PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 12.7.3
Jetpack – WP Security, Backup, Speed, & Growth v12.7.3
12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 14.1.1 14.2.2 14.3.1 14.4.2 14.5.1 14.6.1 14.7.1 14.8.1 14.9.2 15.0.3 15.1.2 15.2.1 15.3.2 15.4.1 15.5.1 15.6.1 15.7.2 15.8.1 15.9.2 16.0.2 16.1.3 16.2-a.5 16.2-a.3 16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / modules / sso / class-jetpack-force-2fa.php
jetpack / modules / sso Last commit date
class-jetpack-force-2fa.php 2 years ago class.jetpack-sso-helpers.php 3 years ago class.jetpack-sso-notices.php 4 years ago jetpack-sso-login-rtl.css 4 years ago jetpack-sso-login-rtl.min.css 4 years ago jetpack-sso-login.css 4 years ago jetpack-sso-login.js 6 years ago jetpack-sso-login.min.css 4 years ago
class-jetpack-force-2fa.php
175 lines
1 <?php
2 /**
3 * Force Jetpack 2FA Functionality
4 *
5 * Ported from original repo at https://github.com/automattic/jetpack-force-2fa
6 *
7 * @package automattic/jetpack
8 */
9
10 /**
11 * Force users to use two factor authentication.
12 */
13 class Jetpack_Force_2FA {
14
15 /**
16 * The role to force 2FA for.
17 *
18 * Defaults to manage_options via the plugins_loaded function.
19 * Can be modified with the jetpack_force_2fa_cap filter.
20 *
21 * @var string
22 */
23 private $role;
24
25 /**
26 * Constructor.
27 */
28 public function __construct() {
29 add_action( 'after_setup_theme', array( $this, 'plugins_loaded' ) );
30 }
31
32 /**
33 * Load the plugin via the plugins_loaded hook.
34 */
35 public function plugins_loaded() {
36 /**
37 * Filter the role to force 2FA for.
38 * Defaults to manage_options.
39 *
40 * @param string $role The role to force 2FA for.
41 * @return string
42 * @since 12.7
43 * @module SSO
44 */
45 $this->role = apply_filters( 'jetpack_force_2fa_cap', 'manage_options' );
46
47 // Bail if Jetpack SSO is not active
48 if ( ! class_exists( 'Jetpack' ) || ! Jetpack::is_active() || ! Jetpack::is_module_active( 'sso' ) ) {
49 add_action( 'admin_notices', array( $this, 'admin_notice' ) );
50 return;
51 }
52
53 $this->force_2fa();
54 }
55
56 /**
57 * Display an admin notice if Jetpack SSO is not active.
58 */
59 public function admin_notice() {
60 /**
61 * Filter if an admin notice is deplayed when Force 2FA is required, but SSO is not enabled.
62 * Defaults to true.
63 *
64 * @param bool $display_notice Whether to display the notice.
65 * @return bool
66 * @since 12.7
67 * @module SSO
68 */
69 if ( apply_filters( 'jetpack_force_2fa_dependency_notice', true ) && current_user_can( $this->role ) ) {
70 printf( '<div class="%1$s"><p>%2$s</p></div>', 'notice notice-warning', 'Jetpack Force 2FA requires Jetpack and the Jetpack SSO module.' );
71 }
72 }
73
74 /**
75 * Force 2FA when using Jetpack SSO and force Jetpack SSO.
76 *
77 * @return void
78 */
79 private function force_2fa() {
80 // Allows WP.com login to a local account if it matches the local account.
81 add_filter( 'jetpack_sso_match_by_email', '__return_true', 9999 );
82
83 // multisite
84 if ( is_multisite() ) {
85
86 // Hide the login form
87 add_filter( 'jetpack_remove_login_form', '__return_true', 9999 );
88 add_filter( 'jetpack_sso_bypass_login_forward_wpcom', '__return_true', 9999 );
89 add_filter( 'jetpack_sso_display_disclaimer', '__return_false', 9999 );
90
91 add_filter(
92 'wp_authenticate_user',
93 function () {
94 return new WP_Error( 'wpcom-required', $this->get_login_error_message() ); },
95 9999
96 );
97
98 add_filter( 'jetpack_sso_require_two_step', '__return_true' );
99
100 add_filter( 'allow_password_reset', '__return_false' );
101 } else {
102 // Not multisite.
103
104 // Completely disable the standard login form for admins.
105 add_filter(
106 'wp_authenticate_user',
107 function ( $user ) {
108 if ( is_wp_error( $user ) ) {
109 return $user;
110 }
111 if ( $user->has_cap( $this->role ) ) {
112 return new WP_Error( 'wpcom-required', $this->get_login_error_message(), $user->user_login );
113 }
114 return $user;
115 },
116 9999
117 );
118
119 add_filter(
120 'allow_password_reset',
121 function ( $allow, $user_id ) {
122 if ( user_can( $user_id, $this->role ) ) {
123 return false;
124 }
125 return $allow; },
126 9999,
127 2
128 );
129
130 add_action( 'jetpack_sso_pre_handle_login', array( $this, 'jetpack_set_two_step' ) );
131 }
132 }
133
134 /**
135 * Specifically set the two step filter for Jetpack SSO.
136 *
137 * @param Object $user_data The user data from WordPress.com.
138 *
139 * @return void
140 */
141 public function jetpack_set_two_step( $user_data ) {
142 $user = Jetpack_SSO::get_user_by_wpcom_id( $user_data->ID );
143
144 // Borrowed from Jetpack. Ignores the match_by_email setting.
145 if ( empty( $user ) ) {
146 $user = get_user_by( 'email', $user_data->email );
147 }
148
149 if ( $user && $user->has_cap( $this->role ) ) {
150 add_filter( 'jetpack_sso_require_two_step', '__return_true' );
151 }
152 }
153
154 /**
155 * Get the login error message.
156 *
157 * @return string
158 */
159 private function get_login_error_message() {
160 /**
161 * Filter the login error message.
162 * Defaults to a message that explains the user must use a WordPress.com account with 2FA enabled.
163 *
164 * @param string $message The login error message.
165 * @return string
166 * @since 12.7
167 * @module SSO
168 */
169 return apply_filters(
170 'jetpack_force_2fa_login_error_message',
171 sprintf( 'For added security, please log in using your WordPress.com account.<br /><br />Note: Your account must have <a href="%1$s" target="_blank">Two Step Authentication</a> enabled, which can be configured from <a href="%2$s" target="_blank">Security Settings</a>.', 'https://support.wordpress.com/security/two-step-authentication/', 'https://wordpress.com/me/security/two-step' )
172 );
173 }
174 }
175