PluginProbe
Plugin Detective – Troubleshooting Conflicts / 1.2.36
Plugin Detective – Troubleshooting Conflicts v1.2.36
1.2.36 1.2.35 1.2.33 1.2.32 1.2.31 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8 1.1.9 1.2 1.2.1 1.2.10 1.2.12 1.2.13 1.2.14 1.2.16 1.2.19 1.2.20 1.2.22 1.2.23 All 55 releases
← All changes | troubleshoot/includes/class-auth.php +27 -12 1.2.31 → 1.2.36 View file →
@@ -69,10 +69,13 @@
69 69
70 70 return $user;
71 71 }
72 72
73 - public static function create_nonce( $action ) {
74 - $uid = 'api';
73 + public static function create_nonce( $action, $uid = null ) {
74 + if ( null === $uid ) {
75 + $uid = get_current_user_id();
76 + }
77 + $uid = (int) $uid;
75 78
76 79 if ( ! empty( $_SERVER['HTTP_USER_AGENT'] ) ) {
77 80 $token = sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) );
78 81 } else {
@@ -79,14 +82,30 @@
79 82 $token = '';
80 83 }
81 84 $i = strtotime( gmdate( 'Y-m-d' ) );
82 85
83 - return substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
86 + // Bind the token to the user it was issued for so a low-privileged user's
87 + // nonce can never stand in for an administrator's. The uid travels with the
88 + // token (the app treats it as opaque) and is re-verified on each request.
89 + return $uid . ':' . substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
84 90 }
85 91
86 92 public static function verify_nonce( $nonce, $action ) {
87 93 $nonce = (string) $nonce;
88 - $uid = 'api';
94 + if ( empty( $nonce ) ) {
95 + return false;
96 + }
97 +
98 + // Tokens are "<uid>:<hash>" — recover the uid so the hash is checked against
99 + // the user it was minted for. Returns that uid on success for the caller's
100 + // capability re-check; false otherwise.
101 + $parts = explode( ':', $nonce, 2 );
102 + if ( count( $parts ) !== 2 || '' === $parts[1] ) {
103 + return false;
104 + }
105 + $uid = (int) $parts[0];
106 + $provided = $parts[1];
107 +
89 108 if ( ! empty( $_SERVER['HTTP_USER_AGENT'] ) ) {
90 109 $token = sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) );
91 110 } else {
92 111 $token = '';
@@ -91,24 +110,20 @@
91 110 } else {
92 111 $token = '';
93 112 }
94 113
95 - if ( empty( $nonce ) ) {
96 - return false;
97 - }
98 -
99 114 $i = strtotime( gmdate( 'Y-m-d' ) );
100 115
101 116 // Nonce generated today (gmt)
102 117 $expected = substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
103 - if ( hash_equals( $expected, $nonce ) ) {
104 - return 1;
118 + if ( hash_equals( $expected, $provided ) ) {
119 + return $uid;
105 120 }
106 121
107 122 // Nonce generated yesterday (gmt)
108 123 $expected = substr( sha1( DB_PASSWORD . ( $i - 24*60*60 ) . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 );
109 - if ( hash_equals( $expected, $nonce ) ) {
110 - return 2;
124 + if ( hash_equals( $expected, $provided ) ) {
125 + return $uid;
111 126 }
112 127
113 128 // Invalid nonce
114 129 return false;