PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 1.3.2
Easy Basic Authentication – Add basic auth to site or admin area v1.3.2
trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 1.9 All 50 releases
easy-basic-authentication / class / easy-basic-authentication-class.php

easy-basic-authentication-class.php in Easy Basic Authentication – Add basic auth to site or admin area 1.3.2, at class/easy-basic-authentication-class.php

239 lines 8.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 class easy_basic_authentication_class {
4
5
6 public function __construct()
7 {
8 if(get_option( 'basic_auth_plugin_admin_enable' )) {
9 if (in_array($GLOBALS['pagenow'], array('wp-login.php', 'wp-register.php'))) {
10 add_action( 'init', array($this,'basic_auth_admin') );
11 }
12 }
13
14 if(get_option( 'basic_auth_plugin_enable' ) && get_option( 'basic_auth_plugin_admin_enable' )){
15 add_action( 'init', array($this,'basic_auth_root') );
16 }
17
18 add_action( 'admin_menu', array($this,'basic_auth_plugin_menu' ));
19 add_action( 'admin_init', array($this,'basic_auth_plugin_settings_init' ));
20
21 add_action( 'admin_init', array($this,'basic_auth_plugin_save_settings') );
22
23 }
24
25 public function basic_auth_root() {
26 $user = get_option( 'basic_auth_plugin_username' );
27 $pass = get_option( 'basic_auth_plugin_password' );
28
29 if ( !isset( $_SERVER['PHP_AUTH_USER'] ) || !isset( $_SERVER['PHP_AUTH_PW'] ) ||
30 $_SERVER['PHP_AUTH_USER'] != $user || !wp_check_password( $_SERVER['PHP_AUTH_PW'], $pass ) ) {
31
32 $this->basic_auth_log_failed_access();
33
34 header( 'WWW-Authenticate: Basic realm="My Website"' );
35 header( 'HTTP/1.0 401 Unauthorized' );
36 echo 'Autenticazione richiesta';
37 exit;
38 }
39 }
40
41 public function basic_auth_admin() {
42 $user = get_option( 'basic_auth_plugin_username' );
43 $pass = get_option( 'basic_auth_plugin_password' );
44
45 if ( !isset( $_SERVER['PHP_AUTH_USER'] ) || !isset( $_SERVER['PHP_AUTH_PW'] ) ||
46 $_SERVER['PHP_AUTH_USER'] != $user || !wp_check_password( $_SERVER['PHP_AUTH_PW'], $pass ) ) {
47
48 $this->basic_auth_log_failed_access();
49
50 header( 'HTTP/1.1 401 Unauthorized' );
51 header( 'WWW-Authenticate: Basic realm="Admin Area"' );
52 exit;
53 }
54 }
55
56
57 public function basic_auth_plugin_menu() {
58 ini_set('display_errors', 1);
59 ini_set('display_startup_errors', 1);
60 error_reporting(E_ALL);
61 $access_count = $this->basic_auth_count_not_viewed_log_failed_access();
62 add_menu_page(
63 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
64 __('Easy Basic A.', 'easy-basic-authentication') . '<span class="update-plugins count-' . $access_count . '"><span class="plugin-count">' . $access_count . '</span></span>',
65 'manage_options',
66 'basic-auth-plugin',
67 array($this, 'basic_auth_plugin_settings_page'),
68 'dashicons-lock'
69 );
70
71 add_submenu_page(
72 'basic-auth-plugin',
73 __('Log Page', 'easy-basic-authentication'),
74 __('Log Page', 'easy-basic-authentication'),
75 'manage_options',
76 'basic-auth-login',
77 array($this, 'basic_auth_login_page')
78 );
79 }
80
81 public function basic_auth_login_page() {
82 if(array_key_exists('clear_mode',$_POST)) {
83 update_option('basic_auth_failure_logs', array());
84 }
85 $user_log_data = array_reverse($this->basic_auth_get_log_failed_access());
86 include plugin_dir_path( __FILE__ ) . '../template/log_page.php';
87 $this->update_view();
88 }
89
90
91 public function basic_auth_plugin_settings_page() {
92 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
93 }
94
95 public function basic_auth_plugin_settings_init() {
96 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
97 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' );
98 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' );
99
100 add_settings_section(
101 'basic-auth-plugin-section',
102 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
103 array($this,'basic_auth_plugin_section_cb'),
104 'basic-auth-plugin-settings'
105 );
106
107 add_settings_field(
108 'basic-auth-plugin-admin-enable',
109 __('Enable for wp-admin', 'easy-basic-authentication'),
110 array($this,'basic_auth_plugin_admin_enable_cb'),
111 'basic-auth-plugin-settings',
112 'basic-auth-plugin-section'
113 );
114
115 add_settings_field(
116 'basic-auth-plugin-enable',
117 __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
118 array($this,'basic_auth_plugin_enable_cb'),
119 'basic-auth-plugin-settings',
120 'basic-auth-plugin-section'
121 );
122
123 add_settings_field(
124 'basic-auth-plugin-username',
125 __('Username', 'easy-basic-authentication'),
126 array($this,'basic_auth_plugin_username_cb'),
127 'basic-auth-plugin-settings',
128 'basic-auth-plugin-section'
129 );
130
131 add_settings_field(
132 'basic-auth-plugin-password',
133 __('Password', 'easy-basic-authentication'),
134 array($this,'basic_auth_plugin_password_cb'),
135 'basic-auth-plugin-settings',
136 'basic-auth-plugin-section'
137 );
138
139 }
140
141 public function basic_auth_plugin_section_cb() {
142 echo __('Configure basic authentication', 'easy-basic-authentication');
143 }
144
145 public function basic_auth_plugin_enable_cb() {
146 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
147 $enable = get_option( 'basic_auth_plugin_enable' );
148 ?>
149 <input type="checkbox" name="basic_auth_plugin_enable" value="1" <?php checked( $enable, 1 ); ?><?php disabled( !$admin_enable ); ?>>
150 <?php
151 }
152
153 public function basic_auth_plugin_admin_enable_cb() {
154 $enable = get_option( 'basic_auth_plugin_admin_enable' );
155 ?>
156 <input type="checkbox" name="basic_auth_plugin_admin_enable" value="1" <?php checked( $enable, 1 ); ?>>
157 <?php
158 }
159
160 public function basic_auth_plugin_username_cb() {
161 $username = get_option( 'basic_auth_plugin_username' );
162 ?>
163 <input type="text" name="basic_auth_plugin_username" value="<?php echo esc_attr( $username ); ?>">
164 <?php
165 }
166
167 public function basic_auth_plugin_password_cb() {
168 $password = get_option( 'basic_auth_plugin_password' )
169 ? __('Password entered', 'easy-basic-authentication')
170 : __('Enter the password', 'easy-basic-authentication');
171 ?>
172 <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php echo $password; ?>">
173 <?php
174 }
175
176
177 public function basic_auth_plugin_save_settings() {
178 if ( isset( $_POST['eba_submit'] ) ) {
179 $admin_enable = isset( $_POST['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
180 $enable = isset( $_POST['basic_auth_plugin_enable'] ) ? 1 : 0;
181 $username = sanitize_text_field( $_POST['basic_auth_plugin_username'] );
182 $password = sanitize_text_field( $_POST['basic_auth_plugin_password'] );
183
184 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
185 update_option( 'basic_auth_plugin_enable', $enable );
186 update_option( 'basic_auth_plugin_username', $username );
187
188 if ( ! empty( $password ) ) {
189 $hashed_password = wp_hash_password( $password );
190 update_option( 'basic_auth_plugin_password', $hashed_password );
191 }
192 }
193 }
194
195 public function basic_auth_log_failed_access() {
196 $logs = get_option('basic_auth_failure_logs', array());
197
198 $log_entry = array(
199 'id' => uniqid(),
200 'ip' => $_SERVER['REMOTE_ADDR'],
201 'data' => current_time('mysql'),
202 'browser' => $_SERVER['HTTP_USER_AGENT'],
203 'viewed' => 0
204 );
205
206 $logs[] = $log_entry;
207
208 update_option('basic_auth_failure_logs', $logs);
209 }
210
211 public function basic_auth_get_log_failed_access() {
212 return get_option('basic_auth_failure_logs', array());
213 }
214
215 public function basic_auth_count_log_failed_access() {
216 return count($this->basic_auth_get_log_failed_access());
217 }
218
219 public function basic_auth_not_viewed_log_failed_access() {
220 $return_not_viewed = array_filter($this->basic_auth_get_log_failed_access(), function ($entry) {
221 return isset($entry['viewed']) && $entry['viewed'] === 0;
222 });
223 return $return_not_viewed;
224 }
225
226 public function basic_auth_count_not_viewed_log_failed_access() {
227 return count($this->basic_auth_not_viewed_log_failed_access());
228 }
229
230 public function update_view() {
231 $logs = get_option('basic_auth_failure_logs', array());
232 foreach ($logs as &$entry) {
233 $entry['viewed'] = 1;
234 }
235 update_option('basic_auth_failure_logs', $logs);
236 }
237
238 }
239