PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 2.5
Easy Basic Authentication – Add basic auth to site or admin area v2.5
trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 1.9 All 50 releases
← All changes | class/easy-basic-authentication-form-class.php +129 -81 1.5.32.5 View file →
@@ -1,54 +1,54 @@
1 1 <?php
2 2
3 3 class easy_basic_authentication_form_class {
4 4
5 - const FORM_FIELD = array(
6 - '0' => array(
7 - 'id' => 'basic-auth-plugin-admin-enable',
8 - 'title' => 'Enable for wp-admin',
9 - 'callback' => 'basic_auth_plugin_admin_enable_cb',
10 - ),
11 - '1' => array(
12 - 'id' => 'basic-auth-plugin-enable',
13 - 'title' => 'Enable for the entire site (only if wp-admin is enabled)',
14 - 'callback' => 'basic_auth_plugin_enable_cb',
15 - ),
16 - '2' => array(
17 - 'id' => 'basic-auth-plugin-username',
18 - 'title' => 'Username',
19 - 'callback' => 'basic_auth_plugin_username_cb',
20 - ),
21 - '3' => array(
22 - 'id' => 'basic-auth-plugin-password',
23 - 'title' => 'Password',
24 - 'callback' => 'basic_auth_plugin_password_cb',
25 - ),
26 - '4' => array(
27 - 'id' => 'basic-auth-plugin-admin-log-enable',
28 - 'title' => 'Enable access logs',
29 - 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
30 - ),
31 - '5' => array(
32 - 'id' => 'basic-auth-plugin-alert-enable',
33 - 'title' => 'Enable email alert',
34 - 'callback' => 'basic_auth_plugin_alert_enable_cb',
35 - ),
36 - '6' => array(
37 - 'id' => 'basic-auth-plugin-email-alert',
38 - 'title' => 'Email for alert',
39 - 'callback' => 'basic_auth_plugin_alertemail_cb',
40 - ),
41 - '7' => array(
42 - 'id' => 'basic-auth-plugin-white-list',
43 - 'title' => 'Ip White list',
44 - 'callback' => 'basic_auth_plugin_whitelist_cb',
45 - )
46 - );
5 + public $form_field = [];
47 6
48 7 public function __construct()
49 - {
50 -
8 + {
9 + $this->form_field = array(
10 + '0' => array(
11 + 'id' => 'basic-auth-plugin-admin-enable',
12 + 'title' => __('Enable for wp-admin', 'easy-basic-authentication'),
13 + 'callback' => 'basic_auth_plugin_admin_enable_cb',
14 + ),
15 + '1' => array(
16 + 'id' => 'basic-auth-plugin-enable',
17 + 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
18 + 'callback' => 'basic_auth_plugin_enable_cb',
19 + ),
20 + '2' => array(
21 + 'id' => 'basic-auth-plugin-username',
22 + 'title' => __('Username', 'easy-basic-authentication'),
23 + 'callback' => 'basic_auth_plugin_username_cb',
24 + ),
25 + '3' => array(
26 + 'id' => 'basic-auth-plugin-password',
27 + 'title' => __('Password', 'easy-basic-authentication'),
28 + 'callback' => 'basic_auth_plugin_password_cb',
29 + ),
30 + '4' => array(
31 + 'id' => 'basic-auth-plugin-admin-log-enable',
32 + 'title' => __('Enable access logs', 'easy-basic-authentication'),
33 + 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
34 + ),
35 + '5' => array(
36 + 'id' => 'basic-auth-plugin-alert-enable',
37 + 'title' => __('Enable email alert', 'easy-basic-authentication'),
38 + 'callback' => 'basic_auth_plugin_alert_enable_cb',
39 + ),
40 + '6' => array(
41 + 'id' => 'basic-auth-plugin-email-alert',
42 + 'title' => __('Email for alert', 'easy-basic-authentication'),
43 + 'callback' => 'basic_auth_plugin_alertemail_cb',
44 + ),
45 + '7' => array(
46 + 'id' => 'basic-auth-plugin-white-list',
47 + 'title' => __('Ip White list', 'easy-basic-authentication'),
48 + 'callback' => 'basic_auth_plugin_whitelist_cb',
49 + )
50 + );
51 51 }
52 52
53 53 public function basic_auth_plugin_settings_init() {
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
@@ -54,9 +54,8 @@
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
55 55 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' );
56 56 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' );
57 57 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' );
58 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_whitelist' );
59 58
60 59 add_settings_section(
61 60 'basic-auth-plugin-section',
62 61 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
@@ -63,12 +62,12 @@
63 62 array($this,'basic_auth_plugin_section_cb'),
64 63 'basic-auth-plugin-settings'
65 64 );
66 65
67 - foreach(self::FORM_FIELD as $field) {
66 + foreach($this->form_field as $field) {
68 67 add_settings_field(
69 68 $field['id'],
70 - __($field['title'], 'easy-basic-authentication'),
69 + esc_html($field['title']),
71 70 array($this,$field['callback']),
72 71 'basic-auth-plugin-settings',
73 72 'basic-auth-plugin-section'
74 73 );
@@ -76,9 +75,9 @@
76 75
77 76 }
78 77
79 78 public function basic_auth_plugin_section_cb() {
80 - echo __('Configure basic authentication', 'easy-basic-authentication');
79 + echo esc_html__('Configure basic authentication', 'easy-basic-authentication');
81 80 }
82 81
83 82 public function basic_auth_plugin_enable_cb() {
84 83 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
@@ -96,11 +95,9 @@
96 95 }
97 96
98 97 public function basic_auth_plugin_username_cb() {
99 98 $username = get_option( 'basic_auth_plugin_username' );
100 - ?>
101 - <input type="text" name="basic_auth_plugin_username" value="<?php echo esc_attr( $username ); ?>">
102 - <?php
99 + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
103 100 }
104 101
105 102 public function basic_auth_plugin_password_cb() {
106 103 $password = get_option( 'basic_auth_plugin_password' )
@@ -105,11 +102,9 @@
105 102 public function basic_auth_plugin_password_cb() {
106 103 $password = get_option( 'basic_auth_plugin_password' )
107 104 ? __('Password entered', 'easy-basic-authentication')
108 105 : __('Enter the password', 'easy-basic-authentication');
109 - ?>
110 - <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php echo $password; ?>">
111 - <?php
106 + $this->printInputText("password","basic_auth_plugin_password",'',$password,'','off');
112 107 }
113 108
114 109 public function basic_auth_plugin_admin_log_enable_cb() {
115 110 $enable = get_option( 'basic_auth_plugin_admin_log_enable' );
@@ -126,20 +121,21 @@
126 121 }
127 122
128 123 public function basic_auth_plugin_alertemail_cb() {
129 124 $email_alert = get_option( 'basic_auth_plugin_alertemail' );
130 - ?>
131 - <input type="text" name="basic_auth_plugin_alertemail" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('Enter the email', 'easy-basic-authentication'); ?>">
132 - <?php
125 + $this->printInputText("text","basic_auth_plugin_alertemail",esc_attr( $email_alert ),__('Enter the email', 'easy-basic-authentication'));
133 126 }
134 127
135 128 public function basic_auth_plugin_whitelist_cb() {
136 - $email_alert = get_option( 'basic_auth_plugin_whitelist' );
137 - ?>
138 - <input type="text" name="basic_auth_plugin_whitelist" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('White list, separated by comma', 'easy-basic-authentication'); ?>">
139 - <?php
129 + $white_list = get_option( 'basic_auth_plugin_whitelist' );
130 + $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication'));
140 131 }
141 132
133 + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
134 + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
135 + }
136 +
137 +
142 138 public function basic_auth_plugin_save_settings($param) {
143 139 if ( isset( $param['eba_submit'] ) ) {
144 140 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
145 141 $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0;
@@ -149,17 +145,38 @@
149 145 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
150 146 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
151 147 $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
152 148
153 - if ( !is_email( $alert_email ) ) {
149 + if ( empty( $username ) ) {
154 150 add_settings_error(
151 + 'basic_auth_plugin_username',
152 + 'basic_auth_plugin_username_error',
153 + __('Username cannot be empty', 'easy-basic-authentication'),
154 + 'error'
155 + );
156 + return;
157 + }
158 +
159 + if ( empty( $password ) ) {
160 + add_settings_error(
161 + 'basic_auth_plugin_password',
162 + 'basic_auth_plugin_password_error',
163 + __('Password cannot be empty', 'easy-basic-authentication'),
164 + 'error'
165 + );
166 + return;
167 + }
168 +
169 + if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
170 + update_option( 'basic_auth_plugin_alertemail', $alert_email );
171 + } else {
172 + add_settings_error(
155 173 'basic_auth_plugin_alertemail',
156 174 'basic_auth_plugin_alertemail_error',
157 175 __('Invalid email address', 'easy-basic-authentication'),
158 176 'error'
159 177 );
160 - } else {
161 - update_option( 'basic_auth_plugin_alertemail', $alert_email );
178 + return;
162 179 }
163 180
164 181 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
165 182 update_option( 'basic_auth_plugin_enable', $enable );
@@ -165,25 +182,26 @@
165 182 update_option( 'basic_auth_plugin_enable', $enable );
166 183 update_option( 'basic_auth_plugin_username', $username );
167 184 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
168 185 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
169 -
170 186
171 - if (strlen($white_list)) {
172 - if( $this->validateIpList( $white_list ) ) {
173 - update_option( 'basic_auth_plugin_whitelist', $white_list );
174 - } else {
175 - add_settings_error(
176 - 'basic_auth_plugin_whitelist',
177 - 'basic_auth_plugin_whitelist_error',
178 - __('Invalid whitelist format. Please enter valid ip addresses separated by commas.', 'easy-basic-authentication'),
179 - 'error'
180 - );
181 - }
187 + if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
188 + update_option( 'basic_auth_plugin_whitelist', $white_list );
189 + } else {
190 + add_settings_error(
191 + 'basic_auth_plugin_whitelist',
192 + 'basic_auth_plugin_whitelist_error',
193 + __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
194 + 'error'
195 + );
196 + return;
197 +
182 198 }
199 +
183 200 if ( ! empty( $password ) ) {
184 201 $hashed_password = wp_hash_password( $password );
185 202 update_option( 'basic_auth_plugin_password', $hashed_password );
203 + $this->send_credentials_email($username, $password);
186 204 }
187 205 }
188 206 }
189 207
@@ -191,13 +209,43 @@
191 209 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
192 210 }
193 211
194 212 public function validateIpList($white_list) {
195 - $pattern = '/^(\s*(?:\d{1,3}\.){3}\d{1,3}\s*(?:,\s*|$))+$/';
213 + $ips = explode(',', $white_list);
214 + foreach ($ips as $ip) {
215 + $ip = trim($ip);
216 + if (!filter_var($ip, FILTER_VALIDATE_IP)) {
217 + return false;
218 + }
219 + }
220 + return true;
221 + }
196 222
197 - if ( preg_match( $pattern, $white_list ) ) {
198 - return true;
199 - }
200 - return false;
223 + public function send_credentials_email($username, $password) {
224 + $admin_email = get_option('admin_email');
225 + $site_url = home_url();
226 + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
227 +
228 + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
229 +
230 + $message = '<html><body>';
231 + $message .= '<p>' . __('Hi Admin,', 'easy-basic-authentication') . '</p>';
232 + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
233 + $message .= '<p><ul>
234 + <li>' . __('Site URL: ', 'easy-basic-authentication') . esc_url($site_url) . '</li>
235 + <li>' . __('Username: ', 'easy-basic-authentication') . esc_html($username) . '</li>
236 + <li>' . __('Password: ', 'easy-basic-authentication') . esc_html($password) . '</li>
237 + </ul></p>';
238 + $message .= '<p>' . __('Please ensure to update your records accordingly and keep this information secure.', 'easy-basic-authentication') . '</p>';
239 + $message .= '<p>' . sprintf(
240 + /* translators: %s is the URL of the plugin */
241 + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'), esc_url($plugin_url)) . '</p>';
242 + $message .= '<p>' . __('If you did not make this change or believe this is an error, please contact support immediately.', 'easy-basic-authentication') . '</p>';
243 + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
244 + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
245 + $message .= '</body></html>';
201 246
247 +
248 + wp_mail($admin_email, $subject, $message);
202 249 }
250 +
203 251 }