PluginProbe
Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF / trunk
Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF vtrunk
2.3.4 2.3.3 2.3.2 2.3.1 2.3.0 2.2.9 2.2.8 trunk 1.10 1.3.3 1.3.4 1.3.5 1.3.5.1 1.3.5.2 1.3.6 1.3.6.1 1.4 1.4.1 1.4.2 1.4.3 1.4.4 1.4.5 1.4.6 1.4.7 1.5 All 103 releases
imagify / vendor / wp-media / mcp-oauth / inc / Auth / Router.php

Router.php in Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF trunk, at vendor/wp-media/mcp-oauth/inc/Auth/Router.php

177 lines 4.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * MCP Auth Router.
4 *
5 * Wires the OAuth 2.1 endpoint routing. Registered directly by Bootstrap via
6 * add_action()/add_filter() calls. Plugin lifecycle (activation) is handled
7 * separately by Rewrite and SecretManager.
8 */
9
10 declare( strict_types=1 );
11
12 namespace WPMedia\MCP\OAuth\Auth;
13
14 use WPMedia\MCP\OAuth\Context;
15
16 /**
17 * Registers OAuth endpoint routing callbacks.
18 */
19 class Router {
20
21 use Http404Trait;
22
23 /**
24 * OAuth rewrite rules and query var registration.
25 *
26 * @var Rewrite
27 */
28 private Rewrite $rewrite;
29
30 /**
31 * Authorize endpoint handler.
32 *
33 * @var AuthorizeEndpoint
34 */
35 private AuthorizeEndpoint $authorize_endpoint;
36
37 /**
38 * Authorize callback handler.
39 *
40 * @var AuthorizeCallback
41 */
42 private AuthorizeCallback $authorize_callback;
43
44 /**
45 * Token endpoint handler.
46 *
47 * @var TokenEndpoint
48 */
49 private TokenEndpoint $token_endpoint;
50
51 /**
52 * Consent endpoint handler.
53 *
54 * @var ConsentEndpoint
55 */
56 private ConsentEndpoint $consent_endpoint;
57
58 /**
59 * Revoke endpoint handler.
60 *
61 * @var RevokeEndpoint
62 */
63 private RevokeEndpoint $revoke_endpoint;
64
65 /**
66 * OAuth server context.
67 *
68 * @var Context
69 */
70 private Context $context;
71
72 /**
73 * Constructor.
74 *
75 * @param Rewrite $rewrite OAuth rewrite rules and query var registration.
76 * @param AuthorizeEndpoint $authorize_endpoint Authorization endpoint.
77 * @param AuthorizeCallback $authorize_callback Authorization callback.
78 * @param TokenEndpoint $token_endpoint Token endpoint.
79 * @param ConsentEndpoint $consent_endpoint Consent endpoint.
80 * @param RevokeEndpoint $revoke_endpoint Revocation endpoint.
81 * @param Context $context OAuth server context.
82 */
83 public function __construct(
84 Rewrite $rewrite,
85 AuthorizeEndpoint $authorize_endpoint,
86 AuthorizeCallback $authorize_callback,
87 TokenEndpoint $token_endpoint,
88 ConsentEndpoint $consent_endpoint,
89 RevokeEndpoint $revoke_endpoint,
90 Context $context
91 ) {
92 $this->rewrite = $rewrite;
93 $this->authorize_endpoint = $authorize_endpoint;
94 $this->authorize_callback = $authorize_callback;
95 $this->token_endpoint = $token_endpoint;
96 $this->consent_endpoint = $consent_endpoint;
97 $this->revoke_endpoint = $revoke_endpoint;
98 $this->context = $context;
99 }
100
101 /**
102 * Register WordPress rewrite rules for all five OAuth endpoints.
103 *
104 * Called on the 'init' action (normal page load).
105 *
106 * @return void
107 */
108 public function register_rewrite_rules(): void {
109 if ( ! $this->context->is_enabled() ) {
110 return;
111 }
112
113 $this->rewrite->register_oauth_rewrite_rules();
114 }
115
116 /**
117 * Add the OAuth query var to WordPress's list of recognised vars.
118 *
119 * @param string[] $vars Existing query vars.
120 * @return string[] Modified list.
121 */
122 public function add_query_vars( array $vars ): array {
123 return $this->rewrite->add_oauth_query_vars( $vars );
124 }
125
126 /**
127 * Dispatch an incoming OAuth endpoint request to the appropriate handler.
128 *
129 * @return void
130 */
131 public function handle_request(): void {
132 $endpoint = (string) get_query_var( Rewrite::OAUTH_QUERY_VAR, '' );
133
134 if ( '' === $endpoint ) {
135 return;
136 }
137
138 if ( ! $this->context->is_enabled() ) {
139 $this->force_404();
140 return;
141 }
142
143 switch ( $endpoint ) {
144 case 'authorize':
145 $this->authorize_endpoint->handle_request();
146 break;
147 case 'authorize-callback':
148 $this->authorize_callback->handle_request();
149 break;
150 case 'consent':
151 $this->consent_endpoint->handle_request();
152 break;
153 case 'revoke':
154 $this->revoke_endpoint->handle_request();
155 break;
156 case 'token':
157 $this->token_endpoint->handle_request();
158 break;
159 default:
160 status_header( 404 );
161 wp_die( esc_html__( 'Unknown OAuth endpoint.', 'mcp-oauth' ), '', [ 'response' => 404 ] );
162 }
163 }
164
165 /**
166 * Remove the refresh-token rotation marker when a session's Application
167 * Password is deleted.
168 *
169 * @param int $user_id WordPress user ID.
170 * @param array<string, mixed> $item The Application Password record being deleted.
171 * @return void
172 */
173 public function purge_refresh_jti_meta( $user_id, $item ): void {
174 $this->token_endpoint->purge_refresh_jti_meta( (int) $user_id, (array) $item );
175 }
176 }
177