PluginProbe
Loginizer / trunk
Loginizer vtrunk
2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 All 74 releases
← All changes | init.php +152 -166 2.0.0 → trunk View file →
@@ -4,9 +4,9 @@
4 4 echo 'You are not allowed to access this page directly.';
5 5 exit;
6 6 }
7 7
8 -define('LOGINIZER_VERSION', '2.0.0');
8 +define('LOGINIZER_VERSION', '2.1.1');
9 9 define('LOGINIZER_DIR', dirname(LOGINIZER_FILE));
10 10 define('LOGINIZER_URL', plugins_url('', LOGINIZER_FILE));
11 11 define('LOGINIZER_PRO_URL', 'https://loginizer.com/features#compare');
12 12 define('LOGINIZER_PRICING_URL', 'https://loginizer.com/pricing');
@@ -187,8 +187,29 @@
187 187 $wpdb->query("ALTER TABLE ".$wpdb->prefix."loginizer_logs ADD `url` VARCHAR(255) NOT NULL DEFAULT '' AFTER `ip`;");
188 188
189 189 }
190 190
191 + // Setting alignment to left in social login ?
192 + if($version < 201){
193 + $social_settings = get_option('loginizer_social_settings', []);
194 +
195 + if(!empty($social_settings)){
196 + if(!empty($social_settings['login']) && (!empty($social_settings['login']['login_form']) || !empty($social_settings['login']['registration_form']))){
197 + $social_settings['login']['button_alignment'] = 'left';
198 + }
199 +
200 + if(!empty($social_settings['woocommerce']) && (!empty($social_settings['woocommmerce']['login_form']) || !empty($social_settings['woocommerce']['registration_form']))){
201 + $social_settings['woocommerce']['button_alignment'] = 'left';
202 + }
203 +
204 + if(!empty($social_settings['comment']) && !empty($social_settings['comment']['enable_buttons'])){
205 + $social_settings['comment']['button_alignment'] = 'left';
206 + }
207 +
208 + update_option('loginizer_social_settings', $social_settings);
209 + }
210 + }
211 +
191 212 // Save the new Version
192 213 update_option('loginizer_version', LOGINIZER_VERSION);
193 214
194 215 // TODO:: REMOVE THIS AFTER MARCH 2025
@@ -204,9 +225,9 @@
204 225 }
205 226
206 227 }
207 228
208 -// Add the action to load the plugin
229 +// Add the action to load the plugin
209 230 add_action('plugins_loaded', 'loginizer_load_plugin');
210 231
211 232 // The function that will be called when the plugin is loaded
212 233 function loginizer_load_plugin(){
@@ -214,8 +235,18 @@
214 235 global $loginizer;
215 236
216 237 // Check if the installed version is outdated
217 238 loginizer_update_check();
239 +
240 + // There was an issue were for some users update was stuck, and free was able to get updated through auto updater option
241 + // removing these filters fixes that issue, and our Pro update blocker was improved in 2.1.1
242 + // This check can be removed 1 year from 28.09.2026
243 + if(defined('LOGINIZER_PRO_VERSION') && version_compare(LOGINIZER_PRO_VERSION, '2.1.1', '<')){
244 + foreach(['site_transient_update_plugins', 'pre_site_transient_update_plugins'] as $hook){
245 + remove_filter($hook, 'loginizer_pro_disable_manual_update_for_plugin'); // Older Pro used the default priority
246 + remove_filter($hook, 'loginizer_pro_disable_manual_update_for_plugin', 99);
247 + }
248 + }
218 249
219 250 // Set the array
220 251 if(empty($loginizer)){
221 252 $loginizer = array();
@@ -268,8 +299,14 @@
268 299 }
269 300
270 301 // When was the database cleared last time
271 302 $loginizer['last_reset'] = get_option('loginizer_last_reset');
303 +
304 + if(!isset($loginizer['ultimate-member-active'])){
305 + $um_is_active = in_array('ultimate-member/ultimate-member.php', apply_filters('active_plugins', get_option('active_plugins', [])));
306 +
307 + $loginizer['ultimate-member-active'] = !empty($um_is_active) ? true : false;
308 + }
272 309
273 310 //print_r($loginizer);
274 311
275 312 // Clear retries
@@ -305,17 +342,22 @@
305 342 // Is called before displaying the error message so that we dont show that the username is wrong or the password
306 343 // Update Error message
307 344 add_action('wp_login_errors', 'loginizer_error_handler', 10001, 2);
308 345 add_action('woocommerce_login_failed', 'loginizer_woocommerce_error_handler', 10001);
309 - add_action('wp_login', 'loginizer_login_success', 10, 2);
346 + add_action('wp_login', 'loginizer_login_success', 11, 2);
347 + add_action('rsssl_two_factor_user_authenticated', 'loginizer_rsssl_2fa_success');
348 +
349 + if(!empty($loginizer['ultimate-member-active'])){
350 + add_action('wp_login_failed', 'loginizer_ultimatemember_error_handler', 10001);
351 + }
310 352
311 - if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings']) && !loginizer_is_blacklisted()){
353 + if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings'])){
312 354 add_filter('wp_login_errors', 'loginizer_social_login_error_handler', 10000, 2);
313 355 }
314 356 }
315 357
316 358 // Social Login Form Actions
317 - if(!empty($loginizer['social_settings']) && !loginizer_is_blacklisted()){
359 + if(!empty($loginizer['social_settings'])){
318 360 if(!empty($loginizer['social_settings']['login']['login_form'])){
319 361 add_action('login_form', 'loginizer_social_btn_login');
320 362 }
321 363 }
@@ -326,63 +368,16 @@
326 368
327 369 if(is_admin()){
328 370 include_once LOGINIZER_DIR . '/main/admin.php';
329 371 }
330 -
372 +
331 373 // ----------------
332 374 // PRO INIT END
333 375 // ----------------
334 376
335 - // Is the premium features there ?
336 - if(!defined('LOGINIZER_PREMIUM')){
337 -
338 - if(current_user_can('activate_plugins')){
339 - // The promo time
340 - $loginizer['promo_time'] = get_option('loginizer_promo_time');
341 - if(empty($loginizer['promo_time'])){
342 - $loginizer['promo_time'] = time();
343 - update_option('loginizer_promo_time', $loginizer['promo_time']);
344 - }
345 -
346 - // Are we to show the loginizer promo
347 - if(!empty($loginizer['promo_time']) && $loginizer['promo_time'] > 0 && $loginizer['promo_time'] < (time() - (30*24*3600))){
348 -
349 - add_action('admin_notices', 'loginizer_promo');
350 -
351 - }
352 -
353 - if(!empty($loginizer['csrf_promo']) && $loginizer['csrf_promo'] > 0 && $loginizer['csrf_promo'] < (time() - 86400)){
354 -
355 - add_action('admin_notices', 'loginizer_csrf_promo');
356 -
357 - }
358 -
359 - // Are we to disable the promo
360 - if(isset($_GET['loginizer_promo']) && (int)$_GET['loginizer_promo'] == 0){
361 - update_option('loginizer_promo_time', (0 - time()) );
362 - die('DONE');
363 - }
364 -
365 - $loginizer['backuply_promo'] = get_option('loginizer_backuply_promo_time');
366 -
367 - if(empty($loginizer['backuply_promo'])){
368 - $loginizer['backuply_promo'] = abs($loginizer['promo_time']);
369 - update_option('loginizer_backuply_promo_time', $loginizer['backuply_promo']);
370 - }
371 -
372 - // Setting CSRF Promo time
373 - $loginizer['csrf_promo'] = get_option('loginizer_csrf_promo_time');
374 -
375 - if(empty($loginizer['csrf_promo'])){
376 - $loginizer['csrf_promo'] = abs($loginizer['promo_time']);
377 - update_option('loginizer_csrf_promo_time', $loginizer['csrf_promo']);
378 - }
379 - }
380 - }
381 -
382 377 // Secuity checks for social login.
383 - if(!empty($_GET['lz_social_provider']) && loginizer_can_login()){
384 - include_once LOGINIZER_DIR . '/main/social-login.php';
378 + if(!empty($_GET['lz_social_provider']) && loginizer_can_login() && empty($_GET['lz_api'])){
379 + add_action('init', 'loginizer_social_login_load');
385 380 return;
386 381 }
387 382 }
388 383
@@ -491,8 +486,11 @@
491 486 }
492 487
493 488 $lz_error['ip_blocked'] = $loginizer['msg']['lockout_err'].' '.$_time;
494 489
490 + if(!empty($loginizer['ultimate-member-active']) && class_exists('UM')){
491 + \UM()->form()->add_error('blocked_msg', $lz_error['ip_blocked']);
492 + }
495 493 return false;
496 494 }
497 495 }
498 496
@@ -507,26 +505,31 @@
507 505
508 506 if(empty($blacklist)){
509 507 return false;
510 508 }
511 -
509 +
510 + $current_ip_inet = inet_ptoi($loginizer['current_ip']);
511 +
512 512 foreach($blacklist as $k => $v){
513 -
513 +
514 + $start_inet = inet_ptoi($v['start']);
515 + $end_inet = inet_ptoi($v['end']);
516 +
514 517 // Is the IP in the blacklist ?
515 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip']) && inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
518 + if($start_inet <= $current_ip_inet && $current_ip_inet <= $end_inet){
516 519 $result = 1;
517 520 break;
518 521 }
519 -
522 +
520 523 // Is it in a wider range ?
521 - if(inet_ptoi($v['start']) >= 0 && inet_ptoi($v['end']) < 0){
524 + if($start_inet >= 0 && $end_inet < 0){
522 525
523 526 // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
524 527 // if the current IP is <= than the start of the range, it is within the range
525 528 // OR
526 529 // if the current IP is <= than the end of the range, it is within the range
527 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip'])
528 - || inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
530 + if($start_inet <= $current_ip_inet
531 + || $current_ip_inet <= $end_inet){
529 532 $result = 1;
530 533 break;
531 534 }
532 535
@@ -532,9 +535,9 @@
532 535
533 536 }
534 537
535 538 }
536 -
539 +
537 540 // You are blacklisted
538 541 if(!empty($result)){
539 542 $lz_error['ip_blacklisted'] = $loginizer['msg']['ip_blacklisted'];
540 543 return true;
@@ -543,52 +546,8 @@
543 546 return false;
544 547
545 548 }
546 549
547 -function loginizer_is_whitelisted(){
548 -
549 - global $wpdb, $loginizer, $lz_error;
550 -
551 - $whitelist = $loginizer['whitelist'];
552 -
553 - if(empty($whitelist)){
554 - return false;
555 - }
556 -
557 - foreach($whitelist as $k => $v){
558 -
559 - // Is the IP in the blacklist ?
560 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip']) && inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
561 - $result = 1;
562 - break;
563 - }
564 -
565 - // Is it in a wider range ?
566 - if(inet_ptoi($v['start']) >= 0 && inet_ptoi($v['end']) < 0){
567 -
568 - // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
569 - // if the current IP is <= than the start of the range, it is within the range
570 - // OR
571 - // if the current IP is <= than the end of the range, it is within the range
572 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip'])
573 - || inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
574 - $result = 1;
575 - break;
576 - }
577 -
578 - }
579 -
580 - }
581 -
582 - // You are whitelisted
583 - if(!empty($result)){
584 - return true;
585 - }
586 -
587 - return false;
588 -
589 -}
590 -
591 550 // When the login fails, then this is called
592 551 // We need to update the database
593 552 function loginizer_login_failed($username, $is_2fa = ''){
594 553
@@ -607,53 +566,78 @@
607 566
608 567 if(empty($lz_cannot_login) && empty($loginizer['ip_is_whitelisted']) && empty($loginizer['no_loginizer_logs'])){
609 568
610 569 // The params which comes when social login returns an error, have some characters, which WordPress could not save.
611 - $server_uri = $_SERVER['REQUEST_URI'];
612 - if(!empty($_SERVER['REQUEST_URI']) && strpos($_SERVER['REQUEST_URI'], 'lz_social_provider') !== FALSE){
613 - $request_uri = explode('=', $_SERVER['REQUEST_URI']);
570 + // REQUEST_URI / HTTP_HOST are not always set (WP-CLI, some CGI and XML-RPC setups)
571 + $server_uri = isset($_SERVER['REQUEST_URI']) ? $_SERVER['REQUEST_URI'] : '';
572 + $http_host = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '';
573 +
574 + if(!empty($server_uri) && strpos($server_uri, 'lz_social_provider') !== FALSE){
575 + $request_uri = explode('=', $server_uri);
614 576 $server_uri = $request_uri[0];
615 577 }
616 578
617 - $url = @addslashes((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$_SERVER['HTTP_HOST'].$server_uri);
618 - $url = esc_url($url);
579 + // No addslashes() here, $wpdb->prepare() below does the escaping
580 + $url = esc_url((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$http_host.$server_uri);
619 581
582 + // Must never be 0, we divide by it below
583 + $max_retries = (int) $loginizer['max_retries'] < 1 ? 1 : (int) $loginizer['max_retries'];
584 +
585 + // This way is atomic now, the earlier one were causing race condition.
586 + // NOTE : In the UPDATE part `count` is already the new value, as MySQL / MariaDB
587 + // evaluate the assignments from left to right, so lockout must NOT add 1 again
588 + $upsert = $wpdb->prepare(
589 + "INSERT INTO `".$wpdb->prefix."loginizer_logs`
590 + (username, time, count, ip, lockout, url)
591 + VALUES
592 + (%s, %d, 1, %s, FLOOR(1 / %d), %s)
593 + ON DUPLICATE KEY UPDATE
594 + username = VALUES(username),
595 + time = VALUES(time),
596 + count = count + 1,
597 + lockout = FLOOR(count / %d),
598 + url = VALUES(url)",
599 + $username,
600 + time(),
601 + $loginizer['current_ip'],
602 + $max_retries,
603 + $url,
604 + $max_retries
605 + );
606 + $wpdb->query($upsert);
607 +
608 + // Re-read the persisted row so email/retries-left reflect the actual count
620 609 $sel_query = $wpdb->prepare("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = %s", $loginizer['current_ip']);
621 610 $result = lz_selectquery($sel_query);
622 -
623 - if(!empty($result)){
624 - $lockout = floor((($result['count']+1) / $loginizer['max_retries']));
625 -
626 - $update_data = array('username' => $username,
627 - 'time' => time(),
628 - 'count' => $result['count']+1,
629 - 'lockout' => $lockout,
630 - 'url' => $url);
631 -
632 - $where_data = array('ip' => $loginizer['current_ip']);
633 -
634 - $format = array('%s','%d','%d','%d','%s');
635 - $where_format = array('%s');
636 -
637 - $wpdb->update($wpdb->prefix.'loginizer_logs', $update_data, $where_data, $format, $where_format);
638 -
639 - // Do we need to email admin ?
640 - if(!empty($loginizer['notify_email']) && $lockout >= $loginizer['notify_email']){
641 -
642 - $lockout_time = $loginizer['lockout_time'];
643 -
644 - if($lockout >= $loginizer['max_lockouts']){
645 - // extended lockout is in hours so we have to convert to minute
646 - $lockout_time = $loginizer['lockouts_extend'];
647 - }
648 -
649 - $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
650 - $mail = array();
651 - $mail['to'] = $loginizer['notify_email_address'];
652 - $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
653 - $mail['message'] = 'Hi,
654 611
655 -'.($result['count']+1).' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
612 + if(empty($result)){
613 + $result = array('count' => 0);
614 + }
615 +
616 + $count = (int) $result['count'];
617 + $lockout = !empty($result['lockout']) ? (int) $result['lockout'] : 0;
618 +
619 + // The lockout goes up only on every max_retries'th failure, which is the
620 + // attempt that actually locks the IP out. On the failures in between there
621 + // is nothing new to report, so we must not email on each one of them
622 + $is_new_lockout = !empty($count) && ($count % $max_retries) == 0;
623 +
624 + // Do we need to email admin ?
625 + if(!empty($loginizer['notify_email']) && !empty($is_new_lockout) && $lockout >= $loginizer['notify_email']){
626 +
627 + $lockout_time = $loginizer['lockout_time'];
628 +
629 + if($lockout >= $loginizer['max_lockouts']){
630 + $lockout_time = $loginizer['lockouts_extend'];
631 + }
632 +
633 + $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
634 + $mail = array();
635 + $mail['to'] = $loginizer['notify_email_address'];
636 + $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
637 + $mail['message'] = 'Hi,
638 +
639 +'.(int) $result['count'].' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
656 640 '.home_url().'
657 641
658 642 Last '.$fail_type.' Attempt : '.date('d/M/Y H:i:s P', time()).'
659 643 Last User Attempt : '.$username.'
@@ -661,35 +645,22 @@
661 645
662 646 Regards,
663 647 Loginizer';
664 648
665 - @wp_mail($mail['to'], $mail['subject'], $mail['message']);
666 - }
667 - }else{
668 - $result = array();
669 - $result['count'] = 0;
670 -
671 - $insert_data = array('username' => $username,
672 - 'time' => time(),
673 - 'count' => 1,
674 - 'ip' => $loginizer['current_ip'],
675 - 'lockout' => 0,
676 - 'url' => $url);
677 -
678 - $format = array('%s','%d','%d','%s','%d','%s');
679 -
680 - $wpdb->insert($wpdb->prefix.'loginizer_logs', $insert_data, $format);
649 + @wp_mail($mail['to'], $mail['subject'], $mail['message']);
681 650 }
682 -
683 - // We need to add one as this is a failed attempt as well
684 - $result['count'] = $result['count'] + 1;
651 +
685 652 loginizer_update_attempt_stats(0);
686 - $loginizer['retries_left'] = ($loginizer['max_retries'] - ($result['count'] % $loginizer['max_retries']));
687 - $loginizer['retries_left'] = $loginizer['retries_left'] == $loginizer['max_retries'] ? 0 : $loginizer['retries_left'];
653 + $loginizer['retries_left'] = $max_retries - ($count % $max_retries);
654 + $loginizer['retries_left'] = $loginizer['retries_left'] == $max_retries ? 0 : $loginizer['retries_left'];
688 655
689 656 }
690 657 }
691 658
659 +function loginizer_rsssl_2fa_success($user){
660 + loginizer_login_success('', $user);
661 +}
662 +
692 663 function loginizer_login_success($user_login, $user) {
693 664 global $wp_version, $loginizer;
694 665
695 666 loginizer_update_attempt_stats(1);
@@ -843,11 +814,22 @@
843 814 wc_add_notice( loginizer_retries_left(), 'error' );
844 815 }
845 816 }
846 817
818 +function loginizer_ultimatemember_error_handler(){
819 +
820 + if(class_exists('UM')){
821 + \UM()->form()->add_error('remaining_tries', loginizer_retries_left());
822 + }
823 +}
824 +
847 825 // Handles social login URL
848 826 function loginizer_social_login_error_handler($errors = '', $redirect_to = ''){
849 827 global $loginizer;
828 +
829 + if(loginizer_is_blacklisted()){
830 + return $errors;
831 + }
850 832
851 833 loginizer_get_social_error();
852 834
853 835 if(empty($loginizer['social_errors'])){
@@ -944,8 +926,12 @@
944 926 $loginizer['2fa_msg'][$lk] = $loginizer['2fa_d_msg'][$lk];
945 927 }
946 928 }
947 929
930 +}
931 +
932 +function loginizer_social_login_load(){
933 + include_once LOGINIZER_DIR . '/main/social-login.php';
948 934 }
949 935
950 936 // Checks if softaculous is installed on the server.
951 937 function loginizer_check_softaculous(){