PluginProbe
Easy Basic Authentication – Add basic auth to site or admin area / 4.1.0
Easy Basic Authentication – Add basic auth to site or admin area v4.1.0
4.1.0 trunk 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.4 1.4.1 1.5 1.5.1 1.5.2 1.5.3 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.7 1.7.1 1.8 1.8.1 All 51 releases
← All changes | class/easy-basic-authentication-form-class.php +121 -20 1.74.1.0 View file →
@@ -45,17 +45,28 @@
45 45 '7' => array(
46 46 'id' => 'basic-auth-plugin-white-list',
47 47 'title' => __('Ip White list', 'easy-basic-authentication'),
48 48 'callback' => 'basic_auth_plugin_whitelist_cb',
49 - )
49 + ),
50 + '8' => array(
51 + 'id' => 'basic-auth-plugin-url-white-list',
52 + 'title' => __('Url White list', 'easy-basic-authentication'),
53 + 'callback' => 'basic_auth_plugin_urlwhitelist_cb',
54 + ),
55 + '9' => array(
56 + 'id' => 'basic-auth-plugin-remove-data-after-uninstall',
57 + 'title' => __('Remove plugin data after uninstall', 'easy-basic-authentication'),
58 + 'callback' => 'basic_auth_plugin_remove_data_after_uninstall_cb',
59 + ),
60 +
50 61 );
51 62 }
52 63
53 64 public function basic_auth_plugin_settings_init() {
54 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' );
55 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' );
56 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' );
57 - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' );
65 + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable', array( 'sanitize_callback' => 'absint' ) );
66 + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable', array( 'sanitize_callback' => 'absint' ) );
67 + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username', array( 'sanitize_callback' => 'sanitize_text_field' ) );
68 + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable', array( 'sanitize_callback' => 'absint' ) );
58 69
59 70 add_settings_section(
60 71 'basic-auth-plugin-section',
61 72 __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'),
@@ -95,16 +106,17 @@
95 106 }
96 107
97 108 public function basic_auth_plugin_username_cb() {
98 109 $username = get_option( 'basic_auth_plugin_username' );
99 - $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ));
110 + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off');
100 111 }
101 112
102 113 public function basic_auth_plugin_password_cb() {
103 - $password = get_option( 'basic_auth_plugin_password' )
104 - ? __('Password entered', 'easy-basic-authentication')
105 - : __('Enter the password', 'easy-basic-authentication');
106 - $this->printInputText("password","basic_auth_plugin_password",'',$password);
114 + $password = get_option( 'basic_auth_plugin_password' );
115 + ?>
116 + <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off">
117 + <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p>
118 + <?php
107 119 }
108 120
109 121 public function basic_auth_plugin_admin_log_enable_cb() {
110 122 $enable = get_option( 'basic_auth_plugin_admin_log_enable' );
@@ -126,26 +138,59 @@
126 138 }
127 139
128 140 public function basic_auth_plugin_whitelist_cb() {
129 141 $white_list = get_option( 'basic_auth_plugin_whitelist' );
130 - $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication'));
142 + $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma. Ex. 127.0.0.1, 1.1.1.1/20, 1.1.0.0 - 1.1.0.255', 'easy-basic-authentication'));
131 143 }
144 +
145 + public function basic_auth_plugin_urlwhitelist_cb() {
146 + $white_list = get_option( 'basic_auth_plugin_urlwhitelist' );
147 + $this->printInputText("text","basic_auth_plugin_urlwhitelist",esc_attr( $white_list ),__('Url white list, separated by comma. Ex. /json/wp-, www.google.it,', 'easy-basic-authentication'));
148 + }
132 149
133 - public function printInputText($tipe, $name, $value='', $placeholder = '') {
134 - echo "<input type='" . esc_attr($tipe) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "'>";
150 + public function basic_auth_plugin_remove_data_after_uninstall_cb() {
151 + $enable = get_option( 'basic_auth_plugin_remove_data_after_uninstall' );
152 + ?>
153 + <input type="checkbox" name="basic_auth_plugin_remove_data_after_uninstall" value="1" <?php checked( $enable, 1 ); ?>>
154 + <?php
135 155 }
136 156
157 + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') {
158 + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >";
159 + }
160 +
161 +
137 162 public function basic_auth_plugin_save_settings($param) {
138 163 if ( isset( $param['eba_submit'] ) ) {
164 + if ( ! isset( $param['_wpnonce'] ) || ! wp_verify_nonce( $param['_wpnonce'], 'basic-auth-plugin-settings-options' ) ) {
165 + return;
166 + }
139 167 $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0;
140 168 $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0;
141 169 $username = sanitize_text_field( $param['basic_auth_plugin_username'] );
142 - $password = sanitize_text_field( $param['basic_auth_plugin_password'] );
170 + $password = isset( $param['basic_auth_plugin_password'] ) ? wp_unslash( $param['basic_auth_plugin_password'] ) : '';
143 171 $log_enable = isset( $param['basic_auth_plugin_admin_log_enable'] ) ? 1 : 0;
144 172 $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0;
145 173 $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] );
146 174 $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] );
175 + $remove_data = isset( $param['basic_auth_plugin_remove_data_after_uninstall'] ) ? 1 : 0;
176 + $url_white_list = sanitize_text_field( $param['basic_auth_plugin_urlwhitelist'] );
147 177
178 + if ( empty( $username ) ) {
179 + add_settings_error(
180 + 'basic_auth_plugin_username',
181 + 'basic_auth_plugin_username_error',
182 + __('Username cannot be empty', 'easy-basic-authentication'),
183 + 'error'
184 + );
185 + return;
186 + }
187 +
188 + if ( ! empty( $password ) ) {
189 + $hashed_password = wp_hash_password( $password );
190 + update_option( 'basic_auth_plugin_password', $hashed_password );
191 + }
192 +
148 193 if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) {
149 194 update_option( 'basic_auth_plugin_alertemail', $alert_email );
150 195 } else {
151 196 add_settings_error(
@@ -161,8 +206,10 @@
161 206 update_option( 'basic_auth_plugin_enable', $enable );
162 207 update_option( 'basic_auth_plugin_username', $username );
163 208 update_option( 'basic_auth_plugin_admin_log_enable', $log_enable );
164 209 update_option( 'basic_auth_plugin_alert_enable', $alert_enable );
210 + update_option( 'basic_auth_plugin_remove_data_after_uninstall', $remove_data );
211 + update_option( 'basic_auth_plugin_urlwhitelist', $url_white_list );
165 212
166 213 if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) {
167 214 update_option( 'basic_auth_plugin_whitelist', $white_list );
168 215 } else {
@@ -172,14 +219,12 @@
172 219 __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'),
173 220 'error'
174 221 );
175 222 return;
223 +
176 224 }
177 225
178 - if ( ! empty( $password ) ) {
179 - $hashed_password = wp_hash_password( $password );
180 - update_option( 'basic_auth_plugin_password', $hashed_password );
181 - }
226 + $this->send_credentials_email($username, $password);
182 227 }
183 228 }
184 229
185 230 public function basic_auth_plugin_settings_page() {
@@ -189,11 +234,67 @@
189 234 public function validateIpList($white_list) {
190 235 $ips = explode(',', $white_list);
191 236 foreach ($ips as $ip) {
192 237 $ip = trim($ip);
193 - if (!filter_var($ip, FILTER_VALIDATE_IP)) {
194 - return false;
238 +
239 + // ✅ Valida IP singoli
240 + if (filter_var($ip, FILTER_VALIDATE_IP)) {
241 + continue;
195 242 }
243 +
244 + // ✅ Valida subnet CIDR (es. 1.1.1.1/20)
245 + if (preg_match('/^(\d{1,3}\.){3}\d{1,3}\/\d{1,2}$/', $ip)) {
246 + list($subnet, $mask) = explode('/', $ip);
247 + if (filter_var($subnet, FILTER_VALIDATE_IP) && $mask >= 0 && $mask <= 32) {
248 + continue;
249 + }
250 + }
251 +
252 + // ✅ Valida range IP (es. 1.1.0.0 - 1.1.0.255)
253 + if (preg_match('/^(\d{1,3}\.){3}\d{1,3}\s*-\s*(\d{1,3}\.){3}\d{1,3}$/', $ip)) {
254 + list($start_ip, $end_ip) = array_map('trim', explode('-', $ip));
255 + if (filter_var($start_ip, FILTER_VALIDATE_IP) && filter_var($end_ip, FILTER_VALIDATE_IP)) {
256 + continue;
257 + }
258 + }
259 +
260 + // ❌ Se non passa nessuna validazione, ritorna false
261 + return false;
196 262 }
263 +
197 264 return true;
198 265 }
266 +
267 + public function send_credentials_email($username, $password) {
268 + $admin_email = get_option('admin_email');
269 + $site_url = home_url();
270 + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/';
271 +
272 + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication');
273 +
274 + $message = '<html><body>';
275 + $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>';
276 + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>';
277 + $message .= '<ul style="list-style-type: none; padding-left: 0;">' .
278 + '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' .
279 + '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' .
280 + '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . __('[updated — not shown for security]', 'easy-basic-authentication') . '</strong></li>' .
281 + '</ul>';
282 + $message .= '<p>' . sprintf(
283 + /* translators: tag "a" and link */
284 + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'),
285 + '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>'
286 + ) . '</p>';
287 + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>';
288 + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>';
289 + $message .= '</body></html>';
290 +
291 + $headers = array(
292 + 'Content-Type: text/html; charset=UTF-8',
293 + 'From: ' . $admin_email,
294 + );
295 +
296 + wp_mail($admin_email, $subject, $message, $headers);
297 + }
298 +
299 +
199 300 }