PluginProbe
JSON API Auth / 1.5
JSON API Auth v1.5
3.1.2 3.1.1 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.7.1 2.8.0 2.9.0 2.9.1 3.0.0 3.1.0 trunk 0.1 1.0 1.1 1.2 1.3 1.4 1.5 1.5.1 All 33 releases
json-api-auth / controllers / Auth.php

Auth.php in JSON API Auth 1.5, at controllers/Auth.php

184 lines 4.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /*
4 Controller Name: Auth
5 Controller Description: Authentication add-on controller for the Wordpress JSON API plugin
6 Controller Author: Matt Berg, Ali Qureshi
7 Controller Author Twitter: @parorrey
8 */
9
10
11
12
13
14
15
16 class JSON_API_Auth_Controller {
17
18
19 public function validate_auth_cookie() {
20
21 global $json_api;
22
23 if (!$json_api->query->cookie) {
24
25 $json_api->error("You must include a 'cookie' authentication cookie. Use the `create_auth_cookie` Auth API method.");
26
27 }
28
29 $valid = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in') ? true : false;
30
31 return array(
32
33 "valid" => $valid
34
35 );
36
37
38 }
39
40 public function generate_auth_cookie() {
41
42 global $json_api;
43
44 $nonce_id = $json_api->get_nonce_id('auth', 'generate_auth_cookie');
45
46
47
48 if (!wp_verify_nonce($json_api->query->nonce, $nonce_id)) {
49
50 $json_api->error("Your 'nonce' value was incorrect. Use the 'get_nonce' API method.");
51 }
52
53
54 if (!$json_api->query->username) {
55
56 $json_api->error("You must include a 'username' var in your request.");
57
58 }
59
60
61 if (!$json_api->query->password) {
62
63 $json_api->error("You must include a 'password' var in your request.");
64
65 }
66
67 if ($json_api->query->seconds) $seconds = (int) $json_api->query->seconds;
68
69 else $seconds = 1209600;//14 days
70
71
72
73 $user = wp_authenticate($json_api->query->username, $json_api->query->password);
74
75 if (is_wp_error($user)) {
76
77 $json_api->error("Invalid username and/or password.", 'error', '401');
78
79 remove_action('wp_login_failed', $json_api->query->username);
80
81 }
82
83
84 $expiration = time() + apply_filters('auth_cookie_expiration', $seconds, $user->ID, true);
85
86 $cookie = wp_generate_auth_cookie($user->ID, $expiration, 'logged_in');
87
88 preg_match('|src="(.+?)"|', get_avatar( $user->ID, 32 ), $avatar);
89
90 return array(
91 "cookie" => $cookie,
92 "user" => array(
93 "id" => $user->ID,
94 "username" => $user->user_login,
95 "nicename" => $user->user_nicename,
96 "email" => $user->user_email,
97 "url" => $user->user_url,
98 "registered" => $user->user_registered,
99 "displayname" => $user->display_name,
100 "firstname" => $user->user_firstname,
101 "lastname" => $user->last_name,
102 "nickname" => $user->nickname,
103 "description" => $user->user_description,
104 "capabilities" => $user->wp_capabilities,
105 "avatar" => $avatar[1]
106
107 ),
108 );
109 }
110
111
112 /*
113 public function clear_auth_cookie() {
114 global $json_api;
115 if (!$json_api->query->cookie) {
116
117 $json_api->error("You must include a valid 'cookie' to clear it.");
118 }
119
120
121
122 $user_id = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in');
123
124
125 if (!$user_id) {
126 $json_api->error("Invalid authentication cookie. Provide a valid cookie to clear.");
127 }
128
129
130 $expiration = time() + apply_filters('auth_cookie_expiration', -1209600, $user_id, true);
131
132 $cookie = wp_generate_auth_cookie($user_id, $expiration, 'logged_in');
133
134 $valid = wp_validate_auth_cookie($cookie, 'logged_in') ? true : false;
135
136
137 return array(
138 "valid" => $valid
139 );
140
141 }
142 */
143
144
145 public function get_currentuserinfo() {
146 global $json_api;
147
148 if (!$json_api->query->cookie) {
149 $json_api->error("You must include a 'cookie' var in your request. Use the `generate_auth_cookie` Auth API method.");
150
151 }
152
153 $user_id = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in');
154
155 if (!$user_id) {
156 $json_api->error("Invalid authentication cookie. Use the `generate_auth_cookie` Auth API method.");
157 }
158
159 $user = get_userdata($user_id);
160 preg_match('|src="(.+?)"|', get_avatar( $user->ID, 32 ), $avatar);
161
162 return array(
163 "user" => array(
164 "id" => $user->ID,
165 "username" => $user->user_login,
166 "nicename" => $user->user_nicename,
167 "email" => $user->user_email,
168 "url" => $user->user_url,
169 "registered" => $user->user_registered,
170 "displayname" => $user->display_name,
171 "firstname" => $user->user_firstname,
172 "lastname" => $user->last_name,
173 "nickname" => $user->nickname,
174 "description" => $user->user_description,
175 "capabilities" => $user->wp_capabilities,
176
177 "avatar" => $avatar[1]
178
179 )
180
181 );
182
183 }
184 }