PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-connection / src / class-nonce-handler.php
jetpack / jetpack_vendor / automattic / jetpack-connection / src Last commit date
abilities 3 days ago connectors 3 days ago health 3 days ago identity-crisis 1 month ago sso 1 month ago traits 8 months ago webhooks 8 months ago class-authorize-json-api.php 1 month ago class-client.php 3 days ago class-connection-assets.php 1 year ago class-connection-notice.php 8 months ago class-error-handler.php 3 days ago class-external-storage.php 4 months ago class-heartbeat.php 1 month ago class-initial-state.php 3 weeks ago class-manager.php 3 days ago class-nonce-handler.php 8 months ago class-package-version-tracker.php 1 month ago class-package-version.php 3 days ago class-partner-coupon.php 2 months ago class-partner.php 2 years ago class-plugin-storage.php 8 months ago class-plugin.php 8 months ago class-rest-authentication.php 3 days ago class-rest-connector.php 3 days ago class-secrets.php 8 months ago class-server-sandbox.php 2 months ago class-site-health.php 3 days ago class-terms-of-service.php 3 days ago class-tokens-locks.php 8 months ago class-tokens.php 3 days ago class-tracking.php 3 days ago class-urls.php 6 months ago class-user-account-status.php 3 days ago class-users-connection-admin.php 2 months ago class-utils.php 2 years ago class-webhooks.php 1 month ago class-xmlrpc-async-call.php 2 years ago class-xmlrpc-connector.php 8 months ago interface-manager.php 4 years ago interface-storage-provider.php 6 months ago
class-nonce-handler.php
213 lines
1 <?php
2 /**
3 * The nonce handler.
4 *
5 * @package automattic/jetpack-connection
6 */
7
8 namespace Automattic\Jetpack\Connection;
9
10 /**
11 * The nonce handler.
12 */
13 class Nonce_Handler {
14
15 /**
16 * How long the scheduled cleanup can run (in seconds).
17 * Can be modified using the filter `jetpack_connection_nonce_scheduled_cleanup_limit`.
18 */
19 const SCHEDULED_CLEANUP_TIME_LIMIT = 5;
20
21 /**
22 * How many nonces should be removed per batch during the `clean_all()` run.
23 */
24 const CLEAN_ALL_LIMIT_PER_BATCH = 1000;
25
26 /**
27 * Nonce lifetime in seconds.
28 */
29 const LIFETIME = HOUR_IN_SECONDS;
30
31 /**
32 * The nonces used during the request are stored here to keep them valid.
33 * The property is static to keep the nonces accessible between the `Nonce_Handler` instances.
34 *
35 * @var array
36 */
37 private static $nonces_used_this_request = array();
38
39 /**
40 * The database object.
41 *
42 * @var \wpdb
43 */
44 private $db;
45
46 /**
47 * Initializing the object.
48 */
49 public function __construct() {
50 global $wpdb;
51
52 $this->db = $wpdb;
53 }
54
55 /**
56 * Scheduling the WP-cron cleanup event.
57 */
58 public function init_schedule() {
59 add_action( 'jetpack_clean_nonces', array( __CLASS__, 'clean_scheduled' ) );
60 if ( ! wp_next_scheduled( 'jetpack_clean_nonces' ) ) {
61 wp_schedule_event( time(), 'hourly', 'jetpack_clean_nonces' );
62 }
63 }
64
65 /**
66 * Reschedule the WP-cron cleanup event to make it start sooner.
67 */
68 public function reschedule() {
69 wp_clear_scheduled_hook( 'jetpack_clean_nonces' );
70 wp_schedule_event( time(), 'hourly', 'jetpack_clean_nonces' );
71 }
72
73 /**
74 * Adds a used nonce to a list of known nonces.
75 *
76 * @param int $timestamp the current request timestamp.
77 * @param string $nonce the nonce value.
78 *
79 * @return bool whether the nonce is unique or not.
80 */
81 public function add( $timestamp, $nonce ) {
82 if ( isset( static::$nonces_used_this_request[ "$timestamp:$nonce" ] ) ) {
83 return static::$nonces_used_this_request[ "$timestamp:$nonce" ];
84 }
85
86 // This should always have gone through Jetpack_Signature::sign_request() first to check $timestamp and $nonce.
87 $timestamp = (int) $timestamp;
88 $nonce = esc_sql( $nonce );
89
90 // Raw query so we can avoid races: add_option will also update.
91 $show_errors = $this->db->hide_errors();
92
93 $return = false;
94
95 // Running `try...finally` to make sure that we re-enable errors in case of an exception.
96 try {
97 $old_nonce = $this->db->get_row(
98 $this->db->prepare( "SELECT 1 FROM `{$this->db->options}` WHERE option_name = %s", "jetpack_nonce_{$timestamp}_{$nonce}" )
99 );
100
101 if ( $old_nonce === null ) {
102 $return = (bool) $this->db->query(
103 $this->db->prepare(
104 "INSERT INTO `{$this->db->options}` (`option_name`, `option_value`, `autoload`) VALUES (%s, %s, %s)",
105 "jetpack_nonce_{$timestamp}_{$nonce}",
106 time(),
107 'no'
108 )
109 );
110 }
111 } finally {
112 $this->db->show_errors( $show_errors );
113 }
114
115 static::$nonces_used_this_request[ "$timestamp:$nonce" ] = $return;
116
117 return $return;
118 }
119
120 /**
121 * Removing all existing nonces, or at least as many as possible.
122 * Capped at 20 seconds to avoid breaking the site.
123 *
124 * @param int $cutoff_timestamp All nonces added before this timestamp will be removed.
125 * @param int $time_limit How long the cleanup can run (in seconds).
126 *
127 * @return true
128 */
129 public function clean_all( $cutoff_timestamp = PHP_INT_MAX, $time_limit = 20 ) {
130 // phpcs:ignore Generic.CodeAnalysis.ForLoopWithTestFunctionCall.NotAllowed
131 for ( $end_time = time() + $time_limit; time() < $end_time; ) {
132 $result = $this->delete( static::CLEAN_ALL_LIMIT_PER_BATCH, $cutoff_timestamp );
133
134 if ( ! $result ) {
135 break;
136 }
137 }
138
139 return true;
140 }
141
142 /**
143 * Scheduled clean up of the expired nonces.
144 */
145 public static function clean_scheduled() {
146 /**
147 * Adjust the time limit for the scheduled cleanup.
148 *
149 * @since 9.5.0
150 *
151 * @param int $time_limit How long the cleanup can run (in seconds).
152 */
153 $time_limit = apply_filters( 'jetpack_connection_nonce_cleanup_runtime_limit', static::SCHEDULED_CLEANUP_TIME_LIMIT );
154
155 ( new static() )->clean_all( time() - static::LIFETIME, $time_limit );
156 }
157
158 /**
159 * Delete the nonces.
160 *
161 * @param int $limit How many nonces to delete.
162 * @param null|int $cutoff_timestamp All nonces added before this timestamp will be removed.
163 *
164 * @return int|false Number of removed nonces, or `false` if nothing to remove (or in case of a database error).
165 */
166 public function delete( $limit = 10, $cutoff_timestamp = null ) {
167 global $wpdb;
168
169 $ids = $wpdb->get_col(
170 $wpdb->prepare(
171 "SELECT option_id FROM `{$wpdb->options}`"
172 . " WHERE `option_name` >= 'jetpack_nonce_' AND `option_name` < %s"
173 . ' LIMIT %d',
174 'jetpack_nonce_' . $cutoff_timestamp,
175 $limit
176 )
177 );
178
179 if ( ! is_array( $ids ) ) {
180 // There's an error and we can't proceed.
181 return false;
182 }
183
184 // Removing zeroes in case AUTO_INCREMENT of the options table is broken, and all ID's are zeroes.
185 $ids = array_filter( $ids );
186
187 if ( array() === $ids ) {
188 // There's nothing to remove.
189 return false;
190 }
191
192 $ids_fill = implode( ', ', array_fill( 0, count( $ids ), '%d' ) );
193
194 $args = $ids;
195 $args[] = 'jetpack_nonce_%';
196
197 // The Code Sniffer is unable to understand what's going on...
198 // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared,WordPress.DB.PreparedSQLPlaceholders.ReplacementsWrongNumber
199 return $wpdb->query( $wpdb->prepare( "DELETE FROM `{$wpdb->options}` WHERE `option_id` IN ( {$ids_fill} ) AND option_name LIKE %s", $args ) );
200 }
201
202 /**
203 * Clean the cached nonces valid during the current request, therefore making them invalid.
204 *
205 * @return bool
206 */
207 public static function invalidate_request_nonces() {
208 static::$nonces_used_this_request = array();
209
210 return true;
211 }
212 }
213