PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 2.7
Easy Basic Authentication – Add basic auth to site or admin area v2.7
trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 1.9 All 50 releases
← All changes | class/easy-basic-authentication-form-class.php +142 -56 1.52.7 View file →
@@ -1,49 +1,54 @@
1 1 <?php
2 2
3 3 class easy_basic_authentication_form_class {
4 4
5 - const FORM_FIELD = array(
6 - '0' => array(
7 - 'id' => 'basic-auth-plugin-admin-enable',
8 - 'title' => 'Enable for wp-admin',
9 - 'callback' => 'basic_auth_plugin_admin_enable_cb',
10 - ),
11 - '1' => array(
12 - 'id' => 'basic-auth-plugin-enable',
13 - 'title' => 'Enable for the entire site (only if wp-admin is enabled)',
14 - 'callback' => 'basic_auth_plugin_enable_cb',
15 - ),
16 - '2' => array(
17 - 'id' => 'basic-auth-plugin-username',
18 - 'title' => 'Username',
19 - 'callback' => 'basic_auth_plugin_username_cb',
20 - ),
21 - '3' => array(
22 - 'id' => 'basic-auth-plugin-password',
23 - 'title' => 'Password',
24 - 'callback' => 'basic_auth_plugin_password_cb',
25 - ),
26 - '4' => array(
27 - 'id' => 'basic-auth-plugin-admin-log-enable',
28 - 'title' => 'Enable access logs',
29 - 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
30 - ),
31 - '5' => array(
32 - 'id' => 'basic-auth-plugin-alert-enable',
33 - 'title' => 'Enable email alert',
34 - 'callback' => 'basic_auth_plugin_alert_enable_cb',
35 - ),
36 - '6' => array(
37 - 'id' => 'basic-auth-plugin-email-alert',
38 - 'title' => 'Email for alert',
39 - 'callback' => 'basic_auth_plugin_alertemail_cb',
40 - )
41 - );
5 + public $form_field = [];
42 6
43 7 public function __construct()
44 - {
45 -
8 + {
9 + $this->form_field = array(
10 + '0' => array(
11 + 'id' => 'basic-auth-plugin-admin-enable',
12 + 'title' => __('Enable for wp-admin', 'easy-basic-authentication'),
13 + 'callback' => 'basic_auth_plugin_admin_enable_cb',
14 + ),
15 + '1' => array(
16 + 'id' => 'basic-auth-plugin-enable',
17 + 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
18 + 'callback' => 'basic_auth_plugin_enable_cb',
19 + ),
20 + '2' => array(
21 + 'id' => 'basic-auth-plugin-username',
22 + 'title' => __('Username', 'easy-basic-authentication'),
23 + 'callback' => 'basic_auth_plugin_username_cb',
24 + ),
25 + '3' => array(
26 + 'id' => 'basic-auth-plugin-password',
27 + 'title' => __('Password', 'easy-basic-authentication'),
28 + 'callback' => 'basic_auth_plugin_password_cb',
29 + ),
30 + '4' => array(
31 + 'id' => 'basic-auth-plugin-admin-log-enable',
32 + 'title' => __('Enable access logs', 'easy-basic-authentication'),
33 + 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
34 + ),
35 + '5' => array(
36 + 'id' => 'basic-auth-plugin-alert-enable',
37 + 'title' => __('Enable email alert', 'easy-basic-authentication'),
38 + 'callback' => 'basic_auth_plugin_alert_enable_cb',
39 + ),
40 + '6' => array(
41 + 'id' => 'basic-auth-plugin-email-alert',
42 + 'title' => __('Email for alert', 'easy-basic-authentication'),
43 + 'callback' => 'basic_auth_plugin_alertemail_cb',
44 + ),
45 + '7' => array(
46 + 'id' => 'basic-auth-plugin-white-list',
47 + 'title' => __('Ip White list', 'easy-basic-authentication'),
48 + 'callback' => 'basic_auth_plugin_whitelist_cb',
49 + )
50 + );
46 51 }
47 52
48 53 public function basic_auth_plugin_settings_init() {
49 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
@@ -57,12 +62,12 @@
57 62 array($this,'basic_auth_plugin_section_cb'),
58 63 'basic-auth-plugin-settings'
59 64 );
60 65
61 - foreach(self::FORM_FIELD as $field) {
66 + foreach($this->form_field as $field) {
62 67 add_settings_field(
63 68 $field['id'],
64 - __($field['title'], 'easy-basic-authentication'),
69 + esc_html($field['title']),
65 70 array($this,$field['callback']),
66 71 'basic-auth-plugin-settings',
67 72 'basic-auth-plugin-section'
68 73 );
@@ -70,9 +75,9 @@
70 75
71 76 }
72 77
73 78 public function basic_auth_plugin_section_cb() {
74 - echo __('Configure basic authentication', 'easy-basic-authentication');
79 + echo esc_html__('Configure basic authentication', 'easy-basic-authentication');
75 80 }
76 81
77 82 public function basic_auth_plugin_enable_cb() {
78 83 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
@@ -90,19 +95,16 @@
90 95 }
91 96
92 97 public function basic_auth_plugin_username_cb() {
93 98 $username = get_option( 'basic_auth_plugin_username' );
94 - ?>
95 - <input type="text" name="basic_auth_plugin_username" value="<?php echo esc_attr( $username ); ?>">
96 - <?php
99 + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
97 100 }
98 101
99 102 public function basic_auth_plugin_password_cb() {
100 - $password = get_option( 'basic_auth_plugin_password' )
101 - ? __('Password entered', 'easy-basic-authentication')
102 - : __('Enter the password', 'easy-basic-authentication');
103 + $password = get_option( 'basic_auth_plugin_password' );
103 104 ?>
104 - <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php echo $password; ?>">
105 + <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off">
106 + <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p>
105 107 <?php
106 108 }
107 109
108 110 public function basic_auth_plugin_admin_log_enable_cb() {
@@ -120,13 +122,21 @@
120 122 }
121 123
122 124 public function basic_auth_plugin_alertemail_cb() {
123 125 $email_alert = get_option( 'basic_auth_plugin_alertemail' );
124 - ?>
125 - <input type="text" name="basic_auth_plugin_alertemail" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('Enter the email', 'easy-basic-authentication'); ?>">
126 - <?php
126 + $this->printInputText("text","basic_auth_plugin_alertemail",esc_attr( $email_alert ),__('Enter the email', 'easy-basic-authentication'));
127 127 }
128 +
129 + public function basic_auth_plugin_whitelist_cb() {
130 + $white_list = get_option( 'basic_auth_plugin_whitelist' );
131 + $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication'));
132 + }
128 133
134 + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
135 + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
136 + }
137 +
138 +
129 139 public function basic_auth_plugin_save_settings($param) {
130 140 if ( isset( $param['eba_submit'] ) ) {
131 141 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
132 142 $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0;
@@ -134,18 +144,35 @@
134 144 $password = sanitize_text_field( $param['basic_auth_plugin_password'] );
135 145 $log_enable = isset( $param['basic_auth_plugin_admin_log_enable'] ) ? 1 : 0;
136 146 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
137 147 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
148 + $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
138 149
139 - if ( !is_email( $alert_email ) ) {
150 + if ( empty( $username ) ) {
140 151 add_settings_error(
152 + 'basic_auth_plugin_username',
153 + 'basic_auth_plugin_username_error',
154 + __('Username cannot be empty', 'easy-basic-authentication'),
155 + 'error'
156 + );
157 + return;
158 + }
159 +
160 + if ( ! empty( $password ) ) {
161 + $hashed_password = wp_hash_password( $password );
162 + update_option( 'basic_auth_plugin_password', $hashed_password );
163 + }
164 +
165 + if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
166 + update_option( 'basic_auth_plugin_alertemail', $alert_email );
167 + } else {
168 + add_settings_error(
141 169 'basic_auth_plugin_alertemail',
142 170 'basic_auth_plugin_alertemail_error',
143 171 __('Invalid email address', 'easy-basic-authentication'),
144 172 'error'
145 173 );
146 - } else {
147 - update_option( 'basic_auth_plugin_alertemail', $alert_email );
174 + return;
148 175 }
149 176
150 177 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
151 178 update_option( 'basic_auth_plugin_enable', $enable );
@@ -151,13 +178,28 @@
151 178 update_option( 'basic_auth_plugin_enable', $enable );
152 179 update_option( 'basic_auth_plugin_username', $username );
153 180 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
154 181 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
155 -
182 +
183 + if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
184 + update_option( 'basic_auth_plugin_whitelist', $white_list );
185 + } else {
186 + add_settings_error(
187 + 'basic_auth_plugin_whitelist',
188 + 'basic_auth_plugin_whitelist_error',
189 + __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
190 + 'error'
191 + );
192 + return;
193 +
194 + }
195 +
156 196 if ( ! empty( $password ) ) {
157 197 $hashed_password = wp_hash_password( $password );
158 198 update_option( 'basic_auth_plugin_password', $hashed_password );
159 199 }
200 +
201 + $this->send_credentials_email($username, $password);
160 202 }
161 203 }
162 204
163 205 public function basic_auth_plugin_settings_page() {
@@ -162,5 +204,49 @@
162 204
163 205 public function basic_auth_plugin_settings_page() {
164 206 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
165 207 }
208 +
209 + public function validateIpList($white_list) {
210 + $ips = explode(',', $white_list);
211 + foreach ($ips as $ip) {
212 + $ip = trim($ip);
213 + if (!filter_var($ip, FILTER_VALIDATE_IP)) {
214 + return false;
215 + }
216 + }
217 + return true;
218 + }
219 +
220 + public function send_credentials_email($username, $password) {
221 + $admin_email = get_option('admin_email');
222 + $site_url = home_url();
223 + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
224 +
225 + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
226 +
227 + $message = '<html><body>';
228 + $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>';
229 + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
230 + $message .= '<ul style="list-style-type: none; padding-left: 0;">' .
231 + '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' .
232 + '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' .
233 + '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . esc_html($password) . '</strong></li>' .
234 + '</ul>';
235 + $message .= '<p>' . sprintf(
236 + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'),
237 + '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>'
238 + ) . '</p>';
239 + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
240 + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
241 + $message .= '</body></html>';
242 +
243 + $headers = array(
244 + 'Content-Type: text/html; charset=UTF-8',
245 + 'From: ' . $admin_email,
246 + );
247 +
248 + wp_mail($admin_email, $subject, $message, $headers);
249 + }
250 +
251 +
166 252 }