← All changes
|
app/Services/CustomerIdentity/EmailVerificationService.php
+22
-4
1.6.5
→
1.7.0
View file →
| @@ -2,8 +2,9 @@ | ||
| 2 | 2 | |
| 3 | 3 | namespace FluentCart\App\Services\CustomerIdentity; |
| 4 | 4 | |
| 5 | 5 | use FluentCart\Api\Resource\CustomerResource; |
| 6 | +use FluentCart\Api\StoreSettings; | |
| 6 | 7 | use FluentCart\App\Models\Customer; |
| 7 | 8 | use FluentCart\Framework\Support\Arr; |
| 8 | 9 | |
| 9 | 10 | /** Tracks inbox proof independently from WordPress authentication. */ |
| @@ -17,9 +18,9 @@ | ||
| 17 | 18 | private static $passwordResetProof = []; |
| 18 | 19 | |
| 19 | 20 | public static function capturePasswordResetProof($user): void |
| 20 | 21 | { |
| 21 | - unset(static::$passwordResetProof[$user->ID]); | |
| 22 | + unset(self::$passwordResetProof[$user->ID]); | |
| 22 | 23 | $cookie = Arr::get($_COOKIE, 'wp-resetpass-' . COOKIEHASH, ''); |
| 23 | 24 | $postedKey = Arr::get($_POST, 'rp_key', ''); |
| 24 | 25 | if (!is_string($cookie) || !is_string($postedKey) || !$postedKey) { |
| 25 | 26 | return; |
| @@ -32,9 +33,9 @@ | ||
| 32 | 33 | $validated = check_password_reset_key($parts[1], $parts[0]); |
| 33 | 34 | if (is_wp_error($validated) || (int) $validated->ID !== (int) $user->ID) { |
| 34 | 35 | return; |
| 35 | 36 | } |
| 36 | - static::$passwordResetProof[$user->ID] = [ | |
| 37 | + self::$passwordResetProof[$user->ID] = [ | |
| 37 | 38 | 'email' => $validated->user_email, |
| 38 | 39 | 'password_hash' => $validated->user_pass, |
| 39 | 40 | ]; |
| 40 | 41 | } |
| @@ -40,10 +41,10 @@ | ||
| 40 | 41 | } |
| 41 | 42 | |
| 42 | 43 | public static function verifyAfterPasswordReset($user): void |
| 43 | 44 | { |
| 44 | - $proof = static::$passwordResetProof[$user->ID] ?? null; | |
| 45 | - unset(static::$passwordResetProof[$user->ID]); | |
| 45 | + $proof = self::$passwordResetProof[$user->ID] ?? null; | |
| 46 | + unset(self::$passwordResetProof[$user->ID]); | |
| 46 | 47 | if (!$proof) { |
| 47 | 48 | return; |
| 48 | 49 | } |
| 49 | 50 | clean_user_cache($user->ID); |
| @@ -75,13 +76,30 @@ | ||
| 75 | 76 | ]); |
| 76 | 77 | CustomerResource::resetCurrentCustomerRuntimeCache(); |
| 77 | 78 | } |
| 78 | 79 | |
| 80 | + public static function isEnabled(): bool | |
| 81 | + { | |
| 82 | + return (new StoreSettings())->get('require_customer_email_verification', 'no') !== 'no'; | |
| 83 | + } | |
| 84 | + | |
| 79 | 85 | public static function isRequired(int $userId): bool |
| 80 | 86 | { |
| 81 | 87 | $user = $userId ? get_userdata($userId) : false; |
| 82 | 88 | if (!$user) { |
| 83 | 89 | return true; |
| 90 | + } | |
| 91 | + | |
| 92 | + if (!static::isEnabled()) { | |
| 93 | + return false; | |
| 94 | + } | |
| 95 | + | |
| 96 | + // Registration and email changes always record state, so an account | |
| 97 | + // without it predates email verification and keeps its existing access. | |
| 98 | + if (!metadata_exists('user', $userId, static::META_KEY)) { | |
| 99 | + if (apply_filters('fluent_cart/customer/trust_legacy_accounts', true, ['user' => $user])) { | |
| 100 | + return false; | |
| 101 | + } | |
| 84 | 102 | } |
| 85 | 103 | |
| 86 | 104 | $state = get_user_meta($userId, static::META_KEY, true); |
| 87 | 105 | if (!is_array($state) || Arr::get($state, 'verified') !== true || !static::isSame(Arr::get($state, 'email', ''), $user->user_email)) { |