PluginProbe
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler / 1.7.0
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler v1.7.0
1.7.0 1.6.6 1.6.5 1.6.4 1.6.3 1.6.2 1.6.1 1.6.0 1.5.4 1.5.5 1.5.3 1.5.2 1.5.1 1.5.0 1.4.2 1.4.1 1.4.0 1.3.28 1.3.27 1.3.26 1.3.25 1.3.23 1.3.22 1.3.21 1.3.20 All 50 releases
← All changes | app/Services/CustomerIdentity/EmailVerificationService.php +22 -4 1.6.5 → 1.7.0 View file →
@@ -2,8 +2,9 @@
2 2
3 3 namespace FluentCart\App\Services\CustomerIdentity;
4 4
5 5 use FluentCart\Api\Resource\CustomerResource;
6 +use FluentCart\Api\StoreSettings;
6 7 use FluentCart\App\Models\Customer;
7 8 use FluentCart\Framework\Support\Arr;
8 9
9 10 /** Tracks inbox proof independently from WordPress authentication. */
@@ -17,9 +18,9 @@
17 18 private static $passwordResetProof = [];
18 19
19 20 public static function capturePasswordResetProof($user): void
20 21 {
21 - unset(static::$passwordResetProof[$user->ID]);
22 + unset(self::$passwordResetProof[$user->ID]);
22 23 $cookie = Arr::get($_COOKIE, 'wp-resetpass-' . COOKIEHASH, '');
23 24 $postedKey = Arr::get($_POST, 'rp_key', '');
24 25 if (!is_string($cookie) || !is_string($postedKey) || !$postedKey) {
25 26 return;
@@ -32,9 +33,9 @@
32 33 $validated = check_password_reset_key($parts[1], $parts[0]);
33 34 if (is_wp_error($validated) || (int) $validated->ID !== (int) $user->ID) {
34 35 return;
35 36 }
36 - static::$passwordResetProof[$user->ID] = [
37 + self::$passwordResetProof[$user->ID] = [
37 38 'email' => $validated->user_email,
38 39 'password_hash' => $validated->user_pass,
39 40 ];
40 41 }
@@ -40,10 +41,10 @@
40 41 }
41 42
42 43 public static function verifyAfterPasswordReset($user): void
43 44 {
44 - $proof = static::$passwordResetProof[$user->ID] ?? null;
45 - unset(static::$passwordResetProof[$user->ID]);
45 + $proof = self::$passwordResetProof[$user->ID] ?? null;
46 + unset(self::$passwordResetProof[$user->ID]);
46 47 if (!$proof) {
47 48 return;
48 49 }
49 50 clean_user_cache($user->ID);
@@ -75,13 +76,30 @@
75 76 ]);
76 77 CustomerResource::resetCurrentCustomerRuntimeCache();
77 78 }
78 79
80 + public static function isEnabled(): bool
81 + {
82 + return (new StoreSettings())->get('require_customer_email_verification', 'no') !== 'no';
83 + }
84 +
79 85 public static function isRequired(int $userId): bool
80 86 {
81 87 $user = $userId ? get_userdata($userId) : false;
82 88 if (!$user) {
83 89 return true;
90 + }
91 +
92 + if (!static::isEnabled()) {
93 + return false;
94 + }
95 +
96 + // Registration and email changes always record state, so an account
97 + // without it predates email verification and keeps its existing access.
98 + if (!metadata_exists('user', $userId, static::META_KEY)) {
99 + if (apply_filters('fluent_cart/customer/trust_legacy_accounts', true, ['user' => $user])) {
100 + return false;
101 + }
84 102 }
85 103
86 104 $state = get_user_meta($userId, static::META_KEY, true);
87 105 if (!is_array($state) || Arr::get($state, 'verified') !== true || !static::isSame(Arr::get($state, 'email', ''), $user->user_email)) {