PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 2.5
Easy Basic Authentication – Add basic auth to site or admin area v2.5
trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 1.9 All 50 releases
← All changes | class/easy-basic-authentication-form-class.php +124 -72 1.62.5 View file →
@@ -1,54 +1,54 @@
1 1 <?php
2 2
3 3 class easy_basic_authentication_form_class {
4 4
5 - const FORM_FIELD = array(
6 - '0' => array(
7 - 'id' => 'basic-auth-plugin-admin-enable',
8 - 'title' => 'Enable for wp-admin',
9 - 'callback' => 'basic_auth_plugin_admin_enable_cb',
10 - ),
11 - '1' => array(
12 - 'id' => 'basic-auth-plugin-enable',
13 - 'title' => 'Enable for the entire site (only if wp-admin is enabled)',
14 - 'callback' => 'basic_auth_plugin_enable_cb',
15 - ),
16 - '2' => array(
17 - 'id' => 'basic-auth-plugin-username',
18 - 'title' => 'Username',
19 - 'callback' => 'basic_auth_plugin_username_cb',
20 - ),
21 - '3' => array(
22 - 'id' => 'basic-auth-plugin-password',
23 - 'title' => 'Password',
24 - 'callback' => 'basic_auth_plugin_password_cb',
25 - ),
26 - '4' => array(
27 - 'id' => 'basic-auth-plugin-admin-log-enable',
28 - 'title' => 'Enable access logs',
29 - 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
30 - ),
31 - '5' => array(
32 - 'id' => 'basic-auth-plugin-alert-enable',
33 - 'title' => 'Enable email alert',
34 - 'callback' => 'basic_auth_plugin_alert_enable_cb',
35 - ),
36 - '6' => array(
37 - 'id' => 'basic-auth-plugin-email-alert',
38 - 'title' => 'Email for alert',
39 - 'callback' => 'basic_auth_plugin_alertemail_cb',
40 - ),
41 - '7' => array(
42 - 'id' => 'basic-auth-plugin-white-list',
43 - 'title' => 'Ip White list',
44 - 'callback' => 'basic_auth_plugin_whitelist_cb',
45 - )
46 - );
5 + public $form_field = [];
47 6
48 7 public function __construct()
49 - {
50 -
8 + {
9 + $this->form_field = array(
10 + '0' => array(
11 + 'id' => 'basic-auth-plugin-admin-enable',
12 + 'title' => __('Enable for wp-admin', 'easy-basic-authentication'),
13 + 'callback' => 'basic_auth_plugin_admin_enable_cb',
14 + ),
15 + '1' => array(
16 + 'id' => 'basic-auth-plugin-enable',
17 + 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
18 + 'callback' => 'basic_auth_plugin_enable_cb',
19 + ),
20 + '2' => array(
21 + 'id' => 'basic-auth-plugin-username',
22 + 'title' => __('Username', 'easy-basic-authentication'),
23 + 'callback' => 'basic_auth_plugin_username_cb',
24 + ),
25 + '3' => array(
26 + 'id' => 'basic-auth-plugin-password',
27 + 'title' => __('Password', 'easy-basic-authentication'),
28 + 'callback' => 'basic_auth_plugin_password_cb',
29 + ),
30 + '4' => array(
31 + 'id' => 'basic-auth-plugin-admin-log-enable',
32 + 'title' => __('Enable access logs', 'easy-basic-authentication'),
33 + 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
34 + ),
35 + '5' => array(
36 + 'id' => 'basic-auth-plugin-alert-enable',
37 + 'title' => __('Enable email alert', 'easy-basic-authentication'),
38 + 'callback' => 'basic_auth_plugin_alert_enable_cb',
39 + ),
40 + '6' => array(
41 + 'id' => 'basic-auth-plugin-email-alert',
42 + 'title' => __('Email for alert', 'easy-basic-authentication'),
43 + 'callback' => 'basic_auth_plugin_alertemail_cb',
44 + ),
45 + '7' => array(
46 + 'id' => 'basic-auth-plugin-white-list',
47 + 'title' => __('Ip White list', 'easy-basic-authentication'),
48 + 'callback' => 'basic_auth_plugin_whitelist_cb',
49 + )
50 + );
51 51 }
52 52
53 53 public function basic_auth_plugin_settings_init() {
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
@@ -54,9 +54,8 @@
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
55 55 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' );
56 56 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' );
57 57 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' );
58 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_whitelist' );
59 58
60 59 add_settings_section(
61 60 'basic-auth-plugin-section',
62 61 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
@@ -63,12 +62,12 @@
63 62 array($this,'basic_auth_plugin_section_cb'),
64 63 'basic-auth-plugin-settings'
65 64 );
66 65
67 - foreach(self::FORM_FIELD as $field) {
66 + foreach($this->form_field as $field) {
68 67 add_settings_field(
69 68 $field['id'],
70 - __($field['title'], 'easy-basic-authentication'),
69 + esc_html($field['title']),
71 70 array($this,$field['callback']),
72 71 'basic-auth-plugin-settings',
73 72 'basic-auth-plugin-section'
74 73 );
@@ -76,9 +75,9 @@
76 75
77 76 }
78 77
79 78 public function basic_auth_plugin_section_cb() {
80 - echo __('Configure basic authentication', 'easy-basic-authentication');
79 + echo esc_html__('Configure basic authentication', 'easy-basic-authentication');
81 80 }
82 81
83 82 public function basic_auth_plugin_enable_cb() {
84 83 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
@@ -96,9 +95,9 @@
96 95 }
97 96
98 97 public function basic_auth_plugin_username_cb() {
99 98 $username = get_option( 'basic_auth_plugin_username' );
100 - $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ));
99 + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
101 100 }
102 101
103 102 public function basic_auth_plugin_password_cb() {
104 103 $password = get_option( 'basic_auth_plugin_password' )
@@ -103,9 +102,9 @@
103 102 public function basic_auth_plugin_password_cb() {
104 103 $password = get_option( 'basic_auth_plugin_password' )
105 104 ? __('Password entered', 'easy-basic-authentication')
106 105 : __('Enter the password', 'easy-basic-authentication');
107 - $this->printInputText("password","basic_auth_plugin_password",'',$password);
106 + $this->printInputText("password","basic_auth_plugin_password",'',$password,'','off');
108 107 }
109 108
110 109 public function basic_auth_plugin_admin_log_enable_cb() {
111 110 $enable = get_option( 'basic_auth_plugin_admin_log_enable' );
@@ -130,11 +129,12 @@
130 129 $white_list = get_option( 'basic_auth_plugin_whitelist' );
131 130 $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication'));
132 131 }
133 132
134 - public function printInputText($tipe, $name, $value='', $placeholder = '') {
135 - echo "<input type='$tipe' name='$name' value='$value' placeholder='$placeholder'>";
133 + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
134 + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
136 135 }
136 +
137 137
138 138 public function basic_auth_plugin_save_settings($param) {
139 139 if ( isset( $param['eba_submit'] ) ) {
140 140 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
@@ -145,17 +145,38 @@
145 145 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
146 146 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
147 147 $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
148 148
149 - if ( !is_email( $alert_email ) ) {
149 + if ( empty( $username ) ) {
150 150 add_settings_error(
151 + 'basic_auth_plugin_username',
152 + 'basic_auth_plugin_username_error',
153 + __('Username cannot be empty', 'easy-basic-authentication'),
154 + 'error'
155 + );
156 + return;
157 + }
158 +
159 + if ( empty( $password ) ) {
160 + add_settings_error(
161 + 'basic_auth_plugin_password',
162 + 'basic_auth_plugin_password_error',
163 + __('Password cannot be empty', 'easy-basic-authentication'),
164 + 'error'
165 + );
166 + return;
167 + }
168 +
169 + if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
170 + update_option( 'basic_auth_plugin_alertemail', $alert_email );
171 + } else {
172 + add_settings_error(
151 173 'basic_auth_plugin_alertemail',
152 174 'basic_auth_plugin_alertemail_error',
153 175 __('Invalid email address', 'easy-basic-authentication'),
154 176 'error'
155 177 );
156 - } else {
157 - update_option( 'basic_auth_plugin_alertemail', $alert_email );
178 + return;
158 179 }
159 180
160 181 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
161 182 update_option( 'basic_auth_plugin_enable', $enable );
@@ -161,25 +182,26 @@
161 182 update_option( 'basic_auth_plugin_enable', $enable );
162 183 update_option( 'basic_auth_plugin_username', $username );
163 184 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
164 185 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
165 -
166 186
167 - if (strlen($white_list)) {
168 - if( $this->validateIpList( $white_list ) ) {
169 - update_option( 'basic_auth_plugin_whitelist', $white_list );
170 - } else {
171 - add_settings_error(
172 - 'basic_auth_plugin_whitelist',
173 - 'basic_auth_plugin_whitelist_error',
174 - __('Invalid whitelist format. Please enter valid ip addresses separated by commas.', 'easy-basic-authentication'),
175 - 'error'
176 - );
177 - }
187 + if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
188 + update_option( 'basic_auth_plugin_whitelist', $white_list );
189 + } else {
190 + add_settings_error(
191 + 'basic_auth_plugin_whitelist',
192 + 'basic_auth_plugin_whitelist_error',
193 + __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
194 + 'error'
195 + );
196 + return;
197 +
178 198 }
199 +
179 200 if ( ! empty( $password ) ) {
180 201 $hashed_password = wp_hash_password( $password );
181 202 update_option( 'basic_auth_plugin_password', $hashed_password );
203 + $this->send_credentials_email($username, $password);
182 204 }
183 205 }
184 206 }
185 207
@@ -187,13 +209,43 @@
187 209 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
188 210 }
189 211
190 212 public function validateIpList($white_list) {
191 - $pattern = '/^(\s*(?:\d{1,3}\.){3}\d{1,3}\s*(?:,\s*|$))+$/';
213 + $ips = explode(',', $white_list);
214 + foreach ($ips as $ip) {
215 + $ip = trim($ip);
216 + if (!filter_var($ip, FILTER_VALIDATE_IP)) {
217 + return false;
218 + }
219 + }
220 + return true;
221 + }
192 222
193 - if ( preg_match( $pattern, $white_list ) ) {
194 - return true;
195 - }
196 - return false;
223 + public function send_credentials_email($username, $password) {
224 + $admin_email = get_option('admin_email');
225 + $site_url = home_url();
226 + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
227 +
228 + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
229 +
230 + $message = '<html><body>';
231 + $message .= '<p>' . __('Hi Admin,', 'easy-basic-authentication') . '</p>';
232 + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
233 + $message .= '<p><ul>
234 + <li>' . __('Site URL: ', 'easy-basic-authentication') . esc_url($site_url) . '</li>
235 + <li>' . __('Username: ', 'easy-basic-authentication') . esc_html($username) . '</li>
236 + <li>' . __('Password: ', 'easy-basic-authentication') . esc_html($password) . '</li>
237 + </ul></p>';
238 + $message .= '<p>' . __('Please ensure to update your records accordingly and keep this information secure.', 'easy-basic-authentication') . '</p>';
239 + $message .= '<p>' . sprintf(
240 + /* translators: %s is the URL of the plugin */
241 + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'), esc_url($plugin_url)) . '</p>';
242 + $message .= '<p>' . __('If you did not make this change or believe this is an error, please contact support immediately.', 'easy-basic-authentication') . '</p>';
243 + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
244 + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
245 + $message .= '</body></html>';
197 246
247 +
248 + wp_mail($admin_email, $subject, $message);
198 249 }
250 +
199 251 }