| @@ -69,10 +69,13 @@ | ||
| 69 | 69 | |
| 70 | 70 | return $user; |
| 71 | 71 | } |
| 72 | 72 | |
| 73 | - public static function create_nonce( $action ) { | |
| 74 | - $uid = 'api'; | |
| 73 | + public static function create_nonce( $action, $uid = null ) { | |
| 74 | + if ( null === $uid ) { | |
| 75 | + $uid = get_current_user_id(); | |
| 76 | + } | |
| 77 | + $uid = (int) $uid; | |
| 75 | 78 | |
| 76 | 79 | if ( ! empty( $_SERVER['HTTP_USER_AGENT'] ) ) { |
| 77 | 80 | $token = sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) ); |
| 78 | 81 | } else { |
| @@ -79,14 +82,30 @@ | ||
| 79 | 82 | $token = ''; |
| 80 | 83 | } |
| 81 | 84 | $i = strtotime( gmdate( 'Y-m-d' ) ); |
| 82 | 85 | |
| 83 | - return substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 ); | |
| 86 | + // Bind the token to the user it was issued for so a low-privileged user's | |
| 87 | + // nonce can never stand in for an administrator's. The uid travels with the | |
| 88 | + // token (the app treats it as opaque) and is re-verified on each request. | |
| 89 | + return $uid . ':' . substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 ); | |
| 84 | 90 | } |
| 85 | 91 | |
| 86 | 92 | public static function verify_nonce( $nonce, $action ) { |
| 87 | 93 | $nonce = (string) $nonce; |
| 88 | - $uid = 'api'; | |
| 94 | + if ( empty( $nonce ) ) { | |
| 95 | + return false; | |
| 96 | + } | |
| 97 | + | |
| 98 | + // Tokens are "<uid>:<hash>" — recover the uid so the hash is checked against | |
| 99 | + // the user it was minted for. Returns that uid on success for the caller's | |
| 100 | + // capability re-check; false otherwise. | |
| 101 | + $parts = explode( ':', $nonce, 2 ); | |
| 102 | + if ( count( $parts ) !== 2 || '' === $parts[1] ) { | |
| 103 | + return false; | |
| 104 | + } | |
| 105 | + $uid = (int) $parts[0]; | |
| 106 | + $provided = $parts[1]; | |
| 107 | + | |
| 89 | 108 | if ( ! empty( $_SERVER['HTTP_USER_AGENT'] ) ) { |
| 90 | 109 | $token = sanitize_text_field( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) ); |
| 91 | 110 | } else { |
| 92 | 111 | $token = ''; |
| @@ -91,24 +110,20 @@ | ||
| 91 | 110 | } else { |
| 92 | 111 | $token = ''; |
| 93 | 112 | } |
| 94 | 113 | |
| 95 | - if ( empty( $nonce ) ) { | |
| 96 | - return false; | |
| 97 | - } | |
| 98 | - | |
| 99 | 114 | $i = strtotime( gmdate( 'Y-m-d' ) ); |
| 100 | 115 | |
| 101 | 116 | // Nonce generated today (gmt) |
| 102 | 117 | $expected = substr( sha1( DB_PASSWORD . $i . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 ); |
| 103 | - if ( hash_equals( $expected, $nonce ) ) { | |
| 104 | - return 1; | |
| 118 | + if ( hash_equals( $expected, $provided ) ) { | |
| 119 | + return $uid; | |
| 105 | 120 | } |
| 106 | 121 | |
| 107 | 122 | // Nonce generated yesterday (gmt) |
| 108 | 123 | $expected = substr( sha1( DB_PASSWORD . ( $i - 24*60*60 ) . '|' . $action . '|' . $uid . '|' . $token ), -12, 10 ); |
| 109 | - if ( hash_equals( $expected, $nonce ) ) { | |
| 110 | - return 2; | |
| 124 | + if ( hash_equals( $expected, $provided ) ) { | |
| 125 | + return $uid; | |
| 111 | 126 | } |
| 112 | 127 | |
| 113 | 128 | // Invalid nonce |
| 114 | 129 | return false; |