| @@ -1,54 +1,54 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | class easy_basic_authentication_form_class { |
| 4 | 4 | |
| 5 | - const FORM_FIELD = array( | |
| 6 | - '0' => array( | |
| 7 | - 'id' => 'basic-auth-plugin-admin-enable', | |
| 8 | - 'title' => 'Enable for wp-admin', | |
| 9 | - 'callback' => 'basic_auth_plugin_admin_enable_cb', | |
| 10 | - ), | |
| 11 | - '1' => array( | |
| 12 | - 'id' => 'basic-auth-plugin-enable', | |
| 13 | - 'title' => 'Enable for the entire site (only if wp-admin is enabled)', | |
| 14 | - 'callback' => 'basic_auth_plugin_enable_cb', | |
| 15 | - ), | |
| 16 | - '2' => array( | |
| 17 | - 'id' => 'basic-auth-plugin-username', | |
| 18 | - 'title' => 'Username', | |
| 19 | - 'callback' => 'basic_auth_plugin_username_cb', | |
| 20 | - ), | |
| 21 | - '3' => array( | |
| 22 | - 'id' => 'basic-auth-plugin-password', | |
| 23 | - 'title' => 'Password', | |
| 24 | - 'callback' => 'basic_auth_plugin_password_cb', | |
| 25 | - ), | |
| 26 | - '4' => array( | |
| 27 | - 'id' => 'basic-auth-plugin-admin-log-enable', | |
| 28 | - 'title' => 'Enable access logs', | |
| 29 | - 'callback' => 'basic_auth_plugin_admin_log_enable_cb', | |
| 30 | - ), | |
| 31 | - '5' => array( | |
| 32 | - 'id' => 'basic-auth-plugin-alert-enable', | |
| 33 | - 'title' => 'Enable email alert', | |
| 34 | - 'callback' => 'basic_auth_plugin_alert_enable_cb', | |
| 35 | - ), | |
| 36 | - '6' => array( | |
| 37 | - 'id' => 'basic-auth-plugin-email-alert', | |
| 38 | - 'title' => 'Email for alert', | |
| 39 | - 'callback' => 'basic_auth_plugin_alertemail_cb', | |
| 40 | - ), | |
| 41 | - '7' => array( | |
| 42 | - 'id' => 'basic-auth-plugin-white-list', | |
| 43 | - 'title' => 'Ip White list', | |
| 44 | - 'callback' => 'basic_auth_plugin_whitelist_cb', | |
| 45 | - ) | |
| 46 | - ); | |
| 5 | + public $form_field = []; | |
| 47 | 6 | |
| 48 | 7 | public function __construct() |
| 49 | - { | |
| 50 | - | |
| 8 | + { | |
| 9 | + $this->form_field = array( | |
| 10 | + '0' => array( | |
| 11 | + 'id' => 'basic-auth-plugin-admin-enable', | |
| 12 | + 'title' => __('Enable for wp-admin', 'easy-basic-authentication'), | |
| 13 | + 'callback' => 'basic_auth_plugin_admin_enable_cb', | |
| 14 | + ), | |
| 15 | + '1' => array( | |
| 16 | + 'id' => 'basic-auth-plugin-enable', | |
| 17 | + 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'), | |
| 18 | + 'callback' => 'basic_auth_plugin_enable_cb', | |
| 19 | + ), | |
| 20 | + '2' => array( | |
| 21 | + 'id' => 'basic-auth-plugin-username', | |
| 22 | + 'title' => __('Username', 'easy-basic-authentication'), | |
| 23 | + 'callback' => 'basic_auth_plugin_username_cb', | |
| 24 | + ), | |
| 25 | + '3' => array( | |
| 26 | + 'id' => 'basic-auth-plugin-password', | |
| 27 | + 'title' => __('Password', 'easy-basic-authentication'), | |
| 28 | + 'callback' => 'basic_auth_plugin_password_cb', | |
| 29 | + ), | |
| 30 | + '4' => array( | |
| 31 | + 'id' => 'basic-auth-plugin-admin-log-enable', | |
| 32 | + 'title' => __('Enable access logs', 'easy-basic-authentication'), | |
| 33 | + 'callback' => 'basic_auth_plugin_admin_log_enable_cb', | |
| 34 | + ), | |
| 35 | + '5' => array( | |
| 36 | + 'id' => 'basic-auth-plugin-alert-enable', | |
| 37 | + 'title' => __('Enable email alert', 'easy-basic-authentication'), | |
| 38 | + 'callback' => 'basic_auth_plugin_alert_enable_cb', | |
| 39 | + ), | |
| 40 | + '6' => array( | |
| 41 | + 'id' => 'basic-auth-plugin-email-alert', | |
| 42 | + 'title' => __('Email for alert', 'easy-basic-authentication'), | |
| 43 | + 'callback' => 'basic_auth_plugin_alertemail_cb', | |
| 44 | + ), | |
| 45 | + '7' => array( | |
| 46 | + 'id' => 'basic-auth-plugin-white-list', | |
| 47 | + 'title' => __('Ip White list', 'easy-basic-authentication'), | |
| 48 | + 'callback' => 'basic_auth_plugin_whitelist_cb', | |
| 49 | + ) | |
| 50 | + ); | |
| 51 | 51 | } |
| 52 | 52 | |
| 53 | 53 | public function basic_auth_plugin_settings_init() { |
| 54 | 54 | register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' ); |
| @@ -54,9 +54,8 @@ | ||
| 54 | 54 | register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' ); |
| 55 | 55 | register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' ); |
| 56 | 56 | register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' ); |
| 57 | 57 | register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' ); |
| 58 | - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_whitelist' ); | |
| 59 | 58 | |
| 60 | 59 | add_settings_section( |
| 61 | 60 | 'basic-auth-plugin-section', |
| 62 | 61 | __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'), |
| @@ -63,12 +62,12 @@ | ||
| 63 | 62 | array($this,'basic_auth_plugin_section_cb'), |
| 64 | 63 | 'basic-auth-plugin-settings' |
| 65 | 64 | ); |
| 66 | 65 | |
| 67 | - foreach(self::FORM_FIELD as $field) { | |
| 66 | + foreach($this->form_field as $field) { | |
| 68 | 67 | add_settings_field( |
| 69 | 68 | $field['id'], |
| 70 | - __($field['title'], 'easy-basic-authentication'), | |
| 69 | + esc_html($field['title']), | |
| 71 | 70 | array($this,$field['callback']), |
| 72 | 71 | 'basic-auth-plugin-settings', |
| 73 | 72 | 'basic-auth-plugin-section' |
| 74 | 73 | ); |
| @@ -76,9 +75,9 @@ | ||
| 76 | 75 | |
| 77 | 76 | } |
| 78 | 77 | |
| 79 | 78 | public function basic_auth_plugin_section_cb() { |
| 80 | - echo __('Configure basic authentication', 'easy-basic-authentication'); | |
| 79 | + echo esc_html__('Configure basic authentication', 'easy-basic-authentication'); | |
| 81 | 80 | } |
| 82 | 81 | |
| 83 | 82 | public function basic_auth_plugin_enable_cb() { |
| 84 | 83 | $admin_enable = get_option( 'basic_auth_plugin_admin_enable' ); |
| @@ -96,19 +95,16 @@ | ||
| 96 | 95 | } |
| 97 | 96 | |
| 98 | 97 | public function basic_auth_plugin_username_cb() { |
| 99 | 98 | $username = get_option( 'basic_auth_plugin_username' ); |
| 100 | - ?> | |
| 101 | - <input type="text" name="basic_auth_plugin_username" value="<?php echo esc_attr( $username ); ?>"> | |
| 102 | - <?php | |
| 99 | + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off'); | |
| 103 | 100 | } |
| 104 | 101 | |
| 105 | 102 | public function basic_auth_plugin_password_cb() { |
| 106 | - $password = get_option( 'basic_auth_plugin_password' ) | |
| 107 | - ? __('Password entered', 'easy-basic-authentication') | |
| 108 | - : __('Enter the password', 'easy-basic-authentication'); | |
| 103 | + $password = get_option( 'basic_auth_plugin_password' ); | |
| 109 | 104 | ?> |
| 110 | - <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php echo $password; ?>"> | |
| 105 | + <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off"> | |
| 106 | + <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p> | |
| 111 | 107 | <?php |
| 112 | 108 | } |
| 113 | 109 | |
| 114 | 110 | public function basic_auth_plugin_admin_log_enable_cb() { |
| @@ -126,20 +122,21 @@ | ||
| 126 | 122 | } |
| 127 | 123 | |
| 128 | 124 | public function basic_auth_plugin_alertemail_cb() { |
| 129 | 125 | $email_alert = get_option( 'basic_auth_plugin_alertemail' ); |
| 130 | - ?> | |
| 131 | - <input type="text" name="basic_auth_plugin_alertemail" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('Enter the email', 'easy-basic-authentication'); ?>"> | |
| 132 | - <?php | |
| 126 | + $this->printInputText("text","basic_auth_plugin_alertemail",esc_attr( $email_alert ),__('Enter the email', 'easy-basic-authentication')); | |
| 133 | 127 | } |
| 134 | 128 | |
| 135 | 129 | public function basic_auth_plugin_whitelist_cb() { |
| 136 | - $email_alert = get_option( 'basic_auth_plugin_whitelist' ); | |
| 137 | - ?> | |
| 138 | - <input type="text" name="basic_auth_plugin_whitelist" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('White list, separated by comma', 'easy-basic-authentication'); ?>"> | |
| 139 | - <?php | |
| 130 | + $white_list = get_option( 'basic_auth_plugin_whitelist' ); | |
| 131 | + $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication')); | |
| 140 | 132 | } |
| 141 | 133 | |
| 134 | + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') { | |
| 135 | + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >"; | |
| 136 | + } | |
| 137 | + | |
| 138 | + | |
| 142 | 139 | public function basic_auth_plugin_save_settings($param) { |
| 143 | 140 | if ( isset( $param['eba_submit'] ) ) { |
| 144 | 141 | $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0; |
| 145 | 142 | $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0; |
| @@ -149,17 +146,33 @@ | ||
| 149 | 146 | $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0; |
| 150 | 147 | $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] ); |
| 151 | 148 | $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] ); |
| 152 | 149 | |
| 153 | - if ( !is_email( $alert_email ) ) { | |
| 150 | + if ( empty( $username ) ) { | |
| 154 | 151 | add_settings_error( |
| 152 | + 'basic_auth_plugin_username', | |
| 153 | + 'basic_auth_plugin_username_error', | |
| 154 | + __('Username cannot be empty', 'easy-basic-authentication'), | |
| 155 | + 'error' | |
| 156 | + ); | |
| 157 | + return; | |
| 158 | + } | |
| 159 | + | |
| 160 | + if ( ! empty( $password ) ) { | |
| 161 | + $hashed_password = wp_hash_password( $password ); | |
| 162 | + update_option( 'basic_auth_plugin_password', $hashed_password ); | |
| 163 | + } | |
| 164 | + | |
| 165 | + if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) { | |
| 166 | + update_option( 'basic_auth_plugin_alertemail', $alert_email ); | |
| 167 | + } else { | |
| 168 | + add_settings_error( | |
| 155 | 169 | 'basic_auth_plugin_alertemail', |
| 156 | 170 | 'basic_auth_plugin_alertemail_error', |
| 157 | 171 | __('Invalid email address', 'easy-basic-authentication'), |
| 158 | 172 | 'error' |
| 159 | 173 | ); |
| 160 | - } else { | |
| 161 | - update_option( 'basic_auth_plugin_alertemail', $alert_email ); | |
| 174 | + return; | |
| 162 | 175 | } |
| 163 | 176 | |
| 164 | 177 | update_option( 'basic_auth_plugin_admin_enable', $admin_enable ); |
| 165 | 178 | update_option( 'basic_auth_plugin_enable', $enable ); |
| @@ -165,26 +178,28 @@ | ||
| 165 | 178 | update_option( 'basic_auth_plugin_enable', $enable ); |
| 166 | 179 | update_option( 'basic_auth_plugin_username', $username ); |
| 167 | 180 | update_option( 'basic_auth_plugin_admin_log_enable', $log_enable ); |
| 168 | 181 | update_option( 'basic_auth_plugin_alert_enable', $alert_enable ); |
| 169 | - | |
| 170 | 182 | |
| 171 | - if (strlen($white_list)) { | |
| 172 | - if( $this->validateIpList( $white_list ) ) { | |
| 173 | - update_option( 'basic_auth_plugin_whitelist', $white_list ); | |
| 174 | - } else { | |
| 175 | - add_settings_error( | |
| 176 | - 'basic_auth_plugin_whitelist', | |
| 177 | - 'basic_auth_plugin_whitelist_error', | |
| 178 | - __('Invalid whitelist format. Please enter valid ip addresses separated by commas.', 'easy-basic-authentication'), | |
| 179 | - 'error' | |
| 180 | - ); | |
| 181 | - } | |
| 183 | + if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) { | |
| 184 | + update_option( 'basic_auth_plugin_whitelist', $white_list ); | |
| 185 | + } else { | |
| 186 | + add_settings_error( | |
| 187 | + 'basic_auth_plugin_whitelist', | |
| 188 | + 'basic_auth_plugin_whitelist_error', | |
| 189 | + __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'), | |
| 190 | + 'error' | |
| 191 | + ); | |
| 192 | + return; | |
| 193 | + | |
| 182 | 194 | } |
| 195 | + | |
| 183 | 196 | if ( ! empty( $password ) ) { |
| 184 | 197 | $hashed_password = wp_hash_password( $password ); |
| 185 | 198 | update_option( 'basic_auth_plugin_password', $hashed_password ); |
| 186 | 199 | } |
| 200 | + | |
| 201 | + $this->send_credentials_email($username, $password); | |
| 187 | 202 | } |
| 188 | 203 | } |
| 189 | 204 | |
| 190 | 205 | public function basic_auth_plugin_settings_page() { |
| @@ -191,13 +206,48 @@ | ||
| 191 | 206 | include plugin_dir_path( __FILE__ ) . '../template/settings_page.php'; |
| 192 | 207 | } |
| 193 | 208 | |
| 194 | 209 | public function validateIpList($white_list) { |
| 195 | - $pattern = '/^(\s*(?:\d{1,3}\.){3}\d{1,3}\s*(?:,\s*|$))+$/'; | |
| 196 | - | |
| 197 | - if ( preg_match( $pattern, $white_list ) ) { | |
| 198 | - return true; | |
| 210 | + $ips = explode(',', $white_list); | |
| 211 | + foreach ($ips as $ip) { | |
| 212 | + $ip = trim($ip); | |
| 213 | + if (!filter_var($ip, FILTER_VALIDATE_IP)) { | |
| 214 | + return false; | |
| 215 | + } | |
| 199 | 216 | } |
| 200 | - return false; | |
| 217 | + return true; | |
| 218 | + } | |
| 201 | 219 | |
| 220 | + public function send_credentials_email($username, $password) { | |
| 221 | + $admin_email = get_option('admin_email'); | |
| 222 | + $site_url = home_url(); | |
| 223 | + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/'; | |
| 224 | + | |
| 225 | + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication'); | |
| 226 | + | |
| 227 | + $message = '<html><body>'; | |
| 228 | + $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>'; | |
| 229 | + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>'; | |
| 230 | + $message .= '<ul style="list-style-type: none; padding-left: 0;">' . | |
| 231 | + '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' . | |
| 232 | + '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' . | |
| 233 | + '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . esc_html($password) . '</strong></li>' . | |
| 234 | + '</ul>'; | |
| 235 | + $message .= '<p>' . sprintf( | |
| 236 | + /* translators: tag "a" and link */ | |
| 237 | + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'), | |
| 238 | + '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>' | |
| 239 | + ) . '</p>'; | |
| 240 | + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>'; | |
| 241 | + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>'; | |
| 242 | + $message .= '</body></html>'; | |
| 243 | + | |
| 244 | + $headers = array( | |
| 245 | + 'Content-Type: text/html; charset=UTF-8', | |
| 246 | + 'From: ' . $admin_email, | |
| 247 | + ); | |
| 248 | + | |
| 249 | + wp_mail($admin_email, $subject, $message, $headers); | |
| 202 | 250 | } |
| 251 | + | |
| 252 | + | |
| 203 | 253 | } |