← All changes
|
includes/widgets/Login_Register_Form/Social_Login_Handler.php
+48
-27
51.1.14
→
51.1.87
View file →
| @@ -7,8 +7,9 @@ | ||
| 7 | 7 | } |
| 8 | 8 | |
| 9 | 9 | // Include Security Manager |
| 10 | 10 | require_once KING_ADDONS_PATH . 'includes/widgets/Login_Register_Form/Security_Manager.php'; |
| 11 | +require_once KING_ADDONS_PATH . 'includes/widgets/Login_Register_Form/Widget_Settings_Resolver.php'; | |
| 11 | 12 | |
| 12 | 13 | /** |
| 13 | 14 | * Social Login Handler for Login Register Form widget |
| 14 | 15 | */ |
| @@ -47,9 +48,11 @@ | ||
| 47 | 48 | wp_send_json_error(['message' => esc_html__('Security check failed.', 'king-addons')]); |
| 48 | 49 | } |
| 49 | 50 | |
| 50 | 51 | $google_token = sanitize_text_field($_POST['google_token'] ?? ''); |
| 51 | - $widget_settings = self::get_widget_settings($_POST['widget_id'] ?? ''); | |
| 52 | + $widget_id = sanitize_text_field($_POST['widget_id'] ?? ''); | |
| 53 | + $post_id = absint($_POST['post_id'] ?? 0); | |
| 54 | + $widget_settings = Widget_Settings_Resolver::resolve($post_id, $widget_id); | |
| 52 | 55 | |
| 53 | 56 | if (empty($google_token)) { |
| 54 | 57 | wp_send_json_error(['message' => esc_html__('Google token is required.', 'king-addons')]); |
| 55 | 58 | } |
| @@ -93,9 +96,11 @@ | ||
| 93 | 96 | wp_send_json_error(['message' => esc_html__('Security check failed.', 'king-addons')]); |
| 94 | 97 | } |
| 95 | 98 | |
| 96 | 99 | $facebook_token = sanitize_text_field($_POST['facebook_token'] ?? ''); |
| 97 | - $widget_settings = self::get_widget_settings($_POST['widget_id'] ?? ''); | |
| 100 | + $widget_id = sanitize_text_field($_POST['widget_id'] ?? ''); | |
| 101 | + $post_id = absint($_POST['post_id'] ?? 0); | |
| 102 | + $widget_settings = Widget_Settings_Resolver::resolve($post_id, $widget_id); | |
| 98 | 103 | |
| 99 | 104 | if (empty($facebook_token)) { |
| 100 | 105 | wp_send_json_error(['message' => esc_html__('Facebook token is required.', 'king-addons')]); |
| 101 | 106 | } |
| @@ -130,12 +135,22 @@ | ||
| 130 | 135 | * Verify Google OAuth token |
| 131 | 136 | */ |
| 132 | 137 | private static function verify_google_token($token, $client_id) |
| 133 | 138 | { |
| 134 | - $url = 'https://oauth2.googleapis.com/tokeninfo?id_token=' . $token; | |
| 139 | + // Security fix: Validate token format | |
| 140 | + if (empty($token) || strlen($token) > 2048) { | |
| 141 | + return false; | |
| 142 | + } | |
| 135 | 143 | |
| 136 | - $response = wp_remote_get($url); | |
| 144 | + $url = 'https://oauth2.googleapis.com/tokeninfo?id_token=' . urlencode($token); | |
| 145 | + | |
| 146 | + $response = wp_remote_get($url, [ | |
| 147 | + 'timeout' => 15, | |
| 148 | + 'user-agent' => 'King Addons Social Login/1.0' | |
| 149 | + ]); | |
| 150 | + | |
| 137 | 151 | if (is_wp_error($response)) { |
| 152 | + // error_log('King Addons Social Login: Google token verification failed: ' . $response->get_error_message()); | |
| 138 | 153 | return false; |
| 139 | 154 | } |
| 140 | 155 | |
| 141 | 156 | $body = wp_remote_retrieve_body($response); |
| @@ -161,13 +176,26 @@ | ||
| 161 | 176 | * Verify Facebook OAuth token |
| 162 | 177 | */ |
| 163 | 178 | private static function verify_facebook_token($token, $app_id, $app_secret) |
| 164 | 179 | { |
| 180 | + // Security fix: Validate inputs | |
| 181 | + if (empty($token) || empty($app_id) || empty($app_secret) || strlen($token) > 1024) { | |
| 182 | + return false; | |
| 183 | + } | |
| 184 | + | |
| 165 | 185 | // First, verify the token |
| 166 | - $verify_url = "https://graph.facebook.com/debug_token?input_token={$token}&access_token={$app_id}|{$app_secret}"; | |
| 186 | + $verify_url = "https://graph.facebook.com/debug_token?" . http_build_query([ | |
| 187 | + 'input_token' => $token, | |
| 188 | + 'access_token' => $app_id . '|' . $app_secret | |
| 189 | + ]); | |
| 167 | 190 | |
| 168 | - $response = wp_remote_get($verify_url); | |
| 191 | + $response = wp_remote_get($verify_url, [ | |
| 192 | + 'timeout' => 15, | |
| 193 | + 'user-agent' => 'King Addons Social Login/1.0' | |
| 194 | + ]); | |
| 195 | + | |
| 169 | 196 | if (is_wp_error($response)) { |
| 197 | + // error_log('King Addons Social Login: Facebook token verification failed: ' . $response->get_error_message()); | |
| 170 | 198 | return false; |
| 171 | 199 | } |
| 172 | 200 | |
| 173 | 201 | $verify_data = json_decode(wp_remote_retrieve_body($response), true); |
| @@ -175,12 +203,20 @@ | ||
| 175 | 203 | return false; |
| 176 | 204 | } |
| 177 | 205 | |
| 178 | 206 | // Get user data |
| 179 | - $user_url = "https://graph.facebook.com/me?fields=id,name,email,first_name,last_name,picture&access_token={$token}"; | |
| 207 | + $user_url = "https://graph.facebook.com/me?" . http_build_query([ | |
| 208 | + 'fields' => 'id,name,email,first_name,last_name,picture', | |
| 209 | + 'access_token' => $token | |
| 210 | + ]); | |
| 180 | 211 | |
| 181 | - $user_response = wp_remote_get($user_url); | |
| 212 | + $user_response = wp_remote_get($user_url, [ | |
| 213 | + 'timeout' => 15, | |
| 214 | + 'user-agent' => 'King Addons Social Login/1.0' | |
| 215 | + ]); | |
| 216 | + | |
| 182 | 217 | if (is_wp_error($user_response)) { |
| 218 | + // error_log('King Addons Social Login: Facebook user data request failed: ' . $user_response->get_error_message()); | |
| 183 | 219 | return false; |
| 184 | 220 | } |
| 185 | 221 | |
| 186 | 222 | $user_data = json_decode(wp_remote_retrieve_body($user_response), true); |
| @@ -212,9 +248,9 @@ | ||
| 212 | 248 | } |
| 213 | 249 | |
| 214 | 250 | // Additional security checks for social login |
| 215 | 251 | if (!filter_var($email, FILTER_VALIDATE_EMAIL)) { |
| 216 | - error_log("King Addons Security: Invalid email from {$provider}: {$email}"); | |
| 252 | + // error_log("King Addons Security: Invalid email from {$provider}: {$email}"); | |
| 217 | 253 | return [ |
| 218 | 254 | 'success' => false, |
| 219 | 255 | 'message' => esc_html__('Invalid email address from social provider.', 'king-addons') |
| 220 | 256 | ]; |
| @@ -227,11 +263,11 @@ | ||
| 227 | 263 | // User exists, log them in |
| 228 | 264 | wp_set_current_user($user->ID); |
| 229 | 265 | wp_set_auth_cookie($user->ID); |
| 230 | 266 | |
| 231 | - // Update social provider info | |
| 232 | - update_user_meta($user->ID, 'king_addons_social_provider', $provider); | |
| 233 | - update_user_meta($user->ID, 'king_addons_social_provider_id', $user_data['provider_id']); | |
| 267 | + // Update social provider info with sanitized data | |
| 268 | + update_user_meta($user->ID, 'king_addons_social_provider', sanitize_text_field($provider)); | |
| 269 | + update_user_meta($user->ID, 'king_addons_social_provider_id', sanitize_text_field($sanitized_data['provider_id'])); | |
| 234 | 270 | |
| 235 | 271 | } else { |
| 236 | 272 | // Create new user with sanitized data |
| 237 | 273 | $username = self::generate_username($sanitized_data['name'] ?: $sanitized_data['email']); |
| @@ -294,23 +330,8 @@ | ||
| 294 | 330 | $counter++; |
| 295 | 331 | } |
| 296 | 332 | |
| 297 | 333 | return $username; |
| 298 | - } | |
| 299 | - | |
| 300 | - /** | |
| 301 | - * Get widget settings from POST data | |
| 302 | - */ | |
| 303 | - private static function get_widget_settings($widget_id) | |
| 304 | - { | |
| 305 | - // This would be enhanced to get actual widget settings | |
| 306 | - // For now, return settings from POST data | |
| 307 | - return [ | |
| 308 | - 'google_client_id' => sanitize_text_field($_POST['google_client_id'] ?? ''), | |
| 309 | - 'google_client_secret' => sanitize_text_field($_POST['google_client_secret'] ?? ''), | |
| 310 | - 'facebook_app_id' => sanitize_text_field($_POST['facebook_app_id'] ?? ''), | |
| 311 | - 'facebook_app_secret' => sanitize_text_field($_POST['facebook_app_secret'] ?? ''), | |
| 312 | - ]; | |
| 313 | 334 | } |
| 314 | 335 | |
| 315 | 336 | /** |
| 316 | 337 | * Handle Google OAuth callback (for future server-side flow) |