143 - *
5144 - * @param string $args Args (e.g., multisite admin mode).
5145 - * @return void
5146 - */
5147 - public function print_text_auth_advanced_lockouts( $args = '' ) {
4107 + function print_text_auth_advanced_lockouts( $args = '' ) {
5148 4108 // Get plugin option.
5149 - $option = 'advanced_lockouts';
4109 + $option = 'advanced_lockouts';
5150 4110 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5151 4111
5152 4112 // Print option elements.
5153 - esc_html_e( 'After', 'authorizer' );
5154 - ?>
5155 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_1]" value="<?php echo esc_attr( $auth_settings_option['attempts_1'] ); ?>" placeholder="10" style="width:30px;" />
5156 - <?php esc_html_e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
5157 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_1]" value="<?php echo esc_attr( $auth_settings_option['duration_1'] ); ?>" placeholder="1" style="width:30px;" />
5158 - <?php esc_html_e( 'minute(s).', 'authorizer' ); ?>
4113 + ?><?php _e( 'After', 'authorizer' ); ?>
4114 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_1" name="auth_settings[<?php echo $option; ?>][attempts_1]" value="<?php echo $auth_settings_option['attempts_1']; ?>" placeholder="10" style="width:30px;" />
4115 + <?php _e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
4116 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_1" name="auth_settings[<?php echo $option; ?>][duration_1]" value="<?php echo $auth_settings_option['duration_1']; ?>" placeholder="1" style="width:30px;" />
4117 + <?php _e( 'minute(s).', 'authorizer' ); ?>
5159 4118 <br />
5160 - <?php esc_html_e( 'After', 'authorizer' ); ?>
5161 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_2]" value="<?php echo esc_attr( $auth_settings_option['attempts_2'] ); ?>" placeholder="10" style="width:30px;" />
5162 - <?php esc_html_e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
5163 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_2]" value="<?php echo esc_attr( $auth_settings_option['duration_2'] ); ?>" placeholder="10" style="width:30px;" />
5164 - <?php esc_html_e( 'minutes.', 'authorizer' ); ?>
4119 + <?php _e( 'After', 'authorizer' ); ?>
4120 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_2" name="auth_settings[<?php echo $option; ?>][attempts_2]" value="<?php echo $auth_settings_option['attempts_2']; ?>" placeholder="10" style="width:30px;" />
4121 + <?php _e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
4122 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_2" name="auth_settings[<?php echo $option; ?>][duration_2]" value="<?php echo $auth_settings_option['duration_2']; ?>" placeholder="10" style="width:30px;" />
4123 + <?php _e( 'minutes.', 'authorizer' ); ?>
5165 4124 <br />
5166 - <?php esc_html_e( 'Reset the delays after', 'authorizer' ); ?>
5167 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_reset_duration" name="auth_settings[<?php echo esc_attr( $option ); ?>][reset_duration]" value="<?php echo esc_attr( $auth_settings_option['reset_duration'] ); ?>" placeholder="240" style="width:40px;" />
5168 - <?php esc_html_e( 'minutes with no invalid attempts.', 'authorizer' ); ?>
5169 - <?php
4125 + <?php _e( 'Reset the delays after', 'authorizer' ); ?>
4126 + <input type="text" id="auth_settings_<?php echo $option; ?>_reset_duration" name="auth_settings[<?php echo $option; ?>][reset_duration]" value="<?php echo $auth_settings_option['reset_duration']; ?>" placeholder="240" style="width:40px;" />
4127 + <?php _e( 'minutes with no invalid attempts.', 'authorizer' ); ?><?php
5170 4128 }
5171 4129
5172 4130
5173 - /**
5174 - * Settings print callback.
5175 - *
5176 - * @param string $args Args (e.g., multisite admin mode).
5177 - * @return void
5178 - */
5179 - public function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
4131 + function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
5180 4132 // Get plugin option.
5181 - $option = 'advanced_hide_wp_login';
4133 + $option = 'advanced_hide_wp_login';
5182 4134 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5183 4135
5184 4136 // Print option elements.
5185 - ?>
5186 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
5187 - <p><small><?php esc_html_e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo esc_attr( wp_login_url() ); ?>?external=wordpress" target="_blank"><?php echo esc_html( wp_login_url() ); ?>?external=wordpress</a>.</p>
5188 - <?php
4137 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
4138 + <p><small><?php _e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo wp_login_url(); ?>?external=wordpress" target="_blank"><?php echo wp_login_url(); ?>?external=wordpress</a>.</p><?php
5189 4139 }
5190 4140
5191 4141
5192 - /**
5193 - * Settings print callback.
5194 - *
5195 - * @param string $args Args (e.g., multisite admin mode).
5196 - * @return void
5197 - */
5198 - public function print_radio_auth_advanced_branding( $args = '' ) {
4142 + function print_radio_auth_advanced_branding( $args = '' ) {
5199 4143 // Get plugin option.
5200 - $option = 'advanced_branding';
4144 + $option = 'advanced_branding';
5201 4145 $auth_settings_option = $this->get_plugin_option( $option );
5202 4146
5203 4147 // Print option elements.
5204 - ?>
5205 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="default"<?php checked( 'default' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default"><?php esc_html_e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
4148 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_default" name="auth_settings[<?php echo $option; ?>]" value="default"<?php checked( 'default' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_default"><?php _e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
5206 4149 <?php
5207 4150
5208 4151 /**
5209 4152 * Developers can use the `authorizer_add_branding_option` filter
@@ -5208,8 +4151,9 @@
5208 4151 /**
5209 4152 * Developers can use the `authorizer_add_branding_option` filter
5210 4153 * to add a radio button for "Custom WordPress login branding"
5211 4154 * under the "Advanced" tab in Authorizer options. Example:
4155 + *
5212 4156 * function my_authorizer_add_branding_option( $branding_options ) {
5213 4157 * $new_branding_option = array(
5214 4158 * 'value' => 'your_brand'
5215 4159 * 'description' => 'Custom Your Brand Login Screen',
@@ -5223,274 +4167,133 @@
5223 4167 */
5224 4168 $branding_options = array();
5225 4169 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
5226 4170 foreach ( $branding_options as $branding_option ) {
5227 - // Make sure the custom brands have the required values.
4171 + // Make sure the custom brands have the required values
5228 4172 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'description', $branding_option ) ) ) {
5229 4173 continue;
5230 4174 }
5231 - ?>
5232 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $branding_option['value'] ); ?>"<?php checked( $branding_option['value'] === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>"><?php echo esc_html( $branding_option['description'] ); ?></label><br />
5233 - <?php
4175 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $branding_option['value']; ?>"<?php checked( $branding_option['value'] == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>"><?php echo $branding_option['description']; ?></label><br /><?php
5234 4176 }
5235 4177
5236 4178 // Print message about adding custom brands if there are none.
5237 4179 if ( count( $branding_options ) === 0 ) {
5238 - ?>
5239 - <p><em><?php echo wp_kses( __( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ), $this->allowed_html ); ?></em></p>
5240 - <?php
4180 + ?><p><em><?php _e( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ); ?></em></p><?php
5241 4181 }
5242 4182 }
5243 4183
5244 4184
5245 - /**
5246 - * Settings print callback.
5247 - *
5248 - * @param string $args Args (e.g., multisite admin mode).
5249 - * @return void
5250 - */
5251 - public function print_radio_auth_advanced_admin_menu( $args = '' ) {
4185 + function print_radio_auth_advanced_admin_menu( $args = '' ) {
5252 4186 // Get plugin option.
5253 - $option = 'advanced_admin_menu';
4187 + $option = 'advanced_admin_menu';
5254 4188 $auth_settings_option = $this->get_plugin_option( $option );
5255 4189
5256 4190 // Print option elements.
5257 - ?>
5258 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="settings"<?php checked( 'settings' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings"><?php esc_html_e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
5259 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="top"<?php checked( 'top' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top"><?php esc_html_e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br />
5260 - <?php
4191 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_settings" name="auth_settings[<?php echo $option; ?>]" value="settings"<?php checked( 'settings' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_settings"><?php _e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
4192 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_top" name="auth_settings[<?php echo $option; ?>]" value="top"<?php checked( 'top' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_top"><?php _e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br /><?php
5261 4193
5262 4194 }
5263 4195
5264 4196
5265 - /**
5266 - * Settings print callback.
5267 - *
5268 - * @param string $args Args (e.g., multisite admin mode).
5269 - * @return void
5270 - */
5271 - public function print_select_auth_advanced_usermeta( $args = '' ) {
4197 + function print_select_auth_advanced_usermeta( $args = '' ) {
5272 4198 // Get plugin option.
5273 - $option = 'advanced_usermeta';
4199 + $option = 'advanced_usermeta';
5274 4200 $auth_settings_option = $this->get_plugin_option( $option );
5275 4201
5276 4202 // Print option elements.
5277 - ?>
5278 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5279 - <option value=""><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
5280 - <?php
5281 - if ( class_exists( 'acf' ) ) :
4203 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4204 + <option value=""><?php _e( '-- None --', 'authorizer' ); ?></option>
4205 + <?php if ( class_exists( 'acf' ) ) :
5282 4206 // Get ACF 5 fields. Note: it would be much easier to use `get_field_objects()`
5283 4207 // or `get_field_objects( 'user_' . get_current_user_id() )`, but neither will
5284 4208 // list fields that have never been given values for users (i.e., new ACF
5285 4209 // fields). Therefore we fall back on finding any ACF fields applied to users
5286 4210 // (user_role or user_form location rules in the field group definition).
5287 - $fields = array();
4211 + $fields = array();
5288 4212 $acf_field_group_ids = array();
5289 - $acf_field_groups = new WP_Query(
5290 - array(
5291 - 'post_type' => 'acf-field-group',
5292 - )
5293 - );
4213 + $acf_field_groups = new WP_Query( array(
4214 + 'post_type' => 'acf-field-group',
4215 + ));
5294 4216 while ( $acf_field_groups->have_posts() ) : $acf_field_groups->the_post();
5295 4217 if ( strpos( get_the_content(), 's:5:"param";s:9:"user_role"' ) !== false || strpos( get_the_content(), 's:5:"param";s:9:"user_form"' ) !== false ) :
5296 4218 array_push( $acf_field_group_ids, get_the_ID() );
5297 4219 endif;
5298 - endwhile;
5299 - wp_reset_postdata();
4220 + endwhile; wp_reset_postdata();
5300 4221 foreach ( $acf_field_group_ids as $acf_field_group_id ) :
5301 - $acf_fields = new WP_Query(
5302 - array(
5303 - 'post_type' => 'acf-field',
5304 - 'post_parent' => $acf_field_group_id,
5305 - )
5306 - );
4222 + $acf_fields = new WP_Query( array(
4223 + 'post_type' => 'acf-field',
4224 + 'post_parent' => $acf_field_group_id,
4225 + ));
5307 4226 while ( $acf_fields->have_posts() ) : $acf_fields->the_post();
5308 4227 global $post;
5309 - $fields[ $post->post_name ] = get_field_object( $post->post_name );
5310 - endwhile;
5311 - wp_reset_postdata();
4228 + $fields[$post->post_name] = get_field_object( $post->post_name );
4229 + endwhile; wp_reset_postdata();
5312 4230 endforeach;
5313 4231 // Get ACF 4 fields.
5314 - $acf4_field_groups = new WP_Query(
5315 - array(
5316 - 'post_type' => 'acf',
5317 - )
5318 - );
4232 + $acf4_field_groups = new WP_Query( array(
4233 + 'post_type' => 'acf',
4234 + ));
5319 4235 while ( $acf4_field_groups->have_posts() ) : $acf4_field_groups->the_post();
5320 4236 $field_group_rules = get_post_meta( get_the_ID(), 'rule', true );
5321 - if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && 'ef_user' === $field_group_rules['param'] ) :
4237 + if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && $field_group_rules['param'] === 'ef_user' ) :
5322 4238 $acf4_fields = get_post_custom( get_the_ID() );
5323 4239 foreach ( $acf4_fields as $meta_key => $meta_value ) :
5324 4240 if ( strpos( $meta_key, 'field_' ) === 0 ) :
5325 - $meta_value = unserialize( $meta_value[0] );
5326 - $fields[ $meta_key ] = $meta_value;
4241 + $meta_value = unserialize( $meta_value[0] );
4242 + $fields[$meta_key] = $meta_value;
5327 4243 endif;
5328 4244 endforeach;
5329 4245 endif;
5330 - endwhile;
5331 - wp_reset_postdata();
5332 - ?>
4246 + endwhile; wp_reset_postdata(); ?>
5333 4247 <optgroup label="ACF User Fields:">
5334 - <?php foreach ( (array) $fields as $field => $field_object ) : ?>
5335 - <option value="acf___<?php echo esc_attr( $field_object['key'] ); ?>"<?php selected( "acf___{$field_object['key']}" === $auth_settings_option ); ?>><?php echo esc_html( $field_object['label'] ); ?></option>
4248 + <?php foreach ( (array)$fields as $field => $field_object ) : ?>
4249 + <option value="acf___<?php echo $field_object['key']; ?>"<?php if ( $auth_settings_option === "acf___{$field_object['key']}" ) echo ' selected="selected"'; ?>><?php echo $field_object['label']; ?></option>
5336 4250 <?php endforeach; ?>
5337 4251 </optgroup>
5338 4252 <?php endif; ?>
5339 - <optgroup label="<?php esc_attr_e( 'All Usermeta:', 'authorizer' ); ?>">
5340 - <?php
5341 - foreach ( $this->get_all_usermeta_keys() as $meta_key ) :
5342 - if ( substr( $meta_key, 0, 3 ) === 'wp_' ) :
5343 - continue;
5344 - endif;
5345 - ?>
5346 - <option value="<?php echo esc_attr( $meta_key ); ?>"<?php selected( $auth_settings_option === $meta_key ); ?>><?php echo esc_html( $meta_key ); ?></option>
4253 + <optgroup label="<?php _e( 'All Usermeta:', 'authorizer' ); ?>">
4254 + <?php foreach ( $this->get_all_usermeta_keys() as $meta_key ) : if ( substr( $meta_key, 0, 3 ) === 'wp_' ) continue; ?>
4255 + <option value="<?php echo $meta_key; ?>"<?php if ( $auth_settings_option === $meta_key ) echo ' selected="selected"'; ?>><?php echo $meta_key; ?></option>
5347 4256 <?php endforeach; ?>
5348 4257 </optgroup>
5349 - </select>
5350 - <?php
4258 + </select><?php
5351 4259 }
5352 4260
5353 4261
5354 - /**
5355 - * Settings print callback.
5356 - *
5357 - * @param string $args Args (e.g., multisite admin mode).
5358 - * @return void
5359 - */
5360 - public function print_text_auth_advanced_users_per_page( $args = '' ) {
4262 + function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5361 4263 // Get plugin option.
5362 - $option = 'advanced_users_per_page';
5363 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5364 -
5365 - // Print option elements.
5366 - ?>
5367 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" size="4" />
5368 - <?php
5369 - }
5370 -
5371 -
5372 - /**
5373 - * Settings print callback.
5374 - *
5375 - * @param string $args Args (e.g., multisite admin mode).
5376 - * @return void
5377 - */
5378 - public function print_select_auth_advanced_users_sort_by( $args = '' ) {
5379 - // Get plugin option.
5380 - $option = 'advanced_users_sort_by';
5381 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5382 -
5383 - // Print option elements.
5384 - ?>
5385 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5386 - <option value="created" <?php selected( $auth_settings_option, 'created' ); ?>><?php esc_html_e( 'Date approved', 'authorizer' ); ?></option>
5387 - <option value="email" <?php selected( $auth_settings_option, 'email' ); ?>><?php esc_html_e( 'Email', 'authorizer' ); ?></option>
5388 - <option value="role" <?php selected( $auth_settings_option, 'role' ); ?>><?php esc_html_e( 'Role', 'authorizer' ); ?></option>
5389 - <option value="date_added" <?php selected( $auth_settings_option, 'date_added' ); ?>><?php esc_html_e( 'Date registered', 'authorizer' ); ?></option>
5390 - </select>
5391 - <?php
5392 - }
5393 -
5394 -
5395 - /**
5396 - * Settings print callback.
5397 - *
5398 - * @param string $args Args (e.g., multisite admin mode).
5399 - * @return void
5400 - */
5401 - public function print_select_auth_advanced_users_sort_order( $args = '' ) {
5402 - // Get plugin option.
5403 - $option = 'advanced_users_sort_order';
5404 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5405 -
5406 - // Print option elements.
5407 - ?>
5408 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5409 - <option value="asc" <?php selected( $auth_settings_option, 'asc' ); ?>><?php esc_html_e( 'Ascending', 'authorizer' ); ?></option>
5410 - <option value="desc" <?php selected( $auth_settings_option, 'desc' ); ?>><?php esc_html_e( 'Descending', 'authorizer' ); ?></option>
5411 - </select>
5412 - <?php
5413 - }
5414 -
5415 -
5416 - /**
5417 - * Settings print callback.
5418 - *
5419 - * @param string $args Args (e.g., multisite admin mode).
5420 - * @return void
5421 - */
5422 - public function print_checkbox_auth_advanced_widget_enabled( $args = '' ) {
5423 - // Get plugin option.
5424 - $option = 'advanced_widget_enabled';
5425 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5426 -
5427 - // Print option elements.
5428 - ?>
5429 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></label>
5430 - <p><small><?php esc_html_e( 'Note: Only users with the create_users capability will be able to see the dashboard widget.', 'authorizer' ); ?></small></p>
5431 - <?php
5432 - }
5433 -
5434 -
5435 - /**
5436 - * Settings print callback.
5437 - *
5438 - * @param string $args Args (e.g., multisite admin mode).
5439 - * @return void
5440 - */
5441 - public function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5442 - // Get plugin option.
5443 - $option = 'advanced_override_multisite';
4264 + $option = 'advanced_override_multisite';
5444 4265 $auth_settings_option = $this->get_plugin_option( $option );
5445 4266
5446 4267 // Print option elements.
5447 - ?>
5448 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label>
5449 - <?php
4268 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label><?php
5450 4269 }
5451 4270
5452 4271
5453 4272
5454 4273 /**
5455 - * Determines whether we are in single site or multisite admin context.
5456 - *
5457 - * @param string $args Args (e.g., multisite admin mode).
5458 - * @return int Current mode.
5459 - */
5460 - private function get_admin_mode( $args ) {
5461 - if ( is_array( $args ) && array_key_exists( WP_Plugin_Authorizer::NETWORK_CONTEXT, $args ) && true === $args[ WP_Plugin_Authorizer::NETWORK_CONTEXT ] ) {
5462 - return WP_Plugin_Authorizer::NETWORK_CONTEXT;
5463 - } else {
5464 - return WP_Plugin_Authorizer::SINGLE_CONTEXT;
5465 - }
5466 - }
5467 -
5468 -
5469 - /**
5470 4274 * Add help documentation to the options page.
5471 - *
5472 - * Action: load-settings_page_authorizer > admin_head
4275 + * Run on action hook chain: load-settings_page_authorizer > admin_head
5473 4276 */
5474 4277 public function admin_head() {
5475 4278 $screen = get_current_screen();
5476 4279
5477 - // Add help tab for Access Lists Settings.
4280 + // Add help tab for Access Lists Settings
5478 4281 $help_auth_settings_access_lists_content = '
5479 - <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) . '</p>
5480 - <p>' . __( '<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.', 'authorizer' ) . '</p>
5481 - <p>' . __( '<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ) . '</p>
5482 - <p>' . __( 'Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.', 'authorizer' ) . '</p>
4282 + <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) .'</p>
4283 + <p>' . __( "<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.", 'authorizer' ) . '</p>
4284 + <p>' . __( "<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.", 'authorizer' ) . '</p>
4285 + <p>' . __( "Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.", 'authorizer' ) . '</p>
5483 4286 ';
5484 4287 $screen->add_help_tab(
5485 4288 array(
5486 - 'id' => 'help_auth_settings_access_lists_content',
5487 - 'title' => __( 'Access Lists', 'authorizer' ),
4289 + 'id' => 'help_auth_settings_access_lists_content',
4290 + 'title' => __( 'Access Lists', 'authorizer' ),
5488 4291 'content' => $help_auth_settings_access_lists_content,
5489 4292 )
5490 4293 );
5491 4294
5492 - // Add help tab for Login Access Settings.
4295 + // Add help tab for Login Access Settings
5493 4296 $help_auth_settings_access_login_content = '
5494 4297 <p>' . __( "<strong>Who can log in to the site?</strong>: Choose the level of access restriction you'd like to use on your site here. You can leave the site open to anyone with a WordPress account or an account on an external service like Google, CAS, or LDAP, or restrict it to WordPress users and only the external users that you specify via the <em>Access Lists</em>.", 'authorizer' ) . '</p>
5495 4298 <p>' . __( "<strong>Which role should receive email notifications about pending users?</strong>: If you've restricted access to <strong>approved users</strong>, you can determine which WordPress users will receive a notification email everytime a new external user successfully logs in and is added to the pending list. All users of the specified role will receive an email, and the external user will get a message (specified below) telling them their access is pending approval.", 'authorizer' ) . '</p>
5496 4299 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
@@ -5496,84 +4299,84 @@
5496 4299 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
5497 4300 ';
5498 4301 $screen->add_help_tab(
5499 4302 array(
5500 - 'id' => 'help_auth_settings_access_login_content',
5501 - 'title' => __( 'Login Access', 'authorizer' ),
4303 + 'id' => 'help_auth_settings_access_login_content',
4304 + 'title' => __( 'Login Access', 'authorizer' ),
5502 4305 'content' => $help_auth_settings_access_login_content,
5503 4306 )
5504 4307 );
5505 4308
5506 - // Add help tab for Public Access Settings.
4309 + // Add help tab for Public Access Settings
5507 4310 $help_auth_settings_access_public_content = '
5508 4311 <p>' . __( "<strong>Who can view the site?</strong>: You can restrict the site's visibility by only allowing logged in users to see pages. If you do so, you can customize the specifics about the site's privacy using the settings below.", 'authorizer' ) . '</p>
5509 4312 <p>' . __( "<strong>What pages (if any) should be available to everyone?</strong>: If you'd like to declare certain pages on your site as always public (such as the course syllabus, introduction, or calendar), specify those pages here. These pages will always be available no matter what access restrictions exist.", 'authorizer' ) . '</p>
5510 - <p>' . __( '<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.', 'authorizer' ) . '</p>
5511 - <p>' . __( '<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.', 'authorizer' ) . '</p>
5512 - <p>' . __( '<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.', 'authorizer' ) . '</p>
4313 + <p>' . __( "<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.", 'authorizer' ) . '</p>
4314 + <p>' . __( "<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.", 'authorizer' ) . '</p>
4315 + <p>' . __( "<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.", 'authorizer' ) . '</p>
5513 4316 ';
5514 4317 $screen->add_help_tab(
5515 4318 array(
5516 - 'id' => 'help_auth_settings_access_public_content',
5517 - 'title' => __( 'Public Access', 'authorizer' ),
4319 + 'id' => 'help_auth_settings_access_public_content',
4320 + 'title' => __( 'Public Access', 'authorizer' ),
5518 4321 'content' => $help_auth_settings_access_public_content,
5519 4322 )
5520 4323 );
5521 4324
5522 - // Add help tab for External Service (CAS, LDAP) Settings.
4325 + // Add help tab for External Service (CAS, LDAP) Settings
5523 4326 $help_auth_settings_external_content = '
5524 4327 <p>' . __( "<strong>Type of external service to authenticate against</strong>: Choose which authentication service type you will be using. You'll have to fill out different fields below depending on which service you choose.", 'authorizer' ) . '</p>
5525 - <p>' . __( '<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.', 'authorizer' ) . '</p>
5526 - <p>' . __( '<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.', 'authorizer' ) . '</p>
5527 - <p>' . __( '<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.', 'authorizer' ) . '</p>
5528 - <p>' . __( '<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!', 'authorizer' ) . '</p>
5529 - <p><strong><em>' . __( 'If you enable Google logins:', 'authorizer' ) . '</em></strong></p>
4328 + <p>' . __( "<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.", 'authorizer' ) . '</p>
4329 + <p>' . __( "<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.", 'authorizer' ) . '</p>
4330 + <p>' . __( "<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.", 'authorizer' ) . '</p>
4331 + <p>' . __( "<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!", 'authorizer' ) . '</p>
4332 + <p><strong><em>' . __( "If you enable Google logins:", 'authorizer' ) . '</em></strong></p>
5530 4333 <ul>
5531 4334 <li>' . __( "<strong>Google Client ID</strong>: You can generate this ID by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client ID typically looks something like this: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com", 'authorizer' ) . '</li>
5532 4335 <li>' . __( "<strong>Google Client Secret</strong>: You can generate this secret by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client Secret typically looks something like this: sDNgX5_pr_5bly-frKmvp8jT", 'authorizer' ) . '</li>
5533 4336 </ul>
5534 - <p><strong><em>' . __( 'If you enable CAS logins:', 'authorizer' ) . '</em></strong></p>
4337 + <p><strong><em>' . __( "If you enable CAS logins:", 'authorizer' ) . '</em></strong></p>
5535 4338 <ul>
5536 - <li>' . __( '<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).', 'authorizer' ) . '</li>
5537 - <li>' . __( '<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).', 'authorizer' ) . '</li>
5538 - <li>' . __( '<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).', 'authorizer' ) . '</li>
4339 + <li>' . __( "<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).", 'authorizer' ) . '</li>
4340 + <li>' . __( "<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).", 'authorizer' ) . '</li>
4341 + <li>' . __( "<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).", 'authorizer' ) . '</li>
5539 4342 <li>' . __( "<strong>CAS attribute containing first name</strong>: Enter the CAS attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5540 4343 <li>' . __( "<strong>CAS attribute containing last name</strong>: Enter the CAS attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5541 - <li>' . __( '<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4344 + <li>' . __( "<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5542 4345 </ul>
5543 - <p><strong><em>' . __( 'If you enable LDAP logins:', 'authorizer' ) . '</em></strong></p>
4346 + <p><strong><em>' . __( "If you enable LDAP logins:", 'authorizer' ) . '</em></strong></p>
5544 4347 <ul>
5545 - <li>' . __( '<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.', 'authorizer' ) . '</li>
5546 - <li>' . __( '<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.', 'authorizer' ) . '</li>
5547 - <li>' . __( '<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu', 'authorizer' ) . '</li>
5548 - <li>' . __( '<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.', 'authorizer' ) . '</li>
5549 - <li>' . __( '<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.', 'authorizer' ) . '</li>
5550 - <li>' . __( '<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.', 'authorizer' ) . '</li>
5551 - <li>' . __( '<strong>Use TLS</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.', 'authorizer' ) . '</li>
4348 + <li>' . __( "<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.", 'authorizer' ) . '</li>
4349 + <li>' . __( "<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.", 'authorizer' ) . '</li>
4350 + <li>' . __( "<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu", 'authorizer' ) . '</li>
4351 + <li>' . __( "<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.", 'authorizer' ) . '</li>
4352 + <li>' . __( "<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.", 'authorizer' ) . '</li>
4353 + <li>' . __( "<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.", 'authorizer' ) . '</li>
4354 + <li>' . __( "<strong>Secure Connection (TLS)</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.", 'authorizer' ) . '</li>
5552 4355 <li>' . __( "<strong>Custom lost password URL</strong>: The WordPress login page contains a link to recover a lost password. If you have external users who shouldn't change the password on their WordPress account, point them to the appropriate location to change the password on their external authentication service here.", 'authorizer' ) . '</li>
5553 4356 <li>' . __( "<strong>LDAP attribute containing first name</strong>: Enter the LDAP attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5554 4357 <li>' . __( "<strong>LDAP attribute containing last name</strong>: Enter the LDAP attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5555 - <li>' . __( '<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4358 + <li>' . __( "<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5556 4359 </ul>
5557 4360 ';
5558 4361 $screen->add_help_tab(
5559 4362 array(
5560 - 'id' => 'help_auth_settings_external_content',
5561 - 'title' => __( 'External Service', 'authorizer' ),
4363 + 'id' => 'help_auth_settings_external_content',
4364 + 'title' => __( 'External Service', 'authorizer' ),
5562 4365 'content' => $help_auth_settings_external_content,
5563 4366 )
5564 4367 );
5565 4368
5566 - // Add help tab for Advanced Settings.
4369 + // Add help tab for Advanced Settings
5567 4370 $help_auth_settings_advanced_content = '
5568 - <p>' . __( '<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.', 'authorizer' ) . '</p>
5569 - <p>' . __( '<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
4371 + <p>' . __( "<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.", 'authorizer' ) . '</p>
4372 + <p>' . __( "<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:", 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
5570 4373 <p>' . __( "<strong>Custom WordPress login branding</strong>: If you'd like to use custom branding on the WordPress login page, select that here. You will need to use the `authorizer_add_branding_option` filter in your theme to add it. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.", 'authorizer' ) . '</p>
5571 4374 ';
5572 4375 $screen->add_help_tab(
5573 4376 array(
5574 - 'id' => 'help_auth_settings_advanced_content',
5575 - 'title' => __( 'Advanced', 'authorizer' ),
4377 + 'id' => 'help_auth_settings_advanced_content',
4378 + 'title' => __( 'Advanced', 'authorizer' ),
5576 4379 'content' => $help_auth_settings_advanced_content,
5577 4380 )
5578 4381 );
5579 4382 }
@@ -5588,66 +4391,65 @@
5588 4391
5589 4392
5590 4393 /**
5591 4394 * Network Admin menu item
4395 + * Hook: network_admin_menu
5592 4396 *
5593 - * Action: network_admin_menu
5594 - *
4397 + * @param none
5595 4398 * @return void
5596 4399 */
5597 4400 public function network_admin_menu() {
5598 4401 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
5599 4402 add_menu_page(
5600 - 'Authorizer',
5601 - 'Authorizer',
5602 - 'manage_network_options',
5603 - 'authorizer',
4403 + 'Authorizer', // Page title
4404 + 'Authorizer', // Menu title
4405 + 'manage_network_options', // Capability
4406 + 'authorizer', // Menu slug
5604 4407 array( $this, 'create_network_admin_page' ),
5605 - 'dashicons-groups',
5606 - 89 // Position.
4408 + 'dashicons-groups', // Icon URL
4409 + 89 // Position
5607 4410 );
5608 4411 }
5609 4412
5610 4413
5611 4414 /**
5612 - * Output the HTML for the options page.
4415 + * Output the HTML for the options page
5613 4416 */
5614 4417 public function create_network_admin_page() {
5615 4418 if ( ! current_user_can( 'manage_network_options' ) ) {
5616 - wp_die( wp_kses( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ), $this->allowed_html ) );
4419 + wp_die( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ) );
5617 4420 }
5618 - $auth_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5619 - ?>
4421 + $auth_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); ?>
5620 4422 <div class="wrap">
5621 4423 <form method="post" action="" autocomplete="off">
5622 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
5623 - <p><?php echo wp_kses( __( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ), $this->allowed_html ); ?></p>
4424 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
4425 + <p><?php _e( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ); ?></p>
5624 4426
5625 - <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 === intval( $auth_settings['multisite_override'] ) ); ?> /><label for="auth_settings_multisite_override"><?php esc_html_e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
4427 + <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 == $auth_settings['multisite_override'] ); ?> /><label for="auth_settings_multisite_override"><?php _e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
5626 4428
5627 4429 <div id="auth_multisite_settings_disabled_overlay" style="display: none;"></div>
5628 4430
5629 4431 <div class="wrap" id="auth_multisite_settings">
5630 - <?php $this->print_section_info_tabs( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?>
4432 + <?php $this->print_section_info_tabs( array( MULTISITE_ADMIN => true ) ); ?>
5631 4433
5632 4434 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
5633 4435
5634 - <?php // Custom access lists (for network, we only really want approved list, not pending or blocked). ?>
4436 + <?php // Custom access lists (for network, we only really want approved list, not pending or blocked) ?>
5635 4437 <div id="section_info_access_lists" class="section_info">
5636 - <p><?php esc_html_e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
4438 + <p><?php _e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
5637 4439 </div>
5638 4440 <table class="form-table"><tbody>
5639 4441 <tr>
5640 - <th scope="row"><?php esc_html_e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
5641 - <td><?php $this->print_radio_auth_access_who_can_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4442 + <th scope="row"><?php _e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
4443 + <td><?php $this->print_radio_auth_access_who_can_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5642 4444 </tr>
5643 4445 <tr>
5644 - <th scope="row"><?php esc_html_e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
5645 - <td><?php $this->print_radio_auth_access_who_can_view( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4446 + <th scope="row"><?php _e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
4447 + <td><?php $this->print_radio_auth_access_who_can_view( array( MULTISITE_ADMIN => true ) ); ?></td>
5646 4448 </tr>
5647 4449 <tr>
5648 - <th scope="row"><?php esc_html_e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php echo wp_kses( __( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ), $this->allowed_html ); ?></em></small></th>
5649 - <td><?php $this->print_combo_auth_access_users_approved( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4450 + <th scope="row"><?php _e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php _e( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ); ?></em></small></th>
4451 + <td><?php $this->print_combo_auth_access_users_approved( array( MULTISITE_ADMIN => true ) ); ?></td>
5650 4452 </tr>
5651 4453 </tbody></table>
5652 4454
5653 4455 <?php $this->print_section_info_external(); ?>
@@ -5652,122 +4454,122 @@
5652 4454
5653 4455 <?php $this->print_section_info_external(); ?>
5654 4456 <table class="form-table"><tbody>
5655 4457 <tr>
5656 - <th scope="row"><?php esc_html_e( 'Default role for new users', 'authorizer' ); ?></th>
5657 - <td><?php $this->print_select_auth_access_default_role( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4458 + <th scope="row"><?php _e( 'Default role for new users', 'authorizer' ); ?></th>
4459 + <td><?php $this->print_select_auth_access_default_role( array( MULTISITE_ADMIN => true ) ); ?></td>
5658 4460 </tr>
5659 4461 <tr>
5660 - <th scope="row"><?php esc_html_e( 'Google Logins', 'authorizer' ); ?></th>
5661 - <td><?php $this->print_checkbox_auth_external_google( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4462 + <th scope="row"><?php _e( 'Google Logins', 'authorizer' ); ?></th>
4463 + <td><?php $this->print_checkbox_auth_external_google( array( MULTISITE_ADMIN => true ) ); ?></td>
5662 4464 </tr>
5663 4465 <tr>
5664 - <th scope="row"><?php esc_html_e( 'Google Client ID', 'authorizer' ); ?></th>
5665 - <td><?php $this->print_text_google_clientid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4466 + <th scope="row"><?php _e( 'Google Client ID', 'authorizer' ); ?></th>
4467 + <td><?php $this->print_text_google_clientid( array( MULTISITE_ADMIN => true ) ); ?></td>
5666 4468 </tr>
5667 4469 <tr>
5668 - <th scope="row"><?php esc_html_e( 'Google Client Secret', 'authorizer' ); ?></th>
5669 - <td><?php $this->print_text_google_clientsecret( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4470 + <th scope="row"><?php _e( 'Google Client Secret', 'authorizer' ); ?></th>
4471 + <td><?php $this->print_text_google_clientsecret( array( MULTISITE_ADMIN => true ) ); ?></td>
5670 4472 </tr>
5671 4473 <tr>
5672 - <th scope="row"><?php esc_html_e( 'Google Hosted Domain', 'authorizer' ); ?></th>
5673 - <td><?php $this->print_text_google_hosteddomain( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4474 + <th scope="row"><?php _e( 'Google Hosted Domain', 'authorizer' ); ?></th>
4475 + <td><?php $this->print_text_google_hosteddomain( array( MULTISITE_ADMIN => true ) ); ?></td>
5674 4476 </tr>
5675 4477 <tr>
5676 - <th scope="row"><?php esc_html_e( 'CAS Logins', 'authorizer' ); ?></th>
5677 - <td><?php $this->print_checkbox_auth_external_cas( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4478 + <th scope="row"><?php _e( 'CAS Logins', 'authorizer' ); ?></th>
4479 + <td><?php $this->print_checkbox_auth_external_cas( array( MULTISITE_ADMIN => true ) ); ?></td>
5678 4480 </tr>
5679 4481 <tr>
5680 - <th scope="row"><?php esc_html_e( 'CAS Custom Label', 'authorizer' ); ?></th>
5681 - <td><?php $this->print_text_cas_custom_label( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4482 + <th scope="row"><?php _e( 'CAS Custom Label', 'authorizer' ); ?></th>
4483 + <td><?php $this->print_text_cas_custom_label( array( MULTISITE_ADMIN => true ) ); ?></td>
5682 4484 </tr>
5683 4485 <tr>
5684 - <th scope="row"><?php esc_html_e( 'CAS server hostname', 'authorizer' ); ?></th>
5685 - <td><?php $this->print_text_cas_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4486 + <th scope="row"><?php _e( 'CAS server hostname', 'authorizer' ); ?></th>
4487 + <td><?php $this->print_text_cas_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5686 4488 </tr>
5687 4489 <tr>
5688 - <th scope="row"><?php esc_html_e( 'CAS server port', 'authorizer' ); ?></th>
5689 - <td><?php $this->print_text_cas_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4490 + <th scope="row"><?php _e( 'CAS server port', 'authorizer' ); ?></th>
4491 + <td><?php $this->print_text_cas_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5690 4492 </tr>
5691 4493 <tr>
5692 - <th scope="row"><?php esc_html_e( 'CAS server path/context', 'authorizer' ); ?></th>
5693 - <td><?php $this->print_text_cas_path( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4494 + <th scope="row"><?php _e( 'CAS server path/context', 'authorizer' ); ?></th>
4495 + <td><?php $this->print_text_cas_path( array( MULTISITE_ADMIN => true ) ); ?></td>
5694 4496 </tr>
5695 4497 <tr>
5696 - <th scope="row"><?php esc_html_e( 'CAS server version', 'authorizer' ); ?></th>
5697 - <td><?php $this->print_select_cas_version( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4498 + <th scope="row"><?php _e( 'CAS server version', 'authorizer' ); ?></th>
4499 + <td><?php $this->print_select_cas_version( array( MULTISITE_ADMIN => true ) ); ?></td>
5698 4500 </tr>
5699 4501 <tr>
5700 - <th scope="row"><?php esc_html_e( 'CAS attribute containing email', 'authorizer' ); ?></th>
5701 - <td><?php $this->print_text_cas_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4502 + <th scope="row"><?php _e( 'CAS attribute containing email', 'authorizer' ); ?></th>
4503 + <td><?php $this->print_text_cas_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5702 4504 </tr>
5703 4505 <tr>
5704 - <th scope="row"><?php esc_html_e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
5705 - <td><?php $this->print_text_cas_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4506 + <th scope="row"><?php _e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
4507 + <td><?php $this->print_text_cas_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5706 4508 </tr>
5707 4509 <tr>
5708 - <th scope="row"><?php esc_html_e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
5709 - <td><?php $this->print_text_cas_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4510 + <th scope="row"><?php _e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
4511 + <td><?php $this->print_text_cas_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5710 4512 </tr>
5711 4513 <tr>
5712 - <th scope="row"><?php esc_html_e( 'CAS attribute update', 'authorizer' ); ?></th>
5713 - <td><?php $this->print_checkbox_cas_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4514 + <th scope="row"><?php _e( 'CAS attribute update', 'authorizer' ); ?></th>
4515 + <td><?php $this->print_checkbox_cas_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5714 4516 </tr>
5715 4517 <tr>
5716 - <th scope="row"><?php esc_html_e( 'CAS automatic login', 'authorizer' ); ?></th>
5717 - <td><?php $this->print_checkbox_cas_auto_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4518 + <th scope="row"><?php _e( 'CAS automatic login', 'authorizer' ); ?></th>
4519 + <td><?php $this->print_checkbox_cas_auto_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5718 4520 </tr>
5719 4521 <tr>
5720 - <th scope="row"><?php esc_html_e( 'LDAP Logins', 'authorizer' ); ?></th>
5721 - <td><?php $this->print_checkbox_auth_external_ldap( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4522 + <th scope="row"><?php _e( 'LDAP Logins', 'authorizer' ); ?></th>
4523 + <td><?php $this->print_checkbox_auth_external_ldap( array( MULTISITE_ADMIN => true ) ); ?></td>
5722 4524 </tr>
5723 4525 <tr>
5724 - <th scope="row"><?php esc_html_e( 'LDAP Host', 'authorizer' ); ?></th>
5725 - <td><?php $this->print_text_ldap_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4526 + <th scope="row"><?php _e( 'LDAP Host', 'authorizer' ); ?></th>
4527 + <td><?php $this->print_text_ldap_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5726 4528 </tr>
5727 4529 <tr>
5728 - <th scope="row"><?php esc_html_e( 'LDAP Port', 'authorizer' ); ?></th>
5729 - <td><?php $this->print_text_ldap_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4530 + <th scope="row"><?php _e( 'LDAP Port', 'authorizer' ); ?></th>
4531 + <td><?php $this->print_text_ldap_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5730 4532 </tr>
5731 4533 <tr>
5732 - <th scope="row"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></th>
5733 - <td><?php $this->print_checkbox_ldap_tls( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4534 + <th scope="row"><?php _e( 'Secure Connection (TLS)', 'authorizer' ); ?></th>
4535 + <td><?php $this->print_checkbox_ldap_tls( array( MULTISITE_ADMIN => true ) ); ?></td>
5734 4536 </tr>
5735 4537 <tr>
5736 - <th scope="row"><?php esc_html_e( 'LDAP Search Base', 'authorizer' ); ?></th>
5737 - <td><?php $this->print_text_ldap_search_base( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4538 + <th scope="row"><?php _e( 'LDAP Search Base', 'authorizer' ); ?></th>
4539 + <td><?php $this->print_text_ldap_search_base( array( MULTISITE_ADMIN => true ) ); ?></td>
5738 4540 </tr>
5739 4541 <tr>
5740 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
5741 - <td><?php $this->print_text_ldap_uid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4542 + <th scope="row"><?php _e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
4543 + <td><?php $this->print_text_ldap_uid( array( MULTISITE_ADMIN => true ) ); ?></td>
5742 4544 </tr>
5743 4545 <tr>
5744 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
5745 - <td><?php $this->print_text_ldap_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4546 + <th scope="row"><?php _e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
4547 + <td><?php $this->print_text_ldap_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5746 4548 </tr>
5747 4549 <tr>
5748 - <th scope="row"><?php esc_html_e( 'LDAP Directory User', 'authorizer' ); ?></th>
5749 - <td><?php $this->print_text_ldap_user( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4550 + <th scope="row"><?php _e( 'LDAP Directory User', 'authorizer' ); ?></th>
4551 + <td><?php $this->print_text_ldap_user( array( MULTISITE_ADMIN => true ) ); ?></td>
5750 4552 </tr>
5751 4553 <tr>
5752 - <th scope="row"><?php esc_html_e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
5753 - <td><?php $this->print_password_ldap_password( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4554 + <th scope="row"><?php _e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
4555 + <td><?php $this->print_password_ldap_password( array( MULTISITE_ADMIN => true ) ); ?></td>
5754 4556 </tr>
5755 4557 <tr>
5756 - <th scope="row"><?php esc_html_e( 'Custom lost password URL', 'authorizer' ); ?></th>
5757 - <td><?php $this->print_text_ldap_lostpassword_url( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4558 + <th scope="row"><?php _e( 'Custom lost password URL', 'authorizer' ); ?></th>
4559 + <td><?php $this->print_text_ldap_lostpassword_url( array( MULTISITE_ADMIN => true ) ); ?></td>
5758 4560 </tr>
5759 4561 <tr>
5760 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
5761 - <td><?php $this->print_text_ldap_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4562 + <th scope="row"><?php _e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
4563 + <td><?php $this->print_text_ldap_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5762 4564 </tr>
5763 4565 <tr>
5764 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
5765 - <td><?php $this->print_text_ldap_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4566 + <th scope="row"><?php _e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
4567 + <td><?php $this->print_text_ldap_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5766 4568 </tr>
5767 4569 <tr>
5768 - <th scope="row"><?php esc_html_e( 'LDAP attribute update', 'authorizer' ); ?></th>
5769 - <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4570 + <th scope="row"><?php _e( 'LDAP attribute update', 'authorizer' ); ?></th>
4571 + <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5770 4572 </tr>
5771 4573 </tbody></table>
5772 4574
5773 4575 <?php $this->print_section_info_advanced(); ?>
@@ -5772,36 +4574,20 @@
5772 4574
5773 4575 <?php $this->print_section_info_advanced(); ?>
5774 4576 <table class="form-table"><tbody>
5775 4577 <tr>
5776 - <th scope="row"><?php esc_html_e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
5777 - <td><?php $this->print_text_auth_advanced_lockouts( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4578 + <th scope="row"><?php _e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
4579 + <td><?php $this->print_text_auth_advanced_lockouts( array( MULTISITE_ADMIN => true ) ); ?></td>
5778 4580 </tr>
5779 4581 <tr>
5780 - <th scope="row"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
5781 - <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4582 + <th scope="row"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
4583 + <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5782 4584 </tr>
5783 - <tr>
5784 - <th scope="row"><?php esc_html_e( 'Number of users per page', 'authorizer' ); ?></th>
5785 - <td><?php $this->print_text_auth_advanced_users_per_page( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5786 - </tr>
5787 - <tr>
5788 - <th scope="row"><?php esc_html_e( 'Approved users sort method', 'authorizer' ); ?></th>
5789 - <td><?php $this->print_select_auth_advanced_users_sort_by( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5790 - </tr>
5791 - <tr>
5792 - <th scope="row"><?php esc_html_e( 'Approved users sort order', 'authorizer' ); ?></th>
5793 - <td><?php $this->print_select_auth_advanced_users_sort_order( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5794 - </tr>
5795 - <tr>
5796 - <th scope="row"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></th>
5797 - <td><?php $this->print_checkbox_auth_advanced_widget_enabled( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5798 - </tr>
5799 4585 </tbody></table>
5800 4586
5801 4587 <br class="clear" />
5802 4588 </div>
5803 - <input type="button" name="submit" id="submit" class="button button-primary" value="<?php esc_attr_e( 'Save Changes', 'authorizer' ); ?>" onclick="saveAuthMultisiteSettings(this);" />
4589 + <input type="button" name="submit" id="submit" class="button button-primary" value="<?php _e( 'Save Changes', 'authorizer' ); ?>" onclick="save_auth_multisite_settings(this);" />
5804 4590 </form>
5805 4591 </div>
5806 4592 <?php
5807 4593 }
@@ -5808,12 +4594,10 @@
5808 4594
5809 4595
5810 4596 /**
5811 4597 * Save multisite settings (ajax call).
5812 - *
5813 - * Action: wp_ajax_save_auth_multisite_settings
5814 4598 */
5815 - public function ajax_save_auth_multisite_settings() {
4599 + function ajax_save_auth_multisite_settings() {
5816 4600 // Fail silently if current user doesn't have permissions.
5817 4601 if ( ! current_user_can( 'manage_network_options' ) ) {
5818 4602 die( '' );
5819 4603 }
@@ -5818,14 +4602,14 @@
5818 4602 die( '' );
5819 4603 }
5820 4604
5821 4605 // Make sure nonce exists.
5822 - if ( empty( $_POST['nonce'] ) ) {
4606 + if ( empty( $_POST['nonce_save_auth_settings'] ) ) {
5823 4607 die( '' );
5824 4608 }
5825 4609
5826 4610 // Nonce check.
5827 - if ( ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4611 + if ( ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5828 4612 die( '' );
5829 4613 }
5830 4614
5831 4615 // Assert multisite.
@@ -5833,15 +4617,15 @@
5833 4617 die( '' );
5834 4618 }
5835 4619
5836 4620 // Get multisite settings.
5837 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
4621 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
5838 4622
5839 - // Sanitize settings.
4623 + // Sanitize settings
5840 4624 $auth_multisite_settings = $this->sanitize_options( $_POST );
5841 4625
5842 - // Filter options to only the allowed values (multisite options are a subset of all options).
5843 - $allowed = array(
4626 + // Filter options to only the allowed values (multisite options are a subset of all options)
4627 + $allowed = array(
5844 4628 'multisite_override',
5845 4629 'access_who_can_login',
5846 4630 'access_who_can_view',
5847 4631 'access_default_role',
@@ -5874,17 +4658,13 @@
5874 4658 'ldap_attr_last_name',
5875 4659 'ldap_attr_update_on_login',
5876 4660 'advanced_lockouts',
5877 4661 'advanced_hide_wp_login',
5878 - 'advanced_users_per_page',
5879 - 'advanced_users_sort_by',
5880 - 'advanced_users_sort_order',
5881 - 'advanced_widget_enabled',
5882 4662 );
5883 4663 $auth_multisite_settings = array_intersect_key( $auth_multisite_settings, array_flip( $allowed ) );
5884 4664
5885 4665 // Update multisite settings in database.
5886 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
4666 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
5887 4667
5888 4668 // Return 'success' value to AJAX call.
5889 4669 die( 'success' );
5890 4670 }
@@ -5898,67 +4678,42 @@
5898 4678 */
5899 4679
5900 4680
5901 4681
5902 - /**
5903 - * Load Authorizer dashboard widget if it's enabled.
5904 - *
5905 - * Action: wp_dashboard_setup
5906 - */
5907 - public function add_dashboard_widgets() {
5908 - $widget_enabled = $this->get_plugin_option( 'advanced_widget_enabled', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) === '1';
5909 -
5910 - // Load authorizer dashboard widget if it's enabled and user has permission.
5911 - if ( current_user_can( 'create_users' ) && $widget_enabled ) {
5912 - // Add dashboard widget for adding/editing users with access.
4682 + function add_dashboard_widgets() {
4683 + // Only users who can edit can see the authorizer dashboard widget
4684 + if ( current_user_can( 'create_users' ) ) {
4685 + // Add dashboard widget for adding/editing users with access
5913 4686 wp_add_dashboard_widget( 'auth_dashboard_widget', __( 'Authorizer Settings', 'authorizer' ), array( $this, 'add_auth_dashboard_widget' ) );
5914 4687 }
5915 4688 }
5916 4689
5917 4690
5918 - /**
5919 - * Render Authorizer dashboard widget (callback).
5920 - */
5921 - public function add_auth_dashboard_widget() {
5922 - ?>
5923 - <form method="post" id="auth_settings_access_form" action="">
4691 + function add_auth_dashboard_widget() {
4692 + ?><form method="post" id="auth_settings_access_form" action="">
5924 4693 <?php $this->print_section_info_access_login(); ?>
5925 4694 <div>
5926 - <h2><?php esc_html_e( 'Pending Users', 'authorizer' ); ?></h2>
4695 + <h2><?php _e( 'Pending Users', 'authorizer' ); ?></h2>
5927 4696 <?php $this->print_combo_auth_access_users_pending(); ?>
5928 4697 </div>
5929 4698 <div>
5930 - <h2><?php esc_html_e( 'Approved Users', 'authorizer' ); ?></h2>
4699 + <h2><?php _e( 'Approved Users', 'authorizer' ); ?></h2>
5931 4700 <?php $this->print_combo_auth_access_users_approved(); ?>
5932 4701 </div>
5933 4702 <div>
5934 - <h2><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?></h2>
4703 + <h2><?php _e( 'Blocked Users', 'authorizer' ); ?></h2>
5935 4704 <?php $this->print_combo_auth_access_users_blocked(); ?>
5936 4705 </div>
5937 4706 <br class="clear" />
5938 - </form>
5939 - <?php
4707 + </form><?php
5940 4708 }
5941 4709
5942 4710
5943 -
5944 - /**
5945 - * ***************************
5946 - * AJAX Actions
5947 - * ***************************
5948 - */
5949 -
5950 -
5951 -
5952 - /**
5953 - * Re-render the Approved User list (usually triggered if pager params have
5954 - * changed, e.g., current page, search term, sort order).
5955 - *
5956 - * Action: wp_ajax_refresh_approved_user_list
5957 - *
5958 - * @return void
5959 - */
5960 - public function ajax_refresh_approved_user_list() {
4711 + // Fired on a change event from the optional usermeta field in the
4712 + // approved user list. Updates the selected usermeta value, or saves it
4713 + // in the user's approved list entry if the user hasn't logged in yet
4714 + // and created a WordPress account.
4715 + function ajax_update_auth_usermeta() {
5961 4716 // Fail silently if current user doesn't have permissions.
5962 4717 if ( ! current_user_can( 'create_users' ) ) {
5963 4718 die( '' );
5964 4719 }
@@ -5963,175 +4718,35 @@
5963 4718 die( '' );
5964 4719 }
5965 4720
5966 4721 // Nonce check.
5967 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4722 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5968 4723 die( '' );
5969 4724 }
5970 4725
5971 4726 // Fail if required post data doesn't exist.
5972 - if ( ! array_key_exists( 'paged', $_REQUEST ) ) {
4727 + if ( ! array_key_exists( 'email', $_REQUEST ) || ! array_key_exists( 'usermeta', $_REQUEST ) ) {
5973 4728 die( '' );
5974 4729 }
5975 4730
5976 - // Get defaults.
5977 - $success = true;
5978 - $message = '';
5979 - $is_network_admin = isset( $_REQUEST['is_network_admin'] ) && '1' === $_REQUEST['is_network_admin'];
5980 -
5981 - // Get user list.
5982 - $option = 'access_users_approved';
5983 - $admin_mode = is_multisite() && $is_network_admin ? WP_Plugin_Authorizer::NETWORK_CONTEXT : WP_Plugin_Authorizer::SINGLE_CONTEXT;
5984 - $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
5985 - $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
5986 -
5987 - // Get multisite approved users (will be added to top of list, greyed out).
5988 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
5989 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
5990 - $auth_settings_option_multisite = array();
5991 - if (
5992 - is_multisite() &&
5993 - ! $is_network_admin &&
5994 - 1 !== intval( $auth_override_multisite ) &&
5995 - array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
5996 - '1' === $auth_multisite_settings['multisite_override']
5997 - ) {
5998 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
5999 - $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
6000 - // Add multisite users to the beginning of the main user array.
6001 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
6002 - $approved_user['multisite_user'] = true;
6003 - array_unshift( $auth_settings_option, $approved_user );
6004 - }
6005 - }
6006 -
6007 - // Get custom usermeta field to show.
6008 - $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
6009 -
6010 - // Filter user list to search terms.
6011 - if ( ! empty( $_REQUEST['search'] ) ) {
6012 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
6013 - $auth_settings_option = array_filter(
6014 - $auth_settings_option, function ( $user ) use ( $search_term ) {
6015 - return stripos( $user['email'], $search_term ) !== false ||
6016 - stripos( $user['role'], $search_term ) !== false ||
6017 - stripos( $user['date_added'], $search_term ) !== false;
6018 - }
6019 - );
6020 - }
6021 -
6022 - // Sort user list.
6023 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
6024 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
6025 - $sort_dimension = array();
6026 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
6027 - foreach ( $auth_settings_option as $key => $user ) {
6028 - if ( 'date_added' === $sort_by ) {
6029 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
6030 - } else {
6031 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
6032 - }
6033 - }
6034 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
6035 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
6036 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
6037 - // If default sort method and reverse order, just reverse the array.
6038 - $auth_settings_option = array_reverse( $auth_settings_option );
6039 - }
6040 -
6041 - // Ensure array keys run from 0..max (keys in database will be the original,
6042 - // index, and removing users will not reorder the array keys of other users).
6043 - $auth_settings_option = array_values( $auth_settings_option );
6044 -
6045 - // Get pager params.
6046 - $total_users = count( $auth_settings_option );
6047 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
6048 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
6049 - $total_pages = ceil( $total_users / $users_per_page );
6050 - if ( $total_pages < 1 ) {
6051 - $total_pages = 1;
6052 - }
6053 -
6054 - // Make sure current_page is between 1 and max pages.
6055 - if ( $current_page < 1 ) {
6056 - $current_page = 1;
6057 - } elseif ( $current_page > $total_pages ) {
6058 - $current_page = $total_pages;
6059 - }
6060 -
6061 - // Render user list.
6062 - ob_start();
6063 - $offset = ( $current_page - 1 ) * $users_per_page;
6064 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
6065 - for ( $key = $offset; $key < $max; $key++ ) :
6066 - $approved_user = $auth_settings_option[ $key ];
6067 - if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
6068 - continue;
6069 - endif;
6070 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
6071 - endfor;
6072 -
6073 - // Send response to client.
6074 - $response = array(
6075 - 'success' => $success,
6076 - 'message' => $message,
6077 - 'html' => ob_get_clean(),
6078 - /* TRANSLATORS: %s: number of users */
6079 - 'total_users_html' => sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ),
6080 - 'total_pages_html' => number_format_i18n( $total_pages ),
6081 - 'total_pages' => $total_pages,
6082 - );
6083 - header( 'content-type: application/json' );
6084 - echo wp_json_encode( $response );
6085 - exit;
6086 - }
6087 -
6088 -
6089 - /**
6090 - * Fired on a change event from the optional usermeta field in the approved
6091 - * user list. Updates the selected usermeta value, or saves it in the user's
6092 - * approved list entry if the user hasn't logged in yet and created a
6093 - * WordPress account.
6094 - *
6095 - * Action: wp_ajax_update_auth_usermeta
6096 - *
6097 - * @return void
6098 - */
6099 - public function ajax_update_auth_usermeta() {
6100 - // Fail silently if current user doesn't have permissions.
6101 - if ( ! current_user_can( 'create_users' ) ) {
6102 - die( '' );
6103 - }
6104 -
6105 - // Nonce check.
6106 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
6107 - die( '' );
6108 - }
6109 -
6110 - // Fail if required post data doesn't exist.
6111 - if ( ! isset( $_REQUEST['email'], $_REQUEST['usermeta'] ) ) {
6112 - die( '' );
6113 - }
6114 -
6115 4731 // Get values to update from post data.
6116 - $email = sanitize_email( wp_unslash( $_REQUEST['email'] ) );
6117 - $meta_value = sanitize_meta( 'authorizer-usermeta', wp_unslash( $_REQUEST['usermeta'] ), 'user' );
6118 - $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
4732 + $email = $_REQUEST['email'];
4733 + $meta_value = $_REQUEST['usermeta'];
4734 + $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
6119 4735
6120 4736 // If user doesn't exist, save usermeta selection to authorizer
6121 4737 // list. This value will get saved to usermeta when the user first
6122 4738 // logs in (i.e., when their WordPress account is created).
6123 - $wp_user = get_user_by( 'email', $email );
6124 - if ( ! $wp_user ) {
4739 + if ( ! ( $wp_user = get_user_by( 'email', $email ) ) ) {
6125 4740 // Look through multisite approved users and add a usermeta
6126 4741 // reference for the current blog if the user is found.
6127 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
4742 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
6128 4743 $should_update_auth_multisite_settings_access_users_approved = false;
6129 4744 foreach ( $auth_multisite_settings_access_users_approved as $index => $approved_user ) {
6130 4745 if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6131 - if ( ! is_array( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] ) ) {
4746 + if ( ! is_array( $auth_multisite_settings_access_users_approved[$index]['usermeta'] ) ) {
6132 4747 // Initialize the array of usermeta for each blog this user belongs to.
6133 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] = array();
4748 + $auth_multisite_settings_access_users_approved[$index]['usermeta'] = array();
6134 4749 } else {
6135 4750 // There is already usermeta associated with this
6136 4751 // preapproved user; iterate through it and make
6137 4752 // sure it's not for old meta_keys (delete it if
@@ -6137,53 +4752,55 @@
6137 4752 // sure it's not for old meta_keys (delete it if
6138 4753 // so). This can happen if someone changes the
6139 4754 // usermeta key in authorizer options, and we don't
6140 4755 // want to hang on to old data.
6141 - foreach ( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] as $blog_id => $usermeta ) {
4756 + foreach ( $auth_multisite_settings_access_users_approved[$index]['usermeta'] as $blog_id => $usermeta ) {
6142 4757 if ( array_key_exists( 'meta_key', $usermeta ) && $usermeta['meta_key'] === $meta_key ) {
6143 4758 continue;
6144 4759 } else {
6145 - unset( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ $blog_id ] );
4760 + unset( $auth_multisite_settings_access_users_approved[$index]['usermeta'][$blog_id] );
6146 4761 }
6147 4762 }
6148 4763 }
6149 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ get_current_blog_id() ] = array(
6150 - 'meta_key' => $meta_key,
4764 + $auth_multisite_settings_access_users_approved[$index]['usermeta'][get_current_blog_id()] = array(
4765 + 'meta_key' => $meta_key,
6151 4766 'meta_value' => $meta_value,
6152 4767 );
6153 - $should_update_auth_multisite_settings_access_users_approved = true;
4768 + $should_update_auth_multisite_settings_access_users_approved = true;
6154 4769 }
6155 4770 }
6156 4771 if ( $should_update_auth_multisite_settings_access_users_approved ) {
6157 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4772 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6158 4773 }
6159 4774
6160 4775 // Look through the approved users (of the current blog in a
6161 4776 // multisite install, or just of the single site) and add a
6162 4777 // usermeta reference if the user is found.
6163 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
4778 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
6164 4779 $should_update_auth_settings_access_users_approved = false;
6165 4780 foreach ( $auth_settings_access_users_approved as $index => $approved_user ) {
6166 4781 if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6167 - $auth_settings_access_users_approved[ $index ]['usermeta'] = array(
6168 - 'meta_key' => $meta_key,
4782 + $auth_settings_access_users_approved[$index]['usermeta'] = array(
4783 + 'meta_key' => $meta_key,
6169 4784 'meta_value' => $meta_value,
6170 4785 );
6171 - $should_update_auth_settings_access_users_approved = true;
4786 + $should_update_auth_settings_access_users_approved = true;
6172 4787 }
6173 4788 }
6174 4789 if ( $should_update_auth_settings_access_users_approved ) {
6175 4790 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6176 4791 }
4792 +
6177 4793 } else {
6178 4794 // Update user's usermeta value for usermeta key stored in authorizer options.
6179 4795 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
6180 4796 // We have an ACF field value, so use the ACF function to update it.
6181 - update_field( str_replace( 'acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
4797 + update_field( str_replace('acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
6182 4798 } else {
6183 4799 // We have a normal usermeta value, so just update it via the WordPress function.
6184 4800 update_user_meta( $wp_user->ID, $meta_key, $meta_value );
6185 4801 }
4802 +
6186 4803 }
6187 4804
6188 4805 // Return 'success' value to AJAX call.
6189 4806 die( 'success' );
@@ -6189,17 +4806,9 @@
6189 4806 die( 'success' );
6190 4807 }
6191 4808
6192 4809
6193 - /**
6194 - * Fired on a change event from the user fields in the user lists. Updates
6195 - * the selected user value.
6196 - *
6197 - * Action: wp_ajax_update_auth_user
6198 - *
6199 - * @return void
6200 - */
6201 - public function ajax_update_auth_user() {
4810 + function ajax_update_auth_user() {
6202 4811 // Fail silently if current user doesn't have permissions.
6203 4812 if ( ! current_user_can( 'create_users' ) ) {
6204 4813 die( '' );
6205 4814 }
@@ -6204,83 +4813,76 @@
6204 4813 die( '' );
6205 4814 }
6206 4815
6207 4816 // Nonce check.
6208 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4817 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
6209 4818 die( '' );
6210 4819 }
6211 4820
6212 4821 // Fail if requesting a change to an invalid setting.
6213 - if ( ! isset( $_POST['setting'] ) || ! in_array( wp_unslash( $_POST['setting'] ), array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
4822 + if ( ! in_array( $_POST['setting'], array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
6214 4823 die( '' );
6215 4824 }
6216 4825
6217 - // Track any emails that couldn't be added (used when adding users).
6218 - $invalid_emails = array();
6219 -
6220 4826 // Editing a pending list entry.
6221 - if ( 'access_users_pending' === $_POST['setting'] ) {
6222 - // Sanitize posted data.
6223 - $access_users_pending = array();
6224 - if ( isset( $_POST['access_users_pending'] ) && is_array( $_POST['access_users_pending'] ) ) {
6225 - $access_users_pending = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_pending'] ) );
4827 + if ( $_POST['setting'] === 'access_users_pending' ) {
4828 + // Initialize posted data if empty.
4829 + if ( ! ( array_key_exists( 'access_users_pending', $_POST ) && is_array( $_POST['access_users_pending'] ) ) ) {
4830 + $_POST['access_users_pending'] = array();
6226 4831 }
6227 4832
6228 4833 // Deal with each modified user (add or remove).
6229 - foreach ( $access_users_pending as $pending_user ) {
4834 + foreach ( $_POST['access_users_pending'] as $pending_user ) {
6230 4835
6231 - if ( 'add' === $pending_user['edit_action'] ) {
4836 + if ( $pending_user['edit_action'] === 'add' ) {
6232 4837
6233 4838 // Add new user to pending list and save (skip if it's
6234 4839 // already there--someone else might have just done it).
6235 4840 if ( ! $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
6236 4841 $auth_settings_access_users_pending = $this->sanitize_user_list(
6237 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4842 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
6238 4843 );
6239 4844 array_push( $auth_settings_access_users_pending, $pending_user );
6240 4845 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6241 4846 }
6242 - } elseif ( 'remove' === $pending_user['edit_action'] ) {
6243 4847
6244 - // Remove user from pending list and save.
4848 + } elseif ( $pending_user['edit_action'] === 'remove' ) {
4849 +
4850 + // Remove user from pending list and save
6245 4851 if ( $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
6246 4852 $auth_settings_access_users_pending = $this->sanitize_user_list(
6247 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4853 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
6248 4854 );
6249 4855 foreach ( $auth_settings_access_users_pending as $key => $existing_user ) {
6250 4856 if ( 0 === strcasecmp( $pending_user['email'], $existing_user['email'] ) ) {
6251 - unset( $auth_settings_access_users_pending[ $key ] );
4857 + unset( $auth_settings_access_users_pending[$key] );
6252 4858 break;
6253 4859 }
6254 4860 }
6255 4861 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6256 4862 }
4863 +
6257 4864 }
6258 4865 }
6259 4866 }
6260 4867
6261 4868 // Editing an approved list entry.
6262 - if ( 'access_users_approved' === $_POST['setting'] ) {
6263 - // Sanitize posted data.
6264 - $access_users_approved = array();
6265 - if ( isset( $_POST['access_users_approved'] ) && is_array( $_POST['access_users_approved'] ) ) {
6266 - $access_users_approved = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_approved'] ) );
4869 + if ( $_POST['setting'] === 'access_users_approved' ) {
4870 + // Initialize posted data if empty.
4871 + if ( ! ( array_key_exists( 'access_users_approved', $_POST ) && is_array( $_POST['access_users_approved'] ) ) ) {
4872 + $_POST['access_users_approved'] = array();
6267 4873 }
6268 4874
6269 4875 // Deal with each modified user (add, remove, or change_role).
6270 - foreach ( $access_users_approved as $approved_user ) {
6271 - // Skip blank entries.
6272 - if ( strlen( $approved_user['email'] ) < 1 ) {
6273 - continue;
6274 - }
4876 + foreach ( $_POST['access_users_approved'] as $approved_user ) {
6275 4877
6276 4878 // New user (create user, or add existing user to current site in multisite).
6277 - if ( 'add' === $approved_user['edit_action'] ) {
4879 + if ( $approved_user['edit_action'] === 'add' ) {
6278 4880 $new_user = get_user_by( 'email', $approved_user['email'] );
6279 - if ( false !== $new_user ) {
4881 + if ( $new_user !== false ) {
6280 4882 // If we're adding an existing multisite user, make sure their
6281 4883 // newly-assigned role is updated on all sites they are already in.
6282 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4884 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6283 4885 foreach ( get_blogs_of_user( $new_user->ID ) as $blog ) {
6284 4886 add_user_to_blog( $blog->userblog_id, $new_user->ID, $approved_user['role'] );
6285 4887 }
6286 4888 }
@@ -6287,9 +4889,9 @@
6287 4889 // If this user already has an account on another site in the network, add them to this site.
6288 4890 if ( is_multisite() ) {
6289 4891 add_user_to_blog( get_current_blog_id(), $new_user->ID, $approved_user['role'] );
6290 4892 }
6291 - } elseif ( $approved_user['local_user'] && 'false' !== $approved_user['local_user'] ) {
4893 + } elseif ( $approved_user['local_user'] === 'true' ) {
6292 4894 // Create a WP account for this new *local* user and email the password.
6293 4895 $plaintext_password = wp_generate_password(); // random password
6294 4896 // If there's already a user with this username (e.g.,
6295 4897 // johndoe/johndoe@gmail.com exists, and we're trying to add
@@ -6297,26 +4899,26 @@
6297 4899 // as the username.
6298 4900 $username = explode( '@', $approved_user['email'] );
6299 4901 $username = $username[0];
6300 4902 if ( get_user_by( 'login', $username ) !== false ) {
6301 - $username = $this->lowercase( $approved_user['email'] );
4903 + $username = mb_strtolower( $approved_user['email'] );
6302 4904 }
6303 - if ( 'false' !== $approved_user['multisite_user'] ) {
4905 + if ( $approved_user['multisite_user'] !== 'false' ) {
6304 4906 $result = wpmu_create_user(
6305 4907 strtolower( $username ),
6306 4908 $plaintext_password,
6307 - $this->lowercase( $approved_user['email'] )
4909 + mb_strtolower( $approved_user['email'] )
6308 4910 );
6309 4911 } else {
6310 4912 $result = wp_insert_user(
6311 4913 array(
6312 - 'user_login' => strtolower( $username ),
6313 - 'user_pass' => $plaintext_password,
6314 - 'first_name' => '',
6315 - 'last_name' => '',
6316 - 'user_email' => $this->lowercase( $approved_user['email'] ),
4914 + 'user_login' => strtolower( $username ),
4915 + 'user_pass' => $plaintext_password,
4916 + 'first_name' => '',
4917 + 'last_name' => '',
4918 + 'user_email' => mb_strtolower( $approved_user['email'] ),
6317 4919 'user_registered' => date( 'Y-m-d H:i:s' ),
6318 - 'role' => $approved_user['role'],
4920 + 'role' => $approved_user['role'],
6319 4921 )
6320 4922 );
6321 4923 }
6322 4924 if ( ! is_wp_error( $result ) ) {
@@ -6322,8 +4924,9 @@
6322 4924 if ( ! is_wp_error( $result ) ) {
6323 4925 // Email login credentials to new user.
6324 4926 wp_new_user_notification( $result, null, 'both' );
6325 4927 }
4928 +
6326 4929 }
6327 4930
6328 4931 // Email new user welcome message if plugin option is set.
6329 4932 $this->maybe_email_welcome_message( $approved_user['email'] );
@@ -6329,46 +4932,41 @@
6329 4932 $this->maybe_email_welcome_message( $approved_user['email'] );
6330 4933
6331 4934 // Add new user to approved list and save (skip if it's
6332 4935 // already there--someone else might have just done it).
6333 - if ( 'false' !== $approved_user['multisite_user'] ) {
4936 + if ( $approved_user['multisite_user'] !== 'false' ) {
6334 4937 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6335 4938 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6336 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4939 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6337 4940 );
6338 - $approved_user['date_added'] = date( 'M Y' );
4941 + $approved_user['date_added'] = date( 'M Y' );
6339 4942 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
6340 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6341 - } else {
6342 - $invalid_emails[] = $approved_user['email'];
4943 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6343 4944 }
6344 4945 } else {
6345 4946 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6346 4947 $auth_settings_access_users_approved = $this->sanitize_user_list(
6347 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4948 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6348 4949 );
6349 - $approved_user['date_added'] = date( 'M Y' );
4950 + $approved_user['date_added'] = date( 'M Y' );
6350 4951 array_push( $auth_settings_access_users_approved, $approved_user );
6351 4952 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6352 - } else {
6353 - $invalid_emails[] = $approved_user['email'];
6354 4953 }
6355 4954 }
6356 4955
6357 4956 // If we've added a new multisite user, go through all pending/approved/blocked lists
6358 4957 // on individual sites and remove this user from them (to prevent duplicate entries).
6359 - if ( 'false' !== $approved_user['multisite_user'] && is_multisite() ) {
4958 + if ( $approved_user['multisite_user'] !== 'false' && is_multisite() ) {
6360 4959 $list_names = array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' );
6361 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6362 4960 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6363 4961 foreach ( $sites as $site ) {
6364 4962 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6365 4963 foreach ( $list_names as $list_name ) {
6366 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
4964 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6367 4965 $list_changed = false;
6368 4966 foreach ( $user_list as $key => $user ) {
6369 4967 if ( 0 === strcasecmp( $user['email'], $approved_user['email'] ) ) {
6370 - unset( $user_list[ $key ] );
4968 + unset( $user_list[$key] );
6371 4969 $list_changed = true;
6372 4970 }
6373 4971 }
6374 4972 if ( $list_changed ) {
@@ -6376,19 +4974,21 @@
6376 4974 }
6377 4975 }
6378 4976 }
6379 4977 }
6380 - } elseif ( 'remove' === $approved_user['edit_action'] ) { // Remove user from approved list and save (also remove their role if they have a WordPress account).
6381 - if ( 'false' !== $approved_user['multisite_user'] ) {
4978 +
4979 + // Remove user from approved list and save (also remove their role if they have a WordPress account)
4980 + } elseif ( $approved_user['edit_action'] === 'remove' ) {
4981 + if ( $approved_user['multisite_user'] !== 'false' ) {
6382 4982 if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6383 4983 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6384 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4984 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6385 4985 );
6386 4986 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6387 4987 if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6388 4988 // Remove role of the associated WordPress user from all blogs (but don't delete the user).
6389 4989 $user = get_user_by( 'email', $approved_user['email'] );
6390 - if ( false !== $user ) {
4990 + if ( $user !== false ) {
6391 4991 // Loop through all of the blogs this user is a member of and remove their capabilities.
6392 4992 foreach ( get_blogs_of_user( $user->ID ) as $blog ) {
6393 4993 remove_user_from_blog( $user->ID, $blog->userblog_id, '' );
6394 4994 }
@@ -6393,28 +4993,28 @@
6393 4993 remove_user_from_blog( $user->ID, $blog->userblog_id, '' );
6394 4994 }
6395 4995 }
6396 4996 // Remove entry from Approved Users list.
6397 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
4997 + unset( $auth_multisite_settings_access_users_approved[$key] );
6398 4998 break;
6399 4999 }
6400 5000 }
6401 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5001 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6402 5002 }
6403 5003 } else {
6404 5004 if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6405 5005 $auth_settings_access_users_approved = $this->sanitize_user_list(
6406 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5006 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6407 5007 );
6408 5008 foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6409 5009 if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6410 5010 // Remove role of the associated WordPress user (but don't delete the user).
6411 5011 $user = get_user_by( 'email', $approved_user['email'] );
6412 - if ( false !== $user ) {
5012 + if ( $user !== false ) {
6413 5013 $user->set_role( '' );
6414 5014 }
6415 5015 // Remove entry from Approved Users list.
6416 - unset( $auth_settings_access_users_approved[ $key ] );
5016 + unset( $auth_settings_access_users_approved[$key] );
6417 5017 break;
6418 5018 }
6419 5019 }
6420 5020 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
@@ -6419,12 +5019,14 @@
6419 5019 }
6420 5020 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6421 5021 }
6422 5022 }
6423 - } elseif ( 'change_role' === $approved_user['edit_action'] ) { // Update user's role in WordPress.
5023 +
5024 + // Update user's role in WordPress
5025 + } elseif ( $approved_user['edit_action'] === 'change_role' ) {
6424 5026 $changed_user = get_user_by( 'email', $approved_user['email'] );
6425 5027 if ( $changed_user ) {
6426 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
5028 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6427 5029 foreach ( get_blogs_of_user( $changed_user->ID ) as $blog ) {
6428 5030 add_user_to_blog( $blog->userblog_id, $changed_user->ID, $approved_user['role'] );
6429 5031 }
6430 5032 } else {
@@ -6431,30 +5033,30 @@
6431 5033 $changed_user->set_role( $approved_user['role'] );
6432 5034 }
6433 5035 }
6434 5036
6435 - if ( 'false' !== $approved_user['multisite_user'] ) {
5037 + if ( $approved_user['multisite_user'] !== 'false' ) {
6436 5038 if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6437 5039 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6438 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5040 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6439 5041 );
6440 5042 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6441 5043 if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6442 - $auth_multisite_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
5044 + $auth_multisite_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6443 5045 break;
6444 5046 }
6445 5047 }
6446 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5048 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6447 5049 }
6448 5050 } else {
6449 5051 // Update user's role in approved list and save.
6450 5052 if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6451 5053 $auth_settings_access_users_approved = $this->sanitize_user_list(
6452 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5054 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6453 5055 );
6454 5056 foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6455 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6456 - $auth_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
5057 + if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
5058 + $auth_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6457 5059 break;
6458 5060 }
6459 5061 }
6460 5062 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
@@ -6459,28 +5061,28 @@
6459 5061 }
6460 5062 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6461 5063 }
6462 5064 }
5065 +
6463 5066 }
6464 5067 }
6465 5068 }
6466 5069
6467 5070 // Editing a blocked list entry.
6468 - if ( 'access_users_blocked' === $_POST['setting'] ) {
6469 - // Sanitize post data.
6470 - $access_users_blocked = array();
6471 - if ( isset( $_POST['access_users_blocked'] ) && is_array( $_POST['access_users_blocked'] ) ) {
6472 - $access_users_blocked = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_blocked'] ) );
5071 + if ( $_POST['setting'] === 'access_users_blocked' ) {
5072 + // Initialize posted data if empty.
5073 + if ( ! ( array_key_exists( 'access_users_blocked', $_POST ) && is_array( $_POST['access_users_blocked'] ) ) ) {
5074 + $_POST['access_users_blocked'] = array();
6473 5075 }
6474 5076
6475 5077 // Deal with each modified user (add or remove).
6476 - foreach ( $access_users_blocked as $blocked_user ) {
5078 + foreach ( $_POST['access_users_blocked'] as $blocked_user ) {
6477 5079
6478 - if ( 'add' === $blocked_user['edit_action'] ) {
5080 + if ( $blocked_user['edit_action'] === 'add' ) {
6479 5081
6480 5082 // Add auth_blocked usermeta for the user.
6481 5083 $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
6482 - if ( false !== $blocked_wp_user ) {
5084 + if ( $blocked_wp_user !== false ) {
6483 5085 update_user_meta( $blocked_wp_user->ID, 'auth_blocked', 'yes' );
6484 5086 }
6485 5087
6486 5088 // Add new user to blocked list and save (skip if it's
@@ -6486,113 +5088,48 @@
6486 5088 // Add new user to blocked list and save (skip if it's
6487 5089 // already there--someone else might have just done it).
6488 5090 if ( ! $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
6489 5091 $auth_settings_access_users_blocked = $this->sanitize_user_list(
6490 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5092 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
6491 5093 );
6492 - $blocked_user['date_added'] = date( 'M Y' );
5094 + $blocked_user['date_added'] = date( 'M Y' );
6493 5095 array_push( $auth_settings_access_users_blocked, $blocked_user );
6494 5096 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6495 - } else {
6496 - $invalid_emails[] = $blocked_user['email'];
6497 5097 }
6498 - } elseif ( 'remove' === $blocked_user['edit_action'] ) {
6499 5098
5099 + } elseif ( $blocked_user['edit_action'] === 'remove' ) {
5100 +
6500 5101 // Remove auth_blocked usermeta for the user.
6501 5102 $unblocked_user = get_user_by( 'email', $blocked_user['email'] );
6502 - if ( false !== $unblocked_user ) {
5103 + if ( $unblocked_user !== false ) {
6503 5104 delete_user_meta( $unblocked_user->ID, 'auth_blocked', 'yes' );
6504 5105 }
6505 5106
6506 - // Remove user from blocked list and save.
5107 + // Remove user from blocked list and save
6507 5108 if ( $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
6508 5109 $auth_settings_access_users_blocked = $this->sanitize_user_list(
6509 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
5110 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
6510 5111 );
6511 5112 foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) {
6512 5113 if ( 0 === strcasecmp( $blocked_user['email'], $existing_user['email'] ) ) {
6513 - unset( $auth_settings_access_users_blocked[ $key ] );
5114 + unset( $auth_settings_access_users_blocked[$key] );
6514 5115 break;
6515 5116 }
6516 5117 }
6517 5118 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6518 5119 }
5120 +
6519 5121 }
6520 5122 }
6521 5123 }
6522 5124
6523 - // Send response to client.
6524 - $response = array(
6525 - 'success' => true,
6526 - 'invalid_emails' => $invalid_emails,
6527 - );
6528 - header( 'content-type: application/json' );
6529 - echo wp_json_encode( $response );
6530 - exit;
5125 + // Return 'success' value to AJAX call.
5126 + die( 'success' );
6531 5127 }
6532 5128
6533 5129
6534 - /**
6535 - * Sanitizes an array of user update commands coming from the AJAX handler in Authorizer Settings.
6536 - *
6537 - * Example $users array:
6538 - * array(
6539 - * array(
6540 - * edit_action: 'add' or 'remove' or 'change_role',
6541 - * email: 'johndoe@example.com',
6542 - * role: 'subscriber',
6543 - * date_added: 'Jun 2014',
6544 - * local_user: 'true' or 'false',
6545 - * multisite_user: 'true' or 'false',
6546 - * ),
6547 - * ...
6548 - * )
6549 - *
6550 - * @param array $users Users to edit.
6551 - * @return array Sanitized users to edit.
6552 - */
6553 - private function sanitize_update_auth_users( $users = array() ) {
6554 - if ( ! is_array( $users ) ) {
6555 - $users = array();
6556 - }
6557 - $users = array_map( array( $this, 'sanitize_update_auth_user' ), $users );
6558 5130
6559 - return $users;
6560 - }
6561 -
6562 -
6563 5131 /**
6564 - * Callback for array_map in sanitize_update_auth_users().
6565 - *
6566 - * @param array $user User data to sanitize.
6567 - * @return array Sanitized user data.
6568 - */
6569 - private function sanitize_update_auth_user( $user ) {
6570 - if ( array_key_exists( 'edit_action', $user ) ) {
6571 - $user['edit_action'] = sanitize_text_field( $user['edit_action'] );
6572 - }
6573 - if ( isset( $user['email'] ) ) {
6574 - $user['email'] = sanitize_email( $user['email'] );
6575 - }
6576 - if ( isset( $user['role'] ) ) {
6577 - $user['role'] = sanitize_text_field( $user['role'] );
6578 - }
6579 - if ( isset( $user['date_added'] ) ) {
6580 - $user['date_added'] = sanitize_text_field( $user['date_added'] );
6581 - }
6582 - if ( isset( $user['local_user'] ) ) {
6583 - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false';
6584 - }
6585 - if ( isset( $user['multisite_user'] ) ) {
6586 - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false';
6587 - }
6588 -
6589 - return $user;
6590 - }
6591 -
6592 -
6593 -
6594 - /**
6595 5132 * ***************************
6596 5133 * Helper functions
6597 5134 * ***************************
6598 5135 */
@@ -6600,20 +5137,20 @@
6600 5137
6601 5138 /**
6602 5139 * Retrieves a specific plugin option from db. Multisite enabled.
6603 5140 *
6604 - * @param string $option Option name.
6605 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6606 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6607 - * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page.
6608 - * @return mixed Option value, or null on failure.
5141 + * @param string $option Option name
5142 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5143 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5144 + * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page
5145 + * @return mixed Option value, or null on failure
6609 5146 */
6610 - private function get_plugin_option( $option, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override', $print_mode = 'no overlay' ) {
5147 + private function get_plugin_option( $option, $admin_mode = SINGLE_ADMIN, $override_mode = 'no override', $print_mode = 'no overlay' ) {
6611 5148 // Special case for user lists (they are saved seperately to prevent concurrency issues).
6612 - if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
6613 - $list = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings_' . $option );
6614 - if ( is_multisite() && WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
6615 - $list = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_' . $option, array() );
5149 + if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
5150 + $list = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings_' . $option );
5151 + if ( is_multisite() && $admin_mode === MULTISITE_ADMIN ) {
5152 + $list = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_' . $option, array() );
6616 5153 }
6617 5154 return $list;
6618 5155 }
6619 5156
@@ -6627,26 +5164,24 @@
6627 5164
6628 5165 // If requested and appropriate, print the overlay hiding the
6629 5166 // single site option that is overridden by a multisite option.
6630 5167 if (
6631 - WP_Plugin_Authorizer::NETWORK_CONTEXT !== $admin_mode &&
6632 - 'allow override' === $override_mode &&
6633 - 'print overlay' === $print_mode &&
5168 + $admin_mode !== MULTISITE_ADMIN &&
5169 + $override_mode === 'allow override' &&
5170 + $print_mode === 'print overlay' &&
6634 5171 array_key_exists( 'multisite_override', $auth_settings ) &&
6635 - '1' === $auth_settings['multisite_override'] &&
6636 - ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) )
5172 + $auth_settings['multisite_override'] === '1' &&
5173 + ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' )
6637 5174 ) {
6638 5175 // Get original plugin options (not overridden value). We'll
6639 5176 // show this old value behind the disabled overlay.
6640 - // $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6641 - // (This feature is disabled).
6642 - //
5177 + $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
5178 +
6643 5179 $name = "auth_settings[$option]";
6644 - $id = "auth_settings_$option";
6645 - ?>
6646 - <div id="overlay-hide-auth_settings_<?php echo esc_attr( $option ); ?>" class="auth_multisite_override_overlay">
5180 + $id = "auth_settings_$option"; ?>
5181 + <div id="overlay-hide-auth_settings_<?php echo $option; ?>" class="auth_multisite_override_overlay">
6647 5182 <span class="overlay-note">
6648 - <?php esc_html_e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo esc_attr( network_admin_url( 'admin.php?page=authorizer' ) ); ?>"><?php esc_html_e( 'multisite option', 'authorizer' ); ?></a>.
5183 + <?php _e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo network_admin_url( 'admin.php?page=authorizer&tab=external' ); ?>"><?php _e( 'multisite option', 'authorizer' ); ?></a>.
6649 5184 </span>
6650 5185 </div>
6651 5186 <?php
6652 5187 }
@@ -6652,9 +5187,9 @@
6652 5187 }
6653 5188
6654 5189 // If we're getting an option in a site that has overridden the multisite override, make
6655 5190 // sure we are returning the option value from that site (not the multisite value).
6656 - if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && 1 === intval( $auth_settings['advanced_override_multisite'] ) ) {
5191 + if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && $auth_settings['advanced_override_multisite'] == '1' ) {
6657 5192 $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6658 5193 }
6659 5194
6660 5195 // Set option to null if it wasn't found.
@@ -6661,115 +5196,98 @@
6661 5196 if ( ! array_key_exists( $option, $auth_settings ) ) {
6662 5197 return null;
6663 5198 }
6664 5199
6665 - return $auth_settings[ $option ];
5200 + return $auth_settings[$option];
6666 5201 }
6667 5202
6668 5203 /**
6669 5204 * Retrieves all plugin options from db. Multisite enabled.
6670 5205 *
6671 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6672 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6673 - * @return mixed Option value, or null on failure.
5206 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5207 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5208 + * @return mixed Option value, or null on failure
6674 5209 */
6675 - private function get_plugin_options( $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override' ) {
6676 - // Grab plugin settings (skip if in WP_Plugin_Authorizer::NETWORK_CONTEXT mode).
6677 - $auth_settings = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings' );
5210 + private function get_plugin_options( $admin_mode = SINGLE_ADMIN, $override_mode = 'no override' ) {
5211 + // Grab plugin settings (skip if in MULTISITE_ADMIN mode).
5212 + $auth_settings = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings' );
6678 5213
6679 5214 // Initialize to default values if the plugin option doesn't exist.
6680 - if ( false === $auth_settings ) {
5215 + if ( $auth_settings === FALSE ) {
6681 5216 $auth_settings = $this->set_default_options();
6682 5217 }
6683 5218
6684 5219 // Merge multisite options if we're in a network and the current site hasn't overridden multisite settings.
6685 - if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) ) ) {
5220 + if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' ) ) {
6686 5221 // Get multisite options.
6687 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5222 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
6688 5223
6689 5224 // Return the multisite options if we're viewing the network admin options page.
6690 5225 // Otherwise override options with their multisite equivalents.
6691 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
5226 + if ( $admin_mode === MULTISITE_ADMIN ) {
6692 5227 $auth_settings = $auth_multisite_settings;
6693 5228 } elseif (
6694 - 'allow override' === $override_mode &&
5229 + $override_mode === 'allow override' &&
6695 5230 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
6696 - '1' === $auth_multisite_settings['multisite_override']
5231 + $auth_multisite_settings['multisite_override'] === '1'
6697 5232 ) {
6698 5233 // Keep track of the multisite override selection.
6699 5234 $auth_settings['multisite_override'] = $auth_multisite_settings['multisite_override'];
6700 5235
6701 - /**
6702 - * Note: the options below should be the complete list of overridden
6703 - * options. It is *not* the complete list of all options (some options
6704 - * don't have a multisite equivalent).
6705 - */
5236 + // Note: the options below should be the complete list of
5237 + // overridden options. It is *not* the complete list of all
5238 + // options (some options don't have a multisite equivalent)
6706 5239
6707 - /**
6708 - * Note: access_users_approved, access_users_pending, and
6709 - * access_users_blocked do not get overridden. However, since
6710 - * access_users_approved has a multisite equivalent, you must retrieve
6711 - * them both seperately. This is done because the two lists should be
6712 - * treated differently.
6713 - *
6714 - * $approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6715 - * $ms_approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
6716 - */
5240 + // Note: access_users_approved, access_users_pending, and
5241 + // access_users_blocked do not get overridden. However,
5242 + // since access_users_approved has a multisite equivalent,
5243 + // you must retrieve them both seperately. This is done
5244 + // because the two lists should be treated differently.
5245 + // $approved_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5246 + // $ms_approved_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
6717 5247
6718 - // Override external services (google, cas, or ldap) and associated options.
6719 - $auth_settings['google'] = $auth_multisite_settings['google'];
6720 - $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
6721 - $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
6722 - $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
6723 - $auth_settings['cas'] = $auth_multisite_settings['cas'];
6724 - $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
6725 - $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
6726 - $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
6727 - $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
6728 - $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
6729 - $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
6730 - $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
6731 - $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
6732 - $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
6733 - $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
6734 - $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
6735 - $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
6736 - $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
6737 - $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
6738 - $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
6739 - $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
6740 - $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
6741 - $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
6742 - $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
6743 - $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
6744 - $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
6745 - $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
5248 + // Override external services (google, cas, or ldap) and associated options
5249 + $auth_settings['google'] = $auth_multisite_settings['google'];
5250 + $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
5251 + $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
5252 + $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
5253 + $auth_settings['cas'] = $auth_multisite_settings['cas'];
5254 + $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
5255 + $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
5256 + $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
5257 + $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
5258 + $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
5259 + $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
5260 + $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
5261 + $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
5262 + $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
5263 + $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
5264 + $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
5265 + $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
5266 + $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
5267 + $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
5268 + $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
5269 + $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
5270 + $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
5271 + $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
5272 + $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
5273 + $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
5274 + $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
5275 + $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
6746 5276 $auth_settings['ldap_attr_update_on_login'] = $auth_multisite_settings['ldap_attr_update_on_login'];
6747 5277
6748 - // Override access_who_can_login and access_who_can_view.
5278 + // Override access_who_can_login and access_who_can_view
6749 5279 $auth_settings['access_who_can_login'] = $auth_multisite_settings['access_who_can_login'];
6750 - $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
5280 + $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
6751 5281
6752 - // Override access_default_role.
5282 + // Override access_default_role
6753 5283 $auth_settings['access_default_role'] = $auth_multisite_settings['access_default_role'];
6754 5284
6755 - // Override lockouts.
5285 + // Override lockouts
6756 5286 $auth_settings['advanced_lockouts'] = $auth_multisite_settings['advanced_lockouts'];
6757 5287
6758 - // Override Hide WordPress login.
5288 + // Override Hide WordPress login
6759 5289 $auth_settings['advanced_hide_wp_login'] = $auth_multisite_settings['advanced_hide_wp_login'];
6760 -
6761 - // Override Users per page.
6762 - $auth_settings['advanced_users_per_page'] = $auth_multisite_settings['advanced_users_per_page'];
6763 -
6764 - // Override Sort users by.
6765 - $auth_settings['advanced_users_sort_by'] = $auth_multisite_settings['advanced_users_sort_by'];
6766 -
6767 - // Override Sort users order.
6768 - $auth_settings['advanced_users_sort_order'] = $auth_multisite_settings['advanced_users_sort_order'];
6769 -
6770 - // Override Show Dashboard Widget.
6771 - $auth_settings['advanced_widget_enabled'] = $auth_multisite_settings['advanced_widget_enabled'];
6772 5290 }
6773 5291 }
6774 5292 return $auth_settings;
6775 5293 }
@@ -6776,27 +5294,23 @@
6776 5294
6777 5295
6778 5296 /**
6779 5297 * Remove user from authorizer lists when that user is deleted in WordPress.
6780 - *
6781 - * Action: delete_user
6782 - *
6783 - * @param int $user_id User ID to remove.
6784 - * @return void
5298 + * Run on action hook: delete_user
6785 5299 */
6786 - public function remove_user_from_authorizer_when_deleted( $user_id ) {
6787 - $user = get_user_by( 'id', $user_id );
5300 + function remove_user_from_authorizer_when_deleted( $user_id ) {
5301 + $user = get_user_by( 'id', $user_id );
6788 5302 $deleted_email = $user->user_email;
6789 5303
6790 5304 // Remove user from pending/approved lists and save.
6791 5305 $list_names = array( 'access_users_pending', 'access_users_approved' );
6792 5306 foreach ( $list_names as $list_name ) {
6793 - $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
5307 + $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, SINGLE_ADMIN ) );
6794 5308 $list_changed = false;
6795 5309 foreach ( $user_list as $key => $existing_user ) {
6796 5310 if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
6797 5311 $list_changed = true;
6798 - unset( $user_list[ $key ] );
5312 + unset( $user_list[$key] );
6799 5313 }
6800 5314 }
6801 5315 if ( $list_changed ) {
6802 5316 update_option( 'auth_settings_' . $list_name, $user_list );
@@ -6806,35 +5320,30 @@
6806 5320
6807 5321
6808 5322 /**
6809 5323 * Remove multisite user from authorizer lists when that user is deleted from Network Users.
6810 - *
6811 - * Action: wpmu_delete_user
6812 - *
6813 - * @param int $user_id User ID to remove.
6814 - * @return void
5324 + * Run on action hook: wpmu_delete_user
6815 5325 */
6816 - public function remove_network_user_from_authorizer_when_deleted( $user_id ) {
6817 - $user = get_user_by( 'id', $user_id );
5326 + function remove_network_user_from_authorizer_when_deleted( $user_id ) {
5327 + $user = get_user_by( 'id', $user_id );
6818 5328 $deleted_email = $user->user_email;
6819 5329
6820 5330 // Go through multisite approved user list and remove this user.
6821 5331 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6822 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5332 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6823 5333 );
6824 - $list_changed = false;
5334 + $list_changed = false;
6825 5335 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6826 5336 if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
6827 5337 $list_changed = true;
6828 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5338 + unset( $auth_multisite_settings_access_users_approved[$key] );
6829 5339 }
6830 5340 }
6831 5341 if ( $list_changed ) {
6832 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5342 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6833 5343 }
6834 5344
6835 5345 // Go through all pending/approved lists on individual sites and remove this user from them.
6836 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6837 5346 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6838 5347 foreach ( $sites as $site ) {
6839 5348 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6840 5349 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -6844,27 +5353,22 @@
6844 5353
6845 5354
6846 5355 /**
6847 5356 * Remove multisite user from a specific site's lists when that user is removed from the site.
6848 - *
6849 - * Action: remove_user_from_blog
6850 - *
6851 - * @param int $user_id User ID to remove.
6852 - * @param int $blog_id Blog ID to remove from.
6853 - * @return void
5357 + * Run on action hook: remove_user_from_blog
6854 5358 */
6855 - public function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
6856 - $user = get_user_by( 'id', $user_id );
5359 + function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
5360 + $user = get_user_by( 'id', $user_id );
6857 5361 $deleted_email = $user->user_email;
6858 5362
6859 5363 $list_names = array( 'access_users_pending', 'access_users_approved' );
6860 5364 foreach ( $list_names as $list_name ) {
6861 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
5365 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6862 5366 $list_changed = false;
6863 5367 foreach ( $user_list as $key => $existing_user ) {
6864 5368 if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
6865 5369 $list_changed = true;
6866 - unset( $user_list[ $key ] );
5370 + unset( $user_list[$key] );
6867 5371 }
6868 5372 }
6869 5373 if ( $list_changed ) {
6870 5374 update_blog_option( $blog_id, 'auth_settings_' . $list_name, $user_list );
@@ -6874,30 +5378,26 @@
6874 5378
6875 5379
6876 5380 /**
6877 5381 * Helper: Add multisite user to a specific site's approved list.
6878 - *
6879 - * @param int $user_id User ID to add.
6880 - * @param int $blog_id Blog ID to add to.
6881 - * @return void
6882 5382 */
6883 - private function add_network_user_to_site( $user_id, $blog_id ) {
5383 + function add_network_user_to_site( $user_id, $blog_id ) {
6884 5384 // Switch to blog.
6885 5385 switch_to_blog( $blog_id );
6886 5386
6887 5387 // Get user details and role.
6888 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
6889 - $user = get_user_by( 'id', $user_id );
6890 - $user_email = $user->user_email;
6891 - $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
5388 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
5389 + $user = get_user_by( 'id', $user_id );
5390 + $user_email = $user->user_email;
5391 + $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
6892 5392
6893 5393 // Add user to approved list if not already there and not in blocked list.
6894 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6895 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5394 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5395 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
6896 5396 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) && ! $this->in_multi_array( $user_email, $auth_settings_access_users_blocked ) ) {
6897 5397 $approved_user = array(
6898 - 'email' => $this->lowercase( $user_email ),
6899 - 'role' => $user_role,
5398 + 'email' => mb_strtolower( $user_email ),
5399 + 'role' => $user_role,
6900 5400 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
6901 5401 'local_user' => true,
6902 5402 );
6903 5403 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -6914,17 +5414,17 @@
6914 5414 * When an existing user is invited to the current site (or a new user is created),
6915 5415 * add them to the authorizer approved list. This action fires when the admin
6916 5416 * doesn't select the "Skip Confirmation Email" option.
6917 5417 *
6918 - * Action: invite_user
5418 + * @action invite_user
6919 5419 *
6920 - * @param int $user_id The invited user's ID.
6921 - * @param array $role The role of the invited user (or none if a new user creation).
5420 + * @param int $user_id The invited user's ID.
5421 + * @param array $role The role of the invited user (or none if a new user creation).
6922 5422 * @param string $newuser_key The key of the invitation.
6923 5423 */
6924 - public function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
5424 + function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
6925 5425 $user = get_user_by( 'id', $user_id );
6926 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles, $role );
5426 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles, $role );
6927 5427 }
6928 5428
6929 5429
6930 5430 /**
@@ -6932,16 +5432,16 @@
6932 5432 * When an existing user is invited to the current site (or a new user is created),
6933 5433 * add them to the authorizer approved list. This action fires when the admin
6934 5434 * selects the "Skip Confirmation Email" option.
6935 5435 *
6936 - * Action: added_existing_user
5436 + * @action added_existing_user
6937 5437 *
6938 - * @param int $user_id The invited user's ID.
6939 - * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
5438 + * @param int $user_id The invited user's ID.
5439 + * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
6940 5440 */
6941 - public function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
5441 + function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
6942 5442 $user = get_user_by( 'id', $user_id );
6943 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5443 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
6944 5444 }
6945 5445
6946 5446
6947 5447 /**
@@ -6948,18 +5448,17 @@
6948 5448 * Multisite:
6949 5449 * When a new user is invited to the current site (or a new user is created),
6950 5450 * add them to the authorizer approved list.
6951 5451 *
6952 - * Action: after_signup_user
5452 + * @action after_signup_user
6953 5453 *
6954 - * @param string $user User's requested login name.
5454 + * @param string $user User's requested login name.
6955 5455 * @param string $user_email User's email address.
6956 - * @param string $key User's activation key.
6957 - * @param array $meta Additional signup meta, including initially set roles.
5456 + * @param string $key User's activation key.
5457 + * @param array $meta Additional signup meta.
6958 5458 */
6959 - public function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
6960 - $user_roles = isset( $meta['new_role'] ) ? array( $meta['new_role'] ) : array();
6961 - $this->add_user_to_authorizer_when_created( $user_email, time(), $user_roles );
5459 + function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
5460 + $this->add_user_to_authorizer_when_created( $user_email, time() );
6962 5461 }
6963 5462
6964 5463
6965 5464 /**
@@ -6966,18 +5465,17 @@
6966 5465 * Single site:
6967 5466 * When a new user is added in single site mode, add them to the authorizer
6968 5467 * approved list.
6969 5468 *
6970 - * Action: edit_user_created_user
5469 + * @action edit_user_created_user
6971 5470 *
6972 - * @param int $user_id ID of the newly created user.
6973 - * @param string $notify Type of notification that should happen. See
6974 - * wp_send_new_user_notifications() for more
6975 - * information on possible values.
5471 + * @param int $user_id ID of the newly created user.
5472 + * @param string $notify Type of notification that should happen. See wp_send_new_user_notifications()
5473 + * for more information on possible values.
6976 5474 */
6977 - public function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
5475 + function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
6978 5476 $user = get_user_by( 'id', $user_id );
6979 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5477 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
6980 5478 }
6981 5479
6982 5480
6983 5481 /**
@@ -6982,19 +5480,14 @@
6982 5480
6983 5481 /**
6984 5482 * Helper: When a new user is added/invited to the current site (or a new
6985 5483 * user is created), add them to the authorizer approved list.
6986 - *
6987 - * @param string $user_email Email address of user to add.
6988 - * @param string $date_registered Date user registered.
6989 - * @param array $user_roles Role to add for user.
6990 - * @param array $default_role Default role, if no role specified.
6991 5484 */
6992 5485 private function add_user_to_authorizer_when_created( $user_email, $date_registered, $user_roles = array(), $default_role = array() ) {
6993 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
6994 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6995 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6996 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5486 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
5487 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5488 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5489 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
6997 5490
6998 5491 // Get default role if one isn't specified.
6999 5492 if ( count( $default_role ) < 1 ) {
7000 5493 $default_role = '';
@@ -7010,9 +5503,9 @@
7010 5503 }
7011 5504 // Remove from pending list if there.
7012 5505 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
7013 5506 if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
7014 - unset( $auth_settings_access_users_pending[ $key ] );
5507 + unset( $auth_settings_access_users_pending[$key] );
7015 5508 $updated = true;
7016 5509 }
7017 5510 }
7018 5511 // Skip if user is in multisite approved list.
@@ -7021,10 +5514,10 @@
7021 5514 }
7022 5515 // Add to approved list if not there.
7023 5516 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) ) {
7024 5517 $approved_user = array(
7025 - 'email' => $this->lowercase( $user_email ),
7026 - 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
5518 + 'email' => mb_strtolower( $user_email ),
5519 + 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
7027 5520 'date_added' => date( 'M Y', strtotime( $date_registered ) ),
7028 5521 'local_user' => true,
7029 5522 );
7030 5523 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -7043,33 +5536,32 @@
7043 5536 * When a user is granted super admin status (checkbox on network user edit
7044 5537 * screen), add them to the authorizer network approved list. Also remove
7045 5538 * them from pending/approved list on any individual sites.
7046 5539 *
7047 - * Action: grant_super_admin
5540 + * @action grant_super_admin
7048 5541 *
7049 5542 * @param int $user_id The user's ID.
7050 5543 */
7051 - public function grant_super_admin__add_to_network_approved( $user_id ) {
7052 - $user = get_user_by( 'id', $user_id );
5544 + function grant_super_admin__add_to_network_approved( $user_id ) {
5545 + $user = get_user_by( 'id', $user_id );
7053 5546 $user_email = $user->user_email;
7054 5547
7055 5548 // Add user to multisite approved user list (if not already there).
7056 5549 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7057 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5550 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7058 5551 );
7059 5552 if ( ! $this->in_multi_array( $user_email, $auth_multisite_settings_access_users_approved ) ) {
7060 5553 $multisite_approved_user = array(
7061 - 'email' => $this->lowercase( $user_email ),
7062 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
5554 + 'email' => mb_strtolower( $user_email ),
5555 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
7063 5556 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
7064 5557 'local_user' => true,
7065 5558 );
7066 5559 array_push( $auth_multisite_settings_access_users_approved, $multisite_approved_user );
7067 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5560 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7068 5561 }
7069 5562
7070 5563 // Go through all pending/approved lists on individual sites and remove this user from them.
7071 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7072 5564 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7073 5565 foreach ( $sites as $site ) {
7074 5566 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7075 5567 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -7082,29 +5574,29 @@
7082 5574 * When a user's super admin status is revoked (checkbox on network user edit
7083 5575 * screen), remove them from the authorizer network approved list. Also add
7084 5576 * them to approved list on any individual sites they are already a part of.
7085 5577 *
7086 - * Action: revoke_super_admin
5578 + * @action revoke_super_admin
7087 5579 *
7088 5580 * @param int $user_id The user's ID.
7089 5581 */
7090 - public function revoke_super_admin__remove_from_network_approved( $user_id ) {
7091 - $user = get_user_by( 'id', $user_id );
5582 + function revoke_super_admin__remove_from_network_approved( $user_id ) {
5583 + $user = get_user_by( 'id', $user_id );
7092 5584 $revoked_email = $user->user_email;
7093 5585
7094 5586 // Go through multisite approved user list and remove this user.
7095 5587 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7096 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5588 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7097 5589 );
7098 - $list_changed = false;
5590 + $list_changed = false;
7099 5591 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
7100 5592 if ( 0 === strcasecmp( $revoked_email, $existing_user['email'] ) ) {
7101 5593 $list_changed = true;
7102 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5594 + unset( $auth_multisite_settings_access_users_approved[$key] );
7103 5595 }
7104 5596 }
7105 5597 if ( $list_changed ) {
7106 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5598 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7107 5599 }
7108 5600
7109 5601 // Go through this user's current sites and add them to the approved list
7110 5602 // (since they are no longer on the network approved list).
@@ -7115,21 +5607,14 @@
7115 5607 }
7116 5608
7117 5609 }
7118 5610
7119 - /**
7120 - * Send a welcome email message to a newly approved user (if the "Should
7121 - * email approved users" setting is enabled).
7122 - *
7123 - * @param string $email Email address to send welcome email to.
7124 - * @return bool Whether the email was sent.
7125 - */
7126 5611 private function maybe_email_welcome_message( $email ) {
7127 5612 // Get option for whether to email welcome messages.
7128 5613 $should_email_new_approved_users = $this->get_plugin_option( 'access_should_email_approved_users' );
7129 5614
7130 5615 // Do not send welcome email if option not enabled.
7131 - if ( '1' !== $should_email_new_approved_users ) {
5616 + if ( $should_email_new_approved_users !== '1' ) {
7132 5617 return false;
7133 5618 }
7134 5619
7135 5620 // Make sure we didn't just email this user (can happen with
@@ -7135,15 +5620,15 @@
7135 5620 // Make sure we didn't just email this user (can happen with
7136 5621 // multiple admins saving at the same time, or by clicking
7137 5622 // Approve button too rapidly).
7138 5623 $recently_sent_emails = get_option( 'auth_settings_recently_sent_emails' );
7139 - if ( false === $recently_sent_emails ) {
5624 + if ( $recently_sent_emails === FALSE ) {
7140 5625 $recently_sent_emails = array();
7141 5626 }
7142 5627 foreach ( $recently_sent_emails as $key => $recently_sent_email ) {
7143 5628 if ( $recently_sent_email['time'] < strtotime( 'now -1 minutes' ) ) {
7144 5629 // Remove emails sent more than 1 minute ago.
7145 - unset( $recently_sent_emails[ $key ] );
5630 + unset( $recently_sent_emails[$key] );
7146 5631 } elseif ( $recently_sent_email['email'] === $email ) {
7147 5632 // Sent an email to this user within the last 1 minute, so
7148 5633 // quit without sending.
7149 5634 return false;
@@ -7151,15 +5636,15 @@
7151 5636 }
7152 5637 // Add the email we're about to send to the list.
7153 5638 $recently_sent_emails[] = array(
7154 5639 'email' => $email,
7155 - 'time' => time(),
5640 + 'time' => time(),
7156 5641 );
7157 5642 update_option( 'auth_settings_recently_sent_emails', $recently_sent_emails );
7158 5643
7159 - // Get welcome email subject and body text.
5644 + // Get welcome email subject and body text
7160 5645 $subject = $this->get_plugin_option( 'access_email_approved_users_subject' );
7161 - $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
5646 + $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
7162 5647
7163 5648 // Fail if the subject/body options don't exist or are empty.
7164 5649 if ( is_null( $subject ) || is_null( $body ) || strlen( $subject ) === 0 || strlen( $body ) === 0 ) {
7165 5650 return false;
@@ -7166,14 +5651,14 @@
7166 5651 }
7167 5652
7168 5653 // Replace approved shortcode patterns in subject and body.
7169 5654 $site_name = get_bloginfo( 'name' );
7170 - $site_url = get_site_url();
7171 - $subject = str_replace( '[site_name]', $site_name, $subject );
7172 - $body = str_replace( '[site_name]', $site_name, $body );
7173 - $body = str_replace( '[site_url]', $site_url, $body );
7174 - $body = str_replace( '[user_email]', $email, $body );
7175 - $headers = 'Content-type: text/html' . "\r\n";
5655 + $site_url = get_site_url();
5656 + $subject = str_replace( '[site_name]', $site_name, $subject );
5657 + $body = str_replace( '[site_name]', $site_name, $body );
5658 + $body = str_replace( '[site_url]', $site_url, $body );
5659 + $body = str_replace( '[user_email]', $email, $body );
5660 + $headers = 'Content-type: text/html' . "\r\n";
7176 5661
7177 5662 // Send email.
7178 5663 wp_mail( $email, $subject, $body, $headers );
7179 5664
@@ -7183,22 +5668,14 @@
7183 5668
7184 5669
7185 5670 /**
7186 5671 * Generate a unique cookie to add to nonces to prevent CSRF.
7187 - *
7188 - * @var string
7189 5672 */
7190 - private $cookie_value = null;
7191 -
7192 - /**
7193 - * Retrieve the unique login cookie.
7194 - *
7195 - * @return string Login cookie value.
7196 - */
7197 - private function get_cookie_value() {
5673 + protected $cookie_value = null;
5674 + function get_cookie_value() {
7198 5675 if ( ! $this->cookie_value ) {
7199 5676 if ( isset( $_COOKIE['login_unique'] ) ) {
7200 - $this->cookie_value = sanitize_key( wp_unslash( $_COOKIE['login_unique'] ) );
5677 + $this->cookie_value = $_COOKIE['login_unique'];
7201 5678 } else {
7202 5679 $this->cookie_value = md5( rand() );
7203 5680 }
7204 5681 }
@@ -7206,51 +5683,37 @@
7206 5683 }
7207 5684
7208 5685
7209 5686 /**
7210 - * Encryption key (not secret!).
7211 - *
7212 - * @var string
7213 - */
7214 - private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
7215 -
7216 - /**
7217 - * Encryption salt (not secret!).
7218 - *
7219 - * @var string
7220 - */
7221 - private static $iv = 'R_O2D]jPn]1[fhJl!-P1.oe';
7222 -
7223 - /**
7224 5687 * Basic encryption using a public (not secret!) key. Used for general
7225 5688 * database obfuscation of passwords.
7226 - *
7227 - * @param string $text String to encrypt.
7228 - * @param string $library Encryption library to use (openssl).
7229 - * @return string Encrypted string.
5689 + * @param $text String to encrypt.
5690 + * @param $library Encryption lib to use (openssl).
5691 + * @return Encrypted string
7230 5692 */
7231 - private function encrypt( $text, $library = 'openssl' ) {
5693 + private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
5694 + private static $iv = "R_O2D]jPn]1[fhJl!-P1.oe";
5695 + function encrypt( $text, $library = 'openssl' ) {
7232 5696 $result = '';
7233 5697
7234 5698 // Use openssl library (better) if it is enabled.
7235 - if ( function_exists( 'openssl_encrypt' ) && 'openssl' === $library ) {
7236 - $result = base64_encode(
7237 - openssl_encrypt(
7238 - $text,
7239 - 'AES-256-CBC',
7240 - hash( 'sha256', self::$key ),
7241 - 0,
7242 - substr( hash( 'sha256', self::$iv ), 0, 16 )
7243 - )
7244 - );
7245 - } elseif ( function_exists( 'mcrypt_encrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5699 + if ( function_exists( 'openssl_encrypt' ) && $library === 'openssl' ) {
5700 + $result = base64_encode( openssl_encrypt(
5701 + $text,
5702 + 'AES-256-CBC',
5703 + hash( 'sha256', self::$key ),
5704 + 0,
5705 + substr( hash( 'sha256', self::$iv ), 0, 16 )
5706 + ) );
5707 + // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5708 + } else if ( function_exists( 'mcrypt_encrypt' ) ) {
7246 5709 $result = base64_encode( mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ) );
7247 - } else { // Fall back to basic obfuscation.
7248 - $length = strlen( $text );
7249 - for ( $i = 0; $i < $length; $i++ ) {
7250 - $char = substr( $text, $i, 1 );
5710 + // Fall back to basic obfuscation.
5711 + } else {
5712 + for ( $i = 0; $i < strlen( $text ); $i++ ) {
5713 + $char = substr( $text, $i, 1 );
7251 5714 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7252 - $char = chr( ord( $char ) + ord( $keychar ) );
5715 + $char = chr( ord( $char ) + ord( $keychar ) );
7253 5716 $result .= $char;
7254 5717 }
7255 5718 $result = base64_encode( $result );
7256 5719 }
@@ -7261,18 +5724,17 @@
7261 5724
7262 5725 /**
7263 5726 * Basic decryption using a public (not secret!) key. Used for general
7264 5727 * database obfuscation of passwords.
7265 - *
7266 - * @param string $secret String to encrypt.
7267 - * @param string $library Encryption lib to use (openssl).
7268 - * @return string Decrypted string
5728 + * @param $text String to encrypt.
5729 + * @param $library Encryption lib to use (openssl).
5730 + * @return Decrypted string
7269 5731 */
7270 - private function decrypt( $secret, $library = 'openssl' ) {
5732 + function decrypt( $secret, $library = 'openssl' ) {
7271 5733 $result = '';
7272 5734
7273 5735 // Use openssl library (better) if it is enabled.
7274 - if ( function_exists( 'openssl_decrypt' ) && 'openssl' === $library ) {
5736 + if ( function_exists( 'openssl_decrypt' ) && $library === 'openssl' ) {
7275 5737 $result = openssl_decrypt(
7276 5738 base64_decode( $secret ),
7277 5739 'AES-256-CBC',
7278 5740 hash( 'sha256', self::$key ),
@@ -7278,18 +5740,19 @@
7278 5740 hash( 'sha256', self::$key ),
7279 5741 0,
7280 5742 substr( hash( 'sha256', self::$iv ), 0, 16 )
7281 5743 );
7282 - } elseif ( function_exists( 'mcrypt_decrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5744 + // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
5745 + } else if ( function_exists( 'mcrypt_decrypt' ) ) {
7283 5746 $secret = base64_decode( $secret );
7284 5747 $result = rtrim( mcrypt_decrypt( MCRYPT_RIJNDAEL_256, self::$key, $secret, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ), "\0$result" );
7285 - } else { // Fall back to basic obfuscation.
5748 + // Fall back to basic obfuscation.
5749 + } else {
7286 5750 $secret = base64_decode( $secret );
7287 - $length = strlen( $secret );
7288 - for ( $i = 0; $i < $length; $i++ ) {
7289 - $char = substr( $secret, $i, 1 );
5751 + for ( $i = 0; $i < strlen( $secret ); $i++ ) {
5752 + $char = substr( $secret, $i, 1 );
7290 5753 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7291 - $char = chr( ord( $char ) - ord( $keychar ) );
5754 + $char = chr( ord( $char ) - ord( $keychar ) );
7292 5755 $result .= $char;
7293 5756 }
7294 5757 }
7295 5758
@@ -7300,12 +5763,10 @@
7300 5763 /**
7301 5764 * In a multisite environment, returns true if the current user is logged
7302 5765 * in and a user of the current blog. In single site mode, simply returns
7303 5766 * true if the current user is logged in.
7304 - *
7305 - * @return bool Whether current user is logged in and a user of the current blog.
7306 5767 */
7307 - protected function is_user_logged_in_and_blog_user() {
5768 + function is_user_logged_in_and_blog_user() {
7308 5769 $is_user_logged_in_and_blog_user = false;
7309 5770 if ( is_multisite() ) {
7310 5771 $is_user_logged_in_and_blog_user = is_user_logged_in() && is_user_member_of_blog( get_current_user_id() );
7311 5772 } else {
@@ -7318,42 +5779,39 @@
7318 5779 /**
7319 5780 * Helper function to determine whether a given email is in one of
7320 5781 * the lists (pending, approved, blocked). Defaults to the list of
7321 5782 * approved users.
7322 - *
7323 - * @param string $email Email to check existent of.
7324 - * @param string $list List to look for email in.
7325 - * @param string $multisite_mode Admin context.
7326 - * @return boolean Whether email was found.
7327 5783 */
7328 - protected function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
7329 - if ( empty( $email ) ) {
5784 + function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
5785 + if ( empty( $email ) )
7330 5786 return false;
7331 - }
7332 5787
7333 5788 switch ( $list ) {
7334 - case 'pending':
7335 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7336 - return $this->in_multi_array( $email, $auth_settings_access_users_pending );
7337 - case 'blocked':
7338 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7339 - return $this->in_multi_array( $email, $auth_settings_access_users_blocked );
7340 - case 'approved':
7341 - default:
7342 - if ( 'single' !== $multisite_mode ) {
7343 - // Get multisite users only.
7344 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7345 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7346 - // This site has overridden any multisite settings, so only get its users.
7347 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7348 - } else {
7349 - // Get all site users and all multisite users.
7350 - $auth_settings_access_users_approved = array_merge(
7351 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7352 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7353 - );
7354 - }
7355 - return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5789 + case 'pending':
5790 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5791 + return $this->in_multi_array( $email, $auth_settings_access_users_pending );
5792 + break;
5793 + case 'blocked':
5794 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5795 + return $this->in_multi_array( $email, $auth_settings_access_users_blocked );
5796 + break;
5797 + case 'approved':
5798 + default:
5799 + if ( $multisite_mode !== 'single' ) {
5800 + // Get multisite users only.
5801 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5802 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5803 + // This site has overridden any multisite settings, so only get its users.
5804 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5805 + } else {
5806 + // Get all site users and all multisite users.
5807 + $auth_settings_access_users_approved = array_merge(
5808 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5809 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5810 + );
5811 + }
5812 + return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5813 + break;
7356 5814 }
7357 5815 }
7358 5816
7359 5817
@@ -7359,37 +5817,36 @@
7359 5817
7360 5818 /**
7361 5819 * Helper function to get number of users (including multisite users)
7362 5820 * in a given list (pending, approved, or blocked).
7363 - *
7364 - * @param string $list List to get count of.
7365 - * @param string $admin_mode WP_Plugin_Authorizer::SINGLE_CONTEXT or WP_Plugin_Authorizer::NETWORK_CONTEXT determines whether to include multisite users.
7366 - * @return int Number of users in list.
5821 + * @param string $list
5822 + * @param string $admin_mode SINGLE_ADMIN or MULTISITE_ADMIN determines whether to include multisite users
5823 + * @return int number of users in list
7367 5824 */
7368 - protected function get_user_count_from_list( $list, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
5825 + function get_user_count_from_list( $list, $admin_mode = SINGLE_ADMIN ) {
7369 5826 $auth_settings_access_users = array();
7370 5827
7371 5828 switch ( $list ) {
7372 - case 'pending':
7373 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7374 - break;
7375 - case 'blocked':
7376 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7377 - break;
7378 - case 'approved':
7379 - if ( WP_Plugin_Authorizer::SINGLE_CONTEXT !== $admin_mode ) {
7380 - // Get multisite users only.
7381 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7382 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7383 - // This site has overridden any multisite settings, so only get its users.
7384 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7385 - } else {
7386 - // Get all site users and all multisite users.
7387 - $auth_settings_access_users = array_merge(
7388 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7389 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7390 - );
7391 - }
5829 + case 'pending':
5830 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5831 + break;
5832 + case 'blocked':
5833 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5834 + break;
5835 + case 'approved':
5836 + if ( $admin_mode !== SINGLE_ADMIN ) {
5837 + // Get multisite users only.
5838 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5839 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5840 + // This site has overridden any multisite settings, so only get its users.
5841 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5842 + } else {
5843 + // Get all site users and all multisite users.
5844 + $auth_settings_access_users = array_merge(
5845 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5846 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5847 + );
5848 + }
7392 5849 }
7393 5850
7394 5851 return count( $auth_settings_access_users );
7395 5852 }
@@ -7396,27 +5853,21 @@
7396 5853
7397 5854
7398 5855 /**
7399 5856 * Helper function to search a multidimensional array for a value.
7400 - *
7401 - * @param string $needle Value to search for.
7402 - * @param array $haystack Multidimensional array to search.
7403 - * @param string $strict_mode 'strict' if strict comparisons should be used.
7404 - * @param string $case_sensitivity 'case sensitive' if comparisons should respect case.
7405 - * @return bool Whether needle was found.
7406 5857 */
7407 - protected function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
5858 + function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
7408 5859 if ( ! is_array( $haystack ) ) {
7409 5860 return false;
7410 5861 }
7411 - if ( 'case insensitive' === $case_sensitivity ) {
5862 + if ( $case_sensitivity === 'case insensitive' ) {
7412 5863 $needle = strtolower( $needle );
7413 5864 }
7414 5865 foreach ( $haystack as $item ) {
7415 - if ( 'case insensitive' === $case_sensitivity && ! is_array( $item ) ) {
5866 + if ( $case_sensitivity === 'case insensitive' && ! is_array( $item ) ) {
7416 5867 $item = strtolower( $item );
7417 5868 }
7418 - if ( ( 'strict' === $strict_mode ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) { // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison
5869 + if ( ( $strict_mode === 'strict' ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) {
7419 5870 return true;
7420 5871 }
7421 5872 }
7422 5873 return false;
@@ -7425,17 +5876,17 @@
7425 5876
7426 5877 /**
7427 5878 * Helper function to determine if an URL is accessible.
7428 5879 *
7429 - * @param string $url URL that should be publicly reachable.
7430 - * @return boolean Whether the URL is publicly reachable.
5880 + * @param string $url URL that should be publicly reachable
5881 + * @return boolean Whether the URL is publicly reachable
7431 5882 */
7432 - protected function url_is_accessible( $url ) {
5883 + function url_is_accessible( $url ) {
7433 5884 // Use wp_remote_retrieve_response_code() to retrieve the URL.
7434 - $response = wp_remote_get( $url );
5885 + $response = wp_remote_get( $url );
7435 5886 $response_code = wp_remote_retrieve_response_code( $response );
7436 5887
7437 - // Return true if the document has loaded successfully without any redirection or error.
5888 + // Return true if the document has loaded successfully without any redirection or error
7438 5889 return $response_code >= 200 && $response_code < 400;
7439 5890 }
7440 5891
7441 5892
@@ -7440,14 +5891,13 @@
7440 5891
7441 5892
7442 5893 /**
7443 5894 * Helper function to reconstruct a URL split using parse_url().
7444 - *
7445 - * @param array $parts Array returned from parse_url().
7446 - * @return string URL.
5895 + * @param array $parts Array returned from parse_url().
5896 + * @return string URL.
7447 5897 */
7448 - protected function build_url( $parts = array() ) {
7449 - return (
5898 + function build_url( $parts = array() ) {
5899 + return
7450 5900 ( isset( $parts['scheme'] ) ? "{$parts['scheme']}:" : '' ) .
7451 5901 ( ( isset( $parts['user'] ) || isset( $parts['host'] ) ) ? '//' : '' ) .
7452 5902 ( isset( $parts['user'] ) ? "{$parts['user']}" : '' ) .
7453 5903 ( isset( $parts['pass'] ) ? ":{$parts['pass']}" : '' ) .
@@ -7455,30 +5905,21 @@
7455 5905 ( isset( $parts['host'] ) ? "{$parts['host']}" : '' ) .
7456 5906 ( isset( $parts['port'] ) ? ":{$parts['port']}" : '' ) .
7457 5907 ( isset( $parts['path'] ) ? "{$parts['path']}" : '' ) .
7458 5908 ( isset( $parts['query'] ) ? "?{$parts['query']}" : '' ) .
7459 - ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' )
7460 - );
5909 + ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' );
7461 5910 }
7462 5911
7463 5912
7464 - /**
7465 - * Helper function that prints option tags for a select element for all
7466 - * roles the current user has permission to assign.
7467 - *
7468 - * @param string $selected_role Which role should be selected in the dropdown.
7469 - * @param string $disable_input 'disabled' if select element should be disabled.
7470 - * @param int $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT if we are in that context.
7471 - * @return void
7472 - */
7473 - protected function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
7474 - $roles = get_editable_roles();
5913 + // Helper function that builds option tags for a select element for all
5914 + // roles the current user has permission to assign.
5915 + function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = SINGLE_ADMIN ) {
5916 + $roles = get_editable_roles();
7475 5917 $current_user = wp_get_current_user();
7476 5918
7477 5919 // If we're in network admin, also show any roles that might exist only on
7478 5920 // specific sites in the network (themes can add their own roles).
7479 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
7480 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
5921 + if ( $admin_mode === MULTISITE_ADMIN ) {
7481 5922 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7482 5923 foreach ( $sites as $site ) {
7483 5924 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7484 5925 switch_to_blog( $blog_id );
@@ -7487,11 +5928,11 @@
7487 5928 }
7488 5929 $unique_role_names = array();
7489 5930 foreach ( $roles as $role_name => $role_info ) {
7490 5931 if ( array_key_exists( $role_name, $unique_role_names ) ) {
7491 - unset( $roles[ $role_name ] );
5932 + unset( $roles[$role_name] );
7492 5933 } else {
7493 - $unique_role_names[ $role_name ] = true;
5934 + $unique_role_names[$role_name] = true;
7494 5935 }
7495 5936 }
7496 5937 }
7497 5938
@@ -7503,41 +5944,37 @@
7503 5944 }
7504 5945
7505 5946 // Print an option element for each permitted role.
7506 5947 foreach ( $roles as $name => $role ) {
7507 - $is_selected = $selected_role === $name;
5948 + $selected = $selected_role === $name ? ' selected="selected"' : '';
7508 5949
7509 - // Don't let a user change their own role (but network admins always can).
7510 - $is_disabled = $selected_role !== $name && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7511 - ?>
7512 - <option value="<?php echo esc_attr( $name ); ?>"<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php echo esc_html( $role['name'] ); ?></option>
7513 - <?php
5950 + // Don't let a user change their own role
5951 + $disabled = $selected_role !== $name && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5952 +
5953 + // But network admins can always change their role.
5954 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5955 + $disabled = '';
5956 + }
5957 +
5958 + ?><option value="<?php echo $name; ?>"<?php echo $selected . $disabled; ?>><?php echo $role['name']; ?></option><?php
7514 5959 }
7515 5960
7516 5961 // Print default role (no role).
7517 - $is_selected = strlen( $selected_role ) === 0 || ! array_key_exists( $selected_role, $roles );
7518 - $is_disabled = strlen( $selected_role ) > 0 && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7519 - ?>
7520 - <option value=""<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php esc_html_e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option>
7521 - <?php
5962 + $selected = strlen( $selected_role ) == 0 || ! array_key_exists( $selected_role, $roles ) ? ' selected="selected"' : '';
5963 + $disabled = strlen( $selected_role ) > 0 && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5964 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5965 + $disabled = '';
5966 + }
5967 + ?><option value=""<?php echo $selected . $disabled; ?>><?php _e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option><?php
7522 5968
7523 5969 }
7524 5970
7525 5971
7526 - /**
7527 - * Helper function to get a single user info array from one of the access
7528 - * control lists (pending, approved, or blocked).
7529 - *
7530 - * @param string $email Email address to retrieve info for.
7531 - * @param string $list List to get info from.
7532 - * @return mixed false if not found, otherwise: array(
7533 - * 'email' => '',
7534 - * 'role' => '',
7535 - * 'date_added' => '',
7536 - * ['usermeta' => [''|array()]]
7537 - * );
7538 - */
7539 - protected function get_user_info_from_list( $email, $list ) {
5972 + // Helper function to get a single user info array from one of the
5973 + // access control lists (pending, approved, or blocked).
5974 + // Returns: false if not found; otherwise
5975 + // array( 'email' => '', 'role' => '', 'date_added' => '', ['usermeta' => [''|array()]] );
5976 + function get_user_info_from_list( $email, $list ) {
7540 5977 foreach ( $list as $user_info ) {
7541 5978 if ( 0 === strcasecmp( $user_info['email'], $email ) ) {
7542 5979 return $user_info;
7543 5980 }
@@ -7544,49 +5981,29 @@
7544 5981 }
7545 5982 return false;
7546 5983 }
7547 5984
7548 - /**
7549 - * Helper function to convert a string to lowercase. Prefers to use mb_strtolower,
7550 - * but will fall back to strtolower if the former is not available.
7551 - *
7552 - * @param string $string String to convert to lowercase.
7553 - * @return string Input in lowercase.
7554 - */
7555 - protected function lowercase( $string ) {
7556 - return function_exists( 'mb_strtolower' ) ? mb_strtolower( $string ) : strtolower( $string );
7557 - }
7558 5985
7559 -
7560 - /**
7561 - * Helper function to convert seconds to human readable text.
7562 - *
7563 - * @see: http://csl.name/php-secs-to-human-text/
7564 - *
7565 - * @param int $secs Seconds to display as readable text.
7566 - * @return string Readable version of number of seconds.
7567 - */
7568 - protected function seconds_as_sentence( $secs ) {
5986 + // Helper function to convert seconds to human readable text.
5987 + // Source: http://csl.name/php-secs-to-human-text/
5988 + function seconds_as_sentence( $secs ) {
7569 5989 $units = array(
7570 - 'week' => 3600 * 24 * 7,
7571 - 'day' => 3600 * 24,
7572 - 'hour' => 3600,
7573 - 'minute' => 60,
7574 - 'second' => 1,
5990 + "week" => 7 * 24 * 3600,
5991 + "day" => 24 * 3600,
5992 + "hour" => 3600,
5993 + "minute" => 60,
5994 + "second" => 1,
7575 5995 );
7576 5996
7577 - // Specifically handle zero.
7578 - if ( 0 === intval( $secs ) ) {
7579 - return '0 seconds';
7580 - }
5997 + // specifically handle zero
5998 + if ( $secs == 0 ) return "0 seconds";
7581 5999
7582 - $s = '';
6000 + $s = "";
7583 6001
7584 6002 foreach ( $units as $name => $divisor ) {
7585 - $quot = intval( $secs / $divisor );
7586 - if ( $quot ) {
7587 - $s .= "$quot $name";
7588 - $s .= ( abs( $quot ) > 1 ? 's' : '' ) . ', ';
6003 + if ( $quot = intval( $secs / $divisor ) ) {
6004 + $s .= "$quot $name";
6005 + $s .= ( abs( $quot ) > 1 ? "s" : "" ) . ", ";
7589 6006 $secs -= $quot * $divisor;
7590 6007 }
7591 6008 }
7592 6009
@@ -7592,14 +6009,10 @@
7592 6009
7593 6010 return substr( $s, 0, -2 );
7594 6011 }
7595 6012
7596 - /**
7597 - * Helper function to get all available usermeta keys as an array.
7598 - *
7599 - * @return array All usermeta keys for user.
7600 - */
7601 - protected function get_all_usermeta_keys() {
6013 + // Helper function to get all available usermeta keys as an array.
6014 + function get_all_usermeta_keys() {
7602 6015 global $wpdb;
7603 6016 $usermeta_keys = $wpdb->get_col( "SELECT DISTINCT $wpdb->usermeta.meta_key FROM $wpdb->usermeta" );
7604 6017 return $usermeta_keys;
7605 6018 }
@@ -7606,12 +6019,10 @@
7606 6019
7607 6020
7608 6021 /**
7609 6022 * Load translated strings from *.mo files in /languages.
7610 - *
7611 - * Action: plugins_loaded
7612 6023 */
7613 - public function load_textdomain() {
6024 + function load_textdomain() {
7614 6025 load_plugin_textdomain(
7615 6026 'authorizer',
7616 6027 false,
7617 6028 plugin_basename( dirname( __FILE__ ) ) . '/languages'
@@ -7622,17 +6033,14 @@
7622 6033 /**
7623 6034 * Generate CAS authentication URL (wp-login.php URL with reauth=1 removed
7624 6035 * and external=cas added).
7625 6036 */
7626 - private function modify_current_url_for_cas_login() {
6037 + function modify_current_url_for_cas_login() {
7627 6038 // Construct the URL of the current page (wp-login.php).
7628 - $url = '';
7629 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
7630 - $url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
7631 - }
6039 + $url = 'http' . ( isset( $_SERVER['HTTPS'] ) ? 's' : '' ) . '://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
7632 6040
7633 6041 // Parse the URL into its components.
7634 - $parsed_url = wp_parse_url( $url );
6042 + $parsed_url = parse_url( $url );
7635 6043
7636 6044 // Fix up the querystring values (remove reauth, make sure external=cas).
7637 6045 $querystring = array();
7638 6046 if ( array_key_exists( 'query', $parsed_url ) ) {
@@ -7639,9 +6047,9 @@
7639 6047 parse_str( $parsed_url['query'], $querystring );
7640 6048 }
7641 6049 unset( $querystring['reauth'] );
7642 6050 $querystring['external'] = 'cas';
7643 - $parsed_url['query'] = http_build_query( $querystring );
6051 + $parsed_url['query'] = http_build_query( $querystring );
7644 6052
7645 6053 // Return the URL as a string.
7646 6054 return $this->unparse_url( $parsed_url );
7647 6055 }
@@ -7648,21 +6056,20 @@
7648 6056
7649 6057
7650 6058 /**
7651 6059 * Reconstruct a URL after it has been deconstructed with parse_url().
7652 - *
7653 - * @param array $parsed_url Keys from parse_url().
7654 - * @return string URL constructed from the components in $parsed_url.
6060 + * @param $parsed_url array() with keys from parse_url().
6061 + * @return string URL constructed from the components in $parsed_url.
7655 6062 */
7656 - protected function unparse_url( $parsed_url = array() ) {
7657 - $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
7658 - $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
7659 - $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
7660 - $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
7661 - $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
7662 - $pass = $user || $pass ? "$pass@" : '';
7663 - $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
7664 - $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
6063 + function unparse_url( $parsed_url = array() ) {
6064 + $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
6065 + $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
6066 + $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
6067 + $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
6068 + $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
6069 + $pass = $user || $pass ? "$pass@" : '';
6070 + $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
6071 + $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
7665 6072 $fragment = isset( $parsed_url['fragment'] ) ? '#' . $parsed_url['fragment'] : '';
7666 6073 return "$scheme$user$pass$host$port$path$query$fragment";
7667 6074 }
7668 6075
@@ -7667,30 +6074,15 @@
7667 6074 }
7668 6075
7669 6076
7670 6077 /**
7671 - * Helper function to generate an HTML class name for an option (used in
7672 - * Authorizer Settings in the Approved User list).
7673 - *
7674 - * @param string $suffix Unique part of class name.
7675 - * @param boolean $is_multisite_user Whether the class name should indicate it's a multisite user.
7676 - * @return string Class name, e.g., "auth-email auth-multisite-email".
7677 - */
7678 - private function create_class_name( $suffix = '', $is_multisite_user = false ) {
7679 - return $is_multisite_user ? "auth-$suffix auth-multisite-$suffix" : "auth-$suffix";
7680 - }
7681 -
7682 -
7683 - /**
7684 6078 * Plugin Update Routines.
7685 - *
7686 - * Action: plugins_loaded
7687 6079 */
7688 - public function auth_update_check() {
6080 + function auth_update_check() {
7689 6081 // Get current version.
7690 6082 $needs_updating = false;
7691 6083 if ( is_multisite() ) {
7692 - $auth_version = get_blog_option( $this->current_site_blog_id, 'auth_version' );
6084 + $auth_version = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_version' );
7693 6085 } else {
7694 6086 $auth_version = get_option( 'auth_version' );
7695 6087 }
7696 6088
@@ -7702,9 +6094,9 @@
7702 6094 // log in; approved and blocked lists are changed whenever an admin
7703 6095 // changes them from the multisite panel, the dashboard widget, or
7704 6096 // the plugin options page.
7705 6097 $update_if_older_than = 20140709;
7706 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6098 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7707 6099 // Copy single site user lists to new options (if they exist).
7708 6100 $auth_settings = get_option( 'auth_settings' );
7709 6101 if ( is_array( $auth_settings ) && array_key_exists( 'access_users_pending', $auth_settings ) ) {
7710 6102 update_option( 'auth_settings_access_users_pending', $auth_settings['access_users_pending'] );
@@ -7722,27 +6114,27 @@
7722 6114 update_option( 'auth_settings', $auth_settings );
7723 6115 }
7724 6116 // Copy multisite user lists to new options (if they exist).
7725 6117 if ( is_multisite() ) {
7726 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
6118 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7727 6119 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_pending', $auth_multisite_settings ) ) {
7728 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
6120 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
7729 6121 unset( $auth_multisite_settings['access_users_pending'] );
7730 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6122 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7731 6123 }
7732 6124 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_approved', $auth_multisite_settings ) ) {
7733 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
6125 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
7734 6126 unset( $auth_multisite_settings['access_users_approved'] );
7735 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6127 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7736 6128 }
7737 6129 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_blocked', $auth_multisite_settings ) ) {
7738 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
6130 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
7739 6131 unset( $auth_multisite_settings['access_users_blocked'] );
7740 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6132 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7741 6133 }
7742 6134 }
7743 6135 // Update version to reflect this change has been made.
7744 - $auth_version = $update_if_older_than;
6136 + $auth_version = $update_if_older_than;
7745 6137 $needs_updating = true;
7746 6138 }
7747 6139
7748 6140 // Update: Set default values for newly added options (forgot to do
@@ -7748,13 +6140,12 @@
7748 6140 // Update: Set default values for newly added options (forgot to do
7749 6141 // this, so some users are getting debug log notices about undefined
7750 6142 // indexes in $auth_settings).
7751 6143 $update_if_older_than = 20160831;
7752 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6144 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7753 6145 // Provide default values for any $auth_settings options that don't exist.
7754 6146 if ( is_multisite() ) {
7755 - // Get all blog ids.
7756 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6147 + // Get all blog ids
7757 6148 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7758 6149 foreach ( $sites as $site ) {
7759 6150 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7760 6151 switch_to_blog( $blog_id );
@@ -7759,9 +6150,9 @@
7759 6150 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7760 6151 switch_to_blog( $blog_id );
7761 6152 // Set meaningful defaults for other sites in the network.
7762 6153 $this->set_default_options();
7763 - // Switch back to original blog.
6154 + // Switch back to original blog. See: https://codex.wordpress.org/Function_Reference/restore_current_blog
7764 6155 restore_current_blog();
7765 6156 }
7766 6157 } else {
7767 6158 // Set meaningful defaults for this site.
@@ -7767,9 +6158,9 @@
7767 6158 // Set meaningful defaults for this site.
7768 6159 $this->set_default_options();
7769 6160 }
7770 6161 // Update version to reflect this change has been made.
7771 - $auth_version = $update_if_older_than;
6162 + $auth_version = $update_if_older_than;
7772 6163 $needs_updating = true;
7773 6164 }
7774 6165
7775 6166 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
@@ -7774,18 +6165,17 @@
7774 6165
7775 6166 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7776 6167 // deprecated as of PHP 7.1. Use openssl library instead.
7777 6168 $update_if_older_than = 20170510;
7778 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6169 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7779 6170 if ( is_multisite() ) {
7780 6171 // Reencrypt LDAP passwords in each site in the network.
7781 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7782 6172 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7783 6173 foreach ( $sites as $site ) {
7784 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6174 + $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7785 6175 $auth_settings = get_blog_option( $blog_id, 'auth_settings', array() );
7786 6176 if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7787 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
6177 + $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7788 6178 $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7789 6179 update_blog_option( $blog_id, 'auth_settings', $auth_settings );
7790 6180 }
7791 6181 }
@@ -7792,15 +6182,15 @@
7792 6182 } else {
7793 6183 // Reencrypt LDAP password on this single-site install.
7794 6184 $auth_settings = get_option( 'auth_settings', array() );
7795 6185 if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7796 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
6186 + $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7797 6187 $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7798 6188 update_option( 'auth_settings', $auth_settings );
7799 6189 }
7800 6190 }
7801 6191 // Update version to reflect this change has been made.
7802 - $auth_version = $update_if_older_than;
6192 + $auth_version = $update_if_older_than;
7803 6193 $needs_updating = true;
7804 6194 }
7805 6195
7806 6196 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
@@ -7806,20 +6196,20 @@
7806 6196 // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7807 6197 // deprecated as of PHP 7.1. Use openssl library instead.
7808 6198 // Note: Forgot to update the auth_multisite_settings ldap password! Do it here.
7809 6199 $update_if_older_than = 20170511;
7810 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6200 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7811 6201 if ( is_multisite() ) {
7812 6202 // Reencrypt LDAP password in network (multisite) options.
7813 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
6203 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7814 6204 if ( array_key_exists( 'ldap_password', $auth_multisite_settings ) && strlen( $auth_multisite_settings['ldap_password'] ) > 0 ) {
7815 - $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
6205 + $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
7816 6206 $auth_multisite_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7817 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
6207 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7818 6208 }
7819 6209 }
7820 6210 // Update version to reflect this change has been made.
7821 - $auth_version = $update_if_older_than;
6211 + $auth_version = $update_if_older_than;
7822 6212 $needs_updating = true;
7823 6213 }
7824 6214
7825 6215 // Update: Remove duplicates from approved list caused by authorizer_automatically_approve_login
@@ -7825,24 +6215,23 @@
7825 6215 // Update: Remove duplicates from approved list caused by authorizer_automatically_approve_login
7826 6216 // filter not respecting users who are already in the approved list
7827 6217 // (causing them to get re-added each time they logged in).
7828 6218 $update_if_older_than = 20170711;
7829 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
6219 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7830 6220 // Remove duplicates from approved user lists.
7831 6221 if ( is_multisite() ) {
7832 - // Remove duplicates from each site in the multisite.
7833 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6222 + // Remove duplicates from each site in the multisite
7834 6223 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7835 6224 foreach ( $sites as $site ) {
7836 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6225 + $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7837 6226 $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
7838 6227 if ( is_array( $auth_settings_access_users_approved ) ) {
7839 - $should_update = false;
6228 + $should_update = false;
7840 6229 $distinct_emails = array();
7841 6230 foreach ( $auth_settings_access_users_approved as $key => $user ) {
7842 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
6231 + if ( in_array( $user['email'], $distinct_emails ) ) {
7843 6232 $should_update = true;
7844 - unset( $auth_settings_access_users_approved[ $key ] );
6233 + unset( $auth_settings_access_users_approved[$key] );
7845 6234 } else {
7846 6235 $distinct_emails[] = $user['email'];
7847 6236 }
7848 6237 }
@@ -7851,22 +6240,22 @@
7851 6240 }
7852 6241 }
7853 6242 }
7854 6243 // Remove duplicates from multisite approved user list.
7855 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
6244 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() );
7856 6245 if ( is_array( $auth_multisite_settings_access_users_approved ) ) {
7857 - $should_update = false;
6246 + $should_update = false;
7858 6247 $distinct_emails = array();
7859 6248 foreach ( $auth_multisite_settings_access_users_approved as $key => $user ) {
7860 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
6249 + if ( in_array( $user['email'], $distinct_emails ) ) {
7861 6250 $should_update = true;
7862 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
6251 + unset( $auth_multisite_settings_access_users_approved[$key] );
7863 6252 } else {
7864 6253 $distinct_emails[] = $user['email'];
7865 6254 }
7866 6255 }
7867 6256 if ( $should_update ) {
7868 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6257 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7869 6258 }
7870 6259 }
7871 6260 } else {
7872 6261 // Remove duplicates from single site approved user list.
@@ -7871,14 +6260,14 @@
7871 6260 } else {
7872 6261 // Remove duplicates from single site approved user list.
7873 6262 $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
7874 6263 if ( is_array( $auth_settings_access_users_approved ) ) {
7875 - $should_update = false;
6264 + $should_update = false;
7876 6265 $distinct_emails = array();
7877 6266 foreach ( $auth_settings_access_users_approved as $key => $user ) {
7878 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
6267 + if ( in_array( $user['email'], $distinct_emails ) ) {
7879 6268 $should_update = true;
7880 - unset( $auth_settings_access_users_approved[ $key ] );
6269 + unset( $auth_settings_access_users_approved[$key] );
7881 6270 } else {
7882 6271 $distinct_emails[] = $user['email'];
7883 6272 }
7884 6273 }
@@ -7887,90 +6276,24 @@
7887 6276 }
7888 6277 }
7889 6278 }
7890 6279 // Update version to reflect this change has been made.
7891 - $auth_version = $update_if_older_than;
6280 + $auth_version = $update_if_older_than;
7892 6281 $needs_updating = true;
7893 6282 }
7894 6283
7895 - // Update: Set default value for newly added option advanced_widget_enabled.
7896 - $update_if_older_than = 20171023;
7897 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7898 - // Provide default values for any $auth_settings options that don't exist.
7899 - if ( is_multisite() ) {
7900 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7901 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7902 - foreach ( $sites as $site ) {
7903 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7904 - switch_to_blog( $blog_id );
7905 - $this->set_default_options();
7906 - restore_current_blog();
7907 - }
7908 - } else {
7909 - $this->set_default_options();
7910 - }
7911 - // Update version to reflect this change has been made.
7912 - $auth_version = $update_if_older_than;
7913 - $needs_updating = true;
7914 - }
6284 + // // Update: TEMPLATE
6285 + // $update_if_older_than = YYYYMMDD;
6286 + // if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
6287 + // UPDATE CODE HERE
6288 + // // Update version to reflect this change has been made.
6289 + // $auth_version = $update_if_older_than;
6290 + // $needs_updating = true;
6291 + // }
7915 6292
7916 - // Update: Set default value for newly added option advanced_users_per_page.
7917 - $update_if_older_than = 20171215;
7918 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7919 - // Provide default values for any $auth_settings options that don't exist.
7920 - if ( is_multisite() ) {
7921 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7922 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7923 - foreach ( $sites as $site ) {
7924 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7925 - switch_to_blog( $blog_id );
7926 - $this->set_default_options();
7927 - restore_current_blog();
7928 - }
7929 - } else {
7930 - $this->set_default_options();
7931 - }
7932 - // Update version to reflect this change has been made.
7933 - $auth_version = $update_if_older_than;
7934 - $needs_updating = true;
7935 - }
7936 -
7937 - // Update: Set default value for newly added options advanced_users_sort_by and advanced_users_sort_order.
7938 - $update_if_older_than = 20171219;
7939 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7940 - // Provide default values for any $auth_settings options that don't exist.
7941 - if ( is_multisite() ) {
7942 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7943 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7944 - foreach ( $sites as $site ) {
7945 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7946 - switch_to_blog( $blog_id );
7947 - $this->set_default_options();
7948 - restore_current_blog();
7949 - }
7950 - } else {
7951 - $this->set_default_options();
7952 - }
7953 - // Update version to reflect this change has been made.
7954 - $auth_version = $update_if_older_than;
7955 - $needs_updating = true;
7956 - }
7957 -
7958 - /*
7959 - // Update: TEMPLATE
7960 - $update_if_older_than = YYYYMMDD;
7961 - if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7962 - UPDATE CODE HERE
7963 - // Update version to reflect this change has been made.
7964 - $auth_version = $update_if_older_than;
7965 - $needs_updating = true;
7966 - }
7967 - */
7968 -
7969 6293 // Save new version number if we performed any updates.
7970 6294 if ( $needs_updating ) {
7971 6295 if ( is_multisite() ) {
7972 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7973 6296 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7974 6297 foreach ( $sites as $site ) {
7975 6298 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7976 6299 update_blog_option( $blog_id, 'auth_version', $auth_version );