PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-connection / src / sso / class-force-2fa.php
jetpack / jetpack_vendor / automattic / jetpack-connection / src / sso Last commit date
class-force-2fa.php 8 months ago class-helpers.php 3 months ago class-notices.php 6 months ago class-sso.php 1 month ago class-user-admin.php 2 months ago jetpack-sso-admin-create-user.css 8 months ago jetpack-sso-admin-create-user.js 2 years ago jetpack-sso-login.css 8 months ago jetpack-sso-login.js 2 years ago jetpack-sso-users.js 8 months ago
class-force-2fa.php
187 lines
1 <?php
2 /**
3 * Force Jetpack 2FA Functionality
4 *
5 * Ported from original repo at https://github.com/automattic/jetpack-force-2fa
6 *
7 * @package automattic/jetpack-connection
8 */
9
10 namespace Automattic\Jetpack\Connection\SSO;
11
12 use Automattic\Jetpack\Connection\SSO;
13 use Automattic\Jetpack\Modules;
14 use WP_Error;
15
16 /**
17 * Force users to use two-factor authentication.
18 *
19 * @phan-constructor-used-for-side-effects
20 */
21 class Force_2FA {
22 /**
23 * The role to force 2FA for.
24 *
25 * Defaults to manage_options via the plugins_loaded function.
26 * Can be modified with the jetpack_force_2fa_cap filter.
27 *
28 * @var string
29 */
30 private $role;
31
32 /**
33 * Constructor.
34 */
35 public function __construct() {
36 add_action( 'after_setup_theme', array( $this, 'plugins_loaded' ) );
37 }
38
39 /**
40 * Load the plugin via the plugins_loaded hook.
41 */
42 public function plugins_loaded() {
43 /**
44 * Filter the role to force 2FA for.
45 * Defaults to manage_options.
46 *
47 * @param string $role The role to force 2FA for.
48 * @return string
49 * @since jetpack-12.7
50 * @module SSO
51 */
52 $this->role = apply_filters( 'jetpack_force_2fa_cap', 'manage_options' );
53
54 // Bail if Jetpack SSO is not active
55 if ( ! ( new Modules() )->is_active( 'sso' ) ) {
56 add_action( 'admin_notices', array( $this, 'admin_notice' ) );
57 return;
58 }
59
60 $this->force_2fa();
61 }
62
63 /**
64 * Display an admin notice if Jetpack SSO is not active.
65 */
66 public function admin_notice() {
67 /**
68 * Filter if an admin notice is deplayed when Force 2FA is required, but SSO is not enabled.
69 * Defaults to true.
70 *
71 * @param bool $display_notice Whether to display the notice.
72 * @return bool
73 * @since jetpack-12.7
74 * @module SSO
75 */
76 if ( apply_filters( 'jetpack_force_2fa_dependency_notice', true ) && current_user_can( $this->role ) ) {
77 wp_admin_notice(
78 esc_html__( 'Jetpack Force 2FA requires Jetpack’s SSO feature.', 'jetpack-connection' ),
79 array(
80 'type' => 'warning',
81 )
82 );
83 }
84 }
85
86 /**
87 * Force 2FA when using Jetpack SSO and force Jetpack SSO.
88 *
89 * @return void
90 */
91 private function force_2fa() {
92 // Allows WP.com login to a local account if it matches the local account.
93 add_filter( 'jetpack_sso_match_by_email', '__return_true', 9999 );
94
95 // multisite
96 if ( is_multisite() ) {
97
98 // Hide the login form
99 add_filter( 'jetpack_remove_login_form', '__return_true', 9999 );
100 add_filter( 'jetpack_sso_bypass_login_forward_wpcom', '__return_true', 9999 );
101 add_filter( 'jetpack_sso_display_disclaimer', '__return_false', 9999 );
102
103 add_filter(
104 'wp_authenticate_user',
105 function () {
106 return new WP_Error( 'wpcom-required', $this->get_login_error_message() ); },
107 9999
108 );
109
110 add_filter( 'jetpack_sso_require_two_step', '__return_true' );
111
112 add_filter( 'allow_password_reset', '__return_false' );
113 } else {
114 // Not multisite.
115
116 // Completely disable the standard login form for admins.
117 add_filter(
118 'wp_authenticate_user',
119 function ( $user ) {
120 if ( is_wp_error( $user ) ) {
121 return $user;
122 }
123 if ( $user->has_cap( $this->role ) ) {
124 return new WP_Error( 'wpcom-required', $this->get_login_error_message(), $user->user_login );
125 }
126 return $user;
127 },
128 9999
129 );
130
131 add_filter(
132 'allow_password_reset',
133 function ( $allow, $user_id ) {
134 if ( user_can( $user_id, $this->role ) ) {
135 return false;
136 }
137 return $allow; },
138 9999,
139 2
140 );
141
142 add_action( 'jetpack_sso_pre_handle_login', array( $this, 'jetpack_set_two_step' ) );
143 }
144 }
145
146 /**
147 * Specifically set the two step filter for Jetpack SSO.
148 *
149 * @param Object $user_data The user data from WordPress.com.
150 *
151 * @return void
152 */
153 public function jetpack_set_two_step( $user_data ) {
154 $user = SSO::get_user_by_wpcom_id( $user_data->ID );
155
156 // Borrowed from Jetpack. Ignores the match_by_email setting.
157 if ( empty( $user ) ) {
158 $user = get_user_by( 'email', $user_data->email );
159 }
160
161 if ( $user && $user->has_cap( $this->role ) ) {
162 add_filter( 'jetpack_sso_require_two_step', '__return_true' );
163 }
164 }
165
166 /**
167 * Get the login error message.
168 *
169 * @return string
170 */
171 private function get_login_error_message() {
172 /**
173 * Filter the login error message.
174 * Defaults to a message that explains the user must use a WordPress.com account with 2FA enabled.
175 *
176 * @param string $message The login error message.
177 * @return string
178 * @since jetpack-12.7
179 * @module SSO
180 */
181 return apply_filters(
182 'jetpack_force_2fa_login_error_message',
183 sprintf( 'For added security, please log in using your WordPress.com account.<br /><br />Note: Your account must have <a href="%1$s" target="_blank">Two Step Authentication</a> enabled, which can be configured from <a href="%2$s" target="_blank">Security Settings</a>.', 'https://support.wordpress.com/security/two-step-authentication/', 'https://wordpress.com/me/security/two-step' )
184 );
185 }
186 }
187