PluginProbe
Plugin Detective – Troubleshooting Conflicts / 1.2.31
Plugin Detective – Troubleshooting Conflicts v1.2.31
1.2.35 1.2.33 1.2.32 1.2.31 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8 1.1.9 1.2 1.2.1 1.2.10 1.2.12 1.2.13 1.2.14 1.2.16 1.2.19 1.2.20 1.2.22 1.2.23 1.2.24 All 54 releases
plugin-detective / troubleshoot / includes / class-auth.php

class-auth.php in Plugin Detective – Troubleshooting Conflicts 1.2.31, at troubleshoot/includes/class-auth.php

118 lines 2.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Troubleshoot Auth.
4 *
5 * @since 0.0.0
6 * @package Troubleshoot
7 */
8
9 /**
10 * Troubleshoot Auth.
11 *
12 * @since 0.0.0
13 */
14 class PDT_Auth {
15 /**
16 * Parent plugin class.
17 *
18 * @since 0.0.0
19 *
20 * @var Troubleshoot
21 */
22 protected $plugin = null;
23
24 /**
25 * Constructor.
26 *
27 * @since 0.0.0
28 *
29 * @param Troubleshoot $plugin Main plugin object.
30 */
31 public function __construct( $plugin ) {
32 $this->plugin = $plugin;
33 $this->hooks();
34 }
35
36 /**
37 * Initiate our hooks.
38 *
39 * @since 0.0.0
40 */
41 public function hooks() {
42
43 }
44
45 /**
46 * Authenticate a username/password and require plugin-management capability.
47 *
48 * Every failure mode — unknown username, wrong password, or a valid login
49 * that lacks the activate_plugins capability — returns the SAME generic
50 * error. Distinct codes/messages here would let an unauthenticated caller
51 * probe which usernames exist (user enumeration), so they are deliberately
52 * collapsed into one indistinguishable response.
53 *
54 * @since 0.0.0
55 *
56 * @param string $username Raw username input.
57 * @param string $password Raw password input.
58 * @return WP_User|WP_Error Plugin-capable user on success, or one generic error.
59 */
60 public static function authenticate( $username, $password ) {
61 $username = sanitize_user( $username );
62 $password = trim( $password );
63
64 $user = apply_filters( 'authenticate', null, $username, $password );
65
66 if ( ! is_a( $user, 'WP_User' ) || ! user_can( $user, 'activate_plugins' ) ) {
67 return new WP_Error( 'authentication_failed', __( '<strong>ERROR</strong>: Authentication failed.', 'plugin-detective' ) );
68 }
69
70 return $user;
71 }
72
73 public static function create_nonce( $action ) {
74 $uid = 'api';
75
76 if ( ! empty( $_SERVER['HTTP_USER_AGENT'] ) ) {
77 $token = sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) );
78 } else {
79 $token = '';
80 }
81 $i = strtotime( gmdate( 'Y-m-d' ) );
82
83 return substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
84 }
85
86 public static function verify_nonce( $nonce, $action ) {
87 $nonce = (string) $nonce;
88 $uid = 'api';
89 if ( ! empty( $_SERVER['HTTP_USER_AGENT'] ) ) {
90 $token = sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) );
91 } else {
92 $token = '';
93 }
94
95 if ( empty( $nonce ) ) {
96 return false;
97 }
98
99 $i = strtotime( gmdate( 'Y-m-d' ) );
100
101 // Nonce generated today (gmt)
102 $expected = substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
103 if ( hash_equals( $expected, $nonce ) ) {
104 return 1;
105 }
106
107 // Nonce generated yesterday (gmt)
108 $expected = substr( sha1( DB_PASSWORD . ( $i - 24*60*60 ) . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
109 if ( hash_equals( $expected, $nonce ) ) {
110 return 2;
111 }
112
113 // Invalid nonce
114 return false;
115 }
116
117 }
118