| 1 |
<?php |
| 2 |
/** |
| 3 |
* SureForms - AI Auth. |
| 4 |
* |
| 5 |
* @package sureforms |
| 6 |
* @since 0.0.8 |
| 7 |
*/ |
| 8 |
|
| 9 |
namespace SRFM\Inc\AI_Form_Builder; |
| 10 |
|
| 11 |
use SRFM\Inc\Traits\Get_Instance; |
| 12 |
use SRFM\Inc\Helper; |
| 13 |
|
| 14 |
// Exit if accessed directly. |
| 15 |
if ( ! defined( 'ABSPATH' ) ) { |
| 16 |
exit; |
| 17 |
} |
| 18 |
|
| 19 |
/** |
| 20 |
* SureForms AI Form Builder Class. |
| 21 |
*/ |
| 22 |
class AI_Auth { |
| 23 |
use Get_Instance; |
| 24 |
|
| 25 |
/** |
| 26 |
* The key for encryption and decryption. |
| 27 |
* |
| 28 |
* @since 0.0.8 |
| 29 |
* @var string |
| 30 |
*/ |
| 31 |
private $key = ''; |
| 32 |
|
| 33 |
/** |
| 34 |
* Initiates the auth process. |
| 35 |
* |
| 36 |
* @param \WP_REST_Request $request The request object. |
| 37 |
* @since 0.0.8 |
| 38 |
* @return void |
| 39 |
*/ |
| 40 |
public function get_auth_url( $request ) { |
| 41 |
|
| 42 |
$nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) ); |
| 43 |
|
| 44 |
if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) { |
| 45 |
wp_send_json_error( 'Nonce verification failed.' ); |
| 46 |
} |
| 47 |
|
| 48 |
// Generate a random key of 16 characters. |
| 49 |
$this->key = wp_generate_password( 16, false ); |
| 50 |
|
| 51 |
// Prepare the token data. |
| 52 |
$token_data = [ |
| 53 |
'redirect-back' => site_url() . '/wp-admin/admin.php?page=add-new-form&method=ai', |
| 54 |
'key' => $this->key, |
| 55 |
'site-url' => site_url(), |
| 56 |
'nonce' => wp_create_nonce( 'ai_auth_nonce' ), |
| 57 |
]; |
| 58 |
|
| 59 |
$encoded_token_data = wp_json_encode( $token_data ); |
| 60 |
|
| 61 |
if ( empty( $encoded_token_data ) ) { |
| 62 |
wp_send_json_error( [ 'message' => 'Failed to encode the token data.' ] ); |
| 63 |
} |
| 64 |
|
| 65 |
// Send the token data to the frontend for redirection. |
| 66 |
wp_send_json_success( SRFM_BILLING_PORTAL . 'auth/?token=' . base64_encode( $encoded_token_data ) ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode |
| 67 |
|
| 68 |
} |
| 69 |
|
| 70 |
/** |
| 71 |
* Handles the access key. |
| 72 |
* |
| 73 |
* @param \WP_REST_Request $request The request object. |
| 74 |
* @since 0.0.8 |
| 75 |
* @return void |
| 76 |
*/ |
| 77 |
public function handle_access_key( $request ) { |
| 78 |
|
| 79 |
$nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) ); |
| 80 |
|
| 81 |
if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) { |
| 82 |
wp_send_json_error( 'Nonce verification failed.' ); |
| 83 |
} |
| 84 |
|
| 85 |
// get body data. |
| 86 |
$body = json_decode( $request->get_body(), true ); |
| 87 |
|
| 88 |
if ( empty( $body ) ) { |
| 89 |
wp_send_json_error( [ 'message' => 'Error processing Access Key.' ] ); |
| 90 |
} |
| 91 |
|
| 92 |
// get access key. |
| 93 |
$access_key = is_array( $body ) && ! empty( |
| 94 |
$body['accessKey'] |
| 95 |
) ? Helper::get_string_value( $body['accessKey'] ) : ''; |
| 96 |
|
| 97 |
// decrypt the access key. |
| 98 |
if ( ! empty( $access_key ) ) { |
| 99 |
$this->decrypt_access_key( |
| 100 |
$access_key, |
| 101 |
$this->key |
| 102 |
); |
| 103 |
} else { |
| 104 |
wp_send_json_error( [ 'message' => 'No access key provided.' ] ); |
| 105 |
} |
| 106 |
} |
| 107 |
|
| 108 |
/** |
| 109 |
* Decrypts a string using OpenSSL decryption. |
| 110 |
* |
| 111 |
* @param string $data The data to decrypt. |
| 112 |
* @param string $key The encryption key. |
| 113 |
* @param string $method The encryption method (e.g., AES-256-CBC). |
| 114 |
* @since 0.0.8 |
| 115 |
* @return string|false The decrypted string or false on failure. |
| 116 |
*/ |
| 117 |
public function decrypt_access_key( $data, $key, $method = 'AES-256-CBC' ) { |
| 118 |
// Decode the data and split IV and encrypted data. |
| 119 |
$decoded_data = base64_decode( $data ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode |
| 120 |
|
| 121 |
// if the data is not base64 encoded then return false. |
| 122 |
if ( empty( $decoded_data ) ) { |
| 123 |
return false; |
| 124 |
} |
| 125 |
|
| 126 |
// split the key and encrypted data. |
| 127 |
list($key, $encrypted) = explode( '::', $decoded_data, 2 ); |
| 128 |
|
| 129 |
// Decrypt the data using the key. |
| 130 |
$decrypted = openssl_decrypt( $encrypted, $method, $key, 0, $key ); |
| 131 |
|
| 132 |
// if the decryption returns false then send error. |
| 133 |
if ( empty( $decrypted ) ) { |
| 134 |
wp_send_json_error( [ 'message' => 'Failed to decrypt the access key.' ] ); |
| 135 |
} |
| 136 |
|
| 137 |
// json decode the decrypted data. |
| 138 |
$decrypted_data_array = json_decode( $decrypted, true ); |
| 139 |
|
| 140 |
if ( ! is_array( $decrypted_data_array ) || empty( $decrypted_data_array ) ) { |
| 141 |
wp_send_json_error( [ 'message' => 'Failed to json decode the decrypted data.' ] ); |
| 142 |
} |
| 143 |
|
| 144 |
// verify the nonce that comes in $encrypted_email_array. |
| 145 |
if ( ! empty( $decrypted_data_array['nonce'] ) && ! wp_verify_nonce( $decrypted_data_array['nonce'], 'ai_auth_nonce' ) ) { |
| 146 |
wp_send_json_error( [ 'message' => 'Nonce verification failed.' ] ); |
| 147 |
} |
| 148 |
|
| 149 |
// check if the user email is present in the decrypted data. |
| 150 |
if ( empty( $decrypted_data_array['user_email'] ) ) { |
| 151 |
wp_send_json_error( [ 'message' => 'No user email found in the decrypted data.' ] ); |
| 152 |
} |
| 153 |
|
| 154 |
// remove the nonce from the decrypted data before saving it to the options. |
| 155 |
unset( $decrypted_data_array['nonce'] ); |
| 156 |
|
| 157 |
// save the user email to the options. |
| 158 |
update_option( 'srfm_ai_auth_user_email', $decrypted_data_array ); |
| 159 |
|
| 160 |
wp_send_json_success(); |
| 161 |
} |
| 162 |
|
| 163 |
} |
| 164 |
|