| @@ -1,31 +1,51 @@ | ||
| 1 | 1 | <?php |
| 2 | -/** | |
| 3 | - * Plugin Name: Authorizer | |
| 4 | - * Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS). | |
| 5 | - * Author: Paul Ryan <prar@hawaii.edu> | |
| 6 | - * Plugin URI: https://github.com/uhm-coe/authorizer | |
| 7 | - * Text Domain: authorizer | |
| 8 | - * Domain Path: /languages | |
| 9 | - * License: GPL2 | |
| 10 | - * Version: 2.8.3 | |
| 11 | - * | |
| 12 | - * @package authorizer | |
| 13 | - */ | |
| 2 | +/* | |
| 3 | +Plugin Name: Authorizer | |
| 4 | +Plugin URI: https://github.com/uhm-coe/authorizer | |
| 5 | +Description: Authorizer limits login attempts, restricts access to specified users, and authenticates against external sources (e.g., Google, LDAP, or CAS). | |
| 6 | +Version: 2.6.7 | |
| 7 | +Author: Paul Ryan | |
| 8 | +Author URI: http://www.linkedin.com/in/paulrryan/ | |
| 9 | +Text Domain: authorizer | |
| 10 | +Domain Path: /languages | |
| 11 | +License: GPL2 | |
| 12 | +*/ | |
| 14 | 13 | |
| 15 | -/** | |
| 16 | - * Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/ | |
| 17 | - * Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/ | |
| 18 | - * Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/ | |
| 19 | - */ | |
| 20 | 14 | |
| 21 | -/** | |
| 22 | - * Add phpCAS library if it's not included. | |
| 23 | - * | |
| 24 | - * @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide | |
| 25 | - */ | |
| 15 | +/* | |
| 16 | +Copyright 2014 Paul Ryan (email: prar@hawaii.edu) | |
| 17 | + | |
| 18 | +This program is free software; you can redistribute it and/or modify | |
| 19 | +it under the terms of the GNU General Public License, version 2, as | |
| 20 | +published by the Free Software Foundation. | |
| 21 | + | |
| 22 | +This program is distributed in the hope that it will be useful, | |
| 23 | +but WITHOUT ANY WARRANTY; without even the implied warranty of | |
| 24 | +MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
| 25 | +GNU General Public License for more details. | |
| 26 | + | |
| 27 | +You should have received a copy of the GNU General Public License | |
| 28 | +along with this program; if not, write to the Free Software | |
| 29 | +Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA | |
| 30 | +*/ | |
| 31 | + | |
| 32 | + | |
| 33 | +/* | |
| 34 | +Portions forked from Restricted Site Access plugin: http://wordpress.org/plugins/restricted-site-access/ | |
| 35 | +Portions forked from wpCAS plugin: http://wordpress.org/extend/plugins/cas-authentication/ | |
| 36 | +Portions forked from Limit Login Attempts: http://wordpress.org/plugins/limit-login-attempts/ | |
| 37 | +*/ | |
| 38 | + | |
| 39 | + | |
| 40 | +define( 'MULTISITE_ADMIN', 'multisite_admin' ); | |
| 41 | +define( 'SINGLE_ADMIN', 'single_admin' ); | |
| 42 | + | |
| 43 | + | |
| 44 | +// Add phpCAS library if it's not included. | |
| 45 | +// @see https://wiki.jasig.org/display/CASC/phpCAS+installation+guide | |
| 26 | 46 | if ( ! defined( 'PHPCAS_VERSION' ) ) { |
| 27 | - require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.5/CAS.php'; | |
| 47 | + require_once dirname( __FILE__ ) . '/vendor/CAS-1.3.4/CAS.php'; | |
| 28 | 48 | } |
| 29 | 49 | |
| 30 | 50 | |
| 31 | 51 | if ( ! class_exists( 'WP_Plugin_Authorizer' ) ) { |
| @@ -39,87 +59,18 @@ | ||
| 39 | 59 | * @link http://hawaii.edu/coe/dcdc/wordpress/authorizer/doc/ |
| 40 | 60 | */ |
| 41 | 61 | class WP_Plugin_Authorizer { |
| 42 | 62 | |
| 43 | - /** | |
| 44 | - * Constants for determining our admin context (network or individual site). | |
| 45 | - */ | |
| 46 | - const NETWORK_CONTEXT = 'multisite_admin'; | |
| 47 | - const SINGLE_CONTEXT = 'single_admin'; | |
| 48 | 63 | |
| 49 | 64 | /** |
| 50 | - * Current site ID (Multisite). | |
| 51 | - * | |
| 52 | - * @var string | |
| 53 | - */ | |
| 54 | - public $current_site_blog_id = 1; | |
| 55 | - | |
| 56 | - /** | |
| 57 | - * HTML allowed when rendering translatable strings in the Authorizer UI. | |
| 58 | - * This is passed to wp_kses() when sanitizing HMTL strings. | |
| 59 | - * | |
| 60 | - * @var array | |
| 61 | - */ | |
| 62 | - private $allowed_html = array( | |
| 63 | - 'a' => array( | |
| 64 | - 'class' => array(), | |
| 65 | - 'href' => array(), | |
| 66 | - 'style' => array(), | |
| 67 | - 'target' => array(), | |
| 68 | - 'title' => array(), | |
| 69 | - ), | |
| 70 | - 'b' => array(), | |
| 71 | - 'br' => array(), | |
| 72 | - 'div' => array( | |
| 73 | - 'class' => array(), | |
| 74 | - ), | |
| 75 | - 'em' => array(), | |
| 76 | - 'hr' => array(), | |
| 77 | - 'i' => array(), | |
| 78 | - 'input' => array( | |
| 79 | - 'aria-describedby' => array(), | |
| 80 | - 'class' => array(), | |
| 81 | - 'id' => array(), | |
| 82 | - 'name' => array(), | |
| 83 | - 'size' => array(), | |
| 84 | - 'type' => array(), | |
| 85 | - 'value' => array(), | |
| 86 | - ), | |
| 87 | - 'label' => array( | |
| 88 | - 'class' => array(), | |
| 89 | - 'for' => array(), | |
| 90 | - ), | |
| 91 | - 'p' => array( | |
| 92 | - 'style' => array(), | |
| 93 | - ), | |
| 94 | - 'span' => array( | |
| 95 | - 'aria-hidden' => array(), | |
| 96 | - 'class' => array(), | |
| 97 | - 'id' => array(), | |
| 98 | - 'style' => array(), | |
| 99 | - ), | |
| 100 | - 'strong' => array(), | |
| 101 | - ); | |
| 102 | - | |
| 103 | - /** | |
| 104 | 65 | * Constructor. |
| 105 | 66 | */ |
| 106 | 67 | public function __construct() { |
| 107 | - // Save reference to current blog id in the network (support deprecated | |
| 108 | - // constant BLOGID_CURRENT_SITE). | |
| 109 | - if ( defined( 'BLOG_ID_CURRENT_SITE' ) ) { | |
| 110 | - $this->current_site_blog_id = BLOG_ID_CURRENT_SITE; | |
| 111 | - } elseif ( defined( 'BLOGID_CURRENT_SITE' ) ) { // deprecated. | |
| 112 | - $this->current_site_blog_id = BLOGID_CURRENT_SITE; | |
| 113 | - } | |
| 114 | - | |
| 115 | 68 | // Installation and uninstallation hooks. |
| 116 | 69 | register_activation_hook( __FILE__, array( $this, 'activate' ) ); |
| 117 | 70 | register_deactivation_hook( __FILE__, array( $this, 'deactivate' ) ); |
| 118 | 71 | |
| 119 | - /** | |
| 120 | - * Register filters. | |
| 121 | - */ | |
| 72 | + // Register filters. | |
| 122 | 73 | |
| 123 | 74 | // Custom wp authentication routine using external service. |
| 124 | 75 | add_filter( 'authenticate', array( $this, 'custom_authenticate' ), 1, 3 ); |
| 125 | 76 | |
| @@ -125,9 +76,13 @@ | ||
| 125 | 76 | |
| 126 | 77 | // Custom logout action using external service. |
| 127 | 78 | add_action( 'wp_logout', array( $this, 'custom_logout' ) ); |
| 128 | 79 | |
| 129 | - // Create settings link on Plugins page. | |
| 80 | + // Removing this bypasses Wordpress authentication (so if external auth fails, | |
| 81 | + // no one can log in); with it enabled, it will run if external auth fails. | |
| 82 | + //remove_filter('authenticate', 'wp_authenticate_username_password', 20, 3); | |
| 83 | + | |
| 84 | + // Create settings link on Plugins page | |
| 130 | 85 | add_filter( 'plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'plugin_settings_link' ) ); |
| 131 | 86 | add_filter( 'network_admin_plugin_action_links_' . plugin_basename( __FILE__ ), array( $this, 'network_admin_plugin_settings_link' ) ); |
| 132 | 87 | |
| 133 | 88 | // Modify login page with a custom password url (if option is set). |
| @@ -138,11 +93,9 @@ | ||
| 138 | 93 | if ( $error && strlen( $error ) > 0 ) { |
| 139 | 94 | add_filter( 'login_errors', array( $this, 'show_advanced_login_error' ) ); |
| 140 | 95 | } |
| 141 | 96 | |
| 142 | - /** | |
| 143 | - * Register actions. | |
| 144 | - */ | |
| 97 | + // Register actions. | |
| 145 | 98 | |
| 146 | 99 | // Enable localization. Translation files stored in /languages. |
| 147 | 100 | add_action( 'plugins_loaded', array( $this, 'load_textdomain' ) ); |
| 148 | 101 | |
| @@ -154,20 +107,18 @@ | ||
| 154 | 107 | |
| 155 | 108 | // Add users who successfully login to the approved list. |
| 156 | 109 | add_action( 'wp_login', array( $this, 'ensure_wordpress_user_in_approved_list_on_login' ), 10, 2 ); |
| 157 | 110 | |
| 158 | - // Create menu item in Settings. | |
| 111 | + // Create menu item in Settings | |
| 159 | 112 | add_action( 'admin_menu', array( $this, 'add_plugin_page' ) ); |
| 160 | 113 | |
| 161 | - // Create options page. | |
| 114 | + // Create options page | |
| 162 | 115 | add_action( 'admin_init', array( $this, 'page_init' ) ); |
| 163 | 116 | |
| 164 | 117 | // Update user role in approved list if it's changed in the WordPress edit user page. |
| 165 | - add_action( 'user_profile_update_errors', array( $this, 'edit_user_profile_update_role' ), 10, 3 ); | |
| 118 | + add_action( 'edit_user_profile_update', array( $this, 'edit_user_profile_update_role' ) ); | |
| 119 | + add_action( 'personal_options_update', array( $this, 'edit_user_profile_update_role' ) ); | |
| 166 | 120 | |
| 167 | - // Update user email in approved list if it's changed in the WordPress edit user page. | |
| 168 | - add_filter( 'send_email_change_email', array( $this, 'edit_user_profile_update_email' ), 10, 3 ); | |
| 169 | - | |
| 170 | 121 | // Enqueue javascript and css on the plugin's options page, the |
| 171 | 122 | // dashboard (for the widget), and the network admin. |
| 172 | 123 | add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) ); |
| 173 | 124 | add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) ); |
| @@ -172,46 +123,35 @@ | ||
| 172 | 123 | add_action( 'load-settings_page_authorizer', array( $this, 'load_options_page' ) ); |
| 173 | 124 | add_action( 'admin_head-index.php', array( $this, 'load_options_page' ) ); |
| 174 | 125 | add_action( 'load-toplevel_page_authorizer', array( $this, 'load_options_page' ) ); |
| 175 | 126 | |
| 176 | - // Add custom css and js to wp-login.php. | |
| 127 | + // Add custom css and js to wp-login.php | |
| 177 | 128 | add_action( 'login_enqueue_scripts', array( $this, 'login_enqueue_scripts_and_styles' ) ); |
| 178 | 129 | add_action( 'login_footer', array( $this, 'load_login_footer_js' ) ); |
| 179 | 130 | |
| 180 | - // Create google nonce cookie when loading wp-login.php if Google is enabled. | |
| 181 | - add_action( 'login_init', array( $this, 'login_init__maybe_set_google_nonce_cookie' ) ); | |
| 182 | - | |
| 183 | - // Modify login page with external auth links (if enabled; e.g., google or cas). | |
| 131 | + // Modify login page with external auth links (if enabled; e.g., google or cas) | |
| 184 | 132 | add_action( 'login_form', array( $this, 'login_form_add_external_service_links' ) ); |
| 185 | 133 | |
| 186 | 134 | // Redirect to CAS login when visiting login page (only if option is |
| 187 | 135 | // enabled, CAS is the only service, and WordPress logins are hidden). |
| 188 | - // Note: hook into wp_login_errors filter so this fires after the | |
| 189 | - // authenticate hook (where the redirect to CAS happens), but before html | |
| 190 | - // output is started (so the redirect header doesn't complain about data | |
| 191 | - // already being sent). | |
| 192 | - add_filter( 'wp_login_errors', array( $this, 'wp_login_errors__maybe_redirect_to_cas' ), 10, 2 ); | |
| 136 | + add_action( 'login_head', array( $this, 'login_head_maybe_redirect_to_cas' ) ); | |
| 193 | 137 | |
| 194 | - // Verify current user has access to page they are visiting. | |
| 138 | + // Verify current user has access to page they are visiting | |
| 195 | 139 | add_action( 'parse_request', array( $this, 'restrict_access' ), 9 ); |
| 196 | - add_action( 'init', array( $this, 'init__maybe_add_network_approved_user' ) ); | |
| 197 | 140 | |
| 198 | - // AJAX: Save options from dashboard widget. | |
| 141 | + // ajax save options from dashboard widget | |
| 199 | 142 | add_action( 'wp_ajax_update_auth_user', array( $this, 'ajax_update_auth_user' ) ); |
| 200 | 143 | |
| 201 | - // AJAX: Save options from multisite options page. | |
| 144 | + // ajax save options from multisite options page | |
| 202 | 145 | add_action( 'wp_ajax_save_auth_multisite_settings', array( $this, 'ajax_save_auth_multisite_settings' ) ); |
| 203 | 146 | |
| 204 | - // AJAX: Save usermeta from options page. | |
| 147 | + // ajax save usermeta from options page | |
| 205 | 148 | add_action( 'wp_ajax_update_auth_usermeta', array( $this, 'ajax_update_auth_usermeta' ) ); |
| 206 | 149 | |
| 207 | - // AJAX: Verify google login. | |
| 150 | + // ajax verify google login | |
| 208 | 151 | add_action( 'wp_ajax_process_google_login', array( $this, 'ajax_process_google_login' ) ); |
| 209 | 152 | add_action( 'wp_ajax_nopriv_process_google_login', array( $this, 'ajax_process_google_login' ) ); |
| 210 | 153 | |
| 211 | - // AJAX: Refresh approved user list. | |
| 212 | - add_action( 'wp_ajax_refresh_approved_user_list', array( $this, 'ajax_refresh_approved_user_list' ) ); | |
| 213 | - | |
| 214 | 154 | // Add dashboard widget so instructors can add/edit users with access. |
| 215 | 155 | // Hint: For Multisite Network Admin Dashboard use wp_network_dashboard_setup instead of wp_dashboard_setup. |
| 216 | 156 | add_action( 'wp_dashboard_setup', array( $this, 'add_dashboard_widgets' ) ); |
| 217 | 157 | |
| @@ -226,12 +166,17 @@ | ||
| 226 | 166 | add_action( 'wp_enqueue_scripts', array( $this, 'auth_public_scripts' ), 20 ); |
| 227 | 167 | |
| 228 | 168 | // Multisite-specific actions. |
| 229 | 169 | if ( is_multisite() ) { |
| 230 | - // Add network admin options page (global settings for all sites). | |
| 170 | + // Add network admin options page (global settings for all sites) | |
| 231 | 171 | add_action( 'network_admin_menu', array( $this, 'network_admin_menu' ) ); |
| 232 | 172 | } |
| 233 | 173 | |
| 174 | + // Create login cookie (used by google login) | |
| 175 | + if ( ! isset( $_COOKIE['login_unique'] ) ) { | |
| 176 | + setcookie( 'login_unique', $this->get_cookie_value(), time()+1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' ); | |
| 177 | + } | |
| 178 | + | |
| 234 | 179 | // Remove user from authorizer lists when that user is deleted in WordPress. |
| 235 | 180 | add_action( 'delete_user', array( $this, 'remove_user_from_authorizer_when_deleted' ) ); |
| 236 | 181 | if ( is_multisite() ) { |
| 237 | 182 | // Remove multisite user from authorizer lists when that user is deleted from Network Users. |
| @@ -264,20 +209,16 @@ | ||
| 264 | 209 | * Will also activate the plugin for all sites/blogs if this is a "Network enable." |
| 265 | 210 | * |
| 266 | 211 | * @return void |
| 267 | 212 | */ |
| 268 | - public function activate( $network_wide ) { | |
| 213 | + public function activate() { | |
| 269 | 214 | global $wpdb; |
| 270 | 215 | |
| 271 | - // If we're in a multisite environment, run the plugin activation for each | |
| 272 | - // site when network enabling. | |
| 273 | - // Note: wp-cli does not use nonces, so we skip the nonce check here to | |
| 274 | - // allow the "wp plugin activate authorizer" command. | |
| 275 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 276 | - if ( is_multisite() && $network_wide ) { | |
| 216 | + // If we're in a multisite environment, run the plugin activation for each site when network enabling | |
| 217 | + if ( is_multisite() && isset( $_GET['networkwide'] ) && $_GET['networkwide'] == 1 ) { | |
| 277 | 218 | |
| 278 | 219 | // Add super admins to the multisite approved list. |
| 279 | - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ); | |
| 220 | + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ); | |
| 280 | 221 | $should_update_auth_multisite_settings_access_users_approved = false; |
| 281 | 222 | foreach ( get_super_admins() as $super_admin ) { |
| 282 | 223 | $user = get_user_by( 'login', $super_admin ); |
| 283 | 224 | // Add to approved list if not there. |
| @@ -282,10 +223,10 @@ | ||
| 282 | 223 | $user = get_user_by( 'login', $super_admin ); |
| 283 | 224 | // Add to approved list if not there. |
| 284 | 225 | if ( ! $this->in_multi_array( $user->user_email, $auth_multisite_settings_access_users_approved ) ) { |
| 285 | 226 | $approved_user = array( |
| 286 | - 'email' => $this->lowercase( $user->user_email ), | |
| 287 | - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator', | |
| 227 | + 'email' => $user->user_email, | |
| 228 | + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator', | |
| 288 | 229 | 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ), |
| 289 | 230 | 'local_user' => true, |
| 290 | 231 | ); |
| 291 | 232 | array_push( $auth_multisite_settings_access_users_approved, $approved_user ); |
| @@ -292,14 +233,13 @@ | ||
| 292 | 233 | $should_update_auth_multisite_settings_access_users_approved = true; |
| 293 | 234 | } |
| 294 | 235 | } |
| 295 | 236 | if ( $should_update_auth_multisite_settings_access_users_approved ) { |
| 296 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 237 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 297 | 238 | } |
| 298 | 239 | |
| 299 | 240 | // Run plugin activation on each site in the network. |
| 300 | 241 | $current_blog_id = $wpdb->blogid; |
| 301 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 302 | 242 | $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); |
| 303 | 243 | foreach ( $sites as $site ) { |
| 304 | 244 | $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; |
| 305 | 245 | switch_to_blog( $blog_id ); |
| @@ -328,13 +268,13 @@ | ||
| 328 | 268 | * @return void |
| 329 | 269 | */ |
| 330 | 270 | private function add_wp_users_to_approved_list() { |
| 331 | 271 | // Add current WordPress users to the approved list. |
| 332 | - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array(); | |
| 333 | - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 334 | - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 335 | - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 336 | - $updated = false; | |
| 272 | + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array(); | |
| 273 | + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ); | |
| 274 | + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 275 | + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ); | |
| 276 | + $updated = false; | |
| 337 | 277 | foreach ( get_users() as $user ) { |
| 338 | 278 | // Skip if user is in blocked list. |
| 339 | 279 | if ( $this->in_multi_array( $user->user_email, $auth_settings_access_users_blocked ) ) { |
| 340 | 280 | continue; |
| @@ -340,10 +280,10 @@ | ||
| 340 | 280 | continue; |
| 341 | 281 | } |
| 342 | 282 | // Remove from pending list if there. |
| 343 | 283 | foreach ( $auth_settings_access_users_pending as $key => $pending_user ) { |
| 344 | - if ( 0 === strcasecmp( $pending_user['email'], $user->user_email ) ) { | |
| 345 | - unset( $auth_settings_access_users_pending[ $key ] ); | |
| 284 | + if ( $pending_user['email'] == $user->user_email ) { | |
| 285 | + unset( $auth_settings_access_users_pending[$key] ); | |
| 346 | 286 | $updated = true; |
| 347 | 287 | } |
| 348 | 288 | } |
| 349 | 289 | // Skip if user is in multisite approved list. |
| @@ -352,10 +292,10 @@ | ||
| 352 | 292 | } |
| 353 | 293 | // Add to approved list if not there. |
| 354 | 294 | if ( ! $this->in_multi_array( $user->user_email, $auth_settings_access_users_approved ) ) { |
| 355 | 295 | $approved_user = array( |
| 356 | - 'email' => $this->lowercase( $user->user_email ), | |
| 357 | - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '', | |
| 296 | + 'email' => $user->user_email, | |
| 297 | + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : '', | |
| 358 | 298 | 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ), |
| 359 | 299 | 'local_user' => true, |
| 360 | 300 | ); |
| 361 | 301 | array_push( $auth_settings_access_users_approved, $approved_user ); |
| @@ -390,14 +330,13 @@ | ||
| 390 | 330 | |
| 391 | 331 | /** |
| 392 | 332 | * Authenticate against an external service. |
| 393 | 333 | * |
| 394 | - * Filter: authenticate | |
| 395 | - * | |
| 396 | - * @param WP_User $user user to authenticate. | |
| 334 | + * @param WP_User $user user to authenticate | |
| 397 | 335 | * @param string $username optional username to authenticate. |
| 398 | 336 | * @param string $password optional password to authenticate. |
| 399 | - * @return WP_User|WP_Error WP_User on success, WP_Error on failure. | |
| 337 | + * | |
| 338 | + * @return WP_User or WP_Error | |
| 400 | 339 | */ |
| 401 | 340 | public function custom_authenticate( $user, $username, $password ) { |
| 402 | 341 | // Pass through if already authenticated. |
| 403 | 342 | if ( is_a( $user, 'WP_User' ) ) { |
| @@ -405,20 +344,20 @@ | ||
| 405 | 344 | } else { |
| 406 | 345 | $user = null; |
| 407 | 346 | } |
| 408 | 347 | |
| 409 | - // If username and password are blank, this isn't a log in attempt. | |
| 348 | + // If username and password are blank, this isn't a log in attempt | |
| 410 | 349 | $is_login_attempt = strlen( $username ) > 0 && strlen( $password ) > 0; |
| 411 | 350 | |
| 412 | 351 | // Check to make sure that $username is not locked out due to too |
| 413 | 352 | // many invalid login attempts. If it is, tell the user how much |
| 414 | 353 | // time remains until they can try again. |
| 415 | - $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false; | |
| 354 | + $unauthenticated_user = $is_login_attempt ? get_user_by( 'login', $username ) : false; | |
| 416 | 355 | $unauthenticated_user_is_blocked = false; |
| 417 | - if ( $is_login_attempt && false !== $unauthenticated_user ) { | |
| 356 | + if ( $is_login_attempt && $unauthenticated_user !== false ) { | |
| 418 | 357 | $last_attempt = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true ); |
| 419 | 358 | $num_attempts = get_user_meta( $unauthenticated_user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true ); |
| 420 | - // Also check the auth_blocked user_meta flag (users in blocked list will get this flag). | |
| 359 | + // Also check the auth_blocked user_meta flag (users in blocked list will get this flag) | |
| 421 | 360 | $unauthenticated_user_is_blocked = get_user_meta( $unauthenticated_user->ID, 'auth_blocked', true ) === 'yes'; |
| 422 | 361 | } else { |
| 423 | 362 | $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' ); |
| 424 | 363 | $num_attempts = get_option( 'auth_settings_advanced_lockouts_failed_attempts' ); |
| @@ -432,9 +371,9 @@ | ||
| 432 | 371 | return new WP_Error( 'empty_password', __( '<strong>ERROR</strong>: Incorrect username or password.', 'authorizer' ) ); |
| 433 | 372 | } |
| 434 | 373 | |
| 435 | 374 | // Grab plugin settings. |
| 436 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 375 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 437 | 376 | |
| 438 | 377 | // Make sure $last_attempt (time) and $num_attempts are positive integers. |
| 439 | 378 | // Note: this addresses resetting them if either is unset from above. |
| 440 | 379 | $last_attempt = abs( intval( $last_attempt ) ); |
| @@ -440,17 +379,17 @@ | ||
| 440 | 379 | $last_attempt = abs( intval( $last_attempt ) ); |
| 441 | 380 | $num_attempts = abs( intval( $num_attempts ) ); |
| 442 | 381 | |
| 443 | 382 | // Create semantic lockout variables. |
| 444 | - $lockouts = $auth_settings['advanced_lockouts']; | |
| 445 | - $time_since_last_fail = time() - $last_attempt; | |
| 446 | - $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds. | |
| 447 | - $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2']; | |
| 448 | - $num_attempts_short_lockout = $lockouts['attempts_1']; | |
| 449 | - $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail; | |
| 383 | + $lockouts = $auth_settings['advanced_lockouts']; | |
| 384 | + $time_since_last_fail = time() - $last_attempt; | |
| 385 | + $reset_duration = $lockouts['reset_duration'] * 60; // minutes to seconds | |
| 386 | + $num_attempts_long_lockout = $lockouts['attempts_1'] + $lockouts['attempts_2']; | |
| 387 | + $num_attempts_short_lockout = $lockouts['attempts_1']; | |
| 388 | + $seconds_remaining_long_lockout = $lockouts['duration_2'] * 60 - $time_since_last_fail; | |
| 450 | 389 | $seconds_remaining_short_lockout = $lockouts['duration_1'] * 60 - $time_since_last_fail; |
| 451 | 390 | |
| 452 | - // Check if we need to institute a lockout delay. | |
| 391 | + // Check if we need to institute a lockout delay | |
| 453 | 392 | if ( $is_login_attempt && $time_since_last_fail > $reset_duration ) { |
| 454 | 393 | // Enough time has passed since the last invalid attempt and |
| 455 | 394 | // now that we can reset the failed attempt count, and let this |
| 456 | 395 | // login attempt go through. |
| @@ -463,9 +402,8 @@ | ||
| 463 | 402 | remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 ); |
| 464 | 403 | return new WP_Error( |
| 465 | 404 | 'empty_password', |
| 466 | 405 | sprintf( |
| 467 | - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */ | |
| 468 | 406 | __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ), |
| 469 | 407 | $username, |
| 470 | 408 | $seconds_remaining_long_lockout, |
| 471 | 409 | $this->seconds_as_sentence( $seconds_remaining_long_lockout ), |
| @@ -480,9 +418,8 @@ | ||
| 480 | 418 | remove_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 ); |
| 481 | 419 | return new WP_Error( |
| 482 | 420 | 'empty_password', |
| 483 | 421 | sprintf( |
| 484 | - /* TRANSLATORS: 1: username 2: duration of lockout in seconds 3: duration of lockout as a phrase 4: lost password URL */ | |
| 485 | 422 | __( '<strong>ERROR</strong>: There have been too many invalid login attempts for the username <strong>%1$s</strong>. Please wait <strong id="seconds_remaining" data-seconds="%2$s">%3$s</strong> before trying again. <a href="%4$s" title="Password Lost and Found">Lost your password</a>?', 'authorizer' ), |
| 486 | 423 | $username, |
| 487 | 424 | $seconds_remaining_short_lockout, |
| 488 | 425 | $this->seconds_as_sentence( $seconds_remaining_short_lockout ), |
| @@ -492,16 +429,16 @@ | ||
| 492 | 429 | } |
| 493 | 430 | |
| 494 | 431 | // Start external authentication. |
| 495 | 432 | $externally_authenticated_emails = array(); |
| 496 | - $authenticated_by = ''; | |
| 497 | - $result = null; | |
| 433 | + $authenticated_by = ''; | |
| 434 | + $result = null; | |
| 498 | 435 | |
| 499 | 436 | // Try Google authentication if it's enabled and we don't have a |
| 500 | 437 | // successful login yet. |
| 501 | 438 | if ( |
| 502 | - '1' === $auth_settings['google'] && | |
| 503 | - 0 === count( $externally_authenticated_emails ) && | |
| 439 | + $auth_settings['google'] === '1' && | |
| 440 | + count( $externally_authenticated_emails ) === 0 && | |
| 504 | 441 | ! is_wp_error( $result ) |
| 505 | 442 | ) { |
| 506 | 443 | $result = $this->custom_authenticate_google( $auth_settings ); |
| 507 | 444 | if ( ! is_null( $result ) && ! is_wp_error( $result ) ) { |
| @@ -516,10 +453,10 @@ | ||
| 516 | 453 | |
| 517 | 454 | // Try CAS authentication if it's enabled and we don't have a |
| 518 | 455 | // successful login yet. |
| 519 | 456 | if ( |
| 520 | - '1' === $auth_settings['cas'] && | |
| 521 | - 0 === count( $externally_authenticated_emails ) && | |
| 457 | + $auth_settings['cas'] === '1' && | |
| 458 | + count( $externally_authenticated_emails ) === 0 && | |
| 522 | 459 | ! is_wp_error( $result ) |
| 523 | 460 | ) { |
| 524 | 461 | $result = $this->custom_authenticate_cas( $auth_settings ); |
| 525 | 462 | if ( ! is_null( $result ) && ! is_wp_error( $result ) ) { |
| @@ -534,10 +471,10 @@ | ||
| 534 | 471 | |
| 535 | 472 | // Try LDAP authentication if it's enabled and we don't have an |
| 536 | 473 | // authenticated user yet. |
| 537 | 474 | if ( |
| 538 | - '1' === $auth_settings['ldap'] && | |
| 539 | - 0 === count( $externally_authenticated_emails ) && | |
| 475 | + $auth_settings['ldap'] === '1' && | |
| 476 | + count( $externally_authenticated_emails ) === 0 && | |
| 540 | 477 | ! is_wp_error( $result ) |
| 541 | 478 | ) { |
| 542 | 479 | $result = $this->custom_authenticate_ldap( $auth_settings, $username, $password ); |
| 543 | 480 | if ( ! is_null( $result ) && ! is_wp_error( $result ) ) { |
| @@ -558,33 +495,31 @@ | ||
| 558 | 495 | |
| 559 | 496 | // Remove duplicate and blank emails, if any. |
| 560 | 497 | $externally_authenticated_emails = array_filter( array_unique( $externally_authenticated_emails ) ); |
| 561 | 498 | |
| 562 | - /** | |
| 563 | - * If we've made it this far, we should have an externally | |
| 564 | - * authenticated user. The following should be set: | |
| 565 | - * $externally_authenticated_emails | |
| 566 | - * $authenticated_by | |
| 567 | - */ | |
| 499 | + // If we've made it this far, we should have an externally | |
| 500 | + // authenticated user. The following should be set: | |
| 501 | + // $externally_authenticated_emails | |
| 502 | + // $authenticated_by | |
| 568 | 503 | |
| 569 | 504 | // Get the external user's WordPress account by email address. |
| 570 | 505 | foreach ( $externally_authenticated_emails as $externally_authenticated_email ) { |
| 571 | - $user = get_user_by( 'email', $this->lowercase( $externally_authenticated_email ) ); | |
| 506 | + $user = get_user_by( 'email', $externally_authenticated_email ); | |
| 572 | 507 | |
| 573 | 508 | // If we've already found a WordPress user associated with one |
| 574 | 509 | // of the supplied email addresses, don't keep examining other |
| 575 | 510 | // email addresses associated with the externally authenticated user. |
| 576 | - if ( false !== $user ) { | |
| 511 | + if ( $user !== FALSE ) { | |
| 577 | 512 | break; |
| 578 | 513 | } |
| 579 | 514 | } |
| 580 | 515 | |
| 581 | 516 | // Check this external user's access against the access lists |
| 582 | - // (pending, approved, blocked). | |
| 517 | + // (pending, approved, blocked) | |
| 583 | 518 | $result = $this->check_user_access( $user, $externally_authenticated_emails, $result ); |
| 584 | 519 | |
| 585 | 520 | // Fail with message if there was an error creating/adding the user. |
| 586 | - if ( is_wp_error( $result ) || 0 === $result ) { | |
| 521 | + if ( is_wp_error( $result ) || $result === 0 ) { | |
| 587 | 522 | return $result; |
| 588 | 523 | } |
| 589 | 524 | |
| 590 | 525 | // If we created a new user in check_user_access(), log that user in. |
| @@ -605,30 +540,27 @@ | ||
| 605 | 540 | /** |
| 606 | 541 | * This function will fail with a wp_die() message to the user if they |
| 607 | 542 | * don't have access. |
| 608 | 543 | * |
| 609 | - * @param WP_User $user User to check. | |
| 610 | - * @param array $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account). | |
| 611 | - * @param array $user_data Array of keys for email, username, first_name, last_name, | |
| 612 | - * authenticated_by, google_attributes, cas_attributes, ldap_attributes. | |
| 613 | - * @return WP_Error|void|null|WP_User | |
| 614 | - * WP_Error if there was an error on user creation / adding user to blog. | |
| 615 | - * wp_die() if user does not have access. | |
| 616 | - * null if user has access (success). | |
| 617 | - * WP_User if user has access and a new account was created for them. | |
| 544 | + * @param WP_User $user User to check | |
| 545 | + * @param [type] $user_emails Array of user's plaintext emails (in case current user doesn't have a WP account) | |
| 546 | + * @param [type] $user_data Array of keys for email, username, first_name, last_name, | |
| 547 | + * authenticated_by, google_attributes, cas_attributes, ldap_attributes. | |
| 548 | + * @return WP_Error if there was an error on user creation / adding user to blog | |
| 549 | + * wp_die() if user does not have access | |
| 550 | + * null if user has access (success) | |
| 551 | + * WP_User if user has access and a new account was created for them | |
| 618 | 552 | */ |
| 619 | 553 | private function check_user_access( $user, $user_emails, $user_data = array() ) { |
| 620 | 554 | // Grab plugin settings. |
| 621 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 622 | - $auth_settings_access_users_pending = $this->sanitize_user_list( | |
| 623 | - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 555 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 556 | + $auth_settings_access_users_pending = $this->sanitize_user_list( | |
| 557 | + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ) | |
| 624 | 558 | ); |
| 625 | - $auth_settings_access_users_approved_single = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 626 | - $auth_settings_access_users_approved_multi = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 627 | - $auth_settings_access_users_approved = $this->sanitize_user_list( | |
| 559 | + $auth_settings_access_users_approved = $this->sanitize_user_list( | |
| 628 | 560 | array_merge( |
| 629 | - $auth_settings_access_users_approved_single, | |
| 630 | - $auth_settings_access_users_approved_multi | |
| 561 | + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ), | |
| 562 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 631 | 563 | ) |
| 632 | 564 | ); |
| 633 | 565 | |
| 634 | 566 | /** |
| @@ -634,31 +566,28 @@ | ||
| 634 | 566 | /** |
| 635 | 567 | * Filter whether to block the currently logging in user based on any of |
| 636 | 568 | * their user attributes. |
| 637 | 569 | * |
| 638 | - * @param bool $allow_login Whether to block the currently logging in user. | |
| 570 | + * @param bool $user_is_blocked Whether to block the currently logging in user. | |
| 639 | 571 | * @param array $user_data User data returned from external service. |
| 640 | 572 | */ |
| 641 | - $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data ); | |
| 642 | - $blocked_by_filter = ! $allow_login; // Use this for better readability. | |
| 573 | + $allow_login = apply_filters( 'authorizer_allow_login', true, $user_data ); | |
| 643 | 574 | |
| 644 | 575 | // Check our externally authenticated user against the block list. |
| 645 | 576 | // If any of their email addresses are blocked, set the relevant user |
| 646 | 577 | // meta field, and show them an error screen. |
| 647 | 578 | foreach ( $user_emails as $user_email ) { |
| 648 | - if ( $blocked_by_filter || $this->is_email_in_list( $user_email, 'blocked' ) ) { | |
| 579 | + if ( ! $allow_login || $this->is_email_in_list( $user_email, 'blocked' ) ) { | |
| 649 | 580 | |
| 650 | 581 | // Add user to blocked list if it was blocked via the filter. |
| 651 | - if ( $blocked_by_filter && ! $this->is_email_in_list( $user_email, 'blocked' ) ) { | |
| 582 | + if ( ! $allow_login && ! $this->is_email_in_list( $user_email, 'blocked' ) ) { | |
| 652 | 583 | $auth_settings_access_users_blocked = $this->sanitize_user_list( |
| 653 | - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 584 | + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ) | |
| 654 | 585 | ); |
| 655 | - array_push( | |
| 656 | - $auth_settings_access_users_blocked, array( | |
| 657 | - 'email' => $this->lowercase( $user_email ), | |
| 658 | - 'date_added' => date( 'M Y' ), | |
| 659 | - ) | |
| 660 | - ); | |
| 586 | + array_push( $auth_settings_access_users_blocked, array( | |
| 587 | + 'email' => $user_email, | |
| 588 | + 'date_added' => date( 'M Y' ), | |
| 589 | + )); | |
| 661 | 590 | update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked ); |
| 662 | 591 | } |
| 663 | 592 | |
| 664 | 593 | // If the blocked external user has a WordPress account, mark it as |
| @@ -667,11 +596,10 @@ | ||
| 667 | 596 | update_user_meta( $user->ID, 'auth_blocked', 'yes' ); |
| 668 | 597 | } |
| 669 | 598 | |
| 670 | 599 | // Notify user about blocked status and return without authenticating them. |
| 671 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 672 | - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url(); | |
| 673 | - $page_title = sprintf( | |
| 600 | + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url(); | |
| 601 | + $page_title = sprintf( | |
| 674 | 602 | /* TRANSLATORS: %s: Name of blog */ |
| 675 | 603 | __( '%s - Access Restricted', 'authorizer' ), |
| 676 | 604 | get_bloginfo( 'name' ) |
| 677 | 605 | ); |
| @@ -682,14 +610,13 @@ | ||
| 682 | 610 | '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' . |
| 683 | 611 | __( 'Back', 'authorizer' ) . |
| 684 | 612 | '</a></p>'; |
| 685 | 613 | update_option( 'auth_settings_advanced_login_error', $error_message ); |
| 686 | - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) ); | |
| 614 | + wp_die( $error_message, $page_title ); | |
| 687 | 615 | } |
| 688 | 616 | } |
| 689 | 617 | |
| 690 | - // Get the default role for this user (or their current role, if they | |
| 691 | - // already have an account). | |
| 618 | + // Get the default role for this new user. | |
| 692 | 619 | $default_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $auth_settings['access_default_role']; |
| 693 | 620 | /** |
| 694 | 621 | * Filter the role of the user currently logging in. The role will be |
| 695 | 622 | * set to the default (specified in Authorizer options) for new users, |
| @@ -694,24 +621,13 @@ | ||
| 694 | 621 | * Filter the role of the user currently logging in. The role will be |
| 695 | 622 | * set to the default (specified in Authorizer options) for new users, |
| 696 | 623 | * or the user's current role for existing users. This filter allows |
| 697 | 624 | * changing user roles based on custom CAS/LDAP attributes. |
| 698 | - * | |
| 699 | 625 | * @param bool $role Role of the user currently logging in. |
| 700 | 626 | * @param array $user_data User data returned from external service. |
| 701 | 627 | */ |
| 702 | 628 | $approved_role = apply_filters( 'authorizer_custom_role', $default_role, $user_data ); |
| 703 | 629 | |
| 704 | - /** | |
| 705 | - * Filter whether to automatically approve the currently logging in user | |
| 706 | - * based on any of their user attributes. | |
| 707 | - * | |
| 708 | - * @param bool $automatically_approve_login | |
| 709 | - * Whether to automatically approve the currently logging in user. | |
| 710 | - * @param array $user_data User data returned from external service. | |
| 711 | - */ | |
| 712 | - $automatically_approve_login = apply_filters( 'authorizer_automatically_approve_login', false, $user_data ); | |
| 713 | - | |
| 714 | 630 | // Iterate through each of the email addresses provided by the external |
| 715 | 631 | // service and determine if any of them have access. |
| 716 | 632 | $last_email = end( $user_emails ); |
| 717 | 633 | reset( $user_emails ); |
| @@ -725,16 +641,12 @@ | ||
| 725 | 641 | return; |
| 726 | 642 | } |
| 727 | 643 | |
| 728 | 644 | // If this externally authenticated user isn't in the approved list |
| 729 | - // and login access is set to "All authenticated users," or if they were | |
| 730 | - // automatically approved in the "authorizer_approve_login" filter | |
| 731 | - // above, then add them to the approved list (they'll get an account | |
| 732 | - // created below if they don't have one yet). | |
| 733 | - if ( | |
| 734 | - ! $this->is_email_in_list( $user_email, 'approved' ) && | |
| 735 | - ( 'external_users' === $auth_settings['access_who_can_login'] || $automatically_approve_login ) | |
| 736 | - ) { | |
| 645 | + // and login access is set to "All authenticated users," add them | |
| 646 | + // to the approved list (they'll get an account created below if | |
| 647 | + // they don't have one yet). | |
| 648 | + if ( ! $this->is_email_in_list( $user_email, 'approved' ) && $auth_settings['access_who_can_login'] === 'external_users' ) { | |
| 737 | 649 | $is_newly_approved_user = true; |
| 738 | 650 | |
| 739 | 651 | // If this user happens to be in the pending list (rare), |
| 740 | 652 | // remove them from pending before adding them to approved. |
| @@ -739,9 +651,9 @@ | ||
| 739 | 651 | // If this user happens to be in the pending list (rare), |
| 740 | 652 | // remove them from pending before adding them to approved. |
| 741 | 653 | if ( $this->is_email_in_list( $user_email, 'pending' ) ) { |
| 742 | 654 | foreach ( $auth_settings_access_users_pending as $key => $pending_user ) { |
| 743 | - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) { | |
| 655 | + if ( $pending_user['email'] === $user_email ) { | |
| 744 | 656 | unset( $auth_settings_access_users_pending[ $key ] ); |
| 745 | 657 | update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending ); |
| 746 | 658 | break; |
| 747 | 659 | } |
| @@ -749,15 +661,14 @@ | ||
| 749 | 661 | } |
| 750 | 662 | |
| 751 | 663 | // Add this user to the approved list. |
| 752 | 664 | $approved_user = array( |
| 753 | - 'email' => $this->lowercase( $user_email ), | |
| 754 | - 'role' => $approved_role, | |
| 755 | - 'date_added' => date( 'Y-m-d H:i:s' ), | |
| 665 | + 'email' => $user_email, | |
| 666 | + 'role' => $approved_role, | |
| 667 | + 'date_added' => date( "Y-m-d H:i:s" ), | |
| 756 | 668 | ); |
| 757 | 669 | array_push( $auth_settings_access_users_approved, $approved_user ); |
| 758 | - array_push( $auth_settings_access_users_approved_single, $approved_user ); | |
| 759 | - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single ); | |
| 670 | + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 760 | 671 | } |
| 761 | 672 | |
| 762 | 673 | // Check our externally authenticated user against the approved |
| 763 | 674 | // list. If they are approved, log them in (and create their account |
| @@ -771,9 +682,9 @@ | ||
| 771 | 682 | if ( $default_role !== $approved_role ) { |
| 772 | 683 | $user_info['role'] = $approved_role; |
| 773 | 684 | } |
| 774 | 685 | |
| 775 | - // If the approved external user does not have a WordPress account, create it. | |
| 686 | + // If the approved external user does not have a WordPress account, create it | |
| 776 | 687 | if ( ! $user ) { |
| 777 | 688 | // If there's already a user with this username (e.g., |
| 778 | 689 | // johndoe/johndoe@gmail.com exists, and we're trying to add |
| 779 | 690 | // johndoe/johndoe@example.com), use the full email address |
| @@ -788,47 +699,26 @@ | ||
| 788 | 699 | $username = $user_info['email']; |
| 789 | 700 | } |
| 790 | 701 | $result = wp_insert_user( |
| 791 | 702 | array( |
| 792 | - 'user_login' => strtolower( $username ), | |
| 793 | - 'user_pass' => wp_generate_password(), // random password. | |
| 794 | - 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '', | |
| 795 | - 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '', | |
| 796 | - 'user_email' => $this->lowercase( $user_info['email'] ), | |
| 703 | + 'user_login' => strtolower( $username ), | |
| 704 | + 'user_pass' => wp_generate_password(), // random password | |
| 705 | + 'first_name' => array_key_exists( 'first_name', $user_data ) ? $user_data['first_name'] : '', | |
| 706 | + 'last_name' => array_key_exists( 'last_name', $user_data ) ? $user_data['last_name'] : '', | |
| 707 | + 'user_email' => strtolower( $user_info['email'] ), | |
| 797 | 708 | 'user_registered' => date( 'Y-m-d H:i:s' ), |
| 798 | - 'role' => $user_info['role'], | |
| 709 | + 'role' => $user_info['role'], | |
| 799 | 710 | ) |
| 800 | 711 | ); |
| 801 | 712 | |
| 802 | 713 | // Fail with message if error. |
| 803 | - if ( is_wp_error( $result ) || 0 === $result ) { | |
| 714 | + if ( is_wp_error( $result ) || $result === 0 ) { | |
| 804 | 715 | return $result; |
| 805 | 716 | } |
| 806 | 717 | |
| 807 | - // Authenticate as new user. | |
| 718 | + // Authenticate as new user | |
| 808 | 719 | $user = new WP_User( $result ); |
| 809 | 720 | |
| 810 | - /** | |
| 811 | - * Fires after an external user is authenticated for the first time | |
| 812 | - * and a new WordPress account is created for them. | |
| 813 | - * | |
| 814 | - * @since 2.8.0 | |
| 815 | - * | |
| 816 | - * @param WP_User $user User object. | |
| 817 | - * @param array $user_data User data from external service. | |
| 818 | - * | |
| 819 | - * Example $user_data: | |
| 820 | - * array( | |
| 821 | - * 'email' => 'user@example.edu', | |
| 822 | - * 'username' => 'user', | |
| 823 | - * 'first_name' => 'First', | |
| 824 | - * 'last_name' => 'Last', | |
| 825 | - * 'authenticated_by' => 'cas', | |
| 826 | - * 'cas_attributes' => array( ... ), | |
| 827 | - * ); | |
| 828 | - */ | |
| 829 | - do_action( 'authorizer_user_register', $user, $user_data ); | |
| 830 | - | |
| 831 | 721 | // If multisite, iterate through all sites in the network and add the user |
| 832 | 722 | // currently logging in to any of them that have the user on the approved list. |
| 833 | 723 | // Note: this is useful for first-time logins--some users will have access |
| 834 | 724 | // to multiple sites, and this prevents them from having to log into each |
| @@ -834,21 +724,18 @@ | ||
| 834 | 724 | // to multiple sites, and this prevents them from having to log into each |
| 835 | 725 | // site individually to get access. |
| 836 | 726 | if ( is_multisite() ) { |
| 837 | 727 | $site_ids_of_user = array_map( |
| 838 | - function ( $site_of_user ) { | |
| 839 | - return intval( $site_of_user->userblog_id ); | |
| 840 | - }, | |
| 728 | + function ( $site_of_user ) { return $site_of_user->userblog_id; }, | |
| 841 | 729 | get_blogs_of_user( $user->ID ) |
| 842 | 730 | ); |
| 843 | 731 | |
| 844 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 845 | 732 | $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); |
| 846 | 733 | foreach ( $sites as $site ) { |
| 847 | 734 | $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; |
| 848 | 735 | |
| 849 | 736 | // Skip if user is already added to this site. |
| 850 | - if ( in_array( intval( $blog_id ), $site_ids_of_user, true ) ) { | |
| 737 | + if ( in_array( $blog_id, $site_ids_of_user ) ) { | |
| 851 | 738 | continue; |
| 852 | 739 | } |
| 853 | 740 | |
| 854 | 741 | // Check if user is on the approved list of this site they are not added to. |
| @@ -874,9 +761,9 @@ | ||
| 874 | 761 | if ( $meta_key === $user_info['usermeta']['meta_key'] ) { |
| 875 | 762 | // Update user's usermeta value for usermeta key stored in authorizer options. |
| 876 | 763 | if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) { |
| 877 | 764 | // We have an ACF field value, so use the ACF function to update it. |
| 878 | - update_field( str_replace( 'acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID ); | |
| 765 | + update_field( str_replace('acf___', '', $meta_key ), $user_info['usermeta']['meta_value'], 'user_' . $user->ID ); | |
| 879 | 766 | } else { |
| 880 | 767 | // We have a normal usermeta value, so just update it via the WordPress function. |
| 881 | 768 | update_user_meta( $user->ID, $meta_key, $user_info['usermeta']['meta_value'] ); |
| 882 | 769 | } |
| @@ -892,9 +779,9 @@ | ||
| 892 | 779 | switch_to_blog( $blog_id ); |
| 893 | 780 | // Update user's usermeta value for usermeta key stored in authorizer options. |
| 894 | 781 | if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) { |
| 895 | 782 | // We have an ACF field value, so use the ACF function to update it. |
| 896 | - update_field( str_replace( 'acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID ); | |
| 783 | + update_field( str_replace('acf___', '', $meta_key ), $usermeta['meta_value'], 'user_' . $user->ID ); | |
| 897 | 784 | } else { |
| 898 | 785 | // We have a normal usermeta value, so just update it via the WordPress function. |
| 899 | 786 | update_user_meta( $user->ID, $meta_key, $usermeta['meta_value'] ); |
| 900 | 787 | } |
| @@ -905,24 +792,20 @@ | ||
| 905 | 792 | } |
| 906 | 793 | } else { |
| 907 | 794 | // Update first/last names of WordPress user from external |
| 908 | 795 | // service if that option is set. |
| 909 | - if ( ( array_key_exists( 'authenticated_by', $user_data ) && 'cas' === $user_data['authenticated_by'] && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['cas_attr_update_on_login'] ) ) || ( array_key_exists( 'authenticated_by', $user_data ) && 'ldap' === $user_data['authenticated_by'] && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && 1 === intval( $auth_settings['ldap_attr_update_on_login'] ) ) ) { | |
| 910 | - if ( array_key_exists( 'first_name', $user_data ) && 0 < strlen( $user_data['first_name'] ) ) { | |
| 911 | - wp_update_user( | |
| 912 | - array( | |
| 913 | - 'ID' => $user->ID, | |
| 914 | - 'first_name' => $user_data['first_name'], | |
| 915 | - ) | |
| 916 | - ); | |
| 796 | + if ( ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'cas' && array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && $auth_settings['cas_attr_update_on_login'] == 1 ) || ( array_key_exists( 'authenticated_by', $user_data ) && $user_data['authenticated_by'] === 'ldap' && array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && $auth_settings['ldap_attr_update_on_login'] == 1 ) ) { | |
| 797 | + if ( array_key_exists( 'first_name', $user_data ) && strlen( $user_data['first_name'] ) > 0 ) { | |
| 798 | + wp_update_user( array( | |
| 799 | + 'ID' => $user->ID, | |
| 800 | + 'first_name' => $user_data['first_name'], | |
| 801 | + )); | |
| 917 | 802 | } |
| 918 | 803 | if ( array_key_exists( 'last_name', $user_data ) && strlen( $user_data['last_name'] ) > 0 ) { |
| 919 | - wp_update_user( | |
| 920 | - array( | |
| 921 | - 'ID' => $user->ID, | |
| 922 | - 'last_name' => $user_data['last_name'], | |
| 923 | - ) | |
| 924 | - ); | |
| 804 | + wp_update_user( array( | |
| 805 | + 'ID' => $user->ID, | |
| 806 | + 'last_name' => $user_data['last_name'], | |
| 807 | + )); | |
| 925 | 808 | } |
| 926 | 809 | } |
| 927 | 810 | |
| 928 | 811 | // Update this user's role if it was modified in the |
| @@ -927,19 +810,12 @@ | ||
| 927 | 810 | |
| 928 | 811 | // Update this user's role if it was modified in the |
| 929 | 812 | // authorizer_custom_role filter. |
| 930 | 813 | if ( $default_role !== $approved_role ) { |
| 931 | - // Update user's role in WordPress. | |
| 932 | - $user->set_role( $approved_role ); | |
| 933 | - | |
| 934 | - // Update user's role in this site's approved list and save. | |
| 935 | - foreach ( $auth_settings_access_users_approved_single as $key => $existing_user ) { | |
| 936 | - if ( 0 === strcasecmp( $user->user_email, $existing_user['email'] ) ) { | |
| 937 | - $auth_settings_access_users_approved_single[ $key ]['role'] = $approved_role; | |
| 938 | - break; | |
| 939 | - } | |
| 940 | - } | |
| 941 | - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved_single ); | |
| 814 | + wp_update_user( array( | |
| 815 | + 'ID' => $user->ID, | |
| 816 | + 'role' => $approved_role, | |
| 817 | + )); | |
| 942 | 818 | } |
| 943 | 819 | } |
| 944 | 820 | |
| 945 | 821 | // If this is multisite, add new user to current blog. |
| @@ -952,34 +828,33 @@ | ||
| 952 | 828 | } |
| 953 | 829 | } |
| 954 | 830 | |
| 955 | 831 | // Ensure user has the same role as their entry in the approved list. |
| 956 | - if ( $user_info && ! in_array( $user_info['role'], $user->roles, true ) ) { | |
| 832 | + // (This is just a precaution, the role should already be set when | |
| 833 | + // saving admin options in the sanitizing function.) | |
| 834 | + if ( $user_info && ! array_key_exists( $user_info['role'], $user->roles ) ) { | |
| 957 | 835 | $user->set_role( $user_info['role'] ); |
| 958 | 836 | } |
| 959 | 837 | |
| 960 | 838 | return $user; |
| 961 | 839 | |
| 962 | - } elseif ( 0 === strcasecmp( $user_email, $last_email ) ) { | |
| 963 | - /** | |
| 964 | - * Note: only do this for the last email address we are checking (we need | |
| 965 | - * to iterate through them all to make sure one of them isn't approved). | |
| 966 | - */ | |
| 967 | - | |
| 840 | + // Note: only do this for the last email address we are checking (we need | |
| 841 | + // to iterate through them all to make sure one of them isn't approved). | |
| 842 | + } elseif ( $user_email === $last_email ) { | |
| 968 | 843 | // User isn't an admin, is not blocked, and is not approved. |
| 969 | 844 | // Add them to the pending list and notify them and their instructor. |
| 970 | 845 | if ( strlen( $user_email ) > 0 && ! $this->is_email_in_list( $user_email, 'pending' ) ) { |
| 971 | - $pending_user = array(); | |
| 972 | - $pending_user['email'] = $this->lowercase( $user_email ); | |
| 973 | - $pending_user['role'] = $approved_role; | |
| 846 | + $pending_user = array(); | |
| 847 | + $pending_user['email'] = $user_email; | |
| 848 | + $pending_user['role'] = $approved_role; | |
| 974 | 849 | $pending_user['date_added'] = ''; |
| 975 | 850 | array_push( $auth_settings_access_users_pending, $pending_user ); |
| 976 | 851 | update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending ); |
| 977 | 852 | |
| 978 | 853 | // Create strings used in the email notification. |
| 979 | - $site_name = get_bloginfo( 'name' ); | |
| 980 | - $site_url = get_bloginfo( 'url' ); | |
| 981 | - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' ); | |
| 854 | + $site_name = get_bloginfo( 'name' ); | |
| 855 | + $site_url = get_bloginfo( 'url' ); | |
| 856 | + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' ); | |
| 982 | 857 | |
| 983 | 858 | // Notify users with the role specified in "Which role should |
| 984 | 859 | // receive email notifications about pending users?". |
| 985 | 860 | if ( strlen( $auth_settings['access_role_receive_pending_emails'] ) > 0 ) { |
| @@ -1004,11 +879,10 @@ | ||
| 1004 | 879 | } |
| 1005 | 880 | } |
| 1006 | 881 | |
| 1007 | 882 | // Notify user about pending status and return without authenticating them. |
| 1008 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 1009 | - $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : home_url(); | |
| 1010 | - $page_title = get_bloginfo( 'name' ) . ' - Access Pending'; | |
| 883 | + $redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : home_url(); | |
| 884 | + $page_title = get_bloginfo( 'name' ) . ' - Access Pending'; | |
| 1011 | 885 | $error_message = |
| 1012 | 886 | apply_filters( 'the_content', $auth_settings['access_pending_redirect_to_message'] ) . |
| 1013 | 887 | '<hr />' . |
| 1014 | 888 | '<p style="text-align: center;">' . |
| @@ -1015,9 +889,9 @@ | ||
| 1015 | 889 | '<a class="button" href="' . wp_logout_url( $redirect_to ) . '">' . |
| 1016 | 890 | __( 'Back', 'authorizer' ) . |
| 1017 | 891 | '</a></p>'; |
| 1018 | 892 | update_option( 'auth_settings_advanced_login_error', $error_message ); |
| 1019 | - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) ); | |
| 893 | + wp_die( $error_message, $page_title ); | |
| 1020 | 894 | } |
| 1021 | 895 | } |
| 1022 | 896 | |
| 1023 | 897 | // Sanity check: if we made it here without returning, something has gone wrong. |
| @@ -1040,34 +914,24 @@ | ||
| 1040 | 914 | * custom_authenticate_google() runs to verify the token; once verified |
| 1041 | 915 | * custom_authenticate proceeds as normal with the google email address |
| 1042 | 916 | * as a successfully authenticated external user. |
| 1043 | 917 | * |
| 1044 | - * Action: wp_ajax_process_google_login | |
| 1045 | - * Action: wp_ajax_nopriv_process_google_login | |
| 1046 | - * | |
| 1047 | - * @return void, but die with the value to return to the success() function in AJAX call signInCallback(). | |
| 918 | + * @return void, but die with the value to return to the success() function in AJAX call signInCallback() | |
| 1048 | 919 | */ |
| 1049 | - public function ajax_process_google_login() { | |
| 920 | + function ajax_process_google_login() { | |
| 921 | + $nonce = array_key_exists( 'nonce', $_POST ) ? $_POST['nonce'] : ''; | |
| 922 | + $code = array_key_exists( 'code', $_POST ) ? $_POST['code'] : null; | |
| 923 | + | |
| 1050 | 924 | // Nonce check. |
| 1051 | - if ( | |
| 1052 | - ! isset( $_POST['nonce'] ) || | |
| 1053 | - ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'google_csrf_nonce' ) | |
| 1054 | - ) { | |
| 1055 | - die( '' ); | |
| 925 | + if ( ! wp_verify_nonce( $nonce, 'google_csrf_nonce' ) ) { | |
| 926 | + return ''; | |
| 1056 | 927 | } |
| 1057 | 928 | |
| 1058 | - // Google authentication token. | |
| 1059 | - // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput.InputNotSanitized | |
| 1060 | - $code = isset( $_POST['code'] ) ? wp_unslash( $_POST['code'] ) : null; | |
| 1061 | - | |
| 1062 | 929 | // Grab plugin settings. |
| 1063 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 930 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 1064 | 931 | |
| 1065 | - /** | |
| 1066 | - * Add Google API PHP Client. | |
| 1067 | - * | |
| 1068 | - * @see https://github.com/google/google-api-php-client branch:v1-master | |
| 1069 | - */ | |
| 932 | + // Add Google API PHP Client. | |
| 933 | + // @see https://github.com/google/google-api-php-client branch:v1-master | |
| 1070 | 934 | require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php'; |
| 1071 | 935 | |
| 1072 | 936 | // Build the Google Client. |
| 1073 | 937 | $client = new Google_Client(); |
| @@ -1075,26 +939,14 @@ | ||
| 1075 | 939 | $client->setClientId( $auth_settings['google_clientid'] ); |
| 1076 | 940 | $client->setClientSecret( $auth_settings['google_clientsecret'] ); |
| 1077 | 941 | $client->setRedirectUri( 'postmessage' ); |
| 1078 | 942 | |
| 1079 | - /** | |
| 1080 | - * If the hosted domain parameter is set, restrict logins to that domain. | |
| 1081 | - * | |
| 1082 | - * Note: Will have to upgrade to google-api-php-client v2 or higher for | |
| 1083 | - * this to function server-side; it's not complete in v1, so this check | |
| 1084 | - * is performed manually below. | |
| 1085 | - * | |
| 1086 | - * if ( | |
| 1087 | - * array_key_exists( 'google_hosteddomain', $auth_settings ) && | |
| 1088 | - * strlen( $auth_settings['google_hosteddomain'] ) > 0 | |
| 1089 | - * ) { | |
| 1090 | - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) ); | |
| 1091 | - * $google_hosteddomain = trim( $google_hosteddomains[0] ); | |
| 1092 | - * $client->setHostedDomain( $google_hosteddomain ); | |
| 1093 | - * } | |
| 1094 | - */ | |
| 943 | + // If the hosted domain parameter is set, restrict logins to that domain. | |
| 944 | + if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) { | |
| 945 | + $client->setHostedDomain( $auth_settings['google_hosteddomain'] ); | |
| 946 | + } | |
| 1095 | 947 | |
| 1096 | - // Get one time use token (if it doesn't exist, we'll create one below). | |
| 948 | + // Get one time use token (if it doesn't exist, we'll create one below) | |
| 1097 | 949 | session_start(); |
| 1098 | 950 | $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null; |
| 1099 | 951 | |
| 1100 | 952 | if ( empty( $token ) ) { |
| @@ -1102,18 +954,18 @@ | ||
| 1102 | 954 | $client->authenticate( $code ); |
| 1103 | 955 | $token = json_decode( $client->getAccessToken() ); |
| 1104 | 956 | |
| 1105 | 957 | // Store the token in the session for later use. |
| 1106 | - $_SESSION['token'] = wp_json_encode( $token ); | |
| 958 | + $_SESSION['token'] = json_encode( $token ); | |
| 1107 | 959 | |
| 1108 | - $response = 'Successfully authenticated.'; | |
| 960 | + $response = "Successfully authenticated."; | |
| 1109 | 961 | } else { |
| 1110 | - $client->setAccessToken( wp_json_encode( $token ) ); | |
| 962 | + $client->setAccessToken( json_encode( $token ) ); | |
| 1111 | 963 | |
| 1112 | 964 | $response = 'Already authenticated.'; |
| 1113 | 965 | } |
| 1114 | 966 | |
| 1115 | - die( esc_html( $response ) ); | |
| 967 | + die( $response ); | |
| 1116 | 968 | } |
| 1117 | 969 | |
| 1118 | 970 | |
| 1119 | 971 | /** |
| @@ -1118,22 +970,22 @@ | ||
| 1118 | 970 | |
| 1119 | 971 | /** |
| 1120 | 972 | * Validate this user's credentials against Google. |
| 1121 | 973 | * |
| 1122 | - * @param array $auth_settings Plugin settings. | |
| 1123 | - * @return array|WP_Error Array containing email, authenticated_by, first_name, | |
| 1124 | - * last_name, and username strings for the successfully | |
| 1125 | - * authenticated user, or WP_Error() object on failure, | |
| 1126 | - * or null if not attempting a google login. | |
| 974 | + * @param array $auth_settings Plugin settings | |
| 975 | + * @return [mixed] Array containing email, authenticated_by, | |
| 976 | + * first_name, last_name, and username | |
| 977 | + * strings for the successfully authenticated | |
| 978 | + * user, or WP_Error() object on failure, | |
| 979 | + * or null if not attempting a google login. | |
| 1127 | 980 | */ |
| 1128 | 981 | private function custom_authenticate_google( $auth_settings ) { |
| 1129 | 982 | // Move on if Google auth hasn't been requested here. |
| 1130 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 1131 | - if ( empty( $_GET['external'] ) || 'google' !== $_GET['external'] ) { | |
| 983 | + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'google' ) { | |
| 1132 | 984 | return null; |
| 1133 | 985 | } |
| 1134 | 986 | |
| 1135 | - // Get one time use token. | |
| 987 | + // Get one time use token | |
| 1136 | 988 | session_start(); |
| 1137 | 989 | $token = array_key_exists( 'token', $_SESSION ) ? json_decode( $_SESSION['token'] ) : null; |
| 1138 | 990 | |
| 1139 | 991 | // No token, so this is not a succesful Google login. |
| @@ -1140,13 +992,10 @@ | ||
| 1140 | 992 | if ( is_null( $token ) ) { |
| 1141 | 993 | return null; |
| 1142 | 994 | } |
| 1143 | 995 | |
| 1144 | - /** | |
| 1145 | - * Add Google API PHP Client. | |
| 1146 | - * | |
| 1147 | - * @see https://github.com/google/google-api-php-client branch:v1-master | |
| 1148 | - */ | |
| 996 | + // Add Google API PHP Client. | |
| 997 | + // @see https://github.com/google/google-api-php-client branch:v1-master | |
| 1149 | 998 | require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php'; |
| 1150 | 999 | |
| 1151 | 1000 | // Build the Google Client. |
| 1152 | 1001 | $client = new Google_Client(); |
| @@ -1154,24 +1003,14 @@ | ||
| 1154 | 1003 | $client->setClientId( $auth_settings['google_clientid'] ); |
| 1155 | 1004 | $client->setClientSecret( $auth_settings['google_clientsecret'] ); |
| 1156 | 1005 | $client->setRedirectUri( 'postmessage' ); |
| 1157 | 1006 | |
| 1158 | - /** | |
| 1159 | - * If the hosted domain parameter is set, restrict logins to that domain. | |
| 1160 | - * Note: Will have to upgrade to google-api-php-client v2 or higher for | |
| 1161 | - * this to function server-side; it's not complete in v1, so this check | |
| 1162 | - * is performed manually later. | |
| 1163 | - * if ( | |
| 1164 | - * array_key_exists( 'google_hosteddomain', $auth_settings ) && | |
| 1165 | - * strlen( $auth_settings['google_hosteddomain'] ) > 0 | |
| 1166 | - * ) { | |
| 1167 | - * $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) ); | |
| 1168 | - * $google_hosteddomain = trim( $google_hosteddomains[0] ); | |
| 1169 | - * $client->setHostedDomain( $google_hosteddomain ); | |
| 1170 | - * } | |
| 1171 | - */ | |
| 1007 | + // If the hosted domain parameter is set, restrict logins to that domain. | |
| 1008 | + if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) { | |
| 1009 | + $client->setHostedDomain( $auth_settings['google_hosteddomain'] ); | |
| 1010 | + } | |
| 1172 | 1011 | |
| 1173 | - // Verify this is a successful Google authentication. | |
| 1012 | + // Verify this is a successful Google authentication | |
| 1174 | 1013 | try { |
| 1175 | 1014 | $ticket = $client->verifyIdToken( $token->id_token, $auth_settings['google_clientid'] ); |
| 1176 | 1015 | } catch ( Google_Auth_Exception $e ) { |
| 1177 | 1016 | // Invalid ticket, so this in not a successful Google login. |
| @@ -1182,40 +1021,37 @@ | ||
| 1182 | 1021 | if ( ! $ticket ) { |
| 1183 | 1022 | return new WP_Error( 'invalid_google_login', __( 'Invalid Google credentials provided.', 'authorizer' ) ); |
| 1184 | 1023 | } |
| 1185 | 1024 | |
| 1186 | - // Get email address. | |
| 1187 | - $attributes = $ticket->getAttributes(); | |
| 1188 | - $email = $this->lowercase( $attributes['payload']['email'] ); | |
| 1025 | + // Get email address | |
| 1026 | + $attributes = $ticket->getAttributes(); | |
| 1027 | + $email = $attributes['payload']['email']; | |
| 1189 | 1028 | $email_domain = substr( strrchr( $email, '@' ), 1 ); |
| 1190 | - $username = current( explode( '@', $email ) ); | |
| 1029 | + $username = current( explode( '@', $email ) ); | |
| 1191 | 1030 | |
| 1192 | - /** | |
| 1193 | - * Fail if hd param is set and the logging in user's email address doesn't | |
| 1194 | - * match the allowed hosted domain. | |
| 1195 | - * | |
| 1196 | - * See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param | |
| 1197 | - * See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416 | |
| 1198 | - * | |
| 1199 | - * Note: Will have to upgrade to google-api-php-client v2 or higher for | |
| 1200 | - * this to function server-side; it's not complete in v1, so this check | |
| 1201 | - * is only performed here. | |
| 1202 | - */ | |
| 1203 | - if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) { | |
| 1204 | - // Allow multiple whitelisted domains. | |
| 1205 | - $google_hosteddomains = explode( "\n", str_replace( "\r", '', $auth_settings['google_hosteddomain'] ) ); | |
| 1206 | - if ( ! in_array( $email_domain, $google_hosteddomains, true ) ) { | |
| 1207 | - $this->custom_logout(); | |
| 1208 | - return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) ); | |
| 1209 | - } | |
| 1031 | + // Fail if hd param is set and the logging in user's email address doesn't | |
| 1032 | + // match the allowed hosted domain. | |
| 1033 | + // See: https://developers.google.com/identity/protocols/OpenIDConnect#hd-param | |
| 1034 | + // See: https://github.com/google/google-api-php-client/blob/v1-master/src/Google/Client.php#L407-L416 | |
| 1035 | + // Note: Will have to upgrade to google-api-php-client v2 or higher for | |
| 1036 | + // this to function server-side; it's not complete in v1, so this check | |
| 1037 | + // is only performed here. | |
| 1038 | + if ( | |
| 1039 | + array_key_exists( 'google_hosteddomain', $auth_settings ) && | |
| 1040 | + strlen( $auth_settings['google_hosteddomain'] ) > 0 && | |
| 1041 | + $email_domain !== $auth_settings['google_hosteddomain'] | |
| 1042 | + ) { | |
| 1043 | + $this->custom_logout(); | |
| 1044 | + return new WP_Error( 'invalid_google_login', __( 'Google credentials do not match the allowed hosted domain', 'authorizer' ) . ' (' . $auth_settings['google_hosteddomain'] . ').' ); | |
| 1210 | 1045 | } |
| 1211 | 1046 | |
| 1047 | + | |
| 1212 | 1048 | return array( |
| 1213 | - 'email' => $email, | |
| 1214 | - 'username' => $username, | |
| 1215 | - 'first_name' => '', | |
| 1216 | - 'last_name' => '', | |
| 1217 | - 'authenticated_by' => 'google', | |
| 1049 | + 'email' => $email, | |
| 1050 | + 'username' => $username, | |
| 1051 | + 'first_name' => '', | |
| 1052 | + 'last_name' => '', | |
| 1053 | + 'authenticated_by' => 'google', | |
| 1218 | 1054 | 'google_attributes' => $attributes, |
| 1219 | 1055 | ); |
| 1220 | 1056 | } |
| 1221 | 1057 | |
| @@ -1222,47 +1058,40 @@ | ||
| 1222 | 1058 | |
| 1223 | 1059 | /** |
| 1224 | 1060 | * Validate this user's credentials against CAS. |
| 1225 | 1061 | * |
| 1226 | - * @param array $auth_settings Plugin settings. | |
| 1227 | - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings | |
| 1228 | - * for the successfully authenticated user, or WP_Error() | |
| 1229 | - * object on failure, or null if not attempting a CAS login. | |
| 1062 | + * @param array $auth_settings Plugin settings | |
| 1063 | + * @return [mixed] Array containing 'email' and 'authenticated_by' | |
| 1064 | + * strings for the successfully authenticated | |
| 1065 | + * user, or WP_Error() object on failure, | |
| 1066 | + * or null if not attempting a CAS login. | |
| 1230 | 1067 | */ |
| 1231 | 1068 | private function custom_authenticate_cas( $auth_settings ) { |
| 1232 | 1069 | // Move on if CAS hasn't been requested here. |
| 1233 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 1234 | - if ( empty( $_GET['external'] ) || 'cas' !== $_GET['external'] ) { | |
| 1070 | + if ( empty( $_GET['external'] ) || $_GET['external'] !== 'cas' ) { | |
| 1235 | 1071 | return null; |
| 1236 | 1072 | } |
| 1237 | 1073 | |
| 1238 | - /** | |
| 1239 | - * Get the CAS server version (default to SAML_VERSION_1_1). | |
| 1240 | - * | |
| 1241 | - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html | |
| 1242 | - */ | |
| 1074 | + // Get the CAS server version (default to SAML_VERSION_1_1). | |
| 1075 | + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html | |
| 1243 | 1076 | $cas_version = SAML_VERSION_1_1; |
| 1244 | - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) { | |
| 1077 | + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) { | |
| 1245 | 1078 | $cas_version = CAS_VERSION_3_0; |
| 1246 | - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) { | |
| 1079 | + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) { | |
| 1247 | 1080 | $cas_version = CAS_VERSION_2_0; |
| 1248 | - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) { | |
| 1081 | + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) { | |
| 1249 | 1082 | $cas_version = CAS_VERSION_1_0; |
| 1250 | 1083 | } |
| 1251 | 1084 | |
| 1252 | - // Set the CAS client configuration. | |
| 1085 | + // Set the CAS client configuration | |
| 1253 | 1086 | phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] ); |
| 1254 | 1087 | |
| 1255 | - // Allow redirects at the CAS server endpoint (e.g., allow connections | |
| 1256 | - // at an old CAS URL that redirects to a newer CAS URL). | |
| 1257 | - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true ); | |
| 1258 | - | |
| 1259 | 1088 | // Update server certificate bundle if it doesn't exist or is older |
| 1260 | 1089 | // than 6 months, then use it to ensure CAS server is legitimate. |
| 1261 | 1090 | // Note: only try to update if the system has the php_openssl extension. |
| 1262 | - $cacert_url = 'https://curl.haxx.se/ca/cacert.pem'; | |
| 1263 | - $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem'; | |
| 1264 | - $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds. | |
| 1091 | + $cacert_url = 'https://curl.haxx.se/ca/cacert.pem'; | |
| 1092 | + $cacert_path = plugin_dir_path( __FILE__ ) . 'vendor/cacert.pem'; | |
| 1093 | + $time_180_days = 180 * 24 * 60 * 60; // days * hours * minutes * seconds | |
| 1265 | 1094 | $time_180_days_ago = time() - $time_180_days; |
| 1266 | 1095 | if ( |
| 1267 | 1096 | extension_loaded( 'openssl' ) && |
| 1268 | 1097 | ( ! file_exists( $cacert_path ) || filemtime( $cacert_path ) < $time_180_days_ago ) |
| @@ -1278,39 +1107,29 @@ | ||
| 1278 | 1107 | } |
| 1279 | 1108 | $cacert_contents = $response['body']; |
| 1280 | 1109 | |
| 1281 | 1110 | // Write out the updated certs to the plugin directory. |
| 1282 | - // Note: Don't use WP_Filesystem because we are not in an admin context | |
| 1283 | - // and don't want to potentially prompt the end user for credentials. | |
| 1284 | - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_read_file_put_contents | |
| 1285 | 1111 | file_put_contents( $cacert_path, $cacert_contents ); |
| 1286 | 1112 | } |
| 1287 | 1113 | phpCAS::setCasServerCACert( $cacert_path ); |
| 1288 | 1114 | |
| 1289 | - // Set the CAS service URL (including the redirect URL for WordPress when it comes back from CAS). | |
| 1290 | - $cas_service_url = site_url( '/wp-login.php?external=cas' ); | |
| 1291 | - $login_querystring = array(); | |
| 1292 | - if ( isset( $_SERVER['QUERY_STRING'] ) ) { | |
| 1293 | - parse_str( $_SERVER['QUERY_STRING'], $login_querystring ); // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput | |
| 1294 | - } | |
| 1295 | - if ( isset( $login_querystring['redirect_to'] ) ) { | |
| 1296 | - $cas_service_url .= '&redirect_to=' . rawurlencode( $login_querystring['redirect_to'] ); | |
| 1297 | - } | |
| 1298 | - phpCAS::setFixedServiceURL( $cas_service_url ); | |
| 1299 | - | |
| 1300 | - // Authenticate against CAS. | |
| 1115 | + // Authenticate against CAS | |
| 1301 | 1116 | try { |
| 1302 | 1117 | phpCAS::forceAuthentication(); |
| 1303 | 1118 | } catch ( CAS_AuthenticationException $e ) { |
| 1304 | 1119 | // CAS server threw an error in isAuthenticated(), potentially because |
| 1305 | 1120 | // the cached ticket is outdated. Try renewing the authentication. |
| 1306 | - error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) ); // phpcs:ignore | |
| 1307 | - error_log( print_r( $e, true ) ); // phpcs:ignore | |
| 1121 | + try { | |
| 1122 | + phpCAS::renewAuthentication(); | |
| 1123 | + } catch ( CAS_AuthenticationException $e ) { | |
| 1124 | + error_log( __( 'CAS server returned an Authentication Exception. Details:', 'authorizer' ) ); | |
| 1125 | + error_log( print_r( $e, true ) ); | |
| 1308 | 1126 | |
| 1309 | - // CAS server is throwing errors on this login, so try logging the | |
| 1310 | - // user out of CAS and redirecting them to the login page. | |
| 1311 | - phpCAS::logoutWithRedirectService( wp_login_url() ); | |
| 1312 | - die(); | |
| 1127 | + // CAS server is throwing errors on this login, so try logging the | |
| 1128 | + // user out of CAS and redirecting them to the login page. | |
| 1129 | + phpCAS::logoutWithRedirectService( wp_login_url() ); | |
| 1130 | + die(); | |
| 1131 | + } | |
| 1313 | 1132 | } |
| 1314 | 1133 | |
| 1315 | 1134 | // Get username (as specified by the CAS server). |
| 1316 | 1135 | $username = phpCAS::getUser(); |
| @@ -1320,10 +1139,10 @@ | ||
| 1320 | 1139 | if ( ! filter_var( $externally_authenticated_email, FILTER_VALIDATE_EMAIL ) ) { |
| 1321 | 1140 | // If we can't get the user's email address from a CAS attribute, |
| 1322 | 1141 | // try to guess the domain from the CAS server hostname. This will only |
| 1323 | 1142 | // be used if we can't discover the email address from CAS attributes. |
| 1324 | - $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : ''; | |
| 1325 | - $externally_authenticated_email = $this->lowercase( $username ) . '@' . $domain_guess; | |
| 1143 | + $domain_guess = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['cas_host'], $matches ) === 1 ? $matches[0] : ''; | |
| 1144 | + $externally_authenticated_email = strtolower( $username ) . '@' . $domain_guess; | |
| 1326 | 1145 | } |
| 1327 | 1146 | |
| 1328 | 1147 | // Retrieve the user attributes (e.g., email address, first name, last name) from the CAS server. |
| 1329 | 1148 | $cas_attributes = phpCAS::getAttributes(); |
| @@ -1334,45 +1153,37 @@ | ||
| 1334 | 1153 | // email domain is manually entered there (instead of a reference to a |
| 1335 | 1154 | // CAS attribute), and combine that with the username to create the email. |
| 1336 | 1155 | // Otherwise, look up the CAS attribute for email. |
| 1337 | 1156 | if ( substr( $auth_settings['cas_attr_email'], 0, 1 ) === '@' ) { |
| 1338 | - $externally_authenticated_email = $this->lowercase( $username . $auth_settings['cas_attr_email'] ); | |
| 1157 | + $externally_authenticated_email = strtolower( $username . $auth_settings['cas_attr_email'] ); | |
| 1339 | 1158 | } elseif ( |
| 1340 | 1159 | // If a CAS attribute has been specified as containing the email address, use that instead. |
| 1341 | 1160 | // Email attribute can be a string or an array of strings. |
| 1342 | 1161 | array_key_exists( $auth_settings['cas_attr_email'], $cas_attributes ) && ( |
| 1343 | 1162 | ( |
| 1344 | - is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) && | |
| 1345 | - count( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0 | |
| 1163 | + is_array( $cas_attributes[$auth_settings['cas_attr_email']] ) && | |
| 1164 | + count( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0 | |
| 1346 | 1165 | ) || ( |
| 1347 | - is_string( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) && | |
| 1348 | - strlen( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) > 0 | |
| 1166 | + is_string( $cas_attributes[$auth_settings['cas_attr_email']] ) && | |
| 1167 | + strlen( $cas_attributes[$auth_settings['cas_attr_email']] ) > 0 | |
| 1349 | 1168 | ) |
| 1350 | 1169 | ) |
| 1351 | 1170 | ) { |
| 1352 | - // Each of the emails in the array needs to be set to lowercase. | |
| 1353 | - if ( is_array( $cas_attributes[ $auth_settings['cas_attr_email'] ] ) ) { | |
| 1354 | - $externally_authenticated_email = array(); | |
| 1355 | - foreach ( $cas_attributes[ $auth_settings['cas_attr_email'] ] as $external_email ) { | |
| 1356 | - $externally_authenticated_email[] = $this->lowercase( $external_email ); | |
| 1357 | - } | |
| 1358 | - } else { | |
| 1359 | - $externally_authenticated_email = $this->lowercase( $cas_attributes[ $auth_settings['cas_attr_email'] ] ); | |
| 1360 | - } | |
| 1171 | + $externally_authenticated_email = $cas_attributes[$auth_settings['cas_attr_email']]; | |
| 1361 | 1172 | } |
| 1362 | 1173 | } |
| 1363 | 1174 | |
| 1364 | 1175 | // Get user first name and last name. |
| 1365 | - $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_first_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_first_name'] ] : ''; | |
| 1366 | - $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[ $auth_settings['cas_attr_last_name'] ] ) > 0 ? $cas_attributes[ $auth_settings['cas_attr_last_name'] ] : ''; | |
| 1176 | + $first_name = array_key_exists( 'cas_attr_first_name', $auth_settings ) && strlen( $auth_settings['cas_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_first_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_first_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_first_name']] : ''; | |
| 1177 | + $last_name = array_key_exists( 'cas_attr_last_name', $auth_settings ) && strlen( $auth_settings['cas_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['cas_attr_last_name'], $cas_attributes ) && strlen( $cas_attributes[$auth_settings['cas_attr_last_name']] ) > 0 ? $cas_attributes[$auth_settings['cas_attr_last_name']] : ''; | |
| 1367 | 1178 | |
| 1368 | 1179 | return array( |
| 1369 | - 'email' => $externally_authenticated_email, | |
| 1370 | - 'username' => $username, | |
| 1371 | - 'first_name' => $first_name, | |
| 1372 | - 'last_name' => $last_name, | |
| 1180 | + 'email' => $externally_authenticated_email, | |
| 1181 | + 'username' => $username, | |
| 1182 | + 'first_name' => $first_name, | |
| 1183 | + 'last_name' => $last_name, | |
| 1373 | 1184 | 'authenticated_by' => 'cas', |
| 1374 | - 'cas_attributes' => $cas_attributes, | |
| 1185 | + 'cas_attributes' => $cas_attributes, | |
| 1375 | 1186 | ); |
| 1376 | 1187 | } |
| 1377 | 1188 | |
| 1378 | 1189 | |
| @@ -1378,32 +1189,24 @@ | ||
| 1378 | 1189 | |
| 1379 | 1190 | /** |
| 1380 | 1191 | * Validate this user's credentials against LDAP. |
| 1381 | 1192 | * |
| 1382 | - * @param array $auth_settings Plugin settings. | |
| 1383 | - * @param string $username Attempted username from authenticate action. | |
| 1384 | - * @param string $password Attempted password from authenticate action. | |
| 1385 | - * @return array|WP_Error Array containing 'email' and 'authenticated_by' strings | |
| 1386 | - * for the successfully authenticated user, or WP_Error() | |
| 1387 | - * object on failure, or null if skipping LDAP auth and | |
| 1388 | - * falling back to WP auth. | |
| 1193 | + * @param array $auth_settings Plugin settings | |
| 1194 | + * @param string $username Attempted username from authenticate action | |
| 1195 | + * @param string $password Attempted password from authenticate action | |
| 1196 | + * @return [mixed] Array containing 'email' and 'authenticated_by' | |
| 1197 | + * strings for the successfully authenticated | |
| 1198 | + * user, or WP_Error() object on failure, | |
| 1199 | + * or null if skipping LDAP auth and falling back to WP auth. | |
| 1389 | 1200 | */ |
| 1390 | 1201 | private function custom_authenticate_ldap( $auth_settings, $username, $password ) { |
| 1391 | - // Get LDAP search base(s). | |
| 1392 | - $search_bases = explode( "\n", str_replace( "\r", '', trim( $auth_settings['ldap_search_base'] ) ) ); | |
| 1393 | - | |
| 1394 | - // Fail silently (fall back to WordPress authentication) if no search base specified. | |
| 1395 | - if ( count( $search_bases ) < 1 ) { | |
| 1396 | - return null; | |
| 1397 | - } | |
| 1398 | - | |
| 1399 | - // Get the FQDN from the first LDAP search base domain components (dc). For | |
| 1400 | - // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk. | |
| 1401 | - $search_base_components = explode( ',', trim( $search_bases[0] ) ); | |
| 1402 | - $domain = array(); | |
| 1202 | + // Get the FQDN from the LDAP search base domain components (dc). For | |
| 1203 | + // example, ou=people,dc=example,dc=edu,dc=uk would yield user@example.edu.uk | |
| 1204 | + $search_base_components = explode( ',', trim( $auth_settings['ldap_search_base'] ) ); | |
| 1205 | + $domain = array(); | |
| 1403 | 1206 | foreach ( $search_base_components as $search_base_component ) { |
| 1404 | 1207 | $component = explode( '=', $search_base_component ); |
| 1405 | - if ( 2 === count( $component ) && 'dc' === $component[0] ) { | |
| 1208 | + if ( count( $component ) === 2 && $component[0] === 'dc' ) { | |
| 1406 | 1209 | $domain[] = $component[1]; |
| 1407 | 1210 | } |
| 1408 | 1211 | } |
| 1409 | 1212 | $domain = implode( '.', $domain ); |
| @@ -1414,9 +1217,9 @@ | ||
| 1414 | 1217 | if ( empty( $domain ) ) { |
| 1415 | 1218 | $domain = preg_match( '/[^.]*\.[^.]*$/', $auth_settings['ldap_host'], $matches ) === 1 ? $matches[0] : ''; |
| 1416 | 1219 | } |
| 1417 | 1220 | |
| 1418 | - // remove @domain if it exists in the username (i.e., if user entered their email). | |
| 1221 | + // remove @domain if it exists in the username (i.e., if user entered their email) | |
| 1419 | 1222 | $username = str_replace( '@' . $domain, '', $username ); |
| 1420 | 1223 | |
| 1421 | 1224 | // Fail silently (fall back to WordPress authentication) if both username |
| 1422 | 1225 | // and password are empty (this will be the case when visiting wp-login.php |
| @@ -1439,13 +1242,13 @@ | ||
| 1439 | 1242 | return null; |
| 1440 | 1243 | } |
| 1441 | 1244 | |
| 1442 | 1245 | // Authenticate against LDAP using options provided in plugin settings. |
| 1443 | - $result = false; | |
| 1246 | + $result = false; | |
| 1444 | 1247 | $ldap_user_dn = ''; |
| 1445 | - $first_name = ''; | |
| 1446 | - $last_name = ''; | |
| 1447 | - $email = ''; | |
| 1248 | + $first_name = ''; | |
| 1249 | + $last_name = ''; | |
| 1250 | + $email = ''; | |
| 1448 | 1251 | |
| 1449 | 1252 | // Construct LDAP connection parameters. ldap_connect() takes either a |
| 1450 | 1253 | // hostname or a full LDAP URI as its first parameter (works with OpenLDAP |
| 1451 | 1254 | // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is |
| @@ -1450,13 +1253,13 @@ | ||
| 1450 | 1253 | // hostname or a full LDAP URI as its first parameter (works with OpenLDAP |
| 1451 | 1254 | // 2.x.x or later). If it's an LDAP URI, the second parameter, $port, is |
| 1452 | 1255 | // ignored, and port must be specified in the full URI. An LDAP URI is of |
| 1453 | 1256 | // the form ldap://hostname:port or ldaps://hostname:port. |
| 1454 | - $ldap_host = $auth_settings['ldap_host']; | |
| 1455 | - $ldap_port = intval( $auth_settings['ldap_port'] ); | |
| 1456 | - $parsed_host = wp_parse_url( $ldap_host ); | |
| 1257 | + $ldap_host = $auth_settings['ldap_host']; | |
| 1258 | + $ldap_port = intval( $auth_settings['ldap_port'] ); | |
| 1259 | + $parsed_host = parse_url( $ldap_host ); | |
| 1457 | 1260 | // Fail (fall back to WordPress auth) if invalid host is specified. |
| 1458 | - if ( false === $parsed_host ) { | |
| 1261 | + if ( $parsed_host === false ) { | |
| 1459 | 1262 | return null; |
| 1460 | 1263 | } |
| 1461 | 1264 | // If a scheme is in the LDAP host, use full LDAP URI instead of just hostname. |
| 1462 | 1265 | if ( array_key_exists( 'scheme', $parsed_host ) ) { |
| @@ -1469,24 +1272,24 @@ | ||
| 1469 | 1272 | |
| 1470 | 1273 | // Establish LDAP connection. |
| 1471 | 1274 | $ldap = ldap_connect( $ldap_host, $ldap_port ); |
| 1472 | 1275 | ldap_set_option( $ldap, LDAP_OPT_PROTOCOL_VERSION, 3 ); |
| 1473 | - if ( 1 === intval( $auth_settings['ldap_tls'] ) ) { | |
| 1474 | - if ( ! ldap_start_tls( $ldap ) ) { | |
| 1276 | + if ( $auth_settings['ldap_tls'] == 1 ) { | |
| 1277 | + if( ! ldap_start_tls( $ldap ) ) { | |
| 1475 | 1278 | return null; |
| 1476 | 1279 | } |
| 1477 | 1280 | } |
| 1478 | 1281 | |
| 1479 | 1282 | // Set bind credentials; attempt an anonymous bind if not provided. |
| 1480 | - $bind_rdn = null; | |
| 1481 | - $bind_password = null; | |
| 1283 | + $bind_rdn = NULL; | |
| 1284 | + $bind_password = NULL; | |
| 1482 | 1285 | if ( strlen( $auth_settings['ldap_user'] ) > 0 ) { |
| 1483 | - $bind_rdn = $auth_settings['ldap_user']; | |
| 1484 | - $bind_password = $this->decrypt( $auth_settings['ldap_password'] ); | |
| 1286 | + $bind_rdn = $auth_settings['ldap_user']; | |
| 1287 | + $bind_password = $this->decrypt( base64_decode( $auth_settings['ldap_password'] ) ); | |
| 1485 | 1288 | } |
| 1486 | 1289 | |
| 1487 | 1290 | // Attempt LDAP bind. |
| 1488 | - $result = @ldap_bind( $ldap, $bind_rdn, stripslashes( $bind_password ) ); // phpcs:ignore | |
| 1291 | + $result = @ldap_bind( $ldap, $bind_rdn, $bind_password ); | |
| 1489 | 1292 | if ( ! $result ) { |
| 1490 | 1293 | // Can't connect to LDAP, so fall back to WordPress authentication. |
| 1491 | 1294 | return null; |
| 1492 | 1295 | } |
| @@ -1500,40 +1303,18 @@ | ||
| 1500 | 1303 | if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 ) { |
| 1501 | 1304 | array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_last_name'] ); |
| 1502 | 1305 | } |
| 1503 | 1306 | if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 && substr( $auth_settings['ldap_attr_email'], 0, 1 ) !== '@' ) { |
| 1504 | - array_push( $ldap_attributes_to_retrieve, $this->lowercase( $auth_settings['ldap_attr_email'] ) ); | |
| 1307 | + array_push( $ldap_attributes_to_retrieve, $auth_settings['ldap_attr_email'] ); | |
| 1505 | 1308 | } |
| 1309 | + $ldap_search = ldap_search( | |
| 1310 | + $ldap, | |
| 1311 | + $auth_settings['ldap_search_base'], | |
| 1312 | + "(" . $auth_settings['ldap_uid'] . "=" . $username . ")", | |
| 1313 | + $ldap_attributes_to_retrieve | |
| 1314 | + ); | |
| 1315 | + $ldap_entries = ldap_get_entries( $ldap, $ldap_search ); | |
| 1506 | 1316 | |
| 1507 | - // Create default LDAP search filter (uid=$username). | |
| 1508 | - $search_filter = '(' . $auth_settings['ldap_uid'] . '=' . $username . ')'; | |
| 1509 | - | |
| 1510 | - /** | |
| 1511 | - * Filter LDAP search filter. | |
| 1512 | - * | |
| 1513 | - * Allows for custom LDAP authentication rules (e.g., restricting login | |
| 1514 | - * access to users in multiple groups, or having certain attributes). | |
| 1515 | - * | |
| 1516 | - * @param string $search_filter The filter to pass to ldap_search(). | |
| 1517 | - * @param string $ldap_uid The attribute to compare username against (from Authorizer Settings). | |
| 1518 | - * @param string $username The username attempting to log in. | |
| 1519 | - */ | |
| 1520 | - $search_filter = apply_filters( 'authorizer_ldap_search_filter', $search_filter, $auth_settings['ldap_uid'], $username ); | |
| 1521 | - | |
| 1522 | - // Multiple search bases can be provided, so iterate through them until a match is found. | |
| 1523 | - foreach ( $search_bases as $search_base ) { | |
| 1524 | - $ldap_search = ldap_search( | |
| 1525 | - $ldap, | |
| 1526 | - $search_base, | |
| 1527 | - $search_filter, | |
| 1528 | - $ldap_attributes_to_retrieve | |
| 1529 | - ); | |
| 1530 | - $ldap_entries = ldap_get_entries( $ldap, $ldap_search ); | |
| 1531 | - if ( $ldap_entries['count'] > 0 ) { | |
| 1532 | - break; | |
| 1533 | - } | |
| 1534 | - } | |
| 1535 | - | |
| 1536 | 1317 | // If we didn't find any users in ldap, fall back to WordPress authentication. |
| 1537 | 1318 | if ( $ldap_entries['count'] < 1 ) { |
| 1538 | 1319 | return null; |
| 1539 | 1320 | } |
| @@ -1539,35 +1320,32 @@ | ||
| 1539 | 1320 | } |
| 1540 | 1321 | |
| 1541 | 1322 | // Get the bind dn and first/last names; if there are multiple results returned, just get the last one. |
| 1542 | 1323 | for ( $i = 0; $i < $ldap_entries['count']; $i++ ) { |
| 1543 | - $ldap_user_dn = $ldap_entries[ $i ]['dn']; | |
| 1324 | + $ldap_user_dn = $ldap_entries[$i]['dn']; | |
| 1544 | 1325 | |
| 1545 | 1326 | // Get user first name and last name. |
| 1546 | - $ldap_attr_first_name = array_key_exists( 'ldap_attr_first_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_first_name'] ) : ''; | |
| 1547 | - if ( strlen( $ldap_attr_first_name ) > 0 && array_key_exists( $ldap_attr_first_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_first_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_first_name ][0] ) > 0 ) { | |
| 1548 | - $first_name = $ldap_entries[ $i ][ $ldap_attr_first_name ][0]; | |
| 1327 | + if ( array_key_exists( 'ldap_attr_first_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_first_name'] ) > 0 && array_key_exists( $auth_settings['ldap_attr_first_name'], $ldap_entries[$i] ) && $ldap_entries[$i][$auth_settings['ldap_attr_first_name']]['count'] > 0 && strlen( $ldap_entries[$i][$auth_settings['ldap_attr_first_name']][0] ) > 0 ) { | |
| 1328 | + $first_name = $ldap_entries[$i][$auth_settings['ldap_attr_first_name']][0]; | |
| 1549 | 1329 | } |
| 1550 | - $ldap_attr_last_name = array_key_exists( 'ldap_attr_last_name', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_last_name'] ) : ''; | |
| 1551 | - if ( strlen( $ldap_attr_last_name ) > 0 && array_key_exists( $ldap_attr_last_name, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_last_name ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_last_name ][0] ) > 0 ) { | |
| 1552 | - $last_name = $ldap_entries[ $i ][ $ldap_attr_last_name ][0]; | |
| 1330 | + if ( array_key_exists( 'ldap_attr_last_name', $auth_settings ) && strlen( $auth_settings['ldap_attr_last_name'] ) > 0 && array_key_exists( $auth_settings['ldap_attr_last_name'], $ldap_entries[$i] ) && $ldap_entries[$i][$auth_settings['ldap_attr_last_name']]['count'] > 0 && strlen( $ldap_entries[$i][$auth_settings['ldap_attr_last_name']][0] ) > 0 ) { | |
| 1331 | + $last_name = $ldap_entries[$i][$auth_settings['ldap_attr_last_name']][0]; | |
| 1553 | 1332 | } |
| 1554 | 1333 | // Get user email if it is specified in another field. |
| 1555 | - $ldap_attr_email = array_key_exists( 'ldap_attr_email', $auth_settings ) ? $this->lowercase( $auth_settings['ldap_attr_email'] ) : ''; | |
| 1556 | - if ( strlen( $ldap_attr_email ) > 0 ) { | |
| 1334 | + if ( array_key_exists( 'ldap_attr_email', $auth_settings ) && strlen( $auth_settings['ldap_attr_email'] ) > 0 ) { | |
| 1557 | 1335 | // If the email attribute starts with an at symbol (@), assume that the |
| 1558 | 1336 | // email domain is manually entered there (instead of a reference to an |
| 1559 | 1337 | // LDAP attribute), and combine that with the username to create the email. |
| 1560 | 1338 | // Otherwise, look up the LDAP attribute for email. |
| 1561 | - if ( substr( $ldap_attr_email, 0, 1 ) === '@' ) { | |
| 1562 | - $email = $this->lowercase( $username . $ldap_attr_email ); | |
| 1563 | - } elseif ( array_key_exists( $ldap_attr_email, $ldap_entries[ $i ] ) && $ldap_entries[ $i ][ $ldap_attr_email ]['count'] > 0 && strlen( $ldap_entries[ $i ][ $ldap_attr_email ][0] ) > 0 ) { | |
| 1564 | - $email = $this->lowercase( $ldap_entries[ $i ][ $ldap_attr_email ][0] ); | |
| 1339 | + if ( substr( $auth_settings['ldap_attr_email'], 0, 1 ) === '@' ) { | |
| 1340 | + $email = strtolower( $username . $auth_settings['ldap_attr_email'] ); | |
| 1341 | + } elseif ( array_key_exists( $auth_settings['ldap_attr_email'], $ldap_entries[$i] ) && $ldap_entries[$i][$auth_settings['ldap_attr_email']]['count'] > 0 && strlen( $ldap_entries[$i][$auth_settings['ldap_attr_email']][0] ) > 0 ) { | |
| 1342 | + $email = strtolower( $ldap_entries[$i][$auth_settings['ldap_attr_email']][0] ); | |
| 1565 | 1343 | } |
| 1566 | 1344 | } |
| 1567 | 1345 | } |
| 1568 | 1346 | |
| 1569 | - $result = @ldap_bind( $ldap, $ldap_user_dn, stripslashes( $password ) ); // phpcs:ignore | |
| 1347 | + $result = @ldap_bind( $ldap, $ldap_user_dn, $password ); | |
| 1570 | 1348 | if ( ! $result ) { |
| 1571 | 1349 | // We have a real ldap user, but an invalid password. Pass |
| 1572 | 1350 | // through to wp authentication after failing LDAP (since |
| 1573 | 1351 | // this could be a local account that happens to be the |
| @@ -1575,22 +1353,22 @@ | ||
| 1575 | 1353 | return null; |
| 1576 | 1354 | } |
| 1577 | 1355 | |
| 1578 | 1356 | // User successfully authenticated against LDAP, so set the relevant variables. |
| 1579 | - $externally_authenticated_email = $this->lowercase( $username . '@' . $domain ); | |
| 1357 | + $externally_authenticated_email = $username . '@' . $domain; | |
| 1580 | 1358 | |
| 1581 | 1359 | // If an LDAP attribute has been specified as containing the email address, use that instead. |
| 1582 | 1360 | if ( strlen( $email ) > 0 ) { |
| 1583 | - $externally_authenticated_email = $this->lowercase( $email ); | |
| 1361 | + $externally_authenticated_email = $email; | |
| 1584 | 1362 | } |
| 1585 | 1363 | |
| 1586 | 1364 | return array( |
| 1587 | - 'email' => $externally_authenticated_email, | |
| 1588 | - 'username' => $username, | |
| 1589 | - 'first_name' => $first_name, | |
| 1590 | - 'last_name' => $last_name, | |
| 1365 | + 'email' => $externally_authenticated_email, | |
| 1366 | + 'username' => $username, | |
| 1367 | + 'first_name' => $first_name, | |
| 1368 | + 'last_name' => $last_name, | |
| 1591 | 1369 | 'authenticated_by' => 'ldap', |
| 1592 | - 'ldap_attributes' => $ldap_entries, | |
| 1370 | + 'ldap_attributes' => $ldap_entries, | |
| 1593 | 1371 | ); |
| 1594 | 1372 | } |
| 1595 | 1373 | |
| 1596 | 1374 | |
| @@ -1596,20 +1374,18 @@ | ||
| 1596 | 1374 | |
| 1597 | 1375 | /** |
| 1598 | 1376 | * Log out of the attached external service. |
| 1599 | 1377 | * |
| 1600 | - * Action: wp_logout | |
| 1601 | - * | |
| 1602 | 1378 | * @return void |
| 1603 | 1379 | */ |
| 1604 | 1380 | public function custom_logout() { |
| 1605 | 1381 | // Grab plugin settings. |
| 1606 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 1382 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 1607 | 1383 | |
| 1608 | 1384 | // Reset option containing old error messages. |
| 1609 | 1385 | delete_option( 'auth_settings_advanced_login_error' ); |
| 1610 | 1386 | |
| 1611 | - if ( session_id() === '' ) { | |
| 1387 | + if ( session_id() == '' ) { | |
| 1612 | 1388 | session_start(); |
| 1613 | 1389 | } |
| 1614 | 1390 | |
| 1615 | 1391 | $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true ); |
| @@ -1614,53 +1390,38 @@ | ||
| 1614 | 1390 | |
| 1615 | 1391 | $current_user_authenticated_by = get_user_meta( get_current_user_id(), 'authenticated_by', true ); |
| 1616 | 1392 | |
| 1617 | 1393 | // If logged in to CAS, Log out of CAS. |
| 1618 | - if ( 'cas' === $current_user_authenticated_by && '1' === $auth_settings['cas'] ) { | |
| 1394 | + if ( $current_user_authenticated_by === 'cas' && $auth_settings['cas'] === '1' ) { | |
| 1619 | 1395 | if ( ! array_key_exists( 'PHPCAS_CLIENT', $GLOBALS ) || ! array_key_exists( 'phpCAS', $_SESSION ) ) { |
| 1620 | 1396 | |
| 1621 | - /** | |
| 1622 | - * Get the CAS server version (default to SAML_VERSION_1_1). | |
| 1623 | - * | |
| 1624 | - * @see: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html | |
| 1625 | - */ | |
| 1397 | + // Get the CAS server version (default to SAML_VERSION_1_1). | |
| 1398 | + // See: https://developer.jasig.org/cas-clients/php/1.3.4/docs/api/group__public.html | |
| 1626 | 1399 | $cas_version = SAML_VERSION_1_1; |
| 1627 | - if ( 'CAS_VERSION_3_0' === $auth_settings['cas_version'] ) { | |
| 1400 | + if ( $auth_settings['cas_version'] === 'CAS_VERSION_3_0' ) { | |
| 1628 | 1401 | $cas_version = CAS_VERSION_3_0; |
| 1629 | - } elseif ( 'CAS_VERSION_2_0' === $auth_settings['cas_version'] ) { | |
| 1402 | + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_2_0' ) { | |
| 1630 | 1403 | $cas_version = CAS_VERSION_2_0; |
| 1631 | - } elseif ( 'CAS_VERSION_1_0' === $auth_settings['cas_version'] ) { | |
| 1404 | + } elseif ( $auth_settings['cas_version'] === 'CAS_VERSION_1_0' ) { | |
| 1632 | 1405 | $cas_version = CAS_VERSION_1_0; |
| 1633 | 1406 | } |
| 1634 | 1407 | |
| 1635 | 1408 | // Set the CAS client configuration if it hasn't been set already. |
| 1636 | 1409 | phpCAS::client( $cas_version, $auth_settings['cas_host'], intval( $auth_settings['cas_port'] ), $auth_settings['cas_path'] ); |
| 1637 | - // Allow redirects at the CAS server endpoint (e.g., allow connections | |
| 1638 | - // at an old CAS URL that redirects to a newer CAS URL). | |
| 1639 | - phpCAS::setExtraCurlOption( CURLOPT_FOLLOWLOCATION, true ); | |
| 1640 | 1410 | // Restrict logout request origin to the CAS server only (prevent DDOS). |
| 1641 | 1411 | phpCAS::handleLogoutRequests( true, array( $auth_settings['cas_host'] ) ); |
| 1642 | 1412 | } |
| 1643 | - if ( phpCAS::isAuthenticated() || phpCAS::isInitialized() ) { | |
| 1644 | - // Redirect to home page, or specified page if it's been provided. | |
| 1645 | - $redirect_to = site_url( '/' ); | |
| 1646 | - if ( ! empty( $_REQUEST['redirect_to'] ) && isset( $_REQUEST['_wpnonce'] ) && wp_verify_nonce( sanitize_key( $_REQUEST['_wpnonce'] ), 'log-out' ) ) { | |
| 1647 | - $redirect_to = esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ); | |
| 1648 | - } | |
| 1649 | - | |
| 1650 | - phpCAS::logoutWithRedirectService( $redirect_to ); | |
| 1413 | + if ( phpCAS::isAuthenticated() ) { | |
| 1414 | + phpCAS::logoutWithRedirectService( get_option( 'siteurl' ) ); | |
| 1651 | 1415 | } |
| 1652 | 1416 | } |
| 1653 | 1417 | |
| 1654 | 1418 | // If session token set, log out of Google. |
| 1655 | - if ( 'google' === $current_user_authenticated_by || array_key_exists( 'token', $_SESSION ) ) { | |
| 1419 | + if ( $current_user_authenticated_by === 'google' || array_key_exists( 'token', $_SESSION ) ) { | |
| 1656 | 1420 | $token = json_decode( $_SESSION['token'] )->access_token; |
| 1657 | 1421 | |
| 1658 | - /** | |
| 1659 | - * Add Google API PHP Client. | |
| 1660 | - * | |
| 1661 | - * @see https://github.com/google/google-api-php-client branch:v1-master | |
| 1662 | - */ | |
| 1422 | + // Add Google API PHP Client. | |
| 1423 | + // @see https://github.com/google/google-api-php-client branch:v1-master | |
| 1663 | 1424 | require_once dirname( __FILE__ ) . '/vendor/google-api-php-client/src/Google/autoload.php'; |
| 1664 | 1425 | |
| 1665 | 1426 | // Build the Google Client. |
| 1666 | 1427 | $client = new Google_Client(); |
| @@ -1668,9 +1429,14 @@ | ||
| 1668 | 1429 | $client->setClientId( $auth_settings['google_clientid'] ); |
| 1669 | 1430 | $client->setClientSecret( $auth_settings['google_clientsecret'] ); |
| 1670 | 1431 | $client->setRedirectUri( 'postmessage' ); |
| 1671 | 1432 | |
| 1672 | - // Revoke the token. | |
| 1433 | + // If the hosted domain parameter is set, restrict logins to that domain. | |
| 1434 | + if ( array_key_exists( 'google_hosteddomain', $auth_settings ) && strlen( $auth_settings['google_hosteddomain'] ) > 0 ) { | |
| 1435 | + $client->setHostedDomain( $auth_settings['google_hosteddomain'] ); | |
| 1436 | + } | |
| 1437 | + | |
| 1438 | + // Revoke the token | |
| 1673 | 1439 | $client->revokeToken( $token ); |
| 1674 | 1440 | |
| 1675 | 1441 | // Remove the credentials from the user's session. |
| 1676 | 1442 | unset( $_SESSION['token'] ); |
| @@ -1689,37 +1455,36 @@ | ||
| 1689 | 1455 | |
| 1690 | 1456 | |
| 1691 | 1457 | /** |
| 1692 | 1458 | * Restrict access to WordPress site based on settings (everyone, logged_in_users). |
| 1459 | + * Hook: parse_request http://codex.wordpress.org/Plugin_API/Action_Reference/parse_request | |
| 1693 | 1460 | * |
| 1694 | - * Action: parse_request | |
| 1461 | + * @param array $wp WordPress object. | |
| 1695 | 1462 | * |
| 1696 | - * @param array $wp WordPress object. | |
| 1697 | - * @return WP|void WP object when passing through to WordPress authentication, or void. | |
| 1463 | + * @return void | |
| 1698 | 1464 | */ |
| 1699 | 1465 | public function restrict_access( $wp ) { |
| 1700 | 1466 | // Grab plugin settings. |
| 1701 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 1467 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 1702 | 1468 | |
| 1703 | 1469 | // Grab current user. |
| 1704 | 1470 | $current_user = wp_get_current_user(); |
| 1705 | 1471 | |
| 1706 | 1472 | $has_access = ( |
| 1707 | - // Always allow access if WordPress is installing. | |
| 1708 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 1473 | + // Always allow access if WordPress is installing | |
| 1709 | 1474 | ( defined( 'WP_INSTALLING' ) && isset( $_GET['key'] ) ) || |
| 1710 | - // Always allow access to admins. | |
| 1475 | + // Always allow access to admins | |
| 1711 | 1476 | ( current_user_can( 'create_users' ) ) || |
| 1712 | - // Allow access if option is set to 'everyone'. | |
| 1713 | - ( 'everyone' === $auth_settings['access_who_can_view'] ) || | |
| 1714 | - // Allow access to approved external users and logged in users if option is set to 'logged_in_users'. | |
| 1715 | - ( 'logged_in_users' === $auth_settings['access_who_can_view'] && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) || | |
| 1716 | - // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API. | |
| 1717 | - ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_oauth1=' ) === 0 ) || | |
| 1718 | - // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them. | |
| 1719 | - ( property_exists( $wp, 'matched_query' ) && 0 === stripos( $wp->matched_query, 'rest_route=' ) && isset( $_SERVER['REQUEST_METHOD'] ) && 'GET' !== $_SERVER['REQUEST_METHOD'] ) || | |
| 1720 | - // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this. | |
| 1721 | - ( property_exists( $wp, 'matched_query' ) && 'rest_route=/' === $wp->matched_query ) | |
| 1477 | + // Allow access if option is set to 'everyone' | |
| 1478 | + ( $auth_settings['access_who_can_view'] == 'everyone' ) || | |
| 1479 | + // Allow access to approved external users and logged in users if option is set to 'logged_in_users' | |
| 1480 | + ( $auth_settings['access_who_can_view'] == 'logged_in_users' && $this->is_user_logged_in_and_blog_user() && $this->is_email_in_list( $current_user->user_email, 'approved' ) ) || | |
| 1481 | + // Allow access for requests to /wp-json/oauth1 so oauth clients can authenticate to use the REST API | |
| 1482 | + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_oauth1=" ) === 0 ) || | |
| 1483 | + // Allow access for non-GET requests to /wp-json/*, since REST API authentication already covers them | |
| 1484 | + ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] !== 'GET' ) || | |
| 1485 | + // Allow access for GET requests to /wp-json/ (root), since REST API discovery calls rely on this | |
| 1486 | + ( property_exists( $wp, 'matched_query' ) && $wp->matched_query === 'rest_route=/' ) | |
| 1722 | 1487 | // Note that GET requests to a rest endpoint will be restricted by authorizer. In that case, error messages will be returned as JSON. |
| 1723 | 1488 | ); |
| 1724 | 1489 | |
| 1725 | 1490 | /** |
| @@ -1741,9 +1506,9 @@ | ||
| 1741 | 1506 | * } |
| 1742 | 1507 | * add_filter( 'authorizer_has_access', 'my_rsa_feed_access_override' ); |
| 1743 | 1508 | */ |
| 1744 | 1509 | if ( apply_filters( 'authorizer_has_access', $has_access, $wp ) === true ) { |
| 1745 | - // Turn off the public notice about browsing anonymously. | |
| 1510 | + // Turn off the public notice about browsing anonymously | |
| 1746 | 1511 | update_option( 'auth_settings_advanced_public_notice', false ); |
| 1747 | 1512 | |
| 1748 | 1513 | // We've determined that the current user has access, so simply return to grant access. |
| 1749 | 1514 | return $wp; |
| @@ -1749,13 +1514,13 @@ | ||
| 1749 | 1514 | return $wp; |
| 1750 | 1515 | } |
| 1751 | 1516 | |
| 1752 | 1517 | // Allow HEAD requests to the root (usually discovery from a REST client). |
| 1753 | - if ( 'HEAD' === $_SERVER['REQUEST_METHOD'] && empty( $wp->request ) && empty( $wp->matched_query ) ) { | |
| 1518 | + if ( $_SERVER['REQUEST_METHOD'] === 'HEAD' && empty( $wp->request ) && empty( $wp->matched_query ) ) { | |
| 1754 | 1519 | return $wp; |
| 1755 | 1520 | } |
| 1756 | 1521 | |
| 1757 | - /* We've determined that the current user doesn't have access, so we deal with them now. */ | |
| 1522 | + // We've determined that the current user doesn't have access, so we deal with them now. | |
| 1758 | 1523 | |
| 1759 | 1524 | // Fringe case: In a multisite, a user of a different blog can successfully |
| 1760 | 1525 | // log in, but they aren't on the 'approved' whitelist for this blog. |
| 1761 | 1526 | // If that's the case, add them to the pending list for this blog. |
| @@ -1766,19 +1531,21 @@ | ||
| 1766 | 1531 | $result = $this->check_user_access( $current_user, array( $current_user->user_email ) ); |
| 1767 | 1532 | } |
| 1768 | 1533 | |
| 1769 | 1534 | // Check to see if the requested page is public. If so, show it. |
| 1770 | - if ( empty( $wp->request ) ) { | |
| 1771 | - $current_page_id = 'home'; | |
| 1772 | - } else { | |
| 1773 | - $request_query = isset( $wp->query_vars ) ? new WP_Query( $wp->query_vars ) : null; | |
| 1774 | - $current_page_id = isset( $request_query->post_count ) && $request_query->post_count > 0 ? $request_query->post->ID : ''; | |
| 1535 | + $current_page_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'name', $wp->query_vars ) && strlen( $wp->query_vars['name'] ) > 0 ? $wp->query_vars['name'] : ''; | |
| 1536 | + if ( ! $current_page_name ) { | |
| 1537 | + // Different WordPress versions store the page slug in different places; look for it elsewhere. | |
| 1538 | + if ( property_exists( $wp, 'query_vars' ) && array_key_exists( 'pagename', $wp->query_vars ) && strlen( $wp->query_vars['pagename'] ) > 0 ) { | |
| 1539 | + $current_page_name = $wp->query_vars['pagename']; | |
| 1540 | + } | |
| 1775 | 1541 | } |
| 1542 | + $current_page_id = empty( $wp->request ) ? 'home' : $this->get_id_from_pagename( $current_page_name ); | |
| 1776 | 1543 | if ( ! array_key_exists( 'access_public_pages', $auth_settings ) || ! is_array( $auth_settings['access_public_pages'] ) ) { |
| 1777 | 1544 | $auth_settings['access_public_pages'] = array(); |
| 1778 | 1545 | } |
| 1779 | - if ( in_array( strval( $current_page_id ), $auth_settings['access_public_pages'], true ) ) { | |
| 1780 | - if ( 'no_warning' === $auth_settings['access_public_warning'] ) { | |
| 1546 | + if ( in_array( $current_page_id, $auth_settings['access_public_pages'] ) ) { | |
| 1547 | + if ( $auth_settings['access_public_warning'] === 'no_warning' ) { | |
| 1781 | 1548 | update_option( 'auth_settings_advanced_public_notice', false ); |
| 1782 | 1549 | } else { |
| 1783 | 1550 | update_option( 'auth_settings_advanced_public_notice', true ); |
| 1784 | 1551 | } |
| @@ -1786,11 +1553,11 @@ | ||
| 1786 | 1553 | } |
| 1787 | 1554 | |
| 1788 | 1555 | // Check to see if any category assigned to the requested page is public. If so, show it. |
| 1789 | 1556 | $current_page_categories = wp_get_post_categories( $current_page_id, array( 'fields' => 'slugs' ) ); |
| 1790 | - foreach ( $current_page_categories as $current_page_category ) { | |
| 1791 | - if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'], true ) ) { | |
| 1792 | - if ( 'no_warning' === $auth_settings['access_public_warning'] ) { | |
| 1557 | + foreach( $current_page_categories as $current_page_category ) { | |
| 1558 | + if ( in_array( 'cat_' . $current_page_category, $auth_settings['access_public_pages'] ) ) { | |
| 1559 | + if ( $auth_settings['access_public_warning'] === 'no_warning' ) { | |
| 1793 | 1560 | update_option( 'auth_settings_advanced_public_notice', false ); |
| 1794 | 1561 | } else { |
| 1795 | 1562 | update_option( 'auth_settings_advanced_public_notice', true ); |
| 1796 | 1563 | } |
| @@ -1798,11 +1565,11 @@ | ||
| 1798 | 1565 | } |
| 1799 | 1566 | } |
| 1800 | 1567 | |
| 1801 | 1568 | // Check to see if this page can't be found. If so, allow showing the 404 page. |
| 1802 | - if ( strlen( $current_page_id ) < 1 ) { | |
| 1803 | - if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'], true ) ) { | |
| 1804 | - if ( 'no_warning' === $auth_settings['access_public_warning'] ) { | |
| 1569 | + if ( strlen( $current_page_name ) > 0 && strlen( $current_page_id ) < 1 ) { | |
| 1570 | + if ( in_array( 'auth_public_404', $auth_settings['access_public_pages'] ) ) { | |
| 1571 | + if ( $auth_settings['access_public_warning'] === 'no_warning' ) { | |
| 1805 | 1572 | update_option( 'auth_settings_advanced_public_notice', false ); |
| 1806 | 1573 | } else { |
| 1807 | 1574 | update_option( 'auth_settings_advanced_public_notice', true ); |
| 1808 | 1575 | } |
| @@ -1807,39 +1574,24 @@ | ||
| 1807 | 1574 | update_option( 'auth_settings_advanced_public_notice', true ); |
| 1808 | 1575 | } |
| 1809 | 1576 | return $wp; |
| 1810 | 1577 | } |
| 1811 | - } | |
| 1812 | 1578 | |
| 1813 | - // Check to see if the requested category is public. If so, show it. | |
| 1814 | - $current_category_name = property_exists( $wp, 'query_vars' ) && array_key_exists( 'category_name', $wp->query_vars ) && strlen( $wp->query_vars['category_name'] ) > 0 ? $wp->query_vars['category_name'] : ''; | |
| 1815 | - if ( $current_category_name ) { | |
| 1816 | - $current_category_name = end( explode( '/', $current_category_name ) ); | |
| 1817 | - if ( in_array( 'cat_' . $current_category_name, $auth_settings['access_public_pages'], true ) ) { | |
| 1818 | - if ( 'no_warning' === $auth_settings['access_public_warning'] ) { | |
| 1819 | - update_option( 'auth_settings_advanced_public_notice', false ); | |
| 1820 | - } else { | |
| 1821 | - update_option( 'auth_settings_advanced_public_notice', true ); | |
| 1822 | - } | |
| 1823 | - return $wp; | |
| 1824 | - } | |
| 1825 | 1579 | } |
| 1826 | 1580 | |
| 1827 | 1581 | // User is denied access, so show them the error message. Render as JSON |
| 1828 | 1582 | // if this is a REST API call; otherwise, show the error message via |
| 1829 | 1583 | // wp_die() (rendered html), or redirect to the login URL. |
| 1830 | - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url(); | |
| 1831 | - if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, 'rest_route=' ) === 0 && 'GET' === $_SERVER['REQUEST_METHOD'] ) { | |
| 1832 | - wp_send_json( | |
| 1833 | - array( | |
| 1834 | - 'code' => 'rest_cannot_view', | |
| 1835 | - 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ), | |
| 1836 | - 'data' => array( | |
| 1837 | - 'status' => 401, | |
| 1838 | - ), | |
| 1839 | - ) | |
| 1840 | - ); | |
| 1841 | - } elseif ( 'message' === $auth_settings['access_redirect'] ) { | |
| 1584 | + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI']; | |
| 1585 | + if ( property_exists( $wp, 'matched_query' ) && stripos( $wp->matched_query, "rest_route=" ) === 0 && $_SERVER['REQUEST_METHOD'] === 'GET' ) { | |
| 1586 | + wp_send_json( array( | |
| 1587 | + 'code' => 'rest_cannot_view', | |
| 1588 | + 'message' => strip_tags( $auth_settings['access_redirect_to_message'] ), | |
| 1589 | + 'data' => array( | |
| 1590 | + 'status' => 401, | |
| 1591 | + ), | |
| 1592 | + )); | |
| 1593 | + } elseif ( $auth_settings['access_redirect'] === 'message' ) { | |
| 1842 | 1594 | $page_title = sprintf( |
| 1843 | 1595 | /* TRANSLATORS: %s: Name of blog */ |
| 1844 | 1596 | __( '%s - Access Restricted', 'authorizer' ), |
| 1845 | 1597 | get_bloginfo( 'name' ) |
| @@ -1850,65 +1602,20 @@ | ||
| 1850 | 1602 | '<p style="text-align: center;margin-bottom: -15px;">' . |
| 1851 | 1603 | '<a class="button" href="' . wp_login_url( $current_path ) . '">' . |
| 1852 | 1604 | __( 'Log In', 'authorizer' ) . |
| 1853 | 1605 | '</a></p>'; |
| 1854 | - wp_die( wp_kses( $error_message, $this->allowed_html ), esc_html( $page_title ) ); | |
| 1855 | - } else { | |
| 1606 | + wp_die( $error_message, $page_title ); | |
| 1607 | + } else { // if ( $auth_settings['access_redirect'] === 'login' ) { | |
| 1856 | 1608 | wp_redirect( wp_login_url( $current_path ), 302 ); |
| 1857 | 1609 | exit; |
| 1858 | 1610 | } |
| 1859 | 1611 | |
| 1860 | - // Sanity check: we should never get here. | |
| 1612 | + // Sanity check: we should never get here | |
| 1861 | 1613 | wp_die( '<p>Access denied.</p>', 'Site Access Restricted' ); |
| 1862 | 1614 | } |
| 1863 | 1615 | |
| 1864 | 1616 | |
| 1865 | - /** | |
| 1866 | - * On an admin page load, check for edge case (network-approved user who has | |
| 1867 | - * not yet been added to this particular blog in a multisite). Note: we do | |
| 1868 | - * this because check_user_access() runs on the parse_request hook, which | |
| 1869 | - * does not fire on wp-admin pages. | |
| 1870 | - * | |
| 1871 | - * Action: init | |
| 1872 | - * | |
| 1873 | - * @return void | |
| 1874 | - */ | |
| 1875 | - public function init__maybe_add_network_approved_user() { | |
| 1876 | - global $current_user; | |
| 1877 | 1617 | |
| 1878 | - // If this is a multisite install and we have a logged in user that's not | |
| 1879 | - // a member of this blog, but is (network) approved, add them to this blog. | |
| 1880 | - if ( | |
| 1881 | - is_admin() && | |
| 1882 | - is_multisite() && | |
| 1883 | - is_user_logged_in() && | |
| 1884 | - ! is_user_member_of_blog() && | |
| 1885 | - $this->is_email_in_list( $current_user->user_email, 'approved' ) | |
| 1886 | - ) { | |
| 1887 | - // Get all approved users. | |
| 1888 | - $auth_settings_access_users_approved = $this->sanitize_user_list( | |
| 1889 | - array_merge( | |
| 1890 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ), | |
| 1891 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 1892 | - ) | |
| 1893 | - ); | |
| 1894 | - | |
| 1895 | - // Get user info (we need user role). | |
| 1896 | - $user_info = $this->get_user_info_from_list( | |
| 1897 | - $current_user->user_email, | |
| 1898 | - $auth_settings_access_users_approved | |
| 1899 | - ); | |
| 1900 | - | |
| 1901 | - // Add user to blog. | |
| 1902 | - add_user_to_blog( get_current_blog_id(), $current_user->ID, $user_info['role'] ); | |
| 1903 | - | |
| 1904 | - // Refresh user permissions. | |
| 1905 | - $current_user = new WP_User( $current_user->ID ); // phpcs:ignore WordPress.Variables.GlobalVariables.OverrideProhibited | |
| 1906 | - } | |
| 1907 | - } | |
| 1908 | - | |
| 1909 | - | |
| 1910 | - | |
| 1911 | 1618 | /** |
| 1912 | 1619 | * *************************** |
| 1913 | 1620 | * Login page (wp-login.php) |
| 1914 | 1621 | * *************************** |
| @@ -1917,15 +1624,11 @@ | ||
| 1917 | 1624 | |
| 1918 | 1625 | |
| 1919 | 1626 | /** |
| 1920 | 1627 | * Add custom error message to login screen. |
| 1921 | - * | |
| 1922 | 1628 | * Filter: login_errors |
| 1923 | - * | |
| 1924 | - * @param string $errors Error description. | |
| 1925 | - * @return string Error description with Authorizer errors added. | |
| 1926 | 1629 | */ |
| 1927 | - public function show_advanced_login_error( $errors ) { | |
| 1630 | + function show_advanced_login_error( $errors ) { | |
| 1928 | 1631 | $error = get_option( 'auth_settings_advanced_login_error' ); |
| 1929 | 1632 | delete_option( 'auth_settings_advanced_login_error' ); |
| 1930 | 1633 | $errors = ' ' . $error . "<br />\n"; |
| 1931 | 1634 | return $errors; |
| @@ -1933,25 +1636,24 @@ | ||
| 1933 | 1636 | |
| 1934 | 1637 | |
| 1935 | 1638 | /** |
| 1936 | 1639 | * Load external resources for the public-facing site. |
| 1937 | - * | |
| 1938 | - * Action: wp_enqueue_scripts | |
| 1939 | 1640 | */ |
| 1940 | - public function auth_public_scripts() { | |
| 1941 | - // Load (and localize) public scripts. | |
| 1942 | - $current_path = ! empty( $_SERVER['REQUEST_URI'] ) ? esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : home_url(); | |
| 1943 | - wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); | |
| 1641 | + function auth_public_scripts() { | |
| 1642 | + // Load (and localize) public scripts | |
| 1643 | + $current_path = empty( $_SERVER['REQUEST_URI'] ) ? home_url() : $_SERVER['REQUEST_URI']; | |
| 1644 | + wp_enqueue_script( 'auth_public_scripts', plugins_url( '/js/authorizer-public.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); | |
| 1944 | 1645 | $auth_localized = array( |
| 1945 | - 'wpLoginUrl' => wp_login_url( $current_path ), | |
| 1946 | - 'publicWarning' => get_option( 'auth_settings_advanced_public_notice' ), | |
| 1947 | - 'anonymousNotice' => $this->get_plugin_option( 'access_redirect_to_message' ), | |
| 1948 | - 'logIn' => esc_html__( 'Log In', 'authorizer' ), | |
| 1646 | + 'wp_login_url' => wp_login_url( $current_path ), | |
| 1647 | + 'public_warning' => get_option( 'auth_settings_advanced_public_notice' ), | |
| 1648 | + 'anonymous_notice' => $this->get_plugin_option( 'access_redirect_to_message' ), | |
| 1649 | + 'log_in' => esc_html__( 'Log In', 'authorizer' ), | |
| 1949 | 1650 | ); |
| 1950 | 1651 | wp_localize_script( 'auth_public_scripts', 'auth', $auth_localized ); |
| 1652 | + //update_option( 'auth_settings_advanced_public_notice', false); | |
| 1951 | 1653 | |
| 1952 | - // Load public css. | |
| 1953 | - wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.8.0' ); | |
| 1654 | + // Load public css | |
| 1655 | + wp_register_style( 'authorizer-public-css', plugins_url( 'css/authorizer-public.css', __FILE__ ), array(), '2.3.2' ); | |
| 1954 | 1656 | wp_enqueue_style( 'authorizer-public-css' ); |
| 1955 | 1657 | } |
| 1956 | 1658 | |
| 1957 | 1659 | |
| @@ -1957,21 +1659,19 @@ | ||
| 1957 | 1659 | |
| 1958 | 1660 | /** |
| 1959 | 1661 | * Enqueue JS scripts and CSS styles appearing on wp-login.php. |
| 1960 | 1662 | * |
| 1961 | - * Action: login_enqueue_scripts | |
| 1962 | - * | |
| 1963 | 1663 | * @return void |
| 1964 | 1664 | */ |
| 1965 | - public function login_enqueue_scripts_and_styles() { | |
| 1665 | + function login_enqueue_scripts_and_styles() { | |
| 1966 | 1666 | // Grab plugin settings. |
| 1967 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 1667 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 1968 | 1668 | |
| 1969 | 1669 | // Enqueue scripts appearing on wp-login.php. |
| 1970 | - wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); | |
| 1670 | + wp_enqueue_script( 'auth_login_scripts', plugins_url( '/js/authorizer-login.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); | |
| 1971 | 1671 | |
| 1972 | 1672 | // Enqueue styles appearing on wp-login.php. |
| 1973 | - wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.8.0' ); | |
| 1673 | + wp_register_style( 'authorizer-login-css', plugins_url( '/css/authorizer-login.css', __FILE__ ), array(), '2.3.2' ); | |
| 1974 | 1674 | wp_enqueue_style( 'authorizer-login-css' ); |
| 1975 | 1675 | |
| 1976 | 1676 | /** |
| 1977 | 1677 | * Developers can use the `authorizer_add_branding_option` filter |
| @@ -1976,8 +1676,9 @@ | ||
| 1976 | 1676 | /** |
| 1977 | 1677 | * Developers can use the `authorizer_add_branding_option` filter |
| 1978 | 1678 | * to add a radio button for "Custom WordPress login branding" |
| 1979 | 1679 | * under the "Advanced" tab in Authorizer options. Example: |
| 1680 | + * | |
| 1980 | 1681 | * function my_authorizer_add_branding_option( $branding_options ) { |
| 1981 | 1682 | * $new_branding_option = array( |
| 1982 | 1683 | * 'value' => 'your_brand' |
| 1983 | 1684 | * 'description' => 'Custom Your Brand Login Screen', |
| @@ -1991,23 +1692,23 @@ | ||
| 1991 | 1692 | */ |
| 1992 | 1693 | $branding_options = array(); |
| 1993 | 1694 | $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options ); |
| 1994 | 1695 | foreach ( $branding_options as $branding_option ) { |
| 1995 | - // Make sure the custom brands have the required values. | |
| 1696 | + // Make sure the custom brands have the required values | |
| 1996 | 1697 | if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'css_url', $branding_option ) && array_key_exists( 'js_url', $branding_option ) ) ) { |
| 1997 | 1698 | continue; |
| 1998 | 1699 | } |
| 1999 | 1700 | if ( $auth_settings['advanced_branding'] === $branding_option['value'] ) { |
| 2000 | - wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.8.0' ); | |
| 2001 | - wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.8.0' ); | |
| 1701 | + wp_enqueue_script( 'auth_login_custom_scripts-' . sanitize_title( $branding_option['value'] ), $branding_option['js_url'], array( 'jquery' ), '2.3.2' ); | |
| 1702 | + wp_register_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ), $branding_option['css_url'], array(), '2.3.2' ); | |
| 2002 | 1703 | wp_enqueue_style( 'authorizer-login-custom-css-' . sanitize_title( $branding_option['value'] ) ); |
| 2003 | 1704 | } |
| 2004 | 1705 | } |
| 2005 | 1706 | |
| 2006 | 1707 | // If we're using Google logins, load those resources. |
| 2007 | - if ( '1' === $auth_settings['google'] ) { | |
| 2008 | - wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.8.0' ); ?> | |
| 2009 | - <meta name="google-signin-clientid" content="<?php echo esc_attr( $auth_settings['google_clientid'] ); ?>" /> | |
| 1708 | + if ( $auth_settings['google'] === '1' ) { | |
| 1709 | + wp_enqueue_script( 'authorizer-login-custom-google', plugins_url( '/js/authorizer-login-custom_google.js', __FILE__ ), array( 'jquery' ), '2.3.2' ); ?> | |
| 1710 | + <meta name="google-signin-clientid" content="<?php echo $auth_settings['google_clientid']; ?>" /> | |
| 2010 | 1711 | <meta name="google-signin-scope" content="email" /> |
| 2011 | 1712 | <meta name="google-signin-cookiepolicy" content="single_host_origin" /> |
| 2012 | 1713 | <?php |
| 2013 | 1714 | } |
| @@ -2015,127 +1716,110 @@ | ||
| 2015 | 1716 | |
| 2016 | 1717 | |
| 2017 | 1718 | /** |
| 2018 | 1719 | * Load external resources in the footer of the wp-login.php page. |
| 2019 | - * | |
| 2020 | - * Action: login_footer | |
| 1720 | + * Run on action hook: login_footer | |
| 2021 | 1721 | */ |
| 2022 | - public function load_login_footer_js() { | |
| 1722 | + function load_login_footer_js() { | |
| 2023 | 1723 | // Grab plugin settings. |
| 2024 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 2025 | - $ajaxurl = admin_url( 'admin-ajax.php' ); | |
| 2026 | - if ( '1' === $auth_settings['google'] ) : | |
| 2027 | - ?> | |
| 2028 | -<script type="text/javascript"> | |
| 2029 | -/* global location, window */ | |
| 2030 | -// Reload login page if reauth querystring param exists, | |
| 2031 | -// since reauth interrupts external logins (e.g., google). | |
| 2032 | -if ( location.search.indexOf( 'reauth=1' ) >= 0 ) { | |
| 2033 | - location.href = location.href.replace( 'reauth=1', '' ); | |
| 2034 | -} | |
| 1724 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?> | |
| 1725 | + <?php if ( $auth_settings['google'] === '1' ): ?> | |
| 1726 | + <script type="text/javascript"> | |
| 1727 | + // Reload login page if reauth querystring param exists, | |
| 1728 | + // since reauth interrupts external logins (e.g., google). | |
| 1729 | + if ( location.search.indexOf( 'reauth=1' ) >= 0 ) { | |
| 1730 | + location.href = location.href.replace( 'reauth=1', '' ); | |
| 1731 | + } | |
| 2035 | 1732 | |
| 2036 | -// eslint-disable-next-line no-implicit-globals | |
| 2037 | -function authUpdateQuerystringParam( uri, key, value ) { | |
| 2038 | - var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' ); | |
| 2039 | - var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?'; | |
| 2040 | - if ( uri.match( re ) ) { | |
| 2041 | - return uri.replace( re, '$1' + key + '=' + value + '$2' ); | |
| 2042 | - } else { | |
| 2043 | - return uri + separator + key + '=' + value; | |
| 2044 | - } | |
| 2045 | -} | |
| 1733 | + function auth_update_querystring_param( uri, key, value ) { | |
| 1734 | + var re = new RegExp( '([?&])' + key + '=.*?(&|$)', 'i' ); | |
| 1735 | + var separator = uri.indexOf( '?' ) !== -1 ? '&' : '?'; | |
| 1736 | + if ( uri.match( re ) ) { | |
| 1737 | + return uri.replace( re, '$1' + key + '=' + value + '$2' ); | |
| 1738 | + } else { | |
| 1739 | + return uri + separator + key + '=' + value; | |
| 1740 | + } | |
| 1741 | + } | |
| 2046 | 1742 | |
| 2047 | -// eslint-disable-next-line | |
| 2048 | -function signInCallback( authResult ) { // jshint ignore:line | |
| 2049 | - var $ = jQuery; | |
| 2050 | - if ( authResult.status && authResult.status.signed_in ) { | |
| 2051 | - // Hide the sign-in button now that the user is authorized, for example: | |
| 2052 | - $( '#googleplus_button' ).attr( 'style', 'display: none' ); | |
| 1743 | + function signInCallback( authResult ) { | |
| 1744 | + var $ = jQuery; | |
| 1745 | + if ( authResult['status'] && authResult['status']['signed_in'] ) { | |
| 1746 | + // Hide the sign-in button now that the user is authorized, for example: | |
| 1747 | + $( '#googleplus_button' ).attr( 'style', 'display: none' ); | |
| 2053 | 1748 | |
| 2054 | - // Send the code to the server | |
| 2055 | - var ajaxurl = '<?php echo esc_attr( $ajaxurl ); ?>'; | |
| 2056 | - $.post(ajaxurl, { | |
| 2057 | - action: 'process_google_login', | |
| 2058 | - code: authResult.code, | |
| 2059 | - nonce: $('#nonce_google_auth-<?php echo esc_attr( $this->get_cookie_value() ); ?>' ).val(), | |
| 2060 | - }, function() { | |
| 2061 | - // Handle or verify the server response if necessary. | |
| 2062 | - // console.log( response ); | |
| 1749 | + // Send the code to the server | |
| 1750 | + var ajaxurl = '<?php echo admin_url( "admin-ajax.php" ); ?>'; | |
| 1751 | + $.post(ajaxurl, { | |
| 1752 | + action: 'process_google_login', | |
| 1753 | + 'code': authResult['code'], | |
| 1754 | + 'nonce': $('#nonce_google_auth-<?php echo $this->get_cookie_value(); ?>' ).val(), | |
| 1755 | + }, function( response ) { | |
| 1756 | + // Handle or verify the server response if necessary. | |
| 1757 | + //console.log( response ); | |
| 2063 | 1758 | |
| 2064 | - // Reload wp-login.php to continue the authentication process. | |
| 2065 | - var newHref = authUpdateQuerystringParam( location.href, 'external', 'google' ); | |
| 2066 | - if ( location.href === newHref ) { | |
| 2067 | - location.reload(); | |
| 2068 | - } else { | |
| 2069 | - location.href = newHref; | |
| 2070 | - } | |
| 2071 | - }); | |
| 2072 | - } else { | |
| 2073 | - // Update the app to reflect a signed out user | |
| 2074 | - // Possible error values: | |
| 2075 | - // "user_signed_out" - User is signed-out | |
| 2076 | - // "access_denied" - User denied access to your app | |
| 2077 | - // "immediate_failed" - Could not automatically log in the user | |
| 2078 | - // console.log('Sign-in state: ' + authResult['error']); | |
| 1759 | + // Reload wp-login.php to continue the authentication process. | |
| 1760 | + var new_href = auth_update_querystring_param( location.href, 'external', 'google' ); | |
| 1761 | + if ( location.href === new_href ) { | |
| 1762 | + location.reload(); | |
| 1763 | + } else { | |
| 1764 | + location.href = new_href; | |
| 1765 | + } | |
| 1766 | + }); | |
| 1767 | + } else { | |
| 1768 | + // Update the app to reflect a signed out user | |
| 1769 | + // Possible error values: | |
| 1770 | + // "user_signed_out" - User is signed-out | |
| 1771 | + // "access_denied" - User denied access to your app | |
| 1772 | + // "immediate_failed" - Could not automatically log in the user | |
| 1773 | + //console.log('Sign-in state: ' + authResult['error']); | |
| 2079 | 1774 | |
| 2080 | - // If user denies access, reload the login page. | |
| 2081 | - if ( authResult.error === 'access_denied' || authResult.error === 'user_signed_out' ) { | |
| 2082 | - window.location.reload(); | |
| 1775 | + // If user denies access, reload the login page. | |
| 1776 | + if ( authResult['error'] === 'access_denied' || authResult['error'] === 'user_signed_out' ) { | |
| 1777 | + window.location.reload(); | |
| 1778 | + } | |
| 1779 | + } | |
| 1780 | + } | |
| 1781 | + </script> | |
| 1782 | + <?php endif; | |
| 2083 | 1783 | } |
| 2084 | - } | |
| 2085 | -} | |
| 2086 | -</script> | |
| 2087 | - <?php | |
| 2088 | - endif; | |
| 2089 | - } | |
| 2090 | 1784 | |
| 2091 | 1785 | |
| 2092 | 1786 | /** |
| 2093 | 1787 | * Create links for any external authentication services that are enabled. |
| 2094 | - * | |
| 2095 | - * Action: login_form | |
| 2096 | 1788 | */ |
| 2097 | - public function login_form_add_external_service_links() { | |
| 1789 | + function login_form_add_external_service_links() { | |
| 2098 | 1790 | // Grab plugin settings. |
| 2099 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 2100 | - ?> | |
| 1791 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); ?> | |
| 2101 | 1792 | <div id="auth-external-service-login"> |
| 2102 | - <?php if ( '1' === $auth_settings['google'] ) : ?> | |
| 2103 | - <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php esc_html_e( 'Sign in with Google', 'authorizer' ); ?></span></a></p> | |
| 1793 | + <?php if ( $auth_settings['google'] === '1' ): ?> | |
| 1794 | + <p><a id="googleplus_button" class="button button-primary button-external button-google"><span class="dashicons dashicons-googleplus"></span><span class="label"><?php _e( 'Sign in with Google', 'authorizer' ); ?></span></a></p> | |
| 2104 | 1795 | <?php wp_nonce_field( 'google_csrf_nonce', 'nonce_google_auth-' . $this->get_cookie_value() ); ?> |
| 2105 | 1796 | <?php endif; ?> |
| 2106 | 1797 | |
| 2107 | - <?php if ( '1' === $auth_settings['cas'] ) : ?> | |
| 2108 | - <p><a class="button button-primary button-external button-cas" href="<?php echo esc_attr( $this->modify_current_url_for_cas_login() ); ?>"> | |
| 1798 | + <?php if ( $auth_settings['cas'] === '1' ): ?> | |
| 1799 | + <p><a class="button button-primary button-external button-cas" href="<?php echo $this->modify_current_url_for_cas_login(); ?>"> | |
| 2109 | 1800 | <span class="dashicons dashicons-lock"></span> |
| 2110 | - <span class="label"> | |
| 2111 | - <?php | |
| 2112 | - echo esc_html( | |
| 2113 | - sprintf( | |
| 2114 | - /* TRANSLATORS: %s: Custom CAS label from authorizer options */ | |
| 2115 | - __( 'Sign in with %s', 'authorizer' ), | |
| 2116 | - $auth_settings['cas_custom_label'] | |
| 2117 | - ) | |
| 1801 | + <span class="label"><?php | |
| 1802 | + printf( | |
| 1803 | + /* TRANSLATORS: %s: Custom CAS label from authorizer options */ | |
| 1804 | + __( 'Sign in with %s', 'authorizer' ), | |
| 1805 | + $auth_settings['cas_custom_label'] | |
| 2118 | 1806 | ); |
| 2119 | - ?> | |
| 2120 | - </span> | |
| 1807 | + ?></span> | |
| 2121 | 1808 | </a></p> |
| 2122 | 1809 | <?php endif; ?> |
| 2123 | 1810 | |
| 2124 | - <?php if ( '1' === $auth_settings['advanced_hide_wp_login'] && isset( $_SERVER['QUERY_STRING'] ) && false === strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) ) : // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput ?> | |
| 1811 | + <?php if ( $auth_settings['advanced_hide_wp_login'] === '1' && strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false ): ?> | |
| 2125 | 1812 | <style type="text/css"> |
| 2126 | - body.login-action-login form { | |
| 2127 | - padding-bottom: 8px; | |
| 1813 | + #loginform { | |
| 1814 | + padding-bottom: 8px !important; | |
| 2128 | 1815 | } |
| 2129 | - body.login-action-login form p > label, | |
| 2130 | - body.login-action-login form .forgetmenot, | |
| 2131 | - body.login-action-login form .submit, | |
| 2132 | - body.login-action-login #nav { /* csslint allow: ids */ | |
| 2133 | - display: none; | |
| 1816 | + #loginform p>label, #loginform p.forgetmenot, #loginform p.submit, p#nav { | |
| 1817 | + display: none !important; | |
| 2134 | 1818 | } |
| 2135 | 1819 | </style> |
| 2136 | - <?php elseif ( '1' === $auth_settings['cas'] || '1' === $auth_settings['google'] ) : ?> | |
| 2137 | - <h3> — <?php esc_html_e( 'or', 'authorizer' ); ?> — </h3> | |
| 1820 | + <?php elseif ( $auth_settings['cas'] === '1' || $auth_settings['google'] === '1' ): ?> | |
| 1821 | + <h3> — <?php _e( 'or', 'authorizer' ); ?> — </h3> | |
| 2138 | 1822 | <?php endif; ?> |
| 2139 | 1823 | </div> |
| 2140 | 1824 | <?php |
| 2141 | 1825 | |
| @@ -2144,79 +1828,36 @@ | ||
| 2144 | 1828 | |
| 2145 | 1829 | /** |
| 2146 | 1830 | * Redirect to CAS login when visiting login page (only if option is |
| 2147 | 1831 | * enabled, CAS is the only service, and WordPress logins are hidden). |
| 2148 | - * Note: hook into wp_login_errors filter so this fires after the | |
| 2149 | - * authenticate hook (where the redirect to CAS happens), but before html | |
| 2150 | - * output is started (so the redirect header doesn't complain about data | |
| 2151 | - * already being sent). | |
| 2152 | - * | |
| 2153 | - * Filter: wp_login_errors | |
| 2154 | - * | |
| 2155 | - * @param object $errors WP Error object. | |
| 2156 | - * @param string $redirect_to Where to redirect on error. | |
| 2157 | - * @return WP_Error|void WP Error object or void on redirect. | |
| 2158 | 1832 | */ |
| 2159 | - public function wp_login_errors__maybe_redirect_to_cas( $errors, $redirect_to ) { | |
| 1833 | + function login_head_maybe_redirect_to_cas() { | |
| 2160 | 1834 | // Grab plugin settings. |
| 2161 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 1835 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 2162 | 1836 | |
| 2163 | 1837 | // Check whether we should redirect to CAS. |
| 2164 | 1838 | if ( |
| 2165 | - isset( $_SERVER['QUERY_STRING'] ) && | |
| 2166 | - strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false && // phpcs:ignore WordPress.VIP.ValidatedSanitizedInput | |
| 2167 | - array_key_exists( 'cas_auto_login', $auth_settings ) && '1' === $auth_settings['cas_auto_login'] && | |
| 2168 | - array_key_exists( 'cas', $auth_settings ) && '1' === $auth_settings['cas'] && | |
| 2169 | - ( ! array_key_exists( 'ldap', $auth_settings ) || '1' !== $auth_settings['ldap'] ) && | |
| 2170 | - ( ! array_key_exists( 'google', $auth_settings ) || '1' !== $auth_settings['google'] ) && | |
| 2171 | - array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && '1' === $auth_settings['advanced_hide_wp_login'] | |
| 1839 | + strpos( $_SERVER['QUERY_STRING'], 'external=wordpress' ) === false && | |
| 1840 | + array_key_exists( 'cas_auto_login', $auth_settings ) && $auth_settings['cas_auto_login'] === '1' && | |
| 1841 | + array_key_exists( 'cas', $auth_settings ) && $auth_settings['cas'] === '1' && | |
| 1842 | + ( ! array_key_exists( 'ldap', $auth_settings ) || $auth_settings['ldap'] !== '1' ) && | |
| 1843 | + ( ! array_key_exists( 'google', $auth_settings ) || $auth_settings['google'] !== '1' ) && | |
| 1844 | + array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && $auth_settings['advanced_hide_wp_login'] === '1' | |
| 2172 | 1845 | ) { |
| 2173 | 1846 | wp_redirect( $this->modify_current_url_for_cas_login() ); |
| 2174 | 1847 | exit; |
| 2175 | 1848 | } |
| 2176 | - | |
| 2177 | - return $errors; | |
| 2178 | 1849 | } |
| 2179 | 1850 | |
| 2180 | 1851 | |
| 2181 | 1852 | /** |
| 2182 | - * Set a unique cookie to add to Google auth nonce to avoid CSRF detection. | |
| 2183 | - * Note: hook into login_init so this fires at the start of the visit to | |
| 2184 | - * wp-login.php, but before any html output is started (so setting the | |
| 2185 | - * cookie header doesn't complain about data already being sent). | |
| 2186 | - * | |
| 2187 | - * Action: login_init | |
| 2188 | - * | |
| 2189 | - * @return void | |
| 2190 | - */ | |
| 2191 | - public function login_init__maybe_set_google_nonce_cookie() { | |
| 2192 | - // Grab plugin settings. | |
| 2193 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 2194 | - | |
| 2195 | - // If Google logins are enabled, make sure the cookie is set. | |
| 2196 | - if ( array_key_exists( 'google', $auth_settings ) && '1' === $auth_settings['google'] ) { | |
| 2197 | - if ( ! isset( $_COOKIE['login_unique'] ) ) { | |
| 2198 | - $this->cookie_value = md5( rand() ); | |
| 2199 | - setcookie( 'login_unique', $this->cookie_value, time() + 1800, '/', defined( 'COOKIE_DOMAIN' ) ? COOKIE_DOMAIN : '' ); | |
| 2200 | - $_COOKIE['login_unique'] = $this->cookie_value; | |
| 2201 | - } | |
| 2202 | - } | |
| 2203 | - } | |
| 2204 | - | |
| 2205 | - | |
| 2206 | - /** | |
| 2207 | 1853 | * Implements hook: do_action( 'wp_login_failed', $username ); |
| 2208 | 1854 | * Update the user meta for the user that just failed logging in. |
| 2209 | 1855 | * Keep track of time of last failed attempt and number of failed attempts. |
| 2210 | - * | |
| 2211 | - * Action: wp_login_failed | |
| 2212 | - * | |
| 2213 | - * @param string $username Username to update login count for. | |
| 2214 | - * @return void | |
| 2215 | 1856 | */ |
| 2216 | - public function update_login_failed_count( $username ) { | |
| 1857 | + function update_login_failed_count( $username ) { | |
| 2217 | 1858 | // Grab plugin settings. |
| 2218 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 1859 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 2219 | 1860 | |
| 2220 | 1861 | // Get user trying to log in. |
| 2221 | 1862 | // If this isn't a real user, update the global failed attempt |
| 2222 | 1863 | // variables. We'll use these global variables to institute the |
| @@ -2224,9 +1865,9 @@ | ||
| 2224 | 1865 | // won't be able to determine which accounts are real by which |
| 2225 | 1866 | // accounts get locked out on multiple invalid attempts. |
| 2226 | 1867 | $user = get_user_by( 'login', $username ); |
| 2227 | 1868 | |
| 2228 | - if ( false !== $user ) { | |
| 1869 | + if ( $user !== FALSE ) { | |
| 2229 | 1870 | $last_attempt = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', true ); |
| 2230 | 1871 | $num_attempts = get_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', true ); |
| 2231 | 1872 | } else { |
| 2232 | 1873 | $last_attempt = get_option( 'auth_settings_advanced_lockouts_time_last_failed' ); |
| @@ -2240,15 +1881,15 @@ | ||
| 2240 | 1881 | |
| 2241 | 1882 | // Reset the failed attempt count if the time since the last |
| 2242 | 1883 | // failed attempt is greater than the reset duration. |
| 2243 | 1884 | $time_since_last_fail = time() - $last_attempt; |
| 2244 | - $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds. | |
| 1885 | + $reset_duration = $auth_settings['advanced_lockouts']['reset_duration'] * 60; // minutes to seconds | |
| 2245 | 1886 | if ( $time_since_last_fail > $reset_duration ) { |
| 2246 | 1887 | $num_attempts = 0; |
| 2247 | 1888 | } |
| 2248 | 1889 | |
| 2249 | 1890 | // Set last failed time to now and increment last failed count. |
| 2250 | - if ( false !== $user ) { | |
| 1891 | + if ( $user !== FALSE ) { | |
| 2251 | 1892 | update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_time_last_failed', time() ); |
| 2252 | 1893 | update_user_meta( $user->ID, 'auth_settings_advanced_lockouts_failed_attempts', $num_attempts + 1 ); |
| 2253 | 1894 | } else { |
| 2254 | 1895 | update_option( 'auth_settings_advanced_lockouts_time_last_failed', time() ); |
| @@ -2259,16 +1900,16 @@ | ||
| 2259 | 1900 | |
| 2260 | 1901 | /** |
| 2261 | 1902 | * When they successfully log in, make sure WordPress users are in the approved list. |
| 2262 | 1903 | * |
| 2263 | - * Action: wp_login | |
| 1904 | + * @action wp_login | |
| 2264 | 1905 | * |
| 2265 | 1906 | * @param string $user_login Username of the user logging in. |
| 2266 | - * @param object $user WP_User object of the user logging in. | |
| 2267 | - * @return void | |
| 1907 | + * @param WP_User $user WP_User object of the user logging in. | |
| 1908 | + * @return null | |
| 2268 | 1909 | */ |
| 2269 | - public function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) { | |
| 2270 | - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles ); | |
| 1910 | + function ensure_wordpress_user_in_approved_list_on_login( $user_login, $user ) { | |
| 1911 | + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles ); | |
| 2271 | 1912 | } |
| 2272 | 1913 | |
| 2273 | 1914 | |
| 2274 | 1915 | /** |
| @@ -2274,17 +1915,12 @@ | ||
| 2274 | 1915 | /** |
| 2275 | 1916 | * Overwrite the URL for the lost password link on the login form. |
| 2276 | 1917 | * If we're authenticating against an external service, standard |
| 2277 | 1918 | * WordPress password resets won't work. |
| 2278 | - * | |
| 2279 | - * Filter: lostpassword_url | |
| 2280 | - * | |
| 2281 | - * @param string $lostpassword_url URL to reset password. | |
| 2282 | - * @return string URL to reset password. | |
| 2283 | 1919 | */ |
| 2284 | - public function custom_lostpassword_url( $lostpassword_url ) { | |
| 1920 | + function custom_lostpassword_url( $lostpassword_url ) { | |
| 2285 | 1921 | // Grab plugin settings. |
| 2286 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 1922 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 2287 | 1923 | |
| 2288 | 1924 | if ( |
| 2289 | 1925 | array_key_exists( 'ldap_lostpassword_url', $auth_settings ) && |
| 2290 | 1926 | filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_VALIDATE_URL ) |
| @@ -2307,16 +1943,15 @@ | ||
| 2307 | 1943 | /** |
| 2308 | 1944 | * Add a link to this plugin's settings page from the WordPress Plugins page. |
| 2309 | 1945 | * Called from "plugin_action_links" filter in __construct() above. |
| 2310 | 1946 | * |
| 2311 | - * Filter: plugin_action_links_authorizer.php | |
| 1947 | + * @param array $links array of links in the admin sidebar | |
| 2312 | 1948 | * |
| 2313 | - * @param array $links Admin sidebar links. | |
| 2314 | - * @return array Admin sidebar links with Authorizer added. | |
| 1949 | + * @return array of links to show in the admin sidebar. | |
| 2315 | 1950 | */ |
| 2316 | 1951 | public function plugin_settings_link( $links ) { |
| 2317 | - $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' ); | |
| 2318 | - $settings_url = 'settings' === $admin_menu ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' ); | |
| 1952 | + $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' ); | |
| 1953 | + $settings_url = $admin_menu === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( 'admin.php?page=authorizer' ); | |
| 2319 | 1954 | array_unshift( $links, '<a href="' . $settings_url . '">' . __( 'Settings', 'authorizer' ) . '</a>' ); |
| 2320 | 1955 | return $links; |
| 2321 | 1956 | } |
| 2322 | 1957 | |
| @@ -2324,12 +1959,11 @@ | ||
| 2324 | 1959 | /** |
| 2325 | 1960 | * Add a link to this plugin's network settings page from the WordPress Plugins page. |
| 2326 | 1961 | * Called from "network_admin_plugin_action_links" filter in __construct() above. |
| 2327 | 1962 | * |
| 2328 | - * Filter: network_admin_plugin_action_links_authorizer.php | |
| 1963 | + * @param array $links array of links in the network admin sidebar | |
| 2329 | 1964 | * |
| 2330 | - * @param array $links Network admin sidebar links. | |
| 2331 | - * @return array Network admin sidebar links with Authorizer added. | |
| 1965 | + * @return array of links to show in the network admin sidebar. | |
| 2332 | 1966 | */ |
| 2333 | 1967 | public function network_admin_plugin_settings_link( $links ) { |
| 2334 | 1968 | $settings_link = '<a href="admin.php?page=authorizer">' . __( 'Network Settings', 'authorizer' ) . '</a>'; |
| 2335 | 1969 | array_unshift( $links, $settings_link ); |
| @@ -2337,33 +1971,32 @@ | ||
| 2337 | 1971 | } |
| 2338 | 1972 | |
| 2339 | 1973 | |
| 2340 | 1974 | /** |
| 2341 | - * Create the options page under Dashboard > Settings. | |
| 2342 | - * | |
| 2343 | - * Action: admin_menu | |
| 1975 | + * Create the options page under Dashboard > Settings | |
| 1976 | + * Run on action hook: admin_menu | |
| 2344 | 1977 | */ |
| 2345 | 1978 | public function add_plugin_page() { |
| 2346 | 1979 | $admin_menu = $this->get_plugin_option( 'advanced_admin_menu' ); |
| 2347 | - if ( 'settings' === $admin_menu ) { | |
| 1980 | + if ( $admin_menu === 'settings' ) { | |
| 2348 | 1981 | // @see http://codex.wordpress.org/Function_Reference/add_options_page |
| 2349 | 1982 | add_options_page( |
| 2350 | - 'Authorizer', | |
| 2351 | - 'Authorizer', | |
| 2352 | - 'create_users', | |
| 2353 | - 'authorizer', | |
| 2354 | - array( $this, 'create_admin_page' ) | |
| 1983 | + 'Authorizer', // Page title | |
| 1984 | + 'Authorizer', // Menu title | |
| 1985 | + 'create_users', // Capability | |
| 1986 | + 'authorizer', // Menu slug | |
| 1987 | + array( $this, 'create_admin_page' ) // function | |
| 2355 | 1988 | ); |
| 2356 | 1989 | } else { |
| 2357 | 1990 | // @see http://codex.wordpress.org/Function_Reference/add_menu_page |
| 2358 | 1991 | add_menu_page( |
| 2359 | - 'Authorizer', | |
| 2360 | - 'Authorizer', | |
| 2361 | - 'create_users', | |
| 2362 | - 'authorizer', | |
| 2363 | - array( $this, 'create_admin_page' ), | |
| 2364 | - 'dashicons-groups', | |
| 2365 | - '99.0018465' // position (decimal is to make overlap with other plugins less likely). | |
| 1992 | + 'Authorizer', // Page title | |
| 1993 | + 'Authorizer', // Menu title | |
| 1994 | + 'create_users', // Capability | |
| 1995 | + 'authorizer', // Menu slug | |
| 1996 | + array( $this, 'create_admin_page' ), // callback | |
| 1997 | + 'dashicons-groups', // icon | |
| 1998 | + '99.0018465' // position (decimal is to make overlap with other plugins less likely) | |
| 2366 | 1999 | ); |
| 2367 | 2000 | } |
| 2368 | 2001 | } |
| 2369 | 2002 | |
| @@ -2368,75 +2001,56 @@ | ||
| 2368 | 2001 | } |
| 2369 | 2002 | |
| 2370 | 2003 | |
| 2371 | 2004 | /** |
| 2372 | - * Output the HTML for the options page. | |
| 2005 | + * Output the HTML for the options page | |
| 2373 | 2006 | */ |
| 2374 | - public function create_admin_page() { | |
| 2375 | - ?> | |
| 2007 | + public function create_admin_page() { ?> | |
| 2376 | 2008 | <div class="wrap"> |
| 2377 | - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2> | |
| 2378 | - <form method="post" action="options.php" autocomplete="off"> | |
| 2379 | - <?php | |
| 2380 | - // This prints out all hidden settings fields. | |
| 2009 | + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2> | |
| 2010 | + <form method="post" action="options.php" autocomplete="off"><?php | |
| 2011 | + // This prints out all hidden settings fields | |
| 2012 | + // @see http://codex.wordpress.org/Function_Reference/settings_fields | |
| 2381 | 2013 | settings_fields( 'auth_settings_group' ); |
| 2382 | - // This prints out all the sections. | |
| 2014 | + // This prints out all the sections | |
| 2015 | + // @see http://codex.wordpress.org/Function_Reference/do_settings_sections | |
| 2383 | 2016 | do_settings_sections( 'authorizer' ); |
| 2384 | - submit_button(); | |
| 2385 | - ?> | |
| 2017 | + submit_button(); ?> | |
| 2386 | 2018 | </form> |
| 2387 | - </div> | |
| 2388 | - <?php | |
| 2019 | + </div><?php | |
| 2389 | 2020 | } |
| 2390 | 2021 | |
| 2391 | 2022 | |
| 2392 | 2023 | /** |
| 2393 | 2024 | * Load external resources on this plugin's options page. |
| 2394 | - * | |
| 2395 | - * Action: load-settings_page_authorizer | |
| 2396 | - * Action: load-toplevel_page_authorizer | |
| 2397 | - * Action: admin_head-index.php | |
| 2025 | + * Run on action hooks: load-settings_page_authorizer, load-toplevel_page_authorizer, admin_head-index.php | |
| 2398 | 2026 | */ |
| 2399 | 2027 | public function load_options_page() { |
| 2400 | 2028 | wp_enqueue_script( |
| 2401 | 2029 | 'authorizer', |
| 2402 | 2030 | plugins_url( 'js/authorizer.js', __FILE__ ), |
| 2403 | - array( 'jquery-effects-shake' ), '2.8.0', true | |
| 2031 | + array( 'jquery-effects-shake' ), '2.3.2', true | |
| 2404 | 2032 | ); |
| 2405 | - wp_localize_script( | |
| 2406 | - 'authorizer', 'authL10n', array( | |
| 2407 | - 'baseurl' => get_bloginfo( 'url' ), | |
| 2408 | - 'saved' => esc_html__( 'Saved', 'authorizer' ), | |
| 2409 | - 'duplicate' => esc_html__( 'Duplicate', 'authorizer' ), | |
| 2410 | - 'failed' => esc_html__( 'Failed', 'authorizer' ), | |
| 2411 | - 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ), | |
| 2412 | - 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ), | |
| 2413 | - 'remove_user' => esc_html__( 'Remove user', 'authorizer' ), | |
| 2414 | - 'no_users_in' => esc_html__( 'No users in', 'authorizer' ), | |
| 2415 | - 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ), | |
| 2416 | - 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ), | |
| 2417 | - 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ), | |
| 2418 | - 'first_page' => esc_html__( 'First page' ), | |
| 2419 | - 'previous_page' => esc_html__( 'Previous page' ), | |
| 2420 | - 'next_page' => esc_html__( 'Next page' ), | |
| 2421 | - 'last_page' => esc_html__( 'Last page' ), | |
| 2422 | - 'is_network_admin' => is_network_admin() ? '1' : '0', | |
| 2423 | - ) | |
| 2424 | - ); | |
| 2033 | + wp_localize_script( 'authorizer', 'auth_L10n', array( | |
| 2034 | + 'baseurl' => get_bloginfo( 'url' ), | |
| 2035 | + 'saved' => esc_html__( 'Saved', 'authorizer' ), | |
| 2036 | + 'failed' => esc_html__( 'Failed', 'authorizer' ), | |
| 2037 | + 'local_wordpress_user' => esc_html__( 'Local WordPress user', 'authorizer' ), | |
| 2038 | + 'block_ban_user' => esc_html__( 'Block/Ban user', 'authorizer' ), | |
| 2039 | + 'remove_user' => esc_html__( 'Remove user', 'authorizer' ), | |
| 2040 | + 'no_users_in' => esc_html__( 'No users in', 'authorizer' ), | |
| 2041 | + 'save_changes' => esc_html__( 'Save Changes', 'authorizer' ), | |
| 2042 | + 'private_pages' => esc_html__( 'Private Pages', 'authorizer' ), | |
| 2043 | + 'public_pages' => esc_html__( 'Public Pages', 'authorizer' ), | |
| 2044 | + )); | |
| 2425 | 2045 | |
| 2426 | 2046 | wp_enqueue_script( |
| 2427 | - 'jquery-autogrow-textarea', | |
| 2428 | - plugins_url( 'vendor/jquery.autogrow-textarea/jquery.autogrow-textarea.js', __FILE__ ), | |
| 2429 | - array( 'jquery' ), '2.7.0', true | |
| 2430 | - ); | |
| 2431 | - | |
| 2432 | - wp_enqueue_script( | |
| 2433 | 2047 | 'jquery.multi-select', |
| 2434 | 2048 | plugins_url( 'vendor/jquery.multi-select/js/jquery.multi-select.js', __FILE__ ), |
| 2435 | 2049 | array( 'jquery' ), '1.8', true |
| 2436 | 2050 | ); |
| 2437 | 2051 | |
| 2438 | - wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.7.3' ); | |
| 2052 | + wp_register_style( 'authorizer-css', plugins_url( 'css/authorizer.css', __FILE__ ), array(), '2.3.2' ); | |
| 2439 | 2053 | wp_enqueue_style( 'authorizer-css' ); |
| 2440 | 2054 | |
| 2441 | 2055 | wp_register_style( 'jquery-multi-select-css', plugins_url( 'vendor/jquery.multi-select/css/multi-select.css', __FILE__ ), array(), '1.8' ); |
| 2442 | 2056 | wp_enqueue_style( 'jquery-multi-select-css' ); |
| @@ -2447,26 +2061,18 @@ | ||
| 2447 | 2061 | |
| 2448 | 2062 | |
| 2449 | 2063 | /** |
| 2450 | 2064 | * Show custom admin notice. |
| 2451 | - * | |
| 2452 | - * Note: currently unused, but if anywhere we: | |
| 2453 | - * add_option( 'auth_settings_advanced_admin_notice, 'Your message.' ); | |
| 2454 | - * It will display and then delete that message on the admin dashboard. | |
| 2455 | - * | |
| 2456 | - * Filter: admin_notices | |
| 2457 | - * filter: network_admin_notices | |
| 2065 | + * Filter: admin_notice | |
| 2458 | 2066 | */ |
| 2459 | - public function show_advanced_admin_notice() { | |
| 2067 | + function show_advanced_admin_notice() { | |
| 2460 | 2068 | $notice = get_option( 'auth_settings_advanced_admin_notice' ); |
| 2461 | 2069 | delete_option( 'auth_settings_advanced_admin_notice' ); |
| 2462 | 2070 | |
| 2463 | - if ( $notice && strlen( $notice ) > 0 ) { | |
| 2464 | - ?> | |
| 2071 | + if ( $notice && strlen( $notice ) > 0 ) { ?> | |
| 2465 | 2072 | <div class="error"> |
| 2466 | - <p><?php echo wp_kses( $notice, $this->allowed_html ); ?></p> | |
| 2467 | - </div> | |
| 2468 | - <?php | |
| 2073 | + <p><?php echo $notice; ?></p> | |
| 2074 | + </div><?php | |
| 2469 | 2075 | } |
| 2470 | 2076 | } |
| 2471 | 2077 | |
| 2472 | 2078 | |
| @@ -2471,11 +2077,9 @@ | ||
| 2471 | 2077 | |
| 2472 | 2078 | |
| 2473 | 2079 | /** |
| 2474 | 2080 | * Add notices to the top of the options page. |
| 2475 | - * | |
| 2476 | - * Action: load-settings_page_authorizer > admin_notices | |
| 2477 | - * | |
| 2081 | + * Run on action hook chain: load-settings_page_authorizer > admin_notices | |
| 2478 | 2082 | * Description: Check for invalid settings combinations and show a warning message, e.g.: |
| 2479 | 2083 | * if ( cas url inaccessible ) : ?> |
| 2480 | 2084 | * <div class='updated settings-error'><p>Can't reach CAS server.</p></div> |
| 2481 | 2085 | * <?php endif; |
| @@ -2481,23 +2085,20 @@ | ||
| 2481 | 2085 | * <?php endif; |
| 2482 | 2086 | */ |
| 2483 | 2087 | public function admin_notices() { |
| 2484 | 2088 | // Grab plugin settings. |
| 2485 | - $auth_settings = $this->get_plugin_options( WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 2089 | + $auth_settings = $this->get_plugin_options( SINGLE_ADMIN, 'allow override' ); | |
| 2486 | 2090 | |
| 2487 | - if ( '1' === $auth_settings['cas'] ) : | |
| 2091 | + if ( $auth_settings['cas'] === '1' ) : | |
| 2488 | 2092 | // Check if provided CAS URL is accessible. |
| 2489 | - $protocol = in_array( strval( $auth_settings['cas_port'] ), array( '80', '8080' ), true ) ? 'http' : 'https'; | |
| 2490 | - $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path']; | |
| 2491 | - $legacy_cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint (old; some servers don't register a ./login endpoint, use serviceValidate instead). | |
| 2492 | - $cas_url = trailingslashit( $cas_url ) . 'serviceValidate'; // Check the specific CAS login endpoint. | |
| 2493 | - if ( ! $this->url_is_accessible( $cas_url ) && ! $this->url_is_accessible( $legacy_cas_url ) ) : | |
| 2494 | - $authorizer_options_url = 'settings' === $auth_settings['advanced_admin_menu'] ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' ); | |
| 2495 | - ?> | |
| 2496 | - <div class='notice notice-warning is-dismissible'> | |
| 2497 | - <p><?php esc_html_e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo esc_attr( $authorizer_options_url ); ?>&tab=external'><?php esc_html_e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php esc_html_e( 'if you intend to use it.', 'authorizer' ); ?></p> | |
| 2498 | - </div> | |
| 2499 | - <?php | |
| 2093 | + $protocol = in_array( $auth_settings['cas_port'], array( '80', '8080' ) ) ? 'http' : 'https'; | |
| 2094 | + $cas_url = $protocol . '://' . $auth_settings['cas_host'] . ':' . $auth_settings['cas_port'] . $auth_settings['cas_path']; | |
| 2095 | + $cas_url = trailingslashit( $cas_url ) . 'login'; // Check the specific CAS login endpoint | |
| 2096 | + if ( ! $this->url_is_accessible( $cas_url ) ) : | |
| 2097 | + $authorizer_options_url = $auth_settings['advanced_admin_menu'] === 'settings' ? admin_url( 'options-general.php?page=authorizer' ) : admin_url( '?page=authorizer' ); | |
| 2098 | + ?><div class='notice notice-warning is-dismissible'> | |
| 2099 | + <p><?php _e( "Can't reach CAS server. Please provide", 'authorizer' ); ?> <a href='<?php echo $authorizer_options_url; ?>&tab=external'><?php _e( 'accurate CAS settings', 'authorizer' ); ?></a> <?php _e( 'if you intend to use it.', 'authorizer' ); ?></p> | |
| 2100 | + </div><?php | |
| 2500 | 2101 | endif; |
| 2501 | 2102 | endif; |
| 2502 | 2103 | } |
| 2503 | 2104 | |
| @@ -2502,430 +2103,399 @@ | ||
| 2502 | 2103 | } |
| 2503 | 2104 | |
| 2504 | 2105 | |
| 2505 | 2106 | /** |
| 2506 | - * Create sections and options. | |
| 2507 | - * | |
| 2508 | - * Action: admin_init | |
| 2107 | + * Create sections and options | |
| 2108 | + * Run on action hook: admin_init | |
| 2509 | 2109 | */ |
| 2510 | 2110 | public function page_init() { |
| 2511 | - /** | |
| 2512 | - * Create one setting that holds all the options (array). | |
| 2513 | - * | |
| 2514 | - * @see http://codex.wordpress.org/Function_Reference/register_setting | |
| 2515 | - * @see http://codex.wordpress.org/Function_Reference/add_settings_section | |
| 2516 | - * @see http://codex.wordpress.org/Function_Reference/add_settings_field | |
| 2517 | - */ | |
| 2111 | + // Create one setting that holds all the options (array) | |
| 2112 | + // @see http://codex.wordpress.org/Function_Reference/register_setting | |
| 2113 | + // @see http://codex.wordpress.org/Function_Reference/add_settings_section | |
| 2114 | + // @see http://codex.wordpress.org/Function_Reference/add_settings_field | |
| 2518 | 2115 | register_setting( |
| 2519 | - 'auth_settings_group', | |
| 2520 | - 'auth_settings', | |
| 2521 | - array( $this, 'sanitize_options' ) | |
| 2116 | + 'auth_settings_group', // Option group | |
| 2117 | + 'auth_settings', // Option name | |
| 2118 | + array( $this, 'sanitize_options' ) // Sanitize callback | |
| 2522 | 2119 | ); |
| 2523 | 2120 | |
| 2524 | 2121 | add_settings_section( |
| 2525 | - 'auth_settings_tabs', | |
| 2526 | - '', | |
| 2527 | - array( $this, 'print_section_info_tabs' ), | |
| 2528 | - 'authorizer' | |
| 2122 | + 'auth_settings_tabs', // HTML element ID | |
| 2123 | + '', // HTML element Title | |
| 2124 | + array( $this, 'print_section_info_tabs' ), // Callback (echos section content) | |
| 2125 | + 'authorizer' // Page this section is shown on (slug) | |
| 2529 | 2126 | ); |
| 2530 | 2127 | |
| 2531 | - // Create Access Lists section. | |
| 2128 | + // Create Access Lists section | |
| 2532 | 2129 | add_settings_section( |
| 2533 | - 'auth_settings_lists', | |
| 2534 | - '', | |
| 2535 | - array( $this, 'print_section_info_access_lists' ), | |
| 2536 | - 'authorizer' | |
| 2130 | + 'auth_settings_lists', // HTML element ID | |
| 2131 | + '', // HTML element Title | |
| 2132 | + array( $this, 'print_section_info_access_lists' ), // Callback (echos section content) | |
| 2133 | + 'authorizer' // Page this section is shown on (slug) | |
| 2537 | 2134 | ); |
| 2538 | 2135 | |
| 2539 | - // Create Login Access section. | |
| 2136 | + // Create Login Access section | |
| 2540 | 2137 | add_settings_section( |
| 2541 | - 'auth_settings_access_login', | |
| 2542 | - '', | |
| 2543 | - array( $this, 'print_section_info_access_login' ), | |
| 2544 | - 'authorizer' | |
| 2138 | + 'auth_settings_access_login', // HTML element ID | |
| 2139 | + '', // HTML element Title | |
| 2140 | + array( $this, 'print_section_info_access_login' ), // Callback (echos section content) | |
| 2141 | + 'authorizer' // Page this section is shown on (slug) | |
| 2545 | 2142 | ); |
| 2546 | 2143 | add_settings_field( |
| 2547 | - 'auth_settings_access_who_can_login', | |
| 2548 | - __( 'Who can log into the site?', 'authorizer' ), | |
| 2549 | - array( $this, 'print_radio_auth_access_who_can_login' ), | |
| 2550 | - 'authorizer', | |
| 2551 | - 'auth_settings_access_login' | |
| 2144 | + 'auth_settings_access_who_can_login', // HTML element ID | |
| 2145 | + __( 'Who can log into the site?', 'authorizer' ), // HTML element Title | |
| 2146 | + array( $this, 'print_radio_auth_access_who_can_login' ), // Callback (echos form element) | |
| 2147 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2148 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2552 | 2149 | ); |
| 2553 | 2150 | add_settings_field( |
| 2554 | - 'auth_settings_access_role_receive_pending_emails', | |
| 2555 | - __( 'Which role should receive email notifications about pending users?', 'authorizer' ), | |
| 2556 | - array( $this, 'print_select_auth_access_role_receive_pending_emails' ), | |
| 2557 | - 'authorizer', | |
| 2558 | - 'auth_settings_access_login' | |
| 2151 | + 'auth_settings_access_role_receive_pending_emails', // HTML element ID | |
| 2152 | + __( 'Which role should receive email notifications about pending users?', 'authorizer' ), // HTML element Title | |
| 2153 | + array( $this, 'print_select_auth_access_role_receive_pending_emails' ), // Callback (echos form element) | |
| 2154 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2155 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2559 | 2156 | ); |
| 2560 | 2157 | add_settings_field( |
| 2561 | - 'auth_settings_access_pending_redirect_to_message', | |
| 2562 | - __( 'What message should pending users see after attempting to log in?', 'authorizer' ), | |
| 2563 | - array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ), | |
| 2564 | - 'authorizer', | |
| 2565 | - 'auth_settings_access_login' | |
| 2158 | + 'auth_settings_access_pending_redirect_to_message', // HTML element ID | |
| 2159 | + __( 'What message should pending users see after attempting to log in?', 'authorizer' ), // HTML element Title | |
| 2160 | + array( $this, 'print_wysiwyg_auth_access_pending_redirect_to_message' ), // Callback (echos form element) | |
| 2161 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2162 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2566 | 2163 | ); |
| 2567 | 2164 | add_settings_field( |
| 2568 | - 'auth_settings_access_blocked_redirect_to_message', | |
| 2569 | - __( 'What message should blocked users see after attempting to log in?', 'authorizer' ), | |
| 2570 | - array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ), | |
| 2571 | - 'authorizer', | |
| 2572 | - 'auth_settings_access_login' | |
| 2165 | + 'auth_settings_access_blocked_redirect_to_message', // HTML element ID | |
| 2166 | + __( 'What message should blocked users see after attempting to log in?', 'authorizer' ), // HTML element Title | |
| 2167 | + array( $this, 'print_wysiwyg_auth_access_blocked_redirect_to_message' ), // Callback (echos form element) | |
| 2168 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2169 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2573 | 2170 | ); |
| 2574 | 2171 | add_settings_field( |
| 2575 | - 'auth_settings_access_should_email_approved_users', | |
| 2576 | - __( 'Send welcome email to new approved users?', 'authorizer' ), | |
| 2577 | - array( $this, 'print_checkbox_auth_access_should_email_approved_users' ), | |
| 2578 | - 'authorizer', | |
| 2579 | - 'auth_settings_access_login' | |
| 2172 | + 'auth_settings_access_should_email_approved_users', // HTML element ID | |
| 2173 | + __( 'Send welcome email to new approved users?', 'authorizer' ), // HTML element Title | |
| 2174 | + array( $this, 'print_checkbox_auth_access_should_email_approved_users' ), // Callback (echos form element) | |
| 2175 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2176 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2580 | 2177 | ); |
| 2581 | 2178 | add_settings_field( |
| 2582 | - 'auth_settings_access_email_approved_users_subject', | |
| 2583 | - __( 'Welcome email subject', 'authorizer' ), | |
| 2584 | - array( $this, 'print_text_auth_access_email_approved_users_subject' ), | |
| 2585 | - 'authorizer', | |
| 2586 | - 'auth_settings_access_login' | |
| 2179 | + 'auth_settings_access_email_approved_users_subject', // HTML element ID | |
| 2180 | + __( 'Welcome email subject', 'authorizer' ), // HTML element Title | |
| 2181 | + array( $this, 'print_text_auth_access_email_approved_users_subject' ), // Callback (echos form element) | |
| 2182 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2183 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2587 | 2184 | ); |
| 2588 | 2185 | add_settings_field( |
| 2589 | - 'auth_settings_access_email_approved_users_body', | |
| 2590 | - __( 'Welcome email body', 'authorizer' ), | |
| 2591 | - array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ), | |
| 2592 | - 'authorizer', | |
| 2593 | - 'auth_settings_access_login' | |
| 2186 | + 'auth_settings_access_email_approved_users_body', // HTML element ID | |
| 2187 | + __( 'Welcome email body', 'authorizer' ), // HTML element Title | |
| 2188 | + array( $this, 'print_wysiwyg_auth_access_email_approved_users_body' ), // Callback (echos form element) | |
| 2189 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2190 | + 'auth_settings_access_login' // Section this setting is shown on | |
| 2594 | 2191 | ); |
| 2595 | 2192 | |
| 2596 | - // Create Public Access section. | |
| 2193 | + | |
| 2194 | + // Create Public Access section | |
| 2597 | 2195 | add_settings_section( |
| 2598 | - 'auth_settings_access_public', | |
| 2599 | - '', | |
| 2600 | - array( $this, 'print_section_info_access_public' ), | |
| 2601 | - 'authorizer' | |
| 2196 | + 'auth_settings_access_public', // HTML element ID | |
| 2197 | + '', // HTML element Title | |
| 2198 | + array( $this, 'print_section_info_access_public' ), // Callback (echos section content) | |
| 2199 | + 'authorizer' // Page this section is shown on (slug) | |
| 2602 | 2200 | ); |
| 2603 | 2201 | add_settings_field( |
| 2604 | - 'auth_settings_access_who_can_view', | |
| 2605 | - __( 'Who can view the site?', 'authorizer' ), | |
| 2606 | - array( $this, 'print_radio_auth_access_who_can_view' ), | |
| 2607 | - 'authorizer', | |
| 2608 | - 'auth_settings_access_public' | |
| 2202 | + 'auth_settings_access_who_can_view', // HTML element ID | |
| 2203 | + __( 'Who can view the site?', 'authorizer' ), // HTML element Title | |
| 2204 | + array( $this, 'print_radio_auth_access_who_can_view' ), // Callback (echos form element) | |
| 2205 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2206 | + 'auth_settings_access_public' // Section this setting is shown on | |
| 2609 | 2207 | ); |
| 2610 | 2208 | add_settings_field( |
| 2611 | - 'auth_settings_access_public_pages', | |
| 2612 | - __( 'What pages (if any) should be available to everyone?', 'authorizer' ), | |
| 2613 | - array( $this, 'print_multiselect_auth_access_public_pages' ), | |
| 2614 | - 'authorizer', | |
| 2615 | - 'auth_settings_access_public' | |
| 2209 | + 'auth_settings_access_public_pages', // HTML element ID | |
| 2210 | + __( 'What pages (if any) should be available to everyone?', 'authorizer' ), // HTML element Title | |
| 2211 | + array( $this, 'print_multiselect_auth_access_public_pages' ), // Callback (echos form element) | |
| 2212 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2213 | + 'auth_settings_access_public' // Section this setting is shown on | |
| 2616 | 2214 | ); |
| 2617 | 2215 | add_settings_field( |
| 2618 | - 'auth_settings_access_redirect', | |
| 2619 | - __( 'What happens to people without access when they visit a private page?', 'authorizer' ), | |
| 2620 | - array( $this, 'print_radio_auth_access_redirect' ), | |
| 2621 | - 'authorizer', | |
| 2622 | - 'auth_settings_access_public' | |
| 2216 | + 'auth_settings_access_redirect', // HTML element ID | |
| 2217 | + __( 'What happens to people without access when they visit a private page?', 'authorizer' ), // HTML element Title | |
| 2218 | + array( $this, 'print_radio_auth_access_redirect' ), // Callback (echos form element) | |
| 2219 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2220 | + 'auth_settings_access_public' // Section this setting is shown on | |
| 2623 | 2221 | ); |
| 2624 | 2222 | add_settings_field( |
| 2625 | - 'auth_settings_access_public_warning', | |
| 2626 | - __( 'What happens to people without access when they visit a public page?', 'authorizer' ), | |
| 2627 | - array( $this, 'print_radio_auth_access_public_warning' ), | |
| 2628 | - 'authorizer', | |
| 2629 | - 'auth_settings_access_public' | |
| 2223 | + 'auth_settings_access_public_warning', // HTML element ID | |
| 2224 | + __( 'What happens to people without access when they visit a public page?', 'authorizer' ), // HTML element Title | |
| 2225 | + array( $this, 'print_radio_auth_access_public_warning' ), // Callback (echos form element) | |
| 2226 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2227 | + 'auth_settings_access_public' // Section this setting is shown on | |
| 2630 | 2228 | ); |
| 2631 | 2229 | add_settings_field( |
| 2632 | - 'auth_settings_access_redirect_to_message', | |
| 2633 | - __( 'What message should people without access see?', 'authorizer' ), | |
| 2634 | - array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ), | |
| 2635 | - 'authorizer', | |
| 2636 | - 'auth_settings_access_public' | |
| 2230 | + 'auth_settings_access_redirect_to_message', // HTML element ID | |
| 2231 | + __( 'What message should people without access see?', 'authorizer' ), // HTML element Title | |
| 2232 | + array( $this, 'print_wysiwyg_auth_access_redirect_to_message' ), // Callback (echos form element) | |
| 2233 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2234 | + 'auth_settings_access_public' // Section this setting is shown on | |
| 2637 | 2235 | ); |
| 2638 | 2236 | |
| 2639 | - // Create External Service Settings section. | |
| 2237 | + // Create External Service Settings section | |
| 2640 | 2238 | add_settings_section( |
| 2641 | - 'auth_settings_external', | |
| 2642 | - '', | |
| 2643 | - array( $this, 'print_section_info_external' ), | |
| 2644 | - 'authorizer' | |
| 2239 | + 'auth_settings_external', // HTML element ID | |
| 2240 | + '', // HTML element Title | |
| 2241 | + array( $this, 'print_section_info_external' ), // Callback (echos section content) | |
| 2242 | + 'authorizer' // Page this section is shown on (slug) | |
| 2645 | 2243 | ); |
| 2646 | 2244 | add_settings_field( |
| 2647 | - 'auth_settings_access_default_role', | |
| 2648 | - __( 'Default role for new users', 'authorizer' ), | |
| 2649 | - array( $this, 'print_select_auth_access_default_role' ), | |
| 2650 | - 'authorizer', | |
| 2651 | - 'auth_settings_external' | |
| 2245 | + 'auth_settings_access_default_role', // HTML element ID | |
| 2246 | + __( 'Default role for new users', 'authorizer' ), // HTML element Title | |
| 2247 | + array( $this, 'print_select_auth_access_default_role' ), // Callback (echos form element) | |
| 2248 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2249 | + 'auth_settings_external' // Section this setting is shown on | |
| 2652 | 2250 | ); |
| 2653 | 2251 | add_settings_field( |
| 2654 | - 'auth_settings_external_google', | |
| 2655 | - __( 'Google Logins', 'authorizer' ), | |
| 2656 | - array( $this, 'print_checkbox_auth_external_google' ), | |
| 2657 | - 'authorizer', | |
| 2658 | - 'auth_settings_external' | |
| 2252 | + 'auth_settings_external_google', // HTML element ID | |
| 2253 | + __( 'Google Logins', 'authorizer' ), // HTML element Title | |
| 2254 | + array( $this, 'print_checkbox_auth_external_google' ), // Callback (echos form element) | |
| 2255 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2256 | + 'auth_settings_external' // Section this setting is shown on | |
| 2659 | 2257 | ); |
| 2660 | 2258 | add_settings_field( |
| 2661 | - 'auth_settings_google_clientid', | |
| 2662 | - __( 'Google Client ID', 'authorizer' ), | |
| 2663 | - array( $this, 'print_text_google_clientid' ), | |
| 2664 | - 'authorizer', | |
| 2665 | - 'auth_settings_external' | |
| 2259 | + 'auth_settings_google_clientid', // HTML element ID | |
| 2260 | + __( 'Google Client ID', 'authorizer' ), // HTML element Title | |
| 2261 | + array( $this, 'print_text_google_clientid' ), // Callback (echos form element) | |
| 2262 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2263 | + 'auth_settings_external' // Section this setting is shown on | |
| 2666 | 2264 | ); |
| 2667 | 2265 | add_settings_field( |
| 2668 | - 'auth_settings_google_clientsecret', | |
| 2669 | - __( 'Google Client Secret', 'authorizer' ), | |
| 2670 | - array( $this, 'print_text_google_clientsecret' ), | |
| 2671 | - 'authorizer', | |
| 2672 | - 'auth_settings_external' | |
| 2266 | + 'auth_settings_google_clientsecret', // HTML element ID | |
| 2267 | + __( 'Google Client Secret', 'authorizer' ), // HTML element Title | |
| 2268 | + array( $this, 'print_text_google_clientsecret' ), // Callback (echos form element) | |
| 2269 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2270 | + 'auth_settings_external' // Section this setting is shown on | |
| 2673 | 2271 | ); |
| 2674 | 2272 | add_settings_field( |
| 2675 | - 'auth_settings_google_hosteddomain', | |
| 2676 | - __( 'Google Hosted Domain', 'authorizer' ), | |
| 2677 | - array( $this, 'print_text_google_hosteddomain' ), | |
| 2678 | - 'authorizer', | |
| 2679 | - 'auth_settings_external' | |
| 2273 | + 'auth_settings_google_hosteddomain', // HTML element ID | |
| 2274 | + __( 'Google Hosted Domain', 'authorizer' ), // HTML element Title | |
| 2275 | + array( $this, 'print_text_google_hosteddomain' ), // Callback (echos form element) | |
| 2276 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2277 | + 'auth_settings_external' // Section this setting is shown on | |
| 2680 | 2278 | ); |
| 2681 | 2279 | add_settings_field( |
| 2682 | - 'auth_settings_external_cas', | |
| 2683 | - __( 'CAS Logins', 'authorizer' ), | |
| 2684 | - array( $this, 'print_checkbox_auth_external_cas' ), | |
| 2685 | - 'authorizer', | |
| 2686 | - 'auth_settings_external' | |
| 2280 | + 'auth_settings_external_cas', // HTML element ID | |
| 2281 | + __( 'CAS Logins', 'authorizer' ), // HTML element Title | |
| 2282 | + array( $this, 'print_checkbox_auth_external_cas' ), // Callback (echos form element) | |
| 2283 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2284 | + 'auth_settings_external' // Section this setting is shown on | |
| 2687 | 2285 | ); |
| 2688 | 2286 | add_settings_field( |
| 2689 | - 'auth_settings_cas_custom_label', | |
| 2690 | - __( 'CAS custom label', 'authorizer' ), | |
| 2691 | - array( $this, 'print_text_cas_custom_label' ), | |
| 2692 | - 'authorizer', | |
| 2693 | - 'auth_settings_external' | |
| 2287 | + 'auth_settings_cas_custom_label', // HTML element ID | |
| 2288 | + __( 'CAS custom label', 'authorizer' ), // HTML element Title | |
| 2289 | + array( $this, 'print_text_cas_custom_label' ), // Callback (echos form element) | |
| 2290 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2291 | + 'auth_settings_external' // Section this setting is shown on | |
| 2694 | 2292 | ); |
| 2695 | 2293 | add_settings_field( |
| 2696 | - 'auth_settings_cas_host', | |
| 2697 | - __( 'CAS server hostname', 'authorizer' ), | |
| 2698 | - array( $this, 'print_text_cas_host' ), | |
| 2699 | - 'authorizer', | |
| 2700 | - 'auth_settings_external' | |
| 2294 | + 'auth_settings_cas_host', // HTML element ID | |
| 2295 | + __( 'CAS server hostname', 'authorizer' ), // HTML element Title | |
| 2296 | + array( $this, 'print_text_cas_host' ), // Callback (echos form element) | |
| 2297 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2298 | + 'auth_settings_external' // Section this setting is shown on | |
| 2701 | 2299 | ); |
| 2702 | 2300 | add_settings_field( |
| 2703 | - 'auth_settings_cas_port', | |
| 2704 | - __( 'CAS server port', 'authorizer' ), | |
| 2705 | - array( $this, 'print_text_cas_port' ), | |
| 2706 | - 'authorizer', | |
| 2707 | - 'auth_settings_external' | |
| 2301 | + 'auth_settings_cas_port', // HTML element ID | |
| 2302 | + __( 'CAS server port', 'authorizer' ), // HTML element Title | |
| 2303 | + array( $this, 'print_text_cas_port' ), // Callback (echos form element) | |
| 2304 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2305 | + 'auth_settings_external' // Section this setting is shown on | |
| 2708 | 2306 | ); |
| 2709 | 2307 | add_settings_field( |
| 2710 | - 'auth_settings_cas_path', | |
| 2711 | - __( 'CAS server path/context', 'authorizer' ), | |
| 2712 | - array( $this, 'print_text_cas_path' ), | |
| 2713 | - 'authorizer', | |
| 2714 | - 'auth_settings_external' | |
| 2308 | + 'auth_settings_cas_path', // HTML element ID | |
| 2309 | + __( 'CAS server path/context', 'authorizer' ), // HTML element Title | |
| 2310 | + array( $this, 'print_text_cas_path' ), // Callback (echos form element) | |
| 2311 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2312 | + 'auth_settings_external' // Section this setting is shown on | |
| 2715 | 2313 | ); |
| 2716 | 2314 | add_settings_field( |
| 2717 | - 'auth_settings_cas_version', | |
| 2718 | - 'CAS server version', | |
| 2719 | - array( $this, 'print_select_cas_version' ), | |
| 2720 | - 'authorizer', | |
| 2721 | - 'auth_settings_external' | |
| 2315 | + 'auth_settings_cas_version', // HTML element ID | |
| 2316 | + 'CAS server version', // HTML element Title | |
| 2317 | + array( $this, 'print_select_cas_version' ), // Callback (echos form element) | |
| 2318 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2319 | + 'auth_settings_external' // Section this setting is shown on | |
| 2722 | 2320 | ); |
| 2723 | 2321 | add_settings_field( |
| 2724 | - 'auth_settings_cas_attr_email', | |
| 2725 | - __( 'CAS attribute containing email address', 'authorizer' ), | |
| 2726 | - array( $this, 'print_text_cas_attr_email' ), | |
| 2727 | - 'authorizer', | |
| 2728 | - 'auth_settings_external' | |
| 2322 | + 'auth_settings_cas_attr_email', // HTML element ID | |
| 2323 | + __( 'CAS attribute containing email address', 'authorizer' ), // HTML element Title | |
| 2324 | + array( $this, 'print_text_cas_attr_email' ), // Callback (echos form element) | |
| 2325 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2326 | + 'auth_settings_external' // Section this setting is shown on | |
| 2729 | 2327 | ); |
| 2730 | 2328 | add_settings_field( |
| 2731 | - 'auth_settings_cas_attr_first_name', | |
| 2732 | - __( 'CAS attribute containing first name', 'authorizer' ), | |
| 2733 | - array( $this, 'print_text_cas_attr_first_name' ), | |
| 2734 | - 'authorizer', | |
| 2735 | - 'auth_settings_external' | |
| 2329 | + 'auth_settings_cas_attr_first_name', // HTML element ID | |
| 2330 | + __( 'CAS attribute containing first name', 'authorizer' ), // HTML element Title | |
| 2331 | + array( $this, 'print_text_cas_attr_first_name' ), // Callback (echos form element) | |
| 2332 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2333 | + 'auth_settings_external' // Section this setting is shown on | |
| 2736 | 2334 | ); |
| 2737 | 2335 | add_settings_field( |
| 2738 | - 'auth_settings_cas_attr_last_name', | |
| 2739 | - __( 'CAS attribute containing last name', 'authorizer' ), | |
| 2740 | - array( $this, 'print_text_cas_attr_last_name' ), | |
| 2741 | - 'authorizer', | |
| 2742 | - 'auth_settings_external' | |
| 2336 | + 'auth_settings_cas_attr_last_name', // HTML element ID | |
| 2337 | + __( 'CAS attribute containing last name', 'authorizer' ), // HTML element Title | |
| 2338 | + array( $this, 'print_text_cas_attr_last_name' ), // Callback (echos form element) | |
| 2339 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2340 | + 'auth_settings_external' // Section this setting is shown on | |
| 2743 | 2341 | ); |
| 2744 | 2342 | add_settings_field( |
| 2745 | - 'auth_settings_cas_attr_update_on_login', | |
| 2746 | - __( 'CAS attribute update', 'authorizer' ), | |
| 2747 | - array( $this, 'print_checkbox_cas_attr_update_on_login' ), | |
| 2748 | - 'authorizer', | |
| 2749 | - 'auth_settings_external' | |
| 2343 | + 'auth_settings_cas_attr_update_on_login', // HTML element ID | |
| 2344 | + __( 'CAS attribute update', 'authorizer' ), // HTML element Title | |
| 2345 | + array( $this, 'print_checkbox_cas_attr_update_on_login' ), // Callback (echos form element) | |
| 2346 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2347 | + 'auth_settings_external' // Section this setting is shown on | |
| 2750 | 2348 | ); |
| 2751 | 2349 | add_settings_field( |
| 2752 | - 'auth_settings_cas_auto_login', | |
| 2753 | - __( 'CAS automatic login', 'authorizer' ), | |
| 2754 | - array( $this, 'print_checkbox_cas_auto_login' ), | |
| 2755 | - 'authorizer', | |
| 2756 | - 'auth_settings_external' | |
| 2350 | + 'auth_settings_cas_auto_login', // HTML element ID | |
| 2351 | + __( 'CAS automatic login', 'authorizer' ), // HTML element Title | |
| 2352 | + array( $this, 'print_checkbox_cas_auto_login' ), // Callback (echos form element) | |
| 2353 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2354 | + 'auth_settings_external' // Section this setting is shown on | |
| 2757 | 2355 | ); |
| 2758 | 2356 | add_settings_field( |
| 2759 | - 'auth_settings_external_ldap', | |
| 2760 | - __( 'LDAP Logins', 'authorizer' ), | |
| 2761 | - array( $this, 'print_checkbox_auth_external_ldap' ), | |
| 2762 | - 'authorizer', | |
| 2763 | - 'auth_settings_external' | |
| 2357 | + 'auth_settings_external_ldap', // HTML element ID | |
| 2358 | + __( 'LDAP Logins', 'authorizer' ), // HTML element Title | |
| 2359 | + array( $this, 'print_checkbox_auth_external_ldap' ), // Callback (echos form element) | |
| 2360 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2361 | + 'auth_settings_external' // Section this setting is shown on | |
| 2764 | 2362 | ); |
| 2765 | 2363 | add_settings_field( |
| 2766 | - 'auth_settings_ldap_host', | |
| 2767 | - __( 'LDAP Host', 'authorizer' ), | |
| 2768 | - array( $this, 'print_text_ldap_host' ), | |
| 2769 | - 'authorizer', | |
| 2770 | - 'auth_settings_external' | |
| 2364 | + 'auth_settings_ldap_host', // HTML element ID | |
| 2365 | + __( 'LDAP Host', 'authorizer' ), // HTML element Title | |
| 2366 | + array( $this, 'print_text_ldap_host' ), // Callback (echos form element) | |
| 2367 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2368 | + 'auth_settings_external' // Section this setting is shown on | |
| 2771 | 2369 | ); |
| 2772 | 2370 | add_settings_field( |
| 2773 | - 'auth_settings_ldap_port', | |
| 2774 | - __( 'LDAP Port', 'authorizer' ), | |
| 2775 | - array( $this, 'print_text_ldap_port' ), | |
| 2776 | - 'authorizer', | |
| 2777 | - 'auth_settings_external' | |
| 2371 | + 'auth_settings_ldap_port', // HTML element ID | |
| 2372 | + __( 'LDAP Port', 'authorizer' ), // HTML element Title | |
| 2373 | + array( $this, 'print_text_ldap_port' ), // Callback (echos form element) | |
| 2374 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2375 | + 'auth_settings_external' // Section this setting is shown on | |
| 2778 | 2376 | ); |
| 2779 | 2377 | add_settings_field( |
| 2780 | - 'auth_settings_ldap_tls', | |
| 2781 | - __( 'Use TLS', 'authorizer' ), | |
| 2782 | - array( $this, 'print_checkbox_ldap_tls' ), | |
| 2783 | - 'authorizer', | |
| 2784 | - 'auth_settings_external' | |
| 2378 | + 'auth_settings_ldap_tls', // HTML element ID | |
| 2379 | + __( 'Secure Connection (TLS)', 'authorizer' ), // HTML element Title | |
| 2380 | + array( $this, 'print_checkbox_ldap_tls' ), // Callback (echos form element) | |
| 2381 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2382 | + 'auth_settings_external' // Section this setting is shown on | |
| 2785 | 2383 | ); |
| 2786 | 2384 | add_settings_field( |
| 2787 | - 'auth_settings_ldap_search_base', | |
| 2788 | - __( 'LDAP Search Base', 'authorizer' ), | |
| 2789 | - array( $this, 'print_text_ldap_search_base' ), | |
| 2790 | - 'authorizer', | |
| 2791 | - 'auth_settings_external' | |
| 2385 | + 'auth_settings_ldap_search_base', // HTML element ID | |
| 2386 | + __( 'LDAP Search Base', 'authorizer' ), // HTML element Title | |
| 2387 | + array( $this, 'print_text_ldap_search_base' ), // Callback (echos form element) | |
| 2388 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2389 | + 'auth_settings_external' // Section this setting is shown on | |
| 2792 | 2390 | ); |
| 2793 | 2391 | add_settings_field( |
| 2794 | - 'auth_settings_ldap_uid', | |
| 2795 | - __( 'LDAP attribute containing username', 'authorizer' ), | |
| 2796 | - array( $this, 'print_text_ldap_uid' ), | |
| 2797 | - 'authorizer', | |
| 2798 | - 'auth_settings_external' | |
| 2392 | + 'auth_settings_ldap_uid', // HTML element ID | |
| 2393 | + __( 'LDAP attribute containing username', 'authorizer' ), // HTML element Title | |
| 2394 | + array( $this, 'print_text_ldap_uid' ), // Callback (echos form element) | |
| 2395 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2396 | + 'auth_settings_external' // Section this setting is shown on | |
| 2799 | 2397 | ); |
| 2800 | 2398 | add_settings_field( |
| 2801 | - 'auth_settings_ldap_attr_email', | |
| 2802 | - __( 'LDAP attribute containing email address', 'authorizer' ), | |
| 2803 | - array( $this, 'print_text_ldap_attr_email' ), | |
| 2804 | - 'authorizer', | |
| 2805 | - 'auth_settings_external' | |
| 2399 | + 'auth_settings_ldap_attr_email', // HTML element ID | |
| 2400 | + __( 'LDAP attribute containing email address', 'authorizer' ), // HTML element Title | |
| 2401 | + array( $this, 'print_text_ldap_attr_email' ), // Callback (echos form element) | |
| 2402 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2403 | + 'auth_settings_external' // Section this setting is shown on | |
| 2806 | 2404 | ); |
| 2807 | 2405 | add_settings_field( |
| 2808 | - 'auth_settings_ldap_user', | |
| 2809 | - __( 'LDAP Directory User', 'authorizer' ), | |
| 2810 | - array( $this, 'print_text_ldap_user' ), | |
| 2811 | - 'authorizer', | |
| 2812 | - 'auth_settings_external' | |
| 2406 | + 'auth_settings_ldap_user', // HTML element ID | |
| 2407 | + __( 'LDAP Directory User', 'authorizer' ), // HTML element Title | |
| 2408 | + array( $this, 'print_text_ldap_user' ), // Callback (echos form element) | |
| 2409 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2410 | + 'auth_settings_external' // Section this setting is shown on | |
| 2813 | 2411 | ); |
| 2814 | 2412 | add_settings_field( |
| 2815 | - 'auth_settings_ldap_password', | |
| 2816 | - __( 'LDAP Directory User Password', 'authorizer' ), | |
| 2817 | - array( $this, 'print_password_ldap_password' ), | |
| 2818 | - 'authorizer', | |
| 2819 | - 'auth_settings_external' | |
| 2413 | + 'auth_settings_ldap_password', // HTML element ID | |
| 2414 | + __( 'LDAP Directory User Password', 'authorizer' ), // HTML element Title | |
| 2415 | + array( $this, 'print_password_ldap_password' ), // Callback (echos form element) | |
| 2416 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2417 | + 'auth_settings_external' // Section this setting is shown on | |
| 2820 | 2418 | ); |
| 2821 | 2419 | add_settings_field( |
| 2822 | - 'auth_settings_ldap_lostpassword_url', | |
| 2823 | - __( 'Custom lost password URL', 'authorizer' ), | |
| 2824 | - array( $this, 'print_text_ldap_lostpassword_url' ), | |
| 2825 | - 'authorizer', | |
| 2826 | - 'auth_settings_external' | |
| 2420 | + 'auth_settings_ldap_lostpassword_url', // HTML element ID | |
| 2421 | + __( 'Custom lost password URL', 'authorizer' ), // HTML element Title | |
| 2422 | + array( $this, 'print_text_ldap_lostpassword_url' ), // Callback (echos form element) | |
| 2423 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2424 | + 'auth_settings_external' // Section this setting is shown on | |
| 2827 | 2425 | ); |
| 2828 | 2426 | add_settings_field( |
| 2829 | - 'auth_settings_ldap_attr_first_name', | |
| 2830 | - __( 'LDAP attribute containing first name', 'authorizer' ), | |
| 2831 | - array( $this, 'print_text_ldap_attr_first_name' ), | |
| 2832 | - 'authorizer', | |
| 2833 | - 'auth_settings_external' | |
| 2427 | + 'auth_settings_ldap_attr_first_name', // HTML element ID | |
| 2428 | + __( 'LDAP attribute containing first name', 'authorizer' ), // HTML element Title | |
| 2429 | + array( $this, 'print_text_ldap_attr_first_name' ), // Callback (echos form element) | |
| 2430 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2431 | + 'auth_settings_external' // Section this setting is shown on | |
| 2834 | 2432 | ); |
| 2835 | 2433 | add_settings_field( |
| 2836 | - 'auth_settings_ldap_attr_last_name', | |
| 2837 | - __( 'LDAP attribute containing last name', 'authorizer' ), | |
| 2838 | - array( $this, 'print_text_ldap_attr_last_name' ), | |
| 2839 | - 'authorizer', | |
| 2840 | - 'auth_settings_external' | |
| 2434 | + 'auth_settings_ldap_attr_last_name', // HTML element ID | |
| 2435 | + __( 'LDAP attribute containing last name', 'authorizer' ), // HTML element Title | |
| 2436 | + array( $this, 'print_text_ldap_attr_last_name' ), // Callback (echos form element) | |
| 2437 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2438 | + 'auth_settings_external' // Section this setting is shown on | |
| 2841 | 2439 | ); |
| 2842 | 2440 | add_settings_field( |
| 2843 | - 'auth_settings_ldap_attr_update_on_login', | |
| 2844 | - __( 'LDAP attribute update', 'authorizer' ), | |
| 2845 | - array( $this, 'print_checkbox_ldap_attr_update_on_login' ), | |
| 2846 | - 'authorizer', | |
| 2847 | - 'auth_settings_external' | |
| 2441 | + 'auth_settings_ldap_attr_update_on_login', // HTML element ID | |
| 2442 | + __( 'LDAP attribute update', 'authorizer' ), // HTML element Title | |
| 2443 | + array( $this, 'print_checkbox_ldap_attr_update_on_login' ), // Callback (echos form element) | |
| 2444 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2445 | + 'auth_settings_external' // Section this setting is shown on | |
| 2848 | 2446 | ); |
| 2849 | 2447 | |
| 2850 | - // Create Advanced Settings section. | |
| 2448 | + // Create Advanced Settings section | |
| 2851 | 2449 | add_settings_section( |
| 2852 | - 'auth_settings_advanced', | |
| 2853 | - '', | |
| 2854 | - array( $this, 'print_section_info_advanced' ), | |
| 2855 | - 'authorizer' | |
| 2450 | + 'auth_settings_advanced', // HTML element ID | |
| 2451 | + '', // HTML element Title | |
| 2452 | + array( $this, 'print_section_info_advanced' ), // Callback (echos section content) | |
| 2453 | + 'authorizer' // Page this section is shown on (slug) | |
| 2856 | 2454 | ); |
| 2857 | 2455 | add_settings_field( |
| 2858 | - 'auth_settings_advanced_lockouts', | |
| 2859 | - __( 'Limit invalid login attempts', 'authorizer' ), | |
| 2860 | - array( $this, 'print_text_auth_advanced_lockouts' ), | |
| 2861 | - 'authorizer', | |
| 2862 | - 'auth_settings_advanced' | |
| 2456 | + 'auth_settings_advanced_lockouts', // HTML element ID | |
| 2457 | + __( 'Limit invalid login attempts', 'authorizer' ), // HTML element Title | |
| 2458 | + array( $this, 'print_text_auth_advanced_lockouts' ), // Callback (echos form element) | |
| 2459 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2460 | + 'auth_settings_advanced' // Section this setting is shown on | |
| 2863 | 2461 | ); |
| 2864 | 2462 | add_settings_field( |
| 2865 | - 'auth_settings_advanced_hide_wp_login', | |
| 2866 | - __( 'Hide WordPress Login', 'authorizer' ), | |
| 2867 | - array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ), | |
| 2868 | - 'authorizer', | |
| 2869 | - 'auth_settings_advanced' | |
| 2463 | + 'auth_settings_advanced_hide_wp_login', // HTML element ID | |
| 2464 | + __( 'Hide WordPress Login', 'authorizer' ), // HTML element Title | |
| 2465 | + array( $this, 'print_checkbox_auth_advanced_hide_wp_login' ), // Callback (echos form element) | |
| 2466 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2467 | + 'auth_settings_advanced' // Section this setting is shown on | |
| 2870 | 2468 | ); |
| 2871 | 2469 | add_settings_field( |
| 2872 | - 'auth_settings_advanced_branding', | |
| 2873 | - __( 'Custom WordPress login branding', 'authorizer' ), | |
| 2874 | - array( $this, 'print_radio_auth_advanced_branding' ), | |
| 2875 | - 'authorizer', | |
| 2876 | - 'auth_settings_advanced' | |
| 2470 | + 'auth_settings_advanced_branding', // HTML element ID | |
| 2471 | + __( 'Custom WordPress login branding', 'authorizer' ), // HTML element Title | |
| 2472 | + array( $this, 'print_radio_auth_advanced_branding' ), // Callback (echos form element) | |
| 2473 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2474 | + 'auth_settings_advanced' // Section this setting is shown on | |
| 2877 | 2475 | ); |
| 2878 | 2476 | add_settings_field( |
| 2879 | - 'auth_settings_advanced_admin_menu', | |
| 2880 | - __( 'Authorizer admin menu item location', 'authorizer' ), | |
| 2881 | - array( $this, 'print_radio_auth_advanced_admin_menu' ), | |
| 2882 | - 'authorizer', | |
| 2883 | - 'auth_settings_advanced' | |
| 2477 | + 'auth_settings_advanced_admin_menu', // HTML element ID | |
| 2478 | + __( 'Authorizer admin menu item location', 'authorizer' ), // HTML element Title | |
| 2479 | + array( $this, 'print_radio_auth_advanced_admin_menu' ), // Callback (echos form element) | |
| 2480 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2481 | + 'auth_settings_advanced' // Section this setting is shown on | |
| 2884 | 2482 | ); |
| 2885 | 2483 | add_settings_field( |
| 2886 | - 'auth_settings_advanced_usermeta', | |
| 2887 | - __( 'Show custom usermeta in user list', 'authorizer' ), | |
| 2888 | - array( $this, 'print_select_auth_advanced_usermeta' ), | |
| 2889 | - 'authorizer', | |
| 2890 | - 'auth_settings_advanced' | |
| 2484 | + 'auth_settings_advanced_usermeta', // HTML element ID | |
| 2485 | + __( 'Show custom usermeta in user list', 'authorizer' ), // HTML element Title | |
| 2486 | + array( $this, 'print_select_auth_advanced_usermeta' ), // Callback (echos form element) | |
| 2487 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2488 | + 'auth_settings_advanced' // Section this setting is shown on | |
| 2891 | 2489 | ); |
| 2892 | - add_settings_field( | |
| 2893 | - 'auth_settings_advanced_users_per_page', | |
| 2894 | - __( 'Number of users per page', 'authorizer' ), | |
| 2895 | - array( $this, 'print_text_auth_advanced_users_per_page' ), | |
| 2896 | - 'authorizer', | |
| 2897 | - 'auth_settings_advanced' | |
| 2898 | - ); | |
| 2899 | - add_settings_field( | |
| 2900 | - 'auth_settings_advanced_users_sort_by', | |
| 2901 | - __( 'Approved users sort method', 'authorizer' ), | |
| 2902 | - array( $this, 'print_select_auth_advanced_users_sort_by' ), | |
| 2903 | - 'authorizer', | |
| 2904 | - 'auth_settings_advanced' | |
| 2905 | - ); | |
| 2906 | - add_settings_field( | |
| 2907 | - 'auth_settings_advanced_users_sort_order', | |
| 2908 | - __( 'Approved users sort order', 'authorizer' ), | |
| 2909 | - array( $this, 'print_select_auth_advanced_users_sort_order' ), | |
| 2910 | - 'authorizer', | |
| 2911 | - 'auth_settings_advanced' | |
| 2912 | - ); | |
| 2913 | - add_settings_field( | |
| 2914 | - 'auth_settings_advanced_widget_enabled', | |
| 2915 | - __( 'Show dashboard widget to admin users', 'authorizer' ), | |
| 2916 | - array( $this, 'print_checkbox_auth_advanced_widget_enabled' ), | |
| 2917 | - 'authorizer', | |
| 2918 | - 'auth_settings_advanced' | |
| 2919 | - ); | |
| 2920 | 2490 | // On multisite installs, add an option to override all multisite settings on individual sites. |
| 2921 | 2491 | if ( is_multisite() ) { |
| 2922 | 2492 | add_settings_field( |
| 2923 | - 'auth_settings_advanced_override_multisite', | |
| 2924 | - __( 'Override multisite options', 'authorizer' ), | |
| 2925 | - array( $this, 'print_checkbox_auth_advanced_override_multisite' ), | |
| 2926 | - 'authorizer', | |
| 2927 | - 'auth_settings_advanced' | |
| 2493 | + 'auth_settings_advanced_override_multisite', // HTML element ID | |
| 2494 | + __( 'Override multisite options', 'authorizer' ), // HTML element Title | |
| 2495 | + array( $this, 'print_checkbox_auth_advanced_override_multisite' ), // Callback (echos form element) | |
| 2496 | + 'authorizer', // Page this setting is shown on (slug) | |
| 2497 | + 'auth_settings_advanced' // Section this setting is shown on | |
| 2928 | 2498 | ); |
| 2929 | 2499 | } |
| 2930 | 2500 | } |
| 2931 | 2501 | |
| @@ -2931,30 +2501,29 @@ | ||
| 2931 | 2501 | |
| 2932 | 2502 | |
| 2933 | 2503 | /** |
| 2934 | 2504 | * Set meaningful defaults for the plugin options. |
| 2935 | - * | |
| 2936 | 2505 | * Note: This function is called on plugin activation. |
| 2937 | 2506 | */ |
| 2938 | - private function set_default_options() { | |
| 2507 | + function set_default_options() { | |
| 2939 | 2508 | global $wp_roles; |
| 2940 | 2509 | |
| 2941 | 2510 | $auth_settings = get_option( 'auth_settings' ); |
| 2942 | - if ( false === $auth_settings ) { | |
| 2511 | + if ( $auth_settings === FALSE ) { | |
| 2943 | 2512 | $auth_settings = array(); |
| 2944 | 2513 | } |
| 2945 | 2514 | |
| 2946 | 2515 | // Access Lists Defaults. |
| 2947 | 2516 | $auth_settings_access_users_pending = get_option( 'auth_settings_access_users_pending' ); |
| 2948 | - if ( false === $auth_settings_access_users_pending ) { | |
| 2517 | + if ( $auth_settings_access_users_pending === FALSE ) { | |
| 2949 | 2518 | $auth_settings_access_users_pending = array(); |
| 2950 | 2519 | } |
| 2951 | 2520 | $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' ); |
| 2952 | - if ( false === $auth_settings_access_users_approved ) { | |
| 2521 | + if ( $auth_settings_access_users_approved === FALSE ) { | |
| 2953 | 2522 | $auth_settings_access_users_approved = array(); |
| 2954 | 2523 | } |
| 2955 | 2524 | $auth_settings_access_users_blocked = get_option( 'auth_settings_access_users_blocked' ); |
| 2956 | - if ( false === $auth_settings_access_users_blocked ) { | |
| 2525 | + if ( $auth_settings_access_users_blocked === FALSE ) { | |
| 2957 | 2526 | $auth_settings_access_users_blocked = array(); |
| 2958 | 2527 | } |
| 2959 | 2528 | |
| 2960 | 2529 | // Login Access Defaults. |
| @@ -3006,12 +2575,13 @@ | ||
| 3006 | 2575 | if ( ! array_key_exists( 'access_redirect_to_message', $auth_settings ) ) { |
| 3007 | 2576 | $auth_settings['access_redirect_to_message'] = '<p>' . __( 'Notice: You are browsing this site anonymously, and only have access to a portion of its content.', 'authorizer' ) . '</p>'; |
| 3008 | 2577 | } |
| 3009 | 2578 | |
| 2579 | + | |
| 3010 | 2580 | // External Service Defaults. |
| 3011 | 2581 | if ( ! array_key_exists( 'access_default_role', $auth_settings ) ) { |
| 3012 | 2582 | // Set default role to 'student' if that role exists, 'subscriber' otherwise. |
| 3013 | - $all_roles = $wp_roles->roles; | |
| 2583 | + $all_roles = $wp_roles->roles; | |
| 3014 | 2584 | $editable_roles = apply_filters( 'editable_roles', $all_roles ); |
| 3015 | 2585 | if ( array_key_exists( 'student', $editable_roles ) ) { |
| 3016 | 2586 | $auth_settings['access_default_role'] = 'student'; |
| 3017 | 2587 | } else { |
| @@ -3109,12 +2679,12 @@ | ||
| 3109 | 2679 | |
| 3110 | 2680 | // Advanced defaults. |
| 3111 | 2681 | if ( ! array_key_exists( 'advanced_lockouts', $auth_settings ) ) { |
| 3112 | 2682 | $auth_settings['advanced_lockouts'] = array( |
| 3113 | - 'attempts_1' => 10, | |
| 3114 | - 'duration_1' => 1, | |
| 3115 | - 'attempts_2' => 10, | |
| 3116 | - 'duration_2' => 10, | |
| 2683 | + 'attempts_1' => 10, | |
| 2684 | + 'duration_1' => 1, | |
| 2685 | + 'attempts_2' => 10, | |
| 2686 | + 'duration_2' => 10, | |
| 3117 | 2687 | 'reset_duration' => 120, |
| 3118 | 2688 | ); |
| 3119 | 2689 | } |
| 3120 | 2690 | if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_settings ) ) { |
| @@ -3128,20 +2698,8 @@ | ||
| 3128 | 2698 | } |
| 3129 | 2699 | if ( ! array_key_exists( 'advanced_usermeta', $auth_settings ) ) { |
| 3130 | 2700 | $auth_settings['advanced_usermeta'] = ''; |
| 3131 | 2701 | } |
| 3132 | - if ( ! array_key_exists( 'advanced_users_per_page', $auth_settings ) ) { | |
| 3133 | - $auth_settings['advanced_users_per_page'] = 20; | |
| 3134 | - } | |
| 3135 | - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_settings ) ) { | |
| 3136 | - $auth_settings['advanced_users_sort_by'] = 'created'; | |
| 3137 | - } | |
| 3138 | - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_settings ) ) { | |
| 3139 | - $auth_settings['advanced_users_sort_order'] = 'asc'; | |
| 3140 | - } | |
| 3141 | - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_settings ) ) { | |
| 3142 | - $auth_settings['advanced_widget_enabled'] = '1'; | |
| 3143 | - } | |
| 3144 | 2702 | if ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) ) { |
| 3145 | 2703 | $auth_settings['advanced_override_multisite'] = ''; |
| 3146 | 2704 | } |
| 3147 | 2705 | |
| @@ -3152,11 +2710,11 @@ | ||
| 3152 | 2710 | update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked ); |
| 3153 | 2711 | |
| 3154 | 2712 | // Multisite defaults. |
| 3155 | 2713 | if ( is_multisite() ) { |
| 3156 | - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() ); | |
| 2714 | + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); | |
| 3157 | 2715 | |
| 3158 | - if ( false === $auth_multisite_settings ) { | |
| 2716 | + if ( $auth_multisite_settings === FALSE ) { | |
| 3159 | 2717 | $auth_multisite_settings = array(); |
| 3160 | 2718 | } |
| 3161 | 2719 | // Global switch for enabling multisite options. |
| 3162 | 2720 | if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) { |
| @@ -3162,10 +2720,10 @@ | ||
| 3162 | 2720 | if ( ! array_key_exists( 'multisite_override', $auth_multisite_settings ) ) { |
| 3163 | 2721 | $auth_multisite_settings['multisite_override'] = ''; |
| 3164 | 2722 | } |
| 3165 | 2723 | // Access Lists Defaults. |
| 3166 | - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved' ); | |
| 3167 | - if ( false === $auth_multisite_settings_access_users_approved ) { | |
| 2724 | + $auth_multisite_settings_access_users_approved = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved' ); | |
| 2725 | + if ( $auth_multisite_settings_access_users_approved === FALSE ) { | |
| 3168 | 2726 | $auth_multisite_settings_access_users_approved = array(); |
| 3169 | 2727 | } |
| 3170 | 2728 | // Login Access Defaults. |
| 3171 | 2729 | if ( ! array_key_exists( 'access_who_can_login', $auth_multisite_settings ) ) { |
| @@ -3177,9 +2735,9 @@ | ||
| 3177 | 2735 | } |
| 3178 | 2736 | // External Service Defaults. |
| 3179 | 2737 | if ( ! array_key_exists( 'access_default_role', $auth_multisite_settings ) ) { |
| 3180 | 2738 | // Set default role to 'student' if that role exists, 'subscriber' otherwise. |
| 3181 | - $all_roles = $wp_roles->roles; | |
| 2739 | + $all_roles = $wp_roles->roles; | |
| 3182 | 2740 | $editable_roles = apply_filters( 'editable_roles', $all_roles ); |
| 3183 | 2741 | if ( array_key_exists( 'student', $editable_roles ) ) { |
| 3184 | 2742 | $auth_multisite_settings['access_default_role'] = 'student'; |
| 3185 | 2743 | } else { |
| @@ -3272,12 +2830,12 @@ | ||
| 3272 | 2830 | } |
| 3273 | 2831 | // Advanced defaults. |
| 3274 | 2832 | if ( ! array_key_exists( 'advanced_lockouts', $auth_multisite_settings ) ) { |
| 3275 | 2833 | $auth_multisite_settings['advanced_lockouts'] = array( |
| 3276 | - 'attempts_1' => 10, | |
| 3277 | - 'duration_1' => 1, | |
| 3278 | - 'attempts_2' => 10, | |
| 3279 | - 'duration_2' => 10, | |
| 2834 | + 'attempts_1' => 10, | |
| 2835 | + 'duration_1' => 1, | |
| 2836 | + 'attempts_2' => 10, | |
| 2837 | + 'duration_2' => 10, | |
| 3280 | 2838 | 'reset_duration' => 120, |
| 3281 | 2839 | ); |
| 3282 | 2840 | } |
| 3283 | 2841 | if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) { |
| @@ -3282,23 +2840,11 @@ | ||
| 3282 | 2840 | } |
| 3283 | 2841 | if ( ! array_key_exists( 'advanced_hide_wp_login', $auth_multisite_settings ) ) { |
| 3284 | 2842 | $auth_multisite_settings['advanced_hide_wp_login'] = ''; |
| 3285 | 2843 | } |
| 3286 | - if ( ! array_key_exists( 'advanced_users_per_page', $auth_multisite_settings ) ) { | |
| 3287 | - $auth_multisite_settings['advanced_users_per_page'] = 20; | |
| 3288 | - } | |
| 3289 | - if ( ! array_key_exists( 'advanced_users_sort_by', $auth_multisite_settings ) ) { | |
| 3290 | - $auth_multisite_settings['advanced_users_sort_by'] = 'created'; | |
| 3291 | - } | |
| 3292 | - if ( ! array_key_exists( 'advanced_users_sort_order', $auth_multisite_settings ) ) { | |
| 3293 | - $auth_multisite_settings['advanced_users_sort_order'] = 'asc'; | |
| 3294 | - } | |
| 3295 | - if ( ! array_key_exists( 'advanced_widget_enabled', $auth_multisite_settings ) ) { | |
| 3296 | - $auth_multisite_settings['advanced_widget_enabled'] = '1'; | |
| 3297 | - } | |
| 3298 | 2844 | // Save default network options to database. |
| 3299 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 3300 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 2845 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 2846 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 3301 | 2847 | } |
| 3302 | 2848 | |
| 3303 | 2849 | return $auth_settings; |
| 3304 | 2850 | } |
| @@ -3305,15 +2851,12 @@ | ||
| 3305 | 2851 | |
| 3306 | 2852 | |
| 3307 | 2853 | /** |
| 3308 | 2854 | * List sanitizer. |
| 3309 | - * | |
| 3310 | - * @param array $list Array of users to sanitize. | |
| 3311 | - * @param string $side_effect Set to 'update roles' if role syncing should be performed. | |
| 3312 | - * @param string $multisite_mode Set to 'multisite' to sync roles on all sites the user belongs to. | |
| 3313 | - * @return array Array of sanitized users. | |
| 2855 | + * $side_effect = 'none' or 'update roles' to make sure WP user roles match | |
| 2856 | + * $multisite_mode = 'single' or 'multisite' to indicate which user roles to change (this site or all sites) | |
| 3314 | 2857 | */ |
| 3315 | - private function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) { | |
| 2858 | + function sanitize_user_list( $list, $side_effect = 'none', $multisite_mode = 'single' ) { | |
| 3316 | 2859 | // If it's not a list, make it so. |
| 3317 | 2860 | if ( ! is_array( $list ) ) { |
| 3318 | 2861 | $list = array(); |
| 3319 | 2862 | } |
| @@ -3318,16 +2861,16 @@ | ||
| 3318 | 2861 | $list = array(); |
| 3319 | 2862 | } |
| 3320 | 2863 | foreach ( $list as $key => $user_info ) { |
| 3321 | 2864 | if ( strlen( $user_info['email'] ) < 1 ) { |
| 3322 | - // Make sure there are no empty entries in the list. | |
| 3323 | - unset( $list[ $key ] ); | |
| 3324 | - } elseif ( 'update roles' === $side_effect ) { | |
| 2865 | + // Make sure there are no empty entries in the list | |
| 2866 | + unset( $list[$key] ); | |
| 2867 | + } elseif ( $side_effect === 'update roles' ) { | |
| 3325 | 2868 | // Make sure the WordPress user accounts have the same role |
| 3326 | 2869 | // as that indicated in the list. |
| 3327 | 2870 | $wp_user = get_user_by( 'email', $user_info['email'] ); |
| 3328 | 2871 | if ( $wp_user ) { |
| 3329 | - if ( is_multisite() && 'multisite' === $multisite_mode ) { | |
| 2872 | + if ( is_multisite() && $multisite_mode === 'multisite' ) { | |
| 3330 | 2873 | foreach ( get_blogs_of_user( $wp_user->ID ) as $blog ) { |
| 3331 | 2874 | add_user_to_blog( $blog->userblog_id, $wp_user->ID, $user_info['role'] ); |
| 3332 | 2875 | } |
| 3333 | 2876 | } else { |
| @@ -3340,21 +2883,18 @@ | ||
| 3340 | 2883 | } |
| 3341 | 2884 | |
| 3342 | 2885 | |
| 3343 | 2886 | /** |
| 3344 | - * Settings sanitizer callback. | |
| 3345 | - * | |
| 3346 | - * @param array $auth_settings Authorizer settings array. | |
| 3347 | - * @return array Sanitized Authorizer settings array. | |
| 2887 | + * Settings sanitizer callback | |
| 3348 | 2888 | */ |
| 3349 | - public function sanitize_options( $auth_settings ) { | |
| 2889 | + function sanitize_options( $auth_settings ) { | |
| 3350 | 2890 | // Default to "Approved Users" login access restriction. |
| 3351 | - if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ), true ) ) { | |
| 2891 | + if ( ! in_array( $auth_settings['access_who_can_login'], array( 'external_users', 'approved_users' ) ) ) { | |
| 3352 | 2892 | $auth_settings['access_who_can_login'] = 'approved_users'; |
| 3353 | 2893 | } |
| 3354 | 2894 | |
| 3355 | 2895 | // Default to "Everyone" view access restriction. |
| 3356 | - if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ), true ) ) { | |
| 2896 | + if ( ! in_array( $auth_settings['access_who_can_view'], array( 'everyone', 'logged_in_users' ) ) ) { | |
| 3357 | 2897 | $auth_settings['access_who_can_view'] = 'everyone'; |
| 3358 | 2898 | } |
| 3359 | 2899 | |
| 3360 | 2900 | // Default to WordPress login access redirect. |
| @@ -3359,9 +2899,9 @@ | ||
| 3359 | 2899 | |
| 3360 | 2900 | // Default to WordPress login access redirect. |
| 3361 | 2901 | // Note: this option doesn't exist in multisite options, so we first |
| 3362 | 2902 | // check to see if it exists. |
| 3363 | - if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ), true ) ) { | |
| 2903 | + if ( array_key_exists( 'access_redirect', $auth_settings ) && ! in_array( $auth_settings['access_redirect'], array( 'login', 'page', 'message' ) ) ) { | |
| 3364 | 2904 | $auth_settings['access_redirect'] = 'login'; |
| 3365 | 2905 | } |
| 3366 | 2906 | |
| 3367 | 2907 | // Default to warning message for anonymous users on public pages. |
| @@ -3366,61 +2906,61 @@ | ||
| 3366 | 2906 | |
| 3367 | 2907 | // Default to warning message for anonymous users on public pages. |
| 3368 | 2908 | // Note: this option doesn't exist in multisite options, so we first |
| 3369 | 2909 | // check to see if it exists. |
| 3370 | - if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ), true ) ) { | |
| 2910 | + if ( array_key_exists( 'access_public_warning', $auth_settings ) && ! in_array( $auth_settings['access_public_warning'], array( 'no_warning', 'warning' ) ) ) { | |
| 3371 | 2911 | $auth_settings['access_public_warning'] = 'no_warning'; |
| 3372 | 2912 | } |
| 3373 | 2913 | |
| 3374 | - // Sanitize Send welcome email (checkbox: value can only be '1' or empty string). | |
| 2914 | + // Sanitize Send welcome email (checkbox: value can only be '1' or empty string) | |
| 3375 | 2915 | $auth_settings['access_should_email_approved_users'] = array_key_exists( 'access_should_email_approved_users', $auth_settings ) && strlen( $auth_settings['access_should_email_approved_users'] ) > 0 ? '1' : ''; |
| 3376 | 2916 | |
| 3377 | - // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string). | |
| 2917 | + // Sanitize Enable Google Logins (checkbox: value can only be '1' or empty string) | |
| 3378 | 2918 | $auth_settings['google'] = array_key_exists( 'google', $auth_settings ) && strlen( $auth_settings['google'] ) > 0 ? '1' : ''; |
| 3379 | 2919 | |
| 3380 | - // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string). | |
| 2920 | + // Sanitize Enable CAS Logins (checkbox: value can only be '1' or empty string) | |
| 3381 | 2921 | $auth_settings['cas'] = array_key_exists( 'cas', $auth_settings ) && strlen( $auth_settings['cas'] ) > 0 ? '1' : ''; |
| 3382 | 2922 | |
| 3383 | - // Sanitize CAS Host setting. | |
| 2923 | + // Sanitize CAS Host setting | |
| 3384 | 2924 | $auth_settings['cas_host'] = filter_var( $auth_settings['cas_host'], FILTER_SANITIZE_URL ); |
| 3385 | 2925 | |
| 3386 | - // Sanitize CAS Port (int). | |
| 2926 | + // Sanitize CAS Port (int) | |
| 3387 | 2927 | $auth_settings['cas_port'] = filter_var( $auth_settings['cas_port'], FILTER_SANITIZE_NUMBER_INT ); |
| 3388 | 2928 | |
| 3389 | - // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string). | |
| 2929 | + // Sanitize CAS attribute update (checkbox: value can only be '1' or empty string) | |
| 3390 | 2930 | $auth_settings['cas_attr_update_on_login'] = array_key_exists( 'cas_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['cas_attr_update_on_login'] ) > 0 ? '1' : ''; |
| 3391 | 2931 | |
| 3392 | - // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string). | |
| 2932 | + // Sanitize CAS auto-login (checkbox: value can only be '1' or empty string) | |
| 3393 | 2933 | $auth_settings['cas_auto_login'] = array_key_exists( 'cas_auto_login', $auth_settings ) && strlen( $auth_settings['cas_auto_login'] ) > 0 ? '1' : ''; |
| 3394 | 2934 | |
| 3395 | - // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string). | |
| 2935 | + // Sanitize Enable LDAP Logins (checkbox: value can only be '1' or empty string) | |
| 3396 | 2936 | $auth_settings['ldap'] = array_key_exists( 'ldap', $auth_settings ) && strlen( $auth_settings['ldap'] ) > 0 ? '1' : ''; |
| 3397 | 2937 | |
| 3398 | - // Sanitize LDAP Host setting. | |
| 2938 | + // Sanitize LDAP Host setting | |
| 3399 | 2939 | $auth_settings['ldap_host'] = filter_var( $auth_settings['ldap_host'], FILTER_SANITIZE_URL ); |
| 3400 | 2940 | |
| 3401 | - // Sanitize LDAP Port (int). | |
| 2941 | + // Sanitize LDAP Port (int) | |
| 3402 | 2942 | $auth_settings['ldap_port'] = filter_var( $auth_settings['ldap_port'], FILTER_SANITIZE_NUMBER_INT ); |
| 3403 | 2943 | |
| 3404 | - // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string). | |
| 2944 | + // Sanitize LDAP TLS (checkbox: value can only be '1' or empty string) | |
| 3405 | 2945 | $auth_settings['ldap_tls'] = array_key_exists( 'ldap_tls', $auth_settings ) && strlen( $auth_settings['ldap_tls'] ) > 0 ? '1' : ''; |
| 3406 | 2946 | |
| 3407 | - // Sanitize LDAP attributes (basically make sure they don't have any parentheses). | |
| 2947 | + // Sanitize LDAP attributes (basically make sure they don't have any parentheses) | |
| 3408 | 2948 | $auth_settings['ldap_uid'] = filter_var( $auth_settings['ldap_uid'], FILTER_SANITIZE_EMAIL ); |
| 3409 | 2949 | |
| 3410 | - // Sanitize LDAP Lost Password URL. | |
| 2950 | + // Sanitize LDAP Lost Password URL | |
| 3411 | 2951 | $auth_settings['ldap_lostpassword_url'] = filter_var( $auth_settings['ldap_lostpassword_url'], FILTER_SANITIZE_URL ); |
| 3412 | 2952 | |
| 3413 | - // Obfuscate LDAP directory user password. | |
| 2953 | + // Obfuscate LDAP directory user password | |
| 3414 | 2954 | if ( strlen( $auth_settings['ldap_password'] ) > 0 ) { |
| 3415 | 2955 | // encrypt the directory user password for some minor obfuscation in the database. |
| 3416 | - $auth_settings['ldap_password'] = $this->encrypt( $auth_settings['ldap_password'] ); | |
| 2956 | + $auth_settings['ldap_password'] = base64_encode( $this->encrypt( $auth_settings['ldap_password'] ) ); | |
| 3417 | 2957 | } |
| 3418 | 2958 | |
| 3419 | - // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string). | |
| 2959 | + // Sanitize LDAP attribute update (checkbox: value can only be '1' or empty string) | |
| 3420 | 2960 | $auth_settings['ldap_attr_update_on_login'] = array_key_exists( 'ldap_attr_update_on_login', $auth_settings ) && strlen( $auth_settings['ldap_attr_update_on_login'] ) > 0 ? '1' : ''; |
| 3421 | 2961 | |
| 3422 | - // Make sure public pages is an empty array if it's empty. | |
| 2962 | + // Make sure public pages is an empty array if it's empty | |
| 3423 | 2963 | // Note: this option doesn't exist in multisite options, so we first |
| 3424 | 2964 | // check to see if it exists. |
| 3425 | 2965 | if ( array_key_exists( 'access_public_pages', $auth_settings ) && ! is_array( $auth_settings['access_public_pages'] ) ) { |
| 3426 | 2966 | $auth_settings['access_public_pages'] = array(); |
| @@ -3428,31 +2968,15 @@ | ||
| 3428 | 2968 | |
| 3429 | 2969 | // Make sure all lockout options are integers (attempts_1, |
| 3430 | 2970 | // duration_1, attempts_2, duration_2, reset_duration). |
| 3431 | 2971 | foreach ( $auth_settings['advanced_lockouts'] as $key => $value ) { |
| 3432 | - $auth_settings['advanced_lockouts'][ $key ] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT ); | |
| 2972 | + $auth_settings['advanced_lockouts'][$key] = filter_var( $value, FILTER_SANITIZE_NUMBER_INT ); | |
| 3433 | 2973 | } |
| 3434 | 2974 | |
| 3435 | - // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string). | |
| 2975 | + // Sanitize Hide WordPress logins (checkbox: value can only be '1' or empty string) | |
| 3436 | 2976 | $auth_settings['advanced_hide_wp_login'] = array_key_exists( 'advanced_hide_wp_login', $auth_settings ) && strlen( $auth_settings['advanced_hide_wp_login'] ) > 0 ? '1' : ''; |
| 3437 | 2977 | |
| 3438 | - // Sanitize Users per page (text: value can only int from 1 to MAX_INT). | |
| 3439 | - $auth_settings['advanced_users_per_page'] = array_key_exists( 'advanced_users_per_page', $auth_settings ) && intval( $auth_settings['advanced_users_per_page'] ) > 0 ? intval( $auth_settings['advanced_users_per_page'] ) : 1; | |
| 3440 | - | |
| 3441 | - // Sanitize Sort users by (select: value can be 'email', 'role', 'date_added', 'created'). | |
| 3442 | - if ( ! isset( $auth_settings['advanced_users_sort_by'] ) || ! in_array( $auth_settings['advanced_users_sort_by'], array( 'email', 'role', 'date_added', 'created' ), true ) ) { | |
| 3443 | - $auth_settings['advanced_users_sort_by'] = 'created'; | |
| 3444 | - } | |
| 3445 | - | |
| 3446 | - // Sanitize Sort users order (select: value can be 'asc', 'desc'). | |
| 3447 | - if ( ! isset( $auth_settings['advanced_users_sort_order'] ) || ! in_array( $auth_settings['advanced_users_sort_order'], array( 'asc', 'desc' ), true ) ) { | |
| 3448 | - $auth_settings['advanced_users_sort_order'] = 'asc'; | |
| 3449 | - } | |
| 3450 | - | |
| 3451 | - // Sanitize Show Dashboard Widget (checkbox: value can only be '1' or empty string). | |
| 3452 | - $auth_settings['advanced_widget_enabled'] = array_key_exists( 'advanced_widget_enabled', $auth_settings ) && strlen( $auth_settings['advanced_widget_enabled'] ) > 0 ? '1' : ''; | |
| 3453 | - | |
| 3454 | - // Sanitize Override multisite options (checkbox: value can only be '1' or empty string). | |
| 2978 | + // Sanitize Override multisite options (checkbox: value can only be '1' or empty string) | |
| 3455 | 2979 | $auth_settings['advanced_override_multisite'] = array_key_exists( 'advanced_override_multisite', $auth_settings ) && strlen( $auth_settings['advanced_override_multisite'] ) > 0 ? '1' : ''; |
| 3456 | 2980 | |
| 3457 | 2981 | return $auth_settings; |
| 3458 | 2982 | } |
| @@ -3459,201 +2983,90 @@ | ||
| 3459 | 2983 | |
| 3460 | 2984 | |
| 3461 | 2985 | /** |
| 3462 | 2986 | * Keep authorizer approved users' roles in sync with WordPress roles |
| 3463 | - * if someone changes the role via the WordPress Edit User page | |
| 3464 | - * (wp-admin/user-edit.php or wp-admin/profile.php). | |
| 2987 | + * if someone changes the role via the WordPress Edit User options page. | |
| 3465 | 2988 | * |
| 3466 | - * Action: user_profile_update_errors | |
| 3467 | - * | |
| 3468 | - * @param WP_Error $errors Errors object to add any custom errors to (passed by reference). | |
| 3469 | - * @param bool $update True if updating existing user, false if saving a new one. | |
| 3470 | - * @param stdClass $user Updated WP_User object for user being edited (passed by reference). | |
| 2989 | + * @action edit_user_profile_update | |
| 2990 | + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/edit_user_profile_update | |
| 2991 | + * @param int $user_id The user ID of the user being edited | |
| 2992 | + | |
| 2993 | + * @action personal_options_update | |
| 2994 | + * @ref https://codex.wordpress.org/Plugin_API/Action_Reference/personal_options_update | |
| 2995 | + * @param int $user_id The user ID of the user being edited | |
| 3471 | 2996 | */ |
| 3472 | - public function edit_user_profile_update_role( &$errors, $update, &$user ) { | |
| 3473 | - // Do nothing if we're not updating role. | |
| 3474 | - if ( ! property_exists( $user, 'role' ) ) { | |
| 2997 | + function edit_user_profile_update_role( $user_id ) { | |
| 2998 | + if ( ! current_user_can( 'edit_user', $user_id ) ) { | |
| 3475 | 2999 | return; |
| 3476 | 3000 | } |
| 3477 | 3001 | |
| 3478 | - // Safety check; will likely not fire if we reach this function. | |
| 3479 | - if ( ! current_user_can( 'edit_user', $user->ID ) ) { | |
| 3480 | - return; | |
| 3481 | - } | |
| 3482 | - | |
| 3483 | - // Don't perform Authorizer updates if we have a WordPress error. | |
| 3484 | - $errors_on_user_update = $errors->get_error_codes(); | |
| 3485 | - if ( ! empty( $errors_on_user_update ) ) { | |
| 3486 | - return; | |
| 3487 | - } | |
| 3488 | - | |
| 3489 | - // Get original user object (fail if not a real WordPress user). | |
| 3490 | - $userdata = get_userdata( $user->ID ); | |
| 3491 | - if ( ! $userdata ) { | |
| 3492 | - return; | |
| 3493 | - } | |
| 3494 | - | |
| 3495 | 3002 | // If user is in approved list, update his/her associated role. |
| 3496 | - if ( $this->is_email_in_list( $userdata->user_email, 'approved' ) ) { | |
| 3497 | - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) ); | |
| 3498 | - foreach ( $auth_settings_access_users_approved as $key => $check_user ) { | |
| 3499 | - if ( 0 === strcasecmp( $check_user['email'], $userdata->user_email ) ) { | |
| 3500 | - $auth_settings_access_users_approved[ $key ]['role'] = $user->role; | |
| 3501 | - } | |
| 3502 | - } | |
| 3503 | - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 3504 | - } | |
| 3505 | - } | |
| 3506 | - | |
| 3507 | - | |
| 3508 | - /** | |
| 3509 | - * Sync any email address changes to WordPress accounts to the corresponding | |
| 3510 | - * entry in the Authorizer approved list. | |
| 3511 | - * | |
| 3512 | - * Note: This filter fires in wp_update_user() if the update includes an | |
| 3513 | - * email address change, and fires after all security and integrity checks | |
| 3514 | - * have been performed, so we can simply update the Authorizer approved | |
| 3515 | - * list, changing the email address on the approved entry, and removing any | |
| 3516 | - * existing entries that also have the new email address (duplicates). | |
| 3517 | - * | |
| 3518 | - * Filter: send_email_change_email | |
| 3519 | - * | |
| 3520 | - * @param bool $send Whether to send the email. | |
| 3521 | - * @param array $user The original user array. | |
| 3522 | - * @param array $userdata The updated user array. | |
| 3523 | - */ | |
| 3524 | - public function edit_user_profile_update_email( $send, $user, $userdata ) { | |
| 3525 | - // If we're in multisite, update the email on all sites in the network | |
| 3526 | - // (and remove from any subsites if it's a network-approved user). | |
| 3527 | - if ( is_multisite() ) { | |
| 3528 | - // If it's a multisite approved user, sync the email there. | |
| 3529 | - $changed_user_is_multisite_user = false; | |
| 3530 | - if ( $this->is_email_in_list( $user['user_email'], 'approved', 'multisite' ) ) { | |
| 3531 | - $changed_user_is_multisite_user = true; | |
| 3532 | - $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( | |
| 3533 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 3534 | - ); | |
| 3535 | - foreach ( $auth_multisite_settings_access_users_approved as $key => $check_user ) { | |
| 3536 | - // Update old user email in approved list to the new email. | |
| 3537 | - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) { | |
| 3538 | - $auth_multisite_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] ); | |
| 3003 | + $wp_user = get_user_by( 'id', $user_id ); | |
| 3004 | + if ( $this->is_email_in_list( $wp_user->get( 'user_email' ), 'approved' ) ) { | |
| 3005 | + $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) ); | |
| 3006 | + // Find approved user and sync with the corresponding WP_User. | |
| 3007 | + foreach ( $auth_settings_access_users_approved as $key => $user ) { | |
| 3008 | + if ( $user['email'] === $wp_user->user_email ) { | |
| 3009 | + // Sync user role. | |
| 3010 | + if ( array_key_exists( 'role', $_REQUEST ) ) { | |
| 3011 | + $auth_settings_access_users_approved[$key]['role'] = $_REQUEST['role']; | |
| 3539 | 3012 | } |
| 3540 | - // If new user email is already in approved list, remove that entry. | |
| 3541 | - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) { | |
| 3542 | - unset( $auth_multisite_settings_access_users_approved[ $key ] ); | |
| 3013 | + // Sync email address. | |
| 3014 | + if ( array_key_exists( 'email', $_REQUEST ) ) { | |
| 3015 | + $auth_settings_access_users_approved[$key]['email'] = $_REQUEST['email']; | |
| 3543 | 3016 | } |
| 3544 | 3017 | } |
| 3545 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 3546 | 3018 | } |
| 3547 | 3019 | |
| 3548 | - // Go through all approved lists on individual sites and sync this user there. | |
| 3549 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 3550 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 3551 | - foreach ( $sites as $site ) { | |
| 3552 | - $updated = false; | |
| 3553 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 3554 | - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() ); | |
| 3555 | - foreach ( $auth_settings_access_users_approved as $key => $check_user ) { | |
| 3556 | - // Update old user email in approved list to the new email. | |
| 3557 | - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) { | |
| 3558 | - // But if the user is already a multisite user, just remove the entry in the subsite. | |
| 3559 | - if ( $changed_user_is_multisite_user ) { | |
| 3560 | - unset( $auth_settings_access_users_approved[ $key ] ); | |
| 3561 | - } else { | |
| 3562 | - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] ); | |
| 3563 | - } | |
| 3564 | - $updated = true; | |
| 3565 | - } | |
| 3566 | - // If new user email is already in approved list, remove that entry. | |
| 3567 | - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) { | |
| 3568 | - unset( $auth_settings_access_users_approved[ $key ] ); | |
| 3569 | - $updated = true; | |
| 3570 | - } | |
| 3571 | - } | |
| 3572 | - if ( $updated ) { | |
| 3573 | - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 3574 | - } | |
| 3575 | - } | |
| 3576 | - } else { | |
| 3577 | - // In a single site environment, just find the old user in the approved list and update the email. | |
| 3578 | - if ( $this->is_email_in_list( $user['user_email'], 'approved' ) ) { | |
| 3579 | - $auth_settings_access_users_approved = $this->sanitize_user_list( $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) ); | |
| 3580 | - foreach ( $auth_settings_access_users_approved as $key => $check_user ) { | |
| 3581 | - // Update old user email in approved list to the new email. | |
| 3582 | - if ( 0 === strcasecmp( $check_user['email'], $user['user_email'] ) ) { | |
| 3583 | - $auth_settings_access_users_approved[ $key ]['email'] = $this->lowercase( $userdata['user_email'] ); | |
| 3584 | - } | |
| 3585 | - // If new user email is already in approved list, remove that entry. | |
| 3586 | - if ( 0 === strcasecmp( $check_user['email'], $userdata['user_email'] ) ) { | |
| 3587 | - unset( $auth_settings_access_users_approved[ $key ] ); | |
| 3588 | - } | |
| 3589 | - } | |
| 3590 | - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 3591 | - } | |
| 3020 | + update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 3592 | 3021 | } |
| 3593 | - | |
| 3594 | - // We're hooking into this filter merely for its location in the codebase, | |
| 3595 | - // so make sure to return the filter value unmodified. | |
| 3596 | - return $send; | |
| 3597 | 3022 | } |
| 3598 | 3023 | |
| 3599 | 3024 | |
| 3600 | 3025 | /** |
| 3601 | - * Settings print callback. | |
| 3602 | - * | |
| 3603 | - * @param string $args Args (e.g., multisite admin mode). | |
| 3604 | - * @return void | |
| 3026 | + * Settings print callbacks | |
| 3605 | 3027 | */ |
| 3606 | - public function print_section_info_tabs( $args = '' ) { | |
| 3607 | - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $this->get_admin_mode( $args ) ) : | |
| 3608 | - ?> | |
| 3028 | + function print_section_info_tabs( $args = '' ) { | |
| 3029 | + if ( MULTISITE_ADMIN === $this->get_admin_mode( $args )): ?> | |
| 3609 | 3030 | <h2 class="nav-tab-wrapper"> |
| 3610 | - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a> | |
| 3611 | - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a> | |
| 3612 | - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a> | |
| 3031 | + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a> | |
| 3032 | + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a> | |
| 3033 | + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a> | |
| 3613 | 3034 | </h2> |
| 3614 | - <?php else : ?> | |
| 3035 | + <?php else: ?> | |
| 3615 | 3036 | <h2 class="nav-tab-wrapper"> |
| 3616 | - <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:chooseTab('access_lists' );"><?php esc_html_e( 'Access Lists', 'authorizer' ); ?></a> | |
| 3617 | - <a class="nav-tab nav-tab-access_login" href="javascript:chooseTab('access_login' );"><?php esc_html_e( 'Login Access', 'authorizer' ); ?></a> | |
| 3618 | - <a class="nav-tab nav-tab-access_public" href="javascript:chooseTab('access_public' );"><?php esc_html_e( 'Public Access', 'authorizer' ); ?></a> | |
| 3619 | - <a class="nav-tab nav-tab-external" href="javascript:chooseTab('external' );"><?php esc_html_e( 'External Service', 'authorizer' ); ?></a> | |
| 3620 | - <a class="nav-tab nav-tab-advanced" href="javascript:chooseTab('advanced' );"><?php esc_html_e( 'Advanced', 'authorizer' ); ?></a> | |
| 3037 | + <a class="nav-tab nav-tab-access_lists nav-tab-active" href="javascript:choose_tab('access_lists' );"><?php _e( 'Access Lists', 'authorizer' ); ?></a> | |
| 3038 | + <a class="nav-tab nav-tab-access_login" href="javascript:choose_tab('access_login' );"><?php _e( 'Login Access', 'authorizer' ); ?></a> | |
| 3039 | + <a class="nav-tab nav-tab-access_public" href="javascript:choose_tab('access_public' );"><?php _e( 'Public Access', 'authorizer' ); ?></a> | |
| 3040 | + <a class="nav-tab nav-tab-external" href="javascript:choose_tab('external' );"><?php _e( 'External Service', 'authorizer' ); ?></a> | |
| 3041 | + <a class="nav-tab nav-tab-advanced" href="javascript:choose_tab('advanced' );"><?php _e( 'Advanced', 'authorizer' ); ?></a> | |
| 3621 | 3042 | </h2> |
| 3622 | - <?php | |
| 3623 | - endif; | |
| 3043 | + <?php endif; | |
| 3624 | 3044 | } |
| 3625 | 3045 | |
| 3626 | 3046 | |
| 3627 | - /** | |
| 3628 | - * Settings print callback. | |
| 3629 | - * | |
| 3630 | - * @param string $args Args (e.g., multisite admin mode). | |
| 3631 | - * @return void | |
| 3632 | - */ | |
| 3633 | - public function print_section_info_access_lists( $args = '' ) { | |
| 3047 | + function print_section_info_access_lists( $args = '' ) { | |
| 3634 | 3048 | $admin_mode = $this->get_admin_mode( $args ); |
| 3635 | - ?> | |
| 3636 | - <div id="section_info_access_lists" class="section_info"> | |
| 3637 | - <p><?php esc_html_e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p> | |
| 3049 | + ?><div id="section_info_access_lists" class="section_info"> | |
| 3050 | + <p><?php _e( 'Manage who has access to this site using these lists.', 'authorizer' ); ?></p> | |
| 3638 | 3051 | <ol> |
| 3639 | - <li><?php echo wp_kses( __( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ), $this->allowed_html ); ?></li> | |
| 3640 | - <li><?php echo wp_kses( __( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 3641 | - <li><?php echo wp_kses( __( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 3052 | + <li><?php _e( "<strong>Pending</strong> users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ); ?></li> | |
| 3053 | + <li><?php _e( '<strong>Approved</strong> users have access to the site once they successfully log in.', 'authorizer' ); ?></li> | |
| 3054 | + <li><?php _e( '<strong>Blocked</strong> users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ); ?></li> | |
| 3642 | 3055 | </ol> |
| 3643 | 3056 | </div> |
| 3644 | 3057 | <table class="form-table"> |
| 3645 | 3058 | <tbody> |
| 3646 | 3059 | <tr> |
| 3647 | - <th scope="row"><?php esc_html_e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'pending', $admin_mode ) ); ?>)</em></th> | |
| 3060 | + <th scope="row"><?php _e( 'Pending Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'pending', $admin_mode ); ?>)</em></th> | |
| 3648 | 3061 | <td><?php $this->print_combo_auth_access_users_pending(); ?></td> |
| 3649 | 3062 | </tr> |
| 3650 | 3063 | <tr> |
| 3651 | - <th scope="row"><?php esc_html_e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'approved', $admin_mode ) ); ?>)</em></th> | |
| 3064 | + <th scope="row"><?php _e( 'Approved Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'approved', $admin_mode ); ?>)</em></th> | |
| 3652 | 3065 | <td><?php $this->print_combo_auth_access_users_approved(); ?></td> |
| 3653 | 3066 | </tr> |
| 3654 | 3067 | <tr> |
| 3655 | - <th scope="row"><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo esc_html( $this->get_user_count_from_list( 'blocked', $admin_mode ) ); ?>)</em></th> | |
| 3068 | + <th scope="row"><?php _e( 'Blocked Users', 'authorizer' ); ?> <em>(<?php echo $this->get_user_count_from_list( 'blocked', $admin_mode ); ?>)</em></th> | |
| 3656 | 3069 | <td><?php $this->print_combo_auth_access_users_blocked(); ?></td> |
| 3657 | 3070 | </tr> |
| 3658 | 3071 | </tbody> |
| 3659 | 3072 | </table> |
| @@ -3660,516 +3073,276 @@ | ||
| 3660 | 3073 | <?php |
| 3661 | 3074 | } |
| 3662 | 3075 | |
| 3663 | 3076 | |
| 3664 | - /** | |
| 3665 | - * Settings print callback. | |
| 3666 | - * | |
| 3667 | - * @param string $args Args (e.g., multisite admin mode). | |
| 3668 | - * @return void | |
| 3669 | - */ | |
| 3670 | - public function print_combo_auth_access_users_pending( $args = '' ) { | |
| 3077 | + function print_combo_auth_access_users_pending( $args = '' ) { | |
| 3671 | 3078 | // Get plugin option. |
| 3672 | - $option = 'access_users_pending'; | |
| 3079 | + $option = 'access_users_pending'; | |
| 3673 | 3080 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 3674 | 3081 | $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array(); |
| 3675 | 3082 | |
| 3676 | - // Render wrapper div (for aligning pager to width of content). | |
| 3677 | - ?> | |
| 3678 | - <div class="wrapper_<?php echo esc_attr( $option ); ?>"> | |
| 3679 | - <ul id="list_auth_settings_access_users_pending" style="margin:0;"> | |
| 3680 | - <?php | |
| 3681 | - if ( count( $auth_settings_option ) > 0 ) : | |
| 3682 | - foreach ( $auth_settings_option as $key => $pending_user ) : | |
| 3683 | - if ( empty( $pending_user ) || count( $pending_user ) < 1 ) : | |
| 3684 | - continue; | |
| 3685 | - endif; | |
| 3686 | - $pending_user['is_wp_user'] = false; | |
| 3687 | - ?> | |
| 3688 | - <li> | |
| 3689 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $pending_user['email'] ); ?>" readonly="true" class="auth-email" /> | |
| 3690 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role"> | |
| 3691 | - <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?> | |
| 3692 | - </select> | |
| 3693 | - <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'approved', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a> | |
| 3694 | - <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="authAddUser( this, 'blocked', false ); authIgnoreUser( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a> | |
| 3695 | - <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'pending' );" title="<?php esc_html_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php esc_html_e( 'Ignore', 'authorizer' ); ?></a> | |
| 3696 | - </li> | |
| 3697 | - <?php endforeach; ?> | |
| 3698 | - <?php else : ?> | |
| 3699 | - <li class="auth-empty"><em><?php esc_html_e( 'No pending users', 'authorizer' ); ?></em></li> | |
| 3700 | - <?php endif; ?> | |
| 3701 | - </ul> | |
| 3702 | - </div> | |
| 3083 | + // Print option elements. | |
| 3084 | + ?><ul id="list_auth_settings_access_users_pending" style="margin:0;"> | |
| 3085 | + <?php if ( count( $auth_settings_option ) > 0 ) : ?> | |
| 3086 | + <?php foreach ( $auth_settings_option as $key => $pending_user ): ?> | |
| 3087 | + <?php if ( empty( $pending_user ) || count( $pending_user ) < 1 ) continue; ?> | |
| 3088 | + <?php $pending_user['is_wp_user'] = false; ?> | |
| 3089 | + <li> | |
| 3090 | + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $pending_user['email']; ?>" readonly="true" class="auth-email" /> | |
| 3091 | + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role"> | |
| 3092 | + <?php $this->wp_dropdown_permitted_roles( $pending_user['role'] ); ?> | |
| 3093 | + </select> | |
| 3094 | + <a href="javascript:void(0);" class="button-primary" id="approve_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'approved', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a> | |
| 3095 | + <a href="javascript:void(0);" class="button-primary" id="block_user_<?php echo $key; ?>" onclick="auth_add_user( this, 'blocked', false ); auth_ignore_user( this, 'pending' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a> | |
| 3096 | + <a href="javascript:void(0);" class="button button-secondary" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user( this, 'pending' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span> <?php _e( 'Ignore', 'authorizer' ); ?></a> | |
| 3097 | + </li> | |
| 3098 | + <?php endforeach; ?> | |
| 3099 | + <?php else: ?> | |
| 3100 | + <li class="auth-empty"><em><?php _e( 'No pending users', 'authorizer' ); ?></em></li> | |
| 3101 | + <?php endif; ?> | |
| 3102 | + </ul> | |
| 3703 | 3103 | <?php |
| 3704 | 3104 | } |
| 3705 | 3105 | |
| 3706 | 3106 | |
| 3707 | - /** | |
| 3708 | - * Settings print callback. | |
| 3709 | - * | |
| 3710 | - * @param string $args Args (e.g., multisite admin mode). | |
| 3711 | - * @return void | |
| 3712 | - */ | |
| 3713 | - public function print_combo_auth_access_users_approved( $args = '' ) { | |
| 3107 | + function print_combo_auth_access_users_approved( $args = '' ) { | |
| 3714 | 3108 | // Get plugin option. |
| 3715 | - $option = 'access_users_approved'; | |
| 3716 | - $admin_mode = $this->get_admin_mode( $args ); | |
| 3109 | + $option = 'access_users_approved'; | |
| 3110 | + $admin_mode = $this->get_admin_mode( $args ); | |
| 3717 | 3111 | $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' ); |
| 3718 | 3112 | $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array(); |
| 3719 | 3113 | |
| 3720 | - // Get multisite approved users (will be added to top of list, greyed out). | |
| 3721 | - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' ); | |
| 3722 | - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 3114 | + // Get multisite approved users (add them to top of list, greyed out). | |
| 3115 | + $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' ); | |
| 3116 | + $auth_multisite_settings = $this->get_plugin_options( MULTISITE_ADMIN ); | |
| 3723 | 3117 | $auth_settings_option_multisite = array(); |
| 3724 | 3118 | if ( |
| 3725 | 3119 | is_multisite() && |
| 3726 | - ! is_network_admin() && | |
| 3727 | - '1' !== intval( $auth_override_multisite ) && | |
| 3120 | + $auth_override_multisite != '1' && | |
| 3728 | 3121 | array_key_exists( 'multisite_override', $auth_multisite_settings ) && |
| 3729 | - '1' === $auth_multisite_settings['multisite_override'] | |
| 3122 | + $auth_multisite_settings['multisite_override'] === '1' | |
| 3730 | 3123 | ) { |
| 3731 | - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' ); | |
| 3124 | + $auth_settings_option_multisite = $this->get_plugin_option( $option, MULTISITE_ADMIN, 'allow override' ); | |
| 3732 | 3125 | $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array(); |
| 3733 | - // Add multisite users to the beginning of the main user array. | |
| 3734 | - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) { | |
| 3735 | - $approved_user['multisite_user'] = true; | |
| 3736 | - array_unshift( $auth_settings_option, $approved_user ); | |
| 3737 | - } | |
| 3738 | 3126 | } |
| 3739 | 3127 | |
| 3740 | 3128 | // Get default role for new user dropdown. |
| 3741 | - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 3129 | + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' ); | |
| 3742 | 3130 | |
| 3743 | 3131 | // Get custom usermeta field to show. |
| 3744 | 3132 | $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' ); |
| 3745 | 3133 | |
| 3746 | 3134 | // Adjust javascript function prefixes if multisite. |
| 3747 | - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth'; | |
| 3748 | - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode; | |
| 3135 | + $js_function_prefix = $admin_mode === MULTISITE_ADMIN ? 'auth_multisite_' : 'auth_'; | |
| 3136 | + $multisite_admin_page = $admin_mode === MULTISITE_ADMIN; | |
| 3749 | 3137 | |
| 3750 | - // Filter user list to search terms. | |
| 3751 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 3752 | - if ( isset( $_REQUEST['search'] ) && strlen( sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) ) > 0 ) { | |
| 3753 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 3754 | - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ); | |
| 3755 | - $auth_settings_option = array_filter( | |
| 3756 | - $auth_settings_option, function ( $user ) use ( $search_term ) { | |
| 3757 | - return stripos( $user['email'], $search_term ) !== false || | |
| 3758 | - stripos( $user['role'], $search_term ) !== false || | |
| 3759 | - stripos( $user['date_added'], $search_term ) !== false; | |
| 3760 | - } | |
| 3761 | - ); | |
| 3762 | - } | |
| 3763 | - | |
| 3764 | - // Sort user list. | |
| 3765 | - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved). | |
| 3766 | - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc. | |
| 3767 | - $sort_dimension = array(); | |
| 3768 | - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) { | |
| 3769 | - foreach ( $auth_settings_option as $key => $user ) { | |
| 3770 | - if ( 'date_added' === $sort_by ) { | |
| 3771 | - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) ); | |
| 3772 | - } else { | |
| 3773 | - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] ); | |
| 3774 | - } | |
| 3775 | - } | |
| 3776 | - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC; | |
| 3777 | - array_multisort( $sort_dimension, $sort_order, $auth_settings_option ); | |
| 3778 | - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) { | |
| 3779 | - // If default sort method and reverse order, just reverse the array. | |
| 3780 | - $auth_settings_option = array_reverse( $auth_settings_option ); | |
| 3781 | - } | |
| 3782 | - | |
| 3783 | - // Ensure array keys run from 0..max (keys in database will be the original, | |
| 3784 | - // index, and removing users will not reorder the array keys of other users). | |
| 3785 | - $auth_settings_option = array_values( $auth_settings_option ); | |
| 3786 | - | |
| 3787 | - // Get pager params. | |
| 3788 | - $total_users = count( $auth_settings_option ); | |
| 3789 | - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) ); | |
| 3790 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 3791 | - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1; | |
| 3792 | - $total_pages = ceil( $total_users / $users_per_page ); | |
| 3793 | - if ( $total_pages < 1 ) { | |
| 3794 | - $total_pages = 1; | |
| 3795 | - } | |
| 3796 | - | |
| 3797 | - // Make sure current_page is between 1 and max pages. | |
| 3798 | - if ( $current_page < 1 ) { | |
| 3799 | - $current_page = 1; | |
| 3800 | - } elseif ( $current_page > $total_pages ) { | |
| 3801 | - $current_page = $total_pages; | |
| 3802 | - } | |
| 3803 | - | |
| 3804 | - // Render wrapper div (for aligning pager to width of content). | |
| 3805 | - ?> | |
| 3806 | - <div class="wrapper_<?php echo esc_attr( $option ); ?>"> | |
| 3807 | - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'top' ); ?> | |
| 3808 | - <ul id="list_auth_settings_access_users_approved" class="<?php echo strlen( $advanced_usermeta ) > 0 ? 'has-usermeta' : ''; ?>"> | |
| 3809 | - <?php | |
| 3810 | - $offset = ( $current_page - 1 ) * $users_per_page; | |
| 3811 | - $max = min( $offset + $users_per_page, count( $auth_settings_option ) ); | |
| 3812 | - for ( $key = $offset; $key < $max; $key++ ) : | |
| 3813 | - $approved_user = $auth_settings_option[ $key ]; | |
| 3138 | + ?><ul id="list_auth_settings_access_users_approved" style="margin:0;"> | |
| 3139 | + <?php if ( ! $multisite_admin_page ) : | |
| 3140 | + foreach ( $auth_settings_option_multisite as $key => $approved_user ) : | |
| 3814 | 3141 | if ( empty( $approved_user ) || count( $approved_user ) < 1 ) : |
| 3815 | 3142 | continue; |
| 3816 | 3143 | endif; |
| 3817 | - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ); | |
| 3818 | - endfor; | |
| 3819 | - ?> | |
| 3820 | - </ul> | |
| 3144 | + $approved_wp_user = get_user_by( 'email', $approved_user['email'] ); | |
| 3145 | + if ( $approved_wp_user ) : | |
| 3146 | + $approved_user['email'] = $approved_wp_user->user_email; | |
| 3147 | + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles ); | |
| 3148 | + $approved_user['date_added'] = $approved_wp_user->user_registered; | |
| 3149 | + // Get usermeta field from the WordPress user's real usermeta. | |
| 3150 | + if ( strlen( $advanced_usermeta ) > 0 ) : | |
| 3151 | + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) : | |
| 3152 | + // Get ACF Field value for the user | |
| 3153 | + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID ); | |
| 3154 | + else : | |
| 3155 | + // Get regular usermeta value for the user. | |
| 3156 | + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true ); | |
| 3157 | + endif; | |
| 3821 | 3158 | |
| 3822 | - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>"> | |
| 3823 | - <textarea id="new_approved_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new autogrow-short" rows="1"></textarea> | |
| 3824 | - <select id="new_approved_user_role" class="auth-role"> | |
| 3825 | - <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?> | |
| 3826 | - </select> | |
| 3827 | - <div class="btn-group"> | |
| 3828 | - <a href="javascript:void(0);" class="btn button-primary dropdown-toggle button-add-user" id="approve_user_new" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php esc_html_e( 'Approve', 'authorizer' ); ?></a> | |
| 3829 | - <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown"> | |
| 3830 | - <span class="caret"></span> | |
| 3831 | - <span class="sr-only"><?php esc_html_e( 'Toggle Dropdown', 'authorizer' ); ?></span> | |
| 3832 | - </button> | |
| 3833 | - <ul class="dropdown-menu" role="menu"> | |
| 3834 | - <li><a href="javascript:void(0);" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( document.getElementById( 'approve_user_new' ), 'approved', true);"><?php esc_html_e( 'Create a local WordPress account instead, and email the user their password.', 'authorizer' ); ?></a></li> | |
| 3835 | - </ul> | |
| 3836 | - </div> | |
| 3837 | - </div> | |
| 3838 | - <?php $this->render_user_pager( $current_page, $users_per_page, $total_users, 'bottom' ); ?> | |
| 3839 | - </div> | |
| 3840 | - <?php | |
| 3841 | - } | |
| 3159 | + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) : | |
| 3160 | + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] ); | |
| 3161 | + endif; | |
| 3162 | + endif; | |
| 3163 | + endif; | |
| 3164 | + if ( ! array_key_exists( 'usermeta', $approved_user ) ) : | |
| 3165 | + $approved_user['usermeta'] = ''; | |
| 3166 | + endif; ?> | |
| 3167 | + <li> | |
| 3168 | + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email auth-multisite-email" /> | |
| 3169 | + <select id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role auth-multisite-role" disabled="disabled"> | |
| 3170 | + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'] ); ?> | |
| 3171 | + </select> | |
| 3172 | + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added auth-multisite-date-added" disabled="disabled" /> | |
| 3173 | + <?php if ( strlen( $advanced_usermeta ) > 0 ) : | |
| 3174 | + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first. | |
| 3175 | + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) : | |
| 3176 | + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) ); | |
| 3177 | + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) : | |
| 3178 | + $should_show_usermeta_in_text_field = false; ?> | |
| 3179 | + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta auth-multisite-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );"> | |
| 3180 | + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option> | |
| 3181 | + <?php foreach ( $field_object['choices'] as $key => $label ) : ?> | |
| 3182 | + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && array_key_exists( get_current_blog_id(), $approved_user['usermeta'] ) && $key === $approved_user['usermeta'][get_current_blog_id()]['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option> | |
| 3183 | + <?php endforeach; ?> | |
| 3184 | + </select> | |
| 3185 | + <?php endif; ?> | |
| 3186 | + <?php endif; ?> | |
| 3187 | + <?php if ( $should_show_usermeta_in_text_field ) : ?> | |
| 3188 | + <input type="text" id="auth_multisite_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta auth-multisite-usermeta" /> | |
| 3189 | + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a> | |
| 3190 | + <?php endif; ?> | |
| 3191 | + <?php endif; ?> | |
| 3192 | + <a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a> | |
| 3193 | + </li> | |
| 3194 | + <?php endforeach; | |
| 3195 | + endif; | |
| 3196 | + foreach ( $auth_settings_option as $key => $approved_user ): | |
| 3197 | + $is_current_user = false; | |
| 3198 | + $local_user_icon = array_key_exists( 'local_user', $approved_user ) && $approved_user['local_user'] === 'true' ? ' <a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a>' : ''; | |
| 3199 | + if ( empty( $approved_user ) || count( $approved_user ) < 1 ) : | |
| 3200 | + continue; | |
| 3201 | + endif; | |
| 3202 | + $approved_wp_user = get_user_by( 'email', $approved_user['email'] ); | |
| 3203 | + if ( $approved_wp_user ) : | |
| 3204 | + $approved_user['email'] = $approved_wp_user->user_email; | |
| 3205 | + $approved_user['role'] = $multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles ); | |
| 3206 | + $approved_user['date_added'] = $approved_wp_user->user_registered; | |
| 3207 | + $approved_user['is_wp_user'] = true; | |
| 3208 | + $is_current_user = $approved_wp_user->ID === get_current_user_id(); | |
| 3209 | + // Get usermeta field from the WordPress user's real usermeta. | |
| 3210 | + if ( strlen( $advanced_usermeta ) > 0 ) : | |
| 3211 | + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) : | |
| 3212 | + // Get ACF Field value for the user | |
| 3213 | + $approved_user['usermeta'] = get_field( str_replace('acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID ); | |
| 3214 | + else : | |
| 3215 | + // Get regular usermeta value for the user. | |
| 3216 | + $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true ); | |
| 3217 | + endif; | |
| 3842 | 3218 | |
| 3843 | - | |
| 3844 | - /** | |
| 3845 | - * Renders the html elements for the pager above and below the Approved User list. | |
| 3846 | - * | |
| 3847 | - * @param integer $current_page Which page we are currently viewing. | |
| 3848 | - * @param integer $users_per_page How many users to show per page. | |
| 3849 | - * @param integer $total_users Total count of users in list. | |
| 3850 | - * @param string $which Where to render the pager ('top' or 'bottom'). | |
| 3851 | - * @return void | |
| 3852 | - */ | |
| 3853 | - private function render_user_pager( $current_page = 1, $users_per_page = 20, $total_users = 0, $which = 'top' ) { | |
| 3854 | - $total_pages = ceil( $total_users / $users_per_page ); | |
| 3855 | - if ( $total_pages < 1 ) { | |
| 3856 | - $total_pages = 1; | |
| 3857 | - } | |
| 3858 | - | |
| 3859 | - /* TRANSLATORS: %s: number of users */ | |
| 3860 | - $output = ' <span class="displaying-num">' . sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ) . '</span>'; | |
| 3861 | - | |
| 3862 | - $disable_first = $current_page <= 1; | |
| 3863 | - $disable_prev = $current_page <= 1; | |
| 3864 | - $disable_next = $current_page >= $total_pages; | |
| 3865 | - $disable_last = $current_page >= $total_pages; | |
| 3866 | - | |
| 3867 | - $current_url = ''; | |
| 3868 | - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) { | |
| 3869 | - $current_url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) ); | |
| 3870 | - $current_url = remove_query_arg( wp_removable_query_args(), $current_url ); | |
| 3871 | - } | |
| 3872 | - | |
| 3873 | - $page_links = array(); | |
| 3874 | - | |
| 3875 | - $total_pages_before = '<span class="paging-input">'; | |
| 3876 | - $total_pages_after = '</span></span>'; | |
| 3877 | - | |
| 3878 | - if ( $disable_first ) { | |
| 3879 | - $page_links[] = '<span class="first-page tablenav-pages-navspan" aria-hidden="true">«</span>'; | |
| 3880 | - } else { | |
| 3881 | - $page_links[] = sprintf( | |
| 3882 | - "<a class='first-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>", | |
| 3883 | - esc_url( remove_query_arg( 'paged', $current_url ) ), | |
| 3884 | - __( 'First page' ), | |
| 3885 | - '«' | |
| 3886 | - ); | |
| 3887 | - } | |
| 3888 | - | |
| 3889 | - if ( $disable_prev ) { | |
| 3890 | - $page_links[] = '<span class="prev-page tablenav-pages-navspan" aria-hidden="true">‹</span>'; | |
| 3891 | - } else { | |
| 3892 | - $page_links[] = sprintf( | |
| 3893 | - "<a class='prev-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>", | |
| 3894 | - esc_url( add_query_arg( 'paged', max( 1, $current_page - 1 ), $current_url ) ), | |
| 3895 | - __( 'Previous page' ), | |
| 3896 | - '‹' | |
| 3897 | - ); | |
| 3898 | - } | |
| 3899 | - | |
| 3900 | - if ( 'bottom' === $which ) { | |
| 3901 | - $html_current_page = '<span class="current-page-text">' . $current_page . '</span>'; | |
| 3902 | - $total_pages_before = '<span class="screen-reader-text">' . __( 'Current Page' ) . '</span><span id="table-paging" class="paging-input"><span class="tablenav-paging-text">'; | |
| 3903 | - } else { | |
| 3904 | - $html_current_page = sprintf( | |
| 3905 | - "%s<input class='current-page' id='current-page-selector' type='text' name='paged' value='%s' size='%d' aria-describedby='table-paging' /><span class='tablenav-paging-text'>", | |
| 3906 | - '<label for="current-page-selector" class="screen-reader-text">' . __( 'Current Page' ) . '</label>', | |
| 3907 | - $current_page, | |
| 3908 | - strlen( $total_pages ) | |
| 3909 | - ); | |
| 3910 | - } | |
| 3911 | - /* TRANSLATORS: %s: number of pages */ | |
| 3912 | - $html_total_pages = sprintf( "<span class='total-pages'>%s</span>", number_format_i18n( $total_pages ) ); | |
| 3913 | - /* TRANSLATORS: 1: number of current page 2: number of total pages */ | |
| 3914 | - $page_links[] = $total_pages_before . sprintf( _x( '%1$s of %2$s', 'paging' ), $html_current_page, $html_total_pages ) . $total_pages_after; | |
| 3915 | - | |
| 3916 | - if ( $disable_next ) { | |
| 3917 | - $page_links[] = '<span class="next-page tablenav-pages-navspan" aria-hidden="true">›</span>'; | |
| 3918 | - } else { | |
| 3919 | - $page_links[] = sprintf( | |
| 3920 | - "<a class='next-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>", | |
| 3921 | - esc_url( add_query_arg( 'paged', min( $total_pages, $current_page + 1 ), $current_url ) ), | |
| 3922 | - __( 'Next page' ), | |
| 3923 | - '›' | |
| 3924 | - ); | |
| 3925 | - } | |
| 3926 | - | |
| 3927 | - if ( $disable_last ) { | |
| 3928 | - $page_links[] = '<span class="last-page tablenav-pages-navspan" aria-hidden="true">»</span>'; | |
| 3929 | - } else { | |
| 3930 | - $page_links[] = sprintf( | |
| 3931 | - "<a class='last-page' href='%s'><span class='screen-reader-text'>%s</span><span aria-hidden='true'>%s</span></a>", | |
| 3932 | - esc_url( add_query_arg( 'paged', $total_pages, $current_url ) ), | |
| 3933 | - __( 'Last page' ), | |
| 3934 | - '»' | |
| 3935 | - ); | |
| 3936 | - } | |
| 3937 | - | |
| 3938 | - $pagination_links_class = 'pagination-links'; | |
| 3939 | - $output .= "\n<span class='$pagination_links_class'>" . join( "\n", $page_links ) . '</span>'; | |
| 3940 | - | |
| 3941 | - $search_form = array(); | |
| 3942 | - if ( 'top' === $which ) { | |
| 3943 | - // phpcs:ignore WordPress.CSRF.NonceVerification.NoNonceVerification | |
| 3944 | - $search_term = isset( $_REQUEST['search'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ) : ''; | |
| 3945 | - $search_form[] = '<div class="search-box">'; | |
| 3946 | - $search_form[] = '<label class="screen-reader-text" for="user-search-input">' . __( 'Search Users', 'authorizer' ) . '</label>'; | |
| 3947 | - $search_form[] = '<input type="search" size="14" id="user-search-input" name="search" value="' . $search_term . '">'; | |
| 3948 | - $search_form[] = '<input type="button" id="search-submit" class="button" value="' . __( 'Search', 'authorizer' ) . '">'; | |
| 3949 | - $search_form[] = '</div>'; | |
| 3950 | - } | |
| 3951 | - $search_form = join( "\n", $search_form ); | |
| 3952 | - | |
| 3953 | - $output = "<div class='tablenav-pages'>$output</div>"; | |
| 3954 | - ?> | |
| 3955 | - <div class="tablenav top"> | |
| 3956 | - <?php echo wp_kses( $output, $this->allowed_html ); ?> | |
| 3957 | - <?php echo wp_kses( $search_form, $this->allowed_html ); ?> | |
| 3958 | - </div> | |
| 3959 | - <?php | |
| 3960 | - } | |
| 3961 | - | |
| 3962 | - | |
| 3963 | - /** | |
| 3964 | - * Renders the html <li> element for a given user in a list. | |
| 3965 | - * | |
| 3966 | - * @param array $approved_user User array to render. | |
| 3967 | - * @param int $key Index of user in list of users. | |
| 3968 | - * @param string $option List user is in (e.g., 'access_users_approved'). | |
| 3969 | - * @param string $admin_mode Current admin context. | |
| 3970 | - * @param string $advanced_usermeta Usermeta field to display. | |
| 3971 | - * @return void | |
| 3972 | - */ | |
| 3973 | - private function render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ) { | |
| 3974 | - $is_local_user = array_key_exists( 'local_user', $approved_user ) && 'true' === $approved_user['local_user']; | |
| 3975 | - $is_multisite_user = array_key_exists( 'multisite_user', $approved_user ) && true === $approved_user['multisite_user']; | |
| 3976 | - $option_prefix = $is_multisite_user ? 'auth_multisite_settings_' : 'auth_settings_'; | |
| 3977 | - $option_id = $option_prefix . $option . '_' . $key; | |
| 3978 | - $approved_wp_user = get_user_by( 'email', $approved_user['email'] ); | |
| 3979 | - $is_current_user = $approved_wp_user && get_current_user_id() === $approved_wp_user->ID; | |
| 3980 | - | |
| 3981 | - // Adjust javascript function prefixes if multisite. | |
| 3982 | - $js_function_prefix = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? 'authMultisite' : 'auth'; | |
| 3983 | - $is_multisite_admin_page = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode; | |
| 3984 | - | |
| 3985 | - if ( ! $approved_wp_user ) : | |
| 3986 | - $approved_user['is_wp_user'] = false; | |
| 3987 | - else : | |
| 3988 | - $approved_user['is_wp_user'] = true; | |
| 3989 | - $approved_user['email'] = $approved_wp_user->user_email; | |
| 3990 | - $approved_user['role'] = $is_multisite_admin_page || count( $approved_wp_user->roles ) === 0 ? $approved_user['role'] : array_shift( $approved_wp_user->roles ); | |
| 3991 | - $approved_user['date_added'] = $approved_wp_user->user_registered; | |
| 3992 | - | |
| 3993 | - // Get usermeta field from the WordPress user's real usermeta. | |
| 3994 | - if ( strlen( $advanced_usermeta ) > 0 ) : | |
| 3995 | - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) : | |
| 3996 | - // Get ACF Field value for the user. | |
| 3997 | - $approved_user['usermeta'] = get_field( str_replace( 'acf___', '', $advanced_usermeta ), 'user_' . $approved_wp_user->ID ); | |
| 3219 | + if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) : | |
| 3220 | + $approved_user['usermeta'] = serialize( $approved_user['usermeta'] ); | |
| 3221 | + endif; | |
| 3222 | + endif; | |
| 3998 | 3223 | else : |
| 3999 | - // Get regular usermeta value for the user. | |
| 4000 | - $approved_user['usermeta'] = get_user_meta( $approved_wp_user->ID, $advanced_usermeta, true ); | |
| 3224 | + $approved_user['is_wp_user'] = false; | |
| 4001 | 3225 | endif; |
| 4002 | - if ( is_array( $approved_user['usermeta'] ) || is_object( $approved_user['usermeta'] ) ) : | |
| 4003 | - $approved_user['usermeta'] = serialize( $approved_user['usermeta'] ); | |
| 4004 | - endif; | |
| 4005 | - endif; | |
| 4006 | - endif; | |
| 4007 | - if ( ! array_key_exists( 'usermeta', $approved_user ) ) : | |
| 4008 | - $approved_user['usermeta'] = ''; | |
| 4009 | - endif; | |
| 4010 | - ?> | |
| 4011 | - <li> | |
| 4012 | - <input | |
| 4013 | - type="text" | |
| 4014 | - id="<?php echo esc_attr( $option_id ); ?>" | |
| 4015 | - value="<?php echo esc_attr( $approved_user['email'] ); ?>" | |
| 4016 | - readonly="true" | |
| 4017 | - class="<?php echo esc_attr( $this->create_class_name( 'email', $is_multisite_user ) ); ?>" | |
| 4018 | - /> | |
| 4019 | - <select | |
| 4020 | - id="<?php echo esc_attr( $option_id ); ?>_role" | |
| 4021 | - class="<?php echo esc_attr( $this->create_class_name( 'role', $is_multisite_user ) ); ?>" | |
| 4022 | - onchange="<?php echo esc_attr( $js_function_prefix ); ?>ChangeRole( this );" | |
| 4023 | - <?php if ( $is_multisite_user ) : ?> | |
| 4024 | - disabled="disabled" | |
| 4025 | - <?php endif; ?> | |
| 4026 | - > | |
| 4027 | - <?php $disable_input = $is_current_user ? 'disabled' : null; ?> | |
| 4028 | - <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?> | |
| 3226 | + if ( ! array_key_exists( 'usermeta', $approved_user ) ) : | |
| 3227 | + $approved_user['usermeta'] = ''; | |
| 3228 | + endif; ?> | |
| 3229 | + <li> | |
| 3230 | + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $approved_user['email']; ?>" readonly="true" class="auth-email" /> | |
| 3231 | + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role" onchange="<?php echo $js_function_prefix; ?>change_role( this );"> | |
| 3232 | + <?php $disable_input = $is_current_user ? 'disabled' : null; ?> | |
| 3233 | + <?php $this->wp_dropdown_permitted_roles( $approved_user['role'], $disable_input, $admin_mode ); ?> | |
| 3234 | + </select> | |
| 3235 | + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $approved_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" /> | |
| 3236 | + <?php if ( strlen( $advanced_usermeta ) > 0 ) : | |
| 3237 | + $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first. | |
| 3238 | + if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) : | |
| 3239 | + $field_object = get_field_object( str_replace('acf___', '', $advanced_usermeta ) ); | |
| 3240 | + if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && $field_object['type'] === 'select' ) : | |
| 3241 | + $should_show_usermeta_in_text_field = false; ?> | |
| 3242 | + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" class="auth-usermeta" onchange="<?php echo $js_function_prefix; ?>update_usermeta( this );" > | |
| 3243 | + <option value=""<?php if ( empty( $approved_user['usermeta'] ) ) echo ' selected="selected"'; ?>><?php _e( '-- None --', 'authorizer' ); ?></option> | |
| 3244 | + <?php foreach ( $field_object['choices'] as $key => $label ) : ?> | |
| 3245 | + <option value="<?php echo $key; ?>"<?php if ( $key === $approved_user['usermeta'] || ( is_array( $approved_user['usermeta'] ) && $key === $approved_user['usermeta']['meta_value'] ) ) echo ' selected="selected"'; ?>><?php echo $label; ?></option> | |
| 3246 | + <?php endforeach; ?> | |
| 3247 | + </select> | |
| 3248 | + <?php endif; ?> | |
| 3249 | + <?php endif; ?> | |
| 3250 | + <?php if ( $should_show_usermeta_in_text_field ) : ?> | |
| 3251 | + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_usermeta" value="<?php echo htmlspecialchars( $approved_user['usermeta'], ENT_COMPAT ); ?>" class="auth-usermeta" /> | |
| 3252 | + <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>update_usermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a> | |
| 3253 | + <?php endif; ?> | |
| 3254 | + <?php endif; ?> | |
| 3255 | + <?php if ( ! $is_current_user ): ?> | |
| 3256 | + <?php if ( ! $multisite_admin_page ) : ?> | |
| 3257 | + <a class="button" id="block_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>add_user( this, 'blocked', false ); <?php echo $js_function_prefix; ?>ignore_user( this, 'approved' );" title="<?php _e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a> | |
| 3258 | + <?php endif; ?> | |
| 3259 | + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="<?php echo $js_function_prefix; ?>ignore_user(this, 'approved' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a> | |
| 3260 | + <?php endif; ?> | |
| 3261 | + <?php echo $local_user_icon; ?> | |
| 3262 | + </li> | |
| 3263 | + <?php endforeach; ?> | |
| 3264 | + </ul> | |
| 3265 | + <div id="new_auth_settings_<?php echo $option; ?>"> | |
| 3266 | + <input type="text" id="new_approved_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" /> | |
| 3267 | + <select id="new_approved_user_role" class="auth-role"> | |
| 3268 | + <?php $this->wp_dropdown_permitted_roles( $access_default_role, 'not disabled', $admin_mode ); ?> | |
| 4029 | 3269 | </select> |
| 4030 | - <input | |
| 4031 | - type="text" | |
| 4032 | - id="<?php echo esc_attr( $option_id ); ?>_date_added" | |
| 4033 | - value="<?php echo esc_attr( date( 'M Y', strtotime( $approved_user['date_added'] ) ) ); ?>" | |
| 4034 | - readonly="true" | |
| 4035 | - class="<?php echo esc_attr( $this->create_class_name( 'date-added', $is_multisite_user ) ); ?>" | |
| 4036 | - /> | |
| 4037 | - <?php | |
| 4038 | - if ( strlen( $advanced_usermeta ) > 0 ) : | |
| 4039 | - $should_show_usermeta_in_text_field = true; // Fallback renderer for usermeta; try to use a select first. | |
| 4040 | - if ( strpos( $advanced_usermeta, 'acf___' ) === 0 && class_exists( 'acf' ) ) : | |
| 4041 | - $field_object = get_field_object( str_replace( 'acf___', '', $advanced_usermeta ) ); | |
| 4042 | - if ( is_array( $field_object ) && array_key_exists( 'type', $field_object ) && 'select' === $field_object['type'] ) : | |
| 4043 | - $should_show_usermeta_in_text_field = false; | |
| 4044 | - ?> | |
| 4045 | - <select | |
| 4046 | - id="<?php echo esc_attr( $option_id ); ?>_usermeta" | |
| 4047 | - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>" | |
| 4048 | - onchange="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );" | |
| 4049 | - > | |
| 4050 | - <option value=""<?php selected( empty( $approved_user['usermeta'] ) ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option> | |
| 4051 | - <?php foreach ( $field_object['choices'] as $key => $label ) : ?> | |
| 4052 | - <option value="<?php echo esc_attr( $key ); ?>"<?php selected( $key === $approved_user['usermeta'] || ( isset( $approved_user['usermeta']['meta_value'] ) && $key === $approved_user['usermeta']['meta_value'] ) ); ?>><?php echo esc_html( $label ); ?></option> | |
| 4053 | - <?php endforeach; ?> | |
| 4054 | - </select> | |
| 4055 | - <?php endif; ?> | |
| 4056 | - <?php endif; ?> | |
| 4057 | - <?php if ( $should_show_usermeta_in_text_field ) : ?> | |
| 4058 | - <input | |
| 4059 | - type="text" | |
| 4060 | - id="<?php echo esc_attr( $option_id ); ?>_usermeta" | |
| 4061 | - value="<?php echo esc_attr( $approved_user['usermeta'], ENT_COMPAT ); ?>" | |
| 4062 | - class="<?php echo esc_attr( $this->create_class_name( 'usermeta', $is_multisite_user ) ); ?>" | |
| 4063 | - /> | |
| 4064 | - <a class="button button-small button-primary update-usermeta" id="update_usermeta_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>UpdateUsermeta( this );" title="Update usermeta"><span class="glyphicon glyphicon-floppy-saved"></span></a> | |
| 4065 | - <?php endif; ?> | |
| 4066 | - <?php endif; ?> | |
| 4067 | - <?php if ( ! $is_current_user && ! $is_multisite_user ) : ?> | |
| 4068 | - <?php if ( ! $is_multisite_admin_page ) : ?> | |
| 4069 | - <a class="button" id="block_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>AddUser( this, 'blocked', false ); <?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser( this, 'approved' );" title="<?php esc_attr_e( 'Block/Ban user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-ban-circle"></span></a> | |
| 4070 | - <?php endif; ?> | |
| 4071 | - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="<?php echo esc_attr( $js_function_prefix ); ?>IgnoreUser(this, 'approved' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a> | |
| 4072 | - <?php endif; ?> | |
| 4073 | - <?php if ( $is_local_user ) : ?> | |
| 4074 | - <a title="Local WordPress user" class="auth-local-user"><span class="glyphicon glyphicon-user"></span></a> | |
| 4075 | - <?php endif; ?> | |
| 4076 | - <?php if ( $is_multisite_user ) : ?> | |
| 4077 | - <a title="WordPress Multisite user" class="auth-multisite-user"><span class="glyphicon glyphicon-globe"></span></a> | |
| 4078 | - <?php endif; ?> | |
| 4079 | - </li> | |
| 3270 | + <div class="btn-group"> | |
| 3271 | + <a href="javascript:void(0);" class="btn button-primary dropdown-toggle" id="approve_user_new" onclick="<?php echo $js_function_prefix; ?>add_user(this, 'approved' );"><span class="glyphicon glyphicon-ok"></span> <?php _e( 'Approve', 'authorizer' ); ?></a> | |
| 3272 | + <button type="button" class="btn button-primary dropdown-toggle" data-toggle="dropdown"> | |
| 3273 | + <span class="caret"></span> | |
| 3274 | + <span class="sr-only"><?php _e( 'Toggle Dropdown', 'authorizer' ); ?></span> | |
| 3275 | + </button> | |
| 3276 | + <ul class="dropdown-menu" role="menu"> | |
| 3277 | + <li><a href="javascript:void(0);" onclick="<?php echo $js_function_prefix; ?>add_user( document.getElementById('approve_user_new' ), 'approved', true);"><?php _e( 'Create a local WordPress <br />account instead, and email <br />the user their password.', 'authorizer' ); ?></a></li> | |
| 3278 | + </ul> | |
| 3279 | + </div> | |
| 3280 | + </div> | |
| 4080 | 3281 | <?php |
| 4081 | 3282 | } |
| 4082 | 3283 | |
| 4083 | 3284 | |
| 4084 | - /** | |
| 4085 | - * Settings print callback. | |
| 4086 | - * | |
| 4087 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4088 | - * @return void | |
| 4089 | - */ | |
| 4090 | - public function print_combo_auth_access_users_blocked( $args = '' ) { | |
| 3285 | + function print_combo_auth_access_users_blocked( $args = '' ) { | |
| 4091 | 3286 | // Get plugin option. |
| 4092 | - $option = 'access_users_blocked'; | |
| 3287 | + $option = 'access_users_blocked'; | |
| 4093 | 3288 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4094 | 3289 | $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array(); |
| 4095 | 3290 | |
| 4096 | 3291 | // Get default role for new blocked user dropdown. |
| 4097 | - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 3292 | + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' ); | |
| 4098 | 3293 | |
| 4099 | - // Render wrapper div (for aligning pager to width of content). | |
| 4100 | - ?> | |
| 4101 | - <div class="wrapper_<?php echo esc_attr( $option ); ?>"> | |
| 4102 | - <ul id="list_auth_settings_<?php echo esc_attr( $option ); ?>" style="margin:0;"> | |
| 4103 | - <?php | |
| 4104 | - foreach ( $auth_settings_option as $key => $blocked_user ) : | |
| 4105 | - if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) : | |
| 4106 | - continue; | |
| 4107 | - endif; | |
| 4108 | - $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ); | |
| 4109 | - if ( $blocked_wp_user ) : | |
| 4110 | - $blocked_user['email'] = $blocked_wp_user->user_email; | |
| 4111 | - $blocked_user['role'] = array_shift( $blocked_wp_user->roles ); | |
| 4112 | - $blocked_user['date_added'] = $blocked_wp_user->user_registered; | |
| 4113 | - $blocked_user['is_wp_user'] = true; | |
| 4114 | - else : | |
| 4115 | - $blocked_user['is_wp_user'] = false; | |
| 4116 | - endif; | |
| 4117 | - ?> | |
| 4118 | - <li> | |
| 4119 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>" value="<?php echo esc_attr( $blocked_user['email'] ); ?>" readonly="true" class="auth-email" /> | |
| 4120 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_role" class="auth-role"> | |
| 4121 | - <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?> | |
| 4122 | - </select> | |
| 4123 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( $key ); ?>_date_added" value="<?php echo esc_attr( date( 'M Y', strtotime( $blocked_user['date_added'] ) ) ); ?>" readonly="true" class="auth-date-added" /> | |
| 4124 | - <a class="button" id="ignore_user_<?php echo esc_attr( $key ); ?>" onclick="authIgnoreUser( this, 'blocked' );" title="<?php esc_attr_e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a> | |
| 4125 | - </li> | |
| 4126 | - <?php endforeach; ?> | |
| 4127 | - </ul> | |
| 4128 | - <div id="new_auth_settings_<?php echo esc_attr( $option ); ?>"> | |
| 4129 | - <input type="text" id="new_blocked_user_email" placeholder="<?php esc_attr_e( 'email address', 'authorizer' ); ?>" class="auth-email new" /> | |
| 4130 | - <select id="new_blocked_user_role" class="auth-role"> | |
| 4131 | - <option value="<?php echo esc_attr( $access_default_role ); ?>"><?php echo esc_html( ucfirst( $access_default_role ) ); ?></option> | |
| 4132 | - </select> | |
| 4133 | - <a href="javascript:void(0);" class="button-primary button-add-user" id="block_user_new" onclick="authAddUser( this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php esc_html_e( 'Block', 'authorizer' ); ?></a> | |
| 4134 | - </div> | |
| 3294 | + // Print option elements. | |
| 3295 | + ?><ul id="list_auth_settings_<?php echo $option; ?>" style="margin:0;"> | |
| 3296 | + <?php foreach ( $auth_settings_option as $key => $blocked_user ): ?> | |
| 3297 | + <?php if ( empty( $blocked_user ) || count( $blocked_user ) < 1 ) continue; ?> | |
| 3298 | + <?php if ( $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ) ): ?> | |
| 3299 | + <?php $blocked_user['email'] = $blocked_wp_user->user_email; ?> | |
| 3300 | + <?php $blocked_user['role'] = array_shift( $blocked_wp_user->roles ); ?> | |
| 3301 | + <?php $blocked_user['date_added'] = $blocked_wp_user->user_registered; ?> | |
| 3302 | + <?php $blocked_user['is_wp_user'] = true; ?> | |
| 3303 | + <?php else: ?> | |
| 3304 | + <?php $blocked_user['is_wp_user'] = false; ?> | |
| 3305 | + <?php endif; ?> | |
| 3306 | + <li> | |
| 3307 | + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>" value="<?php echo $blocked_user['email']; ?>" readonly="true" class="auth-email" /> | |
| 3308 | + <select id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_role" class="auth-role"> | |
| 3309 | + <?php $this->wp_dropdown_permitted_roles( $blocked_user['role'] ); ?> | |
| 3310 | + </select> | |
| 3311 | + <input type="text" id="auth_settings_<?php echo $option; ?>_<?php echo $key; ?>_date_added" value="<?php echo date( 'M Y', strtotime( $blocked_user['date_added'] ) ); ?>" readonly="true" class="auth-date-added" /> | |
| 3312 | + <a class="button" id="ignore_user_<?php echo $key; ?>" onclick="auth_ignore_user(this, 'blocked' );" title="<?php _e( 'Remove user', 'authorizer' ); ?>"><span class="glyphicon glyphicon-remove"></span></a> | |
| 3313 | + </li> | |
| 3314 | + <?php endforeach; ?> | |
| 3315 | + </ul> | |
| 3316 | + <div id="new_auth_settings_<?php echo $option; ?>"> | |
| 3317 | + <input type="text" id="new_blocked_user_email" placeholder="<?php _e( 'email address', 'authorizer' ); ?>" class="auth-email new" /> | |
| 3318 | + <select id="new_blocked_user_role" class="auth-role"> | |
| 3319 | + <option value="<?php echo $access_default_role; ?>"><?php echo ucfirst( $access_default_role ); ?></option> | |
| 3320 | + </select> | |
| 3321 | + <a href="javascript:void(0);" class="button-primary" id="block_user_new" onclick="auth_add_user(this, 'blocked' );"><span class="glyphicon glyphicon-ban-circle"></span> <?php _e( 'Block', 'authorizer' ); ?></a> | |
| 4135 | 3322 | </div> |
| 4136 | 3323 | <?php |
| 4137 | 3324 | } |
| 4138 | 3325 | |
| 4139 | 3326 | |
| 4140 | - /** | |
| 4141 | - * Settings print callback. | |
| 4142 | - * | |
| 4143 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4144 | - * @return void | |
| 4145 | - */ | |
| 4146 | - public function print_section_info_access_login( $args = '' ) { | |
| 4147 | - ?> | |
| 4148 | - <div id="section_info_access_login" class="section_info"> | |
| 3327 | + function print_section_info_access_login( $args = '' ) { | |
| 3328 | + ?><div id="section_info_access_login" class="section_info"> | |
| 4149 | 3329 | <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?> |
| 4150 | - <p><?php esc_html_e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p> | |
| 4151 | - </div> | |
| 4152 | - <?php | |
| 3330 | + <p><?php _e( 'Choose who is able to log into this site below.', 'authorizer' ); ?></p> | |
| 3331 | + </div><?php | |
| 4153 | 3332 | } |
| 4154 | 3333 | |
| 4155 | 3334 | |
| 4156 | - /** | |
| 4157 | - * Settings print callback. | |
| 4158 | - * | |
| 4159 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4160 | - * @return void | |
| 4161 | - */ | |
| 4162 | - public function print_radio_auth_access_who_can_login( $args = '' ) { | |
| 3335 | + function print_radio_auth_access_who_can_login( $args = '' ) { | |
| 4163 | 3336 | // Get plugin option. |
| 4164 | - $option = 'access_who_can_login'; | |
| 4165 | - $admin_mode = $this->get_admin_mode( $args ); | |
| 3337 | + $option = 'access_who_can_login'; | |
| 3338 | + $admin_mode = $this->get_admin_mode( $args ); | |
| 4166 | 3339 | $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' ); |
| 4167 | 3340 | |
| 4168 | 3341 | // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay. |
| 4169 | - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) { | |
| 3342 | + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) { | |
| 4170 | 3343 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4171 | - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) === '1' ) { | |
| 3344 | + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) { | |
| 4172 | 3345 | // Workaround: javascript code hides/shows other settings based |
| 4173 | 3346 | // on the selection in this option. If this option is overridden |
| 4174 | 3347 | // by a multisite option, it should show that value in order to |
| 4175 | 3348 | // correctly display the other appropriate options. |
| @@ -4175,49 +3348,33 @@ | ||
| 4175 | 3348 | // correctly display the other appropriate options. |
| 4176 | 3349 | // Side effect: this site option will be overwritten by the |
| 4177 | 3350 | // multisite option on save. Since this is a 2-item radio, we |
| 4178 | 3351 | // determined this was acceptable. |
| 4179 | - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 3352 | + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN ); | |
| 4180 | 3353 | } |
| 4181 | 3354 | |
| 4182 | 3355 | // Print option elements. |
| 4183 | - ?> | |
| 4184 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="external_users"<?php checked( 'external_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_external_users"><?php esc_html_e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br /> | |
| 4185 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="approved_users"<?php checked( 'approved_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_approved_users"><?php esc_html_e( 'Only', 'authorizer' ); ?> <a href="javascript:chooseTab('access_lists' );" id="dashboard_link_approved_users"><?php esc_html_e( 'approved users', 'authorizer' ); ?></a> <?php esc_html_e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br /> | |
| 4186 | - <?php | |
| 3356 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_external_users" name="auth_settings[<?php echo $option; ?>]" value="external_users"<?php checked( 'external_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_external_users"><?php _e( 'All authenticated users (All external service users and all WordPress users)', 'authorizer' ); ?></label><br /> | |
| 3357 | + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_approved_users" name="auth_settings[<?php echo $option; ?>]" value="approved_users"<?php checked( 'approved_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_approved_users"><?php _e( 'Only', 'authorizer' ); ?> <a href="javascript:choose_tab('access_lists' );" id="dashboard_link_approved_users"><?php _e( 'approved users', 'authorizer' ); ?></a> <?php _e( '(Approved external users and all WordPress users)', 'authorizer' ); ?></label><br /><?php | |
| 4187 | 3358 | } |
| 4188 | 3359 | |
| 4189 | 3360 | |
| 4190 | - /** | |
| 4191 | - * Settings print callback. | |
| 4192 | - * | |
| 4193 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4194 | - * @return void | |
| 4195 | - */ | |
| 4196 | - public function print_select_auth_access_role_receive_pending_emails( $args = '' ) { | |
| 3361 | + function print_select_auth_access_role_receive_pending_emails( $args = '' ) { | |
| 4197 | 3362 | // Get plugin option. |
| 4198 | - $option = 'access_role_receive_pending_emails'; | |
| 3363 | + $option = 'access_role_receive_pending_emails'; | |
| 4199 | 3364 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4200 | 3365 | |
| 4201 | 3366 | // Print option elements. |
| 4202 | - ?> | |
| 4203 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]"> | |
| 4204 | - <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php esc_html_e( "None (Don't send notification emails)", 'authorizer' ); ?></option> | |
| 3367 | + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]"> | |
| 3368 | + <option value="---" <?php selected( $auth_settings_option, '---' ); ?>><?php _e( "None (Don't send notification emails)", 'authorizer' ); ?></option> | |
| 4205 | 3369 | <?php wp_dropdown_roles( $auth_settings_option ); ?> |
| 4206 | - </select> | |
| 4207 | - <?php | |
| 3370 | + </select><?php | |
| 4208 | 3371 | } |
| 4209 | 3372 | |
| 4210 | 3373 | |
| 4211 | - /** | |
| 4212 | - * Settings print callback. | |
| 4213 | - * | |
| 4214 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4215 | - * @return void | |
| 4216 | - */ | |
| 4217 | - public function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) { | |
| 3374 | + function print_wysiwyg_auth_access_pending_redirect_to_message( $args = '' ) { | |
| 4218 | 3375 | // Get plugin option. |
| 4219 | - $option = 'access_pending_redirect_to_message'; | |
| 3376 | + $option = 'access_pending_redirect_to_message'; | |
| 4220 | 3377 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4221 | 3378 | |
| 4222 | 3379 | // Print option elements. |
| 4223 | 3380 | wp_editor( |
| @@ -4226,25 +3383,19 @@ | ||
| 4226 | 3383 | array( |
| 4227 | 3384 | 'media_buttons' => false, |
| 4228 | 3385 | 'textarea_name' => "auth_settings[$option]", |
| 4229 | 3386 | 'textarea_rows' => 5, |
| 4230 | - 'tinymce' => true, | |
| 4231 | - 'teeny' => true, | |
| 4232 | - 'quicktags' => false, | |
| 3387 | + 'tinymce' => true, | |
| 3388 | + 'teeny' => true, | |
| 3389 | + 'quicktags' => false, | |
| 4233 | 3390 | ) |
| 4234 | 3391 | ); |
| 4235 | 3392 | } |
| 4236 | 3393 | |
| 4237 | 3394 | |
| 4238 | - /** | |
| 4239 | - * Settings print callback. | |
| 4240 | - * | |
| 4241 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4242 | - * @return void | |
| 4243 | - */ | |
| 4244 | - public function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) { | |
| 3395 | + function print_wysiwyg_auth_access_blocked_redirect_to_message( $args = '' ) { | |
| 4245 | 3396 | // Get plugin option. |
| 4246 | - $option = 'access_blocked_redirect_to_message'; | |
| 3397 | + $option = 'access_blocked_redirect_to_message'; | |
| 4247 | 3398 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4248 | 3399 | |
| 4249 | 3400 | // Print option elements. |
| 4250 | 3401 | wp_editor( |
| @@ -4253,61 +3404,39 @@ | ||
| 4253 | 3404 | array( |
| 4254 | 3405 | 'media_buttons' => false, |
| 4255 | 3406 | 'textarea_name' => "auth_settings[$option]", |
| 4256 | 3407 | 'textarea_rows' => 5, |
| 4257 | - 'tinymce' => true, | |
| 4258 | - 'teeny' => true, | |
| 4259 | - 'quicktags' => false, | |
| 3408 | + 'tinymce' => true, | |
| 3409 | + 'teeny' => true, | |
| 3410 | + 'quicktags' => false, | |
| 4260 | 3411 | ) |
| 4261 | 3412 | ); |
| 4262 | 3413 | } |
| 4263 | 3414 | |
| 4264 | 3415 | |
| 4265 | - /** | |
| 4266 | - * Settings print callback. | |
| 4267 | - * | |
| 4268 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4269 | - * @return void | |
| 4270 | - */ | |
| 4271 | - public function print_checkbox_auth_access_should_email_approved_users( $args = '' ) { | |
| 3416 | + function print_checkbox_auth_access_should_email_approved_users( $args = '' ) { | |
| 4272 | 3417 | // Get plugin option. |
| 4273 | - $option = 'access_should_email_approved_users'; | |
| 3418 | + $option = 'access_should_email_approved_users'; | |
| 4274 | 3419 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4275 | 3420 | |
| 4276 | 3421 | // Print option elements. |
| 4277 | - ?> | |
| 4278 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label> | |
| 4279 | - <?php | |
| 3422 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Send a welcome email when approving a new user', 'authorizer' ); ?></label><?php | |
| 4280 | 3423 | } |
| 4281 | 3424 | |
| 4282 | 3425 | |
| 4283 | - /** | |
| 4284 | - * Settings print callback. | |
| 4285 | - * | |
| 4286 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4287 | - * @return void | |
| 4288 | - */ | |
| 4289 | - public function print_text_auth_access_email_approved_users_subject( $args = '' ) { | |
| 3426 | + function print_text_auth_access_email_approved_users_subject( $args = '' ) { | |
| 4290 | 3427 | // Get plugin option. |
| 4291 | - $option = 'access_email_approved_users_subject'; | |
| 3428 | + $option = 'access_email_approved_users_subject'; | |
| 4292 | 3429 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4293 | 3430 | |
| 4294 | 3431 | // Print option elements. |
| 4295 | - ?> | |
| 4296 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php echo wp_kses( __( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ), $this->allowed_html ); ?></small> | |
| 4297 | - <?php | |
| 3432 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="Welcome to [site_name]!" style="width:320px;" /><br /><small><?php _e( 'You can use the <b>[site_name]</b> shortcode.', 'authorizer' ); ?></small><?php | |
| 4298 | 3433 | } |
| 4299 | 3434 | |
| 4300 | 3435 | |
| 4301 | - /** | |
| 4302 | - * Settings print callback. | |
| 4303 | - * | |
| 4304 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4305 | - * @return void | |
| 4306 | - */ | |
| 4307 | - public function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) { | |
| 3436 | + function print_wysiwyg_auth_access_email_approved_users_body( $args = '' ) { | |
| 4308 | 3437 | // Get plugin option. |
| 4309 | - $option = 'access_email_approved_users_body'; | |
| 3438 | + $option = 'access_email_approved_users_body'; | |
| 4310 | 3439 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4311 | 3440 | |
| 4312 | 3441 | // Print option elements. |
| 4313 | 3442 | wp_editor( |
| @@ -4316,60 +3445,42 @@ | ||
| 4316 | 3445 | array( |
| 4317 | 3446 | 'media_buttons' => false, |
| 4318 | 3447 | 'textarea_name' => "auth_settings[$option]", |
| 4319 | 3448 | 'textarea_rows' => 9, |
| 4320 | - 'tinymce' => true, | |
| 4321 | - 'teeny' => true, | |
| 4322 | - 'quicktags' => false, | |
| 3449 | + 'tinymce' => true, | |
| 3450 | + 'teeny' => true, | |
| 3451 | + 'quicktags' => false, | |
| 4323 | 3452 | ) |
| 4324 | 3453 | ); |
| 4325 | - ?> | |
| 4326 | - <small> | |
| 4327 | - <?php | |
| 4328 | - printf( | |
| 4329 | - /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */ | |
| 4330 | - wp_kses( __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ), $this->allowed_html ), | |
| 4331 | - '<b>[site_name]</b>', | |
| 4332 | - '<b>[site_url]</b>', | |
| 4333 | - '<b>[user_email]</b>' | |
| 4334 | - ); | |
| 4335 | - ?> | |
| 4336 | - </small> | |
| 4337 | - <?php | |
| 3454 | + | |
| 3455 | + ?><small><?php printf( | |
| 3456 | + /* TRANSLATORS: 1: Shortcode for site name 2: Shortcode for site URL 3: Shortcode for user email */ | |
| 3457 | + __( 'You can use %1$s, %2$s, and %3$s shortcodes.', 'authorizer' ), | |
| 3458 | + '<b>[site_name]</b>', | |
| 3459 | + '<b>[site_url]</b>', | |
| 3460 | + '<b>[user_email]</b>' | |
| 3461 | + ); ?></small><?php | |
| 3462 | + | |
| 4338 | 3463 | } |
| 4339 | 3464 | |
| 4340 | 3465 | |
| 4341 | - /** | |
| 4342 | - * Settings print callback. | |
| 4343 | - * | |
| 4344 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4345 | - * @return void | |
| 4346 | - */ | |
| 4347 | - public function print_section_info_access_public( $args = '' ) { | |
| 4348 | - ?> | |
| 4349 | - <div id="section_info_access_public" class="section_info"> | |
| 4350 | - <p><?php esc_html_e( 'Choose your public access options here.', 'authorizer' ); ?></p> | |
| 4351 | - </div> | |
| 4352 | - <?php | |
| 3466 | + function print_section_info_access_public( $args = '' ) { | |
| 3467 | + ?><div id="section_info_access_public" class="section_info"> | |
| 3468 | + <p><?php _e( 'Choose your public access options here.', 'authorizer' ); ?></p> | |
| 3469 | + </div><?php | |
| 4353 | 3470 | } |
| 4354 | 3471 | |
| 4355 | 3472 | |
| 4356 | - /** | |
| 4357 | - * Settings print callback. | |
| 4358 | - * | |
| 4359 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4360 | - * @return void | |
| 4361 | - */ | |
| 4362 | - public function print_radio_auth_access_who_can_view( $args = '' ) { | |
| 3473 | + function print_radio_auth_access_who_can_view( $args = '' ) { | |
| 4363 | 3474 | // Get plugin option. |
| 4364 | - $option = 'access_who_can_view'; | |
| 4365 | - $admin_mode = $this->get_admin_mode( $args ); | |
| 3475 | + $option = 'access_who_can_view'; | |
| 3476 | + $admin_mode = $this->get_admin_mode( $args ); | |
| 4366 | 3477 | $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'allow override', 'print overlay' ); |
| 4367 | 3478 | |
| 4368 | 3479 | // If this site is configured independently of any multisite overrides, make sure we are not grabbing the multisite value; otherwise, grab the multisite value to show behind the disabled overlay. |
| 4369 | - if ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) { | |
| 3480 | + if ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) { | |
| 4370 | 3481 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4371 | - } elseif ( is_multisite() && WP_Plugin_Authorizer::SINGLE_CONTEXT === $admin_mode && '1' === $this->get_plugin_option( 'multisite_override', WP_Plugin_Authorizer::NETWORK_CONTEXT ) ) { | |
| 3482 | + } elseif ( is_multisite() && $admin_mode === SINGLE_ADMIN && $this->get_plugin_option( 'multisite_override', MULTISITE_ADMIN ) === '1' ) { | |
| 4372 | 3483 | // Workaround: javascript code hides/shows other settings based |
| 4373 | 3484 | // on the selection in this option. If this option is overridden |
| 4374 | 3485 | // by a multisite option, it should show that value in order to |
| 4375 | 3486 | // correctly display the other appropriate options. |
| @@ -4375,66 +3486,42 @@ | ||
| 4375 | 3486 | // correctly display the other appropriate options. |
| 4376 | 3487 | // Side effect: this site option will be overwritten by the |
| 4377 | 3488 | // multisite option on save. Since this is a 2-item radio, we |
| 4378 | 3489 | // determined this was acceptable. |
| 4379 | - $auth_settings_option = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 3490 | + $auth_settings_option = $this->get_plugin_option( $option, MULTISITE_ADMIN ); | |
| 4380 | 3491 | } |
| 4381 | 3492 | |
| 4382 | 3493 | // Print option elements. |
| 4383 | - ?> | |
| 4384 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="everyone"<?php checked( 'everyone' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_everyone"><?php esc_html_e( 'Everyone can see the site', 'authorizer' ); ?></label><br /> | |
| 4385 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="logged_in_users"<?php checked( 'logged_in_users' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_logged_in_users"><?php esc_html_e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br /> | |
| 4386 | - <?php | |
| 3494 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_everyone" name="auth_settings[<?php echo $option; ?>]" value="everyone"<?php checked( 'everyone' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_everyone"><?php _e( 'Everyone can see the site', 'authorizer' ); ?></label><br /> | |
| 3495 | + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_logged_in_users" name="auth_settings[<?php echo $option; ?>]" value="logged_in_users"<?php checked( 'logged_in_users' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_logged_in_users"><?php _e( 'Only logged in users can see the site', 'authorizer' ); ?></label><br /><?php | |
| 4387 | 3496 | } |
| 4388 | 3497 | |
| 4389 | 3498 | |
| 4390 | - /** | |
| 4391 | - * Settings print callback. | |
| 4392 | - * | |
| 4393 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4394 | - * @return void | |
| 4395 | - */ | |
| 4396 | - public function print_radio_auth_access_redirect( $args = '' ) { | |
| 3499 | + function print_radio_auth_access_redirect( $args = '' ) { | |
| 4397 | 3500 | // Get plugin option. |
| 4398 | - $option = 'access_redirect'; | |
| 3501 | + $option = 'access_redirect'; | |
| 4399 | 3502 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4400 | 3503 | |
| 4401 | 3504 | // Print option elements. |
| 4402 | - ?> | |
| 4403 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="login"<?php checked( 'login' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_login"><?php esc_html_e( 'Send them to the login screen', 'authorizer' ); ?></label><br /> | |
| 4404 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="message"<?php checked( 'message' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_to_message"><?php esc_html_e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label> | |
| 4405 | - <?php | |
| 3505 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_login" name="auth_settings[<?php echo $option; ?>]" value="login"<?php checked( 'login' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_login"><?php _e( 'Send them to the login screen', 'authorizer' ); ?></label><br /> | |
| 3506 | + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_to_message" name="auth_settings[<?php echo $option; ?>]" value="message"<?php checked( 'message' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_to_message"><?php _e( 'Show them the anonymous access message (below)', 'authorizer' ); ?></label><?php | |
| 4406 | 3507 | } |
| 4407 | 3508 | |
| 4408 | 3509 | |
| 4409 | - /** | |
| 4410 | - * Settings print callback. | |
| 4411 | - * | |
| 4412 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4413 | - * @return void | |
| 4414 | - */ | |
| 4415 | - public function print_radio_auth_access_public_warning( $args = '' ) { | |
| 3510 | + function print_radio_auth_access_public_warning( $args = '' ) { | |
| 4416 | 3511 | // Get plugin option. |
| 4417 | - $option = 'access_public_warning'; | |
| 3512 | + $option = 'access_public_warning'; | |
| 4418 | 3513 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4419 | 3514 | |
| 4420 | 3515 | // Print option elements. |
| 4421 | - ?> | |
| 4422 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="no_warning"<?php checked( 'no_warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_no"><?php echo wp_kses( __( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ), $this->allowed_html ); ?></label><br /> | |
| 4423 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="warning"<?php checked( 'warning' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>"><?php echo wp_kses( __( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ), $this->allowed_html ); ?></label> | |
| 4424 | - <?php | |
| 3516 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_no" name="auth_settings[<?php echo $option; ?>]" value="no_warning"<?php checked( 'no_warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_no"><?php _e( 'Show them the page <strong>without</strong> the anonymous access message', 'authorizer' ); ?></label><br /> | |
| 3517 | + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="warning"<?php checked( 'warning' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>"><?php _e( 'Show them the page <strong>with</strong> the anonymous access message (marked up as a <a href="http://getbootstrap.com/components/#alerts-dismissible" target="_blank">Bootstrap Dismissible Alert</a>)', 'authorizer' ); ?></label><?php | |
| 4425 | 3518 | } |
| 4426 | 3519 | |
| 4427 | 3520 | |
| 4428 | - /** | |
| 4429 | - * Settings print callback. | |
| 4430 | - * | |
| 4431 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4432 | - * @return void | |
| 4433 | - */ | |
| 4434 | - public function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) { | |
| 3521 | + function print_wysiwyg_auth_access_redirect_to_message( $args = '' ) { | |
| 4435 | 3522 | // Get plugin option. |
| 4436 | - $option = 'access_redirect_to_message'; | |
| 3523 | + $option = 'access_redirect_to_message'; | |
| 4437 | 3524 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4438 | 3525 | |
| 4439 | 3526 | // Print option elements. |
| 4440 | 3527 | wp_editor( |
| @@ -4443,25 +3530,19 @@ | ||
| 4443 | 3530 | array( |
| 4444 | 3531 | 'media_buttons' => false, |
| 4445 | 3532 | 'textarea_name' => "auth_settings[$option]", |
| 4446 | 3533 | 'textarea_rows' => 5, |
| 4447 | - 'tinymce' => true, | |
| 4448 | - 'teeny' => true, | |
| 4449 | - 'quicktags' => false, | |
| 3534 | + 'tinymce' => true, | |
| 3535 | + 'teeny' => true, | |
| 3536 | + 'quicktags' => false, | |
| 4450 | 3537 | ) |
| 4451 | 3538 | ); |
| 4452 | 3539 | } |
| 4453 | 3540 | |
| 4454 | 3541 | |
| 4455 | - /** | |
| 4456 | - * Settings print callback. | |
| 4457 | - * | |
| 4458 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4459 | - * @return void | |
| 4460 | - */ | |
| 4461 | - public function print_multiselect_auth_access_public_pages( $args = '' ) { | |
| 3542 | + function print_multiselect_auth_access_public_pages( $args = '' ) { | |
| 4462 | 3543 | // Get plugin option. |
| 4463 | - $option = 'access_public_pages'; | |
| 3544 | + $option = 'access_public_pages'; | |
| 4464 | 3545 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 4465 | 3546 | $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array(); |
| 4466 | 3547 | |
| 4467 | 3548 | $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) ); |
| @@ -4467,188 +3548,120 @@ | ||
| 4467 | 3548 | $post_types = array_merge( array( 'page', 'post' ), get_post_types( array( '_builtin' => false ), 'names' ) ); |
| 4468 | 3549 | $post_types = is_array( $post_types ) ? $post_types : array(); |
| 4469 | 3550 | |
| 4470 | 3551 | // Print option elements. |
| 4471 | - ?> | |
| 4472 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" multiple="multiple" name="auth_settings[<?php echo esc_attr( $option ); ?>][]"> | |
| 4473 | - <optgroup label="<?php esc_attr_e( 'Home', 'authorizer' ); ?>"> | |
| 4474 | - <option value="home" <?php selected( in_array( 'home', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Home Page', 'authorizer' ); ?></option> | |
| 4475 | - <option value="auth_public_404" <?php selected( in_array( 'auth_public_404', $auth_settings_option, true ) ); ?>><?php esc_html_e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option> | |
| 3552 | + ?><select id="auth_settings_<?php echo $option; ?>" multiple="multiple" name="auth_settings[<?php echo $option; ?>][]"> | |
| 3553 | + <optgroup label="<?php _e( 'Home', 'authorizer' ); ?>"> | |
| 3554 | + <option value="home" <?php echo in_array( 'home', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Home Page', 'authorizer' ); ?></option> | |
| 3555 | + <option value="auth_public_404" <?php echo in_array( 'auth_public_404', $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php _e( 'Nonexistent (404) Pages', 'authorizer' ); ?></option> | |
| 4476 | 3556 | </optgroup> |
| 4477 | - <?php foreach ( $post_types as $post_type ) : ?> | |
| 4478 | - <optgroup label="<?php echo esc_attr( ucfirst( $post_type ) ); ?>"> | |
| 4479 | - <?php | |
| 4480 | - $pages = get_posts( | |
| 4481 | - array( | |
| 4482 | - 'post_type' => $post_type, | |
| 4483 | - 'posts_per_page' => 1000, // phpcs:ignore WordPress.VIP.PostsPerPage.posts_per_page_posts_per_page | |
| 4484 | - ) | |
| 4485 | - ); | |
| 4486 | - $pages = is_array( $pages ) ? $pages : array(); | |
| 4487 | - foreach ( $pages as $page ) : | |
| 4488 | - ?> | |
| 4489 | - <option value="<?php echo esc_attr( $page->ID ); ?>" <?php selected( in_array( strval( $page->ID ), $auth_settings_option, true ) ); ?>><?php echo esc_html( $page->post_title ); ?></option> | |
| 3557 | + <?php foreach ( $post_types as $post_type ): ?> | |
| 3558 | + <optgroup label="<?php echo ucfirst( $post_type ); ?>"> | |
| 3559 | + <?php $pages = get_posts( array( 'post_type' => $post_type, 'posts_per_page' => -1 ) ); ?> | |
| 3560 | + <?php $pages = is_array( $pages ) ? $pages : array(); ?> | |
| 3561 | + <?php foreach ( $pages as $page ): ?> | |
| 3562 | + <option value="<?php echo $page->ID; ?>" <?php echo in_array( $page->ID, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $page->post_title; ?></option> | |
| 4490 | 3563 | <?php endforeach; ?> |
| 4491 | 3564 | </optgroup> |
| 4492 | 3565 | <?php endforeach; ?> |
| 4493 | - <optgroup label="<?php esc_attr_e( 'Categories', 'authorizer' ); ?>"> | |
| 4494 | - <?php | |
| 4495 | - // If sitepress-multilingual-cms plugin is enabled, temporarily disable | |
| 4496 | - // its terms_clauses filter since it conflicts with the category handling. | |
| 4497 | - if ( array_key_exists( 'sitepress', $GLOBALS ) && is_object( $GLOBALS['sitepress'] ) ) { | |
| 4498 | - remove_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) ); | |
| 4499 | - $categories = get_categories( array( 'hide_empty' => false ) ); | |
| 4500 | - add_filter( 'terms_clauses', array( $GLOBALS['sitepress'], 'terms_clauses' ) ); | |
| 4501 | - } else { | |
| 4502 | - $categories = get_categories( array( 'hide_empty' => false ) ); | |
| 4503 | - } | |
| 4504 | - foreach ( $categories as $category ) : | |
| 4505 | - ?> | |
| 4506 | - <option value="<?php echo esc_attr( 'cat_' . $category->slug ); ?>" <?php selected( in_array( 'cat_' . $category->slug, $auth_settings_option, true ) ); ?>><?php echo esc_html( $category->name ); ?></option> | |
| 3566 | + <optgroup label="<?php _e( 'Categories', 'authorizer' ); ?>"> | |
| 3567 | + <?php foreach ( get_categories() as $category ) : ?> | |
| 3568 | + <option value="<?php echo 'cat_' . $category->slug; ?>" <?php echo in_array( 'cat_' . $category->slug, $auth_settings_option ) ? 'selected="selected"' : ''; ?>><?php echo $category->name; ?></option> | |
| 4507 | 3569 | <?php endforeach; ?> |
| 4508 | 3570 | </optgroup> |
| 4509 | - </select> | |
| 4510 | - <?php | |
| 3571 | + </select><?php | |
| 4511 | 3572 | } |
| 4512 | 3573 | |
| 4513 | 3574 | |
| 4514 | - /** | |
| 4515 | - * Settings print callback. | |
| 4516 | - * | |
| 4517 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4518 | - * @return void | |
| 4519 | - */ | |
| 4520 | - public function print_section_info_external( $args = '' ) { | |
| 4521 | - ?> | |
| 4522 | - <div id="section_info_external" class="section_info"> | |
| 4523 | - <p><?php esc_html_e( 'Enter your external server settings below.', 'authorizer' ); ?></p> | |
| 4524 | - </div> | |
| 4525 | - <?php | |
| 3575 | + function print_section_info_external( $args = '' ) { | |
| 3576 | + ?><div id="section_info_external" class="section_info"> | |
| 3577 | + <p><?php _e( 'Enter your external server settings below.', 'authorizer' ); ?></p> | |
| 3578 | + </div><?php | |
| 4526 | 3579 | } |
| 4527 | 3580 | |
| 4528 | 3581 | |
| 4529 | - /** | |
| 4530 | - * Settings print callback. | |
| 4531 | - * | |
| 4532 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4533 | - * @return void | |
| 4534 | - */ | |
| 4535 | - public function print_select_auth_access_default_role( $args = '' ) { | |
| 3582 | + function get_admin_mode( $args ) { | |
| 3583 | + if ( is_array( $args ) && array_key_exists( MULTISITE_ADMIN, $args ) && $args[MULTISITE_ADMIN] === true ) { | |
| 3584 | + return MULTISITE_ADMIN; | |
| 3585 | + } else { | |
| 3586 | + return SINGLE_ADMIN; | |
| 3587 | + } | |
| 3588 | + } | |
| 3589 | + | |
| 3590 | + | |
| 3591 | + function print_select_auth_access_default_role( $args = '' ) { | |
| 4536 | 3592 | // Get plugin option. |
| 4537 | - $option = 'access_default_role'; | |
| 3593 | + $option = 'access_default_role'; | |
| 4538 | 3594 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4539 | 3595 | |
| 4540 | 3596 | // Print option elements. |
| 4541 | - ?> | |
| 4542 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]"> | |
| 3597 | + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]"> | |
| 4543 | 3598 | <?php wp_dropdown_roles( $auth_settings_option ); ?> |
| 4544 | - <option value=""<?php selected( '' === $auth_settings_option ); ?>><?php esc_html_e( '-- None --', 'authorizer' ); ?></option> | |
| 4545 | - </select> | |
| 4546 | - <?php | |
| 3599 | + </select><?php | |
| 4547 | 3600 | } |
| 4548 | 3601 | |
| 4549 | 3602 | |
| 4550 | - /** | |
| 4551 | - * Settings print callback. | |
| 4552 | - * | |
| 4553 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4554 | - * @return void | |
| 4555 | - */ | |
| 4556 | - public function print_checkbox_auth_external_google( $args = '' ) { | |
| 3603 | + function print_checkbox_auth_external_google( $args = '' ) { | |
| 4557 | 3604 | // Get plugin option. |
| 4558 | - $option = 'google'; | |
| 3605 | + $option = 'google'; | |
| 4559 | 3606 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4560 | 3607 | |
| 4561 | 3608 | // Print option elements. |
| 4562 | - ?> | |
| 4563 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable Google Logins', 'authorizer' ); ?></label> | |
| 4564 | - <?php | |
| 3609 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable Google Logins', 'authorizer' ); ?></label><?php | |
| 4565 | 3610 | } |
| 4566 | 3611 | |
| 4567 | 3612 | |
| 4568 | - /** | |
| 4569 | - * Settings print callback. | |
| 4570 | - * | |
| 4571 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4572 | - * @return void | |
| 4573 | - */ | |
| 4574 | - public function print_text_google_clientid( $args = '' ) { | |
| 3613 | + function print_text_google_clientid( $args = '' ) { | |
| 4575 | 3614 | // Get plugin option. |
| 4576 | - $option = 'google_clientid'; | |
| 3615 | + $option = 'google_clientid'; | |
| 4577 | 3616 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4578 | 3617 | |
| 4579 | 3618 | // Print option elements. |
| 4580 | - $site_url_parts = wp_parse_url( get_site_url() ); | |
| 4581 | - $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/'; | |
| 4582 | - | |
| 4583 | - esc_html_e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' ); | |
| 4584 | - ?> | |
| 3619 | + $site_url_parts = parse_url( get_site_url() ); | |
| 3620 | + $site_url_host = $site_url_parts['scheme'] . '://' . $site_url_parts['host'] . '/'; | |
| 3621 | + ?><?php _e( "If you don't have a Google Client ID and Secret, generate them by following these instructions:", 'authorizer' ); ?> | |
| 4585 | 3622 | <ol> |
| 4586 | - <li><?php echo wp_kses( __( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 4587 | - <li><?php echo wp_kses( __( 'Within the project, navigate to <em>APIs and Auth</em> > <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ), $this->allowed_html ); ?> | |
| 3623 | + <li><?php _e( 'Click <strong>Create a Project</strong> on the <a href="https://cloud.google.com/console" target="_blank">Google Developers Console</a>. You can name it whatever you want.', 'authorizer' ); ?></li> | |
| 3624 | + <li><?php _e( 'Within the project, navigate to <em>APIs and Auth</em> > <em>Credentials</em>, then click <strong>Create New Client ID</strong> under OAuth. Use these settings:', 'authorizer' ); ?> | |
| 4588 | 3625 | <ul> |
| 4589 | - <li><?php echo wp_kses( __( 'Application Type: <strong>Web application</strong>', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 4590 | - <li><?php esc_html_e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo esc_html( rtrim( $site_url_host, '/' ) ); ?></strong></li> | |
| 4591 | - <li><?php echo wp_kses( __( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 3626 | + <li><?php _e( 'Application Type: <strong>Web application</strong>', 'authorizer' ); ?></li> | |
| 3627 | + <li><?php _e( 'Authorized Javascript Origins:', 'authorizer' ); ?> <strong><?php echo rtrim( $site_url_host, '/' ); ?></strong></li> | |
| 3628 | + <li><?php _e( 'Authorized Redirect URI: <em>none</em>', 'authorizer' ); ?></li> | |
| 4592 | 3629 | </ul> |
| 4593 | 3630 | </li> |
| 4594 | - <li><?php esc_html_e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li> | |
| 4595 | - <li><?php echo wp_kses( __( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> > <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 4596 | - <li><?php echo wp_kses( __( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ), $this->allowed_html ); ?></li> | |
| 3631 | + <li><?php _e( 'Copy/paste your new Client ID/Secret pair into the fields below.', 'authorizer' ); ?></li> | |
| 3632 | + <li><?php _e( '<strong>Note</strong>: Navigate to <em>APIs and Auth</em> > <em>Consent screen</em> to change the way the Google consent screen appears after a user has successfully entered their password, but before they are redirected back to WordPress.', 'authorizer' ); ?></li> | |
| 3633 | + <li><?php _e( 'Note: Google may have a more recent version of these instructions in their <a href="https://developers.google.com/identity/sign-in/web/devconsole-project" target="_blank">developer documentation</a>.', 'authorizer' ); ?></li> | |
| 4597 | 3634 | </ol> |
| 4598 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:560px;" /> | |
| 4599 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com', 'authorizer' ); ?></label> | |
| 4600 | - <?php | |
| 3635 | + <input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com" style="width:560px;" /><?php | |
| 4601 | 3636 | } |
| 4602 | 3637 | |
| 4603 | 3638 | |
| 4604 | - /** | |
| 4605 | - * Settings print callback. | |
| 4606 | - * | |
| 4607 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4608 | - * @return void | |
| 4609 | - */ | |
| 4610 | - public function print_text_google_clientsecret( $args = '' ) { | |
| 3639 | + function print_text_google_clientsecret( $args = '' ) { | |
| 4611 | 3640 | // Get plugin option. |
| 4612 | - $option = 'google_clientsecret'; | |
| 3641 | + $option = 'google_clientsecret'; | |
| 4613 | 3642 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4614 | 3643 | |
| 4615 | 3644 | // Print option elements. |
| 4616 | - ?> | |
| 4617 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:220px;" /> | |
| 4618 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sDNgX5_pr_5bly-frKmvp8jT', 'authorizer' ); ?></label> | |
| 4619 | - <?php | |
| 3645 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="sDNgX5_pr_5bly-frKmvp8jT" style="width:220px;" /><?php | |
| 4620 | 3646 | } |
| 4621 | 3647 | |
| 4622 | 3648 | |
| 4623 | - /** | |
| 4624 | - * Settings print callback. | |
| 4625 | - * | |
| 4626 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4627 | - * @return void | |
| 4628 | - */ | |
| 4629 | - public function print_text_google_hosteddomain( $args = '' ) { | |
| 3649 | + function print_text_google_hosteddomain( $args = '' ) { | |
| 4630 | 3650 | // Get plugin option. |
| 4631 | - $option = 'google_hosteddomain'; | |
| 3651 | + $option = 'google_hosteddomain'; | |
| 4632 | 3652 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4633 | 3653 | |
| 4634 | 3654 | // Print option elements. |
| 4635 | - ?> | |
| 4636 | - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:220px;"><?php echo esc_html( $auth_settings_option ); ?></textarea> | |
| 4637 | - <br /><small><?php esc_html_e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?><br /><?php esc_html_e( 'If restricting to multiple domains, add one domain per line.', 'authorizer' ); ?></small> | |
| 3655 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="" style="width:220px;" /><br /> | |
| 3656 | + <small><?php _e( 'Restrict Google logins to a specific Google Apps hosted domain (for example, mycollege.edu). Leave blank to allow all Google sign-ins.', 'authorizer' ); ?></small> | |
| 4638 | 3657 | <?php |
| 4639 | 3658 | } |
| 4640 | 3659 | |
| 4641 | 3660 | |
| 4642 | - /** | |
| 4643 | - * Settings print callback. | |
| 4644 | - * | |
| 4645 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4646 | - * @return void | |
| 4647 | - */ | |
| 4648 | - public function print_checkbox_auth_external_cas( $args = '' ) { | |
| 3661 | + function print_checkbox_auth_external_cas( $args = '' ) { | |
| 4649 | 3662 | // Get plugin option. |
| 4650 | - $option = 'cas'; | |
| 3663 | + $option = 'cas'; | |
| 4651 | 3664 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4652 | 3665 | |
| 4653 | 3666 | // Make sure php5-curl extension is installed on server. |
| 4654 | 3667 | $curl_installed_message = ! function_exists( 'curl_init' ) ? __( '<a href="http://www.php.net//manual/en/curl.installation.php" target="_blank" style="color: red;">PHP CURL extension</a> is not installed', 'authorizer' ) : ''; |
| @@ -4667,217 +3680,122 @@ | ||
| 4667 | 3680 | ')</span>'; |
| 4668 | 3681 | } |
| 4669 | 3682 | |
| 4670 | 3683 | // Print option elements. |
| 4671 | - ?> | |
| 4672 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $error_message, $this->allowed_html ); ?> | |
| 4673 | - <?php | |
| 3684 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable CAS Logins', 'authorizer' ); ?></label> <?php echo $error_message; ?><?php | |
| 4674 | 3685 | } |
| 4675 | 3686 | |
| 4676 | 3687 | |
| 4677 | - /** | |
| 4678 | - * Settings print callback. | |
| 4679 | - * | |
| 4680 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4681 | - * @return void | |
| 4682 | - */ | |
| 4683 | - public function print_text_cas_custom_label( $args = '' ) { | |
| 3688 | + function print_text_cas_custom_label( $args = '' ) { | |
| 4684 | 3689 | // Get plugin option. |
| 4685 | - $option = 'cas_custom_label'; | |
| 3690 | + $option = 'cas_custom_label'; | |
| 4686 | 3691 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4687 | 3692 | |
| 4688 | 3693 | // Print option elements. |
| 4689 | - esc_html_e( 'The button on the login page will read:', 'authorizer' ); | |
| 4690 | - ?> | |
| 4691 | - <p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php esc_html_e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="CAS" style="width: 100px;" /></a></p> | |
| 4692 | - <?php | |
| 3694 | + ?><?php _e( 'The button on the login page will read:', 'authorizer' ); ?><p><a class="button-primary button-large" style="padding: 3px 16px; height: 36px;"><span class="dashicons dashicons-lock" style="margin: 4px 4px 0 0;"></span> <strong><?php _e( 'Sign in with', 'authorizer' ); ?> </strong><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="CAS" style="width: 100px;" /></a></p><?php | |
| 4693 | 3695 | } |
| 4694 | 3696 | |
| 4695 | 3697 | |
| 4696 | - /** | |
| 4697 | - * Settings print callback. | |
| 4698 | - * | |
| 4699 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4700 | - * @return void | |
| 4701 | - */ | |
| 4702 | - public function print_text_cas_host( $args = '' ) { | |
| 3698 | + function print_text_cas_host( $args = '' ) { | |
| 4703 | 3699 | // Get plugin option. |
| 4704 | - $option = 'cas_host'; | |
| 3700 | + $option = 'cas_host'; | |
| 4705 | 3701 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4706 | 3702 | |
| 4707 | 3703 | // Print option elements. |
| 4708 | - ?> | |
| 4709 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 4710 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: authn.example.edu', 'authorizer' ); ?></label> | |
| 4711 | - <?php | |
| 3704 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="authn.example.edu" /><?php | |
| 4712 | 3705 | } |
| 4713 | 3706 | |
| 4714 | 3707 | |
| 4715 | - /** | |
| 4716 | - * Settings print callback. | |
| 4717 | - * | |
| 4718 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4719 | - * @return void | |
| 4720 | - */ | |
| 4721 | - public function print_text_cas_port( $args = '' ) { | |
| 3708 | + function print_text_cas_port( $args = '' ) { | |
| 4722 | 3709 | // Get plugin option. |
| 4723 | - $option = 'cas_port'; | |
| 3710 | + $option = 'cas_port'; | |
| 4724 | 3711 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4725 | 3712 | |
| 4726 | 3713 | // Print option elements. |
| 4727 | - ?> | |
| 4728 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" /> | |
| 4729 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 443', 'authorizer' ); ?></label> | |
| 4730 | - <?php | |
| 3714 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="443" style="width:50px;" /><?php | |
| 4731 | 3715 | } |
| 4732 | 3716 | |
| 4733 | 3717 | |
| 4734 | - /** | |
| 4735 | - * Settings print callback. | |
| 4736 | - * | |
| 4737 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4738 | - * @return void | |
| 4739 | - */ | |
| 4740 | - public function print_text_cas_path( $args = '' ) { | |
| 3718 | + function print_text_cas_path( $args = '' ) { | |
| 4741 | 3719 | // Get plugin option. |
| 4742 | - $option = 'cas_path'; | |
| 3720 | + $option = 'cas_path'; | |
| 4743 | 3721 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4744 | 3722 | |
| 4745 | 3723 | // Print option elements. |
| 4746 | - ?> | |
| 4747 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 4748 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: /cas', 'authorizer' ); ?></label> | |
| 4749 | - <?php | |
| 3724 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="/cas" /><?php | |
| 4750 | 3725 | } |
| 4751 | 3726 | |
| 4752 | 3727 | |
| 4753 | - /** | |
| 4754 | - * Settings print callback. | |
| 4755 | - * | |
| 4756 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4757 | - * @return void | |
| 4758 | - */ | |
| 4759 | - public function print_select_cas_version( $args = '' ) { | |
| 3728 | + function print_select_cas_version( $args = '' ) { | |
| 4760 | 3729 | // Get plugin option. |
| 4761 | - $option = 'cas_version'; | |
| 3730 | + $option = 'cas_version'; | |
| 4762 | 3731 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4763 | 3732 | |
| 4764 | 3733 | // Print option elements. |
| 4765 | - ?> | |
| 4766 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]"> | |
| 3734 | + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]"> | |
| 4767 | 3735 | <option value="SAML_VERSION_1_1" <?php selected( $auth_settings_option, 'SAML_VERSION_1_1' ); ?>>SAML_VERSION_1_1</option> |
| 4768 | 3736 | <option value="CAS_VERSION_3_0" <?php selected( $auth_settings_option, 'CAS_VERSION_3_0' ); ?>>CAS_VERSION_3_0</option> |
| 4769 | 3737 | <option value="CAS_VERSION_2_0" <?php selected( $auth_settings_option, 'CAS_VERSION_2_0' ); ?>>CAS_VERSION_2_0</option> |
| 4770 | 3738 | <option value="CAS_VERSION_1_0" <?php selected( $auth_settings_option, 'CAS_VERSION_1_0' ); ?>>CAS_VERSION_1_0</option> |
| 4771 | - </select> | |
| 4772 | - <?php | |
| 3739 | + </select><?php | |
| 4773 | 3740 | } |
| 4774 | 3741 | |
| 4775 | 3742 | |
| 4776 | - /** | |
| 4777 | - * Settings print callback. | |
| 4778 | - * | |
| 4779 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4780 | - * @return void | |
| 4781 | - */ | |
| 4782 | - public function print_text_cas_attr_email( $args = '' ) { | |
| 3743 | + function print_text_cas_attr_email( $args = '' ) { | |
| 4783 | 3744 | // Get plugin option. |
| 4784 | - $option = 'cas_attr_email'; | |
| 3745 | + $option = 'cas_attr_email'; | |
| 4785 | 3746 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4786 | 3747 | |
| 4787 | 3748 | // Print option elements. |
| 4788 | - ?> | |
| 4789 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 4790 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label> | |
| 4791 | - <br /><small><?php echo wp_kses( __( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small> | |
| 4792 | - <?php | |
| 3749 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="mail" /> | |
| 3750 | + <br /><small><?php _e( "Note: If your CAS server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php | |
| 4793 | 3751 | } |
| 4794 | 3752 | |
| 4795 | 3753 | |
| 4796 | - /** | |
| 4797 | - * Settings print callback. | |
| 4798 | - * | |
| 4799 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4800 | - * @return void | |
| 4801 | - */ | |
| 4802 | - public function print_text_cas_attr_first_name( $args = '' ) { | |
| 3754 | + function print_text_cas_attr_first_name( $args = '' ) { | |
| 4803 | 3755 | // Get plugin option. |
| 4804 | - $option = 'cas_attr_first_name'; | |
| 3756 | + $option = 'cas_attr_first_name'; | |
| 4805 | 3757 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4806 | 3758 | |
| 4807 | 3759 | // Print option elements. |
| 4808 | - ?> | |
| 4809 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 4810 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenName', 'authorizer' ); ?></label> | |
| 4811 | - <?php | |
| 3760 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="givenName" /><?php | |
| 4812 | 3761 | } |
| 4813 | 3762 | |
| 4814 | 3763 | |
| 4815 | - /** | |
| 4816 | - * Settings print callback. | |
| 4817 | - * | |
| 4818 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4819 | - * @return void | |
| 4820 | - */ | |
| 4821 | - public function print_text_cas_attr_last_name( $args = '' ) { | |
| 3764 | + function print_text_cas_attr_last_name( $args = '' ) { | |
| 4822 | 3765 | // Get plugin option. |
| 4823 | - $option = 'cas_attr_last_name'; | |
| 3766 | + $option = 'cas_attr_last_name'; | |
| 4824 | 3767 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4825 | 3768 | |
| 4826 | 3769 | // Print option elements. |
| 4827 | - ?> | |
| 4828 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 4829 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label> | |
| 4830 | - <?php | |
| 3770 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="sn" /><?php | |
| 4831 | 3771 | } |
| 4832 | 3772 | |
| 4833 | 3773 | |
| 4834 | - /** | |
| 4835 | - * Settings print callback. | |
| 4836 | - * | |
| 4837 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4838 | - * @return void | |
| 4839 | - */ | |
| 4840 | - public function print_checkbox_cas_attr_update_on_login( $args = '' ) { | |
| 3774 | + function print_checkbox_cas_attr_update_on_login( $args = '' ) { | |
| 4841 | 3775 | // Get plugin option. |
| 4842 | - $option = 'cas_attr_update_on_login'; | |
| 3776 | + $option = 'cas_attr_update_on_login'; | |
| 4843 | 3777 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4844 | 3778 | |
| 4845 | 3779 | // Print option elements. |
| 4846 | - ?> | |
| 4847 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label> | |
| 4848 | - <?php | |
| 3780 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php | |
| 4849 | 3781 | } |
| 4850 | 3782 | |
| 4851 | 3783 | |
| 4852 | - /** | |
| 4853 | - * Settings print callback. | |
| 4854 | - * | |
| 4855 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4856 | - * @return void | |
| 4857 | - */ | |
| 4858 | - public function print_checkbox_cas_auto_login( $args = '' ) { | |
| 3784 | + function print_checkbox_cas_auto_login( $args = '' ) { | |
| 4859 | 3785 | // Get plugin option. |
| 4860 | - $option = 'cas_auto_login'; | |
| 3786 | + $option = 'cas_auto_login'; | |
| 4861 | 3787 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4862 | 3788 | |
| 4863 | 3789 | // Print option elements. |
| 4864 | - ?> | |
| 4865 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label> | |
| 4866 | - <p><small><?php esc_html_e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p> | |
| 4867 | - <?php | |
| 3790 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Immediately redirect to CAS login form if it's the only enabled external service and WordPress logins are hidden", 'authorizer' ); ?></label> | |
| 3791 | + <p><small><?php _e( 'Note: This feature will only work if you have checked "Hide WordPress Logins" in Advanced settings, and if CAS is the only enabled service (i.e., no Google or LDAP). If you have enabled CAS Single Sign-On (SSO), and a user has already logged into CAS elsewhere, enabling this feature will allow automatic logins without any user interaction.', 'authorizer' ); ?></small></p><?php | |
| 4868 | 3792 | } |
| 4869 | 3793 | |
| 4870 | 3794 | |
| 4871 | - /** | |
| 4872 | - * Settings print callback. | |
| 4873 | - * | |
| 4874 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4875 | - * @return void | |
| 4876 | - */ | |
| 4877 | - public function print_checkbox_auth_external_ldap( $args = '' ) { | |
| 3795 | + function print_checkbox_auth_external_ldap( $args = '' ) { | |
| 4878 | 3796 | // Get plugin option. |
| 4879 | - $option = 'ldap'; | |
| 3797 | + $option = 'ldap'; | |
| 4880 | 3798 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4881 | 3799 | |
| 4882 | 3800 | // Make sure php5-ldap extension is installed on server. |
| 4883 | 3801 | $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : ''; |
| @@ -4882,324 +3800,185 @@ | ||
| 4882 | 3800 | // Make sure php5-ldap extension is installed on server. |
| 4883 | 3801 | $ldap_installed_message = ! function_exists( 'ldap_connect' ) ? '<span style="color: red;">(' . __( 'Warning: <a href="http://www.php.net/manual/en/ldap.installation.php" target="_blank" style="color: red;">PHP LDAP extension</a> is <strong>not</strong> installed', 'authorizer' ) . ')</span>' : ''; |
| 4884 | 3802 | |
| 4885 | 3803 | // Print option elements. |
| 4886 | - ?> | |
| 4887 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo wp_kses( $ldap_installed_message, $this->allowed_html ); ?> | |
| 4888 | - <?php | |
| 3804 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Enable LDAP Logins', 'authorizer' ); ?></label> <?php echo $ldap_installed_message; ?><?php | |
| 4889 | 3805 | } |
| 4890 | 3806 | |
| 4891 | 3807 | |
| 4892 | - /** | |
| 4893 | - * Settings print callback. | |
| 4894 | - * | |
| 4895 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4896 | - * @return void | |
| 4897 | - */ | |
| 4898 | - public function print_text_ldap_host( $args = '' ) { | |
| 3808 | + function print_text_ldap_host( $args = '' ) { | |
| 4899 | 3809 | // Get plugin option. |
| 4900 | - $option = 'ldap_host'; | |
| 3810 | + $option = 'ldap_host'; | |
| 4901 | 3811 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4902 | 3812 | |
| 4903 | 3813 | // Print option elements. |
| 4904 | - ?> | |
| 4905 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" /> | |
| 4906 | - <br /><small><?php esc_html_e( 'Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).', 'authorizer' ); ?></small> | |
| 4907 | - <?php | |
| 3814 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="ldap.example.edu" style="width:330px;" /> | |
| 3815 | + <br /><small><?php _e( "Specify either a hostname (for example, ldap.example.edu) or a full LDAP URI (for example, ldaps://ldap.example.edu:636).", 'authorizer' ); ?></small><?php | |
| 4908 | 3816 | } |
| 4909 | 3817 | |
| 4910 | 3818 | |
| 4911 | - /** | |
| 4912 | - * Settings print callback. | |
| 4913 | - * | |
| 4914 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4915 | - * @return void | |
| 4916 | - */ | |
| 4917 | - public function print_text_ldap_port( $args = '' ) { | |
| 3819 | + function print_text_ldap_port( $args = '' ) { | |
| 4918 | 3820 | // Get plugin option. |
| 4919 | - $option = 'ldap_port'; | |
| 3821 | + $option = 'ldap_port'; | |
| 4920 | 3822 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4921 | 3823 | |
| 4922 | 3824 | // Print option elements. |
| 4923 | - ?> | |
| 4924 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:50px;" /> | |
| 4925 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: 389', 'authorizer' ); ?></label> | |
| 4926 | - <br /><small><?php esc_html_e( 'If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.', 'authorizer' ); ?></small> | |
| 4927 | - <?php | |
| 3825 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="389" style="width:50px;" /> | |
| 3826 | + <br /><small><?php _e( "If a full LDAP URI (ldaps://hostname:port) is specified above, this field is ignored.", 'authorizer' ); ?></small><?php | |
| 4928 | 3827 | } |
| 4929 | 3828 | |
| 4930 | 3829 | |
| 4931 | - /** | |
| 4932 | - * Settings print callback. | |
| 4933 | - * | |
| 4934 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4935 | - * @return void | |
| 4936 | - */ | |
| 4937 | - public function print_checkbox_ldap_tls( $args = '' ) { | |
| 3830 | + function print_checkbox_ldap_tls( $args = '' ) { | |
| 4938 | 3831 | // Get plugin option. |
| 4939 | - $option = 'ldap_tls'; | |
| 3832 | + $option = 'ldap_tls'; | |
| 4940 | 3833 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4941 | 3834 | |
| 4942 | 3835 | // Print option elements. |
| 4943 | - ?> | |
| 4944 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></label> | |
| 4945 | - <br /><small><?php esc_html_e( 'If ldaps is used, this should be unchecked', 'authorizer' ); ?></small> | |
| 4946 | - <?php | |
| 3836 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Use TLS', 'authorizer' ); ?></label><?php | |
| 4947 | 3837 | } |
| 4948 | 3838 | |
| 4949 | 3839 | |
| 4950 | - /** | |
| 4951 | - * Settings print callback. | |
| 4952 | - * | |
| 4953 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4954 | - * @return void | |
| 4955 | - */ | |
| 4956 | - public function print_text_ldap_search_base( $args = '' ) { | |
| 3840 | + function print_text_ldap_search_base( $args = '' ) { | |
| 4957 | 3841 | // Get plugin option. |
| 4958 | - $option = 'ldap_search_base'; | |
| 3842 | + $option = 'ldap_search_base'; | |
| 4959 | 3843 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4960 | 3844 | |
| 4961 | 3845 | // Print option elements. |
| 4962 | - ?> | |
| 4963 | - <textarea id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" placeholder="" style="width:330px;"><?php echo esc_attr( $auth_settings_option ); ?></textarea> | |
| 4964 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: ou=people,dc=example,dc=edu', 'authorizer' ); ?></label> | |
| 4965 | - <br /><small><?php esc_html_e( 'If you have multiple search bases, separate them by newlines (one per line).', 'authorizer' ); ?></small> | |
| 4966 | - <?php | |
| 3846 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="ou=people,dc=example,dc=edu" style="width:330px;" /><?php | |
| 4967 | 3847 | } |
| 4968 | 3848 | |
| 4969 | 3849 | |
| 4970 | - /** | |
| 4971 | - * Settings print callback. | |
| 4972 | - * | |
| 4973 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4974 | - * @return void | |
| 4975 | - */ | |
| 4976 | - public function print_text_ldap_uid( $args = '' ) { | |
| 3850 | + function print_text_ldap_uid( $args = '' ) { | |
| 4977 | 3851 | // Get plugin option. |
| 4978 | - $option = 'ldap_uid'; | |
| 3852 | + $option = 'ldap_uid'; | |
| 4979 | 3853 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4980 | 3854 | |
| 4981 | 3855 | // Print option elements. |
| 4982 | - ?> | |
| 4983 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:80px;" /> | |
| 4984 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: uid', 'authorizer' ); ?></label> | |
| 4985 | - <?php | |
| 3856 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="uid" style="width:80px;" /><?php | |
| 4986 | 3857 | } |
| 4987 | 3858 | |
| 4988 | 3859 | |
| 4989 | - /** | |
| 4990 | - * Settings print callback. | |
| 4991 | - * | |
| 4992 | - * @param string $args Args (e.g., multisite admin mode). | |
| 4993 | - * @return void | |
| 4994 | - */ | |
| 4995 | - public function print_text_ldap_attr_email( $args = '' ) { | |
| 3860 | + function print_text_ldap_attr_email( $args = '' ) { | |
| 4996 | 3861 | // Get plugin option. |
| 4997 | - $option = 'ldap_attr_email'; | |
| 3862 | + $option = 'ldap_attr_email'; | |
| 4998 | 3863 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 4999 | 3864 | |
| 5000 | 3865 | // Print option elements. |
| 5001 | - ?> | |
| 5002 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 5003 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: mail', 'authorizer' ); ?></label> | |
| 5004 | - <br /><small><?php echo wp_kses( __( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ), $this->allowed_html ); ?></small> | |
| 5005 | - <?php | |
| 3866 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="mail" /> | |
| 3867 | + <br /><small><?php _e( "Note: If your LDAP server doesn't return an attribute containing an email, you can specify the @domain portion of the email address here, and the email address will be constructed from it and the username. For example, if user 'bob' logs in and his email address should be bob@example.edu, then enter <strong>@example.edu</strong> in this field.", 'authorizer' ); ?></small><?php | |
| 5006 | 3868 | } |
| 5007 | 3869 | |
| 5008 | 3870 | |
| 5009 | - /** | |
| 5010 | - * Settings print callback. | |
| 5011 | - * | |
| 5012 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5013 | - * @return void | |
| 5014 | - */ | |
| 5015 | - public function print_text_ldap_user( $args = '' ) { | |
| 3871 | + function print_text_ldap_user( $args = '' ) { | |
| 5016 | 3872 | // Get plugin option. |
| 5017 | - $option = 'ldap_user'; | |
| 3873 | + $option = 'ldap_user'; | |
| 5018 | 3874 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5019 | 3875 | |
| 5020 | 3876 | // Print option elements. |
| 5021 | - ?> | |
| 5022 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width:330px;" /> | |
| 5023 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: cn=directory-user,ou=specials,dc=example,dc=edu', 'authorizer' ); ?></label> | |
| 5024 | - <?php | |
| 3877 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="cn=directory-user,ou=specials,dc=example,dc=edu" style="width:330px;" /><?php | |
| 5025 | 3878 | } |
| 5026 | 3879 | |
| 5027 | 3880 | |
| 5028 | - /** | |
| 5029 | - * Settings print callback. | |
| 5030 | - * | |
| 5031 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5032 | - * @return void | |
| 5033 | - */ | |
| 5034 | - public function print_password_ldap_password( $args = '' ) { | |
| 3881 | + function print_password_ldap_password( $args = '' ) { | |
| 5035 | 3882 | // Get plugin option. |
| 5036 | - $option = 'ldap_password'; | |
| 3883 | + $option = 'ldap_password'; | |
| 5037 | 3884 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5038 | 3885 | |
| 5039 | 3886 | // Print option elements. |
| 5040 | - ?> | |
| 5041 | - <input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" /> | |
| 5042 | - <input type="password" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $this->decrypt( $auth_settings_option ) ); ?>" autocomplete="off" /> | |
| 5043 | - <?php | |
| 3887 | + ?><input type="password" id="garbage_to_stop_autofill" name="garbage" value="" autocomplete="off" style="display:none;" /> | |
| 3888 | + <input type="password" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $this->decrypt( base64_decode( $auth_settings_option ) ); ?>" autocomplete="off" /><?php | |
| 5044 | 3889 | } |
| 5045 | 3890 | |
| 5046 | 3891 | |
| 5047 | - /** | |
| 5048 | - * Settings print callback. | |
| 5049 | - * | |
| 5050 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5051 | - * @return void | |
| 5052 | - */ | |
| 5053 | - public function print_text_ldap_lostpassword_url( $args = '' ) { | |
| 3892 | + function print_text_ldap_lostpassword_url( $args = '' ) { | |
| 5054 | 3893 | // Get plugin option. |
| 5055 | - $option = 'ldap_lostpassword_url'; | |
| 3894 | + $option = 'ldap_lostpassword_url'; | |
| 5056 | 3895 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5057 | 3896 | |
| 5058 | 3897 | // Print option elements. |
| 5059 | - ?> | |
| 5060 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" style="width: 400px;" /> | |
| 5061 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: https://myschool.example.edu:8888/am-forgot-password', 'authorizer' ); ?></label> | |
| 5062 | - <?php | |
| 3898 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="https://myschool.example.edu:8888/am-forgot-password" style="width: 400px;" /><?php | |
| 5063 | 3899 | } |
| 5064 | 3900 | |
| 5065 | 3901 | |
| 5066 | - /** | |
| 5067 | - * Settings print callback. | |
| 5068 | - * | |
| 5069 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5070 | - * @return void | |
| 5071 | - */ | |
| 5072 | - public function print_text_ldap_attr_first_name( $args = '' ) { | |
| 3902 | + function print_text_ldap_attr_first_name( $args = '' ) { | |
| 5073 | 3903 | // Get plugin option. |
| 5074 | - $option = 'ldap_attr_first_name'; | |
| 3904 | + $option = 'ldap_attr_first_name'; | |
| 5075 | 3905 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5076 | 3906 | |
| 5077 | 3907 | // Print option elements. |
| 5078 | - ?> | |
| 5079 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 5080 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: givenname', 'authorizer' ); ?></label> | |
| 5081 | - <?php | |
| 3908 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="givenname" /><?php | |
| 5082 | 3909 | } |
| 5083 | 3910 | |
| 5084 | 3911 | |
| 5085 | - /** | |
| 5086 | - * Settings print callback. | |
| 5087 | - * | |
| 5088 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5089 | - * @return void | |
| 5090 | - */ | |
| 5091 | - public function print_text_ldap_attr_last_name( $args = '' ) { | |
| 3912 | + function print_text_ldap_attr_last_name( $args = '' ) { | |
| 5092 | 3913 | // Get plugin option. |
| 5093 | - $option = 'ldap_attr_last_name'; | |
| 3914 | + $option = 'ldap_attr_last_name'; | |
| 5094 | 3915 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5095 | 3916 | |
| 5096 | 3917 | // Print option elements. |
| 5097 | - ?> | |
| 5098 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" /> | |
| 5099 | - <br /><label for="auth_settings_<?php echo esc_attr( $option ); ?>" class="helper"><?php esc_html_e( 'Example: sn', 'authorizer' ); ?></label> | |
| 5100 | - <?php | |
| 3918 | + ?><input type="text" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $auth_settings_option; ?>" placeholder="sn" /><?php | |
| 5101 | 3919 | } |
| 5102 | 3920 | |
| 5103 | 3921 | |
| 5104 | - /** | |
| 5105 | - * Settings print callback. | |
| 5106 | - * | |
| 5107 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5108 | - * @return void | |
| 5109 | - */ | |
| 5110 | - public function print_checkbox_ldap_attr_update_on_login( $args = '' ) { | |
| 3922 | + function print_checkbox_ldap_attr_update_on_login( $args = '' ) { | |
| 5111 | 3923 | // Get plugin option. |
| 5112 | - $option = 'ldap_attr_update_on_login'; | |
| 3924 | + $option = 'ldap_attr_update_on_login'; | |
| 5113 | 3925 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5114 | 3926 | |
| 5115 | 3927 | // Print option elements. |
| 5116 | - ?> | |
| 5117 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label> | |
| 5118 | - <?php | |
| 3928 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Update first and last name fields on login (will overwrite any name the user has supplied in their profile)', 'authorizer' ); ?></label><?php | |
| 5119 | 3929 | } |
| 5120 | 3930 | |
| 5121 | 3931 | |
| 5122 | - /** | |
| 5123 | - * Settings print callback. | |
| 5124 | - * | |
| 5125 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5126 | - * @return void | |
| 5127 | - */ | |
| 5128 | - public function print_section_info_advanced( $args = '' ) { | |
| 5129 | - ?> | |
| 5130 | - <div id="section_info_advanced" class="section_info"> | |
| 5131 | - <p><?php esc_html_e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p> | |
| 5132 | - </div> | |
| 5133 | - <?php | |
| 3932 | + function print_section_info_advanced( $args = '' ) { | |
| 3933 | + ?><div id="section_info_advanced" class="section_info"> | |
| 3934 | + <p><?php _e( 'You may optionally specify some advanced settings below.', 'authorizer' ); ?></p> | |
| 3935 | + </div><?php | |
| 5134 | 3936 | } |
| 5135 | 3937 | |
| 5136 | 3938 | |
| 5137 | - /** | |
| 5138 | - * Settings print callback. | |
| 5139 | - * | |
| 5140 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5141 | - * @return void | |
| 5142 | - */ | |
| 5143 | - public function print_text_auth_advanced_lockouts( $args = '' ) { | |
| 3939 | + function print_text_auth_advanced_lockouts( $args = '' ) { | |
| 5144 | 3940 | // Get plugin option. |
| 5145 | - $option = 'advanced_lockouts'; | |
| 3941 | + $option = 'advanced_lockouts'; | |
| 5146 | 3942 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5147 | 3943 | |
| 5148 | 3944 | // Print option elements. |
| 5149 | - esc_html_e( 'After', 'authorizer' ); | |
| 5150 | - ?> | |
| 5151 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_1]" value="<?php echo esc_attr( $auth_settings_option['attempts_1'] ); ?>" placeholder="10" style="width:30px;" /> | |
| 5152 | - <?php esc_html_e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?> | |
| 5153 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_1" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_1]" value="<?php echo esc_attr( $auth_settings_option['duration_1'] ); ?>" placeholder="1" style="width:30px;" /> | |
| 5154 | - <?php esc_html_e( 'minute(s).', 'authorizer' ); ?> | |
| 3945 | + ?><?php _e( 'After', 'authorizer' ); ?> | |
| 3946 | + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_1" name="auth_settings[<?php echo $option; ?>][attempts_1]" value="<?php echo $auth_settings_option['attempts_1']; ?>" placeholder="10" style="width:30px;" /> | |
| 3947 | + <?php _e( 'invalid password attempts, delay further attempts on that user for', 'authorizer' ); ?> | |
| 3948 | + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_1" name="auth_settings[<?php echo $option; ?>][duration_1]" value="<?php echo $auth_settings_option['duration_1']; ?>" placeholder="1" style="width:30px;" /> | |
| 3949 | + <?php _e( 'minute(s).', 'authorizer' ); ?> | |
| 5155 | 3950 | <br /> |
| 5156 | - <?php esc_html_e( 'After', 'authorizer' ); ?> | |
| 5157 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_attempts_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][attempts_2]" value="<?php echo esc_attr( $auth_settings_option['attempts_2'] ); ?>" placeholder="10" style="width:30px;" /> | |
| 5158 | - <?php esc_html_e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?> | |
| 5159 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_duration_2" name="auth_settings[<?php echo esc_attr( $option ); ?>][duration_2]" value="<?php echo esc_attr( $auth_settings_option['duration_2'] ); ?>" placeholder="10" style="width:30px;" /> | |
| 5160 | - <?php esc_html_e( 'minutes.', 'authorizer' ); ?> | |
| 3951 | + <?php _e( 'After', 'authorizer' ); ?> | |
| 3952 | + <input type="text" id="auth_settings_<?php echo $option; ?>_attempts_2" name="auth_settings[<?php echo $option; ?>][attempts_2]" value="<?php echo $auth_settings_option['attempts_2']; ?>" placeholder="10" style="width:30px;" /> | |
| 3953 | + <?php _e( 'more invalid attempts, increase the delay to', 'authorizer' ); ?> | |
| 3954 | + <input type="text" id="auth_settings_<?php echo $option; ?>_duration_2" name="auth_settings[<?php echo $option; ?>][duration_2]" value="<?php echo $auth_settings_option['duration_2']; ?>" placeholder="10" style="width:30px;" /> | |
| 3955 | + <?php _e( 'minutes.', 'authorizer' ); ?> | |
| 5161 | 3956 | <br /> |
| 5162 | - <?php esc_html_e( 'Reset the delays after', 'authorizer' ); ?> | |
| 5163 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>_reset_duration" name="auth_settings[<?php echo esc_attr( $option ); ?>][reset_duration]" value="<?php echo esc_attr( $auth_settings_option['reset_duration'] ); ?>" placeholder="240" style="width:40px;" /> | |
| 5164 | - <?php esc_html_e( 'minutes with no invalid attempts.', 'authorizer' ); ?> | |
| 5165 | - <?php | |
| 3957 | + <?php _e( 'Reset the delays after', 'authorizer' ); ?> | |
| 3958 | + <input type="text" id="auth_settings_<?php echo $option; ?>_reset_duration" name="auth_settings[<?php echo $option; ?>][reset_duration]" value="<?php echo $auth_settings_option['reset_duration']; ?>" placeholder="240" style="width:40px;" /> | |
| 3959 | + <?php _e( 'minutes with no invalid attempts.', 'authorizer' ); ?><?php | |
| 5166 | 3960 | } |
| 5167 | 3961 | |
| 5168 | 3962 | |
| 5169 | - /** | |
| 5170 | - * Settings print callback. | |
| 5171 | - * | |
| 5172 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5173 | - * @return void | |
| 5174 | - */ | |
| 5175 | - public function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) { | |
| 3963 | + function print_checkbox_auth_advanced_hide_wp_login( $args = '' ) { | |
| 5176 | 3964 | // Get plugin option. |
| 5177 | - $option = 'advanced_hide_wp_login'; | |
| 3965 | + $option = 'advanced_hide_wp_login'; | |
| 5178 | 3966 | $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); |
| 5179 | 3967 | |
| 5180 | 3968 | // Print option elements. |
| 5181 | - ?> | |
| 5182 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></label> | |
| 5183 | - <p><small><?php esc_html_e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo esc_attr( wp_login_url() ); ?>?external=wordpress" target="_blank"><?php echo esc_html( wp_login_url() ); ?>?external=wordpress</a>.</p> | |
| 5184 | - <?php | |
| 3969 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></label> | |
| 3970 | + <p><small><?php _e( 'Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ); ?><br /><a href="<?php echo wp_login_url(); ?>?external=wordpress" target="_blank"><?php echo wp_login_url(); ?>?external=wordpress</a>.</p><?php | |
| 5185 | 3971 | } |
| 5186 | 3972 | |
| 5187 | 3973 | |
| 5188 | - /** | |
| 5189 | - * Settings print callback. | |
| 5190 | - * | |
| 5191 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5192 | - * @return void | |
| 5193 | - */ | |
| 5194 | - public function print_radio_auth_advanced_branding( $args = '' ) { | |
| 3974 | + function print_radio_auth_advanced_branding( $args = '' ) { | |
| 5195 | 3975 | // Get plugin option. |
| 5196 | - $option = 'advanced_branding'; | |
| 3976 | + $option = 'advanced_branding'; | |
| 5197 | 3977 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 5198 | 3978 | |
| 5199 | 3979 | // Print option elements. |
| 5200 | - ?> | |
| 5201 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="default"<?php checked( 'default' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_default"><?php esc_html_e( 'Default WordPress login screen', 'authorizer' ); ?></label><br /> | |
| 3980 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_default" name="auth_settings[<?php echo $option; ?>]" value="default"<?php checked( 'default' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_default"><?php _e( 'Default WordPress login screen', 'authorizer' ); ?></label><br /> | |
| 5202 | 3981 | <?php |
| 5203 | 3982 | |
| 5204 | 3983 | /** |
| 5205 | 3984 | * Developers can use the `authorizer_add_branding_option` filter |
| @@ -5204,8 +3983,9 @@ | ||
| 5204 | 3983 | /** |
| 5205 | 3984 | * Developers can use the `authorizer_add_branding_option` filter |
| 5206 | 3985 | * to add a radio button for "Custom WordPress login branding" |
| 5207 | 3986 | * under the "Advanced" tab in Authorizer options. Example: |
| 3987 | + * | |
| 5208 | 3988 | * function my_authorizer_add_branding_option( $branding_options ) { |
| 5209 | 3989 | * $new_branding_option = array( |
| 5210 | 3990 | * 'value' => 'your_brand' |
| 5211 | 3991 | * 'description' => 'Custom Your Brand Login Screen', |
| @@ -5219,274 +3999,133 @@ | ||
| 5219 | 3999 | */ |
| 5220 | 4000 | $branding_options = array(); |
| 5221 | 4001 | $branding_options = apply_filters( 'authorizer_add_branding_option', $branding_options ); |
| 5222 | 4002 | foreach ( $branding_options as $branding_option ) { |
| 5223 | - // Make sure the custom brands have the required values. | |
| 4003 | + // Make sure the custom brands have the required values | |
| 5224 | 4004 | if ( ! ( is_array( $branding_option ) && array_key_exists( 'value', $branding_option ) && array_key_exists( 'description', $branding_option ) ) ) { |
| 5225 | 4005 | continue; |
| 5226 | 4006 | } |
| 5227 | - ?> | |
| 5228 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $branding_option['value'] ); ?>"<?php checked( $branding_option['value'] === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_<?php echo esc_attr( sanitize_title( $branding_option['value'] ) ); ?>"><?php echo esc_html( $branding_option['description'] ); ?></label><br /> | |
| 5229 | - <?php | |
| 4007 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>" name="auth_settings[<?php echo $option; ?>]" value="<?php echo $branding_option['value']; ?>"<?php checked( $branding_option['value'] == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_<?php echo sanitize_title( $branding_option['value'] ); ?>"><?php echo $branding_option['description']; ?></label><br /><?php | |
| 5230 | 4008 | } |
| 5231 | 4009 | |
| 5232 | 4010 | // Print message about adding custom brands if there are none. |
| 5233 | 4011 | if ( count( $branding_options ) === 0 ) { |
| 5234 | - ?> | |
| 5235 | - <p><em><?php echo wp_kses( __( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ), $this->allowed_html ); ?></em></p> | |
| 5236 | - <?php | |
| 4012 | + ?><p><em><?php _e( '<strong>Note for theme developers</strong>: Add more options here by using the `authorizer_add_branding_option` filter in your theme. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.', 'authorizer' ); ?></em></p><?php | |
| 5237 | 4013 | } |
| 5238 | 4014 | } |
| 5239 | 4015 | |
| 5240 | 4016 | |
| 5241 | - /** | |
| 5242 | - * Settings print callback. | |
| 5243 | - * | |
| 5244 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5245 | - * @return void | |
| 5246 | - */ | |
| 5247 | - public function print_radio_auth_advanced_admin_menu( $args = '' ) { | |
| 4017 | + function print_radio_auth_advanced_admin_menu( $args = '' ) { | |
| 5248 | 4018 | // Get plugin option. |
| 5249 | - $option = 'advanced_admin_menu'; | |
| 4019 | + $option = 'advanced_admin_menu'; | |
| 5250 | 4020 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 5251 | 4021 | |
| 5252 | 4022 | // Print option elements. |
| 5253 | - ?> | |
| 5254 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="settings"<?php checked( 'settings' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_settings"><?php esc_html_e( 'Show in Settings menu', 'authorizer' ); ?></label><br /> | |
| 5255 | - <input type="radio" id="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="top"<?php checked( 'top' === $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo esc_attr( $option ); ?>_top"><?php esc_html_e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br /> | |
| 5256 | - <?php | |
| 4023 | + ?><input type="radio" id="radio_auth_settings_<?php echo $option; ?>_settings" name="auth_settings[<?php echo $option; ?>]" value="settings"<?php checked( 'settings' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_settings"><?php _e( 'Show in Settings menu', 'authorizer' ); ?></label><br /> | |
| 4024 | + <input type="radio" id="radio_auth_settings_<?php echo $option; ?>_top" name="auth_settings[<?php echo $option; ?>]" value="top"<?php checked( 'top' == $auth_settings_option ); ?> /><label for="radio_auth_settings_<?php echo $option; ?>_top"><?php _e( 'Show in sidebar (top level)', 'authorizer' ); ?></label><br /><?php | |
| 5257 | 4025 | |
| 5258 | 4026 | } |
| 5259 | 4027 | |
| 5260 | 4028 | |
| 5261 | - /** | |
| 5262 | - * Settings print callback. | |
| 5263 | - * | |
| 5264 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5265 | - * @return void | |
| 5266 | - */ | |
| 5267 | - public function print_select_auth_advanced_usermeta( $args = '' ) { | |
| 4029 | + function print_select_auth_advanced_usermeta( $args = '' ) { | |
| 5268 | 4030 | // Get plugin option. |
| 5269 | - $option = 'advanced_usermeta'; | |
| 4031 | + $option = 'advanced_usermeta'; | |
| 5270 | 4032 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 5271 | 4033 | |
| 5272 | 4034 | // Print option elements. |
| 5273 | - ?> | |
| 5274 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]"> | |
| 5275 | - <option value=""><?php esc_html_e( '-- None --', 'authorizer' ); ?></option> | |
| 5276 | - <?php | |
| 5277 | - if ( class_exists( 'acf' ) ) : | |
| 4035 | + ?><select id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]"> | |
| 4036 | + <option value=""><?php _e( '-- None --', 'authorizer' ); ?></option> | |
| 4037 | + <?php if ( class_exists( 'acf' ) ) : | |
| 5278 | 4038 | // Get ACF 5 fields. Note: it would be much easier to use `get_field_objects()` |
| 5279 | 4039 | // or `get_field_objects( 'user_' . get_current_user_id() )`, but neither will |
| 5280 | 4040 | // list fields that have never been given values for users (i.e., new ACF |
| 5281 | 4041 | // fields). Therefore we fall back on finding any ACF fields applied to users |
| 5282 | 4042 | // (user_role or user_form location rules in the field group definition). |
| 5283 | - $fields = array(); | |
| 4043 | + $fields = array(); | |
| 5284 | 4044 | $acf_field_group_ids = array(); |
| 5285 | - $acf_field_groups = new WP_Query( | |
| 5286 | - array( | |
| 5287 | - 'post_type' => 'acf-field-group', | |
| 5288 | - ) | |
| 5289 | - ); | |
| 4045 | + $acf_field_groups = new WP_Query( array( | |
| 4046 | + 'post_type' => 'acf-field-group', | |
| 4047 | + )); | |
| 5290 | 4048 | while ( $acf_field_groups->have_posts() ) : $acf_field_groups->the_post(); |
| 5291 | 4049 | if ( strpos( get_the_content(), 's:5:"param";s:9:"user_role"' ) !== false || strpos( get_the_content(), 's:5:"param";s:9:"user_form"' ) !== false ) : |
| 5292 | 4050 | array_push( $acf_field_group_ids, get_the_ID() ); |
| 5293 | 4051 | endif; |
| 5294 | - endwhile; | |
| 5295 | - wp_reset_postdata(); | |
| 4052 | + endwhile; wp_reset_postdata(); | |
| 5296 | 4053 | foreach ( $acf_field_group_ids as $acf_field_group_id ) : |
| 5297 | - $acf_fields = new WP_Query( | |
| 5298 | - array( | |
| 5299 | - 'post_type' => 'acf-field', | |
| 5300 | - 'post_parent' => $acf_field_group_id, | |
| 5301 | - ) | |
| 5302 | - ); | |
| 4054 | + $acf_fields = new WP_Query( array( | |
| 4055 | + 'post_type' => 'acf-field', | |
| 4056 | + 'post_parent' => $acf_field_group_id, | |
| 4057 | + )); | |
| 5303 | 4058 | while ( $acf_fields->have_posts() ) : $acf_fields->the_post(); |
| 5304 | 4059 | global $post; |
| 5305 | - $fields[ $post->post_name ] = get_field_object( $post->post_name ); | |
| 5306 | - endwhile; | |
| 5307 | - wp_reset_postdata(); | |
| 4060 | + $fields[$post->post_name] = get_field_object( $post->post_name ); | |
| 4061 | + endwhile; wp_reset_postdata(); | |
| 5308 | 4062 | endforeach; |
| 5309 | 4063 | // Get ACF 4 fields. |
| 5310 | - $acf4_field_groups = new WP_Query( | |
| 5311 | - array( | |
| 5312 | - 'post_type' => 'acf', | |
| 5313 | - ) | |
| 5314 | - ); | |
| 4064 | + $acf4_field_groups = new WP_Query( array( | |
| 4065 | + 'post_type' => 'acf', | |
| 4066 | + )); | |
| 5315 | 4067 | while ( $acf4_field_groups->have_posts() ) : $acf4_field_groups->the_post(); |
| 5316 | 4068 | $field_group_rules = get_post_meta( get_the_ID(), 'rule', true ); |
| 5317 | - if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && 'ef_user' === $field_group_rules['param'] ) : | |
| 4069 | + if ( is_array( $field_group_rules ) && array_key_exists( 'param', $field_group_rules ) && $field_group_rules['param'] === 'ef_user' ) : | |
| 5318 | 4070 | $acf4_fields = get_post_custom( get_the_ID() ); |
| 5319 | 4071 | foreach ( $acf4_fields as $meta_key => $meta_value ) : |
| 5320 | 4072 | if ( strpos( $meta_key, 'field_' ) === 0 ) : |
| 5321 | - $meta_value = unserialize( $meta_value[0] ); | |
| 5322 | - $fields[ $meta_key ] = $meta_value; | |
| 4073 | + $meta_value = unserialize( $meta_value[0] ); | |
| 4074 | + $fields[$meta_key] = $meta_value; | |
| 5323 | 4075 | endif; |
| 5324 | 4076 | endforeach; |
| 5325 | 4077 | endif; |
| 5326 | - endwhile; | |
| 5327 | - wp_reset_postdata(); | |
| 5328 | - ?> | |
| 4078 | + endwhile; wp_reset_postdata(); ?> | |
| 5329 | 4079 | <optgroup label="ACF User Fields:"> |
| 5330 | - <?php foreach ( (array) $fields as $field => $field_object ) : ?> | |
| 5331 | - <option value="acf___<?php echo esc_attr( $field_object['key'] ); ?>"<?php selected( "acf___{$field_object['key']}" === $auth_settings_option ); ?>><?php echo esc_html( $field_object['label'] ); ?></option> | |
| 4080 | + <?php foreach ( (array)$fields as $field => $field_object ) : ?> | |
| 4081 | + <option value="acf___<?php echo $field_object['key']; ?>"<?php if ( $auth_settings_option === "acf___{$field_object['key']}" ) echo ' selected="selected"'; ?>><?php echo $field_object['label']; ?></option> | |
| 5332 | 4082 | <?php endforeach; ?> |
| 5333 | 4083 | </optgroup> |
| 5334 | 4084 | <?php endif; ?> |
| 5335 | - <optgroup label="<?php esc_attr_e( 'All Usermeta:', 'authorizer' ); ?>"> | |
| 5336 | - <?php | |
| 5337 | - foreach ( $this->get_all_usermeta_keys() as $meta_key ) : | |
| 5338 | - if ( substr( $meta_key, 0, 3 ) === 'wp_' ) : | |
| 5339 | - continue; | |
| 5340 | - endif; | |
| 5341 | - ?> | |
| 5342 | - <option value="<?php echo esc_attr( $meta_key ); ?>"<?php selected( $auth_settings_option === $meta_key ); ?>><?php echo esc_html( $meta_key ); ?></option> | |
| 4085 | + <optgroup label="<?php _e( 'All Usermeta:', 'authorizer' ); ?>"> | |
| 4086 | + <?php foreach ( $this->get_all_usermeta_keys() as $meta_key ) : if ( substr( $meta_key, 0, 3 ) === 'wp_' ) continue; ?> | |
| 4087 | + <option value="<?php echo $meta_key; ?>"<?php if ( $auth_settings_option === $meta_key ) echo ' selected="selected"'; ?>><?php echo $meta_key; ?></option> | |
| 5343 | 4088 | <?php endforeach; ?> |
| 5344 | 4089 | </optgroup> |
| 5345 | - </select> | |
| 5346 | - <?php | |
| 4090 | + </select><?php | |
| 5347 | 4091 | } |
| 5348 | 4092 | |
| 5349 | 4093 | |
| 5350 | - /** | |
| 5351 | - * Settings print callback. | |
| 5352 | - * | |
| 5353 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5354 | - * @return void | |
| 5355 | - */ | |
| 5356 | - public function print_text_auth_advanced_users_per_page( $args = '' ) { | |
| 4094 | + function print_checkbox_auth_advanced_override_multisite( $args = '' ) { | |
| 5357 | 4095 | // Get plugin option. |
| 5358 | - $option = 'advanced_users_per_page'; | |
| 5359 | - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); | |
| 5360 | - | |
| 5361 | - // Print option elements. | |
| 5362 | - ?> | |
| 5363 | - <input type="text" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="<?php echo esc_attr( $auth_settings_option ); ?>" placeholder="" size="4" /> | |
| 5364 | - <?php | |
| 5365 | - } | |
| 5366 | - | |
| 5367 | - | |
| 5368 | - /** | |
| 5369 | - * Settings print callback. | |
| 5370 | - * | |
| 5371 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5372 | - * @return void | |
| 5373 | - */ | |
| 5374 | - public function print_select_auth_advanced_users_sort_by( $args = '' ) { | |
| 5375 | - // Get plugin option. | |
| 5376 | - $option = 'advanced_users_sort_by'; | |
| 5377 | - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); | |
| 5378 | - | |
| 5379 | - // Print option elements. | |
| 5380 | - ?> | |
| 5381 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]"> | |
| 5382 | - <option value="created" <?php selected( $auth_settings_option, 'created' ); ?>><?php esc_html_e( 'Date approved', 'authorizer' ); ?></option> | |
| 5383 | - <option value="email" <?php selected( $auth_settings_option, 'email' ); ?>><?php esc_html_e( 'Email', 'authorizer' ); ?></option> | |
| 5384 | - <option value="role" <?php selected( $auth_settings_option, 'role' ); ?>><?php esc_html_e( 'Role', 'authorizer' ); ?></option> | |
| 5385 | - <option value="date_added" <?php selected( $auth_settings_option, 'date_added' ); ?>><?php esc_html_e( 'Date registered', 'authorizer' ); ?></option> | |
| 5386 | - </select> | |
| 5387 | - <?php | |
| 5388 | - } | |
| 5389 | - | |
| 5390 | - | |
| 5391 | - /** | |
| 5392 | - * Settings print callback. | |
| 5393 | - * | |
| 5394 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5395 | - * @return void | |
| 5396 | - */ | |
| 5397 | - public function print_select_auth_advanced_users_sort_order( $args = '' ) { | |
| 5398 | - // Get plugin option. | |
| 5399 | - $option = 'advanced_users_sort_order'; | |
| 5400 | - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); | |
| 5401 | - | |
| 5402 | - // Print option elements. | |
| 5403 | - ?> | |
| 5404 | - <select id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]"> | |
| 5405 | - <option value="asc" <?php selected( $auth_settings_option, 'asc' ); ?>><?php esc_html_e( 'Ascending', 'authorizer' ); ?></option> | |
| 5406 | - <option value="desc" <?php selected( $auth_settings_option, 'desc' ); ?>><?php esc_html_e( 'Descending', 'authorizer' ); ?></option> | |
| 5407 | - </select> | |
| 5408 | - <?php | |
| 5409 | - } | |
| 5410 | - | |
| 5411 | - | |
| 5412 | - /** | |
| 5413 | - * Settings print callback. | |
| 5414 | - * | |
| 5415 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5416 | - * @return void | |
| 5417 | - */ | |
| 5418 | - public function print_checkbox_auth_advanced_widget_enabled( $args = '' ) { | |
| 5419 | - // Get plugin option. | |
| 5420 | - $option = 'advanced_widget_enabled'; | |
| 5421 | - $auth_settings_option = $this->get_plugin_option( $option, $this->get_admin_mode( $args ), 'allow override', 'print overlay' ); | |
| 5422 | - | |
| 5423 | - // Print option elements. | |
| 5424 | - ?> | |
| 5425 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></label> | |
| 5426 | - <p><small><?php esc_html_e( 'Note: Only users with the create_users capability will be able to see the dashboard widget.', 'authorizer' ); ?></small></p> | |
| 5427 | - <?php | |
| 5428 | - } | |
| 5429 | - | |
| 5430 | - | |
| 5431 | - /** | |
| 5432 | - * Settings print callback. | |
| 5433 | - * | |
| 5434 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5435 | - * @return void | |
| 5436 | - */ | |
| 5437 | - public function print_checkbox_auth_advanced_override_multisite( $args = '' ) { | |
| 5438 | - // Get plugin option. | |
| 5439 | - $option = 'advanced_override_multisite'; | |
| 4096 | + $option = 'advanced_override_multisite'; | |
| 5440 | 4097 | $auth_settings_option = $this->get_plugin_option( $option ); |
| 5441 | 4098 | |
| 5442 | 4099 | // Print option elements. |
| 5443 | - ?> | |
| 5444 | - <input type="checkbox" id="auth_settings_<?php echo esc_attr( $option ); ?>" name="auth_settings[<?php echo esc_attr( $option ); ?>]" value="1"<?php checked( 1 === intval( $auth_settings_option ) ); ?> /><label for="auth_settings_<?php echo esc_attr( $option ); ?>"><?php esc_html_e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label> | |
| 5445 | - <?php | |
| 4100 | + ?><input type="checkbox" id="auth_settings_<?php echo $option; ?>" name="auth_settings[<?php echo $option; ?>]" value="1"<?php checked( 1 == $auth_settings_option ); ?> /><label for="auth_settings_<?php echo $option; ?>"><?php _e( "Configure this site independently (don't inherit any multisite settings)", 'authorizer' ); ?></label><?php | |
| 5446 | 4101 | } |
| 5447 | 4102 | |
| 5448 | 4103 | |
| 5449 | 4104 | |
| 5450 | 4105 | /** |
| 5451 | - * Determines whether we are in single site or multisite admin context. | |
| 5452 | - * | |
| 5453 | - * @param string $args Args (e.g., multisite admin mode). | |
| 5454 | - * @return int Current mode. | |
| 5455 | - */ | |
| 5456 | - private function get_admin_mode( $args ) { | |
| 5457 | - if ( is_array( $args ) && array_key_exists( WP_Plugin_Authorizer::NETWORK_CONTEXT, $args ) && true === $args[ WP_Plugin_Authorizer::NETWORK_CONTEXT ] ) { | |
| 5458 | - return WP_Plugin_Authorizer::NETWORK_CONTEXT; | |
| 5459 | - } else { | |
| 5460 | - return WP_Plugin_Authorizer::SINGLE_CONTEXT; | |
| 5461 | - } | |
| 5462 | - } | |
| 5463 | - | |
| 5464 | - | |
| 5465 | - /** | |
| 5466 | 4106 | * Add help documentation to the options page. |
| 5467 | - * | |
| 5468 | - * Action: load-settings_page_authorizer > admin_head | |
| 4107 | + * Run on action hook chain: load-settings_page_authorizer > admin_head | |
| 5469 | 4108 | */ |
| 5470 | 4109 | public function admin_head() { |
| 5471 | 4110 | $screen = get_current_screen(); |
| 5472 | 4111 | |
| 5473 | - // Add help tab for Access Lists Settings. | |
| 4112 | + // Add help tab for Access Lists Settings | |
| 5474 | 4113 | $help_auth_settings_access_lists_content = ' |
| 5475 | - <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) . '</p> | |
| 5476 | - <p>' . __( '<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.', 'authorizer' ) . '</p> | |
| 5477 | - <p>' . __( '<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.', 'authorizer' ) . '</p> | |
| 5478 | - <p>' . __( 'Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.', 'authorizer' ) . '</p> | |
| 4114 | + <p>' . __( "<strong>Pending Users</strong>: Pending users are users who have successfully logged in to the site, but who haven't yet been approved (or blocked) by you.", 'authorizer' ) .'</p> | |
| 4115 | + <p>' . __( "<strong>Approved Users</strong>: Approved users have access to the site once they successfully log in.", 'authorizer' ) . '</p> | |
| 4116 | + <p>' . __( "<strong>Blocked Users</strong>: Blocked users will receive an error message when they try to visit the site after authenticating.", 'authorizer' ) . '</p> | |
| 4117 | + <p>' . __( "Users in the <strong>Pending</strong> list appear automatically after a new user tries to log in from the configured external authentication service. You can add users to the <strong>Approved</strong> or <strong>Blocked</strong> lists by typing them in manually, or by clicking the <em>Approve</em> or <em>Block</em> buttons next to a user in the <strong>Pending</strong> list.", 'authorizer' ) . '</p> | |
| 5479 | 4118 | '; |
| 5480 | 4119 | $screen->add_help_tab( |
| 5481 | 4120 | array( |
| 5482 | - 'id' => 'help_auth_settings_access_lists_content', | |
| 5483 | - 'title' => __( 'Access Lists', 'authorizer' ), | |
| 4121 | + 'id' => 'help_auth_settings_access_lists_content', | |
| 4122 | + 'title' => __( 'Access Lists', 'authorizer' ), | |
| 5484 | 4123 | 'content' => $help_auth_settings_access_lists_content, |
| 5485 | 4124 | ) |
| 5486 | 4125 | ); |
| 5487 | 4126 | |
| 5488 | - // Add help tab for Login Access Settings. | |
| 4127 | + // Add help tab for Login Access Settings | |
| 5489 | 4128 | $help_auth_settings_access_login_content = ' |
| 5490 | 4129 | <p>' . __( "<strong>Who can log in to the site?</strong>: Choose the level of access restriction you'd like to use on your site here. You can leave the site open to anyone with a WordPress account or an account on an external service like Google, CAS, or LDAP, or restrict it to WordPress users and only the external users that you specify via the <em>Access Lists</em>.", 'authorizer' ) . '</p> |
| 5491 | 4130 | <p>' . __( "<strong>Which role should receive email notifications about pending users?</strong>: If you've restricted access to <strong>approved users</strong>, you can determine which WordPress users will receive a notification email everytime a new external user successfully logs in and is added to the pending list. All users of the specified role will receive an email, and the external user will get a message (specified below) telling them their access is pending approval.", 'authorizer' ) . '</p> |
| 5492 | 4131 | <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p> |
| @@ -5492,84 +4131,84 @@ | ||
| 5492 | 4131 | <p>' . __( '<strong>What message should pending users see after attempting to log in?</strong>: Here you can specify the exact message a new external user will see once they try to log in to the site for the first time.', 'authorizer' ) . '</p> |
| 5493 | 4132 | '; |
| 5494 | 4133 | $screen->add_help_tab( |
| 5495 | 4134 | array( |
| 5496 | - 'id' => 'help_auth_settings_access_login_content', | |
| 5497 | - 'title' => __( 'Login Access', 'authorizer' ), | |
| 4135 | + 'id' => 'help_auth_settings_access_login_content', | |
| 4136 | + 'title' => __( 'Login Access', 'authorizer' ), | |
| 5498 | 4137 | 'content' => $help_auth_settings_access_login_content, |
| 5499 | 4138 | ) |
| 5500 | 4139 | ); |
| 5501 | 4140 | |
| 5502 | - // Add help tab for Public Access Settings. | |
| 4141 | + // Add help tab for Public Access Settings | |
| 5503 | 4142 | $help_auth_settings_access_public_content = ' |
| 5504 | 4143 | <p>' . __( "<strong>Who can view the site?</strong>: You can restrict the site's visibility by only allowing logged in users to see pages. If you do so, you can customize the specifics about the site's privacy using the settings below.", 'authorizer' ) . '</p> |
| 5505 | 4144 | <p>' . __( "<strong>What pages (if any) should be available to everyone?</strong>: If you'd like to declare certain pages on your site as always public (such as the course syllabus, introduction, or calendar), specify those pages here. These pages will always be available no matter what access restrictions exist.", 'authorizer' ) . '</p> |
| 5506 | - <p>' . __( '<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.', 'authorizer' ) . '</p> | |
| 5507 | - <p>' . __( '<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.', 'authorizer' ) . '</p> | |
| 5508 | - <p>' . __( '<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.', 'authorizer' ) . '</p> | |
| 4145 | + <p>' . __( "<strong>What happens to people without access when they visit a <em>private</em> page?</strong>: Choose the response anonymous users receive when visiting the site. You can choose between immediately taking them to the <strong>login screen</strong>, or simply showing them a <strong>message</strong>.", 'authorizer' ) . '</p> | |
| 4146 | + <p>' . __( "<strong>What happens to people without access when they visit a <em>public</em> page?</strong>: Choose the response anonymous users receive when visiting a page on the site marked as public. You can choose between showing them the page without any message, or showing them a the page with a message above the content.", 'authorizer' ) . '</p> | |
| 4147 | + <p>' . __( "<strong>What message should people without access see?</strong>: If you chose to show new users a <strong>message</strong> above, type that message here.", 'authorizer' ) . '</p> | |
| 5509 | 4148 | '; |
| 5510 | 4149 | $screen->add_help_tab( |
| 5511 | 4150 | array( |
| 5512 | - 'id' => 'help_auth_settings_access_public_content', | |
| 5513 | - 'title' => __( 'Public Access', 'authorizer' ), | |
| 4151 | + 'id' => 'help_auth_settings_access_public_content', | |
| 4152 | + 'title' => __( 'Public Access', 'authorizer' ), | |
| 5514 | 4153 | 'content' => $help_auth_settings_access_public_content, |
| 5515 | 4154 | ) |
| 5516 | 4155 | ); |
| 5517 | 4156 | |
| 5518 | - // Add help tab for External Service (CAS, LDAP) Settings. | |
| 4157 | + // Add help tab for External Service (CAS, LDAP) Settings | |
| 5519 | 4158 | $help_auth_settings_external_content = ' |
| 5520 | 4159 | <p>' . __( "<strong>Type of external service to authenticate against</strong>: Choose which authentication service type you will be using. You'll have to fill out different fields below depending on which service you choose.", 'authorizer' ) . '</p> |
| 5521 | - <p>' . __( '<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.', 'authorizer' ) . '</p> | |
| 5522 | - <p>' . __( '<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.', 'authorizer' ) . '</p> | |
| 5523 | - <p>' . __( '<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.', 'authorizer' ) . '</p> | |
| 5524 | - <p>' . __( '<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!', 'authorizer' ) . '</p> | |
| 5525 | - <p><strong><em>' . __( 'If you enable Google logins:', 'authorizer' ) . '</em></strong></p> | |
| 4160 | + <p>' . __( "<strong>Enable Google Logins</strong>: Choose if you want to allow users to log in with their Google Account credentials. You will need to enter your API Client ID and Secret to enable Google Logins.", 'authorizer' ) . '</p> | |
| 4161 | + <p>' . __( "<strong>Enable CAS Logins</strong>: Choose if you want to allow users to log in with via CAS (Central Authentication Service). You will need to enter details about your CAS server (host, port, and path) to enable CAS Logins.", 'authorizer' ) . '</p> | |
| 4162 | + <p>' . __( "<strong>Enable LDAP Logins</strong>: Choose if you want to allow users to log in with their LDAP (Lightweight Directory Access Protocol) credentials. You will need to enter details about your LDAP server (host, port, search base, uid attribute, directory user, directory user password, and whether to use TLS) to enable Google Logins.", 'authorizer' ) . '</p> | |
| 4163 | + <p>' . __( "<strong>Default role for new CAS users</strong>: Specify which role new external users will get by default. Be sure to choose a role with limited permissions!", 'authorizer' ) . '</p> | |
| 4164 | + <p><strong><em>' . __( "If you enable Google logins:", 'authorizer' ) . '</em></strong></p> | |
| 5526 | 4165 | <ul> |
| 5527 | 4166 | <li>' . __( "<strong>Google Client ID</strong>: You can generate this ID by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client ID typically looks something like this: 1234567890123-kdjr85yt6vjr6d8g7dhr8g7d6durjf7g.apps.googleusercontent.com", 'authorizer' ) . '</li> |
| 5528 | 4167 | <li>' . __( "<strong>Google Client Secret</strong>: You can generate this secret by creating a new Project in the <a href='https://cloud.google.com/console'>Google Developers Console</a>. A Client Secret typically looks something like this: sDNgX5_pr_5bly-frKmvp8jT", 'authorizer' ) . '</li> |
| 5529 | 4168 | </ul> |
| 5530 | - <p><strong><em>' . __( 'If you enable CAS logins:', 'authorizer' ) . '</em></strong></p> | |
| 4169 | + <p><strong><em>' . __( "If you enable CAS logins:", 'authorizer' ) . '</em></strong></p> | |
| 5531 | 4170 | <ul> |
| 5532 | - <li>' . __( '<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).', 'authorizer' ) . '</li> | |
| 5533 | - <li>' . __( '<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).', 'authorizer' ) . '</li> | |
| 5534 | - <li>' . __( '<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).', 'authorizer' ) . '</li> | |
| 4171 | + <li>' . __( "<strong>CAS server hostname</strong>: Enter the hostname of the CAS server you authenticate against (e.g., authn.example.edu).", 'authorizer' ) . '</li> | |
| 4172 | + <li>' . __( "<strong>CAS server port</strong>: Enter the port on the CAS server to connect to (e.g., 443).", 'authorizer' ) . '</li> | |
| 4173 | + <li>' . __( "<strong>CAS server path/context</strong>: Enter the path to the login endpoint on the CAS server (e.g., /cas).", 'authorizer' ) . '</li> | |
| 5535 | 4174 | <li>' . __( "<strong>CAS attribute containing first name</strong>: Enter the CAS attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li> |
| 5536 | 4175 | <li>' . __( "<strong>CAS attribute containing last name</strong>: Enter the CAS attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from CAS and added to their WordPress profile.", 'authorizer' ) . '</li> |
| 5537 | - <li>' . __( '<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li> | |
| 4176 | + <li>' . __( "<strong>CAS attribute update</strong>: Select whether the first and last names retrieved from CAS should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li> | |
| 5538 | 4177 | </ul> |
| 5539 | - <p><strong><em>' . __( 'If you enable LDAP logins:', 'authorizer' ) . '</em></strong></p> | |
| 4178 | + <p><strong><em>' . __( "If you enable LDAP logins:", 'authorizer' ) . '</em></strong></p> | |
| 5540 | 4179 | <ul> |
| 5541 | - <li>' . __( '<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.', 'authorizer' ) . '</li> | |
| 5542 | - <li>' . __( '<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.', 'authorizer' ) . '</li> | |
| 5543 | - <li>' . __( '<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu', 'authorizer' ) . '</li> | |
| 5544 | - <li>' . __( '<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.', 'authorizer' ) . '</li> | |
| 5545 | - <li>' . __( '<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.', 'authorizer' ) . '</li> | |
| 5546 | - <li>' . __( '<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.', 'authorizer' ) . '</li> | |
| 5547 | - <li>' . __( '<strong>Use TLS</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.', 'authorizer' ) . '</li> | |
| 4180 | + <li>' . __( "<strong>LDAP Host</strong>: Enter the URL of the LDAP server you authenticate against.", 'authorizer' ) . '</li> | |
| 4181 | + <li>' . __( "<strong>LDAP Port</strong>: Enter the port number that the LDAP server listens on.", 'authorizer' ) . '</li> | |
| 4182 | + <li>' . __( "<strong>LDAP Search Base</strong>: Enter the LDAP string that represents the search base, e.g., ou=people,dc=example,dc=edu", 'authorizer' ) . '</li> | |
| 4183 | + <li>' . __( "<strong>LDAP attribute containing username</strong>: Enter the name of the LDAP attribute that contains the usernames used by those attempting to log in. The plugin will search on this attribute to find the cn to bind against for login attempts.", 'authorizer' ) . '</li> | |
| 4184 | + <li>' . __( "<strong>LDAP Directory User</strong>: Enter the name of the LDAP user that has permissions to browse the directory.", 'authorizer' ) . '</li> | |
| 4185 | + <li>' . __( "<strong>LDAP Directory User Password</strong>: Enter the password for the LDAP user that has permission to browse the directory.", 'authorizer' ) . '</li> | |
| 4186 | + <li>' . __( "<strong>Secure Connection (TLS)</strong>: Select whether all communication with the LDAP server should be performed over a TLS-secured connection.", 'authorizer' ) . '</li> | |
| 5548 | 4187 | <li>' . __( "<strong>Custom lost password URL</strong>: The WordPress login page contains a link to recover a lost password. If you have external users who shouldn't change the password on their WordPress account, point them to the appropriate location to change the password on their external authentication service here.", 'authorizer' ) . '</li> |
| 5549 | 4188 | <li>' . __( "<strong>LDAP attribute containing first name</strong>: Enter the LDAP attribute that has the user's first name. When this user first logs in, their WordPress account will have their first name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li> |
| 5550 | 4189 | <li>' . __( "<strong>LDAP attribute containing last name</strong>: Enter the LDAP attribute that has the user's last name. When this user first logs in, their WordPress account will have their last name retrieved from LDAP and added to their WordPress profile.", 'authorizer' ) . '</li> |
| 5551 | - <li>' . __( '<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.', 'authorizer' ) . '</li> | |
| 4190 | + <li>' . __( "<strong>LDAP attribute update</strong>: Select whether the first and last names retrieved from LDAP should overwrite any value the user has entered in the first and last name fields in their WordPress profile. If this is not set, this only happens the first time they log in.", 'authorizer' ) . '</li> | |
| 5552 | 4191 | </ul> |
| 5553 | 4192 | '; |
| 5554 | 4193 | $screen->add_help_tab( |
| 5555 | 4194 | array( |
| 5556 | - 'id' => 'help_auth_settings_external_content', | |
| 5557 | - 'title' => __( 'External Service', 'authorizer' ), | |
| 4195 | + 'id' => 'help_auth_settings_external_content', | |
| 4196 | + 'title' => __( 'External Service', 'authorizer' ), | |
| 5558 | 4197 | 'content' => $help_auth_settings_external_content, |
| 5559 | 4198 | ) |
| 5560 | 4199 | ); |
| 5561 | 4200 | |
| 5562 | - // Add help tab for Advanced Settings. | |
| 4201 | + // Add help tab for Advanced Settings | |
| 5563 | 4202 | $help_auth_settings_advanced_content = ' |
| 5564 | - <p>' . __( '<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.', 'authorizer' ) . '</p> | |
| 5565 | - <p>' . __( '<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:', 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p> | |
| 4203 | + <p>' . __( "<strong>Limit invalid login attempts</strong>: Choose how soon (and for how long) to restrict access to individuals (or bots) making repeated invalid login attempts. You may set a shorter delay first, and then a longer delay after repeated invalid attempts; you may also set how much time must pass before the delays will be reset to normal.", 'authorizer' ) . '</p> | |
| 4204 | + <p>' . __( "<strong>Hide WordPress Logins</strong>: If you want to hide the WordPress username and password fields and the Log In button on the wp-login screen, enable this option. Note: You can always access the WordPress logins by adding external=wordpress to the wp-login URL, like so:", 'authorizer' ) . ' <a href="' . wp_login_url() . '?external=wordpress" target="_blank">' . wp_login_url() . '?external=wordpress</a>.</p> | |
| 5566 | 4205 | <p>' . __( "<strong>Custom WordPress login branding</strong>: If you'd like to use custom branding on the WordPress login page, select that here. You will need to use the `authorizer_add_branding_option` filter in your theme to add it. You can see an example theme that implements this filter in the plugin directory under sample-theme-add-branding.", 'authorizer' ) . '</p> |
| 5567 | 4206 | '; |
| 5568 | 4207 | $screen->add_help_tab( |
| 5569 | 4208 | array( |
| 5570 | - 'id' => 'help_auth_settings_advanced_content', | |
| 5571 | - 'title' => __( 'Advanced', 'authorizer' ), | |
| 4209 | + 'id' => 'help_auth_settings_advanced_content', | |
| 4210 | + 'title' => __( 'Advanced', 'authorizer' ), | |
| 5572 | 4211 | 'content' => $help_auth_settings_advanced_content, |
| 5573 | 4212 | ) |
| 5574 | 4213 | ); |
| 5575 | 4214 | } |
| @@ -5584,66 +4223,65 @@ | ||
| 5584 | 4223 | |
| 5585 | 4224 | |
| 5586 | 4225 | /** |
| 5587 | 4226 | * Network Admin menu item |
| 4227 | + * Hook: network_admin_menu | |
| 5588 | 4228 | * |
| 5589 | - * Action: network_admin_menu | |
| 5590 | - * | |
| 4229 | + * @param none | |
| 5591 | 4230 | * @return void |
| 5592 | 4231 | */ |
| 5593 | 4232 | public function network_admin_menu() { |
| 5594 | 4233 | // @see http://codex.wordpress.org/Function_Reference/add_menu_page |
| 5595 | 4234 | add_menu_page( |
| 5596 | - 'Authorizer', | |
| 5597 | - 'Authorizer', | |
| 5598 | - 'manage_network_options', | |
| 5599 | - 'authorizer', | |
| 4235 | + 'Authorizer', // Page title | |
| 4236 | + 'Authorizer', // Menu title | |
| 4237 | + 'manage_network_options', // Capability | |
| 4238 | + 'authorizer', // Menu slug | |
| 5600 | 4239 | array( $this, 'create_network_admin_page' ), |
| 5601 | - 'dashicons-groups', | |
| 5602 | - 89 // Position. | |
| 4240 | + 'dashicons-groups', // Icon URL | |
| 4241 | + 89 // Position | |
| 5603 | 4242 | ); |
| 5604 | 4243 | } |
| 5605 | 4244 | |
| 5606 | 4245 | |
| 5607 | 4246 | /** |
| 5608 | - * Output the HTML for the options page. | |
| 4247 | + * Output the HTML for the options page | |
| 5609 | 4248 | */ |
| 5610 | 4249 | public function create_network_admin_page() { |
| 5611 | 4250 | if ( ! current_user_can( 'manage_network_options' ) ) { |
| 5612 | - wp_die( wp_kses( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ), $this->allowed_html ) ); | |
| 4251 | + wp_die( __( 'You do not have sufficient permissions to access this page.', 'authorizer' ) ); | |
| 5613 | 4252 | } |
| 5614 | - $auth_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() ); | |
| 5615 | - ?> | |
| 4253 | + $auth_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); ?> | |
| 5616 | 4254 | <div class="wrap"> |
| 5617 | 4255 | <form method="post" action="" autocomplete="off"> |
| 5618 | - <h2><?php esc_html_e( 'Authorizer Settings', 'authorizer' ); ?></h2> | |
| 5619 | - <p><?php echo wp_kses( __( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ), $this->allowed_html ); ?></p> | |
| 4256 | + <h2><?php _e( 'Authorizer Settings', 'authorizer' ); ?></h2> | |
| 4257 | + <p><?php _e( 'Most <strong>Authorizer</strong> settings are set in the individual sites, but you can specify a few options here that apply to <strong>all sites in the network</strong>. These settings will override settings in the individual sites.', 'authorizer' ); ?></p> | |
| 5620 | 4258 | |
| 5621 | - <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 === intval( $auth_settings['multisite_override'] ) ); ?> /><label for="auth_settings_multisite_override"><?php esc_html_e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label> | |
| 4259 | + <input type="checkbox" id="auth_settings_multisite_override" name="auth_settings[multisite_override]" value="1"<?php checked( 1 == $auth_settings['multisite_override'] ); ?> /><label for="auth_settings_multisite_override"><?php _e( 'Override individual site settings with the settings below', 'authorizer' ); ?></label> | |
| 5622 | 4260 | |
| 5623 | 4261 | <div id="auth_multisite_settings_disabled_overlay" style="display: none;"></div> |
| 5624 | 4262 | |
| 5625 | 4263 | <div class="wrap" id="auth_multisite_settings"> |
| 5626 | - <?php $this->print_section_info_tabs( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?> | |
| 4264 | + <?php $this->print_section_info_tabs( array( MULTISITE_ADMIN => true ) ); ?> | |
| 5627 | 4265 | |
| 5628 | 4266 | <?php wp_nonce_field( 'save_auth_settings', 'nonce_save_auth_settings' ); ?> |
| 5629 | 4267 | |
| 5630 | - <?php // Custom access lists (for network, we only really want approved list, not pending or blocked). ?> | |
| 4268 | + <?php // Custom access lists (for network, we only really want approved list, not pending or blocked) ?> | |
| 5631 | 4269 | <div id="section_info_access_lists" class="section_info"> |
| 5632 | - <p><?php esc_html_e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p> | |
| 4270 | + <p><?php _e( 'Manage who has access to all sites in the network.', 'authorizer' ); ?></p> | |
| 5633 | 4271 | </div> |
| 5634 | 4272 | <table class="form-table"><tbody> |
| 5635 | 4273 | <tr> |
| 5636 | - <th scope="row"><?php esc_html_e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th> | |
| 5637 | - <td><?php $this->print_radio_auth_access_who_can_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4274 | + <th scope="row"><?php _e( 'Who can log in to sites in this network?', 'authorizer' ); ?></th> | |
| 4275 | + <td><?php $this->print_radio_auth_access_who_can_login( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5638 | 4276 | </tr> |
| 5639 | 4277 | <tr> |
| 5640 | - <th scope="row"><?php esc_html_e( 'Who can view sites in this network?', 'authorizer' ); ?></th> | |
| 5641 | - <td><?php $this->print_radio_auth_access_who_can_view( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4278 | + <th scope="row"><?php _e( 'Who can view sites in this network?', 'authorizer' ); ?></th> | |
| 4279 | + <td><?php $this->print_radio_auth_access_who_can_view( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5642 | 4280 | </tr> |
| 5643 | 4281 | <tr> |
| 5644 | - <th scope="row"><?php esc_html_e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php echo wp_kses( __( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ), $this->allowed_html ); ?></em></small></th> | |
| 5645 | - <td><?php $this->print_combo_auth_access_users_approved( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4282 | + <th scope="row"><?php _e( 'Approved Users (All Sites)', 'authorizer' ); ?><br /><small><em><?php _e( 'Note: these users will <strong>not</strong> receive welcome emails when approved. Only users approved from individual sites can receive these messages.', 'authorizer' ); ?></em></small></th> | |
| 4283 | + <td><?php $this->print_combo_auth_access_users_approved( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5646 | 4284 | </tr> |
| 5647 | 4285 | </tbody></table> |
| 5648 | 4286 | |
| 5649 | 4287 | <?php $this->print_section_info_external(); ?> |
| @@ -5648,122 +4286,122 @@ | ||
| 5648 | 4286 | |
| 5649 | 4287 | <?php $this->print_section_info_external(); ?> |
| 5650 | 4288 | <table class="form-table"><tbody> |
| 5651 | 4289 | <tr> |
| 5652 | - <th scope="row"><?php esc_html_e( 'Default role for new users', 'authorizer' ); ?></th> | |
| 5653 | - <td><?php $this->print_select_auth_access_default_role( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4290 | + <th scope="row"><?php _e( 'Default role for new users', 'authorizer' ); ?></th> | |
| 4291 | + <td><?php $this->print_select_auth_access_default_role( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5654 | 4292 | </tr> |
| 5655 | 4293 | <tr> |
| 5656 | - <th scope="row"><?php esc_html_e( 'Google Logins', 'authorizer' ); ?></th> | |
| 5657 | - <td><?php $this->print_checkbox_auth_external_google( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4294 | + <th scope="row"><?php _e( 'Google Logins', 'authorizer' ); ?></th> | |
| 4295 | + <td><?php $this->print_checkbox_auth_external_google( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5658 | 4296 | </tr> |
| 5659 | 4297 | <tr> |
| 5660 | - <th scope="row"><?php esc_html_e( 'Google Client ID', 'authorizer' ); ?></th> | |
| 5661 | - <td><?php $this->print_text_google_clientid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4298 | + <th scope="row"><?php _e( 'Google Client ID', 'authorizer' ); ?></th> | |
| 4299 | + <td><?php $this->print_text_google_clientid( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5662 | 4300 | </tr> |
| 5663 | 4301 | <tr> |
| 5664 | - <th scope="row"><?php esc_html_e( 'Google Client Secret', 'authorizer' ); ?></th> | |
| 5665 | - <td><?php $this->print_text_google_clientsecret( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4302 | + <th scope="row"><?php _e( 'Google Client Secret', 'authorizer' ); ?></th> | |
| 4303 | + <td><?php $this->print_text_google_clientsecret( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5666 | 4304 | </tr> |
| 5667 | 4305 | <tr> |
| 5668 | - <th scope="row"><?php esc_html_e( 'Google Hosted Domain', 'authorizer' ); ?></th> | |
| 5669 | - <td><?php $this->print_text_google_hosteddomain( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4306 | + <th scope="row"><?php _e( 'Google Hosted Domain', 'authorizer' ); ?></th> | |
| 4307 | + <td><?php $this->print_text_google_hosteddomain( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5670 | 4308 | </tr> |
| 5671 | 4309 | <tr> |
| 5672 | - <th scope="row"><?php esc_html_e( 'CAS Logins', 'authorizer' ); ?></th> | |
| 5673 | - <td><?php $this->print_checkbox_auth_external_cas( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4310 | + <th scope="row"><?php _e( 'CAS Logins', 'authorizer' ); ?></th> | |
| 4311 | + <td><?php $this->print_checkbox_auth_external_cas( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5674 | 4312 | </tr> |
| 5675 | 4313 | <tr> |
| 5676 | - <th scope="row"><?php esc_html_e( 'CAS Custom Label', 'authorizer' ); ?></th> | |
| 5677 | - <td><?php $this->print_text_cas_custom_label( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4314 | + <th scope="row"><?php _e( 'CAS Custom Label', 'authorizer' ); ?></th> | |
| 4315 | + <td><?php $this->print_text_cas_custom_label( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5678 | 4316 | </tr> |
| 5679 | 4317 | <tr> |
| 5680 | - <th scope="row"><?php esc_html_e( 'CAS server hostname', 'authorizer' ); ?></th> | |
| 5681 | - <td><?php $this->print_text_cas_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4318 | + <th scope="row"><?php _e( 'CAS server hostname', 'authorizer' ); ?></th> | |
| 4319 | + <td><?php $this->print_text_cas_host( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5682 | 4320 | </tr> |
| 5683 | 4321 | <tr> |
| 5684 | - <th scope="row"><?php esc_html_e( 'CAS server port', 'authorizer' ); ?></th> | |
| 5685 | - <td><?php $this->print_text_cas_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4322 | + <th scope="row"><?php _e( 'CAS server port', 'authorizer' ); ?></th> | |
| 4323 | + <td><?php $this->print_text_cas_port( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5686 | 4324 | </tr> |
| 5687 | 4325 | <tr> |
| 5688 | - <th scope="row"><?php esc_html_e( 'CAS server path/context', 'authorizer' ); ?></th> | |
| 5689 | - <td><?php $this->print_text_cas_path( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4326 | + <th scope="row"><?php _e( 'CAS server path/context', 'authorizer' ); ?></th> | |
| 4327 | + <td><?php $this->print_text_cas_path( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5690 | 4328 | </tr> |
| 5691 | 4329 | <tr> |
| 5692 | - <th scope="row"><?php esc_html_e( 'CAS server version', 'authorizer' ); ?></th> | |
| 5693 | - <td><?php $this->print_select_cas_version( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4330 | + <th scope="row"><?php _e( 'CAS server version', 'authorizer' ); ?></th> | |
| 4331 | + <td><?php $this->print_select_cas_version( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5694 | 4332 | </tr> |
| 5695 | 4333 | <tr> |
| 5696 | - <th scope="row"><?php esc_html_e( 'CAS attribute containing email', 'authorizer' ); ?></th> | |
| 5697 | - <td><?php $this->print_text_cas_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4334 | + <th scope="row"><?php _e( 'CAS attribute containing email', 'authorizer' ); ?></th> | |
| 4335 | + <td><?php $this->print_text_cas_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5698 | 4336 | </tr> |
| 5699 | 4337 | <tr> |
| 5700 | - <th scope="row"><?php esc_html_e( 'CAS attribute containing first name', 'authorizer' ); ?></th> | |
| 5701 | - <td><?php $this->print_text_cas_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4338 | + <th scope="row"><?php _e( 'CAS attribute containing first name', 'authorizer' ); ?></th> | |
| 4339 | + <td><?php $this->print_text_cas_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5702 | 4340 | </tr> |
| 5703 | 4341 | <tr> |
| 5704 | - <th scope="row"><?php esc_html_e( 'CAS attribute containing last name', 'authorizer' ); ?></th> | |
| 5705 | - <td><?php $this->print_text_cas_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4342 | + <th scope="row"><?php _e( 'CAS attribute containing last name', 'authorizer' ); ?></th> | |
| 4343 | + <td><?php $this->print_text_cas_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5706 | 4344 | </tr> |
| 5707 | 4345 | <tr> |
| 5708 | - <th scope="row"><?php esc_html_e( 'CAS attribute update', 'authorizer' ); ?></th> | |
| 5709 | - <td><?php $this->print_checkbox_cas_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4346 | + <th scope="row"><?php _e( 'CAS attribute update', 'authorizer' ); ?></th> | |
| 4347 | + <td><?php $this->print_checkbox_cas_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5710 | 4348 | </tr> |
| 5711 | 4349 | <tr> |
| 5712 | - <th scope="row"><?php esc_html_e( 'CAS automatic login', 'authorizer' ); ?></th> | |
| 5713 | - <td><?php $this->print_checkbox_cas_auto_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4350 | + <th scope="row"><?php _e( 'CAS automatic login', 'authorizer' ); ?></th> | |
| 4351 | + <td><?php $this->print_checkbox_cas_auto_login( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5714 | 4352 | </tr> |
| 5715 | 4353 | <tr> |
| 5716 | - <th scope="row"><?php esc_html_e( 'LDAP Logins', 'authorizer' ); ?></th> | |
| 5717 | - <td><?php $this->print_checkbox_auth_external_ldap( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4354 | + <th scope="row"><?php _e( 'LDAP Logins', 'authorizer' ); ?></th> | |
| 4355 | + <td><?php $this->print_checkbox_auth_external_ldap( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5718 | 4356 | </tr> |
| 5719 | 4357 | <tr> |
| 5720 | - <th scope="row"><?php esc_html_e( 'LDAP Host', 'authorizer' ); ?></th> | |
| 5721 | - <td><?php $this->print_text_ldap_host( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4358 | + <th scope="row"><?php _e( 'LDAP Host', 'authorizer' ); ?></th> | |
| 4359 | + <td><?php $this->print_text_ldap_host( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5722 | 4360 | </tr> |
| 5723 | 4361 | <tr> |
| 5724 | - <th scope="row"><?php esc_html_e( 'LDAP Port', 'authorizer' ); ?></th> | |
| 5725 | - <td><?php $this->print_text_ldap_port( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4362 | + <th scope="row"><?php _e( 'LDAP Port', 'authorizer' ); ?></th> | |
| 4363 | + <td><?php $this->print_text_ldap_port( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5726 | 4364 | </tr> |
| 5727 | 4365 | <tr> |
| 5728 | - <th scope="row"><?php esc_html_e( 'Use TLS', 'authorizer' ); ?></th> | |
| 5729 | - <td><?php $this->print_checkbox_ldap_tls( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4366 | + <th scope="row"><?php _e( 'Secure Connection (TLS)', 'authorizer' ); ?></th> | |
| 4367 | + <td><?php $this->print_checkbox_ldap_tls( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5730 | 4368 | </tr> |
| 5731 | 4369 | <tr> |
| 5732 | - <th scope="row"><?php esc_html_e( 'LDAP Search Base', 'authorizer' ); ?></th> | |
| 5733 | - <td><?php $this->print_text_ldap_search_base( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4370 | + <th scope="row"><?php _e( 'LDAP Search Base', 'authorizer' ); ?></th> | |
| 4371 | + <td><?php $this->print_text_ldap_search_base( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5734 | 4372 | </tr> |
| 5735 | 4373 | <tr> |
| 5736 | - <th scope="row"><?php esc_html_e( 'LDAP attribute containing username', 'authorizer' ); ?></th> | |
| 5737 | - <td><?php $this->print_text_ldap_uid( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4374 | + <th scope="row"><?php _e( 'LDAP attribute containing username', 'authorizer' ); ?></th> | |
| 4375 | + <td><?php $this->print_text_ldap_uid( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5738 | 4376 | </tr> |
| 5739 | 4377 | <tr> |
| 5740 | - <th scope="row"><?php esc_html_e( 'LDAP attribute containing email', 'authorizer' ); ?></th> | |
| 5741 | - <td><?php $this->print_text_ldap_attr_email( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4378 | + <th scope="row"><?php _e( 'LDAP attribute containing email', 'authorizer' ); ?></th> | |
| 4379 | + <td><?php $this->print_text_ldap_attr_email( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5742 | 4380 | </tr> |
| 5743 | 4381 | <tr> |
| 5744 | - <th scope="row"><?php esc_html_e( 'LDAP Directory User', 'authorizer' ); ?></th> | |
| 5745 | - <td><?php $this->print_text_ldap_user( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4382 | + <th scope="row"><?php _e( 'LDAP Directory User', 'authorizer' ); ?></th> | |
| 4383 | + <td><?php $this->print_text_ldap_user( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5746 | 4384 | </tr> |
| 5747 | 4385 | <tr> |
| 5748 | - <th scope="row"><?php esc_html_e( 'LDAP Directory User Password', 'authorizer' ); ?></th> | |
| 5749 | - <td><?php $this->print_password_ldap_password( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4386 | + <th scope="row"><?php _e( 'LDAP Directory User Password', 'authorizer' ); ?></th> | |
| 4387 | + <td><?php $this->print_password_ldap_password( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5750 | 4388 | </tr> |
| 5751 | 4389 | <tr> |
| 5752 | - <th scope="row"><?php esc_html_e( 'Custom lost password URL', 'authorizer' ); ?></th> | |
| 5753 | - <td><?php $this->print_text_ldap_lostpassword_url( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4390 | + <th scope="row"><?php _e( 'Custom lost password URL', 'authorizer' ); ?></th> | |
| 4391 | + <td><?php $this->print_text_ldap_lostpassword_url( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5754 | 4392 | </tr> |
| 5755 | 4393 | <tr> |
| 5756 | - <th scope="row"><?php esc_html_e( 'LDAP attribute containing first name', 'authorizer' ); ?></th> | |
| 5757 | - <td><?php $this->print_text_ldap_attr_first_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4394 | + <th scope="row"><?php _e( 'LDAP attribute containing first name', 'authorizer' ); ?></th> | |
| 4395 | + <td><?php $this->print_text_ldap_attr_first_name( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5758 | 4396 | </tr> |
| 5759 | 4397 | <tr> |
| 5760 | - <th scope="row"><?php esc_html_e( 'LDAP attribute containing last name', 'authorizer' ); ?></th> | |
| 5761 | - <td><?php $this->print_text_ldap_attr_last_name( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4398 | + <th scope="row"><?php _e( 'LDAP attribute containing last name', 'authorizer' ); ?></th> | |
| 4399 | + <td><?php $this->print_text_ldap_attr_last_name( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5762 | 4400 | </tr> |
| 5763 | 4401 | <tr> |
| 5764 | - <th scope="row"><?php esc_html_e( 'LDAP attribute update', 'authorizer' ); ?></th> | |
| 5765 | - <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4402 | + <th scope="row"><?php _e( 'LDAP attribute update', 'authorizer' ); ?></th> | |
| 4403 | + <td><?php $this->print_checkbox_ldap_attr_update_on_login( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5766 | 4404 | </tr> |
| 5767 | 4405 | </tbody></table> |
| 5768 | 4406 | |
| 5769 | 4407 | <?php $this->print_section_info_advanced(); ?> |
| @@ -5768,36 +4406,20 @@ | ||
| 5768 | 4406 | |
| 5769 | 4407 | <?php $this->print_section_info_advanced(); ?> |
| 5770 | 4408 | <table class="form-table"><tbody> |
| 5771 | 4409 | <tr> |
| 5772 | - <th scope="row"><?php esc_html_e( 'Limit invalid login attempts', 'authorizer' ); ?></th> | |
| 5773 | - <td><?php $this->print_text_auth_advanced_lockouts( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4410 | + <th scope="row"><?php _e( 'Limit invalid login attempts', 'authorizer' ); ?></th> | |
| 4411 | + <td><?php $this->print_text_auth_advanced_lockouts( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5774 | 4412 | </tr> |
| 5775 | 4413 | <tr> |
| 5776 | - <th scope="row"><?php esc_html_e( 'Hide WordPress Logins', 'authorizer' ); ?></th> | |
| 5777 | - <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 4414 | + <th scope="row"><?php _e( 'Hide WordPress Logins', 'authorizer' ); ?></th> | |
| 4415 | + <td><?php $this->print_checkbox_auth_advanced_hide_wp_login( array( MULTISITE_ADMIN => true ) ); ?></td> | |
| 5778 | 4416 | </tr> |
| 5779 | - <tr> | |
| 5780 | - <th scope="row"><?php esc_html_e( 'Number of users per page', 'authorizer' ); ?></th> | |
| 5781 | - <td><?php $this->print_text_auth_advanced_users_per_page( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 5782 | - </tr> | |
| 5783 | - <tr> | |
| 5784 | - <th scope="row"><?php esc_html_e( 'Approved users sort method', 'authorizer' ); ?></th> | |
| 5785 | - <td><?php $this->print_select_auth_advanced_users_sort_by( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 5786 | - </tr> | |
| 5787 | - <tr> | |
| 5788 | - <th scope="row"><?php esc_html_e( 'Approved users sort order', 'authorizer' ); ?></th> | |
| 5789 | - <td><?php $this->print_select_auth_advanced_users_sort_order( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 5790 | - </tr> | |
| 5791 | - <tr> | |
| 5792 | - <th scope="row"><?php esc_html_e( 'Show Dashboard Widget', 'authorizer' ); ?></th> | |
| 5793 | - <td><?php $this->print_checkbox_auth_advanced_widget_enabled( array( WP_Plugin_Authorizer::NETWORK_CONTEXT => true ) ); ?></td> | |
| 5794 | - </tr> | |
| 5795 | 4417 | </tbody></table> |
| 5796 | 4418 | |
| 5797 | 4419 | <br class="clear" /> |
| 5798 | 4420 | </div> |
| 5799 | - <input type="button" name="submit" id="submit" class="button button-primary" value="<?php esc_attr_e( 'Save Changes', 'authorizer' ); ?>" onclick="saveAuthMultisiteSettings(this);" /> | |
| 4421 | + <input type="button" name="submit" id="submit" class="button button-primary" value="<?php _e( 'Save Changes', 'authorizer' ); ?>" onclick="save_auth_multisite_settings(this);" /> | |
| 5800 | 4422 | </form> |
| 5801 | 4423 | </div> |
| 5802 | 4424 | <?php |
| 5803 | 4425 | } |
| @@ -5804,12 +4426,10 @@ | ||
| 5804 | 4426 | |
| 5805 | 4427 | |
| 5806 | 4428 | /** |
| 5807 | 4429 | * Save multisite settings (ajax call). |
| 5808 | - * | |
| 5809 | - * Action: wp_ajax_save_auth_multisite_settings | |
| 5810 | 4430 | */ |
| 5811 | - public function ajax_save_auth_multisite_settings() { | |
| 4431 | + function ajax_save_auth_multisite_settings() { | |
| 5812 | 4432 | // Fail silently if current user doesn't have permissions. |
| 5813 | 4433 | if ( ! current_user_can( 'manage_network_options' ) ) { |
| 5814 | 4434 | die( '' ); |
| 5815 | 4435 | } |
| @@ -5814,14 +4434,14 @@ | ||
| 5814 | 4434 | die( '' ); |
| 5815 | 4435 | } |
| 5816 | 4436 | |
| 5817 | 4437 | // Make sure nonce exists. |
| 5818 | - if ( empty( $_POST['nonce'] ) ) { | |
| 4438 | + if ( empty( $_POST['nonce_save_auth_settings'] ) ) { | |
| 5819 | 4439 | die( '' ); |
| 5820 | 4440 | } |
| 5821 | 4441 | |
| 5822 | 4442 | // Nonce check. |
| 5823 | - if ( ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) { | |
| 4443 | + if ( ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) { | |
| 5824 | 4444 | die( '' ); |
| 5825 | 4445 | } |
| 5826 | 4446 | |
| 5827 | 4447 | // Assert multisite. |
| @@ -5829,15 +4449,15 @@ | ||
| 5829 | 4449 | die( '' ); |
| 5830 | 4450 | } |
| 5831 | 4451 | |
| 5832 | 4452 | // Get multisite settings. |
| 5833 | - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() ); | |
| 4453 | + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); | |
| 5834 | 4454 | |
| 5835 | - // Sanitize settings. | |
| 4455 | + // Sanitize settings | |
| 5836 | 4456 | $auth_multisite_settings = $this->sanitize_options( $_POST ); |
| 5837 | 4457 | |
| 5838 | - // Filter options to only the allowed values (multisite options are a subset of all options). | |
| 5839 | - $allowed = array( | |
| 4458 | + // Filter options to only the allowed values (multisite options are a subset of all options) | |
| 4459 | + $allowed = array( | |
| 5840 | 4460 | 'multisite_override', |
| 5841 | 4461 | 'access_who_can_login', |
| 5842 | 4462 | 'access_who_can_view', |
| 5843 | 4463 | 'access_default_role', |
| @@ -5870,17 +4490,13 @@ | ||
| 5870 | 4490 | 'ldap_attr_last_name', |
| 5871 | 4491 | 'ldap_attr_update_on_login', |
| 5872 | 4492 | 'advanced_lockouts', |
| 5873 | 4493 | 'advanced_hide_wp_login', |
| 5874 | - 'advanced_users_per_page', | |
| 5875 | - 'advanced_users_sort_by', | |
| 5876 | - 'advanced_users_sort_order', | |
| 5877 | - 'advanced_widget_enabled', | |
| 5878 | 4494 | ); |
| 5879 | 4495 | $auth_multisite_settings = array_intersect_key( $auth_multisite_settings, array_flip( $allowed ) ); |
| 5880 | 4496 | |
| 5881 | 4497 | // Update multisite settings in database. |
| 5882 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 4498 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 5883 | 4499 | |
| 5884 | 4500 | // Return 'success' value to AJAX call. |
| 5885 | 4501 | die( 'success' ); |
| 5886 | 4502 | } |
| @@ -5894,67 +4510,42 @@ | ||
| 5894 | 4510 | */ |
| 5895 | 4511 | |
| 5896 | 4512 | |
| 5897 | 4513 | |
| 5898 | - /** | |
| 5899 | - * Load Authorizer dashboard widget if it's enabled. | |
| 5900 | - * | |
| 5901 | - * Action: wp_dashboard_setup | |
| 5902 | - */ | |
| 5903 | - public function add_dashboard_widgets() { | |
| 5904 | - $widget_enabled = $this->get_plugin_option( 'advanced_widget_enabled', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) === '1'; | |
| 5905 | - | |
| 5906 | - // Load authorizer dashboard widget if it's enabled and user has permission. | |
| 5907 | - if ( current_user_can( 'create_users' ) && $widget_enabled ) { | |
| 5908 | - // Add dashboard widget for adding/editing users with access. | |
| 4514 | + function add_dashboard_widgets() { | |
| 4515 | + // Only users who can edit can see the authorizer dashboard widget | |
| 4516 | + if ( current_user_can( 'create_users' ) ) { | |
| 4517 | + // Add dashboard widget for adding/editing users with access | |
| 5909 | 4518 | wp_add_dashboard_widget( 'auth_dashboard_widget', __( 'Authorizer Settings', 'authorizer' ), array( $this, 'add_auth_dashboard_widget' ) ); |
| 5910 | 4519 | } |
| 5911 | 4520 | } |
| 5912 | 4521 | |
| 5913 | 4522 | |
| 5914 | - /** | |
| 5915 | - * Render Authorizer dashboard widget (callback). | |
| 5916 | - */ | |
| 5917 | - public function add_auth_dashboard_widget() { | |
| 5918 | - ?> | |
| 5919 | - <form method="post" id="auth_settings_access_form" action=""> | |
| 4523 | + function add_auth_dashboard_widget() { | |
| 4524 | + ?><form method="post" id="auth_settings_access_form" action=""> | |
| 5920 | 4525 | <?php $this->print_section_info_access_login(); ?> |
| 5921 | 4526 | <div> |
| 5922 | - <h2><?php esc_html_e( 'Pending Users', 'authorizer' ); ?></h2> | |
| 4527 | + <h2><?php _e( 'Pending Users', 'authorizer' ); ?></h2> | |
| 5923 | 4528 | <?php $this->print_combo_auth_access_users_pending(); ?> |
| 5924 | 4529 | </div> |
| 5925 | 4530 | <div> |
| 5926 | - <h2><?php esc_html_e( 'Approved Users', 'authorizer' ); ?></h2> | |
| 4531 | + <h2><?php _e( 'Approved Users', 'authorizer' ); ?></h2> | |
| 5927 | 4532 | <?php $this->print_combo_auth_access_users_approved(); ?> |
| 5928 | 4533 | </div> |
| 5929 | 4534 | <div> |
| 5930 | - <h2><?php esc_html_e( 'Blocked Users', 'authorizer' ); ?></h2> | |
| 4535 | + <h2><?php _e( 'Blocked Users', 'authorizer' ); ?></h2> | |
| 5931 | 4536 | <?php $this->print_combo_auth_access_users_blocked(); ?> |
| 5932 | 4537 | </div> |
| 5933 | 4538 | <br class="clear" /> |
| 5934 | - </form> | |
| 5935 | - <?php | |
| 4539 | + </form><?php | |
| 5936 | 4540 | } |
| 5937 | 4541 | |
| 5938 | 4542 | |
| 5939 | - | |
| 5940 | - /** | |
| 5941 | - * *************************** | |
| 5942 | - * AJAX Actions | |
| 5943 | - * *************************** | |
| 5944 | - */ | |
| 5945 | - | |
| 5946 | - | |
| 5947 | - | |
| 5948 | - /** | |
| 5949 | - * Re-render the Approved User list (usually triggered if pager params have | |
| 5950 | - * changed, e.g., current page, search term, sort order). | |
| 5951 | - * | |
| 5952 | - * Action: wp_ajax_refresh_approved_user_list | |
| 5953 | - * | |
| 5954 | - * @return void | |
| 5955 | - */ | |
| 5956 | - public function ajax_refresh_approved_user_list() { | |
| 4543 | + // Fired on a change event from the optional usermeta field in the | |
| 4544 | + // approved user list. Updates the selected usermeta value, or saves it | |
| 4545 | + // in the user's approved list entry if the user hasn't logged in yet | |
| 4546 | + // and created a WordPress account. | |
| 4547 | + function ajax_update_auth_usermeta() { | |
| 5957 | 4548 | // Fail silently if current user doesn't have permissions. |
| 5958 | 4549 | if ( ! current_user_can( 'create_users' ) ) { |
| 5959 | 4550 | die( '' ); |
| 5960 | 4551 | } |
| @@ -5959,175 +4550,35 @@ | ||
| 5959 | 4550 | die( '' ); |
| 5960 | 4551 | } |
| 5961 | 4552 | |
| 5962 | 4553 | // Nonce check. |
| 5963 | - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) { | |
| 4554 | + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) { | |
| 5964 | 4555 | die( '' ); |
| 5965 | 4556 | } |
| 5966 | 4557 | |
| 5967 | 4558 | // Fail if required post data doesn't exist. |
| 5968 | - if ( ! array_key_exists( 'paged', $_REQUEST ) ) { | |
| 4559 | + if ( ! array_key_exists( 'email', $_REQUEST ) || ! array_key_exists( 'usermeta', $_REQUEST ) ) { | |
| 5969 | 4560 | die( '' ); |
| 5970 | 4561 | } |
| 5971 | 4562 | |
| 5972 | - // Get defaults. | |
| 5973 | - $success = true; | |
| 5974 | - $message = ''; | |
| 5975 | - $is_network_admin = isset( $_REQUEST['is_network_admin'] ) && '1' === $_REQUEST['is_network_admin']; | |
| 5976 | - | |
| 5977 | - // Get user list. | |
| 5978 | - $option = 'access_users_approved'; | |
| 5979 | - $admin_mode = is_multisite() && $is_network_admin ? WP_Plugin_Authorizer::NETWORK_CONTEXT : WP_Plugin_Authorizer::SINGLE_CONTEXT; | |
| 5980 | - $auth_settings_option = $this->get_plugin_option( $option, $admin_mode, 'no override' ); | |
| 5981 | - $auth_settings_option = is_array( $auth_settings_option ) ? $auth_settings_option : array(); | |
| 5982 | - | |
| 5983 | - // Get multisite approved users (will be added to top of list, greyed out). | |
| 5984 | - $auth_override_multisite = $this->get_plugin_option( 'advanced_override_multisite' ); | |
| 5985 | - $auth_multisite_settings = $this->get_plugin_options( WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 5986 | - $auth_settings_option_multisite = array(); | |
| 5987 | - if ( | |
| 5988 | - is_multisite() && | |
| 5989 | - ! $is_network_admin && | |
| 5990 | - 1 !== intval( $auth_override_multisite ) && | |
| 5991 | - array_key_exists( 'multisite_override', $auth_multisite_settings ) && | |
| 5992 | - '1' === $auth_multisite_settings['multisite_override'] | |
| 5993 | - ) { | |
| 5994 | - $auth_settings_option_multisite = $this->get_plugin_option( $option, WP_Plugin_Authorizer::NETWORK_CONTEXT, 'allow override' ); | |
| 5995 | - $auth_settings_option_multisite = is_array( $auth_settings_option_multisite ) ? $auth_settings_option_multisite : array(); | |
| 5996 | - // Add multisite users to the beginning of the main user array. | |
| 5997 | - foreach ( array_reverse( $auth_settings_option_multisite ) as $approved_user ) { | |
| 5998 | - $approved_user['multisite_user'] = true; | |
| 5999 | - array_unshift( $auth_settings_option, $approved_user ); | |
| 6000 | - } | |
| 6001 | - } | |
| 6002 | - | |
| 6003 | - // Get custom usermeta field to show. | |
| 6004 | - $advanced_usermeta = $this->get_plugin_option( 'advanced_usermeta' ); | |
| 6005 | - | |
| 6006 | - // Filter user list to search terms. | |
| 6007 | - if ( ! empty( $_REQUEST['search'] ) ) { | |
| 6008 | - $search_term = sanitize_text_field( wp_unslash( $_REQUEST['search'] ) ); | |
| 6009 | - $auth_settings_option = array_filter( | |
| 6010 | - $auth_settings_option, function ( $user ) use ( $search_term ) { | |
| 6011 | - return stripos( $user['email'], $search_term ) !== false || | |
| 6012 | - stripos( $user['role'], $search_term ) !== false || | |
| 6013 | - stripos( $user['date_added'], $search_term ) !== false; | |
| 6014 | - } | |
| 6015 | - ); | |
| 6016 | - } | |
| 6017 | - | |
| 6018 | - // Sort user list. | |
| 6019 | - $sort_by = $this->get_plugin_option( 'advanced_users_sort_by', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // email, role, date_added (registered), created (date approved). | |
| 6020 | - $sort_order = $this->get_plugin_option( 'advanced_users_sort_order', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); // asc or desc. | |
| 6021 | - $sort_dimension = array(); | |
| 6022 | - if ( in_array( $sort_by, array( 'email', 'role', 'date_added' ), true ) ) { | |
| 6023 | - foreach ( $auth_settings_option as $key => $user ) { | |
| 6024 | - if ( 'date_added' === $sort_by ) { | |
| 6025 | - $sort_dimension[ $key ] = date( 'Ymd', strtotime( $user[ $sort_by ] ) ); | |
| 6026 | - } else { | |
| 6027 | - $sort_dimension[ $key ] = strtolower( $user[ $sort_by ] ); | |
| 6028 | - } | |
| 6029 | - } | |
| 6030 | - $sort_order = 'asc' === $sort_order ? SORT_ASC : SORT_DESC; | |
| 6031 | - array_multisort( $sort_dimension, $sort_order, $auth_settings_option ); | |
| 6032 | - } elseif ( 'created' === $sort_by && 'asc' !== $sort_order ) { | |
| 6033 | - // If default sort method and reverse order, just reverse the array. | |
| 6034 | - $auth_settings_option = array_reverse( $auth_settings_option ); | |
| 6035 | - } | |
| 6036 | - | |
| 6037 | - // Ensure array keys run from 0..max (keys in database will be the original, | |
| 6038 | - // index, and removing users will not reorder the array keys of other users). | |
| 6039 | - $auth_settings_option = array_values( $auth_settings_option ); | |
| 6040 | - | |
| 6041 | - // Get pager params. | |
| 6042 | - $total_users = count( $auth_settings_option ); | |
| 6043 | - $users_per_page = intval( $this->get_plugin_option( 'advanced_users_per_page', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ) ); | |
| 6044 | - $current_page = isset( $_REQUEST['paged'] ) ? intval( $_REQUEST['paged'] ) : 1; | |
| 6045 | - $total_pages = ceil( $total_users / $users_per_page ); | |
| 6046 | - if ( $total_pages < 1 ) { | |
| 6047 | - $total_pages = 1; | |
| 6048 | - } | |
| 6049 | - | |
| 6050 | - // Make sure current_page is between 1 and max pages. | |
| 6051 | - if ( $current_page < 1 ) { | |
| 6052 | - $current_page = 1; | |
| 6053 | - } elseif ( $current_page > $total_pages ) { | |
| 6054 | - $current_page = $total_pages; | |
| 6055 | - } | |
| 6056 | - | |
| 6057 | - // Render user list. | |
| 6058 | - ob_start(); | |
| 6059 | - $offset = ( $current_page - 1 ) * $users_per_page; | |
| 6060 | - $max = min( $offset + $users_per_page, count( $auth_settings_option ) ); | |
| 6061 | - for ( $key = $offset; $key < $max; $key++ ) : | |
| 6062 | - $approved_user = $auth_settings_option[ $key ]; | |
| 6063 | - if ( empty( $approved_user ) || count( $approved_user ) < 1 ) : | |
| 6064 | - continue; | |
| 6065 | - endif; | |
| 6066 | - $this->render_user_element( $approved_user, $key, $option, $admin_mode, $advanced_usermeta ); | |
| 6067 | - endfor; | |
| 6068 | - | |
| 6069 | - // Send response to client. | |
| 6070 | - $response = array( | |
| 6071 | - 'success' => $success, | |
| 6072 | - 'message' => $message, | |
| 6073 | - 'html' => ob_get_clean(), | |
| 6074 | - /* TRANSLATORS: %s: number of users */ | |
| 6075 | - 'total_users_html' => sprintf( _n( '%s user', '%s users', $total_users, 'authorizer' ), number_format_i18n( $total_users ) ), | |
| 6076 | - 'total_pages_html' => number_format_i18n( $total_pages ), | |
| 6077 | - 'total_pages' => $total_pages, | |
| 6078 | - ); | |
| 6079 | - header( 'content-type: application/json' ); | |
| 6080 | - echo wp_json_encode( $response ); | |
| 6081 | - exit; | |
| 6082 | - } | |
| 6083 | - | |
| 6084 | - | |
| 6085 | - /** | |
| 6086 | - * Fired on a change event from the optional usermeta field in the approved | |
| 6087 | - * user list. Updates the selected usermeta value, or saves it in the user's | |
| 6088 | - * approved list entry if the user hasn't logged in yet and created a | |
| 6089 | - * WordPress account. | |
| 6090 | - * | |
| 6091 | - * Action: wp_ajax_update_auth_usermeta | |
| 6092 | - * | |
| 6093 | - * @return void | |
| 6094 | - */ | |
| 6095 | - public function ajax_update_auth_usermeta() { | |
| 6096 | - // Fail silently if current user doesn't have permissions. | |
| 6097 | - if ( ! current_user_can( 'create_users' ) ) { | |
| 6098 | - die( '' ); | |
| 6099 | - } | |
| 6100 | - | |
| 6101 | - // Nonce check. | |
| 6102 | - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) { | |
| 6103 | - die( '' ); | |
| 6104 | - } | |
| 6105 | - | |
| 6106 | - // Fail if required post data doesn't exist. | |
| 6107 | - if ( ! isset( $_REQUEST['email'], $_REQUEST['usermeta'] ) ) { | |
| 6108 | - die( '' ); | |
| 6109 | - } | |
| 6110 | - | |
| 6111 | 4563 | // Get values to update from post data. |
| 6112 | - $email = sanitize_email( wp_unslash( $_REQUEST['email'] ) ); | |
| 6113 | - $meta_value = sanitize_meta( 'authorizer-usermeta', wp_unslash( $_REQUEST['usermeta'] ), 'user' ); | |
| 6114 | - $meta_key = $this->get_plugin_option( 'advanced_usermeta' ); | |
| 4564 | + $email = $_REQUEST['email']; | |
| 4565 | + $meta_value = $_REQUEST['usermeta']; | |
| 4566 | + $meta_key = $this->get_plugin_option( 'advanced_usermeta' ); | |
| 6115 | 4567 | |
| 6116 | 4568 | // If user doesn't exist, save usermeta selection to authorizer |
| 6117 | 4569 | // list. This value will get saved to usermeta when the user first |
| 6118 | 4570 | // logs in (i.e., when their WordPress account is created). |
| 6119 | - $wp_user = get_user_by( 'email', $email ); | |
| 6120 | - if ( ! $wp_user ) { | |
| 4571 | + if ( ! ( $wp_user = get_user_by( 'email', $email ) ) ) { | |
| 6121 | 4572 | // Look through multisite approved users and add a usermeta |
| 6122 | 4573 | // reference for the current blog if the user is found. |
| 6123 | - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array(); | |
| 4574 | + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array(); | |
| 6124 | 4575 | $should_update_auth_multisite_settings_access_users_approved = false; |
| 6125 | 4576 | foreach ( $auth_multisite_settings_access_users_approved as $index => $approved_user ) { |
| 6126 | - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) { | |
| 6127 | - if ( ! is_array( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] ) ) { | |
| 4577 | + if ( $email === $approved_user['email'] ) { | |
| 4578 | + if ( ! is_array( $auth_multisite_settings_access_users_approved[$index]['usermeta'] ) ) { | |
| 6128 | 4579 | // Initialize the array of usermeta for each blog this user belongs to. |
| 6129 | - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] = array(); | |
| 4580 | + $auth_multisite_settings_access_users_approved[$index]['usermeta'] = array(); | |
| 6130 | 4581 | } else { |
| 6131 | 4582 | // There is already usermeta associated with this |
| 6132 | 4583 | // preapproved user; iterate through it and make |
| 6133 | 4584 | // sure it's not for old meta_keys (delete it if |
| @@ -6133,53 +4584,55 @@ | ||
| 6133 | 4584 | // sure it's not for old meta_keys (delete it if |
| 6134 | 4585 | // so). This can happen if someone changes the |
| 6135 | 4586 | // usermeta key in authorizer options, and we don't |
| 6136 | 4587 | // want to hang on to old data. |
| 6137 | - foreach ( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'] as $blog_id => $usermeta ) { | |
| 4588 | + foreach ( $auth_multisite_settings_access_users_approved[$index]['usermeta'] as $blog_id => $usermeta ) { | |
| 6138 | 4589 | if ( array_key_exists( 'meta_key', $usermeta ) && $usermeta['meta_key'] === $meta_key ) { |
| 6139 | 4590 | continue; |
| 6140 | 4591 | } else { |
| 6141 | - unset( $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ $blog_id ] ); | |
| 4592 | + unset( $auth_multisite_settings_access_users_approved[$index]['usermeta'][$blog_id] ); | |
| 6142 | 4593 | } |
| 6143 | 4594 | } |
| 6144 | 4595 | } |
| 6145 | - $auth_multisite_settings_access_users_approved[ $index ]['usermeta'][ get_current_blog_id() ] = array( | |
| 6146 | - 'meta_key' => $meta_key, | |
| 4596 | + $auth_multisite_settings_access_users_approved[$index]['usermeta'][get_current_blog_id()] = array( | |
| 4597 | + 'meta_key' => $meta_key, | |
| 6147 | 4598 | 'meta_value' => $meta_value, |
| 6148 | 4599 | ); |
| 6149 | - $should_update_auth_multisite_settings_access_users_approved = true; | |
| 4600 | + $should_update_auth_multisite_settings_access_users_approved = true; | |
| 6150 | 4601 | } |
| 6151 | 4602 | } |
| 6152 | 4603 | if ( $should_update_auth_multisite_settings_access_users_approved ) { |
| 6153 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 4604 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 6154 | 4605 | } |
| 6155 | 4606 | |
| 6156 | 4607 | // Look through the approved users (of the current blog in a |
| 6157 | 4608 | // multisite install, or just of the single site) and add a |
| 6158 | 4609 | // usermeta reference if the user is found. |
| 6159 | - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 4610 | + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 6160 | 4611 | $should_update_auth_settings_access_users_approved = false; |
| 6161 | 4612 | foreach ( $auth_settings_access_users_approved as $index => $approved_user ) { |
| 6162 | - if ( 0 === strcasecmp( $email, $approved_user['email'] ) ) { | |
| 6163 | - $auth_settings_access_users_approved[ $index ]['usermeta'] = array( | |
| 6164 | - 'meta_key' => $meta_key, | |
| 4613 | + if ( $email === $approved_user['email'] ) { | |
| 4614 | + $auth_settings_access_users_approved[$index]['usermeta'] = array( | |
| 4615 | + 'meta_key' => $meta_key, | |
| 6165 | 4616 | 'meta_value' => $meta_value, |
| 6166 | 4617 | ); |
| 6167 | - $should_update_auth_settings_access_users_approved = true; | |
| 4618 | + $should_update_auth_settings_access_users_approved = true; | |
| 6168 | 4619 | } |
| 6169 | 4620 | } |
| 6170 | 4621 | if ( $should_update_auth_settings_access_users_approved ) { |
| 6171 | 4622 | update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); |
| 6172 | 4623 | } |
| 4624 | + | |
| 6173 | 4625 | } else { |
| 6174 | 4626 | // Update user's usermeta value for usermeta key stored in authorizer options. |
| 6175 | 4627 | if ( strpos( $meta_key, 'acf___' ) === 0 && class_exists( 'acf' ) ) { |
| 6176 | 4628 | // We have an ACF field value, so use the ACF function to update it. |
| 6177 | - update_field( str_replace( 'acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID ); | |
| 4629 | + update_field( str_replace('acf___', '', $meta_key ), $meta_value, 'user_' . $wp_user->ID ); | |
| 6178 | 4630 | } else { |
| 6179 | 4631 | // We have a normal usermeta value, so just update it via the WordPress function. |
| 6180 | 4632 | update_user_meta( $wp_user->ID, $meta_key, $meta_value ); |
| 6181 | 4633 | } |
| 4634 | + | |
| 6182 | 4635 | } |
| 6183 | 4636 | |
| 6184 | 4637 | // Return 'success' value to AJAX call. |
| 6185 | 4638 | die( 'success' ); |
| @@ -6185,17 +4638,9 @@ | ||
| 6185 | 4638 | die( 'success' ); |
| 6186 | 4639 | } |
| 6187 | 4640 | |
| 6188 | 4641 | |
| 6189 | - /** | |
| 6190 | - * Fired on a change event from the user fields in the user lists. Updates | |
| 6191 | - * the selected user value. | |
| 6192 | - * | |
| 6193 | - * Action: wp_ajax_update_auth_user | |
| 6194 | - * | |
| 6195 | - * @return void | |
| 6196 | - */ | |
| 6197 | - public function ajax_update_auth_user() { | |
| 4642 | + function ajax_update_auth_user() { | |
| 6198 | 4643 | // Fail silently if current user doesn't have permissions. |
| 6199 | 4644 | if ( ! current_user_can( 'create_users' ) ) { |
| 6200 | 4645 | die( '' ); |
| 6201 | 4646 | } |
| @@ -6200,83 +4645,76 @@ | ||
| 6200 | 4645 | die( '' ); |
| 6201 | 4646 | } |
| 6202 | 4647 | |
| 6203 | 4648 | // Nonce check. |
| 6204 | - if ( empty( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_key( $_POST['nonce'] ), 'save_auth_settings' ) ) { | |
| 4649 | + if ( empty( $_POST['nonce_save_auth_settings'] ) || ! wp_verify_nonce( $_POST['nonce_save_auth_settings'], 'save_auth_settings' ) ) { | |
| 6205 | 4650 | die( '' ); |
| 6206 | 4651 | } |
| 6207 | 4652 | |
| 6208 | 4653 | // Fail if requesting a change to an invalid setting. |
| 6209 | - if ( ! isset( $_POST['setting'] ) || ! in_array( wp_unslash( $_POST['setting'] ), array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) { | |
| 4654 | + if ( ! in_array( $_POST['setting'], array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) { | |
| 6210 | 4655 | die( '' ); |
| 6211 | 4656 | } |
| 6212 | 4657 | |
| 6213 | - // Track any emails that couldn't be added (used when adding users). | |
| 6214 | - $invalid_emails = array(); | |
| 6215 | - | |
| 6216 | 4658 | // Editing a pending list entry. |
| 6217 | - if ( 'access_users_pending' === $_POST['setting'] ) { | |
| 6218 | - // Sanitize posted data. | |
| 6219 | - $access_users_pending = array(); | |
| 6220 | - if ( isset( $_POST['access_users_pending'] ) && is_array( $_POST['access_users_pending'] ) ) { | |
| 6221 | - $access_users_pending = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_pending'] ) ); | |
| 4659 | + if ( $_POST['setting'] === 'access_users_pending' ) { | |
| 4660 | + // Initialize posted data if empty. | |
| 4661 | + if ( ! ( array_key_exists( 'access_users_pending', $_POST ) && is_array( $_POST['access_users_pending'] ) ) ) { | |
| 4662 | + $_POST['access_users_pending'] = array(); | |
| 6222 | 4663 | } |
| 6223 | 4664 | |
| 6224 | 4665 | // Deal with each modified user (add or remove). |
| 6225 | - foreach ( $access_users_pending as $pending_user ) { | |
| 4666 | + foreach ( $_POST['access_users_pending'] as $pending_user ) { | |
| 6226 | 4667 | |
| 6227 | - if ( 'add' === $pending_user['edit_action'] ) { | |
| 4668 | + if ( $pending_user['edit_action'] === 'add' ) { | |
| 6228 | 4669 | |
| 6229 | 4670 | // Add new user to pending list and save (skip if it's |
| 6230 | 4671 | // already there--someone else might have just done it). |
| 6231 | 4672 | if ( ! $this->is_email_in_list( $pending_user['email'], 'pending' ) ) { |
| 6232 | 4673 | $auth_settings_access_users_pending = $this->sanitize_user_list( |
| 6233 | - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4674 | + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ) | |
| 6234 | 4675 | ); |
| 6235 | 4676 | array_push( $auth_settings_access_users_pending, $pending_user ); |
| 6236 | 4677 | update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending ); |
| 6237 | 4678 | } |
| 6238 | - } elseif ( 'remove' === $pending_user['edit_action'] ) { | |
| 6239 | 4679 | |
| 6240 | - // Remove user from pending list and save. | |
| 4680 | + } elseif ( $pending_user['edit_action'] === 'remove' ) { | |
| 4681 | + | |
| 4682 | + // Remove user from pending list and save | |
| 6241 | 4683 | if ( $this->is_email_in_list( $pending_user['email'], 'pending' ) ) { |
| 6242 | 4684 | $auth_settings_access_users_pending = $this->sanitize_user_list( |
| 6243 | - $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4685 | + $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ) | |
| 6244 | 4686 | ); |
| 6245 | 4687 | foreach ( $auth_settings_access_users_pending as $key => $existing_user ) { |
| 6246 | - if ( 0 === strcasecmp( $pending_user['email'], $existing_user['email'] ) ) { | |
| 6247 | - unset( $auth_settings_access_users_pending[ $key ] ); | |
| 4688 | + if ( $pending_user['email'] == $existing_user['email'] ) { | |
| 4689 | + unset( $auth_settings_access_users_pending[$key] ); | |
| 6248 | 4690 | break; |
| 6249 | 4691 | } |
| 6250 | 4692 | } |
| 6251 | 4693 | update_option( 'auth_settings_access_users_pending', $auth_settings_access_users_pending ); |
| 6252 | 4694 | } |
| 4695 | + | |
| 6253 | 4696 | } |
| 6254 | 4697 | } |
| 6255 | 4698 | } |
| 6256 | 4699 | |
| 6257 | 4700 | // Editing an approved list entry. |
| 6258 | - if ( 'access_users_approved' === $_POST['setting'] ) { | |
| 6259 | - // Sanitize posted data. | |
| 6260 | - $access_users_approved = array(); | |
| 6261 | - if ( isset( $_POST['access_users_approved'] ) && is_array( $_POST['access_users_approved'] ) ) { | |
| 6262 | - $access_users_approved = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_approved'] ) ); | |
| 4701 | + if ( $_POST['setting'] === 'access_users_approved' ) { | |
| 4702 | + // Initialize posted data if empty. | |
| 4703 | + if ( ! ( array_key_exists( 'access_users_approved', $_POST ) && is_array( $_POST['access_users_approved'] ) ) ) { | |
| 4704 | + $_POST['access_users_approved'] = array(); | |
| 6263 | 4705 | } |
| 6264 | 4706 | |
| 6265 | 4707 | // Deal with each modified user (add, remove, or change_role). |
| 6266 | - foreach ( $access_users_approved as $approved_user ) { | |
| 6267 | - // Skip blank entries. | |
| 6268 | - if ( strlen( $approved_user['email'] ) < 1 ) { | |
| 6269 | - continue; | |
| 6270 | - } | |
| 4708 | + foreach ( $_POST['access_users_approved'] as $approved_user ) { | |
| 6271 | 4709 | |
| 6272 | 4710 | // New user (create user, or add existing user to current site in multisite). |
| 6273 | - if ( 'add' === $approved_user['edit_action'] ) { | |
| 4711 | + if ( $approved_user['edit_action'] === 'add' ) { | |
| 6274 | 4712 | $new_user = get_user_by( 'email', $approved_user['email'] ); |
| 6275 | - if ( false !== $new_user ) { | |
| 4713 | + if ( $new_user !== false ) { | |
| 6276 | 4714 | // If we're adding an existing multisite user, make sure their |
| 6277 | 4715 | // newly-assigned role is updated on all sites they are already in. |
| 6278 | - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) { | |
| 4716 | + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) { | |
| 6279 | 4717 | foreach ( get_blogs_of_user( $new_user->ID ) as $blog ) { |
| 6280 | 4718 | add_user_to_blog( $blog->userblog_id, $new_user->ID, $approved_user['role'] ); |
| 6281 | 4719 | } |
| 6282 | 4720 | } |
| @@ -6283,9 +4721,9 @@ | ||
| 6283 | 4721 | // If this user already has an account on another site in the network, add them to this site. |
| 6284 | 4722 | if ( is_multisite() ) { |
| 6285 | 4723 | add_user_to_blog( get_current_blog_id(), $new_user->ID, $approved_user['role'] ); |
| 6286 | 4724 | } |
| 6287 | - } elseif ( $approved_user['local_user'] && 'false' !== $approved_user['local_user'] ) { | |
| 4725 | + } elseif ( $approved_user['local_user'] === 'true' ) { | |
| 6288 | 4726 | // Create a WP account for this new *local* user and email the password. |
| 6289 | 4727 | $plaintext_password = wp_generate_password(); // random password |
| 6290 | 4728 | // If there's already a user with this username (e.g., |
| 6291 | 4729 | // johndoe/johndoe@gmail.com exists, and we're trying to add |
| @@ -6293,26 +4731,26 @@ | ||
| 6293 | 4731 | // as the username. |
| 6294 | 4732 | $username = explode( '@', $approved_user['email'] ); |
| 6295 | 4733 | $username = $username[0]; |
| 6296 | 4734 | if ( get_user_by( 'login', $username ) !== false ) { |
| 6297 | - $username = $this->lowercase( $approved_user['email'] ); | |
| 4735 | + $username = $approved_user['email']; | |
| 6298 | 4736 | } |
| 6299 | - if ( 'false' !== $approved_user['multisite_user'] ) { | |
| 4737 | + if ( $approved_user['multisite_user'] !== 'false' ) { | |
| 6300 | 4738 | $result = wpmu_create_user( |
| 6301 | 4739 | strtolower( $username ), |
| 6302 | 4740 | $plaintext_password, |
| 6303 | - $this->lowercase( $approved_user['email'] ) | |
| 4741 | + strtolower( $approved_user['email'] ) | |
| 6304 | 4742 | ); |
| 6305 | 4743 | } else { |
| 6306 | 4744 | $result = wp_insert_user( |
| 6307 | 4745 | array( |
| 6308 | - 'user_login' => strtolower( $username ), | |
| 6309 | - 'user_pass' => $plaintext_password, | |
| 6310 | - 'first_name' => '', | |
| 6311 | - 'last_name' => '', | |
| 6312 | - 'user_email' => $this->lowercase( $approved_user['email'] ), | |
| 4746 | + 'user_login' => strtolower( $username ), | |
| 4747 | + 'user_pass' => $plaintext_password, | |
| 4748 | + 'first_name' => '', | |
| 4749 | + 'last_name' => '', | |
| 4750 | + 'user_email' => strtolower( $approved_user['email'] ), | |
| 6313 | 4751 | 'user_registered' => date( 'Y-m-d H:i:s' ), |
| 6314 | - 'role' => $approved_user['role'], | |
| 4752 | + 'role' => $approved_user['role'], | |
| 6315 | 4753 | ) |
| 6316 | 4754 | ); |
| 6317 | 4755 | } |
| 6318 | 4756 | if ( ! is_wp_error( $result ) ) { |
| @@ -6318,8 +4756,9 @@ | ||
| 6318 | 4756 | if ( ! is_wp_error( $result ) ) { |
| 6319 | 4757 | // Email login credentials to new user. |
| 6320 | 4758 | wp_new_user_notification( $result, null, 'both' ); |
| 6321 | 4759 | } |
| 4760 | + | |
| 6322 | 4761 | } |
| 6323 | 4762 | |
| 6324 | 4763 | // Email new user welcome message if plugin option is set. |
| 6325 | 4764 | $this->maybe_email_welcome_message( $approved_user['email'] ); |
| @@ -6325,46 +4764,41 @@ | ||
| 6325 | 4764 | $this->maybe_email_welcome_message( $approved_user['email'] ); |
| 6326 | 4765 | |
| 6327 | 4766 | // Add new user to approved list and save (skip if it's |
| 6328 | 4767 | // already there--someone else might have just done it). |
| 6329 | - if ( 'false' !== $approved_user['multisite_user'] ) { | |
| 4768 | + if ( $approved_user['multisite_user'] !== 'false' ) { | |
| 6330 | 4769 | if ( ! $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) { |
| 6331 | 4770 | $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( |
| 6332 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 4771 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 6333 | 4772 | ); |
| 6334 | - $approved_user['date_added'] = date( 'M Y' ); | |
| 4773 | + $approved_user['date_added'] = date( 'M Y' ); | |
| 6335 | 4774 | array_push( $auth_multisite_settings_access_users_approved, $approved_user ); |
| 6336 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 6337 | - } else { | |
| 6338 | - $invalid_emails[] = $approved_user['email']; | |
| 4775 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 6339 | 4776 | } |
| 6340 | 4777 | } else { |
| 6341 | 4778 | if ( ! $this->is_email_in_list( $approved_user['email'], 'approved' ) ) { |
| 6342 | 4779 | $auth_settings_access_users_approved = $this->sanitize_user_list( |
| 6343 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4780 | + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) | |
| 6344 | 4781 | ); |
| 6345 | - $approved_user['date_added'] = date( 'M Y' ); | |
| 4782 | + $approved_user['date_added'] = date( 'M Y' ); | |
| 6346 | 4783 | array_push( $auth_settings_access_users_approved, $approved_user ); |
| 6347 | 4784 | update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); |
| 6348 | - } else { | |
| 6349 | - $invalid_emails[] = $approved_user['email']; | |
| 6350 | 4785 | } |
| 6351 | 4786 | } |
| 6352 | 4787 | |
| 6353 | 4788 | // If we've added a new multisite user, go through all pending/approved/blocked lists |
| 6354 | 4789 | // on individual sites and remove this user from them (to prevent duplicate entries). |
| 6355 | - if ( 'false' !== $approved_user['multisite_user'] && is_multisite() ) { | |
| 4790 | + if ( $approved_user['multisite_user'] !== 'false' && is_multisite() ) { | |
| 6356 | 4791 | $list_names = array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ); |
| 6357 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 6358 | 4792 | $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); |
| 6359 | 4793 | foreach ( $sites as $site ) { |
| 6360 | 4794 | $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; |
| 6361 | 4795 | foreach ( $list_names as $list_name ) { |
| 6362 | - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() ); | |
| 4796 | + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() ); | |
| 6363 | 4797 | $list_changed = false; |
| 6364 | 4798 | foreach ( $user_list as $key => $user ) { |
| 6365 | - if ( 0 === strcasecmp( $user['email'], $approved_user['email'] ) ) { | |
| 6366 | - unset( $user_list[ $key ] ); | |
| 4799 | + if ( $user['email'] == $approved_user['email'] ) { | |
| 4800 | + unset( $user_list[$key] ); | |
| 6367 | 4801 | $list_changed = true; |
| 6368 | 4802 | } |
| 6369 | 4803 | } |
| 6370 | 4804 | if ( $list_changed ) { |
| @@ -6372,45 +4806,32 @@ | ||
| 6372 | 4806 | } |
| 6373 | 4807 | } |
| 6374 | 4808 | } |
| 6375 | 4809 | } |
| 6376 | - } elseif ( 'remove' === $approved_user['edit_action'] ) { // Remove user from approved list and save (also remove their role if they have a WordPress account). | |
| 6377 | - if ( 'false' !== $approved_user['multisite_user'] ) { | |
| 4810 | + | |
| 4811 | + // Remove user from approved list and save | |
| 4812 | + } elseif ( $approved_user['edit_action'] === 'remove' ) { | |
| 4813 | + if ( $approved_user['multisite_user'] !== 'false' ) { | |
| 6378 | 4814 | if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) { |
| 6379 | 4815 | $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( |
| 6380 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 4816 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 6381 | 4817 | ); |
| 6382 | 4818 | foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) { |
| 6383 | - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) { | |
| 6384 | - // Remove role of the associated WordPress user from all blogs (but don't delete the user). | |
| 6385 | - $user = get_user_by( 'email', $approved_user['email'] ); | |
| 6386 | - if ( false !== $user ) { | |
| 6387 | - // Loop through all of the blogs this user is a member of and remove their capabilities. | |
| 6388 | - foreach ( get_blogs_of_user( $user->ID ) as $blog ) { | |
| 6389 | - remove_user_from_blog( $user->ID, $blog->userblog_id, '' ); | |
| 6390 | - } | |
| 6391 | - } | |
| 6392 | - // Remove entry from Approved Users list. | |
| 6393 | - unset( $auth_multisite_settings_access_users_approved[ $key ] ); | |
| 4819 | + if ( $approved_user['email'] == $existing_user['email'] ) { | |
| 4820 | + unset( $auth_multisite_settings_access_users_approved[$key] ); | |
| 6394 | 4821 | break; |
| 6395 | 4822 | } |
| 6396 | 4823 | } |
| 6397 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 4824 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 6398 | 4825 | } |
| 6399 | 4826 | } else { |
| 6400 | 4827 | if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) { |
| 6401 | 4828 | $auth_settings_access_users_approved = $this->sanitize_user_list( |
| 6402 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4829 | + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) | |
| 6403 | 4830 | ); |
| 6404 | 4831 | foreach ( $auth_settings_access_users_approved as $key => $existing_user ) { |
| 6405 | - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) { | |
| 6406 | - // Remove role of the associated WordPress user (but don't delete the user). | |
| 6407 | - $user = get_user_by( 'email', $approved_user['email'] ); | |
| 6408 | - if ( false !== $user ) { | |
| 6409 | - $user->set_role( '' ); | |
| 6410 | - } | |
| 6411 | - // Remove entry from Approved Users list. | |
| 6412 | - unset( $auth_settings_access_users_approved[ $key ] ); | |
| 4832 | + if ( $approved_user['email'] == $existing_user['email'] ) { | |
| 4833 | + unset( $auth_settings_access_users_approved[$key] ); | |
| 6413 | 4834 | break; |
| 6414 | 4835 | } |
| 6415 | 4836 | } |
| 6416 | 4837 | update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); |
| @@ -6415,12 +4836,14 @@ | ||
| 6415 | 4836 | } |
| 6416 | 4837 | update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); |
| 6417 | 4838 | } |
| 6418 | 4839 | } |
| 6419 | - } elseif ( 'change_role' === $approved_user['edit_action'] ) { // Update user's role in WordPress. | |
| 4840 | + | |
| 4841 | + // Update user's role in WordPress | |
| 4842 | + } elseif ( $approved_user['edit_action'] === 'change_role' ) { | |
| 6420 | 4843 | $changed_user = get_user_by( 'email', $approved_user['email'] ); |
| 6421 | 4844 | if ( $changed_user ) { |
| 6422 | - if ( is_multisite() && 'false' !== $approved_user['multisite_user'] ) { | |
| 4845 | + if ( is_multisite() && $approved_user['multisite_user'] !== 'false' ) { | |
| 6423 | 4846 | foreach ( get_blogs_of_user( $changed_user->ID ) as $blog ) { |
| 6424 | 4847 | add_user_to_blog( $blog->userblog_id, $changed_user->ID, $approved_user['role'] ); |
| 6425 | 4848 | } |
| 6426 | 4849 | } else { |
| @@ -6427,30 +4850,30 @@ | ||
| 6427 | 4850 | $changed_user->set_role( $approved_user['role'] ); |
| 6428 | 4851 | } |
| 6429 | 4852 | } |
| 6430 | 4853 | |
| 6431 | - if ( 'false' !== $approved_user['multisite_user'] ) { | |
| 4854 | + if ( $approved_user['multisite_user'] !== 'false' ) { | |
| 6432 | 4855 | if ( $this->is_email_in_list( $approved_user['email'], 'approved', 'multisite' ) ) { |
| 6433 | 4856 | $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( |
| 6434 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 4857 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 6435 | 4858 | ); |
| 6436 | 4859 | foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) { |
| 6437 | - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) { | |
| 6438 | - $auth_multisite_settings_access_users_approved[ $key ]['role'] = $approved_user['role']; | |
| 4860 | + if ( $approved_user['email'] == $existing_user['email'] ) { | |
| 4861 | + $auth_multisite_settings_access_users_approved[$key]['role'] = $approved_user['role']; | |
| 6439 | 4862 | break; |
| 6440 | 4863 | } |
| 6441 | 4864 | } |
| 6442 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 4865 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 6443 | 4866 | } |
| 6444 | 4867 | } else { |
| 6445 | 4868 | // Update user's role in approved list and save. |
| 6446 | 4869 | if ( $this->is_email_in_list( $approved_user['email'], 'approved' ) ) { |
| 6447 | 4870 | $auth_settings_access_users_approved = $this->sanitize_user_list( |
| 6448 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4871 | + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ) | |
| 6449 | 4872 | ); |
| 6450 | 4873 | foreach ( $auth_settings_access_users_approved as $key => $existing_user ) { |
| 6451 | - if ( 0 === strcasecmp( $approved_user['email'], $existing_user['email'] ) ) { | |
| 6452 | - $auth_settings_access_users_approved[ $key ]['role'] = $approved_user['role']; | |
| 4874 | + if ( $approved_user['email'] == $existing_user['email'] ) { | |
| 4875 | + $auth_settings_access_users_approved[$key]['role'] = $approved_user['role']; | |
| 6453 | 4876 | break; |
| 6454 | 4877 | } |
| 6455 | 4878 | } |
| 6456 | 4879 | update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); |
| @@ -6455,28 +4878,28 @@ | ||
| 6455 | 4878 | } |
| 6456 | 4879 | update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); |
| 6457 | 4880 | } |
| 6458 | 4881 | } |
| 4882 | + | |
| 6459 | 4883 | } |
| 6460 | 4884 | } |
| 6461 | 4885 | } |
| 6462 | 4886 | |
| 6463 | 4887 | // Editing a blocked list entry. |
| 6464 | - if ( 'access_users_blocked' === $_POST['setting'] ) { | |
| 6465 | - // Sanitize post data. | |
| 6466 | - $access_users_blocked = array(); | |
| 6467 | - if ( isset( $_POST['access_users_blocked'] ) && is_array( $_POST['access_users_blocked'] ) ) { | |
| 6468 | - $access_users_blocked = $this->sanitize_update_auth_users( wp_unslash( $_POST['access_users_blocked'] ) ); | |
| 4888 | + if ( $_POST['setting'] === 'access_users_blocked' ) { | |
| 4889 | + // Initialize posted data if empty. | |
| 4890 | + if ( ! ( array_key_exists( 'access_users_blocked', $_POST ) && is_array( $_POST['access_users_blocked'] ) ) ) { | |
| 4891 | + $_POST['access_users_blocked'] = array(); | |
| 6469 | 4892 | } |
| 6470 | 4893 | |
| 6471 | 4894 | // Deal with each modified user (add or remove). |
| 6472 | - foreach ( $access_users_blocked as $blocked_user ) { | |
| 4895 | + foreach ( $_POST['access_users_blocked'] as $blocked_user ) { | |
| 6473 | 4896 | |
| 6474 | - if ( 'add' === $blocked_user['edit_action'] ) { | |
| 4897 | + if ( $blocked_user['edit_action'] === 'add' ) { | |
| 6475 | 4898 | |
| 6476 | 4899 | // Add auth_blocked usermeta for the user. |
| 6477 | 4900 | $blocked_wp_user = get_user_by( 'email', $blocked_user['email'] ); |
| 6478 | - if ( false !== $blocked_wp_user ) { | |
| 4901 | + if ( $blocked_wp_user !== false ) { | |
| 6479 | 4902 | update_user_meta( $blocked_wp_user->ID, 'auth_blocked', 'yes' ); |
| 6480 | 4903 | } |
| 6481 | 4904 | |
| 6482 | 4905 | // Add new user to blocked list and save (skip if it's |
| @@ -6482,113 +4905,48 @@ | ||
| 6482 | 4905 | // Add new user to blocked list and save (skip if it's |
| 6483 | 4906 | // already there--someone else might have just done it). |
| 6484 | 4907 | if ( ! $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) { |
| 6485 | 4908 | $auth_settings_access_users_blocked = $this->sanitize_user_list( |
| 6486 | - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4909 | + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ) | |
| 6487 | 4910 | ); |
| 6488 | - $blocked_user['date_added'] = date( 'M Y' ); | |
| 4911 | + $blocked_user['date_added'] = date( 'M Y' ); | |
| 6489 | 4912 | array_push( $auth_settings_access_users_blocked, $blocked_user ); |
| 6490 | 4913 | update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked ); |
| 6491 | - } else { | |
| 6492 | - $invalid_emails[] = $blocked_user['email']; | |
| 6493 | 4914 | } |
| 6494 | - } elseif ( 'remove' === $blocked_user['edit_action'] ) { | |
| 6495 | 4915 | |
| 4916 | + } elseif ( $blocked_user['edit_action'] === 'remove' ) { | |
| 4917 | + | |
| 6496 | 4918 | // Remove auth_blocked usermeta for the user. |
| 6497 | 4919 | $unblocked_user = get_user_by( 'email', $blocked_user['email'] ); |
| 6498 | - if ( false !== $unblocked_user ) { | |
| 4920 | + if ( $unblocked_user !== false ) { | |
| 6499 | 4921 | delete_user_meta( $unblocked_user->ID, 'auth_blocked', 'yes' ); |
| 6500 | 4922 | } |
| 6501 | 4923 | |
| 6502 | - // Remove user from blocked list and save. | |
| 4924 | + // Remove user from blocked list and save | |
| 6503 | 4925 | if ( $this->is_email_in_list( $blocked_user['email'], 'blocked' ) ) { |
| 6504 | 4926 | $auth_settings_access_users_blocked = $this->sanitize_user_list( |
| 6505 | - $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ) | |
| 4927 | + $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ) | |
| 6506 | 4928 | ); |
| 6507 | 4929 | foreach ( $auth_settings_access_users_blocked as $key => $existing_user ) { |
| 6508 | - if ( 0 === strcasecmp( $blocked_user['email'], $existing_user['email'] ) ) { | |
| 6509 | - unset( $auth_settings_access_users_blocked[ $key ] ); | |
| 4930 | + if ( $blocked_user['email'] == $existing_user['email'] ) { | |
| 4931 | + unset( $auth_settings_access_users_blocked[$key] ); | |
| 6510 | 4932 | break; |
| 6511 | 4933 | } |
| 6512 | 4934 | } |
| 6513 | 4935 | update_option( 'auth_settings_access_users_blocked', $auth_settings_access_users_blocked ); |
| 6514 | 4936 | } |
| 4937 | + | |
| 6515 | 4938 | } |
| 6516 | 4939 | } |
| 6517 | 4940 | } |
| 6518 | 4941 | |
| 6519 | - // Send response to client. | |
| 6520 | - $response = array( | |
| 6521 | - 'success' => true, | |
| 6522 | - 'invalid_emails' => $invalid_emails, | |
| 6523 | - ); | |
| 6524 | - header( 'content-type: application/json' ); | |
| 6525 | - echo wp_json_encode( $response ); | |
| 6526 | - exit; | |
| 4942 | + // Return 'success' value to AJAX call. | |
| 4943 | + die( 'success' ); | |
| 6527 | 4944 | } |
| 6528 | 4945 | |
| 6529 | 4946 | |
| 6530 | - /** | |
| 6531 | - * Sanitizes an array of user update commands coming from the AJAX handler in Authorizer Settings. | |
| 6532 | - * | |
| 6533 | - * Example $users array: | |
| 6534 | - * array( | |
| 6535 | - * array( | |
| 6536 | - * edit_action: 'add' or 'remove' or 'change_role', | |
| 6537 | - * email: 'johndoe@example.com', | |
| 6538 | - * role: 'subscriber', | |
| 6539 | - * date_added: 'Jun 2014', | |
| 6540 | - * local_user: 'true' or 'false', | |
| 6541 | - * multisite_user: 'true' or 'false', | |
| 6542 | - * ), | |
| 6543 | - * ... | |
| 6544 | - * ) | |
| 6545 | - * | |
| 6546 | - * @param array $users Users to edit. | |
| 6547 | - * @return array Sanitized users to edit. | |
| 6548 | - */ | |
| 6549 | - private function sanitize_update_auth_users( $users = array() ) { | |
| 6550 | - if ( ! is_array( $users ) ) { | |
| 6551 | - $users = array(); | |
| 6552 | - } | |
| 6553 | - $users = array_map( array( $this, 'sanitize_update_auth_user' ), $users ); | |
| 6554 | 4947 | |
| 6555 | - return $users; | |
| 6556 | - } | |
| 6557 | - | |
| 6558 | - | |
| 6559 | 4948 | /** |
| 6560 | - * Callback for array_map in sanitize_update_auth_users(). | |
| 6561 | - * | |
| 6562 | - * @param array $user User data to sanitize. | |
| 6563 | - * @return array Sanitized user data. | |
| 6564 | - */ | |
| 6565 | - private function sanitize_update_auth_user( $user ) { | |
| 6566 | - if ( array_key_exists( 'edit_action', $user ) ) { | |
| 6567 | - $user['edit_action'] = sanitize_text_field( $user['edit_action'] ); | |
| 6568 | - } | |
| 6569 | - if ( isset( $user['email'] ) ) { | |
| 6570 | - $user['email'] = sanitize_email( $user['email'] ); | |
| 6571 | - } | |
| 6572 | - if ( isset( $user['role'] ) ) { | |
| 6573 | - $user['role'] = sanitize_text_field( $user['role'] ); | |
| 6574 | - } | |
| 6575 | - if ( isset( $user['date_added'] ) ) { | |
| 6576 | - $user['date_added'] = sanitize_text_field( $user['date_added'] ); | |
| 6577 | - } | |
| 6578 | - if ( isset( $user['local_user'] ) ) { | |
| 6579 | - $user['local_user'] = 'true' === $user['local_user'] ? 'true' : 'false'; | |
| 6580 | - } | |
| 6581 | - if ( isset( $user['multisite_user'] ) ) { | |
| 6582 | - $user['multisite_user'] = 'true' === $user['multisite_user'] ? 'true' : 'false'; | |
| 6583 | - } | |
| 6584 | - | |
| 6585 | - return $user; | |
| 6586 | - } | |
| 6587 | - | |
| 6588 | - | |
| 6589 | - | |
| 6590 | - /** | |
| 6591 | 4949 | * *************************** |
| 6592 | 4950 | * Helper functions |
| 6593 | 4951 | * *************************** |
| 6594 | 4952 | */ |
| @@ -6596,20 +4954,20 @@ | ||
| 6596 | 4954 | |
| 6597 | 4955 | /** |
| 6598 | 4956 | * Retrieves a specific plugin option from db. Multisite enabled. |
| 6599 | 4957 | * |
| 6600 | - * @param string $option Option name. | |
| 6601 | - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value. | |
| 6602 | - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists. | |
| 6603 | - * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page. | |
| 6604 | - * @return mixed Option value, or null on failure. | |
| 4958 | + * @param string $option Option name | |
| 4959 | + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value | |
| 4960 | + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists | |
| 4961 | + * @param string $print_mode 'print overlay' will output overlay that hides this option on the settings page | |
| 4962 | + * @return mixed Option value, or null on failure | |
| 6605 | 4963 | */ |
| 6606 | - private function get_plugin_option( $option, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override', $print_mode = 'no overlay' ) { | |
| 4964 | + private function get_plugin_option( $option, $admin_mode = SINGLE_ADMIN, $override_mode = 'no override', $print_mode = 'no overlay' ) { | |
| 6607 | 4965 | // Special case for user lists (they are saved seperately to prevent concurrency issues). |
| 6608 | - if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ), true ) ) { | |
| 6609 | - $list = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings_' . $option ); | |
| 6610 | - if ( is_multisite() && WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) { | |
| 6611 | - $list = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_' . $option, array() ); | |
| 4966 | + if ( in_array( $option, array( 'access_users_pending', 'access_users_approved', 'access_users_blocked' ) ) ) { | |
| 4967 | + $list = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings_' . $option ); | |
| 4968 | + if ( is_multisite() && $admin_mode === MULTISITE_ADMIN ) { | |
| 4969 | + $list = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_' . $option, array() ); | |
| 6612 | 4970 | } |
| 6613 | 4971 | return $list; |
| 6614 | 4972 | } |
| 6615 | 4973 | |
| @@ -6623,26 +4981,24 @@ | ||
| 6623 | 4981 | |
| 6624 | 4982 | // If requested and appropriate, print the overlay hiding the |
| 6625 | 4983 | // single site option that is overridden by a multisite option. |
| 6626 | 4984 | if ( |
| 6627 | - WP_Plugin_Authorizer::NETWORK_CONTEXT !== $admin_mode && | |
| 6628 | - 'allow override' === $override_mode && | |
| 6629 | - 'print overlay' === $print_mode && | |
| 4985 | + $admin_mode !== MULTISITE_ADMIN && | |
| 4986 | + $override_mode === 'allow override' && | |
| 4987 | + $print_mode === 'print overlay' && | |
| 6630 | 4988 | array_key_exists( 'multisite_override', $auth_settings ) && |
| 6631 | - '1' === $auth_settings['multisite_override'] && | |
| 6632 | - ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) ) | |
| 4989 | + $auth_settings['multisite_override'] === '1' && | |
| 4990 | + ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' ) | |
| 6633 | 4991 | ) { |
| 6634 | 4992 | // Get original plugin options (not overridden value). We'll |
| 6635 | 4993 | // show this old value behind the disabled overlay. |
| 6636 | - // $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' ); | |
| 6637 | - // (This feature is disabled). | |
| 6638 | - // | |
| 4994 | + $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' ); | |
| 4995 | + | |
| 6639 | 4996 | $name = "auth_settings[$option]"; |
| 6640 | - $id = "auth_settings_$option"; | |
| 6641 | - ?> | |
| 6642 | - <div id="overlay-hide-auth_settings_<?php echo esc_attr( $option ); ?>" class="auth_multisite_override_overlay"> | |
| 4997 | + $id = "auth_settings_$option"; ?> | |
| 4998 | + <div id="overlay-hide-auth_settings_<?php echo $option; ?>" class="auth_multisite_override_overlay"> | |
| 6643 | 4999 | <span class="overlay-note"> |
| 6644 | - <?php esc_html_e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo esc_attr( network_admin_url( 'admin.php?page=authorizer' ) ); ?>"><?php esc_html_e( 'multisite option', 'authorizer' ); ?></a>. | |
| 5000 | + <?php _e( 'This setting is overridden by a', 'authorizer' ); ?> <a href="<?php echo network_admin_url( 'admin.php?page=authorizer&tab=external' ); ?>"><?php _e( 'multisite option', 'authorizer' ); ?></a>. | |
| 6645 | 5001 | </span> |
| 6646 | 5002 | </div> |
| 6647 | 5003 | <?php |
| 6648 | 5004 | } |
| @@ -6648,9 +5004,9 @@ | ||
| 6648 | 5004 | } |
| 6649 | 5005 | |
| 6650 | 5006 | // If we're getting an option in a site that has overridden the multisite override, make |
| 6651 | 5007 | // sure we are returning the option value from that site (not the multisite value). |
| 6652 | - if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && 1 === intval( $auth_settings['advanced_override_multisite'] ) ) { | |
| 5008 | + if ( array_key_exists( 'advanced_override_multisite', $auth_settings ) && $auth_settings['advanced_override_multisite'] == '1' ) { | |
| 6653 | 5009 | $auth_settings = $this->get_plugin_options( $admin_mode, 'no override' ); |
| 6654 | 5010 | } |
| 6655 | 5011 | |
| 6656 | 5012 | // Set option to null if it wasn't found. |
| @@ -6657,115 +5013,98 @@ | ||
| 6657 | 5013 | if ( ! array_key_exists( $option, $auth_settings ) ) { |
| 6658 | 5014 | return null; |
| 6659 | 5015 | } |
| 6660 | 5016 | |
| 6661 | - return $auth_settings[ $option ]; | |
| 5017 | + return $auth_settings[$option]; | |
| 6662 | 5018 | } |
| 6663 | 5019 | |
| 6664 | 5020 | /** |
| 6665 | 5021 | * Retrieves all plugin options from db. Multisite enabled. |
| 6666 | 5022 | * |
| 6667 | - * @param string $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT will retrieve the multisite value. | |
| 6668 | - * @param string $override_mode 'allow override' will retrieve the multisite value if it exists. | |
| 6669 | - * @return mixed Option value, or null on failure. | |
| 5023 | + * @param string $admin_mode MULTISITE_ADMIN will retrieve the multisite value | |
| 5024 | + * @param string $override_mode 'allow override' will retrieve the multisite value if it exists | |
| 5025 | + * @return mixed Option value, or null on failure | |
| 6670 | 5026 | */ |
| 6671 | - private function get_plugin_options( $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT, $override_mode = 'no override' ) { | |
| 6672 | - // Grab plugin settings (skip if in WP_Plugin_Authorizer::NETWORK_CONTEXT mode). | |
| 6673 | - $auth_settings = WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ? array() : get_option( 'auth_settings' ); | |
| 5027 | + private function get_plugin_options( $admin_mode = SINGLE_ADMIN, $override_mode = 'no override' ) { | |
| 5028 | + // Grab plugin settings (skip if in MULTISITE_ADMIN mode). | |
| 5029 | + $auth_settings = $admin_mode === MULTISITE_ADMIN ? array() : get_option( 'auth_settings' ); | |
| 6674 | 5030 | |
| 6675 | 5031 | // Initialize to default values if the plugin option doesn't exist. |
| 6676 | - if ( false === $auth_settings ) { | |
| 5032 | + if ( $auth_settings === FALSE ) { | |
| 6677 | 5033 | $auth_settings = $this->set_default_options(); |
| 6678 | 5034 | } |
| 6679 | 5035 | |
| 6680 | 5036 | // Merge multisite options if we're in a network and the current site hasn't overridden multisite settings. |
| 6681 | - if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || 1 !== intval( $auth_settings['advanced_override_multisite'] ) ) ) { | |
| 5037 | + if ( is_multisite() && ( ! array_key_exists( 'advanced_override_multisite', $auth_settings ) || $auth_settings['advanced_override_multisite'] != '1' ) ) { | |
| 6682 | 5038 | // Get multisite options. |
| 6683 | - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() ); | |
| 5039 | + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); | |
| 6684 | 5040 | |
| 6685 | 5041 | // Return the multisite options if we're viewing the network admin options page. |
| 6686 | 5042 | // Otherwise override options with their multisite equivalents. |
| 6687 | - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) { | |
| 5043 | + if ( $admin_mode === MULTISITE_ADMIN ) { | |
| 6688 | 5044 | $auth_settings = $auth_multisite_settings; |
| 6689 | 5045 | } elseif ( |
| 6690 | - 'allow override' === $override_mode && | |
| 5046 | + $override_mode === 'allow override' && | |
| 6691 | 5047 | array_key_exists( 'multisite_override', $auth_multisite_settings ) && |
| 6692 | - '1' === $auth_multisite_settings['multisite_override'] | |
| 5048 | + $auth_multisite_settings['multisite_override'] === '1' | |
| 6693 | 5049 | ) { |
| 6694 | 5050 | // Keep track of the multisite override selection. |
| 6695 | 5051 | $auth_settings['multisite_override'] = $auth_multisite_settings['multisite_override']; |
| 6696 | 5052 | |
| 6697 | - /** | |
| 6698 | - * Note: the options below should be the complete list of overridden | |
| 6699 | - * options. It is *not* the complete list of all options (some options | |
| 6700 | - * don't have a multisite equivalent). | |
| 6701 | - */ | |
| 5053 | + // Note: the options below should be the complete list of | |
| 5054 | + // overridden options. It is *not* the complete list of all | |
| 5055 | + // options (some options don't have a multisite equivalent) | |
| 6702 | 5056 | |
| 6703 | - /** | |
| 6704 | - * Note: access_users_approved, access_users_pending, and | |
| 6705 | - * access_users_blocked do not get overridden. However, since | |
| 6706 | - * access_users_approved has a multisite equivalent, you must retrieve | |
| 6707 | - * them both seperately. This is done because the two lists should be | |
| 6708 | - * treated differently. | |
| 6709 | - * | |
| 6710 | - * $approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 6711 | - * $ms_approved_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 6712 | - */ | |
| 5057 | + // Note: access_users_approved, access_users_pending, and | |
| 5058 | + // access_users_blocked do not get overridden. However, | |
| 5059 | + // since access_users_approved has a multisite equivalent, | |
| 5060 | + // you must retrieve them both seperately. This is done | |
| 5061 | + // because the two lists should be treated differently. | |
| 5062 | + // $approved_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 5063 | + // $ms_approved_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ); | |
| 6713 | 5064 | |
| 6714 | - // Override external services (google, cas, or ldap) and associated options. | |
| 6715 | - $auth_settings['google'] = $auth_multisite_settings['google']; | |
| 6716 | - $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid']; | |
| 6717 | - $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret']; | |
| 6718 | - $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain']; | |
| 6719 | - $auth_settings['cas'] = $auth_multisite_settings['cas']; | |
| 6720 | - $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label']; | |
| 6721 | - $auth_settings['cas_host'] = $auth_multisite_settings['cas_host']; | |
| 6722 | - $auth_settings['cas_port'] = $auth_multisite_settings['cas_port']; | |
| 6723 | - $auth_settings['cas_path'] = $auth_multisite_settings['cas_path']; | |
| 6724 | - $auth_settings['cas_version'] = $auth_multisite_settings['cas_version']; | |
| 6725 | - $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email']; | |
| 6726 | - $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name']; | |
| 6727 | - $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name']; | |
| 6728 | - $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login']; | |
| 6729 | - $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login']; | |
| 6730 | - $auth_settings['ldap'] = $auth_multisite_settings['ldap']; | |
| 6731 | - $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host']; | |
| 6732 | - $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port']; | |
| 6733 | - $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls']; | |
| 6734 | - $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base']; | |
| 6735 | - $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid']; | |
| 6736 | - $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email']; | |
| 6737 | - $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user']; | |
| 6738 | - $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password']; | |
| 6739 | - $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url']; | |
| 6740 | - $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name']; | |
| 6741 | - $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name']; | |
| 5065 | + // Override external services (google, cas, or ldap) and associated options | |
| 5066 | + $auth_settings['google'] = $auth_multisite_settings['google']; | |
| 5067 | + $auth_settings['google_clientid'] = $auth_multisite_settings['google_clientid']; | |
| 5068 | + $auth_settings['google_clientsecret'] = $auth_multisite_settings['google_clientsecret']; | |
| 5069 | + $auth_settings['google_hosteddomain'] = $auth_multisite_settings['google_hosteddomain']; | |
| 5070 | + $auth_settings['cas'] = $auth_multisite_settings['cas']; | |
| 5071 | + $auth_settings['cas_custom_label'] = $auth_multisite_settings['cas_custom_label']; | |
| 5072 | + $auth_settings['cas_host'] = $auth_multisite_settings['cas_host']; | |
| 5073 | + $auth_settings['cas_port'] = $auth_multisite_settings['cas_port']; | |
| 5074 | + $auth_settings['cas_path'] = $auth_multisite_settings['cas_path']; | |
| 5075 | + $auth_settings['cas_version'] = $auth_multisite_settings['cas_version']; | |
| 5076 | + $auth_settings['cas_attr_email'] = $auth_multisite_settings['cas_attr_email']; | |
| 5077 | + $auth_settings['cas_attr_first_name'] = $auth_multisite_settings['cas_attr_first_name']; | |
| 5078 | + $auth_settings['cas_attr_last_name'] = $auth_multisite_settings['cas_attr_last_name']; | |
| 5079 | + $auth_settings['cas_attr_update_on_login'] = $auth_multisite_settings['cas_attr_update_on_login']; | |
| 5080 | + $auth_settings['cas_auto_login'] = $auth_multisite_settings['cas_auto_login']; | |
| 5081 | + $auth_settings['ldap'] = $auth_multisite_settings['ldap']; | |
| 5082 | + $auth_settings['ldap_host'] = $auth_multisite_settings['ldap_host']; | |
| 5083 | + $auth_settings['ldap_port'] = $auth_multisite_settings['ldap_port']; | |
| 5084 | + $auth_settings['ldap_tls'] = $auth_multisite_settings['ldap_tls']; | |
| 5085 | + $auth_settings['ldap_search_base'] = $auth_multisite_settings['ldap_search_base']; | |
| 5086 | + $auth_settings['ldap_uid'] = $auth_multisite_settings['ldap_uid']; | |
| 5087 | + $auth_settings['ldap_attr_email'] = $auth_multisite_settings['ldap_attr_email']; | |
| 5088 | + $auth_settings['ldap_user'] = $auth_multisite_settings['ldap_user']; | |
| 5089 | + $auth_settings['ldap_password'] = $auth_multisite_settings['ldap_password']; | |
| 5090 | + $auth_settings['ldap_lostpassword_url'] = $auth_multisite_settings['ldap_lostpassword_url']; | |
| 5091 | + $auth_settings['ldap_attr_first_name'] = $auth_multisite_settings['ldap_attr_first_name']; | |
| 5092 | + $auth_settings['ldap_attr_last_name'] = $auth_multisite_settings['ldap_attr_last_name']; | |
| 6742 | 5093 | $auth_settings['ldap_attr_update_on_login'] = $auth_multisite_settings['ldap_attr_update_on_login']; |
| 6743 | 5094 | |
| 6744 | - // Override access_who_can_login and access_who_can_view. | |
| 5095 | + // Override access_who_can_login and access_who_can_view | |
| 6745 | 5096 | $auth_settings['access_who_can_login'] = $auth_multisite_settings['access_who_can_login']; |
| 6746 | - $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view']; | |
| 5097 | + $auth_settings['access_who_can_view'] = $auth_multisite_settings['access_who_can_view']; | |
| 6747 | 5098 | |
| 6748 | - // Override access_default_role. | |
| 5099 | + // Override access_default_role | |
| 6749 | 5100 | $auth_settings['access_default_role'] = $auth_multisite_settings['access_default_role']; |
| 6750 | 5101 | |
| 6751 | - // Override lockouts. | |
| 5102 | + // Override lockouts | |
| 6752 | 5103 | $auth_settings['advanced_lockouts'] = $auth_multisite_settings['advanced_lockouts']; |
| 6753 | 5104 | |
| 6754 | - // Override Hide WordPress login. | |
| 5105 | + // Override Hide WordPress login | |
| 6755 | 5106 | $auth_settings['advanced_hide_wp_login'] = $auth_multisite_settings['advanced_hide_wp_login']; |
| 6756 | - | |
| 6757 | - // Override Users per page. | |
| 6758 | - $auth_settings['advanced_users_per_page'] = $auth_multisite_settings['advanced_users_per_page']; | |
| 6759 | - | |
| 6760 | - // Override Sort users by. | |
| 6761 | - $auth_settings['advanced_users_sort_by'] = $auth_multisite_settings['advanced_users_sort_by']; | |
| 6762 | - | |
| 6763 | - // Override Sort users order. | |
| 6764 | - $auth_settings['advanced_users_sort_order'] = $auth_multisite_settings['advanced_users_sort_order']; | |
| 6765 | - | |
| 6766 | - // Override Show Dashboard Widget. | |
| 6767 | - $auth_settings['advanced_widget_enabled'] = $auth_multisite_settings['advanced_widget_enabled']; | |
| 6768 | 5107 | } |
| 6769 | 5108 | } |
| 6770 | 5109 | return $auth_settings; |
| 6771 | 5110 | } |
| @@ -6772,27 +5111,23 @@ | ||
| 6772 | 5111 | |
| 6773 | 5112 | |
| 6774 | 5113 | /** |
| 6775 | 5114 | * Remove user from authorizer lists when that user is deleted in WordPress. |
| 6776 | - * | |
| 6777 | - * Action: delete_user | |
| 6778 | - * | |
| 6779 | - * @param int $user_id User ID to remove. | |
| 6780 | - * @return void | |
| 5115 | + * Run on action hook: delete_user | |
| 6781 | 5116 | */ |
| 6782 | - public function remove_user_from_authorizer_when_deleted( $user_id ) { | |
| 6783 | - $user = get_user_by( 'id', $user_id ); | |
| 5117 | + function remove_user_from_authorizer_when_deleted( $user_id ) { | |
| 5118 | + $user = get_user_by( 'id', $user_id ); | |
| 6784 | 5119 | $deleted_email = $user->user_email; |
| 6785 | 5120 | |
| 6786 | 5121 | // Remove user from pending/approved lists and save. |
| 6787 | 5122 | $list_names = array( 'access_users_pending', 'access_users_approved' ); |
| 6788 | 5123 | foreach ( $list_names as $list_name ) { |
| 6789 | - $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, WP_Plugin_Authorizer::SINGLE_CONTEXT ) ); | |
| 5124 | + $user_list = $this->sanitize_user_list( $this->get_plugin_option( $list_name, SINGLE_ADMIN ) ); | |
| 6790 | 5125 | $list_changed = false; |
| 6791 | 5126 | foreach ( $user_list as $key => $existing_user ) { |
| 6792 | - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) { | |
| 5127 | + if ( $deleted_email === $existing_user['email'] ) { | |
| 6793 | 5128 | $list_changed = true; |
| 6794 | - unset( $user_list[ $key ] ); | |
| 5129 | + unset( $user_list[$key] ); | |
| 6795 | 5130 | } |
| 6796 | 5131 | } |
| 6797 | 5132 | if ( $list_changed ) { |
| 6798 | 5133 | update_option( 'auth_settings_' . $list_name, $user_list ); |
| @@ -6802,35 +5137,30 @@ | ||
| 6802 | 5137 | |
| 6803 | 5138 | |
| 6804 | 5139 | /** |
| 6805 | 5140 | * Remove multisite user from authorizer lists when that user is deleted from Network Users. |
| 6806 | - * | |
| 6807 | - * Action: wpmu_delete_user | |
| 6808 | - * | |
| 6809 | - * @param int $user_id User ID to remove. | |
| 6810 | - * @return void | |
| 5141 | + * Run on action hook: wpmu_delete_user | |
| 6811 | 5142 | */ |
| 6812 | - public function remove_network_user_from_authorizer_when_deleted( $user_id ) { | |
| 6813 | - $user = get_user_by( 'id', $user_id ); | |
| 5143 | + function remove_network_user_from_authorizer_when_deleted( $user_id ) { | |
| 5144 | + $user = get_user_by( 'id', $user_id ); | |
| 6814 | 5145 | $deleted_email = $user->user_email; |
| 6815 | 5146 | |
| 6816 | 5147 | // Go through multisite approved user list and remove this user. |
| 6817 | 5148 | $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( |
| 6818 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 5149 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 6819 | 5150 | ); |
| 6820 | - $list_changed = false; | |
| 5151 | + $list_changed = false; | |
| 6821 | 5152 | foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) { |
| 6822 | - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) { | |
| 5153 | + if ( $deleted_email === $existing_user['email'] ) { | |
| 6823 | 5154 | $list_changed = true; |
| 6824 | - unset( $auth_multisite_settings_access_users_approved[ $key ] ); | |
| 5155 | + unset( $auth_multisite_settings_access_users_approved[$key] ); | |
| 6825 | 5156 | } |
| 6826 | 5157 | } |
| 6827 | 5158 | if ( $list_changed ) { |
| 6828 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 5159 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 6829 | 5160 | } |
| 6830 | 5161 | |
| 6831 | 5162 | // Go through all pending/approved lists on individual sites and remove this user from them. |
| 6832 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 6833 | 5163 | $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); |
| 6834 | 5164 | foreach ( $sites as $site ) { |
| 6835 | 5165 | $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; |
| 6836 | 5166 | $this->remove_network_user_from_site_when_removed( $user_id, $blog_id ); |
| @@ -6840,27 +5170,22 @@ | ||
| 6840 | 5170 | |
| 6841 | 5171 | |
| 6842 | 5172 | /** |
| 6843 | 5173 | * Remove multisite user from a specific site's lists when that user is removed from the site. |
| 6844 | - * | |
| 6845 | - * Action: remove_user_from_blog | |
| 6846 | - * | |
| 6847 | - * @param int $user_id User ID to remove. | |
| 6848 | - * @param int $blog_id Blog ID to remove from. | |
| 6849 | - * @return void | |
| 5174 | + * Run on action hook: remove_user_from_blog | |
| 6850 | 5175 | */ |
| 6851 | - public function remove_network_user_from_site_when_removed( $user_id, $blog_id ) { | |
| 6852 | - $user = get_user_by( 'id', $user_id ); | |
| 5176 | + function remove_network_user_from_site_when_removed( $user_id, $blog_id ) { | |
| 5177 | + $user = get_user_by( 'id', $user_id ); | |
| 6853 | 5178 | $deleted_email = $user->user_email; |
| 6854 | 5179 | |
| 6855 | 5180 | $list_names = array( 'access_users_pending', 'access_users_approved' ); |
| 6856 | 5181 | foreach ( $list_names as $list_name ) { |
| 6857 | - $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() ); | |
| 5182 | + $user_list = get_blog_option( $blog_id, 'auth_settings_' . $list_name, array() ); | |
| 6858 | 5183 | $list_changed = false; |
| 6859 | 5184 | foreach ( $user_list as $key => $existing_user ) { |
| 6860 | - if ( 0 === strcasecmp( $deleted_email, $existing_user['email'] ) ) { | |
| 5185 | + if ( $deleted_email === $existing_user['email'] ) { | |
| 6861 | 5186 | $list_changed = true; |
| 6862 | - unset( $user_list[ $key ] ); | |
| 5187 | + unset( $user_list[$key] ); | |
| 6863 | 5188 | } |
| 6864 | 5189 | } |
| 6865 | 5190 | if ( $list_changed ) { |
| 6866 | 5191 | update_blog_option( $blog_id, 'auth_settings_' . $list_name, $user_list ); |
| @@ -6870,30 +5195,26 @@ | ||
| 6870 | 5195 | |
| 6871 | 5196 | |
| 6872 | 5197 | /** |
| 6873 | 5198 | * Helper: Add multisite user to a specific site's approved list. |
| 6874 | - * | |
| 6875 | - * @param int $user_id User ID to add. | |
| 6876 | - * @param int $blog_id Blog ID to add to. | |
| 6877 | - * @return void | |
| 6878 | 5199 | */ |
| 6879 | - private function add_network_user_to_site( $user_id, $blog_id ) { | |
| 5200 | + function add_network_user_to_site( $user_id, $blog_id ) { | |
| 6880 | 5201 | // Switch to blog. |
| 6881 | 5202 | switch_to_blog( $blog_id ); |
| 6882 | 5203 | |
| 6883 | 5204 | // Get user details and role. |
| 6884 | - $access_default_role = $this->get_plugin_option( 'access_default_role', WP_Plugin_Authorizer::SINGLE_CONTEXT, 'allow override' ); | |
| 6885 | - $user = get_user_by( 'id', $user_id ); | |
| 6886 | - $user_email = $user->user_email; | |
| 6887 | - $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role; | |
| 5205 | + $access_default_role = $this->get_plugin_option( 'access_default_role', SINGLE_ADMIN, 'allow override' ); | |
| 5206 | + $user = get_user_by( 'id', $user_id ); | |
| 5207 | + $user_email = $user->user_email; | |
| 5208 | + $user_role = $user && is_array( $user->roles ) && count( $user->roles ) > 0 ? $user->roles[0] : $access_default_role; | |
| 6888 | 5209 | |
| 6889 | 5210 | // Add user to approved list if not already there and not in blocked list. |
| 6890 | - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 6891 | - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 5211 | + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 5212 | + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ); | |
| 6892 | 5213 | if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) && ! $this->in_multi_array( $user_email, $auth_settings_access_users_blocked ) ) { |
| 6893 | 5214 | $approved_user = array( |
| 6894 | - 'email' => $this->lowercase( $user_email ), | |
| 6895 | - 'role' => $user_role, | |
| 5215 | + 'email' => $user_email, | |
| 5216 | + 'role' => $user_role, | |
| 6896 | 5217 | 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ), |
| 6897 | 5218 | 'local_user' => true, |
| 6898 | 5219 | ); |
| 6899 | 5220 | array_push( $auth_settings_access_users_approved, $approved_user ); |
| @@ -6910,17 +5231,17 @@ | ||
| 6910 | 5231 | * When an existing user is invited to the current site (or a new user is created), |
| 6911 | 5232 | * add them to the authorizer approved list. This action fires when the admin |
| 6912 | 5233 | * doesn't select the "Skip Confirmation Email" option. |
| 6913 | 5234 | * |
| 6914 | - * Action: invite_user | |
| 5235 | + * @action invite_user | |
| 6915 | 5236 | * |
| 6916 | - * @param int $user_id The invited user's ID. | |
| 6917 | - * @param array $role The role of the invited user (or none if a new user creation). | |
| 5237 | + * @param int $user_id The invited user's ID. | |
| 5238 | + * @param array $role The role of the invited user (or none if a new user creation). | |
| 6918 | 5239 | * @param string $newuser_key The key of the invitation. |
| 6919 | 5240 | */ |
| 6920 | - public function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) { | |
| 5241 | + function add_existing_user_to_authorizer_when_created( $user_id, $role = array(), $newuser_key = '' ) { | |
| 6921 | 5242 | $user = get_user_by( 'id', $user_id ); |
| 6922 | - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles, $role ); | |
| 5243 | + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles, $role ); | |
| 6923 | 5244 | } |
| 6924 | 5245 | |
| 6925 | 5246 | |
| 6926 | 5247 | /** |
| @@ -6928,16 +5249,16 @@ | ||
| 6928 | 5249 | * When an existing user is invited to the current site (or a new user is created), |
| 6929 | 5250 | * add them to the authorizer approved list. This action fires when the admin |
| 6930 | 5251 | * selects the "Skip Confirmation Email" option. |
| 6931 | 5252 | * |
| 6932 | - * Action: added_existing_user | |
| 5253 | + * @action added_existing_user | |
| 6933 | 5254 | * |
| 6934 | - * @param int $user_id The invited user's ID. | |
| 6935 | - * @param mixed $result True on success or a WP_Error object if the user doesn't exist. | |
| 5255 | + * @param int $user_id The invited user's ID. | |
| 5256 | + * @param mixed $result True on success or a WP_Error object if the user doesn't exist. | |
| 6936 | 5257 | */ |
| 6937 | - public function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) { | |
| 5258 | + function add_existing_user_to_authorizer_when_created_noconfirmation( $user_id, $result ) { | |
| 6938 | 5259 | $user = get_user_by( 'id', $user_id ); |
| 6939 | - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles ); | |
| 5260 | + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles ); | |
| 6940 | 5261 | } |
| 6941 | 5262 | |
| 6942 | 5263 | |
| 6943 | 5264 | /** |
| @@ -6944,18 +5265,17 @@ | ||
| 6944 | 5265 | * Multisite: |
| 6945 | 5266 | * When a new user is invited to the current site (or a new user is created), |
| 6946 | 5267 | * add them to the authorizer approved list. |
| 6947 | 5268 | * |
| 6948 | - * Action: after_signup_user | |
| 5269 | + * @action after_signup_user | |
| 6949 | 5270 | * |
| 6950 | - * @param string $user User's requested login name. | |
| 5271 | + * @param string $user User's requested login name. | |
| 6951 | 5272 | * @param string $user_email User's email address. |
| 6952 | - * @param string $key User's activation key. | |
| 6953 | - * @param array $meta Additional signup meta, including initially set roles. | |
| 5273 | + * @param string $key User's activation key. | |
| 5274 | + * @param array $meta Additional signup meta. | |
| 6954 | 5275 | */ |
| 6955 | - public function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) { | |
| 6956 | - $user_roles = isset( $meta['new_role'] ) ? array( $meta['new_role'] ) : array(); | |
| 6957 | - $this->add_user_to_authorizer_when_created( $user_email, time(), $user_roles ); | |
| 5276 | + function add_new_user_to_authorizer_when_created( $user, $user_email, $key, $meta ) { | |
| 5277 | + $this->add_user_to_authorizer_when_created( $user_email, time() ); | |
| 6958 | 5278 | } |
| 6959 | 5279 | |
| 6960 | 5280 | |
| 6961 | 5281 | /** |
| @@ -6962,18 +5282,17 @@ | ||
| 6962 | 5282 | * Single site: |
| 6963 | 5283 | * When a new user is added in single site mode, add them to the authorizer |
| 6964 | 5284 | * approved list. |
| 6965 | 5285 | * |
| 6966 | - * Action: edit_user_created_user | |
| 5286 | + * @action edit_user_created_user | |
| 6967 | 5287 | * |
| 6968 | - * @param int $user_id ID of the newly created user. | |
| 6969 | - * @param string $notify Type of notification that should happen. See | |
| 6970 | - * wp_send_new_user_notifications() for more | |
| 6971 | - * information on possible values. | |
| 5288 | + * @param int $user_id ID of the newly created user. | |
| 5289 | + * @param string $notify Type of notification that should happen. See wp_send_new_user_notifications() | |
| 5290 | + * for more information on possible values. | |
| 6972 | 5291 | */ |
| 6973 | - public function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) { | |
| 5292 | + function add_new_user_to_authorizer_when_created_single_site( $user_id, $notify ) { | |
| 6974 | 5293 | $user = get_user_by( 'id', $user_id ); |
| 6975 | - $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->roles ); | |
| 5294 | + $this->add_user_to_authorizer_when_created( $user->user_email, $user->user_registered, $user->user_roles ); | |
| 6976 | 5295 | } |
| 6977 | 5296 | |
| 6978 | 5297 | |
| 6979 | 5298 | /** |
| @@ -6978,19 +5297,14 @@ | ||
| 6978 | 5297 | |
| 6979 | 5298 | /** |
| 6980 | 5299 | * Helper: When a new user is added/invited to the current site (or a new |
| 6981 | 5300 | * user is created), add them to the authorizer approved list. |
| 6982 | - * | |
| 6983 | - * @param string $user_email Email address of user to add. | |
| 6984 | - * @param string $date_registered Date user registered. | |
| 6985 | - * @param array $user_roles Role to add for user. | |
| 6986 | - * @param array $default_role Default role, if no role specified. | |
| 6987 | 5301 | */ |
| 6988 | 5302 | private function add_user_to_authorizer_when_created( $user_email, $date_registered, $user_roles = array(), $default_role = array() ) { |
| 6989 | - $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ) : array(); | |
| 6990 | - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 6991 | - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 6992 | - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 5303 | + $auth_multisite_settings_access_users_approved = is_multisite() ? get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', array() ) : array(); | |
| 5304 | + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ); | |
| 5305 | + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 5306 | + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ); | |
| 6993 | 5307 | |
| 6994 | 5308 | // Get default role if one isn't specified. |
| 6995 | 5309 | if ( count( $default_role ) < 1 ) { |
| 6996 | 5310 | $default_role = ''; |
| @@ -7005,10 +5319,10 @@ | ||
| 7005 | 5319 | return; |
| 7006 | 5320 | } |
| 7007 | 5321 | // Remove from pending list if there. |
| 7008 | 5322 | foreach ( $auth_settings_access_users_pending as $key => $pending_user ) { |
| 7009 | - if ( 0 === strcasecmp( $pending_user['email'], $user_email ) ) { | |
| 7010 | - unset( $auth_settings_access_users_pending[ $key ] ); | |
| 5323 | + if ( $pending_user['email'] == $user_email ) { | |
| 5324 | + unset( $auth_settings_access_users_pending[$key] ); | |
| 7011 | 5325 | $updated = true; |
| 7012 | 5326 | } |
| 7013 | 5327 | } |
| 7014 | 5328 | // Skip if user is in multisite approved list. |
| @@ -7017,10 +5331,10 @@ | ||
| 7017 | 5331 | } |
| 7018 | 5332 | // Add to approved list if not there. |
| 7019 | 5333 | if ( ! $this->in_multi_array( $user_email, $auth_settings_access_users_approved ) ) { |
| 7020 | 5334 | $approved_user = array( |
| 7021 | - 'email' => $this->lowercase( $user_email ), | |
| 7022 | - 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role, | |
| 5335 | + 'email' => $user_email, | |
| 5336 | + 'role' => is_array( $user_roles ) && count( $user_roles ) > 0 ? $user_roles[0] : $default_role, | |
| 7023 | 5337 | 'date_added' => date( 'M Y', strtotime( $date_registered ) ), |
| 7024 | 5338 | 'local_user' => true, |
| 7025 | 5339 | ); |
| 7026 | 5340 | array_push( $auth_settings_access_users_approved, $approved_user ); |
| @@ -7039,33 +5353,32 @@ | ||
| 7039 | 5353 | * When a user is granted super admin status (checkbox on network user edit |
| 7040 | 5354 | * screen), add them to the authorizer network approved list. Also remove |
| 7041 | 5355 | * them from pending/approved list on any individual sites. |
| 7042 | 5356 | * |
| 7043 | - * Action: grant_super_admin | |
| 5357 | + * @action grant_super_admin | |
| 7044 | 5358 | * |
| 7045 | 5359 | * @param int $user_id The user's ID. |
| 7046 | 5360 | */ |
| 7047 | - public function grant_super_admin__add_to_network_approved( $user_id ) { | |
| 7048 | - $user = get_user_by( 'id', $user_id ); | |
| 5361 | + function grant_super_admin__add_to_network_approved( $user_id ) { | |
| 5362 | + $user = get_user_by( 'id', $user_id ); | |
| 7049 | 5363 | $user_email = $user->user_email; |
| 7050 | 5364 | |
| 7051 | 5365 | // Add user to multisite approved user list (if not already there). |
| 7052 | 5366 | $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( |
| 7053 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 5367 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 7054 | 5368 | ); |
| 7055 | 5369 | if ( ! $this->in_multi_array( $user_email, $auth_multisite_settings_access_users_approved ) ) { |
| 7056 | 5370 | $multisite_approved_user = array( |
| 7057 | - 'email' => $this->lowercase( $user_email ), | |
| 7058 | - 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator', | |
| 5371 | + 'email' => $user_email, | |
| 5372 | + 'role' => count( $user->roles ) > 0 ? $user->roles[0] : 'administrator', | |
| 7059 | 5373 | 'date_added' => date( 'M Y', strtotime( $user->user_registered ) ), |
| 7060 | 5374 | 'local_user' => true, |
| 7061 | 5375 | ); |
| 7062 | 5376 | array_push( $auth_multisite_settings_access_users_approved, $multisite_approved_user ); |
| 7063 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 5377 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 7064 | 5378 | } |
| 7065 | 5379 | |
| 7066 | 5380 | // Go through all pending/approved lists on individual sites and remove this user from them. |
| 7067 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7068 | 5381 | $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); |
| 7069 | 5382 | foreach ( $sites as $site ) { |
| 7070 | 5383 | $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; |
| 7071 | 5384 | $this->remove_network_user_from_site_when_removed( $user_id, $blog_id ); |
| @@ -7078,29 +5391,29 @@ | ||
| 7078 | 5391 | * When a user's super admin status is revoked (checkbox on network user edit |
| 7079 | 5392 | * screen), remove them from the authorizer network approved list. Also add |
| 7080 | 5393 | * them to approved list on any individual sites they are already a part of. |
| 7081 | 5394 | * |
| 7082 | - * Action: revoke_super_admin | |
| 5395 | + * @action revoke_super_admin | |
| 7083 | 5396 | * |
| 7084 | 5397 | * @param int $user_id The user's ID. |
| 7085 | 5398 | */ |
| 7086 | - public function revoke_super_admin__remove_from_network_approved( $user_id ) { | |
| 7087 | - $user = get_user_by( 'id', $user_id ); | |
| 5399 | + function revoke_super_admin__remove_from_network_approved( $user_id ) { | |
| 5400 | + $user = get_user_by( 'id', $user_id ); | |
| 7088 | 5401 | $revoked_email = $user->user_email; |
| 7089 | 5402 | |
| 7090 | 5403 | // Go through multisite approved user list and remove this user. |
| 7091 | 5404 | $auth_multisite_settings_access_users_approved = $this->sanitize_user_list( |
| 7092 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 5405 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 7093 | 5406 | ); |
| 7094 | - $list_changed = false; | |
| 5407 | + $list_changed = false; | |
| 7095 | 5408 | foreach ( $auth_multisite_settings_access_users_approved as $key => $existing_user ) { |
| 7096 | - if ( 0 === strcasecmp( $revoked_email, $existing_user['email'] ) ) { | |
| 5409 | + if ( $revoked_email === $existing_user['email'] ) { | |
| 7097 | 5410 | $list_changed = true; |
| 7098 | - unset( $auth_multisite_settings_access_users_approved[ $key ] ); | |
| 5411 | + unset( $auth_multisite_settings_access_users_approved[$key] ); | |
| 7099 | 5412 | } |
| 7100 | 5413 | } |
| 7101 | 5414 | if ( $list_changed ) { |
| 7102 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 5415 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 7103 | 5416 | } |
| 7104 | 5417 | |
| 7105 | 5418 | // Go through this user's current sites and add them to the approved list |
| 7106 | 5419 | // (since they are no longer on the network approved list). |
| @@ -7111,21 +5424,14 @@ | ||
| 7111 | 5424 | } |
| 7112 | 5425 | |
| 7113 | 5426 | } |
| 7114 | 5427 | |
| 7115 | - /** | |
| 7116 | - * Send a welcome email message to a newly approved user (if the "Should | |
| 7117 | - * email approved users" setting is enabled). | |
| 7118 | - * | |
| 7119 | - * @param string $email Email address to send welcome email to. | |
| 7120 | - * @return bool Whether the email was sent. | |
| 7121 | - */ | |
| 7122 | 5428 | private function maybe_email_welcome_message( $email ) { |
| 7123 | 5429 | // Get option for whether to email welcome messages. |
| 7124 | 5430 | $should_email_new_approved_users = $this->get_plugin_option( 'access_should_email_approved_users' ); |
| 7125 | 5431 | |
| 7126 | 5432 | // Do not send welcome email if option not enabled. |
| 7127 | - if ( '1' !== $should_email_new_approved_users ) { | |
| 5433 | + if ( $should_email_new_approved_users !== '1' ) { | |
| 7128 | 5434 | return false; |
| 7129 | 5435 | } |
| 7130 | 5436 | |
| 7131 | 5437 | // Make sure we didn't just email this user (can happen with |
| @@ -7131,15 +5437,15 @@ | ||
| 7131 | 5437 | // Make sure we didn't just email this user (can happen with |
| 7132 | 5438 | // multiple admins saving at the same time, or by clicking |
| 7133 | 5439 | // Approve button too rapidly). |
| 7134 | 5440 | $recently_sent_emails = get_option( 'auth_settings_recently_sent_emails' ); |
| 7135 | - if ( false === $recently_sent_emails ) { | |
| 5441 | + if ( $recently_sent_emails === FALSE ) { | |
| 7136 | 5442 | $recently_sent_emails = array(); |
| 7137 | 5443 | } |
| 7138 | 5444 | foreach ( $recently_sent_emails as $key => $recently_sent_email ) { |
| 7139 | 5445 | if ( $recently_sent_email['time'] < strtotime( 'now -1 minutes' ) ) { |
| 7140 | 5446 | // Remove emails sent more than 1 minute ago. |
| 7141 | - unset( $recently_sent_emails[ $key ] ); | |
| 5447 | + unset( $recently_sent_emails[$key] ); | |
| 7142 | 5448 | } elseif ( $recently_sent_email['email'] === $email ) { |
| 7143 | 5449 | // Sent an email to this user within the last 1 minute, so |
| 7144 | 5450 | // quit without sending. |
| 7145 | 5451 | return false; |
| @@ -7147,15 +5453,15 @@ | ||
| 7147 | 5453 | } |
| 7148 | 5454 | // Add the email we're about to send to the list. |
| 7149 | 5455 | $recently_sent_emails[] = array( |
| 7150 | 5456 | 'email' => $email, |
| 7151 | - 'time' => time(), | |
| 5457 | + 'time' => time(), | |
| 7152 | 5458 | ); |
| 7153 | 5459 | update_option( 'auth_settings_recently_sent_emails', $recently_sent_emails ); |
| 7154 | 5460 | |
| 7155 | - // Get welcome email subject and body text. | |
| 5461 | + // Get welcome email subject and body text | |
| 7156 | 5462 | $subject = $this->get_plugin_option( 'access_email_approved_users_subject' ); |
| 7157 | - $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) ); | |
| 5463 | + $body = apply_filters( 'the_content', $this->get_plugin_option( 'access_email_approved_users_body' ) ); | |
| 7158 | 5464 | |
| 7159 | 5465 | // Fail if the subject/body options don't exist or are empty. |
| 7160 | 5466 | if ( is_null( $subject ) || is_null( $body ) || strlen( $subject ) === 0 || strlen( $body ) === 0 ) { |
| 7161 | 5467 | return false; |
| @@ -7162,14 +5468,14 @@ | ||
| 7162 | 5468 | } |
| 7163 | 5469 | |
| 7164 | 5470 | // Replace approved shortcode patterns in subject and body. |
| 7165 | 5471 | $site_name = get_bloginfo( 'name' ); |
| 7166 | - $site_url = get_site_url(); | |
| 7167 | - $subject = str_replace( '[site_name]', $site_name, $subject ); | |
| 7168 | - $body = str_replace( '[site_name]', $site_name, $body ); | |
| 7169 | - $body = str_replace( '[site_url]', $site_url, $body ); | |
| 7170 | - $body = str_replace( '[user_email]', $email, $body ); | |
| 7171 | - $headers = 'Content-type: text/html' . "\r\n"; | |
| 5472 | + $site_url = get_site_url(); | |
| 5473 | + $subject = str_replace( '[site_name]', $site_name, $subject ); | |
| 5474 | + $body = str_replace( '[site_name]', $site_name, $body ); | |
| 5475 | + $body = str_replace( '[site_url]', $site_url, $body ); | |
| 5476 | + $body = str_replace( '[user_email]', $email, $body ); | |
| 5477 | + $headers = 'Content-type: text/html' . "\r\n"; | |
| 7172 | 5478 | |
| 7173 | 5479 | // Send email. |
| 7174 | 5480 | wp_mail( $email, $subject, $body, $headers ); |
| 7175 | 5481 | |
| @@ -7179,22 +5485,14 @@ | ||
| 7179 | 5485 | |
| 7180 | 5486 | |
| 7181 | 5487 | /** |
| 7182 | 5488 | * Generate a unique cookie to add to nonces to prevent CSRF. |
| 7183 | - * | |
| 7184 | - * @var string | |
| 7185 | 5489 | */ |
| 7186 | - private $cookie_value = null; | |
| 7187 | - | |
| 7188 | - /** | |
| 7189 | - * Retrieve the unique login cookie. | |
| 7190 | - * | |
| 7191 | - * @return string Login cookie value. | |
| 7192 | - */ | |
| 7193 | - private function get_cookie_value() { | |
| 5490 | + protected $cookie_value = null; | |
| 5491 | + function get_cookie_value() { | |
| 7194 | 5492 | if ( ! $this->cookie_value ) { |
| 7195 | 5493 | if ( isset( $_COOKIE['login_unique'] ) ) { |
| 7196 | - $this->cookie_value = sanitize_key( wp_unslash( $_COOKIE['login_unique'] ) ); | |
| 5494 | + $this->cookie_value = $_COOKIE['login_unique']; | |
| 7197 | 5495 | } else { |
| 7198 | 5496 | $this->cookie_value = md5( rand() ); |
| 7199 | 5497 | } |
| 7200 | 5498 | } |
| @@ -7202,51 +5500,23 @@ | ||
| 7202 | 5500 | } |
| 7203 | 5501 | |
| 7204 | 5502 | |
| 7205 | 5503 | /** |
| 7206 | - * Encryption key (not secret!). | |
| 7207 | - * | |
| 7208 | - * @var string | |
| 7209 | - */ | |
| 7210 | - private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0"; | |
| 7211 | - | |
| 7212 | - /** | |
| 7213 | - * Encryption salt (not secret!). | |
| 7214 | - * | |
| 7215 | - * @var string | |
| 7216 | - */ | |
| 7217 | - private static $iv = 'R_O2D]jPn]1[fhJl!-P1.oe'; | |
| 7218 | - | |
| 7219 | - /** | |
| 7220 | 5504 | * Basic encryption using a public (not secret!) key. Used for general |
| 7221 | 5505 | * database obfuscation of passwords. |
| 7222 | - * | |
| 7223 | - * @param string $text String to encrypt. | |
| 7224 | - * @param string $library Encryption library to use (openssl). | |
| 7225 | - * @return string Encrypted string. | |
| 7226 | 5506 | */ |
| 7227 | - private function encrypt( $text, $library = 'openssl' ) { | |
| 5507 | + private static $key = "8QxnrvjdtweisvCBKEY!+0\0\0"; | |
| 5508 | + function encrypt( $text ) { | |
| 7228 | 5509 | $result = ''; |
| 7229 | 5510 | |
| 7230 | - // Use openssl library (better) if it is enabled. | |
| 7231 | - if ( function_exists( 'openssl_encrypt' ) && 'openssl' === $library ) { | |
| 7232 | - $result = base64_encode( | |
| 7233 | - openssl_encrypt( | |
| 7234 | - $text, | |
| 7235 | - 'AES-256-CBC', | |
| 7236 | - hash( 'sha256', self::$key ), | |
| 7237 | - 0, | |
| 7238 | - substr( hash( 'sha256', self::$iv ), 0, 16 ) | |
| 7239 | - ) | |
| 7240 | - ); | |
| 7241 | - } elseif ( function_exists( 'mcrypt_encrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled. | |
| 7242 | - $result = base64_encode( mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ) ); | |
| 7243 | - } else { // Fall back to basic obfuscation. | |
| 7244 | - $length = strlen( $text ); | |
| 7245 | - for ( $i = 0; $i < $length; $i++ ) { | |
| 7246 | - $char = substr( $text, $i, 1 ); | |
| 5511 | + // Use mcrypt library (better) if php5-mcrypt extension is enabled. | |
| 5512 | + if ( function_exists( 'mcrypt_encrypt' ) ) { | |
| 5513 | + $result = mcrypt_encrypt( MCRYPT_RIJNDAEL_256, self::$key, $text, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ); | |
| 5514 | + } else { | |
| 5515 | + for ( $i = 0; $i < strlen( $text ); $i++ ) { | |
| 5516 | + $char = substr( $text, $i, 1 ); | |
| 7247 | 5517 | $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 ); |
| 7248 | - $char = chr( ord( $char ) + ord( $keychar ) ); | |
| 5518 | + $char = chr( ord( $char ) + ord( $keychar ) ); | |
| 7249 | 5519 | $result .= $char; |
| 7250 | 5520 | } |
| 7251 | 5521 | $result = base64_encode( $result ); |
| 7252 | 5522 | } |
| @@ -7254,38 +5524,20 @@ | ||
| 7254 | 5524 | return $result; |
| 7255 | 5525 | } |
| 7256 | 5526 | |
| 7257 | 5527 | |
| 7258 | - /** | |
| 7259 | - * Basic decryption using a public (not secret!) key. Used for general | |
| 7260 | - * database obfuscation of passwords. | |
| 7261 | - * | |
| 7262 | - * @param string $secret String to encrypt. | |
| 7263 | - * @param string $library Encryption lib to use (openssl). | |
| 7264 | - * @return string Decrypted string | |
| 7265 | - */ | |
| 7266 | - private function decrypt( $secret, $library = 'openssl' ) { | |
| 5528 | + function decrypt( $secret ) { | |
| 7267 | 5529 | $result = ''; |
| 7268 | 5530 | |
| 7269 | - // Use openssl library (better) if it is enabled. | |
| 7270 | - if ( function_exists( 'openssl_decrypt' ) && 'openssl' === $library ) { | |
| 7271 | - $result = openssl_decrypt( | |
| 7272 | - base64_decode( $secret ), | |
| 7273 | - 'AES-256-CBC', | |
| 7274 | - hash( 'sha256', self::$key ), | |
| 7275 | - 0, | |
| 7276 | - substr( hash( 'sha256', self::$iv ), 0, 16 ) | |
| 7277 | - ); | |
| 7278 | - } elseif ( function_exists( 'mcrypt_decrypt' ) ) { // Use mcrypt library (deprecated in PHP 7.1) if php5-mcrypt extension is enabled. | |
| 7279 | - $secret = base64_decode( $secret ); | |
| 5531 | + // Use mcrypt library (better) if php5-mcrypt extension is enabled. | |
| 5532 | + if ( function_exists( 'mcrypt_decrypt' ) ) { | |
| 7280 | 5533 | $result = rtrim( mcrypt_decrypt( MCRYPT_RIJNDAEL_256, self::$key, $secret, MCRYPT_MODE_ECB, 'abcdefghijklmnopqrstuvwxyz012345' ), "\0$result" ); |
| 7281 | - } else { // Fall back to basic obfuscation. | |
| 5534 | + } else { | |
| 7282 | 5535 | $secret = base64_decode( $secret ); |
| 7283 | - $length = strlen( $secret ); | |
| 7284 | - for ( $i = 0; $i < $length; $i++ ) { | |
| 7285 | - $char = substr( $secret, $i, 1 ); | |
| 5536 | + for ( $i = 0; $i < strlen( $secret ); $i++ ) { | |
| 5537 | + $char = substr( $secret, $i, 1 ); | |
| 7286 | 5538 | $keychar = substr( self::$key, ( $i % strlen( self::$key ) ) - 1, 1 ); |
| 7287 | - $char = chr( ord( $char ) - ord( $keychar ) ); | |
| 5539 | + $char = chr( ord( $char ) - ord( $keychar ) ); | |
| 7288 | 5540 | $result .= $char; |
| 7289 | 5541 | } |
| 7290 | 5542 | } |
| 7291 | 5543 | |
| @@ -7296,12 +5548,10 @@ | ||
| 7296 | 5548 | /** |
| 7297 | 5549 | * In a multisite environment, returns true if the current user is logged |
| 7298 | 5550 | * in and a user of the current blog. In single site mode, simply returns |
| 7299 | 5551 | * true if the current user is logged in. |
| 7300 | - * | |
| 7301 | - * @return bool Whether current user is logged in and a user of the current blog. | |
| 7302 | 5552 | */ |
| 7303 | - protected function is_user_logged_in_and_blog_user() { | |
| 5553 | + function is_user_logged_in_and_blog_user() { | |
| 7304 | 5554 | $is_user_logged_in_and_blog_user = false; |
| 7305 | 5555 | if ( is_multisite() ) { |
| 7306 | 5556 | $is_user_logged_in_and_blog_user = is_user_logged_in() && is_user_member_of_blog( get_current_user_id() ); |
| 7307 | 5557 | } else { |
| @@ -7314,42 +5564,39 @@ | ||
| 7314 | 5564 | /** |
| 7315 | 5565 | * Helper function to determine whether a given email is in one of |
| 7316 | 5566 | * the lists (pending, approved, blocked). Defaults to the list of |
| 7317 | 5567 | * approved users. |
| 7318 | - * | |
| 7319 | - * @param string $email Email to check existent of. | |
| 7320 | - * @param string $list List to look for email in. | |
| 7321 | - * @param string $multisite_mode Admin context. | |
| 7322 | - * @return boolean Whether email was found. | |
| 7323 | 5568 | */ |
| 7324 | - protected function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) { | |
| 7325 | - if ( empty( $email ) ) { | |
| 5569 | + function is_email_in_list( $email = '', $list = 'approved', $multisite_mode = 'single' ) { | |
| 5570 | + if ( empty( $email ) ) | |
| 7326 | 5571 | return false; |
| 7327 | - } | |
| 7328 | 5572 | |
| 7329 | 5573 | switch ( $list ) { |
| 7330 | - case 'pending': | |
| 7331 | - $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 7332 | - return $this->in_multi_array( $email, $auth_settings_access_users_pending ); | |
| 7333 | - case 'blocked': | |
| 7334 | - $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 7335 | - return $this->in_multi_array( $email, $auth_settings_access_users_blocked ); | |
| 7336 | - case 'approved': | |
| 7337 | - default: | |
| 7338 | - if ( 'single' !== $multisite_mode ) { | |
| 7339 | - // Get multisite users only. | |
| 7340 | - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 7341 | - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) { | |
| 7342 | - // This site has overridden any multisite settings, so only get its users. | |
| 7343 | - $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 7344 | - } else { | |
| 7345 | - // Get all site users and all multisite users. | |
| 7346 | - $auth_settings_access_users_approved = array_merge( | |
| 7347 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ), | |
| 7348 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 7349 | - ); | |
| 7350 | - } | |
| 7351 | - return $this->in_multi_array( $email, $auth_settings_access_users_approved ); | |
| 5574 | + case 'pending': | |
| 5575 | + $auth_settings_access_users_pending = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ); | |
| 5576 | + return $this->in_multi_array( $email, $auth_settings_access_users_pending ); | |
| 5577 | + break; | |
| 5578 | + case 'blocked': | |
| 5579 | + $auth_settings_access_users_blocked = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ); | |
| 5580 | + return $this->in_multi_array( $email, $auth_settings_access_users_blocked ); | |
| 5581 | + break; | |
| 5582 | + case 'approved': | |
| 5583 | + default: | |
| 5584 | + if ( $multisite_mode !== 'single' ) { | |
| 5585 | + // Get multisite users only. | |
| 5586 | + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ); | |
| 5587 | + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) { | |
| 5588 | + // This site has overridden any multisite settings, so only get its users. | |
| 5589 | + $auth_settings_access_users_approved = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 5590 | + } else { | |
| 5591 | + // Get all site users and all multisite users. | |
| 5592 | + $auth_settings_access_users_approved = array_merge( | |
| 5593 | + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ), | |
| 5594 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 5595 | + ); | |
| 5596 | + } | |
| 5597 | + return $this->in_multi_array( $email, $auth_settings_access_users_approved ); | |
| 5598 | + break; | |
| 7352 | 5599 | } |
| 7353 | 5600 | } |
| 7354 | 5601 | |
| 7355 | 5602 | |
| @@ -7355,37 +5602,36 @@ | ||
| 7355 | 5602 | |
| 7356 | 5603 | /** |
| 7357 | 5604 | * Helper function to get number of users (including multisite users) |
| 7358 | 5605 | * in a given list (pending, approved, or blocked). |
| 7359 | - * | |
| 7360 | - * @param string $list List to get count of. | |
| 7361 | - * @param string $admin_mode WP_Plugin_Authorizer::SINGLE_CONTEXT or WP_Plugin_Authorizer::NETWORK_CONTEXT determines whether to include multisite users. | |
| 7362 | - * @return int Number of users in list. | |
| 5606 | + * @param string $list | |
| 5607 | + * @param string $admin_mode SINGLE_ADMIN or MULTISITE_ADMIN determines whether to include multisite users | |
| 5608 | + * @return int number of users in list | |
| 7363 | 5609 | */ |
| 7364 | - protected function get_user_count_from_list( $list, $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) { | |
| 5610 | + function get_user_count_from_list( $list, $admin_mode = SINGLE_ADMIN ) { | |
| 7365 | 5611 | $auth_settings_access_users = array(); |
| 7366 | 5612 | |
| 7367 | 5613 | switch ( $list ) { |
| 7368 | - case 'pending': | |
| 7369 | - $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 7370 | - break; | |
| 7371 | - case 'blocked': | |
| 7372 | - $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 7373 | - break; | |
| 7374 | - case 'approved': | |
| 7375 | - if ( WP_Plugin_Authorizer::SINGLE_CONTEXT !== $admin_mode ) { | |
| 7376 | - // Get multisite users only. | |
| 7377 | - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ); | |
| 7378 | - } elseif ( is_multisite() && 1 === intval( $this->get_plugin_option( 'advanced_override_multisite' ) ) ) { | |
| 7379 | - // This site has overridden any multisite settings, so only get its users. | |
| 7380 | - $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ); | |
| 7381 | - } else { | |
| 7382 | - // Get all site users and all multisite users. | |
| 7383 | - $auth_settings_access_users = array_merge( | |
| 7384 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::SINGLE_CONTEXT ), | |
| 7385 | - $this->get_plugin_option( 'access_users_approved', WP_Plugin_Authorizer::NETWORK_CONTEXT ) | |
| 7386 | - ); | |
| 7387 | - } | |
| 5614 | + case 'pending': | |
| 5615 | + $auth_settings_access_users = $this->get_plugin_option( 'access_users_pending', SINGLE_ADMIN ); | |
| 5616 | + break; | |
| 5617 | + case 'blocked': | |
| 5618 | + $auth_settings_access_users = $this->get_plugin_option( 'access_users_blocked', SINGLE_ADMIN ); | |
| 5619 | + break; | |
| 5620 | + case 'approved': | |
| 5621 | + if ( $admin_mode !== SINGLE_ADMIN ) { | |
| 5622 | + // Get multisite users only. | |
| 5623 | + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ); | |
| 5624 | + } elseif ( is_multisite() && $this->get_plugin_option( 'advanced_override_multisite' ) == '1' ) { | |
| 5625 | + // This site has overridden any multisite settings, so only get its users. | |
| 5626 | + $auth_settings_access_users = $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ); | |
| 5627 | + } else { | |
| 5628 | + // Get all site users and all multisite users. | |
| 5629 | + $auth_settings_access_users = array_merge( | |
| 5630 | + $this->get_plugin_option( 'access_users_approved', SINGLE_ADMIN ), | |
| 5631 | + $this->get_plugin_option( 'access_users_approved', MULTISITE_ADMIN ) | |
| 5632 | + ); | |
| 5633 | + } | |
| 7388 | 5634 | } |
| 7389 | 5635 | |
| 7390 | 5636 | return count( $auth_settings_access_users ); |
| 7391 | 5637 | } |
| @@ -7392,27 +5638,21 @@ | ||
| 7392 | 5638 | |
| 7393 | 5639 | |
| 7394 | 5640 | /** |
| 7395 | 5641 | * Helper function to search a multidimensional array for a value. |
| 7396 | - * | |
| 7397 | - * @param string $needle Value to search for. | |
| 7398 | - * @param array $haystack Multidimensional array to search. | |
| 7399 | - * @param string $strict_mode 'strict' if strict comparisons should be used. | |
| 7400 | - * @param string $case_sensitivity 'case sensitive' if comparisons should respect case. | |
| 7401 | - * @return bool Whether needle was found. | |
| 7402 | 5642 | */ |
| 7403 | - protected function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) { | |
| 5643 | + function in_multi_array( $needle = '', $haystack = array(), $strict_mode = 'not strict', $case_sensitivity = 'case insensitive' ) { | |
| 7404 | 5644 | if ( ! is_array( $haystack ) ) { |
| 7405 | 5645 | return false; |
| 7406 | 5646 | } |
| 7407 | - if ( 'case insensitive' === $case_sensitivity ) { | |
| 5647 | + if ( $case_sensitivity === 'case insensitive' ) { | |
| 7408 | 5648 | $needle = strtolower( $needle ); |
| 7409 | 5649 | } |
| 7410 | 5650 | foreach ( $haystack as $item ) { |
| 7411 | - if ( 'case insensitive' === $case_sensitivity && ! is_array( $item ) ) { | |
| 5651 | + if ( $case_sensitivity === 'case insensitive' && ! is_array( $item ) ) { | |
| 7412 | 5652 | $item = strtolower( $item ); |
| 7413 | 5653 | } |
| 7414 | - if ( ( 'strict' === $strict_mode ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) { // phpcs:ignore WordPress.PHP.StrictComparisons.LooseComparison | |
| 5654 | + if ( ( $strict_mode === 'strict' ? $item === $needle : $item == $needle ) || ( is_array( $item ) && $this->in_multi_array( $needle, $item, $strict_mode, $case_sensitivity ) ) ) { | |
| 7415 | 5655 | return true; |
| 7416 | 5656 | } |
| 7417 | 5657 | } |
| 7418 | 5658 | return false; |
| @@ -7419,31 +5659,43 @@ | ||
| 7419 | 5659 | } |
| 7420 | 5660 | |
| 7421 | 5661 | |
| 7422 | 5662 | /** |
| 5663 | + * Helper function to get a WordPress page ID from the pagename. | |
| 5664 | + * | |
| 5665 | + * @param string $pagename Page Slug | |
| 5666 | + * @return int Page/Post ID | |
| 5667 | + */ | |
| 5668 | + function get_id_from_pagename( $pagename = '' ) { | |
| 5669 | + global $wpdb; | |
| 5670 | + $page_id = $wpdb->get_var( "SELECT ID FROM $wpdb->posts WHERE post_name = '" . sanitize_title_for_query( $pagename ) . "'" ); | |
| 5671 | + return $page_id; | |
| 5672 | + } | |
| 5673 | + | |
| 5674 | + | |
| 5675 | + /** | |
| 7423 | 5676 | * Helper function to determine if an URL is accessible. |
| 7424 | 5677 | * |
| 7425 | - * @param string $url URL that should be publicly reachable. | |
| 7426 | - * @return boolean Whether the URL is publicly reachable. | |
| 5678 | + * @param string $url URL that should be publicly reachable | |
| 5679 | + * @return boolean Whether the URL is publicly reachable | |
| 7427 | 5680 | */ |
| 7428 | - protected function url_is_accessible( $url ) { | |
| 5681 | + function url_is_accessible( $url ) { | |
| 7429 | 5682 | // Use wp_remote_retrieve_response_code() to retrieve the URL. |
| 7430 | - $response = wp_remote_get( $url ); | |
| 5683 | + $response = wp_remote_get( $url ); | |
| 7431 | 5684 | $response_code = wp_remote_retrieve_response_code( $response ); |
| 7432 | 5685 | |
| 7433 | - // Return true if the document has loaded successfully without any redirection or error. | |
| 7434 | - return $response_code >= 200 && $response_code < 400; | |
| 5686 | + // Return true if the document has loaded successfully without any redirection or error | |
| 5687 | + return $response_code >= 200 && $response_code < 300; | |
| 7435 | 5688 | } |
| 7436 | 5689 | |
| 7437 | 5690 | |
| 7438 | 5691 | /** |
| 7439 | 5692 | * Helper function to reconstruct a URL split using parse_url(). |
| 7440 | - * | |
| 7441 | - * @param array $parts Array returned from parse_url(). | |
| 7442 | - * @return string URL. | |
| 5693 | + * @param array $parts Array returned from parse_url(). | |
| 5694 | + * @return string URL. | |
| 7443 | 5695 | */ |
| 7444 | - protected function build_url( $parts = array() ) { | |
| 7445 | - return ( | |
| 5696 | + function build_url( $parts = array() ) { | |
| 5697 | + return | |
| 7446 | 5698 | ( isset( $parts['scheme'] ) ? "{$parts['scheme']}:" : '' ) . |
| 7447 | 5699 | ( ( isset( $parts['user'] ) || isset( $parts['host'] ) ) ? '//' : '' ) . |
| 7448 | 5700 | ( isset( $parts['user'] ) ? "{$parts['user']}" : '' ) . |
| 7449 | 5701 | ( isset( $parts['pass'] ) ? ":{$parts['pass']}" : '' ) . |
| @@ -7451,30 +5703,21 @@ | ||
| 7451 | 5703 | ( isset( $parts['host'] ) ? "{$parts['host']}" : '' ) . |
| 7452 | 5704 | ( isset( $parts['port'] ) ? ":{$parts['port']}" : '' ) . |
| 7453 | 5705 | ( isset( $parts['path'] ) ? "{$parts['path']}" : '' ) . |
| 7454 | 5706 | ( isset( $parts['query'] ) ? "?{$parts['query']}" : '' ) . |
| 7455 | - ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' ) | |
| 7456 | - ); | |
| 5707 | + ( isset( $parts['fragment'] ) ? "#{$parts['fragment']}" : '' ); | |
| 7457 | 5708 | } |
| 7458 | 5709 | |
| 7459 | 5710 | |
| 7460 | - /** | |
| 7461 | - * Helper function that prints option tags for a select element for all | |
| 7462 | - * roles the current user has permission to assign. | |
| 7463 | - * | |
| 7464 | - * @param string $selected_role Which role should be selected in the dropdown. | |
| 7465 | - * @param string $disable_input 'disabled' if select element should be disabled. | |
| 7466 | - * @param int $admin_mode WP_Plugin_Authorizer::NETWORK_CONTEXT if we are in that context. | |
| 7467 | - * @return void | |
| 7468 | - */ | |
| 7469 | - protected function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = WP_Plugin_Authorizer::SINGLE_CONTEXT ) { | |
| 7470 | - $roles = get_editable_roles(); | |
| 5711 | + // Helper function that builds option tags for a select element for all | |
| 5712 | + // roles the current user has permission to assign. | |
| 5713 | + function wp_dropdown_permitted_roles( $selected_role = 'subscriber', $disable_input = 'not disabled', $admin_mode = SINGLE_ADMIN ) { | |
| 5714 | + $roles = get_editable_roles(); | |
| 7471 | 5715 | $current_user = wp_get_current_user(); |
| 7472 | 5716 | |
| 7473 | 5717 | // If we're in network admin, also show any roles that might exist only on |
| 7474 | 5718 | // specific sites in the network (themes can add their own roles). |
| 7475 | - if ( WP_Plugin_Authorizer::NETWORK_CONTEXT === $admin_mode ) { | |
| 7476 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 5719 | + if ( $admin_mode === MULTISITE_ADMIN ) { | |
| 7477 | 5720 | $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); |
| 7478 | 5721 | foreach ( $sites as $site ) { |
| 7479 | 5722 | $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; |
| 7480 | 5723 | switch_to_blog( $blog_id ); |
| @@ -7483,11 +5726,11 @@ | ||
| 7483 | 5726 | } |
| 7484 | 5727 | $unique_role_names = array(); |
| 7485 | 5728 | foreach ( $roles as $role_name => $role_info ) { |
| 7486 | 5729 | if ( array_key_exists( $role_name, $unique_role_names ) ) { |
| 7487 | - unset( $roles[ $role_name ] ); | |
| 5730 | + unset( $roles[$role_name] ); | |
| 7488 | 5731 | } else { |
| 7489 | - $unique_role_names[ $role_name ] = true; | |
| 5732 | + $unique_role_names[$role_name] = true; | |
| 7490 | 5733 | } |
| 7491 | 5734 | } |
| 7492 | 5735 | } |
| 7493 | 5736 | |
| @@ -7499,43 +5742,39 @@ | ||
| 7499 | 5742 | } |
| 7500 | 5743 | |
| 7501 | 5744 | // Print an option element for each permitted role. |
| 7502 | 5745 | foreach ( $roles as $name => $role ) { |
| 7503 | - $is_selected = $selected_role === $name; | |
| 5746 | + $selected = $selected_role === $name ? ' selected="selected"' : ''; | |
| 7504 | 5747 | |
| 7505 | - // Don't let a user change their own role (but network admins always can). | |
| 7506 | - $is_disabled = $selected_role !== $name && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) ); | |
| 7507 | - ?> | |
| 7508 | - <option value="<?php echo esc_attr( $name ); ?>"<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php echo esc_html( $role['name'] ); ?></option> | |
| 7509 | - <?php | |
| 5748 | + // Don't let a user change their own role | |
| 5749 | + $disabled = $selected_role !== $name && $disable_input === 'disabled' ? ' disabled="disabled"' : ''; | |
| 5750 | + | |
| 5751 | + // But network admins can always change their role. | |
| 5752 | + if ( is_multisite() && current_user_can( 'manage_network' ) ) { | |
| 5753 | + $disabled = ''; | |
| 5754 | + } | |
| 5755 | + | |
| 5756 | + ?><option value="<?php echo $name; ?>"<?php echo $selected . $disabled; ?>><?php echo $role['name']; ?></option><?php | |
| 7510 | 5757 | } |
| 7511 | 5758 | |
| 7512 | 5759 | // Print default role (no role). |
| 7513 | - $is_selected = strlen( $selected_role ) === 0 || ! array_key_exists( $selected_role, $roles ); | |
| 7514 | - $is_disabled = strlen( $selected_role ) > 0 && 'disabled' === $disable_input && ! ( is_multisite() && current_user_can( 'manage_network' ) ); | |
| 7515 | - ?> | |
| 7516 | - <option value=""<?php selected( $is_selected ); ?><?php disabled( $is_disabled ); ?>><?php esc_html_e( '— No role for this site —', 'authorizer' ); ?></option> | |
| 7517 | - <?php | |
| 5760 | + $selected = strlen( $selected_role ) == 0 || ! array_key_exists( $selected_role, $roles ) ? ' selected="selected"' : ''; | |
| 5761 | + $disabled = strlen( $selected_role ) > 0 && $disable_input === 'disabled' ? ' disabled="disabled"' : ''; | |
| 5762 | + if ( is_multisite() && current_user_can( 'manage_network' ) ) { | |
| 5763 | + $disabled = ''; | |
| 5764 | + } | |
| 5765 | + ?><option value=""<?php echo $selected . $disabled; ?>><?php _e( '— No role for this site —', 'authorizer' ); ?></option><?php | |
| 7518 | 5766 | |
| 7519 | 5767 | } |
| 7520 | 5768 | |
| 7521 | 5769 | |
| 7522 | - /** | |
| 7523 | - * Helper function to get a single user info array from one of the access | |
| 7524 | - * control lists (pending, approved, or blocked). | |
| 7525 | - * | |
| 7526 | - * @param string $email Email address to retrieve info for. | |
| 7527 | - * @param string $list List to get info from. | |
| 7528 | - * @return mixed false if not found, otherwise: array( | |
| 7529 | - * 'email' => '', | |
| 7530 | - * 'role' => '', | |
| 7531 | - * 'date_added' => '', | |
| 7532 | - * ['usermeta' => [''|array()]] | |
| 7533 | - * ); | |
| 7534 | - */ | |
| 7535 | - protected function get_user_info_from_list( $email, $list ) { | |
| 5770 | + // Helper function to get a single user info array from one of the | |
| 5771 | + // access control lists (pending, approved, or blocked). | |
| 5772 | + // Returns: false if not found; otherwise | |
| 5773 | + // array( 'email' => '', 'role' => '', 'date_added' => '', ['usermeta' => [''|array()]] ); | |
| 5774 | + function get_user_info_from_list( $email, $list ) { | |
| 7536 | 5775 | foreach ( $list as $user_info ) { |
| 7537 | - if ( 0 === strcasecmp( $user_info['email'], $email ) ) { | |
| 5776 | + if ( $user_info['email'] === $email ) { | |
| 7538 | 5777 | return $user_info; |
| 7539 | 5778 | } |
| 7540 | 5779 | } |
| 7541 | 5780 | return false; |
| @@ -7540,49 +5779,29 @@ | ||
| 7540 | 5779 | } |
| 7541 | 5780 | return false; |
| 7542 | 5781 | } |
| 7543 | 5782 | |
| 7544 | - /** | |
| 7545 | - * Helper function to convert a string to lowercase. Prefers to use mb_strtolower, | |
| 7546 | - * but will fall back to strtolower if the former is not available. | |
| 7547 | - * | |
| 7548 | - * @param string $string String to convert to lowercase. | |
| 7549 | - * @return string Input in lowercase. | |
| 7550 | - */ | |
| 7551 | - protected function lowercase( $string ) { | |
| 7552 | - return function_exists( 'mb_strtolower' ) ? mb_strtolower( $string ) : strtolower( $string ); | |
| 7553 | - } | |
| 7554 | 5783 | |
| 7555 | - | |
| 7556 | - /** | |
| 7557 | - * Helper function to convert seconds to human readable text. | |
| 7558 | - * | |
| 7559 | - * @see: http://csl.name/php-secs-to-human-text/ | |
| 7560 | - * | |
| 7561 | - * @param int $secs Seconds to display as readable text. | |
| 7562 | - * @return string Readable version of number of seconds. | |
| 7563 | - */ | |
| 7564 | - protected function seconds_as_sentence( $secs ) { | |
| 5784 | + // Helper function to convert seconds to human readable text. | |
| 5785 | + // Source: http://csl.name/php-secs-to-human-text/ | |
| 5786 | + function seconds_as_sentence( $secs ) { | |
| 7565 | 5787 | $units = array( |
| 7566 | - 'week' => 3600 * 24 * 7, | |
| 7567 | - 'day' => 3600 * 24, | |
| 7568 | - 'hour' => 3600, | |
| 7569 | - 'minute' => 60, | |
| 7570 | - 'second' => 1, | |
| 5788 | + "week" => 7 * 24 * 3600, | |
| 5789 | + "day" => 24 * 3600, | |
| 5790 | + "hour" => 3600, | |
| 5791 | + "minute" => 60, | |
| 5792 | + "second" => 1, | |
| 7571 | 5793 | ); |
| 7572 | 5794 | |
| 7573 | - // Specifically handle zero. | |
| 7574 | - if ( 0 === intval( $secs ) ) { | |
| 7575 | - return '0 seconds'; | |
| 7576 | - } | |
| 5795 | + // specifically handle zero | |
| 5796 | + if ( $secs == 0 ) return "0 seconds"; | |
| 7577 | 5797 | |
| 7578 | - $s = ''; | |
| 5798 | + $s = ""; | |
| 7579 | 5799 | |
| 7580 | 5800 | foreach ( $units as $name => $divisor ) { |
| 7581 | - $quot = intval( $secs / $divisor ); | |
| 7582 | - if ( $quot ) { | |
| 7583 | - $s .= "$quot $name"; | |
| 7584 | - $s .= ( abs( $quot ) > 1 ? 's' : '' ) . ', '; | |
| 5801 | + if ( $quot = intval( $secs / $divisor ) ) { | |
| 5802 | + $s .= "$quot $name"; | |
| 5803 | + $s .= ( abs( $quot ) > 1 ? "s" : "" ) . ", "; | |
| 7585 | 5804 | $secs -= $quot * $divisor; |
| 7586 | 5805 | } |
| 7587 | 5806 | } |
| 7588 | 5807 | |
| @@ -7588,14 +5807,10 @@ | ||
| 7588 | 5807 | |
| 7589 | 5808 | return substr( $s, 0, -2 ); |
| 7590 | 5809 | } |
| 7591 | 5810 | |
| 7592 | - /** | |
| 7593 | - * Helper function to get all available usermeta keys as an array. | |
| 7594 | - * | |
| 7595 | - * @return array All usermeta keys for user. | |
| 7596 | - */ | |
| 7597 | - protected function get_all_usermeta_keys() { | |
| 5811 | + // Helper function to get all available usermeta keys as an array. | |
| 5812 | + function get_all_usermeta_keys() { | |
| 7598 | 5813 | global $wpdb; |
| 7599 | 5814 | $usermeta_keys = $wpdb->get_col( "SELECT DISTINCT $wpdb->usermeta.meta_key FROM $wpdb->usermeta" ); |
| 7600 | 5815 | return $usermeta_keys; |
| 7601 | 5816 | } |
| @@ -7602,12 +5817,10 @@ | ||
| 7602 | 5817 | |
| 7603 | 5818 | |
| 7604 | 5819 | /** |
| 7605 | 5820 | * Load translated strings from *.mo files in /languages. |
| 7606 | - * | |
| 7607 | - * Action: plugins_loaded | |
| 7608 | 5821 | */ |
| 7609 | - public function load_textdomain() { | |
| 5822 | + function load_textdomain() { | |
| 7610 | 5823 | load_plugin_textdomain( |
| 7611 | 5824 | 'authorizer', |
| 7612 | 5825 | false, |
| 7613 | 5826 | plugin_basename( dirname( __FILE__ ) ) . '/languages' |
| @@ -7618,17 +5831,14 @@ | ||
| 7618 | 5831 | /** |
| 7619 | 5832 | * Generate CAS authentication URL (wp-login.php URL with reauth=1 removed |
| 7620 | 5833 | * and external=cas added). |
| 7621 | 5834 | */ |
| 7622 | - private function modify_current_url_for_cas_login() { | |
| 5835 | + function modify_current_url_for_cas_login() { | |
| 7623 | 5836 | // Construct the URL of the current page (wp-login.php). |
| 7624 | - $url = ''; | |
| 7625 | - if ( isset( $_SERVER['HTTP_HOST'], $_SERVER['REQUEST_URI'] ) ) { | |
| 7626 | - $url = set_url_scheme( esc_url_raw( wp_unslash( $_SERVER['HTTP_HOST'] ) ) . esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) ) ); | |
| 7627 | - } | |
| 5837 | + $url = 'http' . ( isset( $_SERVER['HTTPS'] ) ? 's' : '' ) . '://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; | |
| 7628 | 5838 | |
| 7629 | 5839 | // Parse the URL into its components. |
| 7630 | - $parsed_url = wp_parse_url( $url ); | |
| 5840 | + $parsed_url = parse_url( $url ); | |
| 7631 | 5841 | |
| 7632 | 5842 | // Fix up the querystring values (remove reauth, make sure external=cas). |
| 7633 | 5843 | $querystring = array(); |
| 7634 | 5844 | if ( array_key_exists( 'query', $parsed_url ) ) { |
| @@ -7635,9 +5845,9 @@ | ||
| 7635 | 5845 | parse_str( $parsed_url['query'], $querystring ); |
| 7636 | 5846 | } |
| 7637 | 5847 | unset( $querystring['reauth'] ); |
| 7638 | 5848 | $querystring['external'] = 'cas'; |
| 7639 | - $parsed_url['query'] = http_build_query( $querystring ); | |
| 5849 | + $parsed_url['query'] = http_build_query( $querystring ); | |
| 7640 | 5850 | |
| 7641 | 5851 | // Return the URL as a string. |
| 7642 | 5852 | return $this->unparse_url( $parsed_url ); |
| 7643 | 5853 | } |
| @@ -7644,21 +5854,20 @@ | ||
| 7644 | 5854 | |
| 7645 | 5855 | |
| 7646 | 5856 | /** |
| 7647 | 5857 | * Reconstruct a URL after it has been deconstructed with parse_url(). |
| 7648 | - * | |
| 7649 | - * @param array $parsed_url Keys from parse_url(). | |
| 7650 | - * @return string URL constructed from the components in $parsed_url. | |
| 5858 | + * @param $parsed_url array() with keys from parse_url(). | |
| 5859 | + * @return string URL constructed from the components in $parsed_url. | |
| 7651 | 5860 | */ |
| 7652 | - protected function unparse_url( $parsed_url = array() ) { | |
| 7653 | - $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : ''; | |
| 7654 | - $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : ''; | |
| 7655 | - $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : ''; | |
| 7656 | - $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : ''; | |
| 7657 | - $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : ''; | |
| 7658 | - $pass = $user || $pass ? "$pass@" : ''; | |
| 7659 | - $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : ''; | |
| 7660 | - $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : ''; | |
| 5861 | + function unparse_url( $parsed_url = array() ) { | |
| 5862 | + $scheme = isset( $parsed_url['scheme'] ) ? $parsed_url['scheme'] . '://' : ''; | |
| 5863 | + $host = isset( $parsed_url['host'] ) ? $parsed_url['host'] : ''; | |
| 5864 | + $port = isset( $parsed_url['port'] ) ? ':' . $parsed_url['port'] : ''; | |
| 5865 | + $user = isset( $parsed_url['user'] ) ? $parsed_url['user'] : ''; | |
| 5866 | + $pass = isset( $parsed_url['pass'] ) ? ':' . $parsed_url['pass'] : ''; | |
| 5867 | + $pass = $user || $pass ? "$pass@" : ''; | |
| 5868 | + $path = isset( $parsed_url['path'] ) ? $parsed_url['path'] : ''; | |
| 5869 | + $query = isset( $parsed_url['query'] ) ? '?' . $parsed_url['query'] : ''; | |
| 7661 | 5870 | $fragment = isset( $parsed_url['fragment'] ) ? '#' . $parsed_url['fragment'] : ''; |
| 7662 | 5871 | return "$scheme$user$pass$host$port$path$query$fragment"; |
| 7663 | 5872 | } |
| 7664 | 5873 | |
| @@ -7663,32 +5872,35 @@ | ||
| 7663 | 5872 | } |
| 7664 | 5873 | |
| 7665 | 5874 | |
| 7666 | 5875 | /** |
| 7667 | - * Helper function to generate an HTML class name for an option (used in | |
| 7668 | - * Authorizer Settings in the Approved User list). | |
| 7669 | - * | |
| 7670 | - * @param string $suffix Unique part of class name. | |
| 7671 | - * @param boolean $is_multisite_user Whether the class name should indicate it's a multisite user. | |
| 7672 | - * @return string Class name, e.g., "auth-email auth-multisite-email". | |
| 7673 | - */ | |
| 7674 | - private function create_class_name( $suffix = '', $is_multisite_user = false ) { | |
| 7675 | - return $is_multisite_user ? "auth-$suffix auth-multisite-$suffix" : "auth-$suffix"; | |
| 7676 | - } | |
| 7677 | - | |
| 7678 | - | |
| 7679 | - /** | |
| 7680 | 5876 | * Plugin Update Routines. |
| 7681 | - * | |
| 7682 | - * Action: plugins_loaded | |
| 7683 | 5877 | */ |
| 7684 | - public function auth_update_check() { | |
| 7685 | - // Get current version. | |
| 7686 | - $needs_updating = false; | |
| 7687 | - if ( is_multisite() ) { | |
| 7688 | - $auth_version = get_blog_option( $this->current_site_blog_id, 'auth_version' ); | |
| 7689 | - } else { | |
| 7690 | - $auth_version = get_option( 'auth_version' ); | |
| 5878 | + function auth_update_check() { | |
| 5879 | + // Update: Set default values for newly added options (forgot to do | |
| 5880 | + // this, so some users are getting debug log notices about undefined | |
| 5881 | + // indexes in $auth_settings). | |
| 5882 | + $update_if_older_than = 20160831; | |
| 5883 | + $auth_version = get_option( 'auth_version' ); | |
| 5884 | + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) { | |
| 5885 | + // Provide default values for any $auth_settings options that don't exist. | |
| 5886 | + if ( is_multisite() ) { | |
| 5887 | + // Get all blog ids | |
| 5888 | + $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 5889 | + foreach ( $sites as $site ) { | |
| 5890 | + $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 5891 | + switch_to_blog( $blog_id ); | |
| 5892 | + // Set meaningful defaults for other sites in the network. | |
| 5893 | + $this->set_default_options(); | |
| 5894 | + // Switch back to original blog. See: https://codex.wordpress.org/Function_Reference/restore_current_blog | |
| 5895 | + restore_current_blog(); | |
| 5896 | + } | |
| 5897 | + } else { | |
| 5898 | + // Set meaningful defaults for this site. | |
| 5899 | + $this->set_default_options(); | |
| 5900 | + } | |
| 5901 | + // Update version to reflect this change has been made. | |
| 5902 | + update_option( 'auth_version', $update_if_older_than ); | |
| 7691 | 5903 | } |
| 7692 | 5904 | |
| 7693 | 5905 | // Update: migrate user lists to own options (addresses concurrency |
| 7694 | 5906 | // when saving plugin options, since user lists are changed often |
| @@ -7698,9 +5910,10 @@ | ||
| 7698 | 5910 | // log in; approved and blocked lists are changed whenever an admin |
| 7699 | 5911 | // changes them from the multisite panel, the dashboard widget, or |
| 7700 | 5912 | // the plugin options page. |
| 7701 | 5913 | $update_if_older_than = 20140709; |
| 7702 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 5914 | + $auth_version = get_option( 'auth_version' ); | |
| 5915 | + if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) { | |
| 7703 | 5916 | // Copy single site user lists to new options (if they exist). |
| 7704 | 5917 | $auth_settings = get_option( 'auth_settings' ); |
| 7705 | 5918 | if ( is_array( $auth_settings ) && array_key_exists( 'access_users_pending', $auth_settings ) ) { |
| 7706 | 5919 | update_option( 'auth_settings_access_users_pending', $auth_settings['access_users_pending'] ); |
| @@ -7718,264 +5931,36 @@ | ||
| 7718 | 5931 | update_option( 'auth_settings', $auth_settings ); |
| 7719 | 5932 | } |
| 7720 | 5933 | // Copy multisite user lists to new options (if they exist). |
| 7721 | 5934 | if ( is_multisite() ) { |
| 7722 | - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() ); | |
| 5935 | + $auth_multisite_settings = get_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', array() ); | |
| 7723 | 5936 | if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_pending', $auth_multisite_settings ) ) { |
| 7724 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] ); | |
| 5937 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_pending', $auth_multisite_settings['access_users_pending'] ); | |
| 7725 | 5938 | unset( $auth_multisite_settings['access_users_pending'] ); |
| 7726 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 5939 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 7727 | 5940 | } |
| 7728 | 5941 | if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_approved', $auth_multisite_settings ) ) { |
| 7729 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] ); | |
| 5942 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings['access_users_approved'] ); | |
| 7730 | 5943 | unset( $auth_multisite_settings['access_users_approved'] ); |
| 7731 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 5944 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 7732 | 5945 | } |
| 7733 | 5946 | if ( is_array( $auth_multisite_settings ) && array_key_exists( 'access_users_blocked', $auth_multisite_settings ) ) { |
| 7734 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] ); | |
| 5947 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings_access_users_blocked', $auth_multisite_settings['access_users_blocked'] ); | |
| 7735 | 5948 | unset( $auth_multisite_settings['access_users_blocked'] ); |
| 7736 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 5949 | + update_blog_option( BLOG_ID_CURRENT_SITE, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 7737 | 5950 | } |
| 7738 | 5951 | } |
| 7739 | 5952 | // Update version to reflect this change has been made. |
| 7740 | - $auth_version = $update_if_older_than; | |
| 7741 | - $needs_updating = true; | |
| 5953 | + update_option( 'auth_version', $update_if_older_than ); | |
| 7742 | 5954 | } |
| 7743 | 5955 | |
| 7744 | - // Update: Set default values for newly added options (forgot to do | |
| 7745 | - // this, so some users are getting debug log notices about undefined | |
| 7746 | - // indexes in $auth_settings). | |
| 7747 | - $update_if_older_than = 20160831; | |
| 7748 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7749 | - // Provide default values for any $auth_settings options that don't exist. | |
| 7750 | - if ( is_multisite() ) { | |
| 7751 | - // Get all blog ids. | |
| 7752 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7753 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7754 | - foreach ( $sites as $site ) { | |
| 7755 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7756 | - switch_to_blog( $blog_id ); | |
| 7757 | - // Set meaningful defaults for other sites in the network. | |
| 7758 | - $this->set_default_options(); | |
| 7759 | - // Switch back to original blog. | |
| 7760 | - restore_current_blog(); | |
| 7761 | - } | |
| 7762 | - } else { | |
| 7763 | - // Set meaningful defaults for this site. | |
| 7764 | - $this->set_default_options(); | |
| 7765 | - } | |
| 7766 | - // Update version to reflect this change has been made. | |
| 7767 | - $auth_version = $update_if_older_than; | |
| 7768 | - $needs_updating = true; | |
| 7769 | - } | |
| 7770 | - | |
| 7771 | - // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is | |
| 7772 | - // deprecated as of PHP 7.1. Use openssl library instead. | |
| 7773 | - $update_if_older_than = 20170510; | |
| 7774 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7775 | - if ( is_multisite() ) { | |
| 7776 | - // Reencrypt LDAP passwords in each site in the network. | |
| 7777 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7778 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7779 | - foreach ( $sites as $site ) { | |
| 7780 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7781 | - $auth_settings = get_blog_option( $blog_id, 'auth_settings', array() ); | |
| 7782 | - if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) { | |
| 7783 | - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' ); | |
| 7784 | - $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password ); | |
| 7785 | - update_blog_option( $blog_id, 'auth_settings', $auth_settings ); | |
| 7786 | - } | |
| 7787 | - } | |
| 7788 | - } else { | |
| 7789 | - // Reencrypt LDAP password on this single-site install. | |
| 7790 | - $auth_settings = get_option( 'auth_settings', array() ); | |
| 7791 | - if ( array_key_exists( 'ldap_password', $auth_settings ) && strlen( $auth_settings['ldap_password'] ) > 0 ) { | |
| 7792 | - $plaintext_ldap_password = $this->decrypt( $auth_settings['ldap_password'], 'mcrypt' ); | |
| 7793 | - $auth_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password ); | |
| 7794 | - update_option( 'auth_settings', $auth_settings ); | |
| 7795 | - } | |
| 7796 | - } | |
| 7797 | - // Update version to reflect this change has been made. | |
| 7798 | - $auth_version = $update_if_older_than; | |
| 7799 | - $needs_updating = true; | |
| 7800 | - } | |
| 7801 | - | |
| 7802 | - // Update: Migrate LDAP passwords encrypted with mcrypt since mcrypt is | |
| 7803 | - // deprecated as of PHP 7.1. Use openssl library instead. | |
| 7804 | - // Note: Forgot to update the auth_multisite_settings ldap password! Do it here. | |
| 7805 | - $update_if_older_than = 20170511; | |
| 7806 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7807 | - if ( is_multisite() ) { | |
| 7808 | - // Reencrypt LDAP password in network (multisite) options. | |
| 7809 | - $auth_multisite_settings = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', array() ); | |
| 7810 | - if ( array_key_exists( 'ldap_password', $auth_multisite_settings ) && strlen( $auth_multisite_settings['ldap_password'] ) > 0 ) { | |
| 7811 | - $plaintext_ldap_password = $this->decrypt( $auth_multisite_settings['ldap_password'], 'mcrypt' ); | |
| 7812 | - $auth_multisite_settings['ldap_password'] = $this->encrypt( $plaintext_ldap_password ); | |
| 7813 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings', $auth_multisite_settings ); | |
| 7814 | - } | |
| 7815 | - } | |
| 7816 | - // Update version to reflect this change has been made. | |
| 7817 | - $auth_version = $update_if_older_than; | |
| 7818 | - $needs_updating = true; | |
| 7819 | - } | |
| 7820 | - | |
| 7821 | - // Update: Remove duplicates from approved list caused by authorizer_automatically_approve_login | |
| 7822 | - // filter not respecting users who are already in the approved list | |
| 7823 | - // (causing them to get re-added each time they logged in). | |
| 7824 | - $update_if_older_than = 20170711; | |
| 7825 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7826 | - // Remove duplicates from approved user lists. | |
| 7827 | - if ( is_multisite() ) { | |
| 7828 | - // Remove duplicates from each site in the multisite. | |
| 7829 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7830 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7831 | - foreach ( $sites as $site ) { | |
| 7832 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7833 | - $auth_settings_access_users_approved = get_blog_option( $blog_id, 'auth_settings_access_users_approved', array() ); | |
| 7834 | - if ( is_array( $auth_settings_access_users_approved ) ) { | |
| 7835 | - $should_update = false; | |
| 7836 | - $distinct_emails = array(); | |
| 7837 | - foreach ( $auth_settings_access_users_approved as $key => $user ) { | |
| 7838 | - if ( in_array( $user['email'], $distinct_emails, true ) ) { | |
| 7839 | - $should_update = true; | |
| 7840 | - unset( $auth_settings_access_users_approved[ $key ] ); | |
| 7841 | - } else { | |
| 7842 | - $distinct_emails[] = $user['email']; | |
| 7843 | - } | |
| 7844 | - } | |
| 7845 | - if ( $should_update ) { | |
| 7846 | - update_blog_option( $blog_id, 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 7847 | - } | |
| 7848 | - } | |
| 7849 | - } | |
| 7850 | - // Remove duplicates from multisite approved user list. | |
| 7851 | - $auth_multisite_settings_access_users_approved = get_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', array() ); | |
| 7852 | - if ( is_array( $auth_multisite_settings_access_users_approved ) ) { | |
| 7853 | - $should_update = false; | |
| 7854 | - $distinct_emails = array(); | |
| 7855 | - foreach ( $auth_multisite_settings_access_users_approved as $key => $user ) { | |
| 7856 | - if ( in_array( $user['email'], $distinct_emails, true ) ) { | |
| 7857 | - $should_update = true; | |
| 7858 | - unset( $auth_multisite_settings_access_users_approved[ $key ] ); | |
| 7859 | - } else { | |
| 7860 | - $distinct_emails[] = $user['email']; | |
| 7861 | - } | |
| 7862 | - } | |
| 7863 | - if ( $should_update ) { | |
| 7864 | - update_blog_option( $this->current_site_blog_id, 'auth_multisite_settings_access_users_approved', $auth_multisite_settings_access_users_approved ); | |
| 7865 | - } | |
| 7866 | - } | |
| 7867 | - } else { | |
| 7868 | - // Remove duplicates from single site approved user list. | |
| 7869 | - $auth_settings_access_users_approved = get_option( 'auth_settings_access_users_approved' ); | |
| 7870 | - if ( is_array( $auth_settings_access_users_approved ) ) { | |
| 7871 | - $should_update = false; | |
| 7872 | - $distinct_emails = array(); | |
| 7873 | - foreach ( $auth_settings_access_users_approved as $key => $user ) { | |
| 7874 | - if ( in_array( $user['email'], $distinct_emails, true ) ) { | |
| 7875 | - $should_update = true; | |
| 7876 | - unset( $auth_settings_access_users_approved[ $key ] ); | |
| 7877 | - } else { | |
| 7878 | - $distinct_emails[] = $user['email']; | |
| 7879 | - } | |
| 7880 | - } | |
| 7881 | - if ( $should_update ) { | |
| 7882 | - update_option( 'auth_settings_access_users_approved', $auth_settings_access_users_approved ); | |
| 7883 | - } | |
| 7884 | - } | |
| 7885 | - } | |
| 7886 | - // Update version to reflect this change has been made. | |
| 7887 | - $auth_version = $update_if_older_than; | |
| 7888 | - $needs_updating = true; | |
| 7889 | - } | |
| 7890 | - | |
| 7891 | - // Update: Set default value for newly added option advanced_widget_enabled. | |
| 7892 | - $update_if_older_than = 20171023; | |
| 7893 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7894 | - // Provide default values for any $auth_settings options that don't exist. | |
| 7895 | - if ( is_multisite() ) { | |
| 7896 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7897 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7898 | - foreach ( $sites as $site ) { | |
| 7899 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7900 | - switch_to_blog( $blog_id ); | |
| 7901 | - $this->set_default_options(); | |
| 7902 | - restore_current_blog(); | |
| 7903 | - } | |
| 7904 | - } else { | |
| 7905 | - $this->set_default_options(); | |
| 7906 | - } | |
| 7907 | - // Update version to reflect this change has been made. | |
| 7908 | - $auth_version = $update_if_older_than; | |
| 7909 | - $needs_updating = true; | |
| 7910 | - } | |
| 7911 | - | |
| 7912 | - // Update: Set default value for newly added option advanced_users_per_page. | |
| 7913 | - $update_if_older_than = 20171215; | |
| 7914 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7915 | - // Provide default values for any $auth_settings options that don't exist. | |
| 7916 | - if ( is_multisite() ) { | |
| 7917 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7918 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7919 | - foreach ( $sites as $site ) { | |
| 7920 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7921 | - switch_to_blog( $blog_id ); | |
| 7922 | - $this->set_default_options(); | |
| 7923 | - restore_current_blog(); | |
| 7924 | - } | |
| 7925 | - } else { | |
| 7926 | - $this->set_default_options(); | |
| 7927 | - } | |
| 7928 | - // Update version to reflect this change has been made. | |
| 7929 | - $auth_version = $update_if_older_than; | |
| 7930 | - $needs_updating = true; | |
| 7931 | - } | |
| 7932 | - | |
| 7933 | - // Update: Set default value for newly added options advanced_users_sort_by and advanced_users_sort_order. | |
| 7934 | - $update_if_older_than = 20171219; | |
| 7935 | - if ( false === $auth_version || intval( $auth_version ) < $update_if_older_than ) { | |
| 7936 | - // Provide default values for any $auth_settings options that don't exist. | |
| 7937 | - if ( is_multisite() ) { | |
| 7938 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7939 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7940 | - foreach ( $sites as $site ) { | |
| 7941 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7942 | - switch_to_blog( $blog_id ); | |
| 7943 | - $this->set_default_options(); | |
| 7944 | - restore_current_blog(); | |
| 7945 | - } | |
| 7946 | - } else { | |
| 7947 | - $this->set_default_options(); | |
| 7948 | - } | |
| 7949 | - // Update version to reflect this change has been made. | |
| 7950 | - $auth_version = $update_if_older_than; | |
| 7951 | - $needs_updating = true; | |
| 7952 | - } | |
| 7953 | - | |
| 7954 | - /* | |
| 7955 | - // Update: TEMPLATE | |
| 7956 | - $update_if_older_than = YYYYMMDD; | |
| 7957 | - if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) { | |
| 7958 | - UPDATE CODE HERE | |
| 7959 | - // Update version to reflect this change has been made. | |
| 7960 | - $auth_version = $update_if_older_than; | |
| 7961 | - $needs_updating = true; | |
| 7962 | - } | |
| 7963 | - */ | |
| 7964 | - | |
| 7965 | - // Save new version number if we performed any updates. | |
| 7966 | - if ( $needs_updating ) { | |
| 7967 | - if ( is_multisite() ) { | |
| 7968 | - // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_get_sitesFound | |
| 7969 | - $sites = function_exists( 'get_sites' ) ? get_sites() : wp_get_sites( array( 'limit' => PHP_INT_MAX ) ); | |
| 7970 | - foreach ( $sites as $site ) { | |
| 7971 | - $blog_id = function_exists( 'get_sites' ) ? $site->blog_id : $site['blog_id']; | |
| 7972 | - update_blog_option( $blog_id, 'auth_version', $auth_version ); | |
| 7973 | - } | |
| 7974 | - } else { | |
| 7975 | - update_option( 'auth_version', $auth_version ); | |
| 7976 | - } | |
| 7977 | - } | |
| 5956 | + // // Update: TEMPLATE | |
| 5957 | + // $update_if_older_than = YYYYMMDD; | |
| 5958 | + // $auth_version = get_option( 'auth_version' ); | |
| 5959 | + // if ( $auth_version === false || intval( $auth_version ) < $update_if_older_than ) { | |
| 5960 | + // UPDATE CODE HERE | |
| 5961 | + // update_option( 'auth_version', $update_if_older_than ); | |
| 5962 | + // } | |
| 7978 | 5963 | } |
| 7979 | 5964 | |
| 7980 | 5965 | } |
| 7981 | 5966 | } |