| @@ -1,121 +1,121 @@ | ||
| 1 | -<?php | |
| 2 | -// Exit if accessed directly. | |
| 3 | -if ( ! defined( 'ABSPATH' ) ) { | |
| 4 | - exit; | |
| 5 | -} | |
| 6 | - | |
| 7 | -/** | |
| 8 | - * Display the "Disable Default Admin" toggle along with a text field to change the admin login. | |
| 9 | - * | |
| 10 | - * This function generates the settings UI for the administrator to disable the default "admin" login | |
| 11 | - * and specify a new admin username. | |
| 12 | - * | |
| 13 | - * @return void | |
| 14 | - */ | |
| 15 | -function ns_shield_disable_default_admin() { | |
| 16 | - // Odczytujemy wartość opcji (0 lub 1) – musi być zapisana przy użyciu absint. | |
| 17 | - $status = get_option( 'ns_shield_default_admin', 0 ); | |
| 18 | - $admin_login = get_option( 'ns_shield_new_admin_login', '' ); | |
| 19 | - ?> | |
| 20 | - <div class="disable-admin-container"> | |
| 21 | - <label class="switch"> | |
| 22 | - <input type="checkbox" name="ns_shield_default_admin" id="ns_shield_default_admin" value="1" <?php checked( 1, $status, true ); ?>> | |
| 23 | - <span class="slider round"></span> | |
| 24 | - </label> | |
| 25 | - <div class="tooltip" id="tooltip-disable-admin"> | |
| 26 | - <?php echo esc_html__( 'The default "admin" username is a prime target for attackers. Changing this makes it significantly harder for attackers to exploit common login details. Leaving the default admin username active increases vulnerability to brute force attacks.', 'netsensai-shield' ); ?> | |
| 27 | - </div> | |
| 28 | - <!-- Kontener z inline style – widoczność zależy od opcji --> | |
| 29 | - <div id="admin_login_field" style="display:<?php echo $status ? 'block' : 'none'; ?>;"> | |
| 30 | - <input type="text" | |
| 31 | - name="ns_shield_new_admin_login" | |
| 32 | - id="ns_shield_new_admin_login" | |
| 33 | - value="<?php echo esc_attr( $admin_login ); ?>" | |
| 34 | - placeholder="<?php echo esc_attr__( 'Enter new admin login', 'netsensai-shield' ); ?>" | |
| 35 | - class="login-url-input"> | |
| 36 | - </div> | |
| 37 | - </div> | |
| 38 | - <?php | |
| 39 | -} | |
| 40 | - | |
| 41 | -/** | |
| 42 | - * Updates the admin username. | |
| 43 | - * | |
| 44 | - * This function changes the "admin" username to a new value or restores it if the feature is disabled. | |
| 45 | - * | |
| 46 | - * @global WPDB $wpdb | |
| 47 | - * @return void | |
| 48 | - */ | |
| 49 | -function ns_shield_update_admin_username() { | |
| 50 | - global $wpdb; | |
| 51 | - | |
| 52 | - if ( get_option( 'ns_shield_default_admin' ) ) { | |
| 53 | - $admin_user = get_user_by( 'login', 'admin' ); | |
| 54 | - if ( $admin_user ) { | |
| 55 | - $new_admin_login = get_option( 'ns_shield_new_admin_login', '' ); | |
| 56 | - if ( ! empty( $new_admin_login ) ) { | |
| 57 | - if ( wp_get_current_user()->user_login === 'admin' ) { | |
| 58 | - update_option( 'ns_shield_admin_login_change_pending', $new_admin_login ); | |
| 59 | - } else { | |
| 60 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery | |
| 61 | - $wpdb->update( | |
| 62 | - $wpdb->users, | |
| 63 | - array( 'user_login' => sanitize_user( $new_admin_login ) ), | |
| 64 | - array( 'ID' => $admin_user->ID ) | |
| 65 | - ); | |
| 66 | - clean_user_cache( $admin_user->ID ); | |
| 67 | - } | |
| 68 | - } | |
| 69 | - } | |
| 70 | - } else { | |
| 71 | - $custom_admin_login = get_option( 'ns_shield_new_admin_login', '' ); | |
| 72 | - if ( ! empty( $custom_admin_login ) ) { | |
| 73 | - $custom_user = get_user_by( 'login', $custom_admin_login ); | |
| 74 | - if ( $custom_user ) { | |
| 75 | - if ( wp_get_current_user()->user_login === $custom_admin_login ) { | |
| 76 | - update_option( 'ns_shield_admin_login_change_pending', 'admin' ); | |
| 77 | - } else { | |
| 78 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery | |
| 79 | - $wpdb->update( | |
| 80 | - $wpdb->users, | |
| 81 | - array( 'user_login' => 'admin' ), | |
| 82 | - array( 'ID' => $custom_user->ID ) | |
| 83 | - ); | |
| 84 | - clean_user_cache( $custom_user->ID ); | |
| 85 | - } | |
| 86 | - } | |
| 87 | - } | |
| 88 | - } | |
| 89 | -} | |
| 90 | -add_action( 'init', 'ns_shield_update_admin_username' ); | |
| 91 | - | |
| 92 | -/** | |
| 93 | - * Changes the admin username after logout if there's a pending change. | |
| 94 | - * | |
| 95 | - * This function checks if there is a pending admin username change and updates it accordingly. | |
| 96 | - * | |
| 97 | - * @global WPDB $wpdb | |
| 98 | - * @return void | |
| 99 | - */ | |
| 100 | -function ns_shield_change_admin_username_after_logout() { | |
| 101 | - global $wpdb; | |
| 102 | - $pending_login_change = get_option( 'ns_shield_admin_login_change_pending', '' ); | |
| 103 | - | |
| 104 | - if ( ! empty( $pending_login_change ) ) { | |
| 105 | - $target_login = ( $pending_login_change === 'admin' ) | |
| 106 | - ? get_option( 'ns_shield_new_admin_login', '' ) | |
| 107 | - : 'admin'; | |
| 108 | - $admin_user = get_user_by( 'login', $target_login ); | |
| 109 | - if ( $admin_user ) { | |
| 110 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery | |
| 111 | - $wpdb->update( | |
| 112 | - $wpdb->users, | |
| 113 | - array( 'user_login' => sanitize_user( $pending_login_change ) ), | |
| 114 | - array( 'ID' => $admin_user->ID ) | |
| 115 | - ); | |
| 116 | - clean_user_cache( $admin_user->ID ); | |
| 117 | - delete_option( 'ns_shield_admin_login_change_pending' ); | |
| 118 | - } | |
| 119 | - } | |
| 120 | -} | |
| 121 | -add_action( 'wp_logout', 'ns_shield_change_admin_username_after_logout' ); | |
| 1 | +<?php | |
| 2 | +// Exit if accessed directly. | |
| 3 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 4 | + exit; | |
| 5 | +} | |
| 6 | + | |
| 7 | +/** | |
| 8 | + * Display the "Disable Default Admin" toggle along with a text field to change the admin login. | |
| 9 | + * | |
| 10 | + * This function generates the settings UI for the administrator to disable the default "admin" login | |
| 11 | + * and specify a new admin username. | |
| 12 | + * | |
| 13 | + * @return void | |
| 14 | + */ | |
| 15 | +function ns_shield_disable_default_admin() { | |
| 16 | + // Odczytujemy wartość opcji (0 lub 1) – musi być zapisana przy użyciu absint. | |
| 17 | + $status = get_option( 'ns_shield_default_admin', 0 ); | |
| 18 | + $admin_login = get_option( 'ns_shield_new_admin_login', '' ); | |
| 19 | + ?> | |
| 20 | + <div class="disable-admin-container"> | |
| 21 | + <label class="switch"> | |
| 22 | + <input type="checkbox" name="ns_shield_default_admin" id="ns_shield_default_admin" value="1" <?php checked( 1, $status, true ); ?>> | |
| 23 | + <span class="slider round"></span> | |
| 24 | + </label> | |
| 25 | + <div class="tooltip" id="tooltip-disable-admin"> | |
| 26 | + <?php echo esc_html__( 'The default "admin" username is a prime target for attackers. Changing this makes it significantly harder for attackers to exploit common login details. Leaving the default admin username active increases vulnerability to brute force attacks.', 'netsensai-shield' ); ?> | |
| 27 | + </div> | |
| 28 | + <!-- Kontener z inline style – widoczność zależy od opcji --> | |
| 29 | + <div id="admin_login_field" style="display:<?php echo $status ? 'block' : 'none'; ?>;"> | |
| 30 | + <input type="text" | |
| 31 | + name="ns_shield_new_admin_login" | |
| 32 | + id="ns_shield_new_admin_login" | |
| 33 | + value="<?php echo esc_attr( $admin_login ); ?>" | |
| 34 | + placeholder="<?php echo esc_attr__( 'Enter new admin login', 'netsensai-shield' ); ?>" | |
| 35 | + class="login-url-input"> | |
| 36 | + </div> | |
| 37 | + </div> | |
| 38 | + <?php | |
| 39 | +} | |
| 40 | + | |
| 41 | +/** | |
| 42 | + * Updates the admin username. | |
| 43 | + * | |
| 44 | + * This function changes the "admin" username to a new value or restores it if the feature is disabled. | |
| 45 | + * | |
| 46 | + * @global WPDB $wpdb | |
| 47 | + * @return void | |
| 48 | + */ | |
| 49 | +function ns_shield_update_admin_username() { | |
| 50 | + global $wpdb; | |
| 51 | + | |
| 52 | + if ( get_option( 'ns_shield_default_admin' ) ) { | |
| 53 | + $admin_user = get_user_by( 'login', 'admin' ); | |
| 54 | + if ( $admin_user ) { | |
| 55 | + $new_admin_login = get_option( 'ns_shield_new_admin_login', '' ); | |
| 56 | + if ( ! empty( $new_admin_login ) ) { | |
| 57 | + if ( wp_get_current_user()->user_login === 'admin' ) { | |
| 58 | + update_option( 'ns_shield_admin_login_change_pending', $new_admin_login ); | |
| 59 | + } else { | |
| 60 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery | |
| 61 | + $wpdb->update( | |
| 62 | + $wpdb->users, | |
| 63 | + array( 'user_login' => sanitize_user( $new_admin_login ) ), | |
| 64 | + array( 'ID' => $admin_user->ID ) | |
| 65 | + ); | |
| 66 | + clean_user_cache( $admin_user->ID ); | |
| 67 | + } | |
| 68 | + } | |
| 69 | + } | |
| 70 | + } else { | |
| 71 | + $custom_admin_login = get_option( 'ns_shield_new_admin_login', '' ); | |
| 72 | + if ( ! empty( $custom_admin_login ) ) { | |
| 73 | + $custom_user = get_user_by( 'login', $custom_admin_login ); | |
| 74 | + if ( $custom_user ) { | |
| 75 | + if ( wp_get_current_user()->user_login === $custom_admin_login ) { | |
| 76 | + update_option( 'ns_shield_admin_login_change_pending', 'admin' ); | |
| 77 | + } else { | |
| 78 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery | |
| 79 | + $wpdb->update( | |
| 80 | + $wpdb->users, | |
| 81 | + array( 'user_login' => 'admin' ), | |
| 82 | + array( 'ID' => $custom_user->ID ) | |
| 83 | + ); | |
| 84 | + clean_user_cache( $custom_user->ID ); | |
| 85 | + } | |
| 86 | + } | |
| 87 | + } | |
| 88 | + } | |
| 89 | +} | |
| 90 | +add_action( 'init', 'ns_shield_update_admin_username' ); | |
| 91 | + | |
| 92 | +/** | |
| 93 | + * Changes the admin username after logout if there's a pending change. | |
| 94 | + * | |
| 95 | + * This function checks if there is a pending admin username change and updates it accordingly. | |
| 96 | + * | |
| 97 | + * @global WPDB $wpdb | |
| 98 | + * @return void | |
| 99 | + */ | |
| 100 | +function ns_shield_change_admin_username_after_logout() { | |
| 101 | + global $wpdb; | |
| 102 | + $pending_login_change = get_option( 'ns_shield_admin_login_change_pending', '' ); | |
| 103 | + | |
| 104 | + if ( ! empty( $pending_login_change ) ) { | |
| 105 | + $target_login = ( $pending_login_change === 'admin' ) | |
| 106 | + ? get_option( 'ns_shield_new_admin_login', '' ) | |
| 107 | + : 'admin'; | |
| 108 | + $admin_user = get_user_by( 'login', $target_login ); | |
| 109 | + if ( $admin_user ) { | |
| 110 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery | |
| 111 | + $wpdb->update( | |
| 112 | + $wpdb->users, | |
| 113 | + array( 'user_login' => sanitize_user( $pending_login_change ) ), | |
| 114 | + array( 'ID' => $admin_user->ID ) | |
| 115 | + ); | |
| 116 | + clean_user_cache( $admin_user->ID ); | |
| 117 | + delete_option( 'ns_shield_admin_login_change_pending' ); | |
| 118 | + } | |
| 119 | + } | |
| 120 | +} | |
| 121 | +add_action( 'wp_logout', 'ns_shield_change_admin_username_after_logout' ); | |