| 1 |
<?php |
| 2 |
/** |
| 3 |
* Consent screen view template. |
| 4 |
* |
| 5 |
* Rendered by AuthorizeCallback::output_consent_screen() via Render::view(). |
| 6 |
* Pure presentation — assumes `$data` is fully populated and pre-validated. |
| 7 |
* |
| 8 |
* @var array<string, mixed> $data { |
| 9 |
* @type string $state OAuth state token. |
| 10 |
* @type string $client_name Requesting client's display name. |
| 11 |
* @type string $client_id esc_url'd client_id. |
| 12 |
* @type string $client_uri esc_url'd client_uri (may be empty). |
| 13 |
* @type bool $verified Whether the client's publisher is verified. |
| 14 |
* @type string $publisher Verified publisher name (may be empty). |
| 15 |
* @type string $site_name This site's display name. |
| 16 |
* @type string $consent_url esc_url'd POST target for the Allow/Deny form. |
| 17 |
* @type string $display_href client_uri if set, otherwise client_id. |
| 18 |
* } |
| 19 |
*/ |
| 20 |
|
| 21 |
declare(strict_types=1); |
| 22 |
|
| 23 |
?> |
| 24 |
<!DOCTYPE html> |
| 25 |
<html <?php language_attributes(); ?>> |
| 26 |
<head> |
| 27 |
<meta charset="<?php bloginfo( 'charset' ); ?>"> |
| 28 |
<meta name="viewport" content="width=device-width, initial-scale=1"> |
| 29 |
<title><?php echo esc_html( __( 'Authorize Access', 'mcp-oauth' ) . ' — ' . $data['site_name'] ); ?></title> |
| 30 |
<style> |
| 31 |
*, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; } |
| 32 |
body { |
| 33 |
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen-Sans, Ubuntu, Cantarell, "Helvetica Neue", sans-serif; |
| 34 |
background: #f0f0f1; |
| 35 |
display: flex; |
| 36 |
align-items: center; |
| 37 |
justify-content: center; |
| 38 |
min-height: 100vh; |
| 39 |
padding: 20px; |
| 40 |
} |
| 41 |
.consent-card { |
| 42 |
background: #fff; |
| 43 |
border-radius: 4px; |
| 44 |
box-shadow: 0 1px 3px rgba(0,0,0,.13); |
| 45 |
max-width: 420px; |
| 46 |
width: 100%; |
| 47 |
padding: 36px 40px 40px; |
| 48 |
} |
| 49 |
.consent-card h1 { |
| 50 |
font-size: 1.1rem; |
| 51 |
font-weight: 600; |
| 52 |
color: #1d2327; |
| 53 |
margin-bottom: 20px; |
| 54 |
text-align: center; |
| 55 |
} |
| 56 |
.client-block { |
| 57 |
border: 1px solid #ddd; |
| 58 |
border-radius: 3px; |
| 59 |
padding: 14px 16px; |
| 60 |
margin-bottom: 20px; |
| 61 |
} |
| 62 |
.client-name { |
| 63 |
font-size: 1rem; |
| 64 |
font-weight: 600; |
| 65 |
color: #1d2327; |
| 66 |
} |
| 67 |
.client-name a { color: inherit; text-decoration: none; } |
| 68 |
.client-name a:hover { text-decoration: underline; } |
| 69 |
.client-url { |
| 70 |
font-size: .78rem; |
| 71 |
color: #646970; |
| 72 |
word-break: break-all; |
| 73 |
margin-top: 4px; |
| 74 |
} |
| 75 |
.client-url a { color: #646970; } |
| 76 |
.verified-badge { |
| 77 |
display: inline-block; |
| 78 |
font-size: .72rem; |
| 79 |
font-weight: 600; |
| 80 |
color: #00a32a; |
| 81 |
background: #edfaef; |
| 82 |
border: 1px solid #a7e8b1; |
| 83 |
border-radius: 2px; |
| 84 |
padding: 2px 6px; |
| 85 |
margin-top: 8px; |
| 86 |
} |
| 87 |
.scope-text { |
| 88 |
font-size: .875rem; |
| 89 |
color: #3c434a; |
| 90 |
margin-bottom: 24px; |
| 91 |
line-height: 1.5; |
| 92 |
} |
| 93 |
.consent-actions { |
| 94 |
display: flex; |
| 95 |
gap: 10px; |
| 96 |
} |
| 97 |
.btn { |
| 98 |
flex: 1; |
| 99 |
padding: 9px 14px; |
| 100 |
font-size: .875rem; |
| 101 |
font-weight: 600; |
| 102 |
border-radius: 3px; |
| 103 |
border: 1px solid transparent; |
| 104 |
cursor: pointer; |
| 105 |
text-align: center; |
| 106 |
} |
| 107 |
.btn-allow { |
| 108 |
background: #2271b1; |
| 109 |
color: #fff; |
| 110 |
border-color: #2271b1; |
| 111 |
} |
| 112 |
.btn-allow:hover { background: #135e96; border-color: #135e96; } |
| 113 |
.btn-deny { |
| 114 |
background: #fff; |
| 115 |
color: #d63638; |
| 116 |
border-color: #d63638; |
| 117 |
} |
| 118 |
.btn-deny:hover { background: #fcf0f1; } |
| 119 |
</style> |
| 120 |
</head> |
| 121 |
<body> |
| 122 |
<div class="consent-card"> |
| 123 |
<h1><?php esc_html_e( 'Authorize access to your site?', 'mcp-oauth' ); ?></h1> |
| 124 |
|
| 125 |
<div class="client-block"> |
| 126 |
<div class="client-name"> |
| 127 |
<?php if ( '' !== $data['display_href'] ) : ?> |
| 128 |
<a href="<?php echo esc_url( $data['display_href'] ); ?>" rel="noopener noreferrer" target="_blank"><?php echo esc_html( $data['client_name'] ); ?></a> |
| 129 |
<?php else : ?> |
| 130 |
<?php echo esc_html( $data['client_name'] ); ?> |
| 131 |
<?php endif; ?> |
| 132 |
</div> |
| 133 |
<?php if ( '' !== $data['client_id'] ) : ?> |
| 134 |
<div class="client-url"> |
| 135 |
<?php esc_html_e( 'ID:', 'mcp-oauth' ); ?> |
| 136 |
<a href="<?php echo esc_url( $data['client_id'] ); ?>" rel="noopener noreferrer" target="_blank"><?php echo esc_html( $data['client_id'] ); ?></a> |
| 137 |
</div> |
| 138 |
<?php endif; ?> |
| 139 |
<?php if ( $data['verified'] && '' !== $data['publisher'] ) : ?> |
| 140 |
<div class="verified-badge"> |
| 141 |
<?php |
| 142 |
/* translators: %s: publisher name */ |
| 143 |
printf( esc_html__( 'Verified publisher: %s', 'mcp-oauth' ), esc_html( $data['publisher'] ) ); |
| 144 |
?> |
| 145 |
</div> |
| 146 |
<?php endif; ?> |
| 147 |
</div> |
| 148 |
|
| 149 |
<p class="scope-text"> |
| 150 |
<?php |
| 151 |
printf( |
| 152 |
/* translators: 1: client name, 2: site name, 3: application password name */ |
| 153 |
esc_html__( '%1$s is requesting access to the MCP tools of %2$s on your behalf. If you approve this request, an application password (%3$s) will be created for your user and securely shared with %1$s. %1$s will then inherit your user\'s permissions on this website. You can revoke this access at any time by revoking the application password.', 'mcp-oauth' ), |
| 154 |
'<strong>' . esc_html( $data['client_name'] ) . '</strong>', |
| 155 |
'<strong>' . esc_html( $data['site_name'] ) . '</strong>', |
| 156 |
'<strong>' . esc_html( $data['client_name'] ) . '</strong>' |
| 157 |
); |
| 158 |
?> |
| 159 |
</p> |
| 160 |
|
| 161 |
<form method="post" action="<?php echo esc_url( $data['consent_url'] ); ?>"> |
| 162 |
<input type="hidden" name="state" value="<?php echo esc_attr( $data['state'] ); ?>"> |
| 163 |
<?php wp_nonce_field( 'mcp_consent_' . $data['state'], 'mcp_consent_nonce' ); ?> |
| 164 |
<div class="consent-actions"> |
| 165 |
<button type="submit" name="mcp_action" value="allow" class="btn btn-allow"> |
| 166 |
<?php esc_html_e( 'Allow', 'mcp-oauth' ); ?> |
| 167 |
</button> |
| 168 |
<button type="submit" name="mcp_action" value="deny" class="btn btn-deny"> |
| 169 |
<?php esc_html_e( 'Deny', 'mcp-oauth' ); ?> |
| 170 |
</button> |
| 171 |
</div> |
| 172 |
</form> |
| 173 |
</div> |
| 174 |
</body> |
| 175 |
</html> |
| 176 |
|