PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.4.4
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.4.4
4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 4.1.7.3.1 4.1.7.3.2 All 140 releases
learnpress / inc / Ajax / MCP / McpApiKeysAjax.php

McpApiKeysAjax.php in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 4.4.4, at inc/Ajax/MCP/McpApiKeysAjax.php

174 lines 5.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 namespace LearnPress\Ajax\MCP;
3
4 use LearnPress\Ajax\AbstractAjax;
5 use LearnPress\MCP\Auth\ApiKeysRepository;
6 use LP_Helper;
7 use LP_Settings;
8 use LP_REST_Response;
9 use Throwable;
10 use Exception;
11
12 defined( 'ABSPATH' ) || exit;
13
14 /**
15 * Handle MCP API key CRUD requests through lp-load-ajax transport.
16 */
17 class McpApiKeysAjax extends AbstractAjax {
18 /**
19 * @var string
20 */
21 protected static $required_capability = 'manage_options';
22
23 /**
24 * Validate current AJAX request for MCP API key actions.
25 *
26 * This helper enforces the required capability and decodes the JSON payload
27 * sent through LearnPress `lp-load-ajax` transport (`$_REQUEST['data']`).
28 * It throws an exception for all invalid states so action handlers can return
29 * a normalized error response.
30 *
31 * @return array<string, mixed>
32 * @throws Exception
33 */
34 public static function check_valid(): array {
35 if ( ! current_user_can( self::$required_capability ) ) {
36 throw new Exception( __( 'You are not allowed to manage MCP API keys.', 'learnpress' ) );
37 }
38
39 if ( 'yes' !== LP_Settings::get_option( 'enable_mcp_integration', 'no' ) ) {
40 throw new Exception( __( 'MCP integration is disabled.', 'learnpress' ) );
41 }
42
43 $params = wp_unslash( $_REQUEST['data'] ?? '' );
44 if ( empty( $params ) ) {
45 throw new Exception( __( 'Error: params invalid!', 'learnpress' ) );
46 }
47
48 $params = LP_Helper::json_decode( $params, true );
49 if ( ! is_array( $params ) ) {
50 throw new Exception( __( 'Error: params invalid!', 'learnpress' ) );
51 }
52
53 return $params;
54 }
55
56 /**
57 * Create a new LearnPress MCP API key for a selected user.
58 *
59 * Expected payload fields:
60 * - `user_id` (int): key owner user ID.
61 * - `description` (string): optional key description.
62 * - `permissions` (string): one of read/write/read_write.
63 *
64 * Success response includes plaintext credentials once in `data.key`.
65 *
66 * @return void
67 */
68 public static function mcp_create_api_key() {
69 $response = new LP_REST_Response();
70
71 try {
72 $payload = self::check_valid();
73
74 $user_id = absint( $payload['user_id'] ?? 0 );
75 $description = LP_Helper::sanitize_params_submitted( $payload['description'] ?? '' );
76 $permissions = LP_Helper::sanitize_params_submitted( $payload['permissions'] ?? 'read', 'key' );
77
78 $created = ( new ApiKeysRepository() )->create_key( $user_id, $description, $permissions );
79 if ( ! $created ) {
80 throw new Exception( __( 'Could not create API key.', 'learnpress' ) );
81 }
82
83 $response->status = 'success';
84 $response->message = __( 'API key created.', 'learnpress' );
85 $response->data = array(
86 'key' => $created,
87 );
88 } catch ( Throwable $e ) {
89 $response->status = 'error';
90 $response->message = $e->getMessage();
91 }
92
93 wp_send_json( $response );
94 }
95
96 /**
97 * Update mutable metadata for an existing MCP API key.
98 *
99 * Expected payload fields:
100 * - `key_id` (int): target key ID.
101 * - `user_id` (int): updated owner user ID.
102 * - `description` (string): updated description.
103 * - `permissions` (string): updated scope value.
104 *
105 * This action does not return secret material.
106 *
107 * @return void
108 */
109 public static function mcp_update_api_key() {
110 $response = new LP_REST_Response();
111
112 try {
113 $payload = self::check_valid();
114
115 $key_id = absint( $payload['key_id'] ?? 0 );
116 $user_id = absint( $payload['user_id'] ?? 0 );
117 $description = LP_Helper::sanitize_params_submitted( $payload['description'] ?? '' );
118 $permissions = LP_Helper::sanitize_params_submitted( $payload['permissions'] ?? 'read', 'key' );
119
120 $updated = ( new ApiKeysRepository() )->update_key_meta( $key_id, $user_id, $description, $permissions );
121 if ( ! $updated ) {
122 throw new Exception( __( 'Could not update API key.', 'learnpress' ) );
123 }
124
125 $response->status = 'success';
126 $response->message = __( 'API key updated.', 'learnpress' );
127 } catch ( Throwable $e ) {
128 $response->status = 'error';
129 $response->message = $e->getMessage();
130 }
131
132 wp_send_json( $response );
133 }
134
135 /**
136 * Regenerate consumer key and secret for an existing MCP API key.
137 *
138 * Expected payload fields:
139 * - `key_id` (int): target key ID.
140 *
141 * Success response includes newly generated plaintext credentials once in
142 * `data.key`. Existing credentials become invalid after regeneration.
143 *
144 * @return void
145 */
146 public static function mcp_regenerate_api_key() {
147 $response = new LP_REST_Response();
148
149 try {
150 $payload = self::check_valid();
151 $key_id = absint( $payload['key_id'] ?? 0 );
152 if ( $key_id <= 0 ) {
153 throw new Exception( __( 'Invalid key ID.', 'learnpress' ) );
154 }
155
156 $regenerated = ( new ApiKeysRepository() )->regenerate_key( $key_id );
157 if ( ! $regenerated ) {
158 throw new Exception( __( 'Could not regenerate API key.', 'learnpress' ) );
159 }
160
161 $response->status = 'success';
162 $response->message = __( 'API key regenerated.', 'learnpress' );
163 $response->data = array(
164 'key' => $regenerated,
165 );
166 } catch ( Throwable $e ) {
167 $response->status = 'error';
168 $response->message = $e->getMessage();
169 }
170
171 wp_send_json( $response );
172 }
173 }
174