PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 4.1.0
Easy Basic Authentication – Add basic auth to site or admin area v4.1.0
4.1.0 trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 All 51 releases
easy-basic-authentication / class / easy-basic-authentication-form-class.php

easy-basic-authentication-form-class.php in Easy Basic Authentication – Add basic auth to site or admin area 4.1.0, at class/easy-basic-authentication-form-class.php

303 lines 14.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 class easy_basic_authentication_form_class {
4
5 public $form_field = [];
6
7 public function __construct()
8 {
9 $this->form_field = array(
10 '0' => array(
11 'id' => 'basic-auth-plugin-admin-enable',
12 'title' => __('Enable for wp-admin', 'easy-basic-authentication'),
13 'callback' => 'basic_auth_plugin_admin_enable_cb',
14 ),
15 '1' => array(
16 'id' => 'basic-auth-plugin-enable',
17 'title' => __('Enable for the entire site (only if wp-admin is enabled)', 'easy-basic-authentication'),
18 'callback' => 'basic_auth_plugin_enable_cb',
19 ),
20 '2' => array(
21 'id' => 'basic-auth-plugin-username',
22 'title' => __('Username', 'easy-basic-authentication'),
23 'callback' => 'basic_auth_plugin_username_cb',
24 ),
25 '3' => array(
26 'id' => 'basic-auth-plugin-password',
27 'title' => __('Password', 'easy-basic-authentication'),
28 'callback' => 'basic_auth_plugin_password_cb',
29 ),
30 '4' => array(
31 'id' => 'basic-auth-plugin-admin-log-enable',
32 'title' => __('Enable access logs', 'easy-basic-authentication'),
33 'callback' => 'basic_auth_plugin_admin_log_enable_cb',
34 ),
35 '5' => array(
36 'id' => 'basic-auth-plugin-alert-enable',
37 'title' => __('Enable email alert', 'easy-basic-authentication'),
38 'callback' => 'basic_auth_plugin_alert_enable_cb',
39 ),
40 '6' => array(
41 'id' => 'basic-auth-plugin-email-alert',
42 'title' => __('Email for alert', 'easy-basic-authentication'),
43 'callback' => 'basic_auth_plugin_alertemail_cb',
44 ),
45 '7' => array(
46 'id' => 'basic-auth-plugin-white-list',
47 'title' => __('Ip White list', 'easy-basic-authentication'),
48 'callback' => 'basic_auth_plugin_whitelist_cb',
49 ),
50 '8' => array(
51 'id' => 'basic-auth-plugin-url-white-list',
52 'title' => __('Url White list', 'easy-basic-authentication'),
53 'callback' => 'basic_auth_plugin_urlwhitelist_cb',
54 ),
55 '9' => array(
56 'id' => 'basic-auth-plugin-remove-data-after-uninstall',
57 'title' => __('Remove plugin data after uninstall', 'easy-basic-authentication'),
58 'callback' => 'basic_auth_plugin_remove_data_after_uninstall_cb',
59 ),
60
61 );
62 }
63
64 public function basic_auth_plugin_settings_init() {
65 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable', array( 'sanitize_callback' => 'absint' ) );
66 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable', array( 'sanitize_callback' => 'absint' ) );
67 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username', array( 'sanitize_callback' => 'sanitize_text_field' ) );
68 register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable', array( 'sanitize_callback' => 'absint' ) );
69
70 add_settings_section(
71 'basic-auth-plugin-section',
72 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
73 array($this,'basic_auth_plugin_section_cb'),
74 'basic-auth-plugin-settings'
75 );
76
77 foreach($this->form_field as $field) {
78 add_settings_field(
79 $field['id'],
80 esc_html($field['title']),
81 array($this,$field['callback']),
82 'basic-auth-plugin-settings',
83 'basic-auth-plugin-section'
84 );
85 }
86
87 }
88
89 public function basic_auth_plugin_section_cb() {
90 echo esc_html__('Configure basic authentication', 'easy-basic-authentication');
91 }
92
93 public function basic_auth_plugin_enable_cb() {
94 $admin_enable = get_option( 'basic_auth_plugin_admin_enable' );
95 $enable = get_option( 'basic_auth_plugin_enable' );
96 ?>
97 <input type="checkbox" name="basic_auth_plugin_enable" value="1" <?php checked( $enable, 1 ); ?><?php disabled( !$admin_enable ); ?>>
98 <?php
99 }
100
101 public function basic_auth_plugin_admin_enable_cb() {
102 $enable = get_option( 'basic_auth_plugin_admin_enable' );
103 ?>
104 <input type="checkbox" name="basic_auth_plugin_admin_enable" value="1" <?php checked( $enable, 1 ); ?>>
105 <?php
106 }
107
108 public function basic_auth_plugin_username_cb() {
109 $username = get_option( 'basic_auth_plugin_username' );
110 $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
111 }
112
113 public function basic_auth_plugin_password_cb() {
114 $password = get_option( 'basic_auth_plugin_password' );
115 ?>
116 <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off">
117 <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p>
118 <?php
119 }
120
121 public function basic_auth_plugin_admin_log_enable_cb() {
122 $enable = get_option( 'basic_auth_plugin_admin_log_enable' );
123 ?>
124 <input type="checkbox" name="basic_auth_plugin_admin_log_enable" value="1" <?php checked( $enable, 1 ); ?>>
125 <?php
126 }
127
128 public function basic_auth_plugin_alert_enable_cb() {
129 $enable = get_option( 'basic_auth_plugin_alert_enable' );
130 ?>
131 <input type="checkbox" name="basic_auth_plugin_alert_enable" value="1" <?php checked( $enable, 1 ); ?>>
132 <?php
133 }
134
135 public function basic_auth_plugin_alertemail_cb() {
136 $email_alert = get_option( 'basic_auth_plugin_alertemail' );
137 $this->printInputText("text","basic_auth_plugin_alertemail",esc_attr( $email_alert ),__('Enter the email', 'easy-basic-authentication'));
138 }
139
140 public function basic_auth_plugin_whitelist_cb() {
141 $white_list = get_option( 'basic_auth_plugin_whitelist' );
142 $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma. Ex. 127.0.0.1, 1.1.1.1/20, 1.1.0.0 - 1.1.0.255', 'easy-basic-authentication'));
143 }
144
145 public function basic_auth_plugin_urlwhitelist_cb() {
146 $white_list = get_option( 'basic_auth_plugin_urlwhitelist' );
147 $this->printInputText("text","basic_auth_plugin_urlwhitelist",esc_attr( $white_list ),__('Url white list, separated by comma. Ex. /json/wp-, www.google.it,', 'easy-basic-authentication'));
148 }
149
150 public function basic_auth_plugin_remove_data_after_uninstall_cb() {
151 $enable = get_option( 'basic_auth_plugin_remove_data_after_uninstall' );
152 ?>
153 <input type="checkbox" name="basic_auth_plugin_remove_data_after_uninstall" value="1" <?php checked( $enable, 1 ); ?>>
154 <?php
155 }
156
157 public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
158 echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
159 }
160
161
162 public function basic_auth_plugin_save_settings($param) {
163 if ( isset( $param['eba_submit'] ) ) {
164 if ( ! isset( $param['_wpnonce'] ) || ! wp_verify_nonce( $param['_wpnonce'], 'basic-auth-plugin-settings-options' ) ) {
165 return;
166 }
167 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
168 $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0;
169 $username = sanitize_text_field( $param['basic_auth_plugin_username'] );
170 $password = isset( $param['basic_auth_plugin_password'] ) ? wp_unslash( $param['basic_auth_plugin_password'] ) : '';
171 $log_enable = isset( $param['basic_auth_plugin_admin_log_enable'] ) ? 1 : 0;
172 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
173 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
174 $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
175 $remove_data = isset( $param['basic_auth_plugin_remove_data_after_uninstall'] ) ? 1 : 0;
176 $url_white_list = sanitize_text_field( $param['basic_auth_plugin_urlwhitelist'] );
177
178 if ( empty( $username ) ) {
179 add_settings_error(
180 'basic_auth_plugin_username',
181 'basic_auth_plugin_username_error',
182 __('Username cannot be empty', 'easy-basic-authentication'),
183 'error'
184 );
185 return;
186 }
187
188 if ( ! empty( $password ) ) {
189 $hashed_password = wp_hash_password( $password );
190 update_option( 'basic_auth_plugin_password', $hashed_password );
191 }
192
193 if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
194 update_option( 'basic_auth_plugin_alertemail', $alert_email );
195 } else {
196 add_settings_error(
197 'basic_auth_plugin_alertemail',
198 'basic_auth_plugin_alertemail_error',
199 __('Invalid email address', 'easy-basic-authentication'),
200 'error'
201 );
202 return;
203 }
204
205 update_option( 'basic_auth_plugin_admin_enable', $admin_enable );
206 update_option( 'basic_auth_plugin_enable', $enable );
207 update_option( 'basic_auth_plugin_username', $username );
208 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
209 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
210 update_option( 'basic_auth_plugin_remove_data_after_uninstall', $remove_data );
211 update_option( 'basic_auth_plugin_urlwhitelist', $url_white_list );
212
213 if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
214 update_option( 'basic_auth_plugin_whitelist', $white_list );
215 } else {
216 add_settings_error(
217 'basic_auth_plugin_whitelist',
218 'basic_auth_plugin_whitelist_error',
219 __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
220 'error'
221 );
222 return;
223
224 }
225
226 $this->send_credentials_email($username, $password);
227 }
228 }
229
230 public function basic_auth_plugin_settings_page() {
231 include plugin_dir_path( __FILE__ ) . '../template/settings_page.php';
232 }
233
234 public function validateIpList($white_list) {
235 $ips = explode(',', $white_list);
236 foreach ($ips as $ip) {
237 $ip = trim($ip);
238
239 // �
240 Valida IP singoli
241 if (filter_var($ip, FILTER_VALIDATE_IP)) {
242 continue;
243 }
244
245 // �
246 Valida subnet CIDR (es. 1.1.1.1/20)
247 if (preg_match('/^(\d{1,3}\.){3}\d{1,3}\/\d{1,2}$/', $ip)) {
248 list($subnet, $mask) = explode('/', $ip);
249 if (filter_var($subnet, FILTER_VALIDATE_IP) && $mask >= 0 && $mask <= 32) {
250 continue;
251 }
252 }
253
254 // �
255 Valida range IP (es. 1.1.0.0 - 1.1.0.255)
256 if (preg_match('/^(\d{1,3}\.){3}\d{1,3}\s*-\s*(\d{1,3}\.){3}\d{1,3}$/', $ip)) {
257 list($start_ip, $end_ip) = array_map('trim', explode('-', $ip));
258 if (filter_var($start_ip, FILTER_VALIDATE_IP) && filter_var($end_ip, FILTER_VALIDATE_IP)) {
259 continue;
260 }
261 }
262
263 // ❌ Se non passa nessuna validazione, ritorna false
264 return false;
265 }
266
267 return true;
268 }
269
270 public function send_credentials_email($username, $password) {
271 $admin_email = get_option('admin_email');
272 $site_url = home_url();
273 $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
274
275 $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
276
277 $message = '<html><body>';
278 $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>';
279 $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
280 $message .= '<ul style="list-style-type: none; padding-left: 0;">' .
281 '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' .
282 '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' .
283 '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . __('[updated — not shown for security]', 'easy-basic-authentication') . '</strong></li>' .
284 '</ul>';
285 $message .= '<p>' . sprintf(
286 /* translators: tag "a" and link */
287 __('For more information about this plugin, visit: %s', 'easy-basic-authentication'),
288 '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>'
289 ) . '</p>';
290 $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
291 $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
292 $message .= '</body></html>';
293
294 $headers = array(
295 'Content-Type: text/html; charset=UTF-8',
296 'From: ' . $admin_email,
297 );
298
299 wp_mail($admin_email, $subject, $message, $headers);
300 }
301
302
303 }