PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.4.10
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.4.10
4.4.10 4.4.9.1 4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 All 142 releases
← All changes | inc/MCP/Auth/ApiKeyAuthenticator.php +16 -43 4.3.7 → 4.4.10 View file →
@@ -1,8 +1,9 @@
1 1 <?php
2 2
3 3 namespace LearnPress\MCP\Auth;
4 4
5 +use LearnPress\MCP\Support\Errors;
5 6 use LP_Helper;
6 7 use WP_Error;
7 8 use WP_REST_Request;
8 9
@@ -110,13 +111,9 @@
110 111 return $this->auth_error;
111 112 }
112 113
113 114 if ( ! AuthContext::is_api_key_auth() ) {
114 - return new WP_Error(
115 - 'learnpress_mcp_api_key_required',
116 - __( 'MCP API key authentication is required.', 'learnpress' ),
117 - array( 'status' => 401 )
118 - );
115 + return Errors::api_key_required();
119 116 }
120 117
121 118 return $error;
122 119 }
@@ -148,21 +145,21 @@
148 145 $consumer_key = $credentials['consumer_key'];
149 146 $consumer_secret = $credentials['consumer_secret'];
150 147
151 148 if ( '' === $consumer_key || '' === $consumer_secret ) {
152 - $this->auth_error = $this->invalid_credentials_error();
149 + $this->auth_error = Errors::invalid_api_credentials();
153 150 return 0;
154 151 }
155 152
156 153 $key = $this->keys_repository->find_by_consumer_key( $consumer_key );
157 154 if ( ! $key || empty( $key->consumer_secret ) || ! $this->keys_repository->verify_secret_hash( (string) $key->consumer_secret, $consumer_secret ) ) {
158 - $this->auth_error = $this->invalid_credentials_error();
155 + $this->auth_error = Errors::invalid_api_credentials();
159 156 return 0;
160 157 }
161 158
162 159 $resolved_user_id = absint( $key->user_id );
163 160 if ( $resolved_user_id <= 0 || ! get_user_by( 'id', $resolved_user_id ) ) {
164 - $this->auth_error = $this->invalid_credentials_error();
161 + $this->auth_error = Errors::invalid_api_credentials();
165 162 return 0;
166 163 }
167 164
168 165 AuthContext::set_api_key_auth(
@@ -209,22 +206,9 @@
209 206 *
210 207 * @return array<string, mixed>
211 208 */
212 209 protected function parse_credentials(): array {
213 - $consumer_key_present = isset( $_GET['consumer_key'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
214 - $consumer_secret_present = isset( $_GET['consumer_secret'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
215 210
216 - $consumer_key = $consumer_key_present ? LP_Helper::sanitize_params_submitted( $_GET['consumer_key'] ) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
217 - $consumer_secret = $consumer_secret_present ? LP_Helper::sanitize_params_submitted( $_GET['consumer_secret'] ) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
218 -
219 - if ( $consumer_key_present || $consumer_secret_present ) {
220 - return array(
221 - 'present' => true,
222 - 'consumer_key' => $consumer_key,
223 - 'consumer_secret' => $consumer_secret,
224 - );
225 - }
226 -
227 211 $has_php_auth_user = isset( $_SERVER['PHP_AUTH_USER'] );
228 212 $has_php_auth_pw = isset( $_SERVER['PHP_AUTH_PW'] );
229 213
230 214 if ( $has_php_auth_user || $has_php_auth_pw ) {
@@ -340,18 +324,21 @@
340 324 if ( '' === $request_uri ) {
341 325 return false;
342 326 }
343 327
344 - $rest_prefix = trailingslashit( rest_get_url_prefix() );
345 - $is_mcp_target = false;
346 - foreach ( $this->get_target_routes() as $route ) {
347 - $target_path = $rest_prefix . ltrim( $route, '/' );
348 - if ( false !== strpos( $request_uri, $target_path ) ) {
349 - $is_mcp_target = true;
350 - break;
351 - }
328 + $request_path = wp_parse_url( $request_uri, PHP_URL_PATH );
329 + if ( ! is_string( $request_path ) ) {
330 + return false;
352 331 }
353 332
333 + $rest_prefix = '/' . trailingslashit( rest_get_url_prefix() );
334 + $prefix_position = strpos( $request_path, $rest_prefix );
335 + $is_mcp_target = false;
336 + if ( false !== $prefix_position ) {
337 + $route = '/' . ltrim( substr( $request_path, $prefix_position + strlen( $rest_prefix ) ), '/' );
338 + $is_mcp_target = $this->route_matches_mcp_target( $route );
339 + }
340 +
354 341 return (bool) apply_filters( 'learn-press/mcp/api-keys/is-target-rest-request', $is_mcp_target, $request_uri, self::MCP_ROUTE );
355 342 }
356 343 /**
357 344 * Whether a WP_REST_Request route is the MCP endpoint.
@@ -396,22 +383,8 @@
396 383 }
397 384
398 385 return false;
399 386 }
400 - /**
401 - * Standardized invalid credentials error.
402 - *
403 - * @return WP_Error
404 - */
405 - protected function invalid_credentials_error(): WP_Error {
406 -
407 - return new WP_Error(
408 - 'learnpress_mcp_invalid_api_key_credentials',
409 - __( 'Invalid MCP API credentials.', 'learnpress' ),
410 - array( 'status' => 401 )
411 - );
412 - }
413 -
414 387 /**
415 388 * Validate expected consumer key format.
416 389 *
417 390 * @param string $consumer_key Plaintext consumer key.