PluginProbe
Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF / trunk
Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF vtrunk
2.3.4 2.3.3 2.3.2 2.3.1 2.3.0 2.2.9 2.2.8 trunk 1.10 1.3.3 1.3.4 1.3.5 1.3.5.1 1.3.5.2 1.3.6 1.3.6.1 1.4 1.4.1 1.4.2 1.4.3 1.4.4 1.4.5 1.4.6 1.4.7 1.5 All 103 releases
imagify / vendor / wp-media / mcp-oauth / inc / Auth / SecretManager.php

SecretManager.php in Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF trunk, at vendor/wp-media/mcp-oauth/inc/Auth/SecretManager.php

77 lines 1.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Site Secret Manager.
4 *
5 * Generates, stores, and rotates the 256-bit HMAC secret used to sign all
6 * MCP JWTs. Regenerating the secret immediately invalidates every outstanding
7 * access and refresh token site-wide.
8 */
9
10 declare(strict_types=1);
11
12 namespace WPMedia\MCP\OAuth\Auth;
13
14 /**
15 * Secret Manager.
16 */
17 class SecretManager {
18
19 /**
20 * WordPress option key where the JWT signing secret is stored.
21 */
22 const OPTION_KEY = 'mcp_jwt_secret';
23
24 /**
25 * Return the current site JWT signing secret, generating one if absent.
26 *
27 * Uses add_option() for the initial write so that two concurrent requests
28 * racing on first activation cannot both store different secrets — only one
29 * caller's add_option() succeeds; the other reads back the winner's value.
30 *
31 * @return string Hex-encoded 256-bit secret.
32 */
33 public static function get_secret(): string {
34 $secret = (string) get_option( self::OPTION_KEY, '' );
35 if ( '' !== $secret ) {
36 return $secret;
37 }
38
39 $candidate = self::generate();
40 if ( ! add_option( self::OPTION_KEY, $candidate, '', false ) ) {
41 // Another request won the race; read back whatever was stored.
42 $candidate = (string) get_option( self::OPTION_KEY );
43 }
44
45 return $candidate;
46 }
47
48 /**
49 * Ensure a secret exists; create one on first activation.
50 *
51 * Idempotent — safe to call on every activation.
52 *
53 * @return void
54 */
55 public static function ensure_secret(): void {
56 self::get_secret();
57 }
58
59 /**
60 * Regenerate the site secret, invalidating all current MCP sessions.
61 *
62 * @return void
63 */
64 public static function regenerate(): void {
65 update_option( self::OPTION_KEY, self::generate(), false );
66 }
67
68 /**
69 * Generate a fresh 256-bit random secret as a hex string.
70 *
71 * @return string 64-character hex string.
72 */
73 private static function generate(): string {
74 return bin2hex( random_bytes( 32 ) );
75 }
76 }
77