PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 3.0
Easy Basic Authentication – Add basic auth to site or admin area v3.0
trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 1.9 All 50 releases
← All changes | class/easy-basic-authentication-form-class.php +132 -82 1.5.33.0 View file →
@@ -1,54 +1,54 @@
1 1 <?php
2 2
3 3 class easy_basic_authentication_form_class {
4 4
5 - const FORM_FIELD = array(
6 - '0' => array(
7 - 'id' => 'basic-auth-plugin-admin-enable',
8 - 'title' => 'Enable for wp-admin',
9 - 'callback' => 'basic_auth_plugin_admin_enable_cb',
10 - ),
11 - '1' => array(
12 - 'id' => 'basic-auth-plugin-enable',
13 - 'title' => 'Enable for the entire site (only if wp-admin is enabled)',
14 - 'callback' => 'basic_auth_plugin_enable_cb',
15 - ),
16 - '2' => array(
17 - 'id' => 'basic-auth-plugin-username',
18 - 'title' => 'Username',
19 - 'callback' => 'basic_auth_plugin_username_cb',
20 - ),
21 - '3' => array(
22 - 'id' => 'basic-auth-plugin-password',
23 - 'title' => 'Password',
24 - 'callback' => 'basic_auth_plugin_password_cb',
25 - ),
26 - '4' => array(
27 - 'id' => 'basic-auth-plugin-admin-log-enable',
28 - 'title' => 'Enable access logs',
29 - 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
30 - ),
31 - '5' => array(
32 - 'id' => 'basic-auth-plugin-alert-enable',
33 - 'title' => 'Enable email alert',
34 - 'callback' => 'basic_auth_plugin_alert_enable_cb',
35 - ),
36 - '6' => array(
37 - 'id' => 'basic-auth-plugin-email-alert',
38 - 'title' => 'Email for alert',
39 - 'callback' => 'basic_auth_plugin_alertemail_cb',
40 - ),
41 - '7' => array(
42 - 'id' => 'basic-auth-plugin-white-list',
43 - 'title' => 'Ip White list',
44 - 'callback' => 'basic_auth_plugin_whitelist_cb',
45 - )
46 - );
5 + public $form_field = [];
47 6
48 7 public function __construct()
49 - {
50 -
8 + {
9 + $this->form_field = array(
10 + '0' => array(
11 + 'id' => 'basic-auth-plugin-admin-enable',
12 + 'title' => __('Enable for wp-admin', 'easy-basic-authentication'),
13 + 'callback' => 'basic_auth_plugin_admin_enable_cb',
14 + ),
15 + '1' => array(
16 + 'id' => 'basic-auth-plugin-enable',
17 + 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
18 + 'callback' => 'basic_auth_plugin_enable_cb',
19 + ),
20 + '2' => array(
21 + 'id' => 'basic-auth-plugin-username',
22 + 'title' => __('Username', 'easy-basic-authentication'),
23 + 'callback' => 'basic_auth_plugin_username_cb',
24 + ),
25 + '3' => array(
26 + 'id' => 'basic-auth-plugin-password',
27 + 'title' => __('Password', 'easy-basic-authentication'),
28 + 'callback' => 'basic_auth_plugin_password_cb',
29 + ),
30 + '4' => array(
31 + 'id' => 'basic-auth-plugin-admin-log-enable',
32 + 'title' => __('Enable access logs', 'easy-basic-authentication'),
33 + 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
34 + ),
35 + '5' => array(
36 + 'id' => 'basic-auth-plugin-alert-enable',
37 + 'title' => __('Enable email alert', 'easy-basic-authentication'),
38 + 'callback' => 'basic_auth_plugin_alert_enable_cb',
39 + ),
40 + '6' => array(
41 + 'id' => 'basic-auth-plugin-email-alert',
42 + 'title' => __('Email for alert', 'easy-basic-authentication'),
43 + 'callback' => 'basic_auth_plugin_alertemail_cb',
44 + ),
45 + '7' => array(
46 + 'id' => 'basic-auth-plugin-white-list',
47 + 'title' => __('Ip White list', 'easy-basic-authentication'),
48 + 'callback' => 'basic_auth_plugin_whitelist_cb',
49 + )
50 + );
51 51 }
52 52
53 53 public function basic_auth_plugin_settings_init() {
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
@@ -54,9 +54,8 @@
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
55 55 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' );
56 56 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' );
57 57 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' );
58 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_whitelist' );
59 58
60 59 add_settings_section(
61 60 'basic-auth-plugin-section',
62 61 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
@@ -63,12 +62,12 @@
63 62 array($this,'basic_auth_plugin_section_cb'),
64 63 'basic-auth-plugin-settings'
65 64 );
66 65
67 - foreach(self::FORM_FIELD as $field) {
66 + foreach($this->form_field as $field) {
68 67 add_settings_field(
69 68 $field['id'],
70 - __($field['title'], 'easy-basic-authentication'),
69 + esc_html($field['title']),
71 70 array($this,$field['callback']),
72 71 'basic-auth-plugin-settings',
73 72 'basic-auth-plugin-section'
74 73 );
@@ -76,9 +75,9 @@
76 75
77 76 }
78 77
79 78 public function basic_auth_plugin_section_cb() {
80 - echo __('Configure basic authentication', 'easy-basic-authentication');
79 + echo esc_html__('Configure basic authentication', 'easy-basic-authentication');
81 80 }
82 81
83 82 public function basic_auth_plugin_enable_cb() {
84 83 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
@@ -96,19 +95,16 @@
96 95 }
97 96
98 97 public function basic_auth_plugin_username_cb() {
99 98 $username = get_option( 'basic_auth_plugin_username' );
100 - ?>
101 - <input type="text" name="basic_auth_plugin_username" value="<?php echo esc_attr( $username ); ?>">
102 - <?php
99 + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
103 100 }
104 101
105 102 public function basic_auth_plugin_password_cb() {
106 - $password = get_option( 'basic_auth_plugin_password' )
107 - ? __('Password entered', 'easy-basic-authentication')
108 - : __('Enter the password', 'easy-basic-authentication');
103 + $password = get_option( 'basic_auth_plugin_password' );
109 104 ?>
110 - <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php echo $password; ?>">
105 + <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off">
106 + <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p>
111 107 <?php
112 108 }
113 109
114 110 public function basic_auth_plugin_admin_log_enable_cb() {
@@ -126,20 +122,21 @@
126 122 }
127 123
128 124 public function basic_auth_plugin_alertemail_cb() {
129 125 $email_alert = get_option( 'basic_auth_plugin_alertemail' );
130 - ?>
131 - <input type="text" name="basic_auth_plugin_alertemail" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('Enter the email', 'easy-basic-authentication'); ?>">
132 - <?php
126 + $this->printInputText("text","basic_auth_plugin_alertemail",esc_attr( $email_alert ),__('Enter the email', 'easy-basic-authentication'));
133 127 }
134 128
135 129 public function basic_auth_plugin_whitelist_cb() {
136 - $email_alert = get_option( 'basic_auth_plugin_whitelist' );
137 - ?>
138 - <input type="text" name="basic_auth_plugin_whitelist" value="<?php echo esc_attr( $email_alert ); ?>" placeholder="<?php echo __('White list, separated by comma', 'easy-basic-authentication'); ?>">
139 - <?php
130 + $white_list = get_option( 'basic_auth_plugin_whitelist' );
131 + $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication'));
140 132 }
141 133
134 + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
135 + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
136 + }
137 +
138 +
142 139 public function basic_auth_plugin_save_settings($param) {
143 140 if ( isset( $param['eba_submit'] ) ) {
144 141 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
145 142 $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0;
@@ -149,17 +146,33 @@
149 146 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
150 147 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
151 148 $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
152 149
153 - if ( !is_email( $alert_email ) ) {
150 + if ( empty( $username ) ) {
154 151 add_settings_error(
152 + 'basic_auth_plugin_username',
153 + 'basic_auth_plugin_username_error',
154 + __('Username cannot be empty', 'easy-basic-authentication'),
155 + 'error'
156 + );
157 + return;
158 + }
159 +
160 + if ( ! empty( $password ) ) {
161 + $hashed_password = wp_hash_password( $password );
162 + update_option( 'basic_auth_plugin_password', $hashed_password );
163 + }
164 +
165 + if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
166 + update_option( 'basic_auth_plugin_alertemail', $alert_email );
167 + } else {
168 + add_settings_error(
155 169 'basic_auth_plugin_alertemail',
156 170 'basic_auth_plugin_alertemail_error',
157 171 __('Invalid email address', 'easy-basic-authentication'),
158 172 'error'
159 173 );
160 - } else {
161 - update_option( 'basic_auth_plugin_alertemail', $alert_email );
174 + return;
162 175 }
163 176
164 177 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
165 178 update_option( 'basic_auth_plugin_enable', $enable );
@@ -165,26 +178,28 @@
165 178 update_option( 'basic_auth_plugin_enable', $enable );
166 179 update_option( 'basic_auth_plugin_username', $username );
167 180 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
168 181 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
169 -
170 182
171 - if (strlen($white_list)) {
172 - if( $this->validateIpList( $white_list ) ) {
173 - update_option( 'basic_auth_plugin_whitelist', $white_list );
174 - } else {
175 - add_settings_error(
176 - 'basic_auth_plugin_whitelist',
177 - 'basic_auth_plugin_whitelist_error',
178 - __('Invalid whitelist format. Please enter valid ip addresses separated by commas.', 'easy-basic-authentication'),
179 - 'error'
180 - );
181 - }
183 + if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
184 + update_option( 'basic_auth_plugin_whitelist', $white_list );
185 + } else {
186 + add_settings_error(
187 + 'basic_auth_plugin_whitelist',
188 + 'basic_auth_plugin_whitelist_error',
189 + __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
190 + 'error'
191 + );
192 + return;
193 +
182 194 }
195 +
183 196 if ( ! empty( $password ) ) {
184 197 $hashed_password = wp_hash_password( $password );
185 198 update_option( 'basic_auth_plugin_password', $hashed_password );
186 199 }
200 +
201 + $this->send_credentials_email($username, $password);
187 202 }
188 203 }
189 204
190 205 public function basic_auth_plugin_settings_page() {
@@ -191,13 +206,48 @@
191 206 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
192 207 }
193 208
194 209 public function validateIpList($white_list) {
195 - $pattern = '/^(\s*(?:\d{1,3}\.){3}\d{1,3}\s*(?:,\s*|$))+$/';
196 -
197 - if ( preg_match( $pattern, $white_list ) ) {
198 - return true;
210 + $ips = explode(',', $white_list);
211 + foreach ($ips as $ip) {
212 + $ip = trim($ip);
213 + if (!filter_var($ip, FILTER_VALIDATE_IP)) {
214 + return false;
215 + }
199 216 }
200 - return false;
217 + return true;
218 + }
201 219
220 + public function send_credentials_email($username, $password) {
221 + $admin_email = get_option('admin_email');
222 + $site_url = home_url();
223 + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
224 +
225 + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
226 +
227 + $message = '<html><body>';
228 + $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>';
229 + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
230 + $message .= '<ul style="list-style-type: none; padding-left: 0;">' .
231 + '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' .
232 + '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' .
233 + '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . esc_html($password) . '</strong></li>' .
234 + '</ul>';
235 + $message .= '<p>' . sprintf(
236 + /* translators: tag "a" and link */
237 + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'),
238 + '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>'
239 + ) . '</p>';
240 + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
241 + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
242 + $message .= '</body></html>';
243 +
244 + $headers = array(
245 + 'Content-Type: text/html; charset=UTF-8',
246 + 'From: ' . $admin_email,
247 + );
248 +
249 + wp_mail($admin_email, $subject, $message, $headers);
202 250 }
251 +
252 +
203 253 }