PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 3.0
Easy Basic Authentication – Add basic auth to site or admin area v3.0
trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 1.9 All 50 releases
← All changes | class/easy-basic-authentication-form-class.php +129 -75 1.63.0 View file →
@@ -1,54 +1,54 @@
1 1 <?php
2 2
3 3 class easy_basic_authentication_form_class {
4 4
5 - const FORM_FIELD = array(
6 - '0' => array(
7 - 'id' => 'basic-auth-plugin-admin-enable',
8 - 'title' => 'Enable for wp-admin',
9 - 'callback' => 'basic_auth_plugin_admin_enable_cb',
10 - ),
11 - '1' => array(
12 - 'id' => 'basic-auth-plugin-enable',
13 - 'title' => 'Enable for the entire site (only if wp-admin is enabled)',
14 - 'callback' => 'basic_auth_plugin_enable_cb',
15 - ),
16 - '2' => array(
17 - 'id' => 'basic-auth-plugin-username',
18 - 'title' => 'Username',
19 - 'callback' => 'basic_auth_plugin_username_cb',
20 - ),
21 - '3' => array(
22 - 'id' => 'basic-auth-plugin-password',
23 - 'title' => 'Password',
24 - 'callback' => 'basic_auth_plugin_password_cb',
25 - ),
26 - '4' => array(
27 - 'id' => 'basic-auth-plugin-admin-log-enable',
28 - 'title' => 'Enable access logs',
29 - 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
30 - ),
31 - '5' => array(
32 - 'id' => 'basic-auth-plugin-alert-enable',
33 - 'title' => 'Enable email alert',
34 - 'callback' => 'basic_auth_plugin_alert_enable_cb',
35 - ),
36 - '6' => array(
37 - 'id' => 'basic-auth-plugin-email-alert',
38 - 'title' => 'Email for alert',
39 - 'callback' => 'basic_auth_plugin_alertemail_cb',
40 - ),
41 - '7' => array(
42 - 'id' => 'basic-auth-plugin-white-list',
43 - 'title' => 'Ip White list',
44 - 'callback' => 'basic_auth_plugin_whitelist_cb',
45 - )
46 - );
5 + public $form_field = [];
47 6
48 7 public function __construct()
49 - {
50 -
8 + {
9 + $this->form_field = array(
10 + '0' => array(
11 + 'id' => 'basic-auth-plugin-admin-enable',
12 + 'title' => __('Enable for wp-admin', 'easy-basic-authentication'),
13 + 'callback' => 'basic_auth_plugin_admin_enable_cb',
14 + ),
15 + '1' => array(
16 + 'id' => 'basic-auth-plugin-enable',
17 + 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
18 + 'callback' => 'basic_auth_plugin_enable_cb',
19 + ),
20 + '2' => array(
21 + 'id' => 'basic-auth-plugin-username',
22 + 'title' => __('Username', 'easy-basic-authentication'),
23 + 'callback' => 'basic_auth_plugin_username_cb',
24 + ),
25 + '3' => array(
26 + 'id' => 'basic-auth-plugin-password',
27 + 'title' => __('Password', 'easy-basic-authentication'),
28 + 'callback' => 'basic_auth_plugin_password_cb',
29 + ),
30 + '4' => array(
31 + 'id' => 'basic-auth-plugin-admin-log-enable',
32 + 'title' => __('Enable access logs', 'easy-basic-authentication'),
33 + 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
34 + ),
35 + '5' => array(
36 + 'id' => 'basic-auth-plugin-alert-enable',
37 + 'title' => __('Enable email alert', 'easy-basic-authentication'),
38 + 'callback' => 'basic_auth_plugin_alert_enable_cb',
39 + ),
40 + '6' => array(
41 + 'id' => 'basic-auth-plugin-email-alert',
42 + 'title' => __('Email for alert', 'easy-basic-authentication'),
43 + 'callback' => 'basic_auth_plugin_alertemail_cb',
44 + ),
45 + '7' => array(
46 + 'id' => 'basic-auth-plugin-white-list',
47 + 'title' => __('Ip White list', 'easy-basic-authentication'),
48 + 'callback' => 'basic_auth_plugin_whitelist_cb',
49 + )
50 + );
51 51 }
52 52
53 53 public function basic_auth_plugin_settings_init() {
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
@@ -54,9 +54,8 @@
54 54 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
55 55 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' );
56 56 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' );
57 57 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' );
58 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_whitelist' );
59 58
60 59 add_settings_section(
61 60 'basic-auth-plugin-section',
62 61 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
@@ -63,12 +62,12 @@
63 62 array($this,'basic_auth_plugin_section_cb'),
64 63 'basic-auth-plugin-settings'
65 64 );
66 65
67 - foreach(self::FORM_FIELD as $field) {
66 + foreach($this->form_field as $field) {
68 67 add_settings_field(
69 68 $field['id'],
70 - __($field['title'], 'easy-basic-authentication'),
69 + esc_html($field['title']),
71 70 array($this,$field['callback']),
72 71 'basic-auth-plugin-settings',
73 72 'basic-auth-plugin-section'
74 73 );
@@ -76,9 +75,9 @@
76 75
77 76 }
78 77
79 78 public function basic_auth_plugin_section_cb() {
80 - echo __('Configure basic authentication', 'easy-basic-authentication');
79 + echo esc_html__('Configure basic authentication', 'easy-basic-authentication');
81 80 }
82 81
83 82 public function basic_auth_plugin_enable_cb() {
84 83 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
@@ -96,16 +95,17 @@
96 95 }
97 96
98 97 public function basic_auth_plugin_username_cb() {
99 98 $username = get_option( 'basic_auth_plugin_username' );
100 - $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ));
99 + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
101 100 }
102 101
103 102 public function basic_auth_plugin_password_cb() {
104 - $password = get_option( 'basic_auth_plugin_password' )
105 - ? __('Password entered', 'easy-basic-authentication')
106 - : __('Enter the password', 'easy-basic-authentication');
107 - $this->printInputText("password","basic_auth_plugin_password",'',$password);
103 + $password = get_option( 'basic_auth_plugin_password' );
104 + ?>
105 + <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off">
106 + <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p>
107 + <?php
108 108 }
109 109
110 110 public function basic_auth_plugin_admin_log_enable_cb() {
111 111 $enable = get_option( 'basic_auth_plugin_admin_log_enable' );
@@ -130,11 +130,12 @@
130 130 $white_list = get_option( 'basic_auth_plugin_whitelist' );
131 131 $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication'));
132 132 }
133 133
134 - public function printInputText($tipe, $name, $value='', $placeholder = '') {
135 - echo "<input type='$tipe' name='$name' value='$value' placeholder='$placeholder'>";
134 + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
135 + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
136 136 }
137 +
137 138
138 139 public function basic_auth_plugin_save_settings($param) {
139 140 if ( isset( $param['eba_submit'] ) ) {
140 141 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
@@ -145,17 +146,33 @@
145 146 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
146 147 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
147 148 $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
148 149
149 - if ( !is_email( $alert_email ) ) {
150 + if ( empty( $username ) ) {
150 151 add_settings_error(
152 + 'basic_auth_plugin_username',
153 + 'basic_auth_plugin_username_error',
154 + __('Username cannot be empty', 'easy-basic-authentication'),
155 + 'error'
156 + );
157 + return;
158 + }
159 +
160 + if ( ! empty( $password ) ) {
161 + $hashed_password = wp_hash_password( $password );
162 + update_option( 'basic_auth_plugin_password', $hashed_password );
163 + }
164 +
165 + if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
166 + update_option( 'basic_auth_plugin_alertemail', $alert_email );
167 + } else {
168 + add_settings_error(
151 169 'basic_auth_plugin_alertemail',
152 170 'basic_auth_plugin_alertemail_error',
153 171 __('Invalid email address', 'easy-basic-authentication'),
154 172 'error'
155 173 );
156 - } else {
157 - update_option( 'basic_auth_plugin_alertemail', $alert_email );
174 + return;
158 175 }
159 176
160 177 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
161 178 update_option( 'basic_auth_plugin_enable', $enable );
@@ -161,26 +178,28 @@
161 178 update_option( 'basic_auth_plugin_enable', $enable );
162 179 update_option( 'basic_auth_plugin_username', $username );
163 180 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
164 181 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
165 -
166 182
167 - if (strlen($white_list)) {
168 - if( $this->validateIpList( $white_list ) ) {
169 - update_option( 'basic_auth_plugin_whitelist', $white_list );
170 - } else {
171 - add_settings_error(
172 - 'basic_auth_plugin_whitelist',
173 - 'basic_auth_plugin_whitelist_error',
174 - __('Invalid whitelist format. Please enter valid ip addresses separated by commas.', 'easy-basic-authentication'),
175 - 'error'
176 - );
177 - }
183 + if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
184 + update_option( 'basic_auth_plugin_whitelist', $white_list );
185 + } else {
186 + add_settings_error(
187 + 'basic_auth_plugin_whitelist',
188 + 'basic_auth_plugin_whitelist_error',
189 + __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
190 + 'error'
191 + );
192 + return;
193 +
178 194 }
195 +
179 196 if ( ! empty( $password ) ) {
180 197 $hashed_password = wp_hash_password( $password );
181 198 update_option( 'basic_auth_plugin_password', $hashed_password );
182 199 }
200 +
201 + $this->send_credentials_email($username, $password);
183 202 }
184 203 }
185 204
186 205 public function basic_auth_plugin_settings_page() {
@@ -187,13 +206,48 @@
187 206 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
188 207 }
189 208
190 209 public function validateIpList($white_list) {
191 - $pattern = '/^(\s*(?:\d{1,3}\.){3}\d{1,3}\s*(?:,\s*|$))+$/';
192 -
193 - if ( preg_match( $pattern, $white_list ) ) {
194 - return true;
210 + $ips = explode(',', $white_list);
211 + foreach ($ips as $ip) {
212 + $ip = trim($ip);
213 + if (!filter_var($ip, FILTER_VALIDATE_IP)) {
214 + return false;
215 + }
195 216 }
196 - return false;
217 + return true;
218 + }
197 219
220 + public function send_credentials_email($username, $password) {
221 + $admin_email = get_option('admin_email');
222 + $site_url = home_url();
223 + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
224 +
225 + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
226 +
227 + $message = '<html><body>';
228 + $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>';
229 + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
230 + $message .= '<ul style="list-style-type: none; padding-left: 0;">' .
231 + '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' .
232 + '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' .
233 + '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . esc_html($password) . '</strong></li>' .
234 + '</ul>';
235 + $message .= '<p>' . sprintf(
236 + /* translators: tag "a" and link */
237 + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'),
238 + '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>'
239 + ) . '</p>';
240 + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
241 + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
242 + $message .= '</body></html>';
243 +
244 + $headers = array(
245 + 'Content-Type: text/html; charset=UTF-8',
246 + 'From: ' . $admin_email,
247 + );
248 +
249 + wp_mail($admin_email, $subject, $message, $headers);
198 250 }
251 +
252 +
199 253 }