PluginProbe
Authorizer / 2.6.7
Authorizer v2.6.7
3.15.3 3.15.2 3.15.1 3.15.0 3.14.3 3.14.4 3.14.2 3.14.1 2.8.1 2.8.2 2.8.3 2.8.4 2.8.5 2.8.6 2.8.7 2.8.8 2.9.0 2.9.1 2.9.10 2.9.11 2.9.12 2.9.13 2.9.2 2.9.3 2.9.6 All 126 releases
← All changes | authorizer.php +2070 -4089 2.8.12.6.7 View file →
@@ -1,31 +1,51 @@
1 1 <?php
2 -/**
3 - * Plugin Name: Authorizer
4 - * Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
5 - * Author: Paul Ryan <prar@hawaii.edu>
6 - * Plugin URI: https://github.com/uhm-coe/authorizer
7 - * Text Domain: authorizer
8 - * Domain Path: /languages
9 - * License: GPL2
10 - * Version: 2.8.1
11 - *
12 - * @package authorizer
13 - */
2 +/*
3 +Plugin Name: Authorizer
4 +Plugin URI: https://github.com/uhm-coe/authorizer
5 +Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS).
6 +Version: 2.6.7
7 +Author: Paul Ryan
8 +Author URI: http://www.linkedin.com/in/paulrryan/
9 +Text Domain: authorizer
10 +Domain Path: /languages
11 +License: GPL2
12 +*/
14 13
15 -/**
16 - * Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
17 - * Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
18 - * Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
19 - */
20 14
21 -/**
22 - * Add phpCAS library if it's not included.
23 - *
24 - * @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
25 - */
15 +/*
16 +Copyright 2014 Paul Ryan (email: prar@hawaii.edu)
17 +
18 +This program is free software; you can redistribute it and/or modify
19 +it under the terms of the GNU General Public License, version 2, as
20 +published by the Free Software Foundation.
21 +
22 +This program is distributed in the hope that it will be useful,
23 +but WITHOUT ANY WARRANTY; without even the implied warranty of
24 +MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
25 +GNU General Public License for more details.
26 +
27 +You should have received a copy of the GNU General Public License
28 +along with this program; if not, write to the Free Software
29 +Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
30 +*/
31 +
32 +
33 +/*
34 +Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/
35 +Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/
36 +Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/
37 +*/
38 +
39 +
40 +define( 'MULTISITE_ADMIN', 'multisite_admin' );
41 +define( 'SINGLE_ADMIN', 'single_admin' );
42 +
43 +
44 +// Add phpCAS library if it's not included.
45 +// @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide
26 46 if ( ! defined( 'PHPCAS_VERSION' ) ) {
27 - require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.5/CAS.php';
47 + require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.4/CAS.php';
28 48 }
29 49
30 50
31 51 if ( ! class_exists( 'WP_Plugin_Authorizer' ) ) {
@@ -39,87 +59,18 @@
39 59 * @link http://hawaii.edu/coe/dcdc/wordpress/authorizer/doc/
40 60 */
41 61 class WP_Plugin_Authorizer {
42 62
43 - /**
44 - * Constants for determining our admin context (network or individual site).
45 - */
46 - const NETWORK_CONTEXT = 'multisite_admin';
47 - const SINGLE_CONTEXT = 'single_admin';
48 63
49 64 /**
50 - * Current site ID (Multisite).
51 - *
52 - * @var string
53 - */
54 - public $current_site_blog_id = 1;
55 -
56 - /**
57 - * HTML allowed when rendering translatable strings in the Authorizer UI.
58 - * This is passed to wp_kses() when sanitizing HMTL strings.
59 - *
60 - * @var array
61 - */
62 - private $allowed_html = array(
63 - 'a' => array(
64 - 'class' => array(),
65 - 'href' => array(),
66 - 'style' => array(),
67 - 'target' => array(),
68 - 'title' => array(),
69 - ),
70 - 'b' => array(),
71 - 'br' => array(),
72 - 'div' => array(
73 - 'class' => array(),
74 - ),
75 - 'em' => array(),
76 - 'hr' => array(),
77 - 'i' => array(),
78 - 'input' => array(
79 - 'aria-describedby' => array(),
80 - 'class' => array(),
81 - 'id' => array(),
82 - 'name' => array(),
83 - 'size' => array(),
84 - 'type' => array(),
85 - 'value' => array(),
86 - ),
87 - 'label' => array(
88 - 'class' => array(),
89 - 'for' => array(),
90 - ),
91 - 'p' => array(
92 - 'style' => array(),
93 - ),
94 - 'span' => array(
95 - 'aria-hidden' => array(),
96 - 'class' => array(),
97 - 'id' => array(),
98 - 'style' => array(),
99 - ),
100 - 'strong' => array(),
101 - );
102 -
103 - /**
104 65 * Constructor.
105 66 */
106 67 public function __construct() {
107 - // Save reference to current blog id in the network (support deprecated
108 - // constant BLOGID_CURRENT_SITE).
109 - if ( defined( 'BLOG_ID_CURRENT_SITE' ) ) {
110 - $this->current_site_blog_id = BLOG_ID_CURRENT_SITE;
111 - } elseif ( defined( 'BLOGID_CURRENT_SITE' ) ) { // deprecated.
112 - $this->current_site_blog_id = BLOGID_CURRENT_SITE;
113 - }
114 -
115 68 // Installation and uninstallation hooks.
116 69 register_activation_hook( __FILE__, array( $this, 'activate' ) );
117 70 register_deactivation_hook( __FILE__, array( $this, 'deactivate' ) );
118 71
119 - /**
120 - * Register filters.
121 - */
72 + // Register filters.
122 73
123 74 // Custom wp authentication routine using external service.
124 75 add_filter( 'authenticate', array( $this, 'custom_authenticate' ), 1, 3 );
125 76
@@ -125,9 +76,13 @@
125 76
126 77 // Custom logout action using external service.
127 78 add_action( 'wp_logout', array( $this, 'custom_logout' ) );
128 79
129 - // Create settings link on Plugins page.
80 + // Removing this bypasses Wordpress authentication (so if external auth fails,
81 + // no one can log in); with it enabled, it will run if external auth fails.
82 + //remove_filter('authenticate', 'wp_authenticate_username_password', 20, 3);
83 +
84 + // Create settings link on Plugins page
130 85 add_filter( 'plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'plugin_settings_link' ) );
131 86 add_filter( 'network_admin_plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'network_admin_plugin_settings_link' ) );
132 87
133 88 // Modify login page with a custom password url (if option is set).
@@ -138,11 +93,9 @@
138 93 if ( $error && strlen( $error ) > 0 ) {
139 94 add_filter( 'login_errors', array( $this, 'show_advanced_login_error' ) );
140 95 }
141 96
142 - /**
143 - * Register actions.
144 - */
97 + // Register actions.
145 98
146 99 // Enable localization. Translation files stored in /languages.
147 100 add_action( 'plugins_loaded', array( $this, 'load_textdomain' ) );
148 101
@@ -154,20 +107,18 @@
154 107
155 108 // Add users who successfully login to the approved list.
156 109 add_action( 'wp_login', array( $this, 'ensure_wordpress_user_in_approved_list_on_login' ), 10, 2 );
157 110
158 - // Create menu item in Settings.
111 + // Create menu item in Settings
159 112 add_action( 'admin_menu', array( $this, 'add_plugin_page' ) );
160 113
161 - // Create options page.
114 + // Create options page
162 115 add_action( 'admin_init', array( $this, 'page_init' ) );
163 116
164 117 // Update user role in approved list if it's changed in the WordPress edit user page.
165 - add_action( 'user_profile_update_errors', array( $this, 'edit_user_profile_update_role' ), 10, 3 );
118 + add_action( 'edit_user_profile_update', array( $this, 'edit_user_profile_update_role' ) );
119 + add_action( 'personal_options_update', array( $this, 'edit_user_profile_update_role' ) );
166 120
167 - // Update user email in approved list if it's changed in the WordPress edit user page.
168 - add_filter( 'send_email_change_email', array( $this, 'edit_user_profile_update_email' ), 10, 3 );
169 -
170 121 // Enqueue javascript and css on the plugin's options page, the
171 122 // dashboard (for the widget), and the network admin.
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
@@ -172,46 +123,35 @@
172 123 add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) );
173 124 add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) );
174 125 add_action( 'load-toplevel_page_authorizer', array( $this, 'load_options_page' ) );
175 126
176 - // Add custom css and js to wp-login.php.
127 + // Add custom css and js to wp-login.php
177 128 add_action( 'login_enqueue_scripts', array( $this, 'login_enqueue_scripts_and_styles' ) );
178 129 add_action( 'login_footer', array( $this, 'load_login_footer_js' ) );
179 130
180 - // Create google nonce cookie when loading wp-login.php if Google is enabled.
181 - add_action( 'login_init', array( $this, 'login_init__maybe_set_google_nonce_cookie' ) );
182 -
183 - // Modify login page with external auth links (if enabled; e.g., google or cas).
131 + // Modify login page with external auth links (if enabled; e.g., google or cas)
184 132 add_action( 'login_form', array( $this, 'login_form_add_external_service_links' ) );
185 133
186 134 // Redirect to CAS login when visiting login page (only if option is
187 135 // enabled, CAS is the only service, and WordPress logins are hidden).
188 - // Note: hook into wp_login_errors filter so this fires after the
189 - // authenticate hook (where the redirect to CAS happens), but before html
190 - // output is started (so the redirect header doesn't complain about data
191 - // already being sent).
192 - add_filter( 'wp_login_errors', array( $this, 'wp_login_errors__maybe_redirect_to_cas' ), 10, 2 );
136 + add_action( 'login_head', array( $this, 'login_head_maybe_redirect_to_cas' ) );
193 137
194 - // Verify current user has access to page they are visiting.
138 + // Verify current user has access to page they are visiting
195 139 add_action( 'parse_request', array( $this, 'restrict_access' ), 9 );
196 - add_action( 'init', array( $this, 'init__maybe_add_network_approved_user' ) );
197 140
198 - // AJAX: Save options from dashboard widget.
141 + // ajax save options from dashboard widget
199 142 add_action( 'wp_ajax_update_auth_user', array( $this, 'ajax_update_auth_user' ) );
200 143
201 - // AJAX: Save options from multisite options page.
144 + // ajax save options from multisite options page
202 145 add_action( 'wp_ajax_save_auth_multisite_settings', array( $this, 'ajax_save_auth_multisite_settings' ) );
203 146
204 - // AJAX: Save usermeta from options page.
147 + // ajax save usermeta from options page
205 148 add_action( 'wp_ajax_update_auth_usermeta', array( $this, 'ajax_update_auth_usermeta' ) );
206 149
207 - // AJAX: Verify google login.
150 + // ajax verify google login
208 151 add_action( 'wp_ajax_process_google_login', array( $this, 'ajax_process_google_login' ) );
209 152 add_action( 'wp_ajax_nopriv_process_google_login', array( $this, 'ajax_process_google_login' ) );
210 153
211 - // AJAX: Refresh approved user list.
212 - add_action( 'wp_ajax_refresh_approved_user_list', array( $this, 'ajax_refresh_approved_user_list' ) );
213 -
214 154 // Add dashboard widget so instructors can add/edit users with access.
215 155 // Hint: For Multisite Network Admin Dashboard use wp_network_dashboard_setup instead of wp_dashboard_setup.
216 156 add_action( 'wp_dashboard_setup', array( $this, 'add_dashboard_widgets' ) );
217 157
@@ -226,12 +166,17 @@
226 166 add_action( 'wp_enqueue_scripts', array( $this, 'auth_public_scripts' ), 20 );
227 167
228 168 // Multisite-specific actions.
229 169 if ( is_multisite() ) {
230 - // Add network admin options page (global settings for all sites).
170 + // Add network admin options page (global settings for all sites)
231 171 add_action( 'network_admin_menu', array( $this, 'network_admin_menu' ) );
232 172 }
233 173
174 + // Create login cookie (used by google login)
175 + if ( ! isset( $_COOKIE['login_unique'] ) ) {
176 + setcookie( 'login_unique', $this->get_cookie_value(), time()+1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
177 + }
178 +
234 179 // Remove user from authorizer lists when that user is deleted in WordPress.
235 180 add_action( 'delete_user', array( $this, 'remove_user_from_authorizer_when_deleted' ) );
236 181 if ( is_multisite() ) {
237 182 // Remove multisite user from authorizer lists when that user is deleted from Network Users.
@@ -267,21 +212,13 @@
267 212 */
268 213 public function activate() {
269 214 global $wpdb;
270 215
271 - // Nonce check.
272 - if (
273 - ! isset( $_REQUEST['_wpnonce'], $_REQUEST['plugin'] ) ||
274 - ! wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'activate-plugin_' . sanitize_text_field( wp_unslash( $_REQUEST['plugin'] ) ) )
275 - ) {
276 - die( '' );
277 - }
216 + // If we're in a multisite environment, run the plugin activation for each site when network enabling
217 + if ( is_multisite() && isset( $_GET['networkwide'] ) && $_GET['networkwide'] == 1 ) {
278 218
279 - // If we're in a multisite environment, run the plugin activation for each site when network enabling.
280 - if ( is_multisite() && isset( $_GET['networkwide'] ) && 1 === intval( $_GET['networkwide'] ) ) {
281 -
282 219 // Add super admins to the multisite approved list.
283 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
220 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() );
284 221 $should_update_auth_multisite_settings_access_users_approved = false;
285 222 foreach ( get_super_admins() as $super_admin ) {
286 223 $user = get_user_by( 'login', $super_admin );
287 224 // Add to approved list if not there.
@@ -286,10 +223,10 @@
286 223 $user = get_user_by( 'login', $super_admin );
287 224 // Add to approved list if not there.
288 225 if ( ! $this->in_multi_array( $user->user_email, $auth_multisite_settings_access_users_approved ) ) {
289 226 $approved_user = array(
290 - 'email' => $this->lowercase( $user->user_email ),
291 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
227 + 'email' => $user->user_email,
228 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
292 229 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
293 230 'local_user' => true,
294 231 );
295 232 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
@@ -296,14 +233,13 @@
296 233 $should_update_auth_multisite_settings_access_users_approved = true;
297 234 }
298 235 }
299 236 if ( $should_update_auth_multisite_settings_access_users_approved ) {
300 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
237 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
301 238 }
302 239
303 240 // Run plugin activation on each site in the network.
304 241 $current_blog_id = $wpdb->blogid;
305 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
306 242 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
307 243 foreach ( $sites as $site ) {
308 244 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
309 245 switch_to_blog( $blog_id );
@@ -332,13 +268,13 @@
332 268 * @return void
333 269 */
334 270 private function add_wp_users_to_approved_list() {
335 271 // Add current WordPress users to the approved list.
336 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
337 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
338 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
339 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
340 - $updated = false;
272 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
273 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
274 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
275 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
276 + $updated = false;
341 277 foreach ( get_users() as $user ) {
342 278 // Skip if user is in blocked list.
343 279 if ( $this->in_multi_array( $user->user_email, $auth_settings_access_users_blocked ) ) {
344 280 continue;
@@ -344,10 +280,10 @@
344 280 continue;
345 281 }
346 282 // Remove from pending list if there.
347 283 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
348 - if ( 0 === strcasecmp( $pending_user['email'], $user->user_email ) ) {
349 - unset( $auth_settings_access_users_pending[ $key ] );
284 + if ( $pending_user['email'] == $user->user_email ) {
285 + unset( $auth_settings_access_users_pending[$key] );
350 286 $updated = true;
351 287 }
352 288 }
353 289 // Skip if user is in multisite approved list.
@@ -356,10 +292,10 @@
356 292 }
357 293 // Add to approved list if not there.
358 294 if ( ! $this->in_multi_array( $user->user_email, $auth_settings_access_users_approved ) ) {
359 295 $approved_user = array(
360 - 'email' => $this->lowercase( $user->user_email ),
361 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
296 + 'email' => $user->user_email,
297 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '',
362 298 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
363 299 'local_user' => true,
364 300 );
365 301 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -394,14 +330,13 @@
394 330
395 331 /**
396 332 * Authenticate against an external service.
397 333 *
398 - * Filter: authenticate
399 - *
400 - * @param WP_User $user user to authenticate.
334 + * @param WP_User $user user to authenticate
401 335 * @param string $username optional username to authenticate.
402 336 * @param string $password optional password to authenticate.
403 - * @return WP_User|WP_Error WP_User on success, WP_Error on failure.
337 + *
338 + * @return WP_User or WP_Error
404 339 */
405 340 public function custom_authenticate( $user, $username, $password ) {
406 341 // Pass through if already authenticated.
407 342 if ( is_a( $user, 'WP_User' ) ) {
@@ -409,20 +344,20 @@
409 344 } else {
410 345 $user = null;
411 346 }
412 347
413 - // If username and password are blank, this isn't a log in attempt.
348 + // If username and password are blank, this isn't a log in attempt
414 349 $is_login_attempt = strlen( $username ) > 0 && strlen( $password ) > 0;
415 350
416 351 // Check to make sure that $username is not locked out due to too
417 352 // many invalid login attempts. If it is, tell the user how much
418 353 // time remains until they can try again.
419 - $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
354 + $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false;
420 355 $unauthenticated_user_is_blocked = false;
421 - if ( $is_login_attempt && false !== $unauthenticated_user ) {
356 + if ( $is_login_attempt && $unauthenticated_user !== false ) {
422 357 $last_attempt = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
423 358 $num_attempts = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
424 - // Also check the auth_blocked user_meta flag (users in blocked list will get this flag).
359 + // Also check the auth_blocked user_meta flag (users in blocked list will get this flag)
425 360 $unauthenticated_user_is_blocked = get_user_meta( $unauthenticated_user->ID, 'auth_blocked', true ) === 'yes';
426 361 } else {
427 362 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
428 363 $num_attempts = get_option( 'auth_settings_advanced_lockouts_failed_attempts' );
@@ -436,9 +371,9 @@
436 371 return new WP_Error( 'empty_password', __( '<strong>ERROR</strong>: Incorrect username or password.', 'authorizer' ) );
437 372 }
438 373
439 374 // Grab plugin settings.
440 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
375 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
441 376
442 377 // Make sure $last_attempt (time) and $num_attempts are positive integers.
443 378 // Note: this addresses resetting them if either is unset from above.
444 379 $last_attempt = abs( intval( $last_attempt ) );
@@ -444,17 +379,17 @@
444 379 $last_attempt = abs( intval( $last_attempt ) );
445 380 $num_attempts = abs( intval( $num_attempts ) );
446 381
447 382 // Create semantic lockout variables.
448 - $lockouts = $auth_settings['advanced_lockouts'];
449 - $time_since_last_fail = time() - $last_attempt;
450 - $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds.
451 - $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
452 - $num_attempts_short_lockout = $lockouts['attempts_1'];
453 - $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
383 + $lockouts = $auth_settings['advanced_lockouts'];
384 + $time_since_last_fail = time() - $last_attempt;
385 + $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds
386 + $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2'];
387 + $num_attempts_short_lockout = $lockouts['attempts_1'];
388 + $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail;
454 389 $seconds_remaining_short_lockout = $lockouts['duration_1'] * 60 - $time_since_last_fail;
455 390
456 - // Check if we need to institute a lockout delay.
391 + // Check if we need to institute a lockout delay
457 392 if ( $is_login_attempt && $time_since_last_fail > $reset_duration ) {
458 393 // Enough time has passed since the last invalid attempt and
459 394 // now that we can reset the failed attempt count, and let this
460 395 // login attempt go through.
@@ -467,9 +402,8 @@
467 402 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
468 403 return new WP_Error(
469 404 'empty_password',
470 405 sprintf(
471 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
472 406 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
473 407 $username,
474 408 $seconds_remaining_long_lockout,
475 409 $this->seconds_as_sentence( $seconds_remaining_long_lockout ),
@@ -484,9 +418,8 @@
484 418 remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
485 419 return new WP_Error(
486 420 'empty_password',
487 421 sprintf(
488 - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */
489 422 __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ),
490 423 $username,
491 424 $seconds_remaining_short_lockout,
492 425 $this->seconds_as_sentence( $seconds_remaining_short_lockout ),
@@ -496,16 +429,16 @@
496 429 }
497 430
498 431 // Start external authentication.
499 432 $externally_authenticated_emails = array();
500 - $authenticated_by = '';
501 - $result = null;
433 + $authenticated_by = '';
434 + $result = null;
502 435
503 436 // Try Google authentication if it's enabled and we don't have a
504 437 // successful login yet.
505 438 if (
506 - '1' === $auth_settings['google'] &&
507 - 0 === count( $externally_authenticated_emails ) &&
439 + $auth_settings['google'] === '1' &&
440 + count( $externally_authenticated_emails ) === 0 &&
508 441 ! is_wp_error( $result )
509 442 ) {
510 443 $result = $this->custom_authenticate_google( $auth_settings );
511 444 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -520,10 +453,10 @@
520 453
521 454 // Try CAS authentication if it's enabled and we don't have a
522 455 // successful login yet.
523 456 if (
524 - '1' === $auth_settings['cas'] &&
525 - 0 === count( $externally_authenticated_emails ) &&
457 + $auth_settings['cas'] === '1' &&
458 + count( $externally_authenticated_emails ) === 0 &&
526 459 ! is_wp_error( $result )
527 460 ) {
528 461 $result = $this->custom_authenticate_cas( $auth_settings );
529 462 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -538,10 +471,10 @@
538 471
539 472 // Try LDAP authentication if it's enabled and we don't have an
540 473 // authenticated user yet.
541 474 if (
542 - '1' === $auth_settings['ldap'] &&
543 - 0 === count( $externally_authenticated_emails ) &&
475 + $auth_settings['ldap'] === '1' &&
476 + count( $externally_authenticated_emails ) === 0 &&
544 477 ! is_wp_error( $result )
545 478 ) {
546 479 $result = $this->custom_authenticate_ldap( $auth_settings, $username, $password );
547 480 if ( ! is_null( $result ) && ! is_wp_error( $result ) ) {
@@ -562,33 +495,31 @@
562 495
563 496 // Remove duplicate and blank emails, if any.
564 497 $externally_authenticated_emails = array_filter( array_unique( $externally_authenticated_emails ) );
565 498
566 - /**
567 - * If we've made it this far, we should have an externally
568 - * authenticated user. The following should be set:
569 - * $externally_authenticated_emails
570 - * $authenticated_by
571 - */
499 + // If we've made it this far, we should have an externally
500 + // authenticated user. The following should be set:
501 + // $externally_authenticated_emails
502 + // $authenticated_by
572 503
573 504 // Get the external user's WordPress account by email address.
574 505 foreach ( $externally_authenticated_emails as $externally_authenticated_email ) {
575 - $user = get_user_by( 'email', $this->lowercase( $externally_authenticated_email ) );
506 + $user = get_user_by( 'email', $externally_authenticated_email );
576 507
577 508 // If we've already found a WordPress user associated with one
578 509 // of the supplied email addresses, don't keep examining other
579 510 // email addresses associated with the externally authenticated user.
580 - if ( false !== $user ) {
511 + if ( $user !== FALSE ) {
581 512 break;
582 513 }
583 514 }
584 515
585 516 // Check this external user's access against the access lists
586 - // (pending, approved, blocked).
517 + // (pending, approved, blocked)
587 518 $result = $this->check_user_access( $user, $externally_authenticated_emails, $result );
588 519
589 520 // Fail with message if there was an error creating/adding the user.
590 - if ( is_wp_error( $result ) || 0 === $result ) {
521 + if ( is_wp_error( $result ) || $result === 0 ) {
591 522 return $result;
592 523 }
593 524
594 525 // If we created a new user in check_user_access(), log that user in.
@@ -609,30 +540,27 @@
609 540 /**
610 541 * This function will fail with a wp_die() message to the user if they
611 542 * don't have access.
612 543 *
613 - * @param WP_User $user User to check.
614 - * @param array $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account).
615 - * @param array $user_data Array of keys for email, username, first_name, last_name,
616 - * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
617 - * @return WP_Error|void|null|WP_User
618 - * WP_Error if there was an error on user creation / adding user to blog.
619 - * wp_die() if user does not have access.
620 - * null if user has access (success).
621 - * WP_User if user has access and a new account was created for them.
544 + * @param WP_User $user User to check
545 + * @param [type] $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account)
546 + * @param [type] $user_data Array of keys for email, username, first_name, last_name,
547 + * authenticated_by, google_attributes, cas_attributes, ldap_attributes.
548 + * @return WP_Error if there was an error on user creation / adding user to blog
549 + * wp_die() if user does not have access
550 + * null if user has access (success)
551 + * WP_User if user has access and a new account was created for them
622 552 */
623 553 private function check_user_access( $user, $user_emails, $user_data = array() ) {
624 554 // Grab plugin settings.
625 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
626 - $auth_settings_access_users_pending = $this->sanitize_user_list(
627 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
555 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
556 + $auth_settings_access_users_pending = $this->sanitize_user_list(
557 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
628 558 );
629 - $auth_settings_access_users_approved_single = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
630 - $auth_settings_access_users_approved_multi = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
631 - $auth_settings_access_users_approved = $this->sanitize_user_list(
559 + $auth_settings_access_users_approved = $this->sanitize_user_list(
632 560 array_merge(
633 - $auth_settings_access_users_approved_single,
634 - $auth_settings_access_users_approved_multi
561 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
562 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
635 563 )
636 564 );
637 565
638 566 /**
@@ -638,31 +566,28 @@
638 566 /**
639 567 * Filter whether to block the currently logging in user based on any of
640 568 * their user attributes.
641 569 *
642 - * @param bool $allow_login Whether to block the currently logging in user.
570 + * @param bool $user_is_blocked Whether to block the currently logging in user.
643 571 * @param array $user_data User data returned from external service.
644 572 */
645 - $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
646 - $blocked_by_filter = ! $allow_login; // Use this for better readability.
573 + $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data );
647 574
648 575 // Check our externally authenticated user against the block list.
649 576 // If any of their email addresses are blocked, set the relevant user
650 577 // meta field, and show them an error screen.
651 578 foreach ( $user_emails as $user_email ) {
652 - if ( $blocked_by_filter || $this->is_email_in_list( $user_email, 'blocked' ) ) {
579 + if ( ! $allow_login || $this->is_email_in_list( $user_email, 'blocked' ) ) {
653 580
654 581 // Add user to blocked list if it was blocked via the filter.
655 - if ( $blocked_by_filter && ! $this->is_email_in_list( $user_email, 'blocked' ) ) {
582 + if ( ! $allow_login && ! $this->is_email_in_list( $user_email, 'blocked' ) ) {
656 583 $auth_settings_access_users_blocked = $this->sanitize_user_list(
657 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
584 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
658 585 );
659 - array_push(
660 - $auth_settings_access_users_blocked, array(
661 - 'email' => $this->lowercase( $user_email ),
662 - 'date_added' => date( 'M Y' ),
663 - )
664 - );
586 + array_push( $auth_settings_access_users_blocked, array(
587 + 'email' => $user_email,
588 + 'date_added' => date( 'M Y' ),
589 + ));
665 590 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
666 591 }
667 592
668 593 // If the blocked external user has a WordPress account, mark it as
@@ -671,11 +596,10 @@
671 596 update_user_meta( $user->ID, 'auth_blocked', 'yes' );
672 597 }
673 598
674 599 // Notify user about blocked status and return without authenticating them.
675 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
676 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
677 - $page_title = sprintf(
600 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
601 + $page_title = sprintf(
678 602 /* TRANSLATORS: %s: Name of blog */
679 603 __( '%s - Access Restricted', 'authorizer' ),
680 604 get_bloginfo( 'name' )
681 605 );
@@ -686,14 +610,13 @@
686 610 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
687 611 __( 'Back', 'authorizer' ) .
688 612 '</a></p>';
689 613 update_option( 'auth_settings_advanced_login_error', $error_message );
690 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
614 + wp_die( $error_message, $page_title );
691 615 }
692 616 }
693 617
694 - // Get the default role for this user (or their current role, if they
695 - // already have an account).
618 + // Get the default role for this new user.
696 619 $default_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $auth_settings['access_default_role'];
697 620 /**
698 621 * Filter the role of the user currently logging in. The role will be
699 622 * set to the default (specified in Authorizer options) for new users,
@@ -698,24 +621,13 @@
698 621 * Filter the role of the user currently logging in. The role will be
699 622 * set to the default (specified in Authorizer options) for new users,
700 623 * or the user's current role for existing users. This filter allows
701 624 * changing user roles based on custom CAS/LDAP attributes.
702 - *
703 625 * @param bool $role Role of the user currently logging in.
704 626 * @param array $user_data User data returned from external service.
705 627 */
706 628 $approved_role = apply_filters( 'authorizer_custom_role', $default_role, $user_data );
707 629
708 - /**
709 - * Filter whether to automatically approve the currently logging in user
710 - * based on any of their user attributes.
711 - *
712 - * @param bool $automatically_approve_login
713 - * Whether to automatically approve the currently logging in user.
714 - * @param array $user_data User data returned from external service.
715 - */
716 - $automatically_approve_login = apply_filters( 'authorizer_automatically_approve_login', false, $user_data );
717 -
718 630 // Iterate through each of the email addresses provided by the external
719 631 // service and determine if any of them have access.
720 632 $last_email = end( $user_emails );
721 633 reset( $user_emails );
@@ -729,16 +641,12 @@
729 641 return;
730 642 }
731 643
732 644 // If this externally authenticated user isn't in the approved list
733 - // and login access is set to "All authenticated users," or if they were
734 - // automatically approved in the "authorizer_approve_login" filter
735 - // above, then add them to the approved list (they'll get an account
736 - // created below if they don't have one yet).
737 - if (
738 - ! $this->is_email_in_list( $user_email, 'approved' ) &&
739 - ( 'external_users' === $auth_settings['access_who_can_login'] || $automatically_approve_login )
740 - ) {
645 + // and login access is set to "All authenticated users," add them
646 + // to the approved list (they'll get an account created below if
647 + // they don't have one yet).
648 + if ( ! $this->is_email_in_list( $user_email, 'approved' ) && $auth_settings['access_who_can_login'] === 'external_users' ) {
741 649 $is_newly_approved_user = true;
742 650
743 651 // If this user happens to be in the pending list (rare),
744 652 // remove them from pending before adding them to approved.
@@ -743,9 +651,9 @@
743 651 // If this user happens to be in the pending list (rare),
744 652 // remove them from pending before adding them to approved.
745 653 if ( $this->is_email_in_list( $user_email, 'pending' ) ) {
746 654 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
747 - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
655 + if ( $pending_user['email'] === $user_email ) {
748 656 unset( $auth_settings_access_users_pending[ $key ] );
749 657 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
750 658 break;
751 659 }
@@ -753,15 +661,14 @@
753 661 }
754 662
755 663 // Add this user to the approved list.
756 664 $approved_user = array(
757 - 'email' => $this->lowercase( $user_email ),
758 - 'role' => $approved_role,
759 - 'date_added' => date( 'Y-m-d H:i:s' ),
665 + 'email' => $user_email,
666 + 'role' => $approved_role,
667 + 'date_added' => date( "Y-m-d H:i:s" ),
760 668 );
761 669 array_push( $auth_settings_access_users_approved, $approved_user );
762 - array_push( $auth_settings_access_users_approved_single, $approved_user );
763 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
670 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
764 671 }
765 672
766 673 // Check our externally authenticated user against the approved
767 674 // list. If they are approved, log them in (and create their account
@@ -775,9 +682,9 @@
775 682 if ( $default_role !== $approved_role ) {
776 683 $user_info['role'] = $approved_role;
777 684 }
778 685
779 - // If the approved external user does not have a WordPress account, create it.
686 + // If the approved external user does not have a WordPress account, create it
780 687 if ( ! $user ) {
781 688 // If there's already a user with this username (e.g.,
782 689 // johndoe/johndoe@gmail.com exists, and we're trying to add
783 690 // johndoe/johndoe@example.com), use the full email address
@@ -792,47 +699,26 @@
792 699 $username = $user_info['email'];
793 700 }
794 701 $result = wp_insert_user(
795 702 array(
796 - 'user_login' => strtolower( $username ),
797 - 'user_pass' => wp_generate_password(), // random password.
798 - 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
799 - 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
800 - 'user_email' => $this->lowercase( $user_info['email'] ),
703 + 'user_login' => strtolower( $username ),
704 + 'user_pass' => wp_generate_password(), // random password
705 + 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '',
706 + 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '',
707 + 'user_email' => strtolower( $user_info['email'] ),
801 708 'user_registered' => date( 'Y-m-d H:i:s' ),
802 - 'role' => $user_info['role'],
709 + 'role' => $user_info['role'],
803 710 )
804 711 );
805 712
806 713 // Fail with message if error.
807 - if ( is_wp_error( $result ) || 0 === $result ) {
714 + if ( is_wp_error( $result ) || $result === 0 ) {
808 715 return $result;
809 716 }
810 717
811 - // Authenticate as new user.
718 + // Authenticate as new user
812 719 $user = new WP_User( $result );
813 720
814 - /**
815 - * Fires after an external user is authenticated for the first time
816 - * and a new WordPress account is created for them.
817 - *
818 - * @since 2.8.0
819 - *
820 - * @param WP_User $user User object.
821 - * @param array $user_data User data from external service.
822 - *
823 - * Example $user_data:
824 - * array(
825 - * 'email' => 'user@example.edu',
826 - * 'username' => 'user',
827 - * 'first_name' => 'First',
828 - * 'last_name' => 'Last',
829 - * 'authenticated_by' => 'cas',
830 - * 'cas_attributes' => array( ... ),
831 - * );
832 - */
833 - do_action( 'authorizer_user_register', $user, $user_data );
834 -
835 721 // If multisite, iterate through all sites in the network and add the user
836 722 // currently logging in to any of them that have the user on the approved list.
837 723 // Note: this is useful for first-time logins--some users will have access
838 724 // to multiple sites, and this prevents them from having to log into each
@@ -838,21 +724,18 @@
838 724 // to multiple sites, and this prevents them from having to log into each
839 725 // site individually to get access.
840 726 if ( is_multisite() ) {
841 727 $site_ids_of_user = array_map(
842 - function ( $site_of_user ) {
843 - return intval( $site_of_user->userblog_id );
844 - },
728 + function ( $site_of_user ) { return $site_of_user->userblog_id; },
845 729 get_blogs_of_user( $user->ID )
846 730 );
847 731
848 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
849 732 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
850 733 foreach ( $sites as $site ) {
851 734 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
852 735
853 736 // Skip if user is already added to this site.
854 - if ( in_array( intval( $blog_id ), $site_ids_of_user, true ) ) {
737 + if ( in_array( $blog_id, $site_ids_of_user ) ) {
855 738 continue;
856 739 }
857 740
858 741 // Check if user is on the approved list of this site they are not added to.
@@ -878,9 +761,9 @@
878 761 if ( $meta_key === $user_info['usermeta']['meta_key'] ) {
879 762 // Update user's usermeta value for usermeta key stored in authorizer options.
880 763 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
881 764 // We have an ACF field value, so use the ACF function to update it.
882 - update_field( str_replace( 'acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
765 + update_field( str_replace('acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID );
883 766 } else {
884 767 // We have a normal usermeta value, so just update it via the WordPress function.
885 768 update_user_meta( $user->ID, $meta_key, $user_info['usermeta']['meta_value'] );
886 769 }
@@ -896,9 +779,9 @@
896 779 switch_to_blog( $blog_id );
897 780 // Update user's usermeta value for usermeta key stored in authorizer options.
898 781 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
899 782 // We have an ACF field value, so use the ACF function to update it.
900 - update_field( str_replace( 'acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
783 + update_field( str_replace('acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID );
901 784 } else {
902 785 // We have a normal usermeta value, so just update it via the WordPress function.
903 786 update_user_meta( $user->ID, $meta_key, $usermeta['meta_value'] );
904 787 }
@@ -909,24 +792,20 @@
909 792 }
910 793 } else {
911 794 // Update first/last names of WordPress user from external
912 795 // service if that option is set.
913 - if ( ( array_key_exists( 'authenticated_by', $user_data ) && 'cas' === $user_data['authenticated_by'] && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['cas_attr_update_on_login'] ) ) || ( array_key_exists( 'authenticated_by', $user_data ) && 'ldap' === $user_data['authenticated_by'] && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['ldap_attr_update_on_login'] ) ) ) {
914 - if ( array_key_exists( 'first_name', $user_data ) && 0 < strlen( $user_data['first_name'] ) ) {
915 - wp_update_user(
916 - array(
917 - 'ID' => $user->ID,
918 - 'first_name' => $user_data['first_name'],
919 - )
920 - );
796 + if ( ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'cas' && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && $auth_settings['cas_attr_update_on_login'] == 1 ) || ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'ldap' && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && $auth_settings['ldap_attr_update_on_login'] == 1 ) ) {
797 + if ( array_key_exists( 'first_name', $user_data ) && strlen( $user_data['first_name'] ) > 0 ) {
798 + wp_update_user( array(
799 + 'ID' => $user->ID,
800 + 'first_name' => $user_data['first_name'],
801 + ));
921 802 }
922 803 if ( array_key_exists( 'last_name', $user_data ) && strlen( $user_data['last_name'] ) > 0 ) {
923 - wp_update_user(
924 - array(
925 - 'ID' => $user->ID,
926 - 'last_name' => $user_data['last_name'],
927 - )
928 - );
804 + wp_update_user( array(
805 + 'ID' => $user->ID,
806 + 'last_name' => $user_data['last_name'],
807 + ));
929 808 }
930 809 }
931 810
932 811 // Update this user's role if it was modified in the
@@ -931,19 +810,12 @@
931 810
932 811 // Update this user's role if it was modified in the
933 812 // authorizer_custom_role filter.
934 813 if ( $default_role !== $approved_role ) {
935 - // Update user's role in WordPress.
936 - $user->set_role( $approved_role );
937 -
938 - // Update user's role in this site's approved list and save.
939 - foreach ( $auth_settings_access_users_approved_single as $key => $existing_user ) {
940 - if ( 0 === strcasecmp( $user->user_email, $existing_user['email'] ) ) {
941 - $auth_settings_access_users_approved_single[ $key ]['role'] = $approved_role;
942 - break;
943 - }
944 - }
945 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single );
814 + wp_update_user( array(
815 + 'ID' => $user->ID,
816 + 'role' => $approved_role,
817 + ));
946 818 }
947 819 }
948 820
949 821 // If this is multisite, add new user to current blog.
@@ -956,34 +828,33 @@
956 828 }
957 829 }
958 830
959 831 // Ensure user has the same role as their entry in the approved list.
960 - if ( $user_info && ! in_array( $user_info['role'], $user->roles, true ) ) {
832 + // (This is just a precaution, the role should already be set when
833 + // saving admin options in the sanitizing function.)
834 + if ( $user_info && ! array_key_exists( $user_info['role'], $user->roles ) ) {
961 835 $user->set_role( $user_info['role'] );
962 836 }
963 837
964 838 return $user;
965 839
966 - } elseif ( 0 === strcasecmp( $user_email, $last_email ) ) {
967 - /**
968 - * Note: only do this for the last email address we are checking (we need
969 - * to iterate through them all to make sure one of them isn't approved).
970 - */
971 -
840 + // Note: only do this for the last email address we are checking (we need
841 + // to iterate through them all to make sure one of them isn't approved).
842 + } elseif ( $user_email === $last_email ) {
972 843 // User isn't an admin, is not blocked, and is not approved.
973 844 // Add them to the pending list and notify them and their instructor.
974 845 if ( strlen( $user_email ) > 0 && ! $this->is_email_in_list( $user_email, 'pending' ) ) {
975 - $pending_user = array();
976 - $pending_user['email'] = $this->lowercase( $user_email );
977 - $pending_user['role'] = $approved_role;
846 + $pending_user = array();
847 + $pending_user['email'] = $user_email;
848 + $pending_user['role'] = $approved_role;
978 849 $pending_user['date_added'] = '';
979 850 array_push( $auth_settings_access_users_pending, $pending_user );
980 851 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
981 852
982 853 // Create strings used in the email notification.
983 - $site_name = get_bloginfo( 'name' );
984 - $site_url = get_bloginfo( 'url' );
985 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
854 + $site_name = get_bloginfo( 'name' );
855 + $site_url = get_bloginfo( 'url' );
856 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
986 857
987 858 // Notify users with the role specified in "Which role should
988 859 // receive email notifications about pending users?".
989 860 if ( strlen( $auth_settings['access_role_receive_pending_emails'] ) > 0 ) {
@@ -1008,11 +879,10 @@
1008 879 }
1009 880 }
1010 881
1011 882 // Notify user about pending status and return without authenticating them.
1012 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1013 - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url();
1014 - $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
883 + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url();
884 + $page_title = get_bloginfo( 'name' ) . ' - Access Pending';
1015 885 $error_message =
1016 886 apply_filters( 'the_content', $auth_settings['access_pending_redirect_to_message'] ) .
1017 887 '<hr />' .
1018 888 '<p style="text-align: center;">' .
@@ -1019,9 +889,9 @@
1019 889 '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' .
1020 890 __( 'Back', 'authorizer' ) .
1021 891 '</a></p>';
1022 892 update_option( 'auth_settings_advanced_login_error', $error_message );
1023 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
893 + wp_die( $error_message, $page_title );
1024 894 }
1025 895 }
1026 896
1027 897 // Sanity check: if we made it here without returning, something has gone wrong.
@@ -1044,34 +914,24 @@
1044 914 * custom_authenticate_google() runs to verify the token; once verified
1045 915 * custom_authenticate proceeds as normal with the google email address
1046 916 * as a successfully authenticated external user.
1047 917 *
1048 - * Action: wp_ajax_process_google_login
1049 - * Action: wp_ajax_nopriv_process_google_login
1050 - *
1051 - * @return void, but die with the value to return to the success() function in AJAX call signInCallback().
918 + * @return void, but die with the value to return to the success() function in AJAX call signInCallback()
1052 919 */
1053 - public function ajax_process_google_login() {
920 + function ajax_process_google_login() {
921 + $nonce = array_key_exists( 'nonce', $_POST ) ? $_POST['nonce'] : '';
922 + $code = array_key_exists( 'code', $_POST ) ? $_POST['code'] : null;
923 +
1054 924 // Nonce check.
1055 - if (
1056 - ! isset( $_POST['nonce'] ) ||
1057 - ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'google_csrf_nonce' )
1058 - ) {
1059 - die( '' );
925 + if ( ! wp_verify_nonce( $nonce, 'google_csrf_nonce' ) ) {
926 + return '';
1060 927 }
1061 928
1062 - // Google authentication token.
1063 - // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput.InputNotSanitized
1064 - $code = isset( $_POST['code'] ) ? wp_unslash( $_POST['code'] ) : null;
1065 -
1066 929 // Grab plugin settings.
1067 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
930 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1068 931
1069 - /**
1070 - * Add Google API PHP Client.
1071 - *
1072 - * @see https://github.com/google/google-api-php-client branch:v1-master
1073 - */
932 + // Add Google API PHP Client.
933 + // @see https://github.com/google/google-api-php-client branch:v1-master
1074 934 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1075 935
1076 936 // Build the Google Client.
1077 937 $client = new Google_Client();
@@ -1079,26 +939,14 @@
1079 939 $client->setClientId( $auth_settings['google_clientid'] );
1080 940 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1081 941 $client->setRedirectUri( 'postmessage' );
1082 942
1083 - /**
1084 - * If the hosted domain parameter is set, restrict logins to that domain.
1085 - *
1086 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1087 - * this to function server-side; it's not complete in v1, so this check
1088 - * is performed manually below.
1089 - *
1090 - * if (
1091 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1092 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1093 - * ) {
1094 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1095 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1096 - * $client->setHostedDomain( $google_hosteddomain );
1097 - * }
1098 - */
943 + // If the hosted domain parameter is set, restrict logins to that domain.
944 + if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
945 + $client->setHostedDomain( $auth_settings['google_hosteddomain'] );
946 + }
1099 947
1100 - // Get one time use token (if it doesn't exist, we'll create one below).
948 + // Get one time use token (if it doesn't exist, we'll create one below)
1101 949 session_start();
1102 950 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1103 951
1104 952 if ( empty( $token ) ) {
@@ -1106,18 +954,18 @@
1106 954 $client->authenticate( $code );
1107 955 $token = json_decode( $client->getAccessToken() );
1108 956
1109 957 // Store the token in the session for later use.
1110 - $_SESSION['token'] = wp_json_encode( $token );
958 + $_SESSION['token'] = json_encode( $token );
1111 959
1112 - $response = 'Successfully authenticated.';
960 + $response = "Successfully authenticated.";
1113 961 } else {
1114 - $client->setAccessToken( wp_json_encode( $token ) );
962 + $client->setAccessToken( json_encode( $token ) );
1115 963
1116 964 $response = 'Already authenticated.';
1117 965 }
1118 966
1119 - die( esc_html( $response ) );
967 + die( $response );
1120 968 }
1121 969
1122 970
1123 971 /**
@@ -1122,22 +970,22 @@
1122 970
1123 971 /**
1124 972 * Validate this user's credentials against Google.
1125 973 *
1126 - * @param array $auth_settings Plugin settings.
1127 - * @return array|WP_Error Array containing email, authenticated_by, first_name,
1128 - * last_name, and username strings for the successfully
1129 - * authenticated user, or WP_Error() object on failure,
1130 - * or null if not attempting a google login.
974 + * @param array $auth_settings Plugin settings
975 + * @return [mixed] Array containing email, authenticated_by,
976 + * first_name, last_name, and username
977 + * strings for the successfully authenticated
978 + * user, or WP_Error() object on failure,
979 + * or null if not attempting a google login.
1131 980 */
1132 981 private function custom_authenticate_google( $auth_settings ) {
1133 982 // Move on if Google auth hasn't been requested here.
1134 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1135 - if ( empty( $_GET['external'] ) || 'google' !== $_GET['external'] ) {
983 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'google' ) {
1136 984 return null;
1137 985 }
1138 986
1139 - // Get one time use token.
987 + // Get one time use token
1140 988 session_start();
1141 989 $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null;
1142 990
1143 991 // No token, so this is not a succesful Google login.
@@ -1144,13 +992,10 @@
1144 992 if ( is_null( $token ) ) {
1145 993 return null;
1146 994 }
1147 995
1148 - /**
1149 - * Add Google API PHP Client.
1150 - *
1151 - * @see https://github.com/google/google-api-php-client branch:v1-master
1152 - */
996 + // Add Google API PHP Client.
997 + // @see https://github.com/google/google-api-php-client branch:v1-master
1153 998 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1154 999
1155 1000 // Build the Google Client.
1156 1001 $client = new Google_Client();
@@ -1158,24 +1003,14 @@
1158 1003 $client->setClientId( $auth_settings['google_clientid'] );
1159 1004 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1160 1005 $client->setRedirectUri( 'postmessage' );
1161 1006
1162 - /**
1163 - * If the hosted domain parameter is set, restrict logins to that domain.
1164 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1165 - * this to function server-side; it's not complete in v1, so this check
1166 - * is performed manually later.
1167 - * if (
1168 - * array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1169 - * strlen( $auth_settings['google_hosteddomain'] ) > 0
1170 - * ) {
1171 - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1172 - * $google_hosteddomain = trim( $google_hosteddomains[0] );
1173 - * $client->setHostedDomain( $google_hosteddomain );
1174 - * }
1175 - */
1007 + // If the hosted domain parameter is set, restrict logins to that domain.
1008 + if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1009 + $client->setHostedDomain( $auth_settings['google_hosteddomain'] );
1010 + }
1176 1011
1177 - // Verify this is a successful Google authentication.
1012 + // Verify this is a successful Google authentication
1178 1013 try {
1179 1014 $ticket = $client->verifyIdToken( $token->id_token, $auth_settings['google_clientid'] );
1180 1015 } catch ( Google_Auth_Exception $e ) {
1181 1016 // Invalid ticket, so this in not a successful Google login.
@@ -1186,40 +1021,37 @@
1186 1021 if ( ! $ticket ) {
1187 1022 return new WP_Error( 'invalid_google_login', __( 'Invalid Google credentials provided.', 'authorizer' ) );
1188 1023 }
1189 1024
1190 - // Get email address.
1191 - $attributes = $ticket->getAttributes();
1192 - $email = $this->lowercase( $attributes['payload']['email'] );
1025 + // Get email address
1026 + $attributes = $ticket->getAttributes();
1027 + $email = $attributes['payload']['email'];
1193 1028 $email_domain = substr( strrchr( $email, '@' ), 1 );
1194 - $username = current( explode( '@', $email ) );
1029 + $username = current( explode( '@', $email ) );
1195 1030
1196 - /**
1197 - * Fail if hd param is set and the logging in user's email address doesn't
1198 - * match the allowed hosted domain.
1199 - *
1200 - * See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1201 - * See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1202 - *
1203 - * Note: Will have to upgrade to google-api-php-client v2 or higher for
1204 - * this to function server-side; it's not complete in v1, so this check
1205 - * is only performed here.
1206 - */
1207 - if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1208 - // Allow multiple whitelisted domains.
1209 - $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) );
1210 - if ( ! in_array( $email_domain, $google_hosteddomains, true ) ) {
1211 - $this->custom_logout();
1212 - return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) );
1213 - }
1031 + // Fail if hd param is set and the logging in user's email address doesn't
1032 + // match the allowed hosted domain.
1033 + // See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param
1034 + // See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416
1035 + // Note: Will have to upgrade to google-api-php-client v2 or higher for
1036 + // this to function server-side; it's not complete in v1, so this check
1037 + // is only performed here.
1038 + if (
1039 + array_key_exists( 'google_hosteddomain', $auth_settings ) &&
1040 + strlen( $auth_settings['google_hosteddomain'] ) > 0 &&
1041 + $email_domain !== $auth_settings['google_hosteddomain']
1042 + ) {
1043 + $this->custom_logout();
1044 + return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) . ' (' . $auth_settings['google_hosteddomain'] . ').' );
1214 1045 }
1215 1046
1047 +
1216 1048 return array(
1217 - 'email' => $email,
1218 - 'username' => $username,
1219 - 'first_name' => '',
1220 - 'last_name' => '',
1221 - 'authenticated_by' => 'google',
1049 + 'email' => $email,
1050 + 'username' => $username,
1051 + 'first_name' => '',
1052 + 'last_name' => '',
1053 + 'authenticated_by' => 'google',
1222 1054 'google_attributes' => $attributes,
1223 1055 );
1224 1056 }
1225 1057
@@ -1226,47 +1058,40 @@
1226 1058
1227 1059 /**
1228 1060 * Validate this user's credentials against CAS.
1229 1061 *
1230 - * @param array $auth_settings Plugin settings.
1231 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1232 - * for the successfully authenticated user, or WP_Error()
1233 - * object on failure, or null if not attempting a CAS login.
1062 + * @param array $auth_settings Plugin settings
1063 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1064 + * strings for the successfully authenticated
1065 + * user, or WP_Error() object on failure,
1066 + * or null if not attempting a CAS login.
1234 1067 */
1235 1068 private function custom_authenticate_cas( $auth_settings ) {
1236 1069 // Move on if CAS hasn't been requested here.
1237 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1238 - if ( empty( $_GET['external'] ) || 'cas' !== $_GET['external'] ) {
1070 + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'cas' ) {
1239 1071 return null;
1240 1072 }
1241 1073
1242 - /**
1243 - * Get the CAS server version (default to SAML_VERSION_1_1).
1244 - *
1245 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1246 - */
1074 + // Get the CAS server version (default to SAML_VERSION_1_1).
1075 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1247 1076 $cas_version = SAML_VERSION_1_1;
1248 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1077 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1249 1078 $cas_version = CAS_VERSION_3_0;
1250 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1079 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1251 1080 $cas_version = CAS_VERSION_2_0;
1252 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1081 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1253 1082 $cas_version = CAS_VERSION_1_0;
1254 1083 }
1255 1084
1256 - // Set the CAS client configuration.
1085 + // Set the CAS client configuration
1257 1086 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1258 1087
1259 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1260 - // at an old CAS URL that redirects to a newer CAS URL).
1261 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1262 -
1263 1088 // Update server certificate bundle if it doesn't exist or is older
1264 1089 // than 6 months, then use it to ensure CAS server is legitimate.
1265 1090 // Note: only try to update if the system has the php_openssl extension.
1266 - $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1267 - $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1268 - $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds.
1091 + $cacert_url = 'https://curl.haxx.se/ca/cacert.pem';
1092 + $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem';
1093 + $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds
1269 1094 $time_180_days_ago = time() - $time_180_days;
1270 1095 if (
1271 1096 extension_loaded( 'openssl' ) &&
1272 1097 ( ! file_exists( $cacert_path ) || filemtime( $cacert_path ) < $time_180_days_ago )
@@ -1282,39 +1107,29 @@
1282 1107 }
1283 1108 $cacert_contents = $response['body'];
1284 1109
1285 1110 // Write out the updated certs to the plugin directory.
1286 - // Note: Don't use WP_Filesystem because we are not in an admin context
1287 - // and don't want to potentially prompt the end user for credentials.
1288 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_read_file_put_contents
1289 1111 file_put_contents( $cacert_path, $cacert_contents );
1290 1112 }
1291 1113 phpCAS::setCasServerCACert( $cacert_path );
1292 1114
1293 - // Set the CAS service URL (including the redirect URL for WordPress when it comes back from CAS).
1294 - $cas_service_url = site_url( '/wp-login.php?external=cas' );
1295 - $login_querystring = array();
1296 - if ( isset( $_SERVER['QUERY_STRING'] ) ) {
1297 - parse_str( wp_parse_url( esc_url_raw( wp_unslash( $_SERVER['QUERY_STRING'] ) ), PHP_URL_HOST ), $login_querystring );
1298 - }
1299 - if ( isset( $login_querystring['redirect_to'] ) ) {
1300 - $cas_service_url .= '&redirect_to=' . rawurlencode( $login_querystring['redirect_to'] );
1301 - }
1302 - phpCAS::setFixedServiceURL( $cas_service_url );
1303 -
1304 - // Authenticate against CAS.
1115 + // Authenticate against CAS
1305 1116 try {
1306 1117 phpCAS::forceAuthentication();
1307 1118 } catch ( CAS_AuthenticationException $e ) {
1308 1119 // CAS server threw an error in isAuthenticated(), potentially because
1309 1120 // the cached ticket is outdated. Try renewing the authentication.
1310 - error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) ); // phpcs:ignore
1311 - error_log( print_r( $e, true ) ); // phpcs:ignore
1121 + try {
1122 + phpCAS::renewAuthentication();
1123 + } catch ( CAS_AuthenticationException $e ) {
1124 + error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) );
1125 + error_log( print_r( $e, true ) );
1312 1126
1313 - // CAS server is throwing errors on this login, so try logging the
1314 - // user out of CAS and redirecting them to the login page.
1315 - phpCAS::logoutWithRedirectService( wp_login_url() );
1316 - die();
1127 + // CAS server is throwing errors on this login, so try logging the
1128 + // user out of CAS and redirecting them to the login page.
1129 + phpCAS::logoutWithRedirectService( wp_login_url() );
1130 + die();
1131 + }
1317 1132 }
1318 1133
1319 1134 // Get username (as specified by the CAS server).
1320 1135 $username = phpCAS::getUser();
@@ -1324,10 +1139,10 @@
1324 1139 if ( ! filter_var( $externally_authenticated_email, FILTER_VALIDATE_EMAIL ) ) {
1325 1140 // If we can't get the user's email address from a CAS attribute,
1326 1141 // try to guess the domain from the CAS server hostname. This will only
1327 1142 // be used if we can't discover the email address from CAS attributes.
1328 - $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1329 - $externally_authenticated_email = $this->lowercase( $username ) . '@' . $domain_guess;
1143 + $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : '';
1144 + $externally_authenticated_email = strtolower( $username ) . '@' . $domain_guess;
1330 1145 }
1331 1146
1332 1147 // Retrieve the user attributes (e.g., email address, first name, last name) from the CAS server.
1333 1148 $cas_attributes = phpCAS::getAttributes();
@@ -1338,45 +1153,37 @@
1338 1153 // email domain is manually entered there (instead of a reference to a
1339 1154 // CAS attribute), and combine that with the username to create the email.
1340 1155 // Otherwise, look up the CAS attribute for email.
1341 1156 if ( substr( $auth_settings['cas_attr_email'], 0, 1 ) === '@' ) {
1342 - $externally_authenticated_email = $this->lowercase( $username . $auth_settings['cas_attr_email'] );
1157 + $externally_authenticated_email = strtolower( $username . $auth_settings['cas_attr_email'] );
1343 1158 } elseif (
1344 1159 // If a CAS attribute has been specified as containing the email address, use that instead.
1345 1160 // Email attribute can be a string or an array of strings.
1346 1161 array_key_exists( $auth_settings['cas_attr_email'], $cas_attributes ) && (
1347 1162 (
1348 - is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1349 - count( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1163 + is_array( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1164 + count( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1350 1165 ) || (
1351 - is_string( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) &&
1352 - strlen( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0
1166 + is_string( $cas_attributes[$auth_settings['cas_attr_email']] ) &&
1167 + strlen( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0
1353 1168 )
1354 1169 )
1355 1170 ) {
1356 - // Each of the emails in the array needs to be set to lowercase.
1357 - if ( is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) ) {
1358 - $externally_authenticated_email = array();
1359 - foreach ( $cas_attributes[ $auth_settings['cas_attr_email'] ] as $external_email ) {
1360 - $externally_authenticated_email[] = $this->lowercase( $external_email );
1361 - }
1362 - } else {
1363 - $externally_authenticated_email = $this->lowercase( $cas_attributes[ $auth_settings['cas_attr_email'] ] );
1364 - }
1171 + $externally_authenticated_email = $cas_attributes[$auth_settings['cas_attr_email']];
1365 1172 }
1366 1173 }
1367 1174
1368 1175 // Get user first name and last name.
1369 - $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_first_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_first_name'] ] : '';
1370 - $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_last_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_last_name'] ] : '';
1176 + $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_first_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_first_name']] : '';
1177 + $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_last_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_last_name']] : '';
1371 1178
1372 1179 return array(
1373 - 'email' => $externally_authenticated_email,
1374 - 'username' => $username,
1375 - 'first_name' => $first_name,
1376 - 'last_name' => $last_name,
1180 + 'email' => $externally_authenticated_email,
1181 + 'username' => $username,
1182 + 'first_name' => $first_name,
1183 + 'last_name' => $last_name,
1377 1184 'authenticated_by' => 'cas',
1378 - 'cas_attributes' => $cas_attributes,
1185 + 'cas_attributes' => $cas_attributes,
1379 1186 );
1380 1187 }
1381 1188
1382 1189
@@ -1382,32 +1189,24 @@
1382 1189
1383 1190 /**
1384 1191 * Validate this user's credentials against LDAP.
1385 1192 *
1386 - * @param array $auth_settings Plugin settings.
1387 - * @param string $username Attempted username from authenticate action.
1388 - * @param string $password Attempted password from authenticate action.
1389 - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings
1390 - * for the successfully authenticated user, or WP_Error()
1391 - * object on failure, or null if skipping LDAP auth and
1392 - * falling back to WP auth.
1193 + * @param array $auth_settings Plugin settings
1194 + * @param string $username Attempted username from authenticate action
1195 + * @param string $password Attempted password from authenticate action
1196 + * @return [mixed] Array containing 'email' and 'authenticated_by'
1197 + * strings for the successfully authenticated
1198 + * user, or WP_Error() object on failure,
1199 + * or null if skipping LDAP auth and falling back to WP auth.
1393 1200 */
1394 1201 private function custom_authenticate_ldap( $auth_settings, $username, $password ) {
1395 - // Get LDAP search base(s).
1396 - $search_bases = explode( "\n", str_replace( "\r", '', trim( $auth_settings['ldap_search_base'] ) ) );
1397 -
1398 - // Fail silently (fall back to WordPress authentication) if no search base specified.
1399 - if ( count( $search_bases ) < 1 ) {
1400 - return null;
1401 - }
1402 -
1403 - // Get the FQDN from the first LDAP search base domain components (dc). For
1404 - // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk.
1405 - $search_base_components = explode( ',', trim( $search_bases[0] ) );
1406 - $domain = array();
1202 + // Get the FQDN from the LDAP search base domain components (dc). For
1203 + // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk
1204 + $search_base_components = explode( ',', trim( $auth_settings['ldap_search_base'] ) );
1205 + $domain = array();
1407 1206 foreach ( $search_base_components as $search_base_component ) {
1408 1207 $component = explode( '=', $search_base_component );
1409 - if ( 2 === count( $component ) && 'dc' === $component[0] ) {
1208 + if ( count( $component ) === 2 && $component[0] === 'dc' ) {
1410 1209 $domain[] = $component[1];
1411 1210 }
1412 1211 }
1413 1212 $domain = implode( '.', $domain );
@@ -1418,9 +1217,9 @@
1418 1217 if ( empty( $domain ) ) {
1419 1218 $domain = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['ldap_host'], $matches ) === 1 ? $matches[0] : '';
1420 1219 }
1421 1220
1422 - // remove @domain if it exists in the username (i.e., if user entered their email).
1221 + // remove @domain if it exists in the username (i.e., if user entered their email)
1423 1222 $username = str_replace( '@' . $domain, '', $username );
1424 1223
1425 1224 // Fail silently (fall back to WordPress authentication) if both username
1426 1225 // and password are empty (this will be the case when visiting wp-login.php
@@ -1443,13 +1242,13 @@
1443 1242 return null;
1444 1243 }
1445 1244
1446 1245 // Authenticate against LDAP using options provided in plugin settings.
1447 - $result = false;
1246 + $result = false;
1448 1247 $ldap_user_dn = '';
1449 - $first_name = '';
1450 - $last_name = '';
1451 - $email = '';
1248 + $first_name = '';
1249 + $last_name = '';
1250 + $email = '';
1452 1251
1453 1252 // Construct LDAP connection parameters. ldap_connect() takes either a
1454 1253 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1455 1254 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
@@ -1454,13 +1253,13 @@
1454 1253 // hostname or a full LDAP URI as its first parameter (works with OpenLDAP
1455 1254 // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is
1456 1255 // ignored, and port must be specified in the full URI. An LDAP URI is of
1457 1256 // the form ldap://hostname:port or ldaps://hostname:port.
1458 - $ldap_host = $auth_settings['ldap_host'];
1459 - $ldap_port = intval( $auth_settings['ldap_port'] );
1460 - $parsed_host = wp_parse_url( $ldap_host );
1257 + $ldap_host = $auth_settings['ldap_host'];
1258 + $ldap_port = intval( $auth_settings['ldap_port'] );
1259 + $parsed_host = parse_url( $ldap_host );
1461 1260 // Fail (fall back to WordPress auth) if invalid host is specified.
1462 - if ( false === $parsed_host ) {
1261 + if ( $parsed_host === false ) {
1463 1262 return null;
1464 1263 }
1465 1264 // If a scheme is in the LDAP host, use full LDAP URI instead of just hostname.
1466 1265 if ( array_key_exists( 'scheme', $parsed_host ) ) {
@@ -1473,24 +1272,24 @@
1473 1272
1474 1273 // Establish LDAP connection.
1475 1274 $ldap = ldap_connect( $ldap_host, $ldap_port );
1476 1275 ldap_set_option( $ldap, LDAP_OPT_PROTOCOL_VERSION, 3 );
1477 - if ( 1 === intval( $auth_settings['ldap_tls'] ) ) {
1478 - if ( ! ldap_start_tls( $ldap ) ) {
1276 + if ( $auth_settings['ldap_tls'] == 1 ) {
1277 + if( ! ldap_start_tls( $ldap ) ) {
1479 1278 return null;
1480 1279 }
1481 1280 }
1482 1281
1483 1282 // Set bind credentials; attempt an anonymous bind if not provided.
1484 - $bind_rdn = null;
1485 - $bind_password = null;
1283 + $bind_rdn = NULL;
1284 + $bind_password = NULL;
1486 1285 if ( strlen( $auth_settings['ldap_user'] ) > 0 ) {
1487 - $bind_rdn = $auth_settings['ldap_user'];
1488 - $bind_password = $this->decrypt( $auth_settings['ldap_password'] );
1286 + $bind_rdn = $auth_settings['ldap_user'];
1287 + $bind_password = $this->decrypt( base64_decode( $auth_settings['ldap_password'] ) );
1489 1288 }
1490 1289
1491 1290 // Attempt LDAP bind.
1492 - $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) ); // phpcs:ignore
1291 + $result = @ldap_bind( $ldap, $bind_rdn, $bind_password );
1493 1292 if ( ! $result ) {
1494 1293 // Can't connect to LDAP, so fall back to WordPress authentication.
1495 1294 return null;
1496 1295 }
@@ -1504,40 +1303,18 @@
1504 1303 if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 ) {
1505 1304 array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_last_name'] );
1506 1305 }
1507 1306 if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 && substr( $auth_settings['ldap_attr_email'], 0, 1 ) !== '@' ) {
1508 - array_push( $ldap_attributes_to_retrieve, $this->lowercase( $auth_settings['ldap_attr_email'] ) );
1307 + array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_email'] );
1509 1308 }
1309 + $ldap_search = ldap_search(
1310 + $ldap,
1311 + $auth_settings['ldap_search_base'],
1312 + "(" . $auth_settings['ldap_uid'] . "=" . $username . ")",
1313 + $ldap_attributes_to_retrieve
1314 + );
1315 + $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1510 1316
1511 - // Create default LDAP search filter (uid=$username).
1512 - $search_filter = '(' . $auth_settings['ldap_uid'] . '=' . $username . ')';
1513 -
1514 - /**
1515 - * Filter LDAP search filter.
1516 - *
1517 - * Allows for custom LDAP authentication rules (e.g., restricting login
1518 - * access to users in multiple groups, or having certain attributes).
1519 - *
1520 - * @param string $search_filter The filter to pass to ldap_search().
1521 - * @param string $ldap_uid The attribute to compare username against (from Authorizer Settings).
1522 - * @param string $username The username attempting to log in.
1523 - */
1524 - $search_filter = apply_filters( 'authorizer_ldap_search_filter', $search_filter, $auth_settings['ldap_uid'], $username );
1525 -
1526 - // Multiple search bases can be provided, so iterate through them until a match is found.
1527 - foreach ( $search_bases as $search_base ) {
1528 - $ldap_search = ldap_search(
1529 - $ldap,
1530 - $search_base,
1531 - $search_filter,
1532 - $ldap_attributes_to_retrieve
1533 - );
1534 - $ldap_entries = ldap_get_entries( $ldap, $ldap_search );
1535 - if ( $ldap_entries['count'] > 0 ) {
1536 - break;
1537 - }
1538 - }
1539 -
1540 1317 // If we didn't find any users in ldap, fall back to WordPress authentication.
1541 1318 if ( $ldap_entries['count'] < 1 ) {
1542 1319 return null;
1543 1320 }
@@ -1543,35 +1320,32 @@
1543 1320 }
1544 1321
1545 1322 // Get the bind dn and first/last names; if there are multiple results returned, just get the last one.
1546 1323 for ( $i = 0; $i < $ldap_entries['count']; $i++ ) {
1547 - $ldap_user_dn = $ldap_entries[ $i ]['dn'];
1324 + $ldap_user_dn = $ldap_entries[$i]['dn'];
1548 1325
1549 1326 // Get user first name and last name.
1550 - $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_first_name'] ) : '';
1551 - if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_first_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_first_name ][0] ) > 0 ) {
1552 - $first_name = $ldap_entries[ $i ][ $ldap_attr_first_name ][0];
1327 + if ( array_key_exists( 'ldap_attr_first_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['ldap_attr_first_name'], $ldap_entries[$i] ) && $ldap_entries[$i][$auth_settings['ldap_attr_first_name']]['count'] > 0 && strlen( $ldap_entries[$i][$auth_settings['ldap_attr_first_name']][0] ) > 0 ) {
1328 + $first_name = $ldap_entries[$i][$auth_settings['ldap_attr_first_name']][0];
1553 1329 }
1554 - $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_last_name'] ) : '';
1555 - if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_last_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_last_name ][0] ) > 0 ) {
1556 - $last_name = $ldap_entries[ $i ][ $ldap_attr_last_name ][0];
1330 + if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['ldap_attr_last_name'], $ldap_entries[$i] ) && $ldap_entries[$i][$auth_settings['ldap_attr_last_name']]['count'] > 0 && strlen( $ldap_entries[$i][$auth_settings['ldap_attr_last_name']][0] ) > 0 ) {
1331 + $last_name = $ldap_entries[$i][$auth_settings['ldap_attr_last_name']][0];
1557 1332 }
1558 1333 // Get user email if it is specified in another field.
1559 - $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_email'] ) : '';
1560 - if ( strlen( $ldap_attr_email ) > 0 ) {
1334 + if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 ) {
1561 1335 // If the email attribute starts with an at symbol (@), assume that the
1562 1336 // email domain is manually entered there (instead of a reference to an
1563 1337 // LDAP attribute), and combine that with the username to create the email.
1564 1338 // Otherwise, look up the LDAP attribute for email.
1565 - if ( substr( $ldap_attr_email, 0, 1 ) === '@' ) {
1566 - $email = $this->lowercase( $username . $ldap_attr_email );
1567 - } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_email ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_email ][0] ) > 0 ) {
1568 - $email = $this->lowercase( $ldap_entries[ $i ][ $ldap_attr_email ][0] );
1339 + if ( substr( $auth_settings['ldap_attr_email'], 0, 1 ) === '@' ) {
1340 + $email = strtolower( $username . $auth_settings['ldap_attr_email'] );
1341 + } elseif ( array_key_exists( $auth_settings['ldap_attr_email'], $ldap_entries[$i] ) && $ldap_entries[$i][$auth_settings['ldap_attr_email']]['count'] > 0 && strlen( $ldap_entries[$i][$auth_settings['ldap_attr_email']][0] ) > 0 ) {
1342 + $email = strtolower( $ldap_entries[$i][$auth_settings['ldap_attr_email']][0] );
1569 1343 }
1570 1344 }
1571 1345 }
1572 1346
1573 - $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) ); // phpcs:ignore
1347 + $result = @ldap_bind( $ldap, $ldap_user_dn, $password );
1574 1348 if ( ! $result ) {
1575 1349 // We have a real ldap user, but an invalid password. Pass
1576 1350 // through to wp authentication after failing LDAP (since
1577 1351 // this could be a local account that happens to be the
@@ -1579,22 +1353,22 @@
1579 1353 return null;
1580 1354 }
1581 1355
1582 1356 // User successfully authenticated against LDAP, so set the relevant variables.
1583 - $externally_authenticated_email = $this->lowercase( $username . '@' . $domain );
1357 + $externally_authenticated_email = $username . '@' . $domain;
1584 1358
1585 1359 // If an LDAP attribute has been specified as containing the email address, use that instead.
1586 1360 if ( strlen( $email ) > 0 ) {
1587 - $externally_authenticated_email = $this->lowercase( $email );
1361 + $externally_authenticated_email = $email;
1588 1362 }
1589 1363
1590 1364 return array(
1591 - 'email' => $externally_authenticated_email,
1592 - 'username' => $username,
1593 - 'first_name' => $first_name,
1594 - 'last_name' => $last_name,
1365 + 'email' => $externally_authenticated_email,
1366 + 'username' => $username,
1367 + 'first_name' => $first_name,
1368 + 'last_name' => $last_name,
1595 1369 'authenticated_by' => 'ldap',
1596 - 'ldap_attributes' => $ldap_entries,
1370 + 'ldap_attributes' => $ldap_entries,
1597 1371 );
1598 1372 }
1599 1373
1600 1374
@@ -1600,20 +1374,18 @@
1600 1374
1601 1375 /**
1602 1376 * Log out of the attached external service.
1603 1377 *
1604 - * Action: wp_logout
1605 - *
1606 1378 * @return void
1607 1379 */
1608 1380 public function custom_logout() {
1609 1381 // Grab plugin settings.
1610 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1382 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1611 1383
1612 1384 // Reset option containing old error messages.
1613 1385 delete_option( 'auth_settings_advanced_login_error' );
1614 1386
1615 - if ( session_id() === '' ) {
1387 + if ( session_id() == '' ) {
1616 1388 session_start();
1617 1389 }
1618 1390
1619 1391 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
@@ -1618,53 +1390,38 @@
1618 1390
1619 1391 $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true );
1620 1392
1621 1393 // If logged in to CAS, Log out of CAS.
1622 - if ( 'cas' === $current_user_authenticated_by && '1' === $auth_settings['cas'] ) {
1394 + if ( $current_user_authenticated_by === 'cas' && $auth_settings['cas'] === '1' ) {
1623 1395 if ( ! array_key_exists( 'PHPCAS_CLIENT', $GLOBALS ) || ! array_key_exists( 'phpCAS', $_SESSION ) ) {
1624 1396
1625 - /**
1626 - * Get the CAS server version (default to SAML_VERSION_1_1).
1627 - *
1628 - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1629 - */
1397 + // Get the CAS server version (default to SAML_VERSION_1_1).
1398 + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html
1630 1399 $cas_version = SAML_VERSION_1_1;
1631 - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) {
1400 + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) {
1632 1401 $cas_version = CAS_VERSION_3_0;
1633 - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) {
1402 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) {
1634 1403 $cas_version = CAS_VERSION_2_0;
1635 - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) {
1404 + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) {
1636 1405 $cas_version = CAS_VERSION_1_0;
1637 1406 }
1638 1407
1639 1408 // Set the CAS client configuration if it hasn't been set already.
1640 1409 phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] );
1641 - // Allow redirects at the CAS server endpoint (e.g., allow connections
1642 - // at an old CAS URL that redirects to a newer CAS URL).
1643 - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true );
1644 1410 // Restrict logout request origin to the CAS server only (prevent DDOS).
1645 1411 phpCAS::handleLogoutRequests( true, array( $auth_settings['cas_host'] ) );
1646 1412 }
1647 - if ( phpCAS::isAuthenticated() || phpCAS::isInitialized() ) {
1648 - // Redirect to home page, or specified page if it's been provided.
1649 - $redirect_to = site_url( '/' );
1650 - if ( ! empty( $_REQUEST['redirect_to'] ) && isset( $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'log-out' ) ) {
1651 - $redirect_to = esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) );
1652 - }
1653 -
1654 - phpCAS::logoutWithRedirectService( $redirect_to );
1413 + if ( phpCAS::isAuthenticated() ) {
1414 + phpCAS::logoutWithRedirectService( get_option( 'siteurl' ) );
1655 1415 }
1656 1416 }
1657 1417
1658 1418 // If session token set, log out of Google.
1659 - if ( 'google' === $current_user_authenticated_by || array_key_exists( 'token', $_SESSION ) ) {
1419 + if ( $current_user_authenticated_by === 'google' || array_key_exists( 'token', $_SESSION ) ) {
1660 1420 $token = json_decode( $_SESSION['token'] )->access_token;
1661 1421
1662 - /**
1663 - * Add Google API PHP Client.
1664 - *
1665 - * @see https://github.com/google/google-api-php-client branch:v1-master
1666 - */
1422 + // Add Google API PHP Client.
1423 + // @see https://github.com/google/google-api-php-client branch:v1-master
1667 1424 require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php';
1668 1425
1669 1426 // Build the Google Client.
1670 1427 $client = new Google_Client();
@@ -1672,9 +1429,14 @@
1672 1429 $client->setClientId( $auth_settings['google_clientid'] );
1673 1430 $client->setClientSecret( $auth_settings['google_clientsecret'] );
1674 1431 $client->setRedirectUri( 'postmessage' );
1675 1432
1676 - // Revoke the token.
1433 + // If the hosted domain parameter is set, restrict logins to that domain.
1434 + if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) {
1435 + $client->setHostedDomain( $auth_settings['google_hosteddomain'] );
1436 + }
1437 +
1438 + // Revoke the token
1677 1439 $client->revokeToken( $token );
1678 1440
1679 1441 // Remove the credentials from the user's session.
1680 1442 unset( $_SESSION['token'] );
@@ -1693,37 +1455,36 @@
1693 1455
1694 1456
1695 1457 /**
1696 1458 * Restrict access to WordPress site based on settings (everyone, logged_in_users).
1459 + * Hook: parse_request http://codex.wordpress.org/Plugin_API/Action_Reference/parse_request
1697 1460 *
1698 - * Action: parse_request
1461 + * @param array $wp WordPress object.
1699 1462 *
1700 - * @param array $wp WordPress object.
1701 - * @return WP|void WP object when passing through to WordPress authentication, or void.
1463 + * @return void
1702 1464 */
1703 1465 public function restrict_access( $wp ) {
1704 1466 // Grab plugin settings.
1705 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1467 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1706 1468
1707 1469 // Grab current user.
1708 1470 $current_user = wp_get_current_user();
1709 1471
1710 1472 $has_access = (
1711 - // Always allow access if WordPress is installing.
1712 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
1473 + // Always allow access if WordPress is installing
1713 1474 ( defined( 'WP_INSTALLING' ) && isset( $_GET['key'] ) ) ||
1714 - // Always allow access to admins.
1475 + // Always allow access to admins
1715 1476 ( current_user_can( 'create_users' ) ) ||
1716 - // Allow access if option is set to 'everyone'.
1717 - ( 'everyone' === $auth_settings['access_who_can_view'] ) ||
1718 - // Allow access to approved external users and logged in users if option is set to 'logged_in_users'.
1719 - ( 'logged_in_users' === $auth_settings['access_who_can_view'] && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1720 - // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API.
1721 - ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_oauth1=' ) === 0 ) ||
1722 - // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them.
1723 - ( property_exists( $wp, 'matched_query' ) && 0 === stripos( $wp->matched_query, 'rest_route=' ) && isset( $_SERVER['REQUEST_METHOD'] ) && 'GET' !== $_SERVER['REQUEST_METHOD'] ) ||
1724 - // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this.
1725 - ( property_exists( $wp, 'matched_query' ) && 'rest_route=/' === $wp->matched_query )
1477 + // Allow access if option is set to 'everyone'
1478 + ( $auth_settings['access_who_can_view'] == 'everyone' ) ||
1479 + // Allow access to approved external users and logged in users if option is set to 'logged_in_users'
1480 + ( $auth_settings['access_who_can_view'] == 'logged_in_users' && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) ||
1481 + // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API
1482 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_oauth1=" ) === 0 ) ||
1483 + // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them
1484 + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] !== 'GET' ) ||
1485 + // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this
1486 + ( property_exists( $wp, 'matched_query' ) && $wp->matched_query === 'rest_route=/' )
1726 1487 // Note that GET requests to a rest endpoint will be restricted by authorizer. In that case, error messages will be returned as JSON.
1727 1488 );
1728 1489
1729 1490 /**
@@ -1745,9 +1506,9 @@
1745 1506 * }
1746 1507 * add_filter( 'authorizer_has_access', 'my_rsa_feed_access_override' );
1747 1508 */
1748 1509 if ( apply_filters( 'authorizer_has_access', $has_access, $wp ) === true ) {
1749 - // Turn off the public notice about browsing anonymously.
1510 + // Turn off the public notice about browsing anonymously
1750 1511 update_option( 'auth_settings_advanced_public_notice', false );
1751 1512
1752 1513 // We've determined that the current user has access, so simply return to grant access.
1753 1514 return $wp;
@@ -1753,13 +1514,13 @@
1753 1514 return $wp;
1754 1515 }
1755 1516
1756 1517 // Allow HEAD requests to the root (usually discovery from a REST client).
1757 - if ( 'HEAD' === $_SERVER['REQUEST_METHOD'] && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1518 + if ( $_SERVER['REQUEST_METHOD'] === 'HEAD' && empty( $wp->request ) && empty( $wp->matched_query ) ) {
1758 1519 return $wp;
1759 1520 }
1760 1521
1761 - /* We've determined that the current user doesn't have access, so we deal with them now. */
1522 + // We've determined that the current user doesn't have access, so we deal with them now.
1762 1523
1763 1524 // Fringe case: In a multisite, a user of a different blog can successfully
1764 1525 // log in, but they aren't on the 'approved' whitelist for this blog.
1765 1526 // If that's the case, add them to the pending list for this blog.
@@ -1770,19 +1531,21 @@
1770 1531 $result = $this->check_user_access( $current_user, array( $current_user->user_email ) );
1771 1532 }
1772 1533
1773 1534 // Check to see if the requested page is public. If so, show it.
1774 - if ( empty( $wp->request ) ) {
1775 - $current_page_id = 'home';
1776 - } else {
1777 - $request_query = isset( $wp->query_vars ) ? new WP_Query( $wp->query_vars ) : null;
1778 - $current_page_id = isset( $request_query->post_count ) && $request_query->post_count > 0 ? $request_query->post->ID : '';
1535 + $current_page_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'name', $wp->query_vars ) && strlen( $wp->query_vars['name'] ) > 0 ? $wp->query_vars['name'] : '';
1536 + if ( ! $current_page_name ) {
1537 + // Different WordPress versions store the page slug in different places; look for it elsewhere.
1538 + if ( property_exists( $wp, 'query_vars' ) && array_key_exists( 'pagename', $wp->query_vars ) && strlen( $wp->query_vars['pagename'] ) > 0 ) {
1539 + $current_page_name = $wp->query_vars['pagename'];
1540 + }
1779 1541 }
1542 + $current_page_id = empty( $wp->request ) ? 'home' : $this->get_id_from_pagename( $current_page_name );
1780 1543 if ( ! array_key_exists( 'access_public_pages', $auth_settings ) || ! is_array( $auth_settings['access_public_pages'] ) ) {
1781 1544 $auth_settings['access_public_pages'] = array();
1782 1545 }
1783 - if ( in_array( strval( $current_page_id ), $auth_settings['access_public_pages'], true ) ) {
1784 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1546 + if ( in_array( $current_page_id, $auth_settings['access_public_pages'] ) ) {
1547 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1785 1548 update_option( 'auth_settings_advanced_public_notice', false );
1786 1549 } else {
1787 1550 update_option( 'auth_settings_advanced_public_notice', true );
1788 1551 }
@@ -1790,11 +1553,11 @@
1790 1553 }
1791 1554
1792 1555 // Check to see if any category assigned to the requested page is public. If so, show it.
1793 1556 $current_page_categories = wp_get_post_categories( $current_page_id, array( 'fields' => 'slugs' ) );
1794 - foreach ( $current_page_categories as $current_page_category ) {
1795 - if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'], true ) ) {
1796 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1557 + foreach( $current_page_categories as $current_page_category ) {
1558 + if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'] ) ) {
1559 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1797 1560 update_option( 'auth_settings_advanced_public_notice', false );
1798 1561 } else {
1799 1562 update_option( 'auth_settings_advanced_public_notice', true );
1800 1563 }
@@ -1802,11 +1565,11 @@
1802 1565 }
1803 1566 }
1804 1567
1805 1568 // Check to see if this page can't be found. If so, allow showing the 404 page.
1806 - if ( strlen( $current_page_id ) < 1 ) {
1807 - if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'], true ) ) {
1808 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1569 + if ( strlen( $current_page_name ) > 0 && strlen( $current_page_id ) < 1 ) {
1570 + if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'] ) ) {
1571 + if ( $auth_settings['access_public_warning'] === 'no_warning' ) {
1809 1572 update_option( 'auth_settings_advanced_public_notice', false );
1810 1573 } else {
1811 1574 update_option( 'auth_settings_advanced_public_notice', true );
1812 1575 }
@@ -1811,39 +1574,24 @@
1811 1574 update_option( 'auth_settings_advanced_public_notice', true );
1812 1575 }
1813 1576 return $wp;
1814 1577 }
1815 - }
1816 1578
1817 - // Check to see if the requested category is public. If so, show it.
1818 - $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : '';
1819 - if ( $current_category_name ) {
1820 - $current_category_name = end( explode( '/', $current_category_name ) );
1821 - if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'], true ) ) {
1822 - if ( 'no_warning' === $auth_settings['access_public_warning'] ) {
1823 - update_option( 'auth_settings_advanced_public_notice', false );
1824 - } else {
1825 - update_option( 'auth_settings_advanced_public_notice', true );
1826 - }
1827 - return $wp;
1828 - }
1829 1579 }
1830 1580
1831 1581 // User is denied access, so show them the error message. Render as JSON
1832 1582 // if this is a REST API call; otherwise, show the error message via
1833 1583 // wp_die() (rendered html), or redirect to the login URL.
1834 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1835 - if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_route=' ) === 0 && 'GET' === $_SERVER['REQUEST_METHOD'] ) {
1836 - wp_send_json(
1837 - array(
1838 - 'code' => 'rest_cannot_view',
1839 - 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1840 - 'data' => array(
1841 - 'status' => 401,
1842 - ),
1843 - )
1844 - );
1845 - } elseif ( 'message' === $auth_settings['access_redirect'] ) {
1584 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1585 + if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] === 'GET' ) {
1586 + wp_send_json( array(
1587 + 'code' => 'rest_cannot_view',
1588 + 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ),
1589 + 'data' => array(
1590 + 'status' => 401,
1591 + ),
1592 + ));
1593 + } elseif ( $auth_settings['access_redirect'] === 'message' ) {
1846 1594 $page_title = sprintf(
1847 1595 /* TRANSLATORS: %s: Name of blog */
1848 1596 __( '%s - Access Restricted', 'authorizer' ),
1849 1597 get_bloginfo( 'name' )
@@ -1854,65 +1602,20 @@
1854 1602 '<p style="text-align: center;margin-bottom: -15px;">' .
1855 1603 '<a class="button" href="' . wp_login_url( $current_path ) . '">' .
1856 1604 __( 'Log In', 'authorizer' ) .
1857 1605 '</a></p>';
1858 - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) );
1859 - } else {
1606 + wp_die( $error_message, $page_title );
1607 + } else { // if ( $auth_settings['access_redirect'] === 'login' ) {
1860 1608 wp_redirect( wp_login_url( $current_path ), 302 );
1861 1609 exit;
1862 1610 }
1863 1611
1864 - // Sanity check: we should never get here.
1612 + // Sanity check: we should never get here
1865 1613 wp_die( '<p>Access denied.</p>', 'Site Access Restricted' );
1866 1614 }
1867 1615
1868 1616
1869 - /**
1870 - * On an admin page load, check for edge case (network-approved user who has
1871 - * not yet been added to this particular blog in a multisite). Note: we do
1872 - * this because check_user_access() runs on the parse_request hook, which
1873 - * does not fire on wp-admin pages.
1874 - *
1875 - * Action: init
1876 - *
1877 - * @return void
1878 - */
1879 - public function init__maybe_add_network_approved_user() {
1880 - global $current_user;
1881 1617
1882 - // If this is a multisite install and we have a logged in user that's not
1883 - // a member of this blog, but is (network) approved, add them to this blog.
1884 - if (
1885 - is_admin() &&
1886 - is_multisite() &&
1887 - is_user_logged_in() &&
1888 - ! is_user_member_of_blog() &&
1889 - $this->is_email_in_list( $current_user->user_email, 'approved' )
1890 - ) {
1891 - // Get all approved users.
1892 - $auth_settings_access_users_approved = $this->sanitize_user_list(
1893 - array_merge(
1894 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
1895 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
1896 - )
1897 - );
1898 -
1899 - // Get user info (we need user role).
1900 - $user_info = $this->get_user_info_from_list(
1901 - $current_user->user_email,
1902 - $auth_settings_access_users_approved
1903 - );
1904 -
1905 - // Add user to blog.
1906 - add_user_to_blog( get_current_blog_id(), $current_user->ID, $user_info['role'] );
1907 -
1908 - // Refresh user permissions.
1909 - $current_user = new WP_User( $current_user->ID ); // phpcs:ignore WordPress.Variables.GlobalVariables.OverrideProhibited
1910 - }
1911 - }
1912 -
1913 -
1914 -
1915 1618 /**
1916 1619 * ***************************
1917 1620 * Login page (wp-login.php)
1918 1621 * ***************************
@@ -1921,15 +1624,11 @@
1921 1624
1922 1625
1923 1626 /**
1924 1627 * Add custom error message to login screen.
1925 - *
1926 1628 * Filter: login_errors
1927 - *
1928 - * @param string $errors Error description.
1929 - * @return string Error description with Authorizer errors added.
1930 1629 */
1931 - public function show_advanced_login_error( $errors ) {
1630 + function show_advanced_login_error( $errors ) {
1932 1631 $error = get_option( 'auth_settings_advanced_login_error' );
1933 1632 delete_option( 'auth_settings_advanced_login_error' );
1934 1633 $errors = ' ' . $error . "<br />\n";
1935 1634 return $errors;
@@ -1937,25 +1636,24 @@
1937 1636
1938 1637
1939 1638 /**
1940 1639 * Load external resources for the public-facing site.
1941 - *
1942 - * Action: wp_enqueue_scripts
1943 1640 */
1944 - public function auth_public_scripts() {
1945 - // Load (and localize) public scripts.
1946 - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url();
1947 - wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1641 + function auth_public_scripts() {
1642 + // Load (and localize) public scripts
1643 + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI'];
1644 + wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1948 1645 $auth_localized = array(
1949 - 'wpLoginUrl' => wp_login_url( $current_path ),
1950 - 'publicWarning' => get_option( 'auth_settings_advanced_public_notice' ),
1951 - 'anonymousNotice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1952 - 'logIn' => esc_html__( 'Log In', 'authorizer' ),
1646 + 'wp_login_url' => wp_login_url( $current_path ),
1647 + 'public_warning' => get_option( 'auth_settings_advanced_public_notice' ),
1648 + 'anonymous_notice' => $this->get_plugin_option( 'access_redirect_to_message' ),
1649 + 'log_in' => esc_html__( 'Log In', 'authorizer' ),
1953 1650 );
1954 1651 wp_localize_script( 'auth_public_scripts', 'auth', $auth_localized );
1652 + //update_option( 'auth_settings_advanced_public_notice', false);
1955 1653
1956 - // Load public css.
1957 - wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.8.0' );
1654 + // Load public css
1655 + wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.3.2' );
1958 1656 wp_enqueue_style( 'authorizer-public-css' );
1959 1657 }
1960 1658
1961 1659
@@ -1961,21 +1659,19 @@
1961 1659
1962 1660 /**
1963 1661 * Enqueue JS scripts and CSS styles appearing on wp-login.php.
1964 1662 *
1965 - * Action: login_enqueue_scripts
1966 - *
1967 1663 * @return void
1968 1664 */
1969 - public function login_enqueue_scripts_and_styles() {
1665 + function login_enqueue_scripts_and_styles() {
1970 1666 // Grab plugin settings.
1971 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1667 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
1972 1668
1973 1669 // Enqueue scripts appearing on wp-login.php.
1974 - wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.8.0' );
1670 + wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.3.2' );
1975 1671
1976 1672 // Enqueue styles appearing on wp-login.php.
1977 - wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.8.0' );
1673 + wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.3.2' );
1978 1674 wp_enqueue_style( 'authorizer-login-css' );
1979 1675
1980 1676 /**
1981 1677 * Developers can use the `authorizer_add_branding_option` filter
@@ -1980,8 +1676,9 @@
1980 1676 /**
1981 1677 * Developers can use the `authorizer_add_branding_option` filter
1982 1678 * to add a radio button for "Custom WordPress login branding"
1983 1679 * under the "Advanced" tab in Authorizer options. Example:
1680 + *
1984 1681 * function my_authorizer_add_branding_option( $branding_options ) {
1985 1682 * $new_branding_option = array(
1986 1683 * 'value' => 'your_brand'
1987 1684 * 'description' => 'Custom Your Brand Login Screen',
@@ -1995,23 +1692,23 @@
1995 1692 */
1996 1693 $branding_options = array();
1997 1694 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
1998 1695 foreach ( $branding_options as $branding_option ) {
1999 - // Make sure the custom brands have the required values.
1696 + // Make sure the custom brands have the required values
2000 1697 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'css_url', $branding_option ) && array_key_exists( 'js_url', $branding_option ) ) ) {
2001 1698 continue;
2002 1699 }
2003 1700 if ( $auth_settings['advanced_branding'] === $branding_option['value'] ) {
2004 - wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.8.0' );
2005 - wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.8.0' );
1701 + wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.3.2' );
1702 + wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.3.2' );
2006 1703 wp_enqueue_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ) );
2007 1704 }
2008 1705 }
2009 1706
2010 1707 // If we're using Google logins, load those resources.
2011 - if ( '1' === $auth_settings['google'] ) {
2012 - wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); ?>
2013 - <meta name="google-signin-clientid" content="<?php echo esc_attr( $auth_settings['google_clientid'] ); ?>" />
1708 + if ( $auth_settings['google'] === '1' ) {
1709 + wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); ?>
1710 + <meta name="google-signin-clientid" content="<?php echo $auth_settings['google_clientid']; ?>" />
2014 1711 <meta name="google-signin-scope" content="email" />
2015 1712 <meta name="google-signin-cookiepolicy" content="single_host_origin" />
2016 1713 <?php
2017 1714 }
@@ -2019,127 +1716,110 @@
2019 1716
2020 1717
2021 1718 /**
2022 1719 * Load external resources in the footer of the wp-login.php page.
2023 - *
2024 - * Action: login_footer
1720 + * Run on action hook: login_footer
2025 1721 */
2026 - public function load_login_footer_js() {
1722 + function load_login_footer_js() {
2027 1723 // Grab plugin settings.
2028 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2029 - $ajaxurl = admin_url( 'admin-ajax.php' );
2030 - if ( '1' === $auth_settings['google'] ) :
2031 - ?>
2032 -<script type="text/javascript">
2033 -/* global location, window */
2034 -// Reload login page if reauth querystring param exists,
2035 -// since reauth interrupts external logins (e.g., google).
2036 -if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
2037 - location.href = location.href.replace( 'reauth=1', '' );
2038 -}
1724 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
1725 + <?php if ( $auth_settings['google'] === '1' ): ?>
1726 + <script type="text/javascript">
1727 + // Reload login page if reauth querystring param exists,
1728 + // since reauth interrupts external logins (e.g., google).
1729 + if ( location.search.indexOf( 'reauth=1' ) >= 0 ) {
1730 + location.href = location.href.replace( 'reauth=1', '' );
1731 + }
2039 1732
2040 -// eslint-disable-next-line no-implicit-globals
2041 -function authUpdateQuerystringParam( uri, key, value ) {
2042 - var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
2043 - var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
2044 - if ( uri.match( re ) ) {
2045 - return uri.replace( re, '$1' + key + '=' + value + '$2' );
2046 - } else {
2047 - return uri + separator + key + '=' + value;
2048 - }
2049 -}
1733 + function auth_update_querystring_param( uri, key, value ) {
1734 + var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' );
1735 + var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?';
1736 + if ( uri.match( re ) ) {
1737 + return uri.replace( re, '$1' + key + '=' + value + '$2' );
1738 + } else {
1739 + return uri + separator + key + '=' + value;
1740 + }
1741 + }
2050 1742
2051 -// eslint-disable-next-line
2052 -function signInCallback( authResult ) { // jshint ignore:line
2053 - var $ = jQuery;
2054 - if ( authResult.status && authResult.status.signed_in ) {
2055 - // Hide the sign-in button now that the user is authorized, for example:
2056 - $( '#googleplus_button' ).attr( 'style', 'display: none' );
1743 + function signInCallback( authResult ) {
1744 + var $ = jQuery;
1745 + if ( authResult['status'] && authResult['status']['signed_in'] ) {
1746 + // Hide the sign-in button now that the user is authorized, for example:
1747 + $( '#googleplus_button' ).attr( 'style', 'display: none' );
2057 1748
2058 - // Send the code to the server
2059 - var ajaxurl = '<?php echo esc_attr( $ajaxurl ); ?>';
2060 - $.post(ajaxurl, {
2061 - action: 'process_google_login',
2062 - code: authResult.code,
2063 - nonce: $('#nonce_google_auth-<?php echo esc_attr( $this->get_cookie_value() ); ?>' ).val(),
2064 - }, function() {
2065 - // Handle or verify the server response if necessary.
2066 - // console.log( response );
1749 + // Send the code to the server
1750 + var ajaxurl = '<?php echo admin_url( "admin-ajax.php" ); ?>';
1751 + $.post(ajaxurl, {
1752 + action: 'process_google_login',
1753 + 'code': authResult['code'],
1754 + 'nonce': $('#nonce_google_auth-<?php echo $this->get_cookie_value(); ?>' ).val(),
1755 + }, function( response ) {
1756 + // Handle or verify the server response if necessary.
1757 + //console.log( response );
2067 1758
2068 - // Reload wp-login.php to continue the authentication process.
2069 - var newHref = authUpdateQuerystringParam( location.href, 'external', 'google' );
2070 - if ( location.href === newHref ) {
2071 - location.reload();
2072 - } else {
2073 - location.href = newHref;
2074 - }
2075 - });
2076 - } else {
2077 - // Update the app to reflect a signed out user
2078 - // Possible error values:
2079 - // "user_signed_out" - User is signed-out
2080 - // "access_denied" - User denied access to your app
2081 - // "immediate_failed" - Could not automatically log in the user
2082 - // console.log('Sign-in state: ' + authResult['error']);
1759 + // Reload wp-login.php to continue the authentication process.
1760 + var new_href = auth_update_querystring_param( location.href, 'external', 'google' );
1761 + if ( location.href === new_href ) {
1762 + location.reload();
1763 + } else {
1764 + location.href = new_href;
1765 + }
1766 + });
1767 + } else {
1768 + // Update the app to reflect a signed out user
1769 + // Possible error values:
1770 + // "user_signed_out" - User is signed-out
1771 + // "access_denied" - User denied access to your app
1772 + // "immediate_failed" - Could not automatically log in the user
1773 + //console.log('Sign-in state: ' + authResult['error']);
2083 1774
2084 - // If user denies access, reload the login page.
2085 - if ( authResult.error === 'access_denied' || authResult.error === 'user_signed_out' ) {
2086 - window.location.reload();
1775 + // If user denies access, reload the login page.
1776 + if ( authResult['error'] === 'access_denied' || authResult['error'] === 'user_signed_out' ) {
1777 + window.location.reload();
1778 + }
1779 + }
1780 + }
1781 + </script>
1782 + <?php endif;
2087 1783 }
2088 - }
2089 -}
2090 -</script>
2091 - <?php
2092 - endif;
2093 - }
2094 1784
2095 1785
2096 1786 /**
2097 1787 * Create links for any external authentication services that are enabled.
2098 - *
2099 - * Action: login_form
2100 1788 */
2101 - public function login_form_add_external_service_links() {
1789 + function login_form_add_external_service_links() {
2102 1790 // Grab plugin settings.
2103 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2104 - ?>
1791 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?>
2105 1792 <div id="auth-external-service-login">
2106 - <?php if ( '1' === $auth_settings['google'] ) : ?>
2107 - <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php esc_html_e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
1793 + <?php if ( $auth_settings['google'] === '1' ): ?>
1794 + <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php _e( 'Sign in with Google', 'authorizer' ); ?></span></a></p>
2108 1795 <?php wp_nonce_field( 'google_csrf_nonce', 'nonce_google_auth-' . $this->get_cookie_value() ); ?>
2109 1796 <?php endif; ?>
2110 1797
2111 - <?php if ( '1' === $auth_settings['cas'] ) : ?>
2112 - <p><a class="button button-primary button-external button-cas" href="<?php echo esc_attr( $this->modify_current_url_for_cas_login() ); ?>">
1798 + <?php if ( $auth_settings['cas'] === '1' ): ?>
1799 + <p><a class="button button-primary button-external button-cas" href="<?php echo $this->modify_current_url_for_cas_login(); ?>">
2113 1800 <span class="dashicons dashicons-lock"></span>
2114 - <span class="label">
2115 - <?php
2116 - echo esc_html(
2117 - sprintf(
2118 - /* TRANSLATORS: %s: Custom CAS label from authorizer options */
2119 - __( 'Sign in with %s', 'authorizer' ),
2120 - $auth_settings['cas_custom_label']
2121 - )
1801 + <span class="label"><?php
1802 + printf(
1803 + /* TRANSLATORS: %s: Custom CAS label from authorizer options */
1804 + __( 'Sign in with %s', 'authorizer' ),
1805 + $auth_settings['cas_custom_label']
2122 1806 );
2123 - ?>
2124 - </span>
1807 + ?></span>
2125 1808 </a></p>
2126 1809 <?php endif; ?>
2127 1810
2128 - <?php if ( '1' === $auth_settings['advanced_hide_wp_login'] && isset( $_SERVER['QUERY_STRING'] ) && false === strpos( wp_parse_url( esc_url_raw( wp_unslash( $_SERVER['QUERY_STRING'] ) ), PHP_URL_HOST ), 'external=wordpress' ) ) : ?>
1811 + <?php if ( $auth_settings['advanced_hide_wp_login'] === '1' && strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false ): ?>
2129 1812 <style type="text/css">
2130 - body.login-action-login form {
2131 - padding-bottom: 8px;
1813 + #loginform {
1814 + padding-bottom: 8px !important;
2132 1815 }
2133 - body.login-action-login form p > label,
2134 - body.login-action-login form .forgetmenot,
2135 - body.login-action-login form .submit,
2136 - body.login-action-login #nav { /* csslint allow: ids */
2137 - display: none;
1816 + #loginform p>label, #loginform p.forgetmenot, #loginform p.submit, p#nav {
1817 + display: none !important;
2138 1818 }
2139 1819 </style>
2140 - <?php elseif ( '1' === $auth_settings['cas'] || '1' === $auth_settings['google'] ) : ?>
2141 - <h3> &mdash; <?php esc_html_e( 'or', 'authorizer' ); ?> &mdash; </h3>
1820 + <?php elseif ( $auth_settings['cas'] === '1' || $auth_settings['google'] === '1' ): ?>
1821 + <h3> &mdash; <?php _e( 'or', 'authorizer' ); ?> &mdash; </h3>
2142 1822 <?php endif; ?>
2143 1823 </div>
2144 1824 <?php
2145 1825
@@ -2148,79 +1828,36 @@
2148 1828
2149 1829 /**
2150 1830 * Redirect to CAS login when visiting login page (only if option is
2151 1831 * enabled, CAS is the only service, and WordPress logins are hidden).
2152 - * Note: hook into wp_login_errors filter so this fires after the
2153 - * authenticate hook (where the redirect to CAS happens), but before html
2154 - * output is started (so the redirect header doesn't complain about data
2155 - * already being sent).
2156 - *
2157 - * Filter: wp_login_errors
2158 - *
2159 - * @param object $errors WP Error object.
2160 - * @param string $redirect_to Where to redirect on error.
2161 - * @return WP_Error|void WP Error object or void on redirect.
2162 1832 */
2163 - public function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) {
1833 + function login_head_maybe_redirect_to_cas() {
2164 1834 // Grab plugin settings.
2165 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1835 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2166 1836
2167 1837 // Check whether we should redirect to CAS.
2168 1838 if (
2169 - isset( $_SERVER['QUERY_STRING'] ) &&
2170 - strpos( wp_parse_url( esc_url_raw( wp_unslash( $_SERVER['QUERY_STRING'] ) ), PHP_URL_HOST ), 'external=wordpress' ) === false &&
2171 - array_key_exists( 'cas_auto_login', $auth_settings ) && '1' === $auth_settings['cas_auto_login'] &&
2172 - array_key_exists( 'cas', $auth_settings ) && '1' === $auth_settings['cas'] &&
2173 - ( ! array_key_exists( 'ldap', $auth_settings ) || '1' !== $auth_settings['ldap'] ) &&
2174 - ( ! array_key_exists( 'google', $auth_settings ) || '1' !== $auth_settings['google'] ) &&
2175 - array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && '1' === $auth_settings['advanced_hide_wp_login']
1839 + strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false &&
1840 + array_key_exists( 'cas_auto_login', $auth_settings ) && $auth_settings['cas_auto_login'] === '1' &&
1841 + array_key_exists( 'cas', $auth_settings ) && $auth_settings['cas'] === '1' &&
1842 + ( ! array_key_exists( 'ldap', $auth_settings ) || $auth_settings['ldap'] !== '1' ) &&
1843 + ( ! array_key_exists( 'google', $auth_settings ) || $auth_settings['google'] !== '1' ) &&
1844 + array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && $auth_settings['advanced_hide_wp_login'] === '1'
2176 1845 ) {
2177 1846 wp_redirect( $this->modify_current_url_for_cas_login() );
2178 1847 exit;
2179 1848 }
2180 -
2181 - return $errors;
2182 1849 }
2183 1850
2184 1851
2185 1852 /**
2186 - * Set a unique cookie to add to Google auth nonce to avoid CSRF detection.
2187 - * Note: hook into login_init so this fires at the start of the visit to
2188 - * wp-login.php, but before any html output is started (so setting the
2189 - * cookie header doesn't complain about data already being sent).
2190 - *
2191 - * Action: login_init
2192 - *
2193 - * @return void
2194 - */
2195 - public function login_init__maybe_set_google_nonce_cookie() {
2196 - // Grab plugin settings.
2197 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2198 -
2199 - // If Google logins are enabled, make sure the cookie is set.
2200 - if ( array_key_exists( 'google', $auth_settings ) && '1' === $auth_settings['google'] ) {
2201 - if ( ! isset( $_COOKIE['login_unique'] ) ) {
2202 - $this->cookie_value = md5( rand() );
2203 - setcookie( 'login_unique', $this->cookie_value, time() + 1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' );
2204 - $_COOKIE['login_unique'] = $this->cookie_value;
2205 - }
2206 - }
2207 - }
2208 -
2209 -
2210 - /**
2211 1853 * Implements hook: do_action( 'wp_login_failed', $username );
2212 1854 * Update the user meta for the user that just failed logging in.
2213 1855 * Keep track of time of last failed attempt and number of failed attempts.
2214 - *
2215 - * Action: wp_login_failed
2216 - *
2217 - * @param string $username Username to update login count for.
2218 - * @return void
2219 1856 */
2220 - public function update_login_failed_count( $username ) {
1857 + function update_login_failed_count( $username ) {
2221 1858 // Grab plugin settings.
2222 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1859 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2223 1860
2224 1861 // Get user trying to log in.
2225 1862 // If this isn't a real user, update the global failed attempt
2226 1863 // variables. We'll use these global variables to institute the
@@ -2228,9 +1865,9 @@
2228 1865 // won't be able to determine which accounts are real by which
2229 1866 // accounts get locked out on multiple invalid attempts.
2230 1867 $user = get_user_by( 'login', $username );
2231 1868
2232 - if ( false !== $user ) {
1869 + if ( $user !== FALSE ) {
2233 1870 $last_attempt = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true );
2234 1871 $num_attempts = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true );
2235 1872 } else {
2236 1873 $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' );
@@ -2244,15 +1881,15 @@
2244 1881
2245 1882 // Reset the failed attempt count if the time since the last
2246 1883 // failed attempt is greater than the reset duration.
2247 1884 $time_since_last_fail = time() - $last_attempt;
2248 - $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds.
1885 + $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds
2249 1886 if ( $time_since_last_fail > $reset_duration ) {
2250 1887 $num_attempts = 0;
2251 1888 }
2252 1889
2253 1890 // Set last failed time to now and increment last failed count.
2254 - if ( false !== $user ) {
1891 + if ( $user !== FALSE ) {
2255 1892 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', time() );
2256 1893 update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', $num_attempts + 1 );
2257 1894 } else {
2258 1895 update_option( 'auth_settings_advanced_lockouts_time_last_failed', time() );
@@ -2263,16 +1900,16 @@
2263 1900
2264 1901 /**
2265 1902 * When they successfully log in, make sure WordPress users are in the approved list.
2266 1903 *
2267 - * Action: wp_login
1904 + * @action wp_login
2268 1905 *
2269 1906 * @param string $user_login Username of the user logging in.
2270 - * @param object $user WP_User object of the user logging in.
2271 - * @return void
1907 + * @param WP_User $user WP_User object of the user logging in.
1908 + * @return null
2272 1909 */
2273 - public function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
2274 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
1910 + function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) {
1911 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
2275 1912 }
2276 1913
2277 1914
2278 1915 /**
@@ -2278,17 +1915,12 @@
2278 1915 /**
2279 1916 * Overwrite the URL for the lost password link on the login form.
2280 1917 * If we're authenticating against an external service, standard
2281 1918 * WordPress password resets won't work.
2282 - *
2283 - * Filter: lostpassword_url
2284 - *
2285 - * @param string $lostpassword_url URL to reset password.
2286 - * @return string URL to reset password.
2287 1919 */
2288 - public function custom_lostpassword_url( $lostpassword_url ) {
1920 + function custom_lostpassword_url( $lostpassword_url ) {
2289 1921 // Grab plugin settings.
2290 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
1922 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2291 1923
2292 1924 if (
2293 1925 array_key_exists( 'ldap_lostpassword_url', $auth_settings ) &&
2294 1926 filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_VALIDATE_URL )
@@ -2311,16 +1943,15 @@
2311 1943 /**
2312 1944 * Add a link to this plugin's settings page from the WordPress Plugins page.
2313 1945 * Called from "plugin_action_links" filter in __construct() above.
2314 1946 *
2315 - * Filter: plugin_action_links_authorizer.php
1947 + * @param array $links array of links in the admin sidebar
2316 1948 *
2317 - * @param array $links Admin sidebar links.
2318 - * @return array Admin sidebar links with Authorizer added.
1949 + * @return array of links to show in the admin sidebar.
2319 1950 */
2320 1951 public function plugin_settings_link( $links ) {
2321 - $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2322 - $settings_url = 'settings' === $admin_menu ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
1952 + $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
1953 + $settings_url = $admin_menu === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' );
2323 1954 array_unshift( $links, '<a href="' . $settings_url . '">' . __( 'Settings', 'authorizer' ) . '</a>' );
2324 1955 return $links;
2325 1956 }
2326 1957
@@ -2328,12 +1959,11 @@
2328 1959 /**
2329 1960 * Add a link to this plugin's network settings page from the WordPress Plugins page.
2330 1961 * Called from "network_admin_plugin_action_links" filter in __construct() above.
2331 1962 *
2332 - * Filter: network_admin_plugin_action_links_authorizer.php
1963 + * @param array $links array of links in the network admin sidebar
2333 1964 *
2334 - * @param array $links Network admin sidebar links.
2335 - * @return array Network admin sidebar links with Authorizer added.
1965 + * @return array of links to show in the network admin sidebar.
2336 1966 */
2337 1967 public function network_admin_plugin_settings_link( $links ) {
2338 1968 $settings_link = '<a href="admin.php?page=authorizer">' . __( 'Network Settings', 'authorizer' ) . '</a>';
2339 1969 array_unshift( $links, $settings_link );
@@ -2341,33 +1971,32 @@
2341 1971 }
2342 1972
2343 1973
2344 1974 /**
2345 - * Create the options page under Dashboard > Settings.
2346 - *
2347 - * Action: admin_menu
1975 + * Create the options page under Dashboard > Settings
1976 + * Run on action hook: admin_menu
2348 1977 */
2349 1978 public function add_plugin_page() {
2350 1979 $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' );
2351 - if ( 'settings' === $admin_menu ) {
1980 + if ( $admin_menu === 'settings' ) {
2352 1981 // @see http://codex.wordpress.org/Function_Reference/add_options_page
2353 1982 add_options_page(
2354 - 'Authorizer',
2355 - 'Authorizer',
2356 - 'create_users',
2357 - 'authorizer',
2358 - array( $this, 'create_admin_page' )
1983 + 'Authorizer', // Page title
1984 + 'Authorizer', // Menu title
1985 + 'create_users', // Capability
1986 + 'authorizer', // Menu slug
1987 + array( $this, 'create_admin_page' ) // function
2359 1988 );
2360 1989 } else {
2361 1990 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
2362 1991 add_menu_page(
2363 - 'Authorizer',
2364 - 'Authorizer',
2365 - 'create_users',
2366 - 'authorizer',
2367 - array( $this, 'create_admin_page' ),
2368 - 'dashicons-groups',
2369 - '99.0018465' // position (decimal is to make overlap with other plugins less likely).
1992 + 'Authorizer', // Page title
1993 + 'Authorizer', // Menu title
1994 + 'create_users', // Capability
1995 + 'authorizer', // Menu slug
1996 + array( $this, 'create_admin_page' ), // callback
1997 + 'dashicons-groups', // icon
1998 + '99.0018465' // position (decimal is to make overlap with other plugins less likely)
2370 1999 );
2371 2000 }
2372 2001 }
2373 2002
@@ -2372,75 +2001,56 @@
2372 2001 }
2373 2002
2374 2003
2375 2004 /**
2376 - * Output the HTML for the options page.
2005 + * Output the HTML for the options page
2377 2006 */
2378 - public function create_admin_page() {
2379 - ?>
2007 + public function create_admin_page() { ?>
2380 2008 <div class="wrap">
2381 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2382 - <form method="post" action="options.php" autocomplete="off">
2383 - <?php
2384 - // This prints out all hidden settings fields.
2009 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
2010 + <form method="post" action="options.php" autocomplete="off"><?php
2011 + // This prints out all hidden settings fields
2012 + // @see http://codex.wordpress.org/Function_Reference/settings_fields
2385 2013 settings_fields( 'auth_settings_group' );
2386 - // This prints out all the sections.
2014 + // This prints out all the sections
2015 + // @see http://codex.wordpress.org/Function_Reference/do_settings_sections
2387 2016 do_settings_sections( 'authorizer' );
2388 - submit_button();
2389 - ?>
2017 + submit_button(); ?>
2390 2018 </form>
2391 - </div>
2392 - <?php
2019 + </div><?php
2393 2020 }
2394 2021
2395 2022
2396 2023 /**
2397 2024 * Load external resources on this plugin's options page.
2398 - *
2399 - * Action: load-settings_page_authorizer
2400 - * Action: load-toplevel_page_authorizer
2401 - * Action: admin_head-index.php
2025 + * Run on action hooks: load-settings_page_authorizer, load-toplevel_page_authorizer, admin_head-index.php
2402 2026 */
2403 2027 public function load_options_page() {
2404 2028 wp_enqueue_script(
2405 2029 'authorizer',
2406 2030 plugins_url( 'js/authorizer.js', __FILE__ ),
2407 - array( 'jquery-effects-shake' ), '2.8.0', true
2031 + array( 'jquery-effects-shake' ), '2.3.2', true
2408 2032 );
2409 - wp_localize_script(
2410 - 'authorizer', 'authL10n', array(
2411 - 'baseurl' => get_bloginfo( 'url' ),
2412 - 'saved' => esc_html__( 'Saved', 'authorizer' ),
2413 - 'duplicate' => esc_html__( 'Duplicate', 'authorizer' ),
2414 - 'failed' => esc_html__( 'Failed', 'authorizer' ),
2415 - 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2416 - 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2417 - 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2418 - 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2419 - 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2420 - 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2421 - 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2422 - 'first_page' => esc_html__( 'First page' ),
2423 - 'previous_page' => esc_html__( 'Previous page' ),
2424 - 'next_page' => esc_html__( 'Next page' ),
2425 - 'last_page' => esc_html__( 'Last page' ),
2426 - 'is_network_admin' => is_network_admin() ? '1' : '0',
2427 - )
2428 - );
2033 + wp_localize_script( 'authorizer', 'auth_L10n', array(
2034 + 'baseurl' => get_bloginfo( 'url' ),
2035 + 'saved' => esc_html__( 'Saved', 'authorizer' ),
2036 + 'failed' => esc_html__( 'Failed', 'authorizer' ),
2037 + 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ),
2038 + 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ),
2039 + 'remove_user' => esc_html__( 'Remove user', 'authorizer' ),
2040 + 'no_users_in' => esc_html__( 'No users in', 'authorizer' ),
2041 + 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ),
2042 + 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ),
2043 + 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ),
2044 + ));
2429 2045
2430 2046 wp_enqueue_script(
2431 - 'jquery-autogrow-textarea',
2432 - plugins_url( 'vendor/jquery.autogrow-textarea/jquery.autogrow-textarea.js', __FILE__ ),
2433 - array( 'jquery' ), '2.7.0', true
2434 - );
2435 -
2436 - wp_enqueue_script(
2437 2047 'jquery.multi-select',
2438 2048 plugins_url( 'vendor/jquery.multi-select/js/jquery.multi-select.js', __FILE__ ),
2439 2049 array( 'jquery' ), '1.8', true
2440 2050 );
2441 2051
2442 - wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.7.3' );
2052 + wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.3.2' );
2443 2053 wp_enqueue_style( 'authorizer-css' );
2444 2054
2445 2055 wp_register_style( 'jquery-multi-select-css', plugins_url( 'vendor/jquery.multi-select/css/multi-select.css', __FILE__ ), array(), '1.8' );
2446 2056 wp_enqueue_style( 'jquery-multi-select-css' );
@@ -2451,26 +2061,18 @@
2451 2061
2452 2062
2453 2063 /**
2454 2064 * Show custom admin notice.
2455 - *
2456 - * Note: currently unused, but if anywhere we:
2457 - * add_option( 'auth_settings_advanced_admin_notice, 'Your message.' );
2458 - * It will display and then delete that message on the admin dashboard.
2459 - *
2460 - * Filter: admin_notices
2461 - * filter: network_admin_notices
2065 + * Filter: admin_notice
2462 2066 */
2463 - public function show_advanced_admin_notice() {
2067 + function show_advanced_admin_notice() {
2464 2068 $notice = get_option( 'auth_settings_advanced_admin_notice' );
2465 2069 delete_option( 'auth_settings_advanced_admin_notice' );
2466 2070
2467 - if ( $notice && strlen( $notice ) > 0 ) {
2468 - ?>
2071 + if ( $notice && strlen( $notice ) > 0 ) { ?>
2469 2072 <div class="error">
2470 - <p><?php echo wp_kses( $notice, $this->allowed_html ); ?></p>
2471 - </div>
2472 - <?php
2073 + <p><?php echo $notice; ?></p>
2074 + </div><?php
2473 2075 }
2474 2076 }
2475 2077
2476 2078
@@ -2475,11 +2077,9 @@
2475 2077
2476 2078
2477 2079 /**
2478 2080 * Add notices to the top of the options page.
2479 - *
2480 - * Action: load-settings_page_authorizer > admin_notices
2481 - *
2081 + * Run on action hook chain: load-settings_page_authorizer > admin_notices
2482 2082 * Description: Check for invalid settings combinations and show a warning message, e.g.:
2483 2083 * if ( cas url inaccessible ) : ?>
2484 2084 * <div class='updated settings-error'><p>Can't reach CAS server.</p></div>
2485 2085 * <?php endif;
@@ -2485,23 +2085,20 @@
2485 2085 * <?php endif;
2486 2086 */
2487 2087 public function admin_notices() {
2488 2088 // Grab plugin settings.
2489 - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
2089 + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' );
2490 2090
2491 - if ( '1' === $auth_settings['cas'] ) :
2091 + if ( $auth_settings['cas'] === '1' ) :
2492 2092 // Check if provided CAS URL is accessible.
2493 - $protocol = in_array( strval( $auth_settings['cas_port'] ), array( '80', '8080' ), true ) ? 'http' : 'https';
2494 - $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2495 - $legacy_cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint (old; some servers don't register a ./login endpoint, use serviceValidate instead).
2496 - $cas_url = trailingslashit( $cas_url ) . 'serviceValidate'; // Check the specific CAS login endpoint.
2497 - if ( ! $this->url_is_accessible( $cas_url ) && ! $this->url_is_accessible( $legacy_cas_url ) ) :
2498 - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2499 - ?>
2500 - <div class='notice notice-warning is-dismissible'>
2501 - <p><?php esc_html_e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo esc_attr( $authorizer_options_url ); ?>&tab=external'><?php esc_html_e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php esc_html_e( 'if you intend to use it.', 'authorizer' ); ?></p>
2502 - </div>
2503 - <?php
2093 + $protocol = in_array( $auth_settings['cas_port'], array( '80', '8080' ) ) ? 'http' : 'https';
2094 + $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path'];
2095 + $cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint
2096 + if ( ! $this->url_is_accessible( $cas_url ) ) :
2097 + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' );
2098 + ?><div class='notice notice-warning is-dismissible'>
2099 + <p><?php _e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo $authorizer_options_url; ?>&tab=external'><?php _e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php _e( 'if you intend to use it.', 'authorizer' ); ?></p>
2100 + </div><?php
2504 2101 endif;
2505 2102 endif;
2506 2103 }
2507 2104
@@ -2506,430 +2103,399 @@
2506 2103 }
2507 2104
2508 2105
2509 2106 /**
2510 - * Create sections and options.
2511 - *
2512 - * Action: admin_init
2107 + * Create sections and options
2108 + * Run on action hook: admin_init
2513 2109 */
2514 2110 public function page_init() {
2515 - /**
2516 - * Create one setting that holds all the options (array).
2517 - *
2518 - * @see http://codex.wordpress.org/Function_Reference/register_setting
2519 - * @see http://codex.wordpress.org/Function_Reference/add_settings_section
2520 - * @see http://codex.wordpress.org/Function_Reference/add_settings_field
2521 - */
2111 + // Create one setting that holds all the options (array)
2112 + // @see http://codex.wordpress.org/Function_Reference/register_setting
2113 + // @see http://codex.wordpress.org/Function_Reference/add_settings_section
2114 + // @see http://codex.wordpress.org/Function_Reference/add_settings_field
2522 2115 register_setting(
2523 - 'auth_settings_group',
2524 - 'auth_settings',
2525 - array( $this, 'sanitize_options' )
2116 + 'auth_settings_group', // Option group
2117 + 'auth_settings', // Option name
2118 + array( $this, 'sanitize_options' ) // Sanitize callback
2526 2119 );
2527 2120
2528 2121 add_settings_section(
2529 - 'auth_settings_tabs',
2530 - '',
2531 - array( $this, 'print_section_info_tabs' ),
2532 - 'authorizer'
2122 + 'auth_settings_tabs', // HTML element ID
2123 + '', // HTML element Title
2124 + array( $this, 'print_section_info_tabs' ), // Callback (echos section content)
2125 + 'authorizer' // Page this section is shown on (slug)
2533 2126 );
2534 2127
2535 - // Create Access Lists section.
2128 + // Create Access Lists section
2536 2129 add_settings_section(
2537 - 'auth_settings_lists',
2538 - '',
2539 - array( $this, 'print_section_info_access_lists' ),
2540 - 'authorizer'
2130 + 'auth_settings_lists', // HTML element ID
2131 + '', // HTML element Title
2132 + array( $this, 'print_section_info_access_lists' ), // Callback (echos section content)
2133 + 'authorizer' // Page this section is shown on (slug)
2541 2134 );
2542 2135
2543 - // Create Login Access section.
2136 + // Create Login Access section
2544 2137 add_settings_section(
2545 - 'auth_settings_access_login',
2546 - '',
2547 - array( $this, 'print_section_info_access_login' ),
2548 - 'authorizer'
2138 + 'auth_settings_access_login', // HTML element ID
2139 + '', // HTML element Title
2140 + array( $this, 'print_section_info_access_login' ), // Callback (echos section content)
2141 + 'authorizer' // Page this section is shown on (slug)
2549 2142 );
2550 2143 add_settings_field(
2551 - 'auth_settings_access_who_can_login',
2552 - __( 'Who can log into the site?', 'authorizer' ),
2553 - array( $this, 'print_radio_auth_access_who_can_login' ),
2554 - 'authorizer',
2555 - 'auth_settings_access_login'
2144 + 'auth_settings_access_who_can_login', // HTML element ID
2145 + __( 'Who can log into the site?', 'authorizer' ), // HTML element Title
2146 + array( $this, 'print_radio_auth_access_who_can_login' ), // Callback (echos form element)
2147 + 'authorizer', // Page this setting is shown on (slug)
2148 + 'auth_settings_access_login' // Section this setting is shown on
2556 2149 );
2557 2150 add_settings_field(
2558 - 'auth_settings_access_role_receive_pending_emails',
2559 - __( 'Which role should receive email notifications about pending users?', 'authorizer' ),
2560 - array( $this, 'print_select_auth_access_role_receive_pending_emails' ),
2561 - 'authorizer',
2562 - 'auth_settings_access_login'
2151 + 'auth_settings_access_role_receive_pending_emails', // HTML element ID
2152 + __( 'Which role should receive email notifications about pending users?', 'authorizer' ), // HTML element Title
2153 + array( $this, 'print_select_auth_access_role_receive_pending_emails' ), // Callback (echos form element)
2154 + 'authorizer', // Page this setting is shown on (slug)
2155 + 'auth_settings_access_login' // Section this setting is shown on
2563 2156 );
2564 2157 add_settings_field(
2565 - 'auth_settings_access_pending_redirect_to_message',
2566 - __( 'What message should pending users see after attempting to log in?', 'authorizer' ),
2567 - array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ),
2568 - 'authorizer',
2569 - 'auth_settings_access_login'
2158 + 'auth_settings_access_pending_redirect_to_message', // HTML element ID
2159 + __( 'What message should pending users see after attempting to log in?', 'authorizer' ), // HTML element Title
2160 + array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ), // Callback (echos form element)
2161 + 'authorizer', // Page this setting is shown on (slug)
2162 + 'auth_settings_access_login' // Section this setting is shown on
2570 2163 );
2571 2164 add_settings_field(
2572 - 'auth_settings_access_blocked_redirect_to_message',
2573 - __( 'What message should blocked users see after attempting to log in?', 'authorizer' ),
2574 - array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ),
2575 - 'authorizer',
2576 - 'auth_settings_access_login'
2165 + 'auth_settings_access_blocked_redirect_to_message', // HTML element ID
2166 + __( 'What message should blocked users see after attempting to log in?', 'authorizer' ), // HTML element Title
2167 + array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ), // Callback (echos form element)
2168 + 'authorizer', // Page this setting is shown on (slug)
2169 + 'auth_settings_access_login' // Section this setting is shown on
2577 2170 );
2578 2171 add_settings_field(
2579 - 'auth_settings_access_should_email_approved_users',
2580 - __( 'Send welcome email to new approved users?', 'authorizer' ),
2581 - array( $this, 'print_checkbox_auth_access_should_email_approved_users' ),
2582 - 'authorizer',
2583 - 'auth_settings_access_login'
2172 + 'auth_settings_access_should_email_approved_users', // HTML element ID
2173 + __( 'Send welcome email to new approved users?', 'authorizer' ), // HTML element Title
2174 + array( $this, 'print_checkbox_auth_access_should_email_approved_users' ), // Callback (echos form element)
2175 + 'authorizer', // Page this setting is shown on (slug)
2176 + 'auth_settings_access_login' // Section this setting is shown on
2584 2177 );
2585 2178 add_settings_field(
2586 - 'auth_settings_access_email_approved_users_subject',
2587 - __( 'Welcome email subject', 'authorizer' ),
2588 - array( $this, 'print_text_auth_access_email_approved_users_subject' ),
2589 - 'authorizer',
2590 - 'auth_settings_access_login'
2179 + 'auth_settings_access_email_approved_users_subject', // HTML element ID
2180 + __( 'Welcome email subject', 'authorizer' ), // HTML element Title
2181 + array( $this, 'print_text_auth_access_email_approved_users_subject' ), // Callback (echos form element)
2182 + 'authorizer', // Page this setting is shown on (slug)
2183 + 'auth_settings_access_login' // Section this setting is shown on
2591 2184 );
2592 2185 add_settings_field(
2593 - 'auth_settings_access_email_approved_users_body',
2594 - __( 'Welcome email body', 'authorizer' ),
2595 - array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ),
2596 - 'authorizer',
2597 - 'auth_settings_access_login'
2186 + 'auth_settings_access_email_approved_users_body', // HTML element ID
2187 + __( 'Welcome email body', 'authorizer' ), // HTML element Title
2188 + array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ), // Callback (echos form element)
2189 + 'authorizer', // Page this setting is shown on (slug)
2190 + 'auth_settings_access_login' // Section this setting is shown on
2598 2191 );
2599 2192
2600 - // Create Public Access section.
2193 +
2194 + // Create Public Access section
2601 2195 add_settings_section(
2602 - 'auth_settings_access_public',
2603 - '',
2604 - array( $this, 'print_section_info_access_public' ),
2605 - 'authorizer'
2196 + 'auth_settings_access_public', // HTML element ID
2197 + '', // HTML element Title
2198 + array( $this, 'print_section_info_access_public' ), // Callback (echos section content)
2199 + 'authorizer' // Page this section is shown on (slug)
2606 2200 );
2607 2201 add_settings_field(
2608 - 'auth_settings_access_who_can_view',
2609 - __( 'Who can view the site?', 'authorizer' ),
2610 - array( $this, 'print_radio_auth_access_who_can_view' ),
2611 - 'authorizer',
2612 - 'auth_settings_access_public'
2202 + 'auth_settings_access_who_can_view', // HTML element ID
2203 + __( 'Who can view the site?', 'authorizer' ), // HTML element Title
2204 + array( $this, 'print_radio_auth_access_who_can_view' ), // Callback (echos form element)
2205 + 'authorizer', // Page this setting is shown on (slug)
2206 + 'auth_settings_access_public' // Section this setting is shown on
2613 2207 );
2614 2208 add_settings_field(
2615 - 'auth_settings_access_public_pages',
2616 - __( 'What pages (if any) should be available to everyone?', 'authorizer' ),
2617 - array( $this, 'print_multiselect_auth_access_public_pages' ),
2618 - 'authorizer',
2619 - 'auth_settings_access_public'
2209 + 'auth_settings_access_public_pages', // HTML element ID
2210 + __( 'What pages (if any) should be available to everyone?', 'authorizer' ), // HTML element Title
2211 + array( $this, 'print_multiselect_auth_access_public_pages' ), // Callback (echos form element)
2212 + 'authorizer', // Page this setting is shown on (slug)
2213 + 'auth_settings_access_public' // Section this setting is shown on
2620 2214 );
2621 2215 add_settings_field(
2622 - 'auth_settings_access_redirect',
2623 - __( 'What happens to people without access when they visit a private page?', 'authorizer' ),
2624 - array( $this, 'print_radio_auth_access_redirect' ),
2625 - 'authorizer',
2626 - 'auth_settings_access_public'
2216 + 'auth_settings_access_redirect', // HTML element ID
2217 + __( 'What happens to people without access when they visit a private page?', 'authorizer' ), // HTML element Title
2218 + array( $this, 'print_radio_auth_access_redirect' ), // Callback (echos form element)
2219 + 'authorizer', // Page this setting is shown on (slug)
2220 + 'auth_settings_access_public' // Section this setting is shown on
2627 2221 );
2628 2222 add_settings_field(
2629 - 'auth_settings_access_public_warning',
2630 - __( 'What happens to people without access when they visit a public page?', 'authorizer' ),
2631 - array( $this, 'print_radio_auth_access_public_warning' ),
2632 - 'authorizer',
2633 - 'auth_settings_access_public'
2223 + 'auth_settings_access_public_warning', // HTML element ID
2224 + __( 'What happens to people without access when they visit a public page?', 'authorizer' ), // HTML element Title
2225 + array( $this, 'print_radio_auth_access_public_warning' ), // Callback (echos form element)
2226 + 'authorizer', // Page this setting is shown on (slug)
2227 + 'auth_settings_access_public' // Section this setting is shown on
2634 2228 );
2635 2229 add_settings_field(
2636 - 'auth_settings_access_redirect_to_message',
2637 - __( 'What message should people without access see?', 'authorizer' ),
2638 - array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ),
2639 - 'authorizer',
2640 - 'auth_settings_access_public'
2230 + 'auth_settings_access_redirect_to_message', // HTML element ID
2231 + __( 'What message should people without access see?', 'authorizer' ), // HTML element Title
2232 + array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ), // Callback (echos form element)
2233 + 'authorizer', // Page this setting is shown on (slug)
2234 + 'auth_settings_access_public' // Section this setting is shown on
2641 2235 );
2642 2236
2643 - // Create External Service Settings section.
2237 + // Create External Service Settings section
2644 2238 add_settings_section(
2645 - 'auth_settings_external',
2646 - '',
2647 - array( $this, 'print_section_info_external' ),
2648 - 'authorizer'
2239 + 'auth_settings_external', // HTML element ID
2240 + '', // HTML element Title
2241 + array( $this, 'print_section_info_external' ), // Callback (echos section content)
2242 + 'authorizer' // Page this section is shown on (slug)
2649 2243 );
2650 2244 add_settings_field(
2651 - 'auth_settings_access_default_role',
2652 - __( 'Default role for new users', 'authorizer' ),
2653 - array( $this, 'print_select_auth_access_default_role' ),
2654 - 'authorizer',
2655 - 'auth_settings_external'
2245 + 'auth_settings_access_default_role', // HTML element ID
2246 + __( 'Default role for new users', 'authorizer' ), // HTML element Title
2247 + array( $this, 'print_select_auth_access_default_role' ), // Callback (echos form element)
2248 + 'authorizer', // Page this setting is shown on (slug)
2249 + 'auth_settings_external' // Section this setting is shown on
2656 2250 );
2657 2251 add_settings_field(
2658 - 'auth_settings_external_google',
2659 - __( 'Google Logins', 'authorizer' ),
2660 - array( $this, 'print_checkbox_auth_external_google' ),
2661 - 'authorizer',
2662 - 'auth_settings_external'
2252 + 'auth_settings_external_google', // HTML element ID
2253 + __( 'Google Logins', 'authorizer' ), // HTML element Title
2254 + array( $this, 'print_checkbox_auth_external_google' ), // Callback (echos form element)
2255 + 'authorizer', // Page this setting is shown on (slug)
2256 + 'auth_settings_external' // Section this setting is shown on
2663 2257 );
2664 2258 add_settings_field(
2665 - 'auth_settings_google_clientid',
2666 - __( 'Google Client ID', 'authorizer' ),
2667 - array( $this, 'print_text_google_clientid' ),
2668 - 'authorizer',
2669 - 'auth_settings_external'
2259 + 'auth_settings_google_clientid', // HTML element ID
2260 + __( 'Google Client ID', 'authorizer' ), // HTML element Title
2261 + array( $this, 'print_text_google_clientid' ), // Callback (echos form element)
2262 + 'authorizer', // Page this setting is shown on (slug)
2263 + 'auth_settings_external' // Section this setting is shown on
2670 2264 );
2671 2265 add_settings_field(
2672 - 'auth_settings_google_clientsecret',
2673 - __( 'Google Client Secret', 'authorizer' ),
2674 - array( $this, 'print_text_google_clientsecret' ),
2675 - 'authorizer',
2676 - 'auth_settings_external'
2266 + 'auth_settings_google_clientsecret', // HTML element ID
2267 + __( 'Google Client Secret', 'authorizer' ), // HTML element Title
2268 + array( $this, 'print_text_google_clientsecret' ), // Callback (echos form element)
2269 + 'authorizer', // Page this setting is shown on (slug)
2270 + 'auth_settings_external' // Section this setting is shown on
2677 2271 );
2678 2272 add_settings_field(
2679 - 'auth_settings_google_hosteddomain',
2680 - __( 'Google Hosted Domain', 'authorizer' ),
2681 - array( $this, 'print_text_google_hosteddomain' ),
2682 - 'authorizer',
2683 - 'auth_settings_external'
2273 + 'auth_settings_google_hosteddomain', // HTML element ID
2274 + __( 'Google Hosted Domain', 'authorizer' ), // HTML element Title
2275 + array( $this, 'print_text_google_hosteddomain' ), // Callback (echos form element)
2276 + 'authorizer', // Page this setting is shown on (slug)
2277 + 'auth_settings_external' // Section this setting is shown on
2684 2278 );
2685 2279 add_settings_field(
2686 - 'auth_settings_external_cas',
2687 - __( 'CAS Logins', 'authorizer' ),
2688 - array( $this, 'print_checkbox_auth_external_cas' ),
2689 - 'authorizer',
2690 - 'auth_settings_external'
2280 + 'auth_settings_external_cas', // HTML element ID
2281 + __( 'CAS Logins', 'authorizer' ), // HTML element Title
2282 + array( $this, 'print_checkbox_auth_external_cas' ), // Callback (echos form element)
2283 + 'authorizer', // Page this setting is shown on (slug)
2284 + 'auth_settings_external' // Section this setting is shown on
2691 2285 );
2692 2286 add_settings_field(
2693 - 'auth_settings_cas_custom_label',
2694 - __( 'CAS custom label', 'authorizer' ),
2695 - array( $this, 'print_text_cas_custom_label' ),
2696 - 'authorizer',
2697 - 'auth_settings_external'
2287 + 'auth_settings_cas_custom_label', // HTML element ID
2288 + __( 'CAS custom label', 'authorizer' ), // HTML element Title
2289 + array( $this, 'print_text_cas_custom_label' ), // Callback (echos form element)
2290 + 'authorizer', // Page this setting is shown on (slug)
2291 + 'auth_settings_external' // Section this setting is shown on
2698 2292 );
2699 2293 add_settings_field(
2700 - 'auth_settings_cas_host',
2701 - __( 'CAS server hostname', 'authorizer' ),
2702 - array( $this, 'print_text_cas_host' ),
2703 - 'authorizer',
2704 - 'auth_settings_external'
2294 + 'auth_settings_cas_host', // HTML element ID
2295 + __( 'CAS server hostname', 'authorizer' ), // HTML element Title
2296 + array( $this, 'print_text_cas_host' ), // Callback (echos form element)
2297 + 'authorizer', // Page this setting is shown on (slug)
2298 + 'auth_settings_external' // Section this setting is shown on
2705 2299 );
2706 2300 add_settings_field(
2707 - 'auth_settings_cas_port',
2708 - __( 'CAS server port', 'authorizer' ),
2709 - array( $this, 'print_text_cas_port' ),
2710 - 'authorizer',
2711 - 'auth_settings_external'
2301 + 'auth_settings_cas_port', // HTML element ID
2302 + __( 'CAS server port', 'authorizer' ), // HTML element Title
2303 + array( $this, 'print_text_cas_port' ), // Callback (echos form element)
2304 + 'authorizer', // Page this setting is shown on (slug)
2305 + 'auth_settings_external' // Section this setting is shown on
2712 2306 );
2713 2307 add_settings_field(
2714 - 'auth_settings_cas_path',
2715 - __( 'CAS server path/context', 'authorizer' ),
2716 - array( $this, 'print_text_cas_path' ),
2717 - 'authorizer',
2718 - 'auth_settings_external'
2308 + 'auth_settings_cas_path', // HTML element ID
2309 + __( 'CAS server path/context', 'authorizer' ), // HTML element Title
2310 + array( $this, 'print_text_cas_path' ), // Callback (echos form element)
2311 + 'authorizer', // Page this setting is shown on (slug)
2312 + 'auth_settings_external' // Section this setting is shown on
2719 2313 );
2720 2314 add_settings_field(
2721 - 'auth_settings_cas_version',
2722 - 'CAS server version',
2723 - array( $this, 'print_select_cas_version' ),
2724 - 'authorizer',
2725 - 'auth_settings_external'
2315 + 'auth_settings_cas_version', // HTML element ID
2316 + 'CAS server version', // HTML element Title
2317 + array( $this, 'print_select_cas_version' ), // Callback (echos form element)
2318 + 'authorizer', // Page this setting is shown on (slug)
2319 + 'auth_settings_external' // Section this setting is shown on
2726 2320 );
2727 2321 add_settings_field(
2728 - 'auth_settings_cas_attr_email',
2729 - __( 'CAS attribute containing email address', 'authorizer' ),
2730 - array( $this, 'print_text_cas_attr_email' ),
2731 - 'authorizer',
2732 - 'auth_settings_external'
2322 + 'auth_settings_cas_attr_email', // HTML element ID
2323 + __( 'CAS attribute containing email address', 'authorizer' ), // HTML element Title
2324 + array( $this, 'print_text_cas_attr_email' ), // Callback (echos form element)
2325 + 'authorizer', // Page this setting is shown on (slug)
2326 + 'auth_settings_external' // Section this setting is shown on
2733 2327 );
2734 2328 add_settings_field(
2735 - 'auth_settings_cas_attr_first_name',
2736 - __( 'CAS attribute containing first name', 'authorizer' ),
2737 - array( $this, 'print_text_cas_attr_first_name' ),
2738 - 'authorizer',
2739 - 'auth_settings_external'
2329 + 'auth_settings_cas_attr_first_name', // HTML element ID
2330 + __( 'CAS attribute containing first name', 'authorizer' ), // HTML element Title
2331 + array( $this, 'print_text_cas_attr_first_name' ), // Callback (echos form element)
2332 + 'authorizer', // Page this setting is shown on (slug)
2333 + 'auth_settings_external' // Section this setting is shown on
2740 2334 );
2741 2335 add_settings_field(
2742 - 'auth_settings_cas_attr_last_name',
2743 - __( 'CAS attribute containing last name', 'authorizer' ),
2744 - array( $this, 'print_text_cas_attr_last_name' ),
2745 - 'authorizer',
2746 - 'auth_settings_external'
2336 + 'auth_settings_cas_attr_last_name', // HTML element ID
2337 + __( 'CAS attribute containing last name', 'authorizer' ), // HTML element Title
2338 + array( $this, 'print_text_cas_attr_last_name' ), // Callback (echos form element)
2339 + 'authorizer', // Page this setting is shown on (slug)
2340 + 'auth_settings_external' // Section this setting is shown on
2747 2341 );
2748 2342 add_settings_field(
2749 - 'auth_settings_cas_attr_update_on_login',
2750 - __( 'CAS attribute update', 'authorizer' ),
2751 - array( $this, 'print_checkbox_cas_attr_update_on_login' ),
2752 - 'authorizer',
2753 - 'auth_settings_external'
2343 + 'auth_settings_cas_attr_update_on_login', // HTML element ID
2344 + __( 'CAS attribute update', 'authorizer' ), // HTML element Title
2345 + array( $this, 'print_checkbox_cas_attr_update_on_login' ), // Callback (echos form element)
2346 + 'authorizer', // Page this setting is shown on (slug)
2347 + 'auth_settings_external' // Section this setting is shown on
2754 2348 );
2755 2349 add_settings_field(
2756 - 'auth_settings_cas_auto_login',
2757 - __( 'CAS automatic login', 'authorizer' ),
2758 - array( $this, 'print_checkbox_cas_auto_login' ),
2759 - 'authorizer',
2760 - 'auth_settings_external'
2350 + 'auth_settings_cas_auto_login', // HTML element ID
2351 + __( 'CAS automatic login', 'authorizer' ), // HTML element Title
2352 + array( $this, 'print_checkbox_cas_auto_login' ), // Callback (echos form element)
2353 + 'authorizer', // Page this setting is shown on (slug)
2354 + 'auth_settings_external' // Section this setting is shown on
2761 2355 );
2762 2356 add_settings_field(
2763 - 'auth_settings_external_ldap',
2764 - __( 'LDAP Logins', 'authorizer' ),
2765 - array( $this, 'print_checkbox_auth_external_ldap' ),
2766 - 'authorizer',
2767 - 'auth_settings_external'
2357 + 'auth_settings_external_ldap', // HTML element ID
2358 + __( 'LDAP Logins', 'authorizer' ), // HTML element Title
2359 + array( $this, 'print_checkbox_auth_external_ldap' ), // Callback (echos form element)
2360 + 'authorizer', // Page this setting is shown on (slug)
2361 + 'auth_settings_external' // Section this setting is shown on
2768 2362 );
2769 2363 add_settings_field(
2770 - 'auth_settings_ldap_host',
2771 - __( 'LDAP Host', 'authorizer' ),
2772 - array( $this, 'print_text_ldap_host' ),
2773 - 'authorizer',
2774 - 'auth_settings_external'
2364 + 'auth_settings_ldap_host', // HTML element ID
2365 + __( 'LDAP Host', 'authorizer' ), // HTML element Title
2366 + array( $this, 'print_text_ldap_host' ), // Callback (echos form element)
2367 + 'authorizer', // Page this setting is shown on (slug)
2368 + 'auth_settings_external' // Section this setting is shown on
2775 2369 );
2776 2370 add_settings_field(
2777 - 'auth_settings_ldap_port',
2778 - __( 'LDAP Port', 'authorizer' ),
2779 - array( $this, 'print_text_ldap_port' ),
2780 - 'authorizer',
2781 - 'auth_settings_external'
2371 + 'auth_settings_ldap_port', // HTML element ID
2372 + __( 'LDAP Port', 'authorizer' ), // HTML element Title
2373 + array( $this, 'print_text_ldap_port' ), // Callback (echos form element)
2374 + 'authorizer', // Page this setting is shown on (slug)
2375 + 'auth_settings_external' // Section this setting is shown on
2782 2376 );
2783 2377 add_settings_field(
2784 - 'auth_settings_ldap_tls',
2785 - __( 'Use TLS', 'authorizer' ),
2786 - array( $this, 'print_checkbox_ldap_tls' ),
2787 - 'authorizer',
2788 - 'auth_settings_external'
2378 + 'auth_settings_ldap_tls', // HTML element ID
2379 + __( 'Secure Connection (TLS)', 'authorizer' ), // HTML element Title
2380 + array( $this, 'print_checkbox_ldap_tls' ), // Callback (echos form element)
2381 + 'authorizer', // Page this setting is shown on (slug)
2382 + 'auth_settings_external' // Section this setting is shown on
2789 2383 );
2790 2384 add_settings_field(
2791 - 'auth_settings_ldap_search_base',
2792 - __( 'LDAP Search Base', 'authorizer' ),
2793 - array( $this, 'print_text_ldap_search_base' ),
2794 - 'authorizer',
2795 - 'auth_settings_external'
2385 + 'auth_settings_ldap_search_base', // HTML element ID
2386 + __( 'LDAP Search Base', 'authorizer' ), // HTML element Title
2387 + array( $this, 'print_text_ldap_search_base' ), // Callback (echos form element)
2388 + 'authorizer', // Page this setting is shown on (slug)
2389 + 'auth_settings_external' // Section this setting is shown on
2796 2390 );
2797 2391 add_settings_field(
2798 - 'auth_settings_ldap_uid',
2799 - __( 'LDAP attribute containing username', 'authorizer' ),
2800 - array( $this, 'print_text_ldap_uid' ),
2801 - 'authorizer',
2802 - 'auth_settings_external'
2392 + 'auth_settings_ldap_uid', // HTML element ID
2393 + __( 'LDAP attribute containing username', 'authorizer' ), // HTML element Title
2394 + array( $this, 'print_text_ldap_uid' ), // Callback (echos form element)
2395 + 'authorizer', // Page this setting is shown on (slug)
2396 + 'auth_settings_external' // Section this setting is shown on
2803 2397 );
2804 2398 add_settings_field(
2805 - 'auth_settings_ldap_attr_email',
2806 - __( 'LDAP attribute containing email address', 'authorizer' ),
2807 - array( $this, 'print_text_ldap_attr_email' ),
2808 - 'authorizer',
2809 - 'auth_settings_external'
2399 + 'auth_settings_ldap_attr_email', // HTML element ID
2400 + __( 'LDAP attribute containing email address', 'authorizer' ), // HTML element Title
2401 + array( $this, 'print_text_ldap_attr_email' ), // Callback (echos form element)
2402 + 'authorizer', // Page this setting is shown on (slug)
2403 + 'auth_settings_external' // Section this setting is shown on
2810 2404 );
2811 2405 add_settings_field(
2812 - 'auth_settings_ldap_user',
2813 - __( 'LDAP Directory User', 'authorizer' ),
2814 - array( $this, 'print_text_ldap_user' ),
2815 - 'authorizer',
2816 - 'auth_settings_external'
2406 + 'auth_settings_ldap_user', // HTML element ID
2407 + __( 'LDAP Directory User', 'authorizer' ), // HTML element Title
2408 + array( $this, 'print_text_ldap_user' ), // Callback (echos form element)
2409 + 'authorizer', // Page this setting is shown on (slug)
2410 + 'auth_settings_external' // Section this setting is shown on
2817 2411 );
2818 2412 add_settings_field(
2819 - 'auth_settings_ldap_password',
2820 - __( 'LDAP Directory User Password', 'authorizer' ),
2821 - array( $this, 'print_password_ldap_password' ),
2822 - 'authorizer',
2823 - 'auth_settings_external'
2413 + 'auth_settings_ldap_password', // HTML element ID
2414 + __( 'LDAP Directory User Password', 'authorizer' ), // HTML element Title
2415 + array( $this, 'print_password_ldap_password' ), // Callback (echos form element)
2416 + 'authorizer', // Page this setting is shown on (slug)
2417 + 'auth_settings_external' // Section this setting is shown on
2824 2418 );
2825 2419 add_settings_field(
2826 - 'auth_settings_ldap_lostpassword_url',
2827 - __( 'Custom lost password URL', 'authorizer' ),
2828 - array( $this, 'print_text_ldap_lostpassword_url' ),
2829 - 'authorizer',
2830 - 'auth_settings_external'
2420 + 'auth_settings_ldap_lostpassword_url', // HTML element ID
2421 + __( 'Custom lost password URL', 'authorizer' ), // HTML element Title
2422 + array( $this, 'print_text_ldap_lostpassword_url' ), // Callback (echos form element)
2423 + 'authorizer', // Page this setting is shown on (slug)
2424 + 'auth_settings_external' // Section this setting is shown on
2831 2425 );
2832 2426 add_settings_field(
2833 - 'auth_settings_ldap_attr_first_name',
2834 - __( 'LDAP attribute containing first name', 'authorizer' ),
2835 - array( $this, 'print_text_ldap_attr_first_name' ),
2836 - 'authorizer',
2837 - 'auth_settings_external'
2427 + 'auth_settings_ldap_attr_first_name', // HTML element ID
2428 + __( 'LDAP attribute containing first name', 'authorizer' ), // HTML element Title
2429 + array( $this, 'print_text_ldap_attr_first_name' ), // Callback (echos form element)
2430 + 'authorizer', // Page this setting is shown on (slug)
2431 + 'auth_settings_external' // Section this setting is shown on
2838 2432 );
2839 2433 add_settings_field(
2840 - 'auth_settings_ldap_attr_last_name',
2841 - __( 'LDAP attribute containing last name', 'authorizer' ),
2842 - array( $this, 'print_text_ldap_attr_last_name' ),
2843 - 'authorizer',
2844 - 'auth_settings_external'
2434 + 'auth_settings_ldap_attr_last_name', // HTML element ID
2435 + __( 'LDAP attribute containing last name', 'authorizer' ), // HTML element Title
2436 + array( $this, 'print_text_ldap_attr_last_name' ), // Callback (echos form element)
2437 + 'authorizer', // Page this setting is shown on (slug)
2438 + 'auth_settings_external' // Section this setting is shown on
2845 2439 );
2846 2440 add_settings_field(
2847 - 'auth_settings_ldap_attr_update_on_login',
2848 - __( 'LDAP attribute update', 'authorizer' ),
2849 - array( $this, 'print_checkbox_ldap_attr_update_on_login' ),
2850 - 'authorizer',
2851 - 'auth_settings_external'
2441 + 'auth_settings_ldap_attr_update_on_login', // HTML element ID
2442 + __( 'LDAP attribute update', 'authorizer' ), // HTML element Title
2443 + array( $this, 'print_checkbox_ldap_attr_update_on_login' ), // Callback (echos form element)
2444 + 'authorizer', // Page this setting is shown on (slug)
2445 + 'auth_settings_external' // Section this setting is shown on
2852 2446 );
2853 2447
2854 - // Create Advanced Settings section.
2448 + // Create Advanced Settings section
2855 2449 add_settings_section(
2856 - 'auth_settings_advanced',
2857 - '',
2858 - array( $this, 'print_section_info_advanced' ),
2859 - 'authorizer'
2450 + 'auth_settings_advanced', // HTML element ID
2451 + '', // HTML element Title
2452 + array( $this, 'print_section_info_advanced' ), // Callback (echos section content)
2453 + 'authorizer' // Page this section is shown on (slug)
2860 2454 );
2861 2455 add_settings_field(
2862 - 'auth_settings_advanced_lockouts',
2863 - __( 'Limit invalid login attempts', 'authorizer' ),
2864 - array( $this, 'print_text_auth_advanced_lockouts' ),
2865 - 'authorizer',
2866 - 'auth_settings_advanced'
2456 + 'auth_settings_advanced_lockouts', // HTML element ID
2457 + __( 'Limit invalid login attempts', 'authorizer' ), // HTML element Title
2458 + array( $this, 'print_text_auth_advanced_lockouts' ), // Callback (echos form element)
2459 + 'authorizer', // Page this setting is shown on (slug)
2460 + 'auth_settings_advanced' // Section this setting is shown on
2867 2461 );
2868 2462 add_settings_field(
2869 - 'auth_settings_advanced_hide_wp_login',
2870 - __( 'Hide WordPress Login', 'authorizer' ),
2871 - array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ),
2872 - 'authorizer',
2873 - 'auth_settings_advanced'
2463 + 'auth_settings_advanced_hide_wp_login', // HTML element ID
2464 + __( 'Hide WordPress Login', 'authorizer' ), // HTML element Title
2465 + array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ), // Callback (echos form element)
2466 + 'authorizer', // Page this setting is shown on (slug)
2467 + 'auth_settings_advanced' // Section this setting is shown on
2874 2468 );
2875 2469 add_settings_field(
2876 - 'auth_settings_advanced_branding',
2877 - __( 'Custom WordPress login branding', 'authorizer' ),
2878 - array( $this, 'print_radio_auth_advanced_branding' ),
2879 - 'authorizer',
2880 - 'auth_settings_advanced'
2470 + 'auth_settings_advanced_branding', // HTML element ID
2471 + __( 'Custom WordPress login branding', 'authorizer' ), // HTML element Title
2472 + array( $this, 'print_radio_auth_advanced_branding' ), // Callback (echos form element)
2473 + 'authorizer', // Page this setting is shown on (slug)
2474 + 'auth_settings_advanced' // Section this setting is shown on
2881 2475 );
2882 2476 add_settings_field(
2883 - 'auth_settings_advanced_admin_menu',
2884 - __( 'Authorizer admin menu item location', 'authorizer' ),
2885 - array( $this, 'print_radio_auth_advanced_admin_menu' ),
2886 - 'authorizer',
2887 - 'auth_settings_advanced'
2477 + 'auth_settings_advanced_admin_menu', // HTML element ID
2478 + __( 'Authorizer admin menu item location', 'authorizer' ), // HTML element Title
2479 + array( $this, 'print_radio_auth_advanced_admin_menu' ), // Callback (echos form element)
2480 + 'authorizer', // Page this setting is shown on (slug)
2481 + 'auth_settings_advanced' // Section this setting is shown on
2888 2482 );
2889 2483 add_settings_field(
2890 - 'auth_settings_advanced_usermeta',
2891 - __( 'Show custom usermeta in user list', 'authorizer' ),
2892 - array( $this, 'print_select_auth_advanced_usermeta' ),
2893 - 'authorizer',
2894 - 'auth_settings_advanced'
2484 + 'auth_settings_advanced_usermeta', // HTML element ID
2485 + __( 'Show custom usermeta in user list', 'authorizer' ), // HTML element Title
2486 + array( $this, 'print_select_auth_advanced_usermeta' ), // Callback (echos form element)
2487 + 'authorizer', // Page this setting is shown on (slug)
2488 + 'auth_settings_advanced' // Section this setting is shown on
2895 2489 );
2896 - add_settings_field(
2897 - 'auth_settings_advanced_users_per_page',
2898 - __( 'Number of users per page', 'authorizer' ),
2899 - array( $this, 'print_text_auth_advanced_users_per_page' ),
2900 - 'authorizer',
2901 - 'auth_settings_advanced'
2902 - );
2903 - add_settings_field(
2904 - 'auth_settings_advanced_users_sort_by',
2905 - __( 'Approved users sort method', 'authorizer' ),
2906 - array( $this, 'print_select_auth_advanced_users_sort_by' ),
2907 - 'authorizer',
2908 - 'auth_settings_advanced'
2909 - );
2910 - add_settings_field(
2911 - 'auth_settings_advanced_users_sort_order',
2912 - __( 'Approved users sort order', 'authorizer' ),
2913 - array( $this, 'print_select_auth_advanced_users_sort_order' ),
2914 - 'authorizer',
2915 - 'auth_settings_advanced'
2916 - );
2917 - add_settings_field(
2918 - 'auth_settings_advanced_widget_enabled',
2919 - __( 'Show dashboard widget to admin users', 'authorizer' ),
2920 - array( $this, 'print_checkbox_auth_advanced_widget_enabled' ),
2921 - 'authorizer',
2922 - 'auth_settings_advanced'
2923 - );
2924 2490 // On multisite installs, add an option to override all multisite settings on individual sites.
2925 2491 if ( is_multisite() ) {
2926 2492 add_settings_field(
2927 - 'auth_settings_advanced_override_multisite',
2928 - __( 'Override multisite options', 'authorizer' ),
2929 - array( $this, 'print_checkbox_auth_advanced_override_multisite' ),
2930 - 'authorizer',
2931 - 'auth_settings_advanced'
2493 + 'auth_settings_advanced_override_multisite', // HTML element ID
2494 + __( 'Override multisite options', 'authorizer' ), // HTML element Title
2495 + array( $this, 'print_checkbox_auth_advanced_override_multisite' ), // Callback (echos form element)
2496 + 'authorizer', // Page this setting is shown on (slug)
2497 + 'auth_settings_advanced' // Section this setting is shown on
2932 2498 );
2933 2499 }
2934 2500 }
2935 2501
@@ -2935,30 +2501,29 @@
2935 2501
2936 2502
2937 2503 /**
2938 2504 * Set meaningful defaults for the plugin options.
2939 - *
2940 2505 * Note: This function is called on plugin activation.
2941 2506 */
2942 - private function set_default_options() {
2507 + function set_default_options() {
2943 2508 global $wp_roles;
2944 2509
2945 2510 $auth_settings = get_option( 'auth_settings' );
2946 - if ( false === $auth_settings ) {
2511 + if ( $auth_settings === FALSE ) {
2947 2512 $auth_settings = array();
2948 2513 }
2949 2514
2950 2515 // Access Lists Defaults.
2951 2516 $auth_settings_access_users_pending = get_option( 'auth_settings_access_users_pending' );
2952 - if ( false === $auth_settings_access_users_pending ) {
2517 + if ( $auth_settings_access_users_pending === FALSE ) {
2953 2518 $auth_settings_access_users_pending = array();
2954 2519 }
2955 2520 $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
2956 - if ( false === $auth_settings_access_users_approved ) {
2521 + if ( $auth_settings_access_users_approved === FALSE ) {
2957 2522 $auth_settings_access_users_approved = array();
2958 2523 }
2959 2524 $auth_settings_access_users_blocked = get_option( 'auth_settings_access_users_blocked' );
2960 - if ( false === $auth_settings_access_users_blocked ) {
2525 + if ( $auth_settings_access_users_blocked === FALSE ) {
2961 2526 $auth_settings_access_users_blocked = array();
2962 2527 }
2963 2528
2964 2529 // Login Access Defaults.
@@ -3010,12 +2575,13 @@
3010 2575 if ( ! array_key_exists( 'access_redirect_to_message', $auth_settings ) ) {
3011 2576 $auth_settings['access_redirect_to_message'] = '<p>' . __( 'Notice: You are browsing this site anonymously, and only have access to a portion of its content.', 'authorizer' ) . '</p>';
3012 2577 }
3013 2578
2579 +
3014 2580 // External Service Defaults.
3015 2581 if ( ! array_key_exists( 'access_default_role', $auth_settings ) ) {
3016 2582 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3017 - $all_roles = $wp_roles->roles;
2583 + $all_roles = $wp_roles->roles;
3018 2584 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3019 2585 if ( array_key_exists( 'student', $editable_roles ) ) {
3020 2586 $auth_settings['access_default_role'] = 'student';
3021 2587 } else {
@@ -3113,12 +2679,12 @@
3113 2679
3114 2680 // Advanced defaults.
3115 2681 if ( ! array_key_exists( 'advanced_lockouts', $auth_settings ) ) {
3116 2682 $auth_settings['advanced_lockouts'] = array(
3117 - 'attempts_1' => 10,
3118 - 'duration_1' => 1,
3119 - 'attempts_2' => 10,
3120 - 'duration_2' => 10,
2683 + 'attempts_1' => 10,
2684 + 'duration_1' => 1,
2685 + 'attempts_2' => 10,
2686 + 'duration_2' => 10,
3121 2687 'reset_duration' => 120,
3122 2688 );
3123 2689 }
3124 2690 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_settings ) ) {
@@ -3132,20 +2698,8 @@
3132 2698 }
3133 2699 if ( ! array_key_exists( 'advanced_usermeta', $auth_settings ) ) {
3134 2700 $auth_settings['advanced_usermeta'] = '';
3135 2701 }
3136 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_settings ) ) {
3137 - $auth_settings['advanced_users_per_page'] = 20;
3138 - }
3139 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_settings ) ) {
3140 - $auth_settings['advanced_users_sort_by'] = 'created';
3141 - }
3142 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_settings ) ) {
3143 - $auth_settings['advanced_users_sort_order'] = 'asc';
3144 - }
3145 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_settings ) ) {
3146 - $auth_settings['advanced_widget_enabled'] = '1';
3147 - }
3148 2702 if ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) ) {
3149 2703 $auth_settings['advanced_override_multisite'] = '';
3150 2704 }
3151 2705
@@ -3156,11 +2710,11 @@
3156 2710 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
3157 2711
3158 2712 // Multisite defaults.
3159 2713 if ( is_multisite() ) {
3160 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
2714 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
3161 2715
3162 - if ( false === $auth_multisite_settings ) {
2716 + if ( $auth_multisite_settings === FALSE ) {
3163 2717 $auth_multisite_settings = array();
3164 2718 }
3165 2719 // Global switch for enabling multisite options.
3166 2720 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
@@ -3166,10 +2720,10 @@
3166 2720 if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) {
3167 2721 $auth_multisite_settings['multisite_override'] = '';
3168 2722 }
3169 2723 // Access Lists Defaults.
3170 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved' );
3171 - if ( false === $auth_multisite_settings_access_users_approved ) {
2724 + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved' );
2725 + if ( $auth_multisite_settings_access_users_approved === FALSE ) {
3172 2726 $auth_multisite_settings_access_users_approved = array();
3173 2727 }
3174 2728 // Login Access Defaults.
3175 2729 if ( ! array_key_exists( 'access_who_can_login', $auth_multisite_settings ) ) {
@@ -3181,9 +2735,9 @@
3181 2735 }
3182 2736 // External Service Defaults.
3183 2737 if ( ! array_key_exists( 'access_default_role', $auth_multisite_settings ) ) {
3184 2738 // Set default role to 'student' if that role exists, 'subscriber' otherwise.
3185 - $all_roles = $wp_roles->roles;
2739 + $all_roles = $wp_roles->roles;
3186 2740 $editable_roles = apply_filters( 'editable_roles', $all_roles );
3187 2741 if ( array_key_exists( 'student', $editable_roles ) ) {
3188 2742 $auth_multisite_settings['access_default_role'] = 'student';
3189 2743 } else {
@@ -3276,12 +2830,12 @@
3276 2830 }
3277 2831 // Advanced defaults.
3278 2832 if ( ! array_key_exists( 'advanced_lockouts', $auth_multisite_settings ) ) {
3279 2833 $auth_multisite_settings['advanced_lockouts'] = array(
3280 - 'attempts_1' => 10,
3281 - 'duration_1' => 1,
3282 - 'attempts_2' => 10,
3283 - 'duration_2' => 10,
2834 + 'attempts_1' => 10,
2835 + 'duration_1' => 1,
2836 + 'attempts_2' => 10,
2837 + 'duration_2' => 10,
3284 2838 'reset_duration' => 120,
3285 2839 );
3286 2840 }
3287 2841 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
@@ -3286,23 +2840,11 @@
3286 2840 }
3287 2841 if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) {
3288 2842 $auth_multisite_settings['advanced_hide_wp_login'] = '';
3289 2843 }
3290 - if ( ! array_key_exists( 'advanced_users_per_page', $auth_multisite_settings ) ) {
3291 - $auth_multisite_settings['advanced_users_per_page'] = 20;
3292 - }
3293 - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_multisite_settings ) ) {
3294 - $auth_multisite_settings['advanced_users_sort_by'] = 'created';
3295 - }
3296 - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_multisite_settings ) ) {
3297 - $auth_multisite_settings['advanced_users_sort_order'] = 'asc';
3298 - }
3299 - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_multisite_settings ) ) {
3300 - $auth_multisite_settings['advanced_widget_enabled'] = '1';
3301 - }
3302 2844 // Save default network options to database.
3303 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
3304 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
2845 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
2846 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3305 2847 }
3306 2848
3307 2849 return $auth_settings;
3308 2850 }
@@ -3309,15 +2851,12 @@
3309 2851
3310 2852
3311 2853 /**
3312 2854 * List sanitizer.
3313 - *
3314 - * @param array $list Array of users to sanitize.
3315 - * @param string $side_effect Set to 'update roles' if role syncing should be performed.
3316 - * @param string $multisite_mode Set to 'multisite' to sync roles on all sites the user belongs to.
3317 - * @return array Array of sanitized users.
2855 + * $side_effect = 'none' or 'update roles' to make sure WP user roles match
2856 + * $multisite_mode = 'single' or 'multisite' to indicate which user roles to change (this site or all sites)
3318 2857 */
3319 - private function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
2858 + function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) {
3320 2859 // If it's not a list, make it so.
3321 2860 if ( ! is_array( $list ) ) {
3322 2861 $list = array();
3323 2862 }
@@ -3322,16 +2861,16 @@
3322 2861 $list = array();
3323 2862 }
3324 2863 foreach ( $list as $key => $user_info ) {
3325 2864 if ( strlen( $user_info['email'] ) < 1 ) {
3326 - // Make sure there are no empty entries in the list.
3327 - unset( $list[ $key ] );
3328 - } elseif ( 'update roles' === $side_effect ) {
2865 + // Make sure there are no empty entries in the list
2866 + unset( $list[$key] );
2867 + } elseif ( $side_effect === 'update roles' ) {
3329 2868 // Make sure the WordPress user accounts have the same role
3330 2869 // as that indicated in the list.
3331 2870 $wp_user = get_user_by( 'email', $user_info['email'] );
3332 2871 if ( $wp_user ) {
3333 - if ( is_multisite() && 'multisite' === $multisite_mode ) {
2872 + if ( is_multisite() && $multisite_mode === 'multisite' ) {
3334 2873 foreach ( get_blogs_of_user( $wp_user->ID ) as $blog ) {
3335 2874 add_user_to_blog( $blog->userblog_id, $wp_user->ID, $user_info['role'] );
3336 2875 }
3337 2876 } else {
@@ -3344,21 +2883,18 @@
3344 2883 }
3345 2884
3346 2885
3347 2886 /**
3348 - * Settings sanitizer callback.
3349 - *
3350 - * @param array $auth_settings Authorizer settings array.
3351 - * @return array Sanitized Authorizer settings array.
2887 + * Settings sanitizer callback
3352 2888 */
3353 - public function sanitize_options( $auth_settings ) {
2889 + function sanitize_options( $auth_settings ) {
3354 2890 // Default to "Approved Users" login access restriction.
3355 - if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ), true ) ) {
2891 + if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ) ) ) {
3356 2892 $auth_settings['access_who_can_login'] = 'approved_users';
3357 2893 }
3358 2894
3359 2895 // Default to "Everyone" view access restriction.
3360 - if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ), true ) ) {
2896 + if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ) ) ) {
3361 2897 $auth_settings['access_who_can_view'] = 'everyone';
3362 2898 }
3363 2899
3364 2900 // Default to WordPress login access redirect.
@@ -3363,9 +2899,9 @@
3363 2899
3364 2900 // Default to WordPress login access redirect.
3365 2901 // Note: this option doesn't exist in multisite options, so we first
3366 2902 // check to see if it exists.
3367 - if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ), true ) ) {
2903 + if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ) ) ) {
3368 2904 $auth_settings['access_redirect'] = 'login';
3369 2905 }
3370 2906
3371 2907 // Default to warning message for anonymous users on public pages.
@@ -3370,61 +2906,61 @@
3370 2906
3371 2907 // Default to warning message for anonymous users on public pages.
3372 2908 // Note: this option doesn't exist in multisite options, so we first
3373 2909 // check to see if it exists.
3374 - if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ), true ) ) {
2910 + if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ) ) ) {
3375 2911 $auth_settings['access_public_warning'] = 'no_warning';
3376 2912 }
3377 2913
3378 - // Sanitize Send welcome email (checkbox: value can only be '1' or empty string).
2914 + // Sanitize Send welcome email (checkbox: value can only be '1' or empty string)
3379 2915 $auth_settings['access_should_email_approved_users'] = array_key_exists( 'access_should_email_approved_users', $auth_settings ) && strlen( $auth_settings['access_should_email_approved_users'] ) > 0 ? '1' : '';
3380 2916
3381 - // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string).
2917 + // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string)
3382 2918 $auth_settings['google'] = array_key_exists( 'google', $auth_settings ) && strlen( $auth_settings['google'] ) > 0 ? '1' : '';
3383 2919
3384 - // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string).
2920 + // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string)
3385 2921 $auth_settings['cas'] = array_key_exists( 'cas', $auth_settings ) && strlen( $auth_settings['cas'] ) > 0 ? '1' : '';
3386 2922
3387 - // Sanitize CAS Host setting.
2923 + // Sanitize CAS Host setting
3388 2924 $auth_settings['cas_host'] = filter_var( $auth_settings['cas_host'], FILTER_SANITIZE_URL );
3389 2925
3390 - // Sanitize CAS Port (int).
2926 + // Sanitize CAS Port (int)
3391 2927 $auth_settings['cas_port'] = filter_var( $auth_settings['cas_port'], FILTER_SANITIZE_NUMBER_INT );
3392 2928
3393 - // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string).
2929 + // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string)
3394 2930 $auth_settings['cas_attr_update_on_login'] = array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['cas_attr_update_on_login'] ) > 0 ? '1' : '';
3395 2931
3396 - // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string).
2932 + // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string)
3397 2933 $auth_settings['cas_auto_login'] = array_key_exists( 'cas_auto_login', $auth_settings ) && strlen( $auth_settings['cas_auto_login'] ) > 0 ? '1' : '';
3398 2934
3399 - // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string).
2935 + // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string)
3400 2936 $auth_settings['ldap'] = array_key_exists( 'ldap', $auth_settings ) && strlen( $auth_settings['ldap'] ) > 0 ? '1' : '';
3401 2937
3402 - // Sanitize LDAP Host setting.
2938 + // Sanitize LDAP Host setting
3403 2939 $auth_settings['ldap_host'] = filter_var( $auth_settings['ldap_host'], FILTER_SANITIZE_URL );
3404 2940
3405 - // Sanitize LDAP Port (int).
2941 + // Sanitize LDAP Port (int)
3406 2942 $auth_settings['ldap_port'] = filter_var( $auth_settings['ldap_port'], FILTER_SANITIZE_NUMBER_INT );
3407 2943
3408 - // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string).
2944 + // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string)
3409 2945 $auth_settings['ldap_tls'] = array_key_exists( 'ldap_tls', $auth_settings ) && strlen( $auth_settings['ldap_tls'] ) > 0 ? '1' : '';
3410 2946
3411 - // Sanitize LDAP attributes (basically make sure they don't have any parentheses).
2947 + // Sanitize LDAP attributes (basically make sure they don't have any parentheses)
3412 2948 $auth_settings['ldap_uid'] = filter_var( $auth_settings['ldap_uid'], FILTER_SANITIZE_EMAIL );
3413 2949
3414 - // Sanitize LDAP Lost Password URL.
2950 + // Sanitize LDAP Lost Password URL
3415 2951 $auth_settings['ldap_lostpassword_url'] = filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_SANITIZE_URL );
3416 2952
3417 - // Obfuscate LDAP directory user password.
2953 + // Obfuscate LDAP directory user password
3418 2954 if ( strlen( $auth_settings['ldap_password'] ) > 0 ) {
3419 2955 // encrypt the directory user password for some minor obfuscation in the database.
3420 - $auth_settings['ldap_password'] = $this->encrypt( $auth_settings['ldap_password'] );
2956 + $auth_settings['ldap_password'] = base64_encode( $this->encrypt( $auth_settings['ldap_password'] ) );
3421 2957 }
3422 2958
3423 - // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string).
2959 + // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string)
3424 2960 $auth_settings['ldap_attr_update_on_login'] = array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['ldap_attr_update_on_login'] ) > 0 ? '1' : '';
3425 2961
3426 - // Make sure public pages is an empty array if it's empty.
2962 + // Make sure public pages is an empty array if it's empty
3427 2963 // Note: this option doesn't exist in multisite options, so we first
3428 2964 // check to see if it exists.
3429 2965 if ( array_key_exists( 'access_public_pages', $auth_settings ) && ! is_array( $auth_settings['access_public_pages'] ) ) {
3430 2966 $auth_settings['access_public_pages'] = array();
@@ -3432,31 +2968,15 @@
3432 2968
3433 2969 // Make sure all lockout options are integers (attempts_1,
3434 2970 // duration_1, attempts_2, duration_2, reset_duration).
3435 2971 foreach ( $auth_settings['advanced_lockouts'] as $key => $value ) {
3436 - $auth_settings['advanced_lockouts'][ $key ] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
2972 + $auth_settings['advanced_lockouts'][$key] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT );
3437 2973 }
3438 2974
3439 - // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string).
2975 + // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string)
3440 2976 $auth_settings['advanced_hide_wp_login'] = array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && strlen( $auth_settings['advanced_hide_wp_login'] ) > 0 ? '1' : '';
3441 2977
3442 - // Sanitize Users per page (text: value can only int from 1 to MAX_INT).
3443 - $auth_settings['advanced_users_per_page'] = array_key_exists( 'advanced_users_per_page', $auth_settings ) && intval( $auth_settings['advanced_users_per_page'] ) > 0 ? intval( $auth_settings['advanced_users_per_page'] ) : 1;
3444 -
3445 - // Sanitize Sort users by (select: value can be 'email', 'role', 'date_added', 'created').
3446 - if ( ! isset( $auth_settings['advanced_users_sort_by'] ) || ! in_array( $auth_settings['advanced_users_sort_by'], array( 'email', 'role', 'date_added', 'created' ), true ) ) {
3447 - $auth_settings['advanced_users_sort_by'] = 'created';
3448 - }
3449 -
3450 - // Sanitize Sort users order (select: value can be 'asc', 'desc').
3451 - if ( ! isset( $auth_settings['advanced_users_sort_order'] ) || ! in_array( $auth_settings['advanced_users_sort_order'], array( 'asc', 'desc' ), true ) ) {
3452 - $auth_settings['advanced_users_sort_order'] = 'asc';
3453 - }
3454 -
3455 - // Sanitize Show Dashboard Widget (checkbox: value can only be '1' or empty string).
3456 - $auth_settings['advanced_widget_enabled'] = array_key_exists( 'advanced_widget_enabled', $auth_settings ) && strlen( $auth_settings['advanced_widget_enabled'] ) > 0 ? '1' : '';
3457 -
3458 - // Sanitize Override multisite options (checkbox: value can only be '1' or empty string).
2978 + // Sanitize Override multisite options (checkbox: value can only be '1' or empty string)
3459 2979 $auth_settings['advanced_override_multisite'] = array_key_exists( 'advanced_override_multisite', $auth_settings ) && strlen( $auth_settings['advanced_override_multisite'] ) > 0 ? '1' : '';
3460 2980
3461 2981 return $auth_settings;
3462 2982 }
@@ -3463,201 +2983,90 @@
3463 2983
3464 2984
3465 2985 /**
3466 2986 * Keep authorizer approved users' roles in sync with WordPress roles
3467 - * if someone changes the role via the WordPress Edit User page
3468 - * (wp-admin/user-edit.php or wp-admin/profile.php).
2987 + * if someone changes the role via the WordPress Edit User options page.
3469 2988 *
3470 - * Action: user_profile_update_errors
3471 - *
3472 - * @param WP_Error $errors Errors object to add any custom errors to (passed by reference).
3473 - * @param bool $update True if updating existing user, false if saving a new one.
3474 - * @param stdClass $user Updated WP_User object for user being edited (passed by reference).
2989 + * @action edit_user_profile_update
2990 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/edit_user_profile_update
2991 + * @param int $user_id The user ID of the user being edited
2992 +
2993 + * @action personal_options_update
2994 + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/personal_options_update
2995 + * @param int $user_id The user ID of the user being edited
3475 2996 */
3476 - public function edit_user_profile_update_role( &$errors, $update, &$user ) {
3477 - // Do nothing if we're not updating role.
3478 - if ( ! property_exists( $user, 'role' ) ) {
2997 + function edit_user_profile_update_role( $user_id ) {
2998 + if ( ! current_user_can( 'edit_user', $user_id ) ) {
3479 2999 return;
3480 3000 }
3481 3001
3482 - // Safety check; will likely not fire if we reach this function.
3483 - if ( ! current_user_can( 'edit_user', $user->ID ) ) {
3484 - return;
3485 - }
3486 -
3487 - // Don't perform Authorizer updates if we have a WordPress error.
3488 - $errors_on_user_update = $errors->get_error_codes();
3489 - if ( ! empty( $errors_on_user_update ) ) {
3490 - return;
3491 - }
3492 -
3493 - // Get original user object (fail if not a real WordPress user).
3494 - $userdata = get_userdata( $user->ID );
3495 - if ( ! $userdata ) {
3496 - return;
3497 - }
3498 -
3499 3002 // If user is in approved list, update his/her associated role.
3500 - if ( $this->is_email_in_list( $userdata->user_email, 'approved' ) ) {
3501 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3502 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3503 - if ( 0 === strcasecmp( $check_user['email'], $userdata->user_email ) ) {
3504 - $auth_settings_access_users_approved[ $key ]['role'] = $user->role;
3505 - }
3506 - }
3507 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3508 - }
3509 - }
3510 -
3511 -
3512 - /**
3513 - * Sync any email address changes to WordPress accounts to the corresponding
3514 - * entry in the Authorizer approved list.
3515 - *
3516 - * Note: This filter fires in wp_update_user() if the update includes an
3517 - * email address change, and fires after all security and integrity checks
3518 - * have been performed, so we can simply update the Authorizer approved
3519 - * list, changing the email address on the approved entry, and removing any
3520 - * existing entries that also have the new email address (duplicates).
3521 - *
3522 - * Filter: send_email_change_email
3523 - *
3524 - * @param bool $send Whether to send the email.
3525 - * @param array $user The original user array.
3526 - * @param array $userdata The updated user array.
3527 - */
3528 - public function edit_user_profile_update_email( $send, $user, $userdata ) {
3529 - // If we're in multisite, update the email on all sites in the network
3530 - // (and remove from any subsites if it's a network-approved user).
3531 - if ( is_multisite() ) {
3532 - // If it's a multisite approved user, sync the email there.
3533 - $changed_user_is_multisite_user = false;
3534 - if ( $this->is_email_in_list( $user['user_email'], 'approved', 'multisite' ) ) {
3535 - $changed_user_is_multisite_user = true;
3536 - $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
3537 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
3538 - );
3539 - foreach ( $auth_multisite_settings_access_users_approved as $key => $check_user ) {
3540 - // Update old user email in approved list to the new email.
3541 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3542 - $auth_multisite_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3003 + $wp_user = get_user_by( 'id', $user_id );
3004 + if ( $this->is_email_in_list( $wp_user->get( 'user_email' ), 'approved' ) ) {
3005 + $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) );
3006 + // Find approved user and sync with the corresponding WP_User.
3007 + foreach ( $auth_settings_access_users_approved as $key => $user ) {
3008 + if ( $user['email'] === $wp_user->user_email ) {
3009 + // Sync user role.
3010 + if ( array_key_exists( 'role', $_REQUEST ) ) {
3011 + $auth_settings_access_users_approved[$key]['role'] = $_REQUEST['role'];
3543 3012 }
3544 - // If new user email is already in approved list, remove that entry.
3545 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3546 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
3013 + // Sync email address.
3014 + if ( array_key_exists( 'email', $_REQUEST ) ) {
3015 + $auth_settings_access_users_approved[$key]['email'] = $_REQUEST['email'];
3547 3016 }
3548 3017 }
3549 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
3550 3018 }
3551 3019
3552 - // Go through all approved lists on individual sites and sync this user there.
3553 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
3554 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
3555 - foreach ( $sites as $site ) {
3556 - $updated = false;
3557 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
3558 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
3559 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3560 - // Update old user email in approved list to the new email.
3561 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3562 - // But if the user is already a multisite user, just remove the entry in the subsite.
3563 - if ( $changed_user_is_multisite_user ) {
3564 - unset( $auth_settings_access_users_approved[ $key ] );
3565 - } else {
3566 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3567 - }
3568 - $updated = true;
3569 - }
3570 - // If new user email is already in approved list, remove that entry.
3571 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3572 - unset( $auth_settings_access_users_approved[ $key ] );
3573 - $updated = true;
3574 - }
3575 - }
3576 - if ( $updated ) {
3577 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3578 - }
3579 - }
3580 - } else {
3581 - // In a single site environment, just find the old user in the approved list and update the email.
3582 - if ( $this->is_email_in_list( $user['user_email'], 'approved' ) ) {
3583 - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
3584 - foreach ( $auth_settings_access_users_approved as $key => $check_user ) {
3585 - // Update old user email in approved list to the new email.
3586 - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) {
3587 - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] );
3588 - }
3589 - // If new user email is already in approved list, remove that entry.
3590 - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) {
3591 - unset( $auth_settings_access_users_approved[ $key ] );
3592 - }
3593 - }
3594 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3595 - }
3020 + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
3596 3021 }
3597 -
3598 - // We're hooking into this filter merely for its location in the codebase,
3599 - // so make sure to return the filter value unmodified.
3600 - return $send;
3601 3022 }
3602 3023
3603 3024
3604 3025 /**
3605 - * Settings print callback.
3606 - *
3607 - * @param string $args Args (e.g., multisite admin mode).
3608 - * @return void
3026 + * Settings print callbacks
3609 3027 */
3610 - public function print_section_info_tabs( $args = '' ) {
3611 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $this->get_admin_mode( $args ) ) :
3612 - ?>
3028 + function print_section_info_tabs( $args = '' ) {
3029 + if ( MULTISITE_ADMIN === $this->get_admin_mode( $args )): ?>
3613 3030 <h2 class="nav-tab-wrapper">
3614 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3615 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3616 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3031 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3032 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3033 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3617 3034 </h2>
3618 - <?php else : ?>
3035 + <?php else: ?>
3619 3036 <h2 class="nav-tab-wrapper">
3620 - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a>
3621 - <a class="nav-tab nav-tab-access_login" href="javascript:chooseTab('access_login' );"><?php esc_html_e( 'Login Access', 'authorizer' ); ?></a>
3622 - <a class="nav-tab nav-tab-access_public" href="javascript:chooseTab('access_public' );"><?php esc_html_e( 'Public Access', 'authorizer' ); ?></a>
3623 - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a>
3624 - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a>
3037 + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a>
3038 + <a class="nav-tab nav-tab-access_login" href="javascript:choose_tab('access_login' );"><?php _e( 'Login Access', 'authorizer' ); ?></a>
3039 + <a class="nav-tab nav-tab-access_public" href="javascript:choose_tab('access_public' );"><?php _e( 'Public Access', 'authorizer' ); ?></a>
3040 + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a>
3041 + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a>
3625 3042 </h2>
3626 - <?php
3627 - endif;
3043 + <?php endif;
3628 3044 }
3629 3045
3630 3046
3631 - /**
3632 - * Settings print callback.
3633 - *
3634 - * @param string $args Args (e.g., multisite admin mode).
3635 - * @return void
3636 - */
3637 - public function print_section_info_access_lists( $args = '' ) {
3047 + function print_section_info_access_lists( $args = '' ) {
3638 3048 $admin_mode = $this->get_admin_mode( $args );
3639 - ?>
3640 - <div id="section_info_access_lists" class="section_info">
3641 - <p><?php esc_html_e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3049 + ?><div id="section_info_access_lists" class="section_info">
3050 + <p><?php _e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p>
3642 3051 <ol>
3643 - <li><?php echo wp_kses( __( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ), $this->allowed_html ); ?></li>
3644 - <li><?php echo wp_kses( __( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ), $this->allowed_html ); ?></li>
3645 - <li><?php echo wp_kses( __( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ), $this->allowed_html ); ?></li>
3052 + <li><?php _e( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ); ?></li>
3053 + <li><?php _e( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ); ?></li>
3054 + <li><?php _e( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ); ?></li>
3646 3055 </ol>
3647 3056 </div>
3648 3057 <table class="form-table">
3649 3058 <tbody>
3650 3059 <tr>
3651 - <th scope="row"><?php esc_html_e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'pending', $admin_mode ) ); ?>)</em></th>
3060 + <th scope="row"><?php _e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'pending', $admin_mode ); ?>)</em></th>
3652 3061 <td><?php $this->print_combo_auth_access_users_pending(); ?></td>
3653 3062 </tr>
3654 3063 <tr>
3655 - <th scope="row"><?php esc_html_e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'approved', $admin_mode ) ); ?>)</em></th>
3064 + <th scope="row"><?php _e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'approved', $admin_mode ); ?>)</em></th>
3656 3065 <td><?php $this->print_combo_auth_access_users_approved(); ?></td>
3657 3066 </tr>
3658 3067 <tr>
3659 - <th scope="row"><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'blocked', $admin_mode ) ); ?>)</em></th>
3068 + <th scope="row"><?php _e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'blocked', $admin_mode ); ?>)</em></th>
3660 3069 <td><?php $this->print_combo_auth_access_users_blocked(); ?></td>
3661 3070 </tr>
3662 3071 </tbody>
3663 3072 </table>
@@ -3664,516 +3073,276 @@
3664 3073 <?php
3665 3074 }
3666 3075
3667 3076
3668 - /**
3669 - * Settings print callback.
3670 - *
3671 - * @param string $args Args (e.g., multisite admin mode).
3672 - * @return void
3673 - */
3674 - public function print_combo_auth_access_users_pending( $args = '' ) {
3077 + function print_combo_auth_access_users_pending( $args = '' ) {
3675 3078 // Get plugin option.
3676 - $option = 'access_users_pending';
3079 + $option = 'access_users_pending';
3677 3080 $auth_settings_option = $this->get_plugin_option( $option );
3678 3081 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3679 3082
3680 - // Render wrapper div (for aligning pager to width of content).
3681 - ?>
3682 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3683 - <ul id="list_auth_settings_access_users_pending" style="margin:0;">
3684 - <?php
3685 - if ( count( $auth_settings_option ) > 0 ) :
3686 - foreach ( $auth_settings_option as $key => $pending_user ) :
3687 - if ( empty( $pending_user ) || count( $pending_user ) < 1 ) :
3688 - continue;
3689 - endif;
3690 - $pending_user['is_wp_user'] = false;
3691 - ?>
3692 - <li>
3693 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $pending_user['email'] ); ?>" readonly="true" class="auth-email" />
3694 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
3695 - <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3696 - </select>
3697 - <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'approved', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3698 - <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'blocked', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
3699 - <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'pending' );" title="<?php esc_html_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php esc_html_e( 'Ignore', 'authorizer' ); ?></a>
3700 - </li>
3701 - <?php endforeach; ?>
3702 - <?php else : ?>
3703 - <li class="auth-empty"><em><?php esc_html_e( 'No pending users', 'authorizer' ); ?></em></li>
3704 - <?php endif; ?>
3705 - </ul>
3706 - </div>
3083 + // Print option elements.
3084 + ?><ul id="list_auth_settings_access_users_pending" style="margin:0;">
3085 + <?php if ( count( $auth_settings_option ) > 0 ) : ?>
3086 + <?php foreach ( $auth_settings_option as $key => $pending_user ): ?>
3087 + <?php if ( empty( $pending_user ) || count( $pending_user ) < 1 ) continue; ?>
3088 + <?php $pending_user['is_wp_user'] = false; ?>
3089 + <li>
3090 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $pending_user['email']; ?>" readonly="true" class="auth-email" />
3091 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3092 + <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?>
3093 + </select>
3094 + <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'approved', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3095 + <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'blocked', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
3096 + <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user( this, 'pending' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php _e( 'Ignore', 'authorizer' ); ?></a>
3097 + </li>
3098 + <?php endforeach; ?>
3099 + <?php else: ?>
3100 + <li class="auth-empty"><em><?php _e( 'No pending users', 'authorizer' ); ?></em></li>
3101 + <?php endif; ?>
3102 + </ul>
3707 3103 <?php
3708 3104 }
3709 3105
3710 3106
3711 - /**
3712 - * Settings print callback.
3713 - *
3714 - * @param string $args Args (e.g., multisite admin mode).
3715 - * @return void
3716 - */
3717 - public function print_combo_auth_access_users_approved( $args = '' ) {
3107 + function print_combo_auth_access_users_approved( $args = '' ) {
3718 3108 // Get plugin option.
3719 - $option = 'access_users_approved';
3720 - $admin_mode = $this->get_admin_mode( $args );
3109 + $option = 'access_users_approved';
3110 + $admin_mode = $this->get_admin_mode( $args );
3721 3111 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
3722 3112 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
3723 3113
3724 - // Get multisite approved users (will be added to top of list, greyed out).
3725 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3726 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
3114 + // Get multisite approved users (add them to top of list, greyed out).
3115 + $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
3116 + $auth_multisite_settings = $this->get_plugin_options( MULTISITE_ADMIN );
3727 3117 $auth_settings_option_multisite = array();
3728 3118 if (
3729 3119 is_multisite() &&
3730 - ! is_network_admin() &&
3731 - '1' !== intval( $auth_override_multisite ) &&
3120 + $auth_override_multisite != '1' &&
3732 3121 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
3733 - '1' === $auth_multisite_settings['multisite_override']
3122 + $auth_multisite_settings['multisite_override'] === '1'
3734 3123 ) {
3735 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
3124 + $auth_settings_option_multisite = $this->get_plugin_option( $option, MULTISITE_ADMIN, 'allow override' );
3736 3125 $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
3737 - // Add multisite users to the beginning of the main user array.
3738 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
3739 - $approved_user['multisite_user'] = true;
3740 - array_unshift( $auth_settings_option, $approved_user );
3741 - }
3742 3126 }
3743 3127
3744 3128 // Get default role for new user dropdown.
3745 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3129 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
3746 3130
3747 3131 // Get custom usermeta field to show.
3748 3132 $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
3749 3133
3750 3134 // Adjust javascript function prefixes if multisite.
3751 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3752 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3135 + $js_function_prefix = $admin_mode === MULTISITE_ADMIN ? 'auth_multisite_' : 'auth_';
3136 + $multisite_admin_page = $admin_mode === MULTISITE_ADMIN;
3753 3137
3754 - // Filter user list to search terms.
3755 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3756 - if ( isset( $_REQUEST['search'] ) && strlen( sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) ) > 0 ) {
3757 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3758 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
3759 - $auth_settings_option = array_filter(
3760 - $auth_settings_option, function ( $user ) use ( $search_term ) {
3761 - return stripos( $user['email'], $search_term ) !== false ||
3762 - stripos( $user['role'], $search_term ) !== false ||
3763 - stripos( $user['date_added'], $search_term ) !== false;
3764 - }
3765 - );
3766 - }
3767 -
3768 - // Sort user list.
3769 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
3770 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
3771 - $sort_dimension = array();
3772 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
3773 - foreach ( $auth_settings_option as $key => $user ) {
3774 - if ( 'date_added' === $sort_by ) {
3775 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
3776 - } else {
3777 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
3778 - }
3779 - }
3780 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
3781 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
3782 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
3783 - // If default sort method and reverse order, just reverse the array.
3784 - $auth_settings_option = array_reverse( $auth_settings_option );
3785 - }
3786 -
3787 - // Ensure array keys run from 0..max (keys in database will be the original,
3788 - // index, and removing users will not reorder the array keys of other users).
3789 - $auth_settings_option = array_values( $auth_settings_option );
3790 -
3791 - // Get pager params.
3792 - $total_users = count( $auth_settings_option );
3793 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
3794 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3795 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
3796 - $total_pages = ceil( $total_users / $users_per_page );
3797 - if ( $total_pages < 1 ) {
3798 - $total_pages = 1;
3799 - }
3800 -
3801 - // Make sure current_page is between 1 and max pages.
3802 - if ( $current_page < 1 ) {
3803 - $current_page = 1;
3804 - } elseif ( $current_page > $total_pages ) {
3805 - $current_page = $total_pages;
3806 - }
3807 -
3808 - // Render wrapper div (for aligning pager to width of content).
3809 - ?>
3810 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
3811 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'top' ); ?>
3812 - <ul id="list_auth_settings_access_users_approved" class="<?php echo strlen( $advanced_usermeta ) > 0 ? 'has-usermeta' : ''; ?>">
3813 - <?php
3814 - $offset = ( $current_page - 1 ) * $users_per_page;
3815 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
3816 - for ( $key = $offset; $key < $max; $key++ ) :
3817 - $approved_user = $auth_settings_option[ $key ];
3138 + ?><ul id="list_auth_settings_access_users_approved" style="margin:0;">
3139 + <?php if ( ! $multisite_admin_page ) :
3140 + foreach ( $auth_settings_option_multisite as $key => $approved_user ) :
3818 3141 if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3819 3142 continue;
3820 3143 endif;
3821 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
3822 - endfor;
3823 - ?>
3824 - </ul>
3144 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3145 + if ( $approved_wp_user ) :
3146 + $approved_user['email'] = $approved_wp_user->user_email;
3147 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3148 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3149 + // Get usermeta field from the WordPress user's real usermeta.
3150 + if ( strlen( $advanced_usermeta ) > 0 ) :
3151 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3152 + // Get ACF Field value for the user
3153 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3154 + else :
3155 + // Get regular usermeta value for the user.
3156 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3157 + endif;
3825 3158
3826 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
3827 - <textarea id="new_approved_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new autogrow-short" rows="1"></textarea>
3828 - <select id="new_approved_user_role" class="auth-role">
3829 - <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
3830 - </select>
3831 - <div class="btn-group">
3832 - <a href="javascript:void(0);" class="btn button-primary dropdown-toggle button-add-user" id="approve_user_new" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a>
3833 - <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3834 - <span class="caret"></span>
3835 - <span class="sr-only"><?php esc_html_e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3836 - </button>
3837 - <ul class="dropdown-menu" role="menu">
3838 - <li><a href="javascript:void(0);" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( document.getElementById( 'approve_user_new' ), 'approved', true);"><?php esc_html_e( 'Create a local WordPress account instead, and email the user their password.', 'authorizer' ); ?></a></li>
3839 - </ul>
3840 - </div>
3841 - </div>
3842 - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'bottom' ); ?>
3843 - </div>
3844 - <?php
3845 - }
3159 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3160 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3161 + endif;
3162 + endif;
3163 + endif;
3164 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3165 + $approved_user['usermeta'] = '';
3166 + endif; ?>
3167 + <li>
3168 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email auth-multisite-email" />
3169 + <select id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role auth-multisite-role" disabled="disabled">
3170 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'] ); ?>
3171 + </select>
3172 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added auth-multisite-date-added" disabled="disabled" />
3173 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3174 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3175 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3176 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3177 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3178 + $should_show_usermeta_in_text_field = false; ?>
3179 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta auth-multisite-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );">
3180 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3181 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3182 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && array_key_exists( get_current_blog_id(), $approved_user['usermeta'] ) && $key === $approved_user['usermeta'][get_current_blog_id()]['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3183 + <?php endforeach; ?>
3184 + </select>
3185 + <?php endif; ?>
3186 + <?php endif; ?>
3187 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3188 + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta auth-multisite-usermeta" />
3189 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3190 + <?php endif; ?>
3191 + <?php endif; ?>
3192 + &nbsp;&nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
3193 + </li>
3194 + <?php endforeach;
3195 + endif;
3196 + foreach ( $auth_settings_option as $key => $approved_user ):
3197 + $is_current_user = false;
3198 + $local_user_icon = array_key_exists( 'local_user', $approved_user ) && $approved_user['local_user'] === 'true' ? '&nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>' : '';
3199 + if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
3200 + continue;
3201 + endif;
3202 + $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3203 + if ( $approved_wp_user ) :
3204 + $approved_user['email'] = $approved_wp_user->user_email;
3205 + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3206 + $approved_user['date_added'] = $approved_wp_user->user_registered;
3207 + $approved_user['is_wp_user'] = true;
3208 + $is_current_user = $approved_wp_user->ID === get_current_user_id();
3209 + // Get usermeta field from the WordPress user's real usermeta.
3210 + if ( strlen( $advanced_usermeta ) > 0 ) :
3211 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3212 + // Get ACF Field value for the user
3213 + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3214 + else :
3215 + // Get regular usermeta value for the user.
3216 + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3217 + endif;
3846 3218
3847 -
3848 - /**
3849 - * Renders the html elements for the pager above and below the Approved User list.
3850 - *
3851 - * @param integer $current_page Which page we are currently viewing.
3852 - * @param integer $users_per_page How many users to show per page.
3853 - * @param integer $total_users Total count of users in list.
3854 - * @param string $which Where to render the pager ('top' or 'bottom').
3855 - * @return void
3856 - */
3857 - private function render_user_pager( $current_page = 1, $users_per_page = 20, $total_users = 0, $which = 'top' ) {
3858 - $total_pages = ceil( $total_users / $users_per_page );
3859 - if ( $total_pages < 1 ) {
3860 - $total_pages = 1;
3861 - }
3862 -
3863 - /* TRANSLATORS: %s: number of users */
3864 - $output = ' <span class="displaying-num">' . sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ) . '</span>';
3865 -
3866 - $disable_first = $current_page <= 1;
3867 - $disable_prev = $current_page <= 1;
3868 - $disable_next = $current_page >= $total_pages;
3869 - $disable_last = $current_page >= $total_pages;
3870 -
3871 - $current_url = '';
3872 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
3873 - $current_url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
3874 - $current_url = remove_query_arg( wp_removable_query_args(), $current_url );
3875 - }
3876 -
3877 - $page_links = array();
3878 -
3879 - $total_pages_before = '<span class="paging-input">';
3880 - $total_pages_after = '</span></span>';
3881 -
3882 - if ( $disable_first ) {
3883 - $page_links[] = '<span class="first-page tablenav-pages-navspan" aria-hidden="true">&laquo;</span>';
3884 - } else {
3885 - $page_links[] = sprintf(
3886 - "<a class='first-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3887 - esc_url( remove_query_arg( 'paged', $current_url ) ),
3888 - __( 'First page' ),
3889 - '&laquo;'
3890 - );
3891 - }
3892 -
3893 - if ( $disable_prev ) {
3894 - $page_links[] = '<span class="prev-page tablenav-pages-navspan" aria-hidden="true">&lsaquo;</span>';
3895 - } else {
3896 - $page_links[] = sprintf(
3897 - "<a class='prev-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3898 - esc_url( add_query_arg( 'paged', max( 1, $current_page - 1 ), $current_url ) ),
3899 - __( 'Previous page' ),
3900 - '&lsaquo;'
3901 - );
3902 - }
3903 -
3904 - if ( 'bottom' === $which ) {
3905 - $html_current_page = '<span class="current-page-text">' . $current_page . '</span>';
3906 - $total_pages_before = '<span class="screen-reader-text">' . __( 'Current Page' ) . '</span><span id="table-paging" class="paging-input"><span class="tablenav-paging-text">';
3907 - } else {
3908 - $html_current_page = sprintf(
3909 - "%s<input class='current-page' id='current-page-selector' type='text' name='paged' value='%s' size='%d' aria-describedby='table-paging' /><span class='tablenav-paging-text'>",
3910 - '<label for="current-page-selector" class="screen-reader-text">' . __( 'Current Page' ) . '</label>',
3911 - $current_page,
3912 - strlen( $total_pages )
3913 - );
3914 - }
3915 - /* TRANSLATORS: %s: number of pages */
3916 - $html_total_pages = sprintf( "<span class='total-pages'>%s</span>", number_format_i18n( $total_pages ) );
3917 - /* TRANSLATORS: 1: number of current page 2: number of total pages */
3918 - $page_links[] = $total_pages_before . sprintf( _x( '%1$s of %2$s', 'paging' ), $html_current_page, $html_total_pages ) . $total_pages_after;
3919 -
3920 - if ( $disable_next ) {
3921 - $page_links[] = '<span class="next-page tablenav-pages-navspan" aria-hidden="true">&rsaquo;</span>';
3922 - } else {
3923 - $page_links[] = sprintf(
3924 - "<a class='next-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3925 - esc_url( add_query_arg( 'paged', min( $total_pages, $current_page + 1 ), $current_url ) ),
3926 - __( 'Next page' ),
3927 - '&rsaquo;'
3928 - );
3929 - }
3930 -
3931 - if ( $disable_last ) {
3932 - $page_links[] = '<span class="last-page tablenav-pages-navspan" aria-hidden="true">&raquo;</span>';
3933 - } else {
3934 - $page_links[] = sprintf(
3935 - "<a class='last-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>",
3936 - esc_url( add_query_arg( 'paged', $total_pages, $current_url ) ),
3937 - __( 'Last page' ),
3938 - '&raquo;'
3939 - );
3940 - }
3941 -
3942 - $pagination_links_class = 'pagination-links';
3943 - $output .= "\n<span class='$pagination_links_class'>" . join( "\n", $page_links ) . '</span>';
3944 -
3945 - $search_form = array();
3946 - if ( 'top' === $which ) {
3947 - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification
3948 - $search_term = isset( $_REQUEST['search'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) : '';
3949 - $search_form[] = '<div class="search-box">';
3950 - $search_form[] = '<label class="screen-reader-text" for="user-search-input">' . __( 'Search Users', 'authorizer' ) . '</label>';
3951 - $search_form[] = '<input type="search" size="14" id="user-search-input" name="search" value="' . $search_term . '">';
3952 - $search_form[] = '<input type="button" id="search-submit" class="button" value="' . __( 'Search', 'authorizer' ) . '">';
3953 - $search_form[] = '</div>';
3954 - }
3955 - $search_form = join( "\n", $search_form );
3956 -
3957 - $output = "<div class='tablenav-pages'>$output</div>";
3958 - ?>
3959 - <div class="tablenav top">
3960 - <?php echo wp_kses( $output, $this->allowed_html ); ?>
3961 - <?php echo wp_kses( $search_form, $this->allowed_html ); ?>
3962 - </div>
3963 - <?php
3964 - }
3965 -
3966 -
3967 - /**
3968 - * Renders the html <li> element for a given user in a list.
3969 - *
3970 - * @param array $approved_user User array to render.
3971 - * @param int $key Index of user in list of users.
3972 - * @param string $option List user is in (e.g., 'access_users_approved').
3973 - * @param string $admin_mode Current admin context.
3974 - * @param string $advanced_usermeta Usermeta field to display.
3975 - * @return void
3976 - */
3977 - private function render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ) {
3978 - $is_local_user = array_key_exists( 'local_user', $approved_user ) && 'true' === $approved_user['local_user'];
3979 - $is_multisite_user = array_key_exists( 'multisite_user', $approved_user ) && true === $approved_user['multisite_user'];
3980 - $option_prefix = $is_multisite_user ? 'auth_multisite_settings_' : 'auth_settings_';
3981 - $option_id = $option_prefix . $option . '_' . $key;
3982 - $approved_wp_user = get_user_by( 'email', $approved_user['email'] );
3983 - $is_current_user = $approved_wp_user && get_current_user_id() === $approved_wp_user->ID;
3984 -
3985 - // Adjust javascript function prefixes if multisite.
3986 - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth';
3987 - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode;
3988 -
3989 - if ( ! $approved_wp_user ) :
3990 - $approved_user['is_wp_user'] = false;
3991 - else :
3992 - $approved_user['is_wp_user'] = true;
3993 - $approved_user['email'] = $approved_wp_user->user_email;
3994 - $approved_user['role'] = $is_multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles );
3995 - $approved_user['date_added'] = $approved_wp_user->user_registered;
3996 -
3997 - // Get usermeta field from the WordPress user's real usermeta.
3998 - if ( strlen( $advanced_usermeta ) > 0 ) :
3999 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
4000 - // Get ACF Field value for the user.
4001 - $approved_user['usermeta'] = get_field( str_replace( 'acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID );
3219 + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
3220 + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
3221 + endif;
3222 + endif;
4002 3223 else :
4003 - // Get regular usermeta value for the user.
4004 - $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true );
3224 + $approved_user['is_wp_user'] = false;
4005 3225 endif;
4006 - if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) :
4007 - $approved_user['usermeta'] = serialize( $approved_user['usermeta'] );
4008 - endif;
4009 - endif;
4010 - endif;
4011 - if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
4012 - $approved_user['usermeta'] = '';
4013 - endif;
4014 - ?>
4015 - <li>
4016 - <input
4017 - type="text"
4018 - id="<?php echo esc_attr( $option_id ); ?>"
4019 - value="<?php echo esc_attr( $approved_user['email'] ); ?>"
4020 - readonly="true"
4021 - class="<?php echo esc_attr( $this->create_class_name( 'email', $is_multisite_user ) ); ?>"
4022 - />
4023 - <select
4024 - id="<?php echo esc_attr( $option_id ); ?>_role"
4025 - class="<?php echo esc_attr( $this->create_class_name( 'role', $is_multisite_user ) ); ?>"
4026 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>ChangeRole( this );"
4027 - <?php if ( $is_multisite_user ) : ?>
4028 - disabled="disabled"
4029 - <?php endif; ?>
4030 - >
4031 - <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
4032 - <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3226 + if ( ! array_key_exists( 'usermeta', $approved_user ) ) :
3227 + $approved_user['usermeta'] = '';
3228 + endif; ?>
3229 + <li>
3230 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email" />
3231 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role" onchange="<?php echo $js_function_prefix; ?>change_role( this );">
3232 + <?php $disable_input = $is_current_user ? 'disabled' : null; ?>
3233 + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?>
3234 + </select>
3235 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3236 + <?php if ( strlen( $advanced_usermeta ) > 0 ) :
3237 + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
3238 + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
3239 + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) );
3240 + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) :
3241 + $should_show_usermeta_in_text_field = false; ?>
3242 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );" >
3243 + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option>
3244 + <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
3245 + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && $key === $approved_user['usermeta']['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option>
3246 + <?php endforeach; ?>
3247 + </select>
3248 + <?php endif; ?>
3249 + <?php endif; ?>
3250 + <?php if ( $should_show_usermeta_in_text_field ) : ?>
3251 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta" />
3252 + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
3253 + <?php endif; ?>
3254 + <?php endif; ?>
3255 + <?php if ( ! $is_current_user ): ?>
3256 + <?php if ( ! $multisite_admin_page ) : ?>
3257 + <a class="button" id="block_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>add_user( this, 'blocked', false ); <?php echo $js_function_prefix; ?>ignore_user( this, 'approved' );" title="<?php _e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
3258 + <?php endif; ?>
3259 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>ignore_user(this, 'approved' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3260 + <?php endif; ?>
3261 + <?php echo $local_user_icon; ?>
3262 + </li>
3263 + <?php endforeach; ?>
3264 + </ul>
3265 + <div id="new_auth_settings_<?php echo $option; ?>">
3266 + <input type="text" id="new_approved_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3267 + <select id="new_approved_user_role" class="auth-role">
3268 + <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?>
4033 3269 </select>
4034 - <input
4035 - type="text"
4036 - id="<?php echo esc_attr( $option_id ); ?>_date_added"
4037 - value="<?php echo esc_attr( date( 'M Y', strtotime( $approved_user['date_added'] ) ) ); ?>"
4038 - readonly="true"
4039 - class="<?php echo esc_attr( $this->create_class_name( 'date-added', $is_multisite_user ) ); ?>"
4040 - />
4041 - <?php
4042 - if ( strlen( $advanced_usermeta ) > 0 ) :
4043 - $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first.
4044 - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) :
4045 - $field_object = get_field_object( str_replace( 'acf___', '', $advanced_usermeta ) );
4046 - if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && 'select' === $field_object['type'] ) :
4047 - $should_show_usermeta_in_text_field = false;
4048 - ?>
4049 - <select
4050 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4051 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4052 - onchange="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );"
4053 - >
4054 - <option value=""<?php selected( empty( $approved_user['usermeta'] ) ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4055 - <?php foreach ( $field_object['choices'] as $key => $label ) : ?>
4056 - <option value="<?php echo esc_attr( $key ); ?>"<?php selected( $key === $approved_user['usermeta'] || ( isset( $approved_user['usermeta']['meta_value'] ) && $key === $approved_user['usermeta']['meta_value'] ) ); ?>><?php echo esc_html( $label ); ?></option>
4057 - <?php endforeach; ?>
4058 - </select>
4059 - <?php endif; ?>
4060 - <?php endif; ?>
4061 - <?php if ( $should_show_usermeta_in_text_field ) : ?>
4062 - <input
4063 - type="text"
4064 - id="<?php echo esc_attr( $option_id ); ?>_usermeta"
4065 - value="<?php echo esc_attr( $approved_user['usermeta'], ENT_COMPAT ); ?>"
4066 - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>"
4067 - />
4068 - <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a>
4069 - <?php endif; ?>
4070 - <?php endif; ?>
4071 - <?php if ( ! $is_current_user && ! $is_multisite_user ) : ?>
4072 - <?php if ( ! $is_multisite_admin_page ) : ?>
4073 - <a class="button" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( this, 'blocked', false ); <?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser( this, 'approved' );" title="<?php esc_attr_e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a>
4074 - <?php endif; ?>
4075 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser(this, 'approved' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4076 - <?php endif; ?>
4077 - <?php if ( $is_local_user ) : ?>
4078 - &nbsp;<a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>
4079 - <?php endif; ?>
4080 - <?php if ( $is_multisite_user ) : ?>
4081 - &nbsp;<a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a>
4082 - <?php endif; ?>
4083 - </li>
3270 + <div class="btn-group">
3271 + <a href="javascript:void(0);" class="btn button-primary dropdown-toggle" id="approve_user_new" onclick="<?php echo $js_function_prefix; ?>add_user(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a>
3272 + <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown">
3273 + <span class="caret"></span>
3274 + <span class="sr-only"><?php _e( 'Toggle Dropdown', 'authorizer' ); ?></span>
3275 + </button>
3276 + <ul class="dropdown-menu" role="menu">
3277 + <li><a href="javascript:void(0);" onclick="<?php echo $js_function_prefix; ?>add_user( document.getElementById('approve_user_new' ), 'approved', true);"><?php _e( 'Create a local WordPress <br />account instead, and email <br />the user their password.', 'authorizer' ); ?></a></li>
3278 + </ul>
3279 + </div>
3280 + </div>
4084 3281 <?php
4085 3282 }
4086 3283
4087 3284
4088 - /**
4089 - * Settings print callback.
4090 - *
4091 - * @param string $args Args (e.g., multisite admin mode).
4092 - * @return void
4093 - */
4094 - public function print_combo_auth_access_users_blocked( $args = '' ) {
3285 + function print_combo_auth_access_users_blocked( $args = '' ) {
4095 3286 // Get plugin option.
4096 - $option = 'access_users_blocked';
3287 + $option = 'access_users_blocked';
4097 3288 $auth_settings_option = $this->get_plugin_option( $option );
4098 3289 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4099 3290
4100 3291 // Get default role for new blocked user dropdown.
4101 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
3292 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
4102 3293
4103 - // Render wrapper div (for aligning pager to width of content).
4104 - ?>
4105 - <div class="wrapper_<?php echo esc_attr( $option ); ?>">
4106 - <ul id="list_auth_settings_<?php echo esc_attr( $option ); ?>" style="margin:0;">
4107 - <?php
4108 - foreach ( $auth_settings_option as $key => $blocked_user ) :
4109 - if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) :
4110 - continue;
4111 - endif;
4112 - $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
4113 - if ( $blocked_wp_user ) :
4114 - $blocked_user['email'] = $blocked_wp_user->user_email;
4115 - $blocked_user['role'] = array_shift( $blocked_wp_user->roles );
4116 - $blocked_user['date_added'] = $blocked_wp_user->user_registered;
4117 - $blocked_user['is_wp_user'] = true;
4118 - else :
4119 - $blocked_user['is_wp_user'] = false;
4120 - endif;
4121 - ?>
4122 - <li>
4123 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $blocked_user['email'] ); ?>" readonly="true" class="auth-email" />
4124 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role">
4125 - <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
4126 - </select>
4127 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_date_added" value="<?php echo esc_attr( date( 'M Y', strtotime( $blocked_user['date_added'] ) ) ); ?>" readonly="true" class="auth-date-added" />
4128 - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'blocked' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
4129 - </li>
4130 - <?php endforeach; ?>
4131 - </ul>
4132 - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>">
4133 - <input type="text" id="new_blocked_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
4134 - <select id="new_blocked_user_role" class="auth-role">
4135 - <option value="<?php echo esc_attr( $access_default_role ); ?>"><?php echo esc_html( ucfirst( $access_default_role ) ); ?></option>
4136 - </select>
4137 - <a href="javascript:void(0);" class="button-primary button-add-user" id="block_user_new" onclick="authAddUser( this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a>
4138 - </div>
3294 + // Print option elements.
3295 + ?><ul id="list_auth_settings_<?php echo $option; ?>" style="margin:0;">
3296 + <?php foreach ( $auth_settings_option as $key => $blocked_user ): ?>
3297 + <?php if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) continue; ?>
3298 + <?php if ( $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ) ): ?>
3299 + <?php $blocked_user['email'] = $blocked_wp_user->user_email; ?>
3300 + <?php $blocked_user['role'] = array_shift( $blocked_wp_user->roles ); ?>
3301 + <?php $blocked_user['date_added'] = $blocked_wp_user->user_registered; ?>
3302 + <?php $blocked_user['is_wp_user'] = true; ?>
3303 + <?php else: ?>
3304 + <?php $blocked_user['is_wp_user'] = false; ?>
3305 + <?php endif; ?>
3306 + <li>
3307 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $blocked_user['email']; ?>" readonly="true" class="auth-email" />
3308 + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role">
3309 + <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?>
3310 + </select>
3311 + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $blocked_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" />
3312 + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user(this, 'blocked' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a>
3313 + </li>
3314 + <?php endforeach; ?>
3315 + </ul>
3316 + <div id="new_auth_settings_<?php echo $option; ?>">
3317 + <input type="text" id="new_blocked_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" />
3318 + <select id="new_blocked_user_role" class="auth-role">
3319 + <option value="<?php echo $access_default_role; ?>"><?php echo ucfirst( $access_default_role ); ?></option>
3320 + </select>
3321 + <a href="javascript:void(0);" class="button-primary" id="block_user_new" onclick="auth_add_user(this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a>
4139 3322 </div>
4140 3323 <?php
4141 3324 }
4142 3325
4143 3326
4144 - /**
4145 - * Settings print callback.
4146 - *
4147 - * @param string $args Args (e.g., multisite admin mode).
4148 - * @return void
4149 - */
4150 - public function print_section_info_access_login( $args = '' ) {
4151 - ?>
4152 - <div id="section_info_access_login" class="section_info">
3327 + function print_section_info_access_login( $args = '' ) {
3328 + ?><div id="section_info_access_login" class="section_info">
4153 3329 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
4154 - <p><?php esc_html_e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
4155 - </div>
4156 - <?php
3330 + <p><?php _e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p>
3331 + </div><?php
4157 3332 }
4158 3333
4159 3334
4160 - /**
4161 - * Settings print callback.
4162 - *
4163 - * @param string $args Args (e.g., multisite admin mode).
4164 - * @return void
4165 - */
4166 - public function print_radio_auth_access_who_can_login( $args = '' ) {
3335 + function print_radio_auth_access_who_can_login( $args = '' ) {
4167 3336 // Get plugin option.
4168 - $option = 'access_who_can_login';
4169 - $admin_mode = $this->get_admin_mode( $args );
3337 + $option = 'access_who_can_login';
3338 + $admin_mode = $this->get_admin_mode( $args );
4170 3339 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4171 3340
4172 3341 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4173 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3342 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4174 3343 $auth_settings_option = $this->get_plugin_option( $option );
4175 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) === '1' ) {
3344 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4176 3345 // Workaround: javascript code hides/shows other settings based
4177 3346 // on the selection in this option. If this option is overridden
4178 3347 // by a multisite option, it should show that value in order to
4179 3348 // correctly display the other appropriate options.
@@ -4179,49 +3348,33 @@
4179 3348 // correctly display the other appropriate options.
4180 3349 // Side effect: this site option will be overwritten by the
4181 3350 // multisite option on save. Since this is a 2-item radio, we
4182 3351 // determined this was acceptable.
4183 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3352 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4184 3353 }
4185 3354
4186 3355 // Print option elements.
4187 - ?>
4188 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="external_users"<?php checked( 'external_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users"><?php esc_html_e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
4189 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="approved_users"<?php checked( 'approved_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users"><?php esc_html_e( 'Only', 'authorizer' ); ?> <a href="javascript:chooseTab('access_lists' );" id="dashboard_link_approved_users"><?php esc_html_e( 'approved users', 'authorizer' ); ?></a> <?php esc_html_e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br />
4190 - <?php
3356 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_external_users" name="auth_settings[<?php echo $option; ?>]" value="external_users"<?php checked( 'external_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_external_users"><?php _e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br />
3357 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_approved_users" name="auth_settings[<?php echo $option; ?>]" value="approved_users"<?php checked( 'approved_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_approved_users"><?php _e( 'Only', 'authorizer' ); ?> <a href="javascript:choose_tab('access_lists' );" id="dashboard_link_approved_users"><?php _e( 'approved users', 'authorizer' ); ?></a> <?php _e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br /><?php
4191 3358 }
4192 3359
4193 3360
4194 - /**
4195 - * Settings print callback.
4196 - *
4197 - * @param string $args Args (e.g., multisite admin mode).
4198 - * @return void
4199 - */
4200 - public function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
3361 + function print_select_auth_access_role_receive_pending_emails( $args = '' ) {
4201 3362 // Get plugin option.
4202 - $option = 'access_role_receive_pending_emails';
3363 + $option = 'access_role_receive_pending_emails';
4203 3364 $auth_settings_option = $this->get_plugin_option( $option );
4204 3365
4205 3366 // Print option elements.
4206 - ?>
4207 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
4208 - <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php esc_html_e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
3367 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
3368 + <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php _e( "None (Don't send notification emails)", 'authorizer' ); ?></option>
4209 3369 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4210 - </select>
4211 - <?php
3370 + </select><?php
4212 3371 }
4213 3372
4214 3373
4215 - /**
4216 - * Settings print callback.
4217 - *
4218 - * @param string $args Args (e.g., multisite admin mode).
4219 - * @return void
4220 - */
4221 - public function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
3374 + function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) {
4222 3375 // Get plugin option.
4223 - $option = 'access_pending_redirect_to_message';
3376 + $option = 'access_pending_redirect_to_message';
4224 3377 $auth_settings_option = $this->get_plugin_option( $option );
4225 3378
4226 3379 // Print option elements.
4227 3380 wp_editor(
@@ -4230,25 +3383,19 @@
4230 3383 array(
4231 3384 'media_buttons' => false,
4232 3385 'textarea_name' => "auth_settings[$option]",
4233 3386 'textarea_rows' => 5,
4234 - 'tinymce' => true,
4235 - 'teeny' => true,
4236 - 'quicktags' => false,
3387 + 'tinymce' => true,
3388 + 'teeny' => true,
3389 + 'quicktags' => false,
4237 3390 )
4238 3391 );
4239 3392 }
4240 3393
4241 3394
4242 - /**
4243 - * Settings print callback.
4244 - *
4245 - * @param string $args Args (e.g., multisite admin mode).
4246 - * @return void
4247 - */
4248 - public function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
3395 + function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) {
4249 3396 // Get plugin option.
4250 - $option = 'access_blocked_redirect_to_message';
3397 + $option = 'access_blocked_redirect_to_message';
4251 3398 $auth_settings_option = $this->get_plugin_option( $option );
4252 3399
4253 3400 // Print option elements.
4254 3401 wp_editor(
@@ -4257,61 +3404,39 @@
4257 3404 array(
4258 3405 'media_buttons' => false,
4259 3406 'textarea_name' => "auth_settings[$option]",
4260 3407 'textarea_rows' => 5,
4261 - 'tinymce' => true,
4262 - 'teeny' => true,
4263 - 'quicktags' => false,
3408 + 'tinymce' => true,
3409 + 'teeny' => true,
3410 + 'quicktags' => false,
4264 3411 )
4265 3412 );
4266 3413 }
4267 3414
4268 3415
4269 - /**
4270 - * Settings print callback.
4271 - *
4272 - * @param string $args Args (e.g., multisite admin mode).
4273 - * @return void
4274 - */
4275 - public function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
3416 + function print_checkbox_auth_access_should_email_approved_users( $args = '' ) {
4276 3417 // Get plugin option.
4277 - $option = 'access_should_email_approved_users';
3418 + $option = 'access_should_email_approved_users';
4278 3419 $auth_settings_option = $this->get_plugin_option( $option );
4279 3420
4280 3421 // Print option elements.
4281 - ?>
4282 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label>
4283 - <?php
3422 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label><?php
4284 3423 }
4285 3424
4286 3425
4287 - /**
4288 - * Settings print callback.
4289 - *
4290 - * @param string $args Args (e.g., multisite admin mode).
4291 - * @return void
4292 - */
4293 - public function print_text_auth_access_email_approved_users_subject( $args = '' ) {
3426 + function print_text_auth_access_email_approved_users_subject( $args = '' ) {
4294 3427 // Get plugin option.
4295 - $option = 'access_email_approved_users_subject';
3428 + $option = 'access_email_approved_users_subject';
4296 3429 $auth_settings_option = $this->get_plugin_option( $option );
4297 3430
4298 3431 // Print option elements.
4299 - ?>
4300 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php echo wp_kses( __( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ), $this->allowed_html ); ?></small>
4301 - <?php
3432 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php _e( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ); ?></small><?php
4302 3433 }
4303 3434
4304 3435
4305 - /**
4306 - * Settings print callback.
4307 - *
4308 - * @param string $args Args (e.g., multisite admin mode).
4309 - * @return void
4310 - */
4311 - public function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
3436 + function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) {
4312 3437 // Get plugin option.
4313 - $option = 'access_email_approved_users_body';
3438 + $option = 'access_email_approved_users_body';
4314 3439 $auth_settings_option = $this->get_plugin_option( $option );
4315 3440
4316 3441 // Print option elements.
4317 3442 wp_editor(
@@ -4320,60 +3445,42 @@
4320 3445 array(
4321 3446 'media_buttons' => false,
4322 3447 'textarea_name' => "auth_settings[$option]",
4323 3448 'textarea_rows' => 9,
4324 - 'tinymce' => true,
4325 - 'teeny' => true,
4326 - 'quicktags' => false,
3449 + 'tinymce' => true,
3450 + 'teeny' => true,
3451 + 'quicktags' => false,
4327 3452 )
4328 3453 );
4329 - ?>
4330 - <small>
4331 - <?php
4332 - printf(
4333 - /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
4334 - wp_kses( __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ), $this->allowed_html ),
4335 - '<b>[site_name]</b>',
4336 - '<b>[site_url]</b>',
4337 - '<b>[user_email]</b>'
4338 - );
4339 - ?>
4340 - </small>
4341 - <?php
3454 +
3455 + ?><small><?php printf(
3456 + /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */
3457 + __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ),
3458 + '<b>[site_name]</b>',
3459 + '<b>[site_url]</b>',
3460 + '<b>[user_email]</b>'
3461 + ); ?></small><?php
3462 +
4342 3463 }
4343 3464
4344 3465
4345 - /**
4346 - * Settings print callback.
4347 - *
4348 - * @param string $args Args (e.g., multisite admin mode).
4349 - * @return void
4350 - */
4351 - public function print_section_info_access_public( $args = '' ) {
4352 - ?>
4353 - <div id="section_info_access_public" class="section_info">
4354 - <p><?php esc_html_e( 'Choose your public access options here.', 'authorizer' ); ?></p>
4355 - </div>
4356 - <?php
3466 + function print_section_info_access_public( $args = '' ) {
3467 + ?><div id="section_info_access_public" class="section_info">
3468 + <p><?php _e( 'Choose your public access options here.', 'authorizer' ); ?></p>
3469 + </div><?php
4357 3470 }
4358 3471
4359 3472
4360 - /**
4361 - * Settings print callback.
4362 - *
4363 - * @param string $args Args (e.g., multisite admin mode).
4364 - * @return void
4365 - */
4366 - public function print_radio_auth_access_who_can_view( $args = '' ) {
3473 + function print_radio_auth_access_who_can_view( $args = '' ) {
4367 3474 // Get plugin option.
4368 - $option = 'access_who_can_view';
4369 - $admin_mode = $this->get_admin_mode( $args );
3475 + $option = 'access_who_can_view';
3476 + $admin_mode = $this->get_admin_mode( $args );
4370 3477 $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' );
4371 3478
4372 3479 // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay.
4373 - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
3480 + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
4374 3481 $auth_settings_option = $this->get_plugin_option( $option );
4375 - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && '1' === $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) ) {
3482 + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) {
4376 3483 // Workaround: javascript code hides/shows other settings based
4377 3484 // on the selection in this option. If this option is overridden
4378 3485 // by a multisite option, it should show that value in order to
4379 3486 // correctly display the other appropriate options.
@@ -4379,66 +3486,42 @@
4379 3486 // correctly display the other appropriate options.
4380 3487 // Side effect: this site option will be overwritten by the
4381 3488 // multisite option on save. Since this is a 2-item radio, we
4382 3489 // determined this was acceptable.
4383 - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT );
3490 + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN );
4384 3491 }
4385 3492
4386 3493 // Print option elements.
4387 - ?>
4388 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="everyone"<?php checked( 'everyone' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone"><?php esc_html_e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
4389 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="logged_in_users"<?php checked( 'logged_in_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users"><?php esc_html_e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br />
4390 - <?php
3494 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_everyone" name="auth_settings[<?php echo $option; ?>]" value="everyone"<?php checked( 'everyone' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_everyone"><?php _e( 'Everyone can see the site', 'authorizer' ); ?></label><br />
3495 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_logged_in_users" name="auth_settings[<?php echo $option; ?>]" value="logged_in_users"<?php checked( 'logged_in_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_logged_in_users"><?php _e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br /><?php
4391 3496 }
4392 3497
4393 3498
4394 - /**
4395 - * Settings print callback.
4396 - *
4397 - * @param string $args Args (e.g., multisite admin mode).
4398 - * @return void
4399 - */
4400 - public function print_radio_auth_access_redirect( $args = '' ) {
3499 + function print_radio_auth_access_redirect( $args = '' ) {
4401 3500 // Get plugin option.
4402 - $option = 'access_redirect';
3501 + $option = 'access_redirect';
4403 3502 $auth_settings_option = $this->get_plugin_option( $option );
4404 3503
4405 3504 // Print option elements.
4406 - ?>
4407 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="login"<?php checked( 'login' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login"><?php esc_html_e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
4408 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="message"<?php checked( 'message' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message"><?php esc_html_e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label>
4409 - <?php
3505 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_login" name="auth_settings[<?php echo $option; ?>]" value="login"<?php checked( 'login' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_login"><?php _e( 'Send them to the login screen', 'authorizer' ); ?></label><br />
3506 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_message" name="auth_settings[<?php echo $option; ?>]" value="message"<?php checked( 'message' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_message"><?php _e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label><?php
4410 3507 }
4411 3508
4412 3509
4413 - /**
4414 - * Settings print callback.
4415 - *
4416 - * @param string $args Args (e.g., multisite admin mode).
4417 - * @return void
4418 - */
4419 - public function print_radio_auth_access_public_warning( $args = '' ) {
3510 + function print_radio_auth_access_public_warning( $args = '' ) {
4420 3511 // Get plugin option.
4421 - $option = 'access_public_warning';
3512 + $option = 'access_public_warning';
4422 3513 $auth_settings_option = $this->get_plugin_option( $option );
4423 3514
4424 3515 // Print option elements.
4425 - ?>
4426 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="no_warning"<?php checked( 'no_warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no"><?php echo wp_kses( __( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ), $this->allowed_html ); ?></label><br />
4427 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="warning"<?php checked( 'warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>"><?php echo wp_kses( __( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ), $this->allowed_html ); ?></label>
4428 - <?php
3516 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_no" name="auth_settings[<?php echo $option; ?>]" value="no_warning"<?php checked( 'no_warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_no"><?php _e( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ); ?></label><br />
3517 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="warning"<?php checked( 'warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>"><?php _e( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ); ?></label><?php
4429 3518 }
4430 3519
4431 3520
4432 - /**
4433 - * Settings print callback.
4434 - *
4435 - * @param string $args Args (e.g., multisite admin mode).
4436 - * @return void
4437 - */
4438 - public function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
3521 + function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) {
4439 3522 // Get plugin option.
4440 - $option = 'access_redirect_to_message';
3523 + $option = 'access_redirect_to_message';
4441 3524 $auth_settings_option = $this->get_plugin_option( $option );
4442 3525
4443 3526 // Print option elements.
4444 3527 wp_editor(
@@ -4447,25 +3530,19 @@
4447 3530 array(
4448 3531 'media_buttons' => false,
4449 3532 'textarea_name' => "auth_settings[$option]",
4450 3533 'textarea_rows' => 5,
4451 - 'tinymce' => true,
4452 - 'teeny' => true,
4453 - 'quicktags' => false,
3534 + 'tinymce' => true,
3535 + 'teeny' => true,
3536 + 'quicktags' => false,
4454 3537 )
4455 3538 );
4456 3539 }
4457 3540
4458 3541
4459 - /**
4460 - * Settings print callback.
4461 - *
4462 - * @param string $args Args (e.g., multisite admin mode).
4463 - * @return void
4464 - */
4465 - public function print_multiselect_auth_access_public_pages( $args = '' ) {
3542 + function print_multiselect_auth_access_public_pages( $args = '' ) {
4466 3543 // Get plugin option.
4467 - $option = 'access_public_pages';
3544 + $option = 'access_public_pages';
4468 3545 $auth_settings_option = $this->get_plugin_option( $option );
4469 3546 $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
4470 3547
4471 3548 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
@@ -4471,188 +3548,120 @@
4471 3548 $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) );
4472 3549 $post_types = is_array( $post_types ) ? $post_types : array();
4473 3550
4474 3551 // Print option elements.
4475 - ?>
4476 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" multiple="multiple" name="auth_settings[<?php echo esc_attr( $option ); ?>][]">
4477 - <optgroup label="<?php esc_attr_e( 'Home', 'authorizer' ); ?>">
4478 - <option value="home" <?php selected( in_array( 'home', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Home Page', 'authorizer' ); ?></option>
4479 - <option value="auth_public_404" <?php selected( in_array( 'auth_public_404', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
3552 + ?><select id="auth_settings_<?php echo $option; ?>" multiple="multiple" name="auth_settings[<?php echo $option; ?>][]">
3553 + <optgroup label="<?php _e( 'Home', 'authorizer' ); ?>">
3554 + <option value="home" <?php echo in_array( 'home', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Home Page', 'authorizer' ); ?></option>
3555 + <option value="auth_public_404" <?php echo in_array( 'auth_public_404', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option>
4480 3556 </optgroup>
4481 - <?php foreach ( $post_types as $post_type ) : ?>
4482 - <optgroup label="<?php echo esc_attr( ucfirst( $post_type ) ); ?>">
4483 - <?php
4484 - $pages = get_posts(
4485 - array(
4486 - 'post_type' => $post_type,
4487 - 'posts_per_page' => 1000, // phpcs:ignore WordPress.VIP.PostsPerPage.posts_per_page_posts_per_page
4488 - )
4489 - );
4490 - $pages = is_array( $pages ) ? $pages : array();
4491 - foreach ( $pages as $page ) :
4492 - ?>
4493 - <option value="<?php echo esc_attr( $page->ID ); ?>" <?php selected( in_array( strval( $page->ID ), $auth_settings_option, true ) ); ?>><?php echo esc_html( $page->post_title ); ?></option>
3557 + <?php foreach ( $post_types as $post_type ): ?>
3558 + <optgroup label="<?php echo ucfirst( $post_type ); ?>">
3559 + <?php $pages = get_posts( array( 'post_type' => $post_type, 'posts_per_page' => -1 ) ); ?>
3560 + <?php $pages = is_array( $pages ) ? $pages : array(); ?>
3561 + <?php foreach ( $pages as $page ): ?>
3562 + <option value="<?php echo $page->ID; ?>" <?php echo in_array( $page->ID, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $page->post_title; ?></option>
4494 3563 <?php endforeach; ?>
4495 3564 </optgroup>
4496 3565 <?php endforeach; ?>
4497 - <optgroup label="<?php esc_attr_e( 'Categories', 'authorizer' ); ?>">
4498 - <?php
4499 - // If sitepress-multilingual-cms plugin is enabled, temporarily disable
4500 - // its terms_clauses filter since it conflicts with the category handling.
4501 - if ( array_key_exists( 'sitepress', $GLOBALS ) && is_object( $GLOBALS['sitepress'] ) ) {
4502 - remove_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) );
4503 - $categories = get_categories( array( 'hide_empty' => false ) );
4504 - add_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) );
4505 - } else {
4506 - $categories = get_categories( array( 'hide_empty' => false ) );
4507 - }
4508 - foreach ( $categories as $category ) :
4509 - ?>
4510 - <option value="<?php echo esc_attr( 'cat_' . $category->slug ); ?>" <?php selected( in_array( 'cat_' . $category->slug, $auth_settings_option, true ) ); ?>><?php echo esc_html( $category->name ); ?></option>
3566 + <optgroup label="<?php _e( 'Categories', 'authorizer' ); ?>">
3567 + <?php foreach ( get_categories() as $category ) : ?>
3568 + <option value="<?php echo 'cat_' . $category->slug; ?>" <?php echo in_array( 'cat_' . $category->slug, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $category->name; ?></option>
4511 3569 <?php endforeach; ?>
4512 3570 </optgroup>
4513 - </select>
4514 - <?php
3571 + </select><?php
4515 3572 }
4516 3573
4517 3574
4518 - /**
4519 - * Settings print callback.
4520 - *
4521 - * @param string $args Args (e.g., multisite admin mode).
4522 - * @return void
4523 - */
4524 - public function print_section_info_external( $args = '' ) {
4525 - ?>
4526 - <div id="section_info_external" class="section_info">
4527 - <p><?php esc_html_e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
4528 - </div>
4529 - <?php
3575 + function print_section_info_external( $args = '' ) {
3576 + ?><div id="section_info_external" class="section_info">
3577 + <p><?php _e( 'Enter your external server settings below.', 'authorizer' ); ?></p>
3578 + </div><?php
4530 3579 }
4531 3580
4532 3581
4533 - /**
4534 - * Settings print callback.
4535 - *
4536 - * @param string $args Args (e.g., multisite admin mode).
4537 - * @return void
4538 - */
4539 - public function print_select_auth_access_default_role( $args = '' ) {
3582 + function get_admin_mode( $args ) {
3583 + if ( is_array( $args ) && array_key_exists( MULTISITE_ADMIN, $args ) && $args[MULTISITE_ADMIN] === true ) {
3584 + return MULTISITE_ADMIN;
3585 + } else {
3586 + return SINGLE_ADMIN;
3587 + }
3588 + }
3589 +
3590 +
3591 + function print_select_auth_access_default_role( $args = '' ) {
4540 3592 // Get plugin option.
4541 - $option = 'access_default_role';
3593 + $option = 'access_default_role';
4542 3594 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4543 3595
4544 3596 // Print option elements.
4545 - ?>
4546 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3597 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4547 3598 <?php wp_dropdown_roles( $auth_settings_option ); ?>
4548 - <option value=""<?php selected( '' === $auth_settings_option ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
4549 - </select>
4550 - <?php
3599 + </select><?php
4551 3600 }
4552 3601
4553 3602
4554 - /**
4555 - * Settings print callback.
4556 - *
4557 - * @param string $args Args (e.g., multisite admin mode).
4558 - * @return void
4559 - */
4560 - public function print_checkbox_auth_external_google( $args = '' ) {
3603 + function print_checkbox_auth_external_google( $args = '' ) {
4561 3604 // Get plugin option.
4562 - $option = 'google';
3605 + $option = 'google';
4563 3606 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4564 3607
4565 3608 // Print option elements.
4566 - ?>
4567 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable Google Logins', 'authorizer' ); ?></label>
4568 - <?php
3609 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable Google Logins', 'authorizer' ); ?></label><?php
4569 3610 }
4570 3611
4571 3612
4572 - /**
4573 - * Settings print callback.
4574 - *
4575 - * @param string $args Args (e.g., multisite admin mode).
4576 - * @return void
4577 - */
4578 - public function print_text_google_clientid( $args = '' ) {
3613 + function print_text_google_clientid( $args = '' ) {
4579 3614 // Get plugin option.
4580 - $option = 'google_clientid';
3615 + $option = 'google_clientid';
4581 3616 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4582 3617
4583 3618 // Print option elements.
4584 - $site_url_parts = wp_parse_url( get_site_url() );
4585 - $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
4586 -
4587 - esc_html_e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' );
4588 - ?>
3619 + $site_url_parts = parse_url( get_site_url() );
3620 + $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/';
3621 + ?><?php _e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' ); ?>
4589 3622 <ol>
4590 - <li><?php echo wp_kses( __( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ), $this->allowed_html ); ?></li>
4591 - <li><?php echo wp_kses( __( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ), $this->allowed_html ); ?>
3623 + <li><?php _e( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ); ?></li>
3624 + <li><?php _e( 'Within the project, navigate to <em>APIs and Auth</em> &gt; <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ); ?>
4592 3625 <ul>
4593 - <li><?php echo wp_kses( __( 'Application Type: <strong>Web application</strong>', 'authorizer' ), $this->allowed_html ); ?></li>
4594 - <li><?php esc_html_e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo esc_html( rtrim( $site_url_host, '/' ) ); ?></strong></li>
4595 - <li><?php echo wp_kses( __( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ), $this->allowed_html ); ?></li>
3626 + <li><?php _e( 'Application Type: <strong>Web application</strong>', 'authorizer' ); ?></li>
3627 + <li><?php _e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo rtrim( $site_url_host, '/' ); ?></strong></li>
3628 + <li><?php _e( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ); ?></li>
4596 3629 </ul>
4597 3630 </li>
4598 - <li><?php esc_html_e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
4599 - <li><?php echo wp_kses( __( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ), $this->allowed_html ); ?></li>
4600 - <li><?php echo wp_kses( __( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ), $this->allowed_html ); ?></li>
3631 + <li><?php _e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li>
3632 + <li><?php _e( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> &gt; <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ); ?></li>
3633 + <li><?php _e( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ); ?></li>
4601 3634 </ol>
4602 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:560px;" />
4603 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer' ); ?></label>
4604 - <?php
3635 + <input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com" style="width:560px;" /><?php
4605 3636 }
4606 3637
4607 3638
4608 - /**
4609 - * Settings print callback.
4610 - *
4611 - * @param string $args Args (e.g., multisite admin mode).
4612 - * @return void
4613 - */
4614 - public function print_text_google_clientsecret( $args = '' ) {
3639 + function print_text_google_clientsecret( $args = '' ) {
4615 3640 // Get plugin option.
4616 - $option = 'google_clientsecret';
3641 + $option = 'google_clientsecret';
4617 3642 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4618 3643
4619 3644 // Print option elements.
4620 - ?>
4621 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:220px;" />
4622 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer' ); ?></label>
4623 - <?php
3645 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="sDNgX5_pr_5bly-frKmvp8jT" style="width:220px;" /><?php
4624 3646 }
4625 3647
4626 3648
4627 - /**
4628 - * Settings print callback.
4629 - *
4630 - * @param string $args Args (e.g., multisite admin mode).
4631 - * @return void
4632 - */
4633 - public function print_text_google_hosteddomain( $args = '' ) {
3649 + function print_text_google_hosteddomain( $args = '' ) {
4634 3650 // Get plugin option.
4635 - $option = 'google_hosteddomain';
3651 + $option = 'google_hosteddomain';
4636 3652 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4637 3653
4638 3654 // Print option elements.
4639 - ?>
4640 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:220px;"><?php echo esc_html( $auth_settings_option ); ?></textarea>
4641 - <br /><small><?php esc_html_e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php esc_html_e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small>
3655 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:220px;" /><br />
3656 + <small><?php _e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?></small>
4642 3657 <?php
4643 3658 }
4644 3659
4645 3660
4646 - /**
4647 - * Settings print callback.
4648 - *
4649 - * @param string $args Args (e.g., multisite admin mode).
4650 - * @return void
4651 - */
4652 - public function print_checkbox_auth_external_cas( $args = '' ) {
3661 + function print_checkbox_auth_external_cas( $args = '' ) {
4653 3662 // Get plugin option.
4654 - $option = 'cas';
3663 + $option = 'cas';
4655 3664 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4656 3665
4657 3666 // Make sure php5-curl extension is installed on server.
4658 3667 $curl_installed_message = ! function_exists( 'curl_init' ) ? __( '<a href="http://www.php.net//manual/en/curl.installation.php" target="_blank" style="color: red;">PHP CURL extension</a> is not installed', 'authorizer' ) : '';
@@ -4671,217 +3680,122 @@
4671 3680 ')</span>';
4672 3681 }
4673 3682
4674 3683 // Print option elements.
4675 - ?>
4676 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $error_message, $this->allowed_html ); ?>
4677 - <?php
3684 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo $error_message; ?><?php
4678 3685 }
4679 3686
4680 3687
4681 - /**
4682 - * Settings print callback.
4683 - *
4684 - * @param string $args Args (e.g., multisite admin mode).
4685 - * @return void
4686 - */
4687 - public function print_text_cas_custom_label( $args = '' ) {
3688 + function print_text_cas_custom_label( $args = '' ) {
4688 3689 // Get plugin option.
4689 - $option = 'cas_custom_label';
3690 + $option = 'cas_custom_label';
4690 3691 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4691 3692
4692 3693 // Print option elements.
4693 - esc_html_e( 'The button on the login page will read:', 'authorizer' );
4694 - ?>
4695 - <p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php esc_html_e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="CAS" style="width: 100px;" /></a></p>
4696 - <?php
3694 + ?><?php _e( 'The button on the login page will read:', 'authorizer' ); ?><p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php _e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="CAS" style="width: 100px;" /></a></p><?php
4697 3695 }
4698 3696
4699 3697
4700 - /**
4701 - * Settings print callback.
4702 - *
4703 - * @param string $args Args (e.g., multisite admin mode).
4704 - * @return void
4705 - */
4706 - public function print_text_cas_host( $args = '' ) {
3698 + function print_text_cas_host( $args = '' ) {
4707 3699 // Get plugin option.
4708 - $option = 'cas_host';
3700 + $option = 'cas_host';
4709 3701 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4710 3702
4711 3703 // Print option elements.
4712 - ?>
4713 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4714 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: authn.example.edu', 'authorizer' ); ?></label>
4715 - <?php
3704 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="authn.example.edu" /><?php
4716 3705 }
4717 3706
4718 3707
4719 - /**
4720 - * Settings print callback.
4721 - *
4722 - * @param string $args Args (e.g., multisite admin mode).
4723 - * @return void
4724 - */
4725 - public function print_text_cas_port( $args = '' ) {
3708 + function print_text_cas_port( $args = '' ) {
4726 3709 // Get plugin option.
4727 - $option = 'cas_port';
3710 + $option = 'cas_port';
4728 3711 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4729 3712
4730 3713 // Print option elements.
4731 - ?>
4732 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4733 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 443', 'authorizer' ); ?></label>
4734 - <?php
3714 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="443" style="width:50px;" /><?php
4735 3715 }
4736 3716
4737 3717
4738 - /**
4739 - * Settings print callback.
4740 - *
4741 - * @param string $args Args (e.g., multisite admin mode).
4742 - * @return void
4743 - */
4744 - public function print_text_cas_path( $args = '' ) {
3718 + function print_text_cas_path( $args = '' ) {
4745 3719 // Get plugin option.
4746 - $option = 'cas_path';
3720 + $option = 'cas_path';
4747 3721 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4748 3722
4749 3723 // Print option elements.
4750 - ?>
4751 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4752 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: /cas', 'authorizer' ); ?></label>
4753 - <?php
3724 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="/cas" /><?php
4754 3725 }
4755 3726
4756 3727
4757 - /**
4758 - * Settings print callback.
4759 - *
4760 - * @param string $args Args (e.g., multisite admin mode).
4761 - * @return void
4762 - */
4763 - public function print_select_cas_version( $args = '' ) {
3728 + function print_select_cas_version( $args = '' ) {
4764 3729 // Get plugin option.
4765 - $option = 'cas_version';
3730 + $option = 'cas_version';
4766 3731 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4767 3732
4768 3733 // Print option elements.
4769 - ?>
4770 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
3734 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4771 3735 <option value="SAML_VERSION_1_1" <?php selected( $auth_settings_option, 'SAML_VERSION_1_1' ); ?>>SAML_VERSION_1_1</option>
4772 3736 <option value="CAS_VERSION_3_0" <?php selected( $auth_settings_option, 'CAS_VERSION_3_0' ); ?>>CAS_VERSION_3_0</option>
4773 3737 <option value="CAS_VERSION_2_0" <?php selected( $auth_settings_option, 'CAS_VERSION_2_0' ); ?>>CAS_VERSION_2_0</option>
4774 3738 <option value="CAS_VERSION_1_0" <?php selected( $auth_settings_option, 'CAS_VERSION_1_0' ); ?>>CAS_VERSION_1_0</option>
4775 - </select>
4776 - <?php
3739 + </select><?php
4777 3740 }
4778 3741
4779 3742
4780 - /**
4781 - * Settings print callback.
4782 - *
4783 - * @param string $args Args (e.g., multisite admin mode).
4784 - * @return void
4785 - */
4786 - public function print_text_cas_attr_email( $args = '' ) {
3743 + function print_text_cas_attr_email( $args = '' ) {
4787 3744 // Get plugin option.
4788 - $option = 'cas_attr_email';
3745 + $option = 'cas_attr_email';
4789 3746 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4790 3747
4791 3748 // Print option elements.
4792 - ?>
4793 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4794 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
4795 - <br /><small><?php echo wp_kses( __( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
4796 - <?php
3749 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="mail" />
3750 + <br /><small><?php _e( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
4797 3751 }
4798 3752
4799 3753
4800 - /**
4801 - * Settings print callback.
4802 - *
4803 - * @param string $args Args (e.g., multisite admin mode).
4804 - * @return void
4805 - */
4806 - public function print_text_cas_attr_first_name( $args = '' ) {
3754 + function print_text_cas_attr_first_name( $args = '' ) {
4807 3755 // Get plugin option.
4808 - $option = 'cas_attr_first_name';
3756 + $option = 'cas_attr_first_name';
4809 3757 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4810 3758
4811 3759 // Print option elements.
4812 - ?>
4813 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4814 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenName', 'authorizer' ); ?></label>
4815 - <?php
3760 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="givenName" /><?php
4816 3761 }
4817 3762
4818 3763
4819 - /**
4820 - * Settings print callback.
4821 - *
4822 - * @param string $args Args (e.g., multisite admin mode).
4823 - * @return void
4824 - */
4825 - public function print_text_cas_attr_last_name( $args = '' ) {
3764 + function print_text_cas_attr_last_name( $args = '' ) {
4826 3765 // Get plugin option.
4827 - $option = 'cas_attr_last_name';
3766 + $option = 'cas_attr_last_name';
4828 3767 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4829 3768
4830 3769 // Print option elements.
4831 - ?>
4832 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
4833 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
4834 - <?php
3770 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="sn" /><?php
4835 3771 }
4836 3772
4837 3773
4838 - /**
4839 - * Settings print callback.
4840 - *
4841 - * @param string $args Args (e.g., multisite admin mode).
4842 - * @return void
4843 - */
4844 - public function print_checkbox_cas_attr_update_on_login( $args = '' ) {
3774 + function print_checkbox_cas_attr_update_on_login( $args = '' ) {
4845 3775 // Get plugin option.
4846 - $option = 'cas_attr_update_on_login';
3776 + $option = 'cas_attr_update_on_login';
4847 3777 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4848 3778
4849 3779 // Print option elements.
4850 - ?>
4851 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
4852 - <?php
3780 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
4853 3781 }
4854 3782
4855 3783
4856 - /**
4857 - * Settings print callback.
4858 - *
4859 - * @param string $args Args (e.g., multisite admin mode).
4860 - * @return void
4861 - */
4862 - public function print_checkbox_cas_auto_login( $args = '' ) {
3784 + function print_checkbox_cas_auto_login( $args = '' ) {
4863 3785 // Get plugin option.
4864 - $option = 'cas_auto_login';
3786 + $option = 'cas_auto_login';
4865 3787 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4866 3788
4867 3789 // Print option elements.
4868 - ?>
4869 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
4870 - <p><small><?php esc_html_e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p>
4871 - <?php
3790 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label>
3791 + <p><small><?php _e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p><?php
4872 3792 }
4873 3793
4874 3794
4875 - /**
4876 - * Settings print callback.
4877 - *
4878 - * @param string $args Args (e.g., multisite admin mode).
4879 - * @return void
4880 - */
4881 - public function print_checkbox_auth_external_ldap( $args = '' ) {
3795 + function print_checkbox_auth_external_ldap( $args = '' ) {
4882 3796 // Get plugin option.
4883 - $option = 'ldap';
3797 + $option = 'ldap';
4884 3798 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4885 3799
4886 3800 // Make sure php5-ldap extension is installed on server.
4887 3801 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
@@ -4886,324 +3800,185 @@
4886 3800 // Make sure php5-ldap extension is installed on server.
4887 3801 $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : '';
4888 3802
4889 3803 // Print option elements.
4890 - ?>
4891 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $ldap_installed_message, $this->allowed_html ); ?>
4892 - <?php
3804 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo $ldap_installed_message; ?><?php
4893 3805 }
4894 3806
4895 3807
4896 - /**
4897 - * Settings print callback.
4898 - *
4899 - * @param string $args Args (e.g., multisite admin mode).
4900 - * @return void
4901 - */
4902 - public function print_text_ldap_host( $args = '' ) {
3808 + function print_text_ldap_host( $args = '' ) {
4903 3809 // Get plugin option.
4904 - $option = 'ldap_host';
3810 + $option = 'ldap_host';
4905 3811 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4906 3812
4907 3813 // Print option elements.
4908 - ?>
4909 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
4910 - <br /><small><?php esc_html_e( 'Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).', 'authorizer' ); ?></small>
4911 - <?php
3814 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="ldap.example.edu" style="width:330px;" />
3815 + <br /><small><?php _e( "Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).", 'authorizer' ); ?></small><?php
4912 3816 }
4913 3817
4914 3818
4915 - /**
4916 - * Settings print callback.
4917 - *
4918 - * @param string $args Args (e.g., multisite admin mode).
4919 - * @return void
4920 - */
4921 - public function print_text_ldap_port( $args = '' ) {
3819 + function print_text_ldap_port( $args = '' ) {
4922 3820 // Get plugin option.
4923 - $option = 'ldap_port';
3821 + $option = 'ldap_port';
4924 3822 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4925 3823
4926 3824 // Print option elements.
4927 - ?>
4928 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" />
4929 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 389', 'authorizer' ); ?></label>
4930 - <br /><small><?php esc_html_e( 'If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.', 'authorizer' ); ?></small>
4931 - <?php
3825 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="389" style="width:50px;" />
3826 + <br /><small><?php _e( "If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.", 'authorizer' ); ?></small><?php
4932 3827 }
4933 3828
4934 3829
4935 - /**
4936 - * Settings print callback.
4937 - *
4938 - * @param string $args Args (e.g., multisite admin mode).
4939 - * @return void
4940 - */
4941 - public function print_checkbox_ldap_tls( $args = '' ) {
3830 + function print_checkbox_ldap_tls( $args = '' ) {
4942 3831 // Get plugin option.
4943 - $option = 'ldap_tls';
3832 + $option = 'ldap_tls';
4944 3833 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4945 3834
4946 3835 // Print option elements.
4947 - ?>
4948 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></label>
4949 - <br /><small><?php esc_html_e( 'If ldaps is used, this should be unchecked', 'authorizer' ); ?></small>
4950 - <?php
3836 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Use TLS', 'authorizer' ); ?></label><?php
4951 3837 }
4952 3838
4953 3839
4954 - /**
4955 - * Settings print callback.
4956 - *
4957 - * @param string $args Args (e.g., multisite admin mode).
4958 - * @return void
4959 - */
4960 - public function print_text_ldap_search_base( $args = '' ) {
3840 + function print_text_ldap_search_base( $args = '' ) {
4961 3841 // Get plugin option.
4962 - $option = 'ldap_search_base';
3842 + $option = 'ldap_search_base';
4963 3843 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4964 3844
4965 3845 // Print option elements.
4966 - ?>
4967 - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:330px;"><?php echo esc_attr( $auth_settings_option ); ?></textarea>
4968 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: ou=people,dc=example,dc=edu', 'authorizer' ); ?></label>
4969 - <br /><small><?php esc_html_e( 'If you have multiple search bases, separate them by newlines (one per line).', 'authorizer' ); ?></small>
4970 - <?php
3846 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="ou=people,dc=example,dc=edu" style="width:330px;" /><?php
4971 3847 }
4972 3848
4973 3849
4974 - /**
4975 - * Settings print callback.
4976 - *
4977 - * @param string $args Args (e.g., multisite admin mode).
4978 - * @return void
4979 - */
4980 - public function print_text_ldap_uid( $args = '' ) {
3850 + function print_text_ldap_uid( $args = '' ) {
4981 3851 // Get plugin option.
4982 - $option = 'ldap_uid';
3852 + $option = 'ldap_uid';
4983 3853 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
4984 3854
4985 3855 // Print option elements.
4986 - ?>
4987 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:80px;" />
4988 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: uid', 'authorizer' ); ?></label>
4989 - <?php
3856 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="uid" style="width:80px;" /><?php
4990 3857 }
4991 3858
4992 3859
4993 - /**
4994 - * Settings print callback.
4995 - *
4996 - * @param string $args Args (e.g., multisite admin mode).
4997 - * @return void
4998 - */
4999 - public function print_text_ldap_attr_email( $args = '' ) {
3860 + function print_text_ldap_attr_email( $args = '' ) {
5000 3861 // Get plugin option.
5001 - $option = 'ldap_attr_email';
3862 + $option = 'ldap_attr_email';
5002 3863 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5003 3864
5004 3865 // Print option elements.
5005 - ?>
5006 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5007 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label>
5008 - <br /><small><?php echo wp_kses( __( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small>
5009 - <?php
3866 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="mail" />
3867 + <br /><small><?php _e( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php
5010 3868 }
5011 3869
5012 3870
5013 - /**
5014 - * Settings print callback.
5015 - *
5016 - * @param string $args Args (e.g., multisite admin mode).
5017 - * @return void
5018 - */
5019 - public function print_text_ldap_user( $args = '' ) {
3871 + function print_text_ldap_user( $args = '' ) {
5020 3872 // Get plugin option.
5021 - $option = 'ldap_user';
3873 + $option = 'ldap_user';
5022 3874 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5023 3875
5024 3876 // Print option elements.
5025 - ?>
5026 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" />
5027 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label>
5028 - <?php
3877 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="cn=directory-user,ou=specials,dc=example,dc=edu" style="width:330px;" /><?php
5029 3878 }
5030 3879
5031 3880
5032 - /**
5033 - * Settings print callback.
5034 - *
5035 - * @param string $args Args (e.g., multisite admin mode).
5036 - * @return void
5037 - */
5038 - public function print_password_ldap_password( $args = '' ) {
3881 + function print_password_ldap_password( $args = '' ) {
5039 3882 // Get plugin option.
5040 - $option = 'ldap_password';
3883 + $option = 'ldap_password';
5041 3884 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5042 3885
5043 3886 // Print option elements.
5044 - ?>
5045 - <input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
5046 - <input type="password" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $this->decrypt( $auth_settings_option ) ); ?>" autocomplete="off" />
5047 - <?php
3887 + ?><input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" />
3888 + <input type="password" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $this->decrypt( base64_decode( $auth_settings_option ) ); ?>" autocomplete="off" /><?php
5048 3889 }
5049 3890
5050 3891
5051 - /**
5052 - * Settings print callback.
5053 - *
5054 - * @param string $args Args (e.g., multisite admin mode).
5055 - * @return void
5056 - */
5057 - public function print_text_ldap_lostpassword_url( $args = '' ) {
3892 + function print_text_ldap_lostpassword_url( $args = '' ) {
5058 3893 // Get plugin option.
5059 - $option = 'ldap_lostpassword_url';
3894 + $option = 'ldap_lostpassword_url';
5060 3895 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5061 3896
5062 3897 // Print option elements.
5063 - ?>
5064 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width: 400px;" />
5065 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label>
5066 - <?php
3898 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="https://myschool.example.edu:8888/am-forgot-password" style="width: 400px;" /><?php
5067 3899 }
5068 3900
5069 3901
5070 - /**
5071 - * Settings print callback.
5072 - *
5073 - * @param string $args Args (e.g., multisite admin mode).
5074 - * @return void
5075 - */
5076 - public function print_text_ldap_attr_first_name( $args = '' ) {
3902 + function print_text_ldap_attr_first_name( $args = '' ) {
5077 3903 // Get plugin option.
5078 - $option = 'ldap_attr_first_name';
3904 + $option = 'ldap_attr_first_name';
5079 3905 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5080 3906
5081 3907 // Print option elements.
5082 - ?>
5083 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5084 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenname', 'authorizer' ); ?></label>
5085 - <?php
3908 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="givenname" /><?php
5086 3909 }
5087 3910
5088 3911
5089 - /**
5090 - * Settings print callback.
5091 - *
5092 - * @param string $args Args (e.g., multisite admin mode).
5093 - * @return void
5094 - */
5095 - public function print_text_ldap_attr_last_name( $args = '' ) {
3912 + function print_text_ldap_attr_last_name( $args = '' ) {
5096 3913 // Get plugin option.
5097 - $option = 'ldap_attr_last_name';
3914 + $option = 'ldap_attr_last_name';
5098 3915 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5099 3916
5100 3917 // Print option elements.
5101 - ?>
5102 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" />
5103 - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label>
5104 - <?php
3918 + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="sn" /><?php
5105 3919 }
5106 3920
5107 3921
5108 - /**
5109 - * Settings print callback.
5110 - *
5111 - * @param string $args Args (e.g., multisite admin mode).
5112 - * @return void
5113 - */
5114 - public function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
3922 + function print_checkbox_ldap_attr_update_on_login( $args = '' ) {
5115 3923 // Get plugin option.
5116 - $option = 'ldap_attr_update_on_login';
3924 + $option = 'ldap_attr_update_on_login';
5117 3925 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5118 3926
5119 3927 // Print option elements.
5120 - ?>
5121 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label>
5122 - <?php
3928 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php
5123 3929 }
5124 3930
5125 3931
5126 - /**
5127 - * Settings print callback.
5128 - *
5129 - * @param string $args Args (e.g., multisite admin mode).
5130 - * @return void
5131 - */
5132 - public function print_section_info_advanced( $args = '' ) {
5133 - ?>
5134 - <div id="section_info_advanced" class="section_info">
5135 - <p><?php esc_html_e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
5136 - </div>
5137 - <?php
3932 + function print_section_info_advanced( $args = '' ) {
3933 + ?><div id="section_info_advanced" class="section_info">
3934 + <p><?php _e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p>
3935 + </div><?php
5138 3936 }
5139 3937
5140 3938
5141 - /**
5142 - * Settings print callback.
5143 - *
5144 - * @param string $args Args (e.g., multisite admin mode).
5145 - * @return void
5146 - */
5147 - public function print_text_auth_advanced_lockouts( $args = '' ) {
3939 + function print_text_auth_advanced_lockouts( $args = '' ) {
5148 3940 // Get plugin option.
5149 - $option = 'advanced_lockouts';
3941 + $option = 'advanced_lockouts';
5150 3942 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5151 3943
5152 3944 // Print option elements.
5153 - esc_html_e( 'After', 'authorizer' );
5154 - ?>
5155 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_1]" value="<?php echo esc_attr( $auth_settings_option['attempts_1'] ); ?>" placeholder="10" style="width:30px;" />
5156 - <?php esc_html_e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
5157 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_1]" value="<?php echo esc_attr( $auth_settings_option['duration_1'] ); ?>" placeholder="1" style="width:30px;" />
5158 - <?php esc_html_e( 'minute(s).', 'authorizer' ); ?>
3945 + ?><?php _e( 'After', 'authorizer' ); ?>
3946 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_1" name="auth_settings[<?php echo $option; ?>][attempts_1]" value="<?php echo $auth_settings_option['attempts_1']; ?>" placeholder="10" style="width:30px;" />
3947 + <?php _e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?>
3948 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_1" name="auth_settings[<?php echo $option; ?>][duration_1]" value="<?php echo $auth_settings_option['duration_1']; ?>" placeholder="1" style="width:30px;" />
3949 + <?php _e( 'minute(s).', 'authorizer' ); ?>
5159 3950 <br />
5160 - <?php esc_html_e( 'After', 'authorizer' ); ?>
5161 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_2]" value="<?php echo esc_attr( $auth_settings_option['attempts_2'] ); ?>" placeholder="10" style="width:30px;" />
5162 - <?php esc_html_e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
5163 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_2]" value="<?php echo esc_attr( $auth_settings_option['duration_2'] ); ?>" placeholder="10" style="width:30px;" />
5164 - <?php esc_html_e( 'minutes.', 'authorizer' ); ?>
3951 + <?php _e( 'After', 'authorizer' ); ?>
3952 + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_2" name="auth_settings[<?php echo $option; ?>][attempts_2]" value="<?php echo $auth_settings_option['attempts_2']; ?>" placeholder="10" style="width:30px;" />
3953 + <?php _e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?>
3954 + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_2" name="auth_settings[<?php echo $option; ?>][duration_2]" value="<?php echo $auth_settings_option['duration_2']; ?>" placeholder="10" style="width:30px;" />
3955 + <?php _e( 'minutes.', 'authorizer' ); ?>
5165 3956 <br />
5166 - <?php esc_html_e( 'Reset the delays after', 'authorizer' ); ?>
5167 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_reset_duration" name="auth_settings[<?php echo esc_attr( $option ); ?>][reset_duration]" value="<?php echo esc_attr( $auth_settings_option['reset_duration'] ); ?>" placeholder="240" style="width:40px;" />
5168 - <?php esc_html_e( 'minutes with no invalid attempts.', 'authorizer' ); ?>
5169 - <?php
3957 + <?php _e( 'Reset the delays after', 'authorizer' ); ?>
3958 + <input type="text" id="auth_settings_<?php echo $option; ?>_reset_duration" name="auth_settings[<?php echo $option; ?>][reset_duration]" value="<?php echo $auth_settings_option['reset_duration']; ?>" placeholder="240" style="width:40px;" />
3959 + <?php _e( 'minutes with no invalid attempts.', 'authorizer' ); ?><?php
5170 3960 }
5171 3961
5172 3962
5173 - /**
5174 - * Settings print callback.
5175 - *
5176 - * @param string $args Args (e.g., multisite admin mode).
5177 - * @return void
5178 - */
5179 - public function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
3963 + function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) {
5180 3964 // Get plugin option.
5181 - $option = 'advanced_hide_wp_login';
3965 + $option = 'advanced_hide_wp_login';
5182 3966 $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5183 3967
5184 3968 // Print option elements.
5185 - ?>
5186 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
5187 - <p><small><?php esc_html_e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo esc_attr( wp_login_url() ); ?>?external=wordpress" target="_blank"><?php echo esc_html( wp_login_url() ); ?>?external=wordpress</a>.</p>
5188 - <?php
3969 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></label>
3970 + <p><small><?php _e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo wp_login_url(); ?>?external=wordpress" target="_blank"><?php echo wp_login_url(); ?>?external=wordpress</a>.</p><?php
5189 3971 }
5190 3972
5191 3973
5192 - /**
5193 - * Settings print callback.
5194 - *
5195 - * @param string $args Args (e.g., multisite admin mode).
5196 - * @return void
5197 - */
5198 - public function print_radio_auth_advanced_branding( $args = '' ) {
3974 + function print_radio_auth_advanced_branding( $args = '' ) {
5199 3975 // Get plugin option.
5200 - $option = 'advanced_branding';
3976 + $option = 'advanced_branding';
5201 3977 $auth_settings_option = $this->get_plugin_option( $option );
5202 3978
5203 3979 // Print option elements.
5204 - ?>
5205 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="default"<?php checked( 'default' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default"><?php esc_html_e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
3980 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_default" name="auth_settings[<?php echo $option; ?>]" value="default"<?php checked( 'default' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_default"><?php _e( 'Default WordPress login screen', 'authorizer' ); ?></label><br />
5206 3981 <?php
5207 3982
5208 3983 /**
5209 3984 * Developers can use the `authorizer_add_branding_option` filter
@@ -5208,8 +3983,9 @@
5208 3983 /**
5209 3984 * Developers can use the `authorizer_add_branding_option` filter
5210 3985 * to add a radio button for "Custom WordPress login branding"
5211 3986 * under the "Advanced" tab in Authorizer options. Example:
3987 + *
5212 3988 * function my_authorizer_add_branding_option( $branding_options ) {
5213 3989 * $new_branding_option = array(
5214 3990 * 'value' => 'your_brand'
5215 3991 * 'description' => 'Custom Your Brand Login Screen',
@@ -5223,274 +3999,133 @@
5223 3999 */
5224 4000 $branding_options = array();
5225 4001 $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options );
5226 4002 foreach ( $branding_options as $branding_option ) {
5227 - // Make sure the custom brands have the required values.
4003 + // Make sure the custom brands have the required values
5228 4004 if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'description', $branding_option ) ) ) {
5229 4005 continue;
5230 4006 }
5231 - ?>
5232 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $branding_option['value'] ); ?>"<?php checked( $branding_option['value'] === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>"><?php echo esc_html( $branding_option['description'] ); ?></label><br />
5233 - <?php
4007 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $branding_option['value']; ?>"<?php checked( $branding_option['value'] == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>"><?php echo $branding_option['description']; ?></label><br /><?php
5234 4008 }
5235 4009
5236 4010 // Print message about adding custom brands if there are none.
5237 4011 if ( count( $branding_options ) === 0 ) {
5238 - ?>
5239 - <p><em><?php echo wp_kses( __( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ), $this->allowed_html ); ?></em></p>
5240 - <?php
4012 + ?><p><em><?php _e( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ); ?></em></p><?php
5241 4013 }
5242 4014 }
5243 4015
5244 4016
5245 - /**
5246 - * Settings print callback.
5247 - *
5248 - * @param string $args Args (e.g., multisite admin mode).
5249 - * @return void
5250 - */
5251 - public function print_radio_auth_advanced_admin_menu( $args = '' ) {
4017 + function print_radio_auth_advanced_admin_menu( $args = '' ) {
5252 4018 // Get plugin option.
5253 - $option = 'advanced_admin_menu';
4019 + $option = 'advanced_admin_menu';
5254 4020 $auth_settings_option = $this->get_plugin_option( $option );
5255 4021
5256 4022 // Print option elements.
5257 - ?>
5258 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="settings"<?php checked( 'settings' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings"><?php esc_html_e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
5259 - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="top"<?php checked( 'top' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top"><?php esc_html_e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br />
5260 - <?php
4023 + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_settings" name="auth_settings[<?php echo $option; ?>]" value="settings"<?php checked( 'settings' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_settings"><?php _e( 'Show in Settings menu', 'authorizer' ); ?></label><br />
4024 + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_top" name="auth_settings[<?php echo $option; ?>]" value="top"<?php checked( 'top' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_top"><?php _e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br /><?php
5261 4025
5262 4026 }
5263 4027
5264 4028
5265 - /**
5266 - * Settings print callback.
5267 - *
5268 - * @param string $args Args (e.g., multisite admin mode).
5269 - * @return void
5270 - */
5271 - public function print_select_auth_advanced_usermeta( $args = '' ) {
4029 + function print_select_auth_advanced_usermeta( $args = '' ) {
5272 4030 // Get plugin option.
5273 - $option = 'advanced_usermeta';
4031 + $option = 'advanced_usermeta';
5274 4032 $auth_settings_option = $this->get_plugin_option( $option );
5275 4033
5276 4034 // Print option elements.
5277 - ?>
5278 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5279 - <option value=""><?php esc_html_e( '-- None --', 'authorizer' ); ?></option>
5280 - <?php
5281 - if ( class_exists( 'acf' ) ) :
4035 + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]">
4036 + <option value=""><?php _e( '-- None --', 'authorizer' ); ?></option>
4037 + <?php if ( class_exists( 'acf' ) ) :
5282 4038 // Get ACF 5 fields. Note: it would be much easier to use `get_field_objects()`
5283 4039 // or `get_field_objects( 'user_' . get_current_user_id() )`, but neither will
5284 4040 // list fields that have never been given values for users (i.e., new ACF
5285 4041 // fields). Therefore we fall back on finding any ACF fields applied to users
5286 4042 // (user_role or user_form location rules in the field group definition).
5287 - $fields = array();
4043 + $fields = array();
5288 4044 $acf_field_group_ids = array();
5289 - $acf_field_groups = new WP_Query(
5290 - array(
5291 - 'post_type' => 'acf-field-group',
5292 - )
5293 - );
4045 + $acf_field_groups = new WP_Query( array(
4046 + 'post_type' => 'acf-field-group',
4047 + ));
5294 4048 while ( $acf_field_groups->have_posts() ) : $acf_field_groups->the_post();
5295 4049 if ( strpos( get_the_content(), 's:5:"param";s:9:"user_role"' ) !== false || strpos( get_the_content(), 's:5:"param";s:9:"user_form"' ) !== false ) :
5296 4050 array_push( $acf_field_group_ids, get_the_ID() );
5297 4051 endif;
5298 - endwhile;
5299 - wp_reset_postdata();
4052 + endwhile; wp_reset_postdata();
5300 4053 foreach ( $acf_field_group_ids as $acf_field_group_id ) :
5301 - $acf_fields = new WP_Query(
5302 - array(
5303 - 'post_type' => 'acf-field',
5304 - 'post_parent' => $acf_field_group_id,
5305 - )
5306 - );
4054 + $acf_fields = new WP_Query( array(
4055 + 'post_type' => 'acf-field',
4056 + 'post_parent' => $acf_field_group_id,
4057 + ));
5307 4058 while ( $acf_fields->have_posts() ) : $acf_fields->the_post();
5308 4059 global $post;
5309 - $fields[ $post->post_name ] = get_field_object( $post->post_name );
5310 - endwhile;
5311 - wp_reset_postdata();
4060 + $fields[$post->post_name] = get_field_object( $post->post_name );
4061 + endwhile; wp_reset_postdata();
5312 4062 endforeach;
5313 4063 // Get ACF 4 fields.
5314 - $acf4_field_groups = new WP_Query(
5315 - array(
5316 - 'post_type' => 'acf',
5317 - )
5318 - );
4064 + $acf4_field_groups = new WP_Query( array(
4065 + 'post_type' => 'acf',
4066 + ));
5319 4067 while ( $acf4_field_groups->have_posts() ) : $acf4_field_groups->the_post();
5320 4068 $field_group_rules = get_post_meta( get_the_ID(), 'rule', true );
5321 - if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && 'ef_user' === $field_group_rules['param'] ) :
4069 + if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && $field_group_rules['param'] === 'ef_user' ) :
5322 4070 $acf4_fields = get_post_custom( get_the_ID() );
5323 4071 foreach ( $acf4_fields as $meta_key => $meta_value ) :
5324 4072 if ( strpos( $meta_key, 'field_' ) === 0 ) :
5325 - $meta_value = unserialize( $meta_value[0] );
5326 - $fields[ $meta_key ] = $meta_value;
4073 + $meta_value = unserialize( $meta_value[0] );
4074 + $fields[$meta_key] = $meta_value;
5327 4075 endif;
5328 4076 endforeach;
5329 4077 endif;
5330 - endwhile;
5331 - wp_reset_postdata();
5332 - ?>
4078 + endwhile; wp_reset_postdata(); ?>
5333 4079 <optgroup label="ACF User Fields:">
5334 - <?php foreach ( (array) $fields as $field => $field_object ) : ?>
5335 - <option value="acf___<?php echo esc_attr( $field_object['key'] ); ?>"<?php selected( "acf___{$field_object['key']}" === $auth_settings_option ); ?>><?php echo esc_html( $field_object['label'] ); ?></option>
4080 + <?php foreach ( (array)$fields as $field => $field_object ) : ?>
4081 + <option value="acf___<?php echo $field_object['key']; ?>"<?php if ( $auth_settings_option === "acf___{$field_object['key']}" ) echo ' selected="selected"'; ?>><?php echo $field_object['label']; ?></option>
5336 4082 <?php endforeach; ?>
5337 4083 </optgroup>
5338 4084 <?php endif; ?>
5339 - <optgroup label="<?php esc_attr_e( 'All Usermeta:', 'authorizer' ); ?>">
5340 - <?php
5341 - foreach ( $this->get_all_usermeta_keys() as $meta_key ) :
5342 - if ( substr( $meta_key, 0, 3 ) === 'wp_' ) :
5343 - continue;
5344 - endif;
5345 - ?>
5346 - <option value="<?php echo esc_attr( $meta_key ); ?>"<?php selected( $auth_settings_option === $meta_key ); ?>><?php echo esc_html( $meta_key ); ?></option>
4085 + <optgroup label="<?php _e( 'All Usermeta:', 'authorizer' ); ?>">
4086 + <?php foreach ( $this->get_all_usermeta_keys() as $meta_key ) : if ( substr( $meta_key, 0, 3 ) === 'wp_' ) continue; ?>
4087 + <option value="<?php echo $meta_key; ?>"<?php if ( $auth_settings_option === $meta_key ) echo ' selected="selected"'; ?>><?php echo $meta_key; ?></option>
5347 4088 <?php endforeach; ?>
5348 4089 </optgroup>
5349 - </select>
5350 - <?php
4090 + </select><?php
5351 4091 }
5352 4092
5353 4093
5354 - /**
5355 - * Settings print callback.
5356 - *
5357 - * @param string $args Args (e.g., multisite admin mode).
5358 - * @return void
5359 - */
5360 - public function print_text_auth_advanced_users_per_page( $args = '' ) {
4094 + function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5361 4095 // Get plugin option.
5362 - $option = 'advanced_users_per_page';
5363 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5364 -
5365 - // Print option elements.
5366 - ?>
5367 - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" size="4" />
5368 - <?php
5369 - }
5370 -
5371 -
5372 - /**
5373 - * Settings print callback.
5374 - *
5375 - * @param string $args Args (e.g., multisite admin mode).
5376 - * @return void
5377 - */
5378 - public function print_select_auth_advanced_users_sort_by( $args = '' ) {
5379 - // Get plugin option.
5380 - $option = 'advanced_users_sort_by';
5381 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5382 -
5383 - // Print option elements.
5384 - ?>
5385 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5386 - <option value="created" <?php selected( $auth_settings_option, 'created' ); ?>><?php esc_html_e( 'Date approved', 'authorizer' ); ?></option>
5387 - <option value="email" <?php selected( $auth_settings_option, 'email' ); ?>><?php esc_html_e( 'Email', 'authorizer' ); ?></option>
5388 - <option value="role" <?php selected( $auth_settings_option, 'role' ); ?>><?php esc_html_e( 'Role', 'authorizer' ); ?></option>
5389 - <option value="date_added" <?php selected( $auth_settings_option, 'date_added' ); ?>><?php esc_html_e( 'Date registered', 'authorizer' ); ?></option>
5390 - </select>
5391 - <?php
5392 - }
5393 -
5394 -
5395 - /**
5396 - * Settings print callback.
5397 - *
5398 - * @param string $args Args (e.g., multisite admin mode).
5399 - * @return void
5400 - */
5401 - public function print_select_auth_advanced_users_sort_order( $args = '' ) {
5402 - // Get plugin option.
5403 - $option = 'advanced_users_sort_order';
5404 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5405 -
5406 - // Print option elements.
5407 - ?>
5408 - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]">
5409 - <option value="asc" <?php selected( $auth_settings_option, 'asc' ); ?>><?php esc_html_e( 'Ascending', 'authorizer' ); ?></option>
5410 - <option value="desc" <?php selected( $auth_settings_option, 'desc' ); ?>><?php esc_html_e( 'Descending', 'authorizer' ); ?></option>
5411 - </select>
5412 - <?php
5413 - }
5414 -
5415 -
5416 - /**
5417 - * Settings print callback.
5418 - *
5419 - * @param string $args Args (e.g., multisite admin mode).
5420 - * @return void
5421 - */
5422 - public function print_checkbox_auth_advanced_widget_enabled( $args = '' ) {
5423 - // Get plugin option.
5424 - $option = 'advanced_widget_enabled';
5425 - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' );
5426 -
5427 - // Print option elements.
5428 - ?>
5429 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></label>
5430 - <p><small><?php esc_html_e( 'Note: Only users with the create_users capability will be able to see the dashboard widget.', 'authorizer' ); ?></small></p>
5431 - <?php
5432 - }
5433 -
5434 -
5435 - /**
5436 - * Settings print callback.
5437 - *
5438 - * @param string $args Args (e.g., multisite admin mode).
5439 - * @return void
5440 - */
5441 - public function print_checkbox_auth_advanced_override_multisite( $args = '' ) {
5442 - // Get plugin option.
5443 - $option = 'advanced_override_multisite';
4096 + $option = 'advanced_override_multisite';
5444 4097 $auth_settings_option = $this->get_plugin_option( $option );
5445 4098
5446 4099 // Print option elements.
5447 - ?>
5448 - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label>
5449 - <?php
4100 + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label><?php
5450 4101 }
5451 4102
5452 4103
5453 4104
5454 4105 /**
5455 - * Determines whether we are in single site or multisite admin context.
5456 - *
5457 - * @param string $args Args (e.g., multisite admin mode).
5458 - * @return int Current mode.
5459 - */
5460 - private function get_admin_mode( $args ) {
5461 - if ( is_array( $args ) && array_key_exists( WP_Plugin_Authorizer::NETWORK_CONTEXT, $args ) && true === $args[ WP_Plugin_Authorizer::NETWORK_CONTEXT ] ) {
5462 - return WP_Plugin_Authorizer::NETWORK_CONTEXT;
5463 - } else {
5464 - return WP_Plugin_Authorizer::SINGLE_CONTEXT;
5465 - }
5466 - }
5467 -
5468 -
5469 - /**
5470 4106 * Add help documentation to the options page.
5471 - *
5472 - * Action: load-settings_page_authorizer > admin_head
4107 + * Run on action hook chain: load-settings_page_authorizer > admin_head
5473 4108 */
5474 4109 public function admin_head() {
5475 4110 $screen = get_current_screen();
5476 4111
5477 - // Add help tab for Access Lists Settings.
4112 + // Add help tab for Access Lists Settings
5478 4113 $help_auth_settings_access_lists_content = '
5479 - <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) . '</p>
5480 - <p>' . __( '<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.', 'authorizer' ) . '</p>
5481 - <p>' . __( '<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ) . '</p>
5482 - <p>' . __( 'Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.', 'authorizer' ) . '</p>
4114 + <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) .'</p>
4115 + <p>' . __( "<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.", 'authorizer' ) . '</p>
4116 + <p>' . __( "<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.", 'authorizer' ) . '</p>
4117 + <p>' . __( "Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.", 'authorizer' ) . '</p>
5483 4118 ';
5484 4119 $screen->add_help_tab(
5485 4120 array(
5486 - 'id' => 'help_auth_settings_access_lists_content',
5487 - 'title' => __( 'Access Lists', 'authorizer' ),
4121 + 'id' => 'help_auth_settings_access_lists_content',
4122 + 'title' => __( 'Access Lists', 'authorizer' ),
5488 4123 'content' => $help_auth_settings_access_lists_content,
5489 4124 )
5490 4125 );
5491 4126
5492 - // Add help tab for Login Access Settings.
4127 + // Add help tab for Login Access Settings
5493 4128 $help_auth_settings_access_login_content = '
5494 4129 <p>' . __( "<strong>Who can log in to the site?</strong>: Choose the level of access restriction you'd like to use on your site here. You can leave the site open to anyone with a WordPress account or an account on an external service like Google, CAS, or LDAP, or restrict it to WordPress users and only the external users that you specify via the <em>Access Lists</em>.", 'authorizer' ) . '</p>
5495 4130 <p>' . __( "<strong>Which role should receive email notifications about pending users?</strong>: If you've restricted access to <strong>approved users</strong>, you can determine which WordPress users will receive a notification email everytime a new external user successfully logs in and is added to the pending list. All users of the specified role will receive an email, and the external user will get a message (specified below) telling them their access is pending approval.", 'authorizer' ) . '</p>
5496 4131 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
@@ -5496,84 +4131,84 @@
5496 4131 <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p>
5497 4132 ';
5498 4133 $screen->add_help_tab(
5499 4134 array(
5500 - 'id' => 'help_auth_settings_access_login_content',
5501 - 'title' => __( 'Login Access', 'authorizer' ),
4135 + 'id' => 'help_auth_settings_access_login_content',
4136 + 'title' => __( 'Login Access', 'authorizer' ),
5502 4137 'content' => $help_auth_settings_access_login_content,
5503 4138 )
5504 4139 );
5505 4140
5506 - // Add help tab for Public Access Settings.
4141 + // Add help tab for Public Access Settings
5507 4142 $help_auth_settings_access_public_content = '
5508 4143 <p>' . __( "<strong>Who can view the site?</strong>: You can restrict the site's visibility by only allowing logged in users to see pages. If you do so, you can customize the specifics about the site's privacy using the settings below.", 'authorizer' ) . '</p>
5509 4144 <p>' . __( "<strong>What pages (if any) should be available to everyone?</strong>: If you'd like to declare certain pages on your site as always public (such as the course syllabus, introduction, or calendar), specify those pages here. These pages will always be available no matter what access restrictions exist.", 'authorizer' ) . '</p>
5510 - <p>' . __( '<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.', 'authorizer' ) . '</p>
5511 - <p>' . __( '<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.', 'authorizer' ) . '</p>
5512 - <p>' . __( '<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.', 'authorizer' ) . '</p>
4145 + <p>' . __( "<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.", 'authorizer' ) . '</p>
4146 + <p>' . __( "<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.", 'authorizer' ) . '</p>
4147 + <p>' . __( "<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.", 'authorizer' ) . '</p>
5513 4148 ';
5514 4149 $screen->add_help_tab(
5515 4150 array(
5516 - 'id' => 'help_auth_settings_access_public_content',
5517 - 'title' => __( 'Public Access', 'authorizer' ),
4151 + 'id' => 'help_auth_settings_access_public_content',
4152 + 'title' => __( 'Public Access', 'authorizer' ),
5518 4153 'content' => $help_auth_settings_access_public_content,
5519 4154 )
5520 4155 );
5521 4156
5522 - // Add help tab for External Service (CAS, LDAP) Settings.
4157 + // Add help tab for External Service (CAS, LDAP) Settings
5523 4158 $help_auth_settings_external_content = '
5524 4159 <p>' . __( "<strong>Type of external service to authenticate against</strong>: Choose which authentication service type you will be using. You'll have to fill out different fields below depending on which service you choose.", 'authorizer' ) . '</p>
5525 - <p>' . __( '<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.', 'authorizer' ) . '</p>
5526 - <p>' . __( '<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.', 'authorizer' ) . '</p>
5527 - <p>' . __( '<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.', 'authorizer' ) . '</p>
5528 - <p>' . __( '<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!', 'authorizer' ) . '</p>
5529 - <p><strong><em>' . __( 'If you enable Google logins:', 'authorizer' ) . '</em></strong></p>
4160 + <p>' . __( "<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.", 'authorizer' ) . '</p>
4161 + <p>' . __( "<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.", 'authorizer' ) . '</p>
4162 + <p>' . __( "<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.", 'authorizer' ) . '</p>
4163 + <p>' . __( "<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!", 'authorizer' ) . '</p>
4164 + <p><strong><em>' . __( "If you enable Google logins:", 'authorizer' ) . '</em></strong></p>
5530 4165 <ul>
5531 4166 <li>' . __( "<strong>Google Client ID</strong>: You can generate this ID by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client ID typically looks something like this: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com", 'authorizer' ) . '</li>
5532 4167 <li>' . __( "<strong>Google Client Secret</strong>: You can generate this secret by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client Secret typically looks something like this: sDNgX5_pr_5bly-frKmvp8jT", 'authorizer' ) . '</li>
5533 4168 </ul>
5534 - <p><strong><em>' . __( 'If you enable CAS logins:', 'authorizer' ) . '</em></strong></p>
4169 + <p><strong><em>' . __( "If you enable CAS logins:", 'authorizer' ) . '</em></strong></p>
5535 4170 <ul>
5536 - <li>' . __( '<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).', 'authorizer' ) . '</li>
5537 - <li>' . __( '<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).', 'authorizer' ) . '</li>
5538 - <li>' . __( '<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).', 'authorizer' ) . '</li>
4171 + <li>' . __( "<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).", 'authorizer' ) . '</li>
4172 + <li>' . __( "<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).", 'authorizer' ) . '</li>
4173 + <li>' . __( "<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).", 'authorizer' ) . '</li>
5539 4174 <li>' . __( "<strong>CAS attribute containing first name</strong>: Enter the CAS attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5540 4175 <li>' . __( "<strong>CAS attribute containing last name</strong>: Enter the CAS attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li>
5541 - <li>' . __( '<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4176 + <li>' . __( "<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5542 4177 </ul>
5543 - <p><strong><em>' . __( 'If you enable LDAP logins:', 'authorizer' ) . '</em></strong></p>
4178 + <p><strong><em>' . __( "If you enable LDAP logins:", 'authorizer' ) . '</em></strong></p>
5544 4179 <ul>
5545 - <li>' . __( '<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.', 'authorizer' ) . '</li>
5546 - <li>' . __( '<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.', 'authorizer' ) . '</li>
5547 - <li>' . __( '<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu', 'authorizer' ) . '</li>
5548 - <li>' . __( '<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.', 'authorizer' ) . '</li>
5549 - <li>' . __( '<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.', 'authorizer' ) . '</li>
5550 - <li>' . __( '<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.', 'authorizer' ) . '</li>
5551 - <li>' . __( '<strong>Use TLS</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.', 'authorizer' ) . '</li>
4180 + <li>' . __( "<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.", 'authorizer' ) . '</li>
4181 + <li>' . __( "<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.", 'authorizer' ) . '</li>
4182 + <li>' . __( "<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu", 'authorizer' ) . '</li>
4183 + <li>' . __( "<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.", 'authorizer' ) . '</li>
4184 + <li>' . __( "<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.", 'authorizer' ) . '</li>
4185 + <li>' . __( "<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.", 'authorizer' ) . '</li>
4186 + <li>' . __( "<strong>Secure Connection (TLS)</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.", 'authorizer' ) . '</li>
5552 4187 <li>' . __( "<strong>Custom lost password URL</strong>: The WordPress login page contains a link to recover a lost password. If you have external users who shouldn't change the password on their WordPress account, point them to the appropriate location to change the password on their external authentication service here.", 'authorizer' ) . '</li>
5553 4188 <li>' . __( "<strong>LDAP attribute containing first name</strong>: Enter the LDAP attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5554 4189 <li>' . __( "<strong>LDAP attribute containing last name</strong>: Enter the LDAP attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li>
5555 - <li>' . __( '<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li>
4190 + <li>' . __( "<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li>
5556 4191 </ul>
5557 4192 ';
5558 4193 $screen->add_help_tab(
5559 4194 array(
5560 - 'id' => 'help_auth_settings_external_content',
5561 - 'title' => __( 'External Service', 'authorizer' ),
4195 + 'id' => 'help_auth_settings_external_content',
4196 + 'title' => __( 'External Service', 'authorizer' ),
5562 4197 'content' => $help_auth_settings_external_content,
5563 4198 )
5564 4199 );
5565 4200
5566 - // Add help tab for Advanced Settings.
4201 + // Add help tab for Advanced Settings
5567 4202 $help_auth_settings_advanced_content = '
5568 - <p>' . __( '<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.', 'authorizer' ) . '</p>
5569 - <p>' . __( '<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
4203 + <p>' . __( "<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.", 'authorizer' ) . '</p>
4204 + <p>' . __( "<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:", 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p>
5570 4205 <p>' . __( "<strong>Custom WordPress login branding</strong>: If you'd like to use custom branding on the WordPress login page, select that here. You will need to use the `authorizer_add_branding_option` filter in your theme to add it. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.", 'authorizer' ) . '</p>
5571 4206 ';
5572 4207 $screen->add_help_tab(
5573 4208 array(
5574 - 'id' => 'help_auth_settings_advanced_content',
5575 - 'title' => __( 'Advanced', 'authorizer' ),
4209 + 'id' => 'help_auth_settings_advanced_content',
4210 + 'title' => __( 'Advanced', 'authorizer' ),
5576 4211 'content' => $help_auth_settings_advanced_content,
5577 4212 )
5578 4213 );
5579 4214 }
@@ -5588,66 +4223,65 @@
5588 4223
5589 4224
5590 4225 /**
5591 4226 * Network Admin menu item
4227 + * Hook: network_admin_menu
5592 4228 *
5593 - * Action: network_admin_menu
5594 - *
4229 + * @param none
5595 4230 * @return void
5596 4231 */
5597 4232 public function network_admin_menu() {
5598 4233 // @see http://codex.wordpress.org/Function_Reference/add_menu_page
5599 4234 add_menu_page(
5600 - 'Authorizer',
5601 - 'Authorizer',
5602 - 'manage_network_options',
5603 - 'authorizer',
4235 + 'Authorizer', // Page title
4236 + 'Authorizer', // Menu title
4237 + 'manage_network_options', // Capability
4238 + 'authorizer', // Menu slug
5604 4239 array( $this, 'create_network_admin_page' ),
5605 - 'dashicons-groups',
5606 - 89 // Position.
4240 + 'dashicons-groups', // Icon URL
4241 + 89 // Position
5607 4242 );
5608 4243 }
5609 4244
5610 4245
5611 4246 /**
5612 - * Output the HTML for the options page.
4247 + * Output the HTML for the options page
5613 4248 */
5614 4249 public function create_network_admin_page() {
5615 4250 if ( ! current_user_can( 'manage_network_options' ) ) {
5616 - wp_die( wp_kses( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ), $this->allowed_html ) );
4251 + wp_die( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ) );
5617 4252 }
5618 - $auth_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5619 - ?>
4253 + $auth_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); ?>
5620 4254 <div class="wrap">
5621 4255 <form method="post" action="" autocomplete="off">
5622 - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2>
5623 - <p><?php echo wp_kses( __( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ), $this->allowed_html ); ?></p>
4256 + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2>
4257 + <p><?php _e( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ); ?></p>
5624 4258
5625 - <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 === intval( $auth_settings['multisite_override'] ) ); ?> /><label for="auth_settings_multisite_override"><?php esc_html_e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
4259 + <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 == $auth_settings['multisite_override'] ); ?> /><label for="auth_settings_multisite_override"><?php _e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label>
5626 4260
5627 4261 <div id="auth_multisite_settings_disabled_overlay" style="display: none;"></div>
5628 4262
5629 4263 <div class="wrap" id="auth_multisite_settings">
5630 - <?php $this->print_section_info_tabs( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?>
4264 + <?php $this->print_section_info_tabs( array( MULTISITE_ADMIN => true ) ); ?>
5631 4265
5632 4266 <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?>
5633 4267
5634 - <?php // Custom access lists (for network, we only really want approved list, not pending or blocked). ?>
4268 + <?php // Custom access lists (for network, we only really want approved list, not pending or blocked) ?>
5635 4269 <div id="section_info_access_lists" class="section_info">
5636 - <p><?php esc_html_e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
4270 + <p><?php _e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p>
5637 4271 </div>
5638 4272 <table class="form-table"><tbody>
5639 4273 <tr>
5640 - <th scope="row"><?php esc_html_e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
5641 - <td><?php $this->print_radio_auth_access_who_can_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4274 + <th scope="row"><?php _e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th>
4275 + <td><?php $this->print_radio_auth_access_who_can_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5642 4276 </tr>
5643 4277 <tr>
5644 - <th scope="row"><?php esc_html_e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
5645 - <td><?php $this->print_radio_auth_access_who_can_view( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4278 + <th scope="row"><?php _e( 'Who can view sites in this network?', 'authorizer' ); ?></th>
4279 + <td><?php $this->print_radio_auth_access_who_can_view( array( MULTISITE_ADMIN => true ) ); ?></td>
5646 4280 </tr>
5647 4281 <tr>
5648 - <th scope="row"><?php esc_html_e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php echo wp_kses( __( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ), $this->allowed_html ); ?></em></small></th>
5649 - <td><?php $this->print_combo_auth_access_users_approved( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4282 + <th scope="row"><?php _e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php _e( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ); ?></em></small></th>
4283 + <td><?php $this->print_combo_auth_access_users_approved( array( MULTISITE_ADMIN => true ) ); ?></td>
5650 4284 </tr>
5651 4285 </tbody></table>
5652 4286
5653 4287 <?php $this->print_section_info_external(); ?>
@@ -5652,122 +4286,122 @@
5652 4286
5653 4287 <?php $this->print_section_info_external(); ?>
5654 4288 <table class="form-table"><tbody>
5655 4289 <tr>
5656 - <th scope="row"><?php esc_html_e( 'Default role for new users', 'authorizer' ); ?></th>
5657 - <td><?php $this->print_select_auth_access_default_role( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4290 + <th scope="row"><?php _e( 'Default role for new users', 'authorizer' ); ?></th>
4291 + <td><?php $this->print_select_auth_access_default_role( array( MULTISITE_ADMIN => true ) ); ?></td>
5658 4292 </tr>
5659 4293 <tr>
5660 - <th scope="row"><?php esc_html_e( 'Google Logins', 'authorizer' ); ?></th>
5661 - <td><?php $this->print_checkbox_auth_external_google( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4294 + <th scope="row"><?php _e( 'Google Logins', 'authorizer' ); ?></th>
4295 + <td><?php $this->print_checkbox_auth_external_google( array( MULTISITE_ADMIN => true ) ); ?></td>
5662 4296 </tr>
5663 4297 <tr>
5664 - <th scope="row"><?php esc_html_e( 'Google Client ID', 'authorizer' ); ?></th>
5665 - <td><?php $this->print_text_google_clientid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4298 + <th scope="row"><?php _e( 'Google Client ID', 'authorizer' ); ?></th>
4299 + <td><?php $this->print_text_google_clientid( array( MULTISITE_ADMIN => true ) ); ?></td>
5666 4300 </tr>
5667 4301 <tr>
5668 - <th scope="row"><?php esc_html_e( 'Google Client Secret', 'authorizer' ); ?></th>
5669 - <td><?php $this->print_text_google_clientsecret( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4302 + <th scope="row"><?php _e( 'Google Client Secret', 'authorizer' ); ?></th>
4303 + <td><?php $this->print_text_google_clientsecret( array( MULTISITE_ADMIN => true ) ); ?></td>
5670 4304 </tr>
5671 4305 <tr>
5672 - <th scope="row"><?php esc_html_e( 'Google Hosted Domain', 'authorizer' ); ?></th>
5673 - <td><?php $this->print_text_google_hosteddomain( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4306 + <th scope="row"><?php _e( 'Google Hosted Domain', 'authorizer' ); ?></th>
4307 + <td><?php $this->print_text_google_hosteddomain( array( MULTISITE_ADMIN => true ) ); ?></td>
5674 4308 </tr>
5675 4309 <tr>
5676 - <th scope="row"><?php esc_html_e( 'CAS Logins', 'authorizer' ); ?></th>
5677 - <td><?php $this->print_checkbox_auth_external_cas( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4310 + <th scope="row"><?php _e( 'CAS Logins', 'authorizer' ); ?></th>
4311 + <td><?php $this->print_checkbox_auth_external_cas( array( MULTISITE_ADMIN => true ) ); ?></td>
5678 4312 </tr>
5679 4313 <tr>
5680 - <th scope="row"><?php esc_html_e( 'CAS Custom Label', 'authorizer' ); ?></th>
5681 - <td><?php $this->print_text_cas_custom_label( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4314 + <th scope="row"><?php _e( 'CAS Custom Label', 'authorizer' ); ?></th>
4315 + <td><?php $this->print_text_cas_custom_label( array( MULTISITE_ADMIN => true ) ); ?></td>
5682 4316 </tr>
5683 4317 <tr>
5684 - <th scope="row"><?php esc_html_e( 'CAS server hostname', 'authorizer' ); ?></th>
5685 - <td><?php $this->print_text_cas_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4318 + <th scope="row"><?php _e( 'CAS server hostname', 'authorizer' ); ?></th>
4319 + <td><?php $this->print_text_cas_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5686 4320 </tr>
5687 4321 <tr>
5688 - <th scope="row"><?php esc_html_e( 'CAS server port', 'authorizer' ); ?></th>
5689 - <td><?php $this->print_text_cas_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4322 + <th scope="row"><?php _e( 'CAS server port', 'authorizer' ); ?></th>
4323 + <td><?php $this->print_text_cas_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5690 4324 </tr>
5691 4325 <tr>
5692 - <th scope="row"><?php esc_html_e( 'CAS server path/context', 'authorizer' ); ?></th>
5693 - <td><?php $this->print_text_cas_path( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4326 + <th scope="row"><?php _e( 'CAS server path/context', 'authorizer' ); ?></th>
4327 + <td><?php $this->print_text_cas_path( array( MULTISITE_ADMIN => true ) ); ?></td>
5694 4328 </tr>
5695 4329 <tr>
5696 - <th scope="row"><?php esc_html_e( 'CAS server version', 'authorizer' ); ?></th>
5697 - <td><?php $this->print_select_cas_version( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4330 + <th scope="row"><?php _e( 'CAS server version', 'authorizer' ); ?></th>
4331 + <td><?php $this->print_select_cas_version( array( MULTISITE_ADMIN => true ) ); ?></td>
5698 4332 </tr>
5699 4333 <tr>
5700 - <th scope="row"><?php esc_html_e( 'CAS attribute containing email', 'authorizer' ); ?></th>
5701 - <td><?php $this->print_text_cas_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4334 + <th scope="row"><?php _e( 'CAS attribute containing email', 'authorizer' ); ?></th>
4335 + <td><?php $this->print_text_cas_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5702 4336 </tr>
5703 4337 <tr>
5704 - <th scope="row"><?php esc_html_e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
5705 - <td><?php $this->print_text_cas_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4338 + <th scope="row"><?php _e( 'CAS attribute containing first name', 'authorizer' ); ?></th>
4339 + <td><?php $this->print_text_cas_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5706 4340 </tr>
5707 4341 <tr>
5708 - <th scope="row"><?php esc_html_e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
5709 - <td><?php $this->print_text_cas_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4342 + <th scope="row"><?php _e( 'CAS attribute containing last name', 'authorizer' ); ?></th>
4343 + <td><?php $this->print_text_cas_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5710 4344 </tr>
5711 4345 <tr>
5712 - <th scope="row"><?php esc_html_e( 'CAS attribute update', 'authorizer' ); ?></th>
5713 - <td><?php $this->print_checkbox_cas_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4346 + <th scope="row"><?php _e( 'CAS attribute update', 'authorizer' ); ?></th>
4347 + <td><?php $this->print_checkbox_cas_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5714 4348 </tr>
5715 4349 <tr>
5716 - <th scope="row"><?php esc_html_e( 'CAS automatic login', 'authorizer' ); ?></th>
5717 - <td><?php $this->print_checkbox_cas_auto_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4350 + <th scope="row"><?php _e( 'CAS automatic login', 'authorizer' ); ?></th>
4351 + <td><?php $this->print_checkbox_cas_auto_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5718 4352 </tr>
5719 4353 <tr>
5720 - <th scope="row"><?php esc_html_e( 'LDAP Logins', 'authorizer' ); ?></th>
5721 - <td><?php $this->print_checkbox_auth_external_ldap( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4354 + <th scope="row"><?php _e( 'LDAP Logins', 'authorizer' ); ?></th>
4355 + <td><?php $this->print_checkbox_auth_external_ldap( array( MULTISITE_ADMIN => true ) ); ?></td>
5722 4356 </tr>
5723 4357 <tr>
5724 - <th scope="row"><?php esc_html_e( 'LDAP Host', 'authorizer' ); ?></th>
5725 - <td><?php $this->print_text_ldap_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4358 + <th scope="row"><?php _e( 'LDAP Host', 'authorizer' ); ?></th>
4359 + <td><?php $this->print_text_ldap_host( array( MULTISITE_ADMIN => true ) ); ?></td>
5726 4360 </tr>
5727 4361 <tr>
5728 - <th scope="row"><?php esc_html_e( 'LDAP Port', 'authorizer' ); ?></th>
5729 - <td><?php $this->print_text_ldap_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4362 + <th scope="row"><?php _e( 'LDAP Port', 'authorizer' ); ?></th>
4363 + <td><?php $this->print_text_ldap_port( array( MULTISITE_ADMIN => true ) ); ?></td>
5730 4364 </tr>
5731 4365 <tr>
5732 - <th scope="row"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></th>
5733 - <td><?php $this->print_checkbox_ldap_tls( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4366 + <th scope="row"><?php _e( 'Secure Connection (TLS)', 'authorizer' ); ?></th>
4367 + <td><?php $this->print_checkbox_ldap_tls( array( MULTISITE_ADMIN => true ) ); ?></td>
5734 4368 </tr>
5735 4369 <tr>
5736 - <th scope="row"><?php esc_html_e( 'LDAP Search Base', 'authorizer' ); ?></th>
5737 - <td><?php $this->print_text_ldap_search_base( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4370 + <th scope="row"><?php _e( 'LDAP Search Base', 'authorizer' ); ?></th>
4371 + <td><?php $this->print_text_ldap_search_base( array( MULTISITE_ADMIN => true ) ); ?></td>
5738 4372 </tr>
5739 4373 <tr>
5740 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
5741 - <td><?php $this->print_text_ldap_uid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4374 + <th scope="row"><?php _e( 'LDAP attribute containing username', 'authorizer' ); ?></th>
4375 + <td><?php $this->print_text_ldap_uid( array( MULTISITE_ADMIN => true ) ); ?></td>
5742 4376 </tr>
5743 4377 <tr>
5744 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
5745 - <td><?php $this->print_text_ldap_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4378 + <th scope="row"><?php _e( 'LDAP attribute containing email', 'authorizer' ); ?></th>
4379 + <td><?php $this->print_text_ldap_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td>
5746 4380 </tr>
5747 4381 <tr>
5748 - <th scope="row"><?php esc_html_e( 'LDAP Directory User', 'authorizer' ); ?></th>
5749 - <td><?php $this->print_text_ldap_user( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4382 + <th scope="row"><?php _e( 'LDAP Directory User', 'authorizer' ); ?></th>
4383 + <td><?php $this->print_text_ldap_user( array( MULTISITE_ADMIN => true ) ); ?></td>
5750 4384 </tr>
5751 4385 <tr>
5752 - <th scope="row"><?php esc_html_e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
5753 - <td><?php $this->print_password_ldap_password( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4386 + <th scope="row"><?php _e( 'LDAP Directory User Password', 'authorizer' ); ?></th>
4387 + <td><?php $this->print_password_ldap_password( array( MULTISITE_ADMIN => true ) ); ?></td>
5754 4388 </tr>
5755 4389 <tr>
5756 - <th scope="row"><?php esc_html_e( 'Custom lost password URL', 'authorizer' ); ?></th>
5757 - <td><?php $this->print_text_ldap_lostpassword_url( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4390 + <th scope="row"><?php _e( 'Custom lost password URL', 'authorizer' ); ?></th>
4391 + <td><?php $this->print_text_ldap_lostpassword_url( array( MULTISITE_ADMIN => true ) ); ?></td>
5758 4392 </tr>
5759 4393 <tr>
5760 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
5761 - <td><?php $this->print_text_ldap_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4394 + <th scope="row"><?php _e( 'LDAP attribute containing first name', 'authorizer' ); ?></th>
4395 + <td><?php $this->print_text_ldap_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5762 4396 </tr>
5763 4397 <tr>
5764 - <th scope="row"><?php esc_html_e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
5765 - <td><?php $this->print_text_ldap_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4398 + <th scope="row"><?php _e( 'LDAP attribute containing last name', 'authorizer' ); ?></th>
4399 + <td><?php $this->print_text_ldap_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td>
5766 4400 </tr>
5767 4401 <tr>
5768 - <th scope="row"><?php esc_html_e( 'LDAP attribute update', 'authorizer' ); ?></th>
5769 - <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4402 + <th scope="row"><?php _e( 'LDAP attribute update', 'authorizer' ); ?></th>
4403 + <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5770 4404 </tr>
5771 4405 </tbody></table>
5772 4406
5773 4407 <?php $this->print_section_info_advanced(); ?>
@@ -5772,36 +4406,20 @@
5772 4406
5773 4407 <?php $this->print_section_info_advanced(); ?>
5774 4408 <table class="form-table"><tbody>
5775 4409 <tr>
5776 - <th scope="row"><?php esc_html_e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
5777 - <td><?php $this->print_text_auth_advanced_lockouts( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4410 + <th scope="row"><?php _e( 'Limit invalid login attempts', 'authorizer' ); ?></th>
4411 + <td><?php $this->print_text_auth_advanced_lockouts( array( MULTISITE_ADMIN => true ) ); ?></td>
5778 4412 </tr>
5779 4413 <tr>
5780 - <th scope="row"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
5781 - <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
4414 + <th scope="row"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></th>
4415 + <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( MULTISITE_ADMIN => true ) ); ?></td>
5782 4416 </tr>
5783 - <tr>
5784 - <th scope="row"><?php esc_html_e( 'Number of users per page', 'authorizer' ); ?></th>
5785 - <td><?php $this->print_text_auth_advanced_users_per_page( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5786 - </tr>
5787 - <tr>
5788 - <th scope="row"><?php esc_html_e( 'Approved users sort method', 'authorizer' ); ?></th>
5789 - <td><?php $this->print_select_auth_advanced_users_sort_by( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5790 - </tr>
5791 - <tr>
5792 - <th scope="row"><?php esc_html_e( 'Approved users sort order', 'authorizer' ); ?></th>
5793 - <td><?php $this->print_select_auth_advanced_users_sort_order( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5794 - </tr>
5795 - <tr>
5796 - <th scope="row"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></th>
5797 - <td><?php $this->print_checkbox_auth_advanced_widget_enabled( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td>
5798 - </tr>
5799 4417 </tbody></table>
5800 4418
5801 4419 <br class="clear" />
5802 4420 </div>
5803 - <input type="button" name="submit" id="submit" class="button button-primary" value="<?php esc_attr_e( 'Save Changes', 'authorizer' ); ?>" onclick="saveAuthMultisiteSettings(this);" />
4421 + <input type="button" name="submit" id="submit" class="button button-primary" value="<?php _e( 'Save Changes', 'authorizer' ); ?>" onclick="save_auth_multisite_settings(this);" />
5804 4422 </form>
5805 4423 </div>
5806 4424 <?php
5807 4425 }
@@ -5808,12 +4426,10 @@
5808 4426
5809 4427
5810 4428 /**
5811 4429 * Save multisite settings (ajax call).
5812 - *
5813 - * Action: wp_ajax_save_auth_multisite_settings
5814 4430 */
5815 - public function ajax_save_auth_multisite_settings() {
4431 + function ajax_save_auth_multisite_settings() {
5816 4432 // Fail silently if current user doesn't have permissions.
5817 4433 if ( ! current_user_can( 'manage_network_options' ) ) {
5818 4434 die( '' );
5819 4435 }
@@ -5818,14 +4434,14 @@
5818 4434 die( '' );
5819 4435 }
5820 4436
5821 4437 // Make sure nonce exists.
5822 - if ( empty( $_POST['nonce'] ) ) {
4438 + if ( empty( $_POST['nonce_save_auth_settings'] ) ) {
5823 4439 die( '' );
5824 4440 }
5825 4441
5826 4442 // Nonce check.
5827 - if ( ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4443 + if ( ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5828 4444 die( '' );
5829 4445 }
5830 4446
5831 4447 // Assert multisite.
@@ -5833,15 +4449,15 @@
5833 4449 die( '' );
5834 4450 }
5835 4451
5836 4452 // Get multisite settings.
5837 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
4453 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
5838 4454
5839 - // Sanitize settings.
4455 + // Sanitize settings
5840 4456 $auth_multisite_settings = $this->sanitize_options( $_POST );
5841 4457
5842 - // Filter options to only the allowed values (multisite options are a subset of all options).
5843 - $allowed = array(
4458 + // Filter options to only the allowed values (multisite options are a subset of all options)
4459 + $allowed = array(
5844 4460 'multisite_override',
5845 4461 'access_who_can_login',
5846 4462 'access_who_can_view',
5847 4463 'access_default_role',
@@ -5874,17 +4490,13 @@
5874 4490 'ldap_attr_last_name',
5875 4491 'ldap_attr_update_on_login',
5876 4492 'advanced_lockouts',
5877 4493 'advanced_hide_wp_login',
5878 - 'advanced_users_per_page',
5879 - 'advanced_users_sort_by',
5880 - 'advanced_users_sort_order',
5881 - 'advanced_widget_enabled',
5882 4494 );
5883 4495 $auth_multisite_settings = array_intersect_key( $auth_multisite_settings, array_flip( $allowed ) );
5884 4496
5885 4497 // Update multisite settings in database.
5886 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
4498 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
5887 4499
5888 4500 // Return 'success' value to AJAX call.
5889 4501 die( 'success' );
5890 4502 }
@@ -5898,67 +4510,42 @@
5898 4510 */
5899 4511
5900 4512
5901 4513
5902 - /**
5903 - * Load Authorizer dashboard widget if it's enabled.
5904 - *
5905 - * Action: wp_dashboard_setup
5906 - */
5907 - public function add_dashboard_widgets() {
5908 - $widget_enabled = $this->get_plugin_option( 'advanced_widget_enabled', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) === '1';
5909 -
5910 - // Load authorizer dashboard widget if it's enabled and user has permission.
5911 - if ( current_user_can( 'create_users' ) && $widget_enabled ) {
5912 - // Add dashboard widget for adding/editing users with access.
4514 + function add_dashboard_widgets() {
4515 + // Only users who can edit can see the authorizer dashboard widget
4516 + if ( current_user_can( 'create_users' ) ) {
4517 + // Add dashboard widget for adding/editing users with access
5913 4518 wp_add_dashboard_widget( 'auth_dashboard_widget', __( 'Authorizer Settings', 'authorizer' ), array( $this, 'add_auth_dashboard_widget' ) );
5914 4519 }
5915 4520 }
5916 4521
5917 4522
5918 - /**
5919 - * Render Authorizer dashboard widget (callback).
5920 - */
5921 - public function add_auth_dashboard_widget() {
5922 - ?>
5923 - <form method="post" id="auth_settings_access_form" action="">
4523 + function add_auth_dashboard_widget() {
4524 + ?><form method="post" id="auth_settings_access_form" action="">
5924 4525 <?php $this->print_section_info_access_login(); ?>
5925 4526 <div>
5926 - <h2><?php esc_html_e( 'Pending Users', 'authorizer' ); ?></h2>
4527 + <h2><?php _e( 'Pending Users', 'authorizer' ); ?></h2>
5927 4528 <?php $this->print_combo_auth_access_users_pending(); ?>
5928 4529 </div>
5929 4530 <div>
5930 - <h2><?php esc_html_e( 'Approved Users', 'authorizer' ); ?></h2>
4531 + <h2><?php _e( 'Approved Users', 'authorizer' ); ?></h2>
5931 4532 <?php $this->print_combo_auth_access_users_approved(); ?>
5932 4533 </div>
5933 4534 <div>
5934 - <h2><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?></h2>
4535 + <h2><?php _e( 'Blocked Users', 'authorizer' ); ?></h2>
5935 4536 <?php $this->print_combo_auth_access_users_blocked(); ?>
5936 4537 </div>
5937 4538 <br class="clear" />
5938 - </form>
5939 - <?php
4539 + </form><?php
5940 4540 }
5941 4541
5942 4542
5943 -
5944 - /**
5945 - * ***************************
5946 - * AJAX Actions
5947 - * ***************************
5948 - */
5949 -
5950 -
5951 -
5952 - /**
5953 - * Re-render the Approved User list (usually triggered if pager params have
5954 - * changed, e.g., current page, search term, sort order).
5955 - *
5956 - * Action: wp_ajax_refresh_approved_user_list
5957 - *
5958 - * @return void
5959 - */
5960 - public function ajax_refresh_approved_user_list() {
4543 + // Fired on a change event from the optional usermeta field in the
4544 + // approved user list. Updates the selected usermeta value, or saves it
4545 + // in the user's approved list entry if the user hasn't logged in yet
4546 + // and created a WordPress account.
4547 + function ajax_update_auth_usermeta() {
5961 4548 // Fail silently if current user doesn't have permissions.
5962 4549 if ( ! current_user_can( 'create_users' ) ) {
5963 4550 die( '' );
5964 4551 }
@@ -5963,175 +4550,35 @@
5963 4550 die( '' );
5964 4551 }
5965 4552
5966 4553 // Nonce check.
5967 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4554 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
5968 4555 die( '' );
5969 4556 }
5970 4557
5971 4558 // Fail if required post data doesn't exist.
5972 - if ( ! array_key_exists( 'paged', $_REQUEST ) ) {
4559 + if ( ! array_key_exists( 'email', $_REQUEST ) || ! array_key_exists( 'usermeta', $_REQUEST ) ) {
5973 4560 die( '' );
5974 4561 }
5975 4562
5976 - // Get defaults.
5977 - $success = true;
5978 - $message = '';
5979 - $is_network_admin = isset( $_REQUEST['is_network_admin'] ) && '1' === $_REQUEST['is_network_admin'];
5980 -
5981 - // Get user list.
5982 - $option = 'access_users_approved';
5983 - $admin_mode = is_multisite() && $is_network_admin ? WP_Plugin_Authorizer::NETWORK_CONTEXT : WP_Plugin_Authorizer::SINGLE_CONTEXT;
5984 - $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' );
5985 - $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array();
5986 -
5987 - // Get multisite approved users (will be added to top of list, greyed out).
5988 - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' );
5989 - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT );
5990 - $auth_settings_option_multisite = array();
5991 - if (
5992 - is_multisite() &&
5993 - ! $is_network_admin &&
5994 - 1 !== intval( $auth_override_multisite ) &&
5995 - array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
5996 - '1' === $auth_multisite_settings['multisite_override']
5997 - ) {
5998 - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' );
5999 - $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array();
6000 - // Add multisite users to the beginning of the main user array.
6001 - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) {
6002 - $approved_user['multisite_user'] = true;
6003 - array_unshift( $auth_settings_option, $approved_user );
6004 - }
6005 - }
6006 -
6007 - // Get custom usermeta field to show.
6008 - $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' );
6009 -
6010 - // Filter user list to search terms.
6011 - if ( ! empty( $_REQUEST['search'] ) ) {
6012 - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) );
6013 - $auth_settings_option = array_filter(
6014 - $auth_settings_option, function ( $user ) use ( $search_term ) {
6015 - return stripos( $user['email'], $search_term ) !== false ||
6016 - stripos( $user['role'], $search_term ) !== false ||
6017 - stripos( $user['date_added'], $search_term ) !== false;
6018 - }
6019 - );
6020 - }
6021 -
6022 - // Sort user list.
6023 - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved).
6024 - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc.
6025 - $sort_dimension = array();
6026 - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) {
6027 - foreach ( $auth_settings_option as $key => $user ) {
6028 - if ( 'date_added' === $sort_by ) {
6029 - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) );
6030 - } else {
6031 - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] );
6032 - }
6033 - }
6034 - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC;
6035 - array_multisort( $sort_dimension, $sort_order, $auth_settings_option );
6036 - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) {
6037 - // If default sort method and reverse order, just reverse the array.
6038 - $auth_settings_option = array_reverse( $auth_settings_option );
6039 - }
6040 -
6041 - // Ensure array keys run from 0..max (keys in database will be the original,
6042 - // index, and removing users will not reorder the array keys of other users).
6043 - $auth_settings_option = array_values( $auth_settings_option );
6044 -
6045 - // Get pager params.
6046 - $total_users = count( $auth_settings_option );
6047 - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) );
6048 - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1;
6049 - $total_pages = ceil( $total_users / $users_per_page );
6050 - if ( $total_pages < 1 ) {
6051 - $total_pages = 1;
6052 - }
6053 -
6054 - // Make sure current_page is between 1 and max pages.
6055 - if ( $current_page < 1 ) {
6056 - $current_page = 1;
6057 - } elseif ( $current_page > $total_pages ) {
6058 - $current_page = $total_pages;
6059 - }
6060 -
6061 - // Render user list.
6062 - ob_start();
6063 - $offset = ( $current_page - 1 ) * $users_per_page;
6064 - $max = min( $offset + $users_per_page, count( $auth_settings_option ) );
6065 - for ( $key = $offset; $key < $max; $key++ ) :
6066 - $approved_user = $auth_settings_option[ $key ];
6067 - if ( empty( $approved_user ) || count( $approved_user ) < 1 ) :
6068 - continue;
6069 - endif;
6070 - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta );
6071 - endfor;
6072 -
6073 - // Send response to client.
6074 - $response = array(
6075 - 'success' => $success,
6076 - 'message' => $message,
6077 - 'html' => ob_get_clean(),
6078 - /* TRANSLATORS: %s: number of users */
6079 - 'total_users_html' => sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ),
6080 - 'total_pages_html' => number_format_i18n( $total_pages ),
6081 - 'total_pages' => $total_pages,
6082 - );
6083 - header( 'content-type: application/json' );
6084 - echo wp_json_encode( $response );
6085 - exit;
6086 - }
6087 -
6088 -
6089 - /**
6090 - * Fired on a change event from the optional usermeta field in the approved
6091 - * user list. Updates the selected usermeta value, or saves it in the user's
6092 - * approved list entry if the user hasn't logged in yet and created a
6093 - * WordPress account.
6094 - *
6095 - * Action: wp_ajax_update_auth_usermeta
6096 - *
6097 - * @return void
6098 - */
6099 - public function ajax_update_auth_usermeta() {
6100 - // Fail silently if current user doesn't have permissions.
6101 - if ( ! current_user_can( 'create_users' ) ) {
6102 - die( '' );
6103 - }
6104 -
6105 - // Nonce check.
6106 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
6107 - die( '' );
6108 - }
6109 -
6110 - // Fail if required post data doesn't exist.
6111 - if ( ! isset( $_REQUEST['email'], $_REQUEST['usermeta'] ) ) {
6112 - die( '' );
6113 - }
6114 -
6115 4563 // Get values to update from post data.
6116 - $email = sanitize_email( wp_unslash( $_REQUEST['email'] ) );
6117 - $meta_value = sanitize_meta( 'authorizer-usermeta', wp_unslash( $_REQUEST['usermeta'] ), 'user' );
6118 - $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
4564 + $email = $_REQUEST['email'];
4565 + $meta_value = $_REQUEST['usermeta'];
4566 + $meta_key = $this->get_plugin_option( 'advanced_usermeta' );
6119 4567
6120 4568 // If user doesn't exist, save usermeta selection to authorizer
6121 4569 // list. This value will get saved to usermeta when the user first
6122 4570 // logs in (i.e., when their WordPress account is created).
6123 - $wp_user = get_user_by( 'email', $email );
6124 - if ( ! $wp_user ) {
4571 + if ( ! ( $wp_user = get_user_by( 'email', $email ) ) ) {
6125 4572 // Look through multisite approved users and add a usermeta
6126 4573 // reference for the current blog if the user is found.
6127 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
4574 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
6128 4575 $should_update_auth_multisite_settings_access_users_approved = false;
6129 4576 foreach ( $auth_multisite_settings_access_users_approved as $index => $approved_user ) {
6130 - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6131 - if ( ! is_array( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] ) ) {
4577 + if ( $email === $approved_user['email'] ) {
4578 + if ( ! is_array( $auth_multisite_settings_access_users_approved[$index]['usermeta'] ) ) {
6132 4579 // Initialize the array of usermeta for each blog this user belongs to.
6133 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] = array();
4580 + $auth_multisite_settings_access_users_approved[$index]['usermeta'] = array();
6134 4581 } else {
6135 4582 // There is already usermeta associated with this
6136 4583 // preapproved user; iterate through it and make
6137 4584 // sure it's not for old meta_keys (delete it if
@@ -6137,53 +4584,55 @@
6137 4584 // sure it's not for old meta_keys (delete it if
6138 4585 // so). This can happen if someone changes the
6139 4586 // usermeta key in authorizer options, and we don't
6140 4587 // want to hang on to old data.
6141 - foreach ( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] as $blog_id => $usermeta ) {
4588 + foreach ( $auth_multisite_settings_access_users_approved[$index]['usermeta'] as $blog_id => $usermeta ) {
6142 4589 if ( array_key_exists( 'meta_key', $usermeta ) && $usermeta['meta_key'] === $meta_key ) {
6143 4590 continue;
6144 4591 } else {
6145 - unset( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ $blog_id ] );
4592 + unset( $auth_multisite_settings_access_users_approved[$index]['usermeta'][$blog_id] );
6146 4593 }
6147 4594 }
6148 4595 }
6149 - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ get_current_blog_id() ] = array(
6150 - 'meta_key' => $meta_key,
4596 + $auth_multisite_settings_access_users_approved[$index]['usermeta'][get_current_blog_id()] = array(
4597 + 'meta_key' => $meta_key,
6151 4598 'meta_value' => $meta_value,
6152 4599 );
6153 - $should_update_auth_multisite_settings_access_users_approved = true;
4600 + $should_update_auth_multisite_settings_access_users_approved = true;
6154 4601 }
6155 4602 }
6156 4603 if ( $should_update_auth_multisite_settings_access_users_approved ) {
6157 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4604 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6158 4605 }
6159 4606
6160 4607 // Look through the approved users (of the current blog in a
6161 4608 // multisite install, or just of the single site) and add a
6162 4609 // usermeta reference if the user is found.
6163 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
4610 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
6164 4611 $should_update_auth_settings_access_users_approved = false;
6165 4612 foreach ( $auth_settings_access_users_approved as $index => $approved_user ) {
6166 - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) {
6167 - $auth_settings_access_users_approved[ $index ]['usermeta'] = array(
6168 - 'meta_key' => $meta_key,
4613 + if ( $email === $approved_user['email'] ) {
4614 + $auth_settings_access_users_approved[$index]['usermeta'] = array(
4615 + 'meta_key' => $meta_key,
6169 4616 'meta_value' => $meta_value,
6170 4617 );
6171 - $should_update_auth_settings_access_users_approved = true;
4618 + $should_update_auth_settings_access_users_approved = true;
6172 4619 }
6173 4620 }
6174 4621 if ( $should_update_auth_settings_access_users_approved ) {
6175 4622 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6176 4623 }
4624 +
6177 4625 } else {
6178 4626 // Update user's usermeta value for usermeta key stored in authorizer options.
6179 4627 if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) {
6180 4628 // We have an ACF field value, so use the ACF function to update it.
6181 - update_field( str_replace( 'acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
4629 + update_field( str_replace('acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID );
6182 4630 } else {
6183 4631 // We have a normal usermeta value, so just update it via the WordPress function.
6184 4632 update_user_meta( $wp_user->ID, $meta_key, $meta_value );
6185 4633 }
4634 +
6186 4635 }
6187 4636
6188 4637 // Return 'success' value to AJAX call.
6189 4638 die( 'success' );
@@ -6189,17 +4638,9 @@
6189 4638 die( 'success' );
6190 4639 }
6191 4640
6192 4641
6193 - /**
6194 - * Fired on a change event from the user fields in the user lists. Updates
6195 - * the selected user value.
6196 - *
6197 - * Action: wp_ajax_update_auth_user
6198 - *
6199 - * @return void
6200 - */
6201 - public function ajax_update_auth_user() {
4642 + function ajax_update_auth_user() {
6202 4643 // Fail silently if current user doesn't have permissions.
6203 4644 if ( ! current_user_can( 'create_users' ) ) {
6204 4645 die( '' );
6205 4646 }
@@ -6204,83 +4645,76 @@
6204 4645 die( '' );
6205 4646 }
6206 4647
6207 4648 // Nonce check.
6208 - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) {
4649 + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) {
6209 4650 die( '' );
6210 4651 }
6211 4652
6212 4653 // Fail if requesting a change to an invalid setting.
6213 - if ( ! isset( $_POST['setting'] ) || ! in_array( wp_unslash( $_POST['setting'] ), array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
4654 + if ( ! in_array( $_POST['setting'], array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
6214 4655 die( '' );
6215 4656 }
6216 4657
6217 - // Track any emails that couldn't be added (used when adding users).
6218 - $invalid_emails = array();
6219 -
6220 4658 // Editing a pending list entry.
6221 - if ( 'access_users_pending' === $_POST['setting'] ) {
6222 - // Sanitize posted data.
6223 - $access_users_pending = array();
6224 - if ( isset( $_POST['access_users_pending'] ) && is_array( $_POST['access_users_pending'] ) ) {
6225 - $access_users_pending = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_pending'] ) );
4659 + if ( $_POST['setting'] === 'access_users_pending' ) {
4660 + // Initialize posted data if empty.
4661 + if ( ! ( array_key_exists( 'access_users_pending', $_POST ) && is_array( $_POST['access_users_pending'] ) ) ) {
4662 + $_POST['access_users_pending'] = array();
6226 4663 }
6227 4664
6228 4665 // Deal with each modified user (add or remove).
6229 - foreach ( $access_users_pending as $pending_user ) {
4666 + foreach ( $_POST['access_users_pending'] as $pending_user ) {
6230 4667
6231 - if ( 'add' === $pending_user['edit_action'] ) {
4668 + if ( $pending_user['edit_action'] === 'add' ) {
6232 4669
6233 4670 // Add new user to pending list and save (skip if it's
6234 4671 // already there--someone else might have just done it).
6235 4672 if ( ! $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
6236 4673 $auth_settings_access_users_pending = $this->sanitize_user_list(
6237 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4674 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
6238 4675 );
6239 4676 array_push( $auth_settings_access_users_pending, $pending_user );
6240 4677 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6241 4678 }
6242 - } elseif ( 'remove' === $pending_user['edit_action'] ) {
6243 4679
6244 - // Remove user from pending list and save.
4680 + } elseif ( $pending_user['edit_action'] === 'remove' ) {
4681 +
4682 + // Remove user from pending list and save
6245 4683 if ( $this->is_email_in_list( $pending_user['email'], 'pending' ) ) {
6246 4684 $auth_settings_access_users_pending = $this->sanitize_user_list(
6247 - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4685 + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN )
6248 4686 );
6249 4687 foreach ( $auth_settings_access_users_pending as $key => $existing_user ) {
6250 - if ( 0 === strcasecmp( $pending_user['email'], $existing_user['email'] ) ) {
6251 - unset( $auth_settings_access_users_pending[ $key ] );
4688 + if ( $pending_user['email'] == $existing_user['email'] ) {
4689 + unset( $auth_settings_access_users_pending[$key] );
6252 4690 break;
6253 4691 }
6254 4692 }
6255 4693 update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending );
6256 4694 }
4695 +
6257 4696 }
6258 4697 }
6259 4698 }
6260 4699
6261 4700 // Editing an approved list entry.
6262 - if ( 'access_users_approved' === $_POST['setting'] ) {
6263 - // Sanitize posted data.
6264 - $access_users_approved = array();
6265 - if ( isset( $_POST['access_users_approved'] ) && is_array( $_POST['access_users_approved'] ) ) {
6266 - $access_users_approved = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_approved'] ) );
4701 + if ( $_POST['setting'] === 'access_users_approved' ) {
4702 + // Initialize posted data if empty.
4703 + if ( ! ( array_key_exists( 'access_users_approved', $_POST ) && is_array( $_POST['access_users_approved'] ) ) ) {
4704 + $_POST['access_users_approved'] = array();
6267 4705 }
6268 4706
6269 4707 // Deal with each modified user (add, remove, or change_role).
6270 - foreach ( $access_users_approved as $approved_user ) {
6271 - // Skip blank entries.
6272 - if ( strlen( $approved_user['email'] ) < 1 ) {
6273 - continue;
6274 - }
4708 + foreach ( $_POST['access_users_approved'] as $approved_user ) {
6275 4709
6276 4710 // New user (create user, or add existing user to current site in multisite).
6277 - if ( 'add' === $approved_user['edit_action'] ) {
4711 + if ( $approved_user['edit_action'] === 'add' ) {
6278 4712 $new_user = get_user_by( 'email', $approved_user['email'] );
6279 - if ( false !== $new_user ) {
4713 + if ( $new_user !== false ) {
6280 4714 // If we're adding an existing multisite user, make sure their
6281 4715 // newly-assigned role is updated on all sites they are already in.
6282 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4716 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6283 4717 foreach ( get_blogs_of_user( $new_user->ID ) as $blog ) {
6284 4718 add_user_to_blog( $blog->userblog_id, $new_user->ID, $approved_user['role'] );
6285 4719 }
6286 4720 }
@@ -6287,9 +4721,9 @@
6287 4721 // If this user already has an account on another site in the network, add them to this site.
6288 4722 if ( is_multisite() ) {
6289 4723 add_user_to_blog( get_current_blog_id(), $new_user->ID, $approved_user['role'] );
6290 4724 }
6291 - } elseif ( $approved_user['local_user'] && 'false' !== $approved_user['local_user'] ) {
4725 + } elseif ( $approved_user['local_user'] === 'true' ) {
6292 4726 // Create a WP account for this new *local* user and email the password.
6293 4727 $plaintext_password = wp_generate_password(); // random password
6294 4728 // If there's already a user with this username (e.g.,
6295 4729 // johndoe/johndoe@gmail.com exists, and we're trying to add
@@ -6297,26 +4731,26 @@
6297 4731 // as the username.
6298 4732 $username = explode( '@', $approved_user['email'] );
6299 4733 $username = $username[0];
6300 4734 if ( get_user_by( 'login', $username ) !== false ) {
6301 - $username = $this->lowercase( $approved_user['email'] );
4735 + $username = $approved_user['email'];
6302 4736 }
6303 - if ( 'false' !== $approved_user['multisite_user'] ) {
4737 + if ( $approved_user['multisite_user'] !== 'false' ) {
6304 4738 $result = wpmu_create_user(
6305 4739 strtolower( $username ),
6306 4740 $plaintext_password,
6307 - $this->lowercase( $approved_user['email'] )
4741 + strtolower( $approved_user['email'] )
6308 4742 );
6309 4743 } else {
6310 4744 $result = wp_insert_user(
6311 4745 array(
6312 - 'user_login' => strtolower( $username ),
6313 - 'user_pass' => $plaintext_password,
6314 - 'first_name' => '',
6315 - 'last_name' => '',
6316 - 'user_email' => $this->lowercase( $approved_user['email'] ),
4746 + 'user_login' => strtolower( $username ),
4747 + 'user_pass' => $plaintext_password,
4748 + 'first_name' => '',
4749 + 'last_name' => '',
4750 + 'user_email' => strtolower( $approved_user['email'] ),
6317 4751 'user_registered' => date( 'Y-m-d H:i:s' ),
6318 - 'role' => $approved_user['role'],
4752 + 'role' => $approved_user['role'],
6319 4753 )
6320 4754 );
6321 4755 }
6322 4756 if ( ! is_wp_error( $result ) ) {
@@ -6322,8 +4756,9 @@
6322 4756 if ( ! is_wp_error( $result ) ) {
6323 4757 // Email login credentials to new user.
6324 4758 wp_new_user_notification( $result, null, 'both' );
6325 4759 }
4760 +
6326 4761 }
6327 4762
6328 4763 // Email new user welcome message if plugin option is set.
6329 4764 $this->maybe_email_welcome_message( $approved_user['email'] );
@@ -6329,46 +4764,41 @@
6329 4764 $this->maybe_email_welcome_message( $approved_user['email'] );
6330 4765
6331 4766 // Add new user to approved list and save (skip if it's
6332 4767 // already there--someone else might have just done it).
6333 - if ( 'false' !== $approved_user['multisite_user'] ) {
4768 + if ( $approved_user['multisite_user'] !== 'false' ) {
6334 4769 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6335 4770 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6336 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4771 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6337 4772 );
6338 - $approved_user['date_added'] = date( 'M Y' );
4773 + $approved_user['date_added'] = date( 'M Y' );
6339 4774 array_push( $auth_multisite_settings_access_users_approved, $approved_user );
6340 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6341 - } else {
6342 - $invalid_emails[] = $approved_user['email'];
4775 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6343 4776 }
6344 4777 } else {
6345 4778 if ( ! $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6346 4779 $auth_settings_access_users_approved = $this->sanitize_user_list(
6347 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4780 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6348 4781 );
6349 - $approved_user['date_added'] = date( 'M Y' );
4782 + $approved_user['date_added'] = date( 'M Y' );
6350 4783 array_push( $auth_settings_access_users_approved, $approved_user );
6351 4784 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6352 - } else {
6353 - $invalid_emails[] = $approved_user['email'];
6354 4785 }
6355 4786 }
6356 4787
6357 4788 // If we've added a new multisite user, go through all pending/approved/blocked lists
6358 4789 // on individual sites and remove this user from them (to prevent duplicate entries).
6359 - if ( 'false' !== $approved_user['multisite_user'] && is_multisite() ) {
4790 + if ( $approved_user['multisite_user'] !== 'false' && is_multisite() ) {
6360 4791 $list_names = array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' );
6361 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6362 4792 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6363 4793 foreach ( $sites as $site ) {
6364 4794 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6365 4795 foreach ( $list_names as $list_name ) {
6366 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
4796 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6367 4797 $list_changed = false;
6368 4798 foreach ( $user_list as $key => $user ) {
6369 - if ( 0 === strcasecmp( $user['email'], $approved_user['email'] ) ) {
6370 - unset( $user_list[ $key ] );
4799 + if ( $user['email'] == $approved_user['email'] ) {
4800 + unset( $user_list[$key] );
6371 4801 $list_changed = true;
6372 4802 }
6373 4803 }
6374 4804 if ( $list_changed ) {
@@ -6376,45 +4806,32 @@
6376 4806 }
6377 4807 }
6378 4808 }
6379 4809 }
6380 - } elseif ( 'remove' === $approved_user['edit_action'] ) { // Remove user from approved list and save (also remove their role if they have a WordPress account).
6381 - if ( 'false' !== $approved_user['multisite_user'] ) {
4810 +
4811 + // Remove user from approved list and save
4812 + } elseif ( $approved_user['edit_action'] === 'remove' ) {
4813 + if ( $approved_user['multisite_user'] !== 'false' ) {
6382 4814 if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6383 4815 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6384 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4816 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6385 4817 );
6386 4818 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6387 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6388 - // Remove role of the associated WordPress user from all blogs (but don't delete the user).
6389 - $user = get_user_by( 'email', $approved_user['email'] );
6390 - if ( false !== $user ) {
6391 - // Loop through all of the blogs this user is a member of and remove their capabilities.
6392 - foreach ( get_blogs_of_user( $user->ID ) as $blog ) {
6393 - remove_user_from_blog( $user->ID, $blog->userblog_id, '' );
6394 - }
6395 - }
6396 - // Remove entry from Approved Users list.
6397 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
4819 + if ( $approved_user['email'] == $existing_user['email'] ) {
4820 + unset( $auth_multisite_settings_access_users_approved[$key] );
6398 4821 break;
6399 4822 }
6400 4823 }
6401 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4824 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6402 4825 }
6403 4826 } else {
6404 4827 if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6405 4828 $auth_settings_access_users_approved = $this->sanitize_user_list(
6406 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4829 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6407 4830 );
6408 4831 foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6409 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6410 - // Remove role of the associated WordPress user (but don't delete the user).
6411 - $user = get_user_by( 'email', $approved_user['email'] );
6412 - if ( false !== $user ) {
6413 - $user->set_role( '' );
6414 - }
6415 - // Remove entry from Approved Users list.
6416 - unset( $auth_settings_access_users_approved[ $key ] );
4832 + if ( $approved_user['email'] == $existing_user['email'] ) {
4833 + unset( $auth_settings_access_users_approved[$key] );
6417 4834 break;
6418 4835 }
6419 4836 }
6420 4837 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
@@ -6419,12 +4836,14 @@
6419 4836 }
6420 4837 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6421 4838 }
6422 4839 }
6423 - } elseif ( 'change_role' === $approved_user['edit_action'] ) { // Update user's role in WordPress.
4840 +
4841 + // Update user's role in WordPress
4842 + } elseif ( $approved_user['edit_action'] === 'change_role' ) {
6424 4843 $changed_user = get_user_by( 'email', $approved_user['email'] );
6425 4844 if ( $changed_user ) {
6426 - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) {
4845 + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) {
6427 4846 foreach ( get_blogs_of_user( $changed_user->ID ) as $blog ) {
6428 4847 add_user_to_blog( $blog->userblog_id, $changed_user->ID, $approved_user['role'] );
6429 4848 }
6430 4849 } else {
@@ -6431,30 +4850,30 @@
6431 4850 $changed_user->set_role( $approved_user['role'] );
6432 4851 }
6433 4852 }
6434 4853
6435 - if ( 'false' !== $approved_user['multisite_user'] ) {
4854 + if ( $approved_user['multisite_user'] !== 'false' ) {
6436 4855 if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) {
6437 4856 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6438 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
4857 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6439 4858 );
6440 4859 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6441 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6442 - $auth_multisite_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
4860 + if ( $approved_user['email'] == $existing_user['email'] ) {
4861 + $auth_multisite_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6443 4862 break;
6444 4863 }
6445 4864 }
6446 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
4865 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6447 4866 }
6448 4867 } else {
6449 4868 // Update user's role in approved list and save.
6450 4869 if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) {
6451 4870 $auth_settings_access_users_approved = $this->sanitize_user_list(
6452 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4871 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN )
6453 4872 );
6454 4873 foreach ( $auth_settings_access_users_approved as $key => $existing_user ) {
6455 - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) {
6456 - $auth_settings_access_users_approved[ $key ]['role'] = $approved_user['role'];
4874 + if ( $approved_user['email'] == $existing_user['email'] ) {
4875 + $auth_settings_access_users_approved[$key]['role'] = $approved_user['role'];
6457 4876 break;
6458 4877 }
6459 4878 }
6460 4879 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
@@ -6459,28 +4878,28 @@
6459 4878 }
6460 4879 update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
6461 4880 }
6462 4881 }
4882 +
6463 4883 }
6464 4884 }
6465 4885 }
6466 4886
6467 4887 // Editing a blocked list entry.
6468 - if ( 'access_users_blocked' === $_POST['setting'] ) {
6469 - // Sanitize post data.
6470 - $access_users_blocked = array();
6471 - if ( isset( $_POST['access_users_blocked'] ) && is_array( $_POST['access_users_blocked'] ) ) {
6472 - $access_users_blocked = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_blocked'] ) );
4888 + if ( $_POST['setting'] === 'access_users_blocked' ) {
4889 + // Initialize posted data if empty.
4890 + if ( ! ( array_key_exists( 'access_users_blocked', $_POST ) && is_array( $_POST['access_users_blocked'] ) ) ) {
4891 + $_POST['access_users_blocked'] = array();
6473 4892 }
6474 4893
6475 4894 // Deal with each modified user (add or remove).
6476 - foreach ( $access_users_blocked as $blocked_user ) {
4895 + foreach ( $_POST['access_users_blocked'] as $blocked_user ) {
6477 4896
6478 - if ( 'add' === $blocked_user['edit_action'] ) {
4897 + if ( $blocked_user['edit_action'] === 'add' ) {
6479 4898
6480 4899 // Add auth_blocked usermeta for the user.
6481 4900 $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] );
6482 - if ( false !== $blocked_wp_user ) {
4901 + if ( $blocked_wp_user !== false ) {
6483 4902 update_user_meta( $blocked_wp_user->ID, 'auth_blocked', 'yes' );
6484 4903 }
6485 4904
6486 4905 // Add new user to blocked list and save (skip if it's
@@ -6486,113 +4905,48 @@
6486 4905 // Add new user to blocked list and save (skip if it's
6487 4906 // already there--someone else might have just done it).
6488 4907 if ( ! $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
6489 4908 $auth_settings_access_users_blocked = $this->sanitize_user_list(
6490 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4909 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
6491 4910 );
6492 - $blocked_user['date_added'] = date( 'M Y' );
4911 + $blocked_user['date_added'] = date( 'M Y' );
6493 4912 array_push( $auth_settings_access_users_blocked, $blocked_user );
6494 4913 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6495 - } else {
6496 - $invalid_emails[] = $blocked_user['email'];
6497 4914 }
6498 - } elseif ( 'remove' === $blocked_user['edit_action'] ) {
6499 4915
4916 + } elseif ( $blocked_user['edit_action'] === 'remove' ) {
4917 +
6500 4918 // Remove auth_blocked usermeta for the user.
6501 4919 $unblocked_user = get_user_by( 'email', $blocked_user['email'] );
6502 - if ( false !== $unblocked_user ) {
4920 + if ( $unblocked_user !== false ) {
6503 4921 delete_user_meta( $unblocked_user->ID, 'auth_blocked', 'yes' );
6504 4922 }
6505 4923
6506 - // Remove user from blocked list and save.
4924 + // Remove user from blocked list and save
6507 4925 if ( $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) {
6508 4926 $auth_settings_access_users_blocked = $this->sanitize_user_list(
6509 - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT )
4927 + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN )
6510 4928 );
6511 4929 foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) {
6512 - if ( 0 === strcasecmp( $blocked_user['email'], $existing_user['email'] ) ) {
6513 - unset( $auth_settings_access_users_blocked[ $key ] );
4930 + if ( $blocked_user['email'] == $existing_user['email'] ) {
4931 + unset( $auth_settings_access_users_blocked[$key] );
6514 4932 break;
6515 4933 }
6516 4934 }
6517 4935 update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked );
6518 4936 }
4937 +
6519 4938 }
6520 4939 }
6521 4940 }
6522 4941
6523 - // Send response to client.
6524 - $response = array(
6525 - 'success' => true,
6526 - 'invalid_emails' => $invalid_emails,
6527 - );
6528 - header( 'content-type: application/json' );
6529 - echo wp_json_encode( $response );
6530 - exit;
4942 + // Return 'success' value to AJAX call.
4943 + die( 'success' );
6531 4944 }
6532 4945
6533 4946
6534 - /**
6535 - * Sanitizes an array of user update commands coming from the AJAX handler in Authorizer Settings.
6536 - *
6537 - * Example $users array:
6538 - * array(
6539 - * array(
6540 - * edit_action: 'add' or 'remove' or 'change_role',
6541 - * email: 'johndoe@example.com',
6542 - * role: 'subscriber',
6543 - * date_added: 'Jun 2014',
6544 - * local_user: 'true' or 'false',
6545 - * multisite_user: 'true' or 'false',
6546 - * ),
6547 - * ...
6548 - * )
6549 - *
6550 - * @param array $users Users to edit.
6551 - * @return array Sanitized users to edit.
6552 - */
6553 - private function sanitize_update_auth_users( $users = array() ) {
6554 - if ( ! is_array( $users ) ) {
6555 - $users = array();
6556 - }
6557 - $users = array_map( array( $this, 'sanitize_update_auth_user' ), $users );
6558 4947
6559 - return $users;
6560 - }
6561 -
6562 -
6563 4948 /**
6564 - * Callback for array_map in sanitize_update_auth_users().
6565 - *
6566 - * @param array $user User data to sanitize.
6567 - * @return array Sanitized user data.
6568 - */
6569 - private function sanitize_update_auth_user( $user ) {
6570 - if ( array_key_exists( 'edit_action', $user ) ) {
6571 - $user['edit_action'] = sanitize_text_field( $user['edit_action'] );
6572 - }
6573 - if ( isset( $user['email'] ) ) {
6574 - $user['email'] = sanitize_email( $user['email'] );
6575 - }
6576 - if ( isset( $user['role'] ) ) {
6577 - $user['role'] = sanitize_text_field( $user['role'] );
6578 - }
6579 - if ( isset( $user['date_added'] ) ) {
6580 - $user['date_added'] = sanitize_text_field( $user['date_added'] );
6581 - }
6582 - if ( isset( $user['local_user'] ) ) {
6583 - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false';
6584 - }
6585 - if ( isset( $user['multisite_user'] ) ) {
6586 - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false';
6587 - }
6588 -
6589 - return $user;
6590 - }
6591 -
6592 -
6593 -
6594 - /**
6595 4949 * ***************************
6596 4950 * Helper functions
6597 4951 * ***************************
6598 4952 */
@@ -6600,20 +4954,20 @@
6600 4954
6601 4955 /**
6602 4956 * Retrieves a specific plugin option from db. Multisite enabled.
6603 4957 *
6604 - * @param string $option Option name.
6605 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6606 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6607 - * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page.
6608 - * @return mixed Option value, or null on failure.
4958 + * @param string $option Option name
4959 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
4960 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
4961 + * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page
4962 + * @return mixed Option value, or null on failure
6609 4963 */
6610 - private function get_plugin_option( $option, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override', $print_mode = 'no overlay' ) {
4964 + private function get_plugin_option( $option, $admin_mode = SINGLE_ADMIN, $override_mode = 'no override', $print_mode = 'no overlay' ) {
6611 4965 // Special case for user lists (they are saved seperately to prevent concurrency issues).
6612 - if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) {
6613 - $list = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings_' . $option );
6614 - if ( is_multisite() && WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
6615 - $list = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_' . $option, array() );
4966 + if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) {
4967 + $list = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings_' . $option );
4968 + if ( is_multisite() && $admin_mode === MULTISITE_ADMIN ) {
4969 + $list = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_' . $option, array() );
6616 4970 }
6617 4971 return $list;
6618 4972 }
6619 4973
@@ -6627,26 +4981,24 @@
6627 4981
6628 4982 // If requested and appropriate, print the overlay hiding the
6629 4983 // single site option that is overridden by a multisite option.
6630 4984 if (
6631 - WP_Plugin_Authorizer::NETWORK_CONTEXT !== $admin_mode &&
6632 - 'allow override' === $override_mode &&
6633 - 'print overlay' === $print_mode &&
4985 + $admin_mode !== MULTISITE_ADMIN &&
4986 + $override_mode === 'allow override' &&
4987 + $print_mode === 'print overlay' &&
6634 4988 array_key_exists( 'multisite_override', $auth_settings ) &&
6635 - '1' === $auth_settings['multisite_override'] &&
6636 - ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) )
4989 + $auth_settings['multisite_override'] === '1' &&
4990 + ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' )
6637 4991 ) {
6638 4992 // Get original plugin options (not overridden value). We'll
6639 4993 // show this old value behind the disabled overlay.
6640 - // $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6641 - // (This feature is disabled).
6642 - //
4994 + $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
4995 +
6643 4996 $name = "auth_settings[$option]";
6644 - $id = "auth_settings_$option";
6645 - ?>
6646 - <div id="overlay-hide-auth_settings_<?php echo esc_attr( $option ); ?>" class="auth_multisite_override_overlay">
4997 + $id = "auth_settings_$option"; ?>
4998 + <div id="overlay-hide-auth_settings_<?php echo $option; ?>" class="auth_multisite_override_overlay">
6647 4999 <span class="overlay-note">
6648 - <?php esc_html_e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo esc_attr( network_admin_url( 'admin.php?page=authorizer' ) ); ?>"><?php esc_html_e( 'multisite option', 'authorizer' ); ?></a>.
5000 + <?php _e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo network_admin_url( 'admin.php?page=authorizer&tab=external' ); ?>"><?php _e( 'multisite option', 'authorizer' ); ?></a>.
6649 5001 </span>
6650 5002 </div>
6651 5003 <?php
6652 5004 }
@@ -6652,9 +5004,9 @@
6652 5004 }
6653 5005
6654 5006 // If we're getting an option in a site that has overridden the multisite override, make
6655 5007 // sure we are returning the option value from that site (not the multisite value).
6656 - if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && 1 === intval( $auth_settings['advanced_override_multisite'] ) ) {
5008 + if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && $auth_settings['advanced_override_multisite'] == '1' ) {
6657 5009 $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' );
6658 5010 }
6659 5011
6660 5012 // Set option to null if it wasn't found.
@@ -6661,115 +5013,98 @@
6661 5013 if ( ! array_key_exists( $option, $auth_settings ) ) {
6662 5014 return null;
6663 5015 }
6664 5016
6665 - return $auth_settings[ $option ];
5017 + return $auth_settings[$option];
6666 5018 }
6667 5019
6668 5020 /**
6669 5021 * Retrieves all plugin options from db. Multisite enabled.
6670 5022 *
6671 - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value.
6672 - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists.
6673 - * @return mixed Option value, or null on failure.
5023 + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value
5024 + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists
5025 + * @return mixed Option value, or null on failure
6674 5026 */
6675 - private function get_plugin_options( $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override' ) {
6676 - // Grab plugin settings (skip if in WP_Plugin_Authorizer::NETWORK_CONTEXT mode).
6677 - $auth_settings = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings' );
5027 + private function get_plugin_options( $admin_mode = SINGLE_ADMIN, $override_mode = 'no override' ) {
5028 + // Grab plugin settings (skip if in MULTISITE_ADMIN mode).
5029 + $auth_settings = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings' );
6678 5030
6679 5031 // Initialize to default values if the plugin option doesn't exist.
6680 - if ( false === $auth_settings ) {
5032 + if ( $auth_settings === FALSE ) {
6681 5033 $auth_settings = $this->set_default_options();
6682 5034 }
6683 5035
6684 5036 // Merge multisite options if we're in a network and the current site hasn't overridden multisite settings.
6685 - if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) ) ) {
5037 + if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' ) ) {
6686 5038 // Get multisite options.
6687 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5039 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
6688 5040
6689 5041 // Return the multisite options if we're viewing the network admin options page.
6690 5042 // Otherwise override options with their multisite equivalents.
6691 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
5043 + if ( $admin_mode === MULTISITE_ADMIN ) {
6692 5044 $auth_settings = $auth_multisite_settings;
6693 5045 } elseif (
6694 - 'allow override' === $override_mode &&
5046 + $override_mode === 'allow override' &&
6695 5047 array_key_exists( 'multisite_override', $auth_multisite_settings ) &&
6696 - '1' === $auth_multisite_settings['multisite_override']
5048 + $auth_multisite_settings['multisite_override'] === '1'
6697 5049 ) {
6698 5050 // Keep track of the multisite override selection.
6699 5051 $auth_settings['multisite_override'] = $auth_multisite_settings['multisite_override'];
6700 5052
6701 - /**
6702 - * Note: the options below should be the complete list of overridden
6703 - * options. It is *not* the complete list of all options (some options
6704 - * don't have a multisite equivalent).
6705 - */
5053 + // Note: the options below should be the complete list of
5054 + // overridden options. It is *not* the complete list of all
5055 + // options (some options don't have a multisite equivalent)
6706 5056
6707 - /**
6708 - * Note: access_users_approved, access_users_pending, and
6709 - * access_users_blocked do not get overridden. However, since
6710 - * access_users_approved has a multisite equivalent, you must retrieve
6711 - * them both seperately. This is done because the two lists should be
6712 - * treated differently.
6713 - *
6714 - * $approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6715 - * $ms_approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
6716 - */
5057 + // Note: access_users_approved, access_users_pending, and
5058 + // access_users_blocked do not get overridden. However,
5059 + // since access_users_approved has a multisite equivalent,
5060 + // you must retrieve them both seperately. This is done
5061 + // because the two lists should be treated differently.
5062 + // $approved_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5063 + // $ms_approved_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
6717 5064
6718 - // Override external services (google, cas, or ldap) and associated options.
6719 - $auth_settings['google'] = $auth_multisite_settings['google'];
6720 - $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
6721 - $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
6722 - $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
6723 - $auth_settings['cas'] = $auth_multisite_settings['cas'];
6724 - $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
6725 - $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
6726 - $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
6727 - $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
6728 - $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
6729 - $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
6730 - $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
6731 - $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
6732 - $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
6733 - $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
6734 - $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
6735 - $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
6736 - $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
6737 - $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
6738 - $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
6739 - $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
6740 - $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
6741 - $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
6742 - $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
6743 - $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
6744 - $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
6745 - $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
5065 + // Override external services (google, cas, or ldap) and associated options
5066 + $auth_settings['google'] = $auth_multisite_settings['google'];
5067 + $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid'];
5068 + $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret'];
5069 + $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain'];
5070 + $auth_settings['cas'] = $auth_multisite_settings['cas'];
5071 + $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label'];
5072 + $auth_settings['cas_host'] = $auth_multisite_settings['cas_host'];
5073 + $auth_settings['cas_port'] = $auth_multisite_settings['cas_port'];
5074 + $auth_settings['cas_path'] = $auth_multisite_settings['cas_path'];
5075 + $auth_settings['cas_version'] = $auth_multisite_settings['cas_version'];
5076 + $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email'];
5077 + $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name'];
5078 + $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name'];
5079 + $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login'];
5080 + $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login'];
5081 + $auth_settings['ldap'] = $auth_multisite_settings['ldap'];
5082 + $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host'];
5083 + $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port'];
5084 + $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls'];
5085 + $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base'];
5086 + $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid'];
5087 + $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email'];
5088 + $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user'];
5089 + $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password'];
5090 + $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url'];
5091 + $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name'];
5092 + $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name'];
6746 5093 $auth_settings['ldap_attr_update_on_login'] = $auth_multisite_settings['ldap_attr_update_on_login'];
6747 5094
6748 - // Override access_who_can_login and access_who_can_view.
5095 + // Override access_who_can_login and access_who_can_view
6749 5096 $auth_settings['access_who_can_login'] = $auth_multisite_settings['access_who_can_login'];
6750 - $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
5097 + $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view'];
6751 5098
6752 - // Override access_default_role.
5099 + // Override access_default_role
6753 5100 $auth_settings['access_default_role'] = $auth_multisite_settings['access_default_role'];
6754 5101
6755 - // Override lockouts.
5102 + // Override lockouts
6756 5103 $auth_settings['advanced_lockouts'] = $auth_multisite_settings['advanced_lockouts'];
6757 5104
6758 - // Override Hide WordPress login.
5105 + // Override Hide WordPress login
6759 5106 $auth_settings['advanced_hide_wp_login'] = $auth_multisite_settings['advanced_hide_wp_login'];
6760 -
6761 - // Override Users per page.
6762 - $auth_settings['advanced_users_per_page'] = $auth_multisite_settings['advanced_users_per_page'];
6763 -
6764 - // Override Sort users by.
6765 - $auth_settings['advanced_users_sort_by'] = $auth_multisite_settings['advanced_users_sort_by'];
6766 -
6767 - // Override Sort users order.
6768 - $auth_settings['advanced_users_sort_order'] = $auth_multisite_settings['advanced_users_sort_order'];
6769 -
6770 - // Override Show Dashboard Widget.
6771 - $auth_settings['advanced_widget_enabled'] = $auth_multisite_settings['advanced_widget_enabled'];
6772 5107 }
6773 5108 }
6774 5109 return $auth_settings;
6775 5110 }
@@ -6776,27 +5111,23 @@
6776 5111
6777 5112
6778 5113 /**
6779 5114 * Remove user from authorizer lists when that user is deleted in WordPress.
6780 - *
6781 - * Action: delete_user
6782 - *
6783 - * @param int $user_id User ID to remove.
6784 - * @return void
5115 + * Run on action hook: delete_user
6785 5116 */
6786 - public function remove_user_from_authorizer_when_deleted( $user_id ) {
6787 - $user = get_user_by( 'id', $user_id );
5117 + function remove_user_from_authorizer_when_deleted( $user_id ) {
5118 + $user = get_user_by( 'id', $user_id );
6788 5119 $deleted_email = $user->user_email;
6789 5120
6790 5121 // Remove user from pending/approved lists and save.
6791 5122 $list_names = array( 'access_users_pending', 'access_users_approved' );
6792 5123 foreach ( $list_names as $list_name ) {
6793 - $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, WP_Plugin_Authorizer::SINGLE_CONTEXT ) );
5124 + $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, SINGLE_ADMIN ) );
6794 5125 $list_changed = false;
6795 5126 foreach ( $user_list as $key => $existing_user ) {
6796 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5127 + if ( $deleted_email === $existing_user['email'] ) {
6797 5128 $list_changed = true;
6798 - unset( $user_list[ $key ] );
5129 + unset( $user_list[$key] );
6799 5130 }
6800 5131 }
6801 5132 if ( $list_changed ) {
6802 5133 update_option( 'auth_settings_' . $list_name, $user_list );
@@ -6806,35 +5137,30 @@
6806 5137
6807 5138
6808 5139 /**
6809 5140 * Remove multisite user from authorizer lists when that user is deleted from Network Users.
6810 - *
6811 - * Action: wpmu_delete_user
6812 - *
6813 - * @param int $user_id User ID to remove.
6814 - * @return void
5141 + * Run on action hook: wpmu_delete_user
6815 5142 */
6816 - public function remove_network_user_from_authorizer_when_deleted( $user_id ) {
6817 - $user = get_user_by( 'id', $user_id );
5143 + function remove_network_user_from_authorizer_when_deleted( $user_id ) {
5144 + $user = get_user_by( 'id', $user_id );
6818 5145 $deleted_email = $user->user_email;
6819 5146
6820 5147 // Go through multisite approved user list and remove this user.
6821 5148 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
6822 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5149 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
6823 5150 );
6824 - $list_changed = false;
5151 + $list_changed = false;
6825 5152 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
6826 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5153 + if ( $deleted_email === $existing_user['email'] ) {
6827 5154 $list_changed = true;
6828 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5155 + unset( $auth_multisite_settings_access_users_approved[$key] );
6829 5156 }
6830 5157 }
6831 5158 if ( $list_changed ) {
6832 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5159 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
6833 5160 }
6834 5161
6835 5162 // Go through all pending/approved lists on individual sites and remove this user from them.
6836 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
6837 5163 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
6838 5164 foreach ( $sites as $site ) {
6839 5165 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
6840 5166 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -6844,27 +5170,22 @@
6844 5170
6845 5171
6846 5172 /**
6847 5173 * Remove multisite user from a specific site's lists when that user is removed from the site.
6848 - *
6849 - * Action: remove_user_from_blog
6850 - *
6851 - * @param int $user_id User ID to remove.
6852 - * @param int $blog_id Blog ID to remove from.
6853 - * @return void
5174 + * Run on action hook: remove_user_from_blog
6854 5175 */
6855 - public function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
6856 - $user = get_user_by( 'id', $user_id );
5176 + function remove_network_user_from_site_when_removed( $user_id, $blog_id ) {
5177 + $user = get_user_by( 'id', $user_id );
6857 5178 $deleted_email = $user->user_email;
6858 5179
6859 5180 $list_names = array( 'access_users_pending', 'access_users_approved' );
6860 5181 foreach ( $list_names as $list_name ) {
6861 - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
5182 + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() );
6862 5183 $list_changed = false;
6863 5184 foreach ( $user_list as $key => $existing_user ) {
6864 - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) {
5185 + if ( $deleted_email === $existing_user['email'] ) {
6865 5186 $list_changed = true;
6866 - unset( $user_list[ $key ] );
5187 + unset( $user_list[$key] );
6867 5188 }
6868 5189 }
6869 5190 if ( $list_changed ) {
6870 5191 update_blog_option( $blog_id, 'auth_settings_' . $list_name, $user_list );
@@ -6874,30 +5195,26 @@
6874 5195
6875 5196
6876 5197 /**
6877 5198 * Helper: Add multisite user to a specific site's approved list.
6878 - *
6879 - * @param int $user_id User ID to add.
6880 - * @param int $blog_id Blog ID to add to.
6881 - * @return void
6882 5199 */
6883 - private function add_network_user_to_site( $user_id, $blog_id ) {
5200 + function add_network_user_to_site( $user_id, $blog_id ) {
6884 5201 // Switch to blog.
6885 5202 switch_to_blog( $blog_id );
6886 5203
6887 5204 // Get user details and role.
6888 - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' );
6889 - $user = get_user_by( 'id', $user_id );
6890 - $user_email = $user->user_email;
6891 - $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
5205 + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' );
5206 + $user = get_user_by( 'id', $user_id );
5207 + $user_email = $user->user_email;
5208 + $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role;
6892 5209
6893 5210 // Add user to approved list if not already there and not in blocked list.
6894 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6895 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5211 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5212 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
6896 5213 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) && ! $this->in_multi_array( $user_email, $auth_settings_access_users_blocked ) ) {
6897 5214 $approved_user = array(
6898 - 'email' => $this->lowercase( $user_email ),
6899 - 'role' => $user_role,
5215 + 'email' => $user_email,
5216 + 'role' => $user_role,
6900 5217 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
6901 5218 'local_user' => true,
6902 5219 );
6903 5220 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -6914,17 +5231,17 @@
6914 5231 * When an existing user is invited to the current site (or a new user is created),
6915 5232 * add them to the authorizer approved list. This action fires when the admin
6916 5233 * doesn't select the "Skip Confirmation Email" option.
6917 5234 *
6918 - * Action: invite_user
5235 + * @action invite_user
6919 5236 *
6920 - * @param int $user_id The invited user's ID.
6921 - * @param array $role The role of the invited user (or none if a new user creation).
5237 + * @param int $user_id The invited user's ID.
5238 + * @param array $role The role of the invited user (or none if a new user creation).
6922 5239 * @param string $newuser_key The key of the invitation.
6923 5240 */
6924 - public function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
5241 + function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) {
6925 5242 $user = get_user_by( 'id', $user_id );
6926 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles, $role );
5243 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles, $role );
6927 5244 }
6928 5245
6929 5246
6930 5247 /**
@@ -6932,16 +5249,16 @@
6932 5249 * When an existing user is invited to the current site (or a new user is created),
6933 5250 * add them to the authorizer approved list. This action fires when the admin
6934 5251 * selects the "Skip Confirmation Email" option.
6935 5252 *
6936 - * Action: added_existing_user
5253 + * @action added_existing_user
6937 5254 *
6938 - * @param int $user_id The invited user's ID.
6939 - * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
5255 + * @param int $user_id The invited user's ID.
5256 + * @param mixed $result True on success or a WP_Error object if the user doesn't exist.
6940 5257 */
6941 - public function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
5258 + function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) {
6942 5259 $user = get_user_by( 'id', $user_id );
6943 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5260 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
6944 5261 }
6945 5262
6946 5263
6947 5264 /**
@@ -6948,18 +5265,17 @@
6948 5265 * Multisite:
6949 5266 * When a new user is invited to the current site (or a new user is created),
6950 5267 * add them to the authorizer approved list.
6951 5268 *
6952 - * Action: after_signup_user
5269 + * @action after_signup_user
6953 5270 *
6954 - * @param string $user User's requested login name.
5271 + * @param string $user User's requested login name.
6955 5272 * @param string $user_email User's email address.
6956 - * @param string $key User's activation key.
6957 - * @param array $meta Additional signup meta, including initially set roles.
5273 + * @param string $key User's activation key.
5274 + * @param array $meta Additional signup meta.
6958 5275 */
6959 - public function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
6960 - $user_roles = isset( $meta['new_role'] ) ? array( $meta['new_role'] ) : array();
6961 - $this->add_user_to_authorizer_when_created( $user_email, time(), $user_roles );
5276 + function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) {
5277 + $this->add_user_to_authorizer_when_created( $user_email, time() );
6962 5278 }
6963 5279
6964 5280
6965 5281 /**
@@ -6966,18 +5282,17 @@
6966 5282 * Single site:
6967 5283 * When a new user is added in single site mode, add them to the authorizer
6968 5284 * approved list.
6969 5285 *
6970 - * Action: edit_user_created_user
5286 + * @action edit_user_created_user
6971 5287 *
6972 - * @param int $user_id ID of the newly created user.
6973 - * @param string $notify Type of notification that should happen. See
6974 - * wp_send_new_user_notifications() for more
6975 - * information on possible values.
5288 + * @param int $user_id ID of the newly created user.
5289 + * @param string $notify Type of notification that should happen. See wp_send_new_user_notifications()
5290 + * for more information on possible values.
6976 5291 */
6977 - public function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
5292 + function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) {
6978 5293 $user = get_user_by( 'id', $user_id );
6979 - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles );
5294 + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles );
6980 5295 }
6981 5296
6982 5297
6983 5298 /**
@@ -6982,19 +5297,14 @@
6982 5297
6983 5298 /**
6984 5299 * Helper: When a new user is added/invited to the current site (or a new
6985 5300 * user is created), add them to the authorizer approved list.
6986 - *
6987 - * @param string $user_email Email address of user to add.
6988 - * @param string $date_registered Date user registered.
6989 - * @param array $user_roles Role to add for user.
6990 - * @param array $default_role Default role, if no role specified.
6991 5301 */
6992 5302 private function add_user_to_authorizer_when_created( $user_email, $date_registered, $user_roles = array(), $default_role = array() ) {
6993 - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array();
6994 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6995 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
6996 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
5303 + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array();
5304 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5305 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5306 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
6997 5307
6998 5308 // Get default role if one isn't specified.
6999 5309 if ( count( $default_role ) < 1 ) {
7000 5310 $default_role = '';
@@ -7009,10 +5319,10 @@
7009 5319 return;
7010 5320 }
7011 5321 // Remove from pending list if there.
7012 5322 foreach ( $auth_settings_access_users_pending as $key => $pending_user ) {
7013 - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) {
7014 - unset( $auth_settings_access_users_pending[ $key ] );
5323 + if ( $pending_user['email'] == $user_email ) {
5324 + unset( $auth_settings_access_users_pending[$key] );
7015 5325 $updated = true;
7016 5326 }
7017 5327 }
7018 5328 // Skip if user is in multisite approved list.
@@ -7021,10 +5331,10 @@
7021 5331 }
7022 5332 // Add to approved list if not there.
7023 5333 if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) ) {
7024 5334 $approved_user = array(
7025 - 'email' => $this->lowercase( $user_email ),
7026 - 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
5335 + 'email' => $user_email,
5336 + 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role,
7027 5337 'date_added' => date( 'M Y', strtotime( $date_registered ) ),
7028 5338 'local_user' => true,
7029 5339 );
7030 5340 array_push( $auth_settings_access_users_approved, $approved_user );
@@ -7043,33 +5353,32 @@
7043 5353 * When a user is granted super admin status (checkbox on network user edit
7044 5354 * screen), add them to the authorizer network approved list. Also remove
7045 5355 * them from pending/approved list on any individual sites.
7046 5356 *
7047 - * Action: grant_super_admin
5357 + * @action grant_super_admin
7048 5358 *
7049 5359 * @param int $user_id The user's ID.
7050 5360 */
7051 - public function grant_super_admin__add_to_network_approved( $user_id ) {
7052 - $user = get_user_by( 'id', $user_id );
5361 + function grant_super_admin__add_to_network_approved( $user_id ) {
5362 + $user = get_user_by( 'id', $user_id );
7053 5363 $user_email = $user->user_email;
7054 5364
7055 5365 // Add user to multisite approved user list (if not already there).
7056 5366 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7057 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5367 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7058 5368 );
7059 5369 if ( ! $this->in_multi_array( $user_email, $auth_multisite_settings_access_users_approved ) ) {
7060 5370 $multisite_approved_user = array(
7061 - 'email' => $this->lowercase( $user_email ),
7062 - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
5371 + 'email' => $user_email,
5372 + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator',
7063 5373 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ),
7064 5374 'local_user' => true,
7065 5375 );
7066 5376 array_push( $auth_multisite_settings_access_users_approved, $multisite_approved_user );
7067 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5377 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7068 5378 }
7069 5379
7070 5380 // Go through all pending/approved lists on individual sites and remove this user from them.
7071 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7072 5381 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7073 5382 foreach ( $sites as $site ) {
7074 5383 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7075 5384 $this->remove_network_user_from_site_when_removed( $user_id, $blog_id );
@@ -7082,29 +5391,29 @@
7082 5391 * When a user's super admin status is revoked (checkbox on network user edit
7083 5392 * screen), remove them from the authorizer network approved list. Also add
7084 5393 * them to approved list on any individual sites they are already a part of.
7085 5394 *
7086 - * Action: revoke_super_admin
5395 + * @action revoke_super_admin
7087 5396 *
7088 5397 * @param int $user_id The user's ID.
7089 5398 */
7090 - public function revoke_super_admin__remove_from_network_approved( $user_id ) {
7091 - $user = get_user_by( 'id', $user_id );
5399 + function revoke_super_admin__remove_from_network_approved( $user_id ) {
5400 + $user = get_user_by( 'id', $user_id );
7092 5401 $revoked_email = $user->user_email;
7093 5402
7094 5403 // Go through multisite approved user list and remove this user.
7095 5404 $auth_multisite_settings_access_users_approved = $this->sanitize_user_list(
7096 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
5405 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
7097 5406 );
7098 - $list_changed = false;
5407 + $list_changed = false;
7099 5408 foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) {
7100 - if ( 0 === strcasecmp( $revoked_email, $existing_user['email'] ) ) {
5409 + if ( $revoked_email === $existing_user['email'] ) {
7101 5410 $list_changed = true;
7102 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
5411 + unset( $auth_multisite_settings_access_users_approved[$key] );
7103 5412 }
7104 5413 }
7105 5414 if ( $list_changed ) {
7106 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
5415 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7107 5416 }
7108 5417
7109 5418 // Go through this user's current sites and add them to the approved list
7110 5419 // (since they are no longer on the network approved list).
@@ -7115,21 +5424,14 @@
7115 5424 }
7116 5425
7117 5426 }
7118 5427
7119 - /**
7120 - * Send a welcome email message to a newly approved user (if the "Should
7121 - * email approved users" setting is enabled).
7122 - *
7123 - * @param string $email Email address to send welcome email to.
7124 - * @return bool Whether the email was sent.
7125 - */
7126 5428 private function maybe_email_welcome_message( $email ) {
7127 5429 // Get option for whether to email welcome messages.
7128 5430 $should_email_new_approved_users = $this->get_plugin_option( 'access_should_email_approved_users' );
7129 5431
7130 5432 // Do not send welcome email if option not enabled.
7131 - if ( '1' !== $should_email_new_approved_users ) {
5433 + if ( $should_email_new_approved_users !== '1' ) {
7132 5434 return false;
7133 5435 }
7134 5436
7135 5437 // Make sure we didn't just email this user (can happen with
@@ -7135,15 +5437,15 @@
7135 5437 // Make sure we didn't just email this user (can happen with
7136 5438 // multiple admins saving at the same time, or by clicking
7137 5439 // Approve button too rapidly).
7138 5440 $recently_sent_emails = get_option( 'auth_settings_recently_sent_emails' );
7139 - if ( false === $recently_sent_emails ) {
5441 + if ( $recently_sent_emails === FALSE ) {
7140 5442 $recently_sent_emails = array();
7141 5443 }
7142 5444 foreach ( $recently_sent_emails as $key => $recently_sent_email ) {
7143 5445 if ( $recently_sent_email['time'] < strtotime( 'now -1 minutes' ) ) {
7144 5446 // Remove emails sent more than 1 minute ago.
7145 - unset( $recently_sent_emails[ $key ] );
5447 + unset( $recently_sent_emails[$key] );
7146 5448 } elseif ( $recently_sent_email['email'] === $email ) {
7147 5449 // Sent an email to this user within the last 1 minute, so
7148 5450 // quit without sending.
7149 5451 return false;
@@ -7151,15 +5453,15 @@
7151 5453 }
7152 5454 // Add the email we're about to send to the list.
7153 5455 $recently_sent_emails[] = array(
7154 5456 'email' => $email,
7155 - 'time' => time(),
5457 + 'time' => time(),
7156 5458 );
7157 5459 update_option( 'auth_settings_recently_sent_emails', $recently_sent_emails );
7158 5460
7159 - // Get welcome email subject and body text.
5461 + // Get welcome email subject and body text
7160 5462 $subject = $this->get_plugin_option( 'access_email_approved_users_subject' );
7161 - $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
5463 + $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) );
7162 5464
7163 5465 // Fail if the subject/body options don't exist or are empty.
7164 5466 if ( is_null( $subject ) || is_null( $body ) || strlen( $subject ) === 0 || strlen( $body ) === 0 ) {
7165 5467 return false;
@@ -7166,14 +5468,14 @@
7166 5468 }
7167 5469
7168 5470 // Replace approved shortcode patterns in subject and body.
7169 5471 $site_name = get_bloginfo( 'name' );
7170 - $site_url = get_site_url();
7171 - $subject = str_replace( '[site_name]', $site_name, $subject );
7172 - $body = str_replace( '[site_name]', $site_name, $body );
7173 - $body = str_replace( '[site_url]', $site_url, $body );
7174 - $body = str_replace( '[user_email]', $email, $body );
7175 - $headers = 'Content-type: text/html' . "\r\n";
5472 + $site_url = get_site_url();
5473 + $subject = str_replace( '[site_name]', $site_name, $subject );
5474 + $body = str_replace( '[site_name]', $site_name, $body );
5475 + $body = str_replace( '[site_url]', $site_url, $body );
5476 + $body = str_replace( '[user_email]', $email, $body );
5477 + $headers = 'Content-type: text/html' . "\r\n";
7176 5478
7177 5479 // Send email.
7178 5480 wp_mail( $email, $subject, $body, $headers );
7179 5481
@@ -7183,22 +5485,14 @@
7183 5485
7184 5486
7185 5487 /**
7186 5488 * Generate a unique cookie to add to nonces to prevent CSRF.
7187 - *
7188 - * @var string
7189 5489 */
7190 - private $cookie_value = null;
7191 -
7192 - /**
7193 - * Retrieve the unique login cookie.
7194 - *
7195 - * @return string Login cookie value.
7196 - */
7197 - private function get_cookie_value() {
5490 + protected $cookie_value = null;
5491 + function get_cookie_value() {
7198 5492 if ( ! $this->cookie_value ) {
7199 5493 if ( isset( $_COOKIE['login_unique'] ) ) {
7200 - $this->cookie_value = sanitize_key( wp_unslash( $_COOKIE['login_unique'] ) );
5494 + $this->cookie_value = $_COOKIE['login_unique'];
7201 5495 } else {
7202 5496 $this->cookie_value = md5( rand() );
7203 5497 }
7204 5498 }
@@ -7206,51 +5500,23 @@
7206 5500 }
7207 5501
7208 5502
7209 5503 /**
7210 - * Encryption key (not secret!).
7211 - *
7212 - * @var string
7213 - */
7214 - private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
7215 -
7216 - /**
7217 - * Encryption salt (not secret!).
7218 - *
7219 - * @var string
7220 - */
7221 - private static $iv = 'R_O2D]jPn]1[fhJl!-P1.oe';
7222 -
7223 - /**
7224 5504 * Basic encryption using a public (not secret!) key. Used for general
7225 5505 * database obfuscation of passwords.
7226 - *
7227 - * @param string $text String to encrypt.
7228 - * @param string $library Encryption library to use (openssl).
7229 - * @return string Encrypted string.
7230 5506 */
7231 - private function encrypt( $text, $library = 'openssl' ) {
5507 + private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0";
5508 + function encrypt( $text ) {
7232 5509 $result = '';
7233 5510
7234 - // Use openssl library (better) if it is enabled.
7235 - if ( function_exists( 'openssl_encrypt' ) && 'openssl' === $library ) {
7236 - $result = base64_encode(
7237 - openssl_encrypt(
7238 - $text,
7239 - 'AES-256-CBC',
7240 - hash( 'sha256', self::$key ),
7241 - 0,
7242 - substr( hash( 'sha256', self::$iv ), 0, 16 )
7243 - )
7244 - );
7245 - } elseif ( function_exists( 'mcrypt_encrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
7246 - $result = base64_encode( mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ) );
7247 - } else { // Fall back to basic obfuscation.
7248 - $length = strlen( $text );
7249 - for ( $i = 0; $i < $length; $i++ ) {
7250 - $char = substr( $text, $i, 1 );
5511 + // Use mcrypt library (better) if php5-mcrypt extension is enabled.
5512 + if ( function_exists( 'mcrypt_encrypt' ) ) {
5513 + $result = mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' );
5514 + } else {
5515 + for ( $i = 0; $i < strlen( $text ); $i++ ) {
5516 + $char = substr( $text, $i, 1 );
7251 5517 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7252 - $char = chr( ord( $char ) + ord( $keychar ) );
5518 + $char = chr( ord( $char ) + ord( $keychar ) );
7253 5519 $result .= $char;
7254 5520 }
7255 5521 $result = base64_encode( $result );
7256 5522 }
@@ -7258,38 +5524,20 @@
7258 5524 return $result;
7259 5525 }
7260 5526
7261 5527
7262 - /**
7263 - * Basic decryption using a public (not secret!) key. Used for general
7264 - * database obfuscation of passwords.
7265 - *
7266 - * @param string $secret String to encrypt.
7267 - * @param string $library Encryption lib to use (openssl).
7268 - * @return string Decrypted string
7269 - */
7270 - private function decrypt( $secret, $library = 'openssl' ) {
5528 + function decrypt( $secret ) {
7271 5529 $result = '';
7272 5530
7273 - // Use openssl library (better) if it is enabled.
7274 - if ( function_exists( 'openssl_decrypt' ) && 'openssl' === $library ) {
7275 - $result = openssl_decrypt(
7276 - base64_decode( $secret ),
7277 - 'AES-256-CBC',
7278 - hash( 'sha256', self::$key ),
7279 - 0,
7280 - substr( hash( 'sha256', self::$iv ), 0, 16 )
7281 - );
7282 - } elseif ( function_exists( 'mcrypt_decrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled.
7283 - $secret = base64_decode( $secret );
5531 + // Use mcrypt library (better) if php5-mcrypt extension is enabled.
5532 + if ( function_exists( 'mcrypt_decrypt' ) ) {
7284 5533 $result = rtrim( mcrypt_decrypt( MCRYPT_RIJNDAEL_256, self::$key, $secret, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ), "\0$result" );
7285 - } else { // Fall back to basic obfuscation.
5534 + } else {
7286 5535 $secret = base64_decode( $secret );
7287 - $length = strlen( $secret );
7288 - for ( $i = 0; $i < $length; $i++ ) {
7289 - $char = substr( $secret, $i, 1 );
5536 + for ( $i = 0; $i < strlen( $secret ); $i++ ) {
5537 + $char = substr( $secret, $i, 1 );
7290 5538 $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 );
7291 - $char = chr( ord( $char ) - ord( $keychar ) );
5539 + $char = chr( ord( $char ) - ord( $keychar ) );
7292 5540 $result .= $char;
7293 5541 }
7294 5542 }
7295 5543
@@ -7300,12 +5548,10 @@
7300 5548 /**
7301 5549 * In a multisite environment, returns true if the current user is logged
7302 5550 * in and a user of the current blog. In single site mode, simply returns
7303 5551 * true if the current user is logged in.
7304 - *
7305 - * @return bool Whether current user is logged in and a user of the current blog.
7306 5552 */
7307 - protected function is_user_logged_in_and_blog_user() {
5553 + function is_user_logged_in_and_blog_user() {
7308 5554 $is_user_logged_in_and_blog_user = false;
7309 5555 if ( is_multisite() ) {
7310 5556 $is_user_logged_in_and_blog_user = is_user_logged_in() && is_user_member_of_blog( get_current_user_id() );
7311 5557 } else {
@@ -7318,42 +5564,39 @@
7318 5564 /**
7319 5565 * Helper function to determine whether a given email is in one of
7320 5566 * the lists (pending, approved, blocked). Defaults to the list of
7321 5567 * approved users.
7322 - *
7323 - * @param string $email Email to check existent of.
7324 - * @param string $list List to look for email in.
7325 - * @param string $multisite_mode Admin context.
7326 - * @return boolean Whether email was found.
7327 5568 */
7328 - protected function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
7329 - if ( empty( $email ) ) {
5569 + function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) {
5570 + if ( empty( $email ) )
7330 5571 return false;
7331 - }
7332 5572
7333 5573 switch ( $list ) {
7334 - case 'pending':
7335 - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7336 - return $this->in_multi_array( $email, $auth_settings_access_users_pending );
7337 - case 'blocked':
7338 - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7339 - return $this->in_multi_array( $email, $auth_settings_access_users_blocked );
7340 - case 'approved':
7341 - default:
7342 - if ( 'single' !== $multisite_mode ) {
7343 - // Get multisite users only.
7344 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7345 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7346 - // This site has overridden any multisite settings, so only get its users.
7347 - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7348 - } else {
7349 - // Get all site users and all multisite users.
7350 - $auth_settings_access_users_approved = array_merge(
7351 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7352 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7353 - );
7354 - }
7355 - return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5574 + case 'pending':
5575 + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5576 + return $this->in_multi_array( $email, $auth_settings_access_users_pending );
5577 + break;
5578 + case 'blocked':
5579 + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5580 + return $this->in_multi_array( $email, $auth_settings_access_users_blocked );
5581 + break;
5582 + case 'approved':
5583 + default:
5584 + if ( $multisite_mode !== 'single' ) {
5585 + // Get multisite users only.
5586 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5587 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5588 + // This site has overridden any multisite settings, so only get its users.
5589 + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5590 + } else {
5591 + // Get all site users and all multisite users.
5592 + $auth_settings_access_users_approved = array_merge(
5593 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5594 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5595 + );
5596 + }
5597 + return $this->in_multi_array( $email, $auth_settings_access_users_approved );
5598 + break;
7356 5599 }
7357 5600 }
7358 5601
7359 5602
@@ -7359,37 +5602,36 @@
7359 5602
7360 5603 /**
7361 5604 * Helper function to get number of users (including multisite users)
7362 5605 * in a given list (pending, approved, or blocked).
7363 - *
7364 - * @param string $list List to get count of.
7365 - * @param string $admin_mode WP_Plugin_Authorizer::SINGLE_CONTEXT or WP_Plugin_Authorizer::NETWORK_CONTEXT determines whether to include multisite users.
7366 - * @return int Number of users in list.
5606 + * @param string $list
5607 + * @param string $admin_mode SINGLE_ADMIN or MULTISITE_ADMIN determines whether to include multisite users
5608 + * @return int number of users in list
7367 5609 */
7368 - protected function get_user_count_from_list( $list, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
5610 + function get_user_count_from_list( $list, $admin_mode = SINGLE_ADMIN ) {
7369 5611 $auth_settings_access_users = array();
7370 5612
7371 5613 switch ( $list ) {
7372 - case 'pending':
7373 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7374 - break;
7375 - case 'blocked':
7376 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7377 - break;
7378 - case 'approved':
7379 - if ( WP_Plugin_Authorizer::SINGLE_CONTEXT !== $admin_mode ) {
7380 - // Get multisite users only.
7381 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT );
7382 - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) {
7383 - // This site has overridden any multisite settings, so only get its users.
7384 - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT );
7385 - } else {
7386 - // Get all site users and all multisite users.
7387 - $auth_settings_access_users = array_merge(
7388 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ),
7389 - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT )
7390 - );
7391 - }
5614 + case 'pending':
5615 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN );
5616 + break;
5617 + case 'blocked':
5618 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN );
5619 + break;
5620 + case 'approved':
5621 + if ( $admin_mode !== SINGLE_ADMIN ) {
5622 + // Get multisite users only.
5623 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN );
5624 + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) {
5625 + // This site has overridden any multisite settings, so only get its users.
5626 + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN );
5627 + } else {
5628 + // Get all site users and all multisite users.
5629 + $auth_settings_access_users = array_merge(
5630 + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ),
5631 + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN )
5632 + );
5633 + }
7392 5634 }
7393 5635
7394 5636 return count( $auth_settings_access_users );
7395 5637 }
@@ -7396,27 +5638,21 @@
7396 5638
7397 5639
7398 5640 /**
7399 5641 * Helper function to search a multidimensional array for a value.
7400 - *
7401 - * @param string $needle Value to search for.
7402 - * @param array $haystack Multidimensional array to search.
7403 - * @param string $strict_mode 'strict' if strict comparisons should be used.
7404 - * @param string $case_sensitivity 'case sensitive' if comparisons should respect case.
7405 - * @return bool Whether needle was found.
7406 5642 */
7407 - protected function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
5643 + function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) {
7408 5644 if ( ! is_array( $haystack ) ) {
7409 5645 return false;
7410 5646 }
7411 - if ( 'case insensitive' === $case_sensitivity ) {
5647 + if ( $case_sensitivity === 'case insensitive' ) {
7412 5648 $needle = strtolower( $needle );
7413 5649 }
7414 5650 foreach ( $haystack as $item ) {
7415 - if ( 'case insensitive' === $case_sensitivity && ! is_array( $item ) ) {
5651 + if ( $case_sensitivity === 'case insensitive' && ! is_array( $item ) ) {
7416 5652 $item = strtolower( $item );
7417 5653 }
7418 - if ( ( 'strict' === $strict_mode ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) { // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison
5654 + if ( ( $strict_mode === 'strict' ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) {
7419 5655 return true;
7420 5656 }
7421 5657 }
7422 5658 return false;
@@ -7423,31 +5659,43 @@
7423 5659 }
7424 5660
7425 5661
7426 5662 /**
5663 + * Helper function to get a WordPress page ID from the pagename.
5664 + *
5665 + * @param string $pagename Page Slug
5666 + * @return int Page/Post ID
5667 + */
5668 + function get_id_from_pagename( $pagename = '' ) {
5669 + global $wpdb;
5670 + $page_id = $wpdb->get_var( "SELECT ID FROM $wpdb->posts WHERE post_name = '" . sanitize_title_for_query( $pagename ) . "'" );
5671 + return $page_id;
5672 + }
5673 +
5674 +
5675 + /**
7427 5676 * Helper function to determine if an URL is accessible.
7428 5677 *
7429 - * @param string $url URL that should be publicly reachable.
7430 - * @return boolean Whether the URL is publicly reachable.
5678 + * @param string $url URL that should be publicly reachable
5679 + * @return boolean Whether the URL is publicly reachable
7431 5680 */
7432 - protected function url_is_accessible( $url ) {
5681 + function url_is_accessible( $url ) {
7433 5682 // Use wp_remote_retrieve_response_code() to retrieve the URL.
7434 - $response = wp_remote_get( $url );
5683 + $response = wp_remote_get( $url );
7435 5684 $response_code = wp_remote_retrieve_response_code( $response );
7436 5685
7437 - // Return true if the document has loaded successfully without any redirection or error.
7438 - return $response_code >= 200 && $response_code < 400;
5686 + // Return true if the document has loaded successfully without any redirection or error
5687 + return $response_code >= 200 && $response_code < 300;
7439 5688 }
7440 5689
7441 5690
7442 5691 /**
7443 5692 * Helper function to reconstruct a URL split using parse_url().
7444 - *
7445 - * @param array $parts Array returned from parse_url().
7446 - * @return string URL.
5693 + * @param array $parts Array returned from parse_url().
5694 + * @return string URL.
7447 5695 */
7448 - protected function build_url( $parts = array() ) {
7449 - return (
5696 + function build_url( $parts = array() ) {
5697 + return
7450 5698 ( isset( $parts['scheme'] ) ? "{$parts['scheme']}:" : '' ) .
7451 5699 ( ( isset( $parts['user'] ) || isset( $parts['host'] ) ) ? '//' : '' ) .
7452 5700 ( isset( $parts['user'] ) ? "{$parts['user']}" : '' ) .
7453 5701 ( isset( $parts['pass'] ) ? ":{$parts['pass']}" : '' ) .
@@ -7455,30 +5703,21 @@
7455 5703 ( isset( $parts['host'] ) ? "{$parts['host']}" : '' ) .
7456 5704 ( isset( $parts['port'] ) ? ":{$parts['port']}" : '' ) .
7457 5705 ( isset( $parts['path'] ) ? "{$parts['path']}" : '' ) .
7458 5706 ( isset( $parts['query'] ) ? "?{$parts['query']}" : '' ) .
7459 - ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' )
7460 - );
5707 + ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' );
7461 5708 }
7462 5709
7463 5710
7464 - /**
7465 - * Helper function that prints option tags for a select element for all
7466 - * roles the current user has permission to assign.
7467 - *
7468 - * @param string $selected_role Which role should be selected in the dropdown.
7469 - * @param string $disable_input 'disabled' if select element should be disabled.
7470 - * @param int $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT if we are in that context.
7471 - * @return void
7472 - */
7473 - protected function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) {
7474 - $roles = get_editable_roles();
5711 + // Helper function that builds option tags for a select element for all
5712 + // roles the current user has permission to assign.
5713 + function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = SINGLE_ADMIN ) {
5714 + $roles = get_editable_roles();
7475 5715 $current_user = wp_get_current_user();
7476 5716
7477 5717 // If we're in network admin, also show any roles that might exist only on
7478 5718 // specific sites in the network (themes can add their own roles).
7479 - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) {
7480 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
5719 + if ( $admin_mode === MULTISITE_ADMIN ) {
7481 5720 $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7482 5721 foreach ( $sites as $site ) {
7483 5722 $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7484 5723 switch_to_blog( $blog_id );
@@ -7487,11 +5726,11 @@
7487 5726 }
7488 5727 $unique_role_names = array();
7489 5728 foreach ( $roles as $role_name => $role_info ) {
7490 5729 if ( array_key_exists( $role_name, $unique_role_names ) ) {
7491 - unset( $roles[ $role_name ] );
5730 + unset( $roles[$role_name] );
7492 5731 } else {
7493 - $unique_role_names[ $role_name ] = true;
5732 + $unique_role_names[$role_name] = true;
7494 5733 }
7495 5734 }
7496 5735 }
7497 5736
@@ -7503,43 +5742,39 @@
7503 5742 }
7504 5743
7505 5744 // Print an option element for each permitted role.
7506 5745 foreach ( $roles as $name => $role ) {
7507 - $is_selected = $selected_role === $name;
5746 + $selected = $selected_role === $name ? ' selected="selected"' : '';
7508 5747
7509 - // Don't let a user change their own role (but network admins always can).
7510 - $is_disabled = $selected_role !== $name && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7511 - ?>
7512 - <option value="<?php echo esc_attr( $name ); ?>"<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php echo esc_html( $role['name'] ); ?></option>
7513 - <?php
5748 + // Don't let a user change their own role
5749 + $disabled = $selected_role !== $name && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5750 +
5751 + // But network admins can always change their role.
5752 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5753 + $disabled = '';
5754 + }
5755 +
5756 + ?><option value="<?php echo $name; ?>"<?php echo $selected . $disabled; ?>><?php echo $role['name']; ?></option><?php
7514 5757 }
7515 5758
7516 5759 // Print default role (no role).
7517 - $is_selected = strlen( $selected_role ) === 0 || ! array_key_exists( $selected_role, $roles );
7518 - $is_disabled = strlen( $selected_role ) > 0 && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) );
7519 - ?>
7520 - <option value=""<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php esc_html_e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option>
7521 - <?php
5760 + $selected = strlen( $selected_role ) == 0 || ! array_key_exists( $selected_role, $roles ) ? ' selected="selected"' : '';
5761 + $disabled = strlen( $selected_role ) > 0 && $disable_input === 'disabled' ? ' disabled="disabled"' : '';
5762 + if ( is_multisite() && current_user_can( 'manage_network' ) ) {
5763 + $disabled = '';
5764 + }
5765 + ?><option value=""<?php echo $selected . $disabled; ?>><?php _e( '&mdash; No role for this site &mdash;', 'authorizer' ); ?></option><?php
7522 5766
7523 5767 }
7524 5768
7525 5769
7526 - /**
7527 - * Helper function to get a single user info array from one of the access
7528 - * control lists (pending, approved, or blocked).
7529 - *
7530 - * @param string $email Email address to retrieve info for.
7531 - * @param string $list List to get info from.
7532 - * @return mixed false if not found, otherwise: array(
7533 - * 'email' => '',
7534 - * 'role' => '',
7535 - * 'date_added' => '',
7536 - * ['usermeta' => [''|array()]]
7537 - * );
7538 - */
7539 - protected function get_user_info_from_list( $email, $list ) {
5770 + // Helper function to get a single user info array from one of the
5771 + // access control lists (pending, approved, or blocked).
5772 + // Returns: false if not found; otherwise
5773 + // array( 'email' => '', 'role' => '', 'date_added' => '', ['usermeta' => [''|array()]] );
5774 + function get_user_info_from_list( $email, $list ) {
7540 5775 foreach ( $list as $user_info ) {
7541 - if ( 0 === strcasecmp( $user_info['email'], $email ) ) {
5776 + if ( $user_info['email'] === $email ) {
7542 5777 return $user_info;
7543 5778 }
7544 5779 }
7545 5780 return false;
@@ -7544,49 +5779,29 @@
7544 5779 }
7545 5780 return false;
7546 5781 }
7547 5782
7548 - /**
7549 - * Helper function to convert a string to lowercase. Prefers to use mb_strtolower,
7550 - * but will fall back to strtolower if the former is not available.
7551 - *
7552 - * @param string $string String to convert to lowercase.
7553 - * @return string Input in lowercase.
7554 - */
7555 - protected function lowercase( $string ) {
7556 - return function_exists( 'mb_strtolower' ) ? mb_strtolower( $string ) : strtolower( $string );
7557 - }
7558 5783
7559 -
7560 - /**
7561 - * Helper function to convert seconds to human readable text.
7562 - *
7563 - * @see: http://csl.name/php-secs-to-human-text/
7564 - *
7565 - * @param int $secs Seconds to display as readable text.
7566 - * @return string Readable version of number of seconds.
7567 - */
7568 - protected function seconds_as_sentence( $secs ) {
5784 + // Helper function to convert seconds to human readable text.
5785 + // Source: http://csl.name/php-secs-to-human-text/
5786 + function seconds_as_sentence( $secs ) {
7569 5787 $units = array(
7570 - 'week' => 3600 * 24 * 7,
7571 - 'day' => 3600 * 24,
7572 - 'hour' => 3600,
7573 - 'minute' => 60,
7574 - 'second' => 1,
5788 + "week" => 7 * 24 * 3600,
5789 + "day" => 24 * 3600,
5790 + "hour" => 3600,
5791 + "minute" => 60,
5792 + "second" => 1,
7575 5793 );
7576 5794
7577 - // Specifically handle zero.
7578 - if ( 0 === intval( $secs ) ) {
7579 - return '0 seconds';
7580 - }
5795 + // specifically handle zero
5796 + if ( $secs == 0 ) return "0 seconds";
7581 5797
7582 - $s = '';
5798 + $s = "";
7583 5799
7584 5800 foreach ( $units as $name => $divisor ) {
7585 - $quot = intval( $secs / $divisor );
7586 - if ( $quot ) {
7587 - $s .= "$quot $name";
7588 - $s .= ( abs( $quot ) > 1 ? 's' : '' ) . ', ';
5801 + if ( $quot = intval( $secs / $divisor ) ) {
5802 + $s .= "$quot $name";
5803 + $s .= ( abs( $quot ) > 1 ? "s" : "" ) . ", ";
7589 5804 $secs -= $quot * $divisor;
7590 5805 }
7591 5806 }
7592 5807
@@ -7592,14 +5807,10 @@
7592 5807
7593 5808 return substr( $s, 0, -2 );
7594 5809 }
7595 5810
7596 - /**
7597 - * Helper function to get all available usermeta keys as an array.
7598 - *
7599 - * @return array All usermeta keys for user.
7600 - */
7601 - protected function get_all_usermeta_keys() {
5811 + // Helper function to get all available usermeta keys as an array.
5812 + function get_all_usermeta_keys() {
7602 5813 global $wpdb;
7603 5814 $usermeta_keys = $wpdb->get_col( "SELECT DISTINCT $wpdb->usermeta.meta_key FROM $wpdb->usermeta" );
7604 5815 return $usermeta_keys;
7605 5816 }
@@ -7606,12 +5817,10 @@
7606 5817
7607 5818
7608 5819 /**
7609 5820 * Load translated strings from *.mo files in /languages.
7610 - *
7611 - * Action: plugins_loaded
7612 5821 */
7613 - public function load_textdomain() {
5822 + function load_textdomain() {
7614 5823 load_plugin_textdomain(
7615 5824 'authorizer',
7616 5825 false,
7617 5826 plugin_basename( dirname( __FILE__ ) ) . '/languages'
@@ -7622,17 +5831,14 @@
7622 5831 /**
7623 5832 * Generate CAS authentication URL (wp-login.php URL with reauth=1 removed
7624 5833 * and external=cas added).
7625 5834 */
7626 - private function modify_current_url_for_cas_login() {
5835 + function modify_current_url_for_cas_login() {
7627 5836 // Construct the URL of the current page (wp-login.php).
7628 - $url = '';
7629 - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) {
7630 - $url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) );
7631 - }
5837 + $url = 'http' . ( isset( $_SERVER['HTTPS'] ) ? 's' : '' ) . '://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
7632 5838
7633 5839 // Parse the URL into its components.
7634 - $parsed_url = wp_parse_url( $url );
5840 + $parsed_url = parse_url( $url );
7635 5841
7636 5842 // Fix up the querystring values (remove reauth, make sure external=cas).
7637 5843 $querystring = array();
7638 5844 if ( array_key_exists( 'query', $parsed_url ) ) {
@@ -7639,9 +5845,9 @@
7639 5845 parse_str( $parsed_url['query'], $querystring );
7640 5846 }
7641 5847 unset( $querystring['reauth'] );
7642 5848 $querystring['external'] = 'cas';
7643 - $parsed_url['query'] = http_build_query( $querystring );
5849 + $parsed_url['query'] = http_build_query( $querystring );
7644 5850
7645 5851 // Return the URL as a string.
7646 5852 return $this->unparse_url( $parsed_url );
7647 5853 }
@@ -7648,21 +5854,20 @@
7648 5854
7649 5855
7650 5856 /**
7651 5857 * Reconstruct a URL after it has been deconstructed with parse_url().
7652 - *
7653 - * @param array $parsed_url Keys from parse_url().
7654 - * @return string URL constructed from the components in $parsed_url.
5858 + * @param $parsed_url array() with keys from parse_url().
5859 + * @return string URL constructed from the components in $parsed_url.
7655 5860 */
7656 - protected function unparse_url( $parsed_url = array() ) {
7657 - $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
7658 - $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
7659 - $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
7660 - $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
7661 - $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
7662 - $pass = $user || $pass ? "$pass@" : '';
7663 - $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
7664 - $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
5861 + function unparse_url( $parsed_url = array() ) {
5862 + $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : '';
5863 + $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : '';
5864 + $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : '';
5865 + $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : '';
5866 + $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : '';
5867 + $pass = $user || $pass ? "$pass@" : '';
5868 + $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : '';
5869 + $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : '';
7665 5870 $fragment = isset( $parsed_url['fragment'] ) ? '#' . $parsed_url['fragment'] : '';
7666 5871 return "$scheme$user$pass$host$port$path$query$fragment";
7667 5872 }
7668 5873
@@ -7667,32 +5872,35 @@
7667 5872 }
7668 5873
7669 5874
7670 5875 /**
7671 - * Helper function to generate an HTML class name for an option (used in
7672 - * Authorizer Settings in the Approved User list).
7673 - *
7674 - * @param string $suffix Unique part of class name.
7675 - * @param boolean $is_multisite_user Whether the class name should indicate it's a multisite user.
7676 - * @return string Class name, e.g., "auth-email auth-multisite-email".
7677 - */
7678 - private function create_class_name( $suffix = '', $is_multisite_user = false ) {
7679 - return $is_multisite_user ? "auth-$suffix auth-multisite-$suffix" : "auth-$suffix";
7680 - }
7681 -
7682 -
7683 - /**
7684 5876 * Plugin Update Routines.
7685 - *
7686 - * Action: plugins_loaded
7687 5877 */
7688 - public function auth_update_check() {
7689 - // Get current version.
7690 - $needs_updating = false;
7691 - if ( is_multisite() ) {
7692 - $auth_version = get_blog_option( $this->current_site_blog_id, 'auth_version' );
7693 - } else {
7694 - $auth_version = get_option( 'auth_version' );
5878 + function auth_update_check() {
5879 + // Update: Set default values for newly added options (forgot to do
5880 + // this, so some users are getting debug log notices about undefined
5881 + // indexes in $auth_settings).
5882 + $update_if_older_than = 20160831;
5883 + $auth_version = get_option( 'auth_version' );
5884 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
5885 + // Provide default values for any $auth_settings options that don't exist.
5886 + if ( is_multisite() ) {
5887 + // Get all blog ids
5888 + $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
5889 + foreach ( $sites as $site ) {
5890 + $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
5891 + switch_to_blog( $blog_id );
5892 + // Set meaningful defaults for other sites in the network.
5893 + $this->set_default_options();
5894 + // Switch back to original blog. See: https://codex.wordpress.org/Function_Reference/restore_current_blog
5895 + restore_current_blog();
5896 + }
5897 + } else {
5898 + // Set meaningful defaults for this site.
5899 + $this->set_default_options();
5900 + }
5901 + // Update version to reflect this change has been made.
5902 + update_option( 'auth_version', $update_if_older_than );
7695 5903 }
7696 5904
7697 5905 // Update: migrate user lists to own options (addresses concurrency
7698 5906 // when saving plugin options, since user lists are changed often
@@ -7702,9 +5910,10 @@
7702 5910 // log in; approved and blocked lists are changed whenever an admin
7703 5911 // changes them from the multisite panel, the dashboard widget, or
7704 5912 // the plugin options page.
7705 5913 $update_if_older_than = 20140709;
7706 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
5914 + $auth_version = get_option( 'auth_version' );
5915 + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7707 5916 // Copy single site user lists to new options (if they exist).
7708 5917 $auth_settings = get_option( 'auth_settings' );
7709 5918 if ( is_array( $auth_settings ) && array_key_exists( 'access_users_pending', $auth_settings ) ) {
7710 5919 update_option( 'auth_settings_access_users_pending', $auth_settings['access_users_pending'] );
@@ -7722,264 +5931,36 @@
7722 5931 update_option( 'auth_settings', $auth_settings );
7723 5932 }
7724 5933 // Copy multisite user lists to new options (if they exist).
7725 5934 if ( is_multisite() ) {
7726 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
5935 + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() );
7727 5936 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_pending', $auth_multisite_settings ) ) {
7728 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
5937 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] );
7729 5938 unset( $auth_multisite_settings['access_users_pending'] );
7730 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
5939 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7731 5940 }
7732 5941 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_approved', $auth_multisite_settings ) ) {
7733 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
5942 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] );
7734 5943 unset( $auth_multisite_settings['access_users_approved'] );
7735 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
5944 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7736 5945 }
7737 5946 if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_blocked', $auth_multisite_settings ) ) {
7738 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
5947 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] );
7739 5948 unset( $auth_multisite_settings['access_users_blocked'] );
7740 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
5949 + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings );
7741 5950 }
7742 5951 }
7743 5952 // Update version to reflect this change has been made.
7744 - $auth_version = $update_if_older_than;
7745 - $needs_updating = true;
5953 + update_option( 'auth_version', $update_if_older_than );
7746 5954 }
7747 5955
7748 - // Update: Set default values for newly added options (forgot to do
7749 - // this, so some users are getting debug log notices about undefined
7750 - // indexes in $auth_settings).
7751 - $update_if_older_than = 20160831;
7752 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7753 - // Provide default values for any $auth_settings options that don't exist.
7754 - if ( is_multisite() ) {
7755 - // Get all blog ids.
7756 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7757 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7758 - foreach ( $sites as $site ) {
7759 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7760 - switch_to_blog( $blog_id );
7761 - // Set meaningful defaults for other sites in the network.
7762 - $this->set_default_options();
7763 - // Switch back to original blog.
7764 - restore_current_blog();
7765 - }
7766 - } else {
7767 - // Set meaningful defaults for this site.
7768 - $this->set_default_options();
7769 - }
7770 - // Update version to reflect this change has been made.
7771 - $auth_version = $update_if_older_than;
7772 - $needs_updating = true;
7773 - }
7774 -
7775 - // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7776 - // deprecated as of PHP 7.1. Use openssl library instead.
7777 - $update_if_older_than = 20170510;
7778 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7779 - if ( is_multisite() ) {
7780 - // Reencrypt LDAP passwords in each site in the network.
7781 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7782 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7783 - foreach ( $sites as $site ) {
7784 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7785 - $auth_settings = get_blog_option( $blog_id, 'auth_settings', array() );
7786 - if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7787 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7788 - $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7789 - update_blog_option( $blog_id, 'auth_settings', $auth_settings );
7790 - }
7791 - }
7792 - } else {
7793 - // Reencrypt LDAP password on this single-site install.
7794 - $auth_settings = get_option( 'auth_settings', array() );
7795 - if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) {
7796 - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' );
7797 - $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7798 - update_option( 'auth_settings', $auth_settings );
7799 - }
7800 - }
7801 - // Update version to reflect this change has been made.
7802 - $auth_version = $update_if_older_than;
7803 - $needs_updating = true;
7804 - }
7805 -
7806 - // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is
7807 - // deprecated as of PHP 7.1. Use openssl library instead.
7808 - // Note: Forgot to update the auth_multisite_settings ldap password! Do it here.
7809 - $update_if_older_than = 20170511;
7810 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7811 - if ( is_multisite() ) {
7812 - // Reencrypt LDAP password in network (multisite) options.
7813 - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() );
7814 - if ( array_key_exists( 'ldap_password', $auth_multisite_settings ) && strlen( $auth_multisite_settings['ldap_password'] ) > 0 ) {
7815 - $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' );
7816 - $auth_multisite_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password );
7817 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings );
7818 - }
7819 - }
7820 - // Update version to reflect this change has been made.
7821 - $auth_version = $update_if_older_than;
7822 - $needs_updating = true;
7823 - }
7824 -
7825 - // Update: Remove duplicates from approved list caused by authorizer_automatically_approve_login
7826 - // filter not respecting users who are already in the approved list
7827 - // (causing them to get re-added each time they logged in).
7828 - $update_if_older_than = 20170711;
7829 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7830 - // Remove duplicates from approved user lists.
7831 - if ( is_multisite() ) {
7832 - // Remove duplicates from each site in the multisite.
7833 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7834 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7835 - foreach ( $sites as $site ) {
7836 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7837 - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() );
7838 - if ( is_array( $auth_settings_access_users_approved ) ) {
7839 - $should_update = false;
7840 - $distinct_emails = array();
7841 - foreach ( $auth_settings_access_users_approved as $key => $user ) {
7842 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7843 - $should_update = true;
7844 - unset( $auth_settings_access_users_approved[ $key ] );
7845 - } else {
7846 - $distinct_emails[] = $user['email'];
7847 - }
7848 - }
7849 - if ( $should_update ) {
7850 - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
7851 - }
7852 - }
7853 - }
7854 - // Remove duplicates from multisite approved user list.
7855 - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() );
7856 - if ( is_array( $auth_multisite_settings_access_users_approved ) ) {
7857 - $should_update = false;
7858 - $distinct_emails = array();
7859 - foreach ( $auth_multisite_settings_access_users_approved as $key => $user ) {
7860 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7861 - $should_update = true;
7862 - unset( $auth_multisite_settings_access_users_approved[ $key ] );
7863 - } else {
7864 - $distinct_emails[] = $user['email'];
7865 - }
7866 - }
7867 - if ( $should_update ) {
7868 - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved );
7869 - }
7870 - }
7871 - } else {
7872 - // Remove duplicates from single site approved user list.
7873 - $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' );
7874 - if ( is_array( $auth_settings_access_users_approved ) ) {
7875 - $should_update = false;
7876 - $distinct_emails = array();
7877 - foreach ( $auth_settings_access_users_approved as $key => $user ) {
7878 - if ( in_array( $user['email'], $distinct_emails, true ) ) {
7879 - $should_update = true;
7880 - unset( $auth_settings_access_users_approved[ $key ] );
7881 - } else {
7882 - $distinct_emails[] = $user['email'];
7883 - }
7884 - }
7885 - if ( $should_update ) {
7886 - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved );
7887 - }
7888 - }
7889 - }
7890 - // Update version to reflect this change has been made.
7891 - $auth_version = $update_if_older_than;
7892 - $needs_updating = true;
7893 - }
7894 -
7895 - // Update: Set default value for newly added option advanced_widget_enabled.
7896 - $update_if_older_than = 20171023;
7897 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7898 - // Provide default values for any $auth_settings options that don't exist.
7899 - if ( is_multisite() ) {
7900 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7901 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7902 - foreach ( $sites as $site ) {
7903 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7904 - switch_to_blog( $blog_id );
7905 - $this->set_default_options();
7906 - restore_current_blog();
7907 - }
7908 - } else {
7909 - $this->set_default_options();
7910 - }
7911 - // Update version to reflect this change has been made.
7912 - $auth_version = $update_if_older_than;
7913 - $needs_updating = true;
7914 - }
7915 -
7916 - // Update: Set default value for newly added option advanced_users_per_page.
7917 - $update_if_older_than = 20171215;
7918 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7919 - // Provide default values for any $auth_settings options that don't exist.
7920 - if ( is_multisite() ) {
7921 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7922 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7923 - foreach ( $sites as $site ) {
7924 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7925 - switch_to_blog( $blog_id );
7926 - $this->set_default_options();
7927 - restore_current_blog();
7928 - }
7929 - } else {
7930 - $this->set_default_options();
7931 - }
7932 - // Update version to reflect this change has been made.
7933 - $auth_version = $update_if_older_than;
7934 - $needs_updating = true;
7935 - }
7936 -
7937 - // Update: Set default value for newly added options advanced_users_sort_by and advanced_users_sort_order.
7938 - $update_if_older_than = 20171219;
7939 - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) {
7940 - // Provide default values for any $auth_settings options that don't exist.
7941 - if ( is_multisite() ) {
7942 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7943 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7944 - foreach ( $sites as $site ) {
7945 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7946 - switch_to_blog( $blog_id );
7947 - $this->set_default_options();
7948 - restore_current_blog();
7949 - }
7950 - } else {
7951 - $this->set_default_options();
7952 - }
7953 - // Update version to reflect this change has been made.
7954 - $auth_version = $update_if_older_than;
7955 - $needs_updating = true;
7956 - }
7957 -
7958 - /*
7959 - // Update: TEMPLATE
7960 - $update_if_older_than = YYYYMMDD;
7961 - if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
7962 - UPDATE CODE HERE
7963 - // Update version to reflect this change has been made.
7964 - $auth_version = $update_if_older_than;
7965 - $needs_updating = true;
7966 - }
7967 - */
7968 -
7969 - // Save new version number if we performed any updates.
7970 - if ( $needs_updating ) {
7971 - if ( is_multisite() ) {
7972 - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound
7973 - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) );
7974 - foreach ( $sites as $site ) {
7975 - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id'];
7976 - update_blog_option( $blog_id, 'auth_version', $auth_version );
7977 - }
7978 - } else {
7979 - update_option( 'auth_version', $auth_version );
7980 - }
7981 - }
5956 + // // Update: TEMPLATE
5957 + // $update_if_older_than = YYYYMMDD;
5958 + // $auth_version = get_option( 'auth_version' );
5959 + // if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) {
5960 + // UPDATE CODE HERE
5961 + // update_option( 'auth_version', $update_if_older_than );
5962 + // }
7982 5963 }
7983 5964
7984 5965 }
7985 5966 }