PluginProbe
JSON API Auth / 1.7
JSON API Auth v1.7
3.1.2 3.1.1 2.0.0 2.1.0 2.2.0 2.3.0 2.4.0 2.5.0 2.6.0 2.7.0 2.7.1 2.8.0 2.9.0 2.9.1 3.0.0 3.1.0 trunk 0.1 1.0 1.1 1.2 1.3 1.4 1.5 1.5.1 All 33 releases
json-api-auth / controllers / Auth.php

Auth.php in JSON API Auth 1.7, at controllers/Auth.php

151 lines 3.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /*
4 Controller Name: Auth
5 Controller Description: Authentication add-on controller for the Wordpress JSON API plugin
6 Controller Author: Matt Berg, Ali Qureshi
7 Controller Author Twitter: @parorrey
8 */
9
10
11
12
13
14
15
16 class JSON_API_Auth_Controller {
17
18
19 public function validate_auth_cookie() {
20
21 global $json_api;
22
23 if (!$json_api->query->cookie) {
24
25 $json_api->error("You must include a 'cookie' authentication cookie. Use the `create_auth_cookie` Auth API method.");
26
27 }
28
29 $valid = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in') ? true : false;
30
31 return array(
32
33 "valid" => $valid
34
35 );
36
37
38 }
39
40 public function generate_auth_cookie() {
41
42 global $json_api;
43
44 /*
45 $nonce_id = $json_api->get_nonce_id('auth', 'generate_auth_cookie');
46
47 if (!wp_verify_nonce($json_api->query->nonce, $nonce_id)) {
48
49 $json_api->error("Your 'nonce' value was incorrect. Use the 'get_nonce' API method.");
50 }*/
51
52
53 if (!$json_api->query->username) {
54
55 $json_api->error("You must include a 'username' var in your request.");
56
57 }
58
59
60 if (!$json_api->query->password) {
61
62 $json_api->error("You must include a 'password' var in your request.");
63
64 }
65
66 if ($json_api->query->seconds) $seconds = (int) $json_api->query->seconds;
67
68 else $seconds = 1209600;//14 days
69
70
71
72 $user = wp_authenticate($json_api->query->username, $json_api->query->password);
73
74 if (is_wp_error($user)) {
75
76 $json_api->error("Invalid username and/or password.", 'error', '401');
77
78 remove_action('wp_login_failed', $json_api->query->username);
79
80 }
81
82
83 $expiration = time() + apply_filters('auth_cookie_expiration', $seconds, $user->ID, true);
84
85 $cookie = wp_generate_auth_cookie($user->ID, $expiration, 'logged_in');
86
87 preg_match('|src="(.+?)"|', get_avatar( $user->ID, 32 ), $avatar);
88
89 return array(
90 "cookie" => $cookie,
91 "cookie_name" => LOGGED_IN_COOKIE,
92 "user" => array(
93 "id" => $user->ID,
94 "username" => $user->user_login,
95 "nicename" => $user->user_nicename,
96 "email" => $user->user_email,
97 "url" => $user->user_url,
98 "registered" => $user->user_registered,
99 "displayname" => $user->display_name,
100 "firstname" => $user->user_firstname,
101 "lastname" => $user->last_name,
102 "nickname" => $user->nickname,
103 "description" => $user->user_description,
104 "capabilities" => $user->wp_capabilities,
105 "avatar" => $avatar[1]
106
107 ),
108 );
109 }
110
111
112 public function get_currentuserinfo() {
113 global $json_api;
114
115 if (!$json_api->query->cookie) {
116 $json_api->error("You must include a 'cookie' var in your request. Use the `generate_auth_cookie` Auth API method.");
117
118 }
119
120 $user_id = wp_validate_auth_cookie($json_api->query->cookie, 'logged_in');
121
122 if (!$user_id) {
123 $json_api->error("Invalid authentication cookie. Use the `generate_auth_cookie` Auth API method.");
124 }
125
126 $user = get_userdata($user_id);
127 preg_match('|src="(.+?)"|', get_avatar( $user->ID, 32 ), $avatar);
128
129 return array(
130 "user" => array(
131 "id" => $user->ID,
132 "username" => $user->user_login,
133 "nicename" => $user->user_nicename,
134 "email" => $user->user_email,
135 "url" => $user->user_url,
136 "registered" => $user->user_registered,
137 "displayname" => $user->display_name,
138 "firstname" => $user->user_firstname,
139 "lastname" => $user->last_name,
140 "nickname" => $user->nickname,
141 "description" => $user->user_description,
142 "capabilities" => $user->wp_capabilities,
143
144 "avatar" => $avatar[1]
145
146 )
147
148 );
149
150 }
151 }