| 1 |
<?php |
| 2 |
/** |
| 3 |
* Site Secret Manager. |
| 4 |
* |
| 5 |
* Generates, stores, and rotates the 256-bit HMAC secret used to sign all |
| 6 |
* MCP JWTs. Regenerating the secret immediately invalidates every outstanding |
| 7 |
* access and refresh token site-wide. |
| 8 |
*/ |
| 9 |
|
| 10 |
declare(strict_types=1); |
| 11 |
|
| 12 |
namespace WPMedia\MCP\OAuth\Auth; |
| 13 |
|
| 14 |
/** |
| 15 |
* Secret Manager. |
| 16 |
*/ |
| 17 |
class SecretManager { |
| 18 |
|
| 19 |
/** |
| 20 |
* WordPress option key where the JWT signing secret is stored. |
| 21 |
*/ |
| 22 |
const OPTION_KEY = 'mcp_jwt_secret'; |
| 23 |
|
| 24 |
/** |
| 25 |
* Return the current site JWT signing secret, generating one if absent. |
| 26 |
* |
| 27 |
* Uses add_option() for the initial write so that two concurrent requests |
| 28 |
* racing on first activation cannot both store different secrets — only one |
| 29 |
* caller's add_option() succeeds; the other reads back the winner's value. |
| 30 |
* |
| 31 |
* @return string Hex-encoded 256-bit secret. |
| 32 |
*/ |
| 33 |
public static function get_secret(): string { |
| 34 |
$secret = (string) get_option( self::OPTION_KEY, '' ); |
| 35 |
if ( '' !== $secret ) { |
| 36 |
return $secret; |
| 37 |
} |
| 38 |
|
| 39 |
$candidate = self::generate(); |
| 40 |
if ( ! add_option( self::OPTION_KEY, $candidate, '', false ) ) { |
| 41 |
// Another request won the race; read back whatever was stored. |
| 42 |
$candidate = (string) get_option( self::OPTION_KEY ); |
| 43 |
} |
| 44 |
|
| 45 |
return $candidate; |
| 46 |
} |
| 47 |
|
| 48 |
/** |
| 49 |
* Ensure a secret exists; create one on first activation. |
| 50 |
* |
| 51 |
* Idempotent — safe to call on every activation. |
| 52 |
* |
| 53 |
* @return void |
| 54 |
*/ |
| 55 |
public static function ensure_secret(): void { |
| 56 |
self::get_secret(); |
| 57 |
} |
| 58 |
|
| 59 |
/** |
| 60 |
* Regenerate the site secret, invalidating all current MCP sessions. |
| 61 |
* |
| 62 |
* @return void |
| 63 |
*/ |
| 64 |
public static function regenerate(): void { |
| 65 |
update_option( self::OPTION_KEY, self::generate(), false ); |
| 66 |
} |
| 67 |
|
| 68 |
/** |
| 69 |
* Generate a fresh 256-bit random secret as a hex string. |
| 70 |
* |
| 71 |
* @return string 64-character hex string. |
| 72 |
*/ |
| 73 |
private static function generate(): string { |
| 74 |
return bin2hex( random_bytes( 32 ) ); |
| 75 |
} |
| 76 |
} |
| 77 |
|