PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.4.9
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.4.9
4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 4.1.7.3.1 4.1.7.3.2 All 140 releases
← All changes | inc/jwt/includes/class-jwt-public.php +26 -15 4.1.7.3 → 4.4.9 View file →
@@ -1,5 +1,8 @@
1 1 <?php
2 +
3 +use LP\Firebase\JWT\JWT;
4 +
2 5 /**
3 6 * REST API: LP_Jwt_Public
4 7 *
5 8 * @package LPJWTAuth
@@ -6,10 +9,8 @@
6 9 * @since 1.0.0
7 10 * @author Nhamdv <[email protected]>
8 11 */
9 12
10 -use \Firebase\JWT\JWT;
11 -
12 13 class LP_Jwt_Public {
13 14 private $name;
14 15
15 16 private $version;
@@ -215,36 +216,46 @@
215 216 *
216 217 * @return (int|bool)
217 218 */
218 219 public function determine_current_user( $user_id ) {
219 - $rest_prefix = trailingslashit( rest_get_url_prefix() );
220 - $request_uri = esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) );
221 - $valid_api_uri = strpos( $request_uri, $rest_prefix . $this->name . '/' );
220 + if ( ! empty( $user_id ) ) {
221 + return $user_id;
222 + }
222 223
224 + $rest_prefix = trailingslashit( rest_get_url_prefix() );
225 + $request_uri = esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ?? '' ) );
226 +
223 227 /**
224 - * Only check when rest url has wp-json/learnpress/.
228 + * Only process REST requests.
225 229 */
226 - if ( ! empty( $user_id ) || $valid_api_uri === false ) {
230 + if ( strpos( $request_uri, $rest_prefix ) === false ) {
227 231 return $user_id;
228 232 }
229 233
230 234 /*
231 - * if the request URI is for validate the token don't do anything,
232 - * this avoid double calls to the validate_token function.
235 + * Skip the token endpoint itself to avoid double validation.
233 236 */
234 - $validate_token = strpos( $request_uri, '/token' );
237 + if ( strpos( $request_uri, $rest_prefix . $this->namespace . '/token' ) !== false ) {
238 + return $user_id;
239 + }
235 240
236 - /** All course is public so donot need token */
237 - $is_rest_courses = strpos( $request_uri, '/courses' ) || strpos( $request_uri, '/reset-password' ) || strpos( $request_uri, '/course_category' ) || strpos( $request_uri, '/sections/' ) || strpos( $request_uri, '/section-items/' ) || strpos( $request_uri, '/users' );
238 -
239 - if ( $validate_token > 0 ) {
241 + /*
242 + * No Authorization header → let other auth methods (cookie, app passwords) handle it.
243 + */
244 + $has_auth = ! empty( $_SERVER['HTTP_AUTHORIZATION'] ) || ! empty( $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] );
245 + if ( ! $has_auth ) {
240 246 return $user_id;
241 247 }
242 248
249 + /** Public LP endpoints that should not surface auth errors. */
250 + $is_public_lp = (bool) ( strpos( $request_uri, '/courses' ) || strpos( $request_uri, '/reset-password' ) || strpos( $request_uri, '/course_category' ) || strpos( $request_uri, '/sections/' ) || strpos( $request_uri, '/section-items/' ) || strpos( $request_uri, '/users' ) );
251 +
252 + $is_lp_api = strpos( $request_uri, $rest_prefix . $this->name . '/' ) !== false;
253 +
243 254 $token = $this->validate_token( false );
244 255
245 256 if ( is_wp_error( $token ) ) {
246 - if ( ! $is_rest_courses ) {
257 + if ( $is_lp_api && ! $is_public_lp ) {
247 258 $this->jwt_error = $token;
248 259 }
249 260
250 261 return $user_id;