PluginProbe
JSON API Auth / 1.1
JSON API Auth v1.1
3.1.2 3.1.1 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.7.1 2.8.0 2.9.0 2.9.1 3.0.0 3.1.0 trunk 0.1 1.0 1.1 1.2 1.3 1.4 1.5 1.5.1 All 33 releases
json-api-auth / controllers / Auth.php

Auth.php in JSON API Auth 1.1, at controllers/Auth.php

250 lines 4.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /*
4
5 Controller Name: Auth
6
7 Controller Description: Authentication add-on controller for the Wordpress JSON API plugin
8
9 Controller Author: Matt Berg
10
11 Controller Author Twitter: @mattberg
12
13 */
14
15
16
17 class JSON_API_Auth_Controller {
18
19
20
21 public function validate_auth_cookie() {
22
23 global $json_api;
24
25
26
27 if (!$json_api->query->cookie) {
28
29 $json_api->error("You must include a 'cookie' authentication cookie. Use the `create_auth_cookie` Auth API method.");
30
31 }
32
33
34
35 $valid = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in') ? true : false;
36
37
38
39 return array(
40
41 "valid" => $valid
42
43 );
44
45 }
46
47
48
49 public function generate_auth_cookie() {
50
51 global $json_api;
52
53
54
55 $nonce_id = $json_api->get_nonce_id('auth', 'generate_auth_cookie');
56
57 if (!wp_verify_nonce($json_api->query->nonce, $nonce_id)) {
58
59 $json_api->error("Your 'nonce' value was incorrect. Use the 'get_nonce' API method.");
60
61 }
62
63
64
65 if (!$json_api->query->username) {
66
67 $json_api->error("You must include a 'username' var in your request.");
68
69 }
70
71
72
73 if (!$json_api->query->password) {
74
75 $json_api->error("You must include a 'password' var in your request.");
76
77 }
78
79
80
81 $user = wp_authenticate($json_api->query->username, $json_api->query->password);
82
83 if (is_wp_error($user)) {
84
85 $json_api->error("Invalid username and/or password.", 'error', '401');
86
87 remove_action('wp_login_failed', $json_api->query->username);
88
89 }
90
91
92
93 $expiration = time() + apply_filters('auth_cookie_expiration', -1209600, $user->ID, true);
94
95
96
97 $cookie = wp_generate_auth_cookie($user->ID, $expiration, 'logged_in');
98
99
100
101
102
103 preg_match('|src="(.+?)"|', get_avatar( $user->ID, 32 ), $avatar);
104
105
106
107
108
109
110
111 return array(
112
113 "cookie" => $cookie,
114
115 "user" => array(
116
117 "id" => $user->ID,
118
119 "username" => $user->user_login,
120
121 "nicename" => $user->user_nicename,
122
123 "email" => $user->user_email,
124
125 "url" => $user->user_url,
126
127 "registered" => $user->user_registered,
128
129 "displayname" => $user->display_name,
130
131 "firstname" => $user->user_firstname,
132
133 "lastname" => $user->last_name,
134
135 "nickname" => $user->nickname,
136
137 "description" => $user->user_description,
138
139 "capabilities" => $user->wp_capabilities,
140
141 "avatar" => $avatar[1]
142
143 ),
144
145 );
146
147 }
148
149
150 public function clear_auth_cookie() {
151
152 global $json_api;
153
154 if (!$json_api->query->cookie) {
155
156 $json_api->error("You must include a valid 'cookie' to clear it.");
157
158 }
159
160 $user_id = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in');
161
162 if (!$user_id) {
163
164 $json_api->error("Invalid authentication cookie. Provide a valid cookie to clear.");
165
166 }
167
168 $expiration = time() + apply_filters('auth_cookie_expiration', -1209600, $user_id, true);
169
170 $cookie = wp_generate_auth_cookie($user_id, $expiration, 'logged_in');
171
172 $valid = wp_validate_auth_cookie($cookie, 'logged_in') ? true : false;
173
174 return array(
175
176 "valid" => $valid
177
178 );
179
180 }
181
182 public function get_currentuserinfo() {
183
184 global $json_api;
185
186
187
188 if (!$json_api->query->cookie) {
189
190 $json_api->error("You must include a 'cookie' var in your request. Use the `generate_auth_cookie` Auth API method.");
191
192 }
193
194
195
196 $user_id = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in');
197
198 if (!$user_id) {
199
200 $json_api->error("Invalid authentication cookie. Use the `generate_auth_cookie` Auth API method.");
201
202 }
203
204
205
206 $user = get_userdata($user_id);
207
208 preg_match('|src="(.+?)"|', get_avatar( $user->ID, 32 ), $avatar);
209
210
211
212 return array(
213
214 "user" => array(
215
216 "id" => $user->ID,
217
218 "username" => $user->user_login,
219
220 "nicename" => $user->user_nicename,
221
222 "email" => $user->user_email,
223
224 "url" => $user->user_url,
225
226 "registered" => $user->user_registered,
227
228 "displayname" => $user->display_name,
229
230 "firstname" => $user->user_firstname,
231
232 "lastname" => $user->last_name,
233
234 "nickname" => $user->nickname,
235
236 "description" => $user->user_description,
237
238 "capabilities" => $user->wp_capabilities,
239
240 "avatar" => $avatar[1]
241
242 )
243
244 );
245
246 }
247
248
249
250 }