PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.3.7
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.3.7
4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 4.1.7.3.1 4.1.7.3.2 All 140 releases
learnpress / inc / Ajax / MCP / McpApiKeysAjax.php

McpApiKeysAjax.php in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 4.3.7, at inc/Ajax/MCP/McpApiKeysAjax.php

169 lines 4.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 namespace LearnPress\Ajax\MCP;
3
4 use LearnPress\Ajax\AbstractAjax;
5 use LearnPress\MCP\Auth\ApiKeysRepository;
6 use LP_Helper;
7 use LP_REST_Response;
8 use Throwable;
9 use Exception;
10
11 defined( 'ABSPATH' ) || exit;
12
13 /**
14 * Handle MCP API key CRUD requests through lp-load-ajax transport.
15 */
16 class McpApiKeysAjax extends AbstractAjax {
17 /**
18 * @var string
19 */
20 protected static $required_capability = 'manage_options';
21
22 /**
23 * Validate current AJAX request for MCP API key actions.
24 *
25 * This helper enforces the required capability and decodes the JSON payload
26 * sent through LearnPress `lp-load-ajax` transport (`$_REQUEST['data']`).
27 * It throws an exception for all invalid states so action handlers can return
28 * a normalized error response.
29 *
30 * @return array<string, mixed>
31 * @throws Exception
32 */
33 public static function check_valid(): array {
34 if ( ! current_user_can( self::$required_capability ) ) {
35 throw new Exception( __( 'You are not allowed to manage MCP API keys.', 'learnpress' ) );
36 }
37
38 $params = wp_unslash( $_REQUEST['data'] ?? '' );
39 if ( empty( $params ) ) {
40 throw new Exception( __( 'Error: params invalid!', 'learnpress' ) );
41 }
42
43 $params = LP_Helper::json_decode( $params, true );
44 if ( ! is_array( $params ) ) {
45 throw new Exception( __( 'Error: params invalid!', 'learnpress' ) );
46 }
47
48 return $params;
49 }
50
51 /**
52 * Create a new LearnPress MCP API key for a selected user.
53 *
54 * Expected payload fields:
55 * - `user_id` (int): key owner user ID.
56 * - `description` (string): optional key description.
57 * - `permissions` (string): one of read/write/read_write.
58 *
59 * Success response includes plaintext credentials once in `data.key`.
60 *
61 * @return void
62 */
63 public static function mcp_create_api_key() {
64 $response = new LP_REST_Response();
65
66 try {
67 $payload = self::check_valid();
68
69 $user_id = absint( $payload['user_id'] ?? 0 );
70 $description = LP_Helper::sanitize_params_submitted( $payload['description'] ?? '' );
71 $permissions = LP_Helper::sanitize_params_submitted( $payload['permissions'] ?? 'read', 'key' );
72
73 $created = ( new ApiKeysRepository() )->create_key( $user_id, $description, $permissions );
74 if ( ! $created ) {
75 throw new Exception( __( 'Could not create API key.', 'learnpress' ) );
76 }
77
78 $response->status = 'success';
79 $response->message = __( 'API key created.', 'learnpress' );
80 $response->data = array(
81 'key' => $created,
82 );
83 } catch ( Throwable $e ) {
84 $response->status = 'error';
85 $response->message = $e->getMessage();
86 }
87
88 wp_send_json( $response );
89 }
90
91 /**
92 * Update mutable metadata for an existing MCP API key.
93 *
94 * Expected payload fields:
95 * - `key_id` (int): target key ID.
96 * - `user_id` (int): updated owner user ID.
97 * - `description` (string): updated description.
98 * - `permissions` (string): updated scope value.
99 *
100 * This action does not return secret material.
101 *
102 * @return void
103 */
104 public static function mcp_update_api_key() {
105 $response = new LP_REST_Response();
106
107 try {
108 $payload = self::check_valid();
109
110 $key_id = absint( $payload['key_id'] ?? 0 );
111 $user_id = absint( $payload['user_id'] ?? 0 );
112 $description = LP_Helper::sanitize_params_submitted( $payload['description'] ?? '' );
113 $permissions = LP_Helper::sanitize_params_submitted( $payload['permissions'] ?? 'read', 'key' );
114
115 $updated = ( new ApiKeysRepository() )->update_key_meta( $key_id, $user_id, $description, $permissions );
116 if ( ! $updated ) {
117 throw new Exception( __( 'Could not update API key.', 'learnpress' ) );
118 }
119
120 $response->status = 'success';
121 $response->message = __( 'API key updated.', 'learnpress' );
122 } catch ( Throwable $e ) {
123 $response->status = 'error';
124 $response->message = $e->getMessage();
125 }
126
127 wp_send_json( $response );
128 }
129
130 /**
131 * Regenerate consumer key and secret for an existing MCP API key.
132 *
133 * Expected payload fields:
134 * - `key_id` (int): target key ID.
135 *
136 * Success response includes newly generated plaintext credentials once in
137 * `data.key`. Existing credentials become invalid after regeneration.
138 *
139 * @return void
140 */
141 public static function mcp_regenerate_api_key() {
142 $response = new LP_REST_Response();
143
144 try {
145 $payload = self::check_valid();
146 $key_id = absint( $payload['key_id'] ?? 0 );
147 if ( $key_id <= 0 ) {
148 throw new Exception( __( 'Invalid key ID.', 'learnpress' ) );
149 }
150
151 $regenerated = ( new ApiKeysRepository() )->regenerate_key( $key_id );
152 if ( ! $regenerated ) {
153 throw new Exception( __( 'Could not regenerate API key.', 'learnpress' ) );
154 }
155
156 $response->status = 'success';
157 $response->message = __( 'API key regenerated.', 'learnpress' );
158 $response->data = array(
159 'key' => $regenerated,
160 );
161 } catch ( Throwable $e ) {
162 $response->status = 'error';
163 $response->message = $e->getMessage();
164 }
165
166 wp_send_json( $response );
167 }
168 }
169