PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.4.9
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.4.9
4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 4.1.7.3.1 4.1.7.3.2 All 140 releases
← All changes | inc/jwt/includes/class-jwt-public.php +23 -13 4.4.8 → 4.4.9 View file →
@@ -216,36 +216,46 @@
216 216 *
217 217 * @return (int|bool)
218 218 */
219 219 public function determine_current_user( $user_id ) {
220 - $rest_prefix = trailingslashit( rest_get_url_prefix() );
221 - $request_uri = esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ) );
222 - $valid_api_uri = strpos( $request_uri, $rest_prefix . $this->name . '/' );
220 + if ( ! empty( $user_id ) ) {
221 + return $user_id;
222 + }
223 223
224 + $rest_prefix = trailingslashit( rest_get_url_prefix() );
225 + $request_uri = esc_url_raw( wp_unslash( $_SERVER['REQUEST_URI'] ?? '' ) );
226 +
224 227 /**
225 - * Only check when rest url has wp-json/learnpress/.
228 + * Only process REST requests.
226 229 */
227 - if ( ! empty( $user_id ) || $valid_api_uri === false ) {
230 + if ( strpos( $request_uri, $rest_prefix ) === false ) {
228 231 return $user_id;
229 232 }
230 233
231 234 /*
232 - * if the request URI is for validate the token don't do anything,
233 - * this avoid double calls to the validate_token function.
235 + * Skip the token endpoint itself to avoid double validation.
234 236 */
235 - $validate_token = strpos( $request_uri, '/token' );
237 + if ( strpos( $request_uri, $rest_prefix . $this->namespace . '/token' ) !== false ) {
238 + return $user_id;
239 + }
236 240
237 - /** All course is public so donot need token */
238 - $is_rest_courses = strpos( $request_uri, '/courses' ) || strpos( $request_uri, '/reset-password' ) || strpos( $request_uri, '/course_category' ) || strpos( $request_uri, '/sections/' ) || strpos( $request_uri, '/section-items/' ) || strpos( $request_uri, '/users' );
239 -
240 - if ( $validate_token > 0 ) {
241 + /*
242 + * No Authorization header → let other auth methods (cookie, app passwords) handle it.
243 + */
244 + $has_auth = ! empty( $_SERVER['HTTP_AUTHORIZATION'] ) || ! empty( $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] );
245 + if ( ! $has_auth ) {
241 246 return $user_id;
242 247 }
243 248
249 + /** Public LP endpoints that should not surface auth errors. */
250 + $is_public_lp = (bool) ( strpos( $request_uri, '/courses' ) || strpos( $request_uri, '/reset-password' ) || strpos( $request_uri, '/course_category' ) || strpos( $request_uri, '/sections/' ) || strpos( $request_uri, '/section-items/' ) || strpos( $request_uri, '/users' ) );
251 +
252 + $is_lp_api = strpos( $request_uri, $rest_prefix . $this->name . '/' ) !== false;
253 +
244 254 $token = $this->validate_token( false );
245 255
246 256 if ( is_wp_error( $token ) ) {
247 - if ( ! $is_rest_courses ) {
257 + if ( $is_lp_api && ! $is_public_lp ) {
248 258 $this->jwt_error = $token;
249 259 }
250 260
251 261 return $user_id;