PluginProbe
Loginizer / 1.8.3
Loginizer v1.8.3
2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 All 74 releases
← All changes | functions.php +406 -219 1.01.8.3 View file →
@@ -1,219 +1,406 @@
1 -<?php
2 -
3 -// Get the client IP
4 -function lz_getip(){
5 - if(isset($_SERVER["REMOTE_ADDR"])){
6 - return $_SERVER["REMOTE_ADDR"];
7 - }elseif(isset($_SERVER["HTTP_X_FORWARDED_FOR"])){
8 - return $_SERVER["HTTP_X_FORWARDED_FOR"];
9 - }elseif(isset($_SERVER["HTTP_CLIENT_IP"])){
10 - return $_SERVER["HTTP_CLIENT_IP"];
11 - }
12 -}
13 -
14 -// Get the value of option from lz_options table
15 -function lz_get_option($option_name, $default = ''){
16 -
17 - global $wpdb;
18 -
19 - $result = lz_selectquery("SELECT `option_value` FROM `".$wpdb->prefix."lz_options` WHERE `option_name` = '".$option_name."';");
20 -
21 - if(!empty($result['option_value'])){
22 - return $result['option_value'];
23 - }
24 -
25 - return $default;
26 -}
27 -
28 -// Update the value of an option in lz_options table
29 -function lz_update_option($option_name, $value){
30 -
31 - global $wpdb;
32 -
33 - $result = $wpdb->query("INSERT INTO `".$wpdb->prefix."lz_options` SET `option_name` = '".$option_name."', `option_value` = '".$value."', `updated` = '".time()."' ON DUPLICATE KEY UPDATE `option_value` = '".$value."', `updated` = '".time()."';");
34 -
35 - if(empty($result)){
36 - return false;
37 - }
38 -
39 - return true;
40 -}
41 -
42 -// Execute a select query and return an array
43 -function lz_selectquery($query, $array = 0){
44 - global $wpdb;
45 -
46 - $result = $wpdb->get_results($query, 'ARRAY_A');
47 -
48 - if(empty($array)){
49 - return current($result);
50 - }else{
51 - return $result;
52 - }
53 -}
54 -
55 -// Check if an IP is valid
56 -function lz_valid_ip($ip){
57 -
58 - if(!ip2long($ip)){
59 - return false;
60 - }
61 - return true;
62 -}
63 -
64 -// Check if a field is posted via POST else return default value
65 -function lz_optpost($name, $default = ''){
66 -
67 - if(!empty($_POST[$name])){
68 - return lz_inputsec(lz_htmlizer(trim($_POST[$name])));
69 - }
70 -
71 - return $default;
72 -}
73 -
74 -// Check if a field is posted via GET else return default value
75 -function lz_optget($name, $default = ''){
76 -
77 - if(!empty($_GET[$name])){
78 - return lz_inputsec(lz_htmlizer(trim($_GET[$name])));
79 - }
80 -
81 - return $default;
82 -}
83 -
84 -// Check if a field is posted via GET or POST else return default value
85 -function lz_optreq($name, $default = ''){
86 -
87 - if(!empty($_REQUEST[$name])){
88 - return lz_inputsec(lz_htmlizer(trim($_REQUEST[$name])));
89 - }
90 -
91 - return $default;
92 -}
93 -
94 -function lz_inputsec($string){
95 -
96 - if(!get_magic_quotes_gpc()){
97 -
98 - $string = addslashes($string);
99 -
100 - }else{
101 -
102 - $string = stripslashes($string);
103 - $string = addslashes($string);
104 -
105 - }
106 -
107 - // This is to replace ` which can cause the command to be executed in exec()
108 - $string = str_replace('`', '\`', $string);
109 -
110 - return $string;
111 -
112 -}
113 -
114 -function lz_htmlizer($string){
115 -
116 - $string = htmlentities($string, ENT_QUOTES, 'UTF-8');
117 -
118 - $string = preg_replace('/(&amp;#(\d{1,7}|x[0-9a-fA-F]{1,6});)/e', 'entity_check(\\2);', $string);
119 -
120 - return $string;
121 -
122 -}
123 -
124 -// Check if a checkbox is selected
125 -function lz_is_checked($post){
126 -
127 - if(!empty($_POST[$post])){
128 - return true;
129 - }
130 - return false;
131 -}
132 -
133 -// Reoort an error
134 -function lz_report_error($error = array()){
135 -
136 - if(empty($error)){
137 - return true;
138 - }
139 -
140 - $error_string = '<b>Please fix the below error(s) :</b> <br />';
141 -
142 - foreach($error as $ek => $ev){
143 - $error_string .= '* '.$ev.'<br />';
144 - }
145 -
146 - echo '<div id="message" class="error"><p>'
147 - . __($error_string, 'loginizer')
148 - . '</p></div>';
149 -}
150 -
151 -// Report a notice
152 -function lz_report_notice($notice = array()){
153 -
154 - global $wp_version;
155 -
156 - if(empty($notice)){
157 - return true;
158 - }
159 -
160 - // Which class do we have to use ?
161 - if(version_compare($wp_version, '3.8', '<')){
162 - $notice_class = 'updated';
163 - }else{
164 - $notice_class = 'updated';
165 - }
166 -
167 - $notice_string = '<b>Please check the below notice(s) :</b> <br />';
168 -
169 - foreach($notice as $ek => $ev){
170 - $notice_string .= '* '.$ev.'<br />';
171 - }
172 -
173 - echo '<div id="message" class="'.$notice_class.'"><p>'
174 - . __($notice_string, 'loginizer')
175 - . '</p></div>';
176 -}
177 -
178 -// Convert an objext to array
179 -function lz_objectToArray($d){
180 -
181 - if(is_object($d)){
182 - $d = get_object_vars($d);
183 - }
184 -
185 - if(is_array($d)){
186 - return array_map(__FUNCTION__, $d); // recursive
187 - }elseif(is_object($d)){
188 - return lz_objectToArray($d);
189 - }else{
190 - return $d;
191 - }
192 -}
193 -
194 -// Sanitize variables
195 -function lz_sanitize_variables($variables = array()){
196 -
197 - if(is_array($variables)){
198 - foreach($variables as $k => $v){
199 - $variables[$k] = trim($v);
200 - $variables[$k] = escapeshellcmd($v);
201 - }
202 - }else{
203 - $variables = escapeshellcmd(trim($variables));
204 - }
205 -
206 - return $variables;
207 -}
208 -
209 -// Is multisite ?
210 -function lz_is_multisite() {
211 -
212 - if(function_exists('get_site_option') && function_exists('is_multisite') && is_multisite()){
213 - return true;
214 - }
215 -
216 - return false;
217 -}
218 -
219 -?>
1 +<?php
2 +
3 +include_once(LOGINIZER_DIR.'/lib/IPv6/IPv6.php');
4 +
5 +// Get the client IP
6 +function _lz_getip(){
7 + if(isset($_SERVER["REMOTE_ADDR"])){
8 + return $_SERVER["REMOTE_ADDR"];
9 + }elseif(isset($_SERVER["HTTP_X_FORWARDED_FOR"])){
10 + return $_SERVER["HTTP_X_FORWARDED_FOR"];
11 + }elseif(isset($_SERVER["HTTP_CLIENT_IP"])){
12 + return $_SERVER["HTTP_CLIENT_IP"];
13 + }
14 +}
15 +
16 +// Get the client IP
17 +function lz_getip(){
18 +
19 + global $loginizer;
20 +
21 + // Just so that we have something
22 + $ip = _lz_getip();
23 +
24 + $loginizer['ip_method'] = (int) @$loginizer['ip_method'];
25 +
26 + if(isset($_SERVER["REMOTE_ADDR"])){
27 + $ip = $_SERVER["REMOTE_ADDR"];
28 + }
29 +
30 + if(isset($_SERVER["HTTP_X_FORWARDED_FOR"]) && @$loginizer['ip_method'] == 1){
31 + if(strpos($_SERVER["HTTP_X_FORWARDED_FOR"], ',')){
32 + $temp_ip = explode(',', $_SERVER["HTTP_X_FORWARDED_FOR"]);
33 + $ip = trim($temp_ip[0]);
34 + }else{
35 + $ip = $_SERVER["HTTP_X_FORWARDED_FOR"];
36 + }
37 + }
38 +
39 + if(isset($_SERVER["HTTP_CLIENT_IP"]) && @$loginizer['ip_method'] == 2){
40 + $ip = $_SERVER["HTTP_CLIENT_IP"];
41 + }
42 +
43 + if(@$loginizer['ip_method'] == 3 && isset($_SERVER[@$loginizer['custom_ip_method']])){
44 + $ip = $_SERVER[@$loginizer['custom_ip_method']];
45 + }
46 +
47 + // Hacking fix for X-Forwarded-For
48 + if(!lz_valid_ip($ip)){
49 + return '';
50 + }
51 +
52 + return $ip;
53 +
54 +}
55 +
56 +// Execute a select query and return an array
57 +function lz_selectquery($query, $array = 0){
58 + global $wpdb;
59 +
60 + $result = $wpdb->get_results($query, 'ARRAY_A');
61 +
62 + if(empty($array)){
63 + return current($result);
64 + }else{
65 + return $result;
66 + }
67 +}
68 +
69 +// Check if an IP is valid
70 +function lz_valid_ip($ip){
71 +
72 + // IPv6
73 + if(lz_valid_ipv6($ip)){
74 + return true;
75 + }
76 +
77 + // IPv4
78 + if(!ip2long($ip) || !lz_valid_ipv4($ip)){
79 + return false;
80 + }
81 +
82 + return true;
83 +}
84 +
85 +function lz_valid_ipv4($ip){
86 + if(!preg_match('/^(\d){1,3}\.(\d){1,3}\.(\d){1,3}\.(\d){1,3}$/is', $ip) || substr_count($ip, '.') != 3){
87 + return false;
88 + }
89 +
90 + $r = explode('.', $ip);
91 +
92 + foreach($r as $v){
93 + $v = (int) $v;
94 + if($v > 255 || $v < 0){
95 + return false;
96 + }
97 + }
98 +
99 + return true;
100 +
101 +}
102 +
103 +function lz_valid_ipv6($ip){
104 +
105 + $pattern = '/^((([0-9A-Fa-f]{1,4}:){7}[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){6}:[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){5}:([0-9A-Fa-f]{1,4}:)?[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){4}:([0-9A-Fa-f]{1,4}:){0,2}[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){3}:([0-9A-Fa-f]{1,4}:){0,3}[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){2}:([0-9A-Fa-f]{1,4}:){0,4}[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){6}((\b((25[0-5])|(1\d{2})|(2[0-4]\d)|(\d{1,2}))\b)\.){3}(\b((25[0-5])|(1\d{2})|(2[0-4]\d)|(\d{1,2}))\b))|(([0-9A-Fa-f]{1,4}:){0,5}:((\b((25[0-5])|(1\d{2})|(2[0-4]\d)|(\d{1,2}))\b)\.){3}(\b((25[0-5])|(1\d{2})|(2[0-4]\d)|(\d{1,2}))\b))|(::([0-9A-Fa-f]{1,4}:){0,5}((\b((25[0-5])|(1\d{2})|(2[0-4]\d)|(\d{1,2}))\b)\.){3}(\b((25[0-5])|(1\d{2})|(2[0-4]\d)|(\d{1,2}))\b))|([0-9A-Fa-f]{1,4}::([0-9A-Fa-f]{1,4}:){0,5}[0-9A-Fa-f]{1,4})|(::([0-9A-Fa-f]{1,4}:){0,6}[0-9A-Fa-f]{1,4})|(([0-9A-Fa-f]{1,4}:){1,7}:))$/';
106 +
107 + if(!preg_match($pattern, $ip)){
108 + return false;
109 + }
110 +
111 + return true;
112 +
113 +}
114 +
115 +// Check if a field is posted via POST else return default value
116 +function lz_optpost($name, $default = ''){
117 +
118 + if(!empty($_POST[$name])){
119 + return lz_inputsec(lz_htmlizer(trim($_POST[$name])));
120 + }
121 +
122 + return $default;
123 +}
124 +
125 +// Check if a field is posted via GET else return default value
126 +function lz_optget($name, $default = ''){
127 +
128 + if(!empty($_GET[$name])){
129 + return lz_inputsec(lz_htmlizer(trim($_GET[$name])));
130 + }
131 +
132 + return $default;
133 +}
134 +
135 +// Check if a field is posted via GET or POST else return default value
136 +function lz_optreq($name, $default = ''){
137 +
138 + if(!empty($_REQUEST[$name])){
139 + return lz_inputsec(lz_htmlizer(trim($_REQUEST[$name])));
140 + }
141 +
142 + return $default;
143 +}
144 +
145 +// For filling in posted values
146 +function lz_POSTval($name, $default = ''){
147 +
148 + return (!empty($_POST) ? (!isset($_POST[$name]) ? '' : esc_html($_POST[$name])) : $default);
149 +
150 +}
151 +
152 +function lz_POSTchecked($name, $default = false, $submit_name = ''){
153 +
154 + if(!empty($submit_name)){
155 + $post_to_check = isset($_POST[$submit_name]) ? $_POST[$submit_name] : '';
156 + }else{
157 + $post_to_check = $_POST;
158 + }
159 +
160 + return (!empty($post_to_check) ? (isset($_POST[$name]) ? 'checked="checked"' : '') : (!empty($default) ? 'checked="checked"' : ''));
161 +
162 +}
163 +
164 +function lz_POSTselect($name, $value, $default = false){
165 +
166 + if(empty($_POST)){
167 + if(!empty($default)){
168 + return 'selected="selected"';
169 + }
170 + }else{
171 + if(isset($_POST[$name])){
172 + if(trim($_POST[$name]) == $value){
173 + return 'selected="selected"';
174 + }
175 + }
176 + }
177 +
178 +}
179 +
180 +function lz_POSTradio($name, $val, $default = null){
181 +
182 + return (!empty($_POST) ? (@$_POST[$name] == $val ? 'checked="checked"' : '') : (!is_null($default) && $default == $val ? 'checked="checked"' : ''));
183 +
184 +}
185 +
186 +function lz_inputsec($string){
187 +
188 + $string = addslashes($string);
189 +
190 + // This is to replace ` which can cause the command to be executed in exec()
191 + $string = str_replace('`', '\`', $string);
192 +
193 + return $string;
194 +
195 +}
196 +
197 +function lz_htmlizer($string){
198 +
199 + $string = htmlentities($string, ENT_QUOTES, 'UTF-8');
200 +
201 + preg_match_all('/(&amp;#(\d{1,7}|x[0-9a-fA-F]{1,6});)/', $string, $matches);//r_print($matches);
202 +
203 + foreach($matches[1] as $mk => $mv){
204 + $tmp_m = lz_entity_check($matches[2][$mk]);
205 + $string = str_replace($matches[1][$mk], $tmp_m, $string);
206 + }
207 +
208 + return $string;
209 +
210 +}
211 +
212 +function lz_entity_check($string){
213 +
214 + //Convert Hexadecimal to Decimal
215 + $num = ((substr($string, 0, 1) === 'x') ? hexdec(substr($string, 1)) : (int) $string);
216 +
217 + //Squares and Spaces - return nothing
218 + $string = (($num > 0x10FFFF || ($num >= 0xD800 && $num <= 0xDFFF) || $num < 0x20) ? '' : '&#'.$num.';');
219 +
220 + return $string;
221 +
222 +}
223 +
224 +// Check if a checkbox is selected
225 +function lz_is_checked($post){
226 +
227 + if(!empty($_POST[$post])){
228 + return true;
229 + }
230 + return false;
231 +}
232 +
233 +// Reoort an error
234 +function lz_report_error($error = array()){
235 +
236 + if(empty($error)){
237 + return true;
238 + }
239 +
240 + $error_string = '<b>Please fix the below error(s) :</b> <br />';
241 +
242 + foreach($error as $ek => $ev){
243 + $error_string .= '* '.$ev.'<br />';
244 + }
245 +
246 + echo '<div id="message" class="error"><p>'
247 + . __($error_string, 'loginizer')
248 + . '</p></div>';
249 +}
250 +
251 +// Report a notice
252 +function lz_report_notice($notice = array()){
253 +
254 + global $wp_version;
255 +
256 + if(empty($notice)){
257 + return true;
258 + }
259 +
260 + // Which class do we have to use ?
261 + if(version_compare($wp_version, '3.8', '<')){
262 + $notice_class = 'updated';
263 + }else{
264 + $notice_class = 'updated';
265 + }
266 +
267 + $notice_string = '<b>Please check the below notice(s) :</b> <br />';
268 +
269 + foreach($notice as $ek => $ev){
270 + $notice_string .= '* '.$ev.'<br />';
271 + }
272 +
273 + echo '<div id="message" class="'.$notice_class.'"><p>'
274 + . __($notice_string, 'loginizer')
275 + . '</p></div>';
276 +}
277 +
278 +// Convert an objext to array
279 +function lz_objectToArray($d){
280 +
281 + if(is_object($d)){
282 + $d = get_object_vars($d);
283 + }
284 +
285 + if(is_array($d)){
286 + return array_map(__FUNCTION__, $d); // recursive
287 + }elseif(is_object($d)){
288 + return lz_objectToArray($d);
289 + }else{
290 + return $d;
291 + }
292 +}
293 +
294 +// Sanitize variables
295 +function lz_sanitize_variables($variables = array()){
296 +
297 + if(is_array($variables)){
298 + foreach($variables as $k => $v){
299 + $variables[$k] = trim($v);
300 + $variables[$k] = escapeshellcmd($v);
301 + }
302 + }else{
303 + $variables = escapeshellcmd(trim($variables));
304 + }
305 +
306 + return $variables;
307 +}
308 +
309 +// Is multisite ?
310 +function lz_is_multisite() {
311 +
312 + if(function_exists('get_site_option') && function_exists('is_multisite') && is_multisite()){
313 + return true;
314 + }
315 +
316 + return false;
317 +}
318 +
319 +// Generate a random string
320 +function lz_RandomString($length = 10){
321 + $characters = '0123456789abcdefghijklmnopqrstuvwxyz';
322 + $charactersLength = strlen($characters);
323 + $randomString = '';
324 + for($i = 0; $i < $length; $i++){
325 + $randomString .= $characters[rand(0, $charactersLength - 1)];
326 + }
327 + return $randomString;
328 +}
329 +
330 +function lz_print($array){
331 +
332 + echo '<pre>';
333 + print_r($array);
334 + echo '</pre>';
335 +
336 +}
337 +
338 +function lz_cleanpath($path){
339 + $path = str_replace('\\\\', '/', $path);
340 + $path = str_replace('\\', '/', $path);
341 + $path = str_replace('//', '/', $path);
342 + return rtrim($path, '/');
343 +}
344 +
345 +// Returns the Numeric Value of results Per Page
346 +function lz_get_page($get = 'page', $resperpage = 50){
347 +
348 + $resperpage = (!empty($_REQUEST['reslen']) && is_numeric($_REQUEST['reslen']) ? (int) lz_optreq('reslen') : $resperpage);
349 +
350 + if(lz_optget($get)){
351 + $pg = (int) lz_optget($get);
352 + $pg = $pg - 1;
353 + $page = ($pg * $resperpage);
354 + $page = ($page <= 0 ? 0 : $page);
355 + }else{
356 + $page = 0;
357 + }
358 + return $page;
359 +}
360 +
361 +// Replaces the Variables with the supplied ones
362 +function lz_lang_vars_name($str, $array){
363 +
364 + foreach($array as $k => $v){
365 +
366 + $str = str_replace('$'.$k, $v, $str);
367 +
368 + }
369 +
370 + return $str;
371 +
372 +}
373 +
374 +// Check if Loginizer is premium
375 +function loginizer_is_premium(){
376 + return defined('LOGINIZER_PREMIUM');
377 +}
378 +
379 +function loginizer_feature_available($feature = '', $return = 0){
380 +
381 + if(loginizer_is_premium()){
382 + return true;
383 + }
384 +
385 + $msg = '';
386 +
387 + if(!empty($feature)){
388 + $msg .= '<b>'.$feature.'</b> is available in the Pro version of Loginizer. ';
389 + }
390 +
391 + $msg .= '<a href="'.LOGINIZER_PRICING_URL.'" target="_blank" style="text-decoration:none; color:green;"><b>Upgrade to Pro</b></a>';
392 +
393 + if(!empty($return)){
394 + return $msg;
395 + }else{
396 + echo '<div style="color:#a94442; background-color:#f2dede; border-color:#ebccd1; padding:15px; margin-bottom:20px; border:1px solid transparent; border-radius:4px;">'.$msg.'</div>';
397 + }
398 +
399 +}
400 +
401 +// Checks if the email is valid
402 +function lz_valid_email($email){
403 +
404 + return filter_var($email, FILTER_VALIDATE_EMAIL);
405 +
406 +}