PluginProbe
Passster – Password Protect Pages and Content / 4.3.17
Passster – Password Protect Pages and Content v4.3.17
4.3.17 4.3.16 4.3.15 4.3.14 4.3.12 4.3.13 4.3.11 4.3.10 4.3.9 4.3.8 4.3.7 4.3.6 4.3.5 trunk 3.5.4 3.5.5.2 3.5.5.8 3.5.5.9 4.0 4.1.4 4.2.10 4.2.11 4.2.12 4.2.13 4.2.14 All 49 releases
← All changes | assets/public/passster-public.js +31 -23 4.3.5 → 4.3.17 View file →
@@ -24,15 +24,15 @@
24 24 return base + search + hash;
25 25 }
26 26
27 27 // Hash password via REST API.
28 - async function hashPassword( password ) {
28 + async function hashPassword( password, postId ) {
29 29 try {
30 30 const response = await fetch( restUrl + '/hash', {
31 31 method: 'POST',
32 32 credentials: 'same-origin',
33 33 headers: { 'Content-Type': 'application/json' },
34 - body: JSON.stringify( { password } ),
34 + body: JSON.stringify( { password, post_id: postId } ),
35 35 } );
36 36 const data = await response.json();
37 37 return data.hash || '';
38 38 } catch ( e ) {
@@ -50,10 +50,10 @@
50 50 return existing.split( '|' ).filter( h => h.length > 0 );
51 51 }
52 52
53 53 // Set hashed cookie (appends to existing hashes).
54 - async function setHashedCookie( password ) {
55 - const hash = await hashPassword( password );
54 + async function setHashedCookie( password, postId ) {
55 + const hash = await hashPassword( password, postId );
56 56 if ( hash ) {
57 57 const hashes = getExistingHashes();
58 58 // Only add if not already present
59 59 if ( ! hashes.includes( hash ) ) {
@@ -78,13 +78,9 @@
78 78 } );
79 79 }
80 80
81 81 // Handle successful unlock.
82 - function handleSuccess( data, $form, redirect, cookieValue ) {
83 - if ( ! ps_ajax.disable_cookie && cookieValue ) {
84 - setCookie( cookieValue );
85 - }
86 -
82 + function handleSuccess( data, $form, redirect ) {
87 83 if ( data.redirect ) {
88 84 window.location.replace( data.redirect );
89 85 return;
90 86 }
@@ -122,9 +118,9 @@
122 118 // Check if we have an unlock link.
123 119 if ( ps_ajax.link_pass ) {
124 120 if ( ! ps_ajax.disable_cookie ) {
125 121 if ( ps_ajax.link_pass.length < 25 ) {
126 - setHashedCookie( atob( ps_ajax.link_pass ) ).then( () => {
122 + setHashedCookie( atob( ps_ajax.link_pass ), ps_ajax.post_id ).then( () => {
127 123 window.location.replace( ps_ajax.permalink + '?pts=' + Math.floor( Date.now() / 1000 ) );
128 124 } );
129 125 } else {
130 126 setCookie( ps_ajax.link_pass );
@@ -159,8 +155,9 @@
159 155 const protection = $input.attr( 'data-protection' ) || '';
160 156 const acf = $button.attr( 'data-acf' ) || '';
161 157 const redirect = $button.attr( 'data-redirect' ) || '';
162 158 const termId = parseInt( $button.attr( 'data-term-id' ) ) || 0;
159 + const postType = $button.attr( 'data-post-type' ) || '';
163 160
164 161 // Get block ID from parent wrapper if exists.
165 162 const $wrapper = $form.closest( '.passster-protected-content' );
166 163 const blockId = $wrapper.length ? $wrapper.attr( 'data-block-id' ) : '';
@@ -183,8 +180,9 @@
183 180 protection,
184 181 acf,
185 182 redirect,
186 183 term_id: termId,
184 + post_type: postType,
187 185 } ),
188 186 } );
189 187
190 188 const data = await response.json();
@@ -189,12 +187,9 @@
189 187
190 188 const data = await response.json();
191 189 $form.find( '.ps-loader' ).css( 'display', 'none' );
192 190 if ( data.success ) {
193 - if ( ! ps_ajax.disable_cookie ) {
194 - await setHashedCookie( password );
195 - }
196 - handleSuccess( data, $form, redirect, null );
191 + handleSuccess( data, $form, redirect );
197 192 } else {
198 193 showError( $form, data.error );
199 194 $input.val( '' );
200 195 }
@@ -223,9 +218,9 @@
223 218
224 219 const data = await response.json();
225 220
226 221 if ( data.success ) {
227 - handleSuccess( data, $form, redirect, type.replace( '_v2', '' ).replace( '_v3', '' ) );
222 + handleSuccess( data, $form, redirect );
228 223 } else {
229 224 showError( $form, data.error );
230 225 }
231 226 } catch ( err ) {
@@ -296,23 +291,36 @@
296 291 }
297 292 } );
298 293
299 294 // Turnstile
295 + let turnstileToken = '';
300 296 if ( $( '.turnstile-form' ).length > 0 && window.turnstile ) {
301 297 window.turnstile.ready( function() {
302 298 window.turnstile.render( '.passster-turnstile', {
303 299 sitekey: ps_ajax.turnstile_key,
304 300 callback( token ) {
305 - const $btn = $( '.passster-submit-turnstile' );
306 - const psId = $btn.attr( 'data-psid' );
307 - const $form = $( '#' + psId );
308 - const areaId = parseInt( $btn.attr( 'data-area' ) ) || 0;
309 - const redirect = $btn.attr( 'data-redirect' ) || '';
310 - const protection = $btn.attr( 'data-protection' ) || '';
311 -
312 - validateCaptcha( token, 'turnstile', $form, psId, areaId, redirect, protection );
301 + turnstileToken = token;
313 302 },
314 303 } );
304 + } );
305 +
306 + $( '.turnstile-form' ).on( 'submit', function( event ) {
307 + event.preventDefault();
308 +
309 + const $thisForm = $( this );
310 + const $btn = $thisForm.find( '.passster-submit-turnstile' );
311 + const psId = $btn.attr( 'data-psid' );
312 + const $form = $( '#' + psId );
313 + const areaId = parseInt( $btn.attr( 'data-area' ) ) || 0;
314 + const redirect = $btn.attr( 'data-redirect' ) || '';
315 + const protection = $btn.attr( 'data-protection' ) || '';
316 +
317 + if ( ! turnstileToken ) {
318 + showError( $form, 'Please complete the verification.' );
319 + return;
320 + }
321 +
322 + validateCaptcha( turnstileToken, 'turnstile', $form, psId, areaId, redirect, protection );
315 323 } );
316 324 }
317 325
318 326 // Concurrent logout - using REST API.