| @@ -45,17 +45,28 @@ | ||
| 45 | 45 | '7' => array( |
| 46 | 46 | 'id' => 'basic-auth-plugin-white-list', |
| 47 | 47 | 'title' => __('Ip White list', 'easy-basic-authentication'), |
| 48 | 48 | 'callback' => 'basic_auth_plugin_whitelist_cb', |
| 49 | - ) | |
| 49 | + ), | |
| 50 | + '8' => array( | |
| 51 | + 'id' => 'basic-auth-plugin-url-white-list', | |
| 52 | + 'title' => __('Url White list', 'easy-basic-authentication'), | |
| 53 | + 'callback' => 'basic_auth_plugin_urlwhitelist_cb', | |
| 54 | + ), | |
| 55 | + '9' => array( | |
| 56 | + 'id' => 'basic-auth-plugin-remove-data-after-uninstall', | |
| 57 | + 'title' => __('Remove plugin data after uninstall', 'easy-basic-authentication'), | |
| 58 | + 'callback' => 'basic_auth_plugin_remove_data_after_uninstall_cb', | |
| 59 | + ), | |
| 60 | + | |
| 50 | 61 | ); |
| 51 | 62 | } |
| 52 | 63 | |
| 53 | 64 | public function basic_auth_plugin_settings_init() { |
| 54 | - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable' ); | |
| 55 | - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable' ); | |
| 56 | - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username' ); | |
| 57 | - register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable' ); | |
| 65 | + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_enable', array( 'sanitize_callback' => 'absint' ) ); | |
| 66 | + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_enable', array( 'sanitize_callback' => 'absint' ) ); | |
| 67 | + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_username', array( 'sanitize_callback' => 'sanitize_text_field' ) ); | |
| 68 | + register_setting( 'basic-auth-plugin-settings', 'basic_auth_plugin_admin_log_enable', array( 'sanitize_callback' => 'absint' ) ); | |
| 58 | 69 | |
| 59 | 70 | add_settings_section( |
| 60 | 71 | 'basic-auth-plugin-section', |
| 61 | 72 | __('Configurations for Easy Basic Authentication', 'easy-basic-authentication'), |
| @@ -95,16 +106,17 @@ | ||
| 95 | 106 | } |
| 96 | 107 | |
| 97 | 108 | public function basic_auth_plugin_username_cb() { |
| 98 | 109 | $username = get_option( 'basic_auth_plugin_username' ); |
| 99 | - $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username )); | |
| 110 | + $this->printInputText("text","basic_auth_plugin_username",esc_attr( $username ),'','off'); | |
| 100 | 111 | } |
| 101 | 112 | |
| 102 | 113 | public function basic_auth_plugin_password_cb() { |
| 103 | - $password = get_option( 'basic_auth_plugin_password' ) | |
| 104 | - ? __('Password entered', 'easy-basic-authentication') | |
| 105 | - : __('Enter the password', 'easy-basic-authentication'); | |
| 106 | - $this->printInputText("password","basic_auth_plugin_password",'',$password); | |
| 114 | + $password = get_option( 'basic_auth_plugin_password' ); | |
| 115 | + ?> | |
| 116 | + <input type="password" name="basic_auth_plugin_password" value="" placeholder="<?php esc_attr_e('Enter the password', 'easy-basic-authentication'); ?>" autocomplete="off"> | |
| 117 | + <p class="description"><?php esc_html_e('Leave blank to keep the current password.', 'easy-basic-authentication'); ?></p> | |
| 118 | + <?php | |
| 107 | 119 | } |
| 108 | 120 | |
| 109 | 121 | public function basic_auth_plugin_admin_log_enable_cb() { |
| 110 | 122 | $enable = get_option( 'basic_auth_plugin_admin_log_enable' ); |
| @@ -126,26 +138,59 @@ | ||
| 126 | 138 | } |
| 127 | 139 | |
| 128 | 140 | public function basic_auth_plugin_whitelist_cb() { |
| 129 | 141 | $white_list = get_option( 'basic_auth_plugin_whitelist' ); |
| 130 | - $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma', 'easy-basic-authentication')); | |
| 142 | + $this->printInputText("text","basic_auth_plugin_whitelist",esc_attr( $white_list ),__('White list, separated by comma. Ex. 127.0.0.1, 1.1.1.1/20, 1.1.0.0 - 1.1.0.255', 'easy-basic-authentication')); | |
| 131 | 143 | } |
| 144 | + | |
| 145 | + public function basic_auth_plugin_urlwhitelist_cb() { | |
| 146 | + $white_list = get_option( 'basic_auth_plugin_urlwhitelist' ); | |
| 147 | + $this->printInputText("text","basic_auth_plugin_urlwhitelist",esc_attr( $white_list ),__('Url white list, separated by comma. Ex. /json/wp-, www.google.it,', 'easy-basic-authentication')); | |
| 148 | + } | |
| 132 | 149 | |
| 133 | - public function printInputText($tipe, $name, $value='', $placeholder = '') { | |
| 134 | - echo "<input type='" . esc_attr($tipe) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "'>"; | |
| 150 | + public function basic_auth_plugin_remove_data_after_uninstall_cb() { | |
| 151 | + $enable = get_option( 'basic_auth_plugin_remove_data_after_uninstall' ); | |
| 152 | + ?> | |
| 153 | + <input type="checkbox" name="basic_auth_plugin_remove_data_after_uninstall" value="1" <?php checked( $enable, 1 ); ?>> | |
| 154 | + <?php | |
| 135 | 155 | } |
| 136 | 156 | |
| 157 | + public function printInputText($type, $name, $value='', $placeholder = '', $autocomplete = 'off') { | |
| 158 | + echo "<input type='" . esc_attr($type) . "' name='" . esc_attr($name) . "' value='" . esc_attr($value) . "' placeholder='" . esc_attr($placeholder) . "' autocomplete='" . esc_attr($autocomplete) . "' >"; | |
| 159 | + } | |
| 160 | + | |
| 161 | + | |
| 137 | 162 | public function basic_auth_plugin_save_settings($param) { |
| 138 | 163 | if ( isset( $param['eba_submit'] ) ) { |
| 164 | + if ( ! isset( $param['_wpnonce'] ) || ! wp_verify_nonce( $param['_wpnonce'], 'basic-auth-plugin-settings-options' ) ) { | |
| 165 | + return; | |
| 166 | + } | |
| 139 | 167 | $admin_enable = isset( $param['basic_auth_plugin_admin_enable'] ) ? 1 : 0; |
| 140 | 168 | $enable = isset( $param['basic_auth_plugin_enable'] ) ? 1 : 0; |
| 141 | 169 | $username = sanitize_text_field( $param['basic_auth_plugin_username'] ); |
| 142 | - $password = sanitize_text_field( $param['basic_auth_plugin_password'] ); | |
| 170 | + $password = isset( $param['basic_auth_plugin_password'] ) ? wp_unslash( $param['basic_auth_plugin_password'] ) : ''; | |
| 143 | 171 | $log_enable = isset( $param['basic_auth_plugin_admin_log_enable'] ) ? 1 : 0; |
| 144 | 172 | $alert_enable = isset( $param['basic_auth_plugin_alert_enable'] ) ? 1 : 0; |
| 145 | 173 | $alert_email = sanitize_text_field( $param['basic_auth_plugin_alertemail'] ); |
| 146 | 174 | $white_list = sanitize_text_field( $param['basic_auth_plugin_whitelist'] ); |
| 175 | + $remove_data = isset( $param['basic_auth_plugin_remove_data_after_uninstall'] ) ? 1 : 0; | |
| 176 | + $url_white_list = sanitize_text_field( $param['basic_auth_plugin_urlwhitelist'] ); | |
| 147 | 177 | |
| 178 | + if ( empty( $username ) ) { | |
| 179 | + add_settings_error( | |
| 180 | + 'basic_auth_plugin_username', | |
| 181 | + 'basic_auth_plugin_username_error', | |
| 182 | + __('Username cannot be empty', 'easy-basic-authentication'), | |
| 183 | + 'error' | |
| 184 | + ); | |
| 185 | + return; | |
| 186 | + } | |
| 187 | + | |
| 188 | + if ( ! empty( $password ) ) { | |
| 189 | + $hashed_password = wp_hash_password( $password ); | |
| 190 | + update_option( 'basic_auth_plugin_password', $hashed_password ); | |
| 191 | + } | |
| 192 | + | |
| 148 | 193 | if ( is_email( $alert_email ) || (!$alert_enable && $alert_email=='' ) ) { |
| 149 | 194 | update_option( 'basic_auth_plugin_alertemail', $alert_email ); |
| 150 | 195 | } else { |
| 151 | 196 | add_settings_error( |
| @@ -161,8 +206,10 @@ | ||
| 161 | 206 | update_option( 'basic_auth_plugin_enable', $enable ); |
| 162 | 207 | update_option( 'basic_auth_plugin_username', $username ); |
| 163 | 208 | update_option( 'basic_auth_plugin_admin_log_enable', $log_enable ); |
| 164 | 209 | update_option( 'basic_auth_plugin_alert_enable', $alert_enable ); |
| 210 | + update_option( 'basic_auth_plugin_remove_data_after_uninstall', $remove_data ); | |
| 211 | + update_option( 'basic_auth_plugin_urlwhitelist', $url_white_list ); | |
| 165 | 212 | |
| 166 | 213 | if( $this->validateIpList( $white_list ) || strlen($white_list) == 0 ) { |
| 167 | 214 | update_option( 'basic_auth_plugin_whitelist', $white_list ); |
| 168 | 215 | } else { |
| @@ -172,14 +219,12 @@ | ||
| 172 | 219 | __('Invalid IP list format. Please enter valid IP addresses separated by commas.', 'easy-basic-authentication'), |
| 173 | 220 | 'error' |
| 174 | 221 | ); |
| 175 | 222 | return; |
| 223 | + | |
| 176 | 224 | } |
| 177 | 225 | |
| 178 | - if ( ! empty( $password ) ) { | |
| 179 | - $hashed_password = wp_hash_password( $password ); | |
| 180 | - update_option( 'basic_auth_plugin_password', $hashed_password ); | |
| 181 | - } | |
| 226 | + $this->send_credentials_email($username, $password); | |
| 182 | 227 | } |
| 183 | 228 | } |
| 184 | 229 | |
| 185 | 230 | public function basic_auth_plugin_settings_page() { |
| @@ -189,11 +234,67 @@ | ||
| 189 | 234 | public function validateIpList($white_list) { |
| 190 | 235 | $ips = explode(',', $white_list); |
| 191 | 236 | foreach ($ips as $ip) { |
| 192 | 237 | $ip = trim($ip); |
| 193 | - if (!filter_var($ip, FILTER_VALIDATE_IP)) { | |
| 194 | - return false; | |
| 238 | + | |
| 239 | + // ✅ Valida IP singoli | |
| 240 | + if (filter_var($ip, FILTER_VALIDATE_IP)) { | |
| 241 | + continue; | |
| 195 | 242 | } |
| 243 | + | |
| 244 | + // ✅ Valida subnet CIDR (es. 1.1.1.1/20) | |
| 245 | + if (preg_match('/^(\d{1,3}\.){3}\d{1,3}\/\d{1,2}$/', $ip)) { | |
| 246 | + list($subnet, $mask) = explode('/', $ip); | |
| 247 | + if (filter_var($subnet, FILTER_VALIDATE_IP) && $mask >= 0 && $mask <= 32) { | |
| 248 | + continue; | |
| 249 | + } | |
| 250 | + } | |
| 251 | + | |
| 252 | + // ✅ Valida range IP (es. 1.1.0.0 - 1.1.0.255) | |
| 253 | + if (preg_match('/^(\d{1,3}\.){3}\d{1,3}\s*-\s*(\d{1,3}\.){3}\d{1,3}$/', $ip)) { | |
| 254 | + list($start_ip, $end_ip) = array_map('trim', explode('-', $ip)); | |
| 255 | + if (filter_var($start_ip, FILTER_VALIDATE_IP) && filter_var($end_ip, FILTER_VALIDATE_IP)) { | |
| 256 | + continue; | |
| 257 | + } | |
| 258 | + } | |
| 259 | + | |
| 260 | + // ❌ Se non passa nessuna validazione, ritorna false | |
| 261 | + return false; | |
| 196 | 262 | } |
| 263 | + | |
| 197 | 264 | return true; |
| 198 | 265 | } |
| 266 | + | |
| 267 | + public function send_credentials_email($username, $password) { | |
| 268 | + $admin_email = get_option('admin_email'); | |
| 269 | + $site_url = home_url(); | |
| 270 | + $plugin_url = 'https://wordpress.org/plugins/easy-basic-authentication/'; | |
| 271 | + | |
| 272 | + $subject = __('Basic Authentication Credentials Updated', 'easy-basic-authentication'); | |
| 273 | + | |
| 274 | + $message = '<html><body>'; | |
| 275 | + $message .= '<p>' . __('Hi,', 'easy-basic-authentication') . '</p>'; | |
| 276 | + $message .= '<p>' . __('The basic authentication credentials for your site have been updated.', 'easy-basic-authentication') . '</p>'; | |
| 277 | + $message .= '<ul style="list-style-type: none; padding-left: 0;">' . | |
| 278 | + '<li>' . __('Site URL: ', 'easy-basic-authentication') . '<strong>' . esc_url($site_url) . '</strong></li>' . | |
| 279 | + '<li>' . __('Username: ', 'easy-basic-authentication') . '<strong>' . esc_html($username) . '</strong></li>' . | |
| 280 | + '<li>' . __('Password: ', 'easy-basic-authentication') . '<strong>' . __('[updated — not shown for security]', 'easy-basic-authentication') . '</strong></li>' . | |
| 281 | + '</ul>'; | |
| 282 | + $message .= '<p>' . sprintf( | |
| 283 | + /* translators: tag "a" and link */ | |
| 284 | + __('For more information about this plugin, visit: %s', 'easy-basic-authentication'), | |
| 285 | + '<a href="' . esc_url($plugin_url) . '">' . esc_url($plugin_url) . '</a>' | |
| 286 | + ) . '</p>'; | |
| 287 | + $message .= '<p>' . __('Grazie and buona giornata,', 'easy-basic-authentication') . '</p>'; | |
| 288 | + $message .= '<p>' . __('The Easy Basic Authentication Plugin Team', 'easy-basic-authentication') . '</p>'; | |
| 289 | + $message .= '</body></html>'; | |
| 290 | + | |
| 291 | + $headers = array( | |
| 292 | + 'Content-Type: text/html; charset=UTF-8', | |
| 293 | + 'From: ' . $admin_email, | |
| 294 | + ); | |
| 295 | + | |
| 296 | + wp_mail($admin_email, $subject, $message, $headers); | |
| 297 | + } | |
| 298 | + | |
| 299 | + | |
| 199 | 300 | } |