PluginProbe
Loginizer / trunk
Loginizer vtrunk
2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 All 74 releases
← All changes | main/admin.php +195 -66 1.9.9 → trunk View file →
@@ -3,15 +3,82 @@
3 3 if(!defined('ABSPATH')){
4 4 die('Hacking Attempt!');
5 5 }
6 6
7 -// HOOKS
8 -add_action('admin_menu', 'loginizer_admin_menu');
9 -add_action('admin_notices', 'loginizer_social_login_url_alert');
10 -add_action('admin_footer', 'loginizer_social_interim_js');
11 -add_action('admin_init', 'loginizer_admin_actions');
12 -//add_filter("plugin_action_links_plugin_loginizer", 'loginizer_plugin_action_links');
7 +function loginizer_admin_hooks(){
8 + add_action('admin_menu', 'loginizer_admin_menu');
9 + add_action('admin_notices', 'loginizer_social_login_url_alert');
10 + add_action('admin_footer', 'loginizer_social_interim_js');
11 + add_action('admin_init', 'loginizer_admin_actions');
12 + // add_filter("plugin_action_links_plugin_loginizer", 'loginizer_plugin_action_links');
13 +
14 + loginizer_admin_promo_hooks();
15 +}
13 16
17 +function loginizer_admin_promo_hooks(){
18 + global $loginizer;
19 +
20 + if(!current_user_can('activate_plugins') || defined('SITEPAD')){
21 + return;
22 + }
23 +
24 + // Is the premium features there ?
25 + if(!defined('LOGINIZER_PREMIUM')){
26 + // The promo time
27 + $loginizer['promo_time'] = get_option('loginizer_promo_time');
28 + if(empty($loginizer['promo_time'])){
29 + $loginizer['promo_time'] = time();
30 + update_option('loginizer_promo_time', $loginizer['promo_time']);
31 + }
32 +
33 + // Are we to show the loginizer promo
34 + if(!empty($loginizer['promo_time']) && $loginizer['promo_time'] > 0 && $loginizer['promo_time'] < (time() - (30*24*3600))){
35 + add_action('admin_notices', 'loginizer_promo');
36 + }
37 +
38 + if(!empty($loginizer['csrf_promo']) && $loginizer['csrf_promo'] > 0 && $loginizer['csrf_promo'] < (time() - 86400)){
39 + add_action('admin_notices', 'loginizer_csrf_promo');
40 + }
41 +
42 + // Are we to disable the promo
43 + if(isset($_GET['loginizer_promo']) && (int)$_GET['loginizer_promo'] == 0){
44 + update_option('loginizer_promo_time', (0 - time()) );
45 + die('DONE');
46 + }
47 +
48 + $loginizer['backuply_promo'] = get_option('loginizer_backuply_promo_time');
49 + if(empty($loginizer['backuply_promo'])){
50 + $loginizer['backuply_promo'] = abs($loginizer['promo_time']);
51 + update_option('loginizer_backuply_promo_time', $loginizer['backuply_promo']);
52 + }
53 +
54 + // Setting CSRF Promo time
55 + $loginizer['csrf_promo'] = get_option('loginizer_csrf_promo_time');
56 +
57 + if(empty($loginizer['csrf_promo'])){
58 + $loginizer['csrf_promo'] = abs($loginizer['promo_time']);
59 + update_option('loginizer_csrf_promo_time', $loginizer['csrf_promo']);
60 + }
61 + }
62 +
63 + // === Plugin Update Notice === //
64 + $plugin_update_notice = get_option('softaculous_plugin_update_notice', []);
65 + $available_update_list = get_site_transient('update_plugins');
66 +
67 + if(
68 + !empty($available_update_list) &&
69 + is_object($available_update_list) &&
70 + !empty($available_update_list->response) &&
71 + !empty($available_update_list->response['loginizer/loginizer.php']) &&
72 + (empty($plugin_update_notice) || empty($plugin_update_notice['loginizer/loginizer.php']) || (!empty($plugin_update_notice['loginizer/loginizer.php']) &&
73 + version_compare($plugin_update_notice['loginizer/loginizer.php'], $available_update_list->response['loginizer/loginizer.php']->new_version, '<')))
74 + ){
75 + add_action('admin_notices', 'loginizer_plugin_update_notice');
76 + add_filter('softaculous_plugin_update_notice', 'loginizer_update_notice_filter');
77 + }
78 + // === Plugin Update Notice === //
79 +}
80 +
14 81 function loginizer_admin_actions(){
15 82 global $loginizer;
16 83
17 84 if(defined('LOGINIZER_PREMIUM') && !defined('SITEPAD') && current_user_can('activate_plugins') && isset($_GET['page']) && strpos($_GET['page'], 'loginizer') !== FALSE){
@@ -392,9 +459,9 @@
392 459 }
393 460 </script>
394 461
395 462 <hr />
396 - <a href="http://loginizer.com" target="_blank">Loginizer</a> '.__('v'.LOGINIZER_VERSION.'. You can report any bugs ','loginizer').'<a href="http://wordpress.org/support/plugin/loginizer" target="_blank">'.__('here','loginizer').'</a>.';
463 + <a href="http://loginizer.com" target="_blank">Loginizer</a> v'.LOGINIZER_VERSION.'. '.__('You can report any bugs ','loginizer').'<a href="http://wordpress.org/support/plugin/loginizer" target="_blank">'.__('here','loginizer').'</a>.';
397 464
398 465 }
399 466
400 467 echo '
@@ -481,11 +548,19 @@
481 548 // Rename Login
482 549 add_submenu_page('loginizer', __('Security Settings', 'loginizer'), __('Rename Login', 'loginizer'), 'activate_plugins', 'loginizer', 'loginizer_security_settings');
483 550
484 551 }
485 -
552 +
486 553 // Brute Force
487 554 add_submenu_page('loginizer', __('Brute Force Settings', 'loginizer'), __('Brute Force', 'loginizer'), 'activate_plugins', 'loginizer_brute_force', 'loginizer_brute_force_settings');
555 +
556 + if(defined('LOGINIZER_PREMIUM')){
557 + // WAF Security Firewall
558 + $expiry_date = strtotime('2026-03-01');
559 + $tag_new = time() < $expiry_date ? '<span style="display: inline-block; margin-left: 10px; padding: 0px 5px; color: #fff; background-color: #d63638; border-radius: 2px;">'.__('New', 'loginizer').'</span>' : '';
560 +
561 + add_submenu_page('loginizer', __('Country Block', 'loginizer'), __('Country Block', 'loginizer').' '.$tag_new, 'activate_plugins', 'loginizer_firewall', 'loginizer_firewall_settings');
562 + }
488 563
489 564 // PasswordLess
490 565 add_submenu_page('loginizer', __($loginizer['prefix'].'PasswordLess Settings', 'loginizer'), __('PasswordLess', 'loginizer'), 'activate_plugins', 'loginizer_passwordless', 'loginizer_passwordless_settings');
491 566
@@ -497,21 +572,21 @@
497 572
498 573 }
499 574
500 575 // reCaptcha
501 - add_submenu_page('loginizer', __($loginizer['prefix'].'reCAPTCHA Settings', 'loginizer'), __('reCAPTCHA', 'loginizer'), 'activate_plugins', 'loginizer_recaptcha', 'loginizer_recaptcha_settings');
576 + add_submenu_page('loginizer', $loginizer['prefix'].__('reCAPTCHA Settings', 'loginizer'), __('reCAPTCHA', 'loginizer'), 'activate_plugins', 'loginizer_recaptcha', 'loginizer_recaptcha_settings');
502 577
503 578 // Temporary Login
504 - add_submenu_page('loginizer', __($loginizer['prefix'].'SSO', 'loginizer'), __('Single Sign On', 'loginizer'). ((time() < strtotime('30 November 2023')) ? ' <span style="color:yellow;">Update</span>' : ''), 'activate_plugins', 'loginizer_sso', 'loginizer_sso_settings');
579 + add_submenu_page('loginizer', $loginizer['prefix'].__('SSO', 'loginizer'), __('Single Sign On', 'loginizer'). ((time() < strtotime('30 November 2023')) ? ' <span style="color:yellow;">Update</span>' : ''), 'activate_plugins', 'loginizer_sso', 'loginizer_sso_settings');
505 580
506 581 // Social Login
507 - $hook_name = add_submenu_page('loginizer', __($loginizer['prefix'].'social_login', 'loginizer'), __('Social Login', 'loginizer') . ((time() < strtotime('30 July 2024')) ? ' <span style="color:red;">New</span>' : ''), 'activate_plugins', 'loginizer_social_login', 'loginizer_social_login_settings');
582 + $hook_name = add_submenu_page('loginizer', $loginizer['prefix']. __('Social Login', 'loginizer'), __('Social Login', 'loginizer') . (defined('LOGINIZER_PREMIUM') && (time() < strtotime('30 June 2025')) ? ' <span style="color:yellow;font-size:12px;">Updated</span>' : ''), 'activate_plugins', 'loginizer_social_login', 'loginizer_social_login_settings');
508 583
509 584 // Security Settings
510 585 if(!defined('SITEPAD')){
511 586
512 587 // Security Settings
513 - add_submenu_page('loginizer', __($loginizer['prefix'].'Security Settings', 'loginizer'), __('Security Settings', 'loginizer'), 'activate_plugins', 'loginizer_security', 'loginizer_security_settings');
588 + add_submenu_page('loginizer', $loginizer['prefix'].__('Security Settings', 'loginizer'), __('Security Settings', 'loginizer'), 'activate_plugins', 'loginizer_security', 'loginizer_security_settings');
514 589
515 590 // File Checksums
516 591 add_submenu_page('loginizer', __('Loginizer File Checksums', 'loginizer'), __('File Checksums', 'loginizer'), 'activate_plugins', 'loginizer_checksums', 'loginizer_checksums_settings');
517 592
@@ -541,68 +616,60 @@
541 616 function loginizer_promo(){
542 617
543 618 echo '
544 619 <style>
545 -.lz_button {
546 -background-color: #4CAF50; /* Green */
547 -border: none;
548 -color: white;
549 -padding: 8px 16px;
550 -text-align: center;
551 -text-decoration: none;
552 -display: inline-block;
553 -font-size: 16px;
554 -margin: 4px 2px;
555 --webkit-transition-duration: 0.4s; /* Safari */
556 -transition-duration: 0.4s;
557 -cursor: pointer;
558 -}
559 -
560 -.lz_button:focus{
561 -border: none;
562 -color: white;
563 -}
564 -
565 -.lz_button1 {
566 -color: white;
620 +.wp-core-ui .lz_button1 {
567 621 background-color: #4CAF50;
568 -border:3px solid #4CAF50;
622 +border-color: transparent;
623 +border-radius: 2px;
624 +color: #fff;
569 625 }
570 626
571 -.lz_button1:hover {
572 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
573 -color: white;
574 -border:3px solid #4CAF50;
627 +.wp-core-ui .lz_button1:hover {
628 +background-color:#3b963f;
629 +border-color: transparent;
630 +border-radius: 2px;
631 +color: #fff;
575 632 }
576 633
577 -.lz_button2 {
578 -color: white;
634 +.wp-core-ui .lz_button2 {
579 635 background-color: #0085ba;
636 +border-color: transparent;
637 +border-radius: 2px;
638 +color: #fff;
580 639 }
581 640
582 -.lz_button2:hover {
583 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
584 -color: white;
641 +.wp-core-ui .lz_button2:hover {
642 +background-color: #0175a3;
643 +border-color: transparent;
644 +border-radius: 2px;
645 +color: #fff;
585 646 }
586 647
587 -.lz_button3 {
588 -color: white;
648 +.wp-core-ui .lz_button3 {
589 649 background-color: #365899;
650 +border-color: transparent;
651 +border-radius: 2px;
652 +color: #fff;
590 653 }
591 654
592 -.lz_button3:hover {
593 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
594 -color: white;
655 +.wp-core-ui .lz_button3:hover {
656 +border-color: transparent;
657 +background-color: #274785;
658 +color:#fff;
595 659 }
596 660
597 -.lz_button4 {
598 -color: white;
599 -background-color: rgb(66, 184, 221);
661 +.wp-core-ui .lz_button4 {
662 +background-color: #14171A;
663 +border-color: transparent;
664 +border-radius: 2px;
665 +color: #fff;
600 666 }
601 667
602 -.lz_button4:hover {
603 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
604 -color: white;
668 +.wp-core-ui .lz_button4:hover {
669 +background-color: #24292E;
670 +color: #fff;
671 +border-color: transparent;
605 672 }
606 673
607 674 .loginizer_promo-close{
608 675 float:right;
@@ -639,12 +706,12 @@
639 706 </a>
640 707 <img src="'.LOGINIZER_URL.'/assets/images/loginizer-200.png" style="float:left; margin:10px 20px 10px 10px" width="100" />
641 708 <p style="font-size:16px">We are glad you like Loginizer and have been using it since the past few days. It is time to take the next step </p>
642 709 <p>
643 - <a class="lz_button lz_button1" target="_blank" href="https://loginizer.com/features">Upgrade to Pro</a>
644 - <a class="lz_button lz_button2" target="_blank" href="https://wordpress.org/support/view/plugin-reviews/loginizer">Rate it 5★\'s</a>
645 - <a class="lz_button lz_button3" target="_blank" href="https://www.facebook.com/Loginizer-815504798591884/">Like Us on Facebook</a>
646 - <a class="lz_button lz_button4" target="_blank" href="https://twitter.com/home?status='.rawurlencode('I use @loginizer to secure my #WordPress site - https://loginizer.com').'">Tweet about Loginizer</a>
710 + <a class="button lz_button1" target="_blank" href="https://loginizer.com/features">'.esc_html__('Upgrade to Pro', 'loginizer').'</a>
711 + <a class="button lz_button2" target="_blank" href="https://wordpress.org/support/view/plugin-reviews/loginizer">Rate it 5★\'s</a>
712 + <a class="button lz_button3" target="_blank" href="https://www.facebook.com/Loginizer-815504798591884/">'.esc_html__('Like Us on Facebook', 'loginizer').'</a>
713 + <a class="button lz_button4" target="_blank" href="https://x.com/intent/tweet?text='.rawurlencode('I use @loginizer to secure my #WordPress site - https://loginizer.com').'">'.esc_html__('Post on X about Loginizer', 'loginizer').'</a>
647 714 </p>
648 715 </div>';
649 716
650 717 }
@@ -681,9 +748,8 @@
681 748 }
682 749
683 750 function loginizer_dashboard(){
684 751 include_once LOGINIZER_DIR . '/main/settings/dashboard.php';
685 -
686 752 loginizer_page_dashboard();
687 753 }
688 754
689 755 function loginizer_sso_settings(){
@@ -697,8 +763,13 @@
697 763
698 764 loginizer_social_login();
699 765 }
700 766
767 +function loginizer_firewall_settings(){
768 + include_once LOGINIZER_PRO_DIR . 'main/settings/waf.php';
769 + loginizer_pro_firewall();
770 +}
771 +
701 772 // Hides the interim login poup after successful login.
702 773 function loginizer_social_interim_js(){
703 774
704 775 if(isset($_GET['interim_login']) && $_GET['interim_login'] === 'lz' && is_user_logged_in()){
@@ -716,10 +787,11 @@
716 787 // We want to show this error to user which has sufficient privilage
717 788 if(!current_user_can('activate_plugins')){
718 789 return;
719 790 }
720 -
721 - if(get_option('loginizer_social_login_url', '') === wp_login_url()){
791 +
792 + $set_login_url = get_option('loginizer_social_login_url', '');
793 + if(empty($set_login_url) || $set_login_url === wp_login_url()){
722 794 return;
723 795 }
724 796
725 797 $provider_settings = get_option('loginizer_provider_settings', []);
@@ -730,14 +802,23 @@
730 802 return;
731 803 }
732 804
733 805 $has_enabled = false;
806 + $has_non_login_auth = false;
734 807 foreach($provider_settings as $provider){
735 - if($provider['enabled']){
808 + if(empty($provider['loginizer_social_key']) && !empty($provider['enabled'])){
809 + $has_non_login_auth = true;
810 + }
811 +
812 + if(!empty($provider['enabled'])){
736 813 $has_enabled = true;
737 - break;
738 814 }
739 815 }
816 +
817 + // We will only show this error if the user is using key based config
818 + if(empty($has_non_login_auth)){
819 + return;
820 + }
740 821
741 822 // If we have no Provider enabled then just show the warning on the social login page.
742 823 if(empty($has_enabled) && (empty($_GET['page']) || $_GET['page'] !== 'loginizer_social_login')){
743 824 return;
@@ -743,9 +824,9 @@
743 824 return;
744 825 }
745 826
746 827 echo '<div class="notice notice-error">
747 - <h4>'.esc_html__('Your changed login slug!', 'loginizer').'</h4>
828 + <h4>'.esc_html__('You changed login slug!', 'loginizer').'</h4>
748 829 <p>'.esc_html__('You changed the login slug and have some social login apps enabled. These social login apps use the login URL as the redirect URI. This means that since the login URL has changed, the social login will now break.', 'loginizer').'</p>
749 830
750 831 <h4>'.esc_html__('How to fix:', 'loginizer').'</h4>
751 832 <p>'.esc_html__('When you created secret keys for the social apps, you also provided a Redirect URI. To fix this issue, you need to update that Redirect URI.', 'loginizer').'<br/>
@@ -871,5 +952,53 @@
871 952 var admin_url = "'.admin_url().'"+"admin-ajax.php";
872 953 jQuery.post(admin_url, data, function(response){
873 954 });
874 955 });');
875 -}
956 +}
957 +
958 +function loginizer_update_notice_filter($plugins = []){
959 + $plugins['loginizer/loginizer.php'] = 'Loginizer';
960 +
961 + return $plugins;
962 +}
963 +
964 +function loginizer_plugin_update_notice(){
965 + if(defined('SOFTACULOUS_PLUGIN_UPDATE_NOTICE')){
966 + return;
967 + }
968 +
969 + $to_update_plugins = apply_filters('softaculous_plugin_update_notice', []);
970 +
971 + if(empty($to_update_plugins)){
972 + return;
973 + }
974 +
975 + /* translators: %1$s is replaced with a "string" of name of plugins, and %2$s is replaced with "string" which can be "is" or "are" based on the count of the plugin */
976 + $msg = sprintf(__('New versions of %1$s %2$s available. Updating ensures better performance, security, and access to the latest features.', 'loginizer'), '<b>'.esc_html(implode(', ', $to_update_plugins)).'</b>', (count($to_update_plugins) > 1 ? 'are' : 'is')) . ' <a class="button button-primary" href='.esc_url(admin_url('plugins.php?plugin_status=upgrade')).'>Update Now</a>';
977 +
978 + define('SOFTACULOUS_PLUGIN_UPDATE_NOTICE', true); // To make sure other plugins don't return a Notice
979 + echo '<div class="notice notice-info is-dismissible" id="loginizer-plugin-update-notice">
980 + <p>'.$msg. '</p>
981 + </div>';
982 +
983 + wp_register_script('loginizer-update-notice', '', ['jquery'], '', true);
984 + wp_enqueue_script('loginizer-update-notice');
985 + wp_add_inline_script('loginizer-update-notice', 'jQuery("#loginizer-plugin-update-notice").on("click", function(e){
986 + let target = jQuery(e.target);
987 +
988 + if(!target.hasClass("notice-dismiss")){
989 + return;
990 + }
991 +
992 + var data;
993 +
994 + // Hide it
995 + jQuery("#loginizer-plugin-update-notice").hide();
996 +
997 + // Save this preference
998 + jQuery.post("'.admin_url('admin-ajax.php?action=loginizer_close_update_notice').'&security='.wp_create_nonce('loginizer_promo_nonce').'", data, function(response) {
999 + //alert(response);
1000 + });
1001 + });');
1002 +}
1003 +
1004 +loginizer_admin_hooks();